-
Notifications
You must be signed in to change notification settings - Fork 8.3k
Fix various issues when validating DNS response packets #27774
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
nashif
merged 6 commits into
zephyrproject-rtos:master
from
jukkar:dns-validate-response
Aug 27, 2020
Merged
Fix various issues when validating DNS response packets #27774
nashif
merged 6 commits into
zephyrproject-rtos:master
from
jukkar:dns-validate-response
Aug 27, 2020
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
ceolin
reviewed
Aug 25, 2020
ceolin
approved these changes
Aug 25, 2020
This is not possible with valid DNS messages but is possible if we receive malformed DNS packet. Signed-off-by: Jukka Rissanen <[email protected]>
Make sure that IP address information is found in the received message. Signed-off-by: Jukka Rissanen <[email protected]>
As the answer might not be compressed, calculate next answer position correctly. Signed-off-by: Jukka Rissanen <[email protected]>
The ANCOUNT has nothing to do with label count so remove the original while loop and just go through all the labels until we have read all of them. Signed-off-by: Jukka Rissanen <[email protected]>
The DNS message must be long enough for id and flags fields. Signed-off-by: Jukka Rissanen <[email protected]>
Add more tests to verify that we discard malformed packets. In order to simplify the testing, separate message validation to dns_validate_msg() function in resolve.c. Allow that function to be called from unit test. This way we can construct invalid DNS messages in unit test and verify that they are discarded when needed. Signed-off-by: Jukka Rissanen <[email protected]>
440e717 to
a2a4436
Compare
d3zd3z
approved these changes
Aug 26, 2020
tbursztyka
approved these changes
Aug 27, 2020
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There is also a commit that tries to verify that we catch all the fixed issues.