xref: /freebsd/contrib/unbound/cachedb/cachedb.c (revision 0957b409)
1 /*
2  * cachedb/cachedb.c - cache from a database external to the program module
3  *
4  * Copyright (c) 2016, NLnet Labs. All rights reserved.
5  *
6  * This software is open source.
7  *
8  * Redistribution and use in source and binary forms, with or without
9  * modification, are permitted provided that the following conditions
10  * are met:
11  *
12  * Redistributions of source code must retain the above copyright notice,
13  * this list of conditions and the following disclaimer.
14  *
15  * Redistributions in binary form must reproduce the above copyright notice,
16  * this list of conditions and the following disclaimer in the documentation
17  * and/or other materials provided with the distribution.
18  *
19  * Neither the name of the NLNET LABS nor the names of its contributors may
20  * be used to endorse or promote products derived from this software without
21  * specific prior written permission.
22  *
23  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
24  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
25  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
26  * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
27  * HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
28  * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED
29  * TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
30  * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
31  * LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
32  * NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
33  * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
34  */
35 
36 /**
37  * \file
38  *
39  * This file contains a module that uses an external database to cache
40  * dns responses.
41  */
42 
43 #include "config.h"
44 #ifdef USE_CACHEDB
45 #include "cachedb/cachedb.h"
46 #include "cachedb/redis.h"
47 #include "util/regional.h"
48 #include "util/net_help.h"
49 #include "util/config_file.h"
50 #include "util/data/msgreply.h"
51 #include "util/data/msgencode.h"
52 #include "services/cache/dns.h"
53 #include "validator/val_neg.h"
54 #include "validator/val_secalgo.h"
55 #include "iterator/iter_utils.h"
56 #include "sldns/parseutil.h"
57 #include "sldns/wire2str.h"
58 #include "sldns/sbuffer.h"
59 
60 /* header file for htobe64 */
61 #ifdef HAVE_ENDIAN_H
62 #  include <endian.h>
63 #endif
64 #ifdef HAVE_SYS_ENDIAN_H
65 #  include <sys/endian.h>
66 #endif
67 #ifdef HAVE_LIBKERN_OSBYTEORDER_H
68 /* In practice this is specific to MacOS X.  We assume it doesn't have
69 * htobe64/be64toh but has alternatives with a different name. */
70 #  include <libkern/OSByteOrder.h>
71 #  define htobe64(x) OSSwapHostToBigInt64(x)
72 #  define be64toh(x) OSSwapBigToHostInt64(x)
73 #endif
74 
75 /** the unit test testframe for cachedb, its module state contains
76  * a cache for a couple queries (in memory). */
77 struct testframe_moddata {
78 	/** lock for mutex */
79 	lock_basic_type lock;
80 	/** key for single stored data element, NULL if none */
81 	char* stored_key;
82 	/** data for single stored data element, NULL if none */
83 	uint8_t* stored_data;
84 	/** length of stored data */
85 	size_t stored_datalen;
86 };
87 
88 static int
89 testframe_init(struct module_env* env, struct cachedb_env* cachedb_env)
90 {
91 	struct testframe_moddata* d;
92 	(void)env;
93 	verbose(VERB_ALGO, "testframe_init");
94 	d = (struct testframe_moddata*)calloc(1,
95 		sizeof(struct testframe_moddata));
96 	cachedb_env->backend_data = (void*)d;
97 	if(!cachedb_env->backend_data) {
98 		log_err("out of memory");
99 		return 0;
100 	}
101 	lock_basic_init(&d->lock);
102 	lock_protect(&d->lock, d, sizeof(*d));
103 	return 1;
104 }
105 
106 static void
107 testframe_deinit(struct module_env* env, struct cachedb_env* cachedb_env)
108 {
109 	struct testframe_moddata* d = (struct testframe_moddata*)
110 		cachedb_env->backend_data;
111 	(void)env;
112 	verbose(VERB_ALGO, "testframe_deinit");
113 	if(!d)
114 		return;
115 	lock_basic_destroy(&d->lock);
116 	free(d->stored_key);
117 	free(d->stored_data);
118 	free(d);
119 }
120 
121 static int
122 testframe_lookup(struct module_env* env, struct cachedb_env* cachedb_env,
123 	char* key, struct sldns_buffer* result_buffer)
124 {
125 	struct testframe_moddata* d = (struct testframe_moddata*)
126 		cachedb_env->backend_data;
127 	(void)env;
128 	verbose(VERB_ALGO, "testframe_lookup of %s", key);
129 	lock_basic_lock(&d->lock);
130 	if(d->stored_key && strcmp(d->stored_key, key) == 0) {
131 		if(d->stored_datalen > sldns_buffer_capacity(result_buffer)) {
132 			lock_basic_unlock(&d->lock);
133 			return 0; /* too large */
134 		}
135 		verbose(VERB_ALGO, "testframe_lookup found %d bytes",
136 			(int)d->stored_datalen);
137 		sldns_buffer_clear(result_buffer);
138 		sldns_buffer_write(result_buffer, d->stored_data,
139 			d->stored_datalen);
140 		sldns_buffer_flip(result_buffer);
141 		lock_basic_unlock(&d->lock);
142 		return 1;
143 	}
144 	lock_basic_unlock(&d->lock);
145 	return 0;
146 }
147 
148 static void
149 testframe_store(struct module_env* env, struct cachedb_env* cachedb_env,
150 	char* key, uint8_t* data, size_t data_len)
151 {
152 	struct testframe_moddata* d = (struct testframe_moddata*)
153 		cachedb_env->backend_data;
154 	(void)env;
155 	lock_basic_lock(&d->lock);
156 	verbose(VERB_ALGO, "testframe_store %s (%d bytes)", key, (int)data_len);
157 
158 	/* free old data element (if any) */
159 	free(d->stored_key);
160 	d->stored_key = NULL;
161 	free(d->stored_data);
162 	d->stored_data = NULL;
163 	d->stored_datalen = 0;
164 
165 	d->stored_data = memdup(data, data_len);
166 	if(!d->stored_data) {
167 		lock_basic_unlock(&d->lock);
168 		log_err("out of memory");
169 		return;
170 	}
171 	d->stored_datalen = data_len;
172 	d->stored_key = strdup(key);
173 	if(!d->stored_key) {
174 		free(d->stored_data);
175 		d->stored_data = NULL;
176 		d->stored_datalen = 0;
177 		lock_basic_unlock(&d->lock);
178 		return;
179 	}
180 	lock_basic_unlock(&d->lock);
181 	/* (key,data) successfully stored */
182 }
183 
184 /** The testframe backend is for unit tests */
185 static struct cachedb_backend testframe_backend = { "testframe",
186 	testframe_init, testframe_deinit, testframe_lookup, testframe_store
187 };
188 
189 /** find a particular backend from possible backends */
190 static struct cachedb_backend*
191 cachedb_find_backend(const char* str)
192 {
193 #ifdef USE_REDIS
194 	if(strcmp(str, redis_backend.name) == 0)
195 		return &redis_backend;
196 #endif
197 	if(strcmp(str, testframe_backend.name) == 0)
198 		return &testframe_backend;
199 	/* TODO add more backends here */
200 	return NULL;
201 }
202 
203 /** apply configuration to cachedb module 'global' state */
204 static int
205 cachedb_apply_cfg(struct cachedb_env* cachedb_env, struct config_file* cfg)
206 {
207 	const char* backend_str = cfg->cachedb_backend;
208 
209 	/* If unspecified we use the in-memory test DB. */
210 	if(!backend_str)
211 		backend_str = "testframe";
212 	cachedb_env->backend = cachedb_find_backend(backend_str);
213 	if(!cachedb_env->backend) {
214 		log_err("cachedb: cannot find backend name '%s'", backend_str);
215 		return 0;
216 	}
217 
218 	/* TODO see if more configuration needs to be applied or not */
219 	return 1;
220 }
221 
222 int
223 cachedb_init(struct module_env* env, int id)
224 {
225 	struct cachedb_env* cachedb_env = (struct cachedb_env*)calloc(1,
226 		sizeof(struct cachedb_env));
227 	if(!cachedb_env) {
228 		log_err("malloc failure");
229 		return 0;
230 	}
231 	env->modinfo[id] = (void*)cachedb_env;
232 	if(!cachedb_apply_cfg(cachedb_env, env->cfg)) {
233 		log_err("cachedb: could not apply configuration settings.");
234 		return 0;
235 	}
236 	/* see if a backend is selected */
237 	if(!cachedb_env->backend || !cachedb_env->backend->name)
238 		return 1;
239 	if(!(*cachedb_env->backend->init)(env, cachedb_env)) {
240 		log_err("cachedb: could not init %s backend",
241 			cachedb_env->backend->name);
242 		return 0;
243 	}
244 	cachedb_env->enabled = 1;
245 	return 1;
246 }
247 
248 void
249 cachedb_deinit(struct module_env* env, int id)
250 {
251 	struct cachedb_env* cachedb_env;
252 	if(!env || !env->modinfo[id])
253 		return;
254 	cachedb_env = (struct cachedb_env*)env->modinfo[id];
255 	/* free contents */
256 	/* TODO */
257 	if(cachedb_env->enabled) {
258 		(*cachedb_env->backend->deinit)(env, cachedb_env);
259 	}
260 
261 	free(cachedb_env);
262 	env->modinfo[id] = NULL;
263 }
264 
265 /** new query for cachedb */
266 static int
267 cachedb_new(struct module_qstate* qstate, int id)
268 {
269 	struct cachedb_qstate* iq = (struct cachedb_qstate*)regional_alloc(
270 		qstate->region, sizeof(struct cachedb_qstate));
271 	qstate->minfo[id] = iq;
272 	if(!iq)
273 		return 0;
274 	memset(iq, 0, sizeof(*iq));
275 	/* initialise it */
276 	/* TODO */
277 
278 	return 1;
279 }
280 
281 /**
282  * Return an error
283  * @param qstate: our query state
284  * @param id: module id
285  * @param rcode: error code (DNS errcode).
286  * @return: 0 for use by caller, to make notation easy, like:
287  * 	return error_response(..).
288  */
289 static int
290 error_response(struct module_qstate* qstate, int id, int rcode)
291 {
292 	verbose(VERB_QUERY, "return error response %s",
293 		sldns_lookup_by_id(sldns_rcodes, rcode)?
294 		sldns_lookup_by_id(sldns_rcodes, rcode)->name:"??");
295 	qstate->return_rcode = rcode;
296 	qstate->return_msg = NULL;
297 	qstate->ext_state[id] = module_finished;
298 	return 0;
299 }
300 
301 /**
302  * Hash the query name, type, class and dbacess-secret into lookup buffer.
303  * @param qstate: query state with query info
304  * 	and env->cfg with secret.
305  * @param buf: returned buffer with hash to lookup
306  * @param len: length of the buffer.
307  */
308 static void
309 calc_hash(struct module_qstate* qstate, char* buf, size_t len)
310 {
311 	uint8_t clear[1024];
312 	size_t clen = 0;
313 	uint8_t hash[CACHEDB_HASHSIZE/8];
314 	const char* hex = "0123456789ABCDEF";
315 	const char* secret = qstate->env->cfg->cachedb_secret ?
316 		qstate->env->cfg->cachedb_secret : "default";
317 	size_t i;
318 
319 	/* copy the hash info into the clear buffer */
320 	if(clen + qstate->qinfo.qname_len < sizeof(clear)) {
321 		memmove(clear+clen, qstate->qinfo.qname,
322 			qstate->qinfo.qname_len);
323 		clen += qstate->qinfo.qname_len;
324 	}
325 	if(clen + 4 < sizeof(clear)) {
326 		uint16_t t = htons(qstate->qinfo.qtype);
327 		uint16_t c = htons(qstate->qinfo.qclass);
328 		memmove(clear+clen, &t, 2);
329 		memmove(clear+clen+2, &c, 2);
330 		clen += 4;
331 	}
332 	if(secret && secret[0] && clen + strlen(secret) < sizeof(clear)) {
333 		memmove(clear+clen, secret, strlen(secret));
334 		clen += strlen(secret);
335 	}
336 
337 	/* hash the buffer */
338 	secalgo_hash_sha256(clear, clen, hash);
339 	memset(clear, 0, clen);
340 
341 	/* hex encode output for portability (some online dbs need
342 	 * no nulls, no control characters, and so on) */
343 	log_assert(len >= sizeof(hash)*2 + 1);
344 	(void)len;
345 	for(i=0; i<sizeof(hash); i++) {
346 		buf[i*2] = hex[(hash[i]&0xf0)>>4];
347 		buf[i*2+1] = hex[hash[i]&0x0f];
348 	}
349 	buf[sizeof(hash)*2] = 0;
350 }
351 
352 /** convert data from return_msg into the data buffer */
353 static int
354 prep_data(struct module_qstate* qstate, struct sldns_buffer* buf)
355 {
356 	uint64_t timestamp, expiry;
357 	size_t oldlim;
358 	struct edns_data edns;
359 	memset(&edns, 0, sizeof(edns));
360 	edns.edns_present = 1;
361 	edns.bits = EDNS_DO;
362 	edns.ext_rcode = 0;
363 	edns.edns_version = EDNS_ADVERTISED_VERSION;
364 	edns.udp_size = EDNS_ADVERTISED_SIZE;
365 
366 	if(!qstate->return_msg || !qstate->return_msg->rep)
367 		return 0;
368 	/* We don't store the reply if its TTL is 0 unless serve-expired is
369 	 * enabled.  Such a reply won't be reusable and simply be a waste for
370 	 * the backend.  It's also compatible with the default behavior of
371 	 * dns_cache_store_msg(). */
372 	if(qstate->return_msg->rep->ttl == 0 &&
373 		!qstate->env->cfg->serve_expired)
374 		return 0;
375 	if(verbosity >= VERB_ALGO)
376 		log_dns_msg("cachedb encoding", &qstate->return_msg->qinfo,
377 	                qstate->return_msg->rep);
378 	if(!reply_info_answer_encode(&qstate->return_msg->qinfo,
379 		qstate->return_msg->rep, 0, qstate->query_flags,
380 		buf, 0, 1, qstate->env->scratch, 65535, &edns, 1, 0))
381 		return 0;
382 
383 	/* TTLs in the return_msg are relative to time(0) so we have to
384 	 * store that, we also store the smallest ttl in the packet+time(0)
385 	 * as the packet expiry time */
386 	/* qstate->return_msg->rep->ttl contains that relative shortest ttl */
387 	timestamp = (uint64_t)*qstate->env->now;
388 	expiry = timestamp + (uint64_t)qstate->return_msg->rep->ttl;
389 	timestamp = htobe64(timestamp);
390 	expiry = htobe64(expiry);
391 	oldlim = sldns_buffer_limit(buf);
392 	if(oldlim + sizeof(timestamp)+sizeof(expiry) >=
393 		sldns_buffer_capacity(buf))
394 		return 0; /* doesn't fit. */
395 	sldns_buffer_set_limit(buf, oldlim + sizeof(timestamp)+sizeof(expiry));
396 	sldns_buffer_write_at(buf, oldlim, &timestamp, sizeof(timestamp));
397 	sldns_buffer_write_at(buf, oldlim+sizeof(timestamp), &expiry,
398 		sizeof(expiry));
399 
400 	return 1;
401 }
402 
403 /** check expiry, return true if matches OK */
404 static int
405 good_expiry_and_qinfo(struct module_qstate* qstate, struct sldns_buffer* buf)
406 {
407 	uint64_t expiry;
408 	/* the expiry time is the last bytes of the buffer */
409 	if(sldns_buffer_limit(buf) < sizeof(expiry))
410 		return 0;
411 	sldns_buffer_read_at(buf, sldns_buffer_limit(buf)-sizeof(expiry),
412 		&expiry, sizeof(expiry));
413 	expiry = be64toh(expiry);
414 
415 	if((time_t)expiry < *qstate->env->now &&
416 		!qstate->env->cfg->serve_expired)
417 		return 0;
418 
419 	return 1;
420 }
421 
422 /* Adjust the TTL of the given RRset by 'subtract'.  If 'subtract' is
423  * negative, set the TTL to 0. */
424 static void
425 packed_rrset_ttl_subtract(struct packed_rrset_data* data, time_t subtract)
426 {
427         size_t i;
428         size_t total = data->count + data->rrsig_count;
429 	if(subtract >= 0 && data->ttl > subtract)
430 		data->ttl -= subtract;
431 	else	data->ttl = 0;
432         for(i=0; i<total; i++) {
433 		if(subtract >= 0 && data->rr_ttl[i] > subtract)
434                 	data->rr_ttl[i] -= subtract;
435                 else	data->rr_ttl[i] = 0;
436 	}
437 }
438 
439 /* Adjust the TTL of a DNS message and its RRs by 'adjust'.  If 'adjust' is
440  * negative, set the TTLs to 0. */
441 static void
442 adjust_msg_ttl(struct dns_msg* msg, time_t adjust)
443 {
444 	size_t i;
445 	if(adjust >= 0 && msg->rep->ttl > adjust)
446 		msg->rep->ttl -= adjust;
447 	else	msg->rep->ttl = 0;
448 	msg->rep->prefetch_ttl = PREFETCH_TTL_CALC(msg->rep->ttl);
449 	msg->rep->serve_expired_ttl = msg->rep->ttl + SERVE_EXPIRED_TTL;
450 
451 	for(i=0; i<msg->rep->rrset_count; i++) {
452 		packed_rrset_ttl_subtract((struct packed_rrset_data*)msg->
453 			rep->rrsets[i]->entry.data, adjust);
454 	}
455 }
456 
457 /** convert dns message in buffer to return_msg */
458 static int
459 parse_data(struct module_qstate* qstate, struct sldns_buffer* buf)
460 {
461 	struct msg_parse* prs;
462 	struct edns_data edns;
463 	uint64_t timestamp, expiry;
464 	time_t adjust;
465 	size_t lim = sldns_buffer_limit(buf);
466 	if(lim < LDNS_HEADER_SIZE+sizeof(timestamp)+sizeof(expiry))
467 		return 0; /* too short */
468 
469 	/* remove timestamp and expiry from end */
470 	sldns_buffer_read_at(buf, lim-sizeof(expiry), &expiry, sizeof(expiry));
471 	sldns_buffer_read_at(buf, lim-sizeof(expiry)-sizeof(timestamp),
472 		&timestamp, sizeof(timestamp));
473 	expiry = be64toh(expiry);
474 	timestamp = be64toh(timestamp);
475 
476 	/* parse DNS packet */
477 	regional_free_all(qstate->env->scratch);
478 	prs = (struct msg_parse*)regional_alloc(qstate->env->scratch,
479 		sizeof(struct msg_parse));
480 	if(!prs)
481 		return 0; /* out of memory */
482 	memset(prs, 0, sizeof(*prs));
483 	memset(&edns, 0, sizeof(edns));
484 	sldns_buffer_set_limit(buf, lim - sizeof(expiry)-sizeof(timestamp));
485 	if(parse_packet(buf, prs, qstate->env->scratch) != LDNS_RCODE_NOERROR) {
486 		sldns_buffer_set_limit(buf, lim);
487 		return 0;
488 	}
489 	if(parse_extract_edns(prs, &edns, qstate->env->scratch) !=
490 		LDNS_RCODE_NOERROR) {
491 		sldns_buffer_set_limit(buf, lim);
492 		return 0;
493 	}
494 
495 	qstate->return_msg = dns_alloc_msg(buf, prs, qstate->region);
496 	sldns_buffer_set_limit(buf, lim);
497 	if(!qstate->return_msg)
498 		return 0;
499 
500 	qstate->return_rcode = LDNS_RCODE_NOERROR;
501 
502 	/* see how much of the TTL expired, and remove it */
503 	if(*qstate->env->now <= (time_t)timestamp) {
504 		verbose(VERB_ALGO, "cachedb msg adjust by zero");
505 		return 1; /* message from the future (clock skew?) */
506 	}
507 	adjust = *qstate->env->now - (time_t)timestamp;
508 	if(qstate->return_msg->rep->ttl < adjust) {
509 		verbose(VERB_ALGO, "cachedb msg expired");
510 		/* If serve-expired is enabled, we still use an expired message
511 		 * setting the TTL to 0. */
512 		if(qstate->env->cfg->serve_expired)
513 			adjust = -1;
514 		else
515 			return 0; /* message expired */
516 	}
517 	verbose(VERB_ALGO, "cachedb msg adjusted down by %d", (int)adjust);
518 	adjust_msg_ttl(qstate->return_msg, adjust);
519 
520 	/* Similar to the unbound worker, if serve-expired is enabled and
521 	 * the msg would be considered to be expired, mark the state so a
522 	 * refetch will be scheduled.  The comparison between 'expiry' and
523 	 * 'now' should be redundant given how these values were calculated,
524 	 * but we check it just in case as does good_expiry_and_qinfo(). */
525 	if(qstate->env->cfg->serve_expired &&
526 		(adjust == -1 || (time_t)expiry < *qstate->env->now)) {
527 		qstate->need_refetch = 1;
528 	}
529 
530 	return 1;
531 }
532 
533 /**
534  * Lookup the qstate.qinfo in extcache, store in qstate.return_msg.
535  * return true if lookup was successful.
536  */
537 static int
538 cachedb_extcache_lookup(struct module_qstate* qstate, struct cachedb_env* ie)
539 {
540 	char key[(CACHEDB_HASHSIZE/8)*2+1];
541 	calc_hash(qstate, key, sizeof(key));
542 
543 	/* call backend to fetch data for key into scratch buffer */
544 	if( !(*ie->backend->lookup)(qstate->env, ie, key,
545 		qstate->env->scratch_buffer)) {
546 		return 0;
547 	}
548 
549 	/* check expiry date and check if query-data matches */
550 	if( !good_expiry_and_qinfo(qstate, qstate->env->scratch_buffer) ) {
551 		return 0;
552 	}
553 
554 	/* parse dns message into return_msg */
555 	if( !parse_data(qstate, qstate->env->scratch_buffer) ) {
556 		return 0;
557 	}
558 	return 1;
559 }
560 
561 /**
562  * Store the qstate.return_msg in extcache for key qstate.info
563  */
564 static void
565 cachedb_extcache_store(struct module_qstate* qstate, struct cachedb_env* ie)
566 {
567 	char key[(CACHEDB_HASHSIZE/8)*2+1];
568 	calc_hash(qstate, key, sizeof(key));
569 
570 	/* prepare data in scratch buffer */
571 	if(!prep_data(qstate, qstate->env->scratch_buffer))
572 		return;
573 
574 	/* call backend */
575 	(*ie->backend->store)(qstate->env, ie, key,
576 		sldns_buffer_begin(qstate->env->scratch_buffer),
577 		sldns_buffer_limit(qstate->env->scratch_buffer));
578 }
579 
580 /**
581  * See if unbound's internal cache can answer the query
582  */
583 static int
584 cachedb_intcache_lookup(struct module_qstate* qstate)
585 {
586 	struct dns_msg* msg;
587 	msg = dns_cache_lookup(qstate->env, qstate->qinfo.qname,
588 		qstate->qinfo.qname_len, qstate->qinfo.qtype,
589 		qstate->qinfo.qclass, qstate->query_flags,
590 		qstate->region, qstate->env->scratch,
591 		1 /* no partial messages with only a CNAME */
592 		);
593 	if(!msg && qstate->env->neg_cache &&
594 		iter_qname_indicates_dnssec(qstate->env, &qstate->qinfo)) {
595 		/* lookup in negative cache; may result in
596 		 * NOERROR/NODATA or NXDOMAIN answers that need validation */
597 		msg = val_neg_getmsg(qstate->env->neg_cache, &qstate->qinfo,
598 			qstate->region, qstate->env->rrset_cache,
599 			qstate->env->scratch_buffer,
600 			*qstate->env->now, 1/*add SOA*/, NULL,
601 			qstate->env->cfg);
602 	}
603 	if(!msg)
604 		return 0;
605 	/* this is the returned msg */
606 	qstate->return_rcode = LDNS_RCODE_NOERROR;
607 	qstate->return_msg = msg;
608 	return 1;
609 }
610 
611 /**
612  * Store query into the internal cache of unbound.
613  */
614 static void
615 cachedb_intcache_store(struct module_qstate* qstate)
616 {
617 	uint32_t store_flags = qstate->query_flags;
618 
619 	if(qstate->env->cfg->serve_expired)
620 		store_flags |= DNSCACHE_STORE_ZEROTTL;
621 	if(!qstate->return_msg)
622 		return;
623 	(void)dns_cache_store(qstate->env, &qstate->qinfo,
624 		qstate->return_msg->rep, 0, qstate->prefetch_leeway, 0,
625 		qstate->region, store_flags);
626 }
627 
628 /**
629  * Handle a cachedb module event with a query
630  * @param qstate: query state (from the mesh), passed between modules.
631  * 	contains qstate->env module environment with global caches and so on.
632  * @param iq: query state specific for this module.  per-query.
633  * @param ie: environment specific for this module.  global.
634  * @param id: module id.
635  */
636 static void
637 cachedb_handle_query(struct module_qstate* qstate,
638 	struct cachedb_qstate* ATTR_UNUSED(iq),
639 	struct cachedb_env* ie, int id)
640 {
641 	/* check if we are enabled, and skip if so */
642 	if(!ie->enabled) {
643 		/* pass request to next module */
644 		qstate->ext_state[id] = module_wait_module;
645 		return;
646 	}
647 
648 	if(qstate->blacklist || qstate->no_cache_lookup) {
649 		/* cache is blacklisted or we are instructed from edns to not look */
650 		/* pass request to next module */
651 		qstate->ext_state[id] = module_wait_module;
652 		return;
653 	}
654 
655 	/* lookup inside unbound's internal cache */
656 	if(cachedb_intcache_lookup(qstate)) {
657 		if(verbosity >= VERB_ALGO) {
658 			if(qstate->return_msg->rep)
659 				log_dns_msg("cachedb internal cache lookup",
660 					&qstate->return_msg->qinfo,
661 					qstate->return_msg->rep);
662 			else log_info("cachedb internal cache lookup: rcode %s",
663 				sldns_lookup_by_id(sldns_rcodes, qstate->return_rcode)?
664 				sldns_lookup_by_id(sldns_rcodes, qstate->return_rcode)->name:"??");
665 		}
666 		/* we are done with the query */
667 		qstate->ext_state[id] = module_finished;
668 		return;
669 	}
670 
671 	/* ask backend cache to see if we have data */
672 	if(cachedb_extcache_lookup(qstate, ie)) {
673 		if(verbosity >= VERB_ALGO)
674 			log_dns_msg(ie->backend->name,
675 				&qstate->return_msg->qinfo,
676 				qstate->return_msg->rep);
677 		/* store this result in internal cache */
678 		cachedb_intcache_store(qstate);
679 		/* we are done with the query */
680 		qstate->ext_state[id] = module_finished;
681 		return;
682 	}
683 
684 	/* no cache fetches */
685 	/* pass request to next module */
686 	qstate->ext_state[id] = module_wait_module;
687 }
688 
689 /**
690  * Handle a cachedb module event with a response from the iterator.
691  * @param qstate: query state (from the mesh), passed between modules.
692  * 	contains qstate->env module environment with global caches and so on.
693  * @param iq: query state specific for this module.  per-query.
694  * @param ie: environment specific for this module.  global.
695  * @param id: module id.
696  */
697 static void
698 cachedb_handle_response(struct module_qstate* qstate,
699 	struct cachedb_qstate* ATTR_UNUSED(iq), struct cachedb_env* ie, int id)
700 {
701 	/* check if we are not enabled or instructed to not cache, and skip */
702 	if(!ie->enabled || qstate->no_cache_store) {
703 		/* we are done with the query */
704 		qstate->ext_state[id] = module_finished;
705 		return;
706 	}
707 
708 	/* store the item into the backend cache */
709 	cachedb_extcache_store(qstate, ie);
710 
711 	/* we are done with the query */
712 	qstate->ext_state[id] = module_finished;
713 }
714 
715 void
716 cachedb_operate(struct module_qstate* qstate, enum module_ev event, int id,
717 	struct outbound_entry* outbound)
718 {
719 	struct cachedb_env* ie = (struct cachedb_env*)qstate->env->modinfo[id];
720 	struct cachedb_qstate* iq = (struct cachedb_qstate*)qstate->minfo[id];
721 	verbose(VERB_QUERY, "cachedb[module %d] operate: extstate:%s event:%s",
722 		id, strextstate(qstate->ext_state[id]), strmodulevent(event));
723 	if(iq) log_query_info(VERB_QUERY, "cachedb operate: query",
724 		&qstate->qinfo);
725 
726 	/* perform cachedb state machine */
727 	if((event == module_event_new || event == module_event_pass) &&
728 		iq == NULL) {
729 		if(!cachedb_new(qstate, id)) {
730 			(void)error_response(qstate, id, LDNS_RCODE_SERVFAIL);
731 			return;
732 		}
733 		iq = (struct cachedb_qstate*)qstate->minfo[id];
734 	}
735 	if(iq && (event == module_event_pass || event == module_event_new)) {
736 		cachedb_handle_query(qstate, iq, ie, id);
737 		return;
738 	}
739 	if(iq && (event == module_event_moddone)) {
740 		cachedb_handle_response(qstate, iq, ie, id);
741 		return;
742 	}
743 	if(iq && outbound) {
744 		/* cachedb does not need to process responses at this time
745 		 * ignore it.
746 		cachedb_process_response(qstate, iq, ie, id, outbound, event);
747 		*/
748 		return;
749 	}
750 	if(event == module_event_error) {
751 		verbose(VERB_ALGO, "got called with event error, giving up");
752 		(void)error_response(qstate, id, LDNS_RCODE_SERVFAIL);
753 		return;
754 	}
755 	if(!iq && (event == module_event_moddone)) {
756 		/* during priming, module done but we never started */
757 		qstate->ext_state[id] = module_finished;
758 		return;
759 	}
760 
761 	log_err("bad event for cachedb");
762 	(void)error_response(qstate, id, LDNS_RCODE_SERVFAIL);
763 }
764 
765 void
766 cachedb_inform_super(struct module_qstate* ATTR_UNUSED(qstate),
767 	int ATTR_UNUSED(id), struct module_qstate* ATTR_UNUSED(super))
768 {
769 	/* cachedb does not use subordinate requests at this time */
770 	verbose(VERB_ALGO, "cachedb inform_super was called");
771 }
772 
773 void
774 cachedb_clear(struct module_qstate* qstate, int id)
775 {
776 	struct cachedb_qstate* iq;
777 	if(!qstate)
778 		return;
779 	iq = (struct cachedb_qstate*)qstate->minfo[id];
780 	if(iq) {
781 		/* free contents of iq */
782 		/* TODO */
783 	}
784 	qstate->minfo[id] = NULL;
785 }
786 
787 size_t
788 cachedb_get_mem(struct module_env* env, int id)
789 {
790 	struct cachedb_env* ie = (struct cachedb_env*)env->modinfo[id];
791 	if(!ie)
792 		return 0;
793 	return sizeof(*ie); /* TODO - more mem */
794 }
795 
796 /**
797  * The cachedb function block
798  */
799 static struct module_func_block cachedb_block = {
800 	"cachedb",
801 	&cachedb_init, &cachedb_deinit, &cachedb_operate,
802 	&cachedb_inform_super, &cachedb_clear, &cachedb_get_mem
803 };
804 
805 struct module_func_block*
806 cachedb_get_funcblock(void)
807 {
808 	return &cachedb_block;
809 }
810 #endif /* USE_CACHEDB */
811