dns/xfr.go

237 lines
5.6 KiB
Go
Raw Normal View History

2011-03-16 15:21:35 +00:00
package dns
2013-10-02 19:35:13 +00:00
import (
"time"
)
2013-09-28 19:32:38 +00:00
2013-10-12 18:01:29 +00:00
// Envelope is used when doing a zone transfer with a remote server.
type Envelope struct {
2013-10-12 18:01:29 +00:00
RR []RR // The set of RRs in the answer section of the xfr reply message.
2012-12-02 07:41:49 +00:00
Error error // If something went wrong, this contains the error.
}
2013-10-12 18:01:29 +00:00
// A Transfer defines parameters that are used during a zone transfer.
2013-10-02 19:35:13 +00:00
type Transfer struct {
2013-10-11 21:34:04 +00:00
*Conn
2013-10-12 18:01:29 +00:00
DialTimeout time.Duration // net.DialTimeout (ns), defaults to 2 * 1e9
ReadTimeout time.Duration // net.Conn.SetReadTimeout value for connections (ns), defaults to 2 * 1e9
WriteTimeout time.Duration // net.Conn.SetWriteTimeout value for connections (ns), defaults to 2 * 1e9
2013-10-12 13:00:10 +00:00
TsigSecret map[string]string // Secret(s) for Tsig map[<zonename>]<base64 secret>, zonename must be fully qualified
2013-10-11 16:36:37 +00:00
tsigTimersOnly bool
2013-10-02 19:35:13 +00:00
}
2014-06-04 10:21:27 +00:00
// Think we need to away to stop the transfer
2013-10-11 19:10:57 +00:00
// In performs an incoming transfer with the server in a.
func (t *Transfer) In(q *Msg, a string) (env chan *Envelope, err error) {
2013-10-02 19:35:13 +00:00
timeout := dnsTimeout
if t.DialTimeout != 0 {
timeout = t.DialTimeout
2011-09-11 20:10:04 +00:00
}
2013-11-01 09:44:24 +00:00
t.Conn, err = DialTimeout("tcp", a, timeout)
2013-10-02 19:35:13 +00:00
if err != nil {
return nil, err
2011-04-18 20:08:12 +00:00
}
2013-10-12 11:32:14 +00:00
if err := t.WriteMsg(q); err != nil {
return nil, err
2011-03-21 15:28:13 +00:00
}
2013-10-11 19:10:57 +00:00
env = make(chan *Envelope)
go func() {
if q.Question[0].Qtype == TypeAXFR {
go t.inAxfr(q.Id, env)
return
}
if q.Question[0].Qtype == TypeIXFR {
go t.inIxfr(q.Id, env)
return
}
}()
return env, nil
2011-03-21 14:44:51 +00:00
}
2013-10-11 16:40:15 +00:00
func (t *Transfer) inAxfr(id uint16, c chan *Envelope) {
2011-04-18 20:08:12 +00:00
first := true
2013-10-10 19:01:35 +00:00
defer t.Close()
defer close(c)
2013-10-11 16:36:37 +00:00
timeout := dnsTimeout
if t.ReadTimeout != 0 {
timeout = t.ReadTimeout
}
2011-03-21 14:44:51 +00:00
for {
2013-10-12 11:32:14 +00:00
t.Conn.SetReadDeadline(time.Now().Add(timeout))
2013-10-10 19:01:35 +00:00
in, err := t.ReadMsg()
2011-03-21 14:44:51 +00:00
if err != nil {
c <- &Envelope{nil, err}
2011-09-10 12:48:22 +00:00
return
2011-03-21 14:44:51 +00:00
}
2013-10-11 16:18:37 +00:00
if id != in.Id {
c <- &Envelope{in.Answer, ErrId}
2011-09-11 15:01:55 +00:00
return
}
2011-03-21 14:44:51 +00:00
if first {
2013-10-11 16:18:37 +00:00
if !isSOAFirst(in) {
c <- &Envelope{in.Answer, ErrSoa}
2011-09-10 12:48:22 +00:00
return
2011-03-21 14:44:51 +00:00
}
first = !first
// only one answer that is SOA, receive more
2013-09-06 09:49:07 +00:00
if len(in.Answer) == 1 {
2013-10-11 16:18:37 +00:00
t.tsigTimersOnly = true
c <- &Envelope{in.Answer, nil}
continue
}
2011-03-21 14:44:51 +00:00
}
2011-03-18 13:13:42 +00:00
2011-03-21 14:44:51 +00:00
if !first {
2013-10-11 16:18:37 +00:00
t.tsigTimersOnly = true // Subsequent envelopes use this.
if isSOALast(in) {
c <- &Envelope{in.Answer, nil}
2011-09-10 12:48:22 +00:00
return
2011-03-21 14:44:51 +00:00
}
c <- &Envelope{in.Answer, nil}
2011-03-21 14:44:51 +00:00
}
}
panic("dns: not reached")
2011-04-18 07:58:15 +00:00
}
2013-10-11 16:40:15 +00:00
func (t *Transfer) inIxfr(id uint16, c chan *Envelope) {
2013-10-11 16:36:37 +00:00
serial := uint32(0) // The first serial seen is the current server serial
2011-03-21 14:44:51 +00:00
first := true
2013-10-11 16:36:37 +00:00
defer t.Close()
defer close(c)
2013-10-11 16:36:37 +00:00
timeout := dnsTimeout
2013-10-02 19:35:13 +00:00
if t.ReadTimeout != 0 {
timeout = t.ReadTimeout
}
2011-03-21 14:44:51 +00:00
for {
2013-10-11 16:36:37 +00:00
t.SetReadDeadline(time.Now().Add(timeout))
in, err := t.ReadMsg()
2011-09-11 20:10:04 +00:00
if err != nil {
c <- &Envelope{in.Answer, err}
2011-09-11 20:10:04 +00:00
return
}
2013-10-11 16:36:37 +00:00
if id != in.Id {
c <- &Envelope{in.Answer, ErrId}
2011-03-21 14:44:51 +00:00
return
}
if first {
// A single SOA RR signals "no changes"
2013-10-11 16:36:37 +00:00
if len(in.Answer) == 1 && isSOAFirst(in) {
c <- &Envelope{in.Answer, nil}
2011-09-11 20:10:04 +00:00
return
2011-03-21 14:44:51 +00:00
}
// Check if the returned answer is ok
2013-10-11 16:36:37 +00:00
if !isSOAFirst(in) {
c <- &Envelope{in.Answer, ErrSoa}
2011-03-21 14:44:51 +00:00
return
}
// This serial is important
serial = in.Answer[0].(*SOA).Serial
2011-03-21 14:44:51 +00:00
first = !first
}
// Now we need to check each message for SOA records, to see what we need to do
if !first {
2013-10-11 16:36:37 +00:00
t.tsigTimersOnly = true
2011-09-11 20:10:04 +00:00
// If the last record in the IXFR contains the servers' SOA, we should quit
if v, ok := in.Answer[len(in.Answer)-1].(*SOA); ok {
2011-09-11 20:10:04 +00:00
if v.Serial == serial {
c <- &Envelope{in.Answer, nil}
2011-09-11 20:10:04 +00:00
return
}
}
c <- &Envelope{in.Answer, nil}
2011-03-21 14:44:51 +00:00
}
}
2011-03-18 13:13:42 +00:00
}
2011-09-11 15:24:52 +00:00
2013-10-12 15:26:25 +00:00
// Out performs an outgoing transfer with the client connecting in w.
// Basic use pattern:
2013-05-05 18:30:44 +00:00
//
2013-10-12 15:26:25 +00:00
// ch := make(chan *dns.Envelope)
// tr := new(dns.Transfer)
// tr.Out(w, r, ch)
// c <- &dns.Envelope{RR: []dns.RR{soa, rr1, rr2, rr3, soa}}
// close(ch)
// w.Hijack()
// // w.Close() // Client closes connection
2012-08-28 09:03:41 +00:00
//
2013-10-12 15:26:25 +00:00
// The server is responsible for sending the correct sequence of RRs through the
// channel ch.
func (t *Transfer) Out(w ResponseWriter, q *Msg, ch chan *Envelope) error {
2013-10-11 16:18:37 +00:00
r := new(Msg)
// Compress?
2013-10-11 16:18:37 +00:00
r.SetReply(q)
r.Authoritative = true
2013-10-11 16:18:37 +00:00
go func() {
2013-10-11 16:36:37 +00:00
for x := range ch {
// assume it fits TODO(miek): fix
r.Answer = append(r.Answer, x.RR...)
if err := w.WriteMsg(r); err != nil {
return
}
2013-10-11 16:18:37 +00:00
}
2013-10-11 19:10:57 +00:00
w.TsigTimersOnly(true)
r.Answer = nil
2013-10-11 16:18:37 +00:00
}()
return nil
2013-10-02 19:35:13 +00:00
}
// ReadMsg reads a message from the transfer connection t.
func (t *Transfer) ReadMsg() (*Msg, error) {
m := new(Msg)
p := make([]byte, MaxMsgSize)
2013-10-10 19:01:35 +00:00
n, err := t.Read(p)
2013-10-02 19:35:13 +00:00
if err != nil && n == 0 {
return nil, err
2011-09-10 12:59:21 +00:00
}
2013-10-02 19:35:13 +00:00
p = p[:n]
if err := m.Unpack(p); err != nil {
return nil, err
2011-04-18 20:08:12 +00:00
}
2013-10-12 11:32:14 +00:00
if ts := m.IsTsig(); ts != nil && t.TsigSecret != nil {
2013-10-02 19:35:13 +00:00
if _, ok := t.TsigSecret[ts.Hdr.Name]; !ok {
return m, ErrSecret
}
// Need to work on the original message p, as that was used to calculate the tsig.
2013-10-11 16:18:37 +00:00
err = TsigVerify(p, t.TsigSecret[ts.Hdr.Name], t.tsigRequestMAC, t.tsigTimersOnly)
2013-10-02 19:35:13 +00:00
}
return m, err
2011-09-10 12:59:21 +00:00
}
2013-10-12 18:01:29 +00:00
// WriteMsg writes a message through the transfer connection t.
2013-10-02 19:35:13 +00:00
func (t *Transfer) WriteMsg(m *Msg) (err error) {
var out []byte
2013-10-12 11:32:14 +00:00
if ts := m.IsTsig(); ts != nil && t.TsigSecret != nil {
2013-10-02 19:35:13 +00:00
if _, ok := t.TsigSecret[ts.Hdr.Name]; !ok {
return ErrSecret
2012-08-28 07:27:55 +00:00
}
2013-10-11 16:18:37 +00:00
out, t.tsigRequestMAC, err = TsigGenerate(m, t.TsigSecret[ts.Hdr.Name], t.tsigRequestMAC, t.tsigTimersOnly)
2013-10-02 19:35:13 +00:00
} else {
out, err = m.Pack()
2012-08-27 18:58:58 +00:00
}
2013-10-02 19:35:13 +00:00
if err != nil {
return err
}
2013-10-10 19:01:35 +00:00
if _, err = t.Write(out); err != nil {
2013-10-02 19:35:13 +00:00
return err
}
return nil
}
2013-10-11 16:18:37 +00:00
func isSOAFirst(in *Msg) bool {
2011-03-21 15:28:13 +00:00
if len(in.Answer) > 0 {
2013-10-10 19:01:35 +00:00
return in.Answer[0].Header().Rrtype == TypeSOA
}
return false
}
2013-10-11 16:18:37 +00:00
func isSOALast(in *Msg) bool {
2013-10-10 19:01:35 +00:00
if len(in.Answer) > 0 {
return in.Answer[len(in.Answer)-1].Header().Rrtype == TypeSOA
2011-03-21 15:28:13 +00:00
}
return false
2012-08-27 18:58:58 +00:00
}