From nobody Tue Jul 21 08:56:34 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4h4B825Mq9z6lc8D for ; Tue, 21 Jul 2026 08:56:34 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR1" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4h4B822tMGz3chC for ; Tue, 21 Jul 2026 08:56:34 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1784624194; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=pNHUy99g7JN7K/hIj5rqU/7GtaVA0q751Wa3KxToEtE=; b=wumSEnG0AbrTFaMar0v8kQhsE5T8ug9iAKrRf8mwsFtwyBF21xryUNeVNeIcZa8ufks3iN bv5aLrsmL2u9CEL7vn8pQTdZN+HAbnICtyP6g+Szwj9jLNNQKR5gZkgWBLv9Al5H3c8HBs FSWqha6lpHFgLSJgm7iui2sCBtwhHWx4nCg2WvF5d0COh+pJdorEdq4WTl1NX8SsJdFV8+ U1oe4Hh2yle0IXruLPxbHwEmzXTH8WvZ0mLjWkQd0BuWpauHFghQ2+5ho0Wx/rnKHIoES8 DPygHRC+ZTUgHiahYUw2kYJtIC3gEXCMo+UGRd4xKWZWS9dOa8tsMeSBWSwWrw== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1784624194; a=rsa-sha256; cv=none; b=fhOetym3N/PlPaW05YscUVfNVEwYg/Wgayb1qCvJs+Vp8UdNc/glLFc9InmDPkty0h5Qir oedJE2Fg8xFTJq4oHuUdwQVq3oT7FN2GyMR0gY7F5E3fFNrcG1b9WlDC4PrJNMkB5SyQaP oGGqhk8qsZVblFkutSZHf/mxCnhSRR/gIh2qnZ8gbIa/lFLAEQIF5rfk7mOxGo6Z3pD9pD TzHlY1ugQLDQncA6wairykb6wj8QJJy7XNzJ0Z0AoVDI1F0gb6N6NZBNkENOqOdi2fQEjy nQsvHxrn4NQeL2IRJ/bZz/xX2DFIWB7UGhKgDNmY/isOSK15qpOhpINefqB7sw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1784624194; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=pNHUy99g7JN7K/hIj5rqU/7GtaVA0q751Wa3KxToEtE=; b=llyfdVUC95+2kp/Mycq3C/foEJJwfoeuuqBNbikyuv9q1zoEBwj1Tf7b3GxTkqS40IO+EF 9Sw9iJdCLC1Ep/albeYhw5uHKg3Zk6XFozNnhZAb5WSAYG/qR1bqfo9JRvHmI+LKGNH1Ks eXw9LrMSXpQoRNSDcD+fTvT0WHWed9b4aSB+YfMLJ6AFrnRvuPD/YxwZZFaN59tKTqOw9P Kc7Rdvz7B6wInQZ8wPHS+UZ9zTxZsAMn3FEnLPbkJogzvVhi5S86P3CG5v5vtbrny77Wjs 1cS35NWxvGksAgr+aMovjSp12k9QXD+GN/fROyYBkk8QqCMCL3gZoq5v3LtSUA== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4h4B821ZsJzj10 for ; Tue, 21 Jul 2026 08:56:34 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 22a09 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Tue, 21 Jul 2026 08:56:34 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Dag-Erling=?utf-8?Q? Sm=C3=B8rg?=rav Subject: git: 491337c8a21a - stable/15 - libc/resolv: Refactor the option parser List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: des X-Git-Repository: src X-Git-Refname: refs/heads/stable/15 X-Git-Reftype: branch X-Git-Commit: 491337c8a21abf120661db6bc5727474c247e184 Auto-Submitted: auto-generated Date: Tue, 21 Jul 2026 08:56:34 +0000 Message-Id: <6a5f3442.22a09.e4de0b2@gitrepo.freebsd.org> The branch stable/15 has been updated by des: URL: https://cgit.FreeBSD.org/src/commit/?id=491337c8a21abf120661db6bc5727474c247e184 commit 491337c8a21abf120661db6bc5727474c247e184 Author: Dag-Erling Smørgrav AuthorDate: 2026-07-06 12:23:29 +0000 Commit: Dag-Erling Smørgrav CommitDate: 2026-07-21 08:54:41 +0000 libc/resolv: Refactor the option parser Start the loop by finding the end of the option name, the name-value separator (if any), and the end of the option. Use those pointers to simplify matching the option name and parsing the option value, and validate option names and values more strictly. This means that: * We no longer accept trailing garbage in an option name or value. For instance, we would previously interpret “edns0123” as “edns0” and “timeout:3xyz” as “timeout:3”. This was actually quite lucky because we also failed to recognize the newline at the end of the option line as a whitespace character. * For options that take a numerical argument, we would previously accept negative values and treat non-numerical arguments as 0, while large numerical arguments would be capped to the option's maximum permitted value. Now, any failure to parse the argument, including overflow, results in the option being left unchanged. MFC after: 1 week Relnotes: yes Reviewed by: markj Differential Revision: https://reviews.freebsd.org/D57923 (cherry picked from commit 9bfdfecd27359130aa4ef63fc0aa32f98f9e7b50) --- lib/libc/resolv/res_init.c | 194 ++++++++++++++++++++++++--------------------- 1 file changed, 105 insertions(+), 89 deletions(-) diff --git a/lib/libc/resolv/res_init.c b/lib/libc/resolv/res_init.c index e9e982fe27bb..4cddb3b0b72a 100644 --- a/lib/libc/resolv/res_init.c +++ b/lib/libc/resolv/res_init.c @@ -3,6 +3,7 @@ * * Copyright (c) 1985, 1989, 1993 * The Regents of the University of California. All rights reserved. + * Copyright (c) 2026 Dag-Erling Smørgrav * * Redistribution and use in source and binary forms, with or without * modification, are permitted provided that the following conditions @@ -80,6 +81,7 @@ #include #include +#include #include #include #include @@ -103,9 +105,11 @@ static const char sort_mask[] = "/&"; static u_int32_t net_mask(struct in_addr); #endif -#if !defined(isascii) /*%< XXX - could be a function */ -# define isascii(c) (!(c & 0200)) -#endif +#define res_space(ch) \ + isspace((unsigned char)(ch)) +#define res_match(str, end, word) \ + (strncmp((str), (word), (end) - (str)) == 0 && \ + (word)[(end) - (str)] == '\0') /* * Resolver state default settings. @@ -520,129 +524,141 @@ __res_vinit(res_state statp, int preinit) { static void res_setoptions(res_state statp, const char *options, const char *source) { - const char *cp = options; - int i; + const char *cp = options, *sp, *ep; + char *numend; + long num; struct __res_state_ext *ext = statp->_u._ext.ext; #ifdef DEBUG - if (statp->options & RES_DEBUG) + if (statp->options & RES_DEBUG) { printf(";; res_setoptions(\"%s\", \"%s\")...\n", options, source); + } #endif - while (*cp) { + for (;;) { /* skip leading and inner runs of spaces */ - while (*cp == ' ' || *cp == '\t') + while (res_space(*cp)) cp++; + /* find the separator if there is one */ + sp = cp; + while (*sp != '\0' && !res_space(*sp) && *sp != ':') + sp++; + /* find the end of the option */ + ep = sp; + while (*ep != '\0' && !res_space(*ep)) + ep++; + /* end of option line */ + if (ep == cp) + break; /* search for and process individual options */ - if (!strncmp(cp, "ndots:", sizeof("ndots:") - 1)) { - i = atoi(cp + sizeof("ndots:") - 1); - if (i <= RES_MAXNDOTS) - statp->ndots = i; - else - statp->ndots = RES_MAXNDOTS; + /* note: sp < ep if implies *sp == ':' */ + if (res_match(cp, sp, "ndots") && sp < ep) { + num = strtol(sp + 1, &numend, 10); + if (numend == ep && num >= 0 && num <= RES_MAXNDOTS) { + statp->ndots = num; #ifdef DEBUG - if (statp->options & RES_DEBUG) - printf(";;\tndots=%d\n", statp->ndots); + if (statp->options & RES_DEBUG) + printf(";;\tndots=%d\n", statp->ndots); #endif - } else if (!strncmp(cp, "timeout:", sizeof("timeout:") - 1)) { - i = atoi(cp + sizeof("timeout:") - 1); - if (i <= RES_MAXRETRANS) - statp->retrans = i; - else - statp->retrans = RES_MAXRETRANS; + } + } else if (res_match(cp, sp, "timeout") && sp < ep) { + num = strtol(sp + 1, &numend, 10); + if (numend == ep && num > 0 && num <= RES_MAXRETRANS) { + statp->retrans = num; #ifdef DEBUG - if (statp->options & RES_DEBUG) - printf(";;\ttimeout=%d\n", statp->retrans); + if (statp->options & RES_DEBUG) + printf(";;\ttimeout=%d\n", + statp->retrans); #endif - } else if (!strncmp(cp, "attempts:", sizeof("attempts:") - 1)){ - i = atoi(cp + sizeof("attempts:") - 1); - if (i <= RES_MAXRETRY) - statp->retry = i; - else - statp->retry = RES_MAXRETRY; + } + } else if (res_match(cp, sp, "attempts") && sp < ep) { + num = strtol(sp + 1, &numend, 10); + if (numend == ep && num > 0 && num <= RES_MAXRETRY) { + statp->retry = num; #ifdef DEBUG - if (statp->options & RES_DEBUG) - printf(";;\tattempts=%d\n", statp->retry); + if (statp->options & RES_DEBUG) + printf(";;\tattempts=%d\n", + statp->retry); #endif - } else if (!strncmp(cp, "debug", sizeof("debug") - 1)) { + } + } else if (res_match(cp, ep, "debug")) { #ifdef DEBUG if (!(statp->options & RES_DEBUG)) { printf(";; res_setoptions(\"%s\", \"%s\")..\n", options, source); - statp->options |= RES_DEBUG; } +#endif + statp->options |= RES_DEBUG; +#ifdef DEBUG printf(";;\tdebug\n"); #endif - } else if (!strncmp(cp, "no_tld_query", - sizeof("no_tld_query") - 1) || - !strncmp(cp, "no-tld-query", - sizeof("no-tld-query") - 1)) { + } else if (res_match(cp, ep, "no-tld-query") || + res_match(cp, ep, "no_tld_query")) { statp->options |= RES_NOTLDQUERY; - } else if (!strncmp(cp, "inet6", sizeof("inet6") - 1)) { + } else if (res_match(cp, ep, "inet6")) { statp->options |= RES_USE_INET6; - } else if (!strncmp(cp, "insecure1", sizeof("insecure1") - 1)) { - statp->options |= RES_INSECURE1; - } else if (!strncmp(cp, "insecure2", sizeof("insecure2") - 1)) { - statp->options |= RES_INSECURE2; - } else if (!strncmp(cp, "rotate", sizeof("rotate") - 1)) { + } else if (res_match(cp, ep, "insecure1")) { + statp->options |= RES_INSECURE1; + } else if (res_match(cp, ep, "insecure2")) { + statp->options |= RES_INSECURE2; + } else if (res_match(cp, ep, "blast")) { + statp->options |= RES_BLAST; + } else if (res_match(cp, ep, "rotate")) { statp->options |= RES_ROTATE; - } else if (!strncmp(cp, "usevc", sizeof("usevc") - 1)) { + } else if (res_match(cp, ep, "usevc")) { statp->options |= RES_USEVC; - } else if (!strncmp(cp, "no-check-names", - sizeof("no-check-names") - 1)) { + } else if (res_match(cp, ep, "no-check-names")) { statp->options |= RES_NOCHECKNAME; - } else if (!strncmp(cp, "reload-period:", - sizeof("reload-period:") - 1)) { - if (ext != NULL) { - ext->reload_period = (u_short) - atoi(cp + sizeof("reload-period:") - 1); + } else if (res_match(cp, sp, "reload-period") && sp < ep) { + num = strtol(sp + 1, &numend, 10); + if (numend == ep && num > 0 && num <= USHRT_MAX) { + if (ext != NULL) + ext->reload_period = (u_short)num; +#ifdef DEBUG + if (statp->options & RES_DEBUG) + printf(";;\treload-period %hu\n", + (u_short)num); +#endif } - } #ifdef RES_USE_EDNS0 - else if (!strncmp(cp, "edns0", sizeof("edns0") - 1)) { + } else if (res_match(cp, ep, "edns0")) { statp->options |= RES_USE_EDNS0; - } #endif #ifndef _LIBC - else if (!strncmp(cp, "dname", sizeof("dname") - 1)) { + } else if (res_match(cp, ep, "dname")) { statp->options |= RES_USE_DNAME; - } - else if (!strncmp(cp, "nibble:", sizeof("nibble:") - 1)) { - if (ext == NULL) - goto skip; - cp += sizeof("nibble:") - 1; - i = MIN(strcspn(cp, " \t"), sizeof(ext->nsuffix) - 1); - strncpy(ext->nsuffix, cp, i); - ext->nsuffix[i] = '\0'; - } - else if (!strncmp(cp, "nibble2:", sizeof("nibble2:") - 1)) { - if (ext == NULL) - goto skip; - cp += sizeof("nibble2:") - 1; - i = MIN(strcspn(cp, " \t"), sizeof(ext->nsuffix2) - 1); - strncpy(ext->nsuffix2, cp, i); - ext->nsuffix2[i] = '\0'; - } - else if (!strncmp(cp, "v6revmode:", sizeof("v6revmode:") - 1)) { - cp += sizeof("v6revmode:") - 1; + } else if (res_match(cp, sp, "nibble") && sp < ep) { + sp++; + if (ext != NULL && ep - sp < sizeof(ext->nsuffix)) { + memcpy(ext->nsuffix, sp, ep - sp); + ext->nsuffix[ep - sp] = '\0'; + } + } else if (res_match(cp, sp, "nibble2") && sp < ep) { + sp++; + if (ext != NULL && ep - sp < sizeof(ext->nsuffix2)) { + memcpy(ext->nsuffix2, sp, ep - sp); + ext->nsuffix2[ep - sp] = '\0'; + } + } else if (res_match(cp, sp, "v6revmode") && sp < ep) { /* "nibble" and "bitstring" used to be valid */ - if (!strncmp(cp, "single", sizeof("single") - 1)) { + if (res_match(sp + 1, ep, "single")) statp->options |= RES_NO_NIBBLE2; - } else if (!strncmp(cp, "both", sizeof("both") - 1)) { - statp->options &= - ~RES_NO_NIBBLE2; - } - } + else if (res_match(sp + 1, ep, "both")) + statp->options &= ~RES_NO_NIBBLE2; +#ifdef DEBUG + else + printf(";;\t%.*s: unrecognized value: %.*s\n", + (int)(sp - cp), cp, + (int)(ep - sp - 1), sp + 1); #endif - else { - /* XXX - print a warning here? */ - } -#ifndef _LIBC - skip: +#endif /* !_LIBC */ + } else { +#ifdef DEBUG + printf(";;\tunrecognized option: %.*s\n", + (int)(ep - cp), cp); #endif - /* skip to next run of spaces */ - while (*cp && *cp != ' ' && *cp != '\t') - cp++; + } + cp = ep; } }