xref: /minix3/external/bsd/bind/dist/lib/dns/rdata/generic/keydata_65533.c (revision 00b67f09dd46474d133c95011a48590a8e8f94c7)
1 /*	$NetBSD: keydata_65533.c,v 1.8 2015/07/08 17:28:59 christos Exp $	*/
2 
3 /*
4  * Copyright (C) 2009, 2011-2013, 2015  Internet Systems Consortium, Inc. ("ISC")
5  *
6  * Permission to use, copy, modify, and/or distribute this software for any
7  * purpose with or without fee is hereby granted, provided that the above
8  * copyright notice and this permission notice appear in all copies.
9  *
10  * THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
11  * REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
12  * AND FITNESS.  IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
13  * INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
14  * LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
15  * OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
16  * PERFORMANCE OF THIS SOFTWARE.
17  */
18 
19 #ifndef GENERIC_KEYDATA_65533_C
20 #define GENERIC_KEYDATA_65533_C 1
21 
22 #include <isc/time.h>
23 #include <isc/stdtime.h>
24 
25 #include <dst/dst.h>
26 
27 #define RRTYPE_KEYDATA_ATTRIBUTES (0)
28 
29 static inline isc_result_t
fromtext_keydata(ARGS_FROMTEXT)30 fromtext_keydata(ARGS_FROMTEXT) {
31 	isc_result_t result;
32 	isc_token_t token;
33 	dns_secalg_t alg;
34 	dns_secproto_t proto;
35 	dns_keyflags_t flags;
36 	isc_uint32_t refresh, addhd, removehd;
37 
38 	REQUIRE(type == 65533);
39 
40 	UNUSED(type);
41 	UNUSED(rdclass);
42 	UNUSED(origin);
43 	UNUSED(options);
44 	UNUSED(callbacks);
45 
46 	/* refresh timer */
47 	RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
48 				      ISC_FALSE));
49 	RETTOK(dns_time32_fromtext(DNS_AS_STR(token), &refresh));
50 	RETERR(uint32_tobuffer(refresh, target));
51 
52 	/* add hold-down */
53 	RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
54 				      ISC_FALSE));
55 	RETTOK(dns_time32_fromtext(DNS_AS_STR(token), &addhd));
56 	RETERR(uint32_tobuffer(addhd, target));
57 
58 	/* remove hold-down */
59 	RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
60 				      ISC_FALSE));
61 	RETTOK(dns_time32_fromtext(DNS_AS_STR(token), &removehd));
62 	RETERR(uint32_tobuffer(removehd, target));
63 
64 	/* flags */
65 	RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
66 				      ISC_FALSE));
67 	RETTOK(dns_keyflags_fromtext(&flags, &token.value.as_textregion));
68 	RETERR(uint16_tobuffer(flags, target));
69 
70 	/* protocol */
71 	RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
72 				      ISC_FALSE));
73 	RETTOK(dns_secproto_fromtext(&proto, &token.value.as_textregion));
74 	RETERR(mem_tobuffer(target, &proto, 1));
75 
76 	/* algorithm */
77 	RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
78 				      ISC_FALSE));
79 	RETTOK(dns_secalg_fromtext(&alg, &token.value.as_textregion));
80 	RETERR(mem_tobuffer(target, &alg, 1));
81 
82 	/* No Key? */
83 	if ((flags & 0xc000) == 0xc000)
84 		return (ISC_R_SUCCESS);
85 
86 	result = isc_base64_tobuffer(lexer, target, -1);
87 	if (result != ISC_R_SUCCESS)
88 		return (result);
89 
90 	/* Ensure there's at least enough data to compute a key ID for MD5 */
91 	if (alg == DST_ALG_RSAMD5 && isc_buffer_usedlength(target) < 19)
92 		return (ISC_R_UNEXPECTEDEND);
93 
94 	return (ISC_R_SUCCESS);
95 }
96 
97 static inline isc_result_t
totext_keydata(ARGS_TOTEXT)98 totext_keydata(ARGS_TOTEXT) {
99 	isc_region_t sr;
100 	char buf[sizeof("64000")];
101 	unsigned int flags;
102 	unsigned char algorithm;
103 	unsigned long refresh, add, remove;
104 	char algbuf[DNS_NAME_FORMATSIZE];
105 	const char *keyinfo;
106 
107 	REQUIRE(rdata->type == 65533);
108 
109 	if ((tctx->flags & DNS_STYLEFLAG_KEYDATA) == 0 || rdata->length < 16)
110 		return (unknown_totext(rdata, tctx, target));
111 
112 	dns_rdata_toregion(rdata, &sr);
113 
114 	/* refresh timer */
115 	refresh = uint32_fromregion(&sr);
116 	isc_region_consume(&sr, 4);
117 	RETERR(dns_time32_totext(refresh, target));
118 	RETERR(str_totext(" ", target));
119 
120 	/* add hold-down */
121 	add = uint32_fromregion(&sr);
122 	isc_region_consume(&sr, 4);
123 	RETERR(dns_time32_totext(add, target));
124 	RETERR(str_totext(" ", target));
125 
126 	/* remove hold-down */
127 	remove = uint32_fromregion(&sr);
128 	isc_region_consume(&sr, 4);
129 	RETERR(dns_time32_totext(remove, target));
130 	RETERR(str_totext(" ", target));
131 
132 	/* flags */
133 	flags = uint16_fromregion(&sr);
134 	isc_region_consume(&sr, 2);
135 	sprintf(buf, "%u", flags);
136 	RETERR(str_totext(buf, target));
137 	RETERR(str_totext(" ", target));
138 	if ((flags & DNS_KEYFLAG_KSK) != 0) {
139 		if (flags & DNS_KEYFLAG_REVOKE)
140 			keyinfo = "revoked KSK";
141 		else
142 			keyinfo = "KSK";
143 	} else
144 		keyinfo = "ZSK";
145 
146 	/* protocol */
147 	sprintf(buf, "%u", sr.base[0]);
148 	isc_region_consume(&sr, 1);
149 	RETERR(str_totext(buf, target));
150 	RETERR(str_totext(" ", target));
151 
152 	/* algorithm */
153 	algorithm = sr.base[0];
154 	sprintf(buf, "%u", algorithm);
155 	isc_region_consume(&sr, 1);
156 	RETERR(str_totext(buf, target));
157 
158 	/* No Key? */
159 	if ((flags & 0xc000) == 0xc000)
160 		return (ISC_R_SUCCESS);
161 
162 	/* key */
163 	if ((tctx->flags & DNS_STYLEFLAG_MULTILINE) != 0)
164 		RETERR(str_totext(" (", target));
165 	RETERR(str_totext(tctx->linebreak, target));
166 	if (tctx->width == 0)   /* No splitting */
167 		RETERR(isc_base64_totext(&sr, 60, "", target));
168 	else
169 		RETERR(isc_base64_totext(&sr, tctx->width - 2,
170 					 tctx->linebreak, target));
171 
172 	if ((tctx->flags & DNS_STYLEFLAG_RRCOMMENT) != 0)
173 		RETERR(str_totext(tctx->linebreak, target));
174 	else if ((tctx->flags & DNS_STYLEFLAG_MULTILINE) != 0)
175 		RETERR(str_totext(" ", target));
176 
177 	if ((tctx->flags & DNS_STYLEFLAG_MULTILINE) != 0)
178 		RETERR(str_totext(")", target));
179 
180 	if ((tctx->flags & DNS_STYLEFLAG_RRCOMMENT) != 0) {
181 		isc_region_t tmpr;
182 		char rbuf[ISC_FORMATHTTPTIMESTAMP_SIZE];
183 		char abuf[ISC_FORMATHTTPTIMESTAMP_SIZE];
184 		char dbuf[ISC_FORMATHTTPTIMESTAMP_SIZE];
185 		isc_time_t t;
186 
187 		RETERR(str_totext(" ; ", target));
188 		RETERR(str_totext(keyinfo, target));
189 		dns_secalg_format((dns_secalg_t) algorithm, algbuf,
190 				  sizeof(algbuf));
191 		RETERR(str_totext("; alg = ", target));
192 		RETERR(str_totext(algbuf, target));
193 		RETERR(str_totext("; key id = ", target));
194 		dns_rdata_toregion(rdata, &tmpr);
195 		/* Skip over refresh, addhd, and removehd */
196 		isc_region_consume(&tmpr, 12);
197 		sprintf(buf, "%u", dst_region_computeid(&tmpr, algorithm));
198 		RETERR(str_totext(buf, target));
199 
200 		if ((tctx->flags & DNS_STYLEFLAG_MULTILINE) != 0) {
201 			isc_stdtime_t now;
202 
203 			isc_stdtime_get(&now);
204 
205 			RETERR(str_totext(tctx->linebreak, target));
206 			RETERR(str_totext("; next refresh: ", target));
207 			isc_time_set(&t, refresh, 0);
208 			isc_time_formathttptimestamp(&t, rbuf, sizeof(rbuf));
209 			RETERR(str_totext(rbuf, target));
210 
211 			if (add == 0) {
212 				RETERR(str_totext(tctx->linebreak, target));
213 				RETERR(str_totext("; no trust", target));
214 			} else {
215 				RETERR(str_totext(tctx->linebreak, target));
216 				if (add < now) {
217 					RETERR(str_totext("; trusted since: ",
218 							  target));
219 				} else {
220 					RETERR(str_totext("; trust pending: ",
221 							  target));
222 				}
223 				isc_time_set(&t, add, 0);
224 				isc_time_formathttptimestamp(&t, abuf,
225 							     sizeof(abuf));
226 				RETERR(str_totext(abuf, target));
227 			}
228 
229 			if (remove != 0) {
230 				RETERR(str_totext(tctx->linebreak, target));
231 				RETERR(str_totext("; removal pending: ",
232 						  target));
233 				isc_time_set(&t, remove, 0);
234 				isc_time_formathttptimestamp(&t, dbuf,
235 							     sizeof(dbuf));
236 				RETERR(str_totext(dbuf, target));
237 			}
238 		}
239 
240 	}
241 	return (ISC_R_SUCCESS);
242 }
243 
244 static inline isc_result_t
fromwire_keydata(ARGS_FROMWIRE)245 fromwire_keydata(ARGS_FROMWIRE) {
246 	isc_region_t sr;
247 
248 	REQUIRE(type == 65533);
249 
250 	UNUSED(type);
251 	UNUSED(rdclass);
252 	UNUSED(dctx);
253 	UNUSED(options);
254 
255 	isc_buffer_activeregion(source, &sr);
256 	isc_buffer_forward(source, sr.length);
257 	return (mem_tobuffer(target, sr.base, sr.length));
258 }
259 
260 static inline isc_result_t
towire_keydata(ARGS_TOWIRE)261 towire_keydata(ARGS_TOWIRE) {
262 	isc_region_t sr;
263 
264 	REQUIRE(rdata->type == 65533);
265 
266 	UNUSED(cctx);
267 
268 	dns_rdata_toregion(rdata, &sr);
269 	return (mem_tobuffer(target, sr.base, sr.length));
270 }
271 
272 static inline int
compare_keydata(ARGS_COMPARE)273 compare_keydata(ARGS_COMPARE) {
274 	isc_region_t r1;
275 	isc_region_t r2;
276 
277 	REQUIRE(rdata1->type == rdata2->type);
278 	REQUIRE(rdata1->rdclass == rdata2->rdclass);
279 	REQUIRE(rdata1->type == 65533);
280 
281 	dns_rdata_toregion(rdata1, &r1);
282 	dns_rdata_toregion(rdata2, &r2);
283 	return (isc_region_compare(&r1, &r2));
284 }
285 
286 static inline isc_result_t
fromstruct_keydata(ARGS_FROMSTRUCT)287 fromstruct_keydata(ARGS_FROMSTRUCT) {
288 	dns_rdata_keydata_t *keydata = source;
289 
290 	REQUIRE(type == 65533);
291 	REQUIRE(source != NULL);
292 	REQUIRE(keydata->common.rdtype == type);
293 	REQUIRE(keydata->common.rdclass == rdclass);
294 
295 	UNUSED(type);
296 	UNUSED(rdclass);
297 
298 	/* Refresh timer */
299 	RETERR(uint32_tobuffer(keydata->refresh, target));
300 
301 	/* Add hold-down */
302 	RETERR(uint32_tobuffer(keydata->addhd, target));
303 
304 	/* Remove hold-down */
305 	RETERR(uint32_tobuffer(keydata->removehd, target));
306 
307 	/* Flags */
308 	RETERR(uint16_tobuffer(keydata->flags, target));
309 
310 	/* Protocol */
311 	RETERR(uint8_tobuffer(keydata->protocol, target));
312 
313 	/* Algorithm */
314 	RETERR(uint8_tobuffer(keydata->algorithm, target));
315 
316 	/* Data */
317 	return (mem_tobuffer(target, keydata->data, keydata->datalen));
318 }
319 
320 static inline isc_result_t
tostruct_keydata(ARGS_TOSTRUCT)321 tostruct_keydata(ARGS_TOSTRUCT) {
322 	dns_rdata_keydata_t *keydata = target;
323 	isc_region_t sr;
324 
325 	REQUIRE(rdata->type == 65533);
326 	REQUIRE(target != NULL);
327 
328 	keydata->common.rdclass = rdata->rdclass;
329 	keydata->common.rdtype = rdata->type;
330 	ISC_LINK_INIT(&keydata->common, link);
331 
332 	dns_rdata_toregion(rdata, &sr);
333 
334 	/* Refresh timer */
335 	if (sr.length < 4)
336 		return (ISC_R_UNEXPECTEDEND);
337 	keydata->refresh = uint32_fromregion(&sr);
338 	isc_region_consume(&sr, 4);
339 
340 	/* Add hold-down */
341 	if (sr.length < 4)
342 		return (ISC_R_UNEXPECTEDEND);
343 	keydata->addhd = uint32_fromregion(&sr);
344 	isc_region_consume(&sr, 4);
345 
346 	/* Remove hold-down */
347 	if (sr.length < 4)
348 		return (ISC_R_UNEXPECTEDEND);
349 	keydata->removehd = uint32_fromregion(&sr);
350 	isc_region_consume(&sr, 4);
351 
352 	/* Flags */
353 	if (sr.length < 2)
354 		return (ISC_R_UNEXPECTEDEND);
355 	keydata->flags = uint16_fromregion(&sr);
356 	isc_region_consume(&sr, 2);
357 
358 	/* Protocol */
359 	if (sr.length < 1)
360 		return (ISC_R_UNEXPECTEDEND);
361 	keydata->protocol = uint8_fromregion(&sr);
362 	isc_region_consume(&sr, 1);
363 
364 	/* Algorithm */
365 	if (sr.length < 1)
366 		return (ISC_R_UNEXPECTEDEND);
367 	keydata->algorithm = uint8_fromregion(&sr);
368 	isc_region_consume(&sr, 1);
369 
370 	/* Data */
371 	keydata->datalen = sr.length;
372 	keydata->data = mem_maybedup(mctx, sr.base, keydata->datalen);
373 	if (keydata->data == NULL)
374 		return (ISC_R_NOMEMORY);
375 
376 	keydata->mctx = mctx;
377 	return (ISC_R_SUCCESS);
378 }
379 
380 static inline void
freestruct_keydata(ARGS_FREESTRUCT)381 freestruct_keydata(ARGS_FREESTRUCT) {
382 	dns_rdata_keydata_t *keydata = (dns_rdata_keydata_t *) source;
383 
384 	REQUIRE(source != NULL);
385 	REQUIRE(keydata->common.rdtype == 65533);
386 
387 	if (keydata->mctx == NULL)
388 		return;
389 
390 	if (keydata->data != NULL)
391 		isc_mem_free(keydata->mctx, keydata->data);
392 	keydata->mctx = NULL;
393 }
394 
395 static inline isc_result_t
additionaldata_keydata(ARGS_ADDLDATA)396 additionaldata_keydata(ARGS_ADDLDATA) {
397 	REQUIRE(rdata->type == 65533);
398 
399 	UNUSED(rdata);
400 	UNUSED(add);
401 	UNUSED(arg);
402 
403 	return (ISC_R_SUCCESS);
404 }
405 
406 static inline isc_result_t
digest_keydata(ARGS_DIGEST)407 digest_keydata(ARGS_DIGEST) {
408 	isc_region_t r;
409 
410 	REQUIRE(rdata->type == 65533);
411 
412 	dns_rdata_toregion(rdata, &r);
413 
414 	return ((digest)(arg, &r));
415 }
416 
417 static inline isc_boolean_t
checkowner_keydata(ARGS_CHECKOWNER)418 checkowner_keydata(ARGS_CHECKOWNER) {
419 
420 	REQUIRE(type == 65533);
421 
422 	UNUSED(name);
423 	UNUSED(type);
424 	UNUSED(rdclass);
425 	UNUSED(wildcard);
426 
427 	return (ISC_TRUE);
428 }
429 
430 static inline isc_boolean_t
checknames_keydata(ARGS_CHECKNAMES)431 checknames_keydata(ARGS_CHECKNAMES) {
432 
433 	REQUIRE(rdata->type == 65533);
434 
435 	UNUSED(rdata);
436 	UNUSED(owner);
437 	UNUSED(bad);
438 
439 	return (ISC_TRUE);
440 }
441 
442 static inline int
casecompare_keydata(ARGS_COMPARE)443 casecompare_keydata(ARGS_COMPARE) {
444 	return (compare_keydata(rdata1, rdata2));
445 }
446 
447 #endif /* GENERIC_KEYDATA_65533_C */
448