mirror of
https://github.com/NLnetLabs/unbound.git
synced 2026-09-30 13:44:58 +02:00
Merge branch 'xfr-tsig' into update-with-branches/poisonlicious
This commit is contained in:
+20
-6
@@ -188,6 +188,22 @@ delete_replay_answer(struct replay_answer* a)
|
||||
free(a);
|
||||
}
|
||||
|
||||
/** Log the packet for a reply_packet from testpkts. */
|
||||
static void
|
||||
log_testpkt_reply_pkt(const char* txt, struct reply_packet* reppkt)
|
||||
{
|
||||
if(!reppkt) {
|
||||
log_info("%s <null>", txt);
|
||||
return;
|
||||
}
|
||||
if(reppkt->reply_from_hex) {
|
||||
log_pkt(txt, sldns_buffer_begin(reppkt->reply_from_hex),
|
||||
sldns_buffer_limit(reppkt->reply_from_hex));
|
||||
return;
|
||||
}
|
||||
log_pkt(txt, reppkt->reply_pkt, reppkt->reply_len);
|
||||
}
|
||||
|
||||
/**
|
||||
* return: true if pending query matches the now event.
|
||||
*/
|
||||
@@ -240,9 +256,8 @@ pending_find_match(struct replay_runtime* runtime, struct entry** entry,
|
||||
p->start_step, p->end_step, (*entry)->lineno);
|
||||
if(p->addrlen != 0)
|
||||
log_addr(0, "matched ip", &p->addr, p->addrlen);
|
||||
log_pkt("matched pkt: ",
|
||||
(*entry)->reply_list->reply_pkt,
|
||||
(*entry)->reply_list->reply_len);
|
||||
log_testpkt_reply_pkt("matched pkt: ",
|
||||
(*entry)->reply_list);
|
||||
return 1;
|
||||
}
|
||||
p = p->next_range;
|
||||
@@ -330,7 +345,7 @@ fill_buffer_with_reply(sldns_buffer* buffer, struct entry* entry, uint8_t* q,
|
||||
while(reppkt && i--)
|
||||
reppkt = reppkt->next;
|
||||
if(!reppkt) fatal_exit("extra packet read from TCP stream but none is available");
|
||||
log_pkt("extra_packet ", reppkt->reply_pkt, reppkt->reply_len);
|
||||
log_testpkt_reply_pkt("extra packet ", reppkt);
|
||||
}
|
||||
if(reppkt->reply_from_hex) {
|
||||
c = sldns_buffer_begin(reppkt->reply_from_hex);
|
||||
@@ -462,8 +477,7 @@ fake_front_query(struct replay_runtime* runtime, struct replay_moment *todo)
|
||||
repinfo.c->type = comm_udp;
|
||||
fill_buffer_with_reply(repinfo.c->buffer, todo->match, NULL, 0, 0);
|
||||
log_info("testbound: incoming QUERY");
|
||||
log_pkt("query pkt", todo->match->reply_list->reply_pkt,
|
||||
todo->match->reply_list->reply_len);
|
||||
log_testpkt_reply_pkt("query pkt ", todo->match->reply_list);
|
||||
/* call the callback for incoming queries */
|
||||
if((*runtime->callback_query)(repinfo.c, runtime->cb_arg,
|
||||
NETEVENT_NOERROR, &repinfo)) {
|
||||
|
||||
@@ -297,7 +297,11 @@ setup_config(FILE* in, int* lineno, int* pass_argc, char* pass_argv[])
|
||||
/* Allow the use of SHA1 signatures for the test,
|
||||
* in case that OpenSSL disallows use of RSASHA1
|
||||
* with rh-allow-sha1-signatures disabled. */
|
||||
#ifndef UB_ON_WINDOWS
|
||||
setenv("OPENSSL_ENABLE_SHA1_SIGNATURES", "1", 0);
|
||||
#else
|
||||
_putenv("OPENSSL_ENABLE_SHA1_SIGNATURES=1");
|
||||
#endif
|
||||
}
|
||||
fputs(line, cfg);
|
||||
}
|
||||
|
||||
@@ -45,6 +45,7 @@
|
||||
#include "util/data/dname.h"
|
||||
#include "sldns/sbuffer.h"
|
||||
#include "sldns/str2wire.h"
|
||||
#include "sldns/wire2str.h"
|
||||
|
||||
/** put dname into buffer */
|
||||
static sldns_buffer*
|
||||
@@ -876,6 +877,262 @@ dname_setup_bufs(sldns_buffer* loopbuf, sldns_buffer* boundbuf)
|
||||
sldns_buffer_flip(boundbuf);
|
||||
}
|
||||
|
||||
/* Test strings for the test_long_names test. */
|
||||
/* Each label begins with the length of the label including the length octet. */
|
||||
|
||||
char desc_1[] = "Domain is 1 octet too long.";
|
||||
|
||||
uint8_t wire_dom_1[] = { /* Bad: Domain: (8x)0031abcdefghijklmnopqrstuvwxyz.0007ab. */
|
||||
0x1e, 0x30, 0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b,
|
||||
0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e,
|
||||
0x30, 0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c,
|
||||
0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30,
|
||||
0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d,
|
||||
0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30,
|
||||
0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e,
|
||||
0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33,
|
||||
0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f,
|
||||
0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31,
|
||||
0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70,
|
||||
0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31, 0x61,
|
||||
0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71,
|
||||
0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31, 0x61, 0x62,
|
||||
0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72,
|
||||
0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, /* Bad: */ 0x06, 0x30, 0x30, 0x30, 0x37, 0x61, 0x62, 0x00
|
||||
};
|
||||
|
||||
char desc_2[] = "Domain has the maximum allowed length (255).";
|
||||
|
||||
uint8_t wire_dom_2[] = { /* Good: Domain: (8x)0031abcdefghijklmnopqrstuvwxyz.00076a. */
|
||||
0x1e, 0x30, 0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b,
|
||||
0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e,
|
||||
0x30, 0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c,
|
||||
0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30,
|
||||
0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d,
|
||||
0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30,
|
||||
0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e,
|
||||
0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33,
|
||||
0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f,
|
||||
0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31,
|
||||
0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70,
|
||||
0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31, 0x61,
|
||||
0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71,
|
||||
0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31, 0x61, 0x62,
|
||||
0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72,
|
||||
0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, /* Good: */ 0x05, 0x30, 0x30, 0x30, 0x36, 0x61, 0x00
|
||||
};
|
||||
|
||||
char desc_3[] = "Domain has a length one label in the 255th position for a total of 257.";
|
||||
|
||||
uint8_t wire_dom_3[] = { /* Bad: Domain: (8x(0031abcdefghijklmnopqrstuvwxyz.0006ab.1. */
|
||||
0x1e, 0x30, 0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b,
|
||||
0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e,
|
||||
0x30, 0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c,
|
||||
0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30,
|
||||
0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d,
|
||||
0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30,
|
||||
0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e,
|
||||
0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33,
|
||||
0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f,
|
||||
0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31,
|
||||
0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70,
|
||||
0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31, 0x61,
|
||||
0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71,
|
||||
0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31, 0x61, 0x62,
|
||||
0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72,
|
||||
0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, /* Bad: */ 0x05, 0x30, 0x30, 0x30, 0x36, 0x61, 0x01, 0x32, 0x00
|
||||
};
|
||||
|
||||
char desc_4[] = "Domain has the maximum allowed length (255).";
|
||||
|
||||
uint8_t wire_dom_4[] = { /* Good: Domain: (8x)0031abcdefghijklmnopqrstuvwxyz.03.03. */
|
||||
0x1e, 0x30, 0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b,
|
||||
0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e,
|
||||
0x30, 0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c,
|
||||
0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30,
|
||||
0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d,
|
||||
0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30,
|
||||
0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e,
|
||||
0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33,
|
||||
0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f,
|
||||
0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31,
|
||||
0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70,
|
||||
0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31, 0x61,
|
||||
0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71,
|
||||
0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31, 0x61, 0x62,
|
||||
0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72,
|
||||
0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, /* Good: */ 0x02, 0x30, 0x33, 0x02, 0x30, 0x33, 0x00
|
||||
};
|
||||
|
||||
char desc_5[] = "Domain has a maximum length label (63) in the 255th position.";
|
||||
|
||||
uint8_t wire_dom_5[] = { /* Bad: Domain: (8x)0031abcdefghijklmnopqrstuvwxyz.03.03.65abc...zab...zab...ghi. */
|
||||
0x1e, 0x30, 0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b,
|
||||
0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e,
|
||||
0x30, 0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c,
|
||||
0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30,
|
||||
0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d,
|
||||
0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30,
|
||||
0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e,
|
||||
0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33,
|
||||
0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f,
|
||||
0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31,
|
||||
0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70,
|
||||
0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31, 0x61,
|
||||
0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71,
|
||||
0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31, 0x61, 0x62,
|
||||
0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72,
|
||||
0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, /* Bad: */ 0x02, 0x30, 0x33, 0x02, 0x30, 0x33, 0x3f, 0x36,
|
||||
0x33, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f,
|
||||
0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x61, 0x62, 0x63, 0x64, 0x65,
|
||||
0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75,
|
||||
0x76, 0x77, 0x78, 0x79, 0x7a, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x00
|
||||
};
|
||||
|
||||
char desc_6[] = "Domain has a too long label (65) in the 255th position.";
|
||||
|
||||
uint8_t wire_dom_6[] = { /* Bad: Domain: (8x)0031abcdefghijklmnopqrstuvwxyz.03.03.66abc...zab...zab...ijk. */
|
||||
0x1e, 0x30, 0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b,
|
||||
0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e,
|
||||
0x30, 0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c,
|
||||
0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30,
|
||||
0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d,
|
||||
0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30,
|
||||
0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e,
|
||||
0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33,
|
||||
0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f,
|
||||
0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31,
|
||||
0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70,
|
||||
0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31, 0x61,
|
||||
0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71,
|
||||
0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31, 0x61, 0x62,
|
||||
0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72,
|
||||
0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, /* Bad: */ 0x02, 0x30, 0x33, 0x02, 0x30, 0x33, 0x41, 0x36,
|
||||
0x36, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f,
|
||||
0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x61, 0x62, 0x63, 0x64, 0x65,
|
||||
0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75,
|
||||
0x76, 0x77, 0x78, 0x79, 0x7a, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b,
|
||||
0x00
|
||||
};
|
||||
|
||||
char desc_7[] = "Domain has a too long label (65) in the 187th position.";
|
||||
|
||||
uint8_t wire_dom_7[] = { /* Bad: Domain: (6x)0031abcdefghijklmnopqrstuvwxyz.65abc..zab...zab...ijk. */
|
||||
0x1e, 0x30, 0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b,
|
||||
0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e,
|
||||
0x30, 0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c,
|
||||
0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30,
|
||||
0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d,
|
||||
0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30,
|
||||
0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e,
|
||||
0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33,
|
||||
0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f,
|
||||
0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31,
|
||||
0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70,
|
||||
0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a,
|
||||
/* Bad: */ 0x41, 0x36,
|
||||
0x36, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f,
|
||||
0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x61, 0x62, 0x63, 0x64, 0x65,
|
||||
0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75,
|
||||
0x76, 0x77, 0x78, 0x79, 0x7a, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b,
|
||||
0x00
|
||||
};
|
||||
|
||||
char desc_8[] = "Domains has the maximum allowed length and ends with a maximum length label.";
|
||||
|
||||
uint8_t wire_dom_8[] = { /* Good: Domain: (6x)0031abcdefghijklmnopqrstuvwxyz.0004.0064abc..zab...zabcdefg. */
|
||||
0x1e, 0x30, 0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b,
|
||||
0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e,
|
||||
0x30, 0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c,
|
||||
0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30,
|
||||
0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d,
|
||||
0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30,
|
||||
0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e,
|
||||
0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33,
|
||||
0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f,
|
||||
0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31,
|
||||
0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70,
|
||||
0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x03, 0x30, 0x30, 0x34 ,/* Good: */ 0x3f, 0x30,
|
||||
0x30, 0x36, 0x34, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d,
|
||||
0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x61, 0x62, 0x63,
|
||||
0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73,
|
||||
0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x00
|
||||
};
|
||||
|
||||
char desc_9[] = "Domains has 254 octets, one less than the maximum allowed length.";
|
||||
|
||||
uint8_t wire_dom_9[] = { /* Good: Domain: (6x)0031abcdefghijklmnopqrstuvwxyz.0004.0064abc..zab...zabcdef. */
|
||||
0x1e, 0x30, 0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b,
|
||||
0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e,
|
||||
0x30, 0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c,
|
||||
0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30,
|
||||
0x30, 0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d,
|
||||
0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30,
|
||||
0x33, 0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e,
|
||||
0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33,
|
||||
0x31, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f,
|
||||
0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x1e, 0x30, 0x30, 0x33, 0x31,
|
||||
0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70,
|
||||
0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x03, 0x30, 0x30, 0x34 ,/* Good: */ 0x3e, 0x30,
|
||||
0x30, 0x35, 0x34, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d,
|
||||
0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x61, 0x62, 0x63,
|
||||
0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73,
|
||||
0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x00
|
||||
};
|
||||
|
||||
/** Test dname to string with long domain names. */
|
||||
static void
|
||||
test_long_names(void)
|
||||
{
|
||||
/* Set to 1 for verbose output, 0 turns it off. */
|
||||
int verbtest = 0;
|
||||
|
||||
uint8_t* wire_doms[] = {wire_dom_1, wire_dom_2, wire_dom_3,
|
||||
wire_dom_4, wire_dom_5, wire_dom_6, wire_dom_7, wire_dom_8,
|
||||
wire_dom_9, 0};
|
||||
char* descs[] = {desc_1, desc_2, desc_3, desc_4, desc_5, desc_6,
|
||||
desc_7, desc_8, desc_9, 0};
|
||||
|
||||
int n;
|
||||
char string_domain[260];
|
||||
uint8_t** wd = wire_doms;
|
||||
int di = 0;
|
||||
int skip = 5; /* 0..6 */
|
||||
|
||||
while (*wd) {
|
||||
|
||||
if(verbtest)
|
||||
printf("Test: %s\n", descs[di++]);
|
||||
|
||||
memset(string_domain, 0xff, sizeof(string_domain));
|
||||
dname_str(*wd, string_domain);
|
||||
for (n = 0 ; n < (int)sizeof(string_domain); ++n) {
|
||||
if ((uint8_t)string_domain[n] == 0xff)
|
||||
break;
|
||||
}
|
||||
if(verbtest)
|
||||
printf("dname_str: L=%d, S=Skipping %d labels...%s\n",
|
||||
n, skip, string_domain + skip*31);
|
||||
unit_assert(n <= 255);
|
||||
|
||||
memset(string_domain, 0xff, sizeof(string_domain));
|
||||
sldns_wire2str_dname_buf(*wd,
|
||||
strlen((char*)*wd)+1 /* strlen works with these test strings */,
|
||||
string_domain,
|
||||
255 /* for comparable result to dname_str */ );
|
||||
for (n = 0 ; n < (int)sizeof(string_domain); ++n) {
|
||||
if ((uint8_t)string_domain[n] == 0xff)
|
||||
break;
|
||||
}
|
||||
if(verbtest)
|
||||
printf("sldns_wire2str_dname_buf: L=%d, S=Skipping %d labels...%s\n",
|
||||
n, skip, string_domain + skip*31);
|
||||
unit_assert(n <= 255);
|
||||
|
||||
++wd;
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
dname_test_str(sldns_buffer* buff)
|
||||
{
|
||||
@@ -1019,6 +1276,8 @@ dname_test_str(sldns_buffer* buff)
|
||||
unit_assert(0);
|
||||
}
|
||||
}
|
||||
|
||||
test_long_names();
|
||||
}
|
||||
|
||||
void dname_test(void)
|
||||
|
||||
+469
-1
@@ -118,6 +118,46 @@ static int vtest = 0;
|
||||
* buffer. The expected rcode is the result of the verify,
|
||||
* the expected result2 is the result of the sign. If that differs
|
||||
* the test fails.
|
||||
* tsig-verify-reply <key> <time> <expected result> <expected result2>
|
||||
* <hex>
|
||||
* endpacket
|
||||
* The data from previous packet in the buffer is used with
|
||||
* tsig-sign-query. Then the hex data is the reply, it is used
|
||||
* with tsig-verify-reply. It TSIG signs with key name, at timestamp
|
||||
* in secs. The result of the sign call is compared with the
|
||||
* expected result, the result of the verify call is compared with
|
||||
* the expected result2, and the test fails if not equal.
|
||||
*
|
||||
* tsig-sign-reply-xfr <num> <time> <expected rcode> <nth>
|
||||
* packet
|
||||
* <hex>
|
||||
* endpacket
|
||||
* call <time> <expected>
|
||||
* check-packet
|
||||
* <check hex>
|
||||
* endpacket
|
||||
* ..
|
||||
* The data from the previous packet in the buffer is used with
|
||||
* tsig-verify-query. Then a number of times, the hex data is
|
||||
* used with tsig-sign-reply-xfr and the output is checked with
|
||||
* the checkhex.
|
||||
* The expected rcode is from tsig_verify_query. The expected from
|
||||
* call is from tsig_sign_reply_xfr. The nth value 0 or 1 means
|
||||
* sign every packet, but >= 2 signs after a series of unsigned
|
||||
* packets.
|
||||
* tsig-verify-reply-xfr <num> <key> <time> <result>
|
||||
* packet
|
||||
* <hex>
|
||||
* endpacket
|
||||
* call <time> <last> <result2>
|
||||
* ..
|
||||
* The data from previous packet in the buffer is used with
|
||||
* tsig-sign-query. Then a number of times, the hex data is used
|
||||
* with tsig-verify-reply-xfr, and the result is checked.
|
||||
* The TSIG signes with key name, at timestamp in secs. The result
|
||||
* of the tsig-sign-query function is compared with result.
|
||||
* The last is the last_packet argument. The function result is
|
||||
* compared with result2.
|
||||
*
|
||||
*/
|
||||
|
||||
@@ -880,6 +920,428 @@ handle_tsig_sign_reply(char* line, FILE* in, const char* fname,
|
||||
sldns_buffer_copy(pkt, &reply_pkt);
|
||||
}
|
||||
|
||||
/** Handle the tsig-verify-reply */
|
||||
static void
|
||||
handle_tsig_verify_reply(char* line, FILE* in, const char* fname,
|
||||
struct tsig_key_table* key_table, struct sldns_buffer* pkt)
|
||||
{
|
||||
char* arg = get_arg_on_line(line, "tsig-verify-reply");
|
||||
char* s, *keyname, *timestr, *expectedstr, *expectedstr2;
|
||||
int expected_result, expected_result2, ret;
|
||||
uint64_t timepoint;
|
||||
struct tsig_data* tsig;
|
||||
size_t pos;
|
||||
uint8_t buf[65536];
|
||||
sldns_buffer reply_pkt;
|
||||
|
||||
s = arg;
|
||||
keyname = get_next_arg_on_line(&s);
|
||||
timestr = get_next_arg_on_line(&s);
|
||||
expectedstr = get_next_arg_on_line(&s);
|
||||
expectedstr2 = get_next_arg_on_line(&s);
|
||||
|
||||
timepoint = (uint64_t)atoll(timestr);
|
||||
if(timepoint == 0 && strcmp(timestr, "0") != 0)
|
||||
fatal_exit("expected time argument for %s", timestr);
|
||||
expected_result = atoi(expectedstr);
|
||||
if(expected_result == 0 && strcmp(expectedstr, "0") != 0)
|
||||
fatal_exit("expected int argument for %s", expectedstr);
|
||||
expected_result2 = atoi(expectedstr2);
|
||||
if(expected_result2 == 0 && strcmp(expectedstr2, "0") != 0)
|
||||
fatal_exit("expected int argument for %s", expectedstr2);
|
||||
|
||||
sldns_buffer_init_frm_data(&reply_pkt, buf, sizeof(buf));
|
||||
if(!read_packet_hex("", &reply_pkt, in, fname))
|
||||
fatal_exit("Could not read reply packet");
|
||||
if(vtest >= 2) {
|
||||
char* str = sldns_wire2str_pkt(sldns_buffer_begin(&reply_pkt),
|
||||
sldns_buffer_limit(&reply_pkt));
|
||||
if(str)
|
||||
printf("reply packet: %s\n", str);
|
||||
else
|
||||
printf("could not wire2str_pkt\n");
|
||||
free(str);
|
||||
}
|
||||
|
||||
if(vtest) {
|
||||
printf("tsig-verify-reply with %s %d %d %d\n", keyname,
|
||||
(int)timepoint, expected_result, expected_result2);
|
||||
}
|
||||
|
||||
tsig = tsig_create_fromstr(key_table, keyname);
|
||||
if(!tsig)
|
||||
fatal_exit("alloc fail or key not found %s", keyname);
|
||||
|
||||
/* Put position at the end of the packet to sign it. */
|
||||
pos = sldns_buffer_limit(pkt);
|
||||
sldns_buffer_clear(pkt);
|
||||
sldns_buffer_set_position(pkt, pos);
|
||||
|
||||
ret = tsig_sign_query(tsig, pkt, key_table, timepoint);
|
||||
sldns_buffer_flip(pkt);
|
||||
|
||||
if(vtest) {
|
||||
if(ret == expected_result)
|
||||
printf("function ok, %s\n", (ret?"success":"fail"));
|
||||
else
|
||||
printf("function returned %d, expected result %d\n",
|
||||
ret, expected_result);
|
||||
}
|
||||
unit_assert(ret == expected_result);
|
||||
|
||||
/* Verify the reply */
|
||||
/* Put position before TSIG */
|
||||
if(!tsig_find_rr(&reply_pkt)) {
|
||||
if(vtest)
|
||||
printf("tsig-verify-reply found no TSIG RR\n");
|
||||
unit_assert(0);
|
||||
return;
|
||||
}
|
||||
ret = tsig_parse_verify_reply(tsig, &reply_pkt, key_table, timepoint);
|
||||
|
||||
if(vtest) {
|
||||
if(ret == expected_result2)
|
||||
printf("function ok, %s\n", (ret?"success":"fail"));
|
||||
else
|
||||
printf("function returned %d, expected result2 %d\n",
|
||||
ret, expected_result2);
|
||||
}
|
||||
unit_assert(ret == expected_result2);
|
||||
|
||||
tsig_delete(tsig);
|
||||
}
|
||||
|
||||
/* Read next line from file, skip empty and comment lines. It returns the
|
||||
* key_keyword of the line. Returns false on failure. */
|
||||
static char*
|
||||
read_next_keyword(char* line, size_t len, FILE* in)
|
||||
{
|
||||
char* s = NULL;
|
||||
while(1) {
|
||||
if(!fgets(line, len, in)) {
|
||||
if(vtest) printf("fgets: %s\n", strerror(errno));
|
||||
return NULL;
|
||||
}
|
||||
line[len-1]=0;
|
||||
s = get_keyword(line);
|
||||
if(s[0] == 0 || s[0] == '#')
|
||||
continue;
|
||||
break;
|
||||
}
|
||||
return s;
|
||||
}
|
||||
|
||||
/** Handle the tsig-sign-reply-xfr */
|
||||
static void
|
||||
handle_tsig_sign_reply_xfr(char* line, FILE* in, const char* fname,
|
||||
struct tsig_key_table* key_table, struct sldns_buffer* pkt)
|
||||
{
|
||||
char* arg = get_arg_on_line(line, "tsig-sign-reply-xfr");
|
||||
char* s, *numstr, *timestr, *expected_rcode_str, *expectedstr2,
|
||||
*nthstr;
|
||||
int expected_rcode, expected_result2, ret, num, i, nth;
|
||||
uint64_t timepoint;
|
||||
struct tsig_data* tsig;
|
||||
size_t pos;
|
||||
uint8_t buf[65536], buf2[65536];
|
||||
sldns_buffer reply_pkt, check_pkt;
|
||||
sldns_buffer_init_frm_data(&reply_pkt, buf, sizeof(buf));
|
||||
sldns_buffer_init_frm_data(&check_pkt, buf2, sizeof(buf2));
|
||||
|
||||
s = arg;
|
||||
numstr = get_next_arg_on_line(&s);
|
||||
timestr = get_next_arg_on_line(&s);
|
||||
expected_rcode_str = get_next_arg_on_line(&s);
|
||||
nthstr = get_next_arg_on_line(&s);
|
||||
|
||||
num = atoi(numstr);
|
||||
if(num == 0 && strcmp(numstr, "0") != 0)
|
||||
fatal_exit("expected int argument for %s", numstr);
|
||||
timepoint = (uint64_t)atoll(timestr);
|
||||
if(timepoint == 0 && strcmp(timestr, "0") != 0)
|
||||
fatal_exit("expected time argument for %s", timestr);
|
||||
expected_rcode = str2wire_rcode(expected_rcode_str);
|
||||
if(expected_rcode == 0 && strcmp(expected_rcode_str, "0") != 0 &&
|
||||
strcmp(expected_rcode_str, "NOERROR") != 0 &&
|
||||
strcmp(expected_rcode_str, "RCODE0") != 0)
|
||||
fatal_exit("expected rcode argument for %s",
|
||||
expected_rcode_str);
|
||||
nth = atoi(nthstr);
|
||||
if(nth == 0 && strcmp(nthstr, "0") != 0)
|
||||
fatal_exit("expected int argument for %s", nthstr);
|
||||
if(nth == 0)
|
||||
nth = 1;
|
||||
|
||||
if(vtest) {
|
||||
char bufrc[16];
|
||||
sldns_wire2str_rcode_buf(expected_rcode, bufrc, sizeof(bufrc));
|
||||
printf("tsig-sign-reply-xfr with %d %d %s %d\n", num,
|
||||
(int)timepoint, bufrc, nth);
|
||||
}
|
||||
|
||||
/* Verify the query in the packet buffer. Use that TSIG to sign
|
||||
* replies. */
|
||||
if(!tsig_find_rr(pkt)) {
|
||||
if(vtest)
|
||||
printf("tsig-verify-query found no TSIG RR\n");
|
||||
unit_assert(0);
|
||||
return;
|
||||
}
|
||||
ret = tsig_parse_verify_query(key_table, pkt, &tsig, NULL, timepoint);
|
||||
if(vtest) {
|
||||
char bufrc[16];
|
||||
sldns_wire2str_rcode_buf(expected_rcode, bufrc, sizeof(bufrc));
|
||||
if(ret == expected_rcode)
|
||||
printf("verify ok, ret %s\n", bufrc);
|
||||
else
|
||||
printf("verify returned %d, expected result %d %s\n",
|
||||
ret, expected_rcode, bufrc);
|
||||
}
|
||||
unit_assert(ret == expected_rcode);
|
||||
tsig->every_nth = nth;
|
||||
|
||||
/* Sign the reply packets. */
|
||||
for(i=0; i<num; i++) {
|
||||
char callline[1024];
|
||||
if(vtest >= 2)
|
||||
printf("xfr packet %d/%d\n", i+1, num);
|
||||
|
||||
/* read packet keyword */
|
||||
if(!(s=read_next_keyword(callline, sizeof(callline), in)))
|
||||
fatal_exit("could not read next line for "
|
||||
"tsig-sign-reply-xfr %d", i+1);
|
||||
if(strcmp(s, "packet")!=0)
|
||||
fatal_exit("expected 'packet', but read '%s'",
|
||||
callline);
|
||||
if(!read_packet_hex("", &reply_pkt, in, fname))
|
||||
fatal_exit("Could not read reply packet");
|
||||
|
||||
/* read call arguments */
|
||||
if(!(s=read_next_keyword(callline, sizeof(callline), in)))
|
||||
fatal_exit("could not read next line for "
|
||||
"tsig-sign-reply-xfr %d", i+1);
|
||||
if(strncmp(s, "call", 4) == 0) {
|
||||
s = get_arg_on_line(s, "call");
|
||||
timestr = get_next_arg_on_line(&s);
|
||||
expectedstr2 = get_next_arg_on_line(&s);
|
||||
timepoint = (uint64_t)atoll(timestr);
|
||||
if(timepoint == 0 && strcmp(timestr, "0") != 0)
|
||||
fatal_exit("expected time argument for %s", timestr);
|
||||
expected_result2 = atoi(expectedstr2);
|
||||
if(expected_result2 == 0 && strcmp(expectedstr2, "0") != 0)
|
||||
fatal_exit("expected int argument for %s", expectedstr2);
|
||||
} else {
|
||||
fatal_exit("unknown line '%s' is not 'call' for %d in "
|
||||
"tsig-sign-reply-xfr", s, i+1);
|
||||
}
|
||||
|
||||
/* read check-packet keyword */
|
||||
if(!(s=read_next_keyword(callline, sizeof(callline), in)))
|
||||
fatal_exit("could not read next line for "
|
||||
"tsig-sign-reply-xfr %d", i+1);
|
||||
if(strcmp(s, "check-packet")!=0)
|
||||
fatal_exit("expected 'check-packet', but read '%s'",
|
||||
callline);
|
||||
if(!read_packet_hex("", &check_pkt, in, fname))
|
||||
fatal_exit("Could not read check packet");
|
||||
|
||||
if(vtest >= 2) {
|
||||
char* str = sldns_wire2str_pkt(sldns_buffer_begin(&reply_pkt),
|
||||
sldns_buffer_limit(&reply_pkt));
|
||||
if(str)
|
||||
printf("reply packet: %s\n", str);
|
||||
else
|
||||
printf("could not wire2str_pkt\n");
|
||||
free(str);
|
||||
}
|
||||
if(vtest) {
|
||||
printf("call with %d %d\n", (int)timepoint,
|
||||
expected_result2);
|
||||
}
|
||||
|
||||
/* Put position at the end of the packet to sign it. */
|
||||
pos = sldns_buffer_limit(&reply_pkt);
|
||||
sldns_buffer_clear(&reply_pkt);
|
||||
sldns_buffer_set_position(&reply_pkt, pos);
|
||||
if(ret != 0 && i==0) {
|
||||
/* There was an error from verify, set the rcode
|
||||
* for it */
|
||||
LDNS_RCODE_SET(sldns_buffer_begin(&reply_pkt), ret);
|
||||
}
|
||||
ret = tsig_sign_reply_xfr(tsig, &reply_pkt, key_table,
|
||||
timepoint, (i==num-1));
|
||||
sldns_buffer_flip(&reply_pkt);
|
||||
if(vtest) {
|
||||
if(ret == expected_result2)
|
||||
printf("function ok, %s\n", (ret?"success":"fail"));
|
||||
else
|
||||
printf("function returned %d, expected result %d\n",
|
||||
ret, expected_result2);
|
||||
}
|
||||
unit_assert(ret == expected_result2);
|
||||
|
||||
if(vtest >= 2) {
|
||||
char* str = sldns_wire2str_pkt(sldns_buffer_begin(
|
||||
&check_pkt), sldns_buffer_limit(
|
||||
&check_pkt));
|
||||
if(str)
|
||||
printf("check packet: %s\n", str);
|
||||
else
|
||||
printf("could not wire2str_pkt\n");
|
||||
free(str);
|
||||
}
|
||||
unit_assert(sldns_buffer_limit(&reply_pkt) ==
|
||||
sldns_buffer_limit(&check_pkt) &&
|
||||
memcmp(sldns_buffer_begin(&reply_pkt),
|
||||
sldns_buffer_begin(&check_pkt),
|
||||
sldns_buffer_limit(&reply_pkt)) == 0);
|
||||
if(vtest)
|
||||
printf("check-packet is equal, for %d/%d\n",
|
||||
i+1, num);
|
||||
}
|
||||
|
||||
tsig_delete(tsig);
|
||||
sldns_buffer_copy(pkt, &reply_pkt);
|
||||
}
|
||||
|
||||
/** Handle the tsig-verify-reply-xfr */
|
||||
static void
|
||||
handle_tsig_verify_reply_xfr(char* line, FILE* in, const char* fname,
|
||||
struct tsig_key_table* key_table, struct sldns_buffer* pkt)
|
||||
{
|
||||
char* arg = get_arg_on_line(line, "tsig-verify-reply-xfr");
|
||||
char* s, *numstr, *keyname, *timestr, *expectedstr, *expectedstr2,
|
||||
*laststr;
|
||||
int i, num, expected_result, expected_result2, ret, last_packet;
|
||||
uint64_t timepoint;
|
||||
struct tsig_data* tsig;
|
||||
size_t pos;
|
||||
uint8_t buf[65536];
|
||||
sldns_buffer reply_pkt;
|
||||
sldns_buffer_init_frm_data(&reply_pkt, buf, sizeof(buf));
|
||||
|
||||
s = arg;
|
||||
numstr = get_next_arg_on_line(&s);
|
||||
keyname = get_next_arg_on_line(&s);
|
||||
timestr = get_next_arg_on_line(&s);
|
||||
expectedstr = get_next_arg_on_line(&s);
|
||||
|
||||
num = atoi(numstr);
|
||||
if(num == 0 && strcmp(numstr, "0") != 0)
|
||||
fatal_exit("expected int argument for %s", numstr);
|
||||
timepoint = (uint64_t)atoll(timestr);
|
||||
if(timepoint == 0 && strcmp(timestr, "0") != 0)
|
||||
fatal_exit("expected time argument for %s", timestr);
|
||||
expected_result = atoi(expectedstr);
|
||||
if(expected_result == 0 && strcmp(expectedstr, "0") != 0)
|
||||
fatal_exit("expected int argument for %s", expectedstr);
|
||||
|
||||
if(vtest) {
|
||||
printf("tsig-verify-reply-xfr with %d %s %d %d\n", num,
|
||||
keyname, (int)timepoint, expected_result);
|
||||
}
|
||||
|
||||
tsig = tsig_create_fromstr(key_table, keyname);
|
||||
if(!tsig)
|
||||
fatal_exit("alloc fail or key not found %s", keyname);
|
||||
|
||||
/* Put position at the end of the packet to sign it. */
|
||||
pos = sldns_buffer_limit(pkt);
|
||||
sldns_buffer_clear(pkt);
|
||||
sldns_buffer_set_position(pkt, pos);
|
||||
|
||||
ret = tsig_sign_query(tsig, pkt, key_table, timepoint);
|
||||
sldns_buffer_flip(pkt);
|
||||
|
||||
if(vtest) {
|
||||
if(ret == expected_result)
|
||||
printf("function ok, %s\n", (ret?"success":"fail"));
|
||||
else
|
||||
printf("function returned %d, expected result %d\n",
|
||||
ret, expected_result);
|
||||
}
|
||||
unit_assert(ret == expected_result);
|
||||
|
||||
/* Verify the reply packets */
|
||||
for(i=0; i<num; i++) {
|
||||
char callline[1024];
|
||||
if(vtest >= 2)
|
||||
printf("xfr packet %d/%d\n", i+1, num);
|
||||
|
||||
/* read packet keyword */
|
||||
if(!(s=read_next_keyword(callline, sizeof(callline), in)))
|
||||
fatal_exit("could not read next line for "
|
||||
"tsig-verify-reply-xfr %d", i+1);
|
||||
if(strcmp(s, "packet")!=0)
|
||||
fatal_exit("expected 'packet', but read '%s'",
|
||||
callline);
|
||||
if(!read_packet_hex("", &reply_pkt, in, fname))
|
||||
fatal_exit("Could not read reply packet");
|
||||
|
||||
/* read call arguments */
|
||||
if(!(s=read_next_keyword(callline, sizeof(callline), in)))
|
||||
fatal_exit("could not read next line for "
|
||||
"tsig-verify-reply-xfr %d", i+1);
|
||||
if(strncmp(s, "call", 4) == 0) {
|
||||
s = get_arg_on_line(s, "call");
|
||||
timestr = get_next_arg_on_line(&s);
|
||||
laststr = get_next_arg_on_line(&s);
|
||||
expectedstr2 = get_next_arg_on_line(&s);
|
||||
timepoint = (uint64_t)atoll(timestr);
|
||||
if(timepoint == 0 && strcmp(timestr, "0") != 0)
|
||||
fatal_exit("expected time argument for %s", timestr);
|
||||
last_packet = atoi(laststr);
|
||||
if(last_packet == 0 && strcmp(laststr, "0") != 0)
|
||||
fatal_exit("expected int argument for %s", laststr);
|
||||
expected_result2 = atoi(expectedstr2);
|
||||
if(expected_result2 == 0 && strcmp(expectedstr2, "0") != 0)
|
||||
fatal_exit("expected int argument for %s", expectedstr2);
|
||||
} else {
|
||||
fatal_exit("unknown line '%s' is not 'call' for %d in "
|
||||
"tsig-verify-reply-xfr", s, i+1);
|
||||
}
|
||||
|
||||
if(vtest >= 2) {
|
||||
char* str = sldns_wire2str_pkt(sldns_buffer_begin(&reply_pkt),
|
||||
sldns_buffer_limit(&reply_pkt));
|
||||
if(str)
|
||||
printf("reply packet: %s\n", str);
|
||||
else
|
||||
printf("could not wire2str_pkt\n");
|
||||
free(str);
|
||||
}
|
||||
if(vtest) {
|
||||
printf("call with %d %d %d\n", (int)timepoint,
|
||||
last_packet, expected_result2);
|
||||
}
|
||||
|
||||
/* Put position before TSIG */
|
||||
if(!tsig_find_rr(&reply_pkt)) {
|
||||
if(vtest)
|
||||
printf("tsig-verify-reply-xfr found no TSIG RR\n");
|
||||
/* Set position at end, if no TSIG. */
|
||||
sldns_buffer_set_position(&reply_pkt,
|
||||
sldns_buffer_limit(&reply_pkt));
|
||||
}
|
||||
ret = tsig_parse_verify_reply_xfr(tsig, &reply_pkt, key_table,
|
||||
timepoint, last_packet);
|
||||
|
||||
if(vtest) {
|
||||
if(ret == expected_result2)
|
||||
printf("function ok, %s\n", (ret?"success":"fail"));
|
||||
else
|
||||
printf("function returned %d, expected result2 %d\n",
|
||||
ret, expected_result2);
|
||||
}
|
||||
unit_assert(ret == expected_result2);
|
||||
if(vtest)
|
||||
printf("call ok, for %d/%d\n", i+1, num);
|
||||
}
|
||||
|
||||
tsig_delete(tsig);
|
||||
}
|
||||
|
||||
|
||||
/** Handle one line from the TSIG test file */
|
||||
static void
|
||||
handle_line(char* line, struct tsig_key_table* key_table,
|
||||
@@ -907,8 +1369,14 @@ handle_line(char* line, struct tsig_key_table* key_table,
|
||||
handle_tsig_sign_shared(s, key_table, pkt);
|
||||
} else if(strncmp(s, "tsig-verify-shared", 18) == 0) {
|
||||
handle_tsig_verify_shared(s, key_table, pkt);
|
||||
} else if(strncmp(s, "tsig-sign-reply-xfr", 19) == 0) {
|
||||
handle_tsig_sign_reply_xfr(s, in, fname, key_table, pkt);
|
||||
} else if(strncmp(s, "tsig-verify-reply-xfr", 21) == 0) {
|
||||
handle_tsig_verify_reply_xfr(s, in, fname, key_table, pkt);
|
||||
} else if(strncmp(s, "tsig-sign-reply", 15) == 0) {
|
||||
handle_tsig_sign_reply(s, in,fname, key_table, pkt);
|
||||
handle_tsig_sign_reply(s, in, fname, key_table, pkt);
|
||||
} else if(strncmp(s, "tsig-verify-reply", 17) == 0) {
|
||||
handle_tsig_verify_reply(s, in, fname, key_table, pkt);
|
||||
} else if(strncmp(s, "#", 1) == 0) {
|
||||
/* skip comment */
|
||||
} else if(strcmp(s, "") == 0) {
|
||||
|
||||
@@ -638,7 +638,11 @@ verify_test(void)
|
||||
/* Allow the use of SHA1 signatures for the test,
|
||||
* in case that OpenSSL disallows use of RSASHA1
|
||||
* with rh-allow-sha1-signatures disabled. */
|
||||
#ifndef UB_ON_WINDOWS
|
||||
setenv("OPENSSL_ENABLE_SHA1_SIGNATURES", "1", 0);
|
||||
#else
|
||||
_putenv("OPENSSL_ENABLE_SHA1_SIGNATURES=1");
|
||||
#endif
|
||||
}
|
||||
#endif
|
||||
|
||||
|
||||
Reference in New Issue
Block a user