Route every zone seed through a fail-closed journal check
This commit is contained in:
+228
-12
@@ -2,10 +2,19 @@ package bind
|
||||
|
||||
import (
|
||||
"encoding/hex"
|
||||
"os"
|
||||
"os/exec"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
// probeOut frames body the way zoneStateProbe does, so the parser is exercised
|
||||
// on realistic input.
|
||||
func probeOut(body ...string) string {
|
||||
return strings.Join(append(append([]string{probeBegin}, body...), probeEnd, ""), "\n")
|
||||
}
|
||||
|
||||
func journalHeader(magic string, begin, end uint32) []byte {
|
||||
b := make([]byte, 32)
|
||||
copy(b, magic)
|
||||
@@ -67,16 +76,18 @@ func TestParseJournalHeader(t *testing.T) {
|
||||
}
|
||||
|
||||
func TestParseZoneDiskState(t *testing.T) {
|
||||
out := strings.Join([]string{
|
||||
out := probeOut(
|
||||
"zonefile=1",
|
||||
"head<<",
|
||||
probeHeadOpen,
|
||||
"@ IN SOA ns. host. ( 5 300 60 1209600 60 )",
|
||||
">>head",
|
||||
probeHeadShut,
|
||||
"journal=1",
|
||||
"jnl=" + hex.EncodeToString(journalHeader(";BIND LOG V9.2\n", 3, 8)),
|
||||
"",
|
||||
}, "\n")
|
||||
st := parseZoneDiskState(out)
|
||||
"jnl="+hex.EncodeToString(journalHeader(";BIND LOG V9.2\n", 3, 8)),
|
||||
)
|
||||
st, ok := parseZoneDiskState(out)
|
||||
if !ok {
|
||||
t.Fatalf("well-formed probe rejected: %q", out)
|
||||
}
|
||||
if !st.ZoneFile || !st.ZoneSerialOK || st.ZoneSerial != 5 {
|
||||
t.Errorf("zone file state wrong: %+v", st)
|
||||
}
|
||||
@@ -84,9 +95,37 @@ func TestParseZoneDiskState(t *testing.T) {
|
||||
t.Errorf("journal state wrong: %+v", st)
|
||||
}
|
||||
|
||||
empty := parseZoneDiskState("zonefile=0\njournal=0\n")
|
||||
if empty.ZoneFile || empty.Journal {
|
||||
t.Errorf("empty state wrong: %+v", empty)
|
||||
empty, ok := parseZoneDiskState(probeOut("zonefile=0", "journal=0"))
|
||||
if !ok || empty.ZoneFile || empty.Journal {
|
||||
t.Errorf("empty state wrong: %+v (ok=%v)", empty, ok)
|
||||
}
|
||||
}
|
||||
|
||||
// A probe that returns nothing useful must not be read as "fresh install": the
|
||||
// shell exits 0 after its last printf and stderr is dropped on success, so a
|
||||
// missing tool or a truncated stream is otherwise invisible.
|
||||
func TestParseZoneDiskStateRejectsDegradedProbe(t *testing.T) {
|
||||
live := probeHeadOpen + "\n@ IN SOA ns. host. ( 5 300 60 1209600 60 )\n" + probeHeadShut
|
||||
cases := map[string]string{
|
||||
"empty output": "",
|
||||
"whitespace only": "\n\n",
|
||||
"no framing": "zonefile=0\njournal=0\n",
|
||||
"no terminator": probeBegin + "\nzonefile=0\njournal=0\n",
|
||||
"cut before zone file": probeBegin + "\n",
|
||||
"cut mid head": probeBegin + "\nzonefile=1\n" + probeHeadOpen + "\n@ IN SOA ns. host. ( 5",
|
||||
"cut after head": probeBegin + "\nzonefile=1\n" + live + "\n",
|
||||
"no zone declaration": probeOut("journal=0"),
|
||||
"no journal branch": probeOut("zonefile=1", live),
|
||||
"journal without hex": probeOut("zonefile=0", "journal=1"),
|
||||
"duplicate zone decl": probeOut("zonefile=0", "zonefile=1", "journal=0"),
|
||||
"header without file": probeOut("zonefile=0", "journal=0", "jnl=00"),
|
||||
}
|
||||
for name, out := range cases {
|
||||
// The zero state is a legitimate fresh install, so rejection has to
|
||||
// happen here: ZoneDiskState turns it into an error and nothing plans.
|
||||
if st, ok := parseZoneDiskState(out); ok {
|
||||
t.Errorf("%s: degraded probe accepted as %+v", name, st)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -216,8 +255,47 @@ func TestPlanSeedFreshInstallIdempotent(t *testing.T) {
|
||||
|
||||
func TestPlanSeedSerialWrap(t *testing.T) {
|
||||
st := ZoneDiskState{Journal: true, JournalBegin: 1 << 31, JournalEnd: 1<<32 - 1, JournalOK: true}
|
||||
if got := PlanSeed(st).Serial; got != 1 {
|
||||
t.Errorf("serial after wrap = %d want 1", got)
|
||||
if h, known := highestSerial(st); !known || h != 1<<32-1 {
|
||||
t.Fatalf("highestSerial = (%d,%v) want (%d,true): the wrap branch is not being reached", h, known, int64(1)<<32-1)
|
||||
}
|
||||
p := PlanSeed(st)
|
||||
if p.Serial != 1 {
|
||||
t.Fatalf("serial after wrap = %d want 1", p.Serial)
|
||||
}
|
||||
if !serialLT(st.JournalEnd, p.Serial) {
|
||||
t.Errorf("wrapped serial %d must still sort after journal end %d", p.Serial, st.JournalEnd)
|
||||
}
|
||||
}
|
||||
|
||||
// Serials above 2^31 must not be flattened to 1: RFC 1982 comparison against a
|
||||
// zero placeholder reads them as older, and secondaries reject the regression.
|
||||
func TestPlanSeedHighSerialJournal(t *testing.T) {
|
||||
st := ZoneDiskState{Journal: true, JournalBegin: 1<<31 - 10, JournalEnd: 1 << 31, JournalOK: true}
|
||||
p := PlanSeed(st)
|
||||
if !p.WriteSeed {
|
||||
t.Fatalf("orphan journal should still seed, got %+v", p)
|
||||
}
|
||||
if p.Serial != 1<<31+1 {
|
||||
t.Errorf("seed serial = %d want %d", p.Serial, int64(1)<<31+1)
|
||||
}
|
||||
if !serialLT(st.JournalEnd, p.Serial) {
|
||||
t.Errorf("seed serial %d must sort after journal end %d", p.Serial, st.JournalEnd)
|
||||
}
|
||||
if p.QuarantineSuffix != ".orphaned-2147483648" {
|
||||
t.Errorf("quarantine suffix = %q", p.QuarantineSuffix)
|
||||
}
|
||||
}
|
||||
|
||||
// An orphan journal whose header will not parse (no od, EACCES, short read)
|
||||
// hides how far the zone had advanced, so quarantining it and reseeding at 1
|
||||
// would regress live data.
|
||||
func TestPlanSeedBlocksOnUnreadableOrphanJournal(t *testing.T) {
|
||||
p := PlanSeed(ZoneDiskState{Journal: true})
|
||||
if p.Blocked == "" {
|
||||
t.Fatalf("an unreadable orphan journal must block, got %+v", p)
|
||||
}
|
||||
if p.WriteSeed || p.QuarantineJournal || p.QuarantineZoneFile {
|
||||
t.Errorf("a blocked plan must touch nothing, got %+v", p)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -242,3 +320,141 @@ func TestQuarantinePathsAreSuffixed(t *testing.T) {
|
||||
t.Errorf("quarantine must never delete: %s", cmd)
|
||||
}
|
||||
}
|
||||
|
||||
// A repeat incident computes the same suffix, so the rename must not overwrite
|
||||
// the copy preserved by the previous one.
|
||||
func TestMoveAsidePreservesEarlierQuarantine(t *testing.T) {
|
||||
sh, err := exec.LookPath("sh")
|
||||
if err != nil {
|
||||
t.Skipf("no POSIX shell: %v", err)
|
||||
}
|
||||
dir := t.TempDir()
|
||||
path := filepath.Join(dir, "db.example.com")
|
||||
|
||||
for _, content := range []string{"first", "second"} {
|
||||
if err := os.WriteFile(path, []byte(content), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
out, err := exec.Command(sh, "-c", moveAside(path, ".orphaned-16")).CombinedOutput()
|
||||
if err != nil {
|
||||
t.Fatalf("moveAside(%s): %v (%s)", content, err, out)
|
||||
}
|
||||
}
|
||||
|
||||
if _, err := os.Stat(path); err == nil {
|
||||
t.Error("the quarantined file should have been renamed away")
|
||||
}
|
||||
entries, err := os.ReadDir(dir)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
found := map[string]bool{}
|
||||
for _, e := range entries {
|
||||
b, err := os.ReadFile(filepath.Join(dir, e.Name()))
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
found[string(b)] = true
|
||||
}
|
||||
for _, want := range []string{"first", "second"} {
|
||||
if !found[want] {
|
||||
t.Errorf("quarantine destroyed %q: %v", want, found)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestParseJournalHeaderRejectsPaddingGarbage(t *testing.T) {
|
||||
h := journalHeader(";BIND LOG V9\n", 10, 16)
|
||||
h[15] = 'x'
|
||||
if _, _, ok := parseJournalHeader(h); ok {
|
||||
t.Error("format field must match all 16 bytes")
|
||||
}
|
||||
}
|
||||
|
||||
func TestShellQuoteEscapesQuotes(t *testing.T) {
|
||||
sh, err := exec.LookPath("sh")
|
||||
if err != nil {
|
||||
t.Skipf("no POSIX shell: %v", err)
|
||||
}
|
||||
evil := `a'; touch pwned; echo '`
|
||||
out, err := exec.Command(sh, "-c", "printf %s "+shellQuote(evil)).Output()
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if string(out) != evil {
|
||||
t.Errorf("shellQuote round trip = %q want %q", out, evil)
|
||||
}
|
||||
}
|
||||
|
||||
// The probe is shell, so run it and check the parser agrees with what is
|
||||
// actually on disk; a syntax slip or a missing field would otherwise only
|
||||
// surface as a seed over live data.
|
||||
func TestZoneStateProbeRoundTrip(t *testing.T) {
|
||||
sh, err := exec.LookPath("sh")
|
||||
if err != nil {
|
||||
t.Skipf("no POSIX shell: %v", err)
|
||||
}
|
||||
for _, tool := range []string{"head", "od", "tr"} {
|
||||
if _, err := exec.LookPath(tool); err != nil {
|
||||
t.Skipf("probe needs %s: %v", tool, err)
|
||||
}
|
||||
}
|
||||
|
||||
cases := []struct {
|
||||
name string
|
||||
zone string
|
||||
jnl []byte
|
||||
want ZoneDiskState
|
||||
}{
|
||||
{name: "fresh install"},
|
||||
{
|
||||
name: "zone file only",
|
||||
zone: renderSeedZone("example.com", "10.0.0.1", 42),
|
||||
want: ZoneDiskState{ZoneFile: true, ZoneSerial: 42, ZoneSerialOK: true},
|
||||
},
|
||||
{
|
||||
name: "zone file and journal",
|
||||
zone: renderSeedZone("example.com", "10.0.0.1", 12),
|
||||
jnl: journalHeader(";BIND LOG V9.2\n", 10, 16),
|
||||
want: ZoneDiskState{
|
||||
ZoneFile: true, ZoneSerial: 12, ZoneSerialOK: true,
|
||||
Journal: true, JournalBegin: 10, JournalEnd: 16, JournalOK: true,
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "orphan journal",
|
||||
jnl: journalHeader(";BIND LOG V9.2\n", 10, 16),
|
||||
want: ZoneDiskState{Journal: true, JournalBegin: 10, JournalEnd: 16, JournalOK: true},
|
||||
},
|
||||
{
|
||||
name: "journal with unreadable header",
|
||||
jnl: []byte("garbage"),
|
||||
want: ZoneDiskState{Journal: true},
|
||||
},
|
||||
}
|
||||
for _, c := range cases {
|
||||
path := filepath.Join(t.TempDir(), "db.example.com")
|
||||
if c.zone != "" {
|
||||
if err := os.WriteFile(path, []byte(c.zone), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
if c.jnl != nil {
|
||||
if err := os.WriteFile(JournalPath(path), c.jnl, 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
out, err := exec.Command(sh, "-c", zoneStateProbe(path)).Output()
|
||||
if err != nil {
|
||||
t.Fatalf("%s: probe failed: %v", c.name, err)
|
||||
}
|
||||
got, ok := parseZoneDiskState(string(out))
|
||||
if !ok {
|
||||
t.Errorf("%s: probe output rejected: %q", c.name, out)
|
||||
continue
|
||||
}
|
||||
if got != c.want {
|
||||
t.Errorf("%s: state = %+v want %+v (out %q)", c.name, got, c.want, out)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user