1feee8
commit 6a833d798e87536587cd4cc14fe8d078f80b14a0
1feee8
Author: Florian Weimer <fweimer@redhat.com>
1feee8
Date:   Tue Aug 30 10:02:49 2022 +0200
1feee8
1feee8
    resolv: Add tst-resolv-aliases
1feee8
    
1feee8
    Reviewed-by: Siddhesh Poyarekar <siddhesh@sourceware.org>
1feee8
    (cherry picked from commit 87aa98aa80627553a66bdcad2701fd6307723645)
1feee8
1feee8
diff --git a/resolv/Makefile b/resolv/Makefile
1feee8
index 78165eb99e98b525..567f4c2dcf5749df 100644
1feee8
--- a/resolv/Makefile
1feee8
+++ b/resolv/Makefile
1feee8
@@ -90,6 +90,7 @@ tests += \
1feee8
   tst-ns_name_pton \
1feee8
   tst-res_hconf_reorder \
1feee8
   tst-res_hnok \
1feee8
+  tst-resolv-aliases \
1feee8
   tst-resolv-basic \
1feee8
   tst-resolv-binary \
1feee8
   tst-resolv-byaddr \
1feee8
@@ -250,6 +251,7 @@ $(objpfx)tst-resolv-ai_idn.out: $(gen-locales)
1feee8
 $(objpfx)tst-resolv-ai_idn-latin1.out: $(gen-locales)
1feee8
 $(objpfx)tst-resolv-ai_idn-nolibidn2.out: \
1feee8
   $(gen-locales) $(objpfx)tst-no-libidn2.so
1feee8
+$(objpfx)tst-resolv-aliases: $(objpfx)libresolv.so $(shared-thread-library)
1feee8
 $(objpfx)tst-resolv-basic: $(objpfx)libresolv.so $(shared-thread-library)
1feee8
 $(objpfx)tst-resolv-binary: $(objpfx)libresolv.so $(shared-thread-library)
1feee8
 $(objpfx)tst-resolv-byaddr: $(objpfx)libresolv.so $(shared-thread-library)
1feee8
diff --git a/resolv/tst-resolv-aliases.c b/resolv/tst-resolv-aliases.c
1feee8
new file mode 100644
1feee8
index 0000000000000000..b212823aa07ceb21
1feee8
--- /dev/null
1feee8
+++ b/resolv/tst-resolv-aliases.c
1feee8
@@ -0,0 +1,254 @@
1feee8
+/* Test alias handling (mainly for gethostbyname).
1feee8
+   Copyright (C) 2022 Free Software Foundation, Inc.
1feee8
+   This file is part of the GNU C Library.
1feee8
+
1feee8
+   The GNU C Library is free software; you can redistribute it and/or
1feee8
+   modify it under the terms of the GNU Lesser General Public
1feee8
+   License as published by the Free Software Foundation; either
1feee8
+   version 2.1 of the License, or (at your option) any later version.
1feee8
+
1feee8
+   The GNU C Library is distributed in the hope that it will be useful,
1feee8
+   but WITHOUT ANY WARRANTY; without even the implied warranty of
1feee8
+   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
1feee8
+   Lesser General Public License for more details.
1feee8
+
1feee8
+   You should have received a copy of the GNU Lesser General Public
1feee8
+   License along with the GNU C Library; if not, see
1feee8
+   <https://www.gnu.org/licenses/>.  */
1feee8
+
1feee8
+#include <array_length.h>
1feee8
+#include <arpa/inet.h>
1feee8
+#include <netdb.h>
1feee8
+#include <stdbool.h>
1feee8
+#include <stdio.h>
1feee8
+#include <stdlib.h>
1feee8
+#include <string.h>
1feee8
+#include <support/check.h>
1feee8
+#include <support/check_nss.h>
1feee8
+#include <support/resolv_test.h>
1feee8
+#include <support/support.h>
1feee8
+
1feee8
+#include "tst-resolv-maybe_insert_sig.h"
1feee8
+
1feee8
+/* QNAME format:
1feee8
+
1feee8
+   aADDRESSES-cCNAMES.example.net
1feee8
+
1feee8
+   CNAMES is the length of the CNAME chain, ADDRESSES is the number of
1feee8
+   addresses in the response.  The special value 255 means that there
1feee8
+   are no addresses, and the RCODE is NXDOMAIN.  */
1feee8
+static void
1feee8
+response (const struct resolv_response_context *ctx,
1feee8
+          struct resolv_response_builder *b,
1feee8
+          const char *qname, uint16_t qclass, uint16_t qtype)
1feee8
+{
1feee8
+  TEST_COMPARE (qclass, C_IN);
1feee8
+  if (qtype != T_A)
1feee8
+    TEST_COMPARE (qtype, T_AAAA);
1feee8
+
1feee8
+  unsigned int addresses, cnames;
1feee8
+  char *tail;
1feee8
+  if (sscanf (qname, "a%u-c%u%ms", &addresses, &cnames, &tail) == 3)
1feee8
+    {
1feee8
+      if (strcmp (tail, ".example.com") == 0
1feee8
+          || strcmp (tail, ".example.net.example.net") == 0
1feee8
+          || strcmp (tail, ".example.net.example.com") == 0)
1feee8
+        /* These only happen after NXDOMAIN.  */
1feee8
+        TEST_VERIFY (addresses == 255);
1feee8
+      else if (strcmp (tail, ".example.net") != 0)
1feee8
+        FAIL_EXIT1 ("invalid QNAME: %s", qname);
1feee8
+    }
1feee8
+  free (tail);
1feee8
+
1feee8
+  int rcode;
1feee8
+  if (addresses == 255)
1feee8
+    {
1feee8
+      /* Special case: Use no addresses with NXDOMAIN response.  */
1feee8
+      rcode = ns_r_nxdomain;
1feee8
+      addresses = 0;
1feee8
+    }
1feee8
+  else
1feee8
+    rcode = 0;
1feee8
+
1feee8
+  struct resolv_response_flags flags = { .rcode = rcode };
1feee8
+  resolv_response_init (b, flags);
1feee8
+  resolv_response_add_question (b, qname, qclass, qtype);
1feee8
+  resolv_response_section (b, ns_s_an);
1feee8
+  maybe_insert_sig (b, qname);
1feee8
+
1feee8
+  /* Provide the requested number of CNAME records.  */
1feee8
+  char *previous_name = (char *) qname;
1feee8
+  for (int unique = 0; unique < cnames; ++unique)
1feee8
+    {
1feee8
+      resolv_response_open_record (b, previous_name, qclass, T_CNAME, 60);
1feee8
+      char *new_name = xasprintf ("%d.alias.example", unique);
1feee8
+      resolv_response_add_name (b, new_name);
1feee8
+      resolv_response_close_record (b);
1feee8
+
1feee8
+      maybe_insert_sig (b, qname);
1feee8
+
1feee8
+      if (previous_name != qname)
1feee8
+        free (previous_name);
1feee8
+      previous_name = new_name;
1feee8
+    }
1feee8
+
1feee8
+  for (int unique = 0; unique < addresses; ++unique)
1feee8
+    {
1feee8
+      resolv_response_open_record (b, previous_name, qclass, qtype, 60);
1feee8
+
1feee8
+      if (qtype == T_A)
1feee8
+        {
1feee8
+          char ipv4[4] = {192, 0, 2, 1 + unique};
1feee8
+          resolv_response_add_data (b, &ipv4, sizeof (ipv4));
1feee8
+        }
1feee8
+      else if (qtype == T_AAAA)
1feee8
+        {
1feee8
+          char ipv6[16] =
1feee8
+            {
1feee8
+              0x20, 0x01, 0xd, 0xb8, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
1feee8
+              1 + unique
1feee8
+            };
1feee8
+          resolv_response_add_data (b, &ipv6, sizeof (ipv6));
1feee8
+        }
1feee8
+      resolv_response_close_record (b);
1feee8
+    }
1feee8
+
1feee8
+  if (previous_name != qname)
1feee8
+    free (previous_name);
1feee8
+}
1feee8
+
1feee8
+static char *
1feee8
+make_qname (bool do_search, int cnames, int addresses)
1feee8
+{
1feee8
+  return xasprintf ("a%d-c%d%s",
1feee8
+                    addresses, cnames, do_search ? "" : ".example.net");
1feee8
+}
1feee8
+
1feee8
+static void
1feee8
+check_cnames_failure (int af, bool do_search, int cnames, int addresses)
1feee8
+{
1feee8
+  char *qname = make_qname (do_search, cnames, addresses);
1feee8
+
1feee8
+  struct hostent *e;
1feee8
+  if (af == AF_UNSPEC)
1feee8
+    e = gethostbyname (qname);
1feee8
+  else
1feee8
+    e = gethostbyname2 (qname, af);
1feee8
+
1feee8
+  if (addresses == 0)
1feee8
+    check_hostent (qname, e, "error: NO_RECOVERY\n");
1feee8
+  else
1feee8
+    check_hostent (qname, e, "error: HOST_NOT_FOUND\n");
1feee8
+
1feee8
+  free (qname);
1feee8
+}
1feee8
+
1feee8
+static void
1feee8
+check (int af, bool do_search, int cnames, int addresses)
1feee8
+{
1feee8
+  char *qname = make_qname (do_search, cnames, addresses);
1feee8
+  char *fqdn = make_qname (false, cnames, addresses);
1feee8
+
1feee8
+  struct hostent *e;
1feee8
+  if (af == AF_UNSPEC)
1feee8
+    e = gethostbyname (qname);
1feee8
+  else
1feee8
+    e = gethostbyname2 (qname, af);
1feee8
+  if (e == NULL)
1feee8
+    FAIL_EXIT1 ("unexpected failure for %d, %d, %d", af, cnames, addresses);
1feee8
+
1feee8
+  if (af == AF_UNSPEC || af == AF_INET)
1feee8
+    {
1feee8
+      TEST_COMPARE (e->h_addrtype, AF_INET);
1feee8
+      TEST_COMPARE (e->h_length, 4);
1feee8
+    }
1feee8
+  else
1feee8
+    {
1feee8
+      TEST_COMPARE (e->h_addrtype, AF_INET6);
1feee8
+      TEST_COMPARE (e->h_length, 16);
1feee8
+    }
1feee8
+
1feee8
+  for (int i = 0; i < addresses; ++i)
1feee8
+    {
1feee8
+      char ipv4[4] = {192, 0, 2, 1 + i};
1feee8
+      char ipv6[16] =
1feee8
+        { 0x20, 0x01, 0xd, 0xb8, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 1 + i };
1feee8
+      char *expected = e->h_addrtype == AF_INET ? ipv4 : ipv6;
1feee8
+      TEST_COMPARE_BLOB (e->h_addr_list[i], e->h_length,
1feee8
+                         expected, e->h_length);
1feee8
+    }
1feee8
+  TEST_VERIFY (e->h_addr_list[addresses] == NULL);
1feee8
+
1feee8
+
1feee8
+  if (cnames == 0)
1feee8
+    {
1feee8
+      /* QNAME is fully qualified.  */
1feee8
+      TEST_COMPARE_STRING (e->h_name, fqdn);
1feee8
+      TEST_VERIFY (e->h_aliases[0] == NULL);
1feee8
+    }
1feee8
+  else
1feee8
+   {
1feee8
+     /* Fully-qualified QNAME is demoted to an aliases.  */
1feee8
+     TEST_COMPARE_STRING (e->h_aliases[0], fqdn);
1feee8
+
1feee8
+     for (int i = 1; i <= cnames; ++i)
1feee8
+       {
1feee8
+         char *expected = xasprintf ("%d.alias.example", i - 1);
1feee8
+         if (i == cnames)
1feee8
+           TEST_COMPARE_STRING (e->h_name, expected);
1feee8
+         else
1feee8
+           TEST_COMPARE_STRING (e->h_aliases[i], expected);
1feee8
+         free (expected);
1feee8
+       }
1feee8
+     TEST_VERIFY (e->h_aliases[cnames] == NULL);
1feee8
+   }
1feee8
+
1feee8
+  free (fqdn);
1feee8
+  free (qname);
1feee8
+}
1feee8
+
1feee8
+static int
1feee8
+do_test (void)
1feee8
+{
1feee8
+  struct resolv_test *obj = resolv_test_start
1feee8
+    ((struct resolv_redirect_config)
1feee8
+     {
1feee8
+       .response_callback = response,
1feee8
+       .search = { "example.net", "example.com" },
1feee8
+     });
1feee8
+
1feee8
+  static const int families[] = { AF_UNSPEC, AF_INET, AF_INET6 };
1feee8
+
1feee8
+  for (int do_insert_sig = 0; do_insert_sig < 2; ++do_insert_sig)
1feee8
+    {
1feee8
+      insert_sig = do_insert_sig;
1feee8
+
1feee8
+      /* If do_search is true, a bare host name (for example, a1-c1)
1feee8
+         is used.  This exercises search path processing and FQDN
1feee8
+         qualification.  */
1feee8
+      for (int do_search = 0; do_search < 2; ++do_search)
1feee8
+        for (const int *paf = families; paf != array_end (families); ++paf)
1feee8
+          {
1feee8
+            for (int cnames = 0; cnames <= 100; ++cnames)
1feee8
+              {
1feee8
+                check_cnames_failure (*paf, do_search, cnames, 0);
1feee8
+                /* Now with NXDOMAIN responses.  */
1feee8
+                check_cnames_failure (*paf, do_search, cnames, 255);
1feee8
+              }
1feee8
+
1feee8
+            for (int cnames = 0; cnames <= 10; ++cnames)
1feee8
+              for (int addresses = 1; addresses <= 10; ++addresses)
1feee8
+                check (*paf, do_search, cnames, addresses);
1feee8
+
1feee8
+            /* The current implementation is limited to 47 aliases.
1feee8
+               Addresses do not have such a limit.  */
1feee8
+            check (*paf, do_search, 47, 60);
1feee8
+          }
1feee8
+    }
1feee8
+
1feee8
+  resolv_test_end (obj);
1feee8
+
1feee8
+  return 0;
1feee8
+}
1feee8
+
1feee8
+#include <support/test-driver.c>