plugin/rewrite: Add "revert" parameter for EDNS0 options (#6893)

* plugin/rewrite: Add "revert" parameter for EDNS0 options

Signed-off-by: Nikita Usatov <nikitakosatka@yandex.ru>

* Update README

Signed-off-by: Nikita Usatov <nikitakosatka@yandex.ru>

* plugin/rewrite: Update tests

Signed-off-by: Nikita Usatov <nikitakosatka@yandex.ru>

* plugin/rewrite: Revert change to improve coverage

Signed-off-by: Nikita Usatov <nikitakosatka@yandex.ru>

---------

Signed-off-by: Nikita Usatov <nikitakosatka@yandex.ru>
This commit is contained in:
Nikita Usatov
2024-10-07 20:47:56 +03:00
committed by GitHub
parent 5100feebd3
commit 92724349dc
3 changed files with 436 additions and 37 deletions

View File

@@ -70,14 +70,20 @@ func TestNewRule(t *testing.T) {
{[]string{"edns0", "local", "set", "0xffee"}, true, nil},
{[]string{"edns0", "local", "set", "65518", "abcdefg"}, false, reflect.TypeOf(&edns0LocalRule{})},
{[]string{"edns0", "local", "set", "0xffee", "abcdefg"}, false, reflect.TypeOf(&edns0LocalRule{})},
{[]string{"edns0", "local", "set", "0xffee", "abcdefg", "revert"}, false, reflect.TypeOf(&edns0LocalRule{})},
{[]string{"edns0", "local", "append", "0xffee", "abcdefg"}, false, reflect.TypeOf(&edns0LocalRule{})},
{[]string{"edns0", "local", "append", "0xffee", "abcdefg", "revert"}, false, reflect.TypeOf(&edns0LocalRule{})},
{[]string{"edns0", "local", "replace", "0xffee", "abcdefg"}, false, reflect.TypeOf(&edns0LocalRule{})},
{[]string{"edns0", "local", "replace", "0xffee", "abcdefg", "revert"}, false, reflect.TypeOf(&edns0LocalRule{})},
{[]string{"edns0", "local", "foo", "0xffee", "abcdefg"}, true, nil},
{[]string{"edns0", "local", "set", "0xffee", "0xabcdefg"}, true, nil},
{[]string{"edns0", "nsid", "set", "junk"}, true, nil},
{[]string{"edns0", "nsid", "set"}, false, reflect.TypeOf(&edns0NsidRule{})},
{[]string{"edns0", "nsid", "set", "revert"}, false, reflect.TypeOf(&edns0NsidRule{})},
{[]string{"edns0", "nsid", "append"}, false, reflect.TypeOf(&edns0NsidRule{})},
{[]string{"edns0", "nsid", "append", "revert"}, false, reflect.TypeOf(&edns0NsidRule{})},
{[]string{"edns0", "nsid", "replace"}, false, reflect.TypeOf(&edns0NsidRule{})},
{[]string{"edns0", "nsid", "replace", "revert"}, false, reflect.TypeOf(&edns0NsidRule{})},
{[]string{"edns0", "nsid", "foo"}, true, nil},
{[]string{"edns0", "local", "set", "0xffee", "{dummy}"}, true, nil},
{[]string{"edns0", "local", "set", "0xffee", "{qname}"}, false, reflect.TypeOf(&edns0VariableRule{})},
@@ -87,6 +93,7 @@ func TestNewRule(t *testing.T) {
{[]string{"edns0", "local", "set", "0xffee", "{protocol}"}, false, reflect.TypeOf(&edns0VariableRule{})},
{[]string{"edns0", "local", "set", "0xffee", "{server_ip}"}, false, reflect.TypeOf(&edns0VariableRule{})},
{[]string{"edns0", "local", "set", "0xffee", "{server_port}"}, false, reflect.TypeOf(&edns0VariableRule{})},
{[]string{"edns0", "local", "set", "0xffee", "{server_port}", "revert"}, false, reflect.TypeOf(&edns0VariableRule{})},
{[]string{"edns0", "local", "append", "0xffee", "{dummy}"}, true, nil},
{[]string{"edns0", "local", "append", "0xffee", "{qname}"}, false, reflect.TypeOf(&edns0VariableRule{})},
{[]string{"edns0", "local", "append", "0xffee", "{qtype}"}, false, reflect.TypeOf(&edns0VariableRule{})},
@@ -95,6 +102,7 @@ func TestNewRule(t *testing.T) {
{[]string{"edns0", "local", "append", "0xffee", "{protocol}"}, false, reflect.TypeOf(&edns0VariableRule{})},
{[]string{"edns0", "local", "append", "0xffee", "{server_ip}"}, false, reflect.TypeOf(&edns0VariableRule{})},
{[]string{"edns0", "local", "append", "0xffee", "{server_port}"}, false, reflect.TypeOf(&edns0VariableRule{})},
{[]string{"edns0", "local", "append", "0xffee", "{server_port}", "revert"}, false, reflect.TypeOf(&edns0VariableRule{})},
{[]string{"edns0", "local", "replace", "0xffee", "{dummy}"}, true, nil},
{[]string{"edns0", "local", "replace", "0xffee", "{qname}"}, false, reflect.TypeOf(&edns0VariableRule{})},
{[]string{"edns0", "local", "replace", "0xffee", "{qtype}"}, false, reflect.TypeOf(&edns0VariableRule{})},
@@ -103,13 +111,18 @@ func TestNewRule(t *testing.T) {
{[]string{"edns0", "local", "replace", "0xffee", "{protocol}"}, false, reflect.TypeOf(&edns0VariableRule{})},
{[]string{"edns0", "local", "replace", "0xffee", "{server_ip}"}, false, reflect.TypeOf(&edns0VariableRule{})},
{[]string{"edns0", "local", "replace", "0xffee", "{server_port}"}, false, reflect.TypeOf(&edns0VariableRule{})},
{[]string{"edns0", "local", "replace", "0xffee", "{server_port}", "revert"}, false, reflect.TypeOf(&edns0VariableRule{})},
{[]string{"edns0", "subnet", "set", "-1", "56"}, true, nil},
{[]string{"edns0", "subnet", "set", "24", "-56"}, true, nil},
{[]string{"edns0", "subnet", "set", "33", "56"}, true, nil},
{[]string{"edns0", "subnet", "set", "24", "129"}, true, nil},
{[]string{"edns0", "subnet", "set", "24", "56"}, false, reflect.TypeOf(&edns0SubnetRule{})},
{[]string{"edns0", "subnet", "set", "24", "56", "revert"}, false, reflect.TypeOf(&edns0SubnetRule{})},
{[]string{"edns0", "subnet", "append", "24", "56"}, false, reflect.TypeOf(&edns0SubnetRule{})},
{[]string{"edns0", "subnet", "append", "24", "56", "72"}, true, nil},
{[]string{"edns0", "subnet", "append", "24", "56", "revert"}, false, reflect.TypeOf(&edns0SubnetRule{})},
{[]string{"edns0", "subnet", "replace", "24", "56"}, false, reflect.TypeOf(&edns0SubnetRule{})},
{[]string{"edns0", "subnet", "replace", "24", "56", "revert"}, false, reflect.TypeOf(&edns0SubnetRule{})},
{[]string{"unknown-action", "name", "a.com", "b.com"}, true, nil},
{[]string{"stop", "name", "a.com", "b.com"}, false, reflect.TypeOf(&exactNameRule{})},
{[]string{"continue", "name", "a.com", "b.com"}, false, reflect.TypeOf(&exactNameRule{})},
@@ -387,30 +400,207 @@ func TestRewriteEDNS0Local(t *testing.T) {
}
}
func TestEdns0LocalMultiRule(t *testing.T) {
rules := []Rule{}
r, _ := newEdns0Rule("stop", "local", "replace", "0xffee", "abcdef")
rules = append(rules, r)
r, _ = newEdns0Rule("stop", "local", "set", "0xffee", "fedcba")
rules = append(rules, r)
rw := Rewrite{
Next: plugin.HandlerFunc(msgPrinter),
Rules: rules,
RevertPolicy: NoRevertPolicy(),
}
func TestEdns0MultiRule(t *testing.T) {
tests := []struct {
fromOpts []dns.EDNS0
toOpts []dns.EDNS0
rules [][]string
fromOpts []dns.EDNS0
toOpts []dns.EDNS0
revertPolicy RevertPolicy
}{
// Local.
{
[][]string{
{"stop", "local", "replace", "0xffee", "abcdef"},
{"stop", "local", "set", "0xffee", "fedcba"},
},
nil,
[]dns.EDNS0{&dns.EDNS0_LOCAL{Code: 0xffee, Data: []byte("fedcba")}},
NoRevertPolicy(),
},
{
[][]string{
{"stop", "local", "replace", "0xffee", "abcdef"},
{"stop", "local", "set", "0xffee", "fedcba"},
},
[]dns.EDNS0{&dns.EDNS0_LOCAL{Code: 0xffee, Data: []byte("foobar")}},
[]dns.EDNS0{&dns.EDNS0_LOCAL{Code: 0xffee, Data: []byte("abcdef")}},
NoRevertPolicy(),
},
// Local with "revert".
{
[][]string{
{"stop", "local", "replace", "0xffee", "abcdef", "revert"},
{"stop", "local", "set", "0xffee", "fedcba", "revert"},
},
nil,
[]dns.EDNS0{},
NewRevertPolicy(false, false),
},
{
[][]string{
{"stop", "local", "replace", "0xffee", "abcdef", "revert"},
{"stop", "local", "set", "0xffee", "fedcba", "revert"},
},
[]dns.EDNS0{&dns.EDNS0_LOCAL{Code: 0xffee, Data: []byte("foobar")}},
[]dns.EDNS0{&dns.EDNS0_LOCAL{Code: 0xffee, Data: []byte("foobar")}},
NewRevertPolicy(false, false),
},
// Local variable.
{
[][]string{
{"stop", "local", "replace", "0xffee", "{qname}"},
{"stop", "local", "set", "0xffee", "{qtype}"},
},
nil,
[]dns.EDNS0{&dns.EDNS0_LOCAL{Code: 0xffee, Data: []byte{0x00, 0x01}}},
NoRevertPolicy(),
},
{
[][]string{
{"stop", "local", "replace", "0xffee", "{qname}"},
{"stop", "local", "set", "0xffee", "{qtype}"},
},
[]dns.EDNS0{&dns.EDNS0_LOCAL{Code: 0xffee, Data: []byte("foobar")}},
[]dns.EDNS0{&dns.EDNS0_LOCAL{Code: 0xffee, Data: []byte("example.com.")}},
NoRevertPolicy(),
},
// Local variable with "revert".
{
[][]string{
{"stop", "local", "replace", "0xffee", "{qname}", "revert"},
{"stop", "local", "set", "0xffee", "{qtype}", "revert"},
},
nil,
[]dns.EDNS0{},
NewRevertPolicy(false, false),
},
{
[][]string{
{"stop", "local", "replace", "0xffee", "{qname}", "revert"},
{"stop", "local", "set", "0xffee", "{qtype}", "revert"},
},
[]dns.EDNS0{&dns.EDNS0_LOCAL{Code: 0xffee, Data: []byte("foobar")}},
[]dns.EDNS0{&dns.EDNS0_LOCAL{Code: 0xffee, Data: []byte("foobar")}},
NewRevertPolicy(false, false),
},
// Nsid.
{
[][]string{
{"stop", "nsid", "replace"},
{"stop", "nsid", "set"},
},
nil,
[]dns.EDNS0{&dns.EDNS0_NSID{Code: dns.EDNS0NSID, Nsid: ""}},
NoRevertPolicy(),
},
{
[][]string{
{"stop", "nsid", "replace"},
{"stop", "nsid", "set"},
},
[]dns.EDNS0{&dns.EDNS0_LOCAL{Code: 0xffee, Data: []byte("foobar")}},
[]dns.EDNS0{&dns.EDNS0_LOCAL{Code: 0xffee, Data: []byte("foobar")}, &dns.EDNS0_NSID{Code: dns.EDNS0NSID, Nsid: ""}},
NoRevertPolicy(),
},
{
[][]string{
{"stop", "nsid", "replace"},
{"stop", "nsid", "set"},
},
[]dns.EDNS0{&dns.EDNS0_NSID{Code: dns.EDNS0NSID, Nsid: ""}},
[]dns.EDNS0{&dns.EDNS0_NSID{Code: dns.EDNS0NSID, Nsid: ""}},
NoRevertPolicy(),
},
// Nsid with "revert".
{
[][]string{
{"stop", "nsid", "replace", "revert"},
{"stop", "nsid", "set", "revert"},
},
nil,
[]dns.EDNS0{},
NewRevertPolicy(false, false),
},
{
[][]string{
{"stop", "nsid", "replace", "revert"},
{"stop", "nsid", "set", "revert"},
},
[]dns.EDNS0{&dns.EDNS0_LOCAL{Code: 0xffee, Data: []byte("foobar")}},
[]dns.EDNS0{&dns.EDNS0_LOCAL{Code: 0xffee, Data: []byte("foobar")}},
NewRevertPolicy(false, false),
},
{
[][]string{
{"stop", "nsid", "replace", "revert"},
{"stop", "nsid", "set", "revert"},
},
[]dns.EDNS0{&dns.EDNS0_NSID{Code: dns.EDNS0NSID, Nsid: ""}},
[]dns.EDNS0{&dns.EDNS0_NSID{Code: dns.EDNS0NSID, Nsid: ""}},
NewRevertPolicy(false, false),
},
// Subnet.
{
[][]string{
{"stop", "subnet", "replace", "32", "56"},
{"stop", "subnet", "set", "0", "56"},
},
nil,
[]dns.EDNS0{&dns.EDNS0_SUBNET{Code: 0x8,
Family: 0x1,
SourceNetmask: 0x0,
SourceScope: 0x0,
Address: []byte{0x00, 0x00, 0x00, 0x00},
}},
NoRevertPolicy(),
},
{
[][]string{
{"stop", "subnet", "replace", "32", "56"},
{"stop", "subnet", "set", "0", "56"},
},
[]dns.EDNS0{&dns.EDNS0_SUBNET{Code: 0x8,
Family: 0x1,
SourceNetmask: 0x0,
SourceScope: 0x0,
Address: []byte{0x00, 0x00, 0x00, 0x00},
}},
[]dns.EDNS0{&dns.EDNS0_SUBNET{Code: 0x8,
Family: 0x1,
SourceNetmask: 0x20,
SourceScope: 0x0,
Address: []byte{0x0A, 0xF0, 0x00, 0x01},
}},
NoRevertPolicy(),
},
// Subnet with "revert".
{
[][]string{
{"stop", "subnet", "replace", "32", "56", "revert"},
{"stop", "subnet", "set", "0", "56", "revert"},
},
nil,
[]dns.EDNS0{},
NewRevertPolicy(false, false),
},
{
[][]string{
{"stop", "subnet", "replace", "32", "56", "revert"},
{"stop", "subnet", "set", "0", "56", "revert"},
},
[]dns.EDNS0{&dns.EDNS0_SUBNET{Code: 0x8,
Family: 0x1,
SourceNetmask: 0x0,
SourceScope: 0x0,
Address: []byte{0x00, 0x00, 0x00, 0x00},
}},
[]dns.EDNS0{&dns.EDNS0_SUBNET{Code: 0x8,
Family: 0x1,
SourceNetmask: 0x0,
SourceScope: 0x0,
Address: []byte{0x00, 0x00, 0x00, 0x00},
}},
NewRevertPolicy(false, false),
},
}
@@ -428,6 +618,19 @@ func TestEdns0LocalMultiRule(t *testing.T) {
o.Option = append(o.Option, tc.fromOpts...)
}
rec := dnstest.NewRecorder(&test.ResponseWriter{})
rules := make([]Rule, 0, len(tc.rules))
for _, rule := range tc.rules {
r, _ := newEdns0Rule(rule[0], rule[1:]...)
rules = append(rules, r)
}
rw := Rewrite{
Next: plugin.HandlerFunc(msgPrinter),
Rules: rules,
RevertPolicy: tc.revertPolicy,
}
rw.ServeDNS(ctx, rec, m)
resp := rec.Msg
@@ -745,3 +948,101 @@ func TestRewriteEDNS0Subnet(t *testing.T) {
}
}
}
func TestRewriteEDNS0Revert(t *testing.T) {
rw := Rewrite{
Next: plugin.HandlerFunc(msgPrinter),
RevertPolicy: NewRevertPolicy(false, false),
}
tests := []struct {
fromOpts []dns.EDNS0
args []string
toOpts []dns.EDNS0
doBool bool
}{
{
[]dns.EDNS0{},
[]string{"local", "set", "0xffee", "0xabcdef", "revert"},
[]dns.EDNS0{},
false,
},
{
[]dns.EDNS0{},
[]string{"local", "append", "0xffee", "abcdefghijklmnop", "revert"},
[]dns.EDNS0{},
false,
},
{
[]dns.EDNS0{},
[]string{"local", "replace", "0xffee", "abcdefghijklmnop", "revert"},
[]dns.EDNS0{},
true,
},
{
[]dns.EDNS0{},
[]string{"nsid", "set", "revert"},
[]dns.EDNS0{},
false,
},
{
[]dns.EDNS0{},
[]string{"nsid", "append", "revert"},
[]dns.EDNS0{},
true,
},
{
[]dns.EDNS0{},
[]string{"nsid", "replace"},
[]dns.EDNS0{},
true,
},
{
[]dns.EDNS0{&dns.EDNS0_LOCAL{Code: 0xffed, Data: []byte{0xab, 0xcd, 0xef}}},
[]string{"local", "set", "0xffee", "0xabcd", "revert"},
[]dns.EDNS0{&dns.EDNS0_LOCAL{Code: 0xffed, Data: []byte{0xab, 0xcd, 0xef}}},
false,
},
{
[]dns.EDNS0{&dns.EDNS0_LOCAL{Code: 0xffef, Data: []byte{0xab, 0xcd, 0xef}}},
[]string{"local", "replace", "0xffee", "abcdefghijklmnop"},
[]dns.EDNS0{&dns.EDNS0_LOCAL{Code: 0xffef, Data: []byte{0xab, 0xcd, 0xef}}},
true,
},
}
ctx := context.TODO()
for i, tc := range tests {
m := new(dns.Msg)
m.SetQuestion("example.com.", dns.TypeA)
m.Question[0].Qclass = dns.ClassINET
r, err := newEdns0Rule("stop", tc.args...)
if err != nil {
t.Errorf("Error creating test rule: %s", err)
continue
}
rw.Rules = []Rule{r}
rec := dnstest.NewRecorder(&test.ResponseWriter{})
rw.ServeDNS(ctx, rec, m)
resp := rec.Msg
o := resp.IsEdns0()
o.SetDo(tc.doBool)
if tc.fromOpts != nil {
o.Option = append(o.Option, tc.fromOpts...)
}
if o == nil {
t.Errorf("Test %d: EDNS0 options not set", i)
continue
}
if o.Do() != tc.doBool {
t.Errorf("Test %d: Expected %v but got %v", i, tc.doBool, o.Do())
}
if !optsEqual(o.Option, tc.toOpts) {
t.Errorf("Test %d: Expected %v but got %v", i, tc.toOpts, o)
}
}
}