Commit 9fbbd7283b for bind

commit 9fbbd7283b0b950b9df3e01ea99f90ce9547acd5
Author: Mark Andrews <marka@isc.org>
Date:   Mon Sep 28 18:07:00 2026 +1000

    rndc accepts stale or mismatched signed responses

    Check that the messages being received are responses and
    that the serial of the response matches that of the request.

diff --git a/bin/rndc/rndc.c b/bin/rndc/rndc.c
index 7d4f14fe7b..652f9dd649 100644
--- a/bin/rndc/rndc.c
+++ b/bin/rndc/rndc.c
@@ -297,6 +297,29 @@ rndc_senddone(isc_nmhandle_t *handle ISC_ATTR_UNUSED, isc_result_t result,
 	}
 }

+static void
+validate_response(isccc_sexpr_t *response) {
+	isccc_sexpr_t *_ctrl = NULL;
+	uint32_t rpl = 0, ser = ~serial;
+
+	_ctrl = isccc_alist_lookup(response, "_ctrl");
+	if (!isccc_alist_alistp(_ctrl)) {
+		fatal("bad or missing ctrl section in response");
+	}
+
+	if (isccc_cc_lookupuint32(_ctrl, "_rpl", &rpl) != ISC_R_SUCCESS ||
+	    rpl != 1)
+	{
+		fatal("bad or missing ctrl.rpl section in response");
+	}
+
+	if (isccc_cc_lookupuint32(_ctrl, "_ser", &ser) != ISC_R_SUCCESS ||
+	    ser != serial)
+	{
+		fatal("bad or missing ctrl.ser section in response");
+	}
+}
+
 static void
 rndc_recvdone(isc_nmhandle_t *handle, isc_result_t result, void *arg) {
 	isccc_ccmsg_t *ccmsg = (isccc_ccmsg_t *)arg;
@@ -332,6 +355,8 @@ rndc_recvdone(isc_nmhandle_t *handle, isc_result_t result, void *arg) {
 		fprintf(stderr, "\n");
 	}

+	validate_response(response);
+
 	data = isccc_alist_lookup(response, "_data");
 	if (!isccc_alist_alistp(data)) {
 		fatal("bad or missing data section in response");
@@ -407,10 +432,13 @@ rndc_recvnonce(isc_nmhandle_t *handle ISC_ATTR_UNUSED, isc_result_t result,
 	DO("parse message",
 	   isccc_cc_fromwire(&source, &response, algorithm, &secret));

+	validate_response(response);
+
 	_ctrl = isccc_alist_lookup(response, "_ctrl");
 	if (!isccc_alist_alistp(_ctrl)) {
 		fatal("bad or missing ctrl section in response");
 	}
+
 	nonce = 0;
 	if (isccc_cc_lookupuint32(_ctrl, "_nonce", &nonce) != ISC_R_SUCCESS) {
 		nonce = 0;