Handle UDP-to-TCP auto-promotion in FTL code and use new "proto" logging of dnsmasq ("extra" + protocol information)

Signed-off-by: DL6ER <dl6er@dl6er.de>
This commit is contained in:
DL6ER committed 2024-12-02 20:55:11 +01:00
1 parent be18751d7d
commit adcccfc1dc
6 files changed
+34 -15

No files matched your search

+1 -2
View File
@@ -6,8 +6,7 @@
"vscode": {
"extensions": [
"jetmartin.bats",
"ms-vscode.cpptools",
"ms-vscode.cmake-tools",
"ms-vscode.cpptools-extension-pack",
"eamodio.gitlens",
"github.copilot",
"ms-python.python"
+1 -1
View File
@@ -345,7 +345,7 @@ bool __attribute__((const)) write_dnsmasq_config(struct config *conf, bool test_
{
fputs("# Enable query logging\n", pihole_conf);
if(conf->misc.extraLogging.v.b)
fputs("log-queries=extra\n", pihole_conf);
fputs("log-queries=proto\n", pihole_conf);
else
fputs("log-queries\n", pihole_conf);
fputs("log-async\n", pihole_conf);
+2 -2
View File
@@ -419,7 +419,7 @@ static int forward_query(int udpfd, union mysockaddr *udpaddr,
/* get query for logging. */
gotname = extract_request(header, plen, daemon->namebuff, NULL);
FTL_forwarding_retried(forward->sentto, forward->frec_src.log_id, daemon->log_display_id, true);
FTL_forwarding_retried(forward, daemon->log_display_id, true);
/* Find suitable servers: should never fail. */
if (!filter_servers(forward->sentto->arrayposn, F_DNSSECOK, &first, &last))
@@ -437,7 +437,7 @@ static int forward_query(int udpfd, union mysockaddr *udpaddr,
else
forward->sentto->retrys++;
FTL_forwarding_retried(forward->sentto, forward->frec_src.log_id, daemon->log_display_id, false);
FTL_forwarding_retried(forward, daemon->log_display_id, false);
if (!filter_servers(forward->sentto->arrayposn, F_SERVER, &first, &last))
goto reply;
+25 -5
View File
@@ -111,6 +111,10 @@ void FTL_hook(unsigned int flags, const char *name, const union all_addr *addr,
log_debug(DEBUG_FLAGS, "Processing FTL hook from %s:%d (type: %s, name: \"%s\", id: %i)...", path, line, types, name, id);
print_flags(flags);
// The query ID may be negative if this is a TCP query
if(id < 0)
id = -id;
// Check domain name received from dnsmasq
name = check_dnsmasq_name(name);
@@ -580,8 +584,8 @@ static bool is_pihole_domain(const char *domain)
bool _FTL_new_query(const unsigned int flags, const char *name,
union mysockaddr *addr, char *arg,
const unsigned short qtype, const int id,
const enum protocol proto,
const unsigned short qtype, int id,
enum protocol proto,
const char *file, const int line)
{
// Create new query in data structure
@@ -789,6 +793,20 @@ bool _FTL_new_query(const unsigned int flags, const char *name,
return true;
}
// The query ID is negative if this is a TCP query
if(id < 0)
{
id = -id;
// Safety check: If the query ID is negative, the protocol
// should be TCP
if(proto != TCP)
{
proto = TCP;
log_debug(DEBUG_ANY, "Query %d has negative ID, but protocol is not TCP", id);
}
}
// Log new query if in debug mode
if(config.debug.queries.v.b)
{
@@ -3293,10 +3311,11 @@ static char *get_ptrname(const struct in_addr *addr)
return ptrname;
}
void FTL_forwarding_retried(const struct server *serv, const int oldID, const int newID, const bool dnssec)
void FTL_forwarding_retried(struct frec *forward, const int newID, const bool dnssec)
{
// Forwarding to upstream server failed
const struct server *serv = forward->sentto;
const int oldID = forward->frec_src.log_id;
if(oldID == newID)
{
log_debug(DEBUG_QUERIES, "%d: Ignoring self-retry", oldID);
@@ -3737,8 +3756,9 @@ void FTL_connection_error(const char *reason, const union mysockaddr *addr)
if(addr != NULL)
mysockaddr_extract_ip_port(addr, ip, &port);
// Get query ID, may be negative if this is a TCP query
const int id = daemon->log_display_id > 0 ? daemon->log_display_id : -daemon->log_display_id;
// Log to FTL.log
const int id = daemon->log_display_id;
log_debug(DEBUG_QUERIES, "Connection error (%s#%u, ID %d): %s (%s)", ip, port, id, reason, error);
// Log to pihole.log
+2 -2
View File
@@ -24,7 +24,7 @@ void FTL_hook(unsigned int flags, const char *name, const union all_addr *addr,
void _FTL_iface(struct irec *recviface, const union all_addr *addr, const sa_family_t addrfamily, const char *file, const int line);
#define FTL_new_query(flags, name, addr, arg, qtype, id, proto) _FTL_new_query(flags, name, addr, arg, qtype, id, proto, __FILE__, __LINE__)
bool _FTL_new_query(const unsigned int flags, const char *name, union mysockaddr *addr, char *arg, const unsigned short qtype, const int id, enum protocol proto, const char *file, const int line);
bool _FTL_new_query(const unsigned int flags, const char *name, union mysockaddr *addr, char *arg, const unsigned short qtype, int id, enum protocol proto, const char *file, const int line);
#define FTL_header_analysis(header, server, id) _FTL_header_analysis(header, server, id, __FILE__, __LINE__)
void _FTL_header_analysis(const struct dns_header *header, const struct server *server, const int id, const char *file, const int line);
@@ -32,7 +32,7 @@ void _FTL_header_analysis(const struct dns_header *header, const struct server *
#define FTL_check_reply(rcode, flags, addr, id) _FTL_check_reply(rcode, flags, addr, id, __FILE__, __LINE__)
int _FTL_check_reply(const unsigned int rcode, const unsigned short flags, const union all_addr *addr, const int id, const char *file, const int line);
void FTL_forwarding_retried(const struct server *server, const int oldID, const int newID, const bool dnssec);
void FTL_forwarding_retried(struct frec *forward, const int newID, const bool dnssec);
#define MAX_EDE_DATA 128
#define FTL_make_answer(header, limit, len, ede_data, ede_len) _FTL_make_answer(header, limit, len, ede_data, ede_len, __FILE__, __LINE__)
+3 -3
View File
@@ -960,7 +960,7 @@
# with an individual query, and the IP address of the requestor. This setting is only
# effective if dns.queryLogging is enabled, too. This option is only useful for
# debugging and is not recommended for normal use.
extraLogging = false
extraLogging = true ### CHANGED, default = false
# Put configuration into read-only mode. This will prevent any changes to the
# configuration file via the API or CLI. This setting useful when a configuration is
@@ -1117,8 +1117,8 @@
all = true ### CHANGED, default = false
# Configuration statistics:
# 150 total entries out of which 95 entries are default
# --> 55 entries are modified
# 150 total entries out of which 94 entries are default
# --> 56 entries are modified
# 2 entries are forced through environment:
# - misc.nice
# - debug.api