1package eu.siacs.conversations.utils;
2
3import android.content.ContentValues;
4import android.database.Cursor;
5import android.support.annotation.NonNull;
6import android.util.Log;
7
8import java.io.IOException;
9import java.lang.reflect.Field;
10import java.net.Inet4Address;
11import java.net.InetAddress;
12import java.net.UnknownHostException;
13import java.util.ArrayList;
14import java.util.Collections;
15import java.util.List;
16
17import de.measite.minidns.AbstractDNSClient;
18import de.measite.minidns.DNSClient;
19import de.measite.minidns.DNSName;
20import de.measite.minidns.Question;
21import de.measite.minidns.Record;
22import de.measite.minidns.dnssec.DNSSECResultNotAuthenticException;
23import de.measite.minidns.dnsserverlookup.AndroidUsingExec;
24import de.measite.minidns.hla.DnssecResolverApi;
25import de.measite.minidns.hla.ResolverApi;
26import de.measite.minidns.hla.ResolverResult;
27import de.measite.minidns.iterative.ReliableDNSClient;
28import de.measite.minidns.record.A;
29import de.measite.minidns.record.AAAA;
30import de.measite.minidns.record.CNAME;
31import de.measite.minidns.record.Data;
32import de.measite.minidns.record.InternetAddressRR;
33import de.measite.minidns.record.SRV;
34import eu.siacs.conversations.Config;
35import eu.siacs.conversations.R;
36import eu.siacs.conversations.services.XmppConnectionService;
37
38public class Resolver {
39
40 private static final String DIRECT_TLS_SERVICE = "_xmpps-client";
41 private static final String STARTTLS_SERICE = "_xmpp-client";
42
43 private static XmppConnectionService SERVICE = null;
44
45
46 public static void init(XmppConnectionService service) {
47 Resolver.SERVICE = service;
48 DNSClient.removeDNSServerLookupMechanism(AndroidUsingExec.INSTANCE);
49 DNSClient.addDnsServerLookupMechanism(AndroidUsingExecLowPriority.INSTANCE);
50 DNSClient.addDnsServerLookupMechanism(new AndroidUsingLinkProperties(service));
51 final AbstractDNSClient client = ResolverApi.INSTANCE.getClient();
52 if (client instanceof ReliableDNSClient) {
53 disableHardcodedDnsServers((ReliableDNSClient) client);
54 }
55 }
56
57 private static void disableHardcodedDnsServers(ReliableDNSClient reliableDNSClient) {
58 try {
59 final Field dnsClientField = ReliableDNSClient.class.getDeclaredField("dnsClient");
60 dnsClientField.setAccessible(true);
61 final DNSClient dnsClient = (DNSClient) dnsClientField.get(reliableDNSClient);
62 dnsClient.getDataSource().setTimeout(3000);
63 final Field useHardcodedDnsServers = DNSClient.class.getDeclaredField("useHardcodedDnsServers");
64 useHardcodedDnsServers.setAccessible(true);
65 useHardcodedDnsServers.setBoolean(dnsClient, false);
66 } catch (NoSuchFieldException | IllegalAccessException e) {
67 Log.e(Config.LOGTAG, "Unable to disable hardcoded DNS servers", e);
68 }
69 }
70
71 public static List<Result> resolve(String domain) {
72 final List<Result> results = new ArrayList<>();
73 final List<Result> fallbackResults = new ArrayList<>();
74 Thread[] threads = new Thread[3];
75 threads[0] = new Thread(() -> {
76 try {
77 final List<Result> list = resolveSrv(domain, true);
78 synchronized (results) {
79 results.addAll(list);
80 }
81 } catch (Throwable throwable) {
82 Log.d(Config.LOGTAG, Resolver.class.getSimpleName() + ": error resolving SRV record (direct TLS)", throwable);
83 }
84 });
85 threads[1] = new Thread(() -> {
86 try {
87 final List<Result> list = resolveSrv(domain, false);
88 synchronized (results) {
89 results.addAll(list);
90 }
91 } catch (Throwable throwable) {
92 Log.d(Config.LOGTAG, Resolver.class.getSimpleName() + ": error resolving SRV record (STARTTLS)", throwable);
93 }
94 });
95 threads[2] = new Thread(() -> {
96 List<Result> list = resolveNoSrvRecords(DNSName.from(domain), true);
97 synchronized (fallbackResults) {
98 fallbackResults.addAll(list);
99 }
100 });
101 for (Thread thread : threads) {
102 thread.start();
103 }
104 try {
105 threads[0].join();
106 threads[1].join();
107 if (results.size() > 0) {
108 threads[2].interrupt();
109 synchronized (results) {
110 Collections.sort(results);
111 Log.d(Config.LOGTAG, Resolver.class.getSimpleName() + ": " + results.toString());
112 return new ArrayList<>(results);
113 }
114 } else {
115 threads[2].join();
116 synchronized (fallbackResults) {
117 Collections.sort(fallbackResults);
118 Log.d(Config.LOGTAG, Resolver.class.getSimpleName() + ": " + fallbackResults.toString());
119 return new ArrayList<>(fallbackResults);
120 }
121 }
122 } catch (InterruptedException e) {
123 for(Thread thread : threads) {
124 thread.interrupt();
125 }
126 synchronized (results) {
127 return new ArrayList<>(results);
128 }
129 }
130 }
131
132 private static List<Result> resolveSrv(String domain, final boolean directTls) throws IOException {
133 DNSName dnsName = DNSName.from((directTls ? DIRECT_TLS_SERVICE : STARTTLS_SERICE) + "._tcp." + domain);
134 ResolverResult<SRV> result = resolveWithFallback(dnsName, SRV.class);
135 final List<Result> results = new ArrayList<>();
136 final List<Thread> threads = new ArrayList<>();
137 for (SRV record : result.getAnswersOrEmptySet()) {
138 if (record.name.length() == 0 && record.priority == 0) {
139 continue;
140 }
141 threads.add(new Thread(() -> {
142 final List<Result> ipv4s = resolveIp(record, A.class, result.isAuthenticData(), directTls);
143 if (ipv4s.size() == 0) {
144 Result resolverResult = Result.fromRecord(record, directTls);
145 resolverResult.authenticated = resolverResult.isAuthenticated();
146 ipv4s.add(resolverResult);
147 }
148 synchronized (results) {
149 results.addAll(ipv4s);
150 }
151
152 }));
153 threads.add(new Thread(() -> {
154 final List<Result> ipv6s = resolveIp(record, AAAA.class, result.isAuthenticData(), directTls);
155 synchronized (results) {
156 results.addAll(ipv6s);
157 }
158 }));
159 }
160 for (Thread thread : threads) {
161 thread.start();
162 }
163 for (Thread thread : threads) {
164 try {
165 thread.join();
166 } catch (InterruptedException e) {
167 return Collections.emptyList();
168 }
169 }
170 return results;
171 }
172
173 private static <D extends InternetAddressRR> List<Result> resolveIp(SRV srv, Class<D> type, boolean authenticated, boolean directTls) {
174 List<Result> list = new ArrayList<>();
175 try {
176 ResolverResult<D> results = resolveWithFallback(srv.name, type, authenticated);
177 for (D record : results.getAnswersOrEmptySet()) {
178 Result resolverResult = Result.fromRecord(srv, directTls);
179 resolverResult.authenticated = results.isAuthenticData() && authenticated;
180 resolverResult.ip = record.getInetAddress();
181 list.add(resolverResult);
182 }
183 } catch (Throwable t) {
184 Log.d(Config.LOGTAG, Resolver.class.getSimpleName() + ": error resolving " + type.getSimpleName() + " " + t.getMessage());
185 }
186 return list;
187 }
188
189 private static List<Result> resolveNoSrvRecords(DNSName dnsName, boolean withCnames) {
190 List<Result> results = new ArrayList<>();
191 try {
192 for (A a : resolveWithFallback(dnsName, A.class, false).getAnswersOrEmptySet()) {
193 results.add(Result.createDefault(dnsName, a.getInetAddress()));
194 }
195 for (AAAA aaaa : resolveWithFallback(dnsName, AAAA.class, false).getAnswersOrEmptySet()) {
196 results.add(Result.createDefault(dnsName, aaaa.getInetAddress()));
197 }
198 if (results.size() == 0 && withCnames) {
199 for (CNAME cname : resolveWithFallback(dnsName, CNAME.class, false).getAnswersOrEmptySet()) {
200 results.addAll(resolveNoSrvRecords(cname.name, false));
201 }
202 }
203 } catch (Throwable throwable) {
204 Log.d(Config.LOGTAG, Resolver.class.getSimpleName() + "error resolving fallback records", throwable);
205 }
206 results.add(Result.createDefault(dnsName));
207 return results;
208 }
209
210 private static <D extends Data> ResolverResult<D> resolveWithFallback(DNSName dnsName, Class<D> type) throws IOException {
211 return resolveWithFallback(dnsName, type, validateHostname());
212 }
213
214 private static <D extends Data> ResolverResult<D> resolveWithFallback(DNSName dnsName, Class<D> type, boolean validateHostname) throws IOException {
215 final Question question = new Question(dnsName, Record.TYPE.getType(type));
216 if (!validateHostname) {
217 return ResolverApi.INSTANCE.resolve(question);
218 }
219 try {
220 return DnssecResolverApi.INSTANCE.resolveDnssecReliable(question);
221 } catch (DNSSECResultNotAuthenticException e) {
222 Log.d(Config.LOGTAG, Resolver.class.getSimpleName() + ": error resolving " + type.getSimpleName() + " with DNSSEC. Trying DNS instead.", e);
223 } catch (IOException e) {
224 throw e;
225 } catch (Throwable throwable) {
226 Log.d(Config.LOGTAG, Resolver.class.getSimpleName() + ": error resolving " + type.getSimpleName() + " with DNSSEC. Trying DNS instead.", throwable);
227 }
228 return ResolverApi.INSTANCE.resolve(question);
229 }
230
231 private static boolean validateHostname() {
232 return SERVICE != null && SERVICE.getBooleanPreference("validate_hostname", R.bool.validate_hostname);
233 }
234
235 public static class Result implements Comparable<Result> {
236 public static final String DOMAIN = "domain";
237 public static final String IP = "ip";
238 public static final String HOSTNAME = "hostname";
239 public static final String PORT = "port";
240 public static final String PRIORITY = "priority";
241 public static final String DIRECT_TLS = "directTls";
242 public static final String AUTHENTICATED = "authenticated";
243 private InetAddress ip;
244 private DNSName hostname;
245 private int port = 5222;
246 private boolean directTls = false;
247 private boolean authenticated = false;
248 private int priority;
249
250 static Result fromRecord(SRV srv, boolean directTls) {
251 Result result = new Result();
252 result.port = srv.port;
253 result.hostname = srv.name;
254 result.directTls = directTls;
255 result.priority = srv.priority;
256 return result;
257 }
258
259 static Result createDefault(DNSName hostname, InetAddress ip) {
260 Result result = new Result();
261 result.port = 5222;
262 result.hostname = hostname;
263 result.ip = ip;
264 return result;
265 }
266
267 static Result createDefault(DNSName hostname) {
268 return createDefault(hostname, null);
269 }
270
271 public static Result fromCursor(Cursor cursor) {
272 final Result result = new Result();
273 try {
274 result.ip = InetAddress.getByAddress(cursor.getBlob(cursor.getColumnIndex(IP)));
275 } catch (UnknownHostException e) {
276 result.ip = null;
277 }
278 result.hostname = DNSName.from(cursor.getString(cursor.getColumnIndex(HOSTNAME)));
279 result.port = cursor.getInt(cursor.getColumnIndex(PORT));
280 result.priority = cursor.getInt(cursor.getColumnIndex(PRIORITY));
281 result.authenticated = cursor.getInt(cursor.getColumnIndex(AUTHENTICATED)) > 0;
282 result.directTls = cursor.getInt(cursor.getColumnIndex(DIRECT_TLS)) > 0;
283 return result;
284 }
285
286 @Override
287 public boolean equals(Object o) {
288 if (this == o) return true;
289 if (o == null || getClass() != o.getClass()) return false;
290
291 Result result = (Result) o;
292
293 if (port != result.port) return false;
294 if (directTls != result.directTls) return false;
295 if (authenticated != result.authenticated) return false;
296 if (priority != result.priority) return false;
297 if (ip != null ? !ip.equals(result.ip) : result.ip != null) return false;
298 return hostname != null ? hostname.equals(result.hostname) : result.hostname == null;
299 }
300
301 @Override
302 public int hashCode() {
303 int result = ip != null ? ip.hashCode() : 0;
304 result = 31 * result + (hostname != null ? hostname.hashCode() : 0);
305 result = 31 * result + port;
306 result = 31 * result + (directTls ? 1 : 0);
307 result = 31 * result + (authenticated ? 1 : 0);
308 result = 31 * result + priority;
309 return result;
310 }
311
312 public InetAddress getIp() {
313 return ip;
314 }
315
316 public int getPort() {
317 return port;
318 }
319
320 public DNSName getHostname() {
321 return hostname;
322 }
323
324 public boolean isDirectTls() {
325 return directTls;
326 }
327
328 public boolean isAuthenticated() {
329 return authenticated;
330 }
331
332 @Override
333 public String toString() {
334 return "Result{" +
335 "ip='" + (ip == null ? null : ip.getHostAddress()) + '\'' +
336 ", hostame='" + hostname.toString() + '\'' +
337 ", port=" + port +
338 ", directTls=" + directTls +
339 ", authenticated=" + authenticated +
340 ", priority=" + priority +
341 '}';
342 }
343
344 @Override
345 public int compareTo(@NonNull Result result) {
346 if (result.priority == priority) {
347 if (directTls == result.directTls) {
348 if (ip == null && result.ip == null) {
349 return 0;
350 } else if (ip != null && result.ip != null) {
351 if (ip instanceof Inet4Address && result.ip instanceof Inet4Address) {
352 return 0;
353 } else {
354 return ip instanceof Inet4Address ? -1 : 1;
355 }
356 } else {
357 return ip != null ? -1 : 1;
358 }
359 } else {
360 return directTls ? -1 : 1;
361 }
362 } else {
363 return priority - result.priority;
364 }
365 }
366
367 public ContentValues toContentValues() {
368 final ContentValues contentValues = new ContentValues();
369 contentValues.put(IP, ip == null ? null : ip.getAddress());
370 contentValues.put(HOSTNAME, hostname.toString());
371 contentValues.put(PORT, port);
372 contentValues.put(PRIORITY, priority);
373 contentValues.put(DIRECT_TLS, directTls ? 1 : 0);
374 contentValues.put(AUTHENTICATED, authenticated ? 1 : 0);
375 return contentValues;
376 }
377 }
378
379}