Skip to content

Commit

Permalink
Allow specification of multiple dns resolvers
Browse files Browse the repository at this point in the history
  • Loading branch information
oxtoacart committed Oct 6, 2023
1 parent fc47ce0 commit a53bbeb
Show file tree
Hide file tree
Showing 4 changed files with 90 additions and 48 deletions.
77 changes: 77 additions & 0 deletions custom_dns.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,77 @@
package proxy

import (
"context"
"fmt"
"net"
"time"

"github.com/getlantern/errors"
"github.com/getlantern/netx"
)

// Returns a dialer that uses custom DNS servers to resolve the host.
func customDNSDialer(dnsServers []string, timeout time.Duration) (func(context.Context, string, string) (net.Conn, error), error) {
resolvers := make([]*net.Resolver, 0, len(dnsServers))
for _, _dnsServer := range dnsServers {
dnsServer := _dnsServer
r := &net.Resolver{
PreferGo: true,
Dial: func(ctx context.Context, network, address string) (net.Conn, error) {
return netx.DialContext(ctx, "udp", dnsServer)
},
}
resolvers = append(resolvers, r)
}

dial := func(ctx context.Context, network, addr string) (net.Conn, error) {
// resolve separately so that we can track the DNS resolution time
host, port, err := net.SplitHostPort(addr)
if err != nil {
return nil, errors.New("invalid address %v: %v", addr, err)
}
ip := net.ParseIP(host)
var resolveErr error
if ip == nil {
// the host wasn't an IP, so resolve it
resolveLoop:
for _, r := range resolvers {
var ips []net.IPAddr
// Note - 5 seconds is the default Linux DNS timeout
rctx, cancel := context.WithTimeout(ctx, 5*time.Second)
ips, resolveErr = r.LookupIPAddr(rctx, host)
cancel()
if resolveErr == nil && len(ips) > 0 {
// Google anomaly detection can be triggered very often over IPv6.
// Prefer IPv4 to mitigate, see issue #97
// If no IPv4 is available, fall back to IPv6
for _, candidate := range ips {
if candidate.IP.To4() != nil {
ip = candidate.IP
break resolveLoop
}
}
// We couldn't find an IPv4, so just use the first one (at this point we assume it's IPv6)
ip = ips[0].IP
break resolveLoop
}
}
}
if ip == nil {
return nil, errors.New("unable to resolve host %v, last resolution error: %v", host, resolveErr)
}

resolvedAddr := fmt.Sprintf("%s:%s", ip, port)
d := &net.Dialer{
Deadline: time.Now().Add(timeout),
}
conn, dialErr := d.DialContext(ctx, "tcp", resolvedAddr)
if dialErr != nil {
return nil, dialErr
}

return conn, nil
}

return dial, nil
}
4 changes: 2 additions & 2 deletions http-proxy/main.go
Original file line number Diff line number Diff line change
Expand Up @@ -185,7 +185,7 @@ var (

track = flag.String("track", "", "The track this proxy is running on")

dnsServer = flag.String("dns-server", "172.16.0.53:53", "Optional DNS server to use for DNS lookups (in place of system resolver)")
dnsServers = flag.String("dns-servers", "", "Optional DNS servers (comma separated) to use for DNS lookups (in place of system resolver)")
)

const (
Expand Down Expand Up @@ -470,7 +470,7 @@ func main() {
BroflakeAddr: *broflakeAddr,
BroflakeCert: os.Getenv("BROFLAKE_CERT"),
BroflakeKey: os.Getenv("BROFLAKE_KEY"),
DNSServer: *dnsServer,
DNSServers: strings.Split(*dnsServers, ","),
}
if *maxmindLicenseKey != "" {
log.Debug("Will use Maxmind for geolocating clients")
Expand Down
56 changes: 10 additions & 46 deletions http_proxy.go
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,6 @@ import (
shadowsocks "github.com/getlantern/http-proxy-lantern/v2/shadowsocks"
"github.com/getlantern/http-proxy-lantern/v2/starbridge"
"github.com/getlantern/kcpwrapper"
"github.com/getlantern/netx"

"github.com/xtaci/smux"

Expand Down Expand Up @@ -184,7 +183,7 @@ type Proxy struct {
BroflakeCert string
BroflakeKey string

DNSServer string
DNSServers []string
throttleConfig throttle.Config
instrument instrument.Instrument
}
Expand Down Expand Up @@ -279,35 +278,6 @@ func (p *Proxy) ListenAndServe(ctx context.Context) error {
// Throttle connections when signaled
srv.AddListenerWrappers(lanternlisteners.NewBitrateListener, bwReporting.wrapper)

if p.DNSServer != "" {
log.Debugf("Will resolve DNS using %v", p.DNSServer)
host, port, err := net.SplitHostPort(p.DNSServer)
if err != nil {
log.Fatalf("invalid dns-server address %v: %v", p.DNSServer, err)
}
r := &net.Resolver{
PreferGo: true,
Dial: func(ctx context.Context, network, address string) (net.Conn, error) {
log.Debug("Dialing custom resolver")
return netx.DialContext(ctx, host, port)
},
}
netx.OverrideResolveIPs(func(host string) ([]net.IP, error) {
ctx, cancel := context.WithTimeout(context.Background(), 5*time.Second)
defer cancel()

addrs, err := r.LookupIPAddr(ctx, host)
if err != nil {
return nil, err
}
ips := make([]net.IP, 0, len(addrs))
for _, addr := range addrs {
ips = append(ips, addr.IP)
}
return ips, nil
})
}

allListeners := make([]net.Listener, 0)
listenerProtocols := make([]string, 0)
addListenerIfNecessary := func(proto, addr string, fn listenerBuilderFN) error {
Expand Down Expand Up @@ -639,22 +609,16 @@ func (p *Proxy) createFilterChain(bl *blacklist.Blacklist) (filters.Chain, proxy
}
filterChain = filterChain.Append(instrumentedProxyPingFilter)

// Google anomaly detection can be triggered very often over IPv6.
// Prefer IPv4 to mitigate, see issue #97
_dialer := preferIPV4Dialer(timeoutToDialOriginSite)
dialer := func(ctx context.Context, network, addr string) (net.Conn, error) {
// resolve separately so that we can track the DNS resolution time
resolvedAddr, resolveErr := netx.Resolve(network, addr)
if resolveErr != nil {
return nil, resolveErr
}

conn, dialErr := _dialer(ctx, network, resolvedAddr.String())
if dialErr != nil {
return nil, dialErr
var dialer func(context.Context, string, string) (net.Conn, error)
if len(p.DNSServers) == 0 {
log.Debug("Will resolve DNS using system DNS servers")
dialer = preferIPV4Dialer(timeoutToDialOriginSite)
} else {
log.Debugf("Will resolve DNS using %v", p.DNSServers)
dialer, err = customDNSDialer(p.DNSServers, timeoutToDialOriginSite)
if err != nil {
return nil, nil, err
}

return conn, nil
}
dialerForPforward := dialer

Expand Down
1 change: 1 addition & 0 deletions throttle_integration_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -93,6 +93,7 @@ func doTestThrottling(t *testing.T, pro bool, serverAddr string, redisIsUp bool,
TestingLocal: true,
GoogleSearchRegex: "bequiet",
GoogleCaptchaRegex: "bequiet",
DNSServers: []string{"127.0.0.1:2435", "8.8.8.8:53"}, // first one is a bogus DNS server
}
go func() {
assert.NoError(t, proxy.ListenAndServe(context.Background()))
Expand Down

0 comments on commit a53bbeb

Please sign in to comment.