Home | History | Annotate | Line # | Download | only in cachedb
      1 /*
      2  * cachedb/cachedb.c - cache from a database external to the program module
      3  *
      4  * Copyright (c) 2016, NLnet Labs. All rights reserved.
      5  *
      6  * This software is open source.
      7  *
      8  * Redistribution and use in source and binary forms, with or without
      9  * modification, are permitted provided that the following conditions
     10  * are met:
     11  *
     12  * Redistributions of source code must retain the above copyright notice,
     13  * this list of conditions and the following disclaimer.
     14  *
     15  * Redistributions in binary form must reproduce the above copyright notice,
     16  * this list of conditions and the following disclaimer in the documentation
     17  * and/or other materials provided with the distribution.
     18  *
     19  * Neither the name of the NLNET LABS nor the names of its contributors may
     20  * be used to endorse or promote products derived from this software without
     21  * specific prior written permission.
     22  *
     23  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
     24  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
     25  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
     26  * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
     27  * HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
     28  * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED
     29  * TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
     30  * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
     31  * LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
     32  * NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
     33  * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
     34  */
     35 
     36 /**
     37  * \file
     38  *
     39  * This file contains a module that uses an external database to cache
     40  * dns responses.
     41  */
     42 
     43 #include "config.h"
     44 #ifdef USE_CACHEDB
     45 #include "cachedb/cachedb.h"
     46 #include "cachedb/redis.h"
     47 #include "util/regional.h"
     48 #include "util/net_help.h"
     49 #include "util/config_file.h"
     50 #include "util/data/dname.h"
     51 #include "util/data/msgreply.h"
     52 #include "util/data/msgencode.h"
     53 #include "services/cache/dns.h"
     54 #include "services/mesh.h"
     55 #include "services/modstack.h"
     56 #include "validator/val_neg.h"
     57 #include "validator/val_secalgo.h"
     58 #include "iterator/iter_utils.h"
     59 #include "sldns/parseutil.h"
     60 #include "sldns/wire2str.h"
     61 #include "sldns/sbuffer.h"
     62 
     63 /* header file for htobe64 */
     64 #ifdef HAVE_ENDIAN_H
     65 #  include <endian.h>
     66 #endif
     67 #ifdef HAVE_SYS_ENDIAN_H
     68 #  include <sys/endian.h>
     69 #endif
     70 
     71 #ifndef HAVE_HTOBE64
     72 #  ifdef HAVE_LIBKERN_OSBYTEORDER_H
     73      /* In practice this is specific to MacOS X.  We assume it doesn't have
     74       * htobe64/be64toh but has alternatives with a different name. */
     75 #    include <libkern/OSByteOrder.h>
     76 #    define htobe64(x) OSSwapHostToBigInt64(x)
     77 #    define be64toh(x) OSSwapBigToHostInt64(x)
     78 #  else
     79      /* not OSX */
     80      /* Some compilers do not define __BYTE_ORDER__, like IBM XLC on AIX */
     81 #    if __BIG_ENDIAN__
     82 #      define be64toh(n) (n)
     83 #      define htobe64(n) (n)
     84 #    else
     85 #      define be64toh(n) (((uint64_t)htonl((n) & 0xFFFFFFFF) << 32) | htonl((n) >> 32))
     86 #      define htobe64(n) (((uint64_t)htonl((n) & 0xFFFFFFFF) << 32) | htonl((n) >> 32))
     87 #    endif /* _ENDIAN */
     88 #  endif /* HAVE_LIBKERN_OSBYTEORDER_H */
     89 #endif /* HAVE_BE64TOH */
     90 
     91 /** the unit test testframe for cachedb, its module state contains
     92  * a cache for a couple queries (in memory). */
     93 struct testframe_moddata {
     94 	/** lock for mutex */
     95 	lock_basic_type lock;
     96 	/** key for single stored data element, NULL if none */
     97 	char* stored_key;
     98 	/** data for single stored data element, NULL if none */
     99 	uint8_t* stored_data;
    100 	/** length of stored data */
    101 	size_t stored_datalen;
    102 };
    103 
    104 static int
    105 testframe_init(struct module_env* env, struct cachedb_env* cachedb_env)
    106 {
    107 	struct testframe_moddata* d;
    108 	verbose(VERB_ALGO, "testframe_init");
    109 	d = (struct testframe_moddata*)calloc(1,
    110 		sizeof(struct testframe_moddata));
    111 	cachedb_env->backend_data = (void*)d;
    112 	if(!cachedb_env->backend_data) {
    113 		log_err("out of memory");
    114 		return 0;
    115 	}
    116 	/* Register an EDNS option (65534) to bypass the worker cache lookup
    117 	 * for testing */
    118 	if(!edns_register_option(LDNS_EDNS_UNBOUND_CACHEDB_TESTFRAME_TEST,
    119 		1 /* bypass cache */,
    120 		0 /* no aggregation */, env)) {
    121 		log_err("testframe_init, could not register test opcode");
    122 		free(d);
    123 		return 0;
    124 	}
    125 	lock_basic_init(&d->lock);
    126 	lock_protect(&d->lock, d, sizeof(*d));
    127 	return 1;
    128 }
    129 
    130 static void
    131 testframe_deinit(struct module_env* env, struct cachedb_env* cachedb_env)
    132 {
    133 	struct testframe_moddata* d = (struct testframe_moddata*)
    134 		cachedb_env->backend_data;
    135 	(void)env;
    136 	verbose(VERB_ALGO, "testframe_deinit");
    137 	if(!d)
    138 		return;
    139 	lock_basic_destroy(&d->lock);
    140 	free(d->stored_key);
    141 	free(d->stored_data);
    142 	free(d);
    143 }
    144 
    145 static int
    146 testframe_lookup(struct module_env* env, struct cachedb_env* cachedb_env,
    147 	char* key, struct sldns_buffer* result_buffer)
    148 {
    149 	struct testframe_moddata* d = (struct testframe_moddata*)
    150 		cachedb_env->backend_data;
    151 	(void)env;
    152 	verbose(VERB_ALGO, "testframe_lookup of %s", key);
    153 	lock_basic_lock(&d->lock);
    154 	if(d->stored_key && strcmp(d->stored_key, key) == 0) {
    155 		if(d->stored_datalen > sldns_buffer_capacity(result_buffer)) {
    156 			lock_basic_unlock(&d->lock);
    157 			return 0; /* too large */
    158 		}
    159 		verbose(VERB_ALGO, "testframe_lookup found %d bytes",
    160 			(int)d->stored_datalen);
    161 		sldns_buffer_clear(result_buffer);
    162 		sldns_buffer_write(result_buffer, d->stored_data,
    163 			d->stored_datalen);
    164 		sldns_buffer_flip(result_buffer);
    165 		lock_basic_unlock(&d->lock);
    166 		return 1;
    167 	}
    168 	lock_basic_unlock(&d->lock);
    169 	return 0;
    170 }
    171 
    172 static void
    173 testframe_store(struct module_env* env, struct cachedb_env* cachedb_env,
    174 	char* key, uint8_t* data, size_t data_len, time_t ATTR_UNUSED(ttl))
    175 {
    176 	struct testframe_moddata* d = (struct testframe_moddata*)
    177 		cachedb_env->backend_data;
    178 	(void)env;
    179 	lock_basic_lock(&d->lock);
    180 	verbose(VERB_ALGO, "testframe_store %s (%d bytes)", key, (int)data_len);
    181 
    182 	/* free old data element (if any) */
    183 	free(d->stored_key);
    184 	d->stored_key = NULL;
    185 	free(d->stored_data);
    186 	d->stored_data = NULL;
    187 	d->stored_datalen = 0;
    188 
    189 	d->stored_data = memdup(data, data_len);
    190 	if(!d->stored_data) {
    191 		lock_basic_unlock(&d->lock);
    192 		log_err("out of memory");
    193 		return;
    194 	}
    195 	d->stored_datalen = data_len;
    196 	d->stored_key = strdup(key);
    197 	if(!d->stored_key) {
    198 		free(d->stored_data);
    199 		d->stored_data = NULL;
    200 		d->stored_datalen = 0;
    201 		lock_basic_unlock(&d->lock);
    202 		return;
    203 	}
    204 	lock_basic_unlock(&d->lock);
    205 	/* (key,data) successfully stored */
    206 }
    207 
    208 /** The testframe backend is for unit tests */
    209 static struct cachedb_backend testframe_backend = { "testframe",
    210 	testframe_init, testframe_deinit, testframe_lookup, testframe_store
    211 };
    212 
    213 /** find a particular backend from possible backends */
    214 static struct cachedb_backend*
    215 cachedb_find_backend(const char* str)
    216 {
    217 #ifdef USE_REDIS
    218 	if(strcmp(str, redis_backend.name) == 0)
    219 		return &redis_backend;
    220 #endif
    221 	if(strcmp(str, testframe_backend.name) == 0)
    222 		return &testframe_backend;
    223 	/* TODO add more backends here */
    224 	return NULL;
    225 }
    226 
    227 /** apply configuration to cachedb module 'global' state */
    228 static int
    229 cachedb_apply_cfg(struct cachedb_env* cachedb_env, struct config_file* cfg)
    230 {
    231 	const char* backend_str = cfg->cachedb_backend;
    232 	if(!backend_str || *backend_str==0)
    233 		return 1;
    234 	cachedb_env->backend = cachedb_find_backend(backend_str);
    235 	if(!cachedb_env->backend) {
    236 		log_err("cachedb: cannot find backend name '%s'", backend_str);
    237 		return 0;
    238 	}
    239 
    240 	/* TODO see if more configuration needs to be applied or not */
    241 	return 1;
    242 }
    243 
    244 int
    245 cachedb_init(struct module_env* env, int id)
    246 {
    247 	struct cachedb_env* cachedb_env = (struct cachedb_env*)calloc(1,
    248 		sizeof(struct cachedb_env));
    249 	if(!cachedb_env) {
    250 		log_err("malloc failure");
    251 		return 0;
    252 	}
    253 	env->modinfo[id] = (void*)cachedb_env;
    254 	if(!cachedb_apply_cfg(cachedb_env, env->cfg)) {
    255 		log_err("cachedb: could not apply configuration settings.");
    256 		free(cachedb_env);
    257 		env->modinfo[id] = NULL;
    258 		return 0;
    259 	}
    260 	/* see if a backend is selected */
    261 	if(!cachedb_env->backend || !cachedb_env->backend->name)
    262 		return 1;
    263 	if(!(*cachedb_env->backend->init)(env, cachedb_env)) {
    264 		log_err("cachedb: could not init %s backend",
    265 			cachedb_env->backend->name);
    266 		free(cachedb_env);
    267 		env->modinfo[id] = NULL;
    268 		return 0;
    269 	}
    270 	cachedb_env->enabled = 1;
    271 	return 1;
    272 }
    273 
    274 void
    275 cachedb_deinit(struct module_env* env, int id)
    276 {
    277 	struct cachedb_env* cachedb_env;
    278 	if(!env || !env->modinfo[id])
    279 		return;
    280 	cachedb_env = (struct cachedb_env*)env->modinfo[id];
    281 	if(cachedb_env->enabled) {
    282 		(*cachedb_env->backend->deinit)(env, cachedb_env);
    283 	}
    284 	free(cachedb_env);
    285 	env->modinfo[id] = NULL;
    286 }
    287 
    288 /** new query for cachedb */
    289 static int
    290 cachedb_new(struct module_qstate* qstate, int id)
    291 {
    292 	struct cachedb_qstate* iq = (struct cachedb_qstate*)regional_alloc(
    293 		qstate->region, sizeof(struct cachedb_qstate));
    294 	qstate->minfo[id] = iq;
    295 	if(!iq)
    296 		return 0;
    297 	memset(iq, 0, sizeof(*iq));
    298 	/* initialise it */
    299 	/* TODO */
    300 
    301 	return 1;
    302 }
    303 
    304 /**
    305  * Return an error
    306  * @param qstate: our query state
    307  * @param id: module id
    308  * @param rcode: error code (DNS errcode).
    309  * @return: 0 for use by caller, to make notation easy, like:
    310  * 	return error_response(..).
    311  */
    312 static int
    313 error_response(struct module_qstate* qstate, int id, int rcode)
    314 {
    315 	verbose(VERB_QUERY, "return error response %s",
    316 		sldns_lookup_by_id(sldns_rcodes, rcode)?
    317 		sldns_lookup_by_id(sldns_rcodes, rcode)->name:"??");
    318 	qstate->return_rcode = rcode;
    319 	qstate->return_msg = NULL;
    320 	qstate->ext_state[id] = module_finished;
    321 	return 0;
    322 }
    323 
    324 /**
    325  * Hash the query name, type, class and dbacess-secret into lookup buffer.
    326  * @param qinfo: query info
    327  * @param env: with env->cfg with secret.
    328  * @param buf: returned buffer with hash to lookup
    329  * @param len: length of the buffer.
    330  */
    331 static void
    332 calc_hash(struct query_info* qinfo, struct module_env* env, char* buf,
    333 	size_t len)
    334 {
    335 	uint8_t clear[1024];
    336 	size_t clen = 0;
    337 	uint8_t hash[CACHEDB_HASHSIZE/8];
    338 	const char* hex = "0123456789ABCDEF";
    339 	const char* secret = env->cfg->cachedb_secret;
    340 	size_t i;
    341 
    342 	/* copy the hash info into the clear buffer */
    343 	if(clen + qinfo->qname_len < sizeof(clear)) {
    344 		memmove(clear+clen, qinfo->qname, qinfo->qname_len);
    345 		query_dname_tolower(clear+clen);
    346 		clen += qinfo->qname_len;
    347 	}
    348 	if(clen + 4 < sizeof(clear)) {
    349 		uint16_t t = htons(qinfo->qtype);
    350 		uint16_t c = htons(qinfo->qclass);
    351 		memmove(clear+clen, &t, 2);
    352 		memmove(clear+clen+2, &c, 2);
    353 		clen += 4;
    354 	}
    355 	if(secret && secret[0] && clen + strlen(secret) < sizeof(clear)) {
    356 		memmove(clear+clen, secret, strlen(secret));
    357 		clen += strlen(secret);
    358 	}
    359 
    360 	/* hash the buffer */
    361 	secalgo_hash_sha256(clear, clen, hash);
    362 #ifdef HAVE_EXPLICIT_BZERO
    363 	explicit_bzero(clear, clen);
    364 #else
    365 	memset(clear, 0, clen);
    366 #endif
    367 
    368 	/* hex encode output for portability (some online dbs need
    369 	 * no nulls, no control characters, and so on) */
    370 	log_assert(len >= sizeof(hash)*2 + 1);
    371 	(void)len;
    372 	for(i=0; i<sizeof(hash); i++) {
    373 		buf[i*2] = hex[(hash[i]&0xf0)>>4];
    374 		buf[i*2+1] = hex[hash[i]&0x0f];
    375 	}
    376 	buf[sizeof(hash)*2] = 0;
    377 }
    378 
    379 /** convert data from return_msg into the data buffer */
    380 static int
    381 prep_data(struct module_qstate* qstate, struct sldns_buffer* buf)
    382 {
    383 	uint64_t timestamp, expiry;
    384 	size_t oldlim;
    385 	struct edns_data edns;
    386 	memset(&edns, 0, sizeof(edns));
    387 	edns.edns_present = 1;
    388 	edns.bits = EDNS_DO;
    389 	edns.ext_rcode = 0;
    390 	edns.edns_version = EDNS_ADVERTISED_VERSION;
    391 	edns.udp_size = EDNS_ADVERTISED_SIZE;
    392 
    393 	if(!qstate->return_msg || !qstate->return_msg->rep)
    394 		return 0;
    395 	/* do not store failures like SERVFAIL in the cachedb, this avoids
    396 	 * overwriting expired, valid, content with broken content. */
    397 	if(FLAGS_GET_RCODE(qstate->return_msg->rep->flags) !=
    398 		LDNS_RCODE_NOERROR &&
    399 	   FLAGS_GET_RCODE(qstate->return_msg->rep->flags) !=
    400 		LDNS_RCODE_NXDOMAIN &&
    401 	   FLAGS_GET_RCODE(qstate->return_msg->rep->flags) !=
    402 		LDNS_RCODE_YXDOMAIN)
    403 		return 0;
    404 	/* Do not persist data the validator has not yet seen, or has rejected.
    405 	 * Otherwise an expired blob could maybe reach clients via
    406 	 * serve-expired. */
    407 	if(qstate->env->need_to_validate &&
    408 		qstate->return_msg->rep->security == sec_status_bogus)
    409 		return 0;
    410 	/* We don't store the reply if its TTL is 0. This is probably coming
    411 	 * from upstream and it is not meant to be stored. */
    412 	if(qstate->return_msg->rep->ttl == 0)
    413 		return 0;
    414 
    415 	/* The EDE is added to the out-list so it is encoded in the cached message */
    416 	if (qstate->env->cfg->ede && qstate->return_msg->rep->reason_bogus != LDNS_EDE_NONE) {
    417 		edns_opt_list_append_ede(&edns.opt_list_out, qstate->env->scratch,
    418 					qstate->return_msg->rep->reason_bogus,
    419 					qstate->return_msg->rep->reason_bogus_str);
    420 	}
    421 
    422 	if(verbosity >= VERB_ALGO)
    423 		log_dns_msg("cachedb encoding", &qstate->return_msg->qinfo,
    424 	                qstate->return_msg->rep);
    425 	if(!reply_info_answer_encode(&qstate->return_msg->qinfo,
    426 		qstate->return_msg->rep, 0, qstate->query_flags,
    427 		buf, 0, 1, qstate->env->scratch, 65535, &edns, 1, 0))
    428 		return 0;
    429 
    430 	/* TTLs in the return_msg are relative to time(0) so we have to
    431 	 * store that, we also store the smallest ttl in the packet+time(0)
    432 	 * as the packet expiry time */
    433 	/* qstate->return_msg->rep->ttl contains that relative shortest ttl */
    434 	timestamp = (uint64_t)*qstate->env->now;
    435 	expiry = timestamp + (uint64_t)qstate->return_msg->rep->ttl;
    436 	timestamp = htobe64(timestamp);
    437 	expiry = htobe64(expiry);
    438 	oldlim = sldns_buffer_limit(buf);
    439 	if(oldlim + sizeof(timestamp)+sizeof(expiry) >=
    440 		sldns_buffer_capacity(buf))
    441 		return 0; /* doesn't fit. */
    442 	sldns_buffer_set_limit(buf, oldlim + sizeof(timestamp)+sizeof(expiry));
    443 	sldns_buffer_write_at(buf, oldlim, &timestamp, sizeof(timestamp));
    444 	sldns_buffer_write_at(buf, oldlim+sizeof(timestamp), &expiry,
    445 		sizeof(expiry));
    446 
    447 	return 1;
    448 }
    449 
    450 /** check expiry, return true if matches OK */
    451 static int
    452 good_expiry_and_qinfo(struct module_qstate* qstate, struct sldns_buffer* buf)
    453 {
    454 	uint64_t expiry;
    455 	/* the expiry time is the last bytes of the buffer */
    456 	if(sldns_buffer_limit(buf) < sizeof(expiry))
    457 		return 0;
    458 	sldns_buffer_read_at(buf, sldns_buffer_limit(buf)-sizeof(expiry),
    459 		&expiry, sizeof(expiry));
    460 	expiry = be64toh(expiry);
    461 
    462 	/* Check if we are allowed to return expired entries:
    463 	 * - serve_expired needs to be set
    464 	 * - if SERVE_EXPIRED_TTL is set make sure that the record is not older
    465 	 *   than that. */
    466 	if(TTL_IS_EXPIRED((time_t)expiry, *qstate->env->now) &&
    467 		(!qstate->env->cfg->serve_expired ||
    468 			(SERVE_EXPIRED_TTL &&
    469 			*qstate->env->now - (time_t)expiry > SERVE_EXPIRED_TTL)))
    470 		return 0;
    471 
    472 	return 1;
    473 }
    474 
    475 /* Adjust the TTL of the given RRset by 'subtract'.  If 'subtract' is
    476  * negative, set the TTL to 0. */
    477 static void
    478 packed_rrset_ttl_subtract(struct packed_rrset_data* data, time_t subtract,
    479 	time_t timestamp)
    480 {
    481 	size_t i;
    482 	size_t total = data->count + data->rrsig_count;
    483 	if(subtract >= 0 && data->ttl > subtract)
    484 		data->ttl -= subtract;
    485 	else	data->ttl = 0;
    486 	for(i=0; i<total; i++) {
    487 		if(subtract >= 0 && data->rr_ttl[i] > subtract)
    488 			data->rr_ttl[i] -= subtract;
    489 		else	data->rr_ttl[i] = 0;
    490 	}
    491 	data->ttl_add = timestamp;
    492 }
    493 
    494 /* Adjust the TTL of a DNS message and its RRs by 'adjust'.  If 'adjust' is
    495  * negative, set the TTLs to 0. */
    496 static void
    497 adjust_msg_ttl(struct dns_msg* msg, time_t adjust, time_t timestamp)
    498 {
    499 	size_t i;
    500 	if(adjust >= 0 && msg->rep->ttl > adjust)
    501 		msg->rep->ttl -= adjust;
    502 	else
    503 		msg->rep->ttl = 0;
    504 	msg->rep->prefetch_ttl = PREFETCH_TTL_CALC(msg->rep->ttl);
    505 	msg->rep->serve_expired_ttl = msg->rep->ttl + SERVE_EXPIRED_TTL;
    506 
    507 	for(i=0; i<msg->rep->rrset_count; i++) {
    508 		packed_rrset_ttl_subtract((struct packed_rrset_data*)msg->
    509 			rep->rrsets[i]->entry.data, adjust, timestamp);
    510 	}
    511 }
    512 
    513 /* Set the TTL of the given RRset to fixed value. */
    514 static void
    515 packed_rrset_ttl_set(struct packed_rrset_data* data, time_t ttl, time_t timestamp)
    516 {
    517 	size_t i;
    518 	size_t total = data->count + data->rrsig_count;
    519 	data->ttl = ttl;
    520 	for(i=0; i<total; i++) {
    521 		data->rr_ttl[i] = ttl;
    522 	}
    523 	data->ttl_add = timestamp;
    524 }
    525 
    526 /* Set the TTL of a DNS message and its RRs by to a fixed value. */
    527 static void
    528 set_msg_ttl(struct dns_msg* msg, time_t ttl, time_t timestamp)
    529 {
    530 	size_t i;
    531 	msg->rep->ttl = ttl;
    532 	msg->rep->prefetch_ttl = PREFETCH_TTL_CALC(msg->rep->ttl);
    533 	msg->rep->serve_expired_ttl = msg->rep->ttl + SERVE_EXPIRED_TTL;
    534 
    535 	for(i=0; i<msg->rep->rrset_count; i++) {
    536 		packed_rrset_ttl_set((struct packed_rrset_data*)msg->
    537 			rep->rrsets[i]->entry.data, ttl, timestamp);
    538 	}
    539 }
    540 
    541 /** convert dns message in buffer to return_msg */
    542 static int
    543 parse_data(struct module_qstate* qstate, struct sldns_buffer* buf,
    544 	int* msg_expired, time_t* msg_timestamp, time_t* msg_expiry)
    545 {
    546 	struct msg_parse* prs;
    547 	struct edns_data edns;
    548 	struct edns_option* ede;
    549 	uint64_t timestamp, expiry;
    550 	time_t adjust;
    551 	size_t lim = sldns_buffer_limit(buf);
    552 	if(lim < LDNS_HEADER_SIZE+sizeof(timestamp)+sizeof(expiry))
    553 		return 0; /* too short */
    554 
    555 	/* remove timestamp and expiry from end */
    556 	sldns_buffer_read_at(buf, lim-sizeof(expiry), &expiry, sizeof(expiry));
    557 	sldns_buffer_read_at(buf, lim-sizeof(expiry)-sizeof(timestamp),
    558 		&timestamp, sizeof(timestamp));
    559 	expiry = be64toh(expiry);
    560 	timestamp = be64toh(timestamp);
    561 	log_assert(timestamp <= expiry);
    562 	*msg_expiry = (time_t)expiry;
    563 	*msg_timestamp = (time_t)timestamp;
    564 
    565 	/* parse DNS packet */
    566 	regional_free_all(qstate->env->scratch);
    567 	prs = (struct msg_parse*)regional_alloc(qstate->env->scratch,
    568 		sizeof(struct msg_parse));
    569 	if(!prs)
    570 		return 0; /* out of memory */
    571 	memset(prs, 0, sizeof(*prs));
    572 	memset(&edns, 0, sizeof(edns));
    573 	sldns_buffer_set_limit(buf, lim - sizeof(expiry)-sizeof(timestamp));
    574 	if(parse_packet(buf, prs, qstate->env->scratch) != LDNS_RCODE_NOERROR) {
    575 		sldns_buffer_set_limit(buf, lim);
    576 		return 0;
    577 	}
    578 	if(parse_extract_edns_from_response_msg(prs, &edns, qstate->env->scratch) !=
    579 		LDNS_RCODE_NOERROR) {
    580 		sldns_buffer_set_limit(buf, lim);
    581 		return 0;
    582 	}
    583 
    584 	qstate->return_msg = dns_alloc_msg(buf, prs, qstate->region);
    585 	sldns_buffer_set_limit(buf, lim);
    586 	if(!qstate->return_msg)
    587 		return 0;
    588 
    589 	/* We find the EDE in the in-list after parsing */
    590 	if(qstate->env->cfg->ede &&
    591 		(ede = edns_opt_list_find(edns.opt_list_in, LDNS_EDNS_EDE))) {
    592 		if(ede->opt_len >= 2) {
    593 			qstate->return_msg->rep->reason_bogus =
    594 				sldns_read_uint16(ede->opt_data);
    595 		}
    596 		/* allocate space and store the error string and it's size */
    597 		if(ede->opt_len > 2) {
    598 			size_t ede_len = ede->opt_len - 2;
    599 			qstate->return_msg->rep->reason_bogus_str = regional_alloc(
    600 				qstate->region, sizeof(char) * (ede_len+1));
    601 			memcpy(qstate->return_msg->rep->reason_bogus_str,
    602 				ede->opt_data+2, ede_len);
    603 			qstate->return_msg->rep->reason_bogus_str[ede_len] = 0;
    604 		}
    605 	}
    606 
    607 	qstate->return_rcode = LDNS_RCODE_NOERROR;
    608 
    609 	/* see how much of the TTL expired, and remove it */
    610 	if(*qstate->env->now <= (time_t)timestamp) {
    611 		verbose(VERB_ALGO, "cachedb msg adjust by zero");
    612 		return 1; /* message from the future (clock skew?) */
    613 	}
    614 	adjust = *qstate->env->now - (time_t)timestamp;
    615 	if(TTL_IS_EXPIRED((time_t)expiry, *qstate->env->now)) {
    616 		verbose(VERB_ALGO, "cachedb msg expired");
    617 		*msg_expired = 1;
    618 		if(!qstate->env->cfg->serve_expired ||
    619 			(FLAGS_GET_RCODE(qstate->return_msg->rep->flags)
    620 			!= LDNS_RCODE_NOERROR &&
    621 			FLAGS_GET_RCODE(qstate->return_msg->rep->flags)
    622 			!= LDNS_RCODE_NXDOMAIN &&
    623 			FLAGS_GET_RCODE(qstate->return_msg->rep->flags)
    624 			!= LDNS_RCODE_YXDOMAIN))
    625 			return 0; /* message expired */
    626 		/* If serve-expired is enabled, we still use an expired message.
    627 		 * Set the TTL to 0 now and it will be handled specially later
    628 		 * when we need to store it internally. */
    629 		adjust = -1;
    630 	}
    631 	adjust_msg_ttl(qstate->return_msg, adjust, timestamp);
    632 	verbose(VERB_ALGO, "cachedb msg adjusted down by %d", (int)adjust);
    633 	if(qstate->env->cfg->aggressive_nsec) {
    634 		limit_nsec_ttl(qstate->return_msg);
    635 	}
    636 
    637 	/* Similar to the unbound worker, if serve-expired is enabled and
    638 	 * the msg would be considered to be expired, mark the state so a
    639 	 * refetch will be scheduled. */
    640 	if(*msg_expired && !qstate->env->cfg->serve_expired_client_timeout) {
    641 		qstate->need_refetch = 1;
    642 	}
    643 
    644 	return 1;
    645 }
    646 
    647 /**
    648  * Lookup the qstate.qinfo in extcache, store in qstate.return_msg.
    649  * return true if lookup was successful.
    650  */
    651 static int
    652 cachedb_extcache_lookup(struct module_qstate* qstate, struct cachedb_env* ie,
    653 	int* msg_expired, time_t* msg_timestamp, time_t* msg_expiry)
    654 {
    655 	char key[(CACHEDB_HASHSIZE/8)*2+1];
    656 	calc_hash(&qstate->qinfo, qstate->env, key, sizeof(key));
    657 
    658 	/* call backend to fetch data for key into scratch buffer */
    659 	if( !(*ie->backend->lookup)(qstate->env, ie, key,
    660 		qstate->env->scratch_buffer)) {
    661 		return 0;
    662 	}
    663 
    664 	/* check expiry date and check if query-data matches */
    665 	if( !good_expiry_and_qinfo(qstate, qstate->env->scratch_buffer) ) {
    666 		return 0;
    667 	}
    668 
    669 	/* parse dns message into return_msg */
    670 	if( !parse_data(qstate, qstate->env->scratch_buffer, msg_expired,
    671 		msg_timestamp, msg_expiry) ) {
    672 		return 0;
    673 	}
    674 	return 1;
    675 }
    676 
    677 /**
    678  * Store the qstate.return_msg in extcache for key qstate.info
    679  */
    680 static void
    681 cachedb_extcache_store(struct module_qstate* qstate, struct cachedb_env* ie)
    682 {
    683 	char key[(CACHEDB_HASHSIZE/8)*2+1];
    684 	calc_hash(&qstate->qinfo, qstate->env, key, sizeof(key));
    685 
    686 	/* prepare data in scratch buffer */
    687 	if(!prep_data(qstate, qstate->env->scratch_buffer))
    688 		return;
    689 
    690 	/* call backend */
    691 	(*ie->backend->store)(qstate->env, ie, key,
    692 		sldns_buffer_begin(qstate->env->scratch_buffer),
    693 		sldns_buffer_limit(qstate->env->scratch_buffer),
    694 		qstate->return_msg->rep->ttl);
    695 }
    696 
    697 /**
    698  * See if unbound's internal cache can answer the query
    699  */
    700 static int
    701 cachedb_intcache_lookup(struct module_qstate* qstate, struct cachedb_env* cde)
    702 {
    703 	uint8_t dpname_storage[LDNS_MAX_DOMAINLEN+1];
    704 	uint8_t* dpname=NULL;
    705 	size_t dpnamelen=0;
    706 	struct dns_msg* msg;
    707 	/* for testframe bypass this lookup */
    708 	if(cde->backend == &testframe_backend) {
    709 		return 0;
    710 	}
    711 	if(iter_stub_fwd_no_cache(qstate, &qstate->qinfo,
    712 		&dpname, &dpnamelen, dpname_storage, sizeof(dpname_storage)))
    713 		return 0; /* no cache for these queries */
    714 	msg = dns_cache_lookup(qstate->env, qstate->qinfo.qname,
    715 		qstate->qinfo.qname_len, qstate->qinfo.qtype,
    716 		qstate->qinfo.qclass, qstate->query_flags,
    717 		qstate->region, qstate->env->scratch,
    718 		1, /* no partial messages with only a CNAME */
    719 		dpname, dpnamelen
    720 		);
    721 	if(!msg && qstate->env->neg_cache &&
    722 		iter_qname_indicates_dnssec(qstate->env, &qstate->qinfo)) {
    723 		/* lookup in negative cache; may result in
    724 		 * NOERROR/NODATA or NXDOMAIN answers that need validation */
    725 		msg = val_neg_getmsg(qstate->env->neg_cache, &qstate->qinfo,
    726 			qstate->region, qstate->env->rrset_cache,
    727 			qstate->env->scratch_buffer,
    728 			*qstate->env->now, 1/*add SOA*/, NULL,
    729 			qstate->env->cfg);
    730 	}
    731 	if(!msg)
    732 		return 0;
    733 	/* this is the returned msg */
    734 	qstate->return_rcode = LDNS_RCODE_NOERROR;
    735 	qstate->return_msg = msg;
    736 	return 1;
    737 }
    738 
    739 /**
    740  * Store query into the internal cache of unbound.
    741  */
    742 static void
    743 cachedb_intcache_store(struct module_qstate* qstate, int msg_expired,
    744 	time_t msg_timestamp, time_t msg_expiry)
    745 {
    746 	uint32_t store_flags = qstate->query_flags;
    747 	int serve_expired = qstate->env->cfg->serve_expired;
    748 	if(!qstate->return_msg)
    749 		return;
    750 	if(serve_expired && msg_expired) {
    751 		time_t original_ttl = msg_expiry - msg_timestamp;
    752 		store_flags |= DNSCACHE_STORE_EXPIRED_MSG_CACHEDB;
    753 		/* Pass the original TTL of the expired message and signal with
    754 		 * the DNSCACHE_STORE_EXPIRED_MSG_CACHEDB flag that
    755 		 * dns_cache_store_msg() needs to set absolute expired TTLs
    756 		 * based on the original message TTL.
    757 		 * Results as expired message in the cache */
    758 		set_msg_ttl(qstate->return_msg, original_ttl, 0);
    759 		verbose(VERB_ALGO, "cachedb expired msg set to be expired now "
    760 			"(original ttl: %d)", (int)original_ttl);
    761 		/* The expired entry does not get checked by the validator
    762 		 * and we need a validation value for it. */
    763 		/* By setting this to unchecked, bogus data is not returned
    764 		 * as non-bogus. */
    765 		if(qstate->env->cfg->cachedb_check_when_serve_expired)
    766 			qstate->return_msg->rep->security = sec_status_unchecked;
    767 	}
    768 	(void)dns_cache_store(qstate->env, &qstate->qinfo,
    769 		qstate->return_msg->rep, 0, qstate->prefetch_leeway, 0,
    770 		qstate->region, store_flags, qstate->qstarttime,
    771 		qstate->is_valrec);
    772 	if(serve_expired && msg_expired) {
    773 		if(qstate->env->cfg->serve_expired_client_timeout) {
    774 			/* No expired response from the query state, the
    775 			 * query resolution needs to continue and it can
    776 			 * pick up the expired result after the timer out
    777 			 * of cache. */
    778 			return;
    779 		}
    780 		/* Send serve expired responses based on the cachedb
    781 		 * returned message, that was just stored in the cache.
    782 		 * It can then continue to work on this query. */
    783 		mesh_respond_serve_expired(qstate->mesh_info);
    784 		/* set TTLs as expired for this return_msg in case it is used
    785 		 * later on */
    786 		set_msg_ttl(qstate->return_msg,
    787 			EXPIRED_REPLY_TTL_CALC(msg_expiry, msg_timestamp), 0);
    788 	}
    789 }
    790 
    791 /**
    792  * Handle a cachedb module event with a query
    793  * @param qstate: query state (from the mesh), passed between modules.
    794  * 	contains qstate->env module environment with global caches and so on.
    795  * @param iq: query state specific for this module.  per-query.
    796  * @param ie: environment specific for this module.  global.
    797  * @param id: module id.
    798  */
    799 static void
    800 cachedb_handle_query(struct module_qstate* qstate,
    801 	struct cachedb_qstate* ATTR_UNUSED(iq),
    802 	struct cachedb_env* ie, int id)
    803 {
    804 	int msg_expired = 0;
    805 	time_t msg_timestamp, msg_expiry;
    806 	qstate->is_cachedb_answer = 0;
    807 	/* check if we are enabled, and skip if so */
    808 	if(!ie->enabled) {
    809 		/* pass request to next module */
    810 		qstate->ext_state[id] = module_wait_module;
    811 		return;
    812 	}
    813 
    814 	if(qstate->blacklist || qstate->no_cache_lookup
    815 		|| iter_stub_fwd_no_cache(qstate, &qstate->qinfo, NULL, NULL,
    816 		NULL, 0)) {
    817 		/* cache is blacklisted or we are instructed from edns to not
    818 		 * look or a forwarder/stub forbids it */
    819 		/* pass request to next module */
    820 		qstate->ext_state[id] = module_wait_module;
    821 		return;
    822 	}
    823 
    824 	/* lookup inside unbound's internal cache.
    825 	 * This does not look for expired entries. */
    826 	if(cachedb_intcache_lookup(qstate, ie)) {
    827 		if(verbosity >= VERB_ALGO) {
    828 			if(qstate->return_msg->rep)
    829 				log_dns_msg("cachedb internal cache lookup",
    830 					&qstate->return_msg->qinfo,
    831 					qstate->return_msg->rep);
    832 			else log_info("cachedb internal cache lookup: rcode %s",
    833 				sldns_lookup_by_id(sldns_rcodes, qstate->return_rcode)
    834 				?sldns_lookup_by_id(sldns_rcodes, qstate->return_rcode)->name
    835 				:"??");
    836 		}
    837 		/* we are done with the query */
    838 		qstate->ext_state[id] = module_finished;
    839 		return;
    840 	}
    841 
    842 	/* ask backend cache to see if we have data */
    843 	if(cachedb_extcache_lookup(qstate, ie, &msg_expired, &msg_timestamp,
    844 		&msg_expiry)) {
    845 		if(verbosity >= VERB_ALGO)
    846 			log_dns_msg(ie->backend->name,
    847 				&qstate->return_msg->qinfo,
    848 				qstate->return_msg->rep);
    849 		/* store this result in internal cache */
    850 		cachedb_intcache_store(qstate,
    851 			msg_expired, msg_timestamp, msg_expiry);
    852 		/* In case we have expired data but there is a client timer for expired
    853 		 * answers, pass execution to next module in order to try updating the
    854 		 * data first.
    855 		 */
    856 		if(qstate->env->cfg->serve_expired && msg_expired) {
    857 			qstate->return_msg = NULL;
    858 			qstate->ext_state[id] = module_wait_module;
    859 			/* The expired reply is sent with
    860 			 * mesh_respond_serve_expired, and so
    861 			 * the need_refetch is not used. */
    862 			qstate->need_refetch = 0;
    863 			return;
    864 		}
    865 		if(qstate->need_refetch && qstate->serve_expired_data &&
    866 			qstate->serve_expired_data->timer) {
    867 				qstate->return_msg = NULL;
    868 				qstate->ext_state[id] = module_wait_module;
    869 				return;
    870 		}
    871 		/* No 0TTL answers escaping from external cache. */
    872 		if(qstate->return_msg->rep->ttl == 0) {
    873 			qstate->return_msg = NULL;
    874 			qstate->ext_state[id] = module_wait_module;
    875 			return;
    876 		}
    877 		log_assert(qstate->return_msg->rep->ttl > 0);
    878 		qstate->is_cachedb_answer = 1;
    879 		/* we are done with the query */
    880 		qstate->ext_state[id] = module_finished;
    881 		return;
    882 	}
    883 
    884 	if(qstate->serve_expired_data &&
    885 		qstate->env->cfg->cachedb_check_when_serve_expired &&
    886 		!qstate->env->cfg->serve_expired_client_timeout) {
    887 		/* Reply with expired data if any to client, because cachedb
    888 		 * also has no useful, current data */
    889 		mesh_respond_serve_expired(qstate->mesh_info);
    890 	}
    891 
    892 	/* no cache fetches */
    893 	/* pass request to next module */
    894 	qstate->ext_state[id] = module_wait_module;
    895 }
    896 
    897 /**
    898  * Handle a cachedb module event with a response from the iterator.
    899  * @param qstate: query state (from the mesh), passed between modules.
    900  * 	contains qstate->env module environment with global caches and so on.
    901  * @param iq: query state specific for this module.  per-query.
    902  * @param ie: environment specific for this module.  global.
    903  * @param id: module id.
    904  */
    905 static void
    906 cachedb_handle_response(struct module_qstate* qstate,
    907 	struct cachedb_qstate* ATTR_UNUSED(iq), struct cachedb_env* ie, int id)
    908 {
    909 	qstate->is_cachedb_answer = 0;
    910 	/* check if we are not enabled or instructed to not cache, and skip */
    911 	if(!ie->enabled || qstate->no_cache_store
    912 		|| iter_stub_fwd_no_cache(qstate, &qstate->qinfo, NULL, NULL,
    913 		NULL, 0)) {
    914 		/* we are done with the query */
    915 		qstate->ext_state[id] = module_finished;
    916 		return;
    917 	}
    918 	if(qstate->env->cfg->cachedb_no_store) {
    919 		/* do not store the item in the external cache */
    920 		qstate->ext_state[id] = module_finished;
    921 		return;
    922 	}
    923 
    924 	/* store the item into the backend cache */
    925 	cachedb_extcache_store(qstate, ie);
    926 
    927 	/* we are done with the query */
    928 	qstate->ext_state[id] = module_finished;
    929 }
    930 
    931 void
    932 cachedb_operate(struct module_qstate* qstate, enum module_ev event, int id,
    933 	struct outbound_entry* outbound)
    934 {
    935 	struct cachedb_env* ie = (struct cachedb_env*)qstate->env->modinfo[id];
    936 	struct cachedb_qstate* iq = (struct cachedb_qstate*)qstate->minfo[id];
    937 	verbose(VERB_QUERY, "cachedb[module %d] operate: extstate:%s event:%s",
    938 		id, strextstate(qstate->ext_state[id]), strmodulevent(event));
    939 	if(iq) log_query_info(VERB_QUERY, "cachedb operate: query",
    940 		&qstate->qinfo);
    941 
    942 	/* perform cachedb state machine */
    943 	if((event == module_event_new || event == module_event_pass) &&
    944 		iq == NULL) {
    945 		if(!cachedb_new(qstate, id)) {
    946 			(void)error_response(qstate, id, LDNS_RCODE_SERVFAIL);
    947 			return;
    948 		}
    949 		iq = (struct cachedb_qstate*)qstate->minfo[id];
    950 	}
    951 	if(iq && (event == module_event_pass || event == module_event_new)) {
    952 		cachedb_handle_query(qstate, iq, ie, id);
    953 		return;
    954 	}
    955 	if(iq && (event == module_event_moddone)) {
    956 		cachedb_handle_response(qstate, iq, ie, id);
    957 		return;
    958 	}
    959 	if(iq && outbound) {
    960 		/* cachedb does not need to process responses at this time
    961 		 * ignore it.
    962 		cachedb_process_response(qstate, iq, ie, id, outbound, event);
    963 		*/
    964 		return;
    965 	}
    966 	if(event == module_event_error) {
    967 		verbose(VERB_ALGO, "got called with event error, giving up");
    968 		(void)error_response(qstate, id, LDNS_RCODE_SERVFAIL);
    969 		return;
    970 	}
    971 	if(!iq && (event == module_event_moddone)) {
    972 		/* during priming, module done but we never started */
    973 		qstate->ext_state[id] = module_finished;
    974 		return;
    975 	}
    976 
    977 	log_err("bad event for cachedb");
    978 	(void)error_response(qstate, id, LDNS_RCODE_SERVFAIL);
    979 }
    980 
    981 void
    982 cachedb_inform_super(struct module_qstate* ATTR_UNUSED(qstate),
    983 	int ATTR_UNUSED(id), struct module_qstate* ATTR_UNUSED(super))
    984 {
    985 	/* cachedb does not use subordinate requests at this time */
    986 	verbose(VERB_ALGO, "cachedb inform_super was called");
    987 }
    988 
    989 void
    990 cachedb_clear(struct module_qstate* qstate, int id)
    991 {
    992 	struct cachedb_qstate* iq;
    993 	if(!qstate)
    994 		return;
    995 	iq = (struct cachedb_qstate*)qstate->minfo[id];
    996 	if(iq) {
    997 		/* free contents of iq */
    998 		/* TODO */
    999 	}
   1000 	qstate->minfo[id] = NULL;
   1001 }
   1002 
   1003 size_t
   1004 cachedb_get_mem(struct module_env* env, int id)
   1005 {
   1006 	struct cachedb_env* ie = (struct cachedb_env*)env->modinfo[id];
   1007 	if(!ie)
   1008 		return 0;
   1009 	return sizeof(*ie); /* TODO - more mem */
   1010 }
   1011 
   1012 /**
   1013  * The cachedb function block
   1014  */
   1015 static struct module_func_block cachedb_block = {
   1016 	"cachedb",
   1017 	NULL, NULL, &cachedb_init, &cachedb_deinit, &cachedb_operate,
   1018 	&cachedb_inform_super, &cachedb_clear, &cachedb_get_mem
   1019 };
   1020 
   1021 struct module_func_block*
   1022 cachedb_get_funcblock(void)
   1023 {
   1024 	return &cachedb_block;
   1025 }
   1026 
   1027 int
   1028 cachedb_is_enabled(struct module_stack* mods, struct module_env* env)
   1029 {
   1030 	struct cachedb_env* ie;
   1031 	int id = modstack_find(mods, "cachedb");
   1032 	if(id == -1)
   1033 		return 0;
   1034 	ie = (struct cachedb_env*)env->modinfo[id];
   1035 	if(ie && ie->enabled)
   1036 		return 1;
   1037 	return 0;
   1038 }
   1039 
   1040 void cachedb_msg_remove(struct module_qstate* qstate)
   1041 {
   1042 	cachedb_msg_remove_qinfo(qstate->env, &qstate->qinfo);
   1043 }
   1044 
   1045 void cachedb_msg_remove_qinfo(struct module_env* env, struct query_info* qinfo)
   1046 {
   1047 	char key[(CACHEDB_HASHSIZE/8)*2+1];
   1048 	int id = modstack_find(env->modstack, "cachedb");
   1049 	struct cachedb_env* ie = (struct cachedb_env*)env->modinfo[id];
   1050 
   1051 	log_query_info(VERB_ALGO, "cachedb msg remove", qinfo);
   1052 	calc_hash(qinfo, env, key, sizeof(key));
   1053 	sldns_buffer_clear(env->scratch_buffer);
   1054 	sldns_buffer_write_u32(env->scratch_buffer, 0);
   1055 	sldns_buffer_flip(env->scratch_buffer);
   1056 
   1057 	/* call backend */
   1058 	(*ie->backend->store)(env, ie, key,
   1059 		sldns_buffer_begin(env->scratch_buffer),
   1060 		sldns_buffer_limit(env->scratch_buffer),
   1061 		0);
   1062 }
   1063 #endif /* USE_CACHEDB */
   1064