test_api_rr.py 24 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418
  1. from typing import List, Tuple
  2. import pytest
  3. from conftest import DeSECAPIV1Client, query_replication, NSLordClient, assert_eventually
  4. def generate_params(dict_value_lists_by_type: dict) -> List[Tuple[str, str]]:
  5. return [
  6. (rr_type, value)
  7. for rr_type in dict_value_lists_by_type.keys()
  8. for value in dict_value_lists_by_type[rr_type]
  9. ]
  10. VALID_RECORDS_CANONICAL = {
  11. 'A': ['127.0.0.1', '127.0.0.2'],
  12. 'AAAA': ['::1', '::2'],
  13. 'AFSDB': ['2 turquoise.femto.edu.'],
  14. 'APL': [
  15. # from RFC 3123 Sec. 4
  16. '1:192.168.32.0/21 !1:192.168.38.0/28',
  17. '1:192.168.42.0/26 1:192.168.42.64/26 1:192.168.42.128/25',
  18. '1:127.0.0.1/32 1:172.16.64.0/22',
  19. '1:224.0.0.0/4 2:ff00::/8',
  20. ],
  21. 'CAA': [
  22. '128 issue "letsencrypt.org"', '128 iodef "mailto:desec@example.com"',
  23. '1 issue "letsencrypt.org"'
  24. ],
  25. 'CDNSKEY': [
  26. None,
  27. '256 3 8 AwEAAday3UX323uVzQqtOMQ7EHQYfD5O fv4akjQGN2zY5AgB/2jmdR/+1PvXFqzK CAGJv4wjABEBNWLLFm7ew1hHMDZEKVL1 7aml0EBKI6Dsz6Mxt6n7ScvLtHaFRKax T4i2JxiuVhKdQR9XGMiWAPQKrRM5SLG0 P+2F+TLKl3D0L/cD',
  28. '257 3 8 AwEAAcw5QLr0IjC0wKbGoBPQv4qmeqHy 9mvL5qGQTuaG5TSrNqEAR6b/qvxDx6my 4JmEmjUPA1JeEI9YfTUieMr2UZflu7aI bZFLw0vqiYrywCGrCHXLalOrEOmrvAxL vq4vHtuTlH7JIszzYBSes8g1vle6KG7x XiP3U5Ll96Qiu6bZ31rlMQSPB20xbqJJ h6psNSrQs41QvdcXAej+K2Hl1Wd8kPri ec4AgiBEh8sk5Pp8W9ROLQ7PcbqqttFa W2m7N/Wy4qcFU13roWKDEAstbxH5CHPo BfZSbIwK4KM6BK/uDHpSPIbiOvOCW+lv u9TAiZPc0oysY6aslO7jXv16Gws=',
  29. '257 3 13 aCoEWYBBVsP9Fek2oC8yqU8ocKmnS1iD SFZNORnQuHKtJ9Wpyz+kNryquB78Pyk/ NTEoai5bxoipVQQXzHlzyg==',
  30. ],
  31. 'CDS': [
  32. None,
  33. '6454 8 1 24396e17e36d031f71c354b06a979a67a01f503e',
  34. ],
  35. 'CERT': ['6 0 0 sadfdQ=='],
  36. 'CNAME': ['example.com.'],
  37. 'CSYNC': ['0 0', '66 1 A', '66 2 AAAA', '66 3 A NS AAAA', '66 15 NSEC'],
  38. 'DHCID': ['aaaaaaaaaaaa', 'xxxx'],
  39. 'DLV': ['6454 8 1 24396e17e36d031f71c354b06a979a67a01f503e'],
  40. 'DNAME': ['example.com.'],
  41. 'DNSKEY': [
  42. None,
  43. '256 3 8 AwEAAday3UX323uVzQqtOMQ7EHQYfD5O fv4akjQGN2zY5AgB/2jmdR/+1PvXFqzK CAGJv4wjABEBNWLLFm7ew1hHMDZEKVL1 7aml0EBKI6Dsz6Mxt6n7ScvLtHaFRKax T4i2JxiuVhKdQR9XGMiWAPQKrRM5SLG0 P+2F+TLKl3D0L/cD',
  44. '257 3 8 AwEAAcw5QLr0IjC0wKbGoBPQv4qmeqHy 9mvL5qGQTuaG5TSrNqEAR6b/qvxDx6my 4JmEmjUPA1JeEI9YfTUieMr2UZflu7aI bZFLw0vqiYrywCGrCHXLalOrEOmrvAxL vq4vHtuTlH7JIszzYBSes8g1vle6KG7x XiP3U5Ll96Qiu6bZ31rlMQSPB20xbqJJ h6psNSrQs41QvdcXAej+K2Hl1Wd8kPri ec4AgiBEh8sk5Pp8W9ROLQ7PcbqqttFa W2m7N/Wy4qcFU13roWKDEAstbxH5CHPo BfZSbIwK4KM6BK/uDHpSPIbiOvOCW+lv u9TAiZPc0oysY6aslO7jXv16Gws=',
  45. '257 3 13 aCoEWYBBVsP9Fek2oC8yqU8ocKmnS1iD SFZNORnQuHKtJ9Wpyz+kNryquB78Pyk/ NTEoai5bxoipVQQXzHlzyg==',
  46. ],
  47. 'DS': ['6454 8 1 24396e17e36d031f71c354b06a979a67a01f503e'],
  48. 'EUI48': ['aa-bb-cc-dd-ee-ff'],
  49. 'EUI64': ['aa-bb-cc-dd-ee-ff-00-11'],
  50. 'HINFO': ['"ARMv8-A" "Linux"'],
  51. 'HTTPS': [
  52. '1 h3POOL.exaMPLe. alpn=h2,h3',
  53. # '1 h3POOL.exaMPLe. alpn=h2,h3 ech="MTIzLi4uCg=="', # TODO dnspython > 2.1.0
  54. ],
  55. # 'IPSECKEY': ['12 0 2 . asdfdQ==', '3 1 1 127.0.0.1 asdfdQ==', '12 3 1 example.com. asdfdQ==',],
  56. 'KX': ['4 example.com.', '28 io.', '0 .'],
  57. 'LOC': [
  58. '23 12 59.000 N 42 22 48.500 W 65.00m 20.00m 10.00m 10.00m',
  59. ],
  60. 'MX': ['10 example.com.', '20 1.1.1.1.'],
  61. 'NAPTR': [
  62. '100 50 "s" "z3950+I2L+I2C" "" _z3950._tcp.gatech.edu.',
  63. ],
  64. 'NS': ['ns1.example.com.'],
  65. 'OPENPGPKEY': [
  66. 'mQINBF3yev8BEADR9GxB6OJ5AJlXBWc3nWyWZ+yNNVBiy73XjgOs0uowbxph'
  67. 'dIw6l75M6xw3i9xAlcjAGG2710FJaye7EZHot3RTIgHpn4FrErQSpNPuJKjD'
  68. 'IedZZ4av5SRtz5FfnXhNkQGs7jAVi6FmjR9/0GWMxj0BdbcOmeePCUfIIH7T'
  69. 'ujQJ2c3XHOu/kZ1h4zsFVSslcLEi4KXy0I52pEz0E2CyJrxCLdBd7uU7wDCg'
  70. 'G8KrIP3UJ5EtukP/LMq4D1eZ4FmtVqzkuDYlJJo70XQytEK9UqDdaDvlUeS5'
  71. 'FrVj4Zf7OaC5YcSvQemVV4VYSBgJIPb+iFY21/1mXAxyYaunqaR0j5qNaMjr'
  72. 'E2g3ADRxJiLExhhzlqwJU8+Lc+0QajF/s3lc+dB5usSPqGk6Eb4hBEMaqQvg'
  73. '5I0W8pFtHINYipNW5xGSrsX0pyWVai6EkoTXfjbBMC7khwmwsycJ8pYj3ipe'
  74. 'aNQuUP+XXqJKepoVOY2475Z7YT1NRRbGGEp743mbqKo4SnEKxS2kApo1UPd1'
  75. 'FbI50TZ62Vsv4tne3bR25eCycjdvIOp6zPm/Pf9LFVm5KF8Wd2U3vRi/uo4v'
  76. 'HPUK1RoIzjmirp3XUBGBgHd/mhlOADPWB9dE96eXK4yEHlbfomfFiKAisHDc'
  77. 'vUa0E/UbklYBhJjdWBaw1fDDyiSxsBCTsq4ObQARAQABtBFzdXBwb3J0QHBv'
  78. 'c3Rlby5kZYkCVAQTAQgAPhYhBJZxyBhcZRmrtOitn6TrgtJXP3x3BQJd8nr/'
  79. 'AhsDBQkDw7iABQsJCAcCBhUKCQgLAgQWAgMBAh4BAheAAAoJEKTrgtJXP3x3'
  80. '+UIP/jpw6Nkp5hLbXxpPRSL2TyyWDfEHPKkBQfU+jnAUIN+WgAV27HpOa+vZ'
  81. '/hmTKOG6SlTOxHWACmDiUVfhLOYMV8QPDD3yPFCZWo4UxBKPZaai6GQwr44u'
  82. 'zCcU+E6AdFnb2nbzYSgACrErU5o5JoU2lPgleMI3FYsG8wb/kQAD7XGDX+Ev'
  83. 'tAbAQGK5EgevycJzot/hsR/S6EM/l0VsW74DIje3fbp3gaJY2fUG9fTdQu7a'
  84. 'gj6f9HuZAvXHIuSFeA/kwhUWuZfTcct8PV78gwQB4d6AOFMzoxLaFQAzxuTR'
  85. '60kZxsyyi4U5km6D/XzI9rTd228PD8xkGr/2Kx1YRU0ixZnohv9xNc4GP/69'
  86. 'GNWbbOZcyJcSL+kvych+ddbP5VjHea+b4vT35KV++PMndj+78BE1u5sdqWir'
  87. 'X9pi09go7SW1BlaJsMHrkR0P8yFCaFWLyCmIC7C/KcSuHVwcjVYWHynLq6CK'
  88. 'kkv4r8BNM/QFzPCeozXjMk7zq9TkJjLVxsUVNcZaNqzlWO0JzCfE6ICpHhyI'
  89. 'g/1bO/VJQyk+6llyX1LwRKCeKQCp6KcLx4qnjgZ8g1ArNvazNot9fAssgAUz'
  90. 'yoyOBF1SYJxWnzu9GE1F47zU1iD6FB8mjspvE00voDs8t2e+xtZoqsM12WtC'
  91. '8R4VbCY0LmTPGiWyxD9y7TnUlDfHuQINBF3yev8BEAC4dyN2BPiHCmwtKV/3'
  92. '9ZUMVCjb39wnsAA8CH7WAAM5j+k8/uXKUmTcFoZ7+9ya6PZCLXbPC64FIAwl'
  93. 'YalzCEP5Jx25Ct/DPhVJPIFWHMOYbyUbLJ8tlC1vnnDhd8czeGmozkuyofMh'
  94. '39QzR3SLzOqucJO3GC6Fx7eFNasajJsaAXaQToKx8YqKCGG4nHxn0Ucb79+G'
  95. '/0wQhtR0Mk3CxcajYJAsTV2ulW05P9xqovblXImXDZpgv0bQ2TX43SdR17yk'
  96. 'QzL33HRNCT7clLblHLMPQVxYy1yGS6hOAQj/Rmp+BO7d3S082+oyAFWeb7a9'
  97. 'fwzedbxPeiE2VOLtZizQUWIHHqwKP0tNEWRvSfCbc6ktvZQnHCIKyhmTC8N7'
  98. 'kvS4T6WjWzpc1M+GOMlOqhtW6t3zV1i2tkcpujduBGRIZ8ZQY+yo/i1HSL5t'
  99. 'N98606YXN1s2JyqwAkBJfPYiMp67J2uaFsML3YQEKAxR64GhkjFR/OqYtlIB'
  100. 'cx1PvcrPbVWQzXZBfFyjbAd55MnWVk6GrbM3y1QATN3NNhXfbMzLLU6cw/8p'
  101. 'sJw0+hxv1W2bJTftrs/5PyLryNOKYHbPEtC6aIyuzbIFFKWxkNshUiasd82Q'
  102. 'Jafgx3pFNnCtB61UV46QeqPI7sVueLslurqVgEGb2dS6unKYWXedoIMELm3C'
  103. 'g0XdJQARAQABiQI8BBgBCAAmFiEElnHIGFxlGau06K2fpOuC0lc/fHcFAl3y'
  104. 'ev8CGwwFCQPDuIAACgkQpOuC0lc/fHc/PxAAj29SBqW6ZRG8zOOw0Dmg1sg4'
  105. 'ONYtJ4hEzqPv2WbtOKxgtdcjQS1gMadtfcrH0omZPn8YmeojdbJCd5b9UBYr'
  106. 'h4Km3usURy79ouqvyQdZOIBOCUuvNcAUX2xvgUEHQW+rDpkd2mxdASsay1I7'
  107. 'yx2S0xE/QP/L2dH0470JWJ+tCIz3WuW2BEi+wijy2tqJfzIkIWA5ND2jwl4n'
  108. 'roY7srmAwZfXlh97/T5oOPIUsupIp+vmtMd4B0qa1wLGFDch+VwVvklLN5/Q'
  109. 'Vfbedy1Y8yHYiRWSrd3pHvkdtE5rI8qCOWaU/271plT9MZiwHe5WzCWESbKi'
  110. 'dwHQanM0Y6+Y8rrvUWGXrlPDvVd3Gd6TjqNhA8+AEiG+BHsw7Azc5in97/yW'
  111. '9cAYEldWv1tUjxgqvWWbGA8E6M/EuE3FuM48HNODfEh/b0ut+b2UAtuz3LzK'
  112. 'NVpqYZ9NIebpIMlUuJoQc9rPCWzMDNX37iGRBA016L7VizeJRpJ8VPRAQWHe'
  113. 'L5eC85dx9wcdK152fqlOUj729J2TZ5JYQdm9vF2cA6bsIB9m48j/UzNEeV3W'
  114. 'NZ3nuZqQ9VjVLYiPURbdkYxWfUvFdVawfqUZ4PGKbVWrFfod8WwHa+gsP4UJ'
  115. 'hLN/nxCalBbc3HnyYo0Inlytu4fumElS7kuUVNielOsJlyUr8kfxU3c6MPk=',
  116. ],
  117. 'PTR': ['example.com.', '*.example.com.'],
  118. 'RP': ['hostmaster.example.com. .'],
  119. 'SMIMEA': ['3 1 0 aabbccddeeff'],
  120. 'SPF': [
  121. '"v=spf1 ip4:10.1" ".1.1 ip4:127" ".0.0.0/16 ip4:192.168.0.0/27 include:example.com -all"',
  122. '"v=spf1 include:example.com ~all"',
  123. '"v=spf1 ip4:10.1.1.1 ip4:127.0.0.0/16 ip4:192.168.0.0/27 include:example.com -all"',
  124. '"spf2.0/pra,mfrom ip6:2001:558:fe14:76:68:87:28:0/120 -all"',
  125. ],
  126. 'SRV': ['0 0 0 .', '100 1 5061 example.com.'],
  127. 'SSHFP': ['2 2 aabbcceeddff'],
  128. 'SVCB': [
  129. '2 sVc2.example.NET. port=1234 ipv6hint=2001:db8::2',
  130. # '2 sVc2.example.NET. port=1234 ech="MjIyLi4uCg==" ipv6hint=2001:db8::2', # TODO dnspython > 2.1.0
  131. ],
  132. 'TLSA': ['3 0 2 696b8f6b92a913560b23ef5720c378881faffe74432d04eb35db957c0a93987b47adf26abb5dac10ba482597ae16edb069b511bec3e26010d1927bf6392760dd 696b8f6b92a913560b23ef5720c378881faffe74432d04eb35db957c0a93987b47adf26abb5dac10ba482597ae16edb069b511bec3e26010d1927bf6392760dd',],
  133. 'TXT': [
  134. '"foobar"',
  135. '"foo" "bar"',
  136. '"foo" "" "bar"',
  137. '"" "" "foo" "" "bar"',
  138. r'"new\010line"',
  139. r'"\000" "NUL byte yo"',
  140. r'"\130\164name\164Boss\164type\1611"', # binary stuff with first bit 1
  141. f'"{"a" * 255}" "{"a" * 243}"', # 500 byte total wire length
  142. r'"\000\001\002\003\004\005\006\007\008\009\010\011\012\013\014\015\016\017\018\019\020\021\022\023\024\025\026\027\028\029\030\031 !\"#$%&' + "'" + r'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\127\128\129\130\131\132\133\134\135\136\137\138\139\140\141\142\143\144\145\146\147\148\149\150\151\152\153\154\155\156\157\158\159\160\161\162\163\164\165\166\167\168\169\170\171\172\173\174\175\176\177\178\179\180\181\182\183\184\185\186\187\188\189\190\191\192\193\194\195\196\197\198\199\200\201\202\203\204\205\206\207\208\209\210\211\212\213\214\215\216\217\218\219\220\221\222\223\224\225\226\227\228\229\230\231\232\233\234\235\236\237\238\239\240\241\242\243\244\245\246\247\248\249\250\251\252\253\254" "\255"',
  143. ],
  144. 'URI': ['10 1 "ftp://ftp1.example.com/public"'],
  145. }
  146. VALID_RECORDS_NON_CANONICAL = {
  147. 'A': ['127.0.0.3'],
  148. 'AAAA': ['0000::0000:0003', '2001:db8::128.2.129.4'],
  149. 'AFSDB': ['03 turquoise.FEMTO.edu.'],
  150. 'APL': ['2:FF00:0:0:0:0::/8 !1:192.168.38.0/28'],
  151. 'CAA': ['0128 "issue" "letsencrypt.org"'],
  152. 'CDNSKEY': [
  153. '0256 3 8 AwEAAday3UX323uVzQqtOMQ7EHQYfD5Ofv4akjQGN2zY5AgB/2jmdR/+1PvXFqzKCAGJv4wjABEBNWLLFm7ew1hHMDZEKVL17aml0EBKI6Dsz6Mxt6n7ScvLtHaFRKaxT4i2JxiuVhKdQR9XGMiWAPQKrRM5SLG0P+2F+TLKl3D0L/cD',
  154. '257 03 8 AwEAAcw5QLr0IjC0wKbGoBPQv4qmeqHy9mvL5qGQTuaG5TSrNqEAR6b/qvxDx6my4JmEmjUPA1JeEI9YfTUieMr2UZflu7aIbZFLw0vqiYrywCGrCHXLalOrEOmrvAxLvq4vHtuTlH7JIszzYBSes8g1vle6KG7xXiP3U5Ll96Qiu6bZ31rlMQSPB20xbqJJh6psNSrQs41QvdcXAej+K2Hl1Wd8kPriec4AgiBEh8sk5Pp8W9ROLQ7PcbqqttFaW2m7N/Wy4qcFU13roWKDEAstbxH5CHPoBfZSbIwK4KM6BK/uDHpSPIbiOvOCW+lvu9TAiZPc0oysY6aslO7jXv16Gws=',
  155. '257 3 013 aCoEWYBBVsP9Fek2oC8yqU8ocKmnS1iDSFZNORnQuHKtJ9Wpyz+kNryquB78Pyk/NTEoai5bxoipVQQXzHlzyg==',
  156. ],
  157. 'CDS': [
  158. '06454 08 01 24396e17e36d031f71c354b06a979a67a01f503e',
  159. '6454 8 2 5C BA665A006F6487625C6218522F09BD3673C25FA10F25CB18459AA1 0DF1F520',
  160. ],
  161. 'CERT': ['06 00 00 sadfee=='],
  162. 'CNAME': ['EXAMPLE.TEST.'],
  163. 'CSYNC': ['066 03 NS AAAA A'],
  164. 'DHCID': ['aa aaa aaaa a a a', 'xxxx'],
  165. 'DLV': [
  166. '06454 08 01 24396e17e36d031f71c354b06a979a67a01f503e',
  167. '6454 8 2 5C BA665A006F6487625C6218522F09BD3673C25FA10F25CB18459AA1 0DF1F520',
  168. ],
  169. 'DNAME': ['EXAMPLE.TEST.'],
  170. 'DNSKEY': [
  171. '0256 3 8 AwEAAday3UX323uVzQqtOMQ7EHQYfD5Ofv4akjQGN2zY5AgB/2jmdR/+1PvXFqzKCAGJv4wjABEBNWLLFm7ew1hHMDZEKVL17aml0EBKI6Dsz6Mxt6n7ScvLtHaFRKaxT4i2JxiuVhKdQR9XGMiWAPQKrRM5SLG0P+2F+TLKl3D0L/cD',
  172. '257 03 8 AwEAAcw5QLr0IjC0wKbGoBPQv4qmeqHy9mvL5qGQTuaG5TSrNqEAR6b/qvxDx6my4JmEmjUPA1JeEI9YfTUieMr2UZflu7aIbZFLw0vqiYrywCGrCHXLalOrEOmrvAxLvq4vHtuTlH7JIszzYBSes8g1vle6KG7xXiP3U5Ll96Qiu6bZ31rlMQSPB20xbqJJh6psNSrQs41QvdcXAej+K2Hl1Wd8kPriec4AgiBEh8sk5Pp8W9ROLQ7PcbqqttFaW2m7N/Wy4qcFU13roWKDEAstbxH5CHPoBfZSbIwK4KM6BK/uDHpSPIbiOvOCW+lvu9TAiZPc0oysY6aslO7jXv16Gws=',
  173. '257 3 013 aCoEWYBBVsP9Fek2oC8yqU8ocKmnS1iDSFZNORnQuHKtJ9Wpyz+kNryquB78Pyk/NTEoai5bxoipVQQXzHlzyg==',
  174. ],
  175. 'DS': [
  176. '06454 08 01 24396e17e36d031f71c354b06a979a67a01f503e',
  177. '6454 8 2 5C BA665A006F6487625C6218522F09BD3673C25FA10F25CB18459AA1 0DF1F520',
  178. ],
  179. 'EUI48': ['AA-BB-CC-DD-EE-F1'],
  180. 'EUI64': ['AA-BB-CC-DD-EE-FF-00-12'],
  181. 'HINFO': ['cpu os'],
  182. 'HTTPS': [
  183. # from https://www.ietf.org/archive/id/draft-ietf-dnsop-svcb-https-06.html#name-examples, with ech base64'd
  184. '1 . alpn=h3',
  185. '0 pool.svc.example.',
  186. # '1 h3pool.example. alpn=h2,h3 ech="MTIzLi4uCg=="', # TODO dnspython > 2.1.0
  187. # '2 . alpn=h2 ech="YWJjLi4uCg=="', # TODO dnspython > 2.1.0
  188. # made-up (not from RFC)
  189. '1 pool.svc.example. no-default-alpn port=1234 ipv4hint=192.168.123.1',
  190. # '2 . ech=... key65333=ex1 key65444=ex2 mandatory=key65444,ech', # see #section-7 # TODO dnspython > 2.1.0
  191. ],
  192. # 'IPSECKEY': ['12 0 2 . asdfdf==', '03 1 1 127.0.00.1 asdfdf==', '12 3 1 example.com. asdfdf==',],
  193. 'KX': ['012 example.TEST.'],
  194. 'LOC': [
  195. '023 012 59 N 042 022 48.500 W 65.00m 20.00m 10.00m 10.00m',
  196. ],
  197. 'MX': ['10 010.1.1.1.'],
  198. 'NAPTR': [
  199. '100 50 "s" "z3950+I2L+I2C" "" _z3950._tcp.gatech.edu.',
  200. ],
  201. 'NS': ['EXaMPLE.COM.'],
  202. 'OPENPGPKEY': [
  203. 'mG8EXtVIsRMFK4EEAC==',
  204. 'mQINBF3yev8BEADR9GxB6OJ5AJlXBWc3nWyWZ+yNNVBiy73XjgOs0uowbxph '
  205. 'dIw6l75M6xw3i9xAlcjAGG2710FJaye7EZHot3RTIgHpn4FrErQSpNPuJKjD '
  206. 'IedZZ4av5SRtz5FfnXhNkQGs7jAVi6FmjR9/0GWMxj0BdbcOmeePCUfIIH7T '
  207. 'ujQJ2c3XHOu/kZ1h4zsFVSslcLEi4KXy0I52pEz0E2CyJrxCLdBd7uU7wDCg '
  208. 'G8KrIP3UJ5EtukP/LMq4D1eZ4FmtVqzkuDYlJJo70XQytEK9UqDdaDvlUeS5 '
  209. 'FrVj4Zf7OaC5YcSvQemVV4VYSBgJIPb+iFY21/1mXAxyYaunqaR0j5qNaMjr '
  210. 'E2g3ADRxJiLExhhzlqwJU8+Lc+0QajF/s3lc+dB5usSPqGk6Eb4hBEMaqQvg '
  211. '5I0W8pFtHINYipNW5xGSrsX0pyWVai6EkoTXfjbBMC7khwmwsycJ8pYj3ipe '
  212. 'aNQuUP+XXqJKepoVOY2475Z7YT1NRRbGGEp743mbqKo4SnEKxS2kApo1UPd1 '
  213. 'FbI50TZ62Vsv4tne3bR25eCycjdvIOp6zPm/Pf9LFVm5KF8Wd2U3vRi/uo4v '
  214. 'HPUK1RoIzjmirp3XUBGBgHd/mhlOADPWB9dE96eXK4yEHlbfomfFiKAisHDc '
  215. 'vUa0E/UbklYBhJjdWBaw1fDDyiSxsBCTsq4ObQARAQABtBFzdXBwb3J0QHBv '
  216. 'c3Rlby5kZYkCVAQTAQgAPhYhBJZxyBhcZRmrtOitn6TrgtJXP3x3BQJd8nr/ '
  217. 'AhsDBQkDw7iABQsJCAcCBhUKCQgLAgQWAgMBAh4BAheAAAoJEKTrgtJXP3x3 '
  218. '+UIP/jpw6Nkp5hLbXxpPRSL2TyyWDfEHPKkBQfU+jnAUIN+WgAV27HpOa+vZ '
  219. '/hmTKOG6SlTOxHWACmDiUVfhLOYMV8QPDD3yPFCZWo4UxBKPZaai6GQwr44u '
  220. 'zCcU+E6AdFnb2nbzYSgACrErU5o5JoU2lPgleMI3FYsG8wb/kQAD7XGDX+Ev '
  221. 'tAbAQGK5EgevycJzot/hsR/S6EM/l0VsW74DIje3fbp3gaJY2fUG9fTdQu7a '
  222. 'gj6f9HuZAvXHIuSFeA/kwhUWuZfTcct8PV78gwQB4d6AOFMzoxLaFQAzxuTR '
  223. '60kZxsyyi4U5km6D/XzI9rTd228PD8xkGr/2Kx1YRU0ixZnohv9xNc4GP/69 '
  224. 'GNWbbOZcyJcSL+kvych+ddbP5VjHea+b4vT35KV++PMndj+78BE1u5sdqWir '
  225. 'X9pi09go7SW1BlaJsMHrkR0P8yFCaFWLyCmIC7C/KcSuHVwcjVYWHynLq6CK '
  226. 'kkv4r8BNM/QFzPCeozXjMk7zq9TkJjLVxsUVNcZaNqzlWO0JzCfE6ICpHhyI '
  227. 'g/1bO/VJQyk+6llyX1LwRKCeKQCp6KcLx4qnjgZ8g1ArNvazNot9fAssgAUz '
  228. 'yoyOBF1SYJxWnzu9GE1F47zU1iD6FB8mjspvE00voDs8t2e+xtZoqsM12WtC '
  229. '8R4VbCY0LmTPGiWyxD9y7TnUlDfHuQINBF3yev8BEAC4dyN2BPiHCmwtKV/3 '
  230. '9ZUMVCjb39wnsAA8CH7WAAM5j+k8/uXKUmTcFoZ7+9ya6PZCLXbPC64FIAwl '
  231. 'YalzCEP5Jx25Ct/DPhVJPIFWHMOYbyUbLJ8tlC1vnnDhd8czeGmozkuyofMh '
  232. '39QzR3SLzOqucJO3GC6Fx7eFNasajJsaAXaQToKx8YqKCGG4nHxn0Ucb79+G '
  233. '/0wQhtR0Mk3CxcajYJAsTV2ulW05P9xqovblXImXDZpgv0bQ2TX43SdR17yk '
  234. 'QzL33HRNCT7clLblHLMPQVxYy1yGS6hOAQj/Rmp+BO7d3S082+oyAFWeb7a9 '
  235. 'fwzedbxPeiE2VOLtZizQUWIHHqwKP0tNEWRvSfCbc6ktvZQnHCIKyhmTC8N7 '
  236. 'kvS4T6WjWzpc1M+GOMlOqhtW6t3zV1i2tkcpujduBGRIZ8ZQY+yo/i1HSL5t '
  237. 'N98606YXN1s2JyqwAkBJfPYiMp67J2uaFsML3YQEKAxR64GhkjFR/OqYtlIB '
  238. 'cx1PvcrPbVWQzXZBfFyjbAd55MnWVk6GrbM3y1QATN3NNhXfbMzLLU6cw/8p '
  239. 'sJw0+hxv1W2bJTftrs/5PyLryNOKYHbPEtC6aIyuzbIFFKWxkNshUiasd82Q '
  240. 'Jafgx3pFNnCtB61UV46QeqPI7sVueLslurqVgEGb2dS6unKYWXedoIMELm3C '
  241. 'g0XdJQARAQABiQI8BBgBCAAmFiEElnHIGFxlGau06K2fpOuC0lc/fHcFAl3y '
  242. 'ev8CGwwFCQPDuIAACgkQpOuC0lc/fHc/PxAAj29SBqW6ZRG8zOOw0Dmg1sg4 '
  243. 'ONYtJ4hEzqPv2WbtOKxgtdcjQS1gMadtfcrH0omZPn8YmeojdbJCd5b9UBYr '
  244. 'h4Km3usURy79ouqvyQdZOIBOCUuvNcAUX2xvgUEHQW+rDpkd2mxdASsay1I7 '
  245. 'yx2S0xE/QP/L2dH0470JWJ+tCIz3WuW2BEi+wijy2tqJfzIkIWA5ND2jwl4n '
  246. 'roY7srmAwZfXlh97/T5oOPIUsupIp+vmtMd4B0qa1wLGFDch+VwVvklLN5/Q '
  247. 'Vfbedy1Y8yHYiRWSrd3pHvkdtE5rI8qCOWaU/271plT9MZiwHe5WzCWESbKi '
  248. 'dwHQanM0Y6+Y8rrvUWGXrlPDvVd3Gd6TjqNhA8+AEiG+BHsw7Azc5in97/yW '
  249. '9cAYEldWv1tUjxgqvWWbGA8E6M/EuE3FuM48HNODfEh/b0ut+b2UAtuz3LzK '
  250. 'NVpqYZ9NIebpIMlUuJoQc9rPCWzMDNX37iGRBA016L7VizeJRpJ8VPRAQWHe '
  251. 'L5eC85dx9wcdK152fqlOUj729J2TZ5JYQdm9vF2cA6bsIB9m48j/UzNEeV3W '
  252. 'NZ3nuZqQ9VjVLYiPURbdkYxWfUvFdVawfqUZ4PGKbVWrFfod8WwHa+gsP4UJ '
  253. 'hLN/nxCalBbc3HnyYo0Inlytu4fumElS7kuUVNielOsJlyUr8kfxU3c6MPk=',
  254. ],
  255. 'PTR': ['EXAMPLE.TEST.'],
  256. 'RP': ['hostmaster.EXAMPLE.com. .'],
  257. 'SMIMEA': ['3 01 0 aabbccDDeeff'],
  258. 'SPF': [],
  259. 'SRV': ['100 01 5061 example.com.'],
  260. 'SSHFP': ['02 2 aabbcceeddff'],
  261. 'SVCB': [
  262. '0 svc4-baz.example.net.',
  263. '1 . key65333=...',
  264. # '2 svc2.example.net. ech="MjIyLi4uCg==" ipv6hint=2001:db8::2 port=1234', # TODO dnspython > 2.1.0
  265. ],
  266. 'TLSA': ['003 00 002 696B8F6B92A913560b23ef5720c378881faffe74432d04eb35db957c0a93987b47adf26abb5dac10ba482597ae16edb069b511bec3e26010d1927bf6392760dd',],
  267. 'TXT': [
  268. f'"{"a" * 498}" ',
  269. '"' + 124 * '🧥' + '==="', # 501 byte total length
  270. '"🧥 👚 👕 👖 👔 👗 👙 👘 👠 👡 👢 👞 👟 🥾 🥿 🧦 🧤 🧣 🎩 🧢 👒 🎓 ⛑ 👑 👝 👛 👜 💼 🎒 "',
  271. '"🧥 👚 👕 👖 👔 👗 👙 👘 👠 👡 👢 👞 👟 🥾 🥿 🧦 🧤 🧣 🎩 🧢 👒 🎓 ⛑ 👑 👝 👛 👜 💼 🎒 👓 🕶 🥽 🥼 🌂 🧵"',
  272. '"' + ''.join(fr'\{n:03}' for n in range(256)) + '"', # all bytes
  273. ],
  274. 'URI': ['10 01 "ftp://ftp1.example.test/public"',],
  275. }
  276. INVALID_RECORDS = {
  277. 'A': ['127.0.0.999', '127.000.0.01', '127.0.0.256', '::1', 'foobar', '10.0.1', '10!'],
  278. 'AAAA': ['::g', '1:1:1:1:1:1:1:1:', '1:1:1:1:1:1:1:1:1'],
  279. 'AFSDB': ['example.com.', '1 1', '1 de'],
  280. 'APL': [
  281. '0:192.168.32.0/21 !1:192.168.38.0/28',
  282. '1:192.168.32.0/21 !!1:192.168.38.0/28',
  283. '1:192.168.32.0/33',
  284. '18:12345/2',
  285. '1:127.0.0.1',
  286. '2:::/129',
  287. ],
  288. 'CAA': ['43235 issue "letsencrypt.org"'],
  289. 'CDNSKEY': ['a 3 13 aCoEWYBBVsP9Fek2oC8yqU8ocKmnS1iDSFZNORnQuHKtJ9Wpyz+kNryq uB78Pyk/NTEoai5bxoipVQQXzHlzyg=='],
  290. 'CDS': [
  291. 'a 8 1 24396E17E36D031F71C354B06A979A67A01F503E',
  292. '6454 8 1 aabbccddeeff',
  293. ],
  294. 'CERT': ['6 0 sadfdd=='],
  295. 'CNAME': ['example.com', '10 example.com.'],
  296. 'CSYNC': ['0 -1 A', '444 65536 A', '0 3 AAA'],
  297. 'DHCID': ['x', 'xx', 'xxx'],
  298. 'DLV': ['-34 13 1 aabbccddeeff'],
  299. 'DNAME': ['example.com', '10 example.com.'],
  300. 'DNSKEY': ['a 3 13 aCoEWYBBVsP9Fek2oC8yqU8ocKmnS1iDSFZNORnQuHKtJ9Wpyz+kNryq uB78Pyk/NTEoai5bxoipVQQXzHlzyg=='],
  301. 'DS': [
  302. '-34 13 1 24396E17E36D031F71C354B06A979A67A01F503E',
  303. '6454 8 1 aabbccddeeff',
  304. ],
  305. 'EUI48': ['aa-bb-ccdd-ee-ff', 'AA-BB-CC-DD-EE-GG'],
  306. 'EUI64': ['aa-bb-cc-dd-ee-ff-gg-11', 'AA-BB-C C-DD-EE-FF-00-11'],
  307. 'HINFO': ['"ARMv8-A"', f'"a" "{"b" * 256}"'],
  308. 'HTTPS': [
  309. # from https://tools.ietf.org/html/draft-ietf-dnsop-svcb-https-02#section-10.3, with ech base64'd
  310. # '1 h3pool alpn=h2,h3 ech="MTIzLi4uCg=="', # TODO dnspython > 2.1.0
  311. # made-up (not from RFC)
  312. '0 pool.svc.example. no-default-alpn port=1234 ipv4hint=192.168.123.1', # no keys in alias mode
  313. '1 pool.svc.example. no-default-alpn port=1234 ipv4hint=192.168.123.1 ipv4hint=192.168.123.2', # dup
  314. ],
  315. # 'IPSECKEY': [],
  316. 'KX': ['-1 example.com', '10 example.com'],
  317. 'LOC': ['23 12 61.000 N 42 22 48.500 W 65.00m 20.00m 10.00m 10.00m', 'foo', '1.1.1.1'],
  318. 'MX': ['10 example.com', 'example.com.', '-5 asdf.', '65537 asdf.' '10 _foo.example.com.', '10 $url.'],
  319. 'NAPTR': ['100 50 "s" "z3950+I2L+I2C" "" _z3950._tcp.gatech.edu',
  320. '100 50 "s" "" _z3950._tcp.gatech.edu.',
  321. '100 50 3 2 "z3950+I2L+I2C" "" _z3950._tcp.gatech.edu.'],
  322. 'NS': ['ns1.example.com', '127.0.0.1'],
  323. 'OPENPGPKEY': ['1 2 3'],
  324. 'PTR': ['"example.com."', '10 *.example.com.'],
  325. 'RP': ['hostmaster.example.com.', '10 foo.'],
  326. 'SMIMEA': ['3 1 0 aGVsbG8gd29ybGQh', 'x 0 0 aabbccddeeff'],
  327. 'SPF': ['"v=spf1', 'v=spf1 include:example.com ~all'],
  328. 'SRV': ['0 0 0 0', '100 5061 example.com.', '0 0 16920 _foo.example.com.', '0 0 16920 $url.'],
  329. 'SSHFP': ['aabbcceeddff'],
  330. 'SVCB': [
  331. '0 svc4-baz.example.net. keys=val',
  332. '1 not.fully.qualified key65333=...',
  333. # '2 duplicate.key. ech="MjIyLi4uCg==" ech="MjIyLi4uCg=="', # TODO dnspython > 2.1.0
  334. ],
  335. 'TLSA': ['3 1 1 AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA'],
  336. 'TXT': [
  337. 'foob"ar',
  338. 'v=spf1 include:example.com ~all',
  339. '"foo\nbar"',
  340. '"\x00" "Django rejects literal NUL byte"',
  341. ],
  342. 'URI': ['"1" "2" "3"'],
  343. }
  344. INVALID_RECORDS_PARAMS = [(rr_type, value) for rr_type in INVALID_RECORDS.keys() for value in INVALID_RECORDS[rr_type]]
  345. def test_soundness():
  346. assert INVALID_RECORDS.keys() == VALID_RECORDS_CANONICAL.keys() == VALID_RECORDS_NON_CANONICAL.keys()
  347. @pytest.mark.parametrize("rr_type,value", generate_params(VALID_RECORDS_CANONICAL))
  348. def test_create_valid_canonical(api_user_domain: DeSECAPIV1Client, rr_type: str, value: str):
  349. domain_name = api_user_domain.domain
  350. expected = set()
  351. subname = 'a'
  352. if rr_type in ('CDNSKEY', 'CDS', 'DNSKEY'):
  353. expected |= api_user_domain.get_key_params(domain_name, rr_type)
  354. subname = ''
  355. if value is not None:
  356. assert api_user_domain.rr_set_create(domain_name, rr_type, [value], subname=subname).status_code == 201
  357. expected.add(value)
  358. _, rrset = NSLordClient.query(f'{subname}.{domain_name}'.strip('.'), rr_type)
  359. assert rrset == expected
  360. assert_eventually(lambda: query_replication(domain_name, subname, rr_type) == expected)
  361. @pytest.mark.parametrize("rr_type,value", generate_params(VALID_RECORDS_NON_CANONICAL))
  362. def test_create_valid_non_canonical(api_user_domain: DeSECAPIV1Client, rr_type: str, value: str):
  363. domain_name = api_user_domain.domain
  364. expected = set()
  365. subname = 'a'
  366. if rr_type in ('CDNSKEY', 'CDS', 'DNSKEY'):
  367. expected |= api_user_domain.get_key_params(domain_name, rr_type)
  368. subname = ''
  369. if value is not None:
  370. assert api_user_domain.rr_set_create(domain_name, rr_type, [value], subname=subname).status_code == 201
  371. expected.add(value)
  372. _, rrset = NSLordClient.query(f'{subname}.{domain_name}'.strip('.'), rr_type)
  373. assert len(rrset) == len(expected)
  374. assert_eventually(lambda: len(query_replication(domain_name, subname, rr_type)) == len(expected))
  375. @pytest.mark.parametrize("rr_type,value", INVALID_RECORDS_PARAMS)
  376. def test_create_invalid(api_user_domain: DeSECAPIV1Client, rr_type: str, value: str):
  377. assert api_user_domain.rr_set_create(api_user_domain.domain, rr_type, [value]).status_code == 400
  378. def test_create_long_subname(api_user_domain: DeSECAPIV1Client):
  379. subname = 'a' * 63
  380. assert api_user_domain.rr_set_create(api_user_domain.domain, "AAAA", ["::1"], subname=subname).status_code == 201
  381. assert NSLordClient.query(f"{subname}.{api_user_domain.domain}", "AAAA")[1] == {"::1"}
  382. assert_eventually(lambda: query_replication(api_user_domain.domain, subname, "AAAA") == {"::1"})
  383. def test_add_remove_DNSKEY(api_user_domain: DeSECAPIV1Client):
  384. domain_name = api_user_domain.domain
  385. auto_dnskeys = api_user_domain.get_key_params(domain_name, 'DNSKEY')
  386. # After adding another DNSKEY, we expect it to be part of the nameserver's response (along with the automatic ones)
  387. value = '257 3 13 aCoEWYBBVsP9Fek2oC8yqU8ocKmnS1iD SFZNORnQuHKtJ9Wpyz+kNryquB78Pyk/ NTEoai5bxoipVQQXzHlzyg=='
  388. assert api_user_domain.rr_set_create(domain_name, 'DNSKEY', [value], subname='').status_code == 201
  389. assert NSLordClient.query(domain_name, 'DNSKEY')[1] == auto_dnskeys | {value}
  390. assert_eventually(lambda: query_replication(domain_name, '', 'DNSKEY') == auto_dnskeys | {value})
  391. # After deleting it, we expect that the automatically managed ones are still there
  392. assert api_user_domain.rr_set_delete(domain_name, "DNSKEY", subname='').status_code == 204
  393. assert NSLordClient.query(domain_name, 'DNSKEY')[1] == auto_dnskeys
  394. assert_eventually(lambda: query_replication(domain_name, '', 'DNSKEY') == auto_dnskeys)