/* * This file is part of PowerDNS or dnsdist. * Copyright -- PowerDNS.COM B.V. and its contributors * * This program is free software; you can redistribute it and/or modify * it under the terms of version 2 of the GNU General Public License as * published by the Free Software Foundation. * * In addition, for the avoidance of any doubt, permission is granted to * link this program with OpenSSL and to (re)distribute the binaries * produced as the result of such linking. * * This program is distributed in the hope that it will be useful, * but WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the * GNU General Public License for more details. * * You should have received a copy of the GNU General Public License * along with this program; if not, write to the Free Software * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. */ #include "config.h" #include "dnsdist.hh" #include "dnsdist-lua.hh" #include "dnsdist-svc.hh" #include "dolog.hh" void setupLuaBindings(LuaContext& luaCtx, bool client) { luaCtx.writeFunction("infolog", [](const string& arg) { infolog("%s", arg); }); luaCtx.writeFunction("errlog", [](const string& arg) { errlog("%s", arg); }); luaCtx.writeFunction("warnlog", [](const string& arg) { warnlog("%s", arg); }); luaCtx.writeFunction("show", [](const string& arg) { g_outputBuffer+=arg; g_outputBuffer+="\n"; }); /* Exceptions */ luaCtx.registerFunction("__tostring", [](const std::exception_ptr& eptr) { try { if (eptr) { std::rethrow_exception(eptr); } } catch(const std::exception& e) { return string(e.what()); } catch(const PDNSException& e) { return e.reason; } catch(...) { return string("Unknown exception"); } return string("No exception"); }); /* ServerPolicy */ luaCtx.writeFunction("newServerPolicy", [](string name, ServerPolicy::policyfunc_t policy) { return std::make_shared(name, policy, true);}); luaCtx.registerMember("name", &ServerPolicy::d_name); luaCtx.registerMember("policy", &ServerPolicy::d_policy); luaCtx.registerMember("ffipolicy", &ServerPolicy::d_ffipolicy); luaCtx.registerMember("isLua", &ServerPolicy::d_isLua); luaCtx.registerMember("isFFI", &ServerPolicy::d_isFFI); luaCtx.registerMember("isPerThread", &ServerPolicy::d_isPerThread); luaCtx.registerFunction("toString", &ServerPolicy::toString); luaCtx.registerFunction("__tostring", &ServerPolicy::toString); ServerPolicy policies[] = { ServerPolicy{"firstAvailable", firstAvailable, false}, ServerPolicy{"roundrobin", roundrobin, false}, ServerPolicy{"wrandom", wrandom, false}, ServerPolicy{"whashed", whashed, false}, ServerPolicy{"chashed", chashed, false}, ServerPolicy{"leastOutstanding", leastOutstanding, false} }; for (auto& policy : policies) { luaCtx.writeVariable(policy.d_name, policy); } /* ServerPool */ luaCtx.registerFunction::*)(std::shared_ptr)>("setCache", [](std::shared_ptr pool, std::shared_ptr cache) { if (pool) { pool->packetCache = cache; } }); luaCtx.registerFunction("getCache", &ServerPool::getCache); luaCtx.registerFunction::*)()>("unsetCache", [](std::shared_ptr pool) { if (pool) { pool->packetCache = nullptr; } }); luaCtx.registerFunction("getECS", &ServerPool::getECS); luaCtx.registerFunction("setECS", &ServerPool::setECS); /* DownstreamState */ luaCtx.registerFunction("setQPS", [](DownstreamState& s, int lim) { s.qps = lim ? QPSLimiter(lim, lim) : QPSLimiter(); }); luaCtx.registerFunction::*)(string)>("addPool", [](std::shared_ptr s, string pool) { auto localPools = g_pools.getCopy(); addServerToPool(localPools, pool, s); g_pools.setState(localPools); s->pools.insert(pool); }); luaCtx.registerFunction::*)(string)>("rmPool", [](std::shared_ptr s, string pool) { auto localPools = g_pools.getCopy(); removeServerFromPool(localPools, pool, s); g_pools.setState(localPools); s->pools.erase(pool); }); luaCtx.registerFunction("getOutstanding", [](const DownstreamState& s) { return s.outstanding.load(); }); luaCtx.registerFunction("getDrops", [](const DownstreamState& s) { return s.reuseds.load(); }); luaCtx.registerFunction("getLatency", [](const DownstreamState& s) { return s.latencyUsec; }); luaCtx.registerFunction("isUp", &DownstreamState::isUp); luaCtx.registerFunction("setDown", &DownstreamState::setDown); luaCtx.registerFunction("setUp", &DownstreamState::setUp); luaCtx.registerFunction newStatus)>("setAuto", [](DownstreamState& s, boost::optional newStatus) { if (newStatus) { s.setUpStatus(*newStatus); } s.setAuto(); }); luaCtx.registerFunction("getName", [](const DownstreamState& s) { return s.getName(); }); luaCtx.registerFunction("getNameWithAddr", [](const DownstreamState& s) { return s.getNameWithAddr(); }); luaCtx.registerMember("upStatus", &DownstreamState::upStatus); luaCtx.registerMember("weight", [](const DownstreamState& s) -> int {return s.weight;}, [](DownstreamState& s, int newWeight) {s.setWeight(newWeight);} ); luaCtx.registerMember("order", &DownstreamState::order); luaCtx.registerMember("name", [](const DownstreamState& backend) -> const std::string { return backend.getName(); }, [](DownstreamState& backend, const std::string& newName) { backend.setName(newName); }); luaCtx.registerFunction("getID", [](const DownstreamState& s) { return boost::uuids::to_string(s.id); }); /* dnsheader */ luaCtx.registerFunction("setRD", [](dnsheader& dh, bool v) { dh.rd=v; }); luaCtx.registerFunction("getRD", [](dnsheader& dh) { return (bool)dh.rd; }); luaCtx.registerFunction("setRA", [](dnsheader& dh, bool v) { dh.ra=v; }); luaCtx.registerFunction("getRA", [](dnsheader& dh) { return (bool)dh.ra; }); luaCtx.registerFunction("setAD", [](dnsheader& dh, bool v) { dh.ad=v; }); luaCtx.registerFunction("getAD", [](dnsheader& dh) { return (bool)dh.ad; }); luaCtx.registerFunction("setAA", [](dnsheader& dh, bool v) { dh.aa=v; }); luaCtx.registerFunction("getAA", [](dnsheader& dh) { return (bool)dh.aa; }); luaCtx.registerFunction("setCD", [](dnsheader& dh, bool v) { dh.cd=v; }); luaCtx.registerFunction("getCD", [](dnsheader& dh) { return (bool)dh.cd; }); luaCtx.registerFunction("setTC", [](dnsheader& dh, bool v) { dh.tc=v; if(v) dh.ra = dh.rd; // you'll always need this, otherwise TC=1 gets ignored }); luaCtx.registerFunction("setQR", [](dnsheader& dh, bool v) { dh.qr=v; }); /* ComboAddress */ luaCtx.writeFunction("newCA", [](const std::string& name) { return ComboAddress(name); }); luaCtx.writeFunction("newCAFromRaw", [](const std::string& raw, boost::optional port) { if (raw.size() == 4) { struct sockaddr_in sin4; memset(&sin4, 0, sizeof(sin4)); sin4.sin_family = AF_INET; memcpy(&sin4.sin_addr.s_addr, raw.c_str(), raw.size()); if (port) { sin4.sin_port = htons(*port); } return ComboAddress(&sin4); } else if (raw.size() == 16) { struct sockaddr_in6 sin6; memset(&sin6, 0, sizeof(sin6)); sin6.sin6_family = AF_INET6; memcpy(&sin6.sin6_addr.s6_addr, raw.c_str(), raw.size()); if (port) { sin6.sin6_port = htons(*port); } return ComboAddress(&sin6); } return ComboAddress(); }); luaCtx.registerFunction("tostring", [](const ComboAddress& ca) { return ca.toString(); }); luaCtx.registerFunction("tostringWithPort", [](const ComboAddress& ca) { return ca.toStringWithPort(); }); luaCtx.registerFunction("__tostring", [](const ComboAddress& ca) { return ca.toString(); }); luaCtx.registerFunction("toString", [](const ComboAddress& ca) { return ca.toString(); }); luaCtx.registerFunction("toStringWithPort", [](const ComboAddress& ca) { return ca.toStringWithPort(); }); luaCtx.registerFunction("getPort", [](const ComboAddress& ca) { return ntohs(ca.sin4.sin_port); } ); luaCtx.registerFunction("truncate", [](ComboAddress& ca, unsigned int bits) { ca.truncate(bits); }); luaCtx.registerFunction("isIPv4", [](const ComboAddress& ca) { return ca.sin4.sin_family == AF_INET; }); luaCtx.registerFunction("isIPv6", [](const ComboAddress& ca) { return ca.sin4.sin_family == AF_INET6; }); luaCtx.registerFunction("isMappedIPv4", [](const ComboAddress& ca) { return ca.isMappedIPv4(); }); luaCtx.registerFunction("mapToIPv4", [](const ComboAddress& ca) { return ca.mapToIPv4(); }); luaCtx.registerFunction("match", [](nmts_t& s, const ComboAddress& ca) { return s.match(ca); }); /* DNSName */ luaCtx.registerFunction("isPartOf", &DNSName::isPartOf); luaCtx.registerFunction("chopOff", [](DNSName&dn ) { return dn.chopOff(); }); luaCtx.registerFunction("countLabels", [](const DNSName& name) { return name.countLabels(); }); luaCtx.registerFunction("hash", [](const DNSName& name) { return name.hash(); }); luaCtx.registerFunction("wirelength", [](const DNSName& name) { return name.wirelength(); }); luaCtx.registerFunction("tostring", [](const DNSName&dn ) { return dn.toString(); }); luaCtx.registerFunction("toString", [](const DNSName&dn ) { return dn.toString(); }); luaCtx.registerFunction("__tostring", [](const DNSName&dn ) { return dn.toString(); }); luaCtx.registerFunction("toDNSString", [](const DNSName&dn ) { return dn.toDNSString(); }); luaCtx.writeFunction("newDNSName", [](const std::string& name) { return DNSName(name); }); luaCtx.writeFunction("newDNSNameFromRaw", [](const std::string& name) { return DNSName(name.c_str(), name.size(), 0, false); }); luaCtx.writeFunction("newSuffixMatchNode", []() { return SuffixMatchNode(); }); luaCtx.writeFunction("newDNSNameSet", []() { return DNSNameSet(); }); /* DNSNameSet */ luaCtx.registerFunction("toString", [](const DNSNameSet&dns ) { return dns.toString(); }); luaCtx.registerFunction("__tostring", [](const DNSNameSet&dns ) { return dns.toString(); }); luaCtx.registerFunction("add", [](DNSNameSet& dns, DNSName& dn) { dns.insert(dn); }); luaCtx.registerFunction("check", [](DNSNameSet& dns, DNSName& dn) { return dns.find(dn) != dns.end(); }); luaCtx.registerFunction("delete",(size_t (DNSNameSet::*)(const DNSName&)) &DNSNameSet::erase); luaCtx.registerFunction("size",(size_t (DNSNameSet::*)() const) &DNSNameSet::size); luaCtx.registerFunction("clear",(void (DNSNameSet::*)()) &DNSNameSet::clear); luaCtx.registerFunction("empty",(bool (DNSNameSet::*)() const) &DNSNameSet::empty); /* SuffixMatchNode */ luaCtx.registerFunction>, vector>> &name)>("add", [](SuffixMatchNode &smn, const boost::variant>, vector>> &name) { if (name.type() == typeid(DNSName)) { auto n = boost::get(name); smn.add(n); return; } if (name.type() == typeid(string)) { auto n = boost::get(name); smn.add(n); return; } if (name.type() == typeid(vector>)) { auto names = boost::get>>(name); for (const auto& n : names) { smn.add(n.second); } return; } if (name.type() == typeid(vector>)) { auto names = boost::get>>(name); for (const auto& n : names) { smn.add(n.second); } return; } }); luaCtx.registerFunction>, vector>> &name)>("remove", [](SuffixMatchNode &smn, const boost::variant>, vector>> &name) { if (name.type() == typeid(DNSName)) { auto n = boost::get(name); smn.remove(n); return; } if (name.type() == typeid(string)) { auto n = boost::get(name); DNSName d(n); smn.remove(d); return; } if (name.type() == typeid(vector>)) { auto names = boost::get>>(name); for (const auto& n : names) { smn.remove(n.second); } return; } if (name.type() == typeid(vector>)) { auto names = boost::get>>(name); for (const auto& n : names) { DNSName d(n.second); smn.remove(d); } return; } }); luaCtx.registerFunction("check",(bool (SuffixMatchNode::*)(const DNSName&) const) &SuffixMatchNode::check); /* Netmask */ luaCtx.writeFunction("newNetmask", [](boost::variant s, boost::optional bits) { if (s.type() == typeid(ComboAddress)) { auto ca = boost::get(s); if (bits) { return Netmask(ca, *bits); } return Netmask(ca); } else if (s.type() == typeid(std::string)) { auto str = boost::get(s); return Netmask(str); } throw std::runtime_error("Invalid parameter passed to 'newNetmask()'"); }); luaCtx.registerFunction("empty", &Netmask::empty); luaCtx.registerFunction("getBits", &Netmask::getBits); luaCtx.registerFunction("getNetwork", [](const Netmask& nm) { return nm.getNetwork(); } ); // const reference makes this necessary luaCtx.registerFunction("getMaskedNetwork", [](const Netmask& nm) { return nm.getMaskedNetwork(); } ); luaCtx.registerFunction("isIpv4", &Netmask::isIPv4); luaCtx.registerFunction("isIPv4", &Netmask::isIPv4); luaCtx.registerFunction("isIpv6", &Netmask::isIPv6); luaCtx.registerFunction("isIPv6", &Netmask::isIPv6); luaCtx.registerFunction("match", (bool (Netmask::*)(const string&) const)&Netmask::match); luaCtx.registerFunction("toString", &Netmask::toString); luaCtx.registerFunction("__tostring", &Netmask::toString); luaCtx.registerEqFunction(&Netmask::operator==); luaCtx.registerToStringFunction(&Netmask::toString); /* NetmaskGroup */ luaCtx.writeFunction("newNMG", []() { return NetmaskGroup(); }); luaCtx.registerFunction("addMask", [](NetmaskGroup&nmg, const std::string& mask) { nmg.addMask(mask); }); luaCtx.registerFunction& map)>("addMasks", [](NetmaskGroup&nmg, const std::map& map) { for (const auto& entry : map) { nmg.addMask(Netmask(entry.first)); } }); luaCtx.registerFunction("match", (bool (NetmaskGroup::*)(const ComboAddress&) const)&NetmaskGroup::match); luaCtx.registerFunction("size", &NetmaskGroup::size); luaCtx.registerFunction("clear", &NetmaskGroup::clear); luaCtx.registerFunction("toString", [](const NetmaskGroup& nmg ) { return "NetmaskGroup " + nmg.toString(); }); luaCtx.registerFunction("__tostring", [](const NetmaskGroup& nmg ) { return "NetmaskGroup " + nmg.toString(); }); /* QPSLimiter */ luaCtx.writeFunction("newQPSLimiter", [](int rate, int burst) { return QPSLimiter(rate, burst); }); luaCtx.registerFunction("check", &QPSLimiter::check); /* ClientState */ luaCtx.registerFunction("toString", [](const ClientState& fe) { setLuaNoSideEffect(); return fe.local.toStringWithPort(); }); luaCtx.registerFunction("__tostring", [](const ClientState& fe) { setLuaNoSideEffect(); return fe.local.toStringWithPort(); }); luaCtx.registerFunction("getType", [](const ClientState& fe) { setLuaNoSideEffect(); return fe.getType(); }); luaCtx.registerFunction("getConfiguredTLSProvider", [](const ClientState& fe) { setLuaNoSideEffect(); if (fe.tlsFrontend != nullptr) { return fe.tlsFrontend->getRequestedProvider(); } else if (fe.dohFrontend != nullptr) { return std::string("openssl"); } return std::string(); }); luaCtx.registerFunction("getEffectiveTLSProvider", [](const ClientState& fe) { setLuaNoSideEffect(); if (fe.tlsFrontend != nullptr) { return fe.tlsFrontend->getEffectiveProvider(); } else if (fe.dohFrontend != nullptr) { return std::string("openssl"); } return std::string(); }); luaCtx.registerMember("muted", &ClientState::muted); #ifdef HAVE_EBPF luaCtx.registerFunction)>("attachFilter", [](ClientState& frontend, std::shared_ptr bpf) { if (bpf) { frontend.attachFilter(bpf); } }); luaCtx.registerFunction("detachFilter", [](ClientState& frontend) { frontend.detachFilter(); }); #endif /* HAVE_EBPF */ /* BPF Filter */ #ifdef HAVE_EBPF using bpfFilterMapParams = boost::variant>>; luaCtx.writeFunction("newBPFFilter", [client](bpfFilterMapParams v4Params, bpfFilterMapParams v6Params, bpfFilterMapParams qnameParams, boost::optional external) { if (client) { return std::shared_ptr(nullptr); } BPFFilter::MapConfiguration v4Config, v6Config, qnameConfig; auto convertParamsToConfig = [](bpfFilterMapParams& params, BPFFilter::MapType type, BPFFilter::MapConfiguration& config) { config.d_type = type; if (params.type() == typeid(uint32_t)) { config.d_maxItems = boost::get(params); } else if (params.type() == typeid(std::unordered_map>)) { auto map = boost::get>>(params); if (map.count("maxItems")) { config.d_maxItems = boost::get(map.at("maxItems")); } if (map.count("pinnedPath")) { config.d_pinnedPath = boost::get(map.at("pinnedPath")); } } }; convertParamsToConfig(v4Params, BPFFilter::MapType::IPv4, v4Config); convertParamsToConfig(v6Params, BPFFilter::MapType::IPv6, v6Config); convertParamsToConfig(qnameParams, BPFFilter::MapType::QNames, qnameConfig); BPFFilter::MapFormat format = BPFFilter::MapFormat::Legacy; if (external && *external) { format = BPFFilter::MapFormat::WithActions; } return std::make_shared(v4Config, v6Config, qnameConfig, format, external.value_or(false)); }); luaCtx.registerFunction::*)(const ComboAddress& ca, boost::optional action)>("block", [](std::shared_ptr bpf, const ComboAddress& ca, boost::optional action) { if (bpf) { if (!action) { return bpf->block(ca, BPFFilter::MatchAction::Drop); } else { BPFFilter::MatchAction match; switch (*action) { case 0: match = BPFFilter::MatchAction::Pass; break; case 1: match = BPFFilter::MatchAction::Drop; break; case 2: match = BPFFilter::MatchAction::Truncate; break; default: throw std::runtime_error("Unsupported action for BPFFilter::block"); } return bpf->block(ca, match); } } }); luaCtx.registerFunction::*)(const DNSName& qname, boost::optional qtype, boost::optional action)>("blockQName", [](std::shared_ptr bpf, const DNSName& qname, boost::optional qtype, boost::optional action) { if (bpf) { if (!action) { return bpf->block(qname, BPFFilter::MatchAction::Drop, qtype.value_or(255)); } else { BPFFilter::MatchAction match; switch (*action) { case 0: match = BPFFilter::MatchAction::Pass; break; case 1: match = BPFFilter::MatchAction::Drop; break; case 2: match = BPFFilter::MatchAction::Truncate; break; default: throw std::runtime_error("Unsupported action for BPFFilter::blockQName"); } return bpf->block(qname, match, qtype.value_or(255)); } } }); luaCtx.registerFunction::*)(const ComboAddress& ca)>("unblock", [](std::shared_ptr bpf, const ComboAddress& ca) { if (bpf) { return bpf->unblock(ca); } }); luaCtx.registerFunction::*)(const DNSName& qname, boost::optional qtype)>("unblockQName", [](std::shared_ptr bpf, const DNSName& qname, boost::optional qtype) { if (bpf) { return bpf->unblock(qname, qtype ? *qtype : 255); } }); luaCtx.registerFunction::*)()const>("getStats", [](const std::shared_ptr bpf) { setLuaNoSideEffect(); std::string res; if (bpf) { auto stats = bpf->getAddrStats(); for (const auto& value : stats) { if (value.first.sin4.sin_family == AF_INET) { res += value.first.toString() + ": " + std::to_string(value.second) + "\n"; } else if (value.first.sin4.sin_family == AF_INET6) { res += "[" + value.first.toString() + "]: " + std::to_string(value.second) + "\n"; } } auto qstats = bpf->getQNameStats(); for (const auto& value : qstats) { res += std::get<0>(value).toString() + " " + std::to_string(std::get<1>(value)) + ": " + std::to_string(std::get<2>(value)) + "\n"; } } return res; }); luaCtx.registerFunction::*)()>("attachToAllBinds", [](std::shared_ptr bpf) { std::string res; if (bpf) { for (const auto& frontend : g_frontends) { frontend->attachFilter(bpf); } } }); luaCtx.writeFunction("newDynBPFFilter", [client](std::shared_ptr bpf) { if (client) { return std::shared_ptr(nullptr); } return std::make_shared(bpf); }); luaCtx.registerFunction::*)(const ComboAddress& addr, boost::optional seconds)>("block", [](std::shared_ptr dbpf, const ComboAddress& addr, boost::optional seconds) { if (dbpf) { struct timespec until; clock_gettime(CLOCK_MONOTONIC, &until); until.tv_sec += seconds ? *seconds : 10; dbpf->block(addr, until); } }); luaCtx.registerFunction::*)()>("purgeExpired", [](std::shared_ptr dbpf) { if (dbpf) { struct timespec now; clock_gettime(CLOCK_MONOTONIC, &now); dbpf->purgeExpired(now); } }); luaCtx.registerFunction::*)(boost::variant>>)>("excludeRange", [](std::shared_ptr dbpf, boost::variant>> ranges) { if (!dbpf) { return; } if (ranges.type() == typeid(std::vector>)) { for (const auto& range : *boost::get>>(&ranges)) { dbpf->excludeRange(Netmask(range.second)); } } else { dbpf->excludeRange(Netmask(*boost::get(&ranges))); } }); luaCtx.registerFunction::*)(boost::variant>>)>("includeRange", [](std::shared_ptr dbpf, boost::variant>> ranges) { if (!dbpf) { return; } if (ranges.type() == typeid(std::vector>)) { for (const auto& range : *boost::get>>(&ranges)) { dbpf->includeRange(Netmask(range.second)); } } else { dbpf->includeRange(Netmask(*boost::get(&ranges))); } }); #endif /* HAVE_EBPF */ /* EDNSOptionView */ luaCtx.registerFunction("count", [](const EDNSOptionView& option) { return option.values.size(); }); luaCtx.registerFunction(EDNSOptionView::*)()const>("getValues", [] (const EDNSOptionView& option) { std::vector values; for (const auto& value : option.values) { values.push_back(std::string(value.content, value.size)); } return values; }); luaCtx.writeFunction("newDOHResponseMapEntry", [](const std::string& regex, uint16_t status, const std::string& content, boost::optional> customHeaders) { boost::optional>> headers{boost::none}; if (customHeaders) { headers = std::vector>(); for (const auto& header : *customHeaders) { headers->push_back({ boost::to_lower_copy(header.first), header.second }); } } return std::make_shared(regex, status, PacketBuffer(content.begin(), content.end()), headers); }); luaCtx.writeFunction("newSVCRecordParameters", [](uint16_t priority, const std::string& target, boost::optional additionalParameters) { SVCRecordParameters parameters; if (additionalParameters) { parameters = parseSVCParameters(*additionalParameters); } parameters.priority = priority; parameters.target = DNSName(target); return parameters; }); }