1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
|
package log
import (
"io"
"log"
"net"
"sync"
"time"
"github.com/mpolden/zdns/sql"
)
const (
// ModeDiscard disables logging of DNS requests.
ModeDiscard = iota
// ModeAll logs all DNS requests.
ModeAll
// ModeHijacked only logs hijacked DNS requests.
ModeHijacked
)
// Logger wraps a standard log.Logger and an optional log database.
type Logger struct {
*log.Logger
mode int
queue chan Entry
db *sql.Client
wg sync.WaitGroup
now func() time.Time
}
// RecordOptions configures recording of DNS requests.
type RecordOptions struct {
Database string
Mode int
TTL time.Duration
}
// Entry represents a DNS request log entry.
type Entry struct {
Time time.Time
RemoteAddr net.IP
Hijacked bool
Qtype uint16
Question string
Answers []string
}
// New creates a new logger, writing log output to writer w prefixed with prefix. Persisted logging behaviour is
// controller by options.
func New(w io.Writer, prefix string, options RecordOptions) (*Logger, error) {
logger := &Logger{
Logger: log.New(w, prefix, 0),
queue: make(chan Entry, 100),
now: time.Now,
mode: options.Mode,
}
var err error
if options.Database != "" {
logger.db, err = sql.New(options.Database)
if err != nil {
return nil, err
}
}
logger.wg.Add(1)
go logger.readQueue(options.TTL)
return logger, nil
}
// Close consumes any outstanding log requests and closes the logger.
func (l *Logger) Close() error {
close(l.queue)
l.wg.Wait()
return nil
}
// Record records the given DNS request to the log database.
func (l *Logger) Record(remoteAddr net.IP, hijacked bool, qtype uint16, question string, answers ...string) {
if l.db == nil {
return
}
if l.mode == ModeDiscard {
return
}
if l.mode == ModeHijacked && !hijacked {
return
}
l.queue <- Entry{
Time: l.now(),
RemoteAddr: remoteAddr,
Hijacked: hijacked,
Qtype: qtype,
Question: question,
Answers: answers,
}
}
// Get returns the n most recent persisted log entries.
func (l *Logger) Get(n int) ([]Entry, error) {
logEntries, err := l.db.ReadLog(n)
if err != nil {
return nil, err
}
ids := make(map[int64]*Entry)
entries := make([]Entry, 0, len(logEntries))
for _, le := range logEntries {
entry, ok := ids[le.ID]
if !ok {
newEntry := Entry{
Time: time.Unix(le.Time, 0).UTC(),
RemoteAddr: le.RemoteAddr,
Hijacked: le.Hijacked,
Qtype: le.Qtype,
Question: le.Question,
}
entries = append(entries, newEntry)
entry = &entries[len(entries)-1]
ids[le.ID] = entry
}
if le.Answer != "" {
entry.Answers = append(entry.Answers, le.Answer)
}
}
return entries, nil
}
func (l *Logger) readQueue(ttl time.Duration) {
defer l.wg.Done()
for e := range l.queue {
if err := l.db.WriteLog(e.Time, e.RemoteAddr, e.Hijacked, e.Qtype, e.Question, e.Answers...); err != nil {
l.Printf("write failed: %+v: %s", e, err)
}
if ttl > 0 {
t := l.now().Add(-ttl)
if err := l.db.DeleteLogBefore(t); err != nil {
l.Printf("deleting log entries before %v failed: %s", t, err)
}
}
}
}
|