[PR #2373] [MERGED] Fix CAA parameter value validation #2994

Closed
opened 2026-03-16 11:19:19 +03:00 by kerem · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/hickory-dns/hickory-dns/pull/2373
Author: @divergentdave
Created: 8/21/2024
Status: Merged
Merged: 8/23/2024
Merged by: @djc

Base: mainHead: david/fix-caa-value-validation


📝 Commits (2)

  • a01ff2d Replace RFC 6844 excerpts with RFC 8659
  • 481cbb5 Fix parsing of issuer parameter values

📊 Changes

1 file changed (+137 additions, -220 deletions)

View changed files

📝 crates/proto/src/rr/rdata/caa.rs (+137 -220)

📄 Description

This fixes another issue listed in #2353, by returning an error upon seeing non-ASCII bytes in CAA issuer parameter values, instead of corrupting them. I also updated RFC excerpt text in various comments in this file, since the excerpts were still from RFC 6844.

RFC 6844 allows *VCHAR in this position (%x21-7E), while RFC 8659 allows *(%x21-3A / %x3C-7E), which excludes semicolons to make the parser unambiguous. The existing code was insufficiently strict about non-ASCII characters.


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/hickory-dns/hickory-dns/pull/2373 **Author:** [@divergentdave](https://github.com/divergentdave) **Created:** 8/21/2024 **Status:** ✅ Merged **Merged:** 8/23/2024 **Merged by:** [@djc](https://github.com/djc) **Base:** `main` ← **Head:** `david/fix-caa-value-validation` --- ### 📝 Commits (2) - [`a01ff2d`](https://github.com/hickory-dns/hickory-dns/commit/a01ff2d981eb83a502b5e3c9d9bb662720efe8be) Replace RFC 6844 excerpts with RFC 8659 - [`481cbb5`](https://github.com/hickory-dns/hickory-dns/commit/481cbb5c5bfa1b3f5d52965bed8088c10a3ac533) Fix parsing of issuer parameter values ### 📊 Changes **1 file changed** (+137 additions, -220 deletions) <details> <summary>View changed files</summary> 📝 `crates/proto/src/rr/rdata/caa.rs` (+137 -220) </details> ### 📄 Description This fixes another issue listed in #2353, by returning an error upon seeing non-ASCII bytes in CAA issuer parameter values, instead of corrupting them. I also updated RFC excerpt text in various comments in this file, since the excerpts were still from RFC 6844. RFC 6844 allows `*VCHAR` in this position (`%x21-7E`), while RFC 8659 allows `*(%x21-3A / %x3C-7E)`, which excludes semicolons to make the parser unambiguous. The existing code was insufficiently strict about non-ASCII characters. --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
kerem 2026-03-16 11:19:19 +03:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/hickory-dns#2994
No description provided.