Commit Graph
1319 Commits
Author SHA1 Message Date
Witold Kręcicki 28f35351ad - Get rid of obsolete fields in ns_client structure
- WiP - local address detection
- WiP - XFR cancel
2019-11-05 12:54:45 +01:00
Evan HuntandWitold Kręcicki f78d234ce3 remove isc_nm_paused(), it's no longer needed 2019-11-05 12:54:45 +01:00
Evan HuntandWitold Kręcicki 97da9703cd add missing atomic_exchange macro in mutexatomic.h 2019-11-05 12:54:45 +01:00
Evan HuntandWitold Kręcicki b8e54a6ca4 don't assert in isc_task_pause() if the task is 'running'
there is a window of time after a task finishes running an event
before the task state is reset from 'running' to 'ready' or 'idle'.
previously, if the network manager ran ns__client_request() during
that time, isc_task_pause() would assert.
2019-11-05 12:54:45 +01:00
Evan HuntandWitold Kręcicki 67211aa288 acquire manager lock before sending 'stoplisten' events to workers
this prevents a potential race between isc_nm_udp_stoplistening()
and isc_nm_pause() which could cause a server to deadlock.
2019-11-05 12:54:45 +01:00
Witold Kręcicki 7a677338ec Fix compilation issues in mutexatomics mode 2019-11-05 12:54:45 +01:00
Evan HuntandWitold Kręcicki 1b4bbebd11 eliminate isc_nm_shutdown in favor of isc_nm_detach 2019-11-05 12:54:45 +01:00
Evan HuntandWitold Kręcicki 021848bca9 experiment: eliminate client reference counting; use nmhandler only 2019-11-05 12:54:45 +01:00
Evan HuntandWitold Kręcicki 669f659fe3 partial fix: improve socket and metmgr cleanup for orderly shudown
- when we attempt to shut down a parent socket, but its children
  still have active handles, the destruction is delayed, and previously
  it was never resumed. now, when the last handle for a child socket is
  detached, we check again whether the parent can be destroyed.
- the netmgr is not shut down until all references to it are detached.
2019-11-05 12:54:45 +01:00
Evan HuntandWitold Kręcicki e8203e3cee documentation and namespace cleanup
- document functions in netmgr.h and netmgr-int.h
- combine identical callback typedefs into one
- remove functions that were never called
- make functions called in only one file static
- rename isc__nm_handle_*() functions to isc__nm_async_*() to avoid
  confusion with the isc__nmhandle type.
2019-11-05 12:54:45 +01:00
Witold Kręcicki 54d420f391 netmgr:
- clean up isc_nmevent structures - make generic types and just typedef to them
 - fix atomic clang warnings in astack
 - add pause/resume read for TCP
 - add sequential (not-pipelining) support for TCPDNS
 - keep peer address in the socket for TCP connections, it's constant for a socket
2019-11-05 12:54:45 +01:00
Evan HuntandWitold Kręcicki 780de22d9f rename isc_faaa_queue to isc_queue 2019-11-05 12:54:45 +01:00
Evan HuntandWitold Kręcicki f6e42f7e81 Style fixes 2019-11-05 12:54:45 +01:00
Evan HuntandWitold Kręcicki 48b4576318 remove the clienmgr->inactive queue, and the ISC_QUEUE data structure 2019-11-05 12:54:45 +01:00
Witold Kręcicki f393756c70 netmgr experiment: constant-sized stack for handle/uvreq reuse 2019-11-05 12:54:45 +01:00
Witold Kręcicki 2324d5c569 Fix isc_nm_pause - it was counting paused workers incorrectly 2019-11-05 12:54:44 +01:00
Ondřej SurýandWitold Kręcicki ac5ddd3d1f - Some style fixes
- Move typedefs to isc/types.h
2019-11-05 12:54:44 +01:00
Witold Kręcicki ce2b3fb599 hp: Can't use const atomics 2019-11-05 12:54:44 +01:00
Witold Kręcicki 8781de6782 FAAA Queue fixes, select proper threads in hp directly 2019-11-05 12:54:44 +01:00
Ondřej SurýandWitold Kręcicki ef05325179 Add implementation of hazard pointers 2019-11-05 12:54:44 +01:00
Ondřej SurýandWitold Kręcicki 41b35d978e Update the whitespaces 2019-11-05 12:54:44 +01:00
Witold Kręcicki 737cc141b6 netmgr: checkpoint: isc_task_pause/unpause - we want to pause client->task when we're processing it outside taskmgr (directly from network thread) 2019-11-05 12:54:44 +01:00
Witold Kręcicki 9b4aab53b3 netmgr: proper closing of TCP/TCPDNS connections, TCP quota support 2019-11-05 12:54:44 +01:00
Witold Kręcicki 841cd63737 netmgr: stop DNS listening, pt 1 2019-11-05 12:54:44 +01:00
Witold Kręcicki 907f983540 netmgr: pause/resume netmgr when going exclusive 2019-11-05 12:54:44 +01:00
Witold Kręcicki fa23c42b5b netmgr: isc_nm_pause/resume implementations - holds all processing 2019-11-05 12:54:44 +01:00
Witold Kręcicki fcc05948a1 netmgr: client mctxs divided by thread 2019-11-05 12:54:44 +01:00
Witold Kręcicki 1e6b065a09 nm: WiP: proper udp shutdown procedure 2019-11-05 12:54:44 +01:00
Witold Kręcicki 11f2da1e26 isc__nm_in_netthread 2019-11-05 12:54:44 +01:00
Witold Kręcicki 0de36b4bf0 Netmgr - work in progress (squashed)
- Start netmgr with named, shutdown at the end
- udplistener in interfacemgr uses netmgr
- use per-client buffer for udp send
- first steps at making ns_client_request use netmgr for UDP
- uncrustify
- Make interfacemgr and interface references isc_refcount_t instead of locked ints
- Use clock_gettime instead of gettimeofday
- Cleanup get_client, use one interface for clientmgr instead of attaching it to each client
- 'extra' field at the end of handle - for client data
- clientmgr has a taskpool, clients attach to it
- TCP support
2019-11-05 12:54:44 +01:00
Witold Kręcicki 0da36457ec Add isc_sockaddr_fromsockaddr function to convert from struct sockaddr to isc_sockaddr 2019-11-05 12:54:44 +01:00
Michał Kępień abfde3d543 Fix cppcheck 1.89 warnings
cppcheck 1.89 enabled certain value flow analysis mechanisms [1] which
trigger null pointer dereference false positives in lib/dns/rpz.c:

    lib/dns/rpz.c:582:7: warning: Possible null pointer dereference: tgt_ip [nullPointer]
      if (KEY_IS_IPV4(tgt_prefix, tgt_ip)) {
          ^
    lib/dns/rpz.c:1419:44: note: Calling function 'adj_trigger_cnt', 4th argument 'NULL' value is 0
      adj_trigger_cnt(rpzs, rpz_num, rpz_type, NULL, 0, true);
                                               ^
    lib/dns/rpz.c:582:7: note: Null pointer dereference
      if (KEY_IS_IPV4(tgt_prefix, tgt_ip)) {
          ^
    lib/dns/rpz.c:596:7: warning: Possible null pointer dereference: tgt_ip [nullPointer]
      if (KEY_IS_IPV4(tgt_prefix, tgt_ip)) {
          ^
    lib/dns/rpz.c:1419:44: note: Calling function 'adj_trigger_cnt', 4th argument 'NULL' value is 0
      adj_trigger_cnt(rpzs, rpz_num, rpz_type, NULL, 0, true);
                                               ^
    lib/dns/rpz.c:596:7: note: Null pointer dereference
      if (KEY_IS_IPV4(tgt_prefix, tgt_ip)) {
          ^
    lib/dns/rpz.c:610:7: warning: Possible null pointer dereference: tgt_ip [nullPointer]
      if (KEY_IS_IPV4(tgt_prefix, tgt_ip)) {
          ^
    lib/dns/rpz.c:1419:44: note: Calling function 'adj_trigger_cnt', 4th argument 'NULL' value is 0
      adj_trigger_cnt(rpzs, rpz_num, rpz_type, NULL, 0, true);
                                               ^
    lib/dns/rpz.c:610:7: note: Null pointer dereference
      if (KEY_IS_IPV4(tgt_prefix, tgt_ip)) {
          ^

It seems that cppcheck no longer treats at least some REQUIRE()
assertion failures as fatal, so add extra assertion macro definitions to
lib/isc/include/isc/util.h that are only used when the CPPCHECK
preprocessor macro is defined; these definitions make cppcheck 1.89
behave as expected.

There is an important requirement for these custom definitions to work:
cppcheck must properly treat abort() as a function which does not
return.  In order for that to happen, the __GNUC__ macro must be set to
a high enough number (because system include directories are used and
system headers compile attributes away if __GNUC__ is not high enough).
__GNUC__ is thus set to the major version number of the GCC compiler
used, which is what that latter does itself during compilation.

[1] https://github.com/danmar/cppcheck/commit/aaeec462e6d96bb70c2b1cf030979d09e2d7c959
2019-10-16 22:23:36 +02:00
Mark Andrews fb87e669fb Detect partial prefixes / incomplete IPv4 address in acls. 2019-10-14 00:28:07 +11:00
Ondřej Surý 635e5293b2 Remove unused RSA Security copyrighted cryptoki.h header 2019-10-04 08:35:45 +02:00
Ondřej Surý 8828a41077 Declare __SANITIZE_THREAD__ in isc/util.h when clang ThreadSanitizer is used 2019-10-02 14:09:33 +02:00
Ondřej Surý 5a788adb1c Add ATOMIC_VAR_INIT initializer to mutexatomics.h 2019-09-26 11:37:35 +02:00
Ondřej Surý 728fc0ca25 Add atomic_fetch_add and atomic_fetch_or convenience macros and unix and win32 shims 2019-09-26 11:37:35 +02:00
Ondřej SurýandOndřej Surý c47fad2431 Replace the OASIS PKCS#11 header file with one from p11-kit
The OASIS pkcs11.h header has a restrictive license.  Replace the
pkcs11.h pkcs11f.h and pkcs11t.h headers with pkcs11.h from p11-kit.

For source distribution, the license for the OASIS headers itself
doesn't pose any licensing problem when combined with MPL license, but
it possibly creates problem for downstream distributors of BIND 9.
2019-09-16 04:47:50 -04:00
Ondřej Surý aea3631fd5 Check isc_mutex_{lock,unlock}() return values in mutexatomic.h shim 2019-09-13 10:55:14 +02:00
Ondřej Surý aeea5ece97 Remove now useless ISC_MEMFLAG_NOLOCK memflag
Previously the libisc allocator had ability to run unlocked when threading was
disabled.  As the threading is now always on, remove the ISC_MEMFLAG_NOLOCK
memory flag as it serves no purpose.
2019-09-12 09:26:09 +02:00
Ondřej Surý 19fbdef31e Remove unused isc_mem_createx() function
The isc_mem_createx() function was only used in the tests to eliminate using the
default flags (which as of writing this commit message was ISC_MEMFLAG_INTERNAL
and ISC_MEMFLAG_FILL).  This commit removes the isc_mem_createx() function from
the public API.
2019-09-12 09:26:09 +02:00
Ondřej Surý 1b716a39f5 Simplify isc_mem_create() to always use defaults and never fail
Previously, the isc_mem_create() and isc_mem_createx() functions took `max_size`
and `target_size` as first two arguments.  Those values were never used in the
BIND 9 code.  The refactoring removes those arguments and let BIND 9 always use
the default values.

Previously, the isc_mem_create() and isc_mem_createx() functions could have
failed because of failed memory allocation.  As this was no longer true and the
functions have always returned ISC_R_SUCCESS, the have been refactored to return
void.
2019-09-12 09:26:09 +02:00
Mark Andrews 2f558854b7 implement maxudp under windows 2019-09-04 10:04:14 +10:00
Ondřej Surý 6fd3259560 Fix alignment issues in the native implementation of isc_siphash24()
The native implementation's conversion from the uint8_t buffers to uint64_t now
follows the reference implementation that doesn't require aligned buffers.
2019-09-02 13:21:07 +02:00
Ondřej Surý a912f31398 Add new default siphash24 cookie algorithm, but keep AES as legacy
This commit changes the BIND cookie algorithms to match
draft-sury-toorop-dnsop-server-cookies-00.  Namely, it changes the Client Cookie
algorithm to use SipHash 2-4, adds the new Server Cookie algorithm using SipHash
2-4, and changes the default for the Server Cookie algorithm to be siphash24.

Add siphash24 cookie algorithm, and make it keep legacy aes as
2019-07-21 15:16:28 -04:00
Witold Kręcicki 92424e23fa Special, for-tests-only, mode with atomics emulated by a mutex-locked variable - useful for finding atomics congestions 2019-07-09 16:09:36 +02:00
Ondřej SurýandOndřej Surý 49462cf974 Make isc_rwlock.c thread-safe
The ThreadSanitizer found several possible data races in our rwlock
implementation.  This commit changes all the unprotected variables to atomic and
also changes the explicit memory ordering (atomic_<foo>_explicit(..., <order>)
functions to use our convenience macros (atomic_<foo>_<order>).
2019-07-03 00:05:34 -04:00
Ondřej SurýandOndřej Surý 570f358252 Add atomic_compare_exchange_strong_relaxed convenience macro 2019-07-03 00:05:34 -04:00
Ondřej Surý e3e6888946 Make the usage of json-c objects opaque to the caller
The json-c have previously leaked into the global namespace leading
to forced -I<include_path> for every compilation unit using isc/xml.h
header.  This MR fixes the usage making the caller object opaque.
2019-06-25 12:04:20 +02:00
Ondřej Surý 0771dd3be8 Make the usage of libxml2 opaque to the caller
The libxml2 have previously leaked into the global namespace leading
to forced -I<include_path> for every compilation unit using isc/xml.h
header.  This MR fixes the usage making the caller object opaque.
2019-06-25 12:01:32 +02:00