]> git.ipfire.org Git - thirdparty/pdns.git/commitdiff
dnsdist: Fix the handling of DoH queries with a non-zero ID 10208/head
authorRemi Gacogne <remi.gacogne@powerdns.com>
Tue, 23 Mar 2021 14:22:09 +0000 (15:22 +0100)
committerRemi Gacogne <remi.gacogne@powerdns.com>
Tue, 23 Mar 2021 14:22:09 +0000 (15:22 +0100)
rfc8484 states that clients "SHOULD use a DNS ID of 0 in every DNS
request", not MUST, so it does indeed happen.
The issue was introduced in 341d2553b74c579df9d9843959f3ca6f5c3dc954
when we moved to a safer PacketBuffer.

pdns/dnsdistdist/doh.cc
regression-tests.dnsdist/test_DOH.py

index 3d6d8cfc984d79f9cbf19fe2318b818e87409c6c..682f62694058b8f578bd23297a6923a4e335b7e2 100644 (file)
@@ -535,7 +535,7 @@ static int processDOHQuery(DOHUnit* du)
     ids->du = du;
 
     ids->cs = &cs;
-    ids->origID = queryId;
+    ids->origID = htons(queryId);
     setIDStateFromDNSQuestion(*ids, dq, std::move(qname));
 
     dq.getHeader()->id = idOffset;
index b19d159f622006f8edc5cdb88962b7e2bcbd09f6..861c3983ca617e900089c371c0ddc0f42d0c3964 100644 (file)
@@ -216,6 +216,33 @@ class TestDOH(DNSDistDOHTest):
         self.assertEquals(response, receivedResponse)
         self.checkHasHeader('cache-control', 'max-age=3600')
 
+    def testDOHTransactionID(self):
+        """
+        DOH: Simple query with ID != 0
+        """
+        name = 'simple-with-non-zero-id.doh.tests.powerdns.com.'
+        query = dns.message.make_query(name, 'A', 'IN', use_edns=False)
+        query.id = 42
+        expectedQuery = dns.message.make_query(name, 'A', 'IN', use_edns=True, payload=4096)
+        expectedQuery.id = 0
+        response = dns.message.make_response(query)
+        rrset = dns.rrset.from_text(name,
+                                    3600,
+                                    dns.rdataclass.IN,
+                                    dns.rdatatype.A,
+                                    '127.0.0.1')
+        response.answer.append(rrset)
+
+        (receivedQuery, receivedResponse) = self.sendDOHQuery(self._dohServerPort, self._serverName, self._dohBaseURL, query, response=response, caFile=self._caCert)
+        self.assertTrue(receivedQuery)
+        self.assertTrue(receivedResponse)
+        receivedQuery.id = expectedQuery.id
+        self.assertEquals(expectedQuery, receivedQuery)
+        self.checkQueryEDNSWithoutECS(expectedQuery, receivedQuery)
+        self.assertEquals(response, receivedResponse)
+        # just to be sure the ID _is_ checked
+        self.assertEquals(response.id, receivedResponse.id)
+
     def testDOHSimplePOST(self):
         """
         DOH: Simple POST query