Compare commits
182
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c65d26855e | ||
|
|
59156c60eb | ||
|
|
d3e2f848ec | ||
|
|
6a9031b0a6 | ||
|
|
e582d085de | ||
|
|
7f508ec229 | ||
|
|
d67b07c115 | ||
|
|
7cba3cc474 | ||
|
|
c74ee5bb17 | ||
|
|
d967e107f6 | ||
|
|
aa3e33575d | ||
|
|
7d44cc2422 | ||
|
|
d60e553a64 | ||
|
|
d03b9ec544 | ||
|
|
77f71d7d4a | ||
|
|
5928d31efc | ||
|
|
ae80e61684 | ||
|
|
1656152d76 | ||
|
|
cacd21c075 | ||
|
|
b938f50ded | ||
|
|
3c18b7d3fd | ||
|
|
e2a2f08ed5 | ||
|
|
dc410ce58f | ||
|
|
416e09d715 | ||
|
|
103b60e0bc | ||
|
|
d077f5c180 | ||
|
|
cddb699690 | ||
|
|
700614a0eb | ||
|
|
cc8a647887 | ||
|
|
c4c3b98a27 | ||
|
|
79ce86090a | ||
|
|
c268c47c76 | ||
|
|
dedb104382 | ||
|
|
fecbc7923a | ||
|
|
6034664e36 | ||
|
|
ddaa853ed6 | ||
|
|
91aa405778 | ||
|
|
0f24c55d38 | ||
|
|
9d5df99a9d | ||
|
|
b5709e5531 | ||
|
|
d1d15c03e2 | ||
|
|
69b9b9ec77 | ||
|
|
bef8ac5bae | ||
|
|
7fbbf09d21 | ||
|
|
2b74478c8f | ||
|
|
93e8ba1b50 | ||
|
|
0a7535ac81 | ||
|
|
e9e55cbd03 | ||
|
|
e119de4169 | ||
|
|
facc390b54 | ||
|
|
7ab9c9dbee | ||
|
|
ecb27adf86 | ||
|
|
f4c8e42f3e | ||
|
|
7de898777f | ||
|
|
1e404fdb0e | ||
|
|
99f17b80b8 | ||
|
|
b6e64eb23b | ||
|
|
2c19877197 | ||
|
|
19a374e45d | ||
|
|
a8b868e820 | ||
|
|
f1d658764c | ||
|
|
52e1c45156 | ||
|
|
a11a271b28 | ||
|
|
1672935717 | ||
|
|
efd613e874 | ||
|
|
1e1804bb96 | ||
|
|
62fb0759e9 | ||
|
|
29c853f500 | ||
|
|
40f7680efa | ||
|
|
e6dc08b06c | ||
|
|
388d6db5a1 | ||
|
|
3ab9c99567 | ||
|
|
8c526df306 | ||
|
|
4150a86046 | ||
|
|
5083a42072 | ||
|
|
b962f47d3e | ||
|
|
243a347d60 | ||
|
|
7b21bbb7c1 | ||
|
|
00ca487fec | ||
|
|
c19713aa51 | ||
|
|
9f4528c623 | ||
|
|
02e349c051 | ||
|
|
b02de1ec30 | ||
|
|
18e3c8d232 | ||
|
|
f0f71420c8 | ||
|
|
9a8da1e25a | ||
|
|
e53a72a649 | ||
|
|
518772e4e0 | ||
|
|
a1d783bbe2 | ||
|
|
ca0ce1cb42 | ||
|
|
525fd76685 | ||
|
|
760182271e | ||
|
|
de41f0beea | ||
|
|
55361748d7 | ||
|
|
edf5c01fcb | ||
|
|
8b3878dc7d | ||
|
|
dc4086d4f2 | ||
|
|
a3c5c2c29c | ||
|
|
0370d13667 | ||
|
|
25bb33c866 | ||
|
|
59057bee5b | ||
|
|
deb3b85cb2 | ||
|
|
d3bd90f3a7 | ||
|
|
a23162ab28 | ||
|
|
8f37439ccf | ||
|
|
7ab228cf71 | ||
|
|
18ebcf2b30 | ||
|
|
8c5aeb6c4c | ||
|
|
e79b42fec0 | ||
|
|
875b29c3e3 | ||
|
|
ba350f40ff | ||
|
|
4fb5d072c2 | ||
|
|
087157d14f | ||
|
|
2359f06aa6 | ||
|
|
e36c869e85 | ||
|
|
1c82dde85c | ||
|
|
42b16771db | ||
|
|
2c1d8b2e99 | ||
|
|
751c660b9d | ||
|
|
05531d3a86 | ||
|
|
4742f4ecba | ||
|
|
e59617441e | ||
|
|
c1bc3baf7f | ||
|
|
1056376d10 | ||
|
|
0213626992 | ||
|
|
0d6f504ba3 | ||
|
|
af1df8738f | ||
|
|
ca9aaf926f | ||
|
|
591a6c94ee | ||
|
|
4016369212 | ||
|
|
31b5360943 | ||
|
|
65de91f512 | ||
|
|
db3d69263d | ||
|
|
d877d4a561 | ||
|
|
1c57b73e34 | ||
|
|
d30b90dba6 | ||
|
|
e67f81bbf1 | ||
|
|
cb28c27b30 | ||
|
|
f9931f1d22 | ||
|
|
5431583971 | ||
|
|
d2785afebe | ||
|
|
b3b1a9081b | ||
|
|
8db550c42f | ||
|
|
71793853df | ||
|
|
2923ab4945 | ||
|
|
24b9ec555a | ||
|
|
3596bad5ce | ||
|
|
083007e930 | ||
|
|
2bb4392bb3 | ||
|
|
bf98eb41bf | ||
|
|
ab9f12c7f4 | ||
|
|
28cf1a7a9c | ||
|
|
44cec639c4 | ||
|
|
c692da2182 | ||
|
|
5cdb38c2c7 | ||
|
|
8e164f784d | ||
|
|
9c950e5961 | ||
|
|
28748db0b2 | ||
|
|
1ff71c7cee | ||
|
|
e2c938d882 | ||
|
|
0bdefcb599 | ||
|
|
4eb0897c90 | ||
|
|
7ecd699e81 | ||
|
|
eaac2057c7 | ||
|
|
509d71e1aa | ||
|
|
0ce82e9d5f | ||
|
|
53690ef21f | ||
|
|
cab7c34fbd | ||
|
|
fe20f8fe25 | ||
|
|
527614c750 | ||
|
|
13fe763798 | ||
|
|
495e10ba5a | ||
|
|
24dd865b97 | ||
|
|
e0d309572f | ||
|
|
5dd1beec8e | ||
|
|
dc5b8ec97a | ||
|
|
eed6778be4 | ||
|
|
cb40c5229a | ||
|
|
f34e7ee612 | ||
|
|
ebf3083e08 | ||
|
|
9689313331 | ||
|
|
4c06eb20cc |
+16
-1
@@ -115,12 +115,19 @@ stages:
|
||||
- test -w "${CCACHE_DIR}" && export PATH="/usr/lib/ccache:${PATH}"
|
||||
# - ./autogen.sh
|
||||
script:
|
||||
- ./configure --enable-developer --with-libtool --disable-static --with-atf=/usr $EXTRA_CONFIGURE
|
||||
- ./configure --enable-developer --with-libtool --disable-static --with-atf=/usr --prefix=$HOME/.local --without-make-clean $EXTRA_CONFIGURE || cat config.log
|
||||
- make -j${PARALLEL_JOBS_BUILD:-1} -k all V=1
|
||||
artifacts:
|
||||
expire_in: '1 hour'
|
||||
untracked: true
|
||||
|
||||
.install_test: &install_test_job
|
||||
stage: test
|
||||
before_script:
|
||||
- mkdir $HOME/.local
|
||||
script:
|
||||
- make install
|
||||
|
||||
.system_test: &system_test_job
|
||||
stage: test
|
||||
before_script:
|
||||
@@ -162,6 +169,8 @@ precheck:debian:sid:amd64:
|
||||
- perl -w util/merge_copyrights
|
||||
- diff -urNap util/copyrights util/newcopyrights
|
||||
- rm util/newcopyrights
|
||||
- perl -w util/update_copyrights < util/copyrights
|
||||
- if test "$(git status --porcelain | grep -Ev '\?\?' | wc -l)" -gt "0"; then git status --short; exit 1; fi
|
||||
- xmllint --noout --nonet `git ls-files '*.xml' '*.docbook'`
|
||||
- xmllint --noout --nonet --html `git ls-files '*.html'`
|
||||
artifacts:
|
||||
@@ -333,6 +342,12 @@ systemtest:debian:sid:i386:
|
||||
dependencies:
|
||||
- build:debian:sid:i386
|
||||
|
||||
install:debian:sid:amd64:
|
||||
<<: *debian_sid_amd64_image
|
||||
<<: *install_test_job
|
||||
dependencies:
|
||||
- build:debian:sid:amd64
|
||||
|
||||
pkcs11:build:debian:sid:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
|
||||
@@ -0,0 +1,29 @@
|
||||
##Release Checklist
|
||||
|
||||
- [ ] Check for the presence of a milestone for the release
|
||||
- If there is a milestone, are all the issues for the milestone resolved? (other than this checklist)
|
||||
- [ ] Prepare the sources for tarball generation
|
||||
- [ ] Change software version and library versions in configure.in
|
||||
- [ ] Update CHANGES
|
||||
- [ ] Ensure the release notes are correct for this release
|
||||
- [ ] Ensure the metainformation is correct for this release
|
||||
- [ ] Make sure the tests are passing
|
||||
- [ ] Create a tag (name vX_Y_Z[-alphatag], content BIND X.Y.Z[-alphatag], signed with a developer's GPG key): git tag -u <DEVELOPER_KEYID> -a -s -m "BIND X.Y.Z" vX.Y.Z
|
||||
- [ ] Push the changes and tag
|
||||
- [ ] Create the tarball
|
||||
- [ ] Create the Windows zips
|
||||
- [ ] Ask QA to sanity check the tarball and zips
|
||||
- [ ] Request the signature on the tarballs
|
||||
- [ ] Make tarballs and signatures available to download
|
||||
- [ ] Edit the release https://gitlab.isc.org/isc-projects/bind9/tags and the NEWS snippet + links to the tarballs
|
||||
- [ ] Update DEB and RPM packages
|
||||
|
||||
##Communication
|
||||
|
||||
- [ ] Inform support to upload to the web site (nice to give them a heads-up in advance)
|
||||
Write release e-mail to bind9-announce, bind-users in case of a major release
|
||||
- [ ] Inform marketing to announce the release
|
||||
Post short note to Twitter
|
||||
Update http://en.wikipedia.org/wiki/BIND (mktg)
|
||||
Blog post if a major release
|
||||
|
||||
@@ -1,3 +1,66 @@
|
||||
5027. [func] Set SO_SNDBUF size on sockets. [GL #74]
|
||||
|
||||
5026. [bug] rndc reconfig should not touch already loaded zones.
|
||||
[GL #276]
|
||||
|
||||
5025. [cleanup] Remove isc_keyboard family of functions. [GL #178]
|
||||
|
||||
5024. [func] Replace custom assembly for atomic operations with
|
||||
atomic support from the compiler. The code will now use
|
||||
C11 stdatomic, or __atomic, or __sync builtins with GCC
|
||||
or Clang compilers, and Interlocked functions with MSVC.
|
||||
[GL #10]
|
||||
|
||||
5023. [cleanup] Remove wrappers that try to fix broken or incomplete
|
||||
implementations of IPv6, pthreads and other core
|
||||
functionality required and used by BIND. [GL #192]
|
||||
|
||||
5022. [doc] Update ms-self, ms-subdomain, krb5-self, and
|
||||
krb5-subdomain documentation. [GL !708]
|
||||
|
||||
5021. [bug] dig returned a non-zero exit code when it received a
|
||||
reply over TCP after a retry. [GL #487]
|
||||
|
||||
5020. [func] RNG uses thread-local storage instead of locks, if
|
||||
supported by platform. [GL #496]
|
||||
|
||||
5019. [cleanup] A message is now logged when ixfr-from-differences is
|
||||
set at zone level for an inline-signed zone. [GL #470]
|
||||
|
||||
5018. [bug] Fix incorrect sizeof arguments in lib/isc/pk11.c.
|
||||
[GL !588]
|
||||
|
||||
5017. [bug] lib/isc/pk11.c failed to unlink the session before
|
||||
releasing the lock which is unsafe. [GL !589]
|
||||
|
||||
5016. [bug] Named could assert with overlapping filter-aaaa and
|
||||
dns64 acls. [GL #445]
|
||||
|
||||
5015. [bug] Reloading all zones caused zone maintenance to cease
|
||||
for inline-signed zones. [GL #435]
|
||||
|
||||
5014. [bug] Signatures loaded from the journal for the signed
|
||||
version of an inline-signed zone were not scheduled for
|
||||
refresh. [GL #482]
|
||||
|
||||
5013. [bug] A referral response with a non-empty ANSWER section was
|
||||
inadvertently being treated as an error. [GL #390]
|
||||
|
||||
5012. [bug] Fix lock order reversal in pk11_initialize. [GL !590]
|
||||
|
||||
5011. [func] Remove support for unthreaded named. [GL #478]
|
||||
|
||||
5010. [func] New "validate-except" option specifies a list of
|
||||
domains beneath which DNSSEC validation should not
|
||||
be performed. [GL #237]
|
||||
|
||||
5009. [bug] Upon an OpenSSL failure, the first error in the OpenSSL
|
||||
error queue was not logged. [GL #476]
|
||||
|
||||
5008. [bug] "rndc signing -nsec3param ..." requests were silently
|
||||
ignored for zones which were not yet loaded or
|
||||
transferred. [GL #468]
|
||||
|
||||
5007. [cleanup] Replace custom ISC boolean and integer data types
|
||||
with C99 stdint.h and stdbool.h types. [GL #9]
|
||||
|
||||
|
||||
+2
-1
@@ -14,7 +14,7 @@ top_builddir = @top_builddir@
|
||||
|
||||
VERSION=@BIND9_VERSION@
|
||||
|
||||
SUBDIRS = make unit lib bin doc
|
||||
SUBDIRS = make unit lib fuzz bin doc
|
||||
TARGETS =
|
||||
PREREQS = bind.keys.h
|
||||
|
||||
@@ -90,6 +90,7 @@ force-test: test-force
|
||||
|
||||
test-force:
|
||||
status=0; \
|
||||
(cd fuzz && ${MAKE} check) || status=1; \
|
||||
(cd bin/tests && ${MAKE} ${MAKEDEFS} test) || status=1; \
|
||||
(test -f ${top_builddir}/unit/unittest.sh && \
|
||||
$(SHELL) ${top_builddir}/unit/unittest.sh) || status=1; \
|
||||
|
||||
@@ -114,6 +114,9 @@ of changes from BIND 9.12 and earlier releases. New features include:
|
||||
subject to DNSSEC validation and are not treated as authoritative data
|
||||
when answering. This makes it easier to configure a local copy of the
|
||||
root zone as described in RFC 7706.
|
||||
* QNAME minimization is now supported
|
||||
* The "validate-except" option allows configuration of domains below
|
||||
which DNSSEC validation should not be performed.
|
||||
|
||||
In addition, cryptographic support has been modernized. BIND now uses the
|
||||
best available pseudo-random number generator for the platform on which
|
||||
|
||||
@@ -131,6 +131,9 @@ include:
|
||||
DNSSEC validation and are not treated as authoritative data when
|
||||
answering. This makes it easier to configure a local copy of the root
|
||||
zone as described in RFC 7706.
|
||||
* QNAME minimization is now supported
|
||||
* The "validate-except" option allows configuration of domains below which
|
||||
DNSSEC validation should not be performed.
|
||||
|
||||
In addition, cryptographic support has been modernized. BIND now uses the
|
||||
best available pseudo-random number generator for the platform on which
|
||||
@@ -144,7 +147,7 @@ Minimally, BIND requires a UNIX or Linux system with an ANSI C compiler,
|
||||
basic POSIX support, and a 64-bit integer type. Successful builds have been
|
||||
observed on many versions of Linux and UNIX, including RedHat, Fedora,
|
||||
Debian, Ubuntu, SuSE, Slackware, FreeBSD, NetBSD, OpenBSD, Mac OS X,
|
||||
Solaris, HP-UX, AIX, SCO OpenServer, and OpenWRT.
|
||||
Solaris, HP-UX, and OpenWRT.
|
||||
|
||||
BIND requires a cryptography provider library such as OpenSSL or a
|
||||
hardware service module supporting PKCS#11. On Linux, BIND requires
|
||||
@@ -268,10 +271,6 @@ specifying `--enable-fixed-rrset` or `--disable-fixed-rrset` on the
|
||||
configure command line. By default, fixed rrset-order is disabled to
|
||||
reduce memory footprint.
|
||||
|
||||
If your operating system has integrated support for IPv6, it will be used
|
||||
automatically. If you have installed KAME IPv6 separately, use
|
||||
`--with-kame[=PATH]` to specify its location.
|
||||
|
||||
`make install` will install `named` and the various BIND 9 libraries. By
|
||||
default, installation is into /usr/local, but this can be changed with the
|
||||
`--prefix` option when running `configure`.
|
||||
|
||||
-50
@@ -17,9 +17,6 @@
|
||||
***/
|
||||
@TOP@
|
||||
|
||||
/** define on DEC OSF to enable 4.4BSD style sa_len support */
|
||||
#undef _SOCKADDR_LEN
|
||||
|
||||
/** define if your system needs pthread_init() before using pthreads */
|
||||
#undef NEED_PTHREAD_INIT
|
||||
|
||||
@@ -29,9 +26,6 @@
|
||||
/** define if sigwait() is the UnixWare flavor */
|
||||
#undef HAVE_UNIXWARE_SIGWAIT
|
||||
|
||||
/** define on Solaris to get sigwait() to work using pthreads semantics */
|
||||
#undef _POSIX_PTHREAD_SEMANTICS
|
||||
|
||||
/** define if LinuxThreads is in use */
|
||||
#undef HAVE_LINUXTHREADS
|
||||
|
||||
@@ -53,62 +47,18 @@
|
||||
/** define if tzset() is available */
|
||||
#undef HAVE_TZSET
|
||||
|
||||
/** define if struct addrinfo exists */
|
||||
#undef HAVE_ADDRINFO
|
||||
|
||||
/** define if getaddrinfo() exists */
|
||||
#undef HAVE_GETADDRINFO
|
||||
|
||||
/** define if gai_strerror() exists */
|
||||
#undef HAVE_GAISTRERROR
|
||||
|
||||
/**
|
||||
* define if pthread_setconcurrency() should be called to tell the
|
||||
* OS how many threads we might want to run.
|
||||
*/
|
||||
#undef CALL_PTHREAD_SETCONCURRENCY
|
||||
|
||||
/** define if IPv6 is not disabled */
|
||||
#undef WANT_IPV6
|
||||
|
||||
/** define if flockfile() is available */
|
||||
#undef HAVE_FLOCKFILE
|
||||
|
||||
/** define if getc_unlocked() is available */
|
||||
#undef HAVE_GETCUNLOCKED
|
||||
|
||||
/** Shut up warnings about sputaux in stdio.h on BSD/OS pre-4.1 */
|
||||
#undef SHUTUP_SPUTAUX
|
||||
#ifdef SHUTUP_SPUTAUX
|
||||
struct __sFILE;
|
||||
extern __inline int __sputaux(int _c, struct __sFILE *_p);
|
||||
#endif
|
||||
|
||||
/** Shut up warnings about missing sigwait prototype on BSD/OS 4.0* */
|
||||
#undef SHUTUP_SIGWAIT
|
||||
#ifdef SHUTUP_SIGWAIT
|
||||
int sigwait(const unsigned int *set, int *sig);
|
||||
#endif
|
||||
|
||||
/** Shut up warnings from gcc -Wcast-qual on BSD/OS 4.1. */
|
||||
#undef SHUTUP_STDARG_CAST
|
||||
#if defined(SHUTUP_STDARG_CAST) && defined(__GNUC__)
|
||||
#include <stdarg.h> /** Grr. Must be included *every time*. */
|
||||
/**
|
||||
* The silly continuation line is to keep configure from
|
||||
* commenting out the #undef.
|
||||
*/
|
||||
|
||||
#undef \
|
||||
va_start
|
||||
#define va_start(ap, last) \
|
||||
do { \
|
||||
union { const void *konst; long *var; } _u; \
|
||||
_u.konst = &(last); \
|
||||
ap = (va_list)(_u.var + __va_words(__typeof(last))); \
|
||||
} while (0)
|
||||
#endif /** SHUTUP_STDARG_CAST && __GNUC__ */
|
||||
|
||||
/** define if the system has a random number generating device */
|
||||
#undef PATH_RANDOMDEV
|
||||
|
||||
|
||||
Vendored
+1
@@ -289,6 +289,7 @@ AS_VAR_IF([$1], [""], [$5], [$4])dnl
|
||||
])dnl PKG_CHECK_VAR
|
||||
|
||||
m4_include([m4/ax_check_openssl.m4])
|
||||
m4_include([m4/ax_pthread.m4])
|
||||
m4_include([m4/libtool.m4])
|
||||
m4_include([m4/ltoptions.m4])
|
||||
m4_include([m4/ltsugar.m4])
|
||||
|
||||
+1
-22
@@ -62,14 +62,6 @@
|
||||
#define CHECK_LOCAL 1
|
||||
#endif
|
||||
|
||||
#ifdef HAVE_ADDRINFO
|
||||
#ifdef HAVE_GETADDRINFO
|
||||
#ifdef HAVE_GAISTRERROR
|
||||
#define USE_GETADDRINFO
|
||||
#endif
|
||||
#endif
|
||||
#endif
|
||||
|
||||
#define CHECK(r) \
|
||||
do { \
|
||||
result = (r); \
|
||||
@@ -177,7 +169,6 @@ static bool
|
||||
checkns(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner,
|
||||
dns_rdataset_t *a, dns_rdataset_t *aaaa)
|
||||
{
|
||||
#ifdef USE_GETADDRINFO
|
||||
dns_rdataset_t *rdataset;
|
||||
dns_rdata_t rdata = DNS_RDATA_INIT;
|
||||
struct addrinfo hints, *ai, *cur;
|
||||
@@ -373,14 +364,10 @@ checkns(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner,
|
||||
}
|
||||
freeaddrinfo(ai);
|
||||
return (answer);
|
||||
#else
|
||||
return (true);
|
||||
#endif
|
||||
}
|
||||
|
||||
static bool
|
||||
checkmx(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
||||
#ifdef USE_GETADDRINFO
|
||||
struct addrinfo hints, *ai, *cur;
|
||||
char namebuf[DNS_NAME_FORMATSIZE + 1];
|
||||
char ownerbuf[DNS_NAME_FORMATSIZE];
|
||||
@@ -459,14 +446,10 @@ checkmx(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
||||
}
|
||||
return (true);
|
||||
}
|
||||
#else
|
||||
return (true);
|
||||
#endif
|
||||
}
|
||||
|
||||
static bool
|
||||
checksrv(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
||||
#ifdef USE_GETADDRINFO
|
||||
struct addrinfo hints, *ai, *cur;
|
||||
char namebuf[DNS_NAME_FORMATSIZE + 1];
|
||||
char ownerbuf[DNS_NAME_FORMATSIZE];
|
||||
@@ -544,9 +527,6 @@ checksrv(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
||||
}
|
||||
return (true);
|
||||
}
|
||||
#else
|
||||
return (true);
|
||||
#endif
|
||||
}
|
||||
|
||||
isc_result_t
|
||||
@@ -711,7 +691,7 @@ load_zone(isc_mem_t *mctx, const char *zonename, const char *filename,
|
||||
if (dochecksrv)
|
||||
dns_zone_setchecksrv(zone, checksrv);
|
||||
|
||||
CHECK(dns_zone_load(zone));
|
||||
CHECK(dns_zone_load(zone, false));
|
||||
|
||||
/*
|
||||
* When loading map files we can't catch oversize TTLs during
|
||||
@@ -791,4 +771,3 @@ DestroySockets(void) {
|
||||
WSACleanup();
|
||||
}
|
||||
#endif
|
||||
|
||||
|
||||
@@ -28,7 +28,6 @@
|
||||
#include <isc/buffer.h>
|
||||
#include <isc/commandline.h>
|
||||
#include <isc/file.h>
|
||||
#include <isc/keyboard.h>
|
||||
#include <isc/mem.h>
|
||||
#include <isc/net.h>
|
||||
#include <isc/print.h>
|
||||
|
||||
@@ -20,7 +20,6 @@
|
||||
#include <isc/base64.h>
|
||||
#include <isc/buffer.h>
|
||||
#include <isc/file.h>
|
||||
#include <isc/keyboard.h>
|
||||
#include <isc/mem.h>
|
||||
#include <isc/print.h>
|
||||
#include <isc/result.h>
|
||||
@@ -192,4 +191,3 @@ write_key_file(const char *keyfile, const char *user,
|
||||
fatal("fclose(%s) failed\n", keyfile);
|
||||
fprintf(stderr, "wrote key file \"%s\"\n", keyfile);
|
||||
}
|
||||
|
||||
|
||||
@@ -31,7 +31,6 @@
|
||||
#include <isc/buffer.h>
|
||||
#include <isc/commandline.h>
|
||||
#include <isc/file.h>
|
||||
#include <isc/keyboard.h>
|
||||
#include <isc/mem.h>
|
||||
#include <isc/net.h>
|
||||
#include <isc/print.h>
|
||||
|
||||
+2
-2
@@ -263,7 +263,7 @@ received(unsigned int bytes, isc_sockaddr_t *from, dig_query_t *query) {
|
||||
printf(";; Query time: %ld msec\n", (long) diff / 1000);
|
||||
printf(";; SERVER: %s(%s)\n", fromtext, query->servname);
|
||||
time(&tnow);
|
||||
#if defined(ISC_PLATFORM_USETHREADS) && !defined(WIN32)
|
||||
#if !defined(WIN32)
|
||||
(void)localtime_r(&tnow, &tmnow);
|
||||
#else
|
||||
tmnow = *localtime(&tnow);
|
||||
@@ -1008,7 +1008,7 @@ plus_option(char *option, bool is_batchfile,
|
||||
code = NULL;
|
||||
if (value != NULL) {
|
||||
code = strtok_r(value,
|
||||
":",
|
||||
":",
|
||||
&last);
|
||||
}
|
||||
if (code == NULL) {
|
||||
|
||||
@@ -3202,6 +3202,7 @@ connect_done(isc_task_t *task, isc_event_t *event) {
|
||||
UNLOCK_LOOKUP;
|
||||
return;
|
||||
}
|
||||
exitcode = 0;
|
||||
if (keep_open) {
|
||||
if (keep != NULL)
|
||||
isc_socket_detach(&keep);
|
||||
|
||||
@@ -29,7 +29,6 @@
|
||||
#include <isc/string.h>
|
||||
#include <isc/util.h>
|
||||
#include <isc/task.h>
|
||||
#include <isc/stdlib.h>
|
||||
|
||||
#include <dns/byaddr.h>
|
||||
#include <dns/fixedname.h>
|
||||
|
||||
@@ -62,7 +62,7 @@
|
||||
#include "dnssectool.h"
|
||||
|
||||
#ifndef PATH_MAX
|
||||
#define PATH_MAX 1024 /* AIX, WIN32, and others don't define this. */
|
||||
#define PATH_MAX 1024 /* WIN32, and others don't define this. */
|
||||
#endif
|
||||
|
||||
const char *program = "dnssec-cds";
|
||||
|
||||
@@ -50,7 +50,7 @@
|
||||
#include "dnssectool.h"
|
||||
|
||||
#ifndef PATH_MAX
|
||||
#define PATH_MAX 1024 /* AIX, WIN32, and others don't define this. */
|
||||
#define PATH_MAX 1024 /* WIN32, and others don't define this. */
|
||||
#endif
|
||||
|
||||
const char *program = "dnssec-dsfromkey";
|
||||
|
||||
@@ -49,7 +49,7 @@
|
||||
#include "dnssectool.h"
|
||||
|
||||
#ifndef PATH_MAX
|
||||
#define PATH_MAX 1024 /* AIX, WIN32, and others don't define this. */
|
||||
#define PATH_MAX 1024 /* WIN32, and others don't define this. */
|
||||
#endif
|
||||
|
||||
const char *program = "dnssec-importkey";
|
||||
|
||||
@@ -49,7 +49,6 @@
|
||||
#include <isc/serial.h>
|
||||
#include <isc/safe.h>
|
||||
#include <isc/stdio.h>
|
||||
#include <isc/stdlib.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/task.h>
|
||||
#include <isc/time.h>
|
||||
@@ -89,7 +88,7 @@
|
||||
#include "dnssectool.h"
|
||||
|
||||
#ifndef PATH_MAX
|
||||
#define PATH_MAX 1024 /* AIX, WIN32, and others don't define this. */
|
||||
#define PATH_MAX 1024 /* WIN32, and others don't define this. */
|
||||
#endif
|
||||
|
||||
const char *program = "dnssec-signzone";
|
||||
|
||||
@@ -32,7 +32,6 @@
|
||||
#include <isc/rwlock.h>
|
||||
#include <isc/serial.h>
|
||||
#include <isc/stdio.h>
|
||||
#include <isc/stdlib.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/time.h>
|
||||
#include <isc/util.h>
|
||||
|
||||
@@ -410,7 +410,7 @@ key_collision(dst_key_t *dstkey, dns_name_t *name, const char *dir,
|
||||
uint16_t id, oldid;
|
||||
uint32_t rid, roldid;
|
||||
dns_secalg_t alg;
|
||||
char filename[ISC_DIR_NAMEMAX];
|
||||
char filename[NAME_MAX];
|
||||
isc_buffer_t fileb;
|
||||
isc_stdtime_t now;
|
||||
|
||||
|
||||
+11
-9
@@ -9,7 +9,7 @@
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
#include "config.h"
|
||||
#include <config.h>
|
||||
|
||||
#include <inttypes.h>
|
||||
#include <stdbool.h>
|
||||
@@ -36,10 +36,6 @@
|
||||
#include <unistd.h>
|
||||
#include <pthread.h>
|
||||
|
||||
#ifndef __AFL_LOOP
|
||||
#error To use American Fuzzy Lop you have to set CC to afl-clang-fast!!!
|
||||
#endif
|
||||
|
||||
/*
|
||||
* We are using pthreads directly because we might be using it with
|
||||
* unthreaded version of BIND, where all thread functions are
|
||||
@@ -61,7 +57,6 @@ fuzz_thread_client(void *arg) {
|
||||
char *port;
|
||||
struct sockaddr_in servaddr;
|
||||
int sockfd;
|
||||
int loop;
|
||||
void *buf;
|
||||
|
||||
UNUSED(arg);
|
||||
@@ -103,14 +98,18 @@ fuzz_thread_client(void *arg) {
|
||||
* Processing fuzzed packets 100,000 times before shutting down
|
||||
* the app.
|
||||
*/
|
||||
for (loop = 0; loop < 100000; loop++) {
|
||||
#ifdef __AFL_LOOP
|
||||
for (int loop = 0; loop < 100000; loop++) {
|
||||
#else
|
||||
{
|
||||
#endif
|
||||
ssize_t length;
|
||||
ssize_t sent;
|
||||
|
||||
length = read(0, buf, 65536);
|
||||
if (length <= 0) {
|
||||
usleep(1000000);
|
||||
continue;
|
||||
goto next;
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -130,7 +129,7 @@ fuzz_thread_client(void *arg) {
|
||||
return (NULL);
|
||||
}
|
||||
raise(SIGSTOP);
|
||||
continue;
|
||||
goto next;
|
||||
}
|
||||
|
||||
RUNTIME_CHECK(pthread_mutex_lock(&mutex) == 0);
|
||||
@@ -151,6 +150,7 @@ fuzz_thread_client(void *arg) {
|
||||
pthread_cond_wait(&cond, &mutex);
|
||||
|
||||
RUNTIME_CHECK(pthread_mutex_unlock(&mutex) == 0);
|
||||
next: ;
|
||||
}
|
||||
|
||||
free(buf);
|
||||
@@ -586,6 +586,7 @@ fuzz_thread_resolver(void *arg) {
|
||||
named_server_flushonshutdown(named_g_server, false);
|
||||
isc_app_shutdown();
|
||||
|
||||
#ifdef __AFL_LOOP
|
||||
/*
|
||||
* This is here just for the signature, that's how AFL detects
|
||||
* if it's a 'persistent mode' binary. It has to occur somewhere
|
||||
@@ -594,6 +595,7 @@ fuzz_thread_resolver(void *arg) {
|
||||
* in persistent mode if it's present.
|
||||
*/
|
||||
__AFL_LOOP(0);
|
||||
#endif
|
||||
|
||||
return (NULL);
|
||||
}
|
||||
|
||||
+2
-14
@@ -110,8 +110,8 @@ LIBDNS_EXTERNAL_DATA extern unsigned int dns_zone_mkey_day;
|
||||
LIBDNS_EXTERNAL_DATA extern unsigned int dns_zone_mkey_month;
|
||||
|
||||
static bool want_stats = false;
|
||||
static char program_name[ISC_DIR_NAMEMAX] = "named";
|
||||
static char absolute_conffile[ISC_DIR_PATHMAX];
|
||||
static char program_name[NAME_MAX] = "named";
|
||||
static char absolute_conffile[PATH_MAX];
|
||||
static char saved_command_line[512];
|
||||
static char version[512];
|
||||
static unsigned int maxsocks = 0;
|
||||
@@ -720,11 +720,7 @@ parse_command_line(int argc, char *argv[]) {
|
||||
printf("linked to zlib version: %s\n",
|
||||
zlibVersion());
|
||||
#endif
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
printf("threads support is enabled\n");
|
||||
#else
|
||||
printf("threads support is disabled\n");
|
||||
#endif
|
||||
exit(0);
|
||||
case 'x':
|
||||
/* Obsolete. No longer in use. Ignore. */
|
||||
@@ -776,7 +772,6 @@ create_managers(void) {
|
||||
|
||||
INSIST(named_g_cpus_detected > 0);
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
if (named_g_cpus == 0)
|
||||
named_g_cpus = named_g_cpus_detected;
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
@@ -785,9 +780,6 @@ create_managers(void) {
|
||||
named_g_cpus_detected,
|
||||
named_g_cpus_detected == 1 ? "" : "s",
|
||||
named_g_cpus, named_g_cpus == 1 ? "" : "s");
|
||||
#else
|
||||
named_g_cpus = 1;
|
||||
#endif
|
||||
#ifdef WIN32
|
||||
named_g_udpdisp = 1;
|
||||
#else
|
||||
@@ -800,12 +792,10 @@ create_managers(void) {
|
||||
if (named_g_udpdisp > named_g_cpus)
|
||||
named_g_udpdisp = named_g_cpus;
|
||||
#endif
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
|
||||
"using %u UDP listener%s per interface",
|
||||
named_g_udpdisp, named_g_udpdisp == 1 ? "" : "s");
|
||||
#endif
|
||||
|
||||
result = isc_taskmgr_create(named_g_mctx, named_g_cpus, 0,
|
||||
&named_g_taskmgr);
|
||||
@@ -917,12 +907,10 @@ setup(void) {
|
||||
isc_mem_free(named_g_mctx, instance);
|
||||
#endif /* HAVE_LIBSCF */
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
/*
|
||||
* Check for the number of cpu's before named_os_chroot().
|
||||
*/
|
||||
named_g_cpus_detected = isc_os_ncpus();
|
||||
#endif
|
||||
|
||||
named_os_chroot(named_g_chrootdir);
|
||||
|
||||
|
||||
@@ -13,7 +13,7 @@
|
||||
|
||||
<refentry xmlns:db="http://docbook.org/ns/docbook" version="5.0" xml:id="man.named.conf">
|
||||
<info>
|
||||
<date>2018-05-29</date>
|
||||
<date>2018-06-21</date>
|
||||
</info>
|
||||
<refentryinfo>
|
||||
<corpname>ISC</corpname>
|
||||
@@ -224,9 +224,9 @@ options {
|
||||
coresize ( default | unlimited | <replaceable>sizeval</replaceable> );
|
||||
datasize ( default | unlimited | <replaceable>sizeval</replaceable> );
|
||||
deny-answer-addresses { <replaceable>address_match_element</replaceable>; ... } [
|
||||
except-from { <replaceable>quoted_string</replaceable>; ... } ];
|
||||
deny-answer-aliases { <replaceable>quoted_string</replaceable>; ... } [ except-from {
|
||||
<replaceable>quoted_string</replaceable>; ... } ];
|
||||
except-from { <replaceable>string</replaceable>; ... } ];
|
||||
deny-answer-aliases { <replaceable>string</replaceable>; ... } [ except-from { <replaceable>string</replaceable>; ...
|
||||
} ];
|
||||
dialup ( notify | notify-passive | passive | refresh | <replaceable>boolean</replaceable> );
|
||||
directory <replaceable>quoted_string</replaceable>;
|
||||
disable-algorithms <replaceable>string</replaceable> { <replaceable>string</replaceable>;
|
||||
@@ -257,14 +257,12 @@ options {
|
||||
dnssec-secure-to-insecure <replaceable>boolean</replaceable>;
|
||||
dnssec-update-mode ( maintain | no-resign );
|
||||
dnssec-validation ( yes | no | auto );
|
||||
dnstap { ( all | auth | client | forwarder |
|
||||
resolver ) [ ( query | response ) ]; ... };
|
||||
dnstap-identity ( <replaceable>quoted_string</replaceable> | none |
|
||||
hostname );
|
||||
dnstap-output ( file | unix ) <replaceable>quoted_string</replaceable> [
|
||||
size ( unlimited | <replaceable>size</replaceable> ) ] [ versions (
|
||||
unlimited | <replaceable>integer</replaceable> ) ] [ suffix ( increment
|
||||
| timestamp ) ];
|
||||
dnstap { ( all | auth | client | forwarder | resolver ) [ ( query |
|
||||
response ) ]; ... };
|
||||
dnstap-identity ( <replaceable>quoted_string</replaceable> | none | hostname );
|
||||
dnstap-output ( file | unix ) <replaceable>quoted_string</replaceable> [ size ( unlimited |
|
||||
<replaceable>size</replaceable> ) ] [ versions ( unlimited | <replaceable>integer</replaceable> ) ] [ suffix (
|
||||
increment | timestamp ) ];
|
||||
dnstap-version ( <replaceable>quoted_string</replaceable> | none );
|
||||
dscp <replaceable>integer</replaceable>;
|
||||
dual-stack-servers [ port <replaceable>integer</replaceable> ] { ( <replaceable>quoted_string</replaceable> [ port
|
||||
@@ -362,7 +360,7 @@ options {
|
||||
preferred-glue <replaceable>string</replaceable>;
|
||||
prefetch <replaceable>integer</replaceable> [ <replaceable>integer</replaceable> ];
|
||||
provide-ixfr <replaceable>boolean</replaceable>;
|
||||
qname-minimization ( strict | relaxed | disabled );
|
||||
qname-minimization ( strict | relaxed | disabled | off );
|
||||
query-source ( ( [ address ] ( <replaceable>ipv4_address</replaceable> | * ) [ port (
|
||||
<replaceable>integer</replaceable> | * ) ] ) | ( [ [ address ] ( <replaceable>ipv4_address</replaceable> | * ) ]
|
||||
port ( <replaceable>integer</replaceable> | * ) ) ) [ dscp <replaceable>integer</replaceable> ];
|
||||
@@ -413,7 +411,7 @@ options {
|
||||
nsip-enable <replaceable>boolean</replaceable> ] [ nsdname-enable <replaceable>boolean</replaceable> ] [
|
||||
dnsrps-enable <replaceable>boolean</replaceable> ] [ dnsrps-options { <replaceable>unspecified-text</replaceable>
|
||||
} ];
|
||||
root-delegation-only [ exclude { <replaceable>quoted_string</replaceable>; ... } ];
|
||||
root-delegation-only [ exclude { <replaceable>string</replaceable>; ... } ];
|
||||
root-key-sentinel <replaceable>boolean</replaceable>;
|
||||
rrset-order { [ class <replaceable>string</replaceable> ] [ type <replaceable>string</replaceable> ] [ name
|
||||
<replaceable>quoted_string</replaceable> ] <replaceable>string</replaceable> <replaceable>string</replaceable>; ... };
|
||||
@@ -463,6 +461,7 @@ options {
|
||||
use-v4-udp-ports { <replaceable>portrange</replaceable>; ... };
|
||||
use-v6-udp-ports { <replaceable>portrange</replaceable>; ... };
|
||||
v6-bias <replaceable>integer</replaceable>;
|
||||
validate-except { <replaceable>string</replaceable>; ... };
|
||||
version ( <replaceable>quoted_string</replaceable> | none );
|
||||
zero-no-soa-ttl <replaceable>boolean</replaceable>;
|
||||
zero-no-soa-ttl-cache <replaceable>boolean</replaceable>;
|
||||
@@ -574,9 +573,9 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
||||
cleaning-interval <replaceable>integer</replaceable>;
|
||||
clients-per-query <replaceable>integer</replaceable>;
|
||||
deny-answer-addresses { <replaceable>address_match_element</replaceable>; ... } [
|
||||
except-from { <replaceable>quoted_string</replaceable>; ... } ];
|
||||
deny-answer-aliases { <replaceable>quoted_string</replaceable>; ... } [ except-from {
|
||||
<replaceable>quoted_string</replaceable>; ... } ];
|
||||
except-from { <replaceable>string</replaceable>; ... } ];
|
||||
deny-answer-aliases { <replaceable>string</replaceable>; ... } [ except-from { <replaceable>string</replaceable>; ...
|
||||
} ];
|
||||
dialup ( notify | notify-passive | passive | refresh | <replaceable>boolean</replaceable> );
|
||||
disable-algorithms <replaceable>string</replaceable> { <replaceable>string</replaceable>;
|
||||
... };
|
||||
@@ -610,8 +609,8 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
||||
dnssec-secure-to-insecure <replaceable>boolean</replaceable>;
|
||||
dnssec-update-mode ( maintain | no-resign );
|
||||
dnssec-validation ( yes | no | auto );
|
||||
dnstap { ( all | auth | client | forwarder |
|
||||
resolver ) [ ( query | response ) ]; ... };
|
||||
dnstap { ( all | auth | client | forwarder | resolver ) [ ( query |
|
||||
response ) ]; ... };
|
||||
dual-stack-servers [ port <replaceable>integer</replaceable> ] { ( <replaceable>quoted_string</replaceable> [ port
|
||||
<replaceable>integer</replaceable> ] [ dscp <replaceable>integer</replaceable> ] | <replaceable>ipv4_address</replaceable> [ port
|
||||
<replaceable>integer</replaceable> ] [ dscp <replaceable>integer</replaceable> ] | <replaceable>ipv6_address</replaceable> [ port
|
||||
@@ -689,7 +688,7 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
||||
preferred-glue <replaceable>string</replaceable>;
|
||||
prefetch <replaceable>integer</replaceable> [ <replaceable>integer</replaceable> ];
|
||||
provide-ixfr <replaceable>boolean</replaceable>;
|
||||
qname-minimization ( strict | relaxed | disabled );
|
||||
qname-minimization ( strict | relaxed | disabled | off );
|
||||
query-source ( ( [ address ] ( <replaceable>ipv4_address</replaceable> | * ) [ port (
|
||||
<replaceable>integer</replaceable> | * ) ] ) | ( [ [ address ] ( <replaceable>ipv4_address</replaceable> | * ) ]
|
||||
port ( <replaceable>integer</replaceable> | * ) ) ) [ dscp <replaceable>integer</replaceable> ];
|
||||
@@ -735,7 +734,7 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
||||
nsip-enable <replaceable>boolean</replaceable> ] [ nsdname-enable <replaceable>boolean</replaceable> ] [
|
||||
dnsrps-enable <replaceable>boolean</replaceable> ] [ dnsrps-options { <replaceable>unspecified-text</replaceable>
|
||||
} ];
|
||||
root-delegation-only [ exclude { <replaceable>quoted_string</replaceable>; ... } ];
|
||||
root-delegation-only [ exclude { <replaceable>string</replaceable>; ... } ];
|
||||
root-key-sentinel <replaceable>boolean</replaceable>;
|
||||
rrset-order { [ class <replaceable>string</replaceable> ] [ type <replaceable>string</replaceable> ] [ name
|
||||
<replaceable>quoted_string</replaceable> ] <replaceable>string</replaceable> <replaceable>string</replaceable>; ... };
|
||||
@@ -797,6 +796,7 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
||||
update-check-ksk <replaceable>boolean</replaceable>;
|
||||
use-alt-transfer-source <replaceable>boolean</replaceable>;
|
||||
v6-bias <replaceable>integer</replaceable>;
|
||||
validate-except { <replaceable>string</replaceable>; ... };
|
||||
zero-no-soa-ttl <replaceable>boolean</replaceable>;
|
||||
zero-no-soa-ttl-cache <replaceable>boolean</replaceable>;
|
||||
zone <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
||||
@@ -878,7 +878,7 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
||||
serial-update-method ( date | increment | unixtime );
|
||||
server-addresses { ( <replaceable>ipv4_address</replaceable> | <replaceable>ipv6_address</replaceable> ) [
|
||||
port <replaceable>integer</replaceable> ]; ... };
|
||||
server-names { <replaceable>quoted_string</replaceable>; ... };
|
||||
server-names { <replaceable>string</replaceable>; ... };
|
||||
sig-signing-nodes <replaceable>integer</replaceable>;
|
||||
sig-signing-signatures <replaceable>integer</replaceable>;
|
||||
sig-signing-type <replaceable>integer</replaceable>;
|
||||
@@ -982,7 +982,7 @@ zone <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
||||
serial-update-method ( date | increment | unixtime );
|
||||
server-addresses { ( <replaceable>ipv4_address</replaceable> | <replaceable>ipv6_address</replaceable> ) [ port
|
||||
<replaceable>integer</replaceable> ]; ... };
|
||||
server-names { <replaceable>quoted_string</replaceable>; ... };
|
||||
server-names { <replaceable>string</replaceable>; ... };
|
||||
sig-signing-nodes <replaceable>integer</replaceable>;
|
||||
sig-signing-signatures <replaceable>integer</replaceable>;
|
||||
sig-signing-type <replaceable>integer</replaceable>;
|
||||
|
||||
+103
-58
@@ -2608,12 +2608,12 @@ catz_addmodzone_taskaction(isc_task_t *task, isc_event_t *event0) {
|
||||
* Load the zone from the master file. If this fails, we'll
|
||||
* need to undo the configuration we've done already.
|
||||
*/
|
||||
result = dns_zone_loadnew(zone);
|
||||
result = dns_zone_load(zone, true);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
dns_db_t *dbp = NULL;
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"catz: dns_zone_loadnew() failed "
|
||||
"catz: dns_zone_load() failed "
|
||||
"with %s; reverting.",
|
||||
isc_result_totext(result));
|
||||
|
||||
@@ -3692,6 +3692,7 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
||||
isc_dscp_t dscp4 = -1, dscp6 = -1;
|
||||
dns_dyndbctx_t *dctx = NULL;
|
||||
unsigned int resolver_param;
|
||||
dns_ntatable_t *ntatable = NULL;
|
||||
const char *qminmode = NULL;
|
||||
|
||||
REQUIRE(DNS_VIEW_VALID(view));
|
||||
@@ -5348,8 +5349,35 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
||||
CHECK(dns_name_fromstring(name, cfg_obj_asstring(obj), 0,
|
||||
NULL));
|
||||
view->redirectzone = name;
|
||||
} else
|
||||
} else {
|
||||
view->redirectzone = NULL;
|
||||
}
|
||||
|
||||
/*
|
||||
* Exceptions to DNSSEC validation.
|
||||
*/
|
||||
obj = NULL;
|
||||
result = named_config_get(maps, "validate-except", &obj);
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
result = dns_view_getntatable(view, &ntatable);
|
||||
}
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
for (element = cfg_list_first(obj);
|
||||
element != NULL;
|
||||
element = cfg_list_next(element))
|
||||
{
|
||||
dns_fixedname_t fntaname;
|
||||
dns_name_t *ntaname;
|
||||
|
||||
ntaname = dns_fixedname_initname(&fntaname);
|
||||
obj = cfg_listelt_value(element);
|
||||
CHECK(dns_name_fromstring(ntaname,
|
||||
cfg_obj_asstring(obj),
|
||||
0, NULL));
|
||||
CHECK(dns_ntatable_add(ntatable, ntaname,
|
||||
true, 0, 0xffffffffU));
|
||||
}
|
||||
}
|
||||
|
||||
#ifdef HAVE_DNSTAP
|
||||
/*
|
||||
@@ -5362,35 +5390,51 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
||||
result = ISC_R_SUCCESS;
|
||||
|
||||
cleanup:
|
||||
if (clients != NULL)
|
||||
if (ntatable != NULL) {
|
||||
dns_ntatable_detach(&ntatable);
|
||||
}
|
||||
if (clients != NULL) {
|
||||
dns_acl_detach(&clients);
|
||||
if (mapped != NULL)
|
||||
}
|
||||
if (mapped != NULL) {
|
||||
dns_acl_detach(&mapped);
|
||||
if (excluded != NULL)
|
||||
}
|
||||
if (excluded != NULL) {
|
||||
dns_acl_detach(&excluded);
|
||||
if (ring != NULL)
|
||||
}
|
||||
if (ring != NULL) {
|
||||
dns_tsigkeyring_detach(&ring);
|
||||
if (zone != NULL)
|
||||
}
|
||||
if (zone != NULL) {
|
||||
dns_zone_detach(&zone);
|
||||
if (dispatch4 != NULL)
|
||||
}
|
||||
if (dispatch4 != NULL) {
|
||||
dns_dispatch_detach(&dispatch4);
|
||||
if (dispatch6 != NULL)
|
||||
}
|
||||
if (dispatch6 != NULL) {
|
||||
dns_dispatch_detach(&dispatch6);
|
||||
if (resstats != NULL)
|
||||
}
|
||||
if (resstats != NULL) {
|
||||
isc_stats_detach(&resstats);
|
||||
if (resquerystats != NULL)
|
||||
}
|
||||
if (resquerystats != NULL) {
|
||||
dns_stats_detach(&resquerystats);
|
||||
if (order != NULL)
|
||||
}
|
||||
if (order != NULL) {
|
||||
dns_order_detach(&order);
|
||||
if (cmctx != NULL)
|
||||
}
|
||||
if (cmctx != NULL) {
|
||||
isc_mem_detach(&cmctx);
|
||||
if (hmctx != NULL)
|
||||
}
|
||||
if (hmctx != NULL) {
|
||||
isc_mem_detach(&hmctx);
|
||||
|
||||
if (cache != NULL)
|
||||
}
|
||||
if (cache != NULL) {
|
||||
dns_cache_detach(&cache);
|
||||
if (dctx != NULL)
|
||||
}
|
||||
if (dctx != NULL) {
|
||||
dns_dyndb_destroyctx(&dctx);
|
||||
}
|
||||
|
||||
return (result);
|
||||
}
|
||||
@@ -5734,6 +5778,7 @@ configure_zone(const cfg_obj_t *config, const cfg_obj_t *zconfig,
|
||||
const cfg_obj_t *typeobj = NULL;
|
||||
const cfg_obj_t *forwarders = NULL;
|
||||
const cfg_obj_t *forwardtype = NULL;
|
||||
const cfg_obj_t *ixfrfromdiffs = NULL;
|
||||
const cfg_obj_t *only = NULL;
|
||||
const cfg_obj_t *signing = NULL;
|
||||
const cfg_obj_t *viewobj = NULL;
|
||||
@@ -6087,6 +6132,15 @@ configure_zone(const cfg_obj_t *config, const cfg_obj_t *zconfig,
|
||||
dns_zone_setstats(raw, named_g_server->zonestats);
|
||||
CHECK(dns_zone_link(zone, raw));
|
||||
}
|
||||
if (cfg_map_get(zoptions, "ixfr-from-differences",
|
||||
&ixfrfromdiffs) == ISC_R_SUCCESS)
|
||||
{
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
|
||||
"zone '%s': 'ixfr-from-differences' is "
|
||||
"ignored for inline-signed zones",
|
||||
zname);
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -9089,7 +9143,6 @@ view_loaded(void *arg) {
|
||||
ns_zoneload_t *zl = (ns_zoneload_t *) arg;
|
||||
named_server_t *server = zl->server;
|
||||
bool reconfig = zl->reconfig;
|
||||
unsigned int refs;
|
||||
|
||||
|
||||
/*
|
||||
@@ -9100,35 +9153,34 @@ view_loaded(void *arg) {
|
||||
* We use the zoneload reference counter to let us
|
||||
* know when all views are finished.
|
||||
*/
|
||||
isc_refcount_decrement(&zl->refs, &refs);
|
||||
if (refs != 0)
|
||||
return (ISC_R_SUCCESS);
|
||||
if (isc_refcount_decrement(&zl->refs) == 1) {
|
||||
|
||||
isc_refcount_destroy(&zl->refs);
|
||||
isc_mem_put(server->mctx, zl, sizeof (*zl));
|
||||
isc_refcount_destroy(&zl->refs);
|
||||
isc_mem_put(server->mctx, zl, sizeof (*zl));
|
||||
|
||||
/*
|
||||
* To maintain compatibility with log parsing tools that might
|
||||
* be looking for this string after "rndc reconfig", we keep it
|
||||
* as it is
|
||||
*/
|
||||
if (reconfig) {
|
||||
/*
|
||||
* To maintain compatibility with log parsing tools that might
|
||||
* be looking for this string after "rndc reconfig", we keep it
|
||||
* as it is
|
||||
*/
|
||||
if (reconfig) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
|
||||
"any newly configured zones are now loaded");
|
||||
} else {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_NOTICE,
|
||||
"all zones loaded");
|
||||
}
|
||||
|
||||
CHECKFATAL(dns_zonemgr_forcemaint(server->zonemgr),
|
||||
"forcing zone maintenance");
|
||||
|
||||
named_os_started();
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
|
||||
"any newly configured zones are now loaded");
|
||||
} else {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_NOTICE,
|
||||
"all zones loaded");
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_NOTICE, "running");
|
||||
}
|
||||
|
||||
CHECKFATAL(dns_zonemgr_forcemaint(server->zonemgr),
|
||||
"forcing zone maintenance");
|
||||
|
||||
named_os_started();
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_NOTICE, "running");
|
||||
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
@@ -9137,7 +9189,6 @@ load_zones(named_server_t *server, bool init, bool reconfig) {
|
||||
isc_result_t result;
|
||||
dns_view_t *view;
|
||||
ns_zoneload_t *zl;
|
||||
unsigned int refs = 0;
|
||||
|
||||
zl = isc_mem_get(server->mctx, sizeof (*zl));
|
||||
if (zl == NULL)
|
||||
@@ -9158,14 +9209,14 @@ load_zones(named_server_t *server, bool init, bool reconfig) {
|
||||
view = ISC_LIST_NEXT(view, link))
|
||||
{
|
||||
if (view->managed_keys != NULL) {
|
||||
result = dns_zone_load(view->managed_keys);
|
||||
result = dns_zone_load(view->managed_keys, false);
|
||||
if (result != ISC_R_SUCCESS &&
|
||||
result != DNS_R_UPTODATE &&
|
||||
result != DNS_R_CONTINUE)
|
||||
goto cleanup;
|
||||
}
|
||||
if (view->redirect != NULL) {
|
||||
result = dns_zone_load(view->redirect);
|
||||
result = dns_zone_load(view->redirect, false);
|
||||
if (result != ISC_R_SUCCESS &&
|
||||
result != DNS_R_UPTODATE &&
|
||||
result != DNS_R_CONTINUE)
|
||||
@@ -9176,13 +9227,12 @@ load_zones(named_server_t *server, bool init, bool reconfig) {
|
||||
* 'dns_view_asyncload' calls view_loaded if there are no
|
||||
* zones.
|
||||
*/
|
||||
isc_refcount_increment(&zl->refs, NULL);
|
||||
CHECK(dns_view_asyncload(view, view_loaded, zl));
|
||||
isc_refcount_increment(&zl->refs);
|
||||
CHECK(dns_view_asyncload(view, reconfig, view_loaded, zl));
|
||||
}
|
||||
|
||||
cleanup:
|
||||
isc_refcount_decrement(&zl->refs, &refs);
|
||||
if (refs == 0) {
|
||||
if (isc_refcount_decrement(&zl->refs) == 1) {
|
||||
isc_refcount_destroy(&zl->refs);
|
||||
isc_mem_put(server->mctx, zl, sizeof (*zl));
|
||||
} else if (init) {
|
||||
@@ -10074,7 +10124,7 @@ named_server_reloadcommand(named_server_t *server, isc_lex_t *lex,
|
||||
dns_zone_detach(&zone);
|
||||
msg = "zone refresh queued";
|
||||
} else {
|
||||
result = dns_zone_load(zone);
|
||||
result = dns_zone_load(zone, false);
|
||||
dns_zone_detach(&zone);
|
||||
switch (result) {
|
||||
case ISC_R_SUCCESS:
|
||||
@@ -11208,7 +11258,6 @@ named_server_status(named_server_t *server, isc_buffer_t **text) {
|
||||
}
|
||||
CHECK(putstr(text, line));
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
snprintf(line, sizeof(line), "CPUs found: %u\n", named_g_cpus_detected);
|
||||
CHECK(putstr(text, line));
|
||||
|
||||
@@ -11218,10 +11267,6 @@ named_server_status(named_server_t *server, isc_buffer_t **text) {
|
||||
snprintf(line, sizeof(line), "UDP listeners per interface: %u\n",
|
||||
named_g_udpdisp);
|
||||
CHECK(putstr(text, line));
|
||||
#else
|
||||
snprintf(line, sizeof(line), "CPUs found: N/A (threads disabled)\n");
|
||||
CHECK(putstr(text, line));
|
||||
#endif
|
||||
|
||||
snprintf(line, sizeof(line), "number of zones: %u (%u automatic)\n",
|
||||
zonecount, automatic);
|
||||
@@ -12733,7 +12778,7 @@ do_addzone(named_server_t *server, ns_cfgctx_t *cfg, dns_view_t *view,
|
||||
* Load the zone from the master file. If this fails, we'll
|
||||
* need to undo the configuration we've done already.
|
||||
*/
|
||||
result = dns_zone_loadnew(zone);
|
||||
result = dns_zone_load(zone, true);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
dns_db_t *dbp = NULL;
|
||||
|
||||
@@ -12923,7 +12968,7 @@ do_modzone(named_server_t *server, ns_cfgctx_t *cfg, dns_view_t *view,
|
||||
}
|
||||
|
||||
/* Load the zone from the master file if it needs reloading. */
|
||||
result = dns_zone_loadnew(zone);
|
||||
result = dns_zone_load(zone, true);
|
||||
|
||||
/*
|
||||
* Dynamic zones need no reloading, so we can pass this result.
|
||||
|
||||
+29
-29
@@ -23,8 +23,8 @@
|
||||
|
||||
#include <ctype.h>
|
||||
#include <errno.h>
|
||||
#include <grp.h>
|
||||
#include <fcntl.h>
|
||||
#include <grp.h> /* Required for initgroups() on IRIX. */
|
||||
#include <pwd.h>
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
@@ -40,7 +40,7 @@
|
||||
#include <isc/print.h>
|
||||
#include <isc/resource.h>
|
||||
#include <isc/result.h>
|
||||
#include <isc/strerror.h>
|
||||
#include <isc/strerr.h>
|
||||
#include <isc/string.h>
|
||||
|
||||
#include <named/globals.h>
|
||||
@@ -130,7 +130,7 @@ linux_setcaps(cap_t caps) {
|
||||
return;
|
||||
}
|
||||
if (cap_set_proc(caps) < 0) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
named_main_earlyfatal("cap_set_proc() failed: %s:"
|
||||
" please ensure that the capset kernel"
|
||||
" module is loaded. see insmod(8)",
|
||||
@@ -146,13 +146,13 @@ linux_setcaps(cap_t caps) {
|
||||
if (err != -1 && curval) { \
|
||||
err = cap_set_flag(caps, CAP_EFFECTIVE, 1, &capval, CAP_SET); \
|
||||
if (err == -1) { \
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf)); \
|
||||
strerror_r(errno, strbuf, sizeof(strbuf)); \
|
||||
named_main_earlyfatal("cap_set_proc failed: %s", strbuf); \
|
||||
} \
|
||||
\
|
||||
err = cap_set_flag(caps, CAP_PERMITTED, 1, &capval, CAP_SET); \
|
||||
if (err == -1) { \
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf)); \
|
||||
strerror_r(errno, strbuf, sizeof(strbuf)); \
|
||||
named_main_earlyfatal("cap_set_proc failed: %s", strbuf); \
|
||||
} \
|
||||
} \
|
||||
@@ -161,12 +161,12 @@ linux_setcaps(cap_t caps) {
|
||||
do { \
|
||||
caps = cap_init(); \
|
||||
if (caps == NULL) { \
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf)); \
|
||||
strerror_r(errno, strbuf, sizeof(strbuf)); \
|
||||
named_main_earlyfatal("cap_init failed: %s", strbuf); \
|
||||
} \
|
||||
curcaps = cap_get_proc(); \
|
||||
if (curcaps == NULL) { \
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf)); \
|
||||
strerror_r(errno, strbuf, sizeof(strbuf)); \
|
||||
named_main_earlyfatal("cap_get_proc failed: %s", strbuf); \
|
||||
} \
|
||||
} while (0)
|
||||
@@ -286,7 +286,7 @@ linux_keepcaps(void) {
|
||||
|
||||
if (prctl(PR_SET_KEEPCAPS, 1, 0, 0, 0) < 0) {
|
||||
if (errno != EINVAL) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
named_main_earlyfatal("prctl() failed: %s", strbuf);
|
||||
}
|
||||
} else {
|
||||
@@ -331,13 +331,13 @@ named_os_daemonize(void) {
|
||||
char strbuf[ISC_STRERRORSIZE];
|
||||
|
||||
if (pipe(dfd) == -1) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
named_main_earlyfatal("pipe(): %s", strbuf);
|
||||
}
|
||||
|
||||
pid = fork();
|
||||
if (pid == -1) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
named_main_earlyfatal("fork(): %s", strbuf);
|
||||
}
|
||||
if (pid != 0) {
|
||||
@@ -367,7 +367,7 @@ named_os_daemonize(void) {
|
||||
#endif
|
||||
|
||||
if (setsid() == -1) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
named_main_earlyfatal("setsid(): %s", strbuf);
|
||||
}
|
||||
|
||||
@@ -450,14 +450,14 @@ named_os_chroot(const char *root) {
|
||||
if (root != NULL) {
|
||||
#ifdef HAVE_CHROOT
|
||||
if (chroot(root) < 0) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
named_main_earlyfatal("chroot(): %s", strbuf);
|
||||
}
|
||||
#else
|
||||
named_main_earlyfatal("chroot(): disabled");
|
||||
#endif
|
||||
if (chdir("/") < 0) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
named_main_earlyfatal("chdir(/): %s", strbuf);
|
||||
}
|
||||
#ifdef HAVE_LIBSCF
|
||||
@@ -484,7 +484,7 @@ named_os_inituserinfo(const char *username) {
|
||||
|
||||
if (getuid() == 0) {
|
||||
if (initgroups(runas_pw->pw_name, runas_pw->pw_gid) < 0) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
named_main_earlyfatal("initgroups(): %s", strbuf);
|
||||
}
|
||||
}
|
||||
@@ -514,12 +514,12 @@ named_os_changeuser(void) {
|
||||
#endif
|
||||
|
||||
if (setgid(runas_pw->pw_gid) < 0) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
named_main_earlyfatal("setgid(): %s", strbuf);
|
||||
}
|
||||
|
||||
if (setuid(runas_pw->pw_uid) < 0) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
named_main_earlyfatal("setuid(): %s", strbuf);
|
||||
}
|
||||
|
||||
@@ -529,7 +529,7 @@ named_os_changeuser(void) {
|
||||
* call has disabled it.
|
||||
*/
|
||||
if (prctl(PR_SET_DUMPABLE,1,0,0,0) < 0) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
named_main_earlywarning("prctl(PR_SET_DUMPABLE) failed: %s",
|
||||
strbuf);
|
||||
}
|
||||
@@ -648,7 +648,7 @@ mkdirpath(char *filename, void (*report)(const char *, ...)) {
|
||||
|
||||
if (stat(filename, &sb) == -1) {
|
||||
if (errno != ENOENT) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
(*report)("couldn't stat '%s': %s", filename,
|
||||
strbuf);
|
||||
goto error;
|
||||
@@ -668,7 +668,7 @@ mkdirpath(char *filename, void (*report)(const char *, ...)) {
|
||||
mode |= S_IRGRP | S_IXGRP; /* g=rx */
|
||||
mode |= S_IROTH | S_IXOTH; /* o=rx */
|
||||
if (mkdir(filename, mode) == -1) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
(*report)("couldn't mkdir '%s': %s", filename,
|
||||
strbuf);
|
||||
goto error;
|
||||
@@ -676,7 +676,7 @@ mkdirpath(char *filename, void (*report)(const char *, ...)) {
|
||||
if (runas_pw != NULL &&
|
||||
chown(filename, runas_pw->pw_uid,
|
||||
runas_pw->pw_gid) == -1) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
(*report)("couldn't chown '%s': %s", filename,
|
||||
strbuf);
|
||||
}
|
||||
@@ -703,7 +703,7 @@ setperms(uid_t uid, gid_t gid) {
|
||||
#endif
|
||||
#if defined(HAVE_SETEGID)
|
||||
if (getegid() != gid && setegid(gid) == -1) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
named_main_earlywarning("unable to set effective "
|
||||
"gid to %ld: %s",
|
||||
(long)gid, strbuf);
|
||||
@@ -711,7 +711,7 @@ setperms(uid_t uid, gid_t gid) {
|
||||
#elif defined(HAVE_SETRESGID)
|
||||
if (getresgid(&tmpg, &oldgid, &tmpg) == -1 || oldgid != gid) {
|
||||
if (setresgid(-1, gid, -1) == -1) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
named_main_earlywarning("unable to set effective "
|
||||
"gid to %d: %s", gid, strbuf);
|
||||
}
|
||||
@@ -720,7 +720,7 @@ setperms(uid_t uid, gid_t gid) {
|
||||
|
||||
#if defined(HAVE_SETEUID)
|
||||
if (geteuid() != uid && seteuid(uid) == -1) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
named_main_earlywarning("unable to set effective "
|
||||
"uid to %ld: %s",
|
||||
(long)uid, strbuf);
|
||||
@@ -728,7 +728,7 @@ setperms(uid_t uid, gid_t gid) {
|
||||
#elif defined(HAVE_SETRESUID)
|
||||
if (getresuid(&tmpu, &olduid, &tmpu) == -1 || olduid != uid) {
|
||||
if (setresuid(-1, uid, -1) == -1) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
named_main_earlywarning("unable to set effective "
|
||||
"uid to %d: %s", uid, strbuf);
|
||||
}
|
||||
@@ -747,7 +747,7 @@ named_os_openfile(const char *filename, mode_t mode, bool switch_user) {
|
||||
*/
|
||||
f = strdup(filename);
|
||||
if (f == NULL) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
named_main_earlywarning("couldn't strdup() '%s': %s",
|
||||
filename, strbuf);
|
||||
return (NULL);
|
||||
@@ -799,7 +799,7 @@ named_os_openfile(const char *filename, mode_t mode, bool switch_user) {
|
||||
}
|
||||
|
||||
if (fd < 0) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
named_main_earlywarning("could not open file '%s': %s",
|
||||
filename, strbuf);
|
||||
return (NULL);
|
||||
@@ -807,7 +807,7 @@ named_os_openfile(const char *filename, mode_t mode, bool switch_user) {
|
||||
|
||||
fp = fdopen(fd, "w");
|
||||
if (fp == NULL) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
named_main_earlywarning("could not fdopen() file '%s': %s",
|
||||
filename, strbuf);
|
||||
}
|
||||
@@ -835,7 +835,7 @@ named_os_writepidfile(const char *filename, bool first_time) {
|
||||
|
||||
pidfile = strdup(filename);
|
||||
if (pidfile == NULL) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
(*report)("couldn't strdup() '%s': %s", filename, strbuf);
|
||||
return;
|
||||
}
|
||||
@@ -882,7 +882,7 @@ named_os_issingleton(const char *filename) {
|
||||
*/
|
||||
lockfile = strdup(filename);
|
||||
if (lockfile == NULL) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||
named_main_earlyfatal("couldn't allocate memory for '%s': %s",
|
||||
filename, strbuf);
|
||||
} else {
|
||||
|
||||
@@ -27,7 +27,6 @@
|
||||
|
||||
#include <isc/print.h>
|
||||
#include <isc/result.h>
|
||||
#include <isc/strerror.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/ntpaths.h>
|
||||
#include <isc/util.h>
|
||||
@@ -231,7 +230,7 @@ named_os_openfile(const char *filename, int mode, bool switch_user) {
|
||||
UNUSED(switch_user);
|
||||
fd = safe_open(filename, mode, false);
|
||||
if (fd < 0) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_s(strbuf, sizeof(strbuf), errno);
|
||||
named_main_earlywarning("could not open file '%s': %s",
|
||||
filename, strbuf);
|
||||
return (NULL);
|
||||
@@ -239,7 +238,7 @@ named_os_openfile(const char *filename, int mode, bool switch_user) {
|
||||
|
||||
fp = fdopen(fd, "w");
|
||||
if (fp == NULL) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_s(strbuf, sizeof(strbuf), errno);
|
||||
named_main_earlywarning("could not fdopen() file '%s': %s",
|
||||
filename, strbuf);
|
||||
close(fd);
|
||||
@@ -268,7 +267,7 @@ named_os_writepidfile(const char *filename, bool first_time) {
|
||||
|
||||
pidfile = strdup(filename);
|
||||
if (pidfile == NULL) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_s(strbuf, sizeof(strbuf), errno);
|
||||
(*report)("couldn't strdup() '%s': %s", filename, strbuf);
|
||||
return;
|
||||
}
|
||||
@@ -312,7 +311,7 @@ named_os_issingleton(const char *filename) {
|
||||
|
||||
lockfile = strdup(filename);
|
||||
if (lockfile == NULL) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
strerror_s(strbuf, sizeof(strbuf), errno);
|
||||
named_main_earlyfatal("couldn't allocate memory for '%s': %s",
|
||||
filename, strbuf);
|
||||
}
|
||||
|
||||
@@ -99,20 +99,6 @@
|
||||
#endif
|
||||
#endif
|
||||
|
||||
#ifdef HAVE_ADDRINFO
|
||||
#ifdef HAVE_GETADDRINFO
|
||||
#ifdef HAVE_GAISTRERROR
|
||||
#define USE_GETADDRINFO
|
||||
#endif
|
||||
#endif
|
||||
#endif
|
||||
|
||||
#ifndef USE_GETADDRINFO
|
||||
#ifndef ISC_PLATFORM_NONSTDHERRNO
|
||||
extern int h_errno;
|
||||
#endif
|
||||
#endif
|
||||
|
||||
#define MAXCMD (128 * 1024)
|
||||
#define MAXWIRE (64 * 1024)
|
||||
#define PACKETSIZE ((64 * 1024) - 1)
|
||||
|
||||
@@ -20,6 +20,7 @@ CDEFINES = @USE_GSSAPI@
|
||||
|
||||
CWARNINGS =
|
||||
BACKTRACECFLAGS = @BACKTRACECFLAGS@
|
||||
PTHREAD_CFLAGS = @PTHREAD_CFLAGS@
|
||||
|
||||
DNSLIBS = ../../../lib/dns/libdns.@A@ @DNS_CRYPTO_LIBS@
|
||||
ISCLIBS = ../../../lib/isc/libisc.@A@ @OPENSSL_LIBS@
|
||||
@@ -51,7 +52,6 @@ XTARGETS = adb_test@EXEEXT@ \
|
||||
hash_test@EXEEXT@ \
|
||||
fsaccess_test@EXEEXT@ \
|
||||
inter_test@EXEEXT@ \
|
||||
keyboard_test@EXEEXT@ \
|
||||
lex_test@EXEEXT@ \
|
||||
lfsr_test@EXEEXT@ \
|
||||
log_test@EXEEXT@ \
|
||||
@@ -82,7 +82,6 @@ XSRCS = adb_test.c \
|
||||
fsaccess_test.c \
|
||||
gsstest.c \
|
||||
inter_test.c \
|
||||
keyboard_test.c \
|
||||
lex_test.c \
|
||||
lfsr_test.c \
|
||||
log_test.c \
|
||||
@@ -106,7 +105,7 @@ XSRCS = adb_test.c \
|
||||
|
||||
# disable optimization for backtrace test to get the expected result
|
||||
BTTEST_CFLAGS = ${BACKTRACECFLAGS} ${EXT_CFLAGS} ${ALL_CPPFLAGS} -g \
|
||||
${ALWAYS_WARNINGS} ${STD_CWARNINGS} ${CWARNINGS}
|
||||
${ALWAYS_WARNINGS} ${STD_CWARNINGS} ${CWARNINGS} ${PTHREAD_CFLAGS}
|
||||
|
||||
all_tests: ${XTARGETS}
|
||||
|
||||
@@ -240,10 +239,6 @@ inter_test@EXEEXT@: inter_test.@O@ ${ISCDEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ inter_test.@O@ \
|
||||
${ISCLIBS} ${LIBS}
|
||||
|
||||
keyboard_test@EXEEXT@: keyboard_test.@O@ ${ISCDEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ keyboard_test.@O@ \
|
||||
${ISCLIBS} ${LIBS}
|
||||
|
||||
sig0_test@EXEEXT@: sig0_test.@O@ ${ISCDEPLIBS} ${DNSDEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ sig0_test.@O@ \
|
||||
${DNSLIBS} ${ISCLIBS} ${LIBS}
|
||||
|
||||
@@ -1,67 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*
|
||||
* See the COPYRIGHT file distributed with this work for additional
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
/*! \file */
|
||||
#include <config.h>
|
||||
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
|
||||
#include <isc/keyboard.h>
|
||||
#include <isc/print.h>
|
||||
#include <isc/util.h>
|
||||
|
||||
static void
|
||||
CHECK(const char *msg, isc_result_t result) {
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
printf("FAILURE: %s: %s\n", msg, isc_result_totext(result));
|
||||
exit(1);
|
||||
}
|
||||
}
|
||||
|
||||
int
|
||||
main(int argc, char **argv) {
|
||||
isc_keyboard_t kbd;
|
||||
unsigned char c;
|
||||
isc_result_t res;
|
||||
unsigned int count;
|
||||
|
||||
UNUSED(argc);
|
||||
UNUSED(argv);
|
||||
|
||||
printf("Type Q to exit.\n");
|
||||
|
||||
res = isc_keyboard_open(&kbd);
|
||||
CHECK("isc_keyboard_open()", res);
|
||||
|
||||
c = 'x';
|
||||
count = 0;
|
||||
while (res == ISC_R_SUCCESS && c != 'Q') {
|
||||
res = isc_keyboard_getchar(&kbd, &c);
|
||||
printf(".");
|
||||
fflush(stdout);
|
||||
count++;
|
||||
if (count % 64 == 0)
|
||||
printf("\r\n");
|
||||
}
|
||||
printf("\r\n");
|
||||
if (res != ISC_R_SUCCESS) {
|
||||
printf("FAILURE: keyboard getchar failed: %s\r\n",
|
||||
isc_result_totext(res));
|
||||
goto errout;
|
||||
}
|
||||
|
||||
errout:
|
||||
res = isc_keyboard_close(&kbd, 3);
|
||||
CHECK("isc_keyboard_close()", res);
|
||||
|
||||
return (0);
|
||||
}
|
||||
@@ -25,8 +25,6 @@
|
||||
#define sleep(x) Sleep(1000 * x)
|
||||
#endif
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
isc_rwlock_t lock;
|
||||
|
||||
static isc_threadresult_t
|
||||
@@ -130,15 +128,3 @@ main(int argc, char *argv[]) {
|
||||
|
||||
return (0);
|
||||
}
|
||||
|
||||
#else
|
||||
|
||||
int
|
||||
main(int argc, char *argv[]) {
|
||||
UNUSED(argc);
|
||||
UNUSED(argv);
|
||||
fprintf(stderr, "This test requires threads.\n");
|
||||
return(1);
|
||||
}
|
||||
|
||||
#endif
|
||||
|
||||
@@ -12,11 +12,11 @@
|
||||
#include <config.h>
|
||||
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <inttypes.h>
|
||||
|
||||
#include <isc/print.h>
|
||||
#include <isc/serial.h>
|
||||
#include <isc/stdlib.h>
|
||||
|
||||
int
|
||||
main() {
|
||||
|
||||
@@ -122,7 +122,7 @@ setup(const char *zonename, const char *filename, const char *classname) {
|
||||
if (zonetype == dns_zone_slave)
|
||||
dns_zone_setmasters(zone, &addr, 1);
|
||||
|
||||
result = dns_zone_load(zone);
|
||||
result = dns_zone_load(zone, false);
|
||||
ERRRET(result, "dns_zone_load");
|
||||
|
||||
result = dns_zonemgr_managezone(zonemgr, zone);
|
||||
|
||||
@@ -65,6 +65,9 @@ options {
|
||||
max-cache-size 20000000000000;
|
||||
nta-lifetime 604800;
|
||||
nta-recheck 604800;
|
||||
validate-except {
|
||||
"corp";
|
||||
};
|
||||
transfer-source 0.0.0.0 dscp 63;
|
||||
zone-statistics none;
|
||||
};
|
||||
|
||||
@@ -138,11 +138,7 @@ else
|
||||
TESTSOCK6=false
|
||||
fi
|
||||
|
||||
if grep "^#define WANT_IPV6 1" $TOP/config.h > /dev/null 2>&1 ; then
|
||||
TESTSOCK6="$TESTSOCK6"
|
||||
else
|
||||
TESTSOCK6=false
|
||||
fi
|
||||
TESTSOCK6="$TESTSOCK6"
|
||||
|
||||
# Windows process management leave empty
|
||||
PSSUSPEND=
|
||||
|
||||
@@ -107,7 +107,7 @@ PARALLELDIRS="allow_query catz rpzrecurse serve-stale"
|
||||
SUBDIRS="$SEQUENTIALDIRS $PARALLELDIRS"
|
||||
|
||||
# missing: chain integrity
|
||||
# extra: dname ednscompliance forward
|
||||
# extra: dname ednscompliance forward
|
||||
|
||||
#Things that are different on Windows
|
||||
KILL="/bin/kill -f"
|
||||
@@ -117,7 +117,7 @@ DOS2UNIX=dos2unix
|
||||
TP=
|
||||
|
||||
# Configure is launched from native environment, but tests are run in Cygwin -
|
||||
# so any detection is unreliable.
|
||||
# so any detection is unreliable.
|
||||
SHELL="/bin/bash -o igncr"
|
||||
CURL=/usr/bin/curl
|
||||
XMLLINT=/usr/bin/xmllint
|
||||
@@ -135,11 +135,7 @@ else
|
||||
TESTSOCK6=false
|
||||
fi
|
||||
|
||||
if grep "^#define WANT_IPV6 1" $TOP/config.h > /dev/null 2>&1 ; then
|
||||
TESTSOCK6="$TESTSOCK6"
|
||||
else
|
||||
TESTSOCK6=false
|
||||
fi
|
||||
TESTSOCK6="$TESTSOCK6"
|
||||
|
||||
#
|
||||
# PsSuspend is part of PSTools and can be downloaded from
|
||||
|
||||
@@ -0,0 +1,21 @@
|
||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
; file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
;
|
||||
; See the COPYRIGHT file distributed with this work for additional
|
||||
; information regarding copyright ownership.
|
||||
|
||||
$TTL 30 ; 5 minutes
|
||||
@ IN SOA mname1. . (
|
||||
2000042407 ; serial
|
||||
20 ; refresh (20 seconds)
|
||||
20 ; retry (20 seconds)
|
||||
1814400 ; expire (3 weeks)
|
||||
30 ; minimum (1 hour)
|
||||
)
|
||||
NS ns2
|
||||
ns2 A 10.53.0.2
|
||||
|
||||
www A 10.0.0.1
|
||||
@@ -158,4 +158,9 @@ zone "cdnskey-auto.secure" {
|
||||
allow-update { any; };
|
||||
};
|
||||
|
||||
zone "corp" {
|
||||
type master;
|
||||
file "corp.db";
|
||||
};
|
||||
|
||||
include "trusted.conf";
|
||||
|
||||
@@ -28,6 +28,8 @@ options {
|
||||
nta-lifetime 12s;
|
||||
nta-recheck 9s;
|
||||
|
||||
validate-except { corp; };
|
||||
|
||||
# Note: We only reference the bind.keys file here to confirm that it
|
||||
# is *not* being used. It contains the real root key, and we're
|
||||
# using a local toy root zone for the tests, so it wouldn't work.
|
||||
@@ -50,4 +52,9 @@ zone "." {
|
||||
file "../../common/root.hint";
|
||||
};
|
||||
|
||||
zone "corp" {
|
||||
type static-stub;
|
||||
server-addresses { 10.53.0.2; };
|
||||
};
|
||||
|
||||
include "trusted.conf";
|
||||
|
||||
@@ -1764,6 +1764,15 @@ n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo_i "checking validate-except in an insecure local domain ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS ns www.corp @10.53.0.4 > dig.out.ns4.test$n || ret=1
|
||||
grep "NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
|
||||
grep "flags:[^;]* ad[^;]*;" dig.out.ns4.test$n > /dev/null && ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo_i "checking positive and negative validation with negative trust anchors ($n)"
|
||||
ret=0
|
||||
|
||||
@@ -2165,10 +2174,14 @@ fi
|
||||
echo_i "sleeping for an additional 4 seconds for ns4 to fully startup"
|
||||
sleep 4
|
||||
|
||||
# dump the NTA to a file
|
||||
# dump the NTA to a file (omit validate-except entries)
|
||||
echo_i "testing 'rndc nta'"
|
||||
$RNDCCMD 10.53.0.4 nta -d > rndc.out.ns4.test$n.1 2>/dev/null
|
||||
# "corp" is configured as a validate-except domain and thus should be
|
||||
# omitted. only "secure.example" should be in the dump at this point.
|
||||
lines=`wc -l < rndc.out.ns4.test$n.1`
|
||||
[ "$lines" -eq 1 ] || ret=1
|
||||
grep 'secure.example' rndc.out.ns4.test$n.1 > /dev/null || ret=1
|
||||
ts=`awk '{print $3" "$4}' < rndc.out.ns4.test$n.1`
|
||||
# rndc nta outputs localtime, so append the timezone
|
||||
ts_with_zone="$ts `date +%z`"
|
||||
|
||||
@@ -26,6 +26,7 @@ options {
|
||||
dnstap { all; };
|
||||
send-cookie no;
|
||||
require-server-cookie no;
|
||||
dnssec-validation yes;
|
||||
};
|
||||
|
||||
key rndc_key {
|
||||
|
||||
@@ -26,6 +26,7 @@ options {
|
||||
dnstap { all; };
|
||||
send-cookie no;
|
||||
require-server-cookie no;
|
||||
dnssec-validation yes;
|
||||
};
|
||||
|
||||
key rndc_key {
|
||||
|
||||
@@ -27,6 +27,7 @@ options {
|
||||
send-cookie no;
|
||||
require-server-cookie no;
|
||||
minimal-responses no;
|
||||
dnssec-validation yes;
|
||||
};
|
||||
|
||||
server 10.53.0.1 { tcp-only yes; };
|
||||
|
||||
@@ -26,6 +26,7 @@ options {
|
||||
dnstap { all; };
|
||||
send-cookie no;
|
||||
require-server-cookie no;
|
||||
dnssec-validation yes;
|
||||
};
|
||||
|
||||
server 10.53.0.1 { tcp-only yes; };
|
||||
|
||||
@@ -72,7 +72,7 @@ attach(dns_db_t *source, dns_db_t **targetp) {
|
||||
|
||||
REQUIRE(VALID_SAMPLEDB(sampledb));
|
||||
|
||||
isc_refcount_increment(&sampledb->refs, NULL);
|
||||
isc_refcount_increment(&sampledb->refs);
|
||||
*targetp = source;
|
||||
}
|
||||
|
||||
@@ -87,15 +87,13 @@ free_sampledb(sampledb_t *sampledb) {
|
||||
|
||||
static void
|
||||
detach(dns_db_t **dbp) {
|
||||
REQUIRE(dbp != NULL && VALID_SAMPLEDB((sampledb_t *)(*dbp)));
|
||||
sampledb_t *sampledb = (sampledb_t *)(*dbp);
|
||||
unsigned int refs;
|
||||
|
||||
REQUIRE(VALID_SAMPLEDB(sampledb));
|
||||
|
||||
isc_refcount_decrement(&sampledb->refs, &refs);
|
||||
if (refs == 0)
|
||||
free_sampledb(sampledb);
|
||||
*dbp = NULL;
|
||||
|
||||
if (isc_refcount_decrement(&sampledb->refs) == 1) {
|
||||
free_sampledb(sampledb);
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -773,7 +771,7 @@ create_db(isc_mem_t *mctx, const dns_name_t *origin, dns_dbtype_t type,
|
||||
|
||||
CHECK(dns_name_dupwithoffsets(origin, mctx, &sampledb->common.origin));
|
||||
|
||||
CHECK(isc_refcount_init(&sampledb->refs, 1));
|
||||
isc_refcount_init(&sampledb->refs, 1);
|
||||
|
||||
/* Translate instance name to instance pointer. */
|
||||
sampledb->inst = driverarg;
|
||||
|
||||
@@ -151,7 +151,7 @@ load_zone(dns_zone_t *zone) {
|
||||
bool zone_dynamic;
|
||||
uint32_t serial;
|
||||
|
||||
result = dns_zone_load(zone);
|
||||
result = dns_zone_load(zone, false);
|
||||
if (result != ISC_R_SUCCESS && result != DNS_R_UPTODATE
|
||||
&& result != DNS_R_DYNAMIC && result != DNS_R_CONTINUE)
|
||||
goto cleanup;
|
||||
|
||||
@@ -0,0 +1,11 @@
|
||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
; file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
;
|
||||
; See the COPYRIGHT file distributed with this work for additional
|
||||
; information regarding copyright ownership.
|
||||
|
||||
. 0 NS ns.rootservers.utld.
|
||||
ns.rootservers.utld. 0 A 10.53.0.1
|
||||
@@ -0,0 +1,42 @@
|
||||
/*
|
||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*
|
||||
* See the COPYRIGHT file distributed with this work for additional
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
options {
|
||||
query-source address 10.53.0.5;
|
||||
notify-source 10.53.0.5;
|
||||
transfer-source 10.53.0.5;
|
||||
port @PORT@;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.5; };
|
||||
listen-on-v6 { fd92:7065:b8e:ffff::5; };
|
||||
recursion yes;
|
||||
dnssec-validation no;
|
||||
notify yes;
|
||||
dns64 64:ff9b::/96 {
|
||||
clients { any; };
|
||||
exclude { any; };
|
||||
mapped { any; };
|
||||
};
|
||||
filter-aaaa-on-v4 break-dnssec;
|
||||
filter-aaaa { any; };
|
||||
minimal-responses no;
|
||||
};
|
||||
|
||||
key rndc_key {
|
||||
secret "1234abcd8765";
|
||||
algorithm hmac-sha256;
|
||||
};
|
||||
|
||||
controls {
|
||||
inet 10.53.0.5 port @CONTROLPORT@ allow { any; } keys { rndc_key; };
|
||||
};
|
||||
|
||||
zone "." { type hint; file "hints"; };
|
||||
@@ -18,6 +18,7 @@ copy_setports ns1/named1.conf.in ns1/named.conf
|
||||
copy_setports ns2/named1.conf.in ns2/named.conf
|
||||
copy_setports ns3/named1.conf.in ns3/named.conf
|
||||
copy_setports ns4/named1.conf.in ns4/named.conf
|
||||
copy_setports ns5/named.conf.in ns5/named.conf
|
||||
|
||||
(cd ns1 && $SHELL -e sign.sh)
|
||||
(cd ns4 && $SHELL -e sign.sh)
|
||||
|
||||
@@ -1374,5 +1374,17 @@ grep "^mx.unsigned.*AAAA" dig.out.ns3.test$n > /dev/null 2>&1 || ret=1
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
# We don't check for the AAAA record here as configuration in ns5 does
|
||||
# not make sense. The AAAA record is wanted by filter-aaaa but discarded
|
||||
# by the dns64 configuration. We just want to ensure the server stays
|
||||
# running.
|
||||
n=`expr $n + 1`
|
||||
echo_i "checking filter-aaaa with dns64 ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS aaaa aaaa-only.unsigned @10.53.0.5 > dig.out.ns5.test$n || ret=1
|
||||
grep "status: NOERROR" dig.out.ns5.test$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo_i "exit status: $status"
|
||||
[ $status -eq 0 ] || exit 1
|
||||
|
||||
@@ -38,15 +38,7 @@ EOF
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# If running on hp-ux, don't even try to run config.guess.
|
||||
# It will try to create a temporary file in the current directory,
|
||||
# which fails when running as root with the current directory
|
||||
# on a NFS mounted disk.
|
||||
|
||||
case `uname -a` in
|
||||
*HP-UX*) sys=hpux ;;
|
||||
*) sys=`sh $config_guess` ;;
|
||||
esac
|
||||
sys=`sh $config_guess`
|
||||
|
||||
use_ip=
|
||||
case "$sys" in
|
||||
|
||||
@@ -73,6 +73,10 @@ rm -f ns3/nsec3.db
|
||||
rm -f ns3/nsec3.db.jnl
|
||||
rm -f ns3/nsec3.db.signed
|
||||
rm -f ns3/nsec3.db.signed.jnl
|
||||
rm -f ns3/delayedkeys.db
|
||||
rm -f ns3/delayedkeys.db.jnl
|
||||
rm -f ns3/delayedkeys.db.signed
|
||||
rm -f ns3/delayedkeys.db.signed.jnl
|
||||
rm -f ns3/removedkeys-primary.db
|
||||
rm -f ns3/removedkeys-primary.db.jnl
|
||||
rm -f ns3/removedkeys-primary.db.signed
|
||||
|
||||
@@ -18,110 +18,3 @@ $TTL 300 ; 5 minutes
|
||||
NS ns3
|
||||
ns2 A 10.53.0.2
|
||||
ns3 A 10.53.0.3
|
||||
|
||||
a A 10.0.0.1
|
||||
b A 10.0.0.2
|
||||
d A 10.0.0.4
|
||||
|
||||
; Used for testing ANY queries
|
||||
foo TXT "testing"
|
||||
foo A 10.0.1.0
|
||||
|
||||
bad-cname CNAME a
|
||||
bad-dname DNAME @
|
||||
|
||||
; Used for testing CNAME queries
|
||||
cname1 CNAME cname1-target
|
||||
cname1-target TXT "testing cname"
|
||||
|
||||
cname2 CNAME cname2-target
|
||||
cname2-target TXT "testing cname"
|
||||
|
||||
; Used for testing DNAME queries
|
||||
dname1 DNAME dname1-target
|
||||
foo.dname1-target TXT "testing dname"
|
||||
|
||||
dname2 DNAME dname2-target
|
||||
foo.dname2-target TXT "testing dname"
|
||||
|
||||
; A secure subdomain
|
||||
secure NS ns.secure
|
||||
ns.secure A 10.53.0.3
|
||||
|
||||
; An insecure subdomain
|
||||
insecure NS ns.insecure
|
||||
ns.insecure A 10.53.0.3
|
||||
|
||||
; A secure subdomain we're going to inject bogus data into
|
||||
bogus NS ns.bogus
|
||||
ns.bogus A 10.53.0.3
|
||||
|
||||
; A dynamic secure subdomain
|
||||
dynamic NS dynamic
|
||||
dynamic A 10.53.0.3
|
||||
|
||||
; A insecure subdomain
|
||||
mustbesecure NS ns.mustbesecure
|
||||
ns.mustbesecure A 10.53.0.3
|
||||
|
||||
; A rfc2535 signed zone w/ CNAME
|
||||
rfc2535 NS ns.rfc2535
|
||||
ns.rfc2535 A 10.53.0.3
|
||||
|
||||
z A 10.0.0.26
|
||||
|
||||
keyless NS ns.keyless
|
||||
ns.keyless A 10.53.0.3
|
||||
|
||||
nsec3 NS ns.nsec3
|
||||
ns.nsec3 A 10.53.0.3
|
||||
|
||||
optout NS ns.optout
|
||||
ns.optout A 10.53.0.3
|
||||
|
||||
nsec3-unknown NS ns.nsec3-unknown
|
||||
ns.nsec3-unknown A 10.53.0.3
|
||||
|
||||
optout-unknown NS ns.optout-unknown
|
||||
ns.optout-unknown A 10.53.0.3
|
||||
|
||||
multiple NS ns.multiple
|
||||
ns.multiple A 10.53.0.3
|
||||
|
||||
*.wild A 10.0.0.27
|
||||
|
||||
rsasha256 NS ns.rsasha256
|
||||
ns.rsasha256 A 10.53.0.3
|
||||
|
||||
rsasha512 NS ns.rsasha512
|
||||
ns.rsasha512 A 10.53.0.3
|
||||
|
||||
kskonly NS ns.kskonly
|
||||
ns.kskonly A 10.53.0.3
|
||||
|
||||
update-nsec3 NS ns.update-nsec3
|
||||
ns.update-nsec3 A 10.53.0.3
|
||||
|
||||
auto-nsec NS ns.auto-nsec
|
||||
ns.auto-nsec A 10.53.0.3
|
||||
|
||||
auto-nsec3 NS ns.auto-nsec3
|
||||
ns.auto-nsec3 A 10.53.0.3
|
||||
|
||||
|
||||
below-cname CNAME some.where.else.
|
||||
|
||||
insecure.below-cname NS ns.insecure.below-cname
|
||||
ns.insecure.below-cname A 10.53.0.3
|
||||
|
||||
secure.below-cname NS ns.secure.below-cname
|
||||
ns.secure.below-cname A 10.53.0.3
|
||||
|
||||
ttlpatch NS ns.ttlpatch
|
||||
ns.ttlpatch A 10.53.0.3
|
||||
|
||||
split-dnssec NS ns.split-dnssec
|
||||
ns.split-dnssec A 10.53.0.3
|
||||
|
||||
split-smart NS ns.split-smart
|
||||
ns.split-smart A 10.53.0.3
|
||||
|
||||
@@ -48,6 +48,7 @@ zone "retransfer3" {
|
||||
type master;
|
||||
file "retransfer3.db";
|
||||
allow-update { any; };
|
||||
allow-transfer { none; }; // changed dynamically by tests.sh
|
||||
notify no;
|
||||
};
|
||||
|
||||
|
||||
@@ -16,112 +16,4 @@ $TTL 300 ; 5 minutes
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
NS ns3
|
||||
ns2 A 10.53.0.2
|
||||
ns3 A 10.53.0.3
|
||||
|
||||
a A 10.0.0.1
|
||||
b A 10.0.0.2
|
||||
d A 10.0.0.4
|
||||
|
||||
; Used for testing ANY queries
|
||||
foo TXT "testing"
|
||||
foo A 10.0.1.0
|
||||
|
||||
bad-cname CNAME a
|
||||
bad-dname DNAME @
|
||||
|
||||
; Used for testing CNAME queries
|
||||
cname1 CNAME cname1-target
|
||||
cname1-target TXT "testing cname"
|
||||
|
||||
cname2 CNAME cname2-target
|
||||
cname2-target TXT "testing cname"
|
||||
|
||||
; Used for testing DNAME queries
|
||||
dname1 DNAME dname1-target
|
||||
foo.dname1-target TXT "testing dname"
|
||||
|
||||
dname2 DNAME dname2-target
|
||||
foo.dname2-target TXT "testing dname"
|
||||
|
||||
; A secure subdomain
|
||||
secure NS ns.secure
|
||||
ns.secure A 10.53.0.3
|
||||
|
||||
; An insecure subdomain
|
||||
insecure NS ns.insecure
|
||||
ns.insecure A 10.53.0.3
|
||||
|
||||
; A secure subdomain we're going to inject bogus data into
|
||||
bogus NS ns.bogus
|
||||
ns.bogus A 10.53.0.3
|
||||
|
||||
; A dynamic secure subdomain
|
||||
dynamic NS dynamic
|
||||
dynamic A 10.53.0.3
|
||||
|
||||
; A insecure subdomain
|
||||
mustbesecure NS ns.mustbesecure
|
||||
ns.mustbesecure A 10.53.0.3
|
||||
|
||||
; A rfc2535 signed zone w/ CNAME
|
||||
rfc2535 NS ns.rfc2535
|
||||
ns.rfc2535 A 10.53.0.3
|
||||
|
||||
z A 10.0.0.26
|
||||
|
||||
keyless NS ns.keyless
|
||||
ns.keyless A 10.53.0.3
|
||||
|
||||
nsec3 NS ns.nsec3
|
||||
ns.nsec3 A 10.53.0.3
|
||||
|
||||
optout NS ns.optout
|
||||
ns.optout A 10.53.0.3
|
||||
|
||||
nsec3-unknown NS ns.nsec3-unknown
|
||||
ns.nsec3-unknown A 10.53.0.3
|
||||
|
||||
optout-unknown NS ns.optout-unknown
|
||||
ns.optout-unknown A 10.53.0.3
|
||||
|
||||
multiple NS ns.multiple
|
||||
ns.multiple A 10.53.0.3
|
||||
|
||||
*.wild A 10.0.0.27
|
||||
|
||||
rsasha256 NS ns.rsasha256
|
||||
ns.rsasha256 A 10.53.0.3
|
||||
|
||||
rsasha512 NS ns.rsasha512
|
||||
ns.rsasha512 A 10.53.0.3
|
||||
|
||||
kskonly NS ns.kskonly
|
||||
ns.kskonly A 10.53.0.3
|
||||
|
||||
update-nsec3 NS ns.update-nsec3
|
||||
ns.update-nsec3 A 10.53.0.3
|
||||
|
||||
auto-nsec NS ns.auto-nsec
|
||||
ns.auto-nsec A 10.53.0.3
|
||||
|
||||
auto-nsec3 NS ns.auto-nsec3
|
||||
ns.auto-nsec3 A 10.53.0.3
|
||||
|
||||
|
||||
below-cname CNAME some.where.else.
|
||||
|
||||
insecure.below-cname NS ns.insecure.below-cname
|
||||
ns.insecure.below-cname A 10.53.0.3
|
||||
|
||||
secure.below-cname NS ns.secure.below-cname
|
||||
ns.secure.below-cname A 10.53.0.3
|
||||
|
||||
ttlpatch NS ns.ttlpatch
|
||||
ns.ttlpatch A 10.53.0.3
|
||||
|
||||
split-dnssec NS ns.split-dnssec
|
||||
ns.split-dnssec A 10.53.0.3
|
||||
|
||||
split-smart NS ns.split-smart
|
||||
ns.split-smart A 10.53.0.3
|
||||
|
||||
@@ -16,113 +16,6 @@ $TTL 300 ; 5 minutes
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
NS ns3
|
||||
ns2 A 10.53.0.2
|
||||
ns3 A 10.53.0.3
|
||||
|
||||
a A 10.0.0.1
|
||||
b A 10.0.0.2
|
||||
d A 10.0.0.4
|
||||
e A 10.0.0.5
|
||||
|
||||
; Used for testing ANY queries
|
||||
foo TXT "testing"
|
||||
foo A 10.0.1.0
|
||||
|
||||
bad-cname CNAME a
|
||||
bad-dname DNAME @
|
||||
|
||||
; Used for testing CNAME queries
|
||||
cname1 CNAME cname1-target
|
||||
cname1-target TXT "testing cname"
|
||||
|
||||
cname2 CNAME cname2-target
|
||||
cname2-target TXT "testing cname"
|
||||
|
||||
; Used for testing DNAME queries
|
||||
dname1 DNAME dname1-target
|
||||
foo.dname1-target TXT "testing dname"
|
||||
|
||||
dname2 DNAME dname2-target
|
||||
foo.dname2-target TXT "testing dname"
|
||||
|
||||
; A secure subdomain
|
||||
secure NS ns.secure
|
||||
ns.secure A 10.53.0.3
|
||||
|
||||
; An insecure subdomain
|
||||
insecure NS ns.insecure
|
||||
ns.insecure A 10.53.0.3
|
||||
|
||||
; A secure subdomain we're going to inject bogus data into
|
||||
bogus NS ns.bogus
|
||||
ns.bogus A 10.53.0.3
|
||||
|
||||
; A dynamic secure subdomain
|
||||
dynamic NS dynamic
|
||||
dynamic A 10.53.0.3
|
||||
|
||||
; A insecure subdomain
|
||||
mustbesecure NS ns.mustbesecure
|
||||
ns.mustbesecure A 10.53.0.3
|
||||
|
||||
; A rfc2535 signed zone w/ CNAME
|
||||
rfc2535 NS ns.rfc2535
|
||||
ns.rfc2535 A 10.53.0.3
|
||||
|
||||
z A 10.0.0.26
|
||||
|
||||
keyless NS ns.keyless
|
||||
ns.keyless A 10.53.0.3
|
||||
|
||||
nsec3 NS ns.nsec3
|
||||
ns.nsec3 A 10.53.0.3
|
||||
|
||||
optout NS ns.optout
|
||||
ns.optout A 10.53.0.3
|
||||
|
||||
nsec3-unknown NS ns.nsec3-unknown
|
||||
ns.nsec3-unknown A 10.53.0.3
|
||||
|
||||
optout-unknown NS ns.optout-unknown
|
||||
ns.optout-unknown A 10.53.0.3
|
||||
|
||||
multiple NS ns.multiple
|
||||
ns.multiple A 10.53.0.3
|
||||
|
||||
*.wild A 10.0.0.27
|
||||
|
||||
rsasha256 NS ns.rsasha256
|
||||
ns.rsasha256 A 10.53.0.3
|
||||
|
||||
rsasha512 NS ns.rsasha512
|
||||
ns.rsasha512 A 10.53.0.3
|
||||
|
||||
kskonly NS ns.kskonly
|
||||
ns.kskonly A 10.53.0.3
|
||||
|
||||
update-nsec3 NS ns.update-nsec3
|
||||
ns.update-nsec3 A 10.53.0.3
|
||||
|
||||
auto-nsec NS ns.auto-nsec
|
||||
ns.auto-nsec A 10.53.0.3
|
||||
|
||||
auto-nsec3 NS ns.auto-nsec3
|
||||
ns.auto-nsec3 A 10.53.0.3
|
||||
|
||||
|
||||
below-cname CNAME some.where.else.
|
||||
|
||||
insecure.below-cname NS ns.insecure.below-cname
|
||||
ns.insecure.below-cname A 10.53.0.3
|
||||
|
||||
secure.below-cname NS ns.secure.below-cname
|
||||
ns.secure.below-cname A 10.53.0.3
|
||||
|
||||
ttlpatch NS ns.ttlpatch
|
||||
ns.ttlpatch A 10.53.0.3
|
||||
|
||||
split-dnssec NS ns.split-dnssec
|
||||
ns.split-dnssec A 10.53.0.3
|
||||
|
||||
split-smart NS ns.split-smart
|
||||
ns.split-smart A 10.53.0.3
|
||||
|
||||
@@ -16,114 +16,7 @@ $TTL 300 ; 5 minutes
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
NS ns3
|
||||
ns2 A 10.53.0.2
|
||||
ns3 A 10.53.0.3
|
||||
|
||||
a A 10.0.0.1
|
||||
b A 10.0.0.2
|
||||
c A 10.0.0.3
|
||||
d A 10.0.0.4
|
||||
e A 10.0.0.5
|
||||
|
||||
; Used for testing ANY queries
|
||||
foo TXT "testing"
|
||||
foo A 10.0.1.0
|
||||
|
||||
bad-cname CNAME a
|
||||
bad-dname DNAME @
|
||||
|
||||
; Used for testing CNAME queries
|
||||
cname1 CNAME cname1-target
|
||||
cname1-target TXT "testing cname"
|
||||
|
||||
cname2 CNAME cname2-target
|
||||
cname2-target TXT "testing cname"
|
||||
|
||||
; Used for testing DNAME queries
|
||||
dname1 DNAME dname1-target
|
||||
foo.dname1-target TXT "testing dname"
|
||||
|
||||
dname2 DNAME dname2-target
|
||||
foo.dname2-target TXT "testing dname"
|
||||
|
||||
; A secure subdomain
|
||||
secure NS ns.secure
|
||||
ns.secure A 10.53.0.3
|
||||
|
||||
; An insecure subdomain
|
||||
insecure NS ns.insecure
|
||||
ns.insecure A 10.53.0.3
|
||||
|
||||
; A secure subdomain we're going to inject bogus data into
|
||||
bogus NS ns.bogus
|
||||
ns.bogus A 10.53.0.3
|
||||
|
||||
; A dynamic secure subdomain
|
||||
dynamic NS dynamic
|
||||
dynamic A 10.53.0.3
|
||||
|
||||
; A insecure subdomain
|
||||
mustbesecure NS ns.mustbesecure
|
||||
ns.mustbesecure A 10.53.0.3
|
||||
|
||||
; A rfc2535 signed zone w/ CNAME
|
||||
rfc2535 NS ns.rfc2535
|
||||
ns.rfc2535 A 10.53.0.3
|
||||
|
||||
z A 10.0.0.26
|
||||
|
||||
keyless NS ns.keyless
|
||||
ns.keyless A 10.53.0.3
|
||||
|
||||
nsec3 NS ns.nsec3
|
||||
ns.nsec3 A 10.53.0.3
|
||||
|
||||
optout NS ns.optout
|
||||
ns.optout A 10.53.0.3
|
||||
|
||||
nsec3-unknown NS ns.nsec3-unknown
|
||||
ns.nsec3-unknown A 10.53.0.3
|
||||
|
||||
optout-unknown NS ns.optout-unknown
|
||||
ns.optout-unknown A 10.53.0.3
|
||||
|
||||
multiple NS ns.multiple
|
||||
ns.multiple A 10.53.0.3
|
||||
|
||||
*.wild A 10.0.0.27
|
||||
|
||||
rsasha256 NS ns.rsasha256
|
||||
ns.rsasha256 A 10.53.0.3
|
||||
|
||||
rsasha512 NS ns.rsasha512
|
||||
ns.rsasha512 A 10.53.0.3
|
||||
|
||||
kskonly NS ns.kskonly
|
||||
ns.kskonly A 10.53.0.3
|
||||
|
||||
update-nsec3 NS ns.update-nsec3
|
||||
ns.update-nsec3 A 10.53.0.3
|
||||
|
||||
auto-nsec NS ns.auto-nsec
|
||||
ns.auto-nsec A 10.53.0.3
|
||||
|
||||
auto-nsec3 NS ns.auto-nsec3
|
||||
ns.auto-nsec3 A 10.53.0.3
|
||||
|
||||
|
||||
below-cname CNAME some.where.else.
|
||||
|
||||
insecure.below-cname NS ns.insecure.below-cname
|
||||
ns.insecure.below-cname A 10.53.0.3
|
||||
|
||||
secure.below-cname NS ns.secure.below-cname
|
||||
ns.secure.below-cname A 10.53.0.3
|
||||
|
||||
ttlpatch NS ns.ttlpatch
|
||||
ns.ttlpatch A 10.53.0.3
|
||||
|
||||
split-dnssec NS ns.split-dnssec
|
||||
ns.split-dnssec A 10.53.0.3
|
||||
|
||||
split-smart NS ns.split-smart
|
||||
ns.split-smart A 10.53.0.3
|
||||
|
||||
@@ -16,114 +16,7 @@ $TTL 300 ; 5 minutes
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
NS ns3
|
||||
ns2 A 10.53.0.2
|
||||
ns3 A 10.53.0.3
|
||||
|
||||
a A 10.0.0.1
|
||||
b A 10.0.0.2
|
||||
c A 10.0.0.3
|
||||
d A 10.0.0.4
|
||||
e A 10.0.0.5
|
||||
|
||||
; Used for testing ANY queries
|
||||
foo TXT "testing"
|
||||
foo A 10.0.1.0
|
||||
|
||||
bad-cname CNAME a
|
||||
bad-dname DNAME @
|
||||
|
||||
; Used for testing CNAME queries
|
||||
cname1 CNAME cname1-target
|
||||
cname1-target TXT "testing cname"
|
||||
|
||||
cname2 CNAME cname2-target
|
||||
cname2-target TXT "testing cname"
|
||||
|
||||
; Used for testing DNAME queries
|
||||
dname1 DNAME dname1-target
|
||||
foo.dname1-target TXT "testing dname"
|
||||
|
||||
dname2 DNAME dname2-target
|
||||
foo.dname2-target TXT "testing dname"
|
||||
|
||||
; A secure subdomain
|
||||
secure NS ns.secure
|
||||
ns.secure A 10.53.0.3
|
||||
|
||||
; An insecure subdomain
|
||||
insecure NS ns.insecure
|
||||
ns.insecure A 10.53.0.3
|
||||
|
||||
; A secure subdomain we're going to inject bogus data into
|
||||
bogus NS ns.bogus
|
||||
ns.bogus A 10.53.0.3
|
||||
|
||||
; A dynamic secure subdomain
|
||||
dynamic NS dynamic
|
||||
dynamic A 10.53.0.3
|
||||
|
||||
; A insecure subdomain
|
||||
mustbesecure NS ns.mustbesecure
|
||||
ns.mustbesecure A 10.53.0.3
|
||||
|
||||
; A rfc2535 signed zone w/ CNAME
|
||||
rfc2535 NS ns.rfc2535
|
||||
ns.rfc2535 A 10.53.0.3
|
||||
|
||||
z A 10.0.0.26
|
||||
|
||||
keyless NS ns.keyless
|
||||
ns.keyless A 10.53.0.3
|
||||
|
||||
nsec3 NS ns.nsec3
|
||||
ns.nsec3 A 10.53.0.3
|
||||
|
||||
optout NS ns.optout
|
||||
ns.optout A 10.53.0.3
|
||||
|
||||
nsec3-unknown NS ns.nsec3-unknown
|
||||
ns.nsec3-unknown A 10.53.0.3
|
||||
|
||||
optout-unknown NS ns.optout-unknown
|
||||
ns.optout-unknown A 10.53.0.3
|
||||
|
||||
multiple NS ns.multiple
|
||||
ns.multiple A 10.53.0.3
|
||||
|
||||
*.wild A 10.0.0.27
|
||||
|
||||
rsasha256 NS ns.rsasha256
|
||||
ns.rsasha256 A 10.53.0.3
|
||||
|
||||
rsasha512 NS ns.rsasha512
|
||||
ns.rsasha512 A 10.53.0.3
|
||||
|
||||
kskonly NS ns.kskonly
|
||||
ns.kskonly A 10.53.0.3
|
||||
|
||||
update-nsec3 NS ns.update-nsec3
|
||||
ns.update-nsec3 A 10.53.0.3
|
||||
|
||||
auto-nsec NS ns.auto-nsec
|
||||
ns.auto-nsec A 10.53.0.3
|
||||
|
||||
auto-nsec3 NS ns.auto-nsec3
|
||||
ns.auto-nsec3 A 10.53.0.3
|
||||
|
||||
|
||||
below-cname CNAME some.where.else.
|
||||
|
||||
insecure.below-cname NS ns.insecure.below-cname
|
||||
ns.insecure.below-cname A 10.53.0.3
|
||||
|
||||
secure.below-cname NS ns.secure.below-cname
|
||||
ns.secure.below-cname A 10.53.0.3
|
||||
|
||||
ttlpatch NS ns.ttlpatch
|
||||
ns.ttlpatch A 10.53.0.3
|
||||
|
||||
split-dnssec NS ns.split-dnssec
|
||||
ns.split-dnssec A 10.53.0.3
|
||||
|
||||
split-smart NS ns.split-smart
|
||||
ns.split-smart A 10.53.0.3
|
||||
|
||||
@@ -0,0 +1,22 @@
|
||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
; file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
;
|
||||
; See the COPYRIGHT file distributed with this work for additional
|
||||
; information regarding copyright ownership.
|
||||
|
||||
$TTL 300 ; 5 minutes
|
||||
@ IN SOA ns3 . (
|
||||
2000042411 ; serial
|
||||
20 ; refresh (20 seconds)
|
||||
20 ; retry (20 seconds)
|
||||
1814400 ; expire (3 weeks)
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
NS ns3
|
||||
ns3 A 10.53.0.3
|
||||
|
||||
c A 10.0.0.3
|
||||
e A 10.0.0.5
|
||||
@@ -58,6 +58,10 @@ zone "master" {
|
||||
inline-signing yes;
|
||||
auto-dnssec maintain;
|
||||
file "master.db";
|
||||
notify explicit;
|
||||
also-notify {
|
||||
10.53.0.3;
|
||||
};
|
||||
};
|
||||
|
||||
zone "dynamic" {
|
||||
@@ -141,6 +145,13 @@ zone "nokeys" {
|
||||
file "nokeys.bk";
|
||||
};
|
||||
|
||||
zone "delayedkeys" {
|
||||
type master;
|
||||
inline-signing yes;
|
||||
auto-dnssec maintain;
|
||||
file "delayedkeys.db";
|
||||
};
|
||||
|
||||
zone "removedkeys-primary" {
|
||||
type master;
|
||||
inline-signing yes;
|
||||
|
||||
@@ -96,6 +96,14 @@ keyname=`$KEYGEN -q -a RSASHA256 -b 1024 -n zone $zone`
|
||||
keyname=`$KEYGEN -q -a RSASHA256 -b 1024 -n zone -f KSK $zone`
|
||||
$DSFROMKEY -T 1200 $keyname >> ../ns1/root.db
|
||||
|
||||
zone=delayedkeys
|
||||
rm -f K${zone}.+*+*.key
|
||||
rm -f K${zone}.+*+*.private
|
||||
keyname=`$KEYGEN -q -a RSASHA1 -b 1024 -n zone $zone`
|
||||
keyname=`$KEYGEN -q -a RSASHA1 -b 1024 -n zone -f KSK $zone`
|
||||
# Keys for the "delayedkeys" zone should not be initially accessible.
|
||||
mv K${zone}.+*+*.* ../
|
||||
|
||||
zone=removedkeys-primary
|
||||
rm -f K${zone}.+*+*.key
|
||||
rm -f K${zone}.+*+*.private
|
||||
|
||||
@@ -18,110 +18,3 @@ $TTL 300 ; 5 minutes
|
||||
NS ns3
|
||||
ns4 A 10.53.0.4
|
||||
ns3 A 10.53.0.3
|
||||
|
||||
a A 10.0.0.1
|
||||
b A 10.0.0.2
|
||||
d A 10.0.0.4
|
||||
|
||||
; Used for testing ANY queries
|
||||
foo TXT "testing"
|
||||
foo A 10.0.1.0
|
||||
|
||||
bad-cname CNAME a
|
||||
bad-dname DNAME @
|
||||
|
||||
; Used for testing CNAME queries
|
||||
cname1 CNAME cname1-target
|
||||
cname1-target TXT "testing cname"
|
||||
|
||||
cname2 CNAME cname2-target
|
||||
cname2-target TXT "testing cname"
|
||||
|
||||
; Used for testing DNAME queries
|
||||
dname1 DNAME dname1-target
|
||||
foo.dname1-target TXT "testing dname"
|
||||
|
||||
dname2 DNAME dname2-target
|
||||
foo.dname2-target TXT "testing dname"
|
||||
|
||||
; A secure subdomain
|
||||
secure NS ns.secure
|
||||
ns.secure A 10.53.0.3
|
||||
|
||||
; An insecure subdomain
|
||||
insecure NS ns.insecure
|
||||
ns.insecure A 10.53.0.3
|
||||
|
||||
; A secure subdomain we're going to inject bogus data into
|
||||
bogus NS ns.bogus
|
||||
ns.bogus A 10.53.0.3
|
||||
|
||||
; A dynamic secure subdomain
|
||||
dynamic NS dynamic
|
||||
dynamic A 10.53.0.3
|
||||
|
||||
; A insecure subdomain
|
||||
mustbesecure NS ns.mustbesecure
|
||||
ns.mustbesecure A 10.53.0.3
|
||||
|
||||
; A rfc2535 signed zone w/ CNAME
|
||||
rfc2535 NS ns.rfc2535
|
||||
ns.rfc2535 A 10.53.0.3
|
||||
|
||||
z A 10.0.0.26
|
||||
|
||||
keyless NS ns.keyless
|
||||
ns.keyless A 10.53.0.3
|
||||
|
||||
nsec3 NS ns.nsec3
|
||||
ns.nsec3 A 10.53.0.3
|
||||
|
||||
optout NS ns.optout
|
||||
ns.optout A 10.53.0.3
|
||||
|
||||
nsec3-unknown NS ns.nsec3-unknown
|
||||
ns.nsec3-unknown A 10.53.0.3
|
||||
|
||||
optout-unknown NS ns.optout-unknown
|
||||
ns.optout-unknown A 10.53.0.3
|
||||
|
||||
multiple NS ns.multiple
|
||||
ns.multiple A 10.53.0.3
|
||||
|
||||
*.wild A 10.0.0.27
|
||||
|
||||
rsasha256 NS ns.rsasha256
|
||||
ns.rsasha256 A 10.53.0.3
|
||||
|
||||
rsasha512 NS ns.rsasha512
|
||||
ns.rsasha512 A 10.53.0.3
|
||||
|
||||
kskonly NS ns.kskonly
|
||||
ns.kskonly A 10.53.0.3
|
||||
|
||||
update-nsec3 NS ns.update-nsec3
|
||||
ns.update-nsec3 A 10.53.0.3
|
||||
|
||||
auto-nsec NS ns.auto-nsec
|
||||
ns.auto-nsec A 10.53.0.3
|
||||
|
||||
auto-nsec3 NS ns.auto-nsec3
|
||||
ns.auto-nsec3 A 10.53.0.3
|
||||
|
||||
|
||||
below-cname CNAME some.where.else.
|
||||
|
||||
insecure.below-cname NS ns.insecure.below-cname
|
||||
ns.insecure.below-cname A 10.53.0.3
|
||||
|
||||
secure.below-cname NS ns.secure.below-cname
|
||||
ns.secure.below-cname A 10.53.0.3
|
||||
|
||||
ttlpatch NS ns.ttlpatch
|
||||
ns.ttlpatch A 10.53.0.3
|
||||
|
||||
split-dnssec NS ns.split-dnssec
|
||||
ns.split-dnssec A 10.53.0.3
|
||||
|
||||
split-smart NS ns.split-smart
|
||||
ns.split-smart A 10.53.0.3
|
||||
|
||||
@@ -31,6 +31,7 @@ cp ns3/master.db.in ns3/updated.db
|
||||
cp ns3/master.db.in ns3/expired.db
|
||||
cp ns3/master.db.in ns3/nsec3.db
|
||||
cp ns3/master.db.in ns3/externalkey.db
|
||||
cp ns3/master.db.in ns3/delayedkeys.db
|
||||
cp ns3/master.db.in ns3/removedkeys-primary.db
|
||||
|
||||
mkdir ns3/removedkeys
|
||||
|
||||
@@ -27,22 +27,6 @@ do
|
||||
sleep 1
|
||||
done
|
||||
|
||||
# Loop until retransfer3 has been transferred.
|
||||
for i in 1 2 3 4 5 6 7 8 9 0
|
||||
do
|
||||
ans=0
|
||||
$RNDCCMD 10.53.0.3 signing -nsec3param 1 0 0 - retransfer3 > /dev/null 2>&1 || ans=1
|
||||
[ $ans = 0 ] && break
|
||||
sleep 1
|
||||
done
|
||||
|
||||
for i in 1 2 3 4 5 6 7 8 9 0
|
||||
do
|
||||
nsec3param=`$DIG $DIGOPTS +nodnssec +short @10.53.0.3 nsec3param retransfer3.`
|
||||
test "$nsec3param" = "1 0 0 -" && break
|
||||
sleep 1
|
||||
done
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo_i "checking that rrsigs are replaced with ksk only ($n)"
|
||||
ret=0
|
||||
@@ -770,9 +754,48 @@ done
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo_i "check 'rndc signing -nsec3param' requests are queued for zones which are not loaded ($n)"
|
||||
ret=0
|
||||
# The "retransfer3" zone is configured with "allow-transfer { none; };" on ns2,
|
||||
# which means it should not yet be available on ns3.
|
||||
$DIG $DIGOPTS @10.53.0.3 retransfer3 SOA > dig.out.ns3.pre.test$n
|
||||
grep "status: SERVFAIL" dig.out.ns3.pre.test$n > /dev/null || ret=1
|
||||
# Switch the zone to NSEC3. An "NSEC3 -> NSEC -> NSEC3" sequence is used purely
|
||||
# to test that multiple queued "rndc signing -nsec3param" requests are handled
|
||||
# properly.
|
||||
$RNDCCMD 10.53.0.3 signing -nsec3param 1 0 0 - retransfer3 > /dev/null 2>&1 || ret=1
|
||||
$RNDCCMD 10.53.0.3 signing -nsec3param none retransfer3 > /dev/null 2>&1 || ret=1
|
||||
$RNDCCMD 10.53.0.3 signing -nsec3param 1 0 0 - retransfer3 > /dev/null 2>&1 || ret=1
|
||||
# Reconfigure ns2 to allow outgoing transfers for the "retransfer3" zone.
|
||||
sed "s|\(allow-transfer { none; };.*\)|// \1|;" ns2/named.conf > ns2/named.conf.new
|
||||
mv ns2/named.conf.new ns2/named.conf
|
||||
$RNDCCMD 10.53.0.2 reconfig || ret=1
|
||||
# Request ns3 to retransfer the "retransfer3" zone.
|
||||
$RNDCCMD 10.53.0.3 retransfer retransfer3 || ret=1
|
||||
# Wait until ns3 finishes building the NSEC3 chain for "retransfer3". There is
|
||||
# no need to immediately set ret=1 if building the NSEC3 chain is not finished
|
||||
# within the time limit because the query we will send shortly will detect any
|
||||
# problems anyway.
|
||||
for i in 0 1 2 3 4 5 6 7 8 9
|
||||
do
|
||||
$RNDCCMD 10.53.0.3 signing -list retransfer3 > signing.out.test$n.$i 2>&1
|
||||
keys_done=`grep "Done signing" signing.out.test$n.$i | wc -l`
|
||||
nsec3_pending=`grep "NSEC3 chain" signing.out.test$n.$i | wc -l`
|
||||
test $keys_done -eq 2 -a $nsec3_pending -eq 0 && break
|
||||
sleep 1
|
||||
done
|
||||
# Check whether "retransfer3" uses NSEC3 as requested.
|
||||
$DIG $DIGOPTS @10.53.0.3 nonexist.retransfer3 A > dig.out.ns3.post.test$n
|
||||
grep "status: NXDOMAIN" dig.out.ns3.post.test$n > /dev/null || ret=1
|
||||
grep "NSEC3" dig.out.ns3.post.test$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo_i "check rndc retransfer of a inline nsec3 slave retains nsec3 ($n)"
|
||||
ret=0
|
||||
$RNDCCMD 10.53.0.3 signing -nsec3param 1 0 0 - retransfer3 > /dev/null 2>&1 || ret=1
|
||||
for i in 0 1 2 3 4 5 6 7 8 9
|
||||
do
|
||||
ans=0
|
||||
@@ -877,6 +900,31 @@ done
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo_i "check that reloading all zones does not cause zone maintenance to cease for inline-signed zones ($n)"
|
||||
ret=1
|
||||
# Ensure "rndc reload" attempts to load ns3/master.db by waiting 1 second so
|
||||
# that the master file modification time has no possibility of being equal to
|
||||
# the one stored during server startup.
|
||||
sleep 1
|
||||
nextpart ns3/named.run > /dev/null
|
||||
cp ns3/master5.db.in ns3/master.db
|
||||
$RNDCCMD 10.53.0.3 reload 2>&1 | sed 's/^/ns3 /' | cat_i
|
||||
for i in 1 2 3 4 5 6 7 8 9 10
|
||||
do
|
||||
if nextpart ns3/named.run | grep "zone master.*sending notifies" > /dev/null; then
|
||||
ret=0
|
||||
break
|
||||
fi
|
||||
sleep 1
|
||||
done
|
||||
# Sanity check: master file updates should be reflected in the signed zone,
|
||||
# i.e. SOA RNAME should no longer be set to "hostmaster".
|
||||
$DIG $DIGOPTS @10.53.0.3 master SOA > dig.out.ns3.test$n || ret=1
|
||||
grep "hostmaster" dig.out.ns3.test$n > /dev/null && ret=1
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo_i "test add/del zone combinations ($n)"
|
||||
ret=0
|
||||
@@ -1244,7 +1292,61 @@ grep "RRSIG" dig.out.ns3.test$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
# Check that the master file $2 for zone $1 does not contain RRSIG records
|
||||
# while the journal file for that zone does contain them.
|
||||
ensure_sigs_only_in_journal() {
|
||||
origin="$1"
|
||||
masterfile="$2"
|
||||
$CHECKZONE -i none -f raw -D -o - "$origin" "$masterfile" 2>&1 | grep -w RRSIG > /dev/null && ret=1
|
||||
$CHECKZONE -j -i none -f raw -D -o - "$origin" "$masterfile" 2>&1 | grep -w RRSIG > /dev/null || ret=1
|
||||
}
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo_i "checking that records added from a journal are scheduled to be resigned ($n)"
|
||||
ret=0
|
||||
# Signing keys for the "delayedkeys" zone are not yet accessible. Thus, the
|
||||
# zone file for the signed version of the zone will contain no DNSSEC records.
|
||||
# Move keys into place now and load them, which will cause DNSSEC records to
|
||||
# only be present in the journal for the signed version of the zone.
|
||||
mv Kdelayedkeys* ns3/
|
||||
$RNDCCMD 10.53.0.3 loadkeys delayedkeys > rndc.out.ns3.pre.test$n 2>&1 || ret=1
|
||||
# Wait until the zone is signed.
|
||||
ans=1
|
||||
for i in 1 2 3 4 5 6 7 8 9 10
|
||||
do
|
||||
$RNDCCMD 10.53.0.3 signing -list delayedkeys > signing.out.test$n 2>&1
|
||||
num=`grep "Done signing with" signing.out.test$n | wc -l`
|
||||
if [ $num -eq 2 ]; then
|
||||
ans=0
|
||||
break
|
||||
fi
|
||||
sleep 1
|
||||
done
|
||||
if [ $ans != 0 ]; then ret=1; fi
|
||||
# Halt rather than stopping the server to prevent the master file from being
|
||||
# flushed upon shutdown since we specifically want to avoid it.
|
||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc --halt --port ${CONTROLPORT} . ns3
|
||||
ensure_sigs_only_in_journal delayedkeys ns3/delayedkeys.db.signed
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart --port ${PORT} . ns3
|
||||
# At this point, the raw zone journal will not have a source serial set. Upon
|
||||
# server startup, receive_secure_serial() will rectify that, update SOA, resign
|
||||
# it, and schedule its future resign. This will cause "rndc zonestatus" to
|
||||
# return delayedkeys/SOA as the next node to resign, so we restart the server
|
||||
# once again; with the raw zone journal now having a source serial set,
|
||||
# receive_secure_serial() should refrain from introducing any zone changes.
|
||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc --halt --port ${CONTROLPORT} . ns3
|
||||
ensure_sigs_only_in_journal delayedkeys ns3/delayedkeys.db.signed
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart --port ${PORT} . ns3
|
||||
# We can now test whether the secure zone journal was correctly processed:
|
||||
# unless the records contained in it were scheduled for resigning, no resigning
|
||||
# event will be scheduled at all since the secure zone master file contains no
|
||||
# DNSSEC records.
|
||||
$RNDCCMD 10.53.0.3 zonestatus delayedkeys > rndc.out.ns3.post.test$n 2>&1 || ret=1
|
||||
grep "next resign node:" rndc.out.ns3.post.test$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
n=`expr $n + 1`
|
||||
|
||||
echo_i "check that zonestatus reports 'type: master' for a inline master zone ($n)"
|
||||
ret=0
|
||||
$RNDCCMD 10.53.0.3 zonestatus master > rndc.out.ns3.test$n
|
||||
|
||||
@@ -48,6 +48,7 @@ zone "initially-unavailable" {
|
||||
masters { 10.53.0.2; };
|
||||
mirror yes;
|
||||
file "initially-unavailable.db.mirror";
|
||||
use-alt-transfer-source no;
|
||||
};
|
||||
|
||||
zone "verify-axfr" {
|
||||
|
||||
@@ -107,6 +107,10 @@ for (;;) {
|
||||
# expected to be accepted regardless of the filter setting.
|
||||
$packet->push("authority", new Net::DNS::RR("sub.example.org 300 NS ns.sub.example.org"));
|
||||
$packet->push("additional", new Net::DNS::RR("ns.sub.example.org 300 A 10.53.0.3"));
|
||||
} elsif ($qname =~ /glue-in-answer\.example\.org/) {
|
||||
$packet->push("answer", new Net::DNS::RR("ns.glue-in-answer.example.org 300 A 10.53.0.3"));
|
||||
$packet->push("authority", new Net::DNS::RR("glue-in-answer.example.org 300 NS ns.glue-in-answer.example.org"));
|
||||
$packet->push("additional", new Net::DNS::RR("ns.glue-in-answer.example.org 300 A 10.53.0.3"));
|
||||
} elsif ($qname =~ /\.broken/ || $qname =~ /^broken/) {
|
||||
# Delegation to broken TLD.
|
||||
$packet->push("authority", new Net::DNS::RR("broken 300 NS ns.broken"));
|
||||
|
||||
@@ -107,6 +107,8 @@ for (;;) {
|
||||
} elsif ($qname eq "www.ok.sub.example.org") {
|
||||
$packet->push("answer",
|
||||
new Net::DNS::RR($qname . " 300 A 192.0.2.1"));
|
||||
} elsif ($qname eq "foo.glue-in-answer.example.org") {
|
||||
$packet->push("answer", new Net::DNS::RR($qname . " 300 A 192.0.2.1"));
|
||||
} else {
|
||||
$packet->push("answer", new Net::DNS::RR("www.example.com 300 A 1.2.3.4"));
|
||||
}
|
||||
|
||||
@@ -247,6 +247,15 @@ if [ -x ${RESOLVE} ] ; then
|
||||
status=`expr $status + $ret`
|
||||
fi
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo_i "check that the resolver accepts a referral response with a non-empty ANSWER section ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS @10.53.0.1 foo.glue-in-answer.example.org. A > dig.ns1.out.${n} || ret=1
|
||||
grep "status: NOERROR" dig.ns1.out.${n} > /dev/null || ret=1
|
||||
grep "foo.glue-in-answer.example.org.*192.0.2.1" dig.ns1.out.${n} > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo_i "RT21594 regression test check setup ($n)"
|
||||
ret=0
|
||||
|
||||
@@ -75,6 +75,8 @@ main(int argc, char **argv) {
|
||||
UNUSED(argc);
|
||||
UNUSED(argv);
|
||||
|
||||
#if !USE_PKCS11
|
||||
|
||||
rsa = RSA_new();
|
||||
e = BN_new();
|
||||
pkey = EVP_PKEY_new();
|
||||
@@ -149,6 +151,9 @@ main(int argc, char **argv) {
|
||||
dns_name_destroy();
|
||||
isc_mem_destroy(&mctx);
|
||||
return (0);
|
||||
#else /* !USE_PKCS11 */
|
||||
return (1);
|
||||
#endif /* !USE_PKC11 */
|
||||
}
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -16,7 +16,7 @@ if $BIGKEY > /dev/null 2>&1
|
||||
then
|
||||
rm -f Kexample.*
|
||||
else
|
||||
echo_i "This test requires cryptography" >&2
|
||||
echo_i "configure with --with-openssl, or --with-pkcs11 and --enable-native-pkcs11" >&2
|
||||
echo_i "This test requires OpenSSL cryptography provider" >&2
|
||||
echo_i "configure with --with-openssl, and make sure you disable --with-pkcs11 and --enable-native-pkcs11" >&2
|
||||
exit 255
|
||||
fi
|
||||
|
||||
@@ -31,11 +31,12 @@ use Getopt::Long;
|
||||
#
|
||||
# server Name of the server directory.
|
||||
|
||||
my $usage = "usage: $0 [--use-rndc [--port port]] test-directory [server-directory]";
|
||||
my $usage = "usage: $0 [--use-rndc [--halt] [--port port]] test-directory [server-directory]";
|
||||
|
||||
my $use_rndc = 0;
|
||||
my $halt = 0;
|
||||
my $port = 9953;
|
||||
GetOptions('use-rndc' => \$use_rndc, 'port=i' => \$port) or die "$usage\n";
|
||||
GetOptions('use-rndc' => \$use_rndc, 'halt' => \$halt, 'port=i' => \$port) or die "$usage\n";
|
||||
|
||||
my $errors = 0;
|
||||
|
||||
@@ -131,9 +132,10 @@ sub stop_rndc {
|
||||
|
||||
return unless ($server =~ /^ns(\d+)$/);
|
||||
my $ip = "10.53.0.$1";
|
||||
my $how = $halt ? "halt" : "stop";
|
||||
|
||||
# Ugly, but should work.
|
||||
system("$ENV{RNDC} -c ../common/rndc.conf -s $ip -p $port stop | sed 's/^/I:$server /'");
|
||||
system("$ENV{RNDC} -c ../common/rndc.conf -s $ip -p $port $how | sed 's/^/I:$server /'");
|
||||
return;
|
||||
}
|
||||
|
||||
|
||||
@@ -10,7 +10,7 @@
|
||||
*/
|
||||
|
||||
|
||||
#include "config.h"
|
||||
#include <config.h>
|
||||
|
||||
#include <isc/net.h>
|
||||
#include <isc/print.h>
|
||||
|
||||
+11
-11
@@ -845,18 +845,18 @@ parse_xint(uint32_t *uip, const char *value, uint32_t max,
|
||||
|
||||
static void
|
||||
newopts(struct query *query) {
|
||||
size_t len = sizeof(query->ednsopts[0]) * EDNSOPTS;
|
||||
size_t i;
|
||||
size_t len = sizeof(query->ednsopts[0]) * EDNSOPTS;
|
||||
size_t i;
|
||||
|
||||
query->ednsopts = isc_mem_allocate(mctx, len);
|
||||
if (query->ednsopts == NULL)
|
||||
fatal("out of memory");
|
||||
query->ednsopts = isc_mem_allocate(mctx, len);
|
||||
if (query->ednsopts == NULL)
|
||||
fatal("out of memory");
|
||||
|
||||
for (i = 0; i < EDNSOPTS; i++) {
|
||||
query->ednsopts[i].code = 0;
|
||||
query->ednsopts[i].length = 0;
|
||||
query->ednsopts[i].value = NULL;
|
||||
}
|
||||
for (i = 0; i < EDNSOPTS; i++) {
|
||||
query->ednsopts[i].code = 0;
|
||||
query->ednsopts[i].length = 0;
|
||||
query->ednsopts[i].value = NULL;
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
@@ -1296,7 +1296,7 @@ plus_option(char *option, struct query *query, bool global)
|
||||
"specified");
|
||||
}
|
||||
value = strtok_r(NULL, "\0",
|
||||
&last);
|
||||
&last);
|
||||
save_opt(query, code, value);
|
||||
break;
|
||||
default:
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
#include "config.h"
|
||||
#include <config.h>
|
||||
|
||||
#ifndef HAVE_LMDB
|
||||
#error This program requires the LMDB library.
|
||||
|
||||
@@ -68,7 +68,7 @@
|
||||
<GenerateDebugInformation>true</GenerateDebugInformation>
|
||||
<OutputFile>..\..\..\Build\$(Configuration)\$(TargetName)$(TargetExt)</OutputFile>
|
||||
<AdditionalLibraryDirectories>..\..\..\lib\isc\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
||||
<AdditionalDependencies>@OPENSSL_LIB@libisc.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
||||
<AdditionalDependencies>@OPENSSL_LIB@libisc.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
||||
</Link>
|
||||
</ItemDefinitionGroup>
|
||||
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
||||
|
||||
@@ -68,7 +68,7 @@
|
||||
<GenerateDebugInformation>true</GenerateDebugInformation>
|
||||
<OutputFile>..\..\..\Build\$(Configuration)\$(TargetName)$(TargetExt)</OutputFile>
|
||||
<AdditionalLibraryDirectories>..\..\..\lib\isc\win32\$(Configuration);..\..\..\lib\dns\win32\$(Configuration);..\..\..\lib\bind9\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
||||
<AdditionalDependencies>@OPENSSL_LIB@libisc.lib;libdns.lib;libbind9.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
||||
<AdditionalDependencies>@OPENSSL_LIB@libisc.lib;libdns.lib;libbind9.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
||||
</Link>
|
||||
</ItemDefinitionGroup>
|
||||
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
||||
|
||||
@@ -4,10 +4,10 @@
|
||||
//
|
||||
|
||||
/*
|
||||
* Minimum version is Windows XP SP1
|
||||
* Minimum version is Windows Vista and Windows Server 2008
|
||||
*/
|
||||
#define _WIN32_WINNT 0x0501
|
||||
#define NTDDI_VERSION 0x05010100
|
||||
#define _WIN32_WINNT 0x0600
|
||||
#define NTDDI_VERSION 0x06000100
|
||||
|
||||
#ifndef _CRT_SECURE_NO_DEPRECATE
|
||||
#define _CRT_SECURE_NO_DEPRECATE 1
|
||||
|
||||
+65
-89
@@ -17,9 +17,6 @@
|
||||
*** it does not get installed.
|
||||
***/
|
||||
|
||||
/** define on DEC OSF to enable 4.4BSD style sa_len support */
|
||||
#undef _SOCKADDR_LEN
|
||||
|
||||
/** define if your system needs pthread_init() before using pthreads */
|
||||
#undef NEED_PTHREAD_INIT
|
||||
|
||||
@@ -29,9 +26,6 @@
|
||||
/** define if sigwait() is the UnixWare flavor */
|
||||
#undef HAVE_UNIXWARE_SIGWAIT
|
||||
|
||||
/** define on Solaris to get sigwait() to work using pthreads semantics */
|
||||
#undef _POSIX_PTHREAD_SEMANTICS
|
||||
|
||||
/** define if LinuxThreads is in use */
|
||||
#undef HAVE_LINUXTHREADS
|
||||
|
||||
@@ -53,62 +47,18 @@
|
||||
/** define if tzset() is available */
|
||||
#undef HAVE_TZSET
|
||||
|
||||
/** define if struct addrinfo exists */
|
||||
#undef HAVE_ADDRINFO
|
||||
|
||||
/** define if getaddrinfo() exists */
|
||||
#undef HAVE_GETADDRINFO
|
||||
|
||||
/** define if gai_strerror() exists */
|
||||
#undef HAVE_GAISTRERROR
|
||||
|
||||
/**
|
||||
* define if pthread_setconcurrency() should be called to tell the
|
||||
* OS how many threads we might want to run.
|
||||
*/
|
||||
#undef CALL_PTHREAD_SETCONCURRENCY
|
||||
|
||||
/** define if IPv6 is not disabled */
|
||||
#undef WANT_IPV6
|
||||
|
||||
/** define if flockfile() is available */
|
||||
#undef HAVE_FLOCKFILE
|
||||
|
||||
/** define if getc_unlocked() is available */
|
||||
#undef HAVE_GETCUNLOCKED
|
||||
|
||||
/** Shut up warnings about sputaux in stdio.h on BSD/OS pre-4.1 */
|
||||
#undef SHUTUP_SPUTAUX
|
||||
#ifdef SHUTUP_SPUTAUX
|
||||
struct __sFILE;
|
||||
extern __inline int __sputaux(int _c, struct __sFILE *_p);
|
||||
#endif
|
||||
|
||||
/** Shut up warnings about missing sigwait prototype on BSD/OS 4.0* */
|
||||
#undef SHUTUP_SIGWAIT
|
||||
#ifdef SHUTUP_SIGWAIT
|
||||
int sigwait(const unsigned int *set, int *sig);
|
||||
#endif
|
||||
|
||||
/** Shut up warnings from gcc -Wcast-qual on BSD/OS 4.1. */
|
||||
#undef SHUTUP_STDARG_CAST
|
||||
#if defined(SHUTUP_STDARG_CAST) && defined(__GNUC__)
|
||||
#include <stdarg.h> /** Grr. Must be included *every time*. */
|
||||
/**
|
||||
* The silly continuation line is to keep configure from
|
||||
* commenting out the #undef.
|
||||
*/
|
||||
|
||||
#undef \
|
||||
va_start
|
||||
#define va_start(ap, last) \
|
||||
do { \
|
||||
union { const void *konst; long *var; } _u; \
|
||||
_u.konst = &(last); \
|
||||
ap = (va_list)(_u.var + __va_words(__typeof(last))); \
|
||||
} while (0)
|
||||
#endif /** SHUTUP_STDARG_CAST && __GNUC__ */
|
||||
|
||||
/** define if the system has a random number generating device */
|
||||
#undef PATH_RANDOMDEV
|
||||
|
||||
@@ -139,10 +89,6 @@ int sigwait(const unsigned int *set, int *sig);
|
||||
/* define if ATF unit tests are to be built. */
|
||||
#undef ATF_TEST
|
||||
|
||||
/* Define if recvmsg() does not meet all of the BSD socket API specifications.
|
||||
*/
|
||||
#undef BROKEN_RECVMSG
|
||||
|
||||
/* Define if you cannot bind() before connect() for TCP sockets. */
|
||||
#undef BROKEN_TCP_BIND_BEFORE_CONNECT
|
||||
|
||||
@@ -326,36 +272,21 @@ int sigwait(const unsigned int *set, int *sig);
|
||||
/* Define to 1 if you have the <krb5/krb5.h> header file. */
|
||||
#undef HAVE_KRB5_KRB5_H
|
||||
|
||||
/* Define to 1 if you have the `c' library (-lc). */
|
||||
#undef HAVE_LIBC
|
||||
|
||||
/* if system have backtrace function */
|
||||
#undef HAVE_LIBCTRACE
|
||||
|
||||
/* Define to 1 if you have the `c_r' library (-lc_r). */
|
||||
#undef HAVE_LIBC_R
|
||||
|
||||
/* Define if libidn2 was found */
|
||||
#undef HAVE_LIBIDN2
|
||||
|
||||
/* Define to 1 if you have the `nsl' library (-lnsl). */
|
||||
#undef HAVE_LIBNSL
|
||||
|
||||
/* Define to 1 if you have the `pthread' library (-lpthread). */
|
||||
#undef HAVE_LIBPTHREAD
|
||||
|
||||
/* Define to 1 if you have the `rt' library (-lrt). */
|
||||
#undef HAVE_LIBRT
|
||||
|
||||
/* Define to 1 if you have the `scf' library (-lscf). */
|
||||
#undef HAVE_LIBSCF
|
||||
|
||||
/* Define to 1 if you have the `socket' library (-lsocket). */
|
||||
#undef HAVE_LIBSOCKET
|
||||
|
||||
/* Define to 1 if you have the `thr' library (-lthr). */
|
||||
#undef HAVE_LIBTHR
|
||||
|
||||
/* Define if libxml2 was found */
|
||||
#undef HAVE_LIBXML2
|
||||
|
||||
@@ -389,12 +320,24 @@ int sigwait(const unsigned int *set, int *sig);
|
||||
/* define if OpenSSL supports Ed25519 */
|
||||
#undef HAVE_OPENSSL_ED25519
|
||||
|
||||
/* Define if you have POSIX threads libraries and header files. */
|
||||
#undef HAVE_PTHREAD
|
||||
|
||||
/* Define to 1 if you have the `pthread_attr_getstacksize' function. */
|
||||
#undef HAVE_PTHREAD_ATTR_GETSTACKSIZE
|
||||
|
||||
/* Define to 1 if you have the `pthread_attr_setstacksize' function. */
|
||||
#undef HAVE_PTHREAD_ATTR_SETSTACKSIZE
|
||||
|
||||
/* Support for PTHREAD_MUTEX_ADAPTIVE_NP */
|
||||
#undef HAVE_PTHREAD_MUTEX_ADAPTIVE_NP
|
||||
|
||||
/* Define to 1 if you have the <pthread_np.h> header file. */
|
||||
#undef HAVE_PTHREAD_NP_H
|
||||
|
||||
/* Have PTHREAD_PRIO_INHERIT. */
|
||||
#undef HAVE_PTHREAD_PRIO_INHERIT
|
||||
|
||||
/* Define to 1 if you have the `pthread_setname_np' function. */
|
||||
#undef HAVE_PTHREAD_SETNAME_NP
|
||||
|
||||
@@ -443,6 +386,12 @@ int sigwait(const unsigned int *set, int *sig);
|
||||
/* Define to 1 if you have the `setresuid' function. */
|
||||
#undef HAVE_SETRESUID
|
||||
|
||||
/* Define to 1 if you have the `sigwait' function. */
|
||||
#undef HAVE_SIGWAIT
|
||||
|
||||
/* Define to 1 if you have the <stdatomic.h> header file. */
|
||||
#undef HAVE_STDATOMIC_H
|
||||
|
||||
/* Define to 1 if you have the <stdint.h> header file. */
|
||||
#undef HAVE_STDINT_H
|
||||
|
||||
@@ -461,9 +410,6 @@ int sigwait(const unsigned int *set, int *sig);
|
||||
/* Define to 1 if you have the <sys/devpoll.h> header file. */
|
||||
#undef HAVE_SYS_DEVPOLL_H
|
||||
|
||||
/* Define to 1 if you have the <sys/dyntune.h> header file. */
|
||||
#undef HAVE_SYS_DYNTUNE_H
|
||||
|
||||
/* Define to 1 if you have the <sys/mman.h> header file. */
|
||||
#undef HAVE_SYS_MMAN_H
|
||||
|
||||
@@ -506,8 +452,8 @@ int sigwait(const unsigned int *set, int *sig);
|
||||
/* Define if Thread-Local Storage is available */
|
||||
#undef HAVE_TLS
|
||||
|
||||
/* Define if running under Compaq TruCluster */
|
||||
#undef HAVE_TRUCLUSTER
|
||||
/* Define to 1 if you have the <uchar.h> header file. */
|
||||
#undef HAVE_UCHAR_H
|
||||
|
||||
/* Define to 1 if the system has the type `uintptr_t'. */
|
||||
#undef HAVE_UINTPTR_T
|
||||
@@ -521,6 +467,9 @@ int sigwait(const unsigned int *set, int *sig);
|
||||
/* Define if zlib was found */
|
||||
#undef HAVE_ZLIB
|
||||
|
||||
/* define if __atomic builtins are not available */
|
||||
#undef HAVE___ATOMIC
|
||||
|
||||
/* Define if __thread keyword is available */
|
||||
#undef HAVE___THREAD
|
||||
|
||||
@@ -530,18 +479,6 @@ int sigwait(const unsigned int *set, int *sig);
|
||||
/* Use HMAC-SHA256 for Client Cookie generation */
|
||||
#undef HMAC_SHA256_CC
|
||||
|
||||
/* return type of gai_strerror */
|
||||
#undef IRS_GAISTRERROR_RETURN_T
|
||||
|
||||
/* Define to the buffer length type used by getnameinfo(3). */
|
||||
#undef IRS_GETNAMEINFO_BUFLEN_T
|
||||
|
||||
/* Define to the flags type used by getnameinfo(3). */
|
||||
#undef IRS_GETNAMEINFO_FLAGS_T
|
||||
|
||||
/* Define to the sockaddr length type used by getnameinfo(3). */
|
||||
#undef IRS_GETNAMEINFO_SOCKLEN_T
|
||||
|
||||
/* Define if you want to use inline buffers */
|
||||
#undef ISC_BUFFER_USEINLINE
|
||||
|
||||
@@ -589,8 +526,9 @@ int sigwait(const unsigned int *set, int *sig);
|
||||
(O_NDELAY/O_NONBLOCK). */
|
||||
#undef PORT_NONBLOCK
|
||||
|
||||
/* The size of `void *', as computed by sizeof. */
|
||||
#undef SIZEOF_VOID_P
|
||||
/* Define to necessary symbol if this constant uses a non-standard name on
|
||||
your system. */
|
||||
#undef PTHREAD_CREATE_JOINABLE
|
||||
|
||||
/* Define to 1 if you have the ANSI C header files. */
|
||||
#undef STDC_HEADERS
|
||||
@@ -614,6 +552,28 @@ int sigwait(const unsigned int *set, int *sig);
|
||||
/* define if PKCS11 is used for Public-Key Cryptography */
|
||||
#undef USE_PKCS11
|
||||
|
||||
/* Enable extensions on AIX 3, Interix. */
|
||||
#ifndef _ALL_SOURCE
|
||||
# undef _ALL_SOURCE
|
||||
#endif
|
||||
/* Enable GNU extensions on systems that have them. */
|
||||
#ifndef _GNU_SOURCE
|
||||
# undef _GNU_SOURCE
|
||||
#endif
|
||||
/* Enable threading extensions on Solaris. */
|
||||
#ifndef _POSIX_PTHREAD_SEMANTICS
|
||||
# undef _POSIX_PTHREAD_SEMANTICS
|
||||
#endif
|
||||
/* Enable extensions on HP NonStop. */
|
||||
#ifndef _TANDEM_SOURCE
|
||||
# undef _TANDEM_SOURCE
|
||||
#endif
|
||||
/* Enable general extensions on Solaris. */
|
||||
#ifndef __EXTENSIONS__
|
||||
# undef __EXTENSIONS__
|
||||
#endif
|
||||
|
||||
|
||||
/* the default value of dnssec-validation option */
|
||||
#undef VALIDATION_DEFAULT
|
||||
|
||||
@@ -632,11 +592,27 @@ int sigwait(const unsigned int *set, int *sig);
|
||||
# endif
|
||||
#endif
|
||||
|
||||
/* Define to 1 if on MINIX. */
|
||||
#undef _MINIX
|
||||
|
||||
/* Define to 2 if the system does not provide POSIX.1 features except with
|
||||
this defined. */
|
||||
#undef _POSIX_1_SOURCE
|
||||
|
||||
/* Define to 1 if you need to in order for `stat' and other things to work. */
|
||||
#undef _POSIX_SOURCE
|
||||
|
||||
/* Select RFC3542 IPv6 API on macOS */
|
||||
#undef __APPLE_USE_RFC_3542
|
||||
|
||||
/* Define to empty if `const' does not conform to ANSI C. */
|
||||
#undef const
|
||||
|
||||
/* Define to empty if your compiler does not support "static inline". */
|
||||
/* Define to `__inline__' or `__inline' if that's what the C compiler
|
||||
calls it, or to nothing if 'inline' is not supported under any name. */
|
||||
#ifndef __cplusplus
|
||||
#undef inline
|
||||
#endif
|
||||
|
||||
/* Define to `unsigned int' if <sys/types.h> does not define. */
|
||||
#undef size_t
|
||||
|
||||
+7
-30
@@ -43,19 +43,19 @@
|
||||
#endif
|
||||
|
||||
/*
|
||||
* Minimum version is Windows XP
|
||||
* Minimum version is Windows Vista and Windows Server 2008
|
||||
*/
|
||||
#ifndef _WIN32_WINNT
|
||||
#define _WIN32_WINNT 0x0501
|
||||
#define _WIN32_WINNT 0x0600
|
||||
#endif
|
||||
#if _WIN32_WINNT < 0x0501
|
||||
#error Minimum Target environment is Windows XP and Windows Server 2003
|
||||
#if _WIN32_WINNT < 0x0600
|
||||
#error Minimum Target environment is Windows Vista and Windows Server 2008
|
||||
#endif
|
||||
#ifndef NTDDI_VERSION
|
||||
#define NTDDI_VERSION 0x05010100
|
||||
#define NTDDI_VERSION 0x06000100
|
||||
#endif
|
||||
#if NTDDI_VERSION < 0x05010100
|
||||
#error Minimum Target environment is Windows XP SP1 and Windows Server 2003
|
||||
#if NTDDI_VERSION < 0x06000100
|
||||
#error Minimum Target environment is Windows Vista and Windows Server 2008
|
||||
#endif
|
||||
|
||||
/* Define if you have the ANSI C header files. */
|
||||
@@ -141,8 +141,6 @@ char *getpassphrase(const char *);
|
||||
*/
|
||||
#define ISC_DLZ_DLOPEN 1
|
||||
|
||||
#define WANT_IPV6
|
||||
|
||||
#define S_IFMT _S_IFMT /* file type mask */
|
||||
#define S_IFDIR _S_IFDIR /* directory */
|
||||
#define S_IFCHR _S_IFCHR /* character special */
|
||||
@@ -291,27 +289,6 @@ typedef __int64 off_t;
|
||||
*/
|
||||
@HAVE_LIBXML2@
|
||||
|
||||
/** define if struct addrinfo exists */
|
||||
#define HAVE_ADDRINFO
|
||||
|
||||
/** define if getaddrinfo() exists */
|
||||
#define HAVE_GETADDRINFO
|
||||
|
||||
/** define if gai_strerror() exists */
|
||||
#define HAVE_GAISTRERROR
|
||||
|
||||
/* return type of gai_strerror */
|
||||
#define IRS_GAISTRERROR_RETURN_T char *
|
||||
|
||||
/* Define to the buffer length type used by getnameinfo(3). */
|
||||
#define IRS_GETNAMEINFO_BUFLEN_T DWORD
|
||||
|
||||
/* Define to the flags type used by getnameinfo(3). */
|
||||
#define IRS_GETNAMEINFO_FLAGS_T int
|
||||
|
||||
/* Define to the sockaddr length type used by getnameinfo(3). */
|
||||
#define IRS_GETNAMEINFO_SOCKLEN_T socklen_t
|
||||
|
||||
/* Define to enable "rrset-order fixed" syntax. */
|
||||
@DNS_RDATASET_FIXED@
|
||||
|
||||
|
||||
+3
-10
@@ -19,8 +19,6 @@ case $host in
|
||||
use_threads=false ;;
|
||||
*-solaris*)
|
||||
use_threads=true ;;
|
||||
*-ibm-aix*)
|
||||
use_threads=true ;;
|
||||
*-hp-hpux10*)
|
||||
use_threads=false ;;
|
||||
*-hp-hpux11*)
|
||||
@@ -50,13 +48,8 @@ case $host in
|
||||
use_threads=false ;;
|
||||
*-freebsd*)
|
||||
use_threads=true ;;
|
||||
[*-bsdi[234]*])
|
||||
# Thread signals do not work reliably on some versions of BSD/OS.
|
||||
use_threads=false ;;
|
||||
*-bsdi5*)
|
||||
use_threads=true ;;
|
||||
*-linux*)
|
||||
use_threads=true ;;
|
||||
use_threads=true ;;
|
||||
*-darwin[[123456789]].*)
|
||||
use_threads=false ;;
|
||||
*-darwin*.*)
|
||||
@@ -86,7 +79,7 @@ if $use_threads
|
||||
then
|
||||
AC_MSG_RESULT(yes)
|
||||
else
|
||||
AC_MSG_RESULT(no)
|
||||
AC_MSG_RESULT(no)
|
||||
fi
|
||||
|
||||
if $use_threads
|
||||
@@ -99,7 +92,7 @@ then
|
||||
# We don't want to set -lpthread as that break
|
||||
# the ability to choose threads library at final
|
||||
# link time and is not valid for all architectures.
|
||||
|
||||
|
||||
PTHREAD=
|
||||
if test "X$GCC" = "Xyes"; then
|
||||
saved_cc="$CC"
|
||||
|
||||
+389
-1431
File diff suppressed because it is too large
Load Diff
+11
-15
@@ -8,14 +8,6 @@ but reported bugs will be fixed as time permits.
|
||||
named and restarts it in the event of a crash, 'zone-edit'
|
||||
which enables editing of a dynamic zone, and others
|
||||
|
||||
- queryperf/
|
||||
|
||||
A DNS query performance testing tool
|
||||
|
||||
- perftcpdns/
|
||||
|
||||
A performance testing tool for DNS over TCP
|
||||
|
||||
- dane/
|
||||
|
||||
mkdane.sh generates TLSA records for use with DNS-based
|
||||
@@ -44,19 +36,23 @@ but reported bugs will be fixed as time permits.
|
||||
sources. (These are no longer actively maintained and are
|
||||
expected to be deprecated eventually.)
|
||||
|
||||
- idn/
|
||||
External tools:
|
||||
|
||||
Contains source for 'idnkit', which provides support for
|
||||
Internationalized Domain Name processing.
|
||||
- https://gitlab.isc.org/isc-projects/queryperf
|
||||
|
||||
- dnsperf-2.1.0.0-1/
|
||||
- dnsperf-patches/
|
||||
A DNS query performance testing tool
|
||||
|
||||
- https://gitlab.isc.org/isc-projects/perftcpdns
|
||||
|
||||
A performance testing tool for DNS over TCP
|
||||
|
||||
- https://gitlab.isc.org/isc-projects/dnsperf
|
||||
|
||||
DNS server performance testing tools, like 'queryperf' but more
|
||||
advanced: 'dnsperf' focuses on authoritative server performance
|
||||
and 'resperf' on recursive server performance. The patch that
|
||||
adds support for EDNS Client Subnet can be found in dnsperf-patches
|
||||
directory.
|
||||
adds support for EDNS Client Subnet has been applied to the
|
||||
git repository.
|
||||
|
||||
Formerly, there was more software included in this directory, but we
|
||||
have removed it in favour of using canonical upstream locations. You
|
||||
|
||||
@@ -66,11 +66,7 @@
|
||||
static dns_sdlzimplementation_t *dlz_bdb = NULL;
|
||||
|
||||
/* should the bdb driver use threads. */
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
#define bdb_threads DB_THREAD
|
||||
#else
|
||||
#define bdb_threads 0
|
||||
#endif
|
||||
|
||||
/* BDB database names */
|
||||
#define dlz_data "dns_data"
|
||||
|
||||
@@ -66,11 +66,7 @@
|
||||
static dns_sdlzimplementation_t *dlz_bdbhpt = NULL;
|
||||
|
||||
/* should the bdb driver use threads. */
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
#define bdbhpt_threads DB_THREAD
|
||||
#else
|
||||
#define bdbhpt_threads 0
|
||||
#endif
|
||||
|
||||
/* bdbhpt database names */
|
||||
#define dlz_data "dns_data"
|
||||
|
||||
@@ -35,7 +35,7 @@
|
||||
|
||||
/*
|
||||
* Copyright (C) 1999-2001, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
@@ -84,7 +84,7 @@ typedef struct config_data {
|
||||
typedef struct dir_entry dir_entry_t;
|
||||
|
||||
struct dir_entry {
|
||||
char dirpath[ISC_DIR_PATHMAX];
|
||||
char dirpath[PATH_MAX];
|
||||
ISC_LINK(dir_entry_t) link;
|
||||
};
|
||||
|
||||
@@ -361,7 +361,7 @@ process_dir(isc_dir_t *dir, void *passback, config_data_t *cd,
|
||||
dlist_t *dir_list, unsigned int basedirlen)
|
||||
{
|
||||
|
||||
char tmp[ISC_DIR_PATHMAX + ISC_DIR_NAMEMAX];
|
||||
char tmp[PATH_MAX + NAME_MAX];
|
||||
int astPos;
|
||||
struct stat sb;
|
||||
isc_result_t result = ISC_R_FAILURE;
|
||||
@@ -369,7 +369,7 @@ process_dir(isc_dir_t *dir, void *passback, config_data_t *cd,
|
||||
char *type;
|
||||
char *ttlStr;
|
||||
char *data;
|
||||
char host[ISC_DIR_NAMEMAX];
|
||||
char host[NAME_MAX];
|
||||
char *tmpString;
|
||||
char *tmpPtr;
|
||||
int ttl;
|
||||
@@ -408,7 +408,7 @@ process_dir(isc_dir_t *dir, void *passback, config_data_t *cd,
|
||||
{
|
||||
if ((strlen(host) +
|
||||
strlen(tmpPtr + 1) + 2)
|
||||
> ISC_DIR_NAMEMAX)
|
||||
> NAME_MAX)
|
||||
continue;
|
||||
strcat(host, tmpPtr + 1);
|
||||
strcat(host, ".");
|
||||
@@ -416,7 +416,7 @@ process_dir(isc_dir_t *dir, void *passback, config_data_t *cd,
|
||||
}
|
||||
if ((strlen(host) +
|
||||
strlen(tmpString) + 1)
|
||||
<= ISC_DIR_NAMEMAX)
|
||||
<= NAME_MAX)
|
||||
strcat(host, tmpString);
|
||||
}
|
||||
|
||||
@@ -443,7 +443,7 @@ process_dir(isc_dir_t *dir, void *passback, config_data_t *cd,
|
||||
strncpy(host,
|
||||
(char *) &dir->entry.name[6],
|
||||
sizeof(host) - 1);
|
||||
host[255] = '\0';
|
||||
host[NAME_MAX-1] = '\0';
|
||||
}
|
||||
foundHost = true;
|
||||
break;
|
||||
|
||||
@@ -94,11 +94,7 @@ static dns_sdlzimplementation_t *dlz_ldap = NULL;
|
||||
*/
|
||||
|
||||
typedef struct {
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
db_list_t *db; /*%< handle to a list of DB */
|
||||
#else
|
||||
dbinstance_t *db; /*%< handle to db */
|
||||
#endif
|
||||
int method; /*%< security authentication method */
|
||||
char *user; /*%< who is authenticating */
|
||||
char *cred; /*%< password for simple authentication method */
|
||||
@@ -244,9 +240,6 @@ dlz_ldap_connect(ldap_instance_t *dbi, dbinstance_t *dbc) {
|
||||
return (result);
|
||||
}
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
|
||||
/*%
|
||||
* Properly cleans up a list of database instances.
|
||||
* This function is only used when the driver is compiled for
|
||||
@@ -316,7 +309,6 @@ ldap_find_avail_conn(db_list_t *dblist) {
|
||||
count);
|
||||
return (NULL);
|
||||
}
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
static isc_result_t
|
||||
ldap_process_results(LDAP *dbc, LDAPMessage *msg, char ** attrs,
|
||||
@@ -569,22 +561,10 @@ ldap_get_results(const char *zone, const char *record,
|
||||
int entries;
|
||||
|
||||
/* get db instance / connection */
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
/* find an available DBI from the list */
|
||||
dbi = ldap_find_avail_conn((db_list_t *)
|
||||
((ldap_instance_t *)dbdata)->db);
|
||||
|
||||
#else /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
/*
|
||||
* only 1 DBI - no need to lock instance lock either
|
||||
* only 1 thread in the whole process, no possible contention.
|
||||
*/
|
||||
dbi = (dbinstance_t *) ((ldap_instance_t *)dbdata)->db;
|
||||
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
/* if DBI is null, can't do anything else */
|
||||
if (dbi == NULL)
|
||||
return (ISC_R_FAILURE);
|
||||
@@ -845,13 +825,9 @@ ldap_get_results(const char *zone, const char *record,
|
||||
if (dbi->client != NULL)
|
||||
isc_mem_free(named_g_mctx, dbi->client);
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
/* release the lock so another thread can use this dbi */
|
||||
isc_mutex_unlock(&dbi->instance_lock);
|
||||
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
/* release query string */
|
||||
if (querystring != NULL)
|
||||
isc_mem_free(named_g_mctx, querystring );
|
||||
@@ -939,30 +915,19 @@ dlz_ldap_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
dbinstance_t *dbi = NULL;
|
||||
int protocol;
|
||||
int method;
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
/* if multi-threaded, we need a few extra variables. */
|
||||
int dbcount;
|
||||
char *endp;
|
||||
/* db_list_t *dblist = NULL; */
|
||||
int i;
|
||||
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
UNUSED(dlzname);
|
||||
UNUSED(driverarg);
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
/* if debugging, let user know we are multithreaded. */
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
|
||||
DNS_LOGMODULE_DLZ, ISC_LOG_DEBUG(1),
|
||||
"LDAP driver running multithreaded");
|
||||
#else /* ISC_PLATFORM_USETHREADS */
|
||||
/* if debugging, let user know we are single threaded. */
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
|
||||
DNS_LOGMODULE_DLZ, ISC_LOG_DEBUG(1),
|
||||
"LDAP driver running single threaded");
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
if (argc < 9) {
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
|
||||
@@ -1010,9 +975,6 @@ dlz_ldap_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
return (ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
/* multithreaded build can have multiple DB connections */
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
/* check how many db connections we should create */
|
||||
dbcount = strtol(argv[1], &endp, 10);
|
||||
if (*endp != '\0' || dbcount < 0) {
|
||||
@@ -1022,7 +984,6 @@ dlz_ldap_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
"must be positive.");
|
||||
return (ISC_R_FAILURE);
|
||||
}
|
||||
#endif
|
||||
|
||||
/* check that LDAP URL parameters make sense */
|
||||
switch(argc) {
|
||||
@@ -1078,7 +1039,6 @@ dlz_ldap_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
/* allocate memory for database connection list */
|
||||
ldap_inst->db = isc_mem_get(named_g_mctx, sizeof(db_list_t));
|
||||
if (ldap_inst->db == NULL) {
|
||||
@@ -1095,8 +1055,6 @@ dlz_ldap_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
*/
|
||||
for (i = 0; i < dbcount; i++) {
|
||||
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
/* how many queries were passed in from config file? */
|
||||
switch(argc) {
|
||||
case 9:
|
||||
@@ -1138,18 +1096,9 @@ dlz_ldap_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
/* when multithreaded, build a list of DBI's */
|
||||
ISC_LINK_INIT(dbi, link);
|
||||
ISC_LIST_APPEND(*(ldap_inst->db), dbi, link);
|
||||
#else
|
||||
/*
|
||||
* when single threaded, hold onto the one connection
|
||||
* instance.
|
||||
*/
|
||||
ldap_inst->db = dbi;
|
||||
|
||||
#endif
|
||||
/* attempt to connect */
|
||||
result = dlz_ldap_connect(ldap_inst, dbi);
|
||||
|
||||
@@ -1166,18 +1115,11 @@ dlz_ldap_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
* allocate memory
|
||||
*/
|
||||
case ISC_R_NOMEMORY:
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
|
||||
DNS_LOGMODULE_DLZ, ISC_LOG_ERROR,
|
||||
"LDAP driver could not allocate memory "
|
||||
"for connection number %u",
|
||||
i+1);
|
||||
#else
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
|
||||
DNS_LOGMODULE_DLZ, ISC_LOG_ERROR,
|
||||
"LDAP driver could not allocate memory "
|
||||
"for connection");
|
||||
#endif
|
||||
goto cleanup;
|
||||
break;
|
||||
/*
|
||||
@@ -1194,18 +1136,11 @@ dlz_ldap_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
break;
|
||||
/* failure means couldn't connect to ldap server */
|
||||
case ISC_R_FAILURE:
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
|
||||
DNS_LOGMODULE_DLZ, ISC_LOG_ERROR,
|
||||
"LDAP driver could not "
|
||||
"bind connection number %u to server.",
|
||||
i+1);
|
||||
#else
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
|
||||
DNS_LOGMODULE_DLZ, ISC_LOG_ERROR,
|
||||
"LDAP driver could not "
|
||||
"bind connection to server.");
|
||||
#endif
|
||||
goto cleanup;
|
||||
break;
|
||||
/*
|
||||
@@ -1221,15 +1156,10 @@ dlz_ldap_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
break;
|
||||
} /* end switch(result) */
|
||||
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
/* set DBI = null for next loop through. */
|
||||
dbi = NULL;
|
||||
} /* end for loop */
|
||||
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
|
||||
/* set dbdata to the ldap_instance we created. */
|
||||
*dbdata = ldap_inst;
|
||||
@@ -1248,20 +1178,10 @@ dlz_ldap_destroy(void *driverarg, void *dbdata) {
|
||||
UNUSED(driverarg);
|
||||
|
||||
if (dbdata != NULL) {
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
/* cleanup the list of DBI's */
|
||||
ldap_destroy_dblist((db_list_t *)
|
||||
((ldap_instance_t *)dbdata)->db);
|
||||
|
||||
#else /* ISC_PLATFORM_USETHREADS */
|
||||
if (((ldap_instance_t *)dbdata)->db->dbconn != NULL)
|
||||
ldap_unbind_s((LDAP *)
|
||||
((ldap_instance_t *)dbdata)->db->dbconn);
|
||||
|
||||
/* destroy single DB instance */
|
||||
destroy_sqldbinstance(((ldap_instance_t *)dbdata)->db);
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
if (((ldap_instance_t *)dbdata)->hosts != NULL)
|
||||
isc_mem_free(named_g_mctx,
|
||||
((ldap_instance_t *)dbdata)->hosts);
|
||||
|
||||
@@ -99,17 +99,7 @@ typedef struct{
|
||||
*/
|
||||
|
||||
typedef struct {
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
db_list_t *db; /* handle to a list of DB */
|
||||
|
||||
#else
|
||||
|
||||
dbinstance_t *db; /* handle to db */
|
||||
|
||||
#endif
|
||||
|
||||
SQLHENV sql_env; /* handle to SQL environment */
|
||||
SQLCHAR *dsn;
|
||||
SQLCHAR *user;
|
||||
@@ -136,9 +126,6 @@ safeLen(void *a) {
|
||||
|
||||
static void
|
||||
destroy_odbc_instance(odbc_instance_t *odbc_inst) {
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
dbinstance_t *ndbi = NULL;
|
||||
dbinstance_t *dbi = NULL;
|
||||
|
||||
@@ -180,34 +167,6 @@ destroy_odbc_instance(odbc_instance_t *odbc_inst) {
|
||||
/* release memory for the list structure */
|
||||
isc_mem_put(named_g_mctx, odbc_inst->db, sizeof(db_list_t));
|
||||
|
||||
#else /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
/* free statement handle */
|
||||
if (((odbc_db_t *) (odbc_inst->db->dbconn))->stmnt != NULL) {
|
||||
SQLFreeHandle(SQL_HANDLE_STMT,
|
||||
((odbc_db_t *) (odbc_inst->db->dbconn))->stmnt);
|
||||
((odbc_db_t *) (odbc_inst->db->dbconn))->stmnt = NULL;
|
||||
}
|
||||
|
||||
/* disconnect from database, free connection handle */
|
||||
if (((odbc_db_t *) (odbc_inst->db->dbconn))->dbc != NULL) {
|
||||
SQLDisconnect(((odbc_db_t *) (odbc_inst->db->dbconn))->dbc);
|
||||
SQLFreeHandle(SQL_HANDLE_DBC,
|
||||
((odbc_db_t *) (odbc_inst->db->dbconn))->dbc);
|
||||
((odbc_db_t *) (odbc_inst->db->dbconn))->dbc = NULL;
|
||||
}
|
||||
/* free mem for the odbc_db_t structure held in db */
|
||||
if (((odbc_db_t *) odbc_inst->db->dbconn) != NULL) {
|
||||
isc_mem_free(named_g_mctx, odbc_inst->db->dbconn);
|
||||
odbc_inst->db->dbconn = NULL;
|
||||
}
|
||||
|
||||
if (odbc_inst->db != NULL)
|
||||
destroy_sqldbinstance(odbc_inst->db);
|
||||
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
|
||||
/* free sql environment */
|
||||
if (odbc_inst->sql_env != NULL)
|
||||
SQLFreeHandle(SQL_HANDLE_ENV, odbc_inst->sql_env);
|
||||
@@ -327,8 +286,6 @@ odbc_connect(odbc_instance_t *dbi, odbc_db_t **dbc) {
|
||||
* multithreaded operation.
|
||||
*/
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
static dbinstance_t *
|
||||
odbc_find_avail_conn(db_list_t *dblist)
|
||||
{
|
||||
@@ -362,8 +319,6 @@ odbc_find_avail_conn(db_list_t *dblist)
|
||||
return NULL;
|
||||
}
|
||||
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
/*% Allocates memory for a new string, and then constructs the new
|
||||
* string by "escaping" the input string. The new string is
|
||||
* safe to be used in queries. This is necessary because we cannot
|
||||
@@ -482,21 +437,10 @@ odbc_get_resultset(const char *zone, const char *record,
|
||||
REQUIRE(*r_dbi == NULL);
|
||||
|
||||
/* get db instance / connection */
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
/* find an available DBI from the list */
|
||||
dbi = odbc_find_avail_conn(((odbc_instance_t *) dbdata)->db);
|
||||
|
||||
#else /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
/*
|
||||
* only 1 DBI - no need to lock instance lock either
|
||||
* only 1 thread in the whole process, no possible contention.
|
||||
*/
|
||||
dbi = (dbinstance_t *) ((odbc_instance_t *) dbdata)->db;
|
||||
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
/* if DBI is null, can't do anything else */
|
||||
if (dbi == NULL) {
|
||||
result = ISC_R_FAILURE;
|
||||
@@ -698,14 +642,10 @@ odbc_get_resultset(const char *zone, const char *record,
|
||||
if (dbi->client != NULL)
|
||||
isc_mem_free(named_g_mctx, dbi->client);
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
/* if we are done using this dbi, release the lock */
|
||||
if (result != ISC_R_SUCCESS)
|
||||
isc_mutex_unlock(&dbi->instance_lock);
|
||||
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
/* release query string */
|
||||
if (querystring != NULL)
|
||||
isc_mem_free(named_g_mctx, querystring );
|
||||
@@ -937,13 +877,9 @@ odbc_process_rs(dns_sdlzlookup_t *lookup, dbinstance_t *dbi)
|
||||
/* close cursor */
|
||||
SQLCloseCursor(((odbc_db_t *) (dbi->dbconn))->stmnt);
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
/* free lock on dbi so someone else can use it. */
|
||||
isc_mutex_unlock(&dbi->instance_lock);
|
||||
|
||||
#endif
|
||||
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -980,11 +916,8 @@ odbc_findzone(void *driverarg, void *dbdata, const char *name,
|
||||
/* get rid of result set, we are done with it. */
|
||||
SQLCloseCursor(((odbc_db_t *) (dbi->dbconn))->stmnt);
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
/* free lock on dbi so someone else can use it. */
|
||||
isc_mutex_unlock(&dbi->instance_lock);
|
||||
#endif
|
||||
}
|
||||
|
||||
return result;
|
||||
@@ -1032,11 +965,8 @@ odbc_allowzonexfr(void *driverarg, void *dbdata, const char *name,
|
||||
/* get rid of result set, we are done with it. */
|
||||
SQLCloseCursor(((odbc_db_t *) (dbi->dbconn))->stmnt);
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
/* free lock on dbi so someone else can use it. */
|
||||
isc_mutex_unlock(&dbi->instance_lock);
|
||||
#endif
|
||||
|
||||
}
|
||||
|
||||
@@ -1167,13 +1097,9 @@ odbc_allnodes(const char *zone, void *driverarg, void *dbdata,
|
||||
/* close cursor */
|
||||
SQLCloseCursor(((odbc_db_t *) (dbi->dbconn))->stmnt);
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
/* free lock on dbi so someone else can use it. */
|
||||
isc_mutex_unlock(&dbi->instance_lock);
|
||||
|
||||
#endif
|
||||
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -1252,29 +1178,17 @@ odbc_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
odbc_instance_t *odbc_inst = NULL;
|
||||
dbinstance_t *db = NULL;
|
||||
SQLRETURN sqlRes;
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
/* if multi-threaded, we need a few extra variables. */
|
||||
int dbcount;
|
||||
int i;
|
||||
char *endp;
|
||||
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
UNUSED(dlzname);
|
||||
UNUSED(driverarg);
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
/* if debugging, let user know we are multithreaded. */
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
|
||||
DNS_LOGMODULE_DLZ, ISC_LOG_DEBUG(1),
|
||||
"Odbc driver running multithreaded");
|
||||
#else /* ISC_PLATFORM_USETHREADS */
|
||||
/* if debugging, let user know we are single threaded. */
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
|
||||
DNS_LOGMODULE_DLZ, ISC_LOG_DEBUG(1),
|
||||
"Odbc driver running single threaded");
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
/* verify we have at least 5 arg's passed to the driver */
|
||||
if (argc < 5) {
|
||||
@@ -1295,8 +1209,6 @@ odbc_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
}
|
||||
|
||||
/* multithreaded build can have multiple DB connections */
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
/* check how many db connections we should create */
|
||||
dbcount = strtol(argv[1], &endp, 10);
|
||||
if (*endp != '\0' || dbcount < 0) {
|
||||
@@ -1307,8 +1219,6 @@ odbc_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
return (ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
/* allocate memory for odbc instance */
|
||||
odbc_inst = isc_mem_get(named_g_mctx, sizeof(odbc_instance_t));
|
||||
if (odbc_inst == NULL)
|
||||
@@ -1361,8 +1271,6 @@ odbc_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
}
|
||||
}
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
/* allocate memory for database connection list */
|
||||
odbc_inst->db = isc_mem_get(named_g_mctx, sizeof(db_list_t));
|
||||
if (odbc_inst->db == NULL) {
|
||||
@@ -1378,8 +1286,6 @@ odbc_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
/* append each new DBI to the end of the list */
|
||||
for (i=0; i < dbcount; i++) {
|
||||
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
/* how many queries were passed in from config file? */
|
||||
switch(argc) {
|
||||
case 5:
|
||||
@@ -1416,20 +1322,14 @@ odbc_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
/* when multithreaded, build a list of DBI's */
|
||||
ISC_LINK_INIT(db, link);
|
||||
ISC_LIST_APPEND(*odbc_inst->db, db, link);
|
||||
|
||||
#endif
|
||||
|
||||
result = odbc_connect(odbc_inst, (odbc_db_t **) &(db->dbconn));
|
||||
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
/*
|
||||
* if multi threaded, let user know which
|
||||
* connection failed. user could be
|
||||
@@ -1442,28 +1342,14 @@ odbc_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
"Odbc driver failed to create database "
|
||||
"connection number %u after 3 attempts",
|
||||
i+1);
|
||||
#else
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
|
||||
DNS_LOGMODULE_DLZ, ISC_LOG_ERROR,
|
||||
"Odbc driver failed to create database "
|
||||
"connection after 3 attempts");
|
||||
#endif
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
/* set DB = null for next loop through. */
|
||||
db = NULL;
|
||||
|
||||
} /* end for loop */
|
||||
|
||||
#else
|
||||
/* tell odbc_inst about the db connection we just created. */
|
||||
odbc_inst->db = db;
|
||||
|
||||
#endif
|
||||
|
||||
/* set dbdata to the odbc_instance we created. */
|
||||
*dbdata = odbc_inst;
|
||||
|
||||
|
||||
@@ -149,8 +149,6 @@ postgres_makesafe(char *to, const char *from, size_t length)
|
||||
return target - to;
|
||||
}
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
/*%
|
||||
* Properly cleans up a list of database instances.
|
||||
* This function is only used when the driver is compiled for
|
||||
@@ -225,8 +223,6 @@ postgres_find_avail_conn(db_list_t *dblist)
|
||||
return NULL;
|
||||
}
|
||||
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
/*%
|
||||
* Allocates memory for a new string, and then constructs the new
|
||||
* string by "escaping" the input string. The new string is
|
||||
@@ -298,21 +294,10 @@ postgres_get_resultset(const char *zone, const char *record,
|
||||
#endif
|
||||
|
||||
/* get db instance / connection */
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
/* find an available DBI from the list */
|
||||
dbi = postgres_find_avail_conn((db_list_t *) dbdata);
|
||||
|
||||
#else /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
/*
|
||||
* only 1 DBI - no need to lock instance lock either
|
||||
* only 1 thread in the whole process, no possible contention.
|
||||
*/
|
||||
dbi = (dbinstance_t *) dbdata;
|
||||
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
#if 0
|
||||
/* temporary logging message */
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
|
||||
@@ -599,8 +584,6 @@ postgres_get_resultset(const char *zone, const char *record,
|
||||
if (dbi->client != NULL)
|
||||
isc_mem_free(named_g_mctx, dbi->client);
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
#if 0
|
||||
/* temporary logging message */
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
|
||||
@@ -611,8 +594,6 @@ postgres_get_resultset(const char *zone, const char *record,
|
||||
/* release the lock so another thread can use this dbi */
|
||||
isc_mutex_unlock(&dbi->instance_lock);
|
||||
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
/* release query string */
|
||||
if (querystring != NULL)
|
||||
isc_mem_free(named_g_mctx, querystring );
|
||||
@@ -1058,15 +1039,12 @@ postgres_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
dbinstance_t *dbi = NULL;
|
||||
unsigned int j;
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
/* if multi-threaded, we need a few extra variables. */
|
||||
int dbcount;
|
||||
db_list_t *dblist = NULL;
|
||||
int i;
|
||||
char *endp;
|
||||
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
UNUSED(driverarg);
|
||||
UNUSED(dlzname);
|
||||
|
||||
@@ -1074,17 +1052,10 @@ postgres_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
srand( (unsigned)time( NULL ) );
|
||||
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
/* if debugging, let user know we are multithreaded. */
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
|
||||
DNS_LOGMODULE_DLZ, ISC_LOG_DEBUG(1),
|
||||
"Postgres driver running multithreaded");
|
||||
#else /* ISC_PLATFORM_USETHREADS */
|
||||
/* if debugging, let user know we are single threaded. */
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
|
||||
DNS_LOGMODULE_DLZ, ISC_LOG_DEBUG(1),
|
||||
"Postgres driver running single threaded");
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
/* verify we have at least 5 arg's passed to the driver */
|
||||
if (argc < 5) {
|
||||
@@ -1105,7 +1076,6 @@ postgres_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
}
|
||||
|
||||
/* multithreaded build can have multiple DB connections */
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
/* check how many db connections we should create */
|
||||
dbcount = strtol(argv[1], &endp, 10);
|
||||
@@ -1131,8 +1101,6 @@ postgres_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
*/
|
||||
for (i=0; i < dbcount; i++) {
|
||||
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
/* how many queries were passed in from config file? */
|
||||
switch(argc) {
|
||||
case 5:
|
||||
@@ -1174,14 +1142,10 @@ postgres_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
/* when multithreaded, build a list of DBI's */
|
||||
ISC_LINK_INIT(dbi, link);
|
||||
ISC_LIST_APPEND(*dblist, dbi, link);
|
||||
|
||||
#endif
|
||||
|
||||
/* create and set db connection */
|
||||
dbi->dbconn = PQconnectdb(argv[2]);
|
||||
/*
|
||||
@@ -1204,8 +1168,6 @@ postgres_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
PQreset((PGconn *) dbi->dbconn);
|
||||
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
/*
|
||||
* if multi threaded, let user know which connection
|
||||
* failed. user could be attempting to create 10 db
|
||||
@@ -1229,30 +1191,11 @@ postgres_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
/* set dbdata to the list we created. */
|
||||
*dbdata = dblist;
|
||||
|
||||
#else /* ISC_PLATFORM_USETHREADS */
|
||||
/* if single threaded, just let user know we couldn't connect. */
|
||||
if (PQstatus((PGconn *) dbi->dbconn) != CONNECTION_OK) {
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_DATABASE,
|
||||
DNS_LOGMODULE_DLZ, ISC_LOG_ERROR,
|
||||
"Postgres driver failed to create database "
|
||||
"connection after 4 attempts");
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/*
|
||||
* single threaded build can only use 1 db connection, return
|
||||
* it via dbdata
|
||||
*/
|
||||
*dbdata = dbi;
|
||||
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
/* hey, we got through all of that ok, return success. */
|
||||
return(ISC_R_SUCCESS);
|
||||
|
||||
cleanup:
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
/*
|
||||
* if multithreaded, we could fail because only 1 connection
|
||||
* couldn't be made. We should cleanup the other successful
|
||||
@@ -1260,11 +1203,6 @@ postgres_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
*/
|
||||
postgres_destroy_dblist(dblist);
|
||||
|
||||
#else /* ISC_PLATFORM_USETHREADS */
|
||||
if (dbi != NULL)
|
||||
destroy_sqldbinstance(dbi);
|
||||
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
return(ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
@@ -1277,29 +1215,9 @@ postgres_create(const char *dlzname, unsigned int argc, char *argv[],
|
||||
static void
|
||||
postgres_destroy(void *driverarg, void *dbdata)
|
||||
{
|
||||
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
|
||||
UNUSED(driverarg);
|
||||
/* cleanup the list of DBI's */
|
||||
postgres_destroy_dblist((db_list_t *) dbdata);
|
||||
|
||||
#else /* ISC_PLATFORM_USETHREADS */
|
||||
|
||||
dbinstance_t *dbi;
|
||||
|
||||
UNUSED(driverarg);
|
||||
|
||||
dbi = (dbinstance_t *) dbdata;
|
||||
|
||||
/* release DB connection */
|
||||
if (dbi->dbconn != NULL)
|
||||
PQfinish((PGconn *) dbi->dbconn);
|
||||
|
||||
/* destroy single DB instance */
|
||||
destroy_sqldbinstance(dbi);
|
||||
|
||||
#endif /* ISC_PLATFORM_USETHREADS */
|
||||
}
|
||||
|
||||
/* pointers to all our runtime methods. */
|
||||
|
||||
@@ -68,11 +68,7 @@
|
||||
#include "dlz_minimal.h"
|
||||
|
||||
/* should the bdb driver use threads. */
|
||||
#ifdef ISC_PLATFORM_USETHREADS
|
||||
#define bdbhpt_threads DB_THREAD
|
||||
#else
|
||||
#define bdbhpt_threads 0
|
||||
#endif
|
||||
|
||||
/* bdbhpt database names */
|
||||
#define dlz_data "dns_data"
|
||||
|
||||
@@ -1,55 +0,0 @@
|
||||
# Copyright 2000, 2001, 2003, 2006-2012 Nominum, Inc. All Rights Reserved.
|
||||
|
||||
prefix = @prefix@
|
||||
exec_prefix = @exec_prefix@
|
||||
bindir = @bindir@
|
||||
mandir = @mandir@
|
||||
datarootdir = @datarootdir@
|
||||
|
||||
INSTALL = @INSTALL@
|
||||
INSTALL_PROGRAM = @INSTALL_PROGRAM@
|
||||
INSTALL_DATA = @INSTALL_DATA@
|
||||
RANLIB = @RANLIB@
|
||||
|
||||
CC = @PTHREAD_CC@
|
||||
CFLAGS = @CFLAGS@ @DNSCFLAGS@ @DEFS@ @PTHREAD_CFLAGS@
|
||||
LIBS = libperf.a @LIBS@ @DNSLIBS@ @PTHREAD_LIBS@ -lm
|
||||
LIBOBJS = @LIBOBJS@
|
||||
LDFLAGS = @LDFLAGS@ @PTHREAD_CFLAGS@
|
||||
|
||||
PERFOBJS = datafile.o dns.o log.o net.o opt.o os.o
|
||||
|
||||
all: dnsperf resperf
|
||||
|
||||
libperf.a: ${PERFOBJS}
|
||||
${AR} ${ARFLAGS} $@ ${PERFOBJS}
|
||||
${RANLIB} $@
|
||||
|
||||
dnsperf: dnsperf.o libperf.a $(LIBOBJS)
|
||||
$(CC) $(LDFLAGS) dnsperf.o $(LIBOBJS) $(LIBS) -o dnsperf
|
||||
|
||||
resperf: resperf.o libperf.a $(LIBOBJS)
|
||||
$(CC) $(LDFLAGS) resperf.o $(LIBOBJS) $(LIBS) -o resperf
|
||||
|
||||
.c.o:
|
||||
$(CC) $(CFLAGS) -c $<
|
||||
|
||||
installdirs:
|
||||
mkdir -p ${DESTDIR}${bindir}
|
||||
mkdir -p ${DESTDIR}${mandir}/man1
|
||||
|
||||
install: all installdirs
|
||||
${INSTALL_PROGRAM} dnsperf ${DESTDIR}${bindir}
|
||||
${INSTALL_PROGRAM} resperf ${DESTDIR}${bindir}
|
||||
${INSTALL_PROGRAM} resperf-report ${DESTDIR}${bindir}
|
||||
${INSTALL_DATA} dnsperf.1 ${DESTDIR}${mandir}/man1
|
||||
${INSTALL_DATA} resperf.1 ${DESTDIR}${mandir}/man1
|
||||
|
||||
clean:
|
||||
rm -f *.o dnsperf resperf libperf.a
|
||||
|
||||
distclean: clean
|
||||
rm -f config.log
|
||||
rm -f config.cache
|
||||
rm -f config.status
|
||||
rm -f Makefile
|
||||
@@ -1,21 +0,0 @@
|
||||
This is dnsperf, a collection of DNS server performance testing tools.
|
||||
For more information, see the dnsperf(1) and resperf(1) man pages.
|
||||
|
||||
To configure, compile, and install these programs, follow these steps.
|
||||
|
||||
1. Make sure that BIND 9 (9.4.0 or greater) is installed, including libraries
|
||||
and header files, and that the isc-config.sh program distributed with BIND
|
||||
is in your path.
|
||||
|
||||
Note: many versions of bind do not correctly install the <isc/hmacsha.h>
|
||||
header file, so if the compilation fails, obtain this file from the BIND
|
||||
source distribution, and install it in the appropriate place.
|
||||
|
||||
2. Run "sh configure" to configure the software. Most standard configure
|
||||
options are supported.
|
||||
|
||||
3. Run "make" to build dnsperf and resperf
|
||||
|
||||
4. Run "make install" to install dnsperf and resperf.
|
||||
|
||||
Additional software is available in the contrib/ directory.
|
||||
@@ -1,183 +0,0 @@
|
||||
Nominum dnsperf 2.1.0.0
|
||||
Release Notes
|
||||
************************
|
||||
|
||||
December 15, 2015
|
||||
|
||||
In addition to various bug fixes, the following new capabilities
|
||||
were added in this release:
|
||||
|
||||
- The -C option was added to resperf. This option enables the local
|
||||
server to act as multiple clients. By default, the local server
|
||||
acts as a single client.
|
||||
|
||||
- the -T option was added to dnsperf. This option separates the
|
||||
number of clients from the number of threads and allows more
|
||||
clients to be simulated effectively. Note that using this option
|
||||
impacts CPU and memory, so we recommend limiting the number of
|
||||
threads.
|
||||
|
||||
|
||||
-----------------------
|
||||
Nominum dnsperf 2.0.0.0
|
||||
March 1, 2012
|
||||
|
||||
In the dnsperf command, the following changes occurred:
|
||||
|
||||
- The socket buffer size is no longer set to 32 kilobytes by default.
|
||||
|
||||
- A new -c clients option was added to enable the server to act as
|
||||
multiple clients. Each client uses the same source IP address with a
|
||||
unique source port. Use the "clients" argument to specify the number of
|
||||
clients represented by the server. We recommend limiting the number of
|
||||
clients represented by the server because the dnsperf process uses two
|
||||
threads for each client (one thread for sent packets and one for
|
||||
received packets), which impacts CPU and memory.
|
||||
|
||||
- Example query files are no longer included with the dnsperf program.
|
||||
Nominum provides a sample query file that is available for download at:
|
||||
ftp://ftp.nominum.com/pub/nominum/dnsperf/data/
|
||||
|
||||
- Latency reporting improved. When the -v (verbose mode) option is
|
||||
configured with the dnsperf command, the command output now includes
|
||||
latency measurements and the DNS RCODE of each response. This enables
|
||||
users to create their own latency graphs.
|
||||
|
||||
- Performance was enhanced on modern operating systems so that faster
|
||||
name servers can be tested.
|
||||
|
||||
- The dnsperf command output is enhanced to display more information in a
|
||||
compact format.
|
||||
|
||||
The following options were removed from the dnsperf command:
|
||||
|
||||
- The -A option for displaying command line arguments passed to the
|
||||
dnsperf tool in the final statistics output. Now, the dnsperf command
|
||||
output always displays command line arguments.
|
||||
|
||||
- The -T option for printing a histogram showing response latency after
|
||||
completing a test run. Now, the -v option enables users to include
|
||||
latency measurements in the dnsperf command output.
|
||||
|
||||
- The -H option for configuring the number of buckets for which response
|
||||
latency is displayed. Now, the -v option enables users to include
|
||||
latency measurements in the dnsperf command output.
|
||||
|
||||
- The -1 option for configuring the dnsperf tool to run through the input
|
||||
file exactly one time. (Now, you use the -n 1 option to configure the
|
||||
dnsperf tool to run through the input file one time.)
|
||||
|
||||
- The -c option for including the number of responses received (for
|
||||
each DNS RCODE) in the final statistics output. Now, DNS RCODE responses
|
||||
are always reported.
|
||||
|
||||
In the resperf command, the following changes occurred:
|
||||
|
||||
- The socket buffer size is no longer set to 32 kilobytes by default.
|
||||
|
||||
- The -A option, which displayed command line arguments passed to the
|
||||
resperf tool in the final statistics output, was removed. Now, the
|
||||
resperf command output always displays command line arguments.
|
||||
|
||||
|
||||
-----------------------
|
||||
Nominum dnsperf 1.0.2.0
|
||||
December 22, 2011
|
||||
|
||||
This release adds support for RHEL6-64 and for Solaris 10 x86-64.
|
||||
|
||||
Some new configuration options have been added. You can now specify:
|
||||
|
||||
- the local port from which to send requests
|
||||
- the local address from which to send requests
|
||||
- the maximum number of runs through the input file, up
|
||||
to the timeout limit.
|
||||
- when using TSIG, algorithms other than hmac-md5 can be used.
|
||||
|
||||
One default has been changed:
|
||||
|
||||
- The maximum number of outstanding requests now defaults
|
||||
to 100.
|
||||
|
||||
A new example query file for IPv6, queryfile-example-ipv6, is now
|
||||
included with the distribution.
|
||||
|
||||
|
||||
-----------------------
|
||||
Nominum dnsperf 1.0.1.0
|
||||
January 10, 2008
|
||||
|
||||
This release makes binary builds of dnsperf available in addition to
|
||||
the source code version previously released.
|
||||
|
||||
This release of dnsperf includes a sample query file containing
|
||||
100,000 queries to help with performance testing. This query file is
|
||||
useful for checking latencies or a continuous dnsperf run. In the
|
||||
binary distribution, this file is found at:
|
||||
|
||||
/usr/local/nom/examples/dnsperf/queryfile-example-100thousand
|
||||
|
||||
In the source distribution, it is at:
|
||||
|
||||
./examples/queryfile-example-100thousand
|
||||
|
||||
where "." is the directory made by extracting the source tarball.
|
||||
|
||||
Nominum recommends using a query file with at least 3 million queries
|
||||
for a full resperf run as described in the man page; we make such a
|
||||
file available for download at:
|
||||
|
||||
ftp://ftp.nominum.com/pub/nominum/dnsperf/data/queryfile-example-3million.gz
|
||||
|
||||
The following fix is included in the source distribution:
|
||||
|
||||
- 20996: makefile.in does not allow overriding mandir
|
||||
|
||||
The --mandir argument to configure, which allows the user to
|
||||
specify the location man pages are installed, was incorrectly
|
||||
ignored.
|
||||
|
||||
"queryparse" is a contributed program available in the source
|
||||
distribution of dnsperf. It can be found at contrib/queryparse/.
|
||||
The following changes were made to that program:
|
||||
|
||||
- 19717: contrib/queryparse includes outgoing queries
|
||||
|
||||
The queryparse script had no way of distinguishing between incoming
|
||||
queries and outgoing queries when applied to a traffic trace from a
|
||||
caching server. This was addressed by adding a new flag (-r) that,
|
||||
when included in the command line, will keep queries with
|
||||
RD=0. Otherwise, it will default to discarding them.
|
||||
|
||||
- The ability to parse responses instead of queries was added.
|
||||
|
||||
- A check was added to avoid short packets.
|
||||
|
||||
- Logic was added to detect link type and correctly set the initial
|
||||
offset to handle both Ethernet and Cisco HDLC frames.
|
||||
|
||||
- Queryparse now uses pcapy instead of the btk python libcap module.
|
||||
|
||||
Note that announcements of new releases of dnsperf are sent to the
|
||||
mailing list: dnsperf-announce@nominum.com. To be added to the
|
||||
mailing list, send a message to dnsperf-announce-request@nominum.com
|
||||
with "subscribe" as the subject.
|
||||
|
||||
Known Issues:
|
||||
|
||||
- None.
|
||||
|
||||
-----------------------
|
||||
Nominum dnsperf 1.0.0.1
|
||||
December 21, 2006
|
||||
|
||||
This release addresses the following issue in the dnsperf program:
|
||||
|
||||
- 18838/18782: dnsperf slow down issue
|
||||
|
||||
Because of an error in how timeout checking was being done, queries
|
||||
were rarely timing out, so the number of valid queries in flight kept
|
||||
dropping. This error has been corrected.
|
||||
|
||||
|
||||
|
||||
Vendored
-2
@@ -1,2 +0,0 @@
|
||||
sinclude(./acx_pthread.m4)dnl
|
||||
|
||||
@@ -1,242 +0,0 @@
|
||||
dnl @synopsis ACX_PTHREAD([ACTION-IF-FOUND[, ACTION-IF-NOT-FOUND]])
|
||||
dnl
|
||||
dnl @summary figure out how to build C programs using POSIX threads
|
||||
dnl
|
||||
dnl This macro figures out how to build C programs using POSIX threads.
|
||||
dnl It sets the PTHREAD_LIBS output variable to the threads library and
|
||||
dnl linker flags, and the PTHREAD_CFLAGS output variable to any special
|
||||
dnl C compiler flags that are needed. (The user can also force certain
|
||||
dnl compiler flags/libs to be tested by setting these environment
|
||||
dnl variables.)
|
||||
dnl
|
||||
dnl Also sets PTHREAD_CC to any special C compiler that is needed for
|
||||
dnl multi-threaded programs (defaults to the value of CC otherwise).
|
||||
dnl (This is necessary on AIX to use the special cc_r compiler alias.)
|
||||
dnl
|
||||
dnl NOTE: You are assumed to not only compile your program with these
|
||||
dnl flags, but also link it with them as well. e.g. you should link
|
||||
dnl with $PTHREAD_CC $CFLAGS $PTHREAD_CFLAGS $LDFLAGS ... $PTHREAD_LIBS
|
||||
dnl $LIBS
|
||||
dnl
|
||||
dnl If you are only building threads programs, you may wish to use
|
||||
dnl these variables in your default LIBS, CFLAGS, and CC:
|
||||
dnl
|
||||
dnl LIBS="$PTHREAD_LIBS $LIBS"
|
||||
dnl CFLAGS="$CFLAGS $PTHREAD_CFLAGS"
|
||||
dnl CC="$PTHREAD_CC"
|
||||
dnl
|
||||
dnl In addition, if the PTHREAD_CREATE_JOINABLE thread-attribute
|
||||
dnl constant has a nonstandard name, defines PTHREAD_CREATE_JOINABLE to
|
||||
dnl that name (e.g. PTHREAD_CREATE_UNDETACHED on AIX).
|
||||
dnl
|
||||
dnl ACTION-IF-FOUND is a list of shell commands to run if a threads
|
||||
dnl library is found, and ACTION-IF-NOT-FOUND is a list of commands to
|
||||
dnl run it if it is not found. If ACTION-IF-FOUND is not specified, the
|
||||
dnl default action will define HAVE_PTHREAD.
|
||||
dnl
|
||||
dnl Please let the authors know if this macro fails on any platform, or
|
||||
dnl if you have any other suggestions or comments. This macro was based
|
||||
dnl on work by SGJ on autoconf scripts for FFTW (www.fftw.org) (with
|
||||
dnl help from M. Frigo), as well as ac_pthread and hb_pthread macros
|
||||
dnl posted by Alejandro Forero Cuervo to the autoconf macro repository.
|
||||
dnl We are also grateful for the helpful feedback of numerous users.
|
||||
dnl
|
||||
dnl @category InstalledPackages
|
||||
dnl @author Steven G. Johnson <stevenj@alum.mit.edu>
|
||||
dnl @version 2006-05-29
|
||||
dnl @license GPLWithACException
|
||||
|
||||
AC_DEFUN([ACX_PTHREAD], [
|
||||
AC_REQUIRE([AC_CANONICAL_HOST])
|
||||
AC_LANG_SAVE
|
||||
AC_LANG_C
|
||||
acx_pthread_ok=no
|
||||
|
||||
# We used to check for pthread.h first, but this fails if pthread.h
|
||||
# requires special compiler flags (e.g. on True64 or Sequent).
|
||||
# It gets checked for in the link test anyway.
|
||||
|
||||
# First of all, check if the user has set any of the PTHREAD_LIBS,
|
||||
# etcetera environment variables, and if threads linking works using
|
||||
# them:
|
||||
if test x"$PTHREAD_LIBS$PTHREAD_CFLAGS" != x; then
|
||||
save_CFLAGS="$CFLAGS"
|
||||
CFLAGS="$CFLAGS $PTHREAD_CFLAGS"
|
||||
save_LIBS="$LIBS"
|
||||
LIBS="$PTHREAD_LIBS $LIBS"
|
||||
AC_MSG_CHECKING([for pthread_join in LIBS=$PTHREAD_LIBS with CFLAGS=$PTHREAD_CFLAGS])
|
||||
AC_TRY_LINK_FUNC(pthread_join, acx_pthread_ok=yes)
|
||||
AC_MSG_RESULT($acx_pthread_ok)
|
||||
if test x"$acx_pthread_ok" = xno; then
|
||||
PTHREAD_LIBS=""
|
||||
PTHREAD_CFLAGS=""
|
||||
fi
|
||||
LIBS="$save_LIBS"
|
||||
CFLAGS="$save_CFLAGS"
|
||||
fi
|
||||
|
||||
# We must check for the threads library under a number of different
|
||||
# names; the ordering is very important because some systems
|
||||
# (e.g. DEC) have both -lpthread and -lpthreads, where one of the
|
||||
# libraries is broken (non-POSIX).
|
||||
|
||||
# Create a list of thread flags to try. Items starting with a "-" are
|
||||
# C compiler flags, and other items are library names, except for "none"
|
||||
# which indicates that we try without any flags at all, and "pthread-config"
|
||||
# which is a program returning the flags for the Pth emulation library.
|
||||
|
||||
acx_pthread_flags="pthreads none -Kthread -kthread lthread -pthread -pthreads -mthreads pthread --thread-safe -mt pthread-config"
|
||||
|
||||
# The ordering *is* (sometimes) important. Some notes on the
|
||||
# individual items follow:
|
||||
|
||||
# pthreads: AIX (must check this before -lpthread)
|
||||
# none: in case threads are in libc; should be tried before -Kthread and
|
||||
# other compiler flags to prevent continual compiler warnings
|
||||
# -Kthread: Sequent (threads in libc, but -Kthread needed for pthread.h)
|
||||
# -kthread: FreeBSD kernel threads (preferred to -pthread since SMP-able)
|
||||
# lthread: LinuxThreads port on FreeBSD (also preferred to -pthread)
|
||||
# -pthread: Linux/gcc (kernel threads), BSD/gcc (userland threads)
|
||||
# -pthreads: Solaris/gcc
|
||||
# -mthreads: Mingw32/gcc, Lynx/gcc
|
||||
# -mt: Sun Workshop C (may only link SunOS threads [-lthread], but it
|
||||
# doesn't hurt to check since this sometimes defines pthreads too;
|
||||
# also defines -D_REENTRANT)
|
||||
# ... -mt is also the pthreads flag for HP/aCC
|
||||
# pthread: Linux, etcetera
|
||||
# --thread-safe: KAI C++
|
||||
# pthread-config: use pthread-config program (for GNU Pth library)
|
||||
|
||||
case "${host_cpu}-${host_os}" in
|
||||
*solaris*)
|
||||
|
||||
# On Solaris (at least, for some versions), libc contains stubbed
|
||||
# (non-functional) versions of the pthreads routines, so link-based
|
||||
# tests will erroneously succeed. (We need to link with -pthreads/-mt/
|
||||
# -lpthread.) (The stubs are missing pthread_cleanup_push, or rather
|
||||
# a function called by this macro, so we could check for that, but
|
||||
# who knows whether they'll stub that too in a future libc.) So,
|
||||
# we'll just look for -pthreads and -lpthread first:
|
||||
|
||||
acx_pthread_flags="-pthreads pthread -mt -pthread $acx_pthread_flags"
|
||||
;;
|
||||
esac
|
||||
|
||||
if test x"$acx_pthread_ok" = xno; then
|
||||
for flag in $acx_pthread_flags; do
|
||||
|
||||
case $flag in
|
||||
none)
|
||||
AC_MSG_CHECKING([whether pthreads work without any flags])
|
||||
;;
|
||||
|
||||
-*)
|
||||
AC_MSG_CHECKING([whether pthreads work with $flag])
|
||||
PTHREAD_CFLAGS="$flag"
|
||||
;;
|
||||
|
||||
pthread-config)
|
||||
AC_CHECK_PROG(acx_pthread_config, pthread-config, yes, no)
|
||||
if test x"$acx_pthread_config" = xno; then continue; fi
|
||||
PTHREAD_CFLAGS="`pthread-config --cflags`"
|
||||
PTHREAD_LIBS="`pthread-config --ldflags` `pthread-config --libs`"
|
||||
;;
|
||||
|
||||
*)
|
||||
AC_MSG_CHECKING([for the pthreads library -l$flag])
|
||||
PTHREAD_LIBS="-l$flag"
|
||||
;;
|
||||
esac
|
||||
|
||||
save_LIBS="$LIBS"
|
||||
save_CFLAGS="$CFLAGS"
|
||||
LIBS="$PTHREAD_LIBS $LIBS"
|
||||
CFLAGS="$CFLAGS $PTHREAD_CFLAGS"
|
||||
|
||||
# Check for various functions. We must include pthread.h,
|
||||
# since some functions may be macros. (On the Sequent, we
|
||||
# need a special flag -Kthread to make this header compile.)
|
||||
# We check for pthread_join because it is in -lpthread on IRIX
|
||||
# while pthread_create is in libc. We check for pthread_attr_init
|
||||
# due to DEC craziness with -lpthreads. We check for
|
||||
# pthread_cleanup_push because it is one of the few pthread
|
||||
# functions on Solaris that doesn't have a non-functional libc stub.
|
||||
# We try pthread_create on general principles.
|
||||
AC_TRY_LINK([#include <pthread.h>],
|
||||
[pthread_t th; pthread_join(th, 0);
|
||||
pthread_attr_init(0); pthread_cleanup_push(0, 0);
|
||||
pthread_create(0,0,0,0); pthread_cleanup_pop(0); ],
|
||||
[acx_pthread_ok=yes])
|
||||
|
||||
LIBS="$save_LIBS"
|
||||
CFLAGS="$save_CFLAGS"
|
||||
|
||||
AC_MSG_RESULT($acx_pthread_ok)
|
||||
if test "x$acx_pthread_ok" = xyes; then
|
||||
break;
|
||||
fi
|
||||
|
||||
PTHREAD_LIBS=""
|
||||
PTHREAD_CFLAGS=""
|
||||
done
|
||||
fi
|
||||
|
||||
# Various other checks:
|
||||
if test "x$acx_pthread_ok" = xyes; then
|
||||
save_LIBS="$LIBS"
|
||||
LIBS="$PTHREAD_LIBS $LIBS"
|
||||
save_CFLAGS="$CFLAGS"
|
||||
CFLAGS="$CFLAGS $PTHREAD_CFLAGS"
|
||||
|
||||
# Detect AIX lossage: JOINABLE attribute is called UNDETACHED.
|
||||
AC_MSG_CHECKING([for joinable pthread attribute])
|
||||
attr_name=unknown
|
||||
for attr in PTHREAD_CREATE_JOINABLE PTHREAD_CREATE_UNDETACHED; do
|
||||
AC_TRY_LINK([#include <pthread.h>], [int attr=$attr; return attr;],
|
||||
[attr_name=$attr; break])
|
||||
done
|
||||
AC_MSG_RESULT($attr_name)
|
||||
if test "$attr_name" != PTHREAD_CREATE_JOINABLE; then
|
||||
AC_DEFINE_UNQUOTED(PTHREAD_CREATE_JOINABLE, $attr_name,
|
||||
[Define to necessary symbol if this constant
|
||||
uses a non-standard name on your system.])
|
||||
fi
|
||||
|
||||
AC_MSG_CHECKING([if more special flags are required for pthreads])
|
||||
flag=no
|
||||
case "${host_cpu}-${host_os}" in
|
||||
*-aix* | *-freebsd* | *-darwin*) flag="-D_THREAD_SAFE";;
|
||||
*solaris* | *-osf* | *-hpux*) flag="-D_REENTRANT";;
|
||||
esac
|
||||
AC_MSG_RESULT(${flag})
|
||||
if test "x$flag" != xno; then
|
||||
PTHREAD_CFLAGS="$flag $PTHREAD_CFLAGS"
|
||||
fi
|
||||
|
||||
LIBS="$save_LIBS"
|
||||
CFLAGS="$save_CFLAGS"
|
||||
|
||||
# More AIX lossage: must compile with xlc_r or cc_r
|
||||
if test x"$GCC" != xyes; then
|
||||
AC_CHECK_PROGS(PTHREAD_CC, xlc_r cc_r, ${CC})
|
||||
else
|
||||
PTHREAD_CC=$CC
|
||||
fi
|
||||
else
|
||||
PTHREAD_CC="$CC"
|
||||
fi
|
||||
|
||||
AC_SUBST(PTHREAD_LIBS)
|
||||
AC_SUBST(PTHREAD_CFLAGS)
|
||||
AC_SUBST(PTHREAD_CC)
|
||||
|
||||
# Finally, execute ACTION-IF-FOUND/ACTION-IF-NOT-FOUND:
|
||||
if test x"$acx_pthread_ok" = xyes; then
|
||||
ifelse([$1],,AC_DEFINE(HAVE_PTHREAD,1,[Define if you have POSIX threads libraries and header files.]),[$1])
|
||||
:
|
||||
else
|
||||
acx_pthread_ok=no
|
||||
$2
|
||||
fi
|
||||
AC_LANG_RESTORE
|
||||
])dnl ACX_PTHREAD
|
||||
-1447
File diff suppressed because it is too large
Load Diff
Vendored
-1555
File diff suppressed because it is too large
Load Diff
Vendored
-4672
File diff suppressed because it is too large
Load Diff
@@ -1,85 +0,0 @@
|
||||
#
|
||||
# Copyright (C) 2000, 2001 Nominum, Inc.
|
||||
#
|
||||
# Permission to use, copy, modify, and distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
# THE SOFTWARE IS PROVIDED "AS IS" AND INTERNET SOFTWARE CONSORTIUM
|
||||
# DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL
|
||||
# IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL
|
||||
# INTERNET SOFTWARE CONSORTIUM BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING
|
||||
# FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT,
|
||||
# NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION
|
||||
# WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
||||
#
|
||||
|
||||
AC_INIT(dnsperf.c)
|
||||
|
||||
AC_PREREQ(2.13)
|
||||
|
||||
AC_PROG_CC
|
||||
AC_PROG_INSTALL
|
||||
AC_PROG_RANLIB
|
||||
|
||||
AC_C_INLINE
|
||||
|
||||
AC_DEFUN(AC_TYPE_SOCKLEN_T,
|
||||
[AC_CACHE_CHECK([for socklen_t], ac_cv_type_socklen_t,
|
||||
[
|
||||
AC_TRY_COMPILE(
|
||||
[#include <sys/types.h>
|
||||
#include <sys/socket.h>],
|
||||
[socklen_t len = 42; return len;],
|
||||
ac_cv_type_socklen_t=yes,
|
||||
ac_cv_type_socklen_t=no)
|
||||
])
|
||||
if test $ac_cv_type_socklen_t != yes; then
|
||||
AC_DEFINE(socklen_t, int)
|
||||
fi
|
||||
])
|
||||
|
||||
AC_DEFUN(AC_SA_LEN,
|
||||
[AC_CACHE_CHECK([for sa_len], ac_cv_sa_len,
|
||||
[
|
||||
AC_TRY_COMPILE(
|
||||
[#include <sys/types.h>
|
||||
#include <sys/socket.h>],
|
||||
[struct sockaddr sa; sa.sa_len = 0;],
|
||||
ac_cv_sa_len=yes,
|
||||
ac_cv_sa_len=no)
|
||||
])
|
||||
if test $ac_cv_sa_len = yes; then
|
||||
AC_DEFINE(HAVE_SA_LEN)
|
||||
fi
|
||||
])
|
||||
|
||||
AC_CHECK_LIB(socket, socket)
|
||||
AC_CHECK_LIB(nsl, inet_ntoa)
|
||||
|
||||
AC_ARG_WITH(bind,
|
||||
[ --with-bind=[[PATH]] Specify ISC BIND 9 prefix path],
|
||||
use_bind="$withval", use_bind="yes")
|
||||
|
||||
AC_MSG_CHECKING(for BIND 9 libraries)
|
||||
if test $use_bind = no; then
|
||||
AC_MSG_ERROR(BIND 9 libraries must be installed)
|
||||
elif test $use_bind = yes; then
|
||||
bindpath="$PATH"
|
||||
else
|
||||
bindpath="$withval/bin"
|
||||
fi
|
||||
AC_PATH_PROG(ac_cv_isc_config, [isc-config.sh], "no", [$bindpath])
|
||||
if test "$ac_cv_isc_config" = "no"; then
|
||||
AC_MSG_ERROR(BIND 9 libraries must be installed)
|
||||
fi
|
||||
AC_SUBST(DNSLIBS, "`$ac_cv_isc_config --libs dns bind9`")
|
||||
AC_SUBST(DNSCFLAGS, "`$ac_cv_isc_config --cflags dns bind9`")
|
||||
|
||||
AC_TYPE_SOCKLEN_T
|
||||
AC_SA_LEN
|
||||
|
||||
ACX_PTHREAD
|
||||
|
||||
AC_OUTPUT(Makefile)
|
||||
@@ -1,48 +0,0 @@
|
||||
|
||||
Installation
|
||||
------------
|
||||
|
||||
Queryparse requires the dnspython and pcapy python modules. Pcapy depends
|
||||
upon the pcap library.
|
||||
|
||||
Libpcap may be obtained from http://www.tcpdump.org/
|
||||
Dnspython may be obtained from http://www.dnspython.org/
|
||||
Pcapy may be obtained from http://oss.coresecurity.com/projects/pcapy.html
|
||||
|
||||
Ensure queryparse is somewhere in your path.
|
||||
|
||||
|
||||
Usage
|
||||
-----
|
||||
queryparse -i <input file> -o <output file>
|
||||
|
||||
-i <input file>: the tcpdump file that will be parsed to locate DNS
|
||||
queries.
|
||||
|
||||
-o <output file>: the file to which you wish to save the queries parsed
|
||||
from <input file>. When complete, this file is suitable
|
||||
for use as input to dnsperf.
|
||||
|
||||
-r Keep packets whose RD flag is not set.
|
||||
Use this flag when parsing captures from authoritative
|
||||
servers. When parsing captures from caching servers,
|
||||
do not use this flag unless you also want to parse the
|
||||
queries the server itself is sending.
|
||||
|
||||
-R Parse response packets (QR=1), instead of query packets
|
||||
(QR=0).
|
||||
|
||||
|
||||
Queryparse takes as input a packet capture file as created by tcpdump (or any
|
||||
other program that can save data in pcap format). It parses every UDP packet,
|
||||
looking for DNS queries. When it finds a potential query, it makes every
|
||||
effort to parse it as a valid query.
|
||||
|
||||
Once queryparse has finished, it will print a set of statistics regarding
|
||||
the capture file to STDOUT.
|
||||
|
||||
|
||||
NOTE: Currently, queryparse will correctly handle packets contained in either
|
||||
Ethernet frames or Cisco HDLC frames. It is not guaranteed to work with other
|
||||
framing formats.
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user