From 0afc7ca910effe1798a182aa2f35f7cc1ecf3cd8 Mon Sep 17 00:00:00 2001 From: DL6ER Date: Sun, 12 Sep 2021 16:15:33 +0200 Subject: [PATCH] Required FTL changes due to the preceding dnsmasq commit. Signed-off-by: DL6ER --- src/api/api.c | 19 +++++++++++++++---- src/dnsmasq/cache.c | 5 +++-- src/dnsmasq/forward.c | 4 ++-- src/dnsmasq/rfc1035.c | 4 ++-- src/dnsmasq_interface.c | 30 ++++++++++++++++++++---------- src/dnsmasq_interface.h | 9 ++++++--- 6 files changed, 48 insertions(+), 23 deletions(-) diff --git a/src/api/api.c b/src/api/api.c index 93811a97..672bbd81 100644 --- a/src/api/api.c +++ b/src/api/api.c @@ -41,6 +41,9 @@ // get_edestr() #include "api_helper.h" +// defined in src/dnsmasq/cache.c +extern char *querystr(char *desc, unsigned short type); + #define min(a,b) ({ __typeof__ (a) _a = (a); __typeof__ (b) _b = (b); _a < _b ? _a : _b; }) /* qsort comparision function (count field), sort ASC */ @@ -881,10 +884,18 @@ void getAllQueries(const char *client_message, const int *sock) char othertype[12] = { 0 }; // Maximum is "TYPE65535" = 10 bytes if(query->type == TYPE_OTHER) { - // Format custom type into buffer - sprintf(othertype, "TYPE%u", query->qtype); - // Replace qtype pointer - qtype = othertype; + // Check the dnsmasq RR types table for a matching record + qtype = querystr((char*)"", query->qtype); + logg("Typestr: %s", qtype); + + // If not known (querystr() returned "type=1234"), we replace this + if(!qtype || strstr(qtype, "type=") != NULL) + { + // Format custom type into buffer + sprintf(othertype, "TYPE%u", query->qtype); + // Replace qtype pointer + qtype = othertype; + } } // Hide UNKNOWN queries when not requesting both query status types diff --git a/src/dnsmasq/cache.c b/src/dnsmasq/cache.c index 80728ee9..18c535fe 100644 --- a/src/dnsmasq/cache.c +++ b/src/dnsmasq/cache.c @@ -1862,7 +1862,8 @@ char *record_source(unsigned int index) return ""; } -static char *querystr(char *desc, unsigned short type) +// Pi-hole modified +char *querystr(char *desc, unsigned short type) { unsigned int i; int len = 10; /* strlen("type=xxxxx") */ @@ -1958,7 +1959,7 @@ void _log_query(unsigned int flags, char *name, union all_addr *addr, char *arg, char *verb = "is"; char *extra = ""; - FTL_hook(flags, name, addr, arg, daemon->log_display_id, file, line); + FTL_hook(flags, name, addr, arg, daemon->log_display_id, type, file, line); if (!option_bool(OPT_LOG)) return; diff --git a/src/dnsmasq/forward.c b/src/dnsmasq/forward.c index 09f328ba..f2a7a2ac 100644 --- a/src/dnsmasq/forward.c +++ b/src/dnsmasq/forward.c @@ -1557,7 +1557,7 @@ void receive_query(struct listener *listen, time_t now) log_query_mysockaddr(F_QUERY | F_FORWARD, daemon->namebuff, &source_addr, auth_dns ? "auth" : "query", type); piholeblocked = FTL_new_query(F_QUERY | F_FORWARD , daemon->namebuff, - &source_addr, types, type, daemon->log_display_id, &edns, UDP); + &source_addr, auth_dns ? "auth" : "query", type, daemon->log_display_id, &edns, UDP); #ifdef HAVE_CONNTRACK is_single_query = 1; @@ -2030,7 +2030,7 @@ unsigned char *tcp_request(int confd, time_t now, &peer_addr, auth_dns ? "auth" : "query", qtype); piholeblocked = FTL_new_query(F_QUERY | F_FORWARD, daemon->namebuff, - &peer_addr, types, qtype, daemon->log_display_id, &edns, TCP); + &peer_addr, auth_dns ? "auth" : "query", qtype, daemon->log_display_id, &edns, TCP); #ifdef HAVE_CONNTRACK diff --git a/src/dnsmasq/rfc1035.c b/src/dnsmasq/rfc1035.c index 7170c81c..9c930dab 100644 --- a/src/dnsmasq/rfc1035.c +++ b/src/dnsmasq/rfc1035.c @@ -648,7 +648,7 @@ int extract_addresses(struct dns_header *header, size_t qlen, char *name, time_t { // This query is to be blocked as we found a blocked // domain while walking the CNAME path. Log to pihole.log here - log_query(F_UPSTREAM, name, NULL, "blocked during CNAME inspection"); + log_query(F_UPSTREAM, name, NULL, "blocked during CNAME inspection", 0); return 2; } // ********************************************************************************** @@ -1856,7 +1856,7 @@ size_t answer_request(struct dns_header *header, char *limit, size_t qlen, { // This query is to be blocked as we found a blocked domain while walking the CNAME path. // Log to pihole.log: "cached domainabc.com is blocked during CNAME inspection" - log_query(F_UPSTREAM, name, NULL, "blocked during CNAME inspection"); + log_query(F_UPSTREAM, name, NULL, "blocked during CNAME inspection", 0); break; } // ********************************************************************************** diff --git a/src/dnsmasq_interface.c b/src/dnsmasq_interface.c index 24ab9f42..6564c37f 100644 --- a/src/dnsmasq_interface.c +++ b/src/dnsmasq_interface.c @@ -91,7 +91,7 @@ static union mysockaddr last_server = {{ 0 }}; unsigned char* pihole_privacylevel = &config.privacylevel; const char *flagnames[] = {"F_IMMORTAL ", "F_NAMEP ", "F_REVERSE ", "F_FORWARD ", "F_DHCP ", "F_NEG ", "F_HOSTS ", "F_IPV4 ", "F_IPV6 ", "F_BIGNAME ", "F_NXDOMAIN ", "F_CNAME ", "F_DNSKEY ", "F_CONFIG ", "F_DS ", "F_DNSSECOK ", "F_UPSTREAM ", "F_RRNAME ", "F_SERVER ", "F_QUERY ", "F_NOERR ", "F_AUTH ", "F_DNSSEC ", "F_KEYTAG ", "F_SECSTAT ", "F_NO_RR ", "F_IPSET ", "F_NOEXTRA ", "F_SERVFAIL", "F_RCODE"}; -void FTL_hook(unsigned int flags, char *name, union all_addr *addr, char *arg, int id, const char* file, const int line) +void FTL_hook(unsigned int flags, char *name, union all_addr *addr, char *arg, int id, unsigned short type, const char* file, const int line) { // Extract filename from path const char *path = short_path(file); @@ -119,7 +119,6 @@ void FTL_hook(unsigned int flags, char *name, union all_addr *addr, char *arg, i if(!config.show_dnssec) return; - const int qtype = strcmp(arg, "dnssec-query[DS]") == 0 ? T_DS : T_DNSKEY; const ednsData edns = { 0 }; union mysockaddr saddr = {{ 0 }}; if(flags & F_IPV4) @@ -132,7 +131,7 @@ void FTL_hook(unsigned int flags, char *name, union all_addr *addr, char *arg, i memcpy(&saddr.in6.sin6_addr, &addr->addr6, sizeof(addr->addr6)); saddr.sa.sa_family = AF_INET; } - _FTL_new_query(flags, name, NULL, arg, qtype, id, &edns, INTERNAL, file, line); + _FTL_new_query(flags, name, NULL, arg, type, id, &edns, INTERNAL, file, line); FTL_forwarded(flags, name, addr, id, path, line); } else if(flags & F_AUTH) @@ -323,7 +322,7 @@ size_t _FTL_make_answer(struct dns_header *header, char *limit, const size_t len add_resource_record(header, limit, &trunc, sizeof(struct dns_header), &p, daemon->local_ttl, NULL, T_A, C_IN, (char*)"4", &addr->addr4); - log_query(flags & ~F_IPV6, name, addr, (char*)blockingreason); + log_query(flags & ~F_IPV6, name, addr, (char*)blockingreason, 0); } // Add AAAA answer record if requested @@ -351,12 +350,12 @@ size_t _FTL_make_answer(struct dns_header *header, char *limit, const size_t len add_resource_record(header, limit, &trunc, sizeof(struct dns_header), &p, daemon->local_ttl, NULL, T_AAAA, C_IN, (char*)"6", &addr->addr6); - log_query(flags & ~F_IPV4, name, addr, (char*)blockingreason); + log_query(flags & ~F_IPV4, name, addr, (char*)blockingreason, 0); } // Log empty replies (NODATA/NXDOMAIN/REFUSED) if(!(flags & (F_IPV4 | F_IPV6))) - log_query(flags, name, NULL, (char*)blockingreason); + log_query(flags, name, NULL, (char*)blockingreason, 0); // Indicate if truncated (client should retry over TCP) if (trunc) @@ -366,7 +365,7 @@ size_t _FTL_make_answer(struct dns_header *header, char *limit, const size_t len } bool _FTL_new_query(const unsigned int flags, const char *name, - union mysockaddr *addr, const char *types, + union mysockaddr *addr, char *arg, const unsigned short qtype, const int id, const ednsData *edns, const enum protocol proto, const char* file, const int line) @@ -553,6 +552,7 @@ bool _FTL_new_query(const unsigned int flags, const char *name, // Log new query if in debug mode if(config.debug & DEBUG_QUERIES) { + const char *types = querystr(arg, qtype); logg("**** new %sIPv%d %s query \"%s\" from %s:%s#%d (ID %i, FTL %i, %s:%i)", proto == TCP ? "TCP " : proto == UDP ? "UDP " : "", family == AF_INET ? 4 : 6, types, domainString, interface, @@ -571,7 +571,11 @@ bool _FTL_new_query(const unsigned int flags, const char *name, if(config.analyze_only_A_AAAA && querytype != TYPE_A && querytype != TYPE_AAAA) { // Don't process this query further here, we already counted it - if(config.debug & DEBUG_QUERIES) logg("Notice: Skipping new query: %s (%i)", types, id); + if(config.debug & DEBUG_QUERIES) + { + const char *types = querystr(arg, qtype); + logg("Notice: Skipping new query: %s (%i)", types, id); + } free(domainString); unlock_shm(); return false; @@ -1699,9 +1703,15 @@ static void FTL_reply(const unsigned int flags, const char *name, const union al answer = arg; // e.g. "reply is no DS" } + // Substitute "." if we are querying the root domain (e.g. DNSKEY) + const char *dispname = name; + if(!name || strlen(name) == 0) + dispname = "."; + if(cached || last_server.sa.sa_family == 0) // Log cache or upstream reply from unknown source - logg("**** got %s reply: %s is %s (ID %i, %s:%i)", cached ? "cache" : "upstream", name, answer, id, file, line); + logg("**** got %s reply: %s is %s (ID %i, %s:%i)", + cached ? "cache" : "upstream", dispname, answer, id, file, line); else { char ip[ADDRSTRLEN+1] = { 0 }; @@ -1709,7 +1719,7 @@ static void FTL_reply(const unsigned int flags, const char *name, const union al mysockaddr_extract_ip_port(&last_server, ip, &port); // Log server which replied to our request logg("**** got %s reply from %s#%d: %s is %s (ID %i, %s:%i)", - cached ? "cache" : "upstream", ip, port, name, answer, id, file, line); + cached ? "cache" : "upstream", ip, port, dispname, answer, id, file, line); } } diff --git a/src/dnsmasq_interface.h b/src/dnsmasq_interface.h index 857c92b1..80c186fd 100644 --- a/src/dnsmasq_interface.h +++ b/src/dnsmasq_interface.h @@ -19,12 +19,12 @@ extern int socketfd, telnetfd4, telnetfd6; extern unsigned char* pihole_privacylevel; enum protocol { TCP, UDP, INTERNAL }; -void FTL_hook(unsigned int flags, char *name, union all_addr *addr, char *arg, int id, const char* file, const int line); +void FTL_hook(unsigned int flags, char *name, union all_addr *addr, char *arg, int id, unsigned short type, const char* file, const int line); void FTL_iface(const int ifidx); -#define FTL_new_query(flags, name, addr, types, qtype, id, edns, proto) _FTL_new_query(flags, name, addr, types, qtype, id, edns, proto, __FILE__, __LINE__) -bool _FTL_new_query(const unsigned int flags, const char *name, union mysockaddr *addr, const char *types, const unsigned short qtype, const int id, const ednsData *edns, enum protocol proto, const char* file, const int line); +#define FTL_new_query(flags, name, addr, arg, qtype, id, edns, proto) _FTL_new_query(flags, name, addr, arg, qtype, id, edns, proto, __FILE__, __LINE__) +bool _FTL_new_query(const unsigned int flags, const char *name, union mysockaddr *addr, char *arg, const unsigned short qtype, const int id, const ednsData *edns, enum protocol proto, const char* file, const int line); #define FTL_header_analysis(header4, rcode, server, id) _FTL_header_analysis(header4, rcode, server, id, __FILE__, __LINE__) void _FTL_header_analysis(const unsigned char header4, const unsigned int rcode, const struct server *server, const int id, const char* file, const int line); @@ -48,4 +48,7 @@ void FTL_TCP_worker_terminating(bool finished); bool FTL_unlink_DHCP_lease(const char *ipaddr); +// defined in src/dnsmasq/cache.c +extern char *querystr(char *desc, unsigned short type); + #endif // DNSMASQ_INTERFACE_H