Compare commits
106
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
14271bf4e2 | ||
|
|
db6e91497c | ||
|
|
b735f2e821 | ||
|
|
e39d265a99 | ||
|
|
8f03f31106 | ||
|
|
d3d981f38e | ||
|
|
6c291971db | ||
|
|
d61dc02a7c | ||
|
|
503c7a86fe | ||
|
|
6876c06918 | ||
|
|
fdb9a24d18 | ||
|
|
ea33257ad0 | ||
|
|
dd971ad4e4 | ||
|
|
8368ef5ae7 | ||
|
|
d8778caec7 | ||
|
|
a8dd267bd0 | ||
|
|
606d30796e | ||
|
|
37ff0aa9c0 | ||
|
|
1c51d44d82 | ||
|
|
3b0b658a52 | ||
|
|
ecde0ea2d7 | ||
|
|
7d98aba3ac | ||
|
|
24eaff7adc | ||
|
|
025ef4d7b8 | ||
|
|
9cfe9f5eb7 | ||
|
|
e6c07b3386 | ||
|
|
1a58bd2113 | ||
|
|
42799ae81f | ||
|
|
de519cd1c9 | ||
|
|
496f7963cd | ||
|
|
98fc14dc75 | ||
|
|
3397212df3 | ||
|
|
947ca25663 | ||
|
|
6c271f6328 | ||
|
|
6ac4cfb948 | ||
|
|
f6f9645ed1 | ||
|
|
1f674ef42e | ||
|
|
f50753f303 | ||
|
|
45ee3715e1 | ||
|
|
7f613c207f | ||
|
|
24ffbdcfea | ||
|
|
e66dc07c68 | ||
|
|
e763d6637f | ||
|
|
334ea1269f | ||
|
|
3309863c97 | ||
|
|
8b3d2e5633 | ||
|
|
3973c2e8c3 | ||
|
|
ecef45bf18 | ||
|
|
33a0cc9823 | ||
|
|
bd711bb839 | ||
|
|
b652d5327c | ||
|
|
1e4695510a | ||
|
|
db5166ab99 | ||
|
|
6cd9e4f67c | ||
|
|
4ba1ccfa2e | ||
|
|
1fae6ccea1 | ||
|
|
eab9fc22e7 | ||
|
|
552cf64a70 | ||
|
|
f28020265c | ||
|
|
e0df774ca0 | ||
|
|
fd48df20f3 | ||
|
|
006c5990ce | ||
|
|
4e68dbf194 | ||
|
|
303c20caf8 | ||
|
|
d388063466 | ||
|
|
87776a51ae | ||
|
|
22b5442722 | ||
|
|
23394afa9e | ||
|
|
f3458fdf43 | ||
|
|
988dc57c8c | ||
|
|
6320586df0 | ||
|
|
00d7c7c346 | ||
|
|
daa9c17905 | ||
|
|
4024e0d5c1 | ||
|
|
c8104daf8d | ||
|
|
eaad0aefe6 | ||
|
|
217a1ebd79 | ||
|
|
c5f7968856 | ||
|
|
0e1b02868a | ||
|
|
0956fb9b9e | ||
|
|
239712df16 | ||
|
|
ce7879c924 | ||
|
|
534069e048 | ||
|
|
901637c25c | ||
|
|
c5075a9a61 | ||
|
|
2aa70fff76 | ||
|
|
e02d73e7e3 | ||
|
|
7293cb0612 | ||
|
|
67d37a365e | ||
|
|
de0598cbc3 | ||
|
|
f3087f1299 | ||
|
|
1b3e7f52ec | ||
|
|
68bbf151a4 | ||
|
|
58ea2b1b22 | ||
|
|
ac9eec6327 | ||
|
|
6e2272d769 | ||
|
|
462f367d87 | ||
|
|
9ebeb60174 | ||
|
|
3de629d6b7 | ||
|
|
f4ab4f07e3 | ||
|
|
ce47cb3ab6 | ||
|
|
29fd756408 | ||
|
|
4214c1e8a7 | ||
|
|
23c1fbc609 | ||
|
|
98ff3a4432 | ||
|
|
5633dc90d3 |
+121
-86
@@ -56,6 +56,16 @@ variables:
|
|||||||
# Some jobs may clean up the build artifacts unless this is set to 0.
|
# Some jobs may clean up the build artifacts unless this is set to 0.
|
||||||
CLEAN_BUILD_ARTIFACTS_ON_SUCCESS: 1
|
CLEAN_BUILD_ARTIFACTS_ON_SUCCESS: 1
|
||||||
|
|
||||||
|
# DNS Shotgun performance testing defaults
|
||||||
|
SHOTGUN_ROUNDS: 1
|
||||||
|
SHOTGUN_DURATION: 120
|
||||||
|
# allow unlimited improvements against baseline
|
||||||
|
SHOTGUN_EVAL_THRESHOLD_CPU_MIN: '-inf'
|
||||||
|
SHOTGUN_EVAL_THRESHOLD_MEMORY_MIN: '-inf'
|
||||||
|
SHOTGUN_EVAL_THRESHOLD_RCODE_MAX: '+inf'
|
||||||
|
SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_MIN: '-inf'
|
||||||
|
SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_DRIFT_MIN: '-inf'
|
||||||
|
|
||||||
default:
|
default:
|
||||||
# Allow all running CI jobs to be automatically canceled when a new
|
# Allow all running CI jobs to be automatically canceled when a new
|
||||||
# version of a branch is pushed.
|
# version of a branch is pushed.
|
||||||
@@ -107,16 +117,55 @@ stages:
|
|||||||
- runner-manager
|
- runner-manager
|
||||||
- aarch64
|
- aarch64
|
||||||
|
|
||||||
# Autoscaling GitLab Runner on AWS EC2 (FreeBSD)
|
.freebsd-autoscaler-13-amd64-tags: &freebsd_autoscaler_13_amd64_tags
|
||||||
|
|
||||||
.freebsd-stress-amd64: &freebsd_stress_amd64
|
|
||||||
tags:
|
tags:
|
||||||
- bsd-stress-test
|
- amd64
|
||||||
- aws
|
|
||||||
- autoscaler
|
- autoscaler
|
||||||
|
- aws
|
||||||
|
- bsd-stress-test-1
|
||||||
- shell
|
- shell
|
||||||
- stress-test
|
- stress-test
|
||||||
|
|
||||||
|
.freebsd-autoscaler-14-amd64-tags: &freebsd_autoscaler_14_amd64_tags
|
||||||
|
tags:
|
||||||
- amd64
|
- amd64
|
||||||
|
- autoscaler
|
||||||
|
- aws
|
||||||
|
- bsd-stress-test-2
|
||||||
|
- shell
|
||||||
|
- stress-test
|
||||||
|
|
||||||
|
.freebsd-autoscaler-amd64: &freebsd_autoscaler_amd64
|
||||||
|
variables:
|
||||||
|
CC: clang
|
||||||
|
CFLAGS: "${CFLAGS_COMMON} -Og"
|
||||||
|
# Even though there's only one job per runtime environment, the GitLab
|
||||||
|
# "instance" executor insists on cloning the Git repository to a path that
|
||||||
|
# contains a variable number from zero to the "maximum concurrent instances
|
||||||
|
# count" allowed on the GitLab Runner. See the "0" directory in this
|
||||||
|
# example path: /home/ec2-user/builds/t1_4FZzvz/0/isc-projects/bind9/.git/.
|
||||||
|
#
|
||||||
|
# This is not a problem for isolated jobs like "stress" tests that depend
|
||||||
|
# on no other jobs. However, it is a problem for jobs that need other jobs'
|
||||||
|
# artifacts. For example, a system test job that has its Git repo cloned to
|
||||||
|
# the "/1/" sub-path will fail if it downloads build job artifacts that
|
||||||
|
# have ./configure output files with "/0/" in its sub-path recorded.
|
||||||
|
GIT_CLONE_PATH: "/home/ec2-user/builds/${CI_PROJECT_PATH}/"
|
||||||
|
# Use MIT Kerberos5 for BIND 9 GSS-API support because of FreeBSD Heimdal
|
||||||
|
# incompatibility; see https://bugs.freebsd.org/275241.
|
||||||
|
EXTRA_CONFIGURE: "${WITH_READLINE_EDITLINE} --with-gssapi=/usr/local/bin/krb5-config"
|
||||||
|
|
||||||
|
# Autoscaling GitLab Runner on AWS EC2 (FreeBSD 13)
|
||||||
|
|
||||||
|
.freebsd-autoscaler-13-amd64: &freebsd_autoscaler_13_amd64
|
||||||
|
<<: *freebsd_autoscaler_amd64
|
||||||
|
<<: *freebsd_autoscaler_13_amd64_tags
|
||||||
|
|
||||||
|
# Autoscaling GitLab Runner on AWS EC2 (FreeBSD 14)
|
||||||
|
|
||||||
|
.freebsd-autoscaler-14-amd64: &freebsd_autoscaler_14_amd64
|
||||||
|
<<: *freebsd_autoscaler_amd64
|
||||||
|
<<: *freebsd_autoscaler_14_amd64_tags
|
||||||
|
|
||||||
### Docker Image Templates
|
### Docker Image Templates
|
||||||
|
|
||||||
@@ -204,14 +253,6 @@ stages:
|
|||||||
|
|
||||||
### QCOW2 Image Templates
|
### QCOW2 Image Templates
|
||||||
|
|
||||||
.freebsd-13-amd64: &freebsd_13_amd64_image
|
|
||||||
image: "freebsd-13.4-x86_64"
|
|
||||||
<<: *libvirt_amd64
|
|
||||||
|
|
||||||
.freebsd-14-amd64: &freebsd_14_amd64_image
|
|
||||||
image: "freebsd-14.2-x86_64"
|
|
||||||
<<: *libvirt_amd64
|
|
||||||
|
|
||||||
.openbsd-amd64: &openbsd_amd64_image
|
.openbsd-amd64: &openbsd_amd64_image
|
||||||
image: "openbsd-7.6-x86_64"
|
image: "openbsd-7.6-x86_64"
|
||||||
<<: *libvirt_amd64
|
<<: *libvirt_amd64
|
||||||
@@ -219,31 +260,18 @@ stages:
|
|||||||
### Job Templates
|
### Job Templates
|
||||||
|
|
||||||
.api-pipelines-schedules-tags-triggers-web-triggering-rules: &api_pipelines_schedules_tags_triggers_web_triggering_rules
|
.api-pipelines-schedules-tags-triggers-web-triggering-rules: &api_pipelines_schedules_tags_triggers_web_triggering_rules
|
||||||
only:
|
rules:
|
||||||
- api
|
- if: '$CI_PIPELINE_SOURCE =~ /^(api|pipeline|schedule|trigger|web)$/'
|
||||||
- pipelines
|
- if: '$CI_COMMIT_TAG != null'
|
||||||
- schedules
|
|
||||||
- tags
|
|
||||||
- triggers
|
|
||||||
- web
|
|
||||||
|
|
||||||
.api-pipelines-schedules-triggers-web-triggering-rules: &api_pipelines_schedules_triggers_web_triggering_rules
|
.api-pipelines-schedules-triggers-web-triggering-rules: &api_pipelines_schedules_triggers_web_triggering_rules
|
||||||
only:
|
rules:
|
||||||
- api
|
- if: '$CI_PIPELINE_SOURCE =~ /^(api|pipeline|schedule|trigger|web)$/'
|
||||||
- pipelines
|
|
||||||
- schedules
|
|
||||||
- triggers
|
|
||||||
- web
|
|
||||||
|
|
||||||
.default-triggering-rules: &default_triggering_rules
|
.default-triggering-rules: &default_triggering_rules
|
||||||
only:
|
rules:
|
||||||
- api
|
- if: '$CI_PIPELINE_SOURCE =~ /^(api|merge_request_event|pipeline|schedule|trigger|web)$/'
|
||||||
- merge_requests
|
- if: '$CI_COMMIT_TAG != null'
|
||||||
- pipelines
|
|
||||||
- schedules
|
|
||||||
- tags
|
|
||||||
- triggers
|
|
||||||
- web
|
|
||||||
|
|
||||||
.precheck: &precheck_job
|
.precheck: &precheck_job
|
||||||
<<: *default_triggering_rules
|
<<: *default_triggering_rules
|
||||||
@@ -343,18 +371,38 @@ stages:
|
|||||||
|
|
||||||
.shotgun: &shotgun_job
|
.shotgun: &shotgun_job
|
||||||
<<: *base_image
|
<<: *base_image
|
||||||
<<: *api_pipelines_schedules_tags_triggers_web_triggering_rules
|
|
||||||
stage: performance
|
stage: performance
|
||||||
|
rules:
|
||||||
|
- &shotgun_rule_mr
|
||||||
|
if: '$CI_MERGE_REQUEST_DIFF_BASE_SHA != null'
|
||||||
|
variables:
|
||||||
|
BASELINE: '$CI_MERGE_REQUEST_DIFF_BASE_SHA'
|
||||||
|
- &shotgun_rule_tag
|
||||||
|
if: '$CI_COMMIT_TAG != null'
|
||||||
|
variables:
|
||||||
|
SHOTGUN_ROUNDS: 3
|
||||||
|
- &shotgun_rule_other
|
||||||
|
if: '$CI_PIPELINE_SOURCE =~ /^(api|pipeline|schedule|trigger|web)$/'
|
||||||
script:
|
script:
|
||||||
- if [ -z "$CI_COMMIT_TAG" ]; then export SHOTGUN_ROUNDS=1; else export SHOTGUN_ROUNDS=3; fi
|
- if [ -z "$BASELINE" ]; then export BASELINE=$BIND_BASELINE_VERSION; fi # this dotenv variable can't be set in the rules section, because rules are evaluated before any jobs run
|
||||||
- PIPELINE_ID=$(curl -s -X POST --fail
|
- PIPELINE_ID=$(curl -s -X POST --fail
|
||||||
-F "token=$CI_JOB_TOKEN"
|
-F "token=$CI_JOB_TOKEN"
|
||||||
-F ref=main
|
-F ref=main
|
||||||
-F "variables[SHOTGUN_TEST_VERSION]=['$CI_COMMIT_REF_NAME', '$BIND_BASELINE_VERSION']"
|
-F "variables[SHOTGUN_TEST_VERSION]=['$CI_COMMIT_REF_NAME', '$BASELINE']"
|
||||||
-F "variables[SHOTGUN_DURATION]=300"
|
-F "variables[SHOTGUN_DURATION]=300"
|
||||||
-F "variables[SHOTGUN_ROUNDS]=$SHOTGUN_ROUNDS"
|
-F "variables[SHOTGUN_ROUNDS]=$SHOTGUN_ROUNDS"
|
||||||
-F "variables[SHOTGUN_TRAFFIC_MULTIPLIER]=$SHOTGUN_TRAFFIC_MULTIPLIER"
|
-F "variables[SHOTGUN_TRAFFIC_MULTIPLIER]=$SHOTGUN_TRAFFIC_MULTIPLIER"
|
||||||
-F "variables[SHOTGUN_SCENARIO]=$SHOTGUN_SCENARIO"
|
-F "variables[SHOTGUN_SCENARIO]=$SHOTGUN_SCENARIO"
|
||||||
|
-F "variables[SHOTGUN_EVAL_THRESHOLD_CPU_MIN]=$SHOTGUN_EVAL_THRESHOLD_CPU_MIN"
|
||||||
|
-F "variables[SHOTGUN_EVAL_THRESHOLD_CPU_MAX]=$SHOTGUN_EVAL_THRESHOLD_CPU_MAX"
|
||||||
|
-F "variables[SHOTGUN_EVAL_THRESHOLD_MEMORY_MIN]=$SHOTGUN_EVAL_THRESHOLD_MEMORY_MIN"
|
||||||
|
-F "variables[SHOTGUN_EVAL_THRESHOLD_MEMORY_MAX]=$SHOTGUN_EVAL_THRESHOLD_MEMORY_MAX"
|
||||||
|
-F "variables[SHOTGUN_EVAL_THRESHOLD_RCODE_MIN]=$SHOTGUN_EVAL_THRESHOLD_RCODE_MIN"
|
||||||
|
-F "variables[SHOTGUN_EVAL_THRESHOLD_RCODE_MAX]=$SHOTGUN_EVAL_THRESHOLD_RCODE_MAX"
|
||||||
|
-F "variables[SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_MIN]=$SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_MIN"
|
||||||
|
-F "variables[SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_MAX]=$SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_MAX"
|
||||||
|
-F "variables[SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_DRIFT_MIN]=$SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_DRIFT_MIN"
|
||||||
|
-F "variables[SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_DRIFT_MAX]=$SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_DRIFT_MAX"
|
||||||
https://gitlab.isc.org/api/v4/projects/188/trigger/pipeline | jq .id)
|
https://gitlab.isc.org/api/v4/projects/188/trigger/pipeline | jq .id)
|
||||||
- util/ci-wait-shotgun.py $PIPELINE_ID
|
- util/ci-wait-shotgun.py $PIPELINE_ID
|
||||||
needs:
|
needs:
|
||||||
@@ -511,6 +559,8 @@ misc:
|
|||||||
- if git grep SYSTEMTESTTOP -- ':!.gitlab-ci.yml'; then echo 'Please use relative paths instead of $SYSTEMTESTTOP.'; exit 1; fi
|
- if git grep SYSTEMTESTTOP -- ':!.gitlab-ci.yml'; then echo 'Please use relative paths instead of $SYSTEMTESTTOP.'; exit 1; fi
|
||||||
- bash util/unused-headers.sh
|
- bash util/unused-headers.sh
|
||||||
- bash util/xmllint-html.sh
|
- bash util/xmllint-html.sh
|
||||||
|
# Check dangling symlinks in the repository
|
||||||
|
- if find . -xtype l | grep .; then exit 1; fi
|
||||||
needs: []
|
needs: []
|
||||||
artifacts:
|
artifacts:
|
||||||
paths:
|
paths:
|
||||||
@@ -619,9 +669,8 @@ danger:
|
|||||||
script:
|
script:
|
||||||
- pip install git+https://gitlab.isc.org/isc-projects/hazard.git
|
- pip install git+https://gitlab.isc.org/isc-projects/hazard.git
|
||||||
- hazard
|
- hazard
|
||||||
only:
|
rules:
|
||||||
refs:
|
- if: '$CI_PIPELINE_SOURCE == "merge_request_event"'
|
||||||
- merge_requests
|
|
||||||
|
|
||||||
checkbashisms:
|
checkbashisms:
|
||||||
<<: *precheck_job
|
<<: *precheck_job
|
||||||
@@ -1289,7 +1338,7 @@ gcc:tsan:
|
|||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Wno-stringop-overread -ggdb -O2 -fsanitize=thread"
|
CFLAGS: "${CFLAGS_COMMON} -Wno-stringop-overread -ggdb -O2 -fsanitize=thread"
|
||||||
LDFLAGS: "-fsanitize=thread"
|
LDFLAGS: "-fsanitize=thread -Wl,--disable-new-dtags"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig"
|
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig"
|
||||||
<<: *tsan_fedora_41_amd64_image
|
<<: *tsan_fedora_41_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -1318,7 +1367,8 @@ clang:tsan:
|
|||||||
variables:
|
variables:
|
||||||
CC: "${CLANG}"
|
CC: "${CLANG}"
|
||||||
CFLAGS: "${CFLAGS_COMMON} -ggdb -O2 -fsanitize=thread"
|
CFLAGS: "${CFLAGS_COMMON} -ggdb -O2 -fsanitize=thread"
|
||||||
LDFLAGS: "-fsanitize=thread"
|
# -Wl,--disable-new-dtags ensures that Clang creates valid TSAN reports
|
||||||
|
LDFLAGS: "-fsanitize=thread -Wl,--disable-new-dtags"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig"
|
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig"
|
||||||
|
|
||||||
system:clang:tsan:
|
system:clang:tsan:
|
||||||
@@ -1397,27 +1447,19 @@ unit:clang:bookworm:amd64:
|
|||||||
# Jobs for Clang builds on FreeBSD 13 (amd64)
|
# Jobs for Clang builds on FreeBSD 13 (amd64)
|
||||||
|
|
||||||
clang:freebsd13:amd64:
|
clang:freebsd13:amd64:
|
||||||
variables:
|
|
||||||
CFLAGS: "${CFLAGS_COMMON}"
|
|
||||||
# Use MIT Kerberos5 for BIND 9 GSS-API support because of FreeBSD Heimdal
|
|
||||||
# incompatibility; see https://bugs.freebsd.org/275241.
|
|
||||||
EXTRA_CONFIGURE: "${WITH_READLINE_LIBEDIT} --with-gssapi=/usr/local/bin/krb5-config"
|
|
||||||
USER: gitlab-runner
|
|
||||||
<<: *freebsd_13_amd64_image
|
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
|
<<: *freebsd_autoscaler_13_amd64
|
||||||
|
|
||||||
system:clang:freebsd13:amd64:
|
system:clang:freebsd13:amd64:
|
||||||
<<: *freebsd_13_amd64_image
|
|
||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
variables:
|
<<: *freebsd_autoscaler_13_amd64
|
||||||
USER: gitlab-runner
|
|
||||||
needs:
|
needs:
|
||||||
- job: clang:freebsd13:amd64
|
- job: clang:freebsd13:amd64
|
||||||
artifacts: true
|
artifacts: true
|
||||||
|
|
||||||
unit:clang:freebsd13:amd64:
|
unit:clang:freebsd13:amd64:
|
||||||
<<: *freebsd_13_amd64_image
|
|
||||||
<<: *unit_test_job
|
<<: *unit_test_job
|
||||||
|
<<: *freebsd_autoscaler_13_amd64
|
||||||
needs:
|
needs:
|
||||||
- job: clang:freebsd13:amd64
|
- job: clang:freebsd13:amd64
|
||||||
artifacts: true
|
artifacts: true
|
||||||
@@ -1425,27 +1467,19 @@ unit:clang:freebsd13:amd64:
|
|||||||
# Jobs for Clang builds on FreeBSD 14 (amd64)
|
# Jobs for Clang builds on FreeBSD 14 (amd64)
|
||||||
|
|
||||||
clang:freebsd14:amd64:
|
clang:freebsd14:amd64:
|
||||||
variables:
|
|
||||||
CFLAGS: "${CFLAGS_COMMON}"
|
|
||||||
# Use MIT Kerberos5 for BIND 9 GSS-API support because of FreeBSD Heimdal
|
|
||||||
# incompatibility; see https://bugs.freebsd.org/275241.
|
|
||||||
EXTRA_CONFIGURE: "${WITH_READLINE_EDITLINE} --with-gssapi=/usr/local/bin/krb5-config"
|
|
||||||
USER: gitlab-runner
|
|
||||||
<<: *freebsd_14_amd64_image
|
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
|
<<: *freebsd_autoscaler_14_amd64
|
||||||
|
|
||||||
system:clang:freebsd14:amd64:
|
system:clang:freebsd14:amd64:
|
||||||
<<: *freebsd_14_amd64_image
|
|
||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
variables:
|
<<: *freebsd_autoscaler_14_amd64
|
||||||
USER: gitlab-runner
|
|
||||||
needs:
|
needs:
|
||||||
- job: clang:freebsd14:amd64
|
- job: clang:freebsd14:amd64
|
||||||
artifacts: true
|
artifacts: true
|
||||||
|
|
||||||
unit:clang:freebsd14:amd64:
|
unit:clang:freebsd14:amd64:
|
||||||
<<: *freebsd_14_amd64_image
|
|
||||||
<<: *unit_test_job
|
<<: *unit_test_job
|
||||||
|
<<: *freebsd_autoscaler_14_amd64
|
||||||
needs:
|
needs:
|
||||||
- job: clang:freebsd14:amd64
|
- job: clang:freebsd14:amd64
|
||||||
artifacts: true
|
artifacts: true
|
||||||
@@ -1494,8 +1528,8 @@ release:
|
|||||||
artifacts: true
|
artifacts: true
|
||||||
- job: docs
|
- job: docs
|
||||||
artifacts: true
|
artifacts: true
|
||||||
only:
|
rules:
|
||||||
- tags
|
- if: '$CI_COMMIT_TAG != null'
|
||||||
artifacts:
|
artifacts:
|
||||||
paths:
|
paths:
|
||||||
- "*-release"
|
- "*-release"
|
||||||
@@ -1538,8 +1572,8 @@ sign:
|
|||||||
needs:
|
needs:
|
||||||
- job: release
|
- job: release
|
||||||
artifacts: true
|
artifacts: true
|
||||||
only:
|
rules:
|
||||||
- tags
|
- if: '$CI_COMMIT_TAG != null'
|
||||||
when: manual
|
when: manual
|
||||||
allow_failure: false
|
allow_failure: false
|
||||||
|
|
||||||
@@ -1591,10 +1625,8 @@ coverity:
|
|||||||
- cov-int.tar.gz
|
- cov-int.tar.gz
|
||||||
expire_in: "1 week"
|
expire_in: "1 week"
|
||||||
when: on_failure
|
when: on_failure
|
||||||
only:
|
rules:
|
||||||
variables:
|
- if: '$COVERITY_SCAN_PROJECT_NAME != null && $COVERITY_SCAN_TOKEN != null'
|
||||||
- $COVERITY_SCAN_PROJECT_NAME
|
|
||||||
- $COVERITY_SCAN_TOKEN
|
|
||||||
|
|
||||||
# Respdiff tests
|
# Respdiff tests
|
||||||
|
|
||||||
@@ -1629,9 +1661,9 @@ respdiff:tsan:
|
|||||||
<<: *default_triggering_rules
|
<<: *default_triggering_rules
|
||||||
<<: *tsan_debian_bookworm_amd64_image
|
<<: *tsan_debian_bookworm_amd64_image
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: "${CLANG}"
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og -fsanitize=thread"
|
CFLAGS: "${CFLAGS_COMMON} -ggdb -O2 -fsanitize=thread"
|
||||||
LDFLAGS: "-fsanitize=thread"
|
LDFLAGS: "-fsanitize=thread -Wl,--disable-new-dtags"
|
||||||
EXTRA_CONFIGURE: "--enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig"
|
EXTRA_CONFIGURE: "--enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig"
|
||||||
MAX_DISAGREEMENTS_PERCENTAGE: "0.15"
|
MAX_DISAGREEMENTS_PERCENTAGE: "0.15"
|
||||||
TSAN_OPTIONS: "${TSAN_OPTIONS_DEBIAN}"
|
TSAN_OPTIONS: "${TSAN_OPTIONS_DEBIAN}"
|
||||||
@@ -1670,24 +1702,28 @@ shotgun:tcp:
|
|||||||
variables:
|
variables:
|
||||||
SHOTGUN_SCENARIO: tcp
|
SHOTGUN_SCENARIO: tcp
|
||||||
SHOTGUN_TRAFFIC_MULTIPLIER: 13
|
SHOTGUN_TRAFFIC_MULTIPLIER: 13
|
||||||
when: delayed
|
|
||||||
start_in: 5 minutes
|
|
||||||
|
|
||||||
shotgun:dot:
|
shotgun:dot:
|
||||||
<<: *shotgun_job
|
<<: *shotgun_job
|
||||||
variables:
|
variables:
|
||||||
SHOTGUN_SCENARIO: dot
|
SHOTGUN_SCENARIO: dot
|
||||||
SHOTGUN_TRAFFIC_MULTIPLIER: 6
|
SHOTGUN_TRAFFIC_MULTIPLIER: 6
|
||||||
when: delayed
|
rules: &shotgun_rules_manual_mr
|
||||||
start_in: 5 minutes
|
- if: '$CI_MERGE_REQUEST_DIFF_BASE_SHA != null'
|
||||||
|
variables:
|
||||||
|
BASELINE: '$CI_MERGE_REQUEST_DIFF_BASE_SHA'
|
||||||
|
when: manual # don't run on each MR unless requested
|
||||||
|
allow_failure: true
|
||||||
|
- *shotgun_rule_tag
|
||||||
|
- *shotgun_rule_other
|
||||||
|
|
||||||
shotgun:doh-get:
|
shotgun:doh-get:
|
||||||
<<: *shotgun_job
|
<<: *shotgun_job
|
||||||
variables:
|
variables:
|
||||||
SHOTGUN_SCENARIO: doh-get
|
SHOTGUN_SCENARIO: doh-get
|
||||||
SHOTGUN_TRAFFIC_MULTIPLIER: 3
|
SHOTGUN_TRAFFIC_MULTIPLIER: 3
|
||||||
when: delayed
|
SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_MAX: 0.3 # bump from the default due to increased tail-end jitter
|
||||||
start_in: 5 minutes
|
rules: *shotgun_rules_manual_mr
|
||||||
|
|
||||||
.stress-test: &stress_test
|
.stress-test: &stress_test
|
||||||
stage: performance
|
stage: performance
|
||||||
@@ -1726,8 +1762,8 @@ fsck:
|
|||||||
- git clone https://gitlab.isc.org/isc-projects/bind9.git bind9-full-clone
|
- git clone https://gitlab.isc.org/isc-projects/bind9.git bind9-full-clone
|
||||||
- cd bind9-full-clone/
|
- cd bind9-full-clone/
|
||||||
- git fsck
|
- git fsck
|
||||||
only:
|
rules:
|
||||||
- schedules
|
- if: '$CI_PIPELINE_SOURCE == "schedule"'
|
||||||
needs: []
|
needs: []
|
||||||
|
|
||||||
gcov:
|
gcov:
|
||||||
@@ -1779,9 +1815,8 @@ pairwise:
|
|||||||
- pairwise-model.txt
|
- pairwise-model.txt
|
||||||
- pairwise-output.*.txt
|
- pairwise-output.*.txt
|
||||||
when: on_failure
|
when: on_failure
|
||||||
only:
|
rules:
|
||||||
variables:
|
- if: '$PAIRWISE_TESTING != null'
|
||||||
- $PAIRWISE_TESTING
|
|
||||||
|
|
||||||
.post_merge_template: &post_merge
|
.post_merge_template: &post_merge
|
||||||
<<: *base_image
|
<<: *base_image
|
||||||
|
|||||||
@@ -761,7 +761,7 @@ cleanup:
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (mctx != NULL) {
|
if (mctx != NULL) {
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
}
|
}
|
||||||
|
|
||||||
return result == ISC_R_SUCCESS ? 0 : 1;
|
return result == ISC_R_SUCCESS ? 0 : 1;
|
||||||
|
|||||||
@@ -577,7 +577,7 @@ main(int argc, char **argv) {
|
|||||||
fprintf(errout, "OK\n");
|
fprintf(errout, "OK\n");
|
||||||
}
|
}
|
||||||
destroy();
|
destroy();
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
|
|
||||||
return (result == ISC_R_SUCCESS) ? 0 : 1;
|
return (result == ISC_R_SUCCESS) ? 0 : 1;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -290,7 +290,7 @@ options {\n\
|
|||||||
isc_mem_stats(mctx, stderr);
|
isc_mem_stats(mctx, stderr);
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
|
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -296,7 +296,7 @@ nsupdate -k <keyfile>\n");
|
|||||||
isc_mem_stats(mctx, stderr);
|
isc_mem_stats(mctx, stderr);
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
|
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|||||||
+2
-36
@@ -26,16 +26,12 @@
|
|||||||
#include <unistd.h>
|
#include <unistd.h>
|
||||||
|
|
||||||
#include <openssl/opensslv.h>
|
#include <openssl/opensslv.h>
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
#include <openssl/err.h>
|
|
||||||
#include <openssl/provider.h>
|
|
||||||
#endif
|
|
||||||
|
|
||||||
#include <isc/async.h>
|
#include <isc/async.h>
|
||||||
#include <isc/attributes.h>
|
#include <isc/attributes.h>
|
||||||
#include <isc/base64.h>
|
#include <isc/base64.h>
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/fips.h>
|
#include <isc/crypto.h>
|
||||||
#include <isc/hex.h>
|
#include <isc/hex.h>
|
||||||
#include <isc/lib.h>
|
#include <isc/lib.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
@@ -167,10 +163,6 @@ static dns_fixedname_t qfn;
|
|||||||
/* Default trust anchors */
|
/* Default trust anchors */
|
||||||
static char anchortext[] = TRUST_ANCHORS;
|
static char anchortext[] = TRUST_ANCHORS;
|
||||||
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
static OSSL_PROVIDER *fips = NULL, *base = NULL;
|
|
||||||
#endif
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Static function prototypes
|
* Static function prototypes
|
||||||
*/
|
*/
|
||||||
@@ -1619,24 +1611,7 @@ preparse_args(int argc, char **argv) {
|
|||||||
while (strpbrk(option, single_dash_opts) == &option[0]) {
|
while (strpbrk(option, single_dash_opts) == &option[0]) {
|
||||||
switch (option[0]) {
|
switch (option[0]) {
|
||||||
case 'F':
|
case 'F':
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
if (isc_crypto_fips_enable() != ISC_R_SUCCESS) {
|
||||||
fips = OSSL_PROVIDER_load(NULL, "fips");
|
|
||||||
if (fips == NULL) {
|
|
||||||
ERR_clear_error();
|
|
||||||
fatal("Failed to load FIPS provider");
|
|
||||||
}
|
|
||||||
base = OSSL_PROVIDER_load(NULL, "base");
|
|
||||||
if (base == NULL) {
|
|
||||||
OSSL_PROVIDER_unload(fips);
|
|
||||||
ERR_clear_error();
|
|
||||||
fatal("Failed to load base provider");
|
|
||||||
}
|
|
||||||
#endif
|
|
||||||
/* Already in FIPS mode? */
|
|
||||||
if (isc_fips_mode()) {
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
if (isc_fips_set_mode(1) != ISC_R_SUCCESS) {
|
|
||||||
fatal("setting FIPS mode failed");
|
fatal("setting FIPS mode failed");
|
||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
@@ -2309,14 +2284,5 @@ cleanup:
|
|||||||
|
|
||||||
isc_managers_destroy(&mctx, &loopmgr, &netmgr);
|
isc_managers_destroy(&mctx, &loopmgr, &netmgr);
|
||||||
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
if (base != NULL) {
|
|
||||||
OSSL_PROVIDER_unload(base);
|
|
||||||
}
|
|
||||||
if (fips != NULL) {
|
|
||||||
OSSL_PROVIDER_unload(fips);
|
|
||||||
}
|
|
||||||
#endif
|
|
||||||
|
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|||||||
+18
-38
@@ -20,8 +20,8 @@
|
|||||||
#include <time.h>
|
#include <time.h>
|
||||||
|
|
||||||
#include <isc/attributes.h>
|
#include <isc/attributes.h>
|
||||||
|
#include <isc/crypto.h>
|
||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
#include <isc/fips.h>
|
|
||||||
#include <isc/lib.h>
|
#include <isc/lib.h>
|
||||||
#include <isc/loop.h>
|
#include <isc/loop.h>
|
||||||
#include <isc/netaddr.h>
|
#include <isc/netaddr.h>
|
||||||
@@ -73,14 +73,6 @@ static bool short_form = false, printcmd = true, plusquest = false,
|
|||||||
static uint32_t splitwidth = 0xffffffff;
|
static uint32_t splitwidth = 0xffffffff;
|
||||||
|
|
||||||
#include <openssl/opensslv.h>
|
#include <openssl/opensslv.h>
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
#include <openssl/err.h>
|
|
||||||
#include <openssl/provider.h>
|
|
||||||
#endif
|
|
||||||
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
static OSSL_PROVIDER *fips = NULL, *base = NULL;
|
|
||||||
#endif
|
|
||||||
|
|
||||||
/*% opcode text */
|
/*% opcode text */
|
||||||
static const char *const opcodetext[] = {
|
static const char *const opcodetext[] = {
|
||||||
@@ -297,6 +289,7 @@ help(void) {
|
|||||||
" form of answers - global "
|
" form of answers - global "
|
||||||
"option)\n"
|
"option)\n"
|
||||||
" +[no]showbadcookie (Show BADCOOKIE message)\n"
|
" +[no]showbadcookie (Show BADCOOKIE message)\n"
|
||||||
|
" +[no]showbadvers (Show BADVERS message)\n"
|
||||||
" +[no]showsearch (Search with intermediate "
|
" +[no]showsearch (Search with intermediate "
|
||||||
"results)\n"
|
"results)\n"
|
||||||
" +[no]split=## (Split hex/base64 fields "
|
" +[no]split=## (Split hex/base64 fields "
|
||||||
@@ -1780,6 +1773,8 @@ plus_option(char *option, bool is_batchfile, bool *need_clone,
|
|||||||
FULLCHECK("edns");
|
FULLCHECK("edns");
|
||||||
if (!state) {
|
if (!state) {
|
||||||
lookup->edns = -1;
|
lookup->edns = -1;
|
||||||
|
lookup->original_edns =
|
||||||
|
-1;
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
if (value == NULL) {
|
if (value == NULL) {
|
||||||
@@ -1796,6 +1791,7 @@ plus_option(char *option, bool is_batchfile, bool *need_clone,
|
|||||||
goto exit_or_usage;
|
goto exit_or_usage;
|
||||||
}
|
}
|
||||||
lookup->edns = num;
|
lookup->edns = num;
|
||||||
|
lookup->original_edns = num;
|
||||||
break;
|
break;
|
||||||
case 'f':
|
case 'f':
|
||||||
FULLCHECK("ednsflags");
|
FULLCHECK("ednsflags");
|
||||||
@@ -2314,8 +2310,18 @@ plus_option(char *option, bool is_batchfile, bool *need_clone,
|
|||||||
case 'w': /* showsearch */
|
case 'w': /* showsearch */
|
||||||
switch (cmd[4]) {
|
switch (cmd[4]) {
|
||||||
case 'b':
|
case 'b':
|
||||||
FULLCHECK("showbadcookie");
|
switch (cmd[7]) {
|
||||||
lookup->showbadcookie = state;
|
case 'c':
|
||||||
|
FULLCHECK("showbadcookie");
|
||||||
|
lookup->showbadcookie = state;
|
||||||
|
break;
|
||||||
|
case 'v':
|
||||||
|
FULLCHECK("showbadvers");
|
||||||
|
lookup->showbadvers = state;
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
goto invalid_option;
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
case 's':
|
case 's':
|
||||||
FULLCHECK("showsearch");
|
FULLCHECK("showsearch");
|
||||||
@@ -2931,24 +2937,7 @@ preparse_args(int argc, char **argv) {
|
|||||||
debugging = true;
|
debugging = true;
|
||||||
break;
|
break;
|
||||||
case 'F':
|
case 'F':
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
if (isc_crypto_fips_enable() != ISC_R_SUCCESS) {
|
||||||
fips = OSSL_PROVIDER_load(NULL, "fips");
|
|
||||||
if (fips == NULL) {
|
|
||||||
ERR_clear_error();
|
|
||||||
fatal("Failed to load FIPS provider");
|
|
||||||
}
|
|
||||||
base = OSSL_PROVIDER_load(NULL, "base");
|
|
||||||
if (base == NULL) {
|
|
||||||
OSSL_PROVIDER_unload(fips);
|
|
||||||
ERR_clear_error();
|
|
||||||
fatal("Failed to load base provider");
|
|
||||||
}
|
|
||||||
#endif
|
|
||||||
/* Already in FIPS mode? */
|
|
||||||
if (isc_fips_mode()) {
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
if (isc_fips_set_mode(1) != ISC_R_SUCCESS) {
|
|
||||||
fatal("setting FIPS mode failed");
|
fatal("setting FIPS mode failed");
|
||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
@@ -3476,14 +3465,5 @@ main(int argc, char **argv) {
|
|||||||
dig_startup();
|
dig_startup();
|
||||||
dig_shutdown();
|
dig_shutdown();
|
||||||
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
if (base != NULL) {
|
|
||||||
OSSL_PROVIDER_unload(base);
|
|
||||||
}
|
|
||||||
if (fips != NULL) {
|
|
||||||
OSSL_PROVIDER_unload(fips);
|
|
||||||
}
|
|
||||||
#endif
|
|
||||||
|
|
||||||
return exitcode;
|
return exitcode;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -614,6 +614,12 @@ abbreviation is unambiguous; for example, :option:`+cd` is equivalent to
|
|||||||
BADCOOKIE rcode before retrying the request or not. The default
|
BADCOOKIE rcode before retrying the request or not. The default
|
||||||
is to not show the messages.
|
is to not show the messages.
|
||||||
|
|
||||||
|
.. option:: +showbadvers, +noshowbadvers
|
||||||
|
|
||||||
|
This option toggles whether to show the message containing the
|
||||||
|
BADVERS rcode before retrying the request or not. The default
|
||||||
|
is to not show the messages.
|
||||||
|
|
||||||
.. option:: +showsearch, +noshowsearch
|
.. option:: +showsearch, +noshowsearch
|
||||||
|
|
||||||
This option performs [or does not perform] a search showing intermediate results.
|
This option performs [or does not perform] a search showing intermediate results.
|
||||||
|
|||||||
+11
-1
@@ -605,6 +605,7 @@ make_empty_lookup(void) {
|
|||||||
.idnout = idnout,
|
.idnout = idnout,
|
||||||
.udpsize = -1,
|
.udpsize = -1,
|
||||||
.edns = -1,
|
.edns = -1,
|
||||||
|
.original_edns = -1,
|
||||||
.recurse = true,
|
.recurse = true,
|
||||||
.retries = tries,
|
.retries = tries,
|
||||||
.comments = true,
|
.comments = true,
|
||||||
@@ -738,6 +739,7 @@ clone_lookup(dig_lookup_t *lookold, bool servers) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
looknew->showbadcookie = lookold->showbadcookie;
|
looknew->showbadcookie = lookold->showbadcookie;
|
||||||
|
looknew->showbadvers = lookold->showbadvers;
|
||||||
looknew->sendcookie = lookold->sendcookie;
|
looknew->sendcookie = lookold->sendcookie;
|
||||||
looknew->seenbadcookie = lookold->seenbadcookie;
|
looknew->seenbadcookie = lookold->seenbadcookie;
|
||||||
looknew->badcookie = lookold->badcookie;
|
looknew->badcookie = lookold->badcookie;
|
||||||
@@ -764,6 +766,7 @@ clone_lookup(dig_lookup_t *lookold, bool servers) {
|
|||||||
looknew->idnout = lookold->idnout;
|
looknew->idnout = lookold->idnout;
|
||||||
looknew->udpsize = lookold->udpsize;
|
looknew->udpsize = lookold->udpsize;
|
||||||
looknew->edns = lookold->edns;
|
looknew->edns = lookold->edns;
|
||||||
|
looknew->original_edns = lookold->original_edns;
|
||||||
looknew->recurse = lookold->recurse;
|
looknew->recurse = lookold->recurse;
|
||||||
looknew->aaonly = lookold->aaonly;
|
looknew->aaonly = lookold->aaonly;
|
||||||
looknew->adflag = lookold->adflag;
|
looknew->adflag = lookold->adflag;
|
||||||
@@ -1938,6 +1941,7 @@ followup_lookup(dns_message_t *msg, dig_query_t *query, dns_section_t section) {
|
|||||||
}
|
}
|
||||||
domain = dns_fixedname_name(&lookup->fdomain);
|
domain = dns_fixedname_name(&lookup->fdomain);
|
||||||
dns_name_copy(name, domain);
|
dns_name_copy(name, domain);
|
||||||
|
lookup->edns = lookup->original_edns;
|
||||||
}
|
}
|
||||||
debug("adding server %s", namestr);
|
debug("adding server %s", namestr);
|
||||||
num = getaddresses(lookup, namestr, &lresult);
|
num = getaddresses(lookup, namestr, &lresult);
|
||||||
@@ -2456,7 +2460,8 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
lookup->udpsize = DEFAULT_EDNS_BUFSIZE;
|
lookup->udpsize = DEFAULT_EDNS_BUFSIZE;
|
||||||
}
|
}
|
||||||
if (lookup->edns < 0) {
|
if (lookup->edns < 0) {
|
||||||
lookup->edns = DEFAULT_EDNS_VERSION;
|
lookup->original_edns = lookup->edns =
|
||||||
|
DEFAULT_EDNS_VERSION;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (lookup->nsid) {
|
if (lookup->nsid) {
|
||||||
@@ -4300,6 +4305,11 @@ recv_done(isc_nmhandle_t *handle, isc_result_t eresult, isc_region_t *region,
|
|||||||
if (msg->rcode == dns_rcode_badvers && msg->opt != NULL &&
|
if (msg->rcode == dns_rcode_badvers && msg->opt != NULL &&
|
||||||
(newedns = ednsvers(msg->opt)) < l->edns && l->ednsneg)
|
(newedns = ednsvers(msg->opt)) < l->edns && l->ednsneg)
|
||||||
{
|
{
|
||||||
|
if (l->showbadvers) {
|
||||||
|
dighost_printmessage(query, &b, msg, true);
|
||||||
|
dighost_received(isc_buffer_usedlength(&b), &peer,
|
||||||
|
query);
|
||||||
|
}
|
||||||
/*
|
/*
|
||||||
* Add minimum EDNS version required checks here if needed.
|
* Add minimum EDNS version required checks here if needed.
|
||||||
*/
|
*/
|
||||||
|
|||||||
+4
-3
@@ -117,9 +117,9 @@ struct dig_lookup {
|
|||||||
section_answer, section_authority, section_question,
|
section_answer, section_authority, section_question,
|
||||||
seenbadcookie, sendcookie, servfail_stops,
|
seenbadcookie, sendcookie, servfail_stops,
|
||||||
setqid, /*% use a speciied query ID */
|
setqid, /*% use a speciied query ID */
|
||||||
showbadcookie, stats, tcflag, tcp_keepalive, tcp_mode,
|
showbadcookie, showbadvers, stats, tcflag, tcp_keepalive,
|
||||||
tcp_mode_set, tls_mode, /*% connect using TLS */
|
tcp_mode, tcp_mode_set, tls_mode, /*% connect using TLS */
|
||||||
trace, /*% dig +trace */
|
trace, /*% dig +trace */
|
||||||
trace_root, /*% initial query for either +trace or +nssearch */
|
trace_root, /*% initial query for either +trace or +nssearch */
|
||||||
ttlunits, use_usec, waiting_connect, zflag;
|
ttlunits, use_usec, waiting_connect, zflag;
|
||||||
char textname[MXNAME]; /*% Name we're going to be looking up */
|
char textname[MXNAME]; /*% Name we're going to be looking up */
|
||||||
@@ -148,6 +148,7 @@ struct dig_lookup {
|
|||||||
int nsfound;
|
int nsfound;
|
||||||
int16_t udpsize;
|
int16_t udpsize;
|
||||||
int16_t edns;
|
int16_t edns;
|
||||||
|
int16_t original_edns;
|
||||||
int16_t padding;
|
int16_t padding;
|
||||||
uint32_t ixfr_serial;
|
uint32_t ixfr_serial;
|
||||||
isc_buffer_t rdatabuf;
|
isc_buffer_t rdatabuf;
|
||||||
|
|||||||
+1
-2
@@ -246,8 +246,7 @@ printsection(dns_message_t *msg, dns_section_t sectionid,
|
|||||||
(list_type == dns_rdatatype_any ||
|
(list_type == dns_rdatatype_any ||
|
||||||
rdataset->type == list_type)) ||
|
rdataset->type == list_type)) ||
|
||||||
(list_addresses &&
|
(list_addresses &&
|
||||||
(rdataset->type == dns_rdatatype_a ||
|
(dns_rdatatype_isaddr(rdataset->type) ||
|
||||||
rdataset->type == dns_rdatatype_aaaa ||
|
|
||||||
rdataset->type == dns_rdatatype_ns ||
|
rdataset->type == dns_rdatatype_ns ||
|
||||||
rdataset->type == dns_rdatatype_ptr))))
|
rdataset->type == dns_rdatatype_ptr))))
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -20,7 +20,6 @@
|
|||||||
#include <isc/attributes.h>
|
#include <isc/attributes.h>
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/condition.h>
|
|
||||||
#include <isc/lib.h>
|
#include <isc/lib.h>
|
||||||
#include <isc/loop.h>
|
#include <isc/loop.h>
|
||||||
#include <isc/netaddr.h>
|
#include <isc/netaddr.h>
|
||||||
|
|||||||
@@ -41,6 +41,14 @@ dnssec_keygen_LDADD = \
|
|||||||
$(LDADD) \
|
$(LDADD) \
|
||||||
$(OPENSSL_LIBS)
|
$(OPENSSL_LIBS)
|
||||||
|
|
||||||
|
dnssec_ksr_CPPFLAGS= \
|
||||||
|
$(AM_CPPFLAGS) \
|
||||||
|
$(OPENSSL_CFLAGS)
|
||||||
|
|
||||||
|
dnssec_ksr_LDADD = \
|
||||||
|
$(LDADD) \
|
||||||
|
$(OPENSSL_LIBS)
|
||||||
|
|
||||||
dnssec_signzone_CPPFLAGS = \
|
dnssec_signzone_CPPFLAGS = \
|
||||||
$(AM_CPPFLAGS) \
|
$(AM_CPPFLAGS) \
|
||||||
$(OPENSSL_CFLAGS)
|
$(OPENSSL_CFLAGS)
|
||||||
|
|||||||
@@ -1075,7 +1075,7 @@ cleanup(void) {
|
|||||||
if (print_mem_stats && verbose > 10) {
|
if (print_mem_stats && verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -543,7 +543,7 @@ main(int argc, char **argv) {
|
|||||||
if (verbose > 10) {
|
if (verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
|
|
||||||
fflush(stdout);
|
fflush(stdout);
|
||||||
if (ferror(stdout)) {
|
if (ferror(stdout)) {
|
||||||
|
|||||||
@@ -456,7 +456,7 @@ main(int argc, char **argv) {
|
|||||||
if (verbose > 10) {
|
if (verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
|
|
||||||
fflush(stdout);
|
fflush(stdout);
|
||||||
if (ferror(stdout)) {
|
if (ferror(stdout)) {
|
||||||
|
|||||||
@@ -746,7 +746,7 @@ main(int argc, char **argv) {
|
|||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
isc_mem_free(mctx, label);
|
isc_mem_free(mctx, label);
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
|
|
||||||
if (freeit != NULL) {
|
if (freeit != NULL) {
|
||||||
free(freeit);
|
free(freeit);
|
||||||
|
|||||||
+11
-47
@@ -38,7 +38,7 @@
|
|||||||
#include <isc/attributes.h>
|
#include <isc/attributes.h>
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/fips.h>
|
#include <isc/crypto.h>
|
||||||
#include <isc/lib.h>
|
#include <isc/lib.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
@@ -58,11 +58,6 @@
|
|||||||
|
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
#include <openssl/err.h>
|
|
||||||
#include <openssl/provider.h>
|
|
||||||
#endif
|
|
||||||
|
|
||||||
#include "dnssectool.h"
|
#include "dnssectool.h"
|
||||||
|
|
||||||
const char *program = "dnssec-keygen";
|
const char *program = "dnssec-keygen";
|
||||||
@@ -151,7 +146,7 @@ usage(void) {
|
|||||||
fprintf(stderr, " -l <file>: configuration file with dnssec-policy "
|
fprintf(stderr, " -l <file>: configuration file with dnssec-policy "
|
||||||
"statement\n");
|
"statement\n");
|
||||||
fprintf(stderr, " -a <algorithm>:\n");
|
fprintf(stderr, " -a <algorithm>:\n");
|
||||||
if (!isc_fips_mode()) {
|
if (!isc_crypto_fips_mode()) {
|
||||||
fprintf(stderr, " RSASHA1 | NSEC3RSASHA1 |\n");
|
fprintf(stderr, " RSASHA1 | NSEC3RSASHA1 |\n");
|
||||||
}
|
}
|
||||||
fprintf(stderr, " RSASHA256 | RSASHA512 |\n");
|
fprintf(stderr, " RSASHA256 | RSASHA512 |\n");
|
||||||
@@ -159,7 +154,7 @@ usage(void) {
|
|||||||
fprintf(stderr, " ED25519 | ED448\n");
|
fprintf(stderr, " ED25519 | ED448\n");
|
||||||
fprintf(stderr, " -3: use NSEC3-capable algorithm\n");
|
fprintf(stderr, " -3: use NSEC3-capable algorithm\n");
|
||||||
fprintf(stderr, " -b <key size in bits>:\n");
|
fprintf(stderr, " -b <key size in bits>:\n");
|
||||||
if (!isc_fips_mode()) {
|
if (!isc_crypto_fips_mode()) {
|
||||||
fprintf(stderr, " RSASHA1:\t[%d..%d]\n", min_rsa,
|
fprintf(stderr, " RSASHA1:\t[%d..%d]\n", min_rsa,
|
||||||
MAX_RSA);
|
MAX_RSA);
|
||||||
fprintf(stderr, " NSEC3RSASHA1:\t[%d..%d]\n", min_rsa,
|
fprintf(stderr, " NSEC3RSASHA1:\t[%d..%d]\n", min_rsa,
|
||||||
@@ -288,7 +283,7 @@ keygen(keygen_ctx_t *ctx, isc_mem_t *mctx, int argc, char **argv) {
|
|||||||
fatal("unsupported algorithm: %s", algstr);
|
fatal("unsupported algorithm: %s", algstr);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (isc_fips_mode()) {
|
if (isc_crypto_fips_mode()) {
|
||||||
/* verify only in FIPS mode */
|
/* verify only in FIPS mode */
|
||||||
switch (ctx->alg) {
|
switch (ctx->alg) {
|
||||||
case DST_ALG_RSASHA1:
|
case DST_ALG_RSASHA1:
|
||||||
@@ -341,7 +336,7 @@ keygen(keygen_ctx_t *ctx, isc_mem_t *mctx, int argc, char **argv) {
|
|||||||
switch (ctx->alg) {
|
switch (ctx->alg) {
|
||||||
case DST_ALG_RSASHA1:
|
case DST_ALG_RSASHA1:
|
||||||
case DST_ALG_NSEC3RSASHA1:
|
case DST_ALG_NSEC3RSASHA1:
|
||||||
if (isc_fips_mode()) {
|
if (isc_crypto_fips_mode()) {
|
||||||
fatal("key size not specified (-b "
|
fatal("key size not specified (-b "
|
||||||
"option)");
|
"option)");
|
||||||
}
|
}
|
||||||
@@ -501,7 +496,7 @@ keygen(keygen_ctx_t *ctx, isc_mem_t *mctx, int argc, char **argv) {
|
|||||||
switch (ctx->alg) {
|
switch (ctx->alg) {
|
||||||
case DNS_KEYALG_RSASHA1:
|
case DNS_KEYALG_RSASHA1:
|
||||||
case DNS_KEYALG_NSEC3RSASHA1:
|
case DNS_KEYALG_NSEC3RSASHA1:
|
||||||
if (isc_fips_mode()) {
|
if (isc_crypto_fips_mode()) {
|
||||||
fatal("SHA1 based keys not supported in FIPS mode");
|
fatal("SHA1 based keys not supported in FIPS mode");
|
||||||
}
|
}
|
||||||
FALLTHROUGH;
|
FALLTHROUGH;
|
||||||
@@ -847,10 +842,6 @@ main(int argc, char **argv) {
|
|||||||
isc_textregion_t r;
|
isc_textregion_t r;
|
||||||
unsigned char c;
|
unsigned char c;
|
||||||
int ch;
|
int ch;
|
||||||
bool set_fips_mode = false;
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
OSSL_PROVIDER *fips = NULL, *base = NULL;
|
|
||||||
#endif
|
|
||||||
|
|
||||||
keygen_ctx_t ctx = {
|
keygen_ctx_t ctx = {
|
||||||
.options = DST_TYPE_PRIVATE | DST_TYPE_PUBLIC,
|
.options = DST_TYPE_PRIVATE | DST_TYPE_PUBLIC,
|
||||||
@@ -1109,7 +1100,9 @@ main(int argc, char **argv) {
|
|||||||
ctx.prepub = strtottl(isc_commandline_argument);
|
ctx.prepub = strtottl(isc_commandline_argument);
|
||||||
break;
|
break;
|
||||||
case 'F':
|
case 'F':
|
||||||
set_fips_mode = true;
|
if (isc_crypto_fips_enable() != ISC_R_SUCCESS) {
|
||||||
|
fatal("setting FIPS mode failed");
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
case '?':
|
case '?':
|
||||||
if (isc_commandline_option != '?') {
|
if (isc_commandline_option != '?') {
|
||||||
@@ -1136,32 +1129,11 @@ main(int argc, char **argv) {
|
|||||||
ctx.quiet = true;
|
ctx.quiet = true;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (set_fips_mode) {
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
fips = OSSL_PROVIDER_load(NULL, "fips");
|
|
||||||
if (fips == NULL) {
|
|
||||||
ERR_clear_error();
|
|
||||||
fatal("Failed to load FIPS provider");
|
|
||||||
}
|
|
||||||
base = OSSL_PROVIDER_load(NULL, "base");
|
|
||||||
if (base == NULL) {
|
|
||||||
OSSL_PROVIDER_unload(fips);
|
|
||||||
ERR_clear_error();
|
|
||||||
fatal("Failed to load base provider");
|
|
||||||
}
|
|
||||||
#endif
|
|
||||||
if (!isc_fips_mode()) {
|
|
||||||
if (isc_fips_set_mode(1) != ISC_R_SUCCESS) {
|
|
||||||
fatal("setting FIPS mode failed");
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* The DST subsystem will set FIPS mode if requested at build time.
|
* The DST subsystem will set FIPS mode if requested at build time.
|
||||||
* The minimum sizes are both raised to 2048.
|
* The minimum sizes are both raised to 2048.
|
||||||
*/
|
*/
|
||||||
if (isc_fips_mode()) {
|
if (isc_crypto_fips_mode()) {
|
||||||
min_rsa = min_dh = 2048;
|
min_rsa = min_dh = 2048;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1308,16 +1280,8 @@ main(int argc, char **argv) {
|
|||||||
if (verbose > 10) {
|
if (verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
if (base != NULL) {
|
|
||||||
OSSL_PROVIDER_unload(base);
|
|
||||||
}
|
|
||||||
if (fips != NULL) {
|
|
||||||
OSSL_PROVIDER_unload(fips);
|
|
||||||
}
|
|
||||||
#endif
|
|
||||||
if (freeit != NULL) {
|
if (freeit != NULL) {
|
||||||
free(freeit);
|
free(freeit);
|
||||||
}
|
}
|
||||||
|
|||||||
+6
-27
@@ -18,7 +18,7 @@
|
|||||||
|
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/fips.h>
|
#include <isc/crypto.h>
|
||||||
#include <isc/lex.h>
|
#include <isc/lex.h>
|
||||||
#include <isc/lib.h>
|
#include <isc/lib.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
@@ -362,7 +362,7 @@ create_key(ksr_ctx_t *ksr, dns_kasp_t *kasp, dns_kasp_key_t *kaspkey,
|
|||||||
switch (ksr->alg) {
|
switch (ksr->alg) {
|
||||||
case DST_ALG_RSASHA1:
|
case DST_ALG_RSASHA1:
|
||||||
case DST_ALG_NSEC3RSASHA1:
|
case DST_ALG_NSEC3RSASHA1:
|
||||||
if (isc_fips_mode()) {
|
if (isc_crypto_fips_mode()) {
|
||||||
/* verify-only in FIPS mode */
|
/* verify-only in FIPS mode */
|
||||||
fatal("unsupported algorithm: %s", algstr);
|
fatal("unsupported algorithm: %s", algstr);
|
||||||
}
|
}
|
||||||
@@ -1348,10 +1348,6 @@ main(int argc, char *argv[]) {
|
|||||||
isc_buffer_t buf;
|
isc_buffer_t buf;
|
||||||
int ch;
|
int ch;
|
||||||
char *endp;
|
char *endp;
|
||||||
bool set_fips_mode = false;
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
OSSL_PROVIDER *fips = NULL, *base = NULL;
|
|
||||||
#endif
|
|
||||||
ksr_ctx_t ksr = {
|
ksr_ctx_t ksr = {
|
||||||
.now = isc_stdtime_now(),
|
.now = isc_stdtime_now(),
|
||||||
};
|
};
|
||||||
@@ -1371,7 +1367,9 @@ main(int argc, char *argv[]) {
|
|||||||
ksr.now, &ksr.setend);
|
ksr.now, &ksr.setend);
|
||||||
break;
|
break;
|
||||||
case 'F':
|
case 'F':
|
||||||
set_fips_mode = true;
|
if (isc_crypto_fips_enable() != ISC_R_SUCCESS) {
|
||||||
|
fatal("setting FIPS mode failed");
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
case 'f':
|
case 'f':
|
||||||
ksr.file = isc_commandline_argument;
|
ksr.file = isc_commandline_argument;
|
||||||
@@ -1425,31 +1423,12 @@ main(int argc, char *argv[]) {
|
|||||||
* The DST subsystem will set FIPS mode if requested at build time.
|
* The DST subsystem will set FIPS mode if requested at build time.
|
||||||
* The minimum sizes are both raised to 2048.
|
* The minimum sizes are both raised to 2048.
|
||||||
*/
|
*/
|
||||||
if (isc_fips_mode()) {
|
if (isc_crypto_fips_mode()) {
|
||||||
min_rsa = min_dh = 2048;
|
min_rsa = min_dh = 2048;
|
||||||
}
|
}
|
||||||
|
|
||||||
setup_logging();
|
setup_logging();
|
||||||
|
|
||||||
if (set_fips_mode) {
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
fips = OSSL_PROVIDER_load(NULL, "fips");
|
|
||||||
if (fips == NULL) {
|
|
||||||
fatal("Failed to load FIPS provider");
|
|
||||||
}
|
|
||||||
base = OSSL_PROVIDER_load(NULL, "base");
|
|
||||||
if (base == NULL) {
|
|
||||||
OSSL_PROVIDER_unload(fips);
|
|
||||||
fatal("Failed to load base provider");
|
|
||||||
}
|
|
||||||
#endif
|
|
||||||
if (!isc_fips_mode()) {
|
|
||||||
if (isc_fips_set_mode(1) != ISC_R_SUCCESS) {
|
|
||||||
fatal("setting FIPS mode failed");
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/* zone */
|
/* zone */
|
||||||
namestr = argv[1];
|
namestr = argv[1];
|
||||||
name = dns_fixedname_initname(&fname);
|
name = dns_fixedname_initname(&fname);
|
||||||
|
|||||||
@@ -248,7 +248,7 @@ cleanup:
|
|||||||
if (dir != NULL) {
|
if (dir != NULL) {
|
||||||
isc_mem_free(mctx, dir);
|
isc_mem_free(mctx, dir);
|
||||||
}
|
}
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
|
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -949,7 +949,7 @@ main(int argc, char **argv) {
|
|||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
isc_mem_free(mctx, directory);
|
isc_mem_free(mctx, directory);
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
|
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -42,7 +42,6 @@
|
|||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/fips.h>
|
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/hex.h>
|
#include <isc/hex.h>
|
||||||
#include <isc/lib.h>
|
#include <isc/lib.h>
|
||||||
@@ -90,10 +89,6 @@
|
|||||||
#include <dns/zoneverify.h>
|
#include <dns/zoneverify.h>
|
||||||
|
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
#include <openssl/err.h>
|
|
||||||
#include <openssl/provider.h>
|
|
||||||
#endif
|
|
||||||
|
|
||||||
#include "dnssectool.h"
|
#include "dnssectool.h"
|
||||||
|
|
||||||
@@ -3380,10 +3375,6 @@ main(int argc, char *argv[]) {
|
|||||||
bool set_optout = false;
|
bool set_optout = false;
|
||||||
bool set_iter = false;
|
bool set_iter = false;
|
||||||
bool nonsecify = false;
|
bool nonsecify = false;
|
||||||
bool set_fips_mode = false;
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
OSSL_PROVIDER *fips = NULL, *base = NULL;
|
|
||||||
#endif
|
|
||||||
|
|
||||||
atomic_init(&shuttingdown, false);
|
atomic_init(&shuttingdown, false);
|
||||||
atomic_init(&finished, false);
|
atomic_init(&finished, false);
|
||||||
@@ -3672,7 +3663,9 @@ main(int argc, char *argv[]) {
|
|||||||
break;
|
break;
|
||||||
|
|
||||||
case 'F':
|
case 'F':
|
||||||
set_fips_mode = true;
|
if (isc_crypto_fips_enable() != ISC_R_SUCCESS) {
|
||||||
|
fatal("setting FIPS mode failed");
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case '?':
|
case '?':
|
||||||
@@ -3743,27 +3736,6 @@ main(int argc, char *argv[]) {
|
|||||||
|
|
||||||
isc_managers_create(&mctx, nloops, &loopmgr, &netmgr);
|
isc_managers_create(&mctx, nloops, &loopmgr, &netmgr);
|
||||||
|
|
||||||
if (set_fips_mode) {
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
fips = OSSL_PROVIDER_load(NULL, "fips");
|
|
||||||
if (fips == NULL) {
|
|
||||||
ERR_clear_error();
|
|
||||||
fatal("Failed to load FIPS provider");
|
|
||||||
}
|
|
||||||
base = OSSL_PROVIDER_load(NULL, "base");
|
|
||||||
if (base == NULL) {
|
|
||||||
OSSL_PROVIDER_unload(fips);
|
|
||||||
ERR_clear_error();
|
|
||||||
fatal("Failed to load base provider");
|
|
||||||
}
|
|
||||||
#endif
|
|
||||||
if (!isc_fips_mode()) {
|
|
||||||
if (isc_fips_set_mode(1) != ISC_R_SUCCESS) {
|
|
||||||
fatal("setting FIPS mode failed");
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
setup_logging();
|
setup_logging();
|
||||||
|
|
||||||
argc -= isc_commandline_index;
|
argc -= isc_commandline_index;
|
||||||
@@ -4135,15 +4107,6 @@ main(int argc, char *argv[]) {
|
|||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
if (base != NULL) {
|
|
||||||
OSSL_PROVIDER_unload(base);
|
|
||||||
}
|
|
||||||
if (fips != NULL) {
|
|
||||||
OSSL_PROVIDER_unload(fips);
|
|
||||||
}
|
|
||||||
#endif
|
|
||||||
|
|
||||||
isc_managers_destroy(&mctx, &loopmgr, &netmgr);
|
isc_managers_destroy(&mctx, &loopmgr, &netmgr);
|
||||||
|
|
||||||
if (printstats) {
|
if (printstats) {
|
||||||
|
|||||||
@@ -330,7 +330,7 @@ main(int argc, char *argv[]) {
|
|||||||
if (verbose > 10) {
|
if (verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
|
|
||||||
return result == ISC_R_SUCCESS ? 0 : 1;
|
return result == ISC_R_SUCCESS ? 0 : 1;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -736,7 +736,6 @@ controlkeylist_fromcfg(const cfg_obj_t *keylist, isc_mem_t *mctx,
|
|||||||
key->secret.length = 0;
|
key->secret.length = 0;
|
||||||
ISC_LINK_INIT(key, link);
|
ISC_LINK_INIT(key, link);
|
||||||
ISC_LIST_APPEND(*keyids, key, link);
|
ISC_LIST_APPEND(*keyids, key, link);
|
||||||
newstr = NULL;
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -25,7 +25,6 @@
|
|||||||
#include <string.h>
|
#include <string.h>
|
||||||
#include <unistd.h>
|
#include <unistd.h>
|
||||||
|
|
||||||
#include <isc/condition.h>
|
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/loop.h>
|
#include <isc/loop.h>
|
||||||
#include <isc/mutex.h>
|
#include <isc/mutex.h>
|
||||||
|
|||||||
@@ -86,7 +86,6 @@ EXTERN named_server_t *named_g_server INIT(NULL);
|
|||||||
/*
|
/*
|
||||||
* Logging.
|
* Logging.
|
||||||
*/
|
*/
|
||||||
EXTERN bool named_g_logging INIT(false);
|
|
||||||
EXTERN unsigned int named_g_debuglevel INIT(0);
|
EXTERN unsigned int named_g_debuglevel INIT(0);
|
||||||
|
|
||||||
/*
|
/*
|
||||||
|
|||||||
@@ -52,8 +52,6 @@ named_log_init(bool safe) {
|
|||||||
named_log_setdefaultsslkeylogfile(lcfg);
|
named_log_setdefaultsslkeylogfile(lcfg);
|
||||||
rcu_read_unlock();
|
rcu_read_unlock();
|
||||||
|
|
||||||
named_g_logging = true;
|
|
||||||
|
|
||||||
return ISC_R_SUCCESS;
|
return ISC_R_SUCCESS;
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
|
|||||||
+37
-110
@@ -30,7 +30,6 @@
|
|||||||
#include <isc/crypto.h>
|
#include <isc/crypto.h>
|
||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/fips.h>
|
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/httpd.h>
|
#include <isc/httpd.h>
|
||||||
#include <isc/lib.h>
|
#include <isc/lib.h>
|
||||||
@@ -91,10 +90,6 @@
|
|||||||
#include <openssl/crypto.h>
|
#include <openssl/crypto.h>
|
||||||
#include <openssl/evp.h>
|
#include <openssl/evp.h>
|
||||||
#include <openssl/opensslv.h>
|
#include <openssl/opensslv.h>
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
#include <openssl/err.h>
|
|
||||||
#include <openssl/provider.h>
|
|
||||||
#endif
|
|
||||||
#ifdef HAVE_LIBXML2
|
#ifdef HAVE_LIBXML2
|
||||||
#include <libxml/parser.h>
|
#include <libxml/parser.h>
|
||||||
#include <libxml/xmlversion.h>
|
#include <libxml/xmlversion.h>
|
||||||
@@ -155,24 +150,13 @@ static bool transferstuck = false;
|
|||||||
static bool disable6 = false;
|
static bool disable6 = false;
|
||||||
static bool disable4 = false;
|
static bool disable4 = false;
|
||||||
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
static OSSL_PROVIDER *fips = NULL, *base = NULL;
|
|
||||||
#endif
|
|
||||||
|
|
||||||
void
|
void
|
||||||
named_main_earlywarning(const char *format, ...) {
|
named_main_earlywarning(const char *format, ...) {
|
||||||
va_list args;
|
va_list args;
|
||||||
|
|
||||||
va_start(args, format);
|
va_start(args, format);
|
||||||
if (named_g_logging) {
|
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
ISC_LOG_WARNING, format, args);
|
||||||
ISC_LOG_WARNING, format, args);
|
|
||||||
} else {
|
|
||||||
fprintf(stderr, "%s: ", program_name);
|
|
||||||
vfprintf(stderr, format, args);
|
|
||||||
fprintf(stderr, "\n");
|
|
||||||
fflush(stderr);
|
|
||||||
}
|
|
||||||
va_end(args);
|
va_end(args);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -181,18 +165,10 @@ named_main_earlyfatal(const char *format, ...) {
|
|||||||
va_list args;
|
va_list args;
|
||||||
|
|
||||||
va_start(args, format);
|
va_start(args, format);
|
||||||
if (named_g_logging) {
|
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
ISC_LOG_CRITICAL, format, args);
|
||||||
ISC_LOG_CRITICAL, format, args);
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
ISC_LOG_CRITICAL, "exiting (due to early fatal error)");
|
||||||
ISC_LOG_CRITICAL,
|
|
||||||
"exiting (due to early fatal error)");
|
|
||||||
} else {
|
|
||||||
fprintf(stderr, "%s: ", program_name);
|
|
||||||
vfprintf(stderr, format, args);
|
|
||||||
fprintf(stderr, "\n");
|
|
||||||
fflush(stderr);
|
|
||||||
}
|
|
||||||
va_end(args);
|
va_end(args);
|
||||||
|
|
||||||
_exit(EXIT_FAILURE);
|
_exit(EXIT_FAILURE);
|
||||||
@@ -209,26 +185,19 @@ assertion_failed(const char *file, int line, isc_assertiontype_t type,
|
|||||||
* Handle assertion failures.
|
* Handle assertion failures.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
if (named_g_logging) {
|
/*
|
||||||
/*
|
* Reset the assertion callback in case it is the log
|
||||||
* Reset the assertion callback in case it is the log
|
* routines causing the assertion.
|
||||||
* routines causing the assertion.
|
*/
|
||||||
*/
|
isc_assertion_setcallback(NULL);
|
||||||
isc_assertion_setcallback(NULL);
|
|
||||||
|
|
||||||
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
ISC_LOG_CRITICAL, "%s:%d: %s(%s) failed", file,
|
ISC_LOG_CRITICAL, "%s:%d: %s(%s) failed", file, line,
|
||||||
line, isc_assertion_typetotext(type), cond);
|
isc_assertion_typetotext(type), cond);
|
||||||
isc_backtrace_log(NAMED_LOGCATEGORY_GENERAL,
|
isc_backtrace_log(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_CRITICAL);
|
ISC_LOG_CRITICAL);
|
||||||
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
ISC_LOG_CRITICAL,
|
ISC_LOG_CRITICAL, "exiting (due to assertion failure)");
|
||||||
"exiting (due to assertion failure)");
|
|
||||||
} else {
|
|
||||||
fprintf(stderr, "%s:%d: %s(%s) failed\n", file, line,
|
|
||||||
isc_assertion_typetotext(type), cond);
|
|
||||||
fflush(stderr);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (named_g_coreok) {
|
if (named_g_coreok) {
|
||||||
abort();
|
abort();
|
||||||
@@ -247,27 +216,20 @@ library_fatal_error(const char *file, int line, const char *func,
|
|||||||
* Handle isc_error_fatal() calls from our libraries.
|
* Handle isc_error_fatal() calls from our libraries.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
if (named_g_logging) {
|
/*
|
||||||
/*
|
* Reset the error callback in case it is the log
|
||||||
* Reset the error callback in case it is the log
|
* routines causing the assertion.
|
||||||
* routines causing the assertion.
|
*/
|
||||||
*/
|
isc_error_setfatal(NULL);
|
||||||
isc_error_setfatal(NULL);
|
|
||||||
|
|
||||||
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
ISC_LOG_CRITICAL,
|
ISC_LOG_CRITICAL, "%s:%d:%s(): fatal error: ", file, line,
|
||||||
"%s:%d:%s(): fatal error: ", file, line, func);
|
func);
|
||||||
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
ISC_LOG_CRITICAL, format, args);
|
ISC_LOG_CRITICAL, format, args);
|
||||||
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
ISC_LOG_CRITICAL,
|
ISC_LOG_CRITICAL,
|
||||||
"exiting (due to fatal error in library)");
|
"exiting (due to fatal error in library)");
|
||||||
} else {
|
|
||||||
fprintf(stderr, "%s:%d:%s(): fatal error: ", file, line, func);
|
|
||||||
vfprintf(stderr, format, args);
|
|
||||||
fprintf(stderr, "\n");
|
|
||||||
fflush(stderr);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (named_g_coreok) {
|
if (named_g_coreok) {
|
||||||
abort();
|
abort();
|
||||||
@@ -287,19 +249,11 @@ library_unexpected_error(const char *file, int line, const char *func,
|
|||||||
* Handle isc_error_unexpected() calls from our libraries.
|
* Handle isc_error_unexpected() calls from our libraries.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
if (named_g_logging) {
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
ISC_LOG_ERROR, "%s:%d:%s(): unexpected error: ", file,
|
||||||
ISC_LOG_ERROR,
|
line, func);
|
||||||
"%s:%d:%s(): unexpected error: ", file, line,
|
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
func);
|
ISC_LOG_ERROR, format, args);
|
||||||
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
|
||||||
ISC_LOG_ERROR, format, args);
|
|
||||||
} else {
|
|
||||||
fprintf(stderr, "%s:%d:%s(): fatal error: ", file, line, func);
|
|
||||||
vfprintf(stderr, format, args);
|
|
||||||
fprintf(stderr, "\n");
|
|
||||||
fflush(stderr);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -952,25 +906,7 @@ parse_command_line(int argc, char *argv[]) {
|
|||||||
named_main_earlyfatal("option '-X' has been removed");
|
named_main_earlyfatal("option '-X' has been removed");
|
||||||
break;
|
break;
|
||||||
case 'F':
|
case 'F':
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
if (isc_crypto_fips_enable() != ISC_R_SUCCESS) {
|
||||||
fips = OSSL_PROVIDER_load(NULL, "fips");
|
|
||||||
if (fips == NULL) {
|
|
||||||
ERR_clear_error();
|
|
||||||
named_main_earlyfatal(
|
|
||||||
"Failed to load FIPS provider");
|
|
||||||
}
|
|
||||||
base = OSSL_PROVIDER_load(NULL, "base");
|
|
||||||
if (base == NULL) {
|
|
||||||
OSSL_PROVIDER_unload(fips);
|
|
||||||
ERR_clear_error();
|
|
||||||
named_main_earlyfatal(
|
|
||||||
"Failed to load base provider");
|
|
||||||
}
|
|
||||||
#endif
|
|
||||||
if (isc_fips_mode()) { /* Already in FIPS mode. */
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
if (isc_fips_set_mode(1) != ISC_R_SUCCESS) {
|
|
||||||
named_main_earlyfatal(
|
named_main_earlyfatal(
|
||||||
"setting FIPS mode failed");
|
"setting FIPS mode failed");
|
||||||
}
|
}
|
||||||
@@ -1574,15 +1510,6 @@ main(int argc, char *argv[]) {
|
|||||||
|
|
||||||
named_os_shutdown();
|
named_os_shutdown();
|
||||||
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
if (base != NULL) {
|
|
||||||
OSSL_PROVIDER_unload(base);
|
|
||||||
}
|
|
||||||
if (fips != NULL) {
|
|
||||||
OSSL_PROVIDER_unload(fips);
|
|
||||||
}
|
|
||||||
#endif
|
|
||||||
|
|
||||||
#ifdef HAVE_GPERFTOOLS_PROFILER
|
#ifdef HAVE_GPERFTOOLS_PROFILER
|
||||||
ProfilerStop();
|
ProfilerStop();
|
||||||
#endif /* ifdef HAVE_GPERFTOOLS_PROFILER */
|
#endif /* ifdef HAVE_GPERFTOOLS_PROFILER */
|
||||||
|
|||||||
+17
-7
@@ -38,7 +38,6 @@
|
|||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/fips.h>
|
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/hex.h>
|
#include <isc/hex.h>
|
||||||
#include <isc/hmac.h>
|
#include <isc/hmac.h>
|
||||||
@@ -3763,7 +3762,7 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
|||||||
uint32_t maxbits;
|
uint32_t maxbits;
|
||||||
unsigned int resopts = 0;
|
unsigned int resopts = 0;
|
||||||
dns_zone_t *zone = NULL;
|
dns_zone_t *zone = NULL;
|
||||||
uint32_t max_clients_per_query;
|
uint32_t clients_per_query, max_clients_per_query;
|
||||||
bool empty_zones_enable;
|
bool empty_zones_enable;
|
||||||
const cfg_obj_t *disablelist = NULL;
|
const cfg_obj_t *disablelist = NULL;
|
||||||
isc_stats_t *resstats = NULL;
|
isc_stats_t *resstats = NULL;
|
||||||
@@ -5169,15 +5168,26 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
|||||||
INSIST(result == ISC_R_SUCCESS);
|
INSIST(result == ISC_R_SUCCESS);
|
||||||
view->v6bias = cfg_obj_asuint32(obj) * 1000;
|
view->v6bias = cfg_obj_asuint32(obj) * 1000;
|
||||||
|
|
||||||
|
obj = NULL;
|
||||||
|
result = named_config_get(maps, "clients-per-query", &obj);
|
||||||
|
INSIST(result == ISC_R_SUCCESS);
|
||||||
|
clients_per_query = cfg_obj_asuint32(obj);
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = named_config_get(maps, "max-clients-per-query", &obj);
|
result = named_config_get(maps, "max-clients-per-query", &obj);
|
||||||
INSIST(result == ISC_R_SUCCESS);
|
INSIST(result == ISC_R_SUCCESS);
|
||||||
max_clients_per_query = cfg_obj_asuint32(obj);
|
max_clients_per_query = cfg_obj_asuint32(obj);
|
||||||
|
|
||||||
obj = NULL;
|
if (max_clients_per_query < clients_per_query) {
|
||||||
result = named_config_get(maps, "clients-per-query", &obj);
|
cfg_obj_log(obj, ISC_LOG_WARNING,
|
||||||
INSIST(result == ISC_R_SUCCESS);
|
"configured clients-per-query (%u) exceeds "
|
||||||
dns_resolver_setclientsperquery(view->resolver, cfg_obj_asuint32(obj),
|
"max-clients-per-query (%u); automatically "
|
||||||
|
"adjusting max-clients-per-query to (%u)",
|
||||||
|
clients_per_query, max_clients_per_query,
|
||||||
|
clients_per_query);
|
||||||
|
max_clients_per_query = clients_per_query;
|
||||||
|
}
|
||||||
|
dns_resolver_setclientsperquery(view->resolver, clients_per_query,
|
||||||
max_clients_per_query);
|
max_clients_per_query);
|
||||||
|
|
||||||
/*
|
/*
|
||||||
@@ -9377,7 +9387,7 @@ view_loaded(void *arg) {
|
|||||||
|
|
||||||
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
ISC_LOG_NOTICE, "FIPS mode is %s",
|
ISC_LOG_NOTICE, "FIPS mode is %s",
|
||||||
isc_fips_mode() ? "enabled" : "disabled");
|
isc_crypto_fips_mode() ? "enabled" : "disabled");
|
||||||
|
|
||||||
#if HAVE_LIBSYSTEMD
|
#if HAVE_LIBSYSTEMD
|
||||||
sd_notifyf(0,
|
sd_notifyf(0,
|
||||||
|
|||||||
@@ -1617,9 +1617,13 @@ xfrin_xmlrender(dns_zone_t *zone, void *arg) {
|
|||||||
isc_sockaddr_format(addrp, addr_buf, sizeof(addr_buf));
|
isc_sockaddr_format(addrp, addr_buf, sizeof(addr_buf));
|
||||||
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR addr_buf));
|
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR addr_buf));
|
||||||
} else if (is_presoa) {
|
} else if (is_presoa) {
|
||||||
addr = dns_zone_getprimaryaddr(zone);
|
if (dns_zone_getprimaryaddr(zone, &addr) == ISC_R_SUCCESS) {
|
||||||
isc_sockaddr_format(&addr, addr_buf, sizeof(addr_buf));
|
isc_sockaddr_format(&addr, addr_buf, sizeof(addr_buf));
|
||||||
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR addr_buf));
|
TRY0(xmlTextWriterWriteString(writer,
|
||||||
|
ISC_XMLCHAR addr_buf));
|
||||||
|
} else {
|
||||||
|
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR "-"));
|
||||||
|
}
|
||||||
} else {
|
} else {
|
||||||
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR "-"));
|
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR "-"));
|
||||||
}
|
}
|
||||||
@@ -2671,10 +2675,15 @@ xfrin_jsonrender(dns_zone_t *zone, void *arg) {
|
|||||||
json_object_object_add(xfrinobj, "remoteaddr",
|
json_object_object_add(xfrinobj, "remoteaddr",
|
||||||
json_object_new_string(addr_buf));
|
json_object_new_string(addr_buf));
|
||||||
} else if (is_presoa) {
|
} else if (is_presoa) {
|
||||||
addr = dns_zone_getprimaryaddr(zone);
|
if (dns_zone_getprimaryaddr(zone, &addr) == ISC_R_SUCCESS) {
|
||||||
isc_sockaddr_format(&addr, addr_buf, sizeof(addr_buf));
|
isc_sockaddr_format(&addr, addr_buf, sizeof(addr_buf));
|
||||||
json_object_object_add(xfrinobj, "remoteaddr",
|
json_object_object_add(
|
||||||
json_object_new_string(addr_buf));
|
xfrinobj, "remoteaddr",
|
||||||
|
json_object_new_string(addr_buf));
|
||||||
|
} else {
|
||||||
|
json_object_object_add(xfrinobj, "remoteaddr",
|
||||||
|
json_object_new_string("-"));
|
||||||
|
}
|
||||||
} else {
|
} else {
|
||||||
json_object_object_add(xfrinobj, "remoteaddr",
|
json_object_object_add(xfrinobj, "remoteaddr",
|
||||||
json_object_new_string("-"));
|
json_object_new_string("-"));
|
||||||
|
|||||||
@@ -28,6 +28,7 @@ options {
|
|||||||
} except-from {
|
} except-from {
|
||||||
"example";
|
"example";
|
||||||
};
|
};
|
||||||
|
qname-minimization disabled; // Regression test for GL #4652
|
||||||
};
|
};
|
||||||
|
|
||||||
trust-anchors { };
|
trust-anchors { };
|
||||||
|
|||||||
@@ -552,16 +552,21 @@ sys.exit(1)'; then
|
|||||||
$DIG $DIGOPTS @10.53.0.1 tsig. >dig.out.test$n.1 || ret=1
|
$DIG $DIGOPTS @10.53.0.1 tsig. >dig.out.test$n.1 || ret=1
|
||||||
grep "status: NOERROR" dig.out.test$n.1 >/dev/null || ret=1
|
grep "status: NOERROR" dig.out.test$n.1 >/dev/null || ret=1
|
||||||
rndc_dumpdb ns1
|
rndc_dumpdb ns1
|
||||||
|
# prime cache with NS response for QNAME minimisation
|
||||||
grep "$pat" ns1/named_dump.db.test$n >/dev/null || ret=1
|
grep "$pat" ns1/named_dump.db.test$n >/dev/null || ret=1
|
||||||
|
$DIG $DIGOPTS @10.53.0.1 NS nocookie.tsig >dig.out.test$n.2 || ret=1
|
||||||
|
grep "status: NOERROR" dig.out.test$n.2 >/dev/null || ret=1
|
||||||
# check the disabled server response
|
# check the disabled server response
|
||||||
nextpart ns1/named.run >/dev/null
|
nextpart ns1/named.run >/dev/null
|
||||||
$DIG $DIGOPTS @10.53.0.1 nocookie.tsig >dig.out.test$n.2 || ret=1
|
$DIG $DIGOPTS @10.53.0.1 nocookie.tsig >dig.out.test$n.3 || ret=1
|
||||||
grep "status: NOERROR" dig.out.test$n.2 >/dev/null || ret=1
|
grep "status: NOERROR" dig.out.test$n.3 >/dev/null || ret=1
|
||||||
grep 'A.10\.53\.0\.9' dig.out.test$n.2 >/dev/null || ret=1
|
grep 'A.10\.53\.0\.9' dig.out.test$n.3 >/dev/null || ret=1
|
||||||
grep 'A.10\.53\.0\.10' dig.out.test$n.2 >/dev/null || ret=1
|
grep 'A.10\.53\.0\.10' dig.out.test$n.3 >/dev/null || ret=1
|
||||||
nextpart ns1/named.run >named.run.test$n
|
nextpart ns1/named.run >named.run.test$n
|
||||||
count=$(grep -c ') [0-9][0-9]* NOERROR 0' named.run.test$n)
|
count=$(grep -c ') [0-9][0-9]* NOERROR 0' named.run.test$n)
|
||||||
test $count -eq 2 || ret=1
|
test $count -eq 2 || ret=1
|
||||||
|
count=$(grep -c '^; COOKIE: ................................' named.run.test$n)
|
||||||
|
test $count -eq 1 || ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -1135,6 +1135,16 @@ if [ -x "$DIG" ]; then
|
|||||||
grep "; EDNS: version: 0, flags:; udp: 1232" dig.out.test$n >/dev/null || ret=1
|
grep "; EDNS: version: 0, flags:; udp: 1232" dig.out.test$n >/dev/null || ret=1
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|
||||||
|
n=$((n + 1))
|
||||||
|
echo_i "check that dig +showbadvers works ($n)"
|
||||||
|
dig_with_opts @10.53.0.3 +edns=1 +qr +showbadvers a.example >dig.out.test$n 2>&1 || ret=1
|
||||||
|
grep "; EDNS: version: 1, flags:; udp: 1232" dig.out.test$n >/dev/null || ret=1
|
||||||
|
grep "; EDNS: version: 0, flags:; udp: 1232" dig.out.test$n >/dev/null || ret=1
|
||||||
|
grep -F "status: BADVERS" dig.out.test$n >/dev/null || ret=1
|
||||||
|
grep -F "status: NOERROR" dig.out.test$n >/dev/null || ret=1
|
||||||
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
|
status=$((status + ret))
|
||||||
else
|
else
|
||||||
echo_i "$DIG is needed, so skipping these dig tests"
|
echo_i "$DIG is needed, so skipping these dig tests"
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -64,7 +64,7 @@ for subdomain in digest-alg-unsupported ds-unsupported secure badds \
|
|||||||
kskonly update-nsec3 auto-nsec auto-nsec3 secure.below-cname \
|
kskonly update-nsec3 auto-nsec auto-nsec3 secure.below-cname \
|
||||||
ttlpatch split-dnssec split-smart expired expiring upper lower \
|
ttlpatch split-dnssec split-smart expired expiring upper lower \
|
||||||
dnskey-unknown dnskey-unsupported dnskey-unsupported-2 \
|
dnskey-unknown dnskey-unsupported dnskey-unsupported-2 \
|
||||||
dnskey-nsec3-unknown managed-future revkey \
|
dnskey-nsec3-unknown managed-future future revkey \
|
||||||
dname-at-apex-nsec3 occluded rsasha1 rsasha1-1024; do
|
dname-at-apex-nsec3 occluded rsasha1 rsasha1-1024; do
|
||||||
cp "../ns3/dsset-$subdomain.example." .
|
cp "../ns3/dsset-$subdomain.example." .
|
||||||
done
|
done
|
||||||
|
|||||||
@@ -0,0 +1,6 @@
|
|||||||
|
; This is a key-signing key, keyid 23640, for .
|
||||||
|
; Created: 20250310185208 (Mon Mar 10 18:52:08 2025)
|
||||||
|
; Publish: 20250310185208 (Mon Mar 10 18:52:08 2025)
|
||||||
|
; Activate: 20250310185208 (Mon Mar 10 18:52:08 2025)
|
||||||
|
; Revoke: 20250310185208 (Mon Mar 10 18:52:08 2025)
|
||||||
|
. IN DNSKEY 257 3 13 uKwpRtMH+9iuUk/Xj6LciIP5ZckaBtXaUqxUxzJYexXjvxGZGX4470Jv hq2NCI3HBZQNaCCP/h9sluhIzRGPTA==
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
Private-key-format: v1.3
|
||||||
|
Algorithm: 13 (ECDSAP256SHA256)
|
||||||
|
PrivateKey: m5udfGNSijISQ8Tfp4kx09O1em4PErLUw/mCj3SKmqw=
|
||||||
|
Created: 20250310185208
|
||||||
|
Publish: 20250310185208
|
||||||
|
Activate: 20250310185208
|
||||||
|
Revoke: 20250310185208
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
; This is a zone-signing key, keyid 23768, for .
|
||||||
|
; Created: 20250310185208 (Mon Mar 10 18:52:08 2025)
|
||||||
|
; Publish: 20250310185208 (Mon Mar 10 18:52:08 2025)
|
||||||
|
; Activate: 20250310185208 (Mon Mar 10 18:52:08 2025)
|
||||||
|
. IN DNSKEY 256 3 13 TFelYtTRBWeA9A307vvuWIcaNwW4txW4RgSELtsi46ZQs24ncRxmxtFf uJuPyVXePNiE4HNI9CIowGUsn5WuBw==
|
||||||
@@ -0,0 +1,37 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; SPDX-License-Identifier: MPL-2.0
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
; This is a zone which has two DNSKEY records, both of which have
|
||||||
|
; existing private key files available. They should be loaded automatically
|
||||||
|
; and the zone correctly signed.
|
||||||
|
;
|
||||||
|
$TTL 30 ; 30 seconds
|
||||||
|
. IN SOA a.root.servers.nil. each.isc.org. (
|
||||||
|
2000042101 ; serial
|
||||||
|
600 ; refresh (10 minutes)
|
||||||
|
600 ; retry (10 minutes)
|
||||||
|
1200 ; expire (20 minutes)
|
||||||
|
600 ; minimum (10 minutes)
|
||||||
|
)
|
||||||
|
NS a.root-servers.nil.
|
||||||
|
DNSKEY 256 3 13 (
|
||||||
|
TFelYtTRBWeA9A307vvuWIcaNwW4txW4RgSELtsi46ZQ
|
||||||
|
s24ncRxmxtFfuJuPyVXePNiE4HNI9CIowGUsn5WuBw==
|
||||||
|
) ; ZSK; alg = ECDSAP256SHA256 ; key id = 23768
|
||||||
|
DNSKEY 257 3 13 (
|
||||||
|
OSmhpULEDCUzHCBeDU5uJXzkCcGuW2qrkQznKRPGhRZN
|
||||||
|
j7ZUIGInGzM5Um5m02ULWt8tKbi55NJUeifKWegQ0g==
|
||||||
|
) ; KSK; alg = ECDSAP256SHA256 ; key id = 22255
|
||||||
|
DNSKEY 385 3 13 (
|
||||||
|
uKwpRtMH+9iuUk/Xj6LciIP5ZckaBtXaUqxUxzJYexXj
|
||||||
|
vxGZGX4470Jvhq2NCI3HBZQNaCCP/h9sluhIzRGPTA==
|
||||||
|
) ; revoked KSK; alg = ECDSAP256SHA256 ; key id = 23768
|
||||||
|
a.root-servers.nil. A 10.53.0.1
|
||||||
@@ -1564,6 +1564,18 @@ n=$((n + 1))
|
|||||||
test "$ret" -eq 0 || echo_i "failed"
|
test "$ret" -eq 0 || echo_i "failed"
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|
||||||
|
echo_ic "revoked KSK ID collides with ZSK ($n)"
|
||||||
|
ret=0
|
||||||
|
# signing should fail, but should not coredump
|
||||||
|
(
|
||||||
|
cd signer/general || exit 0
|
||||||
|
rm -f signed.zone
|
||||||
|
$SIGNER -S -f signed.zone -o . test12.zone >signer.out.$n
|
||||||
|
) && ret=1
|
||||||
|
n=$((n + 1))
|
||||||
|
test "$ret" -eq 0 || echo_i "failed"
|
||||||
|
status=$((status + ret))
|
||||||
|
|
||||||
echo_ic "check that dnssec-signzone rejects excessive NSEC3 iterations ($n)"
|
echo_ic "check that dnssec-signzone rejects excessive NSEC3 iterations ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
(
|
(
|
||||||
@@ -2179,7 +2191,7 @@ echo_i "checking RRSIG query from cache ($n)"
|
|||||||
ret=0
|
ret=0
|
||||||
dig_with_opts normalthenrrsig.secure.example. @10.53.0.4 a >/dev/null || ret=1
|
dig_with_opts normalthenrrsig.secure.example. @10.53.0.4 a >/dev/null || ret=1
|
||||||
ans=$(dig_with_opts +short normalthenrrsig.secure.example. @10.53.0.4 rrsig) || ret=1
|
ans=$(dig_with_opts +short normalthenrrsig.secure.example. @10.53.0.4 rrsig) || ret=1
|
||||||
expect=$(dig_with_opts +short normalthenrrsig.secure.example. @10.53.0.3 rrsig | grep '^A') || ret=1
|
expect=$(dig_with_opts +short normalthenrrsig.secure.example. @10.53.0.3 rrsig | grep '^\(A\|NSEC\)') || ret=1
|
||||||
test "$ans" = "$expect" || ret=1
|
test "$ans" = "$expect" || ret=1
|
||||||
# also check that RA is set
|
# also check that RA is set
|
||||||
dig_with_opts normalthenrrsig.secure.example. @10.53.0.4 rrsig >dig.out.ns4.test$n || ret=1
|
dig_with_opts normalthenrrsig.secure.example. @10.53.0.4 rrsig >dig.out.ns4.test$n || ret=1
|
||||||
@@ -2859,6 +2871,19 @@ dig_with_opts +noauth expired.example. +dnssec @10.53.0.4 soa >dig.out.ns4.test$
|
|||||||
grep "SERVFAIL" dig.out.ns4.test$n >/dev/null || ret=1
|
grep "SERVFAIL" dig.out.ns4.test$n >/dev/null || ret=1
|
||||||
grep "flags:.*ad.*QUERY" dig.out.ns4.test$n >/dev/null && ret=1
|
grep "flags:.*ad.*QUERY" dig.out.ns4.test$n >/dev/null && ret=1
|
||||||
grep "expired.example/.*: RRSIG has expired" ns4/named.run >/dev/null || ret=1
|
grep "expired.example/.*: RRSIG has expired" ns4/named.run >/dev/null || ret=1
|
||||||
|
grep "; EDE: 7 (Signature Expired): (expired.example/DNSKEY)" dig.out.ns4.test$n >/dev/null || ret=1
|
||||||
|
n=$((n + 1))
|
||||||
|
test "$ret" -eq 0 || echo_i "failed"
|
||||||
|
status=$((status + ret))
|
||||||
|
|
||||||
|
status=$((status + ret))
|
||||||
|
echo_i "checking signatures in the future do not validate ($n)"
|
||||||
|
ret=0
|
||||||
|
dig_with_opts +noauth future.example. +dnssec @10.53.0.4 soa >dig.out.ns4.test$n || ret=1
|
||||||
|
grep "SERVFAIL" dig.out.ns4.test$n >/dev/null || ret=1
|
||||||
|
grep "flags:.*ad.*QUERY" dig.out.ns4.test$n >/dev/null && ret=1
|
||||||
|
grep "future.example/.*: RRSIG validity period has not begun" ns4/named.run >/dev/null || ret=1
|
||||||
|
grep "; EDE: 8 (Signature Not Yet Valid): (future.example/DNSKEY)" dig.out.ns4.test$n >/dev/null || ret=1
|
||||||
n=$((n + 1))
|
n=$((n + 1))
|
||||||
test "$ret" -eq 0 || echo_i "failed"
|
test "$ret" -eq 0 || echo_i "failed"
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
@@ -3755,7 +3780,7 @@ status=$((status + ret))
|
|||||||
echo_i "checking EDE code 1 for bad alg mnemonic ($n)"
|
echo_i "checking EDE code 1 for bad alg mnemonic ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
dig_with_opts @10.53.0.4 badalg.secure.example >dig.out.ns4.test$n || ret=1
|
dig_with_opts @10.53.0.4 badalg.secure.example >dig.out.ns4.test$n || ret=1
|
||||||
grep "; EDE: 1 (Unsupported DNSKEY Algorithm): (ECDSAP256SHA256 badalg.secure.example/A)" dig.out.ns4.test$n >/dev/null || ret=1
|
grep "; EDE: 1 (Unsupported DNSKEY Algorithm): (ECDSAP256SHA256 badalg.secure.example/NSEC)" dig.out.ns4.test$n >/dev/null || ret=1
|
||||||
grep "flags:.*ad.*QUERY" dig.out.ns4.test$n >/dev/null && ret=1
|
grep "flags:.*ad.*QUERY" dig.out.ns4.test$n >/dev/null && ret=1
|
||||||
n=$((n + 1))
|
n=$((n + 1))
|
||||||
test "$ret" -eq 0 || echo_i "failed"
|
test "$ret" -eq 0 || echo_i "failed"
|
||||||
|
|||||||
@@ -232,9 +232,7 @@ addrdataset(dns_db_t *db, dns_dbnode_t *node, dns_dbversion_t *version,
|
|||||||
dns_fixedname_init(&name);
|
dns_fixedname_init(&name);
|
||||||
CHECK(dns__db_addrdataset(sampledb->db, node, version, now, rdataset,
|
CHECK(dns__db_addrdataset(sampledb->db, node, version, now, rdataset,
|
||||||
options, addedrdataset DNS__DB_FLARG_PASS));
|
options, addedrdataset DNS__DB_FLARG_PASS));
|
||||||
if (rdataset->type == dns_rdatatype_a ||
|
if (dns_rdatatype_isaddr(rdataset->type)) {
|
||||||
rdataset->type == dns_rdatatype_aaaa)
|
|
||||||
{
|
|
||||||
CHECK(dns_db_nodefullname(sampledb->db, node,
|
CHECK(dns_db_nodefullname(sampledb->db, node,
|
||||||
dns_fixedname_name(&name)));
|
dns_fixedname_name(&name)));
|
||||||
CHECK(syncptrs(sampledb->inst, dns_fixedname_name(&name),
|
CHECK(syncptrs(sampledb->inst, dns_fixedname_name(&name),
|
||||||
@@ -263,9 +261,7 @@ subtractrdataset(dns_db_t *db, dns_dbnode_t *node, dns_dbversion_t *version,
|
|||||||
goto cleanup;
|
goto cleanup;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (rdataset->type == dns_rdatatype_a ||
|
if (dns_rdatatype_isaddr(rdataset->type)) {
|
||||||
rdataset->type == dns_rdatatype_aaaa)
|
|
||||||
{
|
|
||||||
CHECK(dns_db_nodefullname(sampledb->db, node,
|
CHECK(dns_db_nodefullname(sampledb->db, node,
|
||||||
dns_fixedname_name(&name)));
|
dns_fixedname_name(&name)));
|
||||||
CHECK(syncptrs(sampledb->inst, dns_fixedname_name(&name),
|
CHECK(syncptrs(sampledb->inst, dns_fixedname_name(&name),
|
||||||
|
|||||||
@@ -23,7 +23,7 @@
|
|||||||
#include <openssl/provider.h>
|
#include <openssl/provider.h>
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
#include <isc/fips.h>
|
#include <isc/crypto.h>
|
||||||
#include <isc/lib.h>
|
#include <isc/lib.h>
|
||||||
#include <isc/md.h>
|
#include <isc/md.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
@@ -134,7 +134,7 @@ main(int argc, char **argv) {
|
|||||||
return 1;
|
return 1;
|
||||||
#endif
|
#endif
|
||||||
#else
|
#else
|
||||||
if (isc_fips_mode()) {
|
if (isc_crypto_fips_mode()) {
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
return 0;
|
return 0;
|
||||||
#else
|
#else
|
||||||
@@ -149,7 +149,7 @@ main(int argc, char **argv) {
|
|||||||
#if defined(ENABLE_FIPS_MODE)
|
#if defined(ENABLE_FIPS_MODE)
|
||||||
return 0;
|
return 0;
|
||||||
#else
|
#else
|
||||||
return isc_fips_mode() ? 0 : 1;
|
return isc_crypto_fips_mode() ? 0 : 1;
|
||||||
#endif
|
#endif
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,52 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: MPL-2.0
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
options {
|
||||||
|
query-source address 10.53.0.5;
|
||||||
|
notify-source 10.53.0.5;
|
||||||
|
transfer-source 10.53.0.5;
|
||||||
|
port @PORT@;
|
||||||
|
directory ".";
|
||||||
|
pid-file "named.pid";
|
||||||
|
listen-on { 10.53.0.5; };
|
||||||
|
listen-on-v6 { none; };
|
||||||
|
recursion yes;
|
||||||
|
dnssec-validation yes;
|
||||||
|
notify yes;
|
||||||
|
stale-answer-enable yes;
|
||||||
|
stale-cache-enable yes;
|
||||||
|
stale-answer-client-timeout 0;
|
||||||
|
/* max-clients-per-query < clients-per-query */
|
||||||
|
clients-per-query 10;
|
||||||
|
max-clients-per-query 5;
|
||||||
|
};
|
||||||
|
|
||||||
|
trust-anchors { };
|
||||||
|
|
||||||
|
server 10.53.0.4 {
|
||||||
|
edns no;
|
||||||
|
};
|
||||||
|
|
||||||
|
key rndc_key {
|
||||||
|
secret "1234abcd8765";
|
||||||
|
algorithm @DEFAULT_HMAC@;
|
||||||
|
};
|
||||||
|
|
||||||
|
controls {
|
||||||
|
inet 10.53.0.5 port @CONTROLPORT@ allow { any; } keys { rndc_key; };
|
||||||
|
};
|
||||||
|
|
||||||
|
zone "." {
|
||||||
|
type hint;
|
||||||
|
file "root.hint";
|
||||||
|
};
|
||||||
@@ -328,5 +328,14 @@ echo_i "$zspill clients spilled (expected $expected)"
|
|||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|
||||||
|
n=$((n + 1))
|
||||||
|
echo_i "checking a warning is logged if max-clients-per-query < clients-per-query ($n)"
|
||||||
|
ret=0
|
||||||
|
copy_setports ns5/named3.conf.in ns5/named.conf
|
||||||
|
rndc_reconfig ns5 10.53.0.5
|
||||||
|
wait_for_message ns5/named.run "configured clients-per-query (10) exceeds max-clients-per-query (5); automatically adjusting max-clients-per-query to (10)" || ret=1
|
||||||
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
|
status=$((status + ret))
|
||||||
|
|
||||||
echo_i "exit status: $status"
|
echo_i "exit status: $status"
|
||||||
[ $status -eq 0 ] || exit 1
|
[ $status -eq 0 ] || exit 1
|
||||||
|
|||||||
@@ -597,6 +597,10 @@ def test_ksr_common(servers):
|
|||||||
selected += 1
|
selected += 1
|
||||||
if "Generating" in output:
|
if "Generating" in output:
|
||||||
generated += 1
|
generated += 1
|
||||||
|
# Subtract if there was a key collision.
|
||||||
|
if "collide" in output:
|
||||||
|
generated -= 1
|
||||||
|
|
||||||
assert selected == 2
|
assert selected == 2
|
||||||
assert generated == 2
|
assert generated == 2
|
||||||
for index, key in enumerate(overlapping_zsks):
|
for index, key in enumerate(overlapping_zsks):
|
||||||
|
|||||||
@@ -111,7 +111,7 @@ cleanup:
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (mctx != NULL) {
|
if (mctx != NULL) {
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
}
|
}
|
||||||
|
|
||||||
return result != ISC_R_SUCCESS ? 1 : 0;
|
return result != ISC_R_SUCCESS ? 1 : 0;
|
||||||
|
|||||||
@@ -385,7 +385,7 @@ $DIG $DIGOPTS @10.53.0.3 foo.initially-unavailable. A >dig.out.ns3.test$n.1 2>&1
|
|||||||
grep "NOERROR" dig.out.ns3.test$n.1 >/dev/null || ret=1
|
grep "NOERROR" dig.out.ns3.test$n.1 >/dev/null || ret=1
|
||||||
grep "flags:.* ad" dig.out.ns3.test$n.1 >/dev/null || ret=1
|
grep "flags:.* ad" dig.out.ns3.test$n.1 >/dev/null || ret=1
|
||||||
# Sanity check: the authoritative server should have been queried.
|
# Sanity check: the authoritative server should have been queried.
|
||||||
nextpart ns2/named.run | grep "query 'foo.initially-unavailable/A/IN'" >/dev/null || ret=1
|
nextpart ns2/named.run | grep "query 'foo.initially-unavailable/NS/IN'" >/dev/null || ret=1
|
||||||
# Reconfigure ns2 so that the zone can be mirrored on ns3.
|
# Reconfigure ns2 so that the zone can be mirrored on ns3.
|
||||||
sed '/^zone "initially-unavailable" {$/,/^};$/ {
|
sed '/^zone "initially-unavailable" {$/,/^};$/ {
|
||||||
s/10.53.0.254/10.53.0.3/
|
s/10.53.0.254/10.53.0.3/
|
||||||
@@ -403,7 +403,7 @@ $DIG $DIGOPTS @10.53.0.3 foo.initially-unavailable. A >dig.out.ns3.test$n.2 2>&1
|
|||||||
grep "NOERROR" dig.out.ns3.test$n.2 >/dev/null || ret=1
|
grep "NOERROR" dig.out.ns3.test$n.2 >/dev/null || ret=1
|
||||||
grep "flags:.* ad" dig.out.ns3.test$n.2 >/dev/null || ret=1
|
grep "flags:.* ad" dig.out.ns3.test$n.2 >/dev/null || ret=1
|
||||||
# Ensure the authoritative server was not queried.
|
# Ensure the authoritative server was not queried.
|
||||||
nextpart ns2/named.run | grep "query 'foo.initially-unavailable/A/IN'" >/dev/null && ret=1
|
nextpart ns2/named.run | grep "query 'foo.initially-unavailable/NS/IN'" >/dev/null && ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|
||||||
@@ -434,7 +434,7 @@ $DIG $DIGOPTS @10.53.0.3 foo.initially-unavailable. A >dig.out.ns3.test$n 2>&1 |
|
|||||||
grep "NOERROR" dig.out.ns3.test$n >/dev/null || ret=1
|
grep "NOERROR" dig.out.ns3.test$n >/dev/null || ret=1
|
||||||
grep "flags:.* ad" dig.out.ns3.test$n >/dev/null || ret=1
|
grep "flags:.* ad" dig.out.ns3.test$n >/dev/null || ret=1
|
||||||
# Sanity check: the authoritative server should have been queried.
|
# Sanity check: the authoritative server should have been queried.
|
||||||
nextpart ns2/named.run | grep "query 'foo.initially-unavailable/A/IN'" >/dev/null || ret=1
|
nextpart ns2/named.run | grep "query 'foo.initially-unavailable/NS/IN'" >/dev/null || ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|
||||||
|
|||||||
@@ -104,9 +104,10 @@ def create_response(msg):
|
|||||||
r.answer.append(dns.rrset.from_text(lqname, 1, IN, TXT, "hooray"))
|
r.answer.append(dns.rrset.from_text(lqname, 1, IN, TXT, "hooray"))
|
||||||
elif rrtype == NS:
|
elif rrtype == NS:
|
||||||
# NS a.b.
|
# NS a.b.
|
||||||
|
# This is only returned if a query for b.stale/NS has been made
|
||||||
r.answer.append(dns.rrset.from_text(lqname, 1, IN, NS, "ns.a.b.stale."))
|
r.answer.append(dns.rrset.from_text(lqname, 1, IN, NS, "ns.a.b.stale."))
|
||||||
r.additional.append(
|
r.additional.append(
|
||||||
dns.rrset.from_text("ns.a.b.stale.", 1, IN, A, "10.53.0.3")
|
dns.rrset.from_text("ns.a.b.stale.", 1, IN, A, "10.53.0.4")
|
||||||
)
|
)
|
||||||
elif rrtype == SOA:
|
elif rrtype == SOA:
|
||||||
# SOA a.b.
|
# SOA a.b.
|
||||||
@@ -126,7 +127,7 @@ def create_response(msg):
|
|||||||
r.flags |= dns.flags.AA
|
r.flags |= dns.flags.AA
|
||||||
if rrtype == A:
|
if rrtype == A:
|
||||||
r.answer.append(
|
r.answer.append(
|
||||||
dns.rrset.from_text("ns.a.b.stale.", 1, IN, A, "10.53.0.3")
|
dns.rrset.from_text("ns.a.b.stale.", 1, IN, A, "10.53.0.4")
|
||||||
)
|
)
|
||||||
else:
|
else:
|
||||||
# NODATA.
|
# NODATA.
|
||||||
|
|||||||
@@ -127,12 +127,14 @@ ADDR a.bit.longer.ns.name.good.
|
|||||||
ADDR ns2.good.
|
ADDR ns2.good.
|
||||||
ADDR ns3.good.
|
ADDR ns3.good.
|
||||||
ADDR ns3.good.
|
ADDR ns3.good.
|
||||||
|
NS a.bit.longer.ns.name.good.
|
||||||
NS bit.longer.ns.name.good.
|
NS bit.longer.ns.name.good.
|
||||||
NS boing.good.
|
NS boing.good.
|
||||||
NS good.
|
NS good.
|
||||||
NS longer.ns.name.good.
|
NS longer.ns.name.good.
|
||||||
NS name.good.
|
NS name.good.
|
||||||
NS ns.name.good.
|
NS ns.name.good.
|
||||||
|
NS ns3.good.
|
||||||
NS zoop.boing.good.
|
NS zoop.boing.good.
|
||||||
__EOF
|
__EOF
|
||||||
cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1
|
cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1
|
||||||
@@ -165,11 +167,13 @@ ADDR a.bit.longer.ns.name.good.
|
|||||||
ADDR ns2.good.
|
ADDR ns2.good.
|
||||||
ADDR ns3.good.
|
ADDR ns3.good.
|
||||||
ADDR ns3.good.
|
ADDR ns3.good.
|
||||||
|
NS a.bit.longer.ns.name.good.
|
||||||
NS bit.longer.ns.name.good.
|
NS bit.longer.ns.name.good.
|
||||||
NS boing.good.
|
NS boing.good.
|
||||||
NS longer.ns.name.good.
|
NS longer.ns.name.good.
|
||||||
NS name.good.
|
NS name.good.
|
||||||
NS ns.name.good.
|
NS ns.name.good.
|
||||||
|
NS ns3.good.
|
||||||
NS zoop.boing.good.
|
NS zoop.boing.good.
|
||||||
__EOF
|
__EOF
|
||||||
cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1
|
cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1
|
||||||
@@ -221,6 +225,7 @@ ADDR ns3.bad.
|
|||||||
ADDR ns3.bad.
|
ADDR ns3.bad.
|
||||||
NS boing.bad.
|
NS boing.bad.
|
||||||
NS name.bad.
|
NS name.bad.
|
||||||
|
NS ns3.bad.
|
||||||
__EOF
|
__EOF
|
||||||
cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1
|
cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1
|
||||||
ADDR icky.icky.icky.ptang.zoop.boing.bad.
|
ADDR icky.icky.icky.ptang.zoop.boing.bad.
|
||||||
@@ -271,6 +276,7 @@ ADDR ns3.ugly.
|
|||||||
NS boing.ugly.
|
NS boing.ugly.
|
||||||
NS name.ugly.
|
NS name.ugly.
|
||||||
NS name.ugly.
|
NS name.ugly.
|
||||||
|
NS ns3.ugly.
|
||||||
__EOF
|
__EOF
|
||||||
echo "ADDR icky.icky.icky.ptang.zoop.boing.ugly." | diff ans3/query.log - >/dev/null || ret=1
|
echo "ADDR icky.icky.icky.ptang.zoop.boing.ugly." | diff ans3/query.log - >/dev/null || ret=1
|
||||||
echo "ADDR icky.icky.icky.ptang.zoop.boing.ugly." | diff ans4/query.log - >/dev/null || ret=1
|
echo "ADDR icky.icky.icky.ptang.zoop.boing.ugly." | diff ans4/query.log - >/dev/null || ret=1
|
||||||
@@ -302,11 +308,13 @@ ADDR a.bit.longer.ns.name.slow.
|
|||||||
ADDR ns2.slow.
|
ADDR ns2.slow.
|
||||||
ADDR ns3.slow.
|
ADDR ns3.slow.
|
||||||
ADDR ns3.slow.
|
ADDR ns3.slow.
|
||||||
|
NS a.bit.longer.ns.name.slow.
|
||||||
NS bit.longer.ns.name.slow.
|
NS bit.longer.ns.name.slow.
|
||||||
NS boing.slow.
|
NS boing.slow.
|
||||||
NS longer.ns.name.slow.
|
NS longer.ns.name.slow.
|
||||||
NS name.slow.
|
NS name.slow.
|
||||||
NS ns.name.slow.
|
NS ns.name.slow.
|
||||||
|
NS ns3.slow.
|
||||||
NS slow.
|
NS slow.
|
||||||
NS zoop.boing.slow.
|
NS zoop.boing.slow.
|
||||||
__EOF
|
__EOF
|
||||||
@@ -340,6 +348,7 @@ NS 8.f.4.0.1.0.0.2.ip6.arpa.
|
|||||||
NS 0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
|
NS 0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
|
||||||
NS 0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
|
NS 0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
|
||||||
NS 0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
|
NS 0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
|
||||||
|
NS 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
|
||||||
PTR 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
|
PTR 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
|
||||||
__EOF
|
__EOF
|
||||||
for ans in ans2 ans3 ans4; do mv -f $ans/query.log query-$ans-$n.log 2>/dev/null || true; done
|
for ans in ans2 ans3 ans4; do mv -f $ans/query.log query-$ans-$n.log 2>/dev/null || true; done
|
||||||
@@ -362,12 +371,14 @@ ADDR a.bit.longer.ns.name.good.
|
|||||||
ADDR ns2.good.
|
ADDR ns2.good.
|
||||||
ADDR ns3.good.
|
ADDR ns3.good.
|
||||||
ADDR ns3.good.
|
ADDR ns3.good.
|
||||||
|
NS a.bit.longer.ns.name.good.
|
||||||
NS bit.longer.ns.name.good.
|
NS bit.longer.ns.name.good.
|
||||||
NS boing.good.
|
NS boing.good.
|
||||||
NS good.
|
NS good.
|
||||||
NS longer.ns.name.good.
|
NS longer.ns.name.good.
|
||||||
NS name.good.
|
NS name.good.
|
||||||
NS ns.name.good.
|
NS ns.name.good.
|
||||||
|
NS ns3.good.
|
||||||
NS zoop.boing.good.
|
NS zoop.boing.good.
|
||||||
__EOF
|
__EOF
|
||||||
cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1
|
cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1
|
||||||
@@ -449,6 +460,7 @@ grep "a\.b\.stale\..*1.*IN.*TXT.*hooray" dig.out.test$n >/dev/null || ret=1
|
|||||||
sleep 1
|
sleep 1
|
||||||
sort ans2/query.log >ans2/query.log.sorted
|
sort ans2/query.log >ans2/query.log.sorted
|
||||||
cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1
|
cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1
|
||||||
|
ADDR ns.a.b.stale.
|
||||||
ADDR ns.b.stale.
|
ADDR ns.b.stale.
|
||||||
ADDR ns2.stale.
|
ADDR ns2.stale.
|
||||||
NS b.stale.
|
NS b.stale.
|
||||||
@@ -457,7 +469,9 @@ __EOF
|
|||||||
test -f ans3/query.log && ret=1
|
test -f ans3/query.log && ret=1
|
||||||
sort ans4/query.log >ans4/query.log.sorted
|
sort ans4/query.log >ans4/query.log.sorted
|
||||||
cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1
|
cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1
|
||||||
|
ADDR ns.a.b.stale.
|
||||||
ADDR ns.b.stale.
|
ADDR ns.b.stale.
|
||||||
|
NS a.b.stale.
|
||||||
NS b.stale.
|
NS b.stale.
|
||||||
TXT a.b.stale.
|
TXT a.b.stale.
|
||||||
__EOF
|
__EOF
|
||||||
@@ -476,6 +490,7 @@ grep "a\.b\.stale\..*1.*IN.*TXT.*hooray" dig.out.test$n >/dev/null || ret=1
|
|||||||
sleep 1
|
sleep 1
|
||||||
sort ans2/query.log >ans2/query.log.sorted
|
sort ans2/query.log >ans2/query.log.sorted
|
||||||
cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1
|
cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1
|
||||||
|
ADDR ns.a.b.stale.
|
||||||
ADDR ns.b.stale.
|
ADDR ns.b.stale.
|
||||||
ADDR ns2.stale.
|
ADDR ns2.stale.
|
||||||
NS b.stale.
|
NS b.stale.
|
||||||
@@ -483,7 +498,9 @@ __EOF
|
|||||||
test -f ans3/query.log && ret=1
|
test -f ans3/query.log && ret=1
|
||||||
sort ans4/query.log >ans4/query.log.sorted
|
sort ans4/query.log >ans4/query.log.sorted
|
||||||
cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1
|
cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1
|
||||||
|
ADDR ns.a.b.stale.
|
||||||
ADDR ns.b.stale.
|
ADDR ns.b.stale.
|
||||||
|
NS a.b.stale.
|
||||||
TXT a.b.stale.
|
TXT a.b.stale.
|
||||||
__EOF
|
__EOF
|
||||||
for ans in ans2 ans3 ans4; do mv -f $ans/query.log query-$ans-$n.log 2>/dev/null || true; done
|
for ans in ans2 ans3 ans4; do mv -f $ans/query.log query-$ans-$n.log 2>/dev/null || true; done
|
||||||
@@ -519,6 +536,7 @@ grep "a\.b\.stale\..*1.*IN.*TXT.*hooray" dig.out.test$n >/dev/null || ret=1
|
|||||||
sleep 1
|
sleep 1
|
||||||
sort ans2/query.log >ans2/query.log.sorted
|
sort ans2/query.log >ans2/query.log.sorted
|
||||||
cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1
|
cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1
|
||||||
|
ADDR ns.a.b.stale.
|
||||||
ADDR ns.b.stale.
|
ADDR ns.b.stale.
|
||||||
ADDR ns2.stale.
|
ADDR ns2.stale.
|
||||||
NS b.stale.
|
NS b.stale.
|
||||||
@@ -527,7 +545,9 @@ __EOF
|
|||||||
test -f ans3/query.log && ret=1
|
test -f ans3/query.log && ret=1
|
||||||
sort ans4/query.log >ans4/query.log.sorted
|
sort ans4/query.log >ans4/query.log.sorted
|
||||||
cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1
|
cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1
|
||||||
|
ADDR ns.a.b.stale.
|
||||||
ADDR ns.b.stale.
|
ADDR ns.b.stale.
|
||||||
|
NS a.b.stale.
|
||||||
NS b.stale.
|
NS b.stale.
|
||||||
TXT a.b.stale.
|
TXT a.b.stale.
|
||||||
__EOF
|
__EOF
|
||||||
@@ -546,6 +566,7 @@ grep "a\.b\.stale\..*1.*IN.*TXT.*hooray" dig.out.test$n >/dev/null || ret=1
|
|||||||
sleep 1
|
sleep 1
|
||||||
sort ans2/query.log >ans2/query.log.sorted
|
sort ans2/query.log >ans2/query.log.sorted
|
||||||
cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1
|
cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1
|
||||||
|
ADDR ns.a.b.stale.
|
||||||
ADDR ns.b.stale.
|
ADDR ns.b.stale.
|
||||||
ADDR ns2.stale.
|
ADDR ns2.stale.
|
||||||
NS b.stale.
|
NS b.stale.
|
||||||
@@ -553,7 +574,9 @@ __EOF
|
|||||||
test -f ans3/query.log && ret=1
|
test -f ans3/query.log && ret=1
|
||||||
sort ans4/query.log >ans4/query.log.sorted
|
sort ans4/query.log >ans4/query.log.sorted
|
||||||
cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1
|
cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1
|
||||||
|
ADDR ns.a.b.stale.
|
||||||
ADDR ns.b.stale.
|
ADDR ns.b.stale.
|
||||||
|
NS a.b.stale.
|
||||||
TXT a.b.stale.
|
TXT a.b.stale.
|
||||||
__EOF
|
__EOF
|
||||||
for ans in ans2 ans3 ans4; do mv -f $ans/query.log query-$ans-$n.log 2>/dev/null || true; done
|
for ans in ans2 ans3 ans4; do mv -f $ans/query.log query-$ans-$n.log 2>/dev/null || true; done
|
||||||
|
|||||||
@@ -9,9 +9,9 @@
|
|||||||
; See the COPYRIGHT file distributed with this work for additional
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
; information regarding copyright ownership.
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
$TTL 60
|
$TTL 120
|
||||||
|
|
||||||
big. IN SOA ns.big. hostmaster.ns.big. 1 0 0 0 60
|
big. IN SOA ns.big. hostmaster.ns.big. 1 0 0 0 120
|
||||||
big. IN NS ns.big.
|
big. IN NS ns.big.
|
||||||
ns.big. IN A 10.53.0.1
|
ns.big. IN A 10.53.0.1
|
||||||
|
|
||||||
|
|||||||
@@ -280,11 +280,11 @@ echo_i "checking that priority names under the max-types-per-name limit get cach
|
|||||||
|
|
||||||
# Query for NXDOMAIN for items on our priority list - these should get cached
|
# Query for NXDOMAIN for items on our priority list - these should get cached
|
||||||
for rrtype in AAAA MX NS; do
|
for rrtype in AAAA MX NS; do
|
||||||
check_manytypes 1 manytypes.big "${rrtype}" NOERROR big SOA 60 || ret=1
|
check_manytypes 1 manytypes.big "${rrtype}" NOERROR big SOA 120 || ret=1
|
||||||
done
|
done
|
||||||
# Wait at least 1 second
|
# Wait at least 1 second
|
||||||
for rrtype in AAAA MX NS; do
|
for rrtype in AAAA MX NS; do
|
||||||
check_manytypes 2 manytypes.big "${rrtype}" NOERROR big SOA "" 60 || ret=1
|
check_manytypes 2 manytypes.big "${rrtype}" NOERROR big SOA "" 120 || ret=1
|
||||||
done
|
done
|
||||||
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
@@ -299,13 +299,13 @@ echo_i "checking that NXDOMAIN names under the max-types-per-name limit get cach
|
|||||||
|
|
||||||
# Query for 10 NXDOMAIN types
|
# Query for 10 NXDOMAIN types
|
||||||
for ntype in $(seq 65270 65279); do
|
for ntype in $(seq 65270 65279); do
|
||||||
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR big SOA 60 || ret=1
|
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR big SOA 120 || ret=1
|
||||||
done
|
done
|
||||||
# Wait at least 1 second
|
# Wait at least 1 second
|
||||||
sleep 1
|
sleep 1
|
||||||
# Query for 10 NXDOMAIN types again - these should be cached
|
# Query for 10 NXDOMAIN types again - these should be cached
|
||||||
for ntype in $(seq 65270 65279); do
|
for ntype in $(seq 65270 65279); do
|
||||||
check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR big SOA "" 60 || ret=1
|
check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR big SOA "" 120 || ret=1
|
||||||
done
|
done
|
||||||
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
@@ -318,13 +318,13 @@ echo_i "checking that existing names under the max-types-per-name limit get cach
|
|||||||
|
|
||||||
# Limited to 10 types - these should be cached and the previous record should be evicted
|
# Limited to 10 types - these should be cached and the previous record should be evicted
|
||||||
for ntype in $(seq 65280 65289); do
|
for ntype in $(seq 65280 65289); do
|
||||||
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 60 || ret=1
|
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 120 || ret=1
|
||||||
done
|
done
|
||||||
# Wait at least one second
|
# Wait at least one second
|
||||||
sleep 1
|
sleep 1
|
||||||
# Limited to 10 types - these should be cached
|
# Limited to 10 types - these should be cached
|
||||||
for ntype in $(seq 65280 65289); do
|
for ntype in $(seq 65280 65289); do
|
||||||
check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" "" 60 || ret=1
|
check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" "" 120 || ret=1
|
||||||
done
|
done
|
||||||
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
@@ -356,11 +356,11 @@ echo_i "checking that priority NXDOMAIN names over the max-types-per-name limit
|
|||||||
|
|
||||||
# Query for NXDOMAIN for items on our priority list - these should get cached
|
# Query for NXDOMAIN for items on our priority list - these should get cached
|
||||||
for rrtype in AAAA MX NS; do
|
for rrtype in AAAA MX NS; do
|
||||||
check_manytypes 1 manytypes.big "${rrtype}" NOERROR big SOA 60 || ret=1
|
check_manytypes 1 manytypes.big "${rrtype}" NOERROR big SOA 120 || ret=1
|
||||||
done
|
done
|
||||||
# Wait at least 1 second
|
# Wait at least 1 second
|
||||||
for rrtype in AAAA MX NS; do
|
for rrtype in AAAA MX NS; do
|
||||||
check_manytypes 2 manytypes.big "${rrtype}" NOERROR big SOA "" 60 || ret=1
|
check_manytypes 2 manytypes.big "${rrtype}" NOERROR big SOA "" 120 || ret=1
|
||||||
done
|
done
|
||||||
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
@@ -372,11 +372,11 @@ ret=0
|
|||||||
echo_i "checking that priority name over the max-types-per-name get cached ($n)"
|
echo_i "checking that priority name over the max-types-per-name get cached ($n)"
|
||||||
|
|
||||||
# Query for an item on our priority list - it should get cached
|
# Query for an item on our priority list - it should get cached
|
||||||
check_manytypes 1 manytypes.big "A" NOERROR manytypes.big A 60 || ret=1
|
check_manytypes 1 manytypes.big "A" NOERROR manytypes.big A 120 || ret=1
|
||||||
# Wait at least 1 second
|
# Wait at least 1 second
|
||||||
sleep 1
|
sleep 1
|
||||||
# Query the same name again - it should be in the cache
|
# Query the same name again - it should be in the cache
|
||||||
check_manytypes 2 manytypes.big "A" NOERROR big manytypes.A "" 60 || ret=1
|
check_manytypes 2 manytypes.big "A" NOERROR big manytypes.A "" 120 || ret=1
|
||||||
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
@@ -389,7 +389,7 @@ ret=0
|
|||||||
echo_i "checking that priority name over the max-types-per-name don't get evicted ($n)"
|
echo_i "checking that priority name over the max-types-per-name don't get evicted ($n)"
|
||||||
|
|
||||||
# Query for an item on our priority list - it should get cached
|
# Query for an item on our priority list - it should get cached
|
||||||
check_manytypes 1 manytypes.big "A" NOERROR manytypes.big A 60 || ret=1
|
check_manytypes 1 manytypes.big "A" NOERROR manytypes.big A 120 || ret=1
|
||||||
# Query for 10 more types - this should not evict A record
|
# Query for 10 more types - this should not evict A record
|
||||||
for ntype in $(seq 65280 65289); do
|
for ntype in $(seq 65280 65289); do
|
||||||
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big || ret=1
|
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big || ret=1
|
||||||
@@ -397,9 +397,9 @@ done
|
|||||||
# Wait at least 1 second
|
# Wait at least 1 second
|
||||||
sleep 1
|
sleep 1
|
||||||
# Query the same name again - it should be in the cache
|
# Query the same name again - it should be in the cache
|
||||||
check_manytypes 2 manytypes.big "A" NOERROR manytypes.big A "" 60 || ret=1
|
check_manytypes 2 manytypes.big "A" NOERROR manytypes.big A "" 120 || ret=1
|
||||||
# This one was first in the list and should have been evicted
|
# This one was first in the list and should have been evicted
|
||||||
check_manytypes 2 manytypes.big "TYPE65280" NOERROR manytypes.big TYPE65280 60 || ret=1
|
check_manytypes 2 manytypes.big "TYPE65280" NOERROR manytypes.big TYPE65280 120 || ret=1
|
||||||
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
@@ -413,21 +413,21 @@ echo_i "checking that non-priority types cause eviction ($n)"
|
|||||||
|
|
||||||
# Everything on top of that will cause the cache eviction
|
# Everything on top of that will cause the cache eviction
|
||||||
for ntype in $(seq 65280 65299); do
|
for ntype in $(seq 65280 65299); do
|
||||||
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 60 || ret=1
|
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 120 || ret=1
|
||||||
done
|
done
|
||||||
# Wait at least one second
|
# Wait at least one second
|
||||||
sleep 1
|
sleep 1
|
||||||
# These should have TTL != 60 now
|
# These should have TTL != 120 now
|
||||||
for ntype in $(seq 65290 65299); do
|
for ntype in $(seq 65290 65299); do
|
||||||
check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" "" 60 || ret=1
|
check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" "" 120 || ret=1
|
||||||
done
|
done
|
||||||
# These should have been evicted
|
# These should have been evicted
|
||||||
for ntype in $(seq 65280 65289); do
|
for ntype in $(seq 65280 65289); do
|
||||||
check_manytypes 3 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 60 || ret=1
|
check_manytypes 3 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 120 || ret=1
|
||||||
done
|
done
|
||||||
# These should have been evicted by the previous block
|
# These should have been evicted by the previous block
|
||||||
for ntype in $(seq 65290 65299); do
|
for ntype in $(seq 65290 65299); do
|
||||||
check_manytypes 4 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 60 || ret=1
|
check_manytypes 4 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 120 || ret=1
|
||||||
done
|
done
|
||||||
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
@@ -442,25 +442,25 @@ echo_i "checking that signed names under the max-types-per-name limit get cached
|
|||||||
|
|
||||||
# Go through the 10 items, this should result in 20 items (type + rrsig(type))
|
# Go through the 10 items, this should result in 20 items (type + rrsig(type))
|
||||||
for ntype in $(seq 65280 65289); do
|
for ntype in $(seq 65280 65289); do
|
||||||
check_manytypes 1 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" 60 || ret=1
|
check_manytypes 1 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" 120 || ret=1
|
||||||
done
|
done
|
||||||
|
|
||||||
# Wait at least one second
|
# Wait at least one second
|
||||||
sleep 1
|
sleep 1
|
||||||
|
|
||||||
# These should have TTL != 60 now
|
# These should have TTL != 120 now
|
||||||
for ntype in $(seq 65285 65289); do
|
for ntype in $(seq 65285 65289); do
|
||||||
check_manytypes 2 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" "" 60 || ret=1
|
check_manytypes 2 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" "" 120 || ret=1
|
||||||
done
|
done
|
||||||
|
|
||||||
# These should have been evicted
|
# These should have been evicted
|
||||||
for ntype in $(seq 65280 65284); do
|
for ntype in $(seq 65280 65284); do
|
||||||
check_manytypes 3 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" 60 || ret=1
|
check_manytypes 3 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" 120 || ret=1
|
||||||
done
|
done
|
||||||
|
|
||||||
# These should have been evicted by the previous block
|
# These should have been evicted by the previous block
|
||||||
for ntype in $(seq 65285 65289); do
|
for ntype in $(seq 65285 65289); do
|
||||||
check_manytypes 4 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" 60 || ret=1
|
check_manytypes 4 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" 120 || ret=1
|
||||||
done
|
done
|
||||||
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
@@ -475,12 +475,12 @@ echo_i "checking that lifting the limit will allow everything to get cached ($n)
|
|||||||
ns3_reset ns3/named6.conf.in
|
ns3_reset ns3/named6.conf.in
|
||||||
|
|
||||||
for ntype in $(seq 65280 65534); do
|
for ntype in $(seq 65280 65534); do
|
||||||
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 60 || ret=1
|
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 120 || ret=1
|
||||||
done
|
done
|
||||||
# Wait at least one second
|
# Wait at least one second
|
||||||
sleep 1
|
sleep 1
|
||||||
for ntype in $(seq 65280 65534); do
|
for ntype in $(seq 65280 65534); do
|
||||||
check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" "" 60 || ret=1
|
check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" "" 120 || ret=1
|
||||||
done
|
done
|
||||||
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
|
|||||||
@@ -4,37 +4,21 @@
|
|||||||
* SPDX-License-Identifier: MPL-2.0
|
* SPDX-License-Identifier: MPL-2.0
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
*
|
*
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
* information regarding copyright ownership.
|
* information regarding copyright ownership.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#pragma once
|
options {
|
||||||
|
query-source address 10.53.0.11;
|
||||||
/*****
|
notify-source 10.53.0.11;
|
||||||
***** Module Info
|
transfer-source 10.53.0.11;
|
||||||
*****/
|
port @PORT@;
|
||||||
|
pid-file "named.pid";
|
||||||
/***
|
listen-on { 10.53.0.11; };
|
||||||
*** Imports
|
listen-on-v6 { none; };
|
||||||
***/
|
recursion no;
|
||||||
|
dnssec-validation no;
|
||||||
#include <isc/types.h>
|
};
|
||||||
|
|
||||||
/***
|
|
||||||
*** Functions
|
|
||||||
***/
|
|
||||||
|
|
||||||
bool
|
|
||||||
isc_fips_mode(void);
|
|
||||||
/*
|
|
||||||
* Return if FIPS mode is currently enabled or not
|
|
||||||
*/
|
|
||||||
|
|
||||||
isc_result_t
|
|
||||||
isc_fips_set_mode(int mode);
|
|
||||||
/*
|
|
||||||
* Enable FIPS mode.
|
|
||||||
*/
|
|
||||||
@@ -24,5 +24,6 @@ copy_setports ns5/named.conf.in ns5/named.conf
|
|||||||
copy_setports ns6/named.conf.in ns6/named.conf
|
copy_setports ns6/named.conf.in ns6/named.conf
|
||||||
copy_setports ns7/named1.conf.in ns7/named.conf
|
copy_setports ns7/named1.conf.in ns7/named.conf
|
||||||
copy_setports ns9/named.conf.in ns9/named.conf
|
copy_setports ns9/named.conf.in ns9/named.conf
|
||||||
|
copy_setports ns11/named.conf.in ns11/named.conf
|
||||||
|
|
||||||
(cd ns6 && $SHELL keygen.sh)
|
(cd ns6 && $SHELL keygen.sh)
|
||||||
|
|||||||
@@ -729,10 +729,10 @@ if ${FEATURETEST} --enable-querytrace; then
|
|||||||
grep "status: SERVFAIL" dig.ns5.out.${n} >/dev/null || ret=1
|
grep "status: SERVFAIL" dig.ns5.out.${n} >/dev/null || ret=1
|
||||||
check_namedrun() {
|
check_namedrun() {
|
||||||
nextpartpeek ns5/named.run >nextpart.out.${n}
|
nextpartpeek ns5/named.run >nextpart.out.${n}
|
||||||
grep 'resolving tcpalso.no-questions/A for [^:]*: empty question section, accepting it anyway as TC=1' nextpart.out.${n} >/dev/null || return 1
|
grep 'resolving tcpalso.no-questions/NS for [^:]*: empty question section, accepting it anyway as TC=1' nextpart.out.${n} >/dev/null || return 1
|
||||||
grep '(tcpalso.no-questions/A): connecting via TCP' nextpart.out.${n} >/dev/null || return 1
|
grep '(tcpalso.no-questions/NS): connecting via TCP' nextpart.out.${n} >/dev/null || return 1
|
||||||
grep 'resolving tcpalso.no-questions/A for [^:]*: empty question section$' nextpart.out.${n} >/dev/null || return 1
|
grep 'resolving tcpalso.no-questions/NS for [^:]*: empty question section$' nextpart.out.${n} >/dev/null || return 1
|
||||||
grep '(tcpalso.no-questions/A): nextitem' nextpart.out.${n} >/dev/null || return 1
|
grep '(tcpalso.no-questions/NS): nextitem' nextpart.out.${n} >/dev/null || return 1
|
||||||
return 0
|
return 0
|
||||||
}
|
}
|
||||||
retry_quiet 12 check_namedrun || ret=1
|
retry_quiet 12 check_namedrun || ret=1
|
||||||
@@ -1015,5 +1015,14 @@ ttl=$(awk '{print $2}' dig.ns1.out.${n})
|
|||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|
||||||
|
n=$((n + 1))
|
||||||
|
echo_i "client requests recursion but it is disabled - expect EDE 20 code with REFUSED($n)"
|
||||||
|
ret=0
|
||||||
|
dig_with_opts +recurse www.isc.org @10.53.0.11 a >dig.out.ns11.test${n} || ret=1
|
||||||
|
grep "status: REFUSED" dig.out.ns11.test${n} >/dev/null || ret=1
|
||||||
|
grep -F "EDE: 20 (Not Authoritative)" dig.out.ns11.test${n} >/dev/null || ret=1
|
||||||
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
|
status=$((status + ret))
|
||||||
|
|
||||||
echo_i "exit status: $status"
|
echo_i "exit status: $status"
|
||||||
[ $status -eq 0 ] || exit 1
|
[ $status -eq 0 ] || exit 1
|
||||||
|
|||||||
@@ -102,6 +102,23 @@ def test_rpz_passthru_logging():
|
|||||||
dns.rrset.from_text("allowed.", 300, "IN", "A", "10.53.0.2")
|
dns.rrset.from_text("allowed.", 300, "IN", "A", "10.53.0.2")
|
||||||
]
|
]
|
||||||
|
|
||||||
|
# Should also generate a log entry into rpz_passthru.txt
|
||||||
|
msg_allowed_any = dns.message.make_query("allowed.", "ANY")
|
||||||
|
res_allowed_any = isctest.query.udp(
|
||||||
|
msg_allowed_any,
|
||||||
|
resolver_ip,
|
||||||
|
source="10.53.0.1",
|
||||||
|
expected_rcode=dns.rcode.NOERROR,
|
||||||
|
)
|
||||||
|
assert res_allowed_any.answer == [
|
||||||
|
dns.rrset.from_text("allowed.", 300, "IN", "A", "10.53.0.2"),
|
||||||
|
dns.rrset.from_text("allowed.", 300, "IN", "NS", "ns1.allowed."),
|
||||||
|
]
|
||||||
|
# The comparison above doesn't compare the TTL values, and we want to
|
||||||
|
# make sure that the "passthru" rpz doesn't cap the TTL with max-policy-ttl.
|
||||||
|
assert res_allowed_any.answer[0].ttl > 200
|
||||||
|
assert res_allowed_any.answer[1].ttl > 200
|
||||||
|
|
||||||
# baddomain.com isn't allowed (CNAME .), should return NXDOMAIN
|
# baddomain.com isn't allowed (CNAME .), should return NXDOMAIN
|
||||||
# Should generate a log entry into rpz.txt
|
# Should generate a log entry into rpz.txt
|
||||||
msg_not_allowed = dns.message.make_query("baddomain.", "A")
|
msg_not_allowed = dns.message.make_query("baddomain.", "A")
|
||||||
|
|||||||
@@ -140,7 +140,7 @@ main(int argc, char **argv) {
|
|||||||
printf("%s\n", filename);
|
printf("%s\n", filename);
|
||||||
dst_key_free(&key);
|
dst_key_free(&key);
|
||||||
|
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -115,10 +115,12 @@ sleep 2
|
|||||||
# stale for somewhere between 3500-3599 seconds.
|
# stale for somewhere between 3500-3599 seconds.
|
||||||
echo_i "check rndc dump stale data.example ($n)"
|
echo_i "check rndc dump stale data.example ($n)"
|
||||||
rndc_dumpdb ns1 || ret=1
|
rndc_dumpdb ns1 || ret=1
|
||||||
awk '/; stale since [0-9]*/ { x=$0; getline; print x, $0}' ns1/named_dump.db.test$n \
|
# add in inherited owner names
|
||||||
|
awk '$1 ~ /^[0-9][0-9]*$/ { $0 = last " " $0 } $1 != ";" { last = $1 } { print }' ns1/named_dump.db.test$n >named_dump.db.test$n
|
||||||
|
awk '/; stale since [0-9]*/ { x=$0; getline; print x, $0}' named_dump.db.test$n \
|
||||||
| grep "; stale since [0-9]* data\.example.*3[56]...*TXT.*A text record with a 2 second ttl" >/dev/null 2>&1 || ret=1
|
| grep "; stale since [0-9]* data\.example.*3[56]...*TXT.*A text record with a 2 second ttl" >/dev/null 2>&1 || ret=1
|
||||||
# Also make sure the not expired data does not have a stale comment.
|
# Also make sure the not expired data does not have a stale comment.
|
||||||
awk '/; authanswer/ { x=$0; getline; print x, $0}' ns1/named_dump.db.test$n \
|
awk '/; authanswer/ { x=$0; getline; print x, $0}' named_dump.db.test$n \
|
||||||
| grep "; authanswer longttl\.example.*[56]...*TXT.*A text record with a 600 second ttl" >/dev/null 2>&1 || ret=1
|
| grep "; authanswer longttl\.example.*[56]...*TXT.*A text record with a 600 second ttl" >/dev/null 2>&1 || ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
@@ -1664,16 +1666,15 @@ status=$((status + ret))
|
|||||||
# Check that expired records are dumped.
|
# Check that expired records are dumped.
|
||||||
echo_i "check rndc dump expired data.example ($n)"
|
echo_i "check rndc dump expired data.example ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
awk '/; expired/ { x=$0; getline; print x, $0}' ns5/named_dump.db.test$n \
|
# add in inherited owner names
|
||||||
| grep "; expired (awaiting cleanup) data\.example\..*A text record with a 2 second ttl" >/dev/null 2>&1 || ret=1
|
awk '$1 ~ /^[0-9][0-9]*$/ { $0 = last " " $0 } $1 != ";" { last = $1 } { print }' ns5/named_dump.db.test$n >named_dump.db.test$n
|
||||||
awk '/; expired/ { x=$0; getline; print x, $0}' ns5/named_dump.db.test$n \
|
# extract expired records
|
||||||
| grep "; expired (awaiting cleanup) nodata\.example\." >/dev/null 2>&1 || ret=1
|
awk '/; expired/ { x=$0; getline; print x, $0}' named_dump.db.test$n >expired.test$n
|
||||||
awk '/; expired/ { x=$0; getline; print x, $0}' ns5/named_dump.db.test$n \
|
grep "; expired (awaiting cleanup) data\.example\..*A text record with a 2 second ttl" expired.test$n >/dev/null 2>&1 || ret=1
|
||||||
| grep "; expired (awaiting cleanup) nxdomain\.example\." >/dev/null 2>&1 || ret=1
|
grep "; expired (awaiting cleanup) nodata\.example\." expired.test$n >/dev/null 2>&1 || ret=1
|
||||||
awk '/; expired/ { x=$0; getline; print x, $0}' ns5/named_dump.db.test$n \
|
grep "; expired (awaiting cleanup) nxdomain\.example\." expired.test$n >/dev/null 2>&1 || ret=1
|
||||||
| grep "; expired (awaiting cleanup) othertype\.example\." >/dev/null 2>&1 || ret=1
|
|
||||||
# Also make sure the not expired data does not have an expired comment.
|
# Also make sure the not expired data does not have an expired comment.
|
||||||
awk '/; authanswer/ { x=$0; getline; print x, $0}' ns5/named_dump.db.test$n \
|
awk '/; authanswer/ { x=$0; getline; print x, $0}' named_dump.db.test$n \
|
||||||
| grep "; authanswer longttl\.example.*A text record with a 600 second ttl" >/dev/null 2>&1 || ret=1
|
| grep "; authanswer longttl\.example.*A text record with a 600 second ttl" >/dev/null 2>&1 || ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|||||||
@@ -14,6 +14,8 @@ import pytest
|
|||||||
pytestmark = pytest.mark.extra_artifacts(
|
pytestmark = pytest.mark.extra_artifacts(
|
||||||
[
|
[
|
||||||
"dig.out.*",
|
"dig.out.*",
|
||||||
|
"expired.test*",
|
||||||
|
"named_dump.db.test*",
|
||||||
"rndc.out.*",
|
"rndc.out.*",
|
||||||
"ans*/ans.run",
|
"ans*/ans.run",
|
||||||
"ns*/named.stats*",
|
"ns*/named.stats*",
|
||||||
|
|||||||
@@ -234,7 +234,7 @@ sub construct_ns_command {
|
|||||||
$command = "taskset $taskset $NAMED ";
|
$command = "taskset $taskset $NAMED ";
|
||||||
} elsif ($ENV{'USE_RR'}) {
|
} elsif ($ENV{'USE_RR'}) {
|
||||||
$ENV{'_RR_TRACE_DIR'} = ".";
|
$ENV{'_RR_TRACE_DIR'} = ".";
|
||||||
$command = "rr record --chaos $NAMED ";
|
$command = "$ENV{'TOP_BUILDDIR'}/libtool --mode=execute rr record --chaos $NAMED ";
|
||||||
} else {
|
} else {
|
||||||
$command = "$NAMED ";
|
$command = "$NAMED ";
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -414,10 +414,10 @@ for ns in 2 4 5 6; do
|
|||||||
check_status NOERROR dig.out.ns${ns}.test$n || ret=1
|
check_status NOERROR dig.out.ns${ns}.test$n || ret=1
|
||||||
if [ ${synth} = yes ]; then
|
if [ ${synth} = yes ]; then
|
||||||
check_synth_cname b.wild-cname.example. dig.out.ns${ns}.test$n || ret=1
|
check_synth_cname b.wild-cname.example. dig.out.ns${ns}.test$n || ret=1
|
||||||
nextpart ns1/named.run | grep b.wild-cname.example/A >/dev/null && ret=1
|
nextpart ns1/named.run | grep b.wild-cname.example/NS >/dev/null && ret=1
|
||||||
else
|
else
|
||||||
check_nosynth_cname b.wild-cname.example. dig.out.ns${ns}.test$n || ret=1
|
check_nosynth_cname b.wild-cname.example. dig.out.ns${ns}.test$n || ret=1
|
||||||
nextpart ns1/named.run | grep b.wild-cname.example/A >/dev/null || ret=1
|
nextpart ns1/named.run | grep b.wild-cname.example/NS >/dev/null || ret=1
|
||||||
fi
|
fi
|
||||||
grep "ns1.example.*.IN.A" dig.out.ns${ns}.test$n >/dev/null || ret=1
|
grep "ns1.example.*.IN.A" dig.out.ns${ns}.test$n >/dev/null || ret=1
|
||||||
digcomp wildcname.out dig.out.ns${ns}.test$n || ret=1
|
digcomp wildcname.out dig.out.ns${ns}.test$n || ret=1
|
||||||
@@ -470,6 +470,7 @@ for ns in 2 4 5 6; do
|
|||||||
check_nosynth_aaaa b.wild-2-nsec-afterdata.example. dig.out.a.ns${ns}.test$n || ret=1
|
check_nosynth_aaaa b.wild-2-nsec-afterdata.example. dig.out.a.ns${ns}.test$n || ret=1
|
||||||
#
|
#
|
||||||
nextpart ns1/named.run >/dev/null
|
nextpart ns1/named.run >/dev/null
|
||||||
|
sleep 1
|
||||||
dig_with_opts b.wild-2-nsec-afterdata.example. @10.53.0.${ns} TLSA >dig.out.ns${ns}.test$n || ret=1
|
dig_with_opts b.wild-2-nsec-afterdata.example. @10.53.0.${ns} TLSA >dig.out.ns${ns}.test$n || ret=1
|
||||||
check_ad_flag $ad dig.out.ns${ns}.test$n || ret=1
|
check_ad_flag $ad dig.out.ns${ns}.test$n || ret=1
|
||||||
check_status NOERROR dig.out.ns${ns}.test$n || ret=1
|
check_status NOERROR dig.out.ns${ns}.test$n || ret=1
|
||||||
@@ -531,7 +532,7 @@ for ns in 2 4 5 6; do
|
|||||||
check_ad_flag no dig.out.ns${ns}.test$n || ret=1
|
check_ad_flag no dig.out.ns${ns}.test$n || ret=1
|
||||||
check_status NOERROR dig.out.ns${ns}.test$n || ret=1
|
check_status NOERROR dig.out.ns${ns}.test$n || ret=1
|
||||||
check_nosynth_cname b.wild-cname.insecure.example dig.out.ns${ns}.test$n || ret=1
|
check_nosynth_cname b.wild-cname.insecure.example dig.out.ns${ns}.test$n || ret=1
|
||||||
nextpart ns1/named.run | grep b.wild-cname.insecure.example/A >/dev/null || ret=1
|
nextpart ns1/named.run | grep b.wild-cname.insecure.example/NS >/dev/null || ret=1
|
||||||
grep "ns1.insecure.example.*.IN.A" dig.out.ns${ns}.test$n >/dev/null || ret=1
|
grep "ns1.insecure.example.*.IN.A" dig.out.ns${ns}.test$n >/dev/null || ret=1
|
||||||
digcomp insecure.wildcname.out dig.out.ns${ns}.test$n || ret=1
|
digcomp insecure.wildcname.out dig.out.ns${ns}.test$n || ret=1
|
||||||
n=$((n + 1))
|
n=$((n + 1))
|
||||||
|
|||||||
@@ -260,7 +260,7 @@ main(int argc, char *argv[]) {
|
|||||||
if (printmemstats) {
|
if (printmemstats) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
|
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -425,7 +425,7 @@ cleanup:
|
|||||||
if (message != NULL) {
|
if (message != NULL) {
|
||||||
dns_message_detach(&message);
|
dns_message_detach(&message);
|
||||||
}
|
}
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
|
|
||||||
exit(rv);
|
exit(rv);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -61,7 +61,7 @@ cleanup(void) {
|
|||||||
isc_lex_destroy(&lex);
|
isc_lex_destroy(&lex);
|
||||||
}
|
}
|
||||||
if (mctx != NULL) {
|
if (mctx != NULL) {
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+1
-26
@@ -16,7 +16,7 @@
|
|||||||
#
|
#
|
||||||
m4_define([bind_VERSION_MAJOR], 9)dnl
|
m4_define([bind_VERSION_MAJOR], 9)dnl
|
||||||
m4_define([bind_VERSION_MINOR], 21)dnl
|
m4_define([bind_VERSION_MINOR], 21)dnl
|
||||||
m4_define([bind_VERSION_PATCH], 6)dnl
|
m4_define([bind_VERSION_PATCH], 7)dnl
|
||||||
m4_define([bind_VERSION_EXTRA], -dev)dnl
|
m4_define([bind_VERSION_EXTRA], -dev)dnl
|
||||||
m4_define([bind_DESCRIPTION], [(Development Release)])dnl
|
m4_define([bind_DESCRIPTION], [(Development Release)])dnl
|
||||||
m4_define([bind_SRCID], [m4_esyscmd_s([git rev-parse --short HEAD | cut -b1-7])])dnl
|
m4_define([bind_SRCID], [m4_esyscmd_s([git rev-parse --short HEAD | cut -b1-7])])dnl
|
||||||
@@ -886,31 +886,6 @@ AC_CHECK_HEADERS([execinfo.h],
|
|||||||
[AC_SEARCH_LIBS([backtrace_symbols], [execinfo],
|
[AC_SEARCH_LIBS([backtrace_symbols], [execinfo],
|
||||||
[AC_CHECK_FUNCS([backtrace_symbols])])])
|
[AC_CHECK_FUNCS([backtrace_symbols])])])
|
||||||
|
|
||||||
#
|
|
||||||
# We do the IPv6 compilation checking after libtool so that we can put
|
|
||||||
# the right suffix on the files.
|
|
||||||
#
|
|
||||||
AC_MSG_CHECKING([for IPv6 structures])
|
|
||||||
AC_COMPILE_IFELSE(
|
|
||||||
[AC_LANG_PROGRAM(
|
|
||||||
[[
|
|
||||||
#include <sys/types.h>
|
|
||||||
#include <sys/socket.h>
|
|
||||||
#include <netinet/in.h>
|
|
||||||
]],
|
|
||||||
[[
|
|
||||||
struct sockaddr_in6 sin6;
|
|
||||||
struct in6_addr in6;
|
|
||||||
struct in6_pktinfo in6_pi;
|
|
||||||
struct sockaddr_storage storage;
|
|
||||||
in6 = in6addr_any;
|
|
||||||
in6 = in6addr_loopback;
|
|
||||||
sin6.sin6_scope_id = 0;
|
|
||||||
return (0);
|
|
||||||
]])],
|
|
||||||
[AC_MSG_RESULT([yes])],
|
|
||||||
[AC_MSG_FAILURE([IPv6 support is mandatory])])
|
|
||||||
|
|
||||||
#
|
#
|
||||||
# Allow forcibly disabling TCP Fast Open support as autodetection might yield
|
# Allow forcibly disabling TCP Fast Open support as autodetection might yield
|
||||||
# confusing results on some systems (e.g. FreeBSD; see set_tcp_fastopen()
|
# confusing results on some systems (e.g. FreeBSD; see set_tcp_fastopen()
|
||||||
|
|||||||
@@ -3660,9 +3660,13 @@ system.
|
|||||||
after 20 minutes if it has remained unchanged.
|
after 20 minutes if it has remained unchanged.
|
||||||
|
|
||||||
If :any:`max-clients-per-query` is set to zero, there is no upper bound, other
|
If :any:`max-clients-per-query` is set to zero, there is no upper bound, other
|
||||||
than that imposed by :any:`recursive-clients`. If :any:`clients-per-query` is
|
than that imposed by :any:`recursive-clients`. If the option is set to a
|
||||||
set to zero, :any:`max-clients-per-query` no longer applies and there is no
|
lower value than :any:`clients-per-query`, the value is adjusted to
|
||||||
upper bound, other than that imposed by :any:`recursive-clients`.
|
:any:`clients-per-query`.
|
||||||
|
|
||||||
|
If :any:`clients-per-query` is set to zero, :any:`max-clients-per-query` no
|
||||||
|
longer applies and there is no upper bound, other than that imposed by
|
||||||
|
:any:`recursive-clients`.
|
||||||
|
|
||||||
.. namedconf:statement:: max-validations-per-fetch
|
.. namedconf:statement:: max-validations-per-fetch
|
||||||
:tags: server
|
:tags: server
|
||||||
|
|||||||
+1
-1
@@ -154,7 +154,7 @@ main(int argc, char **argv) {
|
|||||||
if (memstats) {
|
if (memstats) {
|
||||||
isc_mem_stats(mctx, stderr);
|
isc_mem_stats(mctx, stderr);
|
||||||
}
|
}
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
|
|
||||||
fflush(stdout);
|
fflush(stdout);
|
||||||
if (ferror(stdout)) {
|
if (ferror(stdout)) {
|
||||||
|
|||||||
@@ -74,6 +74,6 @@ LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
|
|||||||
|
|
||||||
end:
|
end:
|
||||||
dns_db_detach(&db);
|
dns_db_detach(&db);
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|||||||
+1
-1
@@ -211,7 +211,7 @@ LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
dns_qp_destroy(&qp);
|
dns_qp_destroy(&qp);
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
isc_mem_checkdestroyed(stderr);
|
isc_mem_checkdestroyed(stderr);
|
||||||
|
|
||||||
for (size_t i = 0; i < ARRAY_SIZE(item); i++) {
|
for (size_t i = 0; i < ARRAY_SIZE(item); i++) {
|
||||||
|
|||||||
@@ -145,6 +145,6 @@ LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
|
|||||||
cleanup:
|
cleanup:
|
||||||
isc_lex_close(lex);
|
isc_lex_close(lex);
|
||||||
isc_lex_destroy(&lex);
|
isc_lex_destroy(&lex);
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_detach(&mctx);
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|||||||
+2
-2
@@ -567,7 +567,7 @@ import_rdataset(dns_adbname_t *adbname, dns_rdataset_t *rdataset,
|
|||||||
rdataset->ttl = ttlclamp(rdataset->ttl);
|
rdataset->ttl = ttlclamp(rdataset->ttl);
|
||||||
}
|
}
|
||||||
|
|
||||||
REQUIRE(rdtype == dns_rdatatype_a || rdtype == dns_rdatatype_aaaa);
|
REQUIRE(dns_rdatatype_isaddr(rdtype));
|
||||||
|
|
||||||
for (result = dns_rdataset_first(rdataset); result == ISC_R_SUCCESS;
|
for (result = dns_rdataset_first(rdataset); result == ISC_R_SUCCESS;
|
||||||
result = dns_rdataset_next(rdataset))
|
result = dns_rdataset_next(rdataset))
|
||||||
@@ -2557,7 +2557,7 @@ dbfind_name(dns_adbname_t *adbname, isc_stdtime_t now, dns_rdatatype_t rdtype) {
|
|||||||
adb = adbname->adb;
|
adb = adbname->adb;
|
||||||
|
|
||||||
REQUIRE(DNS_ADB_VALID(adb));
|
REQUIRE(DNS_ADB_VALID(adb));
|
||||||
REQUIRE(rdtype == dns_rdatatype_a || rdtype == dns_rdatatype_aaaa);
|
REQUIRE(dns_rdatatype_isaddr(rdtype));
|
||||||
|
|
||||||
fname = dns_fixedname_initname(&foundname);
|
fname = dns_fixedname_initname(&foundname);
|
||||||
dns_rdataset_init(&rdataset);
|
dns_rdataset_init(&rdataset);
|
||||||
|
|||||||
+1
-2
@@ -1516,8 +1516,7 @@ catz_process_primaries(dns_catz_zone_t *catz, dns_ipkeylist_t *ipkl,
|
|||||||
}
|
}
|
||||||
/* else - 'simple' case - without labels */
|
/* else - 'simple' case - without labels */
|
||||||
|
|
||||||
if (value->type != dns_rdatatype_a && value->type != dns_rdatatype_aaaa)
|
if (!dns_rdatatype_isaddr(value->type)) {
|
||||||
{
|
|
||||||
return ISC_R_FAILURE;
|
return ISC_R_FAILURE;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+18
-12
@@ -1428,29 +1428,35 @@ addkey(dns_dnsseckeylist_t *keylist, dst_key_t **newkey, bool savekeys,
|
|||||||
|
|
||||||
if (key != NULL) {
|
if (key != NULL) {
|
||||||
/*
|
/*
|
||||||
* Found a match. If the old key was only public and the
|
* Found a match. If we already had a private key, then
|
||||||
* new key is private, replace the old one; otherwise
|
* the new key can't be an improvement. If the existing
|
||||||
* leave it. But either way, mark the key as having
|
* key was public-only but the new key is too, then it's
|
||||||
* been found in the zone.
|
* still not an improvement. Mark the old key as having
|
||||||
|
* been found in the zone and stop.
|
||||||
*/
|
*/
|
||||||
if (dst_key_isprivate(key->key)) {
|
if (dst_key_isprivate(key->key) || !dst_key_isprivate(*newkey))
|
||||||
dst_key_free(newkey);
|
{
|
||||||
} else if (dst_key_isprivate(*newkey)) {
|
key->source = dns_keysource_zoneapex;
|
||||||
dst_key_free(&key->key);
|
return;
|
||||||
key->key = *newkey;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
key->source = dns_keysource_zoneapex;
|
/*
|
||||||
return;
|
* However, if the old key was public-only, and the new key
|
||||||
|
* is private, then we're throwing away the old key.
|
||||||
|
*/
|
||||||
|
dst_key_free(&key->key);
|
||||||
|
ISC_LIST_UNLINK(*keylist, key, link);
|
||||||
|
dns_dnsseckey_destroy(mctx, &key);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/* Store the new key. */
|
||||||
dns_dnsseckey_create(mctx, newkey, &key);
|
dns_dnsseckey_create(mctx, newkey, &key);
|
||||||
|
key->source = dns_keysource_zoneapex;
|
||||||
key->pubkey = pubkey_only;
|
key->pubkey = pubkey_only;
|
||||||
if (key->legacy || savekeys) {
|
if (key->legacy || savekeys) {
|
||||||
key->force_publish = true;
|
key->force_publish = true;
|
||||||
key->force_sign = dst_key_isprivate(key->key);
|
key->force_sign = dst_key_isprivate(key->key);
|
||||||
}
|
}
|
||||||
key->source = dns_keysource_zoneapex;
|
|
||||||
ISC_LIST_APPEND(*keylist, key, link);
|
ISC_LIST_APPEND(*keylist, key, link);
|
||||||
*newkey = NULL;
|
*newkey = NULL;
|
||||||
}
|
}
|
||||||
|
|||||||
+2
-2
@@ -38,9 +38,9 @@
|
|||||||
#include <unistd.h>
|
#include <unistd.h>
|
||||||
|
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
|
#include <isc/crypto.h>
|
||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/fips.h>
|
|
||||||
#include <isc/lex.h>
|
#include <isc/lex.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/once.h>
|
#include <isc/once.h>
|
||||||
@@ -226,7 +226,7 @@ dst__lib_shutdown(void) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_mem_destroy(&dst__mctx);
|
isc_mem_detach(&dst__mctx);
|
||||||
}
|
}
|
||||||
|
|
||||||
bool
|
bool
|
||||||
|
|||||||
+8
-8
@@ -43,7 +43,7 @@ struct dyndb_implementation {
|
|||||||
dns_dyndb_destroy_t *destroy_func;
|
dns_dyndb_destroy_t *destroy_func;
|
||||||
char *name;
|
char *name;
|
||||||
void *inst;
|
void *inst;
|
||||||
LINK(dyndb_implementation_t) link;
|
ISC_LINK(dyndb_implementation_t) link;
|
||||||
};
|
};
|
||||||
|
|
||||||
/*
|
/*
|
||||||
@@ -52,7 +52,7 @@ struct dyndb_implementation {
|
|||||||
* These are stored here so they can be cleaned up on shutdown.
|
* These are stored here so they can be cleaned up on shutdown.
|
||||||
* (The order in which they are stored is not important.)
|
* (The order in which they are stored is not important.)
|
||||||
*/
|
*/
|
||||||
static LIST(dyndb_implementation_t) dyndb_implementations;
|
static ISC_LIST(dyndb_implementation_t) dyndb_implementations;
|
||||||
|
|
||||||
/* Locks dyndb_implementations. */
|
/* Locks dyndb_implementations. */
|
||||||
static isc_mutex_t dyndb_lock;
|
static isc_mutex_t dyndb_lock;
|
||||||
@@ -60,7 +60,7 @@ static isc_mutex_t dyndb_lock;
|
|||||||
void
|
void
|
||||||
dns__dyndb_initialize(void) {
|
dns__dyndb_initialize(void) {
|
||||||
isc_mutex_init(&dyndb_lock);
|
isc_mutex_init(&dyndb_lock);
|
||||||
INIT_LIST(dyndb_implementations);
|
ISC_LIST_INIT(dyndb_implementations);
|
||||||
}
|
}
|
||||||
|
|
||||||
void
|
void
|
||||||
@@ -135,7 +135,7 @@ load_library(isc_mem_t *mctx, const char *filename, const char *instname,
|
|||||||
|
|
||||||
isc_mem_attach(mctx, &imp->mctx);
|
isc_mem_attach(mctx, &imp->mctx);
|
||||||
|
|
||||||
INIT_LINK(imp, link);
|
ISC_LINK_INIT(imp, link);
|
||||||
|
|
||||||
r = uv_dlopen(filename, &imp->handle);
|
r = uv_dlopen(filename, &imp->handle);
|
||||||
if (r != 0) {
|
if (r != 0) {
|
||||||
@@ -225,7 +225,7 @@ dns_dyndb_load(const char *libname, const char *name, const char *parameters,
|
|||||||
CHECK(implementation->register_func(mctx, name, parameters, file, line,
|
CHECK(implementation->register_func(mctx, name, parameters, file, line,
|
||||||
dctx, &implementation->inst));
|
dctx, &implementation->inst));
|
||||||
|
|
||||||
APPEND(dyndb_implementations, implementation, link);
|
ISC_LIST_APPEND(dyndb_implementations, implementation, link);
|
||||||
result = ISC_R_SUCCESS;
|
result = ISC_R_SUCCESS;
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
@@ -245,10 +245,10 @@ dns_dyndb_cleanup(void) {
|
|||||||
dyndb_implementation_t *prev;
|
dyndb_implementation_t *prev;
|
||||||
|
|
||||||
LOCK(&dyndb_lock);
|
LOCK(&dyndb_lock);
|
||||||
elem = TAIL(dyndb_implementations);
|
elem = ISC_LIST_TAIL(dyndb_implementations);
|
||||||
while (elem != NULL) {
|
while (elem != NULL) {
|
||||||
prev = PREV(elem, link);
|
prev = ISC_LIST_PREV(elem, link);
|
||||||
UNLINK(dyndb_implementations, elem, link);
|
ISC_LIST_UNLINK(dyndb_implementations, elem, link);
|
||||||
isc_log_write(DNS_LOGCATEGORY_DATABASE, DNS_LOGMODULE_DYNDB,
|
isc_log_write(DNS_LOGCATEGORY_DATABASE, DNS_LOGMODULE_DYNDB,
|
||||||
ISC_LOG_INFO, "unloading DynDB instance '%s'",
|
ISC_LOG_INFO, "unloading DynDB instance '%s'",
|
||||||
elem->name);
|
elem->name);
|
||||||
|
|||||||
@@ -205,9 +205,9 @@ dns_keytable_finddeepestmatch(dns_keytable_t *keytable, const dns_name_t *name,
|
|||||||
*\li Any other result indicates an error.
|
*\li Any other result indicates an error.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
isc_result_t
|
bool
|
||||||
dns_keytable_issecuredomain(dns_keytable_t *keytable, const dns_name_t *name,
|
dns_keytable_issecuredomain(dns_keytable_t *keytable, const dns_name_t *name,
|
||||||
dns_name_t *foundname, bool *wantdnssecp);
|
dns_name_t *foundname);
|
||||||
/*%<
|
/*%<
|
||||||
* Is 'name' at or beneath a trusted key?
|
* Is 'name' at or beneath a trusted key?
|
||||||
*
|
*
|
||||||
@@ -219,20 +219,11 @@ dns_keytable_issecuredomain(dns_keytable_t *keytable, const dns_name_t *name,
|
|||||||
*
|
*
|
||||||
*\li 'foundanme' is NULL or is a pointer to an initialized dns_name_t
|
*\li 'foundanme' is NULL or is a pointer to an initialized dns_name_t
|
||||||
*
|
*
|
||||||
*\li '*wantsdnssecp' is a valid bool.
|
|
||||||
*
|
|
||||||
* Ensures:
|
* Ensures:
|
||||||
*
|
*
|
||||||
*\li On success, *wantsdnssecp will be true if and only if 'name'
|
*\li Returns true if and only if 'name' is at or beneath a trusted key.
|
||||||
* is at or beneath a trusted key. If 'foundname' is not NULL, then
|
* If 'foundname' is not NULL, then it will be updated to contain
|
||||||
* it will be updated to contain the name of the closest enclosing
|
* the name of the closest enclosing trust anchor.
|
||||||
* trust anchor.
|
|
||||||
*
|
|
||||||
* Returns:
|
|
||||||
*
|
|
||||||
*\li ISC_R_SUCCESS
|
|
||||||
*
|
|
||||||
*\li Any other result is an error.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
|
|||||||
@@ -54,26 +54,24 @@
|
|||||||
isc_result_t
|
isc_result_t
|
||||||
dns_ncache_add(dns_message_t *message, dns_db_t *cache, dns_dbnode_t *node,
|
dns_ncache_add(dns_message_t *message, dns_db_t *cache, dns_dbnode_t *node,
|
||||||
dns_rdatatype_t covers, isc_stdtime_t now, dns_ttl_t minttl,
|
dns_rdatatype_t covers, isc_stdtime_t now, dns_ttl_t minttl,
|
||||||
dns_ttl_t maxttl, dns_rdataset_t *addedrdataset);
|
dns_ttl_t maxttl, bool optout, bool secure,
|
||||||
isc_result_t
|
dns_rdataset_t *addedrdataset);
|
||||||
dns_ncache_addoptout(dns_message_t *message, dns_db_t *cache,
|
|
||||||
dns_dbnode_t *node, dns_rdatatype_t covers,
|
|
||||||
isc_stdtime_t now, dns_ttl_t minttl, dns_ttl_t maxttl,
|
|
||||||
bool optout, dns_rdataset_t *addedrdataset);
|
|
||||||
/*%<
|
/*%<
|
||||||
* Convert the authority data from 'message' into a negative cache
|
* Convert the authority data from 'message' into a negative cache
|
||||||
* rdataset, and store it in 'cache' at 'node' with a TTL limited to
|
* rdataset, and store it in 'cache' at 'node' with a TTL limited to
|
||||||
* 'maxttl'.
|
* 'maxttl'.
|
||||||
*
|
*
|
||||||
* \li dns_ncache_add produces a negative cache entry with a trust of no
|
* \li If 'secure' is true and all the records that make up the entry
|
||||||
* more than answer
|
* are secure, then dns_ncache_add produces a negative cache entry
|
||||||
* \li dns_ncache_addoptout produces a negative cache entry which will have
|
* with trust level secure.
|
||||||
* a trust of secure if all the records that make up the entry are secure.
|
* \li If 'secure' is false, the negative cache entry's trust level
|
||||||
|
* will be capped at answer.
|
||||||
*
|
*
|
||||||
* The 'covers' argument is the RR type whose nonexistence we are caching,
|
* The 'covers' argument is the RR type whose nonexistence we are caching,
|
||||||
* or dns_rdatatype_any when caching a NXDOMAIN response.
|
* or dns_rdatatype_any when caching a NXDOMAIN response.
|
||||||
*
|
*
|
||||||
* 'optout' indicates a DNS_RDATASETATTR_OPTOUT should be set.
|
* 'optout' indicates DNS_RDATASETATTR_OPTOUT should be set. This only
|
||||||
|
* applies in secure zones; if 'secure' is false, 'optout' is ignored.
|
||||||
*
|
*
|
||||||
* Note:
|
* Note:
|
||||||
*\li If 'addedrdataset' is not NULL, then it will be attached to the added
|
*\li If 'addedrdataset' is not NULL, then it will be attached to the added
|
||||||
|
|||||||
+190
-117
@@ -113,6 +113,36 @@ struct dns_rdata {
|
|||||||
ISC_LINK(dns_rdata_t) link;
|
ISC_LINK(dns_rdata_t) link;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
/*%
|
||||||
|
* Rdatatype attributes.
|
||||||
|
*/
|
||||||
|
enum {
|
||||||
|
/*% only one may exist for a name */
|
||||||
|
DNS_RDATATYPEATTR_SINGLETON = 1 << 0,
|
||||||
|
/*% requires no other data be present */
|
||||||
|
DNS_RDATATYPEATTR_EXCLUSIVE = 1 << 1,
|
||||||
|
/*% Is a meta type */
|
||||||
|
DNS_RDATATYPEATTR_META = 1 << 2,
|
||||||
|
/*% Is a DNSSEC type, like RRSIG or NSEC */
|
||||||
|
DNS_RDATATYPEATTR_DNSSEC = 1 << 3,
|
||||||
|
/*% Is a zone cut authority type */
|
||||||
|
DNS_RDATATYPEATTR_ZONECUTAUTH = 1 << 4,
|
||||||
|
/*% Is reserved (unusable) */
|
||||||
|
DNS_RDATATYPEATTR_RESERVED = 1 << 5,
|
||||||
|
/*% Is an unknown type */
|
||||||
|
DNS_RDATATYPEATTR_UNKNOWN = 1 << 6,
|
||||||
|
/*% Is META, and can only be in a question section */
|
||||||
|
DNS_RDATATYPEATTR_QUESTIONONLY = 1 << 7,
|
||||||
|
/*% Is META, and can NOT be in a question section */
|
||||||
|
DNS_RDATATYPEATTR_NOTQUESTION = 1 << 8,
|
||||||
|
/*% Is present at zone cuts in the parent, not the child */
|
||||||
|
DNS_RDATATYPEATTR_ATPARENT = 1 << 9,
|
||||||
|
/*% Can exist along side a CNAME */
|
||||||
|
DNS_RDATATYPEATTR_ATCNAME = 1 << 10,
|
||||||
|
/*% Follow additional */
|
||||||
|
DNS_RDATATYPEATTR_FOLLOWADDITIONAL = 1 << 11,
|
||||||
|
};
|
||||||
|
|
||||||
#define DNS_RDATA_INIT \
|
#define DNS_RDATA_INIT \
|
||||||
{ \
|
{ \
|
||||||
.data = NULL, \
|
.data = NULL, \
|
||||||
@@ -530,16 +560,28 @@ dns_rdata_freestruct(void *source);
|
|||||||
* dns_rdata_tostruct().
|
* dns_rdata_tostruct().
|
||||||
*/
|
*/
|
||||||
|
|
||||||
bool
|
unsigned int
|
||||||
dns_rdatatype_ismeta(dns_rdatatype_t type);
|
dns_rdatatype_attributes(dns_rdatatype_t rdtype);
|
||||||
/*%<
|
/*%<
|
||||||
|
* Return attributes for the given type.
|
||||||
|
*
|
||||||
|
* Requires:
|
||||||
|
*\li 'rdtype' are known.
|
||||||
|
*
|
||||||
|
* Returns:
|
||||||
|
*\li a bitmask of the rdatatype attribute flags, defined above.
|
||||||
|
*/
|
||||||
|
|
||||||
|
/*%
|
||||||
* Return true iff the rdata type 'type' is a meta-type
|
* Return true iff the rdata type 'type' is a meta-type
|
||||||
* like ANY or AXFR.
|
* like ANY or AXFR.
|
||||||
*/
|
*/
|
||||||
|
static inline bool
|
||||||
|
dns_rdatatype_ismeta(dns_rdatatype_t type) {
|
||||||
|
return (dns_rdatatype_attributes(type) & DNS_RDATATYPEATTR_META) != 0;
|
||||||
|
}
|
||||||
|
|
||||||
bool
|
/*%
|
||||||
dns_rdatatype_issingleton(dns_rdatatype_t type);
|
|
||||||
/*%<
|
|
||||||
* Return true iff the rdata type 'type' is a singleton type,
|
* Return true iff the rdata type 'type' is a singleton type,
|
||||||
* like CNAME or SOA.
|
* like CNAME or SOA.
|
||||||
*
|
*
|
||||||
@@ -547,34 +589,108 @@ dns_rdatatype_issingleton(dns_rdatatype_t type);
|
|||||||
* \li 'type' is a valid rdata type.
|
* \li 'type' is a valid rdata type.
|
||||||
*
|
*
|
||||||
*/
|
*/
|
||||||
|
static inline bool
|
||||||
|
dns_rdatatype_issingleton(dns_rdatatype_t type) {
|
||||||
|
return (dns_rdatatype_attributes(type) & DNS_RDATATYPEATTR_SINGLETON) !=
|
||||||
|
0;
|
||||||
|
}
|
||||||
|
|
||||||
bool
|
/*%
|
||||||
dns_rdataclass_ismeta(dns_rdataclass_t rdclass);
|
* Return true iff rdata of type 'type' can not appear in the question
|
||||||
/*%<
|
* section of a properly formatted message.
|
||||||
* Return true iff the rdata class 'rdclass' is a meta-class
|
*
|
||||||
* like ANY or NONE.
|
* Requires:
|
||||||
|
* \li 'type' is a valid rdata type.
|
||||||
|
*
|
||||||
*/
|
*/
|
||||||
|
static inline bool
|
||||||
|
dns_rdatatype_notquestion(dns_rdatatype_t type) {
|
||||||
|
return (dns_rdatatype_attributes(type) &
|
||||||
|
DNS_RDATATYPEATTR_NOTQUESTION) != 0;
|
||||||
|
}
|
||||||
|
|
||||||
bool
|
/*%
|
||||||
dns_rdatatype_isdnssec(dns_rdatatype_t type);
|
* Return true iff rdata of type 'type' can only appear in the question
|
||||||
/*%<
|
* section of a properly formatted message.
|
||||||
|
*
|
||||||
|
* Requires:
|
||||||
|
* \li 'type' is a valid rdata type.
|
||||||
|
*
|
||||||
|
*/
|
||||||
|
static inline bool
|
||||||
|
dns_rdatatype_questiononly(dns_rdatatype_t type) {
|
||||||
|
return (dns_rdatatype_attributes(type) &
|
||||||
|
DNS_RDATATYPEATTR_QUESTIONONLY) != 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
/*%
|
||||||
|
* Return true iff rdata of type 'type' can appear beside a cname.
|
||||||
|
*
|
||||||
|
* Requires:
|
||||||
|
* \li 'type' is a valid rdata type.
|
||||||
|
*
|
||||||
|
*/
|
||||||
|
static inline bool
|
||||||
|
dns_rdatatype_atcname(dns_rdatatype_t type) {
|
||||||
|
return (dns_rdatatype_attributes(type) & DNS_RDATATYPEATTR_ATCNAME) !=
|
||||||
|
0;
|
||||||
|
}
|
||||||
|
|
||||||
|
/*%
|
||||||
|
* Return true iff rdata of type 'type' should appear at the parent of
|
||||||
|
* a zone cut.
|
||||||
|
*
|
||||||
|
* Requires:
|
||||||
|
* \li 'type' is a valid rdata type.
|
||||||
|
*
|
||||||
|
*/
|
||||||
|
static inline bool
|
||||||
|
dns_rdatatype_atparent(dns_rdatatype_t type) {
|
||||||
|
return (dns_rdatatype_attributes(type) & DNS_RDATATYPEATTR_ATPARENT) !=
|
||||||
|
0;
|
||||||
|
}
|
||||||
|
|
||||||
|
/*%
|
||||||
|
* Return true if adding a record of type 'type' to the ADDITIONAL section
|
||||||
|
* of a message can itself trigger the addition of still more data to the
|
||||||
|
* additional section.
|
||||||
|
*
|
||||||
|
* (For example: adding SRV to the ADDITIONAL section may trigger
|
||||||
|
* the addition of address records associated with that SRV.)
|
||||||
|
*
|
||||||
|
* Requires:
|
||||||
|
* \li 'type' is a valid rdata type.
|
||||||
|
*
|
||||||
|
*/
|
||||||
|
static inline bool
|
||||||
|
dns_rdatatype_followadditional(dns_rdatatype_t type) {
|
||||||
|
return (dns_rdatatype_attributes(type) &
|
||||||
|
DNS_RDATATYPEATTR_FOLLOWADDITIONAL) != 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
/*%
|
||||||
* Return true iff 'type' is one of the DNSSEC
|
* Return true iff 'type' is one of the DNSSEC
|
||||||
* rdata types that may exist alongside a CNAME record.
|
* rdata types that may exist alongside a CNAME record.
|
||||||
*
|
*
|
||||||
* Requires:
|
* Requires:
|
||||||
* \li 'type' is a valid rdata type.
|
* \li 'type' is a valid rdata type.
|
||||||
*/
|
*/
|
||||||
|
static inline bool
|
||||||
|
dns_rdatatype_isdnssec(dns_rdatatype_t type) {
|
||||||
|
return (dns_rdatatype_attributes(type) & DNS_RDATATYPEATTR_DNSSEC) != 0;
|
||||||
|
}
|
||||||
|
|
||||||
bool
|
/*%
|
||||||
dns_rdatatype_iskeymaterial(dns_rdatatype_t type);
|
|
||||||
/*%<
|
|
||||||
* Return true iff the rdata type 'type' is a DNSSEC key
|
* Return true iff the rdata type 'type' is a DNSSEC key
|
||||||
* related type, like DNSKEY, CDNSKEY, or CDS.
|
* related type, like DNSKEY, CDNSKEY, or CDS.
|
||||||
*/
|
*/
|
||||||
|
static inline bool
|
||||||
|
dns_rdatatype_iskeymaterial(dns_rdatatype_t type) {
|
||||||
|
return type == dns_rdatatype_dnskey || type == dns_rdatatype_cdnskey ||
|
||||||
|
type == dns_rdatatype_cds;
|
||||||
|
}
|
||||||
|
|
||||||
bool
|
/*%
|
||||||
dns_rdatatype_iszonecutauth(dns_rdatatype_t type);
|
|
||||||
/*%<
|
|
||||||
* Return true iff rdata of type 'type' is considered authoritative
|
* Return true iff rdata of type 'type' is considered authoritative
|
||||||
* data (not glue) in the NSEC chain when it occurs in the parent zone
|
* data (not glue) in the NSEC chain when it occurs in the parent zone
|
||||||
* at a zone cut.
|
* at a zone cut.
|
||||||
@@ -583,16 +699,68 @@ dns_rdatatype_iszonecutauth(dns_rdatatype_t type);
|
|||||||
* \li 'type' is a valid rdata type.
|
* \li 'type' is a valid rdata type.
|
||||||
*
|
*
|
||||||
*/
|
*/
|
||||||
|
static inline bool
|
||||||
|
dns_rdatatype_iszonecutauth(dns_rdatatype_t type) {
|
||||||
|
return (dns_rdatatype_attributes(type) &
|
||||||
|
DNS_RDATATYPEATTR_ZONECUTAUTH) != 0;
|
||||||
|
}
|
||||||
|
|
||||||
bool
|
/*%
|
||||||
dns_rdatatype_isknown(dns_rdatatype_t type);
|
|
||||||
/*%<
|
|
||||||
* Return true iff the rdata type 'type' is known.
|
* Return true iff the rdata type 'type' is known.
|
||||||
*
|
*
|
||||||
* Requires:
|
* Requires:
|
||||||
* \li 'type' is a valid rdata type.
|
* \li 'type' is a valid rdata type.
|
||||||
*
|
*
|
||||||
*/
|
*/
|
||||||
|
static inline bool
|
||||||
|
dns_rdatatype_isknown(dns_rdatatype_t type) {
|
||||||
|
return (dns_rdatatype_attributes(type) & DNS_RDATATYPEATTR_UNKNOWN) ==
|
||||||
|
0;
|
||||||
|
}
|
||||||
|
|
||||||
|
/*%
|
||||||
|
* Return true iff a query for the rdata type can have multiple
|
||||||
|
* unrelated answers in a response: ANY, RRSIG, or SIG.
|
||||||
|
*/
|
||||||
|
static inline bool
|
||||||
|
dns_rdatatype_ismulti(dns_rdatatype_t type) {
|
||||||
|
return type == dns_rdatatype_any || type == dns_rdatatype_rrsig ||
|
||||||
|
type == dns_rdatatype_sig;
|
||||||
|
}
|
||||||
|
|
||||||
|
/*%
|
||||||
|
* Return true iff the rdata type is a signature: either RRSIG or SIG.
|
||||||
|
*/
|
||||||
|
static inline bool
|
||||||
|
dns_rdatatype_issig(dns_rdatatype_t type) {
|
||||||
|
return type == dns_rdatatype_rrsig || type == dns_rdatatype_sig;
|
||||||
|
}
|
||||||
|
|
||||||
|
/*%
|
||||||
|
* Return true iff the rdata type is an address: either A or AAAA.
|
||||||
|
*/
|
||||||
|
static inline bool
|
||||||
|
dns_rdatatype_isaddr(dns_rdatatype_t type) {
|
||||||
|
return type == dns_rdatatype_a || type == dns_rdatatype_aaaa;
|
||||||
|
}
|
||||||
|
|
||||||
|
/*%
|
||||||
|
* Return true iff the rdata type is an alias: either CNAME or DNAME.
|
||||||
|
*/
|
||||||
|
static inline bool
|
||||||
|
dns_rdatatype_isalias(dns_rdatatype_t type) {
|
||||||
|
return type == dns_rdatatype_cname || type == dns_rdatatype_dname;
|
||||||
|
}
|
||||||
|
|
||||||
|
/*%
|
||||||
|
* Return true iff the rdata class 'rdclass' is a meta-class
|
||||||
|
* like ANY or NONE.
|
||||||
|
*/
|
||||||
|
static inline bool
|
||||||
|
dns_rdataclass_ismeta(dns_rdataclass_t rdclass) {
|
||||||
|
return rdclass == dns_rdataclass_reserved0 ||
|
||||||
|
rdclass == dns_rdataclass_none || rdclass == dns_rdataclass_any;
|
||||||
|
}
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
dns_rdata_additionaldata(dns_rdata_t *rdata, const dns_name_t *owner,
|
dns_rdata_additionaldata(dns_rdata_t *rdata, const dns_name_t *owner,
|
||||||
@@ -653,101 +821,6 @@ dns_rdata_digest(dns_rdata_t *rdata, dns_digestfunc_t digest, void *arg);
|
|||||||
*\li Many other results are possible if not successful.
|
*\li Many other results are possible if not successful.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
bool
|
|
||||||
dns_rdatatype_questiononly(dns_rdatatype_t type);
|
|
||||||
/*%<
|
|
||||||
* Return true iff rdata of type 'type' can only appear in the question
|
|
||||||
* section of a properly formatted message.
|
|
||||||
*
|
|
||||||
* Requires:
|
|
||||||
* \li 'type' is a valid rdata type.
|
|
||||||
*
|
|
||||||
*/
|
|
||||||
|
|
||||||
bool
|
|
||||||
dns_rdatatype_notquestion(dns_rdatatype_t type);
|
|
||||||
/*%<
|
|
||||||
* Return true iff rdata of type 'type' can not appear in the question
|
|
||||||
* section of a properly formatted message.
|
|
||||||
*
|
|
||||||
* Requires:
|
|
||||||
* \li 'type' is a valid rdata type.
|
|
||||||
*
|
|
||||||
*/
|
|
||||||
|
|
||||||
bool
|
|
||||||
dns_rdatatype_atparent(dns_rdatatype_t type);
|
|
||||||
/*%<
|
|
||||||
* Return true iff rdata of type 'type' should appear at the parent of
|
|
||||||
* a zone cut.
|
|
||||||
*
|
|
||||||
* Requires:
|
|
||||||
* \li 'type' is a valid rdata type.
|
|
||||||
*
|
|
||||||
*/
|
|
||||||
|
|
||||||
bool
|
|
||||||
dns_rdatatype_atcname(dns_rdatatype_t type);
|
|
||||||
/*%<
|
|
||||||
* Return true iff rdata of type 'type' can appear beside a cname.
|
|
||||||
*
|
|
||||||
* Requires:
|
|
||||||
* \li 'type' is a valid rdata type.
|
|
||||||
*
|
|
||||||
*/
|
|
||||||
|
|
||||||
bool
|
|
||||||
dns_rdatatype_followadditional(dns_rdatatype_t type);
|
|
||||||
/*%<
|
|
||||||
* Return true if adding a record of type 'type' to the ADDITIONAL section
|
|
||||||
* of a message can itself trigger the addition of still more data to the
|
|
||||||
* additional section.
|
|
||||||
*
|
|
||||||
* (For example: adding SRV to the ADDITIONAL section may trigger
|
|
||||||
* the addition of address records associated with that SRV.)
|
|
||||||
*
|
|
||||||
* Requires:
|
|
||||||
* \li 'type' is a valid rdata type.
|
|
||||||
*
|
|
||||||
*/
|
|
||||||
|
|
||||||
unsigned int
|
|
||||||
dns_rdatatype_attributes(dns_rdatatype_t rdtype);
|
|
||||||
/*%<
|
|
||||||
* Return attributes for the given type.
|
|
||||||
*
|
|
||||||
* Requires:
|
|
||||||
*\li 'rdtype' are known.
|
|
||||||
*
|
|
||||||
* Returns:
|
|
||||||
*\li a bitmask consisting of the following flags.
|
|
||||||
*/
|
|
||||||
|
|
||||||
/*% only one may exist for a name */
|
|
||||||
#define DNS_RDATATYPEATTR_SINGLETON 0x00000001U
|
|
||||||
/*% requires no other data be present */
|
|
||||||
#define DNS_RDATATYPEATTR_EXCLUSIVE 0x00000002U
|
|
||||||
/*% Is a meta type */
|
|
||||||
#define DNS_RDATATYPEATTR_META 0x00000004U
|
|
||||||
/*% Is a DNSSEC type, like RRSIG or NSEC */
|
|
||||||
#define DNS_RDATATYPEATTR_DNSSEC 0x00000008U
|
|
||||||
/*% Is a zone cut authority type */
|
|
||||||
#define DNS_RDATATYPEATTR_ZONECUTAUTH 0x00000010U
|
|
||||||
/*% Is reserved (unusable) */
|
|
||||||
#define DNS_RDATATYPEATTR_RESERVED 0x00000020U
|
|
||||||
/*% Is an unknown type */
|
|
||||||
#define DNS_RDATATYPEATTR_UNKNOWN 0x00000040U
|
|
||||||
/*% Is META, and can only be in a question section */
|
|
||||||
#define DNS_RDATATYPEATTR_QUESTIONONLY 0x00000080U
|
|
||||||
/*% Is META, and can NOT be in a question section */
|
|
||||||
#define DNS_RDATATYPEATTR_NOTQUESTION 0x00000100U
|
|
||||||
/*% Is present at zone cuts in the parent, not the child */
|
|
||||||
#define DNS_RDATATYPEATTR_ATPARENT 0x00000200U
|
|
||||||
/*% Can exist along side a CNAME */
|
|
||||||
#define DNS_RDATATYPEATTR_ATCNAME 0x00000400U
|
|
||||||
/*% Follow additional */
|
|
||||||
#define DNS_RDATATYPEATTR_FOLLOWADDITIONAL 0x00000800U
|
|
||||||
|
|
||||||
dns_rdatatype_t
|
dns_rdatatype_t
|
||||||
dns_rdata_covers(dns_rdata_t *rdata);
|
dns_rdata_covers(dns_rdata_t *rdata);
|
||||||
/*%<
|
/*%<
|
||||||
|
|||||||
@@ -689,3 +689,30 @@ dns_rdataset_equals(const dns_rdataset_t *rdataset1,
|
|||||||
* \li 'rdataset1' is a valid rdataset.
|
* \li 'rdataset1' is a valid rdataset.
|
||||||
* \li 'rdataset2' is a valid rdataset.
|
* \li 'rdataset2' is a valid rdataset.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
/*%
|
||||||
|
* Returns true if the rdataset is of type 'type', or type RRSIG
|
||||||
|
* and covers 'type'.
|
||||||
|
*/
|
||||||
|
static inline bool
|
||||||
|
dns_rdataset_matchestype(const dns_rdataset_t *rdataset,
|
||||||
|
const dns_rdatatype_t type) {
|
||||||
|
REQUIRE(DNS_RDATASET_VALID(rdataset));
|
||||||
|
|
||||||
|
return rdataset->type == type ||
|
||||||
|
(rdataset->type == dns_rdatatype_rrsig &&
|
||||||
|
rdataset->covers == type);
|
||||||
|
}
|
||||||
|
|
||||||
|
/*%
|
||||||
|
* Returns true if the rdataset is of type 'type', or type RRSIG
|
||||||
|
* and covers 'type'.
|
||||||
|
*/
|
||||||
|
static inline bool
|
||||||
|
dns_rdataset_issigtype(const dns_rdataset_t *rdataset,
|
||||||
|
const dns_rdatatype_t type) {
|
||||||
|
REQUIRE(DNS_RDATASET_VALID(rdataset));
|
||||||
|
|
||||||
|
return rdataset->type == dns_rdatatype_rrsig &&
|
||||||
|
rdataset->covers == type;
|
||||||
|
}
|
||||||
|
|||||||
@@ -129,6 +129,7 @@ enum {
|
|||||||
* on ip6.arpa. */
|
* on ip6.arpa. */
|
||||||
DNS_FETCHOPT_NOFORWARD = 1 << 15, /*%< Do not use forwarders if
|
DNS_FETCHOPT_NOFORWARD = 1 << 15, /*%< Do not use forwarders if
|
||||||
* possible. */
|
* possible. */
|
||||||
|
DNS_FETCHOPT_QMINFETCH = 1 << 16, /*%< Qmin fetch */
|
||||||
|
|
||||||
/*% EDNS version bits: */
|
/*% EDNS version bits: */
|
||||||
DNS_FETCHOPT_EDNSVERSIONSET = 1 << 23,
|
DNS_FETCHOPT_EDNSVERSIONSET = 1 << 23,
|
||||||
|
|||||||
@@ -399,7 +399,7 @@ dns_opcodestats_increment(dns_stats_t *stats, dns_opcode_t code);
|
|||||||
*/
|
*/
|
||||||
|
|
||||||
void
|
void
|
||||||
dns_rcodestats_increment(dns_stats_t *stats, dns_opcode_t code);
|
dns_rcodestats_increment(dns_stats_t *stats, dns_rcode_t code);
|
||||||
/*%<
|
/*%<
|
||||||
* Increment the statistics counter for 'code'.
|
* Increment the statistics counter for 'code'.
|
||||||
*
|
*
|
||||||
|
|||||||
@@ -124,7 +124,7 @@ typedef struct dns_nametree dns_nametree_t;
|
|||||||
typedef ISC_LIST(dns_name_t) dns_namelist_t;
|
typedef ISC_LIST(dns_name_t) dns_namelist_t;
|
||||||
typedef struct dns_ntatable dns_ntatable_t;
|
typedef struct dns_ntatable dns_ntatable_t;
|
||||||
typedef struct dns_ntnode dns_ntnode_t;
|
typedef struct dns_ntnode dns_ntnode_t;
|
||||||
typedef uint16_t dns_opcode_t;
|
typedef enum dns_opcode dns_opcode_t;
|
||||||
typedef struct dns_order dns_order_t;
|
typedef struct dns_order dns_order_t;
|
||||||
typedef struct dns_peer dns_peer_t;
|
typedef struct dns_peer dns_peer_t;
|
||||||
typedef struct dns_peerlist dns_peerlist_t;
|
typedef struct dns_peerlist dns_peerlist_t;
|
||||||
@@ -308,20 +308,18 @@ enum {
|
|||||||
/*%
|
/*%
|
||||||
* Opcodes.
|
* Opcodes.
|
||||||
*/
|
*/
|
||||||
enum {
|
enum dns_opcode {
|
||||||
dns_opcode_query = 0,
|
dns_opcode_query = 0,
|
||||||
#define dns_opcode_query ((dns_opcode_t)dns_opcode_query)
|
|
||||||
dns_opcode_iquery = 1,
|
dns_opcode_iquery = 1,
|
||||||
#define dns_opcode_iquery ((dns_opcode_t)dns_opcode_iquery)
|
|
||||||
dns_opcode_status = 2,
|
dns_opcode_status = 2,
|
||||||
#define dns_opcode_status ((dns_opcode_t)dns_opcode_status)
|
|
||||||
dns_opcode_notify = 4,
|
dns_opcode_notify = 4,
|
||||||
#define dns_opcode_notify ((dns_opcode_t)dns_opcode_notify)
|
|
||||||
dns_opcode_update = 5, /* dynamic update */
|
dns_opcode_update = 5, /* dynamic update */
|
||||||
#define dns_opcode_update ((dns_opcode_t)dns_opcode_update)
|
|
||||||
dns_opcode_max = 6,
|
dns_opcode_max = 6,
|
||||||
#define dns_opcode_max ((dns_opcode_t)dns_opcode_max)
|
dns__opcode_expand = UINT16_MAX,
|
||||||
};
|
} __attribute__((__packed__));
|
||||||
|
/* Absent attribute packed, the enum will be sized as an int */
|
||||||
|
STATIC_ASSERT(sizeof(uint16_t) == sizeof(dns_opcode_t),
|
||||||
|
"sizeof(dns_opecode)t) is not 16-bit");
|
||||||
|
|
||||||
/*%
|
/*%
|
||||||
* Trust levels. Must be kept in sync with trustnames[] in masterdump.c.
|
* Trust levels. Must be kept in sync with trustnames[] in masterdump.c.
|
||||||
|
|||||||
@@ -986,13 +986,12 @@ dns_view_getsecroots(dns_view_t *view, dns_keytable_t **ktp);
|
|||||||
*\li ISC_R_NOTFOUND
|
*\li ISC_R_NOTFOUND
|
||||||
*/
|
*/
|
||||||
|
|
||||||
isc_result_t
|
bool
|
||||||
dns_view_issecuredomain(dns_view_t *view, const dns_name_t *name,
|
dns_view_issecuredomain(dns_view_t *view, const dns_name_t *name,
|
||||||
isc_stdtime_t now, bool checknta, bool *ntap,
|
isc_stdtime_t now, bool checknta, bool *ntap);
|
||||||
bool *secure_domain);
|
|
||||||
/*%<
|
/*%<
|
||||||
* Is 'name' at or beneath a trusted key, and not covered by a valid
|
* Is 'name' at or beneath a trusted key, and not covered by a valid
|
||||||
* negative trust anchor? Put answer in '*secure_domain'.
|
* negative trust anchor, and DNSSEC validation is enabled?
|
||||||
*
|
*
|
||||||
* If 'checknta' is false, ignore the NTA table in determining
|
* If 'checknta' is false, ignore the NTA table in determining
|
||||||
* whether this is a secure domain. If 'checknta' is not false, and if
|
* whether this is a secure domain. If 'checknta' is not false, and if
|
||||||
@@ -1001,10 +1000,6 @@ dns_view_issecuredomain(dns_view_t *view, const dns_name_t *name,
|
|||||||
*
|
*
|
||||||
* Requires:
|
* Requires:
|
||||||
* \li 'view' is valid.
|
* \li 'view' is valid.
|
||||||
*
|
|
||||||
* Returns:
|
|
||||||
*\li ISC_R_SUCCESS
|
|
||||||
*\li Any other value indicates failure
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
bool
|
bool
|
||||||
|
|||||||
@@ -1539,14 +1539,19 @@ dns_zone_getsourceaddr(dns_zone_t *zone);
|
|||||||
* \li 'zone' has a non-empty primaries list.
|
* \li 'zone' has a non-empty primaries list.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
isc_sockaddr_t
|
isc_result_t
|
||||||
dns_zone_getprimaryaddr(dns_zone_t *zone);
|
dns_zone_getprimaryaddr(dns_zone_t *zone, isc_sockaddr_t *dest);
|
||||||
/*%<
|
/*%<
|
||||||
* Get the zone's current primary server.
|
* Get the zone's current primary server into '*dest'.
|
||||||
*
|
*
|
||||||
* Requires:
|
* Requires:
|
||||||
* \li 'zone' to be a valid zone.
|
* \li 'zone' to be a valid zone.
|
||||||
* \li 'zone' has a non-empty primaries list.
|
* \li 'zone' has a non-empty primaries list.
|
||||||
|
* \li 'dest' != NULL.
|
||||||
|
*
|
||||||
|
* Returns:
|
||||||
|
*\li #ISC_R_SUCCESS if the current primary server was found
|
||||||
|
*\li #ISC_R_NOMORE if all the primaries were already iterated over
|
||||||
*/
|
*/
|
||||||
|
|
||||||
isc_time_t
|
isc_time_t
|
||||||
|
|||||||
+5
-9
@@ -530,13 +530,14 @@ dns_keytable_finddeepestmatch(dns_keytable_t *keytable, const dns_name_t *name,
|
|||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_result_t
|
bool
|
||||||
dns_keytable_issecuredomain(dns_keytable_t *keytable, const dns_name_t *name,
|
dns_keytable_issecuredomain(dns_keytable_t *keytable, const dns_name_t *name,
|
||||||
dns_name_t *foundname, bool *wantdnssecp) {
|
dns_name_t *foundname) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
dns_qpread_t qpr;
|
dns_qpread_t qpr;
|
||||||
dns_keynode_t *keynode = NULL;
|
dns_keynode_t *keynode = NULL;
|
||||||
void *pval = NULL;
|
void *pval = NULL;
|
||||||
|
bool secure = false;
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Is 'name' at or beneath a trusted key?
|
* Is 'name' at or beneath a trusted key?
|
||||||
@@ -544,7 +545,6 @@ dns_keytable_issecuredomain(dns_keytable_t *keytable, const dns_name_t *name,
|
|||||||
|
|
||||||
REQUIRE(VALID_KEYTABLE(keytable));
|
REQUIRE(VALID_KEYTABLE(keytable));
|
||||||
REQUIRE(dns_name_isabsolute(name));
|
REQUIRE(dns_name_isabsolute(name));
|
||||||
REQUIRE(wantdnssecp != NULL);
|
|
||||||
|
|
||||||
dns_qpmulti_query(keytable->table, &qpr);
|
dns_qpmulti_query(keytable->table, &qpr);
|
||||||
result = dns_qp_lookup(&qpr, name, NULL, NULL, NULL, &pval, NULL);
|
result = dns_qp_lookup(&qpr, name, NULL, NULL, NULL, &pval, NULL);
|
||||||
@@ -553,16 +553,12 @@ dns_keytable_issecuredomain(dns_keytable_t *keytable, const dns_name_t *name,
|
|||||||
if (foundname != NULL) {
|
if (foundname != NULL) {
|
||||||
dns_name_copy(&keynode->name, foundname);
|
dns_name_copy(&keynode->name, foundname);
|
||||||
}
|
}
|
||||||
*wantdnssecp = true;
|
secure = true;
|
||||||
result = ISC_R_SUCCESS;
|
|
||||||
} else if (result == ISC_R_NOTFOUND) {
|
|
||||||
*wantdnssecp = false;
|
|
||||||
result = ISC_R_SUCCESS;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
dns_qpread_destroy(keytable->table, &qpr);
|
dns_qpread_destroy(keytable->table, &qpr);
|
||||||
|
|
||||||
return result;
|
return secure;
|
||||||
}
|
}
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
|
|||||||
+1
-1
@@ -1914,7 +1914,7 @@ load_text(dns_loadctx_t *lctx) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (type == dns_rdatatype_rrsig || type == dns_rdatatype_sig) {
|
if (dns_rdatatype_issig(type)) {
|
||||||
covers = dns_rdata_covers(&rdata[rdcount]);
|
covers = dns_rdata_covers(&rdata[rdcount]);
|
||||||
} else {
|
} else {
|
||||||
covers = 0;
|
covers = 0;
|
||||||
|
|||||||
+7
-27
@@ -50,12 +50,6 @@ atomic_getuint8(isc_buffer_t *b) {
|
|||||||
return ret;
|
return ret;
|
||||||
}
|
}
|
||||||
|
|
||||||
static isc_result_t
|
|
||||||
addoptout(dns_message_t *message, dns_db_t *cache, dns_dbnode_t *node,
|
|
||||||
dns_rdatatype_t covers, isc_stdtime_t now, dns_ttl_t minttl,
|
|
||||||
dns_ttl_t maxttl, bool optout, bool secure,
|
|
||||||
dns_rdataset_t *addedrdataset);
|
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
copy_rdataset(dns_rdataset_t *rdataset, isc_buffer_t *buffer) {
|
copy_rdataset(dns_rdataset_t *rdataset, isc_buffer_t *buffer) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
@@ -107,25 +101,8 @@ copy_rdataset(dns_rdataset_t *rdataset, isc_buffer_t *buffer) {
|
|||||||
isc_result_t
|
isc_result_t
|
||||||
dns_ncache_add(dns_message_t *message, dns_db_t *cache, dns_dbnode_t *node,
|
dns_ncache_add(dns_message_t *message, dns_db_t *cache, dns_dbnode_t *node,
|
||||||
dns_rdatatype_t covers, isc_stdtime_t now, dns_ttl_t minttl,
|
dns_rdatatype_t covers, isc_stdtime_t now, dns_ttl_t minttl,
|
||||||
dns_ttl_t maxttl, dns_rdataset_t *addedrdataset) {
|
dns_ttl_t maxttl, bool optout, bool secure,
|
||||||
return addoptout(message, cache, node, covers, now, minttl, maxttl,
|
dns_rdataset_t *addedrdataset) {
|
||||||
false, false, addedrdataset);
|
|
||||||
}
|
|
||||||
|
|
||||||
isc_result_t
|
|
||||||
dns_ncache_addoptout(dns_message_t *message, dns_db_t *cache,
|
|
||||||
dns_dbnode_t *node, dns_rdatatype_t covers,
|
|
||||||
isc_stdtime_t now, dns_ttl_t minttl, dns_ttl_t maxttl,
|
|
||||||
bool optout, dns_rdataset_t *addedrdataset) {
|
|
||||||
return addoptout(message, cache, node, covers, now, minttl, maxttl,
|
|
||||||
optout, true, addedrdataset);
|
|
||||||
}
|
|
||||||
|
|
||||||
static isc_result_t
|
|
||||||
addoptout(dns_message_t *message, dns_db_t *cache, dns_dbnode_t *node,
|
|
||||||
dns_rdatatype_t covers, isc_stdtime_t now, dns_ttl_t minttl,
|
|
||||||
dns_ttl_t maxttl, bool optout, bool secure,
|
|
||||||
dns_rdataset_t *addedrdataset) {
|
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
isc_buffer_t buffer;
|
isc_buffer_t buffer;
|
||||||
isc_region_t r;
|
isc_region_t r;
|
||||||
@@ -143,14 +120,17 @@ addoptout(dns_message_t *message, dns_db_t *cache, dns_dbnode_t *node,
|
|||||||
/*
|
/*
|
||||||
* Convert the authority data from 'message' into a negative cache
|
* Convert the authority data from 'message' into a negative cache
|
||||||
* rdataset, and store it in 'cache' at 'node'.
|
* rdataset, and store it in 'cache' at 'node'.
|
||||||
|
*
|
||||||
|
* We assume that all data in the authority section has been
|
||||||
|
* validated by the caller.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
REQUIRE(message != NULL);
|
REQUIRE(message != NULL);
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* We assume that all data in the authority section has been
|
* If 'secure' is false, ignore 'optout'.
|
||||||
* validated by the caller.
|
|
||||||
*/
|
*/
|
||||||
|
optout = optout && secure;
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Initialize the list.
|
* Initialize the list.
|
||||||
|
|||||||
@@ -30,7 +30,6 @@
|
|||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/mutex.h>
|
#include <isc/mutex.h>
|
||||||
#include <isc/mutexblock.h>
|
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
#include <isc/string.h>
|
#include <isc/string.h>
|
||||||
#include <isc/thread.h>
|
#include <isc/thread.h>
|
||||||
|
|||||||
@@ -26,7 +26,6 @@
|
|||||||
#include <openssl/param_build.h>
|
#include <openssl/param_build.h>
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
#include <isc/fips.h>
|
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
#include <isc/safe.h>
|
#include <isc/safe.h>
|
||||||
@@ -707,7 +706,7 @@ opensslecdsa_createctx(dst_key_t *key, dst_context_t *dctx) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30200000L
|
#if OPENSSL_VERSION_NUMBER >= 0x30200000L
|
||||||
if (!isc_fips_mode()) {
|
if (!isc_crypto_fips_mode()) {
|
||||||
ret = opensslecdsa_set_deterministic(
|
ret = opensslecdsa_set_deterministic(
|
||||||
pctx, dctx->key->key_alg);
|
pctx, dctx->key->key_alg);
|
||||||
if (ret != ISC_R_SUCCESS) {
|
if (ret != ISC_R_SUCCESS) {
|
||||||
|
|||||||
+101
-79
@@ -202,9 +202,10 @@ struct qpcnode {
|
|||||||
uint8_t : 0;
|
uint8_t : 0;
|
||||||
|
|
||||||
/*%
|
/*%
|
||||||
* Used for dead node cleaning. The deadnodes queue is used
|
* Used for dead nodes cleaning. This linked list is used to mark nodes
|
||||||
* for nodes that have no data any longer, but we can't unlink
|
* which have no data any longer, but we cannot unlink at that exact
|
||||||
* yet because we don't have a tree lock.
|
* moment because we did not or could not obtain a write lock on the
|
||||||
|
* tree.
|
||||||
*/
|
*/
|
||||||
isc_queue_node_t deadlink;
|
isc_queue_node_t deadlink;
|
||||||
};
|
};
|
||||||
@@ -215,8 +216,9 @@ struct qpcnode {
|
|||||||
* to reduce contention between threads.
|
* to reduce contention between threads.
|
||||||
*/
|
*/
|
||||||
typedef struct qpcache_bucket {
|
typedef struct qpcache_bucket {
|
||||||
/*
|
/*%
|
||||||
* Temporary storage for cache nodes that need to be deleted.
|
* Temporary storage for stale cache nodes and dynamically
|
||||||
|
* deleted nodes that await being cleaned up.
|
||||||
*/
|
*/
|
||||||
isc_queue_t deadnodes;
|
isc_queue_t deadnodes;
|
||||||
|
|
||||||
@@ -511,8 +513,7 @@ need_headerupdate(dns_slabheader_t *header, isc_stdtime_t now) {
|
|||||||
#if DNS_QPDB_LIMITLRUUPDATE
|
#if DNS_QPDB_LIMITLRUUPDATE
|
||||||
if (header->type == dns_rdatatype_ns ||
|
if (header->type == dns_rdatatype_ns ||
|
||||||
(header->trust == dns_trust_glue &&
|
(header->trust == dns_trust_glue &&
|
||||||
(header->type == dns_rdatatype_a ||
|
dns_rdatatype_isaddr(header->type)))
|
||||||
header->type == dns_rdatatype_aaaa)))
|
|
||||||
{
|
{
|
||||||
/*
|
/*
|
||||||
* Glue records are updated if at least DNS_QPDB_LRUUPDATE_GLUE
|
* Glue records are updated if at least DNS_QPDB_LRUUPDATE_GLUE
|
||||||
@@ -1997,78 +1998,23 @@ tree_exit:
|
|||||||
}
|
}
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
qpcache_findzonecut(dns_db_t *db, const dns_name_t *name, unsigned int options,
|
seek_ns_headers(qpc_search_t *search, qpcnode_t *node, dns_dbnode_t **nodep,
|
||||||
isc_stdtime_t __now, dns_dbnode_t **nodep,
|
dns_rdataset_t *rdataset, dns_rdataset_t *sigrdataset,
|
||||||
dns_name_t *foundname, dns_name_t *dcname,
|
dns_name_t *foundname, dns_name_t *dcname,
|
||||||
dns_rdataset_t *rdataset,
|
isc_rwlocktype_t *tlocktype) {
|
||||||
dns_rdataset_t *sigrdataset DNS__DB_FLARG) {
|
|
||||||
qpcnode_t *node = NULL;
|
|
||||||
isc_rwlock_t *nlock = NULL;
|
|
||||||
isc_result_t result;
|
|
||||||
dns_slabheader_t *header = NULL;
|
dns_slabheader_t *header = NULL;
|
||||||
dns_slabheader_t *header_prev = NULL, *header_next = NULL;
|
dns_slabheader_t *header_prev = NULL, *header_next = NULL;
|
||||||
dns_slabheader_t *found = NULL, *foundsig = NULL;
|
|
||||||
isc_rwlocktype_t tlocktype = isc_rwlocktype_none;
|
|
||||||
isc_rwlocktype_t nlocktype = isc_rwlocktype_none;
|
isc_rwlocktype_t nlocktype = isc_rwlocktype_none;
|
||||||
bool dcnull = (dcname == NULL);
|
isc_rwlock_t *nlock = &search->qpdb->buckets[node->locknum].lock;
|
||||||
qpc_search_t search = (qpc_search_t){
|
dns_slabheader_t *found = NULL, *foundsig = NULL;
|
||||||
.qpdb = (qpcache_t *)db,
|
|
||||||
.options = options,
|
|
||||||
.now = __now ? __now : isc_stdtime_now(),
|
|
||||||
};
|
|
||||||
|
|
||||||
REQUIRE(VALID_QPDB((qpcache_t *)db));
|
|
||||||
|
|
||||||
if (dcnull) {
|
|
||||||
dcname = foundname;
|
|
||||||
}
|
|
||||||
|
|
||||||
TREE_RDLOCK(&search.qpdb->tree_lock, &tlocktype);
|
|
||||||
|
|
||||||
/*
|
|
||||||
* Search down from the root of the tree.
|
|
||||||
*/
|
|
||||||
result = dns_qp_lookup(search.qpdb->tree, name, NULL, NULL,
|
|
||||||
&search.chain, (void **)&node, NULL);
|
|
||||||
if (result != ISC_R_NOTFOUND) {
|
|
||||||
dns_name_copy(&node->name, dcname);
|
|
||||||
}
|
|
||||||
if ((options & DNS_DBFIND_NOEXACT) != 0 && result == ISC_R_SUCCESS) {
|
|
||||||
int len = dns_qpchain_length(&search.chain);
|
|
||||||
if (len >= 2) {
|
|
||||||
node = NULL;
|
|
||||||
dns_qpchain_node(&search.chain, len - 2, NULL,
|
|
||||||
(void **)&node, NULL);
|
|
||||||
search.chain.len = len - 1;
|
|
||||||
result = DNS_R_PARTIALMATCH;
|
|
||||||
} else {
|
|
||||||
result = ISC_R_NOTFOUND;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if (result == DNS_R_PARTIALMATCH) {
|
|
||||||
result = find_deepest_zonecut(&search, node, nodep, foundname,
|
|
||||||
rdataset,
|
|
||||||
sigrdataset DNS__DB_FLARG_PASS);
|
|
||||||
goto tree_exit;
|
|
||||||
} else if (result != ISC_R_SUCCESS) {
|
|
||||||
goto tree_exit;
|
|
||||||
} else if (!dcnull) {
|
|
||||||
dns_name_copy(dcname, foundname);
|
|
||||||
}
|
|
||||||
|
|
||||||
/*
|
|
||||||
* We now go looking for an NS rdataset at the node.
|
|
||||||
*/
|
|
||||||
|
|
||||||
nlock = &search.qpdb->buckets[node->locknum].lock;
|
|
||||||
NODE_RDLOCK(nlock, &nlocktype);
|
NODE_RDLOCK(nlock, &nlocktype);
|
||||||
|
|
||||||
for (header = node->data; header != NULL; header = header_next) {
|
for (header = node->data; header != NULL; header = header_next) {
|
||||||
header_next = header->next;
|
header_next = header->next;
|
||||||
bool ns = (header->type == dns_rdatatype_ns ||
|
bool ns = (header->type == dns_rdatatype_ns ||
|
||||||
header->type == DNS_SIGTYPE(dns_rdatatype_ns));
|
header->type == DNS_SIGTYPE(dns_rdatatype_ns));
|
||||||
if (check_stale_header(node, header, &nlocktype, nlock, &search,
|
if (check_stale_header(node, header, &nlocktype, nlock, search,
|
||||||
&header_prev))
|
&header_prev))
|
||||||
{
|
{
|
||||||
if (ns) {
|
if (ns) {
|
||||||
@@ -2091,32 +2037,108 @@ qpcache_findzonecut(dns_db_t *db, const dns_name_t *name, unsigned int options,
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (found == NULL) {
|
if (found == NULL) {
|
||||||
|
isc_result_t result;
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* No active NS records found. Call find_deepest_zonecut()
|
* No active NS records found. Call find_deepest_zonecut()
|
||||||
* to look for them in nodes above this one.
|
* to look for them in nodes above this one.
|
||||||
*/
|
*/
|
||||||
NODE_UNLOCK(nlock, &nlocktype);
|
NODE_UNLOCK(nlock, &nlocktype);
|
||||||
result = find_deepest_zonecut(&search, node, nodep, foundname,
|
result = find_deepest_zonecut(search, node, nodep, foundname,
|
||||||
rdataset,
|
rdataset,
|
||||||
sigrdataset DNS__DB_FLARG_PASS);
|
sigrdataset DNS__DB_FLARG_PASS);
|
||||||
dns_name_copy(foundname, dcname);
|
if (dcname != NULL) {
|
||||||
goto tree_exit;
|
dns_name_copy(foundname, dcname);
|
||||||
|
}
|
||||||
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (nodep != NULL) {
|
if (nodep != NULL) {
|
||||||
qpcnode_acquire(search.qpdb, node, nlocktype,
|
qpcnode_acquire(search->qpdb, node, nlocktype,
|
||||||
tlocktype DNS__DB_FLARG_PASS);
|
*tlocktype DNS__DB_FLARG_PASS);
|
||||||
*nodep = (dns_dbnode_t *)node;
|
*nodep = (dns_dbnode_t *)node;
|
||||||
}
|
}
|
||||||
|
|
||||||
bindrdatasets(search.qpdb, node, found, foundsig, search.now, nlocktype,
|
bindrdatasets(search->qpdb, node, found, foundsig, search->now,
|
||||||
tlocktype, rdataset, sigrdataset DNS__DB_FLARG_PASS);
|
nlocktype, *tlocktype, rdataset,
|
||||||
maybe_update_headers(search.qpdb, found, foundsig, nlock, &nlocktype,
|
sigrdataset DNS__DB_FLARG_PASS);
|
||||||
search.now);
|
maybe_update_headers(search->qpdb, found, foundsig, nlock, &nlocktype,
|
||||||
|
search->now);
|
||||||
|
|
||||||
NODE_UNLOCK(nlock, &nlocktype);
|
NODE_UNLOCK(nlock, &nlocktype);
|
||||||
|
|
||||||
tree_exit:
|
return ISC_R_SUCCESS;
|
||||||
|
}
|
||||||
|
|
||||||
|
static isc_result_t
|
||||||
|
qpcache_findzonecut(dns_db_t *db, const dns_name_t *name, unsigned int options,
|
||||||
|
isc_stdtime_t __now, dns_dbnode_t **nodep,
|
||||||
|
dns_name_t *foundname, dns_name_t *dcname,
|
||||||
|
dns_rdataset_t *rdataset,
|
||||||
|
dns_rdataset_t *sigrdataset DNS__DB_FLARG) {
|
||||||
|
qpcnode_t *node = NULL;
|
||||||
|
isc_result_t result;
|
||||||
|
isc_rwlocktype_t tlocktype = isc_rwlocktype_none;
|
||||||
|
qpc_search_t search = (qpc_search_t){
|
||||||
|
.qpdb = (qpcache_t *)db,
|
||||||
|
.options = options,
|
||||||
|
.now = __now ? __now : isc_stdtime_now(),
|
||||||
|
};
|
||||||
|
unsigned int len = 0;
|
||||||
|
|
||||||
|
REQUIRE(VALID_QPDB((qpcache_t *)db));
|
||||||
|
|
||||||
|
TREE_RDLOCK(&search.qpdb->tree_lock, &tlocktype);
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Search down from the root of the tree.
|
||||||
|
*/
|
||||||
|
result = dns_qp_lookup(search.qpdb->tree, name, NULL, NULL,
|
||||||
|
&search.chain, (void **)&node, NULL);
|
||||||
|
|
||||||
|
switch (result) {
|
||||||
|
case ISC_R_SUCCESS:
|
||||||
|
if ((options & DNS_DBFIND_NOEXACT) == 0) {
|
||||||
|
if (dcname != NULL) {
|
||||||
|
dns_name_copy(&node->name, dcname);
|
||||||
|
}
|
||||||
|
dns_name_copy(&node->name, foundname);
|
||||||
|
result = seek_ns_headers(&search, node, nodep, rdataset,
|
||||||
|
sigrdataset, foundname, dcname,
|
||||||
|
&tlocktype);
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
len = dns_qpchain_length(&search.chain);
|
||||||
|
if (len < 2) {
|
||||||
|
result = ISC_R_NOTFOUND;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
FALLTHROUGH;
|
||||||
|
case DNS_R_PARTIALMATCH:
|
||||||
|
if (dcname != NULL) {
|
||||||
|
dns_name_copy(&node->name, dcname);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (result == ISC_R_SUCCESS) {
|
||||||
|
/* Fell through from the previous case */
|
||||||
|
INSIST(len >= 2);
|
||||||
|
|
||||||
|
node = NULL;
|
||||||
|
dns_qpchain_node(&search.chain, len - 2, NULL,
|
||||||
|
(void **)&node, NULL);
|
||||||
|
search.chain.len = len - 1;
|
||||||
|
}
|
||||||
|
|
||||||
|
result = find_deepest_zonecut(&search, node, nodep, foundname,
|
||||||
|
rdataset,
|
||||||
|
sigrdataset DNS__DB_FLARG_PASS);
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
TREE_UNLOCK(&search.qpdb->tree_lock, &tlocktype);
|
TREE_UNLOCK(&search.qpdb->tree_lock, &tlocktype);
|
||||||
|
|
||||||
INSIST(!search.need_cleanup);
|
INSIST(!search.need_cleanup);
|
||||||
|
|||||||
+46
-116
@@ -544,7 +544,7 @@ qpzone_destroy(qpzonedb_t *qpdb) {
|
|||||||
isc_refcount_decrementz(&qpdb->current_version->references);
|
isc_refcount_decrementz(&qpdb->current_version->references);
|
||||||
|
|
||||||
isc_refcount_destroy(&qpdb->current_version->references);
|
isc_refcount_destroy(&qpdb->current_version->references);
|
||||||
UNLINK(qpdb->open_versions, qpdb->current_version, link);
|
ISC_LIST_UNLINK(qpdb->open_versions, qpdb->current_version, link);
|
||||||
cds_wfs_destroy(&qpdb->current_version->glue_stack);
|
cds_wfs_destroy(&qpdb->current_version->glue_stack);
|
||||||
isc_rwlock_destroy(&qpdb->current_version->rwlock);
|
isc_rwlock_destroy(&qpdb->current_version->rwlock);
|
||||||
isc_mem_put(qpdb->common.mctx, qpdb->current_version,
|
isc_mem_put(qpdb->common.mctx, qpdb->current_version,
|
||||||
@@ -723,7 +723,7 @@ dns__qpzone_create(isc_mem_t *mctx, const dns_name_t *origin, dns_dbtype_t type,
|
|||||||
* Keep the current version in the open list so that list operation
|
* Keep the current version in the open list so that list operation
|
||||||
* won't happen in normal lookup operations.
|
* won't happen in normal lookup operations.
|
||||||
*/
|
*/
|
||||||
PREPEND(qpdb->open_versions, qpdb->current_version, link);
|
ISC_LIST_PREPEND(qpdb->open_versions, qpdb->current_version, link);
|
||||||
|
|
||||||
qpdb->common.magic = DNS_DB_MAGIC;
|
qpdb->common.magic = DNS_DB_MAGIC;
|
||||||
qpdb->common.impmagic = QPZONE_DB_MAGIC;
|
qpdb->common.impmagic = QPZONE_DB_MAGIC;
|
||||||
@@ -875,7 +875,6 @@ clean_zone_node(qpznode_t *node, uint32_t least_serial) {
|
|||||||
}
|
}
|
||||||
top_prev = current;
|
top_prev = current;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!still_dirty) {
|
if (!still_dirty) {
|
||||||
node->dirty = false;
|
node->dirty = false;
|
||||||
}
|
}
|
||||||
@@ -1125,13 +1124,13 @@ cleanup_nondirty(qpz_version_t *version, qpz_changedlist_t *cleanup_list) {
|
|||||||
*
|
*
|
||||||
* The caller must be holding the database lock.
|
* The caller must be holding the database lock.
|
||||||
*/
|
*/
|
||||||
for (changed = HEAD(version->changed_list); changed != NULL;
|
for (changed = ISC_LIST_HEAD(version->changed_list); changed != NULL;
|
||||||
changed = next_changed)
|
changed = next_changed)
|
||||||
{
|
{
|
||||||
next_changed = NEXT(changed, link);
|
next_changed = ISC_LIST_NEXT(changed, link);
|
||||||
if (!changed->dirty) {
|
if (!changed->dirty) {
|
||||||
UNLINK(version->changed_list, changed, link);
|
ISC_LIST_UNLINK(version->changed_list, changed, link);
|
||||||
APPEND(*cleanup_list, changed, link);
|
ISC_LIST_APPEND(*cleanup_list, changed, link);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -1378,12 +1377,13 @@ closeversion(dns_db_t *db, dns_dbversion_t **versionp,
|
|||||||
(void)isc_refcount_current(
|
(void)isc_refcount_current(
|
||||||
&cur_version->references);
|
&cur_version->references);
|
||||||
if (cur_version->serial == qpdb->least_serial) {
|
if (cur_version->serial == qpdb->least_serial) {
|
||||||
INSIST(EMPTY(
|
INSIST(ISC_LIST_EMPTY(
|
||||||
cur_version->changed_list));
|
cur_version->changed_list));
|
||||||
}
|
}
|
||||||
UNLINK(qpdb->open_versions, cur_version, link);
|
ISC_LIST_UNLINK(qpdb->open_versions,
|
||||||
|
cur_version, link);
|
||||||
}
|
}
|
||||||
if (EMPTY(qpdb->open_versions)) {
|
if (ISC_LIST_EMPTY(qpdb->open_versions)) {
|
||||||
/*
|
/*
|
||||||
* We're going to become the least open
|
* We're going to become the least open
|
||||||
* version.
|
* version.
|
||||||
@@ -1413,8 +1413,9 @@ closeversion(dns_db_t *db, dns_dbversion_t **versionp,
|
|||||||
*/
|
*/
|
||||||
if (cur_ref == 1) {
|
if (cur_ref == 1) {
|
||||||
cleanup_version = cur_version;
|
cleanup_version = cur_version;
|
||||||
APPENDLIST(version->changed_list,
|
ISC_LIST_APPENDLIST(
|
||||||
cleanup_version->changed_list, link);
|
version->changed_list,
|
||||||
|
cleanup_version->changed_list, link);
|
||||||
}
|
}
|
||||||
/*
|
/*
|
||||||
* Become the current version.
|
* Become the current version.
|
||||||
@@ -1433,8 +1434,8 @@ closeversion(dns_db_t *db, dns_dbversion_t **versionp,
|
|||||||
*/
|
*/
|
||||||
INSIST(isc_refcount_increment0(&version->references) ==
|
INSIST(isc_refcount_increment0(&version->references) ==
|
||||||
0);
|
0);
|
||||||
PREPEND(qpdb->open_versions, qpdb->current_version,
|
ISC_LIST_PREPEND(qpdb->open_versions,
|
||||||
link);
|
qpdb->current_version, link);
|
||||||
resigned_list = version->resigned_list;
|
resigned_list = version->resigned_list;
|
||||||
ISC_LIST_INIT(version->resigned_list);
|
ISC_LIST_INIT(version->resigned_list);
|
||||||
} else {
|
} else {
|
||||||
@@ -1461,7 +1462,7 @@ closeversion(dns_db_t *db, dns_dbversion_t **versionp,
|
|||||||
* Find the version with the least serial
|
* Find the version with the least serial
|
||||||
* number greater than ours.
|
* number greater than ours.
|
||||||
*/
|
*/
|
||||||
least_greater = PREV(version, link);
|
least_greater = ISC_LIST_PREV(version, link);
|
||||||
if (least_greater == NULL) {
|
if (least_greater == NULL) {
|
||||||
least_greater = qpdb->current_version;
|
least_greater = qpdb->current_version;
|
||||||
}
|
}
|
||||||
@@ -1482,20 +1483,21 @@ closeversion(dns_db_t *db, dns_dbversion_t **versionp,
|
|||||||
* Add any unexecuted cleanups to
|
* Add any unexecuted cleanups to
|
||||||
* those of the least greater version.
|
* those of the least greater version.
|
||||||
*/
|
*/
|
||||||
APPENDLIST(least_greater->changed_list,
|
ISC_LIST_APPENDLIST(least_greater->changed_list,
|
||||||
version->changed_list, link);
|
version->changed_list,
|
||||||
|
link);
|
||||||
}
|
}
|
||||||
} else if (version->serial == qpdb->least_serial) {
|
} else if (version->serial == qpdb->least_serial) {
|
||||||
INSIST(EMPTY(version->changed_list));
|
INSIST(ISC_LIST_EMPTY(version->changed_list));
|
||||||
}
|
}
|
||||||
UNLINK(qpdb->open_versions, version, link);
|
ISC_LIST_UNLINK(qpdb->open_versions, version, link);
|
||||||
}
|
}
|
||||||
least_serial = qpdb->least_serial;
|
least_serial = qpdb->least_serial;
|
||||||
RWUNLOCK(&qpdb->lock, isc_rwlocktype_write);
|
RWUNLOCK(&qpdb->lock, isc_rwlocktype_write);
|
||||||
|
|
||||||
if (cleanup_version != NULL) {
|
if (cleanup_version != NULL) {
|
||||||
isc_refcount_destroy(&cleanup_version->references);
|
isc_refcount_destroy(&cleanup_version->references);
|
||||||
INSIST(EMPTY(cleanup_version->changed_list));
|
INSIST(ISC_LIST_EMPTY(cleanup_version->changed_list));
|
||||||
cleanup_gluelists(&cleanup_version->glue_stack);
|
cleanup_gluelists(&cleanup_version->glue_stack);
|
||||||
cds_wfs_destroy(&cleanup_version->glue_stack);
|
cds_wfs_destroy(&cleanup_version->glue_stack);
|
||||||
isc_rwlock_destroy(&cleanup_version->rwlock);
|
isc_rwlock_destroy(&cleanup_version->rwlock);
|
||||||
@@ -1506,8 +1508,8 @@ closeversion(dns_db_t *db, dns_dbversion_t **versionp,
|
|||||||
/*
|
/*
|
||||||
* Commit/rollback re-signed headers.
|
* Commit/rollback re-signed headers.
|
||||||
*/
|
*/
|
||||||
for (header = HEAD(resigned_list); header != NULL;
|
for (header = ISC_LIST_HEAD(resigned_list); header != NULL;
|
||||||
header = HEAD(resigned_list))
|
header = ISC_LIST_HEAD(resigned_list))
|
||||||
{
|
{
|
||||||
isc_rwlock_t *nlock = NULL;
|
isc_rwlock_t *nlock = NULL;
|
||||||
isc_rwlocktype_t nlocktype = isc_rwlocktype_none;
|
isc_rwlocktype_t nlocktype = isc_rwlocktype_none;
|
||||||
@@ -1524,16 +1526,18 @@ closeversion(dns_db_t *db, dns_dbversion_t **versionp,
|
|||||||
NODE_UNLOCK(nlock, &nlocktype);
|
NODE_UNLOCK(nlock, &nlocktype);
|
||||||
}
|
}
|
||||||
|
|
||||||
dns_qp_t *tree = NULL, *nsec = NULL, *nsec3 = NULL;
|
if (ISC_LIST_EMPTY(cleanup_list)) {
|
||||||
bool need_tree = false, need_nsec = false, need_nsec3 = false;
|
*versionp = NULL;
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
for (changed = HEAD(cleanup_list); changed != NULL;
|
for (changed = ISC_LIST_HEAD(cleanup_list); changed != NULL;
|
||||||
changed = next_changed)
|
changed = next_changed)
|
||||||
{
|
{
|
||||||
isc_rwlock_t *nlock = NULL;
|
isc_rwlock_t *nlock = NULL;
|
||||||
isc_rwlocktype_t nlocktype = isc_rwlocktype_none;
|
isc_rwlocktype_t nlocktype = isc_rwlocktype_none;
|
||||||
|
|
||||||
next_changed = NEXT(changed, link);
|
next_changed = ISC_LIST_NEXT(changed, link);
|
||||||
node = changed->node;
|
node = changed->node;
|
||||||
nlock = &qpdb->buckets[node->locknum].lock;
|
nlock = &qpdb->buckets[node->locknum].lock;
|
||||||
|
|
||||||
@@ -1541,100 +1545,14 @@ closeversion(dns_db_t *db, dns_dbversion_t **versionp,
|
|||||||
if (rollback) {
|
if (rollback) {
|
||||||
rollback_node(node, serial);
|
rollback_node(node, serial);
|
||||||
}
|
}
|
||||||
|
|
||||||
qpznode_ref(node);
|
|
||||||
qpznode_release(qpdb, node, least_serial,
|
qpznode_release(qpdb, node, least_serial,
|
||||||
&nlocktype DNS__DB_FILELINE);
|
&nlocktype DNS__DB_FILELINE);
|
||||||
|
|
||||||
/* If the node is now empty, we can delete it. */
|
|
||||||
if (commit && node->data == NULL) {
|
|
||||||
switch ((int)node->nsec) {
|
|
||||||
case DNS_DB_NSEC_HAS_NSEC:
|
|
||||||
/*
|
|
||||||
* Delete the matching node from the NSEC tree
|
|
||||||
* first, then fall through to the main tree.
|
|
||||||
*/
|
|
||||||
if (nsec == NULL) {
|
|
||||||
need_nsec = true;
|
|
||||||
next_changed = changed;
|
|
||||||
} else {
|
|
||||||
dns_qp_deletename(nsec, &node->name,
|
|
||||||
NULL, NULL);
|
|
||||||
}
|
|
||||||
FALLTHROUGH;
|
|
||||||
case DNS_DB_NSEC_NORMAL:
|
|
||||||
if (tree == NULL) {
|
|
||||||
need_tree = true;
|
|
||||||
next_changed = changed;
|
|
||||||
} else {
|
|
||||||
dns_qp_deletename(tree, &node->name,
|
|
||||||
NULL, NULL);
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
case DNS_DB_NSEC_NSEC:
|
|
||||||
if (nsec == NULL) {
|
|
||||||
need_nsec = true;
|
|
||||||
next_changed = changed;
|
|
||||||
} else {
|
|
||||||
dns_qp_deletename(nsec, &node->name,
|
|
||||||
NULL, NULL);
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
case DNS_DB_NSEC_NSEC3:
|
|
||||||
if (nsec3 == NULL) {
|
|
||||||
need_nsec3 = true;
|
|
||||||
next_changed = changed;
|
|
||||||
} else {
|
|
||||||
dns_qp_deletename(nsec3, &node->name,
|
|
||||||
NULL, NULL);
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
default:
|
|
||||||
UNREACHABLE();
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
qpznode_detach(&node);
|
|
||||||
|
|
||||||
NODE_UNLOCK(nlock, &nlocktype);
|
NODE_UNLOCK(nlock, &nlocktype);
|
||||||
|
|
||||||
if (next_changed == changed) {
|
|
||||||
/*
|
|
||||||
* We found a node to delete but didn't have a
|
|
||||||
* QP writer open, so we open one now, then go
|
|
||||||
* back to delete the node. If there's a next
|
|
||||||
* time, we'll already have the writer open,
|
|
||||||
* so we won't need this extra step.
|
|
||||||
*/
|
|
||||||
if (need_tree && tree == NULL) {
|
|
||||||
dns_qpmulti_write(qpdb->tree, &tree);
|
|
||||||
}
|
|
||||||
if (need_nsec && nsec == NULL) {
|
|
||||||
dns_qpmulti_write(qpdb->nsec, &nsec);
|
|
||||||
}
|
|
||||||
if (need_nsec3 && nsec3 == NULL) {
|
|
||||||
dns_qpmulti_write(qpdb->nsec3, &nsec3);
|
|
||||||
}
|
|
||||||
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
|
|
||||||
isc_mem_put(qpdb->common.mctx, changed, sizeof(*changed));
|
isc_mem_put(qpdb->common.mctx, changed, sizeof(*changed));
|
||||||
}
|
}
|
||||||
|
|
||||||
if (tree != NULL) {
|
|
||||||
dns_qp_compact(tree, DNS_QPGC_MAYBE);
|
|
||||||
dns_qpmulti_commit(qpdb->tree, &tree);
|
|
||||||
}
|
|
||||||
if (nsec != NULL) {
|
|
||||||
dns_qp_compact(nsec, DNS_QPGC_MAYBE);
|
|
||||||
dns_qpmulti_commit(qpdb->nsec, &nsec);
|
|
||||||
}
|
|
||||||
if (nsec3 != NULL) {
|
|
||||||
dns_qp_compact(nsec3, DNS_QPGC_MAYBE);
|
|
||||||
dns_qpmulti_commit(qpdb->nsec3, &nsec3);
|
|
||||||
}
|
|
||||||
|
|
||||||
*versionp = NULL;
|
*versionp = NULL;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -2778,13 +2696,25 @@ step(qpz_search_t *search, dns_qpiter_t *it, direction_t direction,
|
|||||||
while (result == ISC_R_SUCCESS) {
|
while (result == ISC_R_SUCCESS) {
|
||||||
isc_rwlock_t *nlock = &qpdb->buckets[node->locknum].lock;
|
isc_rwlock_t *nlock = &qpdb->buckets[node->locknum].lock;
|
||||||
isc_rwlocktype_t nlocktype = isc_rwlocktype_none;
|
isc_rwlocktype_t nlocktype = isc_rwlocktype_none;
|
||||||
|
dns_slabheader_t *header_next = NULL;
|
||||||
|
|
||||||
NODE_RDLOCK(nlock, &nlocktype);
|
NODE_RDLOCK(nlock, &nlocktype);
|
||||||
for (header = node->data; header != NULL; header = header->next)
|
for (header = node->data; header != NULL; header = header_next)
|
||||||
{
|
{
|
||||||
if (header->serial <= search->serial &&
|
header_next = header->next;
|
||||||
!IGNORE(header) && !NONEXISTENT(header))
|
while (header != NULL) {
|
||||||
{
|
if (header->serial <= search->serial &&
|
||||||
|
!IGNORE(header))
|
||||||
|
{
|
||||||
|
if (NONEXISTENT(header)) {
|
||||||
|
header = NULL;
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
} else {
|
||||||
|
header = header->down;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (header != NULL) {
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
-107
@@ -2354,113 +2354,6 @@ dns_rdata_covers(dns_rdata_t *rdata) {
|
|||||||
return covers_sig(rdata);
|
return covers_sig(rdata);
|
||||||
}
|
}
|
||||||
|
|
||||||
bool
|
|
||||||
dns_rdatatype_ismeta(dns_rdatatype_t type) {
|
|
||||||
if ((dns_rdatatype_attributes(type) & DNS_RDATATYPEATTR_META) != 0) {
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
|
|
||||||
bool
|
|
||||||
dns_rdatatype_issingleton(dns_rdatatype_t type) {
|
|
||||||
if ((dns_rdatatype_attributes(type) & DNS_RDATATYPEATTR_SINGLETON) != 0)
|
|
||||||
{
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
|
|
||||||
bool
|
|
||||||
dns_rdatatype_notquestion(dns_rdatatype_t type) {
|
|
||||||
if ((dns_rdatatype_attributes(type) & DNS_RDATATYPEATTR_NOTQUESTION) !=
|
|
||||||
0)
|
|
||||||
{
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
|
|
||||||
bool
|
|
||||||
dns_rdatatype_questiononly(dns_rdatatype_t type) {
|
|
||||||
if ((dns_rdatatype_attributes(type) & DNS_RDATATYPEATTR_QUESTIONONLY) !=
|
|
||||||
0)
|
|
||||||
{
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
|
|
||||||
bool
|
|
||||||
dns_rdatatype_atcname(dns_rdatatype_t type) {
|
|
||||||
if ((dns_rdatatype_attributes(type) & DNS_RDATATYPEATTR_ATCNAME) != 0) {
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
|
|
||||||
bool
|
|
||||||
dns_rdatatype_atparent(dns_rdatatype_t type) {
|
|
||||||
if ((dns_rdatatype_attributes(type) & DNS_RDATATYPEATTR_ATPARENT) != 0)
|
|
||||||
{
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
|
|
||||||
bool
|
|
||||||
dns_rdatatype_followadditional(dns_rdatatype_t type) {
|
|
||||||
if ((dns_rdatatype_attributes(type) &
|
|
||||||
DNS_RDATATYPEATTR_FOLLOWADDITIONAL) != 0)
|
|
||||||
{
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
|
|
||||||
bool
|
|
||||||
dns_rdataclass_ismeta(dns_rdataclass_t rdclass) {
|
|
||||||
if (rdclass == dns_rdataclass_reserved0 ||
|
|
||||||
rdclass == dns_rdataclass_none || rdclass == dns_rdataclass_any)
|
|
||||||
{
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
|
|
||||||
return false; /* Assume it is not a meta class. */
|
|
||||||
}
|
|
||||||
|
|
||||||
bool
|
|
||||||
dns_rdatatype_isdnssec(dns_rdatatype_t type) {
|
|
||||||
if ((dns_rdatatype_attributes(type) & DNS_RDATATYPEATTR_DNSSEC) != 0) {
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
|
|
||||||
bool
|
|
||||||
dns_rdatatype_iskeymaterial(dns_rdatatype_t type) {
|
|
||||||
return type == dns_rdatatype_dnskey || type == dns_rdatatype_cdnskey ||
|
|
||||||
type == dns_rdatatype_cds;
|
|
||||||
}
|
|
||||||
|
|
||||||
bool
|
|
||||||
dns_rdatatype_iszonecutauth(dns_rdatatype_t type) {
|
|
||||||
if ((dns_rdatatype_attributes(type) & DNS_RDATATYPEATTR_ZONECUTAUTH) !=
|
|
||||||
0)
|
|
||||||
{
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
|
|
||||||
bool
|
|
||||||
dns_rdatatype_isknown(dns_rdatatype_t type) {
|
|
||||||
if ((dns_rdatatype_attributes(type) & DNS_RDATATYPEATTR_UNKNOWN) == 0) {
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
|
|
||||||
void
|
void
|
||||||
dns_rdata_exists(dns_rdata_t *rdata, dns_rdatatype_t type) {
|
dns_rdata_exists(dns_rdata_t *rdata, dns_rdatatype_t type) {
|
||||||
REQUIRE(rdata != NULL);
|
REQUIRE(rdata != NULL);
|
||||||
|
|||||||
@@ -387,6 +387,9 @@ static int
|
|||||||
compare_rrsig(ARGS_COMPARE) {
|
compare_rrsig(ARGS_COMPARE) {
|
||||||
isc_region_t r1;
|
isc_region_t r1;
|
||||||
isc_region_t r2;
|
isc_region_t r2;
|
||||||
|
dns_name_t name1;
|
||||||
|
dns_name_t name2;
|
||||||
|
int order;
|
||||||
|
|
||||||
REQUIRE(rdata1->type == rdata2->type);
|
REQUIRE(rdata1->type == rdata2->type);
|
||||||
REQUIRE(rdata1->rdclass == rdata2->rdclass);
|
REQUIRE(rdata1->rdclass == rdata2->rdclass);
|
||||||
@@ -396,6 +399,32 @@ compare_rrsig(ARGS_COMPARE) {
|
|||||||
|
|
||||||
dns_rdata_toregion(rdata1, &r1);
|
dns_rdata_toregion(rdata1, &r1);
|
||||||
dns_rdata_toregion(rdata2, &r2);
|
dns_rdata_toregion(rdata2, &r2);
|
||||||
|
|
||||||
|
INSIST(r1.length > 18);
|
||||||
|
INSIST(r2.length > 18);
|
||||||
|
r1.length = 18;
|
||||||
|
r2.length = 18;
|
||||||
|
order = isc_region_compare(&r1, &r2);
|
||||||
|
if (order != 0) {
|
||||||
|
return order;
|
||||||
|
}
|
||||||
|
|
||||||
|
dns_name_init(&name1);
|
||||||
|
dns_name_init(&name2);
|
||||||
|
dns_rdata_toregion(rdata1, &r1);
|
||||||
|
dns_rdata_toregion(rdata2, &r2);
|
||||||
|
isc_region_consume(&r1, 18);
|
||||||
|
isc_region_consume(&r2, 18);
|
||||||
|
dns_name_fromregion(&name1, &r1);
|
||||||
|
dns_name_fromregion(&name2, &r2);
|
||||||
|
order = dns_name_rdatacompare(&name1, &name2);
|
||||||
|
if (order != 0) {
|
||||||
|
return order;
|
||||||
|
}
|
||||||
|
|
||||||
|
isc_region_consume(&r1, name_length(&name1));
|
||||||
|
isc_region_consume(&r2, name_length(&name2));
|
||||||
|
|
||||||
return isc_region_compare(&r1, &r2);
|
return isc_region_compare(&r1, &r2);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -563,13 +592,32 @@ additionaldata_rrsig(ARGS_ADDLDATA) {
|
|||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
digest_rrsig(ARGS_DIGEST) {
|
digest_rrsig(ARGS_DIGEST) {
|
||||||
|
isc_region_t r1, r2;
|
||||||
|
dns_name_t name;
|
||||||
|
|
||||||
REQUIRE(rdata->type == dns_rdatatype_rrsig);
|
REQUIRE(rdata->type == dns_rdatatype_rrsig);
|
||||||
|
|
||||||
UNUSED(rdata);
|
dns_rdata_toregion(rdata, &r1);
|
||||||
UNUSED(digest);
|
r2 = r1;
|
||||||
UNUSED(arg);
|
|
||||||
|
|
||||||
return ISC_R_NOTIMPLEMENTED;
|
/*
|
||||||
|
* Type covered (2) + Algorithm (1) +
|
||||||
|
* Labels (1) + Original TTL (4) +
|
||||||
|
* Expire time (4) + Time signed (4) +
|
||||||
|
* Key ID (2).
|
||||||
|
*/
|
||||||
|
isc_region_consume(&r2, 18);
|
||||||
|
r1.length = 18;
|
||||||
|
RETERR((digest)(arg, &r1));
|
||||||
|
|
||||||
|
/* Signer */
|
||||||
|
dns_name_init(&name);
|
||||||
|
dns_name_fromregion(&name, &r2);
|
||||||
|
RETERR(dns_name_digest(&name, digest, arg));
|
||||||
|
isc_region_consume(&r2, name_length(&name));
|
||||||
|
|
||||||
|
/* Signature */
|
||||||
|
return (digest)(arg, &r2);
|
||||||
}
|
}
|
||||||
|
|
||||||
static dns_rdatatype_t
|
static dns_rdatatype_t
|
||||||
@@ -610,47 +658,7 @@ checknames_rrsig(ARGS_CHECKNAMES) {
|
|||||||
|
|
||||||
static int
|
static int
|
||||||
casecompare_rrsig(ARGS_COMPARE) {
|
casecompare_rrsig(ARGS_COMPARE) {
|
||||||
isc_region_t r1;
|
return compare_rrsig(rdata1, rdata2);
|
||||||
isc_region_t r2;
|
|
||||||
dns_name_t name1;
|
|
||||||
dns_name_t name2;
|
|
||||||
int order;
|
|
||||||
|
|
||||||
REQUIRE(rdata1->type == rdata2->type);
|
|
||||||
REQUIRE(rdata1->rdclass == rdata2->rdclass);
|
|
||||||
REQUIRE(rdata1->type == dns_rdatatype_rrsig);
|
|
||||||
REQUIRE(rdata1->length != 0);
|
|
||||||
REQUIRE(rdata2->length != 0);
|
|
||||||
|
|
||||||
dns_rdata_toregion(rdata1, &r1);
|
|
||||||
dns_rdata_toregion(rdata2, &r2);
|
|
||||||
|
|
||||||
INSIST(r1.length > 18);
|
|
||||||
INSIST(r2.length > 18);
|
|
||||||
r1.length = 18;
|
|
||||||
r2.length = 18;
|
|
||||||
order = isc_region_compare(&r1, &r2);
|
|
||||||
if (order != 0) {
|
|
||||||
return order;
|
|
||||||
}
|
|
||||||
|
|
||||||
dns_name_init(&name1);
|
|
||||||
dns_name_init(&name2);
|
|
||||||
dns_rdata_toregion(rdata1, &r1);
|
|
||||||
dns_rdata_toregion(rdata2, &r2);
|
|
||||||
isc_region_consume(&r1, 18);
|
|
||||||
isc_region_consume(&r2, 18);
|
|
||||||
dns_name_fromregion(&name1, &r1);
|
|
||||||
dns_name_fromregion(&name2, &r2);
|
|
||||||
order = dns_name_rdatacompare(&name1, &name2);
|
|
||||||
if (order != 0) {
|
|
||||||
return order;
|
|
||||||
}
|
|
||||||
|
|
||||||
isc_region_consume(&r1, name_length(&name1));
|
|
||||||
isc_region_consume(&r2, name_length(&name2));
|
|
||||||
|
|
||||||
return isc_region_compare(&r1, &r2);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
#endif /* RDATA_GENERIC_RRSIG_46_C */
|
#endif /* RDATA_GENERIC_RRSIG_46_C */
|
||||||
|
|||||||
@@ -556,13 +556,32 @@ additionaldata_sig(ARGS_ADDLDATA) {
|
|||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
digest_sig(ARGS_DIGEST) {
|
digest_sig(ARGS_DIGEST) {
|
||||||
|
isc_region_t r1, r2;
|
||||||
|
dns_name_t name;
|
||||||
|
|
||||||
REQUIRE(rdata->type == dns_rdatatype_sig);
|
REQUIRE(rdata->type == dns_rdatatype_sig);
|
||||||
|
|
||||||
UNUSED(rdata);
|
dns_rdata_toregion(rdata, &r1);
|
||||||
UNUSED(digest);
|
r2 = r1;
|
||||||
UNUSED(arg);
|
|
||||||
|
|
||||||
return ISC_R_NOTIMPLEMENTED;
|
/*
|
||||||
|
* Type covered (2) + Algorithm (1) +
|
||||||
|
* Labels (1) + Original TTL (4) +
|
||||||
|
* Expire time (4) + Time signed (4) +
|
||||||
|
* Key ID (2).
|
||||||
|
*/
|
||||||
|
isc_region_consume(&r2, 18);
|
||||||
|
r1.length = 18;
|
||||||
|
RETERR((digest)(arg, &r1));
|
||||||
|
|
||||||
|
/* Signer */
|
||||||
|
dns_name_init(&name);
|
||||||
|
dns_name_fromregion(&name, &r2);
|
||||||
|
RETERR(dns_name_digest(&name, digest, arg));
|
||||||
|
isc_region_consume(&r2, name_length(&name));
|
||||||
|
|
||||||
|
/* Signature */
|
||||||
|
return (digest)(arg, &r2);
|
||||||
}
|
}
|
||||||
|
|
||||||
static dns_rdatatype_t
|
static dns_rdatatype_t
|
||||||
|
|||||||
+1048
-1245
File diff suppressed because it is too large
Load Diff
+1
-1
@@ -752,7 +752,7 @@ findrdataset(dns_db_t *db, dns_dbnode_t *node, dns_dbversion_t *version,
|
|||||||
UNUSED(now);
|
UNUSED(now);
|
||||||
UNUSED(sigrdataset);
|
UNUSED(sigrdataset);
|
||||||
|
|
||||||
if (type == dns_rdatatype_sig || type == dns_rdatatype_rrsig) {
|
if (dns_rdatatype_issig(type)) {
|
||||||
return ISC_R_NOTIMPLEMENTED;
|
return ISC_R_NOTIMPLEMENTED;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+38
-20
@@ -182,6 +182,9 @@ expire_rdatasets(dns_validator_t *val) {
|
|||||||
static void
|
static void
|
||||||
validate_extendederror(dns_validator_t *val);
|
validate_extendederror(dns_validator_t *val);
|
||||||
|
|
||||||
|
static void
|
||||||
|
validator_addede(dns_validator_t *val, uint16_t code, const char *extra);
|
||||||
|
|
||||||
/*%
|
/*%
|
||||||
* Ensure the validator's rdatasets are disassociated.
|
* Ensure the validator's rdatasets are disassociated.
|
||||||
*/
|
*/
|
||||||
@@ -1474,6 +1477,11 @@ again:
|
|||||||
* Temporal errors don't count towards max validations nor max
|
* Temporal errors don't count towards max validations nor max
|
||||||
* fails.
|
* fails.
|
||||||
*/
|
*/
|
||||||
|
validator_addede(val,
|
||||||
|
result == DNS_R_SIGEXPIRED
|
||||||
|
? DNS_EDE_SIGNATUREEXPIRED
|
||||||
|
: DNS_EDE_SIGNATURENOTYETVALID,
|
||||||
|
NULL);
|
||||||
break;
|
break;
|
||||||
case ISC_R_SUCCESS:
|
case ISC_R_SUCCESS:
|
||||||
consume_validation(val);
|
consume_validation(val);
|
||||||
@@ -3627,44 +3635,54 @@ validator_logcreate(dns_validator_t *val, dns_name_t *name,
|
|||||||
}
|
}
|
||||||
|
|
||||||
static void
|
static void
|
||||||
validate_extendederror(dns_validator_t *val) {
|
validator_addede(dns_validator_t *val, uint16_t code, const char *extra) {
|
||||||
REQUIRE(VALID_VALIDATOR(val));
|
REQUIRE(VALID_VALIDATOR(val));
|
||||||
|
|
||||||
char extra[DNS_NAME_FORMATSIZE + DNS_RDATATYPE_FORMATSIZE +
|
char bdata[DNS_NAME_FORMATSIZE + DNS_RDATATYPE_FORMATSIZE +
|
||||||
DNS_EDE_EXTRATEXT_LEN];
|
DNS_EDE_EXTRATEXT_LEN];
|
||||||
isc_buffer_t b;
|
isc_buffer_t b;
|
||||||
|
|
||||||
|
isc_buffer_init(&b, bdata, sizeof(bdata));
|
||||||
|
|
||||||
|
if (extra != NULL) {
|
||||||
|
isc_buffer_putstr(&b, extra);
|
||||||
|
isc_buffer_putuint8(&b, ' ');
|
||||||
|
}
|
||||||
|
|
||||||
|
dns_name_totext(val->name, DNS_NAME_OMITFINALDOT, &b);
|
||||||
|
isc_buffer_putuint8(&b, '/');
|
||||||
|
dns_rdatatype_totext(val->type, &b);
|
||||||
|
isc_buffer_putuint8(&b, '\0');
|
||||||
|
|
||||||
|
dns_ede_add(val->edectx, code, bdata);
|
||||||
|
}
|
||||||
|
|
||||||
|
static void
|
||||||
|
validate_extendederror(dns_validator_t *val) {
|
||||||
dns_validator_t *edeval = val;
|
dns_validator_t *edeval = val;
|
||||||
|
char bdata[DNS_EDE_EXTRATEXT_LEN];
|
||||||
|
isc_buffer_t b;
|
||||||
|
|
||||||
|
REQUIRE(VALID_VALIDATOR(edeval));
|
||||||
|
|
||||||
|
isc_buffer_init(&b, bdata, sizeof(bdata));
|
||||||
|
|
||||||
while (edeval->parent != NULL) {
|
while (edeval->parent != NULL) {
|
||||||
edeval = edeval->parent;
|
edeval = edeval->parent;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (val->unsupported_algorithm != 0) {
|
if (val->unsupported_algorithm != 0) {
|
||||||
isc_buffer_init(&b, extra, sizeof(extra));
|
isc_buffer_clear(&b);
|
||||||
dns_secalg_totext(val->unsupported_algorithm, &b);
|
dns_secalg_totext(val->unsupported_algorithm, &b);
|
||||||
|
|
||||||
isc_buffer_putuint8(&b, ' ');
|
|
||||||
dns_name_totext(val->name, DNS_NAME_OMITFINALDOT, &b);
|
|
||||||
isc_buffer_putuint8(&b, '/');
|
|
||||||
dns_rdatatype_totext(val->type, &b);
|
|
||||||
isc_buffer_putuint8(&b, '\0');
|
isc_buffer_putuint8(&b, '\0');
|
||||||
|
validator_addede(val, DNS_EDE_DNSKEYALG, bdata);
|
||||||
dns_ede_add(val->edectx, DNS_EDE_DNSKEYALG, extra);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (val->unsupported_digest != 0) {
|
if (val->unsupported_digest != 0) {
|
||||||
isc_buffer_init(&b, extra, sizeof(extra));
|
isc_buffer_clear(&b);
|
||||||
|
|
||||||
dns_dsdigest_totext(val->unsupported_digest, &b);
|
dns_dsdigest_totext(val->unsupported_digest, &b);
|
||||||
isc_buffer_putuint8(&b, ' ');
|
|
||||||
dns_name_totext(val->name, DNS_NAME_OMITFINALDOT, &b);
|
|
||||||
isc_buffer_putuint8(&b, '/');
|
|
||||||
dns_rdatatype_totext(val->type, &b);
|
|
||||||
isc_buffer_putuint8(&b, '\0');
|
isc_buffer_putuint8(&b, '\0');
|
||||||
|
validator_addede(val, DNS_EDE_DSDIGESTTYPE, bdata);
|
||||||
dns_ede_add(val->edectx, DNS_EDE_DSDIGESTTYPE, extra);
|
|
||||||
|
|
||||||
isc_buffer_invalidate(&b);
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+7
-17
@@ -1533,41 +1533,31 @@ dns_view_ntacovers(dns_view_t *view, isc_stdtime_t now, const dns_name_t *name,
|
|||||||
return dns_ntatable_covered(view->ntatable_priv, now, name, anchor);
|
return dns_ntatable_covered(view->ntatable_priv, now, name, anchor);
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_result_t
|
bool
|
||||||
dns_view_issecuredomain(dns_view_t *view, const dns_name_t *name,
|
dns_view_issecuredomain(dns_view_t *view, const dns_name_t *name,
|
||||||
isc_stdtime_t now, bool checknta, bool *ntap,
|
isc_stdtime_t now, bool checknta, bool *ntap) {
|
||||||
bool *secure_domain) {
|
|
||||||
isc_result_t result;
|
|
||||||
bool secure = false;
|
bool secure = false;
|
||||||
dns_fixedname_t fn;
|
dns_fixedname_t fn;
|
||||||
dns_name_t *anchor;
|
dns_name_t *anchor;
|
||||||
|
|
||||||
REQUIRE(DNS_VIEW_VALID(view));
|
REQUIRE(DNS_VIEW_VALID(view));
|
||||||
|
|
||||||
if (view->secroots_priv == NULL) {
|
if (!view->enablevalidation || view->secroots_priv == NULL) {
|
||||||
return ISC_R_NOTFOUND;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
anchor = dns_fixedname_initname(&fn);
|
anchor = dns_fixedname_initname(&fn);
|
||||||
|
secure = dns_keytable_issecuredomain(view->secroots_priv, name, anchor);
|
||||||
result = dns_keytable_issecuredomain(view->secroots_priv, name, anchor,
|
|
||||||
&secure);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
return result;
|
|
||||||
}
|
|
||||||
|
|
||||||
SET_IF_NOT_NULL(ntap, false);
|
SET_IF_NOT_NULL(ntap, false);
|
||||||
if (checknta && secure && view->ntatable_priv != NULL &&
|
if (checknta && secure && view->ntatable_priv != NULL &&
|
||||||
dns_ntatable_covered(view->ntatable_priv, now, name, anchor))
|
dns_ntatable_covered(view->ntatable_priv, now, name, anchor))
|
||||||
{
|
{
|
||||||
if (ntap != NULL) {
|
SET_IF_NOT_NULL(ntap, true);
|
||||||
*ntap = true;
|
|
||||||
}
|
|
||||||
secure = false;
|
secure = false;
|
||||||
}
|
}
|
||||||
|
|
||||||
*secure_domain = secure;
|
return secure;
|
||||||
return ISC_R_SUCCESS;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
void
|
void
|
||||||
|
|||||||
+12
-6
@@ -18385,18 +18385,22 @@ dns_zone_getsourceaddr(dns_zone_t *zone) {
|
|||||||
return sourceaddr;
|
return sourceaddr;
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_sockaddr_t
|
isc_result_t
|
||||||
dns_zone_getprimaryaddr(dns_zone_t *zone) {
|
dns_zone_getprimaryaddr(dns_zone_t *zone, isc_sockaddr_t *dest) {
|
||||||
isc_sockaddr_t curraddr;
|
isc_result_t result = ISC_R_NOMORE;
|
||||||
|
|
||||||
REQUIRE(DNS_ZONE_VALID(zone));
|
REQUIRE(DNS_ZONE_VALID(zone));
|
||||||
|
REQUIRE(dest != NULL);
|
||||||
|
|
||||||
LOCK_ZONE(zone);
|
LOCK_ZONE(zone);
|
||||||
INSIST(dns_remote_count(&zone->primaries) > 0);
|
INSIST(dns_remote_count(&zone->primaries) > 0);
|
||||||
curraddr = dns_remote_curraddr(&zone->primaries);
|
if (!dns_remote_done(&zone->primaries)) {
|
||||||
|
*dest = dns_remote_curraddr(&zone->primaries);
|
||||||
|
result = ISC_R_SUCCESS;
|
||||||
|
}
|
||||||
UNLOCK_ZONE(zone);
|
UNLOCK_ZONE(zone);
|
||||||
|
|
||||||
return curraddr;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_time_t
|
isc_time_t
|
||||||
@@ -18457,7 +18461,9 @@ get_request_transport_type(dns_zone_t *zone) {
|
|||||||
: DNS_TRANSPORT_UDP;
|
: DNS_TRANSPORT_UDP;
|
||||||
|
|
||||||
/* Check if the peer is forced to always use TCP. */
|
/* Check if the peer is forced to always use TCP. */
|
||||||
if (transport_type != DNS_TRANSPORT_TCP) {
|
if (transport_type != DNS_TRANSPORT_TCP &&
|
||||||
|
!dns_remote_done(&zone->primaries))
|
||||||
|
{
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
isc_sockaddr_t primaryaddr;
|
isc_sockaddr_t primaryaddr;
|
||||||
isc_netaddr_t primaryip;
|
isc_netaddr_t primaryip;
|
||||||
|
|||||||
@@ -15,7 +15,6 @@ libisc_la_HEADERS = \
|
|||||||
include/isc/base64.h \
|
include/isc/base64.h \
|
||||||
include/isc/buffer.h \
|
include/isc/buffer.h \
|
||||||
include/isc/commandline.h \
|
include/isc/commandline.h \
|
||||||
include/isc/condition.h \
|
|
||||||
include/isc/counter.h \
|
include/isc/counter.h \
|
||||||
include/isc/crypto.h \
|
include/isc/crypto.h \
|
||||||
include/isc/dir.h \
|
include/isc/dir.h \
|
||||||
@@ -25,7 +24,6 @@ libisc_la_HEADERS = \
|
|||||||
include/isc/errno.h \
|
include/isc/errno.h \
|
||||||
include/isc/error.h \
|
include/isc/error.h \
|
||||||
include/isc/file.h \
|
include/isc/file.h \
|
||||||
include/isc/fips.h \
|
|
||||||
include/isc/formatcheck.h \
|
include/isc/formatcheck.h \
|
||||||
include/isc/fuzz.h \
|
include/isc/fuzz.h \
|
||||||
include/isc/getaddresses.h \
|
include/isc/getaddresses.h \
|
||||||
@@ -52,7 +50,6 @@ libisc_la_HEADERS = \
|
|||||||
include/isc/mem.h \
|
include/isc/mem.h \
|
||||||
include/isc/meminfo.h \
|
include/isc/meminfo.h \
|
||||||
include/isc/mutex.h \
|
include/isc/mutex.h \
|
||||||
include/isc/mutexblock.h \
|
|
||||||
include/isc/net.h \
|
include/isc/net.h \
|
||||||
include/isc/netaddr.h \
|
include/isc/netaddr.h \
|
||||||
include/isc/netmgr.h \
|
include/isc/netmgr.h \
|
||||||
@@ -123,7 +120,6 @@ libisc_la_SOURCES = \
|
|||||||
base32.c \
|
base32.c \
|
||||||
base64.c \
|
base64.c \
|
||||||
commandline.c \
|
commandline.c \
|
||||||
condition.c \
|
|
||||||
counter.c \
|
counter.c \
|
||||||
crypto.c \
|
crypto.c \
|
||||||
dir.c \
|
dir.c \
|
||||||
@@ -133,7 +129,6 @@ libisc_la_SOURCES = \
|
|||||||
errno2result.h \
|
errno2result.h \
|
||||||
error.c \
|
error.c \
|
||||||
file.c \
|
file.c \
|
||||||
fips.c \
|
|
||||||
getaddresses.c \
|
getaddresses.c \
|
||||||
hash.c \
|
hash.c \
|
||||||
hashmap.c \
|
hashmap.c \
|
||||||
@@ -161,7 +156,6 @@ libisc_la_SOURCES = \
|
|||||||
meminfo.c \
|
meminfo.c \
|
||||||
mutex.c \
|
mutex.c \
|
||||||
mutex_p.h \
|
mutex_p.h \
|
||||||
mutexblock.c \
|
|
||||||
net.c \
|
net.c \
|
||||||
netaddr.c \
|
netaddr.c \
|
||||||
netscope.c \
|
netscope.c \
|
||||||
|
|||||||
@@ -18,7 +18,6 @@
|
|||||||
#include <isc/async.h>
|
#include <isc/async.h>
|
||||||
#include <isc/atomic.h>
|
#include <isc/atomic.h>
|
||||||
#include <isc/barrier.h>
|
#include <isc/barrier.h>
|
||||||
#include <isc/condition.h>
|
|
||||||
#include <isc/job.h>
|
#include <isc/job.h>
|
||||||
#include <isc/loop.h>
|
#include <isc/loop.h>
|
||||||
#include <isc/magic.h>
|
#include <isc/magic.h>
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user