Diego Fronza and Ondřej Surý
8781aef52e
Refactored dns_message_t for using attach/detach semantics
...
This commit will be used as a base for the next code updates in order
to have a better control of dns_message_t objects' lifetime.
2020-09-30 13:33:43 +02:00
Evan Hunt
400171aee8
update all copyright headers to eliminate the typo
2020-09-14 17:00:40 -07:00
Mark Andrews
054dc48a1f
Only read dns_master_indent and dns_master_indentstr in named
...
The old code was not thread safe w.r.t. to the use of these variable.
We now only set them at the start of execution and copy them to
the message structure so they can be safely updated. This is the
minimal change to make them thread safe.
2020-09-08 09:25:43 +10:00
Mark Andrews and Ondřej Surý
b114651445
Cast the original rcode to (dns_ttl_t) when setting extended rcode
...
Shifting (signed) integer left could trigger undefined behaviour when
the shifted value would overflow into the sign bit (e.g. 2048).
The issue was found when using AFL++ and UBSAN:
message.c:2274:33: runtime error: left shift of 2048 by 20 places cannot be represented in type 'int'
SUMMARY: UndefinedBehaviorSanitizer: undefined-behavior message.c:2274:33 in
(cherry picked from commit a347641782 )
2020-08-25 16:41:08 +02:00
Mark Andrews and Michał Kępień
6ed167ad0a
Always keep a copy of the message
...
this allows it to be available even when dns_message_parse()
returns a error.
2020-08-05 13:01:12 +02:00
Mark Andrews
1f1209e1f6
Add +yaml support for EDE
...
(cherry picked from commit 0ec77c2b92 )
2020-06-05 12:10:53 +10:00
Mark Andrews
0339907d19
Also print out valid printable utf8
...
(cherry picked from commit 1c8f9d06e2 )
(cherry picked from commit c13fb2c67f )
2020-05-13 12:18:55 +10:00
Mark Andrews
c0d34e8b05
Report Extended DNS Error codes
...
(cherry picked from commit b144ae1bb0 )
(cherry picked from commit eed4fab37b )
2020-05-13 12:18:55 +10:00
Ondřej Surý
8dea1118c7
Fix the constification of the dns_name_t * result variable for dns_tsig_identity()
...
(cherry picked from commit fa7475b77a )
2019-10-03 14:21:46 +02:00
Mark Andrews
b67c6fe8bd
Add support for displaying EDNS option LLQ.
...
(cherry picked from commit d98f446d3f )
2019-08-28 17:48:24 +10:00
Mark Andrews
f684368053
POST(optlen)
...
(cherry picked from commit 4e97f7dccc )
2019-06-04 15:49:16 +10:00
Mark Andrews
10c53d2873
Recognise EDNS Client Tag and EDNS Server Tag
...
(cherry picked from commit ee7cf180b3 )
2019-05-09 18:24:57 +10:00
Mark Andrews
ac77f8df02
using 0 instead of false
...
(cherry picked from commit da7f683abf )
2019-04-23 11:46:12 +10:00
Witold Kręcicki and Mark Andrews
736d8c5b80
Fix assertion failure in nslookup/dig/mdig when message has multiple SIG(0) options.
...
When parsing message with DNS_MESSAGE_BESTEFFORT (used exclusively in
tools, never in named itself) if we hit an invalid SIG(0) in wrong
place we continue parsing the message, and put the sig0 in msg->sig0.
If we then hit another sig0 in a proper place we see that msg->sig0
is already 'taken' and we don't free name and rdataset, and we don't
set seen_problem. This causes an assertion failure.
This fixes that issue by setting seen_problem if we hit second sig0,
tsig or opt, which causes name and rdataset to be always freed.
(cherry picked from commit 51a55ddbb7 )
2019-03-26 21:32:41 +11:00
Matthijs Mekking and Evan Hunt
326d40ab08
allow TSIG key to be added to message structure after parsing
...
up until now, message->tsigkey could only be set during parsing
of the request, but gss-tsig allows one to be created afterward.
(cherry picked from commit 879fc0285e )
2019-01-30 12:34:02 -08:00
Ondřej Surý
2f8b28efad
Hint the compiler with ISC_UNREACHABLE(); that code after INSIST(0); cannot be reached
...
(cherry picked from commit 23fff6c569 )
(cherry picked from commit 4568669807 )
2018-11-08 22:42:52 +07:00
Ondřej Surý
12a266211e
Turn (int & flag) into (int & flag) != 0 when implicitly typed to bool
...
(cherry picked from commit b2b43fd235 )
(cherry picked from commit fcd1569e2b )
2018-11-08 22:02:58 +07:00
Ondřej Surý
1084b40b44
Replace custom isc_boolean_t with C standard bool type
...
(cherry picked from commit 994e656977 )
(cherry picked from commit 884929400c )
2018-08-10 15:20:57 +02:00
Ondřej Surý
aaa76dc654
Replace custom isc_u?intNN_t types with C99 u?intNN_t types
...
(cherry picked from commit cb6a185c69 )
(cherry picked from commit d61e6a3111 )
2018-08-10 15:20:57 +02:00
Evan Hunt
8b205089b7
update file headers to remove copyright years
2018-03-14 16:40:20 -07:00
Evan Hunt
442c1530a3
final cleanup
...
- update Kyuafiles to match Atffiles
- copyrights
- CHANGES note
(cherry picked from commit 86e00cbb71 )
(cherry picked from commit 80834b5b90 )
2018-03-09 16:17:56 -08:00
Mark Andrews
7873680877
cast to unsigned
2018-02-16 14:36:56 +11:00
Mark Andrews
a5a1cbece4
4841. [bug] Address -fsanitize=undefined warnings. [RT #46786 ]
...
(cherry picked from commit 9d5a0abe81 )
2017-12-06 21:02:24 +11:00
Mukund Sivaraman
16f43564c6
Backport performance work to 9.11 ( #45637 )
2017-12-06 10:35:21 +05:30
Mark Andrews
a64daf673d
4688. [protocol] Check and display EDNS KEY TAG options (RFC 8145) in
...
messages. [RT #44804 ]
(cherry picked from commit 07741d43c8 )
2017-08-25 08:47:19 +10:00
Evan Hunt
a03f4b1ea4
[v9_11] address TSIG bypass/forgery vulnerabilities
...
4643. [security] An error in TSIG handling could permit unauthorized
zone transfers or zone updates. (CVE-2017-3142)
(CVE-2017-3143) [RT #45383 ]
(cherry picked from commit 581c1526ab )
2017-06-27 11:39:33 -07:00
Mark Andrews
ac9072210c
4615. [bug] AD could be set on truncated answer with no records
...
present in the answer and authority sections.
[RT #45140 ]
(cherry picked from commit 33e94f501f )
2017-05-03 07:52:02 +10:00
Mark Andrews
fd71f5a87f
dns_master_styleflags returns dns_masterstyle_flags_t
2017-02-20 17:38:56 +11:00
Tinderbox User
3b7f610bec
update copyright notice / whitespace
2017-01-11 23:45:54 +00:00
Evan Hunt
e63d63dc85
[v9_11] expand the flags field in dns_master_style
...
4550. [cleanup] Increased the number of available master file
output style flags from 32 to 64. [RT #44043 ]
(cherry picked from commit 2e703d7b61 )
2017-01-11 12:01:06 -08:00
Evan Hunt
7fa388dac3
[v9_11] silence warning
...
(cherry picked from commit b3aebb5890 )
2016-12-28 17:54:39 -08:00
Tinderbox User
2a2618356e
update copyright notice / whitespace
2016-12-28 23:50:44 +00:00
Mark Andrews
2595d1da35
4517. [security] Named could mishandle authority sections that were
...
missing RRSIGs triggering an assertion failure.
(CVE-2016-9444) [RT # 43632]
(cherry picked from commit 1df30cfd27c5a3c57fce357c54aaf6c702227d51)
2016-12-29 10:41:06 +11:00
wpk
b1866070ef
4545. [func] Make dnstap-read output more functionally usable.
...
[RT #43642 ]
4544. [func] Add message/payload size to dnstap-read YAML output.
[RT #43622 ]
2016-12-28 11:58:08 +01:00
Mark Andrews
348d80fb84
4534. [bug] Only set RD, RA and CD in QUERY responses. [RT #43879 ]
...
(cherry picked from commit def6b33bad )
2016-12-13 16:27:49 +11:00
Mark Andrews
db9781d4a2
4468. [bug] Address ECS option handling issues. [RT #43191 ]
...
(cherry picked from commit df17290113 )
2016-09-14 08:23:07 +10:00
Mark Andrews
700d3cb789
4467. [security] It was possible to trigger a assertion when rendering
...
a message. [RT #43139 ]
(cherry picked from commit 2bd0922cf9 )
2016-09-09 11:31:59 +10:00
Mark Andrews
6aaf3d01a1
4462. [bug] Don't describe a returned EDNS COOKIE as "good"
...
when there isn't a valid server cookie. [RT #43167 ]
(cherry picked from commit 58d622d96d )
2016-09-08 11:35:11 +10:00
Mark Andrews
0c27b3fe77
4401. [misc] Change LICENSE to MPL 2.0.
2016-06-27 14:56:38 +10:00
Evan Hunt
395e6865d5
[master] fix ECS with family==0
...
4341. [bug] Correct the handling of ECS options with
address family 0. [RT #41377 ]
2016-03-23 08:54:46 -07:00
Mark Andrews
33a4294f44
4330. [protocol] Identify the PAD option as "PAD" when printing out
...
a message.
2016-03-10 16:53:06 +11:00
Mukund Sivaraman
9da98335c1
Code cleanups ( #41656 )
2016-03-04 12:18:17 +05:30
Mark Andrews
8d00c5ab2c
4312. [bug] dig's unknown dns and edns flags (MBZ value) logging
...
was not consistent. [RT #41600 ]
2016-02-02 14:19:22 +11:00
Evan Hunt
2879ee2c72
[master] fix unchecked result
...
4295. [bug] An unchecked result in dns_message_pseudosectiontotext()
could allow incorrect text formatting of EDNS EXPIRE
options. [RT #41437 ]
2016-01-20 17:19:19 -08:00
Tinderbox User
feb1ccdaf1
update copyright notice / whitespace
2016-01-05 23:45:26 +00:00
Evan Hunt
0302fcbf7e
[master] check addrlen/scopelen fit within family address length
2016-01-05 13:39:44 -08:00
Evan Hunt
1330ae5fc2
[master] check ECS address length
2016-01-05 12:17:54 -08:00
Tinderbox User
0796eca5f7
update copyright notice / whitespace
2015-12-31 11:45:08 +00:00
Mark Andrews
292eb9c4e4
4286. [security] render_ecs errors were mishandled when printing out
...
a OPT record resulting in a assertion failure.
(CVE-2015-8705) [RT #41397 ]
(cherry picked from commit 3e0c1603a8 )
2015-12-31 22:19:46 +11:00
Mark Andrews
f647c0df9f
4281. [bug] Teach dns_message_totext about BADCOOKIE. [RT #41257 ]
2015-12-15 19:49:40 +11:00