1 /*************************************************
2 * fakens - A Fake Nameserver Program *
3 *************************************************/
5 /* This program exists to support the testing of DNS handling code in Exim. It
6 avoids the need to install special zones in a real nameserver. When Exim is
7 running in its (new) test harness, DNS lookups are first passed to this program
8 instead of to the real resolver. (With a few exceptions - see the discussion in
9 the test suite's README file.) The program is also passed the name of the Exim
10 spool directory; it expects to find its "zone files" in dnszones relative to
11 exim config_main_directory. Note that there is little checking in this program. The fake
12 zone files are assumed to be syntactically valid.
14 The zones that are handled are found by scanning the dnszones directory. A file
15 whose name is of the form db.ip4.x is a zone file for .x.in-addr.arpa; a file
16 whose name is of the form db.ip6.x is a zone file for .x.ip6.arpa; a file of
17 the form db.anything.else is a zone file for .anything.else. A file of the form
18 qualify.x.y specifies the domain that is used to qualify single-component
19 names, except for the name "dontqualify".
21 The arguments to the program are:
23 the name of the Exim spool directory
24 the domain name that is being sought
25 the DNS record type that is being sought
27 The output from the program is written to stdout. It is supposed to be in
28 exactly the same format as a traditional namserver response (see RFC 1035) so
29 that Exim can process it as normal. At present, no compression is used.
30 Error messages are written to stderr.
32 The return codes from the program are zero for success, and otherwise the
33 values that are set in h_errno after a failing call to the normal resolver:
35 1 HOST_NOT_FOUND host not found (authoritative)
36 2 TRY_AGAIN server failure
37 3 NO_RECOVERY non-recoverable error
38 4 NO_DATA valid name, no data of requested type
40 In a real nameserver, TRY_AGAIN is also used for a non-authoritative not found,
41 but it is not used for that here. There is also one extra return code:
43 5 PASS_ON requests Exim to call res_search()
45 This is used for zones that fakens does not recognize. It is also used if a
46 line in the zone file contains exactly this:
50 and the domain is not found. It converts the the result to PASS_ON instead of
53 Any DNS record line in a zone file can be prefixed with "DELAY=" and
54 a number of milliseconds (followed by one space).
56 Any DNS record line in a zone file can be prefixed with "DNSSEC ";
57 if all the records found by a lookup are marked
58 as such then the response will have the "AD" bit set.
60 Any DNS record line in a zone file can be prefixed with "AA "
61 if all the records found by a lookup are marked
62 as such then the response will have the "AA" bit set.
64 Any DNS record line in a zone file can be prefixed with "TTL=" and
65 a number of seconds (followed by one space).
77 #include <arpa/nameser.h>
78 #include <arpa/inet.h>
79 #include <sys/types.h>
83 #ifdef HAVE_SYS_SOCKET_H
84 #include <sys/socket.h>
92 typedef unsigned char uschar;
95 #define CCS (const char *)
96 #define US (unsigned char *)
98 #define Ustrcat(s,t) strcat(CS(s),CCS(t))
99 #define Ustrchr(s,n) US strchr(CCS(s),n)
100 #define Ustrcmp(s,t) strcmp(CCS(s),CCS(t))
101 #define Ustrcpy(s,t) strcpy(CS(s),CCS(t))
102 #define Ustrlen(s) (int)strlen(CCS(s))
103 #define Ustrncmp(s,t,n) strncmp(CCS(s),CCS(t),n)
104 #define Ustrncpy(s,t,n) strncpy(CS(s),CCS(t),n)
105 #define Ustrtok(s,t) (uschar*)strtok(CS(s),CCS(t))
107 typedef struct zoneitem {
112 typedef struct tlist {
117 #define DEFAULT_TTL 3600U
119 /* On some (older?) operating systems, the standard ns_t_xxx definitions are
120 not available, and only the older T_xxx ones exist in nameser.h. If ns_t_a is
121 not defined, assume we are in this state. A really old system might not even
122 know about AAAA and SRV at all. */
126 # define ns_t_ns T_NS
127 # define ns_t_cname T_CNAME
128 # define ns_t_soa T_SOA
129 # define ns_t_ptr T_PTR
130 # define ns_t_mx T_MX
131 # define ns_t_txt T_TXT
132 # define ns_t_aaaa T_AAAA
133 # define ns_t_srv T_SRV
134 # define ns_t_tlsa T_TLSA
146 static tlist type_list[] = {
149 { US"CNAME", ns_t_cname },
150 { US"SOA", ns_t_soa },
151 { US"PTR", ns_t_ptr },
153 { US"TXT", ns_t_txt },
154 { US"AAAA", ns_t_aaaa },
155 { US"SRV", ns_t_srv },
156 { US"TLSA", ns_t_tlsa },
162 /*************************************************
163 * Get memory and sprintf into it *
164 *************************************************/
166 /* This is used when building a table of zones and their files.
169 format a format string
172 Returns: pointer to formatted string
176 fcopystring(uschar *format, ...)
181 va_start(ap, format);
182 vsprintf(buffer, CS format, ap);
184 yield = (uschar *)malloc(Ustrlen(buffer) + 1);
185 Ustrcpy(yield, buffer);
190 /*************************************************
191 * Pack name into memory *
192 *************************************************/
194 /* This function packs a domain name into memory according to DNS rules. At
195 present, it doesn't do any compression.
201 Returns: the updated value of pk
205 packname(uschar *name, uschar *pk)
210 while (*p != 0 && *p != '.') p++;
212 memmove(pk, name, p - name);
214 name = (*p == 0)? p : p + 1;
221 bytefield(uschar ** pp, uschar * pk)
226 while (isdigit(*p)) value = value*10 + *p++ - '0';
227 while (isspace(*p)) p++;
234 shortfield(uschar ** pp, uschar * pk)
239 while (isdigit(*p)) value = value*10 + *p++ - '0';
240 while (isspace(*p)) p++;
242 *pk++ = (value >> 8) & 255;
248 longfield(uschar ** pp, uschar * pk)
250 unsigned long value = 0;
253 while (isdigit(*p)) value = value*10 + *p++ - '0';
254 while (isspace(*p)) p++;
256 *pk++ = (value >> 24) & 255;
257 *pk++ = (value >> 16) & 255;
258 *pk++ = (value >> 8) & 255;
265 /*************************************************/
268 milliwait(struct itimerval *itval)
271 sigset_t old_sigmask;
273 if (itval->it_value.tv_usec < 100 && itval->it_value.tv_sec == 0)
275 (void)sigemptyset(&sigmask); /* Empty mask */
276 (void)sigaddset(&sigmask, SIGALRM); /* Add SIGALRM */
277 (void)sigprocmask(SIG_BLOCK, &sigmask, &old_sigmask); /* Block SIGALRM */
278 (void)setitimer(ITIMER_REAL, itval, NULL); /* Start timer */
279 (void)sigfillset(&sigmask); /* All signals */
280 (void)sigdelset(&sigmask, SIGALRM); /* Remove SIGALRM */
281 (void)sigsuspend(&sigmask); /* Until SIGALRM */
282 (void)sigprocmask(SIG_SETMASK, &old_sigmask, NULL); /* Restore mask */
288 struct itimerval itval;
289 itval.it_interval.tv_sec = 0;
290 itval.it_interval.tv_usec = 0;
291 itval.it_value.tv_sec = msec/1000;
292 itval.it_value.tv_usec = (msec % 1000) * 1000;
297 /*************************************************
298 * Scan file for RRs *
299 *************************************************/
301 /* This function scans an open "zone file" for appropriate records, and adds
302 any that are found to the output buffer.
306 zone the current zone name
307 domain the domain we are looking for
308 qtype the type of RR we want
309 qtypelen the length of qtype
310 pkptr points to the output buffer pointer; this is updated
311 countptr points to the record count; this is updated
312 dnssec points to the AD flag indicator; this is updated
313 aa points to the AA flag indicator; this is updated
315 Returns: 0 on success, else HOST_NOT_FOUND or NO_DATA or NO_RECOVERY or
316 PASS_ON - the latter if a "PASS ON NOT FOUND" line is seen
320 find_records(FILE *f, uschar *zone, uschar *domain, uschar *qtype,
321 int qtypelen, uschar **pkptr, int *countptr, BOOL * dnssec, BOOL * aa)
323 int yield = HOST_NOT_FOUND;
324 int domainlen = Ustrlen(domain);
325 BOOL pass_on_not_found = FALSE;
329 uschar rrdomain[256];
330 uschar RRdomain[256];
333 /* Decode the required type */
334 for (typeptr = type_list; typeptr->name != NULL; typeptr++)
335 { if (Ustrcmp(typeptr->name, qtype) == 0) break; }
336 if (typeptr->name == NULL)
338 fprintf(stderr, "fakens: unknown record type %s\n", qtype);
342 rrdomain[0] = 0; /* No previous domain */
343 (void)fseek(f, 0, SEEK_SET); /* Start again at the beginning */
345 if (dnssec) *dnssec = TRUE; /* cancelled by first nonsecure rec found */
346 if (aa) *aa = TRUE; /* cancelled by first non-aa rec found */
350 while (fgets(CS buffer, sizeof(buffer), f) != NULL)
354 BOOL found_cname = FALSE;
356 int tvalue = typeptr->value;
357 int qtlen = qtypelen;
361 uint ttl = DEFAULT_TTL;
364 while (isspace(*p)) p++;
365 if (*p == 0 || *p == ';') continue;
367 if (Ustrncmp(p, US"PASS ON NOT FOUND", 17) == 0)
369 pass_on_not_found = TRUE;
373 ep = buffer + Ustrlen(buffer);
374 while (isspace(ep[-1])) ep--;
380 if (Ustrncmp(p, US"DNSSEC ", 7) == 0) /* tagged as secure */
385 else if (Ustrncmp(p, US"AA ", 3) == 0) /* tagged as authoritive */
390 else if (Ustrncmp(p, US"DELAY=", 6) == 0) /* delay before response */
392 for (p += 6; *p >= '0' && *p <= '9'; p++) delay = delay*10 + *p - '0';
393 if (isspace(*p)) p++;
395 else if (Ustrncmp(p, US"TTL=", 4) == 0) /* TTL for record */
398 for (p += 4; *p >= '0' && *p <= '9'; p++) ttl = ttl*10 + *p - '0';
399 if (isspace(*p)) p++;
405 if (!isspace(*p)) /* new domain name */
407 uschar *pp = rrdomain;
408 uschar *PP = RRdomain;
424 } /* else use previous line's domain name */
426 /* Compare domain names; first check for a wildcard */
428 if (rrdomain[0] == '*')
430 int restlen = Ustrlen(rrdomain) - 1;
431 if (domainlen > restlen &&
432 Ustrcmp(domain + domainlen - restlen, rrdomain + 1) != 0) continue;
435 /* Not a wildcard RR */
437 else if (Ustrcmp(domain, rrdomain) != 0) continue;
439 /* The domain matches */
441 if (yield == HOST_NOT_FOUND) yield = NO_DATA;
443 /* Compare RR types; a CNAME record is always returned */
445 while (isspace(*p)) p++;
447 if (Ustrncmp(p, "CNAME", 5) == 0)
453 else if (Ustrncmp(p, qtype, qtypelen) != 0 || !isspace(p[qtypelen])) continue;
455 /* Found a relevant record */
459 if (dnssec && !rr_sec)
460 *dnssec = FALSE; /* cancel AD return */
463 *aa = FALSE; /* cancel AA return */
466 *countptr = *countptr + 1;
469 while (isspace(*p)) p++;
471 /* For a wildcard record, use the search name; otherwise use the record's
472 name in its original case because it might contain upper case letters. */
474 pk = packname((rrdomain[0] == '*')? domain : RRdomain, pk);
475 *pk++ = (tvalue >> 8) & 255;
476 *pk++ = (tvalue) & 255;
478 *pk++ = 1; /* class = IN */
480 *pk++ = (ttl >>24) & 255;
481 *pk++ = (ttl >>16) & 255;
482 *pk++ = (ttl >> 8) & 255;
485 rdlptr = pk; /* remember rdlength field */
488 /* The rest of the data depends on the type */
495 if (ep[-1] != '.') sprintf(CS ep, "%s.", zone);
496 pk = packname(p, pk); /* primary ns */
497 p = Ustrtok(NULL, " ");
498 pk = packname(p , pk); /* responsible mailbox */
499 *(p += Ustrlen(p)) = ' ';
500 while (isspace(*p)) p++;
501 pk = longfield(&p, pk); /* serial */
502 pk = longfield(&p, pk); /* refresh */
503 pk = longfield(&p, pk); /* retry */
504 pk = longfield(&p, pk); /* expire */
505 pk = longfield(&p, pk); /* minimum */
509 inet_pton(AF_INET, CCS p, pk); /* FIXME: error checking */
514 inet_pton(AF_INET6, CCS p, pk); /* FIXME: error checking */
519 pk = shortfield(&p, pk);
520 if (ep[-1] != '.') sprintf(CS ep, "%s.", zone);
521 pk = packname(p, pk);
526 if (*p == '"') p++; /* Should always be the case */
527 while (*p != 0 && *p != '"') *pk++ = *p++;
532 pk = bytefield(&p, pk); /* usage */
533 pk = bytefield(&p, pk); /* selector */
534 pk = bytefield(&p, pk); /* match type */
537 value = toupper(*p) - (isdigit(*p) ? '0' : '7') << 4;
540 value |= toupper(*p) - (isdigit(*p) ? '0' : '7');
549 for (i = 0; i < 3; i++)
552 while (isdigit(*p)) value = value*10 + *p++ - '0';
553 while (isspace(*p)) p++;
554 *pk++ = (value >> 8) & 255;
563 if (ep[-1] != '.') sprintf(CS ep, "%s.", zone);
564 pk = packname(p, pk);
568 /* Fill in the length, and we are done with this RR */
570 rdlptr[0] = ((pk - rdlptr - 2) >> 8) & 255;
571 rdlptr[1] = (pk -rdlptr - 2) & 255;
575 return (yield == HOST_NOT_FOUND && pass_on_not_found)? PASS_ON : yield;
585 /*************************************************
586 * Special-purpose domains *
587 *************************************************/
590 special_manyhome(uschar * packet, uschar * domain)
592 uschar *pk = packet + 12;
596 memset(packet, 0, 12);
598 for (i = 104; i <= 111; i++) for (j = 0; j <= 255; j++)
600 pk = packname(domain, pk);
601 *pk++ = (ns_t_a >> 8) & 255;
602 *pk++ = (ns_t_a) & 255;
604 *pk++ = 1; /* class = IN */
605 pk += 4; /* TTL field; don't care */
606 rdlptr = pk; /* remember rdlength field */
609 *pk++ = 10; *pk++ = 250; *pk++ = i; *pk++ = j;
611 rdlptr[0] = ((pk - rdlptr - 2) >> 8) & 255;
612 rdlptr[1] = (pk - rdlptr - 2) & 255;
615 packet[6] = (2048 >> 8) & 255;
616 packet[7] = 2048 & 255;
620 (void)fwrite(packet, 1, pk - packet, stdout);
625 special_again(uschar * packet, uschar * domain)
627 int delay = atoi(CCS domain); /* digits at the start of the name */
628 if (delay > 0) sleep(delay);
633 /*************************************************
634 * Entry point and main program *
635 *************************************************/
638 main(int argc, char **argv)
642 int domlen, qtypelen;
648 uschar *qualify = NULL;
650 uschar *zonefile = NULL;
654 uschar packet[2048 * 32 + 32];
655 HEADER *header = (HEADER *)packet;
660 signal(SIGALRM, alarmfn);
664 fprintf(stderr, "fakens: expected 3 arguments, received %d\n", argc-1);
670 (void)sprintf(CS buffer, "%s/dnszones", argv[1]);
672 d = opendir(CCS buffer);
675 fprintf(stderr, "fakens: failed to opendir %s: %s\n", buffer,
680 while ((de = readdir(d)) != NULL)
682 uschar *name = US de->d_name;
683 if (Ustrncmp(name, "qualify.", 8) == 0)
685 qualify = fcopystring(US "%s", name + 7);
688 if (Ustrncmp(name, "db.", 3) != 0) continue;
689 if (Ustrncmp(name + 3, "ip4.", 4) == 0)
690 zones[zonecount].zone = fcopystring(US "%s.in-addr.arpa", name + 6);
691 else if (Ustrncmp(name + 3, "ip6.", 4) == 0)
692 zones[zonecount].zone = fcopystring(US "%s.ip6.arpa", name + 6);
694 zones[zonecount].zone = fcopystring(US "%s", name + 2);
695 zones[zonecount++].zonefile = fcopystring(US "%s", name);
699 /* Get the RR type and upper case it, and check that we recognize it. */
701 Ustrncpy(qtype, argv[3], sizeof(qtype));
702 qtypelen = Ustrlen(qtype);
703 for (p = qtype; *p != 0; p++) *p = toupper(*p);
705 /* Find the domain, lower case it, deal with any specials,
706 check that it is in a zone that we handle,
707 and set up the zone file name. The zone names in the table all start with a
710 domlen = Ustrlen(argv[2]);
711 if (argv[2][domlen-1] == '.') domlen--;
712 Ustrncpy(domain, argv[2], domlen);
714 for (i = 0; i < domlen; i++) domain[i] = tolower(domain[i]);
716 if (Ustrcmp(domain, "manyhome.test.ex") == 0 && Ustrcmp(qtype, "A") == 0)
717 return special_manyhome(packet, domain);
718 else if (domlen >= 14 && Ustrcmp(domain + domlen - 14, "test.again.dns") == 0)
719 return special_again(packet, domain);
720 else if (domlen >= 13 && Ustrcmp(domain + domlen - 13, "test.fail.dns") == 0)
724 if (Ustrchr(domain, '.') == NULL && qualify != NULL &&
725 Ustrcmp(domain, "dontqualify") != 0)
727 Ustrcat(domain, qualify);
728 domlen += Ustrlen(qualify);
731 for (i = 0; i < zonecount; i++)
734 zone = zones[i].zone;
735 zlen = Ustrlen(zone);
736 if (Ustrcmp(domain, zone+1) == 0 || (domlen >= zlen &&
737 Ustrcmp(domain + domlen - zlen, zone) == 0))
739 zonefile = zones[i].zonefile;
744 if (zonefile == NULL)
746 fprintf(stderr, "fakens: query not in faked zone: domain is: %s\n", domain);
750 (void)sprintf(CS buffer, "%s/dnszones/%s", argv[1], zonefile);
752 /* Initialize the start of the response packet. We don't have to fake up
753 everything, because we know that Exim will look only at the answer and
754 additional section parts. */
756 memset(packet, 0, 12);
759 /* Open the zone file. */
761 f = fopen(CS buffer, "r");
764 fprintf(stderr, "fakens: failed to open %s: %s\n", buffer, strerror(errno));
768 /* Find the records we want, and add them to the result. */
771 yield = find_records(f, zone, domain, qtype, qtypelen, &pk, &count, &dnssec, &aa);
772 if (yield == NO_RECOVERY) goto END_OFF;
773 header->ancount = htons(count);
775 /* If the AA bit should be set (as indicated by the AA prefix in the zone file),
776 we are expected to return some records in the authortive section. Bind9: If
777 there is data in the answer section, the authoritive section contains the NS
778 records, otherwise it contains the SOA record. Currently we mimic this
779 behaviour for the first case (there is some answer record).
783 find_records(f, zone, zone[0] == '.' ? zone+1 : zone, US"NS", 2, &pk, &count, NULL, NULL);
784 header->nscount = htons(count - ntohs(header->ancount));
786 /* There is no need to return any additional records because Exim no longer
787 (from release 4.61) makes any use of them. */
796 /* Close the zone file, write the result, and return. */
800 (void)fwrite(packet, 1, pk - packet, stdout);
804 /* vi: aw ai sw=2 sts=2 ts=8 et
806 /* End of fakens.c */