Home | History | Annotate | Line # | Download | only in services
      1 /*
      2  * services/listen_dnsport.h - listen on port 53 for incoming DNS queries.
      3  *
      4  * Copyright (c) 2007, NLnet Labs. All rights reserved.
      5  *
      6  * This software is open source.
      7  *
      8  * Redistribution and use in source and binary forms, with or without
      9  * modification, are permitted provided that the following conditions
     10  * are met:
     11  *
     12  * Redistributions of source code must retain the above copyright notice,
     13  * this list of conditions and the following disclaimer.
     14  *
     15  * Redistributions in binary form must reproduce the above copyright notice,
     16  * this list of conditions and the following disclaimer in the documentation
     17  * and/or other materials provided with the distribution.
     18  *
     19  * Neither the name of the NLNET LABS nor the names of its contributors may
     20  * be used to endorse or promote products derived from this software without
     21  * specific prior written permission.
     22  *
     23  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
     24  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
     25  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
     26  * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
     27  * HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
     28  * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED
     29  * TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
     30  * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
     31  * LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
     32  * NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
     33  * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
     34  */
     35 
     36 /**
     37  * \file
     38  *
     39  * This file has functions to get queries from clients.
     40  */
     41 
     42 #ifndef LISTEN_DNSPORT_H
     43 #define LISTEN_DNSPORT_H
     44 
     45 #include "util/netevent.h"
     46 #include "util/rbtree.h"
     47 #include "util/locks.h"
     48 #include "daemon/acl_list.h"
     49 #ifdef HAVE_NGHTTP2_NGHTTP2_H
     50 #include <nghttp2/nghttp2.h>
     51 #endif
     52 #ifdef HAVE_NGTCP2
     53 #include <ngtcp2/ngtcp2.h>
     54 #include <ngtcp2/ngtcp2_crypto.h>
     55 #ifdef USE_NGTCP2_CRYPTO_OSSL
     56 struct ngtcp2_crypto_ossl_ctx;
     57 #endif
     58 #endif
     59 struct listen_list;
     60 struct config_file;
     61 struct addrinfo;
     62 struct sldns_buffer;
     63 struct tcl_list;
     64 struct mesh_area;
     65 struct mesh_state;
     66 
     67 /**
     68  * Listening for queries structure.
     69  * Contains list of query-listen sockets.
     70  */
     71 struct listen_dnsport {
     72 	/** Base for select calls */
     73 	struct comm_base* base;
     74 
     75 	/** buffer shared by UDP connections, since there is only one
     76 	    datagram at any time. */
     77 	struct sldns_buffer* udp_buff;
     78 #ifdef USE_DNSCRYPT
     79 	struct sldns_buffer* dnscrypt_udp_buff;
     80 #endif
     81 	/** list of comm points used to get incoming events */
     82 	struct listen_list* cps;
     83 };
     84 
     85 /**
     86  * Single linked list to store event points.
     87  */
     88 struct listen_list {
     89 	/** next in list */
     90 	struct listen_list* next;
     91 	/** event info */
     92 	struct comm_point* com;
     93 };
     94 
     95 /**
     96  * type of ports
     97  */
     98 enum listen_type {
     99 	/** udp type */
    100 	listen_type_udp,
    101 	/** tcp type */
    102 	listen_type_tcp,
    103 	/** udp ipv6 (v4mapped) for use with ancillary data */
    104 	listen_type_udpancil,
    105 	/** ssl over tcp type */
    106 	listen_type_ssl,
    107 	/** udp type  + dnscrypt*/
    108 	listen_type_udp_dnscrypt,
    109 	/** tcp type + dnscrypt */
    110 	listen_type_tcp_dnscrypt,
    111 	/** udp ipv6 (v4mapped) for use with ancillary data + dnscrypt*/
    112 	listen_type_udpancil_dnscrypt,
    113 	/** HTTP(2) over TLS over TCP */
    114 	listen_type_http,
    115 	/** DNS over QUIC */
    116 	listen_type_doq
    117 };
    118 
    119 /*
    120  * socket properties (just like NSD nsd_socket structure definition)
    121  */
    122 struct unbound_socket {
    123 	/** the address of the socket */
    124 	struct sockaddr* addr;
    125 	/** length of the address */
    126 	socklen_t addrlen;
    127 	/** socket descriptor returned by socket() syscall */
    128 	int s;
    129 	/** address family (AF_INET/AF_INET6) */
    130 	int fam;
    131 	/** ACL on the socket (listening interface) */
    132 	struct acl_addr* acl;
    133 };
    134 
    135 /**
    136  * Single linked list to store shared ports that have been
    137  * opened for use by all threads.
    138  */
    139 struct listen_port {
    140 	/** next in list */
    141 	struct listen_port* next;
    142 	/** file descriptor, open and ready for use */
    143 	int fd;
    144 	/** type of file descriptor, udp or tcp */
    145 	enum listen_type ftype;
    146 	/** if the port should support PROXYv2 */
    147 	int pp2_enabled;
    148 	/** fill in unbound_socket structure for every opened socket at
    149 	 * Unbound startup */
    150 	struct unbound_socket* socket;
    151 };
    152 
    153 /**
    154  * Create shared listening ports
    155  * Getaddrinfo, create socket, bind and listen to zero or more
    156  * interfaces for IP4 and/or IP6, for UDP and/or TCP.
    157  * On the given port number. It creates the sockets.
    158  * @param cfg: settings on what ports to open.
    159  * @param ifs: interfaces to open, array of IP addresses, "ip[@port]".
    160  * @param num_ifs: length of ifs.
    161  * @param reuseport: set to true if you want reuseport, or NULL to not have it,
    162  *   set to false on exit if reuseport failed to apply (because of no
    163  *   kernel support).
    164  * @return: linked list of ports or NULL on error.
    165  */
    166 struct listen_port* listening_ports_open(struct config_file* cfg,
    167 	char** ifs, int num_ifs, int* reuseport);
    168 
    169 /**
    170  * Close and delete the (list of) listening ports.
    171  */
    172 void listening_ports_free(struct listen_port* list);
    173 
    174 struct config_strlist;
    175 /**
    176  * Resolve interface names in config and store result IP addresses
    177  * @param ifs: array of interfaces.  The list of interface names, if not NULL.
    178  * @param num_ifs: length of ifs array.
    179  * @param list: if not NULL, this is used as the list of interface names.
    180  * @param resif: string array (malloced array of malloced strings) with
    181  * 	result.  NULL if cfg has none.
    182  * @param num_resif: length of resif.  Zero if cfg has zero num_ifs.
    183  * @return 0 on failure.
    184  */
    185 int resolve_interface_names(char** ifs, int num_ifs,
    186 	struct config_strlist* list, char*** resif, int* num_resif);
    187 
    188 /**
    189  * Create commpoints with for this thread for the shared ports.
    190  * @param base: the comm_base that provides event functionality.
    191  *	for default all ifs.
    192  * @param ports: the list of shared ports.
    193  * @param bufsize: size of datagram buffer.
    194  * @param tcp_accept_count: max number of simultaneous TCP connections
    195  * 	from clients.
    196  * @param tcp_idle_timeout: idle timeout for TCP connections in msec.
    197  * @param harden_large_queries: whether query size should be limited.
    198  * @param http_max_streams: maximum number of HTTP/2 streams per connection.
    199  * @param http_endpoint: HTTP endpoint to service queries on
    200  * @param http_notls: no TLS for http downstream
    201  * @param tcp_conn_limit: TCP connection limit info.
    202  * @param dot_sslctx: nonNULL if dot ssl context.
    203  * @param doh_sslctx: nonNULL if doh ssl context.
    204  * @param quic_sslctx: nonNULL if quic ssl context.
    205  * @param dtenv: nonNULL if dnstap enabled.
    206  * @param doq_table: the doq connection table, with shared information.
    207  * @param rnd: random state.
    208  * @param cfg: config file struct.
    209  * @param cb: callback function when a request arrives. It is passed
    210  *	  the packet and user argument. Return true to send a reply.
    211  * @param cb_arg: user data argument for callback function.
    212  * @return: the malloced listening structure, ready for use. NULL on error.
    213  */
    214 struct listen_dnsport*
    215 listen_create(struct comm_base* base, struct listen_port* ports,
    216 	size_t bufsize, int tcp_accept_count, int tcp_idle_timeout,
    217 	int harden_large_queries, uint32_t http_max_streams,
    218 	char* http_endpoint, int http_notls, struct tcl_list* tcp_conn_limit,
    219 	void* dot_sslctx, void* doh_sslctx, void* quic_sslctx,
    220 	struct dt_env* dtenv,
    221 	struct doq_table* doq_table,
    222 	struct ub_randstate* rnd,struct config_file* cfg,
    223 	comm_point_callback_type* cb, void *cb_arg);
    224 
    225 /**
    226  * delete the listening structure
    227  * @param listen: listening structure.
    228  */
    229 void listen_delete(struct listen_dnsport* listen);
    230 
    231 /** setup the locks for the listen ports */
    232 void listen_setup_locks(void);
    233 /** desetup the locks for the listen ports */
    234 void listen_desetup_locks(void);
    235 
    236 /**
    237  * delete listen_list of commpoints. Calls commpointdelete() on items.
    238  * This may close the fds or not depending on flags.
    239  * @param list: to delete.
    240  */
    241 void listen_list_delete(struct listen_list* list);
    242 
    243 /**
    244  * get memory size used by the listening structs
    245  * @param listen: listening structure.
    246  * @return: size in bytes.
    247  */
    248 size_t listen_get_mem(struct listen_dnsport* listen);
    249 
    250 /**
    251  * stop accept handlers for TCP (until enabled again)
    252  * @param listen: listening structure.
    253  */
    254 void listen_stop_accept(struct listen_dnsport* listen);
    255 
    256 /**
    257  * start accept handlers for TCP (was stopped before)
    258  * @param listen: listening structure.
    259  */
    260 void listen_start_accept(struct listen_dnsport* listen);
    261 
    262 /**
    263  * Create and bind nonblocking UDP socket
    264  * @param family: for socket call.
    265  * @param socktype: for socket call.
    266  * @param addr: for bind call.
    267  * @param addrlen: for bind call.
    268  * @param v6only: if enabled, IP6 sockets get IP6ONLY option set.
    269  * 	if enabled with value 2 IP6ONLY option is disabled.
    270  * @param inuse: on error, this is set true if the port was in use.
    271  * @param noproto: on error, this is set true if cause is that the
    272 	IPv6 proto (family) is not available.
    273  * @param rcv: set size on rcvbuf with socket option, if 0 it is not set.
    274  * @param snd: set size on sndbuf with socket option, if 0 it is not set.
    275  * @param listen: if true, this is a listening UDP port, eg port 53, and
    276  * 	set SO_REUSEADDR on it.
    277  * @param reuseport: if nonNULL and true, try to set SO_REUSEPORT on
    278  * 	listening UDP port.  Set to false on return if it failed to do so.
    279  * @param transparent: set IP_TRANSPARENT socket option.
    280  * @param freebind: set IP_FREEBIND socket option.
    281  * @param use_systemd: if true, fetch sockets from systemd.
    282  * @param dscp: DSCP to use.
    283  * @return: the socket. -1 on error.
    284  */
    285 int create_udp_sock(int family, int socktype, struct sockaddr* addr,
    286 	socklen_t addrlen, int v6only, int* inuse, int* noproto, int rcv,
    287 	int snd, int listen, int* reuseport, int transparent, int freebind, int use_systemd, int dscp);
    288 
    289 /**
    290  * Create and bind TCP listening socket
    291  * @param addr: address info ready to make socket.
    292  * @param v6only: enable ip6 only flag on ip6 sockets.
    293  * @param noproto: if error caused by lack of protocol support.
    294  * @param reuseport: if nonNULL and true, try to set SO_REUSEPORT on
    295  * 	listening UDP port.  Set to false on return if it failed to do so.
    296  * @param transparent: set IP_TRANSPARENT socket option.
    297  * @param mss: maximum segment size of the socket. if zero, leaves the default.
    298  * @param nodelay: if true set TCP_NODELAY and TCP_QUICKACK socket options.
    299  * @param freebind: set IP_FREEBIND socket option.
    300  * @param use_systemd: if true, fetch sockets from systemd.
    301  * @param dscp: DSCP to use.
    302  * @param additional: additional log information for the socket type.
    303  * @return: the socket. -1 on error.
    304  */
    305 int create_tcp_accept_sock(struct addrinfo *addr, int v6only, int* noproto,
    306 	int* reuseport, int transparent, int mss, int nodelay, int freebind,
    307 	int use_systemd, int dscp, const char* additional);
    308 
    309 /**
    310  * Create and bind local listening socket
    311  * @param path: path to the socket.
    312  * @param noproto: on error, this is set true if cause is that local sockets
    313  *	are not supported.
    314  * @param use_systemd: if true, fetch sockets from systemd.
    315  * @return: the socket. -1 on error.
    316  */
    317 int create_local_accept_sock(const char* path, int* noproto, int use_systemd);
    318 
    319 /**
    320  * TCP request info.  List of requests outstanding on the channel, that
    321  * are asked for but not yet answered back.
    322  */
    323 struct tcp_req_info {
    324 	/** the TCP comm point for this.  Its buffer is used for read/write */
    325 	struct comm_point* cp;
    326 	/** the buffer to use to spool reply from mesh into,
    327 	 * it can then be copied to the result list and written.
    328 	 * it is a pointer to the shared udp buffer. */
    329 	struct sldns_buffer* spool_buffer;
    330 	/** are we in worker_handle function call (for recursion callback)*/
    331 	int in_worker_handle;
    332 	/** is the comm point dropped (by worker handle).
    333 	 * That means we have to disconnect the channel. */
    334 	int is_drop;
    335 	/** is the comm point set to send_reply (by mesh new client in worker
    336 	 * handle), if so answer is available in c.buffer */
    337 	int is_reply;
    338 	/** read channel has closed, just write pending results */
    339 	int read_is_closed;
    340 	/** read again */
    341 	int read_again;
    342 	/** number of outstanding requests */
    343 	int num_open_req;
    344 	/** list of outstanding requests */
    345 	struct tcp_req_open_item* open_req_list;
    346 	/** number of pending writeable results */
    347 	int num_done_req;
    348 	/** list of pending writable result packets, malloced one at a time */
    349 	struct tcp_req_done_item* done_req_list;
    350 	/** the read again timer, when the number of pipelined TCP queries
    351 	 * is large, it waits, zero time, for a new event loop to service
    352 	 * the remainder of the TCP traffic on the fd. */
    353 	struct comm_timer* read_again_timer;
    354 };
    355 
    356 /**
    357  * List of open items in TCP channel
    358  */
    359 struct tcp_req_open_item {
    360 	/** next in list */
    361 	struct tcp_req_open_item* next;
    362 	/** the mesh area of the mesh_state */
    363 	struct mesh_area* mesh;
    364 	/** the mesh state */
    365 	struct mesh_state* mesh_state;
    366 };
    367 
    368 /**
    369  * List of done items in TCP channel
    370  */
    371 struct tcp_req_done_item {
    372 	/** next in list */
    373 	struct tcp_req_done_item* next;
    374 	/** the buffer with packet contents */
    375 	uint8_t* buf;
    376 	/** length of the buffer */
    377 	size_t len;
    378 };
    379 
    380 /**
    381  * Create tcp request info structure that keeps track of open
    382  * requests on the TCP channel that are resolved at the same time,
    383  * and the pending results that have to get written back to that client.
    384  * @param base: comm base for read again timer.
    385  * @param spoolbuf: shared buffer
    386  * @return new structure or NULL on alloc failure.
    387  */
    388 struct tcp_req_info* tcp_req_info_create(struct comm_base* base,
    389 	struct sldns_buffer* spoolbuf);
    390 
    391 /**
    392  * Delete tcp request structure.  Called by owning commpoint.
    393  * Removes mesh entry references and stored results from the lists.
    394  * @param req: the tcp request info
    395  */
    396 void tcp_req_info_delete(struct tcp_req_info* req);
    397 
    398 /**
    399  * Clear tcp request structure.  Removes list entries, sets it up ready
    400  * for the next connection.
    401  * @param req: tcp request info structure.
    402  */
    403 void tcp_req_info_clear(struct tcp_req_info* req);
    404 
    405 /**
    406  * Remove mesh state entry from list in tcp_req_info.
    407  * caller has to manage the mesh state reply entry in the mesh state.
    408  * @param req: the tcp req info that has the entry removed from the list.
    409  * @param m: the state removed from the list.
    410  */
    411 void tcp_req_info_remove_mesh_state(struct tcp_req_info* req,
    412 	struct mesh_state* m);
    413 
    414 /**
    415  * Handle write done of the last result packet
    416  * @param req: the tcp req info.
    417  */
    418 void tcp_req_info_handle_writedone(struct tcp_req_info* req);
    419 
    420 /**
    421  * Handle read done of a new request from the client
    422  * @param req: the tcp req info.
    423  */
    424 void tcp_req_info_handle_readdone(struct tcp_req_info* req);
    425 
    426 /**
    427  * Add mesh state to the tcp req list of open requests.
    428  * So the comm_reply can be removed off the mesh reply list when
    429  * the tcp channel has to be closed (for other reasons then that that
    430  * request was done, eg. channel closed by client or some format error).
    431  * @param req: tcp req info structure.  It keeps track of the simultaneous
    432  * 	requests and results on a tcp (or TLS) channel.
    433  * @param mesh: mesh area for the state.
    434  * @param m: mesh state to add.
    435  * @return 0 on failure (malloc failure).
    436  */
    437 int tcp_req_info_add_meshstate(struct tcp_req_info* req,
    438 	struct mesh_area* mesh, struct mesh_state* m);
    439 
    440 /**
    441  * Send reply on tcp simultaneous answer channel.  May queue it up.
    442  * @param req: request info structure.
    443  */
    444 void tcp_req_info_send_reply(struct tcp_req_info* req);
    445 
    446 /** the read channel has closed
    447  * @param req: request. remaining queries are looked up and answered.
    448  * @return zero if nothing to do, just close the tcp.
    449  */
    450 int tcp_req_info_handle_read_close(struct tcp_req_info* req);
    451 
    452 /** get the size of currently used tcp stream wait buffers (in bytes) */
    453 size_t tcp_req_info_get_stream_buffer_size(void);
    454 
    455 /** get the size of currently used HTTP2 query buffers (in bytes) */
    456 size_t http2_get_query_buffer_size(void);
    457 /** get the size of currently used HTTP2 response buffers (in bytes) */
    458 size_t http2_get_response_buffer_size(void);
    459 
    460 #ifdef HAVE_NGHTTP2
    461 /**
    462  * Create nghttp2 callbacks to handle HTTP2 requests.
    463  * @return malloc'ed struct, NULL on failure
    464  */
    465 nghttp2_session_callbacks* http2_req_callbacks_create(void);
    466 
    467 /** Free http2 stream buffers and decrease buffer counters */
    468 void http2_req_stream_clear(struct http2_stream* h2_stream);
    469 
    470 /**
    471  * DNS response ready to be submitted to nghttp2, to be prepared for sending
    472  * out. Response is stored in c->buffer. Copy to rbuffer because the c->buffer
    473  * might be used before this will be send out.
    474  * @param h2_session: http2 session, containing c->buffer which contains answer
    475  * @param h2_stream: http2 stream, containing buffer to store answer in
    476  * @return 0 on error, 1 otherwise
    477  */
    478 int http2_submit_dns_response(struct http2_session* h2_session);
    479 #else
    480 int http2_submit_dns_response(void* v);
    481 #endif /* HAVE_NGHTTP2 */
    482 
    483 #ifdef HAVE_NGTCP2
    484 struct doq_conid;
    485 struct doq_server_socket;
    486 
    487 /**
    488  * DoQ shared connection table. This is the connections for the host.
    489  * And some config parameter values for connections. The host has to
    490  * respond on that ip,port for those connections, so they are shared
    491  * between threads.
    492  */
    493 struct doq_table {
    494 	/** the lock on the tree and config elements. insert and deletion,
    495 	 * also lookup in the tree needs to hold the lock. */
    496 	lock_rw_type lock;
    497 	/** rbtree of doq_conn, the connections to different destination
    498 	 * addresses, and can be found by dcid. */
    499 	struct rbtree_type* conn_tree;
    500 	/** lock for the conid tree, needed for the conid tree and also
    501 	 * the conid elements */
    502 	lock_rw_type conid_lock;
    503 	/** rbtree of doq_conid, connections can be found by their
    504 	 * connection ids. Lookup by connection id, finds doq_conn. */
    505 	struct rbtree_type* conid_tree;
    506 	/** the server scid length */
    507 	int sv_scidlen;
    508 	/** the static secret for the server */
    509 	uint8_t* static_secret;
    510 	/** length of the static secret */
    511 	size_t static_secret_len;
    512 	/** the idle timeout in nanoseconds */
    513 	uint64_t idle_timeout;
    514 	/** the list of write interested connections, hold the doq_table.lock
    515 	 * to change them */
    516 	struct doq_conn* write_list_first, *write_list_last;
    517 	/** rbtree of doq_timer. */
    518 	struct rbtree_type* timer_tree;
    519 	/** lock on the current_size counter. */
    520 	lock_basic_type size_lock;
    521 	/** current use, in bytes, of QUIC buffers.
    522 	 * The doq_conn ngtcp2_conn structure, SSL structure and conid structs
    523 	 * are not counted. */
    524 	size_t current_size;
    525 };
    526 
    527 /**
    528  * create SSL context for QUIC
    529  * @param key: private key file.
    530  * @param pem: public key cert.
    531  * @param verifypem: if nonNULL, verifylocation file.
    532  * return SSL_CTX* or NULL on failure (logged).
    533  */
    534 void* quic_sslctx_create(char* key, char* pem, char* verifypem);
    535 
    536 /** create doq table */
    537 struct doq_table* doq_table_create(struct config_file* cfg,
    538 	struct ub_randstate* rnd);
    539 
    540 /** delete doq table */
    541 void doq_table_delete(struct doq_table* table);
    542 
    543 /**
    544  * Timer information for doq timer.
    545  */
    546 struct doq_timer {
    547 	/** The rbnode in the tree sorted by timeout value. Key this struct. */
    548 	struct rbnode_type node;
    549 	/** The timeout value. Monotonic value used with ngtcp2.
    550 	 *  This time value is used for the tree operations. */
    551 	ngtcp2_tstamp time_mono;
    552 	/** The timeout value. Absolute time value. */
    553 	struct timeval time_real;
    554 	/** If the timer is in the time tree, with the node. */
    555 	int timer_in_tree;
    556 	/** If there are more timers with the exact same timeout value,
    557 	 * they form a set of timers. The rbnode timer has a link to the list
    558 	 * with the other timers in the set. The rbnode timer is not a
    559 	 * member of the list with the other timers. The other timers are not
    560 	 * linked into the tree. */
    561 	struct doq_timer* setlist_first, *setlist_last;
    562 	/** If the timer is on the setlist. */
    563 	int timer_in_list;
    564 	/** If in the setlist, the next and prev element. */
    565 	struct doq_timer* setlist_next, *setlist_prev;
    566 	/** The connection that is timeouted. */
    567 	struct doq_conn* conn;
    568 	/** The worker that is waiting for the timeout event.
    569 	 * Set for the rbnode tree linked element. If a worker is waiting
    570 	 * for the event. If NULL, no worker is waiting for this timeout. */
    571 	struct doq_server_socket* worker_doq_socket;
    572 };
    573 
    574 /**
    575  * Key information that makes a doq_conn node in the tree lookup.
    576  */
    577 struct doq_conn_key {
    578 	/** the remote endpoint and local endpoint and ifindex */
    579 	struct doq_pkt_addr paddr;
    580 	/** the doq connection dcid */
    581 	uint8_t* dcid;
    582 	/** length of dcid */
    583 	size_t dcidlen;
    584 };
    585 
    586 /**
    587  * DoQ connection, for DNS over QUIC. One connection to a remote endpoint
    588  * with a number of streams in it. Every stream is like a tcp stream with
    589  * a uint16_t length, query read, and a uint16_t length and answer written.
    590  */
    591 struct doq_conn {
    592 	/** rbtree node, key is addresses and dcid */
    593 	struct rbnode_type node;
    594 	/** lock on the connection */
    595 	lock_basic_type lock;
    596 	/** the key information, with dcid and address endpoint */
    597 	struct doq_conn_key key;
    598 	/** the doq server socket for inside callbacks */
    599 	struct doq_server_socket* doq_socket;
    600 	/** the doq table this connection is part of */
    601 	struct doq_table* table;
    602 	/** if the connection is about to be deleted. */
    603 	uint8_t is_deleted;
    604 	/** the version, the client chosen version of QUIC */
    605 	uint32_t version;
    606 	/** the ngtcp2 connection, a server connection */
    607 	struct ngtcp2_conn* conn;
    608 	/** the connection ids that are associated with this doq_conn.
    609 	 * There can be a number, that can change. They are linked here,
    610 	 * so that upon removal, the list of actually associated conid
    611 	 * elements can be removed as well. */
    612 	struct doq_conid* conid_list;
    613 	/** the ngtcp2 last error for the connection */
    614 #ifdef HAVE_NGTCP2_CCERR_DEFAULT
    615 	struct ngtcp2_ccerr ccerr;
    616 #else
    617 	struct ngtcp2_connection_close_error last_error;
    618 #endif
    619 	/** the recent tls alert error code */
    620 	uint8_t tls_alert;
    621 	/** the ssl context, SSL* */
    622 	void* ssl;
    623 #if defined(USE_NGTCP2_CRYPTO_OSSL) || defined(HAVE_NGTCP2_CRYPTO_QUICTLS_CONFIGURE_SERVER_CONTEXT)
    624 	/** the connection reference for ngtcp2_conn and userdata in ssl */
    625 	struct ngtcp2_crypto_conn_ref conn_ref;
    626 #endif
    627 #ifdef USE_NGTCP2_CRYPTO_OSSL
    628 	/** the per-connection state for ngtcp2_crypto_ossl */
    629 	struct ngtcp2_crypto_ossl_ctx* ossl_ctx;
    630 #endif
    631 	/** closure packet, if any */
    632 	uint8_t* close_pkt;
    633 	/** length of closure packet. */
    634 	size_t close_pkt_len;
    635 	/** closure ecn */
    636 	uint32_t close_ecn;
    637 	/** the streams for this connection, of type doq_stream */
    638 	struct rbtree_type stream_tree;
    639 	/** the streams that want write, they have something to write.
    640 	 * The list is ordered, the last have to wait for the first to
    641 	 * get their data written. */
    642 	struct doq_stream* stream_write_first, *stream_write_last;
    643 	/** the conn has write interest if true, no write interest if false. */
    644 	uint8_t write_interest;
    645 	/** if the conn is on the connection write list */
    646 	uint8_t on_write_list;
    647 	/** the connection write list prev and next, if on the write list */
    648 	struct doq_conn* write_prev, *write_next;
    649 	/** The timer for the connection. If unused, it is not in the tree
    650 	 * and not in the list. It is alloced here, so that it is prealloced.
    651 	 * It has to be set after every read and write on the connection, so
    652 	 * this improves performance, but also the allocation does not fail. */
    653 	struct doq_timer timer;
    654 };
    655 
    656 /**
    657  * Connection ID and the doq_conn that is that connection. A connection
    658  * has an original dcid, and then more connection ids associated.
    659  */
    660 struct doq_conid {
    661 	/** rbtree node, key is the connection id. */
    662 	struct rbnode_type node;
    663 	/** the next and prev in the list of conids for the doq_conn */
    664 	struct doq_conid* next, *prev;
    665 	/** key to the doq_conn that is the connection */
    666 	struct doq_conn_key key;
    667 	/** the connection id, byte string */
    668 	uint8_t* cid;
    669 	/** the length of cid */
    670 	size_t cidlen;
    671 };
    672 
    673 /**
    674  * DoQ stream, for DNS over QUIC.
    675  */
    676 struct doq_stream {
    677 	/** the rbtree node for the stream, key is the stream_id */
    678 	rbnode_type node;
    679 	/** the stream id */
    680 	int64_t stream_id;
    681 	/** if the stream is closed */
    682 	uint8_t is_closed;
    683 	/** if the query is complete */
    684 	uint8_t is_query_complete;
    685 	/** the number of bytes read on the stream, up to querylen+2. */
    686 	size_t nread;
    687 	/** the length of the input query bytes */
    688 	size_t inlen;
    689 	/** the input bytes */
    690 	uint8_t* in;
    691 	/** does the stream have an answer to send */
    692 	uint8_t is_answer_available;
    693 	/** the answer bytes sent, up to outlen+2. */
    694 	size_t nwrite;
    695 	/** the length of the output answer bytes */
    696 	size_t outlen;
    697 	/** the output length in network wireformat */
    698 	uint16_t outlen_wire;
    699 	/** the output packet bytes */
    700 	uint8_t* out;
    701 	/** if the stream is on the write list */
    702 	uint8_t on_write_list;
    703 	/** The mesh area and mesh state, set when this stream's query was
    704 	 * dispatched into the mesh; used to detach the reply on stream close */
    705 	struct mesh_area* mesh;
    706 	/** the mesh state for the query, is nonNULL when there is one. */
    707 	struct mesh_state* mesh_state;
    708 	/** the prev and next on the write list, if on the list */
    709 	struct doq_stream* write_prev, *write_next;
    710 };
    711 
    712 /** doq application error code that is sent when a stream is closed */
    713 #define DOQ_APP_ERROR_CODE 1
    714 
    715 /**
    716  * Create the doq connection.
    717  * @param c: the comm point for the listening doq socket.
    718  * @param paddr: with remote and local address and ifindex for the
    719  * 	connection destination. This is where packets are sent.
    720  * @param dcid: the dcid, Destination Connection ID.
    721  * @param dcidlen: length of dcid.
    722  * @param version: client chosen version.
    723  * @return new doq connection or NULL on allocation failure.
    724  */
    725 struct doq_conn* doq_conn_create(struct comm_point* c,
    726 	struct doq_pkt_addr* paddr, const uint8_t* dcid, size_t dcidlen,
    727 	uint32_t version);
    728 
    729 /**
    730  * Delete the doq connection structure.
    731  * @param conn: to delete.
    732  * @param table: with memory size.
    733  */
    734 void doq_conn_delete(struct doq_conn* conn, struct doq_table* table);
    735 
    736 /** compare function of doq_conn */
    737 int doq_conn_cmp(const void* key1, const void* key2);
    738 
    739 /** compare function of doq_conid */
    740 int doq_conid_cmp(const void* key1, const void* key2);
    741 
    742 /** compare function of doq_timer */
    743 int doq_timer_cmp(const void* key1, const void* key2);
    744 
    745 /** compare function of doq_stream */
    746 int doq_stream_cmp(const void* key1, const void* key2);
    747 
    748 /** setup the doq connection callbacks, and settings. */
    749 int doq_conn_setup(struct doq_conn* conn, uint8_t* scid, size_t scidlen,
    750 	uint8_t* ocid, size_t ocidlen, const uint8_t* token, size_t tokenlen);
    751 
    752 /** fill a buffer with random data */
    753 void doq_fill_rand(struct ub_randstate* rnd, uint8_t* buf, size_t len);
    754 
    755 /** delete a doq_conid */
    756 void doq_conid_delete(struct doq_conid* conid);
    757 
    758 /** add a connection id to the doq_conn.
    759  * caller must hold doq_table.conid_lock. */
    760 int doq_conn_associate_conid(struct doq_conn* conn, uint8_t* data,
    761 	size_t datalen);
    762 
    763 /** remove a connection id from the doq_conn.
    764  * caller must hold doq_table.conid_lock. */
    765 void doq_conn_dissociate_conid(struct doq_conn* conn, const uint8_t* data,
    766 	size_t datalen);
    767 
    768 /** initial setup to link current connection ids to the doq_conn */
    769 int doq_conn_setup_conids(struct doq_conn* conn);
    770 
    771 /** remove the connection ids from the doq_conn.
    772  * caller must hold doq_table.conid_lock. */
    773 void doq_conn_clear_conids(struct doq_conn* conn);
    774 
    775 /** find a conid in the doq_conn connection.
    776  * caller must hold table.conid_lock. */
    777 struct doq_conid* doq_conid_find(struct doq_table* doq_table,
    778 	const uint8_t* data, size_t datalen);
    779 
    780 /** receive a packet for a connection */
    781 int doq_conn_recv(struct comm_point* c, struct doq_pkt_addr* paddr,
    782 	struct doq_conn* conn, struct ngtcp2_pkt_info* pi, int* err_retry,
    783 	int* err_drop);
    784 
    785 /** send packets for a connection */
    786 int doq_conn_write_streams(struct comm_point* c, struct doq_conn* conn,
    787 	int* err_drop);
    788 
    789 /** send the close packet for the connection, perhaps again. */
    790 int doq_conn_send_close(struct comm_point* c, struct doq_conn* conn);
    791 
    792 /** delete doq stream */
    793 void doq_stream_delete(struct doq_stream* stream);
    794 
    795 /** doq read a connection key from repinfo. It is not malloced, but points
    796  * into the repinfo for the dcid. */
    797 void doq_conn_key_from_repinfo(struct doq_conn_key* key,
    798 	struct comm_reply* repinfo);
    799 
    800 /** doq find a stream in the connection */
    801 struct doq_stream* doq_stream_find(struct doq_conn* conn, int64_t stream_id);
    802 
    803 /** doq shutdown the stream. */
    804 int doq_stream_close(struct doq_conn* conn, struct doq_stream* stream,
    805 	int send_shutdown);
    806 
    807 /** send reply for a connection */
    808 int doq_stream_send_reply(struct doq_conn* conn, struct doq_stream* stream,
    809 	struct sldns_buffer* buf);
    810 #endif /* HAVE_NGTCP2 */
    811 
    812 /** add mesh state to doq stream */
    813 void doq_stream_add_meshstate(struct doq_stream* stream,
    814 	struct mesh_area* mesh, struct mesh_state* m);
    815 
    816 /** remove mesh state from doq stream */
    817 void doq_stream_remove_mesh_state(struct doq_stream* stream);
    818 
    819 #ifdef HAVE_NGTCP2
    820 /** the connection has write interest, wants to write packets */
    821 void doq_conn_write_enable(struct doq_conn* conn);
    822 
    823 /** the connection has no write interest, does not want to write packets */
    824 void doq_conn_write_disable(struct doq_conn* conn);
    825 
    826 /** set the connection on or off the write list, depending on write interest */
    827 void doq_conn_set_write_list(struct doq_table* table, struct doq_conn* conn);
    828 
    829 /** doq remove the connection from the write list */
    830 void doq_conn_write_list_remove(struct doq_table* table,
    831 	struct doq_conn* conn);
    832 
    833 /** doq get the first conn from the write list, if any, popped from list.
    834  * Locks the conn that is returned. */
    835 struct doq_conn* doq_table_pop_first(struct doq_table* table);
    836 
    837 /**
    838  * doq check if the timer for the conn needs to be changed.
    839  * @param conn: connection, caller must hold lock on it.
    840  * @param tv: time value, absolute time, returned.
    841  * @param ts: time stamp, absolute time, returned.
    842  * @return true if timer needs to be set to tv, false if no change is needed
    843  * 	to the timer. The timer is already set to the right time in that case.
    844  */
    845 int doq_conn_check_timer(struct doq_conn* conn, struct timeval* tv,
    846 	ngtcp2_tstamp* ts);
    847 
    848 /** doq remove timer from tree */
    849 void doq_timer_tree_remove(struct doq_table* table, struct doq_timer* timer);
    850 
    851 /** doq remove timer from list */
    852 void doq_timer_list_remove(struct doq_table* table, struct doq_timer* timer);
    853 
    854 /** doq unset the timer if it was set. */
    855 void doq_timer_unset(struct doq_table* table, struct doq_timer* timer);
    856 
    857 /** doq set the timer and add it. */
    858 void doq_timer_set(struct doq_table* table, struct doq_timer* timer,
    859 	struct doq_server_socket* worker_doq_socket, struct timeval* tv,
    860 	ngtcp2_tstamp ts);
    861 
    862 /** doq find a timeout in the timer tree */
    863 struct doq_timer* doq_timer_find_time(struct doq_table* table,
    864 	ngtcp2_tstamp ts);
    865 
    866 /** doq handle timeout for a connection. Pass conn locked. Returns false for
    867  * deletion. */
    868 int doq_conn_handle_timeout(struct doq_conn* conn);
    869 
    870 /** doq add size to the current quic buffer counter */
    871 void doq_table_quic_size_add(struct doq_table* table, size_t add);
    872 
    873 /** doq subtract size from the current quic buffer counter */
    874 void doq_table_quic_size_subtract(struct doq_table* table, size_t subtract);
    875 
    876 /** doq check if mem is available for quic. */
    877 int doq_table_quic_size_available(struct doq_table* table,
    878 	struct config_file* cfg, size_t mem);
    879 
    880 /** doq get the quic size value */
    881 size_t doq_table_quic_size_get(struct doq_table* table);
    882 
    883 /** get a timestamp in nanoseconds */
    884 ngtcp2_tstamp doq_get_timestamp_nanosec(void);
    885 #endif /* HAVE_NGTCP2 */
    886 
    887 char* set_ip_dscp(int socket, int addrfamily, int ds);
    888 
    889 /** for debug and profiling purposes only
    890  * @param ub_sock: the structure containing created socket info we want to print or log for
    891  */
    892 void verbose_print_unbound_socket(struct unbound_socket* ub_sock);
    893 
    894 /** event callback for testcode/doqclient */
    895 void doq_client_event_cb(int fd, short event, void* arg);
    896 
    897 /** timer event callback for testcode/doqclient */
    898 void doq_client_timer_cb(int fd, short event, void* arg);
    899 
    900 #endif /* LISTEN_DNSPORT_H */
    901