2018-12-05 04:03:41 -07:00
|
|
|
package dnsforward
|
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
|
|
|
"os"
|
|
|
|
"path"
|
|
|
|
"runtime"
|
|
|
|
"strings"
|
|
|
|
"sync"
|
|
|
|
"time"
|
|
|
|
|
|
|
|
"github.com/bluele/gcache"
|
2018-12-29 09:12:22 -07:00
|
|
|
"github.com/hmage/golibs/log"
|
2018-12-05 04:03:41 -07:00
|
|
|
"github.com/miekg/dns"
|
|
|
|
)
|
|
|
|
|
|
|
|
type hourTop struct {
|
|
|
|
domains gcache.Cache
|
|
|
|
blocked gcache.Cache
|
|
|
|
clients gcache.Cache
|
|
|
|
|
|
|
|
mutex sync.RWMutex
|
|
|
|
}
|
|
|
|
|
2019-01-24 10:11:01 -07:00
|
|
|
func (h *hourTop) init() {
|
|
|
|
h.domains = gcache.New(queryLogTopSize).LRU().Build()
|
|
|
|
h.blocked = gcache.New(queryLogTopSize).LRU().Build()
|
|
|
|
h.clients = gcache.New(queryLogTopSize).LRU().Build()
|
2018-12-05 04:03:41 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
type dayTop struct {
|
|
|
|
hours []*hourTop
|
|
|
|
hoursLock sync.RWMutex // writelock this lock ONLY WHEN rotating or intializing hours!
|
|
|
|
|
|
|
|
loaded bool
|
|
|
|
loadedLock sync.Mutex
|
|
|
|
}
|
|
|
|
|
2019-02-10 10:47:43 -07:00
|
|
|
func (d *dayTop) init() {
|
|
|
|
d.hoursWriteLock()
|
2018-12-05 04:03:41 -07:00
|
|
|
for i := 0; i < 24; i++ {
|
|
|
|
hour := hourTop{}
|
|
|
|
hour.init()
|
2019-02-10 10:47:43 -07:00
|
|
|
d.hours = append(d.hours, &hour)
|
2018-12-05 04:03:41 -07:00
|
|
|
}
|
2019-02-10 10:47:43 -07:00
|
|
|
d.hoursWriteUnlock()
|
2018-12-05 04:03:41 -07:00
|
|
|
}
|
|
|
|
|
2019-02-10 10:47:43 -07:00
|
|
|
func (d *dayTop) rotateHourlyTop() {
|
2018-12-05 04:03:41 -07:00
|
|
|
log.Printf("Rotating hourly top")
|
|
|
|
hour := &hourTop{}
|
|
|
|
hour.init()
|
2019-02-10 10:47:43 -07:00
|
|
|
d.hoursWriteLock()
|
|
|
|
d.hours = append([]*hourTop{hour}, d.hours...)
|
|
|
|
d.hours = d.hours[:24]
|
|
|
|
d.hoursWriteUnlock()
|
2018-12-05 04:03:41 -07:00
|
|
|
}
|
|
|
|
|
2019-02-10 10:47:43 -07:00
|
|
|
func (d *dayTop) periodicHourlyTopRotate() {
|
2018-12-05 04:03:41 -07:00
|
|
|
t := time.Hour
|
|
|
|
for range time.Tick(t) {
|
2019-02-10 10:47:43 -07:00
|
|
|
d.rotateHourlyTop()
|
2018-12-05 04:03:41 -07:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-01-24 10:11:01 -07:00
|
|
|
func (h *hourTop) incrementValue(key string, cache gcache.Cache) error {
|
|
|
|
h.Lock()
|
|
|
|
defer h.Unlock()
|
2018-12-05 04:03:41 -07:00
|
|
|
ivalue, err := cache.Get(key)
|
|
|
|
if err == gcache.KeyNotFoundError {
|
|
|
|
// we just set it and we're done
|
|
|
|
err = cache.Set(key, 1)
|
|
|
|
if err != nil {
|
|
|
|
log.Printf("Failed to set hourly top value: %s", err)
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
if err != nil {
|
|
|
|
log.Printf("gcache encountered an error during get: %s", err)
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
cachedValue, ok := ivalue.(int)
|
|
|
|
if !ok {
|
|
|
|
err = fmt.Errorf("SHOULD NOT HAPPEN: gcache has non-int as value: %v", ivalue)
|
|
|
|
log.Println(err)
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
err = cache.Set(key, cachedValue+1)
|
|
|
|
if err != nil {
|
|
|
|
log.Printf("Failed to set hourly top value: %s", err)
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2019-01-24 10:11:01 -07:00
|
|
|
func (h *hourTop) incrementDomains(key string) error {
|
|
|
|
return h.incrementValue(key, h.domains)
|
2018-12-05 04:03:41 -07:00
|
|
|
}
|
|
|
|
|
2019-01-24 10:11:01 -07:00
|
|
|
func (h *hourTop) incrementBlocked(key string) error {
|
|
|
|
return h.incrementValue(key, h.blocked)
|
2018-12-05 04:03:41 -07:00
|
|
|
}
|
|
|
|
|
2019-01-24 10:11:01 -07:00
|
|
|
func (h *hourTop) incrementClients(key string) error {
|
|
|
|
return h.incrementValue(key, h.clients)
|
2018-12-05 04:03:41 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
// if does not exist -- return 0
|
2019-01-24 10:11:01 -07:00
|
|
|
func (h *hourTop) lockedGetValue(key string, cache gcache.Cache) (int, error) {
|
2018-12-05 04:03:41 -07:00
|
|
|
ivalue, err := cache.Get(key)
|
|
|
|
if err == gcache.KeyNotFoundError {
|
|
|
|
return 0, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
if err != nil {
|
|
|
|
log.Printf("gcache encountered an error during get: %s", err)
|
|
|
|
return 0, err
|
|
|
|
}
|
|
|
|
|
|
|
|
value, ok := ivalue.(int)
|
|
|
|
if !ok {
|
|
|
|
err := fmt.Errorf("SHOULD NOT HAPPEN: gcache has non-int as value: %v", ivalue)
|
|
|
|
log.Println(err)
|
|
|
|
return 0, err
|
|
|
|
}
|
|
|
|
|
|
|
|
return value, nil
|
|
|
|
}
|
|
|
|
|
2019-01-24 10:11:01 -07:00
|
|
|
func (h *hourTop) lockedGetDomains(key string) (int, error) {
|
|
|
|
return h.lockedGetValue(key, h.domains)
|
2018-12-05 04:03:41 -07:00
|
|
|
}
|
|
|
|
|
2019-01-24 10:11:01 -07:00
|
|
|
func (h *hourTop) lockedGetBlocked(key string) (int, error) {
|
|
|
|
return h.lockedGetValue(key, h.blocked)
|
2018-12-05 04:03:41 -07:00
|
|
|
}
|
|
|
|
|
2019-01-24 10:11:01 -07:00
|
|
|
func (h *hourTop) lockedGetClients(key string) (int, error) {
|
|
|
|
return h.lockedGetValue(key, h.clients)
|
2018-12-05 04:03:41 -07:00
|
|
|
}
|
|
|
|
|
2019-01-24 10:11:01 -07:00
|
|
|
func (d *dayTop) addEntry(entry *logEntry, q *dns.Msg, now time.Time) error {
|
2018-12-05 04:03:41 -07:00
|
|
|
// figure out which hour bucket it belongs to
|
|
|
|
hour := int(now.Sub(entry.Time).Hours())
|
|
|
|
if hour >= 24 {
|
|
|
|
log.Printf("t %v is >24 hours ago, ignoring", entry.Time)
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2018-12-29 07:47:50 -07:00
|
|
|
// if a DNS query doesn't have questions, do nothing
|
|
|
|
if len(q.Question) == 0 {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2018-12-05 04:03:41 -07:00
|
|
|
hostname := strings.ToLower(strings.TrimSuffix(q.Question[0].Name, "."))
|
|
|
|
|
|
|
|
// get value, if not set, crate one
|
2019-02-10 10:47:43 -07:00
|
|
|
d.hoursReadLock()
|
|
|
|
defer d.hoursReadUnlock()
|
|
|
|
err := d.hours[hour].incrementDomains(hostname)
|
2018-12-05 04:03:41 -07:00
|
|
|
if err != nil {
|
|
|
|
log.Printf("Failed to increment value: %s", err)
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2018-12-06 07:27:38 -07:00
|
|
|
if entry.Result.IsFiltered {
|
2019-02-10 10:47:43 -07:00
|
|
|
err := d.hours[hour].incrementBlocked(hostname)
|
2018-12-05 04:03:41 -07:00
|
|
|
if err != nil {
|
|
|
|
log.Printf("Failed to increment value: %s", err)
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if len(entry.IP) > 0 {
|
2019-02-10 10:47:43 -07:00
|
|
|
err := d.hours[hour].incrementClients(entry.IP)
|
2018-12-05 04:03:41 -07:00
|
|
|
if err != nil {
|
|
|
|
log.Printf("Failed to increment value: %s", err)
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2019-02-10 10:47:43 -07:00
|
|
|
func (l *queryLog) fillStatsFromQueryLog(s *stats) error {
|
2018-12-05 04:03:41 -07:00
|
|
|
now := time.Now()
|
2019-02-10 10:47:43 -07:00
|
|
|
l.runningTop.loadedWriteLock()
|
|
|
|
defer l.runningTop.loadedWriteUnlock()
|
|
|
|
if l.runningTop.loaded {
|
2018-12-05 04:03:41 -07:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
onEntry := func(entry *logEntry) error {
|
|
|
|
if len(entry.Question) == 0 {
|
|
|
|
log.Printf("entry question is absent, skipping")
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
if entry.Time.After(now) {
|
|
|
|
log.Printf("t %v vs %v is in the future, ignoring", entry.Time, now)
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
q := new(dns.Msg)
|
|
|
|
if err := q.Unpack(entry.Question); err != nil {
|
|
|
|
log.Printf("failed to unpack dns message question: %s", err)
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
if len(q.Question) != 1 {
|
|
|
|
log.Printf("malformed dns message, has no questions, skipping")
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2019-02-10 10:47:43 -07:00
|
|
|
err := l.runningTop.addEntry(entry, q, now)
|
2018-12-05 04:03:41 -07:00
|
|
|
if err != nil {
|
|
|
|
log.Printf("Failed to add entry to running top: %s", err)
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2019-02-10 10:47:43 -07:00
|
|
|
l.queryLogLock.Lock()
|
|
|
|
l.queryLogCache = append(l.queryLogCache, entry)
|
|
|
|
if len(l.queryLogCache) > queryLogSize {
|
|
|
|
toremove := len(l.queryLogCache) - queryLogSize
|
|
|
|
l.queryLogCache = l.queryLogCache[toremove:]
|
2018-12-05 04:03:41 -07:00
|
|
|
}
|
2019-02-10 10:47:43 -07:00
|
|
|
l.queryLogLock.Unlock()
|
2018-12-05 04:03:41 -07:00
|
|
|
|
2019-02-10 10:47:43 -07:00
|
|
|
s.incrementCounters(entry)
|
2018-12-05 04:03:41 -07:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
needMore := func() bool { return true }
|
2019-02-10 10:47:43 -07:00
|
|
|
err := l.genericLoader(onEntry, needMore, queryLogTimeLimit)
|
2018-12-05 04:03:41 -07:00
|
|
|
if err != nil {
|
|
|
|
log.Printf("Failed to load entries from querylog: %s", err)
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2019-02-10 10:47:43 -07:00
|
|
|
l.runningTop.loaded = true
|
2018-12-05 04:03:41 -07:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2019-02-10 10:47:43 -07:00
|
|
|
// StatsTop represents top stat charts
|
|
|
|
type StatsTop struct {
|
|
|
|
Domains map[string]int // Domains - top requested domains
|
|
|
|
Blocked map[string]int // Blocked - top blocked domains
|
|
|
|
Clients map[string]int // Clients - top DNS clients
|
|
|
|
}
|
|
|
|
|
|
|
|
// getStatsTop returns the current top stats
|
|
|
|
func (d *dayTop) getStatsTop() *StatsTop {
|
|
|
|
s := &StatsTop{
|
|
|
|
Domains: map[string]int{},
|
|
|
|
Blocked: map[string]int{},
|
|
|
|
Clients: map[string]int{},
|
|
|
|
}
|
2018-12-05 04:03:41 -07:00
|
|
|
|
|
|
|
do := func(keys []interface{}, getter func(key string) (int, error), result map[string]int) {
|
|
|
|
for _, ikey := range keys {
|
|
|
|
key, ok := ikey.(string)
|
|
|
|
if !ok {
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
value, err := getter(key)
|
|
|
|
if err != nil {
|
|
|
|
log.Printf("Failed to get top domains value for %v: %s", key, err)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
result[key] += value
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-02-10 10:47:43 -07:00
|
|
|
d.hoursReadLock()
|
2018-12-05 04:03:41 -07:00
|
|
|
for hour := 0; hour < 24; hour++ {
|
2019-02-10 10:47:43 -07:00
|
|
|
d.hours[hour].RLock()
|
|
|
|
do(d.hours[hour].domains.Keys(), d.hours[hour].lockedGetDomains, s.Domains)
|
|
|
|
do(d.hours[hour].blocked.Keys(), d.hours[hour].lockedGetBlocked, s.Blocked)
|
|
|
|
do(d.hours[hour].clients.Keys(), d.hours[hour].lockedGetClients, s.Clients)
|
|
|
|
d.hours[hour].RUnlock()
|
2018-12-05 04:03:41 -07:00
|
|
|
}
|
2019-02-10 10:47:43 -07:00
|
|
|
d.hoursReadUnlock()
|
2018-12-05 04:03:41 -07:00
|
|
|
|
2019-02-10 10:47:43 -07:00
|
|
|
return s
|
2018-12-05 04:03:41 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
func (d *dayTop) hoursWriteLock() { tracelock(); d.hoursLock.Lock() }
|
|
|
|
func (d *dayTop) hoursWriteUnlock() { tracelock(); d.hoursLock.Unlock() }
|
|
|
|
func (d *dayTop) hoursReadLock() { tracelock(); d.hoursLock.RLock() }
|
|
|
|
func (d *dayTop) hoursReadUnlock() { tracelock(); d.hoursLock.RUnlock() }
|
|
|
|
func (d *dayTop) loadedWriteLock() { tracelock(); d.loadedLock.Lock() }
|
|
|
|
func (d *dayTop) loadedWriteUnlock() { tracelock(); d.loadedLock.Unlock() }
|
|
|
|
|
|
|
|
func (h *hourTop) Lock() { tracelock(); h.mutex.Lock() }
|
|
|
|
func (h *hourTop) RLock() { tracelock(); h.mutex.RLock() }
|
|
|
|
func (h *hourTop) RUnlock() { tracelock(); h.mutex.RUnlock() }
|
|
|
|
func (h *hourTop) Unlock() { tracelock(); h.mutex.Unlock() }
|
|
|
|
|
|
|
|
func tracelock() {
|
|
|
|
if false { // not commented out to make code checked during compilation
|
|
|
|
pc := make([]uintptr, 10) // at least 1 entry needed
|
|
|
|
runtime.Callers(2, pc)
|
|
|
|
f := path.Base(runtime.FuncForPC(pc[1]).Name())
|
|
|
|
lockf := path.Base(runtime.FuncForPC(pc[0]).Name())
|
|
|
|
fmt.Fprintf(os.Stderr, "%s(): %s\n", f, lockf)
|
|
|
|
}
|
|
|
|
}
|