1feee8
commit 480c820493add16e8dda6f3189d834223e1f4f39
1feee8
Author: Florian Weimer <fweimer@redhat.com>
1feee8
Date:   Tue Aug 30 10:02:49 2022 +0200
1feee8
1feee8
    resolv: Add new tst-resolv-invalid-cname
1feee8
    
1feee8
    This test checks resolution through CNAME chains that do not contain
1feee8
    host names (bug 12154).
1feee8
    
1feee8
    Reviewed-by: Siddhesh Poyarekar <siddhesh@sourceware.org>
1feee8
    (cherry picked from commit 9caf782276ecea4bc86fc94fbb52779736f3106d)
1feee8
1feee8
Conflicts:
1feee8
	resolv/Makefile
1feee8
	  (usual test differences)
1feee8
1feee8
diff --git a/resolv/Makefile b/resolv/Makefile
1feee8
index fded244d61068060..ea1518ec2da860c1 100644
1feee8
--- a/resolv/Makefile
1feee8
+++ b/resolv/Makefile
1feee8
@@ -99,6 +99,7 @@ tests += \
1feee8
   tst-resolv-binary \
1feee8
   tst-resolv-byaddr \
1feee8
   tst-resolv-edns \
1feee8
+  tst-resolv-invalid-cname \
1feee8
   tst-resolv-network \
1feee8
   tst-resolv-noaaaa \
1feee8
   tst-resolv-nondecimal \
1feee8
@@ -279,6 +280,8 @@ $(objpfx)tst-resolv-res_init-multi: $(objpfx)libresolv.so \
1feee8
 $(objpfx)tst-resolv-res_init-thread: $(objpfx)libresolv.so \
1feee8
   $(shared-thread-library)
1feee8
 $(objpfx)tst-resolv-noaaaa: $(objpfx)libresolv.so $(shared-thread-library)
1feee8
+$(objpfx)tst-resolv-invalid-cname: $(objpfx)libresolv.so \
1feee8
+  $(shared-thread-library)
1feee8
 $(objpfx)tst-resolv-nondecimal: $(objpfx)libresolv.so $(shared-thread-library)
1feee8
 $(objpfx)tst-resolv-qtypes: $(objpfx)libresolv.so $(shared-thread-library)
1feee8
 $(objpfx)tst-resolv-rotate: $(objpfx)libresolv.so $(shared-thread-library)
1feee8
diff --git a/resolv/tst-resolv-invalid-cname.c b/resolv/tst-resolv-invalid-cname.c
1feee8
new file mode 100644
1feee8
index 0000000000000000..ae2d4419b1978c02
1feee8
--- /dev/null
1feee8
+++ b/resolv/tst-resolv-invalid-cname.c
1feee8
@@ -0,0 +1,406 @@
1feee8
+/* Test handling of CNAMEs with non-host domain names (bug 12154).
1feee8
+   Copyright (C) 2022 Free Software Foundation, Inc.
1feee8
+   This file is part of the GNU C Library.
1feee8
+
1feee8
+   The GNU C Library is free software; you can redistribute it and/or
1feee8
+   modify it under the terms of the GNU Lesser General Public
1feee8
+   License as published by the Free Software Foundation; either
1feee8
+   version 2.1 of the License, or (at your option) any later version.
1feee8
+
1feee8
+   The GNU C Library is distributed in the hope that it will be useful,
1feee8
+   but WITHOUT ANY WARRANTY; without even the implied warranty of
1feee8
+   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
1feee8
+   Lesser General Public License for more details.
1feee8
+
1feee8
+   You should have received a copy of the GNU Lesser General Public
1feee8
+   License along with the GNU C Library; if not, see
1feee8
+   <https://www.gnu.org/licenses/>.  */
1feee8
+
1feee8
+#include <errno.h>
1feee8
+#include <netdb.h>
1feee8
+#include <resolv.h>
1feee8
+#include <stdlib.h>
1feee8
+#include <string.h>
1feee8
+#include <support/check.h>
1feee8
+#include <support/check_nss.h>
1feee8
+#include <support/resolv_test.h>
1feee8
+#include <support/support.h>
1feee8
+#include <support/xmemstream.h>
1feee8
+
1feee8
+/* Query strings describe the CNAME chain in the response.  They have
1feee8
+   the format "bitsBITS.countCOUNT.example.", where BITS and COUNT are
1feee8
+   replaced by unsigned decimal numbers.  COUNT is the number of CNAME
1feee8
+   records in the response.  BITS has two bits for each CNAME record,
1feee8
+   describing a special prefix that is added to that CNAME.
1feee8
+
1feee8
+   0: No special leading label.
1feee8
+   1: Starting with "*.".
1feee8
+   2: Starting with "-x.".
1feee8
+   3: Starting with "star.*.".
1feee8
+
1feee8
+   The first CNAME in the response using the two least significant
1feee8
+   bits.
1feee8
+
1feee8
+   For PTR queries, the QNAME format is different, it is either
1feee8
+   COUNT.BITS.168.192.in-addr.arpa. (with BITS and COUNT still
1feee8
+   decimal), or:
1feee8
+
1feee8
+COUNT.BITS0.BITS1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa.
1feee8
+
1feee8
+   where BITS and COUNT are hexadecimal.  */
1feee8
+
1feee8
+static void
1feee8
+response (const struct resolv_response_context *ctx,
1feee8
+          struct resolv_response_builder *b,
1feee8
+          const char *qname, uint16_t qclass, uint16_t qtype)
1feee8
+{
1feee8
+  TEST_COMPARE (qclass, C_IN);
1feee8
+
1feee8
+  /* The only other query type besides A is PTR.  */
1feee8
+  if (qtype != T_A && qtype != T_AAAA)
1feee8
+    TEST_COMPARE (qtype, T_PTR);
1feee8
+
1feee8
+  unsigned int bits, bits1, count;
1feee8
+  char *tail = NULL;
1feee8
+  if (sscanf (qname, "bits%u.count%u.%ms", &bits, &count, &tail) == 3)
1feee8
+    TEST_COMPARE_STRING (tail, "example");
1feee8
+  else if (strstr (qname, "in-addr.arpa") != NULL
1feee8
+           && sscanf (qname, "%u.%u.%ms", &bits, &count, &tail) == 3)
1feee8
+    TEST_COMPARE_STRING (tail, "168.192.in-addr.arpa");
1feee8
+  else if (sscanf (qname, "%x.%x.%x.%ms", &bits, &bits1, &count, &tail) == 4)
1feee8
+    {
1feee8
+      TEST_COMPARE_STRING (tail, "\
1feee8
+0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa");
1feee8
+      bits |= bits1 << 4;
1feee8
+    }
1feee8
+  else
1feee8
+    FAIL_EXIT1 ("invalid QNAME: %s\n", qname);
1feee8
+  free (tail);
1feee8
+
1feee8
+  struct resolv_response_flags flags = {};
1feee8
+  resolv_response_init (b, flags);
1feee8
+  resolv_response_add_question (b, qname, qclass, qtype);
1feee8
+  resolv_response_section (b, ns_s_an);
1feee8
+
1feee8
+  /* Provide the requested number of CNAME records.  */
1feee8
+  char *previous_name = (char *) qname;
1feee8
+  unsigned int original_bits = bits;
1feee8
+  for (int unique = 0; unique < count; ++unique)
1feee8
+    {
1feee8
+      resolv_response_open_record (b, previous_name, qclass, T_CNAME, 60);
1feee8
+
1feee8
+      static const char bits_to_prefix[4][8] = { "", "*.", "-x.", "star.*." };
1feee8
+      char *new_name = xasprintf ("%sunique%d.example",
1feee8
+                                  bits_to_prefix[bits & 3], unique);
1feee8
+      bits >>= 2;
1feee8
+      resolv_response_add_name (b, new_name);
1feee8
+      resolv_response_close_record (b);
1feee8
+
1feee8
+      if (previous_name != qname)
1feee8
+        free (previous_name);
1feee8
+      previous_name = new_name;
1feee8
+    }
1feee8
+
1feee8
+  /* Actual answer record.  */
1feee8
+  resolv_response_open_record (b, previous_name, qclass, qtype, 60);
1feee8
+  switch (qtype)
1feee8
+    {
1feee8
+    case T_A:
1feee8
+      {
1feee8
+        char ipv4[4] = {192, 168, count, original_bits};
1feee8
+        resolv_response_add_data (b, &ipv4, sizeof (ipv4));
1feee8
+      }
1feee8
+      break;
1feee8
+    case T_AAAA:
1feee8
+      {
1feee8
+        char ipv6[16] =
1feee8
+          {
1feee8
+            0x20, 0x01, 0xd, 0xb8, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
1feee8
+            count, original_bits
1feee8
+          };
1feee8
+        resolv_response_add_data (b, &ipv6, sizeof (ipv6));
1feee8
+      }
1feee8
+      break;
1feee8
+
1feee8
+    case T_PTR:
1feee8
+      {
1feee8
+        char *name = xasprintf ("bits%u.count%u.example",
1feee8
+                                original_bits, count);
1feee8
+        resolv_response_add_name (b, name);
1feee8
+        free (name);
1feee8
+      }
1feee8
+      break;
1feee8
+    }
1feee8
+  resolv_response_close_record (b);
1feee8
+
1feee8
+  if (previous_name != qname)
1feee8
+    free (previous_name);
1feee8
+}
1feee8
+
1feee8
+/* Controls which name resolution function is invoked.  */
1feee8
+enum test_mode
1feee8
+  {
1feee8
+    byname,                     /* gethostbyname.  */
1feee8
+    byname2,                    /* gethostbyname2.  */
1feee8
+    gai,                        /* getaddrinfo without AI_CANONNAME.  */
1feee8
+    gai_canon,                  /* getaddrinfo with AI_CANONNAME.  */
1feee8
+
1feee8
+    test_mode_num               /* Number of enum values.  */
1feee8
+  };
1feee8
+
1feee8
+static const char *
1feee8
+test_mode_to_string (enum test_mode mode)
1feee8
+{
1feee8
+  switch (mode)
1feee8
+    {
1feee8
+    case byname:
1feee8
+      return "byname";
1feee8
+    case byname2:
1feee8
+      return "byname2";
1feee8
+    case gai:
1feee8
+      return "gai";
1feee8
+    case gai_canon:
1feee8
+      return "gai_canon";
1feee8
+    case test_mode_num:
1feee8
+      /* Report error below.  */
1feee8
+    }
1feee8
+  FAIL_EXIT1 ("invalid test_mode: %d", mode);
1feee8
+}
1feee8
+
1feee8
+/* Append the name and aliases to OUT.  */
1feee8
+static void
1feee8
+append_names (FILE *out, const char *qname, int bits, int count,
1feee8
+              enum test_mode mode)
1feee8
+{
1feee8
+  /* Largest valid index which has a corresponding zero in bits
1feee8
+     (meaning a syntactically valid CNAME).  */
1feee8
+  int last_valid_cname = -1;
1feee8
+
1feee8
+  for (int i = 0; i < count; ++i)
1feee8
+    if ((bits & (3 << (i * 2))) == 0)
1feee8
+      last_valid_cname = i;
1feee8
+
1feee8
+  if (mode != gai)
1feee8
+    {
1feee8
+      const char *label;
1feee8
+      if (mode == gai_canon)
1feee8
+        label = "canonname";
1feee8
+      else
1feee8
+        label = "name";
1feee8
+      if (last_valid_cname >= 0)
1feee8
+        fprintf (out, "%s: unique%d.example\n", label, last_valid_cname);
1feee8
+      else
1feee8
+        fprintf (out, "%s: %s\n", label, qname);
1feee8
+    }
1feee8
+
1feee8
+  if (mode == byname || mode == byname2)
1feee8
+    {
1feee8
+      if (last_valid_cname >= 0)
1feee8
+        fprintf (out, "alias: %s\n", qname);
1feee8
+      for (int i = 0; i < count; ++i)
1feee8
+        {
1feee8
+          if ((bits & (3 << (i * 2))) == 0 && i != last_valid_cname)
1feee8
+            fprintf (out, "alias: unique%d.example\n", i);
1feee8
+        }
1feee8
+    }
1feee8
+}
1feee8
+
1feee8
+/* Append the address information to OUT.  */
1feee8
+static void
1feee8
+append_addresses (FILE *out, int af, int bits, int count, enum test_mode mode)
1feee8
+{
1feee8
+  int last = count * 256 + bits;
1feee8
+  if (mode == gai || mode == gai_canon)
1feee8
+    {
1feee8
+      if (af == AF_INET || af == AF_UNSPEC)
1feee8
+        fprintf (out, "address: STREAM/TCP 192.168.%d.%d 80\n", count, bits);
1feee8
+      if (af == AF_INET6 || af == AF_UNSPEC)
1feee8
+        {
1feee8
+          if (last == 0)
1feee8
+            fprintf (out, "address: STREAM/TCP 2001:db8:: 80\n");
1feee8
+          else
1feee8
+            fprintf (out, "address: STREAM/TCP 2001:db8::%x 80\n", last);
1feee8
+        }
1feee8
+    }
1feee8
+  else
1feee8
+    {
1feee8
+      TEST_VERIFY (af != AF_UNSPEC);
1feee8
+      if (af == AF_INET)
1feee8
+        fprintf (out, "address: 192.168.%d.%d\n", count, bits);
1feee8
+      if (af == AF_INET6)
1feee8
+        {
1feee8
+          if (last == 0)
1feee8
+            fprintf (out, "address: 2001:db8::\n");
1feee8
+          else
1feee8
+            fprintf (out, "address: 2001:db8::%x\n", last);
1feee8
+        }
1feee8
+    }
1feee8
+}
1feee8
+
1feee8
+/* Perform one test using a forward lookup.  */
1feee8
+static void
1feee8
+check_forward (int af, int bits, int count, enum test_mode mode)
1feee8
+{
1feee8
+  char *qname = xasprintf ("bits%d.count%d.example", bits, count);
1feee8
+  char *label = xasprintf ("af=%d bits=%d count=%d mode=%s qname=%s",
1feee8
+                           af, bits, count, test_mode_to_string (mode), qname);
1feee8
+
1feee8
+  struct xmemstream expected;
1feee8
+  xopen_memstream (&expected);
1feee8
+  if (mode == gai_canon)
1feee8
+    fprintf (expected.out, "flags: AI_CANONNAME\n");
1feee8
+  append_names (expected.out, qname, bits, count, mode);
1feee8
+  append_addresses (expected.out, af, bits, count, mode);
1feee8
+  xfclose_memstream (&expected);
1feee8
+
1feee8
+  if (mode == gai || mode == gai_canon)
1feee8
+    {
1feee8
+      struct addrinfo *ai;
1feee8
+      struct addrinfo hints =
1feee8
+        {
1feee8
+          .ai_family = af,
1feee8
+          .ai_socktype = SOCK_STREAM,
1feee8
+        };
1feee8
+      if (mode == gai_canon)
1feee8
+        hints.ai_flags |= AI_CANONNAME;
1feee8
+      int ret = getaddrinfo (qname, "80", &hints, &ai;;
1feee8
+      check_addrinfo (label, ai, ret, expected.buffer);
1feee8
+      if (ret == 0)
1feee8
+        freeaddrinfo (ai);
1feee8
+    }
1feee8
+  else
1feee8
+    {
1feee8
+      struct hostent *e;
1feee8
+      if (mode == gai)
1feee8
+        {
1feee8
+          TEST_COMPARE (af, AF_INET);
1feee8
+          e = gethostbyname (qname);
1feee8
+        }
1feee8
+      else
1feee8
+        {
1feee8
+          if (af != AF_INET)
1feee8
+            TEST_COMPARE (af, AF_INET6);
1feee8
+          e = gethostbyname2 (qname, af);
1feee8
+        }
1feee8
+      check_hostent (label, e, expected.buffer);
1feee8
+    }
1feee8
+
1feee8
+  free (expected.buffer);
1feee8
+  free (label);
1feee8
+  free (qname);
1feee8
+}
1feee8
+
1feee8
+/* Perform one check using a reverse lookup.  */
1feee8
+
1feee8
+static void
1feee8
+check_reverse (int af, int bits, int count)
1feee8
+{
1feee8
+  TEST_VERIFY (af == AF_INET || af == AF_INET6);
1feee8
+
1feee8
+  char *label = xasprintf ("af=%d bits=%d count=%d", af, bits, count);
1feee8
+  char *fqdn = xasprintf ("bits%d.count%d.example", bits, count);
1feee8
+
1feee8
+  struct xmemstream expected;
1feee8
+  xopen_memstream (&expected);
1feee8
+  fprintf (expected.out, "name: %s\n", fqdn);
1feee8
+  append_addresses (expected.out, af, bits, count, byname);
1feee8
+  xfclose_memstream (&expected);
1feee8
+
1feee8
+  char addr[16] = { 0 };
1feee8
+  socklen_t addrlen;
1feee8
+  if (af == AF_INET)
1feee8
+    {
1feee8
+      addr[0] = 192;
1feee8
+      addr[1] = 168;
1feee8
+      addr[2] = count;
1feee8
+      addr[3] = bits;
1feee8
+      addrlen = 4;
1feee8
+    }
1feee8
+  else
1feee8
+    {
1feee8
+      addr[0] = 0x20;
1feee8
+      addr[1] = 0x01;
1feee8
+      addr[2] = 0x0d;
1feee8
+      addr[3] = 0xb8;
1feee8
+      addr[14] = count;
1feee8
+      addr[15] = bits;
1feee8
+      addrlen = 16;
1feee8
+    }
1feee8
+
1feee8
+  struct hostent *e = gethostbyaddr (addr, addrlen, af);
1feee8
+  check_hostent (label, e, expected.buffer);
1feee8
+
1feee8
+  /* getnameinfo check is different.  There is no generic check_*
1feee8
+     function for it.  */
1feee8
+  {
1feee8
+    struct sockaddr_in sin = { };
1feee8
+    struct sockaddr_in6 sin6 = { };
1feee8
+    void *sa;
1feee8
+    socklen_t salen;
1feee8
+    if (af == AF_INET)
1feee8
+      {
1feee8
+        sin.sin_family = AF_INET;
1feee8
+        memcpy (&sin.sin_addr, addr, addrlen);
1feee8
+        sin.sin_port = htons (80);
1feee8
+        sa = &sin;
1feee8
+        salen = sizeof (sin);
1feee8
+      }
1feee8
+    else
1feee8
+      {
1feee8
+        sin6.sin6_family = AF_INET6;
1feee8
+        memcpy (&sin6.sin6_addr, addr, addrlen);
1feee8
+        sin6.sin6_port = htons (80);
1feee8
+        sa = &sin;;
1feee8
+        salen = sizeof (sin6);
1feee8
+      }
1feee8
+
1feee8
+    char host[64];
1feee8
+    char service[64];
1feee8
+    int ret = getnameinfo (sa, salen, host,
1feee8
+                           sizeof (host), service, sizeof (service),
1feee8
+                           NI_NAMEREQD | NI_NUMERICSERV);
1feee8
+    TEST_COMPARE (ret, 0);
1feee8
+    TEST_COMPARE_STRING (host, fqdn);
1feee8
+    TEST_COMPARE_STRING (service, "80");
1feee8
+  }
1feee8
+
1feee8
+  free (expected.buffer);
1feee8
+  free (fqdn);
1feee8
+  free (label);
1feee8
+}
1feee8
+
1feee8
+static int
1feee8
+do_test (void)
1feee8
+{
1feee8
+  struct resolv_test *obj = resolv_test_start
1feee8
+    ((struct resolv_redirect_config)
1feee8
+     {
1feee8
+       .response_callback = response
1feee8
+     });
1feee8
+
1feee8
+  for (int count = 0; count <= 3; ++count)
1feee8
+    for (int bits = 0; bits <= 1 << (count * 2); ++bits)
1feee8
+      {
1feee8
+        if (count > 0 && bits == count)
1feee8
+          /* The last bits value is only checked if count == 0.  */
1feee8
+          continue;
1feee8
+
1feee8
+        for (enum test_mode mode = 0; mode < test_mode_num; ++mode)
1feee8
+          {
1feee8
+            check_forward (AF_INET, bits, count, mode);
1feee8
+            if (mode != byname)
1feee8
+              check_forward (AF_INET6, bits, count, mode);
1feee8
+            if (mode == gai || mode == gai_canon)
1feee8
+              check_forward (AF_UNSPEC, bits, count, mode);
1feee8
+          }
1feee8
+
1feee8
+        check_reverse (AF_INET, bits, count);
1feee8
+        check_reverse (AF_INET6, bits, count);
1feee8
+      }
1feee8
+
1feee8
+  resolv_test_end (obj);
1feee8
+
1feee8
+  return 0;
1feee8
+}
1feee8
+
1feee8
+#include <support/test-driver.c>