Compare commits
391
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3878c145c9 | ||
|
|
4acbfbc2d1 | ||
|
|
1ef9a32de7 | ||
|
|
6c738fe323 | ||
|
|
49ccbe857a | ||
|
|
1edbbc32b4 | ||
|
|
a102e504c3 | ||
|
|
0dd046d007 | ||
|
|
764eb65cf6 | ||
|
|
6c2af2ae3b | ||
|
|
6af708f3b0 | ||
|
|
14ab1629b7 | ||
|
|
f98a8331aa | ||
|
|
1bc7016d7a | ||
|
|
b048190e23 | ||
|
|
5604d3a44e | ||
|
|
ae37ef45ff | ||
|
|
c2e4358267 | ||
|
|
26f8ee7229 | ||
|
|
1784e4a9ae | ||
|
|
e16560a650 | ||
|
|
2f7e6eb019 | ||
|
|
afb424c9b6 | ||
|
|
cf098cf10d | ||
|
|
a6986f6837 | ||
|
|
2edefbad4a | ||
|
|
1d7a9ebeda | ||
|
|
cf981ab13b | ||
|
|
94a96a7a0e | ||
|
|
796b662b92 | ||
|
|
1e4fb53c61 | ||
|
|
24db1b1a8a | ||
|
|
67e1df1a07 | ||
|
|
79c3871a7b | ||
|
|
3bb47bc6cd | ||
|
|
259600c837 | ||
|
|
1c22ab2ef7 | ||
|
|
04c2c2cbc8 | ||
|
|
08e966df82 | ||
|
|
869168545a | ||
|
|
45132df850 | ||
|
|
7fce7707db | ||
|
|
887502e37d | ||
|
|
4e0b62bf10 | ||
|
|
afc4413862 | ||
|
|
02ef8ff01c | ||
|
|
d0fd9cbe3b | ||
|
|
c4868b5bd9 | ||
|
|
d1ef6a93c1 | ||
|
|
6e0c1f151c | ||
|
|
e99627a006 | ||
|
|
4917ffa61b | ||
|
|
f5c204ac3e | ||
|
|
5d0c347e75 | ||
|
|
c6b0368b21 | ||
|
|
479c366c2b | ||
|
|
cf078fadeb | ||
|
|
b9e3cd5d2a | ||
|
|
e127ba0041 | ||
|
|
eae270cc32 | ||
|
|
5ba811bea2 | ||
|
|
3ea2fbc238 | ||
|
|
7471ef5e1a | ||
|
|
77ec2a6c22 | ||
|
|
f0785fedf1 | ||
|
|
4271d93f00 | ||
|
|
83159d0a54 | ||
|
|
d78ebff861 | ||
|
|
5861c10dfb | ||
|
|
716b936045 | ||
|
|
742d379d88 | ||
|
|
c6529891bb | ||
|
|
a282f1ba3f | ||
|
|
c701b590e4 | ||
|
|
b9c6aa24f8 | ||
|
|
f6dfff01ab | ||
|
|
91ea156203 | ||
|
|
fc3a4d6f89 | ||
|
|
e4652a0444 | ||
|
|
6aba56ae89 | ||
|
|
948f8d7a98 | ||
|
|
2fc32c105d | ||
|
|
c2e19771ac | ||
|
|
1d5fe36136 | ||
|
|
ed83455c81 | ||
|
|
82edec67a5 | ||
|
|
b4bde9bef4 | ||
|
|
f1ab7f199b | ||
|
|
6908d1f9be | ||
|
|
4601d4299a | ||
|
|
15fe68e50d | ||
|
|
44026fc4ad | ||
|
|
3033d127d2 | ||
|
|
2adabe835a | ||
|
|
8b8f4d500d | ||
|
|
a22bc2d7d4 | ||
|
|
05e8a50818 | ||
|
|
67255da4b3 | ||
|
|
e58ce19cf2 | ||
|
|
74c9ff384e | ||
|
|
ce9f6e68c3 | ||
|
|
2d53796e28 | ||
|
|
3b2fe808c4 | ||
|
|
bfb219ac2d | ||
|
|
cf66ba02a4 | ||
|
|
4cd1dd8dd7 | ||
|
|
4448f1adb2 | ||
|
|
53d9ef5bd0 | ||
|
|
b24981ea02 | ||
|
|
5281c708d3 | ||
|
|
d34414c47b | ||
|
|
82069a5700 | ||
|
|
1f6a16e6d0 | ||
|
|
fd3beaba2e | ||
|
|
bf7efe03b0 | ||
|
|
b017d9fe67 | ||
|
|
d6b63210a8 | ||
|
|
fffa150df3 | ||
|
|
766805a374 | ||
|
|
409f394d6e | ||
|
|
0921e91a4b | ||
|
|
b804a70fac | ||
|
|
7347abd01f | ||
|
|
3f61a87be3 | ||
|
|
9d441c93d0 | ||
|
|
3482d7e694 | ||
|
|
583a838c25 | ||
|
|
d5d63d6253 | ||
|
|
c6e3695478 | ||
|
|
5559539eb0 | ||
|
|
53991ecc14 | ||
|
|
ebf1606f38 | ||
|
|
04b1484ed8 | ||
|
|
8b900d1808 | ||
|
|
66f293a952 | ||
|
|
a71b617566 | ||
|
|
b694acbe45 | ||
|
|
559fac329a | ||
|
|
dfc367f52c | ||
|
|
5e49a9e4ae | ||
|
|
bd4729e13b | ||
|
|
38e751d9ac | ||
|
|
7c499d1689 | ||
|
|
42a7b6aedf | ||
|
|
5250ad8720 | ||
|
|
7b3dc7ab32 | ||
|
|
a03c4b4cf9 | ||
|
|
3d3247109c | ||
|
|
259678df11 | ||
|
|
ee913c1370 | ||
|
|
e5f02d3a25 | ||
|
|
da23a0c4e1 | ||
|
|
8a742d084f | ||
|
|
b23b0d991a | ||
|
|
af174fe816 | ||
|
|
9b15715558 | ||
|
|
dab7d28b09 | ||
|
|
d4a7bff0b6 | ||
|
|
732fc338a9 | ||
|
|
1fa5219fdf | ||
|
|
6dcc398726 | ||
|
|
c602d76c1f | ||
|
|
a1ca49683a | ||
|
|
1069eb1969 | ||
|
|
b19fb37080 | ||
|
|
a24f71bae4 | ||
|
|
37699ad84b | ||
|
|
b6d645410c | ||
|
|
d2f6e236a2 | ||
|
|
ca859563aa | ||
|
|
166c324142 | ||
|
|
19843f6c9d | ||
|
|
f8802cbfa0 | ||
|
|
0680eb6f64 | ||
|
|
ae73ac81a3 | ||
|
|
355fc48472 | ||
|
|
517c5b6b28 | ||
|
|
36a3ceb19f | ||
|
|
60f6b88c63 | ||
|
|
58179e6a19 | ||
|
|
cfee6aa565 | ||
|
|
e07f5a4a5b | ||
|
|
1bbb57f81b | ||
|
|
d9eb272b69 | ||
|
|
88c31fdd52 | ||
|
|
6469ebd08e | ||
|
|
ea9d7080cd | ||
|
|
282b0ed514 | ||
|
|
1f095b902c | ||
|
|
32518f7de3 | ||
|
|
6276e0b23b | ||
|
|
98325fabeb | ||
|
|
6014060774 | ||
|
|
5a688130e5 | ||
|
|
35604a2cad | ||
|
|
ebeafd93ad | ||
|
|
0ba2b5585d | ||
|
|
e39e7afc16 | ||
|
|
f43bf94ece | ||
|
|
d4f791793e | ||
|
|
431513d8b3 | ||
|
|
36a26bfa1a | ||
|
|
814b87da64 | ||
|
|
fd51d80297 | ||
|
|
d82262d293 | ||
|
|
a8e0a695c4 | ||
|
|
7c5678bb03 | ||
|
|
c7b0fe5bec | ||
|
|
9021f9d802 | ||
|
|
7b01cbfb04 | ||
|
|
f9f41190b3 | ||
|
|
2f8e0edf3b | ||
|
|
53734b6845 | ||
|
|
5d07df807a | ||
|
|
3a64b288c1 | ||
|
|
c5669a274d | ||
|
|
e5636598a5 | ||
|
|
e59bc5b366 | ||
|
|
e3dd7e3d96 | ||
|
|
2e5a3bde7e | ||
|
|
94c72e7943 | ||
|
|
5dbc87730e | ||
|
|
92a3487106 | ||
|
|
9756292a5f | ||
|
|
dc3c3efdbf | ||
|
|
39c2fc4670 | ||
|
|
27f3b8950a | ||
|
|
7cb8a028fe | ||
|
|
78274ec2b1 | ||
|
|
2bee113a46 | ||
|
|
b495e9918e | ||
|
|
b9db917752 | ||
|
|
380a30ba8d | ||
|
|
5a8fce4851 | ||
|
|
244923b9dc | ||
|
|
8b50d63fe1 | ||
|
|
46a58acdf5 | ||
|
|
98522ab702 | ||
|
|
48eab76427 | ||
|
|
8302469507 | ||
|
|
4dfc12cb44 | ||
|
|
df7e9f4ac3 | ||
|
|
23fb615963 | ||
|
|
a72ff9fd57 | ||
|
|
100b759863 | ||
|
|
b2964cc922 | ||
|
|
df8c419058 | ||
|
|
feecbd8e77 | ||
|
|
d3455be08c | ||
|
|
314741fcd0 | ||
|
|
a19f6c6654 | ||
|
|
70e3d91396 | ||
|
|
10accd6260 | ||
|
|
af0a5dfeeb | ||
|
|
0584d3f65f | ||
|
|
da207678f3 | ||
|
|
8daf3782d1 | ||
|
|
417a0e331f | ||
|
|
ae42fa69fa | ||
|
|
8efb4e2f26 | ||
|
|
5e3aef364f | ||
|
|
0a91321d78 | ||
|
|
eec0aaa391 | ||
|
|
7ae7851173 | ||
|
|
e57ebb8f1b | ||
|
|
9c04640def | ||
|
|
89afc11389 | ||
|
|
076e47b427 | ||
|
|
950a0cffb3 | ||
|
|
4096f27130 | ||
|
|
66d4f9184a | ||
|
|
a6d6c3cb45 | ||
|
|
5367ccb561 | ||
|
|
87c453850c | ||
|
|
e61ba5865f | ||
|
|
48471fd50c | ||
|
|
7f4471594d | ||
|
|
3fe440f0cf | ||
|
|
9f945c8b67 | ||
|
|
0673568c17 | ||
|
|
05faff6d53 | ||
|
|
3f490fe3fb | ||
|
|
612d76b83d | ||
|
|
64ffbe82c0 | ||
|
|
114555ea65 | ||
|
|
9ccd1be482 | ||
|
|
65c557c536 | ||
|
|
2164ea8abd | ||
|
|
1732346fcc | ||
|
|
c9529c0acb | ||
|
|
93e6e72eb6 | ||
|
|
87b0c1c1a0 | ||
|
|
bdef1e2176 | ||
|
|
0f626b8cc3 | ||
|
|
4a0a598cc2 | ||
|
|
70187b67ae | ||
|
|
e9003901a7 | ||
|
|
fa4c45d9e8 | ||
|
|
84f36eaa83 | ||
|
|
0937207606 | ||
|
|
b6ccbcbcf1 | ||
|
|
bddaff3210 | ||
|
|
937b5f8349 | ||
|
|
4ae4e255cf | ||
|
|
609a41517b | ||
|
|
3425e4b1d0 | ||
|
|
9846f395ad | ||
|
|
4d054cca7a | ||
|
|
a1982cf1bb | ||
|
|
e51d4d3b88 | ||
|
|
8356179953 | ||
|
|
3a94afa03a | ||
|
|
232dac8cd5 | ||
|
|
71e1c91695 | ||
|
|
3e367a23f9 | ||
|
|
7b94c34965 | ||
|
|
ad4bab306c | ||
|
|
9636dc1a1e | ||
|
|
010d2eb436 | ||
|
|
19a2aab136 | ||
|
|
d75bdabe51 | ||
|
|
3d7a9fba3b | ||
|
|
e71549eaba | ||
|
|
32c5f24713 | ||
|
|
b1b004ed01 | ||
|
|
17804f5154 | ||
|
|
6230bc883a | ||
|
|
dd2c509521 | ||
|
|
7bdf5152d6 | ||
|
|
58d38352ee | ||
|
|
c5555a5ca2 | ||
|
|
4ab35f6839 | ||
|
|
fa073a0a63 | ||
|
|
bafa5d3c2e | ||
|
|
05d69bd7a4 | ||
|
|
064b2c6889 | ||
|
|
44d5dbeab6 | ||
|
|
d6f9785ac6 | ||
|
|
dc90e977fc | ||
|
|
086c325ad3 | ||
|
|
6eb77ed2b0 | ||
|
|
740292d3ec | ||
|
|
e04fb30ee6 | ||
|
|
6691a1530d | ||
|
|
6ce55429f1 | ||
|
|
f7316b44b9 | ||
|
|
1fea227ab8 | ||
|
|
7b26becec0 | ||
|
|
8d9bc93e81 | ||
|
|
06f9163d51 | ||
|
|
e2c1941efd | ||
|
|
29bde687b5 | ||
|
|
759d59801b | ||
|
|
f379e1bef9 | ||
|
|
cf76851c75 | ||
|
|
7f55041426 | ||
|
|
7fb6be62e0 | ||
|
|
57b64dc397 | ||
|
|
f4377a3cd6 | ||
|
|
32f8f6237c | ||
|
|
3fa50a98a2 | ||
|
|
858ba71eaf | ||
|
|
726c9cd73b | ||
|
|
1b2eadb197 | ||
|
|
b121f02eac | ||
|
|
0d5b8bfd40 | ||
|
|
46388d07a2 | ||
|
|
b0eb3ca9d2 | ||
|
|
b711b5b10d | ||
|
|
c38eb87158 | ||
|
|
1a670a4963 | ||
|
|
7048b3ab0d | ||
|
|
8240781cce | ||
|
|
39485c1f70 | ||
|
|
d3765a5f35 | ||
|
|
0bdd03db66 | ||
|
|
2bce06e170 | ||
|
|
3394aa9c25 | ||
|
|
ef6dc36e53 | ||
|
|
673e966d37 | ||
|
|
6d44e7320e | ||
|
|
8306005ef1 | ||
|
|
766c1a13c2 | ||
|
|
10b662811e | ||
|
|
3821a037bb | ||
|
|
7a5dd9503b | ||
|
|
5ebcfca335 | ||
|
|
50ae3a3d4c | ||
|
|
912cd22a8d | ||
|
|
2707c794c7 | ||
|
|
55734f9257 |
@@ -96,6 +96,7 @@ doc/man/pkcs11-tokens.8in
|
|||||||
/GPATH
|
/GPATH
|
||||||
/GRTAGS
|
/GRTAGS
|
||||||
/GTAGS
|
/GTAGS
|
||||||
|
TAGS
|
||||||
# Emacs specific files
|
# Emacs specific files
|
||||||
\.dir-locals-2.el
|
\.dir-locals-2.el
|
||||||
/emacs.desktop
|
/emacs.desktop
|
||||||
|
|||||||
+85
-307
@@ -51,12 +51,11 @@ variables:
|
|||||||
# cross-testrun files as there is no need to use that feature in CI.
|
# cross-testrun files as there is no need to use that feature in CI.
|
||||||
PYTEST_ADDOPTS: "-p no:cacheprovider"
|
PYTEST_ADDOPTS: "-p no:cacheprovider"
|
||||||
|
|
||||||
# Default platforms to run "stress" tests on
|
|
||||||
BIND_STRESS_TEST_OS: linux
|
|
||||||
BIND_STRESS_TEST_ARCH: amd64
|
|
||||||
|
|
||||||
HYPOTHESIS_PROFILE: "ci"
|
HYPOTHESIS_PROFILE: "ci"
|
||||||
|
|
||||||
|
# Some jobs may clean up the build artifacts unless this is set to 0.
|
||||||
|
CLEAN_BUILD_ARTIFACTS_ON_SUCCESS: 1
|
||||||
|
|
||||||
default:
|
default:
|
||||||
# Allow all running CI jobs to be automatically canceled when a new
|
# Allow all running CI jobs to be automatically canceled when a new
|
||||||
# version of a branch is pushed.
|
# version of a branch is pushed.
|
||||||
@@ -377,6 +376,7 @@ stages:
|
|||||||
- >
|
- >
|
||||||
"$PYTEST" --junit-xml="$CI_PROJECT_DIR"/junit.xml -n "$TEST_PARALLEL_JOBS" | tee pytest.out.txt
|
"$PYTEST" --junit-xml="$CI_PROJECT_DIR"/junit.xml -n "$TEST_PARALLEL_JOBS" | tee pytest.out.txt
|
||||||
- '( ! grep -F "grep: warning:" pytest.out.txt )'
|
- '( ! grep -F "grep: warning:" pytest.out.txt )'
|
||||||
|
- test "$CLEAN_BUILD_ARTIFACTS_ON_SUCCESS" -eq 0 || ( cd ../../.. && make clean >/dev/null 2>&1 )
|
||||||
after_script:
|
after_script:
|
||||||
- test -n "${OUT_OF_TREE_WORKSPACE}" && cd "${OUT_OF_TREE_WORKSPACE}"
|
- test -n "${OUT_OF_TREE_WORKSPACE}" && cd "${OUT_OF_TREE_WORKSPACE}"
|
||||||
- *display_pytest_failures
|
- *display_pytest_failures
|
||||||
@@ -431,6 +431,7 @@ stages:
|
|||||||
- test -n "${OUT_OF_TREE_WORKSPACE}" && cd "${OUT_OF_TREE_WORKSPACE}"
|
- test -n "${OUT_OF_TREE_WORKSPACE}" && cd "${OUT_OF_TREE_WORKSPACE}"
|
||||||
script:
|
script:
|
||||||
- make -j${TEST_PARALLEL_JOBS:-1} -k unit V=1
|
- make -j${TEST_PARALLEL_JOBS:-1} -k unit V=1
|
||||||
|
- test "$CLEAN_BUILD_ARTIFACTS_ON_SUCCESS" -eq 0 || make clean >/dev/null 2>&1
|
||||||
after_script:
|
after_script:
|
||||||
- test -d bind-* && cd bind-*
|
- test -d bind-* && cd bind-*
|
||||||
- REALSOURCEDIR="$PWD"
|
- REALSOURCEDIR="$PWD"
|
||||||
@@ -467,10 +468,12 @@ stages:
|
|||||||
junit: junit.xml
|
junit: junit.xml
|
||||||
|
|
||||||
.docs: &docs_job
|
.docs: &docs_job
|
||||||
|
variables:
|
||||||
|
DOC_MAKE_TARGET: doc
|
||||||
stage: docs
|
stage: docs
|
||||||
script:
|
script:
|
||||||
- *configure
|
- *configure
|
||||||
- make -j${BUILD_PARALLEL_JOBS:-1} -k doc V=1
|
- make -j${BUILD_PARALLEL_JOBS:-1} -k ${DOC_MAKE_TARGET} V=1
|
||||||
- find doc/man/ -maxdepth 1 -name "*.[0-9]" -exec mandoc -T lint "{}" \; | ( ! grep -v -e "skipping paragraph macro. sp after" -e "unknown font, skipping request. ft C" -e "input text line longer than 80 bytes" )
|
- find doc/man/ -maxdepth 1 -name "*.[0-9]" -exec mandoc -T lint "{}" \; | ( ! grep -v -e "skipping paragraph macro. sp after" -e "unknown font, skipping request. ft C" -e "input text line longer than 80 bytes" )
|
||||||
|
|
||||||
.respdiff: &respdiff_job
|
.respdiff: &respdiff_job
|
||||||
@@ -564,21 +567,29 @@ clang-format:
|
|||||||
when: on_failure
|
when: on_failure
|
||||||
|
|
||||||
coccinelle:
|
coccinelle:
|
||||||
<<: *precheck_job
|
######################################################################
|
||||||
|
# Revert to using the "precheck_job" anchor after the "base" image is
|
||||||
|
# upgraded to Debian trixie, which has Coccinelle 1.2.
|
||||||
|
<<: *default_triggering_rules
|
||||||
|
<<: *debian_sid_amd64_image
|
||||||
|
stage: precheck
|
||||||
|
######################################################################
|
||||||
needs: []
|
needs: []
|
||||||
script:
|
script:
|
||||||
- util/check-cocci
|
- util/check-cocci
|
||||||
- if test "$(git status --porcelain | grep -Ev '\?\?' | wc -l)" -gt "0"; then git status --short; exit 1; fi
|
- if test "$(git status --porcelain | grep -Ev '\?\?' | wc -l)" -gt "0"; then git status --short; exit 1; fi
|
||||||
|
|
||||||
pylint:
|
pylint:
|
||||||
<<: *precheck_job
|
<<: *default_triggering_rules
|
||||||
|
<<: *debian_sid_amd64_image
|
||||||
|
stage: precheck
|
||||||
needs: []
|
needs: []
|
||||||
variables:
|
variables:
|
||||||
PYTHONPATH: "${CI_PROJECT_DIR}/bin/tests/system"
|
PYTHONPATH: "${CI_PROJECT_DIR}/bin/tests/system"
|
||||||
script:
|
script:
|
||||||
- pylint --rcfile $CI_PROJECT_DIR/.pylintrc $(git ls-files '*.py' | grep -vE '(ans\.py|dangerfile\.py|^bin/tests/system/|^contrib/)')
|
- pylint --rcfile $CI_PROJECT_DIR/.pylintrc $(git ls-files '*.py' | grep -vE '(ans\.py|dangerfile\.py|^bin/tests/system/|^contrib/)')
|
||||||
# Ignore Pylint wrong-import-position error in system test to enable use of pytest.importorskip
|
# Ignore Pylint wrong-import-position error in system test to enable use of pytest.importorskip
|
||||||
- pylint --rcfile $CI_PROJECT_DIR/.pylintrc --disable=wrong-import-position $(git ls-files 'bin/tests/system/*.py' | grep -vE 'ans\.py')
|
- pylint --rcfile $CI_PROJECT_DIR/.pylintrc --disable=wrong-import-position $(git ls-files 'bin/tests/system/*.py' | grep -vE '(ans\.py|vulture_ignore_list\.py)')
|
||||||
|
|
||||||
reuse:
|
reuse:
|
||||||
<<: *precheck_job
|
<<: *precheck_job
|
||||||
@@ -604,11 +615,6 @@ shfmt:
|
|||||||
|
|
||||||
danger:
|
danger:
|
||||||
<<: *precheck_job
|
<<: *precheck_job
|
||||||
# Keep the GIT_DEPTH environment variable set to a "high number" before
|
|
||||||
# https://github.com/libgit2/libgit2/pull/6662 is addressed and integrated
|
|
||||||
# into pygit2.
|
|
||||||
variables:
|
|
||||||
GIT_DEPTH: 1000
|
|
||||||
needs: []
|
needs: []
|
||||||
script:
|
script:
|
||||||
- pip install git+https://gitlab.isc.org/isc-projects/hazard.git
|
- pip install git+https://gitlab.isc.org/isc-projects/hazard.git
|
||||||
@@ -624,7 +630,9 @@ checkbashisms:
|
|||||||
- checkbashisms $(find . -path './.git' -prune -o -type f -exec sh -c 'head -n 1 "{}" | grep -qsF "#!/bin/sh"' \; -print)
|
- checkbashisms $(find . -path './.git' -prune -o -type f -exec sh -c 'head -n 1 "{}" | grep -qsF "#!/bin/sh"' \; -print)
|
||||||
|
|
||||||
mypy:
|
mypy:
|
||||||
<<: *precheck_job
|
<<: *default_triggering_rules
|
||||||
|
<<: *debian_sid_amd64_image
|
||||||
|
stage: precheck
|
||||||
script:
|
script:
|
||||||
- mypy "bin/tests/system/isctest/"
|
- mypy "bin/tests/system/isctest/"
|
||||||
|
|
||||||
@@ -661,18 +669,33 @@ changelog:
|
|||||||
GIT_AUTHOR_EMAIL: $GITLAB_USER_EMAIL
|
GIT_AUTHOR_EMAIL: $GITLAB_USER_EMAIL
|
||||||
GIT_COMMITTER_NAME: $GITLAB_USER_NAME
|
GIT_COMMITTER_NAME: $GITLAB_USER_NAME
|
||||||
GIT_COMMITTER_EMAIL: $GITLAB_USER_EMAIL
|
GIT_COMMITTER_EMAIL: $GITLAB_USER_EMAIL
|
||||||
|
DOC_MAKE_TARGET: html
|
||||||
before_script:
|
before_script:
|
||||||
- echo -e "$CI_MERGE_REQUEST_TITLE\n" > commitmsg
|
- echo -e "$CI_MERGE_REQUEST_TITLE\n" > commitmsg
|
||||||
- sed -i 's/^Draft:\s*//' commitmsg
|
- sed -i 's/^Draft:\s*//' commitmsg
|
||||||
- echo -e "$CI_MERGE_REQUEST_DESCRIPTION" >> commitmsg
|
- echo -e "$CI_MERGE_REQUEST_DESCRIPTION" >> commitmsg
|
||||||
- git commit --allow-empty -F commitmsg
|
- git commit --allow-empty -F commitmsg
|
||||||
- ./contrib/gitchangelog/gitchangelog.py HEAD^..HEAD
|
- ./contrib/gitchangelog/gitchangelog.py HEAD^..HEAD >> $(ls doc/changelog/changelog-9.* | sort --version-sort | tail -n 1)
|
||||||
|
after_script:
|
||||||
|
- git diff
|
||||||
needs:
|
needs:
|
||||||
- job: autoreconf
|
- job: autoreconf
|
||||||
artifacts: true
|
artifacts: true
|
||||||
artifacts:
|
artifacts:
|
||||||
untracked: true
|
untracked: true
|
||||||
|
|
||||||
|
linkcheck:
|
||||||
|
<<: *base_image
|
||||||
|
stage: docs
|
||||||
|
script:
|
||||||
|
- pushd doc/arm/ > /dev/null && sphinx-build -b linkcheck . linkcheck_output/
|
||||||
|
artifacts:
|
||||||
|
paths:
|
||||||
|
- doc/arm/linkcheck_output/
|
||||||
|
rules:
|
||||||
|
- if: '$CI_PIPELINE_SOURCE == "schedule"'
|
||||||
|
needs: []
|
||||||
|
|
||||||
docs:
|
docs:
|
||||||
<<: *default_triggering_rules
|
<<: *default_triggering_rules
|
||||||
<<: *base_image
|
<<: *base_image
|
||||||
@@ -744,18 +767,6 @@ cross-version-config-tests:
|
|||||||
untracked: true
|
untracked: true
|
||||||
expire_in: "1 day"
|
expire_in: "1 day"
|
||||||
when: always
|
when: always
|
||||||
# Changes in the January milestone necessitate allowing this job to fail. The
|
|
||||||
# "soft failure" should be reverted when January releases are published.
|
|
||||||
# - #4261 introduced extra artifacts check but missed a file visible only in
|
|
||||||
# this job. This is fixed in !9815 but present in December releases.
|
|
||||||
# System test affected: mkeys.
|
|
||||||
# - #4666 removed the "fixed" value for the "rrset-order" option, but the
|
|
||||||
# value is still present in the December release system test.
|
|
||||||
# System test affected: rrsetorder.
|
|
||||||
# - #4482 removed the "dnssec-must-be-secure" feature that is still present
|
|
||||||
# in the December release.
|
|
||||||
# System tests affected: autosign, dnssec, and dsdigest.
|
|
||||||
allow_failure: true
|
|
||||||
|
|
||||||
# Jobs for regular GCC builds on Alpine Linux 3.21 (amd64)
|
# Jobs for regular GCC builds on Alpine Linux 3.21 (amd64)
|
||||||
|
|
||||||
@@ -902,7 +913,8 @@ gcc:bookworm:amd64:
|
|||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "${CFLAGS_COMMON} --coverage -O0"
|
CFLAGS: "${CFLAGS_COMMON} --coverage -O0"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2 ${WITH_READLINE_LIBEDIT}"
|
# Tracing needs to be disabled otherwise gcovr fails
|
||||||
|
EXTRA_CONFIGURE: "--with-libidn2 ${WITH_READLINE_LIBEDIT} --disable-tracing"
|
||||||
RUN_MAKE_INSTALL: 1
|
RUN_MAKE_INSTALL: 1
|
||||||
<<: *debian_bookworm_amd64_image
|
<<: *debian_bookworm_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -912,8 +924,9 @@ system:gcc:bookworm:amd64:
|
|||||||
<<: *system_test_gcov_job
|
<<: *system_test_gcov_job
|
||||||
variables:
|
variables:
|
||||||
CI_ENABLE_ALL_TESTS: 1
|
CI_ENABLE_ALL_TESTS: 1
|
||||||
|
CLEAN_BUILD_ARTIFACTS_ON_SUCCESS: 0
|
||||||
TZ: Australia/Sydney
|
TZ: Australia/Sydney
|
||||||
needs:
|
needs: # using artifacts from unit test job is required for gcov
|
||||||
- job: unit:gcc:bookworm:amd64
|
- job: unit:gcc:bookworm:amd64
|
||||||
artifacts: true
|
artifacts: true
|
||||||
|
|
||||||
@@ -922,6 +935,7 @@ unit:gcc:bookworm:amd64:
|
|||||||
<<: *unit_test_gcov_job
|
<<: *unit_test_gcov_job
|
||||||
variables:
|
variables:
|
||||||
CI_ENABLE_ALL_TESTS: 1
|
CI_ENABLE_ALL_TESTS: 1
|
||||||
|
CLEAN_BUILD_ARTIFACTS_ON_SUCCESS: 0
|
||||||
needs:
|
needs:
|
||||||
- job: gcc:bookworm:amd64
|
- job: gcc:bookworm:amd64
|
||||||
artifacts: true
|
artifacts: true
|
||||||
@@ -940,7 +954,7 @@ system:gcc:bookworm:rbt:amd64:
|
|||||||
<<: *debian_bookworm_amd64_image
|
<<: *debian_bookworm_amd64_image
|
||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
needs:
|
needs:
|
||||||
- job: unit:gcc:bookworm:rbt:amd64
|
- job: gcc:bookworm:rbt:amd64
|
||||||
artifacts: true
|
artifacts: true
|
||||||
|
|
||||||
unit:gcc:bookworm:rbt:amd64:
|
unit:gcc:bookworm:rbt:amd64:
|
||||||
@@ -1254,6 +1268,8 @@ clang:asan:
|
|||||||
<<: *build_job
|
<<: *build_job
|
||||||
|
|
||||||
system:clang:asan:
|
system:clang:asan:
|
||||||
|
variables:
|
||||||
|
LSAN_OPTIONS: "suppressions=$CI_PROJECT_DIR/suppr-lsan.txt"
|
||||||
<<: *base_image
|
<<: *base_image
|
||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
needs:
|
needs:
|
||||||
@@ -1589,9 +1605,10 @@ respdiff:
|
|||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og -DISC_TRACK_PTHREADS_OBJECTS"
|
CFLAGS: "${CFLAGS_COMMON} -Og -DISC_TRACK_PTHREADS_OBJECTS"
|
||||||
MAX_DISAGREEMENTS_PERCENTAGE: "0.5"
|
MAX_DISAGREEMENTS_PERCENTAGE: "0.15"
|
||||||
script:
|
script:
|
||||||
- bash respdiff.sh -m /usr/lib/x86_64-linux-gnu/libjemalloc.so.2 -s named -q "${PWD}/100k_mixed.txt" -c 3 -w "${PWD}/rspworkdir" "${CI_PROJECT_DIR}" "/usr/local/respdiff-reference-bind/sbin/named"
|
- bash respdiff.sh -m /usr/lib/x86_64-linux-gnu/libjemalloc.so.2 -s named -q "${PWD}/100k_mixed.txt" -c 3 -w "${PWD}/rspworkdir" "${CI_PROJECT_DIR}" "/usr/local/respdiff-reference-bind/sbin/named"
|
||||||
|
- cd ../.. && make clean >/dev/null 2>&1
|
||||||
|
|
||||||
respdiff:asan:
|
respdiff:asan:
|
||||||
<<: *respdiff_job
|
<<: *respdiff_job
|
||||||
@@ -1602,9 +1619,10 @@ respdiff:asan:
|
|||||||
CFLAGS: "${CFLAGS_COMMON} -Og -fsanitize=address,undefined"
|
CFLAGS: "${CFLAGS_COMMON} -Og -fsanitize=address,undefined"
|
||||||
LDFLAGS: "-fsanitize=address,undefined"
|
LDFLAGS: "-fsanitize=address,undefined"
|
||||||
EXTRA_CONFIGURE: "--without-jemalloc"
|
EXTRA_CONFIGURE: "--without-jemalloc"
|
||||||
MAX_DISAGREEMENTS_PERCENTAGE: "0.5"
|
MAX_DISAGREEMENTS_PERCENTAGE: "0.15"
|
||||||
script:
|
script:
|
||||||
- bash respdiff.sh -s named -q "${PWD}/100k_mixed.txt" -c 3 -w "${PWD}/rspworkdir" "${CI_PROJECT_DIR}" "/usr/local/respdiff-reference-bind/sbin/named"
|
- bash respdiff.sh -s named -q "${PWD}/100k_mixed.txt" -c 3 -w "${PWD}/rspworkdir" "${CI_PROJECT_DIR}" "/usr/local/respdiff-reference-bind/sbin/named"
|
||||||
|
- cd ../.. && make clean >/dev/null 2>&1
|
||||||
|
|
||||||
respdiff:tsan:
|
respdiff:tsan:
|
||||||
<<: *respdiff_job
|
<<: *respdiff_job
|
||||||
@@ -1615,10 +1633,11 @@ respdiff:tsan:
|
|||||||
CFLAGS: "${CFLAGS_COMMON} -Og -fsanitize=thread"
|
CFLAGS: "${CFLAGS_COMMON} -Og -fsanitize=thread"
|
||||||
LDFLAGS: "-fsanitize=thread"
|
LDFLAGS: "-fsanitize=thread"
|
||||||
EXTRA_CONFIGURE: "--enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig"
|
EXTRA_CONFIGURE: "--enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig"
|
||||||
MAX_DISAGREEMENTS_PERCENTAGE: "0.5"
|
MAX_DISAGREEMENTS_PERCENTAGE: "0.15"
|
||||||
TSAN_OPTIONS: "${TSAN_OPTIONS_DEBIAN}"
|
TSAN_OPTIONS: "${TSAN_OPTIONS_DEBIAN}"
|
||||||
script:
|
script:
|
||||||
- bash respdiff.sh -s named -q "${PWD}/100k_mixed.txt" -c 3 -w "${PWD}/rspworkdir" "${CI_PROJECT_DIR}" "/usr/local/respdiff-reference-bind/sbin/named"
|
- bash respdiff.sh -s named -q "${PWD}/100k_mixed.txt" -c 3 -w "${PWD}/rspworkdir" "${CI_PROJECT_DIR}" "/usr/local/respdiff-reference-bind/sbin/named"
|
||||||
|
- cd ../.. && make clean >/dev/null 2>&1
|
||||||
after_script:
|
after_script:
|
||||||
- *find_python
|
- *find_python
|
||||||
- *parse_tsan
|
- *parse_tsan
|
||||||
@@ -1630,9 +1649,10 @@ respdiff-third-party:
|
|||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
CFLAGS: "${CFLAGS_COMMON} -Og"
|
||||||
MAX_DISAGREEMENTS_PERCENTAGE: "0.5"
|
MAX_DISAGREEMENTS_PERCENTAGE: "0.2"
|
||||||
script:
|
script:
|
||||||
- bash respdiff.sh -s third_party -q "${PWD}/100k_mixed.txt" -c 1 -w "${PWD}/rspworkdir" "${CI_PROJECT_DIR}"
|
- bash respdiff.sh -s third_party -q "${PWD}/100k_mixed.txt" -c 1 -w "${PWD}/rspworkdir" "${CI_PROJECT_DIR}"
|
||||||
|
- cd ../.. && make clean >/dev/null 2>&1
|
||||||
|
|
||||||
# Performance tests
|
# Performance tests
|
||||||
|
|
||||||
@@ -1661,281 +1681,39 @@ shotgun:dot:
|
|||||||
when: delayed
|
when: delayed
|
||||||
start_in: 5 minutes
|
start_in: 5 minutes
|
||||||
|
|
||||||
|
shotgun:doh-get:
|
||||||
|
<<: *shotgun_job
|
||||||
|
variables:
|
||||||
|
SHOTGUN_SCENARIO: doh-get
|
||||||
|
SHOTGUN_TRAFFIC_MULTIPLIER: 3
|
||||||
|
when: delayed
|
||||||
|
start_in: 5 minutes
|
||||||
|
|
||||||
.stress-test: &stress_test
|
.stress-test: &stress_test
|
||||||
stage: performance
|
stage: performance
|
||||||
|
|
||||||
|
generate-stress-test-configs:
|
||||||
|
<<: *base_image
|
||||||
|
<<: *default_triggering_rules
|
||||||
|
stage: precheck
|
||||||
script:
|
script:
|
||||||
- *configure
|
- util/generate-stress-test-configs.py > stress-test-configs.yml
|
||||||
- *setup_interfaces
|
artifacts:
|
||||||
- make -j${BUILD_PARALLEL_JOBS:-1} -k all V=1
|
paths:
|
||||||
- make DESTDIR="${INSTALL_PATH}" install
|
- stress-test-configs.yml
|
||||||
- git clone --depth 1 https://gitlab.isc.org/isc-projects/bind9-qa.git
|
needs: []
|
||||||
- cd bind9-qa/stress
|
|
||||||
- LD_LIBRARY_PATH="${INSTALL_PATH}/usr/local/lib" BIND_INSTALL_PATH="${INSTALL_PATH}/usr/local" WORKSPACE="${CI_PROJECT_DIR}" bash stress.sh
|
stress-test-child-pipeline:
|
||||||
|
<<: *default_triggering_rules
|
||||||
|
stage: performance
|
||||||
|
trigger:
|
||||||
|
include:
|
||||||
|
- artifact: stress-test-configs.yml
|
||||||
|
job: generate-stress-test-configs
|
||||||
needs:
|
needs:
|
||||||
- job: autoreconf
|
- job: generate-stress-test-configs
|
||||||
artifacts: true
|
artifacts: true
|
||||||
|
|
||||||
.stress-test-long: &stress_test_long_job
|
|
||||||
<<: *stress_test
|
|
||||||
artifacts:
|
|
||||||
untracked: true
|
|
||||||
exclude:
|
|
||||||
- "output/ns4/*.dtq*"
|
|
||||||
- "output/ns4/large-delta-rpz*.local"
|
|
||||||
- "output/rpz_*"
|
|
||||||
expire_in: "1 week"
|
|
||||||
when: always
|
|
||||||
timeout: 2h
|
|
||||||
|
|
||||||
.stress-test-short: &stress_test_short_job
|
|
||||||
<<: *stress_test
|
|
||||||
only:
|
|
||||||
- merge_requests
|
|
||||||
artifacts:
|
|
||||||
untracked: true
|
|
||||||
exclude:
|
|
||||||
- "output/ns4/*.dtq*"
|
|
||||||
- "output/ns4/large-delta-rpz*.local"
|
|
||||||
- "output/rpz_*"
|
|
||||||
when: always
|
|
||||||
|
|
||||||
stress:short:authoritative:fedora:41:amd64:
|
|
||||||
<<: *fedora_41_amd64_image
|
|
||||||
<<: *linux_amd64
|
|
||||||
<<: *stress_test_short_job
|
|
||||||
variables:
|
|
||||||
CC: gcc
|
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
|
||||||
FLAME: /usr/bin/flame
|
|
||||||
MODE: authoritative
|
|
||||||
RATE: 10000
|
|
||||||
RUN_TIME: 15
|
|
||||||
|
|
||||||
stress:short:recursive:fedora:41:amd64:
|
|
||||||
<<: *fedora_41_amd64_image
|
|
||||||
<<: *linux_amd64
|
|
||||||
<<: *stress_test_short_job
|
|
||||||
variables:
|
|
||||||
CC: gcc
|
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
|
||||||
FLAME: /usr/bin/flame
|
|
||||||
MODE: recursive
|
|
||||||
RATE: 10000
|
|
||||||
RUN_TIME: 15
|
|
||||||
|
|
||||||
stress:short:rpz:fedora:41:amd64:
|
|
||||||
<<: *fedora_41_amd64_image
|
|
||||||
<<: *linux_amd64
|
|
||||||
<<: *stress_test_short_job
|
|
||||||
variables:
|
|
||||||
CC: gcc
|
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
|
||||||
FLAME: /usr/bin/flame
|
|
||||||
MODE: rpz
|
|
||||||
RATE: 1500
|
|
||||||
RUN_TIME: 15
|
|
||||||
|
|
||||||
stress:short:authoritative:fedora:41:arm64:
|
|
||||||
<<: *fedora_41_arm64_image
|
|
||||||
<<: *linux_arm64
|
|
||||||
<<: *stress_test_short_job
|
|
||||||
variables:
|
|
||||||
CC: gcc
|
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
|
||||||
FLAME: /usr/bin/flame
|
|
||||||
MODE: authoritative
|
|
||||||
RATE: 10000
|
|
||||||
RUN_TIME: 15
|
|
||||||
|
|
||||||
stress:short:recursive:fedora:41:arm64:
|
|
||||||
<<: *fedora_41_arm64_image
|
|
||||||
<<: *linux_arm64
|
|
||||||
<<: *stress_test_short_job
|
|
||||||
variables:
|
|
||||||
CC: gcc
|
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
|
||||||
FLAME: /usr/bin/flame
|
|
||||||
MODE: recursive
|
|
||||||
RATE: 10000
|
|
||||||
RUN_TIME: 15
|
|
||||||
|
|
||||||
stress:short:rpz:fedora:41:arm64:
|
|
||||||
<<: *fedora_41_arm64_image
|
|
||||||
<<: *linux_arm64
|
|
||||||
<<: *stress_test_short_job
|
|
||||||
variables:
|
|
||||||
CC: gcc
|
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
|
||||||
FLAME: /usr/bin/flame
|
|
||||||
MODE: rpz
|
|
||||||
RATE: 1500
|
|
||||||
RUN_TIME: 15
|
|
||||||
|
|
||||||
stress:short:authoritative:freebsd13:amd64:
|
|
||||||
<<: *freebsd_stress_amd64
|
|
||||||
<<: *stress_test_short_job
|
|
||||||
variables:
|
|
||||||
CC: clang
|
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
|
||||||
FLAME: /usr/local/bin/flame
|
|
||||||
MODE: authoritative
|
|
||||||
RATE: 10000
|
|
||||||
RUN_TIME: 15
|
|
||||||
|
|
||||||
stress:short:recursive:freebsd13:amd64:
|
|
||||||
<<: *freebsd_stress_amd64
|
|
||||||
<<: *stress_test_short_job
|
|
||||||
variables:
|
|
||||||
CC: clang
|
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
|
||||||
FLAME: /usr/local/bin/flame
|
|
||||||
MODE: recursive
|
|
||||||
RATE: 10000
|
|
||||||
RUN_TIME: 15
|
|
||||||
|
|
||||||
stress:short:rpz:freebsd13:amd64:
|
|
||||||
<<: *freebsd_stress_amd64
|
|
||||||
<<: *stress_test_short_job
|
|
||||||
variables:
|
|
||||||
CC: clang
|
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
|
||||||
FLAME: /usr/local/bin/flame
|
|
||||||
MODE: rpz
|
|
||||||
RATE: 1500
|
|
||||||
RUN_TIME: 15
|
|
||||||
|
|
||||||
stress:authoritative:fedora:41:amd64:
|
|
||||||
<<: *fedora_41_amd64_image
|
|
||||||
<<: *linux_amd64
|
|
||||||
<<: *stress_test_long_job
|
|
||||||
variables:
|
|
||||||
CC: gcc
|
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
|
||||||
FLAME: /usr/bin/flame
|
|
||||||
MODE: authoritative
|
|
||||||
RATE: 10000
|
|
||||||
RUN_TIME: 60
|
|
||||||
only:
|
|
||||||
variables:
|
|
||||||
- $CI_COMMIT_TAG || ($BIND_STRESS_TEST_OS =~ /linux/i && $BIND_STRESS_TEST_MODE =~ /authoritative/i && $BIND_STRESS_TEST_ARCH =~ /amd64/i)
|
|
||||||
|
|
||||||
stress:recursive:fedora:41:amd64:
|
|
||||||
<<: *fedora_41_amd64_image
|
|
||||||
<<: *linux_amd64
|
|
||||||
<<: *stress_test_long_job
|
|
||||||
variables:
|
|
||||||
CC: gcc
|
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
|
||||||
FLAME: /usr/bin/flame
|
|
||||||
MODE: recursive
|
|
||||||
RATE: 10000
|
|
||||||
RUN_TIME: 60
|
|
||||||
only:
|
|
||||||
variables:
|
|
||||||
- $CI_COMMIT_TAG || ($BIND_STRESS_TEST_OS =~ /linux/i && $BIND_STRESS_TEST_MODE =~ /recursive/i && $BIND_STRESS_TEST_ARCH =~ /amd64/i)
|
|
||||||
|
|
||||||
stress:rpz:fedora:41:amd64:
|
|
||||||
<<: *fedora_41_amd64_image
|
|
||||||
<<: *linux_amd64
|
|
||||||
<<: *stress_test_long_job
|
|
||||||
variables:
|
|
||||||
CC: gcc
|
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
|
||||||
FLAME: /usr/bin/flame
|
|
||||||
MODE: rpz
|
|
||||||
RATE: 1500
|
|
||||||
RUN_TIME: 60
|
|
||||||
only:
|
|
||||||
variables:
|
|
||||||
- $CI_COMMIT_TAG || ($BIND_STRESS_TEST_OS =~ /linux/i && $BIND_STRESS_TEST_MODE =~ /rpz/i && $BIND_STRESS_TEST_ARCH =~ /amd64/i)
|
|
||||||
|
|
||||||
stress:authoritative:fedora:41:arm64:
|
|
||||||
<<: *fedora_41_arm64_image
|
|
||||||
<<: *linux_arm64
|
|
||||||
<<: *stress_test_long_job
|
|
||||||
variables:
|
|
||||||
CC: gcc
|
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
|
||||||
FLAME: /usr/bin/flame
|
|
||||||
MODE: authoritative
|
|
||||||
RATE: 10000
|
|
||||||
RUN_TIME: 60
|
|
||||||
only:
|
|
||||||
variables:
|
|
||||||
- $CI_COMMIT_TAG || ($BIND_STRESS_TEST_OS =~ /linux/i && $BIND_STRESS_TEST_MODE =~ /authoritative/i && $BIND_STRESS_TEST_ARCH =~ /arm64/i)
|
|
||||||
|
|
||||||
stress:recursive:fedora:41:arm64:
|
|
||||||
<<: *fedora_41_arm64_image
|
|
||||||
<<: *linux_arm64
|
|
||||||
<<: *stress_test_long_job
|
|
||||||
variables:
|
|
||||||
CC: gcc
|
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
|
||||||
FLAME: /usr/bin/flame
|
|
||||||
MODE: recursive
|
|
||||||
RATE: 10000
|
|
||||||
RUN_TIME: 60
|
|
||||||
only:
|
|
||||||
variables:
|
|
||||||
- $CI_COMMIT_TAG || ($BIND_STRESS_TEST_OS =~ /linux/i && $BIND_STRESS_TEST_MODE =~ /recursive/i && $BIND_STRESS_TEST_ARCH =~ /arm64/i)
|
|
||||||
|
|
||||||
stress:rpz:fedora:41:arm64:
|
|
||||||
<<: *fedora_41_arm64_image
|
|
||||||
<<: *linux_arm64
|
|
||||||
<<: *stress_test_long_job
|
|
||||||
variables:
|
|
||||||
CC: gcc
|
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
|
||||||
FLAME: /usr/bin/flame
|
|
||||||
MODE: rpz
|
|
||||||
RATE: 1500
|
|
||||||
RUN_TIME: 60
|
|
||||||
only:
|
|
||||||
variables:
|
|
||||||
- $CI_COMMIT_TAG || ($BIND_STRESS_TEST_OS =~ /linux/i && $BIND_STRESS_TEST_MODE =~ /rpz/i && $BIND_STRESS_TEST_ARCH =~ /arm64/i)
|
|
||||||
|
|
||||||
stress:authoritative:freebsd13:amd64:
|
|
||||||
<<: *freebsd_stress_amd64
|
|
||||||
<<: *stress_test_long_job
|
|
||||||
variables:
|
|
||||||
CC: clang
|
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
|
||||||
FLAME: /usr/local/bin/flame
|
|
||||||
MODE: authoritative
|
|
||||||
RATE: 10000
|
|
||||||
RUN_TIME: 60
|
|
||||||
only:
|
|
||||||
variables:
|
|
||||||
- $CI_COMMIT_TAG || ($BIND_STRESS_TEST_OS =~ /freebsd/i && $BIND_STRESS_TEST_MODE =~ /authoritative/i && $BIND_STRESS_TEST_ARCH =~ /amd64/i)
|
|
||||||
|
|
||||||
stress:recursive:freebsd13:amd64:
|
|
||||||
<<: *freebsd_stress_amd64
|
|
||||||
<<: *stress_test_long_job
|
|
||||||
variables:
|
|
||||||
CC: clang
|
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
|
||||||
FLAME: /usr/local/bin/flame
|
|
||||||
MODE: recursive
|
|
||||||
RATE: 10000
|
|
||||||
RUN_TIME: 60
|
|
||||||
only:
|
|
||||||
variables:
|
|
||||||
- $CI_COMMIT_TAG || ($BIND_STRESS_TEST_OS =~ /freebsd/i && $BIND_STRESS_TEST_MODE =~ /recursive/i && $BIND_STRESS_TEST_ARCH =~ /amd64/i)
|
|
||||||
|
|
||||||
stress:rpz:freebsd13:amd64:
|
|
||||||
<<: *freebsd_stress_amd64
|
|
||||||
<<: *stress_test_long_job
|
|
||||||
variables:
|
|
||||||
CC: clang
|
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
|
||||||
FLAME: /usr/local/bin/flame
|
|
||||||
MODE: rpz
|
|
||||||
RATE: 1500
|
|
||||||
RUN_TIME: 60
|
|
||||||
only:
|
|
||||||
variables:
|
|
||||||
- $CI_COMMIT_TAG || ($BIND_STRESS_TEST_OS =~ /freebsd/i && $BIND_STRESS_TEST_MODE =~ /rpz/i && $BIND_STRESS_TEST_ARCH =~ /amd64/i)
|
|
||||||
|
|
||||||
# git fsck operates over the whole repository and is sufficient to schedule it
|
# git fsck operates over the whole repository and is sufficient to schedule it
|
||||||
# only in one branch, preferably "main". GitLab's clone strategy prevents us
|
# only in one branch, preferably "main". GitLab's clone strategy prevents us
|
||||||
# from using the "bind9" repo clone; we need to clone it ourselves.
|
# from using the "bind9" repo clone; we need to clone it ourselves.
|
||||||
@@ -2026,10 +1804,10 @@ pairwise:
|
|||||||
- set +o pipefail; git log --format='%H' | grep --silent "$CI_COMMIT_BEFORE_SHA" && PREVIOUS_TIP_REACHABLE=1
|
- set +o pipefail; git log --format='%H' | grep --silent "$CI_COMMIT_BEFORE_SHA" && PREVIOUS_TIP_REACHABLE=1
|
||||||
- test "$PREVIOUS_TIP_REACHABLE" != "1" && echo "force-push detected, stop" && exit 1
|
- test "$PREVIOUS_TIP_REACHABLE" != "1" && echo "force-push detected, stop" && exit 1
|
||||||
# non-fast-forward merges are disabled so we have to have merge commit on top
|
# non-fast-forward merges are disabled so we have to have merge commit on top
|
||||||
- MERGE_REQUEST_ID="$(git log -1 --format='%b' | sed --silent -e 's/^See merge request [^!]\+!//p')"
|
- MERGE_REQUEST_ID="$(git log -1 --format='%b' | sed --silent -e "s|^See merge request ${CI_PROJECT_PATH}\!||p")"
|
||||||
- >
|
- >
|
||||||
: stop if this is not a merge request
|
: stop if this is not a merge request in the current project\'s namespace
|
||||||
- test "$MERGE_REQUEST_ID" -ge 0
|
- test -n "$MERGE_REQUEST_ID"
|
||||||
- git clone --depth 1 https://gitlab.isc.org/isc-projects/bind9-qa.git
|
- git clone --depth 1 https://gitlab.isc.org/isc-projects/bind9-qa.git
|
||||||
|
|
||||||
backports:
|
backports:
|
||||||
@@ -2045,6 +1823,6 @@ backports:
|
|||||||
merged-metadata:
|
merged-metadata:
|
||||||
<<: *post_merge
|
<<: *post_merge
|
||||||
rules:
|
rules:
|
||||||
- if: '$CI_PIPELINE_SOURCE == "push" && ($CI_COMMIT_REF_NAME =~ /^bind-9.[0-9]+(-sub)?$/ || $CI_COMMIT_REF_NAME =~ /^bind-9.[0-9]+.[0-9]+-release$/ || $CI_COMMIT_REF_NAME == $CI_DEFAULT_BRANCH)'
|
- if: '$CI_PIPELINE_SOURCE == "push" && ($CI_COMMIT_REF_NAME =~ /^bind-9.[0-9]+(-sub)?$/ || $CI_COMMIT_REF_NAME =~ /^v9.[0-9]+.[0-9]+-release$/ || $CI_COMMIT_REF_NAME == $CI_DEFAULT_BRANCH)'
|
||||||
script:
|
script:
|
||||||
- bind9-qa/releng/after_merge.py "$CI_PROJECT_ID" "$MERGE_REQUEST_ID"
|
- bind9-qa/releng/after_merge.py "$CI_PROJECT_ID" "$MERGE_REQUEST_ID"
|
||||||
|
|||||||
@@ -31,11 +31,11 @@ confidential!
|
|||||||
- [ ] [:link:][step_deputy] **(IM)** Pick a Deputy Incident Manager
|
- [ ] [:link:][step_deputy] **(IM)** Pick a Deputy Incident Manager
|
||||||
- [ ] [:link:][step_respond] **(IM)** Respond to the bug reporter
|
- [ ] [:link:][step_respond] **(IM)** Respond to the bug reporter
|
||||||
- [ ] [:link:][step_public_mrs] **(SwEng)** Ensure there are no public merge requests which inadvertently disclose the issue
|
- [ ] [:link:][step_public_mrs] **(SwEng)** Ensure there are no public merge requests which inadvertently disclose the issue
|
||||||
|
- [ ] [:link:][step_coordinate_cve_id] **(SwEng)** Check if we need to coordinate with other vendors (an industry-wide CVE identifier might be necessary)
|
||||||
- [ ] [:link:][step_assign_cve_id] **(IM)** Assign a CVE identifier
|
- [ ] [:link:][step_assign_cve_id] **(IM)** Assign a CVE identifier
|
||||||
- [ ] [:link:][step_note_cve_info] **(SwEng)** Update this issue with the assigned CVE identifier, the CVSS score, and CWE category
|
- [ ] [:link:][step_note_cve_info] **(SwEng)** Update this issue with the assigned CVE identifier, the CVSS score, and the CWE category
|
||||||
- [ ] [:link:][step_versions_affected] **(SwEng)** Determine the range of product versions affected (including the Subscription Edition)
|
- [ ] [:link:][step_versions_affected] **(SwEng)** Determine the range of product versions affected (including the Subscription Edition)
|
||||||
- [ ] [:link:][step_workarounds] **(SwEng)** Determine whether workarounds for the problem exist
|
- [ ] [:link:][step_workarounds] **(SwEng)** Determine whether workarounds for the problem exist
|
||||||
- [ ] [:link:][step_coordinate] **(SwEng)** If necessary, coordinate with other parties
|
|
||||||
- [ ] [:link:][step_earliest_prepare] **(Support)** Prepare "earliest" notification text
|
- [ ] [:link:][step_earliest_prepare] **(Support)** Prepare "earliest" notification text
|
||||||
- [ ] [:link:][step_earliest_send] **(Support)** Update "earliest" notification ticket in support portal Earliest queue which will notify earliest customers
|
- [ ] [:link:][step_earliest_send] **(Support)** Update "earliest" notification ticket in support portal Earliest queue which will notify earliest customers
|
||||||
- [ ] [:link:][step_advisory_mr] **(Support)** Create a merge request for the Security Advisory and include all readily available information in it
|
- [ ] [:link:][step_advisory_mr] **(Support)** Create a merge request for the Security Advisory and include all readily available information in it
|
||||||
@@ -48,6 +48,7 @@ confidential!
|
|||||||
- [ ] [:link:][step_backports] **(SwEng)** Prepare backports of the merge request addressing the problem for all affected (and still maintained) branches of a given product
|
- [ ] [:link:][step_backports] **(SwEng)** Prepare backports of the merge request addressing the problem for all affected (and still maintained) branches of a given product
|
||||||
- [ ] [:link:][step_finish_advisory] **(Support)** Finish preparing the Security Advisory
|
- [ ] [:link:][step_finish_advisory] **(Support)** Finish preparing the Security Advisory
|
||||||
- [ ] [:link:][step_meta_issue] **(QA)** Create (or update) the private issue containing links to fixes & reproducers for all CVEs fixed in a given release cycle
|
- [ ] [:link:][step_meta_issue] **(QA)** Create (or update) the private issue containing links to fixes & reproducers for all CVEs fixed in a given release cycle
|
||||||
|
- [ ] [:link:][step_coordinate_check] **(SwEng)** Make sure other vendors are able to release on the date that was previously agreed upon
|
||||||
- [ ] [:link:][step_merge_fixes] **(QA)** Merge the CVE fixes in CVE identifier order
|
- [ ] [:link:][step_merge_fixes] **(QA)** Merge the CVE fixes in CVE identifier order
|
||||||
- [ ] [:link:][step_patches] **(QA)** Prepare a standalone patch for the last stable release of each affected (and still maintained) product branch
|
- [ ] [:link:][step_patches] **(QA)** Prepare a standalone patch for the last stable release of each affected (and still maintained) product branch
|
||||||
- [ ] [:link:][step_asn_releases] **(QA)** Prepare ASN releases (as outlined in the Release Checklist)
|
- [ ] [:link:][step_asn_releases] **(QA)** Prepare ASN releases (as outlined in the Release Checklist)
|
||||||
@@ -68,15 +69,16 @@ confidential!
|
|||||||
### On the Day of Public Disclosure
|
### On the Day of Public Disclosure
|
||||||
|
|
||||||
- [ ] [:link:][step_clearance] **(IM)** Grant QA & Marketing clearance to proceed with public release
|
- [ ] [:link:][step_clearance] **(IM)** Grant QA & Marketing clearance to proceed with public release
|
||||||
- [ ] [:link:][step_publish] **(QA/Marketing)** Publish the releases (as outlined in the release checklist)
|
|
||||||
- [ ] [:link:][step_matrix] **(Support)** (BIND 9 only) Add the new CVEs to the vulnerability matrix in the Knowledge Base
|
- [ ] [:link:][step_matrix] **(Support)** (BIND 9 only) Add the new CVEs to the vulnerability matrix in the Knowledge Base
|
||||||
- [ ] [:link:][step_publish_advisory] **(Support)** Bump Document Version for the Security Advisory and publish it in the Knowledge Base
|
- [ ] [:link:][step_bump_advisory] **(Support)** Bump Document Version for the Security Advisory in Printing Press
|
||||||
|
- [ ] [:link:][step_publish_advisory] **(Support)** Publish the Security Advisory in the Knowledge Base
|
||||||
|
- [ ] [:link:][step_publish] **(QA/Marketing)** Publish the releases (as outlined in the release checklist)
|
||||||
- [ ] [:link:][step_notifications] **(First IM)** Send notification emails to third parties
|
- [ ] [:link:][step_notifications] **(First IM)** Send notification emails to third parties
|
||||||
- [ ] [:link:][step_mitre] **(First IM)** Advise MITRE about the disclosed CVEs
|
- [ ] [:link:][step_mitre] **(First IM)** Advise MITRE about the disclosed CVEs
|
||||||
- [ ] [:link:][step_merge_advisory] **(First IM)** Merge the Security Advisory merge request
|
- [ ] [:link:][step_merge_advisory] **(First IM)** Merge the Security Advisory merge request
|
||||||
- [ ] [:link:][step_embargo_end] **(IM)** Inform original reporter (if external) that the security disclosure process is complete
|
- [ ] [:link:][step_embargo_end] **(IM)** Inform original reporter (if external) that the security disclosure process is complete
|
||||||
- [ ] [:link:][step_asn_clear] **(Support)** Update the tickets in the ASN queues in RT that the embargo is lifted
|
- [ ] [:link:][step_asn_clear] **(Support)** Update the tickets in the ASN queues in RT that the embargo is lifted
|
||||||
- [ ] [:link:][step_customers] **(Marketing)** Open a ticket in the <software name> Announce queue that the release is published
|
- [ ] [:link:][step_customers] **(Marketing)** Open a ticket in the appropriate announce queue in RT that the release is published
|
||||||
|
|
||||||
### After Public Disclosure
|
### After Public Disclosure
|
||||||
|
|
||||||
@@ -85,13 +87,13 @@ confidential!
|
|||||||
[step_deputy]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#pick-a-deputy-incident-manager
|
[step_deputy]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#pick-a-deputy-incident-manager
|
||||||
[step_respond]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#respond-to-the-bug-reporter
|
[step_respond]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#respond-to-the-bug-reporter
|
||||||
[step_public_mrs]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#ensure-there-are-no-public-merge-requests-which-inadvertently-disclose-the-issue
|
[step_public_mrs]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#ensure-there-are-no-public-merge-requests-which-inadvertently-disclose-the-issue
|
||||||
|
[step_coordinate_cve_id]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#check-if-we-need-to-coordinate-with-other-vendors-an-industry-wide-cve-identifier-might-be-necessary
|
||||||
[step_assign_cve_id]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#assign-a-cve-identifier
|
[step_assign_cve_id]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#assign-a-cve-identifier
|
||||||
[step_note_cve_info]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#update-this-issue-with-the-assigned-cve-identifier-the-cvss-score-and-the-cwe-category
|
[step_note_cve_info]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#update-this-issue-with-the-assigned-cve-identifier-the-cvss-score-and-the-cwe-category
|
||||||
[step_versions_affected]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#determine-the-range-of-product-versions-affected-including-the-subscription-edition
|
[step_versions_affected]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#determine-the-range-of-product-versions-affected-including-the-subscription-edition
|
||||||
[step_workarounds]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#determine-whether-workarounds-for-the-problem-exist
|
[step_workarounds]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#determine-whether-workarounds-for-the-problem-exist
|
||||||
[step_coordinate]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#if-necessary-coordinate-with-other-parties
|
[step_earliest_prepare]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#prepare-earliest-notification-text
|
||||||
[step_earliest_prepare]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#prepare-earliest-notification-text-and-hand-it-off-to-marketing
|
[step_earliest_send]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#update-earliest-notification-ticket-in-support-portal-earliest-queue-which-will-notify-earliest-customers
|
||||||
[step_earliest_send]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#update-earliest-notification-document-in-sf-portal-and-send-bulk-email-to-earliest-customers
|
|
||||||
[step_advisory_mr]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#create-a-merge-request-for-the-security-advisory-and-include-all-readily-available-information-in-it
|
[step_advisory_mr]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#create-a-merge-request-for-the-security-advisory-and-include-all-readily-available-information-in-it
|
||||||
[step_reproducer_mr]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#prepare-a-private-merge-request-containing-a-system-test-reproducing-the-problem
|
[step_reproducer_mr]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#prepare-a-private-merge-request-containing-a-system-test-reproducing-the-problem
|
||||||
[step_notify_support]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#notify-support-when-a-reproducer-is-ready
|
[step_notify_support]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#notify-support-when-a-reproducer-is-ready
|
||||||
@@ -102,25 +104,26 @@ confidential!
|
|||||||
[step_backports]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#prepare-backports-of-the-merge-request-addressing-the-problem-for-all-affected-and-still-maintained-branches-of-a-given-product
|
[step_backports]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#prepare-backports-of-the-merge-request-addressing-the-problem-for-all-affected-and-still-maintained-branches-of-a-given-product
|
||||||
[step_finish_advisory]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#finish-preparing-the-security-advisory
|
[step_finish_advisory]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#finish-preparing-the-security-advisory
|
||||||
[step_meta_issue]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#create-or-update-the-private-issue-containing-links-to-fixes-reproducers-for-all-cves-fixed-in-a-given-release-cycle
|
[step_meta_issue]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#create-or-update-the-private-issue-containing-links-to-fixes-reproducers-for-all-cves-fixed-in-a-given-release-cycle
|
||||||
[step_changes]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#bind-9-only-reserve-a-block-of-changes-placeholders-once-the-complete-set-of-vulnerabilities-fixed-in-a-given-release-cycle-is-determined
|
[step_coordinate_check]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#make-sure-other-vendors-are-able-to-release-on-the-date-that-was-previously-agreed-upon
|
||||||
[step_merge_fixes]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#merge-the-cve-fixes-in-cve-identifier-order
|
[step_merge_fixes]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#merge-the-cve-fixes-in-cve-identifier-order
|
||||||
[step_patches]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#prepare-a-standalone-patch-for-the-last-stable-release-of-each-affected-and-still-maintained-product-branch
|
[step_patches]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#prepare-a-standalone-patch-for-the-last-stable-release-of-each-affected-and-still-maintained-product-branch
|
||||||
[step_asn_releases]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#prepare-asn-releases-as-outlined-in-the-release-checklist
|
[step_asn_releases]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#prepare-asn-releases-as-outlined-in-the-release-checklist
|
||||||
[step_asn_documents]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#update-the-text-on-the-t-5-from-the-printing-press-project-and-earliest-asn-documents-in-the-sf-portal
|
[step_asn_links]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#bind-9-only-update-the-bind-s-information-document-in-the-support-portal-with-download-links-to-the-new-versions
|
||||||
[step_asn_links]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#bind-9-only-update-the-bind-s-information-document-in-sf-with-download-links-to-the-new-versions
|
[step_asn_send]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#notify-eligible-customers-by-adding-a-ticket-to-the-5-day-queue-in-rt-with-the-text-of-the-advisory-earliest-and-t-5
|
||||||
[step_asn_send]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#bulk-email-eligible-customers-to-check-the-sf-portal
|
|
||||||
[step_preannouncement]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#bind-9-only-send-a-pre-announcement-email-to-the-bind-announce-mailing-list-to-alert-users-that-the-upcoming-release-will-include-security-fixes
|
[step_preannouncement]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#bind-9-only-send-a-pre-announcement-email-to-the-bind-announce-mailing-list-to-alert-users-that-the-upcoming-release-will-include-security-fixes
|
||||||
|
[step_asn_send]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#notify-eligible-customers-by-adding-a-ticket-to-the-3-day-queue-in-rt-with-the-text-of-the-advisory-t-3
|
||||||
[step_packager_emails]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#send-notifications-to-os-packagers
|
[step_packager_emails]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#send-notifications-to-os-packagers
|
||||||
[step_clearance]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#grant-qa-marketing-clearance-to-proceed-with-public-release
|
[step_clearance]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#grant-qa-marketing-clearance-to-proceed-with-public-release
|
||||||
[step_publish]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#publish-the-releases-as-outlined-in-the-release-checklist
|
|
||||||
[step_matrix]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#bind-9-only-add-the-new-cves-to-the-vulnerability-matrix-in-the-knowledge-base
|
[step_matrix]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#bind-9-only-add-the-new-cves-to-the-vulnerability-matrix-in-the-knowledge-base
|
||||||
[step_publish_advisory]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#bump-document-version-for-the-security-advisory-and-publish-it-in-the-knowledge-base
|
[step_bump_advisory]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#bump-document-version-for-the-security-advisory-in-printing-press
|
||||||
|
[step_publish_advisory]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#publish-the-security-advisory-in-the-knowledge-base
|
||||||
|
[step_publish]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#publish-the-releases-as-outlined-in-the-release-checklist
|
||||||
[step_notifications]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#send-notification-emails-to-third-parties
|
[step_notifications]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#send-notification-emails-to-third-parties
|
||||||
[step_mitre]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#advise-mitre-about-the-disclosed-cves
|
[step_mitre]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#advise-mitre-about-the-disclosed-cves
|
||||||
[step_merge_advisory]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#merge-the-security-advisory-merge-request
|
[step_merge_advisory]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#merge-the-security-advisory-merge-request
|
||||||
[step_embargo_end]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#inform-original-reporter-if-external-that-the-security-disclosure-process-is-complete
|
[step_embargo_end]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#inform-original-reporter-if-external-that-the-security-disclosure-process-is-complete
|
||||||
[step_asn_clear]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#update-the-sf-portal-to-clear-the-asn
|
[step_asn_clear]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#update-the-tickets-in-the-asn-queues-in-rt-that-the-embargo-is-lifted
|
||||||
[step_customers]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#email-asn-recipients-that-the-embargo-is-lifted
|
[step_customers]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#open-a-ticket-in-the-appropriate-announce-queue-in-rt-that-the-release-is-published
|
||||||
[step_regression]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#merge-a-regression-test-reproducing-the-bug-into-all-affected-and-still-maintained-branches
|
[step_regression]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#merge-a-regression-test-reproducing-the-bug-into-all-affected-and-still-maintained-branches
|
||||||
|
|
||||||
/confidential
|
/confidential
|
||||||
|
|||||||
+12
-11
@@ -11,7 +11,7 @@ See the COPYRIGHT file distributed with this work for additional
|
|||||||
information regarding copyright ownership.
|
information regarding copyright ownership.
|
||||||
-->
|
-->
|
||||||
## BIND 9 Source Access and Contributor Guidelines
|
## BIND 9 Source Access and Contributor Guidelines
|
||||||
*May 28, 2020*
|
*Nov 26, 2024*
|
||||||
|
|
||||||
### Contents
|
### Contents
|
||||||
|
|
||||||
@@ -72,13 +72,13 @@ To clone the repository, use:
|
|||||||
> $ git clone https://gitlab.isc.org/isc-projects/bind9.git
|
> $ git clone https://gitlab.isc.org/isc-projects/bind9.git
|
||||||
|
|
||||||
Release branch names are of the form `bind-9.X`, where X represents the second
|
Release branch names are of the form `bind-9.X`, where X represents the second
|
||||||
number in the BIND 9 version number. So, to check out the BIND 9.18
|
number in the BIND 9 version number. So, to check out the BIND 9.20
|
||||||
branch, use:
|
branch, use:
|
||||||
|
|
||||||
> $ git checkout bind-9.18
|
> $ git checkout bind-9.20
|
||||||
|
|
||||||
Whenever a branch is ready for publication, a tag is placed of the
|
Whenever a branch is ready for publication, a tag is placed of the
|
||||||
form `v9.X.Y`. The 9.18.0 release, for instance, is tagged as `v9.18.0`.
|
form `v9.X.Y`. The 9.20.0 release, for instance, is tagged as `v9.20.0`.
|
||||||
|
|
||||||
The branch in which the next major release is being developed is called
|
The branch in which the next major release is being developed is called
|
||||||
`main`.
|
`main`.
|
||||||
@@ -121,8 +121,9 @@ patch will be applied.
|
|||||||
#### <a name="bind"></a>BIND code
|
#### <a name="bind"></a>BIND code
|
||||||
|
|
||||||
Patches for BIND may be submitted directly via merge requests in
|
Patches for BIND may be submitted directly via merge requests in
|
||||||
[ISC's GitLab](https://gitlab.isc.org/isc-projects/bind9/) source
|
[ISC's GitLab](https://gitlab.isc.org/isc-projects/bind9/) source repository for
|
||||||
repository for BIND.
|
BIND. Please contact ISC and provide your GitLab username in order to be allowed
|
||||||
|
to fork the project and submit merge requests.
|
||||||
|
|
||||||
Patches can also be submitted as diffs against a specific version of
|
Patches can also be submitted as diffs against a specific version of
|
||||||
BIND -- preferably the current top of the `main` branch. Diffs may
|
BIND -- preferably the current top of the `main` branch. Diffs may
|
||||||
@@ -144,8 +145,8 @@ we're busy with other work, it may take us a long time to get to it.
|
|||||||
To ensure your patch is acted on as promptly as possible, please:
|
To ensure your patch is acted on as promptly as possible, please:
|
||||||
|
|
||||||
* Try to adhere to the [BIND 9 coding style](doc/dev/style.md).
|
* Try to adhere to the [BIND 9 coding style](doc/dev/style.md).
|
||||||
* Run `make check` to ensure your change hasn't caused any
|
* Run unit and system tests to ensure your change hasn't caused any
|
||||||
functional regressions.
|
functional regressions (these can be checked in the CI pipeline).
|
||||||
* Document your work, both in the patch itself and in the
|
* Document your work, both in the patch itself and in the
|
||||||
accompanying email.
|
accompanying email.
|
||||||
* In patches that make non-trivial functional changes, include system
|
* In patches that make non-trivial functional changes, include system
|
||||||
@@ -156,12 +157,12 @@ To ensure your patch is acted on as promptly as possible, please:
|
|||||||
##### Changes to `configure`
|
##### Changes to `configure`
|
||||||
|
|
||||||
If you need to make changes to `configure`, you should not edit it
|
If you need to make changes to `configure`, you should not edit it
|
||||||
directly; instead, edit `configure.in`, then run `autoconf`. Similarly,
|
directly; instead, edit `configure.ac`, then run `autoconf`. Similarly,
|
||||||
instead of editing `config.h.in` directly, edit `configure.in` and run
|
instead of editing `config.h.in` directly, edit `configure.ac` and run
|
||||||
`autoheader`.
|
`autoheader`.
|
||||||
|
|
||||||
When submitting a patch as a diff, it's fine to omit the `configure`
|
When submitting a patch as a diff, it's fine to omit the `configure`
|
||||||
diffs to save space. Just send the `configure.in` diffs and we'll
|
diffs to save space. Just send the `configure.ac` diffs and we'll
|
||||||
generate the new `configure` during the review process.
|
generate the new `configure` during the review process.
|
||||||
|
|
||||||
##### Documentation
|
##### Documentation
|
||||||
|
|||||||
+130
-48
@@ -112,11 +112,7 @@ add(char *key, int value) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (symtab == NULL) {
|
if (symtab == NULL) {
|
||||||
result = isc_symtab_create(sym_mctx, 100, freekey, sym_mctx,
|
isc_symtab_create(sym_mctx, freekey, sym_mctx, false, &symtab);
|
||||||
false, &symtab);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
key = isc_mem_strdup(sym_mctx, key);
|
key = isc_mem_strdup(sym_mctx, key);
|
||||||
@@ -144,12 +140,97 @@ logged(char *key, int value) {
|
|||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
static bool
|
||||||
|
checkisservedby(dns_zone_t *zone, dns_rdatatype_t type,
|
||||||
|
const dns_name_t *name) {
|
||||||
|
char namebuf[DNS_NAME_FORMATSIZE + 1];
|
||||||
|
char ownerbuf[DNS_NAME_FORMATSIZE + 1];
|
||||||
|
/*
|
||||||
|
* Not all getaddrinfo implementations distinguish NODATA
|
||||||
|
* from NXDOMAIN with PF_INET6 so use PF_UNSPEC and look at
|
||||||
|
* the returned ai_family values.
|
||||||
|
*/
|
||||||
|
struct addrinfo hints = {
|
||||||
|
.ai_flags = AI_CANONNAME,
|
||||||
|
.ai_family = PF_UNSPEC,
|
||||||
|
.ai_socktype = SOCK_STREAM,
|
||||||
|
.ai_protocol = IPPROTO_TCP,
|
||||||
|
};
|
||||||
|
struct addrinfo *ai = NULL, *cur;
|
||||||
|
bool has_type = false;
|
||||||
|
int eai;
|
||||||
|
|
||||||
|
dns_name_format(name, namebuf, sizeof(namebuf) - 1);
|
||||||
|
/*
|
||||||
|
* Turn off search.
|
||||||
|
*/
|
||||||
|
if (dns_name_countlabels(name) > 1U) {
|
||||||
|
strlcat(namebuf, ".", sizeof(namebuf));
|
||||||
|
}
|
||||||
|
eai = getaddrinfo(namebuf, NULL, &hints, &ai);
|
||||||
|
|
||||||
|
switch (eai) {
|
||||||
|
case 0:
|
||||||
|
cur = ai;
|
||||||
|
while (cur != NULL) {
|
||||||
|
if (cur->ai_family == AF_INET &&
|
||||||
|
type == dns_rdatatype_a)
|
||||||
|
{
|
||||||
|
has_type = true;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
if (cur->ai_family == AF_INET6 &&
|
||||||
|
type == dns_rdatatype_aaaa)
|
||||||
|
{
|
||||||
|
has_type = true;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
cur = cur->ai_next;
|
||||||
|
}
|
||||||
|
freeaddrinfo(ai);
|
||||||
|
return has_type;
|
||||||
|
#if defined(EAI_NODATA) && (EAI_NODATA != EAI_NONAME)
|
||||||
|
case EAI_NODATA:
|
||||||
|
#endif /* if defined(EAI_NODATA) && (EAI_NODATA != EAI_NONAME) */
|
||||||
|
case EAI_NONAME:
|
||||||
|
if (!logged(namebuf, ERR_NO_ADDRESSES)) {
|
||||||
|
dns_name_format(dns_zone_getorigin(zone), ownerbuf,
|
||||||
|
sizeof(ownerbuf));
|
||||||
|
dns_name_format(name, namebuf, sizeof(namebuf) - 1);
|
||||||
|
dns_zone_log(zone, ISC_LOG_ERROR,
|
||||||
|
"%s/NS '%s' (out of zone) "
|
||||||
|
"has no addresses records (A or AAAA)",
|
||||||
|
ownerbuf, namebuf);
|
||||||
|
add(namebuf, ERR_NO_ADDRESSES);
|
||||||
|
}
|
||||||
|
return false;
|
||||||
|
default:
|
||||||
|
if (!logged(namebuf, ERR_LOOKUP_FAILURE)) {
|
||||||
|
dns_name_format(dns_zone_getorigin(zone), ownerbuf,
|
||||||
|
sizeof(ownerbuf));
|
||||||
|
dns_name_format(name, namebuf, sizeof(namebuf) - 1);
|
||||||
|
dns_zone_log(zone, ISC_LOG_WARNING,
|
||||||
|
"getaddrinfo(%s) failed: %s", namebuf,
|
||||||
|
gai_strerror(eai));
|
||||||
|
add(namebuf, ERR_LOOKUP_FAILURE);
|
||||||
|
}
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
static bool
|
static bool
|
||||||
checkns(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner,
|
checkns(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner,
|
||||||
dns_rdataset_t *a, dns_rdataset_t *aaaa) {
|
dns_rdataset_t *a, dns_rdataset_t *aaaa) {
|
||||||
dns_rdataset_t *rdataset;
|
dns_rdataset_t *rdataset;
|
||||||
dns_rdata_t rdata = DNS_RDATA_INIT;
|
dns_rdata_t rdata = DNS_RDATA_INIT;
|
||||||
struct addrinfo hints, *ai, *cur;
|
isc_result_t result;
|
||||||
|
struct addrinfo hints = {
|
||||||
|
.ai_flags = AI_CANONNAME,
|
||||||
|
.ai_family = PF_UNSPEC,
|
||||||
|
.ai_socktype = SOCK_STREAM,
|
||||||
|
.ai_protocol = IPPROTO_TCP,
|
||||||
|
};
|
||||||
|
struct addrinfo *ai = NULL, *cur;
|
||||||
char namebuf[DNS_NAME_FORMATSIZE + 1];
|
char namebuf[DNS_NAME_FORMATSIZE + 1];
|
||||||
char ownerbuf[DNS_NAME_FORMATSIZE];
|
char ownerbuf[DNS_NAME_FORMATSIZE];
|
||||||
char addrbuf[sizeof("xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:123.123.123.123")];
|
char addrbuf[sizeof("xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:123.123.123.123")];
|
||||||
@@ -157,7 +238,7 @@ checkns(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner,
|
|||||||
bool match;
|
bool match;
|
||||||
const char *type;
|
const char *type;
|
||||||
void *ptr = NULL;
|
void *ptr = NULL;
|
||||||
int result;
|
int eai;
|
||||||
|
|
||||||
REQUIRE(a == NULL || !dns_rdataset_isassociated(a) ||
|
REQUIRE(a == NULL || !dns_rdataset_isassociated(a) ||
|
||||||
a->type == dns_rdatatype_a);
|
a->type == dns_rdatatype_a);
|
||||||
@@ -168,12 +249,6 @@ checkns(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner,
|
|||||||
return answer;
|
return answer;
|
||||||
}
|
}
|
||||||
|
|
||||||
memset(&hints, 0, sizeof(hints));
|
|
||||||
hints.ai_flags = AI_CANONNAME;
|
|
||||||
hints.ai_family = PF_UNSPEC;
|
|
||||||
hints.ai_socktype = SOCK_STREAM;
|
|
||||||
hints.ai_protocol = IPPROTO_TCP;
|
|
||||||
|
|
||||||
dns_name_format(name, namebuf, sizeof(namebuf) - 1);
|
dns_name_format(name, namebuf, sizeof(namebuf) - 1);
|
||||||
/*
|
/*
|
||||||
* Turn off search.
|
* Turn off search.
|
||||||
@@ -183,9 +258,9 @@ checkns(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner,
|
|||||||
}
|
}
|
||||||
dns_name_format(owner, ownerbuf, sizeof(ownerbuf));
|
dns_name_format(owner, ownerbuf, sizeof(ownerbuf));
|
||||||
|
|
||||||
result = getaddrinfo(namebuf, NULL, &hints, &ai);
|
eai = getaddrinfo(namebuf, NULL, &hints, &ai);
|
||||||
dns_name_format(name, namebuf, sizeof(namebuf) - 1);
|
dns_name_format(name, namebuf, sizeof(namebuf) - 1);
|
||||||
switch (result) {
|
switch (eai) {
|
||||||
case 0:
|
case 0:
|
||||||
/*
|
/*
|
||||||
* Work around broken getaddrinfo() implementations that
|
* Work around broken getaddrinfo() implementations that
|
||||||
@@ -228,7 +303,7 @@ checkns(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner,
|
|||||||
if (!logged(namebuf, ERR_LOOKUP_FAILURE)) {
|
if (!logged(namebuf, ERR_LOOKUP_FAILURE)) {
|
||||||
dns_zone_log(zone, ISC_LOG_WARNING,
|
dns_zone_log(zone, ISC_LOG_WARNING,
|
||||||
"getaddrinfo(%s) failed: %s", namebuf,
|
"getaddrinfo(%s) failed: %s", namebuf,
|
||||||
gai_strerror(result));
|
gai_strerror(eai));
|
||||||
add(namebuf, ERR_LOOKUP_FAILURE);
|
add(namebuf, ERR_LOOKUP_FAILURE);
|
||||||
}
|
}
|
||||||
return true;
|
return true;
|
||||||
@@ -358,25 +433,27 @@ checkmissing:
|
|||||||
add(namebuf, ERR_MISSING_GLUE);
|
add(namebuf, ERR_MISSING_GLUE);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
freeaddrinfo(ai);
|
if (ai != NULL) {
|
||||||
|
freeaddrinfo(ai);
|
||||||
|
}
|
||||||
return answer;
|
return answer;
|
||||||
}
|
}
|
||||||
|
|
||||||
static bool
|
static bool
|
||||||
checkmx(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
checkmx(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
||||||
struct addrinfo hints, *ai, *cur;
|
struct addrinfo hints = {
|
||||||
|
.ai_flags = AI_CANONNAME,
|
||||||
|
.ai_family = PF_UNSPEC,
|
||||||
|
.ai_socktype = SOCK_STREAM,
|
||||||
|
.ai_protocol = IPPROTO_TCP,
|
||||||
|
};
|
||||||
|
struct addrinfo *ai = NULL, *cur;
|
||||||
char namebuf[DNS_NAME_FORMATSIZE + 1];
|
char namebuf[DNS_NAME_FORMATSIZE + 1];
|
||||||
char ownerbuf[DNS_NAME_FORMATSIZE];
|
char ownerbuf[DNS_NAME_FORMATSIZE];
|
||||||
int result;
|
int eai;
|
||||||
int level = ISC_LOG_ERROR;
|
int level = ISC_LOG_ERROR;
|
||||||
bool answer = true;
|
bool answer = true;
|
||||||
|
|
||||||
memset(&hints, 0, sizeof(hints));
|
|
||||||
hints.ai_flags = AI_CANONNAME;
|
|
||||||
hints.ai_family = PF_UNSPEC;
|
|
||||||
hints.ai_socktype = SOCK_STREAM;
|
|
||||||
hints.ai_protocol = IPPROTO_TCP;
|
|
||||||
|
|
||||||
dns_name_format(name, namebuf, sizeof(namebuf) - 1);
|
dns_name_format(name, namebuf, sizeof(namebuf) - 1);
|
||||||
/*
|
/*
|
||||||
* Turn off search.
|
* Turn off search.
|
||||||
@@ -386,9 +463,9 @@ checkmx(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
|||||||
}
|
}
|
||||||
dns_name_format(owner, ownerbuf, sizeof(ownerbuf));
|
dns_name_format(owner, ownerbuf, sizeof(ownerbuf));
|
||||||
|
|
||||||
result = getaddrinfo(namebuf, NULL, &hints, &ai);
|
eai = getaddrinfo(namebuf, NULL, &hints, &ai);
|
||||||
dns_name_format(name, namebuf, sizeof(namebuf) - 1);
|
dns_name_format(name, namebuf, sizeof(namebuf) - 1);
|
||||||
switch (result) {
|
switch (eai) {
|
||||||
case 0:
|
case 0:
|
||||||
/*
|
/*
|
||||||
* Work around broken getaddrinfo() implementations that
|
* Work around broken getaddrinfo() implementations that
|
||||||
@@ -421,7 +498,9 @@ checkmx(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
freeaddrinfo(ai);
|
if (ai != NULL) {
|
||||||
|
freeaddrinfo(ai);
|
||||||
|
}
|
||||||
return answer;
|
return answer;
|
||||||
|
|
||||||
case EAI_NONAME:
|
case EAI_NONAME:
|
||||||
@@ -442,7 +521,7 @@ checkmx(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
|||||||
if (!logged(namebuf, ERR_LOOKUP_FAILURE)) {
|
if (!logged(namebuf, ERR_LOOKUP_FAILURE)) {
|
||||||
dns_zone_log(zone, ISC_LOG_WARNING,
|
dns_zone_log(zone, ISC_LOG_WARNING,
|
||||||
"getaddrinfo(%s) failed: %s", namebuf,
|
"getaddrinfo(%s) failed: %s", namebuf,
|
||||||
gai_strerror(result));
|
gai_strerror(eai));
|
||||||
add(namebuf, ERR_LOOKUP_FAILURE);
|
add(namebuf, ERR_LOOKUP_FAILURE);
|
||||||
}
|
}
|
||||||
return true;
|
return true;
|
||||||
@@ -451,19 +530,19 @@ checkmx(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
|||||||
|
|
||||||
static bool
|
static bool
|
||||||
checksrv(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
checksrv(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
||||||
struct addrinfo hints, *ai, *cur;
|
struct addrinfo hints = {
|
||||||
|
.ai_flags = AI_CANONNAME,
|
||||||
|
.ai_family = PF_UNSPEC,
|
||||||
|
.ai_socktype = SOCK_STREAM,
|
||||||
|
.ai_protocol = IPPROTO_TCP,
|
||||||
|
};
|
||||||
|
struct addrinfo *ai = NULL, *cur;
|
||||||
char namebuf[DNS_NAME_FORMATSIZE + 1];
|
char namebuf[DNS_NAME_FORMATSIZE + 1];
|
||||||
char ownerbuf[DNS_NAME_FORMATSIZE];
|
char ownerbuf[DNS_NAME_FORMATSIZE];
|
||||||
int result;
|
int eai;
|
||||||
int level = ISC_LOG_ERROR;
|
int level = ISC_LOG_ERROR;
|
||||||
bool answer = true;
|
bool answer = true;
|
||||||
|
|
||||||
memset(&hints, 0, sizeof(hints));
|
|
||||||
hints.ai_flags = AI_CANONNAME;
|
|
||||||
hints.ai_family = PF_UNSPEC;
|
|
||||||
hints.ai_socktype = SOCK_STREAM;
|
|
||||||
hints.ai_protocol = IPPROTO_TCP;
|
|
||||||
|
|
||||||
dns_name_format(name, namebuf, sizeof(namebuf) - 1);
|
dns_name_format(name, namebuf, sizeof(namebuf) - 1);
|
||||||
/*
|
/*
|
||||||
* Turn off search.
|
* Turn off search.
|
||||||
@@ -473,9 +552,9 @@ checksrv(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
|||||||
}
|
}
|
||||||
dns_name_format(owner, ownerbuf, sizeof(ownerbuf));
|
dns_name_format(owner, ownerbuf, sizeof(ownerbuf));
|
||||||
|
|
||||||
result = getaddrinfo(namebuf, NULL, &hints, &ai);
|
eai = getaddrinfo(namebuf, NULL, &hints, &ai);
|
||||||
dns_name_format(name, namebuf, sizeof(namebuf) - 1);
|
dns_name_format(name, namebuf, sizeof(namebuf) - 1);
|
||||||
switch (result) {
|
switch (eai) {
|
||||||
case 0:
|
case 0:
|
||||||
/*
|
/*
|
||||||
* Work around broken getaddrinfo() implementations that
|
* Work around broken getaddrinfo() implementations that
|
||||||
@@ -508,7 +587,9 @@ checksrv(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
freeaddrinfo(ai);
|
if (ai != NULL) {
|
||||||
|
freeaddrinfo(ai);
|
||||||
|
}
|
||||||
return answer;
|
return answer;
|
||||||
|
|
||||||
case EAI_NONAME:
|
case EAI_NONAME:
|
||||||
@@ -529,7 +610,7 @@ checksrv(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
|||||||
if (!logged(namebuf, ERR_LOOKUP_FAILURE)) {
|
if (!logged(namebuf, ERR_LOOKUP_FAILURE)) {
|
||||||
dns_zone_log(zone, ISC_LOG_WARNING,
|
dns_zone_log(zone, ISC_LOG_WARNING,
|
||||||
"getaddrinfo(%s) failed: %s", namebuf,
|
"getaddrinfo(%s) failed: %s", namebuf,
|
||||||
gai_strerror(result));
|
gai_strerror(eai));
|
||||||
add(namebuf, ERR_LOOKUP_FAILURE);
|
add(namebuf, ERR_LOOKUP_FAILURE);
|
||||||
}
|
}
|
||||||
return true;
|
return true;
|
||||||
@@ -574,18 +655,18 @@ load_zone(isc_mem_t *mctx, const char *zonename, const char *filename,
|
|||||||
isc_buffer_constinit(&buffer, zonename, strlen(zonename));
|
isc_buffer_constinit(&buffer, zonename, strlen(zonename));
|
||||||
isc_buffer_add(&buffer, strlen(zonename));
|
isc_buffer_add(&buffer, strlen(zonename));
|
||||||
origin = dns_fixedname_initname(&fixorigin);
|
origin = dns_fixedname_initname(&fixorigin);
|
||||||
CHECK(dns_name_fromtext(origin, &buffer, dns_rootname, 0, NULL));
|
CHECK(dns_name_fromtext(origin, &buffer, dns_rootname, 0));
|
||||||
CHECK(dns_zone_setorigin(zone, origin));
|
dns_zone_setorigin(zone, origin);
|
||||||
dns_zone_setdbtype(zone, 1, (const char *const *)dbtype);
|
dns_zone_setdbtype(zone, 1, (const char *const *)dbtype);
|
||||||
if (strcmp(filename, "-") == 0) {
|
if (strcmp(filename, "-") == 0) {
|
||||||
CHECK(dns_zone_setstream(zone, stdin, fileformat,
|
dns_zone_setstream(zone, stdin, fileformat,
|
||||||
&dns_master_style_default));
|
&dns_master_style_default);
|
||||||
} else {
|
} else {
|
||||||
CHECK(dns_zone_setfile(zone, filename, fileformat,
|
dns_zone_setfile(zone, filename, fileformat,
|
||||||
&dns_master_style_default));
|
&dns_master_style_default);
|
||||||
}
|
}
|
||||||
if (journal != NULL) {
|
if (journal != NULL) {
|
||||||
CHECK(dns_zone_setjournal(zone, journal));
|
dns_zone_setjournal(zone, journal);
|
||||||
}
|
}
|
||||||
|
|
||||||
region.base = UNCONST(classname);
|
region.base = UNCONST(classname);
|
||||||
@@ -603,6 +684,7 @@ load_zone(isc_mem_t *mctx, const char *zonename, const char *filename,
|
|||||||
}
|
}
|
||||||
if (docheckns) {
|
if (docheckns) {
|
||||||
dns_zone_setcheckns(zone, checkns);
|
dns_zone_setcheckns(zone, checkns);
|
||||||
|
dns_zone_setcheckisservedby(zone, checkisservedby);
|
||||||
}
|
}
|
||||||
if (dochecksrv) {
|
if (dochecksrv) {
|
||||||
dns_zone_setchecksrv(zone, checksrv);
|
dns_zone_setchecksrv(zone, checksrv);
|
||||||
|
|||||||
@@ -18,7 +18,6 @@
|
|||||||
#include <inttypes.h>
|
#include <inttypes.h>
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
|
|
||||||
#include <isc/lang.h>
|
|
||||||
#include <isc/stdio.h>
|
#include <isc/stdio.h>
|
||||||
#include <isc/types.h>
|
#include <isc/types.h>
|
||||||
|
|
||||||
@@ -26,8 +25,6 @@
|
|||||||
#include <dns/types.h>
|
#include <dns/types.h>
|
||||||
#include <dns/zone.h>
|
#include <dns/zone.h>
|
||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
setup_logging(FILE *errout);
|
setup_logging(FILE *errout);
|
||||||
|
|
||||||
@@ -48,5 +45,3 @@ extern bool docheckmx;
|
|||||||
extern bool docheckns;
|
extern bool docheckns;
|
||||||
extern bool dochecksrv;
|
extern bool dochecksrv;
|
||||||
extern dns_zoneopt_t zone_options;
|
extern dns_zoneopt_t zone_options;
|
||||||
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
|
|||||||
@@ -22,6 +22,7 @@
|
|||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
@@ -30,6 +31,7 @@
|
|||||||
|
|
||||||
#include <dns/db.h>
|
#include <dns/db.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
|
#include <dns/lib.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/rdataclass.h>
|
#include <dns/rdataclass.h>
|
||||||
#include <dns/rootns.h>
|
#include <dns/rootns.h>
|
||||||
|
|||||||
@@ -22,6 +22,7 @@
|
|||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
@@ -31,6 +32,7 @@
|
|||||||
|
|
||||||
#include <dns/db.h>
|
#include <dns/db.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
|
#include <dns/lib.h>
|
||||||
#include <dns/master.h>
|
#include <dns/master.h>
|
||||||
#include <dns/masterdump.h>
|
#include <dns/masterdump.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
|
|||||||
@@ -91,9 +91,13 @@ Options
|
|||||||
(both in-zone and out-of-zone hostnames). Mode ``local`` only
|
(both in-zone and out-of-zone hostnames). Mode ``local`` only
|
||||||
checks SRV records which refer to in-zone hostnames.
|
checks SRV records which refer to in-zone hostnames.
|
||||||
|
|
||||||
|
Mode ``full`` checks that a zone that has A or AAAA records it is served
|
||||||
|
by a server with the same type of address records.
|
||||||
|
|
||||||
Mode ``full`` checks that delegation NS records refer to A or AAAA
|
Mode ``full`` checks that delegation NS records refer to A or AAAA
|
||||||
records (both in-zone and out-of-zone hostnames). It also checks that
|
records (both in-zone and out-of-zone hostnames). It also checks that
|
||||||
glue address records in the zone match those advertised by the child.
|
glue address records in the zone match those advertised by the child.
|
||||||
|
|
||||||
Mode ``local`` only checks NS records which refer to in-zone
|
Mode ``local`` only checks NS records which refer to in-zone
|
||||||
hostnames or verifies that some required glue exists, i.e., when the
|
hostnames or verifies that some required glue exists, i.e., when the
|
||||||
name server is in a child zone.
|
name server is in a child zone.
|
||||||
|
|||||||
@@ -17,10 +17,6 @@
|
|||||||
|
|
||||||
#include <stdio.h>
|
#include <stdio.h>
|
||||||
|
|
||||||
#include <isc/lang.h>
|
|
||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
|
||||||
|
|
||||||
int
|
int
|
||||||
set_user(FILE *fd, const char *user);
|
set_user(FILE *fd, const char *user);
|
||||||
/*%<
|
/*%<
|
||||||
@@ -29,5 +25,3 @@ set_user(FILE *fd, const char *user);
|
|||||||
* 0 success
|
* 0 success
|
||||||
* -1 insufficient permissions, or 'user' does not exist.
|
* -1 insufficient permissions, or 'user' does not exist.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
|
|||||||
@@ -16,13 +16,10 @@
|
|||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/lang.h>
|
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
|
|
||||||
#include <dns/secalg.h>
|
#include <dns/secalg.h>
|
||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
|
||||||
|
|
||||||
void
|
void
|
||||||
generate_key(isc_mem_t *mctx, dns_secalg_t alg, int keysize,
|
generate_key(isc_mem_t *mctx, dns_secalg_t alg, int keysize,
|
||||||
isc_buffer_t *key_txtbuffer);
|
isc_buffer_t *key_txtbuffer);
|
||||||
@@ -37,5 +34,3 @@ dns_secalg_t
|
|||||||
alg_fromtext(const char *name);
|
alg_fromtext(const char *name);
|
||||||
int
|
int
|
||||||
alg_bits(dns_secalg_t alg);
|
alg_bits(dns_secalg_t alg);
|
||||||
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
|
|||||||
@@ -32,6 +32,7 @@
|
|||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/net.h>
|
#include <isc/net.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
@@ -40,6 +41,7 @@
|
|||||||
#include <isc/util.h>
|
#include <isc/util.h>
|
||||||
|
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
|
#include <dns/lib.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
|
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
|
|||||||
@@ -28,6 +28,7 @@
|
|||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/net.h>
|
#include <isc/net.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
@@ -36,6 +37,7 @@
|
|||||||
#include <isc/util.h>
|
#include <isc/util.h>
|
||||||
|
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
|
#include <dns/lib.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
|
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
|
|||||||
@@ -17,7 +17,6 @@
|
|||||||
|
|
||||||
#include <isc/attributes.h>
|
#include <isc/attributes.h>
|
||||||
#include <isc/formatcheck.h>
|
#include <isc/formatcheck.h>
|
||||||
#include <isc/lang.h>
|
|
||||||
|
|
||||||
#define NS_CONTROL_PORT 953
|
#define NS_CONTROL_PORT 953
|
||||||
|
|
||||||
@@ -31,12 +30,8 @@
|
|||||||
notify("%s", name); \
|
notify("%s", name); \
|
||||||
} while (0)
|
} while (0)
|
||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
|
||||||
|
|
||||||
void
|
void
|
||||||
notify(const char *fmt, ...) ISC_FORMAT_PRINTF(1, 2);
|
notify(const char *fmt, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||||
|
|
||||||
ISC_NORETURN void
|
ISC_NORETURN void
|
||||||
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||||
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
|
|||||||
+14
-20
@@ -37,6 +37,7 @@
|
|||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/fips.h>
|
#include <isc/fips.h>
|
||||||
#include <isc/hex.h>
|
#include <isc/hex.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/managers.h>
|
#include <isc/managers.h>
|
||||||
#include <isc/md.h>
|
#include <isc/md.h>
|
||||||
@@ -59,6 +60,7 @@
|
|||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/keytable.h>
|
#include <dns/keytable.h>
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
|
#include <dns/lib.h>
|
||||||
#include <dns/masterdump.h>
|
#include <dns/masterdump.h>
|
||||||
#include <dns/message.h>
|
#include <dns/message.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
@@ -228,7 +230,6 @@ usage(void) {
|
|||||||
" +[no]crypto (Control display of "
|
" +[no]crypto (Control display of "
|
||||||
"cryptographic\n"
|
"cryptographic\n"
|
||||||
" fields in records)\n"
|
" fields in records)\n"
|
||||||
" +[no]dlv (Obsolete)\n"
|
|
||||||
" +[no]dnssec (Display DNSSEC "
|
" +[no]dnssec (Display DNSSEC "
|
||||||
"records)\n"
|
"records)\n"
|
||||||
" +[no]mtrace (Trace messages "
|
" +[no]mtrace (Trace messages "
|
||||||
@@ -596,7 +597,7 @@ convert_name(dns_fixedname_t *fn, dns_name_t **name, const char *text) {
|
|||||||
isc_buffer_add(&b, len);
|
isc_buffer_add(&b, len);
|
||||||
n = dns_fixedname_initname(fn);
|
n = dns_fixedname_initname(fn);
|
||||||
|
|
||||||
result = dns_name_fromtext(n, &b, dns_rootname, 0, NULL);
|
result = dns_name_fromtext(n, &b, dns_rootname, 0);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
delv_log(ISC_LOG_ERROR, "failed to convert name %s: %s", text,
|
delv_log(ISC_LOG_ERROR, "failed to convert name %s: %s", text,
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
@@ -788,9 +789,7 @@ key_fromconfig(const cfg_obj_t *key, dns_client_t *client, dns_view_t *toview) {
|
|||||||
num_keys++;
|
num_keys++;
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
if (result == DST_R_NOCRYPTO) {
|
if (result == DST_R_UNSUPPORTEDALG) {
|
||||||
cfg_obj_log(key, ISC_LOG_ERROR, "no crypto support");
|
|
||||||
} else if (result == DST_R_UNSUPPORTEDALG) {
|
|
||||||
cfg_obj_log(key, ISC_LOG_WARNING,
|
cfg_obj_log(key, ISC_LOG_WARNING,
|
||||||
"skipping trusted key '%s': %s", keynamestr,
|
"skipping trusted key '%s': %s", keynamestr,
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
@@ -824,9 +823,6 @@ load_keys(const cfg_obj_t *keys, dns_client_t *client, dns_view_t *toview) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
if (result == DST_R_NOCRYPTO) {
|
|
||||||
result = ISC_R_SUCCESS;
|
|
||||||
}
|
|
||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1125,14 +1121,6 @@ plus_option(char *option) {
|
|||||||
break;
|
break;
|
||||||
case 'd':
|
case 'd':
|
||||||
switch (cmd[1]) {
|
switch (cmd[1]) {
|
||||||
case 'l': /* dlv */
|
|
||||||
FULLCHECK("dlv");
|
|
||||||
if (state) {
|
|
||||||
fprintf(stderr, "Invalid option: "
|
|
||||||
"+dlv is obsolete\n");
|
|
||||||
exit(EXIT_FAILURE);
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
case 'n': /* dnssec */
|
case 'n': /* dnssec */
|
||||||
FULLCHECK("dnssec");
|
FULLCHECK("dnssec");
|
||||||
showdnssec = state;
|
showdnssec = state;
|
||||||
@@ -2151,9 +2139,15 @@ sendquery(void *arg) {
|
|||||||
&requestmgr));
|
&requestmgr));
|
||||||
|
|
||||||
dns_view_attach(view, &(dns_view_t *){ NULL });
|
dns_view_attach(view, &(dns_view_t *){ NULL });
|
||||||
|
|
||||||
|
uint32_t initial;
|
||||||
|
isc_nm_gettimeouts(netmgr, &initial, NULL, NULL, NULL);
|
||||||
|
const unsigned int connect_timeout = initial, timeout = initial;
|
||||||
|
|
||||||
CHECK(dns_request_create(requestmgr, message, NULL, &peer, NULL, NULL,
|
CHECK(dns_request_create(requestmgr, message, NULL, &peer, NULL, NULL,
|
||||||
DNS_REQUESTOPT_TCP, NULL, 1, 0, 0, isc_loop(),
|
DNS_REQUESTOPT_TCP, NULL, connect_timeout,
|
||||||
recvresponse, message, &request));
|
timeout, 0, 0, isc_loop(), recvresponse,
|
||||||
|
message, &request));
|
||||||
return;
|
return;
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
@@ -2205,8 +2199,8 @@ run_server(void *arg) {
|
|||||||
CHECK(ns_interfacemgr_create(mctx, sctx, loopmgr, netmgr, dispatchmgr,
|
CHECK(ns_interfacemgr_create(mctx, sctx, loopmgr, netmgr, dispatchmgr,
|
||||||
NULL, &interfacemgr));
|
NULL, &interfacemgr));
|
||||||
|
|
||||||
CHECK(dns_view_create(mctx, loopmgr, dispatchmgr, dns_rdataclass_in,
|
dns_view_create(mctx, loopmgr, dispatchmgr, dns_rdataclass_in,
|
||||||
"_default", &view));
|
"_default", &view);
|
||||||
CHECK(dns_cache_create(loopmgr, dns_rdataclass_in, "", mctx, &cache));
|
CHECK(dns_cache_create(loopmgr, dns_rdataclass_in, "", mctx, &cache));
|
||||||
dns_view_setcache(view, cache, false);
|
dns_view_setcache(view, cache, false);
|
||||||
dns_cache_detach(&cache);
|
dns_cache_detach(&cache);
|
||||||
|
|||||||
+16
-4
@@ -22,6 +22,7 @@
|
|||||||
#include <isc/attributes.h>
|
#include <isc/attributes.h>
|
||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
#include <isc/fips.h>
|
#include <isc/fips.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/loop.h>
|
#include <isc/loop.h>
|
||||||
#include <isc/netaddr.h>
|
#include <isc/netaddr.h>
|
||||||
#include <isc/parseint.h>
|
#include <isc/parseint.h>
|
||||||
@@ -33,6 +34,7 @@
|
|||||||
#include <dns/byaddr.h>
|
#include <dns/byaddr.h>
|
||||||
#include <dns/dns64.h>
|
#include <dns/dns64.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
|
#include <dns/lib.h>
|
||||||
#include <dns/masterdump.h>
|
#include <dns/masterdump.h>
|
||||||
#include <dns/message.h>
|
#include <dns/message.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
@@ -303,6 +305,8 @@ help(void) {
|
|||||||
"statistics)\n"
|
"statistics)\n"
|
||||||
" +subnet=addr (Set edns-client-subnet "
|
" +subnet=addr (Set edns-client-subnet "
|
||||||
"option)\n"
|
"option)\n"
|
||||||
|
" +[no]svcparamkeycompat (Display backward-"
|
||||||
|
"compatible SvcParamKey names (keyN) for non-initial entries)\n"
|
||||||
" +[no]tcflag (Set TC flag in query "
|
" +[no]tcflag (Set TC flag in query "
|
||||||
"(+[no]tcflag))\n"
|
"(+[no]tcflag))\n"
|
||||||
" +[no]tcp (TCP mode (+[no]vc))\n"
|
" +[no]tcp (TCP mode (+[no]vc))\n"
|
||||||
@@ -502,6 +506,9 @@ say_message(dns_rdata_t *rdata, dig_query_t *query, isc_buffer_t *buf) {
|
|||||||
if (query->lookup->expandaaaa) {
|
if (query->lookup->expandaaaa) {
|
||||||
styleflags |= DNS_STYLEFLAG_EXPANDAAAA;
|
styleflags |= DNS_STYLEFLAG_EXPANDAAAA;
|
||||||
}
|
}
|
||||||
|
if (query->lookup->svcparamkeycompat) {
|
||||||
|
styleflags |= DNS_STYLEFLAG_SVCPARAMKEYCOMPAT;
|
||||||
|
}
|
||||||
result = dns_rdata_tofmttext(rdata, NULL, styleflags, 0, splitwidth,
|
result = dns_rdata_tofmttext(rdata, NULL, styleflags, 0, splitwidth,
|
||||||
" ", buf);
|
" ", buf);
|
||||||
if (result == ISC_R_NOSPACE) {
|
if (result == ISC_R_NOSPACE) {
|
||||||
@@ -586,7 +593,7 @@ short_answer(dns_message_t *msg, dns_messagetextflag_t flags, isc_buffer_t *buf,
|
|||||||
|
|
||||||
UNUSED(flags);
|
UNUSED(flags);
|
||||||
|
|
||||||
dns_name_init(&empty_name, NULL);
|
dns_name_init(&empty_name);
|
||||||
result = dns_message_firstname(msg, DNS_SECTION_ANSWER);
|
result = dns_message_firstname(msg, DNS_SECTION_ANSWER);
|
||||||
if (result == ISC_R_NOMORE) {
|
if (result == ISC_R_NOMORE) {
|
||||||
return ISC_R_SUCCESS;
|
return ISC_R_SUCCESS;
|
||||||
@@ -628,9 +635,7 @@ static bool
|
|||||||
isdotlocal(dns_message_t *msg) {
|
isdotlocal(dns_message_t *msg) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
static unsigned char local_ndata[] = { "\005local" };
|
static unsigned char local_ndata[] = { "\005local" };
|
||||||
static unsigned char local_offsets[] = { 0, 6 };
|
static dns_name_t local = DNS_NAME_INITABSOLUTE(local_ndata);
|
||||||
static dns_name_t local = DNS_NAME_INITABSOLUTE(local_ndata,
|
|
||||||
local_offsets);
|
|
||||||
|
|
||||||
for (result = dns_message_firstname(msg, DNS_SECTION_QUESTION);
|
for (result = dns_message_firstname(msg, DNS_SECTION_QUESTION);
|
||||||
result == ISC_R_SUCCESS;
|
result == ISC_R_SUCCESS;
|
||||||
@@ -695,6 +700,9 @@ printmessage(dig_query_t *query, const isc_buffer_t *msgbuf, dns_message_t *msg,
|
|||||||
if (query->lookup->expandaaaa) {
|
if (query->lookup->expandaaaa) {
|
||||||
styleflags |= DNS_STYLEFLAG_EXPANDAAAA;
|
styleflags |= DNS_STYLEFLAG_EXPANDAAAA;
|
||||||
}
|
}
|
||||||
|
if (query->lookup->svcparamkeycompat) {
|
||||||
|
styleflags |= DNS_STYLEFLAG_SVCPARAMKEYCOMPAT;
|
||||||
|
}
|
||||||
if (query->lookup->multiline) {
|
if (query->lookup->multiline) {
|
||||||
styleflags |= DNS_STYLEFLAG_OMIT_OWNER;
|
styleflags |= DNS_STYLEFLAG_OMIT_OWNER;
|
||||||
styleflags |= DNS_STYLEFLAG_OMIT_CLASS;
|
styleflags |= DNS_STYLEFLAG_OMIT_CLASS;
|
||||||
@@ -2394,6 +2402,10 @@ plus_option(char *option, bool is_batchfile, bool *need_clone,
|
|||||||
goto exit_or_usage;
|
goto exit_or_usage;
|
||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
|
case 'v': /* svcparamkeycompat */
|
||||||
|
FULLCHECK("svcparamkeycompat");
|
||||||
|
lookup->svcparamkeycompat = state;
|
||||||
|
break;
|
||||||
default:
|
default:
|
||||||
goto invalid_option;
|
goto invalid_option;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -642,6 +642,14 @@ abbreviation is unambiguous; for example, :option:`+cd` is equivalent to
|
|||||||
prefix-length of zero, which signals a resolver that the client's
|
prefix-length of zero, which signals a resolver that the client's
|
||||||
address information must *not* be used when resolving this query.
|
address information must *not* be used when resolving this query.
|
||||||
|
|
||||||
|
.. option:: +svcparamkeycompat, +nosvcparamkeycompat
|
||||||
|
|
||||||
|
This option sets [or does not set] the backward-compatible representation of
|
||||||
|
the Service Parameter Keys (SvcParamKeys) for SVCB records, in which case
|
||||||
|
the keys, which were not defined initially in :rfc:`9460` are represented
|
||||||
|
in their opaque "keyN"-like format, where "N" is their numerical value. The
|
||||||
|
default is ``+nosvcparamkeycompat``.
|
||||||
|
|
||||||
.. option:: +tcflag, +notcflag
|
.. option:: +tcflag, +notcflag
|
||||||
|
|
||||||
This option sets [or does not set] the TC (TrunCation) bit in the query. The default is
|
This option sets [or does not set] the TC (TrunCation) bit in the query. The default is
|
||||||
|
|||||||
+25
-27
@@ -40,7 +40,6 @@
|
|||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/getaddresses.h>
|
#include <isc/getaddresses.h>
|
||||||
#include <isc/hex.h>
|
#include <isc/hex.h>
|
||||||
#include <isc/lang.h>
|
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/loop.h>
|
#include <isc/loop.h>
|
||||||
#include <isc/managers.h>
|
#include <isc/managers.h>
|
||||||
@@ -61,6 +60,7 @@
|
|||||||
#include <isc/xml.h>
|
#include <isc/xml.h>
|
||||||
|
|
||||||
#include <dns/byaddr.h>
|
#include <dns/byaddr.h>
|
||||||
|
#include <dns/ede.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/message.h>
|
#include <dns/message.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
@@ -758,6 +758,7 @@ clone_lookup(dig_lookup_t *lookold, bool servers) {
|
|||||||
looknew->nocrypto = lookold->nocrypto;
|
looknew->nocrypto = lookold->nocrypto;
|
||||||
looknew->ttlunits = lookold->ttlunits;
|
looknew->ttlunits = lookold->ttlunits;
|
||||||
looknew->expandaaaa = lookold->expandaaaa;
|
looknew->expandaaaa = lookold->expandaaaa;
|
||||||
|
looknew->svcparamkeycompat = lookold->svcparamkeycompat;
|
||||||
looknew->qr = lookold->qr;
|
looknew->qr = lookold->qr;
|
||||||
looknew->idnin = lookold->idnin;
|
looknew->idnin = lookold->idnin;
|
||||||
looknew->idnout = lookold->idnout;
|
looknew->idnout = lookold->idnout;
|
||||||
@@ -857,14 +858,14 @@ requeue_lookup(dig_lookup_t *lookold, bool servers) {
|
|||||||
void
|
void
|
||||||
setup_text_key(void) {
|
setup_text_key(void) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
dns_name_t keyname;
|
dns_fixedname_t fkey;
|
||||||
|
dns_name_t *keyname = dns_fixedname_initname(&fkey);
|
||||||
isc_buffer_t secretbuf;
|
isc_buffer_t secretbuf;
|
||||||
unsigned int secretsize;
|
unsigned int secretsize;
|
||||||
unsigned char *secretstore;
|
unsigned char *secretstore;
|
||||||
|
|
||||||
debug("setup_text_key()");
|
debug("setup_text_key()");
|
||||||
isc_buffer_allocate(mctx, &namebuf, MXNAME);
|
isc_buffer_allocate(mctx, &namebuf, MXNAME);
|
||||||
dns_name_init(&keyname, NULL);
|
|
||||||
isc_buffer_putstr(namebuf, keynametext);
|
isc_buffer_putstr(namebuf, keynametext);
|
||||||
secretsize = (unsigned int)strlen(keysecret) * 3 / 4;
|
secretsize = (unsigned int)strlen(keysecret) * 3 / 4;
|
||||||
secretstore = isc_mem_allocate(mctx, secretsize);
|
secretstore = isc_mem_allocate(mctx, secretsize);
|
||||||
@@ -881,12 +882,12 @@ setup_text_key(void) {
|
|||||||
goto failure;
|
goto failure;
|
||||||
}
|
}
|
||||||
|
|
||||||
result = dns_name_fromtext(&keyname, namebuf, dns_rootname, 0, namebuf);
|
result = dns_name_fromtext(keyname, namebuf, dns_rootname, 0);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
goto failure;
|
goto failure;
|
||||||
}
|
}
|
||||||
|
|
||||||
result = dns_tsigkey_create(&keyname, hmac_alg, secretstore,
|
result = dns_tsigkey_create(keyname, hmac_alg, secretstore,
|
||||||
(int)secretsize, mctx, &tsigkey);
|
(int)secretsize, mctx, &tsigkey);
|
||||||
failure:
|
failure:
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
@@ -897,7 +898,6 @@ failure:
|
|||||||
}
|
}
|
||||||
|
|
||||||
isc_mem_free(mctx, secretstore);
|
isc_mem_free(mctx, secretstore);
|
||||||
dns_name_invalidate(&keyname);
|
|
||||||
isc_buffer_free(&namebuf);
|
isc_buffer_free(&namebuf);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -2081,8 +2081,8 @@ insert_soa(dig_lookup_t *lookup) {
|
|||||||
soa.common.rdclass = lookup->rdclass;
|
soa.common.rdclass = lookup->rdclass;
|
||||||
soa.common.rdtype = dns_rdatatype_soa;
|
soa.common.rdtype = dns_rdatatype_soa;
|
||||||
|
|
||||||
dns_name_init(&soa.origin, NULL);
|
dns_name_init(&soa.origin);
|
||||||
dns_name_init(&soa.contact, NULL);
|
dns_name_init(&soa.contact);
|
||||||
|
|
||||||
dns_name_clone(dns_rootname, &soa.origin);
|
dns_name_clone(dns_rootname, &soa.origin);
|
||||||
dns_name_clone(dns_rootname, &soa.contact);
|
dns_name_clone(dns_rootname, &soa.contact);
|
||||||
@@ -2205,11 +2205,6 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
}
|
}
|
||||||
dns_message_gettempname(lookup->sendmsg, &lookup->name);
|
dns_message_gettempname(lookup->sendmsg, &lookup->name);
|
||||||
|
|
||||||
isc_buffer_init(&lookup->namebuf, lookup->name_space,
|
|
||||||
sizeof(lookup->name_space));
|
|
||||||
isc_buffer_init(&lookup->onamebuf, lookup->oname_space,
|
|
||||||
sizeof(lookup->oname_space));
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* We cannot convert `textname' and `origin' separately.
|
* We cannot convert `textname' and `origin' separately.
|
||||||
* `textname' doesn't contain TLD, but local mapping needs
|
* `textname' doesn't contain TLD, but local mapping needs
|
||||||
@@ -2257,8 +2252,7 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
len = (unsigned int)strlen(origin);
|
len = (unsigned int)strlen(origin);
|
||||||
isc_buffer_init(&b, origin, len);
|
isc_buffer_init(&b, origin, len);
|
||||||
isc_buffer_add(&b, len);
|
isc_buffer_add(&b, len);
|
||||||
result = dns_name_fromtext(lookup->oname, &b, dns_rootname, 0,
|
result = dns_name_fromtext(lookup->oname, &b, dns_rootname, 0);
|
||||||
&lookup->onamebuf);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
dns_message_puttempname(lookup->sendmsg, &lookup->name);
|
dns_message_puttempname(lookup->sendmsg, &lookup->name);
|
||||||
dns_message_puttempname(lookup->sendmsg,
|
dns_message_puttempname(lookup->sendmsg,
|
||||||
@@ -2276,12 +2270,12 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
len = (unsigned int)strlen(textname);
|
len = (unsigned int)strlen(textname);
|
||||||
isc_buffer_init(&b, textname, len);
|
isc_buffer_init(&b, textname, len);
|
||||||
isc_buffer_add(&b, len);
|
isc_buffer_add(&b, len);
|
||||||
result = dns_name_fromtext(name, &b, NULL, 0, NULL);
|
result = dns_name_fromtext(name, &b, NULL, 0);
|
||||||
if (result == ISC_R_SUCCESS) {
|
if (result == ISC_R_SUCCESS) {
|
||||||
if (!dns_name_isabsolute(name)) {
|
if (!dns_name_isabsolute(name)) {
|
||||||
result = dns_name_concatenate(
|
result = dns_name_concatenate(
|
||||||
name, lookup->oname,
|
name, lookup->oname,
|
||||||
lookup->name, &lookup->namebuf);
|
lookup->name);
|
||||||
} else {
|
} else {
|
||||||
dns_name_copy(name, lookup->name);
|
dns_name_copy(name, lookup->name);
|
||||||
}
|
}
|
||||||
@@ -2309,8 +2303,7 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
isc_buffer_init(&b, textname, len);
|
isc_buffer_init(&b, textname, len);
|
||||||
isc_buffer_add(&b, len);
|
isc_buffer_add(&b, len);
|
||||||
result = dns_name_fromtext(lookup->name, &b,
|
result = dns_name_fromtext(lookup->name, &b,
|
||||||
dns_rootname, 0,
|
dns_rootname, 0);
|
||||||
&lookup->namebuf);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
dns_message_puttempname(lookup->sendmsg,
|
dns_message_puttempname(lookup->sendmsg,
|
||||||
&lookup->name);
|
&lookup->name);
|
||||||
@@ -2779,6 +2772,12 @@ _cancel_lookup(dig_lookup_t *lookup, const char *file, unsigned int line) {
|
|||||||
check_if_done();
|
check_if_done();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
static inline const char *
|
||||||
|
get_tls_sni_hostname(dig_query_t *query) {
|
||||||
|
return query->lookup->tls_hostname_set ? query->lookup->tls_hostname
|
||||||
|
: query->userarg;
|
||||||
|
}
|
||||||
|
|
||||||
static isc_tlsctx_t *
|
static isc_tlsctx_t *
|
||||||
get_create_tls_context(dig_query_t *query, const bool is_https,
|
get_create_tls_context(dig_query_t *query, const bool is_https,
|
||||||
isc_tlsctx_client_session_cache_t **psess_cache) {
|
isc_tlsctx_client_session_cache_t **psess_cache) {
|
||||||
@@ -2825,10 +2824,7 @@ get_create_tls_context(dig_query_t *query, const bool is_https,
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (store != NULL) {
|
if (store != NULL) {
|
||||||
const char *hostname =
|
const char *hostname = get_tls_sni_hostname(query);
|
||||||
query->lookup->tls_hostname_set
|
|
||||||
? query->lookup->tls_hostname
|
|
||||||
: query->userarg;
|
|
||||||
/*
|
/*
|
||||||
* According to RFC 8310, Subject field MUST NOT be
|
* According to RFC 8310, Subject field MUST NOT be
|
||||||
* inspected when verifying hostname for DoT. Only
|
* inspected when verifying hostname for DoT. Only
|
||||||
@@ -3042,7 +3038,8 @@ start_tcp(dig_query_t *query) {
|
|||||||
}
|
}
|
||||||
isc_nm_streamdnsconnect(netmgr, &localaddr, &query->sockaddr,
|
isc_nm_streamdnsconnect(netmgr, &localaddr, &query->sockaddr,
|
||||||
tcp_connected, connectquery,
|
tcp_connected, connectquery,
|
||||||
local_timeout, tlsctx, sess_cache,
|
local_timeout, tlsctx,
|
||||||
|
get_tls_sni_hostname(query), sess_cache,
|
||||||
proxy_type, ppi);
|
proxy_type, ppi);
|
||||||
#if HAVE_LIBNGHTTP2
|
#if HAVE_LIBNGHTTP2
|
||||||
} else if (query->lookup->https_mode) {
|
} else if (query->lookup->https_mode) {
|
||||||
@@ -3062,14 +3059,15 @@ start_tcp(dig_query_t *query) {
|
|||||||
|
|
||||||
isc_nm_httpconnect(netmgr, &localaddr, &query->sockaddr, uri,
|
isc_nm_httpconnect(netmgr, &localaddr, &query->sockaddr, uri,
|
||||||
!query->lookup->https_get, tcp_connected,
|
!query->lookup->https_get, tcp_connected,
|
||||||
connectquery, tlsctx, sess_cache,
|
connectquery, tlsctx,
|
||||||
|
get_tls_sni_hostname(query), sess_cache,
|
||||||
local_timeout, proxy_type, ppi);
|
local_timeout, proxy_type, ppi);
|
||||||
#endif
|
#endif
|
||||||
} else {
|
} else {
|
||||||
isc_nm_streamdnsconnect(netmgr, &localaddr, &query->sockaddr,
|
isc_nm_streamdnsconnect(netmgr, &localaddr, &query->sockaddr,
|
||||||
tcp_connected, connectquery,
|
tcp_connected, connectquery,
|
||||||
local_timeout, NULL, NULL, proxy_type,
|
local_timeout, NULL, NULL, NULL,
|
||||||
ppi);
|
proxy_type, ppi);
|
||||||
}
|
}
|
||||||
|
|
||||||
return;
|
return;
|
||||||
|
|||||||
+2
-10
@@ -21,7 +21,6 @@
|
|||||||
#include <isc/attributes.h>
|
#include <isc/attributes.h>
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/formatcheck.h>
|
#include <isc/formatcheck.h>
|
||||||
#include <isc/lang.h>
|
|
||||||
#include <isc/list.h>
|
#include <isc/list.h>
|
||||||
#include <isc/loop.h>
|
#include <isc/loop.h>
|
||||||
#include <isc/magic.h>
|
#include <isc/magic.h>
|
||||||
@@ -85,8 +84,6 @@
|
|||||||
* in a tight loop of constant lookups. It's value is arbitrary.
|
* in a tight loop of constant lookups. It's value is arbitrary.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
|
||||||
|
|
||||||
typedef struct dig_lookup dig_lookup_t;
|
typedef struct dig_lookup dig_lookup_t;
|
||||||
typedef struct dig_query dig_query_t;
|
typedef struct dig_query dig_query_t;
|
||||||
typedef struct dig_server dig_server_t;
|
typedef struct dig_server dig_server_t;
|
||||||
@@ -107,9 +104,8 @@ struct dig_lookup {
|
|||||||
isc_refcount_t references;
|
isc_refcount_t references;
|
||||||
bool aaonly, adflag, badcookie, besteffort, cdflag, cleared, comments,
|
bool aaonly, adflag, badcookie, besteffort, cdflag, cleared, comments,
|
||||||
dns64prefix, dnssec, doing_xfr, done_as_is, ednsneg, expandaaaa,
|
dns64prefix, dnssec, doing_xfr, done_as_is, ednsneg, expandaaaa,
|
||||||
expire, fuzzing, header_only, identify, /*%< Append an "on
|
svcparamkeycompat, expire, fuzzing, header_only,
|
||||||
server <foo>" message
|
identify, /*%< Append an "on server <foo>" message */
|
||||||
*/
|
|
||||||
identify_previous_line, /*% Prepend a "Nameserver <foo>:"
|
identify_previous_line, /*% Prepend a "Nameserver <foo>:"
|
||||||
message, with newline and tab */
|
message, with newline and tab */
|
||||||
idnin, idnout, ignore, multiline, need_search, new_search,
|
idnin, idnout, ignore, multiline, need_search, new_search,
|
||||||
@@ -135,8 +131,6 @@ struct dig_lookup {
|
|||||||
bool rdclassset;
|
bool rdclassset;
|
||||||
char name_space[BUFSIZE];
|
char name_space[BUFSIZE];
|
||||||
char oname_space[BUFSIZE];
|
char oname_space[BUFSIZE];
|
||||||
isc_buffer_t namebuf;
|
|
||||||
isc_buffer_t onamebuf;
|
|
||||||
isc_buffer_t renderbuf;
|
isc_buffer_t renderbuf;
|
||||||
char *sendspace;
|
char *sendspace;
|
||||||
dns_name_t *name;
|
dns_name_t *name;
|
||||||
@@ -466,5 +460,3 @@ dig_shutdown(void);
|
|||||||
|
|
||||||
bool
|
bool
|
||||||
dig_lookup_is_tls(const dig_lookup_t *lookup);
|
dig_lookup_is_tls(const dig_lookup_t *lookup);
|
||||||
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
|
|||||||
+14
-1
@@ -21,6 +21,7 @@
|
|||||||
|
|
||||||
#include <isc/attributes.h>
|
#include <isc/attributes.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/loop.h>
|
#include <isc/loop.h>
|
||||||
#include <isc/netaddr.h>
|
#include <isc/netaddr.h>
|
||||||
#include <isc/string.h>
|
#include <isc/string.h>
|
||||||
@@ -28,6 +29,7 @@
|
|||||||
|
|
||||||
#include <dns/byaddr.h>
|
#include <dns/byaddr.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
|
#include <dns/lib.h>
|
||||||
#include <dns/message.h>
|
#include <dns/message.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/rdata.h>
|
#include <dns/rdata.h>
|
||||||
@@ -80,6 +82,7 @@ struct rtype rtypes[] = { { 1, "has address" },
|
|||||||
{ 25, "has key" },
|
{ 25, "has key" },
|
||||||
{ 28, "has IPv6 address" },
|
{ 28, "has IPv6 address" },
|
||||||
{ 29, "location" },
|
{ 29, "location" },
|
||||||
|
{ dns_rdatatype_https, "has HTTP service bindings" },
|
||||||
{ 0, NULL } };
|
{ 0, NULL } };
|
||||||
|
|
||||||
static char *
|
static char *
|
||||||
@@ -218,7 +221,7 @@ printsection(dns_message_t *msg, dns_section_t sectionid,
|
|||||||
printf(";; %s SECTION:\n", section_name);
|
printf(";; %s SECTION:\n", section_name);
|
||||||
}
|
}
|
||||||
|
|
||||||
dns_name_init(&empty_name, NULL);
|
dns_name_init(&empty_name);
|
||||||
|
|
||||||
result = dns_message_firstname(msg, sectionid);
|
result = dns_message_firstname(msg, sectionid);
|
||||||
if (result == ISC_R_NOMORE) {
|
if (result == ISC_R_NOMORE) {
|
||||||
@@ -457,6 +460,16 @@ printmessage(dig_query_t *query, const isc_buffer_t *msgbuf, dns_message_t *msg,
|
|||||||
lookup->retries = tries;
|
lookup->retries = tries;
|
||||||
ISC_LIST_APPEND(lookup_list, lookup, link);
|
ISC_LIST_APPEND(lookup_list, lookup, link);
|
||||||
}
|
}
|
||||||
|
lookup = clone_lookup(query->lookup, false);
|
||||||
|
if (lookup != NULL) {
|
||||||
|
strlcpy(lookup->textname, namestr,
|
||||||
|
sizeof(lookup->textname));
|
||||||
|
lookup->rdtype = dns_rdatatype_https;
|
||||||
|
lookup->rdtypeset = true;
|
||||||
|
lookup->origin = NULL;
|
||||||
|
lookup->retries = tries;
|
||||||
|
ISC_LIST_APPEND(lookup_list, lookup, link);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!short_form) {
|
if (!short_form) {
|
||||||
|
|||||||
+1
-1
@@ -122,7 +122,7 @@ Options
|
|||||||
CNAME, NS, SOA, TXT, DNSKEY, AXFR, etc.
|
CNAME, NS, SOA, TXT, DNSKEY, AXFR, etc.
|
||||||
|
|
||||||
When no query type is specified, :program:`host` automatically selects an
|
When no query type is specified, :program:`host` automatically selects an
|
||||||
appropriate query type. By default, it looks for A, AAAA, and MX
|
appropriate query type. By default, it looks for A, AAAA, MX, and HTTPS
|
||||||
records. If the :option:`-C` option is given, queries are made for SOA
|
records. If the :option:`-C` option is given, queries are made for SOA
|
||||||
records. If ``name`` is a dotted-decimal IPv4 address or
|
records. If ``name`` is a dotted-decimal IPv4 address or
|
||||||
colon-delimited IPv6 address, :program:`host` queries for PTR records.
|
colon-delimited IPv6 address, :program:`host` queries for PTR records.
|
||||||
|
|||||||
@@ -21,6 +21,7 @@
|
|||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/condition.h>
|
#include <isc/condition.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/loop.h>
|
#include <isc/loop.h>
|
||||||
#include <isc/netaddr.h>
|
#include <isc/netaddr.h>
|
||||||
#include <isc/parseint.h>
|
#include <isc/parseint.h>
|
||||||
@@ -30,6 +31,7 @@
|
|||||||
|
|
||||||
#include <dns/byaddr.h>
|
#include <dns/byaddr.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
|
#include <dns/lib.h>
|
||||||
#include <dns/message.h>
|
#include <dns/message.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/rdata.h>
|
#include <dns/rdata.h>
|
||||||
|
|||||||
@@ -29,6 +29,7 @@
|
|||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
@@ -44,6 +45,7 @@
|
|||||||
#include <dns/ds.h>
|
#include <dns/ds.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
|
#include <dns/lib.h>
|
||||||
#include <dns/master.h>
|
#include <dns/master.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/rdata.h>
|
#include <dns/rdata.h>
|
||||||
@@ -176,7 +178,7 @@ initname(char *setname) {
|
|||||||
|
|
||||||
isc_buffer_init(&buf, setname, strlen(setname));
|
isc_buffer_init(&buf, setname, strlen(setname));
|
||||||
isc_buffer_add(&buf, strlen(setname));
|
isc_buffer_add(&buf, strlen(setname));
|
||||||
result = dns_name_fromtext(name, &buf, dns_rootname, 0, NULL);
|
result = dns_name_fromtext(name, &buf, dns_rootname, 0);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("could not initialize name %s", setname);
|
fatal("could not initialize name %s", setname);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -22,6 +22,7 @@
|
|||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
@@ -34,6 +35,7 @@
|
|||||||
#include <dns/ds.h>
|
#include <dns/ds.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
|
#include <dns/lib.h>
|
||||||
#include <dns/master.h>
|
#include <dns/master.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/rdata.h>
|
#include <dns/rdata.h>
|
||||||
@@ -65,7 +67,7 @@ initname(char *setname) {
|
|||||||
|
|
||||||
isc_buffer_init(&buf, setname, strlen(setname));
|
isc_buffer_init(&buf, setname, strlen(setname));
|
||||||
isc_buffer_add(&buf, strlen(setname));
|
isc_buffer_add(&buf, strlen(setname));
|
||||||
result = dns_name_fromtext(name, &buf, dns_rootname, 0, NULL);
|
result = dns_name_fromtext(name, &buf, dns_rootname, 0);
|
||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -381,7 +383,7 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
isc_commandline_errprint = false;
|
isc_commandline_errprint = false;
|
||||||
|
|
||||||
#define OPTIONS "12Aa:Cc:d:Ff:K:l:sT:v:whV"
|
#define OPTIONS "12Aa:Cc:d:Ff:K:sT:v:whV"
|
||||||
while ((ch = isc_commandline_parse(argc, argv, OPTIONS)) != -1) {
|
while ((ch = isc_commandline_parse(argc, argv, OPTIONS)) != -1) {
|
||||||
switch (ch) {
|
switch (ch) {
|
||||||
case '1':
|
case '1':
|
||||||
@@ -417,9 +419,6 @@ main(int argc, char **argv) {
|
|||||||
case 'f':
|
case 'f':
|
||||||
filename = isc_commandline_argument;
|
filename = isc_commandline_argument;
|
||||||
break;
|
break;
|
||||||
case 'l':
|
|
||||||
fatal("-l option (DLV lookaside) is obsolete");
|
|
||||||
break;
|
|
||||||
case 's':
|
case 's':
|
||||||
usekeyset = true;
|
usekeyset = true;
|
||||||
break;
|
break;
|
||||||
|
|||||||
@@ -20,6 +20,7 @@
|
|||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
@@ -32,6 +33,7 @@
|
|||||||
#include <dns/ds.h>
|
#include <dns/ds.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
|
#include <dns/lib.h>
|
||||||
#include <dns/master.h>
|
#include <dns/master.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/rdata.h>
|
#include <dns/rdata.h>
|
||||||
@@ -67,7 +69,7 @@ initname(char *setname) {
|
|||||||
|
|
||||||
isc_buffer_init(&buf, setname, strlen(setname));
|
isc_buffer_init(&buf, setname, strlen(setname));
|
||||||
isc_buffer_add(&buf, strlen(setname));
|
isc_buffer_add(&buf, strlen(setname));
|
||||||
result = dns_name_fromtext(name, &buf, dns_rootname, 0, NULL);
|
result = dns_name_fromtext(name, &buf, dns_rootname, 0);
|
||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -21,6 +21,7 @@
|
|||||||
#include <isc/attributes.h>
|
#include <isc/attributes.h>
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/region.h>
|
#include <isc/region.h>
|
||||||
@@ -31,6 +32,7 @@
|
|||||||
#include <dns/dnssec.h>
|
#include <dns/dnssec.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
|
#include <dns/lib.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/rdataclass.h>
|
#include <dns/rdataclass.h>
|
||||||
#include <dns/secalg.h>
|
#include <dns/secalg.h>
|
||||||
@@ -365,7 +367,7 @@ main(int argc, char **argv) {
|
|||||||
isc_buffer_init(&buf, argv[isc_commandline_index],
|
isc_buffer_init(&buf, argv[isc_commandline_index],
|
||||||
strlen(argv[isc_commandline_index]));
|
strlen(argv[isc_commandline_index]));
|
||||||
isc_buffer_add(&buf, strlen(argv[isc_commandline_index]));
|
isc_buffer_add(&buf, strlen(argv[isc_commandline_index]));
|
||||||
ret = dns_name_fromtext(name, &buf, dns_rootname, 0, NULL);
|
ret = dns_name_fromtext(name, &buf, dns_rootname, 0);
|
||||||
if (ret != ISC_R_SUCCESS) {
|
if (ret != ISC_R_SUCCESS) {
|
||||||
fatal("invalid key name %s: %s",
|
fatal("invalid key name %s: %s",
|
||||||
argv[isc_commandline_index],
|
argv[isc_commandline_index],
|
||||||
|
|||||||
@@ -39,6 +39,7 @@
|
|||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/fips.h>
|
#include <isc/fips.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/region.h>
|
#include <isc/region.h>
|
||||||
@@ -50,6 +51,7 @@
|
|||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/kasp.h>
|
#include <dns/kasp.h>
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
|
#include <dns/lib.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/rdataclass.h>
|
#include <dns/rdataclass.h>
|
||||||
#include <dns/secalg.h>
|
#include <dns/secalg.h>
|
||||||
@@ -275,7 +277,7 @@ keygen(keygen_ctx_t *ctx, isc_mem_t *mctx, int argc, char **argv) {
|
|||||||
isc_buffer_init(&buf, argv[isc_commandline_index],
|
isc_buffer_init(&buf, argv[isc_commandline_index],
|
||||||
strlen(argv[isc_commandline_index]));
|
strlen(argv[isc_commandline_index]));
|
||||||
isc_buffer_add(&buf, strlen(argv[isc_commandline_index]));
|
isc_buffer_add(&buf, strlen(argv[isc_commandline_index]));
|
||||||
ret = dns_name_fromtext(name, &buf, dns_rootname, 0, NULL);
|
ret = dns_name_fromtext(name, &buf, dns_rootname, 0);
|
||||||
if (ret != ISC_R_SUCCESS) {
|
if (ret != ISC_R_SUCCESS) {
|
||||||
fatal("invalid key name %s: %s",
|
fatal("invalid key name %s: %s",
|
||||||
argv[isc_commandline_index],
|
argv[isc_commandline_index],
|
||||||
|
|||||||
@@ -20,6 +20,7 @@
|
|||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/fips.h>
|
#include <isc/fips.h>
|
||||||
#include <isc/lex.h>
|
#include <isc/lex.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
|
|
||||||
#include <dns/callbacks.h>
|
#include <dns/callbacks.h>
|
||||||
@@ -27,6 +28,7 @@
|
|||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/keymgr.h>
|
#include <dns/keymgr.h>
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
|
#include <dns/lib.h>
|
||||||
#include <dns/rdataclass.h>
|
#include <dns/rdataclass.h>
|
||||||
#include <dns/rdatalist.h>
|
#include <dns/rdatalist.h>
|
||||||
#include <dns/rdataset.h>
|
#include <dns/rdataset.h>
|
||||||
@@ -1006,7 +1008,7 @@ parse_dnskey(isc_lex_t *lex, char *owner, isc_buffer_t *buf, dns_ttl_t *ttl) {
|
|||||||
dname = dns_fixedname_initname(&dfname);
|
dname = dns_fixedname_initname(&dfname);
|
||||||
isc_buffer_init(&b, owner, strlen(owner));
|
isc_buffer_init(&b, owner, strlen(owner));
|
||||||
isc_buffer_add(&b, strlen(owner));
|
isc_buffer_add(&b, strlen(owner));
|
||||||
ret = dns_name_fromtext(dname, &b, dns_rootname, 0, NULL);
|
ret = dns_name_fromtext(dname, &b, dns_rootname, 0);
|
||||||
if (ret != ISC_R_SUCCESS) {
|
if (ret != ISC_R_SUCCESS) {
|
||||||
return ret;
|
return ret;
|
||||||
}
|
}
|
||||||
@@ -1453,7 +1455,7 @@ main(int argc, char *argv[]) {
|
|||||||
name = dns_fixedname_initname(&fname);
|
name = dns_fixedname_initname(&fname);
|
||||||
isc_buffer_init(&buf, argv[1], strlen(argv[1]));
|
isc_buffer_init(&buf, argv[1], strlen(argv[1]));
|
||||||
isc_buffer_add(&buf, strlen(argv[1]));
|
isc_buffer_add(&buf, strlen(argv[1]));
|
||||||
ret = dns_name_fromtext(name, &buf, dns_rootname, 0, NULL);
|
ret = dns_name_fromtext(name, &buf, dns_rootname, 0);
|
||||||
if (ret != ISC_R_SUCCESS) {
|
if (ret != ISC_R_SUCCESS) {
|
||||||
fatal("invalid zone name %s: %s", argv[1],
|
fatal("invalid zone name %s: %s", argv[1],
|
||||||
isc_result_totext(ret));
|
isc_result_totext(ret));
|
||||||
|
|||||||
@@ -23,12 +23,14 @@
|
|||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
#include <isc/string.h>
|
#include <isc/string.h>
|
||||||
#include <isc/util.h>
|
#include <isc/util.h>
|
||||||
|
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
|
#include <dns/lib.h>
|
||||||
|
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
|
|
||||||
|
|||||||
@@ -25,6 +25,7 @@
|
|||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
@@ -33,6 +34,7 @@
|
|||||||
#include <isc/util.h>
|
#include <isc/util.h>
|
||||||
|
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
|
#include <dns/lib.h>
|
||||||
|
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
|
|
||||||
|
|||||||
@@ -45,6 +45,7 @@
|
|||||||
#include <isc/fips.h>
|
#include <isc/fips.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/hex.h>
|
#include <isc/hex.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/loop.h>
|
#include <isc/loop.h>
|
||||||
#include <isc/managers.h>
|
#include <isc/managers.h>
|
||||||
@@ -71,6 +72,7 @@
|
|||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/kasp.h>
|
#include <dns/kasp.h>
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
|
#include <dns/lib.h>
|
||||||
#include <dns/master.h>
|
#include <dns/master.h>
|
||||||
#include <dns/masterdump.h>
|
#include <dns/masterdump.h>
|
||||||
#include <dns/nsec.h>
|
#include <dns/nsec.h>
|
||||||
@@ -419,10 +421,9 @@ keythatsigned(dns_rdata_rrsig_t *rrsig) {
|
|||||||
dns_dnsseckey_create(mctx, &privkey, &key);
|
dns_dnsseckey_create(mctx, &privkey, &key);
|
||||||
} else {
|
} else {
|
||||||
dns_dnsseckey_create(mctx, &pubkey, &key);
|
dns_dnsseckey_create(mctx, &pubkey, &key);
|
||||||
|
key->pubkey = true;
|
||||||
}
|
}
|
||||||
|
|
||||||
key->force_publish = false;
|
|
||||||
key->force_sign = false;
|
|
||||||
key->index = keycount++;
|
key->index = keycount++;
|
||||||
ISC_LIST_APPEND(keylist, key, link);
|
ISC_LIST_APPEND(keylist, key, link);
|
||||||
|
|
||||||
@@ -540,7 +541,7 @@ signset(dns_diff_t *del, dns_diff_t *add, dns_dbnode_t *node, dns_name_t *name,
|
|||||||
}
|
}
|
||||||
|
|
||||||
while (result == ISC_R_SUCCESS) {
|
while (result == ISC_R_SUCCESS) {
|
||||||
bool expired, future;
|
bool expired, refresh, future, offline;
|
||||||
bool keep = false, resign = false;
|
bool keep = false, resign = false;
|
||||||
|
|
||||||
dns_rdataset_current(&sigset, &sigrdata);
|
dns_rdataset_current(&sigset, &sigrdata);
|
||||||
@@ -551,8 +552,10 @@ signset(dns_diff_t *del, dns_diff_t *add, dns_dbnode_t *node, dns_name_t *name,
|
|||||||
future = isc_serial_lt(now, rrsig.timesigned);
|
future = isc_serial_lt(now, rrsig.timesigned);
|
||||||
|
|
||||||
key = keythatsigned(&rrsig);
|
key = keythatsigned(&rrsig);
|
||||||
|
offline = (key != NULL) ? key->pubkey : false;
|
||||||
sig_format(&rrsig, sigstr, sizeof(sigstr));
|
sig_format(&rrsig, sigstr, sizeof(sigstr));
|
||||||
expired = isc_serial_gt(now + cycle, rrsig.timeexpire);
|
expired = isc_serial_gt(now, rrsig.timeexpire);
|
||||||
|
refresh = isc_serial_gt(now + cycle, rrsig.timeexpire);
|
||||||
|
|
||||||
if (isc_serial_gt(rrsig.timesigned, rrsig.timeexpire)) {
|
if (isc_serial_gt(rrsig.timesigned, rrsig.timeexpire)) {
|
||||||
/* rrsig is dropped and not replaced */
|
/* rrsig is dropped and not replaced */
|
||||||
@@ -581,15 +584,21 @@ signset(dns_diff_t *del, dns_diff_t *add, dns_dbnode_t *node, dns_name_t *name,
|
|||||||
} else if (issigningkey(key)) {
|
} else if (issigningkey(key)) {
|
||||||
wassignedby[key->index] = true;
|
wassignedby[key->index] = true;
|
||||||
|
|
||||||
if (!expired && rrsig.originalttl == set->ttl &&
|
if (!refresh && rrsig.originalttl == set->ttl &&
|
||||||
setverifies(name, set, key->key, &sigrdata))
|
setverifies(name, set, key->key, &sigrdata))
|
||||||
{
|
{
|
||||||
vbprintf(2, "\trrsig by %s retained\n", sigstr);
|
vbprintf(2, "\trrsig by %s retained\n", sigstr);
|
||||||
keep = true;
|
keep = true;
|
||||||
|
} else if (offline) {
|
||||||
|
vbprintf(2,
|
||||||
|
"\trrsig by %s retained - private key "
|
||||||
|
"missing\n",
|
||||||
|
sigstr);
|
||||||
|
keep = true;
|
||||||
} else {
|
} else {
|
||||||
vbprintf(2, "\trrsig by %s dropped - %s\n",
|
vbprintf(2, "\trrsig by %s dropped - %s\n",
|
||||||
sigstr,
|
sigstr,
|
||||||
expired ? "expired"
|
refresh ? "refresh"
|
||||||
: rrsig.originalttl != set->ttl
|
: rrsig.originalttl != set->ttl
|
||||||
? "ttl change"
|
? "ttl change"
|
||||||
: "failed to "
|
: "failed to "
|
||||||
@@ -602,25 +611,32 @@ signset(dns_diff_t *del, dns_diff_t *add, dns_dbnode_t *node, dns_name_t *name,
|
|||||||
} else if (iszonekey(key)) {
|
} else if (iszonekey(key)) {
|
||||||
wassignedby[key->index] = true;
|
wassignedby[key->index] = true;
|
||||||
|
|
||||||
if (!expired && rrsig.originalttl == set->ttl &&
|
if (!refresh && rrsig.originalttl == set->ttl &&
|
||||||
setverifies(name, set, key->key, &sigrdata))
|
setverifies(name, set, key->key, &sigrdata))
|
||||||
{
|
{
|
||||||
vbprintf(2, "\trrsig by %s retained\n", sigstr);
|
vbprintf(2, "\trrsig by %s retained\n", sigstr);
|
||||||
keep = true;
|
keep = true;
|
||||||
|
} else if (offline) {
|
||||||
|
vbprintf(2,
|
||||||
|
"\trrsig by %s retained - private key "
|
||||||
|
"missing\n",
|
||||||
|
sigstr);
|
||||||
|
keep = true;
|
||||||
} else {
|
} else {
|
||||||
vbprintf(2, "\trrsig by %s dropped - %s\n",
|
vbprintf(2, "\trrsig by %s dropped - %s\n",
|
||||||
sigstr,
|
sigstr,
|
||||||
expired ? "expired"
|
refresh ? "refresh"
|
||||||
: rrsig.originalttl != set->ttl
|
: rrsig.originalttl != set->ttl
|
||||||
? "ttl change"
|
? "ttl change"
|
||||||
: "failed to "
|
: "failed to "
|
||||||
"verify");
|
"verify");
|
||||||
}
|
}
|
||||||
} else if (!expired) {
|
} else if (!refresh) {
|
||||||
vbprintf(2, "\trrsig by %s retained\n", sigstr);
|
vbprintf(2, "\trrsig by %s retained\n", sigstr);
|
||||||
keep = true;
|
keep = true;
|
||||||
} else {
|
} else {
|
||||||
vbprintf(2, "\trrsig by %s expired\n", sigstr);
|
vbprintf(2, "\trrsig by %s %s\n", sigstr,
|
||||||
|
expired ? "expired" : "needs refresh");
|
||||||
}
|
}
|
||||||
|
|
||||||
if (keep) {
|
if (keep) {
|
||||||
@@ -943,7 +959,7 @@ addnowildcardhash(hashlist_t *l,
|
|||||||
|
|
||||||
wild = dns_fixedname_initname(&fixed);
|
wild = dns_fixedname_initname(&fixed);
|
||||||
|
|
||||||
result = dns_name_concatenate(dns_wildcardname, name, wild, NULL);
|
result = dns_name_concatenate(dns_wildcardname, name, wild);
|
||||||
if (result == ISC_R_NOSPACE) {
|
if (result == ISC_R_NOSPACE) {
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
@@ -2018,7 +2034,7 @@ addnsec3(dns_name_t *name, dns_dbnode_t *node, const unsigned char *salt,
|
|||||||
dns_fixedname_init(&hashname);
|
dns_fixedname_init(&hashname);
|
||||||
dns_rdataset_init(&rdataset);
|
dns_rdataset_init(&rdataset);
|
||||||
|
|
||||||
dns_name_downcase(name, name, NULL);
|
dns_name_downcase(name, name);
|
||||||
result = dns_nsec3_hashname(&hashname, hash, &hash_len, name, gorigin,
|
result = dns_nsec3_hashname(&hashname, hash, &hash_len, name, gorigin,
|
||||||
dns_hash_sha1, iterations, salt, salt_len);
|
dns_hash_sha1, iterations, salt, salt_len);
|
||||||
check_result(result, "addnsec3: dns_nsec3_hashname()");
|
check_result(result, "addnsec3: dns_nsec3_hashname()");
|
||||||
@@ -2386,7 +2402,7 @@ nsec3ify(unsigned int hashalg, dns_iterations_t iterations,
|
|||||||
fatal("iterating through the database failed: %s",
|
fatal("iterating through the database failed: %s",
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
}
|
}
|
||||||
dns_name_downcase(name, name, NULL);
|
dns_name_downcase(name, name);
|
||||||
hashlist_add_dns_name(hashlist, name, hashalg, iterations, salt,
|
hashlist_add_dns_name(hashlist, name, hashalg, iterations, salt,
|
||||||
salt_len, false);
|
salt_len, false);
|
||||||
dns_db_detachnode(gdb, &node);
|
dns_db_detachnode(gdb, &node);
|
||||||
@@ -2396,7 +2412,7 @@ nsec3ify(unsigned int hashalg, dns_iterations_t iterations,
|
|||||||
* node for another <name,nextname> span so we don't add
|
* node for another <name,nextname> span so we don't add
|
||||||
* it here. Empty labels on nextname are within the span.
|
* it here. Empty labels on nextname are within the span.
|
||||||
*/
|
*/
|
||||||
dns_name_downcase(nextname, nextname, NULL);
|
dns_name_downcase(nextname, nextname);
|
||||||
dns_name_fullcompare(name, nextname, &order, &nlabels);
|
dns_name_fullcompare(name, nextname, &order, &nlabels);
|
||||||
addnowildcardhash(hashlist, name, hashalg, iterations, salt,
|
addnowildcardhash(hashlist, name, hashalg, iterations, salt,
|
||||||
salt_len);
|
salt_len);
|
||||||
@@ -2563,7 +2579,7 @@ loadzone(char *file, char *origin, dns_rdataclass_t rdclass, dns_db_t **db) {
|
|||||||
isc_buffer_add(&b, len);
|
isc_buffer_add(&b, len);
|
||||||
|
|
||||||
name = dns_fixedname_initname(&fname);
|
name = dns_fixedname_initname(&fname);
|
||||||
result = dns_name_fromtext(name, &b, dns_rootname, 0, NULL);
|
result = dns_name_fromtext(name, &b, dns_rootname, 0);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("failed converting name '%s' to dns format: %s", origin,
|
fatal("failed converting name '%s' to dns format: %s", origin,
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
@@ -3372,9 +3388,12 @@ main(int argc, char *argv[]) {
|
|||||||
atomic_init(&shuttingdown, false);
|
atomic_init(&shuttingdown, false);
|
||||||
atomic_init(&finished, false);
|
atomic_init(&finished, false);
|
||||||
|
|
||||||
/* Unused letters: Bb G J q Yy (and F is reserved). */
|
/*
|
||||||
#define CMDLINE_FLAGS \
|
* Unused letters: Bb G J l q Yy (and F is reserved).
|
||||||
"3:AaCc:Dd:E:e:f:FgG:hH:i:I:j:J:K:k:L:l:m:M:n:N:o:O:PpQqRr:s:ST:tuUv:" \
|
* l was previously used for DLV lookaside.
|
||||||
|
*/
|
||||||
|
#define CMDLINE_FLAGS \
|
||||||
|
"3:AaCc:Dd:E:e:f:FgG:hH:i:I:j:J:K:k:L:m:M:n:N:o:O:PpQqRr:s:ST:tuUv:" \
|
||||||
"VX:xzZ:"
|
"VX:xzZ:"
|
||||||
|
|
||||||
/*
|
/*
|
||||||
@@ -3548,10 +3567,6 @@ main(int argc, char *argv[]) {
|
|||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case 'l':
|
|
||||||
fatal("-l option (DLV lookaside) is obsolete");
|
|
||||||
break;
|
|
||||||
|
|
||||||
case 'M':
|
case 'M':
|
||||||
endp = NULL;
|
endp = NULL;
|
||||||
set_maxttl = true;
|
set_maxttl = true;
|
||||||
|
|||||||
@@ -174,6 +174,11 @@ Options
|
|||||||
days. Therefore, if any existing RRSIG records are due to expire in
|
days. Therefore, if any existing RRSIG records are due to expire in
|
||||||
less than 7.5 days, they are replaced.
|
less than 7.5 days, they are replaced.
|
||||||
|
|
||||||
|
Note that the calculation of cycle interval is based upon the validity
|
||||||
|
period of the replacement signatures that would be generated by
|
||||||
|
``dnssec-signzone``, not on the valid lifetimes of the input RRSIGs being
|
||||||
|
considered for pre-expiry replacement.
|
||||||
|
|
||||||
.. option:: -I input-format
|
.. option:: -I input-format
|
||||||
|
|
||||||
This option sets the format of the input zone file. Possible formats are
|
This option sets the format of the input zone file. Possible formats are
|
||||||
@@ -269,7 +274,7 @@ Options
|
|||||||
with cached copies of the old DNSKEY RRset. The :option:`-Q` option forces
|
with cached copies of the old DNSKEY RRset. The :option:`-Q` option forces
|
||||||
:program:`dnssec-signzone` to remove signatures from keys that are no longer
|
:program:`dnssec-signzone` to remove signatures from keys that are no longer
|
||||||
active. This enables ZSK rollover using the procedure described in
|
active. This enables ZSK rollover using the procedure described in
|
||||||
:rfc:`6781#4.1.1.1` ("Pre-Publish Key Rollover").
|
:rfc:`6781#section-4.1.1.1` ("Pre-Publish Zone Signing Key Rollover").
|
||||||
|
|
||||||
.. option:: -q
|
.. option:: -q
|
||||||
|
|
||||||
@@ -286,7 +291,7 @@ Options
|
|||||||
This option is similar to :option:`-Q`, except it forces
|
This option is similar to :option:`-Q`, except it forces
|
||||||
:program:`dnssec-signzone` to remove signatures from keys that are no longer
|
:program:`dnssec-signzone` to remove signatures from keys that are no longer
|
||||||
published. This enables ZSK rollover using the procedure described in
|
published. This enables ZSK rollover using the procedure described in
|
||||||
:rfc:`6781#4.1.1.2` ("Double Signature Zone Signing Key
|
:rfc:`6781#section-4.1.1.2` ("Double Signature Zone Signing Key
|
||||||
Rollover").
|
Rollover").
|
||||||
|
|
||||||
.. option:: -S
|
.. option:: -S
|
||||||
|
|||||||
@@ -23,6 +23,7 @@
|
|||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/hex.h>
|
#include <isc/hex.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/mutex.h>
|
#include <isc/mutex.h>
|
||||||
@@ -43,6 +44,7 @@
|
|||||||
#include <dns/ds.h>
|
#include <dns/ds.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
|
#include <dns/lib.h>
|
||||||
#include <dns/master.h>
|
#include <dns/master.h>
|
||||||
#include <dns/masterdump.h>
|
#include <dns/masterdump.h>
|
||||||
#include <dns/nsec.h>
|
#include <dns/nsec.h>
|
||||||
@@ -103,7 +105,7 @@ loadzone(char *file, char *origin, dns_rdataclass_t rdclass, dns_db_t **db) {
|
|||||||
isc_buffer_add(&b, len);
|
isc_buffer_add(&b, len);
|
||||||
|
|
||||||
name = dns_fixedname_initname(&fname);
|
name = dns_fixedname_initname(&fname);
|
||||||
result = dns_name_fromtext(name, &b, dns_rootname, 0, NULL);
|
result = dns_name_fromtext(name, &b, dns_rootname, 0);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("failed converting name '%s' to dns format: %s", origin,
|
fatal("failed converting name '%s' to dns format: %s", origin,
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
|
|||||||
@@ -460,9 +460,7 @@ key_collision(dst_key_t *dstkey, dns_name_t *name, const char *dir,
|
|||||||
dns_secalg_t alg;
|
dns_secalg_t alg;
|
||||||
isc_stdtime_t now = isc_stdtime_now();
|
isc_stdtime_t now = isc_stdtime_now();
|
||||||
|
|
||||||
if (exact != NULL) {
|
SET_IF_NOT_NULL(exact, false);
|
||||||
*exact = false;
|
|
||||||
}
|
|
||||||
|
|
||||||
id = dst_key_id(dstkey);
|
id = dst_key_id(dstkey);
|
||||||
rid = dst_key_rid(dstkey);
|
rid = dst_key_rid(dstkey);
|
||||||
|
|||||||
@@ -931,6 +931,7 @@
|
|||||||
<th>Messages Received</th>
|
<th>Messages Received</th>
|
||||||
<th>Records Received</th>
|
<th>Records Received</th>
|
||||||
<th>Bytes Received</th>
|
<th>Bytes Received</th>
|
||||||
|
<th>Transfer Rate (B/s)</th>
|
||||||
</tr>
|
</tr>
|
||||||
</thead>
|
</thead>
|
||||||
<tbody>
|
<tbody>
|
||||||
@@ -959,6 +960,7 @@
|
|||||||
<td><xsl:value-of select="nmsg"/></td>
|
<td><xsl:value-of select="nmsg"/></td>
|
||||||
<td><xsl:value-of select="nrecs"/></td>
|
<td><xsl:value-of select="nrecs"/></td>
|
||||||
<td><xsl:value-of select="nbytes"/></td>
|
<td><xsl:value-of select="nbytes"/></td>
|
||||||
|
<td><xsl:value-of select="rate"/></td>
|
||||||
</tr>
|
</tr>
|
||||||
</xsl:for-each>
|
</xsl:for-each>
|
||||||
</tbody>
|
</tbody>
|
||||||
|
|||||||
+5
-5
@@ -459,7 +459,7 @@ dns64_cname(const dns_name_t *zone, const dns_name_t *name, bdbnode_t *node) {
|
|||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
builtin_lookup(bdb_t *bdb, const dns_name_t *name, bdbnode_t *node) {
|
builtin_lookup(bdb_t *bdb, const dns_name_t *name, bdbnode_t *node) {
|
||||||
if (name->labels == 0 && name->length == 0) {
|
if (name->length == 0) {
|
||||||
return bdb->lookup(node);
|
return bdb->lookup(node);
|
||||||
} else if ((node->bdb->implementation->flags & BDB_DNS64) != 0) {
|
} else if ((node->bdb->implementation->flags & BDB_DNS64) != 0) {
|
||||||
return dns64_cname(&bdb->common.origin, name, node);
|
return dns64_cname(&bdb->common.origin, name, node);
|
||||||
@@ -839,7 +839,7 @@ getoriginnode(dns_db_t *db, dns_dbnode_t **nodep DNS__DB_FLARG) {
|
|||||||
REQUIRE(VALID_BDB(bdb));
|
REQUIRE(VALID_BDB(bdb));
|
||||||
REQUIRE(nodep != NULL && *nodep == NULL);
|
REQUIRE(nodep != NULL && *nodep == NULL);
|
||||||
|
|
||||||
dns_name_init(&relname, NULL);
|
dns_name_init(&relname);
|
||||||
name = &relname;
|
name = &relname;
|
||||||
|
|
||||||
result = createnode(bdb, &node);
|
result = createnode(bdb, &node);
|
||||||
@@ -881,7 +881,7 @@ findnode(dns_db_t *db, const dns_name_t *name, bool create,
|
|||||||
isorigin = dns_name_equal(name, &bdb->common.origin);
|
isorigin = dns_name_equal(name, &bdb->common.origin);
|
||||||
|
|
||||||
labels = dns_name_countlabels(name) - dns_name_countlabels(&db->origin);
|
labels = dns_name_countlabels(name) - dns_name_countlabels(&db->origin);
|
||||||
dns_name_init(&relname, NULL);
|
dns_name_init(&relname);
|
||||||
dns_name_getlabelsequence(name, 0, labels, &relname);
|
dns_name_getlabelsequence(name, 0, labels, &relname);
|
||||||
name = &relname;
|
name = &relname;
|
||||||
|
|
||||||
@@ -1197,8 +1197,8 @@ create(isc_mem_t *mctx, const dns_name_t *origin, dns_dbtype_t type,
|
|||||||
|
|
||||||
isc_refcount_init(&bdb->common.references, 1);
|
isc_refcount_init(&bdb->common.references, 1);
|
||||||
isc_mem_attach(mctx, &bdb->common.mctx);
|
isc_mem_attach(mctx, &bdb->common.mctx);
|
||||||
dns_name_init(&bdb->common.origin, NULL);
|
dns_name_init(&bdb->common.origin);
|
||||||
dns_name_dupwithoffsets(origin, mctx, &bdb->common.origin);
|
dns_name_dup(origin, mctx, &bdb->common.origin);
|
||||||
|
|
||||||
INSIST(argc >= 1);
|
INSIST(argc >= 1);
|
||||||
if (strcmp(argv[0], "authors") == 0) {
|
if (strcmp(argv[0], "authors") == 0) {
|
||||||
|
|||||||
+25
-35
@@ -111,6 +111,8 @@ options {\n\
|
|||||||
session-keyname local-ddns;\n\
|
session-keyname local-ddns;\n\
|
||||||
startup-notify-rate 20;\n\
|
startup-notify-rate 20;\n\
|
||||||
sig0checks-quota 1;\n\
|
sig0checks-quota 1;\n\
|
||||||
|
sig0key-checks-limit 16;\n\
|
||||||
|
sig0message-checks-limit 2;\n\
|
||||||
statistics-file \"named.stats\";\n\
|
statistics-file \"named.stats\";\n\
|
||||||
tcp-advertised-timeout 300;\n\
|
tcp-advertised-timeout 300;\n\
|
||||||
tcp-clients 150;\n\
|
tcp-clients 150;\n\
|
||||||
@@ -193,7 +195,6 @@ options {\n\
|
|||||||
require-server-cookie no;\n\
|
require-server-cookie no;\n\
|
||||||
root-key-sentinel yes;\n\
|
root-key-sentinel yes;\n\
|
||||||
servfail-ttl 1;\n\
|
servfail-ttl 1;\n\
|
||||||
# sortlist <none>\n\
|
|
||||||
stale-answer-client-timeout off;\n\
|
stale-answer-client-timeout off;\n\
|
||||||
stale-answer-enable false;\n\
|
stale-answer-enable false;\n\
|
||||||
stale-answer-ttl 30; /* 30 seconds */\n\
|
stale-answer-ttl 30; /* 30 seconds */\n\
|
||||||
@@ -233,6 +234,7 @@ options {\n\
|
|||||||
max-transfer-time-out 120;\n\
|
max-transfer-time-out 120;\n\
|
||||||
min-refresh-time 300;\n\
|
min-refresh-time 300;\n\
|
||||||
min-retry-time 500;\n\
|
min-retry-time 500;\n\
|
||||||
|
min-transfer-rate-in 10240 5;\n\
|
||||||
multi-master no;\n\
|
multi-master no;\n\
|
||||||
notify yes;\n\
|
notify yes;\n\
|
||||||
notify-delay 5;\n\
|
notify-delay 5;\n\
|
||||||
@@ -332,7 +334,7 @@ dnssec-policy \"insecure\" {\n\
|
|||||||
|
|
||||||
"# END TRUST ANCHORS\n\
|
"# END TRUST ANCHORS\n\
|
||||||
\n\
|
\n\
|
||||||
primaries " DEFAULT_IANA_ROOT_ZONE_PRIMARIES " {\n\
|
remote-servers " DEFAULT_IANA_ROOT_ZONE_PRIMARIES " {\n\
|
||||||
2801:1b8:10::b; # b.root-servers.net\n\
|
2801:1b8:10::b; # b.root-servers.net\n\
|
||||||
2001:500:2::c; # c.root-servers.net\n\
|
2001:500:2::c; # c.root-servers.net\n\
|
||||||
2001:500:2f::f; # f.root-servers.net\n\
|
2001:500:2f::f; # f.root-servers.net\n\
|
||||||
@@ -504,9 +506,9 @@ named_config_getzonetype(const cfg_obj_t *zonetypeobj) {
|
|||||||
return ztype;
|
return ztype;
|
||||||
}
|
}
|
||||||
|
|
||||||
static isc_result_t
|
isc_result_t
|
||||||
getremotesdef(const cfg_obj_t *cctx, const char *list, const char *name,
|
named_config_getremotesdef(const cfg_obj_t *cctx, const char *list,
|
||||||
const cfg_obj_t **ret) {
|
const char *name, const cfg_obj_t **ret) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
const cfg_obj_t *obj = NULL;
|
const cfg_obj_t *obj = NULL;
|
||||||
const cfg_listelt_t *elt;
|
const cfg_listelt_t *elt;
|
||||||
@@ -533,23 +535,6 @@ getremotesdef(const cfg_obj_t *cctx, const char *list, const char *name,
|
|||||||
return ISC_R_NOTFOUND;
|
return ISC_R_NOTFOUND;
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_result_t
|
|
||||||
named_config_getremotesdef(const cfg_obj_t *cctx, const char *list,
|
|
||||||
const char *name, const cfg_obj_t **ret) {
|
|
||||||
isc_result_t result;
|
|
||||||
|
|
||||||
if (strcmp(list, "parental-agents") == 0) {
|
|
||||||
return getremotesdef(cctx, list, name, ret);
|
|
||||||
} else if (strcmp(list, "primaries") == 0) {
|
|
||||||
result = getremotesdef(cctx, list, name, ret);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
result = getremotesdef(cctx, "masters", name, ret);
|
|
||||||
}
|
|
||||||
return result;
|
|
||||||
}
|
|
||||||
return ISC_R_NOTFOUND;
|
|
||||||
}
|
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
named_config_getname(isc_mem_t *mctx, const cfg_obj_t *obj,
|
named_config_getname(isc_mem_t *mctx, const cfg_obj_t *obj,
|
||||||
dns_name_t **namep) {
|
dns_name_t **namep) {
|
||||||
@@ -566,14 +551,14 @@ named_config_getname(isc_mem_t *mctx, const cfg_obj_t *obj,
|
|||||||
}
|
}
|
||||||
|
|
||||||
*namep = isc_mem_get(mctx, sizeof(**namep));
|
*namep = isc_mem_get(mctx, sizeof(**namep));
|
||||||
dns_name_init(*namep, NULL);
|
dns_name_init(*namep);
|
||||||
|
|
||||||
objstr = cfg_obj_asstring(obj);
|
objstr = cfg_obj_asstring(obj);
|
||||||
isc_buffer_constinit(&b, objstr, strlen(objstr));
|
isc_buffer_constinit(&b, objstr, strlen(objstr));
|
||||||
isc_buffer_add(&b, strlen(objstr));
|
isc_buffer_add(&b, strlen(objstr));
|
||||||
dns_fixedname_init(&fname);
|
dns_fixedname_init(&fname);
|
||||||
result = dns_name_fromtext(dns_fixedname_name(&fname), &b, dns_rootname,
|
result = dns_name_fromtext(dns_fixedname_name(&fname), &b, dns_rootname,
|
||||||
0, NULL);
|
0);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
isc_mem_put(mctx, *namep, sizeof(**namep));
|
isc_mem_put(mctx, *namep, sizeof(**namep));
|
||||||
*namep = NULL;
|
*namep = NULL;
|
||||||
@@ -598,10 +583,12 @@ named_config_getname(isc_mem_t *mctx, const cfg_obj_t *obj,
|
|||||||
oldlen = newlen; \
|
oldlen = newlen; \
|
||||||
}
|
}
|
||||||
|
|
||||||
|
static const char *remotesnames[4] = { "remote-servers", "parental-agents",
|
||||||
|
"primaries", "masters" };
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
named_config_getipandkeylist(const cfg_obj_t *config, const char *listtype,
|
named_config_getipandkeylist(const cfg_obj_t *config, const cfg_obj_t *list,
|
||||||
const cfg_obj_t *list, isc_mem_t *mctx,
|
isc_mem_t *mctx, dns_ipkeylist_t *ipkl) {
|
||||||
dns_ipkeylist_t *ipkl) {
|
|
||||||
uint32_t addrcount = 0, srccount = 0;
|
uint32_t addrcount = 0, srccount = 0;
|
||||||
uint32_t keycount = 0, tlscount = 0;
|
uint32_t keycount = 0, tlscount = 0;
|
||||||
uint32_t listcount = 0, l = 0, i = 0;
|
uint32_t listcount = 0, l = 0, i = 0;
|
||||||
@@ -684,8 +671,6 @@ newlist:
|
|||||||
isc_sockaddr_any6(&src6);
|
isc_sockaddr_any6(&src6);
|
||||||
}
|
}
|
||||||
|
|
||||||
result = ISC_R_NOMEMORY;
|
|
||||||
|
|
||||||
element = cfg_list_first(addrlist);
|
element = cfg_list_first(addrlist);
|
||||||
resume:
|
resume:
|
||||||
for (; element != NULL; element = cfg_list_next(element)) {
|
for (; element != NULL; element = cfg_list_next(element)) {
|
||||||
@@ -716,17 +701,22 @@ resume:
|
|||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
list = NULL;
|
list = NULL;
|
||||||
tresult = named_config_getremotesdef(config, listtype,
|
tresult = ISC_R_NOTFOUND;
|
||||||
listname, &list);
|
for (size_t n = 0; n < ARRAY_SIZE(remotesnames); n++) {
|
||||||
|
tresult = named_config_getremotesdef(
|
||||||
|
config, remotesnames[n], listname,
|
||||||
|
&list);
|
||||||
|
if (tresult == ISC_R_SUCCESS) {
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
}
|
||||||
if (tresult == ISC_R_NOTFOUND) {
|
if (tresult == ISC_R_NOTFOUND) {
|
||||||
cfg_obj_log(addr, ISC_LOG_ERROR,
|
cfg_obj_log(addr, ISC_LOG_ERROR,
|
||||||
"%s \"%s\" not found", listtype,
|
"remote-servers \"%s\" not found",
|
||||||
listname);
|
listname);
|
||||||
|
|
||||||
result = tresult;
|
|
||||||
goto cleanup;
|
|
||||||
}
|
}
|
||||||
if (tresult != ISC_R_SUCCESS) {
|
if (tresult != ISC_R_SUCCESS) {
|
||||||
|
result = tresult;
|
||||||
goto cleanup;
|
goto cleanup;
|
||||||
}
|
}
|
||||||
lists[l++].name = listname;
|
lists[l++].name = listname;
|
||||||
|
|||||||
@@ -233,6 +233,8 @@ named_control_docommand(isccc_sexpr_t *message, bool readonly,
|
|||||||
command_compare(command, NAMED_COMMAND_SIGN))
|
command_compare(command, NAMED_COMMAND_SIGN))
|
||||||
{
|
{
|
||||||
result = named_server_rekey(named_g_server, lex, text);
|
result = named_server_rekey(named_g_server, lex, text);
|
||||||
|
} else if (command_compare(command, NAMED_COMMAND_MEMPROF)) {
|
||||||
|
result = named_server_togglememprof(lex);
|
||||||
} else if (command_compare(command, NAMED_COMMAND_MKEYS)) {
|
} else if (command_compare(command, NAMED_COMMAND_MKEYS)) {
|
||||||
result = named_server_mkeys(named_g_server, lex, text);
|
result = named_server_mkeys(named_g_server, lex, text);
|
||||||
} else if (command_compare(command, NAMED_COMMAND_NOTIFY)) {
|
} else if (command_compare(command, NAMED_COMMAND_NOTIFY)) {
|
||||||
|
|||||||
+10
-19
@@ -31,13 +31,13 @@
|
|||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
#include <isc/stdtime.h>
|
#include <isc/stdtime.h>
|
||||||
#include <isc/string.h>
|
#include <isc/string.h>
|
||||||
|
#include <isc/symtab.h>
|
||||||
#include <isc/util.h>
|
#include <isc/util.h>
|
||||||
|
|
||||||
#include <isccc/alist.h>
|
#include <isccc/alist.h>
|
||||||
#include <isccc/cc.h>
|
#include <isccc/cc.h>
|
||||||
#include <isccc/ccmsg.h>
|
#include <isccc/ccmsg.h>
|
||||||
#include <isccc/sexpr.h>
|
#include <isccc/sexpr.h>
|
||||||
#include <isccc/symtab.h>
|
|
||||||
#include <isccc/util.h>
|
#include <isccc/util.h>
|
||||||
|
|
||||||
#include <isccfg/check.h>
|
#include <isccfg/check.h>
|
||||||
@@ -108,7 +108,7 @@ struct named_controls {
|
|||||||
controllistenerlist_t listeners;
|
controllistenerlist_t listeners;
|
||||||
bool shuttingdown;
|
bool shuttingdown;
|
||||||
isc_mutex_t symtab_lock;
|
isc_mutex_t symtab_lock;
|
||||||
isccc_symtab_t *symtab;
|
isc_symtab_t *symtab;
|
||||||
};
|
};
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
@@ -489,7 +489,7 @@ control_recvmessage(isc_nmhandle_t *handle ISC_ATTR_UNUSED, isc_result_t result,
|
|||||||
if ((sent + CLOCKSKEW) < conn->now ||
|
if ((sent + CLOCKSKEW) < conn->now ||
|
||||||
(sent - CLOCKSKEW) > conn->now)
|
(sent - CLOCKSKEW) > conn->now)
|
||||||
{
|
{
|
||||||
result = ISCCC_R_CLOCKSKEW;
|
result = DNS_R_CLOCKSKEW;
|
||||||
goto cleanup;
|
goto cleanup;
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
@@ -503,7 +503,7 @@ control_recvmessage(isc_nmhandle_t *handle ISC_ATTR_UNUSED, isc_result_t result,
|
|||||||
if (isccc_cc_lookupuint32(conn->ctrl, "_exp", &exp) == ISC_R_SUCCESS &&
|
if (isccc_cc_lookupuint32(conn->ctrl, "_exp", &exp) == ISC_R_SUCCESS &&
|
||||||
conn->now > exp)
|
conn->now > exp)
|
||||||
{
|
{
|
||||||
result = ISCCC_R_EXPIRED;
|
result = DNS_R_EXPIRED;
|
||||||
goto cleanup;
|
goto cleanup;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -842,15 +842,12 @@ get_rndckey(isc_mem_t *mctx, controlkeylist_t *keyids) {
|
|||||||
CHECK(cfg_map_get(config, "key", &key));
|
CHECK(cfg_map_get(config, "key", &key));
|
||||||
|
|
||||||
keyid = isc_mem_get(mctx, sizeof(*keyid));
|
keyid = isc_mem_get(mctx, sizeof(*keyid));
|
||||||
|
*keyid = (controlkey_t){
|
||||||
|
.algorithm = DST_ALG_UNKNOWN,
|
||||||
|
.link = ISC_LINK_INITIALIZER,
|
||||||
|
};
|
||||||
keyid->keyname = isc_mem_strdup(mctx,
|
keyid->keyname = isc_mem_strdup(mctx,
|
||||||
cfg_obj_asstring(cfg_map_getname(key)));
|
cfg_obj_asstring(cfg_map_getname(key)));
|
||||||
keyid->secret.base = NULL;
|
|
||||||
keyid->secret.length = 0;
|
|
||||||
keyid->algorithm = DST_ALG_UNKNOWN;
|
|
||||||
ISC_LINK_INIT(keyid, link);
|
|
||||||
if (keyid->keyname == NULL) {
|
|
||||||
CHECK(ISC_R_NOMEMORY);
|
|
||||||
}
|
|
||||||
|
|
||||||
CHECK(isccfg_check_key(key));
|
CHECK(isccfg_check_key(key));
|
||||||
|
|
||||||
@@ -1339,7 +1336,6 @@ named_controls_configure(named_controls_t *cp, const cfg_obj_t *config,
|
|||||||
isc_result_t
|
isc_result_t
|
||||||
named_controls_create(named_server_t *server, named_controls_t **ctrlsp) {
|
named_controls_create(named_server_t *server, named_controls_t **ctrlsp) {
|
||||||
isc_mem_t *mctx = server->mctx;
|
isc_mem_t *mctx = server->mctx;
|
||||||
isc_result_t result;
|
|
||||||
named_controls_t *controls = isc_mem_get(mctx, sizeof(*controls));
|
named_controls_t *controls = isc_mem_get(mctx, sizeof(*controls));
|
||||||
|
|
||||||
*controls = (named_controls_t){
|
*controls = (named_controls_t){
|
||||||
@@ -1350,14 +1346,9 @@ named_controls_create(named_server_t *server, named_controls_t **ctrlsp) {
|
|||||||
|
|
||||||
isc_mutex_init(&controls->symtab_lock);
|
isc_mutex_init(&controls->symtab_lock);
|
||||||
LOCK(&controls->symtab_lock);
|
LOCK(&controls->symtab_lock);
|
||||||
result = isccc_cc_createsymtab(&controls->symtab);
|
isccc_cc_createsymtab(mctx, &controls->symtab);
|
||||||
UNLOCK(&controls->symtab_lock);
|
UNLOCK(&controls->symtab_lock);
|
||||||
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
isc_mutex_destroy(&controls->symtab_lock);
|
|
||||||
isc_mem_put(server->mctx, controls, sizeof(*controls));
|
|
||||||
return result;
|
|
||||||
}
|
|
||||||
*ctrlsp = controls;
|
*ctrlsp = controls;
|
||||||
return ISC_R_SUCCESS;
|
return ISC_R_SUCCESS;
|
||||||
}
|
}
|
||||||
@@ -1371,7 +1362,7 @@ named_controls_destroy(named_controls_t **ctrlsp) {
|
|||||||
REQUIRE(ISC_LIST_EMPTY(controls->listeners));
|
REQUIRE(ISC_LIST_EMPTY(controls->listeners));
|
||||||
|
|
||||||
LOCK(&controls->symtab_lock);
|
LOCK(&controls->symtab_lock);
|
||||||
isccc_symtab_destroy(&controls->symtab);
|
isc_symtab_destroy(&controls->symtab);
|
||||||
UNLOCK(&controls->symtab_lock);
|
UNLOCK(&controls->symtab_lock);
|
||||||
isc_mutex_destroy(&controls->symtab_lock);
|
isc_mutex_destroy(&controls->symtab_lock);
|
||||||
isc_mem_put(controls->server->mctx, controls, sizeof(*controls));
|
isc_mem_put(controls->server->mctx, controls, sizeof(*controls));
|
||||||
|
|||||||
@@ -17,7 +17,6 @@
|
|||||||
|
|
||||||
#include <inttypes.h>
|
#include <inttypes.h>
|
||||||
|
|
||||||
#include <isc/lang.h>
|
|
||||||
#include <isc/types.h>
|
#include <isc/types.h>
|
||||||
|
|
||||||
#include <dns/clientinfo.h>
|
#include <dns/clientinfo.h>
|
||||||
|
|||||||
@@ -57,9 +57,8 @@ named_config_getremotesdef(const cfg_obj_t *cctx, const char *list,
|
|||||||
const char *name, const cfg_obj_t **ret);
|
const char *name, const cfg_obj_t **ret);
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
named_config_getipandkeylist(const cfg_obj_t *config, const char *listtype,
|
named_config_getipandkeylist(const cfg_obj_t *config, const cfg_obj_t *list,
|
||||||
const cfg_obj_t *list, isc_mem_t *mctx,
|
isc_mem_t *mctx, dns_ipkeylist_t *ipkl);
|
||||||
dns_ipkeylist_t *ipkl);
|
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
named_config_getport(const cfg_obj_t *config, const char *type,
|
named_config_getport(const cfg_obj_t *config, const char *type,
|
||||||
|
|||||||
@@ -43,6 +43,7 @@
|
|||||||
#define NAMED_COMMAND_FREEZE "freeze"
|
#define NAMED_COMMAND_FREEZE "freeze"
|
||||||
#define NAMED_COMMAND_HALT "halt"
|
#define NAMED_COMMAND_HALT "halt"
|
||||||
#define NAMED_COMMAND_LOADKEYS "loadkeys"
|
#define NAMED_COMMAND_LOADKEYS "loadkeys"
|
||||||
|
#define NAMED_COMMAND_MEMPROF "memprof"
|
||||||
#define NAMED_COMMAND_MKEYS "managed-keys"
|
#define NAMED_COMMAND_MKEYS "managed-keys"
|
||||||
#define NAMED_COMMAND_MODZONE "modzone"
|
#define NAMED_COMMAND_MODZONE "modzone"
|
||||||
#define NAMED_COMMAND_NOTIFY "notify"
|
#define NAMED_COMMAND_NOTIFY "notify"
|
||||||
|
|||||||
@@ -388,3 +388,15 @@ named_server_fetchlimit(named_server_t *server, isc_lex_t *lex,
|
|||||||
*/
|
*/
|
||||||
isc_result_t
|
isc_result_t
|
||||||
named_server_skr(named_server_t *server, isc_lex_t *lex, isc_buffer_t **text);
|
named_server_skr(named_server_t *server, isc_lex_t *lex, isc_buffer_t **text);
|
||||||
|
|
||||||
|
/*%
|
||||||
|
* Toggle memory profiling if supported.
|
||||||
|
*/
|
||||||
|
isc_result_t
|
||||||
|
named_server_togglememprof(isc_lex_t *lex);
|
||||||
|
|
||||||
|
/*%
|
||||||
|
* Get status of memory profiling.
|
||||||
|
*/
|
||||||
|
const char *
|
||||||
|
named_server_getmemprof(void);
|
||||||
|
|||||||
@@ -15,13 +15,10 @@
|
|||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <isc/lang.h>
|
|
||||||
#include <isc/types.h>
|
#include <isc/types.h>
|
||||||
|
|
||||||
#include <isccfg/cfg.h>
|
#include <isccfg/cfg.h>
|
||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
named_tkeyctx_fromconfig(const cfg_obj_t *options, isc_mem_t *mctx,
|
named_tkeyctx_fromconfig(const cfg_obj_t *options, isc_mem_t *mctx,
|
||||||
dns_tkeyctx_t **tctxp);
|
dns_tkeyctx_t **tctxp);
|
||||||
@@ -37,7 +34,5 @@ named_tkeyctx_fromconfig(const cfg_obj_t *options, isc_mem_t *mctx,
|
|||||||
*
|
*
|
||||||
* Returns:
|
* Returns:
|
||||||
*\li ISC_R_SUCCESS
|
*\li ISC_R_SUCCESS
|
||||||
*\li ISC_R_NOMEMORY
|
*\li return codes from dns_name_fromtext()
|
||||||
*/
|
*/
|
||||||
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
|
|||||||
@@ -15,15 +15,12 @@
|
|||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <isc/lang.h>
|
|
||||||
#include <isc/types.h>
|
#include <isc/types.h>
|
||||||
|
|
||||||
#include <dns/transport.h>
|
#include <dns/transport.h>
|
||||||
|
|
||||||
#include <isccfg/cfg.h>
|
#include <isccfg/cfg.h>
|
||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
named_transports_fromconfig(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
named_transports_fromconfig(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||||
isc_mem_t *mctx, dns_transport_list_t **listp);
|
isc_mem_t *mctx, dns_transport_list_t **listp);
|
||||||
@@ -39,5 +36,3 @@ named_transports_fromconfig(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
* \li 'listp' is not NULL, and '*listp' is NULL
|
* \li 'listp' is not NULL, and '*listp' is NULL
|
||||||
*
|
*
|
||||||
*/
|
*/
|
||||||
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
|
|||||||
@@ -15,11 +15,8 @@
|
|||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <isc/lang.h>
|
|
||||||
#include <isc/types.h>
|
#include <isc/types.h>
|
||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
named_tsigkeyring_fromconfig(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
named_tsigkeyring_fromconfig(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||||
isc_mem_t *mctx, dns_tsigkeyring_t **ringp);
|
isc_mem_t *mctx, dns_tsigkeyring_t **ringp);
|
||||||
@@ -35,7 +32,6 @@ named_tsigkeyring_fromconfig(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
*
|
*
|
||||||
* Returns:
|
* Returns:
|
||||||
* \li ISC_R_SUCCESS
|
* \li ISC_R_SUCCESS
|
||||||
* \li ISC_R_NOMEMORY
|
* \li DNS_R_BADALG
|
||||||
|
* \li return codes from dns_name_fromtext()
|
||||||
*/
|
*/
|
||||||
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
|
|||||||
@@ -17,14 +17,11 @@
|
|||||||
|
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
|
|
||||||
#include <isc/lang.h>
|
|
||||||
#include <isc/types.h>
|
#include <isc/types.h>
|
||||||
|
|
||||||
#include <isccfg/aclconf.h>
|
#include <isccfg/aclconf.h>
|
||||||
#include <isccfg/cfg.h>
|
#include <isccfg/cfg.h>
|
||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||||
const cfg_obj_t *zconfig, cfg_aclconfctx_t *ac,
|
const cfg_obj_t *zconfig, cfg_aclconfctx_t *ac,
|
||||||
@@ -76,5 +73,3 @@ named_zone_configure_writeable_dlz(dns_dlzdb_t *dlzdatabase, dns_zone_t *zone,
|
|||||||
* \li 'rdclass' to be a valid rdataclass
|
* \li 'rdclass' to be a valid rdataclass
|
||||||
* \li 'name' to be a valid zone origin name
|
* \li 'name' to be a valid zone origin name
|
||||||
*/
|
*/
|
||||||
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
|
|||||||
+3
-8
@@ -33,6 +33,7 @@
|
|||||||
#include <isc/fips.h>
|
#include <isc/fips.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/httpd.h>
|
#include <isc/httpd.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/managers.h>
|
#include <isc/managers.h>
|
||||||
#include <isc/netmgr.h>
|
#include <isc/netmgr.h>
|
||||||
#include <isc/os.h>
|
#include <isc/os.h>
|
||||||
@@ -47,6 +48,7 @@
|
|||||||
|
|
||||||
#include <dns/dispatch.h>
|
#include <dns/dispatch.h>
|
||||||
#include <dns/dyndb.h>
|
#include <dns/dyndb.h>
|
||||||
|
#include <dns/lib.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/resolver.h>
|
#include <dns/resolver.h>
|
||||||
#include <dns/view.h>
|
#include <dns/view.h>
|
||||||
@@ -1414,14 +1416,7 @@ named_smf_get_instance(char **ins_name, int debug, isc_mem_t *mctx) {
|
|||||||
return ISC_R_FAILURE;
|
return ISC_R_FAILURE;
|
||||||
}
|
}
|
||||||
|
|
||||||
if ((instance = isc_mem_allocate(mctx, namelen + 1)) == NULL) {
|
instance = isc_mem_allocate(mctx, namelen + 1);
|
||||||
UNEXPECTED_ERROR("named_smf_get_instance memory "
|
|
||||||
"allocation failed: %s",
|
|
||||||
isc_result_totext(ISC_R_NOMEMORY));
|
|
||||||
scf_handle_destroy(h);
|
|
||||||
return ISC_R_FAILURE;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (scf_myname(h, instance, namelen + 1) == -1) {
|
if (scf_myname(h, instance, namelen + 1) == -1) {
|
||||||
if (debug) {
|
if (debug) {
|
||||||
UNEXPECTED_ERROR("scf_myname() failed: %s",
|
UNEXPECTED_ERROR("scf_myname() failed: %s",
|
||||||
|
|||||||
+254
-156
@@ -140,6 +140,15 @@
|
|||||||
#include <named/smf_globals.h>
|
#include <named/smf_globals.h>
|
||||||
#endif /* ifdef HAVE_LIBSCF */
|
#endif /* ifdef HAVE_LIBSCF */
|
||||||
|
|
||||||
|
/* On DragonFly BSD the header does not provide jemalloc API */
|
||||||
|
#if defined(HAVE_MALLOC_NP_H) && !defined(__DragonFly__)
|
||||||
|
#include <malloc_np.h>
|
||||||
|
#define JEMALLOC_API_SUPPORTED 1
|
||||||
|
#elif defined(HAVE_JEMALLOC)
|
||||||
|
#include <jemalloc/jemalloc.h>
|
||||||
|
#define JEMALLOC_API_SUPPORTED 1
|
||||||
|
#endif
|
||||||
|
|
||||||
#ifdef HAVE_LMDB
|
#ifdef HAVE_LMDB
|
||||||
#include <lmdb.h>
|
#include <lmdb.h>
|
||||||
#define configure_newzones configure_newzones_db
|
#define configure_newzones configure_newzones_db
|
||||||
@@ -358,6 +367,22 @@ typedef struct {
|
|||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
} ns_dzarg_t;
|
} ns_dzarg_t;
|
||||||
|
|
||||||
|
typedef enum {
|
||||||
|
MEMPROF_UNSUPPORTED = 0x00,
|
||||||
|
MEMPROF_INACTIVE = 0x01,
|
||||||
|
MEMPROF_FAILING = 0x02,
|
||||||
|
MEMPROF_OFF = 0x03,
|
||||||
|
MEMPROF_ON = 0x04,
|
||||||
|
} memprof_status;
|
||||||
|
|
||||||
|
static const char *memprof_status_text[] = {
|
||||||
|
[MEMPROF_UNSUPPORTED] = "UNSUPPORTED",
|
||||||
|
[MEMPROF_INACTIVE] = "INACTIVE",
|
||||||
|
[MEMPROF_FAILING] = "FAILING",
|
||||||
|
[MEMPROF_OFF] = "OFF",
|
||||||
|
[MEMPROF_ON] = "ON",
|
||||||
|
};
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* These zones should not leak onto the Internet.
|
* These zones should not leak onto the Internet.
|
||||||
*/
|
*/
|
||||||
@@ -584,51 +609,6 @@ configure_view_acl(const cfg_obj_t *vconfig, const cfg_obj_t *config,
|
|||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
/*%
|
|
||||||
* Configure a sortlist at '*aclp'. Essentially the same as
|
|
||||||
* configure_view_acl() except it calls cfg_acl_fromconfig with a
|
|
||||||
* nest_level value of 2.
|
|
||||||
*/
|
|
||||||
static isc_result_t
|
|
||||||
configure_view_sortlist(const cfg_obj_t *vconfig, const cfg_obj_t *config,
|
|
||||||
cfg_aclconfctx_t *actx, isc_mem_t *mctx,
|
|
||||||
dns_acl_t **aclp) {
|
|
||||||
isc_result_t result;
|
|
||||||
const cfg_obj_t *maps[3];
|
|
||||||
const cfg_obj_t *aclobj = NULL;
|
|
||||||
int i = 0;
|
|
||||||
|
|
||||||
if (*aclp != NULL) {
|
|
||||||
dns_acl_detach(aclp);
|
|
||||||
}
|
|
||||||
if (vconfig != NULL) {
|
|
||||||
maps[i++] = cfg_tuple_get(vconfig, "options");
|
|
||||||
}
|
|
||||||
if (config != NULL) {
|
|
||||||
const cfg_obj_t *options = NULL;
|
|
||||||
(void)cfg_map_get(config, "options", &options);
|
|
||||||
if (options != NULL) {
|
|
||||||
maps[i++] = options;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
maps[i] = NULL;
|
|
||||||
|
|
||||||
(void)named_config_get(maps, "sortlist", &aclobj);
|
|
||||||
if (aclobj == NULL) {
|
|
||||||
return ISC_R_SUCCESS;
|
|
||||||
}
|
|
||||||
|
|
||||||
/*
|
|
||||||
* Use a nest level of 3 for the "top level" of the sortlist;
|
|
||||||
* this means each entry in the top three levels will be stored
|
|
||||||
* as lists of separate, nested ACLs, rather than merged together
|
|
||||||
* into IP tables as is usually done with ACLs.
|
|
||||||
*/
|
|
||||||
result = cfg_acl_fromconfig(aclobj, config, actx, mctx, 3, aclp);
|
|
||||||
|
|
||||||
return result;
|
|
||||||
}
|
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
configure_view_nametable(const cfg_obj_t *vconfig, const cfg_obj_t *config,
|
configure_view_nametable(const cfg_obj_t *vconfig, const cfg_obj_t *config,
|
||||||
const char *confname, const char *conftuplename,
|
const char *confname, const char *conftuplename,
|
||||||
@@ -684,7 +664,7 @@ configure_view_nametable(const cfg_obj_t *vconfig, const cfg_obj_t *config,
|
|||||||
str = cfg_obj_asstring(nameobj);
|
str = cfg_obj_asstring(nameobj);
|
||||||
isc_buffer_constinit(&b, str, strlen(str));
|
isc_buffer_constinit(&b, str, strlen(str));
|
||||||
isc_buffer_add(&b, strlen(str));
|
isc_buffer_add(&b, strlen(str));
|
||||||
CHECK(dns_name_fromtext(name, &b, dns_rootname, 0, NULL));
|
CHECK(dns_name_fromtext(name, &b, dns_rootname, 0));
|
||||||
result = dns_nametree_add(*ntp, name, true);
|
result = dns_nametree_add(*ntp, name, true);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(nameobj, ISC_LOG_ERROR,
|
cfg_obj_log(nameobj, ISC_LOG_ERROR,
|
||||||
@@ -744,7 +724,7 @@ ta_fromconfig(const cfg_obj_t *key, bool *initialp, const char **namestrp,
|
|||||||
name = dns_fixedname_initname(&fname);
|
name = dns_fixedname_initname(&fname);
|
||||||
isc_buffer_constinit(&namebuf, namestr, strlen(namestr));
|
isc_buffer_constinit(&namebuf, namestr, strlen(namestr));
|
||||||
isc_buffer_add(&namebuf, strlen(namestr));
|
isc_buffer_add(&namebuf, strlen(namestr));
|
||||||
CHECK(dns_name_fromtext(name, &namebuf, dns_rootname, 0, NULL));
|
CHECK(dns_name_fromtext(name, &namebuf, dns_rootname, 0));
|
||||||
|
|
||||||
if (*initialp) {
|
if (*initialp) {
|
||||||
atstr = cfg_obj_asstring(cfg_tuple_get(key, "anchortype"));
|
atstr = cfg_obj_asstring(cfg_tuple_get(key, "anchortype"));
|
||||||
@@ -933,7 +913,7 @@ process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
|
|||||||
isc_buffer_constinit(&b, namestr, strlen(namestr));
|
isc_buffer_constinit(&b, namestr, strlen(namestr));
|
||||||
isc_buffer_add(&b, strlen(namestr));
|
isc_buffer_add(&b, strlen(namestr));
|
||||||
keyname = dns_fixedname_initname(&fkeyname);
|
keyname = dns_fixedname_initname(&fkeyname);
|
||||||
result = dns_name_fromtext(keyname, &b, dns_rootname, 0, NULL);
|
result = dns_name_fromtext(keyname, &b, dns_rootname, 0);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
@@ -949,15 +929,6 @@ process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
|
|||||||
initializing ? "initial-key" : "static-key",
|
initializing ? "initial-key" : "static-key",
|
||||||
namestr, isc_result_totext(result));
|
namestr, isc_result_totext(result));
|
||||||
return ISC_R_SUCCESS;
|
return ISC_R_SUCCESS;
|
||||||
case DST_R_NOCRYPTO:
|
|
||||||
/*
|
|
||||||
* Crypto support is not available.
|
|
||||||
*/
|
|
||||||
cfg_obj_log(key, ISC_LOG_ERROR,
|
|
||||||
"ignoring %s for '%s': no crypto support",
|
|
||||||
initializing ? "initial-key" : "static-key",
|
|
||||||
namestr);
|
|
||||||
return result;
|
|
||||||
default:
|
default:
|
||||||
/*
|
/*
|
||||||
* Something unexpected happened; we have no choice but to
|
* Something unexpected happened; we have no choice but to
|
||||||
@@ -1039,9 +1010,6 @@ cleanup:
|
|||||||
if (secroots != NULL) {
|
if (secroots != NULL) {
|
||||||
dns_keytable_detach(&secroots);
|
dns_keytable_detach(&secroots);
|
||||||
}
|
}
|
||||||
if (result == DST_R_NOCRYPTO) {
|
|
||||||
result = ISC_R_SUCCESS;
|
|
||||||
}
|
|
||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1338,7 +1306,7 @@ configure_order(dns_order_t *order, const cfg_obj_t *ent) {
|
|||||||
isc_buffer_add(&b, strlen(str));
|
isc_buffer_add(&b, strlen(str));
|
||||||
dns_fixedname_init(&fixed);
|
dns_fixedname_init(&fixed);
|
||||||
result = dns_name_fromtext(dns_fixedname_name(&fixed), &b, dns_rootname,
|
result = dns_name_fromtext(dns_fixedname_name(&fixed), &b, dns_rootname,
|
||||||
0, NULL);
|
0);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
@@ -1362,15 +1330,12 @@ configure_order(dns_order_t *order, const cfg_obj_t *ent) {
|
|||||||
* explicit entry for "." when the name is "*".
|
* explicit entry for "." when the name is "*".
|
||||||
*/
|
*/
|
||||||
if (addroot) {
|
if (addroot) {
|
||||||
result = dns_order_add(order, dns_rootname, rdtype, rdclass,
|
dns_order_add(order, dns_rootname, rdtype, rdclass, mode);
|
||||||
mode);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
return result;
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return dns_order_add(order, dns_fixedname_name(&fixed), rdtype, rdclass,
|
dns_order_add(order, dns_fixedname_name(&fixed), rdtype, rdclass, mode);
|
||||||
mode);
|
|
||||||
|
return ISC_R_SUCCESS;
|
||||||
}
|
}
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
@@ -1626,7 +1591,7 @@ disable_algorithms(const cfg_obj_t *disabled, dns_resolver_t *resolver) {
|
|||||||
str = cfg_obj_asstring(cfg_tuple_get(disabled, "name"));
|
str = cfg_obj_asstring(cfg_tuple_get(disabled, "name"));
|
||||||
isc_buffer_constinit(&b, str, strlen(str));
|
isc_buffer_constinit(&b, str, strlen(str));
|
||||||
isc_buffer_add(&b, strlen(str));
|
isc_buffer_add(&b, strlen(str));
|
||||||
CHECK(dns_name_fromtext(name, &b, dns_rootname, 0, NULL));
|
CHECK(dns_name_fromtext(name, &b, dns_rootname, 0));
|
||||||
|
|
||||||
algorithms = cfg_tuple_get(disabled, "algorithms");
|
algorithms = cfg_tuple_get(disabled, "algorithms");
|
||||||
for (element = cfg_list_first(algorithms); element != NULL;
|
for (element = cfg_list_first(algorithms); element != NULL;
|
||||||
@@ -1669,7 +1634,7 @@ disable_ds_digests(const cfg_obj_t *disabled, dns_resolver_t *resolver) {
|
|||||||
str = cfg_obj_asstring(cfg_tuple_get(disabled, "name"));
|
str = cfg_obj_asstring(cfg_tuple_get(disabled, "name"));
|
||||||
isc_buffer_constinit(&b, str, strlen(str));
|
isc_buffer_constinit(&b, str, strlen(str));
|
||||||
isc_buffer_add(&b, strlen(str));
|
isc_buffer_add(&b, strlen(str));
|
||||||
CHECK(dns_name_fromtext(name, &b, dns_rootname, 0, NULL));
|
CHECK(dns_name_fromtext(name, &b, dns_rootname, 0));
|
||||||
|
|
||||||
digests = cfg_tuple_get(disabled, "digests");
|
digests = cfg_tuple_get(disabled, "digests");
|
||||||
for (element = cfg_list_first(digests); element != NULL;
|
for (element = cfg_list_first(digests); element != NULL;
|
||||||
@@ -1713,7 +1678,7 @@ on_disable_list(const cfg_obj_t *disablelist, dns_name_t *zonename) {
|
|||||||
str = cfg_obj_asstring(value);
|
str = cfg_obj_asstring(value);
|
||||||
isc_buffer_constinit(&b, str, strlen(str));
|
isc_buffer_constinit(&b, str, strlen(str));
|
||||||
isc_buffer_add(&b, strlen(str));
|
isc_buffer_add(&b, strlen(str));
|
||||||
result = dns_name_fromtext(name, &b, dns_rootname, 0, NULL);
|
result = dns_name_fromtext(name, &b, dns_rootname, 0);
|
||||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||||
if (dns_name_equal(name, zonename)) {
|
if (dns_name_equal(name, zonename)) {
|
||||||
return true;
|
return true;
|
||||||
@@ -1729,7 +1694,7 @@ check_dbtype(dns_zone_t *zone, unsigned int dbtypec, const char **dbargv,
|
|||||||
unsigned int i;
|
unsigned int i;
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
isc_result_t result = ISC_R_SUCCESS;
|
||||||
|
|
||||||
CHECK(dns_zone_getdbtype(zone, &argv, mctx));
|
dns_zone_getdbtype(zone, &argv, mctx);
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Check that all the arguments match.
|
* Check that all the arguments match.
|
||||||
@@ -1896,9 +1861,9 @@ dns64_reverse(dns_view_t *view, isc_mem_t *mctx, isc_netaddr_t *na,
|
|||||||
name = dns_fixedname_initname(&fixed);
|
name = dns_fixedname_initname(&fixed);
|
||||||
isc_buffer_constinit(&b, reverse, strlen(reverse));
|
isc_buffer_constinit(&b, reverse, strlen(reverse));
|
||||||
isc_buffer_add(&b, strlen(reverse));
|
isc_buffer_add(&b, strlen(reverse));
|
||||||
CHECK(dns_name_fromtext(name, &b, dns_rootname, 0, NULL));
|
CHECK(dns_name_fromtext(name, &b, dns_rootname, 0));
|
||||||
dns_zone_create(&zone, mctx, 0);
|
dns_zone_create(&zone, mctx, 0);
|
||||||
CHECK(dns_zone_setorigin(zone, name));
|
dns_zone_setorigin(zone, name);
|
||||||
dns_zone_setview(zone, view);
|
dns_zone_setview(zone, view);
|
||||||
CHECK(dns_zonemgr_managezone(named_g_server->zonemgr, zone));
|
CHECK(dns_zonemgr_managezone(named_g_server->zonemgr, zone));
|
||||||
dns_zone_setclass(zone, view->rdclass);
|
dns_zone_setclass(zone, view->rdclass);
|
||||||
@@ -2780,7 +2745,7 @@ configure_catz_zone(dns_view_t *view, dns_view_t *pview,
|
|||||||
dns_name_t origin;
|
dns_name_t origin;
|
||||||
dns_catz_options_t *opts;
|
dns_catz_options_t *opts;
|
||||||
|
|
||||||
dns_name_init(&origin, NULL);
|
dns_name_init(&origin);
|
||||||
catz_obj = cfg_listelt_value(element);
|
catz_obj = cfg_listelt_value(element);
|
||||||
|
|
||||||
str = cfg_obj_asstring(cfg_tuple_get(catz_obj, "zone name"));
|
str = cfg_obj_asstring(cfg_tuple_get(catz_obj, "zone name"));
|
||||||
@@ -2824,8 +2789,8 @@ configure_catz_zone(dns_view_t *view, dns_view_t *pview,
|
|||||||
obj = cfg_tuple_get(catz_obj, "default-primaries");
|
obj = cfg_tuple_get(catz_obj, "default-primaries");
|
||||||
}
|
}
|
||||||
if (obj != NULL && cfg_obj_istuple(obj)) {
|
if (obj != NULL && cfg_obj_istuple(obj)) {
|
||||||
result = named_config_getipandkeylist(
|
result = named_config_getipandkeylist(config, obj, view->mctx,
|
||||||
config, "primaries", obj, view->mctx, &opts->masters);
|
&opts->masters);
|
||||||
}
|
}
|
||||||
|
|
||||||
obj = cfg_tuple_get(catz_obj, "in-memory");
|
obj = cfg_tuple_get(catz_obj, "in-memory");
|
||||||
@@ -3123,7 +3088,7 @@ add_ns(dns_db_t *db, dns_dbversion_t *version, const dns_name_t *name,
|
|||||||
ns.common.rdtype = dns_rdatatype_ns;
|
ns.common.rdtype = dns_rdatatype_ns;
|
||||||
ns.common.rdclass = dns_db_class(db);
|
ns.common.rdclass = dns_db_class(db);
|
||||||
ns.mctx = NULL;
|
ns.mctx = NULL;
|
||||||
dns_name_init(&ns.name, NULL);
|
dns_name_init(&ns.name);
|
||||||
dns_name_clone(nsname, &ns.name);
|
dns_name_clone(nsname, &ns.name);
|
||||||
CHECK(dns_rdata_fromstruct(&rdata, dns_db_class(db), dns_rdatatype_ns,
|
CHECK(dns_rdata_fromstruct(&rdata, dns_db_class(db), dns_rdatatype_ns,
|
||||||
&ns, &b));
|
&ns, &b));
|
||||||
@@ -3268,7 +3233,7 @@ create_empty_zone(dns_zone_t *pzone, dns_name_t *name, dns_view_t *view,
|
|||||||
|
|
||||||
if (pzone == NULL) {
|
if (pzone == NULL) {
|
||||||
CHECK(dns_zonemgr_createzone(named_g_server->zonemgr, &zone));
|
CHECK(dns_zonemgr_createzone(named_g_server->zonemgr, &zone));
|
||||||
CHECK(dns_zone_setorigin(zone, name));
|
dns_zone_setorigin(zone, name);
|
||||||
CHECK(dns_zonemgr_managezone(named_g_server->zonemgr, zone));
|
CHECK(dns_zonemgr_managezone(named_g_server->zonemgr, zone));
|
||||||
if (db == NULL) {
|
if (db == NULL) {
|
||||||
dns_zone_setdbtype(zone, empty_dbtypec, empty_dbtype);
|
dns_zone_setdbtype(zone, empty_dbtypec, empty_dbtype);
|
||||||
@@ -3375,7 +3340,7 @@ create_ipv4only_zone(dns_zone_t *pzone, dns_view_t *view,
|
|||||||
* Create the actual zone.
|
* Create the actual zone.
|
||||||
*/
|
*/
|
||||||
dns_zone_create(&zone, mctx, 0);
|
dns_zone_create(&zone, mctx, 0);
|
||||||
CHECK(dns_zone_setorigin(zone, name));
|
dns_zone_setorigin(zone, name);
|
||||||
CHECK(dns_zonemgr_managezone(named_g_server->zonemgr, zone));
|
CHECK(dns_zonemgr_managezone(named_g_server->zonemgr, zone));
|
||||||
dns_zone_setclass(zone, view->rdclass);
|
dns_zone_setclass(zone, view->rdclass);
|
||||||
dns_zone_settype(zone, dns_zone_primary);
|
dns_zone_settype(zone, dns_zone_primary);
|
||||||
@@ -3958,11 +3923,6 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
|||||||
const cfg_obj_t *name, *search = NULL;
|
const cfg_obj_t *name, *search = NULL;
|
||||||
char *s = isc_mem_strdup(mctx, cfg_obj_asstring(obj));
|
char *s = isc_mem_strdup(mctx, cfg_obj_asstring(obj));
|
||||||
|
|
||||||
if (s == NULL) {
|
|
||||||
result = ISC_R_NOMEMORY;
|
|
||||||
goto cleanup;
|
|
||||||
}
|
|
||||||
|
|
||||||
result = isc_commandline_strtoargv(mctx, s, &dlzargc,
|
result = isc_commandline_strtoargv(mctx, s, &dlzargc,
|
||||||
&dlzargv, 0);
|
&dlzargv, 0);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
@@ -4192,12 +4152,9 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
|||||||
dns64options |= DNS_DNS64_BREAK_DNSSEC;
|
dns64options |= DNS_DNS64_BREAK_DNSSEC;
|
||||||
}
|
}
|
||||||
|
|
||||||
result = dns_dns64_create(mctx, &na, prefixlen, sp,
|
dns_dns64_create(mctx, &na, prefixlen, sp, clients,
|
||||||
clients, mapped, excluded,
|
mapped, excluded, dns64options,
|
||||||
dns64options, &dns64);
|
&dns64);
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
goto cleanup;
|
|
||||||
}
|
|
||||||
dns_dns64_append(&view->dns64, dns64);
|
dns_dns64_append(&view->dns64, dns64);
|
||||||
view->dns64cnt++;
|
view->dns64cnt++;
|
||||||
result = dns64_reverse(view, mctx, &na, prefixlen,
|
result = dns64_reverse(view, mctx, &na, prefixlen,
|
||||||
@@ -4746,6 +4703,19 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
|||||||
dns_view_settransports(view, transports);
|
dns_view_settransports(view, transports);
|
||||||
dns_transport_list_detach(&transports);
|
dns_transport_list_detach(&transports);
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Configure SIG(0) check limits when matching a DNS message to a view.
|
||||||
|
*/
|
||||||
|
obj = NULL;
|
||||||
|
result = named_config_get(maps, "sig0key-checks-limit", &obj);
|
||||||
|
INSIST(result == ISC_R_SUCCESS);
|
||||||
|
view->sig0key_checks_limit = cfg_obj_asuint32(obj);
|
||||||
|
|
||||||
|
obj = NULL;
|
||||||
|
result = named_config_get(maps, "sig0message-checks-limit", &obj);
|
||||||
|
INSIST(result == ISC_R_SUCCESS);
|
||||||
|
view->sig0message_checks_limit = cfg_obj_asuint32(obj);
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Configure the view's TSIG keys.
|
* Configure the view's TSIG keys.
|
||||||
*/
|
*/
|
||||||
@@ -4793,7 +4763,7 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
|||||||
dns_peerlist_t *newpeers = NULL;
|
dns_peerlist_t *newpeers = NULL;
|
||||||
|
|
||||||
(void)named_config_get(cfgmaps, "server", &peers);
|
(void)named_config_get(cfgmaps, "server", &peers);
|
||||||
CHECK(dns_peerlist_new(mctx, &newpeers));
|
dns_peerlist_new(mctx, &newpeers);
|
||||||
for (element = cfg_list_first(peers); element != NULL;
|
for (element = cfg_list_first(peers); element != NULL;
|
||||||
element = cfg_list_next(element))
|
element = cfg_list_next(element))
|
||||||
{
|
{
|
||||||
@@ -4815,7 +4785,7 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
|||||||
const cfg_obj_t *rrsetorder = NULL;
|
const cfg_obj_t *rrsetorder = NULL;
|
||||||
|
|
||||||
(void)named_config_get(maps, "rrset-order", &rrsetorder);
|
(void)named_config_get(maps, "rrset-order", &rrsetorder);
|
||||||
CHECK(dns_order_create(mctx, &order));
|
dns_order_create(mctx, &order);
|
||||||
for (element = cfg_list_first(rrsetorder); element != NULL;
|
for (element = cfg_list_first(rrsetorder); element != NULL;
|
||||||
element = cfg_list_next(element))
|
element = cfg_list_next(element))
|
||||||
{
|
{
|
||||||
@@ -5121,12 +5091,6 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
|||||||
"except-from", named_g_mctx,
|
"except-from", named_g_mctx,
|
||||||
&view->answernames_exclude));
|
&view->answernames_exclude));
|
||||||
|
|
||||||
/*
|
|
||||||
* Configure sortlist, if set
|
|
||||||
*/
|
|
||||||
CHECK(configure_view_sortlist(vconfig, config, actx, named_g_mctx,
|
|
||||||
&view->sortlist));
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Configure default allow-update and allow-update-forwarding ACLs,
|
* Configure default allow-update and allow-update-forwarding ACLs,
|
||||||
* so they can be inherited by zones. (XXX: These are not
|
* so they can be inherited by zones. (XXX: These are not
|
||||||
@@ -5367,9 +5331,9 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
|||||||
|
|
||||||
if (dctx == NULL) {
|
if (dctx == NULL) {
|
||||||
const void *hashinit = isc_hash_get_initializer();
|
const void *hashinit = isc_hash_get_initializer();
|
||||||
CHECK(dns_dyndb_createctx(mctx, hashinit, view,
|
dns_dyndb_createctx(mctx, hashinit, view,
|
||||||
named_g_server->zonemgr,
|
named_g_server->zonemgr,
|
||||||
named_g_loopmgr, &dctx));
|
named_g_loopmgr, &dctx);
|
||||||
}
|
}
|
||||||
|
|
||||||
CHECK(configure_dyndb(dyndb, mctx, dctx));
|
CHECK(configure_dyndb(dyndb, mctx, dctx));
|
||||||
@@ -5912,8 +5876,8 @@ configure_alternates(const cfg_obj_t *config, dns_view_t *view,
|
|||||||
isc_buffer_constinit(&buffer, str, strlen(str));
|
isc_buffer_constinit(&buffer, str, strlen(str));
|
||||||
isc_buffer_add(&buffer, strlen(str));
|
isc_buffer_add(&buffer, strlen(str));
|
||||||
name = dns_fixedname_initname(&fixed);
|
name = dns_fixedname_initname(&fixed);
|
||||||
CHECK(dns_name_fromtext(name, &buffer, dns_rootname, 0,
|
CHECK(dns_name_fromtext(name, &buffer, dns_rootname,
|
||||||
NULL));
|
0));
|
||||||
|
|
||||||
portobj = cfg_tuple_get(alternate, "port");
|
portobj = cfg_tuple_get(alternate, "port");
|
||||||
if (cfg_obj_isuint32(portobj)) {
|
if (cfg_obj_isuint32(portobj)) {
|
||||||
@@ -5968,7 +5932,7 @@ validate_tls(const cfg_obj_t *config, dns_view_t *view, const cfg_obj_t *obj,
|
|||||||
|
|
||||||
if (name != NULL && *name == NULL) {
|
if (name != NULL && *name == NULL) {
|
||||||
*name = isc_mem_get(view->mctx, sizeof(dns_name_t));
|
*name = isc_mem_get(view->mctx, sizeof(dns_name_t));
|
||||||
dns_name_init(*name, NULL);
|
dns_name_init(*name);
|
||||||
dns_name_dup(nm, view->mctx, *name);
|
dns_name_dup(nm, view->mctx, *name);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -6211,12 +6175,8 @@ create_view(const cfg_obj_t *vconfig, dns_viewlist_t *viewlist,
|
|||||||
}
|
}
|
||||||
INSIST(view == NULL);
|
INSIST(view == NULL);
|
||||||
|
|
||||||
result = dns_view_create(named_g_mctx, named_g_loopmgr,
|
dns_view_create(named_g_mctx, named_g_loopmgr, named_g_dispatchmgr,
|
||||||
named_g_dispatchmgr, viewclass, viewname,
|
viewclass, viewname, &view);
|
||||||
&view);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
return result;
|
|
||||||
}
|
|
||||||
|
|
||||||
isc_nonce_buf(view->secret, sizeof(view->secret));
|
isc_nonce_buf(view->secret, sizeof(view->secret));
|
||||||
|
|
||||||
@@ -6272,7 +6232,7 @@ configure_zone(const cfg_obj_t *config, const cfg_obj_t *zconfig,
|
|||||||
isc_buffer_add(&buffer, strlen(zname));
|
isc_buffer_add(&buffer, strlen(zname));
|
||||||
dns_fixedname_init(&fixorigin);
|
dns_fixedname_init(&fixorigin);
|
||||||
CHECK(dns_name_fromtext(dns_fixedname_name(&fixorigin), &buffer,
|
CHECK(dns_name_fromtext(dns_fixedname_name(&fixorigin), &buffer,
|
||||||
dns_rootname, 0, NULL));
|
dns_rootname, 0));
|
||||||
origin = dns_fixedname_name(&fixorigin);
|
origin = dns_fixedname_name(&fixorigin);
|
||||||
|
|
||||||
CHECK(named_config_getclass(cfg_tuple_get(zconfig, "class"),
|
CHECK(named_config_getclass(cfg_tuple_get(zconfig, "class"),
|
||||||
@@ -6420,7 +6380,7 @@ configure_zone(const cfg_obj_t *config, const cfg_obj_t *zconfig,
|
|||||||
} else {
|
} else {
|
||||||
CHECK(dns_zonemgr_createzone(named_g_server->zonemgr,
|
CHECK(dns_zonemgr_createzone(named_g_server->zonemgr,
|
||||||
&zone));
|
&zone));
|
||||||
CHECK(dns_zone_setorigin(zone, origin));
|
dns_zone_setorigin(zone, origin);
|
||||||
dns_zone_setview(zone, view);
|
dns_zone_setview(zone, view);
|
||||||
CHECK(dns_zonemgr_managezone(named_g_server->zonemgr,
|
CHECK(dns_zonemgr_managezone(named_g_server->zonemgr,
|
||||||
zone));
|
zone));
|
||||||
@@ -6523,7 +6483,7 @@ configure_zone(const cfg_obj_t *config, const cfg_obj_t *zconfig,
|
|||||||
* to create a new one.
|
* to create a new one.
|
||||||
*/
|
*/
|
||||||
CHECK(dns_zonemgr_createzone(named_g_server->zonemgr, &zone));
|
CHECK(dns_zonemgr_createzone(named_g_server->zonemgr, &zone));
|
||||||
CHECK(dns_zone_setorigin(zone, origin));
|
dns_zone_setorigin(zone, origin);
|
||||||
dns_zone_setview(zone, view);
|
dns_zone_setview(zone, view);
|
||||||
CHECK(dns_zonemgr_managezone(named_g_server->zonemgr, zone));
|
CHECK(dns_zonemgr_managezone(named_g_server->zonemgr, zone));
|
||||||
dns_zone_setstats(zone, named_g_server->zonestats);
|
dns_zone_setstats(zone, named_g_server->zonestats);
|
||||||
@@ -6581,7 +6541,7 @@ configure_zone(const cfg_obj_t *config, const cfg_obj_t *zconfig,
|
|||||||
if (raw == NULL) {
|
if (raw == NULL) {
|
||||||
dns_zone_create(&raw, dns_zone_getmem(zone),
|
dns_zone_create(&raw, dns_zone_getmem(zone),
|
||||||
dns_zone_gettid(zone));
|
dns_zone_gettid(zone));
|
||||||
CHECK(dns_zone_setorigin(raw, origin));
|
dns_zone_setorigin(raw, origin);
|
||||||
dns_zone_setview(raw, view);
|
dns_zone_setview(raw, view);
|
||||||
dns_zone_setstats(raw, named_g_server->zonestats);
|
dns_zone_setstats(raw, named_g_server->zonestats);
|
||||||
CHECK(dns_zone_link(zone, raw));
|
CHECK(dns_zone_link(zone, raw));
|
||||||
@@ -6682,14 +6642,14 @@ add_keydata_zone(dns_view_t *view, const char *directory, isc_mem_t *mctx) {
|
|||||||
|
|
||||||
/* No existing keydata zone was found; create one */
|
/* No existing keydata zone was found; create one */
|
||||||
CHECK(dns_zonemgr_createzone(named_g_server->zonemgr, &zone));
|
CHECK(dns_zonemgr_createzone(named_g_server->zonemgr, &zone));
|
||||||
CHECK(dns_zone_setorigin(zone, dns_rootname));
|
dns_zone_setorigin(zone, dns_rootname);
|
||||||
|
|
||||||
defaultview = (strcmp(view->name, "_default") == 0);
|
defaultview = (strcmp(view->name, "_default") == 0);
|
||||||
CHECK(isc_file_sanitize(
|
CHECK(isc_file_sanitize(
|
||||||
directory, defaultview ? "managed-keys" : view->name,
|
directory, defaultview ? "managed-keys" : view->name,
|
||||||
defaultview ? "bind" : "mkeys", filename, sizeof(filename)));
|
defaultview ? "bind" : "mkeys", filename, sizeof(filename)));
|
||||||
CHECK(dns_zone_setfile(zone, filename, dns_masterformat_text,
|
dns_zone_setfile(zone, filename, dns_masterformat_text,
|
||||||
&dns_master_style_default));
|
&dns_master_style_default);
|
||||||
|
|
||||||
dns_zone_setview(zone, view);
|
dns_zone_setview(zone, view);
|
||||||
dns_zone_settype(zone, dns_zone_key);
|
dns_zone_settype(zone, dns_zone_key);
|
||||||
@@ -6989,7 +6949,7 @@ tat_send(void *arg) {
|
|||||||
result = dns_resolver_createfetch(
|
result = dns_resolver_createfetch(
|
||||||
tat->view->resolver, tatname, dns_rdatatype_null,
|
tat->view->resolver, tatname, dns_rdatatype_null,
|
||||||
domain, &nameservers, NULL, NULL, 0, 0, 0, NULL, NULL,
|
domain, &nameservers, NULL, NULL, 0, 0, 0, NULL, NULL,
|
||||||
tat->loop, tat_done, tat, &tat->rdataset,
|
tat->loop, tat_done, tat, NULL, &tat->rdataset,
|
||||||
&tat->sigrdataset, &tat->fetch);
|
&tat->sigrdataset, &tat->fetch);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -7283,7 +7243,7 @@ configure_session_key(const cfg_obj_t **maps, named_server_t *server,
|
|||||||
isc_buffer_constinit(&buffer, keynamestr, strlen(keynamestr));
|
isc_buffer_constinit(&buffer, keynamestr, strlen(keynamestr));
|
||||||
isc_buffer_add(&buffer, strlen(keynamestr));
|
isc_buffer_add(&buffer, strlen(keynamestr));
|
||||||
keyname = dns_fixedname_initname(&fname);
|
keyname = dns_fixedname_initname(&fname);
|
||||||
result = dns_name_fromtext(keyname, &buffer, dns_rootname, 0, NULL);
|
result = dns_name_fromtext(keyname, &buffer, dns_rootname, 0);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
@@ -7335,7 +7295,7 @@ configure_session_key(const cfg_obj_t **maps, named_server_t *server,
|
|||||||
INSIST(server->session_keybits == 0);
|
INSIST(server->session_keybits == 0);
|
||||||
|
|
||||||
server->session_keyname = isc_mem_get(mctx, sizeof(dns_name_t));
|
server->session_keyname = isc_mem_get(mctx, sizeof(dns_name_t));
|
||||||
dns_name_init(server->session_keyname, NULL);
|
dns_name_init(server->session_keyname);
|
||||||
dns_name_dup(keyname, mctx, server->session_keyname);
|
dns_name_dup(keyname, mctx, server->session_keyname);
|
||||||
|
|
||||||
server->session_keyfile = isc_mem_strdup(mctx, keyfile);
|
server->session_keyfile = isc_mem_strdup(mctx, keyfile);
|
||||||
@@ -7841,8 +7801,7 @@ get_newzone_config(dns_view_t *view, const char *zonename,
|
|||||||
isc_buffer_constinit(&b, zonename, strlen(zonename));
|
isc_buffer_constinit(&b, zonename, strlen(zonename));
|
||||||
isc_buffer_add(&b, strlen(zonename));
|
isc_buffer_add(&b, strlen(zonename));
|
||||||
name = dns_fixedname_initname(&fname);
|
name = dns_fixedname_initname(&fname);
|
||||||
CHECK(dns_name_fromtext(name, &b, dns_rootname, DNS_NAME_DOWNCASE,
|
CHECK(dns_name_fromtext(name, &b, dns_rootname, DNS_NAME_DOWNCASE));
|
||||||
NULL));
|
|
||||||
dns_name_format(name, zname, sizeof(zname));
|
dns_name_format(name, zname, sizeof(zname));
|
||||||
|
|
||||||
key.mv_data = zname;
|
key.mv_data = zname;
|
||||||
@@ -7952,7 +7911,7 @@ load_configuration(const char *filename, named_server_t *server,
|
|||||||
/*
|
/*
|
||||||
* Shut down all dyndb instances.
|
* Shut down all dyndb instances.
|
||||||
*/
|
*/
|
||||||
dns_dyndb_cleanup(false);
|
dns_dyndb_cleanup();
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Parse the global default pseudo-config file.
|
* Parse the global default pseudo-config file.
|
||||||
@@ -8302,20 +8261,8 @@ load_configuration(const char *filename, named_server_t *server,
|
|||||||
/*
|
/*
|
||||||
* Configure sets of UDP query source ports.
|
* Configure sets of UDP query source ports.
|
||||||
*/
|
*/
|
||||||
result = isc_portset_create(named_g_mctx, &v4portset);
|
isc_portset_create(named_g_mctx, &v4portset);
|
||||||
if (result != ISC_R_SUCCESS) {
|
isc_portset_create(named_g_mctx, &v6portset);
|
||||||
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
|
||||||
ISC_LOG_ERROR, "creating UDP/IPv4 port set: %s",
|
|
||||||
isc_result_totext(result));
|
|
||||||
goto cleanup_bindkeys_parser;
|
|
||||||
}
|
|
||||||
result = isc_portset_create(named_g_mctx, &v6portset);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
|
||||||
ISC_LOG_ERROR, "creating UDP/IPv6 port set: %s",
|
|
||||||
isc_result_totext(result));
|
|
||||||
goto cleanup_v4portset;
|
|
||||||
}
|
|
||||||
|
|
||||||
result = isc_net_getudpportrange(AF_INET, &udpport_low, &udpport_high);
|
result = isc_net_getudpportrange(AF_INET, &udpport_low, &udpport_high);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
@@ -8323,7 +8270,7 @@ load_configuration(const char *filename, named_server_t *server,
|
|||||||
ISC_LOG_ERROR,
|
ISC_LOG_ERROR,
|
||||||
"get the default UDP/IPv4 port range: %s",
|
"get the default UDP/IPv4 port range: %s",
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
goto cleanup_v6portset;
|
goto cleanup_portsets;
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_portset_addrange(v4portset, udpport_low, udpport_high);
|
isc_portset_addrange(v4portset, udpport_low, udpport_high);
|
||||||
@@ -8341,7 +8288,7 @@ load_configuration(const char *filename, named_server_t *server,
|
|||||||
ISC_LOG_ERROR,
|
ISC_LOG_ERROR,
|
||||||
"get the default UDP/IPv6 port range: %s",
|
"get the default UDP/IPv6 port range: %s",
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
goto cleanup_v6portset;
|
goto cleanup_portsets;
|
||||||
}
|
}
|
||||||
isc_portset_addrange(v6portset, udpport_low, udpport_high);
|
isc_portset_addrange(v6portset, udpport_low, udpport_high);
|
||||||
if (!ns_server_getoption(server->sctx, NS_SERVER_DISABLE6)) {
|
if (!ns_server_getoption(server->sctx, NS_SERVER_DISABLE6)) {
|
||||||
@@ -8420,7 +8367,7 @@ load_configuration(const char *filename, named_server_t *server,
|
|||||||
} else {
|
} else {
|
||||||
result = named_config_getport(config, "port", &listen_port);
|
result = named_config_getport(config, "port", &listen_port);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
goto cleanup_v6portset;
|
goto cleanup_portsets;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -8467,13 +8414,13 @@ load_configuration(const char *filename, named_server_t *server,
|
|||||||
|
|
||||||
result = named_config_get(maps, "listen-on", &clistenon);
|
result = named_config_get(maps, "listen-on", &clistenon);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
goto cleanup_v6portset;
|
goto cleanup_portsets;
|
||||||
}
|
}
|
||||||
result = listenlist_fromconfig(
|
result = listenlist_fromconfig(
|
||||||
clistenon, config, named_g_aclconfctx, named_g_mctx,
|
clistenon, config, named_g_aclconfctx, named_g_mctx,
|
||||||
AF_INET, server->tlsctx_server_cache, &listenon);
|
AF_INET, server->tlsctx_server_cache, &listenon);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
goto cleanup_v6portset;
|
goto cleanup_portsets;
|
||||||
}
|
}
|
||||||
if (listenon != NULL) {
|
if (listenon != NULL) {
|
||||||
ns_interfacemgr_setlistenon4(server->interfacemgr,
|
ns_interfacemgr_setlistenon4(server->interfacemgr,
|
||||||
@@ -8491,13 +8438,13 @@ load_configuration(const char *filename, named_server_t *server,
|
|||||||
|
|
||||||
result = named_config_get(maps, "listen-on-v6", &clistenon);
|
result = named_config_get(maps, "listen-on-v6", &clistenon);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
goto cleanup_v6portset;
|
goto cleanup_portsets;
|
||||||
}
|
}
|
||||||
result = listenlist_fromconfig(
|
result = listenlist_fromconfig(
|
||||||
clistenon, config, named_g_aclconfctx, named_g_mctx,
|
clistenon, config, named_g_aclconfctx, named_g_mctx,
|
||||||
AF_INET6, server->tlsctx_server_cache, &listenon);
|
AF_INET6, server->tlsctx_server_cache, &listenon);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
goto cleanup_v6portset;
|
goto cleanup_portsets;
|
||||||
}
|
}
|
||||||
if (listenon != NULL) {
|
if (listenon != NULL) {
|
||||||
ns_interfacemgr_setlistenon6(server->interfacemgr,
|
ns_interfacemgr_setlistenon6(server->interfacemgr,
|
||||||
@@ -8527,7 +8474,7 @@ load_configuration(const char *filename, named_server_t *server,
|
|||||||
"unable to listen on any configured "
|
"unable to listen on any configured "
|
||||||
"interfaces");
|
"interfaces");
|
||||||
result = ISC_R_FAILURE;
|
result = ISC_R_FAILURE;
|
||||||
goto cleanup_v6portset;
|
goto cleanup_portsets;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -9334,10 +9281,8 @@ cleanup_keystorelist:
|
|||||||
dns_keystore_detach(&keystore);
|
dns_keystore_detach(&keystore);
|
||||||
}
|
}
|
||||||
|
|
||||||
cleanup_v6portset:
|
cleanup_portsets:
|
||||||
isc_portset_destroy(named_g_mctx, &v6portset);
|
isc_portset_destroy(named_g_mctx, &v6portset);
|
||||||
|
|
||||||
cleanup_v4portset:
|
|
||||||
isc_portset_destroy(named_g_mctx, &v4portset);
|
isc_portset_destroy(named_g_mctx, &v4portset);
|
||||||
|
|
||||||
cleanup_bindkeys_parser:
|
cleanup_bindkeys_parser:
|
||||||
@@ -9645,7 +9590,7 @@ shutdown_server(void *arg) {
|
|||||||
/*
|
/*
|
||||||
* Shut down all dyndb instances.
|
* Shut down all dyndb instances.
|
||||||
*/
|
*/
|
||||||
dns_dyndb_cleanup(true);
|
dns_dyndb_cleanup();
|
||||||
|
|
||||||
while ((nsc = ISC_LIST_HEAD(server->cachelist)) != NULL) {
|
while ((nsc = ISC_LIST_HEAD(server->cachelist)) != NULL) {
|
||||||
ISC_LIST_UNLINK(server->cachelist, nsc, link);
|
ISC_LIST_UNLINK(server->cachelist, nsc, link);
|
||||||
@@ -10150,6 +10095,39 @@ named_server_closelogswanted(void *arg, int signum) {
|
|||||||
isc_async_run(named_g_mainloop, named_server_closelogs, server);
|
isc_async_run(named_g_mainloop, named_server_closelogs, server);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#ifdef JEMALLOC_API_SUPPORTED
|
||||||
|
static isc_result_t
|
||||||
|
memprof_toggle(bool active) {
|
||||||
|
if (mallctl("prof.active", NULL, NULL, &active, sizeof(active)) != 0) {
|
||||||
|
return ISC_R_FAILURE;
|
||||||
|
}
|
||||||
|
|
||||||
|
return ISC_R_SUCCESS;
|
||||||
|
}
|
||||||
|
|
||||||
|
static isc_result_t
|
||||||
|
memprof_dump(void) {
|
||||||
|
if (mallctl("prof.dump", NULL, NULL, NULL, 0) != 0) {
|
||||||
|
return ISC_R_FAILURE;
|
||||||
|
}
|
||||||
|
|
||||||
|
return ISC_R_SUCCESS;
|
||||||
|
}
|
||||||
|
#else
|
||||||
|
static isc_result_t
|
||||||
|
memprof_toggle(bool active) {
|
||||||
|
UNUSED(active);
|
||||||
|
|
||||||
|
return ISC_R_NOTIMPLEMENTED;
|
||||||
|
}
|
||||||
|
|
||||||
|
static isc_result_t
|
||||||
|
memprof_dump(void) {
|
||||||
|
return ISC_R_NOTIMPLEMENTED;
|
||||||
|
}
|
||||||
|
|
||||||
|
#endif /* JEMALLOC_API_SUPPORTED */
|
||||||
|
|
||||||
void
|
void
|
||||||
named_server_scan_interfaces(named_server_t *server) {
|
named_server_scan_interfaces(named_server_t *server) {
|
||||||
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
@@ -11854,7 +11832,7 @@ named_server_flushnode(named_server_t *server, isc_lex_t *lex, bool tree) {
|
|||||||
isc_buffer_constinit(&b, target, strlen(target));
|
isc_buffer_constinit(&b, target, strlen(target));
|
||||||
isc_buffer_add(&b, strlen(target));
|
isc_buffer_add(&b, strlen(target));
|
||||||
name = dns_fixedname_initname(&fixed);
|
name = dns_fixedname_initname(&fixed);
|
||||||
result = dns_name_fromtext(name, &b, dns_rootname, 0, NULL);
|
result = dns_name_fromtext(name, &b, dns_rootname, 0);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
@@ -12022,6 +12000,10 @@ named_server_status(named_server_t *server, isc_buffer_t **text) {
|
|||||||
: "OFF");
|
: "OFF");
|
||||||
CHECK(putstr(text, line));
|
CHECK(putstr(text, line));
|
||||||
|
|
||||||
|
snprintf(line, sizeof(line), "memory profiling is %s\n",
|
||||||
|
named_server_getmemprof());
|
||||||
|
CHECK(putstr(text, line));
|
||||||
|
|
||||||
snprintf(line, sizeof(line), "recursive clients: %u/%u/%u\n",
|
snprintf(line, sizeof(line), "recursive clients: %u/%u/%u\n",
|
||||||
isc_quota_getused(&server->sctx->recursionquota),
|
isc_quota_getused(&server->sctx->recursionquota),
|
||||||
isc_quota_getsoft(&server->sctx->recursionquota),
|
isc_quota_getsoft(&server->sctx->recursionquota),
|
||||||
@@ -12558,7 +12540,7 @@ nzd_setkey(MDB_val *key, dns_name_t *name, char *namebuf, size_t buflen) {
|
|||||||
dns_fixedname_t fixed;
|
dns_fixedname_t fixed;
|
||||||
|
|
||||||
dns_fixedname_init(&fixed);
|
dns_fixedname_init(&fixed);
|
||||||
dns_name_downcase(name, dns_fixedname_name(&fixed), NULL);
|
dns_name_downcase(name, dns_fixedname_name(&fixed));
|
||||||
dns_name_format(dns_fixedname_name(&fixed), namebuf, buflen);
|
dns_name_format(dns_fixedname_name(&fixed), namebuf, buflen);
|
||||||
|
|
||||||
key->mv_data = namebuf;
|
key->mv_data = namebuf;
|
||||||
@@ -12960,7 +12942,7 @@ load_nzf(dns_view_t *view, ns_cfgctx_t *nzcfg) {
|
|||||||
isc_buffer_add(&b, strlen(origin));
|
isc_buffer_add(&b, strlen(origin));
|
||||||
name = dns_fixedname_initname(&fname);
|
name = dns_fixedname_initname(&fname);
|
||||||
CHECK(dns_name_fromtext(name, &b, dns_rootname,
|
CHECK(dns_name_fromtext(name, &b, dns_rootname,
|
||||||
DNS_NAME_DOWNCASE, NULL));
|
DNS_NAME_DOWNCASE));
|
||||||
dns_name_format(name, zname, sizeof(zname));
|
dns_name_format(name, zname, sizeof(zname));
|
||||||
|
|
||||||
key.mv_data = zname;
|
key.mv_data = zname;
|
||||||
@@ -13669,7 +13651,7 @@ named_server_changezone(named_server_t *server, char *command,
|
|||||||
isc_buffer_add(&buf, strlen(zonename));
|
isc_buffer_add(&buf, strlen(zonename));
|
||||||
|
|
||||||
dnsname = dns_fixedname_initname(&fname);
|
dnsname = dns_fixedname_initname(&fname);
|
||||||
CHECK(dns_name_fromtext(dnsname, &buf, dns_rootname, 0, NULL));
|
CHECK(dns_name_fromtext(dnsname, &buf, dns_rootname, 0));
|
||||||
|
|
||||||
if (redirect) {
|
if (redirect) {
|
||||||
if (!dns_name_equal(dnsname, dns_rootname)) {
|
if (!dns_name_equal(dnsname, dns_rootname)) {
|
||||||
@@ -14641,10 +14623,16 @@ named_server_dnssec(named_server_t *server, isc_lex_t *lex,
|
|||||||
/*
|
/*
|
||||||
* Output the DNSSEC status of the key and signing policy.
|
* Output the DNSSEC status of the key and signing policy.
|
||||||
*/
|
*/
|
||||||
|
isc_result_t r;
|
||||||
LOCK(&kasp->lock);
|
LOCK(&kasp->lock);
|
||||||
dns_keymgr_status(kasp, &keys, now, &output[0], sizeof(output));
|
r = dns_keymgr_status(kasp, &keys, now, &output[0],
|
||||||
|
sizeof(output));
|
||||||
UNLOCK(&kasp->lock);
|
UNLOCK(&kasp->lock);
|
||||||
CHECK(putstr(text, output));
|
CHECK(putstr(text, output));
|
||||||
|
if (r != ISC_R_SUCCESS) {
|
||||||
|
CHECK(putstr(text,
|
||||||
|
"\n\nStatus output is truncated..."));
|
||||||
|
}
|
||||||
} else if (checkds) {
|
} else if (checkds) {
|
||||||
/*
|
/*
|
||||||
* Mark DS record has been seen, so it may move to the
|
* Mark DS record has been seen, so it may move to the
|
||||||
@@ -15229,7 +15217,7 @@ named_server_nta(named_server_t *server, isc_lex_t *lex, bool readonly,
|
|||||||
isc_buffer_t b;
|
isc_buffer_t b;
|
||||||
isc_buffer_init(&b, namebuf, strlen(namebuf));
|
isc_buffer_init(&b, namebuf, strlen(namebuf));
|
||||||
isc_buffer_add(&b, strlen(namebuf));
|
isc_buffer_add(&b, strlen(namebuf));
|
||||||
CHECK(dns_name_fromtext(fname, &b, dns_rootname, 0, NULL));
|
CHECK(dns_name_fromtext(fname, &b, dns_rootname, 0));
|
||||||
ntaname = fname;
|
ntaname = fname;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -16226,3 +16214,113 @@ cleanup:
|
|||||||
|
|
||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
isc_result_t
|
||||||
|
named_server_togglememprof(isc_lex_t *lex) {
|
||||||
|
isc_result_t result = ISC_R_FAILURE;
|
||||||
|
bool active;
|
||||||
|
char *ptr;
|
||||||
|
|
||||||
|
/* Skip the command name. */
|
||||||
|
ptr = next_token(lex, NULL);
|
||||||
|
if (ptr == NULL) {
|
||||||
|
return ISC_R_UNEXPECTEDEND;
|
||||||
|
}
|
||||||
|
|
||||||
|
ptr = next_token(lex, NULL);
|
||||||
|
if (ptr == NULL) {
|
||||||
|
return ISC_R_UNEXPECTEDEND;
|
||||||
|
} else if (!strcasecmp(ptr, "dump")) {
|
||||||
|
result = memprof_dump();
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL,
|
||||||
|
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||||
|
"failed to dump memory profile");
|
||||||
|
|
||||||
|
} else {
|
||||||
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL,
|
||||||
|
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
|
||||||
|
"memory profile dumped");
|
||||||
|
}
|
||||||
|
|
||||||
|
goto done;
|
||||||
|
} else if (!strcasecmp(ptr, "on") || !strcasecmp(ptr, "yes") ||
|
||||||
|
!strcasecmp(ptr, "enable") || !strcasecmp(ptr, "true"))
|
||||||
|
{
|
||||||
|
active = true;
|
||||||
|
} else if (!strcasecmp(ptr, "off") || !strcasecmp(ptr, "no") ||
|
||||||
|
!strcasecmp(ptr, "disable") || !strcasecmp(ptr, "false"))
|
||||||
|
{
|
||||||
|
active = false;
|
||||||
|
} else {
|
||||||
|
return DNS_R_SYNTAX;
|
||||||
|
}
|
||||||
|
|
||||||
|
result = memprof_toggle(active);
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
|
ISC_LOG_ERROR,
|
||||||
|
"failed to toggle memory profiling");
|
||||||
|
} else {
|
||||||
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
|
ISC_LOG_INFO, "memory profiling %s",
|
||||||
|
active ? "enabled" : "disabled");
|
||||||
|
}
|
||||||
|
|
||||||
|
done:
|
||||||
|
return result;
|
||||||
|
}
|
||||||
|
|
||||||
|
#ifdef JEMALLOC_API_SUPPORTED
|
||||||
|
const char *
|
||||||
|
named_server_getmemprof(void) {
|
||||||
|
memprof_status status = MEMPROF_ON;
|
||||||
|
bool is_enabled;
|
||||||
|
size_t len = sizeof(is_enabled);
|
||||||
|
|
||||||
|
if (mallctl("config.prof", &is_enabled, &len, NULL, 0) != 0) {
|
||||||
|
status = MEMPROF_FAILING;
|
||||||
|
goto done;
|
||||||
|
}
|
||||||
|
|
||||||
|
INSIST(len == sizeof(is_enabled));
|
||||||
|
|
||||||
|
if (!is_enabled) {
|
||||||
|
status = MEMPROF_UNSUPPORTED;
|
||||||
|
goto done;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (mallctl("opt.prof", &is_enabled, &len, NULL, 0) != 0) {
|
||||||
|
status = MEMPROF_FAILING;
|
||||||
|
goto done;
|
||||||
|
}
|
||||||
|
|
||||||
|
INSIST(len == sizeof(is_enabled));
|
||||||
|
|
||||||
|
if (!is_enabled) {
|
||||||
|
status = MEMPROF_INACTIVE;
|
||||||
|
goto done;
|
||||||
|
}
|
||||||
|
|
||||||
|
len = sizeof(is_enabled);
|
||||||
|
if (mallctl("prof.active", &is_enabled, &len, NULL, 0) != 0) {
|
||||||
|
status = MEMPROF_FAILING;
|
||||||
|
goto done;
|
||||||
|
}
|
||||||
|
|
||||||
|
INSIST(len == sizeof(is_enabled));
|
||||||
|
|
||||||
|
if (!is_enabled) {
|
||||||
|
status = MEMPROF_OFF;
|
||||||
|
}
|
||||||
|
|
||||||
|
done:
|
||||||
|
return memprof_status_text[status];
|
||||||
|
}
|
||||||
|
|
||||||
|
#else /* JEMALLOC_API_SUPPORTED */
|
||||||
|
const char *
|
||||||
|
named_server_getmemprof(void) {
|
||||||
|
return memprof_status_text[MEMPROF_UNSUPPORTED];
|
||||||
|
}
|
||||||
|
#endif /* JEMALLOC_API_SUPPORTED */
|
||||||
|
|||||||
@@ -97,7 +97,7 @@ typedef struct stats_dumparg {
|
|||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
} stats_dumparg_t;
|
} stats_dumparg_t;
|
||||||
|
|
||||||
static isc_once_t once = ISC_ONCE_INIT;
|
static isc_once_t once = ISC_ONCE_INITIALIZER;
|
||||||
|
|
||||||
#if defined(HAVE_LIBXML2) || defined(HAVE_JSON_C)
|
#if defined(HAVE_LIBXML2) || defined(HAVE_JSON_C)
|
||||||
#define EXTENDED_STATS
|
#define EXTENDED_STATS
|
||||||
@@ -1488,6 +1488,7 @@ xfrin_xmlrender(dns_zone_t *zone, void *arg) {
|
|||||||
unsigned int nmsg = 0;
|
unsigned int nmsg = 0;
|
||||||
unsigned int nrecs = 0;
|
unsigned int nrecs = 0;
|
||||||
uint64_t nbytes = 0;
|
uint64_t nbytes = 0;
|
||||||
|
uint64_t rate = 0;
|
||||||
|
|
||||||
statlevel = dns_zone_getstatlevel(zone);
|
statlevel = dns_zone_getstatlevel(zone);
|
||||||
if (statlevel == dns_zonestat_none) {
|
if (statlevel == dns_zonestat_none) {
|
||||||
@@ -1701,7 +1702,7 @@ xfrin_xmlrender(dns_zone_t *zone, void *arg) {
|
|||||||
TRY0(xmlTextWriterEndElement(writer));
|
TRY0(xmlTextWriterEndElement(writer));
|
||||||
|
|
||||||
if (is_running) {
|
if (is_running) {
|
||||||
dns_xfrin_getstats(xfr, &nmsg, &nrecs, &nbytes);
|
dns_xfrin_getstats(xfr, &nmsg, &nrecs, &nbytes, &rate);
|
||||||
}
|
}
|
||||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "nmsg"));
|
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "nmsg"));
|
||||||
TRY0(xmlTextWriterWriteFormatString(writer, "%u", nmsg));
|
TRY0(xmlTextWriterWriteFormatString(writer, "%u", nmsg));
|
||||||
@@ -1712,6 +1713,9 @@ xfrin_xmlrender(dns_zone_t *zone, void *arg) {
|
|||||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "nbytes"));
|
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "nbytes"));
|
||||||
TRY0(xmlTextWriterWriteFormatString(writer, "%" PRIu64, nbytes));
|
TRY0(xmlTextWriterWriteFormatString(writer, "%" PRIu64, nbytes));
|
||||||
TRY0(xmlTextWriterEndElement(writer));
|
TRY0(xmlTextWriterEndElement(writer));
|
||||||
|
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "rate"));
|
||||||
|
TRY0(xmlTextWriterWriteFormatString(writer, "%" PRIu64, rate));
|
||||||
|
TRY0(xmlTextWriterEndElement(writer));
|
||||||
|
|
||||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "ixfr"));
|
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "ixfr"));
|
||||||
if (is_running && is_first_data_received) {
|
if (is_running && is_first_data_received) {
|
||||||
@@ -2559,6 +2563,7 @@ xfrin_jsonrender(dns_zone_t *zone, void *arg) {
|
|||||||
unsigned int nmsg = 0;
|
unsigned int nmsg = 0;
|
||||||
unsigned int nrecs = 0;
|
unsigned int nrecs = 0;
|
||||||
uint64_t nbytes = 0;
|
uint64_t nbytes = 0;
|
||||||
|
uint64_t rate = 0;
|
||||||
|
|
||||||
statlevel = dns_zone_getstatlevel(zone);
|
statlevel = dns_zone_getstatlevel(zone);
|
||||||
if (statlevel == dns_zonestat_none) {
|
if (statlevel == dns_zonestat_none) {
|
||||||
@@ -2756,7 +2761,7 @@ xfrin_jsonrender(dns_zone_t *zone, void *arg) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (is_running) {
|
if (is_running) {
|
||||||
dns_xfrin_getstats(xfr, &nmsg, &nrecs, &nbytes);
|
dns_xfrin_getstats(xfr, &nmsg, &nrecs, &nbytes, &rate);
|
||||||
}
|
}
|
||||||
json_object_object_add(xfrinobj, "nmsg",
|
json_object_object_add(xfrinobj, "nmsg",
|
||||||
json_object_new_int64((int64_t)nmsg));
|
json_object_new_int64((int64_t)nmsg));
|
||||||
@@ -2766,6 +2771,10 @@ xfrin_jsonrender(dns_zone_t *zone, void *arg) {
|
|||||||
xfrinobj, "nbytes",
|
xfrinobj, "nbytes",
|
||||||
json_object_new_int64(nbytes > INT64_MAX ? INT64_MAX
|
json_object_new_int64(nbytes > INT64_MAX ? INT64_MAX
|
||||||
: (int64_t)nbytes));
|
: (int64_t)nbytes));
|
||||||
|
json_object_object_add(xfrinobj, "rate",
|
||||||
|
json_object_new_int64(rate > INT64_MAX
|
||||||
|
? INT64_MAX
|
||||||
|
: (int64_t)rate));
|
||||||
|
|
||||||
if (is_running && is_first_data_received) {
|
if (is_running && is_first_data_received) {
|
||||||
json_object_object_add(
|
json_object_object_add(
|
||||||
|
|||||||
@@ -53,10 +53,7 @@ named_tkeyctx_fromconfig(const cfg_obj_t *options, isc_mem_t *mctx,
|
|||||||
isc_buffer_t b;
|
isc_buffer_t b;
|
||||||
const cfg_obj_t *obj;
|
const cfg_obj_t *obj;
|
||||||
|
|
||||||
result = dns_tkeyctx_create(mctx, &tctx);
|
dns_tkeyctx_create(mctx, &tctx);
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
return result;
|
|
||||||
}
|
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = cfg_map_get(options, "tkey-domain", &obj);
|
result = cfg_map_get(options, "tkey-domain", &obj);
|
||||||
@@ -65,9 +62,9 @@ named_tkeyctx_fromconfig(const cfg_obj_t *options, isc_mem_t *mctx,
|
|||||||
isc_buffer_constinit(&b, s, strlen(s));
|
isc_buffer_constinit(&b, s, strlen(s));
|
||||||
isc_buffer_add(&b, strlen(s));
|
isc_buffer_add(&b, strlen(s));
|
||||||
name = dns_fixedname_initname(&fname);
|
name = dns_fixedname_initname(&fname);
|
||||||
RETERR(dns_name_fromtext(name, &b, dns_rootname, 0, NULL));
|
RETERR(dns_name_fromtext(name, &b, dns_rootname, 0));
|
||||||
tctx->domain = isc_mem_get(mctx, sizeof(dns_name_t));
|
tctx->domain = isc_mem_get(mctx, sizeof(dns_name_t));
|
||||||
dns_name_init(tctx->domain, NULL);
|
dns_name_init(tctx->domain);
|
||||||
dns_name_dup(name, mctx, tctx->domain);
|
dns_name_dup(name, mctx, tctx->domain);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -79,7 +76,7 @@ named_tkeyctx_fromconfig(const cfg_obj_t *options, isc_mem_t *mctx,
|
|||||||
isc_buffer_constinit(&b, s, strlen(s));
|
isc_buffer_constinit(&b, s, strlen(s));
|
||||||
isc_buffer_add(&b, strlen(s));
|
isc_buffer_add(&b, strlen(s));
|
||||||
name = dns_fixedname_initname(&fname);
|
name = dns_fixedname_initname(&fname);
|
||||||
RETERR(dns_name_fromtext(name, &b, dns_rootname, 0, NULL));
|
RETERR(dns_name_fromtext(name, &b, dns_rootname, 0));
|
||||||
RETERR(dst_gssapi_acquirecred(name, false, &tctx->gsscred));
|
RETERR(dst_gssapi_acquirecred(name, false, &tctx->gsscred));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+21
-23
@@ -27,17 +27,16 @@
|
|||||||
#include <named/log.h>
|
#include <named/log.h>
|
||||||
#include <named/transportconf.h>
|
#include <named/transportconf.h>
|
||||||
|
|
||||||
#define create_name(id, name) \
|
#define create_name(id, name) \
|
||||||
isc_buffer_t namesrc, namebuf; \
|
isc_buffer_t namesrc; \
|
||||||
char namedata[DNS_NAME_FORMATSIZE + 1]; \
|
dns_fixedname_t _fn; \
|
||||||
dns_name_init(name, NULL); \
|
name = dns_fixedname_initname(&_fn); \
|
||||||
isc_buffer_constinit(&namesrc, id, strlen(id)); \
|
isc_buffer_constinit(&namesrc, id, strlen(id)); \
|
||||||
isc_buffer_add(&namesrc, strlen(id)); \
|
isc_buffer_add(&namesrc, strlen(id)); \
|
||||||
isc_buffer_init(&namebuf, namedata, sizeof(namedata)); \
|
result = (dns_name_fromtext(name, &namesrc, dns_rootname, \
|
||||||
result = (dns_name_fromtext(name, &namesrc, dns_rootname, \
|
DNS_NAME_DOWNCASE)); \
|
||||||
DNS_NAME_DOWNCASE, &namebuf)); \
|
if (result != ISC_R_SUCCESS) { \
|
||||||
if (result != ISC_R_SUCCESS) { \
|
goto failure; \
|
||||||
goto failure; \
|
|
||||||
}
|
}
|
||||||
|
|
||||||
#define parse_transport_option(map, transport, name, setter) \
|
#define parse_transport_option(map, transport, name, setter) \
|
||||||
@@ -100,15 +99,15 @@ add_doh_transports(const cfg_obj_t *transportlist, dns_transport_list_t *list) {
|
|||||||
for (const cfg_listelt_t *element = cfg_list_first(transportlist);
|
for (const cfg_listelt_t *element = cfg_list_first(transportlist);
|
||||||
element != NULL; element = cfg_list_next(element))
|
element != NULL; element = cfg_list_next(element))
|
||||||
{
|
{
|
||||||
dns_name_t dohname;
|
dns_name_t *dohname = NULL;
|
||||||
dns_transport_t *transport;
|
dns_transport_t *transport = NULL;
|
||||||
|
|
||||||
doh = cfg_listelt_value(element);
|
doh = cfg_listelt_value(element);
|
||||||
dohid = cfg_obj_asstring(cfg_map_getname(doh));
|
dohid = cfg_obj_asstring(cfg_map_getname(doh));
|
||||||
|
|
||||||
create_name(dohid, &dohname);
|
create_name(dohid, dohname);
|
||||||
|
|
||||||
transport = dns_transport_new(&dohname, DNS_TRANSPORT_HTTP,
|
transport = dns_transport_new(dohname, DNS_TRANSPORT_HTTP,
|
||||||
list);
|
list);
|
||||||
|
|
||||||
dns_transport_set_tlsname(transport, dohid);
|
dns_transport_set_tlsname(transport, dohid);
|
||||||
@@ -148,8 +147,8 @@ add_tls_transports(const cfg_obj_t *transportlist, dns_transport_list_t *list) {
|
|||||||
for (const cfg_listelt_t *element = cfg_list_first(transportlist);
|
for (const cfg_listelt_t *element = cfg_list_first(transportlist);
|
||||||
element != NULL; element = cfg_list_next(element))
|
element != NULL; element = cfg_list_next(element))
|
||||||
{
|
{
|
||||||
dns_name_t tlsname;
|
dns_name_t *tlsname = NULL;
|
||||||
dns_transport_t *transport;
|
dns_transport_t *transport = NULL;
|
||||||
|
|
||||||
tls = cfg_listelt_value(element);
|
tls = cfg_listelt_value(element);
|
||||||
tlsid = cfg_obj_asstring(cfg_map_getname(tls));
|
tlsid = cfg_obj_asstring(cfg_map_getname(tls));
|
||||||
@@ -159,10 +158,9 @@ add_tls_transports(const cfg_obj_t *transportlist, dns_transport_list_t *list) {
|
|||||||
goto failure;
|
goto failure;
|
||||||
}
|
}
|
||||||
|
|
||||||
create_name(tlsid, &tlsname);
|
create_name(tlsid, tlsname);
|
||||||
|
|
||||||
transport = dns_transport_new(&tlsname, DNS_TRANSPORT_TLS,
|
transport = dns_transport_new(tlsname, DNS_TRANSPORT_TLS, list);
|
||||||
list);
|
|
||||||
|
|
||||||
dns_transport_set_tlsname(transport, tlsid);
|
dns_transport_set_tlsname(transport, tlsid);
|
||||||
parse_transport_option(tls, transport, "key-file",
|
parse_transport_option(tls, transport, "key-file",
|
||||||
@@ -222,12 +220,12 @@ transport_list_fromconfig(const cfg_obj_t *config, dns_transport_list_t *list) {
|
|||||||
static void
|
static void
|
||||||
transport_list_add_ephemeral(dns_transport_list_t *list) {
|
transport_list_add_ephemeral(dns_transport_list_t *list) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
dns_name_t tlsname;
|
dns_name_t *tlsname = NULL;
|
||||||
dns_transport_t *transport;
|
dns_transport_t *transport;
|
||||||
|
|
||||||
create_name("ephemeral", &tlsname);
|
create_name("ephemeral", tlsname);
|
||||||
|
|
||||||
transport = dns_transport_new(&tlsname, DNS_TRANSPORT_TLS, list);
|
transport = dns_transport_new(tlsname, DNS_TRANSPORT_TLS, list);
|
||||||
dns_transport_set_tlsname(transport, "ephemeral");
|
dns_transport_set_tlsname(transport, "ephemeral");
|
||||||
|
|
||||||
return;
|
return;
|
||||||
|
|||||||
@@ -46,11 +46,11 @@ add_initial_keys(const cfg_obj_t *list, dns_tsigkeyring_t *ring,
|
|||||||
{
|
{
|
||||||
const cfg_obj_t *algobj = NULL;
|
const cfg_obj_t *algobj = NULL;
|
||||||
const cfg_obj_t *secretobj = NULL;
|
const cfg_obj_t *secretobj = NULL;
|
||||||
dns_name_t keyname;
|
dns_fixedname_t fkey;
|
||||||
|
dns_name_t *keyname = dns_fixedname_initname(&fkey);
|
||||||
dst_algorithm_t alg = DST_ALG_UNKNOWN;
|
dst_algorithm_t alg = DST_ALG_UNKNOWN;
|
||||||
const char *algstr = NULL;
|
const char *algstr = NULL;
|
||||||
char keynamedata[1024];
|
isc_buffer_t keynamesrc;
|
||||||
isc_buffer_t keynamesrc, keynamebuf;
|
|
||||||
const char *secretstr = NULL;
|
const char *secretstr = NULL;
|
||||||
isc_buffer_t secretbuf;
|
isc_buffer_t secretbuf;
|
||||||
int secretlen = 0;
|
int secretlen = 0;
|
||||||
@@ -68,12 +68,10 @@ add_initial_keys(const cfg_obj_t *list, dns_tsigkeyring_t *ring,
|
|||||||
/*
|
/*
|
||||||
* Create the key name.
|
* Create the key name.
|
||||||
*/
|
*/
|
||||||
dns_name_init(&keyname, NULL);
|
|
||||||
isc_buffer_constinit(&keynamesrc, keyid, strlen(keyid));
|
isc_buffer_constinit(&keynamesrc, keyid, strlen(keyid));
|
||||||
isc_buffer_add(&keynamesrc, strlen(keyid));
|
isc_buffer_add(&keynamesrc, strlen(keyid));
|
||||||
isc_buffer_init(&keynamebuf, keynamedata, sizeof(keynamedata));
|
ret = dns_name_fromtext(keyname, &keynamesrc, dns_rootname,
|
||||||
ret = dns_name_fromtext(&keyname, &keynamesrc, dns_rootname,
|
DNS_NAME_DOWNCASE);
|
||||||
DNS_NAME_DOWNCASE, &keynamebuf);
|
|
||||||
if (ret != ISC_R_SUCCESS) {
|
if (ret != ISC_R_SUCCESS) {
|
||||||
goto failure;
|
goto failure;
|
||||||
}
|
}
|
||||||
@@ -103,7 +101,7 @@ add_initial_keys(const cfg_obj_t *list, dns_tsigkeyring_t *ring,
|
|||||||
}
|
}
|
||||||
secretlen = isc_buffer_usedlength(&secretbuf);
|
secretlen = isc_buffer_usedlength(&secretbuf);
|
||||||
|
|
||||||
ret = dns_tsigkey_create(&keyname, alg, secret, secretlen, mctx,
|
ret = dns_tsigkey_create(keyname, alg, secret, secretlen, mctx,
|
||||||
&tsigkey);
|
&tsigkey);
|
||||||
isc_mem_put(mctx, secret, secretalloc);
|
isc_mem_put(mctx, secret, secretalloc);
|
||||||
secret = NULL;
|
secret = NULL;
|
||||||
|
|||||||
+43
-24
@@ -253,7 +253,7 @@ configure_zone_ssutable(const cfg_obj_t *zconfig, dns_zone_t *zone,
|
|||||||
isc_buffer_constinit(&b, str, strlen(str));
|
isc_buffer_constinit(&b, str, strlen(str));
|
||||||
isc_buffer_add(&b, strlen(str));
|
isc_buffer_add(&b, strlen(str));
|
||||||
result = dns_name_fromtext(dns_fixedname_name(&fident), &b,
|
result = dns_name_fromtext(dns_fixedname_name(&fident), &b,
|
||||||
dns_rootname, 0, NULL);
|
dns_rootname, 0);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(identity, ISC_LOG_ERROR,
|
cfg_obj_log(identity, ISC_LOG_ERROR,
|
||||||
"'%s' is not a valid name", str);
|
"'%s' is not a valid name", str);
|
||||||
@@ -283,7 +283,7 @@ configure_zone_ssutable(const cfg_obj_t *zconfig, dns_zone_t *zone,
|
|||||||
isc_buffer_constinit(&b, str, strlen(str));
|
isc_buffer_constinit(&b, str, strlen(str));
|
||||||
isc_buffer_add(&b, strlen(str));
|
isc_buffer_add(&b, strlen(str));
|
||||||
result = dns_name_fromtext(dns_fixedname_name(&fname),
|
result = dns_name_fromtext(dns_fixedname_name(&fname),
|
||||||
&b, dns_rootname, 0, NULL);
|
&b, dns_rootname, 0);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(identity, ISC_LOG_ERROR,
|
cfg_obj_log(identity, ISC_LOG_ERROR,
|
||||||
"'%s' is not a valid name", str);
|
"'%s' is not a valid name", str);
|
||||||
@@ -518,7 +518,7 @@ configure_staticstub_servernames(const cfg_obj_t *zconfig, dns_zone_t *zone,
|
|||||||
|
|
||||||
isc_buffer_constinit(&b, str, strlen(str));
|
isc_buffer_constinit(&b, str, strlen(str));
|
||||||
isc_buffer_add(&b, strlen(str));
|
isc_buffer_add(&b, strlen(str));
|
||||||
result = dns_name_fromtext(nsname, &b, dns_rootname, 0, NULL);
|
result = dns_name_fromtext(nsname, &b, dns_rootname, 0);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(zconfig, ISC_LOG_ERROR,
|
cfg_obj_log(zconfig, ISC_LOG_ERROR,
|
||||||
"server-name '%s' is not a valid "
|
"server-name '%s' is not a valid "
|
||||||
@@ -633,7 +633,7 @@ configure_staticstub(const cfg_obj_t *zconfig, dns_zone_t *zone,
|
|||||||
*/
|
*/
|
||||||
CHECK(dns_db_newversion(db, &dbversion));
|
CHECK(dns_db_newversion(db, &dbversion));
|
||||||
|
|
||||||
dns_name_init(&apexname, NULL);
|
dns_name_init(&apexname);
|
||||||
dns_name_clone(dns_zone_getorigin(zone), &apexname);
|
dns_name_clone(dns_zone_getorigin(zone), &apexname);
|
||||||
CHECK(dns_db_findnode(db, &apexname, false, &apexnode));
|
CHECK(dns_db_findnode(db, &apexname, false, &apexnode));
|
||||||
|
|
||||||
@@ -978,9 +978,6 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
if (result == ISC_R_SUCCESS) {
|
if (result == ISC_R_SUCCESS) {
|
||||||
cpval = isc_mem_strdup(mctx, cfg_obj_asstring(obj));
|
cpval = isc_mem_strdup(mctx, cfg_obj_asstring(obj));
|
||||||
}
|
}
|
||||||
if (cpval == NULL) {
|
|
||||||
CHECK(ISC_R_NOMEMORY);
|
|
||||||
}
|
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = cfg_map_get(zoptions, "dlz", &obj);
|
result = cfg_map_get(zoptions, "dlz", &obj);
|
||||||
@@ -1109,24 +1106,20 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
size_t signedlen = strlen(filename) + sizeof(SIGNED);
|
size_t signedlen = strlen(filename) + sizeof(SIGNED);
|
||||||
char *signedname;
|
char *signedname;
|
||||||
|
|
||||||
CHECK(dns_zone_setfile(raw, filename, masterformat,
|
dns_zone_setfile(raw, filename, masterformat, masterstyle);
|
||||||
masterstyle));
|
|
||||||
signedname = isc_mem_get(mctx, signedlen);
|
signedname = isc_mem_get(mctx, signedlen);
|
||||||
|
|
||||||
(void)snprintf(signedname, signedlen, "%s" SIGNED, filename);
|
(void)snprintf(signedname, signedlen, "%s" SIGNED, filename);
|
||||||
result = dns_zone_setfile(zone, signedname,
|
dns_zone_setfile(zone, signedname, dns_masterformat_raw, NULL);
|
||||||
dns_masterformat_raw, NULL);
|
|
||||||
isc_mem_put(mctx, signedname, signedlen);
|
isc_mem_put(mctx, signedname, signedlen);
|
||||||
CHECK(result);
|
|
||||||
} else {
|
} else {
|
||||||
CHECK(dns_zone_setfile(zone, filename, masterformat,
|
dns_zone_setfile(zone, filename, masterformat, masterstyle);
|
||||||
masterstyle));
|
|
||||||
}
|
}
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = cfg_map_get(zoptions, "journal", &obj);
|
result = cfg_map_get(zoptions, "journal", &obj);
|
||||||
if (result == ISC_R_SUCCESS) {
|
if (result == ISC_R_SUCCESS) {
|
||||||
CHECK(dns_zone_setjournal(mayberaw, cfg_obj_asstring(obj)));
|
dns_zone_setjournal(mayberaw, cfg_obj_asstring(obj));
|
||||||
}
|
}
|
||||||
|
|
||||||
/*
|
/*
|
||||||
@@ -1273,8 +1266,8 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
dns_ipkeylist_t ipkl;
|
dns_ipkeylist_t ipkl;
|
||||||
dns_ipkeylist_init(&ipkl);
|
dns_ipkeylist_init(&ipkl);
|
||||||
|
|
||||||
CHECK(named_config_getipandkeylist(config, "primaries",
|
CHECK(named_config_getipandkeylist(config, obj, mctx,
|
||||||
obj, mctx, &ipkl));
|
&ipkl));
|
||||||
dns_zone_setalsonotify(zone, ipkl.addrs, ipkl.sources,
|
dns_zone_setalsonotify(zone, ipkl.addrs, ipkl.sources,
|
||||||
ipkl.keys, ipkl.tlss,
|
ipkl.keys, ipkl.tlss,
|
||||||
ipkl.count);
|
ipkl.count);
|
||||||
@@ -1627,7 +1620,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
result = named_config_get(maps, "key-directory", &obj);
|
result = named_config_get(maps, "key-directory", &obj);
|
||||||
if (result == ISC_R_SUCCESS) {
|
if (result == ISC_R_SUCCESS) {
|
||||||
filename = cfg_obj_asstring(obj);
|
filename = cfg_obj_asstring(obj);
|
||||||
CHECK(dns_zone_setkeydirectory(zone, filename));
|
dns_zone_setkeydirectory(zone, filename);
|
||||||
}
|
}
|
||||||
/* Also save a reference to the keystore list. */
|
/* Also save a reference to the keystore list. */
|
||||||
dns_zone_setkeystores(zone, keystorelist);
|
dns_zone_setkeystores(zone, keystorelist);
|
||||||
@@ -1679,9 +1672,8 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
if (parentals != NULL) {
|
if (parentals != NULL) {
|
||||||
dns_ipkeylist_t ipkl;
|
dns_ipkeylist_t ipkl;
|
||||||
dns_ipkeylist_init(&ipkl);
|
dns_ipkeylist_init(&ipkl);
|
||||||
CHECK(named_config_getipandkeylist(
|
CHECK(named_config_getipandkeylist(config, parentals,
|
||||||
config, "parental-agents", parentals, mctx,
|
mctx, &ipkl));
|
||||||
&ipkl));
|
|
||||||
dns_zone_setparentals(zone, ipkl.addrs, ipkl.sources,
|
dns_zone_setparentals(zone, ipkl.addrs, ipkl.sources,
|
||||||
ipkl.keys, ipkl.tlss, ipkl.count);
|
ipkl.keys, ipkl.tlss, ipkl.count);
|
||||||
dns_ipkeylist_clear(mctx, &ipkl);
|
dns_ipkeylist_clear(mctx, &ipkl);
|
||||||
@@ -1853,7 +1845,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
dns_name_equal(dns_zone_getorigin(zone), dns_rootname))
|
dns_name_equal(dns_zone_getorigin(zone), dns_rootname))
|
||||||
{
|
{
|
||||||
result = named_config_getremotesdef(
|
result = named_config_getremotesdef(
|
||||||
named_g_config, "primaries",
|
named_g_config, "remote-servers",
|
||||||
DEFAULT_IANA_ROOT_ZONE_PRIMARIES, &obj);
|
DEFAULT_IANA_ROOT_ZONE_PRIMARIES, &obj);
|
||||||
CHECK(result);
|
CHECK(result);
|
||||||
}
|
}
|
||||||
@@ -1861,8 +1853,8 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
dns_ipkeylist_t ipkl;
|
dns_ipkeylist_t ipkl;
|
||||||
dns_ipkeylist_init(&ipkl);
|
dns_ipkeylist_init(&ipkl);
|
||||||
|
|
||||||
CHECK(named_config_getipandkeylist(config, "primaries",
|
CHECK(named_config_getipandkeylist(config, obj, mctx,
|
||||||
obj, mctx, &ipkl));
|
&ipkl));
|
||||||
dns_zone_setprimaries(mayberaw, ipkl.addrs,
|
dns_zone_setprimaries(mayberaw, ipkl.addrs,
|
||||||
ipkl.sources, ipkl.keys,
|
ipkl.sources, ipkl.keys,
|
||||||
ipkl.tlss, ipkl.count);
|
ipkl.tlss, ipkl.count);
|
||||||
@@ -1882,6 +1874,33 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
}
|
}
|
||||||
dns_zone_setoption(mayberaw, DNS_ZONEOPT_MULTIMASTER, multi);
|
dns_zone_setoption(mayberaw, DNS_ZONEOPT_MULTIMASTER, multi);
|
||||||
|
|
||||||
|
obj = NULL;
|
||||||
|
result = named_config_get(maps, "min-transfer-rate-in", &obj);
|
||||||
|
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||||
|
uint32_t traffic_bytes =
|
||||||
|
cfg_obj_asuint32(cfg_tuple_get(obj, "traffic_bytes"));
|
||||||
|
uint32_t time_minutes =
|
||||||
|
cfg_obj_asuint32(cfg_tuple_get(obj, "time_minutes"));
|
||||||
|
if (traffic_bytes == 0) {
|
||||||
|
cfg_obj_log(obj, ISC_LOG_ERROR,
|
||||||
|
"zone '%s': 'min-transfer-rate-in' bytes"
|
||||||
|
"value can not be '0'",
|
||||||
|
zname);
|
||||||
|
CHECK(ISC_R_FAILURE);
|
||||||
|
}
|
||||||
|
/* Max. 28 days (in minutes). */
|
||||||
|
const unsigned int time_minutes_max = 28 * 24 * 60;
|
||||||
|
if (time_minutes < 1 || time_minutes > time_minutes_max) {
|
||||||
|
cfg_obj_log(obj, ISC_LOG_ERROR,
|
||||||
|
"zone '%s': 'min-transfer-rate-in' minutes"
|
||||||
|
"value is out of range (1..%u)",
|
||||||
|
zname, time_minutes_max);
|
||||||
|
CHECK(ISC_R_FAILURE);
|
||||||
|
}
|
||||||
|
dns_zone_setminxfrratein(mayberaw, traffic_bytes,
|
||||||
|
transferinsecs ? time_minutes
|
||||||
|
: time_minutes * 60);
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = named_config_get(maps, "max-transfer-time-in", &obj);
|
result = named_config_get(maps, "max-transfer-time-in", &obj);
|
||||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||||
|
|||||||
+43
-47
@@ -30,6 +30,7 @@
|
|||||||
#include <isc/getaddresses.h>
|
#include <isc/getaddresses.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/lex.h>
|
#include <isc/lex.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/loop.h>
|
#include <isc/loop.h>
|
||||||
#include <isc/managers.h>
|
#include <isc/managers.h>
|
||||||
@@ -52,6 +53,7 @@
|
|||||||
#include <dns/dispatch.h>
|
#include <dns/dispatch.h>
|
||||||
#include <dns/dnssec.h>
|
#include <dns/dnssec.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
|
#include <dns/lib.h>
|
||||||
#include <dns/masterdump.h>
|
#include <dns/masterdump.h>
|
||||||
#include <dns/message.h>
|
#include <dns/message.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
@@ -521,8 +523,7 @@ setup_keystr(void) {
|
|||||||
isc_buffer_add(&keynamesrc, (unsigned int)(n - name));
|
isc_buffer_add(&keynamesrc, (unsigned int)(n - name));
|
||||||
|
|
||||||
debug("namefromtext");
|
debug("namefromtext");
|
||||||
result = dns_name_fromtext(mykeyname, &keynamesrc, dns_rootname, 0,
|
result = dns_name_fromtext(mykeyname, &keynamesrc, dns_rootname, 0);
|
||||||
NULL);
|
|
||||||
check_result(result, "dns_name_fromtext");
|
check_result(result, "dns_name_fromtext");
|
||||||
|
|
||||||
secretlen = strlen(secretstr) * 3 / 4;
|
secretlen = strlen(secretstr) * 3 / 4;
|
||||||
@@ -766,14 +767,12 @@ set_source_ports(dns_dispatchmgr_t *manager) {
|
|||||||
in_port_t udpport_low, udpport_high;
|
in_port_t udpport_low, udpport_high;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
|
|
||||||
result = isc_portset_create(gmctx, &v4portset);
|
isc_portset_create(gmctx, &v4portset);
|
||||||
check_result(result, "isc_portset_create (v4)");
|
|
||||||
result = isc_net_getudpportrange(AF_INET, &udpport_low, &udpport_high);
|
result = isc_net_getudpportrange(AF_INET, &udpport_low, &udpport_high);
|
||||||
check_result(result, "isc_net_getudpportrange (v4)");
|
check_result(result, "isc_net_getudpportrange (v4)");
|
||||||
isc_portset_addrange(v4portset, udpport_low, udpport_high);
|
isc_portset_addrange(v4portset, udpport_low, udpport_high);
|
||||||
|
|
||||||
result = isc_portset_create(gmctx, &v6portset);
|
isc_portset_create(gmctx, &v6portset);
|
||||||
check_result(result, "isc_portset_create (v6)");
|
|
||||||
result = isc_net_getudpportrange(AF_INET6, &udpport_low, &udpport_high);
|
result = isc_net_getudpportrange(AF_INET6, &udpport_low, &udpport_high);
|
||||||
check_result(result, "isc_net_getudpportrange (v6)");
|
check_result(result, "isc_net_getudpportrange (v6)");
|
||||||
isc_portset_addrange(v6portset, udpport_low, udpport_high);
|
isc_portset_addrange(v6portset, udpport_low, udpport_high);
|
||||||
@@ -786,16 +785,14 @@ set_source_ports(dns_dispatchmgr_t *manager) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
create_name(const char *str, char *namedata, size_t len, dns_name_t *name) {
|
create_name(const char *str, dns_name_t *name) {
|
||||||
isc_buffer_t namesrc, namebuf;
|
isc_buffer_t namesrc;
|
||||||
|
|
||||||
dns_name_init(name, NULL);
|
|
||||||
isc_buffer_constinit(&namesrc, str, strlen(str));
|
isc_buffer_constinit(&namesrc, str, strlen(str));
|
||||||
isc_buffer_add(&namesrc, strlen(str));
|
isc_buffer_add(&namesrc, strlen(str));
|
||||||
isc_buffer_init(&namebuf, namedata, len);
|
|
||||||
|
|
||||||
return dns_name_fromtext(name, &namesrc, dns_rootname,
|
return dns_name_fromtext(name, &namesrc, dns_rootname,
|
||||||
DNS_NAME_DOWNCASE, &namebuf);
|
DNS_NAME_DOWNCASE);
|
||||||
}
|
}
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -805,8 +802,8 @@ setup_system(void *arg ISC_ATTR_UNUSED) {
|
|||||||
isc_sockaddrlist_t *nslist;
|
isc_sockaddrlist_t *nslist;
|
||||||
isc_logconfig_t *logconfig = NULL;
|
isc_logconfig_t *logconfig = NULL;
|
||||||
irs_resconf_t *resconf = NULL;
|
irs_resconf_t *resconf = NULL;
|
||||||
dns_name_t tlsname;
|
dns_fixedname_t ftls;
|
||||||
char namedata[DNS_NAME_FORMATSIZE + 1];
|
dns_name_t *tlsname = dns_fixedname_initname(&ftls);
|
||||||
|
|
||||||
ddebug("setup_system()");
|
ddebug("setup_system()");
|
||||||
|
|
||||||
@@ -940,17 +937,15 @@ setup_system(void *arg ISC_ATTR_UNUSED) {
|
|||||||
isc_tlsctx_cache_create(gmctx, &tls_ctx_cache);
|
isc_tlsctx_cache_create(gmctx, &tls_ctx_cache);
|
||||||
|
|
||||||
if (tls_client_key_file == NULL) {
|
if (tls_client_key_file == NULL) {
|
||||||
result = create_name("tls-non-auth-client", namedata,
|
result = create_name("tls-non-auth-client", tlsname);
|
||||||
sizeof(namedata), &tlsname);
|
|
||||||
check_result(result, "create_name (tls-non-auth-client)");
|
check_result(result, "create_name (tls-non-auth-client)");
|
||||||
transport = dns_transport_new(&tlsname, DNS_TRANSPORT_TLS,
|
transport = dns_transport_new(tlsname, DNS_TRANSPORT_TLS,
|
||||||
transport_list);
|
transport_list);
|
||||||
dns_transport_set_tlsname(transport, "tls-non-auth-client");
|
dns_transport_set_tlsname(transport, "tls-non-auth-client");
|
||||||
} else {
|
} else {
|
||||||
result = create_name("tls-auth-client", namedata,
|
result = create_name("tls-auth-client", tlsname);
|
||||||
sizeof(namedata), &tlsname);
|
|
||||||
check_result(result, "create_name (tls-auth-client)");
|
check_result(result, "create_name (tls-auth-client)");
|
||||||
transport = dns_transport_new(&tlsname, DNS_TRANSPORT_TLS,
|
transport = dns_transport_new(tlsname, DNS_TRANSPORT_TLS,
|
||||||
transport_list);
|
transport_list);
|
||||||
dns_transport_set_tlsname(transport, "tls-auth-client");
|
dns_transport_set_tlsname(transport, "tls-auth-client");
|
||||||
dns_transport_set_keyfile(transport, tls_client_key_file);
|
dns_transport_set_keyfile(transport, tls_client_key_file);
|
||||||
@@ -1309,7 +1304,7 @@ parse_name(char **cmdlinep, dns_message_t *msg, dns_name_t **namep) {
|
|||||||
dns_message_gettempname(msg, namep);
|
dns_message_gettempname(msg, namep);
|
||||||
isc_buffer_init(&source, word, strlen(word));
|
isc_buffer_init(&source, word, strlen(word));
|
||||||
isc_buffer_add(&source, strlen(word));
|
isc_buffer_add(&source, strlen(word));
|
||||||
result = dns_name_fromtext(*namep, &source, dns_rootname, 0, NULL);
|
result = dns_name_fromtext(*namep, &source, dns_rootname, 0);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
error("invalid owner name: %s", isc_result_totext(result));
|
error("invalid owner name: %s", isc_result_totext(result));
|
||||||
isc_buffer_invalidate(&source);
|
isc_buffer_invalidate(&source);
|
||||||
@@ -1735,7 +1730,7 @@ evaluate_key(char *cmdline) {
|
|||||||
|
|
||||||
isc_buffer_init(&b, namestr, strlen(namestr));
|
isc_buffer_init(&b, namestr, strlen(namestr));
|
||||||
isc_buffer_add(&b, strlen(namestr));
|
isc_buffer_add(&b, strlen(namestr));
|
||||||
result = dns_name_fromtext(mykeyname, &b, dns_rootname, 0, NULL);
|
result = dns_name_fromtext(mykeyname, &b, dns_rootname, 0);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
fprintf(stderr, "could not parse key name\n");
|
fprintf(stderr, "could not parse key name\n");
|
||||||
return STATUS_SYNTAX;
|
return STATUS_SYNTAX;
|
||||||
@@ -1789,7 +1784,7 @@ evaluate_zone(char *cmdline) {
|
|||||||
userzone = dns_fixedname_initname(&fuserzone);
|
userzone = dns_fixedname_initname(&fuserzone);
|
||||||
isc_buffer_init(&b, word, strlen(word));
|
isc_buffer_init(&b, word, strlen(word));
|
||||||
isc_buffer_add(&b, strlen(word));
|
isc_buffer_add(&b, strlen(word));
|
||||||
result = dns_name_fromtext(userzone, &b, dns_rootname, 0, NULL);
|
result = dns_name_fromtext(userzone, &b, dns_rootname, 0);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
userzone = NULL; /* Lest it point to an invalid name */
|
userzone = NULL; /* Lest it point to an invalid name */
|
||||||
fprintf(stderr, "could not parse zone name\n");
|
fprintf(stderr, "could not parse zone name\n");
|
||||||
@@ -2614,8 +2609,8 @@ done:
|
|||||||
if (usegsstsig) {
|
if (usegsstsig) {
|
||||||
dns_name_free(&tmpzonename, gmctx);
|
dns_name_free(&tmpzonename, gmctx);
|
||||||
dns_name_free(&restart_primary, gmctx);
|
dns_name_free(&restart_primary, gmctx);
|
||||||
dns_name_init(&tmpzonename, 0);
|
dns_name_init(&tmpzonename);
|
||||||
dns_name_init(&restart_primary, 0);
|
dns_name_init(&restart_primary);
|
||||||
}
|
}
|
||||||
done_update();
|
done_update();
|
||||||
}
|
}
|
||||||
@@ -2665,9 +2660,9 @@ send_update(dns_name_t *zone, isc_sockaddr_t *primary) {
|
|||||||
|
|
||||||
result = dns_request_create(requestmgr, updatemsg, srcaddr, primary,
|
result = dns_request_create(requestmgr, updatemsg, srcaddr, primary,
|
||||||
req_transport, req_tls_ctx_cache, options,
|
req_transport, req_tls_ctx_cache, options,
|
||||||
tsigkey, timeout, udp_timeout, udp_retries,
|
tsigkey, timeout, timeout, udp_timeout,
|
||||||
isc_loop_main(loopmgr), update_completed,
|
udp_retries, isc_loop_main(loopmgr),
|
||||||
NULL, &request);
|
update_completed, NULL, &request);
|
||||||
check_result(result, "dns_request_create");
|
check_result(result, "dns_request_create");
|
||||||
|
|
||||||
if (debugging) {
|
if (debugging) {
|
||||||
@@ -2770,11 +2765,11 @@ recvsoa(void *arg) {
|
|||||||
srcaddr = localaddr4;
|
srcaddr = localaddr4;
|
||||||
}
|
}
|
||||||
|
|
||||||
result = dns_request_create(requestmgr, soaquery, srcaddr, addr,
|
result = dns_request_create(
|
||||||
req_transport, req_tls_ctx_cache,
|
requestmgr, soaquery, srcaddr, addr, req_transport,
|
||||||
options, NULL, timeout, udp_timeout,
|
req_tls_ctx_cache, options, NULL, timeout, timeout,
|
||||||
udp_retries, isc_loop_main(loopmgr),
|
udp_timeout, udp_retries, isc_loop_main(loopmgr),
|
||||||
recvsoa, reqinfo, &request);
|
recvsoa, reqinfo, &request);
|
||||||
check_result(result, "dns_request_create");
|
check_result(result, "dns_request_create");
|
||||||
requests++;
|
requests++;
|
||||||
return;
|
return;
|
||||||
@@ -2881,7 +2876,7 @@ lookforsoa:
|
|||||||
result = dns_rdata_tostruct(&soarr, &soa, NULL);
|
result = dns_rdata_tostruct(&soarr, &soa, NULL);
|
||||||
check_result(result, "dns_rdata_tostruct");
|
check_result(result, "dns_rdata_tostruct");
|
||||||
|
|
||||||
dns_name_init(&primary, NULL);
|
dns_name_init(&primary);
|
||||||
dns_name_clone(&soa.origin, &primary);
|
dns_name_clone(&soa.origin, &primary);
|
||||||
|
|
||||||
if (userzone != NULL) {
|
if (userzone != NULL) {
|
||||||
@@ -2937,9 +2932,9 @@ lookforsoa:
|
|||||||
|
|
||||||
#if HAVE_GSSAPI
|
#if HAVE_GSSAPI
|
||||||
if (usegsstsig) {
|
if (usegsstsig) {
|
||||||
dns_name_init(&tmpzonename, NULL);
|
dns_name_init(&tmpzonename);
|
||||||
dns_name_dup(zname, gmctx, &tmpzonename);
|
dns_name_dup(zname, gmctx, &tmpzonename);
|
||||||
dns_name_init(&restart_primary, NULL);
|
dns_name_init(&restart_primary);
|
||||||
dns_name_dup(&primary, gmctx, &restart_primary);
|
dns_name_dup(&primary, gmctx, &restart_primary);
|
||||||
start_gssrequest(&primary);
|
start_gssrequest(&primary);
|
||||||
} else {
|
} else {
|
||||||
@@ -2968,7 +2963,7 @@ droplabel:
|
|||||||
if (nlabels == 1) {
|
if (nlabels == 1) {
|
||||||
fatal("could not find enclosing zone");
|
fatal("could not find enclosing zone");
|
||||||
}
|
}
|
||||||
dns_name_init(&tname, NULL);
|
dns_name_init(&tname);
|
||||||
dns_name_getlabelsequence(name, 1, nlabels - 1, &tname);
|
dns_name_getlabelsequence(name, 1, nlabels - 1, &tname);
|
||||||
dns_name_clone(&tname, name);
|
dns_name_clone(&tname, name);
|
||||||
dns_request_destroy(&request);
|
dns_request_destroy(&request);
|
||||||
@@ -3009,8 +3004,8 @@ sendrequest(isc_sockaddr_t *destaddr, dns_message_t *msg,
|
|||||||
result = dns_request_create(
|
result = dns_request_create(
|
||||||
requestmgr, msg, srcaddr, destaddr, req_transport,
|
requestmgr, msg, srcaddr, destaddr, req_transport,
|
||||||
req_tls_ctx_cache, options, default_servers ? NULL : tsigkey,
|
req_tls_ctx_cache, options, default_servers ? NULL : tsigkey,
|
||||||
timeout, udp_timeout, udp_retries, isc_loop_main(loopmgr),
|
timeout, timeout, udp_timeout, udp_retries,
|
||||||
recvsoa, reqinfo, request);
|
isc_loop_main(loopmgr), recvsoa, reqinfo, request);
|
||||||
check_result(result, "dns_request_create");
|
check_result(result, "dns_request_create");
|
||||||
requests++;
|
requests++;
|
||||||
}
|
}
|
||||||
@@ -3075,8 +3070,8 @@ failed_gssrequest(void) {
|
|||||||
|
|
||||||
dns_name_free(&tmpzonename, gmctx);
|
dns_name_free(&tmpzonename, gmctx);
|
||||||
dns_name_free(&restart_primary, gmctx);
|
dns_name_free(&restart_primary, gmctx);
|
||||||
dns_name_init(&tmpzonename, NULL);
|
dns_name_init(&tmpzonename);
|
||||||
dns_name_init(&restart_primary, NULL);
|
dns_name_init(&restart_primary);
|
||||||
|
|
||||||
done_update();
|
done_update();
|
||||||
}
|
}
|
||||||
@@ -3123,7 +3118,7 @@ start_gssrequest(dns_name_t *primary) {
|
|||||||
RUNTIME_CHECK(result < sizeof(servicename));
|
RUNTIME_CHECK(result < sizeof(servicename));
|
||||||
isc_buffer_init(&buf, servicename, strlen(servicename));
|
isc_buffer_init(&buf, servicename, strlen(servicename));
|
||||||
isc_buffer_add(&buf, strlen(servicename));
|
isc_buffer_add(&buf, strlen(servicename));
|
||||||
result = dns_name_fromtext(servname, &buf, dns_rootname, 0, NULL);
|
result = dns_name_fromtext(servname, &buf, dns_rootname, 0);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("dns_name_fromtext(servname) failed: %s",
|
fatal("dns_name_fromtext(servname) failed: %s",
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
@@ -3140,7 +3135,7 @@ start_gssrequest(dns_name_t *primary) {
|
|||||||
isc_buffer_init(&buf, mykeystr, strlen(mykeystr));
|
isc_buffer_init(&buf, mykeystr, strlen(mykeystr));
|
||||||
isc_buffer_add(&buf, strlen(mykeystr));
|
isc_buffer_add(&buf, strlen(mykeystr));
|
||||||
|
|
||||||
result = dns_name_fromtext(keyname, &buf, dns_rootname, 0, NULL);
|
result = dns_name_fromtext(keyname, &buf, dns_rootname, 0);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("dns_name_fromtext(keyname) failed: %s",
|
fatal("dns_name_fromtext(keyname) failed: %s",
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
@@ -3210,10 +3205,11 @@ send_gssrequest(isc_sockaddr_t *destaddr, dns_message_t *msg,
|
|||||||
srcaddr = localaddr4;
|
srcaddr = localaddr4;
|
||||||
}
|
}
|
||||||
|
|
||||||
result = dns_request_create(
|
result = dns_request_create(requestmgr, msg, srcaddr, destaddr,
|
||||||
requestmgr, msg, srcaddr, destaddr, req_transport,
|
req_transport, req_tls_ctx_cache, options,
|
||||||
req_tls_ctx_cache, options, tsigkey, timeout, udp_timeout,
|
tsigkey, timeout, timeout, udp_timeout,
|
||||||
udp_retries, isc_loop_main(loopmgr), recvgss, reqinfo, request);
|
udp_retries, isc_loop_main(loopmgr),
|
||||||
|
recvgss, reqinfo, request);
|
||||||
check_result(result, "dns_request_create");
|
check_result(result, "dns_request_create");
|
||||||
if (debugging) {
|
if (debugging) {
|
||||||
show_message(stdout, msg, "Outgoing update query:");
|
show_message(stdout, msg, "Outgoing update query:");
|
||||||
@@ -3298,7 +3294,7 @@ recvgss(void *arg) {
|
|||||||
servname = dns_fixedname_initname(&fname);
|
servname = dns_fixedname_initname(&fname);
|
||||||
isc_buffer_init(&buf, servicename, strlen(servicename));
|
isc_buffer_init(&buf, servicename, strlen(servicename));
|
||||||
isc_buffer_add(&buf, strlen(servicename));
|
isc_buffer_add(&buf, strlen(servicename));
|
||||||
result = dns_name_fromtext(servname, &buf, dns_rootname, 0, NULL);
|
result = dns_name_fromtext(servname, &buf, dns_rootname, 0);
|
||||||
check_result(result, "dns_name_fromtext");
|
check_result(result, "dns_name_fromtext");
|
||||||
|
|
||||||
result = dns_tkey_gssnegotiate(tsigquery, rcvmsg, servname, &context,
|
result = dns_tkey_gssnegotiate(tsigquery, rcvmsg, servname, &context,
|
||||||
|
|||||||
@@ -22,6 +22,7 @@
|
|||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/getaddresses.h>
|
#include <isc/getaddresses.h>
|
||||||
|
#include <isc/lib.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/loop.h>
|
#include <isc/loop.h>
|
||||||
#include <isc/managers.h>
|
#include <isc/managers.h>
|
||||||
@@ -36,6 +37,7 @@
|
|||||||
#include <isc/thread.h>
|
#include <isc/thread.h>
|
||||||
#include <isc/util.h>
|
#include <isc/util.h>
|
||||||
|
|
||||||
|
#include <dns/lib.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
|
|
||||||
#include <isccc/alist.h>
|
#include <isccc/alist.h>
|
||||||
@@ -143,6 +145,10 @@ command is one of the following:\n\
|
|||||||
Display RFC 5011 managed keys information\n\
|
Display RFC 5011 managed keys information\n\
|
||||||
managed-keys sync [class [view]]\n\
|
managed-keys sync [class [view]]\n\
|
||||||
Write RFC 5011 managed keys to disk\n\
|
Write RFC 5011 managed keys to disk\n\
|
||||||
|
memprof [ on | off | dump ]\n\
|
||||||
|
Enable / disable memory profiling or dump the profile.\n\
|
||||||
|
Requires named to built with jemalloc and run with the relevant\n\
|
||||||
|
MALLOC_CONF environment variables.\n\
|
||||||
modzone zone [class [view]] { zone-options }\n\
|
modzone zone [class [view]] { zone-options }\n\
|
||||||
Modify a zone's configuration.\n\
|
Modify a zone's configuration.\n\
|
||||||
Requires allow-new-zones option.\n\
|
Requires allow-new-zones option.\n\
|
||||||
|
|||||||
@@ -322,6 +322,19 @@ Currently supported commands are:
|
|||||||
keys in the event of a trust anchor rollover, or as a brute-force
|
keys in the event of a trust anchor rollover, or as a brute-force
|
||||||
repair for key maintenance problems.
|
repair for key maintenance problems.
|
||||||
|
|
||||||
|
.. option:: memprof [(on | off | dump)]
|
||||||
|
|
||||||
|
This command controls memory profiling. To have any effect, :iscman:`named` must be
|
||||||
|
built with jemalloc, the library have profiling support enabled and run with the
|
||||||
|
``prof:true`` allocator configuration. (either via ``MALLOC_CONF`` or ``/etc/malloc.conf``)
|
||||||
|
|
||||||
|
The ``prof_active:false`` option is recommended to ensure the profiling overhead does
|
||||||
|
not affect :iscman:`named` when not needed.
|
||||||
|
|
||||||
|
The ``on`` and ``off`` options will start and stop the jemalloc memory profiling respectively.
|
||||||
|
When run with the `dump` option, :iscman:`named` will dump the profile to the working
|
||||||
|
directory. The name will be chosen automatically by jemalloc.
|
||||||
|
|
||||||
.. option:: modzone zone [class [view]] configuration
|
.. option:: modzone zone [class [view]] configuration
|
||||||
|
|
||||||
This command modifies the configuration of a zone while the server is running. This
|
This command modifies the configuration of a zone while the server is running. This
|
||||||
|
|||||||
@@ -17,7 +17,6 @@
|
|||||||
|
|
||||||
#include <isc/attributes.h>
|
#include <isc/attributes.h>
|
||||||
#include <isc/formatcheck.h>
|
#include <isc/formatcheck.h>
|
||||||
#include <isc/lang.h>
|
|
||||||
|
|
||||||
#define NS_CONTROL_PORT 953
|
#define NS_CONTROL_PORT 953
|
||||||
|
|
||||||
@@ -31,12 +30,8 @@
|
|||||||
notify("%s", name); \
|
notify("%s", name); \
|
||||||
} while (0)
|
} while (0)
|
||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
|
||||||
|
|
||||||
void
|
void
|
||||||
notify(const char *fmt, ...) ISC_FORMAT_PRINTF(1, 2);
|
notify(const char *fmt, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||||
|
|
||||||
ISC_NORETURN void
|
ISC_NORETURN void
|
||||||
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||||
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
|
|||||||
@@ -150,7 +150,6 @@ TESTS = \
|
|||||||
sfcache \
|
sfcache \
|
||||||
shutdown \
|
shutdown \
|
||||||
smartsign \
|
smartsign \
|
||||||
sortlist \
|
|
||||||
spf \
|
spf \
|
||||||
staticstub \
|
staticstub \
|
||||||
statistics \
|
statistics \
|
||||||
|
|||||||
@@ -34,6 +34,6 @@ zone "." {
|
|||||||
file "redirect.db";
|
file "redirect.db";
|
||||||
};
|
};
|
||||||
|
|
||||||
primaries "test" {
|
remote-servers "test" {
|
||||||
10.53.0.99;
|
10.53.0.99;
|
||||||
};
|
};
|
||||||
|
|||||||
+1
-1
@@ -11,5 +11,5 @@
|
|||||||
* information regarding copyright ownership.
|
* information regarding copyright ownership.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
primaries duplicate { 1.2.3.4; };
|
remote-servers duplicate { 1.2.3.4; };
|
||||||
primaries duplicate { 4.3.2.1; };
|
primaries duplicate { 4.3.2.1; };
|
||||||
+2
-2
@@ -11,5 +11,5 @@
|
|||||||
* information regarding copyright ownership.
|
* information regarding copyright ownership.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
masters duplicate { 1.2.3.4; };
|
remote-servers duplicate { 1.2.3.4; };
|
||||||
primaries duplicate { 4.3.2.1; };
|
remote-servers duplicate { 4.3.2.1; };
|
||||||
@@ -12,7 +12,7 @@
|
|||||||
*/
|
*/
|
||||||
|
|
||||||
view "test" {
|
view "test" {
|
||||||
parental-agents "net" {
|
remote-servers "net" {
|
||||||
192.168.1.2;
|
192.168.1.2;
|
||||||
};
|
};
|
||||||
zone "example.net" {
|
zone "example.net" {
|
||||||
|
|||||||
@@ -11,11 +11,11 @@
|
|||||||
* information regarding copyright ownership.
|
* information regarding copyright ownership.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
parental-agents "net" {
|
remote-servers "net" {
|
||||||
192.168.1.1;
|
192.168.1.1;
|
||||||
};
|
};
|
||||||
|
|
||||||
parental-agents "net" {
|
remote-servers "net" {
|
||||||
192.168.1.2;
|
192.168.1.2;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -11,7 +11,7 @@
|
|||||||
* information regarding copyright ownership.
|
* information regarding copyright ownership.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
parental-agents "net" { };
|
remote-servers "net" { };
|
||||||
|
|
||||||
zone "example.net" {
|
zone "example.net" {
|
||||||
type primary;
|
type primary;
|
||||||
|
|||||||
@@ -11,7 +11,7 @@
|
|||||||
* information regarding copyright ownership.
|
* information regarding copyright ownership.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
parental-agents "com" {
|
remote-servers "com" {
|
||||||
192.168.1.2;
|
192.168.1.2;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -11,7 +11,7 @@
|
|||||||
* information regarding copyright ownership.
|
* information regarding copyright ownership.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
primaries "net" {
|
remote-servers "net" {
|
||||||
192.168.1.2;
|
192.168.1.2;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -14,8 +14,6 @@
|
|||||||
options {
|
options {
|
||||||
dnssec-validation yes;
|
dnssec-validation yes;
|
||||||
max-zone-ttl 600;
|
max-zone-ttl 600;
|
||||||
|
|
||||||
sortlist { };
|
|
||||||
};
|
};
|
||||||
|
|
||||||
trust-anchors {
|
trust-anchors {
|
||||||
|
|||||||
@@ -0,0 +1,28 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: MPL-2.0
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
remote-servers "one" {
|
||||||
|
1.2.3.4;
|
||||||
|
};
|
||||||
|
|
||||||
|
parental-agents "two" {
|
||||||
|
1.2.3.5;
|
||||||
|
};
|
||||||
|
|
||||||
|
primaries "three" {
|
||||||
|
1.2.3.6;
|
||||||
|
};
|
||||||
|
|
||||||
|
masters "four" {
|
||||||
|
1.2.3.7;
|
||||||
|
};
|
||||||
+2
-2
@@ -11,5 +11,5 @@
|
|||||||
* information regarding copyright ownership.
|
* information regarding copyright ownership.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
masters a { 1.2.3.4; };
|
remote-servers a { 1.2.3.4; };
|
||||||
primaries b { 1.2.3.4; };
|
remote-servers b { 1.2.3.4; };
|
||||||
@@ -86,7 +86,7 @@ options {
|
|||||||
transfer-source 0.0.0.0;
|
transfer-source 0.0.0.0;
|
||||||
zone-statistics none;
|
zone-statistics none;
|
||||||
};
|
};
|
||||||
parental-agents "parents" port 5353 source 10.10.10.10 source-v6 2001:db8::10 {
|
remote-servers "parents" port 5353 source 10.10.10.10 source-v6 2001:db8::10 {
|
||||||
10.10.10.11;
|
10.10.10.11;
|
||||||
2001:db8::11;
|
2001:db8::11;
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -12,8 +12,8 @@
|
|||||||
*/
|
*/
|
||||||
|
|
||||||
acl "transferees" {};
|
acl "transferees" {};
|
||||||
primaries "stealthPrimaries" {127.0.0.1;};
|
remote-servers "stealthPrimaries" {127.0.0.1;};
|
||||||
primaries "publicSecondaries" {127.0.0.1;};
|
remote-servers "publicSecondaries" {127.0.0.1;};
|
||||||
zone "example.net" {
|
zone "example.net" {
|
||||||
type secondary;
|
type secondary;
|
||||||
key-directory "/var/lib/bind/example.net";
|
key-directory "/var/lib/bind/example.net";
|
||||||
|
|||||||
@@ -12,8 +12,8 @@
|
|||||||
*/
|
*/
|
||||||
|
|
||||||
acl "transferees" {};
|
acl "transferees" {};
|
||||||
primaries "stealthPrimaries" {127.0.0.1;};
|
remote-servers "stealthPrimaries" {127.0.0.1;};
|
||||||
primaries "publicSecondaries" {127.0.0.1;};
|
remote-servers "publicSecondaries" {127.0.0.1;};
|
||||||
zone "example.net" {
|
zone "example.net" {
|
||||||
type secondary;
|
type secondary;
|
||||||
file "/var/cache/bind/example.net.db";
|
file "/var/cache/bind/example.net.db";
|
||||||
|
|||||||
@@ -12,8 +12,8 @@
|
|||||||
*/
|
*/
|
||||||
|
|
||||||
acl "transferees" {};
|
acl "transferees" {};
|
||||||
primaries "stealthPrimaries" {127.0.0.1;};
|
remote-servers "stealthPrimaries" {127.0.0.1;};
|
||||||
primaries "publicSecondaries" {127.0.0.1;};
|
remote-servers "publicSecondaries" {127.0.0.1;};
|
||||||
zone "example.net" {
|
zone "example.net" {
|
||||||
type secondary;
|
type secondary;
|
||||||
key-directory "/var/lib/bind/example.net";
|
key-directory "/var/lib/bind/example.net";
|
||||||
|
|||||||
@@ -184,7 +184,6 @@ echo_i "checking named-checkconf deprecate warnings ($n)"
|
|||||||
ret=0
|
ret=0
|
||||||
$CHECKCONF deprecated.conf >checkconf.out$n.1 2>&1 || ret=1
|
$CHECKCONF deprecated.conf >checkconf.out$n.1 2>&1 || ret=1
|
||||||
grep "option 'max-zone-ttl' is deprecated" <checkconf.out$n.1 >/dev/null || ret=1
|
grep "option 'max-zone-ttl' is deprecated" <checkconf.out$n.1 >/dev/null || ret=1
|
||||||
grep "option 'sortlist' is deprecated" <checkconf.out$n.1 >/dev/null || ret=1
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
# set -i to ignore deprecate warnings
|
# set -i to ignore deprecate warnings
|
||||||
|
|||||||
@@ -37,7 +37,7 @@ controls {
|
|||||||
inet 10.53.0.9 port @CONTROLPORT@ allow { any; } keys { rndc_key; };
|
inet 10.53.0.9 port @CONTROLPORT@ allow { any; } keys { rndc_key; };
|
||||||
};
|
};
|
||||||
|
|
||||||
parental-agents "ns8" port @PORT@ {
|
remote-servers "ns8" port @PORT@ {
|
||||||
10.53.0.8;
|
10.53.0.8;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -44,6 +44,10 @@ for db in zones/bad*.db; do
|
|||||||
zones/bad-dns-sd-reverse.db | zones/bad-svcb-servername.db)
|
zones/bad-dns-sd-reverse.db | zones/bad-svcb-servername.db)
|
||||||
$CHECKZONE -k fail -i local 0.0.0.0.in-addr.arpa $db >test.out.$n 2>&1 || v=$?
|
$CHECKZONE -k fail -i local 0.0.0.0.in-addr.arpa $db >test.out.$n 2>&1 || v=$?
|
||||||
;;
|
;;
|
||||||
|
bad-cname-and*.db)
|
||||||
|
$CHECKZONE -i local example $db >test.out.$n 2>&1 || v=$?
|
||||||
|
grep "CNAME and other data" test.out.$n >/dev/null || ret=1
|
||||||
|
;;
|
||||||
*)
|
*)
|
||||||
$CHECKZONE -i local example $db >test.out.$n 2>&1 || v=$?
|
$CHECKZONE -i local example $db >test.out.$n 2>&1 || v=$?
|
||||||
;;
|
;;
|
||||||
@@ -218,5 +222,41 @@ echo $lines
|
|||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|
||||||
|
echo_i "Checking for 'zone has A records but is not served by IPv4 servers' warning ($n)"
|
||||||
|
ret=0
|
||||||
|
$CHECKZONE example zones/warn.no-a.server.db >test.out1.$n 2>&1 || ret=1
|
||||||
|
grep "zone has A records but is not served by IPv4 servers" test.out1.$n >/dev/null || ret=1
|
||||||
|
grep "zone has AAAA records but is not served by IPv6 servers" test.out1.$n >/dev/null && ret=1
|
||||||
|
n=$((n + 1))
|
||||||
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
|
status=$((status + ret))
|
||||||
|
|
||||||
|
echo_i "Checking for 'zone has AAAA records but is not served by IPv6 servers' warning ($n)"
|
||||||
|
ret=0
|
||||||
|
$CHECKZONE example zones/warn.no-aaaa.server.db >test.out1.$n 2>&1 || ret=1
|
||||||
|
grep "zone has AAAA records but is not served by IPv6 servers" test.out1.$n >/dev/null || ret=1
|
||||||
|
grep "zone has A records but is not served by IPv4 servers" test.out1.$n >/dev/null && ret=1
|
||||||
|
n=$((n + 1))
|
||||||
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
|
status=$((status + ret))
|
||||||
|
|
||||||
|
echo_i "Checking for 'zone has A records but is not served by IPv4 servers' warning for glue ($n)"
|
||||||
|
ret=0
|
||||||
|
$CHECKZONE example zones/warn.no-a.server.glue.db >test.out1.$n 2>&1 || ret=1
|
||||||
|
grep "zone has A records but is not served by IPv4 servers" test.out1.$n >/dev/null || ret=1
|
||||||
|
grep "zone has AAAA records but is not served by IPv6 servers" test.out1.$n >/dev/null && ret=1
|
||||||
|
n=$((n + 1))
|
||||||
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
|
status=$((status + ret))
|
||||||
|
|
||||||
|
echo_i "Checking for 'zone has AAAA records but is not served by IPv6 servers' warning for glue ($n)"
|
||||||
|
ret=0
|
||||||
|
$CHECKZONE example zones/warn.no-aaaa.server.glue.db >test.out1.$n 2>&1 || ret=1
|
||||||
|
grep "zone has AAAA records but is not served by IPv6 servers" test.out1.$n >/dev/null || ret=1
|
||||||
|
grep "zone has A records but is not served by IPv4 servers" test.out1.$n >/dev/null && ret=1
|
||||||
|
n=$((n + 1))
|
||||||
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
|
status=$((status + ret))
|
||||||
|
|
||||||
echo_i "exit status: $status"
|
echo_i "exit status: $status"
|
||||||
[ $status -eq 0 ] || exit 1
|
[ $status -eq 0 ] || exit 1
|
||||||
|
|||||||
@@ -0,0 +1,17 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad A 192.0.2.1
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A6 0 ::1
|
||||||
|
bad WKS 10.0.0.1 tcp telnet ftp 0 1 2
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad AAAA ::1
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad BAD 65535 .
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad APL
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad ATMA +61200000000
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad ATMRELAY 0 0 0
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad AVC foo:bar
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad CAA 128 tbs "Unknown"
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad CDNSKEY 512 ( 255 1 AQMFD5raczCJHViKtLYhWGz8hMY
|
||||||
|
9UGRuniJDBzC7w0aRyzWZriO6i2odGWWQVucZqKV
|
||||||
|
sENW91IOW4vqudngPZsY3GvQ/xVA8/7pyFj6b7Esg
|
||||||
|
a60zyGW6LFe9r8n6paHrlG5ojqf0BaqHT+8= )
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad CDS 30795 1 1 310D27F4D82C1FC2400704EA9939FE6E1CEA A3B9
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad CERT 65534 65535 254 (
|
||||||
|
MxFcby9k/yvedMfQgKzhH5er0Mu/vILz45I
|
||||||
|
kskceFGgiWCn/GxHhai6VAuHAoNUz4YoU1t
|
||||||
|
VfSCSqQYn6//11U6Nld80jEeC8aTrO+KKmCaY= )
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad CSYNC 0 0 A NS AAAA
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad DHCID AAIBY2/AuCccgoJbsaxcQc9TUapptP69l OjxfNuVAA2kjEA=
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad DLV 30795 1 1 (
|
||||||
|
310D27F4D82C1FC2400704EA9939FE6E1CEA
|
||||||
|
A3B9 )
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad DNAME @
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad DOA 0 1 2 "" aHR0cHM6Ly93d3cuaXNjLm9yZy8=
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad EID 12 89 AB
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad EUI48 01-23-45-67-89-ab
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad EUI64 01-23-45-67-89-ab-cd-ef
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad GPOS -22.6882 116.8652 250.0
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad HINFO . .
|
||||||
|
bad CNAME @
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 600
|
||||||
|
@ SOA ns hostmaster 2011012708 3600 1200 604800 1200
|
||||||
|
NS ns
|
||||||
|
ns A 192.0.2.1
|
||||||
|
bad HIP ( 2 200100107B1A74DF365639CC39F1D578
|
||||||
|
AwEAAbdxyhNuSutc5EMzxTs9LBPCIkOFH8cIvM4p9+LrV4e19WzK00+CI6zBCQTdtWsuxKbWIy87UOoJTwkUs7lBu+Upr1gsNrut79ryra+bSRGQb1slImA8YVJyuIDsj7kwzG7jnERNqnWxZ48AWkskmdHaVDP4BcelrTI3rMXdXF5D
|
||||||
|
rvs.example.com. )
|
||||||
|
bad CNAME @
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user