Skip to content

Reject out-of-range WKS ports and oversized wire bitmaps - #1310

Closed
00200200 wants to merge 1 commit into
rthalley:mainfrom
00200200:wks-reject-out-of-range-ports
Closed

00200200 wants to merge 1 commit into
rthalley:mainfrom
00200200:wks-reject-out-of-range-ports

Conversation

@00200200

Copy link
Copy Markdown

Fixes #1309.

RFC 1035 §3.4.2 maps each bit in a WKS bitmap to a protocol port. Ports are 16-bit values, so a presentation-form port above 65535 is not a valid WKS record, and a wire bitmap cannot be longer than 8192 octets.

from_text currently accepts 65536 (and larger) and builds a bitmap past that limit. from_wire also keeps trailing zero octets, so a padded wire form is not equal to the same ports parsed from text.

This change:

  • raises SyntaxError for a port outside 0–65535 in presentation form
  • raises FormError for a wire bitmap longer than 8192 octets
  • drops trailing zero octets from the bitmap so text and wire forms compare equal
import dns.rdata

dns.rdata.from_text('IN', 'WKS', '10.0.0.1 6 65536')  # SyntaxError

wks = dns.rdata.from_text('IN', 'WKS', '10.0.0.1 6 80')
padded = wks.to_wire() + b'\x00\x00'
assert wks == dns.rdata.from_wire('IN', 'WKS', padded, 0, len(padded))

RFC 1035 maps each WKS bit to a protocol port, so ports above 65535
and bitmaps longer than 8192 octets are invalid. Trailing zero octets
from the wire are dropped so the record matches the text form.

Fixes rthalley#1309
@rthalley

Copy link
Copy Markdown
Owner

RFC 1035 probably should have made the restrictions you suggest, as they are sensible; but it didn't. The text allows longer bitmaps and does not specify a canonical form.

@rthalley

Copy link
Copy Markdown
Owner

To give a little more info...

After much debate, the maintainers haven't found a solution they really like. We agree the RFC ought to have been written more strictly. We also note that silent truncation of trailing zeros will break DNSSEC signatures of the data, so we don't love that. It would be better to tolerate the zeros or FORMERR them, though we don't like the FORMERR much either.

Not being happy with any of the menu of alternatives we considered, we're currently thinking "WKS has been in disfavor since 1989 or so, and is not worth worrying about".

@00200200

Copy link
Copy Markdown
Author

Thanks for the context — especially the DNSSEC point on silent truncation. Closing this; no strong reason to change WKS if it's effectively historic.

@00200200 00200200 closed this Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

WKS from_text accepts ports above 65535 and from_wire keeps trailing zero bits

2 participants