1 /* $NetBSD: tsig_250.c,v 1.6 2014/12/10 04:37:58 christos Exp $ */
2
3 /*
4 * Copyright (C) 2004, 2005, 2007, 2009, 2011, 2012 Internet Systems Consortium, Inc. ("ISC")
5 * Copyright (C) 1999-2003 Internet Software Consortium.
6 *
7 * Permission to use, copy, modify, and/or distribute this software for any
8 * purpose with or without fee is hereby granted, provided that the above
9 * copyright notice and this permission notice appear in all copies.
10 *
11 * THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
12 * REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
13 * AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
14 * INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
15 * LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
16 * OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
17 * PERFORMANCE OF THIS SOFTWARE.
18 */
19
20 /* Id */
21
22 /* Reviewed: Thu Mar 16 13:39:43 PST 2000 by gson */
23
24 #ifndef RDATA_ANY_255_TSIG_250_C
25 #define RDATA_ANY_255_TSIG_250_C
26
27 #define RRTYPE_TSIG_ATTRIBUTES \
28 (DNS_RDATATYPEATTR_META | DNS_RDATATYPEATTR_NOTQUESTION)
29
30 static inline isc_result_t
fromtext_any_tsig(ARGS_FROMTEXT)31 fromtext_any_tsig(ARGS_FROMTEXT) {
32 isc_token_t token;
33 dns_name_t name;
34 isc_uint64_t sigtime;
35 isc_buffer_t buffer;
36 dns_rcode_t rcode;
37 long i;
38 char *e;
39
40 REQUIRE(type == 250);
41 REQUIRE(rdclass == 255);
42
43 UNUSED(type);
44 UNUSED(rdclass);
45 UNUSED(callbacks);
46
47 /*
48 * Algorithm Name.
49 */
50 RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
51 ISC_FALSE));
52 dns_name_init(&name, NULL);
53 buffer_fromregion(&buffer, &token.value.as_region);
54 origin = (origin != NULL) ? origin : dns_rootname;
55 RETTOK(dns_name_fromtext(&name, &buffer, origin, options, target));
56
57 /*
58 * Time Signed: 48 bits.
59 */
60 RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
61 ISC_FALSE));
62 sigtime = isc_string_touint64(DNS_AS_STR(token), &e, 10);
63 if (*e != 0)
64 RETTOK(DNS_R_SYNTAX);
65 if ((sigtime >> 48) != 0)
66 RETTOK(ISC_R_RANGE);
67 RETERR(uint16_tobuffer((isc_uint16_t)(sigtime >> 32), target));
68 RETERR(uint32_tobuffer((isc_uint32_t)(sigtime & 0xffffffffU), target));
69
70 /*
71 * Fudge.
72 */
73 RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_number,
74 ISC_FALSE));
75 if (token.value.as_ulong > 0xffffU)
76 RETTOK(ISC_R_RANGE);
77 RETERR(uint16_tobuffer(token.value.as_ulong, target));
78
79 /*
80 * Signature Size.
81 */
82 RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_number,
83 ISC_FALSE));
84 if (token.value.as_ulong > 0xffffU)
85 RETTOK(ISC_R_RANGE);
86 RETERR(uint16_tobuffer(token.value.as_ulong, target));
87
88 /*
89 * Signature.
90 */
91 RETERR(isc_base64_tobuffer(lexer, target, (int)token.value.as_ulong));
92
93 /*
94 * Original ID.
95 */
96 RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_number,
97 ISC_FALSE));
98 if (token.value.as_ulong > 0xffffU)
99 RETTOK(ISC_R_RANGE);
100 RETERR(uint16_tobuffer(token.value.as_ulong, target));
101
102 /*
103 * Error.
104 */
105 RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
106 ISC_FALSE));
107 if (dns_tsigrcode_fromtext(&rcode, &token.value.as_textregion)
108 != ISC_R_SUCCESS)
109 {
110 i = strtol(DNS_AS_STR(token), &e, 10);
111 if (*e != 0)
112 RETTOK(DNS_R_UNKNOWN);
113 if (i < 0 || i > 0xffff)
114 RETTOK(ISC_R_RANGE);
115 rcode = (dns_rcode_t)i;
116 }
117 RETERR(uint16_tobuffer(rcode, target));
118
119 /*
120 * Other Len.
121 */
122 RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_number,
123 ISC_FALSE));
124 if (token.value.as_ulong > 0xffffU)
125 RETTOK(ISC_R_RANGE);
126 RETERR(uint16_tobuffer(token.value.as_ulong, target));
127
128 /*
129 * Other Data.
130 */
131 return (isc_base64_tobuffer(lexer, target, (int)token.value.as_ulong));
132 }
133
134 static inline isc_result_t
totext_any_tsig(ARGS_TOTEXT)135 totext_any_tsig(ARGS_TOTEXT) {
136 isc_region_t sr;
137 isc_region_t sigr;
138 char buf[sizeof(" 281474976710655 ")];
139 char *bufp;
140 dns_name_t name;
141 dns_name_t prefix;
142 isc_boolean_t sub;
143 isc_uint64_t sigtime;
144 unsigned short n;
145
146 REQUIRE(rdata->type == 250);
147 REQUIRE(rdata->rdclass == 255);
148 REQUIRE(rdata->length != 0);
149
150 dns_rdata_toregion(rdata, &sr);
151 /*
152 * Algorithm Name.
153 */
154 dns_name_init(&name, NULL);
155 dns_name_init(&prefix, NULL);
156 dns_name_fromregion(&name, &sr);
157 sub = name_prefix(&name, tctx->origin, &prefix);
158 RETERR(dns_name_totext(&prefix, sub, target));
159 RETERR(str_totext(" ", target));
160 isc_region_consume(&sr, name_length(&name));
161
162 /*
163 * Time Signed.
164 */
165 sigtime = ((isc_uint64_t)sr.base[0] << 40) |
166 ((isc_uint64_t)sr.base[1] << 32) |
167 ((isc_uint64_t)sr.base[2] << 24) |
168 ((isc_uint64_t)sr.base[3] << 16) |
169 ((isc_uint64_t)sr.base[4] << 8) |
170 (isc_uint64_t)sr.base[5];
171 isc_region_consume(&sr, 6);
172 bufp = &buf[sizeof(buf) - 1];
173 *bufp-- = 0;
174 *bufp-- = ' ';
175 do {
176 *bufp-- = decdigits[sigtime % 10];
177 sigtime /= 10;
178 } while (sigtime != 0);
179 bufp++;
180 RETERR(str_totext(bufp, target));
181
182 /*
183 * Fudge.
184 */
185 n = uint16_fromregion(&sr);
186 isc_region_consume(&sr, 2);
187 sprintf(buf, "%u ", n);
188 RETERR(str_totext(buf, target));
189
190 /*
191 * Signature Size.
192 */
193 n = uint16_fromregion(&sr);
194 isc_region_consume(&sr, 2);
195 sprintf(buf, "%u", n);
196 RETERR(str_totext(buf, target));
197
198 /*
199 * Signature.
200 */
201 REQUIRE(n <= sr.length);
202 sigr = sr;
203 sigr.length = n;
204 if ((tctx->flags & DNS_STYLEFLAG_MULTILINE) != 0)
205 RETERR(str_totext(" (", target));
206 RETERR(str_totext(tctx->linebreak, target));
207 if (tctx->width == 0) /* No splitting */
208 RETERR(isc_base64_totext(&sigr, 60, "", target));
209 else
210 RETERR(isc_base64_totext(&sigr, tctx->width - 2,
211 tctx->linebreak, target));
212 if ((tctx->flags & DNS_STYLEFLAG_MULTILINE) != 0)
213 RETERR(str_totext(" ) ", target));
214 else
215 RETERR(str_totext(" ", target));
216 isc_region_consume(&sr, n);
217
218 /*
219 * Original ID.
220 */
221 n = uint16_fromregion(&sr);
222 isc_region_consume(&sr, 2);
223 sprintf(buf, "%u ", n);
224 RETERR(str_totext(buf, target));
225
226 /*
227 * Error.
228 */
229 n = uint16_fromregion(&sr);
230 isc_region_consume(&sr, 2);
231 RETERR(dns_tsigrcode_totext((dns_rcode_t)n, target));
232
233 /*
234 * Other Size.
235 */
236 n = uint16_fromregion(&sr);
237 isc_region_consume(&sr, 2);
238 sprintf(buf, " %u ", n);
239 RETERR(str_totext(buf, target));
240
241 /*
242 * Other.
243 */
244 if (tctx->width == 0) /* No splitting */
245 return (isc_base64_totext(&sr, 60, "", target));
246 else
247 return (isc_base64_totext(&sr, 60, " ", target));
248 }
249
250 static inline isc_result_t
fromwire_any_tsig(ARGS_FROMWIRE)251 fromwire_any_tsig(ARGS_FROMWIRE) {
252 isc_region_t sr;
253 dns_name_t name;
254 unsigned long n;
255
256 REQUIRE(type == 250);
257 REQUIRE(rdclass == 255);
258
259 UNUSED(type);
260 UNUSED(rdclass);
261
262 dns_decompress_setmethods(dctx, DNS_COMPRESS_NONE);
263
264 /*
265 * Algorithm Name.
266 */
267 dns_name_init(&name, NULL);
268 RETERR(dns_name_fromwire(&name, source, dctx, options, target));
269
270 isc_buffer_activeregion(source, &sr);
271 /*
272 * Time Signed + Fudge.
273 */
274 if (sr.length < 8)
275 return (ISC_R_UNEXPECTEDEND);
276 RETERR(mem_tobuffer(target, sr.base, 8));
277 isc_region_consume(&sr, 8);
278 isc_buffer_forward(source, 8);
279
280 /*
281 * Signature Length + Signature.
282 */
283 if (sr.length < 2)
284 return (ISC_R_UNEXPECTEDEND);
285 n = uint16_fromregion(&sr);
286 if (sr.length < n + 2)
287 return (ISC_R_UNEXPECTEDEND);
288 RETERR(mem_tobuffer(target, sr.base, n + 2));
289 isc_region_consume(&sr, n + 2);
290 isc_buffer_forward(source, n + 2);
291
292 /*
293 * Original ID + Error.
294 */
295 if (sr.length < 4)
296 return (ISC_R_UNEXPECTEDEND);
297 RETERR(mem_tobuffer(target, sr.base, 4));
298 isc_region_consume(&sr, 4);
299 isc_buffer_forward(source, 4);
300
301 /*
302 * Other Length + Other.
303 */
304 if (sr.length < 2)
305 return (ISC_R_UNEXPECTEDEND);
306 n = uint16_fromregion(&sr);
307 if (sr.length < n + 2)
308 return (ISC_R_UNEXPECTEDEND);
309 isc_buffer_forward(source, n + 2);
310 return (mem_tobuffer(target, sr.base, n + 2));
311 }
312
313 static inline isc_result_t
towire_any_tsig(ARGS_TOWIRE)314 towire_any_tsig(ARGS_TOWIRE) {
315 isc_region_t sr;
316 dns_name_t name;
317 dns_offsets_t offsets;
318
319 REQUIRE(rdata->type == 250);
320 REQUIRE(rdata->rdclass == 255);
321 REQUIRE(rdata->length != 0);
322
323 dns_compress_setmethods(cctx, DNS_COMPRESS_NONE);
324 dns_rdata_toregion(rdata, &sr);
325 dns_name_init(&name, offsets);
326 dns_name_fromregion(&name, &sr);
327 RETERR(dns_name_towire(&name, cctx, target));
328 isc_region_consume(&sr, name_length(&name));
329 return (mem_tobuffer(target, sr.base, sr.length));
330 }
331
332 static inline int
compare_any_tsig(ARGS_COMPARE)333 compare_any_tsig(ARGS_COMPARE) {
334 isc_region_t r1;
335 isc_region_t r2;
336 dns_name_t name1;
337 dns_name_t name2;
338 int order;
339
340 REQUIRE(rdata1->type == rdata2->type);
341 REQUIRE(rdata1->rdclass == rdata2->rdclass);
342 REQUIRE(rdata1->type == 250);
343 REQUIRE(rdata1->rdclass == 255);
344 REQUIRE(rdata1->length != 0);
345 REQUIRE(rdata2->length != 0);
346
347 dns_rdata_toregion(rdata1, &r1);
348 dns_rdata_toregion(rdata2, &r2);
349 dns_name_init(&name1, NULL);
350 dns_name_init(&name2, NULL);
351 dns_name_fromregion(&name1, &r1);
352 dns_name_fromregion(&name2, &r2);
353 order = dns_name_rdatacompare(&name1, &name2);
354 if (order != 0)
355 return (order);
356 isc_region_consume(&r1, name_length(&name1));
357 isc_region_consume(&r2, name_length(&name2));
358 return (isc_region_compare(&r1, &r2));
359 }
360
361 static inline isc_result_t
fromstruct_any_tsig(ARGS_FROMSTRUCT)362 fromstruct_any_tsig(ARGS_FROMSTRUCT) {
363 dns_rdata_any_tsig_t *tsig = source;
364 isc_region_t tr;
365
366 REQUIRE(type == 250);
367 REQUIRE(rdclass == 255);
368 REQUIRE(source != NULL);
369 REQUIRE(tsig->common.rdclass == rdclass);
370 REQUIRE(tsig->common.rdtype == type);
371
372 UNUSED(type);
373 UNUSED(rdclass);
374
375 /*
376 * Algorithm Name.
377 */
378 RETERR(name_tobuffer(&tsig->algorithm, target));
379
380 isc_buffer_availableregion(target, &tr);
381 if (tr.length < 6 + 2 + 2)
382 return (ISC_R_NOSPACE);
383
384 /*
385 * Time Signed: 48 bits.
386 */
387 RETERR(uint16_tobuffer((isc_uint16_t)(tsig->timesigned >> 32),
388 target));
389 RETERR(uint32_tobuffer((isc_uint32_t)(tsig->timesigned & 0xffffffffU),
390 target));
391
392 /*
393 * Fudge.
394 */
395 RETERR(uint16_tobuffer(tsig->fudge, target));
396
397 /*
398 * Signature Size.
399 */
400 RETERR(uint16_tobuffer(tsig->siglen, target));
401
402 /*
403 * Signature.
404 */
405 RETERR(mem_tobuffer(target, tsig->signature, tsig->siglen));
406
407 isc_buffer_availableregion(target, &tr);
408 if (tr.length < 2 + 2 + 2)
409 return (ISC_R_NOSPACE);
410
411 /*
412 * Original ID.
413 */
414 RETERR(uint16_tobuffer(tsig->originalid, target));
415
416 /*
417 * Error.
418 */
419 RETERR(uint16_tobuffer(tsig->error, target));
420
421 /*
422 * Other Len.
423 */
424 RETERR(uint16_tobuffer(tsig->otherlen, target));
425
426 /*
427 * Other Data.
428 */
429 return (mem_tobuffer(target, tsig->other, tsig->otherlen));
430 }
431
432 static inline isc_result_t
tostruct_any_tsig(ARGS_TOSTRUCT)433 tostruct_any_tsig(ARGS_TOSTRUCT) {
434 dns_rdata_any_tsig_t *tsig;
435 dns_name_t alg;
436 isc_region_t sr;
437
438 REQUIRE(rdata->type == 250);
439 REQUIRE(rdata->rdclass == 255);
440 REQUIRE(rdata->length != 0);
441
442 tsig = (dns_rdata_any_tsig_t *) target;
443 tsig->common.rdclass = rdata->rdclass;
444 tsig->common.rdtype = rdata->type;
445 ISC_LINK_INIT(&tsig->common, link);
446
447 dns_rdata_toregion(rdata, &sr);
448
449 /*
450 * Algorithm Name.
451 */
452 dns_name_init(&alg, NULL);
453 dns_name_fromregion(&alg, &sr);
454 dns_name_init(&tsig->algorithm, NULL);
455 RETERR(name_duporclone(&alg, mctx, &tsig->algorithm));
456
457 isc_region_consume(&sr, name_length(&tsig->algorithm));
458
459 /*
460 * Time Signed.
461 */
462 INSIST(sr.length >= 6);
463 tsig->timesigned = ((isc_uint64_t)sr.base[0] << 40) |
464 ((isc_uint64_t)sr.base[1] << 32) |
465 ((isc_uint64_t)sr.base[2] << 24) |
466 ((isc_uint64_t)sr.base[3] << 16) |
467 ((isc_uint64_t)sr.base[4] << 8) |
468 (isc_uint64_t)sr.base[5];
469 isc_region_consume(&sr, 6);
470
471 /*
472 * Fudge.
473 */
474 tsig->fudge = uint16_fromregion(&sr);
475 isc_region_consume(&sr, 2);
476
477 /*
478 * Signature Size.
479 */
480 tsig->siglen = uint16_fromregion(&sr);
481 isc_region_consume(&sr, 2);
482
483 /*
484 * Signature.
485 */
486 INSIST(sr.length >= tsig->siglen);
487 tsig->signature = mem_maybedup(mctx, sr.base, tsig->siglen);
488 if (tsig->signature == NULL)
489 goto cleanup;
490 isc_region_consume(&sr, tsig->siglen);
491
492 /*
493 * Original ID.
494 */
495 tsig->originalid = uint16_fromregion(&sr);
496 isc_region_consume(&sr, 2);
497
498 /*
499 * Error.
500 */
501 tsig->error = uint16_fromregion(&sr);
502 isc_region_consume(&sr, 2);
503
504 /*
505 * Other Size.
506 */
507 tsig->otherlen = uint16_fromregion(&sr);
508 isc_region_consume(&sr, 2);
509
510 /*
511 * Other.
512 */
513 INSIST(sr.length == tsig->otherlen);
514 tsig->other = mem_maybedup(mctx, sr.base, tsig->otherlen);
515 if (tsig->other == NULL)
516 goto cleanup;
517
518 tsig->mctx = mctx;
519 return (ISC_R_SUCCESS);
520
521 cleanup:
522 if (mctx != NULL)
523 dns_name_free(&tsig->algorithm, tsig->mctx);
524 if (mctx != NULL && tsig->signature != NULL)
525 isc_mem_free(mctx, tsig->signature);
526 return (ISC_R_NOMEMORY);
527 }
528
529 static inline void
freestruct_any_tsig(ARGS_FREESTRUCT)530 freestruct_any_tsig(ARGS_FREESTRUCT) {
531 dns_rdata_any_tsig_t *tsig = (dns_rdata_any_tsig_t *) source;
532
533 REQUIRE(source != NULL);
534 REQUIRE(tsig->common.rdclass == 255);
535 REQUIRE(tsig->common.rdtype == 250);
536
537 if (tsig->mctx == NULL)
538 return;
539
540 dns_name_free(&tsig->algorithm, tsig->mctx);
541 if (tsig->signature != NULL)
542 isc_mem_free(tsig->mctx, tsig->signature);
543 if (tsig->other != NULL)
544 isc_mem_free(tsig->mctx, tsig->other);
545 tsig->mctx = NULL;
546 }
547
548 static inline isc_result_t
additionaldata_any_tsig(ARGS_ADDLDATA)549 additionaldata_any_tsig(ARGS_ADDLDATA) {
550 REQUIRE(rdata->type == 250);
551 REQUIRE(rdata->rdclass == 255);
552
553 UNUSED(rdata);
554 UNUSED(add);
555 UNUSED(arg);
556
557 return (ISC_R_SUCCESS);
558 }
559
560 static inline isc_result_t
digest_any_tsig(ARGS_DIGEST)561 digest_any_tsig(ARGS_DIGEST) {
562
563 REQUIRE(rdata->type == 250);
564 REQUIRE(rdata->rdclass == 255);
565
566 UNUSED(rdata);
567 UNUSED(digest);
568 UNUSED(arg);
569
570 return (ISC_R_NOTIMPLEMENTED);
571 }
572
573 static inline isc_boolean_t
checkowner_any_tsig(ARGS_CHECKOWNER)574 checkowner_any_tsig(ARGS_CHECKOWNER) {
575
576 REQUIRE(type == 250);
577 REQUIRE(rdclass == 255);
578
579 UNUSED(name);
580 UNUSED(type);
581 UNUSED(rdclass);
582 UNUSED(wildcard);
583
584 return (ISC_TRUE);
585 }
586
587 static inline isc_boolean_t
checknames_any_tsig(ARGS_CHECKNAMES)588 checknames_any_tsig(ARGS_CHECKNAMES) {
589
590 REQUIRE(rdata->type == 250);
591 REQUIRE(rdata->rdclass == 250);
592
593 UNUSED(rdata);
594 UNUSED(owner);
595 UNUSED(bad);
596
597 return (ISC_TRUE);
598 }
599
600 static inline int
casecompare_any_tsig(ARGS_COMPARE)601 casecompare_any_tsig(ARGS_COMPARE) {
602 return (compare_any_tsig(rdata1, rdata2));
603 }
604
605 #endif /* RDATA_ANY_255_TSIG_250_C */
606