Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 1 | // Copyright (c) 2012 The Chromium OS Authors. All rights reserved. |
| 2 | // Use of this source code is governed by a BSD-style license that can be |
| 3 | // found in the LICENSE file. |
| 4 | |
Garrick Evans | 3388a03 | 2020-03-24 11:25:55 +0900 | [diff] [blame] | 5 | #include "patchpanel/dns/dns_response.h" |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 6 | |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 7 | #include <algorithm> |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 8 | #include <limits> |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 9 | #include <numeric> |
| 10 | #include <openssl/sha.h> |
| 11 | #include <utility> |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 12 | |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 13 | #include "base/big_endian.h" |
| 14 | #include "base/logging.h" |
| 15 | #include "base/numerics/safe_conversions.h" |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 16 | #include "base/strings/string_util.h" |
| 17 | #include "base/sys_byteorder.h" |
| 18 | |
Garrick Evans | 3388a03 | 2020-03-24 11:25:55 +0900 | [diff] [blame] | 19 | #include "patchpanel/dns/dns_protocol.h" |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 20 | #include "patchpanel/dns/dns_query.h" |
| 21 | #include "patchpanel/dns/dns_util.h" |
Garrick Evans | 3388a03 | 2020-03-24 11:25:55 +0900 | [diff] [blame] | 22 | #include "patchpanel/dns/io_buffer.h" |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 23 | |
Qijiang Fan | 713061e | 2021-03-08 15:45:12 +0900 | [diff] [blame] | 24 | #include <base/check.h> |
| 25 | #include <base/check_op.h> |
| 26 | |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 27 | namespace patchpanel { |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 28 | |
| 29 | namespace { |
| 30 | |
| 31 | const size_t kHeaderSize = sizeof(dns_protocol::Header); |
| 32 | |
| 33 | const uint8_t kRcodeMask = 0xf; |
| 34 | |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 35 | // Taken from Chromium's "net/base/ip_address.h". |
| 36 | static const size_t kSrvRecordMinimumSize = 6; |
| 37 | static const size_t kIPv4AddressSize = 4; |
| 38 | static const size_t kIPv6AddressSize = 16; |
| 39 | |
| 40 | // Taken from Chromium's "net/dns/record_rdata.{h,cc}". |
| 41 | // The simplest INTEGRITY record is a U16-length-prefixed nonce (containing zero |
| 42 | // bytes) followed by its SHA256 digest. |
| 43 | static constexpr size_t kIntegrityMinimumSize = |
| 44 | sizeof(uint16_t) + SHA256_DIGEST_LENGTH; |
| 45 | |
| 46 | bool RecordRdataHasValidSize(const base::StringPiece& data, uint16_t type) { |
| 47 | switch (type) { |
| 48 | case dns_protocol::kTypeSRV: |
| 49 | return data.size() >= kSrvRecordMinimumSize; |
| 50 | case dns_protocol::kTypeA: |
| 51 | return data.size() == kIPv4AddressSize; |
| 52 | case dns_protocol::kTypeAAAA: |
| 53 | return data.size() == kIPv6AddressSize; |
| 54 | case dns_protocol::kExperimentalTypeIntegrity: |
| 55 | return data.size() >= kIntegrityMinimumSize; |
| 56 | case dns_protocol::kTypeHttps: |
| 57 | // TODO(crbug.com/1138620): Implement actual size minimum. |
| 58 | return data.size() == 0; |
| 59 | case dns_protocol::kTypeCNAME: |
| 60 | case dns_protocol::kTypePTR: |
| 61 | case dns_protocol::kTypeTXT: |
| 62 | case dns_protocol::kTypeNSEC: |
| 63 | case dns_protocol::kTypeOPT: |
| 64 | case dns_protocol::kTypeSOA: |
| 65 | return true; |
| 66 | default: |
| 67 | LOG(ERROR) << "Unsupported RDATA type."; |
| 68 | return false; |
| 69 | } |
| 70 | } |
| 71 | |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 72 | } // namespace |
| 73 | |
Ben Chan | 4f38650 | 2019-09-20 16:17:59 -0700 | [diff] [blame] | 74 | DnsResourceRecord::DnsResourceRecord() = default; |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 75 | |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 76 | DnsResourceRecord::DnsResourceRecord(const DnsResourceRecord& other) |
| 77 | : name(other.name), |
| 78 | type(other.type), |
| 79 | klass(other.klass), |
| 80 | ttl(other.ttl), |
| 81 | owned_rdata(other.owned_rdata) { |
| 82 | if (!owned_rdata.empty()) |
| 83 | rdata = owned_rdata; |
| 84 | else |
| 85 | rdata = other.rdata; |
| 86 | } |
| 87 | |
| 88 | DnsResourceRecord::DnsResourceRecord(DnsResourceRecord&& other) |
| 89 | : name(std::move(other.name)), |
| 90 | type(other.type), |
| 91 | klass(other.klass), |
| 92 | ttl(other.ttl), |
| 93 | owned_rdata(std::move(other.owned_rdata)) { |
| 94 | if (!owned_rdata.empty()) |
| 95 | rdata = owned_rdata; |
| 96 | else |
| 97 | rdata = other.rdata; |
| 98 | } |
| 99 | |
Ben Chan | 4f38650 | 2019-09-20 16:17:59 -0700 | [diff] [blame] | 100 | DnsResourceRecord::~DnsResourceRecord() = default; |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 101 | |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 102 | DnsResourceRecord& DnsResourceRecord::operator=( |
| 103 | const DnsResourceRecord& other) { |
| 104 | name = other.name; |
| 105 | type = other.type; |
| 106 | klass = other.klass; |
| 107 | ttl = other.ttl; |
| 108 | owned_rdata = other.owned_rdata; |
| 109 | |
| 110 | if (!owned_rdata.empty()) |
| 111 | rdata = owned_rdata; |
| 112 | else |
| 113 | rdata = other.rdata; |
| 114 | |
| 115 | return *this; |
| 116 | } |
| 117 | |
| 118 | DnsResourceRecord& DnsResourceRecord::operator=(DnsResourceRecord&& other) { |
| 119 | name = std::move(other.name); |
| 120 | type = other.type; |
| 121 | klass = other.klass; |
| 122 | ttl = other.ttl; |
| 123 | owned_rdata = std::move(other.owned_rdata); |
| 124 | |
| 125 | if (!owned_rdata.empty()) |
| 126 | rdata = owned_rdata; |
| 127 | else |
| 128 | rdata = other.rdata; |
| 129 | |
| 130 | return *this; |
| 131 | } |
| 132 | |
| 133 | void DnsResourceRecord::SetOwnedRdata(std::string value) { |
| 134 | DCHECK(!value.empty()); |
| 135 | owned_rdata = std::move(value); |
| 136 | rdata = owned_rdata; |
| 137 | DCHECK_EQ(owned_rdata.data(), rdata.data()); |
| 138 | } |
| 139 | |
| 140 | size_t DnsResourceRecord::CalculateRecordSize() const { |
| 141 | bool has_final_dot = name.back() == '.'; |
| 142 | // Depending on if |name| in the dotted format has the final dot for the root |
| 143 | // domain or not, the corresponding wire data in the DNS domain name format is |
| 144 | // 1 byte (with dot) or 2 bytes larger in size. See RFC 1035, Section 3.1 and |
| 145 | // DNSDomainFromDot. |
| 146 | return name.size() + (has_final_dot ? 1 : 2) + |
| 147 | patchpanel::dns_protocol:: |
| 148 | kResourceRecordSizeInBytesWithoutNameAndRData + |
| 149 | (owned_rdata.empty() ? rdata.size() : owned_rdata.size()); |
| 150 | } |
| 151 | |
| 152 | DnsRecordParser::DnsRecordParser() |
| 153 | : packet_(nullptr), length_(0), cur_(nullptr) {} |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 154 | |
| 155 | DnsRecordParser::DnsRecordParser(const void* packet, |
| 156 | size_t length, |
| 157 | size_t offset) |
| 158 | : packet_(reinterpret_cast<const char*>(packet)), |
| 159 | length_(length), |
| 160 | cur_(packet_ + offset) { |
| 161 | DCHECK_LE(offset, length); |
| 162 | } |
| 163 | |
| 164 | unsigned DnsRecordParser::ReadName(const void* const vpos, |
| 165 | std::string* out) const { |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 166 | static const char kAbortMsg[] = "Abort parsing of noncompliant DNS record."; |
| 167 | |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 168 | const char* const pos = reinterpret_cast<const char*>(vpos); |
| 169 | DCHECK(packet_); |
| 170 | DCHECK_LE(packet_, pos); |
| 171 | DCHECK_LE(pos, packet_ + length_); |
| 172 | |
| 173 | const char* p = pos; |
| 174 | const char* end = packet_ + length_; |
| 175 | // Count number of seen bytes to detect loops. |
| 176 | unsigned seen = 0; |
| 177 | // Remember how many bytes were consumed before first jump. |
| 178 | unsigned consumed = 0; |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 179 | // The length of the encoded name (sum of label octets and label lengths). |
| 180 | // For context, RFC 1034 states that the total number of octets representing a |
| 181 | // domain name (the sum of all label octets and label lengths) is limited to |
| 182 | // 255. RFC 1035 introduces message compression as a way to reduce packet size |
| 183 | // on the wire, not to increase the maximum domain name length. |
| 184 | unsigned encoded_name_len = 0; |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 185 | |
| 186 | if (pos >= end) |
| 187 | return 0; |
| 188 | |
| 189 | if (out) { |
| 190 | out->clear(); |
| 191 | out->reserve(dns_protocol::kMaxNameLength); |
| 192 | } |
| 193 | |
| 194 | for (;;) { |
| 195 | // The first two bits of the length give the type of the length. It's |
| 196 | // either a direct length or a pointer to the remainder of the name. |
| 197 | switch (*p & dns_protocol::kLabelMask) { |
| 198 | case dns_protocol::kLabelPointer: { |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 199 | if (p + sizeof(uint16_t) > end) { |
| 200 | LOG(ERROR) << kAbortMsg << " Truncated or missing label pointer."; |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 201 | return 0; |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 202 | } |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 203 | if (consumed == 0) { |
| 204 | consumed = p - pos + sizeof(uint16_t); |
| 205 | if (!out) |
| 206 | return consumed; // If name is not stored, that's all we need. |
| 207 | } |
| 208 | seen += sizeof(uint16_t); |
| 209 | // If seen the whole packet, then we must be in a loop. |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 210 | if (seen > length_) { |
| 211 | LOG(ERROR) << kAbortMsg << " Detected loop in label pointers."; |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 212 | return 0; |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 213 | } |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 214 | uint16_t offset; |
| 215 | base::ReadBigEndian<uint16_t>(p, &offset); |
| 216 | offset &= dns_protocol::kOffsetMask; |
| 217 | p = packet_ + offset; |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 218 | if (p >= end) { |
| 219 | LOG(ERROR) << kAbortMsg << " Label pointer points outside packet."; |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 220 | return 0; |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 221 | } |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 222 | break; |
| 223 | } |
| 224 | case dns_protocol::kLabelDirect: { |
| 225 | uint8_t label_len = *p; |
| 226 | ++p; |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 227 | // Add one octet for the length and |label_len| for the number of |
| 228 | // following octets. |
| 229 | encoded_name_len += 1 + label_len; |
| 230 | if (encoded_name_len > dns_protocol::kMaxNameLength) { |
| 231 | LOG(ERROR) << kAbortMsg << " Name is too long."; |
| 232 | return 0; |
| 233 | } |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 234 | // Note: root domain (".") is NOT included. |
| 235 | if (label_len == 0) { |
| 236 | if (consumed == 0) { |
| 237 | consumed = p - pos; |
| 238 | } // else we set |consumed| before first jump |
| 239 | return consumed; |
| 240 | } |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 241 | if (p + label_len >= end) { |
| 242 | LOG(ERROR) << kAbortMsg << " Truncated or missing label."; |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 243 | return 0; // Truncated or missing label. |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 244 | } |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 245 | if (out) { |
| 246 | if (!out->empty()) |
| 247 | out->append("."); |
| 248 | out->append(p, label_len); |
| 249 | } |
| 250 | p += label_len; |
| 251 | seen += 1 + label_len; |
| 252 | break; |
| 253 | } |
| 254 | default: |
| 255 | // unhandled label type |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 256 | LOG(ERROR) << kAbortMsg << " Unhandled label type."; |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 257 | return 0; |
| 258 | } |
| 259 | } |
| 260 | } |
| 261 | |
| 262 | bool DnsRecordParser::ReadRecord(DnsResourceRecord* out) { |
| 263 | DCHECK(packet_); |
| 264 | size_t consumed = ReadName(cur_, &out->name); |
| 265 | if (!consumed) |
| 266 | return false; |
| 267 | base::BigEndianReader reader(cur_ + consumed, |
| 268 | packet_ + length_ - (cur_ + consumed)); |
| 269 | uint16_t rdlen; |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 270 | if (reader.ReadU16(&out->type) && |
| 271 | reader.ReadU16(&out->klass) && |
| 272 | reader.ReadU32(&out->ttl) && |
| 273 | reader.ReadU16(&rdlen) && |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 274 | reader.ReadPiece(&out->rdata, rdlen)) { |
| 275 | cur_ = reader.ptr(); |
| 276 | return true; |
| 277 | } |
| 278 | return false; |
| 279 | } |
| 280 | |
| 281 | bool DnsRecordParser::SkipQuestion() { |
Ben Chan | ac00904 | 2019-09-20 16:19:56 -0700 | [diff] [blame] | 282 | size_t consumed = ReadName(cur_, nullptr); |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 283 | if (!consumed) |
| 284 | return false; |
| 285 | |
| 286 | const char* next = cur_ + consumed + 2 * sizeof(uint16_t); // QTYPE + QCLASS |
| 287 | if (next > packet_ + length_) |
| 288 | return false; |
| 289 | |
| 290 | cur_ = next; |
| 291 | |
| 292 | return true; |
| 293 | } |
| 294 | |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 295 | DnsResponse::DnsResponse( |
| 296 | uint16_t id, |
| 297 | bool is_authoritative, |
| 298 | const std::vector<DnsResourceRecord>& answers, |
| 299 | const std::vector<DnsResourceRecord>& authority_records, |
| 300 | const std::vector<DnsResourceRecord>& additional_records, |
| 301 | const base::Optional<DnsQuery>& query, |
| 302 | uint8_t rcode) { |
| 303 | bool has_query = query.has_value(); |
| 304 | dns_protocol::Header header; |
| 305 | header.id = id; |
| 306 | bool success = true; |
| 307 | if (has_query) { |
| 308 | success &= (id == query.value().id()); |
| 309 | DCHECK(success); |
| 310 | // DnsQuery only supports a single question. |
| 311 | header.qdcount = 1; |
| 312 | } |
| 313 | header.flags |= dns_protocol::kFlagResponse; |
| 314 | if (is_authoritative) |
| 315 | header.flags |= dns_protocol::kFlagAA; |
| 316 | DCHECK_EQ(0, rcode & ~kRcodeMask); |
| 317 | header.flags |= rcode; |
| 318 | |
| 319 | header.ancount = answers.size(); |
| 320 | header.nscount = authority_records.size(); |
| 321 | header.arcount = additional_records.size(); |
| 322 | |
| 323 | // Response starts with the header and the question section (if any). |
| 324 | size_t response_size = has_query |
| 325 | ? sizeof(header) + query.value().question_size() |
| 326 | : sizeof(header); |
| 327 | // Add the size of all answers and additional records. |
| 328 | auto do_accumulation = [](size_t cur_size, const DnsResourceRecord& record) { |
| 329 | return cur_size + record.CalculateRecordSize(); |
| 330 | }; |
| 331 | response_size = std::accumulate(answers.begin(), answers.end(), response_size, |
| 332 | do_accumulation); |
| 333 | response_size = |
| 334 | std::accumulate(authority_records.begin(), authority_records.end(), |
| 335 | response_size, do_accumulation); |
| 336 | response_size = |
| 337 | std::accumulate(additional_records.begin(), additional_records.end(), |
| 338 | response_size, do_accumulation); |
| 339 | |
| 340 | io_buffer_ = base::MakeRefCounted<IOBuffer>(response_size); |
| 341 | io_buffer_size_ = response_size; |
| 342 | base::BigEndianWriter writer(io_buffer_->data(), io_buffer_size_); |
| 343 | success &= WriteHeader(&writer, header); |
| 344 | DCHECK(success); |
| 345 | if (has_query) { |
| 346 | success &= WriteQuestion(&writer, query.value()); |
| 347 | DCHECK(success); |
| 348 | } |
| 349 | // Start the Answer section. |
| 350 | for (const auto& answer : answers) { |
| 351 | success &= WriteAnswer(&writer, answer, query); |
| 352 | DCHECK(success); |
| 353 | } |
| 354 | // Start the Authority section. |
| 355 | for (const auto& record : authority_records) { |
| 356 | success &= WriteRecord(&writer, record); |
| 357 | DCHECK(success); |
| 358 | } |
| 359 | // Start the Additional section. |
| 360 | for (const auto& record : additional_records) { |
| 361 | success &= WriteRecord(&writer, record); |
| 362 | DCHECK(success); |
| 363 | } |
| 364 | if (!success) { |
| 365 | io_buffer_.reset(); |
| 366 | io_buffer_size_ = 0; |
| 367 | return; |
| 368 | } |
| 369 | // Ensure we don't have any remaining uninitialized bytes in the buffer. |
| 370 | DCHECK(!writer.remaining()); |
| 371 | memset(writer.ptr(), 0, writer.remaining()); |
| 372 | if (has_query) |
| 373 | InitParse(io_buffer_size_, query.value()); |
| 374 | else |
| 375 | InitParseWithoutQuery(io_buffer_size_); |
| 376 | } |
| 377 | |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 378 | DnsResponse::DnsResponse() |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 379 | : io_buffer_(base::MakeRefCounted<IOBuffer>(dns_protocol::kMaxUDPSize + 1)), |
| 380 | io_buffer_size_(dns_protocol::kMaxUDPSize + 1) {} |
| 381 | |
| 382 | DnsResponse::DnsResponse(scoped_refptr<IOBuffer> buffer, size_t size) |
| 383 | : io_buffer_(std::move(buffer)), io_buffer_size_(size) {} |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 384 | |
| 385 | DnsResponse::DnsResponse(size_t length) |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 386 | : io_buffer_(base::MakeRefCounted<IOBuffer>(length)), |
| 387 | io_buffer_size_(length) {} |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 388 | |
Hidehiko Abe | 3a7e513 | 2018-02-15 13:07:50 +0900 | [diff] [blame] | 389 | DnsResponse::DnsResponse(const void* data, size_t length, size_t answer_offset) |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 390 | : io_buffer_(base::MakeRefCounted<IOBufferWithSize>(length)), |
| 391 | io_buffer_size_(length), |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 392 | parser_(io_buffer_->data(), length, answer_offset) { |
| 393 | DCHECK(data); |
| 394 | memcpy(io_buffer_->data(), data, length); |
| 395 | } |
| 396 | |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 397 | DnsResponse::DnsResponse(DnsResponse&& other) = default; |
| 398 | DnsResponse& DnsResponse::operator=(DnsResponse&& other) = default; |
| 399 | |
Ben Chan | 4f38650 | 2019-09-20 16:17:59 -0700 | [diff] [blame] | 400 | DnsResponse::~DnsResponse() = default; |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 401 | |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 402 | bool DnsResponse::InitParse(size_t nbytes, const DnsQuery& query) { |
| 403 | const base::StringPiece question = query.question(); |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 404 | |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 405 | // Response includes question, it should be at least that size. |
| 406 | if (nbytes < kHeaderSize + question.size() || nbytes > io_buffer_size_) { |
| 407 | return false; |
| 408 | } |
| 409 | |
| 410 | // At this point, it has been validated that the response is at least large |
| 411 | // enough to read the ID field. |
| 412 | id_available_ = true; |
| 413 | |
| 414 | // Match the query id. |
| 415 | DCHECK(id()); |
| 416 | if (id().value() != query.id()) |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 417 | return false; |
| 418 | |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 419 | // Not a response? |
| 420 | if ((base::NetToHost16(header()->flags) & dns_protocol::kFlagResponse) == 0) |
| 421 | return false; |
| 422 | |
| 423 | // Match question count. |
| 424 | if (base::NetToHost16(header()->qdcount) != 1) |
| 425 | return false; |
| 426 | |
| 427 | // Match the question section. |
| 428 | if (question != |
| 429 | base::StringPiece(io_buffer_->data() + kHeaderSize, question.size())) { |
| 430 | return false; |
| 431 | } |
| 432 | |
| 433 | // Construct the parser. |
| 434 | parser_ = DnsRecordParser(io_buffer_->data(), nbytes, |
| 435 | kHeaderSize + question.size()); |
| 436 | return true; |
| 437 | } |
| 438 | |
| 439 | bool DnsResponse::InitParseWithoutQuery(size_t nbytes) { |
| 440 | if (nbytes < kHeaderSize || nbytes > io_buffer_size_) { |
| 441 | return false; |
| 442 | } |
| 443 | id_available_ = true; |
| 444 | |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 445 | parser_ = DnsRecordParser(io_buffer_->data(), nbytes, kHeaderSize); |
| 446 | |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 447 | // Not a response? |
| 448 | if ((base::NetToHost16(header()->flags) & dns_protocol::kFlagResponse) == 0) |
| 449 | return false; |
| 450 | |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 451 | unsigned qdcount = base::NetToHost16(header()->qdcount); |
| 452 | for (unsigned i = 0; i < qdcount; ++i) { |
| 453 | if (!parser_.SkipQuestion()) { |
| 454 | parser_ = DnsRecordParser(); // Make parser invalid again. |
| 455 | return false; |
| 456 | } |
| 457 | } |
| 458 | |
| 459 | return true; |
| 460 | } |
| 461 | |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 462 | base::Optional<uint16_t> DnsResponse::id() const { |
| 463 | if (!id_available_) |
| 464 | return base::nullopt; |
| 465 | |
| 466 | return base::NetToHost16(header()->id); |
| 467 | } |
| 468 | |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 469 | bool DnsResponse::IsValid() const { |
| 470 | return parser_.IsValid(); |
| 471 | } |
| 472 | |
| 473 | uint16_t DnsResponse::flags() const { |
| 474 | DCHECK(parser_.IsValid()); |
| 475 | return base::NetToHost16(header()->flags) & ~(kRcodeMask); |
| 476 | } |
| 477 | |
| 478 | uint8_t DnsResponse::rcode() const { |
| 479 | DCHECK(parser_.IsValid()); |
| 480 | return base::NetToHost16(header()->flags) & kRcodeMask; |
| 481 | } |
| 482 | |
| 483 | unsigned DnsResponse::answer_count() const { |
| 484 | DCHECK(parser_.IsValid()); |
| 485 | return base::NetToHost16(header()->ancount); |
| 486 | } |
| 487 | |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 488 | unsigned DnsResponse::authority_count() const { |
| 489 | DCHECK(parser_.IsValid()); |
| 490 | return base::NetToHost16(header()->nscount); |
| 491 | } |
| 492 | |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 493 | unsigned DnsResponse::additional_answer_count() const { |
| 494 | DCHECK(parser_.IsValid()); |
| 495 | return base::NetToHost16(header()->arcount); |
| 496 | } |
| 497 | |
| 498 | base::StringPiece DnsResponse::qname() const { |
| 499 | DCHECK(parser_.IsValid()); |
| 500 | // The response is HEADER QNAME QTYPE QCLASS ANSWER. |
| 501 | // |parser_| is positioned at the beginning of ANSWER, so the end of QNAME is |
| 502 | // two uint16_ts before it. |
| 503 | const size_t qname_size = |
| 504 | parser_.GetOffset() - 2 * sizeof(uint16_t) - kHeaderSize; |
| 505 | return base::StringPiece(io_buffer_->data() + kHeaderSize, qname_size); |
| 506 | } |
| 507 | |
| 508 | uint16_t DnsResponse::qtype() const { |
| 509 | DCHECK(parser_.IsValid()); |
| 510 | // QTYPE starts where QNAME ends. |
| 511 | const size_t type_offset = parser_.GetOffset() - 2 * sizeof(uint16_t); |
| 512 | uint16_t type; |
| 513 | base::ReadBigEndian<uint16_t>(io_buffer_->data() + type_offset, &type); |
| 514 | return type; |
| 515 | } |
| 516 | |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 517 | std::string DnsResponse::GetDottedName() const { |
| 518 | return DnsDomainToString(qname()).value_or(""); |
| 519 | } |
| 520 | |
Kevin Cernekee | d05be17 | 2017-06-17 17:40:21 -0700 | [diff] [blame] | 521 | DnsRecordParser DnsResponse::Parser() const { |
| 522 | DCHECK(parser_.IsValid()); |
| 523 | // Return a copy of the parser. |
| 524 | return parser_; |
| 525 | } |
| 526 | |
| 527 | const dns_protocol::Header* DnsResponse::header() const { |
| 528 | return reinterpret_cast<const dns_protocol::Header*>(io_buffer_->data()); |
| 529 | } |
| 530 | |
Jason Jeremy Iman | a21be27 | 2020-10-21 17:53:45 +0900 | [diff] [blame] | 531 | bool DnsResponse::WriteHeader(base::BigEndianWriter* writer, |
| 532 | const dns_protocol::Header& header) { |
| 533 | return writer->WriteU16(header.id) && writer->WriteU16(header.flags) && |
| 534 | writer->WriteU16(header.qdcount) && writer->WriteU16(header.ancount) && |
| 535 | writer->WriteU16(header.nscount) && writer->WriteU16(header.arcount); |
| 536 | } |
| 537 | |
| 538 | bool DnsResponse::WriteQuestion(base::BigEndianWriter* writer, |
| 539 | const DnsQuery& query) { |
| 540 | const base::StringPiece& question = query.question(); |
| 541 | return writer->WriteBytes(question.data(), question.size()); |
| 542 | } |
| 543 | |
| 544 | bool DnsResponse::WriteRecord(base::BigEndianWriter* writer, |
| 545 | const DnsResourceRecord& record) { |
| 546 | if (record.rdata != base::StringPiece(record.owned_rdata)) { |
| 547 | LOG(ERROR) << "record.rdata should point to record.owned_rdata."; |
| 548 | return false; |
| 549 | } |
| 550 | |
| 551 | if (!RecordRdataHasValidSize(record.owned_rdata, record.type)) { |
| 552 | LOG(ERROR) << "Invalid RDATA size for a record."; |
| 553 | return false; |
| 554 | } |
| 555 | std::string domain_name; |
| 556 | if (!DNSDomainFromDot(record.name, &domain_name)) { |
| 557 | LOG(ERROR) << "Invalid dotted name."; |
| 558 | return false; |
| 559 | } |
| 560 | return writer->WriteBytes(domain_name.data(), domain_name.size()) && |
| 561 | writer->WriteU16(record.type) && writer->WriteU16(record.klass) && |
| 562 | writer->WriteU32(record.ttl) && |
| 563 | writer->WriteU16(record.owned_rdata.size()) && |
| 564 | // Use the owned RDATA in the record to construct the response. |
| 565 | writer->WriteBytes(record.owned_rdata.data(), |
| 566 | record.owned_rdata.size()); |
| 567 | } |
| 568 | |
| 569 | bool DnsResponse::WriteAnswer(base::BigEndianWriter* writer, |
| 570 | const DnsResourceRecord& answer, |
| 571 | const base::Optional<DnsQuery>& query) { |
| 572 | // Generally assumed to be a mistake if we write answers that don't match the |
| 573 | // query type, except CNAME answers which can always be added. |
| 574 | if (query.has_value() && answer.type != query.value().qtype() && |
| 575 | answer.type != dns_protocol::kTypeCNAME) { |
| 576 | LOG(ERROR) << "Mismatched answer resource record type and qtype."; |
| 577 | return false; |
| 578 | } |
| 579 | return WriteRecord(writer, answer); |
| 580 | } |
| 581 | |
| 582 | } // namespace patchpanel |