2021-09-28 12:42:01 +02:00
|
|
|
package netxlite
|
2021-02-02 12:05:47 +01:00
|
|
|
|
2022-05-15 19:25:27 +02:00
|
|
|
//
|
|
|
|
// DNS-over-{TCP,TLS} transport
|
|
|
|
//
|
|
|
|
|
2021-02-02 12:05:47 +01:00
|
|
|
import (
|
|
|
|
"context"
|
|
|
|
"errors"
|
|
|
|
"io"
|
|
|
|
"math"
|
|
|
|
"net"
|
|
|
|
"time"
|
2022-01-03 13:53:23 +01:00
|
|
|
|
|
|
|
"github.com/ooni/probe-cli/v3/internal/model"
|
2021-02-02 12:05:47 +01:00
|
|
|
)
|
|
|
|
|
2021-09-29 20:21:25 +02:00
|
|
|
// DialContextFunc is the type of net.Dialer.DialContext.
|
2021-02-02 12:05:47 +01:00
|
|
|
type DialContextFunc func(context.Context, string, string) (net.Conn, error)
|
|
|
|
|
2022-05-14 17:38:31 +02:00
|
|
|
// DNSOverTCPTransport is a DNS-over-{TCP,TLS} DNSTransport.
|
2021-02-02 12:05:47 +01:00
|
|
|
//
|
2022-05-25 17:03:58 +02:00
|
|
|
// Note: this implementation always creates a new connection for each query. This
|
|
|
|
// strategy is less efficient but MAY be more robust for cleartext TCP connections
|
|
|
|
// when querying for a blocked domain name causes endpoint blocking.
|
2022-05-14 17:38:31 +02:00
|
|
|
type DNSOverTCPTransport struct {
|
2021-02-02 12:05:47 +01:00
|
|
|
dial DialContextFunc
|
2022-05-25 17:03:58 +02:00
|
|
|
decoder model.DNSDecoder
|
2021-02-02 12:05:47 +01:00
|
|
|
address string
|
|
|
|
network string
|
|
|
|
requiresPadding bool
|
|
|
|
}
|
|
|
|
|
2022-05-14 17:38:31 +02:00
|
|
|
// NewDNSOverTCPTransport creates a new DNSOverTCPTransport.
|
2021-09-29 20:21:25 +02:00
|
|
|
//
|
|
|
|
// Arguments:
|
|
|
|
//
|
|
|
|
// - dial is a function with the net.Dialer.DialContext's signature;
|
|
|
|
//
|
|
|
|
// - address is the endpoint address (e.g., 8.8.8.8:53).
|
2022-05-14 17:38:31 +02:00
|
|
|
func NewDNSOverTCPTransport(dial DialContextFunc, address string) *DNSOverTCPTransport {
|
2022-05-25 17:03:58 +02:00
|
|
|
return newDNSOverTCPOrTLSTransport(dial, "tcp", address, false)
|
2021-02-02 12:05:47 +01:00
|
|
|
}
|
|
|
|
|
2022-05-25 17:03:58 +02:00
|
|
|
// NewDNSOverTLSTransport creates a new DNSOverTLS transport.
|
2021-09-29 20:21:25 +02:00
|
|
|
//
|
|
|
|
// Arguments:
|
|
|
|
//
|
|
|
|
// - dial is a function with the net.Dialer.DialContext's signature;
|
|
|
|
//
|
|
|
|
// - address is the endpoint address (e.g., 8.8.8.8:853).
|
2022-05-25 17:03:58 +02:00
|
|
|
func NewDNSOverTLSTransport(dial DialContextFunc, address string) *DNSOverTCPTransport {
|
|
|
|
return newDNSOverTCPOrTLSTransport(dial, "dot", address, true)
|
|
|
|
}
|
|
|
|
|
|
|
|
// newDNSOverTCPOrTLSTransport is the common factory for creating a transport
|
|
|
|
func newDNSOverTCPOrTLSTransport(
|
|
|
|
dial DialContextFunc, network, address string, padding bool) *DNSOverTCPTransport {
|
2022-05-14 17:38:31 +02:00
|
|
|
return &DNSOverTCPTransport{
|
2021-02-02 12:05:47 +01:00
|
|
|
dial: dial,
|
2022-05-25 17:03:58 +02:00
|
|
|
decoder: &DNSDecoderMiekg{},
|
2021-02-02 12:05:47 +01:00
|
|
|
address: address,
|
2022-05-25 17:03:58 +02:00
|
|
|
network: network,
|
|
|
|
requiresPadding: padding,
|
2021-02-02 12:05:47 +01:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-05-25 17:03:58 +02:00
|
|
|
// errQueryTooLarge indicates the query is too large for the transport.
|
|
|
|
var errQueryTooLarge = errors.New("oodns: query too large for this transport")
|
|
|
|
|
2021-09-29 20:21:25 +02:00
|
|
|
// RoundTrip sends a query and receives a reply.
|
2022-05-25 17:03:58 +02:00
|
|
|
func (t *DNSOverTCPTransport) RoundTrip(
|
|
|
|
ctx context.Context, query model.DNSQuery) (model.DNSResponse, error) {
|
|
|
|
// TODO(bassosimone): this method should more strictly honour the context, which
|
|
|
|
// currently is only used to bound the dial operation
|
|
|
|
rawQuery, err := query.Bytes()
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
if len(rawQuery) > math.MaxUint16 {
|
|
|
|
return nil, errQueryTooLarge
|
2021-02-02 12:05:47 +01:00
|
|
|
}
|
|
|
|
conn, err := t.dial(ctx, "tcp", t.address)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
defer conn.Close()
|
2022-05-25 17:03:58 +02:00
|
|
|
const iotimeout = 10 * time.Second
|
|
|
|
conn.SetDeadline(time.Now().Add(iotimeout))
|
2021-02-02 12:05:47 +01:00
|
|
|
// Write request
|
2022-05-25 17:03:58 +02:00
|
|
|
buf := []byte{byte(len(rawQuery) >> 8)}
|
|
|
|
buf = append(buf, byte(len(rawQuery)))
|
|
|
|
buf = append(buf, rawQuery...)
|
2021-02-02 12:05:47 +01:00
|
|
|
if _, err = conn.Write(buf); err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
// Read response
|
|
|
|
header := make([]byte, 2)
|
|
|
|
if _, err = io.ReadFull(conn, header); err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
length := int(header[0])<<8 | int(header[1])
|
2022-05-25 17:03:58 +02:00
|
|
|
rawResponse := make([]byte, length)
|
|
|
|
if _, err = io.ReadFull(conn, rawResponse); err != nil {
|
2021-02-02 12:05:47 +01:00
|
|
|
return nil, err
|
|
|
|
}
|
2022-05-25 17:03:58 +02:00
|
|
|
return t.decoder.DecodeResponse(rawResponse, query)
|
2021-02-02 12:05:47 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
// RequiresPadding returns true for DoT and false for TCP
|
|
|
|
// according to RFC8467.
|
2022-05-14 17:38:31 +02:00
|
|
|
func (t *DNSOverTCPTransport) RequiresPadding() bool {
|
2021-02-02 12:05:47 +01:00
|
|
|
return t.requiresPadding
|
|
|
|
}
|
|
|
|
|
2021-09-29 20:21:25 +02:00
|
|
|
// Network returns the transport network, i.e., "dot" or "tcp".
|
2022-05-14 17:38:31 +02:00
|
|
|
func (t *DNSOverTCPTransport) Network() string {
|
2021-02-02 12:05:47 +01:00
|
|
|
return t.network
|
|
|
|
}
|
|
|
|
|
2021-09-29 20:21:25 +02:00
|
|
|
// Address returns the upstream server endpoint (e.g., "1.1.1.1:853").
|
2022-05-14 17:38:31 +02:00
|
|
|
func (t *DNSOverTCPTransport) Address() string {
|
2021-02-02 12:05:47 +01:00
|
|
|
return t.address
|
|
|
|
}
|
|
|
|
|
2021-09-29 20:21:25 +02:00
|
|
|
// CloseIdleConnections closes idle connections, if any.
|
2022-05-14 17:38:31 +02:00
|
|
|
func (t *DNSOverTCPTransport) CloseIdleConnections() {
|
2021-09-09 20:49:12 +02:00
|
|
|
// nothing to do
|
|
|
|
}
|
|
|
|
|
2022-05-14 17:38:31 +02:00
|
|
|
var _ model.DNSTransport = &DNSOverTCPTransport{}
|