2021-03-25 16:00:27 +03:00
|
|
|
package dnsforward
|
|
|
|
|
|
|
|
import (
|
|
|
|
"net"
|
2022-11-02 16:18:02 +03:00
|
|
|
"net/netip"
|
2021-03-25 16:00:27 +03:00
|
|
|
"testing"
|
|
|
|
|
2022-11-02 16:18:02 +03:00
|
|
|
"github.com/AdguardTeam/AdGuardHome/internal/aghalg"
|
2021-03-31 15:00:47 +03:00
|
|
|
"github.com/AdguardTeam/AdGuardHome/internal/aghtest"
|
2021-05-21 16:15:47 +03:00
|
|
|
"github.com/AdguardTeam/AdGuardHome/internal/filtering"
|
2021-03-25 16:00:27 +03:00
|
|
|
"github.com/AdguardTeam/dnsproxy/proxy"
|
2021-03-31 15:00:47 +03:00
|
|
|
"github.com/AdguardTeam/dnsproxy/upstream"
|
2022-06-02 17:55:48 +03:00
|
|
|
"github.com/AdguardTeam/golibs/netutil"
|
2022-11-02 16:18:02 +03:00
|
|
|
"github.com/AdguardTeam/golibs/testutil"
|
2021-03-25 16:00:27 +03:00
|
|
|
"github.com/miekg/dns"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
|
|
"github.com/stretchr/testify/require"
|
|
|
|
)
|
|
|
|
|
2022-08-17 18:23:30 +03:00
|
|
|
const (
|
|
|
|
ddrTestDomainName = "dns.example.net"
|
|
|
|
ddrTestFQDN = ddrTestDomainName + "."
|
|
|
|
)
|
|
|
|
|
|
|
|
func TestServer_ProcessDDRQuery(t *testing.T) {
|
|
|
|
dohSVCB := &dns.SVCB{
|
|
|
|
Priority: 1,
|
|
|
|
Target: ddrTestFQDN,
|
|
|
|
Value: []dns.SVCBKeyValue{
|
|
|
|
&dns.SVCBAlpn{Alpn: []string{"h2"}},
|
|
|
|
&dns.SVCBPort{Port: 8044},
|
2022-09-29 17:36:01 +03:00
|
|
|
&dns.SVCBDoHPath{Template: "/dns-query{?dns}"},
|
2022-08-17 18:23:30 +03:00
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
dotSVCB := &dns.SVCB{
|
|
|
|
Priority: 1,
|
|
|
|
Target: ddrTestFQDN,
|
|
|
|
Value: []dns.SVCBKeyValue{
|
|
|
|
&dns.SVCBAlpn{Alpn: []string{"dot"}},
|
|
|
|
&dns.SVCBPort{Port: 8043},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
doqSVCB := &dns.SVCB{
|
|
|
|
Priority: 1,
|
|
|
|
Target: ddrTestFQDN,
|
|
|
|
Value: []dns.SVCBKeyValue{
|
|
|
|
&dns.SVCBAlpn{Alpn: []string{"doq"}},
|
|
|
|
&dns.SVCBPort{Port: 8042},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
testCases := []struct {
|
|
|
|
name string
|
|
|
|
host string
|
|
|
|
want []*dns.SVCB
|
|
|
|
wantRes resultCode
|
|
|
|
portDoH int
|
|
|
|
portDoT int
|
|
|
|
portDoQ int
|
|
|
|
qtype uint16
|
|
|
|
ddrEnabled bool
|
|
|
|
}{{
|
|
|
|
name: "pass_host",
|
|
|
|
wantRes: resultCodeSuccess,
|
|
|
|
host: "example.net.",
|
|
|
|
qtype: dns.TypeSVCB,
|
|
|
|
ddrEnabled: true,
|
|
|
|
portDoH: 8043,
|
|
|
|
}, {
|
|
|
|
name: "pass_qtype",
|
|
|
|
wantRes: resultCodeFinish,
|
|
|
|
host: ddrHostFQDN,
|
|
|
|
qtype: dns.TypeA,
|
|
|
|
ddrEnabled: true,
|
|
|
|
portDoH: 8043,
|
|
|
|
}, {
|
|
|
|
name: "pass_disabled_tls",
|
|
|
|
wantRes: resultCodeFinish,
|
|
|
|
host: ddrHostFQDN,
|
|
|
|
qtype: dns.TypeSVCB,
|
|
|
|
ddrEnabled: true,
|
|
|
|
}, {
|
|
|
|
name: "pass_disabled_ddr",
|
|
|
|
wantRes: resultCodeSuccess,
|
|
|
|
host: ddrHostFQDN,
|
|
|
|
qtype: dns.TypeSVCB,
|
|
|
|
ddrEnabled: false,
|
|
|
|
portDoH: 8043,
|
|
|
|
}, {
|
|
|
|
name: "dot",
|
|
|
|
wantRes: resultCodeFinish,
|
|
|
|
want: []*dns.SVCB{dotSVCB},
|
|
|
|
host: ddrHostFQDN,
|
|
|
|
qtype: dns.TypeSVCB,
|
|
|
|
ddrEnabled: true,
|
|
|
|
portDoT: 8043,
|
|
|
|
}, {
|
|
|
|
name: "doh",
|
|
|
|
wantRes: resultCodeFinish,
|
|
|
|
want: []*dns.SVCB{dohSVCB},
|
|
|
|
host: ddrHostFQDN,
|
|
|
|
qtype: dns.TypeSVCB,
|
|
|
|
ddrEnabled: true,
|
|
|
|
portDoH: 8044,
|
|
|
|
}, {
|
|
|
|
name: "doq",
|
|
|
|
wantRes: resultCodeFinish,
|
|
|
|
want: []*dns.SVCB{doqSVCB},
|
|
|
|
host: ddrHostFQDN,
|
|
|
|
qtype: dns.TypeSVCB,
|
|
|
|
ddrEnabled: true,
|
|
|
|
portDoQ: 8042,
|
|
|
|
}, {
|
|
|
|
name: "dot_doh",
|
|
|
|
wantRes: resultCodeFinish,
|
|
|
|
want: []*dns.SVCB{dotSVCB, dohSVCB},
|
|
|
|
host: ddrHostFQDN,
|
|
|
|
qtype: dns.TypeSVCB,
|
|
|
|
ddrEnabled: true,
|
|
|
|
portDoT: 8043,
|
|
|
|
portDoH: 8044,
|
|
|
|
}}
|
|
|
|
|
|
|
|
for _, tc := range testCases {
|
|
|
|
t.Run(tc.name, func(t *testing.T) {
|
|
|
|
s := prepareTestServer(t, tc.portDoH, tc.portDoT, tc.portDoQ, tc.ddrEnabled)
|
|
|
|
|
|
|
|
req := createTestMessageWithType(tc.host, tc.qtype)
|
|
|
|
|
|
|
|
dctx := &dnsContext{
|
|
|
|
proxyCtx: &proxy.DNSContext{
|
|
|
|
Req: req,
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
res := s.processDDRQuery(dctx)
|
|
|
|
require.Equal(t, tc.wantRes, res)
|
|
|
|
|
|
|
|
if tc.wantRes != resultCodeFinish {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
msg := dctx.proxyCtx.Res
|
|
|
|
require.NotNil(t, msg)
|
|
|
|
|
|
|
|
for _, v := range tc.want {
|
|
|
|
v.Hdr = s.hdr(req, dns.TypeSVCB)
|
|
|
|
}
|
|
|
|
|
|
|
|
assert.ElementsMatch(t, tc.want, msg.Answer)
|
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func prepareTestServer(t *testing.T, portDoH, portDoT, portDoQ int, ddrEnabled bool) (s *Server) {
|
|
|
|
t.Helper()
|
|
|
|
|
|
|
|
s = &Server{
|
|
|
|
dnsProxy: &proxy.Proxy{
|
2022-11-02 16:18:02 +03:00
|
|
|
Config: proxy.Config{},
|
2022-08-17 18:23:30 +03:00
|
|
|
},
|
|
|
|
conf: ServerConfig{
|
|
|
|
FilteringConfig: FilteringConfig{
|
|
|
|
HandleDDR: ddrEnabled,
|
|
|
|
},
|
|
|
|
TLSConfig: TLSConfig{
|
|
|
|
ServerName: ddrTestDomainName,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
2022-11-02 16:18:02 +03:00
|
|
|
if portDoT > 0 {
|
|
|
|
s.dnsProxy.TLSListenAddr = []*net.TCPAddr{{Port: portDoT}}
|
|
|
|
s.conf.hasIPAddrs = true
|
|
|
|
}
|
|
|
|
|
|
|
|
if portDoQ > 0 {
|
|
|
|
s.dnsProxy.QUICListenAddr = []*net.UDPAddr{{Port: portDoQ}}
|
|
|
|
}
|
|
|
|
|
2022-08-17 18:23:30 +03:00
|
|
|
if portDoH > 0 {
|
2022-11-02 16:18:02 +03:00
|
|
|
s.conf.HTTPSListenAddrs = []*net.TCPAddr{{Port: portDoH}}
|
2022-08-17 18:23:30 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
return s
|
|
|
|
}
|
|
|
|
|
2021-04-08 18:07:29 +03:00
|
|
|
func TestServer_ProcessDetermineLocal(t *testing.T) {
|
|
|
|
s := &Server{
|
2022-06-02 17:55:48 +03:00
|
|
|
privateNets: netutil.SubnetSetFunc(netutil.IsLocallyServed),
|
2021-04-08 18:07:29 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
testCases := []struct {
|
2022-06-02 17:55:48 +03:00
|
|
|
want assert.BoolAssertionFunc
|
2021-04-08 18:07:29 +03:00
|
|
|
name string
|
|
|
|
cliIP net.IP
|
|
|
|
}{{
|
2022-06-02 17:55:48 +03:00
|
|
|
want: assert.True,
|
2021-04-08 18:07:29 +03:00
|
|
|
name: "local",
|
|
|
|
cliIP: net.IP{192, 168, 0, 1},
|
|
|
|
}, {
|
2022-06-02 17:55:48 +03:00
|
|
|
want: assert.False,
|
2021-04-08 18:07:29 +03:00
|
|
|
name: "external",
|
|
|
|
cliIP: net.IP{250, 249, 0, 1},
|
2022-06-02 17:55:48 +03:00
|
|
|
}, {
|
|
|
|
want: assert.False,
|
|
|
|
name: "invalid",
|
|
|
|
cliIP: net.IP{1, 2, 3, 4, 5},
|
|
|
|
}, {
|
|
|
|
want: assert.False,
|
|
|
|
name: "nil",
|
|
|
|
cliIP: nil,
|
2021-04-08 18:07:29 +03:00
|
|
|
}}
|
|
|
|
|
|
|
|
for _, tc := range testCases {
|
|
|
|
t.Run(tc.name, func(t *testing.T) {
|
|
|
|
proxyCtx := &proxy.DNSContext{
|
|
|
|
Addr: &net.TCPAddr{
|
|
|
|
IP: tc.cliIP,
|
|
|
|
},
|
|
|
|
}
|
|
|
|
dctx := &dnsContext{
|
|
|
|
proxyCtx: proxyCtx,
|
|
|
|
}
|
|
|
|
s.processDetermineLocal(dctx)
|
|
|
|
|
2022-06-02 17:55:48 +03:00
|
|
|
tc.want(t, dctx.isLocalClient)
|
2021-04-08 18:07:29 +03:00
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-06-28 19:09:26 +03:00
|
|
|
func TestServer_ProcessDHCPHosts_localRestriction(t *testing.T) {
|
2022-11-02 16:18:02 +03:00
|
|
|
knownIP := netip.MustParseAddr("1.2.3.4")
|
2021-03-25 16:00:27 +03:00
|
|
|
testCases := []struct {
|
|
|
|
name string
|
|
|
|
host string
|
2022-11-02 16:18:02 +03:00
|
|
|
wantIP netip.Addr
|
2021-03-25 16:00:27 +03:00
|
|
|
wantRes resultCode
|
2021-04-08 18:07:29 +03:00
|
|
|
isLocalCli bool
|
2021-03-25 16:00:27 +03:00
|
|
|
}{{
|
2021-04-08 18:07:29 +03:00
|
|
|
name: "local_client_success",
|
2021-03-25 16:00:27 +03:00
|
|
|
host: "example.lan",
|
|
|
|
wantIP: knownIP,
|
|
|
|
wantRes: resultCodeSuccess,
|
2021-04-08 18:07:29 +03:00
|
|
|
isLocalCli: true,
|
2021-03-25 16:00:27 +03:00
|
|
|
}, {
|
2021-04-08 18:07:29 +03:00
|
|
|
name: "local_client_unknown_host",
|
|
|
|
host: "wronghost.lan",
|
2022-11-02 16:18:02 +03:00
|
|
|
wantIP: netip.Addr{},
|
2022-09-07 18:03:18 +03:00
|
|
|
wantRes: resultCodeSuccess,
|
2021-04-08 18:07:29 +03:00
|
|
|
isLocalCli: true,
|
2021-03-25 17:21:00 +03:00
|
|
|
}, {
|
2021-04-08 18:07:29 +03:00
|
|
|
name: "external_client_known_host",
|
2021-03-25 17:21:00 +03:00
|
|
|
host: "example.lan",
|
2022-11-02 16:18:02 +03:00
|
|
|
wantIP: netip.Addr{},
|
2021-04-08 18:07:29 +03:00
|
|
|
wantRes: resultCodeFinish,
|
|
|
|
isLocalCli: false,
|
|
|
|
}, {
|
|
|
|
name: "external_client_unknown_host",
|
|
|
|
host: "wronghost.lan",
|
2022-11-02 16:18:02 +03:00
|
|
|
wantIP: netip.Addr{},
|
2021-04-08 18:07:29 +03:00
|
|
|
wantRes: resultCodeFinish,
|
|
|
|
isLocalCli: false,
|
|
|
|
}}
|
|
|
|
|
|
|
|
for _, tc := range testCases {
|
|
|
|
t.Run(tc.name, func(t *testing.T) {
|
|
|
|
s := &Server{
|
2022-09-14 16:36:29 +03:00
|
|
|
dhcpServer: testDHCP,
|
2021-04-15 19:00:31 +03:00
|
|
|
localDomainSuffix: defaultLocalDomainSuffix,
|
2021-04-15 17:52:53 +03:00
|
|
|
tableHostToIP: hostToIPTable{
|
2022-06-28 19:09:26 +03:00
|
|
|
"example." + defaultLocalDomainSuffix: knownIP,
|
2021-04-08 18:07:29 +03:00
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
req := &dns.Msg{
|
|
|
|
MsgHdr: dns.MsgHdr{
|
|
|
|
Id: dns.Id(),
|
|
|
|
},
|
|
|
|
Question: []dns.Question{{
|
|
|
|
Name: dns.Fqdn(tc.host),
|
|
|
|
Qtype: dns.TypeA,
|
|
|
|
Qclass: dns.ClassINET,
|
|
|
|
}},
|
|
|
|
}
|
|
|
|
|
|
|
|
dctx := &dnsContext{
|
|
|
|
proxyCtx: &proxy.DNSContext{
|
|
|
|
Req: req,
|
|
|
|
},
|
|
|
|
isLocalClient: tc.isLocalCli,
|
|
|
|
}
|
|
|
|
|
2022-06-28 19:09:26 +03:00
|
|
|
res := s.processDHCPHosts(dctx)
|
2021-04-08 18:07:29 +03:00
|
|
|
require.Equal(t, tc.wantRes, res)
|
|
|
|
pctx := dctx.proxyCtx
|
|
|
|
if tc.wantRes == resultCodeFinish {
|
|
|
|
require.NotNil(t, pctx.Res)
|
|
|
|
|
|
|
|
assert.Equal(t, dns.RcodeNameError, pctx.Res.Rcode)
|
|
|
|
assert.Len(t, pctx.Res.Answer, 0)
|
|
|
|
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2022-11-02 16:18:02 +03:00
|
|
|
if tc.wantIP == (netip.Addr{}) {
|
2021-04-08 18:07:29 +03:00
|
|
|
assert.Nil(t, pctx.Res)
|
|
|
|
} else {
|
|
|
|
require.NotNil(t, pctx.Res)
|
|
|
|
|
|
|
|
ans := pctx.Res.Answer
|
|
|
|
require.Len(t, ans, 1)
|
|
|
|
|
2022-11-02 16:18:02 +03:00
|
|
|
a := testutil.RequireTypeAssert[*dns.A](t, ans[0])
|
|
|
|
|
|
|
|
ip, err := netutil.IPToAddr(a.A, netutil.AddrFamilyIPv4)
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
assert.Equal(t, tc.wantIP, ip)
|
2021-04-08 18:07:29 +03:00
|
|
|
}
|
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-06-28 19:09:26 +03:00
|
|
|
func TestServer_ProcessDHCPHosts(t *testing.T) {
|
2021-04-08 18:07:29 +03:00
|
|
|
const (
|
|
|
|
examplecom = "example.com"
|
2022-06-28 19:09:26 +03:00
|
|
|
examplelan = "example." + defaultLocalDomainSuffix
|
2021-04-08 18:07:29 +03:00
|
|
|
)
|
|
|
|
|
2022-11-02 16:18:02 +03:00
|
|
|
knownIP := netip.MustParseAddr("1.2.3.4")
|
2021-04-08 18:07:29 +03:00
|
|
|
testCases := []struct {
|
|
|
|
name string
|
|
|
|
host string
|
|
|
|
suffix string
|
2022-11-02 16:18:02 +03:00
|
|
|
wantIP netip.Addr
|
2021-04-08 18:07:29 +03:00
|
|
|
wantRes resultCode
|
|
|
|
qtyp uint16
|
|
|
|
}{{
|
|
|
|
name: "success_external",
|
|
|
|
host: examplecom,
|
2021-04-15 19:00:31 +03:00
|
|
|
suffix: defaultLocalDomainSuffix,
|
2022-11-02 16:18:02 +03:00
|
|
|
wantIP: netip.Addr{},
|
2021-04-08 18:07:29 +03:00
|
|
|
wantRes: resultCodeSuccess,
|
|
|
|
qtyp: dns.TypeA,
|
|
|
|
}, {
|
|
|
|
name: "success_external_non_a",
|
|
|
|
host: examplecom,
|
2021-04-15 19:00:31 +03:00
|
|
|
suffix: defaultLocalDomainSuffix,
|
2022-11-02 16:18:02 +03:00
|
|
|
wantIP: netip.Addr{},
|
2021-04-08 18:07:29 +03:00
|
|
|
wantRes: resultCodeSuccess,
|
|
|
|
qtyp: dns.TypeCNAME,
|
|
|
|
}, {
|
|
|
|
name: "success_internal",
|
|
|
|
host: examplelan,
|
2021-04-15 19:00:31 +03:00
|
|
|
suffix: defaultLocalDomainSuffix,
|
2021-04-08 18:07:29 +03:00
|
|
|
wantIP: knownIP,
|
|
|
|
wantRes: resultCodeSuccess,
|
|
|
|
qtyp: dns.TypeA,
|
|
|
|
}, {
|
|
|
|
name: "success_internal_unknown",
|
|
|
|
host: "example-new.lan",
|
2021-04-15 19:00:31 +03:00
|
|
|
suffix: defaultLocalDomainSuffix,
|
2022-11-02 16:18:02 +03:00
|
|
|
wantIP: netip.Addr{},
|
2022-09-07 18:03:18 +03:00
|
|
|
wantRes: resultCodeSuccess,
|
2021-04-08 18:07:29 +03:00
|
|
|
qtyp: dns.TypeA,
|
|
|
|
}, {
|
|
|
|
name: "success_internal_aaaa",
|
|
|
|
host: examplelan,
|
2021-04-15 19:00:31 +03:00
|
|
|
suffix: defaultLocalDomainSuffix,
|
2022-11-02 16:18:02 +03:00
|
|
|
wantIP: netip.Addr{},
|
2021-04-08 18:07:29 +03:00
|
|
|
wantRes: resultCodeSuccess,
|
|
|
|
qtyp: dns.TypeAAAA,
|
|
|
|
}, {
|
|
|
|
name: "success_custom_suffix",
|
|
|
|
host: "example.custom",
|
2022-06-28 19:09:26 +03:00
|
|
|
suffix: "custom",
|
2021-04-08 18:07:29 +03:00
|
|
|
wantIP: knownIP,
|
|
|
|
wantRes: resultCodeSuccess,
|
|
|
|
qtyp: dns.TypeA,
|
2021-03-25 16:00:27 +03:00
|
|
|
}}
|
|
|
|
|
|
|
|
for _, tc := range testCases {
|
2022-06-28 19:09:26 +03:00
|
|
|
s := &Server{
|
2022-09-14 16:36:29 +03:00
|
|
|
dhcpServer: testDHCP,
|
2022-06-28 19:09:26 +03:00
|
|
|
localDomainSuffix: tc.suffix,
|
|
|
|
tableHostToIP: hostToIPTable{
|
|
|
|
"example." + tc.suffix: knownIP,
|
|
|
|
},
|
|
|
|
}
|
2021-03-25 16:00:27 +03:00
|
|
|
|
2022-06-28 19:09:26 +03:00
|
|
|
req := &dns.Msg{
|
|
|
|
MsgHdr: dns.MsgHdr{
|
|
|
|
Id: 1234,
|
|
|
|
},
|
|
|
|
Question: []dns.Question{{
|
|
|
|
Name: dns.Fqdn(tc.host),
|
|
|
|
Qtype: tc.qtyp,
|
|
|
|
Qclass: dns.ClassINET,
|
|
|
|
}},
|
|
|
|
}
|
2021-03-25 16:00:27 +03:00
|
|
|
|
2022-06-28 19:09:26 +03:00
|
|
|
dctx := &dnsContext{
|
|
|
|
proxyCtx: &proxy.DNSContext{
|
|
|
|
Req: req,
|
|
|
|
},
|
|
|
|
isLocalClient: true,
|
|
|
|
}
|
2021-03-25 16:00:27 +03:00
|
|
|
|
2022-06-28 19:09:26 +03:00
|
|
|
t.Run(tc.name, func(t *testing.T) {
|
|
|
|
res := s.processDHCPHosts(dctx)
|
2021-04-08 18:07:29 +03:00
|
|
|
pctx := dctx.proxyCtx
|
2021-03-25 16:00:27 +03:00
|
|
|
assert.Equal(t, tc.wantRes, res)
|
2021-04-08 18:07:29 +03:00
|
|
|
if tc.wantRes == resultCodeFinish {
|
|
|
|
require.NotNil(t, pctx.Res)
|
|
|
|
assert.Equal(t, dns.RcodeNameError, pctx.Res.Rcode)
|
2021-03-25 16:00:27 +03:00
|
|
|
|
2021-04-08 18:07:29 +03:00
|
|
|
return
|
2021-03-25 16:00:27 +03:00
|
|
|
}
|
|
|
|
|
2021-04-08 18:07:29 +03:00
|
|
|
require.NoError(t, dctx.err)
|
|
|
|
|
2021-03-25 17:21:00 +03:00
|
|
|
if tc.qtyp == dns.TypeAAAA {
|
|
|
|
// TODO(a.garipov): Remove this special handling
|
|
|
|
// when we fully support AAAA.
|
|
|
|
require.NotNil(t, pctx.Res)
|
|
|
|
|
|
|
|
ans := pctx.Res.Answer
|
|
|
|
require.Len(t, ans, 0)
|
2022-11-02 16:18:02 +03:00
|
|
|
} else if tc.wantIP == (netip.Addr{}) {
|
2021-03-25 16:00:27 +03:00
|
|
|
assert.Nil(t, pctx.Res)
|
|
|
|
} else {
|
|
|
|
require.NotNil(t, pctx.Res)
|
|
|
|
|
|
|
|
ans := pctx.Res.Answer
|
|
|
|
require.Len(t, ans, 1)
|
|
|
|
|
2022-11-02 16:18:02 +03:00
|
|
|
a := testutil.RequireTypeAssert[*dns.A](t, ans[0])
|
|
|
|
|
|
|
|
ip, err := netutil.IPToAddr(a.A, netutil.AddrFamilyIPv4)
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
assert.Equal(t, tc.wantIP, ip)
|
2021-03-25 16:00:27 +03:00
|
|
|
}
|
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|
2021-03-31 15:00:47 +03:00
|
|
|
|
2021-05-26 17:55:19 +03:00
|
|
|
func TestServer_ProcessRestrictLocal(t *testing.T) {
|
2022-11-02 16:18:02 +03:00
|
|
|
const (
|
|
|
|
extPTRQuestion = "251.252.253.254.in-addr.arpa."
|
|
|
|
extPTRAnswer = "host1.example.net."
|
|
|
|
intPTRQuestion = "1.1.168.192.in-addr.arpa."
|
|
|
|
intPTRAnswer = "some.local-client."
|
|
|
|
)
|
|
|
|
|
|
|
|
ups := aghtest.NewUpstreamMock(func(req *dns.Msg) (resp *dns.Msg, err error) {
|
|
|
|
return aghalg.Coalesce(
|
|
|
|
aghtest.MatchedResponse(req, dns.TypePTR, extPTRQuestion, extPTRAnswer),
|
|
|
|
aghtest.MatchedResponse(req, dns.TypePTR, intPTRQuestion, intPTRAnswer),
|
|
|
|
new(dns.Msg).SetRcode(req, dns.RcodeNameError),
|
|
|
|
), nil
|
|
|
|
})
|
|
|
|
|
2021-05-21 16:15:47 +03:00
|
|
|
s := createTestServer(t, &filtering.Config{}, ServerConfig{
|
2021-04-09 21:01:21 +03:00
|
|
|
UDPListenAddrs: []*net.UDPAddr{{}},
|
|
|
|
TCPListenAddrs: []*net.TCPAddr{{}},
|
2023-03-09 15:39:35 +03:00
|
|
|
// TODO(s.chzhen): Add tests where EDNSClientSubnet.Enabled is true.
|
|
|
|
// Improve FilteringConfig declaration for tests.
|
|
|
|
FilteringConfig: FilteringConfig{
|
|
|
|
EDNSClientSubnet: &EDNSClientSubnet{Enabled: false},
|
|
|
|
},
|
2021-04-09 21:01:21 +03:00
|
|
|
}, ups)
|
2021-03-31 15:00:47 +03:00
|
|
|
s.conf.UpstreamConfig.Upstreams = []upstream.Upstream{ups}
|
|
|
|
startDeferStop(t, s)
|
|
|
|
|
|
|
|
testCases := []struct {
|
|
|
|
name string
|
|
|
|
want string
|
|
|
|
question net.IP
|
|
|
|
cliIP net.IP
|
|
|
|
wantLen int
|
|
|
|
}{{
|
|
|
|
name: "from_local_to_external",
|
|
|
|
want: "host1.example.net.",
|
|
|
|
question: net.IP{254, 253, 252, 251},
|
|
|
|
cliIP: net.IP{192, 168, 10, 10},
|
|
|
|
wantLen: 1,
|
|
|
|
}, {
|
|
|
|
name: "from_external_for_local",
|
|
|
|
want: "",
|
|
|
|
question: net.IP{192, 168, 1, 1},
|
|
|
|
cliIP: net.IP{254, 253, 252, 251},
|
|
|
|
wantLen: 0,
|
|
|
|
}, {
|
|
|
|
name: "from_local_for_local",
|
|
|
|
want: "some.local-client.",
|
|
|
|
question: net.IP{192, 168, 1, 1},
|
|
|
|
cliIP: net.IP{192, 168, 1, 2},
|
|
|
|
wantLen: 1,
|
|
|
|
}, {
|
|
|
|
name: "from_external_for_external",
|
|
|
|
want: "host1.example.net.",
|
|
|
|
question: net.IP{254, 253, 252, 251},
|
|
|
|
cliIP: net.IP{254, 253, 252, 255},
|
|
|
|
wantLen: 1,
|
|
|
|
}}
|
|
|
|
|
|
|
|
for _, tc := range testCases {
|
|
|
|
reqAddr, err := dns.ReverseAddr(tc.question.String())
|
|
|
|
require.NoError(t, err)
|
|
|
|
req := createTestMessageWithType(reqAddr, dns.TypePTR)
|
|
|
|
|
|
|
|
pctx := &proxy.DNSContext{
|
|
|
|
Proto: proxy.ProtoTCP,
|
|
|
|
Req: req,
|
|
|
|
Addr: &net.TCPAddr{
|
|
|
|
IP: tc.cliIP,
|
|
|
|
},
|
|
|
|
}
|
2021-05-26 17:55:19 +03:00
|
|
|
|
2021-03-31 15:00:47 +03:00
|
|
|
t.Run(tc.name, func(t *testing.T) {
|
|
|
|
err = s.handleDNSRequest(nil, pctx)
|
2021-04-29 16:00:07 +03:00
|
|
|
require.NoError(t, err)
|
2021-03-31 15:00:47 +03:00
|
|
|
require.NotNil(t, pctx.Res)
|
|
|
|
require.Len(t, pctx.Res.Answer, tc.wantLen)
|
2021-05-26 17:55:19 +03:00
|
|
|
|
2021-03-31 15:00:47 +03:00
|
|
|
if tc.wantLen > 0 {
|
2021-05-31 20:11:06 +03:00
|
|
|
assert.Equal(t, tc.want, pctx.Res.Answer[0].(*dns.PTR).Ptr)
|
2021-03-31 15:00:47 +03:00
|
|
|
}
|
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|
2021-05-26 17:55:19 +03:00
|
|
|
|
|
|
|
func TestServer_ProcessLocalPTR_usingResolvers(t *testing.T) {
|
|
|
|
const locDomain = "some.local."
|
|
|
|
const reqAddr = "1.1.168.192.in-addr.arpa."
|
|
|
|
|
2022-11-02 16:18:02 +03:00
|
|
|
s := createTestServer(
|
|
|
|
t,
|
|
|
|
&filtering.Config{},
|
|
|
|
ServerConfig{
|
|
|
|
UDPListenAddrs: []*net.UDPAddr{{}},
|
|
|
|
TCPListenAddrs: []*net.TCPAddr{{}},
|
2023-03-09 15:39:35 +03:00
|
|
|
FilteringConfig: FilteringConfig{
|
|
|
|
EDNSClientSubnet: &EDNSClientSubnet{Enabled: false},
|
|
|
|
},
|
2021-05-26 17:55:19 +03:00
|
|
|
},
|
2022-11-02 16:18:02 +03:00
|
|
|
aghtest.NewUpstreamMock(func(req *dns.Msg) (resp *dns.Msg, err error) {
|
|
|
|
return aghalg.Coalesce(
|
|
|
|
aghtest.MatchedResponse(req, dns.TypePTR, reqAddr, locDomain),
|
|
|
|
new(dns.Msg).SetRcode(req, dns.RcodeNameError),
|
|
|
|
), nil
|
|
|
|
}),
|
|
|
|
)
|
2021-05-26 17:55:19 +03:00
|
|
|
|
|
|
|
var proxyCtx *proxy.DNSContext
|
|
|
|
var dnsCtx *dnsContext
|
|
|
|
setup := func(use bool) {
|
|
|
|
proxyCtx = &proxy.DNSContext{
|
|
|
|
Addr: &net.TCPAddr{
|
|
|
|
IP: net.IP{127, 0, 0, 1},
|
|
|
|
},
|
|
|
|
Req: createTestMessageWithType(reqAddr, dns.TypePTR),
|
|
|
|
}
|
|
|
|
dnsCtx = &dnsContext{
|
|
|
|
proxyCtx: proxyCtx,
|
|
|
|
unreversedReqIP: net.IP{192, 168, 1, 1},
|
|
|
|
}
|
|
|
|
s.conf.UsePrivateRDNS = use
|
|
|
|
}
|
|
|
|
|
|
|
|
t.Run("enabled", func(t *testing.T) {
|
|
|
|
setup(true)
|
|
|
|
|
|
|
|
rc := s.processLocalPTR(dnsCtx)
|
|
|
|
require.Equal(t, resultCodeSuccess, rc)
|
|
|
|
require.NotEmpty(t, proxyCtx.Res.Answer)
|
|
|
|
|
2021-05-31 20:11:06 +03:00
|
|
|
assert.Equal(t, locDomain, proxyCtx.Res.Answer[0].(*dns.PTR).Ptr)
|
2021-05-26 17:55:19 +03:00
|
|
|
})
|
|
|
|
|
|
|
|
t.Run("disabled", func(t *testing.T) {
|
|
|
|
setup(false)
|
|
|
|
|
|
|
|
rc := s.processLocalPTR(dnsCtx)
|
|
|
|
require.Equal(t, resultCodeFinish, rc)
|
|
|
|
require.Empty(t, proxyCtx.Res.Answer)
|
|
|
|
})
|
|
|
|
}
|
2021-05-28 13:02:59 +03:00
|
|
|
|
|
|
|
func TestIPStringFromAddr(t *testing.T) {
|
|
|
|
t.Run("not_nil", func(t *testing.T) {
|
|
|
|
addr := net.UDPAddr{
|
|
|
|
IP: net.ParseIP("1:2:3::4"),
|
|
|
|
Port: 12345,
|
|
|
|
Zone: "eth0",
|
|
|
|
}
|
|
|
|
assert.Equal(t, ipStringFromAddr(&addr), addr.IP.String())
|
|
|
|
})
|
|
|
|
|
|
|
|
t.Run("nil", func(t *testing.T) {
|
|
|
|
assert.Empty(t, ipStringFromAddr(nil))
|
|
|
|
})
|
|
|
|
}
|
2023-04-12 14:48:42 +03:00
|
|
|
|
|
|
|
// TODO(e.burkov): Add fuzzing when moving to golibs.
|
|
|
|
func TestExtractARPASubnet(t *testing.T) {
|
|
|
|
const (
|
|
|
|
v4Suf = `in-addr.arpa.`
|
|
|
|
v4Part = `2.1.` + v4Suf
|
|
|
|
v4Whole = `4.3.` + v4Part
|
|
|
|
|
|
|
|
v6Suf = `ip6.arpa.`
|
|
|
|
v6Part = `4.3.2.1.0.0.0.0.0.0.0.0.0.0.0.0.` + v6Suf
|
|
|
|
v6Whole = `f.e.d.c.0.0.0.0.0.0.0.0.0.0.0.0.` + v6Part
|
|
|
|
)
|
|
|
|
|
|
|
|
v4Pref := netip.MustParsePrefix("1.2.3.4/32")
|
|
|
|
v4PrefPart := netip.MustParsePrefix("1.2.0.0/16")
|
|
|
|
v6Pref := netip.MustParsePrefix("::1234:0:0:0:cdef/128")
|
|
|
|
v6PrefPart := netip.MustParsePrefix("0:0:0:1234::/64")
|
|
|
|
|
|
|
|
testCases := []struct {
|
|
|
|
want netip.Prefix
|
|
|
|
name string
|
|
|
|
domain string
|
|
|
|
wantErr string
|
|
|
|
}{{
|
|
|
|
want: netip.Prefix{},
|
|
|
|
name: "not_an_arpa",
|
|
|
|
domain: "some.domain.name.",
|
|
|
|
wantErr: `bad arpa domain name "some.domain.name.": ` +
|
|
|
|
`not a reversed ip network`,
|
|
|
|
}, {
|
|
|
|
want: netip.Prefix{},
|
|
|
|
name: "bad_domain_name",
|
|
|
|
domain: "abc.123.",
|
|
|
|
wantErr: `bad domain name "abc.123": ` +
|
|
|
|
`bad top-level domain name label "123": all octets are numeric`,
|
|
|
|
}, {
|
|
|
|
want: v4Pref,
|
|
|
|
name: "whole_v4",
|
|
|
|
domain: v4Whole,
|
|
|
|
wantErr: "",
|
|
|
|
}, {
|
|
|
|
want: v4PrefPart,
|
|
|
|
name: "partial_v4",
|
|
|
|
domain: v4Part,
|
|
|
|
wantErr: "",
|
|
|
|
}, {
|
|
|
|
want: v4Pref,
|
|
|
|
name: "whole_v4_within_domain",
|
|
|
|
domain: "a." + v4Whole,
|
|
|
|
wantErr: "",
|
|
|
|
}, {
|
|
|
|
want: v4Pref,
|
|
|
|
name: "whole_v4_additional_label",
|
|
|
|
domain: "5." + v4Whole,
|
|
|
|
wantErr: "",
|
|
|
|
}, {
|
|
|
|
want: v4PrefPart,
|
|
|
|
name: "partial_v4_within_domain",
|
|
|
|
domain: "a." + v4Part,
|
|
|
|
wantErr: "",
|
|
|
|
}, {
|
|
|
|
want: v4PrefPart,
|
|
|
|
name: "overflow_v4",
|
|
|
|
domain: "256." + v4Part,
|
|
|
|
wantErr: "",
|
|
|
|
}, {
|
|
|
|
want: v4PrefPart,
|
|
|
|
name: "overflow_v4_within_domain",
|
|
|
|
domain: "a.256." + v4Part,
|
|
|
|
wantErr: "",
|
|
|
|
}, {
|
|
|
|
want: netip.Prefix{},
|
|
|
|
name: "empty_v4",
|
|
|
|
domain: v4Suf,
|
|
|
|
wantErr: `bad arpa domain name "in-addr.arpa": ` +
|
|
|
|
`not a reversed ip network`,
|
|
|
|
}, {
|
|
|
|
want: netip.Prefix{},
|
|
|
|
name: "empty_v4_within_domain",
|
|
|
|
domain: "a." + v4Suf,
|
|
|
|
wantErr: `bad arpa domain name "in-addr.arpa": ` +
|
|
|
|
`not a reversed ip network`,
|
|
|
|
}, {
|
|
|
|
want: v6Pref,
|
|
|
|
name: "whole_v6",
|
|
|
|
domain: v6Whole,
|
|
|
|
wantErr: "",
|
|
|
|
}, {
|
|
|
|
want: v6PrefPart,
|
|
|
|
name: "partial_v6",
|
|
|
|
domain: v6Part,
|
|
|
|
}, {
|
|
|
|
want: v6Pref,
|
|
|
|
name: "whole_v6_within_domain",
|
|
|
|
domain: "g." + v6Whole,
|
|
|
|
wantErr: "",
|
|
|
|
}, {
|
|
|
|
want: v6Pref,
|
|
|
|
name: "whole_v6_additional_label",
|
|
|
|
domain: "1." + v6Whole,
|
|
|
|
wantErr: "",
|
|
|
|
}, {
|
|
|
|
want: v6PrefPart,
|
|
|
|
name: "partial_v6_within_domain",
|
|
|
|
domain: "label." + v6Part,
|
|
|
|
wantErr: "",
|
|
|
|
}, {
|
|
|
|
want: netip.Prefix{},
|
|
|
|
name: "empty_v6",
|
|
|
|
domain: v6Suf,
|
|
|
|
wantErr: `bad arpa domain name "ip6.arpa": not a reversed ip network`,
|
|
|
|
}, {
|
|
|
|
want: netip.Prefix{},
|
|
|
|
name: "empty_v6_within_domain",
|
|
|
|
domain: "g." + v6Suf,
|
|
|
|
wantErr: `bad arpa domain name "ip6.arpa": not a reversed ip network`,
|
|
|
|
}}
|
|
|
|
|
|
|
|
for _, tc := range testCases {
|
|
|
|
t.Run(tc.name, func(t *testing.T) {
|
|
|
|
subnet, err := extractARPASubnet(tc.domain)
|
|
|
|
testutil.AssertErrorMsg(t, tc.wantErr, err)
|
|
|
|
assert.Equal(t, tc.want, subnet)
|
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|