session_tests.py 61 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288
  1. # Copyright (C) 2012 Internet Systems Consortium.
  2. #
  3. # Permission to use, copy, modify, and distribute this software for any
  4. # purpose with or without fee is hereby granted, provided that the above
  5. # copyright notice and this permission notice appear in all copies.
  6. #
  7. # THE SOFTWARE IS PROVIDED "AS IS" AND INTERNET SYSTEMS CONSORTIUM
  8. # DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL
  9. # IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL
  10. # INTERNET SYSTEMS CONSORTIUM BE LIABLE FOR ANY SPECIAL, DIRECT,
  11. # INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING
  12. # FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT,
  13. # NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION
  14. # WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
  15. import os
  16. import shutil
  17. import isc.log
  18. import unittest
  19. from isc.dns import *
  20. from isc.datasrc import DataSourceClient
  21. from isc.ddns.session import *
  22. from isc.ddns.zone_config import *
  23. # Some common test parameters
  24. TESTDATA_PATH = os.environ['TESTDATA_PATH'] + os.sep
  25. READ_ZONE_DB_FILE = TESTDATA_PATH + "rwtest.sqlite3" # original, to be copied
  26. TESTDATA_WRITE_PATH = os.environ['TESTDATA_WRITE_PATH'] + os.sep
  27. WRITE_ZONE_DB_FILE = TESTDATA_WRITE_PATH + "rwtest.sqlite3.copied"
  28. WRITE_ZONE_DB_CONFIG = "{ \"database_file\": \"" + WRITE_ZONE_DB_FILE + "\"}"
  29. TEST_ZONE_NAME = Name('example.org')
  30. UPDATE_RRTYPE = RRType.SOA()
  31. TEST_RRCLASS = RRClass.IN()
  32. TEST_ZONE_RECORD = Question(TEST_ZONE_NAME, TEST_RRCLASS, UPDATE_RRTYPE)
  33. TEST_CLIENT6 = ('2001:db8::1', 53, 0, 0)
  34. TEST_CLIENT4 = ('192.0.2.1', 53)
  35. # TSIG key for tests when needed. The key name is TEST_ZONE_NAME.
  36. TEST_TSIG_KEY = TSIGKey("example.org:SFuWd/q99SzF8Yzd1QbB9g==")
  37. def create_update_msg(zones=[TEST_ZONE_RECORD], prerequisites=[],
  38. updates=[], tsig_key=None):
  39. msg = Message(Message.RENDER)
  40. msg.set_qid(5353) # arbitrary chosen
  41. msg.set_opcode(Opcode.UPDATE())
  42. msg.set_rcode(Rcode.NOERROR())
  43. for z in zones:
  44. msg.add_question(z)
  45. for p in prerequisites:
  46. msg.add_rrset(SECTION_PREREQUISITE, p)
  47. for u in updates:
  48. msg.add_rrset(SECTION_UPDATE, u)
  49. renderer = MessageRenderer()
  50. if tsig_key is not None:
  51. msg.to_wire(renderer, TSIGContext(tsig_key))
  52. else:
  53. msg.to_wire(renderer)
  54. # re-read the created data in the parse mode
  55. msg.clear(Message.PARSE)
  56. msg.from_wire(renderer.get_data(), Message.PRESERVE_ORDER)
  57. return msg
  58. def add_rdata(rrset, rdata):
  59. '''
  60. Helper function for easily adding Rdata fields to RRsets.
  61. This function assumes the given rdata is of type string or bytes,
  62. and corresponds to the given rrset
  63. '''
  64. rrset.add_rdata(isc.dns.Rdata(rrset.get_type(),
  65. rrset.get_class(),
  66. rdata))
  67. def create_rrset(name, rrclass, rrtype, ttl, rdatas = []):
  68. '''
  69. Helper method to easily create RRsets, auto-converts
  70. name, rrclass, rrtype, and ttl (if possibly through their
  71. respective constructors)
  72. rdatas is a list of rr data strings, or bytestrings, which
  73. should match the RRType of the rrset to create
  74. '''
  75. if type(name) != Name:
  76. name = Name(name)
  77. if type(rrclass) != RRClass:
  78. rrclass = RRClass(rrclass)
  79. if type(rrtype) != RRType:
  80. rrtype = RRType(rrtype)
  81. if type(ttl) != RRTTL:
  82. ttl = RRTTL(ttl)
  83. rrset = isc.dns.RRset(name, rrclass, rrtype, ttl)
  84. for rdata in rdatas:
  85. add_rdata(rrset, rdata)
  86. return rrset
  87. class SessionTestBase(unittest.TestCase):
  88. '''Base class for all sesion related tests.
  89. It just initializes common test parameters in its setUp() and defines
  90. some common utility method(s).
  91. '''
  92. def setUp(self):
  93. shutil.copyfile(READ_ZONE_DB_FILE, WRITE_ZONE_DB_FILE)
  94. self._datasrc_client = DataSourceClient("sqlite3",
  95. WRITE_ZONE_DB_CONFIG)
  96. self._update_msg = create_update_msg()
  97. self._acl_map = {(TEST_ZONE_NAME, TEST_RRCLASS):
  98. REQUEST_LOADER.load([{"action": "ACCEPT"}])}
  99. self._session = UpdateSession(self._update_msg, TEST_CLIENT4,
  100. ZoneConfig([], TEST_RRCLASS,
  101. self._datasrc_client,
  102. self._acl_map))
  103. self._session._UpdateSession__get_update_zone()
  104. def check_response(self, msg, expected_rcode):
  105. '''Perform common checks on update resposne message.'''
  106. self.assertTrue(msg.get_header_flag(Message.HEADERFLAG_QR))
  107. # note: we convert opcode to text it'd be more helpful on failure.
  108. self.assertEqual(Opcode.UPDATE().to_text(), msg.get_opcode().to_text())
  109. self.assertEqual(expected_rcode.to_text(), msg.get_rcode().to_text())
  110. # All sections should be cleared
  111. self.assertEqual(0, msg.get_rr_count(SECTION_ZONE))
  112. self.assertEqual(0, msg.get_rr_count(SECTION_PREREQUISITE))
  113. self.assertEqual(0, msg.get_rr_count(SECTION_UPDATE))
  114. self.assertEqual(0, msg.get_rr_count(Message.SECTION_ADDITIONAL))
  115. class SessionTest(SessionTestBase):
  116. '''Basic session tests'''
  117. def test_handle(self):
  118. '''Basic update case'''
  119. result, zname, zclass = self._session.handle()
  120. self.assertEqual(UPDATE_SUCCESS, result)
  121. self.assertEqual(TEST_ZONE_NAME, zname)
  122. self.assertEqual(TEST_RRCLASS, zclass)
  123. # Just checking these are different from the success code.
  124. self.assertNotEqual(UPDATE_ERROR, result)
  125. self.assertNotEqual(UPDATE_DROP, result)
  126. def test_broken_request(self):
  127. # Zone section is empty
  128. msg = create_update_msg(zones=[])
  129. session = UpdateSession(msg, TEST_CLIENT6, None)
  130. result, zname, zclass = session.handle()
  131. self.assertEqual(UPDATE_ERROR, result)
  132. self.assertEqual(None, zname)
  133. self.assertEqual(None, zclass)
  134. self.check_response(session.get_message(), Rcode.FORMERR())
  135. # Zone section contains multiple records
  136. msg = create_update_msg(zones=[TEST_ZONE_RECORD, TEST_ZONE_RECORD])
  137. session = UpdateSession(msg, TEST_CLIENT4, None)
  138. self.assertEqual(UPDATE_ERROR, session.handle()[0])
  139. self.check_response(session.get_message(), Rcode.FORMERR())
  140. # Zone section's type is not SOA
  141. msg = create_update_msg(zones=[Question(TEST_ZONE_NAME, TEST_RRCLASS,
  142. RRType.A())])
  143. session = UpdateSession(msg, TEST_CLIENT4, None)
  144. self.assertEqual(UPDATE_ERROR, session.handle()[0])
  145. self.check_response(session.get_message(), Rcode.FORMERR())
  146. def test_update_secondary(self):
  147. # specified zone is configured as a secondary. Since this
  148. # implementation doesn't support update forwarding, the result
  149. # should be NOTIMP.
  150. msg = create_update_msg(zones=[Question(TEST_ZONE_NAME, TEST_RRCLASS,
  151. RRType.SOA())])
  152. session = UpdateSession(msg, TEST_CLIENT4,
  153. ZoneConfig([(TEST_ZONE_NAME, TEST_RRCLASS)],
  154. TEST_RRCLASS, self._datasrc_client))
  155. self.assertEqual(UPDATE_ERROR, session.handle()[0])
  156. self.check_response(session.get_message(), Rcode.NOTIMP())
  157. def check_notauth(self, zname, zclass=TEST_RRCLASS):
  158. '''Common test sequence for the 'notauth' test'''
  159. msg = create_update_msg(zones=[Question(zname, zclass, RRType.SOA())])
  160. session = UpdateSession(msg, TEST_CLIENT4,
  161. ZoneConfig([(TEST_ZONE_NAME, TEST_RRCLASS)],
  162. TEST_RRCLASS, self._datasrc_client))
  163. self.assertEqual(UPDATE_ERROR, session.handle()[0])
  164. self.check_response(session.get_message(), Rcode.NOTAUTH())
  165. def test_update_notauth(self):
  166. '''Update attempt for non authoritative zones'''
  167. # zone name doesn't match
  168. self.check_notauth(Name('example.com'))
  169. # zone name is a subdomain of the actual authoritative zone
  170. # (match must be exact)
  171. self.check_notauth(Name('sub.example.org'))
  172. # zone class doesn't match
  173. self.check_notauth(Name('example.org'), RRClass.CH())
  174. def test_update_datasrc_error(self):
  175. # if the data source client raises an exception, it should result in
  176. # a SERVFAIL.
  177. class BadDataSourceClient:
  178. def find_zone(self, name):
  179. raise isc.datasrc.Error('faked exception')
  180. msg = create_update_msg(zones=[Question(TEST_ZONE_NAME, TEST_RRCLASS,
  181. RRType.SOA())])
  182. session = UpdateSession(msg, TEST_CLIENT4,
  183. ZoneConfig([(TEST_ZONE_NAME, TEST_RRCLASS)],
  184. TEST_RRCLASS,
  185. BadDataSourceClient()))
  186. self.assertEqual(UPDATE_ERROR, session.handle()[0])
  187. self.check_response(session.get_message(), Rcode.SERVFAIL())
  188. def test_foreach_rr_in_rrset(self):
  189. rrset = create_rrset("www.example.org", TEST_RRCLASS,
  190. RRType.A(), 3600, [ "192.0.2.1" ])
  191. l = []
  192. for rr in foreach_rr(rrset):
  193. l.append(str(rr))
  194. self.assertEqual(["www.example.org. 3600 IN A 192.0.2.1\n"], l)
  195. add_rdata(rrset, "192.0.2.2")
  196. add_rdata(rrset, "192.0.2.3")
  197. # but through the generator, there should be several 1-line entries
  198. l = []
  199. for rr in foreach_rr(rrset):
  200. l.append(str(rr))
  201. self.assertEqual(["www.example.org. 3600 IN A 192.0.2.1\n",
  202. "www.example.org. 3600 IN A 192.0.2.2\n",
  203. "www.example.org. 3600 IN A 192.0.2.3\n",
  204. ], l)
  205. def test_convert_rrset_class(self):
  206. # Converting an RRSET to a different class should work
  207. # if the rdata types can be converted
  208. rrset = create_rrset("www.example.org", RRClass.NONE(), RRType.A(),
  209. 3600, [ b'\xc0\x00\x02\x01', b'\xc0\x00\x02\x02'])
  210. rrset2 = convert_rrset_class(rrset, RRClass.IN())
  211. self.assertEqual("www.example.org. 3600 IN A 192.0.2.1\n" +
  212. "www.example.org. 3600 IN A 192.0.2.2\n",
  213. str(rrset2))
  214. rrset3 = convert_rrset_class(rrset2, RRClass.NONE())
  215. self.assertEqual("www.example.org. 3600 CLASS254 A \\# 4 " +
  216. "c0000201\nwww.example.org. 3600 CLASS254 " +
  217. "A \\# 4 c0000202\n",
  218. str(rrset3))
  219. # depending on what type of bad data is given, a number
  220. # of different exceptions could be raised (TODO: i recall
  221. # there was a ticket about making a better hierarchy for
  222. # dns/parsing related exceptions)
  223. self.assertRaises(InvalidRdataLength, convert_rrset_class,
  224. rrset, RRClass.CH())
  225. add_rdata(rrset, b'\xc0\x00')
  226. self.assertRaises(DNSMessageFORMERR, convert_rrset_class,
  227. rrset, RRClass.IN())
  228. def test_collect_rrsets(self):
  229. '''
  230. Tests the 'rrset collector' method, which collects rrsets
  231. with the same name and type
  232. '''
  233. collected = []
  234. collect_rrsets(collected, create_rrset("a.example.org", RRClass.IN(),
  235. RRType.A(), 0, [ "192.0.2.1" ]))
  236. # Same name and class, different type
  237. collect_rrsets(collected, create_rrset("a.example.org", RRClass.IN(),
  238. RRType.TXT(), 0, [ "one" ]))
  239. collect_rrsets(collected, create_rrset("a.example.org", RRClass.IN(),
  240. RRType.A(), 0, [ "192.0.2.2" ]))
  241. collect_rrsets(collected, create_rrset("a.example.org", RRClass.IN(),
  242. RRType.TXT(), 0, [ "two" ]))
  243. # Same class and type as an existing one, different name
  244. collect_rrsets(collected, create_rrset("b.example.org", RRClass.IN(),
  245. RRType.A(), 0, [ "192.0.2.3" ]))
  246. # Same name and type as an existing one, different class
  247. collect_rrsets(collected, create_rrset("a.example.org", RRClass.CH(),
  248. RRType.TXT(), 0, [ "one" ]))
  249. collect_rrsets(collected, create_rrset("b.example.org", RRClass.IN(),
  250. RRType.A(), 0, [ "192.0.2.4" ]))
  251. collect_rrsets(collected, create_rrset("a.example.org", RRClass.CH(),
  252. RRType.TXT(), 0, [ "two" ]))
  253. strings = [ rrset.to_text() for rrset in collected ]
  254. # note + vs , in this list
  255. expected = ['a.example.org. 0 IN A 192.0.2.1\n' +
  256. 'a.example.org. 0 IN A 192.0.2.2\n',
  257. 'a.example.org. 0 IN TXT "one"\n' +
  258. 'a.example.org. 0 IN TXT "two"\n',
  259. 'b.example.org. 0 IN A 192.0.2.3\n' +
  260. 'b.example.org. 0 IN A 192.0.2.4\n',
  261. 'a.example.org. 0 CH TXT "one"\n' +
  262. 'a.example.org. 0 CH TXT "two"\n']
  263. self.assertEqual(expected, strings)
  264. def __prereq_helper(self, method, expected, rrset):
  265. '''Calls the given method with self._datasrc_client
  266. and the given rrset, and compares the return value.
  267. Function does not do much but makes the code look nicer'''
  268. self.assertEqual(expected, method(rrset))
  269. def __check_prerequisite_exists_combined(self, method, rrclass, expected):
  270. '''shared code for the checks for the very similar (but reversed
  271. in behaviour) methods __prereq_rrset_exists and
  272. __prereq_rrset_does_not_exist.
  273. For rrset_exists, rrclass should be ANY, for rrset_does_not_exist,
  274. it should be NONE.
  275. '''
  276. # Basic existence checks
  277. # www.example.org should have an A, but not an MX
  278. rrset = create_rrset("www.example.org", rrclass, RRType.A(), 0)
  279. self.__prereq_helper(method, expected, rrset)
  280. rrset = create_rrset("www.example.org", rrclass, RRType.MX(), 0)
  281. self.__prereq_helper(method, not expected, rrset)
  282. # example.org should have an MX, but not an A
  283. rrset = create_rrset("example.org", rrclass, RRType.MX(), 0)
  284. self.__prereq_helper(method, expected, rrset)
  285. rrset = create_rrset("example.org", rrclass, RRType.A(), 0)
  286. self.__prereq_helper(method, not expected, rrset)
  287. # Also check the case where the name does not even exist
  288. rrset = create_rrset("doesnotexist.example.org", rrclass, RRType.A(), 0)
  289. self.__prereq_helper(method, not expected, rrset)
  290. # Wildcard expansion should not be applied, but literal matches
  291. # should work
  292. rrset = create_rrset("foo.wildcard.example.org", rrclass, RRType.A(), 0)
  293. self.__prereq_helper(method, not expected, rrset)
  294. rrset = create_rrset("*.wildcard.example.org", rrclass, RRType.A(), 0)
  295. self.__prereq_helper(method, expected, rrset)
  296. # Likewise, CNAME directly should match, but what it points to should
  297. # not
  298. rrset = create_rrset("cname.example.org", rrclass, RRType.A(), 0)
  299. self.__prereq_helper(method, not expected, rrset)
  300. rrset = create_rrset("cname.example.org", rrclass, RRType.CNAME(), 0)
  301. self.__prereq_helper(method, expected, rrset)
  302. # And also make sure a delegation (itself) is not treated as existing
  303. # data
  304. rrset = create_rrset("foo.sub.example.org", rrclass, RRType.A(), 0)
  305. self.__prereq_helper(method, not expected, rrset)
  306. # But the delegation data itself should match
  307. rrset = create_rrset("sub.example.org", rrclass, RRType.NS(), 0)
  308. self.__prereq_helper(method, expected, rrset)
  309. # As should glue
  310. rrset = create_rrset("ns.sub.example.org", rrclass, RRType.A(), 0)
  311. self.__prereq_helper(method, expected, rrset)
  312. def test_check_prerequisite_exists(self):
  313. method = self._session._UpdateSession__prereq_rrset_exists
  314. self.__check_prerequisite_exists_combined(method,
  315. RRClass.ANY(),
  316. True)
  317. def test_check_prerequisite_does_not_exist(self):
  318. method = self._session._UpdateSession__prereq_rrset_does_not_exist
  319. self.__check_prerequisite_exists_combined(method,
  320. RRClass.NONE(),
  321. False)
  322. def test_check_prerequisite_exists_value(self):
  323. method = self._session._UpdateSession__prereq_rrset_exists_value
  324. rrset = create_rrset("www.example.org", RRClass.IN(), RRType.A(), 0)
  325. # empty one should not match
  326. self.__prereq_helper(method, False, rrset)
  327. # When the rdata is added, it should match
  328. add_rdata(rrset, "192.0.2.1")
  329. self.__prereq_helper(method, True, rrset)
  330. # But adding more should not
  331. add_rdata(rrset, "192.0.2.2")
  332. self.__prereq_helper(method, False, rrset)
  333. # Also test one with more than one RR
  334. rrset = create_rrset("example.org", RRClass.IN(), RRType.NS(), 0)
  335. self.__prereq_helper(method, False, rrset)
  336. add_rdata(rrset, "ns1.example.org.")
  337. self.__prereq_helper(method, False, rrset)
  338. add_rdata(rrset, "ns2.example.org")
  339. self.__prereq_helper(method, False, rrset)
  340. add_rdata(rrset, "ns3.example.org.")
  341. self.__prereq_helper(method, True, rrset)
  342. add_rdata(rrset, "ns4.example.org.")
  343. self.__prereq_helper(method, False, rrset)
  344. # Repeat that, but try a different order of Rdata addition
  345. rrset = create_rrset("example.org", RRClass.IN(), RRType.NS(), 0)
  346. self.__prereq_helper(method, False, rrset)
  347. add_rdata(rrset, "ns3.example.org.")
  348. self.__prereq_helper(method, False, rrset)
  349. add_rdata(rrset, "ns2.example.org.")
  350. self.__prereq_helper(method, False, rrset)
  351. add_rdata(rrset, "ns1.example.org.")
  352. self.__prereq_helper(method, True, rrset)
  353. add_rdata(rrset, "ns4.example.org.")
  354. self.__prereq_helper(method, False, rrset)
  355. # and test one where the name does not even exist
  356. rrset = create_rrset("doesnotexist.example.org", RRClass.IN(),
  357. RRType.A(), 0, [ "192.0.2.1" ])
  358. self.__prereq_helper(method, False, rrset)
  359. def __check_prerequisite_name_in_use_combined(self, method, rrclass,
  360. expected):
  361. '''shared code for the checks for the very similar (but reversed
  362. in behaviour) methods __prereq_name_in_use and
  363. __prereq_name_not_in_use
  364. '''
  365. rrset = create_rrset("example.org", rrclass, RRType.ANY(), 0)
  366. self.__prereq_helper(method, expected, rrset)
  367. rrset = create_rrset("www.example.org", rrclass, RRType.ANY(), 0)
  368. self.__prereq_helper(method, expected, rrset)
  369. rrset = create_rrset("doesnotexist.example.org", rrclass,
  370. RRType.ANY(), 0)
  371. self.__prereq_helper(method, not expected, rrset)
  372. rrset = create_rrset("belowdelegation.sub.example.org", rrclass,
  373. RRType.ANY(), 0)
  374. self.__prereq_helper(method, not expected, rrset)
  375. rrset = create_rrset("foo.wildcard.example.org", rrclass,
  376. RRType.ANY(), 0)
  377. self.__prereq_helper(method, not expected, rrset)
  378. # empty nonterminal should not match
  379. rrset = create_rrset("nonterminal.example.org", rrclass,
  380. RRType.ANY(), 0)
  381. self.__prereq_helper(method, not expected, rrset)
  382. rrset = create_rrset("empty.nonterminal.example.org", rrclass,
  383. RRType.ANY(), 0)
  384. self.__prereq_helper(method, expected, rrset)
  385. def test_check_prerequisite_name_in_use(self):
  386. method = self._session._UpdateSession__prereq_name_in_use
  387. self.__check_prerequisite_name_in_use_combined(method,
  388. RRClass.ANY(),
  389. True)
  390. def test_check_prerequisite_name_not_in_use(self):
  391. method = self._session._UpdateSession__prereq_name_not_in_use
  392. self.__check_prerequisite_name_in_use_combined(method,
  393. RRClass.NONE(),
  394. False)
  395. def check_prerequisite_result(self, expected, prerequisites):
  396. '''Helper method for checking the result of a prerequisite check;
  397. creates an update session, and fills it with the list of rrsets
  398. from 'prerequisites'. Then checks if __check_prerequisites()
  399. returns the Rcode specified in 'expected'.'''
  400. msg = create_update_msg([TEST_ZONE_RECORD], prerequisites)
  401. zconfig = ZoneConfig([], TEST_RRCLASS, self._datasrc_client,
  402. self._acl_map)
  403. session = UpdateSession(msg, TEST_CLIENT4, zconfig)
  404. session._UpdateSession__get_update_zone()
  405. # compare the to_text output of the rcodes (nicer error messages)
  406. # This call itself should also be done by handle(),
  407. # but just for better failures, it is first called on its own
  408. self.assertEqual(expected.to_text(),
  409. session._UpdateSession__check_prerequisites().to_text())
  410. # Now see if handle finds the same result
  411. (result, _, _) = session.handle()
  412. self.assertEqual(expected.to_text(),
  413. session._UpdateSession__message.get_rcode().to_text())
  414. # And that the result looks right
  415. if expected == Rcode.NOERROR():
  416. self.assertEqual(UPDATE_SUCCESS, result)
  417. else:
  418. self.assertEqual(UPDATE_ERROR, result)
  419. def check_prescan_result(self, expected, updates, expected_soa = None):
  420. '''Helper method for checking the result of a prerequisite check;
  421. creates an update session, and fills it with the list of rrsets
  422. from 'updates'. Then checks if __do_prescan()
  423. returns the Rcode specified in 'expected'.'''
  424. msg = create_update_msg([TEST_ZONE_RECORD], [], updates)
  425. zconfig = ZoneConfig([], TEST_RRCLASS, self._datasrc_client,
  426. self._acl_map)
  427. session = UpdateSession(msg, TEST_CLIENT4, zconfig)
  428. session._UpdateSession__get_update_zone()
  429. # compare the to_text output of the rcodes (nicer error messages)
  430. # This call itself should also be done by handle(),
  431. # but just for better failures, it is first called on its own
  432. self.assertEqual(expected.to_text(),
  433. session._UpdateSession__do_prescan().to_text())
  434. # If there is an expected soa, check it
  435. self.assertEqual(str(expected_soa),
  436. str(session._UpdateSession__added_soa))
  437. def check_full_handle_result(self, expected, updates):
  438. '''Helper method for checking the result of a full handle;
  439. creates an update session, and fills it with the list of rrsets
  440. from 'updates'. Then checks if __handle()
  441. results in a response with rcode 'expected'.'''
  442. msg = create_update_msg([TEST_ZONE_RECORD], [], updates)
  443. zconfig = ZoneConfig([], TEST_RRCLASS, self._datasrc_client,
  444. self._acl_map)
  445. session = UpdateSession(msg, TEST_CLIENT4, zconfig)
  446. # Now see if handle finds the same result
  447. (result, _, _) = session.handle()
  448. self.assertEqual(expected.to_text(),
  449. session._UpdateSession__message.get_rcode().to_text())
  450. # And that the result looks right
  451. if expected == Rcode.NOERROR():
  452. self.assertEqual(UPDATE_SUCCESS, result)
  453. else:
  454. self.assertEqual(UPDATE_ERROR, result)
  455. def test_check_prerequisites(self):
  456. # This test checks if the actual prerequisite-type-specific
  457. # methods are called.
  458. # It does test all types of prerequisites, but it does not test
  459. # every possible result for those types (those are tested above,
  460. # in the specific prerequisite type tests)
  461. # Let's first define a number of prereq's that should succeed
  462. rrset_exists_yes = create_rrset("example.org", RRClass.ANY(),
  463. RRType.SOA(), 0)
  464. rrset_exists_value_yes = create_rrset("www.example.org", RRClass.IN(),
  465. RRType.A(), 0, [ "192.0.2.1" ])
  466. rrset_does_not_exist_yes = create_rrset("foo.example.org",
  467. RRClass.NONE(), RRType.SOA(),
  468. 0)
  469. name_in_use_yes = create_rrset("www.example.org", RRClass.ANY(),
  470. RRType.ANY(), 0)
  471. name_not_in_use_yes = create_rrset("foo.example.org", RRClass.NONE(),
  472. RRType.ANY(), 0)
  473. rrset_exists_value_1 = create_rrset("example.org", RRClass.IN(),
  474. RRType.NS(), 0,
  475. [ "ns1.example.org" ])
  476. rrset_exists_value_2 = create_rrset("example.org", RRClass.IN(),
  477. RRType.NS(), 0,
  478. [ "ns2.example.org" ])
  479. rrset_exists_value_3 = create_rrset("example.org", RRClass.IN(),
  480. RRType.NS(), 0,
  481. [ "ns3.example.org" ])
  482. # and a number that should not
  483. rrset_exists_no = create_rrset("foo.example.org", RRClass.ANY(),
  484. RRType.SOA(), 0)
  485. rrset_exists_value_no = create_rrset("www.example.org", RRClass.IN(),
  486. RRType.A(), 0, [ "192.0.2.2" ])
  487. rrset_does_not_exist_no = create_rrset("example.org", RRClass.NONE(),
  488. RRType.SOA(), 0)
  489. name_in_use_no = create_rrset("foo.example.org", RRClass.ANY(),
  490. RRType.ANY(), 0)
  491. name_not_in_use_no = create_rrset("www.example.org", RRClass.NONE(),
  492. RRType.ANY(), 0)
  493. # check 'no' result codes
  494. self.check_prerequisite_result(Rcode.NXRRSET(),
  495. [ rrset_exists_no ])
  496. self.check_prerequisite_result(Rcode.NXRRSET(),
  497. [ rrset_exists_value_no ])
  498. self.check_prerequisite_result(Rcode.YXRRSET(),
  499. [ rrset_does_not_exist_no ])
  500. self.check_prerequisite_result(Rcode.NXDOMAIN(),
  501. [ name_in_use_no ])
  502. self.check_prerequisite_result(Rcode.YXDOMAIN(),
  503. [ name_not_in_use_no ])
  504. # the 'yes' codes should result in ok
  505. # individually
  506. self.check_prerequisite_result(Rcode.NOERROR(),
  507. [ rrset_exists_yes ] )
  508. self.check_prerequisite_result(Rcode.NOERROR(),
  509. [ rrset_exists_value_yes ])
  510. self.check_prerequisite_result(Rcode.NOERROR(),
  511. [ rrset_does_not_exist_yes ])
  512. self.check_prerequisite_result(Rcode.NOERROR(),
  513. [ name_in_use_yes ])
  514. self.check_prerequisite_result(Rcode.NOERROR(),
  515. [ name_not_in_use_yes ])
  516. self.check_prerequisite_result(Rcode.NOERROR(),
  517. [ rrset_exists_value_1,
  518. rrset_exists_value_2,
  519. rrset_exists_value_3])
  520. # and together
  521. self.check_prerequisite_result(Rcode.NOERROR(),
  522. [ rrset_exists_yes,
  523. rrset_exists_value_yes,
  524. rrset_does_not_exist_yes,
  525. name_in_use_yes,
  526. name_not_in_use_yes,
  527. rrset_exists_value_1,
  528. rrset_exists_value_2,
  529. rrset_exists_value_3])
  530. # try out a permutation, note that one rrset is split up,
  531. # and the order of the RRs should not matter
  532. self.check_prerequisite_result(Rcode.NOERROR(),
  533. [ rrset_exists_value_3,
  534. rrset_exists_yes,
  535. rrset_exists_value_2,
  536. name_in_use_yes,
  537. rrset_exists_value_1])
  538. # Should fail on the first error, even if most of the
  539. # prerequisites are ok
  540. self.check_prerequisite_result(Rcode.NXDOMAIN(),
  541. [ rrset_exists_value_3,
  542. rrset_exists_yes,
  543. rrset_exists_value_2,
  544. name_in_use_yes,
  545. name_in_use_no,
  546. rrset_exists_value_1])
  547. def test_prerequisite_notzone(self):
  548. rrset = create_rrset("some.other.zone.", RRClass.ANY(), RRType.SOA(), 0)
  549. self.check_prerequisite_result(Rcode.NOTZONE(), [ rrset ])
  550. def test_prerequisites_formerr(self):
  551. # test for form errors in the prerequisite section
  552. # Class ANY, non-zero TTL
  553. rrset = create_rrset("example.org", RRClass.ANY(), RRType.SOA(), 1)
  554. self.check_prerequisite_result(Rcode.FORMERR(), [ rrset ])
  555. # Class ANY, but with rdata
  556. rrset = create_rrset("example.org", RRClass.ANY(), RRType.A(), 0,
  557. [ b'\x00\x00\x00\x00' ])
  558. self.check_prerequisite_result(Rcode.FORMERR(), [ rrset ])
  559. # Class NONE, non-zero TTL
  560. rrset = create_rrset("example.org", RRClass.NONE(), RRType.SOA(), 1)
  561. self.check_prerequisite_result(Rcode.FORMERR(), [ rrset ])
  562. # Class NONE, but with rdata
  563. rrset = create_rrset("example.org", RRClass.NONE(), RRType.A(), 0,
  564. [ b'\x00\x00\x00\x00' ])
  565. self.check_prerequisite_result(Rcode.FORMERR(), [ rrset ])
  566. # Matching class and type, but non-zero TTL
  567. rrset = create_rrset("www.example.org", RRClass.IN(), RRType.A(), 1,
  568. [ "192.0.2.1" ])
  569. self.check_prerequisite_result(Rcode.FORMERR(), [ rrset ])
  570. # Completely different class
  571. rrset = create_rrset("example.org", RRClass.CH(), RRType.TXT(), 0,
  572. [ "foo" ])
  573. self.check_prerequisite_result(Rcode.FORMERR(), [ rrset ])
  574. def __prereq_helper(self, method, expected, rrset):
  575. '''Calls the given method with self._datasrc_client
  576. and the given rrset, and compares the return value.
  577. Function does not do much but makes the code look nicer'''
  578. self.assertEqual(expected, method(rrset))
  579. def __initialize_update_rrsets(self):
  580. '''Prepare a number of RRsets to be used in several update tests
  581. The rrsets are stored in self'''
  582. orig_a_rrset = create_rrset("www.example.org", TEST_RRCLASS,
  583. RRType.A(), 3600, [ "192.0.2.1" ])
  584. self.orig_a_rrset = orig_a_rrset
  585. rrset_update_a = create_rrset("www.example.org", TEST_RRCLASS,
  586. RRType.A(), 3600,
  587. [ "192.0.2.2", "192.0.2.3" ])
  588. self.rrset_update_a = rrset_update_a
  589. rrset_update_soa = create_rrset("example.org", TEST_RRCLASS,
  590. RRType.SOA(), 3600,
  591. [ "ns1.example.org. " +
  592. "admin.example.org. " +
  593. "1233 3600 1800 2419200 7200" ])
  594. self.rrset_update_soa = rrset_update_soa
  595. rrset_update_soa_del = create_rrset("example.org", RRClass.NONE(),
  596. RRType.SOA(), 0,
  597. [ "ns1.example.org. " +
  598. "admin.example.org. " +
  599. "1233 3600 1800 2419200 7200" ])
  600. self.rrset_update_soa_del = rrset_update_soa_del
  601. rrset_update_soa2 = create_rrset("example.org", TEST_RRCLASS,
  602. RRType.SOA(), 3600,
  603. [ "ns1.example.org. " +
  604. "admin.example.org. " +
  605. "4000 3600 1800 2419200 7200" ])
  606. self.rrset_update_soa2 = rrset_update_soa2
  607. rrset_update_del_name = create_rrset("www.example.org", RRClass.ANY(),
  608. RRType.ANY(), 0)
  609. self.rrset_update_del_name = rrset_update_del_name
  610. rrset_update_del_name_apex = create_rrset("example.org", RRClass.ANY(),
  611. RRType.ANY(), 0)
  612. self.rrset_update_del_name_apex = rrset_update_del_name_apex
  613. rrset_update_del_rrset = create_rrset("www.example.org", RRClass.ANY(),
  614. RRType.A(), 0)
  615. self.rrset_update_del_rrset = rrset_update_del_rrset
  616. rrset_update_del_mx_apex = create_rrset("example.org", RRClass.ANY(),
  617. RRType.MX(), 0)
  618. self.rrset_update_del_mx_apex = rrset_update_del_mx_apex
  619. rrset_update_del_soa_apex = create_rrset("example.org", RRClass.ANY(),
  620. RRType.SOA(), 0)
  621. self.rrset_update_del_soa_apex = rrset_update_del_soa_apex
  622. rrset_update_del_ns_apex = create_rrset("example.org", RRClass.ANY(),
  623. RRType.NS(), 0)
  624. self.rrset_update_del_ns_apex = rrset_update_del_ns_apex
  625. rrset_update_del_rrset_part = create_rrset("www.example.org",
  626. RRClass.NONE(), RRType.A(),
  627. 0,
  628. [ b'\xc0\x00\x02\x02',
  629. b'\xc0\x00\x02\x03' ])
  630. self.rrset_update_del_rrset_part = rrset_update_del_rrset_part
  631. rrset_update_del_rrset_ns = create_rrset("example.org", RRClass.NONE(),
  632. RRType.NS(), 0,
  633. [ b'\x03ns1\x07example\x03org\x00',
  634. b'\x03ns2\x07example\x03org\x00',
  635. b'\x03ns3\x07example\x03org\x00' ])
  636. self.rrset_update_del_rrset_ns = rrset_update_del_rrset_ns
  637. rrset_update_del_rrset_mx = create_rrset("example.org", RRClass.NONE(),
  638. RRType.MX(), 0,
  639. [ b'\x00\x0a\x04mail\x07example\x03org\x00' ])
  640. self.rrset_update_del_rrset_mx = rrset_update_del_rrset_mx
  641. def test_prescan(self):
  642. '''Test whether the prescan succeeds on data that is ok, and whether
  643. if notices the SOA if present'''
  644. # prepare a set of correct update statements
  645. self.__initialize_update_rrsets()
  646. self.check_prescan_result(Rcode.NOERROR(), [ self.rrset_update_a ])
  647. # check if soa is noticed
  648. self.check_prescan_result(Rcode.NOERROR(), [ self.rrset_update_soa ],
  649. self.rrset_update_soa)
  650. # Other types of succesful prechecks
  651. self.check_prescan_result(Rcode.NOERROR(), [ self.rrset_update_soa2 ],
  652. self.rrset_update_soa2)
  653. self.check_prescan_result(Rcode.NOERROR(),
  654. [ self.rrset_update_del_name ])
  655. self.check_prescan_result(Rcode.NOERROR(),
  656. [ self.rrset_update_del_name_apex ])
  657. self.check_prescan_result(Rcode.NOERROR(),
  658. [ self.rrset_update_del_rrset ])
  659. self.check_prescan_result(Rcode.NOERROR(),
  660. [ self.rrset_update_del_mx_apex ])
  661. self.check_prescan_result(Rcode.NOERROR(),
  662. [ self.rrset_update_del_rrset_part ])
  663. # and check a few permutations of the above
  664. # all of them (with one of the soas)
  665. self.check_prescan_result(Rcode.NOERROR(),
  666. [
  667. self.rrset_update_a,
  668. self.rrset_update_soa,
  669. self.rrset_update_del_name,
  670. self.rrset_update_del_name_apex,
  671. self.rrset_update_del_rrset,
  672. self.rrset_update_del_mx_apex,
  673. self.rrset_update_del_rrset_part
  674. ],
  675. self.rrset_update_soa)
  676. # Two soas. Should we reject or simply use the last?
  677. # (RFC is not really explicit on this, but between the lines I read
  678. # use the last)
  679. self.check_prescan_result(Rcode.NOERROR(),
  680. [ self.rrset_update_soa,
  681. self.rrset_update_soa2 ],
  682. self.rrset_update_soa2)
  683. self.check_prescan_result(Rcode.NOERROR(),
  684. [ self.rrset_update_soa2,
  685. self.rrset_update_soa ],
  686. self.rrset_update_soa)
  687. self.check_prescan_result(Rcode.NOERROR(),
  688. [
  689. self.rrset_update_del_mx_apex,
  690. self.rrset_update_del_name,
  691. self.rrset_update_del_name_apex,
  692. self.rrset_update_del_rrset_part,
  693. self.rrset_update_a,
  694. self.rrset_update_del_rrset,
  695. self.rrset_update_soa
  696. ],
  697. self.rrset_update_soa)
  698. def test_prescan_failures(self):
  699. '''Test whether prescan fails on bad data'''
  700. # out of zone data
  701. rrset = create_rrset("different.zone", RRClass.ANY(), RRType.TXT(), 0)
  702. self.check_prescan_result(Rcode.NOTZONE(), [ rrset ])
  703. # forbidden type, zone class
  704. rrset = create_rrset(TEST_ZONE_NAME, TEST_RRCLASS, RRType.ANY(), 0,
  705. [ b'\x00' ])
  706. self.check_prescan_result(Rcode.FORMERR(), [ rrset ])
  707. # non-zero TTL, class ANY
  708. rrset = create_rrset(TEST_ZONE_NAME, RRClass.ANY(), RRType.TXT(), 1)
  709. self.check_prescan_result(Rcode.FORMERR(), [ rrset ])
  710. # non-zero Rdata, class ANY
  711. rrset = create_rrset(TEST_ZONE_NAME, RRClass.ANY(), RRType.TXT(), 0,
  712. [ "foo" ])
  713. self.check_prescan_result(Rcode.FORMERR(), [ rrset ])
  714. # forbidden type, class ANY
  715. rrset = create_rrset(TEST_ZONE_NAME, RRClass.ANY(), RRType.AXFR(), 0,
  716. [ b'\x00' ])
  717. self.check_prescan_result(Rcode.FORMERR(), [ rrset ])
  718. # non-zero TTL, class NONE
  719. rrset = create_rrset(TEST_ZONE_NAME, RRClass.NONE(), RRType.TXT(), 1)
  720. self.check_prescan_result(Rcode.FORMERR(), [ rrset ])
  721. # forbidden type, class NONE
  722. rrset = create_rrset(TEST_ZONE_NAME, RRClass.NONE(), RRType.AXFR(), 0,
  723. [ b'\x00' ])
  724. self.check_prescan_result(Rcode.FORMERR(), [ rrset ])
  725. def __check_inzone_data(self, expected_result, name, rrtype,
  726. expected_rrset = None):
  727. '''Does a find on TEST_ZONE for the given rrset's name and type,
  728. then checks if the result matches the expected result.
  729. If so, and if expected_rrset is given, they are compared as
  730. well.'''
  731. _, finder = self._datasrc_client.find_zone(TEST_ZONE_NAME)
  732. result, found_rrset, _ = finder.find(name, rrtype,
  733. finder.NO_WILDCARD |
  734. finder.FIND_GLUE_OK)
  735. self.assertEqual(expected_result, result)
  736. # Sigh. Need rrsets.compare() again.
  737. # To be sure, compare name, class, type, and ttl
  738. if expected_rrset is not None:
  739. self.assertEqual(expected_rrset.get_name(), found_rrset.get_name())
  740. self.assertEqual(expected_rrset.get_class(), found_rrset.get_class())
  741. self.assertEqual(expected_rrset.get_type(), found_rrset.get_type())
  742. self.assertEqual(expected_rrset.get_ttl().to_text(),
  743. found_rrset.get_ttl().to_text())
  744. expected_rdata =\
  745. [ rdata.to_text() for rdata in expected_rrset.get_rdata() ]
  746. found_rdata =\
  747. [ rdata.to_text() for rdata in found_rrset.get_rdata() ]
  748. expected_rdata.sort()
  749. found_rdata.sort()
  750. self.assertEqual(expected_rdata, found_rdata)
  751. def test_update_add_delete_rrset(self):
  752. '''
  753. Tests a sequence of related add and delete updates. Some other
  754. cases are tested by later tests.
  755. '''
  756. self.__initialize_update_rrsets()
  757. # initially, the www should only contain one rr
  758. # (set to self.orig_a_rrset)
  759. # during this test, we will extend it at some point
  760. extended_a_rrset = create_rrset("www.example.org", TEST_RRCLASS,
  761. RRType.A(), 3600,
  762. [ "192.0.2.1",
  763. "192.0.2.2",
  764. "192.0.2.3" ])
  765. # Sanity check, make sure original data is really there before updates
  766. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  767. isc.dns.Name("www.example.org"),
  768. RRType.A(),
  769. self.orig_a_rrset)
  770. # Add two rrs
  771. self.check_full_handle_result(Rcode.NOERROR(), [ self.rrset_update_a ])
  772. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  773. isc.dns.Name("www.example.org"),
  774. RRType.A(),
  775. extended_a_rrset)
  776. # Adding the same RRsets should not make a difference.
  777. self.check_full_handle_result(Rcode.NOERROR(), [ self.rrset_update_a ])
  778. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  779. isc.dns.Name("www.example.org"),
  780. RRType.A(),
  781. extended_a_rrset)
  782. # Now delete those two, and we should end up with the original RRset
  783. self.check_full_handle_result(Rcode.NOERROR(),
  784. [ self.rrset_update_del_rrset_part ])
  785. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  786. isc.dns.Name("www.example.org"),
  787. RRType.A(),
  788. self.orig_a_rrset)
  789. # 'Deleting' them again should make no difference
  790. self.check_full_handle_result(Rcode.NOERROR(),
  791. [ self.rrset_update_del_rrset_part ])
  792. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  793. isc.dns.Name("www.example.org"),
  794. RRType.A(),
  795. self.orig_a_rrset)
  796. # But deleting the entire rrset, independent of its contents, should
  797. # work
  798. self.check_full_handle_result(Rcode.NOERROR(),
  799. [ self.rrset_update_del_rrset ])
  800. self.__check_inzone_data(isc.datasrc.ZoneFinder.NXDOMAIN,
  801. isc.dns.Name("www.example.org"),
  802. RRType.A())
  803. # Check that if we update the SOA, it is updated to our value
  804. self.check_full_handle_result(Rcode.NOERROR(),
  805. [ self.rrset_update_soa2 ])
  806. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  807. isc.dns.Name("example.org"),
  808. RRType.SOA(),
  809. self.rrset_update_soa2)
  810. def test_glue_deletions(self):
  811. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  812. isc.dns.Name("sub.example.org."),
  813. RRType.NS())
  814. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  815. isc.dns.Name("ns.sub.example.org."),
  816. RRType.A())
  817. # See that we can delete glue
  818. rrset_delete_glue = create_rrset("ns.sub.example.org.",
  819. RRClass.ANY(),
  820. RRType.A(),
  821. 0)
  822. self.check_full_handle_result(Rcode.NOERROR(),
  823. [ rrset_delete_glue ])
  824. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  825. isc.dns.Name("sub.example.org."),
  826. RRType.NS())
  827. self.__check_inzone_data(isc.datasrc.ZoneFinder.NXDOMAIN,
  828. isc.dns.Name("ns.sub.example.org."),
  829. RRType.A())
  830. # Check that we don't accidentally delete a delegation if we
  831. # try to delete non-existent glue
  832. rrset_delete_nonexistent_glue = create_rrset("foo.sub.example.org.",
  833. RRClass.ANY(),
  834. RRType.A(),
  835. 0)
  836. self.check_full_handle_result(Rcode.NOERROR(),
  837. [ rrset_delete_nonexistent_glue ])
  838. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  839. isc.dns.Name("sub.example.org."),
  840. RRType.NS())
  841. def test_update_add_new_data(self):
  842. '''
  843. This tests adds data where none is present
  844. '''
  845. # Add data at a completely new name
  846. self.__check_inzone_data(isc.datasrc.ZoneFinder.NXDOMAIN,
  847. isc.dns.Name("new.example.org"),
  848. RRType.A())
  849. rrset = create_rrset("new.example.org", TEST_RRCLASS, RRType.A(),
  850. 3600, [ "192.0.2.1", "192.0.2.2" ])
  851. self.check_full_handle_result(Rcode.NOERROR(), [ rrset ])
  852. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  853. isc.dns.Name("new.example.org"),
  854. RRType.A(),
  855. rrset)
  856. # Also try a name where data is present, but none of this
  857. # specific type
  858. self.__check_inzone_data(isc.datasrc.ZoneFinder.NXRRSET,
  859. isc.dns.Name("new.example.org"),
  860. RRType.TXT())
  861. rrset = create_rrset("new.example.org", TEST_RRCLASS, RRType.TXT(),
  862. 3600, [ "foo" ])
  863. self.check_full_handle_result(Rcode.NOERROR(), [ rrset ])
  864. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  865. isc.dns.Name("new.example.org"),
  866. RRType.TXT(),
  867. rrset)
  868. def test_update_add_new_data_interspersed(self):
  869. '''
  870. This tests adds data where none is present, similar to
  871. test_update_add_new_data, but this time the second RRset
  872. is put into the record between the two RRs of the first
  873. RRset.
  874. '''
  875. # Add data at a completely new name
  876. self.__check_inzone_data(isc.datasrc.ZoneFinder.NXDOMAIN,
  877. isc.dns.Name("new_a.example.org"),
  878. RRType.A())
  879. self.__check_inzone_data(isc.datasrc.ZoneFinder.NXDOMAIN,
  880. isc.dns.Name("new_txt.example.org"),
  881. RRType.TXT())
  882. rrset1 = create_rrset("new_a.example.org", TEST_RRCLASS, RRType.A(),
  883. 3600, [ "192.0.2.1" ])
  884. rrset2 = create_rrset("new_txt.example.org", TEST_RRCLASS, RRType.TXT(),
  885. 3600, [ "foo" ])
  886. rrset3 = create_rrset("new_a.example.org", TEST_RRCLASS, RRType.A(),
  887. 3600, [ "192.0.2.2" ])
  888. self.check_full_handle_result(Rcode.NOERROR(),
  889. [ rrset1, rrset2, rrset3 ])
  890. # The update should have merged rrset1 and rrset3
  891. rrset_merged = create_rrset("new_a.example.org", TEST_RRCLASS,
  892. RRType.A(), 3600,
  893. [ "192.0.2.1", "192.0.2.2" ])
  894. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  895. isc.dns.Name("new_a.example.org"),
  896. RRType.A(),
  897. rrset_merged)
  898. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  899. isc.dns.Name("new_txt.example.org"),
  900. RRType.TXT(),
  901. rrset2)
  902. def test_update_delete_name(self):
  903. self.__initialize_update_rrsets()
  904. # First check it is there
  905. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  906. isc.dns.Name("www.example.org"),
  907. RRType.A())
  908. # Delete the entire name
  909. self.check_full_handle_result(Rcode.NOERROR(),
  910. [ self.rrset_update_del_name ])
  911. self.__check_inzone_data(isc.datasrc.ZoneFinder.NXDOMAIN,
  912. isc.dns.Name("www.example.org"),
  913. RRType.A())
  914. # Should still be gone after pointless second delete
  915. self.check_full_handle_result(Rcode.NOERROR(),
  916. [ self.rrset_update_del_name ])
  917. self.__check_inzone_data(isc.datasrc.ZoneFinder.NXDOMAIN,
  918. isc.dns.Name("www.example.org"),
  919. RRType.A())
  920. def test_update_apex_special_cases(self):
  921. '''
  922. Tests a few special cases when deleting data from the apex
  923. '''
  924. self.__initialize_update_rrsets()
  925. # the original SOA
  926. orig_soa_rrset = create_rrset("example.org", TEST_RRCLASS,
  927. RRType.SOA(), 3600,
  928. [ "ns1.example.org. " +
  929. "admin.example.org. " +
  930. "1234 3600 1800 2419200 7200" ])
  931. # We will delete some of the NS records
  932. orig_ns_rrset = create_rrset("example.org", TEST_RRCLASS,
  933. RRType.NS(), 3600,
  934. [ "ns1.example.org.",
  935. "ns2.example.org.",
  936. "ns3.example.org." ])
  937. # Sanity check, make sure original data is really there before updates
  938. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  939. isc.dns.Name("example.org"),
  940. RRType.NS(),
  941. orig_ns_rrset)
  942. # We will delete the MX record later in this test, so let's make
  943. # sure that it exists (we do not care about its value)
  944. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  945. isc.dns.Name("example.org"),
  946. RRType.MX())
  947. # Check that we cannot delete the SOA record by direction deletion
  948. # both by name+type and by full rrset
  949. self.check_full_handle_result(Rcode.NOERROR(),
  950. [ self.rrset_update_del_soa_apex,
  951. self.rrset_update_soa_del ])
  952. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  953. isc.dns.Name("example.org"),
  954. RRType.SOA(),
  955. orig_soa_rrset)
  956. # If we delete everything at the apex, the SOA and NS rrsets should be
  957. # untouched
  958. self.check_full_handle_result(Rcode.NOERROR(),
  959. [ self.rrset_update_del_name_apex ])
  960. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  961. isc.dns.Name("example.org"),
  962. RRType.SOA(),
  963. orig_soa_rrset)
  964. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  965. isc.dns.Name("example.org"),
  966. RRType.NS(),
  967. orig_ns_rrset)
  968. # but the MX should be gone
  969. self.__check_inzone_data(isc.datasrc.ZoneFinder.NXRRSET,
  970. isc.dns.Name("example.org"),
  971. RRType.MX())
  972. # Deleting the NS rrset by name and type only, it should also be left
  973. # untouched
  974. self.check_full_handle_result(Rcode.NOERROR(),
  975. [ self.rrset_update_del_ns_apex ])
  976. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  977. isc.dns.Name("example.org"),
  978. RRType.NS(),
  979. orig_ns_rrset)
  980. def DISABLED_test_update_apex_special_case_ns_rrset(self):
  981. # If we delete the NS at the apex specifically, it should still
  982. # keep one record
  983. self.__initialize_update_rrsets()
  984. # When we are done, we should have a reduced NS rrset
  985. short_ns_rrset = create_rrset("example.org", TEST_RRCLASS,
  986. RRType.NS(), 3600,
  987. [ "ns3.example.org." ])
  988. self.check_full_handle_result(Rcode.NOERROR(),
  989. [ self.rrset_update_del_rrset_ns ])
  990. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  991. isc.dns.Name("example.org"),
  992. RRType.NS(),
  993. short_ns_rrset)
  994. def test_update_delete_normal_rrset_at_apex(self):
  995. '''
  996. Tests a number of 'normal rrset' deletes at the apex
  997. '''
  998. # MX should simply be deleted
  999. self.__initialize_update_rrsets()
  1000. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  1001. isc.dns.Name("example.org"),
  1002. RRType.MX())
  1003. self.check_full_handle_result(Rcode.NOERROR(),
  1004. [ self.rrset_update_del_rrset_mx ])
  1005. self.__check_inzone_data(isc.datasrc.ZoneFinder.NXRRSET,
  1006. isc.dns.Name("example.org"),
  1007. RRType.MX())
  1008. def test_update_cname_special_cases(self):
  1009. self.__initialize_update_rrsets()
  1010. # Sanity check
  1011. orig_cname_rrset = create_rrset("cname.example.org", TEST_RRCLASS,
  1012. RRType.CNAME(), 3600,
  1013. [ "www.example.org." ])
  1014. self.__check_inzone_data(isc.datasrc.ZoneFinder.CNAME,
  1015. isc.dns.Name("cname.example.org"),
  1016. RRType.A(),
  1017. orig_cname_rrset)
  1018. # If we try to add data where a cname is preset
  1019. rrset = create_rrset("cname.example.org", TEST_RRCLASS, RRType.A(),
  1020. 3600, [ "192.0.2.1" ])
  1021. self.check_full_handle_result(Rcode.NOERROR(), [ rrset ])
  1022. self.__check_inzone_data(isc.datasrc.ZoneFinder.CNAME,
  1023. isc.dns.Name("cname.example.org"),
  1024. RRType.A(),
  1025. orig_cname_rrset)
  1026. # But updating the cname itself should work
  1027. new_cname_rrset = create_rrset("cname.example.org", TEST_RRCLASS,
  1028. RRType.CNAME(), 3600,
  1029. [ "mail.example.org." ])
  1030. self.check_full_handle_result(Rcode.NOERROR(), [ new_cname_rrset ])
  1031. self.__check_inzone_data(isc.datasrc.ZoneFinder.CNAME,
  1032. isc.dns.Name("cname.example.org"),
  1033. RRType.A(),
  1034. new_cname_rrset)
  1035. self.__initialize_update_rrsets()
  1036. # Likewise, adding a cname where other data is
  1037. # present should do nothing either
  1038. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  1039. isc.dns.Name("www.example.org"),
  1040. RRType.A(),
  1041. self.orig_a_rrset)
  1042. new_cname_rrset = create_rrset("www.example.org", TEST_RRCLASS,
  1043. RRType.CNAME(), 3600,
  1044. [ "mail.example.org." ])
  1045. self.check_full_handle_result(Rcode.NOERROR(), [ new_cname_rrset ])
  1046. self.__check_inzone_data(isc.datasrc.ZoneFinder.SUCCESS,
  1047. isc.dns.Name("www.example.org"),
  1048. RRType.A(),
  1049. self.orig_a_rrset)
  1050. def test_update_bad_class(self):
  1051. rrset = create_rrset("example.org.", RRClass.CH(), RRType.TXT(), 0,
  1052. [ "foo" ])
  1053. self.check_full_handle_result(Rcode.FORMERR(), [ rrset ])
  1054. def test_uncaught_exception(self):
  1055. def my_exc():
  1056. raise Exception("foo")
  1057. self._session._UpdateSession__update_soa = my_exc
  1058. self.assertEqual(Rcode.SERVFAIL().to_text(),
  1059. self._session._UpdateSession__do_update().to_text())
  1060. class SessionACLTest(SessionTestBase):
  1061. '''ACL related tests for update session.'''
  1062. def test_update_acl_check(self):
  1063. '''Test for various ACL checks.
  1064. Note that accepted cases are covered in the basic tests.
  1065. '''
  1066. # create a separate session, with default (empty) ACL map.
  1067. session = UpdateSession(self._update_msg,
  1068. TEST_CLIENT4, ZoneConfig([], TEST_RRCLASS,
  1069. self._datasrc_client))
  1070. # then the request should be rejected.
  1071. self.assertEqual((UPDATE_ERROR, None, None), session.handle())
  1072. # recreate the request message, and test with an ACL that would result
  1073. # in 'DROP'. get_message() should return None.
  1074. msg = create_update_msg()
  1075. acl_map = {(TEST_ZONE_NAME, TEST_RRCLASS):
  1076. REQUEST_LOADER.load([{"action": "DROP", "from":
  1077. TEST_CLIENT4[0]}])}
  1078. session = UpdateSession(msg, TEST_CLIENT4,
  1079. ZoneConfig([], TEST_RRCLASS,
  1080. self._datasrc_client, acl_map))
  1081. self.assertEqual((UPDATE_DROP, None, None), session.handle())
  1082. self.assertEqual(None, session.get_message())
  1083. def test_update_tsigacl_check(self):
  1084. '''Test for various ACL checks using TSIG.'''
  1085. # This ACL will accept requests from TEST_CLIENT4 (any port) *and*
  1086. # has TSIG signed by TEST_ZONE_NAME; all others will be rejected.
  1087. acl_map = {(TEST_ZONE_NAME, TEST_RRCLASS):
  1088. REQUEST_LOADER.load([{"action": "ACCEPT",
  1089. "from": TEST_CLIENT4[0],
  1090. "key": TEST_ZONE_NAME.to_text()}])}
  1091. # If the message doesn't contain TSIG, it doesn't match the ACCEPT
  1092. # ACL entry, and the request should be rejected.
  1093. session = UpdateSession(self._update_msg,
  1094. TEST_CLIENT4, ZoneConfig([], TEST_RRCLASS,
  1095. self._datasrc_client,
  1096. acl_map))
  1097. self.assertEqual((UPDATE_ERROR, None, None), session.handle())
  1098. self.check_response(session.get_message(), Rcode.REFUSED())
  1099. # If the message contains TSIG, it should match the ACCEPT
  1100. # ACL entry, and the request should be granted.
  1101. session = UpdateSession(create_update_msg(tsig_key=TEST_TSIG_KEY),
  1102. TEST_CLIENT4, ZoneConfig([], TEST_RRCLASS,
  1103. self._datasrc_client,
  1104. acl_map))
  1105. self.assertEqual((UPDATE_SUCCESS, TEST_ZONE_NAME, TEST_RRCLASS),
  1106. session.handle())
  1107. if __name__ == "__main__":
  1108. isc.log.init("bind10")
  1109. isc.log.resetUnitTestRootLogger()
  1110. unittest.main()