diff --git a/src/analyzer/protocol/dns/DNS.cc b/src/analyzer/protocol/dns/DNS.cc index b48e516707..c43888cb18 100644 --- a/src/analyzer/protocol/dns/DNS.cc +++ b/src/analyzer/protocol/dns/DNS.cc @@ -1706,6 +1706,15 @@ bool DNS_Interpreter::ParseRR_SVCB(detail::DNS_MsgInfo* msg, const u_char*& data if ( ! name_end ) return false; + // target name can be root - in this case the alternative endpoint is + // qname itself. make sure that we print "." instead of an empty string + if ( name_end - target_name == 0 ) + { + target_name[0] = '.'; + target_name[1] = '\0'; + name_end = target_name+1; + } + SVCB_DATA svcb_data = { .svc_priority = svc_priority, .target_name = new String(target_name, name_end - target_name, true), @@ -1724,6 +1733,7 @@ bool DNS_Interpreter::ParseRR_SVCB(detail::DNS_MsgInfo* msg, const u_char*& data analyzer->EnqueueConnEvent(dns_HTTPS, analyzer->ConnVal(), msg->BuildHdrVal(), msg->BuildAnswerVal(), msg->BuildSVCB_Val(&svcb_data)); break; + default: break; // unreachable. for suppressing compiler warnings. } return true; } diff --git a/testing/btest/Baseline/scripts.base.protocols.dns.https/output b/testing/btest/Baseline/scripts.base.protocols.dns.https/output new file mode 100644 index 0000000000..c94e491f7a --- /dev/null +++ b/testing/btest/Baseline/scripts.base.protocols.dns.https/output @@ -0,0 +1,3 @@ +[svc_priority=1, target_name=., svc_params={ + +}] \ No newline at end of file diff --git a/testing/btest/Traces/dns-https.pcap b/testing/btest/Traces/dns-https.pcap new file mode 100644 index 0000000000..b2c397e62e Binary files /dev/null and b/testing/btest/Traces/dns-https.pcap differ diff --git a/testing/btest/scripts/base/protocols/dns/svcb.zeek b/testing/btest/scripts/base/protocols/dns/https.zeek similarity index 100% rename from testing/btest/scripts/base/protocols/dns/svcb.zeek rename to testing/btest/scripts/base/protocols/dns/https.zeek