mirror of
https://github.com/apache/nuttx.git
synced 2026-09-26 01:46:57 +08:00
libs/libc/netdb: Size an answer header by its header, not by its union.
dns_recv_response() checked for room using sizeof(struct dns_answer_s), but that structure is the 10-byte header plus a union holding the largest address it can carry. With IPv6 built the union is 16 bytes, so the check demanded 26 bytes where 10 were needed, and any answer sitting at the end of a response was rejected as truncated. An A record answer supplies 14 bytes, so whether a lookup worked depended on how much padding the server happened to send after it: $ dig +noedns @10.1.1.2 github.com A # ANSWER 1, AUTHORITY 0, ADDITIONAL 0 -> answer is last in the packet, 14 bytes remain, rejected $ dig +noedns @10.11.5.254 github.com A # ANSWER 1, AUTHORITY 13, ADDITIONAL 7 -> 26+ bytes remain, accepted On the board, before and after, against the first of those servers: nsh> nslookup apache.org [CPU1] dns_recv_response: DNS answer header truncated Host: apache.org Addr: 2a04:4e42::644 <- A record lost nsh> nslookup apache.org Host: apache.org Addr: 2a04:4e42::644 Host: apache.org Addr: 151.101.2.132 <- both returned The address that follows the header is already bounds checked separately, where its real length is known, so only the header check was wrong. The size is now a named constant next to the structure, since the rest of this function already used the literal 10 for the same quantity. Only IPv4-only builds escaped it, where sizeof happens to equal 14 and an A record fits exactly. Assisted-by: Claude:claude-opus-5 Signed-off-by: Justin Hammond <justin@dynam.ac>
This commit is contained in:
committed by
Alan C. Assis
parent
27ff1e74e1
commit
cda33ae4fc
@@ -158,6 +158,19 @@ begin_packed_struct struct dns_question_s
|
||||
|
||||
/* The DNS answer message structure */
|
||||
|
||||
/* The fixed part of an answer: type, class, ttl and length, before the
|
||||
* address itself.
|
||||
*
|
||||
* Use this rather than sizeof(struct dns_answer_s) to test whether a
|
||||
* response holds a whole answer header. That structure also carries the
|
||||
* union below, sixteen bytes once IPv6 is built, so its sizeof demands far
|
||||
* more of the response than the header needs and wrongly rejects a
|
||||
* trailing answer as truncated. The address that follows is bounds
|
||||
* checked separately, against its len field.
|
||||
*/
|
||||
|
||||
#define DNS_ANSWER_HEADER_SIZE 10
|
||||
|
||||
begin_packed_struct struct dns_answer_s
|
||||
{
|
||||
uint16_t type;
|
||||
|
||||
Reference in New Issue
Block a user