From: JINMEI Tatuya Date: Mon, 26 Mar 2012 17:39:14 +0000 (-0700) Subject: [1836] also added unittest that would fail the fixed in this branch. X-Git-Tag: trac2351_base~226^2~116^2~68^2~11^2 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=4e80da3959ae51851ce68294bd59fed429977f4d;p=thirdparty%2Fkea.git [1836] also added unittest that would fail the fixed in this branch. To make this test workable, I needed to change the returned flag for the NXRRSET case in MockZoneFinder::find() from setting NSEC_SIGNED unconditionally to setting any SIGNED flags. this doesn't affect other tests. --- diff --git a/src/bin/auth/tests/query_unittest.cc b/src/bin/auth/tests/query_unittest.cc index fea9cd0c55..63429aeb49 100644 --- a/src/bin/auth/tests/query_unittest.cc +++ b/src/bin/auth/tests/query_unittest.cc @@ -239,6 +239,10 @@ const char* const unsigned_delegation_optout_nsec_txt = const char* const bad_delegation_txt = "bad-delegation.example.com. 3600 IN NS ns.example.net.\n"; +// Delegation from an unsigned parent. There's no DS, and there's no NSEC +// or NSEC3 that proves it. +const char* const nosec_delegation_txt = + "nosec-delegation.example.com. 3600 IN NS ns.nosec.example.net.\n"; // A helper function that generates a textual representation of RRSIG RDATA // for the given covered type. The resulting RRSIG may not necessarily make @@ -314,7 +318,7 @@ public: unsigned_delegation_txt << unsigned_delegation_nsec_txt << unsigned_delegation_optout_txt << unsigned_delegation_optout_nsec_txt << - bad_delegation_txt; + bad_delegation_txt << nosec_delegation_txt; masterLoad(zone_stream, origin_, rrclass_, boost::bind(&MockZoneFinder::loadRRset, this, _1)); @@ -715,8 +719,9 @@ MockZoneFinder::find(const Name& name, const RRType& type, RESULT_NSEC_SIGNED)); } } - return (createContext(options, NXRRSET, RRsetPtr(), - RESULT_NSEC_SIGNED)); + // If no NSEC is found or DNSSEC isn't specified, behave as if the + // zone is unsigned. + return (createContext(options, NXRRSET, RRsetPtr())); } // query name isn't found in our domains. @@ -1097,6 +1102,17 @@ TEST_F(QueryTest, delegation) { NULL, delegation_txt, ns_addrs_txt); } +TEST_F(QueryTest, delegationWithDNSSEC) { + // Similar to the previous one, but with requesting DNSSEC. + // In this case the parent zone would behave as unsigned, so the result + // should be just like non DNSSEC delegation. + query.process(memory_client, Name("www.nosec-delegation.example.com"), + qtype, response, true); + + responseCheck(response, Rcode::NOERROR(), 0, 0, 1, 0, + NULL, nosec_delegation_txt, NULL); +} + TEST_F(QueryTest, secureDelegation) { EXPECT_NO_THROW(query.process(memory_client, Name("foo.signed-delegation.example.com"),