-
-
Notifications
You must be signed in to change notification settings - Fork 11
/
ecs.go
79 lines (69 loc) · 1.81 KB
/
ecs.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
// Copyright © by Jeff Foley 2021-2024. All rights reserved.
// Use of this source code is governed by Apache 2 LICENSE that can be found in the LICENSE file.
// SPDX-License-Identifier: Apache-2.0
package resolve
import (
"sync"
"time"
"github.com/miekg/dns"
)
// ClientSubnetCheck ensures that all the resolvers in the pool respond to the query
// and do not send the EDNS client subnet information.
func (r *Resolvers) ClientSubnetCheck() {
all := r.pool.AllResolvers()
alen := len(all)
ch := make(chan *dns.Msg, alen)
var msglock sync.Mutex
msgsToRes := make(map[string]*resolver)
go func() {
var count int
for _, res := range all {
msg := QueryMsg("o-o.myaddr.l.google.com", dns.TypeTXT)
key := xchgKey(msg.Id, msg.Question[0].Name)
msglock.Lock()
msgsToRes[key] = res
msglock.Unlock()
res.writeReq(&request{
Res: res,
Msg: msg,
Result: ch,
})
count++
if count == 250 {
count = 0
time.Sleep(100 * time.Millisecond)
}
}
}()
for i := 0; i < alen; i++ {
resp := <-ch
// pull the resolver associated with this message
key := xchgKey(resp.Id, resp.Question[0].Name)
msglock.Lock()
res, found := msgsToRes[key]
if !found {
msglock.Unlock()
continue
}
delete(msgsToRes, key)
msglock.Unlock()
// check if the resolver responded, but did not return a successful response
if resp.Rcode != dns.RcodeSuccess || (!resp.Authoritative && !resp.RecursionAvailable) {
if res != nil {
res.stop()
}
continue
}
failed := true
// check if the response included the expected record
if ans := ExtractAnswers(resp); len(ans) > 0 {
if records := AnswersByType(ans, dns.TypeTXT); len(records) > 0 {
failed = false
}
}
// discontinue usage of the resolver when the check fails
if res != nil && failed {
res.stop()
}
}
}