Compare commits

..
Author SHA1 Message Date
Evan Hunt 3878c145c9 experiment 2025-02-26 16:01:01 -08:00
Evan Hunt 4acbfbc2d1 retry fix 2025-02-26 16:01:01 -08:00
Evan Hunt 1ef9a32de7 slight refactoring in validated()
fix some minor code redundancies.
2025-02-26 15:28:57 -08:00
Evan Hunt 6c738fe323 simplify dns_ncache_add()
there's no longer any reason to have both dns_ncache_add() and
dns_ncache_addoptout().
2025-02-26 15:28:57 -08:00
221 changed files with 3818 additions and 4894 deletions
+91 -126
View File
@@ -56,16 +56,6 @@ variables:
# Some jobs may clean up the build artifacts unless this is set to 0. # Some jobs may clean up the build artifacts unless this is set to 0.
CLEAN_BUILD_ARTIFACTS_ON_SUCCESS: 1 CLEAN_BUILD_ARTIFACTS_ON_SUCCESS: 1
# DNS Shotgun performance testing defaults
SHOTGUN_ROUNDS: 1
SHOTGUN_DURATION: 120
# allow unlimited improvements against baseline
SHOTGUN_EVAL_THRESHOLD_CPU_MIN: '-inf'
SHOTGUN_EVAL_THRESHOLD_MEMORY_MIN: '-inf'
SHOTGUN_EVAL_THRESHOLD_RCODE_MAX: '+inf'
SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_MIN: '-inf'
SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_DRIFT_MIN: '-inf'
default: default:
# Allow all running CI jobs to be automatically canceled when a new # Allow all running CI jobs to be automatically canceled when a new
# version of a branch is pushed. # version of a branch is pushed.
@@ -117,55 +107,16 @@ stages:
- runner-manager - runner-manager
- aarch64 - aarch64
.freebsd-autoscaler-13-amd64-tags: &freebsd_autoscaler_13_amd64_tags # Autoscaling GitLab Runner on AWS EC2 (FreeBSD)
.freebsd-stress-amd64: &freebsd_stress_amd64
tags: tags:
- amd64 - bsd-stress-test
- autoscaler
- aws - aws
- bsd-stress-test-1 - autoscaler
- shell - shell
- stress-test - stress-test
.freebsd-autoscaler-14-amd64-tags: &freebsd_autoscaler_14_amd64_tags
tags:
- amd64 - amd64
- autoscaler
- aws
- bsd-stress-test-2
- shell
- stress-test
.freebsd-autoscaler-amd64: &freebsd_autoscaler_amd64
variables:
CC: clang
CFLAGS: "${CFLAGS_COMMON} -Og"
# Even though there's only one job per runtime environment, the GitLab
# "instance" executor insists on cloning the Git repository to a path that
# contains a variable number from zero to the "maximum concurrent instances
# count" allowed on the GitLab Runner. See the "0" directory in this
# example path: /home/ec2-user/builds/t1_4FZzvz/0/isc-projects/bind9/.git/.
#
# This is not a problem for isolated jobs like "stress" tests that depend
# on no other jobs. However, it is a problem for jobs that need other jobs'
# artifacts. For example, a system test job that has its Git repo cloned to
# the "/1/" sub-path will fail if it downloads build job artifacts that
# have ./configure output files with "/0/" in its sub-path recorded.
GIT_CLONE_PATH: "/home/ec2-user/builds/${CI_PROJECT_PATH}/"
# Use MIT Kerberos5 for BIND 9 GSS-API support because of FreeBSD Heimdal
# incompatibility; see https://bugs.freebsd.org/275241.
EXTRA_CONFIGURE: "${WITH_READLINE_EDITLINE} --with-gssapi=/usr/local/bin/krb5-config"
# Autoscaling GitLab Runner on AWS EC2 (FreeBSD 13)
.freebsd-autoscaler-13-amd64: &freebsd_autoscaler_13_amd64
<<: *freebsd_autoscaler_amd64
<<: *freebsd_autoscaler_13_amd64_tags
# Autoscaling GitLab Runner on AWS EC2 (FreeBSD 14)
.freebsd-autoscaler-14-amd64: &freebsd_autoscaler_14_amd64
<<: *freebsd_autoscaler_amd64
<<: *freebsd_autoscaler_14_amd64_tags
### Docker Image Templates ### Docker Image Templates
@@ -253,6 +204,14 @@ stages:
### QCOW2 Image Templates ### QCOW2 Image Templates
.freebsd-13-amd64: &freebsd_13_amd64_image
image: "freebsd-13.4-x86_64"
<<: *libvirt_amd64
.freebsd-14-amd64: &freebsd_14_amd64_image
image: "freebsd-14.2-x86_64"
<<: *libvirt_amd64
.openbsd-amd64: &openbsd_amd64_image .openbsd-amd64: &openbsd_amd64_image
image: "openbsd-7.6-x86_64" image: "openbsd-7.6-x86_64"
<<: *libvirt_amd64 <<: *libvirt_amd64
@@ -260,18 +219,31 @@ stages:
### Job Templates ### Job Templates
.api-pipelines-schedules-tags-triggers-web-triggering-rules: &api_pipelines_schedules_tags_triggers_web_triggering_rules .api-pipelines-schedules-tags-triggers-web-triggering-rules: &api_pipelines_schedules_tags_triggers_web_triggering_rules
rules: only:
- if: '$CI_PIPELINE_SOURCE =~ /^(api|pipeline|schedule|trigger|web)$/' - api
- if: '$CI_COMMIT_TAG != null' - pipelines
- schedules
- tags
- triggers
- web
.api-pipelines-schedules-triggers-web-triggering-rules: &api_pipelines_schedules_triggers_web_triggering_rules .api-pipelines-schedules-triggers-web-triggering-rules: &api_pipelines_schedules_triggers_web_triggering_rules
rules: only:
- if: '$CI_PIPELINE_SOURCE =~ /^(api|pipeline|schedule|trigger|web)$/' - api
- pipelines
- schedules
- triggers
- web
.default-triggering-rules: &default_triggering_rules .default-triggering-rules: &default_triggering_rules
rules: only:
- if: '$CI_PIPELINE_SOURCE =~ /^(api|merge_request_event|pipeline|schedule|trigger|web)$/' - api
- if: '$CI_COMMIT_TAG != null' - merge_requests
- pipelines
- schedules
- tags
- triggers
- web
.precheck: &precheck_job .precheck: &precheck_job
<<: *default_triggering_rules <<: *default_triggering_rules
@@ -371,41 +343,18 @@ stages:
.shotgun: &shotgun_job .shotgun: &shotgun_job
<<: *base_image <<: *base_image
<<: *api_pipelines_schedules_tags_triggers_web_triggering_rules
stage: performance stage: performance
rules:
- &shotgun_rule_mr
if: '$CI_MERGE_REQUEST_DIFF_BASE_SHA != null'
variables:
BASELINE: '$CI_MERGE_REQUEST_DIFF_BASE_SHA'
- &shotgun_rule_tag
if: '$CI_COMMIT_TAG != null'
variables:
SHOTGUN_ROUNDS: 3
- &shotgun_rule_other
if: '$CI_PIPELINE_SOURCE =~ /^(api|pipeline|schedule|trigger|web)$/'
# when using data from a single run, the overall instability of the results
# causes quite high false positive rate, rerun the test to attemp to reduce those
retry: 1
script: script:
- if [ -z "$BASELINE" ]; then export BASELINE=$BIND_BASELINE_VERSION; fi # this dotenv variable can't be set in the rules section, because rules are evaluated before any jobs run - if [ -z "$CI_COMMIT_TAG" ]; then export SHOTGUN_ROUNDS=1; else export SHOTGUN_ROUNDS=3; fi
- PIPELINE_ID=$(curl -s -X POST --fail - PIPELINE_ID=$(curl -s -X POST --fail
-F "token=$CI_JOB_TOKEN" -F "token=$CI_JOB_TOKEN"
-F ref=main -F ref=main
-F "variables[SHOTGUN_TEST_VERSION]=['$CI_COMMIT_REF_NAME', '$BASELINE']" -F "variables[SHOTGUN_TEST_VERSION]=['$CI_COMMIT_REF_NAME', '$BIND_BASELINE_VERSION']"
-F "variables[SHOTGUN_DURATION]=300" -F "variables[SHOTGUN_DURATION]=300"
-F "variables[SHOTGUN_ROUNDS]=$SHOTGUN_ROUNDS" -F "variables[SHOTGUN_ROUNDS]=$SHOTGUN_ROUNDS"
-F "variables[SHOTGUN_TRAFFIC_MULTIPLIER]=$SHOTGUN_TRAFFIC_MULTIPLIER" -F "variables[SHOTGUN_TRAFFIC_MULTIPLIER]=$SHOTGUN_TRAFFIC_MULTIPLIER"
-F "variables[SHOTGUN_SCENARIO]=$SHOTGUN_SCENARIO" -F "variables[SHOTGUN_SCENARIO]=$SHOTGUN_SCENARIO"
-F "variables[SHOTGUN_EVAL_THRESHOLD_CPU_MIN]=$SHOTGUN_EVAL_THRESHOLD_CPU_MIN"
-F "variables[SHOTGUN_EVAL_THRESHOLD_CPU_MAX]=$SHOTGUN_EVAL_THRESHOLD_CPU_MAX"
-F "variables[SHOTGUN_EVAL_THRESHOLD_MEMORY_MIN]=$SHOTGUN_EVAL_THRESHOLD_MEMORY_MIN"
-F "variables[SHOTGUN_EVAL_THRESHOLD_MEMORY_MAX]=$SHOTGUN_EVAL_THRESHOLD_MEMORY_MAX"
-F "variables[SHOTGUN_EVAL_THRESHOLD_RCODE_MIN]=$SHOTGUN_EVAL_THRESHOLD_RCODE_MIN"
-F "variables[SHOTGUN_EVAL_THRESHOLD_RCODE_MAX]=$SHOTGUN_EVAL_THRESHOLD_RCODE_MAX"
-F "variables[SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_MIN]=$SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_MIN"
-F "variables[SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_MAX]=$SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_MAX"
-F "variables[SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_DRIFT_MIN]=$SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_DRIFT_MIN"
-F "variables[SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_DRIFT_MAX]=$SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_DRIFT_MAX"
https://gitlab.isc.org/api/v4/projects/188/trigger/pipeline | jq .id) https://gitlab.isc.org/api/v4/projects/188/trigger/pipeline | jq .id)
- util/ci-wait-shotgun.py $PIPELINE_ID - util/ci-wait-shotgun.py $PIPELINE_ID
needs: needs:
@@ -562,8 +511,6 @@ misc:
- if git grep SYSTEMTESTTOP -- ':!.gitlab-ci.yml'; then echo 'Please use relative paths instead of $SYSTEMTESTTOP.'; exit 1; fi - if git grep SYSTEMTESTTOP -- ':!.gitlab-ci.yml'; then echo 'Please use relative paths instead of $SYSTEMTESTTOP.'; exit 1; fi
- bash util/unused-headers.sh - bash util/unused-headers.sh
- bash util/xmllint-html.sh - bash util/xmllint-html.sh
# Check dangling symlinks in the repository
- if find . -xtype l | grep .; then exit 1; fi
needs: [] needs: []
artifacts: artifacts:
paths: paths:
@@ -587,7 +534,7 @@ vulture:
<<: *precheck_job <<: *precheck_job
needs: [] needs: []
script: script:
- vulture --exclude "*ans.py,conftest.py,isctest" --ignore-names "pytestmark" bin/tests/system/ - vulture --exclude "*/ans*/ans.py,conftest.py,isctest" --ignore-names "pytestmark" bin/tests/system/
ci-variables: ci-variables:
stage: precheck stage: precheck
@@ -672,8 +619,9 @@ danger:
script: script:
- pip install git+https://gitlab.isc.org/isc-projects/hazard.git - pip install git+https://gitlab.isc.org/isc-projects/hazard.git
- hazard - hazard
rules: only:
- if: '$CI_PIPELINE_SOURCE == "merge_request_event"' refs:
- merge_requests
checkbashisms: checkbashisms:
<<: *precheck_job <<: *precheck_job
@@ -1341,7 +1289,7 @@ gcc:tsan:
variables: variables:
CC: gcc CC: gcc
CFLAGS: "${CFLAGS_COMMON} -Wno-stringop-overread -ggdb -O2 -fsanitize=thread" CFLAGS: "${CFLAGS_COMMON} -Wno-stringop-overread -ggdb -O2 -fsanitize=thread"
LDFLAGS: "-fsanitize=thread -Wl,--disable-new-dtags" LDFLAGS: "-fsanitize=thread"
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig" EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig"
<<: *tsan_fedora_41_amd64_image <<: *tsan_fedora_41_amd64_image
<<: *build_job <<: *build_job
@@ -1370,8 +1318,7 @@ clang:tsan:
variables: variables:
CC: "${CLANG}" CC: "${CLANG}"
CFLAGS: "${CFLAGS_COMMON} -ggdb -O2 -fsanitize=thread" CFLAGS: "${CFLAGS_COMMON} -ggdb -O2 -fsanitize=thread"
# -Wl,--disable-new-dtags ensures that Clang creates valid TSAN reports LDFLAGS: "-fsanitize=thread"
LDFLAGS: "-fsanitize=thread -Wl,--disable-new-dtags"
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig" EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig"
system:clang:tsan: system:clang:tsan:
@@ -1450,19 +1397,27 @@ unit:clang:bookworm:amd64:
# Jobs for Clang builds on FreeBSD 13 (amd64) # Jobs for Clang builds on FreeBSD 13 (amd64)
clang:freebsd13:amd64: clang:freebsd13:amd64:
variables:
CFLAGS: "${CFLAGS_COMMON}"
# Use MIT Kerberos5 for BIND 9 GSS-API support because of FreeBSD Heimdal
# incompatibility; see https://bugs.freebsd.org/275241.
EXTRA_CONFIGURE: "${WITH_READLINE_LIBEDIT} --with-gssapi=/usr/local/bin/krb5-config"
USER: gitlab-runner
<<: *freebsd_13_amd64_image
<<: *build_job <<: *build_job
<<: *freebsd_autoscaler_13_amd64
system:clang:freebsd13:amd64: system:clang:freebsd13:amd64:
<<: *freebsd_13_amd64_image
<<: *system_test_job <<: *system_test_job
<<: *freebsd_autoscaler_13_amd64 variables:
USER: gitlab-runner
needs: needs:
- job: clang:freebsd13:amd64 - job: clang:freebsd13:amd64
artifacts: true artifacts: true
unit:clang:freebsd13:amd64: unit:clang:freebsd13:amd64:
<<: *freebsd_13_amd64_image
<<: *unit_test_job <<: *unit_test_job
<<: *freebsd_autoscaler_13_amd64
needs: needs:
- job: clang:freebsd13:amd64 - job: clang:freebsd13:amd64
artifacts: true artifacts: true
@@ -1470,19 +1425,27 @@ unit:clang:freebsd13:amd64:
# Jobs for Clang builds on FreeBSD 14 (amd64) # Jobs for Clang builds on FreeBSD 14 (amd64)
clang:freebsd14:amd64: clang:freebsd14:amd64:
variables:
CFLAGS: "${CFLAGS_COMMON}"
# Use MIT Kerberos5 for BIND 9 GSS-API support because of FreeBSD Heimdal
# incompatibility; see https://bugs.freebsd.org/275241.
EXTRA_CONFIGURE: "${WITH_READLINE_EDITLINE} --with-gssapi=/usr/local/bin/krb5-config"
USER: gitlab-runner
<<: *freebsd_14_amd64_image
<<: *build_job <<: *build_job
<<: *freebsd_autoscaler_14_amd64
system:clang:freebsd14:amd64: system:clang:freebsd14:amd64:
<<: *freebsd_14_amd64_image
<<: *system_test_job <<: *system_test_job
<<: *freebsd_autoscaler_14_amd64 variables:
USER: gitlab-runner
needs: needs:
- job: clang:freebsd14:amd64 - job: clang:freebsd14:amd64
artifacts: true artifacts: true
unit:clang:freebsd14:amd64: unit:clang:freebsd14:amd64:
<<: *freebsd_14_amd64_image
<<: *unit_test_job <<: *unit_test_job
<<: *freebsd_autoscaler_14_amd64
needs: needs:
- job: clang:freebsd14:amd64 - job: clang:freebsd14:amd64
artifacts: true artifacts: true
@@ -1531,8 +1494,8 @@ release:
artifacts: true artifacts: true
- job: docs - job: docs
artifacts: true artifacts: true
rules: only:
- if: '$CI_COMMIT_TAG != null' - tags
artifacts: artifacts:
paths: paths:
- "*-release" - "*-release"
@@ -1575,8 +1538,8 @@ sign:
needs: needs:
- job: release - job: release
artifacts: true artifacts: true
rules: only:
- if: '$CI_COMMIT_TAG != null' - tags
when: manual when: manual
allow_failure: false allow_failure: false
@@ -1628,8 +1591,10 @@ coverity:
- cov-int.tar.gz - cov-int.tar.gz
expire_in: "1 week" expire_in: "1 week"
when: on_failure when: on_failure
rules: only:
- if: '$COVERITY_SCAN_PROJECT_NAME != null && $COVERITY_SCAN_TOKEN != null' variables:
- $COVERITY_SCAN_PROJECT_NAME
- $COVERITY_SCAN_TOKEN
# Respdiff tests # Respdiff tests
@@ -1664,9 +1629,9 @@ respdiff:tsan:
<<: *default_triggering_rules <<: *default_triggering_rules
<<: *tsan_debian_bookworm_amd64_image <<: *tsan_debian_bookworm_amd64_image
variables: variables:
CC: "${CLANG}" CC: gcc
CFLAGS: "${CFLAGS_COMMON} -ggdb -O2 -fsanitize=thread" CFLAGS: "${CFLAGS_COMMON} -Og -fsanitize=thread"
LDFLAGS: "-fsanitize=thread -Wl,--disable-new-dtags" LDFLAGS: "-fsanitize=thread"
EXTRA_CONFIGURE: "--enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig" EXTRA_CONFIGURE: "--enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig"
MAX_DISAGREEMENTS_PERCENTAGE: "0.15" MAX_DISAGREEMENTS_PERCENTAGE: "0.15"
TSAN_OPTIONS: "${TSAN_OPTIONS_DEBIAN}" TSAN_OPTIONS: "${TSAN_OPTIONS_DEBIAN}"
@@ -1691,6 +1656,9 @@ respdiff-third-party:
# Performance tests # Performance tests
# Run shotgun:udp right away, but delay other shotgun jobs sligthly in order to
# allow re-use of the built container image. Otherwise, the jobs would do the
# same builds in parallel rather than re-use the already built image.
shotgun:udp: shotgun:udp:
<<: *shotgun_job <<: *shotgun_job
variables: variables:
@@ -1701,29 +1669,25 @@ shotgun:tcp:
<<: *shotgun_job <<: *shotgun_job
variables: variables:
SHOTGUN_SCENARIO: tcp SHOTGUN_SCENARIO: tcp
SHOTGUN_TRAFFIC_MULTIPLIER: 12 SHOTGUN_TRAFFIC_MULTIPLIER: 13
when: delayed
start_in: 5 minutes
shotgun:dot: shotgun:dot:
<<: *shotgun_job <<: *shotgun_job
variables: variables:
SHOTGUN_SCENARIO: dot SHOTGUN_SCENARIO: dot
SHOTGUN_TRAFFIC_MULTIPLIER: 6 SHOTGUN_TRAFFIC_MULTIPLIER: 6
rules: &shotgun_rules_manual_mr when: delayed
- if: '$CI_MERGE_REQUEST_DIFF_BASE_SHA != null' start_in: 5 minutes
variables:
BASELINE: '$CI_MERGE_REQUEST_DIFF_BASE_SHA'
when: manual # don't run on each MR unless requested
allow_failure: true
- *shotgun_rule_tag
- *shotgun_rule_other
shotgun:doh-get: shotgun:doh-get:
<<: *shotgun_job <<: *shotgun_job
variables: variables:
SHOTGUN_SCENARIO: doh-get SHOTGUN_SCENARIO: doh-get
SHOTGUN_TRAFFIC_MULTIPLIER: 3 SHOTGUN_TRAFFIC_MULTIPLIER: 3
SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_MAX: 0.4 # bump from the default due to increased tail-end jitter when: delayed
rules: *shotgun_rules_manual_mr start_in: 5 minutes
.stress-test: &stress_test .stress-test: &stress_test
stage: performance stage: performance
@@ -1762,8 +1726,8 @@ fsck:
- git clone https://gitlab.isc.org/isc-projects/bind9.git bind9-full-clone - git clone https://gitlab.isc.org/isc-projects/bind9.git bind9-full-clone
- cd bind9-full-clone/ - cd bind9-full-clone/
- git fsck - git fsck
rules: only:
- if: '$CI_PIPELINE_SOURCE == "schedule"' - schedules
needs: [] needs: []
gcov: gcov:
@@ -1815,8 +1779,9 @@ pairwise:
- pairwise-model.txt - pairwise-model.txt
- pairwise-output.*.txt - pairwise-output.*.txt
when: on_failure when: on_failure
rules: only:
- if: '$PAIRWISE_TESTING != null' variables:
- $PAIRWISE_TESTING
.post_merge_template: &post_merge .post_merge_template: &post_merge
<<: *base_image <<: *base_image
+1 -1
View File
@@ -1 +1 @@
doc/arm/changelog.rst CHANGES
+1 -1
View File
@@ -761,7 +761,7 @@ cleanup:
} }
if (mctx != NULL) { if (mctx != NULL) {
isc_mem_detach(&mctx); isc_mem_destroy(&mctx);
} }
return result == ISC_R_SUCCESS ? 0 : 1; return result == ISC_R_SUCCESS ? 0 : 1;
+1 -1
View File
@@ -577,7 +577,7 @@ main(int argc, char **argv) {
fprintf(errout, "OK\n"); fprintf(errout, "OK\n");
} }
destroy(); destroy();
isc_mem_detach(&mctx); isc_mem_destroy(&mctx);
return (result == ISC_R_SUCCESS) ? 0 : 1; return (result == ISC_R_SUCCESS) ? 0 : 1;
} }
+1 -1
View File
@@ -290,7 +290,7 @@ options {\n\
isc_mem_stats(mctx, stderr); isc_mem_stats(mctx, stderr);
} }
isc_mem_detach(&mctx); isc_mem_destroy(&mctx);
return 0; return 0;
} }
+1 -1
View File
@@ -296,7 +296,7 @@ nsupdate -k <keyfile>\n");
isc_mem_stats(mctx, stderr); isc_mem_stats(mctx, stderr);
} }
isc_mem_detach(&mctx); isc_mem_destroy(&mctx);
return 0; return 0;
} }
+36 -2
View File
@@ -26,12 +26,16 @@
#include <unistd.h> #include <unistd.h>
#include <openssl/opensslv.h> #include <openssl/opensslv.h>
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
#include <openssl/err.h>
#include <openssl/provider.h>
#endif
#include <isc/async.h> #include <isc/async.h>
#include <isc/attributes.h> #include <isc/attributes.h>
#include <isc/base64.h> #include <isc/base64.h>
#include <isc/buffer.h> #include <isc/buffer.h>
#include <isc/crypto.h> #include <isc/fips.h>
#include <isc/hex.h> #include <isc/hex.h>
#include <isc/lib.h> #include <isc/lib.h>
#include <isc/log.h> #include <isc/log.h>
@@ -163,6 +167,10 @@ static dns_fixedname_t qfn;
/* Default trust anchors */ /* Default trust anchors */
static char anchortext[] = TRUST_ANCHORS; static char anchortext[] = TRUST_ANCHORS;
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
static OSSL_PROVIDER *fips = NULL, *base = NULL;
#endif
/* /*
* Static function prototypes * Static function prototypes
*/ */
@@ -1611,7 +1619,24 @@ preparse_args(int argc, char **argv) {
while (strpbrk(option, single_dash_opts) == &option[0]) { while (strpbrk(option, single_dash_opts) == &option[0]) {
switch (option[0]) { switch (option[0]) {
case 'F': case 'F':
if (isc_crypto_fips_enable() != ISC_R_SUCCESS) { #if OPENSSL_VERSION_NUMBER >= 0x30000000L
fips = OSSL_PROVIDER_load(NULL, "fips");
if (fips == NULL) {
ERR_clear_error();
fatal("Failed to load FIPS provider");
}
base = OSSL_PROVIDER_load(NULL, "base");
if (base == NULL) {
OSSL_PROVIDER_unload(fips);
ERR_clear_error();
fatal("Failed to load base provider");
}
#endif
/* Already in FIPS mode? */
if (isc_fips_mode()) {
break;
}
if (isc_fips_set_mode(1) != ISC_R_SUCCESS) {
fatal("setting FIPS mode failed"); fatal("setting FIPS mode failed");
} }
break; break;
@@ -2284,5 +2309,14 @@ cleanup:
isc_managers_destroy(&mctx, &loopmgr, &netmgr); isc_managers_destroy(&mctx, &loopmgr, &netmgr);
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
if (base != NULL) {
OSSL_PROVIDER_unload(base);
}
if (fips != NULL) {
OSSL_PROVIDER_unload(fips);
}
#endif
return 0; return 0;
} }
+41 -35
View File
@@ -20,8 +20,8 @@
#include <time.h> #include <time.h>
#include <isc/attributes.h> #include <isc/attributes.h>
#include <isc/crypto.h>
#include <isc/dir.h> #include <isc/dir.h>
#include <isc/fips.h>
#include <isc/lib.h> #include <isc/lib.h>
#include <isc/loop.h> #include <isc/loop.h>
#include <isc/netaddr.h> #include <isc/netaddr.h>
@@ -73,6 +73,14 @@ static bool short_form = false, printcmd = true, plusquest = false,
static uint32_t splitwidth = 0xffffffff; static uint32_t splitwidth = 0xffffffff;
#include <openssl/opensslv.h> #include <openssl/opensslv.h>
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
#include <openssl/err.h>
#include <openssl/provider.h>
#endif
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
static OSSL_PROVIDER *fips = NULL, *base = NULL;
#endif
/*% opcode text */ /*% opcode text */
static const char *const opcodetext[] = { static const char *const opcodetext[] = {
@@ -289,7 +297,6 @@ help(void) {
" form of answers - global " " form of answers - global "
"option)\n" "option)\n"
" +[no]showbadcookie (Show BADCOOKIE message)\n" " +[no]showbadcookie (Show BADCOOKIE message)\n"
" +[no]showbadvers (Show BADVERS message)\n"
" +[no]showsearch (Search with intermediate " " +[no]showsearch (Search with intermediate "
"results)\n" "results)\n"
" +[no]split=## (Split hex/base64 fields " " +[no]split=## (Split hex/base64 fields "
@@ -328,7 +335,6 @@ help(void) {
" +[no]yaml (Present the results as " " +[no]yaml (Present the results as "
"YAML)\n" "YAML)\n"
" +[no]zflag (Set Z flag in query)\n" " +[no]zflag (Set Z flag in query)\n"
" +[no]zoneversion (Request zone version)\n"
" global d-opts and servers (before host name) affect " " global d-opts and servers (before host name) affect "
"all " "all "
"queries.\n" "queries.\n"
@@ -1774,8 +1780,6 @@ plus_option(char *option, bool is_batchfile, bool *need_clone,
FULLCHECK("edns"); FULLCHECK("edns");
if (!state) { if (!state) {
lookup->edns = -1; lookup->edns = -1;
lookup->original_edns =
-1;
break; break;
} }
if (value == NULL) { if (value == NULL) {
@@ -1792,7 +1796,6 @@ plus_option(char *option, bool is_batchfile, bool *need_clone,
goto exit_or_usage; goto exit_or_usage;
} }
lookup->edns = num; lookup->edns = num;
lookup->original_edns = num;
break; break;
case 'f': case 'f':
FULLCHECK("ednsflags"); FULLCHECK("ednsflags");
@@ -2311,18 +2314,8 @@ plus_option(char *option, bool is_batchfile, bool *need_clone,
case 'w': /* showsearch */ case 'w': /* showsearch */
switch (cmd[4]) { switch (cmd[4]) {
case 'b': case 'b':
switch (cmd[7]) { FULLCHECK("showbadcookie");
case 'c': lookup->showbadcookie = state;
FULLCHECK("showbadcookie");
lookup->showbadcookie = state;
break;
case 'v':
FULLCHECK("showbadvers");
lookup->showbadvers = state;
break;
default:
goto invalid_option;
}
break; break;
case 's': case 's':
FULLCHECK("showsearch"); FULLCHECK("showsearch");
@@ -2575,22 +2568,9 @@ plus_option(char *option, bool is_batchfile, bool *need_clone,
lookup->rrcomments = -1; lookup->rrcomments = -1;
} }
break; break;
case 'z': case 'z': /* zflag */
switch (cmd[1]) { FULLCHECK("zflag");
case 'f': /* zflag */ lookup->zflag = state;
FULLCHECK("zflag");
lookup->zflag = state;
break;
case 'o': /* zoneversion */
FULLCHECK("zoneversion");
if (state && lookup->edns == -1) {
lookup->edns = DEFAULT_EDNS_VERSION;
}
lookup->zoneversion = state;
break;
default:
goto invalid_option;
}
break; break;
default: default:
invalid_option: invalid_option:
@@ -2951,7 +2931,24 @@ preparse_args(int argc, char **argv) {
debugging = true; debugging = true;
break; break;
case 'F': case 'F':
if (isc_crypto_fips_enable() != ISC_R_SUCCESS) { #if OPENSSL_VERSION_NUMBER >= 0x30000000L
fips = OSSL_PROVIDER_load(NULL, "fips");
if (fips == NULL) {
ERR_clear_error();
fatal("Failed to load FIPS provider");
}
base = OSSL_PROVIDER_load(NULL, "base");
if (base == NULL) {
OSSL_PROVIDER_unload(fips);
ERR_clear_error();
fatal("Failed to load base provider");
}
#endif
/* Already in FIPS mode? */
if (isc_fips_mode()) {
break;
}
if (isc_fips_set_mode(1) != ISC_R_SUCCESS) {
fatal("setting FIPS mode failed"); fatal("setting FIPS mode failed");
} }
break; break;
@@ -3479,5 +3476,14 @@ main(int argc, char **argv) {
dig_startup(); dig_startup();
dig_shutdown(); dig_shutdown();
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
if (base != NULL) {
OSSL_PROVIDER_unload(base);
}
if (fips != NULL) {
OSSL_PROVIDER_unload(fips);
}
#endif
return exitcode; return exitcode;
} }
-10
View File
@@ -614,12 +614,6 @@ abbreviation is unambiguous; for example, :option:`+cd` is equivalent to
BADCOOKIE rcode before retrying the request or not. The default BADCOOKIE rcode before retrying the request or not. The default
is to not show the messages. is to not show the messages.
.. option:: +showbadvers, +noshowbadvers
This option toggles whether to show the message containing the
BADVERS rcode before retrying the request or not. The default
is to not show the messages.
.. option:: +showsearch, +noshowsearch .. option:: +showsearch, +noshowsearch
This option performs [or does not perform] a search showing intermediate results. This option performs [or does not perform] a search showing intermediate results.
@@ -757,10 +751,6 @@ abbreviation is unambiguous; for example, :option:`+cd` is equivalent to
This option sets [or does not set] the last unassigned DNS header flag in a DNS query. This option sets [or does not set] the last unassigned DNS header flag in a DNS query.
This flag is off by default. This flag is off by default.
.. option:: +zoneversion, +nozoneversion
When enabled, this option includes an EDNS Zone Version request when sending a query.
Multiple Queries Multiple Queries
~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~
+1 -20
View File
@@ -605,7 +605,6 @@ make_empty_lookup(void) {
.idnout = idnout, .idnout = idnout,
.udpsize = -1, .udpsize = -1,
.edns = -1, .edns = -1,
.original_edns = -1,
.recurse = true, .recurse = true,
.retries = tries, .retries = tries,
.comments = true, .comments = true,
@@ -705,7 +704,6 @@ clone_lookup(dig_lookup_t *lookold, bool servers) {
looknew->opcode = lookold->opcode; looknew->opcode = lookold->opcode;
looknew->expire = lookold->expire; looknew->expire = lookold->expire;
looknew->nsid = lookold->nsid; looknew->nsid = lookold->nsid;
looknew->zoneversion = lookold->zoneversion;
looknew->tcp_keepalive = lookold->tcp_keepalive; looknew->tcp_keepalive = lookold->tcp_keepalive;
looknew->header_only = lookold->header_only; looknew->header_only = lookold->header_only;
looknew->https_mode = lookold->https_mode; looknew->https_mode = lookold->https_mode;
@@ -740,7 +738,6 @@ clone_lookup(dig_lookup_t *lookold, bool servers) {
} }
looknew->showbadcookie = lookold->showbadcookie; looknew->showbadcookie = lookold->showbadcookie;
looknew->showbadvers = lookold->showbadvers;
looknew->sendcookie = lookold->sendcookie; looknew->sendcookie = lookold->sendcookie;
looknew->seenbadcookie = lookold->seenbadcookie; looknew->seenbadcookie = lookold->seenbadcookie;
looknew->badcookie = lookold->badcookie; looknew->badcookie = lookold->badcookie;
@@ -767,7 +764,6 @@ clone_lookup(dig_lookup_t *lookold, bool servers) {
looknew->idnout = lookold->idnout; looknew->idnout = lookold->idnout;
looknew->udpsize = lookold->udpsize; looknew->udpsize = lookold->udpsize;
looknew->edns = lookold->edns; looknew->edns = lookold->edns;
looknew->original_edns = lookold->original_edns;
looknew->recurse = lookold->recurse; looknew->recurse = lookold->recurse;
looknew->aaonly = lookold->aaonly; looknew->aaonly = lookold->aaonly;
looknew->adflag = lookold->adflag; looknew->adflag = lookold->adflag;
@@ -1942,7 +1938,6 @@ followup_lookup(dns_message_t *msg, dig_query_t *query, dns_section_t section) {
} }
domain = dns_fixedname_name(&lookup->fdomain); domain = dns_fixedname_name(&lookup->fdomain);
dns_name_copy(name, domain); dns_name_copy(name, domain);
lookup->edns = lookup->original_edns;
} }
debug("adding server %s", namestr); debug("adding server %s", namestr);
num = getaddresses(lookup, namestr, &lresult); num = getaddresses(lookup, namestr, &lresult);
@@ -2461,8 +2456,7 @@ setup_lookup(dig_lookup_t *lookup) {
lookup->udpsize = DEFAULT_EDNS_BUFSIZE; lookup->udpsize = DEFAULT_EDNS_BUFSIZE;
} }
if (lookup->edns < 0) { if (lookup->edns < 0) {
lookup->original_edns = lookup->edns = lookup->edns = DEFAULT_EDNS_VERSION;
DEFAULT_EDNS_VERSION;
} }
if (lookup->nsid) { if (lookup->nsid) {
@@ -2592,14 +2586,6 @@ setup_lookup(dig_lookup_t *lookup) {
i++; i++;
} }
if (lookup->zoneversion) {
INSIST(i < MAXOPTS);
opts[i].code = DNS_OPT_ZONEVERSION;
opts[i].length = 0;
opts[i].value = NULL;
i++;
}
if (lookup->ednsoptscnt != 0) { if (lookup->ednsoptscnt != 0) {
INSIST(i + lookup->ednsoptscnt <= MAXOPTS); INSIST(i + lookup->ednsoptscnt <= MAXOPTS);
memmove(&opts[i], lookup->ednsopts, memmove(&opts[i], lookup->ednsopts,
@@ -4314,11 +4300,6 @@ recv_done(isc_nmhandle_t *handle, isc_result_t eresult, isc_region_t *region,
if (msg->rcode == dns_rcode_badvers && msg->opt != NULL && if (msg->rcode == dns_rcode_badvers && msg->opt != NULL &&
(newedns = ednsvers(msg->opt)) < l->edns && l->ednsneg) (newedns = ednsvers(msg->opt)) < l->edns && l->ednsneg)
{ {
if (l->showbadvers) {
dighost_printmessage(query, &b, msg, true);
dighost_received(isc_buffer_usedlength(&b), &peer,
query);
}
/* /*
* Add minimum EDNS version required checks here if needed. * Add minimum EDNS version required checks here if needed.
*/ */
+4 -5
View File
@@ -117,11 +117,11 @@ struct dig_lookup {
section_answer, section_authority, section_question, section_answer, section_authority, section_question,
seenbadcookie, sendcookie, servfail_stops, seenbadcookie, sendcookie, servfail_stops,
setqid, /*% use a speciied query ID */ setqid, /*% use a speciied query ID */
showbadcookie, showbadvers, stats, tcflag, tcp_keepalive, showbadcookie, stats, tcflag, tcp_keepalive, tcp_mode,
tcp_mode, tcp_mode_set, tls_mode, /*% connect using TLS */ tcp_mode_set, tls_mode, /*% connect using TLS */
trace, /*% dig +trace */ trace, /*% dig +trace */
trace_root, /*% initial query for either +trace or +nssearch */ trace_root, /*% initial query for either +trace or +nssearch */
ttlunits, use_usec, waiting_connect, zflag, zoneversion; ttlunits, use_usec, waiting_connect, zflag;
char textname[MXNAME]; /*% Name we're going to be looking up */ char textname[MXNAME]; /*% Name we're going to be looking up */
char cmdline[MXNAME]; char cmdline[MXNAME];
dns_rdatatype_t rdtype; dns_rdatatype_t rdtype;
@@ -148,7 +148,6 @@ struct dig_lookup {
int nsfound; int nsfound;
int16_t udpsize; int16_t udpsize;
int16_t edns; int16_t edns;
int16_t original_edns;
int16_t padding; int16_t padding;
uint32_t ixfr_serial; uint32_t ixfr_serial;
isc_buffer_t rdatabuf; isc_buffer_t rdatabuf;
+2 -1
View File
@@ -246,7 +246,8 @@ printsection(dns_message_t *msg, dns_section_t sectionid,
(list_type == dns_rdatatype_any || (list_type == dns_rdatatype_any ||
rdataset->type == list_type)) || rdataset->type == list_type)) ||
(list_addresses && (list_addresses &&
(dns_rdatatype_isaddr(rdataset->type) || (rdataset->type == dns_rdatatype_a ||
rdataset->type == dns_rdatatype_aaaa ||
rdataset->type == dns_rdatatype_ns || rdataset->type == dns_rdatatype_ns ||
rdataset->type == dns_rdatatype_ptr)))) rdataset->type == dns_rdatatype_ptr))))
{ {
+1
View File
@@ -20,6 +20,7 @@
#include <isc/attributes.h> #include <isc/attributes.h>
#include <isc/buffer.h> #include <isc/buffer.h>
#include <isc/commandline.h> #include <isc/commandline.h>
#include <isc/condition.h>
#include <isc/lib.h> #include <isc/lib.h>
#include <isc/loop.h> #include <isc/loop.h>
#include <isc/netaddr.h> #include <isc/netaddr.h>
-8
View File
@@ -41,14 +41,6 @@ dnssec_keygen_LDADD = \
$(LDADD) \ $(LDADD) \
$(OPENSSL_LIBS) $(OPENSSL_LIBS)
dnssec_ksr_CPPFLAGS= \
$(AM_CPPFLAGS) \
$(OPENSSL_CFLAGS)
dnssec_ksr_LDADD = \
$(LDADD) \
$(OPENSSL_LIBS)
dnssec_signzone_CPPFLAGS = \ dnssec_signzone_CPPFLAGS = \
$(AM_CPPFLAGS) \ $(AM_CPPFLAGS) \
$(OPENSSL_CFLAGS) $(OPENSSL_CFLAGS)
+1 -1
View File
@@ -1075,7 +1075,7 @@ cleanup(void) {
if (print_mem_stats && verbose > 10) { if (print_mem_stats && verbose > 10) {
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
} }
isc_mem_detach(&mctx); isc_mem_destroy(&mctx);
} }
} }
+1 -1
View File
@@ -543,7 +543,7 @@ main(int argc, char **argv) {
if (verbose > 10) { if (verbose > 10) {
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
} }
isc_mem_detach(&mctx); isc_mem_destroy(&mctx);
fflush(stdout); fflush(stdout);
if (ferror(stdout)) { if (ferror(stdout)) {
+1 -1
View File
@@ -456,7 +456,7 @@ main(int argc, char **argv) {
if (verbose > 10) { if (verbose > 10) {
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
} }
isc_mem_detach(&mctx); isc_mem_destroy(&mctx);
fflush(stdout); fflush(stdout);
if (ferror(stdout)) { if (ferror(stdout)) {
+1 -1
View File
@@ -746,7 +746,7 @@ main(int argc, char **argv) {
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
} }
isc_mem_free(mctx, label); isc_mem_free(mctx, label);
isc_mem_detach(&mctx); isc_mem_destroy(&mctx);
if (freeit != NULL) { if (freeit != NULL) {
free(freeit); free(freeit);
+47 -11
View File
@@ -38,7 +38,7 @@
#include <isc/attributes.h> #include <isc/attributes.h>
#include <isc/buffer.h> #include <isc/buffer.h>
#include <isc/commandline.h> #include <isc/commandline.h>
#include <isc/crypto.h> #include <isc/fips.h>
#include <isc/lib.h> #include <isc/lib.h>
#include <isc/log.h> #include <isc/log.h>
#include <isc/mem.h> #include <isc/mem.h>
@@ -58,6 +58,11 @@
#include <dst/dst.h> #include <dst/dst.h>
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
#include <openssl/err.h>
#include <openssl/provider.h>
#endif
#include "dnssectool.h" #include "dnssectool.h"
const char *program = "dnssec-keygen"; const char *program = "dnssec-keygen";
@@ -146,7 +151,7 @@ usage(void) {
fprintf(stderr, " -l <file>: configuration file with dnssec-policy " fprintf(stderr, " -l <file>: configuration file with dnssec-policy "
"statement\n"); "statement\n");
fprintf(stderr, " -a <algorithm>:\n"); fprintf(stderr, " -a <algorithm>:\n");
if (!isc_crypto_fips_mode()) { if (!isc_fips_mode()) {
fprintf(stderr, " RSASHA1 | NSEC3RSASHA1 |\n"); fprintf(stderr, " RSASHA1 | NSEC3RSASHA1 |\n");
} }
fprintf(stderr, " RSASHA256 | RSASHA512 |\n"); fprintf(stderr, " RSASHA256 | RSASHA512 |\n");
@@ -154,7 +159,7 @@ usage(void) {
fprintf(stderr, " ED25519 | ED448\n"); fprintf(stderr, " ED25519 | ED448\n");
fprintf(stderr, " -3: use NSEC3-capable algorithm\n"); fprintf(stderr, " -3: use NSEC3-capable algorithm\n");
fprintf(stderr, " -b <key size in bits>:\n"); fprintf(stderr, " -b <key size in bits>:\n");
if (!isc_crypto_fips_mode()) { if (!isc_fips_mode()) {
fprintf(stderr, " RSASHA1:\t[%d..%d]\n", min_rsa, fprintf(stderr, " RSASHA1:\t[%d..%d]\n", min_rsa,
MAX_RSA); MAX_RSA);
fprintf(stderr, " NSEC3RSASHA1:\t[%d..%d]\n", min_rsa, fprintf(stderr, " NSEC3RSASHA1:\t[%d..%d]\n", min_rsa,
@@ -283,7 +288,7 @@ keygen(keygen_ctx_t *ctx, isc_mem_t *mctx, int argc, char **argv) {
fatal("unsupported algorithm: %s", algstr); fatal("unsupported algorithm: %s", algstr);
} }
if (isc_crypto_fips_mode()) { if (isc_fips_mode()) {
/* verify only in FIPS mode */ /* verify only in FIPS mode */
switch (ctx->alg) { switch (ctx->alg) {
case DST_ALG_RSASHA1: case DST_ALG_RSASHA1:
@@ -336,7 +341,7 @@ keygen(keygen_ctx_t *ctx, isc_mem_t *mctx, int argc, char **argv) {
switch (ctx->alg) { switch (ctx->alg) {
case DST_ALG_RSASHA1: case DST_ALG_RSASHA1:
case DST_ALG_NSEC3RSASHA1: case DST_ALG_NSEC3RSASHA1:
if (isc_crypto_fips_mode()) { if (isc_fips_mode()) {
fatal("key size not specified (-b " fatal("key size not specified (-b "
"option)"); "option)");
} }
@@ -496,7 +501,7 @@ keygen(keygen_ctx_t *ctx, isc_mem_t *mctx, int argc, char **argv) {
switch (ctx->alg) { switch (ctx->alg) {
case DNS_KEYALG_RSASHA1: case DNS_KEYALG_RSASHA1:
case DNS_KEYALG_NSEC3RSASHA1: case DNS_KEYALG_NSEC3RSASHA1:
if (isc_crypto_fips_mode()) { if (isc_fips_mode()) {
fatal("SHA1 based keys not supported in FIPS mode"); fatal("SHA1 based keys not supported in FIPS mode");
} }
FALLTHROUGH; FALLTHROUGH;
@@ -842,6 +847,10 @@ main(int argc, char **argv) {
isc_textregion_t r; isc_textregion_t r;
unsigned char c; unsigned char c;
int ch; int ch;
bool set_fips_mode = false;
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
OSSL_PROVIDER *fips = NULL, *base = NULL;
#endif
keygen_ctx_t ctx = { keygen_ctx_t ctx = {
.options = DST_TYPE_PRIVATE | DST_TYPE_PUBLIC, .options = DST_TYPE_PRIVATE | DST_TYPE_PUBLIC,
@@ -1100,9 +1109,7 @@ main(int argc, char **argv) {
ctx.prepub = strtottl(isc_commandline_argument); ctx.prepub = strtottl(isc_commandline_argument);
break; break;
case 'F': case 'F':
if (isc_crypto_fips_enable() != ISC_R_SUCCESS) { set_fips_mode = true;
fatal("setting FIPS mode failed");
}
break; break;
case '?': case '?':
if (isc_commandline_option != '?') { if (isc_commandline_option != '?') {
@@ -1129,11 +1136,32 @@ main(int argc, char **argv) {
ctx.quiet = true; ctx.quiet = true;
} }
if (set_fips_mode) {
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
fips = OSSL_PROVIDER_load(NULL, "fips");
if (fips == NULL) {
ERR_clear_error();
fatal("Failed to load FIPS provider");
}
base = OSSL_PROVIDER_load(NULL, "base");
if (base == NULL) {
OSSL_PROVIDER_unload(fips);
ERR_clear_error();
fatal("Failed to load base provider");
}
#endif
if (!isc_fips_mode()) {
if (isc_fips_set_mode(1) != ISC_R_SUCCESS) {
fatal("setting FIPS mode failed");
}
}
}
/* /*
* The DST subsystem will set FIPS mode if requested at build time. * The DST subsystem will set FIPS mode if requested at build time.
* The minimum sizes are both raised to 2048. * The minimum sizes are both raised to 2048.
*/ */
if (isc_crypto_fips_mode()) { if (isc_fips_mode()) {
min_rsa = min_dh = 2048; min_rsa = min_dh = 2048;
} }
@@ -1280,8 +1308,16 @@ main(int argc, char **argv) {
if (verbose > 10) { if (verbose > 10) {
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
} }
isc_mem_detach(&mctx); isc_mem_destroy(&mctx);
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
if (base != NULL) {
OSSL_PROVIDER_unload(base);
}
if (fips != NULL) {
OSSL_PROVIDER_unload(fips);
}
#endif
if (freeit != NULL) { if (freeit != NULL) {
free(freeit); free(freeit);
} }
+27 -6
View File
@@ -18,7 +18,7 @@
#include <isc/buffer.h> #include <isc/buffer.h>
#include <isc/commandline.h> #include <isc/commandline.h>
#include <isc/crypto.h> #include <isc/fips.h>
#include <isc/lex.h> #include <isc/lex.h>
#include <isc/lib.h> #include <isc/lib.h>
#include <isc/mem.h> #include <isc/mem.h>
@@ -362,7 +362,7 @@ create_key(ksr_ctx_t *ksr, dns_kasp_t *kasp, dns_kasp_key_t *kaspkey,
switch (ksr->alg) { switch (ksr->alg) {
case DST_ALG_RSASHA1: case DST_ALG_RSASHA1:
case DST_ALG_NSEC3RSASHA1: case DST_ALG_NSEC3RSASHA1:
if (isc_crypto_fips_mode()) { if (isc_fips_mode()) {
/* verify-only in FIPS mode */ /* verify-only in FIPS mode */
fatal("unsupported algorithm: %s", algstr); fatal("unsupported algorithm: %s", algstr);
} }
@@ -1348,6 +1348,10 @@ main(int argc, char *argv[]) {
isc_buffer_t buf; isc_buffer_t buf;
int ch; int ch;
char *endp; char *endp;
bool set_fips_mode = false;
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
OSSL_PROVIDER *fips = NULL, *base = NULL;
#endif
ksr_ctx_t ksr = { ksr_ctx_t ksr = {
.now = isc_stdtime_now(), .now = isc_stdtime_now(),
}; };
@@ -1367,9 +1371,7 @@ main(int argc, char *argv[]) {
ksr.now, &ksr.setend); ksr.now, &ksr.setend);
break; break;
case 'F': case 'F':
if (isc_crypto_fips_enable() != ISC_R_SUCCESS) { set_fips_mode = true;
fatal("setting FIPS mode failed");
}
break; break;
case 'f': case 'f':
ksr.file = isc_commandline_argument; ksr.file = isc_commandline_argument;
@@ -1423,12 +1425,31 @@ main(int argc, char *argv[]) {
* The DST subsystem will set FIPS mode if requested at build time. * The DST subsystem will set FIPS mode if requested at build time.
* The minimum sizes are both raised to 2048. * The minimum sizes are both raised to 2048.
*/ */
if (isc_crypto_fips_mode()) { if (isc_fips_mode()) {
min_rsa = min_dh = 2048; min_rsa = min_dh = 2048;
} }
setup_logging(); setup_logging();
if (set_fips_mode) {
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
fips = OSSL_PROVIDER_load(NULL, "fips");
if (fips == NULL) {
fatal("Failed to load FIPS provider");
}
base = OSSL_PROVIDER_load(NULL, "base");
if (base == NULL) {
OSSL_PROVIDER_unload(fips);
fatal("Failed to load base provider");
}
#endif
if (!isc_fips_mode()) {
if (isc_fips_set_mode(1) != ISC_R_SUCCESS) {
fatal("setting FIPS mode failed");
}
}
}
/* zone */ /* zone */
namestr = argv[1]; namestr = argv[1];
name = dns_fixedname_initname(&fname); name = dns_fixedname_initname(&fname);
+1 -1
View File
@@ -248,7 +248,7 @@ cleanup:
if (dir != NULL) { if (dir != NULL) {
isc_mem_free(mctx, dir); isc_mem_free(mctx, dir);
} }
isc_mem_detach(&mctx); isc_mem_destroy(&mctx);
return 0; return 0;
} }
+1 -1
View File
@@ -949,7 +949,7 @@ main(int argc, char **argv) {
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
} }
isc_mem_free(mctx, directory); isc_mem_free(mctx, directory);
isc_mem_detach(&mctx); isc_mem_destroy(&mctx);
return 0; return 0;
} }
+40 -3
View File
@@ -42,6 +42,7 @@
#include <isc/commandline.h> #include <isc/commandline.h>
#include <isc/dir.h> #include <isc/dir.h>
#include <isc/file.h> #include <isc/file.h>
#include <isc/fips.h>
#include <isc/hash.h> #include <isc/hash.h>
#include <isc/hex.h> #include <isc/hex.h>
#include <isc/lib.h> #include <isc/lib.h>
@@ -89,6 +90,10 @@
#include <dns/zoneverify.h> #include <dns/zoneverify.h>
#include <dst/dst.h> #include <dst/dst.h>
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
#include <openssl/err.h>
#include <openssl/provider.h>
#endif
#include "dnssectool.h" #include "dnssectool.h"
@@ -3375,6 +3380,10 @@ main(int argc, char *argv[]) {
bool set_optout = false; bool set_optout = false;
bool set_iter = false; bool set_iter = false;
bool nonsecify = false; bool nonsecify = false;
bool set_fips_mode = false;
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
OSSL_PROVIDER *fips = NULL, *base = NULL;
#endif
atomic_init(&shuttingdown, false); atomic_init(&shuttingdown, false);
atomic_init(&finished, false); atomic_init(&finished, false);
@@ -3663,9 +3672,7 @@ main(int argc, char *argv[]) {
break; break;
case 'F': case 'F':
if (isc_crypto_fips_enable() != ISC_R_SUCCESS) { set_fips_mode = true;
fatal("setting FIPS mode failed");
}
break; break;
case '?': case '?':
@@ -3736,6 +3743,27 @@ main(int argc, char *argv[]) {
isc_managers_create(&mctx, nloops, &loopmgr, &netmgr); isc_managers_create(&mctx, nloops, &loopmgr, &netmgr);
if (set_fips_mode) {
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
fips = OSSL_PROVIDER_load(NULL, "fips");
if (fips == NULL) {
ERR_clear_error();
fatal("Failed to load FIPS provider");
}
base = OSSL_PROVIDER_load(NULL, "base");
if (base == NULL) {
OSSL_PROVIDER_unload(fips);
ERR_clear_error();
fatal("Failed to load base provider");
}
#endif
if (!isc_fips_mode()) {
if (isc_fips_set_mode(1) != ISC_R_SUCCESS) {
fatal("setting FIPS mode failed");
}
}
}
setup_logging(); setup_logging();
argc -= isc_commandline_index; argc -= isc_commandline_index;
@@ -4107,6 +4135,15 @@ main(int argc, char *argv[]) {
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
} }
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
if (base != NULL) {
OSSL_PROVIDER_unload(base);
}
if (fips != NULL) {
OSSL_PROVIDER_unload(fips);
}
#endif
isc_managers_destroy(&mctx, &loopmgr, &netmgr); isc_managers_destroy(&mctx, &loopmgr, &netmgr);
if (printstats) { if (printstats) {
+1 -1
View File
@@ -330,7 +330,7 @@ main(int argc, char *argv[]) {
if (verbose > 10) { if (verbose > 10) {
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
} }
isc_mem_detach(&mctx); isc_mem_destroy(&mctx);
return result == ISC_R_SUCCESS ? 0 : 1; return result == ISC_R_SUCCESS ? 0 : 1;
} }
-3
View File
@@ -99,7 +99,6 @@ options {\n\
recursing-file \"named.recursing\";\n\ recursing-file \"named.recursing\";\n\
recursive-clients 1000;\n\ recursive-clients 1000;\n\
request-nsid false;\n\ request-nsid false;\n\
request-zoneversion false;\n\
resolver-query-timeout 10;\n\ resolver-query-timeout 10;\n\
# responselog <boolean>;\n\ # responselog <boolean>;\n\
rrset-order { order random; };\n\ rrset-order { order random; };\n\
@@ -240,7 +239,6 @@ options {\n\
notify yes;\n\ notify yes;\n\
notify-delay 5;\n\ notify-delay 5;\n\
notify-to-soa no;\n\ notify-to-soa no;\n\
provide-zoneversion yes;\n\
send-report-channel .;\n\ send-report-channel .;\n\
serial-update-method increment;\n\ serial-update-method increment;\n\
sig-signing-nodes 100;\n\ sig-signing-nodes 100;\n\
@@ -262,7 +260,6 @@ view \"_bind\" chaos {\n\
notify no;\n\ notify no;\n\
allow-new-zones no;\n\ allow-new-zones no;\n\
max-cache-size 2M;\n\ max-cache-size 2M;\n\
provide-zoneversion no;\n\
\n\ \n\
# Prevent use of this zone in DNS amplified reflection DoS attacks\n\ # Prevent use of this zone in DNS amplified reflection DoS attacks\n\
rate-limit {\n\ rate-limit {\n\
+1
View File
@@ -736,6 +736,7 @@ controlkeylist_fromcfg(const cfg_obj_t *keylist, isc_mem_t *mctx,
key->secret.length = 0; key->secret.length = 0;
ISC_LINK_INIT(key, link); ISC_LINK_INIT(key, link);
ISC_LIST_APPEND(*keyids, key, link); ISC_LIST_APPEND(*keyids, key, link);
newstr = NULL;
} }
} }
+1
View File
@@ -25,6 +25,7 @@
#include <string.h> #include <string.h>
#include <unistd.h> #include <unistd.h>
#include <isc/condition.h>
#include <isc/log.h> #include <isc/log.h>
#include <isc/loop.h> #include <isc/loop.h>
#include <isc/mutex.h> #include <isc/mutex.h>
+1
View File
@@ -86,6 +86,7 @@ EXTERN named_server_t *named_g_server INIT(NULL);
/* /*
* Logging. * Logging.
*/ */
EXTERN bool named_g_logging INIT(false);
EXTERN unsigned int named_g_debuglevel INIT(0); EXTERN unsigned int named_g_debuglevel INIT(0);
/* /*
+2
View File
@@ -52,6 +52,8 @@ named_log_init(bool safe) {
named_log_setdefaultsslkeylogfile(lcfg); named_log_setdefaultsslkeylogfile(lcfg);
rcu_read_unlock(); rcu_read_unlock();
named_g_logging = true;
return ISC_R_SUCCESS; return ISC_R_SUCCESS;
cleanup: cleanup:
+111 -44
View File
@@ -30,6 +30,7 @@
#include <isc/crypto.h> #include <isc/crypto.h>
#include <isc/dir.h> #include <isc/dir.h>
#include <isc/file.h> #include <isc/file.h>
#include <isc/fips.h>
#include <isc/hash.h> #include <isc/hash.h>
#include <isc/httpd.h> #include <isc/httpd.h>
#include <isc/lib.h> #include <isc/lib.h>
@@ -90,6 +91,10 @@
#include <openssl/crypto.h> #include <openssl/crypto.h>
#include <openssl/evp.h> #include <openssl/evp.h>
#include <openssl/opensslv.h> #include <openssl/opensslv.h>
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
#include <openssl/err.h>
#include <openssl/provider.h>
#endif
#ifdef HAVE_LIBXML2 #ifdef HAVE_LIBXML2
#include <libxml/parser.h> #include <libxml/parser.h>
#include <libxml/xmlversion.h> #include <libxml/xmlversion.h>
@@ -129,7 +134,6 @@ static int maxudp = 0;
/* /*
* -T options: * -T options:
*/ */
static bool cookiealwaysvalid = false;
static bool dropedns = false; static bool dropedns = false;
static bool ednsformerr = false; static bool ednsformerr = false;
static bool ednsnotimp = false; static bool ednsnotimp = false;
@@ -151,13 +155,24 @@ static bool transferstuck = false;
static bool disable6 = false; static bool disable6 = false;
static bool disable4 = false; static bool disable4 = false;
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
static OSSL_PROVIDER *fips = NULL, *base = NULL;
#endif
void void
named_main_earlywarning(const char *format, ...) { named_main_earlywarning(const char *format, ...) {
va_list args; va_list args;
va_start(args, format); va_start(args, format);
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN, if (named_g_logging) {
ISC_LOG_WARNING, format, args); isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
ISC_LOG_WARNING, format, args);
} else {
fprintf(stderr, "%s: ", program_name);
vfprintf(stderr, format, args);
fprintf(stderr, "\n");
fflush(stderr);
}
va_end(args); va_end(args);
} }
@@ -166,10 +181,18 @@ named_main_earlyfatal(const char *format, ...) {
va_list args; va_list args;
va_start(args, format); va_start(args, format);
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN, if (named_g_logging) {
ISC_LOG_CRITICAL, format, args); isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN, ISC_LOG_CRITICAL, format, args);
ISC_LOG_CRITICAL, "exiting (due to early fatal error)"); isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
ISC_LOG_CRITICAL,
"exiting (due to early fatal error)");
} else {
fprintf(stderr, "%s: ", program_name);
vfprintf(stderr, format, args);
fprintf(stderr, "\n");
fflush(stderr);
}
va_end(args); va_end(args);
_exit(EXIT_FAILURE); _exit(EXIT_FAILURE);
@@ -186,19 +209,26 @@ assertion_failed(const char *file, int line, isc_assertiontype_t type,
* Handle assertion failures. * Handle assertion failures.
*/ */
/* if (named_g_logging) {
* Reset the assertion callback in case it is the log /*
* routines causing the assertion. * Reset the assertion callback in case it is the log
*/ * routines causing the assertion.
isc_assertion_setcallback(NULL); */
isc_assertion_setcallback(NULL);
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN, isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
ISC_LOG_CRITICAL, "%s:%d: %s(%s) failed", file, line, ISC_LOG_CRITICAL, "%s:%d: %s(%s) failed", file,
isc_assertion_typetotext(type), cond); line, isc_assertion_typetotext(type), cond);
isc_backtrace_log(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN, isc_backtrace_log(NAMED_LOGCATEGORY_GENERAL,
ISC_LOG_CRITICAL); NAMED_LOGMODULE_MAIN, ISC_LOG_CRITICAL);
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN, isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
ISC_LOG_CRITICAL, "exiting (due to assertion failure)"); ISC_LOG_CRITICAL,
"exiting (due to assertion failure)");
} else {
fprintf(stderr, "%s:%d: %s(%s) failed\n", file, line,
isc_assertion_typetotext(type), cond);
fflush(stderr);
}
if (named_g_coreok) { if (named_g_coreok) {
abort(); abort();
@@ -217,20 +247,27 @@ library_fatal_error(const char *file, int line, const char *func,
* Handle isc_error_fatal() calls from our libraries. * Handle isc_error_fatal() calls from our libraries.
*/ */
/* if (named_g_logging) {
* Reset the error callback in case it is the log /*
* routines causing the assertion. * Reset the error callback in case it is the log
*/ * routines causing the assertion.
isc_error_setfatal(NULL); */
isc_error_setfatal(NULL);
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN, isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
ISC_LOG_CRITICAL, "%s:%d:%s(): fatal error: ", file, line, ISC_LOG_CRITICAL,
func); "%s:%d:%s(): fatal error: ", file, line, func);
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN, isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
ISC_LOG_CRITICAL, format, args); ISC_LOG_CRITICAL, format, args);
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN, isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
ISC_LOG_CRITICAL, ISC_LOG_CRITICAL,
"exiting (due to fatal error in library)"); "exiting (due to fatal error in library)");
} else {
fprintf(stderr, "%s:%d:%s(): fatal error: ", file, line, func);
vfprintf(stderr, format, args);
fprintf(stderr, "\n");
fflush(stderr);
}
if (named_g_coreok) { if (named_g_coreok) {
abort(); abort();
@@ -250,11 +287,19 @@ library_unexpected_error(const char *file, int line, const char *func,
* Handle isc_error_unexpected() calls from our libraries. * Handle isc_error_unexpected() calls from our libraries.
*/ */
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN, if (named_g_logging) {
ISC_LOG_ERROR, "%s:%d:%s(): unexpected error: ", file, isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
line, func); ISC_LOG_ERROR,
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN, "%s:%d:%s(): unexpected error: ", file, line,
ISC_LOG_ERROR, format, args); func);
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
ISC_LOG_ERROR, format, args);
} else {
fprintf(stderr, "%s:%d:%s(): fatal error: ", file, line, func);
vfprintf(stderr, format, args);
fprintf(stderr, "\n");
fflush(stderr);
}
} }
static void static void
@@ -653,9 +698,7 @@ parse_T_opt(char *option) {
* force the server to behave (or misbehave) in * force the server to behave (or misbehave) in
* specified ways for testing purposes. * specified ways for testing purposes.
*/ */
if (!strcmp(option, "cookiealwaysvalid")) { if (!strcmp(option, "dropedns")) {
cookiealwaysvalid = true;
} else if (!strcmp(option, "dropedns")) {
dropedns = true; dropedns = true;
} else if (!strcmp(option, "ednsformerr")) { } else if (!strcmp(option, "ednsformerr")) {
ednsformerr = true; ednsformerr = true;
@@ -909,7 +952,25 @@ parse_command_line(int argc, char *argv[]) {
named_main_earlyfatal("option '-X' has been removed"); named_main_earlyfatal("option '-X' has been removed");
break; break;
case 'F': case 'F':
if (isc_crypto_fips_enable() != ISC_R_SUCCESS) { #if OPENSSL_VERSION_NUMBER >= 0x30000000L
fips = OSSL_PROVIDER_load(NULL, "fips");
if (fips == NULL) {
ERR_clear_error();
named_main_earlyfatal(
"Failed to load FIPS provider");
}
base = OSSL_PROVIDER_load(NULL, "base");
if (base == NULL) {
OSSL_PROVIDER_unload(fips);
ERR_clear_error();
named_main_earlyfatal(
"Failed to load base provider");
}
#endif
if (isc_fips_mode()) { /* Already in FIPS mode. */
break;
}
if (isc_fips_set_mode(1) != ISC_R_SUCCESS) {
named_main_earlyfatal( named_main_earlyfatal(
"setting FIPS mode failed"); "setting FIPS mode failed");
} }
@@ -1223,9 +1284,6 @@ setup(void) {
/* /*
* Modify server context according to command line options * Modify server context according to command line options
*/ */
if (cookiealwaysvalid) {
ns_server_setoption(sctx, NS_SERVER_COOKIEALWAYSVALID, true);
}
if (disable4) { if (disable4) {
ns_server_setoption(sctx, NS_SERVER_DISABLE4, true); ns_server_setoption(sctx, NS_SERVER_DISABLE4, true);
} }
@@ -1516,6 +1574,15 @@ main(int argc, char *argv[]) {
named_os_shutdown(); named_os_shutdown();
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
if (base != NULL) {
OSSL_PROVIDER_unload(base);
}
if (fips != NULL) {
OSSL_PROVIDER_unload(fips);
}
#endif
#ifdef HAVE_GPERFTOOLS_PROFILER #ifdef HAVE_GPERFTOOLS_PROFILER
ProfilerStop(); ProfilerStop();
#endif /* ifdef HAVE_GPERFTOOLS_PROFILER */ #endif /* ifdef HAVE_GPERFTOOLS_PROFILER */
+7 -30
View File
@@ -38,6 +38,7 @@
#include <isc/commandline.h> #include <isc/commandline.h>
#include <isc/dir.h> #include <isc/dir.h>
#include <isc/file.h> #include <isc/file.h>
#include <isc/fips.h>
#include <isc/hash.h> #include <isc/hash.h>
#include <isc/hex.h> #include <isc/hex.h>
#include <isc/hmac.h> #include <isc/hmac.h>
@@ -1391,13 +1392,6 @@ configure_peer(const cfg_obj_t *cpeer, isc_mem_t *mctx, dns_peer_t **peerp) {
CHECK(dns_peer_setrequestnsid(peer, cfg_obj_asboolean(obj))); CHECK(dns_peer_setrequestnsid(peer, cfg_obj_asboolean(obj)));
} }
obj = NULL;
(void)cfg_map_get(cpeer, "request-zoneversion", &obj);
if (obj != NULL) {
CHECK(dns_peer_setrequestzoneversion(peer,
cfg_obj_asboolean(obj)));
}
obj = NULL; obj = NULL;
(void)cfg_map_get(cpeer, "send-cookie", &obj); (void)cfg_map_get(cpeer, "send-cookie", &obj);
if (obj != NULL) { if (obj != NULL) {
@@ -3253,7 +3247,6 @@ create_empty_zone(dns_zone_t *pzone, dns_name_t *name, dns_view_t *view,
dns_zone_setoption(zone, ~DNS_ZONEOPT_NOCHECKNS, false); dns_zone_setoption(zone, ~DNS_ZONEOPT_NOCHECKNS, false);
dns_zone_setoption(zone, DNS_ZONEOPT_NOCHECKNS, true); dns_zone_setoption(zone, DNS_ZONEOPT_NOCHECKNS, true);
dns_zone_setoption(zone, DNS_ZONEOPT_ZONEVERSION, false);
dns_zone_setcheckdstype(zone, dns_checkdstype_no); dns_zone_setcheckdstype(zone, dns_checkdstype_no);
dns_zone_setnotifytype(zone, dns_notifytype_no); dns_zone_setnotifytype(zone, dns_notifytype_no);
dns_zone_setautomatic(zone, true); dns_zone_setautomatic(zone, true);
@@ -3770,7 +3763,7 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
uint32_t maxbits; uint32_t maxbits;
unsigned int resopts = 0; unsigned int resopts = 0;
dns_zone_t *zone = NULL; dns_zone_t *zone = NULL;
uint32_t clients_per_query, max_clients_per_query; uint32_t max_clients_per_query;
bool empty_zones_enable; bool empty_zones_enable;
const cfg_obj_t *disablelist = NULL; const cfg_obj_t *disablelist = NULL;
isc_stats_t *resstats = NULL; isc_stats_t *resstats = NULL;
@@ -5140,11 +5133,6 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
INSIST(result == ISC_R_SUCCESS); INSIST(result == ISC_R_SUCCESS);
view->requestnsid = cfg_obj_asboolean(obj); view->requestnsid = cfg_obj_asboolean(obj);
obj = NULL;
result = named_config_get(maps, "request-zoneversion", &obj);
INSIST(result == ISC_R_SUCCESS);
view->requestzoneversion = cfg_obj_asboolean(obj);
obj = NULL; obj = NULL;
result = named_config_get(maps, "send-cookie", &obj); result = named_config_get(maps, "send-cookie", &obj);
INSIST(result == ISC_R_SUCCESS); INSIST(result == ISC_R_SUCCESS);
@@ -5181,26 +5169,15 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
INSIST(result == ISC_R_SUCCESS); INSIST(result == ISC_R_SUCCESS);
view->v6bias = cfg_obj_asuint32(obj) * 1000; view->v6bias = cfg_obj_asuint32(obj) * 1000;
obj = NULL;
result = named_config_get(maps, "clients-per-query", &obj);
INSIST(result == ISC_R_SUCCESS);
clients_per_query = cfg_obj_asuint32(obj);
obj = NULL; obj = NULL;
result = named_config_get(maps, "max-clients-per-query", &obj); result = named_config_get(maps, "max-clients-per-query", &obj);
INSIST(result == ISC_R_SUCCESS); INSIST(result == ISC_R_SUCCESS);
max_clients_per_query = cfg_obj_asuint32(obj); max_clients_per_query = cfg_obj_asuint32(obj);
if (max_clients_per_query < clients_per_query) { obj = NULL;
cfg_obj_log(obj, ISC_LOG_WARNING, result = named_config_get(maps, "clients-per-query", &obj);
"configured clients-per-query (%u) exceeds " INSIST(result == ISC_R_SUCCESS);
"max-clients-per-query (%u); automatically " dns_resolver_setclientsperquery(view->resolver, cfg_obj_asuint32(obj),
"adjusting max-clients-per-query to (%u)",
clients_per_query, max_clients_per_query,
clients_per_query);
max_clients_per_query = clients_per_query;
}
dns_resolver_setclientsperquery(view->resolver, clients_per_query,
max_clients_per_query); max_clients_per_query);
/* /*
@@ -9400,7 +9377,7 @@ view_loaded(void *arg) {
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER, isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
ISC_LOG_NOTICE, "FIPS mode is %s", ISC_LOG_NOTICE, "FIPS mode is %s",
isc_crypto_fips_mode() ? "enabled" : "disabled"); isc_fips_mode() ? "enabled" : "disabled");
#if HAVE_LIBSYSTEMD #if HAVE_LIBSYSTEMD
sd_notifyf(0, sd_notifyf(0,
+9 -20
View File
@@ -358,8 +358,6 @@ init_desc(void) {
SET_NSSTATDESC(expireopt, "Expire option received", "ExpireOpt"); SET_NSSTATDESC(expireopt, "Expire option received", "ExpireOpt");
SET_NSSTATDESC(keepaliveopt, "EDNS TCP keepalive option received", SET_NSSTATDESC(keepaliveopt, "EDNS TCP keepalive option received",
"KeepAliveOpt"); "KeepAliveOpt");
SET_NSSTATDESC(zoneversionopt, "ZONEVERSION option received",
"ZoneVersionOpt");
SET_NSSTATDESC(padopt, "EDNS padding option received", "PadOpt"); SET_NSSTATDESC(padopt, "EDNS padding option received", "PadOpt");
SET_NSSTATDESC(otheropt, "Other EDNS option received", "OtherOpt"); SET_NSSTATDESC(otheropt, "Other EDNS option received", "OtherOpt");
SET_NSSTATDESC(cookiein, "COOKIE option received", "CookieIn"); SET_NSSTATDESC(cookiein, "COOKIE option received", "CookieIn");
@@ -1605,7 +1603,7 @@ xfrin_xmlrender(dns_zone_t *zone, void *arg) {
isc_sockaddr_format(addrp, addr_buf, sizeof(addr_buf)); isc_sockaddr_format(addrp, addr_buf, sizeof(addr_buf));
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR addr_buf)); TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR addr_buf));
} else if (is_presoa) { } else if (is_presoa) {
dns_zone_getsourceaddr(zone, &addr); addr = dns_zone_getsourceaddr(zone);
isc_sockaddr_format(&addr, addr_buf, sizeof(addr_buf)); isc_sockaddr_format(&addr, addr_buf, sizeof(addr_buf));
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR addr_buf)); TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR addr_buf));
} else { } else {
@@ -1619,13 +1617,9 @@ xfrin_xmlrender(dns_zone_t *zone, void *arg) {
isc_sockaddr_format(addrp, addr_buf, sizeof(addr_buf)); isc_sockaddr_format(addrp, addr_buf, sizeof(addr_buf));
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR addr_buf)); TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR addr_buf));
} else if (is_presoa) { } else if (is_presoa) {
if (dns_zone_getprimaryaddr(zone, &addr) == ISC_R_SUCCESS) { addr = dns_zone_getprimaryaddr(zone);
isc_sockaddr_format(&addr, addr_buf, sizeof(addr_buf)); isc_sockaddr_format(&addr, addr_buf, sizeof(addr_buf));
TRY0(xmlTextWriterWriteString(writer, TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR addr_buf));
ISC_XMLCHAR addr_buf));
} else {
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR "-"));
}
} else { } else {
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR "-")); TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR "-"));
} }
@@ -2662,7 +2656,7 @@ xfrin_jsonrender(dns_zone_t *zone, void *arg) {
json_object_object_add(xfrinobj, "localaddr", json_object_object_add(xfrinobj, "localaddr",
json_object_new_string(addr_buf)); json_object_new_string(addr_buf));
} else if (is_presoa) { } else if (is_presoa) {
dns_zone_getsourceaddr(zone, &addr); addr = dns_zone_getsourceaddr(zone);
isc_sockaddr_format(&addr, addr_buf, sizeof(addr_buf)); isc_sockaddr_format(&addr, addr_buf, sizeof(addr_buf));
json_object_object_add(xfrinobj, "localaddr", json_object_object_add(xfrinobj, "localaddr",
json_object_new_string(addr_buf)); json_object_new_string(addr_buf));
@@ -2677,15 +2671,10 @@ xfrin_jsonrender(dns_zone_t *zone, void *arg) {
json_object_object_add(xfrinobj, "remoteaddr", json_object_object_add(xfrinobj, "remoteaddr",
json_object_new_string(addr_buf)); json_object_new_string(addr_buf));
} else if (is_presoa) { } else if (is_presoa) {
if (dns_zone_getprimaryaddr(zone, &addr) == ISC_R_SUCCESS) { addr = dns_zone_getprimaryaddr(zone);
isc_sockaddr_format(&addr, addr_buf, sizeof(addr_buf)); isc_sockaddr_format(&addr, addr_buf, sizeof(addr_buf));
json_object_object_add( json_object_object_add(xfrinobj, "remoteaddr",
xfrinobj, "remoteaddr", json_object_new_string(addr_buf));
json_object_new_string(addr_buf));
} else {
json_object_object_add(xfrinobj, "remoteaddr",
json_object_new_string("-"));
}
} else { } else {
json_object_object_add(xfrinobj, "remoteaddr", json_object_object_add(xfrinobj, "remoteaddr",
json_object_new_string("-")); json_object_new_string("-"));
+8 -12
View File
@@ -1227,12 +1227,6 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
dns_zone_setkasp(zone, NULL); dns_zone_setkasp(zone, NULL);
} }
obj = NULL;
result = named_config_get(maps, "provide-zoneversion", &obj);
INSIST(result == ISC_R_SUCCESS && obj != NULL);
dns_zone_setoption(zone, DNS_ZONEOPT_ZONEVERSION,
cfg_obj_asboolean(obj));
obj = NULL; obj = NULL;
result = named_config_get(maps, "notify", &obj); result = named_config_get(maps, "notify", &obj);
INSIST(result == ISC_R_SUCCESS && obj != NULL); INSIST(result == ISC_R_SUCCESS && obj != NULL);
@@ -1285,22 +1279,22 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
obj = NULL; obj = NULL;
result = named_config_get(maps, "parental-source", &obj); result = named_config_get(maps, "parental-source", &obj);
INSIST(result == ISC_R_SUCCESS && obj != NULL); INSIST(result == ISC_R_SUCCESS && obj != NULL);
dns_zone_setparentalsrc4(zone, cfg_obj_assockaddr(obj)); CHECK(dns_zone_setparentalsrc4(zone, cfg_obj_assockaddr(obj)));
obj = NULL; obj = NULL;
result = named_config_get(maps, "parental-source-v6", &obj); result = named_config_get(maps, "parental-source-v6", &obj);
INSIST(result == ISC_R_SUCCESS && obj != NULL); INSIST(result == ISC_R_SUCCESS && obj != NULL);
dns_zone_setparentalsrc6(zone, cfg_obj_assockaddr(obj)); CHECK(dns_zone_setparentalsrc6(zone, cfg_obj_assockaddr(obj)));
obj = NULL; obj = NULL;
result = named_config_get(maps, "notify-source", &obj); result = named_config_get(maps, "notify-source", &obj);
INSIST(result == ISC_R_SUCCESS && obj != NULL); INSIST(result == ISC_R_SUCCESS && obj != NULL);
dns_zone_setnotifysrc4(zone, cfg_obj_assockaddr(obj)); CHECK(dns_zone_setnotifysrc4(zone, cfg_obj_assockaddr(obj)));
obj = NULL; obj = NULL;
result = named_config_get(maps, "notify-source-v6", &obj); result = named_config_get(maps, "notify-source-v6", &obj);
INSIST(result == ISC_R_SUCCESS && obj != NULL); INSIST(result == ISC_R_SUCCESS && obj != NULL);
dns_zone_setnotifysrc6(zone, cfg_obj_assockaddr(obj)); CHECK(dns_zone_setnotifysrc6(zone, cfg_obj_assockaddr(obj)));
obj = NULL; obj = NULL;
result = named_config_get(maps, "notify-to-soa", &obj); result = named_config_get(maps, "notify-to-soa", &obj);
@@ -1944,12 +1938,14 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
obj = NULL; obj = NULL;
result = named_config_get(maps, "transfer-source", &obj); result = named_config_get(maps, "transfer-source", &obj);
INSIST(result == ISC_R_SUCCESS && obj != NULL); INSIST(result == ISC_R_SUCCESS && obj != NULL);
dns_zone_setxfrsource4(mayberaw, cfg_obj_assockaddr(obj)); CHECK(dns_zone_setxfrsource4(mayberaw,
cfg_obj_assockaddr(obj)));
obj = NULL; obj = NULL;
result = named_config_get(maps, "transfer-source-v6", &obj); result = named_config_get(maps, "transfer-source-v6", &obj);
INSIST(result == ISC_R_SUCCESS && obj != NULL); INSIST(result == ISC_R_SUCCESS && obj != NULL);
dns_zone_setxfrsource6(mayberaw, cfg_obj_assockaddr(obj)); CHECK(dns_zone_setxfrsource6(mayberaw,
cfg_obj_assockaddr(obj)));
obj = NULL; obj = NULL;
(void)named_config_get(maps, "try-tcp-refresh", &obj); (void)named_config_get(maps, "try-tcp-refresh", &obj);
-1
View File
@@ -28,7 +28,6 @@ options {
} except-from { } except-from {
"example"; "example";
}; };
qname-minimization disabled; // Regression test for GL #4652
}; };
trust-anchors { }; trust-anchors { };
@@ -31,7 +31,6 @@ server 0.0.0.0 {
request-ixfr no; request-ixfr no;
request-ixfr-max-diffs 0; request-ixfr-max-diffs 0;
request-nsid no; request-nsid no;
request-zoneversion no;
require-cookie no; require-cookie no;
send-cookie no; send-cookie no;
tcp-keepalive no; tcp-keepalive no;
@@ -56,7 +55,6 @@ server :: {
request-ixfr no; request-ixfr no;
request-ixfr-max-diffs 0; request-ixfr-max-diffs 0;
request-nsid no; request-nsid no;
request-zoneversion no;
require-cookie no; require-cookie no;
send-cookie no; send-cookie no;
tcp-keepalive no; tcp-keepalive no;
+2 -4
View File
@@ -131,13 +131,11 @@ status=$((status + ret))
echo_i "checking that log-report-channel zones fail if '*._er/TXT' is missing ($n)" echo_i "checking that log-report-channel zones fail if '*._er/TXT' is missing ($n)"
ret=0 ret=0
$CHECKZONE -R fail example zones/er.db >test.out2.$n 2>&1 || ret=1 $CHECKZONE -R fail example zones/er.db >test.out2.$n 2>&1 || ret=1
grep -F "no '*._er/TXT' wildcard found" test.out2.$n >/dev/null && ret=1 grep -F "no '*._er/TXT' wildcard found" test.out4.$n >/dev/null && ret=1
$CHECKZONE example zones/er-missing.db >test.out3.$n 2>&1 || ret=1 $CHECKZONE example zones/er-missing.db >test.out3.$n 2>&1 || ret=1
grep -F "no '*._er/TXT' wildcard found" test.out3.$n >/dev/null && ret=1 grep -F "no '*._er/TXT' wildcard found" test.out4.$n >/dev/null && ret=1
$CHECKZONE -R fail example zones/er-missing.db >test.out4.$n 2>&1 && ret=1 $CHECKZONE -R fail example zones/er-missing.db >test.out4.$n 2>&1 && ret=1
grep -F "no '*._er/TXT' wildcard found" test.out4.$n >/dev/null || ret=1 grep -F "no '*._er/TXT' wildcard found" test.out4.$n >/dev/null || ret=1
n=$((n + 1))
if [ $ret != 0 ]; then echo_i "failed"; fi
status=$((status + ret)) status=$((status + ret))
echo_i "checking that raw zone with bad class is handled ($n)" echo_i "checking that raw zone with bad class is handled ($n)"
-1
View File
@@ -308,7 +308,6 @@ def logger(request, system_test_name):
@pytest.fixture(scope="module") @pytest.fixture(scope="module")
def expected_artifacts(request): def expected_artifacts(request):
common_artifacts = [ common_artifacts = [
"*/.hypothesis", # drop after Ubuntu 20.04 Focal Fossa gets removed from CI
".libs/*", # possible build artifacts, see GL #5055 ".libs/*", # possible build artifacts, see GL #5055
"ns*/named.conf", "ns*/named.conf",
"ns*/named.memstats", "ns*/named.memstats",
+4 -26
View File
@@ -361,23 +361,6 @@ grep "status: NOERROR," dig.out.test$n >/dev/null || ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=$((status + ret)) status=$((status + ret))
n=$((n + 1))
echo_i "Restart NS4 with -T cookiealwaysvalid ($n)"
stop_server ns4
touch ns4/named.cookiealwaysvalid
start_server --noclean --restart --port ${PORT} ns4 || ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi
status=$((status + ret))
n=$((n + 1))
echo_i "test NS6 cookie on NS4 with -T cookiealwaysvalid (expect success) ($n)"
ret=0
$DIG $DIGOPTS +cookie=$ns6cookie -b 10.53.0.4 +nobadcookie soa . @10.53.0.4 >dig.out.test$n || ret=1
grep "; COOKIE:.*(good)" dig.out.test$n >/dev/null || ret=1
grep "status: NOERROR," dig.out.test$n >/dev/null || ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi
status=$((status + ret))
n=$((n + 1)) n=$((n + 1))
echo_i "check that test server is correctly configured ($n)" echo_i "check that test server is correctly configured ($n)"
ret=0 ret=0
@@ -569,21 +552,16 @@ sys.exit(1)'; then
$DIG $DIGOPTS @10.53.0.1 tsig. >dig.out.test$n.1 || ret=1 $DIG $DIGOPTS @10.53.0.1 tsig. >dig.out.test$n.1 || ret=1
grep "status: NOERROR" dig.out.test$n.1 >/dev/null || ret=1 grep "status: NOERROR" dig.out.test$n.1 >/dev/null || ret=1
rndc_dumpdb ns1 rndc_dumpdb ns1
# prime cache with NS response for QNAME minimisation
grep "$pat" ns1/named_dump.db.test$n >/dev/null || ret=1 grep "$pat" ns1/named_dump.db.test$n >/dev/null || ret=1
$DIG $DIGOPTS @10.53.0.1 NS nocookie.tsig >dig.out.test$n.2 || ret=1
grep "status: NOERROR" dig.out.test$n.2 >/dev/null || ret=1
# check the disabled server response # check the disabled server response
nextpart ns1/named.run >/dev/null nextpart ns1/named.run >/dev/null
$DIG $DIGOPTS @10.53.0.1 nocookie.tsig >dig.out.test$n.3 || ret=1 $DIG $DIGOPTS @10.53.0.1 nocookie.tsig >dig.out.test$n.2 || ret=1
grep "status: NOERROR" dig.out.test$n.3 >/dev/null || ret=1 grep "status: NOERROR" dig.out.test$n.2 >/dev/null || ret=1
grep 'A.10\.53\.0\.9' dig.out.test$n.3 >/dev/null || ret=1 grep 'A.10\.53\.0\.9' dig.out.test$n.2 >/dev/null || ret=1
grep 'A.10\.53\.0\.10' dig.out.test$n.3 >/dev/null || ret=1 grep 'A.10\.53\.0\.10' dig.out.test$n.2 >/dev/null || ret=1
nextpart ns1/named.run >named.run.test$n nextpart ns1/named.run >named.run.test$n
count=$(grep -c ') [0-9][0-9]* NOERROR 0' named.run.test$n) count=$(grep -c ') [0-9][0-9]* NOERROR 0' named.run.test$n)
test $count -eq 2 || ret=1 test $count -eq 2 || ret=1
count=$(grep -c '^; COOKIE: ................................' named.run.test$n)
test $count -eq 1 || ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=$((status + ret)) status=$((status + ret))
fi fi
@@ -19,7 +19,6 @@ pytestmark = pytest.mark.extra_artifacts(
"ans*/ans.run", "ans*/ans.run",
"ans*/query.log", "ans*/query.log",
"ns1/named_dump.db*", "ns1/named_dump.db*",
"ns4/named.cookiealwaysvalid",
] ]
) )
@@ -36,5 +36,4 @@ zone "example" {
zone "example.tld" { zone "example.tld" {
type primary; type primary;
file "example.tld.db"; file "example.tld.db";
provide-zoneversion no;
}; };
-77
View File
@@ -801,73 +801,6 @@ if [ -x "$DIG" ]; then
if [ $ret -ne 0 ]; then echo_i "failed"; fi if [ $ret -ne 0 ]; then echo_i "failed"; fi
status=$((status + ret)) status=$((status + ret))
n=$((n + 1))
echo_i "checking dig +zoneversion to a authoritative server ($n)"
ret=0
dig_with_opts @10.53.0.2 +zoneversion a.example >dig.out.test$n 2>&1 || ret=1
pat="; ZONEVERSION: ZONE: example, SOA-SERIAL: 2000042407"
grep "$pat" dig.out.test$n >/dev/null || ret=1
if [ $ret -ne 0 ]; then echo_i "failed"; fi
status=$((status + ret))
n=$((n + 1))
echo_i "checking dig +zoneversion to a authoritative server with zoneversion disabled ($n)"
ret=0
dig_with_opts @10.53.0.2 +zoneversion a.example.tld >dig.out.test$n 2>&1 || ret=1
grep "status: NOERROR" dig.out.test$n >/dev/null || ret=1
grep "; ZONEVERSION:" dig.out.test$n >/dev/null && ret=1
if [ $ret -ne 0 ]; then echo_i "failed"; fi
status=$((status + ret))
if [ $HAS_PYYAML -ne 0 ]; then
n=$((n + 1))
echo_i "checking dig +yaml +zoneversion to a authoritative server ($n)"
ret=0
dig_with_opts @10.53.0.2 +yaml +zoneversion a.example >dig.out.test$n 2>&1 || ret=1
$PYTHON yamlget.py dig.out.test$n 0 message response_message_data OPT_PSEUDOSECTION EDNS ZONEVERSION >yamlget.out.test$n 2>&1 || ret=1
read -r value <yamlget.out.test$n
expected="{'ZONE': 'example', 'SOA-SERIAL': 2000042407}"
[ "$value" = "$expected" ] || ret=1
if [ $ret -ne 0 ]; then echo_i "failed"; fi
status=$((status + ret))
fi
n=$((n + 1))
echo_i "checking dig +ednsopt=ZONEVERSION:<answer> to a authoritative server ($n)"
ret=0
dig_with_opts @10.53.0.2 +ednsopt=ZONEVERSION:0100000007DA a.example >dig.out.test$n 2>&1 || ret=1
grep "status: FORMERR" dig.out.test$n >/dev/null || ret=1
grep "; ZONEVERSION:" dig.out.test$n >/dev/null && ret=1
if [ $ret -ne 0 ]; then echo_i "failed"; fi
status=$((status + ret))
n=$((n + 1))
echo_i "checking dig +zoneversion to a recursive server ($n)"
ret=0
dig_with_opts @10.53.0.3 +zoneversion a.example >dig.out.test$n 2>&1 || ret=1
grep '; ZONEVERSION:' dig.out.test$n >/dev/null && ret=1
if [ $ret -ne 0 ]; then echo_i "failed"; fi
status=$((status + ret))
n=$((n + 1))
echo_i "checking display of non serial type zoneversion ($n)"
ret=0
dig_with_opts @10.53.0.2 +qr +ednsopt=ZONEVERSION:0100000007DA a.example >dig.out.test$n 2>&1 || ret=1
grep '; ZONEVERSION: LABELS: 1, TYPE: 0, VALUE: 000007da ("....")' dig.out.test$n >/dev/null && ret=1
if [ $ret -ne 0 ]; then echo_i "failed"; fi
status=$((status + ret))
if [ $HAS_PYYAML -ne 0 ]; then
n=$((n + 1))
echo_i "checking display of non serial type zoneversion +yaml ($n)"
ret=0
dig_with_opts @10.53.0.2 +qr +ednsopt=ZONEVERSION:0100000007DA a.example +yaml >dig.out.test$n 2>&1 || ret=1
$PYTHON yamlget.py dig.out.test$n 0 message query_message_data OPT_PSEUDOSECTION EDNS ZONEVERSION >yamlget.out.test$n 2>&1 || ret=1
expected="{'ZONE': 'example', 'TYPE': 1, 'VALUE': 000007da, PVALUE: '....'}"
if [ $ret -ne 0 ]; then echo_i "failed"; fi
status=$((status + ret))
fi
n=$((n + 1)) n=$((n + 1))
echo_i "check that dig gracefully handles bad escape in domain name ($n)" echo_i "check that dig gracefully handles bad escape in domain name ($n)"
ret=0 ret=0
@@ -1202,16 +1135,6 @@ if [ -x "$DIG" ]; then
grep "; EDNS: version: 0, flags:; udp: 1232" dig.out.test$n >/dev/null || ret=1 grep "; EDNS: version: 0, flags:; udp: 1232" dig.out.test$n >/dev/null || ret=1
if [ $ret -ne 0 ]; then echo_i "failed"; fi if [ $ret -ne 0 ]; then echo_i "failed"; fi
status=$((status + ret)) status=$((status + ret))
n=$((n + 1))
echo_i "check that dig +showbadvers works ($n)"
dig_with_opts @10.53.0.3 +edns=1 +qr +showbadvers a.example >dig.out.test$n 2>&1 || ret=1
grep "; EDNS: version: 1, flags:; udp: 1232" dig.out.test$n >/dev/null || ret=1
grep "; EDNS: version: 0, flags:; udp: 1232" dig.out.test$n >/dev/null || ret=1
grep -F "status: BADVERS" dig.out.test$n >/dev/null || ret=1
grep -F "status: NOERROR" dig.out.test$n >/dev/null || ret=1
if [ $ret -ne 0 ]; then echo_i "failed"; fi
status=$((status + ret))
else else
echo_i "$DIG is needed, so skipping these dig tests" echo_i "$DIG is needed, so skipping these dig tests"
fi fi
+1 -1
View File
@@ -64,7 +64,7 @@ for subdomain in digest-alg-unsupported ds-unsupported secure badds \
kskonly update-nsec3 auto-nsec auto-nsec3 secure.below-cname \ kskonly update-nsec3 auto-nsec auto-nsec3 secure.below-cname \
ttlpatch split-dnssec split-smart expired expiring upper lower \ ttlpatch split-dnssec split-smart expired expiring upper lower \
dnskey-unknown dnskey-unsupported dnskey-unsupported-2 \ dnskey-unknown dnskey-unsupported dnskey-unsupported-2 \
dnskey-nsec3-unknown managed-future future revkey \ dnskey-nsec3-unknown managed-future revkey \
dname-at-apex-nsec3 occluded rsasha1 rsasha1-1024; do dname-at-apex-nsec3 occluded rsasha1 rsasha1-1024; do
cp "../ns3/dsset-$subdomain.example." . cp "../ns3/dsset-$subdomain.example." .
done done
@@ -1,6 +0,0 @@
; This is a key-signing key, keyid 23640, for .
; Created: 20250310185208 (Mon Mar 10 18:52:08 2025)
; Publish: 20250310185208 (Mon Mar 10 18:52:08 2025)
; Activate: 20250310185208 (Mon Mar 10 18:52:08 2025)
; Revoke: 20250310185208 (Mon Mar 10 18:52:08 2025)
. IN DNSKEY 257 3 13 uKwpRtMH+9iuUk/Xj6LciIP5ZckaBtXaUqxUxzJYexXjvxGZGX4470Jv hq2NCI3HBZQNaCCP/h9sluhIzRGPTA==
@@ -1,7 +0,0 @@
Private-key-format: v1.3
Algorithm: 13 (ECDSAP256SHA256)
PrivateKey: m5udfGNSijISQ8Tfp4kx09O1em4PErLUw/mCj3SKmqw=
Created: 20250310185208
Publish: 20250310185208
Activate: 20250310185208
Revoke: 20250310185208
@@ -1,5 +0,0 @@
; This is a zone-signing key, keyid 23768, for .
; Created: 20250310185208 (Mon Mar 10 18:52:08 2025)
; Publish: 20250310185208 (Mon Mar 10 18:52:08 2025)
; Activate: 20250310185208 (Mon Mar 10 18:52:08 2025)
. IN DNSKEY 256 3 13 TFelYtTRBWeA9A307vvuWIcaNwW4txW4RgSELtsi46ZQs24ncRxmxtFf uJuPyVXePNiE4HNI9CIowGUsn5WuBw==
@@ -1,37 +0,0 @@
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
;
; SPDX-License-Identifier: MPL-2.0
;
; This Source Code Form is subject to the terms of the Mozilla Public
; License, v. 2.0. If a copy of the MPL was not distributed with this
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
;
; See the COPYRIGHT file distributed with this work for additional
; information regarding copyright ownership.
; This is a zone which has two DNSKEY records, both of which have
; existing private key files available. They should be loaded automatically
; and the zone correctly signed.
;
$TTL 30 ; 30 seconds
. IN SOA a.root.servers.nil. each.isc.org. (
2000042101 ; serial
600 ; refresh (10 minutes)
600 ; retry (10 minutes)
1200 ; expire (20 minutes)
600 ; minimum (10 minutes)
)
NS a.root-servers.nil.
DNSKEY 256 3 13 (
TFelYtTRBWeA9A307vvuWIcaNwW4txW4RgSELtsi46ZQ
s24ncRxmxtFfuJuPyVXePNiE4HNI9CIowGUsn5WuBw==
) ; ZSK; alg = ECDSAP256SHA256 ; key id = 23768
DNSKEY 257 3 13 (
OSmhpULEDCUzHCBeDU5uJXzkCcGuW2qrkQznKRPGhRZN
j7ZUIGInGzM5Um5m02ULWt8tKbi55NJUeifKWegQ0g==
) ; KSK; alg = ECDSAP256SHA256 ; key id = 22255
DNSKEY 385 3 13 (
uKwpRtMH+9iuUk/Xj6LciIP5ZckaBtXaUqxUxzJYexXj
vxGZGX4470Jvhq2NCI3HBZQNaCCP/h9sluhIzRGPTA==
) ; revoked KSK; alg = ECDSAP256SHA256 ; key id = 23768
a.root-servers.nil. A 10.53.0.1
+2 -27
View File
@@ -1564,18 +1564,6 @@ n=$((n + 1))
test "$ret" -eq 0 || echo_i "failed" test "$ret" -eq 0 || echo_i "failed"
status=$((status + ret)) status=$((status + ret))
echo_ic "revoked KSK ID collides with ZSK ($n)"
ret=0
# signing should fail, but should not coredump
(
cd signer/general || exit 0
rm -f signed.zone
$SIGNER -S -f signed.zone -o . test12.zone >signer.out.$n
) && ret=1
n=$((n + 1))
test "$ret" -eq 0 || echo_i "failed"
status=$((status + ret))
echo_ic "check that dnssec-signzone rejects excessive NSEC3 iterations ($n)" echo_ic "check that dnssec-signzone rejects excessive NSEC3 iterations ($n)"
ret=0 ret=0
( (
@@ -2191,7 +2179,7 @@ echo_i "checking RRSIG query from cache ($n)"
ret=0 ret=0
dig_with_opts normalthenrrsig.secure.example. @10.53.0.4 a >/dev/null || ret=1 dig_with_opts normalthenrrsig.secure.example. @10.53.0.4 a >/dev/null || ret=1
ans=$(dig_with_opts +short normalthenrrsig.secure.example. @10.53.0.4 rrsig) || ret=1 ans=$(dig_with_opts +short normalthenrrsig.secure.example. @10.53.0.4 rrsig) || ret=1
expect=$(dig_with_opts +short normalthenrrsig.secure.example. @10.53.0.3 rrsig | grep -E '^(A|NSEC)') || ret=1 expect=$(dig_with_opts +short normalthenrrsig.secure.example. @10.53.0.3 rrsig | grep '^A') || ret=1
test "$ans" = "$expect" || ret=1 test "$ans" = "$expect" || ret=1
# also check that RA is set # also check that RA is set
dig_with_opts normalthenrrsig.secure.example. @10.53.0.4 rrsig >dig.out.ns4.test$n || ret=1 dig_with_opts normalthenrrsig.secure.example. @10.53.0.4 rrsig >dig.out.ns4.test$n || ret=1
@@ -2871,19 +2859,6 @@ dig_with_opts +noauth expired.example. +dnssec @10.53.0.4 soa >dig.out.ns4.test$
grep "SERVFAIL" dig.out.ns4.test$n >/dev/null || ret=1 grep "SERVFAIL" dig.out.ns4.test$n >/dev/null || ret=1
grep "flags:.*ad.*QUERY" dig.out.ns4.test$n >/dev/null && ret=1 grep "flags:.*ad.*QUERY" dig.out.ns4.test$n >/dev/null && ret=1
grep "expired.example/.*: RRSIG has expired" ns4/named.run >/dev/null || ret=1 grep "expired.example/.*: RRSIG has expired" ns4/named.run >/dev/null || ret=1
grep "; EDE: 7 (Signature Expired): (expired.example/DNSKEY)" dig.out.ns4.test$n >/dev/null || ret=1
n=$((n + 1))
test "$ret" -eq 0 || echo_i "failed"
status=$((status + ret))
status=$((status + ret))
echo_i "checking signatures in the future do not validate ($n)"
ret=0
dig_with_opts +noauth future.example. +dnssec @10.53.0.4 soa >dig.out.ns4.test$n || ret=1
grep "SERVFAIL" dig.out.ns4.test$n >/dev/null || ret=1
grep "flags:.*ad.*QUERY" dig.out.ns4.test$n >/dev/null && ret=1
grep "future.example/.*: RRSIG validity period has not begun" ns4/named.run >/dev/null || ret=1
grep "; EDE: 8 (Signature Not Yet Valid): (future.example/DNSKEY)" dig.out.ns4.test$n >/dev/null || ret=1
n=$((n + 1)) n=$((n + 1))
test "$ret" -eq 0 || echo_i "failed" test "$ret" -eq 0 || echo_i "failed"
status=$((status + ret)) status=$((status + ret))
@@ -3780,7 +3755,7 @@ status=$((status + ret))
echo_i "checking EDE code 1 for bad alg mnemonic ($n)" echo_i "checking EDE code 1 for bad alg mnemonic ($n)"
ret=0 ret=0
dig_with_opts @10.53.0.4 badalg.secure.example >dig.out.ns4.test$n || ret=1 dig_with_opts @10.53.0.4 badalg.secure.example >dig.out.ns4.test$n || ret=1
grep "; EDE: 1 (Unsupported DNSKEY Algorithm): (ECDSAP256SHA256 badalg.secure.example/NSEC)" dig.out.ns4.test$n >/dev/null || ret=1 grep "; EDE: 1 (Unsupported DNSKEY Algorithm): (ECDSAP256SHA256 badalg.secure.example/A)" dig.out.ns4.test$n >/dev/null || ret=1
grep "flags:.*ad.*QUERY" dig.out.ns4.test$n >/dev/null && ret=1 grep "flags:.*ad.*QUERY" dig.out.ns4.test$n >/dev/null && ret=1
n=$((n + 1)) n=$((n + 1))
test "$ret" -eq 0 || echo_i "failed" test "$ret" -eq 0 || echo_i "failed"
+6 -2
View File
@@ -232,7 +232,9 @@ addrdataset(dns_db_t *db, dns_dbnode_t *node, dns_dbversion_t *version,
dns_fixedname_init(&name); dns_fixedname_init(&name);
CHECK(dns__db_addrdataset(sampledb->db, node, version, now, rdataset, CHECK(dns__db_addrdataset(sampledb->db, node, version, now, rdataset,
options, addedrdataset DNS__DB_FLARG_PASS)); options, addedrdataset DNS__DB_FLARG_PASS));
if (dns_rdatatype_isaddr(rdataset->type)) { if (rdataset->type == dns_rdatatype_a ||
rdataset->type == dns_rdatatype_aaaa)
{
CHECK(dns_db_nodefullname(sampledb->db, node, CHECK(dns_db_nodefullname(sampledb->db, node,
dns_fixedname_name(&name))); dns_fixedname_name(&name)));
CHECK(syncptrs(sampledb->inst, dns_fixedname_name(&name), CHECK(syncptrs(sampledb->inst, dns_fixedname_name(&name),
@@ -261,7 +263,9 @@ subtractrdataset(dns_db_t *db, dns_dbnode_t *node, dns_dbversion_t *version,
goto cleanup; goto cleanup;
} }
if (dns_rdatatype_isaddr(rdataset->type)) { if (rdataset->type == dns_rdatatype_a ||
rdataset->type == dns_rdatatype_aaaa)
{
CHECK(dns_db_nodefullname(sampledb->db, node, CHECK(dns_db_nodefullname(sampledb->db, node,
dns_fixedname_name(&name))); dns_fixedname_name(&name)));
CHECK(syncptrs(sampledb->inst, dns_fixedname_name(&name), CHECK(syncptrs(sampledb->inst, dns_fixedname_name(&name),
+3 -3
View File
@@ -23,7 +23,7 @@
#include <openssl/provider.h> #include <openssl/provider.h>
#endif #endif
#include <isc/crypto.h> #include <isc/fips.h>
#include <isc/lib.h> #include <isc/lib.h>
#include <isc/md.h> #include <isc/md.h>
#include <isc/mem.h> #include <isc/mem.h>
@@ -134,7 +134,7 @@ main(int argc, char **argv) {
return 1; return 1;
#endif #endif
#else #else
if (isc_crypto_fips_mode()) { if (isc_fips_mode()) {
#if OPENSSL_VERSION_NUMBER >= 0x30000000L #if OPENSSL_VERSION_NUMBER >= 0x30000000L
return 0; return 0;
#else #else
@@ -149,7 +149,7 @@ main(int argc, char **argv) {
#if defined(ENABLE_FIPS_MODE) #if defined(ENABLE_FIPS_MODE)
return 0; return 0;
#else #else
return isc_crypto_fips_mode() ? 0 : 1; return isc_fips_mode() ? 0 : 1;
#endif #endif
} }
@@ -1,52 +0,0 @@
/*
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
*
* SPDX-License-Identifier: MPL-2.0
*
* This Source Code Form is subject to the terms of the Mozilla Public
* License, v. 2.0. If a copy of the MPL was not distributed with this
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
*
* See the COPYRIGHT file distributed with this work for additional
* information regarding copyright ownership.
*/
options {
query-source address 10.53.0.5;
notify-source 10.53.0.5;
transfer-source 10.53.0.5;
port @PORT@;
directory ".";
pid-file "named.pid";
listen-on { 10.53.0.5; };
listen-on-v6 { none; };
recursion yes;
dnssec-validation yes;
notify yes;
stale-answer-enable yes;
stale-cache-enable yes;
stale-answer-client-timeout 0;
/* max-clients-per-query < clients-per-query */
clients-per-query 10;
max-clients-per-query 5;
};
trust-anchors { };
server 10.53.0.4 {
edns no;
};
key rndc_key {
secret "1234abcd8765";
algorithm @DEFAULT_HMAC@;
};
controls {
inet 10.53.0.5 port @CONTROLPORT@ allow { any; } keys { rndc_key; };
};
zone "." {
type hint;
file "root.hint";
};
-9
View File
@@ -328,14 +328,5 @@ echo_i "$zspill clients spilled (expected $expected)"
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=$((status + ret)) status=$((status + ret))
n=$((n + 1))
echo_i "checking a warning is logged if max-clients-per-query < clients-per-query ($n)"
ret=0
copy_setports ns5/named3.conf.in ns5/named.conf
rndc_reconfig ns5 10.53.0.5
wait_for_message ns5/named.run "configured clients-per-query (10) exceeds max-clients-per-query (5); automatically adjusting max-clients-per-query to (10)" || ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi
status=$((status + ret))
echo_i "exit status: $status" echo_i "exit status: $status"
[ $status -eq 0 ] || exit 1 [ $status -eq 0 ] || exit 1
+35 -103
View File
@@ -224,20 +224,6 @@ class DnsProtocol(enum.Enum):
TCP = enum.auto() TCP = enum.auto()
@dataclass(frozen=True)
class Peer:
"""
Pretty-printed connection endpoint.
"""
host: str
port: int
def __str__(self) -> str:
host = f"[{self.host}]" if ":" in self.host else self.host
return f"{host}:{self.port}"
@dataclass @dataclass
class QueryContext: class QueryContext:
""" """
@@ -246,7 +232,7 @@ class QueryContext:
query: dns.message.Message query: dns.message.Message
response: dns.message.Message response: dns.message.Message
peer: Peer peer: Tuple[str, int]
protocol: DnsProtocol protocol: DnsProtocol
zone: Optional[dns.zone.Zone] = None zone: Optional[dns.zone.Zone] = None
soa: Optional[dns.rrset.RRset] = None soa: Optional[dns.rrset.RRset] = None
@@ -527,110 +513,56 @@ class AsyncDnsServer(AsyncServer):
self._zone_tree.add(zone) self._zone_tree.add(zone)
async def _handle_udp( async def _handle_udp(
self, wire: bytes, addr: Tuple[str, int], transport: asyncio.DatagramTransport self, wire: bytes, peer: Tuple[str, int], transport: asyncio.DatagramTransport
) -> None: ) -> None:
logging.debug("Received UDP message: %s", wire.hex()) logging.debug("Received UDP message: %s", wire.hex())
peer = Peer(addr[0], addr[1])
responses = self._handle_query(wire, peer, DnsProtocol.UDP) responses = self._handle_query(wire, peer, DnsProtocol.UDP)
async for response in responses: async for response in responses:
transport.sendto(response, addr) transport.sendto(response, peer)
async def _handle_tcp( async def _handle_tcp(
self, reader: asyncio.StreamReader, writer: asyncio.StreamWriter self, reader: asyncio.StreamReader, writer: asyncio.StreamWriter
) -> None: ) -> None:
peer_info = writer.get_extra_info("peername") wire_length_bytes = await reader.read(2)
peer = Peer(peer_info[0], peer_info[1])
logging.debug("Accepted TCP connection from %s", peer)
while True:
try:
wire = await self._read_tcp_query(reader, peer)
if not wire:
break
await self._send_tcp_response(writer, peer, wire)
except ConnectionResetError:
logging.error("TCP connection from %s reset by peer", peer)
return
logging.debug("Closing TCP connection from %s", peer)
writer.close()
await writer.wait_closed()
async def _read_tcp_query(
self, reader: asyncio.StreamReader, peer: Peer
) -> Optional[bytes]:
wire_length = await self._read_tcp_query_wire_length(reader, peer)
if not wire_length:
return None
return await self._read_tcp_query_wire(reader, peer, wire_length)
async def _read_tcp_query_wire_length(
self, reader: asyncio.StreamReader, peer: Peer
) -> Optional[int]:
logging.debug("Receiving TCP message length from %s...", peer)
wire_length_bytes = await self._read_tcp_octets(reader, peer, 2)
if not wire_length_bytes:
return None
(wire_length,) = struct.unpack("!H", wire_length_bytes) (wire_length,) = struct.unpack("!H", wire_length_bytes)
logging.debug("Receiving TCP message (%d octets)...", wire_length)
return wire_length wire = await reader.read(wire_length)
full_message = wire_length_bytes + wire
logging.debug("Received complete TCP message: %s", full_message.hex())
async def _read_tcp_query_wire( peer = writer.get_extra_info("peername")
self, reader: asyncio.StreamReader, peer: Peer, wire_length: int
) -> Optional[bytes]:
logging.debug("Receiving TCP message (%d octets) from %s...", wire_length, peer)
wire = await self._read_tcp_octets(reader, peer, wire_length)
if not wire:
return None
logging.debug("Received complete TCP message from %s: %s", peer, wire.hex())
return wire
async def _read_tcp_octets(
self, reader: asyncio.StreamReader, peer: Peer, expected: int
) -> Optional[bytes]:
buffer = b""
while len(buffer) < expected:
chunk = await reader.read(expected - len(buffer))
if not chunk:
if buffer:
logging.debug(
"Received short TCP message (%d octets) from %s: %s",
len(buffer),
peer,
buffer.hex(),
)
else:
logging.debug("Received disconnect from %s", peer)
return None
logging.debug("Received %d TCP octets from %s", len(chunk), peer)
buffer += chunk
return buffer
async def _send_tcp_response(
self, writer: asyncio.StreamWriter, peer: Peer, wire: bytes
) -> None:
responses = self._handle_query(wire, peer, DnsProtocol.TCP) responses = self._handle_query(wire, peer, DnsProtocol.TCP)
async for response in responses: async for response in responses:
writer.write(response) writer.write(response)
await writer.drain() try:
await writer.drain()
except ConnectionResetError:
logging.error(
"TCP connection from %s reset by peer", self._format_peer(peer)
)
return
def _log_query(self, qctx: QueryContext, peer: Peer, protocol: DnsProtocol) -> None: writer.close()
await writer.wait_closed()
def _format_peer(self, peer: Tuple[str, int]) -> str:
host = peer[0]
port = peer[1]
if "::" in host:
host = f"[{host}]"
return f"{host}:{port}"
def _log_query(
self, qctx: QueryContext, peer: Tuple[str, int], protocol: DnsProtocol
) -> None:
logging.info( logging.info(
"Received %s/%s/%s (ID=%d) query from %s (%s)", "Received %s/%s/%s (ID=%d) query from %s (%s)",
qctx.qname.to_text(omit_final_dot=True), qctx.qname.to_text(omit_final_dot=True),
dns.rdataclass.to_text(qctx.qclass), dns.rdataclass.to_text(qctx.qclass),
dns.rdatatype.to_text(qctx.qtype), dns.rdatatype.to_text(qctx.qtype),
qctx.query.id, qctx.query.id,
peer, self._format_peer(peer),
protocol.name, protocol.name,
) )
logging.debug( logging.debug(
@@ -641,14 +573,14 @@ class AsyncDnsServer(AsyncServer):
self, self,
qctx: QueryContext, qctx: QueryContext,
response: Optional[Union[dns.message.Message, bytes]], response: Optional[Union[dns.message.Message, bytes]],
peer: Peer, peer: Tuple[str, int],
protocol: DnsProtocol, protocol: DnsProtocol,
) -> None: ) -> None:
if not response: if not response:
logging.info( logging.info(
"Not sending a response to query (ID=%d) from %s (%s)", "Not sending a response to query (ID=%d) from %s (%s)",
qctx.query.id, qctx.query.id,
peer, self._format_peer(peer),
protocol.name, protocol.name,
) )
return return
@@ -674,7 +606,7 @@ class AsyncDnsServer(AsyncServer):
len(response.authority), len(response.authority),
len(response.additional), len(response.additional),
qctx.query.id, qctx.query.id,
peer, self._format_peer(peer),
protocol.name, protocol.name,
) )
logging.debug( logging.debug(
@@ -686,13 +618,13 @@ class AsyncDnsServer(AsyncServer):
"Sending response (%d bytes) to a query (ID=%d) from %s (%s)", "Sending response (%d bytes) to a query (ID=%d) from %s (%s)",
len(response), len(response),
qctx.query.id, qctx.query.id,
peer, self._format_peer(peer),
protocol.name, protocol.name,
) )
logging.debug("[OUT] %s", response.hex()) logging.debug("[OUT] %s", response.hex())
async def _handle_query( async def _handle_query(
self, wire: bytes, peer: Peer, protocol: DnsProtocol self, wire: bytes, peer: Tuple[str, int], protocol: DnsProtocol
) -> AsyncGenerator[bytes, None]: ) -> AsyncGenerator[bytes, None]:
""" """
Yield wire data to send as a response over the established transport. Yield wire data to send as a response over the established transport.
+7 -6
View File
@@ -130,7 +130,7 @@ $KEYGEN -G -k rsasha256 -l policies/kasp.conf $zone >keygen.out.$zone.2 2>&1
zone="multisigner-model2.kasp" zone="multisigner-model2.kasp"
echo_i "setting up zone: $zone" echo_i "setting up zone: $zone"
KSK=$($KEYGEN -a $DEFAULT_ALGORITHM -f KSK -L 3600 -M 32768:65535 $zone 2>keygen.out.$zone.1) KSK=$($KEYGEN -a $DEFAULT_ALGORITHM -f KSK -L 3600 -M 32768:65535 $zone 2>keygen.out.$zone.1)
ZSK=$($KEYGEN -a $DEFAULT_ALGORITHM -L 3600 -M 32768:65535 $zone 2>keygen.out.$zone.2) ZSK=$($KEYGEN -a $DEFAULT_ALGORITHM -L 3600 $zone -M 32768:65535 2>keygen.out.$zone.2)
cat "${KSK}.key" | grep -v ";.*" >>"${zone}.db" cat "${KSK}.key" | grep -v ";.*" >>"${zone}.db"
cat "${ZSK}.key" | grep -v ";.*" >>"${zone}.db" cat "${ZSK}.key" | grep -v ";.*" >>"${zone}.db"
# Import the ZSK sets of the other providers into their DNSKEY RRset. # Import the ZSK sets of the other providers into their DNSKEY RRset.
@@ -350,9 +350,10 @@ setup step2.enable-dnssec.autosign
TpubN="now-900s" TpubN="now-900s"
# RRSIG TTL: 12 hour (43200 seconds) # RRSIG TTL: 12 hour (43200 seconds)
# zone-propagation-delay: 5 minutes (300 seconds) # zone-propagation-delay: 5 minutes (300 seconds)
# retire-safety: 20 minutes (1200 seconds)
# Already passed time: -900 seconds # Already passed time: -900 seconds
# Total: 42600 seconds # Total: 43800 seconds
TsbmN="now+42600s" TsbmN="now+43800s"
keytimes="-P ${TpubN} -P sync ${TsbmN} -A ${TpubN}" keytimes="-P ${TpubN} -P sync ${TsbmN} -A ${TpubN}"
CSK=$($KEYGEN -k enable-dnssec -l policies/autosign.conf $keytimes $zone 2>keygen.out.$zone.1) CSK=$($KEYGEN -k enable-dnssec -l policies/autosign.conf $keytimes $zone 2>keygen.out.$zone.1)
$SETTIME -s -g $O -k $R $TpubN -r $R $TpubN -d $H $TpubN -z $R $TpubN "$CSK" >settime.out.$zone.1 2>&1 $SETTIME -s -g $O -k $R $TpubN -r $R $TpubN -d $H $TpubN -z $R $TpubN "$CSK" >settime.out.$zone.1 2>&1
@@ -364,10 +365,10 @@ $SIGNER -S -z -x -s now-1h -e now+30d -o $zone -O raw -f "${zonefile}.signed" $i
# Step 3: # Step 3:
# The zone signatures have been published long enough to become OMNIPRESENT. # The zone signatures have been published long enough to become OMNIPRESENT.
setup step3.enable-dnssec.autosign setup step3.enable-dnssec.autosign
# Passed time since publications: 42600 + 900 = 43500 seconds. # Passed time since publications: 43800 + 900 = 44700 seconds.
TpubN="now-43500s" TpubN="now-44700s"
# The key is secure for using in chain of trust when the DNSKEY is OMNIPRESENT. # The key is secure for using in chain of trust when the DNSKEY is OMNIPRESENT.
TcotN="now-42600s" TcotN="now-43800s"
# We can submit the DS now. # We can submit the DS now.
TsbmN="now" TsbmN="now"
keytimes="-P ${TpubN} -P sync ${TsbmN} -A ${TpubN}" keytimes="-P ${TpubN} -P sync ${TsbmN} -A ${TpubN}"
+41 -41
View File
@@ -127,9 +127,9 @@ setup step2.algorithm-roll.kasp
# The time passed since the new algorithm keys have been introduced is 3 hours. # The time passed since the new algorithm keys have been introduced is 3 hours.
TactN="now-3h" TactN="now-3h"
TpubN1="now-3h" TpubN1="now-3h"
# Tsbm(N+1) = TpubN1 + Ipub = now + TTLsig + Dprp = # Tsbm(N+1) = TpubN1 + Ipub = now + TTLsig + Dprp + publish-safety =
# now - 3h + 6h + 1h = now + 4h # now - 3h + 6h + 1h + 1h = now + 5h
TsbmN1="now+4h" TsbmN1="now+5h"
ksk1times="-P ${TactN} -A ${TactN} -P sync ${TactN} -I now" ksk1times="-P ${TactN} -A ${TactN} -P sync ${TactN} -I now"
zsk1times="-P ${TactN} -A ${TactN} -I now" zsk1times="-P ${TactN} -A ${TactN} -I now"
ksk2times="-P ${TpubN1} -A ${TpubN1} -P sync ${TsbmN1}" ksk2times="-P ${TpubN1} -A ${TpubN1} -P sync ${TsbmN1}"
@@ -156,11 +156,11 @@ $SIGNER -S -x -s now-1h -e now+2w -o $zone -O raw -f "${zonefile}.signed" $infil
# Step 3: # Step 3:
# The zone signatures are also OMNIPRESENT. # The zone signatures are also OMNIPRESENT.
setup step3.algorithm-roll.kasp setup step3.algorithm-roll.kasp
# The time passed since the new algorithm keys have been introduced is 7 hours. # The time passed since the new algorithm keys have been introduced is 9 hours.
TactN="now-7h" TactN="now-9h"
TretN="now-3h" TretN="now-6h"
TpubN1="now-7h" TpubN1="now-9h"
TsbmN1="now" TsbmN1="now-1h"
ksk1times="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}" ksk1times="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
zsk1times="-P ${TactN} -A ${TactN} -I ${TretN}" zsk1times="-P ${TactN} -A ${TactN} -I ${TretN}"
ksk2times="-P ${TpubN1} -A ${TpubN1} -P sync ${TsbmN1}" ksk2times="-P ${TpubN1} -A ${TpubN1} -P sync ${TsbmN1}"
@@ -188,11 +188,11 @@ $SIGNER -S -x -s now-1h -e now+2w -o $zone -O raw -f "${zonefile}.signed" $infil
# The DS is swapped and can become OMNIPRESENT. # The DS is swapped and can become OMNIPRESENT.
setup step4.algorithm-roll.kasp setup step4.algorithm-roll.kasp
# The time passed since the DS has been swapped is 29 hours. # The time passed since the DS has been swapped is 29 hours.
TactN="now-36h" TactN="now-38h"
TretN="now-33h" TretN="now-35h"
TpubN1="now-36h" TpubN1="now-38h"
TsbmN1="now-29h" TsbmN1="now-30h"
TactN1="now-27h" TactN1="now-29h"
ksk1times="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}" ksk1times="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
zsk1times="-P ${TactN} -A ${TactN} -I ${TretN}" zsk1times="-P ${TactN} -A ${TactN} -I ${TretN}"
ksk2times="-P ${TpubN1} -A ${TpubN1} -P sync ${TsbmN1}" ksk2times="-P ${TpubN1} -A ${TpubN1} -P sync ${TsbmN1}"
@@ -220,12 +220,12 @@ $SIGNER -S -x -s now-1h -e now+2w -o $zone -O raw -f "${zonefile}.signed" $infil
# The DNSKEY is removed long enough to be HIDDEN. # The DNSKEY is removed long enough to be HIDDEN.
setup step5.algorithm-roll.kasp setup step5.algorithm-roll.kasp
# The time passed since the DNSKEY has been removed is 2 hours. # The time passed since the DNSKEY has been removed is 2 hours.
TactN="now-38h" TactN="now-40h"
TretN="now-35h" TretN="now-37h"
TremN="now-2h" TremN="now-2h"
TpubN1="now-38h" TpubN1="now-40h"
TsbmN1="now-31h" TsbmN1="now-32h"
TactN1="now-29h" TactN1="now-31h"
ksk1times="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}" ksk1times="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
zsk1times="-P ${TactN} -A ${TactN} -I ${TretN}" zsk1times="-P ${TactN} -A ${TactN} -I ${TretN}"
ksk2times="-P ${TpubN1} -A ${TpubN1} -P sync ${TsbmN1}" ksk2times="-P ${TpubN1} -A ${TpubN1} -P sync ${TsbmN1}"
@@ -253,13 +253,13 @@ $SIGNER -S -x -s now-1h -e now+2w -o $zone -O raw -f "${zonefile}.signed" $infil
# The RRSIGs have been removed long enough to be HIDDEN. # The RRSIGs have been removed long enough to be HIDDEN.
setup step6.algorithm-roll.kasp setup step6.algorithm-roll.kasp
# Additional time passed: 7h. # Additional time passed: 7h.
TactN="now-45h" TactN="now-47h"
TretN="now-42h" TretN="now-44h"
TremN="now-7h" TremN="now-7h"
TpubN1="now-45h" TpubN1="now-47h"
TsbmN1="now-38h" TsbmN1="now-39h"
TactN1="now-36h" TactN1="now-38h"
TdeaN="now-7h" TdeaN="now-9h"
ksk1times="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}" ksk1times="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
zsk1times="-P ${TactN} -A ${TactN} -I ${TretN}" zsk1times="-P ${TactN} -A ${TactN} -I ${TretN}"
ksk2times="-P ${TpubN1} -A ${TpubN1} -P sync ${TsbmN1}" ksk2times="-P ${TpubN1} -A ${TpubN1} -P sync ${TsbmN1}"
@@ -324,11 +324,11 @@ $SIGNER -S -x -z -s now-1h -e now+2w -o $zone -O raw -f "${zonefile}.signed" $in
# Step 3: # Step 3:
# The zone signatures are also OMNIPRESENT. # The zone signatures are also OMNIPRESENT.
setup step3.csk-algorithm-roll.kasp setup step3.csk-algorithm-roll.kasp
# The time passed since the new algorithm keys have been introduced is 7 hours. # The time passed since the new algorithm keys have been introduced is 9 hours.
TactN="now-7h" TactN="now-9h"
TretN="now-3h" TretN="now-6h"
TpubN1="now-7h" TpubN1="now-9h"
TactN1="now-3h" TactN1="now-6h"
csktimes="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}" csktimes="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
newtimes="-P ${TpubN1} -A ${TpubN1}" newtimes="-P ${TpubN1} -A ${TpubN1}"
CSK1=$($KEYGEN -k csk-algoroll -l policies/csk1.conf $csktimes $zone 2>keygen.out.$zone.1) CSK1=$($KEYGEN -k csk-algoroll -l policies/csk1.conf $csktimes $zone 2>keygen.out.$zone.1)
@@ -347,10 +347,10 @@ $SIGNER -S -x -z -s now-1h -e now+2w -o $zone -O raw -f "${zonefile}.signed" $in
# The DS is swapped and can become OMNIPRESENT. # The DS is swapped and can become OMNIPRESENT.
setup step4.csk-algorithm-roll.kasp setup step4.csk-algorithm-roll.kasp
# The time passed since the DS has been swapped is 29 hours. # The time passed since the DS has been swapped is 29 hours.
TactN="now-36h" TactN="now-38h"
TretN="now-33h" TretN="now-35h"
TpubN1="now-36h" TpubN1="now-38h"
TactN1="now-33h" TactN1="now-35h"
TsubN1="now-29h" TsubN1="now-29h"
csktimes="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}" csktimes="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
newtimes="-P ${TpubN1} -A ${TpubN1}" newtimes="-P ${TpubN1} -A ${TpubN1}"
@@ -370,11 +370,11 @@ $SIGNER -S -x -z -s now-1h -e now+2w -o $zone -O raw -f "${zonefile}.signed" $in
# The DNSKEY is removed long enough to be HIDDEN. # The DNSKEY is removed long enough to be HIDDEN.
setup step5.csk-algorithm-roll.kasp setup step5.csk-algorithm-roll.kasp
# The time passed since the DNSKEY has been removed is 2 hours. # The time passed since the DNSKEY has been removed is 2 hours.
TactN="now-38h" TactN="now-40h"
TretN="now-35h" TretN="now-37h"
TremN="now-2h" TremN="now-2h"
TpubN1="now-38h" TpubN1="now-40h"
TactN1="now-35h" TactN1="now-37h"
TsubN1="now-31h" TsubN1="now-31h"
csktimes="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}" csktimes="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
newtimes="-P ${TpubN1} -A ${TpubN1}" newtimes="-P ${TpubN1} -A ${TpubN1}"
@@ -394,12 +394,12 @@ $SIGNER -S -x -z -s now-1h -e now+2w -o $zone -O raw -f "${zonefile}.signed" $in
# The RRSIGs have been removed long enough to be HIDDEN. # The RRSIGs have been removed long enough to be HIDDEN.
setup step6.csk-algorithm-roll.kasp setup step6.csk-algorithm-roll.kasp
# Additional time passed: 7h. # Additional time passed: 7h.
TactN="now-45h" TactN="now-47h"
TretN="now-42h" TretN="now-44h"
TdeaN="now-9h" TdeaN="now-9h"
TremN="now-7h" TremN="now-7h"
TpubN1="now-45h" TpubN1="now-47h"
TactN1="now-42h" TactN1="now-44h"
TsubN1="now-38h" TsubN1="now-38h"
csktimes="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}" csktimes="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
newtimes="-P ${TpubN1} -A ${TpubN1}" newtimes="-P ${TpubN1} -A ${TpubN1}"
+125 -120
View File
@@ -275,8 +275,9 @@ set_keytimes_csk_policy() {
set_keytime "KEY1" "ACTIVE" "${created}" set_keytime "KEY1" "ACTIVE" "${created}"
# The DS can be published if the DNSKEY and RRSIG records are # The DS can be published if the DNSKEY and RRSIG records are
# OMNIPRESENT. This happens after max-zone-ttl (1d) plus # OMNIPRESENT. This happens after max-zone-ttl (1d) plus
# zone-propagation-delay (300s) = 86400 + 300 = 86700. # publish-safety (1h) plus zone-propagation-delay (300s) =
set_addkeytime "KEY1" "SYNCPUBLISH" "${created}" 86700 # 86400 + 3600 + 300 = 90300.
set_addkeytime "KEY1" "SYNCPUBLISH" "${created}" 90300
# Key lifetime is unlimited, so not setting RETIRED and REMOVED. # Key lifetime is unlimited, so not setting RETIRED and REMOVED.
} }
@@ -768,8 +769,9 @@ set_keytimes_algorithm_policy() {
# The DS can be published if the DNSKEY and RRSIG records are # The DS can be published if the DNSKEY and RRSIG records are
# OMNIPRESENT. This happens after max-zone-ttl (1d) plus # OMNIPRESENT. This happens after max-zone-ttl (1d) plus
# zone-propagation-delay (300s) = 86400 + 300 = 86700. # publish-safety (1h) plus zone-propagation-delay (300s) =
set_addkeytime "KEY1" "SYNCPUBLISH" "${published}" 86700 # 86400 + 3600 + 300 = 90300.
set_addkeytime "KEY1" "SYNCPUBLISH" "${published}" 90300
# Key lifetime is 10 years, 315360000 seconds. # Key lifetime is 10 years, 315360000 seconds.
set_addkeytime "KEY1" "RETIRED" "${published}" 315360000 set_addkeytime "KEY1" "RETIRED" "${published}" 315360000
# The key is removed after the retire time plus DS TTL (1d), # The key is removed after the retire time plus DS TTL (1d),
@@ -1718,10 +1720,10 @@ published=$(awk '{print $3}' <published.test${n}.key1)
set_keytime "KEY1" "PUBLISHED" "${published}" set_keytime "KEY1" "PUBLISHED" "${published}"
set_keytime "KEY1" "ACTIVE" "${published}" set_keytime "KEY1" "ACTIVE" "${published}"
published=$(key_get KEY1 PUBLISHED) published=$(key_get KEY1 PUBLISHED)
# The DS can be published if the zone is fully signed. # The DS can be published if the DNSKEY and RRSIG records are OMNIPRESENT.
# This happens after max-zone-ttl (1d) plus # This happens after max-zone-ttl (1d) plus publish-safety (1h) plus
# zone-propagation-delay (300s) = 86400 + 300 = 86700. # zone-propagation-delay (300s) = 86400 + 3600 + 300 = 90300.
set_addkeytime "KEY1" "SYNCPUBLISH" "${published}" 86700 set_addkeytime "KEY1" "SYNCPUBLISH" "${published}" 90300
# Key lifetime is 6 months, 315360000 seconds. # Key lifetime is 6 months, 315360000 seconds.
set_addkeytime "KEY1" "RETIRED" "${published}" 16070400 set_addkeytime "KEY1" "RETIRED" "${published}" 16070400
# The key is removed after the retire time plus DS TTL (1d), parent # The key is removed after the retire time plus DS TTL (1d), parent
@@ -2484,9 +2486,9 @@ set_keytime "KEY1" "PUBLISHED" "${created}"
set_keytime "KEY1" "ACTIVE" "${created}" set_keytime "KEY1" "ACTIVE" "${created}"
# - The DS can be published if the DNSKEY and RRSIG records are # - The DS can be published if the DNSKEY and RRSIG records are
# OMNIPRESENT. This happens after max-zone-ttl (12h) plus # OMNIPRESENT. This happens after max-zone-ttl (12h) plus
# plus zone-propagation-delay (5m) = # publish-safety (5m) plus zone-propagation-delay (5m) =
# 43200 + 300 = 43500. # 43200 + 300 + 300 = 43800.
set_addkeytime "KEY1" "SYNCPUBLISH" "${created}" 43500 set_addkeytime "KEY1" "SYNCPUBLISH" "${created}" 43800
# - Key lifetime is unlimited, so not setting RETIRED and REMOVED. # - Key lifetime is unlimited, so not setting RETIRED and REMOVED.
# Various signing policy checks. # Various signing policy checks.
@@ -2554,7 +2556,7 @@ check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
created=$(key_get KEY1 CREATED) created=$(key_get KEY1 CREATED)
set_addkeytime "KEY1" "PUBLISHED" "${created}" -900 set_addkeytime "KEY1" "PUBLISHED" "${created}" -900
set_addkeytime "KEY1" "ACTIVE" "${created}" -900 set_addkeytime "KEY1" "ACTIVE" "${created}" -900
set_addkeytime "KEY1" "SYNCPUBLISH" "${created}" 42600 set_addkeytime "KEY1" "SYNCPUBLISH" "${created}" 43800
# Continue signing policy checks. # Continue signing policy checks.
check_keytimes check_keytimes
@@ -2564,8 +2566,8 @@ dnssec_verify
# Next key event is when the zone signatures become OMNIPRESENT: max-zone-ttl # Next key event is when the zone signatures become OMNIPRESENT: max-zone-ttl
# plus zone propagation delay plus retire safety minus the already elapsed # plus zone propagation delay plus retire safety minus the already elapsed
# 900 seconds: 12h + 300s + 20m - 900 = 43500 - 900 = 42600 seconds # 900 seconds: 12h + 300s + 20m - 900 = 44700 - 900 = 43800 seconds
check_next_key_event 42600 check_next_key_event 43800
# #
# Zone: step3.enable-dnssec.autosign. # Zone: step3.enable-dnssec.autosign.
@@ -2582,10 +2584,10 @@ check_keys
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE" check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
# Set expected key times: # Set expected key times:
# - The key was published and activated 43500 seconds ago (with settime). # - The key was published and activated 44700 seconds ago (with settime).
created=$(key_get KEY1 CREATED) created=$(key_get KEY1 CREATED)
set_addkeytime "KEY1" "PUBLISHED" "${created}" -43500 set_addkeytime "KEY1" "PUBLISHED" "${created}" -44700
set_addkeytime "KEY1" "ACTIVE" "${created}" -43500 set_addkeytime "KEY1" "ACTIVE" "${created}" -44700
set_keytime "KEY1" "SYNCPUBLISH" "${created}" set_keytime "KEY1" "SYNCPUBLISH" "${created}"
# Continue signing policy checks. # Continue signing policy checks.
@@ -2601,8 +2603,8 @@ check_cdslog "$DIR" "$ZONE" KEY1
rndc_checkds "$SERVER" "$DIR" KEY1 "now" "published" "$ZONE" rndc_checkds "$SERVER" "$DIR" KEY1 "now" "published" "$ZONE"
# Next key event is when the DS can move to the OMNIPRESENT state. This occurs # Next key event is when the DS can move to the OMNIPRESENT state. This occurs
# when the parent propagation delay have passed, plus the DS TTL and retire # when the parent propagation delay have passed, plus the DS TTL and retire
# safety delay: 1h + 2h = 3h = 10800 seconds # safety delay: 1h + 2h + 20m = 3h20m = 12000 seconds
check_next_key_event 10800 check_next_key_event 12000
# #
# Zone: step4.enable-dnssec.autosign. # Zone: step4.enable-dnssec.autosign.
@@ -4386,9 +4388,9 @@ check_subdomain
dnssec_verify dnssec_verify
# Next key event is when the DS becomes HIDDEN. This happens after the # Next key event is when the DS becomes HIDDEN. This happens after the
# parent propagation delay, and DS TTL: # parent propagation delay, retire safety delay, and DS TTL:
# 1h + 1d = 25h = 90000 seconds. # 1h + 1h + 1d = 26h = 93600 seconds.
check_next_key_event 90000 check_next_key_event 93600
# #
# Zone: step2.going-insecure.kasp # Zone: step2.going-insecure.kasp
@@ -4454,8 +4456,8 @@ dnssec_verify
# Next key event is when the DS becomes HIDDEN. This happens after the # Next key event is when the DS becomes HIDDEN. This happens after the
# parent propagation delay, retire safety delay, and DS TTL: # parent propagation delay, retire safety delay, and DS TTL:
# 1h + 1d = 25h = 90000 seconds. # 1h + 1h + 1d = 26h = 93600 seconds.
check_next_key_event 90000 check_next_key_event 93600
# #
# Zone: step2.going-insecure-dynamic.kasp # Zone: step2.going-insecure-dynamic.kasp
@@ -4649,11 +4651,12 @@ set_addkeytime "KEY2" "REMOVED" "${retired}" "${IretZSK}"
created=$(key_get KEY3 CREATED) created=$(key_get KEY3 CREATED)
set_keytime "KEY3" "PUBLISHED" "${created}" set_keytime "KEY3" "PUBLISHED" "${created}"
set_keytime "KEY3" "ACTIVE" "${created}" set_keytime "KEY3" "ACTIVE" "${created}"
# - It takes TTLsig + Dprp to propagate the zone. # - It takes TTLsig + Dprp + publish-safety hours to propagate the zone.
# TTLsig: 6h (39600 seconds) # TTLsig: 6h (39600 seconds)
# Dprp: 1h (3600 seconds) # Dprp: 1h (3600 seconds)
# Ipub: 7h (25200 seconds) # publish-safety: 1h (3600 seconds)
Ipub=25200 # Ipub: 8h (28800 seconds)
Ipub=28800
set_addkeytime "KEY3" "SYNCPUBLISH" "${created}" "${Ipub}" set_addkeytime "KEY3" "SYNCPUBLISH" "${created}" "${Ipub}"
# - The new ZSK is published and activated. # - The new ZSK is published and activated.
created=$(key_get KEY4 CREATED) created=$(key_get KEY4 CREATED)
@@ -4722,12 +4725,12 @@ dnssec_verify
# Next key event is when all zone signatures are signed with the new # Next key event is when all zone signatures are signed with the new
# algorithm. This is the max-zone-ttl plus zone propagation delay # algorithm. This is the max-zone-ttl plus zone propagation delay
# 6h + 1h. But three hours have already passed (the time it took to # plus retire safety: 6h + 1h + 2h. But three hours have already passed
# make the DNSKEY omnipresent), so the next event should be scheduled # (the time it took to make the DNSKEY omnipresent), so the next event
# in 4 hour: 14400 seconds. Prevent intermittent # should be scheduled in 6 hour: 21600 seconds. Prevent intermittent
# false positives on slow platforms by subtracting the number of seconds # false positives on slow platforms by subtracting the number of seconds
# which passed between key creation and invoking 'rndc reconfig'. # which passed between key creation and invoking 'rndc reconfig'.
next_time=$((14400 - time_passed)) next_time=$((21600 - time_passed))
check_next_key_event $next_time check_next_key_event $next_time
# #
@@ -4750,28 +4753,28 @@ check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
check_cdslog "$DIR" "$ZONE" KEY3 check_cdslog "$DIR" "$ZONE" KEY3
# Set expected key times: # Set expected key times:
# - The old keys were activated 7 hours ago (25200 seconds). # - The old keys were activated 9 hours ago (32400 seconds).
rollover_predecessor_keytimes -25200 rollover_predecessor_keytimes -32400
# - And retired 3 hours ago (10800 seconds). # - And retired 6 hours ago (21600 seconds).
created=$(key_get KEY1 CREATED) created=$(key_get KEY1 CREATED)
set_addkeytime "KEY1" "RETIRED" "${created}" -10800 set_addkeytime "KEY1" "RETIRED" "${created}" -21600
retired=$(key_get KEY1 RETIRED) retired=$(key_get KEY1 RETIRED)
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretKSK}" set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretKSK}"
created=$(key_get KEY2 CREATED) created=$(key_get KEY2 CREATED)
set_addkeytime "KEY2" "RETIRED" "${created}" -10800 set_addkeytime "KEY2" "RETIRED" "${created}" -21600
retired=$(key_get KEY2 RETIRED) retired=$(key_get KEY2 RETIRED)
set_addkeytime "KEY2" "REMOVED" "${retired}" "${IretZSK}" set_addkeytime "KEY2" "REMOVED" "${retired}" "${IretZSK}"
# - The new keys are published 7 hours ago. # - The new keys are published 9 hours ago.
created=$(key_get KEY3 CREATED) created=$(key_get KEY3 CREATED)
set_addkeytime "KEY3" "PUBLISHED" "${created}" -25200 set_addkeytime "KEY3" "PUBLISHED" "${created}" -32400
set_addkeytime "KEY3" "ACTIVE" "${created}" -25200 set_addkeytime "KEY3" "ACTIVE" "${created}" -32400
published=$(key_get KEY3 PUBLISHED) published=$(key_get KEY3 PUBLISHED)
set_addkeytime "KEY3" "SYNCPUBLISH" "${published}" ${Ipub} set_addkeytime "KEY3" "SYNCPUBLISH" "${published}" ${Ipub}
created=$(key_get KEY4 CREATED) created=$(key_get KEY4 CREATED)
set_addkeytime "KEY4" "PUBLISHED" "${created}" -25200 set_addkeytime "KEY4" "PUBLISHED" "${created}" -32400
set_addkeytime "KEY4" "ACTIVE" "${created}" -25200 set_addkeytime "KEY4" "ACTIVE" "${created}" -32400
# Continue signing policy checks. # Continue signing policy checks.
check_keytimes check_keytimes
@@ -4784,9 +4787,9 @@ dnssec_verify
rndc_checkds "$SERVER" "$DIR" KEY1 "now" "withdrawn" "$ZONE" rndc_checkds "$SERVER" "$DIR" KEY1 "now" "withdrawn" "$ZONE"
rndc_checkds "$SERVER" "$DIR" KEY3 "now" "published" "$ZONE" rndc_checkds "$SERVER" "$DIR" KEY3 "now" "published" "$ZONE"
# Next key event is when the DS becomes OMNIPRESENT. This happens after the # Next key event is when the DS becomes OMNIPRESENT. This happens after the
# parent propagation delay, and DS TTL: # parent propagation delay, retire safety delay, and DS TTL:
# 1h + 2h = 3h = 10800 seconds. # 1h + 2h + 2h = 5h = 18000 seconds.
check_next_key_event 10800 check_next_key_event 18000
# #
# Zone: step4.algorithm-roll.kasp # Zone: step4.algorithm-roll.kasp
@@ -4813,29 +4816,29 @@ wait_for_done_signing
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE" check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
# Set expected key times: # Set expected key times:
# - The old keys were activated 36 hours ago (129600 seconds). # - The old keys were activated 38 hours ago (136800 seconds).
rollover_predecessor_keytimes -129600 rollover_predecessor_keytimes -136800
# - And retired 33 hours ago (118800 seconds). # - And retired 35 hours ago (126000 seconds).
created=$(key_get KEY1 CREATED) created=$(key_get KEY1 CREATED)
set_addkeytime "KEY1" "RETIRED" "${created}" -118800 set_addkeytime "KEY1" "RETIRED" "${created}" -126000
retired=$(key_get KEY1 RETIRED) retired=$(key_get KEY1 RETIRED)
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretKSK}" set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretKSK}"
created=$(key_get KEY2 CREATED) created=$(key_get KEY2 CREATED)
set_addkeytime "KEY2" "RETIRED" "${created}" -118800 set_addkeytime "KEY2" "RETIRED" "${created}" -126000
retired=$(key_get KEY2 RETIRED) retired=$(key_get KEY2 RETIRED)
set_addkeytime "KEY2" "REMOVED" "${retired}" "${IretZSK}" set_addkeytime "KEY2" "REMOVED" "${retired}" "${IretZSK}"
# - The new keys are published 36 hours ago. # - The new keys are published 38 hours ago.
created=$(key_get KEY3 CREATED) created=$(key_get KEY3 CREATED)
set_addkeytime "KEY3" "PUBLISHED" "${created}" -129600 set_addkeytime "KEY3" "PUBLISHED" "${created}" -136800
set_addkeytime "KEY3" "ACTIVE" "${created}" -129600 set_addkeytime "KEY3" "ACTIVE" "${created}" -136800
published=$(key_get KEY3 PUBLISHED) published=$(key_get KEY3 PUBLISHED)
set_addkeytime "KEY3" "SYNCPUBLISH" "${published}" ${Ipub} set_addkeytime "KEY3" "SYNCPUBLISH" "${published}" ${Ipub}
created=$(key_get KEY4 CREATED) created=$(key_get KEY4 CREATED)
set_addkeytime "KEY4" "PUBLISHED" "${created}" -129600 set_addkeytime "KEY4" "PUBLISHED" "${created}" -136800
set_addkeytime "KEY4" "ACTIVE" "${created}" -129600 set_addkeytime "KEY4" "ACTIVE" "${created}" -136800
# Continue signing policy checks. # Continue signing policy checks.
check_keytimes check_keytimes
@@ -4864,29 +4867,29 @@ wait_for_done_signing
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE" check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
# Set expected key times: # Set expected key times:
# - The old keys were activated 38 hours ago (136800 seconds) # - The old keys were activated 40 hours ago (144000 seconds)
rollover_predecessor_keytimes -136800 rollover_predecessor_keytimes -144000
# - And retired 35 hours ago (126000 seconds). # - And retired 37 hours ago (133200 seconds).
created=$(key_get KEY1 CREATED) created=$(key_get KEY1 CREATED)
set_addkeytime "KEY1" "RETIRED" "${created}" -126000 set_addkeytime "KEY1" "RETIRED" "${created}" -133200
retired=$(key_get KEY1 RETIRED) retired=$(key_get KEY1 RETIRED)
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretKSK}" set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretKSK}"
created=$(key_get KEY2 CREATED) created=$(key_get KEY2 CREATED)
set_addkeytime "KEY2" "RETIRED" "${created}" -126000 set_addkeytime "KEY2" "RETIRED" "${created}" -133200
retired=$(key_get KEY2 RETIRED) retired=$(key_get KEY2 RETIRED)
set_addkeytime "KEY2" "REMOVED" "${retired}" "${IretZSK}" set_addkeytime "KEY2" "REMOVED" "${retired}" "${IretZSK}"
# The new keys are published 40 hours ago. # The new keys are published 40 hours ago.
created=$(key_get KEY3 CREATED) created=$(key_get KEY3 CREATED)
set_addkeytime "KEY3" "PUBLISHED" "${created}" -136800 set_addkeytime "KEY3" "PUBLISHED" "${created}" -144000
set_addkeytime "KEY3" "ACTIVE" "${created}" -136800 set_addkeytime "KEY3" "ACTIVE" "${created}" -144000
published=$(key_get KEY3 PUBLISHED) published=$(key_get KEY3 PUBLISHED)
set_addkeytime "KEY3" "SYNCPUBLISH" "${published}" ${Ipub} set_addkeytime "KEY3" "SYNCPUBLISH" "${published}" ${Ipub}
created=$(key_get KEY4 CREATED) created=$(key_get KEY4 CREATED)
set_addkeytime "KEY4" "PUBLISHED" "${created}" -136800 set_addkeytime "KEY4" "PUBLISHED" "${created}" -144000
set_addkeytime "KEY4" "ACTIVE" "${created}" -136800 set_addkeytime "KEY4" "ACTIVE" "${created}" -144000
# Continue signing policy checks. # Continue signing policy checks.
check_keytimes check_keytimes
@@ -4895,12 +4898,12 @@ check_subdomain
dnssec_verify dnssec_verify
# Next key event is when the RSASHA1 signatures become HIDDEN. This happens # Next key event is when the RSASHA1 signatures become HIDDEN. This happens
# after the max-zone-ttl plus zone propagation delay (6h + 1h) # after the max-zone-ttl plus zone propagation delay plus retire safety
# minus the time already passed since the UNRETENTIVE state has # (6h + 1h + 2h) minus the time already passed since the UNRETENTIVE state has
# been reached (2h): 7h - 2h = 5h = 18000 seconds. Prevent intermittent # been reached (2h): 9h - 2h = 7h = 25200 seconds. Prevent intermittent
# false positives on slow platforms by subtracting the number of seconds # false positives on slow platforms by subtracting the number of seconds
# which passed between key creation and invoking 'rndc reconfig'. # which passed between key creation and invoking 'rndc reconfig'.
next_time=$((18000 - time_passed)) next_time=$((25200 - time_passed))
check_next_key_event $next_time check_next_key_event $next_time
# #
@@ -4918,29 +4921,29 @@ wait_for_done_signing
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE" check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
# Set expected key times: # Set expected key times:
# - The old keys were activated 45 hours ago (162000 seconds) # - The old keys were activated 47 hours ago (169200 seconds)
rollover_predecessor_keytimes -162000 rollover_predecessor_keytimes -169200
# - And retired 42 hours ago (151200 seconds). # - And retired 44 hours ago (158400 seconds).
created=$(key_get KEY1 CREATED) created=$(key_get KEY1 CREATED)
set_addkeytime "KEY1" "RETIRED" "${created}" -151200 set_addkeytime "KEY1" "RETIRED" "${created}" -158400
retired=$(key_get KEY1 RETIRED) retired=$(key_get KEY1 RETIRED)
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretKSK}" set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretKSK}"
created=$(key_get KEY2 CREATED) created=$(key_get KEY2 CREATED)
set_addkeytime "KEY2" "RETIRED" "${created}" -151200 set_addkeytime "KEY2" "RETIRED" "${created}" -158400
retired=$(key_get KEY2 RETIRED) retired=$(key_get KEY2 RETIRED)
set_addkeytime "KEY2" "REMOVED" "${retired}" "${IretZSK}" set_addkeytime "KEY2" "REMOVED" "${retired}" "${IretZSK}"
# The new keys are published 47 hours ago. # The new keys are published 47 hours ago.
created=$(key_get KEY3 CREATED) created=$(key_get KEY3 CREATED)
set_addkeytime "KEY3" "PUBLISHED" "${created}" -162000 set_addkeytime "KEY3" "PUBLISHED" "${created}" -169200
set_addkeytime "KEY3" "ACTIVE" "${created}" -162000 set_addkeytime "KEY3" "ACTIVE" "${created}" -169200
published=$(key_get KEY3 PUBLISHED) published=$(key_get KEY3 PUBLISHED)
set_addkeytime "KEY3" "SYNCPUBLISH" "${published}" ${Ipub} set_addkeytime "KEY3" "SYNCPUBLISH" "${published}" ${Ipub}
created=$(key_get KEY4 CREATED) created=$(key_get KEY4 CREATED)
set_addkeytime "KEY4" "PUBLISHED" "${created}" -162000 set_addkeytime "KEY4" "PUBLISHED" "${created}" -169200
set_addkeytime "KEY4" "ACTIVE" "${created}" -162000 set_addkeytime "KEY4" "ACTIVE" "${created}" -169200
# Continue signing policy checks. # Continue signing policy checks.
check_keytimes check_keytimes
@@ -5023,8 +5026,9 @@ set_keytime "KEY2" "ACTIVE" "${created}"
# - It takes TTLsig + Dprp + publish-safety hours to propagate the zone. # - It takes TTLsig + Dprp + publish-safety hours to propagate the zone.
# TTLsig: 6h (39600 seconds) # TTLsig: 6h (39600 seconds)
# Dprp: 1h (3600 seconds) # Dprp: 1h (3600 seconds)
# Ipub: 7h (25200 seconds) # publish-safety: 1h (3600 seconds)
Ipub=25200 # Ipub: 8h (28800 seconds)
Ipub=28800
set_addkeytime "KEY2" "SYNCPUBLISH" "${created}" "${Ipub}" set_addkeytime "KEY2" "SYNCPUBLISH" "${created}" "${Ipub}"
# Continue signing policy checks. # Continue signing policy checks.
@@ -5078,13 +5082,14 @@ check_apex
check_subdomain check_subdomain
dnssec_verify dnssec_verify
# Next key event is when all zone signatures are signed with the new algorithm. # Next key event is when all zone signatures are signed with the new
# This is the max-zone-ttl plus zone propagation delay: 6h + 1h. But three # algorithm. This is the max-zone-ttl plus zone propagation delay
# hours have already passed (the time it took to make the DNSKEY omnipresent), # plus retire safety: 6h + 1h + 2h. But three hours have already passed
# so the next event should be scheduled in 4 hour: 14400 seconds. Prevent # (the time it took to make the DNSKEY omnipresent), so the next event
# intermittent false positives on slow platforms by subtracting the number of # should be scheduled in 6 hour: 21600 seconds. Prevent intermittent
# seconds which passed between key creation and invoking 'rndc reconfig'. # false positives on slow platforms by subtracting the number of seconds
next_time=$((14400 - time_passed)) # which passed between key creation and invoking 'rndc reconfig'.
next_time=$((21600 - time_passed))
check_next_key_event $next_time check_next_key_event $next_time
# #
@@ -5109,17 +5114,17 @@ check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
check_cdslog "$DIR" "$ZONE" KEY2 check_cdslog "$DIR" "$ZONE" KEY2
# Set expected key times: # Set expected key times:
# - The old key was activated 7 hours ago (25200 seconds). # - The old key was activated 9 hours ago (32400 seconds).
csk_rollover_predecessor_keytimes -25200 csk_rollover_predecessor_keytimes -32400
# - And was retired 3 hours ago (10800 seconds). # - And was retired 6 hours ago (21600 seconds).
created=$(key_get KEY1 CREATED) created=$(key_get KEY1 CREATED)
set_addkeytime "KEY1" "RETIRED" "${created}" -10800 set_addkeytime "KEY1" "RETIRED" "${created}" -21600
retired=$(key_get KEY1 RETIRED) retired=$(key_get KEY1 RETIRED)
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretCSK}" set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretCSK}"
# - The new key was published 9 hours ago. # - The new key was published 9 hours ago.
created=$(key_get KEY2 CREATED) created=$(key_get KEY2 CREATED)
set_addkeytime "KEY2" "PUBLISHED" "${created}" -25200 set_addkeytime "KEY2" "PUBLISHED" "${created}" -32400
set_addkeytime "KEY2" "ACTIVE" "${created}" -25200 set_addkeytime "KEY2" "ACTIVE" "${created}" -32400
published=$(key_get KEY2 PUBLISHED) published=$(key_get KEY2 PUBLISHED)
set_addkeytime "KEY2" "SYNCPUBLISH" "${published}" "${Ipub}" set_addkeytime "KEY2" "SYNCPUBLISH" "${published}" "${Ipub}"
@@ -5133,9 +5138,9 @@ dnssec_verify
rndc_checkds "$SERVER" "$DIR" KEY1 "now" "withdrawn" "$ZONE" rndc_checkds "$SERVER" "$DIR" KEY1 "now" "withdrawn" "$ZONE"
rndc_checkds "$SERVER" "$DIR" KEY2 "now" "published" "$ZONE" rndc_checkds "$SERVER" "$DIR" KEY2 "now" "published" "$ZONE"
# Next key event is when the DS becomes OMNIPRESENT. This happens after the # Next key event is when the DS becomes OMNIPRESENT. This happens after the
# parent propagation delay, and DS TTL: # parent propagation delay, retire safety delay, and DS TTL:
# 1h + 2h = 3h = 10800 seconds. # 1h + 2h + 2h = 5h = 18000 seconds.
check_next_key_event 10800 check_next_key_event 18000
# #
# Zone: step4.csk-algorithm-roll.kasp # Zone: step4.csk-algorithm-roll.kasp
@@ -5159,17 +5164,17 @@ wait_for_done_signing
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE" check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
# Set expected key times: # Set expected key times:
# - The old keys were activated 36 hours ago (129600 seconds). # - The old key was activated 38 hours ago (136800 seconds)
csk_rollover_predecessor_keytimes -129600 csk_rollover_predecessor_keytimes -136800
# - And retired 33 hours ago (118800 seconds). # - And retired 35 hours ago (126000 seconds).
created=$(key_get KEY1 CREATED) created=$(key_get KEY1 CREATED)
set_addkeytime "KEY1" "RETIRED" "${created}" -118800 set_addkeytime "KEY1" "RETIRED" "${created}" -126000
retired=$(key_get KEY1 RETIRED) retired=$(key_get KEY1 RETIRED)
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretCSK}" set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretCSK}"
# - The new key was published 36 hours ago. # - The new key was published 38 hours ago.
created=$(key_get KEY2 CREATED) created=$(key_get KEY2 CREATED)
set_addkeytime "KEY2" "PUBLISHED" "${created}" -129600 set_addkeytime "KEY2" "PUBLISHED" "${created}" -136800
set_addkeytime "KEY2" "ACTIVE" "${created}" -129600 set_addkeytime "KEY2" "ACTIVE" "${created}" -136800
published=$(key_get KEY2 PUBLISHED) published=$(key_get KEY2 PUBLISHED)
set_addkeytime "KEY2" "SYNCPUBLISH" "${published}" ${Ipub} set_addkeytime "KEY2" "SYNCPUBLISH" "${published}" ${Ipub}
@@ -5199,17 +5204,17 @@ wait_for_done_signing
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE" check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
# Set expected key times: # Set expected key times:
# - The old key was activated 38 hours ago (136800 seconds) # - The old key was activated 40 hours ago (144000 seconds)
csk_rollover_predecessor_keytimes -136800 csk_rollover_predecessor_keytimes -144000
# - And retired 35 hours ago (126000 seconds). # - And retired 37 hours ago (133200 seconds).
created=$(key_get KEY1 CREATED) created=$(key_get KEY1 CREATED)
set_addkeytime "KEY1" "RETIRED" "${created}" -126000 set_addkeytime "KEY1" "RETIRED" "${created}" -133200
retired=$(key_get KEY1 RETIRED) retired=$(key_get KEY1 RETIRED)
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretCSK}" set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretCSK}"
# - The new key was published 38 hours ago. # - The new key was published 40 hours ago.
created=$(key_get KEY2 CREATED) created=$(key_get KEY2 CREATED)
set_addkeytime "KEY2" "PUBLISHED" "${created}" -136800 set_addkeytime "KEY2" "PUBLISHED" "${created}" -144000
set_addkeytime "KEY2" "ACTIVE" "${created}" -136800 set_addkeytime "KEY2" "ACTIVE" "${created}" -144000
published=$(key_get KEY2 PUBLISHED) published=$(key_get KEY2 PUBLISHED)
set_addkeytime "KEY2" "SYNCPUBLISH" "${published}" ${Ipub} set_addkeytime "KEY2" "SYNCPUBLISH" "${published}" ${Ipub}
@@ -5220,12 +5225,12 @@ check_subdomain
dnssec_verify dnssec_verify
# Next key event is when the RSASHA1 signatures become HIDDEN. This happens # Next key event is when the RSASHA1 signatures become HIDDEN. This happens
# after the max-zone-ttl plus zone propagation delay (6h + 1h) minus the # after the max-zone-ttl plus zone propagation delay plus retire safety
# time already passed since the UNRETENTIVE state has been reached (2h): # (6h + 1h + 2h) minus the time already passed since the UNRETENTIVE state has
# 7h - 2h = 5h = 18000 seconds. Prevent intermittent false positives on slow # been reached (2h): 9h - 2h = 7h = 25200 seconds. Prevent intermittent
# platforms by subtracting the number of seconds which passed between key # false positives on slow platforms by subtracting the number of seconds
# creation and invoking 'rndc reconfig'. # which passed between key creation and invoking 'rndc reconfig'.
next_time=$((18000 - time_passed)) next_time=$((25200 - time_passed))
check_next_key_event $next_time check_next_key_event $next_time
# #
@@ -5243,17 +5248,17 @@ wait_for_done_signing
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE" check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
# Set expected key times: # Set expected key times:
# - The old keys were activated 45 hours ago (162000 seconds) # - The old keys were activated 47 hours ago (169200 seconds)
csk_rollover_predecessor_keytimes -162000 csk_rollover_predecessor_keytimes -169200
# - And retired 42 hours ago (151200 seconds). # - And retired 44 hours ago (158400 seconds).
created=$(key_get KEY1 CREATED) created=$(key_get KEY1 CREATED)
set_addkeytime "KEY1" "RETIRED" "${created}" -151200 set_addkeytime "KEY1" "RETIRED" "${created}" -158400
retired=$(key_get KEY1 RETIRED) retired=$(key_get KEY1 RETIRED)
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretCSK}" set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretCSK}"
# - The new key was published 47 hours ago. # - The new key was published 47 hours ago.
created=$(key_get KEY2 CREATED) created=$(key_get KEY2 CREATED)
set_addkeytime "KEY2" "PUBLISHED" "${created}" -162000 set_addkeytime "KEY2" "PUBLISHED" "${created}" -169200
set_addkeytime "KEY2" "ACTIVE" "${created}" -162000 set_addkeytime "KEY2" "ACTIVE" "${created}" -169200
published=$(key_get KEY2 PUBLISHED) published=$(key_get KEY2 PUBLISHED)
set_addkeytime "KEY2" "SYNCPUBLISH" "${published}" ${Ipub} set_addkeytime "KEY2" "SYNCPUBLISH" "${published}" ${Ipub}
-4
View File
@@ -597,10 +597,6 @@ def test_ksr_common(servers):
selected += 1 selected += 1
if "Generating" in output: if "Generating" in output:
generated += 1 generated += 1
# Subtract if there was a key collision.
if "collide" in output:
generated -= 1
assert selected == 2 assert selected == 2
assert generated == 2 assert generated == 2
for index, key in enumerate(overlapping_zsks): for index, key in enumerate(overlapping_zsks):
+1 -1
View File
@@ -111,7 +111,7 @@ cleanup:
} }
if (mctx != NULL) { if (mctx != NULL) {
isc_mem_detach(&mctx); isc_mem_destroy(&mctx);
} }
return result != ISC_R_SUCCESS ? 1 : 0; return result != ISC_R_SUCCESS ? 1 : 0;
+3 -3
View File
@@ -385,7 +385,7 @@ $DIG $DIGOPTS @10.53.0.3 foo.initially-unavailable. A >dig.out.ns3.test$n.1 2>&1
grep "NOERROR" dig.out.ns3.test$n.1 >/dev/null || ret=1 grep "NOERROR" dig.out.ns3.test$n.1 >/dev/null || ret=1
grep "flags:.* ad" dig.out.ns3.test$n.1 >/dev/null || ret=1 grep "flags:.* ad" dig.out.ns3.test$n.1 >/dev/null || ret=1
# Sanity check: the authoritative server should have been queried. # Sanity check: the authoritative server should have been queried.
nextpart ns2/named.run | grep "query 'foo.initially-unavailable/NS/IN'" >/dev/null || ret=1 nextpart ns2/named.run | grep "query 'foo.initially-unavailable/A/IN'" >/dev/null || ret=1
# Reconfigure ns2 so that the zone can be mirrored on ns3. # Reconfigure ns2 so that the zone can be mirrored on ns3.
sed '/^zone "initially-unavailable" {$/,/^};$/ { sed '/^zone "initially-unavailable" {$/,/^};$/ {
s/10.53.0.254/10.53.0.3/ s/10.53.0.254/10.53.0.3/
@@ -403,7 +403,7 @@ $DIG $DIGOPTS @10.53.0.3 foo.initially-unavailable. A >dig.out.ns3.test$n.2 2>&1
grep "NOERROR" dig.out.ns3.test$n.2 >/dev/null || ret=1 grep "NOERROR" dig.out.ns3.test$n.2 >/dev/null || ret=1
grep "flags:.* ad" dig.out.ns3.test$n.2 >/dev/null || ret=1 grep "flags:.* ad" dig.out.ns3.test$n.2 >/dev/null || ret=1
# Ensure the authoritative server was not queried. # Ensure the authoritative server was not queried.
nextpart ns2/named.run | grep "query 'foo.initially-unavailable/NS/IN'" >/dev/null && ret=1 nextpart ns2/named.run | grep "query 'foo.initially-unavailable/A/IN'" >/dev/null && ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=$((status + ret)) status=$((status + ret))
@@ -434,7 +434,7 @@ $DIG $DIGOPTS @10.53.0.3 foo.initially-unavailable. A >dig.out.ns3.test$n 2>&1 |
grep "NOERROR" dig.out.ns3.test$n >/dev/null || ret=1 grep "NOERROR" dig.out.ns3.test$n >/dev/null || ret=1
grep "flags:.* ad" dig.out.ns3.test$n >/dev/null || ret=1 grep "flags:.* ad" dig.out.ns3.test$n >/dev/null || ret=1
# Sanity check: the authoritative server should have been queried. # Sanity check: the authoritative server should have been queried.
nextpart ns2/named.run | grep "query 'foo.initially-unavailable/NS/IN'" >/dev/null || ret=1 nextpart ns2/named.run | grep "query 'foo.initially-unavailable/A/IN'" >/dev/null || ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=$((status + ret)) status=$((status + ret))
@@ -1,17 +0,0 @@
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
;
; SPDX-License-Identifier: MPL-2.0
;
; This Source Code Form is subject to the terms of the Mozilla Public
; License, v. 2.0. If a copy of the MPL was not distributed with this
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
;
; See the COPYRIGHT file distributed with this work for additional
; information regarding copyright ownership.
@ 30 SOA ns2.good. hostmaster.arpa. 2018050100 1 1 1 1
@ 30 NS ns2.good.
8.2.6.0 60 NS ns3.good.
1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.f.4.0 1 PTR nee.com.
+436 -91
View File
@@ -1,111 +1,456 @@
""" # Copyright (C) Internet Systems Consortium, Inc. ("ISC")
Copyright (C) Internet Systems Consortium, Inc. ("ISC") #
# SPDX-License-Identifier: MPL-2.0
#
# This Source Code Form is subject to the terms of the Mozilla Public
# License, v. 2.0. If a copy of the MPL was not distributed with this
# file, you can obtain one at https://mozilla.org/MPL/2.0/.
#
# See the COPYRIGHT file distributed with this work for additional
# information regarding copyright ownership.
SPDX-License-Identifier: MPL-2.0 from __future__ import print_function
import os
import sys
import signal
import socket
import select
from datetime import datetime, timedelta
import time
import functools
This Source Code Form is subject to the terms of the Mozilla Public import dns, dns.message, dns.query, dns.flags
License, v. 2.0. If a copy of the MPL was not distributed with this from dns.rdatatype import *
file, you can obtain one at https://mozilla.org/MPL/2.0/. from dns.rdataclass import *
from dns.rcode import *
See the COPYRIGHT file distributed with this work for additional from dns.name import *
information regarding copyright ownership.
"""
from typing import AsyncGenerator
import dns.message
import dns.name
import dns.rcode
import dns.rdataclass
import dns.rdatatype
from isctest.asyncserver import (
AsyncDnsServer,
DnsResponseSend,
DomainHandler,
QueryContext,
ResponseAction,
)
from qmin_ans import (
DelayedResponseHandler,
EntRcodeChanger,
QueryLogHandler,
log_query,
)
class QueryLogger(QueryLogHandler): # Log query to file
domains = ["1.0.0.2.ip6.arpa.", "fwd.", "good."] def logquery(type, qname):
with open("qlog", "a") as f:
f.write("%s %s\n", type, qname)
class BadHandler(EntRcodeChanger): def endswith(domain, labels):
domains = ["bad."] return domain.endswith("." + labels) or domain == labels
rcode = dns.rcode.NXDOMAIN
class UglyHandler(EntRcodeChanger): ############################################################################
domains = ["ugly."] # Respond to a DNS query.
rcode = dns.rcode.FORMERR # For good. it serves:
# ns2.good. IN A 10.53.0.2
# zoop.boing.good. NS ns3.good.
# ns3.good. IN A 10.53.0.3
# too.many.labels.a.b.c.d.e.f.g.h.i.j.k.l.m.n.o.p.q.r.s.t.u.v.w.x.y.z.good. A 192.0.2.2
# it responds properly (with NODATA empty response) to non-empty terminals
#
# For slow. it works the same as for good., but each response is delayed by 400 milliseconds
#
# For bad. it works the same as for good., but returns NXDOMAIN to non-empty terminals
#
# For ugly. it works the same as for good., but returns garbage to non-empty terminals
#
# For 1.0.0.2.ip6.arpa it serves
# 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa. IN PTR nee.com.
# 8.2.6.0.1.0.0.2.ip6.arpa IN NS ns3.good
# 1.0.0.2.ip6.arpa. IN NS ns2.good
# ip6.arpa. IN NS ns2.good
#
# For stale. it serves:
# a.b. NS ns.a.b.stale.
# ns.a.b.stale. IN A 10.53.0.3
# b. NS ns.b.stale.
# ns.b.stale. IN A 10.53.0.4
############################################################################
def create_response(msg):
m = dns.message.from_wire(msg)
qname = m.question[0].name.to_text()
lqname = qname.lower()
labels = lqname.split(".")
# get qtype
rrtype = m.question[0].rdtype
typename = dns.rdatatype.to_text(rrtype)
if typename == "A" or typename == "AAAA":
typename = "ADDR"
bad = False
ugly = False
slow = False
# log this query
with open("query.log", "a") as f:
f.write("%s %s\n" % (typename, lqname))
print("%s %s" % (typename, lqname), end=" ")
r = dns.message.make_response(m)
r.set_rcode(NOERROR)
if endswith(lqname, "1.0.0.2.ip6.arpa."):
# Direct query - give direct answer
if endswith(lqname, "8.2.6.0.1.0.0.2.ip6.arpa."):
# Delegate to ns3
r.authority.append(
dns.rrset.from_text(
"8.2.6.0.1.0.0.2.ip6.arpa.", 60, IN, NS, "ns3.good."
)
)
r.additional.append(
dns.rrset.from_text("ns3.good.", 60, IN, A, "10.53.0.3")
)
elif (
lqname
== "1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa."
and rrtype == PTR
):
# Direct query - give direct answer
r.answer.append(
dns.rrset.from_text(
"1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.",
1,
IN,
PTR,
"nee.com.",
)
)
r.flags |= dns.flags.AA
elif lqname == "1.0.0.2.ip6.arpa." and rrtype == NS:
# NS query at the apex
r.answer.append(
dns.rrset.from_text("1.0.0.2.ip6.arpa.", 30, IN, NS, "ns2.good.")
)
r.flags |= dns.flags.AA
elif endswith(
"1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.",
lqname,
):
# NODATA answer
r.authority.append(
dns.rrset.from_text(
"1.0.0.2.ip6.arpa.",
30,
IN,
SOA,
"ns2.good. hostmaster.arpa. 2018050100 1 1 1 1",
)
)
else:
# NXDOMAIN
r.authority.append(
dns.rrset.from_text(
"1.0.0.2.ip6.arpa.",
30,
IN,
SOA,
"ns2.good. hostmaster.arpa. 2018050100 1 1 1 1",
)
)
r.set_rcode(NXDOMAIN)
return r
elif endswith(lqname, "ip6.arpa."):
if lqname == "ip6.arpa." and rrtype == NS:
# NS query at the apex
r.answer.append(dns.rrset.from_text("ip6.arpa.", 30, IN, NS, "ns2.good."))
r.flags |= dns.flags.AA
elif endswith("1.0.0.2.ip6.arpa.", lqname):
# NODATA answer
r.authority.append(
dns.rrset.from_text(
"ip6.arpa.",
30,
IN,
SOA,
"ns2.good. hostmaster.arpa. 2018050100 1 1 1 1",
)
)
else:
# NXDOMAIN
r.authority.append(
dns.rrset.from_text(
"ip6.arpa.",
30,
IN,
SOA,
"ns2.good. hostmaster.arpa. 2018050100 1 1 1 1",
)
)
r.set_rcode(NXDOMAIN)
return r
elif endswith(lqname, "stale."):
if endswith(lqname, "a.b.stale."):
# Delegate to ns.a.b.stale.
r.authority.append(
dns.rrset.from_text("a.b.stale.", 2, IN, NS, "ns.a.b.stale.")
)
r.additional.append(
dns.rrset.from_text("ns.a.b.stale.", 2, IN, A, "10.53.0.3")
)
elif endswith(lqname, "b.stale."):
# Delegate to ns.b.stale.
r.authority.append(
dns.rrset.from_text("b.stale.", 2, IN, NS, "ns.b.stale.")
)
r.additional.append(
dns.rrset.from_text("ns.b.stale.", 2, IN, A, "10.53.0.4")
)
elif lqname == "stale." and rrtype == NS:
# NS query at the apex.
r.answer.append(dns.rrset.from_text("stale.", 2, IN, NS, "ns2.stale."))
r.flags |= dns.flags.AA
elif lqname == "stale." and rrtype == SOA:
# SOA query at the apex.
r.answer.append(
dns.rrset.from_text(
"stale.", 2, IN, SOA, "ns2.stale. hostmaster.stale. 1 2 3 4 5"
)
)
r.flags |= dns.flags.AA
elif lqname == "stale.":
# NODATA answer
r.authority.append(
dns.rrset.from_text(
"stale.", 2, IN, SOA, "ns2.stale. hostmaster.arpa. 1 2 3 4 5"
)
)
r.flags |= dns.flags.AA
elif lqname == "ns2.stale.":
if rrtype == A:
r.additional.append(
dns.rrset.from_text("ns.b.stale.", 2, IN, A, "10.53.0.2")
)
else:
r.authority.append(
dns.rrset.from_text(
"stale.", 2, IN, SOA, "ns2.stale. hostmaster.arpa. 1 2 3 4 5"
)
)
r.flags |= dns.flags.AA
else:
# NXDOMAIN
r.authority.append(
dns.rrset.from_text(
"stale.", 2, IN, SOA, "ns2.stale. hostmaster.arpa. 1 2 3 4 5"
)
)
r.set_rcode(NXDOMAIN)
return r
elif endswith(lqname, "bad."):
bad = True
suffix = "bad."
lqname = lqname[:-4]
elif endswith(lqname, "ugly."):
ugly = True
suffix = "ugly."
lqname = lqname[:-5]
elif endswith(lqname, "good."):
suffix = "good."
lqname = lqname[:-5]
elif endswith(lqname, "slow."):
slow = True
suffix = "slow."
lqname = lqname[:-5]
elif endswith(lqname, "fwd."):
suffix = "fwd."
lqname = lqname[:-4]
else:
r.set_rcode(REFUSED)
return r
# Good/bad/ugly differs only in how we treat non-empty terminals
if endswith(lqname, "zoop.boing."):
r.authority.append(
dns.rrset.from_text("zoop.boing." + suffix, 1, IN, NS, "ns3." + suffix)
)
elif (
lqname == "many.labels.a.b.c.d.e.f.g.h.i.j.k.l.m.n.o.p.q.r.s.t.u.v.w.x.y.z."
and rrtype == A
):
r.answer.append(dns.rrset.from_text(lqname + suffix, 1, IN, A, "192.0.2.2"))
r.flags |= dns.flags.AA
elif lqname == "" and rrtype == NS:
r.answer.append(dns.rrset.from_text(suffix, 30, IN, NS, "ns2." + suffix))
r.flags |= dns.flags.AA
elif lqname == "ns2.":
r.flags |= dns.flags.AA
if rrtype == A:
r.answer.append(
dns.rrset.from_text("ns2." + suffix, 30, IN, A, "10.53.0.2")
)
elif rrtype == AAAA:
r.answer.append(
dns.rrset.from_text(
"ns2." + suffix, 30, IN, AAAA, "fd92:7065:b8e:ffff::2"
)
)
else:
r.authority.append(
dns.rrset.from_text(
suffix,
30,
IN,
SOA,
"ns2." + suffix + " hostmaster.arpa. 2018050100 1 1 1 1",
)
)
elif lqname == "ns3.":
r.flags |= dns.flags.AA
if rrtype == A:
r.answer.append(
dns.rrset.from_text("ns3." + suffix, 30, IN, A, "10.53.0.3")
)
elif lqname == "ns3." and rrtype == AAAA:
r.answer.append(
dns.rrset.from_text(
"ns3." + suffix, 30, IN, AAAA, "fd92:7065:b8e:ffff::3"
)
)
else:
r.authority.append(
dns.rrset.from_text(
suffix,
30,
IN,
SOA,
"ns2." + suffix + " hostmaster.arpa. 2018050100 1 1 1 1",
)
)
elif lqname == "ns4.":
r.flags |= dns.flags.AA
if rrtype == A:
r.answer.append(
dns.rrset.from_text("ns4." + suffix, 30, IN, A, "10.53.0.4")
)
elif rrtype == AAAA:
r.answer.append(
dns.rrset.from_text(
"ns4." + suffix, 30, IN, AAAA, "fd92:7065:b8e:ffff::4"
)
)
else:
r.authority.append(
dns.rrset.from_text(
suffix,
30,
IN,
SOA,
"ns2." + suffix + " hostmaster.arpa. 2018050100 1 1 1 1",
)
)
elif lqname == "a.bit.longer.ns.name." and rrtype == A:
r.answer.append(
dns.rrset.from_text("a.bit.longer.ns.name." + suffix, 1, IN, A, "10.53.0.4")
)
r.flags |= dns.flags.AA
elif lqname == "a.bit.longer.ns.name." and rrtype == AAAA:
r.answer.append(
dns.rrset.from_text(
"a.bit.longer.ns.name." + suffix, 1, IN, AAAA, "fd92:7065:b8e:ffff::4"
)
)
r.flags |= dns.flags.AA
else:
r.authority.append(
dns.rrset.from_text(
suffix,
1,
IN,
SOA,
"ns2." + suffix + " hostmaster.arpa. 2018050100 1 1 1 1",
)
)
if bad or not (
endswith("icky.icky.icky.ptang.zoop.boing.", lqname)
or endswith(
"many.labels.a.b.c.d.e.f.g.h.i.j.k.l.m.n.o.p.q.r.s.t.u.v.w.x.y.z.",
lqname,
)
or endswith("a.bit.longer.ns.name.", lqname)
):
r.set_rcode(NXDOMAIN)
if ugly:
r.set_rcode(FORMERR)
if slow:
time.sleep(0.2)
return r
class SlowHandler(DelayedResponseHandler): def sigterm(signum, frame):
domains = ["slow."] print("Shutting down now...")
delay = 0.2 os.remove("ans.pid")
running = False
sys.exit(0)
def send_delegation( ############################################################################
qctx: QueryContext, zone_cut: dns.name.Name, target_addr: str # Main
) -> ResponseAction: #
""" # Set up responder and control channel, open the pid file, and start
Delegate `zone_cut` to a single in-bailiwick name server, `ns.<zone_cut>`, # the main loop, listening for queries on the query channel or commands
with a single IPv4 glue record (provided in `target_addr`) included in the # on the control channel and acting on them.
ADDITIONAL section. ############################################################################
""" ip4 = "10.53.0.2"
ns_name = "ns." + zone_cut.to_text() ip6 = "fd92:7065:b8e:ffff::2"
ns_rrset = dns.rrset.from_text(
zone_cut, 2, dns.rdataclass.IN, dns.rdatatype.NS, ns_name
)
a_rrset = dns.rrset.from_text(
ns_name, 2, dns.rdataclass.IN, dns.rdatatype.A, target_addr
)
response = dns.message.make_response(qctx.query) try:
response.set_rcode(dns.rcode.NOERROR) port = int(os.environ["PORT"])
response.authority.append(ns_rrset) except:
response.additional.append(a_rrset) port = 5300
return DnsResponseSend(response, authoritative=False) query4_socket = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
query4_socket.bind((ip4, port))
havev6 = True
try:
query6_socket = socket.socket(socket.AF_INET6, socket.SOCK_DGRAM)
try:
query6_socket.bind((ip6, port))
except:
query6_socket.close()
havev6 = False
except:
havev6 = False
class StaleHandler(DomainHandler): signal.signal(signal.SIGTERM, sigterm)
"""
`a.b.stale` is a subdomain of `b.stale` and these two subdomains need to be
delegated to different name servers. Therefore, their delegations cannot
be placed in the zone file because the zone cut at `b.stale` would occlude
the one at `a.b.stale`. Generate these delegations dynamically depending
on the QNAME.
"""
domains = ["stale."] f = open("ans.pid", "w")
pid = os.getpid()
print(pid, file=f)
f.close()
async def get_responses( running = True
self, qctx: QueryContext
) -> AsyncGenerator[ResponseAction, None]:
log_query(qctx)
a_b_stale = dns.name.from_text("a.b.stale.")
b_stale = dns.name.from_text("b.stale.")
if qctx.qname.is_subdomain(a_b_stale):
yield send_delegation(qctx, a_b_stale, "10.53.0.3")
elif qctx.qname.is_subdomain(b_stale):
yield send_delegation(qctx, b_stale, "10.53.0.4")
print("Listening on %s port %d" % (ip4, port))
if havev6:
print("Listening on %s port %d" % (ip6, port))
print("Ctrl-c to quit")
if __name__ == "__main__": if havev6:
server = AsyncDnsServer() input = [query4_socket, query6_socket]
server.install_response_handler(QueryLogger()) else:
server.install_response_handler(BadHandler()) input = [query4_socket]
server.install_response_handler(UglyHandler())
server.install_response_handler(SlowHandler()) while running:
server.install_response_handler(StaleHandler()) try:
server.run() inputready, outputready, exceptready = select.select(input, [], [])
except select.error as e:
break
except socket.error as e:
break
except KeyboardInterrupt:
break
for s in inputready:
if s == query4_socket or s == query6_socket:
print(
"Query received on %s" % (ip4 if s == query4_socket else ip6), end=" "
)
# Handle incoming queries
msg = s.recvfrom(65535)
rsp = create_response(msg[0])
if rsp:
print(dns.rcode.to_text(rsp.rcode()))
s.sendto(rsp.to_wire(), msg[1])
else:
print("NO RESPONSE")
if not running:
break
-1
View File
@@ -1 +0,0 @@
good.db
-1
View File
@@ -1 +0,0 @@
good.db
-26
View File
@@ -1,26 +0,0 @@
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
;
; SPDX-License-Identifier: MPL-2.0
;
; This Source Code Form is subject to the terms of the Mozilla Public
; License, v. 2.0. If a copy of the MPL was not distributed with this
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
;
; See the COPYRIGHT file distributed with this work for additional
; information regarding copyright ownership.
@ 1 SOA ns2 hostmaster.arpa. 2018050100 1 1 1 1
@ 30 NS ns2
ns2 30 A 10.53.0.2
30 AAAA fd92:7065:b8e:ffff::2
zoop.boing 30 NS ns3
ns3 30 A 10.53.0.3
30 AAAA fd92:7065:b8e:ffff::3
ns4 30 A 10.53.0.4
30 AAAA fd92:7065:b8e:ffff::4
a.bit.longer.ns.name 1 A 10.53.0.4
1 AAAA fd92:7065:b8e:ffff::4
-1
View File
@@ -1 +0,0 @@
good.db
-15
View File
@@ -1,15 +0,0 @@
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
;
; SPDX-License-Identifier: MPL-2.0
;
; This Source Code Form is subject to the terms of the Mozilla Public
; License, v. 2.0. If a copy of the MPL was not distributed with this
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
;
; See the COPYRIGHT file distributed with this work for additional
; information regarding copyright ownership.
@ 2 SOA ns2 hostmaster.stale. 1 2 3 4 5
@ 2 NS ns2
ns2 2 A 10.53.0.2
2 AAAA fd92:7065:b8e:ffff::2
-1
View File
@@ -1 +0,0 @@
good.db
@@ -1,15 +0,0 @@
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
;
; SPDX-License-Identifier: MPL-2.0
;
; This Source Code Form is subject to the terms of the Mozilla Public
; License, v. 2.0. If a copy of the MPL was not distributed with this
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
;
; See the COPYRIGHT file distributed with this work for additional
; information regarding copyright ownership.
@ 30 SOA ns3.good. hostmaster.arpa. 2018050100 1 1 1 1
@ 30 NS ns3.good.
1.1.1.1 60 NS ns4.good.
-15
View File
@@ -1,15 +0,0 @@
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
;
; SPDX-License-Identifier: MPL-2.0
;
; This Source Code Form is subject to the terms of the Mozilla Public
; License, v. 2.0. If a copy of the MPL was not distributed with this
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
;
; See the COPYRIGHT file distributed with this work for additional
; information regarding copyright ownership.
@ 1 SOA ns hostmaster.a.b.stale. 1 2 3 4 5
@ 1 NS ns
@ 1 TXT "peekaboo"
ns 1 A 10.53.0.3
+273 -34
View File
@@ -1,46 +1,285 @@
""" # Copyright (C) Internet Systems Consortium, Inc. ("ISC")
Copyright (C) Internet Systems Consortium, Inc. ("ISC") #
# SPDX-License-Identifier: MPL-2.0
#
# This Source Code Form is subject to the terms of the Mozilla Public
# License, v. 2.0. If a copy of the MPL was not distributed with this
# file, you can obtain one at https://mozilla.org/MPL/2.0/.
#
# See the COPYRIGHT file distributed with this work for additional
# information regarding copyright ownership.
SPDX-License-Identifier: MPL-2.0 from __future__ import print_function
import os
import sys
import signal
import socket
import select
from datetime import datetime, timedelta
import time
import functools
This Source Code Form is subject to the terms of the Mozilla Public import dns, dns.message, dns.query, dns.flags
License, v. 2.0. If a copy of the MPL was not distributed with this from dns.rdatatype import *
file, you can obtain one at https://mozilla.org/MPL/2.0/. from dns.rdataclass import *
from dns.rcode import *
See the COPYRIGHT file distributed with this work for additional from dns.name import *
information regarding copyright ownership.
"""
import dns.rcode
from isctest.asyncserver import AsyncDnsServer
from qmin_ans import DelayedResponseHandler, EntRcodeChanger, QueryLogHandler
class QueryLogger(QueryLogHandler): # Log query to file
domains = ["8.2.6.0.1.0.0.2.ip6.arpa.", "a.b.stale.", "zoop.boing.good."] def logquery(type, qname):
with open("qlog", "a") as f:
f.write("%s %s\n", type, qname)
class ZoopBoingBadHandler(EntRcodeChanger): def endswith(domain, labels):
domains = ["zoop.boing.bad."] return domain.endswith("." + labels) or domain == labels
rcode = dns.rcode.NXDOMAIN
class ZoopBoingUglyHandler(EntRcodeChanger): ############################################################################
domains = ["zoop.boing.ugly."] # Respond to a DNS query.
rcode = dns.rcode.FORMERR # For good. it serves:
# zoop.boing.good. NS ns3.good.
# icky.ptang.zoop.boing.good. NS a.bit.longer.ns.name.good.
# it responds properly (with NODATA empty response) to non-empty terminals
#
# For slow. it works the same as for good., but each response is delayed by 400 milliseconds
#
# For bad. it works the same as for good., but returns NXDOMAIN to non-empty terminals
#
# For ugly. it works the same as for good., but returns garbage to non-empty terminals
#
# For stale. it serves:
# a.b.stale. IN TXT peekaboo (resolver did not do qname minimization)
############################################################################
def create_response(msg):
m = dns.message.from_wire(msg)
qname = m.question[0].name.to_text()
lqname = qname.lower()
labels = lqname.split(".")
suffix = ""
# get qtype
rrtype = m.question[0].rdtype
typename = dns.rdatatype.to_text(rrtype)
if typename == "A" or typename == "AAAA":
typename = "ADDR"
bad = False
ugly = False
slow = False
# log this query
with open("query.log", "a") as f:
f.write("%s %s\n" % (typename, lqname))
print("%s %s" % (typename, lqname), end=" ")
r = dns.message.make_response(m)
r.set_rcode(NOERROR)
ip6req = False
if endswith(lqname, "bad."):
bad = True
suffix = "bad."
lqname = lqname[:-4]
elif endswith(lqname, "ugly."):
ugly = True
suffix = "ugly."
lqname = lqname[:-5]
elif endswith(lqname, "good."):
suffix = "good."
lqname = lqname[:-5]
elif endswith(lqname, "slow."):
slow = True
suffix = "slow."
lqname = lqname[:-5]
elif endswith(lqname, "8.2.6.0.1.0.0.2.ip6.arpa."):
ip6req = True
elif endswith(lqname, "a.b.stale."):
if lqname == "a.b.stale.":
r.flags |= dns.flags.AA
if rrtype == TXT:
# Direct query.
r.answer.append(dns.rrset.from_text(lqname, 1, IN, TXT, "peekaboo"))
elif rrtype == NS:
# NS a.b.
r.answer.append(dns.rrset.from_text(lqname, 1, IN, NS, "ns.a.b.stale."))
r.additional.append(
dns.rrset.from_text("ns.a.b.stale.", 1, IN, A, "10.53.0.3")
)
elif rrtype == SOA:
# SOA a.b.
r.answer.append(
dns.rrset.from_text(
lqname, 1, IN, SOA, "a.b.stale. hostmaster.a.b.stale. 1 2 3 4 5"
)
)
else:
# NODATA.
r.authority.append(
dns.rrset.from_text(
lqname, 1, IN, SOA, "a.b.stale. hostmaster.a.b.stale. 1 2 3 4 5"
)
)
elif lqname == "ns.a.b.stale.":
r.flags |= dns.flags.AA
if rrtype == A:
r.answer.append(
dns.rrset.from_text("ns.a.b.stale.", 1, IN, A, "10.53.0.3")
)
else:
r.authority.append(
dns.rrset.from_text(
lqname, 1, IN, SOA, "a.b.stale. hostmaster.a.b.stale. 1 2 3 4 5"
)
)
else:
r.flags |= dns.flags.AA
r.authority.append(
dns.rrset.from_text(
lqname, 1, IN, SOA, "a.b.stale. hostmaster.a.b.stale. 1 2 3 4 5"
)
)
r.set_rcode(NXDOMAIN)
# NXDOMAIN.
return r
else:
r.set_rcode(REFUSED)
return r
# Good/bad differs only in how we treat non-empty terminals
if lqname == "zoop.boing." and rrtype == NS:
r.answer.append(
dns.rrset.from_text(lqname + suffix, 1, IN, NS, "ns3." + suffix)
)
r.flags |= dns.flags.AA
elif endswith(lqname, "icky.ptang.zoop.boing."):
r.authority.append(
dns.rrset.from_text(
"icky.ptang.zoop.boing." + suffix,
1,
IN,
NS,
"a.bit.longer.ns.name." + suffix,
)
)
elif endswith("icky.ptang.zoop.boing.", lqname):
r.authority.append(
dns.rrset.from_text(
"zoop.boing." + suffix,
1,
IN,
SOA,
"ns3." + suffix + " hostmaster.arpa. 2018050100 1 1 1 1",
)
)
if bad:
r.set_rcode(NXDOMAIN)
if ugly:
r.set_rcode(FORMERR)
elif endswith(lqname, "zoop.boing."):
r.authority.append(
dns.rrset.from_text(
"zoop.boing." + suffix,
1,
IN,
SOA,
"ns3." + suffix + " hostmaster.arpa. 2018050100 1 1 1 1",
)
)
r.set_rcode(NXDOMAIN)
elif ip6req:
r.authority.append(
dns.rrset.from_text(
"1.1.1.1.8.2.6.0.1.0.0.2.ip6.arpa.", 60, IN, NS, "ns4.good."
)
)
r.additional.append(dns.rrset.from_text("ns4.good.", 60, IN, A, "10.53.0.4"))
else:
r.set_rcode(REFUSED)
if slow:
time.sleep(0.4)
return r
class ZoopBoingSlowHandler(DelayedResponseHandler): def sigterm(signum, frame):
domains = ["zoop.boing.slow."] print("Shutting down now...")
delay = 0.4 os.remove("ans.pid")
running = False
sys.exit(0)
if __name__ == "__main__": ############################################################################
server = AsyncDnsServer() # Main
server.install_response_handler(QueryLogger()) #
server.install_response_handler(ZoopBoingBadHandler()) # Set up responder and control channel, open the pid file, and start
server.install_response_handler(ZoopBoingUglyHandler()) # the main loop, listening for queries on the query channel or commands
server.install_response_handler(ZoopBoingSlowHandler()) # on the control channel and acting on them.
server.run() ############################################################################
ip4 = "10.53.0.3"
ip6 = "fd92:7065:b8e:ffff::3"
try:
port = int(os.environ["PORT"])
except:
port = 5300
query4_socket = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
query4_socket.bind((ip4, port))
havev6 = True
try:
query6_socket = socket.socket(socket.AF_INET6, socket.SOCK_DGRAM)
try:
query6_socket.bind((ip6, port))
except:
query6_socket.close()
havev6 = False
except:
havev6 = False
signal.signal(signal.SIGTERM, sigterm)
f = open("ans.pid", "w")
pid = os.getpid()
print(pid, file=f)
f.close()
running = True
print("Listening on %s port %d" % (ip4, port))
if havev6:
print("Listening on %s port %d" % (ip6, port))
print("Ctrl-c to quit")
if havev6:
input = [query4_socket, query6_socket]
else:
input = [query4_socket]
while running:
try:
inputready, outputready, exceptready = select.select(input, [], [])
except select.error as e:
break
except socket.error as e:
break
except KeyboardInterrupt:
break
for s in inputready:
if s == query4_socket or s == query6_socket:
print(
"Query received on %s" % (ip4 if s == query4_socket else ip6), end=" "
)
# Handle incoming queries
msg = s.recvfrom(65535)
rsp = create_response(msg[0])
if rsp:
print(dns.rcode.to_text(rsp.rcode()))
s.sendto(rsp.to_wire(), msg[1])
else:
print("NO RESPONSE")
if not running:
break
@@ -1,14 +0,0 @@
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
;
; SPDX-License-Identifier: MPL-2.0
;
; This Source Code Form is subject to the terms of the Mozilla Public
; License, v. 2.0. If a copy of the MPL was not distributed with this
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
;
; See the COPYRIGHT file distributed with this work for additional
; information regarding copyright ownership.
@ 1 SOA ns3.bad. hostmaster.arpa. 2018050100 1 1 1 1
@ 1 NS ns3.bad.
icky.ptang 1 NS a.bit.longer.ns.name.bad.
@@ -1,14 +0,0 @@
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
;
; SPDX-License-Identifier: MPL-2.0
;
; This Source Code Form is subject to the terms of the Mozilla Public
; License, v. 2.0. If a copy of the MPL was not distributed with this
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
;
; See the COPYRIGHT file distributed with this work for additional
; information regarding copyright ownership.
@ 1 SOA ns3.good. hostmaster.arpa. 2018050100 1 1 1 1
@ 1 NS ns3.good.
icky.ptang 1 NS a.bit.longer.ns.name.good.
@@ -1,14 +0,0 @@
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
;
; SPDX-License-Identifier: MPL-2.0
;
; This Source Code Form is subject to the terms of the Mozilla Public
; License, v. 2.0. If a copy of the MPL was not distributed with this
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
;
; See the COPYRIGHT file distributed with this work for additional
; information regarding copyright ownership.
@ 1 SOA ns3.slow. hostmaster.arpa. 2018050100 1 1 1 1
@ 1 NS ns3.slow.
icky.ptang 1 NS a.bit.longer.ns.name.slow.
@@ -1,14 +0,0 @@
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
;
; SPDX-License-Identifier: MPL-2.0
;
; This Source Code Form is subject to the terms of the Mozilla Public
; License, v. 2.0. If a copy of the MPL was not distributed with this
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
;
; See the COPYRIGHT file distributed with this work for additional
; information regarding copyright ownership.
@ 1 SOA ns3.ugly. hostmaster.arpa. 2018050100 1 1 1 1
@ 1 NS ns3.ugly.
icky.ptang 1 NS a.bit.longer.ns.name.ugly.
@@ -1,15 +0,0 @@
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
;
; SPDX-License-Identifier: MPL-2.0
;
; This Source Code Form is subject to the terms of the Mozilla Public
; License, v. 2.0. If a copy of the MPL was not distributed with this
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
;
; See the COPYRIGHT file distributed with this work for additional
; information regarding copyright ownership.
@ 30 SOA ns4.good. hostmaster.arpa. 2018050100 1 1 1 1
@ 30 NS ns4.good.
test1.test2.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.9.0.9.4 1 TXT "long_ip6_name"
-15
View File
@@ -1,15 +0,0 @@
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
;
; SPDX-License-Identifier: MPL-2.0
;
; This Source Code Form is subject to the terms of the Mozilla Public
; License, v. 2.0. If a copy of the MPL was not distributed with this
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
;
; See the COPYRIGHT file distributed with this work for additional
; information regarding copyright ownership.
@ 1 SOA ns hostmaster.a.b.stale. 1 2 3 4 5
@ 1 NS ns
ns 1 A 10.53.0.4
@ 1 TXT "hooray"
+330 -79
View File
@@ -1,93 +1,344 @@
""" # Copyright (C) Internet Systems Consortium, Inc. ("ISC")
Copyright (C) Internet Systems Consortium, Inc. ("ISC") #
# SPDX-License-Identifier: MPL-2.0
#
# This Source Code Form is subject to the terms of the Mozilla Public
# License, v. 2.0. If a copy of the MPL was not distributed with this
# file, you can obtain one at https://mozilla.org/MPL/2.0/.
#
# See the COPYRIGHT file distributed with this work for additional
# information regarding copyright ownership.
SPDX-License-Identifier: MPL-2.0 from __future__ import print_function
import os
import sys
import signal
import socket
import select
from datetime import datetime, timedelta
import time
import functools
This Source Code Form is subject to the terms of the Mozilla Public import dns, dns.message, dns.query, dns.flags
License, v. 2.0. If a copy of the MPL was not distributed with this from dns.rdatatype import *
file, you can obtain one at https://mozilla.org/MPL/2.0/. from dns.rdataclass import *
from dns.rcode import *
See the COPYRIGHT file distributed with this work for additional from dns.name import *
information regarding copyright ownership.
"""
from typing import AsyncGenerator
import dns.rcode
from isctest.asyncserver import (
AsyncDnsServer,
DnsResponseSend,
DomainHandler,
QueryContext,
ResponseAction,
)
from qmin_ans import DelayedResponseHandler, EntRcodeChanger, QueryLogHandler, log_query
class QueryLogger(QueryLogHandler): # Log query to file
domains = [ def logquery(type, qname):
"1.1.1.1.8.2.6.0.1.0.0.2.ip6.arpa.", with open("qlog", "a") as f:
"icky.ptang.zoop.boing.good.", f.write("%s %s\n", type, qname)
]
class StaleHandler(DomainHandler): def endswith(domain, labels):
""" return domain.endswith("." + labels) or domain == labels
The test code relies on this server returning non-minimal (i.e. including
address records in the ADDITIONAL section) responses to NS queries for
`b.stale` and `a.b.stale`. While this logic (returning non-minimal
responses to NS queries) could be implemented in AsyncDnsServer itself,
doing so breaks a lot of other checks in this system test. Therefore, only
these two zones behave in this particular way, thanks to a custom response
handler implemented below.
"""
domains = ["b.stale", "a.b.stale"]
async def get_responses(
self, qctx: QueryContext
) -> AsyncGenerator[ResponseAction, None]:
log_query(qctx)
if qctx.qtype == dns.rdatatype.NS:
assert qctx.zone
assert qctx.response.answer[0]
for nameserver in qctx.response.answer[0]:
if not nameserver.target.is_subdomain(qctx.response.answer[0].name):
continue
glue_a = qctx.zone.get_rrset(nameserver.target, dns.rdatatype.A)
if glue_a:
qctx.response.additional.append(glue_a)
glue_aaaa = qctx.zone.get_rrset(nameserver.target, dns.rdatatype.AAAA)
if glue_aaaa:
qctx.response.additional.append(glue_aaaa)
yield DnsResponseSend(qctx.response)
class IckyPtangZoopBoingBadHandler(EntRcodeChanger): ############################################################################
domains = ["icky.ptang.zoop.boing.bad."] # Respond to a DNS query.
rcode = dns.rcode.NXDOMAIN # For good. it serves:
# icky.ptang.zoop.boing.good. NS a.bit.longer.ns.name.
# icky.icky.icky.ptang.zoop.boing.good. A 192.0.2.1
# more.icky.icky.icky.ptang.zoop.boing.good. A 192.0.2.2
# it responds properly (with NODATA empty response) to non-empty terminals
#
# For slow. it works the same as for good., but each response is delayed by 400 milliseconds
#
# For bad. it works the same as for good., but returns NXDOMAIN to non-empty terminals
#
# For ugly. it works the same as for good., but returns garbage to non-empty terminals
#
# For stale. it serves:
# a.b.stale. IN TXT hooray (resolver did do qname minimization)
############################################################################
def create_response(msg):
m = dns.message.from_wire(msg)
qname = m.question[0].name.to_text()
lqname = qname.lower()
labels = lqname.split(".")
suffix = ""
# get qtype
rrtype = m.question[0].rdtype
typename = dns.rdatatype.to_text(rrtype)
if typename == "A" or typename == "AAAA":
typename = "ADDR"
bad = False
slow = False
ugly = False
# log this query
with open("query.log", "a") as f:
f.write("%s %s\n" % (typename, lqname))
print("%s %s" % (typename, lqname), end=" ")
r = dns.message.make_response(m)
r.set_rcode(NOERROR)
ip6req = False
if endswith(lqname, "bad."):
bad = True
suffix = "bad."
lqname = lqname[:-4]
elif endswith(lqname, "ugly."):
ugly = True
suffix = "ugly."
lqname = lqname[:-5]
elif endswith(lqname, "good."):
suffix = "good."
lqname = lqname[:-5]
elif endswith(lqname, "slow."):
slow = True
suffix = "slow."
lqname = lqname[:-5]
elif endswith(lqname, "1.1.1.1.8.2.6.0.1.0.0.2.ip6.arpa."):
ip6req = True
elif endswith(lqname, "b.stale."):
if lqname == "a.b.stale.":
r.flags |= dns.flags.AA
if rrtype == TXT:
# Direct query.
r.answer.append(dns.rrset.from_text(lqname, 1, IN, TXT, "hooray"))
elif rrtype == NS:
# NS a.b.
r.answer.append(dns.rrset.from_text(lqname, 1, IN, NS, "ns.a.b.stale."))
r.additional.append(
dns.rrset.from_text("ns.a.b.stale.", 1, IN, A, "10.53.0.3")
)
elif rrtype == SOA:
# SOA a.b.
r.answer.append(
dns.rrset.from_text(
lqname, 1, IN, SOA, "a.b.stale. hostmaster.a.b.stale. 1 2 3 4 5"
)
)
else:
# NODATA.
r.authority.append(
dns.rrset.from_text(
lqname, 1, IN, SOA, "a.b.stale. hostmaster.a.b.stale. 1 2 3 4 5"
)
)
elif lqname == "ns.a.b.stale.":
r.flags |= dns.flags.AA
if rrtype == A:
r.answer.append(
dns.rrset.from_text("ns.a.b.stale.", 1, IN, A, "10.53.0.3")
)
else:
# NODATA.
r.authority.append(
dns.rrset.from_text(
lqname, 1, IN, SOA, "a.b.stale. hostmaster.a.b.stale. 1 2 3 4 5"
)
)
elif lqname == "b.stale.":
r.flags |= dns.flags.AA
if rrtype == NS:
# NS b.
r.answer.append(dns.rrset.from_text(lqname, 1, IN, NS, "ns.b.stale."))
r.additional.append(
dns.rrset.from_text("ns.b.stale.", 1, IN, A, "10.53.0.4")
)
elif rrtype == SOA:
# SOA b.
r.answer.append(
dns.rrset.from_text(
lqname, 1, IN, SOA, "b.stale. hostmaster.b.stale. 1 2 3 4 5"
)
)
else:
# NODATA.
r.authority.append(
dns.rrset.from_text(
lqname, 1, IN, SOA, "b.stale. hostmaster.b.stale. 1 2 3 4 5"
)
)
elif lqname == "ns.b.stale.":
r.flags |= dns.flags.AA
if rrtype == A:
# SOA a.b.
r.answer.append(
dns.rrset.from_text("ns.a.b.stale.", 1, IN, A, "10.53.0.4")
)
else:
# NODATA.
r.authority.append(
dns.rrset.from_text(
lqname, 1, IN, SOA, "b.stale. hostmaster.b.stale. 1 2 3 4 5"
)
)
else:
r.authority.append(
dns.rrset.from_text(
lqname, 1, IN, SOA, "b.stale. hostmaster.b.stale. 1 2 3 4 5"
)
)
r.set_rcode(NXDOMAIN)
# NXDOMAIN.
return r
else:
r.set_rcode(REFUSED)
return r
# Good/bad differs only in how we treat non-empty terminals
if lqname == "icky.icky.icky.ptang.zoop.boing." and rrtype == A:
r.answer.append(dns.rrset.from_text(lqname + suffix, 1, IN, A, "192.0.2.1"))
r.flags |= dns.flags.AA
elif lqname == "more.icky.icky.icky.ptang.zoop.boing." and rrtype == A:
r.answer.append(dns.rrset.from_text(lqname + suffix, 1, IN, A, "192.0.2.2"))
r.flags |= dns.flags.AA
elif lqname == "icky.ptang.zoop.boing." and rrtype == NS:
r.answer.append(
dns.rrset.from_text(
lqname + suffix, 1, IN, NS, "a.bit.longer.ns.name." + suffix
)
)
r.flags |= dns.flags.AA
elif endswith(lqname, "icky.ptang.zoop.boing."):
r.authority.append(
dns.rrset.from_text(
"icky.ptang.zoop.boing." + suffix,
1,
IN,
SOA,
"ns2." + suffix + " hostmaster.arpa. 2018050100 1 1 1 1",
)
)
if bad or not endswith("more.icky.icky.icky.ptang.zoop.boing.", lqname):
r.set_rcode(NXDOMAIN)
if ugly:
r.set_rcode(FORMERR)
elif ip6req:
r.flags |= dns.flags.AA
if (
lqname
== "test1.test2.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.9.0.9.4.1.1.1.1.8.2.6.0.1.0.0.2.ip6.arpa."
and rrtype == TXT
):
r.answer.append(
dns.rrset.from_text(
"test1.test2.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.9.0.9.4.1.1.1.1.8.2.6.0.1.0.0.2.ip6.arpa.",
1,
IN,
TXT,
"long_ip6_name",
)
)
elif endswith(
"0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.9.0.9.4.1.1.1.1.8.2.6.0.1.0.0.2.ip6.arpa.",
lqname,
):
# NODATA answer
r.authority.append(
dns.rrset.from_text(
"1.1.1.1.8.2.6.0.1.0.0.2.ip6.arpa.",
60,
IN,
SOA,
"ns4.good. hostmaster.arpa. 2018050100 120 30 320 16",
)
)
else:
# NXDOMAIN
r.authority.append(
dns.rrset.from_text(
"1.1.1.1.8.2.6.0.1.0.0.2.ip6.arpa.",
60,
IN,
SOA,
"ns4.good. hostmaster.arpa. 2018050100 120 30 320 16",
)
)
r.set_rcode(NXDOMAIN)
else:
r.set_rcode(REFUSED)
if slow:
time.sleep(0.4)
return r
class IckyPtangZoopBoingUglyHandler(EntRcodeChanger): def sigterm(signum, frame):
domains = ["icky.ptang.zoop.boing.ugly."] print("Shutting down now...")
rcode = dns.rcode.FORMERR os.remove("ans.pid")
running = False
sys.exit(0)
class IckyPtangZoopBoingSlowHandler(DelayedResponseHandler): ############################################################################
domains = ["icky.ptang.zoop.boing.slow."] # Main
delay = 0.4 #
# Set up responder and control channel, open the pid file, and start
# the main loop, listening for queries on the query channel or commands
# on the control channel and acting on them.
############################################################################
ip4 = "10.53.0.4"
ip6 = "fd92:7065:b8e:ffff::4"
try:
port = int(os.environ["PORT"])
except:
port = 5300
if __name__ == "__main__": query4_socket = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
server = AsyncDnsServer() query4_socket.bind((ip4, port))
server.install_response_handler(QueryLogger())
server.install_response_handler(StaleHandler()) havev6 = True
server.install_response_handler(IckyPtangZoopBoingBadHandler()) try:
server.install_response_handler(IckyPtangZoopBoingUglyHandler()) query6_socket = socket.socket(socket.AF_INET6, socket.SOCK_DGRAM)
server.install_response_handler(IckyPtangZoopBoingSlowHandler()) try:
server.run() query6_socket.bind((ip6, port))
except:
query6_socket.close()
havev6 = False
except:
havev6 = False
signal.signal(signal.SIGTERM, sigterm)
f = open("ans.pid", "w")
pid = os.getpid()
print(pid, file=f)
f.close()
running = True
print("Listening on %s port %d" % (ip4, port))
if havev6:
print("Listening on %s port %d" % (ip6, port))
print("Ctrl-c to quit")
if havev6:
input = [query4_socket, query6_socket]
else:
input = [query4_socket]
while running:
try:
inputready, outputready, exceptready = select.select(input, [], [])
except select.error as e:
break
except socket.error as e:
break
except KeyboardInterrupt:
break
for s in inputready:
if s == query4_socket or s == query6_socket:
print(
"Query received on %s" % (ip4 if s == query4_socket else ip6), end=" "
)
# Handle incoming queries
msg = s.recvfrom(65535)
rsp = create_response(msg[0])
if rsp:
print(dns.rcode.to_text(rsp.rcode()))
s.sendto(rsp.to_wire(), msg[1])
else:
print("NO RESPONSE")
if not running:
break
-16
View File
@@ -1,16 +0,0 @@
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
;
; SPDX-License-Identifier: MPL-2.0
;
; This Source Code Form is subject to the terms of the Mozilla Public
; License, v. 2.0. If a copy of the MPL was not distributed with this
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
;
; See the COPYRIGHT file distributed with this work for additional
; information regarding copyright ownership.
@ 1 SOA ns hostmaster.b.stale. 1 2 3 4 5
@ 1 NS ns
ns 1 A 10.53.0.4
a 1 NS ns.a
ns.a 1 A 10.53.0.4
@@ -1,15 +0,0 @@
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
;
; SPDX-License-Identifier: MPL-2.0
;
; This Source Code Form is subject to the terms of the Mozilla Public
; License, v. 2.0. If a copy of the MPL was not distributed with this
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
;
; See the COPYRIGHT file distributed with this work for additional
; information regarding copyright ownership.
@ 1 SOA ns4.bad. hostmaster.arpa. 2018050100 1 1 1 1
@ 1 NS a.bit.longer.ns.name.bad.
icky.icky 1 A 192.0.2.1
more.icky.icky 1 A 192.0.2.2
@@ -1,15 +0,0 @@
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
;
; SPDX-License-Identifier: MPL-2.0
;
; This Source Code Form is subject to the terms of the Mozilla Public
; License, v. 2.0. If a copy of the MPL was not distributed with this
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
;
; See the COPYRIGHT file distributed with this work for additional
; information regarding copyright ownership.
@ 1 SOA ns4.good. hostmaster.arpa. 2018050100 1 1 1 1
@ 1 NS a.bit.longer.ns.name.good.
icky.icky 1 A 192.0.2.1
more.icky.icky 1 A 192.0.2.2
@@ -1,15 +0,0 @@
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
;
; SPDX-License-Identifier: MPL-2.0
;
; This Source Code Form is subject to the terms of the Mozilla Public
; License, v. 2.0. If a copy of the MPL was not distributed with this
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
;
; See the COPYRIGHT file distributed with this work for additional
; information regarding copyright ownership.
@ 1 SOA ns4.slow. hostmaster.arpa. 2018050100 1 1 1 1
@ 1 NS a.bit.longer.ns.name.slow.
icky.icky 1 A 192.0.2.1
more.icky.icky 1 A 192.0.2.2
@@ -1,15 +0,0 @@
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
;
; SPDX-License-Identifier: MPL-2.0
;
; This Source Code Form is subject to the terms of the Mozilla Public
; License, v. 2.0. If a copy of the MPL was not distributed with this
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
;
; See the COPYRIGHT file distributed with this work for additional
; information regarding copyright ownership.
@ 1 SOA ns4.ugly. hostmaster.arpa. 2018050100 1 1 1 1
@ 1 NS a.bit.longer.ns.name.ugly.
icky.icky 1 A 192.0.2.1
more.icky.icky 1 A 192.0.2.2
-107
View File
@@ -1,107 +0,0 @@
"""
Copyright (C) Internet Systems Consortium, Inc. ("ISC")
SPDX-License-Identifier: MPL-2.0
This Source Code Form is subject to the terms of the Mozilla Public
License, v. 2.0. If a copy of the MPL was not distributed with this
file, you can obtain one at https://mozilla.org/MPL/2.0/.
See the COPYRIGHT file distributed with this work for additional
information regarding copyright ownership.
"""
from typing import AsyncGenerator
import abc
import dns.rcode
import dns.rdataclass
import dns.rdatatype
from isctest.asyncserver import (
DnsResponseSend,
DomainHandler,
QueryContext,
ResponseAction,
)
from isctest.compat import dns_rcode
def log_query(qctx: QueryContext) -> None:
"""
Log a received DNS query to a text file inspected by `tests.sh`. AAAA and
A queries are logged identically because the relative order in which they
are received does not matter.
"""
qname = qctx.qname.to_text()
qtype = dns.rdatatype.to_text(qctx.qtype)
if qtype in ("A", "AAAA"):
qtype = "ADDR"
with open("query.log", "a", encoding="utf-8") as query_log:
print(f"{qtype} {qname}", file=query_log)
class QueryLogHandler(DomainHandler):
"""
Log all received DNS queries to a text file. Use the zone file for
preparing responses.
"""
async def get_responses(
self, qctx: QueryContext
) -> AsyncGenerator[ResponseAction, None]:
log_query(qctx)
yield DnsResponseSend(qctx.response)
class EntRcodeChanger(DomainHandler):
"""
Log all received DNS queries to a text file. Use the zone file for
preparing responses, but override the RCODE returned for empty
non-terminals (ENTs) to the value specified by the child class. This
emulates broken authoritative servers.
"""
@property
@abc.abstractmethod
def rcode(self) -> dns_rcode:
raise NotImplementedError
async def get_responses(
self, qctx: QueryContext
) -> AsyncGenerator[ResponseAction, None]:
assert qctx.zone
log_query(qctx)
if (
qctx.response.rcode() == dns.rcode.NOERROR
and not qctx.response.answer
and qctx.response.authority
and qctx.response.authority[0].rdtype == dns.rdatatype.SOA
and not qctx.zone.get_node(qctx.qname)
):
qctx.response.set_rcode(self.rcode)
yield DnsResponseSend(qctx.response)
class DelayedResponseHandler(DomainHandler):
"""
Log all received DNS queries to a text file. Use the zone file for
preparing responses, but delay sending every answer by the amount of time
specified (in seconds) by the child class. This emulates network delays.
"""
@property
@abc.abstractmethod
def delay(self) -> float:
raise NotImplementedError
async def get_responses(
self, qctx: QueryContext
) -> AsyncGenerator[ResponseAction, None]:
log_query(qctx)
yield DnsResponseSend(qctx.response, delay=self.delay)
-23
View File
@@ -127,14 +127,12 @@ ADDR a.bit.longer.ns.name.good.
ADDR ns2.good. ADDR ns2.good.
ADDR ns3.good. ADDR ns3.good.
ADDR ns3.good. ADDR ns3.good.
NS a.bit.longer.ns.name.good.
NS bit.longer.ns.name.good. NS bit.longer.ns.name.good.
NS boing.good. NS boing.good.
NS good. NS good.
NS longer.ns.name.good. NS longer.ns.name.good.
NS name.good. NS name.good.
NS ns.name.good. NS ns.name.good.
NS ns3.good.
NS zoop.boing.good. NS zoop.boing.good.
__EOF __EOF
cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1 cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1
@@ -167,13 +165,11 @@ ADDR a.bit.longer.ns.name.good.
ADDR ns2.good. ADDR ns2.good.
ADDR ns3.good. ADDR ns3.good.
ADDR ns3.good. ADDR ns3.good.
NS a.bit.longer.ns.name.good.
NS bit.longer.ns.name.good. NS bit.longer.ns.name.good.
NS boing.good. NS boing.good.
NS longer.ns.name.good. NS longer.ns.name.good.
NS name.good. NS name.good.
NS ns.name.good. NS ns.name.good.
NS ns3.good.
NS zoop.boing.good. NS zoop.boing.good.
__EOF __EOF
cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1 cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1
@@ -225,7 +221,6 @@ ADDR ns3.bad.
ADDR ns3.bad. ADDR ns3.bad.
NS boing.bad. NS boing.bad.
NS name.bad. NS name.bad.
NS ns3.bad.
__EOF __EOF
cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1 cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1
ADDR icky.icky.icky.ptang.zoop.boing.bad. ADDR icky.icky.icky.ptang.zoop.boing.bad.
@@ -276,7 +271,6 @@ ADDR ns3.ugly.
NS boing.ugly. NS boing.ugly.
NS name.ugly. NS name.ugly.
NS name.ugly. NS name.ugly.
NS ns3.ugly.
__EOF __EOF
echo "ADDR icky.icky.icky.ptang.zoop.boing.ugly." | diff ans3/query.log - >/dev/null || ret=1 echo "ADDR icky.icky.icky.ptang.zoop.boing.ugly." | diff ans3/query.log - >/dev/null || ret=1
echo "ADDR icky.icky.icky.ptang.zoop.boing.ugly." | diff ans4/query.log - >/dev/null || ret=1 echo "ADDR icky.icky.icky.ptang.zoop.boing.ugly." | diff ans4/query.log - >/dev/null || ret=1
@@ -308,13 +302,11 @@ ADDR a.bit.longer.ns.name.slow.
ADDR ns2.slow. ADDR ns2.slow.
ADDR ns3.slow. ADDR ns3.slow.
ADDR ns3.slow. ADDR ns3.slow.
NS a.bit.longer.ns.name.slow.
NS bit.longer.ns.name.slow. NS bit.longer.ns.name.slow.
NS boing.slow. NS boing.slow.
NS longer.ns.name.slow. NS longer.ns.name.slow.
NS name.slow. NS name.slow.
NS ns.name.slow. NS ns.name.slow.
NS ns3.slow.
NS slow. NS slow.
NS zoop.boing.slow. NS zoop.boing.slow.
__EOF __EOF
@@ -348,7 +340,6 @@ NS 8.f.4.0.1.0.0.2.ip6.arpa.
NS 0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa. NS 0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
NS 0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa. NS 0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
NS 0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa. NS 0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
NS 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
PTR 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa. PTR 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
__EOF __EOF
for ans in ans2 ans3 ans4; do mv -f $ans/query.log query-$ans-$n.log 2>/dev/null || true; done for ans in ans2 ans3 ans4; do mv -f $ans/query.log query-$ans-$n.log 2>/dev/null || true; done
@@ -371,14 +362,12 @@ ADDR a.bit.longer.ns.name.good.
ADDR ns2.good. ADDR ns2.good.
ADDR ns3.good. ADDR ns3.good.
ADDR ns3.good. ADDR ns3.good.
NS a.bit.longer.ns.name.good.
NS bit.longer.ns.name.good. NS bit.longer.ns.name.good.
NS boing.good. NS boing.good.
NS good. NS good.
NS longer.ns.name.good. NS longer.ns.name.good.
NS name.good. NS name.good.
NS ns.name.good. NS ns.name.good.
NS ns3.good.
NS zoop.boing.good. NS zoop.boing.good.
__EOF __EOF
cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1 cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1
@@ -460,7 +449,6 @@ grep "a\.b\.stale\..*1.*IN.*TXT.*hooray" dig.out.test$n >/dev/null || ret=1
sleep 1 sleep 1
sort ans2/query.log >ans2/query.log.sorted sort ans2/query.log >ans2/query.log.sorted
cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1 cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1
ADDR ns.a.b.stale.
ADDR ns.b.stale. ADDR ns.b.stale.
ADDR ns2.stale. ADDR ns2.stale.
NS b.stale. NS b.stale.
@@ -469,9 +457,7 @@ __EOF
test -f ans3/query.log && ret=1 test -f ans3/query.log && ret=1
sort ans4/query.log >ans4/query.log.sorted sort ans4/query.log >ans4/query.log.sorted
cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1 cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1
ADDR ns.a.b.stale.
ADDR ns.b.stale. ADDR ns.b.stale.
NS a.b.stale.
NS b.stale. NS b.stale.
TXT a.b.stale. TXT a.b.stale.
__EOF __EOF
@@ -490,7 +476,6 @@ grep "a\.b\.stale\..*1.*IN.*TXT.*hooray" dig.out.test$n >/dev/null || ret=1
sleep 1 sleep 1
sort ans2/query.log >ans2/query.log.sorted sort ans2/query.log >ans2/query.log.sorted
cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1 cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1
ADDR ns.a.b.stale.
ADDR ns.b.stale. ADDR ns.b.stale.
ADDR ns2.stale. ADDR ns2.stale.
NS b.stale. NS b.stale.
@@ -498,9 +483,7 @@ __EOF
test -f ans3/query.log && ret=1 test -f ans3/query.log && ret=1
sort ans4/query.log >ans4/query.log.sorted sort ans4/query.log >ans4/query.log.sorted
cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1 cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1
ADDR ns.a.b.stale.
ADDR ns.b.stale. ADDR ns.b.stale.
NS a.b.stale.
TXT a.b.stale. TXT a.b.stale.
__EOF __EOF
for ans in ans2 ans3 ans4; do mv -f $ans/query.log query-$ans-$n.log 2>/dev/null || true; done for ans in ans2 ans3 ans4; do mv -f $ans/query.log query-$ans-$n.log 2>/dev/null || true; done
@@ -536,7 +519,6 @@ grep "a\.b\.stale\..*1.*IN.*TXT.*hooray" dig.out.test$n >/dev/null || ret=1
sleep 1 sleep 1
sort ans2/query.log >ans2/query.log.sorted sort ans2/query.log >ans2/query.log.sorted
cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1 cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1
ADDR ns.a.b.stale.
ADDR ns.b.stale. ADDR ns.b.stale.
ADDR ns2.stale. ADDR ns2.stale.
NS b.stale. NS b.stale.
@@ -545,9 +527,7 @@ __EOF
test -f ans3/query.log && ret=1 test -f ans3/query.log && ret=1
sort ans4/query.log >ans4/query.log.sorted sort ans4/query.log >ans4/query.log.sorted
cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1 cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1
ADDR ns.a.b.stale.
ADDR ns.b.stale. ADDR ns.b.stale.
NS a.b.stale.
NS b.stale. NS b.stale.
TXT a.b.stale. TXT a.b.stale.
__EOF __EOF
@@ -566,7 +546,6 @@ grep "a\.b\.stale\..*1.*IN.*TXT.*hooray" dig.out.test$n >/dev/null || ret=1
sleep 1 sleep 1
sort ans2/query.log >ans2/query.log.sorted sort ans2/query.log >ans2/query.log.sorted
cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1 cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1
ADDR ns.a.b.stale.
ADDR ns.b.stale. ADDR ns.b.stale.
ADDR ns2.stale. ADDR ns2.stale.
NS b.stale. NS b.stale.
@@ -574,9 +553,7 @@ __EOF
test -f ans3/query.log && ret=1 test -f ans3/query.log && ret=1
sort ans4/query.log >ans4/query.log.sorted sort ans4/query.log >ans4/query.log.sorted
cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1 cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1
ADDR ns.a.b.stale.
ADDR ns.b.stale. ADDR ns.b.stale.
NS a.b.stale.
TXT a.b.stale. TXT a.b.stale.
__EOF __EOF
for ans in ans2 ans3 ans4; do mv -f $ans/query.log query-$ans-$n.log 2>/dev/null || true; done for ans in ans2 ans3 ans4; do mv -f $ans/query.log query-$ans-$n.log 2>/dev/null || true; done
+2 -2
View File
@@ -9,9 +9,9 @@
; See the COPYRIGHT file distributed with this work for additional ; See the COPYRIGHT file distributed with this work for additional
; information regarding copyright ownership. ; information regarding copyright ownership.
$TTL 120 $TTL 60
big. IN SOA ns.big. hostmaster.ns.big. 1 0 0 0 120 big. IN SOA ns.big. hostmaster.ns.big. 1 0 0 0 60
big. IN NS ns.big. big. IN NS ns.big.
ns.big. IN A 10.53.0.1 ns.big. IN A 10.53.0.1
+25 -25
View File
@@ -280,11 +280,11 @@ echo_i "checking that priority names under the max-types-per-name limit get cach
# Query for NXDOMAIN for items on our priority list - these should get cached # Query for NXDOMAIN for items on our priority list - these should get cached
for rrtype in AAAA MX NS; do for rrtype in AAAA MX NS; do
check_manytypes 1 manytypes.big "${rrtype}" NOERROR big SOA 120 || ret=1 check_manytypes 1 manytypes.big "${rrtype}" NOERROR big SOA 60 || ret=1
done done
# Wait at least 1 second # Wait at least 1 second
for rrtype in AAAA MX NS; do for rrtype in AAAA MX NS; do
check_manytypes 2 manytypes.big "${rrtype}" NOERROR big SOA "" 120 || ret=1 check_manytypes 2 manytypes.big "${rrtype}" NOERROR big SOA "" 60 || ret=1
done done
if [ $ret -ne 0 ]; then echo_i "failed"; fi if [ $ret -ne 0 ]; then echo_i "failed"; fi
@@ -299,13 +299,13 @@ echo_i "checking that NXDOMAIN names under the max-types-per-name limit get cach
# Query for 10 NXDOMAIN types # Query for 10 NXDOMAIN types
for ntype in $(seq 65270 65279); do for ntype in $(seq 65270 65279); do
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR big SOA 120 || ret=1 check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR big SOA 60 || ret=1
done done
# Wait at least 1 second # Wait at least 1 second
sleep 1 sleep 1
# Query for 10 NXDOMAIN types again - these should be cached # Query for 10 NXDOMAIN types again - these should be cached
for ntype in $(seq 65270 65279); do for ntype in $(seq 65270 65279); do
check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR big SOA "" 120 || ret=1 check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR big SOA "" 60 || ret=1
done done
if [ $ret -ne 0 ]; then echo_i "failed"; fi if [ $ret -ne 0 ]; then echo_i "failed"; fi
@@ -318,13 +318,13 @@ echo_i "checking that existing names under the max-types-per-name limit get cach
# Limited to 10 types - these should be cached and the previous record should be evicted # Limited to 10 types - these should be cached and the previous record should be evicted
for ntype in $(seq 65280 65289); do for ntype in $(seq 65280 65289); do
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 120 || ret=1 check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 60 || ret=1
done done
# Wait at least one second # Wait at least one second
sleep 1 sleep 1
# Limited to 10 types - these should be cached # Limited to 10 types - these should be cached
for ntype in $(seq 65280 65289); do for ntype in $(seq 65280 65289); do
check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" "" 120 || ret=1 check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" "" 60 || ret=1
done done
if [ $ret -ne 0 ]; then echo_i "failed"; fi if [ $ret -ne 0 ]; then echo_i "failed"; fi
@@ -356,11 +356,11 @@ echo_i "checking that priority NXDOMAIN names over the max-types-per-name limit
# Query for NXDOMAIN for items on our priority list - these should get cached # Query for NXDOMAIN for items on our priority list - these should get cached
for rrtype in AAAA MX NS; do for rrtype in AAAA MX NS; do
check_manytypes 1 manytypes.big "${rrtype}" NOERROR big SOA 120 || ret=1 check_manytypes 1 manytypes.big "${rrtype}" NOERROR big SOA 60 || ret=1
done done
# Wait at least 1 second # Wait at least 1 second
for rrtype in AAAA MX NS; do for rrtype in AAAA MX NS; do
check_manytypes 2 manytypes.big "${rrtype}" NOERROR big SOA "" 120 || ret=1 check_manytypes 2 manytypes.big "${rrtype}" NOERROR big SOA "" 60 || ret=1
done done
if [ $ret -ne 0 ]; then echo_i "failed"; fi if [ $ret -ne 0 ]; then echo_i "failed"; fi
@@ -372,11 +372,11 @@ ret=0
echo_i "checking that priority name over the max-types-per-name get cached ($n)" echo_i "checking that priority name over the max-types-per-name get cached ($n)"
# Query for an item on our priority list - it should get cached # Query for an item on our priority list - it should get cached
check_manytypes 1 manytypes.big "A" NOERROR manytypes.big A 120 || ret=1 check_manytypes 1 manytypes.big "A" NOERROR manytypes.big A 60 || ret=1
# Wait at least 1 second # Wait at least 1 second
sleep 1 sleep 1
# Query the same name again - it should be in the cache # Query the same name again - it should be in the cache
check_manytypes 2 manytypes.big "A" NOERROR big manytypes.A "" 120 || ret=1 check_manytypes 2 manytypes.big "A" NOERROR big manytypes.A "" 60 || ret=1
if [ $ret -ne 0 ]; then echo_i "failed"; fi if [ $ret -ne 0 ]; then echo_i "failed"; fi
status=$((status + ret)) status=$((status + ret))
@@ -389,7 +389,7 @@ ret=0
echo_i "checking that priority name over the max-types-per-name don't get evicted ($n)" echo_i "checking that priority name over the max-types-per-name don't get evicted ($n)"
# Query for an item on our priority list - it should get cached # Query for an item on our priority list - it should get cached
check_manytypes 1 manytypes.big "A" NOERROR manytypes.big A 120 || ret=1 check_manytypes 1 manytypes.big "A" NOERROR manytypes.big A 60 || ret=1
# Query for 10 more types - this should not evict A record # Query for 10 more types - this should not evict A record
for ntype in $(seq 65280 65289); do for ntype in $(seq 65280 65289); do
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big || ret=1 check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big || ret=1
@@ -397,9 +397,9 @@ done
# Wait at least 1 second # Wait at least 1 second
sleep 1 sleep 1
# Query the same name again - it should be in the cache # Query the same name again - it should be in the cache
check_manytypes 2 manytypes.big "A" NOERROR manytypes.big A "" 120 || ret=1 check_manytypes 2 manytypes.big "A" NOERROR manytypes.big A "" 60 || ret=1
# This one was first in the list and should have been evicted # This one was first in the list and should have been evicted
check_manytypes 2 manytypes.big "TYPE65280" NOERROR manytypes.big TYPE65280 120 || ret=1 check_manytypes 2 manytypes.big "TYPE65280" NOERROR manytypes.big TYPE65280 60 || ret=1
if [ $ret -ne 0 ]; then echo_i "failed"; fi if [ $ret -ne 0 ]; then echo_i "failed"; fi
status=$((status + ret)) status=$((status + ret))
@@ -413,21 +413,21 @@ echo_i "checking that non-priority types cause eviction ($n)"
# Everything on top of that will cause the cache eviction # Everything on top of that will cause the cache eviction
for ntype in $(seq 65280 65299); do for ntype in $(seq 65280 65299); do
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 120 || ret=1 check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 60 || ret=1
done done
# Wait at least one second # Wait at least one second
sleep 1 sleep 1
# These should have TTL != 120 now # These should have TTL != 60 now
for ntype in $(seq 65290 65299); do for ntype in $(seq 65290 65299); do
check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" "" 120 || ret=1 check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" "" 60 || ret=1
done done
# These should have been evicted # These should have been evicted
for ntype in $(seq 65280 65289); do for ntype in $(seq 65280 65289); do
check_manytypes 3 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 120 || ret=1 check_manytypes 3 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 60 || ret=1
done done
# These should have been evicted by the previous block # These should have been evicted by the previous block
for ntype in $(seq 65290 65299); do for ntype in $(seq 65290 65299); do
check_manytypes 4 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 120 || ret=1 check_manytypes 4 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 60 || ret=1
done done
if [ $ret -ne 0 ]; then echo_i "failed"; fi if [ $ret -ne 0 ]; then echo_i "failed"; fi
@@ -442,25 +442,25 @@ echo_i "checking that signed names under the max-types-per-name limit get cached
# Go through the 10 items, this should result in 20 items (type + rrsig(type)) # Go through the 10 items, this should result in 20 items (type + rrsig(type))
for ntype in $(seq 65280 65289); do for ntype in $(seq 65280 65289); do
check_manytypes 1 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" 120 || ret=1 check_manytypes 1 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" 60 || ret=1
done done
# Wait at least one second # Wait at least one second
sleep 1 sleep 1
# These should have TTL != 120 now # These should have TTL != 60 now
for ntype in $(seq 65285 65289); do for ntype in $(seq 65285 65289); do
check_manytypes 2 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" "" 120 || ret=1 check_manytypes 2 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" "" 60 || ret=1
done done
# These should have been evicted # These should have been evicted
for ntype in $(seq 65280 65284); do for ntype in $(seq 65280 65284); do
check_manytypes 3 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" 120 || ret=1 check_manytypes 3 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" 60 || ret=1
done done
# These should have been evicted by the previous block # These should have been evicted by the previous block
for ntype in $(seq 65285 65289); do for ntype in $(seq 65285 65289); do
check_manytypes 4 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" 120 || ret=1 check_manytypes 4 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" 60 || ret=1
done done
if [ $ret -ne 0 ]; then echo_i "failed"; fi if [ $ret -ne 0 ]; then echo_i "failed"; fi
@@ -475,12 +475,12 @@ echo_i "checking that lifting the limit will allow everything to get cached ($n)
ns3_reset ns3/named6.conf.in ns3_reset ns3/named6.conf.in
for ntype in $(seq 65280 65534); do for ntype in $(seq 65280 65534); do
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 120 || ret=1 check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 60 || ret=1
done done
# Wait at least one second # Wait at least one second
sleep 1 sleep 1
for ntype in $(seq 65280 65534); do for ntype in $(seq 65280 65534); do
check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" "" 120 || ret=1 check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" "" 60 || ret=1
done done
if [ $ret -ne 0 ]; then echo_i "failed"; fi if [ $ret -ne 0 ]; then echo_i "failed"; fi
-11
View File
@@ -20,8 +20,6 @@ use IO::Socket;
use Net::DNS; use Net::DNS;
use Net::DNS::Packet; use Net::DNS::Packet;
print "Using Net::DNS $Net::DNS::VERSION\n";
my $localport = int($ENV{'PORT'}); my $localport = int($ENV{'PORT'});
if (!$localport) { $localport = 5300; } if (!$localport) { $localport = 5300; }
@@ -172,15 +170,6 @@ for (;;) {
$packet->push("authority", $packet->push("authority",
new Net::DNS::RR($qname . " 300 SOA . . 0 0 0 0 0")); new Net::DNS::RR($qname . " 300 SOA . . 0 0 0 0 0"));
} }
} elsif ($qname eq "zoneversion") {
$packet->push("authority", new Net::DNS::RR(". 300 SOA . . 0 0 0 0 0"));
if ($Net::DNS::VERSION >= 1.49) {
$packet->edns->option('ZONEVERSION' => [0, 1, '01022304'] )
} elsif ($Net::DNS::VERSION >= 1.35) {
$packet->edns->option('19' => {'BASE16' => '000101022304'} )
} else {
$packet->edns->option('19' => pack 'H*', '000101022304')
}
} else { } else {
# Data for the "bogus referrals" test # Data for the "bogus referrals" test
$packet->push("authority", new Net::DNS::RR("below.www.example.com 300 NS ns.below.www.example.com")); $packet->push("authority", new Net::DNS::RR("below.www.example.com 300 NS ns.below.www.example.com"));
@@ -31,7 +31,6 @@ options {
resolver-query-timeout 5000; # 5 seconds resolver-query-timeout 5000; # 5 seconds
attach-cache "globalcache"; attach-cache "globalcache";
max-recursion-queries 100; max-recursion-queries 100;
request-zoneversion yes;
}; };
trust-anchors { }; trust-anchors { };
@@ -26,15 +26,6 @@ options {
querylog yes; querylog yes;
prefetch 4 10; prefetch 4 10;
responselog yes; responselog yes;
request-nsid yes;
request-zoneversion yes;
};
// Don't break tests which depend on ans10 by requesting
// zoneversion or nsid
server 10.53.0.10 {
request-nsid no;
request-zoneversion no;
}; };
include "trusted.conf"; include "trusted.conf";
-1
View File
@@ -24,6 +24,5 @@ copy_setports ns5/named.conf.in ns5/named.conf
copy_setports ns6/named.conf.in ns6/named.conf copy_setports ns6/named.conf.in ns6/named.conf
copy_setports ns7/named1.conf.in ns7/named.conf copy_setports ns7/named1.conf.in ns7/named.conf
copy_setports ns9/named.conf.in ns9/named.conf copy_setports ns9/named.conf.in ns9/named.conf
copy_setports ns11/named.conf.in ns11/named.conf
(cd ns6 && $SHELL keygen.sh) (cd ns6 && $SHELL keygen.sh)
+4 -50
View File
@@ -43,12 +43,6 @@ grep "status: NOERROR" dig.out.ns1.test${n} >/dev/null || ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=$((status + ret)) status=$((status + ret))
rndccmd 10.53.0.1 stats || ret=1 # Get the responses, RTT and timeout statistics before the following timeout tests
grep -F 'responses received' ns1/named.stats >ns1/named.stats.responses-before || true
grep -F 'queries with RTT' ns1/named.stats >ns1/named.stats.rtt-before || true
grep -F 'query timeouts' ns1/named.stats >ns1/named.stats.timeouts-before || true
mv ns1/named.stats ns1/named.stats-before
# 'resolver-query-timeout' is set to 5 seconds in ns1, so dig with a lower # 'resolver-query-timeout' is set to 5 seconds in ns1, so dig with a lower
# timeout value should give up earlier than that. # timeout value should give up earlier than that.
n=$((n + 1)) n=$((n + 1))
@@ -72,20 +66,6 @@ grep -F "EDE: 22 (No Reachable Authority)" dig.out.ns1.test${n} >/dev/null || re
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=$((status + ret)) status=$((status + ret))
n=$((n + 1))
echo_i "checking that the timeout didn't skew the resolver responses counters and did update the timeout counter ($n)"
ret=0
rndccmd 10.53.0.1 stats || ret=1
grep -F 'responses received' ns1/named.stats >ns1/named.stats.responses-after || true
grep -F 'queries with RTT' ns1/named.stats >ns1/named.stats.rtt-after || true
grep -F 'query timeouts' ns1/named.stats >ns1/named.stats.timeouts-after || true
mv ns1/named.stats ns1/named.stats-after
diff ns1/named.stats.responses-before ns1/named.stats.responses-after >/dev/null || ret=1
diff ns1/named.stats.rtt-before ns1/named.stats.rtt-after >/dev/null || ret=1
diff ns1/named.stats.timeouts-before ns1/named.stats.timeouts-after >/dev/null && ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi
status=$((status + ret))
# 'resolver-query-timeout' is set to 5 seconds in ns1, so named should # 'resolver-query-timeout' is set to 5 seconds in ns1, so named should
# interrupt the non-responsive query and send a SERVFAIL answer before dig's # interrupt the non-responsive query and send a SERVFAIL answer before dig's
# own timeout fires, which is set to 7 seconds. This time, exampleudp.net is # own timeout fires, which is set to 7 seconds. This time, exampleudp.net is
@@ -749,10 +729,10 @@ if ${FEATURETEST} --enable-querytrace; then
grep "status: SERVFAIL" dig.ns5.out.${n} >/dev/null || ret=1 grep "status: SERVFAIL" dig.ns5.out.${n} >/dev/null || ret=1
check_namedrun() { check_namedrun() {
nextpartpeek ns5/named.run >nextpart.out.${n} nextpartpeek ns5/named.run >nextpart.out.${n}
grep 'resolving tcpalso.no-questions/NS for [^:]*: empty question section, accepting it anyway as TC=1' nextpart.out.${n} >/dev/null || return 1 grep 'resolving tcpalso.no-questions/A for [^:]*: empty question section, accepting it anyway as TC=1' nextpart.out.${n} >/dev/null || return 1
grep '(tcpalso.no-questions/NS): connecting via TCP' nextpart.out.${n} >/dev/null || return 1 grep '(tcpalso.no-questions/A): connecting via TCP' nextpart.out.${n} >/dev/null || return 1
grep 'resolving tcpalso.no-questions/NS for [^:]*: empty question section$' nextpart.out.${n} >/dev/null || return 1 grep 'resolving tcpalso.no-questions/A for [^:]*: empty question section$' nextpart.out.${n} >/dev/null || return 1
grep '(tcpalso.no-questions/NS): nextitem' nextpart.out.${n} >/dev/null || return 1 grep '(tcpalso.no-questions/A): nextitem' nextpart.out.${n} >/dev/null || return 1
return 0 return 0
} }
retry_quiet 12 check_namedrun || ret=1 retry_quiet 12 check_namedrun || ret=1
@@ -901,23 +881,6 @@ test ${lines:-1} -ne 0 && ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=$((status + ret)) status=$((status + ret))
n=$((n + 1))
echo_i "check that received ZONEVERSION is logged ($n)"
ret=0
pat="received ZONEVERSION serial 2010 from 10.53.0.4#[0-9]* for mixedttl.tld/TXT zone tld"
grep "$pat" ns5/named.run >/dev/null || ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi
status=$((status + ret))
n=$((n + 1))
echo_i "check that received ZONEVERSION is logged non serial ($n)"
ret=0
dig_with_opts +tcp @10.53.0.1 zoneversion >dig.out.${n} || ret=1
pat='received ZONEVERSION type 1 value 01022304 (\.\.#\.) from 10.53.0.2#[0-9]* for zoneversion/A zone \.'
grep "$pat" ns1/named.run >/dev/null || ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi
status=$((status + ret))
n=$((n + 1)) n=$((n + 1))
echo_i "check resolver behavior when FORMERR for EDNS options happens (${n})" echo_i "check resolver behavior when FORMERR for EDNS options happens (${n})"
ret=0 ret=0
@@ -1052,14 +1015,5 @@ ttl=$(awk '{print $2}' dig.ns1.out.${n})
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=$((status + ret)) status=$((status + ret))
n=$((n + 1))
echo_i "client requests recursion but it is disabled - expect EDE 20 code with REFUSED($n)"
ret=0
dig_with_opts +recurse www.isc.org @10.53.0.11 a >dig.out.ns11.test${n} || ret=1
grep "status: REFUSED" dig.out.ns11.test${n} >/dev/null || ret=1
grep -F "EDE: 20 (Not Authoritative)" dig.out.ns11.test${n} >/dev/null || ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi
status=$((status + ret))
echo_i "exit status: $status" echo_i "exit status: $status"
[ $status -eq 0 ] || exit 1 [ $status -eq 0 ] || exit 1
@@ -21,7 +21,6 @@ pytestmark = pytest.mark.extra_artifacts(
"nextpart.out.*", "nextpart.out.*",
"ans*/ans.run", "ans*/ans.run",
"ans*/query.log", "ans*/query.log",
"ns1/named.stats*",
"ns4/tld.db", "ns4/tld.db",
"ns5/trusted.conf", "ns5/trusted.conf",
"ns6/K*", "ns6/K*",
@@ -102,23 +102,6 @@ def test_rpz_passthru_logging():
dns.rrset.from_text("allowed.", 300, "IN", "A", "10.53.0.2") dns.rrset.from_text("allowed.", 300, "IN", "A", "10.53.0.2")
] ]
# Should also generate a log entry into rpz_passthru.txt
msg_allowed_any = dns.message.make_query("allowed.", "ANY")
res_allowed_any = isctest.query.udp(
msg_allowed_any,
resolver_ip,
source="10.53.0.1",
expected_rcode=dns.rcode.NOERROR,
)
assert res_allowed_any.answer == [
dns.rrset.from_text("allowed.", 300, "IN", "A", "10.53.0.2"),
dns.rrset.from_text("allowed.", 300, "IN", "NS", "ns1.allowed."),
]
# The comparison above doesn't compare the TTL values, and we want to
# make sure that the "passthru" rpz doesn't cap the TTL with max-policy-ttl.
assert res_allowed_any.answer[0].ttl > 200
assert res_allowed_any.answer[1].ttl > 200
# baddomain.com isn't allowed (CNAME .), should return NXDOMAIN # baddomain.com isn't allowed (CNAME .), should return NXDOMAIN
# Should generate a log entry into rpz.txt # Should generate a log entry into rpz.txt
msg_not_allowed = dns.message.make_query("baddomain.", "A") msg_not_allowed = dns.message.make_query("baddomain.", "A")
+1 -1
View File
@@ -140,7 +140,7 @@ main(int argc, char **argv) {
printf("%s\n", filename); printf("%s\n", filename);
dst_key_free(&key); dst_key_free(&key);
isc_mem_detach(&mctx); isc_mem_destroy(&mctx);
return 0; return 0;
} }
+11 -12
View File
@@ -115,12 +115,10 @@ sleep 2
# stale for somewhere between 3500-3599 seconds. # stale for somewhere between 3500-3599 seconds.
echo_i "check rndc dump stale data.example ($n)" echo_i "check rndc dump stale data.example ($n)"
rndc_dumpdb ns1 || ret=1 rndc_dumpdb ns1 || ret=1
# add in inherited owner names awk '/; stale since [0-9]*/ { x=$0; getline; print x, $0}' ns1/named_dump.db.test$n \
awk '$1 ~ /^[0-9][0-9]*$/ { $0 = last " " $0 } $1 != ";" { last = $1 } { print }' ns1/named_dump.db.test$n >named_dump.db.test$n
awk '/; stale since [0-9]*/ { x=$0; getline; print x, $0}' named_dump.db.test$n \
| grep "; stale since [0-9]* data\.example.*3[56]...*TXT.*A text record with a 2 second ttl" >/dev/null 2>&1 || ret=1 | grep "; stale since [0-9]* data\.example.*3[56]...*TXT.*A text record with a 2 second ttl" >/dev/null 2>&1 || ret=1
# Also make sure the not expired data does not have a stale comment. # Also make sure the not expired data does not have a stale comment.
awk '/; authanswer/ { x=$0; getline; print x, $0}' named_dump.db.test$n \ awk '/; authanswer/ { x=$0; getline; print x, $0}' ns1/named_dump.db.test$n \
| grep "; authanswer longttl\.example.*[56]...*TXT.*A text record with a 600 second ttl" >/dev/null 2>&1 || ret=1 | grep "; authanswer longttl\.example.*[56]...*TXT.*A text record with a 600 second ttl" >/dev/null 2>&1 || ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=$((status + ret)) status=$((status + ret))
@@ -1666,15 +1664,16 @@ status=$((status + ret))
# Check that expired records are dumped. # Check that expired records are dumped.
echo_i "check rndc dump expired data.example ($n)" echo_i "check rndc dump expired data.example ($n)"
ret=0 ret=0
# add in inherited owner names awk '/; expired/ { x=$0; getline; print x, $0}' ns5/named_dump.db.test$n \
awk '$1 ~ /^[0-9][0-9]*$/ { $0 = last " " $0 } $1 != ";" { last = $1 } { print }' ns5/named_dump.db.test$n >named_dump.db.test$n | grep "; expired (awaiting cleanup) data\.example\..*A text record with a 2 second ttl" >/dev/null 2>&1 || ret=1
# extract expired records awk '/; expired/ { x=$0; getline; print x, $0}' ns5/named_dump.db.test$n \
awk '/; expired/ { x=$0; getline; print x, $0}' named_dump.db.test$n >expired.test$n | grep "; expired (awaiting cleanup) nodata\.example\." >/dev/null 2>&1 || ret=1
grep "; expired (awaiting cleanup) data\.example\..*A text record with a 2 second ttl" expired.test$n >/dev/null 2>&1 || ret=1 awk '/; expired/ { x=$0; getline; print x, $0}' ns5/named_dump.db.test$n \
grep "; expired (awaiting cleanup) nodata\.example\." expired.test$n >/dev/null 2>&1 || ret=1 | grep "; expired (awaiting cleanup) nxdomain\.example\." >/dev/null 2>&1 || ret=1
grep "; expired (awaiting cleanup) nxdomain\.example\." expired.test$n >/dev/null 2>&1 || ret=1 awk '/; expired/ { x=$0; getline; print x, $0}' ns5/named_dump.db.test$n \
| grep "; expired (awaiting cleanup) othertype\.example\." >/dev/null 2>&1 || ret=1
# Also make sure the not expired data does not have an expired comment. # Also make sure the not expired data does not have an expired comment.
awk '/; authanswer/ { x=$0; getline; print x, $0}' named_dump.db.test$n \ awk '/; authanswer/ { x=$0; getline; print x, $0}' ns5/named_dump.db.test$n \
| grep "; authanswer longttl\.example.*A text record with a 600 second ttl" >/dev/null 2>&1 || ret=1 | grep "; authanswer longttl\.example.*A text record with a 600 second ttl" >/dev/null 2>&1 || ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=$((status + ret)) status=$((status + ret))
@@ -14,8 +14,6 @@ import pytest
pytestmark = pytest.mark.extra_artifacts( pytestmark = pytest.mark.extra_artifacts(
[ [
"dig.out.*", "dig.out.*",
"expired.test*",
"named_dump.db.test*",
"rndc.out.*", "rndc.out.*",
"ans*/ans.run", "ans*/ans.run",
"ns*/named.stats*", "ns*/named.stats*",
+3 -4
View File
@@ -234,7 +234,7 @@ sub construct_ns_command {
$command = "taskset $taskset $NAMED "; $command = "taskset $taskset $NAMED ";
} elsif ($ENV{'USE_RR'}) { } elsif ($ENV{'USE_RR'}) {
$ENV{'_RR_TRACE_DIR'} = "."; $ENV{'_RR_TRACE_DIR'} = ".";
$command = "$ENV{'TOP_BUILDDIR'}/libtool --mode=execute rr record --chaos $NAMED "; $command = "rr record --chaos $NAMED ";
} else { } else {
$command = "$NAMED "; $command = "$NAMED ";
} }
@@ -264,8 +264,7 @@ sub construct_ns_command {
foreach my $t_option( foreach my $t_option(
"dropedns", "ednsformerr", "ednsnotimp", "ednsrefused", "dropedns", "ednsformerr", "ednsnotimp", "ednsrefused",
"cookiealwaysvalid", "noaa", "noedns", "nosoa", "noaa", "noedns", "nosoa", "maxudp512", "maxudp1460",
"maxudp512", "maxudp1460",
) { ) {
if (-e "$testdir/$server/named.$t_option") { if (-e "$testdir/$server/named.$t_option") {
$command .= "-T $t_option " $command .= "-T $t_option "
@@ -324,7 +323,7 @@ sub construct_ans_command {
} }
if (-e "$testdir/$server/ans.py") { if (-e "$testdir/$server/ans.py") {
$ENV{'PYTHONPATH'} = $testdir . ":" . $builddir; $ENV{'PYTHONPATH'} = $testdir . ":" . $ENV{'srcdir'};
$command = "$PYTHON -u ans.py 10.53.0.$n $queryport"; $command = "$PYTHON -u ans.py 10.53.0.$n $queryport";
} elsif (-e "$testdir/$server/ans.pl") { } elsif (-e "$testdir/$server/ans.pl") {
$command = "$PERL ans.pl"; $command = "$PERL ans.pl";
+3 -4
View File
@@ -414,10 +414,10 @@ for ns in 2 4 5 6; do
check_status NOERROR dig.out.ns${ns}.test$n || ret=1 check_status NOERROR dig.out.ns${ns}.test$n || ret=1
if [ ${synth} = yes ]; then if [ ${synth} = yes ]; then
check_synth_cname b.wild-cname.example. dig.out.ns${ns}.test$n || ret=1 check_synth_cname b.wild-cname.example. dig.out.ns${ns}.test$n || ret=1
nextpart ns1/named.run | grep b.wild-cname.example/NS >/dev/null && ret=1 nextpart ns1/named.run | grep b.wild-cname.example/A >/dev/null && ret=1
else else
check_nosynth_cname b.wild-cname.example. dig.out.ns${ns}.test$n || ret=1 check_nosynth_cname b.wild-cname.example. dig.out.ns${ns}.test$n || ret=1
nextpart ns1/named.run | grep b.wild-cname.example/NS >/dev/null || ret=1 nextpart ns1/named.run | grep b.wild-cname.example/A >/dev/null || ret=1
fi fi
grep "ns1.example.*.IN.A" dig.out.ns${ns}.test$n >/dev/null || ret=1 grep "ns1.example.*.IN.A" dig.out.ns${ns}.test$n >/dev/null || ret=1
digcomp wildcname.out dig.out.ns${ns}.test$n || ret=1 digcomp wildcname.out dig.out.ns${ns}.test$n || ret=1
@@ -470,7 +470,6 @@ for ns in 2 4 5 6; do
check_nosynth_aaaa b.wild-2-nsec-afterdata.example. dig.out.a.ns${ns}.test$n || ret=1 check_nosynth_aaaa b.wild-2-nsec-afterdata.example. dig.out.a.ns${ns}.test$n || ret=1
# #
nextpart ns1/named.run >/dev/null nextpart ns1/named.run >/dev/null
sleep 1
dig_with_opts b.wild-2-nsec-afterdata.example. @10.53.0.${ns} TLSA >dig.out.ns${ns}.test$n || ret=1 dig_with_opts b.wild-2-nsec-afterdata.example. @10.53.0.${ns} TLSA >dig.out.ns${ns}.test$n || ret=1
check_ad_flag $ad dig.out.ns${ns}.test$n || ret=1 check_ad_flag $ad dig.out.ns${ns}.test$n || ret=1
check_status NOERROR dig.out.ns${ns}.test$n || ret=1 check_status NOERROR dig.out.ns${ns}.test$n || ret=1
@@ -532,7 +531,7 @@ for ns in 2 4 5 6; do
check_ad_flag no dig.out.ns${ns}.test$n || ret=1 check_ad_flag no dig.out.ns${ns}.test$n || ret=1
check_status NOERROR dig.out.ns${ns}.test$n || ret=1 check_status NOERROR dig.out.ns${ns}.test$n || ret=1
check_nosynth_cname b.wild-cname.insecure.example dig.out.ns${ns}.test$n || ret=1 check_nosynth_cname b.wild-cname.insecure.example dig.out.ns${ns}.test$n || ret=1
nextpart ns1/named.run | grep b.wild-cname.insecure.example/NS >/dev/null || ret=1 nextpart ns1/named.run | grep b.wild-cname.insecure.example/A >/dev/null || ret=1
grep "ns1.insecure.example.*.IN.A" dig.out.ns${ns}.test$n >/dev/null || ret=1 grep "ns1.insecure.example.*.IN.A" dig.out.ns${ns}.test$n >/dev/null || ret=1
digcomp insecure.wildcname.out dig.out.ns${ns}.test$n || ret=1 digcomp insecure.wildcname.out dig.out.ns${ns}.test$n || ret=1
n=$((n + 1)) n=$((n + 1))
+1 -1
View File
@@ -260,7 +260,7 @@ main(int argc, char *argv[]) {
if (printmemstats) { if (printmemstats) {
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
} }
isc_mem_detach(&mctx); isc_mem_destroy(&mctx);
return 0; return 0;
} }
+1 -1
View File
@@ -425,7 +425,7 @@ cleanup:
if (message != NULL) { if (message != NULL) {
dns_message_detach(&message); dns_message_detach(&message);
} }
isc_mem_detach(&mctx); isc_mem_destroy(&mctx);
exit(rv); exit(rv);
} }
+1 -1
View File
@@ -61,7 +61,7 @@ cleanup(void) {
isc_lex_destroy(&lex); isc_lex_destroy(&lex);
} }
if (mctx != NULL) { if (mctx != NULL) {
isc_mem_detach(&mctx); isc_mem_destroy(&mctx);
} }
} }

Some files were not shown because too many files have changed in this diff Show More