mirror of
https://github.com/curl/curl.git
synced 2026-04-11 12:01:42 +08:00
- allow to specify when they are wanted on starting a resolve - match dns cache entries accordingly. An entry which never tried to get HTTPS-RRs is no answer for a resolve that wants it. - fix late arrivals of resolve answers to match the "async" records that started them - if it still exists. - provide for multiple "async" resolves in a transfer at the same time. We may need to resolve an IP interface while the main connection resolve has not finished yet. - allow lookup of HTTPS-RR information as soon as it is available, even if A/AAAA queries are still ongoing. For this, the "async" infrastructure is changed: - Defined bits for DNS queries `CURL_DNSQ_A`, `CURL_DNSQ_AAAA` and `CURL_DNSQ_HTTPS`. These replace `ip_version` which says nothing about HTTPS. Use them in dns cache entries for matching. - enhance the `async->id` to be a unique `uint32_t` for resolves inside one multi. This is weak, as the id may wrap around. However it is combined with the `mid` of the easy handle, making collisions highly unlikely. `data->state.async` is only accessed in few places where the mid/async-id match is performed. - vtls: for ECH supporting TLS backends (openssl, rustls, wolfssl), retrieve the HTTPS-RR information from the dns connection filter. Delay the connect if the HTTPS-RR is needed, but has not been resolved yet. The implementation of all this is complete for the threaded resolver. c-ares resolver and DoH do not take advantage of all new async features yet. To be done in separate PRs. Details: c-ares: cleanup settings and initialisation. Any ares channel is only being created on starting a resolve and propagating operations in setopt.c to the channel are not helpful. Changed threaded+ares pollset handling so that they do not overwrite each others `ASYNC_NAME` timeouts. Add trace name 'threads' for tracing thread queue and pool used by threaded resolver. Closes #21175
179 lines
4.9 KiB
C
179 lines
4.9 KiB
C
#ifndef HEADER_CURL_DOH_H
|
|
#define HEADER_CURL_DOH_H
|
|
/***************************************************************************
|
|
* _ _ ____ _
|
|
* Project ___| | | | _ \| |
|
|
* / __| | | | |_) | |
|
|
* | (__| |_| | _ <| |___
|
|
* \___|\___/|_| \_\_____|
|
|
*
|
|
* Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
|
|
*
|
|
* This software is licensed as described in the file COPYING, which
|
|
* you should have received as part of this distribution. The terms
|
|
* are also available at https://curl.se/docs/copyright.html.
|
|
*
|
|
* You may opt to use, copy, modify, merge, publish, distribute and/or sell
|
|
* copies of the Software, and permit persons to whom the Software is
|
|
* furnished to do so, under the terms of the COPYING file.
|
|
*
|
|
* This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
|
|
* KIND, either express or implied.
|
|
*
|
|
* SPDX-License-Identifier: curl
|
|
*
|
|
***************************************************************************/
|
|
#include "urldata.h"
|
|
|
|
/* enums outside of the #ifdef to make the types work in unitprotos.h even on
|
|
builds without DoH support */
|
|
|
|
struct Curl_resolv_async;
|
|
|
|
typedef enum {
|
|
DOH_OK,
|
|
DOH_DNS_BAD_LABEL, /* 1 */
|
|
DOH_DNS_OUT_OF_RANGE, /* 2 */
|
|
DOH_DNS_LABEL_LOOP, /* 3 */
|
|
DOH_TOO_SMALL_BUFFER, /* 4 */
|
|
DOH_OUT_OF_MEM, /* 5 */
|
|
DOH_DNS_RDATA_LEN, /* 6 */
|
|
DOH_DNS_MALFORMAT, /* 7 */
|
|
DOH_DNS_BAD_RCODE, /* 8 - no such name */
|
|
DOH_DNS_UNEXPECTED_TYPE, /* 9 */
|
|
DOH_DNS_UNEXPECTED_CLASS, /* 10 */
|
|
DOH_NO_CONTENT, /* 11 */
|
|
DOH_DNS_BAD_ID, /* 12 */
|
|
DOH_DNS_NAME_TOO_LONG /* 13 */
|
|
} DOHcode;
|
|
|
|
typedef enum {
|
|
CURL_DNS_TYPE_A = 1,
|
|
CURL_DNS_TYPE_NS = 2,
|
|
CURL_DNS_TYPE_CNAME = 5,
|
|
CURL_DNS_TYPE_AAAA = 28,
|
|
CURL_DNS_TYPE_DNAME = 39, /* RFC6672 */
|
|
CURL_DNS_TYPE_HTTPS = 65
|
|
} DNStype;
|
|
|
|
struct dohentry; /* forward-declare for non-DoH builds */
|
|
|
|
#ifndef CURL_DISABLE_DOH
|
|
|
|
enum doh_slot_num {
|
|
/* Explicit values for first two symbols so as to match hard-coded
|
|
* constants in existing code
|
|
*/
|
|
DOH_SLOT_IPV4 = 0, /* make 'V4' stand out for readability */
|
|
DOH_SLOT_IPV6 = 1, /* 'V6' likewise */
|
|
|
|
/* Space here for (possibly build-specific) additional slot definitions */
|
|
#ifdef USE_HTTPSRR
|
|
DOH_SLOT_HTTPS_RR = 2, /* for HTTPS RR */
|
|
#endif
|
|
|
|
/* for example */
|
|
/* #ifdef WANT_DOH_FOOBAR_TXT */
|
|
/* DOH_PROBE_SLOT_FOOBAR_TXT, */
|
|
/* #endif */
|
|
|
|
/* AFTER all slot definitions, establish how many we have */
|
|
DOH_SLOT_COUNT
|
|
};
|
|
|
|
#define CURL_EZM_DOH_PROBE "ezm:doh-p"
|
|
|
|
/* the largest one we can make, based on RFCs 1034, 1035 */
|
|
#define DOH_MAX_DNSREQ_SIZE (256 + 16)
|
|
|
|
/* each DoH probe request has this
|
|
* as easy meta for CURL_EZM_DOH_PROBE */
|
|
struct doh_request {
|
|
unsigned char req_body[DOH_MAX_DNSREQ_SIZE];
|
|
struct curl_slist *req_hds;
|
|
struct dynbuf resp_body;
|
|
size_t req_body_len;
|
|
uint32_t resolv_id; /* id of the resolve operation */
|
|
DNStype dnstype;
|
|
};
|
|
|
|
struct doh_response {
|
|
uint32_t probe_mid;
|
|
struct dynbuf body;
|
|
DNStype dnstype;
|
|
CURLcode result;
|
|
};
|
|
|
|
/* each transfer firing off DoH requests has this
|
|
* as easy meta for CURL_EZM_DOH_MASTER */
|
|
struct doh_probes {
|
|
struct doh_response probe_resp[DOH_SLOT_COUNT];
|
|
unsigned int pending; /* still outstanding probes */
|
|
uint16_t port;
|
|
const char *host;
|
|
};
|
|
|
|
/*
|
|
* Curl_doh() starts a name resolve using DoH (DNS-over-HTTPS). It resolves a
|
|
* name and returns a 'Curl_addrinfo *' with the address information.
|
|
*/
|
|
|
|
CURLcode Curl_doh(struct Curl_easy *data,
|
|
struct Curl_resolv_async *async);
|
|
|
|
CURLcode Curl_doh_take_result(struct Curl_easy *data,
|
|
struct Curl_resolv_async *async,
|
|
struct Curl_dns_entry **dns);
|
|
|
|
#define DOH_MAX_ADDR 24
|
|
#define DOH_MAX_CNAME 4
|
|
#define DOH_MAX_HTTPS 4
|
|
|
|
struct dohaddr {
|
|
int type;
|
|
union {
|
|
unsigned char v4[4]; /* network byte order */
|
|
unsigned char v6[16];
|
|
} ip;
|
|
};
|
|
|
|
#ifdef USE_HTTPSRR
|
|
|
|
/*
|
|
* These may need escaping when found within an ALPN string
|
|
* value.
|
|
*/
|
|
#define COMMA_CHAR ','
|
|
#define BACKSLASH_CHAR '\\'
|
|
|
|
struct dohhttps_rr {
|
|
uint16_t len; /* raw encoded length */
|
|
unsigned char *val; /* raw encoded octets */
|
|
};
|
|
#endif
|
|
|
|
struct dohentry {
|
|
struct dynbuf cname[DOH_MAX_CNAME];
|
|
struct dohaddr addr[DOH_MAX_ADDR];
|
|
int numaddr;
|
|
unsigned int ttl;
|
|
int numcname;
|
|
#ifdef USE_HTTPSRR
|
|
struct dohhttps_rr https_rrs[DOH_MAX_HTTPS];
|
|
int numhttps_rrs;
|
|
#endif
|
|
};
|
|
|
|
void Curl_doh_cleanup(struct Curl_easy *data,
|
|
struct Curl_resolv_async *async);
|
|
#define Curl_doh_wanted(d) (!!(d)->set.doh)
|
|
|
|
|
|
#else /* CURL_DISABLE_DOH */
|
|
#define Curl_doh(a, b) NULL
|
|
#define Curl_doh_take_result(x, y, z) CURLE_COULDNT_RESOLVE_HOST
|
|
#define Curl_doh_wanted(d) FALSE
|
|
#endif /* !CURL_DISABLE_DOH */
|
|
|
|
#endif /* HEADER_CURL_DOH_H */
|