From c73ee3f002a0e1510216e73195ef3f03a5da56bd Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Thu, 10 Apr 2008 01:30:57 +0000 Subject: [PATCH 001/137] -> rfc5155 --- doc/draft/draft-ietf-dnsext-nsec3-12.txt | 2968 ---------------------- 1 file changed, 2968 deletions(-) delete mode 100644 doc/draft/draft-ietf-dnsext-nsec3-12.txt diff --git a/doc/draft/draft-ietf-dnsext-nsec3-12.txt b/doc/draft/draft-ietf-dnsext-nsec3-12.txt deleted file mode 100644 index 16e95a0b85..0000000000 --- a/doc/draft/draft-ietf-dnsext-nsec3-12.txt +++ /dev/null @@ -1,2968 +0,0 @@ - - - -Network Working Group B. Laurie -Internet-Draft G. Sisson -Intended status: Standards Track R. Arends -Expires: January 2, 2008 Nominet - D. Blacka - VeriSign, Inc. - July 2007 - - - DNSSEC Hashed Authenticated Denial of Existence - draft-ietf-dnsext-nsec3-12 - -Status of this Memo - - By submitting this Internet-Draft, each author represents that any - applicable patent or other IPR claims of which he or she is aware - have been or will be disclosed, and any of which he or she becomes - aware will be disclosed, in accordance with Section 6 of BCP 79. - - Internet-Drafts are working documents of the Internet Engineering - Task Force (IETF), its areas, and its working groups. Note that - other groups may also distribute working documents as Internet- - Drafts. - - Internet-Drafts are draft documents valid for a maximum of six months - and may be updated, replaced, or obsoleted by other documents at any - time. It is inappropriate to use Internet-Drafts as reference - material or to cite them other than as "work in progress." - - The list of current Internet-Drafts can be accessed at - http://www.ietf.org/ietf/1id-abstracts.txt. - - The list of Internet-Draft Shadow Directories can be accessed at - http://www.ietf.org/shadow.html. - - This Internet-Draft will expire on January 2, 2008. - -Copyright Notice - - Copyright (C) The IETF Trust (2007). - -Abstract - - The Domain Name System Security Extensions (DNSSEC) introduced the - NSEC resource record (RR) for authenticated denial of existence. - This document introduces an alternative resource record, NSEC3, which - similarly provides authenticated denial of existence. However, it - also provides measures against zone enumeration and permits gradual - - - -Laurie, et al. Expires January 2, 2008 [Page 1] - -Internet-Draft nsec3 July 2007 - - - expansion of delegation-centric zones. - - -Table of Contents - - 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . . 4 - 1.1. Rationale . . . . . . . . . . . . . . . . . . . . . . . . 4 - 1.2. Reserved Words . . . . . . . . . . . . . . . . . . . . . . 4 - 1.3. Terminology . . . . . . . . . . . . . . . . . . . . . . . 4 - 2. Backwards Compatibility . . . . . . . . . . . . . . . . . . . 6 - 3. The NSEC3 Resource Record . . . . . . . . . . . . . . . . . . 7 - 3.1. RDATA Fields . . . . . . . . . . . . . . . . . . . . . . . 8 - 3.1.1. Hash Algorithm . . . . . . . . . . . . . . . . . . . . 8 - 3.1.2. Flags . . . . . . . . . . . . . . . . . . . . . . . . 8 - 3.1.3. Iterations . . . . . . . . . . . . . . . . . . . . . . 8 - 3.1.4. Salt Length . . . . . . . . . . . . . . . . . . . . . 8 - 3.1.5. Salt . . . . . . . . . . . . . . . . . . . . . . . . . 8 - 3.1.6. Hash Length . . . . . . . . . . . . . . . . . . . . . 9 - 3.1.7. Next Hashed Owner Name . . . . . . . . . . . . . . . . 9 - 3.1.8. Type Bit Maps . . . . . . . . . . . . . . . . . . . . 9 - 3.2. NSEC3 RDATA Wire Format . . . . . . . . . . . . . . . . . 9 - 3.2.1. Type Bit Maps Encoding . . . . . . . . . . . . . . . . 10 - 3.3. Presentation Format . . . . . . . . . . . . . . . . . . . 11 - 4. The NSEC3PARAM Record . . . . . . . . . . . . . . . . . . . . 12 - 4.1. RDATA Fields . . . . . . . . . . . . . . . . . . . . . . . 12 - 4.1.1. Hash Algorithm . . . . . . . . . . . . . . . . . . . . 12 - 4.1.2. Flag Fields . . . . . . . . . . . . . . . . . . . . . 12 - 4.1.3. Iterations . . . . . . . . . . . . . . . . . . . . . . 13 - 4.1.4. Salt Length . . . . . . . . . . . . . . . . . . . . . 13 - 4.1.5. Salt . . . . . . . . . . . . . . . . . . . . . . . . . 13 - 4.2. NSEC3PARAM RDATA Wire Format . . . . . . . . . . . . . . . 13 - 4.3. Presentation Format . . . . . . . . . . . . . . . . . . . 13 - 5. Calculation of the Hash . . . . . . . . . . . . . . . . . . . 14 - 6. Opt-Out . . . . . . . . . . . . . . . . . . . . . . . . . . . 15 - 7. Authoritative Server Considerations . . . . . . . . . . . . . 15 - 7.1. Zone Signing . . . . . . . . . . . . . . . . . . . . . . . 15 - 7.2. Zone Serving . . . . . . . . . . . . . . . . . . . . . . . 17 - 7.2.1. Closest Encloser Proof . . . . . . . . . . . . . . . . 18 - 7.2.2. Name Error Responses . . . . . . . . . . . . . . . . . 18 - 7.2.3. No Data Responses, QTYPE is not DS . . . . . . . . . . 19 - 7.2.4. No Data Responses, QTYPE is DS . . . . . . . . . . . . 19 - 7.2.5. Wildcard No Data Responses . . . . . . . . . . . . . . 19 - 7.2.6. Wildcard Answer Responses . . . . . . . . . . . . . . 19 - 7.2.7. Referrals to Unsigned Subzones . . . . . . . . . . . . 20 - 7.2.8. Responding to Queries for NSEC3 Owner Names . . . . . 20 - 7.2.9. Server Response to a Run-time Collision . . . . . . . 20 - 7.3. Secondary Servers . . . . . . . . . . . . . . . . . . . . 20 - 7.4. Zones Using Unknown Hash Algorithms . . . . . . . . . . . 21 - - - -Laurie, et al. Expires January 2, 2008 [Page 2] - -Internet-Draft nsec3 July 2007 - - - 7.5. Dynamic Update . . . . . . . . . . . . . . . . . . . . . . 21 - 8. Validator Considerations . . . . . . . . . . . . . . . . . . . 22 - 8.1. Responses with Unknown Hash Types . . . . . . . . . . . . 22 - 8.2. Verifying NSEC3 RRs . . . . . . . . . . . . . . . . . . . 22 - 8.3. Closest Encloser Proof . . . . . . . . . . . . . . . . . . 23 - 8.4. Validating Name Error Responses . . . . . . . . . . . . . 24 - 8.5. Validating No Data Responses, QTYPE is not DS . . . . . . 24 - 8.6. Validating No Data Responses, QTYPE is DS . . . . . . . . 24 - 8.7. Validating Wildcard No Data Responses . . . . . . . . . . 24 - 8.8. Validating Wildcard Answer Responses . . . . . . . . . . . 24 - 8.9. Validating Referrals to Unsigned Subzones . . . . . . . . 25 - 9. Resolver Considerations . . . . . . . . . . . . . . . . . . . 25 - 9.1. NSEC3 Resource Record Caching . . . . . . . . . . . . . . 25 - 9.2. Use of the AD Bit . . . . . . . . . . . . . . . . . . . . 25 - 10. Special Considerations . . . . . . . . . . . . . . . . . . . . 26 - 10.1. Domain Name Length Restrictions . . . . . . . . . . . . . 26 - 10.2. DNAME at the Zone Apex . . . . . . . . . . . . . . . . . . 26 - 10.3. Iterations . . . . . . . . . . . . . . . . . . . . . . . . 26 - 10.4. Transitioning a Signed Zone from NSEC to NSEC3 . . . . . . 27 - 10.5. Transitioning a Signed Zone From NSEC3 to NSEC . . . . . . 28 - 11. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 28 - 12. Security Considerations . . . . . . . . . . . . . . . . . . . 29 - 12.1. Hashing Considerations . . . . . . . . . . . . . . . . . . 30 - 12.1.1. Dictionary Attacks . . . . . . . . . . . . . . . . . . 30 - 12.1.2. Collisions . . . . . . . . . . . . . . . . . . . . . . 30 - 12.1.3. Transitioning to a New Hash Algorithm . . . . . . . . 30 - 12.1.4. Using High Iteration Values . . . . . . . . . . . . . 31 - 12.2. Opt-Out Considerations . . . . . . . . . . . . . . . . . . 32 - 12.3. Other Considerations . . . . . . . . . . . . . . . . . . . 32 - 13. References . . . . . . . . . . . . . . . . . . . . . . . . . . 33 - 13.1. Normative References . . . . . . . . . . . . . . . . . . . 33 - 13.2. Informative References . . . . . . . . . . . . . . . . . . 34 - Appendix A. Example Zone . . . . . . . . . . . . . . . . . . . . 34 - Appendix B. Example Responses . . . . . . . . . . . . . . . . . . 39 - B.1. Name Error . . . . . . . . . . . . . . . . . . . . . . . . 39 - B.2. No Data Error . . . . . . . . . . . . . . . . . . . . . . 41 - B.2.1. No Data Error, Empty Non-Terminal . . . . . . . . . . 42 - B.3. Referral to an Opt-Out Unsigned Zone . . . . . . . . . . . 43 - B.4. Wildcard Expansion . . . . . . . . . . . . . . . . . . . . 45 - B.5. Wildcard No Data Error . . . . . . . . . . . . . . . . . . 47 - B.6. DS Child Zone No Data Error . . . . . . . . . . . . . . . 48 - Appendix C. Special Considerations . . . . . . . . . . . . . . . 49 - C.1. Salting . . . . . . . . . . . . . . . . . . . . . . . . . 49 - C.2. Hash Collision . . . . . . . . . . . . . . . . . . . . . . 50 - C.2.1. Avoiding Hash Collisions During Generation . . . . . . 50 - C.2.2. Second Preimage Requirement Analysis . . . . . . . . . 51 - Authors' Addresses . . . . . . . . . . . . . . . . . . . . . . . . 51 - Intellectual Property and Copyright Statements . . . . . . . . . . 53 - - - -Laurie, et al. Expires January 2, 2008 [Page 3] - -Internet-Draft nsec3 July 2007 - - -1. Introduction - -1.1. Rationale - - The DNS Security Extensions included the NSEC RR to provide - authenticated denial of existence. Though the NSEC RR meets the - requirements for authenticated denial of existence, it introduces a - side-effect in that the contents of a zone can be enumerated. This - property introduces undesired policy issues. - - The enumeration is enabled by the set of NSEC records that exists in - a side signed zone. An NSEC record lists two names that are ordered - canonically, in order to show that nothing exists between the two - names. The complete set of NSEC records lists all the names in a - zone. It is trivial to enumerate the content of a zone by querying - for names that do not exist. - - An enumerated zone can be used, for example, as a source of probable - e-mail addresses for spam, or as a key for multiple WHOIS queries to - reveal registrant data which many registries may have legal - obligations to protect. Many registries therefore prohibit copying - of their zone data; however, the use of NSEC RRs renders these - policies unenforceable. - - A second problem is that the cost to cryptographically secure - delegations to unsigned zones is high, relative to the perceived - security benefit, in two cases: large, delegation-centric zones, and - zones where insecure delegations will be updated rapidly. In these - cases, the costs of maintaining the NSEC RR chain may be extremely - high and use of the "Opt-Out" convention may be more appropriate (for - these unsecured zones). - - This document presents the NSEC3 Resource Record which can be used as - an alternative to NSEC to mitigate these issues. - - Earlier work to address these issues include [I-D.jas-dnsext-no], - [RFC4956] and [I-D.laurie-dnsext-nsec2v2]. - -1.2. Reserved Words - - The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", - "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this - document are to be interpreted as described in [RFC2119]. - -1.3. Terminology - - The reader is assumed to be familiar with the basic DNS and DNSSEC - concepts described in [RFC1034], [RFC1035], [RFC4033], [RFC4034], - - - -Laurie, et al. Expires January 2, 2008 [Page 4] - -Internet-Draft nsec3 July 2007 - - - [RFC4035] and subsequent RFCs that update them: [RFC2136], [RFC2181] - and [RFC2308]. - - The following terminology is used throughout this document: - - Zone enumeration: the practice of discovering the full content of a - zone via successive queries. Zone enumeration was non-trivial - prior to the introduction of DNSSEC. - - Original owner name: the owner name corresponding to a hashed owner - name. - - Hashed owner name: the owner name created after applying the hash - function to an owner name. - - Hash order: the order in which hashed owner names are arranged - according to their numerical value, treating the leftmost (lowest - numbered) octet as the most significant octet. Note that this - order is the same as the canonical DNS name order specified in - [RFC4034] when the hashed owner names are in base32 encoded with - Extended Hex Alphabet [RFC4648]. - - Empty non-terminal: a domain name that owns no resource records, but - has one or more subdomains that do. - - Delegation: an NS RRSet with a name different from the current zone - apex (non-zone-apex), signifying a delegation to a child zone. - - Secure delegation: a name containing a delegation (NS RRSet), and a - signed DS RRSet, signifying a delegation to a signed child zone. - - Insecure delegation: a name containing a delegation (NS RRSet), but - lacking a DS RRSet, signifying a delegation to an unsigned child - zone. - - Opt-Out NSEC3 resource record: an NSEC3 resource record which has - the Opt-Out flag set to 1. - - Opt-Out zone: a zone with at least one Opt-Out NSEC3 RR. - - Closest encloser: the longest existing ancestor of a name. See also - section 3.3.1 of [RFC4592]. - - Closest provable encloser: the longest ancestor of a name that can - be proven to exist. Note that this is only different from the - closest encloser in an Opt-Out zone. - - - - - -Laurie, et al. Expires January 2, 2008 [Page 5] - -Internet-Draft nsec3 July 2007 - - - Next closer name: the name one label longer than the closest - provable encloser of a name. - - Base32: the "Base 32 Encoding with Extended Hex Alphabet" as - specified in [RFC4648]. Note that trailing padding characters - ("=") are not used in the NSEC3 specification. - - To cover: An NSEC3 RR is said to "cover" a name if the hash of the - name or "next closer" name falls between the owner name and the - next hashed owner name of the NSEC3. In other words, if it proves - the nonexistence of the name, either directly or by proving the - nonexistence of an ancestor of the name. - - To match: An NSEC3 RR is said to "match" a name if the owner name of - the NSEC3 RR is the same as the hashed owner name of that name. - - -2. Backwards Compatibility - - This specification describes a protocol change that is not generally - backwards compatible with [RFC4033], [RFC4034] and [RFC4035]. In - particular, security-aware resolvers that are unaware of this - specification (NSEC3-unaware resolvers) may fail to validate the - responses introduced by this document. - - In order to aid deployment, this specification uses a signaling - technique to prevent NSEC3-unaware resolvers from attempting to - validate responses from NSEC3-signed zones. - - This specification allocates two new DNSKEY algorithm identifiers for - this purpose. Algorithm XX, DSA-NSEC3-SHA1 [### RFC-editor update - required, temporarily, XX=131] is an alias for algorithm 3, DSA. - Algorithm YY, RSASHA1-NSEC3-SHA1 [### RFC-editor update required, - temporarily, YY=133] is an alias for algorithm 5, RSASHA1. These are - not new algorithms, they are additional identifiers for the existing - algorithms. - - Zones signed according to this specification MUST only use these - algorithm identifiers for their DNSKEY RRs. Because these new - identifiers will be unknown algorithms to existing, NSEC3-unaware - resolvers, those resolvers will then treat responses from the NSEC3 - signed zone as insecure, as detailed in [RFC4035], section 5.2. - - These algorithm identifiers are used with the NSEC3 hash algorithm - SHA1. Using other NSEC3 hash algorithms requires allocation of a new - alias (see Section 12.1.3). - - Security aware resolvers that are aware of this specification MUST - - - -Laurie, et al. Expires January 2, 2008 [Page 6] - -Internet-Draft nsec3 July 2007 - - - recognize the new algorithm identifiers and treat them as equivalent - to the algorithms that they alias. - - A methodology for transitioning from a DNSSEC signed zone to a zone - signed using NSEC3 is discussed in Section 10.4. - - -3. The NSEC3 Resource Record - - The NSEC3 Resource Record (RR) provides authenticated denial of - existence for DNS Resource Record Sets. - - The NSEC3 RR lists RR types present at the original owner name of the - NSEC3 RR. It includes the next hashed owner name in the hash order - of the zone. The complete set of NSEC3 RRs in a zone indicates which - RRSets exist for the original owner name of the RR and form a chain - of hashed owner names in the zone. This information is used to - provide authenticated denial of existence for DNS data. To provide - protection against zone enumeration, the owner names used in the - NSEC3 RR are cryptographic hashes of the original owner name - prepended as a single label to the name of the zone. The NSEC3 RR - indicates which hash function is used to construct the hash, which - salt is used, and how many iterations of the hash function are - performed over the original owner name. The hashing technique is - described fully in Section 5. - - Hashed owner names of unsigned delegations may be excluded from the - chain. An NSEC3 RR whose span covers the hash of an owner name or - "next closer" name of an unsigned delegation is referred to as an - Opt-Out NSEC3 RR and is indicated by the presence of a flag. - - The owner name for the NSEC3 RR is the base32 encoding of the hashed - owner name prepended as a single label to the name of the zone. - - The type value for the NSEC3 RR is NN. [### RFC-editor update - required, the examples assume NN=50] - - The NSEC3 RR RDATA format is class independent and is described - below. - - The class MUST be the same as the class of the original owner name. - - The NSEC3 RR SHOULD have the same TTL value as the SOA minimum TTL - field. This is in the spirit of negative caching [RFC2308]. - - - - - - - -Laurie, et al. Expires January 2, 2008 [Page 7] - -Internet-Draft nsec3 July 2007 - - -3.1. RDATA Fields - -3.1.1. Hash Algorithm - - The Hash Algorithm field identifies the cryptographic hash algorithm - used to construct the hash-value. - - The values for this field are defined in the NSEC3 hash algorithm - registry, described in Section 11. - -3.1.2. Flags - - The Flags field contains 8 one-bit flags that can be used to indicate - different processing. All undefined flags must be zero. The only - flag defined by this specification is the Opt-Out flag. - -3.1.2.1. Opt-Out Flag - - If the Opt-Out flag is set, the NSEC3 record covers zero or more - unsigned delegations. - - If the Opt-Out flag is clear, the NSEC3 record covers zero unsigned - delegations. - - The Opt-Out Flag indicates whether this NSEC3 RR may cover unsigned - delegations. It is the least significant bit in the Flags field. - See Section 6 for details about the use of this flag. - -3.1.3. Iterations - - The Iterations field defines the number of additional times the hash - function has been performed. More iterations result in greater - resiliency of the hash value against dictionary attacks, but at a - higher computational cost for both the server and resolver. See - Section 5 for details of the use of this field, and Section 10.3 for - limitations on the value. - -3.1.4. Salt Length - - The Salt Length field defines the length of the Salt field in octets, - ranging in value from 0 to 255. - -3.1.5. Salt - - The Salt field is appended to the original owner name before hashing - in order to defend against pre-calculated dictionary attacks. See - Section 5 for details on how the salt is used. - - - - -Laurie, et al. Expires January 2, 2008 [Page 8] - -Internet-Draft nsec3 July 2007 - - -3.1.6. Hash Length - - The Hash Length field defines the length of the Next Hashed Owner - Name field, ranging in value from 1 to 255 octets. - -3.1.7. Next Hashed Owner Name - - The Next Hashed Owner Name field contains the next hashed owner name - in hash order. This value is in binary format. Given the ordered - set of all hashed owner names, the Next Hashed Owner Name field - contains the hash of an owner name that immediately follows the owner - name of the given NSEC3 RR. The value of the Next Hashed Owner Name - field in the last NSEC3 RR in the zone is the same as the hashed - owner name of the first NSEC3 RR in the zone in hash order. Note - that, unlike the owner name of the NSEC3 RR, the value of this field - does not contain the appended zone name. - -3.1.8. Type Bit Maps - - The Type Bit Maps field identifies the RRSet types which exist at the - original owner name of the NSEC3 RR. - -3.2. NSEC3 RDATA Wire Format - - The RDATA of the NSEC3 RR is as shown below: - - 1 1 1 1 1 1 1 1 1 1 2 2 2 2 2 2 2 2 2 2 3 3 - 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 - +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ - | Hash Alg. | Flags | Iterations | - +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ - | Salt Length | Salt / - +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ - | Hash Length | Next Hashed Owner Name / - +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ - / Type Bit Maps / - +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ - - Hash Algorithm is a single octet. - - Flags field is a single octet, the Opt-Out flag is the least - significant bit, as shown below: - - 0 1 2 3 4 5 6 7 - +-+-+-+-+-+-+-+-+ - | |O| - +-+-+-+-+-+-+-+-+ - - - - -Laurie, et al. Expires January 2, 2008 [Page 9] - -Internet-Draft nsec3 July 2007 - - - Iterations is represented as a 16-bit unsigned integer, with the most - significant bit first. - - Salt Length is represented as an unsigned octet. Salt Length - represents the length of the Salt field in octets. If the value is - zero, the following Salt field is omitted. - - Salt, if present, is encoded as a sequence of binary octets. The - length of this field is determined by the preceding Salt Length - field. - - Hash Length is represented as an unsigned octet. Hash Length - represents the length of the Next Hashed Owner Name field in octets. - - The next hashed owner name is not base32 encoded, unlike the owner - name of the NSEC3 RR. It is the unmodified binary hash value. It - does not include the name of the containing zone. The length of this - field is determined by the preceding Hash Length field. - -3.2.1. Type Bit Maps Encoding - - The encoding of the Type Bit Maps field is the same as that used by - the NSEC RR, described in [RFC4034]. It is explained and clarified - here for clarity. - - The RR type space is split into 256 window blocks, each representing - the low-order 8 bits of the 16-bit RR type space. Each block that - has at least one active RR type is encoded using a single octet - window number (from 0 to 255), a single octet bitmap length (from 1 - to 32) indicating the number of octets used for the bitmap of the - window block, and up to 32 octets (256 bits) of bitmap. - - Blocks are present in the NSEC3 RR RDATA in increasing numerical - order. - - Type Bit Maps Field = ( Window Block # | Bitmap Length | Bitmap )+ - - where "|" denotes concatenation. - - Each bitmap encodes the low-order 8 bits of RR types within the - window block, in network bit order. The first bit is bit 0. For - window block 0, bit 1 corresponds to RR type 1 (A), bit 2 corresponds - to RR type 2 (NS), and so forth. For window block 1, bit 1 - corresponds to RR type 257, bit 2 to RR type 258. If a bit is set to - 1, it indicates that an RRSet of that type is present for the - original owner name of the NSEC3 RR. If a bit is set to 0, it - indicates that no RRSet of that type is present for the original - owner name of the NSEC3 RR. - - - -Laurie, et al. Expires January 2, 2008 [Page 10] - -Internet-Draft nsec3 July 2007 - - - Since bit 0 in window block 0 refers to the non-existing RR type 0, - it MUST be set to 0. After verification, the validator MUST ignore - the value of bit 0 in window block 0. - - Bits representing Meta-TYPEs or QTYPEs as specified in [RFC2929] - (section 3.1) or within the range reserved for assignment only to - QTYPEs and Meta-TYPEs MUST be set to 0, since they do not appear in - zone data. If encountered, they must be ignored upon reading. - - Blocks with no types present MUST NOT be included. Trailing zero - octets in the bitmap MUST be omitted. The length of the bitmap of - each block is determined by the type code with the largest numerical - value, within that block, among the set of RR types present at the - original owner name of the NSEC3 RR. Trailing octets not specified - MUST be interpreted as zero octets. - -3.3. Presentation Format - - The presentation format of the RDATA portion is as follows: - - o The Hash Algorithm field is represented as an unsigned decimal - integer. The value has a maximum of 255. - - o The Flags field is represented as an unsigned decimal integer. - The value has a maximum of 255. - - o The Iterations field is represented as an unsigned decimal - integer. The value is between 0 and 65535, inclusive. - - o The Salt Length field is not represented. - - o The Salt field is represented as a sequence of case-insensitive - hexadecimal digits. Whitespace is not allowed within the - sequence. The Salt field is represented as "-" (without the - quotes) when the Salt Length field has value 0. - - o The Hash Length field is not represented. - - o The Next Hashed Owner Name field is represented as an unpadded - sequence of case-insensitive base32 digits, without whitespace. - - o The Type Bit Maps field is represented as a sequence of RR type - mnemonics. When the mnemonic is not known, the TYPE - representation as described in [RFC3597] (section 5) MUST be used. - - - - - - - -Laurie, et al. Expires January 2, 2008 [Page 11] - -Internet-Draft nsec3 July 2007 - - -4. The NSEC3PARAM Record - - The NSEC3PARAM RR contains the NSEC3 parameters (hash algorithm, - flags, iterations and salt) needed by authoritative servers to - calculate hashed owner names. The presence of an NSEC3PARAM RR at a - zone apex indicates that the specified parameters may be used by - authoritative servers to choose an appropriate set of NSEC3 RRs for - negative responses. The NSEC3PARAM RR is not used by validators or - resolvers. - - If an NSEC3PARAM RR is present at the apex of a zone with a Flags - field value of zero, then there MUST be an NSEC3 RR using the same - hash algorithm, iterations and salt parameters present at every - hashed owner name in the zone. That is, the zone MUST contain a - complete set of NSEC3 RRs with the same hash algorithm, iterations - and salt parameters. - - The owner name for the NSEC3PARAM RR is the name of the zone apex. - - The type value for the NSEC3PARAM RR is MM. [### RFC-editor update - required, the examples assume MM=51] - - The NSEC3PARAM RR RDATA format is class independent and is described - below. - - The class MUST be the same as the NSEC3 RRs to which this RR refers. - -4.1. RDATA Fields - - The RDATA for this RR mirrors the first four fields in the NSEC3 RR. - -4.1.1. Hash Algorithm - - The Hash Algorithm field identifies the cryptographic hash algorithm - used to construct the hash-value. - - The acceptable values are the same as the corresponding field in the - NSEC3 RR. - -4.1.2. Flag Fields - - The Opt-Out flag is not used and is set to zero. - - All other flags are reserved for future use, and must be zero. - - NSEC3PARAM RRs with a Flags field value other than zero MUST be - ignored. - - - - -Laurie, et al. Expires January 2, 2008 [Page 12] - -Internet-Draft nsec3 July 2007 - - -4.1.3. Iterations - - The Iterations field defines the number of additional times the hash - is performed. - - Its acceptable values are the same as the corresponding field in the - NSEC3 RR. - -4.1.4. Salt Length - - The Salt Length field defines the length of the salt in octets, - ranging in value from 0 to 255. - -4.1.5. Salt - - The Salt field is appended to the original owner name before hashing. - -4.2. NSEC3PARAM RDATA Wire Format - - The RDATA of the NSEC3PARAM RR is as shown below: - - 1 1 1 1 1 1 1 1 1 1 2 2 2 2 2 2 2 2 2 2 3 3 - 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 - +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ - | Hash Alg. | Flags | Iterations | - +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ - | Salt Length | Salt / - +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ - - Hash Algorithm is a single octet. - - Flags field is a single octet. - - Iterations is represented as a 16-bit unsigned integer, with the most - significant bit first. - - Salt Length is represented as an unsigned octet. Salt Length - represents the length of the following Salt field in octets. If the - value is zero, the Salt field is omitted. - - Salt, if present, is encoded as a sequence of binary octets. The - length of this field is determined by the preceding Salt Length - field. - -4.3. Presentation Format - - The presentation format of the RDATA portion is as follows: - - - - -Laurie, et al. Expires January 2, 2008 [Page 13] - -Internet-Draft nsec3 July 2007 - - - o The Hash Algorithm field is represented as an unsigned decimal - integer. The value has a maximum of 255. - - o The Flags field is represented as an unsigned decimal integer. - The value has a maximum value of 255. - - o The Iterations field is represented as an unsigned decimal - integer. The value is between 0 and 65535, inclusive. - - o The Salt Length field is not represented. - - o The Salt field is represented as a sequence of case-insensitive - hexadecimal digits. Whitespace is not allowed within the - sequence. This field is represented as "-" (without the quotes) - when the Salt Length field is zero. - - -5. Calculation of the Hash - - The hash calculation uses three of the NSEC3 RDATA fields: Hash - Algorithm, Salt, and Iterations. - - Define H(x) to be the hash of x using the Hash Algorithm selected by - the NSEC3 RR, k to be the number of Iterations, and || to indicate - concatenation. Then define: - - IH(salt, x, 0) = H(x || salt), and - - IH(salt, x, k) = H(IH(salt, x, k-1) || salt), if k > 0 - - Then the calculated hash of an owner name is - - IH(salt, owner name, iterations), - - where the owner name is in the canonical form, defined as: - - The wire format of the owner name where: - - 1. The owner name is fully expanded (no DNS name compression) and - fully qualified; - - 2. All uppercase US-ASCII letters are replaced by the corresponding - lowercase US-ASCII letters; - - 3. If the owner name is a wildcard name, the owner name is in its - original unexpanded form, including the "*" label (no wildcard - substitution); - - - - -Laurie, et al. Expires January 2, 2008 [Page 14] - -Internet-Draft nsec3 July 2007 - - - This form is as defined in section 6.2 of [RFC4034]. - - The method to calculate the Hash is based on [RFC2898]. - - -6. Opt-Out - - In this specification, as in [RFC4033], [RFC4034] and [RFC4035], NS - RRSets at delegation points are not signed and may be accompanied by - a DS RRSet. With the Opt-Out bit clear, the security status of the - child zone is determined by the presence or absence of this DS RRSet, - cryptographically proven by the signed NSEC3 RR at the hashed owner - name of the delegation. Setting the Opt-Out flag modifies this by - allowing insecure delegations to exist within the signed zone without - a corresponding NSEC3 RR at the hashed owner name of the delegation. - - An Opt-Out NSEC3 RR is said to cover a delegation if the hash of the - owner name or "next closer" name of the delegation is between the - owner name of the NSEC3 RR and the next hashed owner name. - - An Opt-Out NSEC3 RR does not assert the existence or non-existence of - the insecure delegations that it may cover. This allows for the - addition or removal of these delegations without recalculating or re- - signing RRs in the NSEC3 RR chain. However, Opt-Out NSEC3 RRs do - assert the (non)existence of other, authoritative RRSets. - - An Opt-Out NSEC3 RR MAY have the same original owner name as an - insecure delegation. In this case, the delegation is proven insecure - by the lack of a DS bit in the type map and the signed NSEC3 RR does - assert the existence of the delegation. - - Zones using Opt-Out MAY contain a mixture of Opt-Out NSEC3 RRs and - non-Opt-Out NSEC3 RRs. If an NSEC3 RR is not Opt-Out, there MUST NOT - be any hashed owner names of insecure delegations (nor any other RRs) - between it and the name indicated by the next hashed owner name in - the NSEC3 RDATA. If it is Opt-Out, it MUST only cover hashed owner - names or hashed "next closer" names of insecure delegations. - - The effects of the Opt-Out flag on signing, serving, and validating - responses are covered in following sections. - - -7. Authoritative Server Considerations - -7.1. Zone Signing - - Zones using NSEC3 must satisfy the following properties: - - - - -Laurie, et al. Expires January 2, 2008 [Page 15] - -Internet-Draft nsec3 July 2007 - - - o Each owner name within the zone that owns authoritative RRSets - MUST have a corresponding NSEC3 RR. Owner names that correspond - to unsigned delegations MAY have a corresponding NSEC3 RR. - However, if there is not a corresponding NSEC3 RR, there MUST be - an Opt-Out NSEC3 RR that covers the "next closer" name to the - delegation. Other non-authoritative RRs are not represented by - NSEC3 RRs. - - o Each empty non-terminal MUST have a corresponding NSEC3 RR, unless - the empty non-terminal is only derived from an insecure delegation - covered by an Opt-Out NSEC3 RR. - - o The TTL value for any NSEC3 RR SHOULD be the same as the minimum - TTL value field in the zone SOA RR. - - o The Type Bit Maps field of every NSEC3 RR in a signed zone MUST - indicate the presence of all types present at the original owner - name, except for the types solely contributed by an NSEC3 RR - itself. Note that this means that the NSEC3 type itself will - never be present in the Type Bit Maps. - - The following steps describe a method of proper construction of NSEC3 - RRs. This is not the only such possible method. - - 1. Select the hash algorithm and the values for salt and iterations. - - 2. For each unique original owner name in the zone add an NSEC3 RR. - - * If Opt-Out is being used, owner names of unsigned delegations - MAY be excluded. - - * The owner name of the NSEC3 RR is the hash of the original - owner name, prepended as a single label to the zone name. - - * The Next Hashed Owner Name field is left blank for the moment. - - * If Opt-Out is being used, set the Opt-Out bit to one. - - * For collision detection purposes, optionally keep track of the - original owner name with the NSEC3 RR. - - * Additionally, for collision detection purposes, optionally - create an additional NSEC3 RR corresponding to the original - owner name with the asterisk label prepended (i.e., as if a - wildcard existed as a child of this owner name) and keep track - of this original owner name. Mark this NSEC3 RR as temporary. - - - - - -Laurie, et al. Expires January 2, 2008 [Page 16] - -Internet-Draft nsec3 July 2007 - - - 3. For each RRSet at the original owner name, set the corresponding - bit in the Type Bit Maps field. - - 4. If the difference in number of labels between the apex and the - original owner name is greater than 1, additional NSEC3 RRs need - to be added for every empty non-terminal between the apex and the - original owner name. This process may generate NSEC3 RRs with - duplicate hashed owner names. Optionally, for collision - detection, track the original owner names of these NSEC3 RRs and - create temporary NSEC3 RRs for wildcard collisions in a similar - fashion to step 1. - - 5. Sort the set of NSEC3 RRs into hash order. - - 6. Combine NSEC3 RRs with identical hashed owner names by replacing - them with a single NSEC3 RR with the Type Bit Maps field - consisting of the union of the types represented by the set of - NSEC3 RRs. If the original owner name was tracked, then - collisions may be detected when combining, as all of the matching - NSEC3 RRs should have the same original owner name. Discard any - possible temporary NSEC3 RRs. - - 7. In each NSEC3 RR, insert the next hashed owner name by using the - value of the next NSEC3 RR in hash order. The next hashed owner - name of the last NSEC3 RR in the zone contains the value of the - hashed owner name of the first NSEC3 RR in the hash order. - - 8. Finally, add an NSEC3PARAM RR with the same Hash Algorithm, - Iterations and Salt fields to the zone apex. - - If a hash collision is detected, then a new salt has to be chosen and - the signing process restarted. - -7.2. Zone Serving - - This specification modifies DNSSEC-enabled DNS responses generated by - authoritative servers. In particular, it replaces the use of NSEC - RRs in such responses with NSEC3 RRs. - - In the following response cases, the NSEC RRs dictated by DNSSEC - [RFC4035] are replaced with NSEC3 RRs that prove the same facts. - Responses that would not contain NSEC RRs are unchanged by this - specification. - - When returning responses containing multiple NSEC3 RRs, all of the - NSEC3 RRs MUST use the same hash algorithm, iteration, and salt - values. The Flags field value MUST be either zero or one. - - - - -Laurie, et al. Expires January 2, 2008 [Page 17] - -Internet-Draft nsec3 July 2007 - - -7.2.1. Closest Encloser Proof - - For many NSEC3 responses a proof of the closest encloser is required. - This is a proof that some ancestor of the QNAME is the closest - encloser of QNAME. - - This proof consists of (up to) two different NSEC3 RRs: - - o An NSEC3 RR that matches the closest (provable) encloser. - - o An NSEC3 RR that covers the "next closer" name to the closest - encloser. - - The first NSEC3 RR essentially proposes a possible closest encloser, - and proves that the particular encloser does, in fact, exist. The - second NSEC3 RR proves that the possible closest encloser is the - closest, and proves that QNAME (and any ancestors between QNAME and - the closest encloser) do not exist. - - These NSEC3 RRs are collectively referred to as the "closest encloser - proof" in the subsequent descriptions. - - For example, the closest encloser proof for the nonexistent - "alpha.beta.gamma.example." owner name might prove that - "gamma.example." is the closest encloser. This response would - contain the NSEC3 RR that matches "gamma.example.", and would also - contain the NSEC3 RR that covers "beta.gamma.example." (which is the - "next closer" name.) - - It is possible, when using Opt-Out (Section 6), to not be able to - prove the actual closest encloser because it is, or is part of an - insecure delegation covered by an Opt-Out span. In this case, - instead of proving the actual closest encloser, the closest provable - encloser is used. That is, the closest enclosing authoritative name - is used instead. In this case, the set of NSEC3 RRs used for this - proof is referred to as the "closest provable encloser proof." - -7.2.2. Name Error Responses - - To prove the nonexistence of QNAME a closest encloser proof and an - NSEC3 RR covering the (nonexistent) wildcard RR at the closest - encloser MUST be included in the response. This collection of (up - to) three NSEC3 RRs proves both that QNAME does not exist and that a - wildcard that could have matched QNAME also does not exist. - - For example, if "gamma.example." is the closest provable encloser to - QNAME, then a NSEC3 RR covering "*.gamma.example." is included in the - authority section of the response. - - - -Laurie, et al. Expires January 2, 2008 [Page 18] - -Internet-Draft nsec3 July 2007 - - -7.2.3. No Data Responses, QTYPE is not DS - - The server MUST include the NSEC3 RR that matches QNAME. This NSEC3 - RR MUST NOT have the bits corresponding to either the QTYPE or CNAME - set in its Type Bit Maps field. - -7.2.4. No Data Responses, QTYPE is DS - - If there is an NSEC3 RR that matches QNAME, the server MUST return it - in the response. The bits corresponding with DS and CNAME MUST NOT - be set in the Type Bit Maps field of this NSEC3 RR. - - If no NSEC3 RR matches QNAME, the server MUST return a closest - provable encloser proof for QNAME. The NSEC3 RR that covers the - "next closer" name MUST have the Opt-Out bit set (note that this is - true by definition - if the Opt-Out bit is not set, something has - gone wrong). - - If a server is authoritative for both sides of a zone cut at QNAME, - the server MUST return the proof from the parent side of the zone - cut. - -7.2.5. Wildcard No Data Responses - - If there is a wildcard match for QNAME, but QTYPE is not present at - that name, the response MUST include a closest encloser proof for - QNAME and MUST include the NSEC3 RR that matches the wildcard. This - combination proves both that QNAME itself does not exist and that a - wildcard that matches QNAME does exist. Note that the closest - encloser to QNAME MUST be the immediate ancestor of the wildcard RR - (if this is not the case, then something has gone wrong). - -7.2.6. Wildcard Answer Responses - - If there is a wildcard match for QNAME and QTYPE, then, in addition - to the expanded wildcard RRSet returned in the answer section of the - response, proof that the wildcard match was valid must be returned. - - This proof is accomplished by proving that both QNAME does not exist, - and that the closest encloser of the QNAME and the immediate ancestor - of the wildcard are the same (i.e., the correct wildcard matched). - - To this end, the NSEC3 RR that covers the "next closer" name of the - immediate ancestor of the wildcard MUST be returned. It is not - necessary to return an NSEC3 RR that matches the closest encloser, as - the existence of this closest encloser is proven by the presence of - the expanded wildcard in the response. - - - - -Laurie, et al. Expires January 2, 2008 [Page 19] - -Internet-Draft nsec3 July 2007 - - -7.2.7. Referrals to Unsigned Subzones - - If there is an NSEC3 RR that matches the delegation name, then that - NSEC3 RR MUST be included in the response. The DS bit in the type - bit maps of the NSEC3 RR MUST NOT be set. - - If the zone is Opt-Out, then there may not be an NSEC3 RR - corresponding to the delegation. In this case, the closest provable - encloser proof MUST be included in the response. The included NSEC3 - RR that covers the "next closer" name for the delegation MUST have - the Opt-Out flag set to one. (Note that this will be the case unless - something has gone wrong). - -7.2.8. Responding to Queries for NSEC3 Owner Names - - The owner names of NSEC3 RRs are not represented in the NSEC3 RR - chain like other owner names. As a result, each NSEC3 owner name is - covered by another NSEC3 RR, effectively negating the existence of - the NSEC3 RR. This is a paradox, since the existence of an NSEC3 RR - can be proven by its RRSIG RRSet. - - If the following conditions are all true: - - o The QNAME equals the owner name of an existing NSEC3 RR, and - - o No RR types exist at the QNAME, nor at any descendant of QNAME. - - Then the response MUST be constructed as a Name Error response - (Section 7.2.2). Or, in other words, the authoritative name server - will act, as if the owner name of the NSEC3 RR did not exist. - - Note that NSEC3 RRs are returned as a result of an AXFR or IXFR - query. - -7.2.9. Server Response to a Run-time Collision - - If the hash of a non-existing QNAME collides with the owner name of - an existing NSEC3 RR, then the server will be unable to return a - response that proves that QNAME does not exist. In this case, the - server MUST return a response with an RCODE of 2 (server failure). - - Note that with the hash algorithm specified in this document, SHA-1, - such collisions are highly unlikely. - -7.3. Secondary Servers - - Secondary servers (and perhaps other entities) need to reliably - determine which NSEC3 parameters (i.e., hash, salt and iterations) - - - -Laurie, et al. Expires January 2, 2008 [Page 20] - -Internet-Draft nsec3 July 2007 - - - are present at every hashed owner name, in order to be able to choose - an appropriate set of NSEC3 RRs for negative responses. This is - indicated by an NSEC3PARAM RR present at the zone apex. - - If there are multiple NSEC3PARAM RRs present, there are multiple - valid NSEC3 chains present. The server must choose one of them, but - may use any criteria to do so. - -7.4. Zones Using Unknown Hash Algorithms - - Zones that are signed according to this specification, but are using - an unrecognized NSEC3 hash algorithm value, cannot be effectively - served. Such zones SHOULD be rejected when loading. Servers SHOULD - respond with RCODE=2 (server failure) responses when handling queries - that would fall under such zones. - -7.5. Dynamic Update - - A zone signed using NSEC3 may accept dynamic updates [RFC2136]. - However, NSEC3 introduces some special considerations for dynamic - updates. - - Adding and removing names in a zone MUST account for the creation or - removal of empty non-terminals. - - o When removing a name with a corresponding NSEC3 RR, any NSEC3 RRs - corresponding to empty non-terminals created by that name MUST be - removed. Note that more than one name may be asserting the - existence of a particular empty non-terminal. - - o When adding a name that requires adding an NSEC3 RR, NSEC3 RRs - MUST also be added for any empty non-terminals that are created. - That is, if there is not an existing NSEC3 RR matching an empty - non-terminal, it must be created and added. - - The presence of Opt-Out in a zone means that some additions or - delegations of names will not require changes to the NSEC3 RRs in a - zone. - - o When removing a delegation RRSet, if that delegation does not have - a matching NSEC3 RR, then it was opted out. In this case, nothing - further needs to be done. - - o When adding a delegation RRSet, if the "next closer" name of the - delegation is covered by an existing Opt-Out NSEC3 RR, then the - delegation MAY be added without modifying the NSEC3 RRs in the - zone. - - - - -Laurie, et al. Expires January 2, 2008 [Page 21] - -Internet-Draft nsec3 July 2007 - - - The presence of Opt-Out in a zone means that when adding or removing - NSEC3 RRs, the value of the Opt-Out flag that should be set in new or - modified NSEC3 RRs is ambiguous. Servers SHOULD follow this set of - basic rules to resolve the ambiguity. - - The central concept to these rules is that the state of the Opt-Out - flag of the covering NSEC3 RR is preserved. - - o When removing an NSEC3 RR, the value of the Opt-Out flag for the - previous NSEC3 RR (the one whose next hashed owner name is - modified) should not be changed. - - o When adding an NSEC3 RR, the value of the Opt-Out flag is set to - the value of the Opt-Out flag of the NSEC3 RR that previously - covered the owner name of the NSEC3 RR. That is, the now previous - NSEC3 RR. - - If the zone in question is consistent with its use of the Opt-Out - flag (that is, all NSEC3 RRs in the zone have the same value for the - flag) then these rules will retain that consistency. If the zone is - not consistent in the use of the flag (i.e., a partially Opt-Out - zone), then these rules will not retain the same pattern of use of - the Opt-Out flag. - - For zones that partially use the Opt-Out flag, if there is a logical - pattern for that use, the pattern could be maintained by using a - local policy on the server. - - -8. Validator Considerations - -8.1. Responses with Unknown Hash Types - - A validator MUST ignore NSEC3 RRs with unknown hash types. The - practical result of this is that responses containing only such NSEC3 - RRs will generally be considered bogus. - -8.2. Verifying NSEC3 RRs - - A validator MUST ignore NSEC3 RRs with a Flag fields value other than - zero or one. - - A validator MAY treat a response as bogus if the response contains - NSEC3 RRs that contain different values for hash algorithm, - iterations, or salt from each other for that zone. - - - - - - -Laurie, et al. Expires January 2, 2008 [Page 22] - -Internet-Draft nsec3 July 2007 - - -8.3. Closest Encloser Proof - - In order to verify a closest encloser proof, the validator MUST find - the longest name, X, such that - - o X is an ancestor of QNAME that is matched by an NSEC3 RR present - in the response. This is a candidate for the closest encloser. - And: - - o The name one label longer than X (but still an ancestor of--or - equal to--QNAME) is covered by an NSEC3 RR present in the - response. - - One possible algorithm for verifying this proof is as follows: - - 1. Set SNAME=QNAME. Clear the flag. - - 2. Check whether SNAME exists: - - * If there is no NSEC3 RR in the response that matches SNAME - (i.e., an NSEC3 RR whose owner name is the same as the hash of - SNAME, prepended as a single label to the zone name), clear - the flag. - - * If there is an NSEC3 RR in the response that covers SNAME, set - the flag. - - * If there is a matching NSEC3 RR in the response and the flag - was set, then the proof is complete, and SNAME is the closest - encloser. - - * If there is a matching NSEC3 RR in the response, but the flag - is not set, then the response is bogus. - - 3. Truncate SNAME by one label from the left, go to step 2. - - Once the closest encloser has been discovered, the validator MUST - check that the NSEC3 RR that has the closest encloser as the original - owner name is from the proper zone. The DNAME type bit must not be - set and the NS type bit may only be set if the SOA type bit is set. - If this is not the case, it would be an indication that an attacker - is using them to falsely deny the existence of RRs for which the - server is not authoritative. - - In the following descriptions, the phrase "a closest (provable) - encloser proof for X" means that the algorithm above (or an - equivalent algorithm) proves that X does not exist by proving that an - ancestor of X is its closest encloser. - - - -Laurie, et al. Expires January 2, 2008 [Page 23] - -Internet-Draft nsec3 July 2007 - - -8.4. Validating Name Error Responses - - A validator MUST verify that there is a closest encloser proof for - QNAME present in the response and that there is an NSEC3 RR that - covers the wildcard at the closest encloser (i.e., the name formed by - prepending the asterisk label to the closest encloser.) - -8.5. Validating No Data Responses, QTYPE is not DS - - The validator MUST verify that an NSEC3 RR that matches QNAME is - present and that both the QTYPE and the CNAME type are not set in its - Type Bit Maps field. - - Note that this test also covers the case where the NSEC3 RR exists - because it corresponds to an empty non-terminal, in which case the - NSEC3 RR will have an empty Type Bit Maps field. - -8.6. Validating No Data Responses, QTYPE is DS - - If there is an NSEC3 RR that matches QNAME present in the response, - then that NSEC3 RR MUST NOT have the bits corresponding to DS and - CNAME set in its Type Bit Maps field. - - If there is no such NSEC3 RR, then the validator MUST verify that a - closest provable encloser proof for QNAME is present in the response, - and that the NSEC3 RR that covers the "next closer" name has the Opt- - Out bit set. - -8.7. Validating Wildcard No Data Responses - - The validator MUST verify a closest encloser proof for QNAME and MUST - find an NSEC3 RR present in the response that matches the wildcard - name generated by prepending the asterisk label to the closest - encloser. Furthermore, the bits corresponding to both QTYPE and - CNAME MUST NOT be set in the wildcard matching NSEC3 RR. - -8.8. Validating Wildcard Answer Responses - - The verified wildcard answer RRSet in the response provides the - validator with a (candidate) closest encloser for QNAME. This - closest encloser is the immediate ancestor to the generating - wildcard. - - Validators MUST verify that there is an NSEC3 RR that covers the - "next closer" name to QNAME present in the response. This proves - that QNAME itself did not exist and that the correct wildcard was - used to generate the response. - - - - -Laurie, et al. Expires January 2, 2008 [Page 24] - -Internet-Draft nsec3 July 2007 - - -8.9. Validating Referrals to Unsigned Subzones - - The delegation name in a referral is the owner name of the NS RRSet - present in the authority section of the referral response. - - If there is an NSEC3 RR present in the response that matches the - delegation name, then the validator MUST ensure that the NS bit is - set and that the DS bit is not set in the Type Bit Maps field of the - NSEC3 RR. The validator MUST also ensure that the NSEC3 RR is from - the correct (i.e., parent) zone. This is done by ensuring that the - SOA bit is not set in the Type Bit Maps field of this NSEC3 RR. - - Note that the presence of an NS bit implies the absence of a DNAME - bit, so there is no need to check for the DNAME bit in the Type Bit - Maps field of the NSEC3 RR. - - If there is no NSEC3 RR present that matches the delegation name, - then the validator MUST verify a closest provable encloser proof for - the delegation name. The validator MUST verify that the Opt-Out bit - is set in the NSEC3 RR that covers the "next closer" name to the - delegation name. - - -9. Resolver Considerations - -9.1. NSEC3 Resource Record Caching - - Caching resolvers MUST be able to retrieve the appropriate NSEC3 RRs - when returning responses that contain them. In DNSSEC [RFC4035], in - many cases it is possible to find the correct NSEC RR to return in a - response by name (e.g., when returning a referral, the NSEC RR will - always have the same owner name as the delegation.) With this - specification, that will not be true, nor will a cache be able to - calculate the name(s) of the appropriate NSEC3 RR(s). - Implementations may need to use new methods for caching and - retrieving NSEC3 RRs. - -9.2. Use of the AD Bit - - The AD bit, as defined by [RFC4035], MUST NOT be set when returning a - response containing a closest (provable) encloser proof in which the - NSEC3 RR that covers the "next closer" name has the Opt-Out bit set. - - This rule is based on what this closest encloser proof actually - proves: names that would be covered by the Opt-Out NSEC3 RR may or - may not exist as insecure delegations. As such, not all the data in - responses containing such closest encloser proofs will have been - cryptographically verified, so the AD bit cannot be set. - - - -Laurie, et al. Expires January 2, 2008 [Page 25] - -Internet-Draft nsec3 July 2007 - - -10. Special Considerations - -10.1. Domain Name Length Restrictions - - Zones signed using this specification have additional domain name - length restrictions imposed upon them. In particular, zones with - names that, when converted into hashed owner names, exceed the 255 - octet length limit imposed by [RFC1035] cannot use this - specification. - - The actual maximum length of a domain name in a particular zone - depends on both the length of the zone name (versus the whole domain - name) and the particular hash function used. - - As an example, SHA-1 produces a hash of 160 bits. The base-32 - encoding of 160 bits results in 32 characters. The 32 characters are - prepended to the name of the zone as a single label, which includes a - length field of a single octet. The maximum length of the zone name, - when using SHA-1, is 222 octets (255 - 33). - -10.2. DNAME at the Zone Apex - - The DNAME specification [RFC2672] section 3 has a 'no-descendants' - limitation. If a DNAME RR is present at node N, there MUST be no - data at any descendant of N. - - If N is the apex of the zone, there will be NSEC3 and RRSIG types - present at descendants of N. This specification updates the DNAME - specification to allow NSEC3 and RRSIG types at descendants of the - apex regardless of the existence of DNAME at the apex. - -10.3. Iterations - - Setting the number of iterations used allows the zone owner to choose - the cost of computing a hash, and so the cost of generating a - dictionary. Note that this is distinct from the effect of salt, - which prevents the use of a single precomputed dictionary for all - time. - - Obviously the number of iterations also affects the zone owner's cost - of signing and serving the zone as well as the validator's cost of - verifying responses from the zone. We therefore impose an upper - limit on the number of iterations. We base this on the number of - iterations that approximates the cost of verifying an RRSet. - - The limits, therefore, are based on the size of the smallest zone - signing key, rounded up to the nearest table value (or rounded down - if the key is larger than the largest table value.) - - - -Laurie, et al. Expires January 2, 2008 [Page 26] - -Internet-Draft nsec3 July 2007 - - - A zone owner MUST NOT use a value higher than shown in the table - below for iterations for the given key size. A resolver MAY treat a - response with a higher value as insecure, after the validator has - verified that the signature over the NSEC3 RR is correct. - - +----------+------------+ - | Key Size | Iterations | - +----------+------------+ - | 1024 | 150 | - | 2048 | 500 | - | 4096 | 2,500 | - +----------+------------+ - - This table is based on an approximation of the ratio between the cost - of an SHA-1 calculation and the cost of an RSA verification for keys - of size 1024 bits (150 to 1), 2048 bits (500 to 1) and 4096 bits - (2500 to 1). - - The ratio between SHA-1 calculation and DSA verification is higher - (1500 to 1 for keys of size 1024). A higher iteration count degrades - performance, while DSA verification is already more expensive than - RSA for the same key size. Therefore the values in the table MUST be - used independent of the key algorithm. - -10.4. Transitioning a Signed Zone from NSEC to NSEC3 - - When transitioning an already signed and trusted zone to this - specification, care must be taken to prevent client validation - failures during the process. - - The basic procedure is as follows: - - 1. Transition all DNSKEYs to DNSKEYs using the algorithm aliases - described in Section 2. The actual method for safely and - securely changing the DNSKEY RRSet of the zone is outside the - scope of this specification. However, the end result MUST be - that all DS RRs in the parent use the specified algorithm - aliases. - - After this transition is complete, all NSEC3-unaware clients will - treat the zone as insecure. At this point, the authoritative - server still returns negative and wildcard responses that contain - NSEC RRs. - - 2. Add signed NSEC3 RRs to the zone, either incrementally or all at - once. If adding incrementally, then the last RRSet added MUST be - the NSEC3PARAM RRSet. - - - - -Laurie, et al. Expires January 2, 2008 [Page 27] - -Internet-Draft nsec3 July 2007 - - - 3. Upon the addition of the NSEC3PARAM RRSet, the server switches to - serving negative and wildcard responses with NSEC3 RRs according - to this specification. - - 4. Remove the NSEC RRs either incrementally or all at once. - -10.5. Transitioning a Signed Zone From NSEC3 to NSEC - - To safely transition back to a DNSSEC [RFC4035] signed zone, simply - reverse the procedure above: - - 1. Add NSEC RRs incrementally or all at once. - - 2. Remove the NSEC3PARAM RRSet. This will signal the server to use - the NSEC RRs for negative and wildcard responses. - - 3. Remove the NSEC3 RRs either incrementally or all at once. - - 4. Transition all of the DNSKEYs to DNSSEC algorithm identifiers. - After this transition is complete, all NSEC3-unaware clients will - treat the zone as secure. - - -11. IANA Considerations - - This document updates the IANA registry "DOMAIN NAME SYSTEM - PARAMETERS" [http://www.iana.org/assignments/dns-parameters] in sub- - registry "TYPES", by defining two new types. Section 3 defines the - NSEC3 RR type NN, (value 50 suggested). Section 4 defines the - NSEC3PARAM RR type MM (value 51 suggested). - - This document updates the IANA registry "DNS SECURITY ALGORITHM - NUMBERS - per [RFC4035]" - http://www.iana.org/assignments/dns-sec-alg-numbers]. Section 2 - defines the aliases DSA-NSEC3-SHA1 (XX) and RSASHA1-NSEC3-SHA1 (YY) - for respectively existing registrations DSA and RSASHA1 in - combination with NSEC3 hash algorithm SHA1. - - Since these algorithm numbers are aliases for existing DNSKEY - algorithm numbers, the flags that exist for the original algorithm - are valid for the alias algorithm. - - This document creates a new IANA registry for NSEC3 flags. This - registry should be named "DNSSEC NSEC3 Flags". The initial contents - of this registry are: - - - - - - -Laurie, et al. Expires January 2, 2008 [Page 28] - -Internet-Draft nsec3 July 2007 - - - 0 1 2 3 4 5 6 7 - +---+---+---+---+---+---+---+---+ - | | | | | | | |Opt| - | | | | | | | |Out| - +---+---+---+---+---+---+---+---+ - - bit 7 is the Opt-Out flag. - - bits 0 - 6 are available for assignment. - - Assignment of additional NSEC3 Flags in this registry requires IETF - Standards Action [RFC2434]. - - This document creates a new IANA registry for NSEC3PARAM flags. This - registry should be named "DNSSEC NSEC3PARAM Flags". The initial - contents of this registry are: - - 0 1 2 3 4 5 6 7 - +---+---+---+---+---+---+---+---+ - | | | | | | | | 0 | - +---+---+---+---+---+---+---+---+ - - bit 7 is reserved and must be 0. - - bits 0 - 6 are available for assignment. - - Assignment of additional NSEC3PARAM Flags in this registry requires - IETF Standards Action [RFC2434]. - - Finally, this document creates a new IANA registry for NSEC3 hash - algorithms. This registry should be named "DNSSEC NSEC3 Hash - Algorithms". The initial contents of this registry are: - - 0 is Reserved - - 1 is SHA-1. - - 2-255 Available for assignment - - Assignment of additional NSEC3 hash algorithms in this registry - requires IETF Standards Action [RFC2434]. - - -12. Security Considerations - - - - - - - -Laurie, et al. Expires January 2, 2008 [Page 29] - -Internet-Draft nsec3 July 2007 - - -12.1. Hashing Considerations - -12.1.1. Dictionary Attacks - - The NSEC3 RRs are still susceptible to dictionary attacks (i.e. the - attacker retrieves all the NSEC3 RRs, then calculates the hashes of - all likely domain names, comparing against the hashes found in the - NSEC3 RRs, and thus enumerating the zone). These are substantially - more expensive than enumerating the original NSEC RRs would have - been, and in any case, such an attack could also be used directly - against the name server itself by performing queries for all likely - names, though this would obviously be more detectable. The expense - of this off-line attack can be chosen by setting the number of - iterations in the NSEC3 RR. - - Zones are also susceptible to a pre-calculated dictionary attack -- - that is, a list of hashes for all likely names is computed once, then - NSEC3 RR is scanned periodically and compared against the precomputed - hashes. This attack is prevented by changing the salt on a regular - basis. - - The salt SHOULD be at least 64 bits long and unpredictable, so that - an attacker cannot anticipate the value of the salt and compute the - next set of dictionaries before the zone is published. - -12.1.2. Collisions - - Hash collisions between QNAME and the owner name of an NSEC3 RR may - occur. When they do, it will be impossible to prove the non- - existence of the colliding QNAME. However, with SHA-1, this is - highly unlikely (on the order of 1 in 2^160). Note that DNSSEC - already relies on the presumption that a cryptographic hash function - is second pre-image resistant, since these hash functions are used - for generating and validating signatures and DS RRs. - -12.1.3. Transitioning to a New Hash Algorithm - - Since validators are instructed to ignore NSEC3 RRs with unknown hash - algorithms, simply using a new or unknown hash algorithm directly - will lead to validation failures with clients that understand NSEC3 - but do not understand the hash algorithm. - - When transitioning to a new hash algorithm, care must be taken to - prevent client validation failures during the process. This is done - using a similar procedure to transitioning from NSEC to NSEC3 - (Section 10.4) - - The basic procedure is as follows: - - - -Laurie, et al. Expires January 2, 2008 [Page 30] - -Internet-Draft nsec3 July 2007 - - - 1. Transition all DNSKEYs to DNSKEYs using the algorithm aliases - allocated for the new NSEC3 hash algorithm. The actual method - for safely and securely changing the DNSKEY RRSet of the zone is - outside the scope of this specification. However, the end result - MUST be that all DS RRs in the parent use the specified algorithm - aliases. - - After this transition is complete, all clients unaware of the new - hash algorithm will treat the zone as insecure. At this point, - the authoritative server still returns negative and wildcard - responses that contain NSEC3 RRs with the known hash function. - - 2. Add signed NSEC3 RRs with the new hash algorithm to the zone, - either incrementally or all at once. If adding incrementally, - then the last RRSet added MUST be the NSEC3PARAM RRSet containing - the new hash algorithm. - - 3. Upon the addition of the NSEC3PARAM RR containing the new hash - algorithm, and after the removal of the NSEC3PARAM RR containing - the old hash algorithm, the server switches to serving negative - and wildcard responses with NSEC3 RRs containing the new hash - algorithm. - - 4. Remove the NSEC3 RRs containing the old hash algorithm either - incrementally or all at once. - -12.1.4. Using High Iteration Values - - Since validators should treat responses containing NSEC3 RRs with - high iteration values as insecure, presence of just one signed NSEC3 - RR with a high iteration value in a zone provides attackers with a - possible downgrade attack. - - The attack is simply to remove any existing NSEC3 RRs from a - response, and replace or add a single (or multiple) NSEC3 RR that - uses a high iterations value to the response. Validators will then - be forced to treat the response as insecure. This attack would be - effective only when all of following conditions are met: - - o There is at least one signed NSEC3 RR that uses a high iterations - value present in the zone. - - o The attacker has access to one or more of these NSEC3 RRs. This - is trivially true when the NSEC3 RRs with high iterations values - are being returned in typical responses, but may also be true if - the attacker can access the zone via AXFR or IXFR queries, or any - other methodology. - - - - -Laurie, et al. Expires January 2, 2008 [Page 31] - -Internet-Draft nsec3 July 2007 - - - Using a high number of iterations also introduces an additional - denial-of-service opportunity against servers, since servers must - calculate several hashes per negative or wildcard response. - -12.2. Opt-Out Considerations - - The Opt-Out Flag (O) allows for unsigned names, in the form of - delegations to unsigned zones, to exist within an otherwise signed - zone. All unsigned names are, by definition, insecure, and their - validity or existence cannot be cryptographically proven. - - In general: - - o Resource records with unsigned names (whether existing or not) - suffer from the same vulnerabilities as RRs in an unsigned zone. - These vulnerabilities are described in more detail in [RFC3833] - (note in particular sections 2.3, "Name Chaining" and 2.6, - "Authenticated Denial of Domain Names"). - - o Resource records with signed names have the same security whether - or not Opt-Out is used. - - Note that with or without Opt-Out, an insecure delegation may be - undetectably altered by an attacker. Because of this, the primary - difference in security when using Opt-Out is the loss of the ability - to prove the existence or nonexistence of an insecure delegation - within the span of an Opt-Out NSEC3 RR. - - In particular, this means that a malicious entity may be able to - insert or delete RRs with unsigned names. These RRs are normally NS - RRs, but this also includes signed wildcard expansions (while the - wildcard RR itself is signed, its expanded name is an unsigned name). - - Note that being able to add a delegation is functionally equivalent - to being able to add any RR type: an attacker merely has to forge a - delegation to name server under his/her control and place whatever - RRs needed at the subzone apex. - - While in particular cases, this issue may not present a significant - security problem, in general it should not be lightly dismissed. - Therefore, it is strongly RECOMMENDED that Opt-Out be used sparingly. - In particular, zone signing tools SHOULD NOT default to using Opt- - Out, and MAY choose to not support Opt-Out at all. - -12.3. Other Considerations - - Walking the NSEC3 RRs will reveal the total number of RRs in the zone - (plus empty non-terminals), and also what types there are. This - - - -Laurie, et al. Expires January 2, 2008 [Page 32] - -Internet-Draft nsec3 July 2007 - - - could be mitigated by adding dummy entries, but certainly an upper - limit can always be found. - - -13. References - -13.1. Normative References - - [RFC1034] Mockapetris, P., "Domain names - concepts and facilities", - STD 13, RFC 1034, November 1987. - - [RFC1035] Mockapetris, P., "Domain names - implementation and - specification", STD 13, RFC 1035, November 1987. - - [RFC2119] Bradner, S., "Key words for use in RFCs to Indicate - Requirement Levels", BCP 14, RFC 2119, March 1997. - - [RFC2136] Vixie, P., Thomson, S., Rekhter, Y., and J. Bound, - "Dynamic Updates in the Domain Name System (DNS UPDATE)", - RFC 2136, April 1997. - - [RFC2181] Elz, R. and R. Bush, "Clarifications to the DNS - Specification", RFC 2181, July 1997. - - [RFC2308] Andrews, M., "Negative Caching of DNS Queries (DNS - NCACHE)", RFC 2308, March 1998. - - [RFC2434] Narten, T. and H. Alvestrand, "Guidelines for Writing an - IANA Considerations Section in RFCs", BCP 26, RFC 2434, - October 1998. - - [RFC2929] Eastlake, D., Brunner-Williams, E., and B. Manning, - "Domain Name System (DNS) IANA Considerations", BCP 42, - RFC 2929, September 2000. - - [RFC3597] Gustafsson, A., "Handling of Unknown DNS Resource Record - (RR) Types", RFC 3597, September 2003. - - [RFC4033] Arends, R., Austein, R., Larson, M., Massey, D., and S. - Rose, "DNS Security Introduction and Requirements", - RFC 4033, March 2005. - - [RFC4034] Arends, R., Austein, R., Larson, M., Massey, D., and S. - Rose, "Resource Records for the DNS Security Extensions", - RFC 4034, March 2005. - - [RFC4035] Arends, R., Austein, R., Larson, M., Massey, D., and S. - Rose, "Protocol Modifications for the DNS Security - - - -Laurie, et al. Expires January 2, 2008 [Page 33] - -Internet-Draft nsec3 July 2007 - - - Extensions", RFC 4035, March 2005. - - [RFC4648] Josefsson, S., "The Base16, Base32, and Base64 Data - Encodings", RFC 4648, October 2006. - -13.2. Informative References - - [I-D.jas-dnsext-no] - Josefsson, S., "Authenticating denial of existence in DNS - with minimum disclosure", draft-jas-dnsext-no-00 (work in - progress), July 2000. - - [I-D.laurie-dnsext-nsec2v2] - Laurie, B., "DNSSEC NSEC2 Owner and RDATA Format", - draft-laurie-dnsext-nsec2v2-00 (work in progress), - December 2004. - - [RFC2672] Crawford, M., "Non-Terminal DNS Name Redirection", - RFC 2672, August 1999. - - [RFC2898] Kaliski, B., "PKCS #5: Password-Based Cryptography - Specification Version 2.0", RFC 2898, September 2000. - - [RFC3833] Atkins, D. and R. Austein, "Threat Analysis of the Domain - Name System (DNS)", RFC 3833, August 2004. - - [RFC4592] Lewis, E., "The Role of Wildcards in the Domain Name - System", RFC 4592, July 2006. - - [RFC4956] Arends, R., Kosters, M., and D. Blacka, "DNS Security - (DNSSEC) Opt-In", RFC 4956, July 2007. - - -Appendix A. Example Zone - - This is a zone showing its NSEC3 RRs. They can also be used as test - vectors for the hash algorithm. - - The overall TTL and class are specified in the SOA RR, and are - subsequently omitted for clarity. - - The zone is preceded by a list that contains the hashes of the - original ownernames. - - - ; H(example) = 0p9mhaveqvm6t7vbl5lop2u3t2rp3tom - ; H(a.example) = 35mthgpgcu1qg68fab165klnsnk3dpvl - ; H(ai.example) = gjeqe526plbf1g8mklp59enfd789njgi - - - -Laurie, et al. Expires January 2, 2008 [Page 34] - -Internet-Draft nsec3 July 2007 - - - ; H(ns1.example) = 2t7b4g4vsa5smi47k61mv5bv1a22bojr - ; H(ns2.example) = q04jkcevqvmu85r014c7dkba38o0ji5r - ; H(w.example) = k8udemvp1j2f7eg6jebps17vp3n8i58h - ; H(*.w.example) = r53bq7cc2uvmubfu5ocmm6pers9tk9en - ; H(x.w.example) = b4um86eghhds6nea196smvmlo4ors995 - ; H(y.w.example) = ji6neoaepv8b5o6k4ev33abha8ht9fgc - ; H(x.y.w.example) = 2vptu5timamqttgl4luu9kg21e0aor3s - ; H(xx.example) = t644ebqk9bibcna874givr6joj62mlhv - ; H(2t7b4g4vsa5smi47k61mv5bv1a22bojr.example) - ; = kohar7mbb8dc2ce8a9qvl8hon4k53uhi - example. 3600 IN SOA ns1.example. bugs.x.w.example. 1 3600 300 ( - 3600000 3600 ) - RRSIG SOA 133 1 3600 20150420235959 20051021000000 ( - 62827 example. - hNIkW1xzn+c+9P3W7PUVVptI72xEmOtn+eqQ - ux0BE7Pfc6ikx4m7ivOVWETjbwHjqfY0X5G+ - rynLZNqsbLm40Q== ) - NS ns1.example. - NS ns2.example. - RRSIG NS 133 1 3600 20150420235959 20051021000000 ( - 62827 example. - D9+iBwcbeKL5+TorTfYn4/pLr2lSFwyGYCyM - gfq4TpFaZpxrCJPLxHbKjdkR18jAt7+SR7B5 - JpiZcff2Cj2B0w== ) - MX 1 xx.example. - RRSIG MX 133 1 3600 20150420235959 20051021000000 ( - 62827 example. - jsGuTpXTTrZHzUKnViUpJ8YyGNpDd6n/sy2g - HnSC0nj2jPxTC5VENLo3GxSpCSA5DlAz57p+ - RllUJk3DWktkjw== ) - DNSKEY 256 3 133 ( - AQO0gEmbZUL6xbD/xQczHbnwYnf+jQjwz/sU - 5k44rHTt0Ty+3aOdYoome9TjGMhwkkGby1TL - ExXT48OGGdbfIme5 ) - DNSKEY 257 3 133 ( - AQOnsGyJvywVjYmiLbh0EwIRuWYcDiB/8blX - cpkoxtpe19Oicv6Zko+8brVsTMeMOpcUeGB1 - zsYKWJ7BvR2894hX ) - RRSIG DNSKEY 133 1 3600 20150420235959 ( - 20051021000000 22088 example. - Xpo9ptByXb8M1JR1i0KuRmKGc/YeOLcc6Ptn - RJOx6ADLSL2mU6AYX5tAJRMTKTXk6waLIaxu - liqUBOkCjLUZMw== ) - NSEC3PARAM 1 0 12 aabbccdd - RRSIG NSEC3PARAM 133 1 3600 20150420235959 ( - 20051021000000 62827 example. - pwUfI8cF9JJn5dTWI24nJy92HYrRPtPgHtgi - jAlKx9QELe68pLKuGU/8Sf87kyV7yMXJYVhf - - - -Laurie, et al. Expires January 2, 2008 [Page 35] - -Internet-Draft nsec3 July 2007 - - - HIB8wmHllsqM+g== ) - 0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. NSEC3 1 1 12 aabbccdd ( - 2t7b4g4vsa5smi47k61mv5bv1a22bojr MX DNSKEY NS - SOA NSEC3PARAM RRSIG ) - RRSIG NSEC3 133 2 3600 20150420235959 ( - 20051021000000 62827 example. - rn2tv99+9StXbc7JaEnjT1+8I8f2vVOMOIbF - xzlrn94lQLxEOYxQR4SrxDRP4/fC54Jui0Ix - 4eI9tMfaTVgehQ== ) - 2t7b4g4vsa5smi47k61mv5bv1a22bojr.example. A 192.0.2.127 - RRSIG A 133 2 3600 20150420235959 20051021000000 ( - 62827 example. - GtJTFlvT5eYaK3rNUPQjpCKoIefvWZxQrDxU - jYsmoIWdLOVOuD5ZSDDQA3anDctOHdA/XbXn - o2uyWso1OzVlgg== ) - NSEC3 1 1 12 aabbccdd ( - 2vptu5timamqttgl4luu9kg21e0aor3s A RRSIG ) - RRSIG NSEC3 133 2 3600 20150420235959 ( - 20051021000000 62827 example. - fJER1Z3nGoN0HmZm99lqNLSpIf7jLXTMoGm2 - k4gIwlc0R4DztJp6Sq37OV6XnGdre4MfgRpB - mAcgpPWC5A5eiw== ) - 2vptu5timamqttgl4luu9kg21e0aor3s.example. NSEC3 1 1 12 aabbccdd ( - 35mthgpgcu1qg68fab165klnsnk3dpvl MX RRSIG ) - RRSIG NSEC3 133 2 3600 20150420235959 ( - 20051021000000 62827 example. - os2mHXmu3bsaWu0XzT1R61fHL1a3LvyQ6bKq - oKokSyJ0ch0jBqEdxP2BqUe0WW0ja19fQGCG - 8Bc+L9MbAeYsrw== ) - 35mthgpgcu1qg68fab165klnsnk3dpvl.example. NSEC3 1 1 12 aabbccdd ( - b4um86eghhds6nea196smvmlo4ors995 NS DS RRSIG ) - RRSIG NSEC3 133 2 3600 20150420235959 ( - 20051021000000 62827 example. - QrjOpXVIvodCw0O8uPMNA+yEeS/o3KKkEIPX - r5DoEShq2hymAsRTc/t9BvRKpcSTExyc5m3T - vYN3GgN0W/0WHQ== ) - a.example. NS ns1.a.example. - NS ns2.a.example. - DS 58470 5 1 ( - 3079F1593EBAD6DC121E202A8B766A6A4837206C ) - RRSIG DS 133 2 3600 20150420235959 20051021000000 ( - 62827 example. - qxw4j5LNe70UDu121YqAaqQjyjYbdKNd/4bE - nH0kjQswuiGs9EuArCBhcWocWQDBku+A4HMH - JdLqJr5p4JctLg== ) - ns1.a.example. A 192.0.2.5 - ns2.a.example. A 192.0.2.6 - ai.example. A 192.0.2.9 - - - -Laurie, et al. Expires January 2, 2008 [Page 36] - -Internet-Draft nsec3 July 2007 - - - RRSIG A 133 2 3600 20150420235959 20051021000000 ( - 62827 example. - qfXAvKr5o3Jixy5KXnVMEhABo3DDHYSR5+Ag - lVxWCExWGMokdkafjW8Hb54+GrOFp/xmDoj5 - BXfXAqURwLqznA== ) - HINFO "KLH-10" "ITS" - RRSIG HINFO 133 2 3600 20150420235959 ( - 20051021000000 62827 example. - BuDv+No06VEcIsEnvBdjdKm6kxQGrhOgKEKb - Gsb8DJRjY7Lia+YG2//s6OlOIfxPmLlLiYpA - i3q2sEjTJhocGQ== ) - AAAA 2001:db8:0:0:0:0:f00:baa9 - RRSIG AAAA 133 2 3600 20150420235959 ( - 20051021000000 62827 example. - m65zc0A16Xbx3jYb0t5vPwMzE2xS15mKh76M - hSuKfiFVhBFcQ9IilEM0pXnLzt3ozrM/3X0x - 2ruyuN0zC+PABA== ) - b4um86eghhds6nea196smvmlo4ors995.example. NSEC3 1 1 12 aabbccdd ( - gjeqe526plbf1g8mklp59enfd789njgi MX RRSIG ) - RRSIG NSEC3 133 2 3600 20150420235959 ( - 20051021000000 62827 example. - GWDmUk8Sv0dxy/UZFol4Ss7Wz3wBiongcnVy - strNODWwdnoO9z6pDh8JLk58ExfEgXm79i4b - Ma6C/s/bkk1LvA== ) - c.example. NS ns1.c.example. - NS ns2.c.example. - ns1.c.example. A 192.0.2.7 - ns2.c.example. A 192.0.2.8 - gjeqe526plbf1g8mklp59enfd789njgi.example. NSEC3 1 1 12 aabbccdd ( - ji6neoaepv8b5o6k4ev33abha8ht9fgc HINFO A AAAA - RRSIG ) - RRSIG NSEC3 133 2 3600 20150420235959 ( - 20051021000000 62827 example. - DCkJyHQSgA9HNA2AQUENLfmAdAqQ4iIcuqZV - pF2x/i1UyWIBuV25iESs4hhwRVIU5uMZaBGE - lNwi0H6f66BpOA== ) - ji6neoaepv8b5o6k4ev33abha8ht9fgc.example. NSEC3 1 1 12 aabbccdd ( - k8udemvp1j2f7eg6jebps17vp3n8i58h ) - RRSIG NSEC3 133 2 3600 20150420235959 ( - 20051021000000 62827 example. - fvKWkD3lXNLyUn0/gN+i3Z8301oRujSFFrJy - SfAPS2Q1bw1Q5eQoy7IE+ZtUVO15ha6C9cUh - CArJyEk247MADA== ) - k8udemvp1j2f7eg6jebps17vp3n8i58h.example. NSEC3 1 1 12 aabbccdd ( - kohar7mbb8dc2ce8a9qvl8hon4k53uhi ) - RRSIG NSEC3 133 2 3600 20150420235959 ( - 20051021000000 62827 example. - IKJfInxfypsDiXKgT6HDvCPEIBu9lZCc0CWl - - - -Laurie, et al. Expires January 2, 2008 [Page 37] - -Internet-Draft nsec3 July 2007 - - - c46+Gj/Jrg1NBkSJkKMjCERp1HT8tKU+zYp5 - Kyio/cddEaa5Gg== ) - kohar7mbb8dc2ce8a9qvl8hon4k53uhi.example. NSEC3 1 1 12 aabbccdd ( - q04jkcevqvmu85r014c7dkba38o0ji5r A RRSIG ) - RRSIG NSEC3 133 2 3600 20150420235959 ( - 20051021000000 62827 example. - j+XRmZBLAu/s0Ah49x7SChH2VsXAMD3nJE0m - UEjzrjFxkdjhdIAFNlvPMn8gy6mIVe5eNc3r - 4+2KaJUEJhyUEQ== ) - ns1.example. A 192.0.2.1 - RRSIG A 133 2 3600 20150420235959 20051021000000 ( - 62827 example. - ratEKfeWD/pJJHO/XqEINvOp3so7pn9Pphxn - fRiCOVsa527M/ucRcQqGYCF0CN4jAXhW+6BS - ZzT0om+VdioRmg== ) - ns2.example. A 192.0.2.2 - RRSIG A 133 2 3600 20150420235959 20051021000000 ( - 62827 example. - mW/DJMbQyD5y5C+a70vWyIWZyQ+Xg1zzkWHX - w3jfqmePgpdJnMrpGOcRIpy5irCFWiCwTp2o - cPT+k0ccpxtkLQ== ) - q04jkcevqvmu85r014c7dkba38o0ji5r.example. NSEC3 1 1 12 aabbccdd ( - r53bq7cc2uvmubfu5ocmm6pers9tk9en A RRSIG ) - RRSIG NSEC3 133 2 3600 20150420235959 ( - 20051021000000 62827 example. - ktIfH8VRjEKYPB0Qf4EdTuSlYn4DVSRRaGWc - kVGmKzreEU5zs97CL8OQSa6C0JZX2yMBXijC - Wu6EvgCXrflgiQ== ) - r53bq7cc2uvmubfu5ocmm6pers9tk9en.example. NSEC3 1 1 12 aabbccdd ( - t644ebqk9bibcna874givr6joj62mlhv MX RRSIG ) - RRSIG NSEC3 133 2 3600 20150420235959 ( - 20051021000000 62827 example. - SzeyaiFOy9dFO1RKHAK4uVCb5GF4rNnxFMXu - 6hpM44cmLcDgshlnG1CwkkcihfKOiPIBWd7I - bGhsbhqrBrn5Dg== ) - t644ebqk9bibcna874givr6joj62mlhv.example. NSEC3 1 1 12 aabbccdd ( - 0p9mhaveqvm6t7vbl5lop2u3t2rp3tom HINFO A AAAA - RRSIG ) - RRSIG NSEC3 133 2 3600 20150420235959 ( - 20051021000000 62827 example. - hkULY2VaEg8lvI0cf+YkUB0rvOORGMGJnfms - h2OecPBYfI9XGUBvqgIyNpNpK3nIFoW/VNO+ - 3H+6P1NzivDmog== ) - *.w.example. MX 1 ai.example. - RRSIG MX 133 2 3600 20150420235959 20051021000000 ( - 62827 example. - DnT0Y6dRBM8f3v8HdKmZUsGVkXh+b+htujCR - c423x6c8erEMGVnxcrmcrZ53qGXcMYJ+TDkq - - - -Laurie, et al. Expires January 2, 2008 [Page 38] - -Internet-Draft nsec3 July 2007 - - - a7Xfz/f9xzvSTw== ) - x.w.example. MX 1 xx.example. - RRSIG MX 133 3 3600 20150420235959 20051021000000 ( - 62827 example. - BLSDMos8kYR7+2U7iwwdqdhU82hzq0s57xtw - F08tWU/d19jrNO6LdWfBL/FJ8zL8ZpEjhh6b - 8cj0f5yQOUyShw== ) - x.y.w.example. MX 1 xx.example. - RRSIG MX 133 4 3600 20150420235959 20051021000000 ( - 62827 example. - GPzELyUCxrnyep8uMcqthUXjTqYBmgeaveb9 - 2vQgzUyPLLamNN/YqMHr6tGQNxeMAhclxUSQ - eoCggUBVhFfB1Q== ) - xx.example. A 192.0.2.10 - RRSIG A 133 2 3600 20150420235959 20051021000000 ( - 62827 example. - Sz+fPqY8II1VDq+dY48Q40dq1aoBR2RAuhKg - QNKXEYcULtJo/hxxfEAkJSNBKU5QnHpnnT9L - jqaSdob7ZhdxHg== ) - HINFO "KLH-10" "TOPS-20" - RRSIG HINFO 133 2 3600 20150420235959 ( - 20051021000000 62827 example. - YJFwmD0By0NpGEvO1nE1ZTH10XrmpKnVuAEI - cAxLLHyPs3qyGQdDEG7sQX5+PfiOGZrNmZef - 8NgQhW8kGEgN1Q== ) - AAAA 2001:db8:0:0:0:0:f00:baaa - RRSIG AAAA 133 2 3600 20150420235959 ( - 20051021000000 62827 example. - VAJBlXoTOScrIM6yPlDsd9o05v39qIzFnemR - 2vgw1s4l8maJVWi9IHEg8oiypJvGwSCP1nFs - EOlXyNFQJ0fWGA== ) - - -Appendix B. Example Responses - - The examples in this section show response messages using the signed - zone example in Appendix A. - -B.1. Name Error - - An authoritative name error. The NSEC3 RRs prove that the name does - not exist and that there is no wildcard RR that should have been - expanded. - -;; Header: QR AA DO RCODE=3 -;; -;; Question -a.c.x.w.example. IN A - - - -Laurie, et al. Expires January 2, 2008 [Page 39] - -Internet-Draft nsec3 July 2007 - - -;; Answer -;; (empty) - -;; Authority - -example. SOA ns1.example. bugs.x.w.example. 1 3600 300 ( - 3600000 3600 ) -example. RRSIG SOA 133 1 3600 20150420235959 20051021000000 ( - 62827 example. - hNIkW1xzn+c+9P3W7PUVVptI72xEmOtn+eqQ - ux0BE7Pfc6ikx4m7ivOVWETjbwHjqfY0X5G+ - rynLZNqsbLm40Q== ) - -;; NSEC3 RR that covers the "next closer" name (c.x.w.example) -;; H(c.x.w.example) = 0va5bpr2ou0vk0lbqeeljri88laipsfh - -0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. NSEC3 1 1 12 aabbccdd ( - 2t7b4g4vsa5smi47k61mv5bv1a22bojr MX DNSKEY NS - SOA NSEC3PARAM RRSIG ) -0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. RRSIG NSEC3 133 2 3600 ( - 20150420235959 20051021000000 62827 example. - rn2tv99+9StXbc7JaEnjT1+8I8f2vVOMOIbF - xzlrn94lQLxEOYxQR4SrxDRP4/fC54Jui0Ix - 4eI9tMfaTVgehQ== ) - -;; NSEC3 RR that matches the closest encloser (x.w.example) -;; H(x.w.example) = b4um86eghhds6nea196smvmlo4ors995 - -b4um86eghhds6nea196smvmlo4ors995.example. NSEC3 1 1 12 aabbccdd ( - gjeqe526plbf1g8mklp59enfd789njgi MX RRSIG ) -b4um86eghhds6nea196smvmlo4ors995.example. RRSIG NSEC3 133 2 3600 ( - 20150420235959 20051021000000 62827 example. - GWDmUk8Sv0dxy/UZFol4Ss7Wz3wBiongcnVy - strNODWwdnoO9z6pDh8JLk58ExfEgXm79i4b - Ma6C/s/bkk1LvA== ) - -;; NSEC3 RR that covers wildcard at the closest encloser (*.x.w.example) -;; H(*.x.w.example) = 92pqneegtaue7pjatc3l3qnk738c6v5m - -35mthgpgcu1qg68fab165klnsnk3dpvl.example. NSEC3 1 1 12 aabbccdd ( - b4um86eghhds6nea196smvmlo4ors995 NS DS RRSIG ) -35mthgpgcu1qg68fab165klnsnk3dpvl.example. RRSIG NSEC3 133 2 3600 ( - 20150420235959 20051021000000 62827 example. - QrjOpXVIvodCw0O8uPMNA+yEeS/o3KKkEIPX - r5DoEShq2hymAsRTc/t9BvRKpcSTExyc5m3T - vYN3GgN0W/0WHQ== ) - -;; Additional - - - -Laurie, et al. Expires January 2, 2008 [Page 40] - -Internet-Draft nsec3 July 2007 - - -;; (empty) - - The query returned three NSEC3 RRs that prove that the requested data - does not exist and that no wildcard expansion applies. The negative - response is authenticated by verifying the NSEC3 RRs. The - corresponding RRSIGs indicate that the NSEC3 RRs are signed by an - "example" DNSKEY of algorithm 133 and with key tag 62827. The - resolver needs the corresponding DNSKEY RR in order to authenticate - this answer. - - One of the owner names of the NSEC3 RRs matches the closest encloser. - One of the NSEC3 RRs prove that there exists no longer name. One of - the NSEC3 RRs prove that there exists no wildcard RRSets that should - have been expanded. The closest encloser can be found by applying - the algorithm in section Section 8.3. - - In the above example, the name 'x.w.example' hashes to - 'b4um86eghhds6nea196smvmlo4ors995'. This indicates that this might - be the closest encloser. To prove that 'c.x.w.example' and - '*.x.w.example' do not exist, these names are hashed to, - respectively, '0va5bpr2ou0vk0lbqeeljri88laipsfh' and - '92pqneegtaue7pjatc3l3qnk738c6v5m'. The first and last NSEC3 RRs - prove that these hashed owner names do not exist. - -B.2. No Data Error - - A "no data" response. The NSEC3 RR proves that the name exists and - that the requested RR type does not. - - - - - - - - - - - - - - - - - - - - - - - -Laurie, et al. Expires January 2, 2008 [Page 41] - -Internet-Draft nsec3 July 2007 - - -;; Header: QR AA DO RCODE=0 -;; -;; Question -ns1.example. IN MX - -;; Answer -;; (empty) - -;; Authority -example. SOA ns1.example. bugs.x.w.example. 1 3600 300 ( - 3600000 3600 ) -example. RRSIG SOA 133 1 3600 20150420235959 20051021000000 ( - 62827 example. - hNIkW1xzn+c+9P3W7PUVVptI72xEmOtn+eqQ - ux0BE7Pfc6ikx4m7ivOVWETjbwHjqfY0X5G+ - rynLZNqsbLm40Q== ) - -;; NSEC3 RR matches the QNAME and shows that the MX type bit is not set. - -2t7b4g4vsa5smi47k61mv5bv1a22bojr.example. NSEC3 1 1 12 aabbccdd ( - 2vptu5timamqttgl4luu9kg21e0aor3s A RRSIG ) -2t7b4g4vsa5smi47k61mv5bv1a22bojr.example. RRSIG NSEC3 133 2 3600 ( - 20150420235959 20051021000000 62827 example. - fJER1Z3nGoN0HmZm99lqNLSpIf7jLXTMoGm2 - k4gIwlc0R4DztJp6Sq37OV6XnGdre4MfgRpB - mAcgpPWC5A5eiw== ) -;; Additional -;; (empty) - - The query returned an NSEC3 RR that proves that the requested name - exists ("ns1.example." hashes to "2t7b4g4vsa5smi47k61mv5bv1a22bojr"), - but the requested RR type does not exist (type MX is absent in the - type code list of the NSEC3 RR), and was not a CNAME (type CNAME is - also absent in the type code list of the NSEC3 RR.) - -B.2.1. No Data Error, Empty Non-Terminal - - A "no data" response because of an empty non-terminal. The NSEC3 RR - proves that the name exists and that the requested RR type does not. - - - - - - - - - - - - -Laurie, et al. Expires January 2, 2008 [Page 42] - -Internet-Draft nsec3 July 2007 - - - ;; Header: QR AA DO RCODE=0 - ;; - ;; Question - y.w.example. IN A - - ;; Answer - ;; (empty) - - ;; Authority - example. SOA ns1.example. bugs.x.w.example. 1 3600 300 ( - 3600000 3600 ) - example. RRSIG SOA 133 1 3600 20150420235959 20051021000000 ( - 62827 example. - hNIkW1xzn+c+9P3W7PUVVptI72xEmOtn+eqQ - ux0BE7Pfc6ikx4m7ivOVWETjbwHjqfY0X5G+ - rynLZNqsbLm40Q== ) - - ;; NSEC3 RR matches the QNAME and shows that the A type bit is not set. - - ji6neoaepv8b5o6k4ev33abha8ht9fgc.example. NSEC3 1 1 12 aabbccdd ( - k8udemvp1j2f7eg6jebps17vp3n8i58h ) - ji6neoaepv8b5o6k4ev33abha8ht9fgc.example. RRSIG NSEC3 133 2 3600 ( - 20150420235959 20051021000000 62827 example. - fvKWkD3lXNLyUn0/gN+i3Z8301oRujSFFrJy - SfAPS2Q1bw1Q5eQoy7IE+ZtUVO15ha6C9cUh - CArJyEk247MADA== ) - - ;; Additional - ;; (empty) - - - The query returned an NSEC3 RR that proves that the requested name - exists ("y.w.example." hashes to "ji6neoaepv8b5o6k4ev33abha8ht9fgc"), - but the requested RR type does not exist (Type A is absent in the - Type Bit Maps field of the NSEC3 RR). Note that, unlike an empty - non-terminal proof using NSECs, this is identical to a No Data Error. - This example is solely mentioned to be complete. - -B.3. Referral to an Opt-Out Unsigned Zone - - The NSEC3 RRs prove that nothing for this delegation was signed. - There is no proof that the unsigned delegation exists. - - - - - - - - - -Laurie, et al. Expires January 2, 2008 [Page 43] - -Internet-Draft nsec3 July 2007 - - - ;; Header: QR DO RCODE=0 - ;; - ;; Question - mc.c.example. IN MX - - ;; Answer - ;; (empty) - - ;; Authority - c.example. NS ns1.c.example. - NS ns2.c.example. - - ;; NSEC3 RR that covers the "next closer" name (c.example) - ;; H(c.example) = 4g6p9u5gvfshp30pqecj98b3maqbn1ck - - 35mthgpgcu1qg68fab165klnsnk3dpvl.example. NSEC3 1 1 12 aabbccdd ( - b4um86eghhds6nea196smvmlo4ors995 NS DS RRSIG ) - 35mthgpgcu1qg68fab165klnsnk3dpvl.example. RRSIG NSEC3 133 2 3600 ( - 20150420235959 20051021000000 62827 example. - QrjOpXVIvodCw0O8uPMNA+yEeS/o3KKkEIPX - r5DoEShq2hymAsRTc/t9BvRKpcSTExyc5m3T - vYN3GgN0W/0WHQ== ) - - ;; NSEC3 RR that matches the closest encloser (example) - ;; H(example) = 0p9mhaveqvm6t7vbl5lop2u3t2rp3tom - - 0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. NSEC3 1 1 12 aabbccdd ( - 2t7b4g4vsa5smi47k61mv5bv1a22bojr MX DNSKEY NS - SOA NSEC3PARAM RRSIG ) - 0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. RRSIG NSEC3 133 2 3600 ( - 20150420235959 20051021000000 62827 example. - rn2tv99+9StXbc7JaEnjT1+8I8f2vVOMOIbF - xzlrn94lQLxEOYxQR4SrxDRP4/fC54Jui0Ix - 4eI9tMfaTVgehQ== ) - - ;; Additional - ns1.c.example. A 192.0.2.7 - ns2.c.example. A 192.0.2.8 - - - The query returned a referral to the unsigned "c.example." zone. The - response contains the closest provable encloser of "c.example" to be - "example", since the hash of "c.example" - ("4g6p9u5gvfshp30pqecj98b3maqbn1ck") is covered by the first NSEC3 RR - and its Opt-Out bit is set. - - - - - - -Laurie, et al. Expires January 2, 2008 [Page 44] - -Internet-Draft nsec3 July 2007 - - -B.4. Wildcard Expansion - - A query that was answered with a response containing a wildcard - expansion. The label count in the RRSIG RRSet in the answer section - indicates that a wildcard RRSet was expanded to produce this - response, and the NSEC3 RR proves that no "next closer" name exists - in the zone. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -Laurie, et al. Expires January 2, 2008 [Page 45] - -Internet-Draft nsec3 July 2007 - - - ;; Header: QR AA DO RCODE=0 - ;; - ;; Question - a.z.w.example. IN MX - - ;; Answer - a.z.w.example. MX 1 ai.example. - a.z.w.example. RRSIG MX 133 2 3600 20150420235959 20051021000000 ( - 62827 example. - DnT0Y6dRBM8f3v8HdKmZUsGVkXh+b+htujCR - c423x6c8erEMGVnxcrmcrZ53qGXcMYJ+TDkq - a7Xfz/f9xzvSTw== ) - - ;; Authority - example. NS ns1.example. - example. NS ns2.example. - example. RRSIG NS 133 1 3600 20150420235959 20051021000000 ( - 62827 example. - D9+iBwcbeKL5+TorTfYn4/pLr2lSFwyGYCyM - gfq4TpFaZpxrCJPLxHbKjdkR18jAt7+SR7B5 - JpiZcff2Cj2B0w== ) - - ;; NSEC3 RR that covers the "next closer" name (z.w.example) - ;; H(z.w.example) = qlu7gtfaeh0ek0c05ksfhdpbcgglbe03 - - q04jkcevqvmu85r014c7dkba38o0ji5r.example. NSEC3 1 1 12 aabbccdd ( - r53bq7cc2uvmubfu5ocmm6pers9tk9en A RRSIG ) - q04jkcevqvmu85r014c7dkba38o0ji5r.example. RRSIG NSEC3 133 2 3600 ( - 20150420235959 20051021000000 62827 example. - ktIfH8VRjEKYPB0Qf4EdTuSlYn4DVSRRaGWc - kVGmKzreEU5zs97CL8OQSa6C0JZX2yMBXijC - Wu6EvgCXrflgiQ== ) - - ;; Additional - ai.example. A 192.0.2.9 - ai.example. RRSIG A 133 2 3600 20150420235959 20051021000000 ( - 62827 example. - qfXAvKr5o3Jixy5KXnVMEhABo3DDHYSR5+Ag - lVxWCExWGMokdkafjW8Hb54+GrOFp/xmDoj5 - BXfXAqURwLqznA== ) - ai.example. AAAA 2001:db8:0:0:0:0:f00:baa9 - ai.example. RRSIG AAAA 133 2 3600 20150420235959 ( - 20051021000000 62827 example. - m65zc0A16Xbx3jYb0t5vPwMzE2xS15mKh76M - hSuKfiFVhBFcQ9IilEM0pXnLzt3ozrM/3X0x - 2ruyuN0zC+PABA== ) - - - - - -Laurie, et al. Expires January 2, 2008 [Page 46] - -Internet-Draft nsec3 July 2007 - - - The query returned an answer that was produced as a result of - wildcard expansion. The answer section contains a wildcard RRSet - expanded as it would be in a traditional DNS response. The RRSIG - Labels field value of 2 indicates that the answer is the result of - wildcard expansion, as the "a.z.w.example" name contains 4 labels. - This also shows that "w.example" exists, so there is no need for an - NSEC3 RR that matches the closest encloser. - - The NSEC3 RR proves that no closer match could have been used to - answer this query. - -B.5. Wildcard No Data Error - - A "no data" response for a name covered by a wildcard. The NSEC3 RRs - prove that the matching wildcard name does not have any RRs of the - requested type and that no closer match exists in the zone. - - ;; Header: QR AA DO RCODE=0 - ;; - ;; Question - a.z.w.example. IN AAAA - - ;; Answer - ;; (empty) - - ;; Authority - example. SOA ns1.example. bugs.x.w.example. 1 3600 300 ( - 3600000 3600 ) - example. RRSIG SOA 133 1 3600 20150420235959 20051021000000 ( - 62827 example. - hNIkW1xzn+c+9P3W7PUVVptI72xEmOtn+eqQ - ux0BE7Pfc6ikx4m7ivOVWETjbwHjqfY0X5G+ - rynLZNqsbLm40Q== ) - - ;; NSEC3 RR that matches the closest encloser (w.example) - ;; H(w.example) = k8udemvp1j2f7eg6jebps17vp3n8i58h - - k8udemvp1j2f7eg6jebps17vp3n8i58h.example. NSEC3 1 1 12 aabbccdd ( - kohar7mbb8dc2ce8a9qvl8hon4k53uhi ) - k8udemvp1j2f7eg6jebps17vp3n8i58h.example. RRSIG NSEC3 133 2 3600 ( - 20150420235959 20051021000000 62827 example. - IKJfInxfypsDiXKgT6HDvCPEIBu9lZCc0CWl - c46+Gj/Jrg1NBkSJkKMjCERp1HT8tKU+zYp5 - Kyio/cddEaa5Gg== ) - - ;; NSEC3 RR that covers the "next closer" name (z.w.example) - ;; H(z.w.example) = qlu7gtfaeh0ek0c05ksfhdpbcgglbe03 - - - - -Laurie, et al. Expires January 2, 2008 [Page 47] - -Internet-Draft nsec3 July 2007 - - - q04jkcevqvmu85r014c7dkba38o0ji5r.example. NSEC3 1 1 12 aabbccdd ( - r53bq7cc2uvmubfu5ocmm6pers9tk9en A RRSIG ) - q04jkcevqvmu85r014c7dkba38o0ji5r.example. RRSIG NSEC3 133 2 3600 ( - 20150420235959 20051021000000 62827 example. - ktIfH8VRjEKYPB0Qf4EdTuSlYn4DVSRRaGWc - kVGmKzreEU5zs97CL8OQSa6C0JZX2yMBXijC - Wu6EvgCXrflgiQ== ) - - ;; NSEC3 RR that matches a wildcard at the closest encloser. - ;; H(*.w.example) = r53bq7cc2uvmubfu5ocmm6pers9tk9en - - r53bq7cc2uvmubfu5ocmm6pers9tk9en.example. NSEC3 1 1 12 aabbccdd ( - t644ebqk9bibcna874givr6joj62mlhv MX RRSIG ) - r53bq7cc2uvmubfu5ocmm6pers9tk9en.example. RRSIG NSEC3 133 2 3600 ( - 20150420235959 20051021000000 62827 example. - SzeyaiFOy9dFO1RKHAK4uVCb5GF4rNnxFMXu - 6hpM44cmLcDgshlnG1CwkkcihfKOiPIBWd7I - bGhsbhqrBrn5Dg== ) - - ;; Additional - ;; (empty) - - The query returned the NSEC3 RRs that prove that the requested data - does not exist and no wildcard RR applies. - -B.6. DS Child Zone No Data Error - - A "no data" response for a QTYPE=DS query that was mistakenly sent to - a name server for the child zone. - - - - - - - - - - - - - - - - - - - - - - -Laurie, et al. Expires January 2, 2008 [Page 48] - -Internet-Draft nsec3 July 2007 - - -;; Header: QR AA DO RCODE=0 -;; -;; Question -example. IN DS - -;; Answer -;; (empty) - -;; Authority -example. SOA ns1.example. bugs.x.w.example. 1 3600 300 ( - 3600000 3600 ) -example. RRSIG SOA 133 1 3600 20150420235959 20051021000000 ( - 62827 example. - hNIkW1xzn+c+9P3W7PUVVptI72xEmOtn+eqQ - ux0BE7Pfc6ikx4m7ivOVWETjbwHjqfY0X5G+ - rynLZNqsbLm40Q== ) - -;; NSEC3 RR matches the QNAME and shows that the DS type bit is not set. - -0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. NSEC3 1 1 12 aabbccdd ( - 2t7b4g4vsa5smi47k61mv5bv1a22bojr MX DNSKEY NS - SOA NSEC3PARAM RRSIG ) -0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. RRSIG NSEC3 133 2 3600 ( - 20150420235959 20051021000000 62827 example. - rn2tv99+9StXbc7JaEnjT1+8I8f2vVOMOIbF - xzlrn94lQLxEOYxQR4SrxDRP4/fC54Jui0Ix - 4eI9tMfaTVgehQ== ) - -;; Additional -;; (empty) - - The query returned an NSEC3 RR showing that the requested was - answered by the server authoritative for the zone "example". The - NSEC3 RR indicates the presence of an SOA RR, showing that this NSEC3 - RR is from the apex of the child, not from the zone cut of the - parent. Queries for the "example" DS RRSet should be sent to the - parent servers (which are in this case the root servers). - - -Appendix C. Special Considerations - - The following paragraphs clarify specific behavior and explain - special considerations for implementations. - -C.1. Salting - - Augmenting original owner names with salt before hashing increases - the cost of a dictionary of pre-generated hash-values. For every bit - - - -Laurie, et al. Expires January 2, 2008 [Page 49] - -Internet-Draft nsec3 July 2007 - - - of salt, the cost of a precomputed dictionary doubles (because there - must be an entry for each word combined with each possible salt - value). The NSEC3 RR can use a maximum of 2040 bits (255 octets) of - salt, multiplying the cost by 2^2040. This means that an attacker - must, in practice, recompute the dictionary each time the salt is - changed. - - Including a salt, regardless of size, does not affect the cost of - constructing NSEC3 RRs. It does increase the size of the NSEC3 RR. - - There MUST be at least one complete set of NSEC3 RRs for the zone - using the same salt value. - - The salt SHOULD be changed periodically to prevent pre-computation - using a single salt. It is RECOMMENDED that the salt be changed for - every re-signing. - - Note that this could cause a resolver to see RRs with different salt - values for the same zone. This is harmless, since each RR stands - alone (that is, it denies the set of owner names whose hashes, using - the salt in the NSEC3 RR, fall between the two hashes in the NSEC3 - RR) - it is only the server that needs a complete set of NSEC3 RRs - with the same salt in order to be able to answer every possible - query. - - There is no prohibition with having NSEC3 RRs with different salts - within the same zone. However, in order for authoritative servers to - be able to consistently find covering NSEC3 RRs, the authoritative - server MUST choose a single set of parameters (algorithm, salt, and - iterations) to use when selecting NSEC3 RRs. - -C.2. Hash Collision - - Hash collisions occur when different messages have the same hash - value. The expected number of domain names needed to give a 1 in 2 - chance of a single collision is about 2^(n/2) for a hash of length n - bits (i.e. 2^80 for SHA-1). Though this probability is extremely - low, the following paragraphs deal with avoiding collisions and - assessing possible damage in the event of an attack using hash - collisions. - -C.2.1. Avoiding Hash Collisions During Generation - - During generation of NSEC3 RRs, hash values are supposedly unique. - In the (academic) case of a collision occurring, an alternative salt - MUST be chosen and all hash values MUST be regenerated. - - - - - -Laurie, et al. Expires January 2, 2008 [Page 50] - -Internet-Draft nsec3 July 2007 - - -C.2.2. Second Preimage Requirement Analysis - - A cryptographic hash function has a second-preimage resistance - property. The second-preimage resistance property means that it is - computationally infeasible to find another message with the same hash - value as a given message, i.e. given preimage X, to find a second - preimage X' != X such that hash(X) = hash(X'). The work factor for - finding a second preimage is of the order of 2^160 for SHA-1. To - mount an attack using an existing NSEC3 RR, an adversary needs to - find a second preimage. - - Assuming an adversary is capable of mounting such an extreme attack, - the actual damage is that a response message can be generated which - claims that a certain QNAME (i.e. the second pre-image) does exist, - while in reality QNAME does not exist (a false positive), which will - either cause a security aware resolver to re-query for the non- - existent name, or to fail the initial query. Note that the adversary - can't mount this attack on an existing name but only on a name that - the adversary can't choose and does not yet exist. - - -Authors' Addresses - - Ben Laurie - Nominet - 17 Perryn Road - London W3 7LR - England - - Phone: +44 20 8735 0686 - Email: ben@links.org - - - Geoffrey Sisson - Nominet - Sandford Gate - Sandy Lane West - Oxford OX4 6LB - UNITED KINGDOM - - Phone: +44 1865 332211 - Email: geoff@nominet.org.uk - - - - - - - - - -Laurie, et al. Expires January 2, 2008 [Page 51] - -Internet-Draft nsec3 July 2007 - - - Roy Arends - Nominet - Sandford Gate - Sandy Lane West - Oxford OX4 6LB - UNITED KINGDOM - - Phone: +44 1865 332211 - Email: roy@nominet.org.uk - - - David Blacka - VeriSign, Inc. - 21355 Ridgetop Circle - Dulles, VA 20166 - US - - Phone: +1 703 948 3200 - Email: davidb@verisign.com - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -Laurie, et al. Expires January 2, 2008 [Page 52] - -Internet-Draft nsec3 July 2007 - - -Full Copyright Statement - - Copyright (C) The IETF Trust (2007). - - This document is subject to the rights, licenses and restrictions - contained in BCP 78, and except as set forth therein, the authors - retain all their rights. - - This document and the information contained herein are provided on an - "AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS - OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY, THE IETF TRUST AND - THE INTERNET ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS - OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF - THE INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED - WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. - - -Intellectual Property - - The IETF takes no position regarding the validity or scope of any - Intellectual Property Rights or other rights that might be claimed to - pertain to the implementation or use of the technology described in - this document or the extent to which any license under such rights - might or might not be available; nor does it represent that it has - made any independent effort to identify any such rights. Information - on the procedures with respect to rights in RFC documents can be - found in BCP 78 and BCP 79. - - Copies of IPR disclosures made to the IETF Secretariat and any - assurances of licenses to be made available, or the result of an - attempt made to obtain a general license or permission for the use of - such proprietary rights by implementers or users of this - specification can be obtained from the IETF on-line IPR repository at - http://www.ietf.org/ipr. - - The IETF invites any interested party to bring to its attention any - copyrights, patents or patent applications, or other proprietary - rights that may cover technology that may be required to implement - this standard. Please address the information to the IETF at - ietf-ipr@ietf.org. - - -Acknowledgment - - Funding for the RFC Editor function is provided by the IETF - Administrative Support Activity (IASA). - - - - - -Laurie, et al. Expires January 2, 2008 [Page 53] - From ba5af4569a2eee89ed7a6de94f2364a1638b9572 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Thu, 10 Apr 2008 07:20:11 +0000 Subject: [PATCH 002/137] fix bad NSID/EDNS interaction [RT #17952] --- lib/dns/resolver.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c index ac52dd191a..d7e9c6adb0 100644 --- a/lib/dns/resolver.c +++ b/lib/dns/resolver.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: resolver.c,v 1.367 2008/04/07 05:32:52 marka Exp $ */ +/* $Id: resolver.c,v 1.368 2008/04/10 07:20:11 marka Exp $ */ /*! \file */ @@ -1600,7 +1600,7 @@ resquery_send(resquery_t *query) { udpsize, reqnsid); if (reqnsid && result == ISC_R_SUCCESS) { query->options |= DNS_FETCHOPT_WANTNSID; - } else { + } else if (result != ISC_R_SUCCESS) { /* * We couldn't add the OPT, but we'll press on. * We're not using EDNS0, so set the NOEDNS0 From 29317a7e0ec7b5c462736372bd088e9fa98cac23 Mon Sep 17 00:00:00 2001 From: Evan Hunt Date: Fri, 18 Apr 2008 19:03:00 +0000 Subject: [PATCH 003/137] Restoring changes that were backed out before 9.3.5 because they needed to be held for 9.3.6. --- CHANGES | 6 ++++++ lib/dns/adb.c | 15 +++++++-------- lib/dns/rbt.c | 17 +++++++---------- 3 files changed, 20 insertions(+), 18 deletions(-) diff --git a/CHANGES b/CHANGES index f8a1ad0333..6ab048e9a4 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,9 @@ +2347. [bug] Delete now traverses the RB tree in the canonical + order. [RT #17451] + +2343. [bug] (Seemingly) duplicate IPv6 entries could be + created in ADB. [RT #17837] + 2355. [func] Extend the number statistics counters available. [RT #17590] diff --git a/lib/dns/adb.c b/lib/dns/adb.c index a6c6d8b1de..8ec237e2a1 100644 --- a/lib/dns/adb.c +++ b/lib/dns/adb.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: adb.c,v 1.181.2.11.2.34 2008/04/03 06:07:11 tbox Exp $ */ +/* $Id: adb.c,v 1.181.2.11.2.35 2008/04/18 19:03:00 each Exp $ */ /* * Implementation notes @@ -488,6 +488,7 @@ import_rdataset(dns_adbname_t *adbname, dns_rdataset_t *rdataset, isc_boolean_t new_addresses_added; dns_rdatatype_t rdtype; unsigned int findoptions; + dns_adbnamehooklist_t *hookhead; INSIST(DNS_ADBNAME_VALID(adbname)); adb = adbname->adb; @@ -512,10 +513,12 @@ import_rdataset(dns_adbname_t *adbname, dns_rdataset_t *rdataset, INSIST(rdata.length == 4); memcpy(&ina.s_addr, rdata.data, 4); isc_sockaddr_fromin(&sockaddr, &ina, 0); + hookhead = &adbname->v4; } else { INSIST(rdata.length == 16); memcpy(in6a.s6_addr, rdata.data, 16); isc_sockaddr_fromin6(&sockaddr, &in6a, 0); + hookhead = &adbname->v6; } INSIST(nh == NULL); @@ -544,7 +547,7 @@ import_rdataset(dns_adbname_t *adbname, dns_rdataset_t *rdataset, link_entry(adb, addr_bucket, entry); } else { - for (anh = ISC_LIST_HEAD(adbname->v4); + for (anh = ISC_LIST_HEAD(*hookhead); anh != NULL; anh = ISC_LIST_NEXT(anh, plink)) if (anh->entry == foundentry) @@ -557,12 +560,8 @@ import_rdataset(dns_adbname_t *adbname, dns_rdataset_t *rdataset, } new_addresses_added = ISC_TRUE; - if (nh != NULL) { - if (rdtype == dns_rdatatype_a) - ISC_LIST_APPEND(adbname->v4, nh, plink); - else - ISC_LIST_APPEND(adbname->v6, nh, plink); - } + if (nh != NULL) + ISC_LIST_APPEND(*hookhead, nh, plink); nh = NULL; result = dns_rdataset_next(rdataset); } diff --git a/lib/dns/rbt.c b/lib/dns/rbt.c index 46c317d262..14d5ea7384 100644 --- a/lib/dns/rbt.c +++ b/lib/dns/rbt.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: rbt.c,v 1.115.2.2.2.17 2008/04/03 00:17:07 each Exp $ */ +/* $Id: rbt.c,v 1.115.2.2.2.18 2008/04/18 19:03:00 each Exp $ */ /* Principal Authors: DCL */ @@ -2048,10 +2048,6 @@ dns_rbt_deletetreeflat(dns_rbt_t *rbt, unsigned int quantum, node = LEFT(node); goto traverse; } - if (RIGHT(node) != NULL) { - node = RIGHT(node); - goto traverse; - } if (DOWN(node) != NULL) { node = DOWN(node); goto traverse; @@ -2068,14 +2064,15 @@ dns_rbt_deletetreeflat(dns_rbt_t *rbt, unsigned int quantum, node->magic = 0; #endif parent = PARENT(node); + if (RIGHT(node) != NULL) + PARENT(RIGHT(node)) = parent; if (parent != NULL) { if (LEFT(parent) == node) - LEFT(parent) = NULL; + LEFT(parent) = RIGHT(node); else if (DOWN(parent) == node) - DOWN(parent) = NULL; - else if (RIGHT(parent) == node) - RIGHT(parent) = NULL; - } + DOWN(parent) = RIGHT(node); + } else + parent = RIGHT(node); isc_mem_put(rbt->mctx, node, NODE_SIZE(node)); rbt->nodecount--; node = parent; From 4fcd03af9ffd55c7ecb508048fb789f123465b25 Mon Sep 17 00:00:00 2001 From: Evan Hunt Date: Fri, 18 Apr 2008 19:47:48 +0000 Subject: [PATCH 004/137] Missing type in internal_next6() function declaration --- lib/isc/win32/interfaceiter.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/lib/isc/win32/interfaceiter.c b/lib/isc/win32/interfaceiter.c index a0f25897d2..1451249590 100644 --- a/lib/isc/win32/interfaceiter.c +++ b/lib/isc/win32/interfaceiter.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: interfaceiter.c,v 1.12 2008/04/02 23:46:57 tbox Exp $ */ +/* $Id: interfaceiter.c,v 1.13 2008/04/18 19:47:48 each Exp $ */ /* * Note that this code will need to be revisited to support IPv6 Interfaces. @@ -429,6 +429,7 @@ internal_next(isc_interfaceiter_t *iter) { return (ISC_R_SUCCESS); } +static isc_result_t internal_next6(isc_interfaceiter_t *iter) { if (iter->pos6 == 0) return (ISC_R_NOMORE); From 5f23979aa81a9ac07259acfd3d7ef468fdd69cdf Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Mon, 21 Apr 2008 23:17:32 +0000 Subject: [PATCH 005/137] auto update --- doc/private/branches | 1 + 1 file changed, 1 insertion(+) diff --git a/doc/private/branches b/doc/private/branches index 97fb41aaa0..cad1111b47 100644 --- a/doc/private/branches +++ b/doc/private/branches @@ -108,6 +108,7 @@ rt17589 new marka // 2008-02-11 05:52 +0000 rt17590 new rt17596 new fdupont // explicit rollover rt17596a new fdupont // 2008-02-28 08:16 +0000 +rt17596b new fdupont // 2008-04-21 12:27 +0000 rt17598 new marka // 2008-02-17 23:24 +0000 rt17671 new marka // 2008-02-27 01:39 +0000 rt17729 new marka // 2008-03-06 03:56 +0000 From bf64a0d5d9469c42622401bc5d55cf9888eeef44 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tatuya=20JINMEI=20=E7=A5=9E=E6=98=8E=E9=81=94=E5=93=89?= Date: Wed, 23 Apr 2008 01:14:24 +0000 Subject: [PATCH 006/137] 2361. [bug] "recursion" statistics counter could be counted multiple times for a single query. [RT #17990] --- CHANGES | 3 +++ bin/named/query.c | 21 ++++++++++++++------- 2 files changed, 17 insertions(+), 7 deletions(-) diff --git a/CHANGES b/CHANGES index 2f7a4daaa8..77ce4effae 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +2361. [bug] "recursion" statistics counter could be counted + multiple times for a single query. [RT #17990] + 2360. [bug] Fix a condition where we release a database version (which may acquire a lock) while holding the lock. diff --git a/bin/named/query.c b/bin/named/query.c index ea5109a7f5..1caaf013e2 100644 --- a/bin/named/query.c +++ b/bin/named/query.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: query.c,v 1.305 2008/04/03 05:55:51 marka Exp $ */ +/* $Id: query.c,v 1.306 2008/04/23 01:14:24 jinmei Exp $ */ /*! \file */ @@ -2941,13 +2941,14 @@ query_resume(isc_task_t *task, isc_event_t *event) { static isc_result_t query_recurse(ns_client_t *client, dns_rdatatype_t qtype, dns_name_t *qdomain, - dns_rdataset_t *nameservers) + dns_rdataset_t *nameservers, isc_boolean_t resuming) { isc_result_t result; dns_rdataset_t *rdataset, *sigrdataset; isc_sockaddr_t *peeraddr; - inc_stats(client, dns_nsstatscounter_recursion); + if (!resuming) + inc_stats(client, dns_nsstatscounter_recursion); /* * We are about to recurse, which means that this client will @@ -3352,6 +3353,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype) unsigned int options; isc_boolean_t empty_wild; dns_rdataset_t *noqname; + isc_boolean_t resuming; CTRACE("query_find"); @@ -3377,6 +3379,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype) need_wildcardproof = ISC_FALSE; empty_wild = ISC_FALSE; options = 0; + resuming = ISC_FALSE; if (event != NULL) { /* @@ -3419,6 +3422,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype) } result = event->result; + resuming = ISC_TRUE; goto resume; } @@ -3624,7 +3628,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype) */ if (RECURSIONOK(client)) { result = query_recurse(client, qtype, - NULL, NULL); + NULL, NULL, resuming); if (result == ISC_R_SUCCESS) client->query.attributes |= NS_QUERYATTR_RECURSING; @@ -3795,10 +3799,12 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype) */ if (dns_rdatatype_atparent(type)) result = query_recurse(client, qtype, - NULL, NULL); + NULL, NULL, + resuming); else result = query_recurse(client, qtype, - fname, rdataset); + fname, rdataset, + resuming); if (result == ISC_R_SUCCESS) client->query.attributes |= NS_QUERYATTR_RECURSING; @@ -4251,7 +4257,8 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype) result = query_recurse(client, qtype, NULL, - NULL); + NULL, + resuming); if (result == ISC_R_SUCCESS) client->query.attributes |= NS_QUERYATTR_RECURSING; From e0ca4072db51f5b10484cffcef918d8d0672a757 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tatuya=20JINMEI=20=E7=A5=9E=E6=98=8E=E9=81=94=E5=93=89?= Date: Wed, 23 Apr 2008 01:19:50 +0000 Subject: [PATCH 007/137] 2361. [bug] "recursion" statistics counter could be counted multiple times for a single query. [RT #17990] --- CHANGES | 3 +++ bin/named/query.c | 21 ++++++++++++++------- 2 files changed, 17 insertions(+), 7 deletions(-) diff --git a/CHANGES b/CHANGES index 6ab048e9a4..deb59227a9 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +2361. [bug] "recursion" statistics counter could be counted + multiple times for a single query. [RT #17990] + 2347. [bug] Delete now traverses the RB tree in the canonical order. [RT #17451] diff --git a/bin/named/query.c b/bin/named/query.c index 858df8cd97..a4607e92a4 100644 --- a/bin/named/query.c +++ b/bin/named/query.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: query.c,v 1.198.2.13.4.53 2008/01/17 23:45:27 tbox Exp $ */ +/* $Id: query.c,v 1.198.2.13.4.54 2008/04/23 01:19:50 jinmei Exp $ */ #include @@ -2067,12 +2067,13 @@ query_resume(isc_task_t *task, isc_event_t *event) { static isc_result_t query_recurse(ns_client_t *client, dns_rdatatype_t qtype, dns_name_t *qdomain, - dns_rdataset_t *nameservers) + dns_rdataset_t *nameservers, isc_boolean_t resuming) { isc_result_t result; dns_rdataset_t *rdataset, *sigrdataset; - inc_stats(client, dns_statscounter_recursion); + if (!resuming) + inc_stats(client, dns_statscounter_recursion); /* * We are about to recurse, which means that this client will @@ -2367,6 +2368,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype) unsigned int options; isc_boolean_t empty_wild; dns_rdataset_t *noqname; + isc_boolean_t resuming; CTRACE("query_find"); @@ -2392,6 +2394,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype) need_wildcardproof = ISC_FALSE; empty_wild = ISC_FALSE; options = 0; + resuming = ISC_FALSE; if (event != NULL) { /* @@ -2434,6 +2437,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype) } result = event->result; + resuming = ISC_TRUE; goto resume; } @@ -2624,7 +2628,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype) */ if (RECURSIONOK(client)) { result = query_recurse(client, qtype, - NULL, NULL); + NULL, NULL, resuming); if (result == ISC_R_SUCCESS) client->query.attributes |= NS_QUERYATTR_RECURSING; @@ -2791,10 +2795,12 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype) */ if (dns_rdatatype_atparent(type)) result = query_recurse(client, qtype, - NULL, NULL); + NULL, NULL, + resuming); else result = query_recurse(client, qtype, - fname, rdataset); + fname, rdataset, + resuming); if (result == ISC_R_SUCCESS) client->query.attributes |= NS_QUERYATTR_RECURSING; @@ -3223,7 +3229,8 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype) result = query_recurse(client, qtype, NULL, - NULL); + NULL, + resuming); if (result == ISC_R_SUCCESS) client->query.attributes |= NS_QUERYATTR_RECURSING; From 2284b84d74cdfd62ecb962feb850de981bbc2196 Mon Sep 17 00:00:00 2001 From: Evan Hunt Date: Wed, 23 Apr 2008 21:32:57 +0000 Subject: [PATCH 008/137] Make "rrset-order fixed" a compile-time option. settable by "./configure --enable-fixed-rrset". Disabled by default. [rt17977] --- CHANGES | 4 +++ config.h.in | 5 ++- configure | 84 +++++++++++++++++++++++++++++---------------- configure.in | 21 +++++++++++- lib/bind9/check.c | 9 ++--- lib/dns/rbtdb.c | 6 +--- lib/dns/rdataslab.c | 8 ++--- 7 files changed, 89 insertions(+), 48 deletions(-) diff --git a/CHANGES b/CHANGES index 77ce4effae..561a7c6242 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,7 @@ +2362. [cleanup] Make "rrset-order fixed" a compile-time option. + settable by "./configure --enable-fixed-rrset". + Disabled by default. [rt17977] + 2361. [bug] "recursion" statistics counter could be counted multiple times for a single query. [RT #17990] diff --git a/config.h.in b/config.h.in index 3e6b2e4255..40069bc86a 100644 --- a/config.h.in +++ b/config.h.in @@ -16,7 +16,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: config.h.in,v 1.96 2008/03/20 04:51:00 marka Exp $ */ +/* $Id: config.h.in,v 1.97 2008/04/23 21:32:01 each Exp $ */ /*! \file */ @@ -326,3 +326,6 @@ int sigwait(const unsigned int *set, int *sig); /* Define to empty if the keyword `volatile' does not work. Warning: valid code using `volatile' can become incorrect without. Disable with care. */ #undef volatile + +/* Define to enable "rrset-order fixed" syntax. */ +#undef DNS_RDATASET_FIXED diff --git a/configure b/configure index e22606b87e..917ba4c281 100755 --- a/configure +++ b/configure @@ -14,7 +14,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. # -# $Id: configure,v 1.425 2008/03/31 14:59:39 fdupont Exp $ +# $Id: configure,v 1.426 2008/04/23 21:32:57 each Exp $ # # Portions Copyright (C) 1996-2001 Nominum, Inc. # @@ -29,7 +29,7 @@ # WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN # ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT # OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. -# From configure.in Revision: 1.440 . +# From configure.in Revision: 1.441 . # Guess values for system-dependent variables and create Makefiles. # Generated by GNU Autoconf 2.61. # @@ -1638,6 +1638,8 @@ Optional Features: --disable-linux-caps disable linux capabilities --enable-atomic enable machine specific atomic operations [default=autodetect] + --enable-fixed-rrset enable fixed rrset ordering + [default=no] Optional Packages: --with-PACKAGE[=ARG] use PACKAGE [ARG=yes] @@ -9614,7 +9616,7 @@ ia64-*-hpux*) ;; *-*-irix6*) # Find out which ABI we are using. - echo '#line 9617 "configure"' > conftest.$ac_ext + echo '#line 9619 "configure"' > conftest.$ac_ext if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 (eval $ac_compile) 2>&5 ac_status=$? @@ -11736,11 +11738,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:11739: $lt_compile\"" >&5) + (eval echo "\"\$as_me:11741: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:11743: \$? = $ac_status" >&5 + echo "$as_me:11745: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -11979,11 +11981,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:11982: $lt_compile\"" >&5) + (eval echo "\"\$as_me:11984: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:11986: \$? = $ac_status" >&5 + echo "$as_me:11988: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -12039,11 +12041,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:12042: $lt_compile\"" >&5) + (eval echo "\"\$as_me:12044: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:12046: \$? = $ac_status" >&5 + echo "$as_me:12048: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -14187,7 +14189,7 @@ else lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2 lt_status=$lt_dlunknown cat > conftest.$ac_ext < conftest.$ac_ext <&5) + (eval echo "\"\$as_me:16483: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:16485: \$? = $ac_status" >&5 + echo "$as_me:16487: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -16538,11 +16540,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:16541: $lt_compile\"" >&5) + (eval echo "\"\$as_me:16543: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:16545: \$? = $ac_status" >&5 + echo "$as_me:16547: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -17866,7 +17868,7 @@ else lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2 lt_status=$lt_dlunknown cat > conftest.$ac_ext < conftest.$ac_ext <&5) + (eval echo "\"\$as_me:18806: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:18808: \$? = $ac_status" >&5 + echo "$as_me:18810: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -18861,11 +18863,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:18864: $lt_compile\"" >&5) + (eval echo "\"\$as_me:18866: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:18868: \$? = $ac_status" >&5 + echo "$as_me:18870: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -20895,11 +20897,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:20898: $lt_compile\"" >&5) + (eval echo "\"\$as_me:20900: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:20902: \$? = $ac_status" >&5 + echo "$as_me:20904: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -21138,11 +21140,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:21141: $lt_compile\"" >&5) + (eval echo "\"\$as_me:21143: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:21145: \$? = $ac_status" >&5 + echo "$as_me:21147: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -21198,11 +21200,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:21201: $lt_compile\"" >&5) + (eval echo "\"\$as_me:21203: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:21205: \$? = $ac_status" >&5 + echo "$as_me:21207: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -23346,7 +23348,7 @@ else lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2 lt_status=$lt_dlunknown cat > conftest.$ac_ext < conftest.$ac_ext <>confdefs.h <<\_ACEOF +#define DNS_RDATASET_FIXED 1 +_ACEOF + + ;; + no) + ;; + *) + ;; +esac + # # The following sets up how non-blocking i/o is established. # Sunos, cygwin and solaris 2.x (x<5) require special handling. diff --git a/configure.in b/configure.in index 5674d8ced0..94935bfee3 100644 --- a/configure.in +++ b/configure.in @@ -18,7 +18,7 @@ AC_DIVERT_PUSH(1)dnl esyscmd([sed "s/^/# /" COPYRIGHT])dnl AC_DIVERT_POP()dnl -AC_REVISION($Revision: 1.440 $) +AC_REVISION($Revision: 1.441 $) AC_INIT(lib/dns/name.c) AC_PREREQ(2.59) @@ -2261,6 +2261,25 @@ AC_SUBST(ISC_PLATFORM_USEMACASM) ISC_ARCH_DIR=$arch AC_SUBST(ISC_ARCH_DIR) +# +# Activate "rrset-order fixed" or not? +# +AC_ARG_ENABLE(fixed-rrset, + [ --enable-fixed-rrset enable fixed rrset ordering + [[default=no]]], + enable_fixed="$enableval", + enable_fixed="no") +case "$enable_fixed" in + yes) + AC_DEFINE(DNS_RDATASET_FIXED, 1, + [Define to enable "rrset-order fixed" syntax.]) + ;; + no) + ;; + *) + ;; +esac + # # The following sets up how non-blocking i/o is established. # Sunos, cygwin and solaris 2.x (x<5) require special handling. diff --git a/lib/bind9/check.c b/lib/bind9/check.c index 3422f92cb4..d4f2192228 100644 --- a/lib/bind9/check.c +++ b/lib/bind9/check.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: check.c,v 1.91 2008/04/02 02:37:42 marka Exp $ */ +/* $Id: check.c,v 1.92 2008/04/23 21:32:01 each Exp $ */ /*! \file */ @@ -46,10 +46,6 @@ #include -#ifndef DNS_RDATASET_FIXED -#define DNS_RDATASET_FIXED 1 -#endif - static void freekey(char *key, unsigned int type, isc_symvalue_t value, void *userarg) { UNUSED(type); @@ -128,7 +124,8 @@ check_orderent(const cfg_obj_t *ent, isc_log_t *logctx) { } else if (strcasecmp(cfg_obj_asstring(obj), "fixed") == 0) { #if !DNS_RDATASET_FIXED cfg_obj_log(obj, logctx, ISC_LOG_WARNING, - "rrset-order: order 'fixed' not fully implemented"); + "rrset-order: order 'fixed' was disabled at " + "compilation time"); #endif } else if (strcasecmp(cfg_obj_asstring(obj), "random") != 0 && strcasecmp(cfg_obj_asstring(obj), "cyclic") != 0) { diff --git a/lib/dns/rbtdb.c b/lib/dns/rbtdb.c index 13da2b1f1e..ed2f16fca7 100644 --- a/lib/dns/rbtdb.c +++ b/lib/dns/rbtdb.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: rbtdb.c,v 1.258 2008/04/09 04:31:11 marka Exp $ */ +/* $Id: rbtdb.c,v 1.259 2008/04/23 21:32:01 each Exp $ */ /*! \file */ @@ -186,10 +186,6 @@ typedef isc_mutex_t nodelock_t; #define NODE_WEAKDOWNGRADE(l) ((void)0) #endif -#ifndef DNS_RDATASET_FIXED -#define DNS_RDATASET_FIXED 1 -#endif - /* * Allow clients with a virtual time of up to 5 minutes in the past to see * records that would have otherwise have expired. diff --git a/lib/dns/rdataslab.c b/lib/dns/rdataslab.c index 13e223337e..f84bed0393 100644 --- a/lib/dns/rdataslab.c +++ b/lib/dns/rdataslab.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: rdataslab.c,v 1.46 2008/04/02 02:37:42 marka Exp $ */ +/* $Id: rdataslab.c,v 1.47 2008/04/23 21:32:01 each Exp $ */ /*! \file */ @@ -33,10 +33,6 @@ #include #include -#ifndef DNS_RDATASET_FIXED -#define DNS_RDATASET_FIXED 1 -#endif - /* * The rdataslab structure allows iteration to occur in both load order * and DNSSEC order. The structure is as follows: @@ -848,8 +844,8 @@ dns_rdataslab_subtract(unsigned char *mslab, unsigned char *sslab, #if DNS_RDATASET_FIXED unsigned char *offsetbase; unsigned int *offsettable; -#endif unsigned int order; +#endif REQUIRE(tslabp != NULL && *tslabp == NULL); REQUIRE(mslab != NULL && sslab != NULL); From f9b52f6df4d18e91c68cc1d105dfaa87cbbf3cee Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Wed, 23 Apr 2008 23:18:16 +0000 Subject: [PATCH 009/137] auto update --- doc/private/branches | 1 + 1 file changed, 1 insertion(+) diff --git a/doc/private/branches b/doc/private/branches index cad1111b47..a80d245696 100644 --- a/doc/private/branches +++ b/doc/private/branches @@ -115,6 +115,7 @@ rt17729 new marka // 2008-03-06 03:56 +0000 rt17729a new marka // 2008-04-02 23:40 +0000 rt17828 new marka // 2008-04-09 23:06 +0000 rt17949 new +rt17977 new each // 2008-04-23 00:29 +0000 shane_dbbackend open skan open explorer skan-metazones1 private explorer From 66e50468dde42a9757ac489e738d8b2db8fd7f80 Mon Sep 17 00:00:00 2001 From: Evan Hunt Date: Thu, 24 Apr 2008 21:50:27 +0000 Subject: [PATCH 010/137] Change rrsetorder test two ways: 1) only test "fixed" ordering if it was compiled in 2) test whether "cyclic" ordering is cyclic, but don't rely on the initial state being predictable [rt17977] --- bin/tests/system/rrsetorder/clean.sh | 3 +- .../system/rrsetorder/dig.out.cyclic.good1 | 4 - .../system/rrsetorder/dig.out.cyclic.good2 | 4 - .../system/rrsetorder/dig.out.cyclic.good3 | 4 - .../system/rrsetorder/dig.out.cyclic.good4 | 4 - bin/tests/system/rrsetorder/tests.sh | 245 +++++++++--------- 6 files changed, 126 insertions(+), 138 deletions(-) delete mode 100644 bin/tests/system/rrsetorder/dig.out.cyclic.good1 delete mode 100644 bin/tests/system/rrsetorder/dig.out.cyclic.good2 delete mode 100644 bin/tests/system/rrsetorder/dig.out.cyclic.good3 delete mode 100644 bin/tests/system/rrsetorder/dig.out.cyclic.good4 diff --git a/bin/tests/system/rrsetorder/clean.sh b/bin/tests/system/rrsetorder/clean.sh index 0cb15620c2..9d8b7d0c59 100644 --- a/bin/tests/system/rrsetorder/clean.sh +++ b/bin/tests/system/rrsetorder/clean.sh @@ -14,9 +14,10 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: clean.sh,v 1.6 2007/09/26 03:22:44 marka Exp $ +# $Id: clean.sh,v 1.7 2008/04/24 21:50:27 each Exp $ rm -f dig.out.cyclic dig.out.fixed dig.out.random +rm -f dig.out.0 dig.out.1 dig.out.2 dig.out.3 rm -f ns2/root.bk rm -f ns?/named.run ns?/named.core rm -f */named.memstats diff --git a/bin/tests/system/rrsetorder/dig.out.cyclic.good1 b/bin/tests/system/rrsetorder/dig.out.cyclic.good1 deleted file mode 100644 index d2ca6fc366..0000000000 --- a/bin/tests/system/rrsetorder/dig.out.cyclic.good1 +++ /dev/null @@ -1,4 +0,0 @@ -1.2.3.1 -1.2.3.4 -1.2.3.3 -1.2.3.2 diff --git a/bin/tests/system/rrsetorder/dig.out.cyclic.good2 b/bin/tests/system/rrsetorder/dig.out.cyclic.good2 deleted file mode 100644 index c25c75601e..0000000000 --- a/bin/tests/system/rrsetorder/dig.out.cyclic.good2 +++ /dev/null @@ -1,4 +0,0 @@ -1.2.3.4 -1.2.3.3 -1.2.3.2 -1.2.3.1 diff --git a/bin/tests/system/rrsetorder/dig.out.cyclic.good3 b/bin/tests/system/rrsetorder/dig.out.cyclic.good3 deleted file mode 100644 index e8deb6717d..0000000000 --- a/bin/tests/system/rrsetorder/dig.out.cyclic.good3 +++ /dev/null @@ -1,4 +0,0 @@ -1.2.3.3 -1.2.3.2 -1.2.3.1 -1.2.3.4 diff --git a/bin/tests/system/rrsetorder/dig.out.cyclic.good4 b/bin/tests/system/rrsetorder/dig.out.cyclic.good4 deleted file mode 100644 index 3b27693958..0000000000 --- a/bin/tests/system/rrsetorder/dig.out.cyclic.good4 +++ /dev/null @@ -1,4 +0,0 @@ -1.2.3.2 -1.2.3.1 -1.2.3.4 -1.2.3.3 diff --git a/bin/tests/system/rrsetorder/tests.sh b/bin/tests/system/rrsetorder/tests.sh index de9136e99a..bb829e69d3 100644 --- a/bin/tests/system/rrsetorder/tests.sh +++ b/bin/tests/system/rrsetorder/tests.sh @@ -14,54 +14,60 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: tests.sh,v 1.5 2007/06/19 23:47:05 tbox Exp $ +# $Id: tests.sh,v 1.6 2008/04/24 21:50:27 each Exp $ SYSTEMTESTTOP=.. . $SYSTEMTESTTOP/conf.sh status=0 +if grep -q "^#define DNS_RDATASET_FIXED" $TOP/config.h; then + test_fixed=true +else + echo "I: Order 'fixed' disabled at compile time" + test_fixed=false +fi + # # # -echo "I: Checking order fixed (master)" -ret=0 -for i in 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 -do -$DIG +nosea +nocomm +nocmd +noquest +noadd +noauth +nocomm +nostat +short \ - -p 5300 @10.53.0.1 fixed.example > dig.out.fixed || ret=1 -cmp -s dig.out.fixed dig.out.fixed.good || ret=1 -done -if [ $ret != 0 ]; then echo "I:failed"; fi -status=`expr $status + $ret` +if $test_fixed; then + echo "I: Checking order fixed (master)" + ret=0 + for i in 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 + do + $DIG +nosea +nocomm +nocmd +noquest +noadd +noauth +nocomm +nostat +short \ + -p 5300 @10.53.0.1 fixed.example > dig.out.fixed || ret=1 + cmp -s dig.out.fixed dig.out.fixed.good || ret=1 + done + if [ $ret != 0 ]; then echo "I:failed"; fi + status=`expr $status + $ret` +fi # # # echo "I: Checking order cyclic (master)" ret=0 -match1=0 -match2=0 -match3=0 -match4=0 -for i in 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 +matches=0 +for i in 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 do -$DIG +nosea +nocomm +nocmd +noquest +noadd +noauth +nocomm +nostat +short \ - -p 5300 @10.53.0.1 cyclic.example > dig.out.cyclic || ret=1 -cmp -s dig.out.cyclic dig.out.cyclic.good1 || \ -cmp -s dig.out.cyclic dig.out.cyclic.good2 || \ -cmp -s dig.out.cyclic dig.out.cyclic.good3 || \ -cmp -s dig.out.cyclic dig.out.cyclic.good4 || \ -ret=1 - -cmp -s dig.out.cyclic dig.out.cyclic.good1 && match1=1 -cmp -s dig.out.cyclic dig.out.cyclic.good2 && match2=1 -cmp -s dig.out.cyclic dig.out.cyclic.good3 && match3=1 -cmp -s dig.out.cyclic dig.out.cyclic.good4 && match4=1 - + j=`expr $i % 4` + $DIG +nosea +nocomm +nocmd +noquest +noadd +noauth +nocomm +nostat +short \ + -p 5300 @10.53.0.1 cyclic.example > dig.out.cyclic || ret=1 + if [ $i -le 4 ]; then + cp dig.out.cyclic dig.out.$j + else + cmp -s dig.out.cyclic dig.out.$j && matches=`expr $matches + 1` + fi done -match=`expr $match1 + $match2 + $match3 + $match4` -if [ $match != 4 ]; then ret=1; fi +cmp -s dig.out.0 dig.out.1 && ret=1 +cmp -s dig.out.0 dig.out.2 && ret=1 +cmp -s dig.out.0 dig.out.3 && ret=1 +cmp -s dig.out.1 dig.out.2 && ret=1 +cmp -s dig.out.1 dig.out.3 && ret=1 +cmp -s dig.out.2 dig.out.3 && ret=1 +if [ $matches -ne 16 ]; then ret=1; fi if [ $ret != 0 ]; then echo "I:failed"; fi status=`expr $status + $ret` @@ -96,44 +102,43 @@ status=`expr $status + $ret` # # # -echo "I: Checking order fixed (slave)" -ret=0 -for i in 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 -do -$DIG +nosea +nocomm +nocmd +noquest +noadd +noauth +nocomm +nostat +short \ - -p 5300 @10.53.0.2 fixed.example > dig.out.fixed || ret=1 -cmp -s dig.out.fixed dig.out.fixed.good || ret=1 -done -if [ $ret != 0 ]; then echo "I:failed"; fi -status=`expr $status + $ret` +if $test_fixed; then + echo "I: Checking order fixed (slave)" + ret=0 + for i in 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 + do + $DIG +nosea +nocomm +nocmd +noquest +noadd +noauth +nocomm +nostat +short \ + -p 5300 @10.53.0.2 fixed.example > dig.out.fixed || ret=1 + cmp -s dig.out.fixed dig.out.fixed.good || ret=1 + done + if [ $ret != 0 ]; then echo "I:failed"; fi + status=`expr $status + $ret` +fi # # # echo "I: Checking order cyclic (slave)" ret=0 -match1=0 -match2=0 -match3=0 -match4=0 -for i in 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 +matches=0 +for i in 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 do -$DIG +nosea +nocomm +nocmd +noquest +noadd +noauth +nocomm +nostat +short \ - -p 5300 @10.53.0.2 cyclic.example > dig.out.cyclic || ret=1 -cmp -s dig.out.cyclic dig.out.cyclic.good1 || \ -cmp -s dig.out.cyclic dig.out.cyclic.good2 || \ -cmp -s dig.out.cyclic dig.out.cyclic.good3 || \ -cmp -s dig.out.cyclic dig.out.cyclic.good4 || \ -ret=1 - -cmp -s dig.out.cyclic dig.out.cyclic.good1 && match1=1 -cmp -s dig.out.cyclic dig.out.cyclic.good2 && match2=1 -cmp -s dig.out.cyclic dig.out.cyclic.good3 && match3=1 -cmp -s dig.out.cyclic dig.out.cyclic.good4 && match4=1 - + j=`expr $i % 4` + $DIG +nosea +nocomm +nocmd +noquest +noadd +noauth +nocomm +nostat +short \ + -p 5300 @10.53.0.2 cyclic.example > dig.out.cyclic || ret=1 + if [ $i -le 4 ]; then + cp dig.out.cyclic dig.out.$j + else + cmp -s dig.out.cyclic dig.out.$j && matches=`expr $matches + 1` + fi done -match=`expr $match1 + $match2 + $match3 + $match4` -if [ $match != 4 ]; then ret=1; fi +cmp -s dig.out.0 dig.out.1 && ret=1 +cmp -s dig.out.0 dig.out.2 && ret=1 +cmp -s dig.out.0 dig.out.3 && ret=1 +cmp -s dig.out.1 dig.out.2 && ret=1 +cmp -s dig.out.1 dig.out.3 && ret=1 +cmp -s dig.out.2 dig.out.3 && ret=1 +if [ $matches -ne 16 ]; then ret=1; fi if [ $ret != 0 ]; then echo "I:failed"; fi status=`expr $status + $ret` @@ -184,44 +189,43 @@ echo "I: Re-starting slave" # # # -echo "I: Checking order fixed (slave loaded from disk)" -ret=0 -for i in 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 -do -$DIG +nosea +nocomm +nocmd +noquest +noadd +noauth +nocomm +nostat +short \ - -p 5300 @10.53.0.2 fixed.example > dig.out.fixed || ret=1 -cmp -s dig.out.fixed dig.out.fixed.good || ret=1 -done -if [ $ret != 0 ]; then echo "I:failed"; fi -status=`expr $status + $ret` +if $test_fixed; then + echo "I: Checking order fixed (slave loaded from disk)" + ret=0 + for i in 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 + do + $DIG +nosea +nocomm +nocmd +noquest +noadd +noauth +nocomm +nostat +short \ + -p 5300 @10.53.0.2 fixed.example > dig.out.fixed || ret=1 + cmp -s dig.out.fixed dig.out.fixed.good || ret=1 + done + if [ $ret != 0 ]; then echo "I:failed"; fi + status=`expr $status + $ret` +fi # # # echo "I: Checking order cyclic (slave loaded from disk)" ret=0 -match1=0 -match2=0 -match3=0 -match4=0 -for i in 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 +matches=0 +for i in 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 do -$DIG +nosea +nocomm +nocmd +noquest +noadd +noauth +nocomm +nostat +short \ - -p 5300 @10.53.0.2 cyclic.example > dig.out.cyclic || ret=1 -cmp -s dig.out.cyclic dig.out.cyclic.good1 || \ -cmp -s dig.out.cyclic dig.out.cyclic.good2 || \ -cmp -s dig.out.cyclic dig.out.cyclic.good3 || \ -cmp -s dig.out.cyclic dig.out.cyclic.good4 || \ -ret=1 - -cmp -s dig.out.cyclic dig.out.cyclic.good1 && match1=1 -cmp -s dig.out.cyclic dig.out.cyclic.good2 && match2=1 -cmp -s dig.out.cyclic dig.out.cyclic.good3 && match3=1 -cmp -s dig.out.cyclic dig.out.cyclic.good4 && match4=1 - + j=`expr $i % 4` + $DIG +nosea +nocomm +nocmd +noquest +noadd +noauth +nocomm +nostat +short \ + -p 5300 @10.53.0.2 cyclic.example > dig.out.cyclic || ret=1 + if [ $i -le 4 ]; then + cp dig.out.cyclic dig.out.$j + else + cmp -s dig.out.cyclic dig.out.$j && matches=`expr $matches + 1` + fi done -match=`expr $match1 + $match2 + $match3 + $match4` -if [ $match != 4 ]; then ret=1; fi +cmp -s dig.out.0 dig.out.1 && ret=1 +cmp -s dig.out.0 dig.out.2 && ret=1 +cmp -s dig.out.0 dig.out.3 && ret=1 +cmp -s dig.out.1 dig.out.2 && ret=1 +cmp -s dig.out.1 dig.out.3 && ret=1 +cmp -s dig.out.2 dig.out.3 && ret=1 +if [ $matches -ne 16 ]; then ret=1; fi if [ $ret != 0 ]; then echo "I:failed"; fi status=`expr $status + $ret` @@ -256,44 +260,43 @@ status=`expr $status + $ret` # # # -echo "I: Checking order fixed (cache)" -ret=0 -for i in 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 -do -$DIG +nosea +nocomm +nocmd +noquest +noadd +noauth +nocomm +nostat +short \ - -p 5300 @10.53.0.3 fixed.example > dig.out.fixed || ret=1 -cmp -s dig.out.fixed dig.out.fixed.good || ret=1 -done -if [ $ret != 0 ]; then echo "I:failed"; fi -status=`expr $status + $ret` +if $test_fixed; then + echo "I: Checking order fixed (cache)" + ret=0 + for i in 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 + do + $DIG +nosea +nocomm +nocmd +noquest +noadd +noauth +nocomm +nostat +short \ + -p 5300 @10.53.0.3 fixed.example > dig.out.fixed || ret=1 + cmp -s dig.out.fixed dig.out.fixed.good || ret=1 + done + if [ $ret != 0 ]; then echo "I:failed"; fi + status=`expr $status + $ret` +fi # # # echo "I: Checking order cyclic (cache)" ret=0 -match1=0 -match2=0 -match3=0 -match4=0 -for i in 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 +matches=0 +for i in 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 do -$DIG +nosea +nocomm +nocmd +noquest +noadd +noauth +nocomm +nostat +short \ - -p 5300 @10.53.0.3 cyclic.example > dig.out.cyclic || ret=1 -cmp -s dig.out.cyclic dig.out.cyclic.good1 || \ -cmp -s dig.out.cyclic dig.out.cyclic.good2 || \ -cmp -s dig.out.cyclic dig.out.cyclic.good3 || \ -cmp -s dig.out.cyclic dig.out.cyclic.good4 || \ -ret=1 - -cmp -s dig.out.cyclic dig.out.cyclic.good1 && match1=1 -cmp -s dig.out.cyclic dig.out.cyclic.good2 && match2=1 -cmp -s dig.out.cyclic dig.out.cyclic.good3 && match3=1 -cmp -s dig.out.cyclic dig.out.cyclic.good4 && match4=1 - + j=`expr $i % 4` + $DIG +nosea +nocomm +nocmd +noquest +noadd +noauth +nocomm +nostat +short \ + -p 5300 @10.53.0.3 cyclic.example > dig.out.cyclic || ret=1 + if [ $i -le 4 ]; then + cp dig.out.cyclic dig.out.$j + else + cmp -s dig.out.cyclic dig.out.$j && matches=`expr $matches + 1` + fi done -match=`expr $match1 + $match2 + $match3 + $match4` -if [ $match != 4 ]; then ret=1; fi +cmp -s dig.out.0 dig.out.1 && ret=1 +cmp -s dig.out.0 dig.out.2 && ret=1 +cmp -s dig.out.0 dig.out.3 && ret=1 +cmp -s dig.out.1 dig.out.2 && ret=1 +cmp -s dig.out.1 dig.out.3 && ret=1 +cmp -s dig.out.2 dig.out.3 && ret=1 +if [ $matches -ne 16 ]; then ret=1; fi if [ $ret != 0 ]; then echo "I:failed"; fi status=`expr $status + $ret` From af3e516f771c8ba376a8cd954a7233badfce8cdc Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Thu, 24 Apr 2008 23:30:21 +0000 Subject: [PATCH 011/137] newcopyrights --- util/copyrights | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/util/copyrights b/util/copyrights index 616aadfbf4..c1f0cd2ab3 100644 --- a/util/copyrights +++ b/util/copyrights @@ -667,7 +667,7 @@ ./bin/tests/system/resolver/ns1/root.hint ZONE 2000,2001,2004,2007 ./bin/tests/system/resolver/prereq.sh SH 2000,2001,2004,2007 ./bin/tests/system/resolver/tests.sh SH 2000,2001,2004,2007 -./bin/tests/system/rrsetorder/clean.sh SH 2006,2007 +./bin/tests/system/rrsetorder/clean.sh SH 2006,2007,2008 ./bin/tests/system/rrsetorder/dig.out.cyclic.good1 X 2006 ./bin/tests/system/rrsetorder/dig.out.cyclic.good2 X 2006 ./bin/tests/system/rrsetorder/dig.out.cyclic.good3 X 2006 @@ -701,7 +701,7 @@ ./bin/tests/system/rrsetorder/ns1/root.db ZONE 2006,2007 ./bin/tests/system/rrsetorder/ns2/named.conf CONF-C 2006,2007 ./bin/tests/system/rrsetorder/ns3/named.conf CONF-C 2006,2007 -./bin/tests/system/rrsetorder/tests.sh SH 2006,2007 +./bin/tests/system/rrsetorder/tests.sh SH 2006,2007,2008 ./bin/tests/system/run.sh SH 2000,2001,2004,2007 ./bin/tests/system/runall.sh SH 2000,2001,2004,2007 ./bin/tests/system/send.pl PERL 2001,2004,2007 From 1dd754dcdf868e3a7d02d4f3f812f83df1d50521 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Thu, 24 Apr 2008 23:46:59 +0000 Subject: [PATCH 012/137] update copyright notice --- bin/tests/system/rrsetorder/clean.sh | 4 ++-- bin/tests/system/rrsetorder/tests.sh | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/bin/tests/system/rrsetorder/clean.sh b/bin/tests/system/rrsetorder/clean.sh index 9d8b7d0c59..d5b245cc8c 100644 --- a/bin/tests/system/rrsetorder/clean.sh +++ b/bin/tests/system/rrsetorder/clean.sh @@ -1,6 +1,6 @@ #!/bin/sh # -# Copyright (C) 2006, 2007 Internet Systems Consortium, Inc. ("ISC") +# Copyright (C) 2006-2008 Internet Systems Consortium, Inc. ("ISC") # # Permission to use, copy, modify, and/or distribute this software for any # purpose with or without fee is hereby granted, provided that the above @@ -14,7 +14,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: clean.sh,v 1.7 2008/04/24 21:50:27 each Exp $ +# $Id: clean.sh,v 1.8 2008/04/24 23:46:59 tbox Exp $ rm -f dig.out.cyclic dig.out.fixed dig.out.random rm -f dig.out.0 dig.out.1 dig.out.2 dig.out.3 diff --git a/bin/tests/system/rrsetorder/tests.sh b/bin/tests/system/rrsetorder/tests.sh index bb829e69d3..76bfe9ac96 100644 --- a/bin/tests/system/rrsetorder/tests.sh +++ b/bin/tests/system/rrsetorder/tests.sh @@ -1,6 +1,6 @@ #!/bin/sh # -# Copyright (C) 2006, 2007 Internet Systems Consortium, Inc. ("ISC") +# Copyright (C) 2006-2008 Internet Systems Consortium, Inc. ("ISC") # # Permission to use, copy, modify, and/or distribute this software for any # purpose with or without fee is hereby granted, provided that the above @@ -14,7 +14,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: tests.sh,v 1.6 2008/04/24 21:50:27 each Exp $ +# $Id: tests.sh,v 1.7 2008/04/24 23:46:59 tbox Exp $ SYSTEMTESTTOP=.. . $SYSTEMTESTTOP/conf.sh From 71a7aaa631bad972b337a5f1c96fe18cc4fefcb6 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Sun, 27 Apr 2008 03:32:06 +0000 Subject: [PATCH 013/137] update --- util/copyrights | 4 ---- 1 file changed, 4 deletions(-) diff --git a/util/copyrights b/util/copyrights index c1f0cd2ab3..2ff09d03ca 100644 --- a/util/copyrights +++ b/util/copyrights @@ -668,10 +668,6 @@ ./bin/tests/system/resolver/prereq.sh SH 2000,2001,2004,2007 ./bin/tests/system/resolver/tests.sh SH 2000,2001,2004,2007 ./bin/tests/system/rrsetorder/clean.sh SH 2006,2007,2008 -./bin/tests/system/rrsetorder/dig.out.cyclic.good1 X 2006 -./bin/tests/system/rrsetorder/dig.out.cyclic.good2 X 2006 -./bin/tests/system/rrsetorder/dig.out.cyclic.good3 X 2006 -./bin/tests/system/rrsetorder/dig.out.cyclic.good4 X 2006 ./bin/tests/system/rrsetorder/dig.out.fixed.good X 2006 ./bin/tests/system/rrsetorder/dig.out.random.good1 X 2006 ./bin/tests/system/rrsetorder/dig.out.random.good10 X 2006 From bf34d65771c2a9825b4f595e83179ba1edefad36 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 02:45:59 +0000 Subject: [PATCH 014/137] Add correct changes message. 2356. [bug] Builtin mutex profiler was not scalable enough. [RT #17436] --- CHANGES | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/CHANGES b/CHANGES index deb59227a9..16d0cf28de 100644 --- a/CHANGES +++ b/CHANGES @@ -1,15 +1,15 @@ 2361. [bug] "recursion" statistics counter could be counted multiple times for a single query. [RT #17990] +2356. [bug] Builtin mutex profiler was not scalable enough. + [RT #17436] + 2347. [bug] Delete now traverses the RB tree in the canonical order. [RT #17451] 2343. [bug] (Seemingly) duplicate IPv6 entries could be created in ADB. [RT #17837] -2355. [func] Extend the number statistics counters available. - [RT #17590] - --- 9.3.5 released --- --- 9.3.5rc2 released --- From e088ebb8f110e9ed9221fefe4af2a5238f557014 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 02:47:56 +0000 Subject: [PATCH 015/137] 2329. [bug] Clearer help text for dig's '-x' and '-i' options. --- CHANGES | 2 ++ bin/dig/dig.c | 6 +++--- 2 files changed, 5 insertions(+), 3 deletions(-) diff --git a/CHANGES b/CHANGES index 16d0cf28de..834cc308f0 100644 --- a/CHANGES +++ b/CHANGES @@ -10,6 +10,8 @@ 2343. [bug] (Seemingly) duplicate IPv6 entries could be created in ADB. [RT #17837] +2329. [bug] Clearer help text for dig's '-x' and '-i' options. + --- 9.3.5 released --- --- 9.3.5rc2 released --- diff --git a/bin/dig/dig.c b/bin/dig/dig.c index 763613dfca..eff16e0b55 100644 --- a/bin/dig/dig.c +++ b/bin/dig/dig.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: dig.c,v 1.157.2.13.2.35 2007/08/28 07:19:07 tbox Exp $ */ +/* $Id: dig.c,v 1.157.2.13.2.36 2008/04/28 02:47:56 marka Exp $ */ #include #include @@ -136,8 +136,8 @@ help(void) { " q-type is one of (a,any,mx,ns,soa,hinfo,axfr,txt,...) [default:a]\n" " (Use ixfr=version for type ixfr)\n" " q-opt is one of:\n" -" -x dot-notation (shortcut for in-addr lookups)\n" -" -i (IP6.INT reverse IPv6 lookups)\n" +" -x dot-notation (shortcut for reverse lookups)\n" +" -i (use IP6.INT for IPv6 reverse lookups)\n" " -f filename (batch mode)\n" " -b address[#port] (bind to source address/port)\n" " -p port (specify port number)\n" From f9f8465fdd71fc8cfc4e63af742f5856c9427aac Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 03:18:36 +0000 Subject: [PATCH 016/137] 2330. [bug] Remove potential race condition when handling over memory events. [RT #17572] --- CHANGES | 7 +++++++ lib/dns/adb.c | 29 +++++++++++++++++++++++------ lib/dns/cache.c | 9 ++++++--- lib/isc/include/isc/mem.h | 34 +++++++++++++++++++++++++++++----- lib/isc/mem.c | 17 +++++++++++++---- lib/isc/win32/libisc.def | 1 + 6 files changed, 79 insertions(+), 18 deletions(-) diff --git a/CHANGES b/CHANGES index 834cc308f0..7b1897119a 100644 --- a/CHANGES +++ b/CHANGES @@ -10,6 +10,13 @@ 2343. [bug] (Seemingly) duplicate IPv6 entries could be created in ADB. [RT #17837] +2330. [bug] Remove potential race condition when handling + over memory events. [RT #17572] + + WARNING: API CHANGE: over memory callback + function now needs to call isc_mem_waterack(). + See for details. + 2329. [bug] Clearer help text for dig's '-x' and '-i' options. --- 9.3.5 released --- diff --git a/lib/dns/adb.c b/lib/dns/adb.c index 8ec237e2a1..456a0b5adf 100644 --- a/lib/dns/adb.c +++ b/lib/dns/adb.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: adb.c,v 1.181.2.11.2.35 2008/04/18 19:03:00 each Exp $ */ +/* $Id: adb.c,v 1.181.2.11.2.36 2008/04/28 03:18:35 marka Exp $ */ /* * Implementation notes @@ -116,6 +116,7 @@ struct dns_adb { isc_mutex_t lock; isc_mutex_t reflock; /* Covers irefcnt, erefcnt */ + isc_mutex_t overmemlock; /*%< Covers overmem */ isc_mem_t *mctx; dns_view_t *view; isc_timermgr_t *timermgr; @@ -1982,6 +1983,7 @@ destroy(dns_adb_t *adb) { DESTROYLOCK(&adb->reflock); DESTROYLOCK(&adb->lock); DESTROYLOCK(&adb->mplock); + DESTROYLOCK(&adb->overmemlock); isc_mem_putanddetach(&adb->mctx, adb, sizeof(dns_adb_t)); } @@ -2052,6 +2054,10 @@ dns_adb_create(isc_mem_t *mem, dns_view_t *view, isc_timermgr_t *timermgr, if (result != ISC_R_SUCCESS) goto fail0d; + result = isc_mutex_init(&adb->overmemlock); + if (result != ISC_R_SUCCESS) + goto fail0e; + /* * Initialize the bucket locks for names and elements. * May as well initialize the list heads, too. @@ -2154,6 +2160,8 @@ dns_adb_create(isc_mem_t *mem, dns_view_t *view, isc_timermgr_t *timermgr, if (adb->afmp != NULL) isc_mempool_destroy(&adb->afmp); + DESTROYLOCK(&adb->overmemlock); + fail0e: DESTROYLOCK(&adb->reflock); fail0d: DESTROYLOCK(&adb->mplock); @@ -3569,12 +3577,21 @@ water(void *arg, int mark) { DP(ISC_LOG_DEBUG(1), "adb reached %s water mark", overmem ? "high" : "low"); - adb->overmem = overmem; - if (overmem) { - isc_interval_set(&interval, 0, 1); - (void)isc_timer_reset(adb->timer, isc_timertype_once, NULL, - &interval, ISC_TRUE); + /* + * We can't use adb->lock as there is potential for water + * to be called when adb->lock is held. + */ + LOCK(&adb->overmemlock); + if (adb->overmem != overmem) { + adb->overmem = overmem; + if (overmem) { + isc_interval_set(&interval, 0, 1); + (void)isc_timer_reset(adb->timer, isc_timertype_once, + NULL, &interval, ISC_TRUE); + } + isc_mem_waterack(adb->mctx, mark); } + UNLOCK(&adb->overmemlock); } void diff --git a/lib/dns/cache.c b/lib/dns/cache.c index f45af90d08..d1fade2d90 100644 --- a/lib/dns/cache.c +++ b/lib/dns/cache.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: cache.c,v 1.45.2.4.8.15 2006/08/01 01:07:05 marka Exp $ */ +/* $Id: cache.c,v 1.45.2.4.8.16 2008/04/28 03:18:36 marka Exp $ */ #include @@ -909,8 +909,11 @@ water(void *arg, int mark) { LOCK(&cache->cleaner.lock); - dns_db_overmem(cache->db, overmem); - cache->cleaner.overmem = overmem; + if (overmem != cache->cleaner.overmem) { + dns_db_overmem(cache->db, overmem); + cache->cleaner.overmem = overmem; + isc_mem_waterack(cache->mctx, mark); + } if (cache->cleaner.overmem_event != NULL) isc_task_send(cache->cleaner.task, diff --git a/lib/isc/include/isc/mem.h b/lib/isc/include/isc/mem.h index bb94f5236b..92cdffe6dd 100644 --- a/lib/isc/include/isc/mem.h +++ b/lib/isc/include/isc/mem.h @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: mem.h,v 1.54.12.7 2007/08/28 07:19:15 tbox Exp $ */ +/* $Id: mem.h,v 1.54.12.8 2008/04/28 03:18:36 marka Exp $ */ #ifndef ISC_MEM_H #define ISC_MEM_H 1 @@ -271,10 +271,28 @@ void isc_mem_setwater(isc_mem_t *mctx, isc_mem_water_t water, void *water_arg, size_t hiwater, size_t lowater); /* - * Set high and low water marks for this memory context. When the memory - * usage of 'mctx' exceeds 'hiwater', '(water)(water_arg, ISC_MEM_HIWATER)' - * will be called. When the usage drops below 'lowater', 'water' will - * again be called, this time with ISC_MEM_LOWATER. + * Set high and low water marks for this memory context. + * When the memory usage of 'mctx' exceeds 'hiwater', + * '(water)(water_arg, #ISC_MEM_HIWATER)' will be called. 'water' needs to + * call isc_mem_waterack() with #ISC_MEM_HIWATER to acknowlege the state + * change. 'water' may be called multiple times. + * + * When the usage drops below 'lowater', 'water' will again be called, this + * time with #ISC_MEM_LOWATER. 'water' need to calls isc_mem_waterack() with + * #ISC_MEM_LOWATER to acknowlege the change. + * + * static void + * water(void *arg, int mark) { + * struct foo *foo = arg; + * + * LOCK(&foo->marklock); + * if (foo->mark != mark) { + * foo->mark = mark; + * .... + * isc_mem_waterack(foo->mctx, mark); + * } + * UNLOCK(&foo->marklock); + * } * * If 'water' is NULL then 'water_arg', 'hi_water' and 'lo_water' are * ignored and the state is reset. @@ -285,6 +303,12 @@ isc_mem_setwater(isc_mem_t *mctx, isc_mem_water_t water, void *water_arg, * hi_water >= lo_water */ +void +isc_mem_waterack(isc_mem_t *ctx, int mark); +/*%< + * Called to acknowledge changes in signalled by calls to 'water'. + */ + /* * Memory pools */ diff --git a/lib/isc/mem.c b/lib/isc/mem.c index 8bfe967295..fa880918dc 100644 --- a/lib/isc/mem.c +++ b/lib/isc/mem.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: mem.c,v 1.98.2.7.2.12 2007/11/26 23:45:51 tbox Exp $ */ +/* $Id: mem.c,v 1.98.2.7.2.13 2008/04/28 03:18:36 marka Exp $ */ #include @@ -1036,7 +1036,6 @@ isc__mem_get(isc_mem_t *ctx, size_t size FLARG) { ADD_TRACE(ctx, ptr, size, file, line); if (ctx->hi_water != 0U && !ctx->hi_called && ctx->inuse > ctx->hi_water) { - ctx->hi_called = ISC_TRUE; call_water = ISC_TRUE; } if (ctx->inuse > ctx->maxinuse) { @@ -1080,8 +1079,6 @@ isc__mem_put(isc_mem_t *ctx, void *ptr, size_t size FLARG) */ if (ctx->hi_called && (ctx->inuse < ctx->lo_water || ctx->lo_water == 0U)) { - ctx->hi_called = ISC_FALSE; - if (ctx->water != NULL) call_water = ISC_TRUE; } @@ -1091,6 +1088,18 @@ isc__mem_put(isc_mem_t *ctx, void *ptr, size_t size FLARG) (ctx->water)(ctx->water_arg, ISC_MEM_LOWATER); } +void +isc_mem_waterack(isc_mem_t *ctx, int flag) { + REQUIRE(VALID_CONTEXT(ctx)); + + LOCK(&ctx->lock); + if (flag == ISC_MEM_LOWATER) + ctx->hi_called = ISC_FALSE; + else if (flag == ISC_MEM_HIWATER) + ctx->hi_called = ISC_TRUE; + UNLOCK(&ctx->lock); +} + #if ISC_MEM_TRACKLINES static void print_active(isc_mem_t *mctx, FILE *out) { diff --git a/lib/isc/win32/libisc.def b/lib/isc/win32/libisc.def index 897dd4d0df..fe227487ad 100644 --- a/lib/isc/win32/libisc.def +++ b/lib/isc/win32/libisc.def @@ -218,6 +218,7 @@ isc_mem_setdestroycheck isc_mem_setquota isc_mem_setwater isc_mem_stats +isc_mem_waterack isc_mempool_associatelock isc_mempool_create isc_mempool_destroy From c81ae073423885eff716b433058ebca583bf2ff8 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 03:28:10 +0000 Subject: [PATCH 017/137] 2331. [bug] Failure to regenerate any signatures was not being reported nor being past back to the UPDATE client. [RT #17570] --- CHANGES | 4 ++++ bin/named/update.c | 31 ++++++++++++++++++++----------- 2 files changed, 24 insertions(+), 11 deletions(-) diff --git a/CHANGES b/CHANGES index 7b1897119a..a5f34e4fa6 100644 --- a/CHANGES +++ b/CHANGES @@ -10,6 +10,10 @@ 2343. [bug] (Seemingly) duplicate IPv6 entries could be created in ADB. [RT #17837] +2331. [bug] Failure to regenerate any signatures was not being + reported nor being past back to the UPDATE client. + [RT #17570] + 2330. [bug] Remove potential race condition when handling over memory events. [RT #17572] diff --git a/bin/named/update.c b/bin/named/update.c index 6733d76902..b556935a7b 100644 --- a/bin/named/update.c +++ b/bin/named/update.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: update.c,v 1.88.2.5.2.35 2008/01/17 23:45:27 tbox Exp $ */ +/* $Id: update.c,v 1.88.2.5.2.36 2008/04/28 03:28:10 marka Exp $ */ #include @@ -1612,10 +1612,10 @@ find_zone_keys(dns_zone_t *zone, dns_db_t *db, dns_dbversion_t *ver, * Add RRSIG records for an RRset, recording the change in "diff". */ static isc_result_t -add_sigs(dns_db_t *db, dns_dbversion_t *ver, dns_name_t *name, - dns_rdatatype_t type, dns_diff_t *diff, dst_key_t **keys, - unsigned int nkeys, isc_mem_t *mctx, isc_stdtime_t inception, - isc_stdtime_t expire) +add_sigs(ns_client_t *client, dns_zone_t *zone, dns_db_t *db, + dns_dbversion_t *ver, dns_name_t *name, dns_rdatatype_t type, + dns_diff_t *diff, dst_key_t **keys, unsigned int nkeys, + isc_mem_t *mctx, isc_stdtime_t inception, isc_stdtime_t expire) { isc_result_t result; dns_dbnode_t *node = NULL; @@ -1624,6 +1624,7 @@ add_sigs(dns_db_t *db, dns_dbversion_t *ver, dns_name_t *name, isc_buffer_t buffer; unsigned char data[1024]; /* XXX */ unsigned int i; + isc_boolean_t added_sig = ISC_FALSE; dns_rdataset_init(&rdataset); isc_buffer_init(&buffer, data, sizeof(data)); @@ -1648,6 +1649,13 @@ add_sigs(dns_db_t *db, dns_dbversion_t *ver, dns_name_t *name, CHECK(update_one_rr(db, ver, diff, DNS_DIFFOP_ADD, name, rdataset.ttl, &sig_rdata)); dns_rdata_reset(&sig_rdata); + added_sig = ISC_TRUE; + } + if (!added_sig) { + update_log(client, zone, ISC_LOG_ERROR, + "found no private keys, " + "unable to generate any signatures"); + result = ISC_R_NOTFOUND; } failure: @@ -1767,9 +1775,9 @@ update_signatures(ns_client_t *client, dns_zone_t *zone, dns_db_t *db, */ CHECK(rrset_exists(db, newver, name, type, 0, &flag)); if (flag) { - CHECK(add_sigs(db, newver, name, type, - &sig_diff, zone_keys, nkeys, - client->mctx, inception, + CHECK(add_sigs(client, zone, db, newver, name, + type, &sig_diff, zone_keys, + nkeys, client->mctx, inception, expire)); } skip: @@ -1953,9 +1961,10 @@ update_signatures(ns_client_t *client, dns_zone_t *zone, dns_db_t *db, dns_rdatatype_rrsig, dns_rdatatype_nsec, NULL, &sig_diff)); } else if (t->op == DNS_DIFFOP_ADD) { - CHECK(add_sigs(db, newver, &t->name, dns_rdatatype_nsec, - &sig_diff, zone_keys, nkeys, - client->mctx, inception, expire)); + CHECK(add_sigs(client, zone, db, newver, &t->name, + dns_rdatatype_nsec, &sig_diff, + zone_keys, nkeys, client->mctx, + inception, expire)); } else { INSIST(0); } From aef875b27e94586a1f3644d53705e6f5ea4b5daf Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 03:30:51 +0000 Subject: [PATCH 018/137] update #2331 description --- CHANGES | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/CHANGES b/CHANGES index 561a7c6242..e36a40618c 100644 --- a/CHANGES +++ b/CHANGES @@ -90,7 +90,8 @@ 2332. [contrib] query-loc-0.4.0. [RT #17602] 2331. [bug] Failure to regenerate any signatures was not being - reported or past back to the UPDATE client. [RT #17570] + reported nor being past back to the UPDATE client. + [RT #17570] 2330. [bug] Remove potential race condition when handling over memory events. [RT #17572] From 58f4058b004b307ddf5d208ff4e96a1f26f2a18c Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 03:38:07 +0000 Subject: [PATCH 019/137] 2325. [port] Linux: use capset() function if available. [RT #17557] --- CHANGES | 2 + bin/named/unix/os.c | 25 ++++++++++- config.h.in | 8 +++- configure | 101 ++++++++++++++++++++++++++++++++++++++++++-- configure.in | 5 ++- 5 files changed, 133 insertions(+), 8 deletions(-) diff --git a/CHANGES b/CHANGES index a5f34e4fa6..eac14d9929 100644 --- a/CHANGES +++ b/CHANGES @@ -23,6 +23,8 @@ 2329. [bug] Clearer help text for dig's '-x' and '-i' options. +2325. [port] Linux: use capset() function if available. [RT #17557] + --- 9.3.5 released --- --- 9.3.5rc2 released --- diff --git a/bin/named/unix/os.c b/bin/named/unix/os.c index f802666039..7db048cf60 100644 --- a/bin/named/unix/os.c +++ b/bin/named/unix/os.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: os.c,v 1.46.2.4.8.30 2008/01/17 23:45:27 tbox Exp $ */ +/* $Id: os.c,v 1.46.2.4.8.31 2008/04/28 03:37:18 marka Exp $ */ #include #include @@ -114,6 +114,16 @@ static int dfd[2] = { -1, -1 }; static isc_boolean_t non_root = ISC_FALSE; static isc_boolean_t non_root_caps = ISC_FALSE; +#if defined(HAVE_CAPSET) +#undef _POSIX_SOURCE +#ifdef HAVE_SYS_CAPABILITY_H +#include +#else +#include +int capset(cap_user_header_t hdrp, const cap_user_data_t datap); +#endif +#include +#else /* * We define _LINUX_FS_H to prevent it from being included. We don't need * anything from it, and the files it includes cause warnings with 2.2 @@ -146,6 +156,7 @@ static isc_boolean_t non_root_caps = ISC_FALSE; #endif #define SYS_capset __NR_capset #endif +#endif static void linux_setcaps(unsigned int caps) { @@ -163,13 +174,23 @@ linux_setcaps(unsigned int caps) { cap.effective = caps; cap.permitted = caps; cap.inheritable = 0; - if (syscall(SYS_capset, &caphead, &cap) < 0) { +#ifdef HAVE_CAPSET + if (capset(&caphead, &cap) < 0 ) { isc__strerror(errno, strbuf, sizeof(strbuf)); ns_main_earlyfatal("capset failed: %s:" " please ensure that the capset kernel" " module is loaded. see insmod(8)", strbuf); } +#else + if (syscall(SYS_capset, &caphead, &cap) < 0) { + isc__strerror(errno, strbuf, sizeof(strbuf)); + ns_main_earlyfatal("syscall(capset) failed: %s:" + " please ensure that the capset kernel" + " module is loaded. see insmod(8)", + strbuf); + } +#endif } static void diff --git a/config.h.in b/config.h.in index 388c402400..b173693781 100644 --- a/config.h.in +++ b/config.h.in @@ -16,7 +16,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: config.h.in,v 1.47.2.3.2.30 2008/01/04 03:39:56 marka Exp $ */ +/* $Id: config.h.in,v 1.47.2.3.2.33 2008/04/28 03:38:07 marka Exp $ */ /*** *** This file is not to be included by any public header files, because @@ -153,6 +153,9 @@ int sigwait(const unsigned int *set, int *sig); /* Define if you cannot bind() before connect() for TCP sockets. */ #undef BROKEN_TCP_BIND_BEFORE_CONNECT +/* Define to 1 if you have the `capset' function. */ +#undef HAVE_CAPSET + /* Define to 1 if you have the header file. */ #undef HAVE_DLFCN_H @@ -204,6 +207,9 @@ int sigwait(const unsigned int *set, int *sig); /* Define to 1 if you have the header file. */ #undef HAVE_STRING_H +/* Define to 1 if you have the header file. */ +#undef HAVE_SYS_CAPABILITY_H + /* Define to 1 if you have the header file. */ #undef HAVE_SYS_PARAM_H diff --git a/configure b/configure index 514a7ac14a..080413db91 100755 --- a/configure +++ b/configure @@ -14,7 +14,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. # -# $Id: configure,v 1.284.2.19.2.74 2008/01/11 04:51:58 marka Exp $ +# $Id: configure,v 1.284.2.19.2.75 2008/04/28 03:38:07 marka Exp $ # # Portions Copyright (C) 1996-2001 Nominum, Inc. # @@ -29,7 +29,7 @@ # WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN # ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT # OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. -# From configure.in Revision: 1.294.2.23.2.82 . +# From configure.in Revision: 1.294.2.23.2.83 . # Guess values for system-dependent variables and create Makefiles. # Generated by GNU Autoconf 2.61. # @@ -27031,7 +27031,8 @@ fi case "$enable_linux_caps" in yes|'') -for ac_header in linux/capability.h + +for ac_header in linux/capability.h sys/capability.h do as_ac_Header=`echo "ac_cv_header_$ac_header" | $as_tr_sh` if { as_var=$as_ac_Header; eval "test \"\${$as_var+set}\" = set"; }; then @@ -27168,6 +27169,100 @@ _ACEOF fi +done + + +for ac_func in capset +do +as_ac_var=`echo "ac_cv_func_$ac_func" | $as_tr_sh` +{ echo "$as_me:$LINENO: checking for $ac_func" >&5 +echo $ECHO_N "checking for $ac_func... $ECHO_C" >&6; } +if { as_var=$as_ac_var; eval "test \"\${$as_var+set}\" = set"; }; then + echo $ECHO_N "(cached) $ECHO_C" >&6 +else + cat >conftest.$ac_ext <<_ACEOF +/* confdefs.h. */ +_ACEOF +cat confdefs.h >>conftest.$ac_ext +cat >>conftest.$ac_ext <<_ACEOF +/* end confdefs.h. */ +/* Define $ac_func to an innocuous variant, in case declares $ac_func. + For example, HP-UX 11i declares gettimeofday. */ +#define $ac_func innocuous_$ac_func + +/* System header to define __stub macros and hopefully few prototypes, + which can conflict with char $ac_func (); below. + Prefer to if __STDC__ is defined, since + exists even on freestanding compilers. */ + +#ifdef __STDC__ +# include +#else +# include +#endif + +#undef $ac_func + +/* Override any GCC internal prototype to avoid an error. + Use char because int might match the return type of a GCC + builtin and then its argument prototype would still apply. */ +#ifdef __cplusplus +extern "C" +#endif +char $ac_func (); +/* The GNU C library defines this for functions which it implements + to always fail with ENOSYS. Some functions are actually named + something starting with __ and the normal name is an alias. */ +#if defined __stub_$ac_func || defined __stub___$ac_func +choke me +#endif + +int +main () +{ +return $ac_func (); + ; + return 0; +} +_ACEOF +rm -f conftest.$ac_objext conftest$ac_exeext +if { (ac_try="$ac_link" +case "(($ac_try" in + *\"* | *\`* | *\\*) ac_try_echo=\$ac_try;; + *) ac_try_echo=$ac_try;; +esac +eval "echo \"\$as_me:$LINENO: $ac_try_echo\"") >&5 + (eval "$ac_link") 2>conftest.er1 + ac_status=$? + grep -v '^ *+' conftest.er1 >conftest.err + rm -f conftest.er1 + cat conftest.err >&5 + echo "$as_me:$LINENO: \$? = $ac_status" >&5 + (exit $ac_status); } && { + test -z "$ac_c_werror_flag" || + test ! -s conftest.err + } && test -s conftest$ac_exeext && + $as_test_x conftest$ac_exeext; then + eval "$as_ac_var=yes" +else + echo "$as_me: failed program was:" >&5 +sed 's/^/| /' conftest.$ac_ext >&5 + + eval "$as_ac_var=no" +fi + +rm -f core conftest.err conftest.$ac_objext conftest_ipa8_conftest.oo \ + conftest$ac_exeext conftest.$ac_ext +fi +ac_res=`eval echo '${'$as_ac_var'}'` + { echo "$as_me:$LINENO: result: $ac_res" >&5 +echo "${ECHO_T}$ac_res" >&6; } +if test `eval echo '${'$as_ac_var'}'` = yes; then + cat >>confdefs.h <<_ACEOF +#define `echo "HAVE_$ac_func" | $as_tr_cpp` 1 +_ACEOF + +fi done ;; diff --git a/configure.in b/configure.in index d4ea2bd2fe..b980873b09 100644 --- a/configure.in +++ b/configure.in @@ -18,7 +18,7 @@ AC_DIVERT_PUSH(1)dnl esyscmd([sed "s/^/# /" COPYRIGHT])dnl AC_DIVERT_POP()dnl -AC_REVISION($Revision: 1.294.2.23.2.82 $) +AC_REVISION($Revision: 1.294.2.23.2.83 $) AC_INIT(lib/dns/name.c) AC_PREREQ(2.13) @@ -1686,7 +1686,8 @@ AC_ARG_ENABLE(linux-caps, [ --disable-linux-caps disable linux capabilities]) case "$enable_linux_caps" in yes|'') - AC_CHECK_HEADERS(linux/capability.h) + AC_CHECK_HEADERS(linux/capability.h sys/capability.h) + AC_CHECK_FUNCS(capset) ;; no) ;; From 0f94937f44225befa2a37675c4fb4b4d5d5a57fa Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 03:42:12 +0000 Subject: [PATCH 020/137] sync with HEAD --- util/kit.sh | 19 +++++++++++++++---- 1 file changed, 15 insertions(+), 4 deletions(-) diff --git a/util/kit.sh b/util/kit.sh index d848065cd4..f5ee7bfd2c 100644 --- a/util/kit.sh +++ b/util/kit.sh @@ -1,9 +1,9 @@ #!/bin/sh # -# Copyright (C) 2004 Internet Systems Consortium, Inc. ("ISC") +# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC") # Copyright (C) 2000-2003 Internet Software Consortium. # -# Permission to use, copy, modify, and distribute this software for any +# Permission to use, copy, modify, and/or distribute this software for any # purpose with or without fee is hereby granted, provided that the above # copyright notice and this permission notice appear in all copies. # @@ -15,7 +15,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: kit.sh,v 1.20.2.1.10.4 2004/06/03 02:52:00 marka Exp $ +# $Id: kit.sh,v 1.20.2.1.10.5 2008/04/28 03:42:12 marka Exp $ # Make a release kit # @@ -114,7 +114,7 @@ fi # we still delete them from releases just in case something # gets accidentally resurrected. -rm -rf EXCLUDED TODO conftools util doc/design doc/dev doc/expired \ +rm -rf TODO EXCLUDED conftools util doc/design doc/dev doc/expired \ doc/html doc/todo doc/private bin/lwresd doc/man \ lib/lwres/man/resolver.5 \ bin/tests/system/relay lib/cfg @@ -126,6 +126,17 @@ chmod +x configure install-sh mkinstalldirs \ lib/bind/configure lib/bind/mkinstalldirs \ bin/tests/system/ifconfig.sh +# Fix files which should be using DOS style newlines +windirs=`find lib bin -type d -name win32` +windirs="$windirs win32utils" +winnames="-name *.mak -or -name *.dsp -or -name *.dsw -or -name *.txt -or -name *.bat" +for f in `find $windirs -type f \( $winnames \) -print` +do + awk '{sub("\r$", "", $0); printf("%s\r\n", $0);}' < $f > tmp + touch -r $f tmp + mv tmp $f +done + cd .. || exit 1 kit=$topdir.tar.gz From 2e7459026eaa0c125bea13bf0c2f953c177cb39d Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 04:14:32 +0000 Subject: [PATCH 021/137] 2333. [bug] Fix off by one error in isc_time_nowplusinterval(). [RT #17608] --- CHANGES | 3 +++ lib/isc/unix/time.c | 4 ++-- 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/CHANGES b/CHANGES index eac14d9929..57e4e6c2ac 100644 --- a/CHANGES +++ b/CHANGES @@ -10,6 +10,9 @@ 2343. [bug] (Seemingly) duplicate IPv6 entries could be created in ADB. [RT #17837] +2333. [bug] Fix off by one error in isc_time_nowplusinterval(). + [RT #17608] + 2331. [bug] Failure to regenerate any signatures was not being reported nor being past back to the UPDATE client. [RT #17570] diff --git a/lib/isc/unix/time.c b/lib/isc/unix/time.c index 39c851cebe..b0b9cb58b5 100644 --- a/lib/isc/unix/time.c +++ b/lib/isc/unix/time.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: time.c,v 1.34.2.6.2.4 2004/03/06 08:15:03 marka Exp $ */ +/* $Id: time.c,v 1.34.2.6.2.5 2008/04/28 04:14:32 marka Exp $ */ #include @@ -225,7 +225,7 @@ isc_time_nowplusinterval(isc_time_t *t, const isc_interval_t *i) { t->seconds = tv.tv_sec + i->seconds; t->nanoseconds = tv.tv_usec * NS_PER_US + i->nanoseconds; - if (t->nanoseconds > NS_PER_S) { + if (t->nanoseconds >= NS_PER_S) { t->seconds++; t->nanoseconds -= NS_PER_S; } From 562262279355b87d349b642dc29f9bf8e8792d09 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 04:19:28 +0000 Subject: [PATCH 022/137] 2334. [bug] Bad REQUIRES in fromstruct_in_naptr(), off by one bug in fromstruct_txt(). [RT #17609] --- CHANGES | 3 +++ lib/dns/rdata/generic/txt_16.c | 4 ++-- lib/dns/rdata/in_1/naptr_35.c | 6 +++--- 3 files changed, 8 insertions(+), 5 deletions(-) diff --git a/CHANGES b/CHANGES index 57e4e6c2ac..1697d96f5c 100644 --- a/CHANGES +++ b/CHANGES @@ -10,6 +10,9 @@ 2343. [bug] (Seemingly) duplicate IPv6 entries could be created in ADB. [RT #17837] +2334. [bug] Bad REQUIRES in fromstruct_in_naptr(), off by one + bug in fromstruct_txt(). [RT #17609] + 2333. [bug] Fix off by one error in isc_time_nowplusinterval(). [RT #17608] diff --git a/lib/dns/rdata/generic/txt_16.c b/lib/dns/rdata/generic/txt_16.c index 625fa2be8e..998cb3740a 100644 --- a/lib/dns/rdata/generic/txt_16.c +++ b/lib/dns/rdata/generic/txt_16.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: txt_16.c,v 1.37.12.7 2007/08/28 07:19:15 tbox Exp $ */ +/* $Id: txt_16.c,v 1.37.12.8 2008/04/28 04:19:28 marka Exp $ */ /* Reviewed: Thu Mar 16 15:40:00 PST 2000 by bwelling */ @@ -142,7 +142,7 @@ fromstruct_txt(ARGS_FROMSTRUCT) { while (region.length > 0) { length = uint8_fromregion(®ion); isc_region_consume(®ion, 1); - if (region.length <= length) + if (region.length < length) return (ISC_R_UNEXPECTEDEND); isc_region_consume(®ion, length); } diff --git a/lib/dns/rdata/in_1/naptr_35.c b/lib/dns/rdata/in_1/naptr_35.c index f3c93c7c03..de6e4f4491 100644 --- a/lib/dns/rdata/in_1/naptr_35.c +++ b/lib/dns/rdata/in_1/naptr_35.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: naptr_35.c,v 1.43.2.1.2.3 2004/03/06 08:14:17 marka Exp $ */ +/* $Id: naptr_35.c,v 1.43.2.1.2.4 2008/04/28 04:19:28 marka Exp $ */ /* Reviewed: Thu Mar 16 16:52:50 PST 2000 by bwelling */ @@ -321,8 +321,8 @@ fromstruct_in_naptr(ARGS_FROMSTRUCT) { REQUIRE(naptr->common.rdtype == type); REQUIRE(naptr->common.rdclass == rdclass); REQUIRE(naptr->flags != NULL || naptr->flags_len == 0); - REQUIRE(naptr->service != NULL && naptr->service_len == 0); - REQUIRE(naptr->regexp != NULL && naptr->regexp_len == 0); + REQUIRE(naptr->service != NULL || naptr->service_len == 0); + REQUIRE(naptr->regexp != NULL || naptr->regexp_len == 0); UNUSED(type); UNUSED(rdclass); From 67542fde0e5ac5bbc6c8ec05be497469bdeb96f7 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 04:26:34 +0000 Subject: [PATCH 023/137] 2335. [port] sunos: libbind and *printf() support for long long. [RT #17513] --- CHANGES | 3 + README | 3 + lib/bind/bsd/strerror.c | 6 +- lib/bind/bsd/strtoul.c | 10 +- lib/bind/config.h.in | 6 + lib/bind/configure | 425 +++++++++++++++++++++++++----------- lib/bind/configure.in | 53 ++++- lib/bind/include/isc/misc.h | 3 +- lib/bind/irs/irp.c | 10 +- lib/bind/isc/ctl_clnt.c | 5 +- lib/bind/isc/ctl_srvr.c | 5 +- lib/bind/port_after.h.in | 81 ++++++- lib/isc/print.c | 91 ++++++-- 13 files changed, 546 insertions(+), 155 deletions(-) diff --git a/CHANGES b/CHANGES index 1697d96f5c..fce72167b7 100644 --- a/CHANGES +++ b/CHANGES @@ -10,6 +10,9 @@ 2343. [bug] (Seemingly) duplicate IPv6 entries could be created in ADB. [RT #17837] +2335. [port] sunos: libbind and *printf() support for long long. + [RT #17513] + 2334. [bug] Bad REQUIRES in fromstruct_in_naptr(), off by one bug in fromstruct_txt(). [RT #17609] diff --git a/README b/README index 709df1267a..a711b1505e 100644 --- a/README +++ b/README @@ -347,6 +347,9 @@ Building on your system, and some require Perl; see bin/tests/system/README for details. + SunOS 4 requires "printf" to be installed to make the shared + libraries. sh-utils-1.16 provides a "printf" which compiles + on SunOS 4. Documentation diff --git a/lib/bind/bsd/strerror.c b/lib/bind/bsd/strerror.c index d13adbb03b..5fba248f36 100644 --- a/lib/bind/bsd/strerror.c +++ b/lib/bind/bsd/strerror.c @@ -1,6 +1,6 @@ #if defined(LIBC_SCCS) && !defined(lint) static const char sccsid[] = "@(#)strerror.c 8.1 (Berkeley) 6/4/93"; -static const char rcsid[] = "$Id: strerror.c,v 1.3.2.1 2001/11/02 17:45:31 gson Exp $"; +static const char rcsid[] = "$Id: strerror.c,v 1.3.2.1.10.1 2008/04/28 04:25:42 marka Exp $"; #endif /* LIBC_SCCS and not lint */ /* @@ -60,12 +60,14 @@ isc_strerror(int num) { static char ebuf[40] = UPREFIX; /* 64-bit number + slop */ u_int errnum; char *p, *t; +#ifndef USE_SYSERROR_LIST const char *ret; +#endif char tmp[40]; errnum = num; /* convert to unsigned */ #ifdef USE_SYSERROR_LIST - if (errnum < sys_nerr) + if (errnum < (u_int)sys_nerr) return (sys_errlist[errnum]); #else #undef strerror diff --git a/lib/bind/bsd/strtoul.c b/lib/bind/bsd/strtoul.c index d110f30943..0741fc5504 100644 --- a/lib/bind/bsd/strtoul.c +++ b/lib/bind/bsd/strtoul.c @@ -1,6 +1,6 @@ #if defined(LIBC_SCCS) && !defined(lint) static const char sccsid[] = "@(#)strtoul.c 8.1 (Berkeley) 6/4/93"; -static const char rcsid[] = "$Id: strtoul.c,v 1.1.2.1 2003/06/27 03:51:35 marka Exp $"; +static const char rcsid[] = "$Id: strtoul.c,v 1.1.2.1.4.1 2008/04/28 04:25:42 marka Exp $"; #endif /* LIBC_SCCS and not lint */ /* @@ -70,7 +70,7 @@ strtoul(const char *nptr, char **endptr, int base) { * See strtol for comments as to the logic used. */ do { - c = *(unsigned char *)s++; + c = *(const unsigned char *)s++; } while (isspace(c)); if (c == '-') { neg = 1; @@ -87,7 +87,7 @@ strtoul(const char *nptr, char **endptr, int base) { base = c == '0' ? 8 : 10; cutoff = (u_long)ULONG_MAX / (u_long)base; cutlim = (u_long)ULONG_MAX % (u_long)base; - for (acc = 0, any = 0;; c = *(unsigned char*)s++) { + for (acc = 0, any = 0;; c = *(const unsigned char*)s++) { if (isdigit(c)) c -= '0'; else if (isalpha(c)) @@ -96,7 +96,7 @@ strtoul(const char *nptr, char **endptr, int base) { break; if (c >= base) break; - if (any < 0 || acc > cutoff || acc == cutoff && c > cutlim) + if (any < 0 || acc > cutoff || (acc == cutoff && c > cutlim)) any = -1; else { any = 1; @@ -110,7 +110,7 @@ strtoul(const char *nptr, char **endptr, int base) { } else if (neg) acc = -acc; if (endptr != 0) - *endptr = (char *)(any ? s - 1 : nptr); + DE_CONST((any ? s - 1 : nptr), *endptr); return (acc); } diff --git a/lib/bind/config.h.in b/lib/bind/config.h.in index 69ea285430..27df74f838 100644 --- a/lib/bind/config.h.in +++ b/lib/bind/config.h.in @@ -5,6 +5,7 @@ #undef HAVE_STROPTS_H #undef HAVE_SYS_TIMERS_H #undef HAVE_SYS_SELECT_H +#undef HAVE_MEMORY_H #undef SYS_CDEFS_H #undef _POSIX_PTHREAD_SEMANTICS #undef POSIX_GETPWUID_R @@ -13,6 +14,11 @@ #undef POSIX_GETGRNAM_R #undef HAVE_MEMMOVE #undef HAVE_MEMCHR +#undef SPRINTF_CHAR +#undef VSPRINTF_CHAR +#undef USE_SYSERROR_LIST +#undef NEED_STRTOUL +#undef NEED_SUN4PROTOS #undef NEED_SETGROUPENT #undef NEED_GETGROUPLIST diff --git a/lib/bind/configure b/lib/bind/configure index 0926fd9df6..d25508143c 100644 --- a/lib/bind/configure +++ b/lib/bind/configure @@ -1,5 +1,5 @@ #! /bin/sh -# From configure.in Revision: 1.83.2.5.2.38 . +# From configure.in Revision: 1.83.2.5.2.39 . # Guess values for system-dependent variables and create Makefiles. # Generated by GNU Autoconf 2.61. # @@ -929,7 +929,6 @@ ISC_PLATFORM_NEEDSTRSEP ISC_PLATFORM_NEEDVSNPRINTF ISC_EXTRA_OBJS ISC_EXTRA_SRCS -USE_SYSERROR_LIST ISC_PLATFORM_QUADFORMAT ISC_SOCKLEN_T GETGROUPLIST_ARGS @@ -4248,7 +4247,8 @@ done -for ac_header in fcntl.h db.h paths.h sys/time.h unistd.h sys/sockio.h sys/select.h sys/timers.h stropts.h + +for ac_header in fcntl.h db.h paths.h sys/time.h unistd.h sys/sockio.h sys/select.h sys/timers.h stropts.h memory.h do as_ac_Header=`echo "ac_cv_header_$ac_header" | $as_tr_sh` if { as_var=$as_ac_Header; eval "test \"\${$as_var+set}\" = set"; }; then @@ -7258,6 +7258,96 @@ _ACEOF fi +{ echo "$as_me:$LINENO: checking for strtoul" >&5 +echo $ECHO_N "checking for strtoul... $ECHO_C" >&6; } +if test "${ac_cv_func_strtoul+set}" = set; then + echo $ECHO_N "(cached) $ECHO_C" >&6 +else + cat >conftest.$ac_ext <<_ACEOF +/* confdefs.h. */ +_ACEOF +cat confdefs.h >>conftest.$ac_ext +cat >>conftest.$ac_ext <<_ACEOF +/* end confdefs.h. */ +/* Define strtoul to an innocuous variant, in case declares strtoul. + For example, HP-UX 11i declares gettimeofday. */ +#define strtoul innocuous_strtoul + +/* System header to define __stub macros and hopefully few prototypes, + which can conflict with char strtoul (); below. + Prefer to if __STDC__ is defined, since + exists even on freestanding compilers. */ + +#ifdef __STDC__ +# include +#else +# include +#endif + +#undef strtoul + +/* Override any GCC internal prototype to avoid an error. + Use char because int might match the return type of a GCC + builtin and then its argument prototype would still apply. */ +#ifdef __cplusplus +extern "C" +#endif +char strtoul (); +/* The GNU C library defines this for functions which it implements + to always fail with ENOSYS. Some functions are actually named + something starting with __ and the normal name is an alias. */ +#if defined __stub_strtoul || defined __stub___strtoul +choke me +#endif + +int +main () +{ +return strtoul (); + ; + return 0; +} +_ACEOF +rm -f conftest.$ac_objext conftest$ac_exeext +if { (ac_try="$ac_link" +case "(($ac_try" in + *\"* | *\`* | *\\*) ac_try_echo=\$ac_try;; + *) ac_try_echo=$ac_try;; +esac +eval "echo \"\$as_me:$LINENO: $ac_try_echo\"") >&5 + (eval "$ac_link") 2>conftest.er1 + ac_status=$? + grep -v '^ *+' conftest.er1 >conftest.err + rm -f conftest.er1 + cat conftest.err >&5 + echo "$as_me:$LINENO: \$? = $ac_status" >&5 + (exit $ac_status); } && { + test -z "$ac_c_werror_flag" || + test ! -s conftest.err + } && test -s conftest$ac_exeext && + $as_test_x conftest$ac_exeext; then + ac_cv_func_strtoul=yes +else + echo "$as_me: failed program was:" >&5 +sed 's/^/| /' conftest.$ac_ext >&5 + + ac_cv_func_strtoul=no +fi + +rm -f core conftest.err conftest.$ac_objext conftest_ipa8_conftest.oo \ + conftest$ac_exeext conftest.$ac_ext +fi +{ echo "$as_me:$LINENO: result: $ac_cv_func_strtoul" >&5 +echo "${ECHO_T}$ac_cv_func_strtoul" >&6; } +if test $ac_cv_func_strtoul = yes; then + : +else + cat >>confdefs.h <<\_ACEOF +#define NEED_STRTOUL 1 +_ACEOF + +fi + { echo "$as_me:$LINENO: checking for if_nametoindex" >&5 echo $ECHO_N "checking for if_nametoindex... $ECHO_C" >&6; } @@ -7624,6 +7714,61 @@ fi +if test -n "$NEED_STRERROR" +then + { echo "$as_me:$LINENO: checking for extern char * sys_errlist" >&5 +echo $ECHO_N "checking for extern char * sys_errlist... $ECHO_C" >&6; } + cat >conftest.$ac_ext <<_ACEOF +/* confdefs.h. */ +_ACEOF +cat confdefs.h >>conftest.$ac_ext +cat >>conftest.$ac_ext <<_ACEOF +/* end confdefs.h. */ + extern int sys_nerr; extern char *sys_errlist[]; +int +main () +{ + const char *p = sys_errlist[0]; + ; + return 0; +} +_ACEOF +rm -f conftest.$ac_objext conftest$ac_exeext +if { (ac_try="$ac_link" +case "(($ac_try" in + *\"* | *\`* | *\\*) ac_try_echo=\$ac_try;; + *) ac_try_echo=$ac_try;; +esac +eval "echo \"\$as_me:$LINENO: $ac_try_echo\"") >&5 + (eval "$ac_link") 2>conftest.er1 + ac_status=$? + grep -v '^ *+' conftest.er1 >conftest.err + rm -f conftest.er1 + cat conftest.err >&5 + echo "$as_me:$LINENO: \$? = $ac_status" >&5 + (exit $ac_status); } && { + test -z "$ac_c_werror_flag" || + test ! -s conftest.err + } && test -s conftest$ac_exeext && + $as_test_x conftest$ac_exeext; then + { echo "$as_me:$LINENO: result: yes" >&5 +echo "${ECHO_T}yes" >&6; } + cat >>confdefs.h <<\_ACEOF +#define USE_SYSERROR_LIST 1 +_ACEOF + +else + echo "$as_me: failed program was:" >&5 +sed 's/^/| /' conftest.$ac_ext >&5 + + { echo "$as_me:$LINENO: result: no" >&5 +echo "${ECHO_T}no" >&6; } +fi + +rm -f core conftest.err conftest.$ac_objext conftest_ipa8_conftest.oo \ + conftest$ac_exeext conftest.$ac_ext +fi + # # flockfile is usually provided by pthreads, but we may want to use it # even if compiled with --disable-threads. @@ -8972,7 +9117,7 @@ ia64-*-hpux*) ;; *-*-irix6*) # Find out which ABI we are using. - echo '#line 8975 "configure"' > conftest.$ac_ext + echo '#line 9120 "configure"' > conftest.$ac_ext if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 (eval $ac_compile) 2>&5 ac_status=$? @@ -11094,11 +11239,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:11097: $lt_compile\"" >&5) + (eval echo "\"\$as_me:11242: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:11101: \$? = $ac_status" >&5 + echo "$as_me:11246: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -11337,11 +11482,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:11340: $lt_compile\"" >&5) + (eval echo "\"\$as_me:11485: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:11344: \$? = $ac_status" >&5 + echo "$as_me:11489: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -11397,11 +11542,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:11400: $lt_compile\"" >&5) + (eval echo "\"\$as_me:11545: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:11404: \$? = $ac_status" >&5 + echo "$as_me:11549: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -13545,7 +13690,7 @@ else lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2 lt_status=$lt_dlunknown cat > conftest.$ac_ext < conftest.$ac_ext <&5) + (eval echo "\"\$as_me:15984: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:15843: \$? = $ac_status" >&5 + echo "$as_me:15988: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -15896,11 +16041,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:15899: $lt_compile\"" >&5) + (eval echo "\"\$as_me:16044: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:15903: \$? = $ac_status" >&5 + echo "$as_me:16048: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -17224,7 +17369,7 @@ else lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2 lt_status=$lt_dlunknown cat > conftest.$ac_ext < conftest.$ac_ext <&5) + (eval echo "\"\$as_me:18307: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:18166: \$? = $ac_status" >&5 + echo "$as_me:18311: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -18219,11 +18364,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:18222: $lt_compile\"" >&5) + (eval echo "\"\$as_me:18367: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:18226: \$? = $ac_status" >&5 + echo "$as_me:18371: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -20253,11 +20398,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:20256: $lt_compile\"" >&5) + (eval echo "\"\$as_me:20401: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:20260: \$? = $ac_status" >&5 + echo "$as_me:20405: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -20496,11 +20641,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:20499: $lt_compile\"" >&5) + (eval echo "\"\$as_me:20644: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:20503: \$? = $ac_status" >&5 + echo "$as_me:20648: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -20556,11 +20701,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:20559: $lt_compile\"" >&5) + (eval echo "\"\$as_me:20704: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:20563: \$? = $ac_status" >&5 + echo "$as_me:20708: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -22704,7 +22849,7 @@ else lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2 lt_status=$lt_dlunknown cat > conftest.$ac_ext < conftest.$ac_ext <>confdefs.h <<\_ACEOF +#define NEED_SUN4PROTOS 1 +_ACEOF + PORT_NONBLOCK="#define PORT_NONBLOCK O_NDELAY" PORT_DIR="port/sunos";; *-solaris2.[01234]) @@ -25917,6 +26066,128 @@ else ISC_PLATFORM_NEEDSTRSEP="#define ISC_PLATFORM_NEEDSTRSEP 1" fi + + +{ echo "$as_me:$LINENO: checking for char *sprintf" >&5 +echo $ECHO_N "checking for char *sprintf... $ECHO_C" >&6; } +cat >conftest.$ac_ext <<_ACEOF +/* confdefs.h. */ +_ACEOF +cat confdefs.h >>conftest.$ac_ext +cat >>conftest.$ac_ext <<_ACEOF +/* end confdefs.h. */ + +#include + +int +main () +{ + char buf[2]; return(*sprintf(buf,"x")); + ; + return 0; +} +_ACEOF +rm -f conftest.$ac_objext +if { (ac_try="$ac_compile" +case "(($ac_try" in + *\"* | *\`* | *\\*) ac_try_echo=\$ac_try;; + *) ac_try_echo=$ac_try;; +esac +eval "echo \"\$as_me:$LINENO: $ac_try_echo\"") >&5 + (eval "$ac_compile") 2>conftest.er1 + ac_status=$? + grep -v '^ *+' conftest.er1 >conftest.err + rm -f conftest.er1 + cat conftest.err >&5 + echo "$as_me:$LINENO: \$? = $ac_status" >&5 + (exit $ac_status); } && { + test -z "$ac_c_werror_flag" || + test ! -s conftest.err + } && test -s conftest.$ac_objext; then + cat >>confdefs.h <<\_ACEOF +#define SPRINTF_CHAR 1 +_ACEOF + +{ echo "$as_me:$LINENO: result: yes" >&5 +echo "${ECHO_T}yes" >&6; } + +else + echo "$as_me: failed program was:" >&5 +sed 's/^/| /' conftest.$ac_ext >&5 + + { echo "$as_me:$LINENO: result: no" >&5 +echo "${ECHO_T}no" >&6; } + +fi + +rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext + +{ echo "$as_me:$LINENO: checking for char *vsprintf" >&5 +echo $ECHO_N "checking for char *vsprintf... $ECHO_C" >&6; } +case $host in +*sunos4*) # not decared in any header file. +cat >>confdefs.h <<\_ACEOF +#define VSPRINTF_CHAR 1 +_ACEOF + +{ echo "$as_me:$LINENO: result: yes" >&5 +echo "${ECHO_T}yes" >&6; } +;; +*) +cat >conftest.$ac_ext <<_ACEOF +/* confdefs.h. */ +_ACEOF +cat confdefs.h >>conftest.$ac_ext +cat >>conftest.$ac_ext <<_ACEOF +/* end confdefs.h. */ + +#include + +int +main () +{ + char buf[2]; return(*vsprintf(buf,"x")); + ; + return 0; +} +_ACEOF +rm -f conftest.$ac_objext +if { (ac_try="$ac_compile" +case "(($ac_try" in + *\"* | *\`* | *\\*) ac_try_echo=\$ac_try;; + *) ac_try_echo=$ac_try;; +esac +eval "echo \"\$as_me:$LINENO: $ac_try_echo\"") >&5 + (eval "$ac_compile") 2>conftest.er1 + ac_status=$? + grep -v '^ *+' conftest.er1 >conftest.err + rm -f conftest.er1 + cat conftest.err >&5 + echo "$as_me:$LINENO: \$? = $ac_status" >&5 + (exit $ac_status); } && { + test -z "$ac_c_werror_flag" || + test ! -s conftest.err + } && test -s conftest.$ac_objext; then + cat >>confdefs.h <<\_ACEOF +#define VSPRINTF_CHAR 1 +_ACEOF + +{ echo "$as_me:$LINENO: result: yes" >&5 +echo "${ECHO_T}yes" >&6; } + +else + echo "$as_me: failed program was:" >&5 +sed 's/^/| /' conftest.$ac_ext >&5 + + { echo "$as_me:$LINENO: result: no" >&5 +echo "${ECHO_T}no" >&6; } + +fi + +rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext +;; +esac + { echo "$as_me:$LINENO: checking for vsnprintf" >&5 echo $ECHO_N "checking for vsnprintf... $ECHO_C" >&6; } if test "${ac_cv_func_vsnprintf+set}" = set; then @@ -26011,96 +26282,7 @@ fi -{ echo "$as_me:$LINENO: checking for strerror" >&5 -echo $ECHO_N "checking for strerror... $ECHO_C" >&6; } -if test "${ac_cv_func_strerror+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -/* Define strerror to an innocuous variant, in case declares strerror. - For example, HP-UX 11i declares gettimeofday. */ -#define strerror innocuous_strerror -/* System header to define __stub macros and hopefully few prototypes, - which can conflict with char strerror (); below. - Prefer to if __STDC__ is defined, since - exists even on freestanding compilers. */ - -#ifdef __STDC__ -# include -#else -# include -#endif - -#undef strerror - -/* Override any GCC internal prototype to avoid an error. - Use char because int might match the return type of a GCC - builtin and then its argument prototype would still apply. */ -#ifdef __cplusplus -extern "C" -#endif -char strerror (); -/* The GNU C library defines this for functions which it implements - to always fail with ENOSYS. Some functions are actually named - something starting with __ and the normal name is an alias. */ -#if defined __stub_strerror || defined __stub___strerror -choke me -#endif - -int -main () -{ -return strerror (); - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext conftest$ac_exeext -if { (ac_try="$ac_link" -case "(($ac_try" in - *\"* | *\`* | *\\*) ac_try_echo=\$ac_try;; - *) ac_try_echo=$ac_try;; -esac -eval "echo \"\$as_me:$LINENO: $ac_try_echo\"") >&5 - (eval "$ac_link") 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && { - test -z "$ac_c_werror_flag" || - test ! -s conftest.err - } && test -s conftest$ac_exeext && - $as_test_x conftest$ac_exeext; then - ac_cv_func_strerror=yes -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - - ac_cv_func_strerror=no -fi - -rm -f core conftest.err conftest.$ac_objext conftest_ipa8_conftest.oo \ - conftest$ac_exeext conftest.$ac_ext -fi -{ echo "$as_me:$LINENO: result: $ac_cv_func_strerror" >&5 -echo "${ECHO_T}$ac_cv_func_strerror" >&6; } -if test $ac_cv_func_strerror = yes; then - USE_SYSERROR_LIST="#undef USE_SYSERROR_LIST" -else - USE_SYSERROR_LIST="#define USE_SYSERROR_LIST 1" -fi - - - -# # Determine the printf format characters to use when printing # values of type isc_int64_t. We make the assumption that platforms # where a "long long" is the same size as a "long" (e.g., Alpha/OSF1) @@ -33211,7 +33393,6 @@ ISC_PLATFORM_NEEDSTRSEP!$ISC_PLATFORM_NEEDSTRSEP$ac_delim ISC_PLATFORM_NEEDVSNPRINTF!$ISC_PLATFORM_NEEDVSNPRINTF$ac_delim ISC_EXTRA_OBJS!$ISC_EXTRA_OBJS$ac_delim ISC_EXTRA_SRCS!$ISC_EXTRA_SRCS$ac_delim -USE_SYSERROR_LIST!$USE_SYSERROR_LIST$ac_delim ISC_PLATFORM_QUADFORMAT!$ISC_PLATFORM_QUADFORMAT$ac_delim ISC_SOCKLEN_T!$ISC_SOCKLEN_T$ac_delim GETGROUPLIST_ARGS!$GETGROUPLIST_ARGS$ac_delim @@ -33235,6 +33416,7 @@ GROUP_R_OK!$GROUP_R_OK$ac_delim GROUP_R_RETURN!$GROUP_R_RETURN$ac_delim GROUP_R_END_RESULT!$GROUP_R_END_RESULT$ac_delim GROUP_R_END_RETURN!$GROUP_R_END_RETURN$ac_delim +GROUP_R_ENT_ARGS!$GROUP_R_ENT_ARGS$ac_delim _ACEOF if test `sed -n "s/.*$ac_delim\$/X/p" conf$$subs.sed | grep -c X` = 97; then @@ -33276,7 +33458,6 @@ _ACEOF ac_delim='%!_!# ' for ac_last_try in false false false false false :; do cat >conf$$subs.sed <<_ACEOF -GROUP_R_ENT_ARGS!$GROUP_R_ENT_ARGS$ac_delim GROUP_R_SET_RESULT!$GROUP_R_SET_RESULT$ac_delim GROUP_R_SET_RETURN!$GROUP_R_SET_RETURN$ac_delim HOST_R_ARGS!$HOST_R_ARGS$ac_delim @@ -33354,7 +33535,7 @@ LIBOBJS!$LIBOBJS$ac_delim LTLIBOBJS!$LTLIBOBJS$ac_delim _ACEOF - if test `sed -n "s/.*$ac_delim\$/X/p" conf$$subs.sed | grep -c X` = 76; then + if test `sed -n "s/.*$ac_delim\$/X/p" conf$$subs.sed | grep -c X` = 75; then break elif $ac_last_try; then { { echo "$as_me:$LINENO: error: could not make $CONFIG_STATUS" >&5 diff --git a/lib/bind/configure.in b/lib/bind/configure.in index 8cc91e8e8f..b227fe5e1e 100644 --- a/lib/bind/configure.in +++ b/lib/bind/configure.in @@ -13,7 +13,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -AC_REVISION($Revision: 1.83.2.5.2.38 $) +AC_REVISION($Revision: 1.83.2.5.2.39 $) AC_INIT(resolv/herror.c) AC_PREREQ(2.13) @@ -169,7 +169,7 @@ AC_PROG_CC AC_HEADER_STDC -AC_CHECK_HEADERS(fcntl.h db.h paths.h sys/time.h unistd.h sys/sockio.h sys/select.h sys/timers.h stropts.h) +AC_CHECK_HEADERS(fcntl.h db.h paths.h sys/time.h unistd.h sys/sockio.h sys/select.h sys/timers.h stropts.h memory.h) AC_C_CONST AC_C_INLINE @@ -461,6 +461,7 @@ AC_SUBST(WANT_THREADS_OBJS) AC_CHECK_FUNC(strlcat, AC_DEFINE(HAVE_STRLCAT)) AC_CHECK_FUNC(memmove, AC_DEFINE(HAVE_MEMMOVE)) AC_CHECK_FUNC(memchr, AC_DEFINE(HAVE_MEMCHR)) +AC_CHECK_FUNC(strtoul, , AC_DEFINE(NEED_STRTOUL)) AC_CHECK_FUNC(if_nametoindex, [USE_IFNAMELINKID="#define USE_IFNAMELINKID 1"], @@ -490,6 +491,16 @@ AC_CHECK_FUNC(strerror, [NEED_STRERROR="#undef NEED_STRERROR"], [NEED_STRERROR="#define NEED_STRERROR 1"]) AC_SUBST(NEED_STRERROR) +if test -n "$NEED_STRERROR" +then + AC_MSG_CHECKING([for extern char * sys_errlist[]]) + AC_TRY_LINK([ extern int sys_nerr; extern char *sys_errlist[]; ], + [ const char *p = sys_errlist[0]; ], + AC_MSG_RESULT(yes) + AC_DEFINE(USE_SYSERROR_LIST), + AC_MSG_RESULT(no)) +fi + # # flockfile is usually provided by pthreads, but we may want to use it # even if compiled with --disable-threads. @@ -1050,6 +1061,7 @@ case "$host" in *-qnx*) PORT_DIR="port/qnx";; *-rhapsody*) PORT_DIR="port/rhapsody";; *-sunos4*) + AC_DEFINE(NEED_SUN4PROTOS) PORT_NONBLOCK="#define PORT_NONBLOCK O_NDELAY" PORT_DIR="port/sunos";; *-solaris2.[[01234]]) @@ -1246,6 +1258,38 @@ found_rt_iflist AC_CHECK_FUNC(strsep, [ISC_PLATFORM_NEEDSTRSEP="#undef ISC_PLATFORM_NEEDSTRSEP"], [ISC_PLATFORM_NEEDSTRSEP="#define ISC_PLATFORM_NEEDSTRSEP 1"]) + + +AC_MSG_CHECKING(for char *sprintf) +AC_TRY_COMPILE([ +#include +], +[ char buf[2]; return(*sprintf(buf,"x"));], +AC_DEFINE(SPRINTF_CHAR) +AC_MSG_RESULT(yes) +, +AC_MSG_RESULT(no) +) + +AC_MSG_CHECKING(for char *vsprintf) +case $host in +*sunos4*) # not decared in any header file. +AC_DEFINE(VSPRINTF_CHAR) +AC_MSG_RESULT(yes) +;; +*) +AC_TRY_COMPILE([ +#include +], +[ char buf[2]; return(*vsprintf(buf,"x"));], +AC_DEFINE(VSPRINTF_CHAR) +AC_MSG_RESULT(yes) +, +AC_MSG_RESULT(no) +) +;; +esac + AC_CHECK_FUNC(vsnprintf, [ISC_PLATFORM_NEEDVSNPRINTF="#undef ISC_PLATFORM_NEEDVSNPRINTF"], [ISC_EXTRA_OBJS="$ISC_EXTRA_OBJS print.$O" @@ -1256,12 +1300,7 @@ AC_SUBST(ISC_PLATFORM_NEEDVSNPRINTF) AC_SUBST(ISC_EXTRA_OBJS) AC_SUBST(ISC_EXTRA_SRCS) -AC_CHECK_FUNC(strerror, - [USE_SYSERROR_LIST="#undef USE_SYSERROR_LIST"], - [USE_SYSERROR_LIST="#define USE_SYSERROR_LIST 1"]) -AC_SUBST(USE_SYSERROR_LIST) -# # Determine the printf format characters to use when printing # values of type isc_int64_t. We make the assumption that platforms # where a "long long" is the same size as a "long" (e.g., Alpha/OSF1) diff --git a/lib/bind/include/isc/misc.h b/lib/bind/include/isc/misc.h index b08b02d289..a391974c18 100644 --- a/lib/bind/include/isc/misc.h +++ b/lib/bind/include/isc/misc.h @@ -16,13 +16,14 @@ */ /* - * $Id: misc.h,v 1.2.2.1.4.1 2004/03/09 08:33:31 marka Exp $ + * $Id: misc.h,v 1.2.2.1.4.2 2008/04/28 04:25:42 marka Exp $ */ #ifndef _ISC_MISC_H #define _ISC_MISC_H #include +#include #define bitncmp __bitncmp /*#define isc_movefile __isc_movefile */ diff --git a/lib/bind/irs/irp.c b/lib/bind/irs/irp.c index 649079c31f..4ddf2d883f 100644 --- a/lib/bind/irs/irp.c +++ b/lib/bind/irs/irp.c @@ -16,7 +16,7 @@ */ #if !defined(LINT) && !defined(CODECENTER) -static const char rcsid[] = "$Id: irp.c,v 1.3.2.1.10.4 2006/03/10 00:17:21 marka Exp $"; +static const char rcsid[] = "$Id: irp.c,v 1.3.2.1.10.5 2008/04/28 04:25:42 marka Exp $"; #endif /* Imports */ @@ -48,6 +48,12 @@ static const char rcsid[] = "$Id: irp.c,v 1.3.2.1.10.4 2006/03/10 00:17:21 marka #include "port_after.h" +#ifdef VSPRINTF_CHAR +# define VSPRINTF(x) strlen(vsprintf/**/x) +#else +# define VSPRINTF(x) ((size_t)vsprintf x) +#endif + /* Forward. */ static void irp_close(struct irs_acc *); @@ -541,7 +547,7 @@ irs_irp_send_command(struct irp_p *pvt, const char *fmt, ...) { } va_start(ap, fmt); - todo = vsprintf(buffer, fmt, ap); + todo = VSPRINTF((buffer, fmt, ap)); va_end(ap); if (todo > (int)sizeof(buffer) - 3) { syslog(LOG_CRIT, "memory overrun in irs_irp_send_command()"); diff --git a/lib/bind/isc/ctl_clnt.c b/lib/bind/isc/ctl_clnt.c index ddb2efbe66..d921b559c8 100644 --- a/lib/bind/isc/ctl_clnt.c +++ b/lib/bind/isc/ctl_clnt.c @@ -1,5 +1,5 @@ #if !defined(lint) && !defined(SABER) -static const char rcsid[] = "$Id: ctl_clnt.c,v 1.4.2.1.4.4 2007/05/18 06:25:17 marka Exp $"; +static const char rcsid[] = "$Id: ctl_clnt.c,v 1.4.2.1.4.5 2008/04/28 04:25:42 marka Exp $"; #endif /* not lint */ /* @@ -38,6 +38,9 @@ static const char rcsid[] = "$Id: ctl_clnt.c,v 1.4.2.1.4.4 2007/05/18 06:25:17 m #include #include #include +#ifdef HAVE_MEMORY_H +#include +#endif #include #include diff --git a/lib/bind/isc/ctl_srvr.c b/lib/bind/isc/ctl_srvr.c index 0d1b53dfef..11d39c7192 100644 --- a/lib/bind/isc/ctl_srvr.c +++ b/lib/bind/isc/ctl_srvr.c @@ -1,5 +1,5 @@ #if !defined(lint) && !defined(SABER) -static const char rcsid[] = "$Id: ctl_srvr.c,v 1.3.2.1.4.4 2006/12/07 04:52:50 marka Exp $"; +static const char rcsid[] = "$Id: ctl_srvr.c,v 1.3.2.1.4.5 2008/04/28 04:25:42 marka Exp $"; #endif /* not lint */ /* @@ -40,6 +40,9 @@ static const char rcsid[] = "$Id: ctl_srvr.c,v 1.3.2.1.4.4 2006/12/07 04:52:50 m #include #include #include +#ifdef HAVE_MEMORY_H +#include +#endif #include #include diff --git a/lib/bind/port_after.h.in b/lib/bind/port_after.h.in index 162535ee50..8ee135bcdd 100644 --- a/lib/bind/port_after.h.in +++ b/lib/bind/port_after.h.in @@ -22,6 +22,10 @@ @NEED_DAEMON@ @NEED_STRSEP@ @NEED_STRERROR@ +#ifdef NEED_STRERROR +const char *isc_strerror(int); +#define strerror isc_strerror +#endif @HAS_INET6_STRUCTS@ @HAVE_SIN6_SCOPE_ID@ @NEED_IN6ADDR_ANY@ @@ -30,7 +34,6 @@ @NEED_GETTIMEOFDAY@ @HAVE_STRNDUP@ @USE_FIONBIO_IOCTL@ -@USE_SYSERROR_LIST@ @INNETGR_ARGS@ @SETNETGRENT_ARGS@ @USE_IFNAMELINKID@ @@ -419,4 +422,80 @@ setnetgrent_r(const char *netgroup, NGR_R_ENT_ARGS); NGR_R_SET_RETURN setnetgrent_r(const char *netgroup); #endif + +#ifdef NEED_STRTOUL +unsigned long strtoul(const char *, char **, int); +#endif + +#ifdef NEED_SUN4PROTOS +#include +#ifndef __SIZE_TYPE__ +#define __SIZE_TYPE__ int +#endif +struct sockaddr; +struct iovec; +struct timeval; +struct timezone; +int fprintf(FILE *, const char *, ...); +int getsockname(int, struct sockaddr *, int *); +int getpeername(int, struct sockaddr *, int *); +int socket(int, int, int); +int connect(int, const struct sockaddr *, int); +int writev(int, struct iovec *, int); +int readv(int, struct iovec *, int); +int send(int, const char *, int, int); +void bzero(char *, int); +int recvfrom(int, char *, int, int, struct sockaddr *, int *); +int syslog(int, const char *, ... ); +int printf(const char *, ...); +__SIZE_TYPE__ fread(void *, __SIZE_TYPE__, __SIZE_TYPE__, FILE *); +__SIZE_TYPE__ fwrite(const void *, __SIZE_TYPE__, __SIZE_TYPE__, FILE *); +int fclose(FILE *); +int ungetc(int, FILE *); +int scanf(const char *, ...); +int sscanf(const char *, const char *, ... ); +int tolower(int); +int toupper(int); +int strcasecmp(const char *, const char *); +int strncasecmp(const char *, const char *, int); +int select(int, fd_set *, fd_set *, fd_set *, struct timeval *); +#ifdef gettimeofday +#undef gettimeofday +int gettimeofday(struct timeval *, struct timezone *); +#define gettimeofday isc__gettimeofday +#else +int gettimeofday(struct timeval *, struct timezone *); +#endif +long strtol(const char*, char **, int); +int fseek(FILE *, long, int); +int setsockopt(int, int, int, const char *, int); +int bind(int, const struct sockaddr *, int); +void bcopy(char *, char *, int); +int fputc(char, FILE *); +int listen(int, int); +int accept(int, struct sockaddr *, int *); +int getsockopt(int, int, int, char *, int *); +int vfprintf(FILE *, const char *, va_list); +int fflush(FILE *); +int fgetc(FILE *); +int fputs(const char *, FILE *); +int fchown(int, int, int); +void setbuf(FILE *, char *); +int gethostname(char *, int); +int rename(const char *, const char *); +time_t time(time_t *); +int fscanf(FILE *, const char *, ...); +int sscanf(const char *, const char *, ...); +int ioctl(int, int, caddr_t); +void perror(const char *); + +#if !defined(__USE_FIXED_PROTOTYPES__) && !defined(__cplusplus) && !defined(__STRICT_ANSI__) +/* + * 'gcc -ansi' changes the prototype for vsprintf(). + * Use this prototype when 'gcc -ansi' is not in effect. + */ +char *vsprintf(char *, const char *, va_list); +#endif +#endif + #endif diff --git a/lib/isc/print.c b/lib/isc/print.c index ee50b29e5d..c4fd4a187e 100644 --- a/lib/isc/print.c +++ b/lib/isc/print.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: print.c,v 1.22.2.3.2.4 2006/04/17 18:27:20 explorer Exp $ */ +/* $Id: print.c,v 1.22.2.3.2.5 2008/04/28 04:25:43 marka Exp $ */ /*! \file */ @@ -246,8 +246,24 @@ isc_print_vsnprintf(char *str, size_t size, const char *format, va_list ap) { head = ""; tmpui = tmpi; } - sprintf(buf, "%" ISC_PRINT_QUADFORMAT "u", - tmpui); + if (tmpui <= 0xffffffffU) + sprintf(buf, "%lu", + (unsigned long)tmpui); + else { + unsigned long mid; + unsigned long lo; + unsigned long hi; + lo = tmpui % 1000000000; + tmpui /= 1000000000; + mid = tmpui % 1000000000; + hi = tmpui / 1000000000; + if (hi != 0) + sprintf(buf, "%lu", hi); + else + buf[0] = '\n'; + sprintf(buf + strlen(buf), "%lu", mid); + sprintf(buf + strlen(buf), "%lu", lo); + } goto printint; case 'o': if (q) @@ -256,10 +272,29 @@ isc_print_vsnprintf(char *str, size_t size, const char *format, va_list ap) { tmpui = va_arg(ap, long int); else tmpui = va_arg(ap, int); - sprintf(buf, - alt ? "%#" ISC_PRINT_QUADFORMAT "o" - : "%" ISC_PRINT_QUADFORMAT "o", - tmpui); + if (tmpui <= 0xffffffffU) + sprintf(buf, alt ? "%#lo" : "%lo", + (unsigned long)tmpui); + else { + unsigned long mid; + unsigned long lo; + unsigned long hi; + lo = tmpui % 010000000000; + tmpui /= 010000000000; + mid = tmpui % 010000000000; + hi = tmpui / 010000000000; + if (hi != 0) { + sprintf(buf, + alt ? "%#lo" : "%lo", + hi); + sprintf(buf + strlen(buf), + "%lo", mid); + } else + sprintf(buf, + alt ? "%#lo" : "%lo", + mid); + sprintf(buf + strlen(buf), "%lo", lo); + } goto printint; case 'u': if (q) @@ -268,8 +303,24 @@ isc_print_vsnprintf(char *str, size_t size, const char *format, va_list ap) { tmpui = va_arg(ap, unsigned long int); else tmpui = va_arg(ap, unsigned int); - sprintf(buf, "%" ISC_PRINT_QUADFORMAT "u", - tmpui); + if (tmpui <= 0xffffffffU) + sprintf(buf, "%lu", + (unsigned long)tmpui); + else { + unsigned long mid; + unsigned long lo; + unsigned long hi; + lo = tmpui % 1000000000; + tmpui /= 1000000000; + mid = tmpui % 1000000000; + hi = tmpui / 1000000000; + if (hi != 0) + sprintf(buf, "%lu", hi); + else + buf[0] = '\n'; + sprintf(buf + strlen(buf), "%lu", mid); + sprintf(buf + strlen(buf), "%lu", lo); + } goto printint; case 'x': if (q) @@ -283,8 +334,15 @@ isc_print_vsnprintf(char *str, size_t size, const char *format, va_list ap) { if (precision > 2) precision -= 2; } - sprintf(buf, "%" ISC_PRINT_QUADFORMAT "x", - tmpui); + if (tmpui <= 0xffffffffU) + sprintf(buf, "%lx", + (unsigned long)tmpui); + else { + unsigned long hi = tmpui>>32; + unsigned long lo = tmpui & 0xffffffff; + sprintf(buf, "%lx", hi); + sprintf(buf + strlen(buf), "%lx", lo); + } goto printint; case 'X': if (q) @@ -298,8 +356,15 @@ isc_print_vsnprintf(char *str, size_t size, const char *format, va_list ap) { if (precision > 2) precision -= 2; } - sprintf(buf, "%" ISC_PRINT_QUADFORMAT "X", - tmpui); + if (tmpui <= 0xffffffffU) + sprintf(buf, "%lX", + (unsigned long)tmpui); + else { + unsigned long hi = tmpui>>32; + unsigned long lo = tmpui & 0xffffffff; + sprintf(buf, "%lX", hi); + sprintf(buf + strlen(buf), "%lX", lo); + } goto printint; printint: if (precision != 0 || width != 0) { From 6034083caee6fd6d56c1e02471098cb8791e0fc1 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 04:32:48 +0000 Subject: [PATCH 024/137] 2340. [port] openbsd: interface configuration. [RT #17700] --- CHANGES | 2 ++ bin/tests/system/ifconfig.sh | 8 +++++++- 2 files changed, 9 insertions(+), 1 deletion(-) diff --git a/CHANGES b/CHANGES index fce72167b7..f91544bcb3 100644 --- a/CHANGES +++ b/CHANGES @@ -10,6 +10,8 @@ 2343. [bug] (Seemingly) duplicate IPv6 entries could be created in ADB. [RT #17837] +2340. [port] openbsd: interface configuration. [RT #17700] + 2335. [port] sunos: libbind and *printf() support for long long. [RT #17513] diff --git a/bin/tests/system/ifconfig.sh b/bin/tests/system/ifconfig.sh index 13170a77b5..03f96fb9a4 100644 --- a/bin/tests/system/ifconfig.sh +++ b/bin/tests/system/ifconfig.sh @@ -15,7 +15,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: ifconfig.sh,v 1.35.2.8.2.8 2004/10/05 03:18:16 marka Exp $ +# $Id: ifconfig.sh,v 1.35.2.8.2.9 2008/04/28 04:32:48 marka Exp $ # # Set up interface aliases for bind9 system tests. @@ -85,6 +85,9 @@ case "$1" in *-unknown-netbsd*) ifconfig lo0 10.53.0.$ns alias netmask 255.255.255.0 ;; + *-unknown-openbsd*) + ifconfig lo0 10.53.0.$ns alias netmask 255.255.255.0 + ;; *-*-bsdi[3-5].*) ifconfig lo0 add 10.53.0.$ns netmask 255.255.255.0 ;; @@ -145,6 +148,9 @@ case "$1" in *-unknown-netbsd*) ifconfig lo0 10.53.0.$ns delete ;; + *-unknown-openbsd*) + ifconfig lo0 10.53.0.$ns delete + ;; *-*-bsdi[3-5].*) ifconfig lo0 remove 10.53.0.$ns ;; From beb705aeb1750d3d4cb62792e56ca101bb3017e1 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 04:42:07 +0000 Subject: [PATCH 025/137] 2332. [contrib] query-loc-0.4.0. [RT #17602] --- CHANGES | 2 + contrib/query-loc-0.3.0/ADDRESSES | 18 - contrib/query-loc-0.3.0/ALGO | 48 - contrib/query-loc-0.3.0/INSTALL | 9 - contrib/query-loc-0.3.0/Makefile.in | 40 - contrib/query-loc-0.3.0/README | 20 - contrib/query-loc-0.3.0/USAGE | 8 - contrib/query-loc-0.3.0/config.h.in | 69 - contrib/query-loc-0.3.0/configure | 6436 -------------------------- contrib/query-loc-0.3.0/configure.in | 65 - contrib/query-loc-0.3.0/install-sh | 251 - contrib/query-loc-0.3.0/loc.c | 566 --- contrib/query-loc-0.3.0/loc.h | 78 - contrib/query-loc-0.3.0/loc_ntoa.c | 248 - contrib/query-loc-0.3.0/query-loc.1 | 55 - contrib/query-loc-0.3.0/query-loc.c | 98 - contrib/query-loc-0.4.0/ADDRESSES | 2 +- contrib/query-loc-0.4.0/INSTALL | 2 +- contrib/query-loc-0.4.0/Makefile.in | 2 +- contrib/query-loc-0.4.0/README | 2 +- contrib/query-loc-0.4.0/config.h.in | 2 +- contrib/query-loc-0.4.0/configure.in | 2 +- contrib/query-loc-0.4.0/loc.c | 2 +- contrib/query-loc-0.4.0/loc.h | 2 +- contrib/query-loc-0.4.0/query-loc.1 | 2 +- contrib/query-loc-0.4.0/query-loc.c | 2 +- contrib/query-loc-0.4.0/reconf | 2 +- 27 files changed, 13 insertions(+), 8020 deletions(-) delete mode 100644 contrib/query-loc-0.3.0/ADDRESSES delete mode 100644 contrib/query-loc-0.3.0/ALGO delete mode 100644 contrib/query-loc-0.3.0/INSTALL delete mode 100644 contrib/query-loc-0.3.0/Makefile.in delete mode 100644 contrib/query-loc-0.3.0/README delete mode 100644 contrib/query-loc-0.3.0/USAGE delete mode 100644 contrib/query-loc-0.3.0/config.h.in delete mode 100755 contrib/query-loc-0.3.0/configure delete mode 100644 contrib/query-loc-0.3.0/configure.in delete mode 100755 contrib/query-loc-0.3.0/install-sh delete mode 100644 contrib/query-loc-0.3.0/loc.c delete mode 100644 contrib/query-loc-0.3.0/loc.h delete mode 100644 contrib/query-loc-0.3.0/loc_ntoa.c delete mode 100644 contrib/query-loc-0.3.0/query-loc.1 delete mode 100644 contrib/query-loc-0.3.0/query-loc.c diff --git a/CHANGES b/CHANGES index f91544bcb3..a0f473028a 100644 --- a/CHANGES +++ b/CHANGES @@ -21,6 +21,8 @@ 2333. [bug] Fix off by one error in isc_time_nowplusinterval(). [RT #17608] +2332. [contrib] query-loc-0.4.0. [RT #17602] + 2331. [bug] Failure to regenerate any signatures was not being reported nor being past back to the UPDATE client. [RT #17570] diff --git a/contrib/query-loc-0.3.0/ADDRESSES b/contrib/query-loc-0.3.0/ADDRESSES deleted file mode 100644 index 04dd5d29fe..0000000000 --- a/contrib/query-loc-0.3.0/ADDRESSES +++ /dev/null @@ -1,18 +0,0 @@ -The following machines, at least today seem to have LOC -records: - -*.cpod.fr (for instance www.cpod.fr) -130.104.3.* -195.202.193.* -Melanie.Tolna.Net -204.92.254.* -mail.vitts.com -alink.net -caida.org -ckdhr.com -distributed.net (rc5stats.distributed.net) -nikhef.nl -yahoo.com -nic.af - -$Id: ADDRESSES,v 1.1.2.1 2005/04/01 06:13:56 marka Exp $ diff --git a/contrib/query-loc-0.3.0/ALGO b/contrib/query-loc-0.3.0/ALGO deleted file mode 100644 index 4695dc14c7..0000000000 --- a/contrib/query-loc-0.3.0/ALGO +++ /dev/null @@ -1,48 +0,0 @@ -Just for info, can be out of date. - - -RFC 1876, 5.2, specially 5.2.3 - -Important points: - -- LOC RRs are always attached to a *name*. -- we can have two (or more) RRs for one address, one more specific than the other - -main - if (host is a name) - getLOCbyname - else # host is an IP address - gethostbyaddr - if (name) - getLOCbyname - # If there is none, do not search. We assume the above was sufficient # (But check 5.2.2) - else - getLOCbyaddress - -getLOCbyname (host) - get LOC for host - if (it exists) - OK - else - get all A records of the name - foreach A record - getLOCbyaddress - OK at the first one found - # we assume they are consistent - END - -getLOCbyaddress (address) - # May receive a mask. Otherwise, deduce it from the class - makeNetAddress - getLOCbynetwork - -getLOCbynetwork - get PTR and A for it - if (exist) - getLOCbyname - ******* DIFFICULT : we have to manage a stack. See the code - makeNetAddress (level--) - getLOCbynetwork - else - END - diff --git a/contrib/query-loc-0.3.0/INSTALL b/contrib/query-loc-0.3.0/INSTALL deleted file mode 100644 index 808053f2c7..0000000000 --- a/contrib/query-loc-0.3.0/INSTALL +++ /dev/null @@ -1,9 +0,0 @@ -Type './configure', then 'make' and (as root if necessary) 'make -install'. - -It requires a recent libresolv, with loc_ntoa, but use an alternative -which I provide, if not found. - -Tested on Linux (i386 and Alpha), Solaris (Sparc) and Digital Unix (Alpha). - -$Id: INSTALL,v 1.1.2.1 2005/04/01 06:13:57 marka Exp $ diff --git a/contrib/query-loc-0.3.0/Makefile.in b/contrib/query-loc-0.3.0/Makefile.in deleted file mode 100644 index 836bd07cfc..0000000000 --- a/contrib/query-loc-0.3.0/Makefile.in +++ /dev/null @@ -1,40 +0,0 @@ -# $Id: Makefile.in,v 1.1.2.1 2005/04/01 06:13:57 marka Exp $ -CC=@CC@ -CFLAGS=@CFLAGS@ -LIBS=@LIBS@ -DESTDIR=@prefix@ -BINDIR=@prefix@/bin -MANDIR=@prefix@/share/man/man1 -DISTRIB= README INSTALL ALGO USAGE ADDRESSES Makefile.in configure configure.in config.h.in install-sh loc.h loc.c query-loc.c loc_ntoa.c query-loc.1 -OBJS=query-loc.o loc.o @LOC_NTOA@ -VERSION=`grep VERSION loc.h | cut -d ' ' -f 3 | sed s/\"//g` - -all: query-loc - -query-loc: $(OBJS) - $(CC) -o $@ $(OBJS) $(LIBS) - -%.o: %.c loc.h - $(CC) $(CFLAGS) -c $< - -clean: - rm -f *.o query-loc *~ - -distclean: clean - rm -f config.h config.cache config.log config.status Makefile - -distrib: clean - ./reconf - @(echo Query-Loc is version ${VERSION}; \ - mkdir query-loc-${VERSION}; \ - cp $(DISTRIB) query-loc-${VERSION};\ - tar cvf query-loc-${VERSION}.tar query-loc-${VERSION}; \ - rm -rf query-loc-${VERSION}; \ - gzip -v -9 -f query-loc-${VERSION}.tar); - -install: - @INSTALL@ -m 0755 query-loc $(BINDIR) - if [ ! -d $(MANDIR) ]; then \ - mkdir $(MANDIR); \ - fi - @INSTALL@ -m 0644 query-loc.1 $(MANDIR) diff --git a/contrib/query-loc-0.3.0/README b/contrib/query-loc-0.3.0/README deleted file mode 100644 index 67aac94a7f..0000000000 --- a/contrib/query-loc-0.3.0/README +++ /dev/null @@ -1,20 +0,0 @@ - query-loc: a program to retrieve and display the location - information in the DNS. - - It uses the algorithms described in - RFC 1876 (and RFC 1101 to get the network names). - You can find examples of networks wchich implement this scheme - in the ADDRESSES file. - - It is under the General Public Licence (GPL, which - you can fetch from . - - Copyright Stéphane Bortzmeyer , 1998. - - Thanks to Paul Vixie for the RFC and its encouragements. Thanks - to Björn Augustsson for the xtraceroute program - . - -$Id: README,v 1.1.2.1 2005/04/01 06:13:58 marka Exp $ - - diff --git a/contrib/query-loc-0.3.0/USAGE b/contrib/query-loc-0.3.0/USAGE deleted file mode 100644 index 233d6ca144..0000000000 --- a/contrib/query-loc-0.3.0/USAGE +++ /dev/null @@ -1,8 +0,0 @@ -query-loc [-v] [-d nnn] host-name-or-address - -Examples of hosts with LOCation info (quite uncommon, if you know more, -please tell me): - -- Everything in the 193.105.79.0 network, such as www.humanite.presse.fr -- Everything in the 192.88.144 network, such as www.kei.com - diff --git a/contrib/query-loc-0.3.0/config.h.in b/contrib/query-loc-0.3.0/config.h.in deleted file mode 100644 index aee903e5f4..0000000000 --- a/contrib/query-loc-0.3.0/config.h.in +++ /dev/null @@ -1,69 +0,0 @@ -/* config.h.in. Generated from configure.in by autoheader. */ -/* $Id: config.h.in,v 1.1.2.1 2005/04/01 06:13:58 marka Exp $ */ - - -/* Define to 1 if you have the header file. */ -#undef HAVE_INTTYPES_H - -/* Define to 1 if you have the `resolv' library (-lresolv). */ -#undef HAVE_LIBRESOLV - -/* Define to 1 if you have the header file. */ -#undef HAVE_MEMORY_H - -/* Define to 1 if you have the header file. */ -#undef HAVE_STDINT_H - -/* Define to 1 if you have the header file. */ -#undef HAVE_STDLIB_H - -/* Define to 1 if you have the header file. */ -#undef HAVE_STRINGS_H - -/* Define to 1 if you have the header file. */ -#undef HAVE_STRING_H - -/* Define to 1 if you have the header file. */ -#undef HAVE_SYS_STAT_H - -/* Define to 1 if you have the header file. */ -#undef HAVE_SYS_TYPES_H - -/* Define to 1 if you have the header file. */ -#undef HAVE_UNISTD_H - -/* Define to the address where bug reports for this package should be sent. */ -#undef PACKAGE_BUGREPORT - -/* Define to the full name of this package. */ -#undef PACKAGE_NAME - -/* Define to the full name and version of this package. */ -#undef PACKAGE_STRING - -/* Define to the one symbol short name of this package. */ -#undef PACKAGE_TARNAME - -/* Define to the version of this package. */ -#undef PACKAGE_VERSION - -/* The size of a `char', as computed by sizeof. */ -#undef SIZEOF_CHAR - -/* The size of a `int', as computed by sizeof. */ -#undef SIZEOF_INT - -/* The size of a `long', as computed by sizeof. */ -#undef SIZEOF_LONG - -/* The size of a `short', as computed by sizeof. */ -#undef SIZEOF_SHORT - -/* Define to 1 if you have the ANSI C header files. */ -#undef STDC_HEADERS - -/* Define to empty if `const' does not conform to ANSI C. */ -#undef const - -/* Is there a loc_ntoa on this system? */ -#undef HAVE_LOC_NTOA diff --git a/contrib/query-loc-0.3.0/configure b/contrib/query-loc-0.3.0/configure deleted file mode 100755 index d77cf76ca5..0000000000 --- a/contrib/query-loc-0.3.0/configure +++ /dev/null @@ -1,6436 +0,0 @@ -#! /bin/sh -# Guess values for system-dependent variables and create Makefiles. -# Generated by GNU Autoconf 2.59. -# -# Copyright (C) 2003 Free Software Foundation, Inc. -# This configure script is free software; the Free Software Foundation -# gives unlimited permission to copy, distribute and modify it. -## --------------------- ## -## M4sh Initialization. ## -## --------------------- ## - -# Be Bourne compatible -if test -n "${ZSH_VERSION+set}" && (emulate sh) >/dev/null 2>&1; then - emulate sh - NULLCMD=: - # Zsh 3.x and 4.x performs word splitting on ${1+"$@"}, which - # is contrary to our usage. Disable this feature. - alias -g '${1+"$@"}'='"$@"' -elif test -n "${BASH_VERSION+set}" && (set -o posix) >/dev/null 2>&1; then - set -o posix -fi -DUALCASE=1; export DUALCASE # for MKS sh - -# Support unset when possible. -if ( (MAIL=60; unset MAIL) || exit) >/dev/null 2>&1; then - as_unset=unset -else - as_unset=false -fi - - -# Work around bugs in pre-3.0 UWIN ksh. -$as_unset ENV MAIL MAILPATH -PS1='$ ' -PS2='> ' -PS4='+ ' - -# NLS nuisances. -for as_var in \ - LANG LANGUAGE LC_ADDRESS LC_ALL LC_COLLATE LC_CTYPE LC_IDENTIFICATION \ - LC_MEASUREMENT LC_MESSAGES LC_MONETARY LC_NAME LC_NUMERIC LC_PAPER \ - LC_TELEPHONE LC_TIME -do - if (set +x; test -z "`(eval $as_var=C; export $as_var) 2>&1`"); then - eval $as_var=C; export $as_var - else - $as_unset $as_var - fi -done - -# Required to use basename. -if expr a : '\(a\)' >/dev/null 2>&1; then - as_expr=expr -else - as_expr=false -fi - -if (basename /) >/dev/null 2>&1 && test "X`basename / 2>&1`" = "X/"; then - as_basename=basename -else - as_basename=false -fi - - -# Name of the executable. -as_me=`$as_basename "$0" || -$as_expr X/"$0" : '.*/\([^/][^/]*\)/*$' \| \ - X"$0" : 'X\(//\)$' \| \ - X"$0" : 'X\(/\)$' \| \ - . : '\(.\)' 2>/dev/null || -echo X/"$0" | - sed '/^.*\/\([^/][^/]*\)\/*$/{ s//\1/; q; } - /^X\/\(\/\/\)$/{ s//\1/; q; } - /^X\/\(\/\).*/{ s//\1/; q; } - s/.*/./; q'` - - -# PATH needs CR, and LINENO needs CR and PATH. -# Avoid depending upon Character Ranges. -as_cr_letters='abcdefghijklmnopqrstuvwxyz' -as_cr_LETTERS='ABCDEFGHIJKLMNOPQRSTUVWXYZ' -as_cr_Letters=$as_cr_letters$as_cr_LETTERS -as_cr_digits='0123456789' -as_cr_alnum=$as_cr_Letters$as_cr_digits - -# The user is always right. -if test "${PATH_SEPARATOR+set}" != set; then - echo "#! /bin/sh" >conf$$.sh - echo "exit 0" >>conf$$.sh - chmod +x conf$$.sh - if (PATH="/nonexistent;."; conf$$.sh) >/dev/null 2>&1; then - PATH_SEPARATOR=';' - else - PATH_SEPARATOR=: - fi - rm -f conf$$.sh -fi - - - as_lineno_1=$LINENO - as_lineno_2=$LINENO - as_lineno_3=`(expr $as_lineno_1 + 1) 2>/dev/null` - test "x$as_lineno_1" != "x$as_lineno_2" && - test "x$as_lineno_3" = "x$as_lineno_2" || { - # Find who we are. Look in the path if we contain no path at all - # relative or not. - case $0 in - *[\\/]* ) as_myself=$0 ;; - *) as_save_IFS=$IFS; IFS=$PATH_SEPARATOR -for as_dir in $PATH -do - IFS=$as_save_IFS - test -z "$as_dir" && as_dir=. - test -r "$as_dir/$0" && as_myself=$as_dir/$0 && break -done - - ;; - esac - # We did not find ourselves, most probably we were run as `sh COMMAND' - # in which case we are not to be found in the path. - if test "x$as_myself" = x; then - as_myself=$0 - fi - if test ! -f "$as_myself"; then - { echo "$as_me: error: cannot find myself; rerun with an absolute path" >&2 - { (exit 1); exit 1; }; } - fi - case $CONFIG_SHELL in - '') - as_save_IFS=$IFS; IFS=$PATH_SEPARATOR -for as_dir in /bin$PATH_SEPARATOR/usr/bin$PATH_SEPARATOR$PATH -do - IFS=$as_save_IFS - test -z "$as_dir" && as_dir=. - for as_base in sh bash ksh sh5; do - case $as_dir in - /*) - if ("$as_dir/$as_base" -c ' - as_lineno_1=$LINENO - as_lineno_2=$LINENO - as_lineno_3=`(expr $as_lineno_1 + 1) 2>/dev/null` - test "x$as_lineno_1" != "x$as_lineno_2" && - test "x$as_lineno_3" = "x$as_lineno_2" ') 2>/dev/null; then - $as_unset BASH_ENV || test "${BASH_ENV+set}" != set || { BASH_ENV=; export BASH_ENV; } - $as_unset ENV || test "${ENV+set}" != set || { ENV=; export ENV; } - CONFIG_SHELL=$as_dir/$as_base - export CONFIG_SHELL - exec "$CONFIG_SHELL" "$0" ${1+"$@"} - fi;; - esac - done -done -;; - esac - - # Create $as_me.lineno as a copy of $as_myself, but with $LINENO - # uniformly replaced by the line number. The first 'sed' inserts a - # line-number line before each line; the second 'sed' does the real - # work. The second script uses 'N' to pair each line-number line - # with the numbered line, and appends trailing '-' during - # substitution so that $LINENO is not a special case at line end. - # (Raja R Harinath suggested sed '=', and Paul Eggert wrote the - # second 'sed' script. Blame Lee E. McMahon for sed's syntax. :-) - sed '=' <$as_myself | - sed ' - N - s,$,-, - : loop - s,^\(['$as_cr_digits']*\)\(.*\)[$]LINENO\([^'$as_cr_alnum'_]\),\1\2\1\3, - t loop - s,-$,, - s,^['$as_cr_digits']*\n,, - ' >$as_me.lineno && - chmod +x $as_me.lineno || - { echo "$as_me: error: cannot create $as_me.lineno; rerun with a POSIX shell" >&2 - { (exit 1); exit 1; }; } - - # Don't try to exec as it changes $[0], causing all sort of problems - # (the dirname of $[0] is not the place where we might find the - # original and so on. Autoconf is especially sensible to this). - . ./$as_me.lineno - # Exit status is that of the last command. - exit -} - - -case `echo "testing\c"; echo 1,2,3`,`echo -n testing; echo 1,2,3` in - *c*,-n*) ECHO_N= ECHO_C=' -' ECHO_T=' ' ;; - *c*,* ) ECHO_N=-n ECHO_C= ECHO_T= ;; - *) ECHO_N= ECHO_C='\c' ECHO_T= ;; -esac - -if expr a : '\(a\)' >/dev/null 2>&1; then - as_expr=expr -else - as_expr=false -fi - -rm -f conf$$ conf$$.exe conf$$.file -echo >conf$$.file -if ln -s conf$$.file conf$$ 2>/dev/null; then - # We could just check for DJGPP; but this test a) works b) is more generic - # and c) will remain valid once DJGPP supports symlinks (DJGPP 2.04). - if test -f conf$$.exe; then - # Don't use ln at all; we don't have any links - as_ln_s='cp -p' - else - as_ln_s='ln -s' - fi -elif ln conf$$.file conf$$ 2>/dev/null; then - as_ln_s=ln -else - as_ln_s='cp -p' -fi -rm -f conf$$ conf$$.exe conf$$.file - -if mkdir -p . 2>/dev/null; then - as_mkdir_p=: -else - test -d ./-p && rmdir ./-p - as_mkdir_p=false -fi - -as_executable_p="test -f" - -# Sed expression to map a string onto a valid CPP name. -as_tr_cpp="eval sed 'y%*$as_cr_letters%P$as_cr_LETTERS%;s%[^_$as_cr_alnum]%_%g'" - -# Sed expression to map a string onto a valid variable name. -as_tr_sh="eval sed 'y%*+%pp%;s%[^_$as_cr_alnum]%_%g'" - - -# IFS -# We need space, tab and new line, in precisely that order. -as_nl=' -' -IFS=" $as_nl" - -# CDPATH. -$as_unset CDPATH - - -# Name of the host. -# hostname on some systems (SVR3.2, Linux) returns a bogus exit status, -# so uname gets run too. -ac_hostname=`(hostname || uname -n) 2>/dev/null | sed 1q` - -exec 6>&1 - -# -# Initializations. -# -ac_default_prefix=/usr/local -ac_config_libobj_dir=. -cross_compiling=no -subdirs= -MFLAGS= -MAKEFLAGS= -SHELL=${CONFIG_SHELL-/bin/sh} - -# Maximum number of lines to put in a shell here document. -# This variable seems obsolete. It should probably be removed, and -# only ac_max_sed_lines should be used. -: ${ac_max_here_lines=38} - -# Identity of this package. -PACKAGE_NAME= -PACKAGE_TARNAME= -PACKAGE_VERSION= -PACKAGE_STRING= -PACKAGE_BUGREPORT= - -ac_unique_file="query-loc.c" -# Factoring default headers for most tests. -ac_includes_default="\ -#include -#if HAVE_SYS_TYPES_H -# include -#endif -#if HAVE_SYS_STAT_H -# include -#endif -#if STDC_HEADERS -# include -# include -#else -# if HAVE_STDLIB_H -# include -# endif -#endif -#if HAVE_STRING_H -# if !STDC_HEADERS && HAVE_MEMORY_H -# include -# endif -# include -#endif -#if HAVE_STRINGS_H -# include -#endif -#if HAVE_INTTYPES_H -# include -#else -# if HAVE_STDINT_H -# include -# endif -#endif -#if HAVE_UNISTD_H -# include -#endif" - -ac_subst_vars='SHELL PATH_SEPARATOR PACKAGE_NAME PACKAGE_TARNAME PACKAGE_VERSION PACKAGE_STRING PACKAGE_BUGREPORT exec_prefix prefix program_transform_name bindir sbindir libexecdir datadir sysconfdir sharedstatedir localstatedir libdir includedir oldincludedir infodir mandir build_alias host_alias target_alias DEFS ECHO_C ECHO_N ECHO_T LIBS CC CFLAGS LDFLAGS CPPFLAGS ac_ct_CC EXEEXT OBJEXT INSTALL_PROGRAM INSTALL_SCRIPT INSTALL_DATA CPP EGREP LOC_NTOA LIBOBJS LTLIBOBJS' -ac_subst_files='' - -# Initialize some variables set by options. -ac_init_help= -ac_init_version=false -# The variables have the same names as the options, with -# dashes changed to underlines. -cache_file=/dev/null -exec_prefix=NONE -no_create= -no_recursion= -prefix=NONE -program_prefix=NONE -program_suffix=NONE -program_transform_name=s,x,x, -silent= -site= -srcdir= -verbose= -x_includes=NONE -x_libraries=NONE - -# Installation directory options. -# These are left unexpanded so users can "make install exec_prefix=/foo" -# and all the variables that are supposed to be based on exec_prefix -# by default will actually change. -# Use braces instead of parens because sh, perl, etc. also accept them. -bindir='${exec_prefix}/bin' -sbindir='${exec_prefix}/sbin' -libexecdir='${exec_prefix}/libexec' -datadir='${prefix}/share' -sysconfdir='${prefix}/etc' -sharedstatedir='${prefix}/com' -localstatedir='${prefix}/var' -libdir='${exec_prefix}/lib' -includedir='${prefix}/include' -oldincludedir='/usr/include' -infodir='${prefix}/info' -mandir='${prefix}/man' - -ac_prev= -for ac_option -do - # If the previous option needs an argument, assign it. - if test -n "$ac_prev"; then - eval "$ac_prev=\$ac_option" - ac_prev= - continue - fi - - ac_optarg=`expr "x$ac_option" : 'x[^=]*=\(.*\)'` - - # Accept the important Cygnus configure options, so we can diagnose typos. - - case $ac_option in - - -bindir | --bindir | --bindi | --bind | --bin | --bi) - ac_prev=bindir ;; - -bindir=* | --bindir=* | --bindi=* | --bind=* | --bin=* | --bi=*) - bindir=$ac_optarg ;; - - -build | --build | --buil | --bui | --bu) - ac_prev=build_alias ;; - -build=* | --build=* | --buil=* | --bui=* | --bu=*) - build_alias=$ac_optarg ;; - - -cache-file | --cache-file | --cache-fil | --cache-fi \ - | --cache-f | --cache- | --cache | --cach | --cac | --ca | --c) - ac_prev=cache_file ;; - -cache-file=* | --cache-file=* | --cache-fil=* | --cache-fi=* \ - | --cache-f=* | --cache-=* | --cache=* | --cach=* | --cac=* | --ca=* | --c=*) - cache_file=$ac_optarg ;; - - --config-cache | -C) - cache_file=config.cache ;; - - -datadir | --datadir | --datadi | --datad | --data | --dat | --da) - ac_prev=datadir ;; - -datadir=* | --datadir=* | --datadi=* | --datad=* | --data=* | --dat=* \ - | --da=*) - datadir=$ac_optarg ;; - - -disable-* | --disable-*) - ac_feature=`expr "x$ac_option" : 'x-*disable-\(.*\)'` - # Reject names that are not valid shell variable names. - expr "x$ac_feature" : ".*[^-_$as_cr_alnum]" >/dev/null && - { echo "$as_me: error: invalid feature name: $ac_feature" >&2 - { (exit 1); exit 1; }; } - ac_feature=`echo $ac_feature | sed 's/-/_/g'` - eval "enable_$ac_feature=no" ;; - - -enable-* | --enable-*) - ac_feature=`expr "x$ac_option" : 'x-*enable-\([^=]*\)'` - # Reject names that are not valid shell variable names. - expr "x$ac_feature" : ".*[^-_$as_cr_alnum]" >/dev/null && - { echo "$as_me: error: invalid feature name: $ac_feature" >&2 - { (exit 1); exit 1; }; } - ac_feature=`echo $ac_feature | sed 's/-/_/g'` - case $ac_option in - *=*) ac_optarg=`echo "$ac_optarg" | sed "s/'/'\\\\\\\\''/g"`;; - *) ac_optarg=yes ;; - esac - eval "enable_$ac_feature='$ac_optarg'" ;; - - -exec-prefix | --exec_prefix | --exec-prefix | --exec-prefi \ - | --exec-pref | --exec-pre | --exec-pr | --exec-p | --exec- \ - | --exec | --exe | --ex) - ac_prev=exec_prefix ;; - -exec-prefix=* | --exec_prefix=* | --exec-prefix=* | --exec-prefi=* \ - | --exec-pref=* | --exec-pre=* | --exec-pr=* | --exec-p=* | --exec-=* \ - | --exec=* | --exe=* | --ex=*) - exec_prefix=$ac_optarg ;; - - -gas | --gas | --ga | --g) - # Obsolete; use --with-gas. - with_gas=yes ;; - - -help | --help | --hel | --he | -h) - ac_init_help=long ;; - -help=r* | --help=r* | --hel=r* | --he=r* | -hr*) - ac_init_help=recursive ;; - -help=s* | --help=s* | --hel=s* | --he=s* | -hs*) - ac_init_help=short ;; - - -host | --host | --hos | --ho) - ac_prev=host_alias ;; - -host=* | --host=* | --hos=* | --ho=*) - host_alias=$ac_optarg ;; - - -includedir | --includedir | --includedi | --included | --include \ - | --includ | --inclu | --incl | --inc) - ac_prev=includedir ;; - -includedir=* | --includedir=* | --includedi=* | --included=* | --include=* \ - | --includ=* | --inclu=* | --incl=* | --inc=*) - includedir=$ac_optarg ;; - - -infodir | --infodir | --infodi | --infod | --info | --inf) - ac_prev=infodir ;; - -infodir=* | --infodir=* | --infodi=* | --infod=* | --info=* | --inf=*) - infodir=$ac_optarg ;; - - -libdir | --libdir | --libdi | --libd) - ac_prev=libdir ;; - -libdir=* | --libdir=* | --libdi=* | --libd=*) - libdir=$ac_optarg ;; - - -libexecdir | --libexecdir | --libexecdi | --libexecd | --libexec \ - | --libexe | --libex | --libe) - ac_prev=libexecdir ;; - -libexecdir=* | --libexecdir=* | --libexecdi=* | --libexecd=* | --libexec=* \ - | --libexe=* | --libex=* | --libe=*) - libexecdir=$ac_optarg ;; - - -localstatedir | --localstatedir | --localstatedi | --localstated \ - | --localstate | --localstat | --localsta | --localst \ - | --locals | --local | --loca | --loc | --lo) - ac_prev=localstatedir ;; - -localstatedir=* | --localstatedir=* | --localstatedi=* | --localstated=* \ - | --localstate=* | --localstat=* | --localsta=* | --localst=* \ - | --locals=* | --local=* | --loca=* | --loc=* | --lo=*) - localstatedir=$ac_optarg ;; - - -mandir | --mandir | --mandi | --mand | --man | --ma | --m) - ac_prev=mandir ;; - -mandir=* | --mandir=* | --mandi=* | --mand=* | --man=* | --ma=* | --m=*) - mandir=$ac_optarg ;; - - -nfp | --nfp | --nf) - # Obsolete; use --without-fp. - with_fp=no ;; - - -no-create | --no-create | --no-creat | --no-crea | --no-cre \ - | --no-cr | --no-c | -n) - no_create=yes ;; - - -no-recursion | --no-recursion | --no-recursio | --no-recursi \ - | --no-recurs | --no-recur | --no-recu | --no-rec | --no-re | --no-r) - no_recursion=yes ;; - - -oldincludedir | --oldincludedir | --oldincludedi | --oldincluded \ - | --oldinclude | --oldinclud | --oldinclu | --oldincl | --oldinc \ - | --oldin | --oldi | --old | --ol | --o) - ac_prev=oldincludedir ;; - -oldincludedir=* | --oldincludedir=* | --oldincludedi=* | --oldincluded=* \ - | --oldinclude=* | --oldinclud=* | --oldinclu=* | --oldincl=* | --oldinc=* \ - | --oldin=* | --oldi=* | --old=* | --ol=* | --o=*) - oldincludedir=$ac_optarg ;; - - -prefix | --prefix | --prefi | --pref | --pre | --pr | --p) - ac_prev=prefix ;; - -prefix=* | --prefix=* | --prefi=* | --pref=* | --pre=* | --pr=* | --p=*) - prefix=$ac_optarg ;; - - -program-prefix | --program-prefix | --program-prefi | --program-pref \ - | --program-pre | --program-pr | --program-p) - ac_prev=program_prefix ;; - -program-prefix=* | --program-prefix=* | --program-prefi=* \ - | --program-pref=* | --program-pre=* | --program-pr=* | --program-p=*) - program_prefix=$ac_optarg ;; - - -program-suffix | --program-suffix | --program-suffi | --program-suff \ - | --program-suf | --program-su | --program-s) - ac_prev=program_suffix ;; - -program-suffix=* | --program-suffix=* | --program-suffi=* \ - | --program-suff=* | --program-suf=* | --program-su=* | --program-s=*) - program_suffix=$ac_optarg ;; - - -program-transform-name | --program-transform-name \ - | --program-transform-nam | --program-transform-na \ - | --program-transform-n | --program-transform- \ - | --program-transform | --program-transfor \ - | --program-transfo | --program-transf \ - | --program-trans | --program-tran \ - | --progr-tra | --program-tr | --program-t) - ac_prev=program_transform_name ;; - -program-transform-name=* | --program-transform-name=* \ - | --program-transform-nam=* | --program-transform-na=* \ - | --program-transform-n=* | --program-transform-=* \ - | --program-transform=* | --program-transfor=* \ - | --program-transfo=* | --program-transf=* \ - | --program-trans=* | --program-tran=* \ - | --progr-tra=* | --program-tr=* | --program-t=*) - program_transform_name=$ac_optarg ;; - - -q | -quiet | --quiet | --quie | --qui | --qu | --q \ - | -silent | --silent | --silen | --sile | --sil) - silent=yes ;; - - -sbindir | --sbindir | --sbindi | --sbind | --sbin | --sbi | --sb) - ac_prev=sbindir ;; - -sbindir=* | --sbindir=* | --sbindi=* | --sbind=* | --sbin=* \ - | --sbi=* | --sb=*) - sbindir=$ac_optarg ;; - - -sharedstatedir | --sharedstatedir | --sharedstatedi \ - | --sharedstated | --sharedstate | --sharedstat | --sharedsta \ - | --sharedst | --shareds | --shared | --share | --shar \ - | --sha | --sh) - ac_prev=sharedstatedir ;; - -sharedstatedir=* | --sharedstatedir=* | --sharedstatedi=* \ - | --sharedstated=* | --sharedstate=* | --sharedstat=* | --sharedsta=* \ - | --sharedst=* | --shareds=* | --shared=* | --share=* | --shar=* \ - | --sha=* | --sh=*) - sharedstatedir=$ac_optarg ;; - - -site | --site | --sit) - ac_prev=site ;; - -site=* | --site=* | --sit=*) - site=$ac_optarg ;; - - -srcdir | --srcdir | --srcdi | --srcd | --src | --sr) - ac_prev=srcdir ;; - -srcdir=* | --srcdir=* | --srcdi=* | --srcd=* | --src=* | --sr=*) - srcdir=$ac_optarg ;; - - -sysconfdir | --sysconfdir | --sysconfdi | --sysconfd | --sysconf \ - | --syscon | --sysco | --sysc | --sys | --sy) - ac_prev=sysconfdir ;; - -sysconfdir=* | --sysconfdir=* | --sysconfdi=* | --sysconfd=* | --sysconf=* \ - | --syscon=* | --sysco=* | --sysc=* | --sys=* | --sy=*) - sysconfdir=$ac_optarg ;; - - -target | --target | --targe | --targ | --tar | --ta | --t) - ac_prev=target_alias ;; - -target=* | --target=* | --targe=* | --targ=* | --tar=* | --ta=* | --t=*) - target_alias=$ac_optarg ;; - - -v | -verbose | --verbose | --verbos | --verbo | --verb) - verbose=yes ;; - - -version | --version | --versio | --versi | --vers | -V) - ac_init_version=: ;; - - -with-* | --with-*) - ac_package=`expr "x$ac_option" : 'x-*with-\([^=]*\)'` - # Reject names that are not valid shell variable names. - expr "x$ac_package" : ".*[^-_$as_cr_alnum]" >/dev/null && - { echo "$as_me: error: invalid package name: $ac_package" >&2 - { (exit 1); exit 1; }; } - ac_package=`echo $ac_package| sed 's/-/_/g'` - case $ac_option in - *=*) ac_optarg=`echo "$ac_optarg" | sed "s/'/'\\\\\\\\''/g"`;; - *) ac_optarg=yes ;; - esac - eval "with_$ac_package='$ac_optarg'" ;; - - -without-* | --without-*) - ac_package=`expr "x$ac_option" : 'x-*without-\(.*\)'` - # Reject names that are not valid shell variable names. - expr "x$ac_package" : ".*[^-_$as_cr_alnum]" >/dev/null && - { echo "$as_me: error: invalid package name: $ac_package" >&2 - { (exit 1); exit 1; }; } - ac_package=`echo $ac_package | sed 's/-/_/g'` - eval "with_$ac_package=no" ;; - - --x) - # Obsolete; use --with-x. - with_x=yes ;; - - -x-includes | --x-includes | --x-include | --x-includ | --x-inclu \ - | --x-incl | --x-inc | --x-in | --x-i) - ac_prev=x_includes ;; - -x-includes=* | --x-includes=* | --x-include=* | --x-includ=* | --x-inclu=* \ - | --x-incl=* | --x-inc=* | --x-in=* | --x-i=*) - x_includes=$ac_optarg ;; - - -x-libraries | --x-libraries | --x-librarie | --x-librari \ - | --x-librar | --x-libra | --x-libr | --x-lib | --x-li | --x-l) - ac_prev=x_libraries ;; - -x-libraries=* | --x-libraries=* | --x-librarie=* | --x-librari=* \ - | --x-librar=* | --x-libra=* | --x-libr=* | --x-lib=* | --x-li=* | --x-l=*) - x_libraries=$ac_optarg ;; - - -*) { echo "$as_me: error: unrecognized option: $ac_option -Try \`$0 --help' for more information." >&2 - { (exit 1); exit 1; }; } - ;; - - *=*) - ac_envvar=`expr "x$ac_option" : 'x\([^=]*\)='` - # Reject names that are not valid shell variable names. - expr "x$ac_envvar" : ".*[^_$as_cr_alnum]" >/dev/null && - { echo "$as_me: error: invalid variable name: $ac_envvar" >&2 - { (exit 1); exit 1; }; } - ac_optarg=`echo "$ac_optarg" | sed "s/'/'\\\\\\\\''/g"` - eval "$ac_envvar='$ac_optarg'" - export $ac_envvar ;; - - *) - # FIXME: should be removed in autoconf 3.0. - echo "$as_me: WARNING: you should use --build, --host, --target" >&2 - expr "x$ac_option" : ".*[^-._$as_cr_alnum]" >/dev/null && - echo "$as_me: WARNING: invalid host type: $ac_option" >&2 - : ${build_alias=$ac_option} ${host_alias=$ac_option} ${target_alias=$ac_option} - ;; - - esac -done - -if test -n "$ac_prev"; then - ac_option=--`echo $ac_prev | sed 's/_/-/g'` - { echo "$as_me: error: missing argument to $ac_option" >&2 - { (exit 1); exit 1; }; } -fi - -# Be sure to have absolute paths. -for ac_var in exec_prefix prefix -do - eval ac_val=$`echo $ac_var` - case $ac_val in - [\\/$]* | ?:[\\/]* | NONE | '' ) ;; - *) { echo "$as_me: error: expected an absolute directory name for --$ac_var: $ac_val" >&2 - { (exit 1); exit 1; }; };; - esac -done - -# Be sure to have absolute paths. -for ac_var in bindir sbindir libexecdir datadir sysconfdir sharedstatedir \ - localstatedir libdir includedir oldincludedir infodir mandir -do - eval ac_val=$`echo $ac_var` - case $ac_val in - [\\/$]* | ?:[\\/]* ) ;; - *) { echo "$as_me: error: expected an absolute directory name for --$ac_var: $ac_val" >&2 - { (exit 1); exit 1; }; };; - esac -done - -# There might be people who depend on the old broken behavior: `$host' -# used to hold the argument of --host etc. -# FIXME: To remove some day. -build=$build_alias -host=$host_alias -target=$target_alias - -# FIXME: To remove some day. -if test "x$host_alias" != x; then - if test "x$build_alias" = x; then - cross_compiling=maybe - echo "$as_me: WARNING: If you wanted to set the --build type, don't use --host. - If a cross compiler is detected then cross compile mode will be used." >&2 - elif test "x$build_alias" != "x$host_alias"; then - cross_compiling=yes - fi -fi - -ac_tool_prefix= -test -n "$host_alias" && ac_tool_prefix=$host_alias- - -test "$silent" = yes && exec 6>/dev/null - - -# Find the source files, if location was not specified. -if test -z "$srcdir"; then - ac_srcdir_defaulted=yes - # Try the directory containing this script, then its parent. - ac_confdir=`(dirname "$0") 2>/dev/null || -$as_expr X"$0" : 'X\(.*[^/]\)//*[^/][^/]*/*$' \| \ - X"$0" : 'X\(//\)[^/]' \| \ - X"$0" : 'X\(//\)$' \| \ - X"$0" : 'X\(/\)' \| \ - . : '\(.\)' 2>/dev/null || -echo X"$0" | - sed '/^X\(.*[^/]\)\/\/*[^/][^/]*\/*$/{ s//\1/; q; } - /^X\(\/\/\)[^/].*/{ s//\1/; q; } - /^X\(\/\/\)$/{ s//\1/; q; } - /^X\(\/\).*/{ s//\1/; q; } - s/.*/./; q'` - srcdir=$ac_confdir - if test ! -r $srcdir/$ac_unique_file; then - srcdir=.. - fi -else - ac_srcdir_defaulted=no -fi -if test ! -r $srcdir/$ac_unique_file; then - if test "$ac_srcdir_defaulted" = yes; then - { echo "$as_me: error: cannot find sources ($ac_unique_file) in $ac_confdir or .." >&2 - { (exit 1); exit 1; }; } - else - { echo "$as_me: error: cannot find sources ($ac_unique_file) in $srcdir" >&2 - { (exit 1); exit 1; }; } - fi -fi -(cd $srcdir && test -r ./$ac_unique_file) 2>/dev/null || - { echo "$as_me: error: sources are in $srcdir, but \`cd $srcdir' does not work" >&2 - { (exit 1); exit 1; }; } -srcdir=`echo "$srcdir" | sed 's%\([^\\/]\)[\\/]*$%\1%'` -ac_env_build_alias_set=${build_alias+set} -ac_env_build_alias_value=$build_alias -ac_cv_env_build_alias_set=${build_alias+set} -ac_cv_env_build_alias_value=$build_alias -ac_env_host_alias_set=${host_alias+set} -ac_env_host_alias_value=$host_alias -ac_cv_env_host_alias_set=${host_alias+set} -ac_cv_env_host_alias_value=$host_alias -ac_env_target_alias_set=${target_alias+set} -ac_env_target_alias_value=$target_alias -ac_cv_env_target_alias_set=${target_alias+set} -ac_cv_env_target_alias_value=$target_alias -ac_env_CC_set=${CC+set} -ac_env_CC_value=$CC -ac_cv_env_CC_set=${CC+set} -ac_cv_env_CC_value=$CC -ac_env_CFLAGS_set=${CFLAGS+set} -ac_env_CFLAGS_value=$CFLAGS -ac_cv_env_CFLAGS_set=${CFLAGS+set} -ac_cv_env_CFLAGS_value=$CFLAGS -ac_env_LDFLAGS_set=${LDFLAGS+set} -ac_env_LDFLAGS_value=$LDFLAGS -ac_cv_env_LDFLAGS_set=${LDFLAGS+set} -ac_cv_env_LDFLAGS_value=$LDFLAGS -ac_env_CPPFLAGS_set=${CPPFLAGS+set} -ac_env_CPPFLAGS_value=$CPPFLAGS -ac_cv_env_CPPFLAGS_set=${CPPFLAGS+set} -ac_cv_env_CPPFLAGS_value=$CPPFLAGS -ac_env_CPP_set=${CPP+set} -ac_env_CPP_value=$CPP -ac_cv_env_CPP_set=${CPP+set} -ac_cv_env_CPP_value=$CPP - -# -# Report the --help message. -# -if test "$ac_init_help" = "long"; then - # Omit some internal or obsolete options to make the list less imposing. - # This message is too long to be a string in the A/UX 3.1 sh. - cat <<_ACEOF -\`configure' configures this package to adapt to many kinds of systems. - -Usage: $0 [OPTION]... [VAR=VALUE]... - -To assign environment variables (e.g., CC, CFLAGS...), specify them as -VAR=VALUE. See below for descriptions of some of the useful variables. - -Defaults for the options are specified in brackets. - -Configuration: - -h, --help display this help and exit - --help=short display options specific to this package - --help=recursive display the short help of all the included packages - -V, --version display version information and exit - -q, --quiet, --silent do not print \`checking...' messages - --cache-file=FILE cache test results in FILE [disabled] - -C, --config-cache alias for \`--cache-file=config.cache' - -n, --no-create do not create output files - --srcdir=DIR find the sources in DIR [configure dir or \`..'] - -_ACEOF - - cat <<_ACEOF -Installation directories: - --prefix=PREFIX install architecture-independent files in PREFIX - [$ac_default_prefix] - --exec-prefix=EPREFIX install architecture-dependent files in EPREFIX - [PREFIX] - -By default, \`make install' will install all the files in -\`$ac_default_prefix/bin', \`$ac_default_prefix/lib' etc. You can specify -an installation prefix other than \`$ac_default_prefix' using \`--prefix', -for instance \`--prefix=\$HOME'. - -For better control, use the options below. - -Fine tuning of the installation directories: - --bindir=DIR user executables [EPREFIX/bin] - --sbindir=DIR system admin executables [EPREFIX/sbin] - --libexecdir=DIR program executables [EPREFIX/libexec] - --datadir=DIR read-only architecture-independent data [PREFIX/share] - --sysconfdir=DIR read-only single-machine data [PREFIX/etc] - --sharedstatedir=DIR modifiable architecture-independent data [PREFIX/com] - --localstatedir=DIR modifiable single-machine data [PREFIX/var] - --libdir=DIR object code libraries [EPREFIX/lib] - --includedir=DIR C header files [PREFIX/include] - --oldincludedir=DIR C header files for non-gcc [/usr/include] - --infodir=DIR info documentation [PREFIX/info] - --mandir=DIR man documentation [PREFIX/man] -_ACEOF - - cat <<\_ACEOF -_ACEOF -fi - -if test -n "$ac_init_help"; then - - cat <<\_ACEOF - -Some influential environment variables: - CC C compiler command - CFLAGS C compiler flags - LDFLAGS linker flags, e.g. -L if you have libraries in a - nonstandard directory - CPPFLAGS C/C++ preprocessor flags, e.g. -I if you have - headers in a nonstandard directory - CPP C preprocessor - -Use these variables to override the choices made by `configure' or to help -it to find libraries and programs with nonstandard names/locations. - -_ACEOF -fi - -if test "$ac_init_help" = "recursive"; then - # If there are subdirs, report their specific --help. - ac_popdir=`pwd` - for ac_dir in : $ac_subdirs_all; do test "x$ac_dir" = x: && continue - test -d $ac_dir || continue - ac_builddir=. - -if test "$ac_dir" != .; then - ac_dir_suffix=/`echo "$ac_dir" | sed 's,^\.[\\/],,'` - # A "../" for each directory in $ac_dir_suffix. - ac_top_builddir=`echo "$ac_dir_suffix" | sed 's,/[^\\/]*,../,g'` -else - ac_dir_suffix= ac_top_builddir= -fi - -case $srcdir in - .) # No --srcdir option. We are building in place. - ac_srcdir=. - if test -z "$ac_top_builddir"; then - ac_top_srcdir=. - else - ac_top_srcdir=`echo $ac_top_builddir | sed 's,/$,,'` - fi ;; - [\\/]* | ?:[\\/]* ) # Absolute path. - ac_srcdir=$srcdir$ac_dir_suffix; - ac_top_srcdir=$srcdir ;; - *) # Relative path. - ac_srcdir=$ac_top_builddir$srcdir$ac_dir_suffix - ac_top_srcdir=$ac_top_builddir$srcdir ;; -esac - -# Do not use `cd foo && pwd` to compute absolute paths, because -# the directories may not exist. -case `pwd` in -.) ac_abs_builddir="$ac_dir";; -*) - case "$ac_dir" in - .) ac_abs_builddir=`pwd`;; - [\\/]* | ?:[\\/]* ) ac_abs_builddir="$ac_dir";; - *) ac_abs_builddir=`pwd`/"$ac_dir";; - esac;; -esac -case $ac_abs_builddir in -.) ac_abs_top_builddir=${ac_top_builddir}.;; -*) - case ${ac_top_builddir}. in - .) ac_abs_top_builddir=$ac_abs_builddir;; - [\\/]* | ?:[\\/]* ) ac_abs_top_builddir=${ac_top_builddir}.;; - *) ac_abs_top_builddir=$ac_abs_builddir/${ac_top_builddir}.;; - esac;; -esac -case $ac_abs_builddir in -.) ac_abs_srcdir=$ac_srcdir;; -*) - case $ac_srcdir in - .) ac_abs_srcdir=$ac_abs_builddir;; - [\\/]* | ?:[\\/]* ) ac_abs_srcdir=$ac_srcdir;; - *) ac_abs_srcdir=$ac_abs_builddir/$ac_srcdir;; - esac;; -esac -case $ac_abs_builddir in -.) ac_abs_top_srcdir=$ac_top_srcdir;; -*) - case $ac_top_srcdir in - .) ac_abs_top_srcdir=$ac_abs_builddir;; - [\\/]* | ?:[\\/]* ) ac_abs_top_srcdir=$ac_top_srcdir;; - *) ac_abs_top_srcdir=$ac_abs_builddir/$ac_top_srcdir;; - esac;; -esac - - cd $ac_dir - # Check for guested configure; otherwise get Cygnus style configure. - if test -f $ac_srcdir/configure.gnu; then - echo - $SHELL $ac_srcdir/configure.gnu --help=recursive - elif test -f $ac_srcdir/configure; then - echo - $SHELL $ac_srcdir/configure --help=recursive - elif test -f $ac_srcdir/configure.ac || - test -f $ac_srcdir/configure.in; then - echo - $ac_configure --help - else - echo "$as_me: WARNING: no configuration information is in $ac_dir" >&2 - fi - cd "$ac_popdir" - done -fi - -test -n "$ac_init_help" && exit 0 -if $ac_init_version; then - cat <<\_ACEOF - -Copyright (C) 2003 Free Software Foundation, Inc. -This configure script is free software; the Free Software Foundation -gives unlimited permission to copy, distribute and modify it. -_ACEOF - exit 0 -fi -exec 5>config.log -cat >&5 <<_ACEOF -This file contains any messages produced by compilers while -running configure, to aid debugging if configure makes a mistake. - -It was created by $as_me, which was -generated by GNU Autoconf 2.59. Invocation command line was - - $ $0 $@ - -_ACEOF -{ -cat <<_ASUNAME -## --------- ## -## Platform. ## -## --------- ## - -hostname = `(hostname || uname -n) 2>/dev/null | sed 1q` -uname -m = `(uname -m) 2>/dev/null || echo unknown` -uname -r = `(uname -r) 2>/dev/null || echo unknown` -uname -s = `(uname -s) 2>/dev/null || echo unknown` -uname -v = `(uname -v) 2>/dev/null || echo unknown` - -/usr/bin/uname -p = `(/usr/bin/uname -p) 2>/dev/null || echo unknown` -/bin/uname -X = `(/bin/uname -X) 2>/dev/null || echo unknown` - -/bin/arch = `(/bin/arch) 2>/dev/null || echo unknown` -/usr/bin/arch -k = `(/usr/bin/arch -k) 2>/dev/null || echo unknown` -/usr/convex/getsysinfo = `(/usr/convex/getsysinfo) 2>/dev/null || echo unknown` -hostinfo = `(hostinfo) 2>/dev/null || echo unknown` -/bin/machine = `(/bin/machine) 2>/dev/null || echo unknown` -/usr/bin/oslevel = `(/usr/bin/oslevel) 2>/dev/null || echo unknown` -/bin/universe = `(/bin/universe) 2>/dev/null || echo unknown` - -_ASUNAME - -as_save_IFS=$IFS; IFS=$PATH_SEPARATOR -for as_dir in $PATH -do - IFS=$as_save_IFS - test -z "$as_dir" && as_dir=. - echo "PATH: $as_dir" -done - -} >&5 - -cat >&5 <<_ACEOF - - -## ----------- ## -## Core tests. ## -## ----------- ## - -_ACEOF - - -# Keep a trace of the command line. -# Strip out --no-create and --no-recursion so they do not pile up. -# Strip out --silent because we don't want to record it for future runs. -# Also quote any args containing shell meta-characters. -# Make two passes to allow for proper duplicate-argument suppression. -ac_configure_args= -ac_configure_args0= -ac_configure_args1= -ac_sep= -ac_must_keep_next=false -for ac_pass in 1 2 -do - for ac_arg - do - case $ac_arg in - -no-create | --no-c* | -n | -no-recursion | --no-r*) continue ;; - -q | -quiet | --quiet | --quie | --qui | --qu | --q \ - | -silent | --silent | --silen | --sile | --sil) - continue ;; - *" "*|*" "*|*[\[\]\~\#\$\^\&\*\(\)\{\}\\\|\;\<\>\?\"\']*) - ac_arg=`echo "$ac_arg" | sed "s/'/'\\\\\\\\''/g"` ;; - esac - case $ac_pass in - 1) ac_configure_args0="$ac_configure_args0 '$ac_arg'" ;; - 2) - ac_configure_args1="$ac_configure_args1 '$ac_arg'" - if test $ac_must_keep_next = true; then - ac_must_keep_next=false # Got value, back to normal. - else - case $ac_arg in - *=* | --config-cache | -C | -disable-* | --disable-* \ - | -enable-* | --enable-* | -gas | --g* | -nfp | --nf* \ - | -q | -quiet | --q* | -silent | --sil* | -v | -verb* \ - | -with-* | --with-* | -without-* | --without-* | --x) - case "$ac_configure_args0 " in - "$ac_configure_args1"*" '$ac_arg' "* ) continue ;; - esac - ;; - -* ) ac_must_keep_next=true ;; - esac - fi - ac_configure_args="$ac_configure_args$ac_sep'$ac_arg'" - # Get rid of the leading space. - ac_sep=" " - ;; - esac - done -done -$as_unset ac_configure_args0 || test "${ac_configure_args0+set}" != set || { ac_configure_args0=; export ac_configure_args0; } -$as_unset ac_configure_args1 || test "${ac_configure_args1+set}" != set || { ac_configure_args1=; export ac_configure_args1; } - -# When interrupted or exit'd, cleanup temporary files, and complete -# config.log. We remove comments because anyway the quotes in there -# would cause problems or look ugly. -# WARNING: Be sure not to use single quotes in there, as some shells, -# such as our DU 5.0 friend, will then `close' the trap. -trap 'exit_status=$? - # Save into config.log some information that might help in debugging. - { - echo - - cat <<\_ASBOX -## ---------------- ## -## Cache variables. ## -## ---------------- ## -_ASBOX - echo - # The following way of writing the cache mishandles newlines in values, -{ - (set) 2>&1 | - case `(ac_space='"'"' '"'"'; set | grep ac_space) 2>&1` in - *ac_space=\ *) - sed -n \ - "s/'"'"'/'"'"'\\\\'"'"''"'"'/g; - s/^\\([_$as_cr_alnum]*_cv_[_$as_cr_alnum]*\\)=\\(.*\\)/\\1='"'"'\\2'"'"'/p" - ;; - *) - sed -n \ - "s/^\\([_$as_cr_alnum]*_cv_[_$as_cr_alnum]*\\)=\\(.*\\)/\\1=\\2/p" - ;; - esac; -} - echo - - cat <<\_ASBOX -## ----------------- ## -## Output variables. ## -## ----------------- ## -_ASBOX - echo - for ac_var in $ac_subst_vars - do - eval ac_val=$`echo $ac_var` - echo "$ac_var='"'"'$ac_val'"'"'" - done | sort - echo - - if test -n "$ac_subst_files"; then - cat <<\_ASBOX -## ------------- ## -## Output files. ## -## ------------- ## -_ASBOX - echo - for ac_var in $ac_subst_files - do - eval ac_val=$`echo $ac_var` - echo "$ac_var='"'"'$ac_val'"'"'" - done | sort - echo - fi - - if test -s confdefs.h; then - cat <<\_ASBOX -## ----------- ## -## confdefs.h. ## -## ----------- ## -_ASBOX - echo - sed "/^$/d" confdefs.h | sort - echo - fi - test "$ac_signal" != 0 && - echo "$as_me: caught signal $ac_signal" - echo "$as_me: exit $exit_status" - } >&5 - rm -f core *.core && - rm -rf conftest* confdefs* conf$$* $ac_clean_files && - exit $exit_status - ' 0 -for ac_signal in 1 2 13 15; do - trap 'ac_signal='$ac_signal'; { (exit 1); exit 1; }' $ac_signal -done -ac_signal=0 - -# confdefs.h avoids OS command line length limits that DEFS can exceed. -rm -rf conftest* confdefs.h -# AIX cpp loses on an empty file, so make sure it contains at least a newline. -echo >confdefs.h - -# Predefined preprocessor variables. - -cat >>confdefs.h <<_ACEOF -#define PACKAGE_NAME "$PACKAGE_NAME" -_ACEOF - - -cat >>confdefs.h <<_ACEOF -#define PACKAGE_TARNAME "$PACKAGE_TARNAME" -_ACEOF - - -cat >>confdefs.h <<_ACEOF -#define PACKAGE_VERSION "$PACKAGE_VERSION" -_ACEOF - - -cat >>confdefs.h <<_ACEOF -#define PACKAGE_STRING "$PACKAGE_STRING" -_ACEOF - - -cat >>confdefs.h <<_ACEOF -#define PACKAGE_BUGREPORT "$PACKAGE_BUGREPORT" -_ACEOF - - -# Let the site file select an alternate cache file if it wants to. -# Prefer explicitly selected file to automatically selected ones. -if test -z "$CONFIG_SITE"; then - if test "x$prefix" != xNONE; then - CONFIG_SITE="$prefix/share/config.site $prefix/etc/config.site" - else - CONFIG_SITE="$ac_default_prefix/share/config.site $ac_default_prefix/etc/config.site" - fi -fi -for ac_site_file in $CONFIG_SITE; do - if test -r "$ac_site_file"; then - { echo "$as_me:$LINENO: loading site script $ac_site_file" >&5 -echo "$as_me: loading site script $ac_site_file" >&6;} - sed 's/^/| /' "$ac_site_file" >&5 - . "$ac_site_file" - fi -done - -if test -r "$cache_file"; then - # Some versions of bash will fail to source /dev/null (special - # files actually), so we avoid doing that. - if test -f "$cache_file"; then - { echo "$as_me:$LINENO: loading cache $cache_file" >&5 -echo "$as_me: loading cache $cache_file" >&6;} - case $cache_file in - [\\/]* | ?:[\\/]* ) . $cache_file;; - *) . ./$cache_file;; - esac - fi -else - { echo "$as_me:$LINENO: creating cache $cache_file" >&5 -echo "$as_me: creating cache $cache_file" >&6;} - >$cache_file -fi - -# Check that the precious variables saved in the cache have kept the same -# value. -ac_cache_corrupted=false -for ac_var in `(set) 2>&1 | - sed -n 's/^ac_env_\([a-zA-Z_0-9]*\)_set=.*/\1/p'`; do - eval ac_old_set=\$ac_cv_env_${ac_var}_set - eval ac_new_set=\$ac_env_${ac_var}_set - eval ac_old_val="\$ac_cv_env_${ac_var}_value" - eval ac_new_val="\$ac_env_${ac_var}_value" - case $ac_old_set,$ac_new_set in - set,) - { echo "$as_me:$LINENO: error: \`$ac_var' was set to \`$ac_old_val' in the previous run" >&5 -echo "$as_me: error: \`$ac_var' was set to \`$ac_old_val' in the previous run" >&2;} - ac_cache_corrupted=: ;; - ,set) - { echo "$as_me:$LINENO: error: \`$ac_var' was not set in the previous run" >&5 -echo "$as_me: error: \`$ac_var' was not set in the previous run" >&2;} - ac_cache_corrupted=: ;; - ,);; - *) - if test "x$ac_old_val" != "x$ac_new_val"; then - { echo "$as_me:$LINENO: error: \`$ac_var' has changed since the previous run:" >&5 -echo "$as_me: error: \`$ac_var' has changed since the previous run:" >&2;} - { echo "$as_me:$LINENO: former value: $ac_old_val" >&5 -echo "$as_me: former value: $ac_old_val" >&2;} - { echo "$as_me:$LINENO: current value: $ac_new_val" >&5 -echo "$as_me: current value: $ac_new_val" >&2;} - ac_cache_corrupted=: - fi;; - esac - # Pass precious variables to config.status. - if test "$ac_new_set" = set; then - case $ac_new_val in - *" "*|*" "*|*[\[\]\~\#\$\^\&\*\(\)\{\}\\\|\;\<\>\?\"\']*) - ac_arg=$ac_var=`echo "$ac_new_val" | sed "s/'/'\\\\\\\\''/g"` ;; - *) ac_arg=$ac_var=$ac_new_val ;; - esac - case " $ac_configure_args " in - *" '$ac_arg' "*) ;; # Avoid dups. Use of quotes ensures accuracy. - *) ac_configure_args="$ac_configure_args '$ac_arg'" ;; - esac - fi -done -if $ac_cache_corrupted; then - { echo "$as_me:$LINENO: error: changes in the environment can compromise the build" >&5 -echo "$as_me: error: changes in the environment can compromise the build" >&2;} - { { echo "$as_me:$LINENO: error: run \`make distclean' and/or \`rm $cache_file' and start over" >&5 -echo "$as_me: error: run \`make distclean' and/or \`rm $cache_file' and start over" >&2;} - { (exit 1); exit 1; }; } -fi - -ac_ext=c -ac_cpp='$CPP $CPPFLAGS' -ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5' -ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5' -ac_compiler_gnu=$ac_cv_c_compiler_gnu - - - - - - - - - - - - - - - - - - - - -ac_ext=c -ac_cpp='$CPP $CPPFLAGS' -ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5' -ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5' -ac_compiler_gnu=$ac_cv_c_compiler_gnu -if test -n "$ac_tool_prefix"; then - # Extract the first word of "${ac_tool_prefix}gcc", so it can be a program name with args. -set dummy ${ac_tool_prefix}gcc; ac_word=$2 -echo "$as_me:$LINENO: checking for $ac_word" >&5 -echo $ECHO_N "checking for $ac_word... $ECHO_C" >&6 -if test "${ac_cv_prog_CC+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - if test -n "$CC"; then - ac_cv_prog_CC="$CC" # Let the user override the test. -else -as_save_IFS=$IFS; IFS=$PATH_SEPARATOR -for as_dir in $PATH -do - IFS=$as_save_IFS - test -z "$as_dir" && as_dir=. - for ac_exec_ext in '' $ac_executable_extensions; do - if $as_executable_p "$as_dir/$ac_word$ac_exec_ext"; then - ac_cv_prog_CC="${ac_tool_prefix}gcc" - echo "$as_me:$LINENO: found $as_dir/$ac_word$ac_exec_ext" >&5 - break 2 - fi -done -done - -fi -fi -CC=$ac_cv_prog_CC -if test -n "$CC"; then - echo "$as_me:$LINENO: result: $CC" >&5 -echo "${ECHO_T}$CC" >&6 -else - echo "$as_me:$LINENO: result: no" >&5 -echo "${ECHO_T}no" >&6 -fi - -fi -if test -z "$ac_cv_prog_CC"; then - ac_ct_CC=$CC - # Extract the first word of "gcc", so it can be a program name with args. -set dummy gcc; ac_word=$2 -echo "$as_me:$LINENO: checking for $ac_word" >&5 -echo $ECHO_N "checking for $ac_word... $ECHO_C" >&6 -if test "${ac_cv_prog_ac_ct_CC+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - if test -n "$ac_ct_CC"; then - ac_cv_prog_ac_ct_CC="$ac_ct_CC" # Let the user override the test. -else -as_save_IFS=$IFS; IFS=$PATH_SEPARATOR -for as_dir in $PATH -do - IFS=$as_save_IFS - test -z "$as_dir" && as_dir=. - for ac_exec_ext in '' $ac_executable_extensions; do - if $as_executable_p "$as_dir/$ac_word$ac_exec_ext"; then - ac_cv_prog_ac_ct_CC="gcc" - echo "$as_me:$LINENO: found $as_dir/$ac_word$ac_exec_ext" >&5 - break 2 - fi -done -done - -fi -fi -ac_ct_CC=$ac_cv_prog_ac_ct_CC -if test -n "$ac_ct_CC"; then - echo "$as_me:$LINENO: result: $ac_ct_CC" >&5 -echo "${ECHO_T}$ac_ct_CC" >&6 -else - echo "$as_me:$LINENO: result: no" >&5 -echo "${ECHO_T}no" >&6 -fi - - CC=$ac_ct_CC -else - CC="$ac_cv_prog_CC" -fi - -if test -z "$CC"; then - if test -n "$ac_tool_prefix"; then - # Extract the first word of "${ac_tool_prefix}cc", so it can be a program name with args. -set dummy ${ac_tool_prefix}cc; ac_word=$2 -echo "$as_me:$LINENO: checking for $ac_word" >&5 -echo $ECHO_N "checking for $ac_word... $ECHO_C" >&6 -if test "${ac_cv_prog_CC+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - if test -n "$CC"; then - ac_cv_prog_CC="$CC" # Let the user override the test. -else -as_save_IFS=$IFS; IFS=$PATH_SEPARATOR -for as_dir in $PATH -do - IFS=$as_save_IFS - test -z "$as_dir" && as_dir=. - for ac_exec_ext in '' $ac_executable_extensions; do - if $as_executable_p "$as_dir/$ac_word$ac_exec_ext"; then - ac_cv_prog_CC="${ac_tool_prefix}cc" - echo "$as_me:$LINENO: found $as_dir/$ac_word$ac_exec_ext" >&5 - break 2 - fi -done -done - -fi -fi -CC=$ac_cv_prog_CC -if test -n "$CC"; then - echo "$as_me:$LINENO: result: $CC" >&5 -echo "${ECHO_T}$CC" >&6 -else - echo "$as_me:$LINENO: result: no" >&5 -echo "${ECHO_T}no" >&6 -fi - -fi -if test -z "$ac_cv_prog_CC"; then - ac_ct_CC=$CC - # Extract the first word of "cc", so it can be a program name with args. -set dummy cc; ac_word=$2 -echo "$as_me:$LINENO: checking for $ac_word" >&5 -echo $ECHO_N "checking for $ac_word... $ECHO_C" >&6 -if test "${ac_cv_prog_ac_ct_CC+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - if test -n "$ac_ct_CC"; then - ac_cv_prog_ac_ct_CC="$ac_ct_CC" # Let the user override the test. -else -as_save_IFS=$IFS; IFS=$PATH_SEPARATOR -for as_dir in $PATH -do - IFS=$as_save_IFS - test -z "$as_dir" && as_dir=. - for ac_exec_ext in '' $ac_executable_extensions; do - if $as_executable_p "$as_dir/$ac_word$ac_exec_ext"; then - ac_cv_prog_ac_ct_CC="cc" - echo "$as_me:$LINENO: found $as_dir/$ac_word$ac_exec_ext" >&5 - break 2 - fi -done -done - -fi -fi -ac_ct_CC=$ac_cv_prog_ac_ct_CC -if test -n "$ac_ct_CC"; then - echo "$as_me:$LINENO: result: $ac_ct_CC" >&5 -echo "${ECHO_T}$ac_ct_CC" >&6 -else - echo "$as_me:$LINENO: result: no" >&5 -echo "${ECHO_T}no" >&6 -fi - - CC=$ac_ct_CC -else - CC="$ac_cv_prog_CC" -fi - -fi -if test -z "$CC"; then - # Extract the first word of "cc", so it can be a program name with args. -set dummy cc; ac_word=$2 -echo "$as_me:$LINENO: checking for $ac_word" >&5 -echo $ECHO_N "checking for $ac_word... $ECHO_C" >&6 -if test "${ac_cv_prog_CC+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - if test -n "$CC"; then - ac_cv_prog_CC="$CC" # Let the user override the test. -else - ac_prog_rejected=no -as_save_IFS=$IFS; IFS=$PATH_SEPARATOR -for as_dir in $PATH -do - IFS=$as_save_IFS - test -z "$as_dir" && as_dir=. - for ac_exec_ext in '' $ac_executable_extensions; do - if $as_executable_p "$as_dir/$ac_word$ac_exec_ext"; then - if test "$as_dir/$ac_word$ac_exec_ext" = "/usr/ucb/cc"; then - ac_prog_rejected=yes - continue - fi - ac_cv_prog_CC="cc" - echo "$as_me:$LINENO: found $as_dir/$ac_word$ac_exec_ext" >&5 - break 2 - fi -done -done - -if test $ac_prog_rejected = yes; then - # We found a bogon in the path, so make sure we never use it. - set dummy $ac_cv_prog_CC - shift - if test $# != 0; then - # We chose a different compiler from the bogus one. - # However, it has the same basename, so the bogon will be chosen - # first if we set CC to just the basename; use the full file name. - shift - ac_cv_prog_CC="$as_dir/$ac_word${1+' '}$@" - fi -fi -fi -fi -CC=$ac_cv_prog_CC -if test -n "$CC"; then - echo "$as_me:$LINENO: result: $CC" >&5 -echo "${ECHO_T}$CC" >&6 -else - echo "$as_me:$LINENO: result: no" >&5 -echo "${ECHO_T}no" >&6 -fi - -fi -if test -z "$CC"; then - if test -n "$ac_tool_prefix"; then - for ac_prog in cl - do - # Extract the first word of "$ac_tool_prefix$ac_prog", so it can be a program name with args. -set dummy $ac_tool_prefix$ac_prog; ac_word=$2 -echo "$as_me:$LINENO: checking for $ac_word" >&5 -echo $ECHO_N "checking for $ac_word... $ECHO_C" >&6 -if test "${ac_cv_prog_CC+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - if test -n "$CC"; then - ac_cv_prog_CC="$CC" # Let the user override the test. -else -as_save_IFS=$IFS; IFS=$PATH_SEPARATOR -for as_dir in $PATH -do - IFS=$as_save_IFS - test -z "$as_dir" && as_dir=. - for ac_exec_ext in '' $ac_executable_extensions; do - if $as_executable_p "$as_dir/$ac_word$ac_exec_ext"; then - ac_cv_prog_CC="$ac_tool_prefix$ac_prog" - echo "$as_me:$LINENO: found $as_dir/$ac_word$ac_exec_ext" >&5 - break 2 - fi -done -done - -fi -fi -CC=$ac_cv_prog_CC -if test -n "$CC"; then - echo "$as_me:$LINENO: result: $CC" >&5 -echo "${ECHO_T}$CC" >&6 -else - echo "$as_me:$LINENO: result: no" >&5 -echo "${ECHO_T}no" >&6 -fi - - test -n "$CC" && break - done -fi -if test -z "$CC"; then - ac_ct_CC=$CC - for ac_prog in cl -do - # Extract the first word of "$ac_prog", so it can be a program name with args. -set dummy $ac_prog; ac_word=$2 -echo "$as_me:$LINENO: checking for $ac_word" >&5 -echo $ECHO_N "checking for $ac_word... $ECHO_C" >&6 -if test "${ac_cv_prog_ac_ct_CC+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - if test -n "$ac_ct_CC"; then - ac_cv_prog_ac_ct_CC="$ac_ct_CC" # Let the user override the test. -else -as_save_IFS=$IFS; IFS=$PATH_SEPARATOR -for as_dir in $PATH -do - IFS=$as_save_IFS - test -z "$as_dir" && as_dir=. - for ac_exec_ext in '' $ac_executable_extensions; do - if $as_executable_p "$as_dir/$ac_word$ac_exec_ext"; then - ac_cv_prog_ac_ct_CC="$ac_prog" - echo "$as_me:$LINENO: found $as_dir/$ac_word$ac_exec_ext" >&5 - break 2 - fi -done -done - -fi -fi -ac_ct_CC=$ac_cv_prog_ac_ct_CC -if test -n "$ac_ct_CC"; then - echo "$as_me:$LINENO: result: $ac_ct_CC" >&5 -echo "${ECHO_T}$ac_ct_CC" >&6 -else - echo "$as_me:$LINENO: result: no" >&5 -echo "${ECHO_T}no" >&6 -fi - - test -n "$ac_ct_CC" && break -done - - CC=$ac_ct_CC -fi - -fi - - -test -z "$CC" && { { echo "$as_me:$LINENO: error: no acceptable C compiler found in \$PATH -See \`config.log' for more details." >&5 -echo "$as_me: error: no acceptable C compiler found in \$PATH -See \`config.log' for more details." >&2;} - { (exit 1); exit 1; }; } - -# Provide some information about the compiler. -echo "$as_me:$LINENO:" \ - "checking for C compiler version" >&5 -ac_compiler=`set X $ac_compile; echo $2` -{ (eval echo "$as_me:$LINENO: \"$ac_compiler --version &5\"") >&5 - (eval $ac_compiler --version &5) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } -{ (eval echo "$as_me:$LINENO: \"$ac_compiler -v &5\"") >&5 - (eval $ac_compiler -v &5) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } -{ (eval echo "$as_me:$LINENO: \"$ac_compiler -V &5\"") >&5 - (eval $ac_compiler -V &5) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } - -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ - -int -main () -{ - - ; - return 0; -} -_ACEOF -ac_clean_files_save=$ac_clean_files -ac_clean_files="$ac_clean_files a.out a.exe b.out" -# Try to create an executable without -o first, disregard a.out. -# It will help us diagnose broken compilers, and finding out an intuition -# of exeext. -echo "$as_me:$LINENO: checking for C compiler default output file name" >&5 -echo $ECHO_N "checking for C compiler default output file name... $ECHO_C" >&6 -ac_link_default=`echo "$ac_link" | sed 's/ -o *conftest[^ ]*//'` -if { (eval echo "$as_me:$LINENO: \"$ac_link_default\"") >&5 - (eval $ac_link_default) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; then - # Find the output, starting from the most likely. This scheme is -# not robust to junk in `.', hence go to wildcards (a.*) only as a last -# resort. - -# Be careful to initialize this variable, since it used to be cached. -# Otherwise an old cache value of `no' led to `EXEEXT = no' in a Makefile. -ac_cv_exeext= -# b.out is created by i960 compilers. -for ac_file in a_out.exe a.exe conftest.exe a.out conftest a.* conftest.* b.out -do - test -f "$ac_file" || continue - case $ac_file in - *.$ac_ext | *.xcoff | *.tds | *.d | *.pdb | *.xSYM | *.bb | *.bbg | *.o | *.obj ) - ;; - conftest.$ac_ext ) - # This is the source file. - ;; - [ab].out ) - # We found the default executable, but exeext='' is most - # certainly right. - break;; - *.* ) - ac_cv_exeext=`expr "$ac_file" : '[^.]*\(\..*\)'` - # FIXME: I believe we export ac_cv_exeext for Libtool, - # but it would be cool to find out if it's true. Does anybody - # maintain Libtool? --akim. - export ac_cv_exeext - break;; - * ) - break;; - esac -done -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -{ { echo "$as_me:$LINENO: error: C compiler cannot create executables -See \`config.log' for more details." >&5 -echo "$as_me: error: C compiler cannot create executables -See \`config.log' for more details." >&2;} - { (exit 77); exit 77; }; } -fi - -ac_exeext=$ac_cv_exeext -echo "$as_me:$LINENO: result: $ac_file" >&5 -echo "${ECHO_T}$ac_file" >&6 - -# Check the compiler produces executables we can run. If not, either -# the compiler is broken, or we cross compile. -echo "$as_me:$LINENO: checking whether the C compiler works" >&5 -echo $ECHO_N "checking whether the C compiler works... $ECHO_C" >&6 -# FIXME: These cross compiler hacks should be removed for Autoconf 3.0 -# If not cross compiling, check that we can run a simple program. -if test "$cross_compiling" != yes; then - if { ac_try='./$ac_file' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - cross_compiling=no - else - if test "$cross_compiling" = maybe; then - cross_compiling=yes - else - { { echo "$as_me:$LINENO: error: cannot run C compiled programs. -If you meant to cross compile, use \`--host'. -See \`config.log' for more details." >&5 -echo "$as_me: error: cannot run C compiled programs. -If you meant to cross compile, use \`--host'. -See \`config.log' for more details." >&2;} - { (exit 1); exit 1; }; } - fi - fi -fi -echo "$as_me:$LINENO: result: yes" >&5 -echo "${ECHO_T}yes" >&6 - -rm -f a.out a.exe conftest$ac_cv_exeext b.out -ac_clean_files=$ac_clean_files_save -# Check the compiler produces executables we can run. If not, either -# the compiler is broken, or we cross compile. -echo "$as_me:$LINENO: checking whether we are cross compiling" >&5 -echo $ECHO_N "checking whether we are cross compiling... $ECHO_C" >&6 -echo "$as_me:$LINENO: result: $cross_compiling" >&5 -echo "${ECHO_T}$cross_compiling" >&6 - -echo "$as_me:$LINENO: checking for suffix of executables" >&5 -echo $ECHO_N "checking for suffix of executables... $ECHO_C" >&6 -if { (eval echo "$as_me:$LINENO: \"$ac_link\"") >&5 - (eval $ac_link) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; then - # If both `conftest.exe' and `conftest' are `present' (well, observable) -# catch `conftest.exe'. For instance with Cygwin, `ls conftest' will -# work properly (i.e., refer to `conftest.exe'), while it won't with -# `rm'. -for ac_file in conftest.exe conftest conftest.*; do - test -f "$ac_file" || continue - case $ac_file in - *.$ac_ext | *.xcoff | *.tds | *.d | *.pdb | *.xSYM | *.bb | *.bbg | *.o | *.obj ) ;; - *.* ) ac_cv_exeext=`expr "$ac_file" : '[^.]*\(\..*\)'` - export ac_cv_exeext - break;; - * ) break;; - esac -done -else - { { echo "$as_me:$LINENO: error: cannot compute suffix of executables: cannot compile and link -See \`config.log' for more details." >&5 -echo "$as_me: error: cannot compute suffix of executables: cannot compile and link -See \`config.log' for more details." >&2;} - { (exit 1); exit 1; }; } -fi - -rm -f conftest$ac_cv_exeext -echo "$as_me:$LINENO: result: $ac_cv_exeext" >&5 -echo "${ECHO_T}$ac_cv_exeext" >&6 - -rm -f conftest.$ac_ext -EXEEXT=$ac_cv_exeext -ac_exeext=$EXEEXT -echo "$as_me:$LINENO: checking for suffix of object files" >&5 -echo $ECHO_N "checking for suffix of object files... $ECHO_C" >&6 -if test "${ac_cv_objext+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ - -int -main () -{ - - ; - return 0; -} -_ACEOF -rm -f conftest.o conftest.obj -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; then - for ac_file in `(ls conftest.o conftest.obj; ls conftest.*) 2>/dev/null`; do - case $ac_file in - *.$ac_ext | *.xcoff | *.tds | *.d | *.pdb | *.xSYM | *.bb | *.bbg ) ;; - *) ac_cv_objext=`expr "$ac_file" : '.*\.\(.*\)'` - break;; - esac -done -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -{ { echo "$as_me:$LINENO: error: cannot compute suffix of object files: cannot compile -See \`config.log' for more details." >&5 -echo "$as_me: error: cannot compute suffix of object files: cannot compile -See \`config.log' for more details." >&2;} - { (exit 1); exit 1; }; } -fi - -rm -f conftest.$ac_cv_objext conftest.$ac_ext -fi -echo "$as_me:$LINENO: result: $ac_cv_objext" >&5 -echo "${ECHO_T}$ac_cv_objext" >&6 -OBJEXT=$ac_cv_objext -ac_objext=$OBJEXT -echo "$as_me:$LINENO: checking whether we are using the GNU C compiler" >&5 -echo $ECHO_N "checking whether we are using the GNU C compiler... $ECHO_C" >&6 -if test "${ac_cv_c_compiler_gnu+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ - -int -main () -{ -#ifndef __GNUC__ - choke me -#endif - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_compiler_gnu=yes -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_compiler_gnu=no -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -ac_cv_c_compiler_gnu=$ac_compiler_gnu - -fi -echo "$as_me:$LINENO: result: $ac_cv_c_compiler_gnu" >&5 -echo "${ECHO_T}$ac_cv_c_compiler_gnu" >&6 -GCC=`test $ac_compiler_gnu = yes && echo yes` -ac_test_CFLAGS=${CFLAGS+set} -ac_save_CFLAGS=$CFLAGS -CFLAGS="-g" -echo "$as_me:$LINENO: checking whether $CC accepts -g" >&5 -echo $ECHO_N "checking whether $CC accepts -g... $ECHO_C" >&6 -if test "${ac_cv_prog_cc_g+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ - -int -main () -{ - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_cv_prog_cc_g=yes -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_cv_prog_cc_g=no -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -fi -echo "$as_me:$LINENO: result: $ac_cv_prog_cc_g" >&5 -echo "${ECHO_T}$ac_cv_prog_cc_g" >&6 -if test "$ac_test_CFLAGS" = set; then - CFLAGS=$ac_save_CFLAGS -elif test $ac_cv_prog_cc_g = yes; then - if test "$GCC" = yes; then - CFLAGS="-g -O2" - else - CFLAGS="-g" - fi -else - if test "$GCC" = yes; then - CFLAGS="-O2" - else - CFLAGS= - fi -fi -echo "$as_me:$LINENO: checking for $CC option to accept ANSI C" >&5 -echo $ECHO_N "checking for $CC option to accept ANSI C... $ECHO_C" >&6 -if test "${ac_cv_prog_cc_stdc+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - ac_cv_prog_cc_stdc=no -ac_save_CC=$CC -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -#include -#include -#include -#include -/* Most of the following tests are stolen from RCS 5.7's src/conf.sh. */ -struct buf { int x; }; -FILE * (*rcsopen) (struct buf *, struct stat *, int); -static char *e (p, i) - char **p; - int i; -{ - return p[i]; -} -static char *f (char * (*g) (char **, int), char **p, ...) -{ - char *s; - va_list v; - va_start (v,p); - s = g (p, va_arg (v,int)); - va_end (v); - return s; -} - -/* OSF 4.0 Compaq cc is some sort of almost-ANSI by default. It has - function prototypes and stuff, but not '\xHH' hex character constants. - These don't provoke an error unfortunately, instead are silently treated - as 'x'. The following induces an error, until -std1 is added to get - proper ANSI mode. Curiously '\x00'!='x' always comes out true, for an - array size at least. It's necessary to write '\x00'==0 to get something - that's true only with -std1. */ -int osf4_cc_array ['\x00' == 0 ? 1 : -1]; - -int test (int i, double x); -struct s1 {int (*f) (int a);}; -struct s2 {int (*f) (double a);}; -int pairnames (int, char **, FILE *(*)(struct buf *, struct stat *, int), int, int); -int argc; -char **argv; -int -main () -{ -return f (e, argv, 0) != argv[0] || f (e, argv, 1) != argv[1]; - ; - return 0; -} -_ACEOF -# Don't try gcc -ansi; that turns off useful extensions and -# breaks some systems' header files. -# AIX -qlanglvl=ansi -# Ultrix and OSF/1 -std1 -# HP-UX 10.20 and later -Ae -# HP-UX older versions -Aa -D_HPUX_SOURCE -# SVR4 -Xc -D__EXTENSIONS__ -for ac_arg in "" -qlanglvl=ansi -std1 -Ae "-Aa -D_HPUX_SOURCE" "-Xc -D__EXTENSIONS__" -do - CC="$ac_save_CC $ac_arg" - rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_cv_prog_cc_stdc=$ac_arg -break -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -fi -rm -f conftest.err conftest.$ac_objext -done -rm -f conftest.$ac_ext conftest.$ac_objext -CC=$ac_save_CC - -fi - -case "x$ac_cv_prog_cc_stdc" in - x|xno) - echo "$as_me:$LINENO: result: none needed" >&5 -echo "${ECHO_T}none needed" >&6 ;; - *) - echo "$as_me:$LINENO: result: $ac_cv_prog_cc_stdc" >&5 -echo "${ECHO_T}$ac_cv_prog_cc_stdc" >&6 - CC="$CC $ac_cv_prog_cc_stdc" ;; -esac - -# Some people use a C++ compiler to compile C. Since we use `exit', -# in C++ we need to declare it. In case someone uses the same compiler -# for both compiling C and C++ we need to have the C++ compiler decide -# the declaration of exit, since it's the most demanding environment. -cat >conftest.$ac_ext <<_ACEOF -#ifndef __cplusplus - choke me -#endif -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - for ac_declaration in \ - '' \ - 'extern "C" void std::exit (int) throw (); using std::exit;' \ - 'extern "C" void std::exit (int); using std::exit;' \ - 'extern "C" void exit (int) throw ();' \ - 'extern "C" void exit (int);' \ - 'void exit (int);' -do - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_declaration -#include -int -main () -{ -exit (42); - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - : -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -continue -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_declaration -int -main () -{ -exit (42); - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - break -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -done -rm -f conftest* -if test -n "$ac_declaration"; then - echo '#ifdef __cplusplus' >>confdefs.h - echo $ac_declaration >>confdefs.h - echo '#endif' >>confdefs.h -fi - -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -ac_ext=c -ac_cpp='$CPP $CPPFLAGS' -ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5' -ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5' -ac_compiler_gnu=$ac_cv_c_compiler_gnu - -if test "$GCC" = "yes"; then - CFLAGS="${CFLAGS} -Wall" -fi -ac_aux_dir= -for ac_dir in $srcdir $srcdir/.. $srcdir/../..; do - if test -f $ac_dir/install-sh; then - ac_aux_dir=$ac_dir - ac_install_sh="$ac_aux_dir/install-sh -c" - break - elif test -f $ac_dir/install.sh; then - ac_aux_dir=$ac_dir - ac_install_sh="$ac_aux_dir/install.sh -c" - break - elif test -f $ac_dir/shtool; then - ac_aux_dir=$ac_dir - ac_install_sh="$ac_aux_dir/shtool install -c" - break - fi -done -if test -z "$ac_aux_dir"; then - { { echo "$as_me:$LINENO: error: cannot find install-sh or install.sh in $srcdir $srcdir/.. $srcdir/../.." >&5 -echo "$as_me: error: cannot find install-sh or install.sh in $srcdir $srcdir/.. $srcdir/../.." >&2;} - { (exit 1); exit 1; }; } -fi -ac_config_guess="$SHELL $ac_aux_dir/config.guess" -ac_config_sub="$SHELL $ac_aux_dir/config.sub" -ac_configure="$SHELL $ac_aux_dir/configure" # This should be Cygnus configure. - -# Find a good install program. We prefer a C program (faster), -# so one script is as good as another. But avoid the broken or -# incompatible versions: -# SysV /etc/install, /usr/sbin/install -# SunOS /usr/etc/install -# IRIX /sbin/install -# AIX /bin/install -# AmigaOS /C/install, which installs bootblocks on floppy discs -# AIX 4 /usr/bin/installbsd, which doesn't work without a -g flag -# AFS /usr/afsws/bin/install, which mishandles nonexistent args -# SVR4 /usr/ucb/install, which tries to use the nonexistent group "staff" -# OS/2's system install, which has a completely different semantic -# ./install, which can be erroneously created by make from ./install.sh. -echo "$as_me:$LINENO: checking for a BSD-compatible install" >&5 -echo $ECHO_N "checking for a BSD-compatible install... $ECHO_C" >&6 -if test -z "$INSTALL"; then -if test "${ac_cv_path_install+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - as_save_IFS=$IFS; IFS=$PATH_SEPARATOR -for as_dir in $PATH -do - IFS=$as_save_IFS - test -z "$as_dir" && as_dir=. - # Account for people who put trailing slashes in PATH elements. -case $as_dir/ in - ./ | .// | /cC/* | \ - /etc/* | /usr/sbin/* | /usr/etc/* | /sbin/* | /usr/afsws/bin/* | \ - ?:\\/os2\\/install\\/* | ?:\\/OS2\\/INSTALL\\/* | \ - /usr/ucb/* ) ;; - *) - # OSF1 and SCO ODT 3.0 have their own names for install. - # Don't use installbsd from OSF since it installs stuff as root - # by default. - for ac_prog in ginstall scoinst install; do - for ac_exec_ext in '' $ac_executable_extensions; do - if $as_executable_p "$as_dir/$ac_prog$ac_exec_ext"; then - if test $ac_prog = install && - grep dspmsg "$as_dir/$ac_prog$ac_exec_ext" >/dev/null 2>&1; then - # AIX install. It has an incompatible calling convention. - : - elif test $ac_prog = install && - grep pwplus "$as_dir/$ac_prog$ac_exec_ext" >/dev/null 2>&1; then - # program-specific install script used by HP pwplus--don't use. - : - else - ac_cv_path_install="$as_dir/$ac_prog$ac_exec_ext -c" - break 3 - fi - fi - done - done - ;; -esac -done - - -fi - if test "${ac_cv_path_install+set}" = set; then - INSTALL=$ac_cv_path_install - else - # As a last resort, use the slow shell script. We don't cache a - # path for INSTALL within a source directory, because that will - # break other packages using the cache if that directory is - # removed, or if the path is relative. - INSTALL=$ac_install_sh - fi -fi -echo "$as_me:$LINENO: result: $INSTALL" >&5 -echo "${ECHO_T}$INSTALL" >&6 - -# Use test -z because SunOS4 sh mishandles braces in ${var-val}. -# It thinks the first close brace ends the variable substitution. -test -z "$INSTALL_PROGRAM" && INSTALL_PROGRAM='${INSTALL}' - -test -z "$INSTALL_SCRIPT" && INSTALL_SCRIPT='${INSTALL}' - -test -z "$INSTALL_DATA" && INSTALL_DATA='${INSTALL} -m 644' - - - - -echo "$as_me:$LINENO: checking for res_query in -lresolv" >&5 -echo $ECHO_N "checking for res_query in -lresolv... $ECHO_C" >&6 -if test "${ac_cv_lib_resolv_res_query+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - ac_check_lib_save_LIBS=$LIBS -LIBS="-lresolv $LIBS" -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ - -/* Override any gcc2 internal prototype to avoid an error. */ -#ifdef __cplusplus -extern "C" -#endif -/* We use char because int might match the return type of a gcc2 - builtin and then its argument prototype would still apply. */ -char res_query (); -int -main () -{ -res_query (); - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext conftest$ac_exeext -if { (eval echo "$as_me:$LINENO: \"$ac_link\"") >&5 - (eval $ac_link) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest$ac_exeext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_cv_lib_resolv_res_query=yes -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_cv_lib_resolv_res_query=no -fi -rm -f conftest.err conftest.$ac_objext \ - conftest$ac_exeext conftest.$ac_ext -LIBS=$ac_check_lib_save_LIBS -fi -echo "$as_me:$LINENO: result: $ac_cv_lib_resolv_res_query" >&5 -echo "${ECHO_T}$ac_cv_lib_resolv_res_query" >&6 -if test $ac_cv_lib_resolv_res_query = yes; then - cat >>confdefs.h <<_ACEOF -#define HAVE_LIBRESOLV 1 -_ACEOF - - LIBS="-lresolv $LIBS" - -fi - - -ac_ext=c -ac_cpp='$CPP $CPPFLAGS' -ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5' -ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5' -ac_compiler_gnu=$ac_cv_c_compiler_gnu -echo "$as_me:$LINENO: checking how to run the C preprocessor" >&5 -echo $ECHO_N "checking how to run the C preprocessor... $ECHO_C" >&6 -# On Suns, sometimes $CPP names a directory. -if test -n "$CPP" && test -d "$CPP"; then - CPP= -fi -if test -z "$CPP"; then - if test "${ac_cv_prog_CPP+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - # Double quotes because CPP needs to be expanded - for CPP in "$CC -E" "$CC -E -traditional-cpp" "/lib/cpp" - do - ac_preproc_ok=false -for ac_c_preproc_warn_flag in '' yes -do - # Use a header file that comes with gcc, so configuring glibc - # with a fresh cross-compiler works. - # Prefer to if __STDC__ is defined, since - # exists even on freestanding compilers. - # On the NeXT, cc -E runs the code through the compiler's parser, - # not just through cpp. "Syntax error" is here to catch this case. - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -#ifdef __STDC__ -# include -#else -# include -#endif - Syntax error -_ACEOF -if { (eval echo "$as_me:$LINENO: \"$ac_cpp conftest.$ac_ext\"") >&5 - (eval $ac_cpp conftest.$ac_ext) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } >/dev/null; then - if test -s conftest.err; then - ac_cpp_err=$ac_c_preproc_warn_flag - ac_cpp_err=$ac_cpp_err$ac_c_werror_flag - else - ac_cpp_err= - fi -else - ac_cpp_err=yes -fi -if test -z "$ac_cpp_err"; then - : -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - - # Broken: fails on valid input. -continue -fi -rm -f conftest.err conftest.$ac_ext - - # OK, works on sane cases. Now check whether non-existent headers - # can be detected and how. - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -#include -_ACEOF -if { (eval echo "$as_me:$LINENO: \"$ac_cpp conftest.$ac_ext\"") >&5 - (eval $ac_cpp conftest.$ac_ext) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } >/dev/null; then - if test -s conftest.err; then - ac_cpp_err=$ac_c_preproc_warn_flag - ac_cpp_err=$ac_cpp_err$ac_c_werror_flag - else - ac_cpp_err= - fi -else - ac_cpp_err=yes -fi -if test -z "$ac_cpp_err"; then - # Broken: success on invalid input. -continue -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - - # Passes both tests. -ac_preproc_ok=: -break -fi -rm -f conftest.err conftest.$ac_ext - -done -# Because of `break', _AC_PREPROC_IFELSE's cleaning code was skipped. -rm -f conftest.err conftest.$ac_ext -if $ac_preproc_ok; then - break -fi - - done - ac_cv_prog_CPP=$CPP - -fi - CPP=$ac_cv_prog_CPP -else - ac_cv_prog_CPP=$CPP -fi -echo "$as_me:$LINENO: result: $CPP" >&5 -echo "${ECHO_T}$CPP" >&6 -ac_preproc_ok=false -for ac_c_preproc_warn_flag in '' yes -do - # Use a header file that comes with gcc, so configuring glibc - # with a fresh cross-compiler works. - # Prefer to if __STDC__ is defined, since - # exists even on freestanding compilers. - # On the NeXT, cc -E runs the code through the compiler's parser, - # not just through cpp. "Syntax error" is here to catch this case. - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -#ifdef __STDC__ -# include -#else -# include -#endif - Syntax error -_ACEOF -if { (eval echo "$as_me:$LINENO: \"$ac_cpp conftest.$ac_ext\"") >&5 - (eval $ac_cpp conftest.$ac_ext) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } >/dev/null; then - if test -s conftest.err; then - ac_cpp_err=$ac_c_preproc_warn_flag - ac_cpp_err=$ac_cpp_err$ac_c_werror_flag - else - ac_cpp_err= - fi -else - ac_cpp_err=yes -fi -if test -z "$ac_cpp_err"; then - : -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - - # Broken: fails on valid input. -continue -fi -rm -f conftest.err conftest.$ac_ext - - # OK, works on sane cases. Now check whether non-existent headers - # can be detected and how. - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -#include -_ACEOF -if { (eval echo "$as_me:$LINENO: \"$ac_cpp conftest.$ac_ext\"") >&5 - (eval $ac_cpp conftest.$ac_ext) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } >/dev/null; then - if test -s conftest.err; then - ac_cpp_err=$ac_c_preproc_warn_flag - ac_cpp_err=$ac_cpp_err$ac_c_werror_flag - else - ac_cpp_err= - fi -else - ac_cpp_err=yes -fi -if test -z "$ac_cpp_err"; then - # Broken: success on invalid input. -continue -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - - # Passes both tests. -ac_preproc_ok=: -break -fi -rm -f conftest.err conftest.$ac_ext - -done -# Because of `break', _AC_PREPROC_IFELSE's cleaning code was skipped. -rm -f conftest.err conftest.$ac_ext -if $ac_preproc_ok; then - : -else - { { echo "$as_me:$LINENO: error: C preprocessor \"$CPP\" fails sanity check -See \`config.log' for more details." >&5 -echo "$as_me: error: C preprocessor \"$CPP\" fails sanity check -See \`config.log' for more details." >&2;} - { (exit 1); exit 1; }; } -fi - -ac_ext=c -ac_cpp='$CPP $CPPFLAGS' -ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5' -ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5' -ac_compiler_gnu=$ac_cv_c_compiler_gnu - - -echo "$as_me:$LINENO: checking for egrep" >&5 -echo $ECHO_N "checking for egrep... $ECHO_C" >&6 -if test "${ac_cv_prog_egrep+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - if echo a | (grep -E '(a|b)') >/dev/null 2>&1 - then ac_cv_prog_egrep='grep -E' - else ac_cv_prog_egrep='egrep' - fi -fi -echo "$as_me:$LINENO: result: $ac_cv_prog_egrep" >&5 -echo "${ECHO_T}$ac_cv_prog_egrep" >&6 - EGREP=$ac_cv_prog_egrep - - -echo "$as_me:$LINENO: checking for ANSI C header files" >&5 -echo $ECHO_N "checking for ANSI C header files... $ECHO_C" >&6 -if test "${ac_cv_header_stdc+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -#include -#include -#include -#include - -int -main () -{ - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_cv_header_stdc=yes -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_cv_header_stdc=no -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext - -if test $ac_cv_header_stdc = yes; then - # SunOS 4.x string.h does not declare mem*, contrary to ANSI. - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -#include - -_ACEOF -if (eval "$ac_cpp conftest.$ac_ext") 2>&5 | - $EGREP "memchr" >/dev/null 2>&1; then - : -else - ac_cv_header_stdc=no -fi -rm -f conftest* - -fi - -if test $ac_cv_header_stdc = yes; then - # ISC 2.0.2 stdlib.h does not declare free, contrary to ANSI. - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -#include - -_ACEOF -if (eval "$ac_cpp conftest.$ac_ext") 2>&5 | - $EGREP "free" >/dev/null 2>&1; then - : -else - ac_cv_header_stdc=no -fi -rm -f conftest* - -fi - -if test $ac_cv_header_stdc = yes; then - # /bin/cc in Irix-4.0.5 gets non-ANSI ctype macros unless using -ansi. - if test "$cross_compiling" = yes; then - : -else - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -#include -#if ((' ' & 0x0FF) == 0x020) -# define ISLOWER(c) ('a' <= (c) && (c) <= 'z') -# define TOUPPER(c) (ISLOWER(c) ? 'A' + ((c) - 'a') : (c)) -#else -# define ISLOWER(c) \ - (('a' <= (c) && (c) <= 'i') \ - || ('j' <= (c) && (c) <= 'r') \ - || ('s' <= (c) && (c) <= 'z')) -# define TOUPPER(c) (ISLOWER(c) ? ((c) | 0x40) : (c)) -#endif - -#define XOR(e, f) (((e) && !(f)) || (!(e) && (f))) -int -main () -{ - int i; - for (i = 0; i < 256; i++) - if (XOR (islower (i), ISLOWER (i)) - || toupper (i) != TOUPPER (i)) - exit(2); - exit (0); -} -_ACEOF -rm -f conftest$ac_exeext -if { (eval echo "$as_me:$LINENO: \"$ac_link\"") >&5 - (eval $ac_link) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && { ac_try='./conftest$ac_exeext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - : -else - echo "$as_me: program exited with status $ac_status" >&5 -echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -( exit $ac_status ) -ac_cv_header_stdc=no -fi -rm -f core *.core gmon.out bb.out conftest$ac_exeext conftest.$ac_objext conftest.$ac_ext -fi -fi -fi -echo "$as_me:$LINENO: result: $ac_cv_header_stdc" >&5 -echo "${ECHO_T}$ac_cv_header_stdc" >&6 -if test $ac_cv_header_stdc = yes; then - -cat >>confdefs.h <<\_ACEOF -#define STDC_HEADERS 1 -_ACEOF - -fi - - ac_config_headers="$ac_config_headers config.h" - -# On IRIX 5.3, sys/types and inttypes.h are conflicting. - - - - - - - - - -for ac_header in sys/types.h sys/stat.h stdlib.h string.h memory.h strings.h \ - inttypes.h stdint.h unistd.h -do -as_ac_Header=`echo "ac_cv_header_$ac_header" | $as_tr_sh` -echo "$as_me:$LINENO: checking for $ac_header" >&5 -echo $ECHO_N "checking for $ac_header... $ECHO_C" >&6 -if eval "test \"\${$as_ac_Header+set}\" = set"; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default - -#include <$ac_header> -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - eval "$as_ac_Header=yes" -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -eval "$as_ac_Header=no" -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -fi -echo "$as_me:$LINENO: result: `eval echo '${'$as_ac_Header'}'`" >&5 -echo "${ECHO_T}`eval echo '${'$as_ac_Header'}'`" >&6 -if test `eval echo '${'$as_ac_Header'}'` = yes; then - cat >>confdefs.h <<_ACEOF -#define `echo "HAVE_$ac_header" | $as_tr_cpp` 1 -_ACEOF - -fi - -done - - -if test "${ac_cv_header_resolv_h+set}" = set; then - echo "$as_me:$LINENO: checking for resolv.h" >&5 -echo $ECHO_N "checking for resolv.h... $ECHO_C" >&6 -if test "${ac_cv_header_resolv_h+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -fi -echo "$as_me:$LINENO: result: $ac_cv_header_resolv_h" >&5 -echo "${ECHO_T}$ac_cv_header_resolv_h" >&6 -else - # Is the header compilable? -echo "$as_me:$LINENO: checking resolv.h usability" >&5 -echo $ECHO_N "checking resolv.h usability... $ECHO_C" >&6 -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -#include -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_header_compiler=yes -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_header_compiler=no -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -echo "$as_me:$LINENO: result: $ac_header_compiler" >&5 -echo "${ECHO_T}$ac_header_compiler" >&6 - -# Is the header present? -echo "$as_me:$LINENO: checking resolv.h presence" >&5 -echo $ECHO_N "checking resolv.h presence... $ECHO_C" >&6 -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -#include -_ACEOF -if { (eval echo "$as_me:$LINENO: \"$ac_cpp conftest.$ac_ext\"") >&5 - (eval $ac_cpp conftest.$ac_ext) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } >/dev/null; then - if test -s conftest.err; then - ac_cpp_err=$ac_c_preproc_warn_flag - ac_cpp_err=$ac_cpp_err$ac_c_werror_flag - else - ac_cpp_err= - fi -else - ac_cpp_err=yes -fi -if test -z "$ac_cpp_err"; then - ac_header_preproc=yes -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - - ac_header_preproc=no -fi -rm -f conftest.err conftest.$ac_ext -echo "$as_me:$LINENO: result: $ac_header_preproc" >&5 -echo "${ECHO_T}$ac_header_preproc" >&6 - -# So? What about this header? -case $ac_header_compiler:$ac_header_preproc:$ac_c_preproc_warn_flag in - yes:no: ) - { echo "$as_me:$LINENO: WARNING: resolv.h: accepted by the compiler, rejected by the preprocessor!" >&5 -echo "$as_me: WARNING: resolv.h: accepted by the compiler, rejected by the preprocessor!" >&2;} - { echo "$as_me:$LINENO: WARNING: resolv.h: proceeding with the compiler's result" >&5 -echo "$as_me: WARNING: resolv.h: proceeding with the compiler's result" >&2;} - ac_header_preproc=yes - ;; - no:yes:* ) - { echo "$as_me:$LINENO: WARNING: resolv.h: present but cannot be compiled" >&5 -echo "$as_me: WARNING: resolv.h: present but cannot be compiled" >&2;} - { echo "$as_me:$LINENO: WARNING: resolv.h: check for missing prerequisite headers?" >&5 -echo "$as_me: WARNING: resolv.h: check for missing prerequisite headers?" >&2;} - { echo "$as_me:$LINENO: WARNING: resolv.h: see the Autoconf documentation" >&5 -echo "$as_me: WARNING: resolv.h: see the Autoconf documentation" >&2;} - { echo "$as_me:$LINENO: WARNING: resolv.h: section \"Present But Cannot Be Compiled\"" >&5 -echo "$as_me: WARNING: resolv.h: section \"Present But Cannot Be Compiled\"" >&2;} - { echo "$as_me:$LINENO: WARNING: resolv.h: proceeding with the preprocessor's result" >&5 -echo "$as_me: WARNING: resolv.h: proceeding with the preprocessor's result" >&2;} - { echo "$as_me:$LINENO: WARNING: resolv.h: in the future, the compiler will take precedence" >&5 -echo "$as_me: WARNING: resolv.h: in the future, the compiler will take precedence" >&2;} - ( - cat <<\_ASBOX -## ------------------------------------------ ## -## Report this to the AC_PACKAGE_NAME lists. ## -## ------------------------------------------ ## -_ASBOX - ) | - sed "s/^/$as_me: WARNING: /" >&2 - ;; -esac -echo "$as_me:$LINENO: checking for resolv.h" >&5 -echo $ECHO_N "checking for resolv.h... $ECHO_C" >&6 -if test "${ac_cv_header_resolv_h+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - ac_cv_header_resolv_h=$ac_header_preproc -fi -echo "$as_me:$LINENO: result: $ac_cv_header_resolv_h" >&5 -echo "${ECHO_T}$ac_cv_header_resolv_h" >&6 - -fi -if test $ac_cv_header_resolv_h = yes; then - : -else - { { echo "$as_me:$LINENO: error: \"No headers for name service applications\"" >&5 -echo "$as_me: error: \"No headers for name service applications\"" >&2;} - { (exit 1); exit 1; }; } -fi - - -if test "${ac_cv_header_arpa_nameser_h+set}" = set; then - echo "$as_me:$LINENO: checking for arpa/nameser.h" >&5 -echo $ECHO_N "checking for arpa/nameser.h... $ECHO_C" >&6 -if test "${ac_cv_header_arpa_nameser_h+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -fi -echo "$as_me:$LINENO: result: $ac_cv_header_arpa_nameser_h" >&5 -echo "${ECHO_T}$ac_cv_header_arpa_nameser_h" >&6 -else - # Is the header compilable? -echo "$as_me:$LINENO: checking arpa/nameser.h usability" >&5 -echo $ECHO_N "checking arpa/nameser.h usability... $ECHO_C" >&6 -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -#include -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_header_compiler=yes -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_header_compiler=no -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -echo "$as_me:$LINENO: result: $ac_header_compiler" >&5 -echo "${ECHO_T}$ac_header_compiler" >&6 - -# Is the header present? -echo "$as_me:$LINENO: checking arpa/nameser.h presence" >&5 -echo $ECHO_N "checking arpa/nameser.h presence... $ECHO_C" >&6 -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -#include -_ACEOF -if { (eval echo "$as_me:$LINENO: \"$ac_cpp conftest.$ac_ext\"") >&5 - (eval $ac_cpp conftest.$ac_ext) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } >/dev/null; then - if test -s conftest.err; then - ac_cpp_err=$ac_c_preproc_warn_flag - ac_cpp_err=$ac_cpp_err$ac_c_werror_flag - else - ac_cpp_err= - fi -else - ac_cpp_err=yes -fi -if test -z "$ac_cpp_err"; then - ac_header_preproc=yes -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - - ac_header_preproc=no -fi -rm -f conftest.err conftest.$ac_ext -echo "$as_me:$LINENO: result: $ac_header_preproc" >&5 -echo "${ECHO_T}$ac_header_preproc" >&6 - -# So? What about this header? -case $ac_header_compiler:$ac_header_preproc:$ac_c_preproc_warn_flag in - yes:no: ) - { echo "$as_me:$LINENO: WARNING: arpa/nameser.h: accepted by the compiler, rejected by the preprocessor!" >&5 -echo "$as_me: WARNING: arpa/nameser.h: accepted by the compiler, rejected by the preprocessor!" >&2;} - { echo "$as_me:$LINENO: WARNING: arpa/nameser.h: proceeding with the compiler's result" >&5 -echo "$as_me: WARNING: arpa/nameser.h: proceeding with the compiler's result" >&2;} - ac_header_preproc=yes - ;; - no:yes:* ) - { echo "$as_me:$LINENO: WARNING: arpa/nameser.h: present but cannot be compiled" >&5 -echo "$as_me: WARNING: arpa/nameser.h: present but cannot be compiled" >&2;} - { echo "$as_me:$LINENO: WARNING: arpa/nameser.h: check for missing prerequisite headers?" >&5 -echo "$as_me: WARNING: arpa/nameser.h: check for missing prerequisite headers?" >&2;} - { echo "$as_me:$LINENO: WARNING: arpa/nameser.h: see the Autoconf documentation" >&5 -echo "$as_me: WARNING: arpa/nameser.h: see the Autoconf documentation" >&2;} - { echo "$as_me:$LINENO: WARNING: arpa/nameser.h: section \"Present But Cannot Be Compiled\"" >&5 -echo "$as_me: WARNING: arpa/nameser.h: section \"Present But Cannot Be Compiled\"" >&2;} - { echo "$as_me:$LINENO: WARNING: arpa/nameser.h: proceeding with the preprocessor's result" >&5 -echo "$as_me: WARNING: arpa/nameser.h: proceeding with the preprocessor's result" >&2;} - { echo "$as_me:$LINENO: WARNING: arpa/nameser.h: in the future, the compiler will take precedence" >&5 -echo "$as_me: WARNING: arpa/nameser.h: in the future, the compiler will take precedence" >&2;} - ( - cat <<\_ASBOX -## ------------------------------------------ ## -## Report this to the AC_PACKAGE_NAME lists. ## -## ------------------------------------------ ## -_ASBOX - ) | - sed "s/^/$as_me: WARNING: /" >&2 - ;; -esac -echo "$as_me:$LINENO: checking for arpa/nameser.h" >&5 -echo $ECHO_N "checking for arpa/nameser.h... $ECHO_C" >&6 -if test "${ac_cv_header_arpa_nameser_h+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - ac_cv_header_arpa_nameser_h=$ac_header_preproc -fi -echo "$as_me:$LINENO: result: $ac_cv_header_arpa_nameser_h" >&5 -echo "${ECHO_T}$ac_cv_header_arpa_nameser_h" >&6 - -fi -if test $ac_cv_header_arpa_nameser_h = yes; then - : -else - { { echo "$as_me:$LINENO: error: \"No headers for name service applications\"" >&5 -echo "$as_me: error: \"No headers for name service applications\"" >&2;} - { (exit 1); exit 1; }; } -fi - - -if test "${ac_cv_header_sys_time_h+set}" = set; then - echo "$as_me:$LINENO: checking for sys/time.h" >&5 -echo $ECHO_N "checking for sys/time.h... $ECHO_C" >&6 -if test "${ac_cv_header_sys_time_h+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -fi -echo "$as_me:$LINENO: result: $ac_cv_header_sys_time_h" >&5 -echo "${ECHO_T}$ac_cv_header_sys_time_h" >&6 -else - # Is the header compilable? -echo "$as_me:$LINENO: checking sys/time.h usability" >&5 -echo $ECHO_N "checking sys/time.h usability... $ECHO_C" >&6 -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -#include -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_header_compiler=yes -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_header_compiler=no -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -echo "$as_me:$LINENO: result: $ac_header_compiler" >&5 -echo "${ECHO_T}$ac_header_compiler" >&6 - -# Is the header present? -echo "$as_me:$LINENO: checking sys/time.h presence" >&5 -echo $ECHO_N "checking sys/time.h presence... $ECHO_C" >&6 -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -#include -_ACEOF -if { (eval echo "$as_me:$LINENO: \"$ac_cpp conftest.$ac_ext\"") >&5 - (eval $ac_cpp conftest.$ac_ext) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } >/dev/null; then - if test -s conftest.err; then - ac_cpp_err=$ac_c_preproc_warn_flag - ac_cpp_err=$ac_cpp_err$ac_c_werror_flag - else - ac_cpp_err= - fi -else - ac_cpp_err=yes -fi -if test -z "$ac_cpp_err"; then - ac_header_preproc=yes -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - - ac_header_preproc=no -fi -rm -f conftest.err conftest.$ac_ext -echo "$as_me:$LINENO: result: $ac_header_preproc" >&5 -echo "${ECHO_T}$ac_header_preproc" >&6 - -# So? What about this header? -case $ac_header_compiler:$ac_header_preproc:$ac_c_preproc_warn_flag in - yes:no: ) - { echo "$as_me:$LINENO: WARNING: sys/time.h: accepted by the compiler, rejected by the preprocessor!" >&5 -echo "$as_me: WARNING: sys/time.h: accepted by the compiler, rejected by the preprocessor!" >&2;} - { echo "$as_me:$LINENO: WARNING: sys/time.h: proceeding with the compiler's result" >&5 -echo "$as_me: WARNING: sys/time.h: proceeding with the compiler's result" >&2;} - ac_header_preproc=yes - ;; - no:yes:* ) - { echo "$as_me:$LINENO: WARNING: sys/time.h: present but cannot be compiled" >&5 -echo "$as_me: WARNING: sys/time.h: present but cannot be compiled" >&2;} - { echo "$as_me:$LINENO: WARNING: sys/time.h: check for missing prerequisite headers?" >&5 -echo "$as_me: WARNING: sys/time.h: check for missing prerequisite headers?" >&2;} - { echo "$as_me:$LINENO: WARNING: sys/time.h: see the Autoconf documentation" >&5 -echo "$as_me: WARNING: sys/time.h: see the Autoconf documentation" >&2;} - { echo "$as_me:$LINENO: WARNING: sys/time.h: section \"Present But Cannot Be Compiled\"" >&5 -echo "$as_me: WARNING: sys/time.h: section \"Present But Cannot Be Compiled\"" >&2;} - { echo "$as_me:$LINENO: WARNING: sys/time.h: proceeding with the preprocessor's result" >&5 -echo "$as_me: WARNING: sys/time.h: proceeding with the preprocessor's result" >&2;} - { echo "$as_me:$LINENO: WARNING: sys/time.h: in the future, the compiler will take precedence" >&5 -echo "$as_me: WARNING: sys/time.h: in the future, the compiler will take precedence" >&2;} - ( - cat <<\_ASBOX -## ------------------------------------------ ## -## Report this to the AC_PACKAGE_NAME lists. ## -## ------------------------------------------ ## -_ASBOX - ) | - sed "s/^/$as_me: WARNING: /" >&2 - ;; -esac -echo "$as_me:$LINENO: checking for sys/time.h" >&5 -echo $ECHO_N "checking for sys/time.h... $ECHO_C" >&6 -if test "${ac_cv_header_sys_time_h+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - ac_cv_header_sys_time_h=$ac_header_preproc -fi -echo "$as_me:$LINENO: result: $ac_cv_header_sys_time_h" >&5 -echo "${ECHO_T}$ac_cv_header_sys_time_h" >&6 - -fi -if test $ac_cv_header_sys_time_h = yes; then - : -else - { { echo "$as_me:$LINENO: error: \"Mandatory header missing on your system\"" >&5 -echo "$as_me: error: \"Mandatory header missing on your system\"" >&2;} - { (exit 1); exit 1; }; } -fi - - -if test "${ac_cv_header_unistd_h+set}" = set; then - echo "$as_me:$LINENO: checking for unistd.h" >&5 -echo $ECHO_N "checking for unistd.h... $ECHO_C" >&6 -if test "${ac_cv_header_unistd_h+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -fi -echo "$as_me:$LINENO: result: $ac_cv_header_unistd_h" >&5 -echo "${ECHO_T}$ac_cv_header_unistd_h" >&6 -else - # Is the header compilable? -echo "$as_me:$LINENO: checking unistd.h usability" >&5 -echo $ECHO_N "checking unistd.h usability... $ECHO_C" >&6 -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -#include -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_header_compiler=yes -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_header_compiler=no -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -echo "$as_me:$LINENO: result: $ac_header_compiler" >&5 -echo "${ECHO_T}$ac_header_compiler" >&6 - -# Is the header present? -echo "$as_me:$LINENO: checking unistd.h presence" >&5 -echo $ECHO_N "checking unistd.h presence... $ECHO_C" >&6 -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -#include -_ACEOF -if { (eval echo "$as_me:$LINENO: \"$ac_cpp conftest.$ac_ext\"") >&5 - (eval $ac_cpp conftest.$ac_ext) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } >/dev/null; then - if test -s conftest.err; then - ac_cpp_err=$ac_c_preproc_warn_flag - ac_cpp_err=$ac_cpp_err$ac_c_werror_flag - else - ac_cpp_err= - fi -else - ac_cpp_err=yes -fi -if test -z "$ac_cpp_err"; then - ac_header_preproc=yes -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - - ac_header_preproc=no -fi -rm -f conftest.err conftest.$ac_ext -echo "$as_me:$LINENO: result: $ac_header_preproc" >&5 -echo "${ECHO_T}$ac_header_preproc" >&6 - -# So? What about this header? -case $ac_header_compiler:$ac_header_preproc:$ac_c_preproc_warn_flag in - yes:no: ) - { echo "$as_me:$LINENO: WARNING: unistd.h: accepted by the compiler, rejected by the preprocessor!" >&5 -echo "$as_me: WARNING: unistd.h: accepted by the compiler, rejected by the preprocessor!" >&2;} - { echo "$as_me:$LINENO: WARNING: unistd.h: proceeding with the compiler's result" >&5 -echo "$as_me: WARNING: unistd.h: proceeding with the compiler's result" >&2;} - ac_header_preproc=yes - ;; - no:yes:* ) - { echo "$as_me:$LINENO: WARNING: unistd.h: present but cannot be compiled" >&5 -echo "$as_me: WARNING: unistd.h: present but cannot be compiled" >&2;} - { echo "$as_me:$LINENO: WARNING: unistd.h: check for missing prerequisite headers?" >&5 -echo "$as_me: WARNING: unistd.h: check for missing prerequisite headers?" >&2;} - { echo "$as_me:$LINENO: WARNING: unistd.h: see the Autoconf documentation" >&5 -echo "$as_me: WARNING: unistd.h: see the Autoconf documentation" >&2;} - { echo "$as_me:$LINENO: WARNING: unistd.h: section \"Present But Cannot Be Compiled\"" >&5 -echo "$as_me: WARNING: unistd.h: section \"Present But Cannot Be Compiled\"" >&2;} - { echo "$as_me:$LINENO: WARNING: unistd.h: proceeding with the preprocessor's result" >&5 -echo "$as_me: WARNING: unistd.h: proceeding with the preprocessor's result" >&2;} - { echo "$as_me:$LINENO: WARNING: unistd.h: in the future, the compiler will take precedence" >&5 -echo "$as_me: WARNING: unistd.h: in the future, the compiler will take precedence" >&2;} - ( - cat <<\_ASBOX -## ------------------------------------------ ## -## Report this to the AC_PACKAGE_NAME lists. ## -## ------------------------------------------ ## -_ASBOX - ) | - sed "s/^/$as_me: WARNING: /" >&2 - ;; -esac -echo "$as_me:$LINENO: checking for unistd.h" >&5 -echo $ECHO_N "checking for unistd.h... $ECHO_C" >&6 -if test "${ac_cv_header_unistd_h+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - ac_cv_header_unistd_h=$ac_header_preproc -fi -echo "$as_me:$LINENO: result: $ac_cv_header_unistd_h" >&5 -echo "${ECHO_T}$ac_cv_header_unistd_h" >&6 - -fi -if test $ac_cv_header_unistd_h = yes; then - : -else - { { echo "$as_me:$LINENO: error: \"Mandatory header missing on your system\"" >&5 -echo "$as_me: error: \"Mandatory header missing on your system\"" >&2;} - { (exit 1); exit 1; }; } -fi - - - - -echo "$as_me:$LINENO: checking if libnsl is mandatory" >&5 -echo $ECHO_N "checking if libnsl is mandatory... $ECHO_C" >&6 -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -#include - #include - #include - #include - union - { - HEADER hdr; - u_char buf[4096]; /* With RFC 2671, otherwise 512 is enough */ - } - response; - char *domain; - int requested_type; -int -main () -{ -res_query(domain, - C_IN, - requested_type, - (u_char *) & response, - sizeof (response)) - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext conftest$ac_exeext -if { (eval echo "$as_me:$LINENO: \"$ac_link\"") >&5 - (eval $ac_link) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest$ac_exeext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - echo "$as_me:$LINENO: result: no" >&5 -echo "${ECHO_T}no" >&6 -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - - echo "$as_me:$LINENO: result: yes" >&5 -echo "${ECHO_T}yes" >&6; LIBS="${LIBS} -lnsl" -fi -rm -f conftest.err conftest.$ac_objext \ - conftest$ac_exeext conftest.$ac_ext - -echo "$as_me:$LINENO: checking loc_ntoa" >&5 -echo $ECHO_N "checking loc_ntoa... $ECHO_C" >&6 -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -#include -int -main () -{ - u_char *cp; char *result; loc_ntoa(cp, result) - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext conftest$ac_exeext -if { (eval echo "$as_me:$LINENO: \"$ac_link\"") >&5 - (eval $ac_link) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest$ac_exeext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - echo "$as_me:$LINENO: result: yes" >&5 -echo "${ECHO_T}yes" >&6; cat >>confdefs.h <<\_ACEOF -#define HAVE_LOC_NTOA 1 -_ACEOF - -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - - echo "$as_me:$LINENO: result: no, using the alternative" >&5 -echo "${ECHO_T}no, using the alternative" >&6; LOC_NTOA=loc_ntoa.o -fi -rm -f conftest.err conftest.$ac_objext \ - conftest$ac_exeext conftest.$ac_ext - - -echo "$as_me:$LINENO: checking for an ANSI C-conforming const" >&5 -echo $ECHO_N "checking for an ANSI C-conforming const... $ECHO_C" >&6 -if test "${ac_cv_c_const+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ - -int -main () -{ -/* FIXME: Include the comments suggested by Paul. */ -#ifndef __cplusplus - /* Ultrix mips cc rejects this. */ - typedef int charset[2]; - const charset x; - /* SunOS 4.1.1 cc rejects this. */ - char const *const *ccp; - char **p; - /* NEC SVR4.0.2 mips cc rejects this. */ - struct point {int x, y;}; - static struct point const zero = {0,0}; - /* AIX XL C 1.02.0.0 rejects this. - It does not let you subtract one const X* pointer from another in - an arm of an if-expression whose if-part is not a constant - expression */ - const char *g = "string"; - ccp = &g + (g ? g-g : 0); - /* HPUX 7.0 cc rejects these. */ - ++ccp; - p = (char**) ccp; - ccp = (char const *const *) p; - { /* SCO 3.2v4 cc rejects this. */ - char *t; - char const *s = 0 ? (char *) 0 : (char const *) 0; - - *t++ = 0; - } - { /* Someone thinks the Sun supposedly-ANSI compiler will reject this. */ - int x[] = {25, 17}; - const int *foo = &x[0]; - ++foo; - } - { /* Sun SC1.0 ANSI compiler rejects this -- but not the above. */ - typedef const int *iptr; - iptr p = 0; - ++p; - } - { /* AIX XL C 1.02.0.0 rejects this saying - "k.c", line 2.27: 1506-025 (S) Operand must be a modifiable lvalue. */ - struct s { int j; const int *ap[3]; }; - struct s *b; b->j = 5; - } - { /* ULTRIX-32 V3.1 (Rev 9) vcc rejects this */ - const int foo = 10; - } -#endif - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_cv_c_const=yes -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_cv_c_const=no -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -fi -echo "$as_me:$LINENO: result: $ac_cv_c_const" >&5 -echo "${ECHO_T}$ac_cv_c_const" >&6 -if test $ac_cv_c_const = no; then - -cat >>confdefs.h <<\_ACEOF -#define const -_ACEOF - -fi - -echo "$as_me:$LINENO: checking for long" >&5 -echo $ECHO_N "checking for long... $ECHO_C" >&6 -if test "${ac_cv_type_long+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -if ((long *) 0) - return 0; -if (sizeof (long)) - return 0; - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_cv_type_long=yes -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_cv_type_long=no -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -fi -echo "$as_me:$LINENO: result: $ac_cv_type_long" >&5 -echo "${ECHO_T}$ac_cv_type_long" >&6 - -echo "$as_me:$LINENO: checking size of long" >&5 -echo $ECHO_N "checking size of long... $ECHO_C" >&6 -if test "${ac_cv_sizeof_long+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - if test "$ac_cv_type_long" = yes; then - # The cast to unsigned long works around a bug in the HP C Compiler - # version HP92453-01 B.11.11.23709.GP, which incorrectly rejects - # declarations like `int a3[[(sizeof (unsigned char)) >= 0]];'. - # This bug is HP SR number 8606223364. - if test "$cross_compiling" = yes; then - # Depending upon the size, compute the lo and hi bounds. -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -static int test_array [1 - 2 * !(((long) (sizeof (long))) >= 0)]; -test_array [0] = 0 - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_lo=0 ac_mid=0 - while :; do - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -static int test_array [1 - 2 * !(((long) (sizeof (long))) <= $ac_mid)]; -test_array [0] = 0 - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_hi=$ac_mid; break -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_lo=`expr $ac_mid + 1` - if test $ac_lo -le $ac_mid; then - ac_lo= ac_hi= - break - fi - ac_mid=`expr 2 '*' $ac_mid + 1` -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext - done -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -static int test_array [1 - 2 * !(((long) (sizeof (long))) < 0)]; -test_array [0] = 0 - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_hi=-1 ac_mid=-1 - while :; do - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -static int test_array [1 - 2 * !(((long) (sizeof (long))) >= $ac_mid)]; -test_array [0] = 0 - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_lo=$ac_mid; break -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_hi=`expr '(' $ac_mid ')' - 1` - if test $ac_mid -le $ac_hi; then - ac_lo= ac_hi= - break - fi - ac_mid=`expr 2 '*' $ac_mid` -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext - done -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_lo= ac_hi= -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -# Binary search between lo and hi bounds. -while test "x$ac_lo" != "x$ac_hi"; do - ac_mid=`expr '(' $ac_hi - $ac_lo ')' / 2 + $ac_lo` - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -static int test_array [1 - 2 * !(((long) (sizeof (long))) <= $ac_mid)]; -test_array [0] = 0 - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_hi=$ac_mid -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_lo=`expr '(' $ac_mid ')' + 1` -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -done -case $ac_lo in -?*) ac_cv_sizeof_long=$ac_lo;; -'') { { echo "$as_me:$LINENO: error: cannot compute sizeof (long), 77 -See \`config.log' for more details." >&5 -echo "$as_me: error: cannot compute sizeof (long), 77 -See \`config.log' for more details." >&2;} - { (exit 1); exit 1; }; } ;; -esac -else - if test "$cross_compiling" = yes; then - { { echo "$as_me:$LINENO: error: internal error: not reached in cross-compile" >&5 -echo "$as_me: error: internal error: not reached in cross-compile" >&2;} - { (exit 1); exit 1; }; } -else - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -long longval () { return (long) (sizeof (long)); } -unsigned long ulongval () { return (long) (sizeof (long)); } -#include -#include -int -main () -{ - - FILE *f = fopen ("conftest.val", "w"); - if (! f) - exit (1); - if (((long) (sizeof (long))) < 0) - { - long i = longval (); - if (i != ((long) (sizeof (long)))) - exit (1); - fprintf (f, "%ld\n", i); - } - else - { - unsigned long i = ulongval (); - if (i != ((long) (sizeof (long)))) - exit (1); - fprintf (f, "%lu\n", i); - } - exit (ferror (f) || fclose (f) != 0); - - ; - return 0; -} -_ACEOF -rm -f conftest$ac_exeext -if { (eval echo "$as_me:$LINENO: \"$ac_link\"") >&5 - (eval $ac_link) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && { ac_try='./conftest$ac_exeext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_cv_sizeof_long=`cat conftest.val` -else - echo "$as_me: program exited with status $ac_status" >&5 -echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -( exit $ac_status ) -{ { echo "$as_me:$LINENO: error: cannot compute sizeof (long), 77 -See \`config.log' for more details." >&5 -echo "$as_me: error: cannot compute sizeof (long), 77 -See \`config.log' for more details." >&2;} - { (exit 1); exit 1; }; } -fi -rm -f core *.core gmon.out bb.out conftest$ac_exeext conftest.$ac_objext conftest.$ac_ext -fi -fi -rm -f conftest.val -else - ac_cv_sizeof_long=0 -fi -fi -echo "$as_me:$LINENO: result: $ac_cv_sizeof_long" >&5 -echo "${ECHO_T}$ac_cv_sizeof_long" >&6 -cat >>confdefs.h <<_ACEOF -#define SIZEOF_LONG $ac_cv_sizeof_long -_ACEOF - - -echo "$as_me:$LINENO: checking for int" >&5 -echo $ECHO_N "checking for int... $ECHO_C" >&6 -if test "${ac_cv_type_int+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -if ((int *) 0) - return 0; -if (sizeof (int)) - return 0; - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_cv_type_int=yes -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_cv_type_int=no -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -fi -echo "$as_me:$LINENO: result: $ac_cv_type_int" >&5 -echo "${ECHO_T}$ac_cv_type_int" >&6 - -echo "$as_me:$LINENO: checking size of int" >&5 -echo $ECHO_N "checking size of int... $ECHO_C" >&6 -if test "${ac_cv_sizeof_int+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - if test "$ac_cv_type_int" = yes; then - # The cast to unsigned long works around a bug in the HP C Compiler - # version HP92453-01 B.11.11.23709.GP, which incorrectly rejects - # declarations like `int a3[[(sizeof (unsigned char)) >= 0]];'. - # This bug is HP SR number 8606223364. - if test "$cross_compiling" = yes; then - # Depending upon the size, compute the lo and hi bounds. -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -static int test_array [1 - 2 * !(((long) (sizeof (int))) >= 0)]; -test_array [0] = 0 - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_lo=0 ac_mid=0 - while :; do - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -static int test_array [1 - 2 * !(((long) (sizeof (int))) <= $ac_mid)]; -test_array [0] = 0 - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_hi=$ac_mid; break -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_lo=`expr $ac_mid + 1` - if test $ac_lo -le $ac_mid; then - ac_lo= ac_hi= - break - fi - ac_mid=`expr 2 '*' $ac_mid + 1` -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext - done -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -static int test_array [1 - 2 * !(((long) (sizeof (int))) < 0)]; -test_array [0] = 0 - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_hi=-1 ac_mid=-1 - while :; do - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -static int test_array [1 - 2 * !(((long) (sizeof (int))) >= $ac_mid)]; -test_array [0] = 0 - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_lo=$ac_mid; break -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_hi=`expr '(' $ac_mid ')' - 1` - if test $ac_mid -le $ac_hi; then - ac_lo= ac_hi= - break - fi - ac_mid=`expr 2 '*' $ac_mid` -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext - done -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_lo= ac_hi= -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -# Binary search between lo and hi bounds. -while test "x$ac_lo" != "x$ac_hi"; do - ac_mid=`expr '(' $ac_hi - $ac_lo ')' / 2 + $ac_lo` - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -static int test_array [1 - 2 * !(((long) (sizeof (int))) <= $ac_mid)]; -test_array [0] = 0 - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_hi=$ac_mid -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_lo=`expr '(' $ac_mid ')' + 1` -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -done -case $ac_lo in -?*) ac_cv_sizeof_int=$ac_lo;; -'') { { echo "$as_me:$LINENO: error: cannot compute sizeof (int), 77 -See \`config.log' for more details." >&5 -echo "$as_me: error: cannot compute sizeof (int), 77 -See \`config.log' for more details." >&2;} - { (exit 1); exit 1; }; } ;; -esac -else - if test "$cross_compiling" = yes; then - { { echo "$as_me:$LINENO: error: internal error: not reached in cross-compile" >&5 -echo "$as_me: error: internal error: not reached in cross-compile" >&2;} - { (exit 1); exit 1; }; } -else - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -long longval () { return (long) (sizeof (int)); } -unsigned long ulongval () { return (long) (sizeof (int)); } -#include -#include -int -main () -{ - - FILE *f = fopen ("conftest.val", "w"); - if (! f) - exit (1); - if (((long) (sizeof (int))) < 0) - { - long i = longval (); - if (i != ((long) (sizeof (int)))) - exit (1); - fprintf (f, "%ld\n", i); - } - else - { - unsigned long i = ulongval (); - if (i != ((long) (sizeof (int)))) - exit (1); - fprintf (f, "%lu\n", i); - } - exit (ferror (f) || fclose (f) != 0); - - ; - return 0; -} -_ACEOF -rm -f conftest$ac_exeext -if { (eval echo "$as_me:$LINENO: \"$ac_link\"") >&5 - (eval $ac_link) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && { ac_try='./conftest$ac_exeext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_cv_sizeof_int=`cat conftest.val` -else - echo "$as_me: program exited with status $ac_status" >&5 -echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -( exit $ac_status ) -{ { echo "$as_me:$LINENO: error: cannot compute sizeof (int), 77 -See \`config.log' for more details." >&5 -echo "$as_me: error: cannot compute sizeof (int), 77 -See \`config.log' for more details." >&2;} - { (exit 1); exit 1; }; } -fi -rm -f core *.core gmon.out bb.out conftest$ac_exeext conftest.$ac_objext conftest.$ac_ext -fi -fi -rm -f conftest.val -else - ac_cv_sizeof_int=0 -fi -fi -echo "$as_me:$LINENO: result: $ac_cv_sizeof_int" >&5 -echo "${ECHO_T}$ac_cv_sizeof_int" >&6 -cat >>confdefs.h <<_ACEOF -#define SIZEOF_INT $ac_cv_sizeof_int -_ACEOF - - -echo "$as_me:$LINENO: checking for short" >&5 -echo $ECHO_N "checking for short... $ECHO_C" >&6 -if test "${ac_cv_type_short+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -if ((short *) 0) - return 0; -if (sizeof (short)) - return 0; - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_cv_type_short=yes -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_cv_type_short=no -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -fi -echo "$as_me:$LINENO: result: $ac_cv_type_short" >&5 -echo "${ECHO_T}$ac_cv_type_short" >&6 - -echo "$as_me:$LINENO: checking size of short" >&5 -echo $ECHO_N "checking size of short... $ECHO_C" >&6 -if test "${ac_cv_sizeof_short+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - if test "$ac_cv_type_short" = yes; then - # The cast to unsigned long works around a bug in the HP C Compiler - # version HP92453-01 B.11.11.23709.GP, which incorrectly rejects - # declarations like `int a3[[(sizeof (unsigned char)) >= 0]];'. - # This bug is HP SR number 8606223364. - if test "$cross_compiling" = yes; then - # Depending upon the size, compute the lo and hi bounds. -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -static int test_array [1 - 2 * !(((long) (sizeof (short))) >= 0)]; -test_array [0] = 0 - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_lo=0 ac_mid=0 - while :; do - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -static int test_array [1 - 2 * !(((long) (sizeof (short))) <= $ac_mid)]; -test_array [0] = 0 - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_hi=$ac_mid; break -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_lo=`expr $ac_mid + 1` - if test $ac_lo -le $ac_mid; then - ac_lo= ac_hi= - break - fi - ac_mid=`expr 2 '*' $ac_mid + 1` -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext - done -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -static int test_array [1 - 2 * !(((long) (sizeof (short))) < 0)]; -test_array [0] = 0 - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_hi=-1 ac_mid=-1 - while :; do - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -static int test_array [1 - 2 * !(((long) (sizeof (short))) >= $ac_mid)]; -test_array [0] = 0 - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_lo=$ac_mid; break -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_hi=`expr '(' $ac_mid ')' - 1` - if test $ac_mid -le $ac_hi; then - ac_lo= ac_hi= - break - fi - ac_mid=`expr 2 '*' $ac_mid` -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext - done -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_lo= ac_hi= -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -# Binary search between lo and hi bounds. -while test "x$ac_lo" != "x$ac_hi"; do - ac_mid=`expr '(' $ac_hi - $ac_lo ')' / 2 + $ac_lo` - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -static int test_array [1 - 2 * !(((long) (sizeof (short))) <= $ac_mid)]; -test_array [0] = 0 - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_hi=$ac_mid -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_lo=`expr '(' $ac_mid ')' + 1` -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -done -case $ac_lo in -?*) ac_cv_sizeof_short=$ac_lo;; -'') { { echo "$as_me:$LINENO: error: cannot compute sizeof (short), 77 -See \`config.log' for more details." >&5 -echo "$as_me: error: cannot compute sizeof (short), 77 -See \`config.log' for more details." >&2;} - { (exit 1); exit 1; }; } ;; -esac -else - if test "$cross_compiling" = yes; then - { { echo "$as_me:$LINENO: error: internal error: not reached in cross-compile" >&5 -echo "$as_me: error: internal error: not reached in cross-compile" >&2;} - { (exit 1); exit 1; }; } -else - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -long longval () { return (long) (sizeof (short)); } -unsigned long ulongval () { return (long) (sizeof (short)); } -#include -#include -int -main () -{ - - FILE *f = fopen ("conftest.val", "w"); - if (! f) - exit (1); - if (((long) (sizeof (short))) < 0) - { - long i = longval (); - if (i != ((long) (sizeof (short)))) - exit (1); - fprintf (f, "%ld\n", i); - } - else - { - unsigned long i = ulongval (); - if (i != ((long) (sizeof (short)))) - exit (1); - fprintf (f, "%lu\n", i); - } - exit (ferror (f) || fclose (f) != 0); - - ; - return 0; -} -_ACEOF -rm -f conftest$ac_exeext -if { (eval echo "$as_me:$LINENO: \"$ac_link\"") >&5 - (eval $ac_link) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && { ac_try='./conftest$ac_exeext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_cv_sizeof_short=`cat conftest.val` -else - echo "$as_me: program exited with status $ac_status" >&5 -echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -( exit $ac_status ) -{ { echo "$as_me:$LINENO: error: cannot compute sizeof (short), 77 -See \`config.log' for more details." >&5 -echo "$as_me: error: cannot compute sizeof (short), 77 -See \`config.log' for more details." >&2;} - { (exit 1); exit 1; }; } -fi -rm -f core *.core gmon.out bb.out conftest$ac_exeext conftest.$ac_objext conftest.$ac_ext -fi -fi -rm -f conftest.val -else - ac_cv_sizeof_short=0 -fi -fi -echo "$as_me:$LINENO: result: $ac_cv_sizeof_short" >&5 -echo "${ECHO_T}$ac_cv_sizeof_short" >&6 -cat >>confdefs.h <<_ACEOF -#define SIZEOF_SHORT $ac_cv_sizeof_short -_ACEOF - - -echo "$as_me:$LINENO: checking for char" >&5 -echo $ECHO_N "checking for char... $ECHO_C" >&6 -if test "${ac_cv_type_char+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -if ((char *) 0) - return 0; -if (sizeof (char)) - return 0; - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_cv_type_char=yes -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_cv_type_char=no -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -fi -echo "$as_me:$LINENO: result: $ac_cv_type_char" >&5 -echo "${ECHO_T}$ac_cv_type_char" >&6 - -echo "$as_me:$LINENO: checking size of char" >&5 -echo $ECHO_N "checking size of char... $ECHO_C" >&6 -if test "${ac_cv_sizeof_char+set}" = set; then - echo $ECHO_N "(cached) $ECHO_C" >&6 -else - if test "$ac_cv_type_char" = yes; then - # The cast to unsigned long works around a bug in the HP C Compiler - # version HP92453-01 B.11.11.23709.GP, which incorrectly rejects - # declarations like `int a3[[(sizeof (unsigned char)) >= 0]];'. - # This bug is HP SR number 8606223364. - if test "$cross_compiling" = yes; then - # Depending upon the size, compute the lo and hi bounds. -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -static int test_array [1 - 2 * !(((long) (sizeof (char))) >= 0)]; -test_array [0] = 0 - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_lo=0 ac_mid=0 - while :; do - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -static int test_array [1 - 2 * !(((long) (sizeof (char))) <= $ac_mid)]; -test_array [0] = 0 - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_hi=$ac_mid; break -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_lo=`expr $ac_mid + 1` - if test $ac_lo -le $ac_mid; then - ac_lo= ac_hi= - break - fi - ac_mid=`expr 2 '*' $ac_mid + 1` -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext - done -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -static int test_array [1 - 2 * !(((long) (sizeof (char))) < 0)]; -test_array [0] = 0 - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_hi=-1 ac_mid=-1 - while :; do - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -static int test_array [1 - 2 * !(((long) (sizeof (char))) >= $ac_mid)]; -test_array [0] = 0 - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_lo=$ac_mid; break -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_hi=`expr '(' $ac_mid ')' - 1` - if test $ac_mid -le $ac_hi; then - ac_lo= ac_hi= - break - fi - ac_mid=`expr 2 '*' $ac_mid` -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext - done -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_lo= ac_hi= -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -# Binary search between lo and hi bounds. -while test "x$ac_lo" != "x$ac_hi"; do - ac_mid=`expr '(' $ac_hi - $ac_lo ')' / 2 + $ac_lo` - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -int -main () -{ -static int test_array [1 - 2 * !(((long) (sizeof (char))) <= $ac_mid)]; -test_array [0] = 0 - - ; - return 0; -} -_ACEOF -rm -f conftest.$ac_objext -if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 - (eval $ac_compile) 2>conftest.er1 - ac_status=$? - grep -v '^ *+' conftest.er1 >conftest.err - rm -f conftest.er1 - cat conftest.err >&5 - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && - { ac_try='test -z "$ac_c_werror_flag" || test ! -s conftest.err' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; } && - { ac_try='test -s conftest.$ac_objext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_hi=$ac_mid -else - echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -ac_lo=`expr '(' $ac_mid ')' + 1` -fi -rm -f conftest.err conftest.$ac_objext conftest.$ac_ext -done -case $ac_lo in -?*) ac_cv_sizeof_char=$ac_lo;; -'') { { echo "$as_me:$LINENO: error: cannot compute sizeof (char), 77 -See \`config.log' for more details." >&5 -echo "$as_me: error: cannot compute sizeof (char), 77 -See \`config.log' for more details." >&2;} - { (exit 1); exit 1; }; } ;; -esac -else - if test "$cross_compiling" = yes; then - { { echo "$as_me:$LINENO: error: internal error: not reached in cross-compile" >&5 -echo "$as_me: error: internal error: not reached in cross-compile" >&2;} - { (exit 1); exit 1; }; } -else - cat >conftest.$ac_ext <<_ACEOF -/* confdefs.h. */ -_ACEOF -cat confdefs.h >>conftest.$ac_ext -cat >>conftest.$ac_ext <<_ACEOF -/* end confdefs.h. */ -$ac_includes_default -long longval () { return (long) (sizeof (char)); } -unsigned long ulongval () { return (long) (sizeof (char)); } -#include -#include -int -main () -{ - - FILE *f = fopen ("conftest.val", "w"); - if (! f) - exit (1); - if (((long) (sizeof (char))) < 0) - { - long i = longval (); - if (i != ((long) (sizeof (char)))) - exit (1); - fprintf (f, "%ld\n", i); - } - else - { - unsigned long i = ulongval (); - if (i != ((long) (sizeof (char)))) - exit (1); - fprintf (f, "%lu\n", i); - } - exit (ferror (f) || fclose (f) != 0); - - ; - return 0; -} -_ACEOF -rm -f conftest$ac_exeext -if { (eval echo "$as_me:$LINENO: \"$ac_link\"") >&5 - (eval $ac_link) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); } && { ac_try='./conftest$ac_exeext' - { (eval echo "$as_me:$LINENO: \"$ac_try\"") >&5 - (eval $ac_try) 2>&5 - ac_status=$? - echo "$as_me:$LINENO: \$? = $ac_status" >&5 - (exit $ac_status); }; }; then - ac_cv_sizeof_char=`cat conftest.val` -else - echo "$as_me: program exited with status $ac_status" >&5 -echo "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - -( exit $ac_status ) -{ { echo "$as_me:$LINENO: error: cannot compute sizeof (char), 77 -See \`config.log' for more details." >&5 -echo "$as_me: error: cannot compute sizeof (char), 77 -See \`config.log' for more details." >&2;} - { (exit 1); exit 1; }; } -fi -rm -f core *.core gmon.out bb.out conftest$ac_exeext conftest.$ac_objext conftest.$ac_ext -fi -fi -rm -f conftest.val -else - ac_cv_sizeof_char=0 -fi -fi -echo "$as_me:$LINENO: result: $ac_cv_sizeof_char" >&5 -echo "${ECHO_T}$ac_cv_sizeof_char" >&6 -cat >>confdefs.h <<_ACEOF -#define SIZEOF_CHAR $ac_cv_sizeof_char -_ACEOF - - - - ac_config_files="$ac_config_files Makefile" -cat >confcache <<\_ACEOF -# This file is a shell script that caches the results of configure -# tests run on this system so they can be shared between configure -# scripts and configure runs, see configure's option --config-cache. -# It is not useful on other systems. If it contains results you don't -# want to keep, you may remove or edit it. -# -# config.status only pays attention to the cache file if you give it -# the --recheck option to rerun configure. -# -# `ac_cv_env_foo' variables (set or unset) will be overridden when -# loading this file, other *unset* `ac_cv_foo' will be assigned the -# following values. - -_ACEOF - -# The following way of writing the cache mishandles newlines in values, -# but we know of no workaround that is simple, portable, and efficient. -# So, don't put newlines in cache variables' values. -# Ultrix sh set writes to stderr and can't be redirected directly, -# and sets the high bit in the cache file unless we assign to the vars. -{ - (set) 2>&1 | - case `(ac_space=' '; set | grep ac_space) 2>&1` in - *ac_space=\ *) - # `set' does not quote correctly, so add quotes (double-quote - # substitution turns \\\\ into \\, and sed turns \\ into \). - sed -n \ - "s/'/'\\\\''/g; - s/^\\([_$as_cr_alnum]*_cv_[_$as_cr_alnum]*\\)=\\(.*\\)/\\1='\\2'/p" - ;; - *) - # `set' quotes correctly as required by POSIX, so do not add quotes. - sed -n \ - "s/^\\([_$as_cr_alnum]*_cv_[_$as_cr_alnum]*\\)=\\(.*\\)/\\1=\\2/p" - ;; - esac; -} | - sed ' - t clear - : clear - s/^\([^=]*\)=\(.*[{}].*\)$/test "${\1+set}" = set || &/ - t end - /^ac_cv_env/!s/^\([^=]*\)=\(.*\)$/\1=${\1=\2}/ - : end' >>confcache -if diff $cache_file confcache >/dev/null 2>&1; then :; else - if test -w $cache_file; then - test "x$cache_file" != "x/dev/null" && echo "updating cache $cache_file" - cat confcache >$cache_file - else - echo "not updating unwritable cache $cache_file" - fi -fi -rm -f confcache - -test "x$prefix" = xNONE && prefix=$ac_default_prefix -# Let make expand exec_prefix. -test "x$exec_prefix" = xNONE && exec_prefix='${prefix}' - -# VPATH may cause trouble with some makes, so we remove $(srcdir), -# ${srcdir} and @srcdir@ from VPATH if srcdir is ".", strip leading and -# trailing colons and then remove the whole line if VPATH becomes empty -# (actually we leave an empty line to preserve line numbers). -if test "x$srcdir" = x.; then - ac_vpsub='/^[ ]*VPATH[ ]*=/{ -s/:*\$(srcdir):*/:/; -s/:*\${srcdir}:*/:/; -s/:*@srcdir@:*/:/; -s/^\([^=]*=[ ]*\):*/\1/; -s/:*$//; -s/^[^=]*=[ ]*$//; -}' -fi - -DEFS=-DHAVE_CONFIG_H - -ac_libobjs= -ac_ltlibobjs= -for ac_i in : $LIBOBJS; do test "x$ac_i" = x: && continue - # 1. Remove the extension, and $U if already installed. - ac_i=`echo "$ac_i" | - sed 's/\$U\././;s/\.o$//;s/\.obj$//'` - # 2. Add them. - ac_libobjs="$ac_libobjs $ac_i\$U.$ac_objext" - ac_ltlibobjs="$ac_ltlibobjs $ac_i"'$U.lo' -done -LIBOBJS=$ac_libobjs - -LTLIBOBJS=$ac_ltlibobjs - - - -: ${CONFIG_STATUS=./config.status} -ac_clean_files_save=$ac_clean_files -ac_clean_files="$ac_clean_files $CONFIG_STATUS" -{ echo "$as_me:$LINENO: creating $CONFIG_STATUS" >&5 -echo "$as_me: creating $CONFIG_STATUS" >&6;} -cat >$CONFIG_STATUS <<_ACEOF -#! $SHELL -# Generated by $as_me. -# Run this file to recreate the current configuration. -# Compiler output produced by configure, useful for debugging -# configure, is in config.log if it exists. - -debug=false -ac_cs_recheck=false -ac_cs_silent=false -SHELL=\${CONFIG_SHELL-$SHELL} -_ACEOF - -cat >>$CONFIG_STATUS <<\_ACEOF -## --------------------- ## -## M4sh Initialization. ## -## --------------------- ## - -# Be Bourne compatible -if test -n "${ZSH_VERSION+set}" && (emulate sh) >/dev/null 2>&1; then - emulate sh - NULLCMD=: - # Zsh 3.x and 4.x performs word splitting on ${1+"$@"}, which - # is contrary to our usage. Disable this feature. - alias -g '${1+"$@"}'='"$@"' -elif test -n "${BASH_VERSION+set}" && (set -o posix) >/dev/null 2>&1; then - set -o posix -fi -DUALCASE=1; export DUALCASE # for MKS sh - -# Support unset when possible. -if ( (MAIL=60; unset MAIL) || exit) >/dev/null 2>&1; then - as_unset=unset -else - as_unset=false -fi - - -# Work around bugs in pre-3.0 UWIN ksh. -$as_unset ENV MAIL MAILPATH -PS1='$ ' -PS2='> ' -PS4='+ ' - -# NLS nuisances. -for as_var in \ - LANG LANGUAGE LC_ADDRESS LC_ALL LC_COLLATE LC_CTYPE LC_IDENTIFICATION \ - LC_MEASUREMENT LC_MESSAGES LC_MONETARY LC_NAME LC_NUMERIC LC_PAPER \ - LC_TELEPHONE LC_TIME -do - if (set +x; test -z "`(eval $as_var=C; export $as_var) 2>&1`"); then - eval $as_var=C; export $as_var - else - $as_unset $as_var - fi -done - -# Required to use basename. -if expr a : '\(a\)' >/dev/null 2>&1; then - as_expr=expr -else - as_expr=false -fi - -if (basename /) >/dev/null 2>&1 && test "X`basename / 2>&1`" = "X/"; then - as_basename=basename -else - as_basename=false -fi - - -# Name of the executable. -as_me=`$as_basename "$0" || -$as_expr X/"$0" : '.*/\([^/][^/]*\)/*$' \| \ - X"$0" : 'X\(//\)$' \| \ - X"$0" : 'X\(/\)$' \| \ - . : '\(.\)' 2>/dev/null || -echo X/"$0" | - sed '/^.*\/\([^/][^/]*\)\/*$/{ s//\1/; q; } - /^X\/\(\/\/\)$/{ s//\1/; q; } - /^X\/\(\/\).*/{ s//\1/; q; } - s/.*/./; q'` - - -# PATH needs CR, and LINENO needs CR and PATH. -# Avoid depending upon Character Ranges. -as_cr_letters='abcdefghijklmnopqrstuvwxyz' -as_cr_LETTERS='ABCDEFGHIJKLMNOPQRSTUVWXYZ' -as_cr_Letters=$as_cr_letters$as_cr_LETTERS -as_cr_digits='0123456789' -as_cr_alnum=$as_cr_Letters$as_cr_digits - -# The user is always right. -if test "${PATH_SEPARATOR+set}" != set; then - echo "#! /bin/sh" >conf$$.sh - echo "exit 0" >>conf$$.sh - chmod +x conf$$.sh - if (PATH="/nonexistent;."; conf$$.sh) >/dev/null 2>&1; then - PATH_SEPARATOR=';' - else - PATH_SEPARATOR=: - fi - rm -f conf$$.sh -fi - - - as_lineno_1=$LINENO - as_lineno_2=$LINENO - as_lineno_3=`(expr $as_lineno_1 + 1) 2>/dev/null` - test "x$as_lineno_1" != "x$as_lineno_2" && - test "x$as_lineno_3" = "x$as_lineno_2" || { - # Find who we are. Look in the path if we contain no path at all - # relative or not. - case $0 in - *[\\/]* ) as_myself=$0 ;; - *) as_save_IFS=$IFS; IFS=$PATH_SEPARATOR -for as_dir in $PATH -do - IFS=$as_save_IFS - test -z "$as_dir" && as_dir=. - test -r "$as_dir/$0" && as_myself=$as_dir/$0 && break -done - - ;; - esac - # We did not find ourselves, most probably we were run as `sh COMMAND' - # in which case we are not to be found in the path. - if test "x$as_myself" = x; then - as_myself=$0 - fi - if test ! -f "$as_myself"; then - { { echo "$as_me:$LINENO: error: cannot find myself; rerun with an absolute path" >&5 -echo "$as_me: error: cannot find myself; rerun with an absolute path" >&2;} - { (exit 1); exit 1; }; } - fi - case $CONFIG_SHELL in - '') - as_save_IFS=$IFS; IFS=$PATH_SEPARATOR -for as_dir in /bin$PATH_SEPARATOR/usr/bin$PATH_SEPARATOR$PATH -do - IFS=$as_save_IFS - test -z "$as_dir" && as_dir=. - for as_base in sh bash ksh sh5; do - case $as_dir in - /*) - if ("$as_dir/$as_base" -c ' - as_lineno_1=$LINENO - as_lineno_2=$LINENO - as_lineno_3=`(expr $as_lineno_1 + 1) 2>/dev/null` - test "x$as_lineno_1" != "x$as_lineno_2" && - test "x$as_lineno_3" = "x$as_lineno_2" ') 2>/dev/null; then - $as_unset BASH_ENV || test "${BASH_ENV+set}" != set || { BASH_ENV=; export BASH_ENV; } - $as_unset ENV || test "${ENV+set}" != set || { ENV=; export ENV; } - CONFIG_SHELL=$as_dir/$as_base - export CONFIG_SHELL - exec "$CONFIG_SHELL" "$0" ${1+"$@"} - fi;; - esac - done -done -;; - esac - - # Create $as_me.lineno as a copy of $as_myself, but with $LINENO - # uniformly replaced by the line number. The first 'sed' inserts a - # line-number line before each line; the second 'sed' does the real - # work. The second script uses 'N' to pair each line-number line - # with the numbered line, and appends trailing '-' during - # substitution so that $LINENO is not a special case at line end. - # (Raja R Harinath suggested sed '=', and Paul Eggert wrote the - # second 'sed' script. Blame Lee E. McMahon for sed's syntax. :-) - sed '=' <$as_myself | - sed ' - N - s,$,-, - : loop - s,^\(['$as_cr_digits']*\)\(.*\)[$]LINENO\([^'$as_cr_alnum'_]\),\1\2\1\3, - t loop - s,-$,, - s,^['$as_cr_digits']*\n,, - ' >$as_me.lineno && - chmod +x $as_me.lineno || - { { echo "$as_me:$LINENO: error: cannot create $as_me.lineno; rerun with a POSIX shell" >&5 -echo "$as_me: error: cannot create $as_me.lineno; rerun with a POSIX shell" >&2;} - { (exit 1); exit 1; }; } - - # Don't try to exec as it changes $[0], causing all sort of problems - # (the dirname of $[0] is not the place where we might find the - # original and so on. Autoconf is especially sensible to this). - . ./$as_me.lineno - # Exit status is that of the last command. - exit -} - - -case `echo "testing\c"; echo 1,2,3`,`echo -n testing; echo 1,2,3` in - *c*,-n*) ECHO_N= ECHO_C=' -' ECHO_T=' ' ;; - *c*,* ) ECHO_N=-n ECHO_C= ECHO_T= ;; - *) ECHO_N= ECHO_C='\c' ECHO_T= ;; -esac - -if expr a : '\(a\)' >/dev/null 2>&1; then - as_expr=expr -else - as_expr=false -fi - -rm -f conf$$ conf$$.exe conf$$.file -echo >conf$$.file -if ln -s conf$$.file conf$$ 2>/dev/null; then - # We could just check for DJGPP; but this test a) works b) is more generic - # and c) will remain valid once DJGPP supports symlinks (DJGPP 2.04). - if test -f conf$$.exe; then - # Don't use ln at all; we don't have any links - as_ln_s='cp -p' - else - as_ln_s='ln -s' - fi -elif ln conf$$.file conf$$ 2>/dev/null; then - as_ln_s=ln -else - as_ln_s='cp -p' -fi -rm -f conf$$ conf$$.exe conf$$.file - -if mkdir -p . 2>/dev/null; then - as_mkdir_p=: -else - test -d ./-p && rmdir ./-p - as_mkdir_p=false -fi - -as_executable_p="test -f" - -# Sed expression to map a string onto a valid CPP name. -as_tr_cpp="eval sed 'y%*$as_cr_letters%P$as_cr_LETTERS%;s%[^_$as_cr_alnum]%_%g'" - -# Sed expression to map a string onto a valid variable name. -as_tr_sh="eval sed 'y%*+%pp%;s%[^_$as_cr_alnum]%_%g'" - - -# IFS -# We need space, tab and new line, in precisely that order. -as_nl=' -' -IFS=" $as_nl" - -# CDPATH. -$as_unset CDPATH - -exec 6>&1 - -# Open the log real soon, to keep \$[0] and so on meaningful, and to -# report actual input values of CONFIG_FILES etc. instead of their -# values after options handling. Logging --version etc. is OK. -exec 5>>config.log -{ - echo - sed 'h;s/./-/g;s/^.../## /;s/...$/ ##/;p;x;p;x' <<_ASBOX -## Running $as_me. ## -_ASBOX -} >&5 -cat >&5 <<_CSEOF - -This file was extended by $as_me, which was -generated by GNU Autoconf 2.59. Invocation command line was - - CONFIG_FILES = $CONFIG_FILES - CONFIG_HEADERS = $CONFIG_HEADERS - CONFIG_LINKS = $CONFIG_LINKS - CONFIG_COMMANDS = $CONFIG_COMMANDS - $ $0 $@ - -_CSEOF -echo "on `(hostname || uname -n) 2>/dev/null | sed 1q`" >&5 -echo >&5 -_ACEOF - -# Files that config.status was made for. -if test -n "$ac_config_files"; then - echo "config_files=\"$ac_config_files\"" >>$CONFIG_STATUS -fi - -if test -n "$ac_config_headers"; then - echo "config_headers=\"$ac_config_headers\"" >>$CONFIG_STATUS -fi - -if test -n "$ac_config_links"; then - echo "config_links=\"$ac_config_links\"" >>$CONFIG_STATUS -fi - -if test -n "$ac_config_commands"; then - echo "config_commands=\"$ac_config_commands\"" >>$CONFIG_STATUS -fi - -cat >>$CONFIG_STATUS <<\_ACEOF - -ac_cs_usage="\ -\`$as_me' instantiates files from templates according to the -current configuration. - -Usage: $0 [OPTIONS] [FILE]... - - -h, --help print this help, then exit - -V, --version print version number, then exit - -q, --quiet do not print progress messages - -d, --debug don't remove temporary files - --recheck update $as_me by reconfiguring in the same conditions - --file=FILE[:TEMPLATE] - instantiate the configuration file FILE - --header=FILE[:TEMPLATE] - instantiate the configuration header FILE - -Configuration files: -$config_files - -Configuration headers: -$config_headers - -Report bugs to ." -_ACEOF - -cat >>$CONFIG_STATUS <<_ACEOF -ac_cs_version="\\ -config.status -configured by $0, generated by GNU Autoconf 2.59, - with options \\"`echo "$ac_configure_args" | sed 's/[\\""\`\$]/\\\\&/g'`\\" - -Copyright (C) 2003 Free Software Foundation, Inc. -This config.status script is free software; the Free Software Foundation -gives unlimited permission to copy, distribute and modify it." -srcdir=$srcdir -INSTALL="$INSTALL" -_ACEOF - -cat >>$CONFIG_STATUS <<\_ACEOF -# If no file are specified by the user, then we need to provide default -# value. By we need to know if files were specified by the user. -ac_need_defaults=: -while test $# != 0 -do - case $1 in - --*=*) - ac_option=`expr "x$1" : 'x\([^=]*\)='` - ac_optarg=`expr "x$1" : 'x[^=]*=\(.*\)'` - ac_shift=: - ;; - -*) - ac_option=$1 - ac_optarg=$2 - ac_shift=shift - ;; - *) # This is not an option, so the user has probably given explicit - # arguments. - ac_option=$1 - ac_need_defaults=false;; - esac - - case $ac_option in - # Handling of the options. -_ACEOF -cat >>$CONFIG_STATUS <<\_ACEOF - -recheck | --recheck | --rechec | --reche | --rech | --rec | --re | --r) - ac_cs_recheck=: ;; - --version | --vers* | -V ) - echo "$ac_cs_version"; exit 0 ;; - --he | --h) - # Conflict between --help and --header - { { echo "$as_me:$LINENO: error: ambiguous option: $1 -Try \`$0 --help' for more information." >&5 -echo "$as_me: error: ambiguous option: $1 -Try \`$0 --help' for more information." >&2;} - { (exit 1); exit 1; }; };; - --help | --hel | -h ) - echo "$ac_cs_usage"; exit 0 ;; - --debug | --d* | -d ) - debug=: ;; - --file | --fil | --fi | --f ) - $ac_shift - CONFIG_FILES="$CONFIG_FILES $ac_optarg" - ac_need_defaults=false;; - --header | --heade | --head | --hea ) - $ac_shift - CONFIG_HEADERS="$CONFIG_HEADERS $ac_optarg" - ac_need_defaults=false;; - -q | -quiet | --quiet | --quie | --qui | --qu | --q \ - | -silent | --silent | --silen | --sile | --sil | --si | --s) - ac_cs_silent=: ;; - - # This is an error. - -*) { { echo "$as_me:$LINENO: error: unrecognized option: $1 -Try \`$0 --help' for more information." >&5 -echo "$as_me: error: unrecognized option: $1 -Try \`$0 --help' for more information." >&2;} - { (exit 1); exit 1; }; } ;; - - *) ac_config_targets="$ac_config_targets $1" ;; - - esac - shift -done - -ac_configure_extra_args= - -if $ac_cs_silent; then - exec 6>/dev/null - ac_configure_extra_args="$ac_configure_extra_args --silent" -fi - -_ACEOF -cat >>$CONFIG_STATUS <<_ACEOF -if \$ac_cs_recheck; then - echo "running $SHELL $0 " $ac_configure_args \$ac_configure_extra_args " --no-create --no-recursion" >&6 - exec $SHELL $0 $ac_configure_args \$ac_configure_extra_args --no-create --no-recursion -fi - -_ACEOF - - - - - -cat >>$CONFIG_STATUS <<\_ACEOF -for ac_config_target in $ac_config_targets -do - case "$ac_config_target" in - # Handling of arguments. - "Makefile" ) CONFIG_FILES="$CONFIG_FILES Makefile" ;; - "config.h" ) CONFIG_HEADERS="$CONFIG_HEADERS config.h" ;; - *) { { echo "$as_me:$LINENO: error: invalid argument: $ac_config_target" >&5 -echo "$as_me: error: invalid argument: $ac_config_target" >&2;} - { (exit 1); exit 1; }; };; - esac -done - -# If the user did not use the arguments to specify the items to instantiate, -# then the envvar interface is used. Set only those that are not. -# We use the long form for the default assignment because of an extremely -# bizarre bug on SunOS 4.1.3. -if $ac_need_defaults; then - test "${CONFIG_FILES+set}" = set || CONFIG_FILES=$config_files - test "${CONFIG_HEADERS+set}" = set || CONFIG_HEADERS=$config_headers -fi - -# Have a temporary directory for convenience. Make it in the build tree -# simply because there is no reason to put it here, and in addition, -# creating and moving files from /tmp can sometimes cause problems. -# Create a temporary directory, and hook for its removal unless debugging. -$debug || -{ - trap 'exit_status=$?; rm -rf $tmp && exit $exit_status' 0 - trap '{ (exit 1); exit 1; }' 1 2 13 15 -} - -# Create a (secure) tmp directory for tmp files. - -{ - tmp=`(umask 077 && mktemp -d -q "./confstatXXXXXX") 2>/dev/null` && - test -n "$tmp" && test -d "$tmp" -} || -{ - tmp=./confstat$$-$RANDOM - (umask 077 && mkdir $tmp) -} || -{ - echo "$me: cannot create a temporary directory in ." >&2 - { (exit 1); exit 1; } -} - -_ACEOF - -cat >>$CONFIG_STATUS <<_ACEOF - -# -# CONFIG_FILES section. -# - -# No need to generate the scripts if there are no CONFIG_FILES. -# This happens for instance when ./config.status config.h -if test -n "\$CONFIG_FILES"; then - # Protect against being on the right side of a sed subst in config.status. - sed 's/,@/@@/; s/@,/@@/; s/,;t t\$/@;t t/; /@;t t\$/s/[\\\\&,]/\\\\&/g; - s/@@/,@/; s/@@/@,/; s/@;t t\$/,;t t/' >\$tmp/subs.sed <<\\CEOF -s,@SHELL@,$SHELL,;t t -s,@PATH_SEPARATOR@,$PATH_SEPARATOR,;t t -s,@PACKAGE_NAME@,$PACKAGE_NAME,;t t -s,@PACKAGE_TARNAME@,$PACKAGE_TARNAME,;t t -s,@PACKAGE_VERSION@,$PACKAGE_VERSION,;t t -s,@PACKAGE_STRING@,$PACKAGE_STRING,;t t -s,@PACKAGE_BUGREPORT@,$PACKAGE_BUGREPORT,;t t -s,@exec_prefix@,$exec_prefix,;t t -s,@prefix@,$prefix,;t t -s,@program_transform_name@,$program_transform_name,;t t -s,@bindir@,$bindir,;t t -s,@sbindir@,$sbindir,;t t -s,@libexecdir@,$libexecdir,;t t -s,@datadir@,$datadir,;t t -s,@sysconfdir@,$sysconfdir,;t t -s,@sharedstatedir@,$sharedstatedir,;t t -s,@localstatedir@,$localstatedir,;t t -s,@libdir@,$libdir,;t t -s,@includedir@,$includedir,;t t -s,@oldincludedir@,$oldincludedir,;t t -s,@infodir@,$infodir,;t t -s,@mandir@,$mandir,;t t -s,@build_alias@,$build_alias,;t t -s,@host_alias@,$host_alias,;t t -s,@target_alias@,$target_alias,;t t -s,@DEFS@,$DEFS,;t t -s,@ECHO_C@,$ECHO_C,;t t -s,@ECHO_N@,$ECHO_N,;t t -s,@ECHO_T@,$ECHO_T,;t t -s,@LIBS@,$LIBS,;t t -s,@CC@,$CC,;t t -s,@CFLAGS@,$CFLAGS,;t t -s,@LDFLAGS@,$LDFLAGS,;t t -s,@CPPFLAGS@,$CPPFLAGS,;t t -s,@ac_ct_CC@,$ac_ct_CC,;t t -s,@EXEEXT@,$EXEEXT,;t t -s,@OBJEXT@,$OBJEXT,;t t -s,@INSTALL_PROGRAM@,$INSTALL_PROGRAM,;t t -s,@INSTALL_SCRIPT@,$INSTALL_SCRIPT,;t t -s,@INSTALL_DATA@,$INSTALL_DATA,;t t -s,@CPP@,$CPP,;t t -s,@EGREP@,$EGREP,;t t -s,@LOC_NTOA@,$LOC_NTOA,;t t -s,@LIBOBJS@,$LIBOBJS,;t t -s,@LTLIBOBJS@,$LTLIBOBJS,;t t -CEOF - -_ACEOF - - cat >>$CONFIG_STATUS <<\_ACEOF - # Split the substitutions into bite-sized pieces for seds with - # small command number limits, like on Digital OSF/1 and HP-UX. - ac_max_sed_lines=48 - ac_sed_frag=1 # Number of current file. - ac_beg=1 # First line for current file. - ac_end=$ac_max_sed_lines # Line after last line for current file. - ac_more_lines=: - ac_sed_cmds= - while $ac_more_lines; do - if test $ac_beg -gt 1; then - sed "1,${ac_beg}d; ${ac_end}q" $tmp/subs.sed >$tmp/subs.frag - else - sed "${ac_end}q" $tmp/subs.sed >$tmp/subs.frag - fi - if test ! -s $tmp/subs.frag; then - ac_more_lines=false - else - # The purpose of the label and of the branching condition is to - # speed up the sed processing (if there are no `@' at all, there - # is no need to browse any of the substitutions). - # These are the two extra sed commands mentioned above. - (echo ':t - /@[a-zA-Z_][a-zA-Z_0-9]*@/!b' && cat $tmp/subs.frag) >$tmp/subs-$ac_sed_frag.sed - if test -z "$ac_sed_cmds"; then - ac_sed_cmds="sed -f $tmp/subs-$ac_sed_frag.sed" - else - ac_sed_cmds="$ac_sed_cmds | sed -f $tmp/subs-$ac_sed_frag.sed" - fi - ac_sed_frag=`expr $ac_sed_frag + 1` - ac_beg=$ac_end - ac_end=`expr $ac_end + $ac_max_sed_lines` - fi - done - if test -z "$ac_sed_cmds"; then - ac_sed_cmds=cat - fi -fi # test -n "$CONFIG_FILES" - -_ACEOF -cat >>$CONFIG_STATUS <<\_ACEOF -for ac_file in : $CONFIG_FILES; do test "x$ac_file" = x: && continue - # Support "outfile[:infile[:infile...]]", defaulting infile="outfile.in". - case $ac_file in - - | *:- | *:-:* ) # input from stdin - cat >$tmp/stdin - ac_file_in=`echo "$ac_file" | sed 's,[^:]*:,,'` - ac_file=`echo "$ac_file" | sed 's,:.*,,'` ;; - *:* ) ac_file_in=`echo "$ac_file" | sed 's,[^:]*:,,'` - ac_file=`echo "$ac_file" | sed 's,:.*,,'` ;; - * ) ac_file_in=$ac_file.in ;; - esac - - # Compute @srcdir@, @top_srcdir@, and @INSTALL@ for subdirectories. - ac_dir=`(dirname "$ac_file") 2>/dev/null || -$as_expr X"$ac_file" : 'X\(.*[^/]\)//*[^/][^/]*/*$' \| \ - X"$ac_file" : 'X\(//\)[^/]' \| \ - X"$ac_file" : 'X\(//\)$' \| \ - X"$ac_file" : 'X\(/\)' \| \ - . : '\(.\)' 2>/dev/null || -echo X"$ac_file" | - sed '/^X\(.*[^/]\)\/\/*[^/][^/]*\/*$/{ s//\1/; q; } - /^X\(\/\/\)[^/].*/{ s//\1/; q; } - /^X\(\/\/\)$/{ s//\1/; q; } - /^X\(\/\).*/{ s//\1/; q; } - s/.*/./; q'` - { if $as_mkdir_p; then - mkdir -p "$ac_dir" - else - as_dir="$ac_dir" - as_dirs= - while test ! -d "$as_dir"; do - as_dirs="$as_dir $as_dirs" - as_dir=`(dirname "$as_dir") 2>/dev/null || -$as_expr X"$as_dir" : 'X\(.*[^/]\)//*[^/][^/]*/*$' \| \ - X"$as_dir" : 'X\(//\)[^/]' \| \ - X"$as_dir" : 'X\(//\)$' \| \ - X"$as_dir" : 'X\(/\)' \| \ - . : '\(.\)' 2>/dev/null || -echo X"$as_dir" | - sed '/^X\(.*[^/]\)\/\/*[^/][^/]*\/*$/{ s//\1/; q; } - /^X\(\/\/\)[^/].*/{ s//\1/; q; } - /^X\(\/\/\)$/{ s//\1/; q; } - /^X\(\/\).*/{ s//\1/; q; } - s/.*/./; q'` - done - test ! -n "$as_dirs" || mkdir $as_dirs - fi || { { echo "$as_me:$LINENO: error: cannot create directory \"$ac_dir\"" >&5 -echo "$as_me: error: cannot create directory \"$ac_dir\"" >&2;} - { (exit 1); exit 1; }; }; } - - ac_builddir=. - -if test "$ac_dir" != .; then - ac_dir_suffix=/`echo "$ac_dir" | sed 's,^\.[\\/],,'` - # A "../" for each directory in $ac_dir_suffix. - ac_top_builddir=`echo "$ac_dir_suffix" | sed 's,/[^\\/]*,../,g'` -else - ac_dir_suffix= ac_top_builddir= -fi - -case $srcdir in - .) # No --srcdir option. We are building in place. - ac_srcdir=. - if test -z "$ac_top_builddir"; then - ac_top_srcdir=. - else - ac_top_srcdir=`echo $ac_top_builddir | sed 's,/$,,'` - fi ;; - [\\/]* | ?:[\\/]* ) # Absolute path. - ac_srcdir=$srcdir$ac_dir_suffix; - ac_top_srcdir=$srcdir ;; - *) # Relative path. - ac_srcdir=$ac_top_builddir$srcdir$ac_dir_suffix - ac_top_srcdir=$ac_top_builddir$srcdir ;; -esac - -# Do not use `cd foo && pwd` to compute absolute paths, because -# the directories may not exist. -case `pwd` in -.) ac_abs_builddir="$ac_dir";; -*) - case "$ac_dir" in - .) ac_abs_builddir=`pwd`;; - [\\/]* | ?:[\\/]* ) ac_abs_builddir="$ac_dir";; - *) ac_abs_builddir=`pwd`/"$ac_dir";; - esac;; -esac -case $ac_abs_builddir in -.) ac_abs_top_builddir=${ac_top_builddir}.;; -*) - case ${ac_top_builddir}. in - .) ac_abs_top_builddir=$ac_abs_builddir;; - [\\/]* | ?:[\\/]* ) ac_abs_top_builddir=${ac_top_builddir}.;; - *) ac_abs_top_builddir=$ac_abs_builddir/${ac_top_builddir}.;; - esac;; -esac -case $ac_abs_builddir in -.) ac_abs_srcdir=$ac_srcdir;; -*) - case $ac_srcdir in - .) ac_abs_srcdir=$ac_abs_builddir;; - [\\/]* | ?:[\\/]* ) ac_abs_srcdir=$ac_srcdir;; - *) ac_abs_srcdir=$ac_abs_builddir/$ac_srcdir;; - esac;; -esac -case $ac_abs_builddir in -.) ac_abs_top_srcdir=$ac_top_srcdir;; -*) - case $ac_top_srcdir in - .) ac_abs_top_srcdir=$ac_abs_builddir;; - [\\/]* | ?:[\\/]* ) ac_abs_top_srcdir=$ac_top_srcdir;; - *) ac_abs_top_srcdir=$ac_abs_builddir/$ac_top_srcdir;; - esac;; -esac - - - case $INSTALL in - [\\/$]* | ?:[\\/]* ) ac_INSTALL=$INSTALL ;; - *) ac_INSTALL=$ac_top_builddir$INSTALL ;; - esac - - # Let's still pretend it is `configure' which instantiates (i.e., don't - # use $as_me), people would be surprised to read: - # /* config.h. Generated by config.status. */ - if test x"$ac_file" = x-; then - configure_input= - else - configure_input="$ac_file. " - fi - configure_input=$configure_input"Generated from `echo $ac_file_in | - sed 's,.*/,,'` by configure." - - # First look for the input files in the build tree, otherwise in the - # src tree. - ac_file_inputs=`IFS=: - for f in $ac_file_in; do - case $f in - -) echo $tmp/stdin ;; - [\\/$]*) - # Absolute (can't be DOS-style, as IFS=:) - test -f "$f" || { { echo "$as_me:$LINENO: error: cannot find input file: $f" >&5 -echo "$as_me: error: cannot find input file: $f" >&2;} - { (exit 1); exit 1; }; } - echo "$f";; - *) # Relative - if test -f "$f"; then - # Build tree - echo "$f" - elif test -f "$srcdir/$f"; then - # Source tree - echo "$srcdir/$f" - else - # /dev/null tree - { { echo "$as_me:$LINENO: error: cannot find input file: $f" >&5 -echo "$as_me: error: cannot find input file: $f" >&2;} - { (exit 1); exit 1; }; } - fi;; - esac - done` || { (exit 1); exit 1; } - - if test x"$ac_file" != x-; then - { echo "$as_me:$LINENO: creating $ac_file" >&5 -echo "$as_me: creating $ac_file" >&6;} - rm -f "$ac_file" - fi -_ACEOF -cat >>$CONFIG_STATUS <<_ACEOF - sed "$ac_vpsub -$extrasub -_ACEOF -cat >>$CONFIG_STATUS <<\_ACEOF -:t -/@[a-zA-Z_][a-zA-Z_0-9]*@/!b -s,@configure_input@,$configure_input,;t t -s,@srcdir@,$ac_srcdir,;t t -s,@abs_srcdir@,$ac_abs_srcdir,;t t -s,@top_srcdir@,$ac_top_srcdir,;t t -s,@abs_top_srcdir@,$ac_abs_top_srcdir,;t t -s,@builddir@,$ac_builddir,;t t -s,@abs_builddir@,$ac_abs_builddir,;t t -s,@top_builddir@,$ac_top_builddir,;t t -s,@abs_top_builddir@,$ac_abs_top_builddir,;t t -s,@INSTALL@,$ac_INSTALL,;t t -" $ac_file_inputs | (eval "$ac_sed_cmds") >$tmp/out - rm -f $tmp/stdin - if test x"$ac_file" != x-; then - mv $tmp/out $ac_file - else - cat $tmp/out - rm -f $tmp/out - fi - -done -_ACEOF -cat >>$CONFIG_STATUS <<\_ACEOF - -# -# CONFIG_HEADER section. -# - -# These sed commands are passed to sed as "A NAME B NAME C VALUE D", where -# NAME is the cpp macro being defined and VALUE is the value it is being given. -# -# ac_d sets the value in "#define NAME VALUE" lines. -ac_dA='s,^\([ ]*\)#\([ ]*define[ ][ ]*\)' -ac_dB='[ ].*$,\1#\2' -ac_dC=' ' -ac_dD=',;t' -# ac_u turns "#undef NAME" without trailing blanks into "#define NAME VALUE". -ac_uA='s,^\([ ]*\)#\([ ]*\)undef\([ ][ ]*\)' -ac_uB='$,\1#\2define\3' -ac_uC=' ' -ac_uD=',;t' - -for ac_file in : $CONFIG_HEADERS; do test "x$ac_file" = x: && continue - # Support "outfile[:infile[:infile...]]", defaulting infile="outfile.in". - case $ac_file in - - | *:- | *:-:* ) # input from stdin - cat >$tmp/stdin - ac_file_in=`echo "$ac_file" | sed 's,[^:]*:,,'` - ac_file=`echo "$ac_file" | sed 's,:.*,,'` ;; - *:* ) ac_file_in=`echo "$ac_file" | sed 's,[^:]*:,,'` - ac_file=`echo "$ac_file" | sed 's,:.*,,'` ;; - * ) ac_file_in=$ac_file.in ;; - esac - - test x"$ac_file" != x- && { echo "$as_me:$LINENO: creating $ac_file" >&5 -echo "$as_me: creating $ac_file" >&6;} - - # First look for the input files in the build tree, otherwise in the - # src tree. - ac_file_inputs=`IFS=: - for f in $ac_file_in; do - case $f in - -) echo $tmp/stdin ;; - [\\/$]*) - # Absolute (can't be DOS-style, as IFS=:) - test -f "$f" || { { echo "$as_me:$LINENO: error: cannot find input file: $f" >&5 -echo "$as_me: error: cannot find input file: $f" >&2;} - { (exit 1); exit 1; }; } - # Do quote $f, to prevent DOS paths from being IFS'd. - echo "$f";; - *) # Relative - if test -f "$f"; then - # Build tree - echo "$f" - elif test -f "$srcdir/$f"; then - # Source tree - echo "$srcdir/$f" - else - # /dev/null tree - { { echo "$as_me:$LINENO: error: cannot find input file: $f" >&5 -echo "$as_me: error: cannot find input file: $f" >&2;} - { (exit 1); exit 1; }; } - fi;; - esac - done` || { (exit 1); exit 1; } - # Remove the trailing spaces. - sed 's/[ ]*$//' $ac_file_inputs >$tmp/in - -_ACEOF - -# Transform confdefs.h into two sed scripts, `conftest.defines' and -# `conftest.undefs', that substitutes the proper values into -# config.h.in to produce config.h. The first handles `#define' -# templates, and the second `#undef' templates. -# And first: Protect against being on the right side of a sed subst in -# config.status. Protect against being in an unquoted here document -# in config.status. -rm -f conftest.defines conftest.undefs -# Using a here document instead of a string reduces the quoting nightmare. -# Putting comments in sed scripts is not portable. -# -# `end' is used to avoid that the second main sed command (meant for -# 0-ary CPP macros) applies to n-ary macro definitions. -# See the Autoconf documentation for `clear'. -cat >confdef2sed.sed <<\_ACEOF -s/[\\&,]/\\&/g -s,[\\$`],\\&,g -t clear -: clear -s,^[ ]*#[ ]*define[ ][ ]*\([^ (][^ (]*\)\(([^)]*)\)[ ]*\(.*\)$,${ac_dA}\1${ac_dB}\1\2${ac_dC}\3${ac_dD},gp -t end -s,^[ ]*#[ ]*define[ ][ ]*\([^ ][^ ]*\)[ ]*\(.*\)$,${ac_dA}\1${ac_dB}\1${ac_dC}\2${ac_dD},gp -: end -_ACEOF -# If some macros were called several times there might be several times -# the same #defines, which is useless. Nevertheless, we may not want to -# sort them, since we want the *last* AC-DEFINE to be honored. -uniq confdefs.h | sed -n -f confdef2sed.sed >conftest.defines -sed 's/ac_d/ac_u/g' conftest.defines >conftest.undefs -rm -f confdef2sed.sed - -# This sed command replaces #undef with comments. This is necessary, for -# example, in the case of _POSIX_SOURCE, which is predefined and required -# on some systems where configure will not decide to define it. -cat >>conftest.undefs <<\_ACEOF -s,^[ ]*#[ ]*undef[ ][ ]*[a-zA-Z_][a-zA-Z_0-9]*,/* & */, -_ACEOF - -# Break up conftest.defines because some shells have a limit on the size -# of here documents, and old seds have small limits too (100 cmds). -echo ' # Handle all the #define templates only if necessary.' >>$CONFIG_STATUS -echo ' if grep "^[ ]*#[ ]*define" $tmp/in >/dev/null; then' >>$CONFIG_STATUS -echo ' # If there are no defines, we may have an empty if/fi' >>$CONFIG_STATUS -echo ' :' >>$CONFIG_STATUS -rm -f conftest.tail -while grep . conftest.defines >/dev/null -do - # Write a limited-size here document to $tmp/defines.sed. - echo ' cat >$tmp/defines.sed <>$CONFIG_STATUS - # Speed up: don't consider the non `#define' lines. - echo '/^[ ]*#[ ]*define/!b' >>$CONFIG_STATUS - # Work around the forget-to-reset-the-flag bug. - echo 't clr' >>$CONFIG_STATUS - echo ': clr' >>$CONFIG_STATUS - sed ${ac_max_here_lines}q conftest.defines >>$CONFIG_STATUS - echo 'CEOF - sed -f $tmp/defines.sed $tmp/in >$tmp/out - rm -f $tmp/in - mv $tmp/out $tmp/in -' >>$CONFIG_STATUS - sed 1,${ac_max_here_lines}d conftest.defines >conftest.tail - rm -f conftest.defines - mv conftest.tail conftest.defines -done -rm -f conftest.defines -echo ' fi # grep' >>$CONFIG_STATUS -echo >>$CONFIG_STATUS - -# Break up conftest.undefs because some shells have a limit on the size -# of here documents, and old seds have small limits too (100 cmds). -echo ' # Handle all the #undef templates' >>$CONFIG_STATUS -rm -f conftest.tail -while grep . conftest.undefs >/dev/null -do - # Write a limited-size here document to $tmp/undefs.sed. - echo ' cat >$tmp/undefs.sed <>$CONFIG_STATUS - # Speed up: don't consider the non `#undef' - echo '/^[ ]*#[ ]*undef/!b' >>$CONFIG_STATUS - # Work around the forget-to-reset-the-flag bug. - echo 't clr' >>$CONFIG_STATUS - echo ': clr' >>$CONFIG_STATUS - sed ${ac_max_here_lines}q conftest.undefs >>$CONFIG_STATUS - echo 'CEOF - sed -f $tmp/undefs.sed $tmp/in >$tmp/out - rm -f $tmp/in - mv $tmp/out $tmp/in -' >>$CONFIG_STATUS - sed 1,${ac_max_here_lines}d conftest.undefs >conftest.tail - rm -f conftest.undefs - mv conftest.tail conftest.undefs -done -rm -f conftest.undefs - -cat >>$CONFIG_STATUS <<\_ACEOF - # Let's still pretend it is `configure' which instantiates (i.e., don't - # use $as_me), people would be surprised to read: - # /* config.h. Generated by config.status. */ - if test x"$ac_file" = x-; then - echo "/* Generated by configure. */" >$tmp/config.h - else - echo "/* $ac_file. Generated by configure. */" >$tmp/config.h - fi - cat $tmp/in >>$tmp/config.h - rm -f $tmp/in - if test x"$ac_file" != x-; then - if diff $ac_file $tmp/config.h >/dev/null 2>&1; then - { echo "$as_me:$LINENO: $ac_file is unchanged" >&5 -echo "$as_me: $ac_file is unchanged" >&6;} - else - ac_dir=`(dirname "$ac_file") 2>/dev/null || -$as_expr X"$ac_file" : 'X\(.*[^/]\)//*[^/][^/]*/*$' \| \ - X"$ac_file" : 'X\(//\)[^/]' \| \ - X"$ac_file" : 'X\(//\)$' \| \ - X"$ac_file" : 'X\(/\)' \| \ - . : '\(.\)' 2>/dev/null || -echo X"$ac_file" | - sed '/^X\(.*[^/]\)\/\/*[^/][^/]*\/*$/{ s//\1/; q; } - /^X\(\/\/\)[^/].*/{ s//\1/; q; } - /^X\(\/\/\)$/{ s//\1/; q; } - /^X\(\/\).*/{ s//\1/; q; } - s/.*/./; q'` - { if $as_mkdir_p; then - mkdir -p "$ac_dir" - else - as_dir="$ac_dir" - as_dirs= - while test ! -d "$as_dir"; do - as_dirs="$as_dir $as_dirs" - as_dir=`(dirname "$as_dir") 2>/dev/null || -$as_expr X"$as_dir" : 'X\(.*[^/]\)//*[^/][^/]*/*$' \| \ - X"$as_dir" : 'X\(//\)[^/]' \| \ - X"$as_dir" : 'X\(//\)$' \| \ - X"$as_dir" : 'X\(/\)' \| \ - . : '\(.\)' 2>/dev/null || -echo X"$as_dir" | - sed '/^X\(.*[^/]\)\/\/*[^/][^/]*\/*$/{ s//\1/; q; } - /^X\(\/\/\)[^/].*/{ s//\1/; q; } - /^X\(\/\/\)$/{ s//\1/; q; } - /^X\(\/\).*/{ s//\1/; q; } - s/.*/./; q'` - done - test ! -n "$as_dirs" || mkdir $as_dirs - fi || { { echo "$as_me:$LINENO: error: cannot create directory \"$ac_dir\"" >&5 -echo "$as_me: error: cannot create directory \"$ac_dir\"" >&2;} - { (exit 1); exit 1; }; }; } - - rm -f $ac_file - mv $tmp/config.h $ac_file - fi - else - cat $tmp/config.h - rm -f $tmp/config.h - fi -done -_ACEOF - -cat >>$CONFIG_STATUS <<\_ACEOF - -{ (exit 0); exit 0; } -_ACEOF -chmod +x $CONFIG_STATUS -ac_clean_files=$ac_clean_files_save - - -# configure is writing to config.log, and then calls config.status. -# config.status does its own redirection, appending to config.log. -# Unfortunately, on DOS this fails, as config.log is still kept open -# by configure, so config.status won't be able to write to it; its -# output is simply discarded. So we exec the FD to /dev/null, -# effectively closing config.log, so it can be properly (re)opened and -# appended to by config.status. When coming back to configure, we -# need to make the FD available again. -if test "$no_create" != yes; then - ac_cs_success=: - ac_config_status_args= - test "$silent" = yes && - ac_config_status_args="$ac_config_status_args --quiet" - exec 5>/dev/null - $SHELL $CONFIG_STATUS $ac_config_status_args || ac_cs_success=false - exec 5>>config.log - # Use ||, not &&, to avoid exiting from the if with $? = 1, which - # would make configure fail if this is the last instruction. - $ac_cs_success || { (exit 1); exit 1; } -fi - - - - diff --git a/contrib/query-loc-0.3.0/configure.in b/contrib/query-loc-0.3.0/configure.in deleted file mode 100644 index 88ca60d9b8..0000000000 --- a/contrib/query-loc-0.3.0/configure.in +++ /dev/null @@ -1,65 +0,0 @@ -dnl Process this file with autoconf to produce a configure script. -AC_RELEASE("$Id: configure.in,v 1.1.2.1 2005/04/01 06:13:59 marka Exp $") -AC_INIT(query-loc.c) - -dnl Checks for programs. -AC_PROG_CC -if test "$GCC" = "yes"; then - CFLAGS="${CFLAGS} -Wall" -fi -AC_PROG_INSTALL - -dnl Checks for libraries. -AC_CHECK_LIB(resolv, res_query) - -dnl Checks for header files. -AC_HEADER_STDC -AC_CONFIG_HEADER(config.h) -AC_CHECK_HEADER(resolv.h, , AC_MSG_ERROR("No headers for name service applications")) -AC_CHECK_HEADER(arpa/nameser.h, , AC_MSG_ERROR("No headers for name service applications")) -AC_CHECK_HEADER(sys/time.h, , AC_MSG_ERROR("Mandatory header missing on your system")) -AC_CHECK_HEADER(unistd.h, , AC_MSG_ERROR("Mandatory header missing on your system")) - - -dnl This one is only useful for Solaris? -AC_MSG_CHECKING(if libnsl is mandatory) -AC_TRY_LINK([#include - #include - #include - #include - union - { - HEADER hdr; - u_char buf[4096]; /* With RFC 2671, otherwise 512 is enough */ - } - response; - char *domain; - int requested_type; ], - [res_query(domain, - C_IN, - requested_type, - (u_char *) & response, - sizeof (response)) ], dnl - [AC_MSG_RESULT(no)], dnl - [AC_MSG_RESULT(yes); LIBS="${LIBS} -lnsl"]) - -dnl Check for the loc_ntoa macro/function -AC_MSG_CHECKING(loc_ntoa) -AC_TRY_LINK([#include ], dnl - [u_char *cp; char *result; loc_ntoa(cp, result)], dnl - [AC_MSG_RESULT(yes); AC_DEFINE(HAVE_LOC_NTOA)], dnl - [AC_MSG_RESULT([no, using the alternative]); LOC_NTOA=loc_ntoa.o]) -AC_SUBST(LOC_NTOA) - -dnl Checks for typedefs, structures, and compiler characteristics. -AC_C_CONST -AC_CHECK_SIZEOF(long) -AC_CHECK_SIZEOF(int) -AC_CHECK_SIZEOF(short) -AC_CHECK_SIZEOF(char) - -dnl Misc. -AC_OUTPUT(Makefile) - - - diff --git a/contrib/query-loc-0.3.0/install-sh b/contrib/query-loc-0.3.0/install-sh deleted file mode 100755 index e9de23842d..0000000000 --- a/contrib/query-loc-0.3.0/install-sh +++ /dev/null @@ -1,251 +0,0 @@ -#!/bin/sh -# -# install - install a program, script, or datafile -# This comes from X11R5 (mit/util/scripts/install.sh). -# -# Copyright 1991 by the Massachusetts Institute of Technology -# -# Permission to use, copy, modify, distribute, and sell this software and its -# documentation for any purpose is hereby granted without fee, provided that -# the above copyright notice appear in all copies and that both that -# copyright notice and this permission notice appear in supporting -# documentation, and that the name of M.I.T. not be used in advertising or -# publicity pertaining to distribution of the software without specific, -# written prior permission. M.I.T. makes no representations about the -# suitability of this software for any purpose. It is provided "as is" -# without express or implied warranty. -# -# Calling this script install-sh is preferred over install.sh, to prevent -# `make' implicit rules from creating a file called install from it -# when there is no Makefile. -# -# This script is compatible with the BSD install script, but was written -# from scratch. It can only install one file at a time, a restriction -# shared with many OS's install programs. - - -# set DOITPROG to echo to test this script - -# Don't use :- since 4.3BSD and earlier shells don't like it. -doit="${DOITPROG-}" - - -# put in absolute paths if you don't have them in your path; or use env. vars. - -mvprog="${MVPROG-mv}" -cpprog="${CPPROG-cp}" -chmodprog="${CHMODPROG-chmod}" -chownprog="${CHOWNPROG-chown}" -chgrpprog="${CHGRPPROG-chgrp}" -stripprog="${STRIPPROG-strip}" -rmprog="${RMPROG-rm}" -mkdirprog="${MKDIRPROG-mkdir}" - -transformbasename="" -transform_arg="" -instcmd="$mvprog" -chmodcmd="$chmodprog 0755" -chowncmd="" -chgrpcmd="" -stripcmd="" -rmcmd="$rmprog -f" -mvcmd="$mvprog" -src="" -dst="" -dir_arg="" - -while [ x"$1" != x ]; do - case $1 in - -c) instcmd="$cpprog" - shift - continue;; - - -d) dir_arg=true - shift - continue;; - - -m) chmodcmd="$chmodprog $2" - shift - shift - continue;; - - -o) chowncmd="$chownprog $2" - shift - shift - continue;; - - -g) chgrpcmd="$chgrpprog $2" - shift - shift - continue;; - - -s) stripcmd="$stripprog" - shift - continue;; - - -t=*) transformarg=`echo $1 | sed 's/-t=//'` - shift - continue;; - - -b=*) transformbasename=`echo $1 | sed 's/-b=//'` - shift - continue;; - - *) if [ x"$src" = x ] - then - src=$1 - else - # this colon is to work around a 386BSD /bin/sh bug - : - dst=$1 - fi - shift - continue;; - esac -done - -if [ x"$src" = x ] -then - echo "install: no input file specified" - exit 1 -else - true -fi - -if [ x"$dir_arg" != x ]; then - dst=$src - src="" - - if [ -d $dst ]; then - instcmd=: - chmodcmd="" - else - instcmd=mkdir - fi -else - -# Waiting for this to be detected by the "$instcmd $src $dsttmp" command -# might cause directories to be created, which would be especially bad -# if $src (and thus $dsttmp) contains '*'. - - if [ -f $src -o -d $src ] - then - true - else - echo "install: $src does not exist" - exit 1 - fi - - if [ x"$dst" = x ] - then - echo "install: no destination specified" - exit 1 - else - true - fi - -# If destination is a directory, append the input filename; if your system -# does not like double slashes in filenames, you may need to add some logic - - if [ -d $dst ] - then - dst="$dst"/`basename $src` - else - true - fi -fi - -## this sed command emulates the dirname command -dstdir=`echo $dst | sed -e 's,[^/]*$,,;s,/$,,;s,^$,.,'` - -# Make sure that the destination directory exists. -# this part is taken from Noah Friedman's mkinstalldirs script - -# Skip lots of stat calls in the usual case. -if [ ! -d "$dstdir" ]; then -defaultIFS=' -' -IFS="${IFS-${defaultIFS}}" - -oIFS="${IFS}" -# Some sh's can't handle IFS=/ for some reason. -IFS='%' -set - `echo ${dstdir} | sed -e 's@/@%@g' -e 's@^%@/@'` -IFS="${oIFS}" - -pathcomp='' - -while [ $# -ne 0 ] ; do - pathcomp="${pathcomp}${1}" - shift - - if [ ! -d "${pathcomp}" ] ; - then - $mkdirprog "${pathcomp}" - else - true - fi - - pathcomp="${pathcomp}/" -done -fi - -if [ x"$dir_arg" != x ] -then - $doit $instcmd $dst && - - if [ x"$chowncmd" != x ]; then $doit $chowncmd $dst; else true ; fi && - if [ x"$chgrpcmd" != x ]; then $doit $chgrpcmd $dst; else true ; fi && - if [ x"$stripcmd" != x ]; then $doit $stripcmd $dst; else true ; fi && - if [ x"$chmodcmd" != x ]; then $doit $chmodcmd $dst; else true ; fi -else - -# If we're going to rename the final executable, determine the name now. - - if [ x"$transformarg" = x ] - then - dstfile=`basename $dst` - else - dstfile=`basename $dst $transformbasename | - sed $transformarg`$transformbasename - fi - -# don't allow the sed command to completely eliminate the filename - - if [ x"$dstfile" = x ] - then - dstfile=`basename $dst` - else - true - fi - -# Make a temp file name in the proper directory. - - dsttmp=$dstdir/#inst.$$# - -# Move or copy the file name to the temp name - - $doit $instcmd $src $dsttmp && - - trap "rm -f ${dsttmp}" 0 && - -# and set any options; do chmod last to preserve setuid bits - -# If any of these fail, we abort the whole thing. If we want to -# ignore errors from any of these, just make sure not to ignore -# errors from the above "$doit $instcmd $src $dsttmp" command. - - if [ x"$chowncmd" != x ]; then $doit $chowncmd $dsttmp; else true;fi && - if [ x"$chgrpcmd" != x ]; then $doit $chgrpcmd $dsttmp; else true;fi && - if [ x"$stripcmd" != x ]; then $doit $stripcmd $dsttmp; else true;fi && - if [ x"$chmodcmd" != x ]; then $doit $chmodcmd $dsttmp; else true;fi && - -# Now rename the file to the real destination. - - $doit $rmcmd -f $dstdir/$dstfile && - $doit $mvcmd $dsttmp $dstdir/$dstfile - -fi && - - -exit 0 diff --git a/contrib/query-loc-0.3.0/loc.c b/contrib/query-loc-0.3.0/loc.c deleted file mode 100644 index 5062482f42..0000000000 --- a/contrib/query-loc-0.3.0/loc.c +++ /dev/null @@ -1,566 +0,0 @@ -#include "loc.h" - -/* $Id: loc.c,v 1.1.2.1 2005/04/01 06:13:59 marka Exp $ */ - -/* Global variables */ - -short rr_errno; - -/* - Prints the actual usage - */ -void -usage () -{ - (void) fprintf (stderr, - "Usage: %s: [-v] [-d nnn] hostname\n", progname); - exit (2); -} - -/* - Panics - */ -void -panic (message) - char *message; -{ - (void) fprintf (stderr, - "%s: %s\n", progname, message); - exit (2); -} - -/* - ** IN_ADDR_ARPA -- Convert dotted quad string to reverse in-addr.arpa - ** ------------------------------------------------------------------ - ** - ** Returns: - ** Pointer to appropriate reverse in-addr.arpa name - ** with trailing dot to force absolute domain name. - ** NULL in case of invalid dotted quad input string. - */ - -#ifndef ARPA_ROOT -#define ARPA_ROOT "in-addr.arpa" -#endif - -char * -in_addr_arpa (dottedquad) - char *dottedquad; /* input string with dotted quad */ -{ - static char addrbuf[4 * 4 + sizeof (ARPA_ROOT) + 2]; - unsigned int a[4]; - register int n; - - n = sscanf (dottedquad, "%u.%u.%u.%u", &a[0], &a[1], &a[2], &a[3]); - switch (n) - { - case 4: - (void) sprintf (addrbuf, "%u.%u.%u.%u.%s.", - a[3] & 0xff, a[2] & 0xff, a[1] & 0xff, a[0] & 0xff, ARPA_ROOT); - break; - - case 3: - (void) sprintf (addrbuf, "%u.%u.%u.%s.", - a[2] & 0xff, a[1] & 0xff, a[0] & 0xff, ARPA_ROOT); - break; - - case 2: - (void) sprintf (addrbuf, "%u.%u.%s.", - a[1] & 0xff, a[0] & 0xff, ARPA_ROOT); - break; - - case 1: - (void) sprintf (addrbuf, "%u.%s.", - a[0] & 0xff, ARPA_ROOT); - break; - - default: - return (NULL); - } - - while (--n >= 0) - if (a[n] > 255) - return (NULL); - - return (addrbuf); -} - -/* - Returns a human-readable version of the LOC information or - NULL if it failed. Argument is a name (of a network or a machine) - and a boolean telling is it is a network name or a machine name. - */ -char * -getlocbyname (name, is_network) - const char *name; - short is_network; -{ - char *result; - struct list_in_addr *list, *p; - result = findRR (name, T_LOC); - if (result != NULL) - { - if (debug >= 2) - printf ("LOC record found for the name %s\n", name); - return result; - } - else - { - if (!is_network) - { - list = findA (name); - if (debug >= 2) - printf ("No LOC record found for the name %s, trying addresses\n", name); - if (list != NULL) - { - for (p = list; p != NULL; p = p->next) - { - if (debug >= 2) - printf ("Trying address %s\n", inet_ntoa (p->addr)); - result = getlocbyaddr (p->addr, NULL); - if (result != NULL) - return result; - } - return NULL; - } - else - { - if (debug >= 2) - printf (" No A record found for %s\n", name); - return NULL; - } - } - else - { - if (debug >= 2) - printf ("No LOC record found for the network name %s\n", name); - return NULL; - } - } -} - -/* - Returns a human-readable version of the LOC information or - NULL if it failed. Argument is an IP address. - */ -char * -getlocbyaddr (addr, mask) - const struct in_addr addr; - const struct in_addr *mask; -{ - struct in_addr netaddr; - u_int32_t a; - struct in_addr themask; - char *text_addr, *text_mask; - - if (mask == NULL) - { - themask.s_addr = (u_int32_t) 0; - } - else - { - themask = *mask; - } - - text_addr = (char *) malloc (256); - text_mask = (char *) malloc (256); - strcpy (text_addr, inet_ntoa (addr)); - strcpy (text_mask, inet_ntoa (themask)); - - if (debug >= 2) - printf ("Testing address %s/%s\n", text_addr, text_mask); - if (mask == NULL) - { - a = ntohl (addr.s_addr); - if (IN_CLASSA (a)) - { - netaddr.s_addr = htonl (a & IN_CLASSA_NET); - } - else if (IN_CLASSB (a)) - { - netaddr.s_addr = htonl (a & IN_CLASSB_NET); - } - else if (IN_CLASSC (a)) - { - netaddr.s_addr = htonl (a & IN_CLASSC_NET); - } - else - { - /* Error */ - } - return getlocbynet (in_addr_arpa (inet_ntoa (netaddr)), addr, mask); - } - else - { - netaddr.s_addr = addr.s_addr & themask.s_addr; - return getlocbynet (in_addr_arpa (inet_ntoa (netaddr)), addr, mask); - } -} - -/* - Returns a human-readable LOC. - Argument is a network name in the 0.z.y.x.in-addr.arpa format - and the original address - */ -char * -getlocbynet (name, addr, mask) - char *name; - struct in_addr addr; - struct in_addr *mask; -{ - char *network; - char *result, *result_int; - struct list_in_addr *list; - if (debug >= 2) - printf ("Testing network %s\n", name); - network = findRR (name, T_PTR); - if (network == NULL) - { - if (debug >= 2) - printf ("No name for network %s\n", name); - return NULL; - } - else - { - result = getlocbyname (network, TRUE); - list = findA (network); - if (list == NULL) - { - return result; - } - else if ((mask != NULL) && - ((mask->s_addr) == (list->addr.s_addr))) - { - /* Already checked */ - return result; - } - else - { - result_int = getlocbyaddr (addr, &list->addr); - if (result_int == NULL) - return result; - else - return result_int; - } - } -} - -/* - The code for these two functions is stolen from the examples in Liu and Albitz - book "DNS and BIND" (O'Reilly). - */ - -/**************************************************************** - * skipName -- This routine skips over a domain name. If the * - * domain name expansion fails, it crashes. * - * dn_skipname() is probably not on your manual * - * page; it is similar to dn_expand() except that it just * - * skips over the name. dn_skipname() is in res_comp.c if * - * you need to find it. * - ****************************************************************/ -int -skipName (cp, endOfMsg) - u_char *cp; - u_char *endOfMsg; -{ - int n; - - if ((n = dn_skipname (cp, endOfMsg)) < 0) - { - panic ("dn_skipname failed\n"); - } - return (n); -} - -/**************************************************************** - * skipToData -- This routine advances the cp pointer to the * - * start of the resource record data portion. On the way, * - * it fills in the type, class, ttl, and data length * - ****************************************************************/ -int -skipToData (cp, type, class, ttl, dlen, endOfMsg) - u_char *cp; - u_short *type; - u_short *class; - u_int32_t *ttl; - u_short *dlen; - u_char *endOfMsg; -{ - u_char *tmp_cp = cp; /* temporary version of cp */ - - /* Skip the domain name; it matches the name we looked up */ - tmp_cp += skipName (tmp_cp, endOfMsg); - - /* - * Grab the type, class, and ttl. GETSHORT and GETLONG - * are macros defined in arpa/nameser.h. - */ - GETSHORT (*type, tmp_cp); - GETSHORT (*class, tmp_cp); - GETLONG (*ttl, tmp_cp); - GETSHORT (*dlen, tmp_cp); - - return (tmp_cp - cp); -} - - -/* - Returns a human-readable version of a DNS RR (resource record) - associated with the name 'domain'. - If it does not find, ir returns NULL and sets rr_errno to explain why. - - The code for this function is stolen from the examples in Liu and Albitz - book "DNS and BIND" (O'Reilly). - */ -char * -findRR (domain, requested_type) - char *domain; - int requested_type; -{ - char *result, *message; - - union - { - HEADER hdr; /* defined in resolv.h */ - u_char buf[PACKETSZ]; /* defined in arpa/nameser.h */ - } - response; /* response buffers */ -short found = 0; -int responseLen; /* buffer length */ - - u_char *cp; /* character pointer to parse DNS packet */ - u_char *endOfMsg; /* need to know the end of the message */ - u_short class; /* classes defined in arpa/nameser.h */ - u_short type; /* types defined in arpa/nameser.h */ - u_int32_t ttl; /* resource record time to live */ - u_short dlen; /* size of resource record data */ - - int i, count, dup; /* misc variables */ - - char *ptrList[1]; - int ptrNum = 0; - struct in_addr addr; - - result = (char *) malloc (256); - message = (char *) malloc (256); - /* - * Look up the records for the given domain name. - * We expect the domain to be a fully qualified name, so - * we use res_query(). If we wanted the resolver search - * algorithm, we would have used res_search() instead. - */ - if ((responseLen = - res_query (domain, /* the domain we care about */ - C_IN, /* Internet class records */ - requested_type, /* Look up name server records */ - (u_char *) & response, /*response buffer */ - sizeof (response))) /*buffer size */ - < 0) - { /*If negative */ - rr_errno = h_errno; - return NULL; - } - - /* - * Keep track of the end of the message so we don't - * pass it while parsing the response. responseLen is - * the value returned by res_query. - */ - endOfMsg = response.buf + responseLen; - - /* - * Set a pointer to the start of the question section, - * which begins immediately AFTER the header. - */ - cp = response.buf + sizeof (HEADER); - - /* - * Skip over the whole question section. The question - * section is comprised of a name, a type, and a class. - * QFIXEDSZ (defined in arpa/nameser.h) is the size of - * the type and class portions, which is fixed. Therefore, - * we can skip the question section by skipping the - * name (at the beginning) and then advancing QFIXEDSZ. - * After this calculation, cp points to the start of the - * answer section, which is a list of NS records. - */ - cp += skipName (cp, endOfMsg) + QFIXEDSZ; - - count = ntohs (response.hdr.ancount) + - ntohs (response.hdr.nscount); - while ((--count >= 0) /* still more records */ - && (cp < endOfMsg)) - { /* still inside the packet */ - - - /* Skip to the data portion of the resource record */ - cp += skipToData (cp, &type, &class, &ttl, &dlen, endOfMsg); - - if (type == requested_type) - { - switch (requested_type) - { - case (T_LOC): - loc_ntoa (cp, result); - return result; - break; - case (T_PTR): - ptrList[ptrNum] = (char *) malloc (MAXDNAME); - if (ptrList[ptrNum] == NULL) - { - panic ("Malloc failed"); - } - - if (dn_expand (response.buf, /* Start of the packet */ - endOfMsg, /* End of the packet */ - cp, /* Position in the packet */ - (u_char *) ptrList[ptrNum], /* Result */ - MAXDNAME) /* size of ptrList buffer */ - < 0) - { /* Negative: error */ - panic ("dn_expand failed"); - } - - /* - * Check the name we've just unpacked and add it to - * the list if it is not a duplicate. - * If it is a duplicate, just ignore it. - */ - for (i = 0, dup = 0; (i < ptrNum) && !dup; i++) - dup = !strcasecmp (ptrList[i], ptrList[ptrNum]); - if (dup) - free (ptrList[ptrNum]); - else - ptrNum++; - strcpy (result, ptrList[0]); - return result; - break; - case (T_A): - bcopy ((char *) cp, (char *) &addr, INADDRSZ); - strcat (result, " "); - strcat (result, inet_ntoa (addr)); - found = 1; - break; - default: - sprintf (message, "Unexpected type %u", requested_type); - panic (message); - } - } - - /* Advance the pointer over the resource record data */ - cp += dlen; - - } /* end of while */ - if (found) - return result; -else -return NULL; -} - -struct list_in_addr * -findA (domain) - char *domain; -{ - - struct list_in_addr *result, *end; - - union - { - HEADER hdr; /* defined in resolv.h */ - u_char buf[PACKETSZ]; /* defined in arpa/nameser.h */ - } - response; /* response buffers */ - int responseLen; /* buffer length */ - - u_char *cp; /* character pointer to parse DNS packet */ - u_char *endOfMsg; /* need to know the end of the message */ - u_short class; /* classes defined in arpa/nameser.h */ - u_short type; /* types defined in arpa/nameser.h */ - u_int32_t ttl; /* resource record time to live */ - u_short dlen; /* size of resource record data */ - - int count; /* misc variables */ - - struct in_addr addr; - - end = NULL; - result = NULL; - - /* - * Look up the records for the given domain name. - * We expect the domain to be a fully qualified name, so - * we use res_query(). If we wanted the resolver search - * algorithm, we would have used res_search() instead. - */ - if ((responseLen = - res_query (domain, /* the domain we care about */ - C_IN, /* Internet class records */ - T_A, - (u_char *) & response, /*response buffer */ - sizeof (response))) /*buffer size */ - < 0) - { /*If negative */ - rr_errno = h_errno; - return NULL; - } - - /* - * Keep track of the end of the message so we don't - * pass it while parsing the response. responseLen is - * the value returned by res_query. - */ - endOfMsg = response.buf + responseLen; - - /* - * Set a pointer to the start of the question section, - * which begins immediately AFTER the header. - */ - cp = response.buf + sizeof (HEADER); - - /* - * Skip over the whole question section. The question - * section is comprised of a name, a type, and a class. - * QFIXEDSZ (defined in arpa/nameser.h) is the size of - * the type and class portions, which is fixed. Therefore, - * we can skip the question section by skipping the - * name (at the beginning) and then advancing QFIXEDSZ. - * After this calculation, cp points to the start of the - * answer section, which is a list of NS records. - */ - cp += skipName (cp, endOfMsg) + QFIXEDSZ; - - count = ntohs (response.hdr.ancount) + - ntohs (response.hdr.nscount); - while ((--count >= 0) /* still more records */ - && (cp < endOfMsg)) - { /* still inside the packet */ - - - /* Skip to the data portion of the resource record */ - cp += skipToData (cp, &type, &class, &ttl, &dlen, endOfMsg); - - if (type == T_A) - { - bcopy ((char *) cp, (char *) &addr, INADDRSZ); - if (end == NULL) - { - result = (void *) malloc (sizeof (struct list_in_addr)); - result->addr = addr; - result->next = NULL; - end = result; - } - else - { - end->next = (void *) malloc (sizeof (struct list_in_addr)); - end = end->next; - end->addr = addr; - end->next = NULL; - } - } - - /* Advance the pointer over the resource record data */ - cp += dlen; - - } /* end of while */ - return result; -} diff --git a/contrib/query-loc-0.3.0/loc.h b/contrib/query-loc-0.3.0/loc.h deleted file mode 100644 index 981f5e9685..0000000000 --- a/contrib/query-loc-0.3.0/loc.h +++ /dev/null @@ -1,78 +0,0 @@ -/* $Id: loc.h,v 1.1.2.1 2005/04/01 06:14:00 marka Exp $ */ - -#define VERSION "0.3.0" - -#include "config.h" - -/* Probably too many inclusions but this is to keep 'gcc -Wall' happy... */ -#include -#include -#include -#include -#include -#include -#include -#include -#include -#include -#include -#include -#include -#include - -#ifndef FALSE -#define FALSE 0 -#endif -#ifndef TRUE -#define TRUE 1 -#endif - -#if SIZEOF_LONG == 4 -#define u_int32_t unsigned long -#ifndef int32_t -#define int32_t long -#endif -#else -#define u_int32_t unsigned int -#ifndef int32_t -#define int32_t int -#endif -#endif - -#if SIZEOF_CHAR == 1 -#define u_int8_t unsigned char -#ifndef int8_t -#define int8_t char -#endif -#else -#if SIZEOF_SHORT == 1 -#define u_int8_t unsigned short -#ifndef int8_t -#define int8_t short -#endif -#else -#error "No suitable native type for storing bytes" -#endif -#endif - -#ifndef INADDR_NONE -#define INADDR_NONE (in_addr_t)-1 -#endif - -struct list_in_addr - { - struct in_addr addr; - void *next; - }; - -void usage (); -void panic (); - -char *getlocbyname (); -char *getlocbyaddr (); -char *getlocbynet (); -char *findRR (); -struct list_in_addr *findA (); - -extern char *progname; -extern short debug; diff --git a/contrib/query-loc-0.3.0/loc_ntoa.c b/contrib/query-loc-0.3.0/loc_ntoa.c deleted file mode 100644 index 21eada3e31..0000000000 --- a/contrib/query-loc-0.3.0/loc_ntoa.c +++ /dev/null @@ -1,248 +0,0 @@ -/* Stolen from BIND */ - -/* - * Copyright (c) 1985 - * The Regents of the University of California. All rights reserved. - * - * Redistribution and use in source and binary forms, with or without - * modification, are permitted provided that the following conditions - * are met: - * 1. Redistributions of source code must retain the above copyright - * notice, this list of conditions and the following disclaimer. - * 2. Redistributions in binary form must reproduce the above copyright - * notice, this list of conditions and the following disclaimer in the - * documentation and/or other materials provided with the distribution. - * 3. All advertising materials mentioning features or use of this software - * must display the following acknowledgement: - * This product includes software developed by the University of - * California, Berkeley and its contributors. - * 4. Neither the name of the University nor the names of its contributors - * may be used to endorse or promote products derived from this software - * without specific prior written permission. - * - * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND - * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE - * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE - * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE - * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL - * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS - * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) - * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT - * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY - * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF - * SUCH DAMAGE. - */ - -/* - * Portions Copyright (c) 1993 by Digital Equipment Corporation. - * - * Permission to use, copy, modify, and distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies, and that - * the name of Digital Equipment Corporation not be used in advertising or - * publicity pertaining to distribution of the document or software without - * specific, written prior permission. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND DIGITAL EQUIPMENT CORP. DISCLAIMS ALL - * WARRANTIES WITH REGARD TO THIS SOFTWARE, INCLUDING ALL IMPLIED WARRANTIES - * OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL DIGITAL EQUIPMENT - * CORPORATION BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL - * DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR - * PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS - * ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS - * SOFTWARE. - */ - -/* - * Portions Copyright (c) 1995 by International Business Machines, Inc. - * - * International Business Machines, Inc. (hereinafter called IBM) grants - * permission under its copyrights to use, copy, modify, and distribute this - * Software with or without fee, provided that the above copyright notice and - * all paragraphs of this notice appear in all copies, and that the name of IBM - * not be used in connection with the marketing of any product incorporating - * the Software or modifications thereof, without specific, written prior - * permission. - * - * To the extent it has a right to do so, IBM grants an immunity from suit - * under its patents, if any, for the use, sale or manufacture of products to - * the extent that such products are used for performing Domain Name System - * dynamic updates in TCP/IP networks by means of the Software. No immunity is - * granted for any product per se or for any other function of any product. - * - * THE SOFTWARE IS PROVIDED "AS IS", AND IBM DISCLAIMS ALL WARRANTIES, - * INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A - * PARTICULAR PURPOSE. IN NO EVENT SHALL IBM BE LIABLE FOR ANY SPECIAL, - * DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER ARISING - * OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE, EVEN - * IF IBM IS APPRISED OF THE POSSIBILITY OF SUCH DAMAGES. - */ - -/* - * Portions Copyright (c) 1996-1999 by Internet Software Consortium. - * - * Permission to use, copy, modify, and distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND INTERNET SOFTWARE CONSORTIUM DISCLAIMS - * ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES - * OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL INTERNET SOFTWARE - * CONSORTIUM BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL - * DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR - * PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS - * ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS - * SOFTWARE. - */ - -#include -#include -#include - -#include -#include -#include - -#include -#include -#include -#include -#include -#include -#include -#include -#include - -#include "loc.h" - -const char *precsize_ntoa(); - -/* takes an on-the-wire LOC RR and formats it in a human readable format. */ -const char * -loc_ntoa(binary, ascii) - const u_char *binary; - char *ascii; -{ - static char *error = "?"; - static char tmpbuf[sizeof -"1000 60 60.000 N 1000 60 60.000 W -12345678.00m 90000000.00m 90000000.00m 90000000.00m"]; - const u_char *cp = binary; - - int latdeg, latmin, latsec, latsecfrac; - int longdeg, longmin, longsec, longsecfrac; - char northsouth, eastwest; - int altmeters, altfrac, altsign; - - const u_int32_t referencealt = 100000 * 100; - - int32_t latval, longval, altval; - u_int32_t templ; - u_int8_t sizeval, hpval, vpval, versionval; - - char *sizestr, *hpstr, *vpstr; - - versionval = *cp++; - - if (ascii == NULL) - ascii = tmpbuf; - - if (versionval) { - (void) sprintf(ascii, "; error: unknown LOC RR version"); - return (ascii); - } - - sizeval = *cp++; - - hpval = *cp++; - vpval = *cp++; - - GETLONG(templ, cp); - latval = (templ - ((unsigned)1<<31)); - - GETLONG(templ, cp); - longval = (templ - ((unsigned)1<<31)); - - GETLONG(templ, cp); - if (templ < referencealt) { /* below WGS 84 spheroid */ - altval = referencealt - templ; - altsign = -1; - } else { - altval = templ - referencealt; - altsign = 1; - } - - if (latval < 0) { - northsouth = 'S'; - latval = -latval; - } else - northsouth = 'N'; - - latsecfrac = latval % 1000; - latval = latval / 1000; - latsec = latval % 60; - latval = latval / 60; - latmin = latval % 60; - latval = latval / 60; - latdeg = latval; - - if (longval < 0) { - eastwest = 'W'; - longval = -longval; - } else - eastwest = 'E'; - - longsecfrac = longval % 1000; - longval = longval / 1000; - longsec = longval % 60; - longval = longval / 60; - longmin = longval % 60; - longval = longval / 60; - longdeg = longval; - - altfrac = altval % 100; - altmeters = (altval / 100) * altsign; - - if ((sizestr = strdup(precsize_ntoa(sizeval))) == NULL) - sizestr = error; - if ((hpstr = strdup(precsize_ntoa(hpval))) == NULL) - hpstr = error; - if ((vpstr = strdup(precsize_ntoa(vpval))) == NULL) - vpstr = error; - - sprintf(ascii, - "%d %.2d %.2d.%.3d %c %d %.2d %.2d.%.3d %c %d.%.2dm %sm %sm %sm", - latdeg, latmin, latsec, latsecfrac, northsouth, - longdeg, longmin, longsec, longsecfrac, eastwest, - altmeters, altfrac, sizestr, hpstr, vpstr); - - if (sizestr != error) - free(sizestr); - if (hpstr != error) - free(hpstr); - if (vpstr != error) - free(vpstr); - - return (ascii); -} - -static unsigned int poweroften[10] = {1, 10, 100, 1000, 10000, 100000, - 1000000,10000000,100000000,1000000000}; - -/* takes an XeY precision/size value, returns a string representation. */ -const char * -precsize_ntoa(prec) - u_int8_t prec; -{ - static char retbuf[sizeof "90000000.00"]; /* XXX nonreentrant */ - unsigned long val; - int mantissa, exponent; - - mantissa = (int)((prec >> 4) & 0x0f) % 10; - exponent = (int)((prec >> 0) & 0x0f) % 10; - - val = mantissa * poweroften[exponent]; - - (void) sprintf(retbuf, "%ld.%.2ld", val/100, val%100); - return (retbuf); -} - diff --git a/contrib/query-loc-0.3.0/query-loc.1 b/contrib/query-loc-0.3.0/query-loc.1 deleted file mode 100644 index 97eb4362c0..0000000000 --- a/contrib/query-loc-0.3.0/query-loc.1 +++ /dev/null @@ -1,55 +0,0 @@ -.\" Hey, EMACS: -*- nroff -*- -.\" First parameter, NAME, should be all caps -.\" Second parameter, SECTION, should be 1-8, maybe w/ subsection -.\" other parameters are allowed: see man(7), man(1) -.TH QUERY-LOC SECTION "January 11, 2005" -.\" Please adjust this date whenever revising the manpage. -.\" -.\" Some roff macros, for reference: -.\" .nh disable hyphenation -.\" .hy enable hyphenation -.\" .ad l left justify -.\" .ad b justify to both left and right margins -.\" .nf disable filling -.\" .fi enable filling -.\" .br insert line break -.\" .sp insert n+1 empty lines -.\" for manpage-specific macros, see man(7) -.SH NAME -query-loc \- to retrieve and display the location information in the DNS -.SH SYNOPSIS -.B query-loc -.RI [-v] [-d nnn] " host" -.SH DESCRIPTION -This manual page documents briefly the -.B query-loc -command. -.PP -.\" TeX users may be more comfortable with the \fB\fP and -.\" \fI\fP escape sequences to invode bold face and italics, -.\" respectively. -\fBquery-loc\fP is a program to retrieve and display the location -information in the DNS. - -It uses the algorithms described in -RFC 1876 (and RFC 1101 to get the network names). -You can find examples of networks wchich implement this scheme -in the ADDRESSES file. - -.SH OPTIONS -.TP -.B \-v -Verbose mode. -.TP -.B \-d nnn -Debug mode. Displays the RFC's algorithm - -.SH BUGS - -Very few hosts have location information. - -.SH AUTHOR -This manual page was written by Stephane Bortzmeyer -. - -.\" $Id: query-loc.1,v 1.1 2005/04/01 05:35:01 marka Exp $ diff --git a/contrib/query-loc-0.3.0/query-loc.c b/contrib/query-loc-0.3.0/query-loc.c deleted file mode 100644 index 3a6af75639..0000000000 --- a/contrib/query-loc-0.3.0/query-loc.c +++ /dev/null @@ -1,98 +0,0 @@ -#include "loc.h" - -/* $Id: query-loc.c,v 1.1.2.1 2005/04/01 06:14:01 marka Exp $ */ - -/* Global variables */ -char *progname; -short debug; - -int -main (argc, argv) - int argc; - char *argv[]; -{ - extern char *optarg; - extern int optind; - - short verbose = FALSE; - char *host; - - char ch; - - char *loc = NULL; - struct in_addr addr; - struct hostent *hp; - - progname = argv[0]; - while ((ch = getopt (argc, argv, "vd:")) != EOF) - { - switch (ch) - { - case 'v': - verbose = TRUE; - break; - case 'd': - debug = atoi (optarg); - if (debug <= 0) - { - (void) fprintf (stderr, - "%s: illegal debug value.\n", progname); - exit (2); - } - break; - default: - usage (); - } - } - argc -= optind; - argv += optind; - if (argc != 1) - { - usage (); - } - if (verbose || debug) - { - printf ("\nThis is %s, version %s.\n\n", progname, VERSION); - } - host = argv[0]; - (void) res_init (); - - if ((addr.s_addr = inet_addr (host)) == INADDR_NONE) - { - if (debug >= 1) - printf ("%s is a name\n", host); - loc = getlocbyname (host, FALSE); - } - else - { - if (debug >= 1) - printf ("%s is an IP address ", host); - hp = (struct hostent *) gethostbyaddr - ((char *) &addr, sizeof (addr), AF_INET); - if (hp) - { - if (debug >= 1) - printf ("and %s is its official name\n", - hp->h_name); - loc = getlocbyname (hp->h_name, FALSE); - } - else - { - if (debug >= 1) - printf ("which has no name\n"); - loc = getlocbyaddr (addr, NULL); - } - } - if (loc == NULL) - { - printf ("No LOCation found for %s\n", host); - exit (1); - } - else - { - if (verbose || debug) - printf ("LOCation for %s is ", host); - printf ("%s\n", loc); - exit (0); - } -} diff --git a/contrib/query-loc-0.4.0/ADDRESSES b/contrib/query-loc-0.4.0/ADDRESSES index 49fb7d8315..ec5aef89da 100644 --- a/contrib/query-loc-0.4.0/ADDRESSES +++ b/contrib/query-loc-0.4.0/ADDRESSES @@ -13,4 +13,4 @@ nikhef.nl yahoo.com nic.af -$Id: ADDRESSES,v 1.1 2008/02/15 01:47:15 marka Exp $ +$Id: ADDRESSES,v 1.1.32.1 2008/04/28 04:42:07 marka Exp $ diff --git a/contrib/query-loc-0.4.0/INSTALL b/contrib/query-loc-0.4.0/INSTALL index 97e740b3f1..36aae98353 100644 --- a/contrib/query-loc-0.4.0/INSTALL +++ b/contrib/query-loc-0.4.0/INSTALL @@ -6,4 +6,4 @@ which I provide, if not found. Tested on Linux (i386 and Alpha), Solaris (Sparc) and Digital Unix (Alpha). -$Id: INSTALL,v 1.1 2008/02/15 01:47:15 marka Exp $ +$Id: INSTALL,v 1.1.32.1 2008/04/28 04:42:07 marka Exp $ diff --git a/contrib/query-loc-0.4.0/Makefile.in b/contrib/query-loc-0.4.0/Makefile.in index eefa2acbab..6b3528fff3 100644 --- a/contrib/query-loc-0.4.0/Makefile.in +++ b/contrib/query-loc-0.4.0/Makefile.in @@ -1,4 +1,4 @@ -# $Id: Makefile.in,v 1.1 2008/02/15 01:47:15 marka Exp $ +# $Id: Makefile.in,v 1.1.32.1 2008/04/28 04:42:07 marka Exp $ CC=@CC@ CFLAGS=@CFLAGS@ LIBS=@LIBS@ diff --git a/contrib/query-loc-0.4.0/README b/contrib/query-loc-0.4.0/README index 250b378479..7634faf8b1 100644 --- a/contrib/query-loc-0.4.0/README +++ b/contrib/query-loc-0.4.0/README @@ -16,6 +16,6 @@ . Thanks to Roland Dirlewanger for extensive patching. -$Id: README,v 1.1 2008/02/15 01:47:15 marka Exp $ +$Id: README,v 1.1.32.1 2008/04/28 04:42:07 marka Exp $ diff --git a/contrib/query-loc-0.4.0/config.h.in b/contrib/query-loc-0.4.0/config.h.in index d4366392a6..b6e8e63df3 100644 --- a/contrib/query-loc-0.4.0/config.h.in +++ b/contrib/query-loc-0.4.0/config.h.in @@ -1,5 +1,5 @@ /* config.h.in. Generated from configure.in by autoheader. */ -/* $Id: config.h.in,v 1.1 2008/02/15 01:47:15 marka Exp $ */ +/* $Id: config.h.in,v 1.1.32.1 2008/04/28 04:42:07 marka Exp $ */ /* Define to 1 if you have the header file. */ diff --git a/contrib/query-loc-0.4.0/configure.in b/contrib/query-loc-0.4.0/configure.in index 2530fb0650..2fb0280671 100644 --- a/contrib/query-loc-0.4.0/configure.in +++ b/contrib/query-loc-0.4.0/configure.in @@ -1,5 +1,5 @@ dnl Process this file with autoconf to produce a configure script. -AC_RELEASE("$Id: configure.in,v 1.1 2008/02/15 01:47:15 marka Exp $") +AC_RELEASE("$Id: configure.in,v 1.1.32.1 2008/04/28 04:42:07 marka Exp $") AC_INIT(query-loc.c) dnl Checks for programs. diff --git a/contrib/query-loc-0.4.0/loc.c b/contrib/query-loc-0.4.0/loc.c index 57e37370fc..6586651b21 100644 --- a/contrib/query-loc-0.4.0/loc.c +++ b/contrib/query-loc-0.4.0/loc.c @@ -1,6 +1,6 @@ #include "loc.h" -/* $Id: loc.c,v 1.1 2008/02/15 01:47:15 marka Exp $ */ +/* $Id: loc.c,v 1.1.32.1 2008/04/28 04:42:07 marka Exp $ */ /* Global variables */ diff --git a/contrib/query-loc-0.4.0/loc.h b/contrib/query-loc-0.4.0/loc.h index c9b74db594..585bf9aabb 100644 --- a/contrib/query-loc-0.4.0/loc.h +++ b/contrib/query-loc-0.4.0/loc.h @@ -1,4 +1,4 @@ -/* $Id: loc.h,v 1.1 2008/02/15 01:47:15 marka Exp $ */ +/* $Id: loc.h,v 1.1.32.1 2008/04/28 04:42:07 marka Exp $ */ #define VERSION "0.4.0" diff --git a/contrib/query-loc-0.4.0/query-loc.1 b/contrib/query-loc-0.4.0/query-loc.1 index df55b4d815..70affa1d9c 100644 --- a/contrib/query-loc-0.4.0/query-loc.1 +++ b/contrib/query-loc-0.4.0/query-loc.1 @@ -52,4 +52,4 @@ Very few hosts have location information. This manual page was written by Stephane Bortzmeyer . -.\" $Id: query-loc.1,v 1.1 2008/02/15 01:47:15 marka Exp $ +.\" $Id: query-loc.1,v 1.1.32.1 2008/04/28 04:42:07 marka Exp $ diff --git a/contrib/query-loc-0.4.0/query-loc.c b/contrib/query-loc-0.4.0/query-loc.c index 2492d5b0e4..b4e1fe19ad 100644 --- a/contrib/query-loc-0.4.0/query-loc.c +++ b/contrib/query-loc-0.4.0/query-loc.c @@ -1,6 +1,6 @@ #include "loc.h" -/* $Id: query-loc.c,v 1.1 2008/02/15 01:47:15 marka Exp $ */ +/* $Id: query-loc.c,v 1.1.32.1 2008/04/28 04:42:07 marka Exp $ */ /* Global variables */ char *progname; diff --git a/contrib/query-loc-0.4.0/reconf b/contrib/query-loc-0.4.0/reconf index c1cf732240..17ecb19196 100755 --- a/contrib/query-loc-0.4.0/reconf +++ b/contrib/query-loc-0.4.0/reconf @@ -1,6 +1,6 @@ #!/bin/sh -# $Id: reconf,v 1.1 2008/02/15 01:47:15 marka Exp $ +# $Id: reconf,v 1.1.32.1 2008/04/28 04:42:07 marka Exp $ autoreconf # We do not use automake but we need its install-sh file. We do not From ed56f598d6dbaa010a0857feb0d110dda8a64a37 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 04:46:01 +0000 Subject: [PATCH 026/137] add From 2d6f7c8c0ad8e5bf3edcc5bae4f4f97a1e90c6ec Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 04:47:35 +0000 Subject: [PATCH 027/137] add missing period --- doc/arm/Bv9ARM-book.xml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/doc/arm/Bv9ARM-book.xml b/doc/arm/Bv9ARM-book.xml index 67f8c89736..a1f35bb7ed 100644 --- a/doc/arm/Bv9ARM-book.xml +++ b/doc/arm/Bv9ARM-book.xml @@ -18,7 +18,7 @@ - PERFORMANCE OF THIS SOFTWARE. --> - + BIND 9 Administrator Reference Manual @@ -5873,7 +5873,7 @@ delegation. $GENERATE 1-2 0 NS SERVER$.EXAMPLE. $GENERATE 1-127 $ CNAME $.0 is equivalent to -0.0.0.192.IN-ADDR.ARPA NS SERVER1.EXAMPLE. +0.0.0.192.IN-ADDR.ARPA. NS SERVER1.EXAMPLE. 0.0.0.192.IN-ADDR.ARPA. NS SERVER2.EXAMPLE. 1.0.0.192.IN-ADDR.ARPA. CNAME 1.0.0.0.192.IN-ADDR.ARPA. 2.0.0.192.IN-ADDR.ARPA. CNAME 2.0.0.0.192.IN-ADDR.ARPA. From c72fcab80b0b2cd670da397eadd1fea1ab6f1499 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 04:52:06 +0000 Subject: [PATCH 028/137] 2341. [bug] libbind: add missing -I../include for off source tree builds. [RT #17606] --- CHANGES | 3 +++ lib/bind/bsd/Makefile.in | 4 ++-- lib/bind/dst/Makefile.in | 4 ++-- lib/bind/inet/Makefile.in | 4 ++-- lib/bind/irs/Makefile.in | 4 ++-- lib/bind/isc/Makefile.in | 4 ++-- lib/bind/nameser/Makefile.in | 4 ++-- lib/bind/resolv/Makefile.in | 4 ++-- 8 files changed, 17 insertions(+), 14 deletions(-) diff --git a/CHANGES b/CHANGES index a0f473028a..805625dbb3 100644 --- a/CHANGES +++ b/CHANGES @@ -10,6 +10,9 @@ 2343. [bug] (Seemingly) duplicate IPv6 entries could be created in ADB. [RT #17837] +2341. [bug] libbind: add missing -I../include for off source + tree builds. [RT #17606] + 2340. [port] openbsd: interface configuration. [RT #17700] 2335. [port] sunos: libbind and *printf() support for long long. diff --git a/lib/bind/bsd/Makefile.in b/lib/bind/bsd/Makefile.in index dd7b616e48..0e8bccc993 100644 --- a/lib/bind/bsd/Makefile.in +++ b/lib/bind/bsd/Makefile.in @@ -13,7 +13,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: Makefile.in,v 1.6.206.1 2004/03/06 08:13:22 marka Exp $ +# $Id: Makefile.in,v 1.6.206.2 2008/04/28 04:52:06 marka Exp $ srcdir= @srcdir@ VPATH = @srcdir@ @@ -34,6 +34,6 @@ SRCS= daemon.c ftruncate.c gettimeofday.c mktemp.c putenv.c \ TARGETS= ${OBJS} -CINCLUDES= -I.. -I${srcdir}/../include +CINCLUDES= -I.. -I../include -I${srcdir}/../include @BIND9_MAKE_RULES@ diff --git a/lib/bind/dst/Makefile.in b/lib/bind/dst/Makefile.in index 8b30659170..bf8158b222 100644 --- a/lib/bind/dst/Makefile.in +++ b/lib/bind/dst/Makefile.in @@ -13,7 +13,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: Makefile.in,v 1.5.206.1 2004/03/06 08:13:22 marka Exp $ +# $Id: Makefile.in,v 1.5.206.2 2008/04/28 04:52:06 marka Exp $ srcdir= @srcdir@ VPATH = @srcdir@ @@ -26,7 +26,7 @@ TARGETS= ${OBJS} CRYPTFLAGS= -DCYLINK_DSS -DHMAC_MD5 -DUSE_MD5 -DDNSSAFE -CINCLUDES= -I.. -I${srcdir}/../include ${CRYPTINCL} +CINCLUDES= -I.. -I../include -I${srcdir}/../include ${CRYPTINCL} CDEFINES= ${CRYPTFLAGS} @BIND9_MAKE_RULES@ diff --git a/lib/bind/inet/Makefile.in b/lib/bind/inet/Makefile.in index 96698fde7f..97dfd60d29 100644 --- a/lib/bind/inet/Makefile.in +++ b/lib/bind/inet/Makefile.in @@ -13,7 +13,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: Makefile.in,v 1.4.206.1 2004/03/06 08:13:23 marka Exp $ +# $Id: Makefile.in,v 1.4.206.2 2008/04/28 04:52:06 marka Exp $ srcdir= @srcdir@ VPATH = @srcdir@ @@ -30,6 +30,6 @@ SRCS= inet_addr.c inet_cidr_ntop.c inet_cidr_pton.c inet_data.c \ TARGETS= ${OBJS} -CINCLUDES= -I.. -I${srcdir}/../include +CINCLUDES= -I.. -I../include -I${srcdir}/../include @BIND9_MAKE_RULES@ diff --git a/lib/bind/irs/Makefile.in b/lib/bind/irs/Makefile.in index 9695435ba6..e6e0205131 100644 --- a/lib/bind/irs/Makefile.in +++ b/lib/bind/irs/Makefile.in @@ -13,7 +13,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: Makefile.in,v 1.7.206.3 2004/12/07 00:38:35 marka Exp $ +# $Id: Makefile.in,v 1.7.206.4 2008/04/28 04:52:06 marka Exp $ srcdir= @srcdir@ VPATH = @srcdir@ @@ -65,6 +65,6 @@ WANT_IRS_THREADSGR_OBJS=getgrent_r.@O@ TARGETS= ${OBJS} -CINCLUDES= -I.. -I${srcdir}/../include +CINCLUDES= -I.. -I../include -I${srcdir}/../include @BIND9_MAKE_RULES@ diff --git a/lib/bind/isc/Makefile.in b/lib/bind/isc/Makefile.in index d8e8889ab3..09bad47439 100644 --- a/lib/bind/isc/Makefile.in +++ b/lib/bind/isc/Makefile.in @@ -13,7 +13,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: Makefile.in,v 1.6.206.1 2004/03/06 08:13:23 marka Exp $ +# $Id: Makefile.in,v 1.6.206.2 2008/04/28 04:52:06 marka Exp $ srcdir= @srcdir@ VPATH = @srcdir@ @@ -30,6 +30,6 @@ SRCS= assertions.c base64.c bitncmp.c ctl_clnt.c ctl_p.c \ TARGETS= ${OBJS} -CINCLUDES= -I.. -I${srcdir}/../include +CINCLUDES= -I.. -I../include -I${srcdir}/../include @BIND9_MAKE_RULES@ diff --git a/lib/bind/nameser/Makefile.in b/lib/bind/nameser/Makefile.in index aa4bc6cf6b..4410fda49f 100644 --- a/lib/bind/nameser/Makefile.in +++ b/lib/bind/nameser/Makefile.in @@ -13,7 +13,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: Makefile.in,v 1.4.206.1 2004/03/15 01:02:45 marka Exp $ +# $Id: Makefile.in,v 1.4.206.2 2008/04/28 04:52:06 marka Exp $ srcdir= @srcdir@ VPATH = @srcdir@ @@ -26,6 +26,6 @@ SRCS= ns_date.c ns_name.c ns_netint.c ns_parse.c ns_print.c \ TARGETS= ${OBJS} -CINCLUDES= -I.. -I${srcdir}/../include +CINCLUDES= -I.. -I../include -I${srcdir}/../include @BIND9_MAKE_RULES@ diff --git a/lib/bind/resolv/Makefile.in b/lib/bind/resolv/Makefile.in index a235fbc7a5..13ae6be6ae 100644 --- a/lib/bind/resolv/Makefile.in +++ b/lib/bind/resolv/Makefile.in @@ -13,7 +13,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: Makefile.in,v 1.3.206.3 2005/07/29 00:13:09 marka Exp $ +# $Id: Makefile.in,v 1.3.206.4 2008/04/28 04:52:06 marka Exp $ srcdir= @srcdir@ VPATH = @srcdir@ @@ -28,7 +28,7 @@ SRCS= herror.c mtctxres.c res_comp.c res_data.c res_debug.c \ TARGETS= ${OBJS} -CINCLUDES= -I.. -I${srcdir}/../include +CINCLUDES= -I.. -I../include -I${srcdir}/../include CWARNINGS= @BIND9_MAKE_RULES@ From 3bd51537a433ccb3161ea9d21c7a01bb3d3b38ff Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 04:54:26 +0000 Subject: [PATCH 029/137] 2344. [bug] Improve "logging{ file ...; };" documentation. [RT #17888] --- CHANGES | 3 +++ lib/isccfg/namedconf.c | 30 +++++++++++++++++++++--------- 2 files changed, 24 insertions(+), 9 deletions(-) diff --git a/CHANGES b/CHANGES index 805625dbb3..c29418dd0a 100644 --- a/CHANGES +++ b/CHANGES @@ -7,6 +7,9 @@ 2347. [bug] Delete now traverses the RB tree in the canonical order. [RT #17451] +2344. [bug] Improve "logging{ file ...; };" documentation. + [RT #17888] + 2343. [bug] (Seemingly) duplicate IPv6 entries could be created in ADB. [RT #17837] diff --git a/lib/isccfg/namedconf.c b/lib/isccfg/namedconf.c index 1943af3dbe..9ce6af2d5b 100644 --- a/lib/isccfg/namedconf.c +++ b/lib/isccfg/namedconf.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: namedconf.c,v 1.21.44.36 2008/01/24 23:45:28 tbox Exp $ */ +/* $Id: namedconf.c,v 1.21.44.37 2008/04/28 04:54:26 marka Exp $ */ #include @@ -1564,6 +1564,7 @@ static isc_result_t parse_logversions(cfg_parser_t *pctx, const cfg_type_t *type, cfg_obj_t **ret) { return (parse_enum_or_other(pctx, type, &cfg_type_uint32, ret)); } + static cfg_type_t cfg_type_logversions = { "logversions", parse_logversions, cfg_print_ustring, cfg_doc_terminal, &cfg_rep_string, logversions_enums @@ -1637,8 +1638,19 @@ print_logfile(cfg_printer_t *pctx, const cfg_obj_t *obj) { } } + +static void +doc_logfile(cfg_printer_t *pctx, const cfg_type_t *type) { + UNUSED(type); + cfg_print_cstr(pctx, ""); + cfg_print_chars(pctx, " ", 1); + cfg_print_cstr(pctx, "[ versions ( \"unlimited\" | ) ]"); + cfg_print_chars(pctx, " ", 1); + cfg_print_cstr(pctx, "[ size ]"); +} + static cfg_type_t cfg_type_logfile = { - "log_file", parse_logfile, print_logfile, cfg_doc_terminal, + "log_file", parse_logfile, print_logfile, doc_logfile, &cfg_rep_tuple, logfile_fields }; @@ -1670,8 +1682,8 @@ static cfg_type_t cfg_type_lwres_view = { }; static cfg_type_t cfg_type_lwres_searchlist = { - "lwres_searchlist", cfg_parse_bracketed_list, cfg_print_bracketed_list, cfg_doc_bracketed_list, - &cfg_rep_list, &cfg_type_astring }; + "lwres_searchlist", cfg_parse_bracketed_list, cfg_print_bracketed_list, + cfg_doc_bracketed_list, &cfg_rep_list, &cfg_type_astring }; static cfg_clausedef_t lwres_clauses[] = { @@ -1783,15 +1795,15 @@ doc_sockaddrnameport(cfg_printer_t *pctx, const cfg_type_t *type) { cfg_print_chars(pctx, "( ", 2); cfg_print_cstr(pctx, ""); cfg_print_chars(pctx, " ", 1); - cfg_print_cstr(pctx, "[port ]"); + cfg_print_cstr(pctx, "[ port ]"); cfg_print_chars(pctx, " | ", 3); cfg_print_cstr(pctx, ""); cfg_print_chars(pctx, " ", 1); - cfg_print_cstr(pctx, "[port ]"); + cfg_print_cstr(pctx, "[ port ]"); cfg_print_chars(pctx, " | ", 3); cfg_print_cstr(pctx, ""); cfg_print_chars(pctx, " ", 1); - cfg_print_cstr(pctx, "[port ]"); + cfg_print_cstr(pctx, "[ port ]"); cfg_print_chars(pctx, " )", 2); } @@ -1869,11 +1881,11 @@ doc_masterselement(cfg_printer_t *pctx, const cfg_type_t *type) { cfg_print_chars(pctx, " | ", 3); cfg_print_cstr(pctx, ""); cfg_print_chars(pctx, " ", 1); - cfg_print_cstr(pctx, "[port ]"); + cfg_print_cstr(pctx, "[ port ]"); cfg_print_chars(pctx, " | ", 3); cfg_print_cstr(pctx, ""); cfg_print_chars(pctx, " ", 1); - cfg_print_cstr(pctx, "[port ]"); + cfg_print_cstr(pctx, "[ port ]"); cfg_print_chars(pctx, " )", 2); } From f1e91e8855fbc5b295fde09e49a9dc103d3c307b Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 05:22:33 +0000 Subject: [PATCH 030/137] 2345. [bug] named-checkconf failed to detect when forwarders were set at both the options/view level and in a root zone. [RT #17671] --- CHANGES | 4 +++ lib/bind9/check.c | 75 ++++++++++++++++++++++++++++++++--------------- 2 files changed, 55 insertions(+), 24 deletions(-) diff --git a/CHANGES b/CHANGES index c29418dd0a..b174a046bb 100644 --- a/CHANGES +++ b/CHANGES @@ -7,6 +7,10 @@ 2347. [bug] Delete now traverses the RB tree in the canonical order. [RT #17451] +2345. [bug] named-checkconf failed to detect when forwarders + were set at both the options/view level and in + a root zone. [RT #17671] + 2344. [bug] Improve "logging{ file ...; };" documentation. [RT #17888] diff --git a/lib/bind9/check.c b/lib/bind9/check.c index fe9836ca4b..28b193874c 100644 --- a/lib/bind9/check.c +++ b/lib/bind9/check.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: check.c,v 1.37.6.39 2007/12/14 01:28:26 marka Exp $ */ +/* $Id: check.c,v 1.37.6.40 2008/04/28 05:22:33 marka Exp $ */ #include @@ -213,13 +213,24 @@ check_dual_stack(const cfg_obj_t *options, isc_log_t *logctx) { } static isc_result_t -check_forward(const cfg_obj_t *options, isc_log_t *logctx) { +check_forward(const cfg_obj_t *options, const cfg_obj_t *global, + isc_log_t *logctx) +{ const cfg_obj_t *forward = NULL; const cfg_obj_t *forwarders = NULL; (void)cfg_map_get(options, "forward", &forward); (void)cfg_map_get(options, "forwarders", &forwarders); + if (forwarders != NULL && global != NULL) { + const char *file = cfg_obj_file(global); + unsigned int line = cfg_obj_line(global); + cfg_obj_log(forwarders, logctx, ISC_LOG_ERROR, + "forwarders declared in root zone and " + "in general configuration: %s:%u", + file, line); + return (ISC_R_FAILURE); + } if (forward != NULL && forwarders == NULL) { cfg_obj_log(forward, logctx, ISC_LOG_ERROR, "no matching 'forwarders' statement"); @@ -693,9 +704,9 @@ typedef struct { } optionstable; static isc_result_t -check_zoneconf(const cfg_obj_t *zconfig, const cfg_obj_t *config, - isc_symtab_t *symtab, dns_rdataclass_t defclass, - isc_log_t *logctx, isc_mem_t *mctx) +check_zoneconf(const cfg_obj_t *zconfig, const cfg_obj_t *voptions, + const cfg_obj_t *config, isc_symtab_t *symtab, + dns_rdataclass_t defclass, isc_log_t *logctx, isc_mem_t *mctx) { const char *zname; const char *typestr; @@ -708,6 +719,7 @@ check_zoneconf(const cfg_obj_t *zconfig, const cfg_obj_t *config, dns_rdataclass_t zclass; dns_fixedname_t fixedname; isc_buffer_t b; + isc_boolean_t root = ISC_FALSE; static optionstable options[] = { { "allow-query", MASTERZONE | SLAVEZONE | STUBZONE }, @@ -817,7 +829,7 @@ check_zoneconf(const cfg_obj_t *zconfig, const cfg_obj_t *config, isc_buffer_init(&b, zname, strlen(zname)); isc_buffer_add(&b, strlen(zname)); tresult = dns_name_fromtext(dns_fixedname_name(&fixedname), &b, - dns_rootname, ISC_TRUE, NULL); + dns_rootname, ISC_TRUE, NULL); if (tresult != ISC_R_SUCCESS) { cfg_obj_log(zconfig, logctx, ISC_LOG_ERROR, "zone '%s': is not a valid name", zname); @@ -832,6 +844,9 @@ check_zoneconf(const cfg_obj_t *zconfig, const cfg_obj_t *config, "previous definition: %s:%u", logctx, mctx); if (tresult != ISC_R_SUCCESS) result = tresult; + if (dns_name_equal(dns_fixedname_name(&fixedname), + dns_rootname)) + root = ISC_TRUE; } /* @@ -938,7 +953,18 @@ check_zoneconf(const cfg_obj_t *zconfig, const cfg_obj_t *config, /* * Check that forwarding is reasonable. */ - if (check_forward(zoptions, logctx) != ISC_R_SUCCESS) + obj = NULL; + if (root) { + if (voptions != NULL) + (void)cfg_map_get(voptions, "forwarders", &obj); + if (obj == NULL) { + const cfg_obj_t *options = NULL; + (void)cfg_map_get(config, "options", &options); + if (options != NULL) + (void)cfg_map_get(options, "forwarders", &obj); + } + } + if (check_forward(zoptions, obj, logctx) != ISC_R_SUCCESS) result = ISC_R_FAILURE; /* @@ -1096,7 +1122,7 @@ check_servers(const cfg_obj_t *servers, isc_log_t *logctx) { } static isc_result_t -check_viewconf(const cfg_obj_t *config, const cfg_obj_t *vconfig, +check_viewconf(const cfg_obj_t *config, const cfg_obj_t *voptions, dns_rdataclass_t vclass, isc_log_t *logctx, isc_mem_t *mctx) { const cfg_obj_t *servers = NULL; @@ -1116,8 +1142,8 @@ check_viewconf(const cfg_obj_t *config, const cfg_obj_t *vconfig, if (tresult != ISC_R_SUCCESS) return (ISC_R_NOMEMORY); - if (vconfig != NULL) - (void)cfg_map_get(vconfig, "zone", &zones); + if (voptions != NULL) + (void)cfg_map_get(voptions, "zone", &zones); else (void)cfg_map_get(config, "zone", &zones); @@ -1128,7 +1154,7 @@ check_viewconf(const cfg_obj_t *config, const cfg_obj_t *vconfig, isc_result_t tresult; const cfg_obj_t *zone = cfg_listelt_value(element); - tresult = check_zoneconf(zone, config, symtab, vclass, + tresult = check_zoneconf(zone, voptions, config, symtab, vclass, logctx, mctx); if (tresult != ISC_R_SUCCESS) result = ISC_R_FAILURE; @@ -1153,9 +1179,9 @@ check_viewconf(const cfg_obj_t *config, const cfg_obj_t *vconfig, return (tresult); } - if (vconfig != NULL) { + if (voptions != NULL) { keys = NULL; - (void)cfg_map_get(vconfig, "key", &keys); + (void)cfg_map_get(voptions, "key", &keys); tresult = check_keylist(keys, symtab, logctx); if (tresult == ISC_R_EXISTS) result = ISC_R_FAILURE; @@ -1170,47 +1196,48 @@ check_viewconf(const cfg_obj_t *config, const cfg_obj_t *vconfig, /* * Check that forwarding is reasonable. */ - if (vconfig == NULL) { + if (voptions == NULL) { const cfg_obj_t *options = NULL; (void)cfg_map_get(config, "options", &options); if (options != NULL) - if (check_forward(options, logctx) != ISC_R_SUCCESS) + if (check_forward(options, NULL, + logctx) != ISC_R_SUCCESS) result = ISC_R_FAILURE; } else { - if (check_forward(vconfig, logctx) != ISC_R_SUCCESS) + if (check_forward(voptions, NULL, logctx) != ISC_R_SUCCESS) result = ISC_R_FAILURE; } /* * Check that dual-stack-servers is reasonable. */ - if (vconfig == NULL) { + if (voptions == NULL) { const cfg_obj_t *options = NULL; (void)cfg_map_get(config, "options", &options); if (options != NULL) if (check_dual_stack(options, logctx) != ISC_R_SUCCESS) result = ISC_R_FAILURE; } else { - if (check_dual_stack(vconfig, logctx) != ISC_R_SUCCESS) + if (check_dual_stack(voptions, logctx) != ISC_R_SUCCESS) result = ISC_R_FAILURE; } /* * Check that rrset-order is reasonable. */ - if (vconfig != NULL) { - if (check_order(vconfig, logctx) != ISC_R_SUCCESS) + if (voptions != NULL) { + if (check_order(voptions, logctx) != ISC_R_SUCCESS) result = ISC_R_FAILURE; } - if (vconfig != NULL) { - (void)cfg_map_get(vconfig, "server", &servers); + if (voptions != NULL) { + (void)cfg_map_get(voptions, "server", &servers); if (servers != NULL && check_servers(servers, logctx) != ISC_R_SUCCESS) result = ISC_R_FAILURE; } - if (vconfig != NULL) - tresult = check_options(vconfig, logctx, mctx); + if (voptions != NULL) + tresult = check_options(voptions, logctx, mctx); else tresult = check_options(config, logctx, mctx); if (tresult != ISC_R_SUCCESS) From bf5d3ae42a91fd41d109dfef7f9d613006cb612a Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 05:35:45 +0000 Subject: [PATCH 031/137] 2350. [port] win32: IPv6 support. [RT #17797] --- CHANGES | 2 + config.h.win32 | 6 +- lib/dns/resolver.c | 9 +- lib/isc/win32/include/isc/platform.h | 5 +- lib/isc/win32/interfaceiter.c | 229 ++++++++++++++++++++------- lib/isc/win32/net.c | 61 +------ 6 files changed, 195 insertions(+), 117 deletions(-) diff --git a/CHANGES b/CHANGES index b174a046bb..a967ef2124 100644 --- a/CHANGES +++ b/CHANGES @@ -4,6 +4,8 @@ 2356. [bug] Builtin mutex profiler was not scalable enough. [RT #17436] +2350. [port] win32: IPv6 support. [RT #17797] + 2347. [bug] Delete now traverses the RB tree in the canonical order. [RT #17451] diff --git a/config.h.win32 b/config.h.win32 index 5a61510610..2ceea196ee 100644 --- a/config.h.win32 +++ b/config.h.win32 @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: config.h.win32,v 1.6.12.11 2007/08/28 07:19:07 tbox Exp $ */ +/* $Id: config.h.win32,v 1.6.12.12 2008/04/28 05:35:44 marka Exp $ */ /* * win32 configuration file @@ -123,9 +123,7 @@ /* Define if libcrypto has DH_generate_parameters */ #define HAVE_DH_GENERATE_PARAMETERS -#define ISC_PLATFORM_NEEDSTRLCAT - -#define ISC_PLATFORM_NEEDSTRLCPY +#define WANT_IPV6 #define S_IFMT _S_IFMT /* file type mask */ #define S_IFDIR _S_IFDIR /* directory */ diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c index 16d22e08b3..2b80651bb5 100644 --- a/lib/dns/resolver.c +++ b/lib/dns/resolver.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: resolver.c,v 1.218.2.18.4.77 2008/01/17 23:45:27 tbox Exp $ */ +/* $Id: resolver.c,v 1.218.2.18.4.78 2008/04/28 05:35:45 marka Exp $ */ #include @@ -1993,6 +1993,13 @@ fctx_getaddresses(fetchctx_t *fctx) { } while (sa != NULL) { + if ((isc_sockaddr_pf(sa) == AF_INET && + fctx->res->dispatchv4 == NULL) || + (isc_sockaddr_pf(sa) == AF_INET6 && + fctx->res->dispatchv6 == NULL)) { + sa = ISC_LIST_NEXT(sa, link); + continue; + } ai = NULL; result = dns_adb_findaddrinfo(fctx->adb, sa, &ai, 0); /* XXXMLG */ diff --git a/lib/isc/win32/include/isc/platform.h b/lib/isc/win32/include/isc/platform.h index 9aa6cc700b..189c10a10b 100644 --- a/lib/isc/win32/include/isc/platform.h +++ b/lib/isc/win32/include/isc/platform.h @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: platform.h,v 1.5.12.9 2007/08/28 07:19:17 tbox Exp $ */ +/* $Id: platform.h,v 1.5.12.10 2008/04/28 05:35:45 marka Exp $ */ #ifndef ISC_PLATFORM_H #define ISC_PLATFORM_H 1 @@ -34,6 +34,7 @@ #if _MSC_VER > 1200 #define ISC_PLATFORM_HAVEIN6PKTINFO #endif +#define ISC_PLATFORM_HAVESCOPEID #define ISC_PLATFORM_NEEDPORTT #undef MSG_TRUNC #define ISC_PLATFORM_NEEDNTOP @@ -44,6 +45,8 @@ #define ISC_PLATFORM_NEEDSTRSEP #define ISC_PLATFORM_NEEDSTRLCPY +#define ISC_PLATFORM_NEEDSTRLCAT +#define ISC_PLATFORM_NEEDSTRLCPY /* * Used to control how extern data is linked; needed for Win32 platforms. diff --git a/lib/isc/win32/interfaceiter.c b/lib/isc/win32/interfaceiter.c index e70d7c1779..a14aa4152d 100644 --- a/lib/isc/win32/interfaceiter.c +++ b/lib/isc/win32/interfaceiter.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: interfaceiter.c,v 1.4.12.8 2007/08/28 07:19:17 tbox Exp $ */ +/* $Id: interfaceiter.c,v 1.4.12.9 2008/04/28 05:35:45 marka Exp $ */ /* * Note that this code will need to be revisited to support IPv6 Interfaces. @@ -62,11 +62,13 @@ struct isc_interfaceiter { int socket; INTERFACE_INFO IFData; /* Current Interface Info */ int numIF; /* Current Interface count */ - int totalIF; /* Total Number - of Interfaces */ - INTERFACE_INFO *buf; /* Buffer for WSAIoctl data. */ - unsigned int bufsize; /* Bytes allocated. */ - INTERFACE_INFO *pos; /* Current offset in IF List */ + int v4IF; /* Number of IPv4 Interfaces */ + INTERFACE_INFO *buf4; /* Buffer for WSAIoctl data. */ + unsigned int buf4size; /* Bytes allocated. */ + INTERFACE_INFO *pos4; /* Current offset in IF List */ + SOCKET_ADDRESS_LIST *buf6; + unsigned int buf6size; /* Bytes allocated. */ + unsigned int pos6; isc_interface_t current; /* Current interface data. */ isc_result_t result; /* Last result code. */ }; @@ -94,6 +96,7 @@ get_addr(unsigned int family, isc_netaddr_t *dst, struct sockaddr *src) { memcpy(&dst->type.in6, &((struct sockaddr_in6 *) src)->sin6_addr, sizeof(struct in6_addr)); + dst->zone = ((struct sockaddr_in6 *) src)->sin6_scope_id; break; default: INSIST(0); @@ -120,7 +123,15 @@ isc_interfaceiter_create(isc_mem_t *mctx, isc_interfaceiter_t **iterp) { InitSockets(); iter->mctx = mctx; - iter->buf = NULL; + iter->buf4 = NULL; + iter->buf6 = NULL; + iter->pos4 = NULL; + iter->pos6 = 0; + iter->buf6size = 0; + iter->buf4size = 0; + iter->result = ISC_R_FAILURE; + iter->numIF = 0; + iter->v4IF = 0; /* * Create an unbound datagram socket to do the @@ -128,6 +139,8 @@ isc_interfaceiter_create(isc_mem_t *mctx, isc_interfaceiter_t **iterp) { */ if ((iter->socket = socket(AF_INET, SOCK_DGRAM, 0)) < 0) { error = WSAGetLastError(); + if (error == WSAEAFNOSUPPORT) + goto inet6_only; isc__strerror(error, strbuf, sizeof(strbuf)); UNEXPECTED_ERROR(__FILE__, __LINE__, "making interface scan socket: %s", @@ -140,17 +153,17 @@ isc_interfaceiter_create(isc_mem_t *mctx, isc_interfaceiter_t **iterp) { * Get the interface configuration, allocating more memory if * necessary. */ - iter->bufsize = IFCONF_SIZE_INITIAL*sizeof(INTERFACE_INFO); + iter->buf4size = IFCONF_SIZE_INITIAL*sizeof(INTERFACE_INFO); for (;;) { - iter->buf = isc_mem_get(mctx, iter->bufsize); - if (iter->buf == NULL) { + iter->buf4 = isc_mem_get(mctx, iter->buf4size); + if (iter->buf4 == NULL) { result = ISC_R_NOMEMORY; goto alloc_failure; } if (WSAIoctl(iter->socket, SIO_GET_INTERFACE_LIST, - 0, 0, iter->buf, iter->bufsize, + 0, 0, iter->buf4, iter->buf4size, &bytesReturned, 0, 0) == SOCKET_ERROR) { error = WSAGetLastError(); @@ -174,19 +187,19 @@ isc_interfaceiter_create(isc_mem_t *mctx, isc_interfaceiter_t **iterp) { * case and retry. */ if (bytesReturned > 0 && - (bytesReturned < iter->bufsize)) + (bytesReturned < iter->buf4size)) break; } - if (iter->bufsize >= IFCONF_SIZE_MAX*sizeof(INTERFACE_INFO)) { + if (iter->buf4size >= IFCONF_SIZE_MAX*sizeof(INTERFACE_INFO)) { UNEXPECTED_ERROR(__FILE__, __LINE__, "get interface configuration: " "maximum buffer size exceeded"); result = ISC_R_UNEXPECTED; goto ioctl_failure; } - isc_mem_put(mctx, iter->buf, iter->bufsize); + isc_mem_put(mctx, iter->buf4, iter->buf4size); - iter->bufsize += IFCONF_SIZE_INCREMENT * + iter->buf4size += IFCONF_SIZE_INCREMENT * sizeof(INTERFACE_INFO); } @@ -194,23 +207,92 @@ isc_interfaceiter_create(isc_mem_t *mctx, isc_interfaceiter_t **iterp) { * A newly created iterator has an undefined position * until isc_interfaceiter_first() is called. */ - iter->pos = NULL; - iter->result = ISC_R_FAILURE; - iter->numIF = 0; - iter->totalIF = bytesReturned/sizeof(INTERFACE_INFO); + iter->v4IF = bytesReturned/sizeof(INTERFACE_INFO); - - iter->magic = IFITER_MAGIC; - *iterp = iter; /* We don't need the socket any more, so close it */ closesocket(iter->socket); + + inet6_only: + /* + * Create an unbound datagram socket to do the + * SIO_ADDRESS_LIST_QUERY WSAIoctl on. + */ + if ((iter->socket = socket(AF_INET6, SOCK_DGRAM, 0)) < 0) { + error = WSAGetLastError(); + if (error == WSAEAFNOSUPPORT) + goto inet_only; + isc__strerror(error, strbuf, sizeof(strbuf)); + UNEXPECTED_ERROR(__FILE__, __LINE__, + "making interface scan socket: %s", + strbuf); + result = ISC_R_UNEXPECTED; + goto ioctl_failure; + } + + /* + * Get the interface configuration, allocating more memory if + * necessary. + */ + iter->buf6size = sizeof(SOCKET_ADDRESS_LIST) + + IFCONF_SIZE_INITIAL*sizeof(SOCKET_ADDRESS); + + for (;;) { + iter->buf6 = isc_mem_get(mctx, iter->buf6size); + if (iter->buf6 == NULL) { + result = ISC_R_NOMEMORY; + goto ioctl_failure; + } + + if (WSAIoctl(iter->socket, SIO_ADDRESS_LIST_QUERY, + 0, 0, iter->buf6, iter->buf6size, + &bytesReturned, 0, 0) == SOCKET_ERROR) + { + error = WSAGetLastError(); + if (error != WSAEFAULT && error != WSAENOBUFS) { + errno = error; + isc__strerror(error, strbuf, sizeof(strbuf)); + UNEXPECTED_ERROR(__FILE__, __LINE__, + "sio address list query: %s", + strbuf); + result = ISC_R_UNEXPECTED; + goto ioctl6_failure; + } + /* + * EINVAL. Retry with a bigger buffer. + */ + } else + break; + + if (iter->buf6size >= IFCONF_SIZE_MAX*sizeof(SOCKET_ADDRESS)) { + UNEXPECTED_ERROR(__FILE__, __LINE__, + "get interface configuration: " + "maximum buffer size exceeded"); + result = ISC_R_UNEXPECTED; + goto ioctl6_failure; + } + isc_mem_put(mctx, iter->buf6, iter->buf6size); + + iter->buf6size += IFCONF_SIZE_INCREMENT * + sizeof(SOCKET_ADDRESS); + } + + closesocket(iter->socket); + + inet_only: + iter->magic = IFITER_MAGIC; + *iterp = iter; return (ISC_R_SUCCESS); + ioctl6_failure: + isc_mem_put(mctx, iter->buf6, iter->buf6size); + ioctl_failure: - isc_mem_put(mctx, iter->buf, iter->bufsize); + if (iter->buf4 != NULL) + isc_mem_put(mctx, iter->buf4, iter->buf4size); alloc_failure: - (void) closesocket(iter->socket); + if (iter->socket >= 0) + (void) closesocket(iter->socket); socket_failure: isc_mem_put(mctx, iter, sizeof(*iter)); @@ -226,7 +308,7 @@ isc_interfaceiter_create(isc_mem_t *mctx, isc_interfaceiter_t **iterp) { */ static isc_result_t -internal_current(isc_interfaceiter_t *iter, int family) { +internal_current(isc_interfaceiter_t *iter) { BOOL ifNamed = FALSE; unsigned long flags; @@ -234,9 +316,9 @@ internal_current(isc_interfaceiter_t *iter, int family) { REQUIRE(iter->numIF >= 0); memset(&iter->current, 0, sizeof(iter->current)); - iter->current.af = family; + iter->current.af = AF_INET; - get_addr(family, &iter->current.address, + get_addr(AF_INET, &iter->current.address, (struct sockaddr *)&(iter->IFData.iiAddress)); /* @@ -266,7 +348,7 @@ internal_current(isc_interfaceiter_t *iter, int family) { * If the interface is point-to-point, get the destination address. */ if ((iter->current.flags & INTERFACE_F_POINTTOPOINT) != 0) { - get_addr(family, &iter->current.dstaddress, + get_addr(AF_INET, &iter->current.dstaddress, (struct sockaddr *)&(iter->IFData.iiBroadcastAddress)); } @@ -277,18 +359,43 @@ internal_current(isc_interfaceiter_t *iter, int family) { /* * Get the network mask. */ - switch (family) { - case AF_INET: - get_addr(family, &iter->current.netmask, - (struct sockaddr *)&(iter->IFData.iiNetmask)); - break; - case AF_INET6: - break; - } + get_addr(AF_INET, &iter->current.netmask, + (struct sockaddr *)&(iter->IFData.iiNetmask)); return (ISC_R_SUCCESS); } +static isc_result_t +internal_current6(isc_interfaceiter_t *iter) { + BOOL ifNamed = FALSE; + int i; + + REQUIRE(VALID_IFITER(iter)); + REQUIRE(iter->pos6 >= 0); + REQUIRE(iter->buf6 != 0); + + memset(&iter->current, 0, sizeof(iter->current)); + iter->current.af = AF_INET6; + + get_addr(AF_INET6, &iter->current.address, + iter->buf6->Address[iter->pos6].lpSockaddr); + + /* + * Get interface flags. + */ + + iter->current.flags = INTERFACE_F_UP; + + if (ifNamed == FALSE) + sprintf(iter->current.name, + "TCP/IPv6 Interface %d", iter->pos6 + 1); + + for (i = 0; i< 16; i++) + iter->current.netmask.type.in6.s6_addr[i] = 0xff; + iter->current.netmask.family = AF_INET6; + return (ISC_R_SUCCESS); +} + /* * Step the iterator to the next interface. Unlike * isc_interfaceiter_next(), this may leave the iterator @@ -298,7 +405,7 @@ internal_current(isc_interfaceiter_t *iter, int family) { */ static isc_result_t internal_next(isc_interfaceiter_t *iter) { - if (iter->numIF >= iter->totalIF) + if (iter->numIF >= iter->v4IF) return (ISC_R_NOMORE); /* @@ -309,19 +416,26 @@ internal_next(isc_interfaceiter_t *iter) { */ if (iter->numIF == 0) - iter->pos = (INTERFACE_INFO *)(iter->buf + (iter->totalIF)); + iter->pos4 = (INTERFACE_INFO *)(iter->buf4 + (iter->v4IF)); - iter->pos--; - if (&(iter->pos) < &(iter->buf)) + iter->pos4--; + if (&(iter->pos4) < &(iter->buf4)) return (ISC_R_NOMORE); memset(&(iter->IFData), 0, sizeof(INTERFACE_INFO)); - memcpy(&(iter->IFData), iter->pos, sizeof(INTERFACE_INFO)); + memcpy(&(iter->IFData), iter->pos4, sizeof(INTERFACE_INFO)); iter->numIF++; return (ISC_R_SUCCESS); } +internal_next6(isc_interfaceiter_t *iter) { + if (iter->pos6 == 0) + return (ISC_R_NOMORE); + iter->pos6--; + return (ISC_R_SUCCESS); +} + isc_result_t isc_interfaceiter_current(isc_interfaceiter_t *iter, isc_interface_t *ifdata) { @@ -332,21 +446,13 @@ isc_interfaceiter_current(isc_interfaceiter_t *iter, isc_result_t isc_interfaceiter_first(isc_interfaceiter_t *iter) { - isc_result_t result; REQUIRE(VALID_IFITER(iter)); - iter->numIF = 0; - for (;;) { - result = internal_next(iter); - if (result != ISC_R_SUCCESS) - break; - result = internal_current(iter, AF_INET); - if (result != ISC_R_IGNORE) - break; - } - iter->result = result; - return (result); + if (iter->buf6 != NULL) + iter->pos6 = iter->buf6->iAddressCount; + iter->result = ISC_R_SUCCESS; + return (isc_interfaceiter_next(iter)); } isc_result_t @@ -358,9 +464,16 @@ isc_interfaceiter_next(isc_interfaceiter_t *iter) { for (;;) { result = internal_next(iter); - if (result != ISC_R_SUCCESS) + if (result == ISC_R_NOMORE) { + result = internal_next6(iter); + if (result != ISC_R_SUCCESS) + break; + result = internal_current6(iter); + if (result != ISC_R_IGNORE) + break; + } else if (result != ISC_R_SUCCESS) break; - result = internal_current(iter,AF_INET); + result = internal_current(iter); if (result != ISC_R_IGNORE) break; } @@ -375,10 +488,12 @@ isc_interfaceiter_destroy(isc_interfaceiter_t **iterp) { iter = *iterp; REQUIRE(VALID_IFITER(iter)); - isc_mem_put(iter->mctx, iter->buf, iter->bufsize); + if (iter->buf4 != NULL) + isc_mem_put(iter->mctx, iter->buf4, iter->buf4size); + if (iter->buf6 != NULL) + isc_mem_put(iter->mctx, iter->buf6, iter->buf6size); iter->magic = 0; isc_mem_put(iter->mctx, iter, sizeof(*iter)); *iterp = NULL; } - diff --git a/lib/isc/win32/net.c b/lib/isc/win32/net.c index 4fe67837cf..14e7258888 100644 --- a/lib/isc/win32/net.c +++ b/lib/isc/win32/net.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: net.c,v 1.3.2.2.4.10 2007/08/28 07:19:17 tbox Exp $ */ +/* $Id: net.c,v 1.3.2.2.4.11 2008/04/28 05:35:45 marka Exp $ */ #include @@ -51,7 +51,7 @@ try_proto(int domain) { char strbuf[ISC_STRERRORSIZE]; int errval; - s = socket(domain, SOCK_STREAM, 0); + s = socket(domain, SOCK_STREAM, IPPROTO_TCP); if (s == INVALID_SOCKET) { errval = WSAGetLastError(); switch (errval) { @@ -72,53 +72,9 @@ try_proto(int domain) { } } -#ifdef ISC_PLATFORM_HAVEIPV6 -#ifdef WANT_IPV6 -#ifdef ISC_PLATFORM_HAVEIN6PKTINFO - if (domain == PF_INET6) { - struct sockaddr_in6 sin6; - unsigned int len; - - /* - * Check to see if IPv6 is broken, as is common on Linux. - */ - len = sizeof(sin6); - if (getsockname(s, (struct sockaddr *)&sin6, (void *)&len) < 0) - { - isc_log_write(isc_lctx, ISC_LOGCATEGORY_GENERAL, - ISC_LOGMODULE_SOCKET, ISC_LOG_ERROR, - "retrieving the address of an IPv6 " - "socket from the kernel failed."); - isc_log_write(isc_lctx, ISC_LOGCATEGORY_GENERAL, - ISC_LOGMODULE_SOCKET, ISC_LOG_ERROR, - "IPv6 support is disabled."); - result = ISC_R_NOTFOUND; - } else { - if (len == sizeof(struct sockaddr_in6)) - result = ISC_R_SUCCESS; - else { - isc_log_write(isc_lctx, - ISC_LOGCATEGORY_GENERAL, - ISC_LOGMODULE_SOCKET, - ISC_LOG_ERROR, - "IPv6 structures in kernel and " - "user space do not match."); - isc_log_write(isc_lctx, - ISC_LOGCATEGORY_GENERAL, - ISC_LOGMODULE_SOCKET, - ISC_LOG_ERROR, - "IPv6 support is disabled."); - result = ISC_R_NOTFOUND; - } - } - } -#endif -#endif -#endif - closesocket(s); - return (result); + return (ISC_R_SUCCESS); } static void @@ -193,7 +149,7 @@ try_ipv6only(void) { goto close; } - close(s); + closesocket(s); /* check for UDP sockets */ s = socket(PF_INET6, SOCK_DGRAM, 0); @@ -216,12 +172,10 @@ try_ipv6only(void) { goto close; } - close(s); - ipv6only_result = ISC_R_SUCCESS; close: - close(s); + closeocket(s); return; #endif /* IPV6_V6ONLY */ } @@ -247,7 +201,7 @@ try_ipv6pktinfo(void) { /* we only use this for UDP sockets */ s = socket(PF_INET6, SOCK_DGRAM, IPPROTO_UDP); - if (s == -1) { + if (s == INVALID_SOCKET) { isc__strerror(errno, strbuf, sizeof(strbuf)); UNEXPECTED_ERROR(__FILE__, __LINE__, "socket() %s: %s", @@ -271,11 +225,10 @@ try_ipv6pktinfo(void) { goto close; } - close(s); ipv6pktinfo_result = ISC_R_SUCCESS; close: - close(s); + closesocket(s); return; } From ccfdf96d56344b451c3d151ee47dd770f4570f25 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 05:46:51 +0000 Subject: [PATCH 032/137] 2353. [func] libbind: nsid support. [RT #17091] --- CHANGES | 2 + lib/bind/include/arpa/nameser.h | 5 ++- lib/bind/include/resolv.h | 6 ++- lib/bind/resolv/res_debug.c | 55 +++++++++++++++++++++++-- lib/bind/resolv/res_mkquery.c | 71 +++++++++++++++++++++++++++------ lib/bind/resolv/res_query.c | 14 +++++-- 6 files changed, 131 insertions(+), 22 deletions(-) diff --git a/CHANGES b/CHANGES index a967ef2124..b212ac4304 100644 --- a/CHANGES +++ b/CHANGES @@ -4,6 +4,8 @@ 2356. [bug] Builtin mutex profiler was not scalable enough. [RT #17436] +2353. [func] libbind: nsid support. [RT #17091] + 2350. [port] win32: IPv6 support. [RT #17797] 2347. [bug] Delete now traverses the RB tree in the canonical diff --git a/lib/bind/include/arpa/nameser.h b/lib/bind/include/arpa/nameser.h index 23db49871d..ab297a14c7 100644 --- a/lib/bind/include/arpa/nameser.h +++ b/lib/bind/include/arpa/nameser.h @@ -49,7 +49,7 @@ */ /* - * $Id: nameser.h,v 1.2.2.4.4.1 2004/03/09 08:33:30 marka Exp $ + * $Id: nameser.h,v 1.2.2.4.4.2 2008/04/28 05:46:51 marka Exp $ */ #ifndef _ARPA_NAMESER_H_ @@ -430,9 +430,10 @@ typedef enum __ns_cert_types { #define NS_NXT_MAX 127 /* - * EDNS0 extended flags, host order. + * EDNS0 extended flags and option codes, host order. */ #define NS_OPT_DNSSEC_OK 0x8000U +#define NS_OPT_NSID 3 /* * Inline versions of get/put short/long. Pointer is advanced. diff --git a/lib/bind/include/resolv.h b/lib/bind/include/resolv.h index 87a95200bb..0a1c7f2610 100644 --- a/lib/bind/include/resolv.h +++ b/lib/bind/include/resolv.h @@ -50,7 +50,7 @@ /* * @(#)resolv.h 8.1 (Berkeley) 6/2/93 - * $Id: resolv.h,v 1.7.2.11.4.3 2005/08/25 04:44:13 marka Exp $ + * $Id: resolv.h,v 1.7.2.11.4.4 2008/04/28 05:46:51 marka Exp $ */ #ifndef _RESOLV_H_ @@ -252,6 +252,7 @@ union res_sockaddr_union { #define RES_NOCHECKNAME 0x00008000 /* do not check names for sanity. */ #define RES_KEEPTSIG 0x00010000 /* do not strip TSIG records */ #define RES_BLAST 0x00020000 /* blast all recursive servers */ +#define RES_NSID 0x00040000 /*%< request name server ID */ #define RES_NOTLDQUERY 0x00100000 /* don't unqualified name as a tld */ #define RES_USE_DNSSEC 0x00200000 /* use DNSSEC using OK bit in OPT */ /* #define RES_DEBUG2 0x00400000 */ /* nslookup internal */ @@ -398,6 +399,7 @@ extern const struct res_sym __p_rcode_syms[]; #define sym_ntos __sym_ntos #define sym_ston __sym_ston #define res_nopt __res_nopt +#define res_nopt_rdata __res_nopt_rdata #define res_ndestroy __res_ndestroy #define res_nametoclass __res_nametoclass #define res_nametotype __res_nametotype @@ -484,6 +486,8 @@ int res_findzonecut2 __P((res_state, const char *, ns_class, int, union res_sockaddr_union *, int)); void res_nclose __P((res_state)); int res_nopt __P((res_state, int, u_char *, int, int)); +int res_nopt_rdata __P((res_state, int, u_char *, int, u_char *, + u_short, u_short, u_char *)); void res_send_setqhook __P((res_send_qhook)); void res_send_setrhook __P((res_send_rhook)); int __res_vinit __P((res_state, int)); diff --git a/lib/bind/resolv/res_debug.c b/lib/bind/resolv/res_debug.c index 8dda12c5e8..4c3cc7530f 100644 --- a/lib/bind/resolv/res_debug.c +++ b/lib/bind/resolv/res_debug.c @@ -95,7 +95,7 @@ #if defined(LIBC_SCCS) && !defined(lint) static const char sccsid[] = "@(#)res_debug.c 8.1 (Berkeley) 6/4/93"; -static const char rcsid[] = "$Id: res_debug.c,v 1.3.2.5.4.6 2005/07/28 07:43:22 marka Exp $"; +static const char rcsid[] = "$Id: res_debug.c,v 1.3.2.5.4.7 2008/04/28 05:46:51 marka Exp $"; #endif /* LIBC_SCCS and not lint */ #include "port_before.h" @@ -189,10 +189,56 @@ do_section(const res_state statp, p_type(ns_rr_type(rr)), p_class(ns_rr_class(rr))); else if (section == ns_s_ar && ns_rr_type(rr) == ns_t_opt) { + u_int16_t optcode, optlen, rdatalen = ns_rr_rdlen(rr); u_int32_t ttl = ns_rr_ttl(rr); + fprintf(file, "; EDNS: version: %u, udp=%u, flags=%04x\n", (ttl>>16)&0xff, ns_rr_class(rr), ttl&0xffff); + + while (rdatalen >= 4) { + const u_char *cp = ns_rr_rdata(rr); + int i; + + GETSHORT(optcode, cp); + GETSHORT(optlen, cp); + + if (optcode == NS_OPT_NSID) { + fputs("; NSID: ", file); + if (optlen == 0) { + fputs("; NSID\n", file); + } else { + fputs("; NSID: ", file); + for (i = 0; i < optlen; i++) + fprintf(file, "%02x ", + cp[i]); + fputs(" (",file); + for (i = 0; i < optlen; i++) + fprintf(file, "%c", + isprint(cp[i])? + cp[i] : '.'); + fputs(")\n", file); + } + } else { + if (optlen == 0) { + fprintf(file, "; OPT=%u\n", + optcode); + } else { + fprintf(file, "; OPT=%u: ", + optcode); + for (i = 0; i < optlen; i++) + fprintf(file, "%02x ", + cp[i]); + fputs(" (",file); + for (i = 0; i < optlen; i++) + fprintf(file, "%c", + isprint(cp[i]) ? + cp[i] : '.'); + fputs(")\n", file); + } + } + rdatalen -= 4 + optlen; + } } else { n = ns_sprintrr(handle, &rr, NULL, NULL, buf, buflen); @@ -204,7 +250,7 @@ do_section(const res_state statp, buf = malloc(buflen += 1024); if (buf == NULL) { fprintf(file, - ";; memory allocation failure\n"); + ";; memory allocation failure\n"); return; } continue; @@ -380,7 +426,7 @@ const struct res_sym __p_default_section_syms[] = { {ns_s_an, "ANSWER", (char *)0}, {ns_s_ns, "AUTHORITY", (char *)0}, {ns_s_ar, "ADDITIONAL", (char *)0}, - {0, (char *)0, (char *)0} + {0, (char *)0, (char *)0} }; const struct res_sym __p_update_section_syms[] = { @@ -388,7 +434,7 @@ const struct res_sym __p_update_section_syms[] = { {S_PREREQ, "PREREQUISITE", (char *)0}, {S_UPDATE, "UPDATE", (char *)0}, {S_ADDT, "ADDITIONAL", (char *)0}, - {0, (char *)0, (char *)0} + {0, (char *)0, (char *)0} }; const struct res_sym __p_key_syms[] = { @@ -616,6 +662,7 @@ p_option(u_long option) { case RES_USE_INET6: return "inet6"; #ifdef RES_USE_EDNS0 /* KAME extension */ case RES_USE_EDNS0: return "edns0"; + case RES_NSID: return "nsid"; #endif #ifdef RES_USE_DNAME case RES_USE_DNAME: return "dname"; diff --git a/lib/bind/resolv/res_mkquery.c b/lib/bind/resolv/res_mkquery.c index 89000edf6a..0e450e9b53 100644 --- a/lib/bind/resolv/res_mkquery.c +++ b/lib/bind/resolv/res_mkquery.c @@ -70,7 +70,7 @@ #if defined(LIBC_SCCS) && !defined(lint) static const char sccsid[] = "@(#)res_mkquery.c 8.1 (Berkeley) 6/4/93"; -static const char rcsid[] = "$Id: res_mkquery.c,v 1.1.2.2.4.2 2004/03/16 12:34:18 marka Exp $"; +static const char rcsid[] = "$Id: res_mkquery.c,v 1.1.2.2.4.3 2008/04/28 05:46:51 marka Exp $"; #endif /* LIBC_SCCS and not lint */ #include "port_before.h" @@ -203,9 +203,6 @@ res_nmkquery(res_state statp, #ifdef RES_USE_EDNS0 /* attach OPT pseudo-RR, as documented in RFC2671 (EDNS0). */ -#ifndef T_OPT -#define T_OPT 41 -#endif int res_nopt(res_state statp, @@ -230,14 +227,14 @@ res_nopt(res_state statp, if ((ep - cp) < 1 + RRFIXEDSZ) return (-1); - *cp++ = 0; /* "." */ + *cp++ = 0; /*%< "." */ + ns_put16(ns_t_opt, cp); /*%< TYPE */ + cp += INT16SZ; + ns_put16(anslen & 0xffff, cp); /*%< CLASS = UDP payload size */ + cp += INT16SZ; + *cp++ = NOERROR; /*%< extended RCODE */ + *cp++ = 0; /*%< EDNS version */ - ns_put16(T_OPT, cp); /* TYPE */ - cp += INT16SZ; - ns_put16(anslen & 0xffff, cp); /* CLASS = UDP payload size */ - cp += INT16SZ; - *cp++ = NOERROR; /* extended RCODE */ - *cp++ = 0; /* EDNS version */ if (statp->options & RES_USE_DNSSEC) { #ifdef DEBUG if (statp->options & RES_DEBUG) @@ -247,10 +244,60 @@ res_nopt(res_state statp, } ns_put16(flags, cp); cp += INT16SZ; - ns_put16(0, cp); /* RDLEN */ + + ns_put16(0, cp); /*%< RDLEN */ cp += INT16SZ; + hp->arcount = htons(ntohs(hp->arcount) + 1); return (cp - buf); } + +/* + * Construct variable data (RDATA) block for OPT psuedo-RR, append it + * to the buffer, then update the RDLEN field (previously set to zero by + * res_nopt()) with the new RDATA length. + */ +int +res_nopt_rdata(res_state statp, + int n0, /*%< current offset in buffer */ + u_char *buf, /*%< buffer to put query */ + int buflen, /*%< size of buffer */ + u_char *rdata, /*%< ptr to start of opt rdata */ + u_short code, /*%< OPTION-CODE */ + u_short len, /*%< OPTION-LENGTH */ + u_char *data) /*%< OPTION_DATA */ +{ + register u_char *cp, *ep; + +#ifdef DEBUG + if ((statp->options & RES_DEBUG) != 0U) + printf(";; res_nopt_rdata()\n"); #endif + + cp = buf + n0; + ep = buf + buflen; + + if ((ep - cp) < (4 + len)) + return (-1); + + if (rdata < (buf + 2) || rdata >= ep) + return (-1); + + ns_put16(code, cp); + cp += INT16SZ; + + ns_put16(len, cp); + cp += INT16SZ; + + memcpy(cp, data, len); + cp += len; + + len = cp - rdata; + ns_put16(len, rdata - 2); /* Update RDLEN field */ + + return (cp - buf); +} +#endif + +/*! \file */ diff --git a/lib/bind/resolv/res_query.c b/lib/bind/resolv/res_query.c index 5156ce84c0..6855b73f12 100644 --- a/lib/bind/resolv/res_query.c +++ b/lib/bind/resolv/res_query.c @@ -70,7 +70,7 @@ #if defined(LIBC_SCCS) && !defined(lint) static const char sccsid[] = "@(#)res_query.c 8.1 (Berkeley) 6/4/93"; -static const char rcsid[] = "$Id: res_query.c,v 1.2.2.3.4.2 2004/03/16 12:34:19 marka Exp $"; +static const char rcsid[] = "$Id: res_query.c,v 1.2.2.3.4.3 2008/04/28 05:46:51 marka Exp $"; #endif /* LIBC_SCCS and not lint */ #include "port_before.h" @@ -116,8 +116,9 @@ res_nquery(res_state statp, { u_char buf[MAXPACKET]; HEADER *hp = (HEADER *) answer; - int n; u_int oflags; + u_char *rdata; + int n; oflags = statp->_flags; @@ -133,8 +134,14 @@ again: buf, sizeof(buf)); #ifdef RES_USE_EDNS0 if (n > 0 && (statp->_flags & RES_F_EDNS0ERR) == 0 && - (statp->options & (RES_USE_EDNS0|RES_USE_DNSSEC)) != 0U) + (statp->options & (RES_USE_EDNS0|RES_USE_DNSSEC|RES_NSID))) { n = res_nopt(statp, n, buf, sizeof(buf), anslen); + rdata = &buf[n]; + if (n > 0 && (statp->options & RES_NSID) != 0U) { + n = res_nopt_rdata(statp, n, buf, sizeof(buf), rdata, + NS_OPT_NSID, 0, NULL); + } + } #endif if (n <= 0) { #ifdef DEBUG @@ -144,6 +151,7 @@ again: RES_SET_H_ERRNO(statp, NO_RECOVERY); return (n); } + n = res_nsend(statp, buf, n, answer, anslen); if (n < 0) { #ifdef RES_USE_EDNS0 From 1662b369c5184fb7e0e96157ab8c18f07ec1dac9 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 05:50:20 +0000 Subject: [PATCH 033/137] 2358. [doc] Update host's default query description. [RT #17934] --- CHANGES | 2 ++ bin/dig/host.docbook | 4 ++-- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/CHANGES b/CHANGES index b212ac4304..c35015e448 100644 --- a/CHANGES +++ b/CHANGES @@ -1,6 +1,8 @@ 2361. [bug] "recursion" statistics counter could be counted multiple times for a single query. [RT #17990] +2358. [doc] Update host's default query description. [RT #17934] + 2356. [bug] Builtin mutex profiler was not scalable enough. [RT #17436] diff --git a/bin/dig/host.docbook b/bin/dig/host.docbook index a399043403..cab34dbfa8 100644 --- a/bin/dig/host.docbook +++ b/bin/dig/host.docbook @@ -18,7 +18,7 @@ - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -185,7 +185,7 @@ The option is used to select the query type. type can be any recognized query type: CNAME, NS, SOA, SIG, KEY, AXFR, etc. When no query type is specified, host automatically selects an appropriate query -type. By default it looks for A records, but if the +type. By default it looks for A, AAAA, and MX records, but if the option was given, queries will be made for SOA records, and if name is a dotted-decimal IPv4 address or colon-delimited IPv6 address, host will From e7b025d893e0858c771313edee4648b272086006 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Mon, 28 Apr 2008 23:30:04 +0000 Subject: [PATCH 034/137] newcopyrights --- util/copyrights | 89 +++++++++++++++++++++++++++++-------------------- 1 file changed, 53 insertions(+), 36 deletions(-) diff --git a/util/copyrights b/util/copyrights index af2662033b..2d8b06d05a 100644 --- a/util/copyrights +++ b/util/copyrights @@ -5,7 +5,7 @@ ./FAQ X 2000,2001,2002,2003,2004,2005,2006,2007,2008 ./FAQ.xml SGML 2000,2001,2002,2003,2004,2005,2006,2007,2008 ./Makefile.in MAKE 1998,1999,2000,2001,2002,2003,2004,2006,2007 -./README X 1999,2000,2001,2002,2003,2004,2005,2006 +./README X 1999,2000,2001,2002,2003,2004,2005,2006,2008 ./acconfig.h C 1999,2000,2001,2002,2003,2004 ./aclocal.m4 X 1999,2000,2001 ./bin/.cvsignore X 1998,1999,2000,2001 @@ -33,13 +33,13 @@ ./bin/dig/.cvsignore X 2000,2001 ./bin/dig/Makefile.in MAKE 2000,2001,2002,2003,2004,2007 ./bin/dig/dig.1 MAN DOCBOOK -./bin/dig/dig.c C 2000,2001,2002,2003,2004,2005,2006,2007 +./bin/dig/dig.c C 2000,2001,2002,2003,2004,2005,2006,2007,2008 ./bin/dig/dig.docbook SGML 2000,2001,2002,2003,2004,2005,2006,2007 ./bin/dig/dig.html HTML DOCBOOK ./bin/dig/dighost.c C 2000,2001,2002,2003,2004,2005,2006,2007,2008 ./bin/dig/host.1 MAN DOCBOOK ./bin/dig/host.c C 2000,2001,2002,2003,2004,2005,2006,2007 -./bin/dig/host.docbook SGML 2000,2001,2002,2003,2004,2005,2007 +./bin/dig/host.docbook SGML 2000,2001,2002,2003,2004,2005,2007,2008 ./bin/dig/host.html HTML DOCBOOK ./bin/dig/include/dig/dig.h C 2000,2001,2002,2003,2004,2005,2006,2007 ./bin/dig/nslookup.1 MAN DOCBOOK @@ -552,7 +552,7 @@ ./bin/tests/system/glue/tests.sh SH 2000,2001,2003,2004 ./bin/tests/system/glue/xx.good X 2000,2001 ./bin/tests/system/glue/yy.good X 2000,2001,2003 -./bin/tests/system/ifconfig.sh SH 2000,2001,2002,2003,2004 +./bin/tests/system/ifconfig.sh SH 2000,2001,2002,2003,2004,2008 ./bin/tests/system/ixfr/ans2/.cvsignore X 2001 ./bin/tests/system/ixfr/ans2/ans.pl PERL 2001,2004,2007 ./bin/tests/system/ixfr/clean.sh SH 2001,2004 @@ -817,7 +817,7 @@ ./bin/win32/BINDInstall/resource.h X 2001,2003,2005 ./config.guess X 1998,1999,2000,2001,2003,2004 ./config.h.in X 1998,1999,2000,2001,2003,2004,2005,2006,2007,2008 -./config.h.win32 C 1999,2000,2001,2003,2004,2006,2007 +./config.h.win32 C 1999,2000,2001,2003,2004,2006,2007,2008 ./config.sub X 1998,1999,2000,2001,2003,2004 ./config.threads.in X 2005,2006 ./configure X 1998,1999,2000,2001,2002,2003,2004,2005,2006,2007,2008 @@ -1081,6 +1081,22 @@ ./contrib/query-loc-0.3.0/loc_ntoa.c X 2005 ./contrib/query-loc-0.3.0/query-loc.1 X 2005 ./contrib/query-loc-0.3.0/query-loc.c X 2005 +./contrib/query-loc-0.4.0/ADDRESSES X 2008 +./contrib/query-loc-0.4.0/ALGO X 2008 +./contrib/query-loc-0.4.0/INSTALL X 2008 +./contrib/query-loc-0.4.0/Makefile.in X 2008 +./contrib/query-loc-0.4.0/README X 2008 +./contrib/query-loc-0.4.0/USAGE X 2008 +./contrib/query-loc-0.4.0/config.h.in X 2008 +./contrib/query-loc-0.4.0/configure X 2008 +./contrib/query-loc-0.4.0/configure.in X 2008 +./contrib/query-loc-0.4.0/install-sh X 2008 +./contrib/query-loc-0.4.0/loc.c X 2008 +./contrib/query-loc-0.4.0/loc.h X 2008 +./contrib/query-loc-0.4.0/loc_ntoa.c X 2008 +./contrib/query-loc-0.4.0/query-loc.1 X 2008 +./contrib/query-loc-0.4.0/query-loc.c X 2008 +./contrib/query-loc-0.4.0/reconf X 2008 ./contrib/queryperf/.cvsignore X 2001 ./contrib/queryperf/Makefile.in X 2001,2004 ./contrib/queryperf/README X 2001 @@ -1210,7 +1226,7 @@ ./lib/bind/aclocal.m4 X 2001,2004 ./lib/bind/api X 2001,2002,2003,2004,2005,2006,2007,2008 ./lib/bind/bsd/.cvsignore X 2001 -./lib/bind/bsd/Makefile.in MAKE 2001,2004 +./lib/bind/bsd/Makefile.in MAKE 2001,2004,2008 ./lib/bind/bsd/daemon.c X 2001 ./lib/bind/bsd/ftruncate.c X 2001 ./lib/bind/bsd/gettimeofday.c X 2001,2002,2003 @@ -1221,17 +1237,17 @@ ./lib/bind/bsd/setitimer.c X 2001 ./lib/bind/bsd/strcasecmp.c X 2001 ./lib/bind/bsd/strdup.c X 2001 -./lib/bind/bsd/strerror.c X 2001,2003 +./lib/bind/bsd/strerror.c X 2001,2003,2008 ./lib/bind/bsd/strpbrk.c X 2001 ./lib/bind/bsd/strsep.c X 2001 -./lib/bind/bsd/strtoul.c X 2001,2003 +./lib/bind/bsd/strtoul.c X 2001,2003,2008 ./lib/bind/bsd/utimes.c X 2001,2004 ./lib/bind/bsd/writev.c X 2001,2003 ./lib/bind/config.h.in X 2001,2003,2004,2005,2006,2007,2008 ./lib/bind/configure X 2001,2002,2003,2004,2005,2006,2007,2008 ./lib/bind/configure.in SH 2001,2002,2003,2004,2005,2006,2007,2008 ./lib/bind/dst/.cvsignore X 2001 -./lib/bind/dst/Makefile.in MAKE 2001,2004 +./lib/bind/dst/Makefile.in MAKE 2001,2004,2008 ./lib/bind/dst/dst_api.c X 2001,2002,2003,2004,2005,2006,2007 ./lib/bind/dst/dst_internal.h X 2001,2004 ./lib/bind/dst/hmac_link.c X 2001,2003,2005,2006,2007 @@ -1242,12 +1258,13 @@ ./lib/bind/include/.cvsignore X 2001 ./lib/bind/include/Makefile.in MAKE 2001,2004,2008 ./lib/bind/include/arpa/inet.h X 2001,2004 -./lib/bind/include/arpa/nameser.h X 2001,2002,2003,2004 +./lib/bind/include/arpa/nameser.h X 2001,2002,2003,2004,2008 ./lib/bind/include/arpa/nameser_compat.h X 2001,2002,2003,2004,2006 ./lib/bind/include/fd_setsize.h X 2001 ./lib/bind/include/hesiod.h X 2001,2003,2004 ./lib/bind/include/irp.h X 2001,2003,2004 ./lib/bind/include/irs.h X 2001,2003,2004 +./lib/bind/include/isc/.cvsignore X 2008 ./lib/bind/include/isc/assertions.h X 2001,2004 ./lib/bind/include/isc/ctl.h X 2001,2002,2003,2004 ./lib/bind/include/isc/dst.h X 2001,2002,2003 @@ -1257,16 +1274,16 @@ ./lib/bind/include/isc/list.h X 2001,2002,2004,2006 ./lib/bind/include/isc/logging.h X 2001,2002,2003,2004 ./lib/bind/include/isc/memcluster.h X 2001,2004 -./lib/bind/include/isc/misc.h X 2001,2003,2004 +./lib/bind/include/isc/misc.h X 2001,2003,2004,2008 ./lib/bind/include/isc/platform.h.in C 2008 ./lib/bind/include/isc/tree.h X 2001,2003 ./lib/bind/include/netdb.h X 2001,2003,2004,2006 ./lib/bind/include/netgroup.h X 2001,2004 ./lib/bind/include/res_update.h X 2001,2004 -./lib/bind/include/resolv.h X 2001,2002,2003,2004,2005 +./lib/bind/include/resolv.h X 2001,2002,2003,2004,2005,2008 ./lib/bind/include/resolv_mt.h X 2005 ./lib/bind/inet/.cvsignore X 2001 -./lib/bind/inet/Makefile.in MAKE 2001,2004 +./lib/bind/inet/Makefile.in MAKE 2001,2004,2008 ./lib/bind/inet/inet_addr.c X 2001,2004 ./lib/bind/inet/inet_cidr_ntop.c X 2001,2002,2003,2004,2005,2006 ./lib/bind/inet/inet_cidr_pton.c X 2001,2002,2003,2004 @@ -1283,7 +1300,7 @@ ./lib/bind/inet/inet_pton.c X 2001,2004,2005 ./lib/bind/inet/nsap_addr.c X 2001,2004,2005 ./lib/bind/irs/.cvsignore X 2001 -./lib/bind/irs/Makefile.in MAKE 2001,2004 +./lib/bind/irs/Makefile.in MAKE 2001,2004,2008 ./lib/bind/irs/dns.c X 2001,2004,2006 ./lib/bind/irs/dns_gr.c X 2001,2003,2004 ./lib/bind/irs/dns_ho.c X 2001,2002,2003,2004,2005,2006 @@ -1320,7 +1337,7 @@ ./lib/bind/irs/getservent_r.c X 2001,2004,2006 ./lib/bind/irs/hesiod.c X 2001,2003,2004,2005 ./lib/bind/irs/hesiod_p.h X 2001,2004 -./lib/bind/irs/irp.c X 2001,2003,2004,2006 +./lib/bind/irs/irp.c X 2001,2003,2004,2006,2008 ./lib/bind/irs/irp_gr.c X 2001,2004 ./lib/bind/irs/irp_ho.c X 2001,2004 ./lib/bind/irs/irp_ng.c X 2001,2004,2006 @@ -1355,16 +1372,16 @@ ./lib/bind/irs/pathnames.h X 2001,2004 ./lib/bind/irs/util.c X 2001,2004 ./lib/bind/isc/.cvsignore X 2001 -./lib/bind/isc/Makefile.in MAKE 2001,2004 +./lib/bind/isc/Makefile.in MAKE 2001,2004,2008 ./lib/bind/isc/assertions.c X 2001,2004 ./lib/bind/isc/assertions.mdoc X 2001,2003,2004 ./lib/bind/isc/base64.c X 2001,2004 ./lib/bind/isc/bitncmp.c X 2001,2004 ./lib/bind/isc/bitncmp.mdoc X 2001,2003,2004 -./lib/bind/isc/ctl_clnt.c X 2001,2003,2004,2007 +./lib/bind/isc/ctl_clnt.c X 2001,2003,2004,2007,2008 ./lib/bind/isc/ctl_p.c X 2001,2004 ./lib/bind/isc/ctl_p.h X 2001 -./lib/bind/isc/ctl_srvr.c X 2001,2003,2004,2006 +./lib/bind/isc/ctl_srvr.c X 2001,2003,2004,2006,2008 ./lib/bind/isc/ev_connects.c X 2001,2004,2005,2006 ./lib/bind/isc/ev_files.c X 2001,2003,2004,2005 ./lib/bind/isc/ev_streams.c X 2001,2004 @@ -1390,7 +1407,7 @@ ./lib/bind/make/rules.in MAKE 2001,2002,2003,2004,2007 ./lib/bind/mkinstalldirs X 2001 ./lib/bind/nameser/.cvsignore X 2001 -./lib/bind/nameser/Makefile.in MAKE 2001,2004 +./lib/bind/nameser/Makefile.in MAKE 2001,2004,2008 ./lib/bind/nameser/ns_date.c X 2001,2004 ./lib/bind/nameser/ns_name.c X 2001,2002,2003,2004 ./lib/bind/nameser/ns_netint.c X 2001,2004 @@ -1609,27 +1626,27 @@ ./lib/bind/port_after.h.in X 2001,2002,2003,2004,2005,2006,2008 ./lib/bind/port_before.h.in X 2001,2002,2005,2006,2007 ./lib/bind/resolv/.cvsignore X 2001 -./lib/bind/resolv/Makefile.in MAKE 2001,2004,2005 +./lib/bind/resolv/Makefile.in MAKE 2001,2004,2005,2008 ./lib/bind/resolv/herror.c X 2001,2004 ./lib/bind/resolv/mtctxres.c X 2005,2006 ./lib/bind/resolv/res_comp.c X 2001,2003,2004,2005 ./lib/bind/resolv/res_data.c X 2001,2004,2007 -./lib/bind/resolv/res_debug.c X 2001,2002,2003,2004,2005 +./lib/bind/resolv/res_debug.c X 2001,2002,2003,2004,2005,2008 ./lib/bind/resolv/res_debug.h X 2001,2004 ./lib/bind/resolv/res_findzonecut.c X 2001,2002,2003,2004,2005 ./lib/bind/resolv/res_init.c X 2001,2002,2003,2004,2005,2006,2007 -./lib/bind/resolv/res_mkquery.c X 2001,2002,2003,2004 +./lib/bind/resolv/res_mkquery.c X 2001,2002,2003,2004,2008 ./lib/bind/resolv/res_mkupdate.c X 2001,2003,2004,2005 ./lib/bind/resolv/res_mkupdate.h X 2001,2004 ./lib/bind/resolv/res_private.h X 2001,2002,2003 -./lib/bind/resolv/res_query.c X 2001,2002,2003,2004 +./lib/bind/resolv/res_query.c X 2001,2002,2003,2004,2008 ./lib/bind/resolv/res_send.c X 2001,2002,2003,2004,2005,2006,2007,2008 ./lib/bind/resolv/res_sendsigned.c X 2001,2004,2005,2006 ./lib/bind/resolv/res_update.c X 2001,2002,2003,2004 ./lib/bind9/.cvsignore X 2001,2003 ./lib/bind9/Makefile.in MAKE 2001,2003,2004,2007 ./lib/bind9/api X 2001,2003,2004,2005,2006,2007,2008 -./lib/bind9/check.c C 2001,2002,2003,2004,2005,2006,2007 +./lib/bind9/check.c C 2001,2002,2003,2004,2005,2006,2007,2008 ./lib/bind9/getaddresses.c C 2001,2002,2003,2004,2005,2007 ./lib/bind9/include/.cvsignore X 2001,2003 ./lib/bind9/include/Makefile.in MAKE 2001,2003,2004,2007 @@ -1651,7 +1668,7 @@ ./lib/dns/adb.c C 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008 ./lib/dns/api X 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008 ./lib/dns/byaddr.c C 2000,2001,2002,2003,2004 -./lib/dns/cache.c C 1999,2000,2001,2002,2003,2004,2005,2006 +./lib/dns/cache.c C 1999,2000,2001,2002,2003,2004,2005,2006,2008 ./lib/dns/callbacks.c C 1999,2000,2001,2004 ./lib/dns/compress.c C 1999,2000,2001,2004,2006 ./lib/dns/db.c C 1999,2000,2001,2003,2004 @@ -1847,7 +1864,7 @@ ./lib/dns/rdata/generic/sshfp_44.h C 2003,2004 ./lib/dns/rdata/generic/tkey_249.c C 1999,2000,2001,2002,2003,2004 ./lib/dns/rdata/generic/tkey_249.h C 1999,2000,2001,2003,2004 -./lib/dns/rdata/generic/txt_16.c C 1998,1999,2000,2001,2002,2003,2004,2007 +./lib/dns/rdata/generic/txt_16.c C 1998,1999,2000,2001,2002,2003,2004,2007,2008 ./lib/dns/rdata/generic/txt_16.h C 1998,1999,2000,2001,2004 ./lib/dns/rdata/generic/unspec_103.c C 1999,2000,2001,2002,2003,2004,2007 ./lib/dns/rdata/generic/unspec_103.h C 1999,2000,2001,2004 @@ -1865,7 +1882,7 @@ ./lib/dns/rdata/in_1/apl_42.h C 2002,2003,2004,2007 ./lib/dns/rdata/in_1/kx_36.c C 1999,2000,2001,2003,2004 ./lib/dns/rdata/in_1/kx_36.h C 1999,2000,2001,2004 -./lib/dns/rdata/in_1/naptr_35.c C 1999,2000,2001,2003,2004 +./lib/dns/rdata/in_1/naptr_35.c C 1999,2000,2001,2003,2004,2008 ./lib/dns/rdata/in_1/naptr_35.h C 1999,2000,2001,2004 ./lib/dns/rdata/in_1/nsap-ptr_23.c C 1999,2000,2001,2004 ./lib/dns/rdata/in_1/nsap-ptr_23.h C 1999,2000,2001,2004 @@ -1964,7 +1981,7 @@ ./lib/isc/include/isc/log.h C 1999,2000,2001,2002,2003,2004,2007 ./lib/isc/include/isc/magic.h C 1999,2000,2001,2004 ./lib/isc/include/isc/md5.h C 2000,2001,2004 -./lib/isc/include/isc/mem.h C 1997,1998,1999,2000,2001,2003,2004,2007 +./lib/isc/include/isc/mem.h C 1997,1998,1999,2000,2001,2003,2004,2007,2008 ./lib/isc/include/isc/msgcat.h C 1999,2000,2001,2004 ./lib/isc/include/isc/msgs.h C 2000,2001,2002,2003,2004 ./lib/isc/include/isc/mutexblock.h C 1999,2000,2001,2004 @@ -2006,7 +2023,7 @@ ./lib/isc/lib.c C 1999,2000,2001,2003,2004,2007 ./lib/isc/log.c C 1999,2000,2001,2002,2003,2004,2006 ./lib/isc/md5.c C 2000,2001,2004 -./lib/isc/mem.c C 1997,1998,1999,2000,2001,2002,2003,2004,2005,2006,2007 +./lib/isc/mem.c C 1997,1998,1999,2000,2001,2002,2003,2004,2005,2006,2007,2008 ./lib/isc/mutexblock.c C 1999,2000,2001,2003,2004,2007 ./lib/isc/netaddr.c C 1999,2000,2001,2002,2003,2004,2007 ./lib/isc/netscope.c C 2002,2003,2004,2006,2007 @@ -2028,7 +2045,7 @@ ./lib/isc/nothreads/thread.c C 2000,2001,2004 ./lib/isc/ondestroy.c C 2000,2001,2004 ./lib/isc/parseint.c C 2001,2002,2003,2004 -./lib/isc/print.c C 1999,2000,2001,2003,2004,2005,2006 +./lib/isc/print.c C 1999,2000,2001,2003,2004,2005,2006,2008 ./lib/isc/pthreads/.cvsignore X 1998,1999,2000,2001 ./lib/isc/pthreads/Makefile.in MAKE 1998,1999,2000,2001,2004 ./lib/isc/pthreads/condition.c C 1998,1999,2000,2001,2003,2004,2007 @@ -2098,7 +2115,7 @@ ./lib/isc/unix/stdtime.c C 1999,2000,2001,2003,2004,2005,2007 ./lib/isc/unix/strerror.c C 2001,2003,2004,2007 ./lib/isc/unix/syslog.c C 2001,2003,2004,2007 -./lib/isc/unix/time.c C 1998,1999,2000,2001,2003,2004 +./lib/isc/unix/time.c C 1998,1999,2000,2001,2003,2004,2008 ./lib/isc/version.c C 1998,1999,2000,2001,2003,2004,2007 ./lib/isc/win32/.cvsignore X 1999,2000,2001 ./lib/isc/win32/DLLMain.c C 2001,2003,2004,2007 @@ -2129,7 +2146,7 @@ ./lib/isc/win32/include/isc/ntpaths.h C 2000,2001,2003,2004,2007 ./lib/isc/win32/include/isc/offset.h C 2000,2001,2004 ./lib/isc/win32/include/isc/once.h C 1999,2000,2001,2004 -./lib/isc/win32/include/isc/platform.h C 2001,2003,2004,2007 +./lib/isc/win32/include/isc/platform.h C 2001,2003,2004,2007,2008 ./lib/isc/win32/include/isc/stat.h C 2000,2001,2003,2004 ./lib/isc/win32/include/isc/stdtime.h C 1999,2000,2001,2004 ./lib/isc/win32/include/isc/strerror.h C 2001,2002,2003,2004,2007 @@ -2137,14 +2154,14 @@ ./lib/isc/win32/include/isc/thread.h C 1998,1999,2000,2001,2004 ./lib/isc/win32/include/isc/time.h C 1998,1999,2000,2001,2003,2004,2007 ./lib/isc/win32/include/isc/win32os.h C 2002,2003,2004,2007 -./lib/isc/win32/interfaceiter.c C 1999,2000,2001,2003,2004,2007 +./lib/isc/win32/interfaceiter.c C 1999,2000,2001,2003,2004,2007,2008 ./lib/isc/win32/ipv6.c C 1999,2000,2001,2003,2004,2007 ./lib/isc/win32/keyboard.c C 2000,2001,2004 -./lib/isc/win32/libisc.def X 2001,2003,2004,2005,2006,2007 +./lib/isc/win32/libisc.def X 2001,2003,2004,2005,2006,2007,2008 ./lib/isc/win32/libisc.dsp X 2001,2003,2004 ./lib/isc/win32/libisc.dsw X 2001,2003,2004 ./lib/isc/win32/libisc.mak X 2001,2003,2004,2006 -./lib/isc/win32/net.c C 1999,2000,2001,2002,2003,2004,2007 +./lib/isc/win32/net.c C 1999,2000,2001,2002,2003,2004,2007,2008 ./lib/isc/win32/netdb.h C 2000,2001,2003,2004,2007 ./lib/isc/win32/ntgroups.c C 2001,2003,2004,2006,2007 ./lib/isc/win32/ntpaths.c C 2001,2003,2004,2007 @@ -2379,7 +2396,7 @@ ./util/check-pullups.pl PERL 2001,2002,2003,2004 ./util/check-sources.pl PERL 2000,2001,2004 ./util/copyrights X 1998,1999,2000,2001,2002,2003,2004,2005,2006,2007,2008 -./util/kit.sh SH 2000,2001,2002,2003,2004 +./util/kit.sh SH 2000,2001,2002,2003,2004,2008 ./util/mandoc2docbook.pl PERL 2001,2004 ./util/mdnbuildtest.sh SH 2000,2001,2004 ./util/memleak.pl PERL 1999,2000,2001,2004 From 8b56b8956fc1e6c70efacb4f71db28d0d1f0c577 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 23:43:24 +0000 Subject: [PATCH 035/137] 2363. [port] sunos: pre-set "lt_cv_sys_max_cmd_len=4096;". [RT #17513] --- CHANGES | 3 ++ config.h.in | 8 +++--- configure | 66 ++++++++++++++++++++++++------------------- configure.in | 10 ++++++- lib/bind/configure | 64 +++++++++++++++++++++++------------------ lib/bind/configure.in | 10 ++++++- 6 files changed, 98 insertions(+), 63 deletions(-) diff --git a/CHANGES b/CHANGES index e36a40618c..91f9a6d9bc 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +2363. [port] sunos: pre-set "lt_cv_sys_max_cmd_len=4096;". + [RT #17513] + 2362. [cleanup] Make "rrset-order fixed" a compile-time option. settable by "./configure --enable-fixed-rrset". Disabled by default. [rt17977] diff --git a/config.h.in b/config.h.in index 40069bc86a..ab0f0ade8d 100644 --- a/config.h.in +++ b/config.h.in @@ -16,7 +16,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: config.h.in,v 1.97 2008/04/23 21:32:01 each Exp $ */ +/* $Id: config.h.in,v 1.98 2008/04/28 23:43:24 marka Exp $ */ /*! \file */ @@ -157,6 +157,9 @@ int sigwait(const unsigned int *set, int *sig); /* Define if you cannot bind() before connect() for TCP sockets. */ #undef BROKEN_TCP_BIND_BEFORE_CONNECT +/* Define to enable "rrset-order fixed" syntax. */ +#undef DNS_RDATASET_FIXED + /* Define to 1 if you have the `capset' function. */ #undef HAVE_CAPSET @@ -326,6 +329,3 @@ int sigwait(const unsigned int *set, int *sig); /* Define to empty if the keyword `volatile' does not work. Warning: valid code using `volatile' can become incorrect without. Disable with care. */ #undef volatile - -/* Define to enable "rrset-order fixed" syntax. */ -#undef DNS_RDATASET_FIXED diff --git a/configure b/configure index 917ba4c281..154eb4dcc8 100755 --- a/configure +++ b/configure @@ -14,7 +14,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. # -# $Id: configure,v 1.426 2008/04/23 21:32:57 each Exp $ +# $Id: configure,v 1.427 2008/04/28 23:43:24 marka Exp $ # # Portions Copyright (C) 1996-2001 Nominum, Inc. # @@ -29,7 +29,7 @@ # WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN # ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT # OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. -# From configure.in Revision: 1.441 . +# From configure.in Revision: 1.442 . # Guess values for system-dependent variables and create Makefiles. # Generated by GNU Autoconf 2.61. # @@ -9080,6 +9080,14 @@ esac # # GNU libtool support # +case $host in +sunos*) + # Just set the maximum command line length for sunos as it otherwise + # takes a exceptionally long time to work it out. Required for libtool. + lt_cv_sys_max_cmd_len=4096; + ;; +esac + # Check whether --with-libtool was given. if test "${with_libtool+set}" = set; then @@ -9616,7 +9624,7 @@ ia64-*-hpux*) ;; *-*-irix6*) # Find out which ABI we are using. - echo '#line 9619 "configure"' > conftest.$ac_ext + echo '#line 9627 "configure"' > conftest.$ac_ext if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 (eval $ac_compile) 2>&5 ac_status=$? @@ -11738,11 +11746,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:11741: $lt_compile\"" >&5) + (eval echo "\"\$as_me:11749: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:11745: \$? = $ac_status" >&5 + echo "$as_me:11753: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -11981,11 +11989,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:11984: $lt_compile\"" >&5) + (eval echo "\"\$as_me:11992: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:11988: \$? = $ac_status" >&5 + echo "$as_me:11996: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -12041,11 +12049,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:12044: $lt_compile\"" >&5) + (eval echo "\"\$as_me:12052: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:12048: \$? = $ac_status" >&5 + echo "$as_me:12056: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -14189,7 +14197,7 @@ else lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2 lt_status=$lt_dlunknown cat > conftest.$ac_ext < conftest.$ac_ext <&5) + (eval echo "\"\$as_me:16491: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:16487: \$? = $ac_status" >&5 + echo "$as_me:16495: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -16540,11 +16548,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:16543: $lt_compile\"" >&5) + (eval echo "\"\$as_me:16551: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:16547: \$? = $ac_status" >&5 + echo "$as_me:16555: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -17868,7 +17876,7 @@ else lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2 lt_status=$lt_dlunknown cat > conftest.$ac_ext < conftest.$ac_ext <&5) + (eval echo "\"\$as_me:18814: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:18810: \$? = $ac_status" >&5 + echo "$as_me:18818: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -18863,11 +18871,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:18866: $lt_compile\"" >&5) + (eval echo "\"\$as_me:18874: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:18870: \$? = $ac_status" >&5 + echo "$as_me:18878: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -20897,11 +20905,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:20900: $lt_compile\"" >&5) + (eval echo "\"\$as_me:20908: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:20904: \$? = $ac_status" >&5 + echo "$as_me:20912: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -21140,11 +21148,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:21143: $lt_compile\"" >&5) + (eval echo "\"\$as_me:21151: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:21147: \$? = $ac_status" >&5 + echo "$as_me:21155: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -21200,11 +21208,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:21203: $lt_compile\"" >&5) + (eval echo "\"\$as_me:21211: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:21207: \$? = $ac_status" >&5 + echo "$as_me:21215: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -23348,7 +23356,7 @@ else lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2 lt_status=$lt_dlunknown cat > conftest.$ac_ext < conftest.$ac_ext < conftest.$ac_ext + echo '#line 9131 "configure"' > conftest.$ac_ext if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 (eval $ac_compile) 2>&5 ac_status=$? @@ -11242,11 +11250,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:11245: $lt_compile\"" >&5) + (eval echo "\"\$as_me:11253: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:11249: \$? = $ac_status" >&5 + echo "$as_me:11257: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -11485,11 +11493,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:11488: $lt_compile\"" >&5) + (eval echo "\"\$as_me:11496: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:11492: \$? = $ac_status" >&5 + echo "$as_me:11500: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -11545,11 +11553,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:11548: $lt_compile\"" >&5) + (eval echo "\"\$as_me:11556: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:11552: \$? = $ac_status" >&5 + echo "$as_me:11560: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -13693,7 +13701,7 @@ else lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2 lt_status=$lt_dlunknown cat > conftest.$ac_ext < conftest.$ac_ext <&5) + (eval echo "\"\$as_me:15995: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:15991: \$? = $ac_status" >&5 + echo "$as_me:15999: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -16044,11 +16052,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:16047: $lt_compile\"" >&5) + (eval echo "\"\$as_me:16055: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:16051: \$? = $ac_status" >&5 + echo "$as_me:16059: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -17372,7 +17380,7 @@ else lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2 lt_status=$lt_dlunknown cat > conftest.$ac_ext < conftest.$ac_ext <&5) + (eval echo "\"\$as_me:18318: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:18314: \$? = $ac_status" >&5 + echo "$as_me:18322: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -18367,11 +18375,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:18370: $lt_compile\"" >&5) + (eval echo "\"\$as_me:18378: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:18374: \$? = $ac_status" >&5 + echo "$as_me:18382: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -20401,11 +20409,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:20404: $lt_compile\"" >&5) + (eval echo "\"\$as_me:20412: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:20408: \$? = $ac_status" >&5 + echo "$as_me:20416: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -20644,11 +20652,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:20647: $lt_compile\"" >&5) + (eval echo "\"\$as_me:20655: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:20651: \$? = $ac_status" >&5 + echo "$as_me:20659: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -20704,11 +20712,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:20707: $lt_compile\"" >&5) + (eval echo "\"\$as_me:20715: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:20711: \$? = $ac_status" >&5 + echo "$as_me:20719: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -22852,7 +22860,7 @@ else lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2 lt_status=$lt_dlunknown cat > conftest.$ac_ext < conftest.$ac_ext < Date: Mon, 28 Apr 2008 23:45:41 +0000 Subject: [PATCH 036/137] update copyright notice --- bin/dig/dig.c | 58 ++++++++++++++-------------- bin/dig/host.docbook | 5 ++- bin/tests/system/ifconfig.sh | 6 +-- config.h.win32 | 10 ++--- lib/bind/bsd/Makefile.in | 6 +-- lib/bind/dst/Makefile.in | 6 +-- lib/bind/inet/Makefile.in | 6 +-- lib/bind/irs/Makefile.in | 6 +-- lib/bind/isc/Makefile.in | 6 +-- lib/bind/nameser/Makefile.in | 6 +-- lib/bind/resolv/Makefile.in | 6 +-- lib/bind9/check.c | 40 +++++++++---------- lib/dns/adb.c | 12 +++--- lib/dns/cache.c | 20 +++++----- lib/dns/rdata/generic/txt_16.c | 4 +- lib/dns/rdata/in_1/naptr_35.c | 10 ++--- lib/isc/include/isc/mem.h | 44 ++++++++++----------- lib/isc/mem.c | 10 ++--- lib/isc/print.c | 6 +-- lib/isc/unix/time.c | 8 ++-- lib/isc/win32/include/isc/platform.h | 10 ++--- lib/isc/win32/interfaceiter.c | 10 ++--- lib/isc/win32/net.c | 4 +- util/kit.sh | 4 +- 24 files changed, 152 insertions(+), 151 deletions(-) diff --git a/bin/dig/dig.c b/bin/dig/dig.c index eff16e0b55..d5bb953db1 100644 --- a/bin/dig/dig.c +++ b/bin/dig/dig.c @@ -1,5 +1,5 @@ /* - * Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC") + * Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC") * Copyright (C) 2000-2003 Internet Software Consortium. * * Permission to use, copy, modify, and/or distribute this software for any @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: dig.c,v 1.157.2.13.2.36 2008/04/28 02:47:56 marka Exp $ */ +/* $Id: dig.c,v 1.157.2.13.2.37 2008/04/28 23:45:35 tbox Exp $ */ #include #include @@ -47,7 +47,7 @@ #define ADD_STRING(b, s) { \ if (strlen(s) >= isc_buffer_availablelength(b)) \ - return (ISC_R_NOSPACE); \ + return (ISC_R_NOSPACE); \ else \ isc_buffer_putstr(b, s); \ } @@ -367,7 +367,7 @@ printrdataset(dns_name_t *owner_name, dns_rdataset_t *rdataset, else if (nottl || noclass) result = dns_master_stylecreate(&style, styleflags, 24, 24, 32, 40, 80, 8, mctx); - else + else result = dns_master_stylecreate(&style, styleflags, 24, 32, 40, 48, 80, 8, mctx); check_result(result, "dns_master_stylecreate"); @@ -376,7 +376,7 @@ printrdataset(dns_name_t *owner_name, dns_rdataset_t *rdataset, if (style != NULL) dns_master_styledestroy(&style, mctx); - + return(result); } #endif @@ -413,7 +413,7 @@ printmessage(dig_query_t *query, dns_message_t *msg, isc_boolean_t headers) { else if (nottl || noclass) result = dns_master_stylecreate(&style, styleflags, 24, 24, 32, 40, 80, 8, mctx); - else + else result = dns_master_stylecreate(&style, styleflags, 24, 32, 40, 48, 80, 8, mctx); check_result(result, "dns_master_stylecreate"); @@ -613,7 +613,7 @@ printgreeting(int argc, char **argv, dig_lookup_t *lookup) { strncat(lookup->cmdline, append, remaining); } if (first) { - snprintf(append, sizeof(append), + snprintf(append, sizeof(append), ";; global options: %s %s\n", short_form ? "short_form" : "", printcmd ? "printcmd" : ""); @@ -691,7 +691,7 @@ plus_option(char *option, isc_boolean_t is_batchfile, FULLCHECK2("aaonly", "aaflag"); lookup->aaonly = state; break; - case 'd': + case 'd': switch (cmd[2]) { case 'd': /* additional */ FULLCHECK("additional"); @@ -776,11 +776,11 @@ plus_option(char *option, isc_boolean_t is_batchfile, FULLCHECK("defname"); usesearch = state; break; - case 'n': /* dnssec */ + case 'n': /* dnssec */ FULLCHECK("dnssec"); lookup->dnssec = state; break; - case 'o': /* domain */ + case 'o': /* domain */ FULLCHECK("domain"); if (value == NULL) goto need_value; @@ -844,7 +844,7 @@ plus_option(char *option, isc_boolean_t is_batchfile, goto invalid_option; } break; - case 'q': + case 'q': switch (cmd[1]) { case 'r': /* qr */ FULLCHECK("qr"); @@ -907,11 +907,11 @@ plus_option(char *option, isc_boolean_t is_batchfile, break; #ifdef DIG_SIGCHASE case 'i': /* sigchase */ - FULLCHECK("sigchase"); + FULLCHECK("sigchase"); lookup->sigchase = state; if (lookup->sigchase) lookup->dnssec = ISC_TRUE; - break; + break; #endif case 't': /* stats */ FULLCHECK("stats"); @@ -939,7 +939,7 @@ plus_option(char *option, isc_boolean_t is_batchfile, timeout = 1; break; #if DIG_SIGCHASE_TD - case 'o': /* topdown */ + case 'o': /* topdown */ FULLCHECK("topdown"); lookup->do_topdown = state; break; @@ -974,7 +974,7 @@ plus_option(char *option, isc_boolean_t is_batchfile, #ifdef DIG_SIGCHASE case 'u': /* trusted-key */ FULLCHECK("trusted-key"); - if (value == NULL) + if (value == NULL) goto need_value; if (!state) goto invalid_option; @@ -1018,8 +1018,8 @@ static const char *single_dash_opts = "46dhimnv"; static const char *dash_opts = "46bcdfhikmnptvyx"; static isc_boolean_t dash_option(char *option, char *next, dig_lookup_t **lookup, - isc_boolean_t *open_type_class, isc_boolean_t *need_clone, - int argc, char **argv, isc_boolean_t *firstarg) + isc_boolean_t *open_type_class, isc_boolean_t *need_clone, + int argc, char **argv, isc_boolean_t *firstarg) { char opt, *value, *ptr; isc_result_t result; @@ -1107,7 +1107,7 @@ dash_option(char *option, char *next, dig_lookup_t **lookup, hash = strchr(value, '#'); if (hash != NULL) { srcport = (in_port_t) - parse_uint(hash + 1, + parse_uint(hash + 1, "port number", MAXPORT); *hash = '\0'; } else @@ -1179,7 +1179,7 @@ dash_option(char *option, char *next, dig_lookup_t **lookup, (*lookup)->rdtypeset = ISC_TRUE; (*lookup)->ixfr_serial = parse_uint(&value[5], "serial number", - MAXSERIAL); + MAXSERIAL); (*lookup)->section_question = plusquest; (*lookup)->comments = pluscomm; } else { @@ -1286,7 +1286,7 @@ getaddresses(dig_lookup_t *lookup, const char *host) { char tmp[ISC_NETADDR_FORMATSIZE]; result = bind9_getaddresses(host, 0, sockaddrs, - DIG_MAX_ADDRESSES, &count); + DIG_MAX_ADDRESSES, &count); if (result != ISC_R_SUCCESS) fatal("couldn't get address for '%s': %s", host, isc_result_totext(result)); @@ -1348,7 +1348,7 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only, if (homedir != NULL) { unsigned int n; n = snprintf(rcfile, sizeof(rcfile), "%s/.digrc", - homedir); + homedir); if (n < sizeof(rcfile)) batchfp = fopen(rcfile, "r"); } @@ -1402,16 +1402,16 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only, if (rc <= 1) { if (dash_option(&rv[0][1], NULL, &lookup, &open_type_class, - &need_clone, argc, argv, - &firstarg)) { + &need_clone, argc, argv, + &firstarg)) { rc--; rv++; } } else { if (dash_option(&rv[0][1], rv[1], &lookup, &open_type_class, - &need_clone, argc, argv, - &firstarg)) { + &need_clone, argc, argv, + &firstarg)) { rc--; rv++; } @@ -1428,7 +1428,7 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only, tr.base = rv[0]; tr.length = strlen(rv[0]); result = dns_rdatatype_fromtext(&rdtype, - (isc_textregion_t *)&tr); + (isc_textregion_t *)&tr); if (result == ISC_R_SUCCESS && rdtype == dns_rdatatype_ixfr) { result = DNS_R_UNKNOWN; @@ -1449,8 +1449,8 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only, lookup->rdtypeset = ISC_TRUE; lookup->ixfr_serial = parse_uint(&rv[0][5], - "serial number", - MAXSERIAL); + "serial number", + MAXSERIAL); lookup->section_question = plusquest; lookup->comments = pluscomm; @@ -1485,7 +1485,7 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only, lookup = clone_lookup(default_lookup, ISC_TRUE); need_clone = ISC_TRUE; - strncpy(lookup->textname, rv[0], + strncpy(lookup->textname, rv[0], sizeof(lookup->textname)); lookup->textname[sizeof(lookup->textname)-1]=0; lookup->trace_root = ISC_TF(lookup->trace || diff --git a/bin/dig/host.docbook b/bin/dig/host.docbook index cab34dbfa8..29ca7ea658 100644 --- a/bin/dig/host.docbook +++ b/bin/dig/host.docbook @@ -2,7 +2,7 @@ "http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd" []> - + @@ -37,6 +37,7 @@ 2004 2005 2007 + 2008 Internet Systems Consortium, Inc. ("ISC") diff --git a/bin/tests/system/ifconfig.sh b/bin/tests/system/ifconfig.sh index 03f96fb9a4..9dab0c3a75 100644 --- a/bin/tests/system/ifconfig.sh +++ b/bin/tests/system/ifconfig.sh @@ -1,9 +1,9 @@ #!/bin/sh # -# Copyright (C) 2004 Internet Systems Consortium, Inc. ("ISC") +# Copyright (C) 2004, 2008 Internet Systems Consortium, Inc. ("ISC") # Copyright (C) 2000-2003 Internet Software Consortium. # -# Permission to use, copy, modify, and distribute this software for any +# Permission to use, copy, modify, and/or distribute this software for any # purpose with or without fee is hereby granted, provided that the above # copyright notice and this permission notice appear in all copies. # @@ -15,7 +15,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: ifconfig.sh,v 1.35.2.8.2.9 2008/04/28 04:32:48 marka Exp $ +# $Id: ifconfig.sh,v 1.35.2.8.2.10 2008/04/28 23:45:35 tbox Exp $ # # Set up interface aliases for bind9 system tests. diff --git a/config.h.win32 b/config.h.win32 index 2ceea196ee..0c80068fec 100644 --- a/config.h.win32 +++ b/config.h.win32 @@ -1,5 +1,5 @@ /* - * Copyright (C) 2004, 2006, 2007 Internet Systems Consortium, Inc. ("ISC") + * Copyright (C) 2004, 2006-2008 Internet Systems Consortium, Inc. ("ISC") * Copyright (C) 1999-2001, 2003 Internet Software Consortium. * * Permission to use, copy, modify, and/or distribute this software for any @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: config.h.win32,v 1.6.12.12 2008/04/28 05:35:44 marka Exp $ */ +/* $Id: config.h.win32,v 1.6.12.13 2008/04/28 23:45:35 tbox Exp $ */ /* * win32 configuration file @@ -119,7 +119,7 @@ /* Define if libcrypto has DSA_generate_parameters */ #define HAVE_DSA_GENERATE_PARAMETERS - + /* Define if libcrypto has DH_generate_parameters */ #define HAVE_DH_GENERATE_PARAMETERS @@ -144,7 +144,7 @@ /* open() under unix allows setting of read/write permissions * at the owner, group and other levels. These don't exist in NT - * We'll just map them all to the NT equivalent + * We'll just map them all to the NT equivalent */ #define S_IRUSR _S_IREAD /* Owner read permission */ @@ -194,7 +194,7 @@ typedef long off_t; */ #include -/* We actually are using the CryptAPI and not a device */ +/* We actually are using the CryptAPI and not a device */ #define PATH_RANDOMDEV "CryptAPI" #include diff --git a/lib/bind/bsd/Makefile.in b/lib/bind/bsd/Makefile.in index 0e8bccc993..998cd637e2 100644 --- a/lib/bind/bsd/Makefile.in +++ b/lib/bind/bsd/Makefile.in @@ -1,7 +1,7 @@ -# Copyright (C) 2004 Internet Systems Consortium, Inc. ("ISC") +# Copyright (C) 2004, 2008 Internet Systems Consortium, Inc. ("ISC") # Copyright (C) 2001 Internet Software Consortium. # -# Permission to use, copy, modify, and distribute this software for any +# Permission to use, copy, modify, and/or distribute this software for any # purpose with or without fee is hereby granted, provided that the above # copyright notice and this permission notice appear in all copies. # @@ -13,7 +13,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: Makefile.in,v 1.6.206.2 2008/04/28 04:52:06 marka Exp $ +# $Id: Makefile.in,v 1.6.206.3 2008/04/28 23:45:35 tbox Exp $ srcdir= @srcdir@ VPATH = @srcdir@ diff --git a/lib/bind/dst/Makefile.in b/lib/bind/dst/Makefile.in index bf8158b222..dbc0265669 100644 --- a/lib/bind/dst/Makefile.in +++ b/lib/bind/dst/Makefile.in @@ -1,7 +1,7 @@ -# Copyright (C) 2004 Internet Systems Consortium, Inc. ("ISC") +# Copyright (C) 2004, 2008 Internet Systems Consortium, Inc. ("ISC") # Copyright (C) 2001 Internet Software Consortium. # -# Permission to use, copy, modify, and distribute this software for any +# Permission to use, copy, modify, and/or distribute this software for any # purpose with or without fee is hereby granted, provided that the above # copyright notice and this permission notice appear in all copies. # @@ -13,7 +13,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: Makefile.in,v 1.5.206.2 2008/04/28 04:52:06 marka Exp $ +# $Id: Makefile.in,v 1.5.206.3 2008/04/28 23:45:35 tbox Exp $ srcdir= @srcdir@ VPATH = @srcdir@ diff --git a/lib/bind/inet/Makefile.in b/lib/bind/inet/Makefile.in index 97dfd60d29..9f79b92431 100644 --- a/lib/bind/inet/Makefile.in +++ b/lib/bind/inet/Makefile.in @@ -1,7 +1,7 @@ -# Copyright (C) 2004 Internet Systems Consortium, Inc. ("ISC") +# Copyright (C) 2004, 2008 Internet Systems Consortium, Inc. ("ISC") # Copyright (C) 2001 Internet Software Consortium. # -# Permission to use, copy, modify, and distribute this software for any +# Permission to use, copy, modify, and/or distribute this software for any # purpose with or without fee is hereby granted, provided that the above # copyright notice and this permission notice appear in all copies. # @@ -13,7 +13,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: Makefile.in,v 1.4.206.2 2008/04/28 04:52:06 marka Exp $ +# $Id: Makefile.in,v 1.4.206.3 2008/04/28 23:45:35 tbox Exp $ srcdir= @srcdir@ VPATH = @srcdir@ diff --git a/lib/bind/irs/Makefile.in b/lib/bind/irs/Makefile.in index e6e0205131..ba0092b9ae 100644 --- a/lib/bind/irs/Makefile.in +++ b/lib/bind/irs/Makefile.in @@ -1,7 +1,7 @@ -# Copyright (C) 2004 Internet Systems Consortium, Inc. ("ISC") +# Copyright (C) 2004, 2008 Internet Systems Consortium, Inc. ("ISC") # Copyright (C) 2001 Internet Software Consortium. # -# Permission to use, copy, modify, and distribute this software for any +# Permission to use, copy, modify, and/or distribute this software for any # purpose with or without fee is hereby granted, provided that the above # copyright notice and this permission notice appear in all copies. # @@ -13,7 +13,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: Makefile.in,v 1.7.206.4 2008/04/28 04:52:06 marka Exp $ +# $Id: Makefile.in,v 1.7.206.5 2008/04/28 23:45:35 tbox Exp $ srcdir= @srcdir@ VPATH = @srcdir@ diff --git a/lib/bind/isc/Makefile.in b/lib/bind/isc/Makefile.in index 09bad47439..b03a9f2c0e 100644 --- a/lib/bind/isc/Makefile.in +++ b/lib/bind/isc/Makefile.in @@ -1,7 +1,7 @@ -# Copyright (C) 2004 Internet Systems Consortium, Inc. ("ISC") +# Copyright (C) 2004, 2008 Internet Systems Consortium, Inc. ("ISC") # Copyright (C) 2001 Internet Software Consortium. # -# Permission to use, copy, modify, and distribute this software for any +# Permission to use, copy, modify, and/or distribute this software for any # purpose with or without fee is hereby granted, provided that the above # copyright notice and this permission notice appear in all copies. # @@ -13,7 +13,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: Makefile.in,v 1.6.206.2 2008/04/28 04:52:06 marka Exp $ +# $Id: Makefile.in,v 1.6.206.3 2008/04/28 23:45:35 tbox Exp $ srcdir= @srcdir@ VPATH = @srcdir@ diff --git a/lib/bind/nameser/Makefile.in b/lib/bind/nameser/Makefile.in index 4410fda49f..b7b7bc7bad 100644 --- a/lib/bind/nameser/Makefile.in +++ b/lib/bind/nameser/Makefile.in @@ -1,7 +1,7 @@ -# Copyright (C) 2004 Internet Systems Consortium, Inc. ("ISC") +# Copyright (C) 2004, 2008 Internet Systems Consortium, Inc. ("ISC") # Copyright (C) 2001 Internet Software Consortium. # -# Permission to use, copy, modify, and distribute this software for any +# Permission to use, copy, modify, and/or distribute this software for any # purpose with or without fee is hereby granted, provided that the above # copyright notice and this permission notice appear in all copies. # @@ -13,7 +13,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: Makefile.in,v 1.4.206.2 2008/04/28 04:52:06 marka Exp $ +# $Id: Makefile.in,v 1.4.206.3 2008/04/28 23:45:35 tbox Exp $ srcdir= @srcdir@ VPATH = @srcdir@ diff --git a/lib/bind/resolv/Makefile.in b/lib/bind/resolv/Makefile.in index 13ae6be6ae..06ceb96aea 100644 --- a/lib/bind/resolv/Makefile.in +++ b/lib/bind/resolv/Makefile.in @@ -1,7 +1,7 @@ -# Copyright (C) 2004, 2005 Internet Systems Consortium, Inc. ("ISC") +# Copyright (C) 2004, 2005, 2008 Internet Systems Consortium, Inc. ("ISC") # Copyright (C) 2001 Internet Software Consortium. # -# Permission to use, copy, modify, and distribute this software for any +# Permission to use, copy, modify, and/or distribute this software for any # purpose with or without fee is hereby granted, provided that the above # copyright notice and this permission notice appear in all copies. # @@ -13,7 +13,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: Makefile.in,v 1.3.206.4 2008/04/28 04:52:06 marka Exp $ +# $Id: Makefile.in,v 1.3.206.5 2008/04/28 23:45:35 tbox Exp $ srcdir= @srcdir@ VPATH = @srcdir@ diff --git a/lib/bind9/check.c b/lib/bind9/check.c index 28b193874c..4aaa37e38b 100644 --- a/lib/bind9/check.c +++ b/lib/bind9/check.c @@ -1,5 +1,5 @@ /* - * Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC") + * Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC") * Copyright (C) 2001-2003 Internet Software Consortium. * * Permission to use, copy, modify, and/or distribute this software for any @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: check.c,v 1.37.6.40 2008/04/28 05:22:33 marka Exp $ */ +/* $Id: check.c,v 1.37.6.41 2008/04/28 23:45:35 tbox Exp $ */ #include @@ -411,8 +411,8 @@ check_options(const cfg_obj_t *options, isc_log_t *logctx, isc_mem_t *mctx) { (void)cfg_map_get(options, "preferred-glue", &obj); if (obj != NULL) { const char *str; - str = cfg_obj_asstring(obj); - if (strcasecmp(str, "a") != 0 && + str = cfg_obj_asstring(obj); + if (strcasecmp(str, "a") != 0 && strcasecmp(str, "aaaa") != 0 && strcasecmp(str, "none") != 0) cfg_obj_log(obj, logctx, ISC_LOG_ERROR, @@ -441,7 +441,7 @@ check_options(const cfg_obj_t *options, isc_log_t *logctx, isc_mem_t *mctx) { isc_buffer_add(&b, strlen(str)); tresult = dns_name_fromtext(name, &b, dns_rootname, - ISC_FALSE, NULL); + ISC_FALSE, NULL); if (tresult != ISC_R_SUCCESS) { cfg_obj_log(obj, logctx, ISC_LOG_ERROR, "bad domain name '%s'", @@ -451,7 +451,7 @@ check_options(const cfg_obj_t *options, isc_log_t *logctx, isc_mem_t *mctx) { } } } - + /* * Set supported DNSSEC algorithms. */ @@ -597,7 +597,7 @@ get_masters_def(const cfg_obj_t *cctx, const char *name, const cfg_obj_t **ret) static isc_result_t validate_masters(const cfg_obj_t *obj, const cfg_obj_t *config, - isc_uint32_t *countp, isc_log_t *logctx, isc_mem_t *mctx) + isc_uint32_t *countp, isc_log_t *logctx, isc_mem_t *mctx) { isc_result_t result = ISC_R_SUCCESS; isc_result_t tresult; @@ -619,7 +619,7 @@ validate_masters(const cfg_obj_t *obj, const cfg_obj_t *config, newlist: list = cfg_tuple_get(obj, "addresses"); element = cfg_list_first(list); - resume: + resume: for ( ; element != NULL; element = cfg_list_next(element)) @@ -953,7 +953,7 @@ check_zoneconf(const cfg_obj_t *zconfig, const cfg_obj_t *voptions, /* * Check that forwarding is reasonable. */ - obj = NULL; + obj = NULL; if (root) { if (voptions != NULL) (void)cfg_map_get(voptions, "forwarders", &obj); @@ -994,7 +994,7 @@ check_zoneconf(const cfg_obj_t *zconfig, const cfg_obj_t *voptions, result = tresult; } } - + return (result); } @@ -1003,7 +1003,7 @@ bind9_check_key(const cfg_obj_t *key, isc_log_t *logctx) { const cfg_obj_t *algobj = NULL; const cfg_obj_t *secretobj = NULL; const char *keyname = cfg_obj_asstring(cfg_map_getname(key)); - + (void)cfg_map_get(key, "algorithm", &algobj); (void)cfg_map_get(key, "secret", &secretobj); if (secretobj == NULL || algobj == NULL) { @@ -1120,7 +1120,7 @@ check_servers(const cfg_obj_t *servers, isc_log_t *logctx) { } return (result); } - + static isc_result_t check_viewconf(const cfg_obj_t *config, const cfg_obj_t *voptions, dns_rdataclass_t vclass, isc_log_t *logctx, isc_mem_t *mctx) @@ -1178,7 +1178,7 @@ check_viewconf(const cfg_obj_t *config, const cfg_obj_t *voptions, isc_symtab_destroy(&symtab); return (tresult); } - + if (voptions != NULL) { keys = NULL; (void)cfg_map_get(voptions, "key", &keys); @@ -1276,7 +1276,7 @@ bind9_check_namedconf(const cfg_obj_t *config, isc_log_t *logctx, check_servers(servers, logctx) != ISC_R_SUCCESS) result = ISC_R_FAILURE; - if (options != NULL && + if (options != NULL && check_order(options, logctx) != ISC_R_SUCCESS) result = ISC_R_FAILURE; @@ -1338,7 +1338,7 @@ bind9_check_namedconf(const cfg_obj_t *config, isc_log_t *logctx, const char *file; unsigned int line; RUNTIME_CHECK(isc_symtab_lookup(symtab, key, - vclass, &symvalue) == ISC_R_SUCCESS); + vclass, &symvalue) == ISC_R_SUCCESS); file = cfg_obj_file(symvalue.as_cpointer); line = cfg_obj_line(symvalue.as_cpointer); cfg_obj_log(view, logctx, ISC_LOG_ERROR, @@ -1378,8 +1378,8 @@ bind9_check_namedconf(const cfg_obj_t *config, isc_log_t *logctx, } } - tresult = cfg_map_get(config, "acl", &acls); - if (tresult == ISC_R_SUCCESS) { + tresult = cfg_map_get(config, "acl", &acls); + if (tresult == ISC_R_SUCCESS) { const cfg_listelt_t *elt; const cfg_listelt_t *elt2; const char *aclname; @@ -1398,7 +1398,7 @@ bind9_check_namedconf(const cfg_obj_t *config, isc_log_t *logctx, cfg_obj_log(acl, logctx, ISC_LOG_ERROR, "attempt to redefine " "builtin acl '%s'", - aclname); + aclname); result = ISC_R_FAILURE; break; } @@ -1428,8 +1428,8 @@ bind9_check_namedconf(const cfg_obj_t *config, isc_log_t *logctx, } } - tresult = cfg_map_get(config, "kal", &kals); - if (tresult == ISC_R_SUCCESS) { + tresult = cfg_map_get(config, "kal", &kals); + if (tresult == ISC_R_SUCCESS) { const cfg_listelt_t *elt; const cfg_listelt_t *elt2; const char *aclname; diff --git a/lib/dns/adb.c b/lib/dns/adb.c index 456a0b5adf..42e2507a61 100644 --- a/lib/dns/adb.c +++ b/lib/dns/adb.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: adb.c,v 1.181.2.11.2.36 2008/04/28 03:18:35 marka Exp $ */ +/* $Id: adb.c,v 1.181.2.11.2.37 2008/04/28 23:45:37 tbox Exp $ */ /* * Implementation notes @@ -1983,7 +1983,7 @@ destroy(dns_adb_t *adb) { DESTROYLOCK(&adb->reflock); DESTROYLOCK(&adb->lock); DESTROYLOCK(&adb->mplock); - DESTROYLOCK(&adb->overmemlock); + DESTROYLOCK(&adb->overmemlock); isc_mem_putanddetach(&adb->mctx, adb, sizeof(dns_adb_t)); } @@ -2054,9 +2054,9 @@ dns_adb_create(isc_mem_t *mem, dns_view_t *view, isc_timermgr_t *timermgr, if (result != ISC_R_SUCCESS) goto fail0d; - result = isc_mutex_init(&adb->overmemlock); - if (result != ISC_R_SUCCESS) - goto fail0e; + result = isc_mutex_init(&adb->overmemlock); + if (result != ISC_R_SUCCESS) + goto fail0e; /* * Initialize the bucket locks for names and elements. @@ -2160,7 +2160,7 @@ dns_adb_create(isc_mem_t *mem, dns_view_t *view, isc_timermgr_t *timermgr, if (adb->afmp != NULL) isc_mempool_destroy(&adb->afmp); - DESTROYLOCK(&adb->overmemlock); + DESTROYLOCK(&adb->overmemlock); fail0e: DESTROYLOCK(&adb->reflock); fail0d: diff --git a/lib/dns/cache.c b/lib/dns/cache.c index d1fade2d90..1212a73212 100644 --- a/lib/dns/cache.c +++ b/lib/dns/cache.c @@ -1,8 +1,8 @@ /* - * Copyright (C) 2004-2006 Internet Systems Consortium, Inc. ("ISC") + * Copyright (C) 2004-2006, 2008 Internet Systems Consortium, Inc. ("ISC") * Copyright (C) 1999-2003 Internet Software Consortium. * - * Permission to use, copy, modify, and distribute this software for any + * Permission to use, copy, modify, and/or distribute this software for any * purpose with or without fee is hereby granted, provided that the above * copyright notice and this permission notice appear in all copies. * @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: cache.c,v 1.45.2.4.8.16 2008/04/28 03:18:36 marka Exp $ */ +/* $Id: cache.c,v 1.45.2.4.8.17 2008/04/28 23:45:37 tbox Exp $ */ #include @@ -466,7 +466,7 @@ dns_cache_setcleaninginterval(dns_cache_t *cache, unsigned int t) { isc_timertype_ticker, NULL, &interval, ISC_FALSE); } - if (result != ISC_R_SUCCESS) + if (result != ISC_R_SUCCESS) isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE, DNS_LOGMODULE_CACHE, ISC_LOG_WARNING, "could not set cache cleaning interval: %s", @@ -558,7 +558,7 @@ cache_cleaner_init(dns_cache_t *cache, isc_taskmgr_t *taskmgr, result = ISC_R_NOMEMORY; goto cleanup; } - + cleaner->overmem_event = isc_event_allocate(cache->mctx, cleaner, DNS_EVENT_CACHEOVERMEM, @@ -596,7 +596,7 @@ begin_cleaning(cache_cleaner_t *cleaner) { /* * Create an iterator, if it does not already exist, and - * position it at the beginning of the cache. + * position it at the beginning of the cache. */ if (cleaner->iterator == NULL) result = dns_db_createiterator(cleaner->cache->db, ISC_FALSE, @@ -635,7 +635,7 @@ begin_cleaning(cache_cleaner_t *cleaner) { isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE, DNS_LOGMODULE_CACHE, ISC_LOG_DEBUG(1), "begin cache cleaning, mem inuse %lu", - (unsigned long)isc_mem_inuse(cleaner->cache->mctx)); + (unsigned long)isc_mem_inuse(cleaner->cache->mctx)); cleaner->state = cleaner_s_busy; isc_task_send(cleaner->task, &cleaner->resched_event); } @@ -695,7 +695,7 @@ static void overmem_cleaning_action(isc_task_t *task, isc_event_t *event) { cache_cleaner_t *cleaner = event->ev_arg; isc_boolean_t want_cleaning = ISC_FALSE; - + UNUSED(task); INSIST(task == cleaner->task); @@ -908,7 +908,7 @@ water(void *arg, int mark) { REQUIRE(VALID_CACHE(cache)); LOCK(&cache->cleaner.lock); - + if (overmem != cache->cleaner.overmem) { dns_db_overmem(cache->db, overmem); cache->cleaner.overmem = overmem; @@ -1037,7 +1037,7 @@ dns_cache_flushname(dns_cache_t *cache, dns_name_t *name) { dns_rdatasetiter_t *iter = NULL; dns_dbnode_t *node = NULL; dns_db_t *db = NULL; - + LOCK(&cache->lock); if (cache->db != NULL) dns_db_attach(cache->db, &db); diff --git a/lib/dns/rdata/generic/txt_16.c b/lib/dns/rdata/generic/txt_16.c index 998cb3740a..eb511ba859 100644 --- a/lib/dns/rdata/generic/txt_16.c +++ b/lib/dns/rdata/generic/txt_16.c @@ -1,5 +1,5 @@ /* - * Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC") + * Copyright (C) 2004, 2007, 2008 Internet Systems Consortium, Inc. ("ISC") * Copyright (C) 1998-2003 Internet Software Consortium. * * Permission to use, copy, modify, and/or distribute this software for any @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: txt_16.c,v 1.37.12.8 2008/04/28 04:19:28 marka Exp $ */ +/* $Id: txt_16.c,v 1.37.12.9 2008/04/28 23:45:37 tbox Exp $ */ /* Reviewed: Thu Mar 16 15:40:00 PST 2000 by bwelling */ diff --git a/lib/dns/rdata/in_1/naptr_35.c b/lib/dns/rdata/in_1/naptr_35.c index de6e4f4491..fc6ee8cad9 100644 --- a/lib/dns/rdata/in_1/naptr_35.c +++ b/lib/dns/rdata/in_1/naptr_35.c @@ -1,8 +1,8 @@ /* - * Copyright (C) 2004 Internet Systems Consortium, Inc. ("ISC") + * Copyright (C) 2004, 2008 Internet Systems Consortium, Inc. ("ISC") * Copyright (C) 1999-2001, 2003 Internet Software Consortium. * - * Permission to use, copy, modify, and distribute this software for any + * Permission to use, copy, modify, and/or distribute this software for any * purpose with or without fee is hereby granted, provided that the above * copyright notice and this permission notice appear in all copies. * @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: naptr_35.c,v 1.43.2.1.2.4 2008/04/28 04:19:28 marka Exp $ */ +/* $Id: naptr_35.c,v 1.43.2.1.2.5 2008/04/28 23:45:37 tbox Exp $ */ /* Reviewed: Thu Mar 16 16:52:50 PST 2000 by bwelling */ @@ -154,7 +154,7 @@ totext_in_naptr(ARGS_TOTEXT) { static inline isc_result_t fromwire_in_naptr(ARGS_FROMWIRE) { - dns_name_t name; + dns_name_t name; isc_region_t sr; REQUIRE(type == 35); @@ -165,7 +165,7 @@ fromwire_in_naptr(ARGS_FROMWIRE) { dns_decompress_setmethods(dctx, DNS_COMPRESS_NONE); - dns_name_init(&name, NULL); + dns_name_init(&name, NULL); /* * Order, preference. diff --git a/lib/isc/include/isc/mem.h b/lib/isc/include/isc/mem.h index 92cdffe6dd..979407d89c 100644 --- a/lib/isc/include/isc/mem.h +++ b/lib/isc/include/isc/mem.h @@ -1,5 +1,5 @@ /* - * Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC") + * Copyright (C) 2004, 2007, 2008 Internet Systems Consortium, Inc. ("ISC") * Copyright (C) 1997-2001, 2003 Internet Software Consortium. * * Permission to use, copy, modify, and/or distribute this software for any @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: mem.h,v 1.54.12.8 2008/04/28 03:18:36 marka Exp $ */ +/* $Id: mem.h,v 1.54.12.9 2008/04/28 23:45:38 tbox Exp $ */ #ifndef ISC_MEM_H #define ISC_MEM_H 1 @@ -170,11 +170,11 @@ LIBISC_EXTERNAL_DATA extern unsigned int isc_mem_debugging; #define isc_mempool_put(c, p) isc__mempool_put((c), (p) _ISC_MEM_FILELINE) #endif -isc_result_t +isc_result_t isc_mem_create(size_t max_size, size_t target_size, isc_mem_t **mctxp); -isc_result_t +isc_result_t isc_mem_createx(size_t max_size, size_t target_size, isc_memalloc_t memalloc, isc_memfree_t memfree, void *arg, isc_mem_t **mctxp); @@ -203,9 +203,9 @@ isc_mem_createx(size_t max_size, size_t target_size, * Requires: * mctxp != NULL && *mctxp == NULL */ -void +void isc_mem_attach(isc_mem_t *, isc_mem_t **); -void +void isc_mem_detach(isc_mem_t **); /* * Attach to / detach from a memory context. @@ -213,20 +213,20 @@ isc_mem_detach(isc_mem_t **); * This is intended for applications that use multiple memory contexts * in such a way that it is not obvious when the last allocations from * a given context has been freed and destroying the context is safe. - * + * * Most applications do not need to call these functions as they can * simply create a single memory context at the beginning of main() * and destroy it at the end of main(), thereby guaranteeing that it * is not destroyed while there are outstanding allocations. */ -void +void isc_mem_destroy(isc_mem_t **); /* * Destroy a memory context. */ -isc_result_t +isc_result_t isc_mem_ondestroy(isc_mem_t *ctx, isc_task_t *task, isc_event_t **event); @@ -235,13 +235,13 @@ isc_mem_ondestroy(isc_mem_t *ctx, * been successfully destroyed. */ -void +void isc_mem_stats(isc_mem_t *mctx, FILE *out); /* * Print memory usage statistics for 'mctx' on the stream 'out'. */ -void +void isc_mem_setdestroycheck(isc_mem_t *mctx, isc_boolean_t on); /* @@ -249,9 +249,9 @@ isc_mem_setdestroycheck(isc_mem_t *mctx, * destroyed and abort the program if any are present. */ -void +void isc_mem_setquota(isc_mem_t *, size_t); -size_t +size_t isc_mem_getquota(isc_mem_t *); /* * Set/get the memory quota of 'mctx'. This is a hard limit @@ -259,7 +259,7 @@ isc_mem_getquota(isc_mem_t *); * if it is exceeded, allocations will fail. */ -size_t +size_t isc_mem_inuse(isc_mem_t *mctx); /* * Get an estimate of the number of memory in use in 'mctx', in bytes. @@ -453,22 +453,22 @@ isc_mempool_setfillcount(isc_mempool_t *mpctx, unsigned int limit); /* * Pseudo-private functions for use via macros. Do not call directly. */ -void * +void * isc__mem_get(isc_mem_t *, size_t _ISC_MEM_FLARG); -void +void isc__mem_putanddetach(isc_mem_t **, void *, size_t _ISC_MEM_FLARG); -void +void isc__mem_put(isc_mem_t *, void *, size_t _ISC_MEM_FLARG); -void * +void * isc__mem_allocate(isc_mem_t *, size_t _ISC_MEM_FLARG); -void +void isc__mem_free(isc_mem_t *, void * _ISC_MEM_FLARG); -char * +char * isc__mem_strdup(isc_mem_t *, const char *_ISC_MEM_FLARG); -void * +void * isc__mempool_get(isc_mempool_t * _ISC_MEM_FLARG); -void +void isc__mempool_put(isc_mempool_t *, void * _ISC_MEM_FLARG); ISC_LANG_ENDDECLS diff --git a/lib/isc/mem.c b/lib/isc/mem.c index fa880918dc..69f6cab9ea 100644 --- a/lib/isc/mem.c +++ b/lib/isc/mem.c @@ -1,5 +1,5 @@ /* - * Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC") + * Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC") * Copyright (C) 1997-2003 Internet Software Consortium. * * Permission to use, copy, modify, and/or distribute this software for any @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: mem.c,v 1.98.2.7.2.13 2008/04/28 03:18:36 marka Exp $ */ +/* $Id: mem.c,v 1.98.2.7.2.14 2008/04/28 23:45:37 tbox Exp $ */ #include @@ -604,7 +604,7 @@ mem_get(isc_mem_t *ctx, size_t size) { ret = (ctx->memalloc)(ctx->arg, size); if (ret == NULL) - ctx->memalloc_failures++; + ctx->memalloc_failures++; #if ISC_MEM_FILL if (ret != NULL) @@ -1077,7 +1077,7 @@ isc__mem_put(isc_mem_t *ctx, void *ptr, size_t size FLARG) * when the context was pushed over hi_water but then had * isc_mem_setwater() called with 0 for hi_water and lo_water. */ - if (ctx->hi_called && + if (ctx->hi_called && (ctx->inuse < ctx->lo_water || ctx->lo_water == 0U)) { if (ctx->water != NULL) call_water = ISC_TRUE; @@ -1119,7 +1119,7 @@ print_active(isc_mem_t *mctx, FILE *out) { "\tptr %p size %u file %s line %u\n"); for (i = 0; i <= mctx->max_size; i++) { dl = ISC_LIST_HEAD(mctx->debuglist[i]); - + if (dl != NULL) found = ISC_TRUE; diff --git a/lib/isc/print.c b/lib/isc/print.c index c4fd4a187e..e4e4a709f7 100644 --- a/lib/isc/print.c +++ b/lib/isc/print.c @@ -1,8 +1,8 @@ /* - * Copyright (C) 2004-2006 Internet Systems Consortium, Inc. ("ISC") + * Copyright (C) 2004-2006, 2008 Internet Systems Consortium, Inc. ("ISC") * Copyright (C) 1999-2001, 2003 Internet Software Consortium. * - * Permission to use, copy, modify, and distribute this software for any + * Permission to use, copy, modify, and/or distribute this software for any * purpose with or without fee is hereby granted, provided that the above * copyright notice and this permission notice appear in all copies. * @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: print.c,v 1.22.2.3.2.5 2008/04/28 04:25:43 marka Exp $ */ +/* $Id: print.c,v 1.22.2.3.2.6 2008/04/28 23:45:38 tbox Exp $ */ /*! \file */ diff --git a/lib/isc/unix/time.c b/lib/isc/unix/time.c index b0b9cb58b5..c4b7f13600 100644 --- a/lib/isc/unix/time.c +++ b/lib/isc/unix/time.c @@ -1,8 +1,8 @@ /* - * Copyright (C) 2004 Internet Systems Consortium, Inc. ("ISC") + * Copyright (C) 2004, 2008 Internet Systems Consortium, Inc. ("ISC") * Copyright (C) 1998-2001, 2003 Internet Software Consortium. * - * Permission to use, copy, modify, and distribute this software for any + * Permission to use, copy, modify, and/or distribute this software for any * purpose with or without fee is hereby granted, provided that the above * copyright notice and this permission notice appear in all copies. * @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: time.c,v 1.34.2.6.2.5 2008/04/28 04:14:32 marka Exp $ */ +/* $Id: time.c,v 1.34.2.6.2.6 2008/04/28 23:45:41 tbox Exp $ */ #include @@ -408,5 +408,5 @@ isc_time_formattimestamp(const isc_time_t *t, char *buf, unsigned int len) { snprintf(buf + flen, len - flen, ".%03u", t->nanoseconds / 1000000); else - snprintf(buf, len, "99-Bad-9999 99:99:99.999"); + snprintf(buf, len, "99-Bad-9999 99:99:99.999"); } diff --git a/lib/isc/win32/include/isc/platform.h b/lib/isc/win32/include/isc/platform.h index 189c10a10b..881432fb7c 100644 --- a/lib/isc/win32/include/isc/platform.h +++ b/lib/isc/win32/include/isc/platform.h @@ -1,5 +1,5 @@ /* - * Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC") + * Copyright (C) 2004, 2007, 2008 Internet Systems Consortium, Inc. ("ISC") * Copyright (C) 2001, 2003 Internet Software Consortium. * * Permission to use, copy, modify, and/or distribute this software for any @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: platform.h,v 1.5.12.10 2008/04/28 05:35:45 marka Exp $ */ +/* $Id: platform.h,v 1.5.12.11 2008/04/28 23:45:41 tbox Exp $ */ #ifndef ISC_PLATFORM_H #define ISC_PLATFORM_H 1 @@ -65,19 +65,19 @@ #ifdef LIBISC_EXPORTS #define LIBISC_EXTERNAL_DATA __declspec(dllexport) #else -#define LIBISC_EXTERNAL_DATA __declspec(dllimport) +#define LIBISC_EXTERNAL_DATA __declspec(dllimport) #endif #ifdef LIBISCCFG_EXPORTS #define LIBISCCFG_EXTERNAL_DATA __declspec(dllexport) #else -#define LIBISCCFG_EXTERNAL_DATA __declspec(dllimport) +#define LIBISCCFG_EXTERNAL_DATA __declspec(dllimport) #endif #ifdef LIBISCCC_EXPORTS #define LIBISCCC_EXTERNAL_DATA __declspec(dllexport) #else -#define LIBISCCC_EXTERNAL_DATA __declspec(dllimport) +#define LIBISCCC_EXTERNAL_DATA __declspec(dllimport) #endif #ifdef LIBDNS_EXPORTS diff --git a/lib/isc/win32/interfaceiter.c b/lib/isc/win32/interfaceiter.c index a14aa4152d..955388e11b 100644 --- a/lib/isc/win32/interfaceiter.c +++ b/lib/isc/win32/interfaceiter.c @@ -1,5 +1,5 @@ /* - * Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC") + * Copyright (C) 2004, 2007, 2008 Internet Systems Consortium, Inc. ("ISC") * Copyright (C) 1999-2001, 2003 Internet Software Consortium. * * Permission to use, copy, modify, and/or distribute this software for any @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: interfaceiter.c,v 1.4.12.9 2008/04/28 05:35:45 marka Exp $ */ +/* $Id: interfaceiter.c,v 1.4.12.10 2008/04/28 23:45:41 tbox Exp $ */ /* * Note that this code will need to be revisited to support IPv6 Interfaces. @@ -106,7 +106,7 @@ get_addr(unsigned int family, isc_netaddr_t *dst, struct sockaddr *src) { isc_result_t isc_interfaceiter_create(isc_mem_t *mctx, isc_interfaceiter_t **iterp) { - char strbuf[ISC_STRERRORSIZE]; + char strbuf[ISC_STRERRORSIZE]; isc_interfaceiter_t *iter; isc_result_t result; int error; @@ -390,7 +390,7 @@ internal_current6(isc_interfaceiter_t *iter) { sprintf(iter->current.name, "TCP/IPv6 Interface %d", iter->pos6 + 1); - for (i = 0; i< 16; i++) + for (i = 0; i< 16; i++) iter->current.netmask.type.in6.s6_addr[i] = 0xff; iter->current.netmask.family = AF_INET6; return (ISC_R_SUCCESS); @@ -414,7 +414,7 @@ internal_next(isc_interfaceiter_t *iter) { * Microsoft's implementation is peculiar for returning * the list in reverse order */ - + if (iter->numIF == 0) iter->pos4 = (INTERFACE_INFO *)(iter->buf4 + (iter->v4IF)); diff --git a/lib/isc/win32/net.c b/lib/isc/win32/net.c index 14e7258888..af9a2f8fed 100644 --- a/lib/isc/win32/net.c +++ b/lib/isc/win32/net.c @@ -1,5 +1,5 @@ /* - * Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC") + * Copyright (C) 2004, 2007, 2008 Internet Systems Consortium, Inc. ("ISC") * Copyright (C) 1999-2003 Internet Software Consortium. * * Permission to use, copy, modify, and/or distribute this software for any @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: net.c,v 1.3.2.2.4.11 2008/04/28 05:35:45 marka Exp $ */ +/* $Id: net.c,v 1.3.2.2.4.12 2008/04/28 23:45:41 tbox Exp $ */ #include diff --git a/util/kit.sh b/util/kit.sh index f5ee7bfd2c..5449bdd83c 100644 --- a/util/kit.sh +++ b/util/kit.sh @@ -1,6 +1,6 @@ #!/bin/sh # -# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC") +# Copyright (C) 2004, 2008 Internet Systems Consortium, Inc. ("ISC") # Copyright (C) 2000-2003 Internet Software Consortium. # # Permission to use, copy, modify, and/or distribute this software for any @@ -15,7 +15,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: kit.sh,v 1.20.2.1.10.5 2008/04/28 03:42:12 marka Exp $ +# $Id: kit.sh,v 1.20.2.1.10.6 2008/04/28 23:45:41 tbox Exp $ # Make a release kit # From 62127c7094cc2f983aed1b46eedeb257352bfc07 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 28 Apr 2008 23:49:12 +0000 Subject: [PATCH 037/137] 2363. [port] sunos: pre-set "lt_cv_sys_max_cmd_len=4096;". [RT #17513] --- CHANGES | 3 ++ configure | 66 ++++++++++++++++++++++++------------------- configure.in | 10 ++++++- lib/bind/configure | 64 +++++++++++++++++++++++------------------ lib/bind/configure.in | 10 ++++++- 5 files changed, 94 insertions(+), 59 deletions(-) diff --git a/CHANGES b/CHANGES index c35015e448..d003cc2be9 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +2363. [port] sunos: pre-set "lt_cv_sys_max_cmd_len=4096;". + [RT #17513] + 2361. [bug] "recursion" statistics counter could be counted multiple times for a single query. [RT #17990] diff --git a/configure b/configure index 080413db91..293d20ef87 100755 --- a/configure +++ b/configure @@ -14,7 +14,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. # -# $Id: configure,v 1.284.2.19.2.75 2008/04/28 03:38:07 marka Exp $ +# $Id: configure,v 1.284.2.19.2.76 2008/04/28 23:49:08 marka Exp $ # # Portions Copyright (C) 1996-2001 Nominum, Inc. # @@ -29,7 +29,7 @@ # WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN # ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT # OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. -# From configure.in Revision: 1.294.2.23.2.83 . +# From configure.in Revision: 1.294.2.23.2.84 . # Guess values for system-dependent variables and create Makefiles. # Generated by GNU Autoconf 2.61. # @@ -8607,6 +8607,14 @@ esac # # GNU libtool support # +case $host in +sunos*) + # Just set the maximum command line length for sunos as it otherwise + # takes a exceptionally long time to work it out. Required for libtool. + lt_cv_sys_max_cmd_len=4096; + ;; +esac + # Check whether --with-libtool was given. if test "${with_libtool+set}" = set; then @@ -9154,7 +9162,7 @@ ia64-*-hpux*) ;; *-*-irix6*) # Find out which ABI we are using. - echo '#line 9157 "configure"' > conftest.$ac_ext + echo '#line 9165 "configure"' > conftest.$ac_ext if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 (eval $ac_compile) 2>&5 ac_status=$? @@ -11276,11 +11284,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:11279: $lt_compile\"" >&5) + (eval echo "\"\$as_me:11287: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:11283: \$? = $ac_status" >&5 + echo "$as_me:11291: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -11519,11 +11527,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:11522: $lt_compile\"" >&5) + (eval echo "\"\$as_me:11530: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:11526: \$? = $ac_status" >&5 + echo "$as_me:11534: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -11579,11 +11587,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:11582: $lt_compile\"" >&5) + (eval echo "\"\$as_me:11590: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:11586: \$? = $ac_status" >&5 + echo "$as_me:11594: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -13727,7 +13735,7 @@ else lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2 lt_status=$lt_dlunknown cat > conftest.$ac_ext < conftest.$ac_ext <&5) + (eval echo "\"\$as_me:16029: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:16025: \$? = $ac_status" >&5 + echo "$as_me:16033: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -16078,11 +16086,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:16081: $lt_compile\"" >&5) + (eval echo "\"\$as_me:16089: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:16085: \$? = $ac_status" >&5 + echo "$as_me:16093: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -17406,7 +17414,7 @@ else lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2 lt_status=$lt_dlunknown cat > conftest.$ac_ext < conftest.$ac_ext <&5) + (eval echo "\"\$as_me:18352: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:18348: \$? = $ac_status" >&5 + echo "$as_me:18356: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -18401,11 +18409,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:18404: $lt_compile\"" >&5) + (eval echo "\"\$as_me:18412: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:18408: \$? = $ac_status" >&5 + echo "$as_me:18416: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -20435,11 +20443,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:20438: $lt_compile\"" >&5) + (eval echo "\"\$as_me:20446: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:20442: \$? = $ac_status" >&5 + echo "$as_me:20450: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -20678,11 +20686,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:20681: $lt_compile\"" >&5) + (eval echo "\"\$as_me:20689: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:20685: \$? = $ac_status" >&5 + echo "$as_me:20693: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -20738,11 +20746,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:20741: $lt_compile\"" >&5) + (eval echo "\"\$as_me:20749: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:20745: \$? = $ac_status" >&5 + echo "$as_me:20753: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -22886,7 +22894,7 @@ else lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2 lt_status=$lt_dlunknown cat > conftest.$ac_ext < conftest.$ac_ext < conftest.$ac_ext + echo '#line 9128 "configure"' > conftest.$ac_ext if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5 (eval $ac_compile) 2>&5 ac_status=$? @@ -11239,11 +11247,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:11242: $lt_compile\"" >&5) + (eval echo "\"\$as_me:11250: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:11246: \$? = $ac_status" >&5 + echo "$as_me:11254: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -11482,11 +11490,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:11485: $lt_compile\"" >&5) + (eval echo "\"\$as_me:11493: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:11489: \$? = $ac_status" >&5 + echo "$as_me:11497: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -11542,11 +11550,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:11545: $lt_compile\"" >&5) + (eval echo "\"\$as_me:11553: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:11549: \$? = $ac_status" >&5 + echo "$as_me:11557: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -13690,7 +13698,7 @@ else lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2 lt_status=$lt_dlunknown cat > conftest.$ac_ext < conftest.$ac_ext <&5) + (eval echo "\"\$as_me:15992: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:15988: \$? = $ac_status" >&5 + echo "$as_me:15996: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -16041,11 +16049,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:16044: $lt_compile\"" >&5) + (eval echo "\"\$as_me:16052: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:16048: \$? = $ac_status" >&5 + echo "$as_me:16056: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -17369,7 +17377,7 @@ else lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2 lt_status=$lt_dlunknown cat > conftest.$ac_ext < conftest.$ac_ext <&5) + (eval echo "\"\$as_me:18315: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:18311: \$? = $ac_status" >&5 + echo "$as_me:18319: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -18364,11 +18372,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:18367: $lt_compile\"" >&5) + (eval echo "\"\$as_me:18375: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:18371: \$? = $ac_status" >&5 + echo "$as_me:18379: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -20398,11 +20406,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:20401: $lt_compile\"" >&5) + (eval echo "\"\$as_me:20409: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:20405: \$? = $ac_status" >&5 + echo "$as_me:20413: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -20641,11 +20649,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:20644: $lt_compile\"" >&5) + (eval echo "\"\$as_me:20652: $lt_compile\"" >&5) (eval "$lt_compile" 2>conftest.err) ac_status=$? cat conftest.err >&5 - echo "$as_me:20648: \$? = $ac_status" >&5 + echo "$as_me:20656: \$? = $ac_status" >&5 if (exit $ac_status) && test -s "$ac_outfile"; then # The compiler can only warn and ignore the option if not recognized # So say no if there are warnings @@ -20701,11 +20709,11 @@ else -e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \ -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \ -e 's:$: $lt_compiler_flag:'` - (eval echo "\"\$as_me:20704: $lt_compile\"" >&5) + (eval echo "\"\$as_me:20712: $lt_compile\"" >&5) (eval "$lt_compile" 2>out/conftest.err) ac_status=$? cat out/conftest.err >&5 - echo "$as_me:20708: \$? = $ac_status" >&5 + echo "$as_me:20716: \$? = $ac_status" >&5 if (exit $ac_status) && test -s out/conftest2.$ac_objext then # The compiler can only warn and ignore the option if not recognized @@ -22849,7 +22857,7 @@ else lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2 lt_status=$lt_dlunknown cat > conftest.$ac_ext < conftest.$ac_ext < Date: Tue, 29 Apr 2008 00:52:03 +0000 Subject: [PATCH 038/137] 2364. [bug] named could trigger a assertion when serving a malformed signed zone. [RT #17828] --- CHANGES | 3 +++ bin/named/query.c | 9 ++++++++- 2 files changed, 11 insertions(+), 1 deletion(-) diff --git a/CHANGES b/CHANGES index d003cc2be9..f9709c9e12 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +2364. [bug] named could trigger a assertion when serving a + malformed signed zone. [RT #17828] + 2363. [port] sunos: pre-set "lt_cv_sys_max_cmd_len=4096;". [RT #17513] diff --git a/bin/named/query.c b/bin/named/query.c index a4607e92a4..b965499105 100644 --- a/bin/named/query.c +++ b/bin/named/query.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: query.c,v 1.198.2.13.4.54 2008/04/23 01:19:50 jinmei Exp $ */ +/* $Id: query.c,v 1.198.2.13.4.55 2008/04/29 00:52:03 marka Exp $ */ #include @@ -1900,6 +1900,13 @@ query_addwildcardproof(ns_client_t *client, dns_db_t *db, &olabels); (void)dns_name_fullcompare(name, &nsec.next, &order, &nlabels); + /* + * Check for a pathological condition created when + * serving some malformed signed zones and bail out. + */ + if (dns_name_countlabels(name) == nlabels) + goto cleanup; + if (olabels > nlabels) dns_name_split(name, olabels, NULL, wname); else From 229442301442890aee044a0df54d3787acd68e65 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Tue, 29 Apr 2008 00:54:28 +0000 Subject: [PATCH 039/137] 2364. [bug] named could trigger a assertion when serving a malformed signed zone. [RT #17828] --- CHANGES | 3 +++ bin/named/query.c | 9 ++++++++- 2 files changed, 11 insertions(+), 1 deletion(-) diff --git a/CHANGES b/CHANGES index 91f9a6d9bc..fcd4e0fbca 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +2364. [bug] named could trigger a assertion when serving a + malformed signed zone. [RT #17828] + 2363. [port] sunos: pre-set "lt_cv_sys_max_cmd_len=4096;". [RT #17513] diff --git a/bin/named/query.c b/bin/named/query.c index 1caaf013e2..ccd4a036fb 100644 --- a/bin/named/query.c +++ b/bin/named/query.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: query.c,v 1.306 2008/04/23 01:14:24 jinmei Exp $ */ +/* $Id: query.c,v 1.307 2008/04/29 00:54:28 marka Exp $ */ /*! \file */ @@ -2774,6 +2774,13 @@ query_addwildcardproof(ns_client_t *client, dns_db_t *db, &olabels); (void)dns_name_fullcompare(name, &nsec.next, &order, &nlabels); + /* + * Check for a pathological condition created when + * serving some malformed signed zones and bail out. + */ + if (dns_name_countlabels(name) == nlabels) + goto cleanup; + if (olabels > nlabels) dns_name_split(name, olabels, NULL, wname); else From bca5861af85a30d5eb7c256f3dd71c12696fc895 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Tue, 29 Apr 2008 00:58:52 +0000 Subject: [PATCH 040/137] update --- util/copyrights | 15 --------------- 1 file changed, 15 deletions(-) diff --git a/util/copyrights b/util/copyrights index 2d8b06d05a..0c2ed0c82b 100644 --- a/util/copyrights +++ b/util/copyrights @@ -1066,21 +1066,6 @@ ./contrib/nslint-2.1a3/savestr.c X 2001 ./contrib/nslint-2.1a3/savestr.h X 2001 ./contrib/nslint-2.1a3/strerror.c X 2001 -./contrib/query-loc-0.3.0/ADDRESSES X 2005 -./contrib/query-loc-0.3.0/ALGO X 2005 -./contrib/query-loc-0.3.0/INSTALL X 2005 -./contrib/query-loc-0.3.0/Makefile.in X 2005 -./contrib/query-loc-0.3.0/README X 2005 -./contrib/query-loc-0.3.0/USAGE X 2005 -./contrib/query-loc-0.3.0/config.h.in X 2005 -./contrib/query-loc-0.3.0/configure X 2005 -./contrib/query-loc-0.3.0/configure.in X 2005 -./contrib/query-loc-0.3.0/install-sh X 2005 -./contrib/query-loc-0.3.0/loc.c X 2005 -./contrib/query-loc-0.3.0/loc.h X 2005 -./contrib/query-loc-0.3.0/loc_ntoa.c X 2005 -./contrib/query-loc-0.3.0/query-loc.1 X 2005 -./contrib/query-loc-0.3.0/query-loc.c X 2005 ./contrib/query-loc-0.4.0/ADDRESSES X 2008 ./contrib/query-loc-0.4.0/ALGO X 2008 ./contrib/query-loc-0.4.0/INSTALL X 2008 From 28ad0be64ee756013c0f6a474fc447ee613ee0d1 Mon Sep 17 00:00:00 2001 From: Evan Hunt Date: Tue, 29 Apr 2008 01:01:42 +0000 Subject: [PATCH 041/137] Fix a bug causing dns_acl_isany() to return spurious results [rt18000] --- CHANGES | 5 ++++- lib/dns/acl.c | 4 ++-- 2 files changed, 6 insertions(+), 3 deletions(-) diff --git a/CHANGES b/CHANGES index fcd4e0fbca..147aeb544f 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +2365. [bug] Fix an bug that caused dns_acl_isany() to return + spurious results. [RT #18000] + 2364. [bug] named could trigger a assertion when serving a malformed signed zone. [RT #17828] @@ -6,7 +9,7 @@ 2362. [cleanup] Make "rrset-order fixed" a compile-time option. settable by "./configure --enable-fixed-rrset". - Disabled by default. [rt17977] + Disabled by default. [RT #17977] 2361. [bug] "recursion" statistics counter could be counted multiple times for a single query. [RT #17990] diff --git a/lib/dns/acl.c b/lib/dns/acl.c index f6160b70ac..533df2ebca 100644 --- a/lib/dns/acl.c +++ b/lib/dns/acl.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: acl.c,v 1.44 2008/01/27 02:13:34 marka Exp $ */ +/* $Id: acl.c,v 1.45 2008/04/29 01:01:42 each Exp $ */ /*! \file */ @@ -148,7 +148,7 @@ dns_acl_isanyornone(dns_acl_t *acl, isc_boolean_t pos) return (ISC_FALSE); if (acl->iptable->radix->head->prefix->bitlen == 0 && - *(isc_boolean_t *) (acl->iptable->radix->head->data) == pos) + *(isc_boolean_t *) (acl->iptable->radix->head->data[0]) == pos) return (ISC_TRUE); return (ISC_FALSE); /* All others */ From d3345cc201b6d696eb9f6630d5991d3f1e8bfc79 Mon Sep 17 00:00:00 2001 From: Evan Hunt Date: Tue, 29 Apr 2008 01:06:37 +0000 Subject: [PATCH 042/137] *** empty log message *** --- CHANGES | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CHANGES b/CHANGES index 147aeb544f..d5e70ec3be 100644 --- a/CHANGES +++ b/CHANGES @@ -1,4 +1,4 @@ -2365. [bug] Fix an bug that caused dns_acl_isany() to return +2365. [bug] Fix a bug that caused dns_acl_isany() to return spurious results. [RT #18000] 2364. [bug] named could trigger a assertion when serving a From b1bf820fc47f84b982390205ea3c45c704cabfe6 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Tue, 29 Apr 2008 01:21:31 +0000 Subject: [PATCH 043/137] regen --- bin/dig/host.1 | 8 ++++---- bin/dig/host.html | 12 ++++++------ doc/arm/Bv9ARM.ch06.html | 4 ++-- doc/misc/options | 31 ++++++++++++++++--------------- 4 files changed, 28 insertions(+), 27 deletions(-) diff --git a/bin/dig/host.1 b/bin/dig/host.1 index 2d1687a687..1d09af9145 100644 --- a/bin/dig/host.1 +++ b/bin/dig/host.1 @@ -1,4 +1,4 @@ -.\" Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC") +.\" Copyright (C) 2004, 2005, 2007, 2008 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2000-2003 Internet Software Consortium. .\" .\" Permission to use, copy, modify, and distribute this software for any @@ -13,7 +13,7 @@ .\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR .\" PERFORMANCE OF THIS SOFTWARE. .\" -.\" $Id: host.1,v 1.11.2.1.4.12 2007/05/09 03:32:36 marka Exp $ +.\" $Id: host.1,v 1.11.2.1.4.13 2008/04/29 01:21:29 tbox Exp $ .\" .hy 0 .ad l @@ -154,7 +154,7 @@ option is used to select the query type. \fItype\fR can be any recognized query type: CNAME, NS, SOA, SIG, KEY, AXFR, etc. When no query type is specified, \fBhost\fR -automatically selects an appropriate query type. By default it looks for A records, but if the +automatically selects an appropriate query type. By default it looks for A, AAAA, and MX records, but if the \fB\-C\fR option was given, queries will be made for SOA records, and if \fIname\fR @@ -187,7 +187,7 @@ will effectively wait forever for a reply. The time to wait for a response will \fBdig\fR(1), \fBnamed\fR(8). .SH "COPYRIGHT" -Copyright \(co 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC") +Copyright \(co 2004, 2005, 2007, 2008 Internet Systems Consortium, Inc. ("ISC") .br Copyright \(co 2000\-2003 Internet Software Consortium. .br diff --git a/bin/dig/host.html b/bin/dig/host.html index 07c930550f..a1786bb1c5 100644 --- a/bin/dig/host.html +++ b/bin/dig/host.html @@ -1,5 +1,5 @@ - + @@ -32,7 +32,7 @@

host [-aCdlnrTwv] [-c class] [-N ndots] [-R number] [-t type] [-W wait] [-4] [-6] {name} [server]

-

DESCRIPTION

+

DESCRIPTION

host is a simple utility for performing DNS lookups. @@ -134,7 +134,7 @@ The -t option is used to select the query type. type can be any recognized query type: CNAME, NS, SOA, SIG, KEY, AXFR, etc. When no query type is specified, host automatically selects an appropriate query -type. By default it looks for A records, but if the +type. By default it looks for A, AAAA, and MX records, but if the -C option was given, queries will be made for SOA records, and if name is a dotted-decimal IPv4 address or colon-delimited IPv6 address, host will @@ -155,13 +155,13 @@ value for an integer quantity.

-

FILES

+

FILES

/etc/resolv.conf

-

SEE ALSO

+

SEE ALSO

dig(1), named(8). diff --git a/doc/arm/Bv9ARM.ch06.html b/doc/arm/Bv9ARM.ch06.html index dd8d8ca33f..5781bf4919 100644 --- a/doc/arm/Bv9ARM.ch06.html +++ b/doc/arm/Bv9ARM.ch06.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -3898,7 +3898,7 @@ delegation.

$GENERATE 1-2 0 NS SERVER$.EXAMPLE. $GENERATE 1-127 $ CNAME $.0

is equivalent to

-
0.0.0.192.IN-ADDR.ARPA NS SERVER1.EXAMPLE.
+
0.0.0.192.IN-ADDR.ARPA. NS SERVER1.EXAMPLE.
 0.0.0.192.IN-ADDR.ARPA. NS SERVER2.EXAMPLE.
 1.0.0.192.IN-ADDR.ARPA. CNAME 1.0.0.0.192.IN-ADDR.ARPA.
 2.0.0.192.IN-ADDR.ARPA. CNAME 2.0.0.0.192.IN-ADDR.ARPA.
diff --git a/doc/misc/options b/doc/misc/options
index a1bcf779a3..a34a48313d 100644
--- a/doc/misc/options
+++ b/doc/misc/options
@@ -19,7 +19,8 @@ key  {
 logging {
         category  { ; ... };
         channel  {
-                file ;
+                file  [ versions ( "unlimited" |  )
+                    ] [ size  ];
                 null;
                 print-category ;
                 print-severity ;
@@ -38,8 +39,8 @@ lwres {
         view  ;
 };
 
-masters  [ port  ] { (  |  [port
-    ] |  [port ] ) [ key  ]; ... };
+masters  [ port  ] { (  |  [ port
+     ] |  [ port  ] ) [ key  ]; ... };
 
 options {
         additional-from-auth ;
@@ -71,9 +72,9 @@ options {
         dnssec-enable ;
         dnssec-lookaside  trust-anchor ;
         dnssec-must-be-secure  ;
-        dual-stack-servers [ port  ] { (  [port
-            ] |  [port ] | 
-            [port ] ); ... };
+        dual-stack-servers [ port  ] { (  [ port
+             ] |  [ port  ] |
+             [ port  ] ); ... };
         dump-file ;
         edns-udp-size ;
         fake-iquery ; // obsolete
@@ -201,9 +202,9 @@ view   {
         dnssec-enable ;
         dnssec-lookaside  trust-anchor ;
         dnssec-must-be-secure  ;
-        dual-stack-servers [ port  ] { (  [port
-            ] |  [port ] | 
-            [port ] ); ... };
+        dual-stack-servers [ port  ] { (  [ port
+             ] |  [ port  ] |
+             [ port  ] ); ... };
         edns-udp-size ;
         fetch-glue ; // obsolete
         forward ( first | only );
@@ -298,9 +299,9 @@ view   {
                 ixfr-tmp-file ; // obsolete
                 key-directory ;
                 maintain-ixfr-base ; // obsolete
-                masters [ port  ] { (  | 
-                    [port ] |  [port ] ) [
-                    key  ]; ... };
+                masters [ port  ] { (  |  [
+                    port  ] |  [ port  ] )
+                    [ key  ]; ... };
                 max-ixfr-log-size ; // obsolete
                 max-journal-size ;
                 max-refresh-time ;
@@ -359,9 +360,9 @@ zone   {
         ixfr-tmp-file ; // obsolete
         key-directory ;
         maintain-ixfr-base ; // obsolete
-        masters [ port  ] { (  |  [port
-            ] |  [port ] ) [ key 
-            ]; ... };
+        masters [ port  ] { (  |  [ port
+             ] |  [ port  ] ) [ key
+             ]; ... };
         max-ixfr-log-size ; // obsolete
         max-journal-size ;
         max-refresh-time ;

From 6cf976e1d8a4fd52bdec9edc6ab6c76a0d099b77 Mon Sep 17 00:00:00 2001
From: Automatic Updater 
Date: Tue, 29 Apr 2008 23:30:04 +0000
Subject: [PATCH 044/137] newcopyrights

---
 util/copyrights | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/util/copyrights b/util/copyrights
index 0c2ed0c82b..baf5fbfcdf 100644
--- a/util/copyrights
+++ b/util/copyrights
@@ -1172,7 +1172,7 @@
 ./doc/misc/ipv6					TXT.BRIEF	2000,2001,2004
 ./doc/misc/migration				TXT.BRIEF	2000,2001,2003,2004,2007
 ./doc/misc/migration-4to9			TXT.BRIEF	2001,2004
-./doc/misc/options				X	2000,2001,2002,2003,2004,2005,2007
+./doc/misc/options				X	2000,2001,2002,2003,2004,2005,2007,2008
 ./doc/misc/rfc-compliance			TXT.BRIEF	2001,2004
 ./doc/misc/roadmap				TXT.BRIEF	2000,2001,2004
 ./doc/misc/sdb					TXT.BRIEF	2000,2001,2004

From 62fd1414b6ceacb9ec1a350dc90fc4dcf1f1c3c2 Mon Sep 17 00:00:00 2001
From: Automatic Updater 
Date: Wed, 30 Apr 2008 23:18:14 +0000
Subject: [PATCH 045/137] auto update

---
 doc/private/branches | 1 +
 1 file changed, 1 insertion(+)

diff --git a/doc/private/branches b/doc/private/branches
index a80d245696..6a56a525b2 100644
--- a/doc/private/branches
+++ b/doc/private/branches
@@ -116,6 +116,7 @@ rt17729a			new	marka	// 2008-04-02 23:40 +0000
 rt17828				new	marka	// 2008-04-09 23:06 +0000
 rt17949				new	
 rt17977				new	each	// 2008-04-23 00:29 +0000
+rt18018				new	
 shane_dbbackend			open	
 skan				open	explorer
 skan-metazones1			private	explorer

From 5c024f787777143031c2c49f9811c39c84bfa259 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Tatuya=20JINMEI=20=E7=A5=9E=E6=98=8E=E9=81=94=E5=93=89?=
 
Date: Thu, 1 May 2008 18:23:07 +0000
Subject: [PATCH 046/137] cleanups for LRU-caching code [RT #18018]

---
 bin/named/config.c      |   4 +-
 doc/arm/Bv9ARM-book.xml |  13 +-
 lib/dns/adb.c           | 290 +--------------------
 lib/dns/cache.c         | 541 +++++++++++++++++++++++++++-------------
 lib/dns/rbtdb.c         | 267 +-------------------
 lib/dns/resolver.c      | 112 +--------
 6 files changed, 381 insertions(+), 846 deletions(-)

diff --git a/bin/named/config.c b/bin/named/config.c
index 8f48760482..edf0cb26d7 100644
--- a/bin/named/config.c
+++ b/bin/named/config.c
@@ -15,7 +15,7 @@
  * PERFORMANCE OF THIS SOFTWARE.
  */
 
-/* $Id: config.c,v 1.86 2008/04/03 02:01:08 marka Exp $ */
+/* $Id: config.c,v 1.87 2008/05/01 18:23:06 jinmei Exp $ */
 
 /*! \file */
 
@@ -124,7 +124,7 @@ options {\n\
 	query-source-v6 address *;\n\
 	notify-source *;\n\
 	notify-source-v6 *;\n\
-	cleaning-interval 60;\n\
+	cleaning-interval 0;  /* now meaningless */\n\
 	min-roots 2;\n\
 	lame-ttl 600;\n\
 	max-ncache-ttl 10800; /* 3 hours */\n\
diff --git a/doc/arm/Bv9ARM-book.xml b/doc/arm/Bv9ARM-book.xml
index 21d95a8eb8..81be98930a 100644
--- a/doc/arm/Bv9ARM-book.xml
+++ b/doc/arm/Bv9ARM-book.xml
@@ -18,7 +18,7 @@
  - PERFORMANCE OF THIS SOFTWARE.
 -->
 
-
+
 
   BIND 9 Administrator Reference Manual
 
@@ -6870,11 +6870,14 @@ query-source-v6 address * port *;
               cleaning-interval
               
                 
-                  The server will remove expired resource records
+		  This interval is effectively obsolete.  Previously,
+		  the server would remove expired resource records
                   from the cache every cleaning-interval minutes.
-                  The default is 60 minutes.  The maximum value is 28 days
-                  (40320 minutes).
-                  If set to 0, no periodic cleaning will occur.
+		  BIND 9 now manages cache
+		  memory in a more sophisticated manner and does not
+		  rely on the periodic cleaning any more.
+		  Specifying this option therefore has no effect on
+		  the server's behavior.
                 
               
             
diff --git a/lib/dns/adb.c b/lib/dns/adb.c
index 148199312d..320b7264a8 100644
--- a/lib/dns/adb.c
+++ b/lib/dns/adb.c
@@ -15,7 +15,7 @@
  * PERFORMANCE OF THIS SOFTWARE.
  */
 
-/* $Id: adb.c,v 1.238 2008/04/03 06:09:04 tbox Exp $ */
+/* $Id: adb.c,v 1.239 2008/05/01 18:23:07 jinmei Exp $ */
 
 /*! \file
  *
@@ -26,13 +26,6 @@
  *
  */
 
-/*%
- * After we have cleaned all buckets, dump the database contents.
- */
-#if 0
-#define DUMP_ADB_AFTER_CLEANING
-#endif
-
 #include 
 
 #include 
@@ -42,7 +35,6 @@
 #include 
 #include          /* Required for HP/UX (and others?) */
 #include 
-#include 
 #include 
 
 #include 
@@ -89,16 +81,6 @@
 #define ADB_CACHE_MAXIMUM       86400   /*%< seconds (86400 = 24 hours) */
 #define ADB_ENTRY_WINDOW        1800    /*%< seconds */
 
-/*%
- * Wake up every CLEAN_SECONDS and clean CLEAN_BUCKETS buckets, so that all
- * buckets are cleaned in CLEAN_PERIOD seconds.
- */
-#define CLEAN_PERIOD            3600
-/*% See #CLEAN_PERIOD */
-#define CLEAN_SECONDS           30
-/*% See #CLEAN_PERIOD */
-#define CLEAN_BUCKETS           ((NBUCKETS * CLEAN_SECONDS) / CLEAN_PERIOD)
-
 /*%
  * The period in seconds after which an ADB name entry is regarded as stale
  * and forced to be cleaned up.
@@ -132,14 +114,6 @@ struct dns_adb {
 	isc_mutex_t                     overmemlock; /*%< Covers overmem */
 	isc_mem_t                      *mctx;
 	dns_view_t                     *view;
-	isc_timermgr_t                 *timermgr;
-	isc_timer_t                    *timer;
-
-#ifdef LRU_DEBUG
-	isc_timer_t                    *dump_timer; /* for test */
-	isc_time_t                      dump_time; /* for test */
-#define DUMP_INTERVAL 30        /* seconds */
-#endif
 
 	isc_taskmgr_t                  *taskmgr;
 	isc_task_t                     *task;
@@ -187,17 +161,6 @@ struct dns_adb {
 	isc_boolean_t                   cevent_sent;
 	isc_boolean_t                   shutting_down;
 	isc_eventlist_t                 whenshutdown;
-
-#ifdef LRU_DEBUG
-	unsigned int                    stale_purge;
-	unsigned int                    stale_scan;
-	unsigned int                    stale_expire;
-	unsigned int                    stale_lru;
-
-	unsigned int                    nname, nname_total;
-	unsigned int                    nentry, nentry_total;
-	unsigned int                    nameuses, entryuses;
-#endif
 };
 
 /*
@@ -344,7 +307,6 @@ static isc_result_t dbfind_name(dns_adbname_t *, isc_stdtime_t,
 static isc_result_t fetch_name(dns_adbname_t *, isc_boolean_t,
 			       dns_rdatatype_t);
 static inline void check_exit(dns_adb_t *);
-static void timer_cleanup(isc_task_t *, isc_event_t *);
 static void destroy(dns_adb_t *);
 static isc_boolean_t shutdown_names(dns_adb_t *);
 static isc_boolean_t shutdown_entries(dns_adb_t *);
@@ -357,10 +319,6 @@ static isc_boolean_t kill_name(dns_adbname_t **, isc_eventtype_t,
 static void water(void *, int);
 static void dump_entry(FILE *, dns_adbentry_t *, isc_boolean_t, isc_stdtime_t);
 
-#ifdef LRU_DEBUG
-static void timer_dump(isc_task_t *, isc_event_t *);
-#endif
-
 /*
  * MUST NOT overlap DNS_ADBFIND_* flags!
  */
@@ -1332,11 +1290,6 @@ free_adbname(dns_adb_t *adb, dns_adbname_t **name) {
 	INSIST(n->lock_bucket == DNS_ADB_INVALIDBUCKET);
 	INSIST(n->adb == adb);
 
-#ifdef LRU_DEBUG
-	adb->nname--;           /* XXX: omit ADB lock for brevity */
-	INSIST((int)adb->nname >= 0);
-#endif
-
 	n->magic = 0;
 	dns_name_free(&n->name, adb->mctx);
 
@@ -1430,11 +1383,6 @@ new_adbentry(dns_adb_t *adb) {
 	ISC_LIST_INIT(e->lameinfo);
 	ISC_LINK_INIT(e, plink);
 
-#ifdef LRU_DEBUG
-	adb->nentry++;  /* XXX: omit ADB lock for brevity */
-	adb->nentry_total++;
-#endif
-
 	return (e);
 }
 
@@ -1460,11 +1408,6 @@ free_adbentry(dns_adb_t *adb, dns_adbentry_t **entry) {
 		li = ISC_LIST_HEAD(e->lameinfo);
 	}
 
-#ifdef LRU_DEBUG
-	adb->nentry--;  /* XXX: omit ADB lock for brevity */
-	INSIST((int)adb->nentry >= 0);
-#endif
-
 	isc_mempool_put(adb->emp, e);
 }
 
@@ -1609,10 +1552,6 @@ new_adbaddrinfo(dns_adb_t *adb, dns_adbentry_t *entry, in_port_t port) {
 	ai->entry = entry;
 	ISC_LINK_INIT(ai, publink);
 
-#ifdef LRU_DEBUG
-	adb->entryuses++;       /* for debug */
-#endif
-
 	return (ai);
 }
 
@@ -1832,18 +1771,6 @@ shutdown_task(isc_task_t *task, isc_event_t *ev) {
 	adb = ev->ev_arg;
 	INSIST(DNS_ADB_VALID(adb));
 
-	/*
-	 * Kill the timer, and then the ADB itself.  Note that this implies
-	 * that this task was the one scheduled to get timer events.  If
-	 * this is not true (and it is unfortunate there is no way to INSIST()
-	 * this) badness will occur.
-	 */
-	LOCK(&adb->lock);
-	isc_timer_detach(&adb->timer);
-#ifdef LRU_DEBUG
-	isc_timer_detach(&adb->dump_timer);
-#endif
-	UNLOCK(&adb->lock);
 	isc_event_free(&ev);
 	destroy(adb);
 }
@@ -1928,9 +1855,6 @@ check_stale_name(dns_adb_t *adb, int bucket, isc_stdtime_t now) {
 
 		result = check_expire_name(&victim, now);
 		if (victim == NULL) {
-#ifdef LRU_DEBUG
-			adb->stale_expire++;
-#endif
 			victims++;
 			goto next;
 		}
@@ -1941,9 +1865,6 @@ check_stale_name(dns_adb_t *adb, int bucket, isc_stdtime_t now) {
 						DNS_EVENT_ADBCANCELED,
 						ISC_TRUE) ==
 				      ISC_FALSE);
-#ifdef LRU_DEBUG
-			adb->stale_lru++;
-#endif
 			victims++;
 		}
 
@@ -1951,12 +1872,6 @@ check_stale_name(dns_adb_t *adb, int bucket, isc_stdtime_t now) {
 		if (!overmem)
 			break;
 	}
-
-#ifdef LRU_DEBUG
-	/* XXX: omit lock for brevity */
-	adb->stale_scan += scans;
-	adb->stale_purge += victims;
-#endif
 }
 
 /*
@@ -2042,96 +1957,10 @@ cleanup_entries(dns_adb_t *adb, int bucket, isc_stdtime_t now) {
 	return (result);
 }
 
-#if 1
-static void
-timer_cleanup(isc_task_t *task, isc_event_t *ev) {
-	UNUSED(task);
-
-	isc_event_free(&ev);
-}
-#else
-static void
-timer_cleanup(isc_task_t *task, isc_event_t *ev) {
-	dns_adb_t *adb;
-	isc_stdtime_t now;
-	unsigned int i;
-	isc_interval_t interval;
-
-	UNUSED(task);
-
-	adb = ev->ev_arg;
-	INSIST(DNS_ADB_VALID(adb));
-
-	LOCK(&adb->lock);
-
-	isc_stdtime_get(&now);
-
-	for (i = 0; i < CLEAN_BUCKETS; i++) {
-		/*
-		 * Call our cleanup routines.
-		 */
-		RUNTIME_CHECK(cleanup_names(adb, adb->next_cleanbucket, now) ==
-			      ISC_FALSE);
-		RUNTIME_CHECK(cleanup_entries(adb, adb->next_cleanbucket, now)
-			      == ISC_FALSE);
-
-		/*
-		 * Set the next bucket to be cleaned.
-		 */
-		adb->next_cleanbucket++;
-		if (adb->next_cleanbucket >= NBUCKETS) {
-			adb->next_cleanbucket = 0;
-#ifdef DUMP_ADB_AFTER_CLEANING
-			dump_adb(adb, stdout, ISC_TRUE, now);
-#endif
-		}
-	}
-
-	/*
-	 * Reset the timer.
-	 * XXXDCL isc_timer_reset might return ISC_R_UNEXPECTED or
-	 * ISC_R_NOMEMORY, but it isn't clear what could be done here
-	 * if either one of those things happened.
-	 */
-	interval = adb->tick_interval;
-	if (adb->overmem)
-		isc_interval_set(&interval, 0, 1);
-	(void)isc_timer_reset(adb->timer, isc_timertype_once, NULL,
-			      &interval, ISC_FALSE);
-
-	UNLOCK(&adb->lock);
-
-	isc_event_free(&ev);
-}
-#endif
-
 static void
 destroy(dns_adb_t *adb) {
 	adb->magic = 0;
 
-#ifdef LRU_DEBUG
-	/* for debug: print statistics */
-	if (adb->nname_total > 0) {
-		INSIST(adb->nname == 0 && adb->nentry == 0);
-		isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
-			      DNS_LOGMODULE_ADB, ISC_LOG_INFO,
-			      "ADB %p name hit %.2f, entry hit %.2f", adb,
-			      (double)adb->nameuses /
-			      (adb->nname_total + adb->nameuses),
-			      adb->entryuses > 0 ?
-			      (double)adb->entryuses /
-			      (adb->nentry_total + adb->entryuses) : 0);
-		isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
-			      DNS_LOGMODULE_ADB, ISC_LOG_INFO,
-			      "ADB %p stale name purges: %u(%u,%u)/%u",
-			      adb, adb->stale_purge, adb->stale_expire,
-			      adb->stale_lru, adb->stale_scan);
-	}
-#endif
-
-	/*
-	 * The timer is already dead, from the task's shutdown callback.
-	 */
 	isc_task_detach(&adb->task);
 
 	isc_mempool_destroy(&adb->nmp);
@@ -2168,10 +1997,12 @@ dns_adb_create(isc_mem_t *mem, dns_view_t *view, isc_timermgr_t *timermgr,
 
 	REQUIRE(mem != NULL);
 	REQUIRE(view != NULL);
-	REQUIRE(timermgr != NULL);
+	REQUIRE(timermgr != NULL); /* this is actually unused */
 	REQUIRE(taskmgr != NULL);
 	REQUIRE(newadb != NULL && *newadb == NULL);
 
+	UNUSED(timermgr);
+
 	adb = isc_mem_get(mem, sizeof(dns_adb_t));
 	if (adb == NULL)
 		return (ISC_R_NOMEMORY);
@@ -2191,13 +2022,8 @@ dns_adb_create(isc_mem_t *mem, dns_view_t *view, isc_timermgr_t *timermgr,
 	adb->aimp = NULL;
 	adb->afmp = NULL;
 	adb->task = NULL;
-	adb->timer = NULL;
-#ifdef LRU_DEBUG
-	adb->dump_timer = NULL;
-#endif
 	adb->mctx = NULL;
 	adb->view = view;
-	adb->timermgr = timermgr;
 	adb->taskmgr = taskmgr;
 	adb->next_cleanbucket = 0;
 	ISC_EVENT_INIT(&adb->cevent, sizeof(adb->cevent), 0, NULL,
@@ -2208,20 +2034,6 @@ dns_adb_create(isc_mem_t *mem, dns_view_t *view, isc_timermgr_t *timermgr,
 	adb->overmem = ISC_FALSE;
 	ISC_LIST_INIT(adb->whenshutdown);
 
-#ifdef LRU_DEBUG
-	/* for debug */
-	adb->nname = 0;
-	adb->nname_total = 0;
-	adb->nentry = 0;
-	adb->nentry_total = 0;
-	adb->stale_purge = 0;
-	adb->stale_scan = 0;
-	adb->stale_expire = 0;
-	adb->stale_lru = 0;
-	adb->nameuses = 0;
-	adb->entryuses = 0;
-#endif
-
 	isc_mem_attach(mem, &adb->mctx);
 
 	result = isc_mutex_init(&adb->lock);
@@ -2287,41 +2099,12 @@ dns_adb_create(isc_mem_t *mem, dns_view_t *view, isc_timermgr_t *timermgr,
 #undef MPINIT
 
 	/*
-	 * Allocate a timer and a task for our periodic cleanup.
+	 * Allocate an internal task.
 	 */
 	result = isc_task_create(adb->taskmgr, 0, &adb->task);
 	if (result != ISC_R_SUCCESS)
 		goto fail3;
 	isc_task_setname(adb->task, "ADB", adb);
-	/*
-	 * XXXMLG When this is changed to be a config file option,
-	 */
-	isc_interval_set(&adb->tick_interval, CLEAN_SECONDS, 0);
-	result = isc_timer_create(adb->timermgr, isc_timertype_once,
-				  NULL, &adb->tick_interval, adb->task,
-				  timer_cleanup, adb, &adb->timer);
-	if (result != ISC_R_SUCCESS)
-		goto fail3;
-
-#ifdef LRU_DEBUG
-	{
-		isc_interval_t interval;
-
-		interval.seconds = DUMP_INTERVAL;
-		interval.nanoseconds = 0;
-		RUNTIME_CHECK(isc_time_nowplusinterval(&adb->dump_time,
-						       &interval) ==
-			      ISC_R_SUCCESS);
-
-		result = isc_timer_create(adb->timermgr, isc_timertype_once,
-					  &adb->dump_time, NULL, adb->task,
-					  timer_dump, adb, &adb->dump_timer);
-	}
-#endif
-
-	DP(ISC_LOG_DEBUG(5), "cleaning interval for adb: "
-	   "%u buckets every %u seconds, %u buckets in system, %u cl.interval",
-	   CLEAN_BUCKETS, CLEAN_SECONDS, NBUCKETS, CLEAN_PERIOD);
 
 	/*
 	 * Normal return.
@@ -2333,8 +2116,6 @@ dns_adb_create(isc_mem_t *mem, dns_view_t *view, isc_timermgr_t *timermgr,
  fail3:
 	if (adb->task != NULL)
 		isc_task_detach(&adb->task);
-	if (adb->timer != NULL)
-		isc_timer_detach(&adb->timer);
 
 	/* clean up entrylocks */
 	DESTROYMUTEXBLOCK(adb->entrylocks, NBUCKETS);
@@ -2578,18 +2359,10 @@ dns_adb_createfind(dns_adb_t *adb, isc_task_t *task, isc_taskaction_t action,
 			adbname->flags |= NAME_GLUE_OK;
 		if (FIND_STARTATZONE(find))
 			adbname->flags |= NAME_STARTATZONE;
-
-#ifdef LRU_DEBUG
-		adb->nname++;   /* XXX: omit ADB lock for brevity */
-		adb->nname_total++;
-#endif
 	} else {
 		/* Move this name forward in the LRU list */
 		ISC_LIST_UNLINK(adb->names[bucket], adbname, plink);
 		ISC_LIST_PREPEND(adb->names[bucket], adbname, plink);
-#ifdef LRU_DEBUG
-		adb->nameuses++;
-#endif
 	}
 	adbname->last_used = now;
 
@@ -3813,15 +3586,6 @@ water(void *arg, int mark) {
 	LOCK(&adb->overmemlock);
 	if (adb->overmem != overmem) {
 		adb->overmem = overmem;
-#if 0       /* we don't need this timer for the new cleaning policy. */
-		if (overmem) {
-			isc_interval_t interval;
-
-			isc_interval_set(&interval, 0, 1);
-			(void)isc_timer_reset(adb->timer, isc_timertype_once,
-					      NULL, &interval, ISC_TRUE);
-		}
-#endif
 		isc_mem_waterack(adb->mctx, mark);
 	}
 	UNLOCK(&adb->overmemlock);
@@ -3845,47 +3609,3 @@ dns_adb_setadbsize(dns_adb_t *adb, isc_uint32_t size) {
 	else
 		isc_mem_setwater(adb->mctx, water, adb, hiwater, lowater);
 }
-
-#ifdef LRU_DEBUG
-/*
- * Periodic dumping of the internal state of the statistics.
- * This will dump the cache contents, uses, record types, etc.
- */
-static void
-timer_dump(isc_task_t *task, isc_event_t *ev) {
-	dns_adb_t *adb;
-	isc_interval_t interval;
-	isc_time_t nexttime;
-
-	UNUSED(task);
-
-	adb = ev->ev_arg;
-	INSIST(DNS_ADB_VALID(adb));
-
-	LOCK(&adb->lock);
-	if (adb->nname > 0 || adb->nentry > 0) {
-		isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
-			      DNS_LOGMODULE_ADB, ISC_LOG_INFO,
-			      "ADB memory usage %p: mem inuse %lu, "
-			      "%u/%u names, %u/%u entries, "
-			      "purge/scan=%u(%u,%u)/%u, overmem=%d",
-			      adb, (unsigned long)isc_mem_inuse(adb->mctx),
-			      adb->nname, adb->nname_total,
-			      adb->nentry, adb->nentry_total,
-			      adb->stale_purge, adb->stale_expire,
-			      adb->stale_lru, adb->stale_scan, adb->overmem);
-	}
-
-	interval.seconds = DUMP_INTERVAL;
-	interval.nanoseconds = 0;
-
-	RUNTIME_CHECK(isc_time_add(&adb->dump_time, &interval, &nexttime) ==
-		      ISC_R_SUCCESS); /* XXX: this is not always true */
-	adb->dump_time = nexttime;
-	(void)isc_timer_reset(adb->dump_timer, isc_timertype_once,
-			      &adb->dump_time, NULL, ISC_FALSE);
-	UNLOCK(&adb->lock);
-
-	isc_event_free(&ev);
-}
-#endif
diff --git a/lib/dns/cache.c b/lib/dns/cache.c
index ae3d1d0b8e..cc7cad4a16 100644
--- a/lib/dns/cache.c
+++ b/lib/dns/cache.c
@@ -15,13 +15,14 @@
  * PERFORMANCE OF THIS SOFTWARE.
  */
 
-/* $Id: cache.c,v 1.78 2008/02/07 23:46:54 tbox Exp $ */
+/* $Id: cache.c,v 1.79 2008/05/01 18:23:07 jinmei Exp $ */
 
 /*! \file */
 
 #include 
 
 #include 
+#include 
 #include 
 #include 
 #include 
@@ -39,24 +40,24 @@
 #include 
 #include 
 
-#define CACHE_MAGIC             ISC_MAGIC('$', '$', '$', '$')
-#define VALID_CACHE(cache)      ISC_MAGIC_VALID(cache, CACHE_MAGIC)
+#define CACHE_MAGIC		ISC_MAGIC('$', '$', '$', '$')
+#define VALID_CACHE(cache)	ISC_MAGIC_VALID(cache, CACHE_MAGIC)
 
 /*!
  * Control incremental cleaning.
  * DNS_CACHE_MINSIZE is how many bytes is the floor for dns_cache_setcachesize().
  * See also DNS_CACHE_CLEANERINCREMENT
  */
-#define DNS_CACHE_MINSIZE               2097152 /*%< Bytes.  2097152 = 2 MB */
+#define DNS_CACHE_MINSIZE	2097152 /*%< Bytes.  2097152 = 2 MB */
 /*!
  * Control incremental cleaning.
  * CLEANERINCREMENT is how many nodes are examined in one pass.
  * See also DNS_CACHE_MINSIZE
  */
-#define DNS_CACHE_CLEANERINCREMENT      1000U   /*%< Number of nodes. */
+#define DNS_CACHE_CLEANERINCREMENT	1000U	/*%< Number of nodes. */
 
 /***
- ***    Types
+ ***	Types
  ***/
 
 /*
@@ -67,40 +68,48 @@
 typedef struct cache_cleaner cache_cleaner_t;
 
 typedef enum {
-	cleaner_s_idle, /*%< Waiting for cleaning-interval to expire. */
-	cleaner_s_busy, /*%< Currently cleaning. */
-	cleaner_s_done  /*%< Freed enough memory after being overmem. */
+	cleaner_s_idle,	/*%< Waiting for cleaning-interval to expire. */
+	cleaner_s_busy,	/*%< Currently cleaning. */
+	cleaner_s_done	/*%< Freed enough memory after being overmem. */
 } cleaner_state_t;
 
 /*
  * Convenience macros for comprehensive assertion checking.
  */
-#define CLEANER_IDLE(c) ((c)->state == cleaner_s_idle)
-#define CLEANER_BUSY(c) ((c)->state == cleaner_s_busy)
+#define CLEANER_IDLE(c) ((c)->state == cleaner_s_idle && \
+			 (c)->resched_event != NULL)
+#define CLEANER_BUSY(c) ((c)->state == cleaner_s_busy && \
+			 (c)->iterator != NULL && \
+			 (c)->resched_event == NULL)
 
 /*%
  * Accesses to a cache cleaner object are synchronized through
  * task/event serialization, or locked from the cache object.
  */
 struct cache_cleaner {
-	isc_mutex_t     lock;
+	isc_mutex_t	lock;
 	/*%<
-	 * Locks overmem.  Note: never allocate memory
+	 * Locks overmem_event, overmem.  Note: never allocate memory
 	 * while holding this lock - that could lead to deadlock since
 	 * the lock is take by water() which is called from the memory
 	 * allocator.
 	 */
 
-	dns_cache_t     *cache;
-	isc_task_t      *task;
-	unsigned int    cleaning_interval; /*% The cleaning-interval from
+	dns_cache_t	*cache;
+	isc_task_t	*task;
+	unsigned int	cleaning_interval; /*% The cleaning-interval from
 					      named.conf, in seconds. */
-	isc_timer_t     *cleaning_timer;
+	isc_timer_t	*cleaning_timer;
+	isc_event_t	*resched_event;	/*% Sent by cleaner task to
+					   itself to reschedule */
+	isc_event_t	*overmem_event;
 
-	unsigned int     increment;     /*% Number of names to
+	dns_dbiterator_t *iterator;
+	unsigned int	increment;	/*% Number of names to
 					   clean in one increment */
-	cleaner_state_t  state;         /*% Idle/Busy. */
-	isc_boolean_t    overmem;       /*% The cache is in an overmem state. */
+	cleaner_state_t	state;		/*% Idle/Busy. */
+	isc_boolean_t	overmem;	/*% The cache is in an overmem state. */
+	isc_boolean_t	 replaceiterator;
 };
 
 /*%
@@ -109,34 +118,28 @@ struct cache_cleaner {
 
 struct dns_cache {
 	/* Unlocked. */
-	unsigned int            magic;
-	isc_mutex_t             lock;
-	isc_mutex_t             filelock;
-	isc_mem_t               *mctx;
+	unsigned int		magic;
+	isc_mutex_t		lock;
+	isc_mutex_t		filelock;
+	isc_mem_t		*mctx;
 
 	/* Locked by 'lock'. */
-	int                     references;
-	int                     live_tasks;
-	dns_rdataclass_t        rdclass;
-	dns_db_t                *db;
-	cache_cleaner_t         cleaner;
-	char                    *db_type;
-	int                     db_argc;
-	char                    **db_argv;
+	int			references;
+	int			live_tasks;
+	dns_rdataclass_t	rdclass;
+	dns_db_t		*db;
+	cache_cleaner_t		cleaner;
+	char			*db_type;
+	int			db_argc;
+	char			**db_argv;
 
 	/* Locked by 'filelock'. */
-	char *                  filename;
+	char			*filename;
 	/* Access to the on-disk cache file is also locked by 'filelock'. */
-
-#ifdef LRU_DEBUG
-#define DUMP_INTERVAL 30        /* seconds */
-	isc_timer_t                    *dump_timer; /* for test */
-	isc_time_t                      dump_time; /* for test */
-#endif
 };
 
 /***
- ***    Functions
+ ***	Functions
  ***/
 
 static isc_result_t
@@ -146,89 +149,14 @@ cache_cleaner_init(dns_cache_t *cache, isc_taskmgr_t *taskmgr,
 static void
 cleaning_timer_action(isc_task_t *task, isc_event_t *event);
 
+static void
+incremental_cleaning_action(isc_task_t *task, isc_event_t *event);
+
 static void
 cleaner_shutdown_action(isc_task_t *task, isc_event_t *event);
 
-#ifdef LRU_DEBUG
 static void
-timer_dump(isc_task_t *task, isc_event_t *event);
-#endif
-
-#if 0 /* This is no longer needed.  When LRU_TEST is cleaned up,
-       * this should be as well.  XXXMLG */
-/*%
- * Work out how many nodes can be cleaned in the time between two
- * requests to the nameserver.  Smooth the resulting number and use
- * it as a estimate for the number of nodes to be cleaned in the next
- * iteration.
- */
-static void
-adjust_increment(cache_cleaner_t *cleaner, unsigned int remaining,
-		 isc_time_t *start)
-{
-	isc_time_t end;
-	isc_uint64_t usecs;
-	isc_uint64_t new;
-	unsigned int pps = dns_pps;
-	unsigned int interval;
-	unsigned int names;
-
-	/*
-	 * Tune for minumum of 100 packets per second (pps).
-	 */
-	if (pps < 100)
-		pps = 100;
-
-	isc_time_now(&end);
-
-	interval = 1000000 / pps; /* Interval between packets in usecs. */
-	if (interval == 0)
-		interval = 1;
-
-	INSIST(cleaner->increment >= remaining);
-	names = cleaner->increment - remaining;
-	usecs = isc_time_microdiff(&end, start);
-
-	isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE, DNS_LOGMODULE_CACHE,
-		      ISC_LOG_DEBUG(1), "adjust_increment interval=%u "
-		      "names=%u usec=%" ISC_PLATFORM_QUADFORMAT "u",
-		      interval, names, usecs);
-
-	if (usecs == 0) {
-		/*
-		 * If we cleaned all the nodes in unmeasurable time
-		 * double the number of nodes to be cleaned next time.
-		 */
-		if (names == cleaner->increment) {
-			cleaner->increment *= 2;
-			if (cleaner->increment > DNS_CACHE_CLEANERINCREMENT)
-				cleaner->increment = DNS_CACHE_CLEANERINCREMENT;
-			isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
-				      DNS_LOGMODULE_CACHE, ISC_LOG_DEBUG(1),
-				      "%p:new cleaner->increment = %u\n",
-				      cleaner, cleaner->increment);
-		}
-		return;
-	}
-
-	new = (names * interval);
-	new /= (usecs * 2);
-	if (new == 0)
-		new = 1;
-
-	/* Smooth */
-	new = (new + cleaner->increment * 7) / 8;
-
-	if (new > DNS_CACHE_CLEANERINCREMENT)
-		new = DNS_CACHE_CLEANERINCREMENT;
-
-	cleaner->increment = (unsigned int)new;
-
-	isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE, DNS_LOGMODULE_CACHE,
-		      ISC_LOG_DEBUG(1), "%p:new cleaner->increment = %u\n",
-		      cleaner, cleaner->increment);
-}
-#endif
+overmem_cleaning_action(isc_task_t *task, isc_event_t *event);
 
 static inline isc_result_t
 cache_create_db(dns_cache_t *cache, dns_db_t **db) {
@@ -306,7 +234,16 @@ dns_cache_create(isc_mem_t *mctx, isc_taskmgr_t *taskmgr,
 
 	cache->magic = CACHE_MAGIC;
 
-	result = cache_cleaner_init(cache, taskmgr, timermgr, &cache->cleaner);
+	/*
+	 * RBT-type cache DB has its own mechanism of cache cleaning and doesn't
+	 * need the control of the generic cleaner.
+	 */
+	if (strcmp(db_type, "rbt") == 0)
+		result = cache_cleaner_init(cache, NULL, NULL, &cache->cleaner);
+	else {
+		result = cache_cleaner_init(cache, taskmgr, timermgr,
+					    &cache->cleaner);
+	}
 	if (result != ISC_R_SUCCESS)
 		goto cleanup_db;
 
@@ -347,6 +284,15 @@ cache_free(dns_cache_t *cache) {
 	if (cache->cleaner.task != NULL)
 		isc_task_detach(&cache->cleaner.task);
 
+	if (cache->cleaner.overmem_event != NULL)
+		isc_event_free(&cache->cleaner.overmem_event);
+
+	if (cache->cleaner.resched_event != NULL)
+		isc_event_free(&cache->cleaner.resched_event);
+
+	if (cache->cleaner.iterator != NULL)
+		dns_dbiterator_destroy(&cache->cleaner.iterator);
+
 	DESTROYLOCK(&cache->cleaner.lock);
 
 	if (cache->filename) {
@@ -548,9 +494,6 @@ cache_cleaner_init(dns_cache_t *cache, isc_taskmgr_t *taskmgr,
 		   isc_timermgr_t *timermgr, cache_cleaner_t *cleaner)
 {
 	isc_result_t result;
-#ifdef LRU_DEBUG
-	isc_interval_t interval;
-#endif
 
 	result = isc_mutex_init(&cleaner->lock);
 	if (result != ISC_R_SUCCESS)
@@ -559,10 +502,19 @@ cache_cleaner_init(dns_cache_t *cache, isc_taskmgr_t *taskmgr,
 	cleaner->increment = DNS_CACHE_CLEANERINCREMENT;
 	cleaner->state = cleaner_s_idle;
 	cleaner->cache = cache;
+	cleaner->iterator = NULL;
 	cleaner->overmem = ISC_FALSE;
+	cleaner->replaceiterator = ISC_FALSE;
 
 	cleaner->task = NULL;
 	cleaner->cleaning_timer = NULL;
+	cleaner->resched_event = NULL;
+	cleaner->overmem_event = NULL;
+
+	result = dns_db_createiterator(cleaner->cache->db, ISC_FALSE,
+				       &cleaner->iterator);
+	if (result != ISC_R_SUCCESS)
+		goto cleanup;
 
 	if (taskmgr != NULL && timermgr != NULL) {
 		result = isc_task_create(taskmgr, 1, &cleaner->task);
@@ -588,8 +540,7 @@ cache_cleaner_init(dns_cache_t *cache, isc_taskmgr_t *taskmgr,
 
 		cleaner->cleaning_interval = 0; /* Initially turned off. */
 		result = isc_timer_create(timermgr, isc_timertype_inactive,
-					   NULL, NULL,
-					   cleaner->task,
+					   NULL, NULL, cleaner->task,
 					   cleaning_timer_action, cleaner,
 					   &cleaner->cleaning_timer);
 		if (result != ISC_R_SUCCESS) {
@@ -600,33 +551,122 @@ cache_cleaner_init(dns_cache_t *cache, isc_taskmgr_t *taskmgr,
 			goto cleanup;
 		}
 
-#ifdef LRU_DEBUG
-		interval.seconds = DUMP_INTERVAL;
-		interval.nanoseconds = 0;
-		RUNTIME_CHECK(isc_time_nowplusinterval(&cache->dump_time,
-						       &interval) ==
-			      ISC_R_SUCCESS);
-		cache->dump_timer = NULL;
-		result = isc_timer_create(timermgr, isc_timertype_once,
-					  &cache->dump_time, NULL,
-					  cleaner->task, timer_dump,
-					  cache, &cache->dump_timer);
-		RUNTIME_CHECK(result == ISC_R_SUCCESS); /* for brevity */
-#endif
+		cleaner->resched_event =
+			isc_event_allocate(cache->mctx, cleaner,
+					   DNS_EVENT_CACHECLEAN,
+					   incremental_cleaning_action,
+					   cleaner, sizeof(isc_event_t));
+		if (cleaner->resched_event == NULL) {
+			result = ISC_R_NOMEMORY;
+			goto cleanup;
+		}
+
+		cleaner->overmem_event =
+			isc_event_allocate(cache->mctx, cleaner,
+					   DNS_EVENT_CACHEOVERMEM,
+					   overmem_cleaning_action,
+					   cleaner, sizeof(isc_event_t));
+		if (cleaner->overmem_event == NULL) {
+			result = ISC_R_NOMEMORY;
+			goto cleanup;
+		}
 	}
 
 	return (ISC_R_SUCCESS);
 
  cleanup:
+	if (cleaner->overmem_event != NULL)
+		isc_event_free(&cleaner->overmem_event);
+	if (cleaner->resched_event != NULL)
+		isc_event_free(&cleaner->resched_event);
 	if (cleaner->cleaning_timer != NULL)
 		isc_timer_detach(&cleaner->cleaning_timer);
 	if (cleaner->task != NULL)
 		isc_task_detach(&cleaner->task);
+	if (cleaner->iterator != NULL)
+		dns_dbiterator_destroy(&cleaner->iterator);
 	DESTROYLOCK(&cleaner->lock);
  fail:
 	return (result);
 }
 
+static void
+begin_cleaning(cache_cleaner_t *cleaner) {
+	isc_result_t result = ISC_R_SUCCESS;
+
+	REQUIRE(CLEANER_IDLE(cleaner));
+
+	/*
+	 * Create an iterator, if it does not already exist, and
+	 * position it at the beginning of the cache.
+	 */
+	if (cleaner->iterator == NULL)
+		result = dns_db_createiterator(cleaner->cache->db, ISC_FALSE,
+					       &cleaner->iterator);
+	if (result != ISC_R_SUCCESS)
+		isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
+			      DNS_LOGMODULE_CACHE, ISC_LOG_WARNING,
+			      "cache cleaner could not create "
+			      "iterator: %s", isc_result_totext(result));
+	else {
+		dns_dbiterator_setcleanmode(cleaner->iterator, ISC_TRUE);
+		result = dns_dbiterator_first(cleaner->iterator);
+	}
+	if (result != ISC_R_SUCCESS) {
+		/*
+		 * If the result is ISC_R_NOMORE, the database is empty,
+		 * so there is nothing to be cleaned.
+		 */
+		if (result != ISC_R_NOMORE && cleaner->iterator != NULL) {
+			UNEXPECTED_ERROR(__FILE__, __LINE__,
+					 "cache cleaner: "
+					 "dns_dbiterator_first() failed: %s",
+					 dns_result_totext(result));
+			dns_dbiterator_destroy(&cleaner->iterator);
+		} else if (cleaner->iterator != NULL) {
+			result = dns_dbiterator_pause(cleaner->iterator);
+			RUNTIME_CHECK(result == ISC_R_SUCCESS);
+		}
+	} else {
+		/*
+		 * Pause the iterator to free its lock.
+		 */
+		result = dns_dbiterator_pause(cleaner->iterator);
+		RUNTIME_CHECK(result == ISC_R_SUCCESS);
+
+		isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
+			      DNS_LOGMODULE_CACHE, ISC_LOG_DEBUG(1),
+			      "begin cache cleaning, mem inuse %lu",
+			    (unsigned long)isc_mem_inuse(cleaner->cache->mctx));
+		cleaner->state = cleaner_s_busy;
+		isc_task_send(cleaner->task, &cleaner->resched_event);
+	}
+
+	return;
+}
+
+static void
+end_cleaning(cache_cleaner_t *cleaner, isc_event_t *event) {
+	isc_result_t result;
+
+	REQUIRE(CLEANER_BUSY(cleaner));
+	REQUIRE(event != NULL);
+
+	result = dns_dbiterator_pause(cleaner->iterator);
+	if (result != ISC_R_SUCCESS)
+		dns_dbiterator_destroy(&cleaner->iterator);
+
+	dns_cache_setcleaninginterval(cleaner->cache,
+				      cleaner->cleaning_interval);
+
+	isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE, DNS_LOGMODULE_CACHE,
+		      ISC_LOG_DEBUG(1), "end cache cleaning, mem inuse %lu",
+		      (unsigned long)isc_mem_inuse(cleaner->cache->mctx));
+
+	cleaner->state = cleaner_s_idle;
+	cleaner->resched_event = event;
+}
+
 /*
  * This is run once for every cache-cleaning-interval as defined in named.conf.
  */
@@ -643,9 +683,174 @@ cleaning_timer_action(isc_task_t *task, isc_event_t *event) {
 		      ISC_LOG_DEBUG(1), "cache cleaning timer fired, "
 		      "cleaner state = %d", cleaner->state);
 
+	if (cleaner->state == cleaner_s_idle)
+		begin_cleaning(cleaner);
+
 	isc_event_free(&event);
 }
 
+/*
+ * This is called when the cache either surpasses its upper limit
+ * or shrinks beyond its lower limit.
+ */
+static void
+overmem_cleaning_action(isc_task_t *task, isc_event_t *event) {
+	cache_cleaner_t *cleaner = event->ev_arg;
+	isc_boolean_t want_cleaning = ISC_FALSE;
+
+	UNUSED(task);
+
+	INSIST(task == cleaner->task);
+	INSIST(event->ev_type == DNS_EVENT_CACHEOVERMEM);
+	INSIST(cleaner->overmem_event == NULL);
+
+	isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE, DNS_LOGMODULE_CACHE,
+		      ISC_LOG_DEBUG(1), "overmem_cleaning_action called, "
+		      "overmem = %d, state = %d", cleaner->overmem,
+		      cleaner->state);
+
+	LOCK(&cleaner->lock);
+
+	if (cleaner->overmem) {
+		if (cleaner->state == cleaner_s_idle)
+			want_cleaning = ISC_TRUE;
+	} else {
+		if (cleaner->state == cleaner_s_busy)
+			/*
+			 * end_cleaning() can't be called here because
+			 * then both cleaner->overmem_event and
+			 * cleaner->resched_event will point to this
+			 * event.  Set the state to done, and then
+			 * when the incremental_cleaning_action() event
+			 * is posted, it will handle the end_cleaning.
+			 */
+			cleaner->state = cleaner_s_done;
+	}
+
+	cleaner->overmem_event = event;
+
+	UNLOCK(&cleaner->lock);
+
+	if (want_cleaning)
+		begin_cleaning(cleaner);
+}
+
+/*
+ * Do incremental cleaning.
+ */
+static void
+incremental_cleaning_action(isc_task_t *task, isc_event_t *event) {
+	cache_cleaner_t *cleaner = event->ev_arg;
+	isc_result_t result;
+	unsigned int n_names;
+	isc_time_t start;
+
+	UNUSED(task);
+
+	INSIST(task == cleaner->task);
+	INSIST(event->ev_type == DNS_EVENT_CACHECLEAN);
+
+	if (cleaner->state == cleaner_s_done) {
+		cleaner->state = cleaner_s_busy;
+		end_cleaning(cleaner, event);
+		LOCK(&cleaner->cache->lock);
+		LOCK(&cleaner->lock);
+		if (cleaner->replaceiterator) {
+			dns_dbiterator_destroy(&cleaner->iterator);
+			(void) dns_db_createiterator(cleaner->cache->db,
+						     ISC_FALSE,
+						     &cleaner->iterator);
+			cleaner->replaceiterator = ISC_FALSE;
+		}
+		UNLOCK(&cleaner->lock);
+		UNLOCK(&cleaner->cache->lock);
+		return;
+	}
+
+	INSIST(CLEANER_BUSY(cleaner));
+
+	n_names = cleaner->increment;
+
+	REQUIRE(DNS_DBITERATOR_VALID(cleaner->iterator));
+
+	isc_time_now(&start);
+	while (n_names-- > 0) {
+		dns_dbnode_t *node = NULL;
+
+		result = dns_dbiterator_current(cleaner->iterator, &node,
+						NULL);
+		if (result != ISC_R_SUCCESS) {
+			UNEXPECTED_ERROR(__FILE__, __LINE__,
+				 "cache cleaner: dns_dbiterator_current() "
+				 "failed: %s", dns_result_totext(result));
+
+			end_cleaning(cleaner, event);
+			return;
+		}
+
+		/*
+		 * The node was not needed, but was required by
+		 * dns_dbiterator_current().  Give up its reference.
+		 */
+		dns_db_detachnode(cleaner->cache->db, &node);
+
+		/*
+		 * Step to the next node.
+		 */
+		result = dns_dbiterator_next(cleaner->iterator);
+
+		if (result != ISC_R_SUCCESS) {
+			/*
+			 * Either the end was reached (ISC_R_NOMORE) or
+			 * some error was signaled.  If the cache is still
+			 * overmem and no error was encountered,
+			 * keep trying to clean it, otherwise stop cleaning.
+			 */
+			if (result != ISC_R_NOMORE)
+				UNEXPECTED_ERROR(__FILE__, __LINE__,
+						 "cache cleaner: "
+						 "dns_dbiterator_next() "
+						 "failed: %s",
+						 dns_result_totext(result));
+			else if (cleaner->overmem) {
+				result = dns_dbiterator_first(cleaner->
+							      iterator);
+				if (result == ISC_R_SUCCESS) {
+					isc_log_write(dns_lctx,
+						      DNS_LOGCATEGORY_DATABASE,
+						      DNS_LOGMODULE_CACHE,
+						      ISC_LOG_DEBUG(1),
+						      "cache cleaner: "
+						      "still overmem, "
+						      "reset and try again");
+					continue;
+				}
+			}
+
+			end_cleaning(cleaner, event);
+			return;
+		}
+	}
+
+	/*
+	 * We have successfully performed a cleaning increment but have
+	 * not gone through the entire cache.  Free the iterator locks
+	 * and reschedule another batch.  If it fails, just try to continue
+	 * anyway.
+	 */
+	result = dns_dbiterator_pause(cleaner->iterator);
+	RUNTIME_CHECK(result == ISC_R_SUCCESS);
+
+	isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE, DNS_LOGMODULE_CACHE,
+		      ISC_LOG_DEBUG(1), "cache cleaner: checked %u nodes, "
+		      "mem inuse %lu, sleeping", cleaner->increment,
+		      (unsigned long)isc_mem_inuse(cleaner->cache->mctx));
+
+	isc_task_send(task, &event);
+	INSIST(CLEANER_BUSY(cleaner));
+	return;
+}
+
 /*
  * Do immediate cleaning.
  */
@@ -714,6 +919,10 @@ water(void *arg, int mark) {
 		isc_mem_waterack(cache->mctx, mark);
 	}
 
+	if (cache->cleaner.overmem_event != NULL)
+		isc_task_send(cache->cleaner.task,
+			      &cache->cleaner.overmem_event);
+
 	UNLOCK(&cache->cleaner.lock);
 }
 
@@ -731,8 +940,8 @@ dns_cache_setcachesize(dns_cache_t *cache, isc_uint32_t size) {
 	if (size != 0 && size < DNS_CACHE_MINSIZE)
 		size = DNS_CACHE_MINSIZE;
 
-	hiwater = size - (size >> 3);   /* Approximately 7/8ths. */
-	lowater = size - (size >> 2);   /* Approximately 3/4ths. */
+	hiwater = size - (size >> 3);	/* Approximately 7/8ths. */
+	lowater = size - (size >> 2);	/* Approximately 3/4ths. */
 
 	/*
 	 * If the cache was overmem and cleaning, but now with the new limits
@@ -767,6 +976,11 @@ cleaner_shutdown_action(isc_task_t *task, isc_event_t *event) {
 	INSIST(task == cache->cleaner.task);
 	INSIST(event->ev_type == ISC_TASKEVENT_SHUTDOWN);
 
+	if (CLEANER_BUSY(&cache->cleaner))
+		end_cleaning(&cache->cleaner, event);
+	else
+		isc_event_free(&event);
+
 	LOCK(&cache->lock);
 
 	cache->live_tasks--;
@@ -783,10 +997,6 @@ cleaner_shutdown_action(isc_task_t *task, isc_event_t *event) {
 	if (cache->cleaner.cleaning_timer != NULL)
 		isc_timer_detach(&cache->cleaner.cleaning_timer);
 
-#ifdef LRU_DEBUG
-	isc_timer_detach(&cache->dump_timer);
-#endif
-
 	/* Make sure we don't reschedule anymore. */
 	(void)isc_task_purge(task, NULL, DNS_EVENT_CACHECLEAN, NULL);
 
@@ -794,8 +1004,6 @@ cleaner_shutdown_action(isc_task_t *task, isc_event_t *event) {
 
 	if (should_free)
 		cache_free(cache);
-
-	isc_event_free(&event);
 }
 
 isc_result_t
@@ -810,9 +1018,14 @@ dns_cache_flush(dns_cache_t *cache) {
 	LOCK(&cache->lock);
 	LOCK(&cache->cleaner.lock);
 	if (cache->cleaner.state == cleaner_s_idle) {
-		/* XXXMLG do something */
-	} else if (cache->cleaner.state == cleaner_s_busy) {
-		/* XXXMLG do something else */
+		if (cache->cleaner.iterator != NULL)
+			dns_dbiterator_destroy(&cache->cleaner.iterator);
+		(void) dns_db_createiterator(db, ISC_FALSE,
+					     &cache->cleaner.iterator);
+	} else {
+		if (cache->cleaner.state == cleaner_s_busy)
+			cache->cleaner.state = cleaner_s_done;
+		cache->cleaner.replaceiterator = ISC_TRUE;
 	}
 	dns_db_detach(&cache->db);
 	cache->db = db;
@@ -874,33 +1087,3 @@ dns_cache_flushname(dns_cache_t *cache, dns_name_t *name) {
 	dns_db_detach(&db);
 	return (result);
 }
-
-#ifdef LRU_DEBUG
-static void
-timer_dump(isc_task_t *task, isc_event_t *event) {
-	dns_cache_t *cache;
-	isc_interval_t interval;
-	isc_time_t nexttime;
-
-	UNUSED(task);
-
-	cache = event->ev_arg;
-	INSIST(VALID_CACHE(cache));
-
-#ifdef LRU_DEBUG
-	/* XXX: abuse existing overmem method */
-	dns_db_overmem(cache->db, (isc_boolean_t)-1);
-#endif
-
-	interval.seconds = DUMP_INTERVAL;
-	interval.nanoseconds = 0;
-
-	RUNTIME_CHECK(isc_time_add(&cache->dump_time, &interval, &nexttime) ==
-		      ISC_R_SUCCESS); /* XXX: this is not always true */
-	cache->dump_time = nexttime;
-	(void)isc_timer_reset(cache->dump_timer, isc_timertype_once,
-			      &cache->dump_time, NULL, ISC_FALSE);
-
-	isc_event_free(&event);
-}
-#endif
diff --git a/lib/dns/rbtdb.c b/lib/dns/rbtdb.c
index ed2f16fca7..85942971a9 100644
--- a/lib/dns/rbtdb.c
+++ b/lib/dns/rbtdb.c
@@ -15,7 +15,7 @@
  * PERFORMANCE OF THIS SOFTWARE.
  */
 
-/* $Id: rbtdb.c,v 1.259 2008/04/23 21:32:01 each Exp $ */
+/* $Id: rbtdb.c,v 1.260 2008/05/01 18:23:07 jinmei Exp $ */
 
 /*! \file */
 
@@ -275,8 +275,6 @@ typedef ISC_LIST(dns_rbtnode_t)         rbtnodelist_t;
 #define RDATASET_ATTR_NXDOMAIN          0x0010
 #define RDATASET_ATTR_RESIGN            0x0020
 #define RDATASET_ATTR_STATCOUNT         0x0040
-#define RDATASET_ATTR_CACHE             0x1000 /* for debug */
-#define RDATASET_ATTR_CANCELED          0x2000 /* for debug */
 
 typedef struct acache_cbarg {
 	dns_rdatasetadditional_t        type;
@@ -352,33 +350,6 @@ typedef struct rbtdb_version {
 
 typedef ISC_LIST(rbtdb_version_t)       rbtdb_versionlist_t;
 
-#ifdef LRU_DEBUG
-/* statistics info for testing */
-struct cachestat {
-	unsigned int    cache_total;
-	int             cache_current;
-	unsigned int    ncache_total;
-	int             ncache_current;
-	unsigned int    a_total;
-	int             a_current;
-	unsigned int    aaaa_total;
-	int             aaaa_current;
-	unsigned int    ns_total;
-	int             ns_current;
-	unsigned int    ptr_total;
-	int             ptr_current;
-	unsigned int    glue_total;
-	int             glue_current;
-	unsigned int    additional_total;
-	int             additional_current;
-
-	unsigned int    stale_purge;
-	unsigned int    stale_scan;
-	unsigned int    stale_expire;
-	unsigned int    stale_lru;
-};
-#endif
-
 typedef enum {
 	dns_db_insecure,
 	dns_db_partial,
@@ -437,9 +408,6 @@ typedef struct {
 
 	/* Unlocked */
 	unsigned int                    quantum;
-#ifdef LRU_DEBUG
-	struct cachestat                cachestat;
-#endif
 } dns_rbtdb_t;
 
 #define RBTDB_ATTR_LOADED               0x01
@@ -922,41 +890,6 @@ free_rbtdb(dns_rbtdb_t *rbtdb, isc_boolean_t log, isc_event_t *event) {
 	if (rbtdb->task != NULL)
 		isc_task_detach(&rbtdb->task);
 
-#ifdef LRU_DEBUG
-	/* Experimental logging about memory usage */
-	if (IS_CACHE(rbtdb) && rbtdb->common.rdclass == dns_rdataclass_in) {
-		isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
-			      DNS_LOGMODULE_CACHE, ISC_LOG_INFO,
-			      "cache DB %p: mem inuse %lu, XXX node, "
-			      "%d/%u current/total cache, %d/%u neg, %d/%u A, %d/%u AAAA, "
-			      "%d/%u NS, %d/%u PTR, %d/%u glue, "
-			      "%d/%u  additional, purge/scan=%u(%u expiry, %u lru)/%u, "
-			      "overmem=%d",
-			      rbtdb,
-			      (unsigned long)isc_mem_inuse(rbtdb->common.mctx),
-			      rbtdb->cachestat.cache_current, rbtdb->cachestat.cache_total,
-			      rbtdb->cachestat.ncache_current, rbtdb->cachestat.ncache_total,
-			      rbtdb->cachestat.a_current, rbtdb->cachestat.a_total,
-			      rbtdb->cachestat.aaaa_current, rbtdb->cachestat.aaaa_total,
-			      rbtdb->cachestat.ns_current, rbtdb->cachestat.ns_total,
-			      rbtdb->cachestat.ptr_current, rbtdb->cachestat.ptr_total,
-			      rbtdb->cachestat.glue_current, rbtdb->cachestat.glue_total,
-			      rbtdb->cachestat.additional_current,
-			      rbtdb->cachestat.additional_total,
-			      rbtdb->cachestat.stale_purge, rbtdb->cachestat.stale_expire,
-			      rbtdb->cachestat.stale_lru, rbtdb->cachestat.stale_scan,
-			      rbtdb->overmem);
-		INSIST(rbtdb->cachestat.cache_current == 0);
-		INSIST(rbtdb->cachestat.ncache_current == 0);
-		INSIST(rbtdb->cachestat.a_current == 0);
-		INSIST(rbtdb->cachestat.aaaa_current == 0);
-		INSIST(rbtdb->cachestat.ns_current == 0);
-		INSIST(rbtdb->cachestat.ptr_current == 0);
-		INSIST(rbtdb->cachestat.glue_current == 0);
-		INSIST(rbtdb->cachestat.additional_current == 0);
-	}
-#endif
-
 	RBTDB_DESTROYLOCK(&rbtdb->lock);
 	rbtdb->common.magic = 0;
 	rbtdb->common.impmagic = 0;
@@ -1231,69 +1164,6 @@ free_rdataset(dns_rbtdb_t *rbtdb, isc_mem_t *mctx, rdatasetheader_t *rdataset)
 		update_rrsetstats(rbtdb, rdataset, ISC_FALSE);
 	}
 
-#ifdef LRU_DEBUG
-	/*
-	 * for debug: statistics update.
-	 * Nothing in this block should have any side-effects.
-	 */
-	if (EXISTS(rdataset) &&
-	    (rdataset->attributes & RDATASET_ATTR_CACHE) != 0) {
-		rbtdb->cachestat.cache_current--;
-		if ((rdataset->attributes & RDATASET_ATTR_CANCELED) != 0)
-			rbtdb->cachestat.cache_total--;
-		if (RBTDB_RDATATYPE_BASE(rdataset->type) == 0) {
-			rbtdb->cachestat.ncache_current--;
-			INSIST(rbtdb->cachestat.ncache_current >= 0);
-			if ((rdataset->attributes & RDATASET_ATTR_CANCELED)
-			    != 0)
-				rbtdb->cachestat.ncache_total--;
-		}
-		if (rdataset->type == dns_rdatatype_a) {
-			rbtdb->cachestat.a_current--;
-			INSIST(rbtdb->cachestat.a_current >= 0);
-			if ((rdataset->attributes & RDATASET_ATTR_CANCELED)
-			    != 0)
-				rbtdb->cachestat.a_total--;
-		} else if (rdataset->type == dns_rdatatype_aaaa) {
-			rbtdb->cachestat.aaaa_current--;
-			INSIST(rbtdb->cachestat.aaaa_current >= 0);
-			if ((rdataset->attributes & RDATASET_ATTR_CANCELED)
-			    != 0)
-				rbtdb->cachestat.aaaa_total--;
-		} else if (rdataset->type == dns_rdatatype_ptr) {
-			rbtdb->cachestat.ptr_current--;
-			INSIST(rbtdb->cachestat.ptr_current >= 0);
-			if ((rdataset->attributes & RDATASET_ATTR_CANCELED)
-			    != 0)
-				rbtdb->cachestat.ptr_total--;
-		} else if (rdataset->type == dns_rdatatype_ns) {
-			rbtdb->cachestat.ns_current--;
-			INSIST(rbtdb->cachestat.ns_current >= 0);
-			if ((rdataset->attributes & RDATASET_ATTR_CANCELED)
-			    != 0)
-				rbtdb->cachestat.ns_total--;
-		}
-		if (rdataset->trust == dns_trust_glue &&
-		    (rdataset->type == dns_rdatatype_a ||
-		     rdataset->type == dns_rdatatype_aaaa)) {
-			rbtdb->cachestat.glue_current--;
-			INSIST(rbtdb->cachestat.glue_current >= 0);
-			if ((rdataset->attributes & RDATASET_ATTR_CANCELED)
-			    != 0)
-				rbtdb->cachestat.glue_total--;
-		}
-		if (rdataset->trust == dns_trust_additional &&
-		    (rdataset->type == dns_rdatatype_a ||
-		     rdataset->type == dns_rdatatype_aaaa)) {
-			rbtdb->cachestat.additional_current--;
-			INSIST(rbtdb->cachestat.additional_current >= 0);
-			if ((rdataset->attributes & RDATASET_ATTR_CANCELED)
-			    != 0)
-				rbtdb->cachestat.additional_total--;
-		}
-	}
-#endif
-
 	idx = rdataset->node->locknum;
 	if (ISC_LINK_LINKED(rdataset, lru_link))
 		ISC_LIST_UNLINK(rbtdb->rdatasets[idx], rdataset, lru_link);
@@ -4589,40 +4459,8 @@ static void
 overmem(dns_db_t *db, isc_boolean_t overmem) {
 	dns_rbtdb_t *rbtdb = (dns_rbtdb_t *)db;
 
-#ifdef LRU_DEBUG
-	/* XXX: see cache.c:timer_dump() */
-	if ((int)overmem == -1) {
-		if (!IS_CACHE(rbtdb) || db->rdclass != dns_rdataclass_in)
-			return; /* for brevity */
-		isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
-			      DNS_LOGMODULE_CACHE, ISC_LOG_INFO,
-			      "cache DB %p: mem inuse %lu, %u node, "
-			      "%d/%u current/total cache, %d/%u neg, %d/%u A, %d/%u AAAA, "
-			      "%d/%u NS, %d/%u PTR, %d/%u glue, "
-			      "%d/%u  additional, purge/scan=%u(%u expiry, %u lru)/%u, "
-			      "overmem=%d",
-			      rbtdb,
-			      (unsigned long)isc_mem_inuse(rbtdb->common.mctx),
-			      dns_rbt_nodecount(rbtdb->tree),
-			      rbtdb->cachestat.cache_current, rbtdb->cachestat.cache_total,
-			      rbtdb->cachestat.ncache_current, rbtdb->cachestat.ncache_total,
-			      rbtdb->cachestat.a_current, rbtdb->cachestat.a_total,
-			      rbtdb->cachestat.aaaa_current, rbtdb->cachestat.aaaa_total,
-			      rbtdb->cachestat.ns_current, rbtdb->cachestat.ns_total,
-			      rbtdb->cachestat.ptr_current, rbtdb->cachestat.ptr_total,
-			      rbtdb->cachestat.glue_current, rbtdb->cachestat.glue_total,
-			      rbtdb->cachestat.additional_current,
-			      rbtdb->cachestat.additional_total,
-			      rbtdb->cachestat.stale_purge, rbtdb->cachestat.stale_expire,
-			      rbtdb->cachestat.stale_lru, rbtdb->cachestat.stale_scan,
-			      rbtdb->overmem);
-		return;
-	}
-#endif
-
-	if (IS_CACHE(rbtdb)) {
+	if (IS_CACHE(rbtdb))
 		rbtdb->overmem = overmem;
-	}
 }
 
 static void
@@ -5019,38 +4857,6 @@ cname_and_other_data(dns_rbtnode_t *node, rbtdb_serial_t serial) {
 	return (ISC_FALSE);
 }
 
-#ifdef LRU_DEBUG
-static void
-cachestat_update(dns_rbtdb_t *rbtdb, rdatasetheader_t *header) {
-	if ((header->attributes & RDATASET_ATTR_CACHE) == 0)
-		return;
-
-	/* XXX: don't use lock for brevity */
-	rbtdb->cachestat.cache_total++;
-	if (RBTDB_RDATATYPE_BASE(header->type) == 0)
-			rbtdb->cachestat.ncache_total++;
-	if (header->type == dns_rdatatype_a)
-			rbtdb->cachestat.a_total++;
-	else if (header->type == dns_rdatatype_aaaa)
-		rbtdb->cachestat.aaaa_total++;
-	else if (header->type == dns_rdatatype_ns)
-		rbtdb->cachestat.ns_total++;
-	else if (header->type == dns_rdatatype_ptr)
-		rbtdb->cachestat.ptr_total++;
-
-	if (header->trust == dns_trust_glue &&
-	    (header->type == dns_rdatatype_a ||
-	     header->type == dns_rdatatype_aaaa)) {
-		rbtdb->cachestat.glue_total++;
-	}
-	if (header->trust == dns_trust_additional &&
-	    (header->type == dns_rdatatype_a ||
-	     header->type == dns_rdatatype_aaaa)) {
-		rbtdb->cachestat.additional_total++;
-	}
-}
-#endif
-
 static isc_result_t
 resign_insert(dns_rbtdb_t *rbtdb, int idx, rdatasetheader_t *newheader) {
 	isc_result_t result;
@@ -5166,9 +4972,6 @@ add(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, rbtdb_version_t *rbtversion,
 					 * The NXDOMAIN/NODATA(QTYPE=ANY)
 					 * is more trusted.
 					 */
-					/* set the flag for debug */
-					newheader->attributes |=
-						RDATASET_ATTR_CANCELED;
 					free_rdataset(rbtdb,
 						      rbtdb->common.mctx,
 						      newheader);
@@ -5227,7 +5030,6 @@ add(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, rbtdb_version_t *rbtversion,
 		 */
 		if (rbtversion == NULL && trust < header->trust &&
 		    (header->rdh_ttl > now || header_nx)) {
-			newheader->attributes |= RDATASET_ATTR_CANCELED;
 			free_rdataset(rbtdb, rbtdb->common.mctx, newheader);
 			if (addedrdataset != NULL)
 				bind_rdataset(rbtdb, rbtnode, header, now,
@@ -5316,7 +5118,6 @@ add(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, rbtdb_version_t *rbtversion,
 				header->noqname = newheader->noqname;
 				newheader->noqname = NULL;
 			}
-			newheader->attributes |= RDATASET_ATTR_CANCELED;
 			free_rdataset(rbtdb, rbtdb->common.mctx, newheader);
 			if (addedrdataset != NULL)
 				bind_rdataset(rbtdb, rbtnode, header, now,
@@ -5342,7 +5143,6 @@ add(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, rbtdb_version_t *rbtversion,
 				header->noqname = newheader->noqname;
 				newheader->noqname = NULL;
 			}
-			newheader->attributes |= RDATASET_ATTR_CANCELED;
 			free_rdataset(rbtdb, rbtdb->common.mctx, newheader);
 			if (addedrdataset != NULL)
 				bind_rdataset(rbtdb, rbtnode, header, now,
@@ -5387,9 +5187,6 @@ add(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, rbtdb_version_t *rbtversion,
 				 * will not leak... for long.
 				 */
 				isc_heap_insert(rbtdb->heaps[idx], newheader);
-#ifdef LRU_DEBUG
-				cachestat_update(rbtdb, newheader);
-#endif
 			} else if (RESIGN(newheader))
 				resign_insert(rbtdb, idx, newheader);
 		}
@@ -5442,9 +5239,6 @@ add(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, rbtdb_version_t *rbtversion,
 			ISC_LIST_PREPEND(rbtdb->rdatasets[idx],
 					 newheader, lru_link);
 			isc_heap_insert(rbtdb->heaps[idx], newheader);
-#ifdef LRU_DEBUG
-			cachestat_update(rbtdb, newheader);
-#endif
 		} else if (RESIGN(newheader)) {
 			resign_insert(rbtdb, idx, newheader);
 		}
@@ -5621,45 +5415,6 @@ addrdataset(dns_db_t *db, dns_dbnode_t *node, dns_dbversion_t *version,
 		update_rrsetstats(rbtdb, newheader, ISC_TRUE);
 	}
 
-#ifdef LRU_DEBUG
-	/* for debug: statistics update */
-	if (IS_CACHE(rbtdb) && rdataset->rdclass == dns_rdataclass_in) {
-		/* XXX: don't use lock for brevity */
-		newheader->attributes |= RDATASET_ATTR_CACHE;
-		rbtdb->cachestat.cache_total++;
-		rbtdb->cachestat.cache_current++;
-		if (rdataset->type == 0) {
-			rbtdb->cachestat.ncache_total++;
-			rbtdb->cachestat.ncache_current++;
-		}
-		if (rdataset->type == dns_rdatatype_a) {
-			rbtdb->cachestat.a_total++;
-			rbtdb->cachestat.a_current++;
-		} else if (rdataset->type == dns_rdatatype_aaaa) {
-			rbtdb->cachestat.aaaa_total++;
-			rbtdb->cachestat.aaaa_current++;
-		} else if (rdataset->type == dns_rdatatype_ns) {
-			rbtdb->cachestat.ns_total++;
-			rbtdb->cachestat.ns_current++;
-		} else if (rdataset->type == dns_rdatatype_ptr) {
-			rbtdb->cachestat.ptr_total++;
-			rbtdb->cachestat.ptr_current++;
-		}
-		if (rdataset->trust == dns_trust_glue &&
-		    (rdataset->type == dns_rdatatype_a ||
-		     rdataset->type == dns_rdatatype_aaaa)) {
-			rbtdb->cachestat.glue_total++;
-			rbtdb->cachestat.glue_current++;
-		}
-		if (rdataset->trust == dns_trust_additional &&
-		    (rdataset->type == dns_rdatatype_a ||
-		     rdataset->type == dns_rdatatype_aaaa)) {
-			rbtdb->cachestat.additional_total++;
-			rbtdb->cachestat.additional_current++;
-		}
-	}
-#endif
-
 	if (IS_CACHE(rbtdb)) {
 		if (tree_locked)
 			cleanup_dead_nodes(rbtdb, rbtnode->locknum);
@@ -7893,7 +7648,6 @@ check_stale_cache(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode,
 {
 	rdatasetheader_t *victim;
 	isc_boolean_t overmem = rbtdb->overmem;
-	int scans = 0;          /* for debug */
 	int victims = 0;
 
 	/*
@@ -7902,11 +7656,6 @@ check_stale_cache(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode,
 	victim = isc_heap_element(rbtdb->heaps[rbtnode->locknum], 1);
 	if (victim != NULL && victim->rdh_ttl <= now - RBTDB_VIRTUAL) {
 		INSIST(victim->node->locknum == rbtnode->locknum);
-
-#ifdef LRU_DEBUG
-		/* for debug */
-		rbtdb->cachestat.stale_expire++;
-#endif
 		victims++;
 
 		set_ttl(rbtdb, victim, 0);
@@ -7935,13 +7684,7 @@ check_stale_cache(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode,
 	victim = ISC_LIST_TAIL(rbtdb->rdatasets[rbtnode->locknum]);
 	if (victim != NULL && overmem) {
 		INSIST(victim->node->locknum == rbtnode->locknum);
-
-#ifdef LRU_DEBUG
-		/* for debug */
-		rbtdb->cachestat.stale_lru++;
-#endif
 		victims++;
-		scans++;
 
 		set_ttl(rbtdb, victim, 0);
 		victim->attributes |= RDATASET_ATTR_STALE;
@@ -7962,10 +7705,4 @@ check_stale_cache(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode,
 					    isc_rwlocktype_none);
 		}
 	}
-
-#ifdef LRU_DEBUG
-	/* update statistics for debug (no lock for brevity) */
-	rbtdb->cachestat.stale_scan += scans;
-	rbtdb->cachestat.stale_purge += victims;
-#endif
 }
diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c
index d7e9c6adb0..c5354a4c7e 100644
--- a/lib/dns/resolver.c
+++ b/lib/dns/resolver.c
@@ -15,7 +15,7 @@
  * PERFORMANCE OF THIS SOFTWARE.
  */
 
-/* $Id: resolver.c,v 1.368 2008/04/10 07:20:11 marka Exp $ */
+/* $Id: resolver.c,v 1.369 2008/05/01 18:23:07 jinmei Exp $ */
 
 /*! \file */
 
@@ -353,11 +353,7 @@ struct dns_resolver {
 	isc_timer_t *			spillattimer;
 	isc_boolean_t			zero_no_soa_ttl;
 	isc_timer_t *			disppooltimer;
-#ifdef LRU_DEBUG
-#define DUMP_INTERVAL 30        /* seconds */
-	isc_timer_t *			dumptimer;
-	isc_time_t			dump_time;
-#endif
+
 	/* Locked by lock. */
 	unsigned int			references;
 	isc_boolean_t			exiting;
@@ -373,15 +369,6 @@ struct dns_resolver {
 	/* Locked by poollock. */
 	dns_dispatch_t **		dispatchv4pool;
 	dns_dispatch_t **		dispatchv6pool;
-
-#ifdef LRU_DEBUG
-	/* Unlocked: just for debug */
-	unsigned int			extqueries;
-	unsigned int			extqueries_ns;
-	unsigned int			extqueries_soa;
-	unsigned int			extqueries_a;
-	unsigned int			extqueries_aaaa;
-#endif
 };
 
 #define RES_MAGIC			ISC_MAGIC('R', 'e', 's', '!')
@@ -416,10 +403,6 @@ static isc_result_t ncache_adderesult(dns_message_t *message,
 static void validated(isc_task_t *task, isc_event_t *event);
 static void maybe_destroy(fetchctx_t *fctx);
 
-#ifdef LRU_DEBUG
-static void timer_dump(isc_task_t *task, isc_event_t *ev);
-#endif
-
 /*%
  * Increment resolver-related statistics counters.
  */
@@ -1706,23 +1689,6 @@ resquery_send(resquery_t *query) {
 	if (result != ISC_R_SUCCESS)
 		goto cleanup_message;
 
-#ifdef LRU_DEBUG
-	res->extqueries++;
-	switch (fctx->type) {
-	case dns_rdatatype_ns:
-		res->extqueries_ns++;
-		break;
-	case dns_rdatatype_soa:
-		res->extqueries_soa++;
-		break;
-	case dns_rdatatype_a:
-		res->extqueries_a++;
-		break;
-	case dns_rdatatype_aaaa:
-		res->extqueries_aaaa++;
-		break;
-	}
-#endif
 	query->sends++;
 
 	QTRACE("sent");
@@ -6291,16 +6257,6 @@ destroy(dns_resolver_t *res) {
 
 	INSIST(res->nfctx == 0);
 
-#ifdef LRU_DEBUG
-	isc_log_write(dns_lctx, DNS_LOGCATEGORY_RESOLVER,
-		      DNS_LOGMODULE_RESOLVER, ISC_LOG_INFO,
-		      "destroying resolver %p: external queries "
-		      "total/NS/SOA/A/AAAA=%u/%u/%u/%u/%u",
-		      res, res->extqueries, res->extqueries_ns,
-		      res->extqueries_soa, res->extqueries_a,
-		      res->extqueries_aaaa);
-#endif
-
 	RES_DESTROYLOCK(&res->poollock);
 	DESTROYLOCK(&res->primelock);
 	DESTROYLOCK(&res->nlock);
@@ -6338,10 +6294,6 @@ destroy(dns_resolver_t *res) {
 	}
 	if (res->disppooltimer != NULL)
 		isc_timer_detach(&res->disppooltimer);
-#ifdef LRU_DEBUG
-	if (res->dumptimer != NULL)
-		isc_timer_detach(&res->dumptimer);
-#endif
 	dns_resolver_reset_algorithms(res);
 	dns_resolver_resetmustbesecure(res);
 #if USE_ALGLOCK
@@ -6475,15 +6427,6 @@ dns_resolver_create(dns_view_t *view,
 	res->dispatchv4pool = NULL;
 	res->dispatchv6pool = NULL;
 	res->disppooltimer = NULL;
-#ifdef LRU_DEBUG
-	res->dumptimer = NULL;
-	res->extqueries = 0;
-	res->extqueries_ns = 0;
-	res->extqueries_soa = 0;
-	res->extqueries_a = 0;
-	res->extqueries_aaaa = 0;
-#endif
-
 	res->nbuckets = ntasks;
 	res->activebuckets = ntasks;
 	res->buckets = isc_mem_get(view->mctx,
@@ -6566,22 +6509,6 @@ dns_resolver_create(dns_view_t *view,
 	result = isc_timer_create(timermgr, isc_timertype_inactive, NULL, NULL,
 				  task, spillattimer_countdown, res,
 				  &res->spillattimer);
-
-#ifdef LRU_DEBUG
-	{
-		isc_interval_t interval;
-
-		interval.seconds = DUMP_INTERVAL;
-		interval.nanoseconds = 0;
-		RUNTIME_CHECK(isc_time_nowplusinterval(&res->dump_time,
-						       &interval) ==
-			      ISC_R_SUCCESS);
-
-		result = isc_timer_create(timermgr, isc_timertype_once,
-					  &res->dump_time, NULL, task,
-					  timer_dump, res, &res->dumptimer);
-	}
-#endif
 	isc_task_detach(&task);
 	if (result != ISC_R_SUCCESS)
 		goto cleanup_poollock;
@@ -7769,38 +7696,3 @@ dns_resolver_createdispatchpool(dns_resolver_t *res, unsigned int ndisps,
 
 	return (result);
 }
-
-#ifdef LRU_DEBUG
-static void
-timer_dump(isc_task_t *task, isc_event_t *ev) {
-	dns_resolver_t *res;
-	isc_interval_t interval;
-	isc_time_t nexttime;
-
-	UNUSED(task);
-
-	res = ev->ev_arg;
-	INSIST(VALID_RESOLVER(res));
-
-	if (res->extqueries > 0) {
-		isc_log_write(dns_lctx, DNS_LOGCATEGORY_RESOLVER,
-			      DNS_LOGMODULE_RESOLVER, ISC_LOG_INFO,
-			      "resolver dump %p: external queries "
-			      "total/NS/SOA/A/AAAA=%u/%u/%u/%u/%u",
-			      res, res->extqueries, res->extqueries_ns,
-			      res->extqueries_soa, res->extqueries_a,
-			      res->extqueries_aaaa);
-	}
-
-	interval.seconds = DUMP_INTERVAL;
-	interval.nanoseconds = 0;
-
-	RUNTIME_CHECK(isc_time_add(&res->dump_time, &interval, &nexttime) ==
-		      ISC_R_SUCCESS); /* XXX: this is not always true */
-	res->dump_time = nexttime;
-	(void)isc_timer_reset(res->dumptimer, isc_timertype_once,
-			      &res->dump_time, NULL, ISC_FALSE);
-
-	isc_event_free(&ev);
-}
-#endif

From b4074b62552affb6f16531c88ad8281a7fbdf38c Mon Sep 17 00:00:00 2001
From: Automatic Updater 
Date: Thu, 1 May 2008 23:18:41 +0000
Subject: [PATCH 047/137] auto update

---
 doc/private/branches | 1 +
 1 file changed, 1 insertion(+)

diff --git a/doc/private/branches b/doc/private/branches
index 6a56a525b2..638d6db934 100644
--- a/doc/private/branches
+++ b/doc/private/branches
@@ -117,6 +117,7 @@ rt17828				new	marka	// 2008-04-09 23:06 +0000
 rt17949				new	
 rt17977				new	each	// 2008-04-23 00:29 +0000
 rt18018				new	
+rt18020				new	fdupont	// 2008-05-01 07:57 +0000
 shane_dbbackend			open	
 skan				open	explorer
 skan-metazones1			private	explorer

From 2a9a5e1871710510cdbba67c13ce21e75296b451 Mon Sep 17 00:00:00 2001
From: Automatic Updater 
Date: Fri, 2 May 2008 01:11:51 +0000
Subject: [PATCH 048/137] regen

---
 doc/arm/Bv9ARM.ch06.html             |  85 +++++++------
 doc/arm/Bv9ARM.ch07.html             |  14 +--
 doc/arm/Bv9ARM.ch08.html             |  18 +--
 doc/arm/Bv9ARM.ch09.html             | 180 +++++++++++++--------------
 doc/arm/Bv9ARM.html                  |  46 +++----
 doc/arm/man.dig.html                 |  20 +--
 doc/arm/man.dnssec-keyfromlabel.html |  12 +-
 doc/arm/man.dnssec-keygen.html       |  14 +--
 doc/arm/man.dnssec-signzone.html     |  12 +-
 doc/arm/man.host.html                |  10 +-
 doc/arm/man.named-checkconf.html     |  12 +-
 doc/arm/man.named-checkzone.html     |  12 +-
 doc/arm/man.named.html               |  16 +--
 doc/arm/man.rndc-confgen.html        |  12 +-
 doc/arm/man.rndc.conf.html           |  12 +-
 doc/arm/man.rndc.html                |  12 +-
 16 files changed, 245 insertions(+), 242 deletions(-)

diff --git a/doc/arm/Bv9ARM.ch06.html b/doc/arm/Bv9ARM.ch06.html
index eebf37ada7..80c86264c2 100644
--- a/doc/arm/Bv9ARM.ch06.html
+++ b/doc/arm/Bv9ARM.ch06.html
@@ -14,7 +14,7 @@
  - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
  - PERFORMANCE OF THIS SOFTWARE.
 -->
-
+
 
 
 
@@ -75,32 +75,32 @@
 
options Statement Definition and Usage
statistics-channels Statement Grammar
-
statistics-channels Statement Definition and +
statistics-channels Statement Definition and Usage
server Statement Grammar
server Statement Definition and Usage
-
trusted-keys Statement Grammar
-
trusted-keys Statement Definition +
trusted-keys Statement Grammar
+
trusted-keys Statement Definition and Usage
view Statement Grammar
-
view Statement Definition and Usage
+
view Statement Definition and Usage
zone Statement Grammar
-
zone Statement Definition and Usage
+
zone Statement Definition and Usage
-
Zone File
+
Zone File
Types of Resource Records and When to Use Them
-
Discussion of MX Records
+
Discussion of MX Records
Setting TTLs
-
Inverse Mapping in IPv4
-
Other Zone File Directives
-
BIND Master File Extension: the $GENERATE Directive
+
Inverse Mapping in IPv4
+
Other Zone File Directives
+
BIND Master File Extension: the $GENERATE Directive
Additional File Formats
-
BIND9 Statistics
-
Statistics Counters
+
BIND9 Statistics
+
Statistics Counters

@@ -3671,11 +3671,14 @@ query-source-v6 address * port *;

cleaning-interval

- The server will remove expired resource records + This interval is effectively obsolete. Previously, + the server would remove expired resource records from the cache every cleaning-interval minutes. - The default is 60 minutes. The maximum value is 28 days - (40320 minutes). - If set to 0, no periodic cleaning will occur. + BIND 9 now manages cache + memory in a more sophisticated manner and does not + rely on the periodic cleaning any more. + Specifying this option therefore has no effect on + the server's behavior.

heartbeat-interval

@@ -4452,7 +4455,7 @@ query-source-v6 address * port *;

-statistics-channels Statement Definition and +statistics-channels Statement Definition and Usage

The statistics-channels statement @@ -4697,7 +4700,7 @@ query-source-v6 address * port *;

-trusted-keys Statement Grammar

+trusted-keys Statement Grammar
trusted-keys {
     string number number number string ;
     [ string number number number string ; [...]]
@@ -4706,7 +4709,7 @@ query-source-v6 address * port *;
 
 

-trusted-keys Statement Definition +trusted-keys Statement Definition and Usage

The trusted-keys statement defines @@ -4749,7 +4752,7 @@ query-source-v6 address * port *;

-view Statement Definition and Usage

+view Statement Definition and Usage

The view statement is a powerful feature @@ -5012,10 +5015,10 @@ zone zone_name [

-zone Statement Definition and Usage

+zone Statement Definition and Usage

-Zone Types

+Zone Types
@@ -5224,7 +5227,7 @@ zone zone_name [

-Class

+Class

The zone's name may optionally be followed by a class. If a class is not specified, class IN (for Internet), @@ -5246,7 +5249,7 @@ zone zone_name [

-Zone Options

+Zone Options
allow-notify

@@ -5818,7 +5821,7 @@ zone zone_name [

-Zone File

+Zone File

Types of Resource Records and When to Use Them

@@ -5831,7 +5834,7 @@ zone zone_name [

-Resource Records

+Resource Records

A domain name identifies a node. Each node has a set of resource information, which may be empty. The set of resource @@ -6482,7 +6485,7 @@ zone zone_name [

-Textual expression of RRs

+Textual expression of RRs

RRs are represented in binary form in the packets of the DNS protocol, and are usually represented in highly encoded form @@ -6685,7 +6688,7 @@ zone zone_name [

-Discussion of MX Records

+Discussion of MX Records

As described above, domain servers store information as a series of resource records, each of which contains a particular @@ -6943,7 +6946,7 @@ zone zone_name [

-Inverse Mapping in IPv4

+Inverse Mapping in IPv4

Reverse name resolution (that is, translation from IP address to name) is achieved by means of the in-addr.arpa domain @@ -7004,7 +7007,7 @@ zone zone_name [

-Other Zone File Directives

+Other Zone File Directives

The Master File Format was initially defined in RFC 1035 and has subsequently been extended. While the Master File Format @@ -7019,7 +7022,7 @@ zone zone_name [

-The $ORIGIN Directive

+The $ORIGIN Directive

Syntax: $ORIGIN domain-name @@ -7047,7 +7050,7 @@ WWW.EXAMPLE.COM. CNAME MAIN-SERVER.EXAMPLE.COM.

-The $INCLUDE Directive

+The $INCLUDE Directive

Syntax: $INCLUDE filename @@ -7083,7 +7086,7 @@ WWW.EXAMPLE.COM. CNAME MAIN-SERVER.EXAMPLE.COM.

-The $TTL Directive

+The $TTL Directive

Syntax: $TTL default-ttl @@ -7102,7 +7105,7 @@ WWW.EXAMPLE.COM. CNAME MAIN-SERVER.EXAMPLE.COM.

-BIND Master File Extension: the $GENERATE Directive

+BIND Master File Extension: the $GENERATE Directive

Syntax: $GENERATE range @@ -7307,7 +7310,7 @@ $GENERATE 1-127 $ CNAME $.0

-BIND9 Statistics

+BIND9 Statistics

BIND 9 maintains lots of statistics information and provides several interfaces for users to @@ -7464,7 +7467,7 @@ $GENERATE 1-127 $ CNAME $.0

-Statistics Counters

+Statistics Counters

The following tables summarize statistics counters that BIND 9 provides. @@ -7483,7 +7486,7 @@ $GENERATE 1-127 $ CNAME $.0

-Name Server Statistics Counters

+Name Server Statistics Counters
@@ -8024,7 +8027,7 @@ $GENERATE 1-127 $ CNAME $.0

-Zone Maintenance Statistics Counters

+Zone Maintenance Statistics Counters
@@ -8178,7 +8181,7 @@ $GENERATE 1-127 $ CNAME $.0

-Resolver Statistics Counters

+Resolver Statistics Counters
@@ -8484,7 +8487,7 @@ $GENERATE 1-127 $ CNAME $.0

-Compatibility with BIND 8 Counters

+Compatibility with BIND 8 Counters

Most statistics counters that were available in BIND 8 are also supported in diff --git a/doc/arm/Bv9ARM.ch07.html b/doc/arm/Bv9ARM.ch07.html index e9ac306929..50e2ef12a0 100644 --- a/doc/arm/Bv9ARM.ch07.html +++ b/doc/arm/Bv9ARM.ch07.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -46,10 +46,10 @@

Table of Contents

Access Control Lists
-
Chroot and Setuid
+
Chroot and Setuid
-
The chroot Environment
-
Using the setuid Function
+
The chroot Environment
+
Using the setuid Function
Dynamic Update Security
@@ -119,7 +119,7 @@ zone "example.com" {

-Chroot and Setuid +Chroot and Setuid

On UNIX servers, it is possible to run BIND in a chrooted environment @@ -143,7 +143,7 @@ zone "example.com" {

-The chroot Environment

+The chroot Environment

In order for a chroot environment to @@ -171,7 +171,7 @@ zone "example.com" {

-Using the setuid Function

+Using the setuid Function

Prior to running the named daemon, use diff --git a/doc/arm/Bv9ARM.ch08.html b/doc/arm/Bv9ARM.ch08.html index 3ade78f355..a3c9503254 100644 --- a/doc/arm/Bv9ARM.ch08.html +++ b/doc/arm/Bv9ARM.ch08.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -45,18 +45,18 @@

-Common Problems

+Common Problems

-It's not working; how can I figure out what's wrong?

+It's not working; how can I figure out what's wrong?

The best solution to solving installation and configuration issues is to take preventative measures by setting @@ -68,7 +68,7 @@

-Incrementing and Changing the Serial Number

+Incrementing and Changing the Serial Number

Zone serial numbers are just numbers — they aren't date related. A lot of people set them to a number that @@ -95,7 +95,7 @@

-Where Can I Get Help?

+Where Can I Get Help?

The Internet Systems Consortium (ISC) offers a wide range diff --git a/doc/arm/Bv9ARM.ch09.html b/doc/arm/Bv9ARM.ch09.html index 56a99ff40a..a1022c4a3a 100644 --- a/doc/arm/Bv9ARM.ch09.html +++ b/doc/arm/Bv9ARM.ch09.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -45,21 +45,21 @@

-Acknowledgments

+Acknowledgments

A Brief History of the DNS and BIND @@ -164,7 +164,7 @@

-General DNS Reference Information

+General DNS Reference Information

IPv6 addresses (AAAA)

@@ -252,17 +252,17 @@

-Bibliography

+Bibliography

Standards

-

[RFC974] C. Partridge. Mail Routing and the Domain System. January 1986.

+

[RFC974] C. Partridge. Mail Routing and the Domain System. January 1986.

-

[RFC1034] P.V. Mockapetris. Domain Names — Concepts and Facilities. November 1987.

+

[RFC1034] P.V. Mockapetris. Domain Names — Concepts and Facilities. November 1987.

-

[RFC1035] P. V. Mockapetris. Domain Names — Implementation and +

[RFC1035] P. V. Mockapetris. Domain Names — Implementation and Specification. November 1987.

@@ -270,42 +270,42 @@

Proposed Standards

-

[RFC2181] R., R. Bush Elz. Clarifications to the DNS +

[RFC2181] R., R. Bush Elz. Clarifications to the DNS Specification. July 1997.

-

[RFC2308] M. Andrews. Negative Caching of DNS +

[RFC2308] M. Andrews. Negative Caching of DNS Queries. March 1998.

-

[RFC1995] M. Ohta. Incremental Zone Transfer in DNS. August 1996.

+

[RFC1995] M. Ohta. Incremental Zone Transfer in DNS. August 1996.

-

[RFC1996] P. Vixie. A Mechanism for Prompt Notification of Zone Changes. August 1996.

+

[RFC1996] P. Vixie. A Mechanism for Prompt Notification of Zone Changes. August 1996.

-

[RFC2136] P. Vixie, S. Thomson, Y. Rekhter, and J. Bound. Dynamic Updates in the Domain Name System. April 1997.

+

[RFC2136] P. Vixie, S. Thomson, Y. Rekhter, and J. Bound. Dynamic Updates in the Domain Name System. April 1997.

-

[RFC2671] P. Vixie. Extension Mechanisms for DNS (EDNS0). August 1997.

+

[RFC2671] P. Vixie. Extension Mechanisms for DNS (EDNS0). August 1997.

-

[RFC2672] M. Crawford. Non-Terminal DNS Name Redirection. August 1999.

+

[RFC2672] M. Crawford. Non-Terminal DNS Name Redirection. August 1999.

-

[RFC2845] P. Vixie, O. Gudmundsson, D. Eastlake, 3rd, and B. Wellington. Secret Key Transaction Authentication for DNS (TSIG). May 2000.

+

[RFC2845] P. Vixie, O. Gudmundsson, D. Eastlake, 3rd, and B. Wellington. Secret Key Transaction Authentication for DNS (TSIG). May 2000.

-

[RFC2930] D. Eastlake, 3rd. Secret Key Establishment for DNS (TKEY RR). September 2000.

+

[RFC2930] D. Eastlake, 3rd. Secret Key Establishment for DNS (TKEY RR). September 2000.

-

[RFC2931] D. Eastlake, 3rd. DNS Request and Transaction Signatures (SIG(0)s). September 2000.

+

[RFC2931] D. Eastlake, 3rd. DNS Request and Transaction Signatures (SIG(0)s). September 2000.

-

[RFC3007] B. Wellington. Secure Domain Name System (DNS) Dynamic Update. November 2000.

+

[RFC3007] B. Wellington. Secure Domain Name System (DNS) Dynamic Update. November 2000.

-

[RFC3645] S. Kwan, P. Garg, J. Gilroy, L. Esibov, J. Westhead, and R. Hall. Generic Security Service Algorithm for Secret +

[RFC3645] S. Kwan, P. Garg, J. Gilroy, L. Esibov, J. Westhead, and R. Hall. Generic Security Service Algorithm for Secret Key Transaction Authentication for DNS (GSS-TSIG). October 2003.

@@ -314,19 +314,19 @@

DNS Security Proposed Standards

-

[RFC3225] D. Conrad. Indicating Resolver Support of DNSSEC. December 2001.

+

[RFC3225] D. Conrad. Indicating Resolver Support of DNSSEC. December 2001.

-

[RFC3833] D. Atkins and R. Austein. Threat Analysis of the Domain Name System (DNS). August 2004.

+

[RFC3833] D. Atkins and R. Austein. Threat Analysis of the Domain Name System (DNS). August 2004.

-

[RFC4033] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. DNS Security Introduction and Requirements. March 2005.

+

[RFC4033] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. DNS Security Introduction and Requirements. March 2005.

-

[RFC4044] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. Resource Records for the DNS Security Extensions. March 2005.

+

[RFC4044] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. Resource Records for the DNS Security Extensions. March 2005.

-

[RFC4035] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. Protocol Modifications for the DNS +

[RFC4035] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. Protocol Modifications for the DNS Security Extensions. March 2005.

@@ -334,146 +334,146 @@

Other Important RFCs About DNS Implementation

-

[RFC1535] E. Gavron. A Security Problem and Proposed Correction With Widely +

[RFC1535] E. Gavron. A Security Problem and Proposed Correction With Widely Deployed DNS Software.. October 1993.

-

[RFC1536] A. Kumar, J. Postel, C. Neuman, P. Danzig, and S. Miller. Common DNS Implementation +

[RFC1536] A. Kumar, J. Postel, C. Neuman, P. Danzig, and S. Miller. Common DNS Implementation Errors and Suggested Fixes. October 1993.

-

[RFC1982] R. Elz and R. Bush. Serial Number Arithmetic. August 1996.

+

[RFC1982] R. Elz and R. Bush. Serial Number Arithmetic. August 1996.

-

[RFC4074] Y. Morishita and T. Jinmei. Common Misbehaviour Against DNS +

[RFC4074] Y. Morishita and T. Jinmei. Common Misbehaviour Against DNS Queries for IPv6 Addresses. May 2005.

Resource Record Types

-

[RFC1183] C.F. Everhart, L. A. Mamakos, R. Ullmann, and P. Mockapetris. New DNS RR Definitions. October 1990.

+

[RFC1183] C.F. Everhart, L. A. Mamakos, R. Ullmann, and P. Mockapetris. New DNS RR Definitions. October 1990.

-

[RFC1706] B. Manning and R. Colella. DNS NSAP Resource Records. October 1994.

+

[RFC1706] B. Manning and R. Colella. DNS NSAP Resource Records. October 1994.

-

[RFC2168] R. Daniel and M. Mealling. Resolution of Uniform Resource Identifiers using +

[RFC2168] R. Daniel and M. Mealling. Resolution of Uniform Resource Identifiers using the Domain Name System. June 1997.

-

[RFC1876] C. Davis, P. Vixie, T., and I. Dickinson. A Means for Expressing Location Information in the +

[RFC1876] C. Davis, P. Vixie, T., and I. Dickinson. A Means for Expressing Location Information in the Domain Name System. January 1996.

-

[RFC2052] A. Gulbrandsen and P. Vixie. A DNS RR for Specifying the +

[RFC2052] A. Gulbrandsen and P. Vixie. A DNS RR for Specifying the Location of Services.. October 1996.

-

[RFC2163] A. Allocchio. Using the Internet DNS to +

[RFC2163] A. Allocchio. Using the Internet DNS to Distribute MIXER Conformant Global Address Mapping. January 1998.

-

[RFC2230] R. Atkinson. Key Exchange Delegation Record for the DNS. October 1997.

+

[RFC2230] R. Atkinson. Key Exchange Delegation Record for the DNS. October 1997.

-

[RFC2536] D. Eastlake, 3rd. DSA KEYs and SIGs in the Domain Name System (DNS). March 1999.

+

[RFC2536] D. Eastlake, 3rd. DSA KEYs and SIGs in the Domain Name System (DNS). March 1999.

-

[RFC2537] D. Eastlake, 3rd. RSA/MD5 KEYs and SIGs in the Domain Name System (DNS). March 1999.

+

[RFC2537] D. Eastlake, 3rd. RSA/MD5 KEYs and SIGs in the Domain Name System (DNS). March 1999.

-

[RFC2538] D. Eastlake, 3rd and O. Gudmundsson. Storing Certificates in the Domain Name System (DNS). March 1999.

+

[RFC2538] D. Eastlake, 3rd and O. Gudmundsson. Storing Certificates in the Domain Name System (DNS). March 1999.

-

[RFC2539] D. Eastlake, 3rd. Storage of Diffie-Hellman Keys in the Domain Name System (DNS). March 1999.

+

[RFC2539] D. Eastlake, 3rd. Storage of Diffie-Hellman Keys in the Domain Name System (DNS). March 1999.

-

[RFC2540] D. Eastlake, 3rd. Detached Domain Name System (DNS) Information. March 1999.

+

[RFC2540] D. Eastlake, 3rd. Detached Domain Name System (DNS) Information. March 1999.

-

[RFC2782] A. Gulbrandsen. P. Vixie. L. Esibov. A DNS RR for specifying the location of services (DNS SRV). February 2000.

+

[RFC2782] A. Gulbrandsen. P. Vixie. L. Esibov. A DNS RR for specifying the location of services (DNS SRV). February 2000.

-

[RFC2915] M. Mealling. R. Daniel. The Naming Authority Pointer (NAPTR) DNS Resource Record. September 2000.

+

[RFC2915] M. Mealling. R. Daniel. The Naming Authority Pointer (NAPTR) DNS Resource Record. September 2000.

-

[RFC3110] D. Eastlake, 3rd. RSA/SHA-1 SIGs and RSA KEYs in the Domain Name System (DNS). May 2001.

+

[RFC3110] D. Eastlake, 3rd. RSA/SHA-1 SIGs and RSA KEYs in the Domain Name System (DNS). May 2001.

-

[RFC3123] P. Koch. A DNS RR Type for Lists of Address Prefixes (APL RR). June 2001.

+

[RFC3123] P. Koch. A DNS RR Type for Lists of Address Prefixes (APL RR). June 2001.

-

[RFC3596] S. Thomson, C. Huitema, V. Ksinant, and M. Souissi. DNS Extensions to support IP +

[RFC3596] S. Thomson, C. Huitema, V. Ksinant, and M. Souissi. DNS Extensions to support IP version 6. October 2003.

-

[RFC3597] A. Gustafsson. Handling of Unknown DNS Resource Record (RR) Types. September 2003.

+

[RFC3597] A. Gustafsson. Handling of Unknown DNS Resource Record (RR) Types. September 2003.

DNS and the Internet

-

[RFC1101] P. V. Mockapetris. DNS Encoding of Network Names +

[RFC1101] P. V. Mockapetris. DNS Encoding of Network Names and Other Types. April 1989.

-

[RFC1123] Braden. Requirements for Internet Hosts - Application and +

[RFC1123] Braden. Requirements for Internet Hosts - Application and Support. October 1989.

-

[RFC1591] J. Postel. Domain Name System Structure and Delegation. March 1994.

+

[RFC1591] J. Postel. Domain Name System Structure and Delegation. March 1994.

-

[RFC2317] H. Eidnes, G. de Groot, and P. Vixie. Classless IN-ADDR.ARPA Delegation. March 1998.

+

[RFC2317] H. Eidnes, G. de Groot, and P. Vixie. Classless IN-ADDR.ARPA Delegation. March 1998.

-

[RFC2826] Internet Architecture Board. IAB Technical Comment on the Unique DNS Root. May 2000.

+

[RFC2826] Internet Architecture Board. IAB Technical Comment on the Unique DNS Root. May 2000.

-

[RFC2929] D. Eastlake, 3rd, E. Brunner-Williams, and B. Manning. Domain Name System (DNS) IANA Considerations. September 2000.

+

[RFC2929] D. Eastlake, 3rd, E. Brunner-Williams, and B. Manning. Domain Name System (DNS) IANA Considerations. September 2000.

DNS Operations

-

[RFC1033] M. Lottor. Domain administrators operations guide.. November 1987.

+

[RFC1033] M. Lottor. Domain administrators operations guide.. November 1987.

-

[RFC1537] P. Beertema. Common DNS Data File +

[RFC1537] P. Beertema. Common DNS Data File Configuration Errors. October 1993.

-

[RFC1912] D. Barr. Common DNS Operational and +

[RFC1912] D. Barr. Common DNS Operational and Configuration Errors. February 1996.

-

[RFC2010] B. Manning and P. Vixie. Operational Criteria for Root Name Servers.. October 1996.

+

[RFC2010] B. Manning and P. Vixie. Operational Criteria for Root Name Servers.. October 1996.

-

[RFC2219] M. Hamilton and R. Wright. Use of DNS Aliases for +

[RFC2219] M. Hamilton and R. Wright. Use of DNS Aliases for Network Services.. October 1997.

Internationalized Domain Names

-

[RFC2825] IAB and R. Daigle. A Tangled Web: Issues of I18N, Domain Names, +

[RFC2825] IAB and R. Daigle. A Tangled Web: Issues of I18N, Domain Names, and the Other Internet protocols. May 2000.

-

[RFC3490] P. Faltstrom, P. Hoffman, and A. Costello. Internationalizing Domain Names in Applications (IDNA). March 2003.

+

[RFC3490] P. Faltstrom, P. Hoffman, and A. Costello. Internationalizing Domain Names in Applications (IDNA). March 2003.

-

[RFC3491] P. Hoffman and M. Blanchet. Nameprep: A Stringprep Profile for Internationalized Domain Names. March 2003.

+

[RFC3491] P. Hoffman and M. Blanchet. Nameprep: A Stringprep Profile for Internationalized Domain Names. March 2003.

-

[RFC3492] A. Costello. Punycode: A Bootstring encoding of Unicode +

[RFC3492] A. Costello. Punycode: A Bootstring encoding of Unicode for Internationalized Domain Names in Applications (IDNA). March 2003.

@@ -489,47 +489,47 @@

-

[RFC1464] R. Rosenbaum. Using the Domain Name System To Store Arbitrary String +

[RFC1464] R. Rosenbaum. Using the Domain Name System To Store Arbitrary String Attributes. May 1993.

-

[RFC1713] A. Romao. Tools for DNS Debugging. November 1994.

+

[RFC1713] A. Romao. Tools for DNS Debugging. November 1994.

-

[RFC1794] T. Brisco. DNS Support for Load +

[RFC1794] T. Brisco. DNS Support for Load Balancing. April 1995.

-

[RFC2240] O. Vaughan. A Legal Basis for Domain Name Allocation. November 1997.

+

[RFC2240] O. Vaughan. A Legal Basis for Domain Name Allocation. November 1997.

-

[RFC2345] J. Klensin, T. Wolf, and G. Oglesby. Domain Names and Company Name Retrieval. May 1998.

+

[RFC2345] J. Klensin, T. Wolf, and G. Oglesby. Domain Names and Company Name Retrieval. May 1998.

-

[RFC2352] O. Vaughan. A Convention For Using Legal Names as Domain Names. May 1998.

+

[RFC2352] O. Vaughan. A Convention For Using Legal Names as Domain Names. May 1998.

-

[RFC3071] J. Klensin. Reflections on the DNS, RFC 1591, and Categories of Domains. February 2001.

+

[RFC3071] J. Klensin. Reflections on the DNS, RFC 1591, and Categories of Domains. February 2001.

-

[RFC3258] T. Hardie. Distributing Authoritative Name Servers via +

[RFC3258] T. Hardie. Distributing Authoritative Name Servers via Shared Unicast Addresses. April 2002.

-

[RFC3901] A. Durand and J. Ihren. DNS IPv6 Transport Operational Guidelines. September 2004.

+

[RFC3901] A. Durand and J. Ihren. DNS IPv6 Transport Operational Guidelines. September 2004.

Obsolete and Unimplemented Experimental RFC

-

[RFC1712] C. Farrell, M. Schulze, S. Pleitner, and D. Baldoni. DNS Encoding of Geographical +

[RFC1712] C. Farrell, M. Schulze, S. Pleitner, and D. Baldoni. DNS Encoding of Geographical Location. November 1994.

-

[RFC2673] M. Crawford. Binary Labels in the Domain Name System. August 1999.

+

[RFC2673] M. Crawford. Binary Labels in the Domain Name System. August 1999.

-

[RFC2874] M. Crawford and C. Huitema. DNS Extensions to Support IPv6 Address Aggregation +

[RFC2874] M. Crawford and C. Huitema. DNS Extensions to Support IPv6 Address Aggregation and Renumbering. July 2000.

@@ -543,39 +543,39 @@

-

[RFC2065] D. Eastlake, 3rd and C. Kaufman. Domain Name System Security Extensions. January 1997.

+

[RFC2065] D. Eastlake, 3rd and C. Kaufman. Domain Name System Security Extensions. January 1997.

-

[RFC2137] D. Eastlake, 3rd. Secure Domain Name System Dynamic Update. April 1997.

+

[RFC2137] D. Eastlake, 3rd. Secure Domain Name System Dynamic Update. April 1997.

-

[RFC2535] D. Eastlake, 3rd. Domain Name System Security Extensions. March 1999.

+

[RFC2535] D. Eastlake, 3rd. Domain Name System Security Extensions. March 1999.

-

[RFC3008] B. Wellington. Domain Name System Security (DNSSEC) +

[RFC3008] B. Wellington. Domain Name System Security (DNSSEC) Signing Authority. November 2000.

-

[RFC3090] E. Lewis. DNS Security Extension Clarification on Zone Status. March 2001.

+

[RFC3090] E. Lewis. DNS Security Extension Clarification on Zone Status. March 2001.

-

[RFC3445] D. Massey and S. Rose. Limiting the Scope of the KEY Resource Record (RR). December 2002.

+

[RFC3445] D. Massey and S. Rose. Limiting the Scope of the KEY Resource Record (RR). December 2002.

-

[RFC3655] B. Wellington and O. Gudmundsson. Redefinition of DNS Authenticated Data (AD) bit. November 2003.

+

[RFC3655] B. Wellington and O. Gudmundsson. Redefinition of DNS Authenticated Data (AD) bit. November 2003.

-

[RFC3658] O. Gudmundsson. Delegation Signer (DS) Resource Record (RR). December 2003.

+

[RFC3658] O. Gudmundsson. Delegation Signer (DS) Resource Record (RR). December 2003.

-

[RFC3755] S. Weiler. Legacy Resolver Compatibility for Delegation Signer (DS). May 2004.

+

[RFC3755] S. Weiler. Legacy Resolver Compatibility for Delegation Signer (DS). May 2004.

-

[RFC3757] O. Kolkman, J. Schlyter, and E. Lewis. Domain Name System KEY (DNSKEY) Resource Record +

[RFC3757] O. Kolkman, J. Schlyter, and E. Lewis. Domain Name System KEY (DNSKEY) Resource Record (RR) Secure Entry Point (SEP) Flag. April 2004.

-

[RFC3845] J. Schlyter. DNS Security (DNSSEC) NextSECure (NSEC) RDATA Format. August 2004.

+

[RFC3845] J. Schlyter. DNS Security (DNSSEC) NextSECure (NSEC) RDATA Format. August 2004.

@@ -596,14 +596,14 @@

-Other Documents About BIND +Other Documents About BIND

-Bibliography

+Bibliography
-

Paul Albitz and Cricket Liu. DNS and BIND. Copyright © 1998 Sebastopol, CA: O'Reilly and Associates.

+

Paul Albitz and Cricket Liu. DNS and BIND. Copyright © 1998 Sebastopol, CA: O'Reilly and Associates.

diff --git a/doc/arm/Bv9ARM.html b/doc/arm/Bv9ARM.html index 5f7a1eb9cd..5806f0edc0 100644 --- a/doc/arm/Bv9ARM.html +++ b/doc/arm/Bv9ARM.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -154,61 +154,61 @@
options Statement Definition and Usage
statistics-channels Statement Grammar
-
statistics-channels Statement Definition and +
statistics-channels Statement Definition and Usage
server Statement Grammar
server Statement Definition and Usage
-
trusted-keys Statement Grammar
-
trusted-keys Statement Definition +
trusted-keys Statement Grammar
+
trusted-keys Statement Definition and Usage
view Statement Grammar
-
view Statement Definition and Usage
+
view Statement Definition and Usage
zone Statement Grammar
-
zone Statement Definition and Usage
+
zone Statement Definition and Usage
-
Zone File
+
Zone File
Types of Resource Records and When to Use Them
-
Discussion of MX Records
+
Discussion of MX Records
Setting TTLs
-
Inverse Mapping in IPv4
-
Other Zone File Directives
-
BIND Master File Extension: the $GENERATE Directive
+
Inverse Mapping in IPv4
+
Other Zone File Directives
+
BIND Master File Extension: the $GENERATE Directive
Additional File Formats
-
BIND9 Statistics
-
Statistics Counters
+
BIND9 Statistics
+
Statistics Counters
7. BIND 9 Security Considerations
Access Control Lists
-
Chroot and Setuid
+
Chroot and Setuid
-
The chroot Environment
-
Using the setuid Function
+
The chroot Environment
+
Using the setuid Function
Dynamic Update Security
8. Troubleshooting
-
Common Problems
-
It's not working; how can I figure out what's wrong?
-
Incrementing and Changing the Serial Number
-
Where Can I Get Help?
+
Common Problems
+
It's not working; how can I figure out what's wrong?
+
Incrementing and Changing the Serial Number
+
Where Can I Get Help?
A. Appendices
-
Acknowledgments
+
Acknowledgments
A Brief History of the DNS and BIND
-
General DNS Reference Information
+
General DNS Reference Information
IPv6 addresses (AAAA)
Bibliography (and Suggested Reading)
Request for Comments (RFCs)
Internet Drafts
-
Other Documents About BIND
+
Other Documents About BIND
I. Manual pages
diff --git a/doc/arm/man.dig.html b/doc/arm/man.dig.html index 7762030191..769c6e0a94 100644 --- a/doc/arm/man.dig.html +++ b/doc/arm/man.dig.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -52,7 +52,7 @@

dig [global-queryopt...] [query...]

-

DESCRIPTION

+

DESCRIPTION

dig (domain information groper) is a flexible tool for interrogating DNS name servers. It performs DNS lookups and @@ -98,7 +98,7 @@

-

SIMPLE USAGE

+

SIMPLE USAGE

A typical invocation of dig looks like:

@@ -144,7 +144,7 @@

-

OPTIONS

+

OPTIONS

The -b option sets the source IP address of the query to address. This must be a valid @@ -244,7 +244,7 @@

-

QUERY OPTIONS

+

QUERY OPTIONS

dig provides a number of query options which affect the way in which lookups are made and the results displayed. Some of @@ -563,7 +563,7 @@

-

MULTIPLE QUERIES

+

MULTIPLE QUERIES

The BIND 9 implementation of dig supports @@ -609,7 +609,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

IDN SUPPORT

+

IDN SUPPORT

If dig has been built with IDN (internationalized domain name) support, it can accept and display non-ASCII domain names. @@ -623,14 +623,14 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

FILES

+

FILES

/etc/resolv.conf

${HOME}/.digrc

-

SEE ALSO

+

SEE ALSO

host(1), named(8), dnssec-keygen(8), @@ -638,7 +638,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

BUGS

+

BUGS

There are probably too many query options.

diff --git a/doc/arm/man.dnssec-keyfromlabel.html b/doc/arm/man.dnssec-keyfromlabel.html index a9bc795081..7bd379a4f3 100644 --- a/doc/arm/man.dnssec-keyfromlabel.html +++ b/doc/arm/man.dnssec-keyfromlabel.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

dnssec-keyfromlabel {-a algorithm} {-l label} [-c class] [-f flag] [-k] [-n nametype] [-p protocol] [-t type] [-v level] {name}

-

DESCRIPTION

+

DESCRIPTION

dnssec-keyfromlabel gets keys with the given label from a crypto hardware and builds key files for DNSSEC (Secure DNS), as defined in RFC 2535 @@ -58,7 +58,7 @@

-

OPTIONS

+

OPTIONS

-a algorithm
@@ -131,7 +131,7 @@
-

GENERATED KEY FILES

+

GENERATED KEY FILES

When dnssec-keyfromlabel completes successfully, @@ -172,7 +172,7 @@

-

SEE ALSO

+

SEE ALSO

dnssec-keygen(8), dnssec-signzone(8), BIND 9 Administrator Reference Manual, @@ -182,7 +182,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.dnssec-keygen.html b/doc/arm/man.dnssec-keygen.html index 723c98cb92..2d03664656 100644 --- a/doc/arm/man.dnssec-keygen.html +++ b/doc/arm/man.dnssec-keygen.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

dnssec-keygen {-a algorithm} {-b keysize} {-n nametype} [-c class] [-e] [-f flag] [-g generator] [-h] [-k] [-p protocol] [-r randomdev] [-s strength] [-t type] [-v level] {name}

-

DESCRIPTION

+

DESCRIPTION

dnssec-keygen generates keys for DNSSEC (Secure DNS), as defined in RFC 2535 and RFC 4034. It can also generate keys for use with @@ -58,7 +58,7 @@

-

OPTIONS

+

OPTIONS

-a algorithm
@@ -166,7 +166,7 @@
-

GENERATED KEYS

+

GENERATED KEYS

When dnssec-keygen completes successfully, @@ -212,7 +212,7 @@

-

EXAMPLE

+

EXAMPLE

To generate a 768-bit DSA key for the domain example.com, the following command would be @@ -233,7 +233,7 @@

-

SEE ALSO

+

SEE ALSO

dnssec-signzone(8), BIND 9 Administrator Reference Manual, RFC 2535, @@ -242,7 +242,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.dnssec-signzone.html b/doc/arm/man.dnssec-signzone.html index e5f4f6628d..200cc8d706 100644 --- a/doc/arm/man.dnssec-signzone.html +++ b/doc/arm/man.dnssec-signzone.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

dnssec-signzone [-a] [-c class] [-d directory] [-e end-time] [-f output-file] [-g] [-h] [-k key] [-l domain] [-i interval] [-I input-format] [-j jitter] [-N soa-serial-format] [-o origin] [-O output-format] [-p] [-r randomdev] [-s start-time] [-t] [-v level] [-z] {zonefile} [key...]

-

DESCRIPTION

+

DESCRIPTION

dnssec-signzone signs a zone. It generates NSEC and RRSIG records and produces a signed version of the @@ -61,7 +61,7 @@

-

OPTIONS

+

OPTIONS

-a

@@ -259,7 +259,7 @@

-

EXAMPLE

+

EXAMPLE

The following command signs the example.com zone with the DSA key generated by dnssec-keygen @@ -288,14 +288,14 @@ db.example.com.signed %

-

SEE ALSO

+

SEE ALSO

dnssec-keygen(8), BIND 9 Administrator Reference Manual, RFC 2535.

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.host.html b/doc/arm/man.host.html index 81d49280c0..0c445e60d7 100644 --- a/doc/arm/man.host.html +++ b/doc/arm/man.host.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

host [-aCdlnrsTwv] [-c class] [-N ndots] [-R number] [-t type] [-W wait] [-m flag] [-4] [-6] {name} [server]

-

DESCRIPTION

+

DESCRIPTION

host is a simple utility for performing DNS lookups. It is normally used to convert names to IP addresses and vice versa. @@ -202,7 +202,7 @@

-

IDN SUPPORT

+

IDN SUPPORT

If host has been built with IDN (internationalized domain name) support, it can accept and display non-ASCII domain names. @@ -216,12 +216,12 @@

-

FILES

+

FILES

/etc/resolv.conf

-

SEE ALSO

+

SEE ALSO

dig(1), named(8).

diff --git a/doc/arm/man.named-checkconf.html b/doc/arm/man.named-checkconf.html index 00fcac3527..f7619ca3bf 100644 --- a/doc/arm/man.named-checkconf.html +++ b/doc/arm/man.named-checkconf.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,14 +50,14 @@

named-checkconf [-h] [-v] [-j] [-t directory] {filename} [-z]

-

DESCRIPTION

+

DESCRIPTION

named-checkconf checks the syntax, but not the semantics, of a named configuration file.

-

OPTIONS

+

OPTIONS

-h

@@ -92,21 +92,21 @@

-

RETURN VALUES

+

RETURN VALUES

named-checkconf returns an exit status of 1 if errors were detected and 0 otherwise.

-

SEE ALSO

+

SEE ALSO

named(8), named-checkzone(8), BIND 9 Administrator Reference Manual.

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.named-checkzone.html b/doc/arm/man.named-checkzone.html index 25fc839f37..265be7d132 100644 --- a/doc/arm/man.named-checkzone.html +++ b/doc/arm/man.named-checkzone.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -51,7 +51,7 @@

named-compilezone [-d] [-j] [-q] [-v] [-c class] [-C mode] [-f format] [-F format] [-i mode] [-k mode] [-m mode] [-n mode] [-o filename] [-s style] [-t directory] [-w directory] [-D] [-W mode] {zonename} {filename}

-

DESCRIPTION

+

DESCRIPTION

named-checkzone checks the syntax and integrity of a zone file. It performs the same checks as named does when loading a @@ -71,7 +71,7 @@

-

OPTIONS

+

OPTIONS

-d

@@ -257,14 +257,14 @@

-

RETURN VALUES

+

RETURN VALUES

named-checkzone returns an exit status of 1 if errors were detected and 0 otherwise.

-

SEE ALSO

+

SEE ALSO

named(8), named-checkconf(8), RFC 1035, @@ -272,7 +272,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.named.html b/doc/arm/man.named.html index b790eab065..78ca9f584a 100644 --- a/doc/arm/man.named.html +++ b/doc/arm/man.named.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

named [-4] [-6] [-c config-file] [-d debug-level] [-f] [-g] [-m flag] [-n #cpus] [-p port] [-s] [-t directory] [-u user] [-v] [-x cache-file]

-

DESCRIPTION

+

DESCRIPTION

named is a Domain Name System (DNS) server, part of the BIND 9 distribution from ISC. For more @@ -65,7 +65,7 @@

-

OPTIONS

+

OPTIONS

-4

@@ -209,7 +209,7 @@

-

SIGNALS

+

SIGNALS

In routine operation, signals should not be used to control the nameserver; rndc should be used @@ -230,7 +230,7 @@

-

CONFIGURATION

+

CONFIGURATION

The named configuration file is too complex to describe in detail here. A complete description is provided @@ -239,7 +239,7 @@

-

FILES

+

FILES

/etc/named.conf

@@ -252,7 +252,7 @@

-

SEE ALSO

+

SEE ALSO

RFC 1033, RFC 1034, RFC 1035, @@ -265,7 +265,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.rndc-confgen.html b/doc/arm/man.rndc-confgen.html index 57d754804b..6437f79210 100644 --- a/doc/arm/man.rndc-confgen.html +++ b/doc/arm/man.rndc-confgen.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -48,7 +48,7 @@

rndc-confgen [-a] [-b keysize] [-c keyfile] [-h] [-k keyname] [-p port] [-r randomfile] [-s address] [-t chrootdir] [-u user]

-

DESCRIPTION

+

DESCRIPTION

rndc-confgen generates configuration files for rndc. It can be used as a @@ -64,7 +64,7 @@

-

OPTIONS

+

OPTIONS

-a
@@ -171,7 +171,7 @@
-

EXAMPLES

+

EXAMPLES

To allow rndc to be used with no manual configuration, run @@ -188,7 +188,7 @@

-

SEE ALSO

+

SEE ALSO

rndc(8), rndc.conf(5), named(8), @@ -196,7 +196,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.rndc.conf.html b/doc/arm/man.rndc.conf.html index 66197d6b56..6f38883b62 100644 --- a/doc/arm/man.rndc.conf.html +++ b/doc/arm/man.rndc.conf.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

rndc.conf

-

DESCRIPTION

+

DESCRIPTION

rndc.conf is the configuration file for rndc, the BIND 9 name server control utility. This file has a similar structure and syntax to @@ -135,7 +135,7 @@

-

EXAMPLE

+

EXAMPLE

       options {
         default-server  localhost;
@@ -209,7 +209,7 @@
     

-

NAME SERVER CONFIGURATION

+

NAME SERVER CONFIGURATION

The name server must be configured to accept rndc connections and to recognize the key specified in the rndc.conf @@ -219,7 +219,7 @@

-

SEE ALSO

+

SEE ALSO

rndc(8), rndc-confgen(8), mmencode(1), @@ -227,7 +227,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.rndc.html b/doc/arm/man.rndc.html index cec279763b..0b970bf649 100644 --- a/doc/arm/man.rndc.html +++ b/doc/arm/man.rndc.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

rndc [-b source-address] [-c config-file] [-k key-file] [-s server] [-p port] [-V] [-y key_id] {command}

-

DESCRIPTION

+

DESCRIPTION

rndc controls the operation of a name server. It supersedes the ndc utility @@ -79,7 +79,7 @@

-

OPTIONS

+

OPTIONS

-b source-address

@@ -151,7 +151,7 @@

-

LIMITATIONS

+

LIMITATIONS

rndc does not yet support all the commands of the BIND 8 ndc utility. @@ -165,7 +165,7 @@

-

SEE ALSO

+

SEE ALSO

rndc.conf(5), rndc-confgen(8), named(8), @@ -175,7 +175,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

From 816496b22114ee7c2c15321c2c6cc4be77fdf822 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Fri, 2 May 2008 04:40:12 +0000 Subject: [PATCH 049/137] 2366. [bug] Adb shutdown race. [RT #18021] --- CHANGES | 2 ++ lib/dns/adb.c | 6 ++++-- 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/CHANGES b/CHANGES index d5e70ec3be..8fb987754b 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,5 @@ +2366. [bug] Adb shutdown race. [RT #18021] + 2365. [bug] Fix a bug that caused dns_acl_isany() to return spurious results. [RT #18000] diff --git a/lib/dns/adb.c b/lib/dns/adb.c index 320b7264a8..893a7dea24 100644 --- a/lib/dns/adb.c +++ b/lib/dns/adb.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: adb.c,v 1.239 2008/05/01 18:23:07 jinmei Exp $ */ +/* $Id: adb.c,v 1.240 2008/05/02 04:40:12 marka Exp $ */ /*! \file * @@ -1234,7 +1234,7 @@ dec_entry_refcnt(dns_adb_t *adb, dns_adbentry_t *entry, isc_boolean_t lock) { free_adbentry(adb, &entry); if (result) - result =dec_adb_irefcnt(adb); + result = dec_adb_irefcnt(adb); return (result); } @@ -1772,6 +1772,8 @@ shutdown_task(isc_task_t *task, isc_event_t *ev) { INSIST(DNS_ADB_VALID(adb)); isc_event_free(&ev); + LOCK(&adb->lock); + UNLOCK(&adb->lock); destroy(adb); } From 3e358ada3e2645bb674a6639d286d5fed20e8413 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Sat, 3 May 2008 04:21:58 +0000 Subject: [PATCH 050/137] new draft --- ...draft-ietf-dnsext-rfc2672bis-dname-13.txt} | 608 ++++++++++-------- 1 file changed, 332 insertions(+), 276 deletions(-) rename doc/draft/{draft-ietf-dnsext-rfc2672bis-dname-09.txt => draft-ietf-dnsext-rfc2672bis-dname-13.txt} (70%) diff --git a/doc/draft/draft-ietf-dnsext-rfc2672bis-dname-09.txt b/doc/draft/draft-ietf-dnsext-rfc2672bis-dname-13.txt similarity index 70% rename from doc/draft/draft-ietf-dnsext-rfc2672bis-dname-09.txt rename to doc/draft/draft-ietf-dnsext-rfc2672bis-dname-13.txt index 9104c3859d..13195bb4a2 100644 --- a/doc/draft/draft-ietf-dnsext-rfc2672bis-dname-09.txt +++ b/doc/draft/draft-ietf-dnsext-rfc2672bis-dname-13.txt @@ -3,14 +3,15 @@ DNS Extensions Working Group S. Rose Internet-Draft NIST -Updates: 2672,3363,4294 W. Wijngaards -(if approved) NLnet Labs -Intended status: Standards Track February 5, 2008 -Expires: August 8, 2008 +Obsoletes: 2672 (if approved) W. Wijngaards +Updates: 3363,4294 NLnet Labs +(if approved) May 2, 2008 +Intended status: Standards Track +Expires: November 3, 2008 Update to DNAME Redirection in the DNS - draft-ietf-dnsext-rfc2672bis-dname-09 + draft-ietf-dnsext-rfc2672bis-dname-13 Status of This Memo @@ -35,7 +36,7 @@ Status of This Memo The list of Internet-Draft Shadow Directories can be accessed at http://www.ietf.org/shadow.html. - This Internet-Draft will expire on August 8, 2008. + This Internet-Draft will expire on November 3, 2008. Copyright Notice @@ -46,15 +47,14 @@ Abstract The DNAME record provides redirection for a sub-tree of the domain name tree in the DNS system. That is, all names that end with a particular suffix are redirected to another part of the DNS. This is - an update to the original specification in RFC 2672, also aligning + an update of the original specification in RFC 2672, also aligning RFC 3363 and RFC 4294 with this revision. - -Rose & Wijngaards Expires August 8, 2008 [Page 1] +Rose & Wijngaards Expires November 3, 2008 [Page 1] -Internet-Draft DNAME Redirection February 2008 +Internet-Draft DNAME Redirection May 2008 Requirements Language @@ -71,52 +71,61 @@ Table of Contents 2.1. Format . . . . . . . . . . . . . . . . . . . . . . . . . . 3 2.2. The DNAME Substitution . . . . . . . . . . . . . . . . . . 4 2.3. DNAME Apex not Redirected itself . . . . . . . . . . . . . 5 - 2.4. Names Next to and Below a DNAME Record . . . . . . . . . . 5 + 2.4. Names Next to and Below a DNAME Record . . . . . . . . . . 6 2.5. Compression of the DNAME record. . . . . . . . . . . . . . 6 - 3. Processing . . . . . . . . . . . . . . . . . . . . . . . . . . 6 - 3.1. Wildcards . . . . . . . . . . . . . . . . . . . . . . . . 6 - 3.2. CNAME synthesis . . . . . . . . . . . . . . . . . . . . . 7 - 3.3. Acceptance and Intermediate Storage . . . . . . . . . . . 7 - 3.4. Server algorithm . . . . . . . . . . . . . . . . . . . . . 8 + 3. Processing . . . . . . . . . . . . . . . . . . . . . . . . . . 7 + 3.1. CNAME synthesis and UD bit . . . . . . . . . . . . . . . . 7 + 3.2. Server algorithm . . . . . . . . . . . . . . . . . . . . . 8 + 3.3. Wildcards . . . . . . . . . . . . . . . . . . . . . . . . 9 + 3.4. Acceptance and Intermediate Storage . . . . . . . . . . . 10 4. DNAME Discussions in Other Documents . . . . . . . . . . . . . 10 - 5. Other Issues with DNAME . . . . . . . . . . . . . . . . . . . 11 - 5.1. MX, NS and PTR Records Must Point to Target of DNAME . . . 11 - 5.2. Dynamic Update and DNAME . . . . . . . . . . . . . . . . . 11 + 5. Other Issues with DNAME . . . . . . . . . . . . . . . . . . . 12 + 5.1. Canonical hostnames cannot be below DNAME owners . . . . . 12 + 5.2. Dynamic Update and DNAME . . . . . . . . . . . . . . . . . 12 5.3. DNSSEC and DNAME . . . . . . . . . . . . . . . . . . . . . 12 5.3.1. DNAME bit in NSEC type map . . . . . . . . . . . . . . 12 5.3.2. Validators Must Understand DNAME . . . . . . . . . . . 12 - 5.3.2.1. DNAME in Bitmap Causes Invalid Name Error . . . . 12 + 5.3.2.1. DNAME in Bitmap Causes Invalid Name Error . . . . 13 5.3.2.2. Valid Name Error Response Involving DNAME in - Bitmap . . . . . . . . . . . . . . . . . . . . . . 12 - 5.3.2.3. Response With Synthesized CNAME . . . . . . . . . 12 + Bitmap . . . . . . . . . . . . . . . . . . . . . . 13 + 5.3.2.3. Response With Synthesized CNAME . . . . . . . . . 13 - 6. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 13 + 6. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 14 - 7. Security Considerations . . . . . . . . . . . . . . . . . . . 13 + 7. Security Considerations . . . . . . . . . . . . . . . . . . . 14 - 8. Acknowledgments . . . . . . . . . . . . . . . . . . . . . . . 13 + 8. Acknowledgments . . . . . . . . . . . . . . . . . . . . . . . 14 9. References . . . . . . . . . . . . . . . . . . . . . . . . . . 14 9.1. Normative References . . . . . . . . . . . . . . . . . . . 14 - 9.2. Informative References . . . . . . . . . . . . . . . . . . 14 + 9.2. Informative References . . . . . . . . . . . . . . . . . . 15 -Rose & Wijngaards Expires August 8, 2008 [Page 2] +Rose & Wijngaards Expires November 3, 2008 [Page 2] -Internet-Draft DNAME Redirection February 2008 +Internet-Draft DNAME Redirection May 2008 1. Introduction - DNAME is a DNS Resource Record type. DNAME provides redirection from - a part of the DNS name tree to another part of the DNS name tree. + DNAME is a DNS Resource Record type originally defined in RFC 2672 + [RFC2672]. DNAME provides redirection from a part of the DNS name + tree to another part of the DNS name tree. + + The DNAME RR and the CNAME RR [RFC1034] cause a lookup to + (potentially) return data corresponding to a domain name different + from the queried domain name. The difference between the two + resource records is that the CNAME RR directs the lookup of data at + its owner to another single name, a DNAME RR directs lookups for data + at descendents of its owner's name to corresponding names under a + different (single) node of the tree. Take for example, looking through a zone (see RFC 1034 [RFC1034], section 4.3.2, step 3) for the domain name "foo.example.com" and a @@ -126,27 +135,23 @@ Internet-Draft DNAME Redirection February 2008 "foo.example.net". Had the query name been "www.foo.example.com" the new query name would be "www.foo.example.net". - The DNAME RR is similar to the CNAME RR in that it provides - redirection. The CNAME RR only provides redirection for exactly one - name while the DNAME RR provides redirection for all names in a sub- - tree of the DNS name tree. - - This document is an update to the original specification of DNAME in + This document is an update of the original specification of DNAME in RFC 2672 [RFC2672]. DNAME was conceived to help with the problem of maintaining address-to-name mappings in a context of network renumbering. With a careful set-up, a renumbering event in the network causes no change to the authoritative server that has the address-to-name mappings. Examples in practice are classless reverse - address space delegations and punycode alternates for domain spaces. + address space delegations. Another usage of DNAME lies in redirection of name spaces. For example, a zone administrator may want sub-trees of the DNS to - contain the same information. DNAME is also used for the redirection - of ENUM domains to another maintaining party. + contain the same information. Examples include punycode alternates + for domain spaces. DNAME is also used for the redirection of ENUM + domains to another maintaining party. This update to DNAME does not change the wire format or the handling of DNAME Resource Records by existing software. A new UD (Understand - Dname) bit in the EDNS flags field can be used to signal that CNAME + DNAME) bit in the EDNS flags field can be used to signal that CNAME synthesis is not needed. Discussion is added on problems that may be encountered when using DNAME. @@ -154,45 +159,72 @@ Internet-Draft DNAME Redirection February 2008 2.1. Format - The DNAME RR has mnemonic DNAME and type code 39 (decimal). + The DNAME RR has mnemonic DNAME and type code 39 (decimal). It is + not class-sensitive. - - - - - - -Rose & Wijngaards Expires August 8, 2008 [Page 3] +Rose & Wijngaards Expires November 3, 2008 [Page 3] -Internet-Draft DNAME Redirection February 2008 +Internet-Draft DNAME Redirection May 2008 - The format of the DNAME record has not changed from the original - specification in RFC 2672. DNAME has the following format: + Its RDATA is comprised of a single field, , which contains a + fully qualified domain name that must be sent in uncompressed form + [RFC1035], [RFC3597]. The field MUST be present. The + presentation format of is that of a domain name [RFC1035]. DNAME - The format is not class-sensitive. All fields are required. The - RDATA field target is a domain name. The RDATA field target name - MUST be sent uncompressed [RFC3597]. + The effect of the DNAME RR is the substitution of the record's + for its owner name, as a suffix of a domain name. This + substitution has to be applied for every DNAME RR found in the + resolution process, which allows fairly lengthy valid chains of DNAME + RRs. - The DNAME RR causes type NS additional section processing. + Details of the substitution process, methods to avoid conflicting + resource records, and rules for specific corner cases are given in + the following subsections. 2.2. The DNAME Substitution - DNAMEs cause a name substitution to happen to query names. This is - called the DNAME substitution. The portion of the QNAME ending with - the root label that matches the owner name of the DNAME RR is - replaced with the contents of the DNAME RR's RDATA. The owner name - of the DNAME is not itself redirected, only domain names below the - owner name are redirected. Only whole labels are replaced. A name - is considered below the owner name if it has more labels than the - owner name, and the labels of the owner name appear at the end of the - query name. See the table of examples for common cases and corner + When following RFC 1034 [RFC1034], section 4.3.2's algorithm's third + step, "start matching down, label by label, in the zone" and a node + is found to own a DNAME resource record a DNAME substitution occurs. + The name being sought may be the original query name or a name that + is the result of a CNAME resource record being followed or a + previously encountered DNAME. As is the case of finding a CNAME + resource record or NS resource record set, the processing of a DNAME + will happen prior to finding the desired domain name. + + A DNAME substitution is performed by replacing the suffix labels of + the name being sought matching the owner name of the DNAME resource + record with the string of labels in the RDATA field. The matching + labels end with the root label in all cases. Only whole labels are + replaced. See the table of examples for common cases and corner cases. + + + + + + + + + + + + + + + + +Rose & Wijngaards Expires November 3, 2008 [Page 4] + +Internet-Draft DNAME Redirection May 2008 + + In the table below, the QNAME refers to the query name. The owner is the DNAME owner domain name, and the target refers to the target of the DNAME record. The result is the resulting name after performing @@ -217,14 +249,6 @@ Internet-Draft DNAME Redirection February 2008 shortloop.x.x. x. . shortloop.x. shortloop.x. x. . shortloop. - - - -Rose & Wijngaards Expires August 8, 2008 [Page 4] - -Internet-Draft DNAME Redirection February 2008 - - Table 1. DNAME Substitution Examples. It is possible for DNAMEs to form loops, just as CNAMEs can form @@ -246,122 +270,104 @@ Internet-Draft DNAME Redirection February 2008 2.3. DNAME Apex not Redirected itself - The owner name of a DNAME is not redirected itself. The reason for - the original decision was that one can have a DNAME at the zone apex - without problem. Then use this DNAME at the zone apex to point - queries to the target zone. There still is a need to have the - customary SOA and NS resource records at the zone apex. This means - that DNAME does not mirror a zone completely, as it does not mirror - the zone apex. + Unlike a CNAME RR, a DNAME RR redirects DNS names subordinate to its + owner name; the owner name of a DNAME is not redirected itself. The + domain name that owns a DNAME record is allowed to have other - Another reason for excluding the DNAME owner from the DNAME - substitution is that one can then query for the DNAME through RFC - 1034 [RFC1034] caches. + +Rose & Wijngaards Expires November 3, 2008 [Page 5] + +Internet-Draft DNAME Redirection May 2008 + + + resource record types at that domain name, except DNAMEs or CNAMEs. This means that DNAME RRs are not allowed at the parent side of a delegation point but are allowed at a zone apex. + The reason for this decision was that one can have a DNAME at the + zone apex. There still is a need to have the customary SOA and NS + resource records at the zone apex. This means that DNAME does not + mirror a zone completely, as it does not mirror the zone apex. + + These rules also allow DNAME records to be queried through RFC 1034 + [RFC1034] compliant, DNAME-unaware caches. + 2.4. Names Next to and Below a DNAME Record - Other resource records MUST NOT exist at a domain name subordinate to - the owner of a DNAME RR. To get the contents for names subordinate - to that owner, the DNAME redirection must be invoked and the - resulting target queried. A server SHOULD refuse to load a zone that - has data at a domain name subordinate to a domain name owning a DNAME - RR. Also a server SHOULD refuse to load a zone subordinate to the - owner of a DNAME record in the ancestor zone. See Section 5.2 for - further restrictions related to dynamic update. + Resource records MUST NOT exist at any domain name subordinate to the + owner of a DNAME RR. To get the contents for names subordinate to + that owner, the DNAME redirection must be invoked and the resulting + target queried. A server MAY refuse to load a zone that has data at + a domain name subordinate to a domain name owning a DNAME RR. If the + server does load the zone, those names below the DNAME RR will be + occluded, RFC 2136 [RFC2136], section 7.18. Also a server SHOULD + refuse to load a zone subordinate to the owner of a DNAME record in + the ancestor zone. See Section 5.2 for further discussion related to + dynamic update. DNAME is a singleton type, meaning only one DNAME is allowed per - - - -Rose & Wijngaards Expires August 8, 2008 [Page 5] - -Internet-Draft DNAME Redirection February 2008 - - name. The owner name of a DNAME can only have one DNAME RR, and no CNAME RRs can exist at that name. These rules make sure that for a single domain name only one redirection exists, and thus no confusion which one to follow. A server SHOULD refuse to load a zone that violates these rules. - The domain name that owns a DNAME record is allowed to have other - resource record types at that domain name, except DNAMEs or CNAMEs. - - These rules allow DNAME records to be queried through DNAME unaware - caches. - 2.5. Compression of the DNAME record. The DNAME owner name can be compressed like any other owner name. The DNAME RDATA target name MUST NOT be sent out in compressed form, - so that a DNAME RR can be treated as an unknown type. + so that a DNAME RR can be treated as an unknown type [RFC3597]. - Although the previous specification [RFC2672] talked about signaling - to allow compression of the target name, no such signaling is - explicitly specified. + Although the previous DNAME specification [RFC2672] (that is + obsoleted by this specification) talked about signaling to allow + compression of the target name, such signaling is not specified. RFC 2672 stated that the EDNS version had a meaning for understanding of DNAME and DNAME target name compression. This document updates - RFC 2672, in that there is no EDNS version signaling for DNAME as of - yet. However, the flags section of EDNS(0) is updated with a - Understand-DNAME flag by this document (See Section 3.2). + RFC 2672, in that there is no EDNS version signaling for DNAME. + However, the flags section of EDNS(0) is updated with a Understand- + DNAME flag by this document (See Section 3.3). + + + + +Rose & Wijngaards Expires November 3, 2008 [Page 6] + +Internet-Draft DNAME Redirection May 2008 + 3. Processing -3.1. Wildcards + The DNAME RR causes type NS additional section processing. - The use of DNAME in conjunction with wildcards is discouraged - [RFC4592]. Thus records of the form "*.example.com DNAME - example.net" SHOULD NOT be used. +3.1. CNAME synthesis and UD bit - The interaction between the expansion of the wildcard and the - redirection of the DNAME is non-deterministic. Because the - processing is non-deterministic, DNSSEC validating resolvers may not - be able to validate a wildcarded DNAME. - - A server MAY give a warning that the behavior is unspecified if such - a wildcarded DNAME is loaded. The server MAY refuse it, refuse to - load or refuse dynamic update. - - - - - - - -Rose & Wijngaards Expires August 8, 2008 [Page 6] - -Internet-Draft DNAME Redirection February 2008 - - -3.2. CNAME synthesis - - On the server side, the DNAME RR record is always included in the - answer section of a query, when one is encountered. A CNAME RR - record with TTL equal to the corresponding DNAME RR is synthesized - for old resolvers, specifically for the QNAME in the query. DNSSEC - [RFC4033], [RFC4034], [RFC4035] says that the synthesized CNAME does - not have to be signed. The DNAME has an RRSIG and a validating - resolver can check the CNAME against the DNAME record and validate - the DNAME record. + When preparing an response, a server upon performing a DNAME + substitution will in all cases include the DNAME RR used in the + answer section. A CNAME RR record with TTL equal to the + corresponding DNAME RR is synthesized and included in the answer + section for old resolvers. The owner name of the CNAME is the QNAME + of the query. DNSSEC [RFC4033], [RFC4034], [RFC4035] says that the + synthesized CNAME does not have to be signed. The DNAME has an RRSIG + and a validating resolver can check the CNAME against the DNAME + record and validate the DNAME record. Resolvers MUST be able to handle a synthesized CNAME TTL of zero or - equal to the TTL of the corresponding DNAME record. The TTL of zero + equal to the TTL of the corresponding DNAME record. A TTL of zero means that the CNAME can be discarded immediately after processing the answer. DNAME aware resolvers can set the Understand-DNAME (UD bit) to receive a response with only the DNAME RR and no synthesized CNAMEs. - The UD bit is part of the EDNS extended RCODE and Flags field. It is - used to omit server processing, transmission and resolver processing - of unsigned synthesized CNAMEs. Resolvers can set this in a query to - request omission of the synthesized CNAMEs. Servers copy the UD bit - to the response, and can omit synthesized CNAMEs from the answer. - Older resolvers do not set the UD bit, and older servers do not copy - the UD bit to the answer, and will not omit synthesized CNAMEs. + The UD bit is part of the EDNS [RFC2671] extended RCODE and Flags + field. It is used to omit server processing, transmission and + resolver processing of unsigned synthesized CNAMEs. Resolvers can + set this in a query to request omission of the synthesized CNAMEs. + Servers copy the UD bit to the response, and can omit synthesized + CNAMEs from the answer. Older resolvers do not set the UD bit, and + older servers do not copy the UD bit to the answer, and will not omit + synthesized CNAMEs. Updated EDNS extended RCODE and Flags field. @@ -372,39 +378,25 @@ Internet-Draft DNAME Redirection February 2008 2: |DO|UD| Z | +--+--+--+--+--+--+--+--+--+--+--+--+--+--+--+--+ - Servers MUST be able to answer a query for a synthesized CNAME. An - answer containing the synthesized CNAME cannot contain an error - (since a CNAME has been followed), as per RFC 1034 CNAME rules. - -3.3. Acceptance and Intermediate Storage - - DNS caches can encounter data at names below the owner name of a - DNAME RR, due to a change at the authoritative server where data from - before and after the change resides in the cache. This conflict - situation is a transitional phase, that ends when the old data times - out. The cache can opt to store both old and new data and treat each - as if the other did not exist, or drop the old data, or drop the - longer domain name. In any approach, consistency returns after the + Servers MUST be able to answer a query for a synthesized CNAME. Like + other query types this invokes the DNAME, and synthesizes the CNAME + into the answer. -Rose & Wijngaards Expires August 8, 2008 [Page 7] + + + + +Rose & Wijngaards Expires November 3, 2008 [Page 7] -Internet-Draft DNAME Redirection February 2008 +Internet-Draft DNAME Redirection May 2008 - older data TTL times out. - - DNS caches MUST perform CNAME synthesis on behalf of DNAME-ignorant - clients. A DNS cache that understands DNAMEs can send out queries on - behalf of clients with the UD bit set. After receiving the answers - the DNS cache sends replies to DNAME ignorant clients that include - DNAMEs and synthesized CNAMEs. - -3.4. Server algorithm +3.2. Server algorithm Below the server algorithm, which appeared in RFC 2672 Section 4.1, - is expanded to handle the UD bit. + is expanded to handle the UD (Understand DNAME) bit. 1. Set or clear the value of recursion available in the response depending on whether the name server is willing to provide @@ -439,16 +431,6 @@ Internet-Draft DNAME Redirection February 2008 available from authoritative data or the cache. Go to step 4. - - - - - -Rose & Wijngaards Expires August 8, 2008 [Page 8] - -Internet-Draft DNAME Redirection February 2008 - - C. If at some label, a match is impossible (i.e., the corresponding label does not exist), look to see whether the last label matched has a DNAME record. @@ -459,6 +441,14 @@ Internet-Draft DNAME Redirection February 2008 name>, set RCODE to YXDOMAIN [RFC2136] and exit; otherwise perform the substitution and continue. If the EDNS OPT record is present in the query and the UD bit is set, the + + + +Rose & Wijngaards Expires November 3, 2008 [Page 8] + +Internet-Draft DNAME Redirection May 2008 + + server MAY copy the UD bit to the answer EDNS OPT record, and omit CNAME synthesis. Else the server MUST synthesize a CNAME record as described above and include it in the answer @@ -497,25 +487,80 @@ Internet-Draft DNAME Redirection February 2008 6. Using local data only, attempt to add other RRs which may be useful to the additional section of the query. Exit. - - - -Rose & Wijngaards Expires August 8, 2008 [Page 9] - -Internet-Draft DNAME Redirection February 2008 - - Note that there will be at most one ancestor with a DNAME as described in step 4 unless some zone's data is in violation of the no-descendants limitation in section 3. An implementation might take advantage of this limitation by stopping the search of step 3c or step 4 when a DNAME record is encountered. +3.3. Wildcards + + The use of DNAME in conjunction with wildcards is discouraged + [RFC4592]. Thus records of the form "*.example.com DNAME + + + +Rose & Wijngaards Expires November 3, 2008 [Page 9] + +Internet-Draft DNAME Redirection May 2008 + + + example.net" SHOULD NOT be used. + + The interaction between the expansion of the wildcard and the + redirection of the DNAME is non-deterministic. Because the + processing is non-deterministic, DNSSEC validating resolvers may not + be able to validate a wildcarded DNAME. + + A server MAY give a warning that the behavior is unspecified if such + a wildcarded DNAME is loaded. The server MAY refuse it, refuse to + load or refuse dynamic update. + +3.4. Acceptance and Intermediate Storage + + DNS caches can encounter data at names below the owner name of a + DNAME RR, due to a change at the authoritative server where data from + before and after the change resides in the cache. This conflict + situation is a transitional phase, that ends when the old data times + out. The cache can opt to store both old and new data and treat each + as if the other did not exist, or drop the old data, or drop the + longer domain name. In any approach, consistency returns after the + older data TTL times out. + + DNS caches MUST perform CNAME synthesis on behalf of DNAME-ignorant + clients. A DNS cache that understands DNAMEs can send out queries on + behalf of clients with the UD bit set (See Section 3.1). After + receiving the answers the DNS cache sends replies to DNAME ignorant + clients that include DNAMEs and synthesized CNAMEs. + 4. DNAME Discussions in Other Documents In [RFC2181], in Section 10.3., the discussion on MX and NS records touches on redirection by CNAMEs, but this also holds for DNAMEs. + + + + + + + + + + + + + + + + + + +Rose & Wijngaards Expires November 3, 2008 [Page 10] + +Internet-Draft DNAME Redirection May 2008 + + Excerpt from 10.3. MX and NS records (in RFC 2181). The domain name used as the value of a NS resource record, @@ -551,16 +596,6 @@ Internet-Draft DNAME Redirection February 2008 is to be replaced with the word "DELETED". - - - - - -Rose & Wijngaards Expires August 8, 2008 [Page 10] - -Internet-Draft DNAME Redirection February 2008 - - In [RFC4294], the reference to DNAME was left in as an editorial oversight. The paragraph @@ -572,50 +607,47 @@ Internet-Draft DNAME Redirection February 2008 "Those nodes are NOT RECOMMENDED to support the experimental A6 Resource Record [RFC3363]." + + + + + +Rose & Wijngaards Expires November 3, 2008 [Page 11] + +Internet-Draft DNAME Redirection May 2008 + + 5. Other Issues with DNAME There are several issues to be aware of about the use of DNAME. -5.1. MX, NS and PTR Records Must Point to Target of DNAME +5.1. Canonical hostnames cannot be below DNAME owners - The names listed as target names of MX, NS and PTR records must be - canonical hostnames. This means no CNAME or DNAME redirection may be - present during DNS lookup of the address records for the host. This - is discussed in RFC 2181 [RFC2181], section 10.3, and RFC 1912 - [RFC1912], section 2.4. + The names listed as target names of MX, NS, PTR and SRV [RFC2782] + records must be canonical hostnames. This means no CNAME or DNAME + redirection may be present during DNS lookup of the address records + for the host. This is discussed in RFC 2181 [RFC2181], section 10.3, + and RFC 1912 [RFC1912], section 2.4. For SRV see RFC 2782 [RFC2782] + page 4. The upshot of this is that although the lookup of a PTR record can involve DNAMEs, the name listed in the PTR record can not fall under - a DNAME. The same holds for NS and MX records. For example, when - punycode alternates for a zone use DNAME then the NS, MX and PTR - records that point to that zone must use names without punycode in - their RDATA. What must be done then is to have the domain names with - DNAME substitution already applied to it as the MX, NS, PTR data. - These are valid canonical hostnames. + a DNAME. The same holds for NS, SRV and MX records. For example, + when punycode alternates for a zone use DNAME then the NS, MX, SRV + and PTR records that point to that zone must use names without + punycode in their RDATA. What must be done then is to have the + domain names with DNAME substitution already applied to it as the MX, + NS, PTR, SRV data. These are valid canonical hostnames. 5.2. Dynamic Update and DNAME - Dynamic update for DNAME records works similar to dynamic update for - delegating NS records. For example, adding a DNAME obscures names in - the zone. DNAME records can be added, changed and removed. - - Zones containing a DNAME RR MUST NOT accept a dynamic update message - that would add a record or delegation with a name existing under a - DNAME. - - A server MUST return an error message with RCODE=YXDOMAIN [RFC2136] - in response to a dynamic update message that would add a resource - record under a DNAME in the zone. This is similar to a dynamic - update request to add a resource record under a delegation NS in a - zone. - - - - -Rose & Wijngaards Expires August 8, 2008 [Page 11] - -Internet-Draft DNAME Redirection February 2008 + DNAME records can be added, changed and removed in a zone using + dynamic update transactions. Adding a DNAME RR to a zone occludes + any domain names that may exist under the added DNAME. + A server MUST ignore a dynamic update message that attempts to add a + DNAME RR at a name that already has a CNAME RR or another DNAME RR + associated with that name. 5.3. DNSSEC and DNAME @@ -630,6 +662,17 @@ Internet-Draft DNAME Redirection February 2008 Examples of why DNSSEC validators MUST understand DNAME. + + + + + + +Rose & Wijngaards Expires November 3, 2008 [Page 12] + +Internet-Draft DNAME Redirection May 2008 + + 5.3.2.1. DNAME in Bitmap Causes Invalid Name Error ;; Header: QR AA DO RCODE=3(NXDOMAIN) @@ -663,16 +706,6 @@ Internet-Draft DNAME Redirection February 2008 5.3.2.3. Response With Synthesized CNAME - - - - - -Rose & Wijngaards Expires August 8, 2008 [Page 12] - -Internet-Draft DNAME Redirection February 2008 - - ;; Header: QR AA DO RCODE=0(NOERROR) ;; Question foo.bar.example.com. IN A @@ -688,15 +721,21 @@ Internet-Draft DNAME Redirection February 2008 have its signature included, since it does not change for every query name. The validator must verify the DNAME signature and then recursively resolve further to query for the foo.bar.example.net A + + + +Rose & Wijngaards Expires November 3, 2008 [Page 13] + +Internet-Draft DNAME Redirection May 2008 + + record. 6. IANA Considerations - The main purpose of this draft is to discuss issues related to the - use of DNAME RRs in a DNS zone. The original document registered the - DNAME Resource Record type code 39 (decimal). IANA should update the - DNS resource record registry by adding a pointer to this document for - RR type 39. + The DNAME Resource Record type code 39 (decimal) originally has been + registered by [RFC2672]. IANA should update the DNS resource record + registry to point to this document for RR type 39. This draft requests the second highest bit in the EDNS flags field for the Understand-DNAME (UD) flag. @@ -721,17 +760,9 @@ Internet-Draft DNAME Redirection February 2008 The authors of this draft would like to acknowledge Matt Larson for beginning this effort to address the issues related to the DNAME RR - - - -Rose & Wijngaards Expires August 8, 2008 [Page 13] - -Internet-Draft DNAME Redirection February 2008 - - type. The authors would also like to acknowledge Paul Vixie, Ed - Lewis, Mark Andrews, Mike StJohns and Niall O'Reilly for their review - and comments on this document. + Lewis, Mark Andrews, Mike StJohns, Niall O'Reilly, Sam Weiler, Alfred + Hines and Kevin Darcy for their review and comments on this document. 9. References @@ -740,9 +771,20 @@ Internet-Draft DNAME Redirection February 2008 [RFC1034] Mockapetris, P., "Domain names - concepts and facilities", STD 13, RFC 1034, November 1987. + [RFC1035] Mockapetris, P., "Domain names - implementation and + specification", STD 13, RFC 1035, November 1987. + [RFC2119] Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, March 1997. + + + +Rose & Wijngaards Expires November 3, 2008 [Page 14] + +Internet-Draft DNAME Redirection May 2008 + + [RFC2136] Vixie, P., Thomson, S., Rekhter, Y., and J. Bound, "Dynamic Updates in the Domain Name System (DNS UPDATE)", RFC 2136, April 1997. @@ -750,8 +792,12 @@ Internet-Draft DNAME Redirection February 2008 [RFC2181] Elz, R. and R. Bush, "Clarifications to the DNS Specification", RFC 2181, July 1997. - [RFC2672] Crawford, M., "Non-Terminal DNS Name Redirection", - RFC 2672, August 1999. + [RFC2671] Vixie, P., "Extension Mechanisms for DNS (EDNS0)", + RFC 2671, August 1999. + + [RFC2782] Gulbrandsen, A., Vixie, P., and L. Esibov, "A DNS RR for + specifying the location of services (DNS SRV)", RFC 2782, + February 2000. [RFC3597] Gustafsson, A., "Handling of Unknown DNS Resource Record (RR) Types", RFC 3597, September 2003. @@ -776,15 +822,10 @@ Internet-Draft DNAME Redirection February 2008 [RFC1912] Barr, D., "Common DNS Operational and Configuration Errors", RFC 1912, February 1996. + [RFC2672] Crawford, M., "Non-Terminal DNS Name Redirection", + RFC 2672, August 1999. + [RFC3363] Bush, R., Durand, A., Fink, B., Gudmundsson, O., and T. - - - -Rose & Wijngaards Expires August 8, 2008 [Page 14] - -Internet-Draft DNAME Redirection February 2008 - - Hain, "Representing Internet Protocol version 6 (IPv6) Addresses in the Domain Name System (DNS)", RFC 3363, August 2002. @@ -792,6 +833,14 @@ Internet-Draft DNAME Redirection February 2008 [RFC4294] Loughney, J., "IPv6 Node Requirements", RFC 4294, April 2006. + + + +Rose & Wijngaards Expires November 3, 2008 [Page 15] + +Internet-Draft DNAME Redirection May 2008 + + Authors' Addresses Scott Rose @@ -836,9 +885,16 @@ Authors' Addresses -Rose & Wijngaards Expires August 8, 2008 [Page 15] + + + + + + + +Rose & Wijngaards Expires November 3, 2008 [Page 16] -Internet-Draft DNAME Redirection February 2008 +Internet-Draft DNAME Redirection May 2008 Full Copyright Statement @@ -892,5 +948,5 @@ Acknowledgement -Rose & Wijngaards Expires August 8, 2008 [Page 16] +Rose & Wijngaards Expires November 3, 2008 [Page 17] From 0dba2713dec4cf3f97f21b957e403a36ee989b3c Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Sat, 3 May 2008 05:07:13 +0000 Subject: [PATCH 051/137] add lock comment --- lib/dns/adb.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/lib/dns/adb.c b/lib/dns/adb.c index 893a7dea24..96c4260383 100644 --- a/lib/dns/adb.c +++ b/lib/dns/adb.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: adb.c,v 1.240 2008/05/02 04:40:12 marka Exp $ */ +/* $Id: adb.c,v 1.241 2008/05/03 05:07:13 marka Exp $ */ /*! \file * @@ -1772,6 +1772,9 @@ shutdown_task(isc_task_t *task, isc_event_t *ev) { INSIST(DNS_ADB_VALID(adb)); isc_event_free(&ev); + /* + * Wait for lock around check_exit() call to be released. + */ LOCK(&adb->lock); UNLOCK(&adb->lock); destroy(adb); From e1ebedbb2325c0102aabdc5bc4ea380f4d87c97a Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 5 May 2008 01:49:39 +0000 Subject: [PATCH 052/137] add shutdown_task lock comment --- lib/dns/adb.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/lib/dns/adb.c b/lib/dns/adb.c index 42e2507a61..c0761cd4b9 100644 --- a/lib/dns/adb.c +++ b/lib/dns/adb.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: adb.c,v 1.181.2.11.2.37 2008/04/28 23:45:37 tbox Exp $ */ +/* $Id: adb.c,v 1.181.2.11.2.38 2008/05/05 01:49:39 marka Exp $ */ /* * Implementation notes @@ -1765,13 +1765,16 @@ shutdown_task(isc_task_t *task, isc_event_t *ev) { adb = ev->ev_arg; INSIST(DNS_ADB_VALID(adb)); + /* + * Wait for lock around check_exit() call to be released. + */ + LOCK(&adb->lock); /* * Kill the timer, and then the ADB itself. Note that this implies * that this task was the one scheduled to get timer events. If * this is not true (and it is unfortunate there is no way to INSIST() * this) badness will occur. */ - LOCK(&adb->lock); isc_timer_detach(&adb->timer); UNLOCK(&adb->lock); isc_event_free(&ev); From 9ff097ed393b7cfe978bc0613480dafdfaac3e21 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Mon, 5 May 2008 23:45:30 +0000 Subject: [PATCH 053/137] update copyright notice --- lib/dns/adb.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/lib/dns/adb.c b/lib/dns/adb.c index c0761cd4b9..1f8bd291ad 100644 --- a/lib/dns/adb.c +++ b/lib/dns/adb.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: adb.c,v 1.181.2.11.2.38 2008/05/05 01:49:39 marka Exp $ */ +/* $Id: adb.c,v 1.181.2.11.2.39 2008/05/05 23:45:30 tbox Exp $ */ /* * Implementation notes @@ -1765,9 +1765,9 @@ shutdown_task(isc_task_t *task, isc_event_t *ev) { adb = ev->ev_arg; INSIST(DNS_ADB_VALID(adb)); - /* - * Wait for lock around check_exit() call to be released. - */ + /* + * Wait for lock around check_exit() call to be released. + */ LOCK(&adb->lock); /* * Kill the timer, and then the ADB itself. Note that this implies From 767c53c304b86460d72eeec7d3304172cdd904bd Mon Sep 17 00:00:00 2001 From: Evan Hunt Date: Tue, 6 May 2008 01:09:00 +0000 Subject: [PATCH 054/137] Document changes to "rrset-order fixed" [rt17977] --- README | 9 +++++++-- doc/arm/Bv9ARM-book.xml | 19 +++++++++++++------ doc/arm/Bv9ARM.ch06.html | 19 +++++++++++++------ 3 files changed, 33 insertions(+), 14 deletions(-) diff --git a/README b/README index 6d915f81f5..288ffddf46 100644 --- a/README +++ b/README @@ -62,6 +62,8 @@ BIND 9.5.0 Efficient LRU cache-cleaning mechanism. + NSID support. + BIND 9.4.0 BIND 9.4.0 has a number of new features over 9.3, @@ -431,8 +433,6 @@ Building -DDIG_SIGCHASE_BU=1) Disable dropping queries from particular well known ports. -DNS_CLIENT_DROPPORT=0 - Disable support for "rrset-order fixed". - -DDNS_RDATASET_FIXED=0 LDFLAGS Linker flags. Defaults to empty string. @@ -468,6 +468,11 @@ Building on the configure command line. The default is operating system dependent. + Support for the "fixed" rrset-order option can be enabled + or disabled by specifying "--enable-fixed-rrset" or + "--disable-fixed-rrset" on the configure command line. + The default is "disabled", to reduce memory footprint. + If your operating system has integrated support for IPv6, it will be used automatically. If you have installed KAME IPv6 separately, use "--with-kame[=PATH]" to specify its location. diff --git a/doc/arm/Bv9ARM-book.xml b/doc/arm/Bv9ARM-book.xml index 81be98930a..03d041d0e1 100644 --- a/doc/arm/Bv9ARM-book.xml +++ b/doc/arm/Bv9ARM-book.xml @@ -18,7 +18,7 @@ - PERFORMANCE OF THIS SOFTWARE. --> - + BIND 9 Administrator Reference Manual @@ -7159,8 +7159,13 @@ query-source-v6 address * port *; - Records are returned in a round-robin - order. + Records are returned in a cyclic round-robin order. + + + If BIND is configured with the + "--enable-fixed-rrset" option at compile time, then + the initial ordering of the RRset will match the + one specified in the zone file. @@ -7191,9 +7196,11 @@ query-source-v6 address * port *; - The rrset-order statement - is not yet fully implemented in BIND 9. - BIND 9 currently does not fully support "fixed" ordering. + In this release of BIND 9, the + rrset-order statement does not support + "fixed" ordering by default. Fixed ordering can be enabled + at compile time by specifying "--enable-fixed-rrset" on + the "configure" command line. diff --git a/doc/arm/Bv9ARM.ch06.html b/doc/arm/Bv9ARM.ch06.html index 80c86264c2..0f11fdf4d5 100644 --- a/doc/arm/Bv9ARM.ch06.html +++ b/doc/arm/Bv9ARM.ch06.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -3935,8 +3935,13 @@ query-source-v6 address * port *;
@@ -3964,9 +3969,11 @@ query-source-v6 address * port *;

Note

- The rrset-order statement - is not yet fully implemented in BIND 9. - BIND 9 currently does not fully support "fixed" ordering. + In this release of BIND 9, + the rrset-order + statement does not support "fixed" ordering by default. + Fixed ordering can be enabled at compile time by specifying + "--enable-fixed-rrset" on the "configure" command line.

From 69ec1b7eb3be37f06b53f572f6c33622e95a7935 Mon Sep 17 00:00:00 2001 From: Evan Hunt Date: Tue, 6 May 2008 01:12:55 +0000 Subject: [PATCH 055/137] Improve counting of dns_resstatscounter_retry [rt18030] --- CHANGES | 3 +++ lib/dns/resolver.c | 28 ++++++++++++++-------------- 2 files changed, 17 insertions(+), 14 deletions(-) diff --git a/CHANGES b/CHANGES index 8fb987754b..c59bc55d52 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +2367. [bug] Improve counting of dns_resstatscounter_retry + [RT #18030] + 2366. [bug] Adb shutdown race. [RT #18021] 2365. [bug] Fix a bug that caused dns_acl_isany() to return diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c index c5354a4c7e..1e5ac81cf4 100644 --- a/lib/dns/resolver.c +++ b/lib/dns/resolver.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: resolver.c,v 1.369 2008/05/01 18:23:07 jinmei Exp $ */ +/* $Id: resolver.c,v 1.370 2008/05/06 01:12:55 each Exp $ */ /*! \file */ @@ -392,7 +392,7 @@ static void empty_bucket(dns_resolver_t *res); static isc_result_t resquery_send(resquery_t *query); static void resquery_response(isc_task_t *task, isc_event_t *event); static void resquery_connected(isc_task_t *task, isc_event_t *event); -static void fctx_try(fetchctx_t *fctx); +static void fctx_try(fetchctx_t *fctx, isc_boolean_t retrying); static isc_boolean_t fctx_destroy(fetchctx_t *fctx); static isc_result_t ncache_adderesult(dns_message_t *message, dns_db_t *cache, dns_dbnode_t *node, @@ -983,7 +983,7 @@ resquery_senddone(isc_task_t *task, isc_event_t *event) { if (result != ISC_R_SUCCESS) fctx_done(fctx, result); else - fctx_try(fctx); + fctx_try(fctx, ISC_TRUE); } } @@ -1823,7 +1823,7 @@ resquery_connected(isc_task_t *task, isc_event_t *event) { if (result != ISC_R_SUCCESS) fctx_done(fctx, result); else - fctx_try(fctx); + fctx_try(fctx, ISC_TRUE); } } @@ -1882,7 +1882,7 @@ fctx_finddone(isc_task_t *task, isc_event_t *event) { dns_adb_destroyfind(&find); if (want_try) - fctx_try(fctx); + fctx_try(fctx, ISC_TRUE); else if (want_done) fctx_done(fctx, ISC_R_FAILURE); else if (bucket_empty) @@ -2641,7 +2641,7 @@ fctx_nextaddress(fetchctx_t *fctx) { } static void -fctx_try(fetchctx_t *fctx) { +fctx_try(fetchctx_t *fctx, isc_boolean_t retrying) { isc_result_t result; dns_adbaddrinfo_t *addrinfo; @@ -2649,9 +2649,6 @@ fctx_try(fetchctx_t *fctx) { REQUIRE(!ADDRWAIT(fctx)); - if (fctx->restarts > 0) - inc_stats(fctx->res, dns_resstatscounter_retry); - addrinfo = fctx_nextaddress(fctx); if (addrinfo == NULL) { /* @@ -2692,6 +2689,8 @@ fctx_try(fetchctx_t *fctx) { result = fctx_query(fctx, addrinfo, fctx->options); if (result != ISC_R_SUCCESS) fctx_done(fctx, result); + else if (retrying) + inc_stats(fctx->res, dns_resstatscounter_retry); } static isc_boolean_t @@ -2809,7 +2808,7 @@ fctx_timeout(isc_task_t *task, isc_event_t *event) { /* * Keep trying. */ - fctx_try(fctx); + fctx_try(fctx, ISC_TRUE); } isc_event_free(&event); @@ -2979,7 +2978,7 @@ fctx_start(isc_task_t *task, isc_event_t *event) { if (result != ISC_R_SUCCESS) fctx_done(fctx, result); else - fctx_try(fctx); + fctx_try(fctx, ISC_FALSE); } else if (bucket_empty) empty_bucket(res); } @@ -3607,7 +3606,7 @@ validated(isc_task_t *task, isc_event_t *event) { } else if (sentresponse) fctx_done(fctx, result); /* Locks bucket. */ else - fctx_try(fctx); /* Locks bucket. */ + fctx_try(fctx, ISC_TRUE); /* Locks bucket. */ return; } @@ -5376,7 +5375,7 @@ resume_dslookup(isc_task_t *task, isc_event_t *event) { /* * Try again. */ - fctx_try(fctx); + fctx_try(fctx, ISC_TRUE); } else { unsigned int n; dns_rdataset_t *nsrdataset = NULL; @@ -6182,12 +6181,13 @@ resquery_response(isc_task_t *task, isc_event_t *event) { /* * Try again. */ - fctx_try(fctx); + fctx_try(fctx, !get_nameservers); } else if (resend) { /* * Resend (probably with changed options). */ FCTXTRACE("resend"); + inc_stats(fctx->res, dns_resstatscounter_retry); result = fctx_query(fctx, addrinfo, options); if (result != ISC_R_SUCCESS) fctx_done(fctx, result); From 0415ca35ada2cac6a86127eaca64f3a997aea121 Mon Sep 17 00:00:00 2001 From: Evan Hunt Date: Tue, 6 May 2008 01:31:11 +0000 Subject: [PATCH 056/137] Linux: use libcap for capability management if possible. [RT# 18026] --- CHANGES | 3 ++ bin/named/unix/os.c | 121 ++++++++++++++++++++++++++++---------------- config.h.in | 8 +-- configure | 61 +++++++--------------- configure.in | 4 +- 5 files changed, 105 insertions(+), 92 deletions(-) diff --git a/CHANGES b/CHANGES index c59bc55d52..ce24256a99 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +2368. [port] Linux: use libcap for capability management if + possible. [RT# 18026] + 2367. [bug] Improve counting of dns_resstatscounter_retry [RT #18030] diff --git a/bin/named/unix/os.c b/bin/named/unix/os.c index 3c75009d20..171b20dde1 100644 --- a/bin/named/unix/os.c +++ b/bin/named/unix/os.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: os.c,v 1.83 2008/01/30 04:48:05 marka Exp $ */ +/* $Id: os.c,v 1.84 2008/05/06 01:30:26 each Exp $ */ /*! \file */ @@ -69,7 +69,7 @@ static int devnullfd = -1; /* * Linux defines: * (T) HAVE_LINUXTHREADS - * (C) HAVE_LINUX_CAPABILITY_H + * (C) HAVE_SYS_CAPABILITY_H (or HAVE_LINUX_CAPABILITY_H) * (P) HAVE_SYS_PRCTL_H * The possible cases are: * none: setuid() normally @@ -116,16 +116,9 @@ static int dfd[2] = { -1, -1 }; static isc_boolean_t non_root = ISC_FALSE; static isc_boolean_t non_root_caps = ISC_FALSE; -#if defined(HAVE_CAPSET) -#undef _POSIX_SOURCE #ifdef HAVE_SYS_CAPABILITY_H #include #else -#include -int capset(cap_user_header_t hdrp, const cap_user_data_t datap); -#endif -#include -#else /*% * We define _LINUX_FS_H to prevent it from being included. We don't need * anything from it, and the files it includes cause warnings with 2.2 @@ -133,9 +126,15 @@ int capset(cap_user_header_t hdrp, const cap_user_data_t datap); * and ) on 2.3 kernels. */ #define _LINUX_FS_H - -#include /* Required for syscall(). */ -#include /* Required for _LINUX_CAPABILITY_VERSION. */ +#include +#include +#ifndef SYS_capset +#ifndef __NR_capset +#include /* Slackware 4.0 needs this. */ +#endif /* __NR_capset */ +#define SYS_capset __NR_capset +#endif /* SYS_capset */ +#endif /* HAVE_SYS_CAPABILITY_H */ #ifdef HAVE_SYS_PRCTL_H #include /* Required for prctl(). */ @@ -152,23 +151,24 @@ int capset(cap_user_header_t hdrp, const cap_user_data_t datap); #endif /* HAVE_SYS_PRCTL_H */ -#ifndef SYS_capset -#ifndef __NR_capset -#include /* Slackware 4.0 needs this. */ -#endif -#define SYS_capset __NR_capset -#endif -#endif +#ifdef HAVE_LIBCAP +#define SETCAPS_FUNC "cap_set_proc " +#else +typedef unsigned int cap_t; +#define SETCAPS_FUNC "syscall(capset) " +#endif /* HAVE_LIBCAP */ static void -linux_setcaps(unsigned int caps) { +linux_setcaps(cap_t caps) { +#ifndef HAVE_LIBCAP struct __user_cap_header_struct caphead; struct __user_cap_data_struct cap; +#endif char strbuf[ISC_STRERRORSIZE]; if ((getuid() != 0 && !non_root_caps) || non_root) return; - +#ifndef HAVE_LIBCAP memset(&caphead, 0, sizeof(caphead)); caphead.version = _LINUX_CAPABILITY_VERSION; caphead.pid = 0; @@ -176,46 +176,74 @@ linux_setcaps(unsigned int caps) { cap.effective = caps; cap.permitted = caps; cap.inheritable = 0; -#ifdef HAVE_CAPSET - if (capset(&caphead, &cap) < 0 ) { - isc__strerror(errno, strbuf, sizeof(strbuf)); - ns_main_earlyfatal("capset failed: %s:" - " please ensure that the capset kernel" - " module is loaded. see insmod(8)", - strbuf); - } +#endif +#ifdef HAVE_LIBCAP + if (cap_set_proc(caps) < 0) { #else if (syscall(SYS_capset, &caphead, &cap) < 0) { +#endif isc__strerror(errno, strbuf, sizeof(strbuf)); - ns_main_earlyfatal("syscall(capset) failed: %s:" + ns_main_earlyfatal(SETCAPS_FUNC "failed: %s:" " please ensure that the capset kernel" " module is loaded. see insmod(8)", strbuf); } -#endif } +#ifdef HAVE_LIBCAP +#define SET_CAP(flag) \ + do { \ + capval = (flag); \ + err = cap_set_flag(caps, CAP_EFFECTIVE, 1, &capval, CAP_SET); \ + if (err == -1) { \ + isc__strerror(errno, strbuf, sizeof(strbuf)); \ + ns_main_earlyfatal("cap_set_proc failed: %s", strbuf); \ + } \ + \ + err = cap_set_flag(caps, CAP_PERMITTED, 1, &capval, CAP_SET); \ + if (err == -1) { \ + isc__strerror(errno, strbuf, sizeof(strbuf)); \ + ns_main_earlyfatal("cap_set_proc failed: %s", strbuf); \ + } \ + } while (0) +#define INIT_CAP \ + do { \ + caps = cap_init(); \ + if (caps == NULL) { \ + isc__strerror(errno, strbuf, sizeof(strbuf)); \ + ns_main_earlyfatal("cap_init failed: %s", strbuf); \ + } \ + } while (0) +#else +#define SET_CAP(flag) { caps |= (1 << (flag)); } +#define INIT_CAP { caps = 0; } +#endif /* HAVE_LIBCAP */ + static void linux_initialprivs(void) { - unsigned int caps; + cap_t caps; +#ifdef HAVE_LIBCAP + cap_value_t capval; + char strbuf[ISC_STRERRORSIZE]; + int err; +#endif /*% * We don't need most privileges, so we drop them right away. * Later on linux_minprivs() will be called, which will drop our * capabilities to the minimum needed to run the server. */ - - caps = 0; + INIT_CAP; /* * We need to be able to bind() to privileged ports, notably port 53! */ - caps |= (1 << CAP_NET_BIND_SERVICE); + SET_CAP(CAP_NET_BIND_SERVICE); /* * We need chroot() initially too. */ - caps |= (1 << CAP_SYS_CHROOT); + SET_CAP(CAP_SYS_CHROOT); #if defined(HAVE_SYS_PRCTL_H) || !defined(HAVE_LINUXTHREADS) /* @@ -224,19 +252,19 @@ linux_initialprivs(void) { * tried) or we're not using threads. If either of these is * true, we want the setuid capability. */ - caps |= (1 << CAP_SETUID); + SET_CAP(CAP_SETUID); #endif /* * Since we call initgroups, we need this. */ - caps |= (1 << CAP_SETGID); + SET_CAP(CAP_SETGID); /* * Without this, we run into problems reading a configuration file * owned by a non-root user and non-world-readable on startup. */ - caps |= (1 << CAP_DAC_READ_SEARCH); + SET_CAP(CAP_DAC_READ_SEARCH); /* * XXX We might want to add CAP_SYS_RESOURCE, though it's not @@ -245,15 +273,21 @@ linux_initialprivs(void) { * of files, the stack size, data size, and core dump size to * support named.conf options, this is now being added to test. */ - caps |= (1 << CAP_SYS_RESOURCE); + SET_CAP(CAP_SYS_RESOURCE); linux_setcaps(caps); } static void linux_minprivs(void) { - unsigned int caps; + cap_t caps; +#ifdef HAVE_LIBCAP + cap_value_t capval; + char strbuf[ISC_STRERRORSIZE]; + int err; +#endif + INIT_CAP; /*% * Drop all privileges except the ability to bind() to privileged * ports. @@ -262,8 +296,7 @@ linux_minprivs(void) { * chroot() could be used to escape from the chrooted area. */ - caps = 0; - caps |= (1 << CAP_NET_BIND_SERVICE); + SET_CAP(CAP_NET_BIND_SERVICE); /* * XXX We might want to add CAP_SYS_RESOURCE, though it's not @@ -272,7 +305,7 @@ linux_minprivs(void) { * of files, the stack size, data size, and core dump size to * support named.conf options, this is now being added to test. */ - caps |= (1 << CAP_SYS_RESOURCE); + SET_CAP(CAP_SYS_RESOURCE); linux_setcaps(caps); } diff --git a/config.h.in b/config.h.in index ab0f0ade8d..692ead8cfd 100644 --- a/config.h.in +++ b/config.h.in @@ -16,7 +16,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: config.h.in,v 1.98 2008/04/28 23:43:24 marka Exp $ */ +/* $Id: config.h.in,v 1.99 2008/05/06 01:30:26 each Exp $ */ /*! \file */ @@ -160,9 +160,6 @@ int sigwait(const unsigned int *set, int *sig); /* Define to enable "rrset-order fixed" syntax. */ #undef DNS_RDATASET_FIXED -/* Define to 1 if you have the `capset' function. */ -#undef HAVE_CAPSET - /* Define to 1 if you have the header file. */ #undef HAVE_DLFCN_H @@ -181,6 +178,9 @@ int sigwait(const unsigned int *set, int *sig); /* Define to 1 if you have the `c' library (-lc). */ #undef HAVE_LIBC +/* Define to 1 if you have the `cap' library (-lcap). */ +#undef HAVE_LIBCAP + /* Define to 1 if you have the `c_r' library (-lc_r). */ #undef HAVE_LIBC_R diff --git a/configure b/configure index 154eb4dcc8..61adb40be9 100755 --- a/configure +++ b/configure @@ -14,7 +14,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. # -# $Id: configure,v 1.427 2008/04/28 23:43:24 marka Exp $ +# $Id: configure,v 1.428 2008/05/06 01:31:11 each Exp $ # # Portions Copyright (C) 1996-2001 Nominum, Inc. # @@ -29,7 +29,7 @@ # WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN # ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT # OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. -# From configure.in Revision: 1.442 . +# From configure.in Revision: 1.443 . # Guess values for system-dependent variables and create Makefiles. # Generated by GNU Autoconf 2.61. # @@ -27592,36 +27592,19 @@ fi done -for ac_func in capset -do -as_ac_var=`echo "ac_cv_func_$ac_func" | $as_tr_sh` -{ echo "$as_me:$LINENO: checking for $ac_func" >&5 -echo $ECHO_N "checking for $ac_func... $ECHO_C" >&6; } -if { as_var=$as_ac_var; eval "test \"\${$as_var+set}\" = set"; }; then +{ echo "$as_me:$LINENO: checking for cap_set_proc in -lcap" >&5 +echo $ECHO_N "checking for cap_set_proc in -lcap... $ECHO_C" >&6; } +if test "${ac_cv_lib_cap_cap_set_proc+set}" = set; then echo $ECHO_N "(cached) $ECHO_C" >&6 else - cat >conftest.$ac_ext <<_ACEOF + ac_check_lib_save_LIBS=$LIBS +LIBS="-lcap $LIBS" +cat >conftest.$ac_ext <<_ACEOF /* confdefs.h. */ _ACEOF cat confdefs.h >>conftest.$ac_ext cat >>conftest.$ac_ext <<_ACEOF /* end confdefs.h. */ -/* Define $ac_func to an innocuous variant, in case declares $ac_func. - For example, HP-UX 11i declares gettimeofday. */ -#define $ac_func innocuous_$ac_func - -/* System header to define __stub macros and hopefully few prototypes, - which can conflict with char $ac_func (); below. - Prefer to if __STDC__ is defined, since - exists even on freestanding compilers. */ - -#ifdef __STDC__ -# include -#else -# include -#endif - -#undef $ac_func /* Override any GCC internal prototype to avoid an error. Use char because int might match the return type of a GCC @@ -27629,18 +27612,11 @@ cat >>conftest.$ac_ext <<_ACEOF #ifdef __cplusplus extern "C" #endif -char $ac_func (); -/* The GNU C library defines this for functions which it implements - to always fail with ENOSYS. Some functions are actually named - something starting with __ and the normal name is an alias. */ -#if defined __stub_$ac_func || defined __stub___$ac_func -choke me -#endif - +char cap_set_proc (); int main () { -return $ac_func (); +return cap_set_proc (); ; return 0; } @@ -27663,27 +27639,28 @@ eval "echo \"\$as_me:$LINENO: $ac_try_echo\"") >&5 test ! -s conftest.err } && test -s conftest$ac_exeext && $as_test_x conftest$ac_exeext; then - eval "$as_ac_var=yes" + ac_cv_lib_cap_cap_set_proc=yes else echo "$as_me: failed program was:" >&5 sed 's/^/| /' conftest.$ac_ext >&5 - eval "$as_ac_var=no" + ac_cv_lib_cap_cap_set_proc=no fi rm -f core conftest.err conftest.$ac_objext conftest_ipa8_conftest.oo \ conftest$ac_exeext conftest.$ac_ext +LIBS=$ac_check_lib_save_LIBS fi -ac_res=`eval echo '${'$as_ac_var'}'` - { echo "$as_me:$LINENO: result: $ac_res" >&5 -echo "${ECHO_T}$ac_res" >&6; } -if test `eval echo '${'$as_ac_var'}'` = yes; then +{ echo "$as_me:$LINENO: result: $ac_cv_lib_cap_cap_set_proc" >&5 +echo "${ECHO_T}$ac_cv_lib_cap_cap_set_proc" >&6; } +if test $ac_cv_lib_cap_cap_set_proc = yes; then cat >>confdefs.h <<_ACEOF -#define `echo "HAVE_$ac_func" | $as_tr_cpp` 1 +#define HAVE_LIBCAP 1 _ACEOF + LIBS="-lcap $LIBS" + fi -done ;; no) diff --git a/configure.in b/configure.in index 17957d28ff..e31442a880 100644 --- a/configure.in +++ b/configure.in @@ -18,7 +18,7 @@ AC_DIVERT_PUSH(1)dnl esyscmd([sed "s/^/# /" COPYRIGHT])dnl AC_DIVERT_POP()dnl -AC_REVISION($Revision: 1.442 $) +AC_REVISION($Revision: 1.443 $) AC_INIT(lib/dns/name.c) AC_PREREQ(2.59) @@ -1891,7 +1891,7 @@ AC_ARG_ENABLE(linux-caps, case "$enable_linux_caps" in yes|'') AC_CHECK_HEADERS(linux/capability.h sys/capability.h) - AC_CHECK_FUNCS(capset) + AC_CHECK_LIB(cap, cap_set_proc) ;; no) ;; From d65ec15e06696703fb6537ead651b6fd43e787aa Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Tue, 6 May 2008 23:18:42 +0000 Subject: [PATCH 057/137] auto update --- doc/private/branches | 1 + 1 file changed, 1 insertion(+) diff --git a/doc/private/branches b/doc/private/branches index 638d6db934..90d9bd799c 100644 --- a/doc/private/branches +++ b/doc/private/branches @@ -118,6 +118,7 @@ rt17949 new rt17977 new each // 2008-04-23 00:29 +0000 rt18018 new rt18020 new fdupont // 2008-05-01 07:57 +0000 +rt18033 new fdupont // 2008-05-06 15:54 +0000 shane_dbbackend open skan open explorer skan-metazones1 private explorer From 9ef82979c49da3dd3647273b1cd6ed7d3352c003 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Wed, 7 May 2008 01:11:57 +0000 Subject: [PATCH 058/137] regen --- doc/arm/Bv9ARM.ch06.html | 94 +++++++------- doc/arm/Bv9ARM.ch07.html | 14 +-- doc/arm/Bv9ARM.ch08.html | 18 +-- doc/arm/Bv9ARM.ch09.html | 180 +++++++++++++-------------- doc/arm/Bv9ARM.html | 46 +++---- doc/arm/man.dig.html | 20 +-- doc/arm/man.dnssec-keyfromlabel.html | 12 +- doc/arm/man.dnssec-keygen.html | 14 +-- doc/arm/man.dnssec-signzone.html | 12 +- doc/arm/man.host.html | 10 +- doc/arm/man.named-checkconf.html | 12 +- doc/arm/man.named-checkzone.html | 12 +- doc/arm/man.named.html | 16 +-- doc/arm/man.rndc-confgen.html | 12 +- doc/arm/man.rndc.conf.html | 12 +- doc/arm/man.rndc.html | 12 +- 16 files changed, 248 insertions(+), 248 deletions(-) diff --git a/doc/arm/Bv9ARM.ch06.html b/doc/arm/Bv9ARM.ch06.html index 0f11fdf4d5..05d5de68ea 100644 --- a/doc/arm/Bv9ARM.ch06.html +++ b/doc/arm/Bv9ARM.ch06.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -75,32 +75,32 @@
options Statement Definition and Usage
statistics-channels Statement Grammar
-
statistics-channels Statement Definition and +
statistics-channels Statement Definition and Usage
server Statement Grammar
server Statement Definition and Usage
-
trusted-keys Statement Grammar
-
trusted-keys Statement Definition +
trusted-keys Statement Grammar
+
trusted-keys Statement Definition and Usage
view Statement Grammar
-
view Statement Definition and Usage
+
view Statement Definition and Usage
zone Statement Grammar
-
zone Statement Definition and Usage
+
zone Statement Definition and Usage
-
Zone File
+
Zone File
Types of Resource Records and When to Use Them
-
Discussion of MX Records
+
Discussion of MX Records
Setting TTLs
-
Inverse Mapping in IPv4
-
Other Zone File Directives
-
BIND Master File Extension: the $GENERATE Directive
+
Inverse Mapping in IPv4
+
Other Zone File Directives
+
BIND Master File Extension: the $GENERATE Directive
Additional File Formats
-
BIND9 Statistics
-
Statistics Counters
+
BIND9 Statistics
+
Statistics Counters

@@ -3935,13 +3935,13 @@ query-source-v6 address * port *;

@@ -3969,11 +3969,11 @@ query-source-v6 address * port *;

Note

- In this release of BIND 9, - the rrset-order - statement does not support "fixed" ordering by default. - Fixed ordering can be enabled at compile time by specifying - "--enable-fixed-rrset" on the "configure" command line. + In this release of BIND 9, the + rrset-order statement does not support + "fixed" ordering by default. Fixed ordering can be enabled + at compile time by specifying "--enable-fixed-rrset" on + the "configure" command line.

@@ -4462,7 +4462,7 @@ query-source-v6 address * port *;

-statistics-channels Statement Definition and +statistics-channels Statement Definition and Usage

The statistics-channels statement @@ -4707,7 +4707,7 @@ query-source-v6 address * port *;

-trusted-keys Statement Grammar

+trusted-keys Statement Grammar
trusted-keys {
     string number number number string ;
     [ string number number number string ; [...]]
@@ -4716,7 +4716,7 @@ query-source-v6 address * port *;
 
 

-trusted-keys Statement Definition +trusted-keys Statement Definition and Usage

The trusted-keys statement defines @@ -4759,7 +4759,7 @@ query-source-v6 address * port *;

-view Statement Definition and Usage

+view Statement Definition and Usage

The view statement is a powerful feature @@ -5022,10 +5022,10 @@ zone zone_name [

-zone Statement Definition and Usage

+zone Statement Definition and Usage

-Zone Types

+Zone Types

- Records are returned in a round-robin - order. + Records are returned in a round-robin order. +

+

+ If BINDis + configured with the "--enable-fixed-rrset" option + at compile time, then the initial ordering of the + RRset will match the one specified in the zone file.

- Records are returned in a round-robin order. + Records are returned in a cyclic round-robin order.

- If BINDis - configured with the "--enable-fixed-rrset" option - at compile time, then the initial ordering of the - RRset will match the one specified in the zone file. + If BIND is configured with the + "--enable-fixed-rrset" option at compile time, then + the initial ordering of the RRset will match the + one specified in the zone file.

@@ -5234,7 +5234,7 @@ zone zone_name [

-Class

+Class

The zone's name may optionally be followed by a class. If a class is not specified, class IN (for Internet), @@ -5256,7 +5256,7 @@ zone zone_name [

-Zone Options

+Zone Options
allow-notify

@@ -5828,7 +5828,7 @@ zone zone_name [

-Zone File

+Zone File

Types of Resource Records and When to Use Them

@@ -5841,7 +5841,7 @@ zone zone_name [

-Resource Records

+Resource Records

A domain name identifies a node. Each node has a set of resource information, which may be empty. The set of resource @@ -6492,7 +6492,7 @@ zone zone_name [

-Textual expression of RRs

+Textual expression of RRs

RRs are represented in binary form in the packets of the DNS protocol, and are usually represented in highly encoded form @@ -6695,7 +6695,7 @@ zone zone_name [

-Discussion of MX Records

+Discussion of MX Records

As described above, domain servers store information as a series of resource records, each of which contains a particular @@ -6953,7 +6953,7 @@ zone zone_name [

-Inverse Mapping in IPv4

+Inverse Mapping in IPv4

Reverse name resolution (that is, translation from IP address to name) is achieved by means of the in-addr.arpa domain @@ -7014,7 +7014,7 @@ zone zone_name [

-Other Zone File Directives

+Other Zone File Directives

The Master File Format was initially defined in RFC 1035 and has subsequently been extended. While the Master File Format @@ -7029,7 +7029,7 @@ zone zone_name [

-The $ORIGIN Directive

+The $ORIGIN Directive

Syntax: $ORIGIN domain-name @@ -7057,7 +7057,7 @@ WWW.EXAMPLE.COM. CNAME MAIN-SERVER.EXAMPLE.COM.

-The $INCLUDE Directive

+The $INCLUDE Directive

Syntax: $INCLUDE filename @@ -7093,7 +7093,7 @@ WWW.EXAMPLE.COM. CNAME MAIN-SERVER.EXAMPLE.COM.

-The $TTL Directive

+The $TTL Directive

Syntax: $TTL default-ttl @@ -7112,7 +7112,7 @@ WWW.EXAMPLE.COM. CNAME MAIN-SERVER.EXAMPLE.COM.

-BIND Master File Extension: the $GENERATE Directive

+BIND Master File Extension: the $GENERATE Directive

Syntax: $GENERATE range @@ -7317,7 +7317,7 @@ $GENERATE 1-127 $ CNAME $.0

-BIND9 Statistics

+BIND9 Statistics

BIND 9 maintains lots of statistics information and provides several interfaces for users to @@ -7474,7 +7474,7 @@ $GENERATE 1-127 $ CNAME $.0

-Statistics Counters

+Statistics Counters

The following tables summarize statistics counters that BIND 9 provides. @@ -7493,7 +7493,7 @@ $GENERATE 1-127 $ CNAME $.0

-Name Server Statistics Counters

+Name Server Statistics Counters
@@ -8034,7 +8034,7 @@ $GENERATE 1-127 $ CNAME $.0

-Zone Maintenance Statistics Counters

+Zone Maintenance Statistics Counters
@@ -8188,7 +8188,7 @@ $GENERATE 1-127 $ CNAME $.0

-Resolver Statistics Counters

+Resolver Statistics Counters
@@ -8494,7 +8494,7 @@ $GENERATE 1-127 $ CNAME $.0

-Compatibility with BIND 8 Counters

+Compatibility with BIND 8 Counters

Most statistics counters that were available in BIND 8 are also supported in diff --git a/doc/arm/Bv9ARM.ch07.html b/doc/arm/Bv9ARM.ch07.html index 50e2ef12a0..ecd84abe65 100644 --- a/doc/arm/Bv9ARM.ch07.html +++ b/doc/arm/Bv9ARM.ch07.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -46,10 +46,10 @@

Table of Contents

Access Control Lists
-
Chroot and Setuid
+
Chroot and Setuid
-
The chroot Environment
-
Using the setuid Function
+
The chroot Environment
+
Using the setuid Function
Dynamic Update Security
@@ -119,7 +119,7 @@ zone "example.com" {

-Chroot and Setuid +Chroot and Setuid

On UNIX servers, it is possible to run BIND in a chrooted environment @@ -143,7 +143,7 @@ zone "example.com" {

-The chroot Environment

+The chroot Environment

In order for a chroot environment to @@ -171,7 +171,7 @@ zone "example.com" {

-Using the setuid Function

+Using the setuid Function

Prior to running the named daemon, use diff --git a/doc/arm/Bv9ARM.ch08.html b/doc/arm/Bv9ARM.ch08.html index a3c9503254..2f9e8aca4b 100644 --- a/doc/arm/Bv9ARM.ch08.html +++ b/doc/arm/Bv9ARM.ch08.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -45,18 +45,18 @@

-Common Problems

+Common Problems

-It's not working; how can I figure out what's wrong?

+It's not working; how can I figure out what's wrong?

The best solution to solving installation and configuration issues is to take preventative measures by setting @@ -68,7 +68,7 @@

-Incrementing and Changing the Serial Number

+Incrementing and Changing the Serial Number

Zone serial numbers are just numbers — they aren't date related. A lot of people set them to a number that @@ -95,7 +95,7 @@

-Where Can I Get Help?

+Where Can I Get Help?

The Internet Systems Consortium (ISC) offers a wide range diff --git a/doc/arm/Bv9ARM.ch09.html b/doc/arm/Bv9ARM.ch09.html index a1022c4a3a..276d40372a 100644 --- a/doc/arm/Bv9ARM.ch09.html +++ b/doc/arm/Bv9ARM.ch09.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -45,21 +45,21 @@

-Acknowledgments

+Acknowledgments

A Brief History of the DNS and BIND @@ -164,7 +164,7 @@

-General DNS Reference Information

+General DNS Reference Information

IPv6 addresses (AAAA)

@@ -252,17 +252,17 @@

-Bibliography

+Bibliography

Standards

-

[RFC974] C. Partridge. Mail Routing and the Domain System. January 1986.

+

[RFC974] C. Partridge. Mail Routing and the Domain System. January 1986.

-

[RFC1034] P.V. Mockapetris. Domain Names — Concepts and Facilities. November 1987.

+

[RFC1034] P.V. Mockapetris. Domain Names — Concepts and Facilities. November 1987.

-

[RFC1035] P. V. Mockapetris. Domain Names — Implementation and +

[RFC1035] P. V. Mockapetris. Domain Names — Implementation and Specification. November 1987.

@@ -270,42 +270,42 @@

Proposed Standards

-

[RFC2181] R., R. Bush Elz. Clarifications to the DNS +

[RFC2181] R., R. Bush Elz. Clarifications to the DNS Specification. July 1997.

-

[RFC2308] M. Andrews. Negative Caching of DNS +

[RFC2308] M. Andrews. Negative Caching of DNS Queries. March 1998.

-

[RFC1995] M. Ohta. Incremental Zone Transfer in DNS. August 1996.

+

[RFC1995] M. Ohta. Incremental Zone Transfer in DNS. August 1996.

-

[RFC1996] P. Vixie. A Mechanism for Prompt Notification of Zone Changes. August 1996.

+

[RFC1996] P. Vixie. A Mechanism for Prompt Notification of Zone Changes. August 1996.

-

[RFC2136] P. Vixie, S. Thomson, Y. Rekhter, and J. Bound. Dynamic Updates in the Domain Name System. April 1997.

+

[RFC2136] P. Vixie, S. Thomson, Y. Rekhter, and J. Bound. Dynamic Updates in the Domain Name System. April 1997.

-

[RFC2671] P. Vixie. Extension Mechanisms for DNS (EDNS0). August 1997.

+

[RFC2671] P. Vixie. Extension Mechanisms for DNS (EDNS0). August 1997.

-

[RFC2672] M. Crawford. Non-Terminal DNS Name Redirection. August 1999.

+

[RFC2672] M. Crawford. Non-Terminal DNS Name Redirection. August 1999.

-

[RFC2845] P. Vixie, O. Gudmundsson, D. Eastlake, 3rd, and B. Wellington. Secret Key Transaction Authentication for DNS (TSIG). May 2000.

+

[RFC2845] P. Vixie, O. Gudmundsson, D. Eastlake, 3rd, and B. Wellington. Secret Key Transaction Authentication for DNS (TSIG). May 2000.

-

[RFC2930] D. Eastlake, 3rd. Secret Key Establishment for DNS (TKEY RR). September 2000.

+

[RFC2930] D. Eastlake, 3rd. Secret Key Establishment for DNS (TKEY RR). September 2000.

-

[RFC2931] D. Eastlake, 3rd. DNS Request and Transaction Signatures (SIG(0)s). September 2000.

+

[RFC2931] D. Eastlake, 3rd. DNS Request and Transaction Signatures (SIG(0)s). September 2000.

-

[RFC3007] B. Wellington. Secure Domain Name System (DNS) Dynamic Update. November 2000.

+

[RFC3007] B. Wellington. Secure Domain Name System (DNS) Dynamic Update. November 2000.

-

[RFC3645] S. Kwan, P. Garg, J. Gilroy, L. Esibov, J. Westhead, and R. Hall. Generic Security Service Algorithm for Secret +

[RFC3645] S. Kwan, P. Garg, J. Gilroy, L. Esibov, J. Westhead, and R. Hall. Generic Security Service Algorithm for Secret Key Transaction Authentication for DNS (GSS-TSIG). October 2003.

@@ -314,19 +314,19 @@

DNS Security Proposed Standards

-

[RFC3225] D. Conrad. Indicating Resolver Support of DNSSEC. December 2001.

+

[RFC3225] D. Conrad. Indicating Resolver Support of DNSSEC. December 2001.

-

[RFC3833] D. Atkins and R. Austein. Threat Analysis of the Domain Name System (DNS). August 2004.

+

[RFC3833] D. Atkins and R. Austein. Threat Analysis of the Domain Name System (DNS). August 2004.

-

[RFC4033] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. DNS Security Introduction and Requirements. March 2005.

+

[RFC4033] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. DNS Security Introduction and Requirements. March 2005.

-

[RFC4044] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. Resource Records for the DNS Security Extensions. March 2005.

+

[RFC4044] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. Resource Records for the DNS Security Extensions. March 2005.

-

[RFC4035] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. Protocol Modifications for the DNS +

[RFC4035] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. Protocol Modifications for the DNS Security Extensions. March 2005.

@@ -334,146 +334,146 @@

Other Important RFCs About DNS Implementation

-

[RFC1535] E. Gavron. A Security Problem and Proposed Correction With Widely +

[RFC1535] E. Gavron. A Security Problem and Proposed Correction With Widely Deployed DNS Software.. October 1993.

-

[RFC1536] A. Kumar, J. Postel, C. Neuman, P. Danzig, and S. Miller. Common DNS Implementation +

[RFC1536] A. Kumar, J. Postel, C. Neuman, P. Danzig, and S. Miller. Common DNS Implementation Errors and Suggested Fixes. October 1993.

-

[RFC1982] R. Elz and R. Bush. Serial Number Arithmetic. August 1996.

+

[RFC1982] R. Elz and R. Bush. Serial Number Arithmetic. August 1996.

-

[RFC4074] Y. Morishita and T. Jinmei. Common Misbehaviour Against DNS +

[RFC4074] Y. Morishita and T. Jinmei. Common Misbehaviour Against DNS Queries for IPv6 Addresses. May 2005.

Resource Record Types

-

[RFC1183] C.F. Everhart, L. A. Mamakos, R. Ullmann, and P. Mockapetris. New DNS RR Definitions. October 1990.

+

[RFC1183] C.F. Everhart, L. A. Mamakos, R. Ullmann, and P. Mockapetris. New DNS RR Definitions. October 1990.

-

[RFC1706] B. Manning and R. Colella. DNS NSAP Resource Records. October 1994.

+

[RFC1706] B. Manning and R. Colella. DNS NSAP Resource Records. October 1994.

-

[RFC2168] R. Daniel and M. Mealling. Resolution of Uniform Resource Identifiers using +

[RFC2168] R. Daniel and M. Mealling. Resolution of Uniform Resource Identifiers using the Domain Name System. June 1997.

-

[RFC1876] C. Davis, P. Vixie, T., and I. Dickinson. A Means for Expressing Location Information in the +

[RFC1876] C. Davis, P. Vixie, T., and I. Dickinson. A Means for Expressing Location Information in the Domain Name System. January 1996.

-

[RFC2052] A. Gulbrandsen and P. Vixie. A DNS RR for Specifying the +

[RFC2052] A. Gulbrandsen and P. Vixie. A DNS RR for Specifying the Location of Services.. October 1996.

-

[RFC2163] A. Allocchio. Using the Internet DNS to +

[RFC2163] A. Allocchio. Using the Internet DNS to Distribute MIXER Conformant Global Address Mapping. January 1998.

-

[RFC2230] R. Atkinson. Key Exchange Delegation Record for the DNS. October 1997.

+

[RFC2230] R. Atkinson. Key Exchange Delegation Record for the DNS. October 1997.

-

[RFC2536] D. Eastlake, 3rd. DSA KEYs and SIGs in the Domain Name System (DNS). March 1999.

+

[RFC2536] D. Eastlake, 3rd. DSA KEYs and SIGs in the Domain Name System (DNS). March 1999.

-

[RFC2537] D. Eastlake, 3rd. RSA/MD5 KEYs and SIGs in the Domain Name System (DNS). March 1999.

+

[RFC2537] D. Eastlake, 3rd. RSA/MD5 KEYs and SIGs in the Domain Name System (DNS). March 1999.

-

[RFC2538] D. Eastlake, 3rd and O. Gudmundsson. Storing Certificates in the Domain Name System (DNS). March 1999.

+

[RFC2538] D. Eastlake, 3rd and O. Gudmundsson. Storing Certificates in the Domain Name System (DNS). March 1999.

-

[RFC2539] D. Eastlake, 3rd. Storage of Diffie-Hellman Keys in the Domain Name System (DNS). March 1999.

+

[RFC2539] D. Eastlake, 3rd. Storage of Diffie-Hellman Keys in the Domain Name System (DNS). March 1999.

-

[RFC2540] D. Eastlake, 3rd. Detached Domain Name System (DNS) Information. March 1999.

+

[RFC2540] D. Eastlake, 3rd. Detached Domain Name System (DNS) Information. March 1999.

-

[RFC2782] A. Gulbrandsen. P. Vixie. L. Esibov. A DNS RR for specifying the location of services (DNS SRV). February 2000.

+

[RFC2782] A. Gulbrandsen. P. Vixie. L. Esibov. A DNS RR for specifying the location of services (DNS SRV). February 2000.

-

[RFC2915] M. Mealling. R. Daniel. The Naming Authority Pointer (NAPTR) DNS Resource Record. September 2000.

+

[RFC2915] M. Mealling. R. Daniel. The Naming Authority Pointer (NAPTR) DNS Resource Record. September 2000.

-

[RFC3110] D. Eastlake, 3rd. RSA/SHA-1 SIGs and RSA KEYs in the Domain Name System (DNS). May 2001.

+

[RFC3110] D. Eastlake, 3rd. RSA/SHA-1 SIGs and RSA KEYs in the Domain Name System (DNS). May 2001.

-

[RFC3123] P. Koch. A DNS RR Type for Lists of Address Prefixes (APL RR). June 2001.

+

[RFC3123] P. Koch. A DNS RR Type for Lists of Address Prefixes (APL RR). June 2001.

-

[RFC3596] S. Thomson, C. Huitema, V. Ksinant, and M. Souissi. DNS Extensions to support IP +

[RFC3596] S. Thomson, C. Huitema, V. Ksinant, and M. Souissi. DNS Extensions to support IP version 6. October 2003.

-

[RFC3597] A. Gustafsson. Handling of Unknown DNS Resource Record (RR) Types. September 2003.

+

[RFC3597] A. Gustafsson. Handling of Unknown DNS Resource Record (RR) Types. September 2003.

DNS and the Internet

-

[RFC1101] P. V. Mockapetris. DNS Encoding of Network Names +

[RFC1101] P. V. Mockapetris. DNS Encoding of Network Names and Other Types. April 1989.

-

[RFC1123] Braden. Requirements for Internet Hosts - Application and +

[RFC1123] Braden. Requirements for Internet Hosts - Application and Support. October 1989.

-

[RFC1591] J. Postel. Domain Name System Structure and Delegation. March 1994.

+

[RFC1591] J. Postel. Domain Name System Structure and Delegation. March 1994.

-

[RFC2317] H. Eidnes, G. de Groot, and P. Vixie. Classless IN-ADDR.ARPA Delegation. March 1998.

+

[RFC2317] H. Eidnes, G. de Groot, and P. Vixie. Classless IN-ADDR.ARPA Delegation. March 1998.

-

[RFC2826] Internet Architecture Board. IAB Technical Comment on the Unique DNS Root. May 2000.

+

[RFC2826] Internet Architecture Board. IAB Technical Comment on the Unique DNS Root. May 2000.

-

[RFC2929] D. Eastlake, 3rd, E. Brunner-Williams, and B. Manning. Domain Name System (DNS) IANA Considerations. September 2000.

+

[RFC2929] D. Eastlake, 3rd, E. Brunner-Williams, and B. Manning. Domain Name System (DNS) IANA Considerations. September 2000.

DNS Operations

-

[RFC1033] M. Lottor. Domain administrators operations guide.. November 1987.

+

[RFC1033] M. Lottor. Domain administrators operations guide.. November 1987.

-

[RFC1537] P. Beertema. Common DNS Data File +

[RFC1537] P. Beertema. Common DNS Data File Configuration Errors. October 1993.

-

[RFC1912] D. Barr. Common DNS Operational and +

[RFC1912] D. Barr. Common DNS Operational and Configuration Errors. February 1996.

-

[RFC2010] B. Manning and P. Vixie. Operational Criteria for Root Name Servers.. October 1996.

+

[RFC2010] B. Manning and P. Vixie. Operational Criteria for Root Name Servers.. October 1996.

-

[RFC2219] M. Hamilton and R. Wright. Use of DNS Aliases for +

[RFC2219] M. Hamilton and R. Wright. Use of DNS Aliases for Network Services.. October 1997.

Internationalized Domain Names

-

[RFC2825] IAB and R. Daigle. A Tangled Web: Issues of I18N, Domain Names, +

[RFC2825] IAB and R. Daigle. A Tangled Web: Issues of I18N, Domain Names, and the Other Internet protocols. May 2000.

-

[RFC3490] P. Faltstrom, P. Hoffman, and A. Costello. Internationalizing Domain Names in Applications (IDNA). March 2003.

+

[RFC3490] P. Faltstrom, P. Hoffman, and A. Costello. Internationalizing Domain Names in Applications (IDNA). March 2003.

-

[RFC3491] P. Hoffman and M. Blanchet. Nameprep: A Stringprep Profile for Internationalized Domain Names. March 2003.

+

[RFC3491] P. Hoffman and M. Blanchet. Nameprep: A Stringprep Profile for Internationalized Domain Names. March 2003.

-

[RFC3492] A. Costello. Punycode: A Bootstring encoding of Unicode +

[RFC3492] A. Costello. Punycode: A Bootstring encoding of Unicode for Internationalized Domain Names in Applications (IDNA). March 2003.

@@ -489,47 +489,47 @@

-

[RFC1464] R. Rosenbaum. Using the Domain Name System To Store Arbitrary String +

[RFC1464] R. Rosenbaum. Using the Domain Name System To Store Arbitrary String Attributes. May 1993.

-

[RFC1713] A. Romao. Tools for DNS Debugging. November 1994.

+

[RFC1713] A. Romao. Tools for DNS Debugging. November 1994.

-

[RFC1794] T. Brisco. DNS Support for Load +

[RFC1794] T. Brisco. DNS Support for Load Balancing. April 1995.

-

[RFC2240] O. Vaughan. A Legal Basis for Domain Name Allocation. November 1997.

+

[RFC2240] O. Vaughan. A Legal Basis for Domain Name Allocation. November 1997.

-

[RFC2345] J. Klensin, T. Wolf, and G. Oglesby. Domain Names and Company Name Retrieval. May 1998.

+

[RFC2345] J. Klensin, T. Wolf, and G. Oglesby. Domain Names and Company Name Retrieval. May 1998.

-

[RFC2352] O. Vaughan. A Convention For Using Legal Names as Domain Names. May 1998.

+

[RFC2352] O. Vaughan. A Convention For Using Legal Names as Domain Names. May 1998.

-

[RFC3071] J. Klensin. Reflections on the DNS, RFC 1591, and Categories of Domains. February 2001.

+

[RFC3071] J. Klensin. Reflections on the DNS, RFC 1591, and Categories of Domains. February 2001.

-

[RFC3258] T. Hardie. Distributing Authoritative Name Servers via +

[RFC3258] T. Hardie. Distributing Authoritative Name Servers via Shared Unicast Addresses. April 2002.

-

[RFC3901] A. Durand and J. Ihren. DNS IPv6 Transport Operational Guidelines. September 2004.

+

[RFC3901] A. Durand and J. Ihren. DNS IPv6 Transport Operational Guidelines. September 2004.

Obsolete and Unimplemented Experimental RFC

-

[RFC1712] C. Farrell, M. Schulze, S. Pleitner, and D. Baldoni. DNS Encoding of Geographical +

[RFC1712] C. Farrell, M. Schulze, S. Pleitner, and D. Baldoni. DNS Encoding of Geographical Location. November 1994.

-

[RFC2673] M. Crawford. Binary Labels in the Domain Name System. August 1999.

+

[RFC2673] M. Crawford. Binary Labels in the Domain Name System. August 1999.

-

[RFC2874] M. Crawford and C. Huitema. DNS Extensions to Support IPv6 Address Aggregation +

[RFC2874] M. Crawford and C. Huitema. DNS Extensions to Support IPv6 Address Aggregation and Renumbering. July 2000.

@@ -543,39 +543,39 @@

-

[RFC2065] D. Eastlake, 3rd and C. Kaufman. Domain Name System Security Extensions. January 1997.

+

[RFC2065] D. Eastlake, 3rd and C. Kaufman. Domain Name System Security Extensions. January 1997.

-

[RFC2137] D. Eastlake, 3rd. Secure Domain Name System Dynamic Update. April 1997.

+

[RFC2137] D. Eastlake, 3rd. Secure Domain Name System Dynamic Update. April 1997.

-

[RFC2535] D. Eastlake, 3rd. Domain Name System Security Extensions. March 1999.

+

[RFC2535] D. Eastlake, 3rd. Domain Name System Security Extensions. March 1999.

-

[RFC3008] B. Wellington. Domain Name System Security (DNSSEC) +

[RFC3008] B. Wellington. Domain Name System Security (DNSSEC) Signing Authority. November 2000.

-

[RFC3090] E. Lewis. DNS Security Extension Clarification on Zone Status. March 2001.

+

[RFC3090] E. Lewis. DNS Security Extension Clarification on Zone Status. March 2001.

-

[RFC3445] D. Massey and S. Rose. Limiting the Scope of the KEY Resource Record (RR). December 2002.

+

[RFC3445] D. Massey and S. Rose. Limiting the Scope of the KEY Resource Record (RR). December 2002.

-

[RFC3655] B. Wellington and O. Gudmundsson. Redefinition of DNS Authenticated Data (AD) bit. November 2003.

+

[RFC3655] B. Wellington and O. Gudmundsson. Redefinition of DNS Authenticated Data (AD) bit. November 2003.

-

[RFC3658] O. Gudmundsson. Delegation Signer (DS) Resource Record (RR). December 2003.

+

[RFC3658] O. Gudmundsson. Delegation Signer (DS) Resource Record (RR). December 2003.

-

[RFC3755] S. Weiler. Legacy Resolver Compatibility for Delegation Signer (DS). May 2004.

+

[RFC3755] S. Weiler. Legacy Resolver Compatibility for Delegation Signer (DS). May 2004.

-

[RFC3757] O. Kolkman, J. Schlyter, and E. Lewis. Domain Name System KEY (DNSKEY) Resource Record +

[RFC3757] O. Kolkman, J. Schlyter, and E. Lewis. Domain Name System KEY (DNSKEY) Resource Record (RR) Secure Entry Point (SEP) Flag. April 2004.

-

[RFC3845] J. Schlyter. DNS Security (DNSSEC) NextSECure (NSEC) RDATA Format. August 2004.

+

[RFC3845] J. Schlyter. DNS Security (DNSSEC) NextSECure (NSEC) RDATA Format. August 2004.

@@ -596,14 +596,14 @@

-Other Documents About BIND +Other Documents About BIND

-Bibliography

+Bibliography
-

Paul Albitz and Cricket Liu. DNS and BIND. Copyright © 1998 Sebastopol, CA: O'Reilly and Associates.

+

Paul Albitz and Cricket Liu. DNS and BIND. Copyright © 1998 Sebastopol, CA: O'Reilly and Associates.

diff --git a/doc/arm/Bv9ARM.html b/doc/arm/Bv9ARM.html index 5806f0edc0..27da600ada 100644 --- a/doc/arm/Bv9ARM.html +++ b/doc/arm/Bv9ARM.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -154,61 +154,61 @@
options Statement Definition and Usage
statistics-channels Statement Grammar
-
statistics-channels Statement Definition and +
statistics-channels Statement Definition and Usage
server Statement Grammar
server Statement Definition and Usage
-
trusted-keys Statement Grammar
-
trusted-keys Statement Definition +
trusted-keys Statement Grammar
+
trusted-keys Statement Definition and Usage
view Statement Grammar
-
view Statement Definition and Usage
+
view Statement Definition and Usage
zone Statement Grammar
-
zone Statement Definition and Usage
+
zone Statement Definition and Usage
-
Zone File
+
Zone File
Types of Resource Records and When to Use Them
-
Discussion of MX Records
+
Discussion of MX Records
Setting TTLs
-
Inverse Mapping in IPv4
-
Other Zone File Directives
-
BIND Master File Extension: the $GENERATE Directive
+
Inverse Mapping in IPv4
+
Other Zone File Directives
+
BIND Master File Extension: the $GENERATE Directive
Additional File Formats
-
BIND9 Statistics
-
Statistics Counters
+
BIND9 Statistics
+
Statistics Counters
7. BIND 9 Security Considerations
Access Control Lists
-
Chroot and Setuid
+
Chroot and Setuid
-
The chroot Environment
-
Using the setuid Function
+
The chroot Environment
+
Using the setuid Function
Dynamic Update Security
8. Troubleshooting
-
Common Problems
-
It's not working; how can I figure out what's wrong?
-
Incrementing and Changing the Serial Number
-
Where Can I Get Help?
+
Common Problems
+
It's not working; how can I figure out what's wrong?
+
Incrementing and Changing the Serial Number
+
Where Can I Get Help?
A. Appendices
-
Acknowledgments
+
Acknowledgments
A Brief History of the DNS and BIND
-
General DNS Reference Information
+
General DNS Reference Information
IPv6 addresses (AAAA)
Bibliography (and Suggested Reading)
Request for Comments (RFCs)
Internet Drafts
-
Other Documents About BIND
+
Other Documents About BIND
I. Manual pages
diff --git a/doc/arm/man.dig.html b/doc/arm/man.dig.html index 769c6e0a94..82807a3f88 100644 --- a/doc/arm/man.dig.html +++ b/doc/arm/man.dig.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -52,7 +52,7 @@

dig [global-queryopt...] [query...]

-

DESCRIPTION

+

DESCRIPTION

dig (domain information groper) is a flexible tool for interrogating DNS name servers. It performs DNS lookups and @@ -98,7 +98,7 @@

-

SIMPLE USAGE

+

SIMPLE USAGE

A typical invocation of dig looks like:

@@ -144,7 +144,7 @@

-

OPTIONS

+

OPTIONS

The -b option sets the source IP address of the query to address. This must be a valid @@ -244,7 +244,7 @@

-

QUERY OPTIONS

+

QUERY OPTIONS

dig provides a number of query options which affect the way in which lookups are made and the results displayed. Some of @@ -563,7 +563,7 @@

-

MULTIPLE QUERIES

+

MULTIPLE QUERIES

The BIND 9 implementation of dig supports @@ -609,7 +609,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

IDN SUPPORT

+

IDN SUPPORT

If dig has been built with IDN (internationalized domain name) support, it can accept and display non-ASCII domain names. @@ -623,14 +623,14 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

FILES

+

FILES

/etc/resolv.conf

${HOME}/.digrc

-

SEE ALSO

+

SEE ALSO

host(1), named(8), dnssec-keygen(8), @@ -638,7 +638,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

BUGS

+

BUGS

There are probably too many query options.

diff --git a/doc/arm/man.dnssec-keyfromlabel.html b/doc/arm/man.dnssec-keyfromlabel.html index 7bd379a4f3..36402ba241 100644 --- a/doc/arm/man.dnssec-keyfromlabel.html +++ b/doc/arm/man.dnssec-keyfromlabel.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

dnssec-keyfromlabel {-a algorithm} {-l label} [-c class] [-f flag] [-k] [-n nametype] [-p protocol] [-t type] [-v level] {name}

-

DESCRIPTION

+

DESCRIPTION

dnssec-keyfromlabel gets keys with the given label from a crypto hardware and builds key files for DNSSEC (Secure DNS), as defined in RFC 2535 @@ -58,7 +58,7 @@

-

OPTIONS

+

OPTIONS

-a algorithm
@@ -131,7 +131,7 @@
-

GENERATED KEY FILES

+

GENERATED KEY FILES

When dnssec-keyfromlabel completes successfully, @@ -172,7 +172,7 @@

-

SEE ALSO

+

SEE ALSO

dnssec-keygen(8), dnssec-signzone(8), BIND 9 Administrator Reference Manual, @@ -182,7 +182,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.dnssec-keygen.html b/doc/arm/man.dnssec-keygen.html index 2d03664656..36feca6841 100644 --- a/doc/arm/man.dnssec-keygen.html +++ b/doc/arm/man.dnssec-keygen.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

dnssec-keygen {-a algorithm} {-b keysize} {-n nametype} [-c class] [-e] [-f flag] [-g generator] [-h] [-k] [-p protocol] [-r randomdev] [-s strength] [-t type] [-v level] {name}

-

DESCRIPTION

+

DESCRIPTION

dnssec-keygen generates keys for DNSSEC (Secure DNS), as defined in RFC 2535 and RFC 4034. It can also generate keys for use with @@ -58,7 +58,7 @@

-

OPTIONS

+

OPTIONS

-a algorithm
@@ -166,7 +166,7 @@
-

GENERATED KEYS

+

GENERATED KEYS

When dnssec-keygen completes successfully, @@ -212,7 +212,7 @@

-

EXAMPLE

+

EXAMPLE

To generate a 768-bit DSA key for the domain example.com, the following command would be @@ -233,7 +233,7 @@

-

SEE ALSO

+

SEE ALSO

dnssec-signzone(8), BIND 9 Administrator Reference Manual, RFC 2535, @@ -242,7 +242,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.dnssec-signzone.html b/doc/arm/man.dnssec-signzone.html index 200cc8d706..5e41a9727a 100644 --- a/doc/arm/man.dnssec-signzone.html +++ b/doc/arm/man.dnssec-signzone.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

dnssec-signzone [-a] [-c class] [-d directory] [-e end-time] [-f output-file] [-g] [-h] [-k key] [-l domain] [-i interval] [-I input-format] [-j jitter] [-N soa-serial-format] [-o origin] [-O output-format] [-p] [-r randomdev] [-s start-time] [-t] [-v level] [-z] {zonefile} [key...]

-

DESCRIPTION

+

DESCRIPTION

dnssec-signzone signs a zone. It generates NSEC and RRSIG records and produces a signed version of the @@ -61,7 +61,7 @@

-

OPTIONS

+

OPTIONS

-a

@@ -259,7 +259,7 @@

-

EXAMPLE

+

EXAMPLE

The following command signs the example.com zone with the DSA key generated by dnssec-keygen @@ -288,14 +288,14 @@ db.example.com.signed %

-

SEE ALSO

+

SEE ALSO

dnssec-keygen(8), BIND 9 Administrator Reference Manual, RFC 2535.

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.host.html b/doc/arm/man.host.html index 0c445e60d7..957831fa6e 100644 --- a/doc/arm/man.host.html +++ b/doc/arm/man.host.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

host [-aCdlnrsTwv] [-c class] [-N ndots] [-R number] [-t type] [-W wait] [-m flag] [-4] [-6] {name} [server]

-

DESCRIPTION

+

DESCRIPTION

host is a simple utility for performing DNS lookups. It is normally used to convert names to IP addresses and vice versa. @@ -202,7 +202,7 @@

-

IDN SUPPORT

+

IDN SUPPORT

If host has been built with IDN (internationalized domain name) support, it can accept and display non-ASCII domain names. @@ -216,12 +216,12 @@

-

FILES

+

FILES

/etc/resolv.conf

-

SEE ALSO

+

SEE ALSO

dig(1), named(8).

diff --git a/doc/arm/man.named-checkconf.html b/doc/arm/man.named-checkconf.html index f7619ca3bf..5ede46471a 100644 --- a/doc/arm/man.named-checkconf.html +++ b/doc/arm/man.named-checkconf.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,14 +50,14 @@

named-checkconf [-h] [-v] [-j] [-t directory] {filename} [-z]

-

DESCRIPTION

+

DESCRIPTION

named-checkconf checks the syntax, but not the semantics, of a named configuration file.

-

OPTIONS

+

OPTIONS

-h

@@ -92,21 +92,21 @@

-

RETURN VALUES

+

RETURN VALUES

named-checkconf returns an exit status of 1 if errors were detected and 0 otherwise.

-

SEE ALSO

+

SEE ALSO

named(8), named-checkzone(8), BIND 9 Administrator Reference Manual.

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.named-checkzone.html b/doc/arm/man.named-checkzone.html index 265be7d132..a3b03c8915 100644 --- a/doc/arm/man.named-checkzone.html +++ b/doc/arm/man.named-checkzone.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -51,7 +51,7 @@

named-compilezone [-d] [-j] [-q] [-v] [-c class] [-C mode] [-f format] [-F format] [-i mode] [-k mode] [-m mode] [-n mode] [-o filename] [-s style] [-t directory] [-w directory] [-D] [-W mode] {zonename} {filename}

-

DESCRIPTION

+

DESCRIPTION

named-checkzone checks the syntax and integrity of a zone file. It performs the same checks as named does when loading a @@ -71,7 +71,7 @@

-

OPTIONS

+

OPTIONS

-d

@@ -257,14 +257,14 @@

-

RETURN VALUES

+

RETURN VALUES

named-checkzone returns an exit status of 1 if errors were detected and 0 otherwise.

-

SEE ALSO

+

SEE ALSO

named(8), named-checkconf(8), RFC 1035, @@ -272,7 +272,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.named.html b/doc/arm/man.named.html index 78ca9f584a..ab5337e499 100644 --- a/doc/arm/man.named.html +++ b/doc/arm/man.named.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

named [-4] [-6] [-c config-file] [-d debug-level] [-f] [-g] [-m flag] [-n #cpus] [-p port] [-s] [-t directory] [-u user] [-v] [-x cache-file]

-

DESCRIPTION

+

DESCRIPTION

named is a Domain Name System (DNS) server, part of the BIND 9 distribution from ISC. For more @@ -65,7 +65,7 @@

-

OPTIONS

+

OPTIONS

-4

@@ -209,7 +209,7 @@

-

SIGNALS

+

SIGNALS

In routine operation, signals should not be used to control the nameserver; rndc should be used @@ -230,7 +230,7 @@

-

CONFIGURATION

+

CONFIGURATION

The named configuration file is too complex to describe in detail here. A complete description is provided @@ -239,7 +239,7 @@

-

FILES

+

FILES

/etc/named.conf

@@ -252,7 +252,7 @@

-

SEE ALSO

+

SEE ALSO

RFC 1033, RFC 1034, RFC 1035, @@ -265,7 +265,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.rndc-confgen.html b/doc/arm/man.rndc-confgen.html index 6437f79210..faea48f07a 100644 --- a/doc/arm/man.rndc-confgen.html +++ b/doc/arm/man.rndc-confgen.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -48,7 +48,7 @@

rndc-confgen [-a] [-b keysize] [-c keyfile] [-h] [-k keyname] [-p port] [-r randomfile] [-s address] [-t chrootdir] [-u user]

-

DESCRIPTION

+

DESCRIPTION

rndc-confgen generates configuration files for rndc. It can be used as a @@ -64,7 +64,7 @@

-

OPTIONS

+

OPTIONS

-a
@@ -171,7 +171,7 @@
-

EXAMPLES

+

EXAMPLES

To allow rndc to be used with no manual configuration, run @@ -188,7 +188,7 @@

-

SEE ALSO

+

SEE ALSO

rndc(8), rndc.conf(5), named(8), @@ -196,7 +196,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.rndc.conf.html b/doc/arm/man.rndc.conf.html index 6f38883b62..55f5378d91 100644 --- a/doc/arm/man.rndc.conf.html +++ b/doc/arm/man.rndc.conf.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

rndc.conf

-

DESCRIPTION

+

DESCRIPTION

rndc.conf is the configuration file for rndc, the BIND 9 name server control utility. This file has a similar structure and syntax to @@ -135,7 +135,7 @@

-

EXAMPLE

+

EXAMPLE

       options {
         default-server  localhost;
@@ -209,7 +209,7 @@
     

-

NAME SERVER CONFIGURATION

+

NAME SERVER CONFIGURATION

The name server must be configured to accept rndc connections and to recognize the key specified in the rndc.conf @@ -219,7 +219,7 @@

-

SEE ALSO

+

SEE ALSO

rndc(8), rndc-confgen(8), mmencode(1), @@ -227,7 +227,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.rndc.html b/doc/arm/man.rndc.html index 0b970bf649..ffe4ab90fc 100644 --- a/doc/arm/man.rndc.html +++ b/doc/arm/man.rndc.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

rndc [-b source-address] [-c config-file] [-k key-file] [-s server] [-p port] [-V] [-y key_id] {command}

-

DESCRIPTION

+

DESCRIPTION

rndc controls the operation of a name server. It supersedes the ndc utility @@ -79,7 +79,7 @@

-

OPTIONS

+

OPTIONS

-b source-address

@@ -151,7 +151,7 @@

-

LIMITATIONS

+

LIMITATIONS

rndc does not yet support all the commands of the BIND 8 ndc utility. @@ -165,7 +165,7 @@

-

SEE ALSO

+

SEE ALSO

rndc.conf(5), rndc-confgen(8), named(8), @@ -175,7 +175,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

From 6101a43bde7f30f2143c1219073986f85e8bc3bc Mon Sep 17 00:00:00 2001 From: Francis Dupont Date: Wed, 7 May 2008 12:27:43 +0000 Subject: [PATCH 059/137] update own branches comments --- doc/private/branches | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/doc/private/branches b/doc/private/branches index 90d9bd799c..810be97e6e 100644 --- a/doc/private/branches +++ b/doc/private/branches @@ -91,7 +91,7 @@ rt17374 open each // 2007-12-19 05:51 +0000 rt17375 open each // 2007-12-20 16:47 +0000 rt17435 new rt17441 new marka // 2008-01-08 03:41 +0000 -rt17451 new fdupont // 2008-03-17 13:44 +0000 +rt17451 new fdupont // Delete RB tree order rt17455 new each // 2008-01-10 00:20 +0000 rt17460 new marka // 2008-01-11 03:44 +0000 rt17462 new each // 2008-01-11 17:47 +0000 @@ -117,8 +117,8 @@ rt17828 new marka // 2008-04-09 23:06 +0000 rt17949 new rt17977 new each // 2008-04-23 00:29 +0000 rt18018 new -rt18020 new fdupont // 2008-05-01 07:57 +0000 -rt18033 new fdupont // 2008-05-06 15:54 +0000 +rt18020 new fdupont // FIPS 140-2 +rt18033 new fdupont // HSM maintenance shane_dbbackend open skan open explorer skan-metazones1 private explorer From 252ad65e4664099b666914075c6075c84ad1d513 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Wed, 7 May 2008 23:18:32 +0000 Subject: [PATCH 060/137] auto update --- doc/private/branches | 1 + 1 file changed, 1 insertion(+) diff --git a/doc/private/branches b/doc/private/branches index 810be97e6e..cd34d3ad9f 100644 --- a/doc/private/branches +++ b/doc/private/branches @@ -81,6 +81,7 @@ rt17138 open marka // 2007-09-11 01:39 +0000 rt17146 open rt17151 open marka // 2007-09-18 00:34 +0000 rt17214 review jakob +rt17214b new each // 2008-05-07 00:27 +0000 rt17224 new marka // 2008-02-08 04:24 +0000 rt17261 new marka // 2008-01-22 13:29 +0000 rt1727 open // ixfr-from-differences workfile From 88dbebcebcc4ecb838c54c03a0193223809fed8c Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Thu, 8 May 2008 23:18:14 +0000 Subject: [PATCH 061/137] auto update --- doc/private/branches | 1 + 1 file changed, 1 insertion(+) diff --git a/doc/private/branches b/doc/private/branches index cd34d3ad9f..090861a0e0 100644 --- a/doc/private/branches +++ b/doc/private/branches @@ -120,6 +120,7 @@ rt17977 new each // 2008-04-23 00:29 +0000 rt18018 new rt18020 new fdupont // FIPS 140-2 rt18033 new fdupont // HSM maintenance +rt18040 new marka // 2008-05-08 02:25 +0000 shane_dbbackend open skan open explorer skan-metazones1 private explorer From 6fbe9050cb09f6534373c05dbab03a4bd2eb1cce Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Fri, 9 May 2008 23:18:12 +0000 Subject: [PATCH 062/137] auto update --- doc/private/branches | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/doc/private/branches b/doc/private/branches index 090861a0e0..86a3a8498f 100644 --- a/doc/private/branches +++ b/doc/private/branches @@ -116,11 +116,16 @@ rt17729 new marka // 2008-03-06 03:56 +0000 rt17729a new marka // 2008-04-02 23:40 +0000 rt17828 new marka // 2008-04-09 23:06 +0000 rt17949 new +rt17949_v9_3 new +rt17949_v9_4 new +rt17949_v9_5 new rt17977 new each // 2008-04-23 00:29 +0000 rt18018 new rt18020 new fdupont // FIPS 140-2 rt18033 new fdupont // HSM maintenance rt18040 new marka // 2008-05-08 02:25 +0000 +rt18042 new fdupont // 2008-05-09 13:27 +0000 +rt18046 new fdupont // 2008-05-09 06:56 +0000 shane_dbbackend open skan open explorer skan-metazones1 private explorer From e1aeb1569a0ae08c97dd76acb00376e4246e59b8 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 12 May 2008 00:17:27 +0000 Subject: [PATCH 063/137] 2369. [bug] libbind: Array bounds overrun on read in bitncmp(). [RT #18054] --- CHANGES | 3 +++ lib/bind/isc/bitncmp.c | 4 ++-- 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/CHANGES b/CHANGES index ce24256a99..6164c3a838 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +2369. [bug] libbind: Array bounds overrun on read in bitncmp(). + [RT #18054] + 2368. [port] Linux: use libcap for capability management if possible. [RT# 18026] diff --git a/lib/bind/isc/bitncmp.c b/lib/bind/isc/bitncmp.c index 7f9a55f19e..06d3188c88 100644 --- a/lib/bind/isc/bitncmp.c +++ b/lib/bind/isc/bitncmp.c @@ -16,7 +16,7 @@ */ #if defined(LIBC_SCCS) && !defined(lint) -static const char rcsid[] = "$Id: bitncmp.c,v 1.3 2005/04/27 04:56:35 sra Exp $"; +static const char rcsid[] = "$Id: bitncmp.c,v 1.4 2008/05/12 00:17:27 marka Exp $"; #endif #include "port_before.h" @@ -48,7 +48,7 @@ bitncmp(const void *l, const void *r, int n) { b = n / 8; x = memcmp(l, r, b); - if (x) + if (x || (n % 8) == 0) return (x); lb = ((const u_char *)l)[b]; From 2a5780de8aca5363b4b2ea1d3687d32c0579e514 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 12 May 2008 00:20:16 +0000 Subject: [PATCH 064/137] 2369. [bug] libbind: Array bounds overrun on read in bitncmp(). [RT #18054] --- CHANGES | 3 +++ lib/bind/isc/bitncmp.c | 4 ++-- 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/CHANGES b/CHANGES index f9709c9e12..aee148a07d 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +2369. [bug] libbind: Array bounds overrun on read in bitncmp(). + [RT #18054] + 2364. [bug] named could trigger a assertion when serving a malformed signed zone. [RT #17828] diff --git a/lib/bind/isc/bitncmp.c b/lib/bind/isc/bitncmp.c index fcff9f71ed..35b570b45f 100644 --- a/lib/bind/isc/bitncmp.c +++ b/lib/bind/isc/bitncmp.c @@ -16,7 +16,7 @@ */ #if defined(LIBC_SCCS) && !defined(lint) -static const char rcsid[] = "$Id: bitncmp.c,v 1.1.206.1 2004/03/09 08:33:39 marka Exp $"; +static const char rcsid[] = "$Id: bitncmp.c,v 1.1.206.2 2008/05/12 00:20:16 marka Exp $"; #endif #include "port_before.h" @@ -48,7 +48,7 @@ bitncmp(const void *l, const void *r, int n) { b = n / 8; x = memcmp(l, r, b); - if (x) + if (x || (n % 8) == 0) return (x); lb = ((const u_char *)l)[b]; From b0ce139d9f238acbacf45e880f11e22379d231cd Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Mon, 12 May 2008 23:30:04 +0000 Subject: [PATCH 065/137] newcopyrights --- util/copyrights | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/util/copyrights b/util/copyrights index baf5fbfcdf..261cd8b31f 100644 --- a/util/copyrights +++ b/util/copyrights @@ -1361,7 +1361,7 @@ ./lib/bind/isc/assertions.c X 2001,2004 ./lib/bind/isc/assertions.mdoc X 2001,2003,2004 ./lib/bind/isc/base64.c X 2001,2004 -./lib/bind/isc/bitncmp.c X 2001,2004 +./lib/bind/isc/bitncmp.c X 2001,2004,2008 ./lib/bind/isc/bitncmp.mdoc X 2001,2003,2004 ./lib/bind/isc/ctl_clnt.c X 2001,2003,2004,2007,2008 ./lib/bind/isc/ctl_p.c X 2001,2004 From cfe548a265ec948a191174ead4ec97c0d699dfa0 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Mon, 12 May 2008 23:30:21 +0000 Subject: [PATCH 066/137] newcopyrights --- util/copyrights | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/util/copyrights b/util/copyrights index 2ff09d03ca..9d0906d240 100644 --- a/util/copyrights +++ b/util/copyrights @@ -1480,7 +1480,7 @@ ./lib/bind/isc/assertions.c X 2001,2004,2005 ./lib/bind/isc/assertions.mdoc X 2001,2004 ./lib/bind/isc/base64.c X 2001,2004,2005 -./lib/bind/isc/bitncmp.c X 2001,2004,2005 +./lib/bind/isc/bitncmp.c X 2001,2004,2005,2008 ./lib/bind/isc/bitncmp.mdoc X 2001,2004 ./lib/bind/isc/ctl_clnt.c X 2001,2003,2004,2005,2007,2008 ./lib/bind/isc/ctl_p.c X 2001,2004,2005 From 68cd13fff2b45c8a941ed8ac3efa0698798dcc96 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Tue, 13 May 2008 00:20:54 +0000 Subject: [PATCH 067/137] spelling --- CHANGES | 170 ++++++++++++++++++++++++++++---------------------------- 1 file changed, 85 insertions(+), 85 deletions(-) diff --git a/CHANGES b/CHANGES index 6164c3a838..bb524883f8 100644 --- a/CHANGES +++ b/CHANGES @@ -35,13 +35,13 @@ 2357. [port] Don't use OpenSSL's engine support in versions before OpenSSL 0.9.7f. [RT #17922] -2356. [bug] Builtin mutex profiler was not scalable enough. +2356. [bug] Built in mutex profiler was not scalable enough. [RT #17436] 2355. [func] Extend the number statistics counters available. [RT #17590] -2354. [bug] Failed to initialise sone rdatasetheader_t elements. +2354. [bug] Failed to initialize some rdatasetheader_t elements. [RT #17927] 2353. [func] Add support for Name Server ID (RFC 5001). @@ -128,7 +128,7 @@ M.ROOT-SERVERS.NET. 2327. [bug] It was possible to dereference a NULL pointer in - rbtdb.c. Implement deadnode processing in zones as + rbtdb.c. Implement dead node processing in zones as we do for caches. [RT #17312] 2326. [bug] It was possible to trigger a INSIST in the acache @@ -145,7 +145,7 @@ 2321. [placeholder] -2320. [func] Make statistics couters thread-safe for platforms +2320. [func] Make statistics counters thread-safe for platforms that support certain atomic operations. [RT #17466] 2319. [bug] Silence Coverity warnings in @@ -222,7 +222,7 @@ multiple connections and ACL. Note: the stats-server and stats-server-v6 options available in the previous beta releases are replaced - with the generic statistics-channels statment. + with the generic statistics-channels statement. 2293. [func] Add ACL regression test. [RT #17375] @@ -272,7 +272,7 @@ SIGPIPE signals when using the resolver. 2278. [bug] win32: handle the case where Windows returns no - searchlist or DNS suffix. [RT #17354] + search list or DNS suffix. [RT #17354] 2277. [bug] Empty zone names were not correctly being caught at in the post parse checks. [RT #17357] @@ -284,7 +284,7 @@ 2274. [func] Log zone transfer statistics. [RT #17336] -2273. [bug] Adjust log level to WARNING when saving inconsistant +2273. [bug] Adjust log level to WARNING when saving inconsistent stub/slave master and journal files. [RT# 17279] 2272. [bug] Handle illegal dnssec-lookaside trust-anchor names. @@ -381,7 +381,7 @@ library could require a source of random data. [RT #17127] -2241. [func] nsupdate: add a interative 'help' command. [RT #17099] +2241. [func] nsupdate: add a interactive 'help' command. [RT #17099] 2240. [bug] Cleanup nsupdates GSS-TSIG support. Convert a number of INSIST()s into plain fatal() errors @@ -389,10 +389,10 @@ The 'key' command wasn't disabling GSS-TSIG. [RT #17099] -2239. [func] Ship a prebuilt bin/named/bind9.xsl.h. [RT #17114] +2239. [func] Ship a pre built bin/named/bind9.xsl.h. [RT #17114] 2238. [bug] It was possible to trigger a REQUIRE when a - validation was cancelled. [RT #17106] + validation was canceled. [RT #17106] 2237. [bug] libbind: res_init() was not thread aware. [RT #17123] @@ -404,8 +404,8 @@ 2234. [port] Correct some compiler warnings on SCO OSr5 [RT #17134] 2233. [func] Add support for O(1) ACL processing, based on - radix tree code originally written by kevin - brintnall. [RT #16288] + radix tree code originally written by Kevin + Brintnall. [RT #16288] 2232. [bug] dns_adb_findaddrinfo() could fail and return ISC_R_SUCCESS. [RT #17137] @@ -444,7 +444,7 @@ 2220. [bug] win32: Address a race condition in final shutdown of the Windows socket code. [RT #17028] -2219. [bug] Apply zone consistancy checks to additions, not +2219. [bug] Apply zone consistency checks to additions, not removals, when updating. [RT #17049] 2218. [bug] Remove unnecessary REQUIRE from dns_validator_create(). @@ -562,7 +562,7 @@ 2187. [bug] query_addds(), query_addwildcardproof() and query_addnxrrsetnsec() should take a version - arguement. [RT #16368] + argument. [RT #16368] 2186. [port] cygwin: libbind: check for struct sockaddr_storage independently of IPv6. [RT #16482] @@ -595,7 +595,7 @@ debug level 10+. [RT #16798] 2176. [contrib] dbus update to handle race condition during - initialisation (Bugzilla 235809). [RT #16842] + initialization (Bugzilla 235809). [RT #16842] 2175. [bug] win32: windows broadcast condition variable support was broken. [RT #16592] @@ -659,7 +659,7 @@ 2159. [bug] Array bounds overrun in acache processing. [RT #16710] -2158. [bug] ns_client_isself() failed to initialise key +2158. [bug] ns_client_isself() failed to initialize key leading to a REQUIRE failure. [RT #16688] 2157. [func] dns_db_transfernode() created. [RT #16685] @@ -730,7 +730,7 @@ 2136. [bug] nslookup/host looped if there was no search list and the host didn't exist. [RT #16657] -2135. [bug] Uninitialised rdataset in sdlz.c. [RT# 16656] +2135. [bug] Uninitialized rdataset in sdlz.c. [RT# 16656] 2134. [func] Additional statistics support. [RT #16666] @@ -752,7 +752,7 @@ 2127. [port] Improved OpenSSL 0.9.8 support. [RT #16563] -2126. [security] Serialise validation of type ANY responses. [RT #16555] +2126. [security] Serialize validation of type ANY responses. [RT #16555] 2125. [bug] dns_zone_getzeronosoattl() REQUIRE failure if DLZ was defined. [RT #16574] @@ -762,7 +762,7 @@ --- 9.5.0a1 released --- -2123. [func] Use Doxygen to generate internal documention. +2123. [func] Use Doxygen to generate internal documentation. [RT #11398] 2122. [func] Experimental http server and statistics support @@ -823,7 +823,7 @@ 2103. [port] Add /usr/sfw to list of locations for OpenSSL under Solaris. -2102. [port] Silence solaris 10 warnings. +2102. [port] Silence Solaris 10 warnings. 2101. [bug] OpenSSL version checks were not quite right. [RT #16476] @@ -831,7 +831,7 @@ 2100. [port] win32: copy libeay32.dll to Build\Debug. Copy Debug\named-checkzone to Debug\named-compilezone. -2099. [port] win32: more manifiest issues. +2099. [port] win32: more manifest issues. 2098. [bug] Race in rbtdb.c:no_references(), which occasionally triggered an INSIST failure about the node lock @@ -893,7 +893,7 @@ 2078. [bug] dnssec-checkzone output style "default" was badly named. It is now called "relative". [RT #16326] -2077. [bug] 'dnssec-signzone -O raw' wasn't outputing the +2077. [bug] 'dnssec-signzone -O raw' wasn't outputting the complete signed zone. [RT #16326] 2076. [bug] Several files were missing #include @@ -976,7 +976,7 @@ [RT #16287] 2049. [bug] Restore SOA before AXFR when falling back from - a attempted IXFR when transfering in a zone. + a attempted IXFR when transferring in a zone. Allow a initial SOA query before attempting a AXFR to be requested. [RT #16156] @@ -985,7 +985,7 @@ the OS always returned the same local port. [RT #16182] -2047. [bug] Failed to initialise the interface flags to zero. +2047. [bug] Failed to initialize the interface flags to zero. [RT #16245] 2046. [bug] rbtdb.c:rdataset_setadditional() could cause duplicate @@ -1029,7 +1029,7 @@ 2034. [bug] gcc: set -fno-strict-aliasing. [RT #16124] -2033. [bug] We wern't creating multiple client memory contexts +2033. [bug] We weren't creating multiple client memory contexts on demand as expected. [RT #16095] 2032. [bug] Remove a INSIST in query_addadditional2(). [RT #16074] @@ -1043,7 +1043,7 @@ 2029. [bug] host printed out the server multiple times when specified on the command line. [RT #15992] -2028. [port] linux: socket.c compatability for old systems. +2028. [port] linux: socket.c compatibility for old systems. [RT #16015] 2027. [port] libbind: Solaris x86 support. [RT #16020] @@ -1053,7 +1053,7 @@ 2025. [func] Update "zone serial unchanged" message. [RT #16026] -2024. [bug] named emited spurious "zone serial unchanged" +2024. [bug] named emitted spurious "zone serial unchanged" messages on reload. [RT #16027] 2023. [bug] "make install" should create ${localstatedir}/run and @@ -1079,7 +1079,7 @@ to the original qname. [RT #15945] 2015. [cleanup] use-additional-cache is now acache-enable for - consistancy. Default acache-enable off in BIND 9.4 + consistency. Default acache-enable off in BIND 9.4 as it requires memory usage to be configured. It may be enabled by default in BIND 9.5 once we have more experience with it. @@ -1099,9 +1099,9 @@ 2010. [placeholder] rt15958 -2009. [bug] libbind: coverity fixes. [RT #15808] +2009. [bug] libbind: Coverity fixes. [RT #15808] -2008. [func] It is now posssible to enable/disable DNSSEC +2008. [func] It is now possible to enable/disable DNSSEC validation from rndc. This is useful for the mobile hosts where the current connection point breaks DNSSEC (firewall/proxy). [RT #15592] @@ -1113,7 +1113,7 @@ be changed to yes in 9.5.0. [RT #15674] 2006. [security] Allow-query-cache and allow-recursion now default - to the builtin acls "localnets" and "localhost". + to the built in acls "localnets" and "localhost". This is being done to make caching servers less attractive as reflective amplifying targets for @@ -1161,7 +1161,7 @@ 1994. [port] OpenSSL 0.9.8 support. [RT #15694] -1993. [bug] Log messsage, via syslog, were missing the space +1993. [bug] Log messages, via syslog, were missing the space after the timestamp if "print-time yes" was specified. [RT #15844] @@ -1169,11 +1169,11 @@ view. [RT #15825] 1991. [cleanup] The configuration data, once read, should be treated - as readonly. Expand the use of const to enforce this + as read only. Expand the use of const to enforce this at compile time. [RT #15813] 1990. [bug] libbind: isc's override of broken gettimeofday() - implementions was not always effective. + implementations was not always effective. [RT #15709] 1989. [bug] win32: don't check the service password when @@ -1195,7 +1195,7 @@ server for the zone. Also any zones that contain DLV records should be removed when upgrading a slave zone. You do not however have to upgrade all - servers for a zone with DLV records simultaniously. + servers for a zone with DLV records simultaneously. 1984. [func] dig, nslookup and host now advertise a 4096 byte EDNS UDP buffer size by default. [RT #15855] @@ -1232,7 +1232,7 @@ 1973. [func] TSIG HMACSHA1, HMACSHA224, HMACSHA256, HMACSHA384 and HMACSHA512 support. [RT #13606] -1972. [contrib] DBUS dynamic forwarders integation from +1972. [contrib] DBUS dynamic forwarders integration from Jason Vas Dias . 1971. [port] linux: make detection of missing IF_NAMESIZE more @@ -1282,7 +1282,7 @@ by native compiler. See README for additional cross compile support information. [RT #15148] -1955. [bug] Pre-allocate the cache cleaning interator. [RT #14998] +1955. [bug] Pre-allocate the cache cleaning iterator. [RT #14998] 1954. [func] Named now falls back to advertising EDNS with a 512 byte receive buffer if the initial EDNS queries @@ -1318,7 +1318,7 @@ 1946. [bug] resume_dslookup() could trigger a REQUIRE failure when using forwarders. [RT #15549] -1945. [cleanup] dnssec-keygen: RSA (RSAMD5) is nolonger recommended. +1945. [cleanup] dnssec-keygen: RSA (RSAMD5) is no longer recommended. To generate a RSAMD5 key you must explicitly request RSAMD5. [RT #13780] @@ -1402,15 +1402,15 @@ 1917. [doc] funcsynopsisinfo wasn't being treated as verbatim when generating man pages. [RT #15385] -1916. [func] Integrate contibuted IDN code from JPNIC. [RT #15383] +1916. [func] Integrate contributed IDN code from JPNIC. [RT #15383] 1915. [bug] dig +ndots was broken. [RT #15215] 1914. [protocol] DS is required to accept mnemonic algorithms (RFC 4034). Still emit numeric algorithms for - compatability with RFC 3658. [RT #15354] + compatibility with RFC 3658. [RT #15354] -1913. [func] Integrate contibuted DLZ code into named. [RT #11382] +1913. [func] Integrate contributed DLZ code into named. [RT #11382] 1912. [port] aix: atomic locking for powerpc. [RT #15020] @@ -1482,7 +1482,7 @@ 1891. [port] freebsd: pthread_mutex_init can fail if it runs out of memory. [RT #14995] -1890. [func] Raise the UDP recieve buffer size to 32k if it is +1890. [func] Raise the UDP receive buffer size to 32k if it is less than 32k. [RT #14953] 1889. [port] sunos: non blocking i/o support. [RT #14951] @@ -1522,7 +1522,7 @@ [RT #2471] 1877. [bug] Fix unreasonably low quantum on call to - dns_rbt_destroy2(). Remove unnecessay unhash_node() + dns_rbt_destroy2(). Remove unnecessary unhash_node() call. [RT #14919] 1876. [func] Additional memory debugging support to track size @@ -1606,7 +1606,7 @@ 1850. [bug] Memory leak in lwres_getipnodebyaddr(). [RT #14591] 1849. [doc] All forms of the man pages (docbook, man, html) should - have consistant copyright dates. + have consistent copyright dates. 1848. [bug] Improve SMF integration. [RT #13238] @@ -1617,13 +1617,13 @@ 1846. [contrib] query-loc-0.3.0 from Stephane Bortzmeyer . -1845. [bug] Improve error reporting to distingish between +1845. [bug] Improve error reporting to distinguish between accept()/fcntl() and socket()/fcntl() errors. [RT #13745] 1844. [bug] inet_pton() accepted more that 4 hexadecimal digits for each 16 bit piece of the IPv6 address. The text - representation of a IPv6 address has been tighted + representation of a IPv6 address has been tightened to disallow this (draft-ietf-ipv6-addr-arch-v4-02.txt). [RT #5662] @@ -1857,7 +1857,7 @@ 1765. [bug] configure --with-openssl=auto failed. [RT #12937] 1764. [bug] dns_zone_replacedb failed to emit a error message - if there was no SOA record in the replacment db. + if there was no SOA record in the replacement db. [RT #13016] 1763. [func] Perform sanity checks on NS records which refer to @@ -1885,7 +1885,7 @@ 1755. [func] allow-update is now settable at the options / view level. [RT #6636] -1754. [bug] We wern't always attempting to query the parent +1754. [bug] We weren't always attempting to query the parent server for the DS records at the zone cut. [RT #12774] @@ -1906,7 +1906,7 @@ 1748. [func] dig now returns the byte count for axfr/ixfr. -1747. [bug] BIND 8 compatability: named/named-checkconf failed +1747. [bug] BIND 8 compatibility: named/named-checkconf failed to parse "host-statistics-max" in named.conf. 1746. [func] Make public the function to read a key file, @@ -1989,7 +1989,7 @@ [RT #12519] 1721. [bug] Error message from the journal processing were not - always identifing the relevent journal. [RT #12519] + always identifying the relevant journal. [RT #12519] 1720. [bug] 'dig +chase' did not terminate on a RFC 2308 Type 1 negative response. [RT #12506] @@ -2046,7 +2046,7 @@ 1703. [bug] named would loop sending NOTIFY messages when it failed to receive a response. [RT #12322] -1702. [bug] also-notify should not be applied to builtin zones. +1702. [bug] also-notify should not be applied to built in zones. [RT #12323] 1701. [doc] A minimal named.conf man page. @@ -2213,7 +2213,7 @@ masters with keys are specified. 1644. [bug] Update the journal modification time after a - sucessfull refresh query. [RT #11436] + successful refresh query. [RT #11436] 1643. [bug] dns_db_closeversion() could leak memory / node references. [RT #11163] @@ -2234,7 +2234,7 @@ 1637. [bug] Node reference leak on error in addnoqname(). 1636. [bug] The dump done callback could get ISC_R_SUCCESS even if - a error had occured. The database version no longer + a error had occurred. The database version no longer matched the version of the database that was dumped. 1635. [bug] Memory leak on error in query_addds(). @@ -2602,7 +2602,7 @@ type, class and responding nameserver. 1511. [bug] delegation-only was generating false positives - on negative answers from subzones. + on negative answers from sub-zones. 1510. [func] New view option "root-delegation-only". Apply delegation-only check to all TLDs and root. @@ -4283,7 +4283,7 @@ 954. [bug] When requesting AXFRs or IXFRs using dig, host, or nslookup, the RD bit should not be set as zone - transfers are inherently nonrecursive. [RT #1575] + transfers are inherently non-recursive. [RT #1575] 953. [func] The /var/run/named.key file from change #843 has been replaced by /etc/rndc.key. Both @@ -4598,7 +4598,7 @@ 860. [func] Drop cross class glue in zone transfers. 859. [bug] Cache cleaning now won't swamp the CPU if there - is a persistent overlimit condition. + is a persistent over limit condition. 858. [func] isc_mem_setwater() no longer requires that when the callback function is non-NULL then its hi_water @@ -4774,7 +4774,7 @@ 811. [bug] Parentheses were not quoted in zone dumps. [RT #1194] 810. [bug] The signer name in SIG records was not properly - downcased when signing/verifying records. [RT #1186] + down-cased when signing/verifying records. [RT #1186] 809. [bug] Configuring a non-local address as a transfer-source could cause an assertion failure during load. @@ -4786,9 +4786,9 @@ ignored like it should be. 806. [bug] DNS_R_SEENINCLUDE was failing to propagate back up - the calling stack to the zone maintence level, causing - zones to not reload when an included file was touched - but the top-level zone file was not. + the calling stack to the zone maintenance level, + causing zones to not reload when an included file was + touched but the top-level zone file was not. 805. [bug] When using "forward only", missing root hints should not cause queries to fail. [RT #1143] @@ -4828,7 +4828,7 @@ in rndc.conf. 793. [cleanup] The DNSSEC tools could create filenames that were - illegal or contained shell metacharacters. They + illegal or contained shell meta-characters. They now use a different text encoding of names that doesn't have these problems. [RT #1101] @@ -4852,7 +4852,7 @@ names when mapping them into file names. 786. [bug] When DNSSEC signing/verifying data, owner names were - not properly downcased. + not properly down-cased. 785. [bug] A race condition in the resolver could cause an assertion failure. [RT #673, #872, #1048] @@ -4871,7 +4871,7 @@ 780. [bug] Error handling code dealing with out of memory or other rare errors could lead to assertion failures - by calling functions on unitialized names. [RT #1065] + by calling functions on uninitialized names. [RT #1065] 779. [func] Added the "minimal-responses" option. @@ -5014,7 +5014,7 @@ 735. [doc] Add BIND 4 migration notes. 734. [bug] An attempt to re-lock the zone lock could occur if - the server was shutdown during a zone tranfer. + the server was shutdown during a zone transfer. [RT #830] 733. [bug] Reference counts of dns_acl_t objects need to be @@ -5154,7 +5154,7 @@ 688. [func] "make tags" now works on systems with the "Exuberant Ctags" etags. - 687. [bug] Only say we have IPv6, with sufficent functionality, + 687. [bug] Only say we have IPv6, with sufficient functionality, if it has actually been tested. [RT #586] 686. [bug] dig and nslookup can now be properly aborted during @@ -5472,7 +5472,7 @@ --- 9.1.0b1 released --- 591. [bug] Work around non-reentrancy in openssl by disabling - precomputation in keys. + pre-computation in keys. 590. [doc] There are now man pages for the lwres library in doc/man/lwres. @@ -5521,7 +5521,7 @@ source address for notify messages. 577. [func] Log illegal RDATA combinations. e.g. multiple - singlton types, cname and other data. + singleton types, cname and other data. 576. [doc] isc_log_create() description did not match reality. @@ -5532,7 +5532,7 @@ have their responses validated and would leak memory. 573. [bug] The journal files of IXFRed slave zones were - inadvertantly discarded on server reload, causing + inadvertently discarded on server reload, causing "journal out of sync with zone" errors on subsequent reloads. [RT #482] @@ -5701,7 +5701,7 @@ others). 519. [bug] dns_name_split() would improperly split some bitstring - labels, zeroing a few of the least signficant bits in + labels, zeroing a few of the least significant bits in the prefix part. When such an improperly created prefix was returned to the RBT database, the bogus label was dutifully stored, corrupting the tree. @@ -5729,7 +5729,7 @@ 513. [func] New functionality added to rdnc and server to allow individual zones to be refreshed or reloaded. - 512. [bug] The zone transfer code could throw an execption with + 512. [bug] The zone transfer code could throw an exception with an invalid IXFR stream. 511. [bug] The message code could throw an assertion on an @@ -5920,7 +5920,7 @@ 452. [bug] Warn if the unimplemented option "statistics-file" is specified in named.conf. [RT #301] - 451. [func] Update forwarding implememted. + 451. [func] Update forwarding implemented. 450. [func] New function ns_client_sendraw(). @@ -6021,7 +6021,7 @@ e.g. due to corrupt zones with multiple SOA records. [RT #279] - 423. [bug] When responding to a recusive query, errors that occur + 423. [bug] When responding to a recursive query, errors that occur after following a CNAME should cause the query to fail. [RT #274] @@ -6066,7 +6066,7 @@ 409. [bug] If named was shut down early in the startup process, ns_omapi_shutdown() would attempt to lock - an unintialized mutex. [RT #262] + an uninitialized mutex. [RT #262] 408. [bug] stub zones could leak memory and reference counts if all the masters were unreachable. @@ -6133,7 +6133,7 @@ making the functions dns_zone_adddbarg() and dns_zone_cleardbargs() unnecessary. - 389. [bug] Attempting to send a reqeust over IPv6 using + 389. [bug] Attempting to send a request over IPv6 using dns_request_create() on a system without IPv6 support caused an assertion failure [RT #235]. @@ -6190,7 +6190,7 @@ of a very large RRset could cause an assertion failure during logging. - 370. [bug] The error messages for rollforward failures were + 370. [bug] The error messages for roll-forward failures were overly terse. 369. [func] Support new named.conf options, view and zone @@ -6333,7 +6333,7 @@ 328. [func] Added isc_base64_decodestring(). - 327. [bug] rndc.conf parser wasn't correctly recognising an IP + 327. [bug] rndc.conf parser wasn't correctly recognizing an IP address where a host specification was required. 326. [func] 'keys' in an 'inet' control statement is now @@ -6363,7 +6363,7 @@ where they previously didn't. 321. [bug] When synthesizing a CNAME RR for a DNAME - response, query_addcname() failed to intitialize + response, query_addcname() failed to initialize the type and class of the CNAME dns_rdata_t, causing random failures. @@ -6639,7 +6639,7 @@ --- 9.0.0b4 released --- - 253. [func] resolv.conf parser now recognises ';' and '#' as + 253. [func] resolv.conf parser now recognizes ';' and '#' as comments (anywhere in line, not just as the beginning). 252. [bug] resolv.conf parser mishandled masks on sortlists. @@ -6709,7 +6709,7 @@ requiring a quoted string. 233. [cleanup] Convert all config structure integer values to unsigned - integer (isc_uint32_t) to match grammer. + integer (isc_uint32_t) to match grammar. 232. [bug] Allow slave zones to not have a file. @@ -6746,7 +6746,7 @@ from confparser.c, because of yacc's code, are unfortunately to be expected.) - 223. [func] Several functions were reprototyped to qualify one + 223. [func] Several functions were re-prototyped to qualify one or more of their arguments with "const". Similarly, several functions that return pointers now have those pointers qualified with const. @@ -6911,7 +6911,7 @@ 183. [func] ISC_LOG_PRINTTAG option for log channels. Useful for logging the program name or other identifier. - 182. [cleanup] New commandline parameters for dnssec tools + 182. [cleanup] New command-line parameters for dnssec tools 181. [func] Added dst_key_buildfilename and dst_key_parsefilename @@ -6956,7 +6956,7 @@ --with-mit-pthreads option is no longer needed and has been removed. - 170. [cleanup] Remove inter server consistancy checks from zone, + 170. [cleanup] Remove inter server consistency checks from zone, these should return as a separate module in 9.1. dns_zone_checkservers(), dns_zone_checkparents(), dns_zone_checkchildren(), dns_zone_checkglue(). @@ -7049,7 +7049,7 @@ than continuing to itemize every header which changed, this changelog entry just notes that if a header file did not need another header file that it was including - in order to provide its advertized functionality, the + in order to provide its advertised functionality, the inclusion of the other header file was removed. See util/check-includes for how this was tested. @@ -7441,7 +7441,7 @@ 31. [bug] Use ${LIBTOOL} to compile bin/named/main.@O@. - 30. [func] config file grammer change to support optional + 30. [func] config file grammar change to support optional class type for a view. 29. [func] support new config file view options: @@ -7505,7 +7505,7 @@ 13. [bug] lib/dns/master.c and lib/dns/xfrin.c didn't ignore out-of-zone data. - 12. [bug] Fixed possible unitialized variable error. + 12. [bug] Fixed possible uninitialized variable error. 11. [bug] axfr_rrstream_first() didn't check the result code of db_rr_iterator_first(), possibly causing an assertion From fa94d768cb8c9f6fa4ef0072d593c3583abe74cc Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Tue, 13 May 2008 00:33:43 +0000 Subject: [PATCH 068/137] spelling --- CHANGES | 126 ++++++++++++++++++++++++++++---------------------------- 1 file changed, 63 insertions(+), 63 deletions(-) diff --git a/CHANGES b/CHANGES index aee148a07d..edd55023ce 100644 --- a/CHANGES +++ b/CHANGES @@ -12,7 +12,7 @@ 2358. [doc] Update host's default query description. [RT #17934] -2356. [bug] Builtin mutex profiler was not scalable enough. +2356. [bug] Built in mutex profiler was not scalable enough. [RT #17436] 2353. [func] libbind: nsid support. [RT #17091] @@ -176,7 +176,7 @@ --- 9.3.5b1 released --- -2273. [bug] Adjust log level to WARNING when saving inconsistant +2273. [bug] Adjust log level to WARNING when saving inconsistent stub/slave master and journal files. [RT# 17279] 2272. [bug] Handle illegal dnssec-lookaside trust-anchor names. @@ -227,7 +227,7 @@ working. [RT #17151] 2238. [bug] It was possible to trigger a REQUIRE when a - validation was cancelled. [RT #17106] + validation was canceled. [RT #17106] 2237. [bug] libbind: res_init() was not thread aware. [RT #17123] @@ -316,7 +316,7 @@ 2187. [bug] query_addds(), query_addwildcardproof() and query_addnxrrsetnsec() should take a version - arguement. [RT #16368] + argument. [RT #16368] 2186. [port] cygwin: libbind: check for struct sockaddr_storage independently of IPv6. [RT #16482] @@ -343,7 +343,7 @@ debug level 10+. [RT #16798] 2176. [contrib] dbus update to handle race condition during - initialisation (Bugzilla 235809). [RT #16842] + initialization (Bugzilla 235809). [RT #16842] 2175. [bug] win32: windows broadcast condition variable support was broken. [RT #16592] @@ -482,7 +482,7 @@ --- 9.3.4 released --- -2126. [security] Serialise validation of type ANY responses. [RT #16555] +2126. [security] Serialize validation of type ANY responses. [RT #16555] 2124. [security] It was possible to dereference a freed fetch context. [RT #16584] @@ -496,14 +496,14 @@ 2103. [port] Add /usr/sfw to list of locations for OpenSSL under Solaris. -2102. [port] Silence solaris 10 warnings. +2102. [port] Silence Solaris 10 warnings. 2101. [bug] OpenSSL version checks were not quite right. [RT #16476] 2100. [port] win32: copy libeay32.dll to Build\Debug. -2099. [port] win32: more manifiest issues. +2099. [port] win32: more manifest issues. --- 9.3.3rc3 released --- @@ -607,7 +607,7 @@ [RT #16287] 2049. [bug] Restore SOA before AXFR when falling back from - a attempted IXFR when transfering in a zone. + a attempted IXFR when transferring in a zone. Allow a initial SOA query before attempting a AXFR to be requested. [RT #16156] @@ -616,7 +616,7 @@ the OS always returned the same local port. [RT #16182] -2047. [bug] Failed to initialise the interface flags to zero. +2047. [bug] Failed to initialize the interface flags to zero. [RT #16245] 2043. [port] nsupdate/nslookup: Force the flushing of the prompt @@ -645,7 +645,7 @@ 2029. [bug] host printed out the server multiple times when specified on the command line. [RT #15992] -2028. [port] linux: socket.c compatability for old systems. +2028. [port] linux: socket.c compatibility for old systems. [RT #16015] 2027. [port] libbind: Solaris x86 support. [RT #16020] @@ -653,7 +653,7 @@ 2026. [bug] Rate limit the two recursive client exceeded messages. [RT #16044] -2024. [bug] named emited spurious "zone serial unchanged" +2024. [bug] named emitted spurious "zone serial unchanged" messages on reload. [RT #16027] 2023. [bug] "make install" should create ${localstatedir}/run and @@ -666,7 +666,7 @@ 2013. [bug] Handle unexpected TSIGs on unsigned AXFR/IXFR responses more gracefully. [RT #15941] -2009. [bug] libbind: coverity fixes. [RT #15808] +2009. [bug] libbind: Coverity fixes. [RT #15808] 2005. [bug] libbind: Retransmission timeouts should be based on which attempt it is to the nameserver @@ -698,16 +698,16 @@ 1994. [port] OpenSSL 0.9.8 support. [RT #15694] -1993. [bug] Log messsage, via syslog, were missing the space +1993. [bug] Log messages, via syslog, were missing the space after the timestamp if "print-time yes" was specified. [RT #15844] 1991. [cleanup] The configuration data, once read, should be treated - as readonly. Expand the use of const to enforce this + as read only. Expand the use of const to enforce this at compile time. [RT #15813] 1990. [bug] libbind: isc's override of broken gettimeofday() - implementions was not always effective. + implementations was not always effective. [RT #15709] 1989. [bug] win32: don't check the service password when @@ -722,7 +722,7 @@ server for the zone. Also any zones that contain DLV records should be removed when upgrading a slave zone. You do not however have to upgrade all - servers for a zone with DLV records simultaniously. + servers for a zone with DLV records simultaneously. 1982. [bug] DNSKEY was being accepted on the parent side of a delegation. KEY is still accepted there for @@ -747,7 +747,7 @@ 1974. [doc] List each of the zone types and associated zone options separately in the ARM. -1972. [contrib] DBUS dynamic forwarders integation from +1972. [contrib] DBUS dynamic forwarders integration from Jason Vas Dias . 1971. [port] linux: make detection of missing IF_NAMESIZE more @@ -786,7 +786,7 @@ by native compiler. See README for additional cross compile support information. [RT #15148] -1955. [bug] Pre-allocate the cache cleaning interator. [RT #14998] +1955. [bug] Pre-allocate the cache cleaning iterator. [RT #14998] 1952. [port] hpux: tell the linker to build a runtime link path "-Wl,+b:". [RT #14816]. @@ -867,7 +867,7 @@ 1914. [protocol] DS is required to accept mnemonic algorithms (RFC 4034). Still emit numeric algorithms for - compatability with RFC 3658. [RT #15354] + compatibility with RFC 3658. [RT #15354] 1911. [bug] Update windows socket code. [RT #14965] @@ -911,7 +911,7 @@ 1881. [func] Add a system test for named-checkconf. [RT #14931] 1877. [bug] Fix unreasonably low quantum on call to - dns_rbt_destroy2(). Remove unnecessay unhash_node() + dns_rbt_destroy2(). Remove unnecessary unhash_node() call. [RT #14919] 1875. [bug] process_dhtkey() was using the wrong memory context @@ -970,7 +970,7 @@ 1850. [bug] Memory leak in lwres_getipnodebyaddr(). [RT #14591] 1849. [doc] All forms of the man pages (docbook, man, html) should - have consistant copyright dates. + have consistent copyright dates. 1848. [bug] Improve SMF integration. [RT #13238] @@ -981,13 +981,13 @@ 1846. [contrib] query-loc-0.3.0 from Stephane Bortzmeyer . -1845. [bug] Improve error reporting to distingish between +1845. [bug] Improve error reporting to distinguish between accept()/fcntl() and socket()/fcntl() errors. [RT #13745] 1844. [bug] inet_pton() accepted more that 4 hexadecimal digits for each 16 bit piece of the IPv6 address. The text - representation of a IPv6 address has been tighted + representation of a IPv6 address has been tightened to disallow this (draft-ietf-ipv6-addr-arch-v4-02.txt). [RT #5662] @@ -1184,7 +1184,7 @@ 1765. [bug] configure --with-openssl=auto failed. [RT #12937] 1764. [bug] dns_zone_replacedb failed to emit a error message - if there was no SOA record in the replacment db. + if there was no SOA record in the replacement db. [RT #13016] 1762. [bug] isc_interfaceiter_create() could return ISC_R_SUCCESS @@ -1199,7 +1199,7 @@ 1759. [bug] Named failed to startup if the OS supported IPv6 but had no IPv6 interfaces configured. [RT #12942] -1754. [bug] We wern't always attempting to query the parent +1754. [bug] We weren't always attempting to query the parent server for the DS records at the zone cut. [RT #12774] @@ -1218,7 +1218,7 @@ 1749. [bug] 'check-names response ignore;' failed to ignore. [RT #12866] -1747. [bug] BIND 8 compatability: named/named-checkconf failed +1747. [bug] BIND 8 compatibility: named/named-checkconf failed to parse "host-statistics-max" in named.conf. 1745. [bug] Dig/host/nslookup accept replies from link locals @@ -1296,7 +1296,7 @@ [RT #12519] 1721. [bug] Error message from the journal processing were not - always identifing the relevent journal. [RT #12519] + always identifying the relevant journal. [RT #12519] 1720. [bug] 'dig +chase' did not terminate on a RFC 2308 Type 1 negative response. [RT #12506] @@ -1349,7 +1349,7 @@ 1703. [bug] named would loop sending NOTIFY messages when it failed to receive a response. [RT #12322] -1702. [bug] also-notify should not be applied to builtin zones. +1702. [bug] also-notify should not be applied to built in zones. [RT #12323] 1701. [doc] A minimal named.conf man page. @@ -1505,7 +1505,7 @@ masters with keys are specified. 1644. [bug] Update the journal modification time after a - sucessfull refresh query. [RT #11436] + successful refresh query. [RT #11436] 1643. [bug] dns_db_closeversion() could leak memory / node references. [RT #11163] @@ -1528,7 +1528,7 @@ 1637. [bug] Node reference leak on error in addnoqname(). 1636. [bug] The dump done callback could get ISC_R_SUCCESS even if - a error had occured. The database version no longer + a error had occurred. The database version no longer matched the version of the database that was dumped. 1635. [bug] Memory leak on error in query_addds(). @@ -1879,7 +1879,7 @@ type, class and responding nameserver. 1511. [bug] delegation-only was generating false positives - on negative answers from subzones. + on negative answers from sub-zones. 1510. [func] New view option "root-delegation-only". Apply delegation-only check to all TLDs and root. @@ -3587,7 +3587,7 @@ 954. [bug] When requesting AXFRs or IXFRs using dig, host, or nslookup, the RD bit should not be set as zone - transfers are inherently nonrecursive. [RT #1575] + transfers are inherently non-recursive. [RT #1575] 953. [func] The /var/run/named.key file from change #843 has been replaced by /etc/rndc.key. Both @@ -3860,7 +3860,7 @@ 860. [func] Drop cross class glue in zone transfers. 859. [bug] Cache cleaning now won't swamp the CPU if there - is a persistent overlimit condition. + is a persistent over limit condition. 858. [func] isc_mem_setwater() no longer requires that when the callback function is non-NULL then its hi_water @@ -4036,7 +4036,7 @@ 811. [bug] Parentheses were not quoted in zone dumps. [RT #1194] 810. [bug] The signer name in SIG records was not properly - downcased when signing/verifying records. [RT #1186] + down-cased when signing/verifying records. [RT #1186] 809. [bug] Configuring a non-local address as a transfer-source could cause an assertion failure during load. @@ -4048,9 +4048,9 @@ ignored like it should be. 806. [bug] DNS_R_SEENINCLUDE was failing to propagate back up - the calling stack to the zone maintence level, causing - zones to not reload when an included file was touched - but the top-level zone file was not. + the calling stack to the zone maintenance level, + causing zones to not reload when an included file was + touched but the top-level zone file was not. 805. [bug] When using "forward only", missing root hints should not cause queries to fail. [RT #1143] @@ -4090,7 +4090,7 @@ in rndc.conf. 793. [cleanup] The DNSSEC tools could create filenames that were - illegal or contained shell metacharacters. They + illegal or contained shell meta-characters. They now use a different text encoding of names that doesn't have these problems. [RT #1101] @@ -4114,7 +4114,7 @@ names when mapping them into file names. 786. [bug] When DNSSEC signing/verifying data, owner names were - not properly downcased. + not properly down-cased. 785. [bug] A race condition in the resolver could cause an assertion failure. [RT #673, #872, #1048] @@ -4133,7 +4133,7 @@ 780. [bug] Error handling code dealing with out of memory or other rare errors could lead to assertion failures - by calling functions on unitialized names. [RT #1065] + by calling functions on uninitialized names. [RT #1065] 779. [func] Added the "minimal-responses" option. @@ -4276,7 +4276,7 @@ 735. [doc] Add BIND 4 migration notes. 734. [bug] An attempt to re-lock the zone lock could occur if - the server was shutdown during a zone tranfer. + the server was shutdown during a zone transfer. [RT #830] 733. [bug] Reference counts of dns_acl_t objects need to be @@ -4416,7 +4416,7 @@ 688. [func] "make tags" now works on systems with the "Exuberant Ctags" etags. - 687. [bug] Only say we have IPv6, with sufficent functionality, + 687. [bug] Only say we have IPv6, with sufficient functionality, if it has actually been tested. [RT #586] 686. [bug] dig and nslookup can now be properly aborted during @@ -4732,7 +4732,7 @@ --- 9.1.0b1 released --- 591. [bug] Work around non-reentrancy in openssl by disabling - precomputation in keys. + pre-computation in keys. 590. [doc] There are now man pages for the lwres library in doc/man/lwres. @@ -4781,7 +4781,7 @@ source address for notify messages. 577. [func] Log illegal RDATA combinations. e.g. multiple - singlton types, cname and other data. + singleton types, cname and other data. 576. [doc] isc_log_create() description did not match reality. @@ -4792,7 +4792,7 @@ have their responses validated and would leak memory. 573. [bug] The journal files of IXFRed slave zones were - inadvertantly discarded on server reload, causing + inadvertently discarded on server reload, causing "journal out of sync with zone" errors on subsequent reloads. [RT #482] @@ -4957,7 +4957,7 @@ others). 519. [bug] dns_name_split() would improperly split some bitstring - labels, zeroing a few of the least signficant bits in + labels, zeroing a few of the least significant bits in the prefix part. When such an improperly created prefix was returned to the RBT database, the bogus label was dutifully stored, corrupting the tree. @@ -4985,7 +4985,7 @@ 513. [func] New functionality added to rdnc and server to allow individual zones to be refreshed or reloaded. - 512. [bug] The zone transfer code could throw an execption with + 512. [bug] The zone transfer code could throw an exception with an invalid IXFR stream. 511. [bug] The message code could throw an assertion on an @@ -5176,7 +5176,7 @@ 452. [bug] Warn if the unimplemented option "statistics-file" is specified in named.conf. [RT #301] - 451. [func] Update forwarding implememted. + 451. [func] Update forwarding implemented. 450. [func] New function ns_client_sendraw(). @@ -5277,7 +5277,7 @@ e.g. due to corrupt zones with multiple SOA records. [RT #279] - 423. [bug] When responding to a recusive query, errors that occur + 423. [bug] When responding to a recursive query, errors that occur after following a CNAME should cause the query to fail. [RT #274] @@ -5322,7 +5322,7 @@ 409. [bug] If named was shut down early in the startup process, ns_omapi_shutdown() would attempt to lock - an unintialized mutex. [RT #262] + an uninitialized mutex. [RT #262] 408. [bug] stub zones could leak memory and reference counts if all the masters were unreachable. @@ -5389,7 +5389,7 @@ making the functions dns_zone_adddbarg() and dns_zone_cleardbargs() unnecessary. - 389. [bug] Attempting to send a reqeust over IPv6 using + 389. [bug] Attempting to send a request over IPv6 using dns_request_create() on a system without IPv6 support caused an assertion failure [RT #235]. @@ -5446,7 +5446,7 @@ of a very large RRset could cause an assertion failure during logging. - 370. [bug] The error messages for rollforward failures were + 370. [bug] The error messages for roll-forward failures were overly terse. 369. [func] Support new named.conf options, view and zone @@ -5588,7 +5588,7 @@ 328. [func] Added isc_base64_decodestring(). - 327. [bug] rndc.conf parser wasn't correctly recognising an IP + 327. [bug] rndc.conf parser wasn't correctly recognizing an IP address where a host specification was required. 326. [func] 'keys' in an 'inet' control statement is now @@ -5618,7 +5618,7 @@ where they previously didn't. 321. [bug] When synthesizing a CNAME RR for a DNAME - response, query_addcname() failed to intitialize + response, query_addcname() failed to initialize the type and class of the CNAME dns_rdata_t, causing random failures. @@ -5894,7 +5894,7 @@ --- 9.0.0b4 released --- - 253. [func] resolv.conf parser now recognises ';' and '#' as + 253. [func] resolv.conf parser now recognizes ';' and '#' as comments (anywhere in line, not just as the beginning). 252. [bug] resolv.conf parser mishandled masks on sortlists. @@ -5964,7 +5964,7 @@ requiring a quoted string. 233. [cleanup] Convert all config structure integer values to unsigned - integer (isc_uint32_t) to match grammer. + integer (isc_uint32_t) to match grammar. 232. [bug] Allow slave zones to not have a file. @@ -6001,7 +6001,7 @@ from confparser.c, because of yacc's code, are unfortunately to be expected.) - 223. [func] Several functions were reprototyped to qualify one + 223. [func] Several functions were re-prototyped to qualify one or more of their arguments with "const". Similarly, several functions that return pointers now have those pointers qualified with const. @@ -6167,7 +6167,7 @@ 183. [func] ISC_LOG_PRINTTAG option for log channels. Useful for logging the program name or other identifier. - 182. [cleanup] New commandline parameters for dnssec tools + 182. [cleanup] New command-line parameters for dnssec tools 181. [func] Added dst_key_buildfilename and dst_key_parsefilename @@ -6212,7 +6212,7 @@ --with-mit-pthreads option is no longer needed and has been removed. - 170. [cleanup] Remove inter server consistancy checks from zone, + 170. [cleanup] Remove inter server consistency checks from zone, these should return as a separate module in 9.1. dns_zone_checkservers(), dns_zone_checkparents(), dns_zone_checkchildren(), dns_zone_checkglue(). @@ -6305,7 +6305,7 @@ than continuing to itemize every header which changed, this changelog entry just notes that if a header file did not need another header file that it was including - in order to provide its advertized functionality, the + in order to provide its advertised functionality, the inclusion of the other header file was removed. See util/check-includes for how this was tested. @@ -6697,7 +6697,7 @@ 31. [bug] Use ${LIBTOOL} to compile bin/named/main.@O@. - 30. [func] config file grammer change to support optional + 30. [func] config file grammar change to support optional class type for a view. 29. [func] support new config file view options: @@ -6761,7 +6761,7 @@ 13. [bug] lib/dns/master.c and lib/dns/xfrin.c didn't ignore out-of-zone data. - 12. [bug] Fixed possible unitialized variable error. + 12. [bug] Fixed possible uninitialized variable error. 11. [bug] axfr_rrstream_first() didn't check the result code of db_rr_iterator_first(), possibly causing an assertion From c72279e756e6578dc8f09ceac5158d80a8a61ce5 Mon Sep 17 00:00:00 2001 From: Evan Hunt Date: Tue, 13 May 2008 01:20:24 +0000 Subject: [PATCH 069/137] "rndc freeze" could trigger an assertion in named when called on a nonexistent zone. [rt18050] --- CHANGES | 3 +++ lib/dns/view.c | 23 +++++++++++++++++++---- 2 files changed, 22 insertions(+), 4 deletions(-) diff --git a/CHANGES b/CHANGES index bb524883f8..68267b0232 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +2370. [bug] "rndc freeze" could trigger an assertion in named + when called on a nonexistent zone. [RT #18050] + 2369. [bug] libbind: Array bounds overrun on read in bitncmp(). [RT #18054] diff --git a/lib/dns/view.c b/lib/dns/view.c index cd740c79ef..ba8124b790 100644 --- a/lib/dns/view.c +++ b/lib/dns/view.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: view.c,v 1.146 2008/04/03 05:55:52 marka Exp $ */ +/* $Id: view.c,v 1.147 2008/05/13 01:20:24 each Exp $ */ /*! \file */ @@ -1161,6 +1161,7 @@ dns_viewlist_findzone(dns_viewlist_t *list, dns_name_t *name, dns_view_t *view; isc_result_t result; dns_zone_t *zone1 = NULL, *zone2 = NULL; + dns_zone_t **zp = NULL;; REQUIRE(list != NULL); for (view = ISC_LIST_HEAD(*list); @@ -1168,9 +1169,23 @@ dns_viewlist_findzone(dns_viewlist_t *list, dns_name_t *name, view = ISC_LIST_NEXT(view, link)) { if (allclasses == ISC_FALSE && view->rdclass != rdclass) continue; - result = dns_zt_find(view->zonetable, name, 0, NULL, - (zone1 == NULL) ? &zone1 : &zone2); - INSIST(result == ISC_R_SUCCESS || result == ISC_R_NOTFOUND); + + /* + * If the zone is defined in more than one view, + * treat it as not found. + */ + zp = (zone1 == NULL) ? &zone1 : &zone2; + result = dns_zt_find(view->zonetable, name, 0, NULL, zp); + INSIST(result == ISC_R_SUCCESS || + result == ISC_R_NOTFOUND || + result == DNS_R_PARTIALMATCH); + + /* Treat a partial match as no match */ + if (result == DNS_R_PARTIALMATCH) { + dns_zone_detach(zp); + result = ISC_R_NOTFOUND; + } + if (zone2 != NULL) { dns_zone_detach(&zone1); dns_zone_detach(&zone2); From 59b6d8259a2c13102e4ba4003b6e85fb1ac032f9 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Tue, 13 May 2008 23:47:01 +0000 Subject: [PATCH 070/137] update copyright notice --- lib/dns/view.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/lib/dns/view.c b/lib/dns/view.c index ba8124b790..1c4bcdeea0 100644 --- a/lib/dns/view.c +++ b/lib/dns/view.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: view.c,v 1.147 2008/05/13 01:20:24 each Exp $ */ +/* $Id: view.c,v 1.148 2008/05/13 23:47:01 tbox Exp $ */ /*! \file */ @@ -1171,7 +1171,7 @@ dns_viewlist_findzone(dns_viewlist_t *list, dns_name_t *name, continue; /* - * If the zone is defined in more than one view, + * If the zone is defined in more than one view, * treat it as not found. */ zp = (zone1 == NULL) ? &zone1 : &zone2; From aed0e61611268afd72a023a7fbba88698bc6bbeb Mon Sep 17 00:00:00 2001 From: Evan Hunt Date: Tue, 13 May 2008 23:59:18 +0000 Subject: [PATCH 071/137] add +nsid option to dig man page. [rt18039] --- CHANGES | 2 + bin/dig/dig.1 | 592 +++++++++++--------------------------------- bin/dig/dig.docbook | 10 +- 3 files changed, 154 insertions(+), 450 deletions(-) diff --git a/CHANGES b/CHANGES index 68267b0232..d8e7f22dff 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,5 @@ +2371. [doc] add +nsid option to dig man page. [RT #18039] + 2370. [bug] "rndc freeze" could trigger an assertion in named when called on a nonexistent zone. [RT #18050] diff --git a/bin/dig/dig.1 b/bin/dig/dig.1 index 58ead793de..f95ad1c794 100644 --- a/bin/dig/dig.1 +++ b/bin/dig/dig.1 @@ -13,545 +13,239 @@ .\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR .\" PERFORMANCE OF THIS SOFTWARE. .\" -.\" $Id: dig.1,v 1.45 2007/05/16 06:12:00 marka Exp $ +.\" $Id: dig.1,v 1.46 2008/05/13 23:59:18 each Exp $ .\" .hy 0 .ad l -.\" Title: dig -.\" Author: -.\" Generator: DocBook XSL Stylesheets v1.71.1 -.\" Date: Jun 30, 2000 -.\" Manual: BIND9 -.\" Source: BIND9 -.\" -.TH "DIG" "1" "Jun 30, 2000" "BIND9" "BIND9" -.\" disable hyphenation -.nh -.\" disable justification (adjust text to left margin only) -.ad l -.SH "NAME" +.\"Generated by db2man.xsl. Don't modify this, modify the source. +.de Sh \" Subsection +.br +.if t .Sp +.ne 5 +.PP +\fB\\$1\fR +.PP +.. +.de Sp \" Vertical space (when we can't use .PP) +.if t .sp .5v +.if n .sp +.. +.de Ip \" List item +.br +.ie \\n(.$>=3 .ne \\$3 +.el .ne 3 +.IP "\\$1" \\$2 +.. +.TH "DIG" 1 "Jun 30, 2000" "" "" +.SH NAME dig \- DNS lookup utility .SH "SYNOPSIS" .HP 4 -\fBdig\fR [@server] [\fB\-b\ \fR\fB\fIaddress\fR\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-f\ \fR\fB\fIfilename\fR\fR] [\fB\-k\ \fR\fB\fIfilename\fR\fR] [\fB\-p\ \fR\fB\fIport#\fR\fR] [\fB\-q\ \fR\fB\fIname\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-x\ \fR\fB\fIaddr\fR\fR] [\fB\-y\ \fR\fB\fI[hmac:]\fR\fIname:key\fR\fR] [\fB\-4\fR] [\fB\-6\fR] [name] [type] [class] [queryopt...] +\fBdig\fR [@server] [\fB\-b\ \fIaddress\fR\fR] [\fB\-c\ \fIclass\fR\fR] [\fB\-f\ \fIfilename\fR\fR] [\fB\-k\ \fIfilename\fR\fR] [\fB\-p\ \fIport#\fR\fR] [\fB\-q\ \fIname\fR\fR] [\fB\-t\ \fItype\fR\fR] [\fB\-x\ \fIaddr\fR\fR] [\fB\-y\ \fI[hmac:]name:key\fR\fR] [\fB\-4\fR] [\fB\-6\fR] [name] [type] [class] [queryopt...] .HP 4 \fBdig\fR [\fB\-h\fR] .HP 4 \fBdig\fR [global\-queryopt...] [query...] .SH "DESCRIPTION" .PP -\fBdig\fR -(domain information groper) is a flexible tool for interrogating DNS name servers. It performs DNS lookups and displays the answers that are returned from the name server(s) that were queried. Most DNS administrators use -\fBdig\fR -to troubleshoot DNS problems because of its flexibility, ease of use and clarity of output. Other lookup tools tend to have less functionality than -\fBdig\fR. +\fBdig\fR (domain information groper) is a flexible tool for interrogating DNS name servers\&. It performs DNS lookups and displays the answers that are returned from the name server(s) that were queried\&. Most DNS administrators use \fBdig\fR to troubleshoot DNS problems because of its flexibility, ease of use and clarity of output\&. Other lookup tools tend to have less functionality than \fBdig\fR\&. .PP -Although -\fBdig\fR -is normally used with command\-line arguments, it also has a batch mode of operation for reading lookup requests from a file. A brief summary of its command\-line arguments and options is printed when the -\fB\-h\fR -option is given. Unlike earlier versions, the BIND 9 implementation of -\fBdig\fR -allows multiple lookups to be issued from the command line. +Although \fBdig\fR is normally used with command\-line arguments, it also has a batch mode of operation for reading lookup requests from a file\&. A brief summary of its command\-line arguments and options is printed when the \fB\-h\fR option is given\&. Unlike earlier versions, the BIND 9 implementation of \fBdig\fR allows multiple lookups to be issued from the command line\&. .PP -Unless it is told to query a specific name server, -\fBdig\fR -will try each of the servers listed in -\fI/etc/resolv.conf\fR. +Unless it is told to query a specific name server, \fBdig\fR will try each of the servers listed in \fI/etc/resolv\&.conf\fR\&. .PP -When no command line arguments or options are given, will perform an NS query for "." (the root). +When no command line arguments or options are given, will perform an NS query for "\&." (the root)\&. .PP -It is possible to set per\-user defaults for -\fBdig\fR -via -\fI${HOME}/.digrc\fR. This file is read and any options in it are applied before the command line arguments. +It is possible to set per\-user defaults for \fBdig\fR via \fI${HOME}/\&.digrc\fR\&. This file is read and any options in it are applied before the command line arguments\&. .PP -The IN and CH class names overlap with the IN and CH top level domains names. Either use the -\fB\-t\fR -and -\fB\-c\fR -options to specify the type and class or use the -\fB\-q\fR -the specify the domain name or use "IN." and "CH." when looking up these top level domains. +The IN and CH class names overlap with the IN and CH top level domains names\&. Either use the \fB\-t\fR and \fB\-c\fR options to specify the type and class or use the \fB\-q\fR the specify the domain name or use "IN\&." and "CH\&." when looking up these top level domains\&. .SH "SIMPLE USAGE" .PP -A typical invocation of -\fBdig\fR -looks like: -.sp -.RS 4 +A typical invocation of \fBdig\fR looks like: .nf dig @server name type .fi -.RE -.sp -where: -.PP + where: +.TP \fBserver\fR -.RS 4 -is the name or IP address of the name server to query. This can be an IPv4 address in dotted\-decimal notation or an IPv6 address in colon\-delimited notation. When the supplied -\fIserver\fR -argument is a hostname, -\fBdig\fR -resolves that name before querying that name server. If no -\fIserver\fR -argument is provided, -\fBdig\fR -consults -\fI/etc/resolv.conf\fR -and queries the name servers listed there. The reply from the name server that responds is displayed. -.RE -.PP +is the name or IP address of the name server to query\&. This can be an IPv4 address in dotted\-decimal notation or an IPv6 address in colon\-delimited notation\&. When the supplied \fIserver\fR argument is a hostname, \fBdig\fR resolves that name before querying that name server\&. If no \fIserver\fR argument is provided, \fBdig\fR consults \fI/etc/resolv\&.conf\fR and queries the name servers listed there\&. The reply from the name server that responds is displayed\&. +.TP \fBname\fR -.RS 4 -is the name of the resource record that is to be looked up. -.RE -.PP +is the name of the resource record that is to be looked up\&. +.TP \fBtype\fR -.RS 4 -indicates what type of query is required \(em ANY, A, MX, SIG, etc. -\fItype\fR -can be any valid query type. If no -\fItype\fR -argument is supplied, -\fBdig\fR -will perform a lookup for an A record. -.RE +indicates what type of query is required -- ANY, A, MX, SIG, etc\&. \fItype\fR can be any valid query type\&. If no \fItype\fR argument is supplied, \fBdig\fR will perform a lookup for an A record\&. .SH "OPTIONS" .PP -The -\fB\-b\fR -option sets the source IP address of the query to -\fIaddress\fR. This must be a valid address on one of the host's network interfaces or "0.0.0.0" or "::". An optional port may be specified by appending "#" +The \fB\-b\fR option sets the source IP address of the query to \fIaddress\fR\&. This must be a valid address on one of the host's network interfaces or "0\&.0\&.0\&.0" or "::"\&. An optional port may be specified by appending "#" .PP -The default query class (IN for internet) is overridden by the -\fB\-c\fR -option. -\fIclass\fR -is any valid class, such as HS for Hesiod records or CH for Chaosnet records. +The default query class (IN for internet) is overridden by the \fB\-c\fR option\&. \fIclass\fR is any valid class, such as HS for Hesiod records or CH for Chaosnet records\&. .PP -The -\fB\-f\fR -option makes -\fBdig \fR -operate in batch mode by reading a list of lookup requests to process from the file -\fIfilename\fR. The file contains a number of queries, one per line. Each entry in the file should be organized in the same way they would be presented as queries to -\fBdig\fR -using the command\-line interface. +The \fB\-f\fR option makes \fBdig \fR operate in batch mode by reading a list of lookup requests to process from the file \fIfilename\fR\&. The file contains a number of queries, one per line\&. Each entry in the file should be organized in the same way they would be presented as queries to \fBdig\fR using the command\-line interface\&. .PP -If a non\-standard port number is to be queried, the -\fB\-p\fR -option is used. -\fIport#\fR -is the port number that -\fBdig\fR -will send its queries instead of the standard DNS port number 53. This option would be used to test a name server that has been configured to listen for queries on a non\-standard port number. +If a non\-standard port number is to be queried, the \fB\-p\fR option is used\&. \fIport#\fR is the port number that \fBdig\fR will send its queries instead of the standard DNS port number 53\&. This option would be used to test a name server that has been configured to listen for queries on a non\-standard port number\&. .PP -The -\fB\-4\fR -option forces -\fBdig\fR -to only use IPv4 query transport. The -\fB\-6\fR -option forces -\fBdig\fR -to only use IPv6 query transport. +The \fB\-4\fR option forces \fBdig\fR to only use IPv4 query transport\&. The \fB\-6\fR option forces \fBdig\fR to only use IPv6 query transport\&. .PP -The -\fB\-t\fR -option sets the query type to -\fItype\fR. It can be any valid query type which is supported in BIND 9. The default query type is "A", unless the -\fB\-x\fR -option is supplied to indicate a reverse lookup. A zone transfer can be requested by specifying a type of AXFR. When an incremental zone transfer (IXFR) is required, -\fItype\fR -is set to -ixfr=N. The incremental zone transfer will contain the changes made to the zone since the serial number in the zone's SOA record was -\fIN\fR. +The \fB\-t\fR option sets the query type to \fItype\fR\&. It can be any valid query type which is supported in BIND 9\&. The default query type is "A", unless the \fB\-x\fR option is supplied to indicate a reverse lookup\&. A zone transfer can be requested by specifying a type of AXFR\&. When an incremental zone transfer (IXFR) is required, \fItype\fR is set to ixfr=N\&. The incremental zone transfer will contain the changes made to the zone since the serial number in the zone's SOA record was \fIN\fR\&. .PP -The -\fB\-q\fR -option sets the query name to -\fIname\fR. This useful do distinguish the -\fIname\fR -from other arguments. +The \fB\-q\fR option sets the query name to \fIname\fR\&. This useful do distinguish the \fIname\fR from other arguments\&. .PP -Reverse lookups \(em mapping addresses to names \(em are simplified by the -\fB\-x\fR -option. -\fIaddr\fR -is an IPv4 address in dotted\-decimal notation, or a colon\-delimited IPv6 address. When this option is used, there is no need to provide the -\fIname\fR, -\fIclass\fR -and -\fItype\fR -arguments. -\fBdig\fR -automatically performs a lookup for a name like -11.12.13.10.in\-addr.arpa -and sets the query type and class to PTR and IN respectively. By default, IPv6 addresses are looked up using nibble format under the IP6.ARPA domain. To use the older RFC1886 method using the IP6.INT domain specify the -\fB\-i\fR -option. Bit string labels (RFC2874) are now experimental and are not attempted. +Reverse lookups -- mapping addresses to names -- are simplified by the \fB\-x\fR option\&. \fIaddr\fR is an IPv4 address in dotted\-decimal notation, or a colon\-delimited IPv6 address\&. When this option is used, there is no need to provide the \fIname\fR, \fIclass\fR and \fItype\fR arguments\&. \fBdig\fR automatically performs a lookup for a name like 11\&.12\&.13\&.10\&.in\-addr\&.arpa and sets the query type and class to PTR and IN respectively\&. By default, IPv6 addresses are looked up using nibble format under the IP6\&.ARPA domain\&. To use the older RFC1886 method using the IP6\&.INT domain specify the \fB\-i\fR option\&. Bit string labels (RFC2874) are now experimental and are not attempted\&. .PP -To sign the DNS queries sent by -\fBdig\fR -and their responses using transaction signatures (TSIG), specify a TSIG key file using the -\fB\-k\fR -option. You can also specify the TSIG key itself on the command line using the -\fB\-y\fR -option; -\fIhmac\fR -is the type of the TSIG, default HMAC\-MD5, -\fIname\fR -is the name of the TSIG key and -\fIkey\fR -is the actual key. The key is a base\-64 encoded string, typically generated by -\fBdnssec\-keygen\fR(8). Caution should be taken when using the -\fB\-y\fR -option on multi\-user systems as the key can be visible in the output from -\fBps\fR(1) -or in the shell's history file. When using TSIG authentication with -\fBdig\fR, the name server that is queried needs to know the key and algorithm that is being used. In BIND, this is done by providing appropriate -\fBkey\fR -and -\fBserver\fR -statements in -\fInamed.conf\fR. +To sign the DNS queries sent by \fBdig\fR and their responses using transaction signatures (TSIG), specify a TSIG key file using the \fB\-k\fR option\&. You can also specify the TSIG key itself on the command line using the \fB\-y\fR option; \fIhmac\fR is the type of the TSIG, default HMAC\-MD5, \fIname\fR is the name of the TSIG key and \fIkey\fR is the actual key\&. The key is a base\-64 encoded string, typically generated by \fBdnssec\-keygen\fR(8)\&. Caution should be taken when using the \fB\-y\fR option on multi\-user systems as the key can be visible in the output from \fBps\fR(1) or in the shell's history file\&. When using TSIG authentication with \fBdig\fR, the name server that is queried needs to know the key and algorithm that is being used\&. In BIND, this is done by providing appropriate \fBkey\fR and \fBserver\fR statements in \fInamed\&.conf\fR\&. .SH "QUERY OPTIONS" .PP -\fBdig\fR -provides a number of query options which affect the way in which lookups are made and the results displayed. Some of these set or reset flag bits in the query header, some determine which sections of the answer get printed, and others determine the timeout and retry strategies. -.PP -Each query option is identified by a keyword preceded by a plus sign (+). Some keywords set or reset an option. These may be preceded by the string -no -to negate the meaning of that keyword. Other keywords assign values to options like the timeout interval. They have the form -\fB+keyword=value\fR. The query options are: +\fBdig\fR provides a number of query options which affect the way in which lookups are made and the results displayed\&. Some of these set or reset flag bits in the query header, some determine which sections of the answer get printed, and others determine the timeout and retry strategies\&. .PP +Each query option is identified by a keyword preceded by a plus sign (+)\&. Some keywords set or reset an option\&. These may be preceded by the string no to negate the meaning of that keyword\&. Other keywords assign values to options like the timeout interval\&. They have the form \fB+keyword=value\fR\&. The query options are: +.TP \fB+[no]tcp\fR -.RS 4 -Use [do not use] TCP when querying name servers. The default behavior is to use UDP unless an AXFR or IXFR query is requested, in which case a TCP connection is used. -.RE -.PP +Use [do not use] TCP when querying name servers\&. The default behavior is to use UDP unless an AXFR or IXFR query is requested, in which case a TCP connection is used\&. +.TP \fB+[no]vc\fR -.RS 4 -Use [do not use] TCP when querying name servers. This alternate syntax to -\fI+[no]tcp\fR -is provided for backwards compatibility. The "vc" stands for "virtual circuit". -.RE -.PP +Use [do not use] TCP when querying name servers\&. This alternate syntax to \fI+[no]tcp\fR is provided for backwards compatibility\&. The "vc" stands for "virtual circuit"\&. +.TP \fB+[no]ignore\fR -.RS 4 -Ignore truncation in UDP responses instead of retrying with TCP. By default, TCP retries are performed. -.RE -.PP +Ignore truncation in UDP responses instead of retrying with TCP\&. By default, TCP retries are performed\&. +.TP \fB+domain=somename\fR -.RS 4 -Set the search list to contain the single domain -\fIsomename\fR, as if specified in a -\fBdomain\fR -directive in -\fI/etc/resolv.conf\fR, and enable search list processing as if the -\fI+search\fR -option were given. -.RE -.PP +Set the search list to contain the single domain \fIsomename\fR, as if specified in a \fBdomain\fR directive in \fI/etc/resolv\&.conf\fR, and enable search list processing as if the \fI+search\fR option were given\&. +.TP \fB+[no]search\fR -.RS 4 -Use [do not use] the search list defined by the searchlist or domain directive in -\fIresolv.conf\fR -(if any). The search list is not used by default. -.RE -.PP +Use [do not use] the search list defined by the searchlist or domain directive in \fIresolv\&.conf\fR (if any)\&. The search list is not used by default\&. +.TP \fB+[no]showsearch\fR -.RS 4 -Perform [do not perform] a search showing intermediate results. -.RE -.PP +Perform [do not perform] a search showing intermediate results\&. +.TP \fB+[no]defname\fR -.RS 4 -Deprecated, treated as a synonym for -\fI+[no]search\fR -.RE -.PP +Deprecated, treated as a synonym for \fI+[no]search\fR +.TP \fB+[no]aaonly\fR -.RS 4 -Sets the "aa" flag in the query. -.RE -.PP +Sets the "aa" flag in the query\&. +.TP \fB+[no]aaflag\fR -.RS 4 -A synonym for -\fI+[no]aaonly\fR. -.RE -.PP +A synonym for \fI+[no]aaonly\fR\&. +.TP \fB+[no]adflag\fR -.RS 4 -Set [do not set] the AD (authentic data) bit in the query. The AD bit currently has a standard meaning only in responses, not in queries, but the ability to set the bit in the query is provided for completeness. -.RE -.PP +Set [do not set] the AD (authentic data) bit in the query\&. The AD bit currently has a standard meaning only in responses, not in queries, but the ability to set the bit in the query is provided for completeness\&. +.TP \fB+[no]cdflag\fR -.RS 4 -Set [do not set] the CD (checking disabled) bit in the query. This requests the server to not perform DNSSEC validation of responses. -.RE -.PP +Set [do not set] the CD (checking disabled) bit in the query\&. This requests the server to not perform DNSSEC validation of responses\&. +.TP \fB+[no]cl\fR -.RS 4 -Display [do not display] the CLASS when printing the record. -.RE -.PP +Display [do not display] the CLASS when printing the record\&. +.TP \fB+[no]ttlid\fR -.RS 4 -Display [do not display] the TTL when printing the record. -.RE -.PP +Display [do not display] the TTL when printing the record\&. +.TP \fB+[no]recurse\fR -.RS 4 -Toggle the setting of the RD (recursion desired) bit in the query. This bit is set by default, which means -\fBdig\fR -normally sends recursive queries. Recursion is automatically disabled when the -\fI+nssearch\fR -or -\fI+trace\fR -query options are used. -.RE -.PP +Toggle the setting of the RD (recursion desired) bit in the query\&. This bit is set by default, which means \fBdig\fR normally sends recursive queries\&. Recursion is automatically disabled when the \fI+nssearch\fR or \fI+trace\fR query options are used\&. +.TP \fB+[no]nssearch\fR -.RS 4 -When this option is set, -\fBdig\fR -attempts to find the authoritative name servers for the zone containing the name being looked up and display the SOA record that each name server has for the zone. -.RE -.PP +When this option is set, \fBdig\fR attempts to find the authoritative name servers for the zone containing the name being looked up and display the SOA record that each name server has for the zone\&. +.TP \fB+[no]trace\fR -.RS 4 -Toggle tracing of the delegation path from the root name servers for the name being looked up. Tracing is disabled by default. When tracing is enabled, -\fBdig\fR -makes iterative queries to resolve the name being looked up. It will follow referrals from the root servers, showing the answer from each server that was used to resolve the lookup. -.RE -.PP +Toggle tracing of the delegation path from the root name servers for the name being looked up\&. Tracing is disabled by default\&. When tracing is enabled, \fBdig\fR makes iterative queries to resolve the name being looked up\&. It will follow referrals from the root servers, showing the answer from each server that was used to resolve the lookup\&. +.TP \fB+[no]cmd\fR -.RS 4 -Toggles the printing of the initial comment in the output identifying the version of -\fBdig\fR -and the query options that have been applied. This comment is printed by default. -.RE -.PP +Toggles the printing of the initial comment in the output identifying the version of \fBdig\fR and the query options that have been applied\&. This comment is printed by default\&. +.TP \fB+[no]short\fR -.RS 4 -Provide a terse answer. The default is to print the answer in a verbose form. -.RE -.PP +Provide a terse answer\&. The default is to print the answer in a verbose form\&. +.TP \fB+[no]identify\fR -.RS 4 -Show [or do not show] the IP address and port number that supplied the answer when the -\fI+short\fR -option is enabled. If short form answers are requested, the default is not to show the source address and port number of the server that provided the answer. -.RE -.PP +Show [or do not show] the IP address and port number that supplied the answer when the \fI+short\fR option is enabled\&. If short form answers are requested, the default is not to show the source address and port number of the server that provided the answer\&. +.TP \fB+[no]comments\fR -.RS 4 -Toggle the display of comment lines in the output. The default is to print comments. -.RE -.PP +Toggle the display of comment lines in the output\&. The default is to print comments\&. +.TP \fB+[no]stats\fR -.RS 4 -This query option toggles the printing of statistics: when the query was made, the size of the reply and so on. The default behavior is to print the query statistics. -.RE -.PP +This query option toggles the printing of statistics: when the query was made, the size of the reply and so on\&. The default behavior is to print the query statistics\&. +.TP \fB+[no]qr\fR -.RS 4 -Print [do not print] the query as it is sent. By default, the query is not printed. -.RE -.PP +Print [do not print] the query as it is sent\&. By default, the query is not printed\&. +.TP \fB+[no]question\fR -.RS 4 -Print [do not print] the question section of a query when an answer is returned. The default is to print the question section as a comment. -.RE -.PP +Print [do not print] the question section of a query when an answer is returned\&. The default is to print the question section as a comment\&. +.TP \fB+[no]answer\fR -.RS 4 -Display [do not display] the answer section of a reply. The default is to display it. -.RE -.PP +Display [do not display] the answer section of a reply\&. The default is to display it\&. +.TP \fB+[no]authority\fR -.RS 4 -Display [do not display] the authority section of a reply. The default is to display it. -.RE -.PP +Display [do not display] the authority section of a reply\&. The default is to display it\&. +.TP \fB+[no]additional\fR -.RS 4 -Display [do not display] the additional section of a reply. The default is to display it. -.RE -.PP +Display [do not display] the additional section of a reply\&. The default is to display it\&. +.TP \fB+[no]all\fR -.RS 4 -Set or clear all display flags. -.RE -.PP +Set or clear all display flags\&. +.TP \fB+time=T\fR -.RS 4 -Sets the timeout for a query to -\fIT\fR -seconds. The default timeout is 5 seconds. An attempt to set -\fIT\fR -to less than 1 will result in a query timeout of 1 second being applied. -.RE -.PP +Sets the timeout for a query to \fIT\fR seconds\&. The default timeout is 5 seconds\&. An attempt to set \fIT\fR to less than 1 will result in a query timeout of 1 second being applied\&. +.TP \fB+tries=T\fR -.RS 4 -Sets the number of times to try UDP queries to server to -\fIT\fR -instead of the default, 3. If -\fIT\fR -is less than or equal to zero, the number of tries is silently rounded up to 1. -.RE -.PP +Sets the number of times to try UDP queries to server to \fIT\fR instead of the default, 3\&. If \fIT\fR is less than or equal to zero, the number of tries is silently rounded up to 1\&. +.TP \fB+retry=T\fR -.RS 4 -Sets the number of times to retry UDP queries to server to -\fIT\fR -instead of the default, 2. Unlike -\fI+tries\fR, this does not include the initial query. -.RE -.PP +Sets the number of times to retry UDP queries to server to \fIT\fR instead of the default, 2\&. Unlike \fI+tries\fR, this does not include the initial query\&. +.TP \fB+ndots=D\fR -.RS 4 -Set the number of dots that have to appear in -\fIname\fR -to -\fID\fR -for it to be considered absolute. The default value is that defined using the ndots statement in -\fI/etc/resolv.conf\fR, or 1 if no ndots statement is present. Names with fewer dots are interpreted as relative names and will be searched for in the domains listed in the -\fBsearch\fR -or -\fBdomain\fR -directive in -\fI/etc/resolv.conf\fR. -.RE -.PP +Set the number of dots that have to appear in \fIname\fR to \fID\fR for it to be considered absolute\&. The default value is that defined using the ndots statement in \fI/etc/resolv\&.conf\fR, or 1 if no ndots statement is present\&. Names with fewer dots are interpreted as relative names and will be searched for in the domains listed in the \fBsearch\fR or \fBdomain\fR directive in \fI/etc/resolv\&.conf\fR\&. +.TP \fB+bufsize=B\fR -.RS 4 -Set the UDP message buffer size advertised using EDNS0 to -\fIB\fR -bytes. The maximum and minimum sizes of this buffer are 65535 and 0 respectively. Values outside this range are rounded up or down appropriately. Values other than zero will cause a EDNS query to be sent. -.RE -.PP +Set the UDP message buffer size advertised using EDNS0 to \fIB\fR bytes\&. The maximum and minimum sizes of this buffer are 65535 and 0 respectively\&. Values outside this range are rounded up or down appropriately\&. Values other than zero will cause a EDNS query to be sent\&. +.TP \fB+edns=#\fR -.RS 4 -Specify the EDNS version to query with. Valid values are 0 to 255. Setting the EDNS version will cause a EDNS query to be sent. -\fB+noedns\fR -clears the remembered EDNS version. -.RE -.PP +Specify the EDNS version to query with\&. Valid values are 0 to 255\&. Setting the EDNS version will cause a EDNS query to be sent\&. \fB+noedns\fR clears the remembered EDNS version\&. +.TP \fB+[no]multiline\fR -.RS 4 -Print records like the SOA records in a verbose multi\-line format with human\-readable comments. The default is to print each record on a single line, to facilitate machine parsing of the -\fBdig\fR -output. -.RE -.PP +Print records like the SOA records in a verbose multi\-line format with human\-readable comments\&. The default is to print each record on a single line, to facilitate machine parsing of the \fBdig\fR output\&. +.TP \fB+[no]fail\fR -.RS 4 -Do not try the next server if you receive a SERVFAIL. The default is to not try the next server which is the reverse of normal stub resolver behavior. -.RE -.PP +Do not try the next server if you receive a SERVFAIL\&. The default is to not try the next server which is the reverse of normal stub resolver behavior\&. +.TP \fB+[no]besteffort\fR -.RS 4 -Attempt to display the contents of messages which are malformed. The default is to not display malformed answers. -.RE -.PP +Attempt to display the contents of messages which are malformed\&. The default is to not display malformed answers\&. +.TP \fB+[no]dnssec\fR -.RS 4 -Requests DNSSEC records be sent by setting the DNSSEC OK bit (DO) in the OPT record in the additional section of the query. -.RE -.PP +Requests DNSSEC records be sent by setting the DNSSEC OK bit (DO) in the OPT record in the additional section of the query\&. +.TP \fB+[no]sigchase\fR -.RS 4 -Chase DNSSEC signature chains. Requires dig be compiled with \-DDIG_SIGCHASE. -.RE -.PP +Chase DNSSEC signature chains\&. Requires dig be compiled with \-DDIG_SIGCHASE\&. +.TP \fB+trusted\-key=####\fR -.RS 4 -Specifies a file containing trusted keys to be used with -\fB+sigchase\fR. Each DNSKEY record must be on its own line. -.sp -If not specified -\fBdig\fR -will look for -\fI/etc/trusted\-key.key\fR -then -\fItrusted\-key.key\fR -in the current directory. -.sp -Requires dig be compiled with \-DDIG_SIGCHASE. -.RE -.PP +Specifies a file containing trusted keys to be used with \fB+sigchase\fR\&. Each DNSKEY record must be on its own line\&. +If not specified \fBdig\fR will look for \fI/etc/trusted\-key\&.key\fR then \fItrusted\-key\&.key\fR in the current directory\&. +Requires dig be compiled with \-DDIG_SIGCHASE\&. +.TP \fB+[no]topdown\fR -.RS 4 -When chasing DNSSEC signature chains perform a top\-down validation. Requires dig be compiled with \-DDIG_SIGCHASE. -.RE +When chasing DNSSEC signature chains perform a top\-down validation\&. Requires dig be compiled with \-DDIG_SIGCHASE\&. +.TP +\fB+[no]nsid\fR +Include an EDNS name server ID request when sending a query\&. .SH "MULTIPLE QUERIES" .PP -The BIND 9 implementation of -\fBdig \fR -supports specifying multiple queries on the command line (in addition to supporting the -\fB\-f\fR -batch file option). Each of those queries can be supplied with its own set of flags, options and query options. +The BIND 9 implementation of \fBdig \fR supports specifying multiple queries on the command line (in addition to supporting the \fB\-f\fR batch file option)\&. Each of those queries can be supplied with its own set of flags, options and query options\&. .PP -In this case, each -\fIquery\fR -argument represent an individual query in the command\-line syntax described above. Each consists of any of the standard options and flags, the name to be looked up, an optional query type and class and any query options that should be applied to that query. +In this case, each \fIquery\fR argument represent an individual query in the command\-line syntax described above\&. Each consists of any of the standard options and flags, the name to be looked up, an optional query type and class and any query options that should be applied to that query\&. .PP -A global set of query options, which should be applied to all queries, can also be supplied. These global query options must precede the first tuple of name, class, type, options, flags, and query options supplied on the command line. Any global query options (except the -\fB+[no]cmd\fR -option) can be overridden by a query\-specific set of query options. For example: -.sp -.RS 4 +A global set of query options, which should be applied to all queries, can also be supplied\&. These global query options must precede the first tuple of name, class, type, options, flags, and query options supplied on the command line\&. Any global query options (except the \fB+[no]cmd\fR option) can be overridden by a query\-specific set of query options\&. For example: .nf -dig +qr www.isc.org any \-x 127.0.0.1 isc.org ns +noqr +dig +qr www\&.isc\&.org any \-x 127\&.0\&.0\&.1 isc\&.org ns +noqr .fi -.RE -.sp -shows how -\fBdig\fR -could be used from the command line to make three lookups: an ANY query for -www.isc.org, a reverse lookup of 127.0.0.1 and a query for the NS records of -isc.org. A global query option of -\fI+qr\fR -is applied, so that -\fBdig\fR -shows the initial query it made for each lookup. The final query has a local query option of -\fI+noqr\fR -which means that -\fBdig\fR -will not print the initial query when it looks up the NS records for -isc.org. + shows how \fBdig\fR could be used from the command line to make three lookups: an ANY query for www\&.isc\&.org, a reverse lookup of 127\&.0\&.0\&.1 and a query for the NS records of isc\&.org\&. A global query option of \fI+qr\fR is applied, so that \fBdig\fR shows the initial query it made for each lookup\&. The final query has a local query option of \fI+noqr\fR which means that \fBdig\fR will not print the initial query when it looks up the NS records for isc\&.org\&. .SH "IDN SUPPORT" .PP -If -\fBdig\fR -has been built with IDN (internationalized domain name) support, it can accept and display non\-ASCII domain names. -\fBdig\fR -appropriately converts character encoding of domain name before sending a request to DNS server or displaying a reply from the server. If you'd like to turn off the IDN support for some reason, defines the -\fBIDN_DISABLE\fR -environment variable. The IDN support is disabled if the variable is set when -\fBdig\fR -runs. +If \fBdig\fR has been built with IDN (internationalized domain name) support, it can accept and display non\-ASCII domain names\&. \fBdig\fR appropriately converts character encoding of domain name before sending a request to DNS server or displaying a reply from the server\&. If you'd like to turn off the IDN support for some reason, defines the \fBIDN_DISABLE\fR environment variable\&. The IDN support is disabled if the variable is set when \fBdig\fR runs\&. .SH "FILES" .PP -\fI/etc/resolv.conf\fR +\fI/etc/resolv\&.conf\fR .PP -\fI${HOME}/.digrc\fR +\fI${HOME}/\&.digrc\fR .SH "SEE ALSO" .PP -\fBhost\fR(1), -\fBnamed\fR(8), -\fBdnssec\-keygen\fR(8), -RFC1035. +\fBhost\fR(1), \fBnamed\fR(8), \fBdnssec\-keygen\fR(8), RFC1035\&. .SH "BUGS" .PP -There are probably too many query options. -.SH "COPYRIGHT" -Copyright \(co 2004\-2007 Internet Systems Consortium, Inc. ("ISC") -.br -Copyright \(co 2000\-2003 Internet Software Consortium. -.br +There are probably too many query options\&. diff --git a/bin/dig/dig.docbook b/bin/dig/dig.docbook index bb469619bd..4ef19498b2 100644 --- a/bin/dig/dig.docbook +++ b/bin/dig/dig.docbook @@ -18,7 +18,7 @@ - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -829,6 +829,14 @@ + + + + + Include an EDNS name server ID request when sending a query. + + + From 8dc5d5e460da15b2481893687cad7e5b72d0314a Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Wed, 14 May 2008 01:12:08 +0000 Subject: [PATCH 072/137] regen --- bin/dig/dig.1 | 595 ++++++++++++++++++++------- bin/dig/dig.html | 16 +- doc/arm/man.dig.html | 24 +- doc/arm/man.dnssec-keyfromlabel.html | 12 +- doc/arm/man.dnssec-keygen.html | 14 +- doc/arm/man.dnssec-signzone.html | 12 +- doc/arm/man.host.html | 10 +- doc/arm/man.named-checkconf.html | 12 +- doc/arm/man.named-checkzone.html | 12 +- doc/arm/man.named.html | 16 +- doc/arm/man.rndc-confgen.html | 12 +- doc/arm/man.rndc.conf.html | 12 +- doc/arm/man.rndc.html | 12 +- 13 files changed, 539 insertions(+), 220 deletions(-) diff --git a/bin/dig/dig.1 b/bin/dig/dig.1 index f95ad1c794..65a451964c 100644 --- a/bin/dig/dig.1 +++ b/bin/dig/dig.1 @@ -13,239 +13,550 @@ .\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR .\" PERFORMANCE OF THIS SOFTWARE. .\" -.\" $Id: dig.1,v 1.46 2008/05/13 23:59:18 each Exp $ +.\" $Id: dig.1,v 1.47 2008/05/14 01:12:07 tbox Exp $ .\" .hy 0 .ad l -.\"Generated by db2man.xsl. Don't modify this, modify the source. -.de Sh \" Subsection -.br -.if t .Sp -.ne 5 -.PP -\fB\\$1\fR -.PP -.. -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Ip \" List item -.br -.ie \\n(.$>=3 .ne \\$3 -.el .ne 3 -.IP "\\$1" \\$2 -.. -.TH "DIG" 1 "Jun 30, 2000" "" "" -.SH NAME +.\" Title: dig +.\" Author: +.\" Generator: DocBook XSL Stylesheets v1.71.1 +.\" Date: Jun 30, 2000 +.\" Manual: BIND9 +.\" Source: BIND9 +.\" +.TH "DIG" "1" "Jun 30, 2000" "BIND9" "BIND9" +.\" disable hyphenation +.nh +.\" disable justification (adjust text to left margin only) +.ad l +.SH "NAME" dig \- DNS lookup utility .SH "SYNOPSIS" .HP 4 -\fBdig\fR [@server] [\fB\-b\ \fIaddress\fR\fR] [\fB\-c\ \fIclass\fR\fR] [\fB\-f\ \fIfilename\fR\fR] [\fB\-k\ \fIfilename\fR\fR] [\fB\-p\ \fIport#\fR\fR] [\fB\-q\ \fIname\fR\fR] [\fB\-t\ \fItype\fR\fR] [\fB\-x\ \fIaddr\fR\fR] [\fB\-y\ \fI[hmac:]name:key\fR\fR] [\fB\-4\fR] [\fB\-6\fR] [name] [type] [class] [queryopt...] +\fBdig\fR [@server] [\fB\-b\ \fR\fB\fIaddress\fR\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-f\ \fR\fB\fIfilename\fR\fR] [\fB\-k\ \fR\fB\fIfilename\fR\fR] [\fB\-p\ \fR\fB\fIport#\fR\fR] [\fB\-q\ \fR\fB\fIname\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-x\ \fR\fB\fIaddr\fR\fR] [\fB\-y\ \fR\fB\fI[hmac:]\fR\fIname:key\fR\fR] [\fB\-4\fR] [\fB\-6\fR] [name] [type] [class] [queryopt...] .HP 4 \fBdig\fR [\fB\-h\fR] .HP 4 \fBdig\fR [global\-queryopt...] [query...] .SH "DESCRIPTION" .PP -\fBdig\fR (domain information groper) is a flexible tool for interrogating DNS name servers\&. It performs DNS lookups and displays the answers that are returned from the name server(s) that were queried\&. Most DNS administrators use \fBdig\fR to troubleshoot DNS problems because of its flexibility, ease of use and clarity of output\&. Other lookup tools tend to have less functionality than \fBdig\fR\&. +\fBdig\fR +(domain information groper) is a flexible tool for interrogating DNS name servers. It performs DNS lookups and displays the answers that are returned from the name server(s) that were queried. Most DNS administrators use +\fBdig\fR +to troubleshoot DNS problems because of its flexibility, ease of use and clarity of output. Other lookup tools tend to have less functionality than +\fBdig\fR. .PP -Although \fBdig\fR is normally used with command\-line arguments, it also has a batch mode of operation for reading lookup requests from a file\&. A brief summary of its command\-line arguments and options is printed when the \fB\-h\fR option is given\&. Unlike earlier versions, the BIND 9 implementation of \fBdig\fR allows multiple lookups to be issued from the command line\&. +Although +\fBdig\fR +is normally used with command\-line arguments, it also has a batch mode of operation for reading lookup requests from a file. A brief summary of its command\-line arguments and options is printed when the +\fB\-h\fR +option is given. Unlike earlier versions, the BIND 9 implementation of +\fBdig\fR +allows multiple lookups to be issued from the command line. .PP -Unless it is told to query a specific name server, \fBdig\fR will try each of the servers listed in \fI/etc/resolv\&.conf\fR\&. +Unless it is told to query a specific name server, +\fBdig\fR +will try each of the servers listed in +\fI/etc/resolv.conf\fR. .PP -When no command line arguments or options are given, will perform an NS query for "\&." (the root)\&. +When no command line arguments or options are given, will perform an NS query for "." (the root). .PP -It is possible to set per\-user defaults for \fBdig\fR via \fI${HOME}/\&.digrc\fR\&. This file is read and any options in it are applied before the command line arguments\&. +It is possible to set per\-user defaults for +\fBdig\fR +via +\fI${HOME}/.digrc\fR. This file is read and any options in it are applied before the command line arguments. .PP -The IN and CH class names overlap with the IN and CH top level domains names\&. Either use the \fB\-t\fR and \fB\-c\fR options to specify the type and class or use the \fB\-q\fR the specify the domain name or use "IN\&." and "CH\&." when looking up these top level domains\&. +The IN and CH class names overlap with the IN and CH top level domains names. Either use the +\fB\-t\fR +and +\fB\-c\fR +options to specify the type and class or use the +\fB\-q\fR +the specify the domain name or use "IN." and "CH." when looking up these top level domains. .SH "SIMPLE USAGE" .PP -A typical invocation of \fBdig\fR looks like: +A typical invocation of +\fBdig\fR +looks like: +.sp +.RS 4 .nf dig @server name type .fi - where: -.TP +.RE +.sp +where: +.PP \fBserver\fR -is the name or IP address of the name server to query\&. This can be an IPv4 address in dotted\-decimal notation or an IPv6 address in colon\-delimited notation\&. When the supplied \fIserver\fR argument is a hostname, \fBdig\fR resolves that name before querying that name server\&. If no \fIserver\fR argument is provided, \fBdig\fR consults \fI/etc/resolv\&.conf\fR and queries the name servers listed there\&. The reply from the name server that responds is displayed\&. -.TP +.RS 4 +is the name or IP address of the name server to query. This can be an IPv4 address in dotted\-decimal notation or an IPv6 address in colon\-delimited notation. When the supplied +\fIserver\fR +argument is a hostname, +\fBdig\fR +resolves that name before querying that name server. If no +\fIserver\fR +argument is provided, +\fBdig\fR +consults +\fI/etc/resolv.conf\fR +and queries the name servers listed there. The reply from the name server that responds is displayed. +.RE +.PP \fBname\fR -is the name of the resource record that is to be looked up\&. -.TP +.RS 4 +is the name of the resource record that is to be looked up. +.RE +.PP \fBtype\fR -indicates what type of query is required -- ANY, A, MX, SIG, etc\&. \fItype\fR can be any valid query type\&. If no \fItype\fR argument is supplied, \fBdig\fR will perform a lookup for an A record\&. +.RS 4 +indicates what type of query is required \(em ANY, A, MX, SIG, etc. +\fItype\fR +can be any valid query type. If no +\fItype\fR +argument is supplied, +\fBdig\fR +will perform a lookup for an A record. +.RE .SH "OPTIONS" .PP -The \fB\-b\fR option sets the source IP address of the query to \fIaddress\fR\&. This must be a valid address on one of the host's network interfaces or "0\&.0\&.0\&.0" or "::"\&. An optional port may be specified by appending "#" +The +\fB\-b\fR +option sets the source IP address of the query to +\fIaddress\fR. This must be a valid address on one of the host's network interfaces or "0.0.0.0" or "::". An optional port may be specified by appending "#" .PP -The default query class (IN for internet) is overridden by the \fB\-c\fR option\&. \fIclass\fR is any valid class, such as HS for Hesiod records or CH for Chaosnet records\&. +The default query class (IN for internet) is overridden by the +\fB\-c\fR +option. +\fIclass\fR +is any valid class, such as HS for Hesiod records or CH for Chaosnet records. .PP -The \fB\-f\fR option makes \fBdig \fR operate in batch mode by reading a list of lookup requests to process from the file \fIfilename\fR\&. The file contains a number of queries, one per line\&. Each entry in the file should be organized in the same way they would be presented as queries to \fBdig\fR using the command\-line interface\&. +The +\fB\-f\fR +option makes +\fBdig \fR +operate in batch mode by reading a list of lookup requests to process from the file +\fIfilename\fR. The file contains a number of queries, one per line. Each entry in the file should be organized in the same way they would be presented as queries to +\fBdig\fR +using the command\-line interface. .PP -If a non\-standard port number is to be queried, the \fB\-p\fR option is used\&. \fIport#\fR is the port number that \fBdig\fR will send its queries instead of the standard DNS port number 53\&. This option would be used to test a name server that has been configured to listen for queries on a non\-standard port number\&. +If a non\-standard port number is to be queried, the +\fB\-p\fR +option is used. +\fIport#\fR +is the port number that +\fBdig\fR +will send its queries instead of the standard DNS port number 53. This option would be used to test a name server that has been configured to listen for queries on a non\-standard port number. .PP -The \fB\-4\fR option forces \fBdig\fR to only use IPv4 query transport\&. The \fB\-6\fR option forces \fBdig\fR to only use IPv6 query transport\&. +The +\fB\-4\fR +option forces +\fBdig\fR +to only use IPv4 query transport. The +\fB\-6\fR +option forces +\fBdig\fR +to only use IPv6 query transport. .PP -The \fB\-t\fR option sets the query type to \fItype\fR\&. It can be any valid query type which is supported in BIND 9\&. The default query type is "A", unless the \fB\-x\fR option is supplied to indicate a reverse lookup\&. A zone transfer can be requested by specifying a type of AXFR\&. When an incremental zone transfer (IXFR) is required, \fItype\fR is set to ixfr=N\&. The incremental zone transfer will contain the changes made to the zone since the serial number in the zone's SOA record was \fIN\fR\&. +The +\fB\-t\fR +option sets the query type to +\fItype\fR. It can be any valid query type which is supported in BIND 9. The default query type is "A", unless the +\fB\-x\fR +option is supplied to indicate a reverse lookup. A zone transfer can be requested by specifying a type of AXFR. When an incremental zone transfer (IXFR) is required, +\fItype\fR +is set to +ixfr=N. The incremental zone transfer will contain the changes made to the zone since the serial number in the zone's SOA record was +\fIN\fR. .PP -The \fB\-q\fR option sets the query name to \fIname\fR\&. This useful do distinguish the \fIname\fR from other arguments\&. +The +\fB\-q\fR +option sets the query name to +\fIname\fR. This useful do distinguish the +\fIname\fR +from other arguments. .PP -Reverse lookups -- mapping addresses to names -- are simplified by the \fB\-x\fR option\&. \fIaddr\fR is an IPv4 address in dotted\-decimal notation, or a colon\-delimited IPv6 address\&. When this option is used, there is no need to provide the \fIname\fR, \fIclass\fR and \fItype\fR arguments\&. \fBdig\fR automatically performs a lookup for a name like 11\&.12\&.13\&.10\&.in\-addr\&.arpa and sets the query type and class to PTR and IN respectively\&. By default, IPv6 addresses are looked up using nibble format under the IP6\&.ARPA domain\&. To use the older RFC1886 method using the IP6\&.INT domain specify the \fB\-i\fR option\&. Bit string labels (RFC2874) are now experimental and are not attempted\&. +Reverse lookups \(em mapping addresses to names \(em are simplified by the +\fB\-x\fR +option. +\fIaddr\fR +is an IPv4 address in dotted\-decimal notation, or a colon\-delimited IPv6 address. When this option is used, there is no need to provide the +\fIname\fR, +\fIclass\fR +and +\fItype\fR +arguments. +\fBdig\fR +automatically performs a lookup for a name like +11.12.13.10.in\-addr.arpa +and sets the query type and class to PTR and IN respectively. By default, IPv6 addresses are looked up using nibble format under the IP6.ARPA domain. To use the older RFC1886 method using the IP6.INT domain specify the +\fB\-i\fR +option. Bit string labels (RFC2874) are now experimental and are not attempted. .PP -To sign the DNS queries sent by \fBdig\fR and their responses using transaction signatures (TSIG), specify a TSIG key file using the \fB\-k\fR option\&. You can also specify the TSIG key itself on the command line using the \fB\-y\fR option; \fIhmac\fR is the type of the TSIG, default HMAC\-MD5, \fIname\fR is the name of the TSIG key and \fIkey\fR is the actual key\&. The key is a base\-64 encoded string, typically generated by \fBdnssec\-keygen\fR(8)\&. Caution should be taken when using the \fB\-y\fR option on multi\-user systems as the key can be visible in the output from \fBps\fR(1) or in the shell's history file\&. When using TSIG authentication with \fBdig\fR, the name server that is queried needs to know the key and algorithm that is being used\&. In BIND, this is done by providing appropriate \fBkey\fR and \fBserver\fR statements in \fInamed\&.conf\fR\&. +To sign the DNS queries sent by +\fBdig\fR +and their responses using transaction signatures (TSIG), specify a TSIG key file using the +\fB\-k\fR +option. You can also specify the TSIG key itself on the command line using the +\fB\-y\fR +option; +\fIhmac\fR +is the type of the TSIG, default HMAC\-MD5, +\fIname\fR +is the name of the TSIG key and +\fIkey\fR +is the actual key. The key is a base\-64 encoded string, typically generated by +\fBdnssec\-keygen\fR(8). Caution should be taken when using the +\fB\-y\fR +option on multi\-user systems as the key can be visible in the output from +\fBps\fR(1) +or in the shell's history file. When using TSIG authentication with +\fBdig\fR, the name server that is queried needs to know the key and algorithm that is being used. In BIND, this is done by providing appropriate +\fBkey\fR +and +\fBserver\fR +statements in +\fInamed.conf\fR. .SH "QUERY OPTIONS" .PP -\fBdig\fR provides a number of query options which affect the way in which lookups are made and the results displayed\&. Some of these set or reset flag bits in the query header, some determine which sections of the answer get printed, and others determine the timeout and retry strategies\&. +\fBdig\fR +provides a number of query options which affect the way in which lookups are made and the results displayed. Some of these set or reset flag bits in the query header, some determine which sections of the answer get printed, and others determine the timeout and retry strategies. +.PP +Each query option is identified by a keyword preceded by a plus sign (+). Some keywords set or reset an option. These may be preceded by the string +no +to negate the meaning of that keyword. Other keywords assign values to options like the timeout interval. They have the form +\fB+keyword=value\fR. The query options are: .PP -Each query option is identified by a keyword preceded by a plus sign (+)\&. Some keywords set or reset an option\&. These may be preceded by the string no to negate the meaning of that keyword\&. Other keywords assign values to options like the timeout interval\&. They have the form \fB+keyword=value\fR\&. The query options are: -.TP \fB+[no]tcp\fR -Use [do not use] TCP when querying name servers\&. The default behavior is to use UDP unless an AXFR or IXFR query is requested, in which case a TCP connection is used\&. -.TP +.RS 4 +Use [do not use] TCP when querying name servers. The default behavior is to use UDP unless an AXFR or IXFR query is requested, in which case a TCP connection is used. +.RE +.PP \fB+[no]vc\fR -Use [do not use] TCP when querying name servers\&. This alternate syntax to \fI+[no]tcp\fR is provided for backwards compatibility\&. The "vc" stands for "virtual circuit"\&. -.TP +.RS 4 +Use [do not use] TCP when querying name servers. This alternate syntax to +\fI+[no]tcp\fR +is provided for backwards compatibility. The "vc" stands for "virtual circuit". +.RE +.PP \fB+[no]ignore\fR -Ignore truncation in UDP responses instead of retrying with TCP\&. By default, TCP retries are performed\&. -.TP +.RS 4 +Ignore truncation in UDP responses instead of retrying with TCP. By default, TCP retries are performed. +.RE +.PP \fB+domain=somename\fR -Set the search list to contain the single domain \fIsomename\fR, as if specified in a \fBdomain\fR directive in \fI/etc/resolv\&.conf\fR, and enable search list processing as if the \fI+search\fR option were given\&. -.TP +.RS 4 +Set the search list to contain the single domain +\fIsomename\fR, as if specified in a +\fBdomain\fR +directive in +\fI/etc/resolv.conf\fR, and enable search list processing as if the +\fI+search\fR +option were given. +.RE +.PP \fB+[no]search\fR -Use [do not use] the search list defined by the searchlist or domain directive in \fIresolv\&.conf\fR (if any)\&. The search list is not used by default\&. -.TP +.RS 4 +Use [do not use] the search list defined by the searchlist or domain directive in +\fIresolv.conf\fR +(if any). The search list is not used by default. +.RE +.PP \fB+[no]showsearch\fR -Perform [do not perform] a search showing intermediate results\&. -.TP +.RS 4 +Perform [do not perform] a search showing intermediate results. +.RE +.PP \fB+[no]defname\fR -Deprecated, treated as a synonym for \fI+[no]search\fR -.TP +.RS 4 +Deprecated, treated as a synonym for +\fI+[no]search\fR +.RE +.PP \fB+[no]aaonly\fR -Sets the "aa" flag in the query\&. -.TP +.RS 4 +Sets the "aa" flag in the query. +.RE +.PP \fB+[no]aaflag\fR -A synonym for \fI+[no]aaonly\fR\&. -.TP +.RS 4 +A synonym for +\fI+[no]aaonly\fR. +.RE +.PP \fB+[no]adflag\fR -Set [do not set] the AD (authentic data) bit in the query\&. The AD bit currently has a standard meaning only in responses, not in queries, but the ability to set the bit in the query is provided for completeness\&. -.TP +.RS 4 +Set [do not set] the AD (authentic data) bit in the query. The AD bit currently has a standard meaning only in responses, not in queries, but the ability to set the bit in the query is provided for completeness. +.RE +.PP \fB+[no]cdflag\fR -Set [do not set] the CD (checking disabled) bit in the query\&. This requests the server to not perform DNSSEC validation of responses\&. -.TP +.RS 4 +Set [do not set] the CD (checking disabled) bit in the query. This requests the server to not perform DNSSEC validation of responses. +.RE +.PP \fB+[no]cl\fR -Display [do not display] the CLASS when printing the record\&. -.TP +.RS 4 +Display [do not display] the CLASS when printing the record. +.RE +.PP \fB+[no]ttlid\fR -Display [do not display] the TTL when printing the record\&. -.TP +.RS 4 +Display [do not display] the TTL when printing the record. +.RE +.PP \fB+[no]recurse\fR -Toggle the setting of the RD (recursion desired) bit in the query\&. This bit is set by default, which means \fBdig\fR normally sends recursive queries\&. Recursion is automatically disabled when the \fI+nssearch\fR or \fI+trace\fR query options are used\&. -.TP +.RS 4 +Toggle the setting of the RD (recursion desired) bit in the query. This bit is set by default, which means +\fBdig\fR +normally sends recursive queries. Recursion is automatically disabled when the +\fI+nssearch\fR +or +\fI+trace\fR +query options are used. +.RE +.PP \fB+[no]nssearch\fR -When this option is set, \fBdig\fR attempts to find the authoritative name servers for the zone containing the name being looked up and display the SOA record that each name server has for the zone\&. -.TP +.RS 4 +When this option is set, +\fBdig\fR +attempts to find the authoritative name servers for the zone containing the name being looked up and display the SOA record that each name server has for the zone. +.RE +.PP \fB+[no]trace\fR -Toggle tracing of the delegation path from the root name servers for the name being looked up\&. Tracing is disabled by default\&. When tracing is enabled, \fBdig\fR makes iterative queries to resolve the name being looked up\&. It will follow referrals from the root servers, showing the answer from each server that was used to resolve the lookup\&. -.TP +.RS 4 +Toggle tracing of the delegation path from the root name servers for the name being looked up. Tracing is disabled by default. When tracing is enabled, +\fBdig\fR +makes iterative queries to resolve the name being looked up. It will follow referrals from the root servers, showing the answer from each server that was used to resolve the lookup. +.RE +.PP \fB+[no]cmd\fR -Toggles the printing of the initial comment in the output identifying the version of \fBdig\fR and the query options that have been applied\&. This comment is printed by default\&. -.TP +.RS 4 +Toggles the printing of the initial comment in the output identifying the version of +\fBdig\fR +and the query options that have been applied. This comment is printed by default. +.RE +.PP \fB+[no]short\fR -Provide a terse answer\&. The default is to print the answer in a verbose form\&. -.TP +.RS 4 +Provide a terse answer. The default is to print the answer in a verbose form. +.RE +.PP \fB+[no]identify\fR -Show [or do not show] the IP address and port number that supplied the answer when the \fI+short\fR option is enabled\&. If short form answers are requested, the default is not to show the source address and port number of the server that provided the answer\&. -.TP +.RS 4 +Show [or do not show] the IP address and port number that supplied the answer when the +\fI+short\fR +option is enabled. If short form answers are requested, the default is not to show the source address and port number of the server that provided the answer. +.RE +.PP \fB+[no]comments\fR -Toggle the display of comment lines in the output\&. The default is to print comments\&. -.TP +.RS 4 +Toggle the display of comment lines in the output. The default is to print comments. +.RE +.PP \fB+[no]stats\fR -This query option toggles the printing of statistics: when the query was made, the size of the reply and so on\&. The default behavior is to print the query statistics\&. -.TP +.RS 4 +This query option toggles the printing of statistics: when the query was made, the size of the reply and so on. The default behavior is to print the query statistics. +.RE +.PP \fB+[no]qr\fR -Print [do not print] the query as it is sent\&. By default, the query is not printed\&. -.TP +.RS 4 +Print [do not print] the query as it is sent. By default, the query is not printed. +.RE +.PP \fB+[no]question\fR -Print [do not print] the question section of a query when an answer is returned\&. The default is to print the question section as a comment\&. -.TP +.RS 4 +Print [do not print] the question section of a query when an answer is returned. The default is to print the question section as a comment. +.RE +.PP \fB+[no]answer\fR -Display [do not display] the answer section of a reply\&. The default is to display it\&. -.TP +.RS 4 +Display [do not display] the answer section of a reply. The default is to display it. +.RE +.PP \fB+[no]authority\fR -Display [do not display] the authority section of a reply\&. The default is to display it\&. -.TP +.RS 4 +Display [do not display] the authority section of a reply. The default is to display it. +.RE +.PP \fB+[no]additional\fR -Display [do not display] the additional section of a reply\&. The default is to display it\&. -.TP +.RS 4 +Display [do not display] the additional section of a reply. The default is to display it. +.RE +.PP \fB+[no]all\fR -Set or clear all display flags\&. -.TP +.RS 4 +Set or clear all display flags. +.RE +.PP \fB+time=T\fR -Sets the timeout for a query to \fIT\fR seconds\&. The default timeout is 5 seconds\&. An attempt to set \fIT\fR to less than 1 will result in a query timeout of 1 second being applied\&. -.TP +.RS 4 +Sets the timeout for a query to +\fIT\fR +seconds. The default timeout is 5 seconds. An attempt to set +\fIT\fR +to less than 1 will result in a query timeout of 1 second being applied. +.RE +.PP \fB+tries=T\fR -Sets the number of times to try UDP queries to server to \fIT\fR instead of the default, 3\&. If \fIT\fR is less than or equal to zero, the number of tries is silently rounded up to 1\&. -.TP +.RS 4 +Sets the number of times to try UDP queries to server to +\fIT\fR +instead of the default, 3. If +\fIT\fR +is less than or equal to zero, the number of tries is silently rounded up to 1. +.RE +.PP \fB+retry=T\fR -Sets the number of times to retry UDP queries to server to \fIT\fR instead of the default, 2\&. Unlike \fI+tries\fR, this does not include the initial query\&. -.TP +.RS 4 +Sets the number of times to retry UDP queries to server to +\fIT\fR +instead of the default, 2. Unlike +\fI+tries\fR, this does not include the initial query. +.RE +.PP \fB+ndots=D\fR -Set the number of dots that have to appear in \fIname\fR to \fID\fR for it to be considered absolute\&. The default value is that defined using the ndots statement in \fI/etc/resolv\&.conf\fR, or 1 if no ndots statement is present\&. Names with fewer dots are interpreted as relative names and will be searched for in the domains listed in the \fBsearch\fR or \fBdomain\fR directive in \fI/etc/resolv\&.conf\fR\&. -.TP +.RS 4 +Set the number of dots that have to appear in +\fIname\fR +to +\fID\fR +for it to be considered absolute. The default value is that defined using the ndots statement in +\fI/etc/resolv.conf\fR, or 1 if no ndots statement is present. Names with fewer dots are interpreted as relative names and will be searched for in the domains listed in the +\fBsearch\fR +or +\fBdomain\fR +directive in +\fI/etc/resolv.conf\fR. +.RE +.PP \fB+bufsize=B\fR -Set the UDP message buffer size advertised using EDNS0 to \fIB\fR bytes\&. The maximum and minimum sizes of this buffer are 65535 and 0 respectively\&. Values outside this range are rounded up or down appropriately\&. Values other than zero will cause a EDNS query to be sent\&. -.TP +.RS 4 +Set the UDP message buffer size advertised using EDNS0 to +\fIB\fR +bytes. The maximum and minimum sizes of this buffer are 65535 and 0 respectively. Values outside this range are rounded up or down appropriately. Values other than zero will cause a EDNS query to be sent. +.RE +.PP \fB+edns=#\fR -Specify the EDNS version to query with\&. Valid values are 0 to 255\&. Setting the EDNS version will cause a EDNS query to be sent\&. \fB+noedns\fR clears the remembered EDNS version\&. -.TP +.RS 4 +Specify the EDNS version to query with. Valid values are 0 to 255. Setting the EDNS version will cause a EDNS query to be sent. +\fB+noedns\fR +clears the remembered EDNS version. +.RE +.PP \fB+[no]multiline\fR -Print records like the SOA records in a verbose multi\-line format with human\-readable comments\&. The default is to print each record on a single line, to facilitate machine parsing of the \fBdig\fR output\&. -.TP +.RS 4 +Print records like the SOA records in a verbose multi\-line format with human\-readable comments. The default is to print each record on a single line, to facilitate machine parsing of the +\fBdig\fR +output. +.RE +.PP \fB+[no]fail\fR -Do not try the next server if you receive a SERVFAIL\&. The default is to not try the next server which is the reverse of normal stub resolver behavior\&. -.TP +.RS 4 +Do not try the next server if you receive a SERVFAIL. The default is to not try the next server which is the reverse of normal stub resolver behavior. +.RE +.PP \fB+[no]besteffort\fR -Attempt to display the contents of messages which are malformed\&. The default is to not display malformed answers\&. -.TP +.RS 4 +Attempt to display the contents of messages which are malformed. The default is to not display malformed answers. +.RE +.PP \fB+[no]dnssec\fR -Requests DNSSEC records be sent by setting the DNSSEC OK bit (DO) in the OPT record in the additional section of the query\&. -.TP +.RS 4 +Requests DNSSEC records be sent by setting the DNSSEC OK bit (DO) in the OPT record in the additional section of the query. +.RE +.PP \fB+[no]sigchase\fR -Chase DNSSEC signature chains\&. Requires dig be compiled with \-DDIG_SIGCHASE\&. -.TP +.RS 4 +Chase DNSSEC signature chains. Requires dig be compiled with \-DDIG_SIGCHASE. +.RE +.PP \fB+trusted\-key=####\fR -Specifies a file containing trusted keys to be used with \fB+sigchase\fR\&. Each DNSKEY record must be on its own line\&. -If not specified \fBdig\fR will look for \fI/etc/trusted\-key\&.key\fR then \fItrusted\-key\&.key\fR in the current directory\&. -Requires dig be compiled with \-DDIG_SIGCHASE\&. -.TP +.RS 4 +Specifies a file containing trusted keys to be used with +\fB+sigchase\fR. Each DNSKEY record must be on its own line. +.sp +If not specified +\fBdig\fR +will look for +\fI/etc/trusted\-key.key\fR +then +\fItrusted\-key.key\fR +in the current directory. +.sp +Requires dig be compiled with \-DDIG_SIGCHASE. +.RE +.PP \fB+[no]topdown\fR -When chasing DNSSEC signature chains perform a top\-down validation\&. Requires dig be compiled with \-DDIG_SIGCHASE\&. -.TP +.RS 4 +When chasing DNSSEC signature chains perform a top\-down validation. Requires dig be compiled with \-DDIG_SIGCHASE. +.RE +.PP \fB+[no]nsid\fR -Include an EDNS name server ID request when sending a query\&. +.RS 4 +Include an EDNS name server ID request when sending a query. +.RE .SH "MULTIPLE QUERIES" .PP -The BIND 9 implementation of \fBdig \fR supports specifying multiple queries on the command line (in addition to supporting the \fB\-f\fR batch file option)\&. Each of those queries can be supplied with its own set of flags, options and query options\&. +The BIND 9 implementation of +\fBdig \fR +supports specifying multiple queries on the command line (in addition to supporting the +\fB\-f\fR +batch file option). Each of those queries can be supplied with its own set of flags, options and query options. .PP -In this case, each \fIquery\fR argument represent an individual query in the command\-line syntax described above\&. Each consists of any of the standard options and flags, the name to be looked up, an optional query type and class and any query options that should be applied to that query\&. +In this case, each +\fIquery\fR +argument represent an individual query in the command\-line syntax described above. Each consists of any of the standard options and flags, the name to be looked up, an optional query type and class and any query options that should be applied to that query. .PP -A global set of query options, which should be applied to all queries, can also be supplied\&. These global query options must precede the first tuple of name, class, type, options, flags, and query options supplied on the command line\&. Any global query options (except the \fB+[no]cmd\fR option) can be overridden by a query\-specific set of query options\&. For example: +A global set of query options, which should be applied to all queries, can also be supplied. These global query options must precede the first tuple of name, class, type, options, flags, and query options supplied on the command line. Any global query options (except the +\fB+[no]cmd\fR +option) can be overridden by a query\-specific set of query options. For example: +.sp +.RS 4 .nf -dig +qr www\&.isc\&.org any \-x 127\&.0\&.0\&.1 isc\&.org ns +noqr +dig +qr www.isc.org any \-x 127.0.0.1 isc.org ns +noqr .fi - shows how \fBdig\fR could be used from the command line to make three lookups: an ANY query for www\&.isc\&.org, a reverse lookup of 127\&.0\&.0\&.1 and a query for the NS records of isc\&.org\&. A global query option of \fI+qr\fR is applied, so that \fBdig\fR shows the initial query it made for each lookup\&. The final query has a local query option of \fI+noqr\fR which means that \fBdig\fR will not print the initial query when it looks up the NS records for isc\&.org\&. +.RE +.sp +shows how +\fBdig\fR +could be used from the command line to make three lookups: an ANY query for +www.isc.org, a reverse lookup of 127.0.0.1 and a query for the NS records of +isc.org. A global query option of +\fI+qr\fR +is applied, so that +\fBdig\fR +shows the initial query it made for each lookup. The final query has a local query option of +\fI+noqr\fR +which means that +\fBdig\fR +will not print the initial query when it looks up the NS records for +isc.org. .SH "IDN SUPPORT" .PP -If \fBdig\fR has been built with IDN (internationalized domain name) support, it can accept and display non\-ASCII domain names\&. \fBdig\fR appropriately converts character encoding of domain name before sending a request to DNS server or displaying a reply from the server\&. If you'd like to turn off the IDN support for some reason, defines the \fBIDN_DISABLE\fR environment variable\&. The IDN support is disabled if the variable is set when \fBdig\fR runs\&. +If +\fBdig\fR +has been built with IDN (internationalized domain name) support, it can accept and display non\-ASCII domain names. +\fBdig\fR +appropriately converts character encoding of domain name before sending a request to DNS server or displaying a reply from the server. If you'd like to turn off the IDN support for some reason, defines the +\fBIDN_DISABLE\fR +environment variable. The IDN support is disabled if the variable is set when +\fBdig\fR +runs. .SH "FILES" .PP -\fI/etc/resolv\&.conf\fR +\fI/etc/resolv.conf\fR .PP -\fI${HOME}/\&.digrc\fR +\fI${HOME}/.digrc\fR .SH "SEE ALSO" .PP -\fBhost\fR(1), \fBnamed\fR(8), \fBdnssec\-keygen\fR(8), RFC1035\&. +\fBhost\fR(1), +\fBnamed\fR(8), +\fBdnssec\-keygen\fR(8), +RFC1035. .SH "BUGS" .PP -There are probably too many query options\&. +There are probably too many query options. +.SH "COPYRIGHT" +Copyright \(co 2004\-2007 Internet Systems Consortium, Inc. ("ISC") +.br +Copyright \(co 2000\-2003 Internet Software Consortium. +.br diff --git a/bin/dig/dig.html b/bin/dig/dig.html index 962e680902..8478ef3ff3 100644 --- a/bin/dig/dig.html +++ b/bin/dig/dig.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -539,13 +539,17 @@ validation. Requires dig be compiled with -DDIG_SIGCHASE.

+
+[no]nsid
+

+ Include an EDNS name server ID request when sending a query. +

-

MULTIPLE QUERIES

+

MULTIPLE QUERIES

The BIND 9 implementation of dig supports @@ -591,7 +595,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

IDN SUPPORT

+

IDN SUPPORT

If dig has been built with IDN (internationalized domain name) support, it can accept and display non-ASCII domain names. @@ -605,14 +609,14 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

FILES

+

FILES

/etc/resolv.conf

${HOME}/.digrc

-

SEE ALSO

+

SEE ALSO

host(1), named(8), dnssec-keygen(8), @@ -620,7 +624,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

BUGS

+

BUGS

There are probably too many query options.

diff --git a/doc/arm/man.dig.html b/doc/arm/man.dig.html index 82807a3f88..8a5d27433e 100644 --- a/doc/arm/man.dig.html +++ b/doc/arm/man.dig.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -52,7 +52,7 @@

dig [global-queryopt...] [query...]

-

DESCRIPTION

+

DESCRIPTION

dig (domain information groper) is a flexible tool for interrogating DNS name servers. It performs DNS lookups and @@ -98,7 +98,7 @@

-

SIMPLE USAGE

+

SIMPLE USAGE

A typical invocation of dig looks like:

@@ -144,7 +144,7 @@

-

OPTIONS

+

OPTIONS

The -b option sets the source IP address of the query to address. This must be a valid @@ -244,7 +244,7 @@

-

QUERY OPTIONS

+

QUERY OPTIONS

dig provides a number of query options which affect the way in which lookups are made and the results displayed. Some of @@ -557,13 +557,17 @@ validation. Requires dig be compiled with -DDIG_SIGCHASE.

+
+[no]nsid
+

+ Include an EDNS name server ID request when sending a query. +

-

MULTIPLE QUERIES

+

MULTIPLE QUERIES

The BIND 9 implementation of dig supports @@ -609,7 +613,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

IDN SUPPORT

+

IDN SUPPORT

If dig has been built with IDN (internationalized domain name) support, it can accept and display non-ASCII domain names. @@ -623,14 +627,14 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

FILES

+

FILES

/etc/resolv.conf

${HOME}/.digrc

-

SEE ALSO

+

SEE ALSO

host(1), named(8), dnssec-keygen(8), @@ -638,7 +642,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

BUGS

+

BUGS

There are probably too many query options.

diff --git a/doc/arm/man.dnssec-keyfromlabel.html b/doc/arm/man.dnssec-keyfromlabel.html index 36402ba241..886a0d7d4d 100644 --- a/doc/arm/man.dnssec-keyfromlabel.html +++ b/doc/arm/man.dnssec-keyfromlabel.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

dnssec-keyfromlabel {-a algorithm} {-l label} [-c class] [-f flag] [-k] [-n nametype] [-p protocol] [-t type] [-v level] {name}

-

DESCRIPTION

+

DESCRIPTION

dnssec-keyfromlabel gets keys with the given label from a crypto hardware and builds key files for DNSSEC (Secure DNS), as defined in RFC 2535 @@ -58,7 +58,7 @@

-

OPTIONS

+

OPTIONS

-a algorithm
@@ -131,7 +131,7 @@
-

GENERATED KEY FILES

+

GENERATED KEY FILES

When dnssec-keyfromlabel completes successfully, @@ -172,7 +172,7 @@

-

SEE ALSO

+

SEE ALSO

dnssec-keygen(8), dnssec-signzone(8), BIND 9 Administrator Reference Manual, @@ -182,7 +182,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.dnssec-keygen.html b/doc/arm/man.dnssec-keygen.html index 36feca6841..1cce76e1a1 100644 --- a/doc/arm/man.dnssec-keygen.html +++ b/doc/arm/man.dnssec-keygen.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

dnssec-keygen {-a algorithm} {-b keysize} {-n nametype} [-c class] [-e] [-f flag] [-g generator] [-h] [-k] [-p protocol] [-r randomdev] [-s strength] [-t type] [-v level] {name}

-

DESCRIPTION

+

DESCRIPTION

dnssec-keygen generates keys for DNSSEC (Secure DNS), as defined in RFC 2535 and RFC 4034. It can also generate keys for use with @@ -58,7 +58,7 @@

-

OPTIONS

+

OPTIONS

-a algorithm
@@ -166,7 +166,7 @@
-

GENERATED KEYS

+

GENERATED KEYS

When dnssec-keygen completes successfully, @@ -212,7 +212,7 @@

-

EXAMPLE

+

EXAMPLE

To generate a 768-bit DSA key for the domain example.com, the following command would be @@ -233,7 +233,7 @@

-

SEE ALSO

+

SEE ALSO

dnssec-signzone(8), BIND 9 Administrator Reference Manual, RFC 2535, @@ -242,7 +242,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.dnssec-signzone.html b/doc/arm/man.dnssec-signzone.html index 5e41a9727a..47d00d61f0 100644 --- a/doc/arm/man.dnssec-signzone.html +++ b/doc/arm/man.dnssec-signzone.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

dnssec-signzone [-a] [-c class] [-d directory] [-e end-time] [-f output-file] [-g] [-h] [-k key] [-l domain] [-i interval] [-I input-format] [-j jitter] [-N soa-serial-format] [-o origin] [-O output-format] [-p] [-r randomdev] [-s start-time] [-t] [-v level] [-z] {zonefile} [key...]

-

DESCRIPTION

+

DESCRIPTION

dnssec-signzone signs a zone. It generates NSEC and RRSIG records and produces a signed version of the @@ -61,7 +61,7 @@

-

OPTIONS

+

OPTIONS

-a

@@ -259,7 +259,7 @@

-

EXAMPLE

+

EXAMPLE

The following command signs the example.com zone with the DSA key generated by dnssec-keygen @@ -288,14 +288,14 @@ db.example.com.signed %

-

SEE ALSO

+

SEE ALSO

dnssec-keygen(8), BIND 9 Administrator Reference Manual, RFC 2535.

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.host.html b/doc/arm/man.host.html index 957831fa6e..72f56eb0cb 100644 --- a/doc/arm/man.host.html +++ b/doc/arm/man.host.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

host [-aCdlnrsTwv] [-c class] [-N ndots] [-R number] [-t type] [-W wait] [-m flag] [-4] [-6] {name} [server]

-

DESCRIPTION

+

DESCRIPTION

host is a simple utility for performing DNS lookups. It is normally used to convert names to IP addresses and vice versa. @@ -202,7 +202,7 @@

-

IDN SUPPORT

+

IDN SUPPORT

If host has been built with IDN (internationalized domain name) support, it can accept and display non-ASCII domain names. @@ -216,12 +216,12 @@

-

FILES

+

FILES

/etc/resolv.conf

-

SEE ALSO

+

SEE ALSO

dig(1), named(8).

diff --git a/doc/arm/man.named-checkconf.html b/doc/arm/man.named-checkconf.html index 5ede46471a..b76cf53fc4 100644 --- a/doc/arm/man.named-checkconf.html +++ b/doc/arm/man.named-checkconf.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,14 +50,14 @@

named-checkconf [-h] [-v] [-j] [-t directory] {filename} [-z]

-

DESCRIPTION

+

DESCRIPTION

named-checkconf checks the syntax, but not the semantics, of a named configuration file.

-

OPTIONS

+

OPTIONS

-h

@@ -92,21 +92,21 @@

-

RETURN VALUES

+

RETURN VALUES

named-checkconf returns an exit status of 1 if errors were detected and 0 otherwise.

-

SEE ALSO

+

SEE ALSO

named(8), named-checkzone(8), BIND 9 Administrator Reference Manual.

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.named-checkzone.html b/doc/arm/man.named-checkzone.html index a3b03c8915..cdbf64b665 100644 --- a/doc/arm/man.named-checkzone.html +++ b/doc/arm/man.named-checkzone.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -51,7 +51,7 @@

named-compilezone [-d] [-j] [-q] [-v] [-c class] [-C mode] [-f format] [-F format] [-i mode] [-k mode] [-m mode] [-n mode] [-o filename] [-s style] [-t directory] [-w directory] [-D] [-W mode] {zonename} {filename}

-

DESCRIPTION

+

DESCRIPTION

named-checkzone checks the syntax and integrity of a zone file. It performs the same checks as named does when loading a @@ -71,7 +71,7 @@

-

OPTIONS

+

OPTIONS

-d

@@ -257,14 +257,14 @@

-

RETURN VALUES

+

RETURN VALUES

named-checkzone returns an exit status of 1 if errors were detected and 0 otherwise.

-

SEE ALSO

+

SEE ALSO

named(8), named-checkconf(8), RFC 1035, @@ -272,7 +272,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.named.html b/doc/arm/man.named.html index ab5337e499..78f512cf1d 100644 --- a/doc/arm/man.named.html +++ b/doc/arm/man.named.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

named [-4] [-6] [-c config-file] [-d debug-level] [-f] [-g] [-m flag] [-n #cpus] [-p port] [-s] [-t directory] [-u user] [-v] [-x cache-file]

-

DESCRIPTION

+

DESCRIPTION

named is a Domain Name System (DNS) server, part of the BIND 9 distribution from ISC. For more @@ -65,7 +65,7 @@

-

OPTIONS

+

OPTIONS

-4

@@ -209,7 +209,7 @@

-

SIGNALS

+

SIGNALS

In routine operation, signals should not be used to control the nameserver; rndc should be used @@ -230,7 +230,7 @@

-

CONFIGURATION

+

CONFIGURATION

The named configuration file is too complex to describe in detail here. A complete description is provided @@ -239,7 +239,7 @@

-

FILES

+

FILES

/etc/named.conf

@@ -252,7 +252,7 @@

-

SEE ALSO

+

SEE ALSO

RFC 1033, RFC 1034, RFC 1035, @@ -265,7 +265,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.rndc-confgen.html b/doc/arm/man.rndc-confgen.html index faea48f07a..29995a5c8d 100644 --- a/doc/arm/man.rndc-confgen.html +++ b/doc/arm/man.rndc-confgen.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -48,7 +48,7 @@

rndc-confgen [-a] [-b keysize] [-c keyfile] [-h] [-k keyname] [-p port] [-r randomfile] [-s address] [-t chrootdir] [-u user]

-

DESCRIPTION

+

DESCRIPTION

rndc-confgen generates configuration files for rndc. It can be used as a @@ -64,7 +64,7 @@

-

OPTIONS

+

OPTIONS

-a
@@ -171,7 +171,7 @@
-

EXAMPLES

+

EXAMPLES

To allow rndc to be used with no manual configuration, run @@ -188,7 +188,7 @@

-

SEE ALSO

+

SEE ALSO

rndc(8), rndc.conf(5), named(8), @@ -196,7 +196,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.rndc.conf.html b/doc/arm/man.rndc.conf.html index 55f5378d91..3d0f3bfb7b 100644 --- a/doc/arm/man.rndc.conf.html +++ b/doc/arm/man.rndc.conf.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

rndc.conf

-

DESCRIPTION

+

DESCRIPTION

rndc.conf is the configuration file for rndc, the BIND 9 name server control utility. This file has a similar structure and syntax to @@ -135,7 +135,7 @@

-

EXAMPLE

+

EXAMPLE

       options {
         default-server  localhost;
@@ -209,7 +209,7 @@
     

-

NAME SERVER CONFIGURATION

+

NAME SERVER CONFIGURATION

The name server must be configured to accept rndc connections and to recognize the key specified in the rndc.conf @@ -219,7 +219,7 @@

-

SEE ALSO

+

SEE ALSO

rndc(8), rndc-confgen(8), mmencode(1), @@ -227,7 +227,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.rndc.html b/doc/arm/man.rndc.html index ffe4ab90fc..e14d866c37 100644 --- a/doc/arm/man.rndc.html +++ b/doc/arm/man.rndc.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

rndc [-b source-address] [-c config-file] [-k key-file] [-s server] [-p port] [-V] [-y key_id] {command}

-

DESCRIPTION

+

DESCRIPTION

rndc controls the operation of a name server. It supersedes the ndc utility @@ -79,7 +79,7 @@

-

OPTIONS

+

OPTIONS

-b source-address

@@ -151,7 +151,7 @@

-

LIMITATIONS

+

LIMITATIONS

rndc does not yet support all the commands of the BIND 8 ndc utility. @@ -165,7 +165,7 @@

-

SEE ALSO

+

SEE ALSO

rndc.conf(5), rndc-confgen(8), named(8), @@ -175,7 +175,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

From 298c514fff250c1a147176cfbbc1c0ca441d1ea5 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Wed, 14 May 2008 23:30:22 +0000 Subject: [PATCH 073/137] newcopyrights --- util/copyrights | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/util/copyrights b/util/copyrights index 9d0906d240..83cf6ee582 100644 --- a/util/copyrights +++ b/util/copyrights @@ -35,7 +35,7 @@ ./bin/dig/Makefile.in MAKE 2000,2001,2002,2004,2005,2007 ./bin/dig/dig.1 MAN DOCBOOK ./bin/dig/dig.c C 2000,2001,2002,2003,2004,2005,2006,2007,2008 -./bin/dig/dig.docbook SGML 2000,2001,2002,2003,2004,2005,2006,2007 +./bin/dig/dig.docbook SGML 2000,2001,2002,2003,2004,2005,2006,2007,2008 ./bin/dig/dig.html HTML DOCBOOK ./bin/dig/dighost.c C 2000,2001,2002,2003,2004,2005,2006,2007,2008 ./bin/dig/host.1 MAN DOCBOOK From 7b8b5e34b6daf793373580dfb095f56af5e918ce Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Wed, 14 May 2008 23:47:03 +0000 Subject: [PATCH 074/137] update copyright notice --- bin/dig/dig.docbook | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/bin/dig/dig.docbook b/bin/dig/dig.docbook index 4ef19498b2..43f5c9cce6 100644 --- a/bin/dig/dig.docbook +++ b/bin/dig/dig.docbook @@ -2,7 +2,7 @@ "http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd" []> - + @@ -42,6 +42,7 @@ 2005 2006 2007 + 2008 Internet Systems Consortium, Inc. ("ISC") From d230b29aba3ce1d0362194801c34321ed22f5aa5 Mon Sep 17 00:00:00 2001 From: Evan Hunt Date: Thu, 15 May 2008 00:50:26 +0000 Subject: [PATCH 075/137] fixed incorrect TAG_HMACSHA256_BITS value [rt18047] --- CHANGES | 2 ++ lib/dns/dst_parse.h | 4 ++-- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/CHANGES b/CHANGES index d8e7f22dff..79859f08f2 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,5 @@ +2372. [bug] fixed incorrect TAG_HMACSHA256_BITS value [RT #18047] + 2371. [doc] add +nsid option to dig man page. [RT #18039] 2370. [bug] "rndc freeze" could trigger an assertion in named diff --git a/lib/dns/dst_parse.h b/lib/dns/dst_parse.h index 3ed4ee1656..27c7580e54 100644 --- a/lib/dns/dst_parse.h +++ b/lib/dns/dst_parse.h @@ -29,7 +29,7 @@ * IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: dst_parse.h,v 1.10 2008/04/01 23:47:10 tbox Exp $ */ +/* $Id: dst_parse.h,v 1.11 2008/05/15 00:50:26 each Exp $ */ /*! \file */ #ifndef DST_DST_PARSE_H @@ -91,7 +91,7 @@ #define HMACSHA256_NTAGS 2 #define TAG_HMACSHA256_KEY ((DST_ALG_HMACSHA256 << TAG_SHIFT) + 0) -#define TAG_HMACSHA256_BITS ((DST_ALG_HMACSHA224 << TAG_SHIFT) + 1) +#define TAG_HMACSHA256_BITS ((DST_ALG_HMACSHA256 << TAG_SHIFT) + 1) #define HMACSHA384_NTAGS 2 #define TAG_HMACSHA384_KEY ((DST_ALG_HMACSHA384 << TAG_SHIFT) + 0) From 232d4387e2ef22eb95f7e49ebbfb4d7e8d0daae6 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Thu, 15 May 2008 01:12:21 +0000 Subject: [PATCH 076/137] regen --- bin/dig/dig.1 | 6 +++--- bin/dig/dig.html | 22 +++++++++++----------- doc/arm/man.dig.html | 20 ++++++++++---------- doc/arm/man.dnssec-keyfromlabel.html | 12 ++++++------ doc/arm/man.dnssec-keygen.html | 14 +++++++------- doc/arm/man.dnssec-signzone.html | 12 ++++++------ doc/arm/man.host.html | 10 +++++----- doc/arm/man.named-checkconf.html | 12 ++++++------ doc/arm/man.named-checkzone.html | 12 ++++++------ doc/arm/man.named.html | 16 ++++++++-------- doc/arm/man.rndc-confgen.html | 12 ++++++------ doc/arm/man.rndc.conf.html | 12 ++++++------ doc/arm/man.rndc.html | 12 ++++++------ 13 files changed, 86 insertions(+), 86 deletions(-) diff --git a/bin/dig/dig.1 b/bin/dig/dig.1 index 65a451964c..b6f8d5be04 100644 --- a/bin/dig/dig.1 +++ b/bin/dig/dig.1 @@ -1,4 +1,4 @@ -.\" Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC") +.\" Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2000-2003 Internet Software Consortium. .\" .\" Permission to use, copy, modify, and distribute this software for any @@ -13,7 +13,7 @@ .\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR .\" PERFORMANCE OF THIS SOFTWARE. .\" -.\" $Id: dig.1,v 1.47 2008/05/14 01:12:07 tbox Exp $ +.\" $Id: dig.1,v 1.48 2008/05/15 01:12:20 tbox Exp $ .\" .hy 0 .ad l @@ -556,7 +556,7 @@ RFC1035. .PP There are probably too many query options. .SH "COPYRIGHT" -Copyright \(co 2004\-2007 Internet Systems Consortium, Inc. ("ISC") +Copyright \(co 2004\-2008 Internet Systems Consortium, Inc. ("ISC") .br Copyright \(co 2000\-2003 Internet Software Consortium. .br diff --git a/bin/dig/dig.html b/bin/dig/dig.html index 8478ef3ff3..17ac5f1b1f 100644 --- a/bin/dig/dig.html +++ b/bin/dig/dig.html @@ -1,5 +1,5 @@ - + @@ -34,7 +34,7 @@

dig [global-queryopt...] [query...]

-

DESCRIPTION

+

DESCRIPTION

dig (domain information groper) is a flexible tool for interrogating DNS name servers. It performs DNS lookups and @@ -80,7 +80,7 @@

-

SIMPLE USAGE

+

SIMPLE USAGE

A typical invocation of dig looks like:

@@ -126,7 +126,7 @@

-

OPTIONS

+

OPTIONS

The -b option sets the source IP address of the query to address. This must be a valid @@ -226,7 +226,7 @@

-

QUERY OPTIONS

+

QUERY OPTIONS

dig provides a number of query options which affect the way in which lookups are made and the results displayed. Some of @@ -549,7 +549,7 @@

-

MULTIPLE QUERIES

+

MULTIPLE QUERIES

The BIND 9 implementation of dig supports @@ -595,7 +595,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

IDN SUPPORT

+

IDN SUPPORT

If dig has been built with IDN (internationalized domain name) support, it can accept and display non-ASCII domain names. @@ -609,14 +609,14 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

FILES

+

FILES

/etc/resolv.conf

${HOME}/.digrc

-

SEE ALSO

+

SEE ALSO

host(1), named(8), dnssec-keygen(8), @@ -624,7 +624,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

BUGS

+

BUGS

There are probably too many query options.

diff --git a/doc/arm/man.dig.html b/doc/arm/man.dig.html index 8a5d27433e..53847c05ea 100644 --- a/doc/arm/man.dig.html +++ b/doc/arm/man.dig.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -52,7 +52,7 @@

dig [global-queryopt...] [query...]

-

DESCRIPTION

+

DESCRIPTION

dig (domain information groper) is a flexible tool for interrogating DNS name servers. It performs DNS lookups and @@ -98,7 +98,7 @@

-

SIMPLE USAGE

+

SIMPLE USAGE

A typical invocation of dig looks like:

@@ -144,7 +144,7 @@

-

OPTIONS

+

OPTIONS

The -b option sets the source IP address of the query to address. This must be a valid @@ -244,7 +244,7 @@

-

QUERY OPTIONS

+

QUERY OPTIONS

dig provides a number of query options which affect the way in which lookups are made and the results displayed. Some of @@ -567,7 +567,7 @@

-

MULTIPLE QUERIES

+

MULTIPLE QUERIES

The BIND 9 implementation of dig supports @@ -613,7 +613,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

IDN SUPPORT

+

IDN SUPPORT

If dig has been built with IDN (internationalized domain name) support, it can accept and display non-ASCII domain names. @@ -627,14 +627,14 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

FILES

+

FILES

/etc/resolv.conf

${HOME}/.digrc

-

SEE ALSO

+

SEE ALSO

host(1), named(8), dnssec-keygen(8), @@ -642,7 +642,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

BUGS

+

BUGS

There are probably too many query options.

diff --git a/doc/arm/man.dnssec-keyfromlabel.html b/doc/arm/man.dnssec-keyfromlabel.html index 886a0d7d4d..b54d27b252 100644 --- a/doc/arm/man.dnssec-keyfromlabel.html +++ b/doc/arm/man.dnssec-keyfromlabel.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

dnssec-keyfromlabel {-a algorithm} {-l label} [-c class] [-f flag] [-k] [-n nametype] [-p protocol] [-t type] [-v level] {name}

-

DESCRIPTION

+

DESCRIPTION

dnssec-keyfromlabel gets keys with the given label from a crypto hardware and builds key files for DNSSEC (Secure DNS), as defined in RFC 2535 @@ -58,7 +58,7 @@

-

OPTIONS

+

OPTIONS

-a algorithm
@@ -131,7 +131,7 @@
-

GENERATED KEY FILES

+

GENERATED KEY FILES

When dnssec-keyfromlabel completes successfully, @@ -172,7 +172,7 @@

-

SEE ALSO

+

SEE ALSO

dnssec-keygen(8), dnssec-signzone(8), BIND 9 Administrator Reference Manual, @@ -182,7 +182,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.dnssec-keygen.html b/doc/arm/man.dnssec-keygen.html index 1cce76e1a1..3809a94a23 100644 --- a/doc/arm/man.dnssec-keygen.html +++ b/doc/arm/man.dnssec-keygen.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

dnssec-keygen {-a algorithm} {-b keysize} {-n nametype} [-c class] [-e] [-f flag] [-g generator] [-h] [-k] [-p protocol] [-r randomdev] [-s strength] [-t type] [-v level] {name}

-

DESCRIPTION

+

DESCRIPTION

dnssec-keygen generates keys for DNSSEC (Secure DNS), as defined in RFC 2535 and RFC 4034. It can also generate keys for use with @@ -58,7 +58,7 @@

-

OPTIONS

+

OPTIONS

-a algorithm
@@ -166,7 +166,7 @@
-

GENERATED KEYS

+

GENERATED KEYS

When dnssec-keygen completes successfully, @@ -212,7 +212,7 @@

-

EXAMPLE

+

EXAMPLE

To generate a 768-bit DSA key for the domain example.com, the following command would be @@ -233,7 +233,7 @@

-

SEE ALSO

+

SEE ALSO

dnssec-signzone(8), BIND 9 Administrator Reference Manual, RFC 2535, @@ -242,7 +242,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.dnssec-signzone.html b/doc/arm/man.dnssec-signzone.html index 47d00d61f0..f1632f923b 100644 --- a/doc/arm/man.dnssec-signzone.html +++ b/doc/arm/man.dnssec-signzone.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

dnssec-signzone [-a] [-c class] [-d directory] [-e end-time] [-f output-file] [-g] [-h] [-k key] [-l domain] [-i interval] [-I input-format] [-j jitter] [-N soa-serial-format] [-o origin] [-O output-format] [-p] [-r randomdev] [-s start-time] [-t] [-v level] [-z] {zonefile} [key...]

-

DESCRIPTION

+

DESCRIPTION

dnssec-signzone signs a zone. It generates NSEC and RRSIG records and produces a signed version of the @@ -61,7 +61,7 @@

-

OPTIONS

+

OPTIONS

-a

@@ -259,7 +259,7 @@

-

EXAMPLE

+

EXAMPLE

The following command signs the example.com zone with the DSA key generated by dnssec-keygen @@ -288,14 +288,14 @@ db.example.com.signed %

-

SEE ALSO

+

SEE ALSO

dnssec-keygen(8), BIND 9 Administrator Reference Manual, RFC 2535.

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.host.html b/doc/arm/man.host.html index 72f56eb0cb..a3b4599827 100644 --- a/doc/arm/man.host.html +++ b/doc/arm/man.host.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

host [-aCdlnrsTwv] [-c class] [-N ndots] [-R number] [-t type] [-W wait] [-m flag] [-4] [-6] {name} [server]

-

DESCRIPTION

+

DESCRIPTION

host is a simple utility for performing DNS lookups. It is normally used to convert names to IP addresses and vice versa. @@ -202,7 +202,7 @@

-

IDN SUPPORT

+

IDN SUPPORT

If host has been built with IDN (internationalized domain name) support, it can accept and display non-ASCII domain names. @@ -216,12 +216,12 @@

-

FILES

+

FILES

/etc/resolv.conf

-

SEE ALSO

+

SEE ALSO

dig(1), named(8).

diff --git a/doc/arm/man.named-checkconf.html b/doc/arm/man.named-checkconf.html index b76cf53fc4..d112fb443b 100644 --- a/doc/arm/man.named-checkconf.html +++ b/doc/arm/man.named-checkconf.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,14 +50,14 @@

named-checkconf [-h] [-v] [-j] [-t directory] {filename} [-z]

-

DESCRIPTION

+

DESCRIPTION

named-checkconf checks the syntax, but not the semantics, of a named configuration file.

-

OPTIONS

+

OPTIONS

-h

@@ -92,21 +92,21 @@

-

RETURN VALUES

+

RETURN VALUES

named-checkconf returns an exit status of 1 if errors were detected and 0 otherwise.

-

SEE ALSO

+

SEE ALSO

named(8), named-checkzone(8), BIND 9 Administrator Reference Manual.

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.named-checkzone.html b/doc/arm/man.named-checkzone.html index cdbf64b665..085a3ece1f 100644 --- a/doc/arm/man.named-checkzone.html +++ b/doc/arm/man.named-checkzone.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -51,7 +51,7 @@

named-compilezone [-d] [-j] [-q] [-v] [-c class] [-C mode] [-f format] [-F format] [-i mode] [-k mode] [-m mode] [-n mode] [-o filename] [-s style] [-t directory] [-w directory] [-D] [-W mode] {zonename} {filename}

-

DESCRIPTION

+

DESCRIPTION

named-checkzone checks the syntax and integrity of a zone file. It performs the same checks as named does when loading a @@ -71,7 +71,7 @@

-

OPTIONS

+

OPTIONS

-d

@@ -257,14 +257,14 @@

-

RETURN VALUES

+

RETURN VALUES

named-checkzone returns an exit status of 1 if errors were detected and 0 otherwise.

-

SEE ALSO

+

SEE ALSO

named(8), named-checkconf(8), RFC 1035, @@ -272,7 +272,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.named.html b/doc/arm/man.named.html index 78f512cf1d..29c53ac52b 100644 --- a/doc/arm/man.named.html +++ b/doc/arm/man.named.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

named [-4] [-6] [-c config-file] [-d debug-level] [-f] [-g] [-m flag] [-n #cpus] [-p port] [-s] [-t directory] [-u user] [-v] [-x cache-file]

-

DESCRIPTION

+

DESCRIPTION

named is a Domain Name System (DNS) server, part of the BIND 9 distribution from ISC. For more @@ -65,7 +65,7 @@

-

OPTIONS

+

OPTIONS

-4

@@ -209,7 +209,7 @@

-

SIGNALS

+

SIGNALS

In routine operation, signals should not be used to control the nameserver; rndc should be used @@ -230,7 +230,7 @@

-

CONFIGURATION

+

CONFIGURATION

The named configuration file is too complex to describe in detail here. A complete description is provided @@ -239,7 +239,7 @@

-

FILES

+

FILES

/etc/named.conf

@@ -252,7 +252,7 @@

-

SEE ALSO

+

SEE ALSO

RFC 1033, RFC 1034, RFC 1035, @@ -265,7 +265,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.rndc-confgen.html b/doc/arm/man.rndc-confgen.html index 29995a5c8d..0368e147bd 100644 --- a/doc/arm/man.rndc-confgen.html +++ b/doc/arm/man.rndc-confgen.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -48,7 +48,7 @@

rndc-confgen [-a] [-b keysize] [-c keyfile] [-h] [-k keyname] [-p port] [-r randomfile] [-s address] [-t chrootdir] [-u user]

-

DESCRIPTION

+

DESCRIPTION

rndc-confgen generates configuration files for rndc. It can be used as a @@ -64,7 +64,7 @@

-

OPTIONS

+

OPTIONS

-a
@@ -171,7 +171,7 @@
-

EXAMPLES

+

EXAMPLES

To allow rndc to be used with no manual configuration, run @@ -188,7 +188,7 @@

-

SEE ALSO

+

SEE ALSO

rndc(8), rndc.conf(5), named(8), @@ -196,7 +196,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.rndc.conf.html b/doc/arm/man.rndc.conf.html index 3d0f3bfb7b..ef8997ae73 100644 --- a/doc/arm/man.rndc.conf.html +++ b/doc/arm/man.rndc.conf.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

rndc.conf

-

DESCRIPTION

+

DESCRIPTION

rndc.conf is the configuration file for rndc, the BIND 9 name server control utility. This file has a similar structure and syntax to @@ -135,7 +135,7 @@

-

EXAMPLE

+

EXAMPLE

       options {
         default-server  localhost;
@@ -209,7 +209,7 @@
     

-

NAME SERVER CONFIGURATION

+

NAME SERVER CONFIGURATION

The name server must be configured to accept rndc connections and to recognize the key specified in the rndc.conf @@ -219,7 +219,7 @@

-

SEE ALSO

+

SEE ALSO

rndc(8), rndc-confgen(8), mmencode(1), @@ -227,7 +227,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.rndc.html b/doc/arm/man.rndc.html index e14d866c37..5994cae860 100644 --- a/doc/arm/man.rndc.html +++ b/doc/arm/man.rndc.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

rndc [-b source-address] [-c config-file] [-k key-file] [-s server] [-p port] [-V] [-y key_id] {command}

-

DESCRIPTION

+

DESCRIPTION

rndc controls the operation of a name server. It supersedes the ndc utility @@ -79,7 +79,7 @@

-

OPTIONS

+

OPTIONS

-b source-address

@@ -151,7 +151,7 @@

-

LIMITATIONS

+

LIMITATIONS

rndc does not yet support all the commands of the BIND 8 ndc utility. @@ -165,7 +165,7 @@

-

SEE ALSO

+

SEE ALSO

rndc.conf(5), rndc-confgen(8), named(8), @@ -175,7 +175,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

From a89eda002e83b0be75cffc33c3f74a0bdf02e401 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Thu, 15 May 2008 23:19:52 +0000 Subject: [PATCH 077/137] auto update --- doc/private/branches | 1 + 1 file changed, 1 insertion(+) diff --git a/doc/private/branches b/doc/private/branches index 86a3a8498f..97f1643430 100644 --- a/doc/private/branches +++ b/doc/private/branches @@ -122,6 +122,7 @@ rt17949_v9_5 new rt17977 new each // 2008-04-23 00:29 +0000 rt18018 new rt18020 new fdupont // FIPS 140-2 +rt18020a new fdupont // 2008-05-15 14:50 +0000 rt18033 new fdupont // HSM maintenance rt18040 new marka // 2008-05-08 02:25 +0000 rt18042 new fdupont // 2008-05-09 13:27 +0000 From b3ac666ce5c11ee8a8eb8b5b56faef695f96925b Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 19 May 2008 00:36:14 +0000 Subject: [PATCH 078/137] silence linker warning: add ${LDFLAGS} --- bin/tests/dst/Makefile.in | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/bin/tests/dst/Makefile.in b/bin/tests/dst/Makefile.in index eeedec489e..01cb2de157 100644 --- a/bin/tests/dst/Makefile.in +++ b/bin/tests/dst/Makefile.in @@ -13,7 +13,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: Makefile.in,v 1.44 2007/06/19 23:47:00 tbox Exp $ +# $Id: Makefile.in,v 1.45 2008/05/19 00:36:14 marka Exp $ srcdir = @srcdir@ VPATH = @srcdir@ @@ -54,7 +54,7 @@ t_dst@EXEEXT@: t_dst.@O@ ${DEPLIBS} ${TLIB} t_dst.@O@ ${TLIB} ${LIBS} gsstest@EXEEXT@: gsstest.@O@ ${DEPLIBS} - ${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} -o $@ \ + ${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \ gsstest.@O@ ${LIBS} test: t_dst@EXEEXT@ From 998b76837ac21e4243a0f97618ea91206be8c028 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Mon, 19 May 2008 23:30:23 +0000 Subject: [PATCH 079/137] newcopyrights --- util/copyrights | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/util/copyrights b/util/copyrights index 83cf6ee582..6c997e601a 100644 --- a/util/copyrights +++ b/util/copyrights @@ -278,7 +278,7 @@ ./bin/tests/dst/Ktest.+003+23616.key X 2001,2004 ./bin/tests/dst/Ktest.+003+23616.private X 2001 ./bin/tests/dst/Ktest.+003+49667.key X 2001,2004 -./bin/tests/dst/Makefile.in MAKE 1999,2000,2001,2002,2004,2006,2007 +./bin/tests/dst/Makefile.in MAKE 1999,2000,2001,2002,2004,2006,2007,2008 ./bin/tests/dst/dst_2_data X 1999,2000,2001 ./bin/tests/dst/dst_test.c C 1999,2000,2001,2004,2005,2007 ./bin/tests/dst/gsstest.c C 2006,2007 From ebce5dc2fe1625ee34ed9de85d170e19f397d929 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Mon, 19 May 2008 23:47:03 +0000 Subject: [PATCH 080/137] update copyright notice --- bin/tests/dst/Makefile.in | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/bin/tests/dst/Makefile.in b/bin/tests/dst/Makefile.in index 01cb2de157..9b317fc7b9 100644 --- a/bin/tests/dst/Makefile.in +++ b/bin/tests/dst/Makefile.in @@ -1,4 +1,4 @@ -# Copyright (C) 2004, 2006, 2007 Internet Systems Consortium, Inc. ("ISC") +# Copyright (C) 2004, 2006-2008 Internet Systems Consortium, Inc. ("ISC") # Copyright (C) 1999-2002 Internet Software Consortium. # # Permission to use, copy, modify, and/or distribute this software for any @@ -13,7 +13,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. -# $Id: Makefile.in,v 1.45 2008/05/19 00:36:14 marka Exp $ +# $Id: Makefile.in,v 1.46 2008/05/19 23:47:03 tbox Exp $ srcdir = @srcdir@ VPATH = @srcdir@ From 5a17fe2916ce37793c12b243ab08c16095a59cf7 Mon Sep 17 00:00:00 2001 From: Evan Hunt Date: Wed, 21 May 2008 23:17:21 +0000 Subject: [PATCH 081/137] Default values of zone ACLs were re-parsed each time a new zone was configured, causing an overconsumption of memory. [rt18092] --- CHANGES | 8 +++- bin/named/server.c | 24 +++++++++- bin/named/zoneconf.c | 93 ++++++++++++++++++++++++++++++++------ lib/dns/include/dns/view.h | 6 ++- lib/dns/view.c | 14 +++++- lib/isccfg/aclconf.c | 15 +++++- 6 files changed, 140 insertions(+), 20 deletions(-) diff --git a/CHANGES b/CHANGES index 79859f08f2..35f1a27e0c 100644 --- a/CHANGES +++ b/CHANGES @@ -1,6 +1,10 @@ -2372. [bug] fixed incorrect TAG_HMACSHA256_BITS value [RT #18047] +2373. [bug] Default values of zone ACLs were re-parsed each time a + new zone was configured, causing an overconsumption + of memory. [RT #18092] -2371. [doc] add +nsid option to dig man page. [RT #18039] +2372. [bug] Fixed incorrect TAG_HMACSHA256_BITS value [RT #18047] + +2371. [doc] Add +nsid option to dig man page. [RT #18039] 2370. [bug] "rndc freeze" could trigger an assertion in named when called on a nonexistent zone. [RT #18050] diff --git a/bin/named/server.c b/bin/named/server.c index 8c4f6c2d44..6d36a9e2b0 100644 --- a/bin/named/server.c +++ b/bin/named/server.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: server.c,v 1.506 2008/04/03 06:09:04 tbox Exp $ */ +/* $Id: server.c,v 1.507 2008/05/21 23:17:20 each Exp $ */ /*! \file */ @@ -1684,6 +1684,28 @@ configure_view(dns_view_t *view, const cfg_obj_t *config, CHECK(configure_view_sortlist(vconfig, config, actx, ns_g_mctx, &view->sortlist)); + /* + * Configure default allow-transfer, allow-notify, allow-update + * and allow-update-forwarding ACLs, if set, so they can be + * inherited by zones. + */ + if (view->notifyacl == NULL) + CHECK(configure_view_acl(NULL, ns_g_config, + "allow-notify", actx, + ns_g_mctx, &view->notifyacl)); + if (view->transferacl == NULL) + CHECK(configure_view_acl(NULL, ns_g_config, + "allow-transfer", actx, + ns_g_mctx, &view->transferacl)); + if (view->updateacl == NULL) + CHECK(configure_view_acl(NULL, ns_g_config, + "allow-update", actx, + ns_g_mctx, &view->updateacl)); + if (view->upfwdacl == NULL) + CHECK(configure_view_acl(NULL, ns_g_config, + "allow-update-forwarding", actx, + ns_g_mctx, &view->upfwdacl)); + obj = NULL; result = ns_config_get(maps, "request-ixfr", &obj); INSIST(result == ISC_R_SUCCESS); diff --git a/bin/named/zoneconf.c b/bin/named/zoneconf.c index 9cc6b5e25e..ea760a4f3e 100644 --- a/bin/named/zoneconf.c +++ b/bin/named/zoneconf.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: zoneconf.c,v 1.144 2008/04/03 05:55:51 marka Exp $ */ +/* $Id: zoneconf.c,v 1.145 2008/05/21 23:17:20 each Exp $ */ /*% */ @@ -45,6 +45,15 @@ #include #include +/* ACLs associated with zone */ +typedef enum { + allow_notify, + allow_query, + allow_transfer, + allow_update, + allow_update_forwarding +} acl_type_t; + /*% * These are BIND9 server defaults, not necessarily identical to the * library defaults defined in zone.c. @@ -60,19 +69,69 @@ */ static isc_result_t configure_zone_acl(const cfg_obj_t *zconfig, const cfg_obj_t *vconfig, - const cfg_obj_t *config, const char *aclname, + const cfg_obj_t *config, acl_type_t acltype, cfg_aclconfctx_t *actx, dns_zone_t *zone, void (*setzacl)(dns_zone_t *, dns_acl_t *), void (*clearzacl)(dns_zone_t *)) { isc_result_t result; - const cfg_obj_t *maps[5]; + const cfg_obj_t *maps[5] = {NULL, NULL, NULL, NULL, NULL}; const cfg_obj_t *aclobj = NULL; int i = 0; - dns_acl_t *dacl = NULL; + dns_acl_t **aclp = NULL, *acl = NULL; + const char *aclname; + dns_view_t *view; - if (zconfig != NULL) - maps[i++] = cfg_tuple_get(zconfig, "options"); + view = dns_zone_getview(zone); + + switch (acltype) { + case allow_notify: + if (view != NULL) + aclp = &view->notifyacl; + aclname = "allow-notify"; + break; + case allow_query: + if (view != NULL) + aclp = &view->queryacl; + aclname = "allow-query"; + break; + case allow_transfer: + if (view != NULL) + aclp = &view->transferacl; + aclname = "allow-transfer"; + break; + case allow_update: + if (view != NULL) + aclp = &view->updateacl; + aclname = "allow-update"; + break; + case allow_update_forwarding: + if (view != NULL) + aclp = &view->upfwdacl; + aclname = "allow-update-forwarding"; + break; + default: + INSIST(0); + return (ISC_R_FAILURE); + } + + /* First check to see if ACL is defined within the zone */ + if (zconfig != NULL) { + maps[0] = cfg_tuple_get(zconfig, "options"); + ns_config_get(maps, aclname, &aclobj); + if (aclobj != NULL) { + aclp = NULL; + goto parse_acl; + } + } + + /* Failing that, see if there's a default ACL already in the view */ + if (aclp != NULL && *aclp != NULL) { + (*setzacl)(zone, *aclp); + return (ISC_R_SUCCESS); + } + + /* Check for default ACLs that haven't been parsed yet */ if (vconfig != NULL) maps[i++] = cfg_tuple_get(vconfig, "options"); if (config != NULL) { @@ -90,12 +149,18 @@ configure_zone_acl(const cfg_obj_t *zconfig, const cfg_obj_t *vconfig, return (ISC_R_SUCCESS); } +parse_acl: result = cfg_acl_fromconfig(aclobj, config, ns_g_lctx, actx, - dns_zone_getmctx(zone), 0, &dacl); + dns_zone_getmctx(zone), 0, &acl); if (result != ISC_R_SUCCESS) return (result); - (*setzacl)(zone, dacl); - dns_acl_detach(&dacl); + (*setzacl)(zone, acl); + + /* Set the view default now */ + if (aclp != NULL) + dns_acl_attach(acl, aclp); + + dns_acl_detach(&acl); return (ISC_R_SUCCESS); } @@ -459,14 +524,14 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig, if (ztype == dns_zone_slave) RETERR(configure_zone_acl(zconfig, vconfig, config, - "allow-notify", ac, zone, + allow_notify, ac, zone, dns_zone_setnotifyacl, dns_zone_clearnotifyacl)); /* * XXXAG This probably does not make sense for stubs. */ RETERR(configure_zone_acl(zconfig, vconfig, config, - "allow-query", ac, zone, + allow_query, ac, zone, dns_zone_setqueryacl, dns_zone_clearqueryacl)); @@ -569,7 +634,7 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig, dns_zone_setisself(zone, ns_client_isself, NULL); RETERR(configure_zone_acl(zconfig, vconfig, config, - "allow-transfer", ac, zone, + allow_transfer, ac, zone, dns_zone_setxfracl, dns_zone_clearxfracl)); @@ -660,7 +725,7 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig, if (ztype == dns_zone_master) { dns_acl_t *updateacl; RETERR(configure_zone_acl(zconfig, vconfig, config, - "allow-update", ac, zone, + allow_update, ac, zone, dns_zone_setupdateacl, dns_zone_clearupdateacl)); @@ -734,7 +799,7 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig, } else if (ztype == dns_zone_slave) { RETERR(configure_zone_acl(zconfig, vconfig, config, - "allow-update-forwarding", ac, zone, + allow_update_forwarding, ac, zone, dns_zone_setforwardacl, dns_zone_clearforwardacl)); } diff --git a/lib/dns/include/dns/view.h b/lib/dns/include/dns/view.h index 09171549c8..8329523f84 100644 --- a/lib/dns/include/dns/view.h +++ b/lib/dns/include/dns/view.h @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: view.h,v 1.110 2008/04/03 06:09:05 tbox Exp $ */ +/* $Id: view.h,v 1.111 2008/05/21 23:17:21 each Exp $ */ #ifndef DNS_VIEW_H #define DNS_VIEW_H 1 @@ -123,6 +123,10 @@ struct dns_view { dns_acl_t * recursionacl; dns_acl_t * recursiononacl; dns_acl_t * sortlist; + dns_acl_t * notifyacl; + dns_acl_t * transferacl; + dns_acl_t * updateacl; + dns_acl_t * upfwdacl; isc_boolean_t requestixfr; isc_boolean_t provideixfr; isc_boolean_t requestnsid; diff --git a/lib/dns/view.c b/lib/dns/view.c index 1c4bcdeea0..22d03cdf85 100644 --- a/lib/dns/view.c +++ b/lib/dns/view.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: view.c,v 1.148 2008/05/13 23:47:01 tbox Exp $ */ +/* $Id: view.c,v 1.149 2008/05/21 23:17:21 each Exp $ */ /*! \file */ @@ -172,6 +172,10 @@ dns_view_create(isc_mem_t *mctx, dns_rdataclass_t rdclass, view->recursionacl = NULL; view->recursiononacl = NULL; view->sortlist = NULL; + view->transferacl = NULL; + view->notifyacl = NULL; + view->updateacl = NULL; + view->upfwdacl = NULL; view->requestixfr = ISC_TRUE; view->provideixfr = ISC_TRUE; view->maxcachettl = 7 * 24 * 3600; @@ -299,6 +303,14 @@ destroy(dns_view_t *view) { dns_acl_detach(&view->recursiononacl); if (view->sortlist != NULL) dns_acl_detach(&view->sortlist); + if (view->transferacl != NULL) + dns_acl_detach(&view->transferacl); + if (view->notifyacl != NULL) + dns_acl_detach(&view->notifyacl); + if (view->updateacl != NULL) + dns_acl_detach(&view->updateacl); + if (view->upfwdacl != NULL) + dns_acl_detach(&view->upfwdacl); if (view->delonly != NULL) { dns_name_t *name; int i; diff --git a/lib/isccfg/aclconf.c b/lib/isccfg/aclconf.c index 253a8ce9a3..74ae0d234f 100644 --- a/lib/isccfg/aclconf.c +++ b/lib/isccfg/aclconf.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: aclconf.c,v 1.17 2007/12/21 06:46:47 marka Exp $ */ +/* $Id: aclconf.c,v 1.18 2008/05/21 23:17:21 each Exp $ */ #include @@ -175,6 +175,7 @@ cfg_acl_fromconfig(const cfg_obj_t *caml, const cfg_listelt_t *elt; dns_iptable_t *iptab; int new_nest_level = 0; + int nelem; if (nest_level != 0) new_nest_level = nest_level - 1; @@ -206,6 +207,8 @@ cfg_acl_fromconfig(const cfg_obj_t *caml, return (result); } + nelem = cfg_list_length(caml, ISC_FALSE); + de = dacl->elements; for (elt = cfg_list_first(caml); elt != NULL; @@ -350,6 +353,16 @@ nested_acl: if (result != ISC_R_SUCCESS) goto cleanup; + /* + * There was only one element and it was + * a nested named ACL; attach it to the + * target and let's go home. + */ + if (nelem == 1) { + dns_acl_attach(inneracl, target); + goto cleanup; + } + goto nested_acl; } } else { From 0d228cec61740a2e078bcca5751cba999c92721b Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Wed, 21 May 2008 23:19:04 +0000 Subject: [PATCH 082/137] auto update --- doc/private/branches | 1 + 1 file changed, 1 insertion(+) diff --git a/doc/private/branches b/doc/private/branches index 97f1643430..f6d10326ae 100644 --- a/doc/private/branches +++ b/doc/private/branches @@ -127,6 +127,7 @@ rt18033 new fdupont // HSM maintenance rt18040 new marka // 2008-05-08 02:25 +0000 rt18042 new fdupont // 2008-05-09 13:27 +0000 rt18046 new fdupont // 2008-05-09 06:56 +0000 +rt18092 new each // 2008-05-21 05:49 +0000 shane_dbbackend open skan open explorer skan-metazones1 private explorer From 080a964a3f0622f2e343f114aa1cc066372c06ca Mon Sep 17 00:00:00 2001 From: Evan Hunt Date: Wed, 21 May 2008 23:21:33 +0000 Subject: [PATCH 083/137] "blackhole" ACLs could cause named to segfault due to some uninitialized memory. [rt18095] --- CHANGES | 3 +++ lib/isc/radix.c | 4 ++-- 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/CHANGES b/CHANGES index 35f1a27e0c..b9e894a745 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +2374. [bug] "blackhole" ACLs could cause named to segfault due + to some uninitialized memory. [RT #18095] + 2373. [bug] Default values of zone ACLs were re-parsed each time a new zone was configured, causing an overconsumption of memory. [RT #18092] diff --git a/lib/isc/radix.c b/lib/isc/radix.c index c6178c06f7..ee0c815811 100644 --- a/lib/isc/radix.c +++ b/lib/isc/radix.c @@ -14,7 +14,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: radix.c,v 1.13 2008/01/27 23:47:20 tbox Exp $ */ +/* $Id: radix.c,v 1.14 2008/05/21 23:21:33 each Exp $ */ /* * This source was adapted from MRT's RCS Ids: @@ -323,6 +323,7 @@ isc_radix_insert(isc_radix_tree_t *radix, isc_radix_node_t **target, if (node == NULL) return (ISC_R_NOMEMORY); node->bit = bitlen; + node->node_num[0] = node->node_num[1] = -1; result = _ref_prefix(radix->mctx, &node->prefix, prefix); if (result != ISC_R_SUCCESS) { isc_mem_put(radix->mctx, node, @@ -351,7 +352,6 @@ isc_radix_insert(isc_radix_tree_t *radix, isc_radix_node_t **target, } else { node->node_num[ISC_IS6(family)] = ++radix->num_added_node; - node->node_num[!ISC_IS6(family)] = -1; node->data[0] = NULL; node->data[1] = NULL; } From db6fa15ef076390f83ad1292c0becdbab5d8d9ed Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Wed, 21 May 2008 23:30:20 +0000 Subject: [PATCH 084/137] newcopyrights --- util/copyrights | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/util/copyrights b/util/copyrights index 6c997e601a..89f53c6efd 100644 --- a/util/copyrights +++ b/util/copyrights @@ -2410,7 +2410,7 @@ ./lib/isccc/win32/version.c C 2001,2004,2007 ./lib/isccfg/.cvsignore X 2001 ./lib/isccfg/Makefile.in MAKE 2001,2002,2003,2004,2005,2007 -./lib/isccfg/aclconf.c C 1999,2000,2001,2002,2004,2005,2006,2007 +./lib/isccfg/aclconf.c C 1999,2000,2001,2002,2004,2005,2006,2007,2008 ./lib/isccfg/api X 2001,2006 ./lib/isccfg/include/.cvsignore X 2001 ./lib/isccfg/include/Makefile.in MAKE 2001,2004,2007 From 11156f82bab19b2e7f5d4df6184ae0c99518442f Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Wed, 21 May 2008 23:47:01 +0000 Subject: [PATCH 085/137] update copyright notice --- bin/named/server.c | 12 ++++++------ bin/named/zoneconf.c | 34 +++++++++++++++++----------------- lib/isccfg/aclconf.c | 10 +++++----- 3 files changed, 28 insertions(+), 28 deletions(-) diff --git a/bin/named/server.c b/bin/named/server.c index 6d36a9e2b0..02dc33bf7d 100644 --- a/bin/named/server.c +++ b/bin/named/server.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: server.c,v 1.507 2008/05/21 23:17:20 each Exp $ */ +/* $Id: server.c,v 1.508 2008/05/21 23:47:00 tbox Exp $ */ /*! \file */ @@ -1684,11 +1684,11 @@ configure_view(dns_view_t *view, const cfg_obj_t *config, CHECK(configure_view_sortlist(vconfig, config, actx, ns_g_mctx, &view->sortlist)); - /* - * Configure default allow-transfer, allow-notify, allow-update - * and allow-update-forwarding ACLs, if set, so they can be - * inherited by zones. - */ + /* + * Configure default allow-transfer, allow-notify, allow-update + * and allow-update-forwarding ACLs, if set, so they can be + * inherited by zones. + */ if (view->notifyacl == NULL) CHECK(configure_view_acl(NULL, ns_g_config, "allow-notify", actx, diff --git a/bin/named/zoneconf.c b/bin/named/zoneconf.c index ea760a4f3e..d78cf3bfb5 100644 --- a/bin/named/zoneconf.c +++ b/bin/named/zoneconf.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: zoneconf.c,v 1.145 2008/05/21 23:17:20 each Exp $ */ +/* $Id: zoneconf.c,v 1.146 2008/05/21 23:47:00 tbox Exp $ */ /*% */ @@ -80,39 +80,39 @@ configure_zone_acl(const cfg_obj_t *zconfig, const cfg_obj_t *vconfig, int i = 0; dns_acl_t **aclp = NULL, *acl = NULL; const char *aclname; - dns_view_t *view; + dns_view_t *view; - view = dns_zone_getview(zone); + view = dns_zone_getview(zone); switch (acltype) { case allow_notify: - if (view != NULL) - aclp = &view->notifyacl; + if (view != NULL) + aclp = &view->notifyacl; aclname = "allow-notify"; break; case allow_query: - if (view != NULL) - aclp = &view->queryacl; + if (view != NULL) + aclp = &view->queryacl; aclname = "allow-query"; break; case allow_transfer: - if (view != NULL) - aclp = &view->transferacl; + if (view != NULL) + aclp = &view->transferacl; aclname = "allow-transfer"; break; case allow_update: - if (view != NULL) - aclp = &view->updateacl; + if (view != NULL) + aclp = &view->updateacl; aclname = "allow-update"; break; case allow_update_forwarding: - if (view != NULL) - aclp = &view->upfwdacl; + if (view != NULL) + aclp = &view->upfwdacl; aclname = "allow-update-forwarding"; break; - default: - INSIST(0); - return (ISC_R_FAILURE); + default: + INSIST(0); + return (ISC_R_FAILURE); } /* First check to see if ACL is defined within the zone */ @@ -156,7 +156,7 @@ parse_acl: return (result); (*setzacl)(zone, acl); - /* Set the view default now */ + /* Set the view default now */ if (aclp != NULL) dns_acl_attach(acl, aclp); diff --git a/lib/isccfg/aclconf.c b/lib/isccfg/aclconf.c index 74ae0d234f..f81462796b 100644 --- a/lib/isccfg/aclconf.c +++ b/lib/isccfg/aclconf.c @@ -1,5 +1,5 @@ /* - * Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC") + * Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC") * Copyright (C) 1999-2002 Internet Software Consortium. * * Permission to use, copy, modify, and/or distribute this software for any @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: aclconf.c,v 1.18 2008/05/21 23:17:21 each Exp $ */ +/* $Id: aclconf.c,v 1.19 2008/05/21 23:47:01 tbox Exp $ */ #include @@ -31,7 +31,7 @@ #include #include -#define LOOP_MAGIC ISC_MAGIC('L','O','O','P') +#define LOOP_MAGIC ISC_MAGIC('L','O','O','P') void cfg_aclconfctx_init(cfg_aclconfctx_t *ctx) { @@ -59,7 +59,7 @@ get_acl_def(const cfg_obj_t *cctx, const char *name, const cfg_obj_t **ret) { isc_result_t result; const cfg_obj_t *acls = NULL; const cfg_listelt_t *elt; - + result = cfg_map_get(cctx, "acl", &acls); if (result != ISC_R_SUCCESS) return (result); @@ -376,7 +376,7 @@ nested_acl: /* * This should only be reached for localhost, localnets * and keyname elements, and nested ACLs if nest_level is - * nonzero (i.e., in sortlists). + * nonzero (i.e., in sortlists). */ if (de->nestedacl != NULL && de->type != dns_aclelementtype_nestedacl) From 6421f9a9aa8b72a1cd10e2824fc8a68d6c33779a Mon Sep 17 00:00:00 2001 From: Evan Hunt Date: Thu, 22 May 2008 20:46:35 +0000 Subject: [PATCH 086/137] Fully randomize UDP query ports to improve forgery resilience. [rt17949] --- CHANGES | 3 + bin/named/client.c | 10 +- bin/named/server.c | 34 +- doc/arm/Bv9ARM-book.xml | 12 +- lib/dns/dispatch.c | 707 +++++++++++---------------------- lib/dns/include/dns/dispatch.h | 13 +- lib/dns/resolver.c | 43 +- 7 files changed, 318 insertions(+), 504 deletions(-) diff --git a/CHANGES b/CHANGES index edd55023ce..09886ba34b 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +2375. [security] Fully randomize UDP query ports to improve + forgery resilience. [RT #17949] + 2369. [bug] libbind: Array bounds overrun on read in bitncmp(). [RT #18054] diff --git a/bin/named/client.c b/bin/named/client.c index 6d4cc91a4e..3b92c51507 100644 --- a/bin/named/client.c +++ b/bin/named/client.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: client.c,v 1.176.2.13.4.38 2007/08/28 07:19:08 tbox Exp $ */ +/* $Id: client.c,v 1.176.2.13.4.39 2008/05/22 20:46:34 each Exp $ */ #include @@ -1348,14 +1348,6 @@ client_request(isc_task_t *task, isc_event_t *event) { } } - /* - * Hash the incoming request here as it is after - * dns_dispatch_importrecv(). - */ - dns_dispatch_hash(&client->now, sizeof(client->now)); - dns_dispatch_hash(isc_buffer_base(buffer), - isc_buffer_usedlength(buffer)); - /* * It's a request. Parse it. */ diff --git a/bin/named/server.c b/bin/named/server.c index a01e5e79cf..cca48dbcdc 100644 --- a/bin/named/server.c +++ b/bin/named/server.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: server.c,v 1.339.2.15.2.78 2008/01/17 23:45:27 tbox Exp $ */ +/* $Id: server.c,v 1.339.2.15.2.79 2008/05/22 20:46:34 each Exp $ */ #include @@ -485,6 +485,14 @@ get_view_querysource_dispatch(const cfg_obj_t **maps, attrs |= DNS_DISPATCHATTR_IPV6; break; } + + if (isc_sockaddr_getport(&sa) != 0) { + INSIST(obj != NULL); + cfg_obj_log(obj, ns_g_lctx, ISC_LOG_INFO, + "using specific query-source port suppresses port " + "randomization and can be insecure."); + } + attrmask = 0; attrmask |= DNS_DISPATCHATTR_UDP; attrmask |= DNS_DISPATCHATTR_TCP; @@ -494,7 +502,7 @@ get_view_querysource_dispatch(const cfg_obj_t **maps, disp = NULL; result = dns_dispatch_getudp(ns_g_dispatchmgr, ns_g_socketmgr, ns_g_taskmgr, &sa, 4096, - 1000, 32768, 16411, 16433, + 1024, 32768, 16411, 16433, attrs, attrmask, &disp); if (result != ISC_R_SUCCESS) { isc_sockaddr_t any; @@ -1866,7 +1874,9 @@ scan_interfaces(ns_server_t *server, isc_boolean_t verbose) { } static isc_result_t -add_listenelt(isc_mem_t *mctx, ns_listenlist_t *list, isc_sockaddr_t *addr) { +add_listenelt(isc_mem_t *mctx, ns_listenlist_t *list, isc_sockaddr_t *addr, + isc_boolean_t wcardport_ok) +{ ns_listenelt_t *lelt = NULL; dns_acl_t *src_acl = NULL; dns_aclelement_t aelt; @@ -1876,7 +1886,8 @@ add_listenelt(isc_mem_t *mctx, ns_listenlist_t *list, isc_sockaddr_t *addr) { REQUIRE(isc_sockaddr_pf(addr) == AF_INET6); isc_sockaddr_any6(&any_sa6); - if (!isc_sockaddr_equal(&any_sa6, addr)) { + if (!isc_sockaddr_equal(&any_sa6, addr) && + (wcardport_ok || isc_sockaddr_getport(addr) != 0)) { aelt.type = dns_aclelementtype_ipprefix; aelt.negative = ISC_FALSE; aelt.u.ip_prefix.prefixlen = 128; @@ -1935,7 +1946,16 @@ adjust_interfaces(ns_server_t *server, isc_mem_t *mctx) { result = dns_dispatch_getlocaladdress(dispatch6, &addr); if (result != ISC_R_SUCCESS) goto fail; - result = add_listenelt(mctx, list, &addr); + + /* + * We always add non-wildcard address regardless of whether + * the port is 'any' (the fourth arg is TRUE): if the port is + * specific, we need to add it since it may conflict with a + * listening interface; if it's zero, we'll dynamically open + * query ports, and some of them may override an existing + * wildcard IPv6 port. + */ + result = add_listenelt(mctx, list, &addr, ISC_TRUE); if (result != ISC_R_SUCCESS) goto fail; } @@ -1965,12 +1985,12 @@ adjust_interfaces(ns_server_t *server, isc_mem_t *mctx) { continue; addrp = dns_zone_getnotifysrc6(zone); - result = add_listenelt(mctx, list, addrp); + result = add_listenelt(mctx, list, addrp, ISC_FALSE); if (result != ISC_R_SUCCESS) goto fail; addrp = dns_zone_getxfrsource6(zone); - result = add_listenelt(mctx, list, addrp); + result = add_listenelt(mctx, list, addrp, ISC_FALSE); if (result != ISC_R_SUCCESS) goto fail; } diff --git a/doc/arm/Bv9ARM-book.xml b/doc/arm/Bv9ARM-book.xml index a1f35bb7ed..9d1419e6d3 100644 --- a/doc/arm/Bv9ARM-book.xml +++ b/doc/arm/Bv9ARM-book.xml @@ -18,7 +18,7 @@ - PERFORMANCE OF THIS SOFTWARE. --> - + BIND 9 Administrator Reference Manual @@ -3732,7 +3732,15 @@ IPv6, there is a separate query-source-v6 option. If address is * (asterisk) or is omitted, a wildcard IP address (INADDR_ANY) will be used. If port is * or is omitted, -a random unprivileged port will be used. The avoid-v4-udp-ports +a random unprivileged port number is picked up and will be +used for each query. +It is generally strongly discouraged to +specify a particular port for the +query-source or +query-source-v6 options; +it implicitly disables the use of randomized port numbers +and leads to insecure operation. +The avoid-v4-udp-ports and avoid-v6-udp-ports options can be used to prevent named from selecting certain ports. The defaults are: query-source address * port *; diff --git a/lib/dns/dispatch.c b/lib/dns/dispatch.c index 869fd7bba0..47aa7d3191 100644 --- a/lib/dns/dispatch.c +++ b/lib/dns/dispatch.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: dispatch.c,v 1.101.2.6.2.21 2007/08/28 07:19:13 tbox Exp $ */ +/* $Id: dispatch.c,v 1.101.2.6.2.22 2008/05/22 20:46:35 each Exp $ */ #include @@ -27,6 +27,7 @@ #include #include #include +#include #include #include #include @@ -43,25 +44,22 @@ typedef ISC_LIST(dns_dispentry_t) dns_displist_t; -typedef struct dns_nsid { - isc_uint16_t nsid_state; - isc_uint16_t *nsid_vtable; - isc_uint16_t *nsid_pool; - isc_uint16_t nsid_a1, nsid_a2, nsid_a3; - isc_uint16_t nsid_c1, nsid_c2, nsid_c3; - isc_uint16_t nsid_state2; - isc_boolean_t nsid_usepool; -} dns_nsid_t; - typedef struct dns_qid { unsigned int magic; unsigned int qid_nbuckets; /* hash table size */ unsigned int qid_increment; /* id increment on collision */ isc_mutex_t lock; - dns_nsid_t nsid; dns_displist_t *qid_table; /* the table itself */ } dns_qid_t; +/* ARC4 Random generator state */ +typedef struct arc4ctx { + isc_uint8_t i; + isc_uint8_t j; + isc_uint8_t s[256]; + int count; +} arc4ctx_t; + struct dns_dispatchmgr { /* Unlocked. */ unsigned int magic; @@ -74,6 +72,10 @@ struct dns_dispatchmgr { unsigned int state; ISC_LIST(dns_dispatch_t) list; + /* Locked by arc4_lock. */ + isc_mutex_t arc4_lock; + arc4ctx_t arc4ctx; /*%< ARC4 context for QID */ + /* locked by buffer lock */ dns_qid_t *qid; isc_mutex_t buffer_lock; @@ -100,6 +102,7 @@ struct dns_dispentry { unsigned int magic; dns_dispatch_t *disp; dns_messageid_t id; + in_port_t port; unsigned int bucket; isc_sockaddr_t host; isc_task_t *task; @@ -119,6 +122,7 @@ struct dns_dispatch { isc_task_t *task; /* internal task */ isc_socket_t *socket; /* isc socket attached to */ isc_sockaddr_t local; /* local address */ + in_port_t localport; /* local UDP port */ unsigned int maxrequests; /* max requests */ isc_event_t *ctlevent; @@ -161,14 +165,14 @@ struct dns_dispatch { * Statics. */ static dns_dispentry_t *bucket_search(dns_qid_t *, isc_sockaddr_t *, - dns_messageid_t, unsigned int); + dns_messageid_t, in_port_t, unsigned int); static isc_boolean_t destroy_disp_ok(dns_dispatch_t *); static void destroy_disp(isc_task_t *task, isc_event_t *event); static void udp_recv(isc_task_t *, isc_event_t *); static void tcp_recv(isc_task_t *, isc_event_t *); static void startrecv(dns_dispatch_t *); -static dns_messageid_t dns_randomid(dns_nsid_t *); -static isc_uint32_t dns_hash(dns_qid_t *, isc_sockaddr_t *, dns_messageid_t); +static isc_uint32_t dns_hash(dns_qid_t *, isc_sockaddr_t *, dns_messageid_t, + in_port_t); static void free_buffer(dns_dispatch_t *disp, void *buf, unsigned int len); static void *allocate_udp_buffer(dns_dispatch_t *disp); static inline void free_event(dns_dispatch_t *disp, dns_dispatchevent_t *ev); @@ -188,12 +192,8 @@ static isc_result_t dispatch_createudp(dns_dispatchmgr_t *mgr, static isc_boolean_t destroy_mgr_ok(dns_dispatchmgr_t *mgr); static void destroy_mgr(dns_dispatchmgr_t **mgrp); static isc_result_t qid_allocate(dns_dispatchmgr_t *mgr, unsigned int buckets, - unsigned int increment, isc_boolean_t usepool, - dns_qid_t **qidp); + unsigned int increment, dns_qid_t **qidp); static void qid_destroy(isc_mem_t *mctx, dns_qid_t **qidp); -static isc_uint16_t nsid_next(dns_nsid_t *nsid); -static isc_result_t nsid_init(isc_mem_t *mctx, dns_nsid_t *nsid, isc_boolean_t usepool); -static void nsid_destroy(isc_mem_t *mctx, dns_nsid_t *nsid); #define LVL(x) ISC_LOG_DEBUG(x) @@ -274,26 +274,152 @@ request_log(dns_dispatch_t *disp, dns_dispentry_t *resp, } /* - * Return an unpredictable message ID. + * ARC4 random number generator obtained from OpenBSD */ -static dns_messageid_t -dns_randomid(dns_nsid_t *nsid) { - isc_uint32_t id; +static void +dispatch_arc4init(arc4ctx_t *actx) { + int n; + for (n = 0; n < 256; n++) + actx->s[n] = n; + actx->i = 0; + actx->j = 0; + actx->count = 0; +} - id = nsid_next(nsid); +static void +dispatch_arc4addrandom(arc4ctx_t *actx, unsigned char *dat, int datlen) { + int n; + isc_uint8_t si; - return ((dns_messageid_t)id); + actx->i--; + for (n = 0; n < 256; n++) { + actx->i = (actx->i + 1); + si = actx->s[actx->i]; + actx->j = (actx->j + si + dat[n % datlen]); + actx->s[actx->i] = actx->s[actx->j]; + actx->s[actx->j] = si; + } + actx->j = actx->i; +} + +static inline isc_uint8_t +dispatch_arc4get8(arc4ctx_t *actx) { + isc_uint8_t si, sj; + + actx->i = (actx->i + 1); + si = actx->s[actx->i]; + actx->j = (actx->j + si); + sj = actx->s[actx->j]; + actx->s[actx->i] = sj; + actx->s[actx->j] = si; + + return (actx->s[(si + sj) & 0xff]); +} + +static inline isc_uint16_t +dispatch_arc4get16(arc4ctx_t *actx) { + isc_uint16_t val; + + val = dispatch_arc4get8(actx) << 8; + val |= dispatch_arc4get8(actx); + + return (val); +} + +static void +dispatch_arc4stir(dns_dispatchmgr_t *mgr) { + int i; + union { + unsigned char rnd[128]; + isc_uint32_t rnd32[32]; + } rnd; + isc_result_t result; + + if (mgr->entropy != NULL) { + /* + * We accept any quality of random data to avoid blocking. + */ + result = isc_entropy_getdata(mgr->entropy, rnd.rnd, + sizeof(rnd), NULL, 0); + RUNTIME_CHECK(result == ISC_R_SUCCESS); + } else { + for (i = 0; i < 32; i++) + isc_random_get(&rnd.rnd32[i]); + } + dispatch_arc4addrandom(&mgr->arc4ctx, rnd.rnd, sizeof(rnd.rnd)); + + /* + * Discard early keystream, as per recommendations in: + * http://www.wisdom.weizmann.ac.il/~itsik/RC4/Papers/Rc4_ksa.ps + */ + for (i = 0; i < 256; i++) + (void)dispatch_arc4get8(&mgr->arc4ctx); + + /* + * Derived from OpenBSD's implementation. The rationale is not clear, + * but should be conservative enough in safety, and reasonably large + * for efficiency. + */ + mgr->arc4ctx.count = 1600000; +} + +static isc_uint16_t +dispatch_arc4random(dns_dispatchmgr_t *mgr) { + isc_uint16_t result; + + LOCK(&mgr->arc4_lock); + mgr->arc4ctx.count -= sizeof(isc_uint16_t); + if (mgr->arc4ctx.count <= 0) + dispatch_arc4stir(mgr); + result = dispatch_arc4get16(&mgr->arc4ctx); + UNLOCK(&mgr->arc4_lock); + return (result); +} + +static isc_uint16_t +dispatch_arc4uniformrandom(dns_dispatchmgr_t *mgr, isc_uint16_t upper_bound) { + isc_uint16_t min, r; + /* The caller must hold the manager lock. */ + + if (upper_bound < 2) + return (0); + + /* + * Ensure the range of random numbers [min, 0xffff] be a multiple of + * upper_bound and contain at least a half of the 16 bit range. + */ + + if (upper_bound > 0x8000) + min = 1 + ~upper_bound; /* 0x8000 - upper_bound */ + else + min = (isc_uint16_t)(0x10000 % (isc_uint32_t)upper_bound); + + /* + * This could theoretically loop forever but each retry has + * p > 0.5 (worst case, usually far better) of selecting a + * number inside the range we need, so it should rarely need + * to re-roll. + */ + for (;;) { + r = dispatch_arc4random(mgr); + if (r >= min) + break; + } + + return (r % upper_bound); } /* * Return a hash of the destination and message id. */ static isc_uint32_t -dns_hash(dns_qid_t *qid, isc_sockaddr_t *dest, dns_messageid_t id) { +dns_hash(dns_qid_t *qid, isc_sockaddr_t *dest, dns_messageid_t id, + in_port_t port) +{ unsigned int ret; ret = isc_sockaddr_hash(dest, ISC_TRUE); - ret ^= id; + ret ^= (id << 16) | port; ret %= qid->qid_nbuckets; INSIST(ret < qid->qid_nbuckets); @@ -410,7 +536,7 @@ destroy_disp(isc_task_t *task, isc_event_t *event) { */ static dns_dispentry_t * bucket_search(dns_qid_t *qid, isc_sockaddr_t *dest, dns_messageid_t id, - unsigned int bucket) + in_port_t port, unsigned int bucket) { dns_dispentry_t *res; @@ -419,8 +545,10 @@ bucket_search(dns_qid_t *qid, isc_sockaddr_t *dest, dns_messageid_t id, res = ISC_LIST_HEAD(qid->qid_table[bucket]); while (res != NULL) { - if ((res->id == id) && isc_sockaddr_equal(dest, &res->host)) + if ((res->id == id) && isc_sockaddr_equal(dest, &res->host) && + res->port == port) { return (res); + } res = ISC_LIST_NEXT(res, link); } @@ -622,13 +750,10 @@ udp_recv(isc_task_t *task, isc_event_t *ev_in) { goto restart; } - dns_dispatch_hash(&ev->timestamp, sizeof(&ev->timestamp)); - dns_dispatch_hash(ev->region.base, ev->region.length); - /* response */ - bucket = dns_hash(qid, &ev->address, id); + bucket = dns_hash(qid, &ev->address, id, disp->localport); LOCK(&qid->lock); - resp = bucket_search(qid, &ev->address, id, bucket); + resp = bucket_search(qid, &ev->address, id, disp->localport, bucket); dispatch_log(disp, LVL(90), "search for response in bucket %d: %s", bucket, (resp == NULL ? "not found" : "found")); @@ -859,14 +984,13 @@ tcp_recv(isc_task_t *task, isc_event_t *ev_in) { goto restart; } - dns_dispatch_hash(tcpmsg->buffer.base, tcpmsg->buffer.length); - /* * Response. */ - bucket = dns_hash(qid, &tcpmsg->address, id); + bucket = dns_hash(qid, &tcpmsg->address, id, disp->localport); LOCK(&qid->lock); - resp = bucket_search(qid, &tcpmsg->address, id, bucket); + resp = bucket_search(qid, &tcpmsg->address, id, disp->localport, + bucket); dispatch_log(disp, LVL(90), "search for response in bucket %d: %s", bucket, (resp == NULL ? "not found" : "found")); @@ -1015,6 +1139,8 @@ destroy_mgr(dns_dispatchmgr_t **mgrp) { DESTROYLOCK(&mgr->lock); mgr->state = 0; + DESTROYLOCK(&mgr->arc4_lock); + isc_mempool_destroy(&mgr->epool); isc_mempool_destroy(&mgr->rpool); isc_mempool_destroy(&mgr->dpool); @@ -1093,10 +1219,14 @@ dns_dispatchmgr_create(isc_mem_t *mctx, isc_entropy_t *entropy, if (result != ISC_R_SUCCESS) goto deallocate; - result = isc_mutex_init(&mgr->buffer_lock); + result = isc_mutex_init(&mgr->arc4_lock); if (result != ISC_R_SUCCESS) goto kill_lock; + result = isc_mutex_init(&mgr->buffer_lock); + if (result != ISC_R_SUCCESS) + goto kill_arc4_lock; + result = isc_mutex_init(&mgr->pool_lock); if (result != ISC_R_SUCCESS) goto kill_buffer_lock; @@ -1147,6 +1277,8 @@ dns_dispatchmgr_create(isc_mem_t *mctx, isc_entropy_t *entropy, if (entropy != NULL) isc_entropy_attach(entropy, &mgr->entropy); + dispatch_arc4init(&mgr->arc4ctx); + *mgrp = mgr; return (ISC_R_SUCCESS); @@ -1158,6 +1290,8 @@ dns_dispatchmgr_create(isc_mem_t *mctx, isc_entropy_t *entropy, DESTROYLOCK(&mgr->pool_lock); kill_buffer_lock: DESTROYLOCK(&mgr->buffer_lock); + kill_arc4_lock: + DESTROYLOCK(&mgr->arc4_lock); kill_lock: DESTROYLOCK(&mgr->lock); deallocate: @@ -1245,7 +1379,7 @@ dns_dispatchmgr_setudp(dns_dispatchmgr_t *mgr, isc_mempool_setmaxalloc(mgr->bpool, maxbuffers); isc_mempool_associatelock(mgr->bpool, &mgr->pool_lock); - result = qid_allocate(mgr, buckets, increment, ISC_TRUE, &mgr->qid); + result = qid_allocate(mgr, buckets, increment, &mgr->qid); if (result != ISC_R_SUCCESS) goto cleanup; @@ -1284,20 +1418,27 @@ dns_dispatchmgr_destroy(dns_dispatchmgr_t **mgrp) { } static isc_boolean_t -blacklisted(dns_dispatchmgr_t *mgr, isc_socket_t *sock) { +blacklisted(dns_dispatchmgr_t *mgr, isc_socket_t *sock, + isc_sockaddr_t *sockaddrp) +{ isc_sockaddr_t sockaddr; isc_result_t result; + REQUIRE(sock != NULL || sockaddrp != NULL); + if (mgr->portlist == NULL) return (ISC_FALSE); - result = isc_socket_getsockname(sock, &sockaddr); - if (result != ISC_R_SUCCESS) - return (ISC_FALSE); + if (sock != NULL) { + sockaddrp = &sockaddr; + result = isc_socket_getsockname(sock, sockaddrp); + if (result != ISC_R_SUCCESS) + return (ISC_FALSE); + } if (mgr->portlist != NULL && - dns_portlist_match(mgr->portlist, isc_sockaddr_pf(&sockaddr), - isc_sockaddr_getport(&sockaddr))) + dns_portlist_match(mgr->portlist, isc_sockaddr_pf(sockaddrp), + isc_sockaddr_getport(sockaddrp))) return (ISC_TRUE); return (ISC_FALSE); } @@ -1318,7 +1459,7 @@ local_addr_match(dns_dispatch_t *disp, isc_sockaddr_t *addr) { if (disp->mgr->portlist != NULL && isc_sockaddr_getport(addr) == 0 && isc_sockaddr_getport(&disp->local) == 0 && - blacklisted(disp->mgr, disp->socket)) + blacklisted(disp->mgr, disp->socket, NULL)) return (ISC_FALSE); /* @@ -1391,7 +1532,7 @@ dispatch_find(dns_dispatchmgr_t *mgr, isc_sockaddr_t *local, static isc_result_t qid_allocate(dns_dispatchmgr_t *mgr, unsigned int buckets, - unsigned int increment, isc_boolean_t usepool, dns_qid_t **qidp) + unsigned int increment, dns_qid_t **qidp) { dns_qid_t *qid; unsigned int i; @@ -1412,16 +1553,8 @@ qid_allocate(dns_dispatchmgr_t *mgr, unsigned int buckets, return (ISC_R_NOMEMORY); } - if (nsid_init(mgr->mctx, &qid->nsid, usepool) != ISC_R_SUCCESS) { - isc_mem_put(mgr->mctx, qid->qid_table, - buckets * sizeof(dns_displist_t)); - isc_mem_put(mgr->mctx, qid, sizeof(*qid)); - return (ISC_R_NOMEMORY); - } - if (isc_mutex_init(&qid->lock) != ISC_R_SUCCESS) { UNEXPECTED_ERROR(__FILE__, __LINE__, "isc_mutex_init failed"); - nsid_destroy(mgr->mctx, &qid->nsid); isc_mem_put(mgr->mctx, qid->qid_table, buckets * sizeof(dns_displist_t)); isc_mem_put(mgr->mctx, qid, sizeof(*qid)); @@ -1449,7 +1582,6 @@ qid_destroy(isc_mem_t *mctx, dns_qid_t **qidp) { *qidp = NULL; qid->magic = 0; - nsid_destroy(mctx, &qid->nsid); isc_mem_put(mctx, qid->qid_table, qid->qid_nbuckets * sizeof(dns_displist_t)); DESTROYLOCK(&qid->lock); @@ -1486,6 +1618,7 @@ dispatch_allocate(dns_dispatchmgr_t *mgr, unsigned int maxrequests, disp->refcount = 1; disp->recv_pending = 0; memset(&disp->local, 0, sizeof(disp->local)); + disp->localport = 0; disp->shutting_down = 0; disp->shutdown_out = 0; disp->connected = 0; @@ -1593,7 +1726,7 @@ dns_dispatch_createtcp(dns_dispatchmgr_t *mgr, isc_socket_t *sock, return (result); } - result = qid_allocate(mgr, buckets, increment, ISC_FALSE, &disp->qid); + result = qid_allocate(mgr, buckets, increment, &disp->qid); if (result != ISC_R_SUCCESS) goto deallocate_dispatch; @@ -1660,7 +1793,7 @@ dns_dispatch_getudp(dns_dispatchmgr_t *mgr, isc_socketmgr_t *sockmgr, dns_dispatch_t **dispp) { isc_result_t result; - dns_dispatch_t *disp; + dns_dispatch_t *disp = NULL; REQUIRE(VALID_DISPATCHMGR(mgr)); REQUIRE(sockmgr != NULL); @@ -1680,6 +1813,11 @@ dns_dispatch_getudp(dns_dispatchmgr_t *mgr, isc_socketmgr_t *sockmgr, LOCK(&mgr->lock); + if ((attributes & DNS_DISPATCHATTR_RANDOMPORT) != 0) { + REQUIRE(isc_sockaddr_getport(localaddr) == 0); + goto createudp; + } + /* * First, see if we have a dispatcher that matches. */ @@ -1708,6 +1846,7 @@ dns_dispatch_getudp(dns_dispatchmgr_t *mgr, isc_socketmgr_t *sockmgr, return (ISC_R_SUCCESS); } + createudp: /* * Nope, create one. */ @@ -1743,7 +1882,9 @@ dispatch_createudp(dns_dispatchmgr_t *mgr, isc_socketmgr_t *sockmgr, dns_dispatch_t *disp; isc_socket_t *sock = NULL; isc_socket_t *held[DNS_DISPATCH_HELD]; - unsigned int i = 0, j = 0; + unsigned int i = 0, j = 0, k = 0; + isc_sockaddr_t localaddr_bound; + in_port_t localport = 0; /* * dispatch_allocate() checks mgr for us. @@ -1759,11 +1900,34 @@ dispatch_createudp(dns_dispatchmgr_t *mgr, isc_socketmgr_t *sockmgr, * from returning the same port to us too quickly. */ memset(held, 0, sizeof(held)); + localaddr_bound = *localaddr; getsocket: - result = create_socket(sockmgr, localaddr, &sock); + if ((attributes & DNS_DISPATCHATTR_RANDOMPORT) != 0) { + in_port_t prt; + + /* XXX: should the range be configurable? */ + prt = 1024 + dispatch_arc4uniformrandom(mgr, 65535 - 1023); + isc_sockaddr_setport(&localaddr_bound, prt); + if (blacklisted(mgr, NULL, &localaddr_bound)) { + if (++k == 1024) + attributes &= ~DNS_DISPATCHATTR_RANDOMPORT; + goto getsocket; + } + result = create_socket(sockmgr, &localaddr_bound, &sock); + if (result == ISC_R_ADDRINUSE) { + if (++k == 1024) + attributes &= ~DNS_DISPATCHATTR_RANDOMPORT; + goto getsocket; + } + localport = prt; + } else + result = create_socket(sockmgr, localaddr, &sock); if (result != ISC_R_SUCCESS) goto deallocate_dispatch; - if (isc_sockaddr_getport(localaddr) == 0 && blacklisted(mgr, sock)) { + if ((attributes & DNS_DISPATCHATTR_RANDOMPORT) == 0 && + isc_sockaddr_getport(localaddr) == 0 && + blacklisted(mgr, sock, NULL)) + { if (held[i] != NULL) isc_socket_detach(&held[i]); held[i++] = sock; @@ -1784,6 +1948,7 @@ dispatch_createudp(dns_dispatchmgr_t *mgr, isc_socketmgr_t *sockmgr, disp->socktype = isc_sockettype_udp; disp->socket = sock; disp->local = *localaddr; + disp->localport = localport; disp->task = NULL; result = isc_task_create(taskmgr, 0, &disp->task); @@ -1916,19 +2081,20 @@ dns_dispatch_addresponse(dns_dispatch_t *disp, isc_sockaddr_t *dest, /* * Try somewhat hard to find an unique ID. */ + id = (dns_messageid_t)dispatch_arc4random(disp->mgr); qid = DNS_QID(disp); LOCK(&qid->lock); - id = dns_randomid(&qid->nsid); - bucket = dns_hash(qid, dest, id); + bucket = dns_hash(qid, dest, id, disp->localport); ok = ISC_FALSE; for (i = 0; i < 64; i++) { - if (bucket_search(qid, dest, id, bucket) == NULL) { + if (bucket_search(qid, dest, id, disp->localport, bucket) == + NULL) { ok = ISC_TRUE; break; } id += qid->qid_increment; id &= 0x0000ffff; - bucket = dns_hash(qid, dest, id); + bucket = dns_hash(qid, dest, id, disp->localport); } if (!ok) { @@ -1950,6 +2116,7 @@ dns_dispatch_addresponse(dns_dispatch_t *disp, isc_sockaddr_t *dest, isc_task_attach(task, &res->task); res->disp = disp; res->id = id; + res->port = disp->localport; res->bucket = bucket; res->host = *dest; res->action = action; @@ -2261,409 +2428,3 @@ dns_dispatchmgr_dump(dns_dispatchmgr_t *mgr) { } } #endif - -/* - * Allow the user to pick one of two ID randomization algorithms. - * - * The first algorithm is an adaptation of the sequence shuffling - * algorithm discovered by Carter Bays and S. D. Durham [ACM Trans. Math. - * Software 2 (1976), 59-64], as documented as Algorithm B in Chapter - * 3.2.2 in Volume 2 of Knuth's "The Art of Computer Programming". We use - * a randomly selected linear congruential random number generator with a - * modulus of 2^16, whose increment is a randomly picked odd number, and - * whose multiplier is picked from a set which meets the following - * criteria: - * Is of the form 8*n+5, which ensures "high potency" according to - * principle iii in the summary chapter 3.6. This form also has a - * gcd(a-1,m) of 4 which is good according to principle iv. - * - * Is between 0.01 and 0.99 times the modulus as specified by - * principle iv. - * - * Passes the spectral test "with flying colors" (ut >= 1) in - * dimensions 2 through 6 as calculated by Algorithm S in Chapter - * 3.3.4 and the ratings calculated by formula 35 in section E. - * - * Of the multipliers that pass this test, pick the set that is - * best according to the theoretical bounds of the serial - * correlation test. This was calculated using a simplified - * version of Knuth's Theorem K in Chapter 3.3.3. - * - * These criteria may not be important for this use, but we might as well - * pick from the best generators since there are so many possible ones and - * we don't have that many random bits to do the picking. - * - * We use a modulus of 2^16 instead of something bigger so that we will - * tend to cycle through all the possible IDs before repeating any, - * however the shuffling will perturb this somewhat. Theoretically there - * is no minimimum interval between two uses of the same ID, but in - * practice it seems to be >64000. - * - * Our adaptatation of Algorithm B mixes the hash state which has - * captured various random events into the shuffler to perturb the - * sequence. - * - * One disadvantage of this algorithm is that if the generator parameters - * were to be guessed, it would be possible to mount a limited brute force - * attack on the ID space since the IDs are only shuffled within a limited - * range. - * - * The second algorithm uses the same random number generator to populate - * a pool of 65536 IDs. The hash state is used to pick an ID from a window - * of 4096 IDs in this pool, then the chosen ID is swapped with the ID - * at the beginning of the window and the window position is advanced. - * This means that the interval between uses of the ID will be no less - * than 65536-4096. The ID sequence in the pool will become more random - * over time. - * - * For both algorithms, two more linear congruential random number generators - * are selected. The ID from the first part of algorithm is used to seed - * the first of these generators, and its output is used to seed the second. - * The strategy is use these generators as 1 to 1 hashes to obfuscate the - * properties of the generator used in the first part of either algorithm. - * - * The first algorithm may be suitable for use in a client resolver since - * its memory requirements are fairly low and it's pretty random out of - * the box. It is somewhat succeptible to a limited brute force attack, - * so the second algorithm is probably preferable for a longer running - * program that issues a large number of queries and has time to randomize - * the pool. - */ - -#define NSID_SHUFFLE_TABLE_SIZE 100 /* Suggested by Knuth */ -/* - * Pick one of the next 4096 IDs in the pool. - * There is a tradeoff here between randomness and how often and ID is reused. - */ -#define NSID_LOOKAHEAD 4096 /* Must be a power of 2 */ -#define NSID_SHUFFLE_ONLY 1 /* algorithm 1 */ -#define NSID_USE_POOL 2 /* algorithm 2 */ -#define NSID_HASHSHIFT 3 -#define NSID_HASHROTATE(v) \ - (((v) << NSID_HASHSHIFT) | ((v) >> ((sizeof(v) * 8) - NSID_HASHSHIFT))) - -static isc_uint32_t nsid_hash_state; - -/* - * Keep a running hash of various bits of data that we'll use to - * stir the ID pool or perturb the ID generator - */ -static void -nsid_hash(void *data, size_t len) { - unsigned char *p = data; - /* - * Hash function similar to the one we use for hashing names. - * We don't fold case or toss the upper bit here, though. - * This hash doesn't do much interesting when fed binary zeros, - * so there may be a better hash function. - * This function doesn't need to be very strong since we're - * only using it to stir the pool, but it should be reasonably - * fast. - */ - /* - * We don't care about locking access to nsid_hash_state. - * In fact races make the result even more non deteministic. - */ - while (len-- > 0U) { - nsid_hash_state = NSID_HASHROTATE(nsid_hash_state); - nsid_hash_state += *p++; - } -} - -/* - * Table of good linear congruential multipliers for modulus 2^16 - * in order of increasing serial correlation bounds (so trim from - * the end). - */ -static const isc_uint16_t nsid_multiplier_table[] = { - 17565, 25013, 11733, 19877, 23989, 23997, 24997, 25421, - 26781, 27413, 35901, 35917, 35973, 36229, 38317, 38437, - 39941, 40493, 41853, 46317, 50581, 51429, 53453, 53805, - 11317, 11789, 12045, 12413, 14277, 14821, 14917, 18989, - 19821, 23005, 23533, 23573, 23693, 27549, 27709, 28461, - 29365, 35605, 37693, 37757, 38309, 41285, 45261, 47061, - 47269, 48133, 48597, 50277, 50717, 50757, 50805, 51341, - 51413, 51581, 51597, 53445, 11493, 14229, 20365, 20653, - 23485, 25541, 27429, 29421, 30173, 35445, 35653, 36789, - 36797, 37109, 37157, 37669, 38661, 39773, 40397, 41837, - 41877, 45293, 47277, 47845, 49853, 51085, 51349, 54085, - 56933, 8877, 8973, 9885, 11365, 11813, 13581, 13589, - 13613, 14109, 14317, 15765, 15789, 16925, 17069, 17205, - 17621, 17941, 19077, 19381, 20245, 22845, 23733, 24869, - 25453, 27213, 28381, 28965, 29245, 29997, 30733, 30901, - 34877, 35485, 35613, 36133, 36661, 36917, 38597, 40285, - 40693, 41413, 41541, 41637, 42053, 42349, 45245, 45469, - 46493, 48205, 48613, 50861, 51861, 52877, 53933, 54397, - 55669, 56453, 56965, 58021, 7757, 7781, 8333, 9661, - 12229, 14373, 14453, 17549, 18141, 19085, 20773, 23701, - 24205, 24333, 25261, 25317, 27181, 30117, 30477, 34757, - 34885, 35565, 35885, 36541, 37957, 39733, 39813, 41157, - 41893, 42317, 46621, 48117, 48181, 49525, 55261, 55389, - 56845, 7045, 7749, 7965, 8469, 9133, 9549, 9789, - 10173, 11181, 11285, 12253, 13453, 13533, 13757, 14477, - 15053, 16901, 17213, 17269, 17525, 17629, 18605, 19013, - 19829, 19933, 20069, 20093, 23261, 23333, 24949, 25309, - 27613, 28453, 28709, 29301, 29541, 34165, 34413, 37301, - 37773, 38045, 38405, 41077, 41781, 41925, 42717, 44437, - 44525, 44613, 45933, 45941, 47077, 50077, 50893, 52117, - 5293, 55069, 55989, 58125, 59205, 6869, 14685, 15453, - 16821, 17045, 17613, 18437, 21029, 22773, 22909, 25445, - 25757, 26541, 30709, 30909, 31093, 31149, 37069, 37725, - 37925, 38949, 39637, 39701, 40765, 40861, 42965, 44813, - 45077, 45733, 47045, 50093, 52861, 52957, 54181, 56325, - 56365, 56381, 56877, 57013, 5741, 58101, 58669, 8613, - 10045, 10261, 10653, 10733, 11461, 12261, 14069, 15877, - 17757, 21165, 23885, 24701, 26429, 26645, 27925, 28765, - 29197, 30189, 31293, 39781, 39909, 40365, 41229, 41453, - 41653, 42165, 42365, 47421, 48029, 48085, 52773, 5573, - 57037, 57637, 58341, 58357, 58901, 6357, 7789, 9093, - 10125, 10709, 10765, 11957, 12469, 13437, 13509, 14773, - 15437, 15773, 17813, 18829, 19565, 20237, 23461, 23685, - 23725, 23941, 24877, 25461, 26405, 29509, 30285, 35181, - 37229, 37893, 38565, 40293, 44189, 44581, 45701, 47381, - 47589, 48557, 4941, 51069, 5165, 52797, 53149, 5341, - 56301, 56765, 58581, 59493, 59677, 6085, 6349, 8293, - 8501, 8517, 11597, 11709, 12589, 12693, 13517, 14909, - 17397, 18085, 21101, 21269, 22717, 25237, 25661, 29189, - 30101, 31397, 33933, 34213, 34661, 35533, 36493, 37309, - 40037, 4189, 42909, 44309, 44357, 44389, 4541, 45461, - 46445, 48237, 54149, 55301, 55853, 56621, 56717, 56901, - 5813, 58437, 12493, 15365, 15989, 17829, 18229, 19341, - 21013, 21357, 22925, 24885, 26053, 27581, 28221, 28485, - 30605, 30613, 30789, 35437, 36285, 37189, 3941, 41797, - 4269, 42901, 43293, 44645, 45221, 46893, 4893, 50301, - 50325, 5189, 52109, 53517, 54053, 54485, 5525, 55949, - 56973, 59069, 59421, 60733, 61253, 6421, 6701, 6709, - 7101, 8669, 15797, 19221, 19837, 20133, 20957, 21293, - 21461, 22461, 29085, 29861, 30869, 34973, 36469, 37565, - 38125, 38829, 39469, 40061, 40117, 44093, 47429, 48341, - 50597, 51757, 5541, 57629, 58405, 59621, 59693, 59701, - 61837, 7061, 10421, 11949, 15405, 20861, 25397, 25509, - 25893, 26037, 28629, 28869, 29605, 30213, 34205, 35637, - 36365, 37285, 3773, 39117, 4021, 41061, 42653, 44509, - 4461, 44829, 4725, 5125, 52269, 56469, 59085, 5917, - 60973, 8349, 17725, 18637, 19773, 20293, 21453, 22533, - 24285, 26333, 26997, 31501, 34541, 34805, 37509, 38477, - 41333, 44125, 46285, 46997, 47637, 48173, 4925, 50253, - 50381, 50917, 51205, 51325, 52165, 52229, 5253, 5269, - 53509, 56253, 56341, 5821, 58373, 60301, 61653, 61973, - 62373, 8397, 11981, 14341, 14509, 15077, 22261, 22429, - 24261, 28165, 28685, 30661, 34021, 34445, 39149, 3917, - 43013, 43317, 44053, 44101, 4533, 49541, 49981, 5277, - 54477, 56357, 57261, 57765, 58573, 59061, 60197, 61197, - 62189, 7725, 8477, 9565, 10229, 11437, 14613, 14709, - 16813, 20029, 20677, 31445, 3165, 31957, 3229, 33541, - 36645, 3805, 38973, 3965, 4029, 44293, 44557, 46245, - 48917, 4909, 51749, 53709, 55733, 56445, 5925, 6093, - 61053, 62637, 8661, 9109, 10821, 11389, 13813, 14325, - 15501, 16149, 18845, 22669, 26437, 29869, 31837, 33709, - 33973, 34173, 3677, 3877, 3981, 39885, 42117, 4421, - 44221, 44245, 44693, 46157, 47309, 5005, 51461, 52037, - 55333, 55693, 56277, 58949, 6205, 62141, 62469, 6293, - 10101, 12509, 14029, 17997, 20469, 21149, 25221, 27109, - 2773, 2877, 29405, 31493, 31645, 4077, 42005, 42077, - 42469, 42501, 44013, 48653, 49349, 4997, 50101, 55405, - 56957, 58037, 59429, 60749, 61797, 62381, 62837, 6605, - 10541, 23981, 24533, 2701, 27333, 27341, 31197, 33805, - 3621, 37381, 3749, 3829, 38533, 42613, 44381, 45901, - 48517, 51269, 57725, 59461, 60045, 62029, 13805, 14013, - 15461, 16069, 16157, 18573, 2309, 23501, 28645, 3077, - 31541, 36357, 36877, 3789, 39429, 39805, 47685, 47949, - 49413, 5485, 56757, 57549, 57805, 58317, 59549, 62213, - 62613, 62853, 62933, 8909, 12941, 16677, 20333, 21541, - 24429, 26077, 26421, 2885, 31269, 33381, 3661, 40925, - 42925, 45173, 4525, 4709, 53133, 55941, 57413, 57797, - 62125, 62237, 62733, 6773, 12317, 13197, 16533, 16933, - 18245, 2213, 2477, 29757, 33293, 35517, 40133, 40749, - 4661, 49941, 62757, 7853, 8149, 8573, 11029, 13421, - 21549, 22709, 22725, 24629, 2469, 26125, 2669, 34253, - 36709, 41013, 45597, 46637, 52285, 52333, 54685, 59013, - 60997, 61189, 61981, 62605, 62821, 7077, 7525, 8781, - 10861, 15277, 2205, 22077, 28517, 28949, 32109, 33493, - 4661, 49941, 62757, 7853, 8149, 8573, 11029, 13421, - 21549, 22709, 22725, 24629, 2469, 26125, 2669, 34253, - 36709, 41013, 45597, 46637, 52285, 52333, 54685, 59013, - 60997, 61189, 61981, 62605, 62821, 7077, 7525, 8781, - 10861, 15277, 2205, 22077, 28517, 28949, 32109, 33493, - 3685, 39197, 39869, 42621, 44997, 48565, 5221, 57381, - 61749, 62317, 63245, 63381, 23149, 2549, 28661, 31653, - 33885, 36341, 37053, 39517, 42805, 45853, 48997, 59349, - 60053, 62509, 63069, 6525, 1893, 20181, 2365, 24893, - 27397, 31357, 32277, 33357, 34437, 36677, 37661, 43469, - 43917, 50997, 53869, 5653, 13221, 16741, 17893, 2157, - 28653, 31789, 35301, 35821, 61613, 62245, 12405, 14517, - 17453, 18421, 3149, 3205, 40341, 4109, 43941, 46869, - 48837, 50621, 57405, 60509, 62877, 8157, 12933, 12957, - 16501, 19533, 3461, 36829, 52357, 58189, 58293, 63053, - 17109, 1933, 32157, 37701, 59005, 61621, 13029, 15085, - 16493, 32317, 35093, 5061, 51557, 62221, 20765, 24613, - 2629, 30861, 33197, 33749, 35365, 37933, 40317, 48045, - 56229, 61157, 63797, 7917, 17965, 1917, 1973, 20301, - 2253, 33157, 58629, 59861, 61085, 63909, 8141, 9221, - 14757, 1581, 21637, 26557, 33869, 34285, 35733, 40933, - 42517, 43501, 53653, 61885, 63805, 7141, 21653, 54973, - 31189, 60061, 60341, 63357, 16045, 2053, 26069, 33997, - 43901, 54565, 63837, 8949, 17909, 18693, 32349, 33125, - 37293, 48821, 49053, 51309, 64037, 7117, 1445, 20405, - 23085, 26269, 26293, 27349, 32381, 33141, 34525, 36461, - 37581, 43525, 4357, 43877, 5069, 55197, 63965, 9845, - 12093, 2197, 2229, 32165, 33469, 40981, 42397, 8749, - 10853, 1453, 18069, 21693, 30573, 36261, 37421, 42533 -}; - -#define NSID_MULT_TABLE_SIZE \ - ((sizeof nsid_multiplier_table)/(sizeof nsid_multiplier_table[0])) -#define NSID_RANGE_MASK (NSID_LOOKAHEAD - 1) -#define NSID_POOL_MASK 0xFFFF /* used to wrap the pool index */ -#define NSID_SHUFFLE_ONLY 1 -#define NSID_USE_POOL 2 - -static isc_uint16_t -nsid_next(dns_nsid_t *nsid) { - isc_uint16_t id, compressed_hash; - isc_uint16_t j; - - compressed_hash = ((nsid_hash_state >> 16) ^ - (nsid_hash_state)) & 0xFFFF; - - if (nsid->nsid_usepool) { - isc_uint16_t pick; - - pick = compressed_hash & NSID_RANGE_MASK; - pick = (nsid->nsid_state + pick) & NSID_POOL_MASK; - id = nsid->nsid_pool[pick]; - if (pick != 0) { - /* Swap two IDs to stir the pool */ - nsid->nsid_pool[pick] = - nsid->nsid_pool[nsid->nsid_state]; - nsid->nsid_pool[nsid->nsid_state] = id; - } - - /* increment the base pointer into the pool */ - if (nsid->nsid_state == 65535) - nsid->nsid_state = 0; - else - nsid->nsid_state++; - } else { - /* - * This is the original Algorithm B - * j = ((u_long) NSID_SHUFFLE_TABLE_SIZE * nsid_state2) >> 16; - * - * We'll perturb it with some random stuff ... - */ - j = ((isc_uint32_t) NSID_SHUFFLE_TABLE_SIZE * - (nsid->nsid_state2 ^ compressed_hash)) >> 16; - nsid->nsid_state2 = id = nsid->nsid_vtable[j]; - nsid->nsid_state = (((isc_uint32_t) nsid->nsid_a1 * nsid->nsid_state) + - nsid->nsid_c1) & 0xFFFF; - nsid->nsid_vtable[j] = nsid->nsid_state; - } - - /* Now lets obfuscate ... */ - id = (((isc_uint32_t) nsid->nsid_a2 * id) + nsid->nsid_c2) & 0xFFFF; - id = (((isc_uint32_t) nsid->nsid_a3 * id) + nsid->nsid_c3) & 0xFFFF; - - return (id); -} - -static isc_result_t -nsid_init(isc_mem_t *mctx, dns_nsid_t *nsid, isc_boolean_t usepool) { - isc_time_t now; - pid_t mypid; - isc_uint16_t a1ndx, a2ndx, a3ndx, c1ndx, c2ndx, c3ndx; - int i; - - isc_time_now(&now); - mypid = getpid(); - - /* Initialize the state */ - memset(nsid, 0, sizeof(*nsid)); - nsid_hash(&now, sizeof now); - nsid_hash(&mypid, sizeof mypid); - - /* - * Select our random number generators and initial seed. - * We could really use more random bits at this point, - * but we'll try to make a silk purse out of a sows ear ... - */ - /* generator 1 */ - a1ndx = ((isc_uint32_t) NSID_MULT_TABLE_SIZE * - (nsid_hash_state & 0xFFFF)) >> 16; - nsid->nsid_a1 = nsid_multiplier_table[a1ndx]; - c1ndx = (nsid_hash_state >> 9) & 0x7FFF; - nsid->nsid_c1 = 2 * c1ndx + 1; - - /* generator 2, distinct from 1 */ - a2ndx = ((isc_uint32_t) (NSID_MULT_TABLE_SIZE - 1) * - ((nsid_hash_state >> 10) & 0xFFFF)) >> 16; - if (a2ndx >= a1ndx) - a2ndx++; - nsid->nsid_a2 = nsid_multiplier_table[a2ndx]; - c2ndx = nsid_hash_state % 32767; - if (c2ndx >= c1ndx) - c2ndx++; - nsid->nsid_c2 = 2*c2ndx + 1; - - /* generator 3, distinct from 1 and 2 */ - a3ndx = ((isc_uint32_t) (NSID_MULT_TABLE_SIZE - 2) * - ((nsid_hash_state >> 20) & 0xFFFF)) >> 16; - if (a3ndx >= a1ndx || a3ndx >= a2ndx) - a3ndx++; - if (a3ndx >= a1ndx && a3ndx >= a2ndx) - a3ndx++; - nsid->nsid_a3 = nsid_multiplier_table[a3ndx]; - c3ndx = nsid_hash_state % 32766; - if (c3ndx >= c1ndx || c3ndx >= c2ndx) - c3ndx++; - if (c3ndx >= c1ndx && c3ndx >= c2ndx) - c3ndx++; - nsid->nsid_c3 = 2*c3ndx + 1; - - nsid->nsid_state = - ((nsid_hash_state >> 16) ^ (nsid_hash_state)) & 0xFFFF; - - nsid->nsid_usepool = usepool; - if (nsid->nsid_usepool) { - nsid->nsid_pool = isc_mem_get(mctx, 0x10000 * sizeof(isc_uint16_t)); - if (nsid->nsid_pool == NULL) - return (ISC_R_NOMEMORY); - for (i = 0; ; i++) { - nsid->nsid_pool[i] = nsid->nsid_state; - nsid->nsid_state = - (((u_long) nsid->nsid_a1 * nsid->nsid_state) + - nsid->nsid_c1) & 0xFFFF; - if (i == 0xFFFF) - break; - } - } else { - nsid->nsid_vtable = isc_mem_get(mctx, NSID_SHUFFLE_TABLE_SIZE * - (sizeof(isc_uint16_t)) ); - if (nsid->nsid_vtable == NULL) - return (ISC_R_NOMEMORY); - - for (i = 0; i < NSID_SHUFFLE_TABLE_SIZE; i++) { - nsid->nsid_vtable[i] = nsid->nsid_state; - nsid->nsid_state = - (((isc_uint32_t) nsid->nsid_a1 * nsid->nsid_state) + - nsid->nsid_c1) & 0xFFFF; - } - nsid->nsid_state2 = nsid->nsid_state; - } - return (ISC_R_SUCCESS); -} - -static void -nsid_destroy(isc_mem_t *mctx, dns_nsid_t *nsid) { - if (nsid->nsid_usepool) - isc_mem_put(mctx, nsid->nsid_pool, - 0x10000 * sizeof(isc_uint16_t)); - else - isc_mem_put(mctx, nsid->nsid_vtable, - NSID_SHUFFLE_TABLE_SIZE * (sizeof(isc_uint16_t)) ); - memset(nsid, 0, sizeof(*nsid)); -} - -void -dns_dispatch_hash(void *data, size_t len) { - nsid_hash(data, len); -} diff --git a/lib/dns/include/dns/dispatch.h b/lib/dns/include/dns/dispatch.h index 29dd7f8063..76b9ec85d0 100644 --- a/lib/dns/include/dns/dispatch.h +++ b/lib/dns/include/dns/dispatch.h @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: dispatch.h,v 1.45.2.2.4.5 2007/08/28 07:19:14 tbox Exp $ */ +/* $Id: dispatch.h,v 1.45.2.2.4.6 2008/05/22 20:46:35 each Exp $ */ #ifndef DNS_DISPATCH_H #define DNS_DISPATCH_H 1 @@ -112,6 +112,9 @@ struct dns_dispatchevent { * _MAKEQUERY * The dispatcher can be used to issue queries to other servers, and * accept replies from them. + * + * _RANDOMPORT + * Allocate UDP port randomly. */ #define DNS_DISPATCHATTR_PRIVATE 0x00000001U #define DNS_DISPATCHATTR_TCP 0x00000002U @@ -121,6 +124,7 @@ struct dns_dispatchevent { #define DNS_DISPATCHATTR_NOLISTEN 0x00000020U #define DNS_DISPATCHATTR_MAKEQUERY 0x00000040U #define DNS_DISPATCHATTR_CONNECTED 0x00000080U +#define DNS_DISPATCHATTR_RANDOMPORT 0x00000100U isc_result_t dns_dispatchmgr_create(isc_mem_t *mctx, isc_entropy_t *entropy, @@ -437,13 +441,6 @@ dns_dispatch_importrecv(dns_dispatch_t *disp, isc_event_t *event); * event != NULL */ -void -dns_dispatch_hash(void *data, size_t len); -/*%< - * Feed 'data' to the dispatch query id generator where 'len' is the size - * of 'data'. - */ - ISC_LANG_ENDDECLS #endif /* DNS_DISPATCH_H */ diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c index 2b80651bb5..1bba103b6d 100644 --- a/lib/dns/resolver.c +++ b/lib/dns/resolver.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: resolver.c,v 1.218.2.18.4.78 2008/04/28 05:35:45 marka Exp $ */ +/* $Id: resolver.c,v 1.218.2.18.4.79 2008/05/22 20:46:35 each Exp $ */ #include @@ -1070,17 +1070,50 @@ fctx_query(fetchctx_t *fctx, dns_adbaddrinfo_t *addrinfo, * A dispatch will be created once the connect succeeds. */ } else { + isc_sockaddr_t localaddr; + unsigned int attrs, attrmask; + dns_dispatch_t *disp_base; + + attrs = 0; + attrs |= DNS_DISPATCHATTR_UDP; + attrs |= DNS_DISPATCHATTR_RANDOMPORT; + + attrmask = 0; + attrmask |= DNS_DISPATCHATTR_UDP; + attrmask |= DNS_DISPATCHATTR_TCP; + attrmask |= DNS_DISPATCHATTR_IPV4; + attrmask |= DNS_DISPATCHATTR_IPV6; + switch (isc_sockaddr_pf(&addrinfo->sockaddr)) { - case PF_INET: - dns_dispatch_attach(res->dispatchv4, &query->dispatch); + case AF_INET: + disp_base = res->dispatchv4; + attrs |= DNS_DISPATCHATTR_IPV4; break; - case PF_INET6: - dns_dispatch_attach(res->dispatchv6, &query->dispatch); + case AF_INET6: + disp_base = res->dispatchv6; + attrs |= DNS_DISPATCHATTR_IPV6; break; default: result = ISC_R_NOTIMPLEMENTED; goto cleanup_query; } + + result = dns_dispatch_getlocaladdress(disp_base, &localaddr); + if (result != ISC_R_SUCCESS) + goto cleanup_query; + if (isc_sockaddr_getport(&localaddr) == 0) { + result = dns_dispatch_getudp(res->dispatchmgr, + res->socketmgr, + res->taskmgr, + &localaddr, + 4096, 1000, 32768, + 16411, 16433, + attrs, attrmask, + &query->dispatch); + if (result != ISC_R_SUCCESS) + goto cleanup_query; + } else + dns_dispatch_attach(disp_base, &query->dispatch); /* * We should always have a valid dispatcher here. If we * don't support a protocol family, then its dispatcher From ce6521e13de6a9e768b40c32db6835ca67413d65 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Thu, 22 May 2008 23:18:23 +0000 Subject: [PATCH 087/137] auto update --- doc/private/branches | 2 ++ 1 file changed, 2 insertions(+) diff --git a/doc/private/branches b/doc/private/branches index f6d10326ae..4ef29add3b 100644 --- a/doc/private/branches +++ b/doc/private/branches @@ -160,9 +160,11 @@ v9_3_0base active // security fixes 9.3.0 only v9_3_2_patch active // security fixes 9.3.2 only v9_3_4-cisco active v9_3_4_patch active // security fixes 9.3.4 only +v9_3_5_P1 new each // 2008-05-22 20:42 +0000 v9_4 active v9_4_1_P1_lruttl active v9_4_1_patch active // security fixes 9.4.1 only +v9_4_2_P1 new each // 2008-05-22 21:12 +0000 v9_5 new marka // 2008-01-02 04:47 +0000 From 2adff8836c0072ccd138db9af651c6724341c886 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Thu, 22 May 2008 23:30:06 +0000 Subject: [PATCH 088/137] newcopyrights --- util/copyrights | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/util/copyrights b/util/copyrights index 261cd8b31f..43a5ff7039 100644 --- a/util/copyrights +++ b/util/copyrights @@ -83,7 +83,7 @@ ./bin/named/Makefile.in MAKE 1998,1999,2000,2001,2002,2003,2004,2007 ./bin/named/aclconf.c C 1999,2000,2001,2002,2003,2004,2005,2006,2007 ./bin/named/builtin.c C 2001,2002,2003,2004 -./bin/named/client.c C 1999,2000,2001,2002,2003,2004,2005,2006,2007 +./bin/named/client.c C 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008 ./bin/named/config.c C 2001,2002,2003,2004,2006,2007 ./bin/named/control.c C 2001,2002,2003,2004,2005,2007 ./bin/named/controlconf.c C 2001,2002,2003,2004,2006,2008 @@ -1660,7 +1660,7 @@ ./lib/dns/dbiterator.c C 1999,2000,2001,2004 ./lib/dns/dbtable.c C 1999,2000,2001,2003,2004,2007 ./lib/dns/diff.c C 2000,2001,2002,2003,2004 -./lib/dns/dispatch.c C 1999,2000,2001,2002,2003,2004,2006,2007 +./lib/dns/dispatch.c C 1999,2000,2001,2002,2003,2004,2006,2007,2008 ./lib/dns/dnssec.c C 1999,2000,2001,2002,2003,2004,2006,2007 ./lib/dns/ds.c C 2002,2003,2004 ./lib/dns/dst_api.c C.NAI 1999,2000,2001,2002,2003,2004,2006 @@ -1693,7 +1693,7 @@ ./lib/dns/include/dns/dbiterator.h C 1999,2000,2001,2004 ./lib/dns/include/dns/dbtable.h C 1999,2000,2001,2004 ./lib/dns/include/dns/diff.h C 2000,2001,2003,2004,2007 -./lib/dns/include/dns/dispatch.h C 1999,2000,2001,2002,2003,2004,2007 +./lib/dns/include/dns/dispatch.h C 1999,2000,2001,2002,2003,2004,2007,2008 ./lib/dns/include/dns/dnssec.h C 1999,2000,2001,2002,2003,2004,2007 ./lib/dns/include/dns/ds.h C 2002,2004 ./lib/dns/include/dns/events.h C 1999,2000,2001,2002,2003,2004,2007 From 5e12264e75160c1136a08db44ead45e404a6c553 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Thu, 22 May 2008 23:45:34 +0000 Subject: [PATCH 089/137] update copyright notice --- bin/named/client.c | 44 +++++++++++++++++----------------- lib/dns/dispatch.c | 18 +++++++------- lib/dns/include/dns/dispatch.h | 14 +++++------ 3 files changed, 38 insertions(+), 38 deletions(-) diff --git a/bin/named/client.c b/bin/named/client.c index 3b92c51507..9c22b1fe56 100644 --- a/bin/named/client.c +++ b/bin/named/client.c @@ -1,5 +1,5 @@ /* - * Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC") + * Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC") * Copyright (C) 1999-2003 Internet Software Consortium. * * Permission to use, copy, modify, and/or distribute this software for any @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: client.c,v 1.176.2.13.4.39 2008/05/22 20:46:34 each Exp $ */ +/* $Id: client.c,v 1.176.2.13.4.40 2008/05/22 23:45:34 tbox Exp $ */ #include @@ -256,7 +256,7 @@ exit_check(ns_client_t *client) { * * Keep the view attached until any outstanding updates complete. */ - if (client->nupdates == 0 && + if (client->nupdates == 0 && client->newstate == NS_CLIENTSTATE_FREED && client->view != NULL) dns_view_detach(&client->view); @@ -786,7 +786,7 @@ client_sendpkg(ns_client_t *client, isc_buffer_t *buffer) { isc_netaddr_fromsockaddr(&netaddr, &client->peeraddr); if (ns_g_server->blackholeacl != NULL && dns_acl_match(&netaddr, NULL, - ns_g_server->blackholeacl, + ns_g_server->blackholeacl, &ns_g_server->aclenv, &match, NULL) == ISC_R_SUCCESS && match > 0) @@ -803,7 +803,7 @@ client_sendpkg(ns_client_t *client, isc_buffer_t *buffer) { isc_buffer_usedregion(buffer, &r); CTRACE("sendto"); - + result = isc_socket_sendto2(socket, &r, client->task, address, pktinfo, client->sendevent, sockflags); @@ -1077,8 +1077,8 @@ ns_client_error(ns_client_t *client, isc_result_t result) { /* * FORMERR loop avoidance: If we sent a FORMERR message * with the same ID to the same client less than two - * seconds ago, assume that we are in an infinite error - * packet dialog with a server for some protocol whose + * seconds ago, assume that we are in an infinite error + * packet dialog with a server for some protocol whose * error responses look enough like DNS queries to * elicit a FORMERR response. Drop a packet to break * the loop. @@ -1443,7 +1443,7 @@ client_request(isc_task_t *task, isc_event_t *event) { * For IPv6 UDP queries, we get this from the pktinfo structure (if * supported). * If all the attempts fail (this can happen due to memory shortage, - * etc), we regard this as an error for safety. + * etc), we regard this as an error for safety. */ if ((client->interface->flags & NS_INTERFACEFLAG_ANYADDR) == 0) isc_netaddr_fromsockaddr(&destaddr, &client->interface->addr); @@ -1504,7 +1504,7 @@ client_request(isc_task_t *task, isc_event_t *event) { view); if (sigresult == ISC_R_SUCCESS) tsig = client->message->tsigname; - + if (allowed(&netaddr, tsig, view->matchclients) && allowed(&destaddr, tsig, view->matchdestinations) && !((client->message->flags & DNS_MESSAGEFLAG_RD) @@ -1635,7 +1635,7 @@ client_request(isc_task_t *task, isc_event_t *event) { ns_client_log(client, DNS_LOGCATEGORY_SECURITY, NS_LOGMODULE_CLIENT, ISC_LOG_DEBUG(3), ra ? "recursion available" : - "recursion not available"); + "recursion not available"); /* * Dispatch the request. @@ -1949,7 +1949,7 @@ client_newconn(isc_task_t *task, isc_event_t *event) { if (ns_g_server->blackholeacl != NULL && dns_acl_match(&netaddr, NULL, - ns_g_server->blackholeacl, + ns_g_server->blackholeacl, &ns_g_server->aclenv, &match, NULL) == ISC_R_SUCCESS && match > 0) @@ -2319,7 +2319,7 @@ ns_client_checkacl(ns_client_t *client, isc_result_t result = ns_client_checkaclsilent(client, acl, default_allow); - if (result == ISC_R_SUCCESS) + if (result == ISC_R_SUCCESS) ns_client_log(client, DNS_LOGCATEGORY_SECURITY, NS_LOGMODULE_CLIENT, ISC_LOG_DEBUG(3), "%s approved", opname); @@ -2375,16 +2375,16 @@ ns_client_log(ns_client_t *client, isc_logcategory_t *category, void ns_client_aclmsg(const char *msg, dns_name_t *name, dns_rdatatype_t type, - dns_rdataclass_t rdclass, char *buf, size_t len) + dns_rdataclass_t rdclass, char *buf, size_t len) { - char namebuf[DNS_NAME_FORMATSIZE]; - char typebuf[DNS_RDATATYPE_FORMATSIZE]; - char classbuf[DNS_RDATACLASS_FORMATSIZE]; + char namebuf[DNS_NAME_FORMATSIZE]; + char typebuf[DNS_RDATATYPE_FORMATSIZE]; + char classbuf[DNS_RDATACLASS_FORMATSIZE]; - dns_name_format(name, namebuf, sizeof(namebuf)); - dns_rdatatype_format(type, typebuf, sizeof(typebuf)); - dns_rdataclass_format(rdclass, classbuf, sizeof(classbuf)); - (void)snprintf(buf, len, "%s '%s/%s/%s'", msg, namebuf, typebuf, + dns_name_format(name, namebuf, sizeof(namebuf)); + dns_rdatatype_format(type, typebuf, sizeof(typebuf)); + dns_rdataclass_format(rdclass, classbuf, sizeof(classbuf)); + (void)snprintf(buf, len, "%s '%s/%s/%s'", msg, namebuf, typebuf, classbuf); } @@ -2412,7 +2412,7 @@ ns_client_dumpmessage(ns_client_t *client, const char *reason) { isc_mem_put(client->mctx, buf, len); len += 1024; } else if (result == ISC_R_SUCCESS) - ns_client_log(client, NS_LOGCATEGORY_UNMATCHED, + ns_client_log(client, NS_LOGCATEGORY_UNMATCHED, NS_LOGMODULE_CLIENT, ISC_LOG_DEBUG(1), "%s\n%.*s", reason, (int)isc_buffer_usedlength(&buffer), @@ -2432,7 +2432,7 @@ ns_client_dumprecursing(FILE *f, ns_clientmgr_t *manager) { const char *sep; REQUIRE(VALID_MANAGER(manager)); - + LOCK(&manager->lock); client = ISC_LIST_HEAD(manager->recursing); while (client != NULL) { diff --git a/lib/dns/dispatch.c b/lib/dns/dispatch.c index 47aa7d3191..fe03bf1ab0 100644 --- a/lib/dns/dispatch.c +++ b/lib/dns/dispatch.c @@ -1,5 +1,5 @@ /* - * Copyright (C) 2004, 2006, 2007 Internet Systems Consortium, Inc. ("ISC") + * Copyright (C) 2004, 2006-2008 Internet Systems Consortium, Inc. ("ISC") * Copyright (C) 1999-2003 Internet Software Consortium. * * Permission to use, copy, modify, and/or distribute this software for any @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: dispatch.c,v 1.101.2.6.2.22 2008/05/22 20:46:35 each Exp $ */ +/* $Id: dispatch.c,v 1.101.2.6.2.23 2008/05/22 23:45:34 tbox Exp $ */ #include @@ -708,7 +708,7 @@ udp_recv(isc_task_t *task, isc_event_t *ev_in) { isc_netaddr_fromsockaddr(&netaddr, &ev->address); if (disp->mgr->blackhole != NULL && dns_acl_match(&netaddr, NULL, disp->mgr->blackhole, - NULL, &match, NULL) == ISC_R_SUCCESS && + NULL, &match, NULL) == ISC_R_SUCCESS && match > 0) { if (isc_log_wouldlog(dns_lctx, LVL(10))) { @@ -761,7 +761,7 @@ udp_recv(isc_task_t *task, isc_event_t *ev_in) { if (resp == NULL) { free_buffer(disp, ev->region.base, ev->region.length); goto unlock; - } + } /* * Now that we have the original dispatch the query was sent @@ -771,7 +771,7 @@ udp_recv(isc_task_t *task, isc_event_t *ev_in) { if (disp != resp->disp) { isc_sockaddr_t a1; isc_sockaddr_t a2; - + /* * Check that the socket types and ports match. */ @@ -784,11 +784,11 @@ udp_recv(isc_task_t *task, isc_event_t *ev_in) { /* * If both dispatches are bound to an address then fail as - * the addresses can't be equal (enforced by the IP stack). + * the addresses can't be equal (enforced by the IP stack). * * Note under Linux a packet can be sent out via IPv4 socket * and the response be received via a IPv6 socket. - * + * * Requests sent out via IPv6 should always come back in * via IPv6. */ @@ -909,7 +909,7 @@ tcp_recv(isc_task_t *task, isc_event_t *ev_in) { switch (tcpmsg->result) { case ISC_R_CANCELED: break; - + case ISC_R_EOF: dispatch_log(disp, LVL(90), "shutting down on EOF"); do_cancel(disp); @@ -2410,7 +2410,7 @@ dns_dispatch_importrecv(dns_dispatch_t *disp, isc_event_t *event) { newsevent->timestamp = sevent->timestamp; newsevent->pktinfo = sevent->pktinfo; newsevent->attributes = sevent->attributes; - + isc_task_send(disp->task, ISC_EVENT_PTR(&newsevent)); } diff --git a/lib/dns/include/dns/dispatch.h b/lib/dns/include/dns/dispatch.h index 76b9ec85d0..5d44b85035 100644 --- a/lib/dns/include/dns/dispatch.h +++ b/lib/dns/include/dns/dispatch.h @@ -1,5 +1,5 @@ /* - * Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC") + * Copyright (C) 2004, 2007, 2008 Internet Systems Consortium, Inc. ("ISC") * Copyright (C) 1999-2003 Internet Software Consortium. * * Permission to use, copy, modify, and/or distribute this software for any @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: dispatch.h,v 1.45.2.2.4.6 2008/05/22 20:46:35 each Exp $ */ +/* $Id: dispatch.h,v 1.45.2.2.4.7 2008/05/22 23:45:34 tbox Exp $ */ #ifndef DNS_DISPATCH_H #define DNS_DISPATCH_H 1 @@ -185,7 +185,7 @@ dns_dispatchmgr_getblackhole(dns_dispatchmgr_t *mgr); void dns_dispatchmgr_setblackportlist(dns_dispatchmgr_t *mgr, - dns_portlist_t *portlist); + dns_portlist_t *portlist); /* * Sets a list of UDP ports that won't be used when creating a udp * dispatch with a wildcard port. @@ -365,7 +365,7 @@ dns_dispatch_removeresponse(dns_dispentry_t **resp, * "resp" != NULL and "*resp" contain a value previously allocated * by dns_dispatch_addresponse(); * - * May only be called from within the task given as the 'task' + * May only be called from within the task given as the 'task' * argument to dns_dispatch_addresponse() when allocating '*resp'. */ @@ -382,7 +382,7 @@ dns_dispatch_getsocket(dns_dispatch_t *disp); * The socket the dispatcher is using. */ -isc_result_t +isc_result_t dns_dispatch_getlocaladdress(dns_dispatch_t *disp, isc_sockaddr_t *addrp); /* * Return the local address for this dispatch. @@ -393,7 +393,7 @@ dns_dispatch_getlocaladdress(dns_dispatch_t *disp, isc_sockaddr_t *addrp); * addrp to be non null. * * Returns: - * ISC_R_SUCCESS + * ISC_R_SUCCESS * ISC_R_NOTIMPLEMENTED */ @@ -417,7 +417,7 @@ dns_dispatch_changeattributes(dns_dispatch_t *disp, * * new = (old & ~mask) | (attributes & mask) * - * This function has a side effect when DNS_DISPATCHATTR_NOLISTEN changes. + * This function has a side effect when DNS_DISPATCHATTR_NOLISTEN changes. * When the flag becomes off, the dispatch will start receiving on the * corresponding socket. When the flag becomes on, receive events on the * corresponding socket will be canceled. From 0bab451b04309721a76d0c7283d776cd217cc243 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Fri, 23 May 2008 01:20:47 +0000 Subject: [PATCH 090/137] regen --- doc/arm/Bv9ARM.ch06.html | 72 ++++++++++++++++-------------- doc/arm/Bv9ARM.ch07.html | 14 +++--- doc/arm/Bv9ARM.ch08.html | 18 ++++---- doc/arm/Bv9ARM.ch09.html | 94 ++++++++++++++++++++-------------------- doc/arm/Bv9ARM.html | 40 ++++++++--------- 5 files changed, 123 insertions(+), 115 deletions(-) diff --git a/doc/arm/Bv9ARM.ch06.html b/doc/arm/Bv9ARM.ch06.html index 5781bf4919..b8d4ce7893 100644 --- a/doc/arm/Bv9ARM.ch06.html +++ b/doc/arm/Bv9ARM.ch06.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -71,23 +71,23 @@ Usage
options Statement Definition and Usage
server Statement Grammar
server Statement Definition and Usage
-
trusted-keys Statement Grammar
-
trusted-keys Statement Definition +
trusted-keys Statement Grammar
+
trusted-keys Statement Definition and Usage
view Statement Grammar
-
view Statement Definition and Usage
+
view Statement Definition and Usage
zone Statement Grammar
-
zone Statement Definition and Usage
+
zone Statement Definition and Usage
-
Zone File
+
Zone File
Types of Resource Records and When to Use Them
-
Discussion of MX Records
+
Discussion of MX Records
Setting TTLs
-
Inverse Mapping in IPv4
-
Other Zone File Directives
-
BIND Master File Extension: the $GENERATE Directive
+
Inverse Mapping in IPv4
+
Other Zone File Directives
+
BIND Master File Extension: the $GENERATE Directive
@@ -1892,7 +1892,15 @@ IPv6, there is a separate query-source-v6 If address is * (asterisk) or is omitted, a wildcard IP address (INADDR_ANY) will be used. If port is * or is omitted, -a random unprivileged port will be used. The avoid-v4-udp-ports +a random unprivileged port number is picked up and will be +used for each query. +It is generally strongly discouraged to +specify a particular port for the +query-source or +query-source-v6 options; +it implicitly disables the use of randomized port numbers +and leads to insecure operation. +The avoid-v4-udp-ports and avoid-v6-udp-ports options can be used to prevent named from selecting certain ports. The defaults are:

query-source address * port *;
@@ -2075,7 +2083,7 @@ but applies to notify messages sent to IPv6 addresses.

-Bad UDP Port Lists

+Bad UDP Port Lists

avoid-v4-udp-ports and avoid-v6-udp-ports specify a list of IPv4 and IPv6 UDP ports that will not be used as system @@ -2088,7 +2096,7 @@ to query again.

-Operating System Resource Limits

+Operating System Resource Limits

The server's usage of many system resources can be limited. Scaled values are allowed when specifying resource limits. For example, 1G can be used instead of @@ -2132,7 +2140,7 @@ may use. The default is default.

-Server Resource Limits

+Server Resource Limits

The following options set limits on the server's resource consumption that are enforced internally by the server rather than the operating system.

@@ -2186,7 +2194,7 @@ silently raised.

-Periodic Task Intervals

+Periodic Task Intervals
cleaning-interval

The server will remove expired resource records @@ -2681,7 +2689,7 @@ For more details, see the description of

-trusted-keys Statement Grammar

+trusted-keys Statement Grammar
trusted-keys {
     string number number number string ;
     [ string number number number string ; [...]]
@@ -2690,7 +2698,7 @@ For more details, see the description of
 
 

-trusted-keys Statement Definition +trusted-keys Statement Definition and Usage

The trusted-keys statement defines @@ -2733,7 +2741,7 @@ For more details, see the description of

-view Statement Definition and Usage

+view Statement Definition and Usage

The view statement is a powerful new feature of BIND 9 that lets a name server answer a DNS query differently depending on who is asking. It is particularly useful for implementing @@ -2935,10 +2943,10 @@ zone zone_name [

-zone Statement Definition and Usage

+zone Statement Definition and Usage

-Zone Types

+Zone Types
@@ -3051,7 +3059,7 @@ from forwarders.

-Class

+Class

The zone's name may optionally be followed by a class. If a class is not specified, class IN (for Internet), is assumed. This is correct for the vast majority of cases.

@@ -3066,7 +3074,7 @@ in the mid-1970s. Zone data for it can be specified with the

-Zone Options

+Zone Options
allow-notify

See the description of @@ -3314,7 +3322,7 @@ name, the rules are checked for each existing record type.

-Zone File

+Zone File

Types of Resource Records and When to Use Them

@@ -3324,7 +3332,7 @@ Since the publication of RFC 1034, several new RRs have been identified and implemented in the DNS. These are also included.

-Resource Records

+Resource Records

A domain name identifies a node. Each node has a set of resource information, which may be empty. The set of resource information associated with a particular name is composed of @@ -3583,7 +3591,7 @@ used as "pointers" to other data in the DNS.

-Textual expression of RRs

+Textual expression of RRs

RRs are represented in binary form in the packets of the DNS protocol, and are usually represented in highly encoded form when stored in a name server or resolver. In the examples provided in @@ -3673,7 +3681,7 @@ each of a different class.

-Discussion of MX Records

+Discussion of MX Records

As described above, domain servers store information as a series of resource records, each of which contains a particular piece of information about a given domain name (which is usually, @@ -3790,7 +3798,7 @@ can be explicitly specified, for example, 1h30m.

-Inverse Mapping in IPv4

+Inverse Mapping in IPv4

Reverse name resolution (that is, translation from IP address to name) is achieved by means of the in-addr.arpa domain and PTR records. Entries in the in-addr.arpa domain are made in @@ -3828,7 +3836,7 @@ that the example is relative to the listed origin.

-Other Zone File Directives

+Other Zone File Directives

The Master File Format was initially defined in RFC 1035 and has subsequently been extended. While the Master File Format itself is class independent all records in a Master File must be of the same @@ -3837,7 +3845,7 @@ class.

and $TTL.

-The $ORIGIN Directive

+The $ORIGIN Directive

Syntax: $ORIGIN domain-name [ comment]

$ORIGIN sets the domain name that will @@ -3852,7 +3860,7 @@ WWW CNAME MAIN-SERVER

-The $INCLUDE Directive

+The $INCLUDE Directive

Syntax: $INCLUDE filename [ origin ] [ comment ]

@@ -3876,7 +3884,7 @@ This could be construed as a deviation from RFC 1035, a feature, or both.

-The $TTL Directive

+The $TTL Directive

Syntax: $TTL default-ttl [ comment ]

@@ -3887,7 +3895,7 @@ with undefined TTLs. Valid TTLs are of the range 0-2147483647 seconds.

-BIND Master File Extension: the $GENERATE Directive

+BIND Master File Extension: the $GENERATE Directive

Syntax: $GENERATE range lhs [ttl] [class] type rhs [ comment ]

$GENERATE is used to create a series of resource records that only differ from each other by an iterator. $GENERATE can diff --git a/doc/arm/Bv9ARM.ch07.html b/doc/arm/Bv9ARM.ch07.html index cfb405482e..5ce4b0ba61 100644 --- a/doc/arm/Bv9ARM.ch07.html +++ b/doc/arm/Bv9ARM.ch07.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -46,11 +46,11 @@

Table of Contents

Access Control Lists
-
Chroot and Setuid (for +
Chroot and Setuid (for UNIX servers)
-
The chroot Environment
-
Using the setuid Function
+
The chroot Environment
+
Using the setuid Function
Dynamic Update Security
@@ -102,7 +102,7 @@ see the AUSCERT advisory at

-Chroot and Setuid (for +Chroot and Setuid (for UNIX servers)

On UNIX servers, it is possible to run BIND in a chrooted environment (using the chroot() function) by specifying the "-t" @@ -117,7 +117,7 @@ user 202:

/usr/local/bin/named -u 202 -t /var/named

-The chroot Environment

+The chroot Environment

In order for a chroot environment to work properly in a particular directory (for example, /var/named), @@ -142,7 +142,7 @@ to set up things like

-Using the setuid Function

+Using the setuid Function

Prior to running the named daemon, use the touch utility (to change file access and modification times) or the chown utility (to diff --git a/doc/arm/Bv9ARM.ch08.html b/doc/arm/Bv9ARM.ch08.html index 1bb97711b5..3006927f62 100644 --- a/doc/arm/Bv9ARM.ch08.html +++ b/doc/arm/Bv9ARM.ch08.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -45,18 +45,18 @@

-Common Problems

+Common Problems

-It's not working; how can I figure out what's wrong?

+It's not working; how can I figure out what's wrong?

The best solution to solving installation and configuration issues is to take preventative measures by setting up logging files beforehand. The log files provide a @@ -66,7 +66,7 @@

-Incrementing and Changing the Serial Number

+Incrementing and Changing the Serial Number

Zone serial numbers are just numbers — they aren't date related. A lot of people set them to a number that @@ -89,7 +89,7 @@

-Where Can I Get Help?

+Where Can I Get Help?

The Internet Software Consortium (ISC) offers a wide range of support and service agreements for BIND and DHCP servers. Four levels of premium support are available and each level includes diff --git a/doc/arm/Bv9ARM.ch09.html b/doc/arm/Bv9ARM.ch09.html index 4d07ae9a1c..1e2204c382 100644 --- a/doc/arm/Bv9ARM.ch09.html +++ b/doc/arm/Bv9ARM.ch09.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -43,24 +43,24 @@

-Acknowledgments

+Acknowledgments

-A Brief History of the DNS and BIND +A Brief History of the DNS and BIND

Although the "official" beginning of the Domain Name System occurred in 1984 with the publication of RFC 920, the @@ -277,17 +277,17 @@ the number of the RFC). RFCs are also available via the Web at

-Bibliography

+Bibliography

Standards

-

[RFC974] C. Partridge. Mail Routing and the Domain System. January 1986.

+

[RFC974] C. Partridge. Mail Routing and the Domain System. January 1986.

-

[RFC1034] P.V. Mockapetris. Domain Names — Concepts and Facilities. November 1987.

+

[RFC1034] P.V. Mockapetris. Domain Names — Concepts and Facilities. November 1987.

-

[RFC1035] P. V. Mockapetris. Domain Names — Implementation and +

[RFC1035] P. V. Mockapetris. Domain Names — Implementation and Specification. November 1987.

@@ -295,22 +295,22 @@ Specification. November 1987.

Proposed Standards

-

[RFC2181] R., R. Bush Elz. Clarifications to the DNS Specification. July 1997.

+

[RFC2181] R., R. Bush Elz. Clarifications to the DNS Specification. July 1997.

-

[RFC2308] M. Andrews. Negative Caching of DNS Queries. March 1998.

+

[RFC2308] M. Andrews. Negative Caching of DNS Queries. March 1998.

-

[RFC1995] M. Ohta. Incremental Zone Transfer in DNS. August 1996.

+

[RFC1995] M. Ohta. Incremental Zone Transfer in DNS. August 1996.

-

[RFC1996] P. Vixie. A Mechanism for Prompt Notification of Zone Changes. August 1996.

+

[RFC1996] P. Vixie. A Mechanism for Prompt Notification of Zone Changes. August 1996.

-

[RFC2136] P. Vixie, S. Thomson, Y. Rekhter, and J. Bound. Dynamic Updates in the Domain Name System. April 1997.

+

[RFC2136] P. Vixie, S. Thomson, Y. Rekhter, and J. Bound. Dynamic Updates in the Domain Name System. April 1997.

-

[RFC2845] P. Vixie, O. Gudmundsson, D. Eastlake, 3rd, and B. Wellington. Secret Key Transaction Authentication for DNS (TSIG). May 2000.

+

[RFC2845] P. Vixie, O. Gudmundsson, D. Eastlake, 3rd, and B. Wellington. Secret Key Transaction Authentication for DNS (TSIG). May 2000.

@@ -321,85 +321,85 @@ Specification. November 1987.

RFCs are undergoing major revision by the IETF.

-

[RFC1886] S. Thomson and C. Huitema. DNS Extensions to support IP version 6. December 1995.

+

[RFC1886] S. Thomson and C. Huitema. DNS Extensions to support IP version 6. December 1995.

-

[RFC2065] D. Eastlake, 3rd and C. Kaufman. Domain Name System Security Extensions. January 1997.

+

[RFC2065] D. Eastlake, 3rd and C. Kaufman. Domain Name System Security Extensions. January 1997.

-

[RFC2137] D. Eastlake, 3rd. Secure Domain Name System Dynamic Update. April 1997.

+

[RFC2137] D. Eastlake, 3rd. Secure Domain Name System Dynamic Update. April 1997.

Other Important RFCs About DNS Implementation

-

[RFC1535] E. Gavron. A Security Problem and Proposed Correction With Widely Deployed DNS Software.. October 1993.

+

[RFC1535] E. Gavron. A Security Problem and Proposed Correction With Widely Deployed DNS Software.. October 1993.

-

[RFC1536] A. Kumar, J. Postel, C. Neuman, P. Danzig, and S. Miller. Common DNS Implementation Errors and Suggested Fixes. October 1993.

+

[RFC1536] A. Kumar, J. Postel, C. Neuman, P. Danzig, and S. Miller. Common DNS Implementation Errors and Suggested Fixes. October 1993.

-

[RFC1982] R. Elz and R. Bush. Serial Number Arithmetic. August 1996.

+

[RFC1982] R. Elz and R. Bush. Serial Number Arithmetic. August 1996.

Resource Record Types

-

[RFC1183] C.F. Everhart, L. A. Mamakos, R. Ullmann, and P. Mockapetris. New DNS RR Definitions. October 1990.

+

[RFC1183] C.F. Everhart, L. A. Mamakos, R. Ullmann, and P. Mockapetris. New DNS RR Definitions. October 1990.

-

[RFC1706] B. Manning and R. Colella. DNS NSAP Resource Records. October 1994.

+

[RFC1706] B. Manning and R. Colella. DNS NSAP Resource Records. October 1994.

-

[RFC2168] R. Daniel and M. Mealling. Resolution of Uniform Resource Identifiers using +

[RFC2168] R. Daniel and M. Mealling. Resolution of Uniform Resource Identifiers using the Domain Name System. June 1997.

-

[RFC1876] C. Davis, P. Vixie, T., and I. Dickinson. A Means for Expressing Location Information in the Domain +

[RFC1876] C. Davis, P. Vixie, T., and I. Dickinson. A Means for Expressing Location Information in the Domain Name System. January 1996.

-

[RFC2052] A. Gulbrandsen and P. Vixie. A DNS RR for Specifying the Location of +

[RFC2052] A. Gulbrandsen and P. Vixie. A DNS RR for Specifying the Location of Services.. October 1996.

-

[RFC2163] A. Allocchio. Using the Internet DNS to Distribute MIXER +

[RFC2163] A. Allocchio. Using the Internet DNS to Distribute MIXER Conformant Global Address Mapping. January 1998.

-

[RFC2230] R. Atkinson. Key Exchange Delegation Record for the DNS. October 1997.

+

[RFC2230] R. Atkinson. Key Exchange Delegation Record for the DNS. October 1997.

DNS and the Internet

-

[RFC1101] P. V. Mockapetris. DNS Encoding of Network Names and Other Types. April 1989.

+

[RFC1101] P. V. Mockapetris. DNS Encoding of Network Names and Other Types. April 1989.

-

[RFC1123] Braden. Requirements for Internet Hosts - Application and Support. October 1989.

+

[RFC1123] Braden. Requirements for Internet Hosts - Application and Support. October 1989.

-

[RFC1591] J. Postel. Domain Name System Structure and Delegation. March 1994.

+

[RFC1591] J. Postel. Domain Name System Structure and Delegation. March 1994.

-

[RFC2317] H. Eidnes, G. de Groot, and P. Vixie. Classless IN-ADDR.ARPA Delegation. March 1998.

+

[RFC2317] H. Eidnes, G. de Groot, and P. Vixie. Classless IN-ADDR.ARPA Delegation. March 1998.

DNS Operations

-

[RFC1537] P. Beertema. Common DNS Data File Configuration Errors. October 1993.

+

[RFC1537] P. Beertema. Common DNS Data File Configuration Errors. October 1993.

-

[RFC1912] D. Barr. Common DNS Operational and Configuration Errors. February 1996.

+

[RFC1912] D. Barr. Common DNS Operational and Configuration Errors. February 1996.

-

[RFC2010] B. Manning and P. Vixie. Operational Criteria for Root Name Servers.. October 1996.

+

[RFC2010] B. Manning and P. Vixie. Operational Criteria for Root Name Servers.. October 1996.

-

[RFC2219] M. Hamilton and R. Wright. Use of DNS Aliases for Network Services.. October 1997.

+

[RFC2219] M. Hamilton and R. Wright. Use of DNS Aliases for Network Services.. October 1997.

@@ -410,28 +410,28 @@ Conformant Global Address Mapping. January 1998 DNS-related, are not concerned with implementing software.

-

[RFC1464] R. Rosenbaum. Using the Domain Name System To Store Arbitrary String Attributes. May 1993.

+

[RFC1464] R. Rosenbaum. Using the Domain Name System To Store Arbitrary String Attributes. May 1993.

-

[RFC1713] A. Romao. Tools for DNS Debugging. November 1994.

+

[RFC1713] A. Romao. Tools for DNS Debugging. November 1994.

-

[RFC1794] T. Brisco. DNS Support for Load Balancing. April 1995.

+

[RFC1794] T. Brisco. DNS Support for Load Balancing. April 1995.

-

[RFC2240] O. Vaughan. A Legal Basis for Domain Name Allocation. November 1997.

+

[RFC2240] O. Vaughan. A Legal Basis for Domain Name Allocation. November 1997.

-

[RFC2345] J. Klensin, T. Wolf, and G. Oglesby. Domain Names and Company Name Retrieval. May 1998.

+

[RFC2345] J. Klensin, T. Wolf, and G. Oglesby. Domain Names and Company Name Retrieval. May 1998.

-

[RFC2352] O. Vaughan. A Convention For Using Legal Names as Domain Names. May 1998.

+

[RFC2352] O. Vaughan. A Convention For Using Legal Names as Domain Names. May 1998.

Obsolete and Unimplemented Experimental RRs

-

[RFC1712] C. Farrell, M. Schulze, S. Pleitner, and D. Baldoni. DNS Encoding of Geographical +

[RFC1712] C. Farrell, M. Schulze, S. Pleitner, and D. Baldoni. DNS Encoding of Geographical Location. November 1994.

@@ -451,14 +451,14 @@ after which they are deleted unless updated by their authors.

-Other Documents About BIND +Other Documents About BIND

-Bibliography

+Bibliography
-

Paul Albitz and Cricket Liu. DNS and BIND. Copyright © 1998 Sebastopol, CA: O'Reilly and Associates.

+

Paul Albitz and Cricket Liu. DNS and BIND. Copyright © 1998 Sebastopol, CA: O'Reilly and Associates.

diff --git a/doc/arm/Bv9ARM.html b/doc/arm/Bv9ARM.html index 41b763c3e3..732a682779 100644 --- a/doc/arm/Bv9ARM.html +++ b/doc/arm/Bv9ARM.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -150,54 +150,54 @@ Usage
options Statement Definition and Usage
server Statement Grammar
server Statement Definition and Usage
-
trusted-keys Statement Grammar
-
trusted-keys Statement Definition +
trusted-keys Statement Grammar
+
trusted-keys Statement Definition and Usage
view Statement Grammar
-
view Statement Definition and Usage
+
view Statement Definition and Usage
zone Statement Grammar
-
zone Statement Definition and Usage
+
zone Statement Definition and Usage
-
Zone File
+
Zone File
Types of Resource Records and When to Use Them
-
Discussion of MX Records
+
Discussion of MX Records
Setting TTLs
-
Inverse Mapping in IPv4
-
Other Zone File Directives
-
BIND Master File Extension: the $GENERATE Directive
+
Inverse Mapping in IPv4
+
Other Zone File Directives
+
BIND Master File Extension: the $GENERATE Directive
7. BIND 9 Security Considerations
Access Control Lists
-
Chroot and Setuid (for +
Chroot and Setuid (for UNIX servers)
-
The chroot Environment
-
Using the setuid Function
+
The chroot Environment
+
Using the setuid Function
Dynamic Update Security
8. Troubleshooting
-
Common Problems
-
It's not working; how can I figure out what's wrong?
-
Incrementing and Changing the Serial Number
-
Where Can I Get Help?
+
Common Problems
+
It's not working; how can I figure out what's wrong?
+
Incrementing and Changing the Serial Number
+
Where Can I Get Help?
A. Appendices
-
Acknowledgments
-
A Brief History of the DNS and BIND
+
Acknowledgments
+
A Brief History of the DNS and BIND
General DNS Reference Information
IPv6 addresses (AAAA)
Bibliography (and Suggested Reading)
Request for Comments (RFCs)
Internet Drafts
-
Other Documents About BIND
+
Other Documents About BIND
From e933a1bd237ef8c0a77e1d3d0fb6e8539c571d62 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Fri, 23 May 2008 23:18:36 +0000 Subject: [PATCH 091/137] auto update --- doc/private/branches | 1 + 1 file changed, 1 insertion(+) diff --git a/doc/private/branches b/doc/private/branches index 4ef29add3b..10dbf94a97 100644 --- a/doc/private/branches +++ b/doc/private/branches @@ -128,6 +128,7 @@ rt18040 new marka // 2008-05-08 02:25 +0000 rt18042 new fdupont // 2008-05-09 13:27 +0000 rt18046 new fdupont // 2008-05-09 06:56 +0000 rt18092 new each // 2008-05-21 05:49 +0000 +rt18098 new shane_dbbackend open skan open explorer skan-metazones1 private explorer From 36978a7d7f669806748415d7e649baa02ae239ab Mon Sep 17 00:00:00 2001 From: Evan Hunt Date: Tue, 27 May 2008 23:00:33 +0000 Subject: [PATCH 092/137] custom_WFB_v9_4_2_P1 --- doc/private/delete-list | 1 + 1 file changed, 1 insertion(+) diff --git a/doc/private/delete-list b/doc/private/delete-list index 8d2f078ae6..96bcd2e2dd 100644 --- a/doc/private/delete-list +++ b/doc/private/delete-list @@ -6,6 +6,7 @@ custom_WFB_v9_4_0 custom_WFB_v9_4_1 custom_WFB_v9_4_1_P1 custom_WFB_v9_4_2 +custom_WFB_v9_4_2_P1 custom_ALLIANZ_v9_4_1_P1 custom_AFILIAS_v9_4_1_P1 custom_AFIS_v9_4_0 From f7db7f3fb16d576054df1f0b07b4f5f64959732d Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Tue, 27 May 2008 23:19:40 +0000 Subject: [PATCH 093/137] auto update --- doc/private/branches | 1 + 1 file changed, 1 insertion(+) diff --git a/doc/private/branches b/doc/private/branches index 10dbf94a97..506f669ca5 100644 --- a/doc/private/branches +++ b/doc/private/branches @@ -26,6 +26,7 @@ custom_WFB_v9_4_0 private custom_WFB_v9_4_1 private marka // 2007-04-30 01:53 +0000 custom_WFB_v9_4_1_P1 private marka // 2007-08-01 22:49 +0000 custom_WFB_v9_4_2 private each // 2007-12-05 18:10 +0000 +custom_WFB_v9_4_2_P1 new each // 2008-05-27 22:59 +0000 gsstsig4 open sra // head + gsstsig as of 12 may 2006 gsstsig4_win32 open danny // sub-branch off gsstsig4 for windows development ietf71 new marka // 2008-03-12 04:10 +0000 From fa2423190831fc7e3adc2a718a3ee07b64e5bacb Mon Sep 17 00:00:00 2001 From: Evan Hunt Date: Tue, 27 May 2008 23:35:40 +0000 Subject: [PATCH 094/137] custom_ALLIANZ_v9_4_2_P1 --- doc/private/delete-list | 1 + 1 file changed, 1 insertion(+) diff --git a/doc/private/delete-list b/doc/private/delete-list index 96bcd2e2dd..1df5ebcffb 100644 --- a/doc/private/delete-list +++ b/doc/private/delete-list @@ -16,3 +16,4 @@ custom_NOM_v9_5_0a7 custom_NOM_v9_5_0b2+ custom_CISCO_v9_3_4_P1 custom_ALLIANZ_v9_4_2 +custom_ALLIANZ_v9_4_2_P1 From 3634531310252976deeb0842c782d34f16febe30 Mon Sep 17 00:00:00 2001 From: Evan Hunt Date: Wed, 28 May 2008 21:02:45 +0000 Subject: [PATCH 095/137] Switch "dnssec-validation" default from no to yes. [rt18121] --- bin/named/config.c | 4 ++-- doc/arm/Bv9ARM-book.xml | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/bin/named/config.c b/bin/named/config.c index edf0cb26d7..730fa502ea 100644 --- a/bin/named/config.c +++ b/bin/named/config.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: config.c,v 1.87 2008/05/01 18:23:06 jinmei Exp $ */ +/* $Id: config.c,v 1.88 2008/05/28 21:02:45 each Exp $ */ /*! \file */ @@ -139,7 +139,7 @@ options {\n\ acache-cleaning-interval 60;\n\ max-acache-size 16M;\n\ dnssec-enable yes;\n\ - dnssec-validation no; /* Make yes for 9.5. */ \n\ + dnssec-validation yes; \n\ dnssec-accept-expired no;\n\ clients-per-query 10;\n\ max-clients-per-query 100;\n\ diff --git a/doc/arm/Bv9ARM-book.xml b/doc/arm/Bv9ARM-book.xml index 03d041d0e1..8168504603 100644 --- a/doc/arm/Bv9ARM-book.xml +++ b/doc/arm/Bv9ARM-book.xml @@ -18,7 +18,7 @@ - PERFORMANCE OF THIS SOFTWARE. --> - + BIND 9 Administrator Reference Manual @@ -5651,7 +5651,7 @@ options { Enable DNSSEC validation in named. Note dnssec-enable also needs to be set to yes to be effective. - The default is no. + The default is yes. From 5ce4bd833588e5f6b0aa4cd1a728a4057a3d5b28 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Wed, 28 May 2008 23:18:40 +0000 Subject: [PATCH 096/137] auto update --- doc/private/branches | 1 + 1 file changed, 1 insertion(+) diff --git a/doc/private/branches b/doc/private/branches index 506f669ca5..b3bd6e1791 100644 --- a/doc/private/branches +++ b/doc/private/branches @@ -13,6 +13,7 @@ custom_AFILIAS_v9_4_1_P1 private marka // 2007-08-30 01:11 +0000 custom_AFIS_v9_4_0 private marka // 2007-04-23 05:08 +0000 custom_ALLIANZ_v9_4_1_P1 private marka // 2007-08-03 04:51 +0000 custom_ALLIANZ_v9_4_2 private marka // 2007-11-23 04:32 +0000 +custom_ALLIANZ_v9_4_2_P1 new each // 2008-05-27 23:33 +0000 custom_CISCO_v9_3_4_P1 private marka // 2007-11-23 04:19 +0000 custom_NOM_v9_5_0a7 private custom_NOM_v9_5_0b2 new marka // 2008-03-06 06:45 +0000 From 67354524bee279b7242a1a35b061151754e057b1 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Thu, 29 May 2008 01:12:05 +0000 Subject: [PATCH 097/137] regen --- doc/arm/Bv9ARM.ch06.html | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/doc/arm/Bv9ARM.ch06.html b/doc/arm/Bv9ARM.ch06.html index 05d5de68ea..7136338f01 100644 --- a/doc/arm/Bv9ARM.ch06.html +++ b/doc/arm/Bv9ARM.ch06.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -2768,7 +2768,7 @@ options { Enable DNSSEC validation in named. Note dnssec-enable also needs to be set to yes to be effective. - The default is no. + The default is yes.

dnssec-accept-expired

From 58253bddc4c33507ba28654b9c4a36ca1053730c Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Thu, 29 May 2008 04:46:32 +0000 Subject: [PATCH 098/137] 2375. [bug] Change #2144 was not complete. --- CHANGES | 2 ++ lib/dns/resolver.c | 4 ++-- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/CHANGES b/CHANGES index b9e894a745..92b67143dc 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,5 @@ +2375. [bug] Change #2144 was not complete. + 2374. [bug] "blackhole" ACLs could cause named to segfault due to some uninitialized memory. [RT #18095] diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c index 1e5ac81cf4..a2c40295db 100644 --- a/lib/dns/resolver.c +++ b/lib/dns/resolver.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: resolver.c,v 1.370 2008/05/06 01:12:55 each Exp $ */ +/* $Id: resolver.c,v 1.371 2008/05/29 04:46:32 marka Exp $ */ /*! \file */ @@ -2003,7 +2003,7 @@ add_bad(fetchctx_t *fctx, dns_adbaddrinfo_t *addrinfo, isc_result_t reason) { return; if (reason == DNS_R_UNEXPECTEDRCODE && - fctx->rmessage->opcode == dns_rcode_servfail && + fctx->rmessage->rcode == dns_rcode_servfail && ISFORWARDER(addrinfo)) return; From ae6942e3d1fc7327ba5df9d638e0af15a908f8fb Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Thu, 29 May 2008 05:20:45 +0000 Subject: [PATCH 099/137] placeholder --- CHANGES | 34 ++++++++++++++++++---------------- 1 file changed, 18 insertions(+), 16 deletions(-) diff --git a/CHANGES b/CHANGES index 92b67143dc..8687d1cd42 100644 --- a/CHANGES +++ b/CHANGES @@ -1,32 +1,34 @@ -2375. [bug] Change #2144 was not complete. +2376. [bug] Change #2144 was not complete. -2374. [bug] "blackhole" ACLs could cause named to segfault due +2375. [placeholder] + +2374. [bug] "blackhole" ACLs could cause named to segfault due to some uninitialized memory. [RT #18095] -2373. [bug] Default values of zone ACLs were re-parsed each time a +2373. [bug] Default values of zone ACLs were re-parsed each time a new zone was configured, causing an overconsumption of memory. [RT #18092] -2372. [bug] Fixed incorrect TAG_HMACSHA256_BITS value [RT #18047] +2372. [bug] Fixed incorrect TAG_HMACSHA256_BITS value [RT #18047] -2371. [doc] Add +nsid option to dig man page. [RT #18039] +2371. [doc] Add +nsid option to dig man page. [RT #18039] -2370. [bug] "rndc freeze" could trigger an assertion in named - when called on a nonexistent zone. [RT #18050] +2370. [bug] "rndc freeze" could trigger an assertion in named + when called on a nonexistent zone. [RT #18050] 2369. [bug] libbind: Array bounds overrun on read in bitncmp(). [RT #18054] -2368. [port] Linux: use libcap for capability management if - possible. [RT# 18026] +2368. [port] Linux: use libcap for capability management if + possible. [RT# 18026] -2367. [bug] Improve counting of dns_resstatscounter_retry - [RT #18030] +2367. [bug] Improve counting of dns_resstatscounter_retry + [RT #18030] 2366. [bug] Adb shutdown race. [RT #18021] -2365. [bug] Fix a bug that caused dns_acl_isany() to return - spurious results. [RT #18000] +2365. [bug] Fix a bug that caused dns_acl_isany() to return + spurious results. [RT #18000] 2364. [bug] named could trigger a assertion when serving a malformed signed zone. [RT #17828] @@ -34,9 +36,9 @@ 2363. [port] sunos: pre-set "lt_cv_sys_max_cmd_len=4096;". [RT #17513] -2362. [cleanup] Make "rrset-order fixed" a compile-time option. - settable by "./configure --enable-fixed-rrset". - Disabled by default. [RT #17977] +2362. [cleanup] Make "rrset-order fixed" a compile-time option. + settable by "./configure --enable-fixed-rrset". + Disabled by default. [RT #17977] 2361. [bug] "recursion" statistics counter could be counted multiple times for a single query. [RT #17990] From 2a9280e202aab33e7929e328216a407774e30eaa Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Thu, 29 May 2008 05:31:55 +0000 Subject: [PATCH 100/137] 2376. [bug] Change #2144 was not complete. --- CHANGES | 84 ++++++++++++++++++++++++---------------------- lib/dns/resolver.c | 4 +-- 2 files changed, 45 insertions(+), 43 deletions(-) diff --git a/CHANGES b/CHANGES index 09886ba34b..4f2f341fc2 100644 --- a/CHANGES +++ b/CHANGES @@ -1,4 +1,6 @@ -2375. [security] Fully randomize UDP query ports to improve +2376. [bug] Change #2144 was not complete. + +2375. [security] Fully randomize UDP query ports to improve forgery resilience. [RT #17949] 2369. [bug] libbind: Array bounds overrun on read in bitncmp(). @@ -40,19 +42,19 @@ 2340. [port] openbsd: interface configuration. [RT #17700] -2335. [port] sunos: libbind and *printf() support for long long. +2335. [port] sunos: libbind and *printf() support for long long. [RT #17513] 2334. [bug] Bad REQUIRES in fromstruct_in_naptr(), off by one bug in fromstruct_txt(). [RT #17609] - + 2333. [bug] Fix off by one error in isc_time_nowplusinterval(). [RT #17608] 2332. [contrib] query-loc-0.4.0. [RT #17602] 2331. [bug] Failure to regenerate any signatures was not being - reported nor being past back to the UPDATE client. + reported nor being past back to the UPDATE client. [RT #17570] 2330. [bug] Remove potential race condition when handling @@ -87,11 +89,11 @@ 2322. [port] MacOS: work around the limitation of setrlimit() for RLIMIT_NOFILE. [RT #17526] -2321. [bug] Silence Coverity warnings in lib/dns/master.c, +2321. [bug] Silence Coverity warnings in lib/dns/master.c, lib/dns/rbtdb.c, lib/isccfg/namedconf.c, lib/dns/tsig.c and bin/dnssec/dnssec-signzone.c. -2319. [bug] Silence Coverity warnings in +2319. [bug] Silence Coverity warnings in lib/dns/rdata/in_1/apl_42.c. [RT #17469] 2318. [port] sunos fixes for libbind. [RT #17514] @@ -105,7 +107,7 @@ 2312. [cleanup] Silence Coverity warning in lib/isc/unix/socket.c. [RT #17458] -2311. [func] Update ACL regression test. [RT #17462] +2311. [func] Update ACL regression test. [RT #17462] 2310. [bug] dig, host, nslookup: flush stdout before emitting debug/fatal messages. [RT #17501] @@ -128,7 +130,7 @@ 2301. [bug] Remove resource leak and fix error messages in bin/tests/system/lwresd/lwtest.c. [RT #17474] -2300. [bug] Fixed failure to close open file in +2300. [bug] Fixed failure to close open file in bin/tests/names/t_names.c. [RT #17473] 2299. [bug] Remove unnecessary NULL check in @@ -151,7 +153,7 @@ 2292. [bug] Log if the working directory is not writable. [RT #17312] -2291. [bug] PR_SET_DUMPABLE may be set too late. Also report +2291. [bug] PR_SET_DUMPABLE may be set too late. Also report failure to set PR_SET_DUMPABLE. [RT #17312] 2290. [bug] Let AD in the query signal that the client wants AD @@ -170,7 +172,7 @@ memory context rather than the clients memory context. [RT #17377] -2279. [bug] Use setsockopt(SO_NOSIGPIPE), when available, +2279. [bug] Use setsockopt(SO_NOSIGPIPE), when available, to protect applications from receiving spurious SIGPIPE signals when using the resolver. @@ -216,10 +218,10 @@ reality. Note there is behaviour change for BIND 9.5. [RT #17113] -2249. [bug] Only set Authentic Data bit if client requested - DNSSEC, per RFC 3655 [RT #17175] +2249. [bug] Only set Authentic Data bit if client requested + DNSSEC, per RFC 3655 [RT #17175] -2248. [cleanup] Fix several errors reported by Coverity. [RT #17160] +2248. [cleanup] Fix several errors reported by Coverity. [RT #17160] 2247. [doc] Sort doc/misc/options. [RT #17067] @@ -237,11 +239,11 @@ 2236. [bug] dnssec-signzone failed to preserve the case of of wildcard owner names. [RT #17085] -2234. [port] Correct some compiler warnings on SCO OSr5 [RT #17134] - +2234. [port] Correct some compiler warnings on SCO OSr5 [RT #17134] + 2229. [bug] Null pointer dereference on query pool creation - failure. [RT #17133] - + failure. [RT #17133] + 2232. [bug] dns_adb_findaddrinfo() could fail and return ISC_R_SUCCESS. [RT #17137] @@ -252,10 +254,10 @@ 2227. [cleanup] Tidied up the FAQ. [RT #17121] -2226. [bug] Fix build error. [RT #17124] +2226. [bug] Fix build error. [RT #17124] 2225. [bug] More support for systems with no IPv4 addresses. - [RT #17111] + [RT #17111] 2224. [bug] Defer journal compaction if a xfrin is in progress. [RT #17119] @@ -269,12 +271,12 @@ 2220. [bug] win32: Address a race condition in final shutdown of the Windows socket code. [RT #17028] - + 2218. [bug] Remove unnecessary REQUIRE from dns_validator_create(). [RT #16976] 2216. [cleanup] Fix a number of errors reported by Coverity. - [RT #17094] + [RT #17094] 2214. [bug] Deregister OpenSSL lock callback when cleaning up. [RT #17098] @@ -475,7 +477,7 @@ 2203. [security] Query id generation was cryptographically weak. [RT # 16915] - + 2193. [port] win32: BINDInstall.exe is now linked statically. [RT #16906] @@ -515,12 +517,12 @@ 2095. [port] libbind: alway prototype inet_cidr_ntop_ipv6() and net_cidr_ntop_ipv6(). [RT #16388] - + 2094. [contrib] Update named-bootconf. [RT# 16404] 2092. [bug] win32: dig, host, nslookup. Use registry config if resolv.conf does not exist or no nameservers - listed. [RT #15877] + listed. [RT #15877] 2091. [port] dighost.c: race condition on cleanup. [RT #16417] @@ -767,7 +769,7 @@ 1966. [bug] Don't set CD when we have fallen back to plain DNS. [RT #15727] -1963. [port] Tru64 4.0E doesn't support send() and recv(). +1963. [port] Tru64 4.0E doesn't support send() and recv(). [RT #15586] 1962. [bug] Named failed to clear old update-policy when it @@ -797,7 +799,7 @@ 1951. [security] Drop queries from particular well known ports. Don't return FORMERR to queries from particular well known ports. [RT #15636] - + 1950. [port] Solaris 2.5.1 and earlier cannot bind() then connect() a TCP socket. This prevents the source address being set for TCP connections. [RT #15628] @@ -825,7 +827,7 @@ 1940. [bug] Fixed a number of error conditions reported by Coverity. -1939. [bug] The resolver could dereference a null pointer after +1939. [bug] The resolver could dereference a null pointer after validation if all the queries have timed out. [RT #15528] @@ -880,7 +882,7 @@ query order sensitive. [RT #14933] 1905. [bug] Strings returned from cfg_obj_asstring() should be - treated as read-only. [RT #15256] + treated as read-only. [RT #15256] 1901. [cleanup] Don't add DNSKEY records to the additional section. @@ -978,9 +980,9 @@ 1848. [bug] Improve SMF integration. [RT #13238] 1847. [bug] isc_ondestroy_init() is called too late in - dns_rbtdb_create()/dns_rbtdb64_create(). + dns_rbtdb_create()/dns_rbtdb64_create(). [RT #13661] - + 1846. [contrib] query-loc-0.3.0 from Stephane Bortzmeyer . @@ -1048,7 +1050,7 @@ 1822. [bug] check-names test for RT was reversed. [RT #13382] -1821. [doc] acls definitions are no longer required to be +1821. [doc] acls definitions are no longer required to be in named.conf prior to reference. They can be defined after being referenced. @@ -1074,7 +1076,7 @@ 1807. [bug] When forwarding (forward only) set the active domain from the forward zone name. [RT #13526] - + 1804. [bug] Ensure that if we are queried for glue that it fits in the additional section or TC is set to tell the client to retry using TCP. [RT #10114] @@ -1235,7 +1237,7 @@ requested number of worker threads then destruction of the manager would trigger an INSIST() failure. [RT #12790] - + 1742. [bug] Deleting all records at a node then adding a previously existing record, in a single UPDATE transaction, failed to leave / regenerate the @@ -1246,7 +1248,7 @@ 1740. [bug] Replace rbt's hash algorithm as it performed badly with certain zones. [RT #12729] - + NOTE: a hash context now needs to be established via isc_hash_create() if the application was not already doing this. @@ -1261,7 +1263,7 @@ 1736. [bug] dst_key_fromnamedfile() could fail to read a public key. [RT #12687] - + 1735. [bug] 'dig +sigtrace' could die with a REQUIRE failure. [RE #12688] @@ -1424,7 +1426,7 @@ 1675. [bug] named would sometimes add extra NSEC records to the authority section. - + 1674. [port] linux: increase buffer size used to scan /proc/net/if_inet6. @@ -1495,7 +1497,7 @@ 1648. [func] Update dnssec-lookaside named.conf syntax to support multiple dnssec-lookaside namespaces (not yet - implemented). + implemented). 1647. [bug] It was possible trigger a INSIST when chasing a DS record that required walking back over a empty node. @@ -1527,7 +1529,7 @@ 1638. [bug] "ixfr-from-differences" could generate a REQUIRE failure if the journal open failed. [RT #11347] - + 1637. [bug] Node reference leak on error in addnoqname(). 1636. [bug] The dump done callback could get ISC_R_SUCCESS even if @@ -1564,7 +1566,7 @@ 1625. [bug] named failed to load/transfer RFC2535 signed zones which contained CNAMES. [RT# 11237] -1606. [bug] DLV insecurity proof was failing. +1606. [bug] DLV insecurity proof was failing. 1605. [func] New dns_db_find() option DNS_DBFIND_COVERINGNSEC. @@ -1640,14 +1642,14 @@ 1604. [bug] A xfrout_ctx_create() failure would result in xfrout_ctx_destroy() being called with a partially initialized structure. - + 1603. [bug] nsupdate: set interactive based on isatty(). [RT# 10929] 1602. [bug] Logging to a file failed unless a size was specified. [RT# 10925] -1601. [bug] Silence spurious warning 'both "recursion no;" and +1601. [bug] Silence spurious warning 'both "recursion no;" and "allow-recursion" active' warning from view "_bind". [RT# 10920] diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c index 1bba103b6d..9fa88a0e08 100644 --- a/lib/dns/resolver.c +++ b/lib/dns/resolver.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: resolver.c,v 1.218.2.18.4.79 2008/05/22 20:46:35 each Exp $ */ +/* $Id: resolver.c,v 1.218.2.18.4.80 2008/05/29 05:31:55 marka Exp $ */ #include @@ -1740,7 +1740,7 @@ add_bad(fetchctx_t *fctx, dns_adbaddrinfo_t *addrinfo, isc_result_t reason) { return; if (reason == DNS_R_UNEXPECTEDRCODE && - fctx->rmessage->opcode == dns_rcode_servfail && + fctx->rmessage->rcode == dns_rcode_servfail && ISFORWARDER(addrinfo)) return; From 5cb56973ea7278b733aec76cc211cb0de7c263e2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tatuya=20JINMEI=20=E7=A5=9E=E6=98=8E=E9=81=94=E5=93=89?= Date: Fri, 30 May 2008 18:27:27 +0000 Subject: [PATCH 101/137] fixed a typo in comment [RT #18130] --- lib/isc/include/isc/lex.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/lib/isc/include/isc/lex.h b/lib/isc/include/isc/lex.h index 35c7ccc8b6..7429caec58 100644 --- a/lib/isc/include/isc/lex.h +++ b/lib/isc/include/isc/lex.h @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: lex.h,v 1.35 2007/06/19 23:47:18 tbox Exp $ */ +/* $Id: lex.h,v 1.36 2008/05/30 18:27:27 jinmei Exp $ */ #ifndef ISC_LEX_H #define ISC_LEX_H 1 @@ -86,7 +86,7 @@ ISC_LANG_BEGINDECLS #define ISC_LEXOPT_DNSMULTILINE 0x20 /*%< Handle '(' and ')'. */ #define ISC_LEXOPT_NOMORE 0x40 /*%< Want "no more" token. */ -#define ISC_LEXOPT_CNUMBER 0x80 /*%< Regognize octal and hex. */ +#define ISC_LEXOPT_CNUMBER 0x80 /*%< Recognize octal and hex. */ #define ISC_LEXOPT_ESCAPE 0x100 /*%< Recognize escapes. */ #define ISC_LEXOPT_QSTRINGMULTILINE 0x200 /*%< Allow multiline "" strings */ #define ISC_LEXOPT_OCTAL 0x400 /*%< Expect a octal number. */ From 5c3477af3821d82684ddf55bdfd693d4d8c30a08 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Fri, 30 May 2008 23:19:09 +0000 Subject: [PATCH 102/137] auto update --- doc/private/branches | 1 + 1 file changed, 1 insertion(+) diff --git a/doc/private/branches b/doc/private/branches index b3bd6e1791..17ccc47c7c 100644 --- a/doc/private/branches +++ b/doc/private/branches @@ -125,6 +125,7 @@ rt17977 new each // 2008-04-23 00:29 +0000 rt18018 new rt18020 new fdupont // FIPS 140-2 rt18020a new fdupont // 2008-05-15 14:50 +0000 +rt18029 new each // 2008-05-30 05:02 +0000 rt18033 new fdupont // HSM maintenance rt18040 new marka // 2008-05-08 02:25 +0000 rt18042 new fdupont // 2008-05-09 13:27 +0000 From 83d29eff2912ef967596eb5ed148de7668b35564 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Fri, 30 May 2008 23:30:28 +0000 Subject: [PATCH 103/137] newcopyrights --- util/copyrights | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/util/copyrights b/util/copyrights index 89f53c6efd..46937bdef3 100644 --- a/util/copyrights +++ b/util/copyrights @@ -2119,7 +2119,7 @@ ./lib/isc/include/isc/interfaceiter.h C 1999,2000,2001,2004,2005,2006,2007 ./lib/isc/include/isc/ipv6.h C 1999,2000,2001,2002,2004,2005,2007 ./lib/isc/include/isc/lang.h C 1999,2000,2001,2004,2005,2006,2007 -./lib/isc/include/isc/lex.h C 1998,1999,2000,2001,2002,2004,2005,2007 +./lib/isc/include/isc/lex.h C 1998,1999,2000,2001,2002,2004,2005,2007,2008 ./lib/isc/include/isc/lfsr.h C 1999,2000,2001,2004,2005,2006,2007 ./lib/isc/include/isc/lib.h C 1999,2000,2001,2004,2005,2006,2007 ./lib/isc/include/isc/list.h C 1997,1998,1999,2000,2001,2002,2004,2006,2007 From 022b5c5a3623e7328510379e633317d2ea3a0b44 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Fri, 30 May 2008 23:47:01 +0000 Subject: [PATCH 104/137] update copyright notice --- lib/isc/include/isc/lex.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/lib/isc/include/isc/lex.h b/lib/isc/include/isc/lex.h index 7429caec58..8612150991 100644 --- a/lib/isc/include/isc/lex.h +++ b/lib/isc/include/isc/lex.h @@ -1,5 +1,5 @@ /* - * Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC") + * Copyright (C) 2004, 2005, 2007, 2008 Internet Systems Consortium, Inc. ("ISC") * Copyright (C) 1998-2002 Internet Software Consortium. * * Permission to use, copy, modify, and/or distribute this software for any @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: lex.h,v 1.36 2008/05/30 18:27:27 jinmei Exp $ */ +/* $Id: lex.h,v 1.37 2008/05/30 23:47:01 tbox Exp $ */ #ifndef ISC_LEX_H #define ISC_LEX_H 1 From a538dc4e862dc30a306d383342ec1c34f2dad33e Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Sat, 31 May 2008 00:54:50 +0000 Subject: [PATCH 105/137] Linux: IPSEC and xfrm_larval_drop --- FAQ.xml | 26 +++++++++++++++++++++++++- 1 file changed, 25 insertions(+), 1 deletion(-) diff --git a/FAQ.xml b/FAQ.xml index 5594024a85..cf24dc8a10 100644 --- a/FAQ.xml +++ b/FAQ.xml @@ -17,7 +17,7 @@ - PERFORMANCE OF THIS SOFTWARE. --> - +

Frequently Asked Questions about BIND 9 @@ -1015,6 +1015,30 @@ client: UDP client handler shutting down due to fatal receive error: unexpected + + + + Why does named lock up when it attempts to connect over IPSEC tunnels? + + + + + This is due to a kernel bug where the fact the a socket is marked + non-blocking is ignored. It is reported that setting + xfrm_larval_drop to 1 helps but this may have negative side effects. + See: +https://bugzilla.redhat.com/show_bug.cgi?id=427629 + and +http://lkml.org/lkml/2007/12/4/260 + + + xfrm_larval_drop can be set to 1 by the following proceedure: + +echo "1" > proc/sys/net/core/xfrm_larval_drop + + + + From b8ee0d56f0294d0b276725e701d109853f05c237 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Sat, 31 May 2008 00:55:42 +0000 Subject: [PATCH 106/137] grammer --- FAQ.xml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/FAQ.xml b/FAQ.xml index cf24dc8a10..0020b7bc4c 100644 --- a/FAQ.xml +++ b/FAQ.xml @@ -17,7 +17,7 @@ - PERFORMANCE OF THIS SOFTWARE. --> - +
Frequently Asked Questions about BIND 9 @@ -1023,7 +1023,7 @@ client: UDP client handler shutting down due to fatal receive error: unexpected - This is due to a kernel bug where the fact the a socket is marked + This is due to a kernel bug where the fact that a socket is marked non-blocking is ignored. It is reported that setting xfrm_larval_drop to 1 helps but this may have negative side effects. See: From b4c8e92f7f1e5053941dd92e5e2ccb557443d5ff Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Sat, 31 May 2008 01:06:18 +0000 Subject: [PATCH 107/137] <> delimit urls --- FAQ.xml | 23 +++++++++++------------ 1 file changed, 11 insertions(+), 12 deletions(-) diff --git a/FAQ.xml b/FAQ.xml index 0020b7bc4c..41a77303ed 100644 --- a/FAQ.xml +++ b/FAQ.xml @@ -17,7 +17,7 @@ - PERFORMANCE OF THIS SOFTWARE. --> - +
Frequently Asked Questions about BIND 9 @@ -706,8 +706,7 @@ zone "list.dsbl.org" { requests are coming from a Windows 2000 machine, see - http://support.microsoft.com/support/kb/articles/q246/8/04.asp - + <http://support.microsoft.com/support/kb/articles/q246/8/04.asp> for information about how to turn them off. @@ -857,7 +856,7 @@ serial-query-rate 5; // default 20 usage rules and are leaking queries to the Internet. You should establish your own zones for these addresses to prevent you querying the Internet's name servers for these addresses. - Please see http://as112.net/ + Please see <http://as112.net/> for details of the problems you are causing and the counter measures that have had to be deployed. @@ -1010,7 +1009,7 @@ client: UDP client handler shutting down due to fatal receive error: unexpected See: - http://marc.theaimsgroup.com/?l=linux-netdev&m=113081708031466&w=2 + <http://marc.theaimsgroup.com/?l=linux-netdev&m=113081708031466&w=2> @@ -1027,9 +1026,9 @@ client: UDP client handler shutting down due to fatal receive error: unexpected non-blocking is ignored. It is reported that setting xfrm_larval_drop to 1 helps but this may have negative side effects. See: -https://bugzilla.redhat.com/show_bug.cgi?id=427629 +<https://bugzilla.redhat.com/show_bug.cgi?id=427629> and -http://lkml.org/lkml/2007/12/4/260 +<http://lkml.org/lkml/2007/12/4/260>. xfrm_larval_drop can be set to 1 by the following proceedure: @@ -1125,8 +1124,9 @@ modprobe capability Red Hat have adopted the National Security Agency's - SELinux security policy ( see http://www.nsa.gov/selinux - ) and recommendations for BIND security , which are more + SELinux security policy (see <http://www.nsa.gov/selinux>) + and recommendations for BIND security , which are more secure than running named in a chroot and make use of the bind-chroot environment unnecessary . @@ -1365,8 +1365,7 @@ rand_irqs="3 14 15" See also - http://people.freebsd.org/~dougb/randomness.html - + <http://people.freebsd.org/~dougb/randomness.html>. @@ -1388,7 +1387,7 @@ rand_irqs="3 14 15" - http://blogs.sun.com/roller/page/anay/Weblog?catname=%2FSolaris + <http://blogs.sun.com/roller/page/anay/Weblog?catname=%2FSolaris> From 13ec0fb27874dea05b47adfa9ad296285a0ed2ee Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Sat, 31 May 2008 01:11:51 +0000 Subject: [PATCH 108/137] regen --- FAQ | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/FAQ b/FAQ index e6b2ff27ce..eb97e2548f 100644 --- a/FAQ +++ b/FAQ @@ -571,6 +571,18 @@ A: This is the result of a Linux kernel bug. See: http://marc.theaimsgroup.com/?l=linux-netdev&m=113081708031466&w=2 +Q: Why does named lock up when it attempts to connect over IPSEC tunnels? + +A: This is due to a kernel bug where the fact that a socket is marked + non-blocking is ignored. It is reported that setting xfrm_larval_drop + to 1 helps but this may have negative side effects. See: https:// + bugzilla.redhat.com/show_bug.cgi?id=427629 and http://lkml.org/lkml/ + 2007/12/4/260 + + xfrm_larval_drop can be set to 1 by the following proceedure: + + echo "1" > proc/sys/net/core/xfrm_larval_drop + Q: Why do I see 5 (or more) copies of named on Linux? A: Linux threads each show up as a process under ps. The approximate From 4447547f3a373b7275409a8bd96b33b989180fa6 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Sat, 31 May 2008 01:21:10 +0000 Subject: [PATCH 109/137] regen --- FAQ | 12 ++++++++++++ FAQ.xml | 26 +++++++++++++++++++++++++- 2 files changed, 37 insertions(+), 1 deletion(-) diff --git a/FAQ b/FAQ index e6b2ff27ce..eb97e2548f 100644 --- a/FAQ +++ b/FAQ @@ -571,6 +571,18 @@ A: This is the result of a Linux kernel bug. See: http://marc.theaimsgroup.com/?l=linux-netdev&m=113081708031466&w=2 +Q: Why does named lock up when it attempts to connect over IPSEC tunnels? + +A: This is due to a kernel bug where the fact that a socket is marked + non-blocking is ignored. It is reported that setting xfrm_larval_drop + to 1 helps but this may have negative side effects. See: https:// + bugzilla.redhat.com/show_bug.cgi?id=427629 and http://lkml.org/lkml/ + 2007/12/4/260 + + xfrm_larval_drop can be set to 1 by the following proceedure: + + echo "1" > proc/sys/net/core/xfrm_larval_drop + Q: Why do I see 5 (or more) copies of named on Linux? A: Linux threads each show up as a process under ps. The approximate diff --git a/FAQ.xml b/FAQ.xml index 818390b5a8..3cb8b9b29b 100644 --- a/FAQ.xml +++ b/FAQ.xml @@ -17,7 +17,7 @@ - PERFORMANCE OF THIS SOFTWARE. --> - +
Frequently Asked Questions about BIND 9 @@ -1015,6 +1015,30 @@ client: UDP client handler shutting down due to fatal receive error: unexpected + + + + Why does named lock up when it attempts to connect over IPSEC tunnels? + + + + + This is due to a kernel bug where the fact that a socket is marked + non-blocking is ignored. It is reported that setting + xfrm_larval_drop to 1 helps but this may have negative side effects. + See: +https://bugzilla.redhat.com/show_bug.cgi?id=427629 + and +http://lkml.org/lkml/2007/12/4/260 + + + xfrm_larval_drop can be set to 1 by the following proceedure: + +echo "1" > proc/sys/net/core/xfrm_larval_drop + + + + From 99f7557bf071d488f00598f3e5be3bfbaa7b98d4 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Sat, 31 May 2008 01:44:13 +0000 Subject: [PATCH 110/137] spelling --- FAQ.xml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/FAQ.xml b/FAQ.xml index 41a77303ed..4674456777 100644 --- a/FAQ.xml +++ b/FAQ.xml @@ -17,7 +17,7 @@ - PERFORMANCE OF THIS SOFTWARE. --> - +
Frequently Asked Questions about BIND 9 @@ -1031,7 +1031,7 @@ client: UDP client handler shutting down due to fatal receive error: unexpected <http://lkml.org/lkml/2007/12/4/260>. - xfrm_larval_drop can be set to 1 by the following proceedure: + xfrm_larval_drop can be set to 1 by the following procedure: echo "1" > proc/sys/net/core/xfrm_larval_drop From 9d362f90efcdfa270d5392f2623a14f1dad9fa44 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Sun, 1 Jun 2008 01:12:07 +0000 Subject: [PATCH 111/137] regen --- FAQ | 23 ++++++++++++----------- 1 file changed, 12 insertions(+), 11 deletions(-) diff --git a/FAQ b/FAQ index eb97e2548f..912a2f8f53 100644 --- a/FAQ +++ b/FAQ @@ -396,8 +396,8 @@ A: Someone is trying to update your DNS data using the RFC2136 Dynamic Update protocol. Windows 2000 machines have a habit of sending dynamic update requests to DNS servers without being specifically configured to do so. If the update requests are coming from a Windows 2000 machine, - see http://support.microsoft.com/support/kb/articles/q246/8/04.asp for - information about how to turn them off. + see + for information about how to turn them off. Q: When I do a "dig . ns", many of the A records for the root servers are missing. Why? @@ -468,7 +468,7 @@ A: If the IN-ADDR.ARPA name covered refers to a internal address space you are using then you have failed to follow RFC 1918 usage rules and are leaking queries to the Internet. You should establish your own zones for these addresses to prevent you querying the Internet's name servers - for these addresses. Please see http://as112.net/ for details of the + for these addresses. Please see for details of the problems you are causing and the counter measures that have had to be deployed. @@ -569,17 +569,18 @@ Q: Why do I get the following errors: A: This is the result of a Linux kernel bug. - See: http://marc.theaimsgroup.com/?l=linux-netdev&m=113081708031466&w=2 + See: Q: Why does named lock up when it attempts to connect over IPSEC tunnels? A: This is due to a kernel bug where the fact that a socket is marked non-blocking is ignored. It is reported that setting xfrm_larval_drop - to 1 helps but this may have negative side effects. See: https:// - bugzilla.redhat.com/show_bug.cgi?id=427629 and http://lkml.org/lkml/ - 2007/12/4/260 + to 1 helps but this may have negative side effects. See: and . - xfrm_larval_drop can be set to 1 by the following proceedure: + xfrm_larval_drop can be set to 1 by the following procedure: echo "1" > proc/sys/net/core/xfrm_larval_drop @@ -625,7 +626,7 @@ Q: I'm running BIND on Red Hat Enterprise Linux or Fedora Core - A: Red Hat Security Enhanced Linux (SELinux) policy security protections : Red Hat have adopted the National Security Agency's SELinux security - policy ( see http://www.nsa.gov/selinux ) and recommendations for BIND + policy (see ) and recommendations for BIND security , which are more secure than running named in a chroot and make use of the bind-chroot environment unnecessary . @@ -765,7 +766,7 @@ A: /dev/random is not configured. Use rndcontrol(8) to tell the kernel to /etc/rc.conf rand_irqs="3 14 15" - See also http://people.freebsd.org/~dougb/randomness.html + See also . 4.5. Solaris @@ -773,7 +774,7 @@ Q: How do I integrate BIND 9 and Solaris SMF A: Sun has a blog entry describing how to do this. - http://blogs.sun.com/roller/page/anay/Weblog?catname=%2FSolaris + 4.6. Apple Mac OS X From 344a6d0ff60022e9d6665c7b101a3e0cfc61539a Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Sun, 1 Jun 2008 01:21:11 +0000 Subject: [PATCH 112/137] regen --- FAQ | 23 ++++++++++++----------- FAQ.xml | 25 ++++++++++++------------- 2 files changed, 24 insertions(+), 24 deletions(-) diff --git a/FAQ b/FAQ index eb97e2548f..912a2f8f53 100644 --- a/FAQ +++ b/FAQ @@ -396,8 +396,8 @@ A: Someone is trying to update your DNS data using the RFC2136 Dynamic Update protocol. Windows 2000 machines have a habit of sending dynamic update requests to DNS servers without being specifically configured to do so. If the update requests are coming from a Windows 2000 machine, - see http://support.microsoft.com/support/kb/articles/q246/8/04.asp for - information about how to turn them off. + see + for information about how to turn them off. Q: When I do a "dig . ns", many of the A records for the root servers are missing. Why? @@ -468,7 +468,7 @@ A: If the IN-ADDR.ARPA name covered refers to a internal address space you are using then you have failed to follow RFC 1918 usage rules and are leaking queries to the Internet. You should establish your own zones for these addresses to prevent you querying the Internet's name servers - for these addresses. Please see http://as112.net/ for details of the + for these addresses. Please see for details of the problems you are causing and the counter measures that have had to be deployed. @@ -569,17 +569,18 @@ Q: Why do I get the following errors: A: This is the result of a Linux kernel bug. - See: http://marc.theaimsgroup.com/?l=linux-netdev&m=113081708031466&w=2 + See: Q: Why does named lock up when it attempts to connect over IPSEC tunnels? A: This is due to a kernel bug where the fact that a socket is marked non-blocking is ignored. It is reported that setting xfrm_larval_drop - to 1 helps but this may have negative side effects. See: https:// - bugzilla.redhat.com/show_bug.cgi?id=427629 and http://lkml.org/lkml/ - 2007/12/4/260 + to 1 helps but this may have negative side effects. See: and . - xfrm_larval_drop can be set to 1 by the following proceedure: + xfrm_larval_drop can be set to 1 by the following procedure: echo "1" > proc/sys/net/core/xfrm_larval_drop @@ -625,7 +626,7 @@ Q: I'm running BIND on Red Hat Enterprise Linux or Fedora Core - A: Red Hat Security Enhanced Linux (SELinux) policy security protections : Red Hat have adopted the National Security Agency's SELinux security - policy ( see http://www.nsa.gov/selinux ) and recommendations for BIND + policy (see ) and recommendations for BIND security , which are more secure than running named in a chroot and make use of the bind-chroot environment unnecessary . @@ -765,7 +766,7 @@ A: /dev/random is not configured. Use rndcontrol(8) to tell the kernel to /etc/rc.conf rand_irqs="3 14 15" - See also http://people.freebsd.org/~dougb/randomness.html + See also . 4.5. Solaris @@ -773,7 +774,7 @@ Q: How do I integrate BIND 9 and Solaris SMF A: Sun has a blog entry describing how to do this. - http://blogs.sun.com/roller/page/anay/Weblog?catname=%2FSolaris + 4.6. Apple Mac OS X diff --git a/FAQ.xml b/FAQ.xml index 3cb8b9b29b..5e239901eb 100644 --- a/FAQ.xml +++ b/FAQ.xml @@ -17,7 +17,7 @@ - PERFORMANCE OF THIS SOFTWARE. --> - +
Frequently Asked Questions about BIND 9 @@ -706,8 +706,7 @@ zone "list.dsbl.org" { requests are coming from a Windows 2000 machine, see - http://support.microsoft.com/support/kb/articles/q246/8/04.asp - + <http://support.microsoft.com/support/kb/articles/q246/8/04.asp> for information about how to turn them off. @@ -857,7 +856,7 @@ serial-query-rate 5; // default 20 usage rules and are leaking queries to the Internet. You should establish your own zones for these addresses to prevent you querying the Internet's name servers for these addresses. - Please see http://as112.net/ + Please see <http://as112.net/> for details of the problems you are causing and the counter measures that have had to be deployed. @@ -1010,7 +1009,7 @@ client: UDP client handler shutting down due to fatal receive error: unexpected See: - http://marc.theaimsgroup.com/?l=linux-netdev&m=113081708031466&w=2 + <http://marc.theaimsgroup.com/?l=linux-netdev&m=113081708031466&w=2> @@ -1027,12 +1026,12 @@ client: UDP client handler shutting down due to fatal receive error: unexpected non-blocking is ignored. It is reported that setting xfrm_larval_drop to 1 helps but this may have negative side effects. See: -https://bugzilla.redhat.com/show_bug.cgi?id=427629 +<https://bugzilla.redhat.com/show_bug.cgi?id=427629> and -http://lkml.org/lkml/2007/12/4/260 +<http://lkml.org/lkml/2007/12/4/260>. - xfrm_larval_drop can be set to 1 by the following proceedure: + xfrm_larval_drop can be set to 1 by the following procedure: echo "1" > proc/sys/net/core/xfrm_larval_drop @@ -1125,8 +1124,9 @@ modprobe capability Red Hat have adopted the National Security Agency's - SELinux security policy ( see http://www.nsa.gov/selinux - ) and recommendations for BIND security , which are more + SELinux security policy (see <http://www.nsa.gov/selinux>) + and recommendations for BIND security , which are more secure than running named in a chroot and make use of the bind-chroot environment unnecessary . @@ -1365,8 +1365,7 @@ rand_irqs="3 14 15" See also - http://people.freebsd.org/~dougb/randomness.html - + <http://people.freebsd.org/~dougb/randomness.html>. @@ -1388,7 +1387,7 @@ rand_irqs="3 14 15" - http://blogs.sun.com/roller/page/anay/Weblog?catname=%2FSolaris + <http://blogs.sun.com/roller/page/anay/Weblog?catname=%2FSolaris> From d87ad693fc0e91168da01f887cc6ae318b6b7f3e Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 2 Jun 2008 00:17:39 +0000 Subject: [PATCH 113/137] 2377. [bug] Address race condition in dnssec-signzone. [RT #18142] --- CHANGES | 2 ++ bin/dnssec/dnssec-signzone.c | 21 +++++++++++---------- 2 files changed, 13 insertions(+), 10 deletions(-) diff --git a/CHANGES b/CHANGES index 8687d1cd42..7693295fbf 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,5 @@ +2377. [bug] Address race condition in dnssec-signzone. [RT #18142] + 2376. [bug] Change #2144 was not complete. 2375. [placeholder] diff --git a/bin/dnssec/dnssec-signzone.c b/bin/dnssec/dnssec-signzone.c index a0a123053b..536afbb5b7 100644 --- a/bin/dnssec/dnssec-signzone.c +++ b/bin/dnssec/dnssec-signzone.c @@ -29,7 +29,7 @@ * IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: dnssec-signzone.c,v 1.204 2007/08/28 07:20:42 tbox Exp $ */ +/* $Id: dnssec-signzone.c,v 1.205 2008/06/02 00:17:39 marka Exp $ */ /*! \file */ @@ -141,7 +141,6 @@ static dns_name_t *gorigin; /* The database origin */ static isc_task_t *master = NULL; static unsigned int ntasks = 0; static isc_boolean_t shuttingdown = ISC_FALSE, finished = ISC_FALSE; -static unsigned int assigned = 0, completed = 0; static isc_boolean_t nokeys = ISC_FALSE; static isc_boolean_t removefile = ISC_FALSE; static isc_boolean_t generateds = ISC_FALSE; @@ -1237,16 +1236,19 @@ assignwork(isc_task_t *task, isc_task_t *worker) { dns_rdataset_t nsec; isc_boolean_t found; isc_result_t result; + static unsigned int ended = 0; /* Protected by namelock. */ if (shuttingdown) return; + LOCK(&namelock); if (finished) { - if (assigned == completed) { + ended++; + if (ended == ntasks) { isc_task_detach(&task); isc_app_shutdown(); } - return; + goto unlock; } fname = isc_mem_get(mctx, sizeof(dns_fixedname_t)); @@ -1256,7 +1258,6 @@ assignwork(isc_task_t *task, isc_task_t *worker) { name = dns_fixedname_name(fname); node = NULL; found = ISC_FALSE; - LOCK(&namelock); while (!found) { result = dns_dbiterator_current(gdbiter, &node, name); if (result != ISC_R_SUCCESS) @@ -1283,14 +1284,14 @@ assignwork(isc_task_t *task, isc_task_t *worker) { fatal("failure iterating database: %s", isc_result_totext(result)); } - UNLOCK(&namelock); if (!found) { - if (assigned == completed) { + ended++; + if (ended == ntasks) { isc_task_detach(&task); isc_app_shutdown(); } isc_mem_put(mctx, fname, sizeof(dns_fixedname_t)); - return; + goto unlock; } sevent = (sevent_t *) isc_event_allocate(mctx, task, SIGNER_EVENT_WORK, @@ -1301,7 +1302,8 @@ assignwork(isc_task_t *task, isc_task_t *worker) { sevent->node = node; sevent->fname = fname; isc_task_send(worker, ISC_EVENT_PTR(&sevent)); - assigned++; + unlock: + UNLOCK(&namelock); } /*% @@ -1324,7 +1326,6 @@ writenode(isc_task_t *task, isc_event_t *event) { isc_task_t *worker; sevent_t *sevent = (sevent_t *)event; - completed++; worker = (isc_task_t *)event->ev_sender; dumpnode(dns_fixedname_name(sevent->fname), sevent->node); cleannode(gdb, gversion, sevent->node); From 8a680487db94a0656a0498a867841e5a93f408de Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 2 Jun 2008 00:26:20 +0000 Subject: [PATCH 114/137] 2377. [bug] Address race condition in dnssec-signzone. [RT #18142] --- CHANGES | 2 ++ bin/dnssec/dnssec-signzone.c | 21 +++++++++++---------- 2 files changed, 13 insertions(+), 10 deletions(-) diff --git a/CHANGES b/CHANGES index 4f2f341fc2..1241d56c03 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,5 @@ +2377. [bug] Address race condition in dnssec-signzone. [RT #18142] + 2376. [bug] Change #2144 was not complete. 2375. [security] Fully randomize UDP query ports to improve diff --git a/bin/dnssec/dnssec-signzone.c b/bin/dnssec/dnssec-signzone.c index 10e1133660..4d35f98f8f 100644 --- a/bin/dnssec/dnssec-signzone.c +++ b/bin/dnssec/dnssec-signzone.c @@ -16,7 +16,7 @@ * IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: dnssec-signzone.c,v 1.139.2.2.4.29 2008/01/30 01:51:54 marka Exp $ */ +/* $Id: dnssec-signzone.c,v 1.139.2.2.4.30 2008/06/02 00:26:20 marka Exp $ */ #include @@ -117,7 +117,6 @@ static dns_name_t *gorigin; /* The database origin */ static isc_task_t *master = NULL; static unsigned int ntasks = 0; static isc_boolean_t shuttingdown = ISC_FALSE, finished = ISC_FALSE; -static unsigned int assigned = 0, completed = 0; static isc_boolean_t nokeys = ISC_FALSE; static isc_boolean_t removefile = ISC_FALSE; static isc_boolean_t generateds = ISC_FALSE; @@ -1094,16 +1093,19 @@ assignwork(isc_task_t *task, isc_task_t *worker) { dns_rdataset_t nsec; isc_boolean_t found; isc_result_t result; + static unsigned int ended = 0; /* Protected by namelock. */ if (shuttingdown) return; + LOCK(&namelock); if (finished) { - if (assigned == completed) { + ended++; + if (ended == ntasks) { isc_task_detach(&task); isc_app_shutdown(); } - return; + goto unlock; } fname = isc_mem_get(mctx, sizeof(dns_fixedname_t)); @@ -1113,7 +1115,6 @@ assignwork(isc_task_t *task, isc_task_t *worker) { name = dns_fixedname_name(fname); node = NULL; found = ISC_FALSE; - LOCK(&namelock); while (!found) { result = dns_dbiterator_current(gdbiter, &node, name); if (result != ISC_R_SUCCESS) @@ -1140,14 +1141,14 @@ assignwork(isc_task_t *task, isc_task_t *worker) { fatal("failure iterating database: %s", isc_result_totext(result)); } - UNLOCK(&namelock); if (!found) { - if (assigned == completed) { + ended++; + if (ended == ntasks) { isc_task_detach(&task); isc_app_shutdown(); } isc_mem_put(mctx, fname, sizeof(dns_fixedname_t)); - return; + goto unlock; } sevent = (sevent_t *) isc_event_allocate(mctx, task, SIGNER_EVENT_WORK, @@ -1158,7 +1159,8 @@ assignwork(isc_task_t *task, isc_task_t *worker) { sevent->node = node; sevent->fname = fname; isc_task_send(worker, ISC_EVENT_PTR(&sevent)); - assigned++; + unlock: + UNLOCK(&namelock); } /* @@ -1181,7 +1183,6 @@ writenode(isc_task_t *task, isc_event_t *event) { isc_task_t *worker; sevent_t *sevent = (sevent_t *)event; - completed++; worker = (isc_task_t *)event->ev_sender; dumpnode(dns_fixedname_name(sevent->fname), sevent->node); cleannode(gdb, gversion, sevent->node); From 4d0520004a9663324a6a30f2d1716565e6d0024c Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Mon, 2 Jun 2008 23:30:31 +0000 Subject: [PATCH 115/137] newcopyrights --- util/copyrights | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/util/copyrights b/util/copyrights index 46937bdef3..af79cc1a20 100644 --- a/util/copyrights +++ b/util/copyrights @@ -69,7 +69,7 @@ ./bin/dnssec/dnssec-keygen.docbook SGML 2000,2001,2002,2003,2004,2005,2007 ./bin/dnssec/dnssec-keygen.html HTML DOCBOOK ./bin/dnssec/dnssec-signzone.8 MAN DOCBOOK -./bin/dnssec/dnssec-signzone.c C.NAI 1999,2000,2001,2002,2003,2004,2005,2006,2007 +./bin/dnssec/dnssec-signzone.c C.NAI 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008 ./bin/dnssec/dnssec-signzone.docbook SGML 2000,2001,2002,2003,2004,2005,2006,2007 ./bin/dnssec/dnssec-signzone.html HTML DOCBOOK ./bin/dnssec/dnssectool.c C 2000,2001,2003,2004,2005,2007 From 177bcb466ba55485da65017a2f5b0293a1925ee0 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Mon, 2 Jun 2008 23:47:04 +0000 Subject: [PATCH 116/137] update copyright notice --- bin/dnssec/dnssec-signzone.c | 30 +++++++++++++++--------------- 1 file changed, 15 insertions(+), 15 deletions(-) diff --git a/bin/dnssec/dnssec-signzone.c b/bin/dnssec/dnssec-signzone.c index 536afbb5b7..2297682172 100644 --- a/bin/dnssec/dnssec-signzone.c +++ b/bin/dnssec/dnssec-signzone.c @@ -1,5 +1,5 @@ /* - * Portions Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC") + * Portions Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC") * Portions Copyright (C) 1999-2003 Internet Software Consortium. * * Permission to use, copy, modify, and/or distribute this software for any @@ -29,7 +29,7 @@ * IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: dnssec-signzone.c,v 1.205 2008/06/02 00:17:39 marka Exp $ */ +/* $Id: dnssec-signzone.c,v 1.206 2008/06/02 23:47:04 tbox Exp $ */ /*! \file */ @@ -981,7 +981,7 @@ active_node(dns_dbnode_t *node) { fatal("rdataset iteration failed: %s", isc_result_totext(result)); } else { - /* + /* * Delete RRSIGs for types that no longer exist. */ result = dns_db_allrdatasets(gdb, node, gversion, 0, &rdsiter2); @@ -1206,7 +1206,7 @@ signapex(void) { dns_fixedname_t fixed; dns_name_t *name; isc_result_t result; - + dns_fixedname_init(&fixed); name = dns_fixedname_name(&fixed); result = dns_dbiterator_current(gdbiter, &node, name); @@ -1619,7 +1619,7 @@ writeset(const char *prefix, dns_rdatatype_t type) { unsigned char dsbuf[DNS_DS_BUFFERSIZE]; unsigned char keybuf[DST_KEY_MAXSIZE]; unsigned int filenamelen; - const dns_master_style_t *style = + const dns_master_style_t *style = (type == dns_rdatatype_dnskey) ? masterstyle : dsstyle; isc_buffer_init(&namebuf, namestr, sizeof(namestr)); @@ -1832,13 +1832,13 @@ print_stats(isc_time_t *timer_start, isc_time_t *timer_finish) { printf("Signatures successfully verified: %10d\n", nverified); printf("Signatures unsuccessfully verified: %10d\n", nverifyfailed); runtime_ms = runtime_us / 1000; - printf("Runtime in seconds: %7u.%03u\n", - (unsigned int) (runtime_ms / 1000), + printf("Runtime in seconds: %7u.%03u\n", + (unsigned int) (runtime_ms / 1000), (unsigned int) (runtime_ms % 1000)); if (runtime_us > 0) { sig_ms = ((isc_uint64_t)nsigned * 1000000000) / runtime_us; printf("Signatures per second: %7u.%03u\n", - (unsigned int) sig_ms / 1000, + (unsigned int) sig_ms / 1000, (unsigned int) sig_ms % 1000); } } @@ -1938,7 +1938,7 @@ main(int argc, char *argv[]) { fatal("jitter must be numeric and positive"); break; - case 'l': + case 'l': dns_fixedname_init(&dlv_fixed); len = strlen(isc_commandline_argument); isc_buffer_init(&b, isc_commandline_argument, len); @@ -2104,7 +2104,7 @@ main(int argc, char *argv[]) { result = dns_master_stylecreate(&dsstyle, DNS_STYLEFLAG_NO_TTL, 0, 24, 0, 0, 0, 8, mctx); check_result(result, "dns_master_stylecreate"); - + gdb = NULL; TIME_NOW(&timer_start); @@ -2126,8 +2126,8 @@ main(int argc, char *argv[]) { DST_TYPE_PRIVATE, mctx, &newkey); if (result != ISC_R_SUCCESS) - fatal("cannot load dnskey %s: %s", argv[i], - isc_result_totext(result)); + fatal("cannot load dnskey %s: %s", argv[i], + isc_result_totext(result)); key = ISC_LIST_HEAD(keylist); while (key != NULL) { @@ -2135,7 +2135,7 @@ main(int argc, char *argv[]) { if (dst_key_id(dkey) == dst_key_id(newkey) && dst_key_alg(dkey) == dst_key_alg(newkey) && dns_name_equal(dst_key_name(dkey), - dst_key_name(newkey))) + dst_key_name(newkey))) { if (!dst_key_isprivate(dkey)) fatal("cannot sign zone with " @@ -2164,7 +2164,7 @@ main(int argc, char *argv[]) { mctx, &newkey); if (result != ISC_R_SUCCESS) fatal("cannot load dnskey %s: %s", dskeyfile[i], - isc_result_totext(result)); + isc_result_totext(result)); key = ISC_LIST_HEAD(keylist); while (key != NULL) { @@ -2172,7 +2172,7 @@ main(int argc, char *argv[]) { if (dst_key_id(dkey) == dst_key_id(newkey) && dst_key_alg(dkey) == dst_key_alg(newkey) && dns_name_equal(dst_key_name(dkey), - dst_key_name(newkey))) + dst_key_name(newkey))) { /* Override key flags. */ key->issigningkey = ISC_TRUE; From 99a87dacc33f5ef02cd206bc0057c9f0b84029f4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tatuya=20JINMEI=20=E7=A5=9E=E6=98=8E=E9=81=94=E5=93=89?= Date: Wed, 4 Jun 2008 01:11:05 +0000 Subject: [PATCH 117/137] cleanup (removed meaningless condition) [RT #18144] --- lib/dns/rbtdb.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/lib/dns/rbtdb.c b/lib/dns/rbtdb.c index 85942971a9..135f9774de 100644 --- a/lib/dns/rbtdb.c +++ b/lib/dns/rbtdb.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: rbtdb.c,v 1.260 2008/05/01 18:23:07 jinmei Exp $ */ +/* $Id: rbtdb.c,v 1.261 2008/06/04 01:11:05 jinmei Exp $ */ /*! \file */ @@ -2059,7 +2059,7 @@ findnode(dns_db_t *db, dns_name_t *name, isc_boolean_t create, need_relock = ISC_FALSE; NODE_WEAKLOCK(&rbtdb->node_locks[node->locknum].lock, isc_rwlocktype_read); - if (ISC_LINK_LINKED(node, deadlink) && isc_rwlocktype_write) + if (ISC_LINK_LINKED(node, deadlink)) need_relock = ISC_TRUE; else if (!ISC_LIST_EMPTY(rbtdb->deadnodes[node->locknum]) && locktype == isc_rwlocktype_write) From b09318463a313540df459650f199f2d3764ef7a2 Mon Sep 17 00:00:00 2001 From: Jeremy Reed Date: Wed, 4 Jun 2008 22:32:53 +0000 Subject: [PATCH 118/137] Remove trailing (extra) comma in enum. Fixes "Unexpected" error with AIX cc (and probably other old compilers). As reported on bind-users and confirmed by original poster. This is for bugs ticket #18151. --- lib/isc/include/isc/socket.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/lib/isc/include/isc/socket.h b/lib/isc/include/isc/socket.h index 44587d5237..3a310fdc6e 100644 --- a/lib/isc/include/isc/socket.h +++ b/lib/isc/include/isc/socket.h @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: socket.h,v 1.72 2007/06/18 23:47:44 tbox Exp $ */ +/* $Id: socket.h,v 1.73 2008/06/04 22:32:53 jreed Exp $ */ #ifndef ISC_SOCKET_H #define ISC_SOCKET_H 1 @@ -146,7 +146,7 @@ typedef enum { isc_sockettype_udp = 1, isc_sockettype_tcp = 2, isc_sockettype_unix = 3, - isc_sockettype_fdwatch = 4, + isc_sockettype_fdwatch = 4 } isc_sockettype_t; /*@{*/ From ba291c35f734eb307495f13a073bdd12f725c23e Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Wed, 4 Jun 2008 23:30:27 +0000 Subject: [PATCH 119/137] newcopyrights --- util/copyrights | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/util/copyrights b/util/copyrights index af79cc1a20..599c228f13 100644 --- a/util/copyrights +++ b/util/copyrights @@ -2151,7 +2151,7 @@ ./lib/isc/include/isc/sha1.h C 2000,2001,2004,2005,2006,2007 ./lib/isc/include/isc/sha2.h C 2005,2006,2007 ./lib/isc/include/isc/sockaddr.h C 1998,1999,2000,2001,2002,2003,2004,2005,2006,2007 -./lib/isc/include/isc/socket.h C 1998,1999,2000,2001,2002,2004,2005,2006,2007 +./lib/isc/include/isc/socket.h C 1998,1999,2000,2001,2002,2004,2005,2006,2007,2008 ./lib/isc/include/isc/stdio.h C 2000,2001,2004,2005,2006,2007 ./lib/isc/include/isc/stdlib.h C 2003,2004,2005,2006,2007 ./lib/isc/include/isc/string.h C 2000,2001,2003,2004,2005,2006,2007 From 97c432334e93e63a5ac12ea4403e29017312235c Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Wed, 4 Jun 2008 23:47:11 +0000 Subject: [PATCH 120/137] update copyright notice --- lib/isc/include/isc/socket.h | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/lib/isc/include/isc/socket.h b/lib/isc/include/isc/socket.h index 3a310fdc6e..c3558fed7b 100644 --- a/lib/isc/include/isc/socket.h +++ b/lib/isc/include/isc/socket.h @@ -1,5 +1,5 @@ /* - * Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC") + * Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC") * Copyright (C) 1998-2002 Internet Software Consortium. * * Permission to use, copy, modify, and/or distribute this software for any @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: socket.h,v 1.73 2008/06/04 22:32:53 jreed Exp $ */ +/* $Id: socket.h,v 1.74 2008/06/04 23:47:11 tbox Exp $ */ #ifndef ISC_SOCKET_H #define ISC_SOCKET_H 1 @@ -780,7 +780,7 @@ isc_socket_cleanunix(isc_sockaddr_t *addr, isc_boolean_t active); isc_result_t isc_socket_permunix(isc_sockaddr_t *sockaddr, isc_uint32_t perm, - isc_uint32_t owner, isc_uint32_t group); + isc_uint32_t owner, isc_uint32_t group); /*%< * Set ownership and file permissions on the UNIX domain socket. * From c7357336cbd31a854d941bb464448e373d9f1a71 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Thu, 5 Jun 2008 01:08:22 +0000 Subject: [PATCH 121/137] new draft --- ... => draft-ietf-dnsext-axfr-clarify-08.txt} | 1840 +++++++++-------- ...aft-ietf-dnsop-default-local-zones-05.txt} | 166 +- 2 files changed, 1035 insertions(+), 971 deletions(-) rename doc/draft/{draft-ietf-dnsext-axfr-clarify-07.txt => draft-ietf-dnsext-axfr-clarify-08.txt} (61%) rename doc/draft/{draft-ietf-dnsop-default-local-zones-03.txt => draft-ietf-dnsop-default-local-zones-05.txt} (84%) diff --git a/doc/draft/draft-ietf-dnsext-axfr-clarify-07.txt b/doc/draft/draft-ietf-dnsext-axfr-clarify-08.txt similarity index 61% rename from doc/draft/draft-ietf-dnsext-axfr-clarify-07.txt rename to doc/draft/draft-ietf-dnsext-axfr-clarify-08.txt index c3e536601e..91dd61379c 100644 --- a/doc/draft/draft-ietf-dnsext-axfr-clarify-07.txt +++ b/doc/draft/draft-ietf-dnsext-axfr-clarify-08.txt @@ -1,888 +1,952 @@ -INTERNET-DRAFT Edward Lewis -draft-ietf-dnsext-axfr-clarify-07.txt NeuStar, Inc. -DNSEXT WG February 2008 -Updates: 1034, 1035 (if approved) Intended status: Standards Track - - DNS Zone Transfer Protocol (AXFR) -Status of this Memo - - By submitting this Internet-Draft, each author represents that any - applicable patent or other IPR claims of which he or she is aware - have been or will be disclosed, and any of which he or she becomes - aware will be disclosed, in accordance with Section 6 of BCP 79. - - Internet-Drafts are working documents of the Internet Engineering - Task Force (IETF), its areas, and its working groups. Note that - other groups may also distribute working documents as Internet- - Drafts. - - Internet-Drafts are draft documents valid for a maximum of six months - and may be updated, replaced, or obsoleted by other documents at any - time. It is inappropriate to use Internet-Drafts as reference - material or to cite them other than as "work in progress." - - The list of current Internet-Drafts can be accessed at - http://www.ietf.org/ietf/1id-abstracts.txt. - - The list of Internet-Draft Shadow Directories can be accessed at - http://www.ietf.org/shadow.html. - - This Internet-Draft will expire on September 1, 2008. - -Copyright Notice - - Copyright (C) The IETF Trust (2008). - -Abstract - -The Domain Name System standard facilities for maintaining coherent -servers for a zone consist of three elements. The Authoritative -Transfer (AXFR) is defined in RFC 1034 and RFC 1035. The Incremental -Zone Transfer (IXFR) is defined in RFC 1995. A mechanism for prompt -notification of zone changes (NOTIFY) is defined in RFC 1996. The base -definition of these facilities, that of the AXFR, has proven -insufficient in detail, resulting in no implementation complying with -it. Yet today we have a satisfactory set of implementations that do -interoperate. This document is a new definition of the AXFR, new in the -sense that is it recording an accurate definition of an interoperable -AXFR mechanism. - -1 Introduction - -The Domain Name System standard facilities for maintaining coherent -servers for a zone consist of three elements. Authoritative -Transfer (AXFR) is defined in "Domain Names - Concepts and Facilities" -[RFC1034] (referred to in this document as RFC 1034) and "Domain Names -- Implementation and Specification" [RFC1035] (aka RFC 1035). -Incremental Zone Transfer (IXFR) is defined in "Incremental Zone -Transfer in DNS" [RFC1995]. A mechanism for prompt notification of zone -changes (NOTIFY) is defined in "A Mechanism for Prompt Notification of -Zone Changes (DNS NOTIFY)" [RFC1996]. The goal of these mechanisms is -to enable a set of DNS name servers to remain coherently authoritative -for a given zone. - -Comments on this draft ought to be addressed to the editor or to -namedroppers@ops.ietf.org. - -1.1 Definition of Terms - -The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", -"SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this -document are to be interpreted as described in "Key words for use in -RFCs to Indicate Requirement Levels" [BCP14]. - -"Newer"/"New DNS and "older"/"old" DNS refers to implementations -written after and prior to the publication of this document. - -1.2 Scope - -In the greater context, there are many ways to achieve coherency among a -set of name servers. These mechanisms form just one, the one defined in -the RFCs cited. For example, there are DNS implementations that -assemble answers from data stored in commercial (as opposed to open -source, etc.) database instances, and rely on the database's -proprietary or otherwise external-to-DNS means to synchronize the -database instances. Some of these non-DNS solutions might even -interoperate in some fashion. As far as it is known, AXFR, IXFR, and -NOTIFY are the only mechanisms that provide an interoperable solution -to the desire for coherency within the definition of DNS, they -certainly are the only mechanisms documented by the IETF. - -This document does not cover incoherent DNS situations. There are -applications of the DNS in which servers for a zone are designed to be -incoherent. For these configurations, a coherency mechanism as -described here would be unsuitable. - -"General purpose DNS implementation" refers to DNS software developed -for wide-spread use. This includes resolvers and servers freely -accessible as libraries and standalone processes. This also includes -proprietary implementations used only in support of DNS service -offerings. - -"Turnkey DNS implementation" refers to custom made, single use -implementations of DNS. Such implementations consist of software -that employes the DNS protocol message format yet do not conform to -the entire range of DNS functionality. - -A DNS implementation is not required to support AXFR, IXFR, and NOTIFY. -A DNS implementation SHOULD have some means for maintaining name server -coherency. A general purpose DNS implementation SHOULD include AXFR, -IXFR, and NOTIFY, but turnkey DNS implementations MAY operate without -it. - -1.3 Context - -Besides describing the mechanisms themselves, there is the context in -which they operate to consider. When AXFR, IXFR, and NOTIFY were -defined, there was little consideration given to security and privacy -issues. Since the original definition of AXFR, new opinions have -appeared on the access to an entire zone's contents. In this document, -the basic mechanisms will be discussed separately from the permission to -use these mechanisms. - -1.4 Coverage - -This document concentrates on just the definition of AXFR. Any effort -to update the IXFR or NOTIFY mechanisms would be done in different -documents. This is not strictly a clarification of the definition in -RFC 1034 and RFC 1035. This document will update those sections, and -invalidate at least one part of that definition. The goal of this -document is to define AXFR as it exists, or is supposed to exist, -currently. - -2 AXFR Messages - -An AXFR message exchange (or session) consists of an AXFR query message -and a set of AXFR response messages. In this document, AXFR client is -the sender of the AXFR query and the AXFR server is the responder. (Use -of terms such as master, slave, primary, secondary are not important to -defining the AXFR exchange.) The reason for the imbalance in number of -messages derives from large zones whose contents cannot be fit into the -limited permissible size of a DNS message. - -An important aspect to keep in mind is that the definition of AXFR is -restricted to TCP [RFC0793]. The design of the AXFR process has certain -inherit features that are not easily ported to UDP [RFC0768]. -Nonetheless, AXFR over UDP has some potential use cases. AXFR over UDP -is not defined here and might some day appear in an extension document. - -The basic format of an AXFR message is the DNS message as defined in RFC -1035, Section 4 ("MESSAGES") [RFC1035], updated by the following: -- "A Mechanism for Prompt Notification of Zone Changes (...)" [RFC1996] -- "Domain Name System (DNS) IANA Considerations" [RFC2929] -- "Dynamic Updates in the Domain Name System (DNS UPDATE)" [RFC2136] -- "Extension Mechanisms for DNS (EDNS0)" [RFC2671] -- "Secret Key Transaction Authentication for DNS (TSIG)" [RFC2845] -- "Secret Key Establishment for DNS (TKEY RR)" [RFC2930] -- "Obsoleting IQUERY" [RFC3425] -- "Protocol Modifications for the DNS Security Extensions" [RFC4035] -- "HMAC SHA TSIG Algorithm Identifiers" [RFC4635] - -The upper limit on the permissible size of a DNS message is defined in -RFC 1035, section 2.3.4, and supplemented in RFC 2671, section 4.5. -The limit on the permissible size of a DNS message will be referenced -a few times in this document. - -Field names used in this document will correspond to the names as they -appear in the IANA registry for DNS Header Flags [DNSFLGS]. - -2.1 AXFR query - -An AXFR query is sent by a client whenever there is a reason to ask. -This might be because of zone maintenance activities or as a result of -a command line request, say for debugging. - -2.1.1 Header Values - -These are the DNS message header values for an AXFR query. - -ID See note 2.1.1.a -QR MUST be 0 (Query) -OPCODE MUST be 0 (Standard Query) -AA See note 2.1.1.b -TC See note 2.1.1.b -RD See note 2.1.1.b -RA See note 2.1.1.b -Z See note 2.1.1.c -AD See note 2.1.1.b -CD See note 2.1.1.b -RCODE MUST be 0 (No error) -QDCOUNT MUST be 1 -ANCOUNT MUST be 0 -NSCOUNT MUST be 0 -ARCOUNT See note 2.1.1.d - -Note 2.1.1.a Set to any value that the client desires. There -is no specific means for selecting the value in this field. However, -consideration can be given to making it harder for forged messages to be -accepted by referencing the work in progress "Measures for making DNS -more resilient against forged answers" [FORGERY]. - -Note 2.1.1.b The value in this field has no meaning in the context of -AXFR query messages. For the client, it is RECOMMENDED that the -value be zero. For the server, it is RECOMMENDED ignoring this value. - -Note 2.1.1.c The client MUST set to 0, the server MUST ignore. - -Note 2.1.1.d The value MAY be 0, 1 or 2. If it is 2, the additional -section MUST contain both an EDNS0 [RFC2671] OPT resource record and -a record carrying transaction integrity and authentication data, -currently a choice of TSIG [RFC2845] and SIG(0) [RFC2931]. If the -value is 1, then the additional section MUST contain either only an -EDNS0 OPT resource record or a record carrying transaction integrity -and authentication data. If the value is 0, the additional section -MUST be empty. - -2.1.2 Query Section - -The Query section of the AXFR query MUST conform to section 4.1.2 of RFC -1035, and contain the following values: - -QNAME the name of the zone requested -QTYPE AXFR [DNSVALS], see the registry for the numeric value -QCLASS the class of the zone requested - -2.1.3 Answer Section - -MUST be empty. - -2.1.4 Authority Section - -MUST be empty. - -2.1.5 Additional Section - -The client MAY include an EDNS0 OPT resource record. If the server -has indicated that it does not support EDNS0, the client MUST send -this section without an EDNS0 OPT resource record if there is a retry. - -The client MAY include a transaction integrity and authentication -resource record, currently a choice of TSIG or SIG(0). If the server -has indicated that it does not recognize the resource record, the client -MUST send this section without such a resource record if there is a -retry. - -If the client is aware that the server does not support EDNS0, it is -RECOMMENDED that this section be sent without the OPT resource record. -If the client is aware that the server will not participate in TSIG or -SIG(0), it is RECOMMENDED that the client not try to send such a record. -In general, if an AXFR client is aware that an AXFR server does not -support a particular mechanism, the client SHOULD NOT attempt to engage -the server using the mechanism. A client MAY become aware of a server's -abilities via a configuration setting. - -2.2 AXFR response - -The AXFR response will consist of 0 or more messages. - -An AXFR response that is transferring the zone's contents will consist -of a series of DNS messages bounded in size by the limited permissible -size. In such a series, the first message MUST begin with the SOA -resource record of the zone, the last message MUST conclude with the -same SOA resource record. Intermediate message MUST NOT contain the -SOA resource record. The first message MUST copy the Query Section -from the corresponding AXFR query message in to the first response -message's query section. Subsequent messages MAY do the same. - -An AXFR response that is indicating an error MUST consist of a single -DNS message with the return code set to the appropriate value for the -condition encountered. Such a message MUST copy the AXFR query -Query Section into its Query Section. - -An AXFR client MUST be able to react to no AXFR response Messages from -the server. An AXFR server MAY elect to silently discard the AXFR -query but this is only RECOMMENDED if the server has reasons to deduce -that the query was sent maliciously. - -An AXFR server MAY elect to close the underlying TCP connection in -response to an AXFR query. Because this action could impact other -DNS queries and responses, it is RECOMMENDED that this tactic only be -employed when there are strong indications of malicious activity. -Still, an AXFR client MUST be able to adequately react to this -situation. - -2.2.1 Header Values - -ID See note 2.2.1.a -QR MUST be 1 (Response) -OPCODE MUST be 0 (Standard Query) -AA See note 2.2.1.b -TC MUST be 0 (Not truncated) -RD RECOMMENDED copy request's value, MAY be set to 0 -RA See note 2.2.1.c -Z See note 2.2.1.d -AD See note 2.2.1.e -CD See note 2.2.1.e -RCODE See note 2.2.1.f -QDCOUNT MUST be 1 in the first message; MUST be 0 or 1 in all - following -ANCOUNT See note 2.2.1.g -NSCOUNT MUST be 0 -ARCOUNT See note 2.2.1.h - -Note 2.2.1.a Because of old implementations, the requirement -on this section is stated in detail. New DNS servers MUST set this -field to the value of the AXFR query ID in each AXFR response message -for the session. New AXFR clients MUST be able to accept sessions in -which the responses do not have the same ID field. - -If a client detects or is aware that the server is new, that is, all of -the responses have the same ID value as the query, the client MAY issue -other DNS queries (of any type) to the server using the same transport. -Unless the client is sure that the server will consistently set the ID -field to the query's ID, the client is NOT RECOMMENDED to issue any -other queries until the end of the zone transfer. A client MAY become -aware of a server's abilities via a configuration setting. - -Note 2.2.1.b If the RCODE is 0 (no error), then the AA bit MUST be 1. -For any other value of RCODE, the AA bit MUST be set according to rules -for that error code. If in doubt, it is RECOMMENDED that is be set -to 1. It is RECOMMENDED that the value be ignored by the AXFR client. - -Note 2.2.1.c It is RECOMMENDED that the server set the value to 0, -it is RECOMMENDED that the client ignore this value. - -The server MAY set this value according to the local policy regarding -recursive service, but doing so might confuse the interpretation of the -response as AXFR can not be retrieved recursively. A client MAY note -the server's policy regarding recursive from this value, but SHOULD NOT -conclude that the AXFR response was obtained recursively even if the RD -bit was 1 in the query. - -Note 2.2.1.d The server MUST set to 0, and the client MUST ignore. - -Note 2.2.1.e If the implementation supports the DNS Security Extensions -(see below) then this value MUST be set according to the rules in RFC -4035, section 3.1.6, "The AD and CD Bits in an Authoritative Response". -If the implementation does not support the DNS Security Extensions, then -this value MUST be set to 0 and MUST be ignored upon receipt. - -The DNS Security Extensions (DNSSEC) is defined in these base documents: -- "DNS Security Introduction and Requirements" [RFC4033] -- "Resource Records for the DNS Security Extensions" [RFC4034] -- "Protocol Modifications for the DNS Security Extensions" [RFC4035] - -Note 2.2.1.f In the absence of an error, the server MUST set the value -of this field to NoError. If a server is not authoritative for the -queried zone, the server SHOULD set the value to NotAuth. (Reminder, -consult the appropriate IANA registry [DNSVALS].) If a client -receives any other value in response, it MUST act according to the -error. For example, a malformed AXFR query or the presence of an EDNS0 -OPT resource record sent to an old server will garner a FormErr value. -This value is not set as part of the AXFR response processing. The same -is true for other error-indicating values. - -Note 2.2.1.g The count of answer records MUST equal the number of -resource records in the AXFR Answer Section. When a server is aware -that a client will only accept one resource record per response message, -then the value MUST be 1. A server MAY be made aware of a client's -limitations via configuration data. - -Note 2.2.1.h The value MAY be 0, 1 or 2. If it is 2, the additional -section MUST contain both an EDNS0 [RFC2671] OPT resource record and -a record carrying transaction integrity and authentication data, -currently a choice of TSIG [RFC2845] and SIG(0) [RFC2931]. If the -value is 1, then the additional section MUST contain either only an -EDNS0 OPT resource record or a record carrying transaction integrity -and authentication data. If the value is 0, the additional section -MUST be empty. - -2.2.2 Query Section - -In the first response message, this section MUST be copied from the -query. In subsequent messages this section MAY be copied from the -query, MAY be empty. The content of this section MAY be used to -determine the context of the message, that is, the name of the zone -being transferred. - -2.2.3 Answer Section - -MUST be populated with the zone contents. See later section on encoding -zone contents. - -2.2.4 Authority Section - -MUST be empty. - -2.2.5 Additional Section - -The contents of this section MUST follow the guidelines for EDNS0, TSIG, -SIG(0), or what ever other future record is possible here. See the -appropriate specifications for instructions and restrictions. - -3 Zone Contents - -The objective of the AXFR session is to request and transfer the -contents of a zone. The objective is to permit the client to -reconstruct the zone as it exists at the server for the given zone -serial number. Over time the definition of a zone has evolved from a -static set of records to a dynamically updated set of records to a -continually regenerated set of records. - -3.1 Records to Include - -In the answer section of AXFR response messages the resource records -within a zone for the given serial number MUST appear. The definition -of what belongs in a zone is described in RFC 1034, Section 4.2, "How -the database is divided into zones", and in particular, section 4.2.1, -"Technical considerations". - -The first resource record of the first AXFR response message sent by the -AXFR server MUST be the zone's SOA resource record. The last resource -record of the final AXFR response message sent by the AXFR server MUST -be the zone's SOA resource record. The order and grouping of all other -records in the AXFR is arbitrary, but the AXFR server SHOULD group -resource record sets together. - -Unless the AXFR server knows that the AXFR client expects just one -resource record per AXFR response message, an AXFR server SHOULD -populate an AXFR response message with as many complete resource records -as will fit within the limited permissible message size. - -Zones for which it is impractical to list the entire zones for a serial -number (because changes happen too quickly) are not suitable for AXFR -retrieval. - -3.2 Delegation Records - -In RFC 1034, section 4.2.1, this text appears (keep in mind that the use -of the word "should" in the quotation is exempt from the interpretation -in section 1.1) "The RRs that describe cuts ... should be exactly the -same as the corresponding RRs in the top node of the subzone." There -has been some controversy over this statement and the impact on which -NS resource records are included in a zone transfer. - -The phrase "that describe cuts" is a reference to the NS set and -applicable glue records. It does not mean that the cut points and the -apex resource records are identical. For example, the SOA resource -record is only found at the apex, as well as a slew of DNSSEC resource -records. There are also some DNSSEC resource record sets that are -explicitly different between the cut point and the apex. The -discussion here is restricted to just the NS resource record set and -glue as these "describe cuts." - -The issue is that in operations there are times when the NS resource -records for a zone might be different at a cut point in the parent and -at the apex of a zone. Sometimes this is the result of an error and -sometimes it is part of an ongoing change in name servers. The DNS -protocol is robust enough to overcome inconsistencies up to there being -no parent indicated NS resource record referencing a server that is able -to serve the child zone. This robustness is one quality that has -fueled the success of the DNS. Still, the inconsistency is a error -state and steps need to be taken to make it apparent (if it is -unplanned) and to make it clear once the inconsistency has been removed. - -Another issue is that the AXFR server could be authoritative for a -different set of zones than the AXFR client. It is possible that the -AXFR server be authoritative for both halves of an inconsistent cut -point and that the AXFR client is authoritative for just the parent of -the cut point. - -The question that arises is, when facing a situation in which a cut -point's NS resource records do not match the authoritative set, whether -an AXFR server responds with the NS resource record set that is in the -zone or is at the authoritative location. - -The AXFR response MUST contain the cut point NS resource record set -registered with the zone whether it agrees with the authoritative set or -not. "Registered with" can be widely interpreted to include data -residing in the zone file of the zone for the particular serial -number (in zone file environments) or as any data configured to be in -the zone (database), statically or dynamically. - -The reasons for this requirement are: - -1) The AXFR server might not be able to determine that there is an -inconsistency given local data, hence requiring consistency would mean -a lot more needed work and even network retrieval of data. An -authoritative server ought not be required to perform any queries. - -2) By transferring the inconsistent NS resource records from a server -that is authoritative for both the cut point and the apex to a client -that is not authoritative for both, the error is exposed. For example, -an authorized administrator can manually request the AXFR and inspect -the results to see the inconsistent records. (A server authoritative -for both halves would otherwise always answer from the more -authoritative set, concealing the error.) - -3) The inconsistent NS resource record set might indicate a problem in a -registration database. - -3.3 Glue Records - -As quoted in the previous section, RFC 1034, section 4.2.1, provides -guidance and rationale for the inclusion of glue records as part of -an AXFR transfer. And, as also argued in the previous section of this -document, even when there is an inconsistency between the address in a -glue record and the authoritative copy of the name server's address, -the glue resource record that is registered as part of the zone for -that serial number is to be included. - -This applies for glue records for any address family. - -The AXFR response MUST contain the appropriate glue records as -registered with the zone. The interpretation of "registered with" -in the previous section applies here. Inconsistent glue records are -an operational matter. - -3.4 Name Compression - -Compression of names in DNS messages is described in RFC 1035, section -4.1.4, "Message compression". The issue highlighted here relates to a -comment made in RFC 1034, section 3.1, "Name space specifications and -terminology" which says "When you receive a domain name or label, you -should preserve its case." ("Should" in the quote predates [BCP14].) - -Name compression in an AXFR message MUST preserve the case of the -original domain name. That is, although when comparing a domain name, -"a" equals "A", when comparing for the purposes of message comparison, -"a" is not equal to "A". - -Name compression of RDATA in an AXFR message MAY only be done on -resource record types which explicitly permit such compression. - -4 Transport - -AXFR sessions are restricted by RFC 1034, section 4.3.5's "because -accuracy is essential, TCP or some other reliable protocol must be used -for AXFR requests." The most common scenario is for an AXFR client -to open a TCP connection to the AXFR server, send an AXFR query, -receive the AXFR response, and then close the connection. There are -variations on this, such as a query for the zone's SOA resource -record first, and so on. - -Two issues have emerged since the original specification of AXFR. -One is that lack of specificity has yielded some implementations -that assume the TCP connection is dedicated to the single AXFR -session, which has led to implementation choices that prevent either -multiple concurrent zone transfers or the use of the open connection -for other queries. The other issue is the prospect of using UDP as a -transport has come to look promising because of trends in the past -two decades. - -Being able to have multiple concurrent zone transfers is considered -desirable by operators who have sets of name servers that are -authoritative for a common set of zones. It would be desirable -if the name server implementations did not have to wait for one -zone to transfer before the next could begin. The desire here is to -tighten the specification, not a change, but adding words to the -unclear areas, to define what is needed to permit two servers to -share a TCP connection among concurrent AXFR sessions. The challenge -is to design this in a way that can fallback to the old behavior if -either the AXFR client or AXFR server is incapable of performing -multiple concurrent AXFR sessions. - -With the addition of EDNS0 and applications which require many -small zones such as in web hosting and some ENUM scenarios, AXFR -sessions on UDP are now possible and desirable. However, there -are still some aspects of the AXFR session that are not easily -translated to UDP. This document leaves AXFR over UDP undefined, -with the issue to be discussed and possibly appear in a separate -definition. - -4.1 TCP - -In the original definition there is an implicit assumption (probably -unintentional) that a TCP connection is used for one and only one -AXFR session. This is evidenced in no requirement to copy neither -the Query Section nor the message ID in responses, no explicit -ordering information within the AXFR response messages and the lack -of an explicit notice indicating that a zone transfer continues in the -next message. - -The guidance given here is intended to enable better performance of -the AXFR exchange as well as guidelines on interactions with older -software. Better performance includes being able to multiplex DNS -message exchanges including zone transfer sessions. Guidelines for -interacting with older software are generally applicable to AXFR -clients as reversing the situation, older AXFR client and newer -AXFR server ought to induce the server to operate within the -specification for an older server. - -4.1.1 AXFR client TCP - -An AXFR client MAY request an connection to an AXFR server upon any -demand. An AXFR client SHOULD close the connection when there is -no apparent need to use the connection for some time period. This -latter comment is made so that the AXFR server does not have -to keep open idle connections, and placing the planning for a -connection closure on the client. Apparent need for the connection -is a judgement for the AXFR client and the DNS client in general, if -the connection is used for multiple sessions, or it is know sessions -will be coming, or is there is other query/response traffic on the -open connection, that is "apparent need." - -An AXFR client MAY cancel delivery of a zone only by closing the -connection. However, this action will also cancel all other outstanding -activity using the connection. There is no other mechanism by which -an AXFR response can be cancelled. - -When a TCP connection is closed remotely (relative to the client), -whether by the AXFR server or due to a network event, the AXFR client -MUST cancel all outstanding sessions. Recovery from this situation -is not straightforward. If the disruption was a spurious event, -attempting to restart the connection would be proper. If the -disruption was caused by a medium or long term disruption, the AXFR -client would be wise to not spend too many resources trying to rebuild -the connection. Finally, if the connection was dropped because of a -policy at the AXFR server (as can be the case with older AXFR servers), -the AXFR client would be wise not retry the connection. Unfortunately, -knowing which of the three cases above applies is not clear -(momentary disruption, failure, policy). - -An AXFR client MAY use an already opened TCP connection to start an -AXFR session. Using an existing open connection is RECOMMENDED over -opening a new connection. (Non AXFR session traffic can also use an -open connection.) If in doing so that the AXFR client realizes that -the responses cannot be properly differentiated (lack of matching -query IDs for example) or the connection is terminated for a remote -reason, then the AXFR client SHOULD not attempt to reuse an open -connection with the specific AXFR server until the AXFR server is -updated (which is of course, not an event captured in the DNS protocol). - -4.1.2 AXFR server TCP - -An AXFR server MUST be able to handle multiple AXFR sessions on a -single TCP connection, as well as handle other query/response sessions. - -If a TCP connection is closed remotely, the AXFR server MUST cancel -all AXFR sessions in place. No retry activity is necessary, that is -initiated by the AXFR client. - -Local policy MAY dictate that a TCP connection is to be closed. Such -as action SHOULD be in reaction to limits such as those placed on -the number of outstanding open connections. Closing a connection in -response to a suspected security event SHOULD be done only in extreme -cases, when the server is certain the action is warranted. An -isolated request for a zone not on the AXFR server SHOULD receive -a response with the appropriate return code and not see the connection -broken. - -4.2 UDP - -AXFR sessions over UDP transport are not defined. - -5 Authorization - -A zone administrator has the option to restrict AXFR access to a zone. -This was not envisioned in the original design of the DNS but has -emerged as a requirement as the DNS has evolved. Restrictions on AXFR -could be for various reasons including a desire (or in some instances, -having a legal requirement) to keep the bulk version of the zone -concealed or to prevent the servers from handling the load incurred in -serving AXFR. All reasons are arguable, but the fact remains that -there is a requirement to provide mechanisms to restrict AXFR. - -A DNS implementation SHOULD provide means to restrict AXFR sessions to -specific clients. By default, a DNS implementation SHOULD only allow -the designated authoritative servers to have access to the zone. - -An implementation SHOULD allow access to be granted to Internet Protocol -addresses and ranges, regardless of whether a source address could be -spoofed. Combining this with techniques such as Virtual Private -Networks (VPN) [RFC2764] or Virtual LANs has proven to be effective. - -A general purpose implementation is RECOMMENDED to implement access -controls based upon "Secret Key Transaction Authentication for DNS" -[RFC2845] and/or "DNS Request and Transaction Signatures ( SIG(0)s )" -[RFC2931]. - -A general purpose implementation SHOULD allow access to be open to -all AXFR requests. I.e., an operator ought to be able to allow any -AXFR query to be granted. - -A general purpose implementation SHOULD NOT have a default policy -for AXFR requests to be "open to all." - -6 Zone Integrity - -Ensuring that an AXFR client does not accept a forged copy of a zone is -important to the security of a zone. If a zone operator has the -opportunity, protection can be afforded via dedicated links, physical or -virtual via a VPN among the authoritative servers. But there are -instances in which zone operators have no choice but to run AXFR -sessions over the global public Internet. - -Besides best attempts at securing TCP sessions, DNS implementations -SHOULD provide means to make use of "Secret Key Transaction -Authentication for DNS" [RFC2845] and/or "DNS Request and Transaction -Signatures ( SIG(0)s )" [RFC2931] to allow AXFR clients to verify the -contents. These techniques MAY also be used for authorization. - -7 Backwards Compatibility - -Describing backwards compatibility is difficult because of a lack of -specifics in the original definition. In this section some hints at -building in backwards compatibility are given, mostly repeated from the -earlier sections. - -Backwards compatibility is not necessary, but the greater extent of an -implementation's compatibility increases it's interoperability. For -turnkey implementations this is not usually a concern. For general -purpose implementations this takes on varying levels of importance -depending on the implementers desire to maintain interoperability. - -It is unfortunate that needs to fall back to older behavior cannot be -discovered, hence need to be noted in a configuration file. An -implementation SHOULD, in it's documentation, encourage operators to -periodically review AXFR clients and servers it has made notes about as -old software periodically gets updated. - -7.1 Server - -An AXFR server has the luxury of being able to react to an AXFR client's -abilities with the exception of knowing if the client can accept -multiple resource records per AXFR response message. The knowledge that -a client is so restricted apparently cannot be discovered, hence it has -to be set by configuration. - -An implementation of an AXFR server SHOULD permit configuring, on a per -AXFR client basis, a need to revert to single resource record per -message. The default SHOULD be to use multiple records per message. - -7.2 Client - -An AXFR client has the opportunity to try extensions when querying an -AXFR server. - -The use of EDNS0 to increase the DNS message size, offer authorizing -proof, or to invoke message integrity can be tried and rejected by the -AXFR server via the methods already described as part of the EDNS0 -mechanism. - -If an AXFR client attempts to use the UDP transport, non-response from -the AXFR server or other error message can indicate not to retry that. - -Attempting to issue multiple DNS queries over a TCP transport for an -AXFR session SHOULD be aborted if it interrupts the original request and -SHOULD take into consideration whether the AXFR server intends to close -the connection immediately upon completion of the original -(connection-causing) zone transfer. - -8 Security Considerations - -Concerns regarding authorization, traffic flooding, and message -integrity are mentioned in "Authorization" (section 5), "TCP" (section -4.2) and Zone Integrity (section 6). - -9 IANA Considerations - -No new registries or new registrations are included in this document. - -10 Internationalization Considerations - -It is assumed that supporting of international domain names has been -solved via "Internationalizing Domain Names in Applications (IDNA)" -[RFC3490]. - -11 Acknowledgements - -Earlier editions of this document have been edited by Andreas -Gustafsson. In his latest version, this acknowledgement appeared. - -"Many people have contributed input and commentary to earlier versions -of this document, including but not limited to Bob Halley, Dan -Bernstein, Eric A. Hall, Josh Littlefield, Kevin Darcy, Robert Elz, -Levon Esibov, Mark Andrews, Michael Patton, Peter Koch, Sam Trenholme, -and Brian Wellington." - -Comments since the -05 version have come from these individuals: -Alfred Hoenes, Mark Andrews, Paul Vixie, Wouter Wijngaards, Iain -Calder, Tony Finch, Ian Jackson, ... - -12 References - -All references prefixed by "RFC" can be obtained from the RFC Editor, -information regarding this organization can be found at the following -URL: - http://rfc-editor.org/ -Additionally, these documents can be obtained via the IETF web site. - -12.1 Normative - -[RFC0793] "Transmission Control Protocol." J. Postel. September 1981. -[RFC0768] "User Datagram Protocol. " J. Postel. August 1980. -[RFC1034] "Domain names - concepts and facilities.", P.V. Mockapetris. - Nov-01-1987. -[RFC1035] "Domain names - implementation and specification." P.V. - Mockapetris. Nov-01-1987. -[RFC1995] "Incremental Zone Transfer in DNS." M. Ohta. August 1996. -[RFC1996] "A Mechanism for Prompt Notification of Zone Changes (DNS - NOTIFY)." P. Vixie. August 1996. -[RFC2136] "Dynamic Updates in the Domain Name System (DNS UPDATE)." - P. Vixie, Ed., S. Thomson, Y. Rekhter, J. Bound. April 1997. -[RFC2671] "Extension Mechanisms for DNS (EDNS0)." P. Vixie. - August 1999. -[RFC2845] "Secret Key Transaction Authentication for DNS (TSIG)." - P. Vixie, O. Gudmundsson, D. Eastlake, B. Wellington. - May 2000. -[RFC2929] "Domain Name System (DNS) IANA Considerations." D. Eastlake - 3rd, E. Brunner-Williams, B. Manning. September 2000. -[RFC2930] "Secret Key Establishment for DNS (TKEY RR)." D. Eastlake. - September 2000. -[RFC2931] "DNS Request and Transaction Signatures ( SIG(0)s)." - D. Eastlake. September 2000. -[RFC3425] "Obsoleting IQUERY." D. Lawrence. November 2002. -[RFC4033] "DNS Security Introduction and Requirements." - R. Arends, R. Austein, M. Larson, D. Massey, S. Rose. March - 2005. -[RFC4034] "Resource Records for the DNS Security Extensions." - R. Arends, R. Austein, M. Larson, D. Massey, S. Rose. March - 2005. -[RFC4035] "Protocol Modifications for the DNS Security Extensions." - R. Arends, R. Austein, M. Larson, D. Massey, S. Rose. March - 2005. -[RFC4635] "HMAC SHA (Hashed Message Authentication Code, Secure Hash - Algorithm) TSIG Algorithm Identifiers." D. Eastlake 3rd. - August 2006. -[DNSFLGS] http://www.iana.org/assignments/dns-header-flags -[DNSVALS] http://www.iana.org/assignments/dns-parameters - -12.2 Informative - -[BCP14] "Key words for use in RFCs to Indicate Requirement Levels." - S. Bradner. March 1997. -[RFC2764] "A Framework for IP Based Virtual Private Networks." B. - Gleeson, A. Lin, J. Heinanen, G. Armitage, A. Malis. - February 2000. -[RFC3490] "Internationalizing Domain Names in Applications (IDNA)." P. - Faltstrom, P. Hoffman, A. Costello. March 2003. -[FORGERY] "Measures for making DNS more resilient against forged - answers." A. Hubert, R. van Mook. Work in Progress. - http://www.ietf.org/internet-drafts/ - draft-ietf-dnsext-forgery-resilience-01.txt - -13 Editor's Address - -Edward Lewis -46000 Center Oak Plaza -Sterling, VA, 22033, US -+1-571-434-5468 -ed.lewis@neustar.biz - -Full Copyright Statement - - Copyright (C) The IETF Trust (2008). - - This document is subject to the rights, licenses and restrictions - contained in BCP 78, and except as set forth therein, the authors - retain all their rights. - - This document and the information contained herein are provided on an - "AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS - OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY, THE IETF TRUST AND - THE INTERNET ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS - OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF - THE INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED - WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. - -Intellectual Property - - The IETF takes no position regarding the validity or scope of any - Intellectual Property Rights or other rights that might be claimed to - pertain to the implementation or use of the technology described in - this document or the extent to which any license under such rights - might or might not be available; nor does it represent that it has - made any independent effort to identify any such rights. Information - on the procedures with respect to rights in RFC documents can be - found in BCP 78 and BCP 79. - - Copies of IPR disclosures made to the IETF Secretariat and any - assurances of licenses to be made available, or the result of an - attempt made to obtain a general license or permission for the use of - such proprietary rights by implementers or users of this - specification can be obtained from the IETF on-line IPR repository at - http://www.ietf.org/ipr. - - The IETF invites any interested party to bring to its attention any - copyrights, patents or patent applications, or other proprietary - rights that may cover technology that may be required to implement - this standard. Please address the information to the IETF at - ietf-ipr@ietf.org. - -Acknowledgment - - Funding for the RFC Editor function is provided by the IETF - Administrative Support Activity (IASA). - - +INTERNET-DRAFT Edward Lewis +draft-ietf-dnsext-axfr-clarify-08.txt NeuStar, Inc. +DNSEXT WG June 2008 +Updates: 1034, 1035 (if approved) Intended status: Standards Track + + DNS Zone Transfer Protocol (AXFR) +Status of this Memo + +By submitting this Internet-Draft, each author represents that any +applicable patent or other IPR claims of which he or she is aware +have been or will be disclosed, and any of which he or she becomes +aware will be disclosed, in accordance with Section 6 of BCP 79. + +Internet-Drafts are working documents of the Internet Engineering +Task Force (IETF), its areas, and its working groups. Note that +other groups may also distribute working documents as Internet- +Drafts. + +Internet-Drafts are draft documents valid for a maximum of six months +and may be updated, replaced, or obsoleted by other documents at any +time. It is inappropriate to use Internet-Drafts as reference +material or to cite them other than as "work in progress." + +The list of current Internet-Drafts can be accessed at +http://www.ietf.org/ietf/1id-abstracts.txt. + +The list of Internet-Draft Shadow Directories can be accessed at +http://www.ietf.org/shadow.html. + +This Internet-Draft will expire on December 1, 2008. + +Copyright Notice + +Copyright (C) The IETF Trust (2008). + +Abstract + +The Domain Name System standard facilities for maintaining coherent +servers for a zone consist of three elements. The Authoritative +Transfer (AXFR) is defined in RFC 1034 and RFC 1035. The Incremental +Zone Transfer (IXFR) is defined in RFC 1995. A mechanism for prompt +notification of zone changes (NOTIFY) is defined in RFC 1996. The base +definition of these facilities, that of the AXFR, has proven +insufficient in detail, resulting in no implementation complying with +it. Yet today we have a satisfactory set of implementations that do +interoperate. This document is a new definition of the AXFR, new in the +sense that is it recording an accurate definition of an interoperable +AXFR mechanism. + +1 Introduction + +The Domain Name System standard facilities for maintaining coherent +servers for a zone consist of three elements. Authoritative +Transfer (AXFR) is defined in "Domain Names - Concepts and Facilities" +[RFC1034] (referred to in this document as RFC 1034) and "Domain Names +- Implementation and Specification" [RFC1035] (aka RFC 1035). +Incremental Zone Transfer (IXFR) is defined in "Incremental Zone +Transfer in DNS" [RFC1995]. A mechanism for prompt notification of +zone changes (NOTIFY) is defined in "A Mechanism for Prompt +Notification of Zone Changes (DNS NOTIFY)" [RFC1996]. The goal of +these mechanisms is to enable a set of DNS name servers to remain +coherently authoritative for a given zone. + +Comments on this draft ought to be addressed to the editor or to +namedroppers@ops.ietf.org. + +1.1 Definition of Terms + +The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", +"SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this +document are to be interpreted as described in "Key words for use in +RFCs to Indicate Requirement Levels" [BCP14]. + +"Newer"/"New" DNS and "older"/"old" DNS refers to implementations +written after and prior to the publication of this document. + +1.2 Scope + +In the greater context there are many ways to achieve coherency among +a set of name servers. The AXFR, IXFR and NOTIFY mechanisms form +just one, the one defined in the RFCs cited. For example, there are +DNS implementations that assemble answers from data stored in +relational databases (as opposed to master files) relying on the +database's non-DNS means to synchronize the database instances. Some +of these non-DNS solutions interoperate in some fashion. As far as +it is known, AXFR, IXFR and NOTIFY are the only mechanisms that +provide an interoperable solution to the desire for coherency within +the definition of DNS, they certainly are the only mechanisms +documented by the IETF. + +This document does not cover incoherent DNS situations. There are +applications of the DNS in which servers for a zone are designed to be +incoherent. For these configurations, a coherency mechanism as +described here would be unsuitable. + +"General purpose DNS implementation" refers to DNS software developed +for wide-spread use. This includes resolvers and servers freely +accessible as libraries and standalone processes. This also includes +proprietary implementations used only in support of DNS service +offerings. + +"Turnkey DNS implementation" refers to custom made, single use +implementations of DNS. Such implementations consist of software +that employes the DNS protocol message format yet do not conform to +the entire range of DNS functionality. + +A DNS implementation is not required to support AXFR, IXFR and NOTIFY. +A DNS implementation SHOULD have some means for maintaining name server +coherency. A general purpose DNS implementation SHOULD include AXFR, +IXFR and NOTIFY, but turnkey DNS implementations MAY operate without +it. + +1.3 Context + +Besides describing the mechanisms themselves, there is the context in +which they operate to consider. When AXFR, IXFR and NOTIFY were +defined, there was little consideration given to security and privacy +issues. Since the original definition of AXFR, new opinions have +appeared on the access to an entire zone's contents. In this document, +the basic mechanisms will be discussed separately from the permission +to use these mechanisms. + +1.4 Coverage + +This document concentrates on just the definition of AXFR. Any effort +to update the IXFR or NOTIFY mechanisms would be done in different +documents. This is not strictly a clarification of the definition in +RFC 1034 and RFC 1035. This document will update those sections, and +invalidate at least one part of that definition. The goal of this +document is to define AXFR as it exists, or is supposed to exist, +currently. + +2 AXFR Messages + +An AXFR message exchange (or session) consists of an AXFR query message +and a set of AXFR response messages. In this document, AXFR client is +the sender of the AXFR query and the AXFR server is the responder. +(Use of terms such as master, slave, primary, secondary are not +important to defining the AXFR exchange.) The reason for the imbalance +in number of messages derives from large zones whose contents cannot be +fit into the limited permissible size of a DNS message. + +An important aspect to keep in mind is that the definition of AXFR is +restricted to TCP [RFC0793]. The design of the AXFR process has +certain inherit features that are not easily ported to UDP [RFC0768]. + +The basic format of an AXFR message is the DNS message as defined in +RFC 1035, Section 4 ("MESSAGES") [RFC1035], updated by the following: +- "A Mechanism for Prompt Notification of Zone Changes (...)" [RFC1996] +- "Domain Name System (DNS) IANA Considerations" [RFC2929] +- "Dynamic Updates in the Domain Name System (DNS UPDATE)" [RFC2136] +- "Extension Mechanisms for DNS (EDNS0)" [RFC2671] +- "Secret Key Transaction Authentication for DNS (TSIG)" [RFC2845] +- "Secret Key Establishment for DNS (TKEY RR)" [RFC2930] +- "Obsoleting IQUERY" [RFC3425] +- "Handling of Unknown DNS Resource Record (RR) Types" [RFC3597] +- "Protocol Modifications for the DNS Security Extensions" [RFC4035] +- "HMAC SHA TSIG Algorithm Identifiers" [RFC4635] + +The upper limit on the permissible size of a DNS message over TCP is +defined in RFC 1035, section 4.2.2. Unlike DNS messages over UDP, +this limit is not changed by EDNS0. + +Field names used in this document will correspond to the names as they +appear in the IANA registry for DNS Header Flags [DNSFLGS]. + +2.1 AXFR query + +An AXFR query is sent by a client whenever there is a reason to ask. +This might be because of zone maintenance activities or as a result of +a command line request, say for debugging. + +2.1.1 Header Values + +These are the DNS message header values for an AXFR query. + +ID See note 2.1.1.a +QR MUST be 0 (Query) +OPCODE MUST be 0 (Standard Query) +AA See note 2.1.1.b +TC See note 2.1.1.b +RD See note 2.1.1.b +RA See note 2.1.1.b +Z See note 2.1.1.c +AD See note 2.1.1.b +CD See note 2.1.1.b +RCODE MUST be 0 (No error) +QDCOUNT MUST be 1 +ANCOUNT MUST be 0 +NSCOUNT MUST be 0 +ARCOUNT See note 2.1.1.d + +Note 2.1.1.a Set to any value that the client desires. There +is no specific means for selecting the value in this field. +(Recall that AXFR is done only via TCP connections.) + +Note 2.1.1.b The value in this field has no meaning in the context of +AXFR query messages. For the client, it is RECOMMENDED that the +value be zero. The server MUST ignore this value. + +Note 2.1.1.c The client MUST set to 0, the server MUST ignore. + +Note 2.1.1.d The value MAY be 0, 1 or 2. If it is 2, the additional +section MUST contain both an EDNS0 [RFC2671] OPT resource record and +a record carrying transaction integrity and authentication data, +currently a choice of TSIG [RFC2845] and SIG(0) [RFC2931]. If the +value is 1, then the additional section MUST contain either only an +EDNS0 OPT resource record or a record carrying transaction integrity +and authentication data. If the value is 0, the additional section +MUST be empty. + +A note on "future proofing" this document. It is possible that in the +future more records might be introduced that share the property of +being placed in the additional section. Such records might be other +options to, say, TSIG and SIG(0) for message authentication or may +be completely unrelated to that service. In any case, each new record +that might appear in the additional section might expand the range of +values that this field can take on. As predicting the future is still +an unproven field, further details are not available. Check back +later for updates. + +2.1.2 Query Section + +The Query section of the AXFR query MUST conform to section 4.1.2 of +RFC 1035, and contain the following values: + +QNAME the name of the zone requested +QTYPE AXFR(= 252), the pseudo-RR type for zone transfer [DNSVALS] +QCLASS the class of the zone requested + +2.1.3 Answer Section + +MUST be empty. + +2.1.4 Authority Section + +MUST be empty. + +2.1.5 Additional Section + +The client MAY include an EDNS0 OPT resource record. If the server +has indicated that it does not support EDNS0, the client MUST send +this section without an EDNS0 OPT resource record if there is a retry. +Indication that a server does not support EDNS0 is not an explicit +element in the protocol, it is up to the client to interpret. Most +likely, the server will return a FORMERR which might be related to +the OPT resource record. + +The client MAY include a transaction integrity and authentication +resource record, currently a choice of TSIG or SIG(0). If the server +has indicated that it does not recognize the resource record, and +that the error is indeed caused by the resource record, the client +probably ought not try again. Removing the security data in the +face of an obstacle ought to only be done with full awareness of the +implication of doing so. + +In general, if an AXFR client is aware that an AXFR server does not +support a particular mechanism, the client SHOULD NOT attempt to engage +the server using the mechanism (or at all). A client MAY become aware +of a server's abilities via a configuration setting. + +2.2 AXFR response + +The AXFR response will consist of 0 or more messages. + +A 0 message response is very exceptional. It is unhealthy for there +to be 0 responses in a protocol that is designed around a query - +response paradigm. A 0 message response is reserved for situations in +which the server has a reason to suspect that the query is sent for +the purpose of abuse. Therefore any earnest query has the expectation +of some response. + +An AXFR response that is transferring the zone's contents will consist +of a series of DNS messages bounded in size by the limited permissible +size. In such a series, the first message MUST begin with the SOA +resource record of the zone, the last message MUST conclude with the +same SOA resource record. Intermediate message MUST NOT contain the +SOA resource record. The first message MUST copy the Query Section +from the corresponding AXFR query message in to the first response +message's query section. Subsequent messages MAY do the same. + +Editorial note "MAY" or SHOULD/are RECOMMENDED TO + +An AXFR response that is indicating an error MUST consist of a single +DNS message with the return code set to the appropriate value for the +condition encountered - once the error condition is detected. Such +a message MUST copy the AXFR query Query Section into its Query +Section. + +An AXFR client might receive a number of AXFR response messages +free of an error condition before the message indicating the error +is received. But once an error is reported, the AXFR client can +assume this the reporting message is the last. + +An AXFR client MUST be able to react to no AXFR response messages from +the server. An AXFR server MAY elect to silently discard the AXFR +query but this is only RECOMMENDED if the server has reasons to deduce +that the query was sent maliciously. + +An AXFR server MAY elect to close the underlying TCP connection in +response to an AXFR query. Because this action could impact other +DNS queries and responses, it is RECOMMENDED that this tactic only be +employed when there are strong indications of malicious activity. +Still, an AXFR client MUST be able to adequately react to this +situation. + +2.2.1 Header Values + +ID See note 2.2.1.a +QR MUST be 1 (Response) +OPCODE MUST be 0 (Standard Query) +AA See note 2.2.1.b +TC MUST be 0 (Not truncated) +RD RECOMMENDED copy request's value, MAY be set to 0 +RA See note 2.2.1.c +Z See note 2.2.1.d +AD See note 2.2.1.e +CD See note 2.2.1.e +RCODE See note 2.2.1.f +QDCOUNT MUST be 1 in the first message; MUST be 0 or 1 in all + following +ANCOUNT See note 2.2.1.g +NSCOUNT MUST be 0 +ARCOUNT See note 2.2.1.h + +Note 2.2.1.a Because of old implementations, the requirement +on this section is stated in detail. New DNS servers MUST set this +field to the value of the AXFR query ID in each AXFR response message +for the session. New AXFR clients MUST be able to accept sessions in +which the responses do not have the same ID field. + +If a client detects or is aware that the server is new, that is, all of +the responses have the same ID value as the query, the client MAY issue +other DNS queries (of any type) to the server using the same transport. +Unless the client is sure that the server will consistently set the ID +field to the query's ID, the client is NOT RECOMMENDED to issue any +other queries until the end of the zone transfer. A client MAY become +aware of a server's abilities via a configuration setting. + +Note 2.2.1.b If the RCODE is 0 (no error), then the AA bit MUST be 1. +For any other value of RCODE, the AA bit MUST be set according to rules +for that error code. If in doubt, it is RECOMMENDED that is be set +to 1. It is RECOMMENDED that the value be ignored by the AXFR client. + +Note 2.2.1.c It is RECOMMENDED that the server set the value to 0, +the client MUST ignore this value. + +The server MAY set this value according to the local policy regarding +recursive service, but doing so might confuse the interpretation of the +response as AXFR can not be retrieved recursively. A client MAY note +the server's policy regarding recursive from this value, but SHOULD NOT +conclude that the AXFR response was obtained recursively even if the RD +bit was 1 in the query. + +Note 2.2.1.d The server MUST set to 0, and the client MUST ignore. + +Note 2.2.1.e If the implementation supports the DNS Security Extensions +(see below) then this value MUST be set according to the rules in RFC +4035, section 3.1.6, "The AD and CD Bits in an Authoritative Response". +If the implementation does not support the DNS Security Extensions, +then this value MUST be set to 0 and MUST be ignored upon receipt. + +The DNS Security Extensions (DNSSEC) is defined in these base +documents: +- "DNS Security Introduction and Requirements" [RFC4033] +- "Resource Records for the DNS Security Extensions" [RFC4034] +- "Protocol Modifications for the DNS Security Extensions" [RFC4035] + +Note 2.2.1.f In the absence of an error, the server MUST set the value +of this field to NoError. If a server is not authoritative for the +queried zone, the server SHOULD set the value to NotAuth. (Reminder, +consult the appropriate IANA registry [DNSVALS].) If a client +receives any other value in response, it MUST act according to the +error. For example, a malformed AXFR query or the presence of an EDNS0 +OPT resource record sent to an old server will garner a FormErr value. +This value is not set as part of the AXFR response processing. The +same is true for other error-indicating values. + +Note 2.2.1.g The count of answer records MUST equal the number of +resource records in the AXFR Answer Section. When a server is aware +that a client will only accept one resource record per response +message, then the value MUST be 1. A server MAY be made aware of a +client's limitations via configuration data. + +Note 2.2.1.h The value MAY be 0, 1 or 2. If it is 2, the additional +section MUST contain both an EDNS0 [RFC2671] OPT resource record and +a record carrying transaction integrity and authentication data, +currently a choice of TSIG [RFC2845] and SIG(0) [RFC2931]. If the +value is 1, then the additional section MUST contain either only an +EDNS0 OPT resource record or a record carrying transaction integrity +and authentication data. If the value is 0, the additional section +MUST be empty. + +A note on "future proofing" this document. It is possible that in the +future more records might be introduced that share the property of +being placed in the additional section. Such records might be other +options to, say, TSIG and SIG(0), for message authentication or may +be completely unrelated to that service. In any case, each new record +that might appear in the additional section might expand the range of +values that this field can take on. As predicting the future is still +an unproven field, further details are not available. Check back +later for updates. + +2.2.2 Query Section + +In the first response message, this section MUST be copied from the +query. In subsequent messages this section MAY be copied from the +query, MAY be empty. The content of this section MAY be used to +determine the context of the message, that is, the name of the zone +being transferred. + +2.2.3 Answer Section + +MUST be populated with the zone contents. See later section on +encoding zone contents. + +2.2.4 Authority Section + +MUST be empty. + +2.2.5 Additional Section + +The contents of this section MUST follow the guidelines for EDNS0, +TSIG, SIG(0), or what ever other future record is possible here. See +the appropriate specifications for instructions and restrictions. + +3 Zone Contents + +The objective of the AXFR session is to request and transfer the +contents of a zone. The objective is to permit the client to +reconstruct the zone as it exists at the server for the given zone +serial number. Over time the definition of a zone has evolved from a +static set of records to a dynamically updated set of records to a +continually regenerated set of records. + +3.1 Records to Include + +In the answer section of AXFR response messages the resource records +within a zone for the given serial number MUST appear. The definition +of what belongs in a zone is described in RFC 1034, Section 4.2, "How +the database is divided into zones", and in particular, section 4.2.1, +"Technical considerations". + +The first resource record of the first AXFR response message sent by +the AXFR server MUST be the zone's SOA resource record. The last +resource record of the final AXFR response message sent by the AXFR +server MUST be the zone's SOA resource record. The order and grouping +of all other records in the AXFR is arbitrary, but the AXFR server +SHOULD group resource record sets together. + +Unless the AXFR server knows that the AXFR client expects just one +resource record per AXFR response message, an AXFR server SHOULD +populate an AXFR response message with as many complete resource +records as will fit within the limited permissible message size. + +Zones for which it is impractical to list the entire zones for a serial +number (because changes happen too quickly) are not suitable for AXFR +retrieval. + +3.2 Delegation Records + +In RFC 1034, section 4.2.1, this text appears (keep in mind that the +"should" in the quotation predates [BCP14], cf. section 1.1) "The RRs +that describe cuts ... should be exactly the same as the corresponding +RRs in the top node of the subzone." There has been some controversy +over this statement and the impact on which NS resource records are +included in a zone transfer. + +The phrase "that describe cuts" is a reference to the NS set and +applicable glue records. It does not mean that the cut points and the +apex resource records are identical. For example, the SOA resource +record is only found at the apex, as well as a slew of DNSSEC resource +records. There are also some DNSSEC resource record sets that are +explicitly different between the cut point and the apex. The +discussion here is restricted to just the NS resource record set and +glue as these "describe cuts." + +The issue is that in operations there are times when the NS resource +records for a zone might be different at a cut point in the parent and +at the apex of a zone. Sometimes this is the result of an error and +sometimes it is part of an ongoing change in name servers. The DNS +protocol is robust enough to overcome inconsistencies up to (but not +including) there being no parent indicated NS resource record +referencing a server that is able to serve the child zone. This +robustness is one quality that has fueled the success of the DNS. +Still, the inconsistency is a error state and steps need to be taken +to make it apparent (if it is unplanned) and to make it clear once +the inconsistency has been removed. + +Another issue is that the AXFR server could be authoritative for a +different set of zones than the AXFR client. It is possible that the +AXFR server be authoritative for both halves of an inconsistent cut +point and that the AXFR client is authoritative for just the parent of +the cut point. + +The question that arises is, when facing a situation in which a cut +point's NS resource records do not match the authoritative set, whether +an AXFR server responds with the NS resource record set that is in the +zone or is at the authoritative location. + +The AXFR response MUST contain the cut point NS resource record set +registered with the zone whether it agrees with the authoritative set +or not. "Registered with" can be widely interpreted to include data +residing in the zone file of the zone for the particular serial +number (in zone file environments) or as any data configured to be in +the zone (database), statically or dynamically. + +The reasons for this requirement are: + +1) The AXFR server might not be able to determine that there is an +inconsistency given local data, hence requiring consistency would mean +a lot more needed work and even network retrieval of data. An +authoritative server ought not be required to perform any queries. + +2) By transferring the inconsistent NS resource records from a server +that is authoritative for both the cut point and the apex to a client +that is not authoritative for both, the error is exposed. For example, +an authorized administrator can manually request the AXFR and inspect +the results to see the inconsistent records. (A server authoritative +for both halves would otherwise always answer from the more +authoritative set, concealing the error.) + +3) The inconsistent NS resource record set might indicate a problem +in a registration database. + +4) Beginning with an error state of two servers for a zone having +inconsistent zone contents for a given zone serial number, if a client +requests and recieves an IXFR transfer from one server followed by +another IXFR transfer from the other server, the client can encounter +an IXFR protocol error state where an attempt is made to incrementally +add a record that already exists or to delete a record that does not +exist. + +(Editorial note, the 4th reason was suggested, but I don't see how +it relates. A nudge for updated text on this.) + +3.3 Glue Records + +As quoted in the previous section, RFC 1034, section 4.2.1, provides +guidance and rationale for the inclusion of glue records as part of +an AXFR transfer. And, as also argued in the previous section of this +document, even when there is an inconsistency between the address in a +glue record and the authoritative copy of the name server's address, +the glue resource record that is registered as part of the zone for +that serial number is to be included. + +This applies for glue records for any address family. + +The AXFR response MUST contain the appropriate glue records as +registered with the zone. The interpretation of "registered with" +in the previous section applies here. Inconsistent glue records are +an operational matter. + +3.4 Name Compression + +Compression of names in DNS messages is described in RFC 1035, section +4.1.4, "Message compression". The issue highlighted here relates to a +comment made in RFC 1034, section 3.1, "Name space specifications and +terminology" which says "When you receive a domain name or label, you +should preserve its case." ("Should" in the quote predates [BCP14].) + +Name compression in an AXFR message MUST preserve the case of the +original domain name. That is, although when comparing a domain name, +"a" equals "A", when comparing for the purposes of message compression, +"a" is not equal to "A". Note that this is not the usual definition +of name comparison in the DNS protocol and represents a new +requirement on AXFR servers. + +Rules governing name compression of RDATA in an AXFR message MUST +abide by the specification in "Handling of Unknown DNS Resource Record +(RR) Types" [RFC3597], specifically, section 4 on "Domain Name +Compression." + +3.5 Occluded Names + +Dynamic Update [RFC2136] (and including DNAME [2672]) operations can +have a side effect of occluding names in a zone. The addition of a +delegation point via dynamic update will render all subordinate domain +names to be in a limbo, still part of the zone but not available for to +the look up process. The addition of a DNAME resource record set has +the same impact. The subordinate names are said to be "occluded." + +Occluded names MUST be included in AXFR responses. An AXFR client MUST +be able to identify and handle occluded names. The rationale for this +action is based on a speedy recovery if the dynamic update operation +was in error and is to be undone. + +4 Transport + +AXFR sessions are currently restricted to TCP by section 4.3.5 of RFC +1034 that states: "Because accuracy is essential, TCP or some other +reliable protocol must be used for AXFR requests." The most common +scenario is for an AXFR client to open a TCP connection to the AXFR +server, send an AXFR query, receive the AXFR response, and then +close the connection. There are variations on this, such as a query +for the zone's SOA resource record first, and so on. + +Two issues have emerged since the original specification of AXFR. +One is that lack of specificity has yielded some implementations +that assume the TCP connection is dedicated to the single AXFR +session, which has led to implementation choices that prevent either +multiple concurrent zone transfers or the use of the open connection +for other queries. The other issue is the prospect of using UDP as a +transport has come to look promising because of trends in the past +two decades. + +Being able to have multiple concurrent zone transfers is considered +desirable by operators who have sets of name servers that are +authoritative for a common set of zones. It would be desirable +if the name server implementations did not have to wait for one +zone to transfer before the next could begin. The desire here is to +tighten the specification, not a change, but adding words to the +unclear areas, to define what is needed to permit two servers to +share a TCP connection among concurrent AXFR sessions. The challenge +is to design this in a way that can fallback to the old behavior if +either the AXFR client or AXFR server is incapable of performing +multiple concurrent AXFR sessions. + +With the addition of EDNS0 and applications which require many +small zones such as in web hosting and some ENUM scenarios, AXFR +sessions on UDP are now possible and desirable. However, there +are still some aspects of the AXFR session that are not easily +translated to UDP. This document leaves AXFR over UDP undefined, +with the issue to be discussed and possibly appear in a separate +definition. + +4.1 TCP + +In the original definition there is an implicit assumption (probably +unintentional) that a TCP connection is used for one and only one +AXFR session. This is evidenced in no requirement to copy neither +the Query Section nor the message ID in responses, no explicit +ordering information within the AXFR response messages and the lack +of an explicit notice indicating that a zone transfer continues in the +next message. + +The guidance given here is intended to enable better performance of +the AXFR exchange as well as guidelines on interactions with older +software. Better performance includes being able to multiplex DNS +message exchanges including zone transfer sessions. Guidelines for +interacting with older software are generally applicable to AXFR +clients as reversing the situation, older AXFR client and newer +AXFR server ought to induce the server to operate within the +specification for an older server. + +4.1.1 AXFR client TCP + +An AXFR client MAY request an connection to an AXFR server for any +reason. An AXFR client SHOULD close the connection when there is +no apparent need to use the connection for some time period. The +AXFR server ought not to maintain idle connections, the burden of +connection closure ought to be on the client. Apparent need for +the connection is a judgement for the AXFR client and the DNS +client. If the connection is used for multiple sessions, or it is +known sessions will be coming or is there is other query/response +traffic on the open connection, that is "apparent need." + +An AXFR client MAY cancel delivery of a zone only by closing the +connection. However, this action will also cancel all other outstanding +activity using the connection. There is no other mechanism by which +an AXFR response can be cancelled. + +When a TCP connection is closed remotely (relative to the client), +whether by the AXFR server or due to a network event, the AXFR client +MUST cancel all outstanding sessions. Recovery from this situation +is not straightforward. If the disruption was a spurious event, +attempting to restart the connection would be proper. If the +disruption was caused by a medium or long term disruption, the AXFR +client would be wise to not spend too many resources trying to rebuild +the connection. Finally, if the connection was dropped because of a +policy at the AXFR server (as can be the case with older AXFR servers), +the AXFR client would be wise to not retry the connection. +Unfortunately, knowing which of the three cases above applies is not +clear (momentary disruption, failure, policy). + +An AXFR client MAY use an already opened TCP connection to start an +AXFR session. Using an existing open connection is RECOMMENDED over +opening a new connection. (Non AXFR session traffic can also use an +open connection.) If in doing so the AXFR client realizes that +the responses cannot be properly differentiated (lack of matching +query IDs for example) or the connection is terminated for a remote +reason, then the AXFR client SHOULD not attempt to reuse an open +connection with the specific AXFR server until the AXFR server is +updated (which is of course, not an event captured in the DNS +protocol). + +4.1.2 AXFR server TCP + +An AXFR server MUST be able to handle multiple AXFR sessions on a +single TCP connection, as well as handle other query/response sessions. + +If a TCP connection is closed remotely, the AXFR server MUST cancel +all AXFR sessions in place. No retry activity is necessary, that is +initiated by the AXFR client. + +Local policy MAY dictate that a TCP connection is to be closed. Such +as action SHOULD be in reaction to limits such as those placed on +the number of outstanding open connections. Closing a connection in +response to a suspected security event SHOULD be done only in extreme +cases, when the server is certain the action is warranted. An +isolated request for a zone not on the AXFR server SHOULD receive +a response with the appropriate return code and not see the connection +broken. + +4.2 UDP + +AXFR sessions over UDP transport are not defined. + +5 Authorization + +A zone administrator has the option to restrict AXFR access to a zone. +This was not envisioned in the original design of the DNS but has +emerged as a requirement as the DNS has evolved. Restrictions on AXFR +could be for various reasons including a desire (or in some instances, +having a legal requirement) to keep the bulk version of the zone +concealed or to prevent the servers from handling the load incurred in +serving AXFR. All reasons are arguable, but the fact remains that +there is a requirement to provide mechanisms to restrict AXFR. + +A DNS implementation SHOULD provide means to restrict AXFR sessions to +specific clients. By default, a DNS implementation SHOULD only allow +the designated authoritative servers to have access to the zone. + +An implementation SHOULD allow access to be granted to Internet +Protocol addresses and ranges, regardless of whether a source address +could be spoofed. Combining this with techniques such as Virtual +Private Networks (VPN) [RFC2764] or Virtual LANs has proven to be +effective. + +A general purpose implementation is RECOMMENDED to implement access +controls based upon "Secret Key Transaction Authentication for DNS" +[RFC2845] and/or "DNS Request and Transaction Signatures ( SIG(0)s )" +[RFC2931]. + +A general purpose implementation SHOULD allow access to be open to +all AXFR requests. I.e., an operator ought to be able to allow any +AXFR query to be granted. + +A general purpose implementation SHOULD NOT have a default policy +for AXFR requests to be "open to all." + +6 Zone Integrity + +Ensuring that an AXFR client does not accept a forged copy of a zone is +important to the security of a zone. If a zone operator has the +opportunity, protection can be afforded via dedicated links, physical +or virtual via a VPN among the authoritative servers. But there are +instances in which zone operators have no choice but to run AXFR +sessions over the global public Internet. + +Besides best attempts at securing TCP sessions, DNS implementations +SHOULD provide means to make use of "Secret Key Transaction +Authentication for DNS" [RFC2845] and/or "DNS Request and Transaction +Signatures ( SIG(0)s )" [RFC2931] to allow AXFR clients to verify the +contents. These techniques MAY also be used for authorization. + +7 Backwards Compatibility + +Describing backwards compatibility is difficult because of the lack of +specifics in the original definition. In this section some hints at +building in backwards compatibility are given, mostly repeated from the +earlier sections. + +Backwards compatibility is not necessary, but the greater extent of an +implementation's compatibility increases it's interoperability. For +turnkey implementations this is not usually a concern. For general +purpose implementations this takes on varying levels of importance +depending on the implementer's desire to maintain interoperability. + +It is unfortunate that a need to fall back to older behavior cannot be +discovered, hence needs to be noted in a configuration file. An +implementation SHOULD, in it's documentation, encourage operators to +periodically review AXFR clients and servers it has made notes about as +old software periodically gets updated. + +7.1 Server + +An AXFR server has the luxury of being able to react to an AXFR +client's abilities with the exception of knowing if the client can +accept multiple resource records per AXFR response message. The +knowledge that a client is so restricted apparently cannot be +discovered, hence it has to be set by configuration. + +An implementation of an AXFR server SHOULD permit configuring, on a per +AXFR client basis, a need to revert to single resource record per +message. The default SHOULD be to use multiple records per message. + +7.2 Client + +An AXFR client has the opportunity to try extensions when querying +an AXFR server. + +Attempting to issue multiple DNS queries over a TCP transport for an +AXFR session SHOULD be aborted if it interrupts the original request +and SHOULD take into consideration whether the AXFR server intends to +close the connection immediately upon completion of the original +(connection-causing) zone transfer. + +8 Security Considerations + +Concerns regarding authorization, traffic flooding, and message +integrity are mentioned in "Authorization" (section 5), "TCP" (section +4.2) and Zone Integrity (section 6). + +9 IANA Considerations + +No new registries or new registrations are included in this document. + +10 Internationalization Considerations + +It is assumed that supporting of international domain names has been +solved via "Internationalizing Domain Names in Applications (IDNA)" +[RFC3490]. + +11 Acknowledgements + +Earlier editions of this document have been edited by Andreas +Gustafsson. In his latest version, this acknowledgement appeared. + +"Many people have contributed input and commentary to earlier versions +of this document, including but not limited to Bob Halley, Dan +Bernstein, Eric A. Hall, Josh Littlefield, Kevin Darcy, Robert Elz, +Levon Esibov, Mark Andrews, Michael Patton, Peter Koch, Sam Trenholme, +and Brian Wellington." + +Comments since the -05 version have come from these individuals: +Alfred Hoenes, Mark Andrews, Paul Vixie, Wouter Wijngaards, Iain +Calder, Tony Finch, Ian Jackson, Andreas Gustafsson, Brian Wellington, +... + +12 References + +All references prefixed by "RFC" can be obtained from the RFC Editor, +information regarding this organization can be found at the following +URL: + http://rfc-editor.org/ +Additionally, these documents can be obtained via the IETF web site. + +12.1 Normative + +[RFC0793] Postel, J., "Transmission Control Protocol", STD 7, RFC 793, + September 1981. +[RFC0768] Postel, J., "User Datagram Protocol", STD 6, RFC 768, August + 1980. +[RFC1034] Mockapetris, P., "Domain names - concepts and facilities", + STD 13, RFC 1034, November 1987. +[RFC1035] Mockapetris, P., "Domain names - implementation and + specification", STD 13, RFC 1035, November 1987. +[RFC1995] Ohta, M., "Incremental Zone Transfer in DNS", RFC 1995, + August 1996. +[RFC1996] Vixie, P., "A Mechanism for Prompt Notification of Zone + Changes (DNS NOTIFY)", RFC 1996, August 1996. +[RFC2136] Vixie, P., Ed., Thomson, S., Rekhter, Y., and J. Bound, + "Dynamic Updates in the Domain Name System (DNS UPDATE)", RFC + 2136, April 1997. +[RFC2671] Vixie, P., "Extension Mechanisms for DNS (EDNS0)", RFC 2671, + August 1999. +[RFC2672] Crawford, M., "Non-Terminal DNS Name Redirection", RFC 2672, + August 1999. +[RFC2845] Vixie, P., Gudmundsson, O., Eastlake 3rd, D., and B. + Wellington, "Secret Key Transaction Authentication for DNS + (TSIG)", RFC 2845, May 2000. +[RFC2929] Eastlake 3rd, D., Brunner-Williams, E., and B. Manning, + "Domain Name System (DNS) IANA Considerations", BCP 42, RFC + 2929, September 2000. +[RFC2930] Eastlake 3rd, D., "Secret Key Establishment for DNS (TKEY + RR)", RFC 2930, September 2000. +[RFC2931] Eastlake 3rd, D., "DNS Request and Transaction Signatures + ( SIG(0)s )", RFC 2931, September 2000. +[RFC3425] Lawrence, D., "Obsoleting IQUERY", RFC 3425, November 2002. +[RFC3597] Gustafsson, A., "Handling of Unknown DNS Resource Record + (RR) Types", RFC 3597, September 2003. +[RFC4033] Arends, R., Austein, R., Larson, M., Massey, D., and S. + Rose, "DNS Security Introduction and Requirements", RFC 4033, + March 2005. +[RFC4034] Arends, R., Austein, R., Larson, M., Massey, D., and S. + Rose, "Resource Records for the DNS Security Extensions", + RFC 4034, March 2005. +[RFC4035] Arends, R., Austein, R., Larson, M., Massey, D., and S. + Rose, "Protocol Modifications for the DNS Security + Extensions", RFC 4035, March 2005. +[RFC4635] Eastlake 3rd, D., "HMAC SHA (Hashed Message Authentication + Code, Secure Hash Algorithm) TSIG Algorithm Identifiers", + RFC 4635, August 2006. +[DNSFLGS] http://www.iana.org/assignments/dns-header-flags +[DNSVALS] http://www.iana.org/assignments/dns-parameters + +12.2 Informative + +[BCP14] Bradner, S., "Key words for use in RFCs to Indicate + Requirement Levels", BCP 14, RFC 2119, March 1997. +[RFC2764] Gleeson, B., Lin, A., Heinanen, J., Armitage, G., and A. + Malis, "A Framework for IP Based Virtual Private Networks", + RFC 2764, February 2000. +[RFC3490] Faltstrom, P., Hoffman, P., and A. Costello, + "Internationalizing Domain Names in Applications (IDNA)", RFC + 3490, March 2003. + +13 Editor's Address + +Edward Lewis +46000 Center Oak Plaza +Sterling, VA, 22033, US ++1-571-434-5468 +ed.lewis@neustar.biz + +Full Copyright Statement + +Copyright (C) The IETF Trust (2008). + +This document is subject to the rights, licenses and restrictions +contained in BCP 78, and except as set forth therein, the authors +retain all their rights. + +This document and the information contained herein are provided on an +"AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS +OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY, THE IETF TRUST AND +THE INTERNET ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS +OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF +THE INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED +WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. + +Intellectual Property + +The IETF takes no position regarding the validity or scope of any +Intellectual Property Rights or other rights that might be claimed to +pertain to the implementation or use of the technology described in +this document or the extent to which any license under such rights +might or might not be available; nor does it represent that it has +made any independent effort to identify any such rights. Information +on the procedures with respect to rights in RFC documents can be +found in BCP 78 and BCP 79. + +Copies of IPR disclosures made to the IETF Secretariat and any +assurances of licenses to be made available, or the result of an +attempt made to obtain a general license or permission for the use of +such proprietary rights by implementers or users of this +specification can be obtained from the IETF on-line IPR repository at +http://www.ietf.org/ipr. + +The IETF invites any interested party to bring to its attention any +copyrights, patents or patent applications, or other proprietary +rights that may cover technology that may be required to implement +this standard. Please address the information to the IETF at +ietf-ipr@ietf.org. + +Acknowledgment + +Funding for the RFC Editor function is provided by the IETF +Administrative Support Activity (IASA). + + diff --git a/doc/draft/draft-ietf-dnsop-default-local-zones-03.txt b/doc/draft/draft-ietf-dnsop-default-local-zones-05.txt similarity index 84% rename from doc/draft/draft-ietf-dnsop-default-local-zones-03.txt rename to doc/draft/draft-ietf-dnsop-default-local-zones-05.txt index 5d47673ccb..230c036776 100644 --- a/doc/draft/draft-ietf-dnsop-default-local-zones-03.txt +++ b/doc/draft/draft-ietf-dnsop-default-local-zones-05.txt @@ -3,13 +3,12 @@ Network Working Group M. Andrews Internet-Draft ISC -Intended status: Best Current November 19, 2007 -Practice -Expires: May 22, 2008 +Intended status: BCP June 5, 2008 +Expires: December 7, 2008 Locally-served DNS Zones - draft-ietf-dnsop-default-local-zones-03 + draft-ietf-dnsop-default-local-zones-05 Status of this Memo @@ -34,11 +33,7 @@ Status of this Memo The list of Internet-Draft Shadow Directories can be accessed at http://www.ietf.org/shadow.html. - This Internet-Draft will expire on May 22, 2008. - -Copyright Notice - - Copyright (C) The IETF Trust (2007). + This Internet-Draft will expire on December 7, 2008. Abstract @@ -52,9 +47,14 @@ Abstract -Andrews Expires May 22, 2008 [Page 1] + + + + + +Andrews Expires December 7, 2008 [Page 1] -Internet-Draft Locally-served DNS Zones November 2007 +Internet-Draft Locally-served DNS Zones June 2008 Table of Contents @@ -77,12 +77,14 @@ Table of Contents 9.1. Normative References . . . . . . . . . . . . . . . . . . . 8 9.2. Informative References . . . . . . . . . . . . . . . . . . 10 Appendix A. Change History [To Be Removed on Publication] . . . . 10 - A.1. draft-ietf-dnsop-default-local-zones-03.txt . . . . . . . 10 - A.2. draft-ietf-dnsop-default-local-zones-02.txt . . . . . . . 10 - A.3. draft-ietf-dnsop-default-local-zones-01.txt . . . . . . . 10 - A.4. draft-ietf-dnsop-default-local-zones-00.txt . . . . . . . 11 - A.5. draft-andrews-full-service-resolvers-03.txt . . . . . . . 11 - A.6. draft-andrews-full-service-resolvers-02.txt . . . . . . . 11 + A.1. draft-ietf-dnsop-default-local-zones-05.txt . . . . . . . 10 + A.2. draft-ietf-dnsop-default-local-zones-04.txt . . . . . . . 10 + A.3. draft-ietf-dnsop-default-local-zones-03.txt . . . . . . . 10 + A.4. draft-ietf-dnsop-default-local-zones-02.txt . . . . . . . 10 + A.5. draft-ietf-dnsop-default-local-zones-01.txt . . . . . . . 11 + A.6. draft-ietf-dnsop-default-local-zones-00.txt . . . . . . . 11 + A.7. draft-andrews-full-service-resolvers-03.txt . . . . . . . 11 + A.8. draft-andrews-full-service-resolvers-02.txt . . . . . . . 11 Appendix B. Proposed Status [To Be Removed on Publication] . . . 11 Author's Address . . . . . . . . . . . . . . . . . . . . . . . . . 11 Intellectual Property and Copyright Statements . . . . . . . . . . 12 @@ -106,11 +108,9 @@ Table of Contents - - -Andrews Expires May 22, 2008 [Page 2] +Andrews Expires December 7, 2008 [Page 2] -Internet-Draft Locally-served DNS Zones November 2007 +Internet-Draft Locally-served DNS Zones June 2008 1. Introduction @@ -164,9 +164,9 @@ Internet-Draft Locally-served DNS Zones November 2007 -Andrews Expires May 22, 2008 [Page 3] +Andrews Expires December 7, 2008 [Page 3] -Internet-Draft Locally-served DNS Zones November 2007 +Internet-Draft Locally-served DNS Zones June 2008 2. Effects on sites using RFC 1918 addresses. @@ -215,14 +215,14 @@ Internet-Draft Locally-served DNS Zones November 2007 Below is an example of a generic empty zone in master file format. It will produce a negative cache TTL of 3 hours. - @ 10800 IN SOA @ nobody.invalid. 1 3600 1200 604800 10800 @ 10800 - IN NS @ + @ 10800 IN SOA @ nobody.invalid. 1 3600 1200 604800 10800 + @ 10800 IN NS @ -Andrews Expires May 22, 2008 [Page 4] +Andrews Expires December 7, 2008 [Page 4] -Internet-Draft Locally-served DNS Zones November 2007 +Internet-Draft Locally-served DNS Zones June 2008 The SOA RR is needed to support negative caching [RFC 2308] of name @@ -234,10 +234,9 @@ Internet-Draft Locally-served DNS Zones November 2007 SOA timer values MAY be chosen arbitrarily since they are not intended to control any zone transfer activity. - The NS RR is needed as some UPDATE clients use NS queries to discover - the zone to be updated. Having no address records for the name - server is expected to abort UPDATE [RFC 2136] processing in the - client. + The NS RR is needed as some UPDATE [RFC 2136] clients use NS queries + to discover the zone to be updated. Having no address records for + the name server is expected to abort UPDATE processing in the client. 4. Lists Of Zones Covered @@ -276,9 +275,10 @@ Internet-Draft Locally-served DNS Zones November 2007 -Andrews Expires May 22, 2008 [Page 5] + +Andrews Expires December 7, 2008 [Page 5] -Internet-Draft Locally-served DNS Zones November 2007 +Internet-Draft Locally-served DNS Zones June 2008 4.2. RFC 3330 Zones @@ -293,7 +293,7 @@ Internet-Draft Locally-served DNS Zones November 2007 1.0.0.127.IN-ADDR.ARPA locally. In fact, a meaningful reverse mapping should exist, but the exact setup is out of the scope of this document. Similar logic applies to the reverse mapping for ::1 - Section 4.3. The recommendations made here simply assume no other + (Section 4.3). The recommendations made here simply assume no other coverage for these domains exists. +------------------------------+------------------------+ @@ -332,9 +332,9 @@ Internet-Draft Locally-served DNS Zones November 2007 -Andrews Expires May 22, 2008 [Page 6] +Andrews Expires December 7, 2008 [Page 6] -Internet-Draft Locally-served DNS Zones November 2007 +Internet-Draft Locally-served DNS Zones June 2008 +--------------+ @@ -360,16 +360,16 @@ Internet-Draft Locally-served DNS Zones November 2007 5. Zones that are Out-Of-Scope - IPv6 site-local addresses, [RFC 4291] Sections 2.4 and 2.57, and IPv6 - Centrally Assigned Local [RFC 4193] addresses are not covered here. - It is expected that IPv6 site-local addresses will be self correcting - as IPv6 implementations remove support for site-local addresses. - However, sacrificial servers for C.E.F.IP6.ARPA through + IPv6 site-local addresses, [RFC 4291] Sections 2.4 and 2.5.7, and + IPv6 Non-Locally Assigned Local addresses [RFC 4193] are not covered + here. It is expected that IPv6 site-local addresses will be self + correcting as IPv6 implementations remove support for site-local + addresses. However, sacrificial servers for C.E.F.IP6.ARPA through F.E.F.IP6.ARPA may still need to be deployed in the short term if the traffic becomes excessive. - For IPv6 Centrally Assigned Local addresses (L = 0) [RFC 4193], there - has been no decision made about whether the Regional Internet + For IPv6 Non-Locally Assigned Local addresses (L = 0) [RFC 4193], + there has been no decision made about whether the Regional Internet Registries (RIRs) will provide delegations in this space or not. If they don't, then C.F.IP6.ARPA will need to be added to the list in Section 4.4. If they do, then registries will need to take steps to @@ -388,9 +388,9 @@ Internet-Draft Locally-served DNS Zones November 2007 -Andrews Expires May 22, 2008 [Page 7] +Andrews Expires December 7, 2008 [Page 7] -Internet-Draft Locally-served DNS Zones November 2007 +Internet-Draft Locally-served DNS Zones June 2008 6. IANA Considerations @@ -440,23 +440,23 @@ Internet-Draft Locally-served DNS Zones November 2007 [RFC 1034] Mockapetris, P., "DOMAIN NAMES - CONCEPTS AND FACILITIES", - RFC 1034, STD 13, November 1987. + STD 13, RFC 1034, November 1987. -Andrews Expires May 22, 2008 [Page 8] +Andrews Expires December 7, 2008 [Page 8] -Internet-Draft Locally-served DNS Zones November 2007 +Internet-Draft Locally-served DNS Zones June 2008 [RFC 1035] Mockapetris, P., "DOMAIN NAMES - IMPLEMENTATION AND - SPECIFICATION", RFC 1035, STD 13, November 1987. + SPECIFICATION", STD 13, RFC 1035, November 1987. [RFC 1918] Rekhter, Y., Moskowitz, B., Karrenberg, D., de Groot, G., and E. Lear, "Address Allocation for Private Internets", - RFC 1918, February 1996. + BCP 5, RFC 1918, February 1996. [RFC 2119] Bradner, S., "Key words for use in RFCs to Indicate @@ -500,9 +500,9 @@ Internet-Draft Locally-served DNS Zones November 2007 -Andrews Expires May 22, 2008 [Page 9] +Andrews Expires December 7, 2008 [Page 9] -Internet-Draft Locally-served DNS Zones November 2007 +Internet-Draft Locally-served DNS Zones June 2008 [RFC 4291] @@ -530,7 +530,16 @@ Internet-Draft Locally-served DNS Zones November 2007 Appendix A. Change History [To Be Removed on Publication] -A.1. draft-ietf-dnsop-default-local-zones-03.txt +A.1. draft-ietf-dnsop-default-local-zones-05.txt + + none, expiry prevention + +A.2. draft-ietf-dnsop-default-local-zones-04.txt + + Centrally Assigned Local addresses -> Non-Locally Assigned Local + address + +A.3. draft-ietf-dnsop-default-local-zones-03.txt expanded section 4 descriptions @@ -540,28 +549,27 @@ A.1. draft-ietf-dnsop-default-local-zones-03.txt Revised language. -A.2. draft-ietf-dnsop-default-local-zones-02.txt +A.4. draft-ietf-dnsop-default-local-zones-02.txt RNAME now "nobody.invalid." + + + +Andrews Expires December 7, 2008 [Page 10] + +Internet-Draft Locally-served DNS Zones June 2008 + + Revised language. -A.3. draft-ietf-dnsop-default-local-zones-01.txt +A.5. draft-ietf-dnsop-default-local-zones-01.txt Revised impact description. Updated to reflect change in IP6.INT status. - - - - -Andrews Expires May 22, 2008 [Page 10] - -Internet-Draft Locally-served DNS Zones November 2007 - - -A.4. draft-ietf-dnsop-default-local-zones-00.txt +A.6. draft-ietf-dnsop-default-local-zones-00.txt Adopted by DNSOP. @@ -571,11 +579,11 @@ A.4. draft-ietf-dnsop-default-local-zones-00.txt Title changed. -A.5. draft-andrews-full-service-resolvers-03.txt +A.7. draft-andrews-full-service-resolvers-03.txt Added "Proposed Status". -A.6. draft-andrews-full-service-resolvers-02.txt +A.8. draft-andrews-full-service-resolvers-02.txt Added 0.IN-ADDR.ARPA. @@ -604,22 +612,14 @@ Author's Address - - - - - - - - -Andrews Expires May 22, 2008 [Page 11] +Andrews Expires December 7, 2008 [Page 11] -Internet-Draft Locally-served DNS Zones November 2007 +Internet-Draft Locally-served DNS Zones June 2008 Full Copyright Statement - Copyright (C) The IETF Trust (2007). + Copyright (C) The IETF Trust (2008). This document is subject to the rights, licenses and restrictions contained in BCP 78, and except as set forth therein, the authors @@ -659,14 +659,14 @@ Intellectual Property ietf-ipr@ietf.org. -Acknowledgment - - Funding for the RFC Editor function is provided by the IETF - Administrative Support Activity (IASA). -Andrews Expires May 22, 2008 [Page 12] + + + + +Andrews Expires December 7, 2008 [Page 12] From cbd66826af7279079c9c97829ef4ca610aea0c55 Mon Sep 17 00:00:00 2001 From: Jeremy Reed Date: Fri, 6 Jun 2008 18:27:59 +0000 Subject: [PATCH 122/137] Add section IDs for statistics_counters and statistics. This is so HTML anchors can use these instead of some arbitrary link. --- doc/arm/Bv9ARM-book.xml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/doc/arm/Bv9ARM-book.xml b/doc/arm/Bv9ARM-book.xml index 8168504603..0a852e3987 100644 --- a/doc/arm/Bv9ARM-book.xml +++ b/doc/arm/Bv9ARM-book.xml @@ -18,7 +18,7 @@ - PERFORMANCE OF THIS SOFTWARE. --> - + BIND 9 Administrator Reference Manual @@ -10950,7 +10950,7 @@ $GENERATE 1-127 $ CNAME $.0 - + BIND9 Statistics BIND 9 maintains lots of statistics @@ -11122,7 +11122,7 @@ $GENERATE 1-127 $ CNAME $.0 - + Statistics Counters The following tables summarize statistics counters that From 507151045be68c671ffd4e2f37e17cdfa0376fc4 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Sat, 7 Jun 2008 01:12:04 +0000 Subject: [PATCH 123/137] regen --- doc/arm/Bv9ARM.ch06.html | 18 +-- doc/arm/Bv9ARM.ch07.html | 14 +-- doc/arm/Bv9ARM.ch08.html | 18 +-- doc/arm/Bv9ARM.ch09.html | 180 +++++++++++++-------------- doc/arm/Bv9ARM.html | 26 ++-- doc/arm/man.dig.html | 20 +-- doc/arm/man.dnssec-keyfromlabel.html | 12 +- doc/arm/man.dnssec-keygen.html | 14 +-- doc/arm/man.dnssec-signzone.html | 12 +- doc/arm/man.host.html | 10 +- doc/arm/man.named-checkconf.html | 12 +- doc/arm/man.named-checkzone.html | 12 +- doc/arm/man.named.html | 16 +-- doc/arm/man.rndc-confgen.html | 12 +- doc/arm/man.rndc.conf.html | 12 +- doc/arm/man.rndc.html | 12 +- 16 files changed, 200 insertions(+), 200 deletions(-) diff --git a/doc/arm/Bv9ARM.ch06.html b/doc/arm/Bv9ARM.ch06.html index 7136338f01..4440c0e410 100644 --- a/doc/arm/Bv9ARM.ch06.html +++ b/doc/arm/Bv9ARM.ch06.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -99,8 +99,8 @@
BIND Master File Extension: the $GENERATE Directive
Additional File Formats
-
BIND9 Statistics
-
Statistics Counters
+
BIND9 Statistics
+
Statistics Counters

@@ -7317,7 +7317,7 @@ $GENERATE 1-127 $ CNAME $.0

-BIND9 Statistics

+BIND9 Statistics

BIND 9 maintains lots of statistics information and provides several interfaces for users to @@ -7474,7 +7474,7 @@ $GENERATE 1-127 $ CNAME $.0

-Statistics Counters

+Statistics Counters

The following tables summarize statistics counters that BIND 9 provides. @@ -7493,7 +7493,7 @@ $GENERATE 1-127 $ CNAME $.0

-Name Server Statistics Counters

+Name Server Statistics Counters
@@ -8034,7 +8034,7 @@ $GENERATE 1-127 $ CNAME $.0

-Zone Maintenance Statistics Counters

+Zone Maintenance Statistics Counters
@@ -8188,7 +8188,7 @@ $GENERATE 1-127 $ CNAME $.0

-Resolver Statistics Counters

+Resolver Statistics Counters
@@ -8494,7 +8494,7 @@ $GENERATE 1-127 $ CNAME $.0

-Compatibility with BIND 8 Counters

+Compatibility with BIND 8 Counters

Most statistics counters that were available in BIND 8 are also supported in diff --git a/doc/arm/Bv9ARM.ch07.html b/doc/arm/Bv9ARM.ch07.html index ecd84abe65..2444decd4f 100644 --- a/doc/arm/Bv9ARM.ch07.html +++ b/doc/arm/Bv9ARM.ch07.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -46,10 +46,10 @@

Table of Contents

Access Control Lists
-
Chroot and Setuid
+
Chroot and Setuid
-
The chroot Environment
-
Using the setuid Function
+
The chroot Environment
+
Using the setuid Function
Dynamic Update Security
@@ -119,7 +119,7 @@ zone "example.com" {

-Chroot and Setuid +Chroot and Setuid

On UNIX servers, it is possible to run BIND in a chrooted environment @@ -143,7 +143,7 @@ zone "example.com" {

-The chroot Environment

+The chroot Environment

In order for a chroot environment to @@ -171,7 +171,7 @@ zone "example.com" {

-Using the setuid Function

+Using the setuid Function

Prior to running the named daemon, use diff --git a/doc/arm/Bv9ARM.ch08.html b/doc/arm/Bv9ARM.ch08.html index 2f9e8aca4b..c14db145fc 100644 --- a/doc/arm/Bv9ARM.ch08.html +++ b/doc/arm/Bv9ARM.ch08.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -45,18 +45,18 @@

-Common Problems

+Common Problems

-It's not working; how can I figure out what's wrong?

+It's not working; how can I figure out what's wrong?

The best solution to solving installation and configuration issues is to take preventative measures by setting @@ -68,7 +68,7 @@

-Incrementing and Changing the Serial Number

+Incrementing and Changing the Serial Number

Zone serial numbers are just numbers — they aren't date related. A lot of people set them to a number that @@ -95,7 +95,7 @@

-Where Can I Get Help?

+Where Can I Get Help?

The Internet Systems Consortium (ISC) offers a wide range diff --git a/doc/arm/Bv9ARM.ch09.html b/doc/arm/Bv9ARM.ch09.html index 276d40372a..a6283bb5ad 100644 --- a/doc/arm/Bv9ARM.ch09.html +++ b/doc/arm/Bv9ARM.ch09.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -45,21 +45,21 @@

-Acknowledgments

+Acknowledgments

A Brief History of the DNS and BIND @@ -164,7 +164,7 @@

-General DNS Reference Information

+General DNS Reference Information

IPv6 addresses (AAAA)

@@ -252,17 +252,17 @@

-Bibliography

+Bibliography

Standards

-

[RFC974] C. Partridge. Mail Routing and the Domain System. January 1986.

+

[RFC974] C. Partridge. Mail Routing and the Domain System. January 1986.

-

[RFC1034] P.V. Mockapetris. Domain Names — Concepts and Facilities. November 1987.

+

[RFC1034] P.V. Mockapetris. Domain Names — Concepts and Facilities. November 1987.

-

[RFC1035] P. V. Mockapetris. Domain Names — Implementation and +

[RFC1035] P. V. Mockapetris. Domain Names — Implementation and Specification. November 1987.

@@ -270,42 +270,42 @@

Proposed Standards

-

[RFC2181] R., R. Bush Elz. Clarifications to the DNS +

[RFC2181] R., R. Bush Elz. Clarifications to the DNS Specification. July 1997.

-

[RFC2308] M. Andrews. Negative Caching of DNS +

[RFC2308] M. Andrews. Negative Caching of DNS Queries. March 1998.

-

[RFC1995] M. Ohta. Incremental Zone Transfer in DNS. August 1996.

+

[RFC1995] M. Ohta. Incremental Zone Transfer in DNS. August 1996.

-

[RFC1996] P. Vixie. A Mechanism for Prompt Notification of Zone Changes. August 1996.

+

[RFC1996] P. Vixie. A Mechanism for Prompt Notification of Zone Changes. August 1996.

-

[RFC2136] P. Vixie, S. Thomson, Y. Rekhter, and J. Bound. Dynamic Updates in the Domain Name System. April 1997.

+

[RFC2136] P. Vixie, S. Thomson, Y. Rekhter, and J. Bound. Dynamic Updates in the Domain Name System. April 1997.

-

[RFC2671] P. Vixie. Extension Mechanisms for DNS (EDNS0). August 1997.

+

[RFC2671] P. Vixie. Extension Mechanisms for DNS (EDNS0). August 1997.

-

[RFC2672] M. Crawford. Non-Terminal DNS Name Redirection. August 1999.

+

[RFC2672] M. Crawford. Non-Terminal DNS Name Redirection. August 1999.

-

[RFC2845] P. Vixie, O. Gudmundsson, D. Eastlake, 3rd, and B. Wellington. Secret Key Transaction Authentication for DNS (TSIG). May 2000.

+

[RFC2845] P. Vixie, O. Gudmundsson, D. Eastlake, 3rd, and B. Wellington. Secret Key Transaction Authentication for DNS (TSIG). May 2000.

-

[RFC2930] D. Eastlake, 3rd. Secret Key Establishment for DNS (TKEY RR). September 2000.

+

[RFC2930] D. Eastlake, 3rd. Secret Key Establishment for DNS (TKEY RR). September 2000.

-

[RFC2931] D. Eastlake, 3rd. DNS Request and Transaction Signatures (SIG(0)s). September 2000.

+

[RFC2931] D. Eastlake, 3rd. DNS Request and Transaction Signatures (SIG(0)s). September 2000.

-

[RFC3007] B. Wellington. Secure Domain Name System (DNS) Dynamic Update. November 2000.

+

[RFC3007] B. Wellington. Secure Domain Name System (DNS) Dynamic Update. November 2000.

-

[RFC3645] S. Kwan, P. Garg, J. Gilroy, L. Esibov, J. Westhead, and R. Hall. Generic Security Service Algorithm for Secret +

[RFC3645] S. Kwan, P. Garg, J. Gilroy, L. Esibov, J. Westhead, and R. Hall. Generic Security Service Algorithm for Secret Key Transaction Authentication for DNS (GSS-TSIG). October 2003.

@@ -314,19 +314,19 @@

DNS Security Proposed Standards

-

[RFC3225] D. Conrad. Indicating Resolver Support of DNSSEC. December 2001.

+

[RFC3225] D. Conrad. Indicating Resolver Support of DNSSEC. December 2001.

-

[RFC3833] D. Atkins and R. Austein. Threat Analysis of the Domain Name System (DNS). August 2004.

+

[RFC3833] D. Atkins and R. Austein. Threat Analysis of the Domain Name System (DNS). August 2004.

-

[RFC4033] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. DNS Security Introduction and Requirements. March 2005.

+

[RFC4033] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. DNS Security Introduction and Requirements. March 2005.

-

[RFC4044] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. Resource Records for the DNS Security Extensions. March 2005.

+

[RFC4044] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. Resource Records for the DNS Security Extensions. March 2005.

-

[RFC4035] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. Protocol Modifications for the DNS +

[RFC4035] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. Protocol Modifications for the DNS Security Extensions. March 2005.

@@ -334,146 +334,146 @@

Other Important RFCs About DNS Implementation

-

[RFC1535] E. Gavron. A Security Problem and Proposed Correction With Widely +

[RFC1535] E. Gavron. A Security Problem and Proposed Correction With Widely Deployed DNS Software.. October 1993.

-

[RFC1536] A. Kumar, J. Postel, C. Neuman, P. Danzig, and S. Miller. Common DNS Implementation +

[RFC1536] A. Kumar, J. Postel, C. Neuman, P. Danzig, and S. Miller. Common DNS Implementation Errors and Suggested Fixes. October 1993.

-

[RFC1982] R. Elz and R. Bush. Serial Number Arithmetic. August 1996.

+

[RFC1982] R. Elz and R. Bush. Serial Number Arithmetic. August 1996.

-

[RFC4074] Y. Morishita and T. Jinmei. Common Misbehaviour Against DNS +

[RFC4074] Y. Morishita and T. Jinmei. Common Misbehaviour Against DNS Queries for IPv6 Addresses. May 2005.

Resource Record Types

-

[RFC1183] C.F. Everhart, L. A. Mamakos, R. Ullmann, and P. Mockapetris. New DNS RR Definitions. October 1990.

+

[RFC1183] C.F. Everhart, L. A. Mamakos, R. Ullmann, and P. Mockapetris. New DNS RR Definitions. October 1990.

-

[RFC1706] B. Manning and R. Colella. DNS NSAP Resource Records. October 1994.

+

[RFC1706] B. Manning and R. Colella. DNS NSAP Resource Records. October 1994.

-

[RFC2168] R. Daniel and M. Mealling. Resolution of Uniform Resource Identifiers using +

[RFC2168] R. Daniel and M. Mealling. Resolution of Uniform Resource Identifiers using the Domain Name System. June 1997.

-

[RFC1876] C. Davis, P. Vixie, T., and I. Dickinson. A Means for Expressing Location Information in the +

[RFC1876] C. Davis, P. Vixie, T., and I. Dickinson. A Means for Expressing Location Information in the Domain Name System. January 1996.

-

[RFC2052] A. Gulbrandsen and P. Vixie. A DNS RR for Specifying the +

[RFC2052] A. Gulbrandsen and P. Vixie. A DNS RR for Specifying the Location of Services.. October 1996.

-

[RFC2163] A. Allocchio. Using the Internet DNS to +

[RFC2163] A. Allocchio. Using the Internet DNS to Distribute MIXER Conformant Global Address Mapping. January 1998.

-

[RFC2230] R. Atkinson. Key Exchange Delegation Record for the DNS. October 1997.

+

[RFC2230] R. Atkinson. Key Exchange Delegation Record for the DNS. October 1997.

-

[RFC2536] D. Eastlake, 3rd. DSA KEYs and SIGs in the Domain Name System (DNS). March 1999.

+

[RFC2536] D. Eastlake, 3rd. DSA KEYs and SIGs in the Domain Name System (DNS). March 1999.

-

[RFC2537] D. Eastlake, 3rd. RSA/MD5 KEYs and SIGs in the Domain Name System (DNS). March 1999.

+

[RFC2537] D. Eastlake, 3rd. RSA/MD5 KEYs and SIGs in the Domain Name System (DNS). March 1999.

-

[RFC2538] D. Eastlake, 3rd and O. Gudmundsson. Storing Certificates in the Domain Name System (DNS). March 1999.

+

[RFC2538] D. Eastlake, 3rd and O. Gudmundsson. Storing Certificates in the Domain Name System (DNS). March 1999.

-

[RFC2539] D. Eastlake, 3rd. Storage of Diffie-Hellman Keys in the Domain Name System (DNS). March 1999.

+

[RFC2539] D. Eastlake, 3rd. Storage of Diffie-Hellman Keys in the Domain Name System (DNS). March 1999.

-

[RFC2540] D. Eastlake, 3rd. Detached Domain Name System (DNS) Information. March 1999.

+

[RFC2540] D. Eastlake, 3rd. Detached Domain Name System (DNS) Information. March 1999.

-

[RFC2782] A. Gulbrandsen. P. Vixie. L. Esibov. A DNS RR for specifying the location of services (DNS SRV). February 2000.

+

[RFC2782] A. Gulbrandsen. P. Vixie. L. Esibov. A DNS RR for specifying the location of services (DNS SRV). February 2000.

-

[RFC2915] M. Mealling. R. Daniel. The Naming Authority Pointer (NAPTR) DNS Resource Record. September 2000.

+

[RFC2915] M. Mealling. R. Daniel. The Naming Authority Pointer (NAPTR) DNS Resource Record. September 2000.

-

[RFC3110] D. Eastlake, 3rd. RSA/SHA-1 SIGs and RSA KEYs in the Domain Name System (DNS). May 2001.

+

[RFC3110] D. Eastlake, 3rd. RSA/SHA-1 SIGs and RSA KEYs in the Domain Name System (DNS). May 2001.

-

[RFC3123] P. Koch. A DNS RR Type for Lists of Address Prefixes (APL RR). June 2001.

+

[RFC3123] P. Koch. A DNS RR Type for Lists of Address Prefixes (APL RR). June 2001.

-

[RFC3596] S. Thomson, C. Huitema, V. Ksinant, and M. Souissi. DNS Extensions to support IP +

[RFC3596] S. Thomson, C. Huitema, V. Ksinant, and M. Souissi. DNS Extensions to support IP version 6. October 2003.

-

[RFC3597] A. Gustafsson. Handling of Unknown DNS Resource Record (RR) Types. September 2003.

+

[RFC3597] A. Gustafsson. Handling of Unknown DNS Resource Record (RR) Types. September 2003.

DNS and the Internet

-

[RFC1101] P. V. Mockapetris. DNS Encoding of Network Names +

[RFC1101] P. V. Mockapetris. DNS Encoding of Network Names and Other Types. April 1989.

-

[RFC1123] Braden. Requirements for Internet Hosts - Application and +

[RFC1123] Braden. Requirements for Internet Hosts - Application and Support. October 1989.

-

[RFC1591] J. Postel. Domain Name System Structure and Delegation. March 1994.

+

[RFC1591] J. Postel. Domain Name System Structure and Delegation. March 1994.

-

[RFC2317] H. Eidnes, G. de Groot, and P. Vixie. Classless IN-ADDR.ARPA Delegation. March 1998.

+

[RFC2317] H. Eidnes, G. de Groot, and P. Vixie. Classless IN-ADDR.ARPA Delegation. March 1998.

-

[RFC2826] Internet Architecture Board. IAB Technical Comment on the Unique DNS Root. May 2000.

+

[RFC2826] Internet Architecture Board. IAB Technical Comment on the Unique DNS Root. May 2000.

-

[RFC2929] D. Eastlake, 3rd, E. Brunner-Williams, and B. Manning. Domain Name System (DNS) IANA Considerations. September 2000.

+

[RFC2929] D. Eastlake, 3rd, E. Brunner-Williams, and B. Manning. Domain Name System (DNS) IANA Considerations. September 2000.

DNS Operations

-

[RFC1033] M. Lottor. Domain administrators operations guide.. November 1987.

+

[RFC1033] M. Lottor. Domain administrators operations guide.. November 1987.

-

[RFC1537] P. Beertema. Common DNS Data File +

[RFC1537] P. Beertema. Common DNS Data File Configuration Errors. October 1993.

-

[RFC1912] D. Barr. Common DNS Operational and +

[RFC1912] D. Barr. Common DNS Operational and Configuration Errors. February 1996.

-

[RFC2010] B. Manning and P. Vixie. Operational Criteria for Root Name Servers.. October 1996.

+

[RFC2010] B. Manning and P. Vixie. Operational Criteria for Root Name Servers.. October 1996.

-

[RFC2219] M. Hamilton and R. Wright. Use of DNS Aliases for +

[RFC2219] M. Hamilton and R. Wright. Use of DNS Aliases for Network Services.. October 1997.

Internationalized Domain Names

-

[RFC2825] IAB and R. Daigle. A Tangled Web: Issues of I18N, Domain Names, +

[RFC2825] IAB and R. Daigle. A Tangled Web: Issues of I18N, Domain Names, and the Other Internet protocols. May 2000.

-

[RFC3490] P. Faltstrom, P. Hoffman, and A. Costello. Internationalizing Domain Names in Applications (IDNA). March 2003.

+

[RFC3490] P. Faltstrom, P. Hoffman, and A. Costello. Internationalizing Domain Names in Applications (IDNA). March 2003.

-

[RFC3491] P. Hoffman and M. Blanchet. Nameprep: A Stringprep Profile for Internationalized Domain Names. March 2003.

+

[RFC3491] P. Hoffman and M. Blanchet. Nameprep: A Stringprep Profile for Internationalized Domain Names. March 2003.

-

[RFC3492] A. Costello. Punycode: A Bootstring encoding of Unicode +

[RFC3492] A. Costello. Punycode: A Bootstring encoding of Unicode for Internationalized Domain Names in Applications (IDNA). March 2003.

@@ -489,47 +489,47 @@

-

[RFC1464] R. Rosenbaum. Using the Domain Name System To Store Arbitrary String +

[RFC1464] R. Rosenbaum. Using the Domain Name System To Store Arbitrary String Attributes. May 1993.

-

[RFC1713] A. Romao. Tools for DNS Debugging. November 1994.

+

[RFC1713] A. Romao. Tools for DNS Debugging. November 1994.

-

[RFC1794] T. Brisco. DNS Support for Load +

[RFC1794] T. Brisco. DNS Support for Load Balancing. April 1995.

-

[RFC2240] O. Vaughan. A Legal Basis for Domain Name Allocation. November 1997.

+

[RFC2240] O. Vaughan. A Legal Basis for Domain Name Allocation. November 1997.

-

[RFC2345] J. Klensin, T. Wolf, and G. Oglesby. Domain Names and Company Name Retrieval. May 1998.

+

[RFC2345] J. Klensin, T. Wolf, and G. Oglesby. Domain Names and Company Name Retrieval. May 1998.

-

[RFC2352] O. Vaughan. A Convention For Using Legal Names as Domain Names. May 1998.

+

[RFC2352] O. Vaughan. A Convention For Using Legal Names as Domain Names. May 1998.

-

[RFC3071] J. Klensin. Reflections on the DNS, RFC 1591, and Categories of Domains. February 2001.

+

[RFC3071] J. Klensin. Reflections on the DNS, RFC 1591, and Categories of Domains. February 2001.

-

[RFC3258] T. Hardie. Distributing Authoritative Name Servers via +

[RFC3258] T. Hardie. Distributing Authoritative Name Servers via Shared Unicast Addresses. April 2002.

-

[RFC3901] A. Durand and J. Ihren. DNS IPv6 Transport Operational Guidelines. September 2004.

+

[RFC3901] A. Durand and J. Ihren. DNS IPv6 Transport Operational Guidelines. September 2004.

Obsolete and Unimplemented Experimental RFC

-

[RFC1712] C. Farrell, M. Schulze, S. Pleitner, and D. Baldoni. DNS Encoding of Geographical +

[RFC1712] C. Farrell, M. Schulze, S. Pleitner, and D. Baldoni. DNS Encoding of Geographical Location. November 1994.

-

[RFC2673] M. Crawford. Binary Labels in the Domain Name System. August 1999.

+

[RFC2673] M. Crawford. Binary Labels in the Domain Name System. August 1999.

-

[RFC2874] M. Crawford and C. Huitema. DNS Extensions to Support IPv6 Address Aggregation +

[RFC2874] M. Crawford and C. Huitema. DNS Extensions to Support IPv6 Address Aggregation and Renumbering. July 2000.

@@ -543,39 +543,39 @@

-

[RFC2065] D. Eastlake, 3rd and C. Kaufman. Domain Name System Security Extensions. January 1997.

+

[RFC2065] D. Eastlake, 3rd and C. Kaufman. Domain Name System Security Extensions. January 1997.

-

[RFC2137] D. Eastlake, 3rd. Secure Domain Name System Dynamic Update. April 1997.

+

[RFC2137] D. Eastlake, 3rd. Secure Domain Name System Dynamic Update. April 1997.

-

[RFC2535] D. Eastlake, 3rd. Domain Name System Security Extensions. March 1999.

+

[RFC2535] D. Eastlake, 3rd. Domain Name System Security Extensions. March 1999.

-

[RFC3008] B. Wellington. Domain Name System Security (DNSSEC) +

[RFC3008] B. Wellington. Domain Name System Security (DNSSEC) Signing Authority. November 2000.

-

[RFC3090] E. Lewis. DNS Security Extension Clarification on Zone Status. March 2001.

+

[RFC3090] E. Lewis. DNS Security Extension Clarification on Zone Status. March 2001.

-

[RFC3445] D. Massey and S. Rose. Limiting the Scope of the KEY Resource Record (RR). December 2002.

+

[RFC3445] D. Massey and S. Rose. Limiting the Scope of the KEY Resource Record (RR). December 2002.

-

[RFC3655] B. Wellington and O. Gudmundsson. Redefinition of DNS Authenticated Data (AD) bit. November 2003.

+

[RFC3655] B. Wellington and O. Gudmundsson. Redefinition of DNS Authenticated Data (AD) bit. November 2003.

-

[RFC3658] O. Gudmundsson. Delegation Signer (DS) Resource Record (RR). December 2003.

+

[RFC3658] O. Gudmundsson. Delegation Signer (DS) Resource Record (RR). December 2003.

-

[RFC3755] S. Weiler. Legacy Resolver Compatibility for Delegation Signer (DS). May 2004.

+

[RFC3755] S. Weiler. Legacy Resolver Compatibility for Delegation Signer (DS). May 2004.

-

[RFC3757] O. Kolkman, J. Schlyter, and E. Lewis. Domain Name System KEY (DNSKEY) Resource Record +

[RFC3757] O. Kolkman, J. Schlyter, and E. Lewis. Domain Name System KEY (DNSKEY) Resource Record (RR) Secure Entry Point (SEP) Flag. April 2004.

-

[RFC3845] J. Schlyter. DNS Security (DNSSEC) NextSECure (NSEC) RDATA Format. August 2004.

+

[RFC3845] J. Schlyter. DNS Security (DNSSEC) NextSECure (NSEC) RDATA Format. August 2004.

@@ -596,14 +596,14 @@

-Other Documents About BIND +Other Documents About BIND

-Bibliography

+Bibliography
-

Paul Albitz and Cricket Liu. DNS and BIND. Copyright © 1998 Sebastopol, CA: O'Reilly and Associates.

+

Paul Albitz and Cricket Liu. DNS and BIND. Copyright © 1998 Sebastopol, CA: O'Reilly and Associates.

diff --git a/doc/arm/Bv9ARM.html b/doc/arm/Bv9ARM.html index 27da600ada..ccd9efd8ea 100644 --- a/doc/arm/Bv9ARM.html +++ b/doc/arm/Bv9ARM.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -178,37 +178,37 @@
BIND Master File Extension: the $GENERATE Directive
Additional File Formats
-
BIND9 Statistics
-
Statistics Counters
+
BIND9 Statistics
+
Statistics Counters
7. BIND 9 Security Considerations
Access Control Lists
-
Chroot and Setuid
+
Chroot and Setuid
-
The chroot Environment
-
Using the setuid Function
+
The chroot Environment
+
Using the setuid Function
Dynamic Update Security
8. Troubleshooting
-
Common Problems
-
It's not working; how can I figure out what's wrong?
-
Incrementing and Changing the Serial Number
-
Where Can I Get Help?
+
Common Problems
+
It's not working; how can I figure out what's wrong?
+
Incrementing and Changing the Serial Number
+
Where Can I Get Help?
A. Appendices
-
Acknowledgments
+
Acknowledgments
A Brief History of the DNS and BIND
-
General DNS Reference Information
+
General DNS Reference Information
IPv6 addresses (AAAA)
Bibliography (and Suggested Reading)
Request for Comments (RFCs)
Internet Drafts
-
Other Documents About BIND
+
Other Documents About BIND
I. Manual pages
diff --git a/doc/arm/man.dig.html b/doc/arm/man.dig.html index 53847c05ea..ed2e154749 100644 --- a/doc/arm/man.dig.html +++ b/doc/arm/man.dig.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -52,7 +52,7 @@

dig [global-queryopt...] [query...]

-

DESCRIPTION

+

DESCRIPTION

dig (domain information groper) is a flexible tool for interrogating DNS name servers. It performs DNS lookups and @@ -98,7 +98,7 @@

-

SIMPLE USAGE

+

SIMPLE USAGE

A typical invocation of dig looks like:

@@ -144,7 +144,7 @@

-

OPTIONS

+

OPTIONS

The -b option sets the source IP address of the query to address. This must be a valid @@ -244,7 +244,7 @@

-

QUERY OPTIONS

+

QUERY OPTIONS

dig provides a number of query options which affect the way in which lookups are made and the results displayed. Some of @@ -567,7 +567,7 @@

-

MULTIPLE QUERIES

+

MULTIPLE QUERIES

The BIND 9 implementation of dig supports @@ -613,7 +613,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

IDN SUPPORT

+

IDN SUPPORT

If dig has been built with IDN (internationalized domain name) support, it can accept and display non-ASCII domain names. @@ -627,14 +627,14 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

FILES

+

FILES

/etc/resolv.conf

${HOME}/.digrc

-

SEE ALSO

+

SEE ALSO

host(1), named(8), dnssec-keygen(8), @@ -642,7 +642,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

BUGS

+

BUGS

There are probably too many query options.

diff --git a/doc/arm/man.dnssec-keyfromlabel.html b/doc/arm/man.dnssec-keyfromlabel.html index b54d27b252..87d4a57928 100644 --- a/doc/arm/man.dnssec-keyfromlabel.html +++ b/doc/arm/man.dnssec-keyfromlabel.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

dnssec-keyfromlabel {-a algorithm} {-l label} [-c class] [-f flag] [-k] [-n nametype] [-p protocol] [-t type] [-v level] {name}

-

DESCRIPTION

+

DESCRIPTION

dnssec-keyfromlabel gets keys with the given label from a crypto hardware and builds key files for DNSSEC (Secure DNS), as defined in RFC 2535 @@ -58,7 +58,7 @@

-

OPTIONS

+

OPTIONS

-a algorithm
@@ -131,7 +131,7 @@
-

GENERATED KEY FILES

+

GENERATED KEY FILES

When dnssec-keyfromlabel completes successfully, @@ -172,7 +172,7 @@

-

SEE ALSO

+

SEE ALSO

dnssec-keygen(8), dnssec-signzone(8), BIND 9 Administrator Reference Manual, @@ -182,7 +182,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.dnssec-keygen.html b/doc/arm/man.dnssec-keygen.html index 3809a94a23..6531d009bc 100644 --- a/doc/arm/man.dnssec-keygen.html +++ b/doc/arm/man.dnssec-keygen.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

dnssec-keygen {-a algorithm} {-b keysize} {-n nametype} [-c class] [-e] [-f flag] [-g generator] [-h] [-k] [-p protocol] [-r randomdev] [-s strength] [-t type] [-v level] {name}

-

DESCRIPTION

+

DESCRIPTION

dnssec-keygen generates keys for DNSSEC (Secure DNS), as defined in RFC 2535 and RFC 4034. It can also generate keys for use with @@ -58,7 +58,7 @@

-

OPTIONS

+

OPTIONS

-a algorithm
@@ -166,7 +166,7 @@
-

GENERATED KEYS

+

GENERATED KEYS

When dnssec-keygen completes successfully, @@ -212,7 +212,7 @@

-

EXAMPLE

+

EXAMPLE

To generate a 768-bit DSA key for the domain example.com, the following command would be @@ -233,7 +233,7 @@

-

SEE ALSO

+

SEE ALSO

dnssec-signzone(8), BIND 9 Administrator Reference Manual, RFC 2535, @@ -242,7 +242,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.dnssec-signzone.html b/doc/arm/man.dnssec-signzone.html index f1632f923b..62c8c238a7 100644 --- a/doc/arm/man.dnssec-signzone.html +++ b/doc/arm/man.dnssec-signzone.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

dnssec-signzone [-a] [-c class] [-d directory] [-e end-time] [-f output-file] [-g] [-h] [-k key] [-l domain] [-i interval] [-I input-format] [-j jitter] [-N soa-serial-format] [-o origin] [-O output-format] [-p] [-r randomdev] [-s start-time] [-t] [-v level] [-z] {zonefile} [key...]

-

DESCRIPTION

+

DESCRIPTION

dnssec-signzone signs a zone. It generates NSEC and RRSIG records and produces a signed version of the @@ -61,7 +61,7 @@

-

OPTIONS

+

OPTIONS

-a

@@ -259,7 +259,7 @@

-

EXAMPLE

+

EXAMPLE

The following command signs the example.com zone with the DSA key generated by dnssec-keygen @@ -288,14 +288,14 @@ db.example.com.signed %

-

SEE ALSO

+

SEE ALSO

dnssec-keygen(8), BIND 9 Administrator Reference Manual, RFC 2535.

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.host.html b/doc/arm/man.host.html index a3b4599827..42b77dedaa 100644 --- a/doc/arm/man.host.html +++ b/doc/arm/man.host.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

host [-aCdlnrsTwv] [-c class] [-N ndots] [-R number] [-t type] [-W wait] [-m flag] [-4] [-6] {name} [server]

-

DESCRIPTION

+

DESCRIPTION

host is a simple utility for performing DNS lookups. It is normally used to convert names to IP addresses and vice versa. @@ -202,7 +202,7 @@

-

IDN SUPPORT

+

IDN SUPPORT

If host has been built with IDN (internationalized domain name) support, it can accept and display non-ASCII domain names. @@ -216,12 +216,12 @@

-

FILES

+

FILES

/etc/resolv.conf

-

SEE ALSO

+

SEE ALSO

dig(1), named(8).

diff --git a/doc/arm/man.named-checkconf.html b/doc/arm/man.named-checkconf.html index d112fb443b..e2b55213ef 100644 --- a/doc/arm/man.named-checkconf.html +++ b/doc/arm/man.named-checkconf.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,14 +50,14 @@

named-checkconf [-h] [-v] [-j] [-t directory] {filename} [-z]

-

DESCRIPTION

+

DESCRIPTION

named-checkconf checks the syntax, but not the semantics, of a named configuration file.

-

OPTIONS

+

OPTIONS

-h

@@ -92,21 +92,21 @@

-

RETURN VALUES

+

RETURN VALUES

named-checkconf returns an exit status of 1 if errors were detected and 0 otherwise.

-

SEE ALSO

+

SEE ALSO

named(8), named-checkzone(8), BIND 9 Administrator Reference Manual.

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.named-checkzone.html b/doc/arm/man.named-checkzone.html index 085a3ece1f..11d33b20fe 100644 --- a/doc/arm/man.named-checkzone.html +++ b/doc/arm/man.named-checkzone.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -51,7 +51,7 @@

named-compilezone [-d] [-j] [-q] [-v] [-c class] [-C mode] [-f format] [-F format] [-i mode] [-k mode] [-m mode] [-n mode] [-o filename] [-s style] [-t directory] [-w directory] [-D] [-W mode] {zonename} {filename}

-

DESCRIPTION

+

DESCRIPTION

named-checkzone checks the syntax and integrity of a zone file. It performs the same checks as named does when loading a @@ -71,7 +71,7 @@

-

OPTIONS

+

OPTIONS

-d

@@ -257,14 +257,14 @@

-

RETURN VALUES

+

RETURN VALUES

named-checkzone returns an exit status of 1 if errors were detected and 0 otherwise.

-

SEE ALSO

+

SEE ALSO

named(8), named-checkconf(8), RFC 1035, @@ -272,7 +272,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.named.html b/doc/arm/man.named.html index 29c53ac52b..1f5d3a4708 100644 --- a/doc/arm/man.named.html +++ b/doc/arm/man.named.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

named [-4] [-6] [-c config-file] [-d debug-level] [-f] [-g] [-m flag] [-n #cpus] [-p port] [-s] [-t directory] [-u user] [-v] [-x cache-file]

-

DESCRIPTION

+

DESCRIPTION

named is a Domain Name System (DNS) server, part of the BIND 9 distribution from ISC. For more @@ -65,7 +65,7 @@

-

OPTIONS

+

OPTIONS

-4

@@ -209,7 +209,7 @@

-

SIGNALS

+

SIGNALS

In routine operation, signals should not be used to control the nameserver; rndc should be used @@ -230,7 +230,7 @@

-

CONFIGURATION

+

CONFIGURATION

The named configuration file is too complex to describe in detail here. A complete description is provided @@ -239,7 +239,7 @@

-

FILES

+

FILES

/etc/named.conf

@@ -252,7 +252,7 @@

-

SEE ALSO

+

SEE ALSO

RFC 1033, RFC 1034, RFC 1035, @@ -265,7 +265,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.rndc-confgen.html b/doc/arm/man.rndc-confgen.html index 0368e147bd..786c23ecd9 100644 --- a/doc/arm/man.rndc-confgen.html +++ b/doc/arm/man.rndc-confgen.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -48,7 +48,7 @@

rndc-confgen [-a] [-b keysize] [-c keyfile] [-h] [-k keyname] [-p port] [-r randomfile] [-s address] [-t chrootdir] [-u user]

-

DESCRIPTION

+

DESCRIPTION

rndc-confgen generates configuration files for rndc. It can be used as a @@ -64,7 +64,7 @@

-

OPTIONS

+

OPTIONS

-a
@@ -171,7 +171,7 @@
-

EXAMPLES

+

EXAMPLES

To allow rndc to be used with no manual configuration, run @@ -188,7 +188,7 @@

-

SEE ALSO

+

SEE ALSO

rndc(8), rndc.conf(5), named(8), @@ -196,7 +196,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.rndc.conf.html b/doc/arm/man.rndc.conf.html index ef8997ae73..b7df2a1872 100644 --- a/doc/arm/man.rndc.conf.html +++ b/doc/arm/man.rndc.conf.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

rndc.conf

-

DESCRIPTION

+

DESCRIPTION

rndc.conf is the configuration file for rndc, the BIND 9 name server control utility. This file has a similar structure and syntax to @@ -135,7 +135,7 @@

-

EXAMPLE

+

EXAMPLE

       options {
         default-server  localhost;
@@ -209,7 +209,7 @@
     

-

NAME SERVER CONFIGURATION

+

NAME SERVER CONFIGURATION

The name server must be configured to accept rndc connections and to recognize the key specified in the rndc.conf @@ -219,7 +219,7 @@

-

SEE ALSO

+

SEE ALSO

rndc(8), rndc-confgen(8), mmencode(1), @@ -227,7 +227,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.rndc.html b/doc/arm/man.rndc.html index 5994cae860..57ab266dbf 100644 --- a/doc/arm/man.rndc.html +++ b/doc/arm/man.rndc.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

rndc [-b source-address] [-c config-file] [-k key-file] [-s server] [-p port] [-V] [-y key_id] {command}

-

DESCRIPTION

+

DESCRIPTION

rndc controls the operation of a name server. It supersedes the ndc utility @@ -79,7 +79,7 @@

-

OPTIONS

+

OPTIONS

-b source-address

@@ -151,7 +151,7 @@

-

LIMITATIONS

+

LIMITATIONS

rndc does not yet support all the commands of the BIND 8 ndc utility. @@ -165,7 +165,7 @@

-

SEE ALSO

+

SEE ALSO

rndc.conf(5), rndc-confgen(8), named(8), @@ -175,7 +175,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

From d0b01398ca44bf573fcc3fab0d9bafc32d8f6eae Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Mon, 9 Jun 2008 23:18:31 +0000 Subject: [PATCH 124/137] auto update --- doc/private/branches | 1 + 1 file changed, 1 insertion(+) diff --git a/doc/private/branches b/doc/private/branches index 17ccc47c7c..7418687e69 100644 --- a/doc/private/branches +++ b/doc/private/branches @@ -132,6 +132,7 @@ rt18042 new fdupont // 2008-05-09 13:27 +0000 rt18046 new fdupont // 2008-05-09 06:56 +0000 rt18092 new each // 2008-05-21 05:49 +0000 rt18098 new +rt18159 new shane_dbbackend open skan open explorer skan-metazones1 private explorer From 4875b50dca297a5d2082f503da31eaab896b3a8f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tatuya=20JINMEI=20=E7=A5=9E=E6=98=8E=E9=81=94=E5=93=89?= Date: Fri, 13 Jun 2008 00:19:33 +0000 Subject: [PATCH 125/137] 2378. [bug] gssapi_functions{} had a redundant member in BIND 9.5. [RT #18169] --- CHANGES | 3 +++ 1 file changed, 3 insertions(+) diff --git a/CHANGES b/CHANGES index 7693295fbf..aa35cde68e 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +2378. [bug] gssapi_functions{} had a redundant member in BIND 9.5. + [RT #18169] + 2377. [bug] Address race condition in dnssec-signzone. [RT #18142] 2376. [bug] Change #2144 was not complete. From 250dcb4cf5c356bb492c849edff5fe3c81f61f77 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tatuya=20JINMEI=20=E7=A5=9E=E6=98=8E=E9=81=94=E5=93=89?= Date: Fri, 13 Jun 2008 18:17:08 +0000 Subject: [PATCH 126/137] 2379. [contrib] queryperf/gen-data-queryperf.py: removed redundant TLDs and supported RRs with TTLs [RT #17972] --- CHANGES | 3 +++ contrib/queryperf/utils/gen-data-queryperf.py | 27 ++++++++++++++----- 2 files changed, 23 insertions(+), 7 deletions(-) diff --git a/CHANGES b/CHANGES index aa35cde68e..d343b9be15 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +2379. [contrib] queryperf/gen-data-queryperf.py: removed redundant + TLDs and supported RRs with TTLs [RT #17972] + 2378. [bug] gssapi_functions{} had a redundant member in BIND 9.5. [RT #18169] diff --git a/contrib/queryperf/utils/gen-data-queryperf.py b/contrib/queryperf/utils/gen-data-queryperf.py index b164025a06..52074b795e 100644 --- a/contrib/queryperf/utils/gen-data-queryperf.py +++ b/contrib/queryperf/utils/gen-data-queryperf.py @@ -1,7 +1,7 @@ #!/usr/bin/python # -# $Id: gen-data-queryperf.py,v 1.1 2003/04/10 02:33:40 marka Exp $ +# $Id: gen-data-queryperf.py,v 1.2 2008/06/13 18:17:08 jinmei Exp $ # # Contributed by Stephane Bortzmeyer # @@ -32,9 +32,15 @@ percent_random = 0.3 gen = None zone_file = None domains = {} -domain_ns = "^([a-z0-9-]+)(\.([a-z0-9-\.]+|)|)( +IN|) +NS" +domain_ns = r'^([a-z0-9-\.]+)((\s+\d+)?(\s+IN)?|(\s+IN)(\s+\d+)?)\s+NS' domain_ns_re = re.compile(domain_ns, re.IGNORECASE) +def remove_tld(label, tld): + if label.endswith('.' + tld + '.'): + return label[0:-(1+ len(tld) + 1)] + else: + return label + def gen_random_label(): label = "" for i in range(gen.randint(1, maxsize)): @@ -52,7 +58,7 @@ def usage(): try: optlist, args = getopt.getopt(sys.argv[1:], "hp:f:n:t:m:", ["help", "percentrandom=", "zonefile=", - "num=", "tld=", + "number=", "tld=", "maxsize="]) for option, value in optlist: if option == "--help" or option == "-h": @@ -86,15 +92,22 @@ if zone_file: while line: domain_line = domain_ns_re.match(line) if domain_line: - domain = domain_line.group(1) + print domain_line.group(1) + domain = remove_tld(domain_line.group(1), tld) domains[domain] = 1 line = file.readline() file.close() +if zone_file: + domains = domains.keys() + if len(domains) == 0: + sys.stderr.write("No domains found in '%s'\n" % zone_file) + sys.exit(1) for i in range(num): if zone_file: if gen.random() < percent_random: - print make_domain(gen_random_label()) + sys.stdout.write(make_domain(gen_random_label())) else: - print make_domain(gen.choice(domains.keys())) + sys.stdout.write(make_domain(gen.choice(domains))) else: - print make_domain(gen_random_label()) + sys.stdout.write(make_domain(gen_random_label())) + sys.stdout.write("\n") From 20301d55b464238042d639f6f4829a918c9b8fa4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tatuya=20JINMEI=20=E7=A5=9E=E6=98=8E=E9=81=94=E5=93=89?= Date: Fri, 13 Jun 2008 18:19:36 +0000 Subject: [PATCH 127/137] 2379. [contrib] queryperf/gen-data-queryperf.py: removed redundant TLDs and supported RRs with TTLs [RT #17972] --- CHANGES | 3 +++ contrib/queryperf/utils/gen-data-queryperf.py | 27 ++++++++++++++----- 2 files changed, 23 insertions(+), 7 deletions(-) diff --git a/CHANGES b/CHANGES index 1241d56c03..07ea95ce25 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +2379. [contrib] queryperf/gen-data-queryperf.py: removed redundant + TLDs and supported RRs with TTLs [RT #17972] + 2377. [bug] Address race condition in dnssec-signzone. [RT #18142] 2376. [bug] Change #2144 was not complete. diff --git a/contrib/queryperf/utils/gen-data-queryperf.py b/contrib/queryperf/utils/gen-data-queryperf.py index b164025a06..2784d38923 100644 --- a/contrib/queryperf/utils/gen-data-queryperf.py +++ b/contrib/queryperf/utils/gen-data-queryperf.py @@ -1,7 +1,7 @@ #!/usr/bin/python # -# $Id: gen-data-queryperf.py,v 1.1 2003/04/10 02:33:40 marka Exp $ +# $Id: gen-data-queryperf.py,v 1.1.10.1.4.1 2008/06/13 18:19:36 jinmei Exp $ # # Contributed by Stephane Bortzmeyer # @@ -32,9 +32,15 @@ percent_random = 0.3 gen = None zone_file = None domains = {} -domain_ns = "^([a-z0-9-]+)(\.([a-z0-9-\.]+|)|)( +IN|) +NS" +domain_ns = r'^([a-z0-9-\.]+)((\s+\d+)?(\s+IN)?|(\s+IN)(\s+\d+)?)\s+NS' domain_ns_re = re.compile(domain_ns, re.IGNORECASE) +def remove_tld(label, tld): + if label.endswith('.' + tld + '.'): + return label[0:-(1+ len(tld) + 1)] + else: + return label + def gen_random_label(): label = "" for i in range(gen.randint(1, maxsize)): @@ -52,7 +58,7 @@ def usage(): try: optlist, args = getopt.getopt(sys.argv[1:], "hp:f:n:t:m:", ["help", "percentrandom=", "zonefile=", - "num=", "tld=", + "number=", "tld=", "maxsize="]) for option, value in optlist: if option == "--help" or option == "-h": @@ -86,15 +92,22 @@ if zone_file: while line: domain_line = domain_ns_re.match(line) if domain_line: - domain = domain_line.group(1) + print domain_line.group(1) + domain = remove_tld(domain_line.group(1), tld) domains[domain] = 1 line = file.readline() file.close() +if zone_file: + domains = domains.keys() + if len(domains) == 0: + sys.stderr.write("No domains found in '%s'\n" % zone_file) + sys.exit(1) for i in range(num): if zone_file: if gen.random() < percent_random: - print make_domain(gen_random_label()) + sys.stdout.write(make_domain(gen_random_label())) else: - print make_domain(gen.choice(domains.keys())) + sys.stdout.write(make_domain(gen.choice(domains))) else: - print make_domain(gen_random_label()) + sys.stdout.write(make_domain(gen_random_label())) + sys.stdout.write("\n") From 1948b2b113324b728bc46266eeb42a682f1024d6 Mon Sep 17 00:00:00 2001 From: Jeremy Reed Date: Fri, 13 Jun 2008 19:36:12 +0000 Subject: [PATCH 128/137] Document the rndc "validation" command. This is part of my bug #18158. --- doc/arm/Bv9ARM-book.xml | 17 ++++++++++++++++- 1 file changed, 16 insertions(+), 1 deletion(-) diff --git a/doc/arm/Bv9ARM-book.xml b/doc/arm/Bv9ARM-book.xml index 0a852e3987..c0dc513b94 100644 --- a/doc/arm/Bv9ARM-book.xml +++ b/doc/arm/Bv9ARM-book.xml @@ -18,7 +18,7 @@ - PERFORMANCE OF THIS SOFTWARE. --> - + BIND 9 Administrator Reference Manual @@ -1364,6 +1364,21 @@ zone "eng.example.com" { + + validation + on|off + view ... + + + + Enable or disable DNSSEC validation. + Note dnssec-enable also needs to be + set to yes to be effective. + It defaults to enabled. + + + + From 08c12c5bb32c72b941f719b9481eef6c16e6399c Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Fri, 13 Jun 2008 23:30:05 +0000 Subject: [PATCH 129/137] newcopyrights --- util/copyrights | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/util/copyrights b/util/copyrights index 43a5ff7039..b42b3d7746 100644 --- a/util/copyrights +++ b/util/copyrights @@ -1094,7 +1094,7 @@ ./contrib/queryperf/missing/getaddrinfo.c C 2004 ./contrib/queryperf/missing/getnameinfo.c C 2004 ./contrib/queryperf/queryperf.c X 2001,2002,2003,2004,2006,2007 -./contrib/queryperf/utils/gen-data-queryperf.py X 2003 +./contrib/queryperf/utils/gen-data-queryperf.py X 2003,2008 ./contrib/sdb/bdb/README X 2002 ./contrib/sdb/bdb/bdb.c X 2002,2003 ./contrib/sdb/bdb/bdb.h X 2002,2003 From 94df856897945fe58f130ba78765c57308bc5400 Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Fri, 13 Jun 2008 23:30:27 +0000 Subject: [PATCH 130/137] newcopyrights --- util/copyrights | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/util/copyrights b/util/copyrights index 599c228f13..a79ac68ac9 100644 --- a/util/copyrights +++ b/util/copyrights @@ -1186,7 +1186,7 @@ ./contrib/queryperf/missing/getaddrinfo.c X 2004 ./contrib/queryperf/missing/getnameinfo.c X 2004 ./contrib/queryperf/queryperf.c X 2001,2002,2003,2004,2005,2007 -./contrib/queryperf/utils/gen-data-queryperf.py X 2003 +./contrib/queryperf/utils/gen-data-queryperf.py X 2003,2008 ./contrib/sdb/bdb/README X 2002 ./contrib/sdb/bdb/bdb.c X 2002 ./contrib/sdb/bdb/bdb.h X 2002 From f8c849e22415de8f739c17552b0f0ee9a6c7c9fc Mon Sep 17 00:00:00 2001 From: Automatic Updater Date: Sat, 14 Jun 2008 01:12:10 +0000 Subject: [PATCH 131/137] regen --- doc/arm/Bv9ARM.ch03.html | 16 ++- doc/arm/Bv9ARM.ch04.html | 70 +++++------ doc/arm/Bv9ARM.ch05.html | 6 +- doc/arm/Bv9ARM.ch06.html | 146 +++++++++++----------- doc/arm/Bv9ARM.ch07.html | 14 +-- doc/arm/Bv9ARM.ch08.html | 18 +-- doc/arm/Bv9ARM.ch09.html | 180 +++++++++++++-------------- doc/arm/Bv9ARM.html | 106 ++++++++-------- doc/arm/man.dig.html | 20 +-- doc/arm/man.dnssec-keyfromlabel.html | 12 +- doc/arm/man.dnssec-keygen.html | 14 +-- doc/arm/man.dnssec-signzone.html | 12 +- doc/arm/man.host.html | 10 +- doc/arm/man.named-checkconf.html | 12 +- doc/arm/man.named-checkzone.html | 12 +- doc/arm/man.named.html | 16 +-- doc/arm/man.rndc-confgen.html | 12 +- doc/arm/man.rndc.conf.html | 12 +- doc/arm/man.rndc.html | 12 +- 19 files changed, 355 insertions(+), 345 deletions(-) diff --git a/doc/arm/Bv9ARM.ch03.html b/doc/arm/Bv9ARM.ch03.html index 5d007c77ab..1710a89193 100644 --- a/doc/arm/Bv9ARM.ch03.html +++ b/doc/arm/Bv9ARM.ch03.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -54,7 +54,7 @@
Name Server Operations
Tools for Use With the Name Server Daemon
-
Signals
+
Signals
@@ -589,6 +589,16 @@ zone "eng.example.com" { Dump the list of queries named is currently recursing on.

+
validation + [on|off] + [view ...] +
+

+ Enable or disable DNSSEC validation. + Note dnssec-enable also needs to be + set to yes to be effective. + It defaults to enabled. +

A configuration file is required, since all @@ -739,7 +749,7 @@ controls {

-Signals

+Signals

Certain UNIX signals cause the name server to take specific actions, as described in the following table. These signals can diff --git a/doc/arm/Bv9ARM.ch04.html b/doc/arm/Bv9ARM.ch04.html index ca88acac8a..4c6ddf9e0b 100644 --- a/doc/arm/Bv9ARM.ch04.html +++ b/doc/arm/Bv9ARM.ch04.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -49,29 +49,29 @@

Dynamic Update
The journal file
Incremental Zone Transfers (IXFR)
-
Split DNS
-
Example split DNS setup
+
Split DNS
+
Example split DNS setup
TSIG
-
Generate Shared Keys for Each Pair of Hosts
-
Copying the Shared Secret to Both Machines
-
Informing the Servers of the Key's Existence
-
Instructing the Server to Use the Key
-
TSIG Key Based Access Control
-
Errors
+
Generate Shared Keys for Each Pair of Hosts
+
Copying the Shared Secret to Both Machines
+
Informing the Servers of the Key's Existence
+
Instructing the Server to Use the Key
+
TSIG Key Based Access Control
+
Errors
-
TKEY
-
SIG(0)
+
TKEY
+
SIG(0)
DNSSEC
-
Generating Keys
-
Signing the Zone
-
Configuring Servers
+
Generating Keys
+
Signing the Zone
+
Configuring Servers
-
IPv6 Support in BIND 9
+
IPv6 Support in BIND 9
-
Address Lookups Using AAAA Records
-
Address to Name Lookups Using Nibble Format
+
Address Lookups Using AAAA Records
+
Address to Name Lookups Using Nibble Format
@@ -210,7 +210,7 @@

-Split DNS

+Split DNS

Setting up different views, or visibility, of the DNS space to internal and external resolvers is usually referred to as a @@ -240,7 +240,7 @@

-Example split DNS setup

+Example split DNS setup

Let's say a company named Example, Inc. (example.com) @@ -486,7 +486,7 @@ nameserver 172.16.72.4

-Generate Shared Keys for Each Pair of Hosts

+Generate Shared Keys for Each Pair of Hosts

A shared secret is generated to be shared between host1 and host2. An arbitrary key name is chosen: "host1-host2.". The key name must @@ -494,7 +494,7 @@ nameserver 172.16.72.4

-Automatic Generation

+Automatic Generation

The following command will generate a 128-bit (16 byte) HMAC-MD5 key as described above. Longer keys are better, but shorter keys @@ -519,7 +519,7 @@ nameserver 172.16.72.4

-Manual Generation

+Manual Generation

The shared secret is simply a random sequence of bits, encoded in base-64. Most ASCII strings are valid base-64 strings (assuming @@ -534,7 +534,7 @@ nameserver 172.16.72.4

-Copying the Shared Secret to Both Machines

+Copying the Shared Secret to Both Machines

This is beyond the scope of DNS. A secure transport mechanism should be used. This could be secure FTP, ssh, telephone, etc. @@ -542,7 +542,7 @@ nameserver 172.16.72.4

-Informing the Servers of the Key's Existence

+Informing the Servers of the Key's Existence

Imagine host1 and host 2 are @@ -571,7 +571,7 @@ key host1-host2. {

-Instructing the Server to Use the Key

+Instructing the Server to Use the Key

Since keys are shared between two hosts only, the server must be told when keys are to be used. The following is added to the named.conf file @@ -603,7 +603,7 @@ server 10.1.2.3 {

-TSIG Key Based Access Control

+TSIG Key Based Access Control

BIND allows IP addresses and ranges to be specified in ACL @@ -631,7 +631,7 @@ allow-update { key host1-host2. ;};

-Errors

+Errors

The processing of TSIG signed messages can result in several errors. If a signed message is sent to a non-TSIG aware @@ -657,7 +657,7 @@ allow-update { key host1-host2. ;};

-TKEY

+TKEY

TKEY is a mechanism for automatically generating a shared secret between two hosts. There are several "modes" of @@ -693,7 +693,7 @@ allow-update { key host1-host2. ;};

-SIG(0)

+SIG(0)

BIND 9 partially supports DNSSEC SIG(0) transaction signatures as specified in RFC 2535 and RFC2931. @@ -754,7 +754,7 @@ allow-update { key host1-host2. ;};

-Generating Keys

+Generating Keys

The dnssec-keygen program is used to generate keys. @@ -810,7 +810,7 @@ allow-update { key host1-host2. ;};

-Signing the Zone

+Signing the Zone

The dnssec-signzone program is used to @@ -854,7 +854,7 @@ allow-update { key host1-host2. ;};

-Configuring Servers

+Configuring Servers

To enable named to respond appropriately to DNS requests from DNSSEC aware clients, @@ -942,7 +942,7 @@ options {

-IPv6 Support in BIND 9

+IPv6 Support in BIND 9

BIND 9 fully supports all currently defined forms of IPv6 @@ -981,7 +981,7 @@ options {

-Address Lookups Using AAAA Records

+Address Lookups Using AAAA Records

The IPv6 AAAA record is a parallel to the IPv4 A record, and, unlike the deprecated A6 record, specifies the entire @@ -1000,7 +1000,7 @@ host 3600 IN AAAA 2001:db8::1

-Address to Name Lookups Using Nibble Format

+Address to Name Lookups Using Nibble Format

When looking up an address in nibble format, the address components are simply reversed, just as in IPv4, and diff --git a/doc/arm/Bv9ARM.ch05.html b/doc/arm/Bv9ARM.ch05.html index 3a7efc9cec..7c345f3c59 100644 --- a/doc/arm/Bv9ARM.ch05.html +++ b/doc/arm/Bv9ARM.ch05.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -45,13 +45,13 @@

-The Lightweight Resolver Library

+The Lightweight Resolver Library

Traditionally applications have been linked with a stub resolver library that sends recursive DNS queries to a local caching name diff --git a/doc/arm/Bv9ARM.ch06.html b/doc/arm/Bv9ARM.ch06.html index 4440c0e410..95f4e70eef 100644 --- a/doc/arm/Bv9ARM.ch06.html +++ b/doc/arm/Bv9ARM.ch06.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -48,55 +48,55 @@

Configuration File Elements
Address Match Lists
-
Comment Syntax
+
Comment Syntax
Configuration File Grammar
-
acl Statement Grammar
+
acl Statement Grammar
acl Statement Definition and Usage
-
controls Statement Grammar
+
controls Statement Grammar
controls Statement Definition and Usage
-
include Statement Grammar
-
include Statement Definition and +
include Statement Grammar
+
include Statement Definition and Usage
-
key Statement Grammar
-
key Statement Definition and Usage
-
logging Statement Grammar
-
logging Statement Definition and +
key Statement Grammar
+
key Statement Definition and Usage
+
logging Statement Grammar
+
logging Statement Definition and Usage
-
lwres Statement Grammar
-
lwres Statement Definition and Usage
-
masters Statement Grammar
-
masters Statement Definition and +
lwres Statement Grammar
+
lwres Statement Definition and Usage
+
masters Statement Grammar
+
masters Statement Definition and Usage
-
options Statement Grammar
+
options Statement Grammar
options Statement Definition and Usage
statistics-channels Statement Grammar
-
statistics-channels Statement Definition and +
statistics-channels Statement Definition and Usage
server Statement Grammar
server Statement Definition and Usage
-
trusted-keys Statement Grammar
-
trusted-keys Statement Definition +
trusted-keys Statement Grammar
+
trusted-keys Statement Definition and Usage
view Statement Grammar
-
view Statement Definition and Usage
+
view Statement Definition and Usage
zone Statement Grammar
-
zone Statement Definition and Usage
+
zone Statement Definition and Usage
-
Zone File
+
Zone File
Types of Resource Records and When to Use Them
-
Discussion of MX Records
+
Discussion of MX Records
Setting TTLs
-
Inverse Mapping in IPv4
-
Other Zone File Directives
-
BIND Master File Extension: the $GENERATE Directive
+
Inverse Mapping in IPv4
+
Other Zone File Directives
+
BIND Master File Extension: the $GENERATE Directive
Additional File Formats
BIND9 Statistics
@@ -434,7 +434,7 @@ Address Match Lists

-Syntax

+Syntax
address_match_list = address_match_list_element ;
   [ address_match_list_element; ... ]
 address_match_list_element = [ ! ] (ip_address [/length] |
@@ -443,7 +443,7 @@
 
 

-Definition and Usage

+Definition and Usage

Address match lists are primarily used to determine access control for various server operations. They are also used in @@ -527,7 +527,7 @@

-Comment Syntax

+Comment Syntax

The BIND 9 comment syntax allows for comments to appear @@ -537,7 +537,7 @@

-Syntax

+Syntax

/* This is a BIND comment as in C */
@@ -552,7 +552,7 @@

-Definition and Usage

+Definition and Usage

Comments may appear anywhere that whitespace may appear in a BIND configuration file. @@ -797,7 +797,7 @@

-acl Statement Grammar

+acl Statement Grammar
acl acl-name {
     address_match_list
 };
@@ -879,7 +879,7 @@
 
 

-controls Statement Grammar

+controls Statement Grammar
controls {
    [ inet ( ip_addr | * ) [ port ip_port ] allow {  address_match_list  }
                 keys { key_list }; ]
@@ -1001,12 +1001,12 @@
 
 

-include Statement Grammar

+include Statement Grammar
include filename;

-include Statement Definition and +include Statement Definition and Usage

The include statement inserts the @@ -1021,7 +1021,7 @@

-key Statement Grammar

+key Statement Grammar
key key_id {
     algorithm string;
     secret string;
@@ -1030,7 +1030,7 @@
 
 

-key Statement Definition and Usage

+key Statement Definition and Usage

The key statement defines a shared secret key for use with TSIG (see the section called “TSIG”) @@ -1077,7 +1077,7 @@

-logging Statement Grammar

+logging Statement Grammar
logging {
    [ channel channel_name {
      ( file path name
@@ -1101,7 +1101,7 @@
 
 

-logging Statement Definition and +logging Statement Definition and Usage

The logging statement configures a @@ -1135,7 +1135,7 @@

-The channel Phrase

+The channel Phrase

All log output goes to one or more channels; you can make as many of them as you want. @@ -1691,7 +1691,7 @@ category notify { null; };

-lwres Statement Grammar

+lwres Statement Grammar

This is the grammar of the lwres statement in the named.conf file: @@ -1706,7 +1706,7 @@ category notify { null; };

-lwres Statement Definition and Usage

+lwres Statement Definition and Usage

The lwres statement configures the name @@ -1757,14 +1757,14 @@ category notify { null; };

-masters Statement Grammar

+masters Statement Grammar
 masters name [port ip_port] { ( masters_list | ip_addr [port ip_port] [key key] ) ; [...] };
 

-masters Statement Definition and +masters Statement Definition and Usage

masters lists allow for a common set of masters to be easily used by @@ -1773,7 +1773,7 @@ category notify { null; };

-options Statement Grammar

+options Statement Grammar

This is the grammar of the options statement in the named.conf file: @@ -2892,7 +2892,7 @@ options {

-Forwarding

+Forwarding

The forwarding facility can be used to create a large site-wide cache on a few servers, reducing traffic over links to external @@ -2936,7 +2936,7 @@ options {

-Dual-stack Servers

+Dual-stack Servers

Dual-stack servers are used as servers of last resort to work around @@ -3132,7 +3132,7 @@ options {

-Interfaces

+Interfaces

The interfaces and ports that the server will answer queries from may be specified using the listen-on option. listen-on takes @@ -3518,7 +3518,7 @@ query-source-v6 address * port *;

-Bad UDP Port Lists

+Bad UDP Port Lists

avoid-v4-udp-ports and avoid-v6-udp-ports specify a list of IPv4 and IPv6 UDP ports that will not be used as system @@ -3532,7 +3532,7 @@ query-source-v6 address * port *;

-Operating System Resource Limits

+Operating System Resource Limits

The server's usage of many system resources can be limited. Scaled values are allowed when specifying resource limits. For @@ -3591,7 +3591,7 @@ query-source-v6 address * port *;

-Server Resource Limits

+Server Resource Limits

The following options set limits on the server's resource consumption that are enforced internally by the @@ -3667,7 +3667,7 @@ query-source-v6 address * port *;

-Periodic Task Intervals

+Periodic Task Intervals
cleaning-interval

@@ -4462,7 +4462,7 @@ query-source-v6 address * port *;

-statistics-channels Statement Definition and +statistics-channels Statement Definition and Usage

The statistics-channels statement @@ -4707,7 +4707,7 @@ query-source-v6 address * port *;

-trusted-keys Statement Grammar

+trusted-keys Statement Grammar
trusted-keys {
     string number number number string ;
     [ string number number number string ; [...]]
@@ -4716,7 +4716,7 @@ query-source-v6 address * port *;
 
 

-trusted-keys Statement Definition +trusted-keys Statement Definition and Usage

The trusted-keys statement defines @@ -4759,7 +4759,7 @@ query-source-v6 address * port *;

-view Statement Definition and Usage

+view Statement Definition and Usage

The view statement is a powerful feature @@ -5022,10 +5022,10 @@ zone zone_name [

-zone Statement Definition and Usage

+zone Statement Definition and Usage

-Zone Types

+Zone Types
@@ -5234,7 +5234,7 @@ zone zone_name [

-Class

+Class

The zone's name may optionally be followed by a class. If a class is not specified, class IN (for Internet), @@ -5256,7 +5256,7 @@ zone zone_name [

-Zone Options

+Zone Options
allow-notify

@@ -5828,7 +5828,7 @@ zone zone_name [

-Zone File

+Zone File

Types of Resource Records and When to Use Them

@@ -5841,7 +5841,7 @@ zone zone_name [

-Resource Records

+Resource Records

A domain name identifies a node. Each node has a set of resource information, which may be empty. The set of resource @@ -6492,7 +6492,7 @@ zone zone_name [

-Textual expression of RRs

+Textual expression of RRs

RRs are represented in binary form in the packets of the DNS protocol, and are usually represented in highly encoded form @@ -6695,7 +6695,7 @@ zone zone_name [

-Discussion of MX Records

+Discussion of MX Records

As described above, domain servers store information as a series of resource records, each of which contains a particular @@ -6953,7 +6953,7 @@ zone zone_name [

-Inverse Mapping in IPv4

+Inverse Mapping in IPv4

Reverse name resolution (that is, translation from IP address to name) is achieved by means of the in-addr.arpa domain @@ -7014,7 +7014,7 @@ zone zone_name [

-Other Zone File Directives

+Other Zone File Directives

The Master File Format was initially defined in RFC 1035 and has subsequently been extended. While the Master File Format @@ -7029,7 +7029,7 @@ zone zone_name [

-The $ORIGIN Directive

+The $ORIGIN Directive

Syntax: $ORIGIN domain-name @@ -7057,7 +7057,7 @@ WWW.EXAMPLE.COM. CNAME MAIN-SERVER.EXAMPLE.COM.

-The $INCLUDE Directive

+The $INCLUDE Directive

Syntax: $INCLUDE filename @@ -7093,7 +7093,7 @@ WWW.EXAMPLE.COM. CNAME MAIN-SERVER.EXAMPLE.COM.

-The $TTL Directive

+The $TTL Directive

Syntax: $TTL default-ttl @@ -7112,7 +7112,7 @@ WWW.EXAMPLE.COM. CNAME MAIN-SERVER.EXAMPLE.COM.

-BIND Master File Extension: the $GENERATE Directive

+BIND Master File Extension: the $GENERATE Directive

Syntax: $GENERATE range @@ -7493,7 +7493,7 @@ $GENERATE 1-127 $ CNAME $.0

-Name Server Statistics Counters

+Name Server Statistics Counters
@@ -8034,7 +8034,7 @@ $GENERATE 1-127 $ CNAME $.0

-Zone Maintenance Statistics Counters

+Zone Maintenance Statistics Counters
@@ -8188,7 +8188,7 @@ $GENERATE 1-127 $ CNAME $.0

-Resolver Statistics Counters

+Resolver Statistics Counters
@@ -8494,7 +8494,7 @@ $GENERATE 1-127 $ CNAME $.0

-Compatibility with BIND 8 Counters

+Compatibility with BIND 8 Counters

Most statistics counters that were available in BIND 8 are also supported in diff --git a/doc/arm/Bv9ARM.ch07.html b/doc/arm/Bv9ARM.ch07.html index 2444decd4f..ca48062307 100644 --- a/doc/arm/Bv9ARM.ch07.html +++ b/doc/arm/Bv9ARM.ch07.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -46,10 +46,10 @@

Table of Contents

Access Control Lists
-
Chroot and Setuid
+
Chroot and Setuid
-
The chroot Environment
-
Using the setuid Function
+
The chroot Environment
+
Using the setuid Function
Dynamic Update Security
@@ -119,7 +119,7 @@ zone "example.com" {

-Chroot and Setuid +Chroot and Setuid

On UNIX servers, it is possible to run BIND in a chrooted environment @@ -143,7 +143,7 @@ zone "example.com" {

-The chroot Environment

+The chroot Environment

In order for a chroot environment to @@ -171,7 +171,7 @@ zone "example.com" {

-Using the setuid Function

+Using the setuid Function

Prior to running the named daemon, use diff --git a/doc/arm/Bv9ARM.ch08.html b/doc/arm/Bv9ARM.ch08.html index c14db145fc..9052da6bbf 100644 --- a/doc/arm/Bv9ARM.ch08.html +++ b/doc/arm/Bv9ARM.ch08.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -45,18 +45,18 @@

-Common Problems

+Common Problems

-It's not working; how can I figure out what's wrong?

+It's not working; how can I figure out what's wrong?

The best solution to solving installation and configuration issues is to take preventative measures by setting @@ -68,7 +68,7 @@

-Incrementing and Changing the Serial Number

+Incrementing and Changing the Serial Number

Zone serial numbers are just numbers — they aren't date related. A lot of people set them to a number that @@ -95,7 +95,7 @@

-Where Can I Get Help?

+Where Can I Get Help?

The Internet Systems Consortium (ISC) offers a wide range diff --git a/doc/arm/Bv9ARM.ch09.html b/doc/arm/Bv9ARM.ch09.html index a6283bb5ad..0a41e9752d 100644 --- a/doc/arm/Bv9ARM.ch09.html +++ b/doc/arm/Bv9ARM.ch09.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -45,21 +45,21 @@

-Acknowledgments

+Acknowledgments

A Brief History of the DNS and BIND @@ -164,7 +164,7 @@

-General DNS Reference Information

+General DNS Reference Information

IPv6 addresses (AAAA)

@@ -252,17 +252,17 @@

-Bibliography

+Bibliography

Standards

-

[RFC974] C. Partridge. Mail Routing and the Domain System. January 1986.

+

[RFC974] C. Partridge. Mail Routing and the Domain System. January 1986.

-

[RFC1034] P.V. Mockapetris. Domain Names — Concepts and Facilities. November 1987.

+

[RFC1034] P.V. Mockapetris. Domain Names — Concepts and Facilities. November 1987.

-

[RFC1035] P. V. Mockapetris. Domain Names — Implementation and +

[RFC1035] P. V. Mockapetris. Domain Names — Implementation and Specification. November 1987.

@@ -270,42 +270,42 @@

Proposed Standards

-

[RFC2181] R., R. Bush Elz. Clarifications to the DNS +

[RFC2181] R., R. Bush Elz. Clarifications to the DNS Specification. July 1997.

-

[RFC2308] M. Andrews. Negative Caching of DNS +

[RFC2308] M. Andrews. Negative Caching of DNS Queries. March 1998.

-

[RFC1995] M. Ohta. Incremental Zone Transfer in DNS. August 1996.

+

[RFC1995] M. Ohta. Incremental Zone Transfer in DNS. August 1996.

-

[RFC1996] P. Vixie. A Mechanism for Prompt Notification of Zone Changes. August 1996.

+

[RFC1996] P. Vixie. A Mechanism for Prompt Notification of Zone Changes. August 1996.

-

[RFC2136] P. Vixie, S. Thomson, Y. Rekhter, and J. Bound. Dynamic Updates in the Domain Name System. April 1997.

+

[RFC2136] P. Vixie, S. Thomson, Y. Rekhter, and J. Bound. Dynamic Updates in the Domain Name System. April 1997.

-

[RFC2671] P. Vixie. Extension Mechanisms for DNS (EDNS0). August 1997.

+

[RFC2671] P. Vixie. Extension Mechanisms for DNS (EDNS0). August 1997.

-

[RFC2672] M. Crawford. Non-Terminal DNS Name Redirection. August 1999.

+

[RFC2672] M. Crawford. Non-Terminal DNS Name Redirection. August 1999.

-

[RFC2845] P. Vixie, O. Gudmundsson, D. Eastlake, 3rd, and B. Wellington. Secret Key Transaction Authentication for DNS (TSIG). May 2000.

+

[RFC2845] P. Vixie, O. Gudmundsson, D. Eastlake, 3rd, and B. Wellington. Secret Key Transaction Authentication for DNS (TSIG). May 2000.

-

[RFC2930] D. Eastlake, 3rd. Secret Key Establishment for DNS (TKEY RR). September 2000.

+

[RFC2930] D. Eastlake, 3rd. Secret Key Establishment for DNS (TKEY RR). September 2000.

-

[RFC2931] D. Eastlake, 3rd. DNS Request and Transaction Signatures (SIG(0)s). September 2000.

+

[RFC2931] D. Eastlake, 3rd. DNS Request and Transaction Signatures (SIG(0)s). September 2000.

-

[RFC3007] B. Wellington. Secure Domain Name System (DNS) Dynamic Update. November 2000.

+

[RFC3007] B. Wellington. Secure Domain Name System (DNS) Dynamic Update. November 2000.

-

[RFC3645] S. Kwan, P. Garg, J. Gilroy, L. Esibov, J. Westhead, and R. Hall. Generic Security Service Algorithm for Secret +

[RFC3645] S. Kwan, P. Garg, J. Gilroy, L. Esibov, J. Westhead, and R. Hall. Generic Security Service Algorithm for Secret Key Transaction Authentication for DNS (GSS-TSIG). October 2003.

@@ -314,19 +314,19 @@

DNS Security Proposed Standards

-

[RFC3225] D. Conrad. Indicating Resolver Support of DNSSEC. December 2001.

+

[RFC3225] D. Conrad. Indicating Resolver Support of DNSSEC. December 2001.

-

[RFC3833] D. Atkins and R. Austein. Threat Analysis of the Domain Name System (DNS). August 2004.

+

[RFC3833] D. Atkins and R. Austein. Threat Analysis of the Domain Name System (DNS). August 2004.

-

[RFC4033] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. DNS Security Introduction and Requirements. March 2005.

+

[RFC4033] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. DNS Security Introduction and Requirements. March 2005.

-

[RFC4044] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. Resource Records for the DNS Security Extensions. March 2005.

+

[RFC4044] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. Resource Records for the DNS Security Extensions. March 2005.

-

[RFC4035] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. Protocol Modifications for the DNS +

[RFC4035] R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. Protocol Modifications for the DNS Security Extensions. March 2005.

@@ -334,146 +334,146 @@

Other Important RFCs About DNS Implementation

-

[RFC1535] E. Gavron. A Security Problem and Proposed Correction With Widely +

[RFC1535] E. Gavron. A Security Problem and Proposed Correction With Widely Deployed DNS Software.. October 1993.

-

[RFC1536] A. Kumar, J. Postel, C. Neuman, P. Danzig, and S. Miller. Common DNS Implementation +

[RFC1536] A. Kumar, J. Postel, C. Neuman, P. Danzig, and S. Miller. Common DNS Implementation Errors and Suggested Fixes. October 1993.

-

[RFC1982] R. Elz and R. Bush. Serial Number Arithmetic. August 1996.

+

[RFC1982] R. Elz and R. Bush. Serial Number Arithmetic. August 1996.

-

[RFC4074] Y. Morishita and T. Jinmei. Common Misbehaviour Against DNS +

[RFC4074] Y. Morishita and T. Jinmei. Common Misbehaviour Against DNS Queries for IPv6 Addresses. May 2005.

Resource Record Types

-

[RFC1183] C.F. Everhart, L. A. Mamakos, R. Ullmann, and P. Mockapetris. New DNS RR Definitions. October 1990.

+

[RFC1183] C.F. Everhart, L. A. Mamakos, R. Ullmann, and P. Mockapetris. New DNS RR Definitions. October 1990.

-

[RFC1706] B. Manning and R. Colella. DNS NSAP Resource Records. October 1994.

+

[RFC1706] B. Manning and R. Colella. DNS NSAP Resource Records. October 1994.

-

[RFC2168] R. Daniel and M. Mealling. Resolution of Uniform Resource Identifiers using +

[RFC2168] R. Daniel and M. Mealling. Resolution of Uniform Resource Identifiers using the Domain Name System. June 1997.

-

[RFC1876] C. Davis, P. Vixie, T., and I. Dickinson. A Means for Expressing Location Information in the +

[RFC1876] C. Davis, P. Vixie, T., and I. Dickinson. A Means for Expressing Location Information in the Domain Name System. January 1996.

-

[RFC2052] A. Gulbrandsen and P. Vixie. A DNS RR for Specifying the +

[RFC2052] A. Gulbrandsen and P. Vixie. A DNS RR for Specifying the Location of Services.. October 1996.

-

[RFC2163] A. Allocchio. Using the Internet DNS to +

[RFC2163] A. Allocchio. Using the Internet DNS to Distribute MIXER Conformant Global Address Mapping. January 1998.

-

[RFC2230] R. Atkinson. Key Exchange Delegation Record for the DNS. October 1997.

+

[RFC2230] R. Atkinson. Key Exchange Delegation Record for the DNS. October 1997.

-

[RFC2536] D. Eastlake, 3rd. DSA KEYs and SIGs in the Domain Name System (DNS). March 1999.

+

[RFC2536] D. Eastlake, 3rd. DSA KEYs and SIGs in the Domain Name System (DNS). March 1999.

-

[RFC2537] D. Eastlake, 3rd. RSA/MD5 KEYs and SIGs in the Domain Name System (DNS). March 1999.

+

[RFC2537] D. Eastlake, 3rd. RSA/MD5 KEYs and SIGs in the Domain Name System (DNS). March 1999.

-

[RFC2538] D. Eastlake, 3rd and O. Gudmundsson. Storing Certificates in the Domain Name System (DNS). March 1999.

+

[RFC2538] D. Eastlake, 3rd and O. Gudmundsson. Storing Certificates in the Domain Name System (DNS). March 1999.

-

[RFC2539] D. Eastlake, 3rd. Storage of Diffie-Hellman Keys in the Domain Name System (DNS). March 1999.

+

[RFC2539] D. Eastlake, 3rd. Storage of Diffie-Hellman Keys in the Domain Name System (DNS). March 1999.

-

[RFC2540] D. Eastlake, 3rd. Detached Domain Name System (DNS) Information. March 1999.

+

[RFC2540] D. Eastlake, 3rd. Detached Domain Name System (DNS) Information. March 1999.

-

[RFC2782] A. Gulbrandsen. P. Vixie. L. Esibov. A DNS RR for specifying the location of services (DNS SRV). February 2000.

+

[RFC2782] A. Gulbrandsen. P. Vixie. L. Esibov. A DNS RR for specifying the location of services (DNS SRV). February 2000.

-

[RFC2915] M. Mealling. R. Daniel. The Naming Authority Pointer (NAPTR) DNS Resource Record. September 2000.

+

[RFC2915] M. Mealling. R. Daniel. The Naming Authority Pointer (NAPTR) DNS Resource Record. September 2000.

-

[RFC3110] D. Eastlake, 3rd. RSA/SHA-1 SIGs and RSA KEYs in the Domain Name System (DNS). May 2001.

+

[RFC3110] D. Eastlake, 3rd. RSA/SHA-1 SIGs and RSA KEYs in the Domain Name System (DNS). May 2001.

-

[RFC3123] P. Koch. A DNS RR Type for Lists of Address Prefixes (APL RR). June 2001.

+

[RFC3123] P. Koch. A DNS RR Type for Lists of Address Prefixes (APL RR). June 2001.

-

[RFC3596] S. Thomson, C. Huitema, V. Ksinant, and M. Souissi. DNS Extensions to support IP +

[RFC3596] S. Thomson, C. Huitema, V. Ksinant, and M. Souissi. DNS Extensions to support IP version 6. October 2003.

-

[RFC3597] A. Gustafsson. Handling of Unknown DNS Resource Record (RR) Types. September 2003.

+

[RFC3597] A. Gustafsson. Handling of Unknown DNS Resource Record (RR) Types. September 2003.

DNS and the Internet

-

[RFC1101] P. V. Mockapetris. DNS Encoding of Network Names +

[RFC1101] P. V. Mockapetris. DNS Encoding of Network Names and Other Types. April 1989.

-

[RFC1123] Braden. Requirements for Internet Hosts - Application and +

[RFC1123] Braden. Requirements for Internet Hosts - Application and Support. October 1989.

-

[RFC1591] J. Postel. Domain Name System Structure and Delegation. March 1994.

+

[RFC1591] J. Postel. Domain Name System Structure and Delegation. March 1994.

-

[RFC2317] H. Eidnes, G. de Groot, and P. Vixie. Classless IN-ADDR.ARPA Delegation. March 1998.

+

[RFC2317] H. Eidnes, G. de Groot, and P. Vixie. Classless IN-ADDR.ARPA Delegation. March 1998.

-

[RFC2826] Internet Architecture Board. IAB Technical Comment on the Unique DNS Root. May 2000.

+

[RFC2826] Internet Architecture Board. IAB Technical Comment on the Unique DNS Root. May 2000.

-

[RFC2929] D. Eastlake, 3rd, E. Brunner-Williams, and B. Manning. Domain Name System (DNS) IANA Considerations. September 2000.

+

[RFC2929] D. Eastlake, 3rd, E. Brunner-Williams, and B. Manning. Domain Name System (DNS) IANA Considerations. September 2000.

DNS Operations

-

[RFC1033] M. Lottor. Domain administrators operations guide.. November 1987.

+

[RFC1033] M. Lottor. Domain administrators operations guide.. November 1987.

-

[RFC1537] P. Beertema. Common DNS Data File +

[RFC1537] P. Beertema. Common DNS Data File Configuration Errors. October 1993.

-

[RFC1912] D. Barr. Common DNS Operational and +

[RFC1912] D. Barr. Common DNS Operational and Configuration Errors. February 1996.

-

[RFC2010] B. Manning and P. Vixie. Operational Criteria for Root Name Servers.. October 1996.

+

[RFC2010] B. Manning and P. Vixie. Operational Criteria for Root Name Servers.. October 1996.

-

[RFC2219] M. Hamilton and R. Wright. Use of DNS Aliases for +

[RFC2219] M. Hamilton and R. Wright. Use of DNS Aliases for Network Services.. October 1997.

Internationalized Domain Names

-

[RFC2825] IAB and R. Daigle. A Tangled Web: Issues of I18N, Domain Names, +

[RFC2825] IAB and R. Daigle. A Tangled Web: Issues of I18N, Domain Names, and the Other Internet protocols. May 2000.

-

[RFC3490] P. Faltstrom, P. Hoffman, and A. Costello. Internationalizing Domain Names in Applications (IDNA). March 2003.

+

[RFC3490] P. Faltstrom, P. Hoffman, and A. Costello. Internationalizing Domain Names in Applications (IDNA). March 2003.

-

[RFC3491] P. Hoffman and M. Blanchet. Nameprep: A Stringprep Profile for Internationalized Domain Names. March 2003.

+

[RFC3491] P. Hoffman and M. Blanchet. Nameprep: A Stringprep Profile for Internationalized Domain Names. March 2003.

-

[RFC3492] A. Costello. Punycode: A Bootstring encoding of Unicode +

[RFC3492] A. Costello. Punycode: A Bootstring encoding of Unicode for Internationalized Domain Names in Applications (IDNA). March 2003.

@@ -489,47 +489,47 @@

-

[RFC1464] R. Rosenbaum. Using the Domain Name System To Store Arbitrary String +

[RFC1464] R. Rosenbaum. Using the Domain Name System To Store Arbitrary String Attributes. May 1993.

-

[RFC1713] A. Romao. Tools for DNS Debugging. November 1994.

+

[RFC1713] A. Romao. Tools for DNS Debugging. November 1994.

-

[RFC1794] T. Brisco. DNS Support for Load +

[RFC1794] T. Brisco. DNS Support for Load Balancing. April 1995.

-

[RFC2240] O. Vaughan. A Legal Basis for Domain Name Allocation. November 1997.

+

[RFC2240] O. Vaughan. A Legal Basis for Domain Name Allocation. November 1997.

-

[RFC2345] J. Klensin, T. Wolf, and G. Oglesby. Domain Names and Company Name Retrieval. May 1998.

+

[RFC2345] J. Klensin, T. Wolf, and G. Oglesby. Domain Names and Company Name Retrieval. May 1998.

-

[RFC2352] O. Vaughan. A Convention For Using Legal Names as Domain Names. May 1998.

+

[RFC2352] O. Vaughan. A Convention For Using Legal Names as Domain Names. May 1998.

-

[RFC3071] J. Klensin. Reflections on the DNS, RFC 1591, and Categories of Domains. February 2001.

+

[RFC3071] J. Klensin. Reflections on the DNS, RFC 1591, and Categories of Domains. February 2001.

-

[RFC3258] T. Hardie. Distributing Authoritative Name Servers via +

[RFC3258] T. Hardie. Distributing Authoritative Name Servers via Shared Unicast Addresses. April 2002.

-

[RFC3901] A. Durand and J. Ihren. DNS IPv6 Transport Operational Guidelines. September 2004.

+

[RFC3901] A. Durand and J. Ihren. DNS IPv6 Transport Operational Guidelines. September 2004.

Obsolete and Unimplemented Experimental RFC

-

[RFC1712] C. Farrell, M. Schulze, S. Pleitner, and D. Baldoni. DNS Encoding of Geographical +

[RFC1712] C. Farrell, M. Schulze, S. Pleitner, and D. Baldoni. DNS Encoding of Geographical Location. November 1994.

-

[RFC2673] M. Crawford. Binary Labels in the Domain Name System. August 1999.

+

[RFC2673] M. Crawford. Binary Labels in the Domain Name System. August 1999.

-

[RFC2874] M. Crawford and C. Huitema. DNS Extensions to Support IPv6 Address Aggregation +

[RFC2874] M. Crawford and C. Huitema. DNS Extensions to Support IPv6 Address Aggregation and Renumbering. July 2000.

@@ -543,39 +543,39 @@

-

[RFC2065] D. Eastlake, 3rd and C. Kaufman. Domain Name System Security Extensions. January 1997.

+

[RFC2065] D. Eastlake, 3rd and C. Kaufman. Domain Name System Security Extensions. January 1997.

-

[RFC2137] D. Eastlake, 3rd. Secure Domain Name System Dynamic Update. April 1997.

+

[RFC2137] D. Eastlake, 3rd. Secure Domain Name System Dynamic Update. April 1997.

-

[RFC2535] D. Eastlake, 3rd. Domain Name System Security Extensions. March 1999.

+

[RFC2535] D. Eastlake, 3rd. Domain Name System Security Extensions. March 1999.

-

[RFC3008] B. Wellington. Domain Name System Security (DNSSEC) +

[RFC3008] B. Wellington. Domain Name System Security (DNSSEC) Signing Authority. November 2000.

-

[RFC3090] E. Lewis. DNS Security Extension Clarification on Zone Status. March 2001.

+

[RFC3090] E. Lewis. DNS Security Extension Clarification on Zone Status. March 2001.

-

[RFC3445] D. Massey and S. Rose. Limiting the Scope of the KEY Resource Record (RR). December 2002.

+

[RFC3445] D. Massey and S. Rose. Limiting the Scope of the KEY Resource Record (RR). December 2002.

-

[RFC3655] B. Wellington and O. Gudmundsson. Redefinition of DNS Authenticated Data (AD) bit. November 2003.

+

[RFC3655] B. Wellington and O. Gudmundsson. Redefinition of DNS Authenticated Data (AD) bit. November 2003.

-

[RFC3658] O. Gudmundsson. Delegation Signer (DS) Resource Record (RR). December 2003.

+

[RFC3658] O. Gudmundsson. Delegation Signer (DS) Resource Record (RR). December 2003.

-

[RFC3755] S. Weiler. Legacy Resolver Compatibility for Delegation Signer (DS). May 2004.

+

[RFC3755] S. Weiler. Legacy Resolver Compatibility for Delegation Signer (DS). May 2004.

-

[RFC3757] O. Kolkman, J. Schlyter, and E. Lewis. Domain Name System KEY (DNSKEY) Resource Record +

[RFC3757] O. Kolkman, J. Schlyter, and E. Lewis. Domain Name System KEY (DNSKEY) Resource Record (RR) Secure Entry Point (SEP) Flag. April 2004.

-

[RFC3845] J. Schlyter. DNS Security (DNSSEC) NextSECure (NSEC) RDATA Format. August 2004.

+

[RFC3845] J. Schlyter. DNS Security (DNSSEC) NextSECure (NSEC) RDATA Format. August 2004.

@@ -596,14 +596,14 @@

-Other Documents About BIND +Other Documents About BIND

-Bibliography

+Bibliography
-

Paul Albitz and Cricket Liu. DNS and BIND. Copyright © 1998 Sebastopol, CA: O'Reilly and Associates.

+

Paul Albitz and Cricket Liu. DNS and BIND. Copyright © 1998 Sebastopol, CA: O'Reilly and Associates.

diff --git a/doc/arm/Bv9ARM.html b/doc/arm/Bv9ARM.html index ccd9efd8ea..08aa407067 100644 --- a/doc/arm/Bv9ARM.html +++ b/doc/arm/Bv9ARM.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -83,7 +83,7 @@
Name Server Operations
Tools for Use With the Name Server Daemon
-
Signals
+
Signals
4. Advanced DNS Features
@@ -92,34 +92,34 @@
Dynamic Update
The journal file
Incremental Zone Transfers (IXFR)
-
Split DNS
-
Example split DNS setup
+
Split DNS
+
Example split DNS setup
TSIG
-
Generate Shared Keys for Each Pair of Hosts
-
Copying the Shared Secret to Both Machines
-
Informing the Servers of the Key's Existence
-
Instructing the Server to Use the Key
-
TSIG Key Based Access Control
-
Errors
+
Generate Shared Keys for Each Pair of Hosts
+
Copying the Shared Secret to Both Machines
+
Informing the Servers of the Key's Existence
+
Instructing the Server to Use the Key
+
TSIG Key Based Access Control
+
Errors
-
TKEY
-
SIG(0)
+
TKEY
+
SIG(0)
DNSSEC
-
Generating Keys
-
Signing the Zone
-
Configuring Servers
+
Generating Keys
+
Signing the Zone
+
Configuring Servers
-
IPv6 Support in BIND 9
+
IPv6 Support in BIND 9
-
Address Lookups Using AAAA Records
-
Address to Name Lookups Using Nibble Format
+
Address Lookups Using AAAA Records
+
Address to Name Lookups Using Nibble Format
5. The BIND 9 Lightweight Resolver
-
The Lightweight Resolver Library
+
The Lightweight Resolver Library
Running a Resolver Daemon
6. BIND 9 Configuration Reference
@@ -127,55 +127,55 @@
Configuration File Elements
Address Match Lists
-
Comment Syntax
+
Comment Syntax
Configuration File Grammar
-
acl Statement Grammar
+
acl Statement Grammar
acl Statement Definition and Usage
-
controls Statement Grammar
+
controls Statement Grammar
controls Statement Definition and Usage
-
include Statement Grammar
-
include Statement Definition and +
include Statement Grammar
+
include Statement Definition and Usage
-
key Statement Grammar
-
key Statement Definition and Usage
-
logging Statement Grammar
-
logging Statement Definition and +
key Statement Grammar
+
key Statement Definition and Usage
+
logging Statement Grammar
+
logging Statement Definition and Usage
-
lwres Statement Grammar
-
lwres Statement Definition and Usage
-
masters Statement Grammar
-
masters Statement Definition and +
lwres Statement Grammar
+
lwres Statement Definition and Usage
+
masters Statement Grammar
+
masters Statement Definition and Usage
-
options Statement Grammar
+
options Statement Grammar
options Statement Definition and Usage
statistics-channels Statement Grammar
-
statistics-channels Statement Definition and +
statistics-channels Statement Definition and Usage
server Statement Grammar
server Statement Definition and Usage
-
trusted-keys Statement Grammar
-
trusted-keys Statement Definition +
trusted-keys Statement Grammar
+
trusted-keys Statement Definition and Usage
view Statement Grammar
-
view Statement Definition and Usage
+
view Statement Definition and Usage
zone Statement Grammar
-
zone Statement Definition and Usage
+
zone Statement Definition and Usage
-
Zone File
+
Zone File
Types of Resource Records and When to Use Them
-
Discussion of MX Records
+
Discussion of MX Records
Setting TTLs
-
Inverse Mapping in IPv4
-
Other Zone File Directives
-
BIND Master File Extension: the $GENERATE Directive
+
Inverse Mapping in IPv4
+
Other Zone File Directives
+
BIND Master File Extension: the $GENERATE Directive
Additional File Formats
BIND9 Statistics
@@ -184,31 +184,31 @@
7. BIND 9 Security Considerations
Access Control Lists
-
Chroot and Setuid
+
Chroot and Setuid
-
The chroot Environment
-
Using the setuid Function
+
The chroot Environment
+
Using the setuid Function
Dynamic Update Security
8. Troubleshooting
-
Common Problems
-
It's not working; how can I figure out what's wrong?
-
Incrementing and Changing the Serial Number
-
Where Can I Get Help?
+
Common Problems
+
It's not working; how can I figure out what's wrong?
+
Incrementing and Changing the Serial Number
+
Where Can I Get Help?
A. Appendices
-
Acknowledgments
+
Acknowledgments
A Brief History of the DNS and BIND
-
General DNS Reference Information
+
General DNS Reference Information
IPv6 addresses (AAAA)
Bibliography (and Suggested Reading)
Request for Comments (RFCs)
Internet Drafts
-
Other Documents About BIND
+
Other Documents About BIND
I. Manual pages
diff --git a/doc/arm/man.dig.html b/doc/arm/man.dig.html index ed2e154749..c4802e4dba 100644 --- a/doc/arm/man.dig.html +++ b/doc/arm/man.dig.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -52,7 +52,7 @@

dig [global-queryopt...] [query...]

-

DESCRIPTION

+

DESCRIPTION

dig (domain information groper) is a flexible tool for interrogating DNS name servers. It performs DNS lookups and @@ -98,7 +98,7 @@

-

SIMPLE USAGE

+

SIMPLE USAGE

A typical invocation of dig looks like:

@@ -144,7 +144,7 @@

-

OPTIONS

+

OPTIONS

The -b option sets the source IP address of the query to address. This must be a valid @@ -244,7 +244,7 @@

-

QUERY OPTIONS

+

QUERY OPTIONS

dig provides a number of query options which affect the way in which lookups are made and the results displayed. Some of @@ -567,7 +567,7 @@

-

MULTIPLE QUERIES

+

MULTIPLE QUERIES

The BIND 9 implementation of dig supports @@ -613,7 +613,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

IDN SUPPORT

+

IDN SUPPORT

If dig has been built with IDN (internationalized domain name) support, it can accept and display non-ASCII domain names. @@ -627,14 +627,14 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

FILES

+

FILES

/etc/resolv.conf

${HOME}/.digrc

-

SEE ALSO

+

SEE ALSO

host(1), named(8), dnssec-keygen(8), @@ -642,7 +642,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr

-

BUGS

+

BUGS

There are probably too many query options.

diff --git a/doc/arm/man.dnssec-keyfromlabel.html b/doc/arm/man.dnssec-keyfromlabel.html index 87d4a57928..4c0979fc62 100644 --- a/doc/arm/man.dnssec-keyfromlabel.html +++ b/doc/arm/man.dnssec-keyfromlabel.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

dnssec-keyfromlabel {-a algorithm} {-l label} [-c class] [-f flag] [-k] [-n nametype] [-p protocol] [-t type] [-v level] {name}

-

DESCRIPTION

+

DESCRIPTION

dnssec-keyfromlabel gets keys with the given label from a crypto hardware and builds key files for DNSSEC (Secure DNS), as defined in RFC 2535 @@ -58,7 +58,7 @@

-

OPTIONS

+

OPTIONS

-a algorithm
@@ -131,7 +131,7 @@
-

GENERATED KEY FILES

+

GENERATED KEY FILES

When dnssec-keyfromlabel completes successfully, @@ -172,7 +172,7 @@

-

SEE ALSO

+

SEE ALSO

dnssec-keygen(8), dnssec-signzone(8), BIND 9 Administrator Reference Manual, @@ -182,7 +182,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.dnssec-keygen.html b/doc/arm/man.dnssec-keygen.html index 6531d009bc..451f5e630d 100644 --- a/doc/arm/man.dnssec-keygen.html +++ b/doc/arm/man.dnssec-keygen.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

dnssec-keygen {-a algorithm} {-b keysize} {-n nametype} [-c class] [-e] [-f flag] [-g generator] [-h] [-k] [-p protocol] [-r randomdev] [-s strength] [-t type] [-v level] {name}

-

DESCRIPTION

+

DESCRIPTION

dnssec-keygen generates keys for DNSSEC (Secure DNS), as defined in RFC 2535 and RFC 4034. It can also generate keys for use with @@ -58,7 +58,7 @@

-

OPTIONS

+

OPTIONS

-a algorithm
@@ -166,7 +166,7 @@
-

GENERATED KEYS

+

GENERATED KEYS

When dnssec-keygen completes successfully, @@ -212,7 +212,7 @@

-

EXAMPLE

+

EXAMPLE

To generate a 768-bit DSA key for the domain example.com, the following command would be @@ -233,7 +233,7 @@

-

SEE ALSO

+

SEE ALSO

dnssec-signzone(8), BIND 9 Administrator Reference Manual, RFC 2535, @@ -242,7 +242,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.dnssec-signzone.html b/doc/arm/man.dnssec-signzone.html index 62c8c238a7..25ec827f14 100644 --- a/doc/arm/man.dnssec-signzone.html +++ b/doc/arm/man.dnssec-signzone.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

dnssec-signzone [-a] [-c class] [-d directory] [-e end-time] [-f output-file] [-g] [-h] [-k key] [-l domain] [-i interval] [-I input-format] [-j jitter] [-N soa-serial-format] [-o origin] [-O output-format] [-p] [-r randomdev] [-s start-time] [-t] [-v level] [-z] {zonefile} [key...]

-

DESCRIPTION

+

DESCRIPTION

dnssec-signzone signs a zone. It generates NSEC and RRSIG records and produces a signed version of the @@ -61,7 +61,7 @@

-

OPTIONS

+

OPTIONS

-a

@@ -259,7 +259,7 @@

-

EXAMPLE

+

EXAMPLE

The following command signs the example.com zone with the DSA key generated by dnssec-keygen @@ -288,14 +288,14 @@ db.example.com.signed %

-

SEE ALSO

+

SEE ALSO

dnssec-keygen(8), BIND 9 Administrator Reference Manual, RFC 2535.

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.host.html b/doc/arm/man.host.html index 42b77dedaa..92dcc13017 100644 --- a/doc/arm/man.host.html +++ b/doc/arm/man.host.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

host [-aCdlnrsTwv] [-c class] [-N ndots] [-R number] [-t type] [-W wait] [-m flag] [-4] [-6] {name} [server]

-

DESCRIPTION

+

DESCRIPTION

host is a simple utility for performing DNS lookups. It is normally used to convert names to IP addresses and vice versa. @@ -202,7 +202,7 @@

-

IDN SUPPORT

+

IDN SUPPORT

If host has been built with IDN (internationalized domain name) support, it can accept and display non-ASCII domain names. @@ -216,12 +216,12 @@

-

FILES

+

FILES

/etc/resolv.conf

-

SEE ALSO

+

SEE ALSO

dig(1), named(8).

diff --git a/doc/arm/man.named-checkconf.html b/doc/arm/man.named-checkconf.html index e2b55213ef..ad8df8f066 100644 --- a/doc/arm/man.named-checkconf.html +++ b/doc/arm/man.named-checkconf.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,14 +50,14 @@

named-checkconf [-h] [-v] [-j] [-t directory] {filename} [-z]

-

DESCRIPTION

+

DESCRIPTION

named-checkconf checks the syntax, but not the semantics, of a named configuration file.

-

OPTIONS

+

OPTIONS

-h

@@ -92,21 +92,21 @@

-

RETURN VALUES

+

RETURN VALUES

named-checkconf returns an exit status of 1 if errors were detected and 0 otherwise.

-

SEE ALSO

+

SEE ALSO

named(8), named-checkzone(8), BIND 9 Administrator Reference Manual.

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.named-checkzone.html b/doc/arm/man.named-checkzone.html index 11d33b20fe..fb211979d8 100644 --- a/doc/arm/man.named-checkzone.html +++ b/doc/arm/man.named-checkzone.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -51,7 +51,7 @@

named-compilezone [-d] [-j] [-q] [-v] [-c class] [-C mode] [-f format] [-F format] [-i mode] [-k mode] [-m mode] [-n mode] [-o filename] [-s style] [-t directory] [-w directory] [-D] [-W mode] {zonename} {filename}

-

DESCRIPTION

+

DESCRIPTION

named-checkzone checks the syntax and integrity of a zone file. It performs the same checks as named does when loading a @@ -71,7 +71,7 @@

-

OPTIONS

+

OPTIONS

-d

@@ -257,14 +257,14 @@

-

RETURN VALUES

+

RETURN VALUES

named-checkzone returns an exit status of 1 if errors were detected and 0 otherwise.

-

SEE ALSO

+

SEE ALSO

named(8), named-checkconf(8), RFC 1035, @@ -272,7 +272,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.named.html b/doc/arm/man.named.html index 1f5d3a4708..d1af7c7908 100644 --- a/doc/arm/man.named.html +++ b/doc/arm/man.named.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

named [-4] [-6] [-c config-file] [-d debug-level] [-f] [-g] [-m flag] [-n #cpus] [-p port] [-s] [-t directory] [-u user] [-v] [-x cache-file]

-

DESCRIPTION

+

DESCRIPTION

named is a Domain Name System (DNS) server, part of the BIND 9 distribution from ISC. For more @@ -65,7 +65,7 @@

-

OPTIONS

+

OPTIONS

-4

@@ -209,7 +209,7 @@

-

SIGNALS

+

SIGNALS

In routine operation, signals should not be used to control the nameserver; rndc should be used @@ -230,7 +230,7 @@

-

CONFIGURATION

+

CONFIGURATION

The named configuration file is too complex to describe in detail here. A complete description is provided @@ -239,7 +239,7 @@

-

FILES

+

FILES

/etc/named.conf

@@ -252,7 +252,7 @@

-

SEE ALSO

+

SEE ALSO

RFC 1033, RFC 1034, RFC 1035, @@ -265,7 +265,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.rndc-confgen.html b/doc/arm/man.rndc-confgen.html index 786c23ecd9..69dbd8166f 100644 --- a/doc/arm/man.rndc-confgen.html +++ b/doc/arm/man.rndc-confgen.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -48,7 +48,7 @@

rndc-confgen [-a] [-b keysize] [-c keyfile] [-h] [-k keyname] [-p port] [-r randomfile] [-s address] [-t chrootdir] [-u user]

-

DESCRIPTION

+

DESCRIPTION

rndc-confgen generates configuration files for rndc. It can be used as a @@ -64,7 +64,7 @@

-

OPTIONS

+

OPTIONS

-a
@@ -171,7 +171,7 @@
-

EXAMPLES

+

EXAMPLES

To allow rndc to be used with no manual configuration, run @@ -188,7 +188,7 @@

-

SEE ALSO

+

SEE ALSO

rndc(8), rndc.conf(5), named(8), @@ -196,7 +196,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.rndc.conf.html b/doc/arm/man.rndc.conf.html index b7df2a1872..42356f2479 100644 --- a/doc/arm/man.rndc.conf.html +++ b/doc/arm/man.rndc.conf.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

rndc.conf

-

DESCRIPTION

+

DESCRIPTION

rndc.conf is the configuration file for rndc, the BIND 9 name server control utility. This file has a similar structure and syntax to @@ -135,7 +135,7 @@

-

EXAMPLE

+

EXAMPLE

       options {
         default-server  localhost;
@@ -209,7 +209,7 @@
     

-

NAME SERVER CONFIGURATION

+

NAME SERVER CONFIGURATION

The name server must be configured to accept rndc connections and to recognize the key specified in the rndc.conf @@ -219,7 +219,7 @@

-

SEE ALSO

+

SEE ALSO

rndc(8), rndc-confgen(8), mmencode(1), @@ -227,7 +227,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

diff --git a/doc/arm/man.rndc.html b/doc/arm/man.rndc.html index 57ab266dbf..102571978c 100644 --- a/doc/arm/man.rndc.html +++ b/doc/arm/man.rndc.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@

rndc [-b source-address] [-c config-file] [-k key-file] [-s server] [-p port] [-V] [-y key_id] {command}

-

DESCRIPTION

+

DESCRIPTION

rndc controls the operation of a name server. It supersedes the ndc utility @@ -79,7 +79,7 @@

-

OPTIONS

+

OPTIONS

-b source-address

@@ -151,7 +151,7 @@

-

LIMITATIONS

+

LIMITATIONS

rndc does not yet support all the commands of the BIND 8 ndc utility. @@ -165,7 +165,7 @@

-

SEE ALSO

+

SEE ALSO

rndc.conf(5), rndc-confgen(8), named(8), @@ -175,7 +175,7 @@

-

AUTHOR

+

AUTHOR

Internet Systems Consortium

From 538a0a40a2c308a004ea40a9efd31c9aecb0f041 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Tue, 17 Jun 2008 03:14:20 +0000 Subject: [PATCH 132/137] 2380. [bug] dns_view_find() was not returning NXDOMAIN/NXRRSET proofs which, in turn, caused validation failures for insecure zones immediately below a secure zone the server was authoritative for. [RT #18112] --- CHANGES | 5 +++++ lib/dns/view.c | 13 +------------ 2 files changed, 6 insertions(+), 12 deletions(-) diff --git a/CHANGES b/CHANGES index d343b9be15..9e3b49fbc5 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,8 @@ +2380. [bug] dns_view_find() was not returning NXDOMAIN/NXRRSET + proofs which, in turn, caused validation failures + for insecure zones immediately below a secure zone + the server was authoritative for. [RT #18112] + 2379. [contrib] queryperf/gen-data-queryperf.py: removed redundant TLDs and supported RRs with TTLs [RT #17972] diff --git a/lib/dns/view.c b/lib/dns/view.c index 22d03cdf85..ba5a811fae 100644 --- a/lib/dns/view.c +++ b/lib/dns/view.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: view.c,v 1.149 2008/05/21 23:17:21 each Exp $ */ +/* $Id: view.c,v 1.150 2008/06/17 03:14:20 marka Exp $ */ /*! \file */ @@ -872,17 +872,6 @@ dns_view_find(dns_view_t *view, dns_name_t *name, dns_rdatatype_t type, } cleanup: - if (result == DNS_R_NXDOMAIN || result == DNS_R_NXRRSET) { - /* - * We don't care about any DNSSEC proof data in these cases. - */ - if (dns_rdataset_isassociated(rdataset)) - dns_rdataset_disassociate(rdataset); - if (sigrdataset != NULL && - dns_rdataset_isassociated(sigrdataset)) - dns_rdataset_disassociate(sigrdataset); - } - if (dns_rdataset_isassociated(&zrdataset)) { dns_rdataset_disassociate(&zrdataset); if (dns_rdataset_isassociated(&zsigrdataset)) From 4bbc0f18715b908b0ae88a47410150bdda757be9 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Tue, 17 Jun 2008 03:30:30 +0000 Subject: [PATCH 133/137] 2380. [bug] dns_view_find() was not returning NXDOMAIN/NXRRSET proofs which, in turn, caused validation failures for insecure zones immediately below a secure zone the server was authoritative for. [RT #18112] --- CHANGES | 5 +++++ lib/dns/view.c | 13 +------------ 2 files changed, 6 insertions(+), 12 deletions(-) diff --git a/CHANGES b/CHANGES index 07ea95ce25..31f1073f79 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,8 @@ +2380. [bug] dns_view_find() was not returning NXDOMAIN/NXRRSET + proofs which, in turn, caused validation failures + for insecure zones immediately below a secure zone + the server was authoritative for. [RT #18112] + 2379. [contrib] queryperf/gen-data-queryperf.py: removed redundant TLDs and supported RRs with TTLs [RT #17972] diff --git a/lib/dns/view.c b/lib/dns/view.c index 90b7e938b3..a447bc16c8 100644 --- a/lib/dns/view.c +++ b/lib/dns/view.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: view.c,v 1.103.2.5.2.17 2007/08/28 07:19:14 tbox Exp $ */ +/* $Id: view.c,v 1.103.2.5.2.18 2008/06/17 03:30:30 marka Exp $ */ #include @@ -822,17 +822,6 @@ dns_view_find(dns_view_t *view, dns_name_t *name, dns_rdatatype_t type, } cleanup: - if (result == DNS_R_NXDOMAIN || result == DNS_R_NXRRSET) { - /* - * We don't care about any DNSSEC proof data in these cases. - */ - if (dns_rdataset_isassociated(rdataset)) - dns_rdataset_disassociate(rdataset); - if (sigrdataset != NULL && - dns_rdataset_isassociated(sigrdataset)) - dns_rdataset_disassociate(sigrdataset); - } - if (dns_rdataset_isassociated(&zrdataset)) { dns_rdataset_disassociate(&zrdataset); if (dns_rdataset_isassociated(&zsigrdataset)) From 8ef7b7f3f68a26cb60f98da398562f8d1c616f96 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Tue, 17 Jun 2008 03:52:37 +0000 Subject: [PATCH 134/137] 2381. [port] dlz/mysql: support multiple install layouts for mysql. /include/{,mysql/}mysql.h and /lib/{,mysql/}. [RT #18152] --- CHANGES | 4 ++++ contrib/dlz/config.dlz.in | 48 ++++++++++++++++++++++++++++++++++++--- 2 files changed, 49 insertions(+), 3 deletions(-) diff --git a/CHANGES b/CHANGES index 9e3b49fbc5..e18f868ff7 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,7 @@ +2381. [port] dlz/mysql: support multiple install layouts for + mysql. /include/{,mysql/}mysql.h and + /lib/{,mysql/}. [RT #18152] + 2380. [bug] dns_view_find() was not returning NXDOMAIN/NXRRSET proofs which, in turn, caused validation failures for insecure zones immediately below a secure zone diff --git a/contrib/dlz/config.dlz.in b/contrib/dlz/config.dlz.in index 0e4b2e580b..a186eed5b9 100644 --- a/contrib/dlz/config.dlz.in +++ b/contrib/dlz/config.dlz.in @@ -123,6 +123,8 @@ AC_ARG_WITH(dlz_mysql, (Required to use MySQL with DLZ)], use_dlz_mysql="$withval", use_dlz_mysql="no") +mysql_include="" +mysql_lib="" if test "$use_dlz_mysql" = "yes" then # User did not specify a path - guess it @@ -132,9 +134,49 @@ then if test -f $d/include/mysql/mysql.h then use_dlz_mysql=$d + mysql_include=$d/include/mysql + if test -d $d/lib/mysql + then + mysql_lib=$d/lib/mysql + else + mysql_lib=$d/lib + fi + break + elif test -f $d/include/mysql.h + then + use_dlz_mysql=$d + mysql_include=$d/include + if test -d $d/lib/mysql + then + mysql_lib=$d/lib/mysql + else + mysql_lib=$d/lib + fi break fi done +elif test "$use_dlz_mysql" != "no" +then + d = $use_dlz_mysql + if test -f $d/include/mysql/mysql.h + then + mysql_include=$d/include/mysql + if test -d $d/lib/mysql + then + mysql_lib=$d/lib/mysql + else + mysql_lib=$d/lib + fi + elif test -f $d/include/mysql.h + then + mysql_include=$d/include + if test -d $d/lib/mysql + then + mysql_lib=$d/lib/mysql + else + mysql_lib=$d/lib + fi + fi fi if test "$use_dlz_mysql" = "yes" @@ -150,11 +192,11 @@ case "$use_dlz_mysql" in ;; *) DLZ_ADD_DRIVER(MYSQL, dlz_mysql_driver, - [-I$use_dlz_mysql/include/mysql], - [-L$use_dlz_mysql/lib/mysql -lmysqlclient -lz -lcrypt -lm]) + [-I${mysql_include}], + [-L${mysql_lib} -lmysqlclient -lz -lcrypt -lm]) AC_MSG_RESULT( -[using mysql from $use_dlz_mysql/lib/mysql and $use_dlz_mysql/include/mysql]) +[using mysql from ${mysql_lib} and ${mysql_include}]) ;; esac From 510dca6f52622cc06847b6b243eb9375dbeff016 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Tue, 17 Jun 2008 03:54:30 +0000 Subject: [PATCH 135/137] remove whitespace --- contrib/dlz/config.dlz.in | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/contrib/dlz/config.dlz.in b/contrib/dlz/config.dlz.in index a186eed5b9..f78e907a77 100644 --- a/contrib/dlz/config.dlz.in +++ b/contrib/dlz/config.dlz.in @@ -157,7 +157,7 @@ then done elif test "$use_dlz_mysql" != "no" then - d = $use_dlz_mysql + d=$use_dlz_mysql if test -f $d/include/mysql/mysql.h then mysql_include=$d/include/mysql From 418b9e4549fe8a543fe7f8d02918a4c60b659665 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Tue, 17 Jun 2008 03:58:27 +0000 Subject: [PATCH 136/137] regen --- configure | 56 ++++++++++++++++++++++++++++++++++++++++++++++++------- 1 file changed, 49 insertions(+), 7 deletions(-) diff --git a/configure b/configure index 61adb40be9..60ee99b330 100755 --- a/configure +++ b/configure @@ -14,7 +14,7 @@ # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. # -# $Id: configure,v 1.428 2008/05/06 01:31:11 each Exp $ +# $Id: configure,v 1.429 2008/06/17 03:58:27 marka Exp $ # # Portions Copyright (C) 1996-2001 Nominum, Inc. # @@ -30516,6 +30516,8 @@ else fi +mysql_include="" +mysql_lib="" if test "$use_dlz_mysql" = "yes" then # User did not specify a path - guess it @@ -30525,9 +30527,49 @@ then if test -f $d/include/mysql/mysql.h then use_dlz_mysql=$d + mysql_include=$d/include/mysql + if test -d $d/lib/mysql + then + mysql_lib=$d/lib/mysql + else + mysql_lib=$d/lib + fi + break + elif test -f $d/include/mysql.h + then + use_dlz_mysql=$d + mysql_include=$d/include + if test -d $d/lib/mysql + then + mysql_lib=$d/lib/mysql + else + mysql_lib=$d/lib + fi break fi done +elif test "$use_dlz_mysql" != "no" +then + d = $use_dlz_mysql + if test -f $d/include/mysql/mysql.h + then + mysql_include=$d/include/mysql + if test -d $d/lib/mysql + then + mysql_lib=$d/lib/mysql + else + mysql_lib=$d/lib + fi + elif test -f $d/include/mysql.h + then + mysql_include=$d/include + if test -d $d/lib/mysql + then + mysql_lib=$d/lib/mysql + else + mysql_lib=$d/lib + fi + fi fi if test "$use_dlz_mysql" = "yes" @@ -30552,18 +30594,18 @@ echo "${ECHO_T}no" >&6; } DLZ_DRIVER_SRCS="$DLZ_DRIVER_SRCS $dlzdir/$i.c" DLZ_DRIVER_OBJS="$DLZ_DRIVER_OBJS $i.$O" done - if test -n "-I$use_dlz_mysql/include/mysql" + if test -n "-I${mysql_include}" then - DLZ_DRIVER_INCLUDES="$DLZ_DRIVER_INCLUDES -I$use_dlz_mysql/include/mysql" + DLZ_DRIVER_INCLUDES="$DLZ_DRIVER_INCLUDES -I${mysql_include}" fi - if test -n "-L$use_dlz_mysql/lib/mysql -lmysqlclient -lz -lcrypt -lm" + if test -n "-L${mysql_lib} -lmysqlclient -lz -lcrypt -lm" then - DLZ_DRIVER_LIBS="$DLZ_DRIVER_LIBS -L$use_dlz_mysql/lib/mysql -lmysqlclient -lz -lcrypt -lm" + DLZ_DRIVER_LIBS="$DLZ_DRIVER_LIBS -L${mysql_lib} -lmysqlclient -lz -lcrypt -lm" fi - { echo "$as_me:$LINENO: result: using mysql from $use_dlz_mysql/lib/mysql and $use_dlz_mysql/include/mysql" >&5 -echo "${ECHO_T}using mysql from $use_dlz_mysql/lib/mysql and $use_dlz_mysql/include/mysql" >&6; } + { echo "$as_me:$LINENO: result: using mysql from ${mysql_lib} and ${mysql_include}" >&5 +echo "${ECHO_T}using mysql from ${mysql_lib} and ${mysql_include}" >&6; } ;; esac From 7ecbfb6c0f566894fb7050e021cded6822771789 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Tue, 17 Jun 2008 06:38:58 +0000 Subject: [PATCH 137/137] 2382. [doc] Add descriptions of DHCID, IPSECKEY, SPF and SSHFP to ARM. --- CHANGES | 3 + doc/arm/Bv9ARM-book.xml | 54 +- doc/rfc/index | 10 +- .../rfc4701.txt} | 531 +++++++++--------- 4 files changed, 328 insertions(+), 270 deletions(-) rename doc/{draft/draft-ietf-dnsext-dhcid-rr-12.txt => rfc/rfc4701.txt} (54%) diff --git a/CHANGES b/CHANGES index e18f868ff7..0bdfc5ef69 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +2382. [doc] Add descriptions of DHCID, IPSECKEY, SPF and SSHFP + to ARM. + 2381. [port] dlz/mysql: support multiple install layouts for mysql. /include/{,mysql/}mysql.h and /lib/{,mysql/}. [RT #18152] diff --git a/doc/arm/Bv9ARM-book.xml b/doc/arm/Bv9ARM-book.xml index c0dc513b94..9e0155c104 100644 --- a/doc/arm/Bv9ARM-book.xml +++ b/doc/arm/Bv9ARM-book.xml @@ -18,7 +18,7 @@ - PERFORMANCE OF THIS SOFTWARE. --> - + BIND 9 Administrator Reference Manual @@ -9680,6 +9680,19 @@ zone zone_name class + + + + DHCID + + + + + Is used for identifying which DHCP client is + associated with this name. Described in RFC 4701. + + + @@ -9749,6 +9762,19 @@ zone zone_name class + + + + IPSECKEY + + + + + Provides a method for storing IPsec keying material in + DNS. Described in RFC 4025. + + + @@ -9987,6 +10013,19 @@ zone zone_name class + + + + SPF + + + + + Contains the Sender Policy Framework information + for a given email domain. Described in RFC 4408. + + + @@ -10000,6 +10039,19 @@ zone zone_name class + + + + SSHFP + + + + + Provides a way to securly publish a secure shell key's + fingerprint. Described in RFC 4255. + + + diff --git a/doc/rfc/index b/doc/rfc/index index 6fa08342d1..fea5f71819 100644 --- a/doc/rfc/index +++ b/doc/rfc/index @@ -9,7 +9,7 @@ 1183: New DNS RR Definitions (AFSDB, RP, X25, ISDN and RT) 1348: DNS NSAP RRs 1535: A Security Problem and Proposed Correction - With Widely Deployed DNS Software + With Widely Deployed DNS Software 1536: Common DNS Implementation Errors and Suggested Fixes 1537: Common DNS Data File Configuration Errors 1591: Domain Name System Structure and Delegation @@ -82,17 +82,17 @@ 3490: Internationalizing Domain Names In Applications (IDNA) 3491: Nameprep: A Stringprep Profile for Internationalized Domain Names (IDN) 3492: Punycode:A Bootstring encoding of Unicode for - Internationalized Domain Names in Applications (IDNA) + Internationalized Domain Names in Applications (IDNA) 3493: Basic Socket Interface Extensions for IPv6 3513: Internet Protocol Version 6 (IPv6) Addressing Architecture 3596: DNS Extensions to Support IP Version 6 3597: Handling of Unknown DNS Resource Record (RR) Types 3645: Generic Security Service Algorithm for - Secret Key Transaction Authentication for DNS (GSS-TSIG) + Secret Key Transaction Authentication for DNS (GSS-TSIG) 3655: Redefinition of DNS Authenticated Data (AD) bit 3658: Delegation Signer (DS) Resource Record (RR) 3757: Domain Name System KEY (DNSKEY) Resource Record (RR) - Secure Entry Point (SEP) Flag + Secure Entry Point (SEP) Flag 3833: Threat Analysis of the Domain Name System (DNS) 3845: DNS Security (DNSSEC) NextSECure (NSEC) RDATA Format 3901: DNS IPv6 Transport Operational Guidelines @@ -114,4 +114,6 @@ 4634: US Secure Hash Algorithms (SHA and HMAC-SHA) 4641: DNSSEC Operational Practices 4648: The Base16, Base32, and Base64 Data Encodings +4701: A DNS Resource Record (RR) for Encoding + Dynamic Host Configuration Protocol (DHCP) Information (DHCID RR) 5155: DNS Security (DNSSEC) Hashed Authenticated Denial of Existence diff --git a/doc/draft/draft-ietf-dnsext-dhcid-rr-12.txt b/doc/rfc/rfc4701.txt similarity index 54% rename from doc/draft/draft-ietf-dnsext-dhcid-rr-12.txt rename to doc/rfc/rfc4701.txt index 07749d9549..03e3c54376 100644 --- a/doc/draft/draft-ietf-dnsext-dhcid-rr-12.txt +++ b/doc/rfc/rfc4701.txt @@ -2,42 +2,27 @@ -DNSEXT M. Stapp -Internet-Draft Cisco Systems, Inc. -Expires: September 1, 2006 T. Lemon + + +Network Working Group M. Stapp +Request for Comments: 4701 Cisco Systems, Inc. +Category: Standards Track T. Lemon Nominum, Inc. A. Gustafsson Araneus Information Systems Oy - February 28, 2006 + October 2006 - A DNS RR for Encoding DHCP Information (DHCID RR) - + A DNS Resource Record (RR) for Encoding + Dynamic Host Configuration Protocol (DHCP) Information (DHCID RR) -Status of this Memo +Status of This Memo - By submitting this Internet-Draft, each author represents that any - applicable patent or other IPR claims of which he or she is aware - have been or will be disclosed, and any of which he or she becomes - aware will be disclosed, in accordance with Section 6 of BCP 79. - - Internet-Drafts are working documents of the Internet Engineering - Task Force (IETF), its areas, and its working groups. Note that - other groups may also distribute working documents as Internet- - Drafts. - - Internet-Drafts are draft documents valid for a maximum of six months - and may be updated, replaced, or obsoleted by other documents at any - time. It is inappropriate to use Internet-Drafts as reference - material or to cite them other than as "work in progress." - - The list of current Internet-Drafts can be accessed at - http://www.ietf.org/ietf/1id-abstracts.txt. - - The list of Internet-Draft Shadow Directories can be accessed at - http://www.ietf.org/shadow.html. - - This Internet-Draft will expire on September 1, 2006. + This document specifies an Internet standards track protocol for the + Internet community, and requests discussion and suggestions for + improvements. Please refer to the current edition of the "Internet + Official Protocol Standards" (STD 1) for the standardization state + and status of this protocol. Distribution of this memo is unlimited. Copyright Notice @@ -45,52 +30,61 @@ Copyright Notice Abstract - It is possible for DHCP clients to attempt to update the same DNS - FQDN or attempt to update a DNS FQDN that has been added to the DNS - for another purpose as they obtain DHCP leases. Whether the DHCP - server or the clients themselves perform the DNS updates, conflicts - can arise. To resolve such conflicts, "Resolution of DNS Name + It is possible for Dynamic Host Configuration Protocol (DHCP) clients + to attempt to update the same DNS Fully Qualified Domain Name (FQDN) + or to update a DNS FQDN that has been added to the DNS for another + purpose as they obtain DHCP leases. Whether the DHCP server or the + clients themselves perform the DNS updates, conflicts can arise. To + resolve such conflicts, RFC 4703 proposes storing client identifiers + in the DNS to unambiguously associate domain names with the DHCP + clients to which they refer. This memo defines a distinct Resource + Record (RR) type for this purpose for use by DHCP clients and + servers: the "DHCID" RR. -Stapp, et al. Expires September 1, 2006 [Page 1] + + + + + + + + + + + + +Stapp, et al. Standards Track [Page 1] -Internet-Draft The DHCID RR February 2006 - - - Conflicts" [1] proposes storing client identifiers in the DNS to - unambiguously associate domain names with the DHCP clients to which - they refer. This memo defines a distinct RR type for this purpose - for use by DHCP clients and servers, the "DHCID" RR. +RFC 4701 The DHCID RR October 2006 Table of Contents - 1. Terminology . . . . . . . . . . . . . . . . . . . . . . . . . 3 - 2. Introduction . . . . . . . . . . . . . . . . . . . . . . . . . 3 - 3. The DHCID RR . . . . . . . . . . . . . . . . . . . . . . . . . 3 - 3.1. DHCID RDATA format . . . . . . . . . . . . . . . . . . . . 3 - 3.2. DHCID Presentation Format . . . . . . . . . . . . . . . . 4 - 3.3. The DHCID RR Identifier Type Codes . . . . . . . . . . . . 4 - 3.4. The DHCID RR Digest Type Code . . . . . . . . . . . . . . 4 - 3.5. Computation of the RDATA . . . . . . . . . . . . . . . . . 5 - 3.5.1. Using the Client's DUID . . . . . . . . . . . . . . . 5 - 3.5.2. Using the Client Identifier Option . . . . . . . . . . 5 - 3.5.3. Using the Client's htype and chaddr . . . . . . . . . 6 - 3.6. Examples . . . . . . . . . . . . . . . . . . . . . . . . . 6 - 3.6.1. Example 1 . . . . . . . . . . . . . . . . . . . . . . 6 - 3.6.2. Example 2 . . . . . . . . . . . . . . . . . . . . . . 6 - 3.6.3. Example 3 . . . . . . . . . . . . . . . . . . . . . . 7 - 4. Use of the DHCID RR . . . . . . . . . . . . . . . . . . . . . 7 - 5. Updater Behavior . . . . . . . . . . . . . . . . . . . . . . . 8 - 6. Security Considerations . . . . . . . . . . . . . . . . . . . 8 - 7. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 8 - 8. Acknowledgements . . . . . . . . . . . . . . . . . . . . . . . 9 - 9. References . . . . . . . . . . . . . . . . . . . . . . . . . . 9 - 9.1. Normative References . . . . . . . . . . . . . . . . . . . 9 - 9.2. Informative References . . . . . . . . . . . . . . . . . . 10 - Authors' Addresses . . . . . . . . . . . . . . . . . . . . . . . . 11 - Intellectual Property and Copyright Statements . . . . . . . . . . 12 + 1. Introduction ....................................................3 + 2. Terminology .....................................................3 + 3. The DHCID RR ....................................................3 + 3.1. DHCID RDATA Format .........................................3 + 3.2. DHCID Presentation Format ..................................4 + 3.3. The DHCID RR Identifier Type Codes .........................4 + 3.4. The DHCID RR Digest Type Code ..............................4 + 3.5. Computation of the RDATA ...................................5 + 3.5.1. Using the Client's DUID .............................5 + 3.5.2. Using the Client Identifier Option ..................6 + 3.5.3. Using the Client's htype and chaddr .................6 + 3.6. Examples ...................................................6 + 3.6.1. Example 1 ...........................................6 + 3.6.2. Example 2 ...........................................7 + 3.6.3. Example 3 ...........................................7 + 4. Use of the DHCID RR .............................................8 + 5. Updater Behavior ................................................8 + 6. Security Considerations .........................................8 + 7. IANA Considerations .............................................9 + 8. Acknowledgements ................................................9 + 9. References ......................................................9 + 9.1. Normative References .......................................9 + 9.2. Informative References ....................................10 @@ -109,33 +103,32 @@ Table of Contents -Stapp, et al. Expires September 1, 2006 [Page 2] + + + + + + + + +Stapp, et al. Standards Track [Page 2] -Internet-Draft The DHCID RR February 2006 +RFC 4701 The DHCID RR October 2006 -1. Terminology +1. Introduction - The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", - "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this - document are to be interpreted as described in RFC 2119 [2]. - - -2. Introduction - - A set of procedures to allow DHCP [6] [10] clients and servers to - automatically update the DNS (RFC 1034 [3], RFC 1035 [4]) is proposed - in "Resolution of DNS Name Conflicts" [1]. + A set of procedures to allow DHCP [7] [11] clients and servers to + automatically update the DNS ([3], [4]) is proposed in [1]. Conflicts can arise if multiple DHCP clients wish to use the same DNS name or a DHCP client attempts to use a name added for another - purpose. To resolve such conflicts, "Resolution of DNS Name - Conflicts" [1] proposes storing client identifiers in the DNS to - unambiguously associate domain names with the DHCP clients using - them. In the interest of clarity, it is preferable for this DHCP - information to use a distinct RR type. This memo defines a distinct - RR for this purpose for use by DHCP clients or servers, the "DHCID" - RR. + purpose. To resolve such conflicts, [1] proposes storing client + identifiers in the DNS to unambiguously associate domain names with + the DHCP clients using them. In the interest of clarity, it is + preferable for this DHCP information to use a distinct RR type. This + memo defines a distinct RR for this purpose for use by DHCP clients + or servers: the "DHCID" RR. In order to obscure potentially sensitive client identifying information, the data stored is the result of a one-way SHA-256 hash @@ -147,14 +140,19 @@ Internet-Draft The DHCID RR February 2006 time with more than one name. This makes it difficult to 'track' a client as it is associated with various domain names. +2. Terminology + + The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", + "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this + document are to be interpreted as described in [2]. 3. The DHCID RR - The DHCID RR is defined with mnemonic DHCID and type code [TBD]. The + The DHCID RR is defined with mnemonic DHCID and type code 49. The DHCID RR is only defined in the IN class. DHCID RRs cause no - additional section processing. The DHCID RR is not a singleton type. + additional section processing. -3.1. DHCID RDATA format +3.1. DHCID RDATA Format The RDATA section of a DHCID RR in transmission contains RDLENGTH octets of binary data. The format of this data and its @@ -162,18 +160,18 @@ Internet-Draft The DHCID RR February 2006 DNS software should consider the RDATA section to be opaque. DHCP clients or servers use the DHCID RR to associate a DHCP client's - - - -Stapp, et al. Expires September 1, 2006 [Page 3] - -Internet-Draft The DHCID RR February 2006 - - identity with a DNS name, so that multiple DHCP clients and servers may deterministically perform dynamic DNS updates to the same zone. From the updater's perspective, the DHCID resource record RDATA consists of a 2-octet identifier type, in network byte order, + + + +Stapp, et al. Standards Track [Page 3] + +RFC 4701 The DHCID RR October 2006 + + followed by a 1-octet digest type, followed by one or more octets representing the actual identifier: @@ -184,11 +182,11 @@ Internet-Draft The DHCID RR February 2006 3.2. DHCID Presentation Format In DNS master files, the RDATA is represented as a single block in - base 64 encoding identical to that used for representing binary data - in RFC 3548 [7]. The data may be divided up into any number of white - space separated substrings, down to single base 64 digits, which are - concatenated to form the complete RDATA. These substrings can span - lines using the standard parentheses. + base-64 encoding identical to that used for representing binary data + in [8], Section 3. The data may be divided up into any number of + white-space-separated substrings, down to single base-64 digits, + which are concatenated to form the complete RDATA. These substrings + can span lines using the standard parentheses. 3.3. The DHCID RR Identifier Type Codes @@ -196,18 +194,26 @@ Internet-Draft The DHCID RR February 2006 client's request was used as input into the hash function. The identifier type codes are defined in a registry maintained by IANA, as specified in Section 7. The initial list of assigned values for - the identifier type code is: + the identifier type code and that type's identifier is: - 0x0000 = htype, chaddr from a DHCPv4 client's DHCPREQUEST [6]. - 0x0001 = The data octets (i.e., the Type and Client-Identifier - fields) from a DHCPv4 client's Client Identifier option [9]. - 0x0002 = The client's DUID (i.e., the data octets of a DHCPv6 - client's Client Identifier option [10] or the DUID field from a - DHCPv4 client's Client Identifier option [12]). - 0x0003 - 0xfffe = Available to be assigned by IANA. - - 0xffff = RESERVED + +------------------+------------------------------------------------+ + | Identifier Type | Identifier | + | Code | | + +------------------+------------------------------------------------+ + | 0x0000 | The 1-octet 'htype' followed by 'hlen' octets | + | | of 'chaddr' from a DHCPv4 client's DHCPREQUEST | + | | [7]. | + | 0x0001 | The data octets (i.e., the Type and | + | | Client-Identifier fields) from a DHCPv4 | + | | client's Client Identifier option [10]. | + | 0x0002 | The client's DUID (i.e., the data octets of a | + | | DHCPv6 client's Client Identifier option [11] | + | | or the DUID field from a DHCPv4 client's | + | | Client Identifier option [6]). | + | 0x0003 - 0xfffe | Undefined; available to be assigned by IANA. | + | 0xffff | Undefined; RESERVED. | + +------------------+------------------------------------------------+ 3.4. The DHCID RR Digest Type Code @@ -215,20 +221,19 @@ Internet-Draft The DHCID RR February 2006 algorithm used. The digest is calculated over an identifier and the canonical FQDN as described in the next section. + + +Stapp, et al. Standards Track [Page 4] + +RFC 4701 The DHCID RR October 2006 + + The digest type codes are defined in a registry maintained by IANA, as specified in Section 7. The initial list of assigned values for - the digest type codes is: value 0 is reserved and value 1 is SHA-256. - - - -Stapp, et al. Expires September 1, 2006 [Page 4] - -Internet-Draft The DHCID RR February 2006 - - - Reserving other types requires IETF standards action. Defining new - values will also require IETF standards action to document how DNS - updaters are to deal with multiple digest types. + the digest type codes is: value 0 is reserved, and value 1 is + SHA-256. Reserving other types requires IETF standards action. + Defining new values will also require IETF standards action to + document how DNS updaters are to deal with multiple digest types. 3.5. Computation of the RDATA @@ -246,15 +251,15 @@ Internet-Draft The DHCID RR February 2006 digest = SHA-256(< identifier > < FQDN >) - The FQDN is represented in the buffer in unambiguous canonical form - as described in RFC 4034 [8], section 6.1. The identifier type code - and the identifier are related as specified in Section 3.3: the - identifier type code describes the source of the identifier. + The FQDN is represented in the buffer in the canonical wire format as + described in [9], Section 6.2. The identifier type code and the + identifier are related as specified in Section 3.3: the identifier + type code describes the source of the identifier. A DHCPv4 updater uses the 0x0002 type code if a Client Identifier option is present in the DHCPv4 messages and it is encoded as - specified in [12]. Otherwise, the updater uses 0x0001 if a Client - Identifier option is present and 0x0000 if not. + specified in [6]. Otherwise, the updater uses 0x0001 if a Client + Identifier option is present, and 0x0000 if not. A DHCPv6 updater always uses the 0x0002 type code. @@ -262,26 +267,29 @@ Internet-Draft The DHCID RR February 2006 When the updater is using the Client's DUID (either from a DHCPv6 Client Identifier option or from a portion of the DHCPv4 Client - Identifier option encoded as specified in [12]), the first two octets + Identifier option encoded as specified in [6]), the first two octets of the DHCID RR MUST be 0x0002, in network byte order. The third octet is the digest type code (1 for SHA-256). The rest of the DHCID RR MUST contain the results of computing the SHA-256 hash across the octets of the DUID followed by the FQDN. + + + + + + +Stapp, et al. Standards Track [Page 5] + +RFC 4701 The DHCID RR October 2006 + + 3.5.2. Using the Client Identifier Option When the updater is using the DHCPv4 Client Identifier option sent by the client in its DHCPREQUEST message, the first two octets of the DHCID RR MUST be 0x0001, in network byte order. The third octet is the digest type code (1 for SHA-256). The rest of the DHCID RR MUST - - - -Stapp, et al. Expires September 1, 2006 [Page 5] - -Internet-Draft The DHCID RR February 2006 - - contain the results of computing the SHA-256 hash across the data octets (i.e., the Type and Client-Identifier fields) of the option, followed by the FQDN. @@ -307,46 +315,47 @@ Internet-Draft The DHCID RR February 2006 3.6.1. Example 1 - A DHCP server allocating the IPv4 address 10.0.0.1 to a client with - Ethernet MAC address 01:02:03:04:05:06 using domain name - "client.example.com" uses the client's link-layer address to identify - the client. The DHCID RDATA is composed by setting the two type - octets to zero, the 1-octet digest type to 1 for SHA-256, and - performing an SHA-256 hash computation across a buffer containing the - Ethernet MAC type octet, 0x01, the six octets of MAC address, and the - domain name (represented as specified in Section 3.5). + A DHCP server allocates the IPv6 address 2001:DB8::1234:5678 to a + client that included the DHCPv6 client-identifier option data 00:01: + 00:06:41:2d:f1:66:01:02:03:04:05:06 in its DHCPv6 request. The + server updates the name "chi6.example.com" on the client's behalf and + uses the DHCP client identifier option data as input in forming a + DHCID RR. The DHCID RDATA is formed by setting the two type octets + to the value 0x0002, the 1-octet digest type to 1 for SHA-256, and + performing a SHA-256 hash computation across a buffer containing the + 14 octets from the client-id option and the FQDN (represented as + specified in Section 3.5). - client.example.com. A 10.0.0.1 - client.example.com. DHCID ( AAABxLmlskllE0MVjd57zHcWmEH3pCQ6V - ytcKD//7es/deY= ) + chi6.example.com. AAAA 2001:DB8::1234:5678 + chi6.example.com. DHCID ( AAIBY2/AuCccgoJbsaxcQc9TUapptP69l + OjxfNuVAA2kjEA= ) If the DHCID RR type is not supported, the RDATA would be encoded [13] as: - \# 35 ( 000001c4b9a5b249651343158dde7bcc77169841f7a4243a572b5c283 - fffedeb3f75e6 ) + + +Stapp, et al. Standards Track [Page 6] + +RFC 4701 The DHCID RR October 2006 + + + \# 35 ( 000201636fc0b8271c82825bb1ac5c41cf5351aa69b4febd94e8f17cd + b95000da48c40 ) 3.6.2. Example 2 - A DHCP server allocates the IPv4 address 10.0.12.99 to a client which + A DHCP server allocates the IPv4 address 192.0.2.2 to a client that included the DHCP client-identifier option data 01:07:08:09:0a:0b:0c - - - -Stapp, et al. Expires September 1, 2006 [Page 6] - -Internet-Draft The DHCID RR February 2006 - - in its DHCP request. The server updates the name "chi.example.com" - on the client's behalf, and uses the DHCP client identifier option + on the client's behalf and uses the DHCP client identifier option data as input in forming a DHCID RR. The DHCID RDATA is formed by setting the two type octets to the value 0x0001, the 1-octet digest type to 1 for SHA-256, and performing a SHA-256 hash computation across a buffer containing the seven octets from the client-id option and the FQDN (represented as specified in Section 3.5). - chi.example.com. A 10.0.12.99 + chi.example.com. A 192.0.2.2 chi.example.com. DHCID ( AAEBOSD+XR3Os/0LozeXVqcNc7FwCfQdW L3b/NaiUDlW2No= ) @@ -358,45 +367,43 @@ Internet-Draft The DHCID RR February 2006 3.6.3. Example 3 - A DHCP server allocates the IPv6 address 2000::1234:5678 to a client - which included the DHCPv6 client-identifier option data 00:01:00:06: - 41:2d:f1:66:01:02:03:04:05:06 in its DHCPv6 request. The server - updates the name "chi6.example.com" on the client's behalf, and uses - the DHCP client identifier option data as input in forming a DHCID - RR. The DHCID RDATA is formed by setting the two type octets to the - value 0x0002, the 1-octet digest type to 1 for SHA-256, and - performing a SHA-256 hash computation across a buffer containing the - 14 octets from the client-id option and the FQDN (represented as + A DHCP server allocating the IPv4 address 192.0.2.3 to a client with + the Ethernet MAC address 01:02:03:04:05:06 using domain name + "client.example.com" uses the client's link-layer address to identify + the client. The DHCID RDATA is composed by setting the two type + octets to zero, the 1-octet digest type to 1 for SHA-256, and + performing an SHA-256 hash computation across a buffer containing the + 1-octet 'htype' value for Ethernet, 0x01, followed by the six octets + of the Ethernet MAC address, and the domain name (represented as specified in Section 3.5). - chi6.example.com. AAAA 2000::1234:5678 - chi6.example.com. DHCID ( AAIBY2/AuCccgoJbsaxcQc9TUapptP69l - OjxfNuVAA2kjEA= ) + client.example.com. A 192.0.2.3 + client.example.com. DHCID ( AAABxLmlskllE0MVjd57zHcWmEH3pCQ6V + ytcKD//7es/deY= ) If the DHCID RR type is not supported, the RDATA would be encoded [13] as: - \# 35 ( 000201636fc0b8271c82825bb1ac5c41cf5351aa69b4febd94e8f17cd - b95000da48c40 ) + \# 35 ( 000001c4b9a5b249651343158dde7bcc77169841f7a4243a572b5c283 + fffedeb3f75e6 ) + + + + + +Stapp, et al. Standards Track [Page 7] + +RFC 4701 The DHCID RR October 2006 4. Use of the DHCID RR This RR MUST NOT be used for any purpose other than that detailed in - "Resolution of DNS Name Conflicts" [1]. Although this RR contains - data that is opaque to DNS servers, the data must be consistent - across all entities that update and interpret this record. - - - -Stapp, et al. Expires September 1, 2006 [Page 7] - -Internet-Draft The DHCID RR February 2006 - - - Therefore, new data formats may only be defined through actions of - the DHC Working Group, as a result of revising [1]. - + [1]. Although this RR contains data that is opaque to DNS servers, + the data must be consistent across all entities that update and + interpret this record. Therefore, new data formats may only be + defined through actions of the DHC Working Group, as a result of + revising [1]. 5. Updater Behavior @@ -416,12 +423,11 @@ Internet-Draft The DHCID RR February 2006 policy. That policy might dictate that a different name be selected, or it might permit the updater to continue. - 6. Security Considerations The DHCID record as such does not introduce any new security problems into the DNS. In order to obscure the client's identity information, - a one-way hash is used. And, in order to make it difficult to + a one-way hash is used. Further, in order to make it difficult to 'track' a client by examining the names associated with a particular hash value, the FQDN is included in the hash computation. Thus, the RDATA is dependent on both the DHCP client identification data and on @@ -437,37 +443,31 @@ Internet-Draft The DHCID RR February 2006 Administrators should be wary of permitting unsecured DNS updates to zones, whether or not they are exposed to the global Internet. Both DHCP clients and servers SHOULD use some form of update - authentication (e.g., TSIG [11]) when performing DNS updates. + authentication (e.g., [12]) when performing DNS updates. + + + +Stapp, et al. Standards Track [Page 8] + +RFC 4701 The DHCID RR October 2006 7. IANA Considerations - - - -Stapp, et al. Expires September 1, 2006 [Page 8] - -Internet-Draft The DHCID RR February 2006 - - - IANA is requested to allocate a DNS RR type number for the DHCID - record type. + IANA has allocated a DNS RR type number for the DHCID record type. This specification defines a new number-space for the 2-octet - identifier type codes associated with the DHCID RR. IANA is - requested to establish a registry of the values for this number- - space. Three initial values are assigned in Section 3.3, and the - value 0xFFFF is reserved for future use. New DHCID RR identifier - type codes are assigned through Standards Action, as defined in RFC - 2434 [5]. + identifier type codes associated with the DHCID RR. IANA has + established a registry of the values for this number-space. Three + initial values are assigned in Section 3.3, and the value 0xFFFF is + reserved for future use. New DHCID RR identifier type codes are + assigned through Standards Action, as defined in [5]. This specification defines a new number-space for the 1-octet digest - type codes associated with the DHCID RR. IANA is requested to - establish a registry of the values for this number-space. Two - initial values are assigned in Section 3.4. New DHCID RR digest type - codes are assigned through Standards Action, as defined in RFC 2434 - [5]. - + type codes associated with the DHCID RR. IANA has established a + registry of the values for this number-space. Two initial values are + assigned in Section 3.4. New DHCID RR digest type codes are assigned + through Standards Action, as defined in [5]. 8. Acknowledgements @@ -475,13 +475,13 @@ Internet-Draft The DHCID RR February 2006 Sam Hartman, Josh Littlefield, Pekka Savola, and especially Bernie Volz for their review and suggestions. - 9. References 9.1. Normative References - [1] Stapp, M. and B. Volz, "Resolution of DNS Name Conflicts Among - DHCP Clients (draft-ietf-dhc-dns-resolution-*)", February 2006. + [1] Stapp, M. and B. Volz, "Resolution of Fully Qualified Domain + Name (FQDN) Conflicts among Dynamic Host Configuration Protocol + (DHCP) Clients", RFC 4703, October 2006. [2] Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, March 1997. @@ -495,44 +495,42 @@ Internet-Draft The DHCID RR February 2006 [5] Narten, T. and H. Alvestrand, "Guidelines for Writing an IANA Considerations Section in RFCs", BCP 26, RFC 2434, October 1998. + [6] Lemon, T. and B. Sommerfeld, "Node-specific Client Identifiers + for Dynamic Host Configuration Protocol Version Four (DHCPv4)", + RFC 4361, February 2006. - -Stapp, et al. Expires September 1, 2006 [Page 9] +Stapp, et al. Standards Track [Page 9] -Internet-Draft The DHCID RR February 2006 +RFC 4701 The DHCID RR October 2006 9.2. Informative References - [6] Droms, R., "Dynamic Host Configuration Protocol", RFC 2131, + [7] Droms, R., "Dynamic Host Configuration Protocol", RFC 2131, March 1997. - [7] Josefsson, S., "The Base16, Base32, and Base64 Data Encodings", + [8] Josefsson, S., "The Base16, Base32, and Base64 Data Encodings", RFC 3548, July 2003. - [8] Arends, R., Austein, R., Larson, M., Massey, D., and S. Rose, + [9] Arends, R., Austein, R., Larson, M., Massey, D., and S. Rose, "Resource Records for the DNS Security Extensions", RFC 4034, March 2005. - [9] Alexander, S. and R. Droms, "DHCP Options and BOOTP Vendor + [10] Alexander, S. and R. Droms, "DHCP Options and BOOTP Vendor Extensions", RFC 2132, March 1997. - [10] Droms, R., Bound, J., Volz, B., Lemon, T., Perkins, C., and M. + [11] Droms, R., Bound, J., Volz, B., Lemon, T., Perkins, C., and M. Carney, "Dynamic Host Configuration Protocol for IPv6 (DHCPv6)", RFC 3315, July 2003. - [11] Vixie, P., Gudmundsson, O., Eastlake, D., and B. Wellington, + [12] Vixie, P., Gudmundsson, O., Eastlake, D., and B. Wellington, "Secret Key Transaction Authentication for DNS (TSIG)", RFC 2845, May 2000. - [12] Lemon, T. and B. Sommerfeld, "Node-specific Client Identifiers - for Dynamic Host Configuration Protocol Version Four (DHCPv4)", - RFC 4361, February 2006. - [13] Gustafsson, A., "Handling of Unknown DNS Resource Record (RR) Types", RFC 3597, September 2003. @@ -557,9 +555,13 @@ Internet-Draft The DHCID RR February 2006 -Stapp, et al. Expires September 1, 2006 [Page 10] + + + + +Stapp, et al. Standards Track [Page 10] -Internet-Draft The DHCID RR February 2006 +RFC 4701 The DHCID RR October 2006 Authors' Addresses @@ -571,7 +573,7 @@ Authors' Addresses USA Phone: 978.936.1535 - Email: mjs@cisco.com + EMail: mjs@cisco.com Ted Lemon @@ -580,7 +582,7 @@ Authors' Addresses Redwood City, CA 94063 USA - Email: mellon@nominum.com + EMail: mellon@nominum.com Andreas Gustafsson @@ -589,7 +591,7 @@ Authors' Addresses 02320 Espoo Finland - Email: gson@araneus.fi + EMail: gson@araneus.fi @@ -613,12 +615,28 @@ Authors' Addresses -Stapp, et al. Expires September 1, 2006 [Page 11] +Stapp, et al. Standards Track [Page 11] -Internet-Draft The DHCID RR February 2006 +RFC 4701 The DHCID RR October 2006 -Intellectual Property Statement +Full Copyright Statement + + Copyright (C) The Internet Society (2006). + + This document is subject to the rights, licenses and restrictions + contained in BCP 78, and except as set forth therein, the authors + retain all their rights. + + This document and the information contained herein are provided on an + "AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS + OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND THE INTERNET + ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, + INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE + INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED + WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. + +Intellectual Property The IETF takes no position regarding the validity or scope of any Intellectual Property Rights or other rights that might be claimed to @@ -642,33 +660,16 @@ Intellectual Property Statement this standard. Please address the information to the IETF at ietf-ipr@ietf.org. +Acknowledgement -Disclaimer of Validity - - This document and the information contained herein are provided on an - "AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS - OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND THE INTERNET - ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, - INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE - INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED - WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. - - -Copyright Statement - - Copyright (C) The Internet Society (2006). This document is subject - to the rights, licenses and restrictions contained in BCP 78, and - except as set forth therein, the authors retain all their rights. - - -Acknowledgment - - Funding for the RFC Editor function is currently provided by the - Internet Society. + Funding for the RFC Editor function is provided by the IETF + Administrative Support Activity (IASA). -Stapp, et al. Expires September 1, 2006 [Page 12] + + + +Stapp, et al. Standards Track [Page 12] -