1 /*************************************************
2 * fakens - A Fake Nameserver Program *
3 *************************************************/
5 /* This program exists to support the testing of DNS handling code in Exim. It
6 avoids the need to install special zones in a real nameserver. When Exim is
7 running in its (new) test harness, DNS lookups are first passed to this program
8 instead of to the real resolver. (With a few exceptions - see the discussion in
9 the test suite's README file.) The program is also passed the name of the Exim
10 spool directory; it expects to find its "zone files" in dnszones relative to
11 exim config_main_directory. Note that there is little checking in this program. The fake
12 zone files are assumed to be syntactically valid.
14 The zones that are handled are found by scanning the dnszones directory. A file
15 whose name is of the form db.ip4.x is a zone file for .x.in-addr.arpa; a file
16 whose name is of the form db.ip6.x is a zone file for .x.ip6.arpa; a file of
17 the form db.anything.else is a zone file for .anything.else. A file of the form
18 qualify.x.y specifies the domain that is used to qualify single-component
19 names, except for the name "dontqualify".
21 The arguments to the program are:
23 the name of the Exim spool directory
24 the domain name that is being sought
25 the DNS record type that is being sought
27 The output from the program is written to stdout. It is supposed to be in
28 exactly the same format as a traditional namserver response (see RFC 1035) so
29 that Exim can process it as normal. At present, no compression is used.
30 Error messages are written to stderr.
32 The return codes from the program are zero for success, and otherwise the
33 values that are set in h_errno after a failing call to the normal resolver:
35 1 HOST_NOT_FOUND host not found (authoritative)
36 2 TRY_AGAIN server failure
37 3 NO_RECOVERY non-recoverable error
38 4 NO_DATA valid name, no data of requested type
40 In a real nameserver, TRY_AGAIN is also used for a non-authoritative not found,
41 but it is not used for that here. There is also one extra return code:
43 5 PASS_ON requests Exim to call res_search()
45 This is used for zones that fakens does not recognize. It is also used if a
46 line in the zone file contains exactly this:
50 and the domain is not found. It converts the the result to PASS_ON instead of
53 Any DNS record line in a zone file can be prefixed with "DELAY=" and
54 a number of milliseconds (followed by one space).
56 Any DNS record line in a zone file can be prefixed with "DNSSEC ";
57 if all the records found by a lookup are marked
58 as such then the response will have the "AD" bit set.
60 Any DNS record line in a zone file can be prefixed with "AA "
61 if all the records found by a lookup are marked
62 as such then the response will have the "AA" bit set.
64 Any DNS record line in a zone file can be prefixed with "TTL=" and
65 a number of seconds (followed by one space).
77 #include <arpa/nameser.h>
78 #include <sys/types.h>
87 typedef unsigned char uschar;
90 #define CCS (const char *)
91 #define US (unsigned char *)
93 #define Ustrcat(s,t) strcat(CS(s),CCS(t))
94 #define Ustrchr(s,n) US strchr(CCS(s),n)
95 #define Ustrcmp(s,t) strcmp(CCS(s),CCS(t))
96 #define Ustrcpy(s,t) strcpy(CS(s),CCS(t))
97 #define Ustrlen(s) (int)strlen(CCS(s))
98 #define Ustrncmp(s,t,n) strncmp(CCS(s),CCS(t),n)
99 #define Ustrncpy(s,t,n) strncpy(CS(s),CCS(t),n)
101 typedef struct zoneitem {
106 typedef struct tlist {
111 #define DEFAULT_TTL 3600U
113 /* On some (older?) operating systems, the standard ns_t_xxx definitions are
114 not available, and only the older T_xxx ones exist in nameser.h. If ns_t_a is
115 not defined, assume we are in this state. A really old system might not even
116 know about AAAA and SRV at all. */
120 # define ns_t_ns T_NS
121 # define ns_t_cname T_CNAME
122 # define ns_t_soa T_SOA
123 # define ns_t_ptr T_PTR
124 # define ns_t_mx T_MX
125 # define ns_t_txt T_TXT
126 # define ns_t_aaaa T_AAAA
127 # define ns_t_srv T_SRV
128 # define ns_t_tlsa T_TLSA
140 static tlist type_list[] = {
143 { US"CNAME", ns_t_cname },
144 { US"SOA", ns_t_soa },
145 { US"PTR", ns_t_ptr },
147 { US"TXT", ns_t_txt },
148 { US"AAAA", ns_t_aaaa },
149 { US"SRV", ns_t_srv },
150 { US"TLSA", ns_t_tlsa },
156 /*************************************************
157 * Get memory and sprintf into it *
158 *************************************************/
160 /* This is used when building a table of zones and their files.
163 format a format string
166 Returns: pointer to formatted string
170 fcopystring(uschar *format, ...)
175 va_start(ap, format);
176 vsprintf(buffer, CS format, ap);
178 yield = (uschar *)malloc(Ustrlen(buffer) + 1);
179 Ustrcpy(yield, buffer);
184 /*************************************************
185 * Pack name into memory *
186 *************************************************/
188 /* This function packs a domain name into memory according to DNS rules. At
189 present, it doesn't do any compression.
195 Returns: the updated value of pk
199 packname(uschar *name, uschar *pk)
204 while (*p != 0 && *p != '.') p++;
206 memmove(pk, name, p - name);
208 name = (*p == 0)? p : p + 1;
215 bytefield(uschar ** pp, uschar * pk)
220 while (isdigit(*p)) value = value*10 + *p++ - '0';
221 while (isspace(*p)) p++;
228 shortfield(uschar ** pp, uschar * pk)
233 while (isdigit(*p)) value = value*10 + *p++ - '0';
234 while (isspace(*p)) p++;
236 *pk++ = (value >> 8) & 255;
242 longfield(uschar ** pp, uschar * pk)
244 unsigned long value = 0;
247 while (isdigit(*p)) value = value*10 + *p++ - '0';
248 while (isspace(*p)) p++;
250 *pk++ = (value >> 24) & 255;
251 *pk++ = (value >> 16) & 255;
252 *pk++ = (value >> 8) & 255;
259 /*************************************************/
262 milliwait(struct itimerval *itval)
265 sigset_t old_sigmask;
267 if (itval->it_value.tv_usec < 100 && itval->it_value.tv_sec == 0)
269 (void)sigemptyset(&sigmask); /* Empty mask */
270 (void)sigaddset(&sigmask, SIGALRM); /* Add SIGALRM */
271 (void)sigprocmask(SIG_BLOCK, &sigmask, &old_sigmask); /* Block SIGALRM */
272 (void)setitimer(ITIMER_REAL, itval, NULL); /* Start timer */
273 (void)sigfillset(&sigmask); /* All signals */
274 (void)sigdelset(&sigmask, SIGALRM); /* Remove SIGALRM */
275 (void)sigsuspend(&sigmask); /* Until SIGALRM */
276 (void)sigprocmask(SIG_SETMASK, &old_sigmask, NULL); /* Restore mask */
282 struct itimerval itval;
283 itval.it_interval.tv_sec = 0;
284 itval.it_interval.tv_usec = 0;
285 itval.it_value.tv_sec = msec/1000;
286 itval.it_value.tv_usec = (msec % 1000) * 1000;
291 /*************************************************
292 * Scan file for RRs *
293 *************************************************/
295 /* This function scans an open "zone file" for appropriate records, and adds
296 any that are found to the output buffer.
300 zone the current zone name
301 domain the domain we are looking for
302 qtype the type of RR we want
303 qtypelen the length of qtype
304 pkptr points to the output buffer pointer; this is updated
305 countptr points to the record count; this is updated
306 dnssec points to the AD flag indicator; this is updated
307 aa points to the AA flag indicator; this is updated
309 Returns: 0 on success, else HOST_NOT_FOUND or NO_DATA or NO_RECOVERY or
310 PASS_ON - the latter if a "PASS ON NOT FOUND" line is seen
314 find_records(FILE *f, uschar *zone, uschar *domain, uschar *qtype,
315 int qtypelen, uschar **pkptr, int *countptr, BOOL * dnssec, BOOL * aa)
317 int yield = HOST_NOT_FOUND;
318 int domainlen = Ustrlen(domain);
319 BOOL pass_on_not_found = FALSE;
323 uschar rrdomain[256];
324 uschar RRdomain[256];
327 /* Decode the required type */
328 for (typeptr = type_list; typeptr->name != NULL; typeptr++)
329 { if (Ustrcmp(typeptr->name, qtype) == 0) break; }
330 if (typeptr->name == NULL)
332 fprintf(stderr, "fakens: unknown record type %s\n", qtype);
336 rrdomain[0] = 0; /* No previous domain */
337 (void)fseek(f, 0, SEEK_SET); /* Start again at the beginning */
339 if (dnssec) *dnssec = TRUE; /* cancelled by first nonsecure rec found */
340 if (aa) *aa = TRUE; /* cancelled by first non-aa rec found */
344 while (fgets(CS buffer, sizeof(buffer), f) != NULL)
348 BOOL found_cname = FALSE;
350 int tvalue = typeptr->value;
351 int qtlen = qtypelen;
355 uint ttl = DEFAULT_TTL;
358 while (isspace(*p)) p++;
359 if (*p == 0 || *p == ';') continue;
361 if (Ustrncmp(p, US"PASS ON NOT FOUND", 17) == 0)
363 pass_on_not_found = TRUE;
367 ep = buffer + Ustrlen(buffer);
368 while (isspace(ep[-1])) ep--;
374 if (Ustrncmp(p, US"DNSSEC ", 7) == 0) /* tagged as secure */
379 else if (Ustrncmp(p, US"AA ", 3) == 0) /* tagged as authoritive */
384 else if (Ustrncmp(p, US"DELAY=", 6) == 0) /* delay before response */
386 for (p += 6; *p >= '0' && *p <= '9'; p++) delay = delay*10 + *p - '0';
387 if (isspace(*p)) p++;
389 else if (Ustrncmp(p, US"TTL=", 4) == 0) /* TTL for record */
392 for (p += 4; *p >= '0' && *p <= '9'; p++) ttl = ttl*10 + *p - '0';
393 if (isspace(*p)) p++;
399 if (!isspace(*p)) /* new domain name */
401 uschar *pp = rrdomain;
402 uschar *PP = RRdomain;
418 } /* else use previous line's domain name */
420 /* Compare domain names; first check for a wildcard */
422 if (rrdomain[0] == '*')
424 int restlen = Ustrlen(rrdomain) - 1;
425 if (domainlen > restlen &&
426 Ustrcmp(domain + domainlen - restlen, rrdomain + 1) != 0) continue;
429 /* Not a wildcard RR */
431 else if (Ustrcmp(domain, rrdomain) != 0) continue;
433 /* The domain matches */
435 if (yield == HOST_NOT_FOUND) yield = NO_DATA;
437 /* Compare RR types; a CNAME record is always returned */
439 while (isspace(*p)) p++;
441 if (Ustrncmp(p, "CNAME", 5) == 0)
447 else if (Ustrncmp(p, qtype, qtypelen) != 0 || !isspace(p[qtypelen])) continue;
449 /* Found a relevant record */
453 if (dnssec && !rr_sec)
454 *dnssec = FALSE; /* cancel AD return */
457 *aa = FALSE; /* cancel AA return */
460 *countptr = *countptr + 1;
463 while (isspace(*p)) p++;
465 /* For a wildcard record, use the search name; otherwise use the record's
466 name in its original case because it might contain upper case letters. */
468 pk = packname((rrdomain[0] == '*')? domain : RRdomain, pk);
469 *pk++ = (tvalue >> 8) & 255;
470 *pk++ = (tvalue) & 255;
472 *pk++ = 1; /* class = IN */
474 *pk++ = (ttl >>24) & 255;
475 *pk++ = (ttl >>16) & 255;
476 *pk++ = (ttl >> 8) & 255;
479 rdlptr = pk; /* remember rdlength field */
482 /* The rest of the data depends on the type */
489 if (ep[-1] != '.') sprintf(CS ep, "%s.", zone);
490 pk = packname(p, pk); /* primary ns */
491 p = strtok(NULL, " ");
492 pk = packname(p , pk); /* responsible mailbox */
493 *(p += strlen(p)) = ' ';
494 while (isspace(*p)) p++;
495 pk = longfield(&p, pk); /* serial */
496 pk = longfield(&p, pk); /* refresh */
497 pk = longfield(&p, pk); /* retry */
498 pk = longfield(&p, pk); /* expire */
499 pk = longfield(&p, pk); /* minimum */
503 for (i = 0; i < 4; i++)
506 while (isdigit(*p)) value = value*10 + *p++ - '0';
512 /* The only occurrence of a double colon is for ::1 */
514 if (Ustrcmp(p, "::1") == 0)
520 else for (i = 0; i < 8; i++)
525 value = value * 16 + toupper(*p) - (isdigit(*p)? '0' : '7');
528 *pk++ = (value >> 8) & 255;
535 pk = shortfield(&p, pk);
536 if (ep[-1] != '.') sprintf(CS ep, "%s.", zone);
537 pk = packname(p, pk);
542 if (*p == '"') p++; /* Should always be the case */
543 while (*p != 0 && *p != '"') *pk++ = *p++;
548 pk = bytefield(&p, pk); /* usage */
549 pk = bytefield(&p, pk); /* selector */
550 pk = bytefield(&p, pk); /* match type */
553 value = toupper(*p) - (isdigit(*p) ? '0' : '7') << 4;
556 value |= toupper(*p) - (isdigit(*p) ? '0' : '7');
565 for (i = 0; i < 3; i++)
568 while (isdigit(*p)) value = value*10 + *p++ - '0';
569 while (isspace(*p)) p++;
570 *pk++ = (value >> 8) & 255;
579 if (ep[-1] != '.') sprintf(CS ep, "%s.", zone);
580 pk = packname(p, pk);
584 /* Fill in the length, and we are done with this RR */
586 rdlptr[0] = ((pk - rdlptr - 2) >> 8) & 255;
587 rdlptr[1] = (pk -rdlptr - 2) & 255;
591 return (yield == HOST_NOT_FOUND && pass_on_not_found)? PASS_ON : yield;
601 /*************************************************
602 * Special-purpose domains *
603 *************************************************/
606 special_manyhome(uschar * packet, uschar * domain)
608 uschar *pk = packet + 12;
612 memset(packet, 0, 12);
614 for (i = 104; i <= 111; i++) for (j = 0; j <= 255; j++)
616 pk = packname(domain, pk);
617 *pk++ = (ns_t_a >> 8) & 255;
618 *pk++ = (ns_t_a) & 255;
620 *pk++ = 1; /* class = IN */
621 pk += 4; /* TTL field; don't care */
622 rdlptr = pk; /* remember rdlength field */
625 *pk++ = 10; *pk++ = 250; *pk++ = i; *pk++ = j;
627 rdlptr[0] = ((pk - rdlptr - 2) >> 8) & 255;
628 rdlptr[1] = (pk - rdlptr - 2) & 255;
631 packet[6] = (2048 >> 8) & 255;
632 packet[7] = 2048 & 255;
636 (void)fwrite(packet, 1, pk - packet, stdout);
641 special_again(uschar * packet, uschar * domain)
643 int delay = atoi(CCS domain); /* digits at the start of the name */
644 if (delay > 0) sleep(delay);
649 /*************************************************
650 * Entry point and main program *
651 *************************************************/
654 main(int argc, char **argv)
658 int domlen, qtypelen;
664 uschar *qualify = NULL;
666 uschar *zonefile = NULL;
670 uschar packet[2048 * 32 + 32];
671 HEADER *header = (HEADER *)packet;
676 signal(SIGALRM, alarmfn);
680 fprintf(stderr, "fakens: expected 3 arguments, received %d\n", argc-1);
686 (void)sprintf(CS buffer, "%s/dnszones", argv[1]);
688 d = opendir(CCS buffer);
691 fprintf(stderr, "fakens: failed to opendir %s: %s\n", buffer,
696 while ((de = readdir(d)) != NULL)
698 uschar *name = US de->d_name;
699 if (Ustrncmp(name, "qualify.", 8) == 0)
701 qualify = fcopystring(US "%s", name + 7);
704 if (Ustrncmp(name, "db.", 3) != 0) continue;
705 if (Ustrncmp(name + 3, "ip4.", 4) == 0)
706 zones[zonecount].zone = fcopystring(US "%s.in-addr.arpa", name + 6);
707 else if (Ustrncmp(name + 3, "ip6.", 4) == 0)
708 zones[zonecount].zone = fcopystring(US "%s.ip6.arpa", name + 6);
710 zones[zonecount].zone = fcopystring(US "%s", name + 2);
711 zones[zonecount++].zonefile = fcopystring(US "%s", name);
715 /* Get the RR type and upper case it, and check that we recognize it. */
717 Ustrncpy(qtype, argv[3], sizeof(qtype));
718 qtypelen = Ustrlen(qtype);
719 for (p = qtype; *p != 0; p++) *p = toupper(*p);
721 /* Find the domain, lower case it, deal with any specials,
722 check that it is in a zone that we handle,
723 and set up the zone file name. The zone names in the table all start with a
726 domlen = Ustrlen(argv[2]);
727 if (argv[2][domlen-1] == '.') domlen--;
728 Ustrncpy(domain, argv[2], domlen);
730 for (i = 0; i < domlen; i++) domain[i] = tolower(domain[i]);
732 if (Ustrcmp(domain, "manyhome.test.ex") == 0 && Ustrcmp(qtype, "A") == 0)
733 return special_manyhome(packet, domain);
734 else if (domlen >= 14 && Ustrcmp(domain + domlen - 14, "test.again.dns") == 0)
735 return special_again(packet, domain);
736 else if (domlen >= 13 && Ustrcmp(domain + domlen - 13, "test.fail.dns") == 0)
740 if (Ustrchr(domain, '.') == NULL && qualify != NULL &&
741 Ustrcmp(domain, "dontqualify") != 0)
743 Ustrcat(domain, qualify);
744 domlen += Ustrlen(qualify);
747 for (i = 0; i < zonecount; i++)
750 zone = zones[i].zone;
751 zlen = Ustrlen(zone);
752 if (Ustrcmp(domain, zone+1) == 0 || (domlen >= zlen &&
753 Ustrcmp(domain + domlen - zlen, zone) == 0))
755 zonefile = zones[i].zonefile;
760 if (zonefile == NULL)
762 fprintf(stderr, "fakens: query not in faked zone: domain is: %s\n", domain);
766 (void)sprintf(CS buffer, "%s/dnszones/%s", argv[1], zonefile);
768 /* Initialize the start of the response packet. We don't have to fake up
769 everything, because we know that Exim will look only at the answer and
770 additional section parts. */
772 memset(packet, 0, 12);
775 /* Open the zone file. */
777 f = fopen(CS buffer, "r");
780 fprintf(stderr, "fakens: failed to open %s: %s\n", buffer, strerror(errno));
784 /* Find the records we want, and add them to the result. */
787 yield = find_records(f, zone, domain, qtype, qtypelen, &pk, &count, &dnssec, &aa);
788 if (yield == NO_RECOVERY) goto END_OFF;
789 header->ancount = htons(count);
791 /* If the AA bit should be set (as indicated by the AA prefix in the zone file),
792 we are expected to return some records in the authortive section. Bind9: If
793 there is data in the answer section, the authoritive section contains the NS
794 records, otherwise it contains the SOA record. Currently we mimic this
795 behaviour for the first case (there is some answer record).
799 find_records(f, zone, zone[0] == '.' ? zone+1 : zone, US"NS", 2, &pk, &count, NULL, NULL);
800 header->nscount = htons(count - ntohs(header->ancount));
802 /* There is no need to return any additional records because Exim no longer
803 (from release 4.61) makes any use of them. */
812 /* Close the zone file, write the result, and return. */
816 (void)fwrite(packet, 1, pk - packet, stdout);
820 /* vi: aw ai sw=2 sts=2 ts=8 et
822 /* End of fakens.c */