Home | History | Annotate | Line # | Download | only in util
      1 /*
      2  * util/fptr_wlist.c - function pointer whitelists.
      3  *
      4  * Copyright (c) 2007, NLnet Labs. All rights reserved.
      5  *
      6  * This software is open source.
      7  *
      8  * Redistribution and use in source and binary forms, with or without
      9  * modification, are permitted provided that the following conditions
     10  * are met:
     11  *
     12  * Redistributions of source code must retain the above copyright notice,
     13  * this list of conditions and the following disclaimer.
     14  *
     15  * Redistributions in binary form must reproduce the above copyright notice,
     16  * this list of conditions and the following disclaimer in the documentation
     17  * and/or other materials provided with the distribution.
     18  *
     19  * Neither the name of the NLNET LABS nor the names of its contributors may
     20  * be used to endorse or promote products derived from this software without
     21  * specific prior written permission.
     22  *
     23  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
     24  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
     25  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
     26  * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
     27  * HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
     28  * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED
     29  * TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
     30  * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
     31  * LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
     32  * NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
     33  * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
     34  */
     35 
     36 /**
     37  * \file
     38  *
     39  * This file contains functions that check function pointers.
     40  * The functions contain a whitelist of known good callback values.
     41  * Any other values lead to an error.
     42  *
     43  * Due to the listing nature, this file violates all the modularization
     44  * boundaries in the program.
     45  */
     46 #include "config.h"
     47 #include "util/fptr_wlist.h"
     48 #include "util/mini_event.h"
     49 #include "services/outside_network.h"
     50 #include "services/listen_dnsport.h"
     51 #include "services/mesh.h"
     52 #include "services/localzone.h"
     53 #include "services/authzone.h"
     54 #include "services/cache/infra.h"
     55 #include "services/cache/rrset.h"
     56 #include "services/view.h"
     57 #include "dns64/dns64.h"
     58 #include "iterator/iterator.h"
     59 #include "iterator/iter_fwd.h"
     60 #include "validator/validator.h"
     61 #include "validator/val_anchor.h"
     62 #include "validator/val_nsec3.h"
     63 #include "validator/val_sigcrypt.h"
     64 #include "validator/val_kentry.h"
     65 #include "validator/val_neg.h"
     66 #include "validator/autotrust.h"
     67 #include "util/data/msgreply.h"
     68 #include "util/data/packed_rrset.h"
     69 #include "util/storage/slabhash.h"
     70 #include "util/storage/dnstree.h"
     71 #include "util/locks.h"
     72 #include "libunbound/libworker.h"
     73 #include "libunbound/context.h"
     74 #include "libunbound/worker.h"
     75 #include "util/tube.h"
     76 #include "util/config_file.h"
     77 #include "daemon/remote.h"
     78 #ifdef UB_ON_WINDOWS
     79 #include "winrc/win_svc.h"
     80 #endif
     81 #include "respip/respip.h"
     82 
     83 #ifdef WITH_PYTHONMODULE
     84 #include "pythonmod/pythonmod.h"
     85 #endif
     86 #ifdef WITH_DYNLIBMODULE
     87 #include "dynlibmod/dynlibmod.h"
     88 #endif
     89 #ifdef USE_CACHEDB
     90 #include "cachedb/cachedb.h"
     91 #endif
     92 #ifdef USE_IPSECMOD
     93 #include "ipsecmod/ipsecmod.h"
     94 #endif
     95 #ifdef CLIENT_SUBNET
     96 #include "edns-subnet/subnetmod.h"
     97 #endif
     98 #ifdef USE_IPSET
     99 #include "ipset/ipset.h"
    100 #endif
    101 #ifdef USE_DNSTAP
    102 #include "dnstap/dtstream.h"
    103 #endif
    104 
    105 int
    106 fptr_whitelist_comm_point(comm_point_callback_type *fptr)
    107 {
    108 	if(fptr == &worker_handle_request) return 1;
    109 	else if(fptr == &outnet_udp_cb) return 1;
    110 	else if(fptr == &outnet_tcp_cb) return 1;
    111 	else if(fptr == &tube_handle_listen) return 1;
    112 	else if(fptr == &auth_xfer_probe_udp_callback) return 1;
    113 	else if(fptr == &auth_xfer_transfer_tcp_callback) return 1;
    114 	else if(fptr == &auth_xfer_transfer_http_callback) return 1;
    115 	return 0;
    116 }
    117 
    118 int
    119 fptr_whitelist_comm_point_raw(comm_point_callback_type *fptr)
    120 {
    121 	if(fptr == &tube_handle_listen) return 1;
    122 	else if(fptr == &tube_handle_write) return 1;
    123 	else if(fptr == &remote_accept_callback) return 1;
    124 	else if(fptr == &remote_control_callback) return 1;
    125 	else if(fptr == &fast_reload_client_callback) return 1;
    126 	return 0;
    127 }
    128 
    129 int
    130 fptr_whitelist_comm_timer(void (*fptr)(void*))
    131 {
    132 	if(fptr == &pending_udp_timer_cb) return 1;
    133 	else if(fptr == &outnet_tcptimer) return 1;
    134 	else if(fptr == &pending_udp_timer_delay_cb) return 1;
    135 	else if(fptr == &worker_stat_timer_cb) return 1;
    136 	else if(fptr == &worker_probe_timer_cb) return 1;
    137 	else if(fptr == &validate_suspend_timer_cb) return 1;
    138 #ifdef HAVE_NGTCP2
    139 	else if(fptr == &doq_timer_cb) return 1;
    140 #endif
    141 #ifdef UB_ON_WINDOWS
    142 	else if(fptr == &wsvc_cron_cb) return 1;
    143 #endif
    144 	else if(fptr == &tcp_read_again_cb) return 1;
    145 	else if(fptr == &tcp_more_read_again_cb) return 1;
    146 	else if(fptr == &auth_xfer_timer) return 1;
    147 	else if(fptr == &auth_xfer_probe_timer_callback) return 1;
    148 	else if(fptr == &auth_xfer_transfer_timer_callback) return 1;
    149 	else if(fptr == &mesh_serve_expired_callback) return 1;
    150 	else if(fptr == &serviced_timer_cb) return 1;
    151 #ifdef USE_DNSTAP
    152 	else if(fptr == &mq_wakeup_cb) return 1;
    153 #endif
    154 	return 0;
    155 }
    156 
    157 int
    158 fptr_whitelist_comm_signal(void (*fptr)(int, void*))
    159 {
    160 	if(fptr == &worker_sighandler) return 1;
    161 	return 0;
    162 }
    163 
    164 int fptr_whitelist_start_accept(void (*fptr)(void*))
    165 {
    166 	if(fptr == &worker_start_accept) return 1;
    167 	return 0;
    168 }
    169 
    170 int fptr_whitelist_stop_accept(void (*fptr)(void*))
    171 {
    172 	if(fptr == &worker_stop_accept) return 1;
    173 	return 0;
    174 }
    175 
    176 int
    177 fptr_whitelist_event(void (*fptr)(int, short, void *))
    178 {
    179 	if(fptr == &comm_point_udp_callback) return 1;
    180 #if defined(AF_INET6) && defined(IPV6_PKTINFO) && defined(HAVE_RECVMSG)
    181 	else if(fptr == &comm_point_udp_ancil_callback) return 1;
    182 #endif
    183 	else if(fptr == &comm_point_tcp_accept_callback) return 1;
    184 	else if(fptr == &comm_point_tcp_handle_callback) return 1;
    185 	else if(fptr == &comm_timer_callback) return 1;
    186 	else if(fptr == &comm_signal_callback) return 1;
    187 	else if(fptr == &comm_point_local_handle_callback) return 1;
    188 	else if(fptr == &comm_point_raw_handle_callback) return 1;
    189 	else if(fptr == &tube_handle_signal) return 1;
    190 	else if(fptr == &comm_base_handle_slow_accept) return 1;
    191 	else if(fptr == &comm_point_http_handle_callback) return 1;
    192 #ifdef HAVE_NGTCP2
    193 	else if(fptr == &comm_point_doq_callback) return 1;
    194 #endif
    195 	else if(fptr == &fast_reload_service_cb) return 1;
    196 #ifdef USE_DNSTAP
    197 	else if(fptr == &dtio_output_cb) return 1;
    198 	else if(fptr == &dtio_cmd_cb) return 1;
    199 	else if(fptr == &dtio_reconnect_timeout_cb) return 1;
    200 	else if(fptr == &dtio_stop_timer_cb) return 1;
    201 	else if(fptr == &dtio_stop_ev_cb) return 1;
    202 	else if(fptr == &dtio_tap_callback) return 1;
    203 	else if(fptr == &dtio_mainfdcallback) return 1;
    204 #endif
    205 #ifdef HAVE_NGTCP2
    206 	else if(fptr == &doq_client_event_cb) return 1;
    207 	else if(fptr == &doq_client_timer_cb) return 1;
    208 #endif
    209 #ifdef UB_ON_WINDOWS
    210 	else if(fptr == &worker_win_stop_cb) return 1;
    211 #endif
    212 	return 0;
    213 }
    214 
    215 int
    216 fptr_whitelist_pending_udp(comm_point_callback_type *fptr)
    217 {
    218 	if(fptr == &serviced_udp_callback) return 1;
    219 	return 0;
    220 }
    221 
    222 int
    223 fptr_whitelist_pending_tcp(comm_point_callback_type *fptr)
    224 {
    225 	if(fptr == &serviced_tcp_callback) return 1;
    226 	return 0;
    227 }
    228 
    229 int
    230 fptr_whitelist_serviced_query(comm_point_callback_type *fptr)
    231 {
    232 	if(fptr == &worker_handle_service_reply) return 1;
    233 	else if(fptr == &libworker_handle_service_reply) return 1;
    234 	return 0;
    235 }
    236 
    237 int
    238 fptr_whitelist_rbtree_cmp(int (*fptr) (const void *, const void *))
    239 {
    240 	if(fptr == &mesh_state_compare) return 1;
    241 	else if(fptr == &mesh_state_ref_compare) return 1;
    242 	else if(fptr == &addr_tree_compare) return 1;
    243 	else if(fptr == &addr_tree_addrport_compare) return 1;
    244 	else if(fptr == &local_zone_cmp) return 1;
    245 	else if(fptr == &local_data_cmp) return 1;
    246 	else if(fptr == &fwd_cmp) return 1;
    247 	else if(fptr == &pending_cmp) return 1;
    248 	else if(fptr == &serviced_cmp) return 1;
    249 	else if(fptr == &reuse_cmp) return 1;
    250 	else if(fptr == &reuse_id_cmp) return 1;
    251 	else if(fptr == &name_tree_compare) return 1;
    252 	else if(fptr == &order_lock_cmp) return 1;
    253 	else if(fptr == &codeline_cmp) return 1;
    254 	else if(fptr == &nsec3_hash_cmp) return 1;
    255 	else if(fptr == &mini_ev_cmp) return 1;
    256 	else if(fptr == &anchor_cmp) return 1;
    257 	else if(fptr == &canonical_tree_compare) return 1;
    258 	else if(fptr == &context_query_cmp) return 1;
    259 	else if(fptr == &val_neg_data_compare) return 1;
    260 	else if(fptr == &val_neg_zone_compare) return 1;
    261 	else if(fptr == &probetree_cmp) return 1;
    262 	else if(fptr == &replay_var_compare) return 1;
    263 	else if(fptr == &view_cmp) return 1;
    264 	else if(fptr == &auth_zone_cmp) return 1;
    265 	else if(fptr == &auth_data_cmp) return 1;
    266 	else if(fptr == &auth_xfer_cmp) return 1;
    267 #ifdef HAVE_NGTCP2
    268 	else if(fptr == &doq_conn_cmp) return 1;
    269 	else if(fptr == &doq_conid_cmp) return 1;
    270 	else if(fptr == &doq_timer_cmp) return 1;
    271 	else if(fptr == &doq_stream_cmp) return 1;
    272 #endif
    273 	return 0;
    274 }
    275 
    276 int
    277 fptr_whitelist_hash_sizefunc(lruhash_sizefunc_type fptr)
    278 {
    279 	if(fptr == &msgreply_sizefunc) return 1;
    280 	else if(fptr == &ub_rrset_sizefunc) return 1;
    281 	else if(fptr == &infra_sizefunc) return 1;
    282 	else if(fptr == &key_entry_sizefunc) return 1;
    283 	else if(fptr == &rate_sizefunc) return 1;
    284 	else if(fptr == &ip_rate_sizefunc) return 1;
    285 	else if(fptr == &test_slabhash_sizefunc) return 1;
    286 #ifdef CLIENT_SUBNET
    287 	else if(fptr == &msg_cache_sizefunc) return 1;
    288 #endif
    289 #ifdef USE_DNSCRYPT
    290 	else if(fptr == &dnsc_shared_secrets_sizefunc) return 1;
    291 	else if(fptr == &dnsc_nonces_sizefunc) return 1;
    292 #endif
    293 	return 0;
    294 }
    295 
    296 int
    297 fptr_whitelist_hash_compfunc(lruhash_compfunc_type fptr)
    298 {
    299 	if(fptr == &query_info_compare) return 1;
    300 	else if(fptr == &ub_rrset_compare) return 1;
    301 	else if(fptr == &infra_compfunc) return 1;
    302 	else if(fptr == &key_entry_compfunc) return 1;
    303 	else if(fptr == &rate_compfunc) return 1;
    304 	else if(fptr == &ip_rate_compfunc) return 1;
    305 	else if(fptr == &test_slabhash_compfunc) return 1;
    306 #ifdef USE_DNSCRYPT
    307 	else if(fptr == &dnsc_shared_secrets_compfunc) return 1;
    308 	else if(fptr == &dnsc_nonces_compfunc) return 1;
    309 #endif
    310 	return 0;
    311 }
    312 
    313 int
    314 fptr_whitelist_hash_delkeyfunc(lruhash_delkeyfunc_type fptr)
    315 {
    316 	if(fptr == &query_entry_delete) return 1;
    317 	else if(fptr == &ub_rrset_key_delete) return 1;
    318 	else if(fptr == &infra_delkeyfunc) return 1;
    319 	else if(fptr == &key_entry_delkeyfunc) return 1;
    320 	else if(fptr == &rate_delkeyfunc) return 1;
    321 	else if(fptr == &ip_rate_delkeyfunc) return 1;
    322 	else if(fptr == &test_slabhash_delkey) return 1;
    323 #ifdef USE_DNSCRYPT
    324 	else if(fptr == &dnsc_shared_secrets_delkeyfunc) return 1;
    325 	else if(fptr == &dnsc_nonces_delkeyfunc) return 1;
    326 #endif
    327 	return 0;
    328 }
    329 
    330 int
    331 fptr_whitelist_hash_deldatafunc(lruhash_deldatafunc_type fptr)
    332 {
    333 	if(fptr == &reply_info_delete) return 1;
    334 	else if(fptr == &rrset_data_delete) return 1;
    335 	else if(fptr == &infra_deldatafunc) return 1;
    336 	else if(fptr == &key_entry_deldatafunc) return 1;
    337 	else if(fptr == &rate_deldatafunc) return 1;
    338 	else if(fptr == &test_slabhash_deldata) return 1;
    339 #ifdef CLIENT_SUBNET
    340 	else if(fptr == &subnet_data_delete) return 1;
    341 #endif
    342 #ifdef USE_DNSCRYPT
    343 	else if(fptr == &dnsc_shared_secrets_deldatafunc) return 1;
    344 	else if(fptr == &dnsc_nonces_deldatafunc) return 1;
    345 #endif
    346 	return 0;
    347 }
    348 
    349 int
    350 fptr_whitelist_hash_markdelfunc(lruhash_markdelfunc_type fptr)
    351 {
    352 	if(fptr == NULL) return 1;
    353 	else if(fptr == &rrset_markdel) return 1;
    354 #ifdef CLIENT_SUBNET
    355 	else if(fptr == &subnet_markdel) return 1;
    356 #endif
    357 	return 0;
    358 }
    359 
    360 /** whitelist env->send_query callbacks */
    361 int
    362 fptr_whitelist_modenv_send_query(struct outbound_entry* (*fptr)(
    363 	struct query_info* qinfo, uint16_t flags, int dnssec, int want_dnssec,
    364 	int nocaps, int check_ratelimit, struct sockaddr_storage* addr,
    365 	socklen_t addrlen, uint8_t* zone, size_t zonelen, int tcp_upstream,
    366 	int ssl_upstream, char* tls_auth_name, struct module_qstate* q,
    367 	int* was_ratelimited, int* ratelimit_incremented))
    368 {
    369 	if(fptr == &worker_send_query) return 1;
    370 	else if(fptr == &libworker_send_query) return 1;
    371 	return 0;
    372 }
    373 
    374 int
    375 fptr_whitelist_modenv_detach_subs(void (*fptr)(
    376         struct module_qstate* qstate))
    377 {
    378 	if(fptr == &mesh_detach_subs) return 1;
    379 	return 0;
    380 }
    381 
    382 int
    383 fptr_whitelist_modenv_attach_sub(int (*fptr)(
    384         struct module_qstate* qstate, struct query_info* qinfo,
    385 	struct respip_client_info* cinfo, uint16_t qflags, int prime,
    386 	int valrec, struct module_qstate** newq))
    387 {
    388 	if(fptr == &mesh_attach_sub) return 1;
    389 	return 0;
    390 }
    391 
    392 int
    393 fptr_whitelist_modenv_add_sub(int (*fptr)(
    394         struct module_qstate* qstate, struct query_info* qinfo,
    395 	struct respip_client_info* cinfo, uint16_t qflags, int prime,
    396 	int valrec, struct module_qstate** newq, struct mesh_state** sub))
    397 {
    398 	if(fptr == &mesh_add_sub) return 1;
    399 	return 0;
    400 }
    401 
    402 int
    403 fptr_whitelist_modenv_kill_sub(void (*fptr)(struct module_qstate* newq))
    404 {
    405 	if(fptr == &mesh_state_delete) return 1;
    406 	return 0;
    407 }
    408 
    409 int
    410 fptr_whitelist_modenv_detect_cycle(int (*fptr)(
    411 	struct module_qstate* qstate, struct query_info* qinfo,
    412 	uint16_t flags, int prime, int valrec))
    413 {
    414 	if(fptr == &mesh_detect_cycle) return 1;
    415 	return 0;
    416 }
    417 
    418 int
    419 fptr_whitelist_mod_init(int (*fptr)(struct module_env* env, int id))
    420 {
    421 	if(fptr == &iter_init) return 1;
    422 	else if(fptr == &val_init) return 1;
    423 	else if(fptr == &dns64_init) return 1;
    424 	else if(fptr == &respip_init) return 1;
    425 #ifdef WITH_PYTHONMODULE
    426 	else if(fptr == &pythonmod_init) return 1;
    427 #endif
    428 #ifdef WITH_DYNLIBMODULE
    429 	else if(fptr == &dynlibmod_init) return 1;
    430 #endif
    431 #ifdef USE_CACHEDB
    432 	else if(fptr == &cachedb_init) return 1;
    433 #endif
    434 #ifdef USE_IPSECMOD
    435 	else if(fptr == &ipsecmod_init) return 1;
    436 #endif
    437 #ifdef CLIENT_SUBNET
    438 	else if(fptr == &subnetmod_init) return 1;
    439 #endif
    440 #ifdef USE_IPSET
    441 	else if(fptr == &ipset_init) return 1;
    442 #endif
    443 	return 0;
    444 }
    445 
    446 int
    447 fptr_whitelist_mod_deinit(void (*fptr)(struct module_env* env, int id))
    448 {
    449 	if(fptr == &iter_deinit) return 1;
    450 	else if(fptr == &val_deinit) return 1;
    451 	else if(fptr == &dns64_deinit) return 1;
    452 	else if(fptr == &respip_deinit) return 1;
    453 #ifdef WITH_PYTHONMODULE
    454 	else if(fptr == &pythonmod_deinit) return 1;
    455 #endif
    456 #ifdef WITH_DYNLIBMODULE
    457 	else if(fptr == &dynlibmod_deinit) return 1;
    458 #endif
    459 #ifdef USE_CACHEDB
    460 	else if(fptr == &cachedb_deinit) return 1;
    461 #endif
    462 #ifdef USE_IPSECMOD
    463 	else if(fptr == &ipsecmod_deinit) return 1;
    464 #endif
    465 #ifdef CLIENT_SUBNET
    466 	else if(fptr == &subnetmod_deinit) return 1;
    467 #endif
    468 #ifdef USE_IPSET
    469 	else if(fptr == &ipset_deinit) return 1;
    470 #endif
    471 	return 0;
    472 }
    473 
    474 int
    475 fptr_whitelist_mod_startup(int (*fptr)(struct module_env* env, int id))
    476 {
    477 #ifdef USE_IPSET
    478 	if(fptr == &ipset_startup) return 1;
    479 #else
    480 	(void)fptr;
    481 #endif
    482 	return 0;
    483 }
    484 
    485 int
    486 fptr_whitelist_mod_destartup(void (*fptr)(struct module_env* env, int id))
    487 {
    488 #ifdef USE_IPSET
    489 	if(fptr == &ipset_destartup) return 1;
    490 #else
    491 	(void)fptr;
    492 #endif
    493 	return 0;
    494 }
    495 
    496 int
    497 fptr_whitelist_mod_operate(void (*fptr)(struct module_qstate* qstate,
    498         enum module_ev event, int id, struct outbound_entry* outbound))
    499 {
    500 	if(fptr == &iter_operate) return 1;
    501 	else if(fptr == &val_operate) return 1;
    502 	else if(fptr == &dns64_operate) return 1;
    503 	else if(fptr == &respip_operate) return 1;
    504 #ifdef WITH_PYTHONMODULE
    505 	else if(fptr == &pythonmod_operate) return 1;
    506 #endif
    507 #ifdef WITH_DYNLIBMODULE
    508 	else if(fptr == &dynlibmod_operate) return 1;
    509 #endif
    510 #ifdef USE_CACHEDB
    511 	else if(fptr == &cachedb_operate) return 1;
    512 #endif
    513 #ifdef USE_IPSECMOD
    514 	else if(fptr == &ipsecmod_operate) return 1;
    515 #endif
    516 #ifdef CLIENT_SUBNET
    517 	else if(fptr == &subnetmod_operate) return 1;
    518 #endif
    519 #ifdef USE_IPSET
    520 	else if(fptr == &ipset_operate) return 1;
    521 #endif
    522 	return 0;
    523 }
    524 
    525 int
    526 fptr_whitelist_mod_inform_super(void (*fptr)(
    527         struct module_qstate* qstate, int id, struct module_qstate* super))
    528 {
    529 	if(fptr == &iter_inform_super) return 1;
    530 	else if(fptr == &val_inform_super) return 1;
    531 	else if(fptr == &dns64_inform_super) return 1;
    532 	else if(fptr == &respip_inform_super) return 1;
    533 #ifdef WITH_PYTHONMODULE
    534 	else if(fptr == &pythonmod_inform_super) return 1;
    535 #endif
    536 #ifdef WITH_DYNLIBMODULE
    537 	else if(fptr == &dynlibmod_inform_super) return 1;
    538 #endif
    539 #ifdef USE_CACHEDB
    540 	else if(fptr == &cachedb_inform_super) return 1;
    541 #endif
    542 #ifdef USE_IPSECMOD
    543 	else if(fptr == &ipsecmod_inform_super) return 1;
    544 #endif
    545 #ifdef CLIENT_SUBNET
    546 	else if(fptr == &subnetmod_inform_super) return 1;
    547 #endif
    548 #ifdef USE_IPSET
    549 	else if(fptr == &ipset_inform_super) return 1;
    550 #endif
    551 	return 0;
    552 }
    553 
    554 int
    555 fptr_whitelist_mod_clear(void (*fptr)(struct module_qstate* qstate,
    556         int id))
    557 {
    558 	if(fptr == &iter_clear) return 1;
    559 	else if(fptr == &val_clear) return 1;
    560 	else if(fptr == &dns64_clear) return 1;
    561 	else if(fptr == &respip_clear) return 1;
    562 #ifdef WITH_PYTHONMODULE
    563 	else if(fptr == &pythonmod_clear) return 1;
    564 #endif
    565 #ifdef WITH_DYNLIBMODULE
    566 	else if(fptr == &dynlibmod_clear) return 1;
    567 #endif
    568 #ifdef USE_CACHEDB
    569 	else if(fptr == &cachedb_clear) return 1;
    570 #endif
    571 #ifdef USE_IPSECMOD
    572 	else if(fptr == &ipsecmod_clear) return 1;
    573 #endif
    574 #ifdef CLIENT_SUBNET
    575 	else if(fptr == &subnetmod_clear) return 1;
    576 #endif
    577 #ifdef USE_IPSET
    578 	else if(fptr == &ipset_clear) return 1;
    579 #endif
    580 	return 0;
    581 }
    582 
    583 int
    584 fptr_whitelist_mod_get_mem(size_t (*fptr)(struct module_env* env, int id))
    585 {
    586 	if(fptr == &iter_get_mem) return 1;
    587 	else if(fptr == &val_get_mem) return 1;
    588 	else if(fptr == &dns64_get_mem) return 1;
    589 	else if(fptr == &respip_get_mem) return 1;
    590 #ifdef WITH_PYTHONMODULE
    591 	else if(fptr == &pythonmod_get_mem) return 1;
    592 #endif
    593 #ifdef WITH_DYNLIBMODULE
    594 	else if(fptr == &dynlibmod_get_mem) return 1;
    595 #endif
    596 #ifdef USE_CACHEDB
    597 	else if(fptr == &cachedb_get_mem) return 1;
    598 #endif
    599 #ifdef USE_IPSECMOD
    600 	else if(fptr == &ipsecmod_get_mem) return 1;
    601 #endif
    602 #ifdef CLIENT_SUBNET
    603 	else if(fptr == &subnetmod_get_mem) return 1;
    604 #endif
    605 #ifdef USE_IPSET
    606 	else if(fptr == &ipset_get_mem) return 1;
    607 #endif
    608 	return 0;
    609 }
    610 
    611 int
    612 fptr_whitelist_alloc_cleanup(void (*fptr)(void*))
    613 {
    614 	if(fptr == &worker_alloc_cleanup) return 1;
    615 	else if(fptr == &libworker_alloc_cleanup) return 1;
    616 	return 0;
    617 }
    618 
    619 int fptr_whitelist_tube_listen(tube_callback_type* fptr)
    620 {
    621 	if(fptr == &worker_handle_control_cmd) return 1;
    622 	else if(fptr == &libworker_handle_control_cmd) return 1;
    623 	return 0;
    624 }
    625 
    626 int fptr_whitelist_mesh_cb(mesh_cb_func_type fptr)
    627 {
    628 	if(fptr == &libworker_fg_done_cb) return 1;
    629 	else if(fptr == &libworker_bg_done_cb) return 1;
    630 	else if(fptr == &libworker_event_done_cb) return 1;
    631 	else if(fptr == &probe_answer_cb) return 1;
    632 	else if(fptr == &auth_xfer_probe_lookup_callback) return 1;
    633 	else if(fptr == &auth_xfer_transfer_lookup_callback) return 1;
    634 	else if(fptr == &auth_zonemd_dnskey_lookup_callback) return 1;
    635 	return 0;
    636 }
    637 
    638 int fptr_whitelist_print_func(void (*fptr)(char*,void*))
    639 {
    640 	if(fptr == &config_print_func) return 1;
    641 	else if(fptr == &config_collate_func) return 1;
    642 	else if(fptr == &remote_get_opt_ssl) return 1;
    643 	return 0;
    644 }
    645 
    646 int fptr_whitelist_inplace_cb_reply_generic(inplace_cb_reply_func_type* fptr,
    647 	enum inplace_cb_list_type type)
    648 {
    649 #ifndef WITH_PYTHONMODULE
    650 	(void)fptr;
    651 #endif
    652 	if(type == inplace_cb_reply) {
    653 #ifdef WITH_PYTHONMODULE
    654 		if(fptr == &python_inplace_cb_reply_generic) return 1;
    655 #endif
    656 #ifdef WITH_DYNLIBMODULE
    657 		if(fptr == &dynlib_inplace_cb_reply_generic) return 1;
    658 #endif
    659 	} else if(type == inplace_cb_reply_cache) {
    660 #ifdef WITH_PYTHONMODULE
    661 		if(fptr == &python_inplace_cb_reply_generic) return 1;
    662 #endif
    663 #ifdef WITH_DYNLIBMODULE
    664 		if(fptr == &dynlib_inplace_cb_reply_generic) return 1;
    665 #endif
    666 	} else if(type == inplace_cb_reply_local) {
    667 #ifdef WITH_PYTHONMODULE
    668 		if(fptr == &python_inplace_cb_reply_generic) return 1;
    669 #endif
    670 #ifdef WITH_DYNLIBMODULE
    671 		if(fptr == &dynlib_inplace_cb_reply_generic) return 1;
    672 #endif
    673 	} else if(type == inplace_cb_reply_servfail) {
    674 #ifdef WITH_PYTHONMODULE
    675 		if(fptr == &python_inplace_cb_reply_generic) return 1;
    676 #endif
    677 #ifdef WITH_DYNLIBMODULE
    678 		if(fptr == &dynlib_inplace_cb_reply_generic) return 1;
    679 #endif
    680 	}
    681 	return 0;
    682 }
    683 
    684 int fptr_whitelist_inplace_cb_query(inplace_cb_query_func_type* fptr)
    685 {
    686 #ifdef CLIENT_SUBNET
    687 	if(fptr == &ecs_whitelist_check)
    688 		return 1;
    689 #endif
    690 #ifdef WITH_PYTHONMODULE
    691         if(fptr == &python_inplace_cb_query_generic)
    692                 return 1;
    693 #endif
    694 #ifdef WITH_DYNLIBMODULE
    695         if(fptr == &dynlib_inplace_cb_query_generic)
    696                 return 1;
    697 #endif
    698 	(void)fptr;
    699 	return 0;
    700 }
    701 
    702 int fptr_whitelist_inplace_cb_edns_back_parsed(
    703 	inplace_cb_edns_back_parsed_func_type* fptr)
    704 {
    705 #ifdef CLIENT_SUBNET
    706 	if(fptr == &ecs_edns_back_parsed)
    707 		return 1;
    708 #else
    709 	(void)fptr;
    710 #endif
    711 #ifdef WITH_PYTHONMODULE
    712     if(fptr == &python_inplace_cb_edns_back_parsed_call)
    713         return 1;
    714 #endif
    715 #ifdef WITH_DYNLIBMODULE
    716     if(fptr == &dynlib_inplace_cb_edns_back_parsed)
    717             return 1;
    718 #endif
    719 	return 0;
    720 }
    721 
    722 int fptr_whitelist_inplace_cb_query_response(
    723 	inplace_cb_query_response_func_type* fptr)
    724 {
    725 #ifdef CLIENT_SUBNET
    726 	if(fptr == &ecs_query_response)
    727 		return 1;
    728 #else
    729 	(void)fptr;
    730 #endif
    731 #ifdef WITH_PYTHONMODULE
    732     if(fptr == &python_inplace_cb_query_response)
    733         return 1;
    734 #endif
    735 #ifdef WITH_DYNLIBMODULE
    736     if(fptr == &dynlib_inplace_cb_query_response)
    737             return 1;
    738 #endif
    739 	return 0;
    740 }
    741 
    742 int fptr_whitelist_serve_expired_lookup(serve_expired_lookup_func_type* fptr)
    743 {
    744 	if(fptr == &mesh_serve_expired_lookup)
    745 		return 1;
    746 	return 0;
    747 }
    748