2021-05-21 16:15:47 +03:00
|
|
|
package filtering
|
2019-10-09 19:51:26 +03:00
|
|
|
|
|
|
|
import (
|
2021-12-27 19:40:39 +03:00
|
|
|
"fmt"
|
2023-08-23 16:58:24 +03:00
|
|
|
"net/netip"
|
2024-02-08 20:39:18 +03:00
|
|
|
"slices"
|
2020-01-16 12:51:35 +03:00
|
|
|
"strings"
|
2019-10-09 19:51:26 +03:00
|
|
|
|
2021-12-27 19:40:39 +03:00
|
|
|
"github.com/AdguardTeam/golibs/errors"
|
2023-08-22 16:45:11 +03:00
|
|
|
"github.com/AdguardTeam/golibs/log"
|
2020-01-16 12:51:35 +03:00
|
|
|
"github.com/miekg/dns"
|
2019-10-09 19:51:26 +03:00
|
|
|
)
|
|
|
|
|
2023-02-21 16:38:22 +03:00
|
|
|
// Legacy DNS rewrites
|
|
|
|
|
2021-12-27 19:40:39 +03:00
|
|
|
// LegacyRewrite is a single legacy DNS rewrite record.
|
|
|
|
//
|
|
|
|
// Instances of *LegacyRewrite must never be nil.
|
|
|
|
type LegacyRewrite struct {
|
|
|
|
// Domain is the domain pattern for which this rewrite should work.
|
2020-01-16 12:51:35 +03:00
|
|
|
Domain string `yaml:"domain"`
|
2021-12-24 20:14:36 +03:00
|
|
|
|
2021-07-12 21:10:39 +03:00
|
|
|
// Answer is the IP address, canonical name, or one of the special
|
|
|
|
// values: "A" or "AAAA".
|
|
|
|
Answer string `yaml:"answer"`
|
2021-12-24 20:14:36 +03:00
|
|
|
|
2021-07-12 21:10:39 +03:00
|
|
|
// IP is the IP address that should be used in the response if Type is
|
2021-12-27 19:40:39 +03:00
|
|
|
// dns.TypeA or dns.TypeAAAA.
|
2023-08-23 16:58:24 +03:00
|
|
|
IP netip.Addr `yaml:"-"`
|
2021-12-24 20:14:36 +03:00
|
|
|
|
2021-07-12 21:10:39 +03:00
|
|
|
// Type is the DNS record type: A, AAAA, or CNAME.
|
|
|
|
Type uint16 `yaml:"-"`
|
2020-01-16 12:51:35 +03:00
|
|
|
}
|
|
|
|
|
2021-12-27 19:40:39 +03:00
|
|
|
// equal returns true if the rw is equal to the other.
|
|
|
|
func (rw *LegacyRewrite) equal(other *LegacyRewrite) (ok bool) {
|
|
|
|
return rw.Domain == other.Domain && rw.Answer == other.Answer
|
2021-09-17 14:37:55 +03:00
|
|
|
}
|
|
|
|
|
2021-12-27 19:40:39 +03:00
|
|
|
// matchesQType returns true if the entry matches the question type qt.
|
|
|
|
func (rw *LegacyRewrite) matchesQType(qt uint16) (ok bool) {
|
2021-09-17 14:37:55 +03:00
|
|
|
// Add CNAMEs, since they match for all types requests.
|
2021-12-27 19:40:39 +03:00
|
|
|
if rw.Type == dns.TypeCNAME {
|
2021-09-17 14:37:55 +03:00
|
|
|
return true
|
|
|
|
}
|
|
|
|
|
|
|
|
// Reject types other than A and AAAA.
|
2021-12-27 19:40:39 +03:00
|
|
|
if qt != dns.TypeA && qt != dns.TypeAAAA {
|
2021-09-17 14:37:55 +03:00
|
|
|
return false
|
|
|
|
}
|
|
|
|
|
|
|
|
// If the types match or the entry is set to allow only the other type,
|
|
|
|
// include them.
|
2023-08-23 16:58:24 +03:00
|
|
|
return rw.Type == qt || rw.IP == netip.Addr{}
|
2021-09-17 14:37:55 +03:00
|
|
|
}
|
|
|
|
|
2023-08-23 16:58:24 +03:00
|
|
|
// normalize makes sure that the new or decoded entry is normalized with regards
|
|
|
|
// to domain name case, IP length, and so on.
|
2021-12-27 19:40:39 +03:00
|
|
|
//
|
|
|
|
// If rw is nil, it returns an errors.
|
|
|
|
func (rw *LegacyRewrite) normalize() (err error) {
|
|
|
|
if rw == nil {
|
|
|
|
return errors.Error("nil rewrite entry")
|
|
|
|
}
|
|
|
|
|
|
|
|
// TODO(a.garipov): Write a case-agnostic version of strings.HasSuffix and
|
|
|
|
// use it in matchDomainWildcard instead of using strings.ToLower
|
2021-09-17 14:37:55 +03:00
|
|
|
// everywhere.
|
2021-12-27 19:40:39 +03:00
|
|
|
rw.Domain = strings.ToLower(rw.Domain)
|
2021-09-17 14:37:55 +03:00
|
|
|
|
2021-12-27 19:40:39 +03:00
|
|
|
switch rw.Answer {
|
2021-09-17 14:37:55 +03:00
|
|
|
case "AAAA":
|
2023-08-23 16:58:24 +03:00
|
|
|
rw.IP = netip.Addr{}
|
2021-12-27 19:40:39 +03:00
|
|
|
rw.Type = dns.TypeAAAA
|
2021-09-17 14:37:55 +03:00
|
|
|
|
2021-12-27 19:40:39 +03:00
|
|
|
return nil
|
2021-09-17 14:37:55 +03:00
|
|
|
case "A":
|
2023-08-23 16:58:24 +03:00
|
|
|
rw.IP = netip.Addr{}
|
2021-12-27 19:40:39 +03:00
|
|
|
rw.Type = dns.TypeA
|
2021-09-17 14:37:55 +03:00
|
|
|
|
2021-12-27 19:40:39 +03:00
|
|
|
return nil
|
2021-09-17 14:37:55 +03:00
|
|
|
default:
|
|
|
|
// Go on.
|
|
|
|
}
|
|
|
|
|
2023-08-23 16:58:24 +03:00
|
|
|
ip, err := netip.ParseAddr(rw.Answer)
|
|
|
|
if err != nil {
|
|
|
|
log.Debug("normalizing legacy rewrite: %s", err)
|
2021-12-27 19:40:39 +03:00
|
|
|
rw.Type = dns.TypeCNAME
|
2021-09-17 14:37:55 +03:00
|
|
|
|
2021-12-27 19:40:39 +03:00
|
|
|
return nil
|
2021-09-17 14:37:55 +03:00
|
|
|
}
|
|
|
|
|
2023-08-23 16:58:24 +03:00
|
|
|
rw.IP = ip
|
|
|
|
if ip.Is4() {
|
2021-12-27 19:40:39 +03:00
|
|
|
rw.Type = dns.TypeA
|
2021-09-17 14:37:55 +03:00
|
|
|
} else {
|
2021-12-27 19:40:39 +03:00
|
|
|
rw.Type = dns.TypeAAAA
|
2021-09-17 14:37:55 +03:00
|
|
|
}
|
2021-12-27 19:40:39 +03:00
|
|
|
|
|
|
|
return nil
|
2020-01-16 12:51:35 +03:00
|
|
|
}
|
|
|
|
|
2021-12-27 19:40:39 +03:00
|
|
|
// isWildcard returns true if pat is a wildcard domain pattern.
|
|
|
|
func isWildcard(pat string) bool {
|
|
|
|
return len(pat) > 1 && pat[0] == '*' && pat[1] == '.'
|
2020-01-16 12:51:35 +03:00
|
|
|
}
|
|
|
|
|
2021-07-12 21:10:39 +03:00
|
|
|
// matchDomainWildcard returns true if host matches the wildcard pattern.
|
|
|
|
func matchDomainWildcard(host, wildcard string) (ok bool) {
|
|
|
|
return isWildcard(wildcard) && strings.HasSuffix(host, wildcard[1:])
|
2020-01-16 12:51:35 +03:00
|
|
|
}
|
|
|
|
|
2023-08-10 20:00:17 +03:00
|
|
|
// Compare is used to sort rewrites according to the following priority:
|
2022-09-23 13:23:35 +03:00
|
|
|
//
|
2023-02-21 16:38:22 +03:00
|
|
|
// 1. A and AAAA > CNAME;
|
|
|
|
// 2. wildcard > exact;
|
|
|
|
// 3. lower level wildcard > higher level wildcard;
|
2023-08-10 20:00:17 +03:00
|
|
|
func (rw *LegacyRewrite) Compare(b *LegacyRewrite) (res int) {
|
2023-09-19 17:58:37 +03:00
|
|
|
if rw.Type == dns.TypeCNAME {
|
|
|
|
if b.Type != dns.TypeCNAME {
|
|
|
|
return -1
|
|
|
|
}
|
|
|
|
} else if b.Type == dns.TypeCNAME {
|
2023-08-10 20:00:17 +03:00
|
|
|
return 1
|
|
|
|
}
|
|
|
|
|
2023-09-19 17:58:37 +03:00
|
|
|
if aIsWld, bIsWld := isWildcard(rw.Domain), isWildcard(b.Domain); aIsWld == bIsWld {
|
2023-08-10 20:00:17 +03:00
|
|
|
// Both are either wildcards or both aren't.
|
2023-09-19 17:58:37 +03:00
|
|
|
return len(b.Domain) - len(rw.Domain)
|
|
|
|
} else if aIsWld {
|
2023-08-10 20:00:17 +03:00
|
|
|
return 1
|
2023-09-19 17:58:37 +03:00
|
|
|
} else {
|
|
|
|
return -1
|
2020-01-16 12:51:35 +03:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-12-27 19:40:39 +03:00
|
|
|
// prepareRewrites normalizes and validates all legacy DNS rewrites.
|
|
|
|
func (d *DNSFilter) prepareRewrites() (err error) {
|
2023-09-04 17:18:43 +03:00
|
|
|
for i, r := range d.conf.Rewrites {
|
2021-12-27 19:40:39 +03:00
|
|
|
err = r.normalize()
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("at index %d: %w", i, err)
|
|
|
|
}
|
2020-01-16 12:51:35 +03:00
|
|
|
}
|
2021-12-27 19:40:39 +03:00
|
|
|
|
|
|
|
return nil
|
2020-01-16 12:51:35 +03:00
|
|
|
}
|
|
|
|
|
2021-12-24 20:14:36 +03:00
|
|
|
// findRewrites returns the list of matched rewrite entries. If rewrites are
|
|
|
|
// empty, but matched is true, the domain is found among the rewrite rules but
|
|
|
|
// not for this question type.
|
|
|
|
//
|
|
|
|
// The result priority is: CNAME, then A and AAAA; exact, then wildcard. If the
|
|
|
|
// host is matched exactly, wildcard entries aren't returned. If the host
|
|
|
|
// matched by wildcards, return the most specific for the question type.
|
|
|
|
func findRewrites(
|
2021-12-27 19:40:39 +03:00
|
|
|
entries []*LegacyRewrite,
|
2021-12-24 20:14:36 +03:00
|
|
|
host string,
|
|
|
|
qtype uint16,
|
2021-12-27 19:40:39 +03:00
|
|
|
) (rewrites []*LegacyRewrite, matched bool) {
|
2021-09-17 14:37:55 +03:00
|
|
|
for _, e := range entries {
|
|
|
|
if e.Domain != host && !matchDomainWildcard(host, e.Domain) {
|
2021-07-12 21:10:39 +03:00
|
|
|
continue
|
|
|
|
}
|
|
|
|
|
2021-12-24 20:14:36 +03:00
|
|
|
matched = true
|
2021-09-17 14:37:55 +03:00
|
|
|
if e.matchesQType(qtype) {
|
2021-12-24 20:14:36 +03:00
|
|
|
rewrites = append(rewrites, e)
|
2020-01-16 12:51:35 +03:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-12-24 20:14:36 +03:00
|
|
|
if len(rewrites) == 0 {
|
|
|
|
return nil, matched
|
2020-01-16 12:51:35 +03:00
|
|
|
}
|
|
|
|
|
2023-08-10 20:00:17 +03:00
|
|
|
slices.SortFunc(rewrites, (*LegacyRewrite).Compare)
|
2020-01-16 12:51:35 +03:00
|
|
|
|
2021-12-24 20:14:36 +03:00
|
|
|
for i, r := range rewrites {
|
2021-03-29 19:35:35 +03:00
|
|
|
if isWildcard(r.Domain) {
|
2021-12-24 20:14:36 +03:00
|
|
|
// Don't use rewrites[:0], because we need to return at least one
|
|
|
|
// item here.
|
2024-02-13 13:19:22 +03:00
|
|
|
rewrites = rewrites[:max(1, i)]
|
2021-03-29 19:35:35 +03:00
|
|
|
|
|
|
|
break
|
2020-01-16 12:51:35 +03:00
|
|
|
}
|
|
|
|
}
|
2020-04-27 17:24:55 +03:00
|
|
|
|
2021-12-24 20:14:36 +03:00
|
|
|
return rewrites, matched
|
2020-01-16 12:51:35 +03:00
|
|
|
}
|
2023-08-22 16:45:11 +03:00
|
|
|
|
|
|
|
// setRewriteResult sets the Reason or IPList of res if necessary. res must not
|
|
|
|
// be nil.
|
|
|
|
func setRewriteResult(res *Result, host string, rewrites []*LegacyRewrite, qtype uint16) {
|
|
|
|
for _, rw := range rewrites {
|
|
|
|
if rw.Type == qtype && (qtype == dns.TypeA || qtype == dns.TypeAAAA) {
|
2023-08-23 16:58:24 +03:00
|
|
|
if rw.IP == (netip.Addr{}) {
|
2023-08-22 16:45:11 +03:00
|
|
|
// "A"/"AAAA" exception: allow getting from upstream.
|
|
|
|
res.Reason = NotFilteredNotFound
|
|
|
|
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
res.IPList = append(res.IPList, rw.IP)
|
|
|
|
|
|
|
|
log.Debug("rewrite: a/aaaa for %s is %s", host, rw.IP)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// cloneRewrites returns a deep copy of entries.
|
|
|
|
func cloneRewrites(entries []*LegacyRewrite) (clone []*LegacyRewrite) {
|
|
|
|
clone = make([]*LegacyRewrite, len(entries))
|
|
|
|
for i, rw := range entries {
|
2023-08-23 16:58:24 +03:00
|
|
|
clone[i] = &LegacyRewrite{
|
|
|
|
Domain: rw.Domain,
|
|
|
|
Answer: rw.Answer,
|
|
|
|
IP: rw.IP,
|
|
|
|
Type: rw.Type,
|
|
|
|
}
|
2023-08-22 16:45:11 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
return clone
|
|
|
|
}
|