engine.c 25.5 KB
Newer Older
1
/*  Copyright (C) 2015-2017 CZ.NIC, z.s.p.o. <knot-dns@labs.nic.cz>
2 3 4 5 6 7 8 9 10 11 12 13

    This program is free software: you can redistribute it and/or modify
    it under the terms of the GNU General Public License as published by
    the Free Software Foundation, either version 3 of the License, or
    (at your option) any later version.

    This program is distributed in the hope that it will be useful,
    but WITHOUT ANY WARRANTY; without even the implied warranty of
    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
    GNU General Public License for more details.

    You should have received a copy of the GNU General Public License
14
    along with this program.  If not, see <https://www.gnu.org/licenses/>.
15 16
 */

17
#include <contrib/cleanup.h>
18
#include <ccan/json/json.h>
19
#include <ccan/asprintf/asprintf.h>
20 21
#include <uv.h>
#include <unistd.h>
22 23
#include <grp.h>
#include <pwd.h>
24
#include <sys/param.h>
Vladimír Čunát's avatar
Vladimír Čunát committed
25
#include <libzscanner/scanner.h>
26

27 28 29
#include <lua.h>
#include <lualib.h>
#include <lauxlib.h>
30
#include "daemon/bindings/impl.h"
31

32
#include "daemon/engine.h"
33
#include "daemon/ffimodule.h"
34
#include "lib/nsrep.h"
35
#include "lib/cache/api.h"
36
#include "lib/defines.h"
37
#include "lib/cache/cdb_lmdb.h"
38
#include "lib/dnssec/ta.h"
39

40 41 42 43 44 45 46 47 48 49 50 51 52 53 54
/* Magic defaults for the engine. */
#ifndef LRU_RTT_SIZE
#define LRU_RTT_SIZE 65536 /**< NS RTT cache size */
#endif
#ifndef LRU_REP_SIZE
#define LRU_REP_SIZE (LRU_RTT_SIZE / 4) /**< NS reputation cache size */
#endif
#ifndef LRU_COOKIES_SIZE
	#ifdef ENABLE_COOKIES
	#define LRU_COOKIES_SIZE LRU_RTT_SIZE /**< DNS cookies cache size. */
	#else
	#define LRU_COOKIES_SIZE LRU_ASSOC /* simpler than guards everywhere */
	#endif
#endif

55 56 57 58 59
/** @internal Compatibility wrapper for Lua < 5.2 */
#if LUA_VERSION_NUM < 502
#define lua_rawlen(L, obj) lua_objlen((L), (obj))
#endif

60 61 62 63 64 65
/**@internal Maximum number of incomplete TCP connections in queue.
* Default is from Redis and Apache. */
#ifndef TCP_BACKLOG_DEFAULT
#define TCP_BACKLOG_DEFAULT 511
#endif

66 67 68
/* Cleanup engine state every 5 minutes */
const size_t CLEANUP_TIMER = 5*60*1000;

69 70 71 72 73 74 75
/* Execute byte code */
#define l_dobytecode(L, arr, len, name) \
	(luaL_loadbuffer((L), (arr), (len), (name)) || lua_pcall((L), 0, LUA_MULTRET, 0))
/** Load file in a sandbox environment. */
#define l_dosandboxfile(L, filename) \
	(luaL_loadfile((L), (filename)) || engine_pcall((L), 0))

76 77 78 79
/*
 * Global bindings.
 */

80
/** Register module callback into Lua world. */
81
#define REGISTER_MODULE_CALL(L, module, cb, name) do { \
82 83 84
	lua_pushlightuserdata((L), (module)); \
	lua_pushlightuserdata((L), (cb)); \
	lua_pushcclosure((L), l_trampoline, 2); \
85 86
	lua_setfield((L), -2, (name)); \
	} while (0)
87

88 89 90
/** Print help and available commands. */
static int l_help(lua_State *L)
{
91
	static const char *help_str =
92 93
		"help()\n    show this help\n"
		"quit()\n    quit\n"
94
		"hostname()\n    hostname\n"
95
		"package_version()\n    return package version\n"
96
		"user(name[, group])\n    change process user (and group)\n"
97
		"verbose(true|false)\n    toggle verbose mode\n"
98
		"option(opt[, new_val])\n    get/set server option\n"
99
		"mode(strict|normal|permissive)\n    set resolver strictness level\n"
100
		"reorder_RR([true|false])\n    set/get reordering of RRs within RRsets\n"
101 102
		"resolve(name, type[, class, flags, callback])\n    resolve query, callback when it's finished\n"
		"todname(name)\n    convert name to wire format\n"
103
		"tojson(val)\n    convert value to JSON\n"
104
		"map(expr)\n    run expression on all workers\n"
105 106 107 108
		"net\n    network configuration\n"
		"cache\n    network configuration\n"
		"modules\n    modules configuration\n"
		"kres\n    resolver services\n"
109
		"trust_anchors\n    configure trust anchors\n"
110
		;
111 112
	lua_pushstring(L, help_str);
	return 1;
113 114
}

115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133
static bool update_privileges(int uid, int gid)
{
	if ((gid_t)gid != getgid()) {
		if (setregid(gid, gid) < 0) {
			return false;
		}
	}
	if ((uid_t)uid != getuid()) {
		if (setreuid(uid, uid) < 0) {
			return false;
		}
	}
	return true;
}

/** Set process user/group. */
static int l_setuser(lua_State *L)
{
	int n = lua_gettop(L);
134 135 136
	if (n < 1 || !lua_isstring(L, 1))
		lua_error_p(L, "user(user[, group])");

137 138
	/* Fetch UID/GID based on string identifiers. */
	struct passwd *user_pw = getpwnam(lua_tostring(L, 1));
139 140
	if (!user_pw)
		lua_error_p(L, "invalid user name");
141 142 143 144
	int uid = user_pw->pw_uid;
	int gid = getgid();
	if (n > 1 && lua_isstring(L, 2)) {
		struct group *group_pw = getgrnam(lua_tostring(L, 2));
145 146
		if (!group_pw)
			lua_error_p(L, "invalid group name");
147 148 149 150 151
		gid = group_pw->gr_gid;
	}
	/* Drop privileges */
	bool ret = update_privileges(uid, gid);
	if (!ret) {
152
		lua_error_maybe(L, errno);
153 154 155 156 157
	}
	lua_pushboolean(L, ret);
	return 1;
}

158 159 160 161 162 163 164
/** Quit current executable. */
static int l_quit(lua_State *L)
{
	engine_stop(engine_luaget(L));
	return 0;
}

165 166 167 168
/** Toggle verbose mode. */
static int l_verbose(lua_State *L)
{
	if (lua_isboolean(L, 1) || lua_isnumber(L, 1)) {
169
		kr_verbose_set(lua_toboolean(L, 1));
170
	}
171
	lua_pushboolean(L, kr_verbose_status);
172 173 174
	return 1;
}

175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201
char *engine_get_hostname(struct engine *engine) {
	static char hostname_str[KNOT_DNAME_MAXLEN];
	if (!engine) {
		return NULL;
	}

	if (!engine->hostname) {
		if (gethostname(hostname_str, sizeof(hostname_str)) != 0)
			return NULL;
		return hostname_str;
	}
	return engine->hostname;
}

int engine_set_hostname(struct engine *engine, const char *hostname) {
	if (!engine || !hostname) {
		return kr_error(EINVAL);
	}

	char *new_hostname = strdup(hostname);
	if (!new_hostname) {
		return kr_error(ENOMEM);
	}
	if (engine->hostname) {
		free(engine->hostname);
	}
	engine->hostname = new_hostname;
202
	network_new_hostname(&engine->net, engine);
203 204 205 206

	return 0;
}

207 208 209
/** Return hostname. */
static int l_hostname(lua_State *L)
{
210 211 212 213 214
	struct engine *engine = engine_luaget(L);
	if (lua_gettop(L) == 0) {
		lua_pushstring(L, engine_get_hostname(engine));
		return 1;
	}
215 216
	if ((lua_gettop(L) != 1) || !lua_isstring(L, 1))
		lua_error_p(L, "hostname takes at most one parameter: (\"fqdn\")");
217

218 219
	if (engine_set_hostname(engine, lua_tostring(L, 1)) != 0)
		lua_error_p(L, "setting hostname failed");
220

221
	lua_pushstring(L, engine_get_hostname(engine));
222 223 224
	return 1;
}

225 226 227 228 229 230 231
/** Return server package version. */
static int l_package_version(lua_State *L)
{
	lua_pushliteral(L, PACKAGE_VERSION);
	return 1;
}

232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251
char *engine_get_moduledir(struct engine *engine) {
	return engine->moduledir;
}

int engine_set_moduledir(struct engine *engine, const char *moduledir) {
	if (!engine || !moduledir) {
		return kr_error(EINVAL);
	}

	char *new_moduledir = strdup(moduledir);
	if (!new_moduledir) {
		return kr_error(ENOMEM);
	}
	if (engine->moduledir) {
		free(engine->moduledir);
	}
	engine->moduledir = new_moduledir;

	/* Use module path for including Lua scripts */
	char l_paths[MAXPATHLEN] = { 0 };
252 253
	#pragma GCC diagnostic push
	#pragma GCC diagnostic ignored "-Wformat" /* %1$ is not in C standard */
254 255 256
	/* Save original package.path to package._path */
	snprintf(l_paths, MAXPATHLEN - 1,
		 "if package._path == nil then package._path = package.path end\n"
257 258
		 "package.path = '%1$s/?.lua;%1$s/?/init.lua;'..package._path\n"
		 "if package._cpath == nil then package._cpath = package.cpath end\n"
259 260
		 "package.cpath = '%1$s/?%2$s;'..package._cpath\n",
		 new_moduledir, LIBEXT);
261
	#pragma GCC diagnostic pop
262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278

	int ret = l_dobytecode(engine->L, l_paths, strlen(l_paths), "");
	if (ret != 0) {
		lua_pop(engine->L, 1);
		return ret;
	}
	return 0;
}

/** Return hostname. */
static int l_moduledir(lua_State *L)
{
	struct engine *engine = engine_luaget(L);
	if (lua_gettop(L) == 0) {
		lua_pushstring(L, engine_get_moduledir(engine));
		return 1;
	}
279 280
	if ((lua_gettop(L) != 1) || !lua_isstring(L, 1))
		lua_error_p(L, "moduledir takes at most one parameter: (\"directory\")");
281

282 283
	if (engine_set_moduledir(engine, lua_tostring(L, 1)) != 0)
		lua_error_p(L, "setting moduledir failed");
284 285 286 287 288

	lua_pushstring(L, engine_get_moduledir(engine));
	return 1;
}

289
/** Load root hints from zonefile. */
290
static int l_hint_root_file(lua_State *L)
291 292 293 294 295
{
	struct engine *engine = engine_luaget(L);
	struct kr_context *ctx = &engine->resolver;
	const char *file = lua_tostring(L, 1);

296
	const char *err = engine_hint_root_file(ctx, file);
297
	if (err) {
298 299 300
		if (!file) {
			file = ROOTHINTS;
		}
301
		lua_error_p(L, "error when opening '%s': %s", file, err);
302 303 304
	} else {
		lua_pushboolean(L, true);
		return 1;
305
	}
306 307
}

308 309 310 311 312 313 314 315
/** @internal for engine_hint_root_file */
static void roothints_add(zs_scanner_t *zs)
{
	struct kr_zonecut *hints = zs->process.data;
	if (!hints) {
		return;
	}
	if (zs->r_type == KNOT_RRTYPE_A || zs->r_type == KNOT_RRTYPE_AAAA) {
316
		kr_zonecut_add(hints, zs->r_owner, zs->r_data, zs->r_data_length);
317 318 319
	}
}
const char* engine_hint_root_file(struct kr_context *ctx, const char *file)
320 321 322 323 324 325 326 327 328 329 330 331
{
	if (!file) {
		file = ROOTHINTS;
	}
	if (strlen(file) == 0 || !ctx) {
		return "invalid parameters";
	}
	struct kr_zonecut *root_hints = &ctx->root_hints;

	zs_scanner_t zs;
	if (zs_init(&zs, ".", 1, 0) != 0) {
		return "not enough memory";
332
	}
333
	if (zs_set_input_file(&zs, file) != 0) {
334
		zs_deinit(&zs);
335 336 337
		return "failed to open root hints file";
	}

338
	kr_zonecut_set(root_hints, (const uint8_t *)"");
339 340
	zs_set_processing(&zs, roothints_add, NULL, root_hints);
	zs_parse_all(&zs);
341
	zs_deinit(&zs);
342
	return NULL;
343
}
344

345 346 347
/** Unpack JSON object to table */
static void l_unpack_json(lua_State *L, JsonNode *table)
{
348 349 350 351 352 353 354 355
	/* Unpack POD */
	switch(table->tag) {
		case JSON_STRING: lua_pushstring(L, table->string_); return;
		case JSON_NUMBER: lua_pushnumber(L, table->number_); return;
		case JSON_BOOL:   lua_pushboolean(L, table->bool_); return;
		default: break;
	}
	/* Unpack object or array into table */
356 357 358 359 360 361 362 363 364
	lua_newtable(L);
	JsonNode *node = NULL;
	json_foreach(node, table) {
		/* Push node value */
		switch(node->tag) {
		case JSON_OBJECT: /* as array */
		case JSON_ARRAY:  l_unpack_json(L, node); break;
		case JSON_STRING: lua_pushstring(L, node->string_); break;
		case JSON_NUMBER: lua_pushnumber(L, node->number_); break;
365
		case JSON_BOOL:   lua_pushboolean(L, node->bool_); break;
366 367 368 369 370 371 372 373 374 375 376
		default: continue;
		}
		/* Set table key */
		if (node->key) {
			lua_setfield(L, -2, node->key);
		} else {
			lua_rawseti(L, -2, lua_rawlen(L, -2) + 1);
		}
	}
}

377
/** @internal Recursive Lua/JSON serialization. */
378 379
static JsonNode *l_pack_elem(lua_State *L, int top)
{
380 381 382 383 384 385
	switch(lua_type(L, top)) {
	case LUA_TSTRING:  return json_mkstring(lua_tostring(L, top));
	case LUA_TNUMBER:  return json_mknumber(lua_tonumber(L, top));
	case LUA_TBOOLEAN: return json_mkbool(lua_toboolean(L, top));
	case LUA_TTABLE:   break; /* Table, iterate it. */
	default:           return json_mknull();
386
	}
387 388 389 390
	/* Use absolute indexes here, as the table may be nested. */
	JsonNode *node = NULL;
	lua_pushnil(L);
	while(lua_next(L, top) != 0) {
391
		bool is_array = false;
392
		if (!node) {
393
			is_array = (lua_type(L, top + 1) == LUA_TNUMBER);
394
			node = is_array ? json_mkarray() : json_mkobject();
395 396 397
			if (!node) {
				return NULL;
			}
398 399
		} else {
			is_array = node->tag == JSON_ARRAY;
400
		}
401

402 403 404
		/* Insert to array/table. */
		JsonNode *val = l_pack_elem(L, top + 2);
		if (is_array) {
405 406
			json_append_element(node, val);
		} else {
407 408
			const char *key = lua_tostring(L, top + 1);
			json_append_member(node, key, val);
409 410
		}
		lua_pop(L, 1);
411
	}
412 413
	/* Return empty object for empty tables. */
	return node ? node : json_mkobject();
414 415
}

416
/** @internal Serialize to string */
417 418
static char *l_pack_json(lua_State *L, int top)
{
419
	JsonNode *root = l_pack_elem(L, top);
420 421 422 423 424 425 426 427
	if (!root) {
		return NULL;
	}
	char *result = json_encode(root);
	json_delete(root);
	return result;
}

428 429
static int l_tojson(lua_State *L)
{
430
	auto_free char *json_str = l_pack_json(L, lua_gettop(L));
431 432 433 434 435 436 437
	if (!json_str) {
		return 0;
	}
	lua_pushstring(L, json_str);
	return 1;
}

438 439
static int l_fromjson(lua_State *L)
{
440 441
	if (lua_gettop(L) != 1 || !lua_isstring(L, 1))
		lua_error_p(L, "a JSON string is required");
442 443 444 445

	const char *json_str = lua_tostring(L, 1);
	JsonNode *root_node = json_decode(json_str);

446 447
	if (!root_node)
		lua_error_p(L, "invalid JSON string");
448 449 450 451 452 453
	l_unpack_json(L, root_node);
	json_delete(root_node);

	return 1;
}

454 455 456 457 458 459
/** @internal Throw Lua error if expr is false */
#define expr_checked(expr) \
	if (!(expr)) { lua_pushboolean(L, false); lua_rawseti(L, -2, lua_rawlen(L, -2) + 1); continue; }

static int l_map(lua_State *L)
{
460 461
	if (lua_gettop(L) != 1 || !lua_isstring(L, 1))
		lua_error_p(L, "map('string with a lua expression')");
462

463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481
	struct engine *engine = engine_luaget(L);
	const char *cmd = lua_tostring(L, 1);
	uint32_t len = strlen(cmd);
	lua_newtable(L);

	/* Execute on leader instance */
	int ntop = lua_gettop(L);
	engine_cmd(L, cmd, true);
	lua_settop(L, ntop + 1); /* Push only one return value to table */
	lua_rawseti(L, -2, 1);

	for (size_t i = 0; i < engine->ipc_set.len; ++i) {
		int fd = engine->ipc_set.at[i];
		/* Send command */
		expr_checked(write(fd, &len, sizeof(len)) == sizeof(len));
		expr_checked(write(fd, cmd, len) == len);
		/* Read response */
		uint32_t rlen = 0;
		if (read(fd, &rlen, sizeof(rlen)) == sizeof(rlen)) {
482
			expr_checked(rlen < UINT32_MAX);
483 484 485 486 487 488 489 490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505 506 507
			auto_free char *rbuf = malloc(rlen + 1);
			expr_checked(rbuf != NULL);
			expr_checked(read(fd, rbuf, rlen) == rlen);
			rbuf[rlen] = '\0';
			/* Unpack from JSON */
			JsonNode *root_node = json_decode(rbuf);
			if (root_node) {
				l_unpack_json(L, root_node);
			} else {
				lua_pushlstring(L, rbuf, rlen);
			}
			json_delete(root_node);
			lua_rawseti(L, -2, lua_rawlen(L, -2) + 1);
			continue;
		}
		/* Didn't respond */
		lua_pushboolean(L, false);
		lua_rawseti(L, -2, lua_rawlen(L, -2) + 1);
	}
	return 1;
}

#undef expr_checked


508
/** Trampoline function for module properties. */
509 510
static int l_trampoline(lua_State *L)
{
511 512
	struct kr_module *module = lua_touserdata(L, lua_upvalueindex(1));
	void* callback = lua_touserdata(L, lua_upvalueindex(2));
513
	struct engine *engine = engine_luaget(L);
514 515
	if (!module)
		lua_error_p(L, "module closure missing upvalue");
516

517 518 519
	/* Now we only have property callback or config,
	 * if we expand the callables, we might need a callback_type.
	 */
520
	const char *args = NULL;
521
	auto_free char *cleanup_args = NULL;
522
	if (lua_gettop(L) > 0) {
523
		if (lua_istable(L, 1) || lua_isboolean(L, 1)) {
524 525 526 527 528
			cleanup_args = l_pack_json(L, 1);
			args = cleanup_args;
		} else {
			args = lua_tostring(L, 1);
		}
529
	}
530 531
	#pragma GCC diagnostic push
	#pragma GCC diagnostic ignored "-Wpedantic" /* void* vs. function pointer */
532
	if (callback == module->config) {
533
		module->config(module, args);
534 535
	} else {
		kr_prop_cb *prop = (kr_prop_cb *)callback;
536 537 538 539 540
		auto_free char *ret = prop(engine, module, args);
		if (!ret) { /* No results */
			return 0;
		}
		JsonNode *root_node = json_decode(ret);
541
		if (root_node) {
542 543 544 545 546
			l_unpack_json(L, root_node);
		} else {
			lua_pushstring(L, ret);
		}
		json_delete(root_node);
547
		return 1;
548
	}
549
	#pragma GCC diagnostic pop
550

551 552 553 554 555 556 557 558 559 560
	/* No results */
	return 0;
}

/*
 * Engine API.
 */

static int init_resolver(struct engine *engine)
{
561
	/* Note: it had been zored by engine_init(). */
562
	/* Open resolution context */
563 564
	engine->resolver.trust_anchors = map_make(NULL);
	engine->resolver.negative_anchors = map_make(NULL);
565
	engine->resolver.pool = engine->pool;
566
	engine->resolver.modules = &engine->modules;
567
	engine->resolver.cache_rtt_tout_retry_interval = KR_NS_TIMEOUT_RETRY_INTERVAL;
568 569 570 571 572 573
	/* Create OPT RR */
	engine->resolver.opt_rr = mm_alloc(engine->pool, sizeof(knot_rrset_t));
	if (!engine->resolver.opt_rr) {
		return kr_error(ENOMEM);
	}
	knot_edns_init(engine->resolver.opt_rr, KR_EDNS_PAYLOAD, 0, KR_EDNS_VERSION, engine->pool);
574 575
	/* Use default TLS padding */
	engine->resolver.tls_padding = -1;
576
	/* Empty init; filled via ./lua/config.lua */
577
	kr_zonecut_init(&engine->resolver.root_hints, (const uint8_t *)"", engine->pool);
578
	/* Open NS rtt + reputation cache */
579 580 581
	lru_create(&engine->resolver.cache_rtt, LRU_RTT_SIZE, NULL, NULL);
	lru_create(&engine->resolver.cache_rep, LRU_REP_SIZE, NULL, NULL);
	lru_create(&engine->resolver.cache_cookie, LRU_COOKIES_SIZE, NULL, NULL);
582 583

	/* Load basic modules */
584 585
	engine_register(engine, "iterate", NULL, NULL);
	engine_register(engine, "validate", NULL, NULL);
586
	engine_register(engine, "cache", NULL, NULL);
587

588
	return array_push(engine->backends, kr_cdb_lmdb());
589 590 591 592 593 594 595 596 597 598
}

static int init_state(struct engine *engine)
{
	/* Initialize Lua state */
	engine->L = luaL_newstate();
	if (engine->L == NULL) {
		return kr_error(ENOMEM);
	}
	/* Initialize used libraries. */
599
	lua_gc(engine->L, LUA_GCSTOP, 0);
600 601 602 603 604 605
	luaL_openlibs(engine->L);
	/* Global functions */
	lua_pushcfunction(engine->L, l_help);
	lua_setglobal(engine->L, "help");
	lua_pushcfunction(engine->L, l_quit);
	lua_setglobal(engine->L, "quit");
606 607
	lua_pushcfunction(engine->L, l_hostname);
	lua_setglobal(engine->L, "hostname");
608 609
	lua_pushcfunction(engine->L, l_package_version);
	lua_setglobal(engine->L, "package_version");
610 611
	lua_pushcfunction(engine->L, l_moduledir);
	lua_setglobal(engine->L, "moduledir");
612 613
	lua_pushcfunction(engine->L, l_verbose);
	lua_setglobal(engine->L, "verbose");
614 615
	lua_pushcfunction(engine->L, l_setuser);
	lua_setglobal(engine->L, "user");
616 617
	lua_pushcfunction(engine->L, l_hint_root_file);
	lua_setglobal(engine->L, "_hint_root_file");
618 619 620 621
	lua_pushliteral(engine->L, libknot_SONAME);
	lua_setglobal(engine->L, "libknot_SONAME");
	lua_pushliteral(engine->L, libzscanner_SONAME);
	lua_setglobal(engine->L, "libzscanner_SONAME");
622 623
	lua_pushcfunction(engine->L, l_tojson);
	lua_setglobal(engine->L, "tojson");
624 625
	lua_pushcfunction(engine->L, l_fromjson);
	lua_setglobal(engine->L, "fromjson");
626 627
	lua_pushcfunction(engine->L, l_map);
	lua_setglobal(engine->L, "map");
628 629 630 631 632
	lua_pushlightuserdata(engine->L, engine);
	lua_setglobal(engine->L, "__engine");
	return kr_ok();
}

633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652
/**
 * Start luacov measurement and store results to file specified by
 * KRESD_COVERAGE_STATS environment variable.
 * Do nothing if the variable is not set.
 */
static void init_measurement(struct engine *engine)
{
	const char * const statspath = getenv("KRESD_COVERAGE_STATS");
	if (!statspath)
		return;

	char * snippet = NULL;
	int ret = asprintf(&snippet,
		"_luacov_runner = require('luacov.runner')\n"
		"_luacov_runner.init({\n"
		"	statsfile = '%s',\n"
		"	exclude = {'test', 'tapered', 'lua/5.1'},\n"
		"})\n"
		"jit.off()\n", statspath
	);
653
	assert(ret > 0); (void)ret;
654 655 656 657 658 659 660

	ret = luaL_loadstring(engine->L, snippet);
	assert(ret == 0);
	lua_call(engine->L, 0, 0);
	free(snippet);
}

661
int engine_init(struct engine *engine, knot_mm_t *pool)
662 663 664 665 666 667 668 669 670 671 672 673
{
	if (engine == NULL) {
		return kr_error(EINVAL);
	}

	memset(engine, 0, sizeof(*engine));
	engine->pool = pool;

	/* Initialize state */
	int ret = init_state(engine);
	if (ret != 0) {
		engine_deinit(engine);
674
		return ret;
675
	}
676
	init_measurement(engine);
677 678 679
	/* Initialize resolver */
	ret = init_resolver(engine);
	if (ret != 0) {
680
		engine_deinit(engine);
681 682
		return ret;
	}
683
	/* Initialize network */
684
	network_init(&engine->net, uv_default_loop(), TCP_BACKLOG_DEFAULT);
685 686 687 688

	return ret;
}

689 690 691 692 693
static void engine_unload(struct engine *engine, struct kr_module *module)
{
	/* Unregister module */
	auto_free char *name = strdup(module->name);
	kr_module_unload(module);
694 695
	/* Clear in Lua world, but not for embedded modules ('cache' in particular). */
	if (name && !kr_module_embedded(name)) {
696 697 698 699 700 701
		lua_pushnil(engine->L);
		lua_setglobal(engine->L, name);
	}
	free(module);
}

702 703 704 705 706 707
void engine_deinit(struct engine *engine)
{
	if (engine == NULL) {
		return;
	}

708 709
	/* Only close sockets and services,
	 * no need to clean up mempool. */
710
	network_deinit(&engine->net);
711
	kr_zonecut_deinit(&engine->resolver.root_hints);
712
	kr_cache_close(&engine->resolver.cache);
713

714
	/* The LRUs are currently malloc-ated and need to be freed. */
715 716 717
	lru_free(engine->resolver.cache_rtt);
	lru_free(engine->resolver.cache_rep);
	lru_free(engine->resolver.cache_cookie);
718

719 720 721 722 723
	/* Clear IPC pipes */
	for (size_t i = 0; i < engine->ipc_set.len; ++i) {
		close(engine->ipc_set.at[i]);
	}

724
	/* Unload modules and engine. */
725
	for (size_t i = 0; i < engine->modules.len; ++i) {
726
		engine_unload(engine, engine->modules.at[i]);
727 728 729 730 731
	}
	if (engine->L) {
		lua_close(engine->L);
	}

732 733
	/* Free data structures */
	array_clear(engine->modules);
734
	array_clear(engine->backends);
735
	array_clear(engine->ipc_set);
736 737
	kr_ta_clear(&engine->resolver.trust_anchors);
	kr_ta_clear(&engine->resolver.negative_anchors);
738 739
	free(engine->hostname);
	free(engine->moduledir);
740 741
}

742
int engine_pcall(lua_State *L, int argc)
743 744 745
{
#if LUA_VERSION_NUM >= 502
	lua_getglobal(L, "_SANDBOX");
746
	lua_setupvalue(L, -(2 + argc), 1);
747
#endif
748
	return lua_pcall(L, argc, LUA_MULTRET, 0);
749 750
}

751
int engine_cmd(lua_State *L, const char *str, bool raw)
752
{
753
	if (L == NULL) {
754 755 756 757
		return kr_error(ENOEXEC);
	}

	/* Evaluate results */
758 759 760
	lua_getglobal(L, "eval_cmd");
	lua_pushstring(L, str);
	lua_pushboolean(L, raw);
761 762

	/* Check result. */
763 764 765 766 767 768 769 770 771 772 773 774 775 776 777 778 779
	return engine_pcall(L, 2);
}

int engine_ipc(struct engine *engine, const char *expr)
{
	if (engine == NULL || engine->L == NULL) {
		return kr_error(ENOEXEC);
	}

	/* Run expression and serialize response. */
	engine_cmd(engine->L, expr, true);
	if (lua_gettop(engine->L) > 0) {
		l_tojson(engine->L);
		return 1;
	} else {
		return 0;
	}
780 781
}

782
int engine_load_sandbox(struct engine *engine)
783
{
784
	/* Init environment */
785 786 787 788
	static const char sandbox_bytecode[] = {
		#include "daemon/lua/sandbox.inc"
	};
	if (l_dobytecode(engine->L, sandbox_bytecode, sizeof(sandbox_bytecode), "init") != 0) {
789 790
		fprintf(stderr, "[system] error %s\n", lua_tostring(engine->L, -1));
		lua_pop(engine->L, 1);
791 792
		return kr_error(ENOEXEC);
	}
793 794
	return kr_ok();
}
795

796 797 798 799
int engine_loadconf(struct engine *engine, const char *config_path)
{
	assert(config_path != NULL);
	int ret = l_dosandboxfile(engine->L, config_path);
800
	if (ret != 0) {
801
		fprintf(stderr, "%s\n", lua_tostring(engine->L, -1));
802 803
		lua_pop(engine->L, 1);
	}
804
	return ret;
805 806
}

807
int engine_load_defaults(struct engine *engine)
808
{
809 810 811 812 813
	/* Load defaults */
	static const char config_bytecode[] = {
		#include "daemon/lua/config.inc"
	};
	int ret = l_dobytecode(engine->L, config_bytecode, sizeof(config_bytecode), "config");
814
	if (ret != 0) {
815 816
		fprintf(stderr, "%s\n", lua_tostring(engine->L, -1));
		lua_pop(engine->L, 1);
817
	}
818 819
	return ret;
}
820

821 822
int engine_start(struct engine *engine)
{
823 824 825
	/* Clean up stack and restart GC */
	lua_settop(engine->L, 0);
	lua_gc(engine->L, LUA_GCCOLLECT, 0);
826
	lua_gc(engine->L, LUA_GCSETSTEPMUL, 50);
827 828
	lua_gc(engine->L, LUA_GCSETPAUSE, 400);
	lua_gc(engine->L, LUA_GCRESTART, 0);
829

830
	return kr_ok();
831 832 833 834
}

void engine_stop(struct engine *engine)
{
835 836 837
	if (!engine) {
		return;
	}
838 839 840
	uv_stop(uv_default_loop());
}

841
/** Register module properties in Lua environment, if any. */
842 843
static int register_properties(struct engine *engine, struct kr_module *module)
{
844 845
	#pragma GCC diagnostic push
	#pragma GCC diagnostic ignored "-Wpedantic" /* casts in lua_pushlightuserdata() */
846 847 848
	if (!module->config && !module->props) {
		return kr_ok();
	}
849 850 851 852
	lua_newtable(engine->L);
	if (module->config != NULL) {
		REGISTER_MODULE_CALL(engine->L, module, module->config, "config");
	}
853 854 855 856

	const struct kr_prop *p = module->props == NULL ? NULL : module->props();
	for (; p && p->name; ++p) {
		if (p->cb != NULL) {
857 858 859 860
			REGISTER_MODULE_CALL(engine->L, module, p->cb, p->name);
		}
	}
	lua_setglobal(engine->L, module->name);
861
	#pragma GCC diagnostic pop
862 863 864 865

	/* Register module in Lua env */
	lua_getglobal(engine->L, "modules_register");
	lua_getglobal(engine->L, module->name);
866
	if (engine_pcall(engine->L, 1) != 0) {
867 868 869 870 871 872
		lua_pop(engine->L, 1);
	}

	return kr_ok();
}

873 874 875 876 877 878 879 880 881 882 883 884 885 886 887
/** @internal Find matching module */
static size_t module_find(module_array_t *mod_list, const char *name)
{
	size_t found = mod_list->len;
	for (size_t i = 0; i < mod_list->len; ++i) {
		struct kr_module *mod = mod_list->at[i];
		if (strcmp(mod->name, name) == 0) {
			found = i;
			break;
		}
	}
	return found;
}

int engine_register(struct engine *engine, const char *name, const char *precedence, const char* ref)
888 889 890 891
{
	if (engine == NULL || name == NULL) {
		return kr_error(EINVAL);
	}
892 893
	/* Make sure module is unloaded */
	(void) engine_unregister(engine, name);
894 895 896 897 898 899 900 901 902
	/* Find the index of referenced module. */
	module_array_t *mod_list = &engine->modules;
	size_t ref_pos = mod_list->len;
	if (precedence && ref) {
		ref_pos = module_find(mod_list, ref);
		if (ref_pos >= mod_list->len) {
			return kr_error(EIDRM);
		}
	}
903
	/* Attempt to load binary module */
904 905 906 907
	struct kr_module *module = malloc(sizeof(*module));
	if (!module) {
		return kr_error(ENOMEM);
	}
908
	module->data = engine;
909
	int ret = kr_module_load(module, name, engine->moduledir);
910 911
	/* Load Lua module if not a binary */
	if (ret == kr_error(ENOENT)) {
912
		ret = ffimodule_register_lua(engine, module, name);
913 914 915
	} else if (ret == kr_error(ENOTSUP)) {
		/* Print a more helpful message when module is linked against an old resolver ABI. */
		fprintf(stderr, "[system] module '%s' links to unsupported ABI, please rebuild it\n", name);
916
	}
917
	if (ret != 0) {
918
		free(module);
919
		return ret;
920 921 922 923
	}
	if (array_push(engine->modules, module) < 0) {
		engine_unload(engine, module);
		return kr_error(ENOMEM);
924
	}
925 926 927 928 929 930 931 932 933 934 935 936 937 938 939 940
	/* Evaluate precedence operator */
	if (precedence) {
		struct kr_module **arr = mod_list->at;
		size_t emplacement = mod_list->len;
		if (strcasecmp(precedence, ">") == 0) {
			if (ref_pos + 1 < mod_list->len)
				emplacement = ref_pos + 1; /* Insert after target */
		}
		if (strcasecmp(precedence, "<") == 0) {
			emplacement = ref_pos; /* Insert at target */
		}
		/* Move the tail if it has some elements. */
		if (emplacement + 1 < mod_list->len) {
			memmove(&arr[emplacement + 1], &arr[emplacement], sizeof(*arr) * (mod_list->len - (emplacement + 1)));
			arr[emplacement] = module;
		}
941
	}
942

943
	return register_properties(engine, module);
944 945 946 947
}

int engine_unregister(struct engine *engine, const char *name)
{
948
	module_array_t *mod_list = &engine->modules;
949
	size_t found = module_find(mod_list, name);
950
	if (found < mod_list->len) {
951
		engine_unload(engine, mod_list->at[found]);
952 953 954 955 956 957 958 959 960
		array_del(*mod_list, found);
		return kr_ok();
	}

	return kr_error(ENOENT);
}

struct engine *engine_luaget(lua_State *L)
{
961
	lua_getglobal(L, "__engine");
962
	struct engine *engine = lua_touserdata(L, -1);
963
	if (!engine) luaL_error(L, "internal error, empty engine pointer");
964
	lua_pop(L, 1);
965
	return engine;
966
}