1 /*************************************************
2 * fakens - A Fake Nameserver Program *
3 *************************************************/
5 /* This program exists to support the testing of DNS handling code in Exim. It
6 avoids the need to install special zones in a real nameserver. When Exim is
7 running in its (new) test harness, DNS lookups are first passed to this program
8 instead of to the real resolver. (With a few exceptions - see the discussion in
9 the test suite's README file.) The program is also passed the name of the Exim
10 spool directory; it expects to find its "zone files" in dnszones relative to
11 exim config_main_directory. Note that there is little checking in this program. The fake
12 zone files are assumed to be syntactically valid.
14 The zones that are handled are found by scanning the dnszones directory. A file
15 whose name is of the form db.ip4.x is a zone file for .x.in-addr.arpa; a file
16 whose name is of the form db.ip6.x is a zone file for .x.ip6.arpa; a file of
17 the form db.anything.else is a zone file for .anything.else. A file of the form
18 qualify.x.y specifies the domain that is used to qualify single-component
19 names, except for the name "dontqualify".
21 The arguments to the program are:
23 the name of the Exim spool directory
24 the domain name that is being sought
25 the DNS record type that is being sought
27 The output from the program is written to stdout. It is supposed to be in
28 exactly the same format as a traditional namserver response (see RFC 1035) so
29 that Exim can process it as normal. At present, no compression is used.
30 Error messages are written to stderr.
32 The return codes from the program are zero for success, and otherwise the
33 values that are set in h_errno after a failing call to the normal resolver:
35 1 HOST_NOT_FOUND host not found (authoritative)
36 2 TRY_AGAIN server failure
37 3 NO_RECOVERY non-recoverable error
38 4 NO_DATA valid name, no data of requested type
40 In a real nameserver, TRY_AGAIN is also used for a non-authoritative not found,
41 but it is not used for that here. There is also one extra return code:
43 5 PASS_ON requests Exim to call res_search()
45 This is used for zones that fakens does not recognize. It is also used if a
46 line in the zone file contains exactly this:
50 and the domain is not found. It converts the the result to PASS_ON instead of
53 Any DNS record line in a zone file can be prefixed with "DELAY=" and
54 a number of milliseconds (followed by one space).
56 Any DNS record line in a zone file can be prefixed with "DNSSEC ";
57 if all the records found by a lookup are marked
58 as such then the response will have the "AD" bit set.
60 Any DNS record line in a zone file can be prefixed with "AA "
61 if all the records found by a lookup are marked
62 as such then the response will have the "AA" bit set.
64 Any DNS record line in a zone file can be prefixed with "TTL=" and
65 a number of seconds (followed by one space).
77 #include <arpa/nameser.h>
78 #include <sys/types.h>
88 typedef unsigned char uschar;
91 #define CCS (const char *)
92 #define US (unsigned char *)
94 #define Ustrcat(s,t) strcat(CS(s),CCS(t))
95 #define Ustrchr(s,n) US strchr(CCS(s),n)
96 #define Ustrcmp(s,t) strcmp(CCS(s),CCS(t))
97 #define Ustrcpy(s,t) strcpy(CS(s),CCS(t))
98 #define Ustrlen(s) (int)strlen(CCS(s))
99 #define Ustrncmp(s,t,n) strncmp(CCS(s),CCS(t),n)
100 #define Ustrncpy(s,t,n) strncpy(CS(s),CCS(t),n)
102 typedef struct zoneitem {
107 typedef struct tlist {
112 #define DEFAULT_TTL 3600U
114 /* On some (older?) operating systems, the standard ns_t_xxx definitions are
115 not available, and only the older T_xxx ones exist in nameser.h. If ns_t_a is
116 not defined, assume we are in this state. A really old system might not even
117 know about AAAA and SRV at all. */
121 # define ns_t_ns T_NS
122 # define ns_t_cname T_CNAME
123 # define ns_t_soa T_SOA
124 # define ns_t_ptr T_PTR
125 # define ns_t_mx T_MX
126 # define ns_t_txt T_TXT
127 # define ns_t_aaaa T_AAAA
128 # define ns_t_srv T_SRV
129 # define ns_t_tlsa T_TLSA
141 static tlist type_list[] = {
144 { US"CNAME", ns_t_cname },
145 { US"SOA", ns_t_soa },
146 { US"PTR", ns_t_ptr },
148 { US"TXT", ns_t_txt },
149 { US"AAAA", ns_t_aaaa },
150 { US"SRV", ns_t_srv },
151 { US"TLSA", ns_t_tlsa },
157 /*************************************************
158 * Get memory and sprintf into it *
159 *************************************************/
161 /* This is used when building a table of zones and their files.
164 format a format string
167 Returns: pointer to formatted string
171 fcopystring(uschar *format, ...)
176 va_start(ap, format);
177 vsprintf(buffer, CS format, ap);
179 yield = (uschar *)malloc(Ustrlen(buffer) + 1);
180 Ustrcpy(yield, buffer);
185 /*************************************************
186 * Pack name into memory *
187 *************************************************/
189 /* This function packs a domain name into memory according to DNS rules. At
190 present, it doesn't do any compression.
196 Returns: the updated value of pk
200 packname(uschar *name, uschar *pk)
205 while (*p != 0 && *p != '.') p++;
207 memmove(pk, name, p - name);
209 name = (*p == 0)? p : p + 1;
216 bytefield(uschar ** pp, uschar * pk)
221 while (isdigit(*p)) value = value*10 + *p++ - '0';
222 while (isspace(*p)) p++;
229 shortfield(uschar ** pp, uschar * pk)
234 while (isdigit(*p)) value = value*10 + *p++ - '0';
235 while (isspace(*p)) p++;
237 *pk++ = (value >> 8) & 255;
243 longfield(uschar ** pp, uschar * pk)
245 unsigned long value = 0;
248 while (isdigit(*p)) value = value*10 + *p++ - '0';
249 while (isspace(*p)) p++;
251 *pk++ = (value >> 24) & 255;
252 *pk++ = (value >> 16) & 255;
253 *pk++ = (value >> 8) & 255;
260 /*************************************************/
263 milliwait(struct itimerval *itval)
266 sigset_t old_sigmask;
268 if (itval->it_value.tv_usec < 100 && itval->it_value.tv_sec == 0)
270 (void)sigemptyset(&sigmask); /* Empty mask */
271 (void)sigaddset(&sigmask, SIGALRM); /* Add SIGALRM */
272 (void)sigprocmask(SIG_BLOCK, &sigmask, &old_sigmask); /* Block SIGALRM */
273 (void)setitimer(ITIMER_REAL, itval, NULL); /* Start timer */
274 (void)sigfillset(&sigmask); /* All signals */
275 (void)sigdelset(&sigmask, SIGALRM); /* Remove SIGALRM */
276 (void)sigsuspend(&sigmask); /* Until SIGALRM */
277 (void)sigprocmask(SIG_SETMASK, &old_sigmask, NULL); /* Restore mask */
283 struct itimerval itval;
284 itval.it_interval.tv_sec = 0;
285 itval.it_interval.tv_usec = 0;
286 itval.it_value.tv_sec = msec/1000;
287 itval.it_value.tv_usec = (msec % 1000) * 1000;
292 /*************************************************
293 * Scan file for RRs *
294 *************************************************/
296 /* This function scans an open "zone file" for appropriate records, and adds
297 any that are found to the output buffer.
301 zone the current zone name
302 domain the domain we are looking for
303 qtype the type of RR we want
304 qtypelen the length of qtype
305 pkptr points to the output buffer pointer; this is updated
306 countptr points to the record count; this is updated
307 dnssec points to the AD flag indicator; this is updated
308 aa points to the AA flag indicator; this is updated
310 Returns: 0 on success, else HOST_NOT_FOUND or NO_DATA or NO_RECOVERY or
311 PASS_ON - the latter if a "PASS ON NOT FOUND" line is seen
315 find_records(FILE *f, uschar *zone, uschar *domain, uschar *qtype,
316 int qtypelen, uschar **pkptr, int *countptr, BOOL * dnssec, BOOL * aa)
318 int yield = HOST_NOT_FOUND;
319 int domainlen = Ustrlen(domain);
320 BOOL pass_on_not_found = FALSE;
324 uschar rrdomain[256];
325 uschar RRdomain[256];
328 /* Decode the required type */
329 for (typeptr = type_list; typeptr->name != NULL; typeptr++)
330 { if (Ustrcmp(typeptr->name, qtype) == 0) break; }
331 if (typeptr->name == NULL)
333 fprintf(stderr, "fakens: unknown record type %s\n", qtype);
337 rrdomain[0] = 0; /* No previous domain */
338 (void)fseek(f, 0, SEEK_SET); /* Start again at the beginning */
340 if (dnssec) *dnssec = TRUE; /* cancelled by first nonsecure rec found */
341 if (aa) *aa = TRUE; /* cancelled by first non-aa rec found */
345 while (fgets(CS buffer, sizeof(buffer), f) != NULL)
349 BOOL found_cname = FALSE;
351 int tvalue = typeptr->value;
352 int qtlen = qtypelen;
356 uint ttl = DEFAULT_TTL;
359 while (isspace(*p)) p++;
360 if (*p == 0 || *p == ';') continue;
362 if (Ustrncmp(p, US"PASS ON NOT FOUND", 17) == 0)
364 pass_on_not_found = TRUE;
368 ep = buffer + Ustrlen(buffer);
369 while (isspace(ep[-1])) ep--;
375 if (Ustrncmp(p, US"DNSSEC ", 7) == 0) /* tagged as secure */
380 else if (Ustrncmp(p, US"AA ", 3) == 0) /* tagged as authoritive */
385 else if (Ustrncmp(p, US"DELAY=", 6) == 0) /* delay before response */
387 for (p += 6; *p >= '0' && *p <= '9'; p++) delay = delay*10 + *p - '0';
388 if (isspace(*p)) p++;
390 else if (Ustrncmp(p, US"TTL=", 4) == 0) /* TTL for record */
393 for (p += 4; *p >= '0' && *p <= '9'; p++) ttl = ttl*10 + *p - '0';
394 if (isspace(*p)) p++;
400 if (!isspace(*p)) /* new domain name */
402 uschar *pp = rrdomain;
403 uschar *PP = RRdomain;
419 } /* else use previous line's domain name */
421 /* Compare domain names; first check for a wildcard */
423 if (rrdomain[0] == '*')
425 int restlen = Ustrlen(rrdomain) - 1;
426 if (domainlen > restlen &&
427 Ustrcmp(domain + domainlen - restlen, rrdomain + 1) != 0) continue;
430 /* Not a wildcard RR */
432 else if (Ustrcmp(domain, rrdomain) != 0) continue;
434 /* The domain matches */
436 if (yield == HOST_NOT_FOUND) yield = NO_DATA;
438 /* Compare RR types; a CNAME record is always returned */
440 while (isspace(*p)) p++;
442 if (Ustrncmp(p, "CNAME", 5) == 0)
448 else if (Ustrncmp(p, qtype, qtypelen) != 0 || !isspace(p[qtypelen])) continue;
450 /* Found a relevant record */
454 if (dnssec && !rr_sec)
455 *dnssec = FALSE; /* cancel AD return */
458 *aa = FALSE; /* cancel AA return */
461 *countptr = *countptr + 1;
464 while (isspace(*p)) p++;
466 /* For a wildcard record, use the search name; otherwise use the record's
467 name in its original case because it might contain upper case letters. */
469 pk = packname((rrdomain[0] == '*')? domain : RRdomain, pk);
470 *pk++ = (tvalue >> 8) & 255;
471 *pk++ = (tvalue) & 255;
473 *pk++ = 1; /* class = IN */
475 *pk++ = (ttl >>24) & 255;
476 *pk++ = (ttl >>16) & 255;
477 *pk++ = (ttl >> 8) & 255;
480 rdlptr = pk; /* remember rdlength field */
483 /* The rest of the data depends on the type */
490 if (ep[-1] != '.') sprintf(CS ep, "%s.", zone);
491 pk = packname(p, pk); /* primary ns */
492 p = strtok(NULL, " ");
493 pk = packname(p , pk); /* responsible mailbox */
494 *(p += strlen(p)) = ' ';
495 while (isspace(*p)) p++;
496 pk = longfield(&p, pk); /* serial */
497 pk = longfield(&p, pk); /* refresh */
498 pk = longfield(&p, pk); /* retry */
499 pk = longfield(&p, pk); /* expire */
500 pk = longfield(&p, pk); /* minimum */
504 for (i = 0; i < 4; i++)
507 while (isdigit(*p)) value = value*10 + *p++ - '0';
513 /* The only occurrence of a double colon is for ::1 */
515 if (Ustrcmp(p, "::1") == 0)
521 else for (i = 0; i < 8; i++)
526 value = value * 16 + toupper(*p) - (isdigit(*p)? '0' : '7');
529 *pk++ = (value >> 8) & 255;
536 pk = shortfield(&p, pk);
537 if (ep[-1] != '.') sprintf(CS ep, "%s.", zone);
538 pk = packname(p, pk);
543 if (*p == '"') p++; /* Should always be the case */
544 while (*p != 0 && *p != '"') *pk++ = *p++;
549 pk = bytefield(&p, pk); /* usage */
550 pk = bytefield(&p, pk); /* selector */
551 pk = bytefield(&p, pk); /* match type */
554 value = toupper(*p) - (isdigit(*p) ? '0' : '7') << 4;
557 value |= toupper(*p) - (isdigit(*p) ? '0' : '7');
566 for (i = 0; i < 3; i++)
569 while (isdigit(*p)) value = value*10 + *p++ - '0';
570 while (isspace(*p)) p++;
571 *pk++ = (value >> 8) & 255;
580 if (ep[-1] != '.') sprintf(CS ep, "%s.", zone);
581 pk = packname(p, pk);
585 /* Fill in the length, and we are done with this RR */
587 rdlptr[0] = ((pk - rdlptr - 2) >> 8) & 255;
588 rdlptr[1] = (pk -rdlptr - 2) & 255;
592 return (yield == HOST_NOT_FOUND && pass_on_not_found)? PASS_ON : yield;
602 /*************************************************
603 * Special-purpose domains *
604 *************************************************/
607 special_manyhome(uschar * packet, uschar * domain)
609 uschar *pk = packet + 12;
613 memset(packet, 0, 12);
615 for (i = 104; i <= 111; i++) for (j = 0; j <= 255; j++)
617 pk = packname(domain, pk);
618 *pk++ = (ns_t_a >> 8) & 255;
619 *pk++ = (ns_t_a) & 255;
621 *pk++ = 1; /* class = IN */
622 pk += 4; /* TTL field; don't care */
623 rdlptr = pk; /* remember rdlength field */
626 *pk++ = 10; *pk++ = 250; *pk++ = i; *pk++ = j;
628 rdlptr[0] = ((pk - rdlptr - 2) >> 8) & 255;
629 rdlptr[1] = (pk - rdlptr - 2) & 255;
632 packet[6] = (2048 >> 8) & 255;
633 packet[7] = 2048 & 255;
637 (void)fwrite(packet, 1, pk - packet, stdout);
642 special_again(uschar * packet, uschar * domain)
644 int delay = atoi(CCS domain); /* digits at the start of the name */
645 if (delay > 0) sleep(delay);
650 /*************************************************
651 * Entry point and main program *
652 *************************************************/
655 main(int argc, char **argv)
659 int domlen, qtypelen;
665 uschar *qualify = NULL;
667 uschar *zonefile = NULL;
671 uschar packet[2048 * 32 + 32];
672 HEADER *header = (HEADER *)packet;
677 signal(SIGALRM, alarmfn);
681 fprintf(stderr, "fakens: expected 3 arguments, received %d\n", argc-1);
687 (void)sprintf(CS buffer, "%s/dnszones", argv[1]);
689 d = opendir(CCS buffer);
692 fprintf(stderr, "fakens: failed to opendir %s: %s\n", buffer,
697 while ((de = readdir(d)) != NULL)
699 uschar *name = US de->d_name;
700 if (Ustrncmp(name, "qualify.", 8) == 0)
702 qualify = fcopystring(US "%s", name + 7);
705 if (Ustrncmp(name, "db.", 3) != 0) continue;
706 if (Ustrncmp(name + 3, "ip4.", 4) == 0)
707 zones[zonecount].zone = fcopystring(US "%s.in-addr.arpa", name + 6);
708 else if (Ustrncmp(name + 3, "ip6.", 4) == 0)
709 zones[zonecount].zone = fcopystring(US "%s.ip6.arpa", name + 6);
711 zones[zonecount].zone = fcopystring(US "%s", name + 2);
712 zones[zonecount++].zonefile = fcopystring(US "%s", name);
716 /* Get the RR type and upper case it, and check that we recognize it. */
718 Ustrncpy(qtype, argv[3], sizeof(qtype));
719 qtypelen = Ustrlen(qtype);
720 for (p = qtype; *p != 0; p++) *p = toupper(*p);
722 /* Find the domain, lower case it, deal with any specials,
723 check that it is in a zone that we handle,
724 and set up the zone file name. The zone names in the table all start with a
727 domlen = Ustrlen(argv[2]);
728 if (argv[2][domlen-1] == '.') domlen--;
729 Ustrncpy(domain, argv[2], domlen);
731 for (i = 0; i < domlen; i++) domain[i] = tolower(domain[i]);
733 if (Ustrcmp(domain, "manyhome.test.ex") == 0 && Ustrcmp(qtype, "A") == 0)
734 return special_manyhome(packet, domain);
735 else if (domlen >= 14 && Ustrcmp(domain + domlen - 14, "test.again.dns") == 0)
736 return special_again(packet, domain);
737 else if (domlen >= 13 && Ustrcmp(domain + domlen - 13, "test.fail.dns") == 0)
741 if (Ustrchr(domain, '.') == NULL && qualify != NULL &&
742 Ustrcmp(domain, "dontqualify") != 0)
744 Ustrcat(domain, qualify);
745 domlen += Ustrlen(qualify);
748 for (i = 0; i < zonecount; i++)
751 zone = zones[i].zone;
752 zlen = Ustrlen(zone);
753 if (Ustrcmp(domain, zone+1) == 0 || (domlen >= zlen &&
754 Ustrcmp(domain + domlen - zlen, zone) == 0))
756 zonefile = zones[i].zonefile;
761 if (zonefile == NULL)
763 fprintf(stderr, "fakens: query not in faked zone: domain is: %s\n", domain);
767 (void)sprintf(CS buffer, "%s/dnszones/%s", argv[1], zonefile);
769 /* Initialize the start of the response packet. We don't have to fake up
770 everything, because we know that Exim will look only at the answer and
771 additional section parts. */
773 memset(packet, 0, 12);
776 /* Open the zone file. */
778 f = fopen(CS buffer, "r");
781 fprintf(stderr, "fakens: failed to open %s: %s\n", buffer, strerror(errno));
785 /* Find the records we want, and add them to the result. */
788 yield = find_records(f, zone, domain, qtype, qtypelen, &pk, &count, &dnssec, &aa);
789 if (yield == NO_RECOVERY) goto END_OFF;
790 header->ancount = htons(count);
792 /* If the AA bit should be set (as indicated by the AA prefix in the zone file),
793 we are expected to return some records in the authortive section. Bind9: If
794 there is data in the answer section, the authoritive section contains the NS
795 records, otherwise it contains the SOA record. Currently we mimic this
796 behaviour for the first case (there is some answer record).
800 find_records(f, zone, zone[0] == '.' ? zone+1 : zone, US"NS", 2, &pk, &count, NULL, NULL);
801 header->nscount = htons(count - ntohs(header->ancount));
803 /* There is no need to return any additional records because Exim no longer
804 (from release 4.61) makes any use of them. */
813 /* Close the zone file, write the result, and return. */
817 (void)fwrite(packet, 1, pk - packet, stdout);
821 /* vi: aw ai sw=2 sts=2 ts=8 et
823 /* End of fakens.c */