2020-10-29 16:39:11 +00:00
|
|
|
// Package home contains AdGuard Home's HTTP API methods.
|
2019-06-10 09:33:19 +01:00
|
|
|
package home
|
2018-08-30 15:25:33 +01:00
|
|
|
|
|
|
|
import (
|
2019-04-25 12:57:03 +01:00
|
|
|
"context"
|
2020-03-04 12:11:17 +00:00
|
|
|
"crypto/x509"
|
2018-08-30 15:25:33 +01:00
|
|
|
"fmt"
|
2021-05-21 12:55:42 +01:00
|
|
|
"io/fs"
|
2024-07-10 13:18:46 +01:00
|
|
|
"log/slog"
|
2018-08-30 15:25:33 +01:00
|
|
|
"net/http"
|
2022-10-14 13:29:44 +01:00
|
|
|
"net/netip"
|
2023-09-21 15:07:57 +01:00
|
|
|
"net/url"
|
2018-08-30 15:25:33 +01:00
|
|
|
"os"
|
2018-12-05 12:36:18 +00:00
|
|
|
"os/signal"
|
2018-08-30 15:25:33 +01:00
|
|
|
"path/filepath"
|
2019-02-05 11:09:05 +00:00
|
|
|
"runtime"
|
2024-02-08 17:39:18 +00:00
|
|
|
"slices"
|
2019-02-12 18:14:02 +00:00
|
|
|
"sync"
|
2018-12-05 12:36:18 +00:00
|
|
|
"syscall"
|
2019-06-06 01:00:15 +01:00
|
|
|
"time"
|
2018-08-30 15:25:33 +01:00
|
|
|
|
2022-01-19 17:45:50 +00:00
|
|
|
"github.com/AdguardTeam/AdGuardHome/internal/aghalg"
|
2021-03-16 16:42:15 +00:00
|
|
|
"github.com/AdguardTeam/AdGuardHome/internal/aghnet"
|
|
|
|
"github.com/AdguardTeam/AdGuardHome/internal/aghos"
|
2022-01-26 11:39:34 +00:00
|
|
|
"github.com/AdguardTeam/AdGuardHome/internal/aghtls"
|
2023-08-24 11:42:17 +01:00
|
|
|
"github.com/AdguardTeam/AdGuardHome/internal/arpdb"
|
2020-10-30 10:32:02 +00:00
|
|
|
"github.com/AdguardTeam/AdGuardHome/internal/dhcpd"
|
|
|
|
"github.com/AdguardTeam/AdGuardHome/internal/dnsforward"
|
2021-05-21 14:15:47 +01:00
|
|
|
"github.com/AdguardTeam/AdGuardHome/internal/filtering"
|
2023-04-27 14:39:35 +01:00
|
|
|
"github.com/AdguardTeam/AdGuardHome/internal/filtering/hashprefix"
|
2023-03-15 11:31:07 +00:00
|
|
|
"github.com/AdguardTeam/AdGuardHome/internal/filtering/safesearch"
|
2024-10-02 19:00:15 +01:00
|
|
|
"github.com/AdguardTeam/AdGuardHome/internal/permcheck"
|
2020-10-30 10:32:02 +00:00
|
|
|
"github.com/AdguardTeam/AdGuardHome/internal/querylog"
|
|
|
|
"github.com/AdguardTeam/AdGuardHome/internal/stats"
|
2021-01-13 13:18:51 +00:00
|
|
|
"github.com/AdguardTeam/AdGuardHome/internal/updater"
|
|
|
|
"github.com/AdguardTeam/AdGuardHome/internal/version"
|
2023-04-27 14:39:35 +01:00
|
|
|
"github.com/AdguardTeam/dnsproxy/upstream"
|
2021-05-24 15:28:11 +01:00
|
|
|
"github.com/AdguardTeam/golibs/errors"
|
2023-12-07 13:48:55 +00:00
|
|
|
"github.com/AdguardTeam/golibs/hostsfile"
|
2019-02-25 13:44:22 +00:00
|
|
|
"github.com/AdguardTeam/golibs/log"
|
2024-08-27 18:42:10 +01:00
|
|
|
"github.com/AdguardTeam/golibs/logutil/slogutil"
|
2021-08-09 14:03:37 +01:00
|
|
|
"github.com/AdguardTeam/golibs/netutil"
|
2024-11-05 09:25:39 +00:00
|
|
|
"github.com/AdguardTeam/golibs/netutil/urlutil"
|
2023-12-07 13:48:55 +00:00
|
|
|
"github.com/AdguardTeam/golibs/osutil"
|
2019-02-05 11:09:05 +00:00
|
|
|
)
|
|
|
|
|
2019-12-11 09:38:58 +00:00
|
|
|
// Global context
|
|
|
|
type homeContext struct {
|
2020-02-13 15:42:07 +00:00
|
|
|
// Modules
|
|
|
|
// --
|
|
|
|
|
2021-10-14 17:39:21 +01:00
|
|
|
clients clientsContainer // per-client-settings module
|
2022-08-04 17:05:28 +01:00
|
|
|
stats stats.Interface // statistics module
|
2021-10-14 17:39:21 +01:00
|
|
|
queryLog querylog.QueryLog // query log module
|
|
|
|
dnsServer *dnsforward.Server // DNS module
|
2022-09-13 21:45:35 +01:00
|
|
|
dhcpServer dhcpd.Interface // DHCP module
|
2021-10-14 17:39:21 +01:00
|
|
|
auth *Auth // HTTP authentication module
|
2022-09-23 11:23:35 +01:00
|
|
|
filters *filtering.DNSFilter // DNS filtering module
|
2023-04-11 15:22:51 +01:00
|
|
|
web *webAPI // Web (HTTP, HTTPS) module
|
2022-10-14 17:37:14 +01:00
|
|
|
tls *tlsManager // TLS module
|
2023-03-28 11:27:46 +01:00
|
|
|
|
|
|
|
// etcHosts contains IP-hostname mappings taken from the OS-specific hosts
|
|
|
|
// configuration files, for example /etc/hosts.
|
2021-10-14 17:39:21 +01:00
|
|
|
etcHosts *aghnet.HostsContainer
|
2021-11-17 14:21:10 +00:00
|
|
|
|
2020-11-25 12:50:59 +00:00
|
|
|
// mux is our custom http.ServeMux.
|
|
|
|
mux *http.ServeMux
|
|
|
|
|
2020-02-13 15:42:07 +00:00
|
|
|
// Runtime properties
|
|
|
|
// --
|
|
|
|
|
2024-02-21 14:01:15 +00:00
|
|
|
// confFilePath is the configuration file path as set by default or from the
|
|
|
|
// command-line options.
|
|
|
|
confFilePath string
|
|
|
|
|
|
|
|
workDir string // Location of our directory, used to protect against CWD being somewhere else
|
|
|
|
pidFileName string // PID file name. Empty if no PID file was created.
|
|
|
|
controlLock sync.Mutex
|
|
|
|
tlsRoots *x509.CertPool // list of root CAs for TLSv1.2
|
2022-10-14 18:14:07 +01:00
|
|
|
|
|
|
|
// tlsCipherIDs are the ID of the cipher suites that AdGuard Home must use.
|
|
|
|
tlsCipherIDs []uint16
|
|
|
|
|
2022-11-08 08:36:42 +00:00
|
|
|
// firstRun, if true, tells AdGuard Home to only start the web interface
|
|
|
|
// service, and only serve the first-run APIs.
|
|
|
|
firstRun bool
|
2020-02-13 15:42:07 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// getDataDir returns path to the directory where we store databases and filters
|
|
|
|
func (c *homeContext) getDataDir() string {
|
|
|
|
return filepath.Join(c.workDir, dataDir)
|
2019-12-11 09:38:58 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// Context - a global context object
|
2024-07-10 13:18:46 +01:00
|
|
|
//
|
|
|
|
// TODO(a.garipov): Refactor.
|
2019-12-11 09:38:58 +00:00
|
|
|
var Context homeContext
|
|
|
|
|
2019-07-09 16:52:18 +01:00
|
|
|
// Main is the entry point
|
2021-05-21 12:55:42 +01:00
|
|
|
func Main(clientBuildFS fs.FS) {
|
2022-10-05 15:07:08 +01:00
|
|
|
initCmdLineOpts()
|
|
|
|
|
|
|
|
// The configuration file path can be overridden, but other command-line
|
|
|
|
// options have to override config values. Therefore, do it manually
|
|
|
|
// instead of using package flag.
|
|
|
|
//
|
|
|
|
// TODO(a.garipov): The comment above is most likely false. Replace with
|
|
|
|
// package flag.
|
|
|
|
opts := loadCmdLineOpts()
|
2018-08-30 15:25:33 +01:00
|
|
|
|
2023-08-28 14:40:46 +01:00
|
|
|
done := make(chan struct{})
|
|
|
|
|
2023-07-19 14:57:57 +01:00
|
|
|
signals := make(chan os.Signal, 1)
|
|
|
|
signal.Notify(signals, syscall.SIGINT, syscall.SIGTERM, syscall.SIGHUP, syscall.SIGQUIT)
|
2023-08-28 14:40:46 +01:00
|
|
|
|
2020-02-13 15:42:07 +00:00
|
|
|
go func() {
|
2024-10-22 11:57:54 +01:00
|
|
|
ctx := context.Background()
|
2020-02-18 11:49:50 +00:00
|
|
|
for {
|
2023-07-19 14:57:57 +01:00
|
|
|
sig := <-signals
|
2020-11-05 12:20:57 +00:00
|
|
|
log.Info("Received signal %q", sig)
|
2020-02-18 11:49:50 +00:00
|
|
|
switch sig {
|
|
|
|
case syscall.SIGHUP:
|
2024-10-22 11:57:54 +01:00
|
|
|
Context.clients.storage.ReloadARP(ctx)
|
2022-10-14 17:37:14 +01:00
|
|
|
Context.tls.reload()
|
2020-02-18 11:49:50 +00:00
|
|
|
default:
|
2024-10-22 11:57:54 +01:00
|
|
|
cleanup(ctx)
|
2020-02-18 11:49:50 +00:00
|
|
|
cleanupAlways()
|
2023-08-28 14:40:46 +01:00
|
|
|
close(done)
|
2020-02-18 11:49:50 +00:00
|
|
|
}
|
|
|
|
}
|
2020-02-13 15:42:07 +00:00
|
|
|
}()
|
|
|
|
|
2022-10-05 15:07:08 +01:00
|
|
|
if opts.serviceControlAction != "" {
|
2023-08-31 15:50:46 +01:00
|
|
|
handleServiceControlAction(opts, clientBuildFS, signals, done)
|
2021-06-03 19:04:13 +01:00
|
|
|
|
2020-06-11 08:24:43 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2019-02-05 11:09:05 +00:00
|
|
|
// run the protection
|
2023-08-28 14:40:46 +01:00
|
|
|
run(opts, clientBuildFS, done)
|
2019-02-04 10:54:53 +00:00
|
|
|
}
|
|
|
|
|
2023-05-10 14:30:03 +01:00
|
|
|
// setupContext initializes [Context] fields. It also reads and upgrades
|
|
|
|
// config file if necessary.
|
|
|
|
func setupContext(opts options) (err error) {
|
2023-07-19 14:57:57 +01:00
|
|
|
Context.firstRun = detectFirstRun()
|
2019-04-01 10:22:54 +01:00
|
|
|
|
2022-10-14 17:03:03 +01:00
|
|
|
Context.tlsRoots = aghtls.SystemRootCAs()
|
2023-05-10 14:30:03 +01:00
|
|
|
Context.mux = http.NewServeMux()
|
|
|
|
|
2024-10-04 16:10:56 +01:00
|
|
|
if !opts.noEtcHosts {
|
|
|
|
err = setupHostsContainer()
|
|
|
|
if err != nil {
|
|
|
|
// Don't wrap the error, because it's informative enough as is.
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-07-19 14:57:57 +01:00
|
|
|
if Context.firstRun {
|
|
|
|
log.Info("This is the first time AdGuard Home is launched")
|
2024-11-22 14:03:09 +00:00
|
|
|
checkNetworkPermissions()
|
2021-04-16 08:32:41 +01:00
|
|
|
|
2023-07-19 14:57:57 +01:00
|
|
|
return nil
|
|
|
|
}
|
2019-04-30 13:26:57 +01:00
|
|
|
|
2023-08-31 14:34:15 +01:00
|
|
|
err = parseConfig()
|
2023-07-19 14:57:57 +01:00
|
|
|
if err != nil {
|
|
|
|
log.Error("parsing configuration file: %s", err)
|
2022-04-26 11:04:16 +01:00
|
|
|
|
2023-07-19 14:57:57 +01:00
|
|
|
os.Exit(1)
|
2019-02-04 10:54:53 +00:00
|
|
|
}
|
2020-11-25 12:50:59 +00:00
|
|
|
|
2023-07-19 14:57:57 +01:00
|
|
|
if opts.checkConfig {
|
|
|
|
log.Info("configuration file is ok")
|
2019-02-04 10:54:53 +00:00
|
|
|
|
2023-07-19 14:57:57 +01:00
|
|
|
os.Exit(0)
|
2022-10-05 15:07:08 +01:00
|
|
|
}
|
|
|
|
|
2023-07-19 14:57:57 +01:00
|
|
|
return nil
|
2022-10-05 15:07:08 +01:00
|
|
|
}
|
|
|
|
|
2021-06-04 14:35:34 +01:00
|
|
|
// logIfUnsupported logs a formatted warning if the error is one of the
|
|
|
|
// unsupported errors and returns nil. If err is nil, logIfUnsupported returns
|
2022-01-26 11:39:34 +00:00
|
|
|
// nil. Otherwise, it returns err.
|
2021-06-04 14:35:34 +01:00
|
|
|
func logIfUnsupported(msg string, err error) (outErr error) {
|
2024-06-14 10:32:19 +01:00
|
|
|
if errors.Is(err, errors.ErrUnsupported) {
|
2021-06-04 14:35:34 +01:00
|
|
|
log.Debug(msg, err)
|
2021-12-16 17:54:59 +00:00
|
|
|
|
|
|
|
return nil
|
2021-06-04 14:35:34 +01:00
|
|
|
}
|
|
|
|
|
2021-12-16 17:54:59 +00:00
|
|
|
return err
|
2021-06-04 14:35:34 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
// configureOS sets the OS-related configuration.
|
|
|
|
func configureOS(conf *configuration) (err error) {
|
|
|
|
osConf := conf.OSConfig
|
|
|
|
if osConf == nil {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
if osConf.Group != "" {
|
|
|
|
err = aghos.SetGroup(osConf.Group)
|
|
|
|
err = logIfUnsupported("warning: setting group", err)
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("setting group: %w", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
log.Info("group set to %s", osConf.Group)
|
|
|
|
}
|
|
|
|
|
|
|
|
if osConf.User != "" {
|
|
|
|
err = aghos.SetUser(osConf.User)
|
|
|
|
err = logIfUnsupported("warning: setting user", err)
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("setting user: %w", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
log.Info("user set to %s", osConf.User)
|
|
|
|
}
|
|
|
|
|
|
|
|
if osConf.RlimitNoFile != 0 {
|
|
|
|
err = aghos.SetRlimit(osConf.RlimitNoFile)
|
|
|
|
err = logIfUnsupported("warning: setting rlimit", err)
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("setting rlimit: %w", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
log.Info("rlimit_nofile set to %d", osConf.RlimitNoFile)
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2021-11-17 14:21:10 +00:00
|
|
|
// setupHostsContainer initializes the structures to keep up-to-date the hosts
|
|
|
|
// provided by the OS.
|
|
|
|
func setupHostsContainer() (err error) {
|
2023-03-28 11:27:46 +01:00
|
|
|
hostsWatcher, err := aghos.NewOSWritesWatcher()
|
2021-11-17 14:21:10 +00:00
|
|
|
if err != nil {
|
2024-06-17 17:34:46 +01:00
|
|
|
log.Info("WARNING: initializing filesystem watcher: %s; not watching for changes", err)
|
|
|
|
|
|
|
|
hostsWatcher = aghos.EmptyFSWatcher{}
|
2021-11-17 14:21:10 +00:00
|
|
|
}
|
|
|
|
|
2023-12-07 13:48:55 +00:00
|
|
|
paths, err := hostsfile.DefaultHostsPaths()
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("getting default system hosts paths: %w", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
Context.etcHosts, err = aghnet.NewHostsContainer(osutil.RootDirFS(), hostsWatcher, paths...)
|
2021-11-17 14:21:10 +00:00
|
|
|
if err != nil {
|
2023-03-28 11:27:46 +01:00
|
|
|
closeErr := hostsWatcher.Close()
|
2023-11-16 11:05:10 +00:00
|
|
|
if errors.Is(err, aghnet.ErrNoHostsPaths) {
|
2021-11-17 14:21:10 +00:00
|
|
|
log.Info("warning: initing hosts container: %s", err)
|
|
|
|
|
2023-11-16 11:05:10 +00:00
|
|
|
return closeErr
|
2021-11-17 14:21:10 +00:00
|
|
|
}
|
|
|
|
|
2023-11-16 11:05:10 +00:00
|
|
|
return errors.Join(fmt.Errorf("initializing hosts container: %w", err), closeErr)
|
2021-11-17 14:21:10 +00:00
|
|
|
}
|
|
|
|
|
2024-02-13 10:19:22 +00:00
|
|
|
return hostsWatcher.Start()
|
2021-11-17 14:21:10 +00:00
|
|
|
}
|
|
|
|
|
2023-05-10 14:30:03 +01:00
|
|
|
// setupOpts sets up command-line options.
|
|
|
|
func setupOpts(opts options) (err error) {
|
|
|
|
err = setupBindOpts(opts)
|
2023-04-27 14:39:35 +01:00
|
|
|
if err != nil {
|
2023-05-10 14:30:03 +01:00
|
|
|
// Don't wrap the error, because it's informative enough as is.
|
|
|
|
return err
|
2023-04-27 14:39:35 +01:00
|
|
|
}
|
|
|
|
|
2023-05-10 14:30:03 +01:00
|
|
|
if len(opts.pidFile) != 0 && writePIDFile(opts.pidFile) {
|
|
|
|
Context.pidFileName = opts.pidFile
|
2023-04-27 14:39:35 +01:00
|
|
|
}
|
|
|
|
|
2023-05-10 14:30:03 +01:00
|
|
|
return nil
|
|
|
|
}
|
2023-04-27 14:39:35 +01:00
|
|
|
|
2023-05-10 14:30:03 +01:00
|
|
|
// initContextClients initializes Context clients and related fields.
|
2024-10-09 14:31:03 +01:00
|
|
|
func initContextClients(ctx context.Context, logger *slog.Logger) (err error) {
|
|
|
|
err = setupDNSFilteringConf(ctx, logger, config.Filtering)
|
2023-03-15 11:31:07 +00:00
|
|
|
if err != nil {
|
2023-05-10 14:30:03 +01:00
|
|
|
// Don't wrap the error, because it's informative enough as is.
|
|
|
|
return err
|
2023-03-15 11:31:07 +00:00
|
|
|
}
|
|
|
|
|
2023-07-19 14:57:57 +01:00
|
|
|
//lint:ignore SA1019 Migration is not over.
|
2020-02-13 15:42:07 +00:00
|
|
|
config.DHCP.WorkDir = Context.workDir
|
2023-04-18 13:12:11 +01:00
|
|
|
config.DHCP.DataDir = Context.getDataDir()
|
2019-10-11 17:56:18 +01:00
|
|
|
config.DHCP.HTTPRegister = httpRegister
|
|
|
|
config.DHCP.ConfigModified = onConfigModified
|
2020-11-16 16:01:12 +00:00
|
|
|
|
2021-06-16 14:48:46 +01:00
|
|
|
Context.dhcpServer, err = dhcpd.Create(config.DHCP)
|
|
|
|
if Context.dhcpServer == nil || err != nil {
|
2021-04-29 14:00:07 +01:00
|
|
|
// TODO(a.garipov): There are a lot of places in the code right
|
|
|
|
// now which assume that the DHCP server can be nil despite this
|
|
|
|
// condition. Inspect them and perhaps rewrite them to use
|
|
|
|
// Enabled() instead.
|
2021-06-03 19:04:13 +01:00
|
|
|
return fmt.Errorf("initing dhcp: %w", err)
|
2020-03-13 14:30:09 +00:00
|
|
|
}
|
2020-11-16 16:01:12 +00:00
|
|
|
|
2023-08-24 11:42:17 +01:00
|
|
|
var arpDB arpdb.Interface
|
2022-04-26 11:04:16 +01:00
|
|
|
if config.Clients.Sources.ARP {
|
2024-08-27 18:42:10 +01:00
|
|
|
arpDB = arpdb.New(logger.With(slogutil.KeyError, "arpdb"))
|
2021-04-12 16:31:45 +01:00
|
|
|
}
|
2021-12-13 12:18:21 +00:00
|
|
|
|
2023-11-16 11:05:10 +00:00
|
|
|
return Context.clients.Init(
|
2024-10-09 14:31:03 +01:00
|
|
|
ctx,
|
|
|
|
logger,
|
2023-05-10 14:30:03 +01:00
|
|
|
config.Clients.Persistent,
|
|
|
|
Context.dhcpServer,
|
|
|
|
Context.etcHosts,
|
2023-08-24 11:42:17 +01:00
|
|
|
arpDB,
|
2023-08-30 16:26:02 +01:00
|
|
|
config.Filtering,
|
2023-05-10 14:30:03 +01:00
|
|
|
)
|
|
|
|
}
|
2019-09-26 14:40:52 +01:00
|
|
|
|
2023-05-10 14:30:03 +01:00
|
|
|
// setupBindOpts overrides bind host/port from the opts.
|
|
|
|
func setupBindOpts(opts options) (err error) {
|
2023-06-29 13:29:52 +01:00
|
|
|
bindAddr := opts.bindAddr
|
|
|
|
if bindAddr != (netip.AddrPort{}) {
|
|
|
|
config.HTTPConfig.Address = bindAddr
|
2022-08-03 12:36:18 +01:00
|
|
|
|
2023-06-29 13:29:52 +01:00
|
|
|
if config.HTTPConfig.Address.Port() != 0 {
|
|
|
|
err = checkPorts()
|
|
|
|
if err != nil {
|
|
|
|
// Don't wrap the error, because it's informative enough as is.
|
|
|
|
return err
|
|
|
|
}
|
2021-12-16 17:54:59 +00:00
|
|
|
}
|
|
|
|
|
2023-06-29 13:29:52 +01:00
|
|
|
return nil
|
2019-02-04 10:54:53 +00:00
|
|
|
}
|
2023-05-10 14:30:03 +01:00
|
|
|
|
2023-06-29 13:29:52 +01:00
|
|
|
if opts.bindPort != 0 {
|
|
|
|
config.HTTPConfig.Address = netip.AddrPortFrom(
|
|
|
|
config.HTTPConfig.Address.Addr(),
|
2023-10-05 13:26:19 +01:00
|
|
|
opts.bindPort,
|
2023-06-29 13:29:52 +01:00
|
|
|
)
|
2023-06-23 08:03:01 +01:00
|
|
|
|
|
|
|
err = checkPorts()
|
|
|
|
if err != nil {
|
|
|
|
// Don't wrap the error, because it's informative enough as is.
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-06-29 13:29:52 +01:00
|
|
|
if opts.bindHost.IsValid() {
|
|
|
|
config.HTTPConfig.Address = netip.AddrPortFrom(
|
|
|
|
opts.bindHost,
|
|
|
|
config.HTTPConfig.Address.Port(),
|
|
|
|
)
|
|
|
|
}
|
|
|
|
|
2023-05-10 14:30:03 +01:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// setupDNSFilteringConf sets up DNS filtering configuration settings.
|
2024-10-09 14:31:03 +01:00
|
|
|
func setupDNSFilteringConf(
|
|
|
|
ctx context.Context,
|
|
|
|
baseLogger *slog.Logger,
|
|
|
|
conf *filtering.Config,
|
|
|
|
) (err error) {
|
2023-05-10 14:30:03 +01:00
|
|
|
const (
|
|
|
|
dnsTimeout = 3 * time.Second
|
|
|
|
|
|
|
|
sbService = "safe browsing"
|
|
|
|
defaultSafeBrowsingServer = `https://family.adguard-dns.com/dns-query`
|
|
|
|
sbTXTSuffix = `sb.dns.adguard.com.`
|
|
|
|
|
|
|
|
pcService = "parental control"
|
|
|
|
defaultParentalServer = `https://family.adguard-dns.com/dns-query`
|
|
|
|
pcTXTSuffix = `pc.dns.adguard.com.`
|
|
|
|
)
|
|
|
|
|
|
|
|
conf.EtcHosts = Context.etcHosts
|
2024-01-18 13:14:11 +00:00
|
|
|
// TODO(s.chzhen): Use empty interface.
|
2024-02-21 10:04:58 +00:00
|
|
|
if Context.etcHosts == nil || !config.DNS.HostsFileEnabled {
|
2024-01-18 13:14:11 +00:00
|
|
|
conf.EtcHosts = nil
|
|
|
|
}
|
|
|
|
|
2023-05-10 14:30:03 +01:00
|
|
|
conf.ConfigModified = onConfigModified
|
|
|
|
conf.HTTPRegister = httpRegister
|
|
|
|
conf.DataDir = Context.getDataDir()
|
|
|
|
conf.Filters = slices.Clone(config.Filters)
|
|
|
|
conf.WhitelistFilters = slices.Clone(config.WhitelistFilters)
|
|
|
|
conf.UserRules = slices.Clone(config.UserRules)
|
2023-07-18 15:02:07 +01:00
|
|
|
conf.HTTPClient = httpClient()
|
2023-05-10 14:30:03 +01:00
|
|
|
|
|
|
|
cacheTime := time.Duration(conf.CacheTime) * time.Minute
|
|
|
|
|
|
|
|
upsOpts := &upstream.Options{
|
|
|
|
Timeout: dnsTimeout,
|
2023-11-16 11:05:10 +00:00
|
|
|
Bootstrap: upstream.StaticResolver{
|
|
|
|
// 94.140.14.15.
|
|
|
|
netip.AddrFrom4([4]byte{94, 140, 14, 15}),
|
|
|
|
// 94.140.14.16.
|
|
|
|
netip.AddrFrom4([4]byte{94, 140, 14, 16}),
|
|
|
|
// 2a10:50c0::bad1:ff.
|
|
|
|
netip.AddrFrom16([16]byte{42, 16, 80, 192, 12: 186, 209, 0, 255}),
|
|
|
|
// 2a10:50c0::bad2:ff.
|
|
|
|
netip.AddrFrom16([16]byte{42, 16, 80, 192, 12: 186, 210, 0, 255}),
|
2023-05-10 14:30:03 +01:00
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
sbUps, err := upstream.AddressToUpstream(defaultSafeBrowsingServer, upsOpts)
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("converting safe browsing server: %w", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
conf.SafeBrowsingChecker = hashprefix.New(&hashprefix.Config{
|
|
|
|
Upstream: sbUps,
|
|
|
|
ServiceName: sbService,
|
|
|
|
TXTSuffix: sbTXTSuffix,
|
|
|
|
CacheTime: cacheTime,
|
|
|
|
CacheSize: conf.SafeBrowsingCacheSize,
|
|
|
|
})
|
|
|
|
|
2023-09-08 13:04:25 +01:00
|
|
|
// Protect against invalid configuration, see #6181.
|
|
|
|
//
|
|
|
|
// TODO(a.garipov): Validate against an empty host instead of setting it to
|
|
|
|
// default.
|
|
|
|
if conf.SafeBrowsingBlockHost == "" {
|
|
|
|
host := defaultSafeBrowsingBlockHost
|
|
|
|
log.Info("%s: warning: empty blocking host; using default: %q", sbService, host)
|
|
|
|
|
|
|
|
conf.SafeBrowsingBlockHost = host
|
2023-08-30 16:26:02 +01:00
|
|
|
}
|
|
|
|
|
2023-05-10 14:30:03 +01:00
|
|
|
parUps, err := upstream.AddressToUpstream(defaultParentalServer, upsOpts)
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("converting parental server: %w", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
conf.ParentalControlChecker = hashprefix.New(&hashprefix.Config{
|
|
|
|
Upstream: parUps,
|
|
|
|
ServiceName: pcService,
|
|
|
|
TXTSuffix: pcTXTSuffix,
|
|
|
|
CacheTime: cacheTime,
|
2023-07-10 18:00:29 +01:00
|
|
|
CacheSize: conf.ParentalCacheSize,
|
2023-05-10 14:30:03 +01:00
|
|
|
})
|
|
|
|
|
2023-09-08 13:04:25 +01:00
|
|
|
// Protect against invalid configuration, see #6181.
|
|
|
|
//
|
|
|
|
// TODO(a.garipov): Validate against an empty host instead of setting it to
|
|
|
|
// default.
|
|
|
|
if conf.ParentalBlockHost == "" {
|
|
|
|
host := defaultParentalBlockHost
|
|
|
|
log.Info("%s: warning: empty blocking host; using default: %q", pcService, host)
|
|
|
|
|
|
|
|
conf.ParentalBlockHost = host
|
2023-08-30 16:26:02 +01:00
|
|
|
}
|
|
|
|
|
2024-10-09 14:31:03 +01:00
|
|
|
logger := baseLogger.With(slogutil.KeyPrefix, safesearch.LogPrefix)
|
|
|
|
conf.SafeSearch, err = safesearch.NewDefault(ctx, &safesearch.DefaultConfig{
|
|
|
|
Logger: logger,
|
|
|
|
ServicesConfig: conf.SafeSearchConf,
|
|
|
|
CacheSize: conf.SafeSearchCacheSize,
|
|
|
|
CacheTTL: cacheTime,
|
|
|
|
})
|
2023-05-10 14:30:03 +01:00
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("initializing safesearch: %w", err)
|
2020-02-18 16:27:09 +00:00
|
|
|
}
|
2021-06-03 19:04:13 +01:00
|
|
|
|
|
|
|
return nil
|
2020-11-20 14:32:41 +00:00
|
|
|
}
|
|
|
|
|
2023-03-15 11:31:07 +00:00
|
|
|
// checkPorts is a helper for ports validation in config.
|
|
|
|
func checkPorts() (err error) {
|
|
|
|
tcpPorts := aghalg.UniqChecker[tcpPort]{}
|
2023-06-29 13:29:52 +01:00
|
|
|
addPorts(tcpPorts, tcpPort(config.HTTPConfig.Address.Port()))
|
2023-03-15 11:31:07 +00:00
|
|
|
|
|
|
|
udpPorts := aghalg.UniqChecker[udpPort]{}
|
|
|
|
addPorts(udpPorts, udpPort(config.DNS.Port))
|
|
|
|
|
|
|
|
if config.TLS.Enabled {
|
|
|
|
addPorts(
|
|
|
|
tcpPorts,
|
|
|
|
tcpPort(config.TLS.PortHTTPS),
|
|
|
|
tcpPort(config.TLS.PortDNSOverTLS),
|
|
|
|
tcpPort(config.TLS.PortDNSCrypt),
|
|
|
|
)
|
|
|
|
|
|
|
|
addPorts(udpPorts, udpPort(config.TLS.PortDNSOverQUIC))
|
|
|
|
}
|
|
|
|
|
|
|
|
if err = tcpPorts.Validate(); err != nil {
|
|
|
|
return fmt.Errorf("validating tcp ports: %w", err)
|
|
|
|
} else if err = udpPorts.Validate(); err != nil {
|
|
|
|
return fmt.Errorf("validating udp ports: %w", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2024-11-26 17:35:16 +00:00
|
|
|
// isUpdateEnabled returns true if the update is enabled for current
|
|
|
|
// configuration. It also logs the decision. customURL should be true if the
|
|
|
|
// updater is using a custom URL.
|
|
|
|
func isUpdateEnabled(ctx context.Context, l *slog.Logger, opts *options, customURL bool) (ok bool) {
|
|
|
|
if opts.disableUpdate {
|
|
|
|
l.DebugContext(ctx, "updates are disabled by command-line option")
|
|
|
|
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
|
|
|
|
switch version.Channel() {
|
|
|
|
case
|
|
|
|
version.ChannelDevelopment,
|
|
|
|
version.ChannelCandidate:
|
|
|
|
if customURL {
|
|
|
|
l.DebugContext(ctx, "updates are enabled because custom url is used")
|
|
|
|
} else {
|
|
|
|
l.DebugContext(ctx, "updates are disabled for development and candidate builds")
|
|
|
|
}
|
|
|
|
|
|
|
|
return customURL
|
|
|
|
default:
|
|
|
|
l.DebugContext(ctx, "updates are enabled")
|
|
|
|
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// initWeb initializes the web module.
|
2024-07-10 13:18:46 +01:00
|
|
|
func initWeb(
|
2024-11-26 17:35:16 +00:00
|
|
|
ctx context.Context,
|
2024-07-10 13:18:46 +01:00
|
|
|
opts options,
|
|
|
|
clientBuildFS fs.FS,
|
|
|
|
upd *updater.Updater,
|
|
|
|
l *slog.Logger,
|
2024-11-26 17:35:16 +00:00
|
|
|
customURL bool,
|
2024-07-10 13:18:46 +01:00
|
|
|
) (web *webAPI, err error) {
|
2023-01-23 09:47:59 +00:00
|
|
|
var clientFS fs.FS
|
2022-10-05 15:07:08 +01:00
|
|
|
if opts.localFrontend {
|
2021-05-21 12:55:42 +01:00
|
|
|
log.Info("warning: using local frontend files")
|
|
|
|
|
|
|
|
clientFS = os.DirFS("build/static")
|
|
|
|
} else {
|
|
|
|
clientFS, err = fs.Sub(clientBuildFS, "build/static")
|
|
|
|
if err != nil {
|
|
|
|
return nil, fmt.Errorf("getting embedded client subdir: %w", err)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2024-11-26 17:35:16 +00:00
|
|
|
disableUpdate := !isUpdateEnabled(ctx, l, &opts, customURL)
|
2023-07-19 14:57:57 +01:00
|
|
|
|
|
|
|
webConf := &webConfig{
|
|
|
|
updater: upd,
|
|
|
|
|
|
|
|
clientFS: clientFS,
|
|
|
|
|
2023-10-05 13:26:19 +01:00
|
|
|
BindAddr: config.HTTPConfig.Address,
|
2021-05-21 12:55:42 +01:00
|
|
|
|
|
|
|
ReadTimeout: readTimeout,
|
|
|
|
ReadHeaderTimeout: readHdrTimeout,
|
|
|
|
WriteTimeout: writeTimeout,
|
|
|
|
|
2023-07-19 14:57:57 +01:00
|
|
|
firstRun: Context.firstRun,
|
|
|
|
disableUpdate: disableUpdate,
|
|
|
|
runningAsService: opts.runningAsService,
|
|
|
|
serveHTTP3: config.DNS.ServeHTTP3,
|
2021-05-21 12:55:42 +01:00
|
|
|
}
|
|
|
|
|
2024-07-10 13:18:46 +01:00
|
|
|
web = newWebAPI(webConf, l)
|
2021-05-21 12:55:42 +01:00
|
|
|
if web == nil {
|
2024-11-26 17:35:16 +00:00
|
|
|
return nil, errors.Error("can not initialize web")
|
2021-05-21 12:55:42 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
return web, nil
|
|
|
|
}
|
|
|
|
|
2021-06-03 19:04:13 +01:00
|
|
|
func fatalOnError(err error) {
|
|
|
|
if err != nil {
|
|
|
|
log.Fatal(err)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-12-28 14:00:52 +00:00
|
|
|
// run configures and starts AdGuard Home.
|
2024-11-26 17:35:16 +00:00
|
|
|
//
|
|
|
|
// TODO(e.burkov): Make opts a pointer.
|
2023-08-28 14:40:46 +01:00
|
|
|
func run(opts options, clientBuildFS fs.FS, done chan struct{}) {
|
2024-04-01 09:31:51 +01:00
|
|
|
// Configure working dir.
|
2023-05-10 14:30:03 +01:00
|
|
|
err := initWorkingDir(opts)
|
|
|
|
fatalOnError(err)
|
2020-11-20 14:32:41 +00:00
|
|
|
|
2024-04-01 09:31:51 +01:00
|
|
|
// Configure config filename.
|
|
|
|
initConfigFilename(opts)
|
|
|
|
|
2024-07-10 13:18:46 +01:00
|
|
|
ls := getLogSettings(opts)
|
|
|
|
|
2023-05-10 14:30:03 +01:00
|
|
|
// Configure log level and output.
|
2024-07-10 13:18:46 +01:00
|
|
|
err = configureLogger(ls)
|
2023-05-10 14:30:03 +01:00
|
|
|
fatalOnError(err)
|
2020-11-20 14:32:41 +00:00
|
|
|
|
2024-07-10 13:18:46 +01:00
|
|
|
// TODO(a.garipov): Use slog everywhere.
|
|
|
|
slogLogger := newSlogLogger(ls)
|
|
|
|
|
2022-01-11 18:33:14 +00:00
|
|
|
// Print the first message after logger is configured.
|
2022-09-29 17:04:26 +01:00
|
|
|
log.Info(version.Full())
|
2022-01-11 18:33:14 +00:00
|
|
|
log.Debug("current working directory is %s", Context.workDir)
|
2022-10-05 15:07:08 +01:00
|
|
|
if opts.runningAsService {
|
2020-11-20 14:32:41 +00:00
|
|
|
log.Info("AdGuard Home is running as a service")
|
|
|
|
}
|
|
|
|
|
2023-05-10 14:30:03 +01:00
|
|
|
err = setupContext(opts)
|
|
|
|
fatalOnError(err)
|
2020-11-20 14:32:41 +00:00
|
|
|
|
2023-05-10 14:30:03 +01:00
|
|
|
err = configureOS(config)
|
2021-06-04 14:35:34 +01:00
|
|
|
fatalOnError(err)
|
|
|
|
|
2023-05-10 14:30:03 +01:00
|
|
|
// Clients package uses filtering package's static data
|
|
|
|
// (filtering.BlockedSvcKnown()), so we have to initialize filtering static
|
|
|
|
// data first, but also to avoid relying on automatic Go init() function.
|
2021-05-21 14:15:47 +01:00
|
|
|
filtering.InitModule()
|
2020-11-20 14:32:41 +00:00
|
|
|
|
2024-10-09 14:31:03 +01:00
|
|
|
// TODO(s.chzhen): Use it for the entire initialization process.
|
|
|
|
ctx := context.Background()
|
|
|
|
|
|
|
|
err = initContextClients(ctx, slogLogger)
|
2023-05-10 14:30:03 +01:00
|
|
|
fatalOnError(err)
|
|
|
|
|
|
|
|
err = setupOpts(opts)
|
2021-06-03 19:04:13 +01:00
|
|
|
fatalOnError(err)
|
2018-08-30 15:25:33 +01:00
|
|
|
|
2023-09-21 15:07:57 +01:00
|
|
|
execPath, err := os.Executable()
|
|
|
|
fatalOnError(errors.Annotate(err, "getting executable path: %w"))
|
|
|
|
|
2024-02-21 14:01:15 +00:00
|
|
|
confPath := configFilePath()
|
|
|
|
|
2024-11-26 17:35:16 +00:00
|
|
|
upd, customURL := newUpdater(ctx, slogLogger, Context.workDir, confPath, execPath, config)
|
2023-07-19 14:57:57 +01:00
|
|
|
|
2023-05-10 14:30:03 +01:00
|
|
|
// TODO(e.burkov): This could be made earlier, probably as the option's
|
2023-01-09 10:38:31 +00:00
|
|
|
// effect.
|
2024-11-26 17:35:16 +00:00
|
|
|
cmdlineUpdate(ctx, slogLogger, opts, upd)
|
2023-01-09 10:38:31 +00:00
|
|
|
|
2020-02-13 15:42:07 +00:00
|
|
|
if !Context.firstRun {
|
2023-05-10 14:30:03 +01:00
|
|
|
// Save the updated config.
|
2021-06-03 19:04:13 +01:00
|
|
|
err = config.write()
|
|
|
|
fatalOnError(err)
|
2020-04-22 14:00:26 +01:00
|
|
|
|
2023-08-02 15:39:33 +01:00
|
|
|
if config.HTTPConfig.Pprof.Enabled {
|
|
|
|
startPprof(config.HTTPConfig.Pprof.Port)
|
2020-04-22 14:00:26 +01:00
|
|
|
}
|
2020-02-18 16:27:09 +00:00
|
|
|
}
|
|
|
|
|
2024-10-02 19:00:15 +01:00
|
|
|
dataDir := Context.getDataDir()
|
2024-12-03 15:26:00 +00:00
|
|
|
err = os.MkdirAll(dataDir, aghos.DefaultPermDir)
|
2024-10-02 19:00:15 +01:00
|
|
|
fatalOnError(errors.Annotate(err, "creating DNS data dir at %s: %w", dataDir))
|
2018-08-30 15:25:33 +01:00
|
|
|
|
2022-10-05 15:07:08 +01:00
|
|
|
GLMode = opts.glinetMode
|
2021-05-21 12:55:42 +01:00
|
|
|
|
2023-05-10 14:30:03 +01:00
|
|
|
// Init auth module.
|
|
|
|
Context.auth, err = initUsers()
|
|
|
|
fatalOnError(err)
|
2020-02-19 12:24:55 +00:00
|
|
|
|
2023-12-12 10:16:01 +00:00
|
|
|
Context.tls, err = newTLSManager(config.TLS, config.DNS.ServePlainDNS)
|
2022-10-14 17:37:14 +01:00
|
|
|
if err != nil {
|
2022-11-25 12:41:54 +00:00
|
|
|
log.Error("initializing tls: %s", err)
|
|
|
|
onConfigModified()
|
2020-02-19 12:28:06 +00:00
|
|
|
}
|
|
|
|
|
2024-11-26 17:35:16 +00:00
|
|
|
Context.web, err = initWeb(ctx, opts, clientBuildFS, upd, slogLogger, customURL)
|
2021-06-03 19:04:13 +01:00
|
|
|
fatalOnError(err)
|
2020-02-18 16:27:09 +00:00
|
|
|
|
2024-10-02 19:00:15 +01:00
|
|
|
statsDir, querylogDir, err := checkStatsAndQuerylogDirs(&Context, config)
|
|
|
|
fatalOnError(err)
|
|
|
|
|
2020-02-18 16:27:09 +00:00
|
|
|
if !Context.firstRun {
|
2024-10-02 19:00:15 +01:00
|
|
|
err = initDNS(slogLogger, statsDir, querylogDir)
|
2021-06-03 19:04:13 +01:00
|
|
|
fatalOnError(err)
|
2021-03-12 11:32:08 +00:00
|
|
|
|
2022-10-14 17:37:14 +01:00
|
|
|
Context.tls.start()
|
2020-02-19 12:28:06 +00:00
|
|
|
|
2019-10-09 17:51:26 +01:00
|
|
|
go func() {
|
2023-07-18 15:02:07 +01:00
|
|
|
startErr := startDNSServer()
|
|
|
|
if startErr != nil {
|
2021-02-16 15:46:49 +00:00
|
|
|
closeDNSServer()
|
2023-07-18 15:02:07 +01:00
|
|
|
fatalOnError(startErr)
|
2019-10-09 17:51:26 +01:00
|
|
|
}
|
|
|
|
}()
|
2018-09-06 00:00:57 +01:00
|
|
|
|
2020-07-03 16:20:01 +01:00
|
|
|
if Context.dhcpServer != nil {
|
2021-04-21 12:42:19 +01:00
|
|
|
err = Context.dhcpServer.Start()
|
|
|
|
if err != nil {
|
|
|
|
log.Error("starting dhcp server: %s", err)
|
|
|
|
}
|
2019-02-01 16:25:04 +00:00
|
|
|
}
|
2018-12-28 18:01:16 +00:00
|
|
|
}
|
|
|
|
|
2024-11-22 14:03:09 +00:00
|
|
|
if !opts.noPermCheck {
|
2024-12-03 15:26:00 +00:00
|
|
|
checkPermissions(ctx, slogLogger, Context.workDir, confPath, dataDir, statsDir, querylogDir)
|
2024-10-02 19:00:15 +01:00
|
|
|
}
|
|
|
|
|
2023-04-11 15:22:51 +01:00
|
|
|
Context.web.start()
|
2020-02-18 16:27:09 +00:00
|
|
|
|
2023-08-28 14:40:46 +01:00
|
|
|
// Wait for other goroutines to complete their job.
|
|
|
|
<-done
|
2020-02-18 16:27:09 +00:00
|
|
|
}
|
|
|
|
|
2024-11-26 17:35:16 +00:00
|
|
|
// newUpdater creates a new AdGuard Home updater. customURL is true if the user
|
|
|
|
// has specified a custom version announcement URL.
|
|
|
|
func newUpdater(
|
|
|
|
ctx context.Context,
|
|
|
|
l *slog.Logger,
|
|
|
|
workDir string,
|
|
|
|
confPath string,
|
|
|
|
execPath string,
|
|
|
|
config *configuration,
|
|
|
|
) (upd *updater.Updater, customURL bool) {
|
|
|
|
// envName is the name of the environment variable that can be used to
|
|
|
|
// override the default version check URL.
|
|
|
|
const envName = "ADGUARD_HOME_TEST_UPDATE_VERSION_URL"
|
|
|
|
|
|
|
|
customURLStr := os.Getenv(envName)
|
|
|
|
|
|
|
|
var versionURL *url.URL
|
|
|
|
switch {
|
|
|
|
case version.Channel() == version.ChannelRelease:
|
|
|
|
// Only enable custom version URL for development builds.
|
|
|
|
l.DebugContext(ctx, "custom version url is disabled for release builds")
|
|
|
|
case !config.UnsafeUseCustomUpdateIndexURL:
|
|
|
|
l.DebugContext(ctx, "custom version url is disabled in config")
|
|
|
|
default:
|
|
|
|
versionURL, _ = url.Parse(customURLStr)
|
|
|
|
}
|
|
|
|
|
|
|
|
err := urlutil.ValidateHTTPURL(versionURL)
|
2024-11-27 14:16:45 +00:00
|
|
|
if customURL = err == nil; !customURL {
|
2024-11-26 17:35:16 +00:00
|
|
|
l.DebugContext(ctx, "parsing custom version url", slogutil.KeyError, err)
|
|
|
|
|
|
|
|
versionURL = updater.DefaultVersionURL()
|
|
|
|
}
|
|
|
|
|
|
|
|
l.DebugContext(ctx, "creating updater", "config_path", confPath)
|
|
|
|
|
|
|
|
return updater.NewUpdater(&updater.Config{
|
|
|
|
Client: config.Filtering.HTTPClient,
|
|
|
|
Version: version.Version(),
|
|
|
|
Channel: version.Channel(),
|
|
|
|
GOARCH: runtime.GOARCH,
|
|
|
|
GOOS: runtime.GOOS,
|
|
|
|
GOARM: version.GOARM(),
|
|
|
|
GOMIPS: version.GOMIPS(),
|
|
|
|
WorkDir: workDir,
|
|
|
|
ConfName: confPath,
|
|
|
|
ExecPath: execPath,
|
|
|
|
VersionCheckURL: versionURL,
|
|
|
|
}), customURL
|
|
|
|
}
|
|
|
|
|
2024-11-22 14:03:09 +00:00
|
|
|
// checkPermissions checks and migrates permissions of the files and directories
|
|
|
|
// used by AdGuard Home, if needed.
|
2024-12-03 15:26:00 +00:00
|
|
|
func checkPermissions(
|
|
|
|
ctx context.Context,
|
|
|
|
baseLogger *slog.Logger,
|
|
|
|
workDir string,
|
|
|
|
confPath string,
|
|
|
|
dataDir string,
|
|
|
|
statsDir string,
|
|
|
|
querylogDir string,
|
|
|
|
) {
|
|
|
|
l := baseLogger.With(slogutil.KeyPrefix, "permcheck")
|
|
|
|
|
|
|
|
if permcheck.NeedsMigration(ctx, l, workDir, confPath) {
|
|
|
|
permcheck.Migrate(ctx, l, workDir, dataDir, statsDir, querylogDir, confPath)
|
2024-11-22 14:03:09 +00:00
|
|
|
}
|
|
|
|
|
2024-12-03 15:26:00 +00:00
|
|
|
permcheck.Check(ctx, l, workDir, dataDir, statsDir, querylogDir, confPath)
|
2024-11-22 14:03:09 +00:00
|
|
|
}
|
|
|
|
|
2023-05-10 14:30:03 +01:00
|
|
|
// initUsers initializes context auth module. Clears config users field.
|
|
|
|
func initUsers() (auth *Auth, err error) {
|
|
|
|
sessFilename := filepath.Join(Context.getDataDir(), "sessions.db")
|
|
|
|
|
|
|
|
var rateLimiter *authRateLimiter
|
|
|
|
if config.AuthAttempts > 0 && config.AuthBlockMin > 0 {
|
|
|
|
blockDur := time.Duration(config.AuthBlockMin) * time.Minute
|
|
|
|
rateLimiter = newAuthRateLimiter(blockDur, config.AuthAttempts)
|
|
|
|
} else {
|
|
|
|
log.Info("authratelimiter is disabled")
|
|
|
|
}
|
|
|
|
|
2024-03-20 16:25:59 +00:00
|
|
|
trustedProxies := netutil.SliceSubnetSet(netutil.UnembedPrefixes(config.DNS.TrustedProxies))
|
|
|
|
|
2023-06-29 13:29:52 +01:00
|
|
|
sessionTTL := config.HTTPConfig.SessionTTL.Seconds()
|
2024-03-20 16:25:59 +00:00
|
|
|
auth = InitAuth(sessFilename, config.Users, uint32(sessionTTL), rateLimiter, trustedProxies)
|
2023-05-10 14:30:03 +01:00
|
|
|
if auth == nil {
|
|
|
|
return nil, errors.Error("initializing auth module failed")
|
|
|
|
}
|
|
|
|
|
|
|
|
config.Users = nil
|
|
|
|
|
|
|
|
return auth, nil
|
|
|
|
}
|
|
|
|
|
2023-01-09 10:38:31 +00:00
|
|
|
func (c *configuration) anonymizer() (ipmut *aghnet.IPMut) {
|
|
|
|
var anonFunc aghnet.IPMutFunc
|
|
|
|
if c.DNS.AnonymizeClientIP {
|
|
|
|
anonFunc = querylog.AnonymizeIP
|
|
|
|
}
|
|
|
|
|
|
|
|
return aghnet.NewIPMut(anonFunc)
|
|
|
|
}
|
|
|
|
|
2024-07-10 13:18:46 +01:00
|
|
|
// startMods initializes and starts the DNS server after installation. l must
|
|
|
|
// not be nil.
|
|
|
|
func startMods(l *slog.Logger) (err error) {
|
2024-10-02 19:00:15 +01:00
|
|
|
statsDir, querylogDir, err := checkStatsAndQuerylogDirs(&Context, config)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
err = initDNS(l, statsDir, querylogDir)
|
2020-02-19 12:28:06 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2022-10-14 17:37:14 +01:00
|
|
|
Context.tls.start()
|
2020-02-19 12:28:06 +00:00
|
|
|
|
|
|
|
err = startDNSServer()
|
|
|
|
if err != nil {
|
|
|
|
closeDNSServer()
|
2022-10-14 17:37:14 +01:00
|
|
|
|
2020-02-19 12:28:06 +00:00
|
|
|
return err
|
|
|
|
}
|
2022-10-14 17:37:14 +01:00
|
|
|
|
2020-02-19 12:28:06 +00:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2024-11-22 14:03:09 +00:00
|
|
|
// checkNetworkPermissions checks if the current user permissions are enough to
|
|
|
|
// use the required networking functionality.
|
|
|
|
func checkNetworkPermissions() {
|
2020-06-23 16:02:28 +01:00
|
|
|
log.Info("Checking if AdGuard Home has necessary permissions")
|
2019-04-01 10:22:54 +01:00
|
|
|
|
2022-03-31 17:56:50 +01:00
|
|
|
if ok, err := aghnet.CanBindPrivilegedPorts(); !ok || err != nil {
|
2019-04-01 10:22:54 +01:00
|
|
|
log.Fatal("This is the first launch of AdGuard Home. You must run it as Administrator.")
|
2020-06-23 16:02:28 +01:00
|
|
|
}
|
2019-04-01 10:22:54 +01:00
|
|
|
|
2020-06-23 16:02:28 +01:00
|
|
|
// We should check if AdGuard Home is able to bind to port 53
|
2022-11-09 11:37:07 +00:00
|
|
|
err := aghnet.CheckPort("tcp", netip.AddrPortFrom(netutil.IPv4Localhost(), defaultPortDNS))
|
2022-03-31 17:56:50 +01:00
|
|
|
if err != nil {
|
|
|
|
if errors.Is(err, os.ErrPermission) {
|
|
|
|
log.Fatal(`Permission check failed.
|
2020-06-23 16:02:28 +01:00
|
|
|
|
|
|
|
AdGuard Home is not allowed to bind to privileged ports (for instance, port 53).
|
|
|
|
Please note, that this is crucial for a server to be able to use privileged ports.
|
|
|
|
|
|
|
|
You have two options:
|
|
|
|
1. Run AdGuard Home with root privileges
|
|
|
|
2. On Linux you can grant the CAP_NET_BIND_SERVICE capability:
|
2022-03-31 17:56:50 +01:00
|
|
|
https://github.com/AdguardTeam/AdGuardHome/wiki/Getting-Started#running-without-superuser`)
|
|
|
|
}
|
2020-06-23 16:02:28 +01:00
|
|
|
|
2022-03-31 17:56:50 +01:00
|
|
|
log.Info(
|
|
|
|
"AdGuard failed to bind to port 53: %s\n\n"+
|
|
|
|
"Please note, that this is crucial for a DNS server to be able to use that port.",
|
|
|
|
err,
|
|
|
|
)
|
2019-04-01 10:22:54 +01:00
|
|
|
}
|
2020-06-23 16:02:28 +01:00
|
|
|
|
2022-03-31 17:56:50 +01:00
|
|
|
log.Info("AdGuard Home can bind to port 53")
|
2019-04-01 10:22:54 +01:00
|
|
|
}
|
|
|
|
|
2019-04-05 10:19:28 +01:00
|
|
|
// Write PID to a file
|
|
|
|
func writePIDFile(fn string) bool {
|
|
|
|
data := fmt.Sprintf("%d", os.Getpid())
|
2021-05-21 12:55:42 +01:00
|
|
|
err := os.WriteFile(fn, []byte(data), 0o644)
|
2019-04-05 10:19:28 +01:00
|
|
|
if err != nil {
|
|
|
|
log.Error("Couldn't write PID to file %s: %v", fn, err)
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
|
2023-05-10 14:30:03 +01:00
|
|
|
// initConfigFilename sets up context config file path. This file path can be
|
2024-04-01 09:31:51 +01:00
|
|
|
// overridden by command-line arguments, or is set to default. Must only be
|
|
|
|
// called after initializing the workDir with initWorkingDir.
|
2022-10-05 15:07:08 +01:00
|
|
|
func initConfigFilename(opts options) {
|
2024-02-21 14:01:15 +00:00
|
|
|
confPath := opts.confFilename
|
|
|
|
if confPath == "" {
|
2024-04-01 09:31:51 +01:00
|
|
|
Context.confFilePath = filepath.Join(Context.workDir, "AdGuardHome.yaml")
|
2024-02-21 14:01:15 +00:00
|
|
|
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
log.Debug("config path overridden to %q from cmdline", confPath)
|
|
|
|
|
|
|
|
Context.confFilePath = confPath
|
2020-09-28 08:57:56 +01:00
|
|
|
}
|
|
|
|
|
2023-05-10 14:30:03 +01:00
|
|
|
// initWorkingDir initializes the workDir. If no command-line arguments are
|
|
|
|
// specified, the directory with the binary file is used.
|
|
|
|
func initWorkingDir(opts options) (err error) {
|
2020-02-11 09:59:21 +00:00
|
|
|
execPath, err := os.Executable()
|
2019-02-05 11:09:05 +00:00
|
|
|
if err != nil {
|
2023-05-10 14:30:03 +01:00
|
|
|
// Don't wrap the error, because it's informative enough as is.
|
|
|
|
return err
|
2019-02-05 11:09:05 +00:00
|
|
|
}
|
|
|
|
|
2022-10-05 15:07:08 +01:00
|
|
|
if opts.workDir != "" {
|
2019-02-05 17:35:48 +00:00
|
|
|
// If there is a custom config file, use it's directory as our working dir
|
2022-10-05 15:07:08 +01:00
|
|
|
Context.workDir = opts.workDir
|
2019-02-05 11:09:05 +00:00
|
|
|
} else {
|
2020-02-13 15:42:07 +00:00
|
|
|
Context.workDir = filepath.Dir(execPath)
|
2019-02-05 11:09:05 +00:00
|
|
|
}
|
2021-01-27 15:32:13 +00:00
|
|
|
|
2021-03-12 11:32:08 +00:00
|
|
|
workDir, err := filepath.EvalSymlinks(Context.workDir)
|
|
|
|
if err != nil {
|
2023-05-10 14:30:03 +01:00
|
|
|
// Don't wrap the error, because it's informative enough as is.
|
|
|
|
return err
|
2021-01-27 15:32:13 +00:00
|
|
|
}
|
2021-03-12 11:32:08 +00:00
|
|
|
|
|
|
|
Context.workDir = workDir
|
2023-05-10 14:30:03 +01:00
|
|
|
|
|
|
|
return nil
|
2019-02-04 10:54:53 +00:00
|
|
|
}
|
|
|
|
|
2021-01-26 16:44:19 +00:00
|
|
|
// cleanup stops and resets all the modules.
|
|
|
|
func cleanup(ctx context.Context) {
|
2021-06-16 14:48:46 +01:00
|
|
|
log.Info("stopping AdGuard Home")
|
2019-02-04 10:54:53 +00:00
|
|
|
|
2020-02-19 12:24:55 +00:00
|
|
|
if Context.web != nil {
|
2023-04-11 15:22:51 +01:00
|
|
|
Context.web.close(ctx)
|
2020-02-19 12:24:55 +00:00
|
|
|
Context.web = nil
|
|
|
|
}
|
|
|
|
if Context.auth != nil {
|
|
|
|
Context.auth.Close()
|
|
|
|
Context.auth = nil
|
|
|
|
}
|
2020-02-18 16:27:09 +00:00
|
|
|
|
2018-12-05 12:36:18 +00:00
|
|
|
err := stopDNSServer()
|
|
|
|
if err != nil {
|
2021-06-16 14:48:46 +01:00
|
|
|
log.Error("stopping dns server: %s", err)
|
2018-12-05 12:36:18 +00:00
|
|
|
}
|
2020-07-03 16:20:01 +01:00
|
|
|
|
|
|
|
if Context.dhcpServer != nil {
|
2021-06-16 14:48:46 +01:00
|
|
|
err = Context.dhcpServer.Stop()
|
|
|
|
if err != nil {
|
|
|
|
log.Error("stopping dhcp server: %s", err)
|
|
|
|
}
|
2019-02-04 10:54:53 +00:00
|
|
|
}
|
2020-02-19 12:28:06 +00:00
|
|
|
|
2021-10-14 17:39:21 +01:00
|
|
|
if Context.etcHosts != nil {
|
|
|
|
if err = Context.etcHosts.Close(); err != nil {
|
2021-11-17 14:21:10 +00:00
|
|
|
log.Error("closing hosts container: %s", err)
|
2021-10-14 17:39:21 +01:00
|
|
|
}
|
|
|
|
}
|
2020-03-20 12:05:43 +00:00
|
|
|
|
2020-02-19 12:28:06 +00:00
|
|
|
if Context.tls != nil {
|
|
|
|
Context.tls = nil
|
|
|
|
}
|
2018-12-05 12:36:18 +00:00
|
|
|
}
|
|
|
|
|
2019-04-05 10:19:28 +01:00
|
|
|
// This function is called before application exits
|
|
|
|
func cleanupAlways() {
|
2020-02-13 15:42:07 +00:00
|
|
|
if len(Context.pidFileName) != 0 {
|
|
|
|
_ = os.Remove(Context.pidFileName)
|
2019-04-05 10:19:28 +01:00
|
|
|
}
|
2022-10-14 17:37:14 +01:00
|
|
|
|
|
|
|
log.Info("stopped")
|
2019-04-05 10:19:28 +01:00
|
|
|
}
|
|
|
|
|
2020-09-07 09:10:56 +01:00
|
|
|
func exitWithError() {
|
|
|
|
os.Exit(64)
|
2019-02-04 10:54:53 +00:00
|
|
|
}
|
|
|
|
|
2022-10-05 15:07:08 +01:00
|
|
|
// loadCmdLineOpts reads command line arguments and initializes configuration
|
|
|
|
// from them. If there is an error or an effect, loadCmdLineOpts processes them
|
|
|
|
// and exits.
|
|
|
|
func loadCmdLineOpts() (opts options) {
|
|
|
|
opts, eff, err := parseCmdOpts(os.Args[0], os.Args[1:])
|
2020-09-07 09:10:56 +01:00
|
|
|
if err != nil {
|
|
|
|
log.Error(err.Error())
|
2022-10-05 15:07:08 +01:00
|
|
|
printHelp(os.Args[0])
|
|
|
|
|
2020-09-07 09:10:56 +01:00
|
|
|
exitWithError()
|
2022-10-05 15:07:08 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
if eff != nil {
|
|
|
|
err = eff()
|
2020-09-07 09:10:56 +01:00
|
|
|
if err != nil {
|
|
|
|
log.Error(err.Error())
|
|
|
|
exitWithError()
|
2019-01-24 17:11:01 +00:00
|
|
|
}
|
2022-10-05 15:07:08 +01:00
|
|
|
|
|
|
|
os.Exit(0)
|
2019-01-24 17:11:01 +00:00
|
|
|
}
|
|
|
|
|
2022-10-05 15:07:08 +01:00
|
|
|
return opts
|
2019-01-24 17:11:01 +00:00
|
|
|
}
|
2019-02-22 14:59:42 +00:00
|
|
|
|
2021-06-01 19:06:55 +01:00
|
|
|
// printWebAddrs prints addresses built from proto, addr, and an appropriate
|
2023-01-23 09:47:59 +00:00
|
|
|
// port. At least one address is printed with the value of port. Output
|
|
|
|
// example:
|
2021-06-01 19:06:55 +01:00
|
|
|
//
|
2023-01-23 09:47:59 +00:00
|
|
|
// go to http://127.0.0.1:80
|
2023-10-05 13:26:19 +01:00
|
|
|
func printWebAddrs(proto, addr string, port uint16) {
|
2023-01-23 09:47:59 +00:00
|
|
|
log.Printf("go to %s://%s", proto, netutil.JoinHostPort(addr, port))
|
2021-06-01 19:06:55 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
// printHTTPAddresses prints the IP addresses which user can use to access the
|
2021-03-15 11:19:04 +00:00
|
|
|
// admin interface. proto is either schemeHTTP or schemeHTTPS.
|
2019-02-22 14:59:42 +00:00
|
|
|
func printHTTPAddresses(proto string) {
|
2020-02-19 12:28:06 +00:00
|
|
|
tlsConf := tlsConfigSettings{}
|
2020-04-07 17:24:29 +01:00
|
|
|
if Context.tls != nil {
|
|
|
|
Context.tls.WriteDiskConfig(&tlsConf)
|
|
|
|
}
|
2020-05-16 00:02:50 +01:00
|
|
|
|
2023-10-05 13:26:19 +01:00
|
|
|
port := config.HTTPConfig.Address.Port()
|
2024-11-05 09:25:39 +00:00
|
|
|
if proto == urlutil.SchemeHTTPS {
|
2021-06-01 19:06:55 +01:00
|
|
|
port = tlsConf.PortHTTPS
|
2020-05-16 00:02:50 +01:00
|
|
|
}
|
|
|
|
|
2021-12-16 17:54:59 +00:00
|
|
|
// TODO(e.burkov): Inspect and perhaps merge with the previous condition.
|
2024-11-05 09:25:39 +00:00
|
|
|
if proto == urlutil.SchemeHTTPS && tlsConf.ServerName != "" {
|
2023-01-23 09:47:59 +00:00
|
|
|
printWebAddrs(proto, tlsConf.ServerName, tlsConf.PortHTTPS)
|
2019-02-22 14:59:42 +00:00
|
|
|
|
2021-06-01 19:06:55 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2023-06-29 13:29:52 +01:00
|
|
|
bindHost := config.HTTPConfig.Address.Addr()
|
|
|
|
if !bindHost.IsUnspecified() {
|
|
|
|
printWebAddrs(proto, bindHost.String(), port)
|
2021-06-01 19:06:55 +01:00
|
|
|
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
ifaces, err := aghnet.GetValidNetInterfacesForWeb()
|
|
|
|
if err != nil {
|
|
|
|
log.Error("web: getting iface ips: %s", err)
|
|
|
|
// That's weird, but we'll ignore it.
|
|
|
|
//
|
|
|
|
// TODO(e.burkov): Find out when it happens.
|
2023-06-29 13:29:52 +01:00
|
|
|
printWebAddrs(proto, bindHost.String(), port)
|
2021-06-01 19:06:55 +01:00
|
|
|
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
for _, iface := range ifaces {
|
|
|
|
for _, addr := range iface.Addresses {
|
2023-06-29 13:29:52 +01:00
|
|
|
printWebAddrs(proto, addr.String(), port)
|
2020-12-29 16:53:56 +00:00
|
|
|
}
|
2019-02-22 14:59:42 +00:00
|
|
|
}
|
|
|
|
}
|
2020-02-13 15:42:07 +00:00
|
|
|
|
2024-02-21 14:01:15 +00:00
|
|
|
// detectFirstRun returns true if this is the first run of AdGuard Home.
|
|
|
|
func detectFirstRun() (ok bool) {
|
|
|
|
confPath := Context.confFilePath
|
|
|
|
if !filepath.IsAbs(confPath) {
|
|
|
|
confPath = filepath.Join(Context.workDir, Context.confFilePath)
|
2020-02-13 15:42:07 +00:00
|
|
|
}
|
2024-02-21 14:01:15 +00:00
|
|
|
|
|
|
|
_, err := os.Stat(confPath)
|
|
|
|
if err == nil {
|
|
|
|
return false
|
|
|
|
} else if errors.Is(err, os.ErrNotExist) {
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
|
|
|
|
log.Error("detecting first run: %s; considering first run", err)
|
|
|
|
|
|
|
|
return true
|
2020-02-13 15:42:07 +00:00
|
|
|
}
|
|
|
|
|
2020-11-25 15:09:41 +00:00
|
|
|
// jsonError is a generic JSON error response.
|
|
|
|
//
|
2023-01-09 10:38:31 +00:00
|
|
|
// TODO(a.garipov): Merge together with the implementations in [dhcpd] and other
|
|
|
|
// packages after refactoring the web handler registering.
|
2020-11-25 15:09:41 +00:00
|
|
|
type jsonError struct {
|
|
|
|
// Message is the error message, an opaque string.
|
|
|
|
Message string `json:"message"`
|
|
|
|
}
|
2022-11-15 14:44:50 +00:00
|
|
|
|
2024-07-10 13:18:46 +01:00
|
|
|
// cmdlineUpdate updates current application and exits. l must not be nil.
|
2024-11-26 17:35:16 +00:00
|
|
|
func cmdlineUpdate(ctx context.Context, l *slog.Logger, opts options, upd *updater.Updater) {
|
2022-11-15 14:44:50 +00:00
|
|
|
if !opts.performUpdate {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2023-01-09 10:38:31 +00:00
|
|
|
// Initialize the DNS server to use the internal resolver which the updater
|
|
|
|
// needs to be able to resolve the update source hostname.
|
|
|
|
//
|
|
|
|
// TODO(e.burkov): We could probably initialize the internal resolver
|
|
|
|
// separately.
|
2024-07-10 13:18:46 +01:00
|
|
|
err := initDNSServer(nil, nil, nil, nil, nil, nil, &tlsConfigSettings{}, l)
|
2023-01-09 10:38:31 +00:00
|
|
|
fatalOnError(err)
|
2022-11-15 14:44:50 +00:00
|
|
|
|
2024-11-26 17:35:16 +00:00
|
|
|
l.InfoContext(ctx, "performing update via cli")
|
2022-11-15 14:44:50 +00:00
|
|
|
|
2023-07-19 14:57:57 +01:00
|
|
|
info, err := upd.VersionInfo(true)
|
2022-11-15 14:44:50 +00:00
|
|
|
if err != nil {
|
2024-11-26 17:35:16 +00:00
|
|
|
l.ErrorContext(ctx, "getting version info", slogutil.KeyError, err)
|
2022-11-15 14:44:50 +00:00
|
|
|
|
2024-11-26 17:35:16 +00:00
|
|
|
os.Exit(osutil.ExitCodeFailure)
|
2022-11-15 14:44:50 +00:00
|
|
|
}
|
|
|
|
|
2023-01-09 10:38:31 +00:00
|
|
|
if info.NewVersion == version.Version() {
|
2024-11-26 17:35:16 +00:00
|
|
|
l.InfoContext(ctx, "no updates available")
|
2022-11-15 14:44:50 +00:00
|
|
|
|
2024-11-26 17:35:16 +00:00
|
|
|
os.Exit(osutil.ExitCodeSuccess)
|
2022-11-15 14:44:50 +00:00
|
|
|
}
|
|
|
|
|
2023-07-19 14:57:57 +01:00
|
|
|
err = upd.Update(Context.firstRun)
|
2022-11-15 14:44:50 +00:00
|
|
|
fatalOnError(err)
|
|
|
|
|
2023-01-09 10:38:31 +00:00
|
|
|
err = restartService()
|
|
|
|
if err != nil {
|
2024-11-26 17:35:16 +00:00
|
|
|
l.DebugContext(ctx, "restarting service", slogutil.KeyError, err)
|
|
|
|
l.InfoContext(ctx, "AdGuard Home was not installed as a service. "+
|
2023-01-09 10:38:31 +00:00
|
|
|
"Please restart running instances of AdGuardHome manually.")
|
|
|
|
}
|
|
|
|
|
2024-11-26 17:35:16 +00:00
|
|
|
os.Exit(osutil.ExitCodeSuccess)
|
2022-11-15 14:44:50 +00:00
|
|
|
}
|