xref: /dflybsd-src/lib/libssh/openbsd-compat/getrrsetbyname-ldns.c (revision e926d9f338dd5529d4bd857f7ac14e0a32ea0ab1)
1*e926d9f3SDaniel Fojt /* $OpenBSD: getrrsetbyname.c,v 1.10 2005/03/30 02:58:28 tedu Exp $ */
2*e926d9f3SDaniel Fojt 
3*e926d9f3SDaniel Fojt /*
4*e926d9f3SDaniel Fojt  * Copyright (c) 2007 Simon Vallet / Genoscope <svallet@genoscope.cns.fr>
5*e926d9f3SDaniel Fojt  *
6*e926d9f3SDaniel Fojt  * Redistribution and use in source and binary forms, with or without
7*e926d9f3SDaniel Fojt  * modification, are permitted provided that the following conditions
8*e926d9f3SDaniel Fojt  * are met:
9*e926d9f3SDaniel Fojt  *
10*e926d9f3SDaniel Fojt  * 1. Redistributions of source code must retain the above copyright
11*e926d9f3SDaniel Fojt  *    notice, this list of conditions and the following disclaimer.
12*e926d9f3SDaniel Fojt  *
13*e926d9f3SDaniel Fojt  * 2. Redistributions in binary form must reproduce the above copyright
14*e926d9f3SDaniel Fojt  *    notice, this list of conditions and the following disclaimer in the
15*e926d9f3SDaniel Fojt  *    documentation and/or other materials provided with the distribution.
16*e926d9f3SDaniel Fojt  *
17*e926d9f3SDaniel Fojt  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
18*e926d9f3SDaniel Fojt  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
19*e926d9f3SDaniel Fojt  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
20*e926d9f3SDaniel Fojt  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
21*e926d9f3SDaniel Fojt  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
22*e926d9f3SDaniel Fojt  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
23*e926d9f3SDaniel Fojt  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
24*e926d9f3SDaniel Fojt  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
25*e926d9f3SDaniel Fojt  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
26*e926d9f3SDaniel Fojt  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
27*e926d9f3SDaniel Fojt  */
28*e926d9f3SDaniel Fojt 
29*e926d9f3SDaniel Fojt /*
30*e926d9f3SDaniel Fojt  * Portions Copyright (c) 1999-2001 Internet Software Consortium.
31*e926d9f3SDaniel Fojt  *
32*e926d9f3SDaniel Fojt  * Permission to use, copy, modify, and distribute this software for any
33*e926d9f3SDaniel Fojt  * purpose with or without fee is hereby granted, provided that the above
34*e926d9f3SDaniel Fojt  * copyright notice and this permission notice appear in all copies.
35*e926d9f3SDaniel Fojt  *
36*e926d9f3SDaniel Fojt  * THE SOFTWARE IS PROVIDED "AS IS" AND INTERNET SOFTWARE CONSORTIUM
37*e926d9f3SDaniel Fojt  * DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL
38*e926d9f3SDaniel Fojt  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL
39*e926d9f3SDaniel Fojt  * INTERNET SOFTWARE CONSORTIUM BE LIABLE FOR ANY SPECIAL, DIRECT,
40*e926d9f3SDaniel Fojt  * INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING
41*e926d9f3SDaniel Fojt  * FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT,
42*e926d9f3SDaniel Fojt  * NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION
43*e926d9f3SDaniel Fojt  * WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
44*e926d9f3SDaniel Fojt  */
45*e926d9f3SDaniel Fojt 
46*e926d9f3SDaniel Fojt #include "includes.h"
47*e926d9f3SDaniel Fojt 
48*e926d9f3SDaniel Fojt #if !defined (HAVE_GETRRSETBYNAME) && defined (HAVE_LDNS)
49*e926d9f3SDaniel Fojt 
50*e926d9f3SDaniel Fojt #include <stdlib.h>
51*e926d9f3SDaniel Fojt #include <string.h>
52*e926d9f3SDaniel Fojt 
53*e926d9f3SDaniel Fojt #include <ldns/ldns.h>
54*e926d9f3SDaniel Fojt 
55*e926d9f3SDaniel Fojt #include "getrrsetbyname.h"
56*e926d9f3SDaniel Fojt #include "log.h"
57*e926d9f3SDaniel Fojt #include "xmalloc.h"
58*e926d9f3SDaniel Fojt 
59*e926d9f3SDaniel Fojt #define malloc(x)	(xmalloc(x))
60*e926d9f3SDaniel Fojt #define calloc(x, y)	(xcalloc((x),(y)))
61*e926d9f3SDaniel Fojt 
62*e926d9f3SDaniel Fojt int
getrrsetbyname(const char * hostname,unsigned int rdclass,unsigned int rdtype,unsigned int flags,struct rrsetinfo ** res)63*e926d9f3SDaniel Fojt getrrsetbyname(const char *hostname, unsigned int rdclass,
64*e926d9f3SDaniel Fojt 	       unsigned int rdtype, unsigned int flags,
65*e926d9f3SDaniel Fojt 	       struct rrsetinfo **res)
66*e926d9f3SDaniel Fojt {
67*e926d9f3SDaniel Fojt 	int result;
68*e926d9f3SDaniel Fojt 	unsigned int i, j, index_ans, index_sig;
69*e926d9f3SDaniel Fojt 	struct rrsetinfo *rrset = NULL;
70*e926d9f3SDaniel Fojt 	struct rdatainfo *rdata;
71*e926d9f3SDaniel Fojt 	size_t len;
72*e926d9f3SDaniel Fojt 	ldns_resolver *ldns_res = NULL;
73*e926d9f3SDaniel Fojt 	ldns_rdf *domain = NULL;
74*e926d9f3SDaniel Fojt 	ldns_pkt *pkt = NULL;
75*e926d9f3SDaniel Fojt 	ldns_rr_list *rrsigs = NULL, *rrdata = NULL;
76*e926d9f3SDaniel Fojt 	ldns_status err;
77*e926d9f3SDaniel Fojt 	ldns_rr *rr;
78*e926d9f3SDaniel Fojt 
79*e926d9f3SDaniel Fojt 	/* check for invalid class and type */
80*e926d9f3SDaniel Fojt 	if (rdclass > 0xffff || rdtype > 0xffff) {
81*e926d9f3SDaniel Fojt 		result = ERRSET_INVAL;
82*e926d9f3SDaniel Fojt 		goto fail;
83*e926d9f3SDaniel Fojt 	}
84*e926d9f3SDaniel Fojt 
85*e926d9f3SDaniel Fojt 	/* don't allow queries of class or type ANY */
86*e926d9f3SDaniel Fojt 	if (rdclass == 0xff || rdtype == 0xff) {
87*e926d9f3SDaniel Fojt 		result = ERRSET_INVAL;
88*e926d9f3SDaniel Fojt 		goto fail;
89*e926d9f3SDaniel Fojt 	}
90*e926d9f3SDaniel Fojt 
91*e926d9f3SDaniel Fojt 	/* don't allow flags yet, unimplemented */
92*e926d9f3SDaniel Fojt 	if (flags) {
93*e926d9f3SDaniel Fojt 		result = ERRSET_INVAL;
94*e926d9f3SDaniel Fojt 		goto fail;
95*e926d9f3SDaniel Fojt 	}
96*e926d9f3SDaniel Fojt 
97*e926d9f3SDaniel Fojt 	/* Initialize resolver from resolv.conf */
98*e926d9f3SDaniel Fojt 	domain = ldns_dname_new_frm_str(hostname);
99*e926d9f3SDaniel Fojt 	if ((err = ldns_resolver_new_frm_file(&ldns_res, NULL)) != \
100*e926d9f3SDaniel Fojt 	    LDNS_STATUS_OK) {
101*e926d9f3SDaniel Fojt 		result = ERRSET_FAIL;
102*e926d9f3SDaniel Fojt 		goto fail;
103*e926d9f3SDaniel Fojt 	}
104*e926d9f3SDaniel Fojt 
105*e926d9f3SDaniel Fojt #ifdef LDNS_DEBUG
106*e926d9f3SDaniel Fojt 	ldns_resolver_set_debug(ldns_res, true);
107*e926d9f3SDaniel Fojt #endif /* LDNS_DEBUG */
108*e926d9f3SDaniel Fojt 
109*e926d9f3SDaniel Fojt 	ldns_resolver_set_dnssec(ldns_res, true); /* Use DNSSEC */
110*e926d9f3SDaniel Fojt 
111*e926d9f3SDaniel Fojt 	/* make query */
112*e926d9f3SDaniel Fojt 	pkt = ldns_resolver_query(ldns_res, domain, rdtype, rdclass, LDNS_RD);
113*e926d9f3SDaniel Fojt 
114*e926d9f3SDaniel Fojt 	/*** TODO: finer errcodes -- see original **/
115*e926d9f3SDaniel Fojt 	if (!pkt || ldns_pkt_ancount(pkt) < 1) {
116*e926d9f3SDaniel Fojt 		result = ERRSET_FAIL;
117*e926d9f3SDaniel Fojt 		goto fail;
118*e926d9f3SDaniel Fojt 	}
119*e926d9f3SDaniel Fojt 
120*e926d9f3SDaniel Fojt 	/* initialize rrset */
121*e926d9f3SDaniel Fojt 	rrset = calloc(1, sizeof(struct rrsetinfo));
122*e926d9f3SDaniel Fojt 	if (rrset == NULL) {
123*e926d9f3SDaniel Fojt 		result = ERRSET_NOMEMORY;
124*e926d9f3SDaniel Fojt 		goto fail;
125*e926d9f3SDaniel Fojt 	}
126*e926d9f3SDaniel Fojt 
127*e926d9f3SDaniel Fojt 	rrdata = ldns_pkt_rr_list_by_type(pkt, rdtype, LDNS_SECTION_ANSWER);
128*e926d9f3SDaniel Fojt 	rrset->rri_nrdatas = ldns_rr_list_rr_count(rrdata);
129*e926d9f3SDaniel Fojt 	if (!rrset->rri_nrdatas) {
130*e926d9f3SDaniel Fojt 		result = ERRSET_NODATA;
131*e926d9f3SDaniel Fojt 		goto fail;
132*e926d9f3SDaniel Fojt 	}
133*e926d9f3SDaniel Fojt 
134*e926d9f3SDaniel Fojt 	/* copy name from answer section */
135*e926d9f3SDaniel Fojt 	len = ldns_rdf_size(ldns_rr_owner(ldns_rr_list_rr(rrdata, 0)));
136*e926d9f3SDaniel Fojt 	if ((rrset->rri_name = malloc(len)) == NULL) {
137*e926d9f3SDaniel Fojt 		result = ERRSET_NOMEMORY;
138*e926d9f3SDaniel Fojt 		goto fail;
139*e926d9f3SDaniel Fojt 	}
140*e926d9f3SDaniel Fojt 	memcpy(rrset->rri_name,
141*e926d9f3SDaniel Fojt 	    ldns_rdf_data(ldns_rr_owner(ldns_rr_list_rr(rrdata, 0))), len);
142*e926d9f3SDaniel Fojt 
143*e926d9f3SDaniel Fojt 	rrset->rri_rdclass = ldns_rr_get_class(ldns_rr_list_rr(rrdata, 0));
144*e926d9f3SDaniel Fojt 	rrset->rri_rdtype = ldns_rr_get_type(ldns_rr_list_rr(rrdata, 0));
145*e926d9f3SDaniel Fojt 	rrset->rri_ttl = ldns_rr_ttl(ldns_rr_list_rr(rrdata, 0));
146*e926d9f3SDaniel Fojt 
147*e926d9f3SDaniel Fojt 	debug2("ldns: got %u answers from DNS", rrset->rri_nrdatas);
148*e926d9f3SDaniel Fojt 
149*e926d9f3SDaniel Fojt 	/* Check for authenticated data */
150*e926d9f3SDaniel Fojt 	if (ldns_pkt_ad(pkt)) {
151*e926d9f3SDaniel Fojt 		rrset->rri_flags |= RRSET_VALIDATED;
152*e926d9f3SDaniel Fojt 	} else { /* AD is not set, try autonomous validation */
153*e926d9f3SDaniel Fojt 		ldns_rr_list * trusted_keys = ldns_rr_list_new();
154*e926d9f3SDaniel Fojt 
155*e926d9f3SDaniel Fojt 		debug2("ldns: trying to validate RRset");
156*e926d9f3SDaniel Fojt 		/* Get eventual sigs */
157*e926d9f3SDaniel Fojt 		rrsigs = ldns_pkt_rr_list_by_type(pkt, LDNS_RR_TYPE_RRSIG,
158*e926d9f3SDaniel Fojt 		    LDNS_SECTION_ANSWER);
159*e926d9f3SDaniel Fojt 
160*e926d9f3SDaniel Fojt 		rrset->rri_nsigs = ldns_rr_list_rr_count(rrsigs);
161*e926d9f3SDaniel Fojt 		debug2("ldns: got %u signature(s) (RRTYPE %u) from DNS",
162*e926d9f3SDaniel Fojt 		       rrset->rri_nsigs, LDNS_RR_TYPE_RRSIG);
163*e926d9f3SDaniel Fojt 
164*e926d9f3SDaniel Fojt 		if ((err = ldns_verify_trusted(ldns_res, rrdata, rrsigs,
165*e926d9f3SDaniel Fojt 		     trusted_keys)) == LDNS_STATUS_OK) {
166*e926d9f3SDaniel Fojt 			rrset->rri_flags |= RRSET_VALIDATED;
167*e926d9f3SDaniel Fojt 			debug2("ldns: RRset is signed with a valid key");
168*e926d9f3SDaniel Fojt 		} else {
169*e926d9f3SDaniel Fojt 			debug2("ldns: RRset validation failed: %s",
170*e926d9f3SDaniel Fojt 			    ldns_get_errorstr_by_id(err));
171*e926d9f3SDaniel Fojt 		}
172*e926d9f3SDaniel Fojt 
173*e926d9f3SDaniel Fojt 		ldns_rr_list_deep_free(trusted_keys);
174*e926d9f3SDaniel Fojt 	}
175*e926d9f3SDaniel Fojt 
176*e926d9f3SDaniel Fojt 	/* allocate memory for answers */
177*e926d9f3SDaniel Fojt 	rrset->rri_rdatas = calloc(rrset->rri_nrdatas,
178*e926d9f3SDaniel Fojt 	   sizeof(struct rdatainfo));
179*e926d9f3SDaniel Fojt 
180*e926d9f3SDaniel Fojt 	if (rrset->rri_rdatas == NULL) {
181*e926d9f3SDaniel Fojt 		result = ERRSET_NOMEMORY;
182*e926d9f3SDaniel Fojt 		goto fail;
183*e926d9f3SDaniel Fojt 	}
184*e926d9f3SDaniel Fojt 
185*e926d9f3SDaniel Fojt 	/* allocate memory for signatures */
186*e926d9f3SDaniel Fojt 	if (rrset->rri_nsigs > 0) {
187*e926d9f3SDaniel Fojt 		rrset->rri_sigs = calloc(rrset->rri_nsigs,
188*e926d9f3SDaniel Fojt 		    sizeof(struct rdatainfo));
189*e926d9f3SDaniel Fojt 
190*e926d9f3SDaniel Fojt 		if (rrset->rri_sigs == NULL) {
191*e926d9f3SDaniel Fojt 			result = ERRSET_NOMEMORY;
192*e926d9f3SDaniel Fojt 			goto fail;
193*e926d9f3SDaniel Fojt 		}
194*e926d9f3SDaniel Fojt 	}
195*e926d9f3SDaniel Fojt 
196*e926d9f3SDaniel Fojt 	/* copy answers & signatures */
197*e926d9f3SDaniel Fojt 	for (i=0, index_ans=0, index_sig=0; i< pkt->_header->_ancount; i++) {
198*e926d9f3SDaniel Fojt 		rdata = NULL;
199*e926d9f3SDaniel Fojt 		rr = ldns_rr_list_rr(ldns_pkt_answer(pkt), i);
200*e926d9f3SDaniel Fojt 
201*e926d9f3SDaniel Fojt 		if (ldns_rr_get_class(rr) == rrset->rri_rdclass &&
202*e926d9f3SDaniel Fojt 		    ldns_rr_get_type(rr) == rrset->rri_rdtype) {
203*e926d9f3SDaniel Fojt 			rdata = &rrset->rri_rdatas[index_ans++];
204*e926d9f3SDaniel Fojt 		}
205*e926d9f3SDaniel Fojt 
206*e926d9f3SDaniel Fojt 		if (rr->_rr_class == rrset->rri_rdclass &&
207*e926d9f3SDaniel Fojt 		    rr->_rr_type == LDNS_RR_TYPE_RRSIG &&
208*e926d9f3SDaniel Fojt 		    rrset->rri_sigs) {
209*e926d9f3SDaniel Fojt 			rdata = &rrset->rri_sigs[index_sig++];
210*e926d9f3SDaniel Fojt 		}
211*e926d9f3SDaniel Fojt 
212*e926d9f3SDaniel Fojt 		if (rdata) {
213*e926d9f3SDaniel Fojt 			size_t rdata_offset = 0;
214*e926d9f3SDaniel Fojt 
215*e926d9f3SDaniel Fojt 			rdata->rdi_length = 0;
216*e926d9f3SDaniel Fojt 			for (j=0; j< rr->_rd_count; j++) {
217*e926d9f3SDaniel Fojt 				rdata->rdi_length +=
218*e926d9f3SDaniel Fojt 				    ldns_rdf_size(ldns_rr_rdf(rr, j));
219*e926d9f3SDaniel Fojt 			}
220*e926d9f3SDaniel Fojt 
221*e926d9f3SDaniel Fojt 			rdata->rdi_data = malloc(rdata->rdi_length);
222*e926d9f3SDaniel Fojt 			if (rdata->rdi_data == NULL) {
223*e926d9f3SDaniel Fojt 				result = ERRSET_NOMEMORY;
224*e926d9f3SDaniel Fojt 				goto fail;
225*e926d9f3SDaniel Fojt 			}
226*e926d9f3SDaniel Fojt 
227*e926d9f3SDaniel Fojt 			/* Re-create the raw DNS RDATA */
228*e926d9f3SDaniel Fojt 			for (j=0; j< rr->_rd_count; j++) {
229*e926d9f3SDaniel Fojt 				len = ldns_rdf_size(ldns_rr_rdf(rr, j));
230*e926d9f3SDaniel Fojt 				memcpy(rdata->rdi_data + rdata_offset,
231*e926d9f3SDaniel Fojt 				       ldns_rdf_data(ldns_rr_rdf(rr, j)), len);
232*e926d9f3SDaniel Fojt 				rdata_offset += len;
233*e926d9f3SDaniel Fojt 			}
234*e926d9f3SDaniel Fojt 		}
235*e926d9f3SDaniel Fojt 	}
236*e926d9f3SDaniel Fojt 
237*e926d9f3SDaniel Fojt 	*res = rrset;
238*e926d9f3SDaniel Fojt 	result = ERRSET_SUCCESS;
239*e926d9f3SDaniel Fojt 
240*e926d9f3SDaniel Fojt fail:
241*e926d9f3SDaniel Fojt 	/* freerrset(rrset); */
242*e926d9f3SDaniel Fojt 	ldns_rdf_deep_free(domain);
243*e926d9f3SDaniel Fojt 	ldns_pkt_free(pkt);
244*e926d9f3SDaniel Fojt 	ldns_rr_list_deep_free(rrsigs);
245*e926d9f3SDaniel Fojt 	ldns_rr_list_deep_free(rrdata);
246*e926d9f3SDaniel Fojt 	ldns_resolver_deep_free(ldns_res);
247*e926d9f3SDaniel Fojt 
248*e926d9f3SDaniel Fojt 	return result;
249*e926d9f3SDaniel Fojt }
250*e926d9f3SDaniel Fojt 
251*e926d9f3SDaniel Fojt 
252*e926d9f3SDaniel Fojt void
freerrset(struct rrsetinfo * rrset)253*e926d9f3SDaniel Fojt freerrset(struct rrsetinfo *rrset)
254*e926d9f3SDaniel Fojt {
255*e926d9f3SDaniel Fojt 	u_int16_t i;
256*e926d9f3SDaniel Fojt 
257*e926d9f3SDaniel Fojt 	if (rrset == NULL)
258*e926d9f3SDaniel Fojt 		return;
259*e926d9f3SDaniel Fojt 
260*e926d9f3SDaniel Fojt 	if (rrset->rri_rdatas) {
261*e926d9f3SDaniel Fojt 		for (i = 0; i < rrset->rri_nrdatas; i++) {
262*e926d9f3SDaniel Fojt 			if (rrset->rri_rdatas[i].rdi_data == NULL)
263*e926d9f3SDaniel Fojt 				break;
264*e926d9f3SDaniel Fojt 			free(rrset->rri_rdatas[i].rdi_data);
265*e926d9f3SDaniel Fojt 		}
266*e926d9f3SDaniel Fojt 		free(rrset->rri_rdatas);
267*e926d9f3SDaniel Fojt 	}
268*e926d9f3SDaniel Fojt 
269*e926d9f3SDaniel Fojt 	if (rrset->rri_sigs) {
270*e926d9f3SDaniel Fojt 		for (i = 0; i < rrset->rri_nsigs; i++) {
271*e926d9f3SDaniel Fojt 			if (rrset->rri_sigs[i].rdi_data == NULL)
272*e926d9f3SDaniel Fojt 				break;
273*e926d9f3SDaniel Fojt 			free(rrset->rri_sigs[i].rdi_data);
274*e926d9f3SDaniel Fojt 		}
275*e926d9f3SDaniel Fojt 		free(rrset->rri_sigs);
276*e926d9f3SDaniel Fojt 	}
277*e926d9f3SDaniel Fojt 
278*e926d9f3SDaniel Fojt 	if (rrset->rri_name)
279*e926d9f3SDaniel Fojt 		free(rrset->rri_name);
280*e926d9f3SDaniel Fojt 	free(rrset);
281*e926d9f3SDaniel Fojt }
282*e926d9f3SDaniel Fojt 
283*e926d9f3SDaniel Fojt 
284*e926d9f3SDaniel Fojt #endif /* !defined (HAVE_GETRRSETBYNAME) && defined (HAVE_LDNS) */
285