Home | History | Annotate | Line # | Download | only in data
      1 /*
      2  * util/data/msgreply.c - store message and reply data.
      3  *
      4  * Copyright (c) 2007, NLnet Labs. All rights reserved.
      5  *
      6  * This software is open source.
      7  *
      8  * Redistribution and use in source and binary forms, with or without
      9  * modification, are permitted provided that the following conditions
     10  * are met:
     11  *
     12  * Redistributions of source code must retain the above copyright notice,
     13  * this list of conditions and the following disclaimer.
     14  *
     15  * Redistributions in binary form must reproduce the above copyright notice,
     16  * this list of conditions and the following disclaimer in the documentation
     17  * and/or other materials provided with the distribution.
     18  *
     19  * Neither the name of the NLNET LABS nor the names of its contributors may
     20  * be used to endorse or promote products derived from this software without
     21  * specific prior written permission.
     22  *
     23  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
     24  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
     25  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
     26  * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
     27  * HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
     28  * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED
     29  * TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
     30  * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
     31  * LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
     32  * NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
     33  * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
     34  */
     35 
     36 /**
     37  * \file
     38  *
     39  * This file contains a data structure to store a message and its reply.
     40  */
     41 
     42 #include "config.h"
     43 #include "util/data/msgreply.h"
     44 #include "util/storage/lookup3.h"
     45 #include "util/log.h"
     46 #include "util/alloc.h"
     47 #include "util/netevent.h"
     48 #include "util/net_help.h"
     49 #include "util/data/dname.h"
     50 #include "util/regional.h"
     51 #include "util/data/msgparse.h"
     52 #include "util/data/msgencode.h"
     53 #include "sldns/sbuffer.h"
     54 #include "sldns/wire2str.h"
     55 #include "util/module.h"
     56 #include "util/fptr_wlist.h"
     57 
     58 /** MAX TTL default for messages and rrsets */
     59 time_t MAX_TTL = 3600 * 24 * 10; /* ten days */
     60 /** MIN TTL default for messages and rrsets */
     61 time_t MIN_TTL = 0;
     62 /** MAX Negative TTL, for SOA records in authority section */
     63 time_t MAX_NEG_TTL = 3600; /* one hour */
     64 /** MIN Negative TTL, for SOA records in authority section */
     65 time_t MIN_NEG_TTL = 0;
     66 /** If we serve expired entries and prefetch them */
     67 int SERVE_EXPIRED = 0;
     68 /** Time to serve records after expiration */
     69 time_t SERVE_EXPIRED_TTL = 86400;
     70 /** Reset serve expired TTL after failed update attempt */
     71 time_t SERVE_EXPIRED_TTL_RESET = 0;
     72 /** TTL to use for expired records */
     73 time_t SERVE_EXPIRED_REPLY_TTL = 30;
     74 /** If we serve the original TTL or decrementing TTLs */
     75 int SERVE_ORIGINAL_TTL = 0;
     76 
     77 /** allocate qinfo, return 0 on error */
     78 static int
     79 parse_create_qinfo(sldns_buffer* pkt, struct msg_parse* msg,
     80 	struct query_info* qinf, struct regional* region)
     81 {
     82 	if(msg->qname) {
     83 		if(region)
     84 			qinf->qname = (uint8_t*)regional_alloc(region,
     85 				msg->qname_len);
     86 		else	qinf->qname = (uint8_t*)malloc(msg->qname_len);
     87 		if(!qinf->qname) return 0;
     88 		dname_pkt_copy(pkt, qinf->qname, msg->qname);
     89 	} else	qinf->qname = 0;
     90 	qinf->qname_len = msg->qname_len;
     91 	qinf->qtype = msg->qtype;
     92 	qinf->qclass = msg->qclass;
     93 	qinf->local_alias = NULL;
     94 	return 1;
     95 }
     96 
     97 /** constructor for replyinfo */
     98 struct reply_info*
     99 construct_reply_info_base(struct regional* region, uint16_t flags, size_t qd,
    100 	time_t ttl, time_t prettl, time_t expttl, time_t norecttl, size_t an,
    101 	size_t ns, size_t ar, size_t total, enum sec_status sec,
    102 	sldns_ede_code reason_bogus)
    103 {
    104 	struct reply_info* rep;
    105 	/* rrset_count-1 because the first ref is part of the struct. */
    106 	size_t s = sizeof(struct reply_info) - sizeof(struct rrset_ref) +
    107 		sizeof(struct ub_packed_rrset_key*) * total;
    108 	if(total >= RR_COUNT_MAX) return NULL; /* sanity check on numRRS*/
    109 	if(region)
    110 		rep = (struct reply_info*)regional_alloc(region, s);
    111 	else	rep = (struct reply_info*)malloc(s +
    112 			sizeof(struct rrset_ref) * (total));
    113 	if(!rep)
    114 		return NULL;
    115 	rep->flags = flags;
    116 	rep->qdcount = qd;
    117 	rep->ttl = ttl;
    118 	rep->prefetch_ttl = prettl;
    119 	rep->serve_expired_ttl = expttl;
    120 	rep->serve_expired_norec_ttl = norecttl;
    121 	rep->an_numrrsets = an;
    122 	rep->ns_numrrsets = ns;
    123 	rep->ar_numrrsets = ar;
    124 	rep->rrset_count = total;
    125 	rep->security = sec;
    126 	rep->reason_bogus = reason_bogus;
    127 	/* this is only allocated and used for caching on copy */
    128 	rep->reason_bogus_str = NULL;
    129 	rep->authoritative = 0;
    130 	/* array starts after the refs */
    131 	if(region)
    132 		rep->rrsets = (struct ub_packed_rrset_key**)&(rep->ref[0]);
    133 	else	rep->rrsets = (struct ub_packed_rrset_key**)&(rep->ref[total]);
    134 	/* zero the arrays to assist cleanup in case of malloc failure */
    135 	memset( rep->rrsets, 0, sizeof(struct ub_packed_rrset_key*) * total);
    136 	if(!region)
    137 		memset( &rep->ref[0], 0, sizeof(struct rrset_ref) * total);
    138 	return rep;
    139 }
    140 
    141 /** allocate replyinfo, return 0 on error */
    142 static int
    143 parse_create_repinfo(struct msg_parse* msg, struct reply_info** rep,
    144 	struct regional* region)
    145 {
    146 	*rep = construct_reply_info_base(region, msg->flags, msg->qdcount, 0,
    147 		0, 0, 0, msg->an_rrsets, msg->ns_rrsets, msg->ar_rrsets,
    148 		msg->rrset_count, sec_status_unchecked, LDNS_EDE_NONE);
    149 	if(!*rep)
    150 		return 0;
    151 	return 1;
    152 }
    153 
    154 int
    155 reply_info_alloc_rrset_keys(struct reply_info* rep, struct alloc_cache* alloc,
    156 	struct regional* region)
    157 {
    158 	size_t i;
    159 	for(i=0; i<rep->rrset_count; i++) {
    160 		if(region) {
    161 			rep->rrsets[i] = (struct ub_packed_rrset_key*)
    162 				regional_alloc(region,
    163 				sizeof(struct ub_packed_rrset_key));
    164 			if(rep->rrsets[i]) {
    165 				memset(rep->rrsets[i], 0,
    166 					sizeof(struct ub_packed_rrset_key));
    167 				rep->rrsets[i]->entry.key = rep->rrsets[i];
    168 			}
    169 		}
    170 		else	rep->rrsets[i] = alloc_special_obtain(alloc);
    171 		if(!rep->rrsets[i])
    172 			return 0;
    173 		rep->rrsets[i]->entry.data = NULL;
    174 	}
    175 	return 1;
    176 }
    177 
    178 int
    179 reply_info_can_answer_expired(struct reply_info* rep, time_t timenow)
    180 {
    181 	log_assert(TTL_IS_EXPIRED(rep->ttl, timenow));
    182 	/* Really expired */
    183 	if(SERVE_EXPIRED_TTL && TTL_IS_EXPIRED(rep->serve_expired_ttl, timenow)) return 0;
    184 	/* Ignore expired failure answers */
    185 	if(FLAGS_GET_RCODE(rep->flags) != LDNS_RCODE_NOERROR &&
    186 		FLAGS_GET_RCODE(rep->flags) != LDNS_RCODE_NXDOMAIN &&
    187 		FLAGS_GET_RCODE(rep->flags) != LDNS_RCODE_YXDOMAIN) return 0;
    188 	return 1;
    189 }
    190 
    191 int
    192 reply_info_could_use_expired(struct reply_info* rep, time_t timenow)
    193 {
    194 	log_assert(TTL_IS_EXPIRED(rep->ttl, timenow));
    195 	/* Really expired */
    196 	if(SERVE_EXPIRED_TTL && TTL_IS_EXPIRED(rep->serve_expired_ttl, timenow)
    197 		&& !SERVE_EXPIRED_TTL_RESET) return 0;
    198 	/* Ignore expired failure answers */
    199 	if(FLAGS_GET_RCODE(rep->flags) != LDNS_RCODE_NOERROR &&
    200 		FLAGS_GET_RCODE(rep->flags) != LDNS_RCODE_NXDOMAIN &&
    201 		FLAGS_GET_RCODE(rep->flags) != LDNS_RCODE_YXDOMAIN) return 0;
    202 	return 1;
    203 }
    204 
    205 struct reply_info *
    206 make_new_reply_info(const struct reply_info* rep, struct regional* region,
    207 	size_t an_numrrsets, size_t copy_rrsets)
    208 {
    209 	struct reply_info* new_rep;
    210 	size_t i;
    211 
    212 	/* create a base struct.  we specify 'insecure' security status as
    213 	 * the modified response won't be DNSSEC-valid.  In our faked response
    214 	 * the authority and additional sections will be empty (except possible
    215 	 * EDNS0 OPT RR in the additional section appended on sending it out),
    216 	 * so the total number of RRsets is an_numrrsets. */
    217 	new_rep = construct_reply_info_base(region, rep->flags,
    218 		rep->qdcount, rep->ttl, rep->prefetch_ttl,
    219 		rep->serve_expired_ttl, rep->serve_expired_norec_ttl,
    220 		an_numrrsets, 0, 0, an_numrrsets,
    221 		sec_status_insecure, LDNS_EDE_NONE);
    222 	if(!new_rep)
    223 		return NULL;
    224 	if(!reply_info_alloc_rrset_keys(new_rep, NULL, region))
    225 		return NULL;
    226 	for(i=0; i<copy_rrsets; i++)
    227 		new_rep->rrsets[i] = rep->rrsets[i];
    228 
    229 	return new_rep;
    230 }
    231 
    232 /** find the minimumttl in the rdata of SOA record */
    233 static uint32_t
    234 soa_find_minttl(struct rr_parse* rr)
    235 {
    236 	uint16_t rlen = sldns_read_uint16(rr->ttl_data+4);
    237 	if(rlen < 20)
    238 		return 0; /* rdata too small for SOA (dname, dname, 5*32bit) */
    239 	/* minimum TTL is the last 32bit value in the rdata of the record */
    240 	/* at position ttl_data + 4(ttl) + 2(rdatalen) + rdatalen - 4(timeval)*/
    241 	return sldns_read_uint32(rr->ttl_data+6+rlen-4);
    242 }
    243 
    244 /** do the rdata copy */
    245 static int
    246 rdata_copy(sldns_buffer* pkt, struct packed_rrset_data* data, uint8_t* to,
    247 	struct rr_parse* rr, time_t* rr_ttl, uint16_t type,
    248 	sldns_pkt_section section)
    249 {
    250 	uint16_t pkt_len;
    251 	size_t tolen;
    252 	uint32_t ttl;
    253 	const sldns_rr_descriptor* desc;
    254 
    255 	ttl = sldns_read_uint32(rr->ttl_data);
    256 	/* RFC 2181 Section 8. if msb of ttl is set treat as if zero. */
    257 	/* RFC 8767 Section 4. values with high-order bit as positive, not 0.
    258 +	 *	As such, it will be capped by MAX_TTL below. */
    259 	if(type == LDNS_RR_TYPE_SOA && section == LDNS_SECTION_AUTHORITY) {
    260 		/* negative response. see if TTL of SOA record larger than the
    261 		 * minimum-ttl in the rdata of the SOA record */
    262 		if(ttl > soa_find_minttl(rr)) ttl = soa_find_minttl(rr);
    263 		if(!SERVE_ORIGINAL_TTL) {
    264 			/* If MIN_NEG_TTL is configured skip setting MIN_TTL */
    265 			if(MIN_NEG_TTL <= 0 && ttl < (uint32_t)MIN_TTL) {
    266 				ttl = (uint32_t)MIN_TTL;
    267 			}
    268 			if(ttl > (uint32_t)MAX_TTL) ttl = (uint32_t)MAX_TTL;
    269 		}
    270 		/* MAX_NEG_TTL overrides the min and max ttl of everything
    271 		 * else; it is for a more specific record */
    272 		if(ttl > (uint32_t)MAX_NEG_TTL) ttl = (uint32_t)MAX_NEG_TTL;
    273 		/* MIN_NEG_TTL overrides the min and max ttl of everything
    274 		 * else if configured; it is for a more specific record */
    275 		if(MIN_NEG_TTL > 0 && ttl < (uint32_t)MIN_NEG_TTL) {
    276 			ttl = (uint32_t)MIN_NEG_TTL;
    277 		}
    278 	} else if(!SERVE_ORIGINAL_TTL) {
    279 		if(ttl < (uint32_t)MIN_TTL) ttl = (uint32_t)MIN_TTL;
    280 		if(ttl > (uint32_t)MAX_TTL) ttl = (uint32_t)MAX_TTL;
    281 	}
    282 	if((time_t)ttl < data->ttl)
    283 		data->ttl = (time_t)ttl;
    284 	/* We have concluded the TTL checks */
    285 	*rr_ttl = (time_t)ttl;
    286 
    287 	if(rr->outside_packet) {
    288 		/* uncompressed already, only needs copy */
    289 		memmove(to, rr->ttl_data+sizeof(uint32_t), rr->size);
    290 		return 1;
    291 	}
    292 
    293 	sldns_buffer_set_position(pkt, (size_t)
    294 		(rr->ttl_data - sldns_buffer_begin(pkt) + sizeof(uint32_t)));
    295 	/* insert decompressed size into rdata len stored in memory */
    296 	/* -2 because rdatalen bytes are not included. */
    297 	tolen = rr->size;
    298 	if(tolen < 2)
    299 		return 0;
    300 	pkt_len = htons(rr->size - 2);
    301 	memmove(to, &pkt_len, sizeof(uint16_t));
    302 	to += 2;
    303 	tolen -= 2;
    304 	/* read packet rdata len */
    305 	pkt_len = sldns_buffer_read_u16(pkt);
    306 	if(sldns_buffer_remaining(pkt) < pkt_len)
    307 		return 0;
    308 	desc = sldns_rr_descript(type);
    309 	if(pkt_len > 0 && desc && desc->_dname_count > 0) {
    310 		int count = (int)desc->_dname_count;
    311 		int rdf = 0;
    312 		size_t len, dlen;
    313 		size_t oldpos, newpos;
    314 		/* decompress dnames. */
    315 		while(pkt_len > 0 && count) {
    316 			switch(desc->_wireformat[rdf]) {
    317 			case LDNS_RDF_TYPE_DNAME:
    318 				oldpos = sldns_buffer_position(pkt);
    319 				dlen = pkt_dname_len(pkt);
    320 				if(dlen == 0)
    321 					return 0; /* malformed */
    322 				if(dlen > tolen)
    323 					return 0; /* alloc mismatch */
    324 				newpos = sldns_buffer_position(pkt);
    325 				if(oldpos > newpos)
    326 					return 0; /* should have moved forward*/
    327 				sldns_buffer_set_position(pkt, oldpos);
    328 				dname_pkt_copy(pkt, to,
    329 					sldns_buffer_current(pkt));
    330 				sldns_buffer_set_position(pkt, newpos);
    331 				to += dlen;
    332 				tolen -= dlen;
    333 				if(sldns_buffer_position(pkt)-oldpos > pkt_len)
    334 					return 0; /* malformed: walks diverged */
    335 				pkt_len -= sldns_buffer_position(pkt)-oldpos;
    336 				count--;
    337 				len = 0;
    338 				break;
    339 			case LDNS_RDF_TYPE_STR:
    340 				len = sldns_buffer_current(pkt)[0] + 1;
    341 				break;
    342 			default:
    343 				len = get_rdf_size(desc->_wireformat[rdf]);
    344 				break;
    345 			}
    346 			if(len) {
    347 				if(len > tolen)
    348 					return 0; /* alloc mismatch */
    349 				log_assert(len <= pkt_len);
    350 				memmove(to, sldns_buffer_current(pkt), len);
    351 				to += len;
    352 				tolen -= len;
    353 				sldns_buffer_skip(pkt, (ssize_t)len);
    354 				pkt_len -= len;
    355 			}
    356 			rdf++;
    357 		}
    358 	}
    359 	/* copy remaining rdata */
    360 	if(pkt_len >  0) {
    361 		if(pkt_len > tolen)
    362 			return 0; /* alloc mismatch */
    363 		memmove(to, sldns_buffer_current(pkt), pkt_len);
    364 	}
    365 
    366 	return 1;
    367 }
    368 
    369 /** copy over the data into packed rrset */
    370 static int
    371 parse_rr_copy(sldns_buffer* pkt, struct rrset_parse* pset,
    372 	struct packed_rrset_data* data)
    373 {
    374 	size_t i;
    375 	struct rr_parse* rr = pset->rr_first;
    376 	uint8_t* nextrdata;
    377 	size_t total = pset->rr_count + pset->rrsig_count;
    378 	data->ttl = MAX_TTL;
    379 	data->count = pset->rr_count;
    380 	data->rrsig_count = pset->rrsig_count;
    381 	data->trust = rrset_trust_none;
    382 	data->security = sec_status_unchecked;
    383 	/* layout: struct - rr_len - rr_data - rr_ttl - rdata - rrsig */
    384 	data->rr_len = (size_t*)((uint8_t*)data +
    385 		sizeof(struct packed_rrset_data));
    386 	data->rr_data = (uint8_t**)&(data->rr_len[total]);
    387 	data->rr_ttl = (time_t*)&(data->rr_data[total]);
    388 	nextrdata = (uint8_t*)&(data->rr_ttl[total]);
    389 	for(i=0; i<data->count; i++) {
    390 		data->rr_len[i] = rr->size;
    391 		data->rr_data[i] = nextrdata;
    392 		nextrdata += rr->size;
    393 		if(!rdata_copy(pkt, data, data->rr_data[i], rr,
    394 			&data->rr_ttl[i], pset->type, pset->section))
    395 			return 0;
    396 		rr = rr->next;
    397 	}
    398 	/* if rrsig, its rdata is at nextrdata */
    399 	rr = pset->rrsig_first;
    400 	for(i=data->count; i<total; i++) {
    401 		data->rr_len[i] = rr->size;
    402 		data->rr_data[i] = nextrdata;
    403 		nextrdata += rr->size;
    404 		if(!rdata_copy(pkt, data, data->rr_data[i], rr,
    405 			&data->rr_ttl[i], LDNS_RR_TYPE_RRSIG, pset->section))
    406 			return 0;
    407 		rr = rr->next;
    408 	}
    409 	return 1;
    410 }
    411 
    412 /** create rrset return 0 on failure */
    413 static int
    414 parse_create_rrset(sldns_buffer* pkt, struct rrset_parse* pset,
    415 	struct packed_rrset_data** data, struct regional* region)
    416 {
    417 	/* allocate */
    418 	size_t s;
    419 	if(pset->rr_count > RR_COUNT_MAX || pset->rrsig_count > RR_COUNT_MAX ||
    420 		pset->size > RR_COUNT_MAX)
    421 		return 0; /* protect against integer overflow */
    422 	s = sizeof(struct packed_rrset_data) +
    423 		(pset->rr_count + pset->rrsig_count) *
    424 		(sizeof(size_t)+sizeof(uint8_t*)+sizeof(time_t)) +
    425 		pset->size;
    426 	if(region)
    427 		*data = regional_alloc_zero(region, s);
    428 	else	*data = calloc(1, s);
    429 	if(!*data)
    430 		return 0;
    431 	/* copy & decompress */
    432 	if(!parse_rr_copy(pkt, pset, *data)) {
    433 		if(!region) {
    434 			free(*data);
    435 			*data = NULL;
    436 		}
    437 		return 0;
    438 	}
    439 	return 1;
    440 }
    441 
    442 /** get trust value for rrset */
    443 static enum rrset_trust
    444 get_rrset_trust(struct msg_parse* msg, struct rrset_parse* rrset)
    445 {
    446 	uint16_t AA = msg->flags & BIT_AA;
    447 	if(rrset->section == LDNS_SECTION_ANSWER) {
    448 		if(AA) {
    449 			/* RFC2181 says remainder of CNAME chain is nonauth*/
    450 			if(msg->rrset_first &&
    451 				msg->rrset_first->section==LDNS_SECTION_ANSWER
    452 				&& msg->rrset_first->type==LDNS_RR_TYPE_CNAME){
    453 				if(rrset == msg->rrset_first)
    454 					return rrset_trust_ans_AA;
    455 				else 	return rrset_trust_ans_noAA;
    456 			}
    457 			if(msg->rrset_first &&
    458 				msg->rrset_first->section==LDNS_SECTION_ANSWER
    459 				&& msg->rrset_first->type==LDNS_RR_TYPE_DNAME){
    460 				if(rrset == msg->rrset_first ||
    461 				   rrset == msg->rrset_first->rrset_all_next)
    462 					return rrset_trust_ans_AA;
    463 				else 	return rrset_trust_ans_noAA;
    464 			}
    465 			return rrset_trust_ans_AA;
    466 		}
    467 		else	return rrset_trust_ans_noAA;
    468 	} else if(rrset->section == LDNS_SECTION_AUTHORITY) {
    469 		if(AA)	return rrset_trust_auth_AA;
    470 		else	return rrset_trust_auth_noAA;
    471 	} else {
    472 		/* addit section */
    473 		if(AA)	return rrset_trust_add_AA;
    474 		else	return rrset_trust_add_noAA;
    475 	}
    476 	/* NOTREACHED */
    477 	return rrset_trust_none;
    478 }
    479 
    480 int
    481 parse_copy_decompress_rrset(sldns_buffer* pkt, struct msg_parse* msg,
    482 	struct rrset_parse *pset, struct regional* region,
    483 	struct ub_packed_rrset_key* pk)
    484 {
    485 	struct packed_rrset_data* data;
    486 	pk->rk.flags = pset->flags;
    487 	pk->rk.dname_len = pset->dname_len;
    488 	if(region)
    489 		pk->rk.dname = (uint8_t*)regional_alloc(
    490 			region, pset->dname_len);
    491 	else	pk->rk.dname =
    492 			(uint8_t*)malloc(pset->dname_len);
    493 	if(!pk->rk.dname)
    494 		return 0;
    495 	/** copy & decompress dname */
    496 	dname_pkt_copy(pkt, pk->rk.dname, pset->dname);
    497 	/** copy over type and class */
    498 	pk->rk.type = htons(pset->type);
    499 	pk->rk.rrset_class = pset->rrset_class;
    500 	/** read data part. */
    501 	if(!parse_create_rrset(pkt, pset, &data, region)) {
    502 		if(!region) {
    503 			free(pk->rk.dname);
    504 			pk->rk.dname = NULL;
    505 		}
    506 		return 0;
    507 	}
    508 	pk->entry.data = (void*)data;
    509 	pk->entry.key = (void*)pk;
    510 	pk->rk.flags |= (data->ttl == 0) ? PACKED_RRSET_UPSTREAM_0TTL : 0;
    511 	if( (pk->rk.flags & PACKED_RRSET_UPSTREAM_0TTL) != 0)
    512 		pk->entry.hash = rrset_key_hash(&pk->rk);
    513 	else
    514 		pk->entry.hash = pset->hash;
    515 	data->trust = get_rrset_trust(msg, pset);
    516 	return 1;
    517 }
    518 
    519 /**
    520  * Copy and decompress rrs
    521  * @param pkt: the packet for compression pointer resolution.
    522  * @param msg: the parsed message
    523  * @param rep: reply info to put rrs into.
    524  * @param region: if not NULL, used for allocation.
    525  * @return 0 on failure.
    526  */
    527 static int
    528 parse_copy_decompress(sldns_buffer* pkt, struct msg_parse* msg,
    529 	struct reply_info* rep, struct regional* region)
    530 {
    531 	size_t i;
    532 	struct rrset_parse *pset = msg->rrset_first;
    533 	struct packed_rrset_data* data;
    534 	log_assert(rep);
    535 	rep->ttl = MAX_TTL;
    536 	rep->security = sec_status_unchecked;
    537 	if(rep->rrset_count == 0)
    538 		rep->ttl = NORR_TTL;
    539 
    540 	for(i=0; i<rep->rrset_count; i++) {
    541 		if(!parse_copy_decompress_rrset(pkt, msg, pset, region,
    542 			rep->rrsets[i]))
    543 			return 0;
    544 		data = (struct packed_rrset_data*)rep->rrsets[i]->entry.data;
    545 		if(data->ttl < rep->ttl)
    546 			rep->ttl = data->ttl;
    547 
    548 		pset = pset->rrset_all_next;
    549 	}
    550 	rep->prefetch_ttl = PREFETCH_TTL_CALC(rep->ttl);
    551 	rep->serve_expired_ttl = rep->ttl + SERVE_EXPIRED_TTL;
    552 	/* rep->serve_expired_norec_ttl should stay at 0 */
    553 	log_assert(rep->serve_expired_norec_ttl == 0);
    554 	return 1;
    555 }
    556 
    557 int
    558 parse_create_msg(sldns_buffer* pkt, struct msg_parse* msg,
    559 	struct alloc_cache* alloc, struct query_info* qinf,
    560 	struct reply_info** rep, struct regional* region)
    561 {
    562 	log_assert(pkt && msg);
    563 	if(!parse_create_qinfo(pkt, msg, qinf, region))
    564 		return 0;
    565 	if(!parse_create_repinfo(msg, rep, region))
    566 		return 0;
    567 	if(!reply_info_alloc_rrset_keys(*rep, alloc, region)) {
    568 		if(!region) reply_info_parsedelete(*rep, alloc);
    569 		return 0;
    570 	}
    571 	if(!parse_copy_decompress(pkt, msg, *rep, region)) {
    572 		if(!region) reply_info_parsedelete(*rep, alloc);
    573 		return 0;
    574 	}
    575 	return 1;
    576 }
    577 
    578 int reply_info_parse(sldns_buffer* pkt, struct alloc_cache* alloc,
    579         struct query_info* qinf, struct reply_info** rep,
    580 	struct regional* region, struct edns_data* edns)
    581 {
    582 	/* use scratch pad region-allocator during parsing. */
    583 	struct msg_parse* msg;
    584 	int ret;
    585 
    586 	qinf->qname = NULL;
    587 	qinf->local_alias = NULL;
    588 	*rep = NULL;
    589 	if(!(msg = regional_alloc(region, sizeof(*msg)))) {
    590 		return LDNS_RCODE_SERVFAIL;
    591 	}
    592 	memset(msg, 0, sizeof(*msg));
    593 
    594 	sldns_buffer_set_position(pkt, 0);
    595 	if((ret = parse_packet(pkt, msg, region)) != 0) {
    596 		return ret;
    597 	}
    598 	if((ret = parse_extract_edns_from_response_msg(msg, edns, region)) != 0)
    599 		return ret;
    600 
    601 	/* parse OK, allocate return structures */
    602 	/* this also performs dname decompression */
    603 	if(!parse_create_msg(pkt, msg, alloc, qinf, rep, NULL)) {
    604 		query_info_clear(qinf);
    605 		*rep = NULL;
    606 		return LDNS_RCODE_SERVFAIL;
    607 	}
    608 	return 0;
    609 }
    610 
    611 /** helper compare function to sort in lock order */
    612 static int
    613 reply_info_sortref_cmp(const void* a, const void* b)
    614 {
    615 	struct rrset_ref* x = (struct rrset_ref*)a;
    616 	struct rrset_ref* y = (struct rrset_ref*)b;
    617 	if(x->key < y->key) return -1;
    618 	if(x->key > y->key) return 1;
    619 	return 0;
    620 }
    621 
    622 void
    623 reply_info_sortref(struct reply_info* rep)
    624 {
    625 	qsort(&rep->ref[0], rep->rrset_count, sizeof(struct rrset_ref),
    626 		reply_info_sortref_cmp);
    627 }
    628 
    629 void
    630 reply_info_set_ttls(struct reply_info* rep, time_t timenow)
    631 {
    632 	size_t i, j;
    633 	rep->ttl += timenow;
    634 	rep->prefetch_ttl += timenow;
    635 	rep->serve_expired_ttl += timenow;
    636 	/* Don't set rep->serve_expired_norec_ttl; this should only be set
    637 	 * on cached records when encountering an error */
    638 	log_assert(rep->serve_expired_norec_ttl == 0);
    639 	for(i=0; i<rep->rrset_count; i++) {
    640 		struct packed_rrset_data* data = (struct packed_rrset_data*)
    641 			rep->ref[i].key->entry.data;
    642 		if(i>0 && rep->ref[i].key == rep->ref[i-1].key)
    643 			continue;
    644 		data->ttl += timenow;
    645 		for(j=0; j<data->count + data->rrsig_count; j++) {
    646 			data->rr_ttl[j] += timenow;
    647 		}
    648 		data->ttl_add = timenow;
    649 	}
    650 }
    651 
    652 void
    653 reply_info_absolute_ttls(struct reply_info* rep, time_t ttl, time_t ttl_add)
    654 {
    655 	size_t i, j;
    656 	rep->ttl = ttl;
    657 	rep->prefetch_ttl = PREFETCH_TTL_CALC(ttl);
    658 	rep->serve_expired_ttl = ttl + SERVE_EXPIRED_TTL;
    659 	/* Don't set rep->serve_expired_norec_ttl; this should only be set
    660 	 * on cached records when encountering an error */
    661 	log_assert(rep->serve_expired_norec_ttl == 0);
    662 	for(i=0; i<rep->rrset_count; i++) {
    663 		struct packed_rrset_data* data = (struct packed_rrset_data*)
    664 			rep->ref[i].key->entry.data;
    665 		if(i>0 && rep->ref[i].key == rep->ref[i-1].key)
    666 			continue;
    667 		data->ttl = ttl;
    668 		for(j=0; j<data->count + data->rrsig_count; j++) {
    669 			data->rr_ttl[j] = ttl;
    670 		}
    671 		data->ttl_add = ttl_add;
    672 	}
    673 }
    674 
    675 void
    676 reply_info_parsedelete(struct reply_info* rep, struct alloc_cache* alloc)
    677 {
    678 	size_t i;
    679 	if(!rep)
    680 		return;
    681 	/* no need to lock, since not shared in hashtables. */
    682 	for(i=0; i<rep->rrset_count; i++) {
    683 		ub_packed_rrset_parsedelete(rep->rrsets[i], alloc);
    684 	}
    685 	if(rep->reason_bogus_str) {
    686 		free(rep->reason_bogus_str);
    687 		rep->reason_bogus_str = NULL;
    688 	}
    689 	free(rep);
    690 }
    691 
    692 int
    693 query_info_parse(struct query_info* m, sldns_buffer* query)
    694 {
    695 	uint8_t* q = sldns_buffer_begin(query);
    696 	/* minimum size: header + \0 + qtype + qclass */
    697 	if(sldns_buffer_limit(query) < LDNS_HEADER_SIZE + 5)
    698 		return 0;
    699 	if((LDNS_OPCODE_WIRE(q) != LDNS_PACKET_QUERY && LDNS_OPCODE_WIRE(q) !=
    700 		LDNS_PACKET_NOTIFY) || LDNS_QDCOUNT(q) != 1 ||
    701 		sldns_buffer_position(query) != 0)
    702 		return 0;
    703 	sldns_buffer_skip(query, LDNS_HEADER_SIZE);
    704 	m->qname = sldns_buffer_current(query);
    705 	if((m->qname_len = query_dname_len(query)) == 0)
    706 		return 0; /* parse error */
    707 	if(sldns_buffer_remaining(query) < 4)
    708 		return 0; /* need qtype, qclass */
    709 	m->qtype = sldns_buffer_read_u16(query);
    710 	m->qclass = sldns_buffer_read_u16(query);
    711 	m->local_alias = NULL;
    712 	return 1;
    713 }
    714 
    715 /** tiny subroutine for msgreply_compare */
    716 #define COMPARE_IT(x, y) \
    717 	if( (x) < (y) ) return -1; \
    718 	else if( (x) > (y) ) return +1; \
    719 	log_assert( (x) == (y) );
    720 
    721 int
    722 query_info_compare(void* m1, void* m2)
    723 {
    724 	struct query_info* msg1 = (struct query_info*)m1;
    725 	struct query_info* msg2 = (struct query_info*)m2;
    726 	int mc;
    727 	/* from most different to least different for speed */
    728 	COMPARE_IT(msg1->qtype, msg2->qtype);
    729 	if((mc = query_dname_compare(msg1->qname, msg2->qname)) != 0)
    730 		return mc;
    731 	log_assert(msg1->qname_len == msg2->qname_len);
    732 	COMPARE_IT(msg1->qclass, msg2->qclass);
    733 	return 0;
    734 #undef COMPARE_IT
    735 }
    736 
    737 void
    738 query_info_clear(struct query_info* m)
    739 {
    740 	free(m->qname);
    741 	m->qname = NULL;
    742 }
    743 
    744 size_t
    745 msgreply_sizefunc(void* k, void* d)
    746 {
    747 	struct msgreply_entry* q = (struct msgreply_entry*)k;
    748 	struct reply_info* r = (struct reply_info*)d;
    749 	size_t s = sizeof(struct msgreply_entry) + sizeof(struct reply_info)
    750 		+ q->key.qname_len + lock_get_mem(&q->entry.lock)
    751 		- sizeof(struct rrset_ref);
    752 	s += r->rrset_count * sizeof(struct rrset_ref);
    753 	s += r->rrset_count * sizeof(struct ub_packed_rrset_key*);
    754 	return s;
    755 }
    756 
    757 void
    758 query_entry_delete(void *k, void* ATTR_UNUSED(arg))
    759 {
    760 	struct msgreply_entry* q = (struct msgreply_entry*)k;
    761 	lock_rw_destroy(&q->entry.lock);
    762 	query_info_clear(&q->key);
    763 	free(q);
    764 }
    765 
    766 void
    767 reply_info_delete(void* d, void* ATTR_UNUSED(arg))
    768 {
    769 	struct reply_info* r = (struct reply_info*)d;
    770 	if(r->reason_bogus_str) {
    771 		free(r->reason_bogus_str);
    772 		r->reason_bogus_str = NULL;
    773 	}
    774 	free(r);
    775 }
    776 
    777 hashvalue_type
    778 query_info_hash(struct query_info *q, uint16_t flags)
    779 {
    780 	hashvalue_type h = 0xab;
    781 	h = hashlittle(&q->qtype, sizeof(q->qtype), h);
    782 	if(q->qtype == LDNS_RR_TYPE_AAAA && (flags&BIT_CD))
    783 		h++;
    784 	h = hashlittle(&q->qclass, sizeof(q->qclass), h);
    785 	h = dname_query_hash(q->qname, h);
    786 	return h;
    787 }
    788 
    789 struct msgreply_entry*
    790 query_info_entrysetup(struct query_info* q, struct reply_info* r,
    791 	hashvalue_type h)
    792 {
    793 	struct msgreply_entry* e = (struct msgreply_entry*)malloc(
    794 		sizeof(struct msgreply_entry));
    795 	if(!e) return NULL;
    796 	memcpy(&e->key, q, sizeof(*q));
    797 	e->entry.hash = h;
    798 	e->entry.key = e;
    799 	e->entry.data = r;
    800 	lock_rw_init(&e->entry.lock);
    801 	lock_protect(&e->entry.lock, &e->key.qname, sizeof(e->key.qname));
    802 	lock_protect(&e->entry.lock, &e->key.qname_len, sizeof(e->key.qname_len));
    803 	lock_protect(&e->entry.lock, &e->key.qtype, sizeof(e->key.qtype));
    804 	lock_protect(&e->entry.lock, &e->key.qclass, sizeof(e->key.qclass));
    805 	lock_protect(&e->entry.lock, &e->key.local_alias, sizeof(e->key.local_alias));
    806 	lock_protect(&e->entry.lock, &e->entry.hash, sizeof(e->entry.hash));
    807 	lock_protect(&e->entry.lock, &e->entry.key, sizeof(e->entry.key));
    808 	lock_protect(&e->entry.lock, &e->entry.data, sizeof(e->entry.data));
    809 	lock_protect(&e->entry.lock, e->key.qname, e->key.qname_len);
    810 	q->qname = NULL;
    811 	return e;
    812 }
    813 
    814 /** copy rrsets from replyinfo to dest replyinfo */
    815 static int
    816 repinfo_copy_rrsets(struct reply_info* dest, struct reply_info* from,
    817 	struct regional* region)
    818 {
    819 	size_t i, s;
    820 	struct packed_rrset_data* fd, *dd;
    821 	struct ub_packed_rrset_key* fk, *dk;
    822 	for(i=0; i<dest->rrset_count; i++) {
    823 		fk = from->rrsets[i];
    824 		dk = dest->rrsets[i];
    825 		fd = (struct packed_rrset_data*)fk->entry.data;
    826 		dk->entry.hash = fk->entry.hash;
    827 		dk->rk = fk->rk;
    828 		if(region) {
    829 			dk->id = fk->id;
    830 			dk->rk.dname = (uint8_t*)regional_alloc_init(region,
    831 				fk->rk.dname, fk->rk.dname_len);
    832 		} else
    833 			dk->rk.dname = (uint8_t*)memdup(fk->rk.dname,
    834 				fk->rk.dname_len);
    835 		if(!dk->rk.dname)
    836 			return 0;
    837 		s = packed_rrset_sizeof(fd);
    838 		if(region)
    839 			dd = (struct packed_rrset_data*)regional_alloc_init(
    840 				region, fd, s);
    841 		else	dd = (struct packed_rrset_data*)memdup(fd, s);
    842 		if(!dd)
    843 			return 0;
    844 		packed_rrset_ptr_fixup(dd);
    845 		dk->entry.data = (void*)dd;
    846 	}
    847 	return 1;
    848 }
    849 
    850 struct reply_info*
    851 reply_info_copy(struct reply_info* rep, struct alloc_cache* alloc,
    852 	struct regional* region)
    853 {
    854 	struct reply_info* cp;
    855 	cp = construct_reply_info_base(region, rep->flags, rep->qdcount,
    856 		rep->ttl, rep->prefetch_ttl, rep->serve_expired_ttl,
    857 		rep->serve_expired_norec_ttl,
    858 		rep->an_numrrsets, rep->ns_numrrsets, rep->ar_numrrsets,
    859 		rep->rrset_count, rep->security, rep->reason_bogus);
    860 	if(!cp)
    861 		return NULL;
    862 
    863 	if(rep->reason_bogus_str && *rep->reason_bogus_str != 0) {
    864 		if(region) {
    865 			cp->reason_bogus_str = (char*)regional_alloc(region,
    866 				sizeof(char)
    867 				* (strlen(rep->reason_bogus_str)+1));
    868 		} else {
    869 			cp->reason_bogus_str = malloc(sizeof(char)
    870 				* (strlen(rep->reason_bogus_str)+1));
    871 		}
    872 		if(!cp->reason_bogus_str) {
    873 			if(!region)
    874 				reply_info_parsedelete(cp, alloc);
    875 			return NULL;
    876 		}
    877 		memcpy(cp->reason_bogus_str, rep->reason_bogus_str,
    878 			strlen(rep->reason_bogus_str)+1);
    879 	}
    880 
    881 	/* allocate ub_key structures special or not */
    882 	if(!reply_info_alloc_rrset_keys(cp, alloc, region)) {
    883 		if(!region)
    884 			reply_info_parsedelete(cp, alloc);
    885 		return NULL;
    886 	}
    887 	if(!repinfo_copy_rrsets(cp, rep, region)) {
    888 		if(!region)
    889 			reply_info_parsedelete(cp, alloc);
    890 		return NULL;
    891 	}
    892 	return cp;
    893 }
    894 
    895 uint8_t*
    896 reply_find_final_cname_target(struct query_info* qinfo, struct reply_info* rep)
    897 {
    898 	uint8_t* sname = qinfo->qname;
    899 	size_t snamelen = qinfo->qname_len;
    900 	size_t i;
    901 	for(i=0; i<rep->an_numrrsets; i++) {
    902 		struct ub_packed_rrset_key* s = rep->rrsets[i];
    903 		/* follow CNAME chain (if any) */
    904 		if(ntohs(s->rk.type) == LDNS_RR_TYPE_CNAME &&
    905 			ntohs(s->rk.rrset_class) == qinfo->qclass &&
    906 			snamelen == s->rk.dname_len &&
    907 			query_dname_compare(sname, s->rk.dname) == 0) {
    908 			get_cname_target(s, &sname, &snamelen);
    909 		}
    910 	}
    911 	if(sname != qinfo->qname)
    912 		return sname;
    913 	return NULL;
    914 }
    915 
    916 struct ub_packed_rrset_key*
    917 reply_find_answer_rrset(struct query_info* qinfo, struct reply_info* rep)
    918 {
    919 	uint8_t* sname = qinfo->qname;
    920 	size_t snamelen = qinfo->qname_len;
    921 	size_t i;
    922 	for(i=0; i<rep->an_numrrsets; i++) {
    923 		struct ub_packed_rrset_key* s = rep->rrsets[i];
    924 		/* first match type, for query of qtype cname */
    925 		if(ntohs(s->rk.type) == qinfo->qtype &&
    926 			ntohs(s->rk.rrset_class) == qinfo->qclass &&
    927 			snamelen == s->rk.dname_len &&
    928 			query_dname_compare(sname, s->rk.dname) == 0) {
    929 			return s;
    930 		}
    931 		/* follow CNAME chain (if any) */
    932 		if(ntohs(s->rk.type) == LDNS_RR_TYPE_CNAME &&
    933 			ntohs(s->rk.rrset_class) == qinfo->qclass &&
    934 			snamelen == s->rk.dname_len &&
    935 			query_dname_compare(sname, s->rk.dname) == 0) {
    936 			get_cname_target(s, &sname, &snamelen);
    937 		}
    938 	}
    939 	return NULL;
    940 }
    941 
    942 struct ub_packed_rrset_key* reply_find_rrset_section_an(struct reply_info* rep,
    943 	uint8_t* name, size_t namelen, uint16_t type, uint16_t dclass)
    944 {
    945 	size_t i;
    946 	for(i=0; i<rep->an_numrrsets; i++) {
    947 		struct ub_packed_rrset_key* s = rep->rrsets[i];
    948 		if(ntohs(s->rk.type) == type &&
    949 			ntohs(s->rk.rrset_class) == dclass &&
    950 			namelen == s->rk.dname_len &&
    951 			query_dname_compare(name, s->rk.dname) == 0) {
    952 			return s;
    953 		}
    954 	}
    955 	return NULL;
    956 }
    957 
    958 struct ub_packed_rrset_key* reply_find_rrset_section_ns(struct reply_info* rep,
    959 	uint8_t* name, size_t namelen, uint16_t type, uint16_t dclass)
    960 {
    961 	size_t i;
    962 	for(i=rep->an_numrrsets; i<rep->an_numrrsets+rep->ns_numrrsets; i++) {
    963 		struct ub_packed_rrset_key* s = rep->rrsets[i];
    964 		if(ntohs(s->rk.type) == type &&
    965 			ntohs(s->rk.rrset_class) == dclass &&
    966 			namelen == s->rk.dname_len &&
    967 			query_dname_compare(name, s->rk.dname) == 0) {
    968 			return s;
    969 		}
    970 	}
    971 	return NULL;
    972 }
    973 
    974 struct ub_packed_rrset_key* reply_find_rrset(struct reply_info* rep,
    975 	uint8_t* name, size_t namelen, uint16_t type, uint16_t dclass)
    976 {
    977 	size_t i;
    978 	for(i=0; i<rep->rrset_count; i++) {
    979 		struct ub_packed_rrset_key* s = rep->rrsets[i];
    980 		if(ntohs(s->rk.type) == type &&
    981 			ntohs(s->rk.rrset_class) == dclass &&
    982 			namelen == s->rk.dname_len &&
    983 			query_dname_compare(name, s->rk.dname) == 0) {
    984 			return s;
    985 		}
    986 	}
    987 	return NULL;
    988 }
    989 
    990 void
    991 log_dns_msg(const char* str, struct query_info* qinfo, struct reply_info* rep)
    992 {
    993 	/* not particularly fast but flexible, make wireformat and print */
    994 	sldns_buffer* buf = sldns_buffer_new(65535);
    995 	struct regional* region = regional_create();
    996 	if(!(buf && region)) {
    997 		log_err("%s: log_dns_msg: out of memory", str);
    998 		sldns_buffer_free(buf);
    999 		regional_destroy(region);
   1000 		return;
   1001 	}
   1002 	if(!reply_info_encode(qinfo, rep, 0, rep->flags, buf, 0,
   1003 		region, 65535, 1, 0)) {
   1004 		log_err("%s: log_dns_msg: out of memory", str);
   1005 	} else {
   1006 		char* s = sldns_wire2str_pkt(sldns_buffer_begin(buf),
   1007 			sldns_buffer_limit(buf));
   1008 		if(!s) {
   1009 			log_info("%s: log_dns_msg: ldns tostr failed", str);
   1010 		} else {
   1011 			log_info("%s %s", str, s);
   1012 		}
   1013 		free(s);
   1014 	}
   1015 	sldns_buffer_free(buf);
   1016 	regional_destroy(region);
   1017 }
   1018 
   1019 void
   1020 log_reply_info(enum verbosity_value v, struct query_info *qinf,
   1021 	struct sockaddr_storage *addr, socklen_t addrlen, struct timeval dur,
   1022 	int cached, struct sldns_buffer *rmsg, struct sockaddr_storage* daddr,
   1023 	enum comm_point_type tp, void* ssl)
   1024 {
   1025 	char clientip_buf[128];
   1026 	char rcode_buf[16];
   1027 	char dest_buf[160];
   1028 	uint16_t rcode = FLAGS_GET_RCODE(sldns_buffer_read_u16_at(rmsg, 2));
   1029 
   1030 	if(verbosity < v)
   1031 	  return;
   1032 
   1033 	sldns_wire2str_rcode_buf((int)rcode, rcode_buf, sizeof(rcode_buf));
   1034 	addr_to_str(addr, addrlen, clientip_buf, sizeof(clientip_buf));
   1035 	if(daddr) {
   1036 		char da[128];
   1037 		int port = 0;
   1038 		char* comm;
   1039 		if(daddr->ss_family == AF_INET6) {
   1040 			struct sockaddr_in6 *d = (struct sockaddr_in6 *)daddr;
   1041 			if(inet_ntop(d->sin6_family, &d->sin6_addr, da,
   1042 				sizeof(da)) == 0)
   1043 				snprintf(dest_buf, sizeof(dest_buf),
   1044 					"(inet_ntop_error)");
   1045 			port = ntohs(d->sin6_port);
   1046 		} else if(daddr->ss_family == AF_INET) {
   1047 			struct sockaddr_in *d = (struct sockaddr_in *)daddr;
   1048 			if(inet_ntop(d->sin_family, &d->sin_addr, da,
   1049 				sizeof(da)) == 0)
   1050 				snprintf(dest_buf, sizeof(dest_buf),
   1051 					"(inet_ntop_error)");
   1052 			port = ntohs(d->sin_port);
   1053 		} else {
   1054 			snprintf(da, sizeof(da), "socket%d",
   1055 				(int)daddr->ss_family);
   1056 		}
   1057 		comm = "udp";
   1058 		if(tp == comm_tcp) comm = (ssl?"dot":"tcp");
   1059 		else if(tp == comm_tcp_accept) comm = (ssl?"dot":"tcp");
   1060 		else if(tp == comm_http) comm = "doh";
   1061 		else if(tp == comm_local) comm = "unix";
   1062 		else if(tp == comm_raw) comm = "raw";
   1063 		snprintf(dest_buf, sizeof(dest_buf), " on %s %s %d",
   1064 			comm, da, port);
   1065 	} else {
   1066 		dest_buf[0]=0;
   1067 	}
   1068 	if(rcode == LDNS_RCODE_FORMERR)
   1069 	{
   1070 		if(LOG_TAG_QUERYREPLY)
   1071 			log_reply("%s - - - %s - - -%s", clientip_buf,
   1072 				rcode_buf, dest_buf);
   1073 		else	log_info("%s - - - %s - - -%s", clientip_buf,
   1074 				rcode_buf, dest_buf);
   1075 	} else {
   1076 		char qname_buf[LDNS_MAX_DOMAINLEN];
   1077 		char type_buf[16];
   1078 		char class_buf[16];
   1079 		size_t pktlen;
   1080 		if(qinf->qname)
   1081 			dname_str(qinf->qname, qname_buf);
   1082 		else	snprintf(qname_buf, sizeof(qname_buf), "null");
   1083 		pktlen = sldns_buffer_limit(rmsg);
   1084 		sldns_wire2str_type_buf(qinf->qtype, type_buf, sizeof(type_buf));
   1085 		sldns_wire2str_class_buf(qinf->qclass, class_buf, sizeof(class_buf));
   1086 		if(LOG_TAG_QUERYREPLY)
   1087 		     log_reply("%s %s %s %s %s " ARG_LL "d.%6.6d %d %d%s",
   1088 			clientip_buf, qname_buf, type_buf, class_buf,
   1089 			rcode_buf, (long long)dur.tv_sec, (int)dur.tv_usec,
   1090 			cached, (int)pktlen, dest_buf);
   1091 		else log_info("%s %s %s %s %s " ARG_LL "d.%6.6d %d %d%s",
   1092 			clientip_buf, qname_buf, type_buf, class_buf,
   1093 			rcode_buf, (long long)dur.tv_sec, (int)dur.tv_usec,
   1094 			cached, (int)pktlen, dest_buf);
   1095 	}
   1096 }
   1097 
   1098 void
   1099 log_query_info(enum verbosity_value v, const char* str,
   1100 	struct query_info* qinf)
   1101 {
   1102 	log_nametypeclass(v, str, qinf->qname, qinf->qtype, qinf->qclass);
   1103 }
   1104 
   1105 int
   1106 reply_check_cname_chain(struct query_info* qinfo, struct reply_info* rep)
   1107 {
   1108 	/* check only answer section rrs for matching cname chain.
   1109 	 * the cache may return changed rdata, but owner names are untouched.*/
   1110 	size_t i;
   1111 	uint8_t* sname = qinfo->qname;
   1112 	size_t snamelen = qinfo->qname_len;
   1113 	for(i=0; i<rep->an_numrrsets; i++) {
   1114 		uint16_t t = ntohs(rep->rrsets[i]->rk.type);
   1115 		if(t == LDNS_RR_TYPE_DNAME)
   1116 			continue; /* skip dnames; note TTL 0 not cached */
   1117 		/* verify that owner matches current sname */
   1118 		if(query_dname_compare(sname, rep->rrsets[i]->rk.dname) != 0){
   1119 			/* cname chain broken */
   1120 			return 0;
   1121 		}
   1122 		/* if this is a cname; move on */
   1123 		if(t == LDNS_RR_TYPE_CNAME) {
   1124 			get_cname_target(rep->rrsets[i], &sname, &snamelen);
   1125 		}
   1126 	}
   1127 	return 1;
   1128 }
   1129 
   1130 int
   1131 reply_all_rrsets_secure(struct reply_info* rep)
   1132 {
   1133 	size_t i;
   1134 	for(i=0; i<rep->rrset_count; i++) {
   1135 		if( ((struct packed_rrset_data*)rep->rrsets[i]->entry.data)
   1136 			->security != sec_status_secure )
   1137 		return 0;
   1138 	}
   1139 	return 1;
   1140 }
   1141 
   1142 int reply_an_ns_rrsets_secure(struct reply_info* rep)
   1143 {
   1144 	size_t i;
   1145 	for(i=0; i<rep->an_numrrsets+rep->ns_numrrsets; i++) {
   1146 		if( ((struct packed_rrset_data*)rep->rrsets[i]->entry.data)
   1147 			->security != sec_status_secure )
   1148 		return 0;
   1149 	}
   1150 	return 1;
   1151 }
   1152 
   1153 struct reply_info*
   1154 parse_reply_in_temp_region(sldns_buffer* pkt, struct regional* region,
   1155 	struct query_info* qi)
   1156 {
   1157 	struct reply_info* rep;
   1158 	struct msg_parse* msg;
   1159 	if(!(msg = regional_alloc(region, sizeof(*msg)))) {
   1160 		return NULL;
   1161 	}
   1162 	memset(msg, 0, sizeof(*msg));
   1163 	sldns_buffer_set_position(pkt, 0);
   1164 	if(parse_packet(pkt, msg, region) != 0){
   1165 		return 0;
   1166 	}
   1167 	if(!parse_create_msg(pkt, msg, NULL, qi, &rep, region)) {
   1168 		return 0;
   1169 	}
   1170 	return rep;
   1171 }
   1172 
   1173 int edns_opt_list_append_ede(struct edns_option** list, struct regional* region,
   1174 	sldns_ede_code code, const char *txt)
   1175 {
   1176 	struct edns_option** prevp;
   1177 	struct edns_option* opt;
   1178 	size_t txt_len = txt ? strlen(txt) : 0;
   1179 
   1180 	/* allocate new element */
   1181 	opt = (struct edns_option*)regional_alloc(region, sizeof(*opt));
   1182 	if(!opt)
   1183 		return 0;
   1184 	opt->next = NULL;
   1185 	opt->opt_code = LDNS_EDNS_EDE;
   1186 	opt->opt_len = txt_len + sizeof(uint16_t);
   1187 	opt->opt_data = regional_alloc(region, txt_len + sizeof(uint16_t));
   1188 	if(!opt->opt_data)
   1189 		return 0;
   1190 	sldns_write_uint16(opt->opt_data, (uint16_t)code);
   1191 	if (txt_len)
   1192 		memmove(opt->opt_data + 2, txt, txt_len);
   1193 
   1194 	/* append at end of list */
   1195 	prevp = list;
   1196 	while(*prevp != NULL)
   1197 		prevp = &((*prevp)->next);
   1198 	verbose(VERB_ALGO, "attached EDE code: %d with message: '%s'", code, (txt?txt:""));
   1199 	*prevp = opt;
   1200 	return 1;
   1201 }
   1202 
   1203 int edns_opt_list_append_keepalive(struct edns_option** list, int msec,
   1204 	struct regional* region)
   1205 {
   1206 	uint8_t data[2]; /* For keepalive value */
   1207 	data[0] = (uint8_t)((msec >> 8) & 0xff);
   1208 	data[1] = (uint8_t)(msec & 0xff);
   1209 	return edns_opt_list_append(list, LDNS_EDNS_KEEPALIVE, sizeof(data),
   1210 		data, region);
   1211 }
   1212 
   1213 int edns_opt_list_append(struct edns_option** list, uint16_t code, size_t len,
   1214 	uint8_t* data, struct regional* region)
   1215 {
   1216 	struct edns_option** prevp;
   1217 	struct edns_option* opt;
   1218 
   1219 	/* allocate new element */
   1220 	opt = (struct edns_option*)regional_alloc(region, sizeof(*opt));
   1221 	if(!opt)
   1222 		return 0;
   1223 	opt->next = NULL;
   1224 	opt->opt_code = code;
   1225 	opt->opt_len = len;
   1226 	opt->opt_data = NULL;
   1227 	if(len > 0) {
   1228 		opt->opt_data = regional_alloc_init(region, data, len);
   1229 		if(!opt->opt_data)
   1230 			return 0;
   1231 	}
   1232 
   1233 	/* append at end of list */
   1234 	prevp = list;
   1235 	while(*prevp != NULL) {
   1236 		prevp = &((*prevp)->next);
   1237 	}
   1238 	*prevp = opt;
   1239 	return 1;
   1240 }
   1241 
   1242 int edns_opt_list_remove(struct edns_option** list, uint16_t code)
   1243 {
   1244 	/* The list should already be allocated in a region. Freeing the
   1245 	 * allocated space in a region is not possible. We just unlink the
   1246 	 * required elements and they will be freed together with the region. */
   1247 
   1248 	struct edns_option* prev;
   1249 	struct edns_option* curr;
   1250 	if(!list || !(*list)) return 0;
   1251 
   1252 	/* Unlink and repoint if the element(s) are first in list */
   1253 	while(list && *list && (*list)->opt_code == code) {
   1254 		*list = (*list)->next;
   1255 	}
   1256 
   1257 	if(!list || !(*list)) return 1;
   1258 	/* Unlink elements and reattach the list */
   1259 	prev = *list;
   1260 	curr = (*list)->next;
   1261 	while(curr != NULL) {
   1262 		if(curr->opt_code == code) {
   1263 			prev->next = curr->next;
   1264 			curr = curr->next;
   1265 		} else {
   1266 			prev = curr;
   1267 			curr = curr->next;
   1268 		}
   1269 	}
   1270 	return 1;
   1271 }
   1272 
   1273 static int inplace_cb_reply_call_generic(
   1274     struct inplace_cb* callback_list, enum inplace_cb_list_type type,
   1275 	struct query_info* qinfo, struct module_qstate* qstate,
   1276 	struct reply_info* rep, int rcode, struct edns_data* edns,
   1277 	struct comm_reply* repinfo, struct regional* region,
   1278 	struct timeval* start_time)
   1279 {
   1280 	struct inplace_cb* cb;
   1281 	struct edns_option* opt_list_out = NULL;
   1282 #if defined(EXPORT_ALL_SYMBOLS)
   1283 	(void)type; /* param not used when fptr_ok disabled */
   1284 #endif
   1285 	if(qstate)
   1286 		opt_list_out = qstate->edns_opts_front_out;
   1287 	for(cb=callback_list; cb; cb=cb->next) {
   1288 		fptr_ok(fptr_whitelist_inplace_cb_reply_generic(
   1289 			(inplace_cb_reply_func_type*)cb->cb, type));
   1290 		(void)(*(inplace_cb_reply_func_type*)cb->cb)(qinfo, qstate, rep,
   1291 			rcode, edns, &opt_list_out, repinfo, region, start_time, cb->id, cb->cb_arg);
   1292 	}
   1293 	edns->opt_list_inplace_cb_out = opt_list_out;
   1294 	return 1;
   1295 }
   1296 
   1297 int inplace_cb_reply_call(struct module_env* env, struct query_info* qinfo,
   1298 	struct module_qstate* qstate, struct reply_info* rep, int rcode,
   1299 	struct edns_data* edns, struct comm_reply* repinfo, struct regional* region,
   1300 	struct timeval* start_time)
   1301 {
   1302 	return inplace_cb_reply_call_generic(
   1303 		env->inplace_cb_lists[inplace_cb_reply], inplace_cb_reply, qinfo,
   1304 		qstate, rep, rcode, edns, repinfo, region, start_time);
   1305 }
   1306 
   1307 int inplace_cb_reply_cache_call(struct module_env* env,
   1308 	struct query_info* qinfo, struct module_qstate* qstate,
   1309 	struct reply_info* rep, int rcode, struct edns_data* edns,
   1310 	struct comm_reply* repinfo, struct regional* region,
   1311 	struct timeval* start_time)
   1312 {
   1313 	return inplace_cb_reply_call_generic(
   1314 		env->inplace_cb_lists[inplace_cb_reply_cache], inplace_cb_reply_cache,
   1315 		qinfo, qstate, rep, rcode, edns, repinfo, region, start_time);
   1316 }
   1317 
   1318 int inplace_cb_reply_local_call(struct module_env* env,
   1319 	struct query_info* qinfo, struct module_qstate* qstate,
   1320 	struct reply_info* rep, int rcode, struct edns_data* edns,
   1321 	struct comm_reply* repinfo, struct regional* region,
   1322 	struct timeval* start_time)
   1323 {
   1324 	return inplace_cb_reply_call_generic(
   1325 		env->inplace_cb_lists[inplace_cb_reply_local], inplace_cb_reply_local,
   1326 		qinfo, qstate, rep, rcode, edns, repinfo, region, start_time);
   1327 }
   1328 
   1329 int inplace_cb_reply_servfail_call(struct module_env* env,
   1330 	struct query_info* qinfo, struct module_qstate* qstate,
   1331 	struct reply_info* rep, int rcode, struct edns_data* edns,
   1332 	struct comm_reply* repinfo, struct regional* region,
   1333 	struct timeval* start_time)
   1334 {
   1335 	/* We are going to servfail. Remove any potential edns options. */
   1336 	if(qstate)
   1337 		qstate->edns_opts_front_out = NULL;
   1338 	return inplace_cb_reply_call_generic(
   1339 		env->inplace_cb_lists[inplace_cb_reply_servfail],
   1340 		inplace_cb_reply_servfail, qinfo, qstate, rep, rcode, edns, repinfo,
   1341 		region, start_time);
   1342 }
   1343 
   1344 int inplace_cb_query_call(struct module_env* env, struct query_info* qinfo,
   1345 	uint16_t flags, struct sockaddr_storage* addr, socklen_t addrlen,
   1346 	uint8_t* zone, size_t zonelen, struct module_qstate* qstate,
   1347 	struct regional* region)
   1348 {
   1349 	struct inplace_cb* cb = env->inplace_cb_lists[inplace_cb_query];
   1350 	for(; cb; cb=cb->next) {
   1351 		fptr_ok(fptr_whitelist_inplace_cb_query(
   1352 			(inplace_cb_query_func_type*)cb->cb));
   1353 		(void)(*(inplace_cb_query_func_type*)cb->cb)(qinfo, flags,
   1354 			qstate, addr, addrlen, zone, zonelen, region,
   1355 			cb->id, cb->cb_arg);
   1356 	}
   1357 	return 1;
   1358 }
   1359 
   1360 int inplace_cb_edns_back_parsed_call(struct module_env* env,
   1361 	struct module_qstate* qstate)
   1362 {
   1363 	struct inplace_cb* cb =
   1364 		env->inplace_cb_lists[inplace_cb_edns_back_parsed];
   1365 	for(; cb; cb=cb->next) {
   1366 		fptr_ok(fptr_whitelist_inplace_cb_edns_back_parsed(
   1367 			(inplace_cb_edns_back_parsed_func_type*)cb->cb));
   1368 		(void)(*(inplace_cb_edns_back_parsed_func_type*)cb->cb)(qstate,
   1369 			cb->id, cb->cb_arg);
   1370 	}
   1371 	return 1;
   1372 }
   1373 
   1374 int inplace_cb_query_response_call(struct module_env* env,
   1375 	struct module_qstate* qstate, struct dns_msg* response) {
   1376 	struct inplace_cb* cb =
   1377 		env->inplace_cb_lists[inplace_cb_query_response];
   1378 	for(; cb; cb=cb->next) {
   1379 		fptr_ok(fptr_whitelist_inplace_cb_query_response(
   1380 			(inplace_cb_query_response_func_type*)cb->cb));
   1381 		(void)(*(inplace_cb_query_response_func_type*)cb->cb)(qstate,
   1382 			response, cb->id, cb->cb_arg);
   1383 	}
   1384 	return 1;
   1385 }
   1386 
   1387 struct edns_option* edns_opt_copy_region(struct edns_option* list,
   1388 	struct regional* region)
   1389 {
   1390 	struct edns_option* result = NULL, *cur = NULL, *s;
   1391 	while(list) {
   1392 		/* copy edns option structure */
   1393 		s = regional_alloc_init(region, list, sizeof(*list));
   1394 		if(!s) return NULL;
   1395 		s->next = NULL;
   1396 
   1397 		/* copy option data */
   1398 		if(s->opt_data) {
   1399 			s->opt_data = regional_alloc_init(region, s->opt_data,
   1400 				s->opt_len);
   1401 			if(!s->opt_data)
   1402 				return NULL;
   1403 		}
   1404 
   1405 		/* link into list */
   1406 		if(cur)
   1407 			cur->next = s;
   1408 		else	result = s;
   1409 		cur = s;
   1410 
   1411 		/* examine next element */
   1412 		list = list->next;
   1413 	}
   1414 	return result;
   1415 }
   1416 
   1417 struct edns_option* edns_opt_copy_filter_region(struct edns_option* list,
   1418 	uint16_t* filter_list, size_t filter_list_len, struct regional* region)
   1419 {
   1420 	struct edns_option* result = NULL, *cur = NULL, *s;
   1421 	size_t i;
   1422 	while(list) {
   1423 		for(i=0; i<filter_list_len; i++)
   1424 			if(filter_list[i] == list->opt_code) goto found;
   1425 		if(i == filter_list_len) goto next;
   1426 found:
   1427 		/* copy edns option structure */
   1428 		s = regional_alloc_init(region, list, sizeof(*list));
   1429 		if(!s) return NULL;
   1430 		s->next = NULL;
   1431 
   1432 		/* copy option data */
   1433 		if(s->opt_data) {
   1434 			s->opt_data = regional_alloc_init(region, s->opt_data,
   1435 				s->opt_len);
   1436 			if(!s->opt_data)
   1437 				return NULL;
   1438 		}
   1439 
   1440 		/* link into list */
   1441 		if(cur)
   1442 			cur->next = s;
   1443 		else	result = s;
   1444 		cur = s;
   1445 
   1446 next:
   1447 		/* examine next element */
   1448 		list = list->next;
   1449 	}
   1450 	return result;
   1451 }
   1452 
   1453 int edns_opt_compare(struct edns_option* p, struct edns_option* q)
   1454 {
   1455 	if(!p && !q) return 0;
   1456 	if(!p) return -1;
   1457 	if(!q) return 1;
   1458 	log_assert(p && q);
   1459 	if(p->opt_code != q->opt_code)
   1460 		return (int)q->opt_code - (int)p->opt_code;
   1461 	if(p->opt_len != q->opt_len)
   1462 		return (int)q->opt_len - (int)p->opt_len;
   1463 	if(p->opt_len != 0)
   1464 		return memcmp(p->opt_data, q->opt_data, p->opt_len);
   1465 	return 0;
   1466 }
   1467 
   1468 int edns_opt_list_compare(struct edns_option* p, struct edns_option* q)
   1469 {
   1470 	int r;
   1471 	while(p && q) {
   1472 		r = edns_opt_compare(p, q);
   1473 		if(r != 0)
   1474 			return r;
   1475 		p = p->next;
   1476 		q = q->next;
   1477 	}
   1478 	if(p || q) {
   1479 		/* uneven length lists */
   1480 		if(p) return 1;
   1481 		if(q) return -1;
   1482 	}
   1483 	return 0;
   1484 }
   1485 
   1486 void edns_opt_list_free(struct edns_option* list)
   1487 {
   1488 	struct edns_option* n;
   1489 	while(list) {
   1490 		free(list->opt_data);
   1491 		n = list->next;
   1492 		free(list);
   1493 		list = n;
   1494 	}
   1495 }
   1496 
   1497 struct edns_option* edns_opt_copy_alloc(struct edns_option* list)
   1498 {
   1499 	struct edns_option* result = NULL, *cur = NULL, *s;
   1500 	while(list) {
   1501 		/* copy edns option structure */
   1502 		s = memdup(list, sizeof(*list));
   1503 		if(!s) {
   1504 			edns_opt_list_free(result);
   1505 			return NULL;
   1506 		}
   1507 		s->next = NULL;
   1508 
   1509 		/* copy option data */
   1510 		if(s->opt_data) {
   1511 			s->opt_data = memdup(s->opt_data, s->opt_len);
   1512 			if(!s->opt_data) {
   1513 				free(s);
   1514 				edns_opt_list_free(result);
   1515 				return NULL;
   1516 			}
   1517 		}
   1518 
   1519 		/* link into list */
   1520 		if(cur)
   1521 			cur->next = s;
   1522 		else	result = s;
   1523 		cur = s;
   1524 
   1525 		/* examine next element */
   1526 		list = list->next;
   1527 	}
   1528 	return result;
   1529 }
   1530 
   1531 struct edns_option* edns_opt_list_find(struct edns_option* list, uint16_t code)
   1532 {
   1533 	struct edns_option* p;
   1534 	for(p=list; p; p=p->next) {
   1535 		if(p->opt_code == code)
   1536 			return p;
   1537 	}
   1538 	return NULL;
   1539 }
   1540 
   1541 int local_alias_shallow_copy_qname(struct local_rrset* local_alias, uint8_t** qname,
   1542 	size_t* qname_len)
   1543 {
   1544 	struct ub_packed_rrset_key* rrset;
   1545 	struct packed_rrset_data* d;
   1546 	rrset = local_alias->rrset;
   1547 	if(!rrset) return 0;
   1548 	d = rrset->entry.data;
   1549 	if(!d) return 0;
   1550 
   1551 	/* Sanity check: our current implementation only supports
   1552 	    * a single CNAME RRset as a local alias. */
   1553 	if(local_alias->next ||
   1554 		rrset->rk.type != htons(LDNS_RR_TYPE_CNAME) ||
   1555 		d->count != 1) {
   1556 		log_err("assumption failure: unexpected local alias");
   1557 		return 0;
   1558 	}
   1559 	*qname = d->rr_data[0] + 2;
   1560 	*qname_len = d->rr_len[0] - 2;
   1561 	return 1;
   1562 }
   1563