Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 6 additions & 1 deletion lib/resolv.rb
Original file line number Diff line number Diff line change
Expand Up @@ -1244,7 +1244,12 @@ def generate_candidates(name)
[name]
else
abs = Name.new(name.to_a)
search = @search.map {|domain| Name.new(name.to_a + domain)}
search = @search.map {|domain| name.to_a + domain}
# A search domain can push a candidate past 255 octets even though
# the name itself fits. No reply can carry such a name, so skip it
# and leave the other candidates to be tried. [RFC 1035 3.1]
search.reject! {|labels| labels.inject(1) {|size, label| size + 1 + label.string.bytesize} > 255}
search.map! {|labels| Name.new(labels)}
if @ndots <= name.length - 1
[abs, *search].uniq
else
Expand Down
17 changes: 17 additions & 0 deletions test/resolv/test_dns.rb
Original file line number Diff line number Diff line change
Expand Up @@ -154,6 +154,23 @@ def test_conf_search_root_domain
assert_equal ['example.com', 'example.com.local'], candidates.map(&:to_s)
end

def test_conf_search_skips_candidate_over_255_octets
# 246 octets encoded, so a search domain may add at most 9 more.
name = (["a" * 63] * 3 + ["a" * 52]).join(".")
conf = Resolv::DNS::Config.new(nameserver: '127.0.0.1', search: ['b' * 9, 'c' * 8], ndots: 1)
conf.lazy_initialize
candidates = conf.generate_candidates(name)
assert_equal [name, "#{name}.#{'c' * 8}"], candidates.map(&:to_s)
msg = Resolv::DNS::Message.new
msg.add_question(candidates[1], Resolv::DNS::Resource::IN::A)
assert_equal candidates[1], Resolv::DNS::Message.decode(msg.encode).question[0][0]

conf = Resolv::DNS::Config.new(nameserver: '127.0.0.1', search: ['b' * 9], ndots: 5)
conf.lazy_initialize
candidates = conf.generate_candidates(name)
assert_equal [name], candidates.map(&:to_s)
end

def test_query_ipv4_address
begin
OpenSSL
Expand Down
Loading