1 /* 2 * util/data/packed_rrset.h - data storage for a set of resource records. 3 * 4 * Copyright (c) 2007, NLnet Labs. All rights reserved. 5 * 6 * This software is open source. 7 * 8 * Redistribution and use in source and binary forms, with or without 9 * modification, are permitted provided that the following conditions 10 * are met: 11 * 12 * Redistributions of source code must retain the above copyright notice, 13 * this list of conditions and the following disclaimer. 14 * 15 * Redistributions in binary form must reproduce the above copyright notice, 16 * this list of conditions and the following disclaimer in the documentation 17 * and/or other materials provided with the distribution. 18 * 19 * Neither the name of the NLNET LABS nor the names of its contributors may 20 * be used to endorse or promote products derived from this software without 21 * specific prior written permission. 22 * 23 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS 24 * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT 25 * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR 26 * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT 27 * HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, 28 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED 29 * TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR 30 * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF 31 * LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING 32 * NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS 33 * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 34 */ 35 36 /** 37 * \file 38 * 39 * This file contains the data storage for RRsets. 40 */ 41 42 #ifndef UTIL_DATA_PACKED_RRSET_H 43 #define UTIL_DATA_PACKED_RRSET_H 44 #include "util/storage/lruhash.h" 45 struct alloc_cache; 46 struct regional; 47 48 /** type used to uniquely identify rrsets. Cannot be reused without 49 * clearing the cache. */ 50 typedef uint64_t rrset_id_type; 51 52 /** this rrset is NSEC and is at zone apex (at child side of zonecut) */ 53 #define PACKED_RRSET_NSEC_AT_APEX 0x1 54 /** this rrset is A/AAAA and is in-zone-glue (from parent side of zonecut) */ 55 #define PACKED_RRSET_PARENT_SIDE 0x2 56 /** this rrset is SOA and has the negative ttl (from nxdomain or nodata), 57 * this is set on SOA rrsets in the authority section, to keep its TTL separate 58 * from the SOA in the answer section from a direct SOA query or ANY query. */ 59 #define PACKED_RRSET_SOA_NEG 0x4 60 /** This rrset is considered to have a fixed TTL; its TTL doesn't have to be 61 * updated on encoding in a reply. This flag is not expected to be set in 62 * cached data. */ 63 #define PACKED_RRSET_FIXEDTTL 0x80000000 64 /** This rrset is from RPZ. It is not real, it is synthesized data to block 65 * access. The flag makes lookups, from cache in iterator, ignore the fake 66 * items and only use actual data. Eg. when the iterator looksup NS, CNAME, 67 * A and AAAA types, it then gets items without this flag that are the 68 * actual network. But messages with these records in it can be stored in 69 * the cache and retrieved for a reply. */ 70 #define PACKED_RRSET_RPZ 0x8 71 /** this rrset is A/AAAA and is an unverified glue record */ 72 #define PACKED_RRSET_UNVERIFIED_GLUE 0x10 73 /** this rrset has a 0TTL from upstream */ 74 #define PACKED_RRSET_UPSTREAM_0TTL 0x20 75 /** this rrset has 0TTL from upstream and also has had grace TTL applied */ 76 #define PACKED_RRSET_0TTL_GRACE 0x40 77 78 /** number of rrs and rrsets for integer overflow protection. More than 79 * this is not really possible (64K packet has much less RRs and RRsets) in 80 * a message. And this is small enough that also multiplied there is no 81 * integer overflow. */ 82 #define RR_COUNT_MAX 0xffffff 83 84 /** 85 * The identifying information for an RRset. 86 */ 87 struct packed_rrset_key { 88 /** 89 * The domain name. If not null (for id=0) it is allocated, and 90 * contains the wireformat domain name. 91 * This dname is not canonicalized. 92 */ 93 uint8_t* dname; 94 /** 95 * Length of the domain name, including last 0 root octet. 96 */ 97 size_t dname_len; 98 /** 99 * Flags. 32bit to be easy for hashing: 100 * o PACKED_RRSET_NSEC_AT_APEX 101 * o PACKED_RRSET_PARENT_SIDE 102 * o PACKED_RRSET_SOA_NEG 103 * o PACKED_RRSET_FIXEDTTL (not supposed to be cached) 104 * o PACKED_RRSET_RPZ 105 * o PACKED_RRSET_UNVERIFIED_GLUE 106 * o PACKED_RRSET_UPSTREAM_0TTL (not supposed to be cached) 107 */ 108 uint32_t flags; 109 /** the rrset type in network format */ 110 uint16_t type; 111 /** the rrset class in network format */ 112 uint16_t rrset_class; 113 }; 114 115 /** 116 * This structure contains an RRset. A set of resource records that 117 * share the same domain name, type and class. 118 * 119 * Due to memory management and threading, the key structure cannot be 120 * deleted, although the data can be. The id can be set to 0 to store and the 121 * structure can be recycled with a new id. 122 */ 123 struct ub_packed_rrset_key { 124 /** 125 * entry into hashtable. Note the lock is never destroyed, 126 * even when this key is retired to the cache. 127 * the data pointer (if not null) points to a struct packed_rrset. 128 */ 129 struct lruhash_entry entry; 130 /** 131 * the ID of this rrset. unique, based on threadid + sequenceno. 132 * ids are not reused, except after flushing the cache. 133 * zero is an unused entry, and never a valid id. 134 * Check this value after getting entry.lock. 135 * The other values in this struct may only be altered after changing 136 * the id (which needs a writelock on entry.lock). 137 */ 138 rrset_id_type id; 139 /** key data: dname, type and class */ 140 struct packed_rrset_key rk; 141 }; 142 143 /** 144 * RRset trustworthiness. Bigger value is more trust. RFC 2181. 145 * The rrset_trust_add_noAA, rrset_trust_auth_noAA, rrset_trust_add_AA, 146 * are mentioned as the same trustworthiness in 2181, but split up here 147 * for ease of processing. 148 * 149 * rrset_trust_nonauth_ans_AA, rrset_trust_ans_noAA 150 * are also mentioned as the same trustworthiness in 2181, but split up here 151 * for ease of processing. 152 * 153 * Added trust_none for a sane initial value, smaller than anything else. 154 * Added validated and ultimate trust for keys and rrsig validated content. 155 */ 156 enum rrset_trust { 157 /** initial value for trust */ 158 rrset_trust_none = 0, 159 /** Additional information from non-authoritative answers */ 160 rrset_trust_add_noAA, 161 /** Data from the authority section of a non-authoritative answer */ 162 rrset_trust_auth_noAA, 163 /** Additional information from an authoritative answer */ 164 rrset_trust_add_AA, 165 /** non-authoritative data from the answer section of authoritative 166 * answers */ 167 rrset_trust_nonauth_ans_AA, 168 /** Data from the answer section of a non-authoritative answer */ 169 rrset_trust_ans_noAA, 170 /** Glue from a primary zone, or glue from a zone transfer */ 171 rrset_trust_glue, 172 /** Data from the authority section of an authoritative answer */ 173 rrset_trust_auth_AA, 174 /** The authoritative data included in the answer section of an 175 * authoritative reply */ 176 rrset_trust_ans_AA, 177 /** Data from a zone transfer, other than glue */ 178 rrset_trust_sec_noglue, 179 /** Data from a primary zone file, other than glue data */ 180 rrset_trust_prim_noglue, 181 /** DNSSEC(rfc4034) validated with trusted keys */ 182 rrset_trust_validated, 183 /** ultimately trusted, no more trust is possible; 184 * trusted keys from the unbound configuration setup. */ 185 rrset_trust_ultimate 186 }; 187 188 /** 189 * Security status from validation for data. 190 * The order is significant; more secure, more proven later. 191 */ 192 enum sec_status { 193 /** UNCHECKED means that object has yet to be validated. */ 194 sec_status_unchecked = 0, 195 /** BOGUS means that the object (RRset or message) failed to validate 196 * (according to local policy), but should have validated. */ 197 sec_status_bogus, 198 /** INDETERMINATE means that the object is insecure, but not 199 * authoritatively so. Generally this means that the RRset is not 200 * below a configured trust anchor. */ 201 sec_status_indeterminate, 202 /** INSECURE means that the object is authoritatively known to be 203 * insecure. Generally this means that this RRset is below a trust 204 * anchor, but also below a verified, insecure delegation. */ 205 sec_status_insecure, 206 /** SECURE_SENTINEL_FAIL means that the object (RRset or message) 207 * validated according to local policy but did not succeed in the root 208 * KSK sentinel test (draft-ietf-dnsop-kskroll-sentinel). */ 209 sec_status_secure_sentinel_fail, 210 /** SECURE means that the object (RRset or message) validated 211 * according to local policy. */ 212 sec_status_secure 213 }; 214 215 /** 216 * RRset data. 217 * 218 * The data is packed, stored contiguously in memory. 219 * 220 * It is not always stored contiguously, in that case, an unpacked-packed 221 * rrset has the arrays separate. A bunch of routines work on that, but 222 * the packed rrset that is contiguous is for the rrset-cache and the 223 * cache-response routines in daemon/worker.c. 224 * 225 * memory layout: 226 * o base struct 227 * o rr_len size_t array 228 * o rr_data uint8_t* array 229 * o rr_ttl time_t array (after size_t and ptrs because those may be 230 * 64bit and this array before those would make them unaligned). 231 * Since the stuff before is 32/64bit, rr_ttl is 32 bit aligned. 232 * o rr_data rdata wireformats 233 * o rrsig_data rdata wireformat(s) 234 * 235 * Rdata is stored in wireformat. The dname is stored in wireformat. 236 * TTLs are stored as absolute values (and could be expired). 237 * 238 * RRSIGs are stored in the arrays after the regular rrs. 239 * 240 * You need the packed_rrset_key to know dname, type, class of the 241 * resource records in this RRset. (if signed the rrsig gives the type too). 242 * 243 * On the wire an RR is: 244 * name, type, class, ttl, rdlength, rdata. 245 * So we need to send the following per RR: 246 * key.dname, ttl, rr_data[i]. 247 * since key.dname ends with type and class. 248 * and rr_data starts with the rdlength. 249 * the ttl value to send changes due to time. 250 */ 251 struct packed_rrset_data { 252 /** Timestamp added to TTLs in the packed data. 253 * Needed to support serving original TTLs. */ 254 time_t ttl_add; 255 /** TTL (in seconds like time()) of the rrset. 256 * Same for all RRs see rfc2181(5.2). */ 257 time_t ttl; 258 /** number of rrs. */ 259 size_t count; 260 /** number of rrsigs, if 0 no rrsigs */ 261 size_t rrsig_count; 262 /** the trustworthiness of the rrset data */ 263 enum rrset_trust trust; 264 /** security status of the rrset data */ 265 enum sec_status security; 266 /** length of every rr's rdata, rr_len[i] is size of rr_data[i]. */ 267 size_t* rr_len; 268 /** ttl of every rr. rr_ttl[i] ttl of rr i. */ 269 time_t *rr_ttl; 270 /** 271 * Array of pointers to every rr's rdata. 272 * The rr_data[i] rdata is stored in uncompressed wireformat. 273 * The first uint16_t of rr_data[i] is network format rdlength. 274 * 275 * rr_data[count] to rr_data[count+rrsig_count] contain the rrsig data. 276 */ 277 uint8_t** rr_data; 278 }; 279 280 /** 281 * An RRset can be represented using both key and data together. 282 * Split into key and data structures to simplify implementation of 283 * caching schemes. 284 */ 285 struct packed_rrset { 286 /** domain name, type and class */ 287 struct packed_rrset_key* k; 288 /** ttl, count and rdatas (and rrsig) */ 289 struct packed_rrset_data* d; 290 }; 291 292 /** 293 * list of packed rrsets 294 */ 295 struct packed_rrset_list { 296 /** next in list */ 297 struct packed_rrset_list* next; 298 /** rrset key and data */ 299 struct packed_rrset rrset; 300 }; 301 302 /** 303 * Delete packed rrset key and data, not entered in hashtables yet. 304 * Used during parsing. 305 * @param pkey: rrset key structure with locks, key and data pointers. 306 * @param alloc: where to return the unfree-able key structure. 307 */ 308 void ub_packed_rrset_parsedelete(struct ub_packed_rrset_key* pkey, 309 struct alloc_cache* alloc); 310 311 /** 312 * Memory size of rrset data. RRset data must be filled in correctly. 313 * @param data: data to examine. 314 * @return size in bytes. 315 */ 316 size_t packed_rrset_sizeof(struct packed_rrset_data* data); 317 318 /** 319 * Get TTL of rrset. RRset data must be filled in correctly. 320 * @param key: rrset key, with data to examine. 321 * @return ttl value. 322 */ 323 time_t ub_packed_rrset_ttl(struct ub_packed_rrset_key* key); 324 325 /** 326 * Calculate memory size of rrset entry. For hash table usage. 327 * @param key: struct ub_packed_rrset_key*. 328 * @param data: struct packed_rrset_data*. 329 * @return size in bytes. 330 */ 331 size_t ub_rrset_sizefunc(void* key, void* data); 332 333 /** 334 * compares two rrset keys. 335 * @param k1: struct ub_packed_rrset_key*. 336 * @param k2: struct ub_packed_rrset_key*. 337 * @return 0 if equal. 338 */ 339 int ub_rrset_compare(void* k1, void* k2); 340 341 /** 342 * compare two rrset data structures. 343 * Compared rdata and rrsigdata, not the trust or ttl value. 344 * @param d1: data to compare. 345 * @param d2: data to compare. 346 * @return 1 if equal. 347 */ 348 int rrsetdata_equal(struct packed_rrset_data* d1, struct packed_rrset_data* d2); 349 350 /** 351 * Old key to be deleted. RRset keys are recycled via alloc. 352 * The id is set to 0. So that other threads, after acquiring a lock always 353 * get the correct value, in this case the 0 deleted-special value. 354 * @param key: struct ub_packed_rrset_key*. 355 * @param userdata: alloc structure to use for recycling. 356 */ 357 void ub_rrset_key_delete(void* key, void* userdata); 358 359 /** 360 * Old data to be deleted. 361 * @param data: what to delete. 362 * @param userdata: user data ptr. 363 */ 364 void rrset_data_delete(void* data, void* userdata); 365 366 /** 367 * Calculate hash value for a packed rrset key. 368 * @param key: the rrset key with name, type, class, flags. 369 * @return hash value. 370 */ 371 hashvalue_type rrset_key_hash(struct packed_rrset_key* key); 372 373 /** 374 * Fixup pointers in fixed data packed_rrset_data blob. 375 * After a memcpy of the data for example. Will set internal pointers right. 376 * @param data: rrset data structure. Otherwise correctly filled in. 377 */ 378 void packed_rrset_ptr_fixup(struct packed_rrset_data* data); 379 380 /** 381 * Fixup TTLs in fixed data packed_rrset_data blob. 382 * @param data: rrset data structure. Otherwise correctly filled in. 383 * @param add: how many seconds to add, pass time(0) for example. 384 */ 385 void packed_rrset_ttl_add(struct packed_rrset_data* data, time_t add); 386 387 /** 388 * Utility procedure to extract CNAME target name from its rdata. 389 * Failsafes; it will change passed dname to a valid dname or do nothing. 390 * @param rrset: the rrset structure. Must be a CNAME. 391 * Only first RR is used (multiple RRs are technically illegal anyway). 392 * Also works on type DNAME. Returns target name. 393 * @param dname: this pointer is updated to point into the cname rdata. 394 * If a failsafe fails, nothing happens to the pointer (such as the 395 * rdata was not a valid dname, not a CNAME, ...). 396 * @param dname_len: length of dname is returned. 397 */ 398 void get_cname_target(struct ub_packed_rrset_key* rrset, uint8_t** dname, 399 size_t* dname_len); 400 401 /** 402 * Get a printable string for a rrset trust value 403 * @param s: rrset trust value 404 * @return printable string. 405 */ 406 const char* rrset_trust_to_string(enum rrset_trust s); 407 408 /** 409 * Get a printable string for a security status value 410 * @param s: security status 411 * @return printable string. 412 */ 413 const char* sec_status_to_string(enum sec_status s); 414 415 /** 416 * Print string with neat domain name, type, class from rrset. 417 * @param v: at what verbosity level to print this. 418 * @param str: string of message. 419 * @param rrset: structure with name, type and class. 420 */ 421 void log_rrset_key(enum verbosity_value v, const char* str, 422 struct ub_packed_rrset_key* rrset); 423 424 /** 425 * Convert RR from RRset to string. 426 * @param rrset: structure with data. 427 * @param i: index of rr or RRSIG. 428 * @param now: time that is subtracted from ttl before printout. Can be 0. 429 * @param dest: destination string buffer. Must be nonNULL. 430 * @param dest_len: length of dest buffer (>0). 431 * @return false on failure. 432 */ 433 int packed_rr_to_string(struct ub_packed_rrset_key* rrset, size_t i, 434 time_t now, char* dest, size_t dest_len); 435 436 /** 437 * Print the string with prefix, one rr per line. 438 * @param v: at what verbosity level to print this. 439 * @param str: string of message. 440 * @param rrset: with name, and rdata, and rrsigs. 441 */ 442 void log_packed_rrset(enum verbosity_value v, const char* str, 443 struct ub_packed_rrset_key* rrset); 444 445 /** 446 * Allocate rrset in region - no more locks needed 447 * @param key: a (just from rrset cache looked up) rrset key + valid, 448 * packed data record. 449 * @param region: where to alloc the copy 450 * @param now: adjust the TTLs to be relative (subtract from all TTLs). 451 * @return new region-alloced rrset key or NULL on alloc failure. 452 */ 453 struct ub_packed_rrset_key* packed_rrset_copy_region( 454 struct ub_packed_rrset_key* key, struct regional* region, 455 time_t now); 456 457 /** 458 * Allocate rrset with malloc (from region or you are holding the lock). 459 * @param key: key with data entry. 460 * @param alloc: alloc_cache to create rrset_keys 461 * @param now: adjust the TTLs to be absolute (add to all TTLs). 462 * @return new region-alloced rrset key or NULL on alloc failure. 463 */ 464 struct ub_packed_rrset_key* packed_rrset_copy_alloc( 465 struct ub_packed_rrset_key* key, struct alloc_cache* alloc, 466 time_t now); 467 468 /** 469 * Find RR index in packed rrset 470 * Raw comparison, does not canonicalize RDATA 471 * @param d: packed rrset 472 * @param rdata: RDATA of RR to find 473 * @param len: length of rdata 474 * @param index: pointer to int to store index of found RR 475 * @return 1 if RR found, 0 otherwise 476 */ 477 int 478 packed_rrset_find_rr(struct packed_rrset_data* d, uint8_t* rdata, size_t len, 479 size_t* index); 480 481 #endif /* UTIL_DATA_PACKED_RRSET_H */ 482