/src/bind9/fuzz/dns_message_checksig.c
Line | Count | Source |
1 | | /* |
2 | | * Copyright (C) Internet Systems Consortium, Inc. ("ISC") |
3 | | * |
4 | | * SPDX-License-Identifier: MPL-2.0 |
5 | | * |
6 | | * This Source Code Form is subject to the terms of the Mozilla Public |
7 | | * License, v. 2.0. If a copy of the MPL was not distributed with this |
8 | | * file, you can obtain one at https://mozilla.org/MPL/2.0/. |
9 | | * |
10 | | * See the COPYRIGHT file distributed with this work for additional |
11 | | * information regarding copyright ownership. |
12 | | */ |
13 | | |
14 | | #include <inttypes.h> |
15 | | #include <stdbool.h> |
16 | | #include <stdlib.h> |
17 | | #include <unistd.h> |
18 | | |
19 | | #include <isc/buffer.h> |
20 | | #include <isc/commandline.h> |
21 | | #include <isc/file.h> |
22 | | #include <isc/mem.h> |
23 | | #include <isc/result.h> |
24 | | #include <isc/string.h> |
25 | | #include <isc/tid.h> |
26 | | #include <isc/util.h> |
27 | | |
28 | | #include <dns/fixedname.h> |
29 | | #include <dns/message.h> |
30 | | #include <dns/name.h> |
31 | | #include <dns/rcode.h> |
32 | | #include <dns/tsig.h> |
33 | | #include <dns/view.h> |
34 | | #include <dns/zone.h> |
35 | | #include <dns/zoneproperties.h> |
36 | | |
37 | | #include "fuzz.h" |
38 | | |
39 | | bool debug = false; |
40 | | |
41 | | static isc_mem_t *mctx = NULL; |
42 | | |
43 | | /* |
44 | | * Packet dumps of validily signed request ./IN/SOA |
45 | | * requests. |
46 | | * |
47 | | * TSIG: |
48 | | * |
49 | | * 0x0000: 600b 0900 006a 1140 0000 0000 0000 0000 |
50 | | * 0x0010: 0000 0000 0000 0001 0000 0000 0000 0000 |
51 | | * 0x0020: 0000 0000 0000 0001 cc88 0035 006a 007d |
52 | | * 0x0030: 1dfa 0000 0001 0000 0000 0001 0000 0600 |
53 | | * 0x0040: 0108 7473 6967 2d6b 6579 0000 fa00 ff00 |
54 | | * 0x0050: 0000 0000 3d0b 686d 6163 2d73 6861 3235 |
55 | | * 0x0060: 3600 0000 622a cce1 012c 0020 224d 5807 |
56 | | * 0x0070: 648d 1400 9d8e fc1c d049 55e9 cc90 2187 |
57 | | * 0x0080: 3b5f af5c 8899 dc27 c8df b34b 1dfa 0000 |
58 | | * 0x0090: 0000 |
59 | | * |
60 | | * SIG(0): |
61 | | * |
62 | | * 0x0000: 6004 0e00 013f 1140 0000 0000 0000 0000 |
63 | | * 0x0010: 0000 0000 0000 0001 0000 0000 0000 0000 |
64 | | * 0x0020: 0000 0000 0000 0001 c0a7 0035 013f 0152 |
65 | | * 0x0030: 0000 0000 0001 0000 0000 0001 0000 0600 |
66 | | * 0x0040: 0100 0018 00ff 0000 0000 011b 0000 0800 |
67 | | * 0x0050: 0000 0000 622a ce0d 622a cbb5 da71 0773 |
68 | | * 0x0060: 6967 306b 6579 0068 988b 27bf 5c89 5270 |
69 | | * 0x0070: c5ba ea8b 2e10 0512 9b44 48d3 69de b7ec |
70 | | * 0x0080: 7c67 15f3 6bc7 b0dc 277b e8f1 6979 4c89 |
71 | | * 0x0090: 149a 0203 30a1 c0b7 a711 ee8a 8d90 ebb9 |
72 | | * 0x00a0: 9e33 dd65 33d5 5d1d 90db cf9c bb6a b346 |
73 | | * 0x00b0: 568f a399 71d7 c877 616d 2fb7 0f86 963f |
74 | | * 0x00c0: aa00 850d 180a 9f83 cd4b d115 c79f 64c9 |
75 | | * 0x00d0: ff05 e751 6810 28b3 2249 c4ba 2d8d 57ba |
76 | | * 0x00e0: 9aad f1fc b34e c237 9465 04fd fe4d 19c9 |
77 | | * 0x00f0: 2368 ec8e 7097 eaea e067 2b9c 06eb c383 |
78 | | * 0x0100: e901 a11e 606b 4cce c12a 0e57 8c09 b7cb |
79 | | * 0x0110: 23bb ec05 b68b 1852 9288 b665 fe89 cf62 |
80 | | * 0x0120: 0a41 5e5a acbe 6903 cbb7 e7b6 cab4 e4a2 |
81 | | * 0x0130: b98f 884f c09d 5b39 c695 c84c 9a92 f110 |
82 | | * 0x0140: ccc3 f2ee 313f a2a1 1cda 5aa2 faec d593 |
83 | | * 0x0150: 4514 724a 868f 94b9 0547 4dc9 7b73 c85e |
84 | | * 0x0160: 544c 73d4 e892 f9 |
85 | | */ |
86 | | |
87 | 228 | #define HMACSHA256 "\x0bhmac-sha256" |
88 | | |
89 | | static isc_stdtime_t fuzztime = 0x622acce1; |
90 | | static dns_view_t *view = NULL; |
91 | | static dns_tsigkey_t *tsigkey = NULL; |
92 | | static dns_tsigkeyring_t *ring = NULL; |
93 | | static dns_tsigkeyring_t *emptyring = NULL; |
94 | | static char *wd = NULL; |
95 | | static char template[] = "/tmp/dns-message-checksig-XXXXXX"; |
96 | | |
97 | | static char f1[] = "Ksig0key.+008+55921.key"; |
98 | | static char c1[] = "sig0key. IN KEY 512 3 8 " |
99 | | "AwEAAa22lgHi1vAbQvu5ETdTrm2H8rwga9tvyMa6LFiSDyevLvSv0Uo5 " |
100 | | "uvfrXnxaLdtBMts6e1Ly2piSH9JRbOGMNibOK4EXWhWAn8MII4SWgQAs " |
101 | | "bFwtiz4HyPn2wScrUQdo8DocKiQJBanesr7vDO8fdA6Rg1e0yAtSeNti " |
102 | | "e8avx46/HJa6CFs3CoE0sf6oOFSxM954AgCBTXOGNBt1Nt3Bhfqt2qyA " |
103 | | "TLFii5K1jLDTZDVkoiyDXL1M7wcTwKf9METgj1eQmH3GGlRM/OJ/j8xk " |
104 | | "ZiFGbL3cipWdiH48031jiV2hlc92mKn8Ya0d9AN6c44piza/JSFydZXw " |
105 | | "sY32nxzjDbs=\n"; |
106 | | |
107 | | static char f2[] = "Ksig0key.+008+55921.private"; |
108 | | static char c2[] = "Private-key-format: v1.3\n\ |
109 | | Algorithm: 8 (RSASHA256)\n\ |
110 | | Modulus: rbaWAeLW8BtC+7kRN1OubYfyvCBr22/IxrosWJIPJ68u9K/RSjm69+tefFot20Ey2zp7UvLamJIf0lFs4Yw2Js4rgRdaFYCfwwgjhJaBACxsXC2LPgfI+fbBJytRB2jwOhwqJAkFqd6yvu8M7x90DpGDV7TIC1J422J7xq/Hjr8clroIWzcKgTSx/qg4VLEz3ngCAIFNc4Y0G3U23cGF+q3arIBMsWKLkrWMsNNkNWSiLINcvUzvBxPAp/0wROCPV5CYfcYaVEz84n+PzGRmIUZsvdyKlZ2IfjzTfWOJXaGVz3aYqfxhrR30A3pzjimLNr8lIXJ1lfCxjfafHOMNuw==\n\ |
111 | | PublicExponent: AQAB\n\ |
112 | | PrivateExponent: GDfclFkR5ToFGH9rMTRMnP73Q5dzjLgkx4vyHcuzKtxcvAans4+hNj+NazckAy2E+mpzV2j95TJ4wZjSM2RvB5xLwBIc4Dg6oyAHL6Ikoae6gw64cHFOaYb808n8CyqWqfX+QWAz9sRSVZXnTuPViX3A+svR7ejVak9Bzr1NTDm0DFlrhaKVCYA++dKVZerfuNiXT/jQvrc4wMCa7WWsfLsFO8aTNkEhqUnmS9c5VYgr7MkCV4ENDBcISpQc9wElI0hl12QPaSj8iSdk9liYp+HTiOxOyp6BGGuecKAoQijMwrZy4qExdOxvowptll8+nZLtwGRn/un/xvIZY5OLAQ==\n\ |
113 | | Prime1: ww3C6jwnrLQik/zxSgC0KuqgHq68cCjiRjwK2/euzs7NkMevFpXvV0cWO8x1/wKC1mszVLsUaKTvH6fzRsXfz5MPihzNzUYFwvobKVLserSxEwHNk+FKUU+q07Kf8WWnCqX5nX9QzVG1q4J8Q44N49I5S480jHLGYbyLZrEYMQE=\n\ |
114 | | Prime2: 4/3Ozq/8vRgcO4bieFs4CbZR7C98HiTi65SiLBIKY09mDfCleZI0uurAYBluZJgHS5AC5cdyHFuJr3uKxvD+Mgdlru40U6cSCEdK7HAhyUGZUndWl28wyMEB6Kke1/owxVn0S4RKLPOgFI2668H6JObaqXf0wyY89RdVQP6VQrs=\n\ |
115 | | Exponent1: Tbr9MyVX1j5PDVSev5P6OKQZvUB7PeM9ESo6VaCl3CqTxx+cic6ke86LcLcxSrewdkxwP1LydiVMWfwvOcP/RhRf+/Uwmp5OC35qNpSiQuAhNObiCw2b9T1fYU/s52FQKTEtgXNMOxZV5IxyguVoaaLMTG08TsAqiKZ/kyP99QE=\n\ |
116 | | Exponent2: Q4qSNKrwLbixzHS2LL+hR0dK17RtiaSV0QKUVIf3qdoAusp6yxwkIOegnBeMm6JqLtl38kh2pq37iRAJWcxVEc8dMYiB2fJZpjgwmwDREYUsfcC611vqUN7UyO8pIwSMZDq045ZKPyzhVJV0NZmemEYHq0LNMO7oCheiewGwiDc=\n\ |
117 | | Coefficient: T2u/J4NgyO+OqoLpXBIpTBzqrvDk8tb0feYgsp5d16hHvbXxNkMUR8cI07RdbI9HnEldtmhAnbQ6SvFiy2YYjpw/1Fz2WwdxRqLaDV7UlhrT+CqltvU9d/N/xThBNKDa23Wf5Vat+HRiLHSgzsY1PseVCWN+g4azuK2D8+DLeHE=\n\ |
118 | | Created: 20220311073606\n\ |
119 | | Publish: 20220311073606\n\ |
120 | | Activate: 20220311073606\n"; |
121 | | |
122 | | static char f3[] = "sig0key.db"; |
123 | | static char c3[] = "sig0key. 0 IN SOA . . 0 0 0 0 0\n\ |
124 | | sig0key. 0 IN NS .\n\ |
125 | | sig0key. 0 IN KEY 512 3 8 AwEAAa22lgHi1vAbQvu5ETdTrm2H8rwga9tvyMa6LFiSDyevLvSv0Uo5 uvfrXnxaLdtBMts6e1Ly2piSH9JRbOGMNibOK4EXWhWAn8MII4SWgQAs bFwtiz4HyPn2wScrUQdo8DocKiQJBanesr7vDO8fdA6Rg1e0yAtSeNti e8avx46/HJa6CFs3CoE0sf6oOFSxM954AgCBTXOGNBt1Nt3Bhfqt2qyA TLFii5K1jLDTZDVkoiyDXL1M7wcTwKf9METgj1eQmH3GGlRM/OJ/j8xk ZiFGbL3cipWdiH48031jiV2hlc92mKn8Ya0d9AN6c44piza/JSFydZXw sY32nxzjDbs=\n"; |
126 | | |
127 | | int |
128 | 2 | LLVMFuzzerInitialize(int *argc ISC_ATTR_UNUSED, char ***argv ISC_ATTR_UNUSED) { |
129 | 2 | isc_result_t result; |
130 | 2 | dns_fixedname_t fixed; |
131 | 2 | dns_name_t *name = dns_fixedname_initname(&fixed); |
132 | 2 | unsigned char secret[16] = { 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, |
133 | 2 | 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, |
134 | 2 | 0xff, 0xff, 0xff, 0xff }; |
135 | 2 | dns_zone_t *zone = NULL; |
136 | 2 | char pathbuf[PATH_MAX]; |
137 | 2 | FILE *fd; |
138 | | |
139 | 2 | wd = mkdtemp(template); |
140 | 2 | if (wd == NULL) { |
141 | 0 | fprintf(stderr, "mkdtemp failed\n"); |
142 | 0 | return 1; |
143 | 0 | } |
144 | | |
145 | 2 | snprintf(pathbuf, sizeof(pathbuf), "%s/%s", wd, f1); |
146 | 2 | fd = fopen(pathbuf, "w"); |
147 | 2 | if (fd == NULL) { |
148 | 0 | fprintf(stderr, "fopen(%s) failed\n", pathbuf); |
149 | 0 | return 1; |
150 | 0 | } |
151 | 2 | fputs(c1, fd); |
152 | 2 | fclose(fd); |
153 | | |
154 | 2 | snprintf(pathbuf, sizeof(pathbuf), "%s/%s", wd, f2); |
155 | 2 | fd = fopen(pathbuf, "w"); |
156 | 2 | if (fd == NULL) { |
157 | 0 | fprintf(stderr, "fopen(%s) failed\n", pathbuf); |
158 | 0 | return 1; |
159 | 0 | } |
160 | 2 | fputs(c2, fd); |
161 | 2 | fclose(fd); |
162 | | |
163 | 2 | snprintf(pathbuf, sizeof(pathbuf), "%s/%s", wd, f3); |
164 | 2 | fd = fopen(pathbuf, "w"); |
165 | 2 | if (fd == NULL) { |
166 | 0 | fprintf(stderr, "fopen(%s) failed\n", pathbuf); |
167 | 0 | return 1; |
168 | 0 | } |
169 | 2 | fputs(c3, fd); |
170 | 2 | fclose(fd); |
171 | | |
172 | 2 | isc_mem_create("fuzz", &mctx); |
173 | | |
174 | 2 | isc_loopmgr_create(mctx, 1); |
175 | | |
176 | 2 | dns_view_create(mctx, NULL, dns_rdataclass_in, "view", &view); |
177 | | |
178 | 2 | dns_tsigkeyring_create(mctx, &ring); |
179 | 2 | dns_tsigkeyring_create(mctx, &emptyring); |
180 | | |
181 | 2 | result = dns_name_fromstring(name, "tsig-key", dns_rootname, 0, NULL); |
182 | 2 | if (result != ISC_R_SUCCESS) { |
183 | 0 | fprintf(stderr, "dns_name_fromstring failed: %s\n", |
184 | 0 | isc_result_totext(result)); |
185 | 0 | return 1; |
186 | 0 | } |
187 | | |
188 | 2 | result = dns_tsigkey_create(name, DST_ALG_HMACSHA256, secret, |
189 | 2 | sizeof(secret), mctx, &tsigkey); |
190 | 2 | if (result != ISC_R_SUCCESS) { |
191 | 0 | fprintf(stderr, "dns_tsigkey_create failed: %s\n", |
192 | 0 | isc_result_totext(result)); |
193 | 0 | return 1; |
194 | 0 | } |
195 | 2 | result = dns_tsigkeyring_add(ring, tsigkey); |
196 | 2 | if (result != ISC_R_SUCCESS) { |
197 | 0 | fprintf(stderr, "dns_tsigkeyring_add failed: %s\n", |
198 | 0 | isc_result_totext(result)); |
199 | 0 | return 1; |
200 | 0 | } |
201 | | |
202 | 2 | result = dns_name_fromstring(name, "sig0key", dns_rootname, 0, NULL); |
203 | 2 | if (result != ISC_R_SUCCESS) { |
204 | 0 | fprintf(stderr, "dns_name_fromstring failed: %s\n", |
205 | 0 | isc_result_totext(result)); |
206 | 0 | return 1; |
207 | 0 | } |
208 | | |
209 | 2 | dns_zone_create(&zone, mctx, 0); |
210 | | |
211 | 2 | dns_zone_setorigin(zone, name); |
212 | 2 | dns_zone_setclass(zone, view->rdclass); |
213 | 2 | dns_zone_settype(zone, dns_zone_primary); |
214 | 2 | dns_zone_setkeydirectory(zone, wd); |
215 | 2 | dns_zone_setfile(zone, pathbuf, NULL, dns_masterformat_text, |
216 | 2 | &dns_master_style_default); |
217 | | |
218 | 2 | result = dns_zone_load(zone, false); |
219 | 2 | if (result != ISC_R_SUCCESS) { |
220 | 0 | fprintf(stderr, "dns_zone_load failed: %s\n", |
221 | 0 | isc_result_totext(result)); |
222 | 0 | return 1; |
223 | 0 | } |
224 | | |
225 | 2 | result = dns_view_addzone(view, zone); |
226 | 2 | if (result != ISC_R_SUCCESS) { |
227 | 0 | fprintf(stderr, "dns_view_addzone failed: %s\n", |
228 | 0 | isc_result_totext(result)); |
229 | 0 | return 1; |
230 | 0 | } |
231 | | |
232 | 2 | dns_zone_setview(zone, view); |
233 | 2 | dns_view_freeze(view); |
234 | | |
235 | 2 | dns_zone_detach(&zone); |
236 | | |
237 | 2 | return 0; |
238 | 2 | } |
239 | | |
240 | | static isc_result_t |
241 | | create_message(dns_message_t **messagep, const uint8_t *data, size_t size, |
242 | 1.70k | bool addasig, bool addtsig) { |
243 | 1.70k | isc_result_t result; |
244 | 1.70k | dns_message_t *message = NULL; |
245 | 1.70k | isc_buffer_t b; |
246 | 1.70k | static unsigned char buf[65535]; |
247 | | |
248 | 1.70k | isc_buffer_init(&b, buf, sizeof(buf)); |
249 | | |
250 | | /* Message ID */ |
251 | 1.70k | isc_buffer_putuint16(&b, 0); |
252 | | |
253 | | /* QR, Opcode, other flags = 0, rcode = 0 */ |
254 | 1.70k | isc_buffer_putuint16(&b, (*data & 0x1f) << 11); |
255 | | /* Counts */ |
256 | 1.70k | isc_buffer_putuint16(&b, 1); |
257 | 1.70k | isc_buffer_putuint16(&b, 0); |
258 | 1.70k | isc_buffer_putuint16(&b, 0); |
259 | 1.70k | isc_buffer_putuint16(&b, addasig ? 1 : 0); |
260 | | |
261 | | /* Question ./IN/SOA */ |
262 | 1.70k | isc_buffer_putuint8(&b, 0); |
263 | 1.70k | isc_buffer_putuint16(&b, 6); |
264 | 1.70k | isc_buffer_putuint16(&b, 1); |
265 | | |
266 | 1.70k | if (addasig) { |
267 | | /* Signature */ |
268 | 1.68k | if (addtsig) { |
269 | 1.00k | const unsigned char keyname[] = "\x08tsig-key"; |
270 | 1.00k | isc_buffer_putmem(&b, keyname, sizeof(keyname)); |
271 | 1.00k | isc_buffer_putuint16(&b, dns_rdatatype_tsig); |
272 | 1.00k | isc_buffer_putuint16(&b, dns_rdataclass_any); |
273 | 1.00k | } else { |
274 | 678 | isc_buffer_putuint8(&b, 0); /* '.' */ |
275 | 678 | isc_buffer_putuint16(&b, dns_rdatatype_sig); |
276 | 678 | isc_buffer_putuint16(&b, dns_rdataclass_in); |
277 | 678 | } |
278 | 1.68k | isc_buffer_putuint32(&b, 0); /* ttl */ |
279 | 1.68k | data++; |
280 | 1.68k | size--; |
281 | 1.68k | if (size > isc_buffer_availablelength(&b) - 2) { |
282 | 11 | size = isc_buffer_availablelength(&b) - 2; |
283 | 11 | } |
284 | 1.68k | isc_buffer_putuint16(&b, size); |
285 | 1.68k | isc_buffer_putmem(&b, data, size); |
286 | 1.68k | } |
287 | | |
288 | 1.70k | dns_message_create(mctx, NULL, NULL, DNS_MESSAGE_INTENTPARSE, &message); |
289 | | |
290 | 1.70k | result = dns_message_parse(message, &b, 0); |
291 | 1.70k | if (debug) { |
292 | 0 | fprintf(stderr, "dns_message_parse => %s\n", |
293 | 0 | isc_result_totext(result)); |
294 | 0 | } |
295 | 1.70k | if (result != ISC_R_SUCCESS) { |
296 | 550 | dns_message_detach(&message); |
297 | 1.15k | } else { |
298 | 1.15k | if (debug) { |
299 | 0 | char text[200000]; |
300 | 0 | isc_buffer_init(&b, text, sizeof(text)); |
301 | |
|
302 | 0 | result = dns_message_totext( |
303 | 0 | message, &dns_master_style_debug, 0, &b); |
304 | 0 | if (result == ISC_R_SUCCESS) { |
305 | 0 | fprintf(stderr, "%.*s", (int)b.used, text); |
306 | 0 | } else { |
307 | 0 | fprintf(stderr, "dns_message_totext => %s\n", |
308 | 0 | isc_result_totext(result)); |
309 | 0 | } |
310 | 0 | } |
311 | 1.15k | *messagep = message; |
312 | 1.15k | } |
313 | 1.70k | return result; |
314 | 1.70k | } |
315 | | |
316 | | int |
317 | 1.70k | LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) { |
318 | 1.70k | isc_result_t result; |
319 | 1.70k | dns_message_t *message = NULL; |
320 | 1.70k | unsigned char query_tsig[23 + 32 + 6] = { 0 }; |
321 | 1.70k | bool addasig = false; |
322 | 1.70k | bool addtime = false; |
323 | 1.70k | bool addtsig = false; |
324 | 1.70k | bool setquerytsig = false; |
325 | 1.70k | bool settsigkey = false; |
326 | 1.70k | bool subtime = false; |
327 | 1.70k | bool withring = false; |
328 | 1.70k | bool withview = false; |
329 | | |
330 | | /* |
331 | | * The first 2 octets affect setup. |
332 | | * Octet 1 determines whether a signature is added and which type |
333 | | * (addasig, addtsig), whether time should be adjusted (addtime, |
334 | | * subtime), whether dns_message_setquerytsig and dns_message_settsigkey |
335 | | * have been called, whether there is a keyring available with the |
336 | | * TSIG key or a view is defined. |
337 | | * |
338 | | * The second octet defines if the message is a response and the |
339 | | * opcode. |
340 | | */ |
341 | 1.70k | if (size > 65535 || size < 2) { |
342 | 7 | return 0; |
343 | 7 | } |
344 | | |
345 | 1.70k | addasig = (*data & 0x80) != 0; |
346 | 1.70k | addtime = (*data & 0x40) != 0; |
347 | 1.70k | addtsig = (*data & 0x20) != 0; |
348 | 1.70k | setquerytsig = (*data & 0x10) != 0; |
349 | 1.70k | settsigkey = (*data & 0x08) != 0; |
350 | 1.70k | subtime = (*data & 0x04) != 0; |
351 | 1.70k | withring = (*data & 0x02) != 0; |
352 | 1.70k | withview = (*data & 0x01) != 0; |
353 | | |
354 | 1.70k | data++; |
355 | 1.70k | size--; |
356 | | |
357 | 1.70k | if (debug) { |
358 | 0 | fprintf(stderr, |
359 | 0 | "addasig=%u addtime=%u addtsig=%u setquerytsig=%u " |
360 | 0 | "settsigkey=%u subtime=%u withring=%u\nwithview=%u\n", |
361 | 0 | addasig, addtime, addtsig, setquerytsig, settsigkey, |
362 | 0 | subtime, withring, withview); |
363 | 0 | } |
364 | | |
365 | 1.70k | result = create_message(&message, data, size, addasig, addtsig); |
366 | 1.70k | if (result != ISC_R_SUCCESS) { |
367 | 550 | return 0; |
368 | 550 | } |
369 | | |
370 | | /* |
371 | | * Make time calculations consistent. |
372 | | */ |
373 | 1.15k | message->fuzzing = 1; |
374 | 1.15k | message->fuzztime = fuzztime; |
375 | 1.15k | if (addtime) { |
376 | 327 | message->fuzztime += 1200; |
377 | 327 | } |
378 | 1.15k | if (subtime) { |
379 | 857 | message->fuzztime -= 1200; |
380 | 857 | } |
381 | | |
382 | 1.15k | if ((message->flags & DNS_MESSAGEFLAG_QR) != 0) { |
383 | 386 | if (setquerytsig) { |
384 | 228 | isc_buffer_t b; |
385 | 228 | unsigned char hmacname[] = HMACSHA256; |
386 | 228 | unsigned char hmacvalue[32] = { |
387 | 228 | 0x22, 0x4d, 0x58, 0x07, 0x64, 0x8d, 0x14, 0x00, |
388 | 228 | 0x9d, 0x8e, 0xfc, 0x1c, 0xd0, 0x49, 0x55, 0xe9, |
389 | 228 | 0xcc, 0x90, 0x21, 0x87, 0x3b, 0x5f, 0xaf, 0x5c, |
390 | 228 | 0x88, 0x99, 0xdc, 0x27, 0xc8, 0xdf, 0xb3, 0x4b |
391 | 228 | }; |
392 | | |
393 | | /* |
394 | | * Valid TSIG rdata for tsig-key over a plain |
395 | | * DNS QUERY for ./SOA/IN with no flags set. |
396 | | */ |
397 | 228 | isc_buffer_init(&b, query_tsig, sizeof(query_tsig)); |
398 | 228 | isc_buffer_putmem(&b, hmacname, sizeof(hmacname)); |
399 | 228 | isc_buffer_putuint16(&b, 0); /* time high */ |
400 | 228 | isc_buffer_putuint32(&b, 0x622abec0); /* time low */ |
401 | 228 | isc_buffer_putuint16(&b, 300); /* Fudge */ |
402 | 228 | isc_buffer_putuint16(&b, 32); /* Mac Length */ |
403 | | /* Mac */ |
404 | 228 | isc_buffer_putmem(&b, hmacvalue, 32); |
405 | 228 | isc_buffer_putuint16(&b, 7674); /* Original Id */ |
406 | 228 | isc_buffer_putuint16(&b, 0); /* Error */ |
407 | 228 | isc_buffer_putuint16(&b, 0); /* Other len */ |
408 | | |
409 | 228 | dns_message_setquerytsig(message, &b); |
410 | 228 | } |
411 | 386 | } |
412 | | |
413 | 1.15k | if (settsigkey) { |
414 | 280 | result = dns_message_settsigkey(message, tsigkey); |
415 | 280 | if (debug) { |
416 | 0 | fprintf(stderr, "dns_message_settsigkey => %s\n", |
417 | 0 | isc_result_totext(result)); |
418 | 0 | } |
419 | 280 | } |
420 | | |
421 | 1.15k | dns_view_setkeyring(view, withring ? ring : emptyring); |
422 | | |
423 | 1.15k | result = dns_message_checksig(message, withview ? view : NULL); |
424 | 1.15k | if (debug) { |
425 | 0 | char textbuf[64]; |
426 | 0 | isc_buffer_t b; |
427 | |
|
428 | 0 | fprintf(stderr, "dns_message_checksig => %s\n", |
429 | 0 | isc_result_totext(result)); |
430 | 0 | isc_buffer_init(&b, textbuf, sizeof(textbuf)); |
431 | 0 | dns_tsigrcode_totext(message->tsigstatus, &b); |
432 | 0 | fprintf(stderr, "tsigstatus=%.*s\n", (int)b.used, textbuf); |
433 | 0 | isc_buffer_init(&b, textbuf, sizeof(textbuf)); |
434 | 0 | dns_tsigrcode_totext(message->sig0status, &b); |
435 | 0 | fprintf(stderr, "sig0status=%.*s\n", (int)b.used, textbuf); |
436 | 0 | } |
437 | 1.15k | if (result != ISC_R_SUCCESS) { |
438 | 1.08k | goto cleanup; |
439 | 1.08k | } |
440 | | |
441 | 1.15k | cleanup: |
442 | 1.15k | if (message != NULL) { |
443 | 1.15k | dns_message_detach(&message); |
444 | 1.15k | } |
445 | | |
446 | 1.15k | return 0; |
447 | 1.15k | } |