From nobody Mon Jul 6 12:24:26 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4gv3Sq1sB4z6jRwC for ; Mon, 06 Jul 2026 12:24:27 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR1" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4gv3Sp4yXgz3gS8 for ; Mon, 06 Jul 2026 12:24:26 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1783340666; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=jKeqcgDNcpFOsssbRSeNwfdgo/LM90dlMd0n+U+gPvs=; b=mrQMPlUAWJTr4C6tUa2E05hE5ygKiV/D87psuSa+ertqft/sci+4wgcivwe7TNXOoE7Uzy DIjCmudh8v6DAYfvb1PFLq1ktIncWQjupQGA6vWPitAbwyYSrRw2/NMrD8/Eu6CxTOkkAc riVYcp7vjgKoUFW3aJkr3ZKYgQxYPunqalg22+g0AvAq60p+lH7uqcjj3wUt8fcHgbYxLX h1gsQyRiYGGsPuseRaUu0LtXb9MwO0dCfD6bmAqZRW5zLrgDez4iL++QHoqcjim2leyV3w GhDqBpH4BisT3ie/nF7OSPL6IJm+jkEOsqa/sTafDRdRrMHsWwnYZtxB2yX+XQ== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1783340666; a=rsa-sha256; cv=none; b=Ib4iw5Z5qhzZfYCDsc9UliA8vhuvXfYXQdUBaTsey1RbXf7DDvJ4TBtPpIbfL8jW3JiUU2 OeDjpWEld+5ia/L5v4u/r9uQ+4REciKI72uY0kKdsULYOICDCY4da9PjuDfUppHQ6NWLur p3gHVJx1rFOD3IwEjDxRYK9EykpIOBbRKL3GBAvmXOTOz8wbCcNQRcxTXl4TGD5TlWXU6J PZDJ0BC/XcvywtzxlTDFWDGc2S3/b9wgDWT+0Rvr2hGswLjag5gYCciy4PTobYgpaRIhnj FnIJTEP6zvWDfIx+n8THJckmPuqlZnApy83Gu5cgpLz3si1Nn+z9KAMmBxHCjw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1783340666; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=jKeqcgDNcpFOsssbRSeNwfdgo/LM90dlMd0n+U+gPvs=; b=u7n5GjKwtde/59TQ05Wc4AsMstD/BMZn63uZ82kMq9nRiezVrBMBBfEIwnFlCq965kLsKI D4qUZqDGMEKHOKoPoVfGFOhpY1K3wB6ckVYfmKE5tLqoaRRIVy5w5gb2hC9p3sqqQbZwBH msDMS3HmZ+iPx9zonDwgnf0Ca4jS/O1RQrrhaeH3P45pb/BVBEc5FBn5X4b9SGgRv3DtUG rmQcVW40o86vuYUF/JRxyaW7XnOi/AL9FAMFLwF8p0TV4lMU1mq+tLBhjOI94UtXdtkYeE 7jvIiDfO6PEFWfgpKS0KKNv1MDSPgE2yplU8U2qkJCcdjKxPqIr79rJxxt6Wmg== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4gv3Sp3l6cz147Q for ; Mon, 06 Jul 2026 12:24:26 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 39ef7 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Mon, 06 Jul 2026 12:24:26 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Dag-Erling=?utf-8?Q? Sm=C3=B8rg?=rav Subject: git: 9bfdfecd2735 - main - libc/resolv: Refactor the option parser List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: des X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 9bfdfecd27359130aa4ef63fc0aa32f98f9e7b50 Auto-Submitted: auto-generated Date: Mon, 06 Jul 2026 12:24:26 +0000 Message-Id: <6a4b9e7a.39ef7.5ff4d111@gitrepo.freebsd.org> The branch main has been updated by des: URL: https://cgit.FreeBSD.org/src/commit/?id=9bfdfecd27359130aa4ef63fc0aa32f98f9e7b50 commit 9bfdfecd27359130aa4ef63fc0aa32f98f9e7b50 Author: Dag-Erling Smørgrav AuthorDate: 2026-07-06 12:23:29 +0000 Commit: Dag-Erling Smørgrav CommitDate: 2026-07-06 12:23:29 +0000 libc/resolv: Refactor the option parser Start the loop by finding the end of the option name, the name-value separator (if any), and the end of the option. Use those pointers to simplify matching the option name and parsing the option value, and validate option names and values more strictly. This means that: * We no longer accept trailing garbage in an option name or value. For instance, we would previously interpret “edns0123” as “edns0” and “timeout:3xyz” as “timeout:3”. This was actually quite lucky because we also failed to recognize the newline at the end of the option line as a whitespace character. * For options that take a numerical argument, we would previously accept negative values and treat non-numerical arguments as 0, while large numerical arguments would be capped to the option's maximum permitted value. Now, any failure to parse the argument, including overflow, results in the option being left unchanged. MFC after: 1 week Relnotes: yes Reviewed by: markj Differential Revision: https://reviews.freebsd.org/D57923 --- lib/libc/resolv/res_init.c | 194 ++++++++++++++++++++++++--------------------- 1 file changed, 105 insertions(+), 89 deletions(-) diff --git a/lib/libc/resolv/res_init.c b/lib/libc/resolv/res_init.c index e9e982fe27bb..4cddb3b0b72a 100644 --- a/lib/libc/resolv/res_init.c +++ b/lib/libc/resolv/res_init.c @@ -3,6 +3,7 @@ * * Copyright (c) 1985, 1989, 1993 * The Regents of the University of California. All rights reserved. + * Copyright (c) 2026 Dag-Erling Smørgrav * * Redistribution and use in source and binary forms, with or without * modification, are permitted provided that the following conditions @@ -80,6 +81,7 @@ #include #include +#include #include #include #include @@ -103,9 +105,11 @@ static const char sort_mask[] = "/&"; static u_int32_t net_mask(struct in_addr); #endif -#if !defined(isascii) /*%< XXX - could be a function */ -# define isascii(c) (!(c & 0200)) -#endif +#define res_space(ch) \ + isspace((unsigned char)(ch)) +#define res_match(str, end, word) \ + (strncmp((str), (word), (end) - (str)) == 0 && \ + (word)[(end) - (str)] == '\0') /* * Resolver state default settings. @@ -520,129 +524,141 @@ __res_vinit(res_state statp, int preinit) { static void res_setoptions(res_state statp, const char *options, const char *source) { - const char *cp = options; - int i; + const char *cp = options, *sp, *ep; + char *numend; + long num; struct __res_state_ext *ext = statp->_u._ext.ext; #ifdef DEBUG - if (statp->options & RES_DEBUG) + if (statp->options & RES_DEBUG) { printf(";; res_setoptions(\"%s\", \"%s\")...\n", options, source); + } #endif - while (*cp) { + for (;;) { /* skip leading and inner runs of spaces */ - while (*cp == ' ' || *cp == '\t') + while (res_space(*cp)) cp++; + /* find the separator if there is one */ + sp = cp; + while (*sp != '\0' && !res_space(*sp) && *sp != ':') + sp++; + /* find the end of the option */ + ep = sp; + while (*ep != '\0' && !res_space(*ep)) + ep++; + /* end of option line */ + if (ep == cp) + break; /* search for and process individual options */ - if (!strncmp(cp, "ndots:", sizeof("ndots:") - 1)) { - i = atoi(cp + sizeof("ndots:") - 1); - if (i <= RES_MAXNDOTS) - statp->ndots = i; - else - statp->ndots = RES_MAXNDOTS; + /* note: sp < ep if implies *sp == ':' */ + if (res_match(cp, sp, "ndots") && sp < ep) { + num = strtol(sp + 1, &numend, 10); + if (numend == ep && num >= 0 && num <= RES_MAXNDOTS) { + statp->ndots = num; #ifdef DEBUG - if (statp->options & RES_DEBUG) - printf(";;\tndots=%d\n", statp->ndots); + if (statp->options & RES_DEBUG) + printf(";;\tndots=%d\n", statp->ndots); #endif - } else if (!strncmp(cp, "timeout:", sizeof("timeout:") - 1)) { - i = atoi(cp + sizeof("timeout:") - 1); - if (i <= RES_MAXRETRANS) - statp->retrans = i; - else - statp->retrans = RES_MAXRETRANS; + } + } else if (res_match(cp, sp, "timeout") && sp < ep) { + num = strtol(sp + 1, &numend, 10); + if (numend == ep && num > 0 && num <= RES_MAXRETRANS) { + statp->retrans = num; #ifdef DEBUG - if (statp->options & RES_DEBUG) - printf(";;\ttimeout=%d\n", statp->retrans); + if (statp->options & RES_DEBUG) + printf(";;\ttimeout=%d\n", + statp->retrans); #endif - } else if (!strncmp(cp, "attempts:", sizeof("attempts:") - 1)){ - i = atoi(cp + sizeof("attempts:") - 1); - if (i <= RES_MAXRETRY) - statp->retry = i; - else - statp->retry = RES_MAXRETRY; + } + } else if (res_match(cp, sp, "attempts") && sp < ep) { + num = strtol(sp + 1, &numend, 10); + if (numend == ep && num > 0 && num <= RES_MAXRETRY) { + statp->retry = num; #ifdef DEBUG - if (statp->options & RES_DEBUG) - printf(";;\tattempts=%d\n", statp->retry); + if (statp->options & RES_DEBUG) + printf(";;\tattempts=%d\n", + statp->retry); #endif - } else if (!strncmp(cp, "debug", sizeof("debug") - 1)) { + } + } else if (res_match(cp, ep, "debug")) { #ifdef DEBUG if (!(statp->options & RES_DEBUG)) { printf(";; res_setoptions(\"%s\", \"%s\")..\n", options, source); - statp->options |= RES_DEBUG; } +#endif + statp->options |= RES_DEBUG; +#ifdef DEBUG printf(";;\tdebug\n"); #endif - } else if (!strncmp(cp, "no_tld_query", - sizeof("no_tld_query") - 1) || - !strncmp(cp, "no-tld-query", - sizeof("no-tld-query") - 1)) { + } else if (res_match(cp, ep, "no-tld-query") || + res_match(cp, ep, "no_tld_query")) { statp->options |= RES_NOTLDQUERY; - } else if (!strncmp(cp, "inet6", sizeof("inet6") - 1)) { + } else if (res_match(cp, ep, "inet6")) { statp->options |= RES_USE_INET6; - } else if (!strncmp(cp, "insecure1", sizeof("insecure1") - 1)) { - statp->options |= RES_INSECURE1; - } else if (!strncmp(cp, "insecure2", sizeof("insecure2") - 1)) { - statp->options |= RES_INSECURE2; - } else if (!strncmp(cp, "rotate", sizeof("rotate") - 1)) { + } else if (res_match(cp, ep, "insecure1")) { + statp->options |= RES_INSECURE1; + } else if (res_match(cp, ep, "insecure2")) { + statp->options |= RES_INSECURE2; + } else if (res_match(cp, ep, "blast")) { + statp->options |= RES_BLAST; + } else if (res_match(cp, ep, "rotate")) { statp->options |= RES_ROTATE; - } else if (!strncmp(cp, "usevc", sizeof("usevc") - 1)) { + } else if (res_match(cp, ep, "usevc")) { statp->options |= RES_USEVC; - } else if (!strncmp(cp, "no-check-names", - sizeof("no-check-names") - 1)) { + } else if (res_match(cp, ep, "no-check-names")) { statp->options |= RES_NOCHECKNAME; - } else if (!strncmp(cp, "reload-period:", - sizeof("reload-period:") - 1)) { - if (ext != NULL) { - ext->reload_period = (u_short) - atoi(cp + sizeof("reload-period:") - 1); + } else if (res_match(cp, sp, "reload-period") && sp < ep) { + num = strtol(sp + 1, &numend, 10); + if (numend == ep && num > 0 && num <= USHRT_MAX) { + if (ext != NULL) + ext->reload_period = (u_short)num; +#ifdef DEBUG + if (statp->options & RES_DEBUG) + printf(";;\treload-period %hu\n", + (u_short)num); +#endif } - } #ifdef RES_USE_EDNS0 - else if (!strncmp(cp, "edns0", sizeof("edns0") - 1)) { + } else if (res_match(cp, ep, "edns0")) { statp->options |= RES_USE_EDNS0; - } #endif #ifndef _LIBC - else if (!strncmp(cp, "dname", sizeof("dname") - 1)) { + } else if (res_match(cp, ep, "dname")) { statp->options |= RES_USE_DNAME; - } - else if (!strncmp(cp, "nibble:", sizeof("nibble:") - 1)) { - if (ext == NULL) - goto skip; - cp += sizeof("nibble:") - 1; - i = MIN(strcspn(cp, " \t"), sizeof(ext->nsuffix) - 1); - strncpy(ext->nsuffix, cp, i); - ext->nsuffix[i] = '\0'; - } - else if (!strncmp(cp, "nibble2:", sizeof("nibble2:") - 1)) { - if (ext == NULL) - goto skip; - cp += sizeof("nibble2:") - 1; - i = MIN(strcspn(cp, " \t"), sizeof(ext->nsuffix2) - 1); - strncpy(ext->nsuffix2, cp, i); - ext->nsuffix2[i] = '\0'; - } - else if (!strncmp(cp, "v6revmode:", sizeof("v6revmode:") - 1)) { - cp += sizeof("v6revmode:") - 1; + } else if (res_match(cp, sp, "nibble") && sp < ep) { + sp++; + if (ext != NULL && ep - sp < sizeof(ext->nsuffix)) { + memcpy(ext->nsuffix, sp, ep - sp); + ext->nsuffix[ep - sp] = '\0'; + } + } else if (res_match(cp, sp, "nibble2") && sp < ep) { + sp++; + if (ext != NULL && ep - sp < sizeof(ext->nsuffix2)) { + memcpy(ext->nsuffix2, sp, ep - sp); + ext->nsuffix2[ep - sp] = '\0'; + } + } else if (res_match(cp, sp, "v6revmode") && sp < ep) { /* "nibble" and "bitstring" used to be valid */ - if (!strncmp(cp, "single", sizeof("single") - 1)) { + if (res_match(sp + 1, ep, "single")) statp->options |= RES_NO_NIBBLE2; - } else if (!strncmp(cp, "both", sizeof("both") - 1)) { - statp->options &= - ~RES_NO_NIBBLE2; - } - } + else if (res_match(sp + 1, ep, "both")) + statp->options &= ~RES_NO_NIBBLE2; +#ifdef DEBUG + else + printf(";;\t%.*s: unrecognized value: %.*s\n", + (int)(sp - cp), cp, + (int)(ep - sp - 1), sp + 1); #endif - else { - /* XXX - print a warning here? */ - } -#ifndef _LIBC - skip: +#endif /* !_LIBC */ + } else { +#ifdef DEBUG + printf(";;\tunrecognized option: %.*s\n", + (int)(ep - cp), cp); #endif - /* skip to next run of spaces */ - while (*cp && *cp != ' ' && *cp != '\t') - cp++; + } + cp = ep; } }