1 /*
2 * Copyright (C) 2004, 2005, 2007, 2009, 2011, 2012, 2014, 2015 Internet Systems Consortium, Inc. ("ISC")
3 * Copyright (C) 2003 Internet Software Consortium.
4 *
5 * Permission to use, copy, modify, and/or distribute this software for any
6 * purpose with or without fee is hereby granted, provided that the above
7 * copyright notice and this permission notice appear in all copies.
8 *
9 * THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
10 * REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
11 * AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
12 * INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
13 * LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
14 * OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
15 * PERFORMANCE OF THIS SOFTWARE.
16 */
17
18 /* $Id$ */
19
20 /* Reviewed: Fri Mar 17 09:05:02 PST 2000 by gson */
21
22 /* RFC2535 */
23
24 #ifndef RDATA_GENERIC_RRSIG_46_C
25 #define RDATA_GENERIC_RRSIG_46_C
26
27 #define RRTYPE_RRSIG_ATTRIBUTES (DNS_RDATATYPEATTR_DNSSEC)
28
29 static inline isc_result_t
fromtext_rrsig(ARGS_FROMTEXT)30 fromtext_rrsig(ARGS_FROMTEXT) {
31 isc_token_t token;
32 unsigned char c;
33 long i;
34 dns_rdatatype_t covered;
35 char *e;
36 isc_result_t result;
37 dns_name_t name;
38 isc_buffer_t buffer;
39 isc_uint32_t time_signed, time_expire;
40
41 REQUIRE(type == dns_rdatatype_rrsig);
42
43 UNUSED(type);
44 UNUSED(rdclass);
45 UNUSED(callbacks);
46
47 /*
48 * Type covered.
49 */
50 RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
51 ISC_FALSE));
52 result = dns_rdatatype_fromtext(&covered, &token.value.as_textregion);
53 if (result != ISC_R_SUCCESS && result != ISC_R_NOTIMPLEMENTED) {
54 i = strtol(DNS_AS_STR(token), &e, 10);
55 if (i < 0 || i > 65535)
56 RETTOK(ISC_R_RANGE);
57 if (*e != 0)
58 RETTOK(result);
59 covered = (dns_rdatatype_t)i;
60 }
61 RETERR(uint16_tobuffer(covered, target));
62
63 /*
64 * Algorithm.
65 */
66 RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
67 ISC_FALSE));
68 RETTOK(dns_secalg_fromtext(&c, &token.value.as_textregion));
69 RETERR(mem_tobuffer(target, &c, 1));
70
71 /*
72 * Labels.
73 */
74 RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_number,
75 ISC_FALSE));
76 if (token.value.as_ulong > 0xffU)
77 RETTOK(ISC_R_RANGE);
78 c = (unsigned char)token.value.as_ulong;
79 RETERR(mem_tobuffer(target, &c, 1));
80
81 /*
82 * Original ttl.
83 */
84 RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_number,
85 ISC_FALSE));
86 RETERR(uint32_tobuffer(token.value.as_ulong, target));
87
88 /*
89 * Signature expiration.
90 */
91 RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
92 ISC_FALSE));
93 if (strlen(DNS_AS_STR(token)) <= 10U &&
94 *DNS_AS_STR(token) != '-' && *DNS_AS_STR(token) != '+') {
95 char *end;
96 unsigned long u;
97 isc_uint64_t u64;
98
99 u64 = u = strtoul(DNS_AS_STR(token), &end, 10);
100 if (u == ULONG_MAX || *end != 0)
101 RETTOK(DNS_R_SYNTAX);
102 if (u64 > 0xffffffffUL)
103 RETTOK(ISC_R_RANGE);
104 time_expire = u;
105 } else
106 RETTOK(dns_time32_fromtext(DNS_AS_STR(token), &time_expire));
107 RETERR(uint32_tobuffer(time_expire, target));
108
109 /*
110 * Time signed.
111 */
112 RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
113 ISC_FALSE));
114 if (strlen(DNS_AS_STR(token)) <= 10U &&
115 *DNS_AS_STR(token) != '-' && *DNS_AS_STR(token) != '+') {
116 char *end;
117 unsigned long u;
118 isc_uint64_t u64;
119
120 u64 = u = strtoul(DNS_AS_STR(token), &end, 10);
121 if (u == ULONG_MAX || *end != 0)
122 RETTOK(DNS_R_SYNTAX);
123 if (u64 > 0xffffffffUL)
124 RETTOK(ISC_R_RANGE);
125 time_signed = u;
126 } else
127 RETTOK(dns_time32_fromtext(DNS_AS_STR(token), &time_signed));
128 RETERR(uint32_tobuffer(time_signed, target));
129
130 /*
131 * Key footprint.
132 */
133 RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_number,
134 ISC_FALSE));
135 RETERR(uint16_tobuffer(token.value.as_ulong, target));
136
137 /*
138 * Signer.
139 */
140 RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
141 ISC_FALSE));
142 dns_name_init(&name, NULL);
143 buffer_fromregion(&buffer, &token.value.as_region);
144 if (origin == NULL)
145 origin = dns_rootname;
146 RETTOK(dns_name_fromtext(&name, &buffer, origin, options, target));
147
148 /*
149 * Sig.
150 */
151 return (isc_base64_tobuffer(lexer, target, -1));
152 }
153
154 static inline isc_result_t
totext_rrsig(ARGS_TOTEXT)155 totext_rrsig(ARGS_TOTEXT) {
156 isc_region_t sr;
157 char buf[sizeof("4294967295")];
158 dns_rdatatype_t covered;
159 unsigned long ttl;
160 unsigned long when;
161 unsigned long exp;
162 unsigned long foot;
163 dns_name_t name;
164
165 REQUIRE(rdata->type == dns_rdatatype_rrsig);
166 REQUIRE(rdata->length != 0);
167
168 dns_rdata_toregion(rdata, &sr);
169
170 /*
171 * Type covered.
172 */
173 covered = uint16_fromregion(&sr);
174 isc_region_consume(&sr, 2);
175 /*
176 * XXXAG We should have something like dns_rdatatype_isknown()
177 * that does the right thing with type 0.
178 */
179 if (dns_rdatatype_isknown(covered) && covered != 0) {
180 RETERR(dns_rdatatype_totext(covered, target));
181 } else {
182 sprintf(buf, "TYPE%u", covered);
183 RETERR(str_totext(buf, target));
184 }
185 RETERR(str_totext(" ", target));
186
187 /*
188 * Algorithm.
189 */
190 sprintf(buf, "%u", sr.base[0]);
191 isc_region_consume(&sr, 1);
192 RETERR(str_totext(buf, target));
193 RETERR(str_totext(" ", target));
194
195 /*
196 * Labels.
197 */
198 sprintf(buf, "%u", sr.base[0]);
199 isc_region_consume(&sr, 1);
200 RETERR(str_totext(buf, target));
201 RETERR(str_totext(" ", target));
202
203 /*
204 * Ttl.
205 */
206 ttl = uint32_fromregion(&sr);
207 isc_region_consume(&sr, 4);
208 sprintf(buf, "%lu", ttl);
209 RETERR(str_totext(buf, target));
210
211 if ((tctx->flags & DNS_STYLEFLAG_MULTILINE) != 0)
212 RETERR(str_totext(" (", target));
213 RETERR(str_totext(tctx->linebreak, target));
214
215 /*
216 * Sig exp.
217 */
218 exp = uint32_fromregion(&sr);
219 isc_region_consume(&sr, 4);
220 RETERR(dns_time32_totext(exp, target));
221 RETERR(str_totext(" ", target));
222
223 /*
224 * Time signed.
225 */
226 when = uint32_fromregion(&sr);
227 isc_region_consume(&sr, 4);
228 RETERR(dns_time32_totext(when, target));
229 RETERR(str_totext(" ", target));
230
231 /*
232 * Footprint.
233 */
234 foot = uint16_fromregion(&sr);
235 isc_region_consume(&sr, 2);
236 sprintf(buf, "%lu", foot);
237 RETERR(str_totext(buf, target));
238 RETERR(str_totext(" ", target));
239
240 /*
241 * Signer.
242 */
243 dns_name_init(&name, NULL);
244 dns_name_fromregion(&name, &sr);
245 isc_region_consume(&sr, name_length(&name));
246 RETERR(dns_name_totext(&name, ISC_FALSE, target));
247
248 /*
249 * Sig.
250 */
251 RETERR(str_totext(tctx->linebreak, target));
252 if (tctx->width == 0) /* No splitting */
253 RETERR(isc_base64_totext(&sr, 60, "", target));
254 else
255 RETERR(isc_base64_totext(&sr, tctx->width - 2,
256 tctx->linebreak, target));
257 if ((tctx->flags & DNS_STYLEFLAG_MULTILINE) != 0)
258 RETERR(str_totext(" )", target));
259
260 return (ISC_R_SUCCESS);
261 }
262
263 static inline isc_result_t
fromwire_rrsig(ARGS_FROMWIRE)264 fromwire_rrsig(ARGS_FROMWIRE) {
265 isc_region_t sr;
266 dns_name_t name;
267
268 REQUIRE(type == dns_rdatatype_rrsig);
269
270 UNUSED(type);
271 UNUSED(rdclass);
272
273 dns_decompress_setmethods(dctx, DNS_COMPRESS_NONE);
274
275 isc_buffer_activeregion(source, &sr);
276 /*
277 * type covered: 2
278 * algorithm: 1
279 * labels: 1
280 * original ttl: 4
281 * signature expiration: 4
282 * time signed: 4
283 * key footprint: 2
284 */
285 if (sr.length < 18)
286 return (ISC_R_UNEXPECTEDEND);
287
288 isc_buffer_forward(source, 18);
289 RETERR(mem_tobuffer(target, sr.base, 18));
290
291 /*
292 * Signer.
293 */
294 dns_name_init(&name, NULL);
295 RETERR(dns_name_fromwire(&name, source, dctx, options, target));
296
297 /*
298 * Sig.
299 */
300 isc_buffer_activeregion(source, &sr);
301 isc_buffer_forward(source, sr.length);
302 return (mem_tobuffer(target, sr.base, sr.length));
303 }
304
305 static inline isc_result_t
towire_rrsig(ARGS_TOWIRE)306 towire_rrsig(ARGS_TOWIRE) {
307 isc_region_t sr;
308 dns_name_t name;
309 dns_offsets_t offsets;
310
311 REQUIRE(rdata->type == dns_rdatatype_rrsig);
312 REQUIRE(rdata->length != 0);
313
314 dns_compress_setmethods(cctx, DNS_COMPRESS_NONE);
315 dns_rdata_toregion(rdata, &sr);
316 /*
317 * type covered: 2
318 * algorithm: 1
319 * labels: 1
320 * original ttl: 4
321 * signature expiration: 4
322 * time signed: 4
323 * key footprint: 2
324 */
325 RETERR(mem_tobuffer(target, sr.base, 18));
326 isc_region_consume(&sr, 18);
327
328 /*
329 * Signer.
330 */
331 dns_name_init(&name, offsets);
332 dns_name_fromregion(&name, &sr);
333 isc_region_consume(&sr, name_length(&name));
334 RETERR(dns_name_towire(&name, cctx, target));
335
336 /*
337 * Signature.
338 */
339 return (mem_tobuffer(target, sr.base, sr.length));
340 }
341
342 static inline int
compare_rrsig(ARGS_COMPARE)343 compare_rrsig(ARGS_COMPARE) {
344 isc_region_t r1;
345 isc_region_t r2;
346
347 REQUIRE(rdata1->type == rdata2->type);
348 REQUIRE(rdata1->rdclass == rdata2->rdclass);
349 REQUIRE(rdata1->type == dns_rdatatype_rrsig);
350 REQUIRE(rdata1->length != 0);
351 REQUIRE(rdata2->length != 0);
352
353 dns_rdata_toregion(rdata1, &r1);
354 dns_rdata_toregion(rdata2, &r2);
355 return (isc_region_compare(&r1, &r2));
356 }
357
358 static inline isc_result_t
fromstruct_rrsig(ARGS_FROMSTRUCT)359 fromstruct_rrsig(ARGS_FROMSTRUCT) {
360 dns_rdata_rrsig_t *sig = source;
361
362 REQUIRE(type == dns_rdatatype_rrsig);
363 REQUIRE(source != NULL);
364 REQUIRE(sig->common.rdtype == type);
365 REQUIRE(sig->common.rdclass == rdclass);
366 REQUIRE(sig->signature != NULL || sig->siglen == 0);
367
368 UNUSED(type);
369 UNUSED(rdclass);
370
371 /*
372 * Type covered.
373 */
374 RETERR(uint16_tobuffer(sig->covered, target));
375
376 /*
377 * Algorithm.
378 */
379 RETERR(uint8_tobuffer(sig->algorithm, target));
380
381 /*
382 * Labels.
383 */
384 RETERR(uint8_tobuffer(sig->labels, target));
385
386 /*
387 * Original TTL.
388 */
389 RETERR(uint32_tobuffer(sig->originalttl, target));
390
391 /*
392 * Expire time.
393 */
394 RETERR(uint32_tobuffer(sig->timeexpire, target));
395
396 /*
397 * Time signed.
398 */
399 RETERR(uint32_tobuffer(sig->timesigned, target));
400
401 /*
402 * Key ID.
403 */
404 RETERR(uint16_tobuffer(sig->keyid, target));
405
406 /*
407 * Signer name.
408 */
409 RETERR(name_tobuffer(&sig->signer, target));
410
411 /*
412 * Signature.
413 */
414 return (mem_tobuffer(target, sig->signature, sig->siglen));
415 }
416
417 static inline isc_result_t
tostruct_rrsig(ARGS_TOSTRUCT)418 tostruct_rrsig(ARGS_TOSTRUCT) {
419 isc_region_t sr;
420 dns_rdata_rrsig_t *sig = target;
421 dns_name_t signer;
422
423 REQUIRE(rdata->type == dns_rdatatype_rrsig);
424 REQUIRE(target != NULL);
425 REQUIRE(rdata->length != 0);
426
427 sig->common.rdclass = rdata->rdclass;
428 sig->common.rdtype = rdata->type;
429 ISC_LINK_INIT(&sig->common, link);
430
431 dns_rdata_toregion(rdata, &sr);
432
433 /*
434 * Type covered.
435 */
436 sig->covered = uint16_fromregion(&sr);
437 isc_region_consume(&sr, 2);
438
439 /*
440 * Algorithm.
441 */
442 sig->algorithm = uint8_fromregion(&sr);
443 isc_region_consume(&sr, 1);
444
445 /*
446 * Labels.
447 */
448 sig->labels = uint8_fromregion(&sr);
449 isc_region_consume(&sr, 1);
450
451 /*
452 * Original TTL.
453 */
454 sig->originalttl = uint32_fromregion(&sr);
455 isc_region_consume(&sr, 4);
456
457 /*
458 * Expire time.
459 */
460 sig->timeexpire = uint32_fromregion(&sr);
461 isc_region_consume(&sr, 4);
462
463 /*
464 * Time signed.
465 */
466 sig->timesigned = uint32_fromregion(&sr);
467 isc_region_consume(&sr, 4);
468
469 /*
470 * Key ID.
471 */
472 sig->keyid = uint16_fromregion(&sr);
473 isc_region_consume(&sr, 2);
474
475 dns_name_init(&signer, NULL);
476 dns_name_fromregion(&signer, &sr);
477 dns_name_init(&sig->signer, NULL);
478 RETERR(name_duporclone(&signer, mctx, &sig->signer));
479 isc_region_consume(&sr, name_length(&sig->signer));
480
481 /*
482 * Signature.
483 */
484 sig->siglen = sr.length;
485 sig->signature = mem_maybedup(mctx, sr.base, sig->siglen);
486 if (sig->signature == NULL)
487 goto cleanup;
488
489
490 sig->mctx = mctx;
491 return (ISC_R_SUCCESS);
492
493 cleanup:
494 if (mctx != NULL)
495 dns_name_free(&sig->signer, mctx);
496 return (ISC_R_NOMEMORY);
497 }
498
499 static inline void
freestruct_rrsig(ARGS_FREESTRUCT)500 freestruct_rrsig(ARGS_FREESTRUCT) {
501 dns_rdata_rrsig_t *sig = (dns_rdata_rrsig_t *) source;
502
503 REQUIRE(source != NULL);
504 REQUIRE(sig->common.rdtype == dns_rdatatype_rrsig);
505
506 if (sig->mctx == NULL)
507 return;
508
509 dns_name_free(&sig->signer, sig->mctx);
510 if (sig->signature != NULL)
511 isc_mem_free(sig->mctx, sig->signature);
512 sig->mctx = NULL;
513 }
514
515 static inline isc_result_t
additionaldata_rrsig(ARGS_ADDLDATA)516 additionaldata_rrsig(ARGS_ADDLDATA) {
517 REQUIRE(rdata->type == dns_rdatatype_rrsig);
518
519 UNUSED(rdata);
520 UNUSED(add);
521 UNUSED(arg);
522
523 return (ISC_R_SUCCESS);
524 }
525
526 static inline isc_result_t
digest_rrsig(ARGS_DIGEST)527 digest_rrsig(ARGS_DIGEST) {
528
529 REQUIRE(rdata->type == dns_rdatatype_rrsig);
530
531 UNUSED(rdata);
532 UNUSED(digest);
533 UNUSED(arg);
534
535 return (ISC_R_NOTIMPLEMENTED);
536 }
537
538 static inline dns_rdatatype_t
covers_rrsig(dns_rdata_t * rdata)539 covers_rrsig(dns_rdata_t *rdata) {
540 dns_rdatatype_t type;
541 isc_region_t r;
542
543 REQUIRE(rdata->type == dns_rdatatype_rrsig);
544
545 dns_rdata_toregion(rdata, &r);
546 type = uint16_fromregion(&r);
547
548 return (type);
549 }
550
551 static inline isc_boolean_t
checkowner_rrsig(ARGS_CHECKOWNER)552 checkowner_rrsig(ARGS_CHECKOWNER) {
553
554 REQUIRE(type == dns_rdatatype_rrsig);
555
556 UNUSED(name);
557 UNUSED(type);
558 UNUSED(rdclass);
559 UNUSED(wildcard);
560
561 return (ISC_TRUE);
562 }
563
564 static inline isc_boolean_t
checknames_rrsig(ARGS_CHECKNAMES)565 checknames_rrsig(ARGS_CHECKNAMES) {
566
567 REQUIRE(rdata->type == dns_rdatatype_rrsig);
568
569 UNUSED(rdata);
570 UNUSED(owner);
571 UNUSED(bad);
572
573 return (ISC_TRUE);
574 }
575
576 static inline int
casecompare_rrsig(ARGS_COMPARE)577 casecompare_rrsig(ARGS_COMPARE) {
578 isc_region_t r1;
579 isc_region_t r2;
580 dns_name_t name1;
581 dns_name_t name2;
582 int order;
583
584 REQUIRE(rdata1->type == rdata2->type);
585 REQUIRE(rdata1->rdclass == rdata2->rdclass);
586 REQUIRE(rdata1->type == dns_rdatatype_rrsig);
587 REQUIRE(rdata1->length != 0);
588 REQUIRE(rdata2->length != 0);
589
590 dns_rdata_toregion(rdata1, &r1);
591 dns_rdata_toregion(rdata2, &r2);
592
593 INSIST(r1.length > 18);
594 INSIST(r2.length > 18);
595 r1.length = 18;
596 r2.length = 18;
597 order = isc_region_compare(&r1, &r2);
598 if (order != 0)
599 return (order);
600
601 dns_name_init(&name1, NULL);
602 dns_name_init(&name2, NULL);
603 dns_rdata_toregion(rdata1, &r1);
604 dns_rdata_toregion(rdata2, &r2);
605 isc_region_consume(&r1, 18);
606 isc_region_consume(&r2, 18);
607 dns_name_fromregion(&name1, &r1);
608 dns_name_fromregion(&name2, &r2);
609 order = dns_name_rdatacompare(&name1, &name2);
610 if (order != 0)
611 return (order);
612
613 isc_region_consume(&r1, name_length(&name1));
614 isc_region_consume(&r2, name_length(&name2));
615
616 return (isc_region_compare(&r1, &r2));
617 }
618
619 #endif /* RDATA_GENERIC_RRSIG_46_C */
620