tst-resolv-search.c 9.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344
  1. /* Test search/default domain name behavior.
  2. Copyright (C) 2016-2019 Free Software Foundation, Inc.
  3. This file is part of the GNU C Library.
  4. The GNU C Library is free software; you can redistribute it and/or
  5. modify it under the terms of the GNU Lesser General Public
  6. License as published by the Free Software Foundation; either
  7. version 2.1 of the License, or (at your option) any later version.
  8. The GNU C Library is distributed in the hope that it will be useful,
  9. but WITHOUT ANY WARRANTY; without even the implied warranty of
  10. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  11. Lesser General Public License for more details.
  12. You should have received a copy of the GNU Lesser General Public
  13. License along with the GNU C Library; if not, see
  14. <http://www.gnu.org/licenses/>. */
  15. #include <resolv.h>
  16. #include <stdlib.h>
  17. #include <string.h>
  18. #include <support/check.h>
  19. #include <support/check_nss.h>
  20. #include <support/resolv_test.h>
  21. #include <support/support.h>
  22. #include <support/xmemstream.h>
  23. struct item
  24. {
  25. const char *name;
  26. int response;
  27. };
  28. const struct item items[] =
  29. {
  30. {"hostname.usersys.example.com", 1},
  31. {"hostname.corp.example.com", 1},
  32. {"hostname.example.com", 1},
  33. {"mail.corp.example.com", 1},
  34. {"mail.example.com", 1},
  35. {"file.corp.example.com", 2},
  36. {"file.corp", 1},
  37. {"file.example.com", 1},
  38. {"servfail-usersys.usersys.example.com", -ns_r_servfail},
  39. {"servfail-usersys.corp.example.com", 1},
  40. {"servfail-usersys.example.com", 1},
  41. {"servfail-corp.usersys.example.com", 1},
  42. {"servfail-corp.corp.example.com", -ns_r_servfail},
  43. {"servfail-corp.example.com", 1},
  44. {"www.example.com", 1},
  45. {"large.example.com", 200},
  46. /* Test query amplification with a SERVFAIL response combined with
  47. a large RRset. */
  48. {"large-servfail.usersys.example.com", -ns_r_servfail},
  49. {"large-servfail.example.com", 2000},
  50. {}
  51. };
  52. enum
  53. {
  54. name_not_found = -1,
  55. name_no_data = -2
  56. };
  57. static int
  58. find_name (const char *name)
  59. {
  60. for (int i = 0; items[i].name != NULL; ++i)
  61. {
  62. if (strcmp (name, items[i].name) == 0)
  63. return i;
  64. }
  65. if (strcmp (name, "example.com") == 0
  66. || strcmp (name, "usersys.example.com") == 0
  67. || strcmp (name, "corp.example.com") == 0)
  68. return name_no_data;
  69. return name_not_found;
  70. }
  71. static int rcode_override_server_index = -1;
  72. static int rcode_override;
  73. static void
  74. response (const struct resolv_response_context *ctx,
  75. struct resolv_response_builder *b,
  76. const char *qname, uint16_t qclass, uint16_t qtype)
  77. {
  78. if (ctx->server_index == rcode_override_server_index)
  79. {
  80. struct resolv_response_flags flags = {.rcode = rcode_override};
  81. resolv_response_init (b, flags);
  82. resolv_response_add_question (b, qname, qclass, qtype);
  83. return;
  84. }
  85. int index = find_name (qname);
  86. struct resolv_response_flags flags = {};
  87. if (index == name_not_found)
  88. flags.rcode = ns_r_nxdomain;
  89. else if (index >= 0 && items[index].response < 0)
  90. flags.rcode = -items[index].response;
  91. else if (index >= 0 && items[index].response > 5 && !ctx->tcp)
  92. /* Force TCP if more than 5 addresses where requested. */
  93. flags.tc = true;
  94. resolv_response_init (b, flags);
  95. resolv_response_add_question (b, qname, qclass, qtype);
  96. if (flags.tc || index < 0 || items[index].response < 0)
  97. return;
  98. resolv_response_section (b, ns_s_an);
  99. for (int i = 0; i < items[index].response; ++i)
  100. {
  101. resolv_response_open_record (b, qname, qclass, qtype, 0);
  102. switch (qtype)
  103. {
  104. case T_A:
  105. {
  106. char addr[4] = {10, index, i >> 8, i};
  107. resolv_response_add_data (b, addr, sizeof (addr));
  108. }
  109. break;
  110. case T_AAAA:
  111. {
  112. char addr[16]
  113. = {0x20, 0x01, 0xd, 0xb8, 0, 0, 0, 0, 0, 0, 0, 0,
  114. 0, index + 1, (i + 1) >> 8, i + 1};
  115. resolv_response_add_data (b, addr, sizeof (addr));
  116. }
  117. break;
  118. default:
  119. support_record_failure ();
  120. printf ("error: unexpected QTYPE: %s/%u/%u\n",
  121. qname, qclass, qtype);
  122. }
  123. resolv_response_close_record (b);
  124. }
  125. }
  126. enum output_format
  127. {
  128. format_get, format_gai
  129. };
  130. static void
  131. format_expected_1 (FILE *out, int family, enum output_format format, int index)
  132. {
  133. for (int i = 0; i < items[index].response; ++i)
  134. {
  135. char address[200];
  136. switch (family)
  137. {
  138. case AF_INET:
  139. snprintf (address, sizeof (address), "10.%d.%d.%d",
  140. index, (i >> 8) & 0xff, i & 0xff);
  141. break;
  142. case AF_INET6:
  143. snprintf (address, sizeof (address), "2001:db8::%x:%x",
  144. index + 1, i + 1);
  145. break;
  146. default:
  147. FAIL_EXIT1 ("unreachable");
  148. }
  149. switch (format)
  150. {
  151. case format_get:
  152. fprintf (out, "address: %s\n", address);
  153. break;
  154. case format_gai:
  155. fprintf (out, "address: STREAM/TCP %s 80\n", address);
  156. }
  157. }
  158. }
  159. static char *
  160. format_expected (const char *fqdn, int family, enum output_format format)
  161. {
  162. int index = find_name (fqdn);
  163. TEST_VERIFY_EXIT (index >= 0);
  164. struct xmemstream stream;
  165. xopen_memstream (&stream);
  166. TEST_VERIFY_EXIT (items[index].response >= 0);
  167. if (format == format_get)
  168. fprintf (stream.out, "name: %s\n", items[index].name);
  169. if (family == AF_INET || family == AF_UNSPEC)
  170. format_expected_1 (stream.out, AF_INET, format, index);
  171. if (family == AF_INET6 || family == AF_UNSPEC)
  172. format_expected_1 (stream.out, AF_INET6, format, index);
  173. xfclose_memstream (&stream);
  174. return stream.buffer;
  175. }
  176. static void
  177. do_get (const char *name, const char *fqdn, int family)
  178. {
  179. char *expected = format_expected (fqdn, family, format_get);
  180. if (family == AF_INET)
  181. {
  182. char *query = xasprintf ("gethostbyname (\"%s\")", name);
  183. check_hostent (query, gethostbyname (name), expected);
  184. free (query);
  185. }
  186. char *query = xasprintf ("gethostbyname2 (\"%s\", %d)", name, family);
  187. check_hostent (query, gethostbyname2 (name, family), expected);
  188. /* Test res_search. */
  189. int qtype;
  190. switch (family)
  191. {
  192. case AF_INET:
  193. qtype = T_A;
  194. break;
  195. case AF_INET6:
  196. qtype = T_AAAA;
  197. break;
  198. default:
  199. qtype = -1;
  200. }
  201. if (qtype >= 0)
  202. {
  203. int sz = 512;
  204. unsigned char *response = xmalloc (sz);
  205. int ret = res_search (name, C_IN, qtype, response, sz);
  206. TEST_VERIFY_EXIT (ret >= 0);
  207. if (ret > sz)
  208. {
  209. /* Truncation. Retry with a larger buffer. */
  210. sz = 65535;
  211. unsigned char *newptr = xrealloc (response, sz);
  212. response = newptr;
  213. ret = res_search (name, C_IN, qtype, response, sz);
  214. TEST_VERIFY_EXIT (ret >= 0);
  215. TEST_VERIFY_EXIT (ret < sz);
  216. }
  217. check_dns_packet (query, response, ret, expected);
  218. free (response);
  219. }
  220. free (query);
  221. free (expected);
  222. }
  223. static void
  224. do_gai (const char *name, const char *fqdn, int family)
  225. {
  226. struct addrinfo hints =
  227. {
  228. .ai_family = family,
  229. .ai_protocol = IPPROTO_TCP,
  230. .ai_socktype = SOCK_STREAM
  231. };
  232. struct addrinfo *ai;
  233. char *query = xasprintf ("%s:80 [%d]", name, family);
  234. int ret = getaddrinfo (name, "80", &hints, &ai);
  235. char *expected = format_expected (fqdn, family, format_gai);
  236. check_addrinfo (query, ai, ret, expected);
  237. if (ret == 0)
  238. freeaddrinfo (ai);
  239. free (expected);
  240. free (query);
  241. }
  242. static void
  243. do_both (const char *name, const char *fqdn)
  244. {
  245. do_get (name, fqdn, AF_INET);
  246. do_get (name, fqdn, AF_INET6);
  247. do_gai (name, fqdn, AF_INET);
  248. do_gai (name, fqdn, AF_INET6);
  249. do_gai (name, fqdn, AF_UNSPEC);
  250. }
  251. static void
  252. do_test_all (bool unconnectable_server)
  253. {
  254. struct resolv_redirect_config config =
  255. {
  256. .response_callback = response,
  257. .search = {"usersys.example.com", "corp.example.com", "example.com"},
  258. };
  259. struct resolv_test *obj = resolv_test_start (config);
  260. if (unconnectable_server)
  261. {
  262. /* 255.255.255.255 results in an immediate connect failure. The
  263. next server will supply the answer instead. This is a
  264. triggering condition for bug 19791. */
  265. _res.nsaddr_list[0].sin_addr.s_addr = -1;
  266. _res.nsaddr_list[0].sin_port = htons (53);
  267. }
  268. do_both ("file", "file.corp.example.com");
  269. do_both ("www", "www.example.com");
  270. do_both ("servfail-usersys", "servfail-usersys.corp.example.com");
  271. do_both ("servfail-corp", "servfail-corp.usersys.example.com");
  272. do_both ("large", "large.example.com");
  273. do_both ("large-servfail", "large-servfail.example.com");
  274. do_both ("file.corp", "file.corp");
  275. /* Check that SERVFAIL and REFUSED responses do not alter the search
  276. path resolution. */
  277. rcode_override_server_index = 0;
  278. rcode_override = ns_r_servfail;
  279. do_both ("hostname", "hostname.usersys.example.com");
  280. do_both ("large", "large.example.com");
  281. do_both ("large-servfail", "large-servfail.example.com");
  282. rcode_override = ns_r_refused;
  283. do_both ("hostname", "hostname.usersys.example.com");
  284. do_both ("large", "large.example.com");
  285. do_both ("large-servfail", "large-servfail.example.com");
  286. /* Likewise, but with an NXDOMAIN for the first search path
  287. entry. */
  288. rcode_override = ns_r_servfail;
  289. do_both ("mail", "mail.corp.example.com");
  290. rcode_override = ns_r_refused;
  291. do_both ("mail", "mail.corp.example.com");
  292. /* Likewise, but with ndots handling. */
  293. rcode_override = ns_r_servfail;
  294. do_both ("file.corp", "file.corp");
  295. rcode_override = ns_r_refused;
  296. do_both ("file.corp", "file.corp");
  297. resolv_test_end (obj);
  298. }
  299. static int
  300. do_test (void)
  301. {
  302. for (int unconnectable_server = 0; unconnectable_server < 2;
  303. ++unconnectable_server)
  304. do_test_all (unconnectable_server);
  305. return 0;
  306. }
  307. #include <support/test-driver.c>