1 /* dnsmasq is Copyright (c) 2000-2018 Simon Kelley
3 This program is free software; you can redistribute it and/or modify
4 it under the terms of the GNU General Public License as published by
5 the Free Software Foundation; version 2 dated June, 1991, or
6 (at your option) version 3 dated 29 June, 2007.
8 This program is distributed in the hope that it will be useful,
9 but WITHOUT ANY WARRANTY; without even the implied warranty of
10 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
11 GNU General Public License for more details.
13 You should have received a copy of the GNU General Public License
14 along with this program. If not, see <http://www.gnu.org/licenses/>.
17 #define VERSION "2.79"
19 #define FTABSIZ 150 /* max number of outstanding requests (default) */
20 #define MAX_PROCS 20 /* max no children for TCP requests */
21 #define CHILD_LIFETIME 150 /* secs 'till terminated (RFC1035 suggests > 120s) */
22 #define TCP_MAX_QUERIES 100 /* Maximum number of queries per incoming TCP connection */
23 #define TCP_BACKLOG 32 /* kernel backlog limit for TCP connections */
24 #define EDNS_PKTSZ 4096 /* default max EDNS.0 UDP packet from RFC5625 */
25 #define SAFE_PKTSZ 1280 /* "go anywhere" UDP packet size */
26 #define KEYBLOCK_LEN 40 /* choose to minimise fragmentation when storing DNSSEC keys */
27 #define DNSSEC_WORK 50 /* Max number of queries to validate one question */
28 #define TIMEOUT 10 /* drop UDP queries after TIMEOUT seconds */
29 #define FORWARD_TEST 50 /* try all servers every 50 queries */
30 #define FORWARD_TIME 20 /* or 20 seconds */
31 #define UDP_TEST_TIME 60 /* How often to reset our idea of max packet size. */
32 #define SERVERS_LOGGED 30 /* Only log this many servers when logging state */
33 #define LOCALS_LOGGED 8 /* Only log this many local addresses when logging state */
34 #define RANDOM_SOCKS 64 /* max simultaneous random ports */
35 #define LEASE_RETRY 60 /* on error, retry writing leasefile after LEASE_RETRY seconds */
36 #define CACHESIZ 150 /* default cache size */
37 #define TTL_FLOOR_LIMIT 3600 /* don't allow --min-cache-ttl to raise TTL above this under any circumstances */
38 #define MAXLEASES 1000 /* maximum number of DHCP leases */
39 #define PING_WAIT 3 /* wait for ping address-in-use test */
40 #define PING_CACHE_TIME 30 /* Ping test assumed to be valid this long. */
41 #define DECLINE_BACKOFF 600 /* disable DECLINEd static addresses for this long */
42 #define DHCP_PACKET_MAX 16384 /* hard limit on DHCP packet size */
43 #define SMALLDNAME 50 /* most domain names are smaller than this */
44 #define CNAME_CHAIN 10 /* chains longer than this atr dropped for loop protection */
45 #define HOSTSFILE "/etc/hosts"
46 #define ETHERSFILE "/etc/ethers"
47 #define DEFLEASE 3600 /* default lease time, 1 hour */
48 #define CHUSER "nobody"
50 #define TFTP_MAX_CONNECTIONS 50 /* max simultaneous connections */
51 #define LOG_MAX 5 /* log-queue length */
52 #define RANDFILE "/dev/urandom"
53 #define DNSMASQ_SERVICE "uk.org.thekelleys.dnsmasq" /* Default - may be overridden by config */
54 #define DNSMASQ_PATH "/uk/org/thekelleys/dnsmasq"
55 #define AUTH_TTL 600 /* default TTL for auth DNS */
56 #define SOA_REFRESH 1200 /* SOA refresh default */
57 #define SOA_RETRY 180 /* SOA retry default */
58 #define SOA_EXPIRY 1209600 /* SOA expiry default */
59 #define LOOP_TEST_DOMAIN "test" /* domain for loop testing, "test" is reserved by RFC 2606 and won't therefore clash */
60 #define LOOP_TEST_TYPE T_TXT
62 /* compile-time options: uncomment below to enable or do eg.
63 make COPTS=-DHAVE_BROKEN_RTC
66 define this on embedded systems which don't have an RTC
67 which keeps time over reboots. Causes dnsmasq to use uptime
68 for timing, and keep lease lengths rather than expiry times
69 in its leases file. This also make dnsmasq "flash disk friendly".
70 Normally, dnsmasq tries very hard to keep the on-disk leases file
71 up-to-date: rewriting it after every renewal. When HAVE_BROKEN_RTC
72 is in effect, the lease file is only written when a new lease is
73 created, or an old one destroyed. (Because those are the only times
74 it changes.) This vastly reduces the number of file writes, and makes
75 it viable to keep the lease file on a flash filesystem.
76 NOTE: when enabling or disabling this, be sure to delete any old
77 leases file, otherwise dnsmasq may get very confused.
80 define this to get dnsmasq's built-in TFTP server.
83 define this to get dnsmasq's DHCPv4 server.
86 define this to get dnsmasq's DHCPv6 server. (implies HAVE_DHCP).
89 define this to get the ability to call scripts on lease-change.
92 define this to get the ability to call Lua script on lease-change. (implies HAVE_SCRIPT)
95 define this if you want to link against libdbus, and have dnsmasq
96 support some methods to allow (re)configuration of the upstream DNS
100 define this if you want international domain name 2003 support.
103 define this if you want international domain name 2008 support.
106 define this to include code which propagates conntrack marks from
107 incoming DNS queries to the corresponding upstream queries. This adds
108 a build-dependency on libnetfilter_conntrack, but the resulting binary will
109 still run happily on a kernel without conntrack support.
112 define this to include the ability to selectively add resolved ip addresses
116 define this to include the facility to act as an authoritative DNS
117 server for one or more zones.
120 include DNSSEC validator.
123 include functionality to probe for and remove DNS forwarding loops.
126 use the Linux inotify facility to efficiently re-read configuration files.
129 Don't report *.bind CHAOS info to clients, forward such requests upstream instead.
138 these are available to explicitly disable compile time options which would
139 otherwise be enabled automatically (HAVE_IPV6, >2Gb file sizes) or
140 which are enabled by default in the distributed source tree. Building dnsmasq
141 with something like "make COPTS=-DNO_SCRIPT" will do the trick.
143 Don't use and link against libgmp, Useful if nettle is built with --enable-mini-gmp.
148 the default locations of these files are determined below, but may be overridden
149 in a build command line using COPTS.
153 /* Defining this builds a binary which handles time differently and works better on a system without a
154 stable RTC (it uses uptime, not epoch time) and writes the DHCP leases file less often to avoid flash wear.
157 /* #define HAVE_BROKEN_RTC */
159 /* The default set of options to build. Built with these options, dnsmasq
160 has no library dependencies other than libc */
170 /* Build options which require external libraries.
172 Defining HAVE_<opt>_STATIC as _well_ as HAVE_<opt> will link the library statically.
174 You can use "make COPTS=-DHAVE_<opt>" instead of editing these.
177 /* #define HAVE_LUASCRIPT */
179 /* #define HAVE_IDN */
180 /* #define HAVE_LIBIDN2 */
181 /* #define HAVE_CONNTRACK */
182 /* #define HAVE_DNSSEC */
185 /* Default locations for important system files. */
188 # if defined(__FreeBSD__) || defined (__OpenBSD__) || defined(__DragonFly__) || defined(__NetBSD__)
189 # define LEASEFILE "/var/db/dnsmasq.leases"
190 # elif defined(__sun__) || defined (__sun)
191 # define LEASEFILE "/var/cache/dnsmasq.leases"
192 # elif defined(__ANDROID__)
193 # define LEASEFILE "/data/misc/dhcp/dnsmasq.leases"
195 # define LEASEFILE "/var/lib/misc/dnsmasq.leases"
200 # if defined(__FreeBSD__)
201 # define CONFFILE "/usr/local/etc/dnsmasq.conf"
203 # define CONFFILE "/etc/dnsmasq.conf"
208 # if defined(__uClinux__)
209 # define RESOLVFILE "/etc/config/resolv.conf"
211 # define RESOLVFILE "/etc/resolv.conf"
216 # if defined(__ANDROID__)
217 # define RUNFILE "/data/dnsmasq.pid"
219 # define RUNFILE "/var/run/dnsmasq.pid"
223 /* platform dependent options: these are determined automatically below
228 define exactly one of these to alter interaction with kernel networking.
231 defined when GNU-style getopt_long available.
234 defined if struct sockaddr has sa_len field (*BSD)
237 /* Must precede __linux__ since uClinux defines __linux__ too. */
238 #if defined(__uClinux__)
239 #define HAVE_LINUX_NETWORK
240 #define HAVE_GETOPT_LONG
241 #undef HAVE_SOCKADDR_SA_LEN
242 /* Never use fork() on uClinux. Note that this is subtly different from the
243 --keep-in-foreground option, since it also suppresses forking new
244 processes for TCP connections and disables the call-a-script on leasechange
245 system. It's intended for use on MMU-less kernels. */
248 #elif defined(__UCLIBC__)
249 #define HAVE_LINUX_NETWORK
250 #if defined(__UCLIBC_HAS_GNU_GETOPT__) || \
251 ((__UCLIBC_MAJOR__==0) && (__UCLIBC_MINOR__==9) && (__UCLIBC_SUBLEVEL__<21))
252 # define HAVE_GETOPT_LONG
254 #undef HAVE_SOCKADDR_SA_LEN
255 #if !defined(__ARCH_HAS_MMU__) && !defined(__UCLIBC_HAS_MMU__)
258 #if defined(__UCLIBC_HAS_IPV6__)
260 # define IPV6_V6ONLY 26
264 /* This is for glibc 2.x */
265 #elif defined(__linux__)
266 #define HAVE_LINUX_NETWORK
267 #define HAVE_GETOPT_LONG
268 #undef HAVE_SOCKADDR_SA_LEN
270 #elif defined(__FreeBSD__) || \
271 defined(__OpenBSD__) || \
272 defined(__DragonFly__) || \
273 defined(__FreeBSD_kernel__)
274 #define HAVE_BSD_NETWORK
275 /* Later versions of FreeBSD have getopt_long() */
276 #if defined(optional_argument) && defined(required_argument)
277 # define HAVE_GETOPT_LONG
279 #define HAVE_SOCKADDR_SA_LEN
281 #elif defined(__APPLE__)
282 #define HAVE_BSD_NETWORK
283 #define HAVE_GETOPT_LONG
284 #define HAVE_SOCKADDR_SA_LEN
285 /* Define before sys/socket.h is included so we get socklen_t */
286 #define _BSD_SOCKLEN_T_
287 /* Select the RFC_3542 version of the IPv6 socket API.
288 Define before netinet6/in6.h is included. */
289 #define __APPLE_USE_RFC_3542
292 #elif defined(__NetBSD__)
293 #define HAVE_BSD_NETWORK
294 #define HAVE_GETOPT_LONG
295 #define HAVE_SOCKADDR_SA_LEN
297 #elif defined(__sun) || defined(__sun__)
298 #define HAVE_SOLARIS_NETWORK
299 #define HAVE_GETOPT_LONG
300 #undef HAVE_SOCKADDR_SA_LEN
301 #define ETHER_ADDR_LEN 6
305 /* Decide if we're going to support IPv6 */
306 /* We assume that systems which don't have IPv6
307 headers don't have ntop and pton either */
309 #if defined(INET6_ADDRSTRLEN) && defined(IPV6_V6ONLY)
311 # define ADDRSTRLEN INET6_ADDRSTRLEN
313 # if !defined(INET_ADDRSTRLEN)
314 # define INET_ADDRSTRLEN 16 /* 4*3 + 3 dots + NULL */
317 # define ADDRSTRLEN INET_ADDRSTRLEN
321 /* rules to implement compile-time option dependencies and
337 #if defined(NO_DHCP6) || !defined(HAVE_IPV6)
341 /* DHCP6 needs DHCP too */
346 #if defined(NO_SCRIPT) || defined(NO_FORK)
348 #undef HAVE_LUASCRIPT
351 /* Must HAVE_SCRIPT to HAVE_LUASCRIPT */
352 #ifdef HAVE_LUASCRIPT
360 #if defined(NO_IPSET)
368 #if defined (HAVE_LINUX_NETWORK) && !defined(NO_INOTIFY)
372 /* Define a string indicating which options are in use.
373 DNSMASQ_COMPILE_OPTS is only defined in dnsmasq.c */
375 #ifdef DNSMASQ_COMPILE_OPTS
377 static char *compile_opts =
382 #ifndef HAVE_GETOPT_LONG
386 #ifdef HAVE_BROKEN_RTC
400 #if defined(HAVE_LIBIDN2)
403 #if !defined(HAVE_IDN)
412 #if defined(HAVE_DHCP)
413 # if !defined (HAVE_DHCP6)
418 #if !defined(HAVE_SCRIPT)
421 # if !defined(HAVE_LUASCRIPT)
430 #ifndef HAVE_CONNTRACK