1 /*************************************************
2 * fakens - A Fake Nameserver Program *
3 *************************************************/
5 /* This program exists to support the testing of DNS handling code in Exim. It
6 avoids the need to install special zones in a real nameserver. When Exim is
7 running in its (new) test harness, DNS lookups are first passed to this program
8 instead of to the real resolver. (With a few exceptions - see the discussion in
9 the test suite's README file.) The program is also passed the name of the Exim
10 spool directory; it expects to find its "zone files" in dnszones relative to
11 exim config_main_directory. Note that there is little checking in this program. The fake
12 zone files are assumed to be syntactically valid.
14 The zones that are handled are found by scanning the dnszones directory. A file
15 whose name is of the form db.ip4.x is a zone file for .x.in-addr.arpa; a file
16 whose name is of the form db.ip6.x is a zone file for .x.ip6.arpa; a file of
17 the form db.anything.else is a zone file for .anything.else. A file of the form
18 qualify.x.y specifies the domain that is used to qualify single-component
19 names, except for the name "dontqualify".
21 The arguments to the program are:
23 the name of the Exim spool directory
24 the domain name that is being sought
25 the DNS record type that is being sought
27 The output from the program is written to stdout. It is supposed to be in
28 exactly the same format as a traditional namserver response (see RFC 1035) so
29 that Exim can process it as normal. At present, no compression is used.
30 Error messages are written to stderr.
32 The return codes from the program are zero for success, and otherwise the
33 values that are set in h_errno after a failing call to the normal resolver:
35 1 HOST_NOT_FOUND host not found (authoritative)
36 2 TRY_AGAIN server failure
37 3 NO_RECOVERY non-recoverable error
38 4 NO_DATA valid name, no data of requested type
40 In a real nameserver, TRY_AGAIN is also used for a non-authoritative not found,
41 but it is not used for that here. There is also one extra return code:
43 5 PASS_ON requests Exim to call res_search()
45 This is used for zones that fakens does not recognize. It is also used if a
46 line in the zone file contains exactly this:
50 and the domain is not found. It converts the the result to PASS_ON instead of
53 Any DNS record line in a zone file can be prefixed with "DELAY=" and
54 a number of milliseconds (followed by whitespace).
56 Any DNS record line in a zone file can be prefixed with "DNSSEC" and
57 at least one space; if all the records found by a lookup are marked
58 as such then the response will have the "AD" bit set. */
68 #include <arpa/nameser.h>
69 #include <sys/types.h>
78 typedef unsigned char uschar;
81 #define CCS (const char *)
82 #define US (unsigned char *)
84 #define Ustrcat(s,t) strcat(CS(s),CCS(t))
85 #define Ustrchr(s,n) US strchr(CCS(s),n)
86 #define Ustrcmp(s,t) strcmp(CCS(s),CCS(t))
87 #define Ustrcpy(s,t) strcpy(CS(s),CCS(t))
88 #define Ustrlen(s) (int)strlen(CCS(s))
89 #define Ustrncmp(s,t,n) strncmp(CCS(s),CCS(t),n)
90 #define Ustrncpy(s,t,n) strncpy(CS(s),CCS(t),n)
92 typedef struct zoneitem {
97 typedef struct tlist {
102 /* On some (older?) operating systems, the standard ns_t_xxx definitions are
103 not available, and only the older T_xxx ones exist in nameser.h. If ns_t_a is
104 not defined, assume we are in this state. A really old system might not even
105 know about AAAA and SRV at all. */
109 # define ns_t_ns T_NS
110 # define ns_t_cname T_CNAME
111 # define ns_t_soa T_SOA
112 # define ns_t_ptr T_PTR
113 # define ns_t_mx T_MX
114 # define ns_t_txt T_TXT
115 # define ns_t_aaaa T_AAAA
116 # define ns_t_srv T_SRV
117 # define ns_t_tlsa T_TLSA
129 static tlist type_list[] = {
132 { US"CNAME", ns_t_cname },
133 { US"SOA", ns_t_soa },
134 { US"PTR", ns_t_ptr },
136 { US"TXT", ns_t_txt },
137 { US"AAAA", ns_t_aaaa },
138 { US"SRV", ns_t_srv },
139 { US"TLSA", ns_t_tlsa },
145 /*************************************************
146 * Get memory and sprintf into it *
147 *************************************************/
149 /* This is used when building a table of zones and their files.
152 format a format string
155 Returns: pointer to formatted string
159 fcopystring(uschar *format, ...)
164 va_start(ap, format);
165 vsprintf(buffer, CS format, ap);
167 yield = (uschar *)malloc(Ustrlen(buffer) + 1);
168 Ustrcpy(yield, buffer);
173 /*************************************************
174 * Pack name into memory *
175 *************************************************/
177 /* This function packs a domain name into memory according to DNS rules. At
178 present, it doesn't do any compression.
184 Returns: the updated value of pk
188 packname(uschar *name, uschar *pk)
193 while (*p != 0 && *p != '.') p++;
195 memmove(pk, name, p - name);
197 name = (*p == 0)? p : p + 1;
204 bytefield(uschar ** pp, uschar * pk)
209 while (isdigit(*p)) value = value*10 + *p++ - '0';
210 while (isspace(*p)) p++;
217 shortfield(uschar ** pp, uschar * pk)
222 while (isdigit(*p)) value = value*10 + *p++ - '0';
223 while (isspace(*p)) p++;
225 *pk++ = (value >> 8) & 255;
231 longfield(uschar ** pp, uschar * pk)
233 unsigned long value = 0;
236 while (isdigit(*p)) value = value*10 + *p++ - '0';
237 while (isspace(*p)) p++;
239 *pk++ = (value >> 24) & 255;
240 *pk++ = (value >> 16) & 255;
241 *pk++ = (value >> 8) & 255;
248 /*************************************************/
251 milliwait(struct itimerval *itval)
254 sigset_t old_sigmask;
256 if (itval->it_value.tv_usec < 100 && itval->it_value.tv_sec == 0)
258 (void)sigemptyset(&sigmask); /* Empty mask */
259 (void)sigaddset(&sigmask, SIGALRM); /* Add SIGALRM */
260 (void)sigprocmask(SIG_BLOCK, &sigmask, &old_sigmask); /* Block SIGALRM */
261 (void)setitimer(ITIMER_REAL, itval, NULL); /* Start timer */
262 (void)sigfillset(&sigmask); /* All signals */
263 (void)sigdelset(&sigmask, SIGALRM); /* Remove SIGALRM */
264 (void)sigsuspend(&sigmask); /* Until SIGALRM */
265 (void)sigprocmask(SIG_SETMASK, &old_sigmask, NULL); /* Restore mask */
271 struct itimerval itval;
272 itval.it_interval.tv_sec = 0;
273 itval.it_interval.tv_usec = 0;
274 itval.it_value.tv_sec = msec/1000;
275 itval.it_value.tv_usec = (msec % 1000) * 1000;
280 /*************************************************
281 * Scan file for RRs *
282 *************************************************/
284 /* This function scans an open "zone file" for appropriate records, and adds
285 any that are found to the output buffer.
289 zone the current zone name
290 domain the domain we are looking for
291 qtype the type of RR we want
292 qtypelen the length of qtype
293 pkptr points to the output buffer pointer; this is updated
294 countptr points to the record count; this is updated
296 Returns: 0 on success, else HOST_NOT_FOUND or NO_DATA or NO_RECOVERY or
297 PASS_ON - the latter if a "PASS ON NOT FOUND" line is seen
301 find_records(FILE *f, uschar *zone, uschar *domain, uschar *qtype,
302 int qtypelen, uschar **pkptr, int *countptr, BOOL * dnssec)
304 int yield = HOST_NOT_FOUND;
305 int domainlen = Ustrlen(domain);
306 BOOL pass_on_not_found = FALSE;
310 uschar rrdomain[256];
311 uschar RRdomain[256];
313 /* Decode the required type */
315 for (typeptr = type_list; typeptr->name != NULL; typeptr++)
316 { if (Ustrcmp(typeptr->name, qtype) == 0) break; }
317 if (typeptr->name == NULL)
319 fprintf(stderr, "fakens: unknown record type %s\n", qtype);
323 rrdomain[0] = 0; /* No previous domain */
324 (void)fseek(f, 0, SEEK_SET); /* Start again at the beginning */
326 *dnssec = TRUE; /* cancelled by first nonsecure rec found */
330 while (fgets(CS buffer, sizeof(buffer), f) != NULL)
334 BOOL found_cname = FALSE;
336 int tvalue = typeptr->value;
337 int qtlen = qtypelen;
342 while (isspace(*p)) p++;
343 if (*p == 0 || *p == ';') continue;
345 if (Ustrncmp(p, US"PASS ON NOT FOUND", 17) == 0)
347 pass_on_not_found = TRUE;
351 ep = buffer + Ustrlen(buffer);
352 while (isspace(ep[-1])) ep--;
358 if (Ustrncmp(p, US"DNSSEC ", 7) == 0) /* tagged as secure */
363 else if (Ustrncmp(p, US"DELAY=", 6) == 0) /* delay before response */
365 for (p += 6; *p >= '0' && *p <= '9'; p++) delay = delay*10 + *p - '0';
366 while (isspace(*p)) p++;
374 uschar *pp = rrdomain;
375 uschar *PP = RRdomain;
393 /* Compare domain names; first check for a wildcard */
395 if (rrdomain[0] == '*')
397 int restlen = Ustrlen(rrdomain) - 1;
398 if (domainlen > restlen &&
399 Ustrcmp(domain + domainlen - restlen, rrdomain + 1) != 0) continue;
402 /* Not a wildcard RR */
404 else if (Ustrcmp(domain, rrdomain) != 0) continue;
406 /* The domain matches */
408 if (yield == HOST_NOT_FOUND) yield = NO_DATA;
410 /* Compare RR types; a CNAME record is always returned */
412 while (isspace(*p)) p++;
414 if (Ustrncmp(p, "CNAME", 5) == 0)
420 else if (Ustrncmp(p, qtype, qtypelen) != 0 || !isspace(p[qtypelen])) continue;
422 /* Found a relevant record */
428 *dnssec = FALSE; /* cancel AD return */
431 *countptr = *countptr + 1;
434 while (isspace(*p)) p++;
436 /* For a wildcard record, use the search name; otherwise use the record's
437 name in its original case because it might contain upper case letters. */
439 pk = packname((rrdomain[0] == '*')? domain : RRdomain, pk);
440 *pk++ = (tvalue >> 8) & 255;
441 *pk++ = (tvalue) & 255;
443 *pk++ = 1; /* class = IN */
445 pk += 4; /* TTL field; don't care */
447 rdlptr = pk; /* remember rdlength field */
450 /* The rest of the data depends on the type */
457 if (ep[-1] != '.') sprintf(CS ep, "%s.", zone);
458 pk = packname(p, pk); /* primary ns */
459 p = strtok(NULL, " ");
460 pk = packname(p , pk); /* responsible mailbox */
461 *(p += strlen(p)) = ' ';
462 while (isspace(*p)) p++;
463 pk = longfield(&p, pk); /* serial */
464 pk = longfield(&p, pk); /* refresh */
465 pk = longfield(&p, pk); /* retry */
466 pk = longfield(&p, pk); /* expire */
467 pk = longfield(&p, pk); /* minimum */
471 for (i = 0; i < 4; i++)
474 while (isdigit(*p)) value = value*10 + *p++ - '0';
480 /* The only occurrence of a double colon is for ::1 */
482 if (Ustrcmp(p, "::1") == 0)
488 else for (i = 0; i < 8; i++)
493 value = value * 16 + toupper(*p) - (isdigit(*p)? '0' : '7');
496 *pk++ = (value >> 8) & 255;
503 pk = shortfield(&p, pk);
504 if (ep[-1] != '.') sprintf(CS ep, "%s.", zone);
505 pk = packname(p, pk);
510 if (*p == '"') p++; /* Should always be the case */
511 while (*p != 0 && *p != '"') *pk++ = *p++;
516 pk = bytefield(&p, pk); /* usage */
517 pk = bytefield(&p, pk); /* selector */
518 pk = bytefield(&p, pk); /* match type */
521 value = toupper(*p) - (isdigit(*p) ? '0' : '7') << 4;
524 value |= toupper(*p) - (isdigit(*p) ? '0' : '7');
533 for (i = 0; i < 3; i++)
536 while (isdigit(*p)) value = value*10 + *p++ - '0';
537 while (isspace(*p)) p++;
538 *pk++ = (value >> 8) & 255;
547 if (ep[-1] != '.') sprintf(CS ep, "%s.", zone);
548 pk = packname(p, pk);
552 /* Fill in the length, and we are done with this RR */
554 rdlptr[0] = ((pk - rdlptr - 2) >> 8) & 255;
555 rdlptr[1] = (pk -rdlptr - 2) & 255;
559 return (yield == HOST_NOT_FOUND && pass_on_not_found)? PASS_ON : yield;
568 /*************************************************
569 * Entry point and main program *
570 *************************************************/
573 main(int argc, char **argv)
577 int domlen, qtypelen;
583 uschar *qualify = NULL;
585 uschar *zonefile = NULL;
589 uschar packet[2048 * 32 + 32];
593 signal(SIGALRM, alarmfn);
597 fprintf(stderr, "fakens: expected 3 arguments, received %d\n", argc-1);
603 (void)sprintf(CS buffer, "%s/dnszones", argv[1]);
605 d = opendir(CCS buffer);
608 fprintf(stderr, "fakens: failed to opendir %s: %s\n", buffer,
613 while ((de = readdir(d)) != NULL)
615 uschar *name = US de->d_name;
616 if (Ustrncmp(name, "qualify.", 8) == 0)
618 qualify = fcopystring(US "%s", name + 7);
621 if (Ustrncmp(name, "db.", 3) != 0) continue;
622 if (Ustrncmp(name + 3, "ip4.", 4) == 0)
623 zones[zonecount].zone = fcopystring(US "%s.in-addr.arpa", name + 6);
624 else if (Ustrncmp(name + 3, "ip6.", 4) == 0)
625 zones[zonecount].zone = fcopystring(US "%s.ip6.arpa", name + 6);
627 zones[zonecount].zone = fcopystring(US "%s", name + 2);
628 zones[zonecount++].zonefile = fcopystring(US "%s", name);
632 /* Get the RR type and upper case it, and check that we recognize it. */
634 Ustrncpy(qtype, argv[3], sizeof(qtype));
635 qtypelen = Ustrlen(qtype);
636 for (p = qtype; *p != 0; p++) *p = toupper(*p);
638 /* Find the domain, lower case it, deal with any specials,
639 check that it is in a zone that we handle,
640 and set up the zone file name. The zone names in the table all start with a
643 domlen = Ustrlen(argv[2]);
644 if (argv[2][domlen-1] == '.') domlen--;
645 Ustrncpy(domain, argv[2], domlen);
647 for (i = 0; i < domlen; i++) domain[i] = tolower(domain[i]);
649 if (Ustrcmp(domain, "manyhome.test.ex") == 0 && Ustrcmp(qtype, "A") == 0)
651 uschar *pk = packet + 12;
655 memset(packet, 0, 12);
657 for (i = 104; i <= 111; i++) for (j = 0; j <= 255; j++)
659 pk = packname(domain, pk);
660 *pk++ = (ns_t_a >> 8) & 255;
661 *pk++ = (ns_t_a) & 255;
663 *pk++ = 1; /* class = IN */
664 pk += 4; /* TTL field; don't care */
665 rdlptr = pk; /* remember rdlength field */
668 *pk++ = 10; *pk++ = 250; *pk++ = i; *pk++ = j;
670 rdlptr[0] = ((pk - rdlptr - 2) >> 8) & 255;
671 rdlptr[1] = (pk - rdlptr - 2) & 255;
674 packet[6] = (2048 >> 8) & 255;
675 packet[7] = 2048 & 255;
679 (void)fwrite(packet, 1, pk - packet, stdout);
684 if (Ustrchr(domain, '.') == NULL && qualify != NULL &&
685 Ustrcmp(domain, "dontqualify") != 0)
687 Ustrcat(domain, qualify);
688 domlen += Ustrlen(qualify);
691 for (i = 0; i < zonecount; i++)
694 zone = zones[i].zone;
695 zlen = Ustrlen(zone);
696 if (Ustrcmp(domain, zone+1) == 0 || (domlen >= zlen &&
697 Ustrcmp(domain + domlen - zlen, zone) == 0))
699 zonefile = zones[i].zonefile;
704 if (zonefile == NULL)
706 fprintf(stderr, "fakens: query not in faked zone: domain is: %s\n", domain);
710 (void)sprintf(CS buffer, "%s/dnszones/%s", argv[1], zonefile);
712 /* Initialize the start of the response packet. We don't have to fake up
713 everything, because we know that Exim will look only at the answer and
714 additional section parts. */
716 memset(packet, 0, 12);
719 /* Open the zone file. */
721 f = fopen(CS buffer, "r");
724 fprintf(stderr, "fakens: failed to open %s: %s\n", buffer, strerror(errno));
728 /* Find the records we want, and add them to the result. */
731 yield = find_records(f, zone, domain, qtype, qtypelen, &pk, &count, &dnssec);
732 if (yield == NO_RECOVERY) goto END_OFF;
734 packet[6] = (count >> 8) & 255;
735 packet[7] = count & 255;
737 /* There is no need to return any additional records because Exim no longer
738 (from release 4.61) makes any use of them. */
744 ((HEADER *)packet)->ad = 1;
746 /* Close the zone file, write the result, and return. */
750 (void)fwrite(packet, 1, pk - packet, stdout);
756 /* End of fakens.c */