-
Notifications
You must be signed in to change notification settings - Fork 62
/
dtlslistener.go
113 lines (95 loc) · 2.58 KB
/
dtlslistener.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
package rdns
import (
"bytes"
"context"
"net"
"strconv"
"time"
"github.com/miekg/dns"
"github.com/pion/dtls/v2"
"github.com/sirupsen/logrus"
)
// DTLSListener is a DNS listener/server for DNS-over-DTLS.
type DTLSListener struct {
*dns.Server
id string
opt DTLSListenerOptions
}
var _ Listener = &DTLSListener{}
// DoTListenerOptions contains options used by the DNS-over-DTLS server.
type DTLSListenerOptions struct {
ListenOptions
DTLSConfig *dtls.Config
}
// NewDTLSListener returns an instance of a DNS-over-DTLS listener.
func NewDTLSListener(id, addr string, opt DTLSListenerOptions, resolver Resolver) *DTLSListener {
return &DTLSListener{
id: id,
Server: &dns.Server{
Addr: addr,
Handler: listenHandler(id, "dtls", addr, resolver, opt.AllowedNet),
},
opt: opt,
}
}
// Start the DTLS server.
func (s *DTLSListener) Start() error {
Log.WithFields(logrus.Fields{"id": s.id, "protocol": "dtls", "addr": s.Addr}).Info("starting listener")
host, port, err := net.SplitHostPort(s.Server.Addr)
if err != nil {
return err
}
p, err := strconv.Atoi(port)
if err != nil {
return err
}
addr := &net.UDPAddr{IP: net.ParseIP(host), Port: p}
s.opt.DTLSConfig.ConnectContextMaker = func() (context.Context, func()) {
return context.WithTimeout(context.Background(), 2*time.Second)
}
listener, err := dtls.Listen("udp", addr, s.opt.DTLSConfig)
if err != nil {
return err
}
s.Server.Listener = dtlsListener{listener}
return s.Server.ActivateAndServe()
}
// Stop the server.
func (s *DTLSListener) Stop() error {
Log.WithFields(logrus.Fields{"id": s.id, "protocol": "dtls", "addr": s.Addr}).Info("stopping listener")
return s.Shutdown()
}
func (s *DTLSListener) String() string {
return s.id
}
// dtlsListener wraps a dtls.Listener to return a dtlsConn that
// supports partial reads.
type dtlsListener struct {
net.Listener
}
func (l dtlsListener) Accept() (net.Conn, error) {
conn, err := l.Listener.Accept()
return &dtlsConn{Conn: conn}, err
}
// dtlsConn wraps a dtls.Conn to support partial read operations. While
// github.com/pion/dtls/v2 returns a net.Conn, that Read() fails on
// slices that are smaller than the data available. This wrapper adds a
// buffer to allow github.com/miekg/dns to first read 2 bytes (size) and
// then the rest of the DNS packet.
type dtlsConn struct {
net.Conn
buf *bytes.Buffer
}
func (c *dtlsConn) Read(b []byte) (int, error) {
var (
n int
err error
)
if c.buf == nil || c.buf.Len() == 0 {
tmp := make([]byte, 4096)
n, err = c.Conn.Read(tmp)
c.buf = bytes.NewBuffer(tmp[:n])
}
n, _ = c.buf.Read(b)
return n, err
}