- r = hashmap_ensure_allocated(&s->manager->dns_query_transactions, NULL, NULL);
- if (r < 0)
- return r;
-
- t = new0(DnsQueryTransaction, 1);
- if (!t)
- return -ENOMEM;
-
- t->question = dns_question_ref(q);
-
- do
- random_bytes(&t->id, sizeof(t->id));
- while (t->id == 0 ||
- hashmap_get(s->manager->dns_query_transactions, UINT_TO_PTR(t->id)));
-
- r = hashmap_put(s->manager->dns_query_transactions, UINT_TO_PTR(t->id), t);
- if (r < 0) {
- t->id = 0;
- return r;
- }
-
- LIST_PREPEND(transactions_by_scope, s->transactions, t);
- t->scope = s;
-
- if (ret)
- *ret = t;
-
- t = NULL;
-
- return 0;
-}
-
-static void dns_query_transaction_stop(DnsQueryTransaction *t) {
- assert(t);
-
- t->timeout_event_source = sd_event_source_unref(t->timeout_event_source);
- t->stream = dns_stream_free(t->stream);
-}
-
-void dns_query_transaction_complete(DnsQueryTransaction *t, DnsQueryState state) {
- DnsQuery *q;
- Iterator i;
-
- assert(t);
- assert(!IN_SET(state, DNS_QUERY_NULL, DNS_QUERY_PENDING));
- assert(IN_SET(t->state, DNS_QUERY_NULL, DNS_QUERY_PENDING));
-
- /* Note that this call might invalidate the query. Callers
- * should hence not attempt to access the query or transaction
- * after calling this function. */
-
- log_debug("Transaction on scope %s on %s/%s now complete with %s",
- dns_protocol_to_string(t->scope->protocol),
- t->scope->link ? t->scope->link->name : "*",
- t->scope->family == AF_UNSPEC ? "*" : af_to_name(t->scope->family),
- dns_query_state_to_string(state));
-
- t->state = state;
-
- dns_query_transaction_stop(t);
-
- /* Notify all queries that are interested, but make sure the
- * transaction isn't freed while we are still looking at it */
- t->block_gc++;
- SET_FOREACH(q, t->queries, i)
- dns_query_ready(q);
- t->block_gc--;
-
- dns_query_transaction_gc(t);
-}
-
-static int on_stream_complete(DnsStream *s, int error) {
- _cleanup_(dns_packet_unrefp) DnsPacket *p = NULL;
- DnsQueryTransaction *t;
-
- assert(s);
- assert(s->transaction);
-
- /* Copy the data we care about out of the stream before we
- * destroy it. */
- t = s->transaction;
- p = dns_packet_ref(s->read_packet);
-
- t->stream = dns_stream_free(t->stream);
-
- if (error != 0) {
- dns_query_transaction_complete(t, DNS_QUERY_RESOURCES);
- return 0;
- }
-
- t->block_gc++;
- dns_query_transaction_process_reply(t, p);
- t->block_gc--;
-
- /* If the response wasn't useful, then complete the transition now */
- if (t->state == DNS_QUERY_PENDING)
- dns_query_transaction_complete(t, DNS_QUERY_INVALID_REPLY);
-
- return 0;
-}
-
-static int dns_query_transaction_open_tcp(DnsQueryTransaction *t) {
- _cleanup_close_ int fd = -1;
- int r;
-
- assert(t);
-
- if (t->stream)
- return 0;
-
- if (t->scope->protocol == DNS_PROTOCOL_DNS)
- fd = dns_scope_tcp_socket(t->scope, AF_UNSPEC, NULL, 53);
- else if (t->scope->protocol == DNS_PROTOCOL_LLMNR) {
-
- /* When we already received a query to this (but it was truncated), send to its sender address */
- if (t->received)
- fd = dns_scope_tcp_socket(t->scope, t->received->family, &t->received->sender, t->received->sender_port);
- else {
- union in_addr_union address;
- int family;
-
- /* Otherwise, try to talk to the owner of a
- * the IP address, in case this is a reverse
- * PTR lookup */
- r = dns_question_extract_reverse_address(t->question, &family, &address);
- if (r < 0)
- return r;
- if (r == 0)
- return -EINVAL;
-
- fd = dns_scope_tcp_socket(t->scope, family, &address, 5355);
- }
- } else
- return -EAFNOSUPPORT;
-
- if (fd < 0)
- return fd;
-
- r = dns_stream_new(t->scope->manager, &t->stream, t->scope->protocol, fd);
- if (r < 0)
- return r;
-
- fd = -1;
-
- r = dns_stream_write_packet(t->stream, t->sent);
- if (r < 0) {
- t->stream = dns_stream_free(t->stream);
- return r;
- }
-
- t->received = dns_packet_unref(t->received);
- t->stream->complete = on_stream_complete;
- t->stream->transaction = t;
-
- /* The interface index is difficult to determine if we are
- * connecting to the local host, hence fill this in right away
- * instead of determining it from the socket */
- if (t->scope->link)
- t->stream->ifindex = t->scope->link->ifindex;
-
- return 0;
-}
-
-void dns_query_transaction_process_reply(DnsQueryTransaction *t, DnsPacket *p) {
- int r;
-
- assert(t);
- assert(p);
- assert(t->state == DNS_QUERY_PENDING);
-
- /* Note that this call might invalidate the query. Callers
- * should hence not attempt to access the query or transaction
- * after calling this function. */
-
- if (t->scope->protocol == DNS_PROTOCOL_LLMNR) {
- assert(t->scope->link);
-
- /* For LLMNR we will not accept any packets from other
- * interfaces */
-
- if (p->ifindex != t->scope->link->ifindex)
- return;
-
- if (p->family != t->scope->family)
- return;
-
- /* Tentative replies shall be discarded, see RFC 4795,
- * 2.1.1 */
-
- if (DNS_PACKET_T(p))
- return;
- }
-
- if (t->scope->protocol == DNS_PROTOCOL_DNS) {
-
- /* For DNS we are fine with accepting packets on any
- * interface, but the source IP address must be one of
- * a valid DNS server */
-
- if (!dns_scope_good_dns_server(t->scope, p->family, &p->sender))
- return;
-
- if (p->sender_port != 53)
- return;
- }
-
- if (t->received != p) {
- dns_packet_unref(t->received);
- t->received = dns_packet_ref(p);
- }
-
- if (p->ipproto == IPPROTO_TCP) {
- if (DNS_PACKET_TC(p)) {
- /* Truncated via TCP? Somebody must be fucking with us */
- dns_query_transaction_complete(t, DNS_QUERY_INVALID_REPLY);
- return;
- }
-
- if (DNS_PACKET_ID(p) != t->id) {
- /* Not the reply to our query? Somebody must be fucking with us */
- dns_query_transaction_complete(t, DNS_QUERY_INVALID_REPLY);
- return;
- }
- }
-
- if (DNS_PACKET_TC(p)) {
- /* Response was truncated, let's try again with good old TCP */
- r = dns_query_transaction_open_tcp(t);
- if (r == -ESRCH) {
- /* No servers found? Damn! */
- dns_query_transaction_complete(t, DNS_QUERY_NO_SERVERS);
- return;
- }
- if (r < 0) {
- /* On LLMNR, if we cannot connect to the host,
- * we immediately give up */
- if (t->scope->protocol == DNS_PROTOCOL_LLMNR) {
- dns_query_transaction_complete(t, DNS_QUERY_RESOURCES);
- return;
- }
-
- /* On DNS, couldn't send? Try immediately again, with a new server */
- dns_scope_next_dns_server(t->scope);
-
- r = dns_query_transaction_go(t);
- if (r < 0) {
- dns_query_transaction_complete(t, DNS_QUERY_RESOURCES);
- return;
- }
-
- return;
- }
- }
-
- /* Parse and update the cache */
- r = dns_packet_extract(p);
- if (r < 0) {
- dns_query_transaction_complete(t, DNS_QUERY_INVALID_REPLY);
- return;
- }
-
- /* According to RFC 4795, section 2.9. only the RRs from the answer section shall be cached */
- dns_cache_put(&t->scope->cache, p->question, DNS_PACKET_RCODE(p), p->answer, DNS_PACKET_ANCOUNT(p), 0);
-
- if (DNS_PACKET_RCODE(p) == DNS_RCODE_SUCCESS)
- dns_query_transaction_complete(t, DNS_QUERY_SUCCESS);
- else
- dns_query_transaction_complete(t, DNS_QUERY_FAILURE);
-}
-
-static int on_transaction_timeout(sd_event_source *s, usec_t usec, void *userdata) {
- DnsQueryTransaction *t = userdata;
- int r;
-
- assert(s);
- assert(t);
-
- /* Timeout reached? Try again, with a new server */
- dns_scope_next_dns_server(t->scope);
-
- r = dns_query_transaction_go(t);
- if (r < 0)
- dns_query_transaction_complete(t, DNS_QUERY_RESOURCES);
-
- return 0;
-}
-
-static int dns_query_make_packet(DnsQueryTransaction *t) {
- _cleanup_(dns_packet_unrefp) DnsPacket *p = NULL;
- unsigned n, added = 0;
- int r;
-
- assert(t);
-
- if (t->sent)
- return 0;
-
- r = dns_packet_new_query(&p, t->scope->protocol, 0);
- if (r < 0)
- return r;
-
- for (n = 0; n < t->question->n_keys; n++) {
- r = dns_scope_good_key(t->scope, t->question->keys[n]);
- if (r < 0)
- return r;
- if (r == 0)
- continue;
-
- r = dns_packet_append_key(p, t->question->keys[n], NULL);
- if (r < 0)
- return r;
-
- added++;
- }
-
- if (added <= 0)
- return -EDOM;
-
- DNS_PACKET_HEADER(p)->qdcount = htobe16(added);
- DNS_PACKET_HEADER(p)->id = t->id;
-
- t->sent = p;
- p = NULL;
-
- return 0;
-}
-
-static int dns_query_transaction_go(DnsQueryTransaction *t) {
- bool had_stream;
- int r;
-
- assert(t);
-
- had_stream = !!t->stream;
-
- dns_query_transaction_stop(t);
-
- log_debug("Beginning transaction on scope %s on %s/%s",
- dns_protocol_to_string(t->scope->protocol),
- t->scope->link ? t->scope->link->name : "*",
- t->scope->family == AF_UNSPEC ? "*" : af_to_name(t->scope->family));
-
- if (t->n_attempts >= TRANSACTION_ATTEMPTS_MAX(t)) {
- dns_query_transaction_complete(t, DNS_QUERY_ATTEMPTS_MAX);
- return 0;
- }
-
- if (t->scope->protocol == DNS_PROTOCOL_LLMNR && had_stream) {
- /* If we already tried via a stream, then we don't
- * retry on LLMNR. See RFC 4795, Section 2.7. */
- dns_query_transaction_complete(t, DNS_QUERY_ATTEMPTS_MAX);
- return 0;
- }
-
- t->n_attempts++;
- t->received = dns_packet_unref(t->received);
- t->cached = dns_answer_unref(t->cached);
- t->cached_rcode = 0;
-
- /* First, let's try the cache */
- dns_cache_prune(&t->scope->cache);
- r = dns_cache_lookup(&t->scope->cache, t->question, &t->cached_rcode, &t->cached);
- if (r < 0)
- return r;
- if (r > 0) {
- if (t->cached_rcode == DNS_RCODE_SUCCESS)
- dns_query_transaction_complete(t, DNS_QUERY_SUCCESS);
- else
- dns_query_transaction_complete(t, DNS_QUERY_FAILURE);
- return 0;
- }
-
- /* Otherwise, we need to ask the network */
- r = dns_query_make_packet(t);
- if (r == -EDOM) {
- /* Not the right request to make on this network?
- * (i.e. an A request made on IPv6 or an AAAA request
- * made on IPv4, on LLMNR or mDNS.) */
- dns_query_transaction_complete(t, DNS_QUERY_NO_SERVERS);
- return 0;
- }
- if (r < 0)
- return r;
-
- if (t->scope->protocol == DNS_PROTOCOL_LLMNR &&
- (dns_question_endswith(t->question, "in-addr.arpa") > 0 ||
- dns_question_endswith(t->question, "ip6.arpa") > 0)) {
-
- /* RFC 4795, Section 2.4. says reverse lookups shall
- * always be made via TCP on LLMNR */
- r = dns_query_transaction_open_tcp(t);
- } else {
- /* Try via UDP, and if that fails due to large size try via TCP */
- r = dns_scope_send(t->scope, t->sent);
- if (r == -EMSGSIZE)
- r = dns_query_transaction_open_tcp(t);
- }
- if (r == -ESRCH) {
- /* No servers to send this to? */
- dns_query_transaction_complete(t, DNS_QUERY_NO_SERVERS);
- return 0;
- }
- if (r < 0) {
- /* Couldn't send? Try immediately again, with a new server */
- dns_scope_next_dns_server(t->scope);