Files
unbound/testdata/edns_downstream_cookie_short.rpl
T
W.C.A. Wijngaards bd210d124b - Fix that when a partial EDNS option is in a query, the
response is a more RFC conformant FORMERR, since the EDNS
  option is malformed. Also fix to have an EDNS size for
  the reply error encoding for failed EDNS parse of the query.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-09-03 17:20:35 +02:00

75 lines
1.6 KiB
Plaintext

; config options
server:
answer-cookie: yes
cookie-secret: "000102030405060708090a0b0c0d0e0f"
access-control: 127.0.0.1 allow_cookie
access-control: 1.2.3.4 allow
local-data: "test. TXT test"
harden-short-bufsize: no
CONFIG_END
SCENARIO_BEGIN Test downstream DNS Cookies with short bufsize
; Note: When a valid hash was required, it was generated by running this test
; with an invalid one and checking the output for the valid one.
; Actual hash generation is tested with unit tests.
; Query without a client cookie ...
; There is no space in udpsize for the EDE.
STEP 0 QUERY
ENTRY_BEGIN
REPLY RD
SECTION QUESTION
test. IN TXT
SECTION ADDITIONAL
. 0 CLASS20 OPT \# 00
ENTRY_END
; ... get TC and refused
STEP 1 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA TC REFUSED
SECTION QUESTION
test. IN TXT
ENTRY_END
; Query with only a client cookie ...
; The OPT udpsize is short so the reply EDNS OPT does not fit.
STEP 20 QUERY
ENTRY_BEGIN
REPLY RD
SECTION QUESTION
test. IN TXT
SECTION ADDITIONAL
. 0 CLASS24 OPT \# 12 00 0a 00 08 31 32 33 34 35 36 37 38
ENTRY_END
; ... the BADCOOKIE and a new cookie, does not fit.
STEP 21 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA TC SERVFAIL
SECTION QUESTION
test. IN TXT
ENTRY_END
; Check an EDNS option with a too short content
; The EDNS OPT rdata is too short, for the option opt_len.
STEP 30 QUERY
ENTRY_BEGIN
REPLY RD
SECTION QUESTION
test. IN TXT
SECTION ADDITIONAL
. 32768 CLASS1230 OPT \# 04 00 0a 00 08
ENTRY_END
STEP 31 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA DO FORMERR
SECTION QUESTION
test. IN TXT
ENTRY_END
SCENARIO_END