1 /*************************************************
2 * fakens - A Fake Nameserver Program *
3 *************************************************/
5 /* This program exists to support the testing of DNS handling code in Exim. It
6 avoids the need to install special zones in a real nameserver. When Exim is
7 running in its (new) test harness, DNS lookups are first passed to this program
8 instead of to the real resolver. (With a few exceptions - see the discussion in
9 the test suite's README file.) The program is also passed the name of the Exim
10 spool directory; it expects to find its "zone files" in ../dnszones relative to
11 that directory. Note that there is little checking in this program. The fake
12 zone files are assumed to be syntactically valid.
14 The zones that are handled are found by scanning the dnszones directory. A file
15 whose name is of the form db.ip4.x is a zone file for .x.in-addr.arpa; a file
16 whose name is of the form db.ip6.x is a zone file for .x.ip6.arpa; a file of
17 the form db.anything.else is a zone file for .anything.else. A file of the form
18 qualify.x.y specifies the domain that is used to qualify single-component
19 names, except for the name "dontqualify".
21 The arguments to the program are:
23 the name of the Exim spool directory
24 the domain name that is being sought
25 the DNS record type that is being sought
27 The output from the program is written to stdout. It is supposed to be in
28 exactly the same format as a traditional namserver response (see RFC 1035) so
29 that Exim can process it as normal. At present, no compression is used.
30 Error messages are written to stderr.
32 The return codes from the program are zero for success, and otherwise the
33 values that are set in h_errno after a failing call to the normal resolver:
35 1 HOST_NOT_FOUND host not found (authoritative)
36 2 TRY_AGAIN server failure
37 3 NO_RECOVERY non-recoverable error
38 4 NO_DATA valid name, no data of requested type
40 In a real nameserver, TRY_AGAIN is also used for a non-authoritative not found,
41 but it is not used for that here. There is also one extra return code:
43 5 PASS_ON requests Exim to call res_search()
45 This is used for zones that fakens does not recognize. It is also used if a
46 line in the zone file contains exactly this:
50 and the domain is not found. It converts the the result to PASS_ON instead of
53 Any DNS record line in a zone file can be prefixed with "DNSSEC" and
54 at least one space; if all the records found by a lookup are marked
55 as such then the response will have the "AD" bit set. */
63 #include <arpa/nameser.h>
64 #include <sys/types.h>
72 typedef unsigned char uschar;
75 #define CCS (const char *)
76 #define US (unsigned char *)
78 #define Ustrcat(s,t) strcat(CS(s),CCS(t))
79 #define Ustrchr(s,n) US strchr(CCS(s),n)
80 #define Ustrcmp(s,t) strcmp(CCS(s),CCS(t))
81 #define Ustrcpy(s,t) strcpy(CS(s),CCS(t))
82 #define Ustrlen(s) (int)strlen(CCS(s))
83 #define Ustrncmp(s,t,n) strncmp(CCS(s),CCS(t),n)
84 #define Ustrncpy(s,t,n) strncpy(CS(s),CCS(t),n)
86 typedef struct zoneitem {
91 typedef struct tlist {
96 /* On some (older?) operating systems, the standard ns_t_xxx definitions are
97 not available, and only the older T_xxx ones exist in nameser.h. If ns_t_a is
98 not defined, assume we are in this state. A really old system might not even
99 know about AAAA and SRV at all. */
104 #define ns_t_cname T_CNAME
105 #define ns_t_soa T_SOA
106 #define ns_t_ptr T_PTR
108 #define ns_t_txt T_TXT
109 #define ns_t_aaaa T_AAAA
110 #define ns_t_srv T_SRV
119 static tlist type_list[] = {
122 { US"CNAME", ns_t_cname },
123 /* { US"SOA", ns_t_soa }, Not currently in use */
124 { US"PTR", ns_t_ptr },
126 { US"TXT", ns_t_txt },
127 { US"AAAA", ns_t_aaaa },
128 { US"SRV", ns_t_srv },
134 /*************************************************
135 * Get memory and sprintf into it *
136 *************************************************/
138 /* This is used when building a table of zones and their files.
141 format a format string
144 Returns: pointer to formatted string
148 fcopystring(uschar *format, ...)
153 va_start(ap, format);
154 vsprintf(buffer, format, ap);
156 yield = (uschar *)malloc(Ustrlen(buffer) + 1);
157 Ustrcpy(yield, buffer);
162 /*************************************************
163 * Pack name into memory *
164 *************************************************/
166 /* This function packs a domain name into memory according to DNS rules. At
167 present, it doesn't do any compression.
173 Returns: the updated value of pk
177 packname(uschar *name, uschar *pk)
182 while (*p != 0 && *p != '.') p++;
184 memmove(pk, name, p - name);
186 name = (*p == 0)? p : p + 1;
194 /*************************************************
195 * Scan file for RRs *
196 *************************************************/
198 /* This function scans an open "zone file" for appropriate records, and adds
199 any that are found to the output buffer.
203 zone the current zone name
204 domain the domain we are looking for
205 qtype the type of RR we want
206 qtypelen the length of qtype
207 pkptr points to the output buffer pointer; this is updated
208 countptr points to the record count; this is updated
210 Returns: 0 on success, else HOST_NOT_FOUND or NO_DATA or NO_RECOVERY or
211 PASS_ON - the latter if a "PASS ON NOT FOUND" line is seen
215 find_records(FILE *f, uschar *zone, uschar *domain, uschar *qtype,
216 int qtypelen, uschar **pkptr, int *countptr, BOOL * dnssec)
218 int yield = HOST_NOT_FOUND;
219 int domainlen = Ustrlen(domain);
220 BOOL pass_on_not_found = FALSE;
224 uschar rrdomain[256];
225 uschar RRdomain[256];
227 /* Decode the required type */
229 for (typeptr = type_list; typeptr->name != NULL; typeptr++)
230 { if (Ustrcmp(typeptr->name, qtype) == 0) break; }
231 if (typeptr->name == NULL)
233 fprintf(stderr, "fakens: unknown record type %s\n", qtype);
237 rrdomain[0] = 0; /* No previous domain */
238 (void)fseek(f, 0, SEEK_SET); /* Start again at the beginning */
240 *dnssec = TRUE; /* cancelled by first nonsecure rec found */
244 while (fgets(CS buffer, sizeof(buffer), f) != NULL)
248 BOOL found_cname = FALSE;
250 int tvalue = typeptr->value;
251 int qtlen = qtypelen;
255 while (isspace(*p)) p++;
256 if (*p == 0 || *p == ';') continue;
258 if (Ustrncmp(p, US"PASS ON NOT FOUND", 17) == 0)
260 pass_on_not_found = TRUE;
264 ep = buffer + Ustrlen(buffer);
265 while (isspace(ep[-1])) ep--;
269 if (Ustrncmp(p, US"DNSSEC ", 7) == 0) /* tagged as secure */
277 uschar *pp = rrdomain;
278 uschar *PP = RRdomain;
296 /* Compare domain names; first check for a wildcard */
298 if (rrdomain[0] == '*')
300 int restlen = Ustrlen(rrdomain) - 1;
301 if (domainlen > restlen &&
302 Ustrcmp(domain + domainlen - restlen, rrdomain + 1) != 0) continue;
305 /* Not a wildcard RR */
307 else if (Ustrcmp(domain, rrdomain) != 0) continue;
309 /* The domain matches */
311 if (yield == HOST_NOT_FOUND) yield = NO_DATA;
313 /* Compare RR types; a CNAME record is always returned */
315 while (isspace(*p)) p++;
317 if (Ustrncmp(p, "CNAME", 5) == 0)
323 else if (Ustrncmp(p, qtype, qtypelen) != 0 || !isspace(p[qtypelen])) continue;
325 /* Found a relevant record */
328 *dnssec = FALSE; /* cancel AD return */
331 *countptr = *countptr + 1;
334 while (isspace(*p)) p++;
336 /* For a wildcard record, use the search name; otherwise use the record's
337 name in its original case because it might contain upper case letters. */
339 pk = packname((rrdomain[0] == '*')? domain : RRdomain, pk);
340 *pk++ = (tvalue >> 8) & 255;
341 *pk++ = (tvalue) & 255;
343 *pk++ = 1; /* class = IN */
345 pk += 4; /* TTL field; don't care */
347 rdlptr = pk; /* remember rdlength field */
350 /* The rest of the data depends on the type */
354 case ns_t_soa: /* Not currently used */
358 for (i = 0; i < 4; i++)
361 while (isdigit(*p)) value = value*10 + *p++ - '0';
367 /* The only occurrence of a double colon is for ::1 */
369 if (Ustrcmp(p, "::1") == 0)
375 else for (i = 0; i < 8; i++)
380 value = value * 16 + toupper(*p) - (isdigit(*p)? '0' : '7');
383 *pk++ = (value >> 8) & 255;
391 while (isdigit(*p)) value = value*10 + *p++ - '0';
392 while (isspace(*p)) p++;
393 *pk++ = (value >> 8) & 255;
395 if (ep[-1] != '.') sprintf(ep, "%s.", zone);
396 pk = packname(p, pk);
402 if (*p == '"') p++; /* Should always be the case */
403 while (*p != 0 && *p != '"') *pk++ = *p++;
408 for (i = 0; i < 3; i++)
411 while (isdigit(*p)) value = value*10 + *p++ - '0';
412 while (isspace(*p)) p++;
413 *pk++ = (value >> 8) & 255;
422 if (ep[-1] != '.') sprintf(ep, "%s.", zone);
423 pk = packname(p, pk);
428 /* Fill in the length, and we are done with this RR */
430 rdlptr[0] = ((pk - rdlptr - 2) >> 8) & 255;
431 rdlptr[1] = (pk -rdlptr - 2) & 255;
435 return (yield == HOST_NOT_FOUND && pass_on_not_found)? PASS_ON : yield;
440 /*************************************************
441 * Entry point and main program *
442 *************************************************/
445 main(int argc, char **argv)
449 int domlen, qtypelen;
455 uschar *qualify = NULL;
457 uschar *zonefile = NULL;
467 fprintf(stderr, "fakens: expected 3 arguments, received %d\n", argc-1);
473 (void)sprintf(buffer, "%s/../dnszones", argv[1]);
475 d = opendir(CCS buffer);
478 fprintf(stderr, "fakens: failed to opendir %s: %s\n", buffer,
483 while ((de = readdir(d)) != NULL)
485 uschar *name = de->d_name;
486 if (Ustrncmp(name, "qualify.", 8) == 0)
488 qualify = fcopystring("%s", name + 7);
491 if (Ustrncmp(name, "db.", 3) != 0) continue;
492 if (Ustrncmp(name + 3, "ip4.", 4) == 0)
493 zones[zonecount].zone = fcopystring("%s.in-addr.arpa", name + 6);
494 else if (Ustrncmp(name + 3, "ip6.", 4) == 0)
495 zones[zonecount].zone = fcopystring("%s.ip6.arpa", name + 6);
497 zones[zonecount].zone = fcopystring("%s", name + 2);
498 zones[zonecount++].zonefile = fcopystring("%s", name);
502 /* Get the RR type and upper case it, and check that we recognize it. */
504 Ustrncpy(qtype, argv[3], sizeof(qtype));
505 qtypelen = Ustrlen(qtype);
506 for (p = qtype; *p != 0; p++) *p = toupper(*p);
508 /* Find the domain, lower case it, check that it is in a zone that we handle,
509 and set up the zone file name. The zone names in the table all start with a
512 domlen = Ustrlen(argv[2]);
513 if (argv[2][domlen-1] == '.') domlen--;
514 Ustrncpy(domain, argv[2], domlen);
516 for (i = 0; i < domlen; i++) domain[i] = tolower(domain[i]);
518 if (Ustrchr(domain, '.') == NULL && qualify != NULL &&
519 Ustrcmp(domain, "dontqualify") != 0)
521 Ustrcat(domain, qualify);
522 domlen += Ustrlen(qualify);
525 for (i = 0; i < zonecount; i++)
528 zone = zones[i].zone;
529 zlen = Ustrlen(zone);
530 if (Ustrcmp(domain, zone+1) == 0 || (domlen >= zlen &&
531 Ustrcmp(domain + domlen - zlen, zone) == 0))
533 zonefile = zones[i].zonefile;
538 if (zonefile == NULL)
540 fprintf(stderr, "fakens: query not in faked zone: domain is: %s\n", domain);
544 (void)sprintf(buffer, "%s/../dnszones/%s", argv[1], zonefile);
546 /* Initialize the start of the response packet. We don't have to fake up
547 everything, because we know that Exim will look only at the answer and
548 additional section parts. */
550 memset(packet, 0, 12);
553 /* Open the zone file. */
555 f = fopen(buffer, "r");
558 fprintf(stderr, "fakens: failed to open %s: %s\n", buffer, strerror(errno));
562 /* Find the records we want, and add them to the result. */
565 yield = find_records(f, zone, domain, qtype, qtypelen, &pk, &count, &dnssec);
566 if (yield == NO_RECOVERY) goto END_OFF;
568 packet[6] = (count >> 8) & 255;
569 packet[7] = count & 255;
571 /* There is no need to return any additional records because Exim no longer
572 (from release 4.61) makes any use of them. */
578 ((HEADER *)packet)->ad = 1;
580 /* Close the zone file, write the result, and return. */
584 (void)fwrite(packet, 1, pk - packet, stdout);
590 /* End of fakens.c */