upleb.uk

Public git repos — served from a NIP-34 GRASP relay at git.upleb.uk

summaryrefslogtreecommitdiff
path: root/main/dns_server.c
diff options
context:
space:
mode:
authorYour Name <you@example.com>2026-05-23 04:50:26 +0530
committerYour Name <you@example.com>2026-05-23 04:50:26 +0530
commit9330b01c28aebc865a3c0a51df8730196cb4152e (patch)
tree60c3ae35b2550c737c228e81fd342c8d07af11af /main/dns_server.c
parent851801f50f1282ab1db5f8a241dbd245f59e447e (diff)
Phase 6a-6d: Consolidate and clean up
6a: Delete dead standalone tollgate_core/ (12 files, never compiled) 6b: Rewrite dns_server.c as thin shim to component's tollgate_core_dns - Fix component DNS to bind to AP IP instead of INADDR_ANY 6c: Rewrite stratum_proxy.c as thin shim with struct cast to component types 6d: Move sandbox logic into component's tollgate_core_firewall - Add tollgate_core_fw_set_sandbox_ports/set_sandbox_mint_access - Add is_sandbox_allowed() to component's ip4_canforward_filter - Clean main/firewall.c to delegate filter to component - Remove redundant DNS auth double-calls from main firewall Add ROADMAP.md with full extraction plan and checklists All 21 unit tests pass. ESP-IDF build passes.
Diffstat (limited to 'main/dns_server.c')
-rw-r--r--main/dns_server.c304
1 files changed, 5 insertions, 299 deletions
diff --git a/main/dns_server.c b/main/dns_server.c
index b84a4cf..5b1bdc3 100644
--- a/main/dns_server.c
+++ b/main/dns_server.c
@@ -1,316 +1,22 @@
1#include "dns_server.h" 1#include "dns_server.h"
2#include "esp_log.h" 2#include "tollgate_core_dns.h"
3#include "freertos/FreeRTOS.h"
4#include "freertos/task.h"
5#include "lwip/sockets.h"
6#include "lwip/netdb.h"
7#include <string.h>
8#include <sys/param.h>
9
10#define MAX_AUTH_IPS 10
11#define MAX_PENDING 50
12#define DNS_BUF_SIZE 512
13#define DNS_PORT 53
14#define DOT_PORT 853
15#define DNS_TASK_STACK 4096
16#define DOT_TASK_STACK 3072
17#define DNS_TASK_PRIO 5
18#define DOT_TASK_PRIO 5
19#define DNS_FORWARD_TIMEOUT_MS 2000
20#define NXDOMAIN_TTL 30
21#define HIJACK_TTL 10
22
23static const char *TAG = "dns_server";
24
25#pragma pack(push, 1)
26typedef struct {
27 uint16_t id;
28 uint16_t flags;
29 uint16_t qdcount;
30 uint16_t ancount;
31 uint16_t nscount;
32 uint16_t arcount;
33} dns_header_t;
34#pragma pack(pop)
35
36#pragma pack(push, 1)
37typedef struct {
38 uint16_t name;
39 uint16_t type;
40 uint16_t class;
41 uint32_t ttl;
42 uint16_t len;
43 uint32_t addr;
44} dns_answer_t;
45#pragma pack(pop)
46
47typedef struct {
48 uint32_t ip;
49} auth_entry_t;
50
51static auth_entry_t s_auth_list[MAX_AUTH_IPS];
52static int s_auth_count = 0;
53static TaskHandle_t s_dns_task = NULL;
54static TaskHandle_t s_dot_task = NULL;
55static volatile bool s_dns_running = false;
56static esp_ip4_addr_t s_ap_ip;
57static esp_ip4_addr_t s_upstream_dns;
58
59static bool is_authenticated(uint32_t ip)
60{
61 for (int i = 0; i < s_auth_count; i++) {
62 if (s_auth_list[i].ip == ip) return true;
63 }
64 return false;
65}
66
67static void parse_dns_name(const uint8_t *buf, int buf_len, int offset, char *out, int out_len)
68{
69 int pos = offset;
70 int out_pos = 0;
71 int jumped = 0;
72 int jump_pos = 0;
73 while (pos < buf_len && out_pos < out_len - 1) {
74 uint8_t len = buf[pos];
75 if (len == 0) break;
76 if ((len & 0xC0) == 0xC0) {
77 if (!jumped) jump_pos = pos + 2;
78 pos = ((len & 0x3F) << 8) | buf[pos + 1];
79 jumped = 1;
80 continue;
81 }
82 if (out_pos > 0 && out_pos < out_len - 1) out[out_pos++] = '.';
83 pos++;
84 for (int i = 0; i < len && pos < buf_len && out_pos < out_len - 1; i++) {
85 out[out_pos++] = buf[pos++];
86 }
87 }
88 out[out_pos] = '\0';
89}
90
91static int build_nxdomain(uint8_t *response, int req_len)
92{
93 dns_header_t *hdr = (dns_header_t *)response;
94 hdr->flags = htons(0x8403);
95 hdr->ancount = 0;
96 hdr->nscount = 0;
97 hdr->arcount = 0;
98 return req_len;
99}
100
101static int build_redirect_response(uint8_t *response, int req_len)
102{
103 memmove(response, response, req_len);
104 dns_header_t *hdr = (dns_header_t *)response;
105 hdr->flags = htons(0x8180);
106 hdr->ancount = htons(1);
107 hdr->nscount = 0;
108 hdr->arcount = 0;
109 int resp_len = req_len;
110 dns_answer_t ans;
111 ans.name = htons(0xC00C);
112 ans.type = htons(1);
113 ans.class = htons(1);
114 ans.ttl = htonl(HIJACK_TTL);
115 ans.len = htons(4);
116 ans.addr = s_ap_ip.addr;
117 memcpy(response + resp_len, &ans, sizeof(ans));
118 resp_len += sizeof(ans);
119 return resp_len;
120}
121
122static int forward_dns(const uint8_t *req, int req_len, uint8_t *resp, int resp_buf_len,
123 const struct sockaddr_in *client_addr, uint16_t txn_id)
124{
125 int upstream_sock = socket(AF_INET, SOCK_DGRAM, 0);
126 if (upstream_sock < 0) return -1;
127
128 struct timeval tv = { .tv_sec = DNS_FORWARD_TIMEOUT_MS / 1000, .tv_usec = (DNS_FORWARD_TIMEOUT_MS % 1000) * 1000 };
129 setsockopt(upstream_sock, SOL_SOCKET, SO_RCVTIMEO, &tv, sizeof(tv));
130
131 struct sockaddr_in upstream_addr = {
132 .sin_family = AF_INET,
133 .sin_port = htons(DNS_PORT),
134 .sin_addr.s_addr = s_upstream_dns.addr,
135 };
136
137 sendto(upstream_sock, req, req_len, 0, (struct sockaddr *)&upstream_addr, sizeof(upstream_addr));
138
139 int n = recvfrom(upstream_sock, resp, resp_buf_len, 0, NULL, NULL);
140 close(upstream_sock);
141
142 if (n > 0) {
143 if (n >= sizeof(dns_header_t)) {
144 dns_header_t *hdr = (dns_header_t *)resp;
145 hdr->id = htons(txn_id);
146 }
147 }
148 return n;
149}
150
151static void dns_server_task(void *arg)
152{
153 int sock = socket(AF_INET, SOCK_DGRAM, 0);
154 if (sock < 0) {
155 ESP_LOGE(TAG, "Failed to create DNS socket");
156 s_dns_running = false;
157 vTaskDelete(NULL);
158 return;
159 }
160
161 struct sockaddr_in bind_addr = {
162 .sin_family = AF_INET,
163 .sin_port = htons(DNS_PORT),
164 .sin_addr.s_addr = s_ap_ip.addr,
165 };
166 if (bind(sock, (struct sockaddr *)&bind_addr, sizeof(bind_addr)) < 0) {
167 ESP_LOGE(TAG, "Failed to bind DNS socket");
168 close(sock);
169 s_dns_running = false;
170 vTaskDelete(NULL);
171 return;
172 }
173
174 ESP_LOGI(TAG, "DNS server started on port %d, AP IP=" IPSTR ", upstream DNS=" IPSTR,
175 DNS_PORT, IP2STR(&s_ap_ip), IP2STR(&s_upstream_dns));
176
177 uint8_t rx_buf[DNS_BUF_SIZE];
178 uint8_t tx_buf[DNS_BUF_SIZE + sizeof(dns_answer_t)];
179
180 while (s_dns_running) {
181 struct sockaddr_in client_addr;
182 socklen_t client_len = sizeof(client_addr);
183 int n = recvfrom(sock, rx_buf, sizeof(rx_buf), 0,
184 (struct sockaddr *)&client_addr, &client_len);
185 if (n < (int)sizeof(dns_header_t)) continue;
186
187 uint32_t client_ip = client_addr.sin_addr.s_addr;
188 dns_header_t *hdr = (dns_header_t *)rx_buf;
189 uint16_t txn_id = ntohs(hdr->id);
190 bool is_query = (ntohs(hdr->flags) & 0x8000) == 0;
191 uint16_t qdcount = ntohs(hdr->qdcount);
192
193 if (!is_query || qdcount == 0) continue;
194
195 int q_offset = sizeof(dns_header_t);
196 while (q_offset < n && rx_buf[q_offset] != 0) {
197 q_offset += rx_buf[q_offset] + 1;
198 }
199 if (q_offset + 5 > n) continue;
200 uint16_t qtype = (rx_buf[q_offset + 1] << 8) | rx_buf[q_offset + 2];
201 int req_len = q_offset + 5;
202
203 if (is_authenticated(client_ip)) {
204 int resp_len = forward_dns(rx_buf, req_len, tx_buf, sizeof(tx_buf), &client_addr, txn_id);
205 if (resp_len > 0) {
206 sendto(sock, tx_buf, resp_len, 0, (struct sockaddr *)&client_addr, client_len);
207 }
208 } else {
209 char qname[256] = {0};
210 parse_dns_name(rx_buf, n, sizeof(dns_header_t), qname, sizeof(qname));
211 ESP_LOGI(TAG, "Hijack DNS from " IPSTR ": %s (type=%d)", IP2STR(&(esp_ip4_addr_t){.addr=client_ip}), qname, qtype);
212 if (qtype == 1) {
213 int resp_len = build_redirect_response(rx_buf, req_len);
214 memcpy(tx_buf, rx_buf, resp_len);
215 dns_header_t *resp_hdr = (dns_header_t *)tx_buf;
216 resp_hdr->id = htons(txn_id);
217 sendto(sock, tx_buf, resp_len, 0, (struct sockaddr *)&client_addr, client_len);
218 } else {
219 int resp_len = build_nxdomain(rx_buf, req_len);
220 memcpy(tx_buf, rx_buf, resp_len);
221 dns_header_t *resp_hdr = (dns_header_t *)tx_buf;
222 resp_hdr->id = htons(txn_id);
223 sendto(sock, tx_buf, resp_len, 0, (struct sockaddr *)&client_addr, client_len);
224 }
225 }
226 }
227
228 close(sock);
229 ESP_LOGI(TAG, "DNS server stopped");
230 vTaskDelete(NULL);
231}
232
233static void dot_reject_task(void *arg)
234{
235 int sock = socket(AF_INET, SOCK_STREAM, 0);
236 if (sock < 0) {
237 ESP_LOGE(TAG, "Failed to create DoT reject socket");
238 vTaskDelete(NULL);
239 return;
240 }
241
242 int opt = 1;
243 setsockopt(sock, SOL_SOCKET, SO_REUSEADDR, &opt, sizeof(opt));
244
245 struct sockaddr_in bind_addr = {
246 .sin_family = AF_INET,
247 .sin_port = htons(DOT_PORT),
248 .sin_addr.s_addr = INADDR_ANY,
249 };
250 if (bind(sock, (struct sockaddr *)&bind_addr, sizeof(bind_addr)) < 0) {
251 ESP_LOGE(TAG, "Failed to bind DoT reject socket on port %d", DOT_PORT);
252 close(sock);
253 vTaskDelete(NULL);
254 return;
255 }
256
257 listen(sock, 1);
258 ESP_LOGI(TAG, "DoT reject server on port %d (forces DNS fallback to port 53)", DOT_PORT);
259
260 while (s_dns_running) {
261 struct sockaddr_in client_addr;
262 socklen_t client_len = sizeof(client_addr);
263 int client_sock = accept(sock, (struct sockaddr *)&client_addr, &client_len);
264 if (client_sock >= 0) {
265 struct linger ling = { .l_onoff = 1, .l_linger = 0 };
266 setsockopt(client_sock, SOL_SOCKET, SO_LINGER, &ling, sizeof(ling));
267 close(client_sock);
268 }
269 }
270
271 close(sock);
272 ESP_LOGI(TAG, "DoT reject server stopped");
273 vTaskDelete(NULL);
274}
275 3
276esp_err_t dns_server_start(esp_ip4_addr_t ap_ip, esp_ip4_addr_t upstream_dns) 4esp_err_t dns_server_start(esp_ip4_addr_t ap_ip, esp_ip4_addr_t upstream_dns)
277{ 5{
278 if (s_dns_running) return ESP_OK; 6 return tollgate_core_dns_start_internal(ap_ip, upstream_dns);
279 s_ap_ip = ap_ip;
280 s_upstream_dns = upstream_dns;
281 s_dns_running = true;
282 xTaskCreate(dns_server_task, "dns_server", DNS_TASK_STACK, NULL, DNS_TASK_PRIO, &s_dns_task);
283 xTaskCreate(dot_reject_task, "dot_reject", DOT_TASK_STACK, NULL, DOT_TASK_PRIO, &s_dot_task);
284 return ESP_OK;
285} 7}
286 8
287void dns_server_stop(void) 9void dns_server_stop(void)
288{ 10{
289 s_dns_running = false; 11 tollgate_core_dns_stop();
290 vTaskDelay(pdMS_TO_TICKS(200));
291 s_dns_task = NULL;
292} 12}
293 13
294void dns_server_set_client_authenticated(uint32_t client_ip, bool authenticated) 14void dns_server_set_client_authenticated(uint32_t client_ip, bool authenticated)
295{ 15{
296 if (authenticated) { 16 tollgate_core_dns_set_authenticated(client_ip, authenticated);
297 if (is_authenticated(client_ip)) return;
298 if (s_auth_count < MAX_AUTH_IPS) {
299 s_auth_list[s_auth_count].ip = client_ip;
300 s_auth_count++;
301 }
302 } else {
303 for (int i = 0; i < s_auth_count; i++) {
304 if (s_auth_list[i].ip == client_ip) {
305 s_auth_list[i] = s_auth_list[s_auth_count - 1];
306 s_auth_count--;
307 return;
308 }
309 }
310 }
311} 17}
312 18
313bool dns_server_is_running(void) 19bool dns_server_is_running(void)
314{ 20{
315 return s_dns_running; 21 return tollgate_core_dns_is_running();
316} 22}