Compare commits

..
Author SHA1 Message Date
Ondřej Surý 8fdbf3171a Revert "Skip the runtime ellipsis test"
This reverts commit 161e02845f.
2019-11-26 12:13:07 +01:00
Evan HuntandOndřej Surý 8fa02de98d fixed a test failure, some other shell cleanup 2019-11-26 12:11:59 +01:00
Ondřej Surý cff65624e0 Detect cores on FreeBSD 2019-11-26 12:11:59 +01:00
Ondřej Surý ca4b4bf421 Request exclusive access when crashing via fatal()
When loading the configuration fails, there might be already other tasks
running and calling OpenSSL library functions.  The OpenSSL on_exit
handler is called when exiting the main process and there's a timing
race between the on_exit function that destroys OpenSSL allocated
resources (threads, locks, ...) and other tasks accessing the very same
resources leading to a crash in the system threading library. Therefore,
the fatal() function needs to request exlusive access to the task
manager to finish the already running tasks and exit only when no other
tasks are running.
2019-11-26 12:11:59 +01:00
Ondřej SurýandOndřej Surý bc66044246 Instead of sleeping for a fixed time, wait for named to log specific message in a loop 2019-11-26 12:11:59 +01:00
Ondřej SurýandOndřej Surý d52fa06bc1 Use pre-prepared long command line for better portability 2019-11-26 12:11:59 +01:00
Ondřej SurýandOndřej Surý 34a4ceeb1c Make runtime/tests.sh shellcheck and set -e clean
This mostly comprises of:

* using $(...) instead of `...`
* changing the directories in subshell and not ignoring `cd` return code
* handling every error gracefully instead of ignoring the return code
2019-11-26 12:11:06 +01:00
Ondřej SurýandOndřej Surý 207b449fab Further improve the runtime tests to look for a specific instead of generic error 2019-11-26 12:11:06 +01:00
Ondřej SurýandOndřej Surý d953cabb26 The PATH_MAX on macOS is 1024, we can't override conffile path to test for ellipsis 2019-11-26 12:11:06 +01:00
Ondřej SurýandOndřej Surý 6d319355b8 Fix couple of no-op tests to actually test something (configuration files were missing) 2019-11-26 12:11:06 +01:00
Ondřej SurýandOndřej Surý 161e02845f Skip the runtime ellipsis test 2019-11-26 12:11:06 +01:00
Ondřej SurýandOndřej Surý c89ceb5ad3 runtime test: make the pidfiles match the names of configuration files 2019-11-26 12:11:06 +01:00
Ondřej SurýandOndřej Surý 01688a6cf5 runtime test: use helper function that kills named and waits for the finish 2019-11-26 12:11:06 +01:00
377 changed files with 7394 additions and 7725 deletions
-8
View File
@@ -1,10 +1,2 @@
*.sln.in eol=crlf *.sln.in eol=crlf
*.vcxproj.* eol=crlf *.vcxproj.* eol=crlf
.gitignore export-ignore
/conftools export-ignore
/doc/design export-ignore
/doc/dev export-ignore
/util/** export-ignore
/util/bindkeys.pl -export-ignore
/util/mksymtbl.pl -export-ignore
-1
View File
@@ -60,4 +60,3 @@ timestamp
/compile_commands.json /compile_commands.json
/cppcheck_html/ /cppcheck_html/
/cppcheck.results /cppcheck.results
/tsan
+62 -258
View File
@@ -18,17 +18,9 @@ variables:
MAKE: make MAKE: make
CONFIGURE: ./configure CONFIGURE: ./configure
SCAN_BUILD: scan-build-9 SCAN_BUILD: scan-build-9
SYMBOLIZER: /usr/lib/llvm-9/bin/llvm-symbolizer
ASAN_SYMBOLIZER_PATH: "$SYMBOLIZER"
CFLAGS_COMMON: -fno-omit-frame-pointer -fno-optimize-sibling-calls -O1 -g -Wall -Wextra CFLAGS_COMMON: -fno-omit-frame-pointer -fno-optimize-sibling-calls -O1 -g -Wall -Wextra
# Pass run-time flags to AddressSanitizer to get core dumps on error.
ASAN_OPTIONS_COMMON: abort_on_error=1:disable_coredump=0:unmap_shadow_on_exit=1
TARBALL_COMPRESSOR: xz
TARBALL_EXTENSION: xz
stages: stages:
- precheck - precheck
- build - build
@@ -37,7 +29,6 @@ stages:
- docs - docs
- push - push
- postcheck - postcheck
- release
### Runner Tag Templates ### Runner Tag Templates
@@ -113,8 +104,8 @@ stages:
# Fedora # Fedora
.fedora-31-amd64: &fedora_31_amd64_image .fedora-30-amd64: &fedora_30_amd64_image
image: "$CI_REGISTRY_IMAGE:fedora-31-amd64" image: "$CI_REGISTRY_IMAGE:fedora-30-amd64"
<<: *linux_amd64 <<: *linux_amd64
# Ubuntu # Ubuntu
@@ -142,14 +133,12 @@ stages:
- merge_requests - merge_requests
- tags - tags
- web - web
- schedules
.release-branch-triggering-rules: &release_branch_triggering_rules .release-branch-triggering-rules: &release_branch_triggering_rules
only: only:
- merge_requests - merge_requests
- tags - tags
- web - web
- schedules
- master@isc-projects/bind9 - master@isc-projects/bind9
- /^v9_[1-9][0-9]$/@isc-projects/bind9 - /^v9_[1-9][0-9]$/@isc-projects/bind9
@@ -203,36 +192,6 @@ stages:
untracked: true untracked: true
expire_in: "1 week" expire_in: "1 week"
.windows_build: &windows_build_job
stage: build
tags:
- windows
- amd64
script:
- 'Push-Location "C:/Program Files (x86)/Microsoft Visual Studio/2017/BuildTools/VC/Auxiliary/Build"'
- '& cmd.exe /C "vcvarsall.bat x64 & set" | Foreach-Object { if ($_ -match "(.*?)=(.*)") { Set-Item -force -path "Env:\$($matches[1])" -value "$($matches[2])" } }'
- 'Pop-Location'
- 'Set-Location win32utils'
- '& "C:/Strawberry/perl/bin/perl.exe" Configure
"with-tools-version=15.0"
"with-platform-toolset=v141"
"with-platform-version=10.0.17763.0"
"with-vcredist=C:/Program Files (x86)/Microsoft Visual Studio/2017/BuildTools/VC/Redist/MSVC/14.16.27012/vcredist_x64.exe"
"with-openssl=C:/OpenSSL"
"with-libxml2=C:/libxml2"
"with-libuv=C:/libuv"
"without-python"
"with-system-tests"
x64'
- 'Set-Item -path "Env:CL" -value "/MP$([Math]::Truncate($BUILD_PARALLEL_JOBS/2))"'
- '& msbuild.exe /maxCpuCount:2 /t:Build /p:Configuration=$VSCONF bind9.sln'
dependencies: []
needs:
- autoreconf:sid:amd64
artifacts:
untracked: true
expire_in: "1 week"
.setup_interfaces: &setup_interfaces | .setup_interfaces: &setup_interfaces |
if [ "$(id -u)" -eq "0" ]; then if [ "$(id -u)" -eq "0" ]; then
sh -x bin/tests/system/ifconfig.sh up; sh -x bin/tests/system/ifconfig.sh up;
@@ -241,11 +200,12 @@ stages:
fi fi
.setup_softhsm: &setup_softhsm | .setup_softhsm: &setup_softhsm |
sh -x bin/tests/prepare-softhsm2.sh sh -x util/prepare-softhsm2.sh
.system_test: &system_test_job .system_test: &system_test_job
<<: *default_triggering_rules <<: *default_triggering_rules
stage: system stage: system
retry: 2
before_script: before_script:
- *setup_interfaces - *setup_interfaces
- *setup_softhsm - *setup_softhsm
@@ -264,30 +224,6 @@ stages:
--results-filter "" \ --results-filter "" \
--output kyua_html --output kyua_html
.windows_system_test: &windows_system_test_job
stage: system
tags:
- windows
- amd64
script:
- 'Push-Location bin/tests/system'
- '$ifIndex = Get-NetIPInterface -AddressFamily IPv4 -InterfaceMetric 75 | Select-Object -ExpandProperty ifIndex'
- '& C:/tools/cygwin/bin/sed.exe -i "s/^exit.*/netsh interface ipv4 set dnsservers $ifIndex dhcp/; s/\(name\|interface\)=Loopback/$ifIndex/;" ifconfig.bat'
- '& C:/tools/cygwin/bin/sed.exe -i "s/kill -f/kill -W/;" conf.sh stop.pl'
- '& cmd.exe /C ifconfig.bat up; ""'
- 'Start-Sleep 2'
- '$Env:Path = "C:/tools/cygwin/bin;$Env:Path"'
- '& sh.exe runall.sh $TEST_PARALLEL_JOBS'
- 'If (Test-Path C:/CrashDumps/*) { dir C:/CrashDumps; Throw }'
artifacts:
untracked: true
expire_in: "1 week"
when: on_failure
only:
- schedules
- tags
- web
.unit_test: &unit_test_job .unit_test: &unit_test_job
<<: *default_triggering_rules <<: *default_triggering_rules
stage: unit stage: unit
@@ -381,23 +317,6 @@ misc:sid:amd64:
- util/check-cocci - util/check-cocci
- if test "$(git status --porcelain | grep -Ev '\?\?' | wc -l)" -gt "0"; then git status --short; exit 1; fi - if test "$(git status --porcelain | grep -Ev '\?\?' | wc -l)" -gt "0"; then git status --short; exit 1; fi
tarball-create:sid:amd64:
<<: *debian_sid_amd64_image
stage: precheck
script:
- source version
- export BIND_DIRECTORY="bind-${MAJORVER}.${MINORVER}.${PATCHVER}${RELEASETYPE}${RELEASEVER}"
- git archive --prefix="${BIND_DIRECTORY}/" --output="${BIND_DIRECTORY}.tar" HEAD
- mkdir "${BIND_DIRECTORY}"
- echo "SRCID=$(git rev-list --max-count=1 HEAD | cut -b1-7)" > "${BIND_DIRECTORY}/srcid"
- tar --append --file="${BIND_DIRECTORY}.tar" "${BIND_DIRECTORY}/srcid"
- ${TARBALL_COMPRESSOR} "${BIND_DIRECTORY}.tar"
artifacts:
paths:
- bind-*.tar.${TARBALL_EXTENSION}
only:
- tags
# Jobs for doc builds on Debian Sid (amd64) # Jobs for doc builds on Debian Sid (amd64)
docs:sid:amd64: docs:sid:amd64:
@@ -658,48 +577,6 @@ cppcheck:gcc:sid:amd64:
- gcc:sid:amd64 - gcc:sid:amd64
needs: ["gcc:sid:amd64"] needs: ["gcc:sid:amd64"]
# Jobs for tarball GCC builds on Debian Sid (amd64)
tarball:sid:amd64:
variables:
CC: gcc
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
RUN_MAKE_INSTALL: 1
<<: *debian_sid_amd64_image
<<: *build_job
before_script:
- tar --extract --file bind-*.tar.${TARBALL_EXTENSION}
- rm -f bind-*.tar.${TARBALL_EXTENSION}
- cd bind-*
dependencies:
- tarball-create:sid:amd64
needs: ["tarball-create:sid:amd64"]
only:
- tags
system:tarball:sid:amd64:
<<: *debian_sid_amd64_image
<<: *system_test_job
before_script:
- cd bind-*
- *setup_interfaces
dependencies:
- tarball:sid:amd64
needs: ["tarball:sid:amd64"]
only:
- tags
unit:tarball:sid:amd64:
<<: *debian_sid_amd64_image
<<: *unit_test_job
before_script:
- cd bind-*
dependencies:
- tarball:sid:amd64
needs: ["tarball:sid:amd64"]
only:
- tags
# Jobs for regular GCC builds on Debian Sid (i386) # Jobs for regular GCC builds on Debian Sid (i386)
gcc:sid:i386: gcc:sid:i386:
@@ -724,29 +601,29 @@ unit:gcc:sid:i386:
- gcc:sid:i386 - gcc:sid:i386
needs: ["gcc:sid:i386"] needs: ["gcc:sid:i386"]
# Jobs for regular GCC builds on Fedora 31 (amd64) # Jobs for regular GCC builds on Fedora 30 (amd64)
gcc:fedora31:amd64: gcc:fedora30:amd64:
variables: variables:
CC: gcc CC: gcc
CFLAGS: "${CFLAGS_COMMON} -O1" CFLAGS: "${CFLAGS_COMMON} -O1"
EXTRA_CONFIGURE: "--with-libidn2" EXTRA_CONFIGURE: "--with-libidn2"
<<: *fedora_31_amd64_image <<: *fedora_30_amd64_image
<<: *build_job <<: *build_job
system:gcc:fedora31:amd64: system:gcc:fedora30:amd64:
<<: *fedora_31_amd64_image <<: *fedora_30_amd64_image
<<: *system_test_job <<: *system_test_job
dependencies: dependencies:
- gcc:fedora31:amd64 - gcc:fedora30:amd64
needs: ["gcc:fedora31:amd64"] needs: ["gcc:fedora30:amd64"]
unit:gcc:fedora31:amd64: unit:gcc:fedora30:amd64:
<<: *fedora_31_amd64_image <<: *fedora_30_amd64_image
<<: *unit_test_job <<: *unit_test_job
dependencies: dependencies:
- gcc:fedora31:amd64 - gcc:fedora30:amd64
needs: ["gcc:fedora31:amd64"] needs: ["gcc:fedora30:amd64"]
# Jobs for regular GCC builds on Ubuntu 16.04 Xenial Xerus (amd64) # Jobs for regular GCC builds on Ubuntu 16.04 Xenial Xerus (amd64)
@@ -801,6 +678,7 @@ unit:gcc:bionic:amd64:
asan:sid:amd64: asan:sid:amd64:
variables: variables:
CC: gcc CC: gcc
ASAN_OPTIONS: "detect_leaks=0"
CFLAGS: "${CFLAGS_COMMON} -fsanitize=address,undefined -DISC_MEM_USE_INTERNAL_MALLOC=0" CFLAGS: "${CFLAGS_COMMON} -fsanitize=address,undefined -DISC_MEM_USE_INTERNAL_MALLOC=0"
LDFLAGS: "-fsanitize=address,undefined" LDFLAGS: "-fsanitize=address,undefined"
EXTRA_CONFIGURE: "--with-libidn2" EXTRA_CONFIGURE: "--with-libidn2"
@@ -808,8 +686,6 @@ asan:sid:amd64:
<<: *build_job <<: *build_job
system:asan:sid:amd64: system:asan:sid:amd64:
variables:
ASAN_OPTIONS: ${ASAN_OPTIONS_COMMON}
<<: *debian_sid_amd64_image <<: *debian_sid_amd64_image
<<: *system_test_job <<: *system_test_job
dependencies: dependencies:
@@ -817,71 +693,12 @@ system:asan:sid:amd64:
needs: ["asan:sid:amd64"] needs: ["asan:sid:amd64"]
unit:asan:sid:amd64: unit:asan:sid:amd64:
variables:
ASAN_OPTIONS: ${ASAN_OPTIONS_COMMON}
<<: *debian_sid_amd64_image <<: *debian_sid_amd64_image
<<: *unit_test_job <<: *unit_test_job
dependencies: dependencies:
- asan:sid:amd64 - asan:sid:amd64
needs: ["asan:sid:amd64"] needs: ["asan:sid:amd64"]
# Jobs for GCC builds with TSAN enabled on Debian Sid (amd64)
tsan:buster:amd64:
<<: *debian_buster_amd64_image
<<: *build_job
variables:
CC: clang-9
CFLAGS: "${CFLAGS_COMMON} -fsanitize=thread -DISC_MEM_USE_INTERNAL_MALLOC=0"
LDFLAGS: "-fsanitize=thread"
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock"
system:tsan:buster:amd64:
variables:
TSAN_OPTIONS: "second_deadlock_stack=1 history_size=7 log_exe_name=true log_path=tsan external_symbolizer_path=$SYMBOLIZER exitcode=0"
before_script:
- *setup_interfaces
- echo $TSAN_OPTIONS
<<: *debian_buster_amd64_image
<<: *system_test_job
dependencies:
- tsan:buster:amd64
needs: ["tsan:buster:amd64"]
allow_failure: true
after_script:
- find bin -name 'tsan.*' -exec python3 util/parse_tsan.py {} \;
artifacts:
expire_in: "1 week"
paths:
- bin/tests/system/*/tsan.*
- bin/tests/system/*/*/tsan.*
- tsan/
when: on_failure
unit:tsan:buster:amd64:
variables:
TSAN_OPTIONS: "second_deadlock_stack=1 history_size=7 log_exe_name=true log_path=tsan external_symbolizer_path=$SYMBOLIZER"
before_script:
- echo $TSAN_OPTIONS
- lib/isc/tests/result_test
<<: *debian_buster_amd64_image
<<: *unit_test_job
dependencies:
- tsan:buster:amd64
needs: ["tsan:buster:amd64"]
allow_failure: true
after_script:
- find lib -name 'tsan.*' -exec python3 util/parse_tsan.py {} \;
artifacts:
expire_in: "1 week"
paths:
- lib/*/tests/tsan.*
- tsan/
- kyua.log
- kyua.results
- kyua_html/
when: on_failure
rwlock:sid:amd64: rwlock:sid:amd64:
variables: variables:
CC: gcc CC: gcc
@@ -1039,7 +856,6 @@ system:clang:openbsd6.5:amd64:
- clang:openbsd6.5:amd64 - clang:openbsd6.5:amd64
needs: ["clang:openbsd6.5:amd64"] needs: ["clang:openbsd6.5:amd64"]
only: only:
- schedules
- tags - tags
- web - web
@@ -1070,74 +886,62 @@ unit:nolibtool:sid:amd64:
# Jobs for Visual Studio 2017 builds on Windows (amd64) # Jobs for Visual Studio 2017 builds on Windows (amd64)
msvc:windows:amd64: msvc:windows:amd64:
<<: *windows_build_job
<<: *default_triggering_rules <<: *default_triggering_rules
stage: build
tags:
- windows
- amd64
variables: variables:
VSCONF: Release VSCONF: Release
script:
- 'Push-Location "C:/Program Files (x86)/Microsoft Visual Studio/2017/BuildTools/VC/Auxiliary/Build"'
- '& cmd.exe /C "vcvarsall.bat x64 & set" | Foreach-Object { if ($_ -match "(.*?)=(.*)") { Set-Item -force -path "Env:\$($matches[1])" -value "$($matches[2])" } }'
- 'Pop-Location'
- 'Set-Location win32utils'
- '& "C:/Strawberry/perl/bin/perl.exe" Configure
"with-tools-version=15.0"
"with-platform-toolset=v141"
"with-platform-version=10.0.17763.0"
"with-vcredist=C:/Program Files (x86)/Microsoft Visual Studio/2017/BuildTools/VC/Redist/MSVC/14.16.27012/vcredist_x64.exe"
"with-openssl=C:/OpenSSL"
"with-libxml2=C:/libxml2"
"with-libuv=C:/libuv"
"without-python"
"with-system-tests"
x64'
- 'Set-Item -path "Env:CL" -value "/MP$([Math]::Truncate($BUILD_PARALLEL_JOBS/2))"'
- '& msbuild.exe /maxCpuCount:2 /t:Build /p:Configuration=$VSCONF bind9.sln'
dependencies: []
needs:
- autoreconf:sid:amd64
artifacts:
untracked: true
expire_in: "1 week"
system:msvc:windows:amd64: system:msvc:windows:amd64:
<<: *windows_system_test_job stage: system
tags:
- windows
- amd64
variables: variables:
VSCONF: Release VSCONF: Release
script:
- 'Push-Location bin/tests/system'
- '$ifIndex = Get-NetIPInterface -AddressFamily IPv4 -InterfaceMetric 75 | Select-Object -ExpandProperty ifIndex'
- '& C:/tools/cygwin/bin/sed.exe -i "s/^exit.*/netsh interface ipv4 set dnsservers $ifIndex dhcp/; s/\(name\|interface\)=Loopback/$ifIndex/;" ifconfig.bat'
- '& C:/tools/cygwin/bin/sed.exe -i "s/kill -f/kill -W/;" conf.sh stop.pl'
- '& cmd.exe /C ifconfig.bat up; ""'
- 'Start-Sleep 2'
- '$Env:Path = "C:/tools/cygwin/bin;$Env:Path"'
- '& sh.exe runall.sh $TEST_PARALLEL_JOBS'
- 'If (Test-Path C:/CrashDumps/*) { dir C:/CrashDumps; Throw }'
dependencies: dependencies:
- msvc:windows:amd64 - msvc:windows:amd64
needs: ["msvc:windows:amd64"] needs: ["msvc:windows:amd64"]
artifacts:
msvc-debug:windows:amd64: untracked: true
<<: *windows_build_job expire_in: "1 week"
variables: when: on_failure
VSCONF: Debug
only: only:
- schedules
- tags - tags
- web - web
system:msvc-debug:windows:amd64:
<<: *windows_system_test_job
variables:
VSCONF: Debug
dependencies:
- msvc-debug:windows:amd64
needs: ["msvc-debug:windows:amd64"]
# Job producing a release tarball
release:sid:amd64:
<<: *debian_sid_amd64_image
stage: release
script:
# Determine BIND version
- source version
- export BIND_DIRECTORY="bind-${MAJORVER}.${MINORVER}.${PATCHVER}${RELEASETYPE}${RELEASEVER}"
# Remove redundant files and system test utilities from Windows build artifacts
- find Build/Release/ -name "*.pdb" -print -delete
- find Build/Debug/ \( -name "*.bsc" -o -name "*.idb" \) -print -delete
- find Build/ -regextype posix-extended -regex "Build/.*/($(find bin/tests/ -type f | sed -nE "s|^bin/tests(/system)?/win32/(.*)\.vcxproj$|\2|p" | paste -d"|" -s))\..*" -print -delete
# Create Windows zips
- openssl dgst -sha256 "${BIND_DIRECTORY}.tar.${TARBALL_EXTENSION}" | tee Build/Release/SHA256 Build/Debug/SHA256
- ( cd Build/Release; zip "../../BIND${BIND_DIRECTORY#bind-}.x64.zip" * )
- ( cd Build/Debug; zip "../../BIND${BIND_DIRECTORY#bind-}.debug.x64.zip" * )
# Prepare release tarball contents (tarballs + zips + documentation)
- mkdir -p release/doc/arm
- pushd release
- mv "../${BIND_DIRECTORY}.tar.${TARBALL_EXTENSION}" ../BIND*.zip .
- tar --extract --file="${BIND_DIRECTORY}.tar.${TARBALL_EXTENSION}"
- mv "${BIND_DIRECTORY}"/{CHANGES*,COPYRIGHT,LICENSE,README,srcid} .
- mv "${BIND_DIRECTORY}"/doc/arm/{Bv9ARM{*.html,.pdf},man.*,notes.{html,pdf,txt}} doc/arm/
- rm -rf "${BIND_DIRECTORY}"
- cp doc/arm/notes.html "RELEASE-NOTES-${BIND_DIRECTORY}.html"
- cp doc/arm/notes.pdf "RELEASE-NOTES-${BIND_DIRECTORY}.pdf"
- cp doc/arm/notes.txt "RELEASE-NOTES-${BIND_DIRECTORY}.txt"
- popd
# Create release tarball
- tar --create --file="${CI_COMMIT_TAG}.tar.gz" --gzip release/
dependencies:
- tarball-create:sid:amd64
- msvc:windows:amd64
- msvc-debug:windows:amd64
only:
- tags
artifacts:
paths:
- "*.tar.gz"
expire_in: "1 week"
+11 -11
View File
@@ -2,6 +2,8 @@
**Tagging Deadline:** **Tagging Deadline:**
**ASN Deadline:**
**Public Release:** **Public Release:**
## Release Checklist ## Release Checklist
@@ -10,7 +12,6 @@
- [ ] ***(QA)*** Check whether all issues assigned to the release milestone are resolved[^1]. - [ ] ***(QA)*** Check whether all issues assigned to the release milestone are resolved[^1].
- [ ] ***(QA)*** Ensure that there are no outstanding merge requests in the private repository[^1] (Subscription Edition only). - [ ] ***(QA)*** Ensure that there are no outstanding merge requests in the private repository[^1] (Subscription Edition only).
- [ ] ***(QA)*** Ensure all merge requests marked for backporting have been indeed backported.
## Before the Tagging Deadline ## Before the Tagging Deadline
@@ -32,22 +33,21 @@
## Before the ASN Deadline (for ASN Releases) or the Public Release Date (for Regular Releases) ## Before the ASN Deadline (for ASN Releases) or the Public Release Date (for Regular Releases)
- [ ] ***(QA)*** Verify GitLab CI results for the tags created and prepare a QA report for the releases to be published. - [ ] ***(QA)*** Run the `make release` Jenkins jobs to produce the tarballs and zips.
- [ ] ***(QA)*** Request signatures for the tarballs, providing their location and checksums. - [ ] ***(QA)*** Verify the results of `make release` Jenkins jobs and prepare a QA report for the releases to be published.
- [ ] ***(Signers)*** Validate tarball checksums, sign tarballs, and upload signatures. - [ ] ***(QA)*** Request signatures for the tarballs.
- [ ] ***(QA)*** Verify tarball signatures and check tarball checksums again. - [ ] ***(Signers)*** Sign the tarballs.
- [ ] ***(QA)*** Check tarball signatures.
- [ ] ***(QA)*** Notify Support that the releases are ready for publication.
- [ ] ***(Support)*** Pre-publish ASN and/or Subscription Edition tarballs so that packages can be built. - [ ] ***(Support)*** Pre-publish ASN and/or Subscription Edition tarballs so that packages can be built.
- [ ] ***(QA)*** Build and test ASN and/or Subscription Edition packages. - [ ] ***(QA)*** Build and test ASN and/or Subscription Edition packages.
- [ ] ***(QA)*** Notify Support that the releases have been prepared.
- [ ] ***(Support)*** Send out ASNs (if applicable). - [ ] ***(Support)*** Send out ASNs (if applicable).
## On the Day of Public Release ## On the Day of Public Release
- [ ] ***(Support)*** Wait for clearance from Security Officer to proceed with the public release (if applicable). - [ ] ***(Support)*** Publish the releases according to the release schedule.
- [ ] ***(Support)*** Place tarballs in public location on FTP site. - [ ] ***(Support)*** Write release email to *bind9-announce*.
- [ ] ***(Support)*** Publish links to downloads on ISC website. - [ ] ***(Support)*** Write email to *bind9-users* (if a major release).
- [ ] ***(Support)*** Write release email to *bind-announce*.
- [ ] ***(Support)*** Write email to *bind-users* (if a major release).
- [ ] ***(Support)*** Update tickets in case of waiting support customers. - [ ] ***(Support)*** Update tickets in case of waiting support customers.
- [ ] ***(QA)*** Build and test any outstanding private packages. - [ ] ***(QA)*** Build and test any outstanding private packages.
- [ ] ***(QA)*** Build public packages (`*.deb`, RPMs). - [ ] ***(QA)*** Build public packages (`*.deb`, RPMs).
+1 -37
View File
@@ -1,40 +1,4 @@
5337. [func] 'named -V' now reports maxminddb and protobuf-c 5326. [bug] Add python dependancy on 'distutils.core' to configure.
versions. [GL !2686]
--- 9.15.7 released ---
5336. [bug] The TCP high-water statistic could report an
incorrect value on startup. [GL #1392]
5335. [func] Make TCP listening code multithreaded. [GL !2659]
5334. [doc] Update documentation with dnssec-policy clarifications.
Also change some defaults. [GL !2711]
5333. [bug] Fix duration printing on Solaris when value is not
an ISO 8601 duration. [GL #1460]
5332. [func] Renamed "dnssec-keys" configuration statement
to the more descriptive "trust-anchors". [GL !2702]
5331. [func] Use compiler-provided mechanisms for thread local
storage, and make the requirement for such mechanisms
explicit in configure. [GL #1444]
5330. [bug] 'configure --without-python' was ineffective if
PYTHON was set in the environment. [GL #1434]
5329. [bug] Reconfiguring named caused memory to be leaked when any
GeoIP2 database was in use. [GL #1445]
5328. [bug] rbtdb.c:rdataset_{get,set}ownercase failed to obtain
a node lock. [GL #1417]
5327. [func] Added a statistics counter to track queries
dropped because the recursive-clients quota was
exceeded. [GL #1399]
5326. [bug] Add Python dependency on 'distutils.core' to configure.
'distutils.core' is required for installation. 'distutils.core' is required for installation.
[GL #1397] [GL #1397]
+1 -1
View File
@@ -1,4 +1,4 @@
Copyright (C) 1996-2020 Internet Systems Consortium, Inc. ("ISC") Copyright (C) 1996-2019 Internet Systems Consortium, Inc. ("ISC")
This Source Code Form is subject to the terms of the Mozilla Public This Source Code Form is subject to the terms of the Mozilla Public
License, v. 2.0. If a copy of the MPL was not distributed with this License, v. 2.0. If a copy of the MPL was not distributed with this
+16 -26
View File
@@ -5,28 +5,16 @@ Supported platforms
In general, this version of BIND will build and run on any POSIX-compliant In general, this version of BIND will build and run on any POSIX-compliant
system with a C11-compliant C compiler, BSD-style sockets with system with a C11-compliant C compiler, BSD-style sockets with
RFC-compliant IPv6 support, POSIX-compliant threads, the libuv RFC-compliant IPv6 support, POSIX-compliant threads, the libuv
asynchronous I/O library, and the OpenSSL cryptography library. asynchronous I/O library, and the OpenSSL cryptography library. Atomic
operations support from the compiler is needed, either in the form of
builtin operations, C11 atomics, or the Interlocked family of functions on
Windows.
The following C11 features are used in BIND 9: BIND 9.15 requires fairly recent version of libuv library to run (>= 1.x).
For some of the older systems listed below, you will have to install
* Atomic operations support from the compiler is needed, either in the updated libuv package from sources such as EPEL, PPA and other native
form of builtin operations, C11 atomics, or the Interlocked family of sources for updated packages. The other option is to install libuv from
functions on Windows. sources.
* Thread Local Storage support from the compiler is needed, either in
the form of C11 _Thread_local/thread_local, the __thread GCC
extension, or the __declspec(thread) MSVC extension on Windows.
BIND 9.15 requires a fairly recent version of libuv (at least 1.x). For
some of the older systems listed below, you will have to install an
updated libuv package from sources such as EPEL, PPA, or other native
sources for updated packages. The other option is to build and install
libuv from source.
Certain optional BIND features have additional library dependencies. These
include libxml2 and libjson-c for statistics, libmaxminddb for
geolocation, libfstrm and libprotobuf-c for DNSTAP, and libidn2 for
internationalized domain name conversion.
ISC regularly tests BIND on many operating systems and architectures, but ISC regularly tests BIND on many operating systems and architectures, but
lacks the resources to test all of them. Consequently, ISC is only able to lacks the resources to test all of them. Consequently, ISC is only able to
@@ -39,7 +27,7 @@ following systems:
* Debian 9, 10 * Debian 9, 10
* Ubuntu LTS 16.04, 18.04 * Ubuntu LTS 16.04, 18.04
* Fedora 31 * Fedora 30
* Red Hat Enterprise Linux / CentOS 7, 8 * Red Hat Enterprise Linux / CentOS 7, 8
* FreeBSD 11.3, 12.0 * FreeBSD 11.3, 12.0
* OpenBSD 6.5 * OpenBSD 6.5
@@ -70,10 +58,10 @@ Server 2012 R2, none of these are tested regularly by ISC.
Community maintained Community maintained
These systems may not all have the required dependencies for building BIND These systems may not all have easily available the required dependencies
easily available, although it will be possible in many cases to compile for building BIND although it will be possible in many cases to compile
those directly from source. The community and interested parties may wish those directly from source. The community and interested parties may wish
to help with maintenance, and we welcome patch contributions, although we to help with maintenance and we welcome patch contributions, although we
cannot guarantee that we will accept them. All contributions will be cannot guarantee that we will accept them. All contributions will be
assessed against the risk of adverse effect on officially supported assessed against the risk of adverse effect on officially supported
platforms. platforms.
@@ -96,4 +84,6 @@ These are platforms on which BIND 9.15 is known not to build or run:
* Platforms that don't support atomic operations (via compiler or * Platforms that don't support atomic operations (via compiler or
library) library)
* Linux without NPTL (Native POSIX Thread Library) * Linux without NPTL (Native POSIX Thread Library)
* Platforms on which libuv cannot be compiled * Platforms where libuv cannot be compiled
Platform quirks
+17 -30
View File
@@ -13,28 +13,14 @@
In general, this version of BIND will build and run on any POSIX-compliant In general, this version of BIND will build and run on any POSIX-compliant
system with a C11-compliant C compiler, BSD-style sockets with RFC-compliant system with a C11-compliant C compiler, BSD-style sockets with RFC-compliant
IPv6 support, POSIX-compliant threads, the `libuv` asynchronous I/O library, IPv6 support, POSIX-compliant threads, the `libuv` asynchronous I/O library,
and the OpenSSL cryptography library. and the OpenSSL cryptography library. Atomic operations support from the
compiler is needed, either in the form of builtin operations, C11 atomics,
or the `Interlocked` family of functions on Windows.
The following C11 features are used in BIND 9: BIND 9.15 requires fairly recent version of libuv library to run (>= 1.x). For
some of the older systems listed below, you will have to install updated libuv
* Atomic operations support from the compiler is needed, either in the form of package from sources such as EPEL, PPA and other native sources for updated
builtin operations, C11 atomics, or the `Interlocked` family of functions on packages. The other option is to install libuv from sources.
Windows.
* Thread Local Storage support from the compiler is needed, either in the form
of C11 `_Thread_local`/`thread_local`, the `__thread` GCC extension, or
the `__declspec(thread)` MSVC extension on Windows.
BIND 9.15 requires a fairly recent version of `libuv` (at least 1.x). For
some of the older systems listed below, you will have to install an updated
`libuv` package from sources such as EPEL, PPA, or other native sources for
updated packages. The other option is to build and install `libuv` from
source.
Certain optional BIND features have additional library dependencies.
These include `libxml2` and `libjson-c` for statistics, `libmaxminddb` for
geolocation, `libfstrm` and `libprotobuf-c` for DNSTAP, and `libidn2` for
internationalized domain name conversion.
ISC regularly tests BIND on many operating systems and architectures, but ISC regularly tests BIND on many operating systems and architectures, but
lacks the resources to test all of them. Consequently, ISC is only able to lacks the resources to test all of them. Consequently, ISC is only able to
@@ -47,7 +33,7 @@ following systems:
* Debian 9, 10 * Debian 9, 10
* Ubuntu LTS 16.04, 18.04 * Ubuntu LTS 16.04, 18.04
* Fedora 31 * Fedora 30
* Red Hat Enterprise Linux / CentOS 7, 8 * Red Hat Enterprise Linux / CentOS 7, 8
* FreeBSD 11.3, 12.0 * FreeBSD 11.3, 12.0
* OpenBSD 6.5 * OpenBSD 6.5
@@ -77,13 +63,12 @@ Server 2012 R2, none of these are tested regularly by ISC.
### Community maintained ### Community maintained
These systems may not all have the required dependencies for building BIND These systems may not all have easily available the required dependencies for
easily available, although it will be possible in many cases to compile building BIND although it will be possible in many cases to compile those
those directly from source. The community and interested parties may wish directly from source. The community and interested parties may wish to help with
to help with maintenance, and we welcome patch contributions, although we maintenance and we welcome patch contributions, although we cannot guarantee
cannot guarantee that we will accept them. All contributions will be that we will accept them. All contributions will be assessed against the risk
assessed against the risk of adverse effect on officially supported of adverse effect on officially supported platforms.
platforms.
* Platforms past or close to their respective EOL dates, such as: * Platforms past or close to their respective EOL dates, such as:
* Ubuntu 14.04, 18.10 * Ubuntu 14.04, 18.10
@@ -102,4 +87,6 @@ These are platforms on which BIND 9.15 is known *not* to build or run:
* Platforms that don't support IPv6 Advanced Socket API (RFC 3542) * Platforms that don't support IPv6 Advanced Socket API (RFC 3542)
* Platforms that don't support atomic operations (via compiler or library) * Platforms that don't support atomic operations (via compiler or library)
* Linux without NPTL (Native POSIX Thread Library) * Linux without NPTL (Native POSIX Thread Library)
* Platforms on which `libuv` cannot be compiled * Platforms where libuv cannot be compiled
## Platform quirks
+6 -7
View File
@@ -115,9 +115,9 @@ of changes from BIND 9.14 and earlier releases. New features include:
for zones, enabling automatic key regeneration and rollover. for zones, enabling automatic key regeneration and rollover.
* New new network manager based on libuv. * New new network manager based on libuv.
* Support for the new GeoIP2 geolocation API * Support for the new GeoIP2 geolocation API
* Improved DNSSEC trust anchor configuration using the trust-anchors * Improved DNSSEC trust anchor configuration using dnssec-keys,
statement, permitting configuration of trust anchors in DS as well as permitting configuration of trust anchors in DS as well as DNSKEY
DNSKEY format. format.
* YAML output for dig, mdig, and delv. * YAML output for dig, mdig, and delv.
Building BIND Building BIND
@@ -180,10 +180,9 @@ Dependencies
Portions of BIND that are written in Python, including dnssec-keymgr, Portions of BIND that are written in Python, including dnssec-keymgr,
dnssec-coverage, dnssec-checkds, and some of the system tests, require the dnssec-coverage, dnssec-checkds, and some of the system tests, require the
argparse, ply and distutils.core modules to be available. argparse is a argparse and ply modules to be available. argparse is a standard module as
standard module as of Python 2.7 and Python 3.2. ply is available from of Python 2.7 and Python 3.2. ply is available from https://
https://pypi.python.org/pypi/ply. distutils.core is required for pypi.python.org/pypi/ply.
installation.
Compile-time options Compile-time options
+2 -2
View File
@@ -131,8 +131,8 @@ include:
for zones, enabling automatic key regeneration and rollover. for zones, enabling automatic key regeneration and rollover.
* New new network manager based on libuv. * New new network manager based on libuv.
* Support for the new GeoIP2 geolocation API * Support for the new GeoIP2 geolocation API
* Improved DNSSEC trust anchor configuration using the `trust-anchors` * Improved DNSSEC trust anchor configuration using `dnssec-keys`,
statement, permitting configuration of trust anchors in DS as well as permitting configuration of trust anchors in DS as well as
DNSKEY format. DNSKEY format.
* YAML output for `dig`, `mdig`, and `delv`. * YAML output for `dig`, `mdig`, and `delv`.
+2
View File
@@ -709,6 +709,8 @@ main(int argc, char **argv) {
cfg_parser_destroy(&parser); cfg_parser_destroy(&parser);
dns_name_destroy();
isc_log_destroy(&logc); isc_log_destroy(&logc);
isc_mem_destroy(&mctx); isc_mem_destroy(&mctx);
-1
View File
@@ -41,7 +41,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+2 -2
View File
@@ -85,9 +85,9 @@ usage(void) {
static void static void
destroy(void) { destroy(void) {
if (zone != NULL) { if (zone != NULL)
dns_zone_detach(&zone); dns_zone_detach(&zone);
} dns_name_destroy();
} }
/*% main processing routine */ /*% main processing routine */
-1
View File
@@ -44,7 +44,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
-1
View File
@@ -38,7 +38,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
-1
View File
@@ -45,7 +45,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -144,7 +144,7 @@ options\&.
Note: When reading the trust anchor file, Note: When reading the trust anchor file,
\fBdelv\fR \fBdelv\fR
treats treats
\fBtrust\-anchors\fR\fBinitial\-key\fR \fBdnssec\-keys\fR\fBinitial\-key\fR
and and
\fBstatic\-key\fR \fBstatic\-key\fR
entries identically\&. That is, even if a key is configured with entries identically\&. That is, even if a key is configured with
+22 -23
View File
@@ -140,7 +140,7 @@ static dns_fixedname_t afn;
static dns_name_t *anchor_name = NULL; static dns_name_t *anchor_name = NULL;
/* Default bind.keys contents */ /* Default bind.keys contents */
static char anchortext[] = TRUST_ANCHORS; static char anchortext[] = DNSSEC_KEYS;
/* /*
* Static function prototypes * Static function prototypes
@@ -498,17 +498,14 @@ printdata(dns_rdataset_t *rdataset, dns_name_t *owner,
dns_rdata_reset(&rdata); dns_rdata_reset(&rdata);
} }
} else { } else {
dns_indent_t indent = { " ", 2 };
if (!yaml && (rdataset->attributes & if (!yaml && (rdataset->attributes &
DNS_RDATASETATTR_NEGATIVE) != 0) DNS_RDATASETATTR_NEGATIVE) != 0)
{ {
isc_buffer_putstr(&target, "; "); isc_buffer_putstr(&target, "; ");
} }
result = dns_master_rdatasettotext(owner, rdataset, result = dns_master_rdatasettotext(owner, rdataset,
style, style, &target);
yaml ? &indent :
NULL,
&target);
} }
if (result == ISC_R_NOSPACE) { if (result == ISC_R_NOSPACE) {
@@ -540,6 +537,8 @@ setup_style(dns_master_style_t **stylep) {
styleflags |= DNS_STYLEFLAG_REL_OWNER; styleflags |= DNS_STYLEFLAG_REL_OWNER;
if (yaml) { if (yaml) {
styleflags |= DNS_STYLEFLAG_YAML; styleflags |= DNS_STYLEFLAG_YAML;
dns_master_indentstr = " ";
dns_master_indent = 2;
} else { } else {
if (showcomments) { if (showcomments) {
styleflags |= DNS_STYLEFLAG_COMMENT; styleflags |= DNS_STYLEFLAG_COMMENT;
@@ -614,7 +613,7 @@ static isc_result_t
key_fromconfig(const cfg_obj_t *key, dns_client_t *client) { key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
dns_rdata_dnskey_t dnskey; dns_rdata_dnskey_t dnskey;
dns_rdata_ds_t ds; dns_rdata_ds_t ds;
uint32_t rdata1, rdata2, rdata3; uint32_t n1, n2, n3;
const char *datastr = NULL, *keynamestr = NULL, *atstr = NULL; const char *datastr = NULL, *keynamestr = NULL, *atstr = NULL;
unsigned char data[4096]; unsigned char data[4096];
isc_buffer_t databuf; isc_buffer_t databuf;
@@ -655,13 +654,13 @@ key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
delv_log(ISC_LOG_DEBUG(3), "adding trust anchor %s", trust_anchor); delv_log(ISC_LOG_DEBUG(3), "adding trust anchor %s", trust_anchor);
/* if DNSKEY, flags; if DS, key tag */ /* if DNSKEY, flags; if DS, key tag */
rdata1 = cfg_obj_asuint32(cfg_tuple_get(key, "rdata1")); n1 = cfg_obj_asuint32(cfg_tuple_get(key, "n1"));
/* if DNSKEY, protocol; if DS, algorithm */ /* if DNSKEY, protocol; if DS, algorithm */
rdata2 = cfg_obj_asuint32(cfg_tuple_get(key, "rdata2")); n2 = cfg_obj_asuint32(cfg_tuple_get(key, "n2"));
/* if DNSKEY, algorithm; if DS, digest type */ /* if DNSKEY, algorithm; if DS, digest type */
rdata3 = cfg_obj_asuint32(cfg_tuple_get(key, "rdata3")); n3 = cfg_obj_asuint32(cfg_tuple_get(key, "n3"));
/* What type of trust anchor is this? */ /* What type of trust anchor is this? */
atstr = cfg_obj_asstring(cfg_tuple_get(key, "anchortype")); atstr = cfg_obj_asstring(cfg_tuple_get(key, "anchortype"));
@@ -684,13 +683,13 @@ key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
isc_buffer_init(&databuf, data, sizeof(data)); isc_buffer_init(&databuf, data, sizeof(data));
isc_buffer_init(&rrdatabuf, rrdata, sizeof(rrdata)); isc_buffer_init(&rrdatabuf, rrdata, sizeof(rrdata));
if (rdata1 > 0xffff) { if (n1 > 0xffff) {
CHECK(ISC_R_RANGE); CHECK(ISC_R_RANGE);
} }
if (rdata2 > 0xff) { if (n2 > 0xff) {
CHECK(ISC_R_RANGE); CHECK(ISC_R_RANGE);
} }
if (rdata3 > 0xff) { if (n3 > 0xff) {
CHECK(ISC_R_RANGE); CHECK(ISC_R_RANGE);
} }
@@ -704,9 +703,9 @@ key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
ISC_LINK_INIT(&dnskey.common, link); ISC_LINK_INIT(&dnskey.common, link);
dnskey.flags = (uint16_t)rdata1; dnskey.flags = (uint16_t)n1;
dnskey.protocol = (uint8_t)rdata2; dnskey.protocol = (uint8_t)n2;
dnskey.algorithm = (uint8_t)rdata3; dnskey.algorithm = (uint8_t)n3;
datastr = cfg_obj_asstring(cfg_tuple_get(key, "data")); datastr = cfg_obj_asstring(cfg_tuple_get(key, "data"));
CHECK(isc_base64_decodestring(datastr, &databuf)); CHECK(isc_base64_decodestring(datastr, &databuf));
@@ -729,9 +728,9 @@ key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
ISC_LINK_INIT(&ds.common, link); ISC_LINK_INIT(&ds.common, link);
ds.key_tag = (uint16_t)rdata1; ds.key_tag = (uint16_t)n1;
ds.algorithm = (uint8_t)rdata2; ds.algorithm = (uint8_t)n2;
ds.digest_type = (uint8_t)rdata3; ds.digest_type = (uint8_t)n3;
datastr = cfg_obj_asstring(cfg_tuple_get(key, "data")); datastr = cfg_obj_asstring(cfg_tuple_get(key, "data"));
CHECK(isc_hex_decodestring(datastr, &databuf)); CHECK(isc_hex_decodestring(datastr, &databuf));
@@ -819,7 +818,7 @@ setup_dnsseckeys(dns_client_t *client) {
cfg_parser_t *parser = NULL; cfg_parser_t *parser = NULL;
const cfg_obj_t *trusted_keys = NULL; const cfg_obj_t *trusted_keys = NULL;
const cfg_obj_t *managed_keys = NULL; const cfg_obj_t *managed_keys = NULL;
const cfg_obj_t *trust_anchors = NULL; const cfg_obj_t *dnssec_keys = NULL;
cfg_obj_t *bindkeys = NULL; cfg_obj_t *bindkeys = NULL;
const char *filename = anchorfile; const char *filename = anchorfile;
@@ -878,7 +877,7 @@ setup_dnsseckeys(dns_client_t *client) {
INSIST(bindkeys != NULL); INSIST(bindkeys != NULL);
cfg_map_get(bindkeys, "trusted-keys", &trusted_keys); cfg_map_get(bindkeys, "trusted-keys", &trusted_keys);
cfg_map_get(bindkeys, "managed-keys", &managed_keys); cfg_map_get(bindkeys, "managed-keys", &managed_keys);
cfg_map_get(bindkeys, "trust-anchors", &trust_anchors); cfg_map_get(bindkeys, "dnssec-keys", &dnssec_keys);
if (trusted_keys != NULL) { if (trusted_keys != NULL) {
CHECK(load_keys(trusted_keys, client)); CHECK(load_keys(trusted_keys, client));
@@ -886,8 +885,8 @@ setup_dnsseckeys(dns_client_t *client) {
if (managed_keys != NULL) { if (managed_keys != NULL) {
CHECK(load_keys(managed_keys, client)); CHECK(load_keys(managed_keys, client));
} }
if (trust_anchors != NULL) { if (dnssec_keys != NULL) {
CHECK(load_keys(trust_anchors, client)); CHECK(load_keys(dnssec_keys, client));
} }
result = ISC_R_SUCCESS; result = ISC_R_SUCCESS;
+1 -2
View File
@@ -40,7 +40,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
@@ -216,7 +215,7 @@
</para> </para>
<para> <para>
Note: When reading the trust anchor file, Note: When reading the trust anchor file,
<command>delv</command> treats <option>trust-anchors</option> <command>delv</command> treats <option>dnssec-keys</option>
<option>initial-key</option> and <option>static-key</option> <option>initial-key</option> and <option>static-key</option>
entries identically. That is, even if a key is configured entries identically. That is, even if a key is configured
with <command>initial-key</command>, indicating that it is with <command>initial-key</command>, indicating that it is
+1 -1
View File
@@ -197,7 +197,7 @@
</p> </p>
<p> <p>
Note: When reading the trust anchor file, Note: When reading the trust anchor file,
<span class="command"><strong>delv</strong></span> treats <code class="option">trust-anchors</code> <span class="command"><strong>delv</strong></span> treats <code class="option">dnssec-keys</code>
<code class="option">initial-key</code> and <code class="option">static-key</code> <code class="option">initial-key</code> and <code class="option">static-key</code>
entries identically. That is, even if a key is configured entries identically. That is, even if a key is configured
with <span class="command"><strong>initial-key</strong></span>, indicating that it is with <span class="command"><strong>initial-key</strong></span>, indicating that it is
+15 -18
View File
@@ -54,7 +54,7 @@
dig_lookup_t *default_lookup = NULL; dig_lookup_t *default_lookup = NULL;
static atomic_uintptr_t batchname = ATOMIC_VAR_INIT(0); static char *batchname = NULL;
static FILE *batchfp = NULL; static FILE *batchfp = NULL;
static char *argv0; static char *argv0;
static int addresscount = 0; static int addresscount = 0;
@@ -487,8 +487,8 @@ printmessage(dig_query_t *query, const isc_buffer_t *msgbuf,
styleflags |= DNS_STYLEFLAG_REL_OWNER; styleflags |= DNS_STYLEFLAG_REL_OWNER;
if (yaml) { if (yaml) {
msg->indent.string = " "; dns_master_indentstr = " ";
msg->indent.count = 3; dns_master_indent = 3;
styleflags |= DNS_STYLEFLAG_YAML; styleflags |= DNS_STYLEFLAG_YAML;
} else { } else {
if (query->lookup->comments) { if (query->lookup->comments) {
@@ -1874,7 +1874,7 @@ dash_option(char *option, char *next, dig_lookup_t **lookup,
value); value);
return (value_from_next); return (value_from_next);
case 'f': case 'f':
atomic_store(&batchname, (uintptr_t)value); batchname = value;
return (value_from_next); return (value_from_next);
case 'k': case 'k':
strlcpy(keyfile, value, sizeof(keyfile)); strlcpy(keyfile, value, sizeof(keyfile));
@@ -2327,15 +2327,13 @@ parse_args(bool is_batchfile, bool config_only,
* first entry, then trust the callback in dighost_shutdown * first entry, then trust the callback in dighost_shutdown
* to get the rest * to get the rest
*/ */
char *filename = (char *)atomic_load(&batchname); if ((batchname != NULL) && !(is_batchfile)) {
if ((filename != NULL) && !(is_batchfile)) { if (strcmp(batchname, "-") == 0)
if (strcmp(filename, "-") == 0) {
batchfp = stdin; batchfp = stdin;
} else { else
batchfp = fopen(filename, "r"); batchfp = fopen(batchname, "r");
}
if (batchfp == NULL) { if (batchfp == NULL) {
perror(filename); perror(batchname);
if (exitcode < 8) if (exitcode < 8)
exitcode = 8; exitcode = 8;
fatal("couldn't open specified batch file"); fatal("couldn't open specified batch file");
@@ -2390,14 +2388,14 @@ query_finished(void) {
int bargc; int bargc;
char *bargv[16]; char *bargv[16];
if (atomic_load(&batchname) == 0) { if (batchname == NULL) {
isc_app_shutdown(); isc_app_shutdown();
return; return;
} }
fflush(stdout); fflush(stdout);
if (feof(batchfp)) { if (feof(batchfp)) {
atomic_store(&batchname, 0); batchname = NULL;
isc_app_shutdown(); isc_app_shutdown();
if (batchfp != stdin) if (batchfp != stdin)
fclose(batchfp); fclose(batchfp);
@@ -2411,7 +2409,7 @@ query_finished(void) {
parse_args(true, false, bargc, (char **)bargv); parse_args(true, false, bargc, (char **)bargv);
start_lookup(); start_lookup();
} else { } else {
atomic_store(&batchname, 0); batchname = NULL;
if (batchfp != stdin) if (batchfp != stdin)
fclose(batchfp); fclose(batchfp);
isc_app_shutdown(); isc_app_shutdown();
@@ -2541,11 +2539,10 @@ void dig_query_start()
void void
dig_shutdown() { dig_shutdown() {
destroy_lookup(default_lookup); destroy_lookup(default_lookup);
if (atomic_load(&batchname) != 0) { if (batchname != NULL) {
if (batchfp != stdin) { if (batchfp != stdin)
fclose(batchfp); fclose(batchfp);
} batchname = NULL;
atomic_store(&batchname, 0);
} }
cancel_all(); cancel_all();
destroy_libs(); destroy_libs();
-1
View File
@@ -53,7 +53,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -4252,6 +4252,7 @@ destroy_libs(void) {
result = dns_name_settotextfilter(NULL); result = dns_name_settotextfilter(NULL);
check_result(result, "dns_name_settotextfilter"); check_result(result, "dns_name_settotextfilter");
#endif /* HAVE_LIBIDN2 */ #endif /* HAVE_LIBIDN2 */
dns_name_destroy();
if (commctx != NULL) { if (commctx != NULL) {
debug("freeing commctx"); debug("freeing commctx");
-1
View File
@@ -48,7 +48,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
-1
View File
@@ -72,7 +72,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -372,7 +372,7 @@ formatset(dns_rdataset_t *rdataset) {
result = isc_buffer_allocate(mctx, &buf, MAX_CDS_RDATA_TEXT_SIZE); result = isc_buffer_allocate(mctx, &buf, MAX_CDS_RDATA_TEXT_SIZE);
check_result(result, "printing DS records"); check_result(result, "printing DS records");
result = dns_master_rdatasettotext(name, rdataset, style, NULL, buf); result = dns_master_rdatasettotext(name, rdataset, style, buf);
if ((result == ISC_R_SUCCESS) && isc_buffer_availablelength(buf) < 1) { if ((result == ISC_R_SUCCESS) && isc_buffer_availablelength(buf) < 1) {
result = ISC_R_NOSPACE; result = ISC_R_NOSPACE;
-1
View File
@@ -41,7 +41,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -517,6 +517,7 @@ main(int argc, char **argv) {
} }
cleanup_logging(&log); cleanup_logging(&log);
dst_lib_destroy(); dst_lib_destroy();
dns_name_destroy();
if (verbose > 10) { if (verbose > 10) {
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
} }
-1
View File
@@ -42,7 +42,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -439,6 +439,7 @@ main(int argc, char **argv) {
dns_rdataset_disassociate(&rdataset); dns_rdataset_disassociate(&rdataset);
cleanup_logging(&log); cleanup_logging(&log);
dst_lib_destroy(); dst_lib_destroy();
dns_name_destroy();
if (verbose > 10) if (verbose > 10)
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
isc_mem_destroy(&mctx); isc_mem_destroy(&mctx);
-1
View File
@@ -39,7 +39,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -694,6 +694,7 @@ main(int argc, char **argv) {
cleanup_logging(&log); cleanup_logging(&log);
dst_lib_destroy(); dst_lib_destroy();
dns_name_destroy();
if (verbose > 10) if (verbose > 10)
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
isc_mem_free(mctx, label); isc_mem_free(mctx, label);
-1
View File
@@ -44,7 +44,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -1222,6 +1222,7 @@ main(int argc, char **argv) {
cleanup_logging(&log); cleanup_logging(&log);
dst_lib_destroy(); dst_lib_destroy();
dns_name_destroy();
if (verbose > 10) if (verbose > 10)
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
isc_mem_destroy(&mctx); isc_mem_destroy(&mctx);
-1
View File
@@ -51,7 +51,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
-1
View File
@@ -39,7 +39,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
-1
View File
@@ -41,7 +41,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+2 -2
View File
@@ -246,8 +246,7 @@ dumpnode(dns_name_t *name, dns_dbnode_t *node) {
for (;;) { for (;;) {
result = dns_master_rdatasettotext(name, &rds, result = dns_master_rdatasettotext(name, &rds,
masterstyle, NULL, masterstyle, buffer);
buffer);
if (result != ISC_R_NOSPACE) if (result != ISC_R_NOSPACE)
break; break;
@@ -3922,6 +3921,7 @@ main(int argc, char *argv[]) {
cleanup_logging(&log); cleanup_logging(&log);
dst_lib_destroy(); dst_lib_destroy();
dns_name_destroy();
if (verbose > 10) if (verbose > 10)
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
isc_mem_destroy(&mctx); isc_mem_destroy(&mctx);
-1
View File
@@ -51,7 +51,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -335,6 +335,7 @@ main(int argc, char *argv[]) {
cleanup_logging(&log); cleanup_logging(&log);
dst_lib_destroy(); dst_lib_destroy();
dns_name_destroy();
if (verbose > 10) if (verbose > 10)
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
isc_mem_destroy(&mctx); isc_mem_destroy(&mctx);
-1
View File
@@ -38,7 +38,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+5 -2
View File
@@ -296,7 +296,7 @@ view \"_bind\" chaos {\n\
# BEGIN DNSSEC KEYS\n" # BEGIN DNSSEC KEYS\n"
/* Imported from bind.keys.h: */ /* Imported from bind.keys.h: */
TRUST_ANCHORS DNSSEC_KEYS
"# END MANAGED KEYS\n\ "# END MANAGED KEYS\n\
\n\ \n\
@@ -800,7 +800,10 @@ named_config_getipandkeylist(const cfg_obj_t *config, const cfg_obj_t *list,
dns_rootname, 0, NULL); dns_rootname, 0, NULL);
if (result != ISC_R_SUCCESS) if (result != ISC_R_SUCCESS)
goto cleanup; goto cleanup;
dns_name_dup(dns_fixedname_name(&fname), mctx, keys[i - 1]); result = dns_name_dup(dns_fixedname_name(&fname), mctx,
keys[i - 1]);
if (result != ISC_R_SUCCESS)
goto cleanup;
} }
if (pushed != 0) { if (pushed != 0) {
pushed--; pushed--;
+4 -8
View File
@@ -113,7 +113,8 @@ named_geoip_load(char *dir) {
#endif #endif
} }
void named_geoip_unload(void) { void
named_geoip_shutdown(void) {
#ifdef HAVE_GEOIP2 #ifdef HAVE_GEOIP2
if (named_g_geoip->country != NULL) { if (named_g_geoip->country != NULL) {
MMDB_close(named_g_geoip->country); MMDB_close(named_g_geoip->country);
@@ -135,12 +136,7 @@ void named_geoip_unload(void) {
MMDB_close(named_g_geoip->domain); MMDB_close(named_g_geoip->domain);
named_g_geoip->domain = NULL; named_g_geoip->domain = NULL;
} }
#endif
}
void
named_geoip_shutdown(void) {
#ifdef HAVE_GEOIP2
named_geoip_unload();
#endif /* HAVE_GEOIP2 */ #endif /* HAVE_GEOIP2 */
dns_geoip_shutdown();
} }
-3
View File
@@ -19,8 +19,5 @@ named_geoip_init(void);
void void
named_geoip_load(char *dir); named_geoip_load(char *dir);
void
named_geoip_unload(void);
void void
named_geoip_shutdown(void); named_geoip_shutdown(void);
+3 -24
View File
@@ -59,10 +59,6 @@
#include <json_c_version.h> #include <json_c_version.h>
#endif /* HAVE_JSON_C */ #endif /* HAVE_JSON_C */
#ifdef HAVE_GEOIP2
#include <maxminddb.h>
#endif
/* /*
* Defining NAMED_MAIN provides storage declarations (rather than extern) * Defining NAMED_MAIN provides storage declarations (rather than extern)
* for variables in named/globals.h. * for variables in named/globals.h.
@@ -120,7 +116,7 @@ LIBDNS_EXTERNAL_DATA extern unsigned int dns_zone_mkey_month;
static bool want_stats = false; static bool want_stats = false;
static char program_name[NAME_MAX] = "named"; static char program_name[NAME_MAX] = "named";
static char absolute_conffile[PATH_MAX]; static char absolute_conffile[PATH_MAX];
static char saved_command_line[4096] = { 0 }; static char saved_command_line[8192] = { 0 };
static char ellipsis[5] = { 0 }; static char ellipsis[5] = { 0 };
static char version[512]; static char version[512];
static unsigned int maxsocks = 0; static unsigned int maxsocks = 0;
@@ -552,17 +548,6 @@ OPENSSL_VERSION_NUMBER >= 0x10100000L /* 1.1.0 or higher */
ZLIB_VERSION); ZLIB_VERSION);
printf("linked to zlib version: %s\n", printf("linked to zlib version: %s\n",
zlibVersion()); zlibVersion());
#endif
#if defined(HAVE_GEOIP2)
/* Unfortunately, no version define on link time */
printf("linked to maxminddb version: %s\n",
MMDB_lib_version());
#endif
#if defined(HAVE_DNSTAP)
printf("compiled with protobuf-c version: %s\n",
PROTOBUF_C_VERSION);
printf("linked to protobuf-c version: %s\n",
protobuf_c_version());
#endif #endif
printf("threads support is enabled\n\n"); printf("threads support is enabled\n\n");
@@ -1344,6 +1329,8 @@ cleanup(void) {
dlz_dlopen_clear(); dlz_dlopen_clear();
#endif #endif
dns_name_destroy();
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL, isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
NAMED_LOGMODULE_MAIN, NAMED_LOGMODULE_MAIN,
ISC_LOG_NOTICE, "exiting"); ISC_LOG_NOTICE, "exiting");
@@ -1456,10 +1443,6 @@ main(int argc, char *argv[]) {
setvbuf(stderr, NULL, _IOFBF, BUFSIZ); setvbuf(stderr, NULL, _IOFBF, BUFSIZ);
#endif #endif
#ifdef HAVE_LIBXML2
xmlInitThreads();
#endif /* HAVE_LIBXML2 */
/* /*
* Record version in core image. * Record version in core image.
* strings named.core | grep "named version:" * strings named.core | grep "named version:"
@@ -1592,10 +1575,6 @@ main(int argc, char *argv[]) {
named_os_shutdown(); named_os_shutdown();
#ifdef HAVE_LIBXML2
xmlCleanupThreads();
#endif /* HAVE_LIBXML2 */
#ifdef HAVE_GPERFTOOLS_PROFILER #ifdef HAVE_GPERFTOOLS_PROFILER
ProfilerStop(); ProfilerStop();
#endif #endif
+21 -21
View File
@@ -97,6 +97,20 @@ dlz \fIstring\fR {
.if n \{\ .if n \{\
.RE .RE
.\} .\}
.SH "DNSSEC-KEYS"
.sp
.if n \{\
.RS 4
.\}
.nf
dnssec\-keys { \fIstring\fR ( static\-key |
initial\-key | static\-ds | initial\-ds )
\fIinteger\fR \fIinteger\fR \fIinteger\fR
\fIquoted_string\fR; \&.\&.\&. };
.fi
.if n \{\
.RE
.\}
.SH "DYNDB" .SH "DYNDB"
.sp .sp
.if n \{\ .if n \{\
@@ -150,7 +164,7 @@ logging {
.\} .\}
.SH "MANAGED-KEYS" .SH "MANAGED-KEYS"
.PP .PP
Deprecated \- see TRUST\-ANCHORS\&. Deprecated \- see DNSSEC\-KEYS\&.
.sp .sp
.if n \{\ .if n \{\
.RS 4 .RS 4
@@ -551,23 +565,9 @@ statistics\-channels {
.if n \{\ .if n \{\
.RE .RE
.\} .\}
.SH "TRUST-ANCHORS"
.sp
.if n \{\
.RS 4
.\}
.nf
trust\-anchors { \fIstring\fR ( static\-key |
initial\-key | static\-ds | initial\-ds )
\fIinteger\fR \fIinteger\fR \fIinteger\fR
\fIquoted_string\fR; \&.\&.\&. };
.fi
.if n \{\
.RE
.\}
.SH "TRUSTED-KEYS" .SH "TRUSTED-KEYS"
.PP .PP
Deprecated \- see TRUST\-ANCHORS\&. Deprecated \- see DNSSEC\-KEYS\&.
.sp .sp
.if n \{\ .if n \{\
.RS 4 .RS 4
@@ -655,6 +655,10 @@ view \fIstring\fR [ \fIclass\fR ] {
dnsrps\-options { \fIunspecified\-text\fR }; dnsrps\-options { \fIunspecified\-text\fR };
dnssec\-accept\-expired \fIboolean\fR; dnssec\-accept\-expired \fIboolean\fR;
dnssec\-dnskey\-kskonly \fIboolean\fR; dnssec\-dnskey\-kskonly \fIboolean\fR;
dnssec\-keys { \fIstring\fR ( static\-key |
initial\-key | static\-ds | initial\-ds
) \fIinteger\fR \fIinteger\fR \fIinteger\fR
\fIquoted_string\fR; \&.\&.\&. };
dnssec\-loadkeys\-interval \fIinteger\fR; dnssec\-loadkeys\-interval \fIinteger\fR;
dnssec\-must\-be\-secure \fIstring\fR \fIboolean\fR; dnssec\-must\-be\-secure \fIstring\fR \fIboolean\fR;
dnssec\-secure\-to\-insecure \fIboolean\fR; dnssec\-secure\-to\-insecure \fIboolean\fR;
@@ -845,10 +849,6 @@ view \fIstring\fR [ \fIclass\fR ] {
transfer\-source\-v6 ( \fIipv6_address\fR | * ) [ port ( \fIinteger\fR | * ) transfer\-source\-v6 ( \fIipv6_address\fR | * ) [ port ( \fIinteger\fR | * )
] [ dscp \fIinteger\fR ]; ] [ dscp \fIinteger\fR ];
trust\-anchor\-telemetry \fIboolean\fR; // experimental trust\-anchor\-telemetry \fIboolean\fR; // experimental
trust\-anchors { \fIstring\fR ( static\-key |
initial\-key | static\-ds | initial\-ds
) \fIinteger\fR \fIinteger\fR \fIinteger\fR
\fIquoted_string\fR; \&.\&.\&. };
trusted\-keys { \fIstring\fR trusted\-keys { \fIstring\fR
\fIinteger\fR \fIinteger\fR \fIinteger\fR \fIinteger\fR
\fIinteger\fR \fIinteger\fR
@@ -1074,7 +1074,7 @@ zone \fIstring\fR [ \fIclass\fR ] {
.\} .\}
.nf .nf
dnssec\-policy \fIstring\fR { dnssec\-policy \fIstring\fR {
dnskey\-ttl \fIduration\fR; dnskey\-ttl \fIttlval\fR;
keys { ( csk | ksk | zsk ) key\-directory lifetime \fIduration\fR algorithm \fIinteger\fR [ \fIinteger\fR ] ; \&.\&.\&. }; keys { ( csk | ksk | zsk ) key\-directory lifetime \fIduration\fR algorithm \fIinteger\fR [ \fIinteger\fR ] ; \&.\&.\&. };
parent\-ds\-ttl \fIduration\fR; parent\-ds\-ttl \fIduration\fR;
parent\-propagation\-delay \fIduration\fR; parent\-propagation\-delay \fIduration\fR;
+16 -17
View File
@@ -49,7 +49,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
@@ -111,6 +110,15 @@ dlz <replaceable>string</replaceable> {
</literallayout> </literallayout>
</refsection> </refsection>
<refsection><info><title>DNSSEC-KEYS</title></info>
<literallayout class="normal">
dnssec-keys { <replaceable>string</replaceable> ( static-key |
initial-key | static-ds | initial-ds )
<replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
<replaceable>quoted_string</replaceable>; ... };
</literallayout>
</refsection>
<refsection><info><title>DYNDB</title></info> <refsection><info><title>DYNDB</title></info>
<literallayout class="normal"> <literallayout class="normal">
dyndb <replaceable>string</replaceable> <replaceable>quoted_string</replaceable> { dyndb <replaceable>string</replaceable> <replaceable>quoted_string</replaceable> {
@@ -148,7 +156,7 @@ logging {
</refsection> </refsection>
<refsection><info><title>MANAGED-KEYS</title></info> <refsection><info><title>MANAGED-KEYS</title></info>
<para>Deprecated - see TRUST-ANCHORS.</para> <para>Deprecated - see DNSSEC-KEYS.</para>
<literallayout class="normal"> <literallayout class="normal">
managed-keys { <replaceable>string</replaceable> ( static-key managed-keys { <replaceable>string</replaceable> ( static-key
| initial-key | static-ds | | initial-key | static-ds |
@@ -519,17 +527,8 @@ statistics-channels {
</literallayout> </literallayout>
</refsection> </refsection>
<refsection><info><title>TRUST-ANCHORS</title></info>
<literallayout class="normal">
trust-anchors { <replaceable>string</replaceable> ( static-key |
initial-key | static-ds | initial-ds )
<replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
<replaceable>quoted_string</replaceable>; ... };
</literallayout>
</refsection>
<refsection><info><title>TRUSTED-KEYS</title></info> <refsection><info><title>TRUSTED-KEYS</title></info>
<para>Deprecated - see TRUST-ANCHORS.</para> <para>Deprecated - see DNSSEC-KEYS.</para>
<literallayout class="normal"> <literallayout class="normal">
trusted-keys { <replaceable>string</replaceable> <replaceable>integer</replaceable> trusted-keys { <replaceable>string</replaceable> <replaceable>integer</replaceable>
<replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
@@ -608,6 +607,10 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
dnsrps-options { <replaceable>unspecified-text</replaceable> }; dnsrps-options { <replaceable>unspecified-text</replaceable> };
dnssec-accept-expired <replaceable>boolean</replaceable>; dnssec-accept-expired <replaceable>boolean</replaceable>;
dnssec-dnskey-kskonly <replaceable>boolean</replaceable>; dnssec-dnskey-kskonly <replaceable>boolean</replaceable>;
dnssec-keys { <replaceable>string</replaceable> ( static-key |
initial-key | static-ds | initial-ds
) <replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
<replaceable>quoted_string</replaceable>; ... };
dnssec-loadkeys-interval <replaceable>integer</replaceable>; dnssec-loadkeys-interval <replaceable>integer</replaceable>;
dnssec-must-be-secure <replaceable>string</replaceable> <replaceable>boolean</replaceable>; dnssec-must-be-secure <replaceable>string</replaceable> <replaceable>boolean</replaceable>;
dnssec-secure-to-insecure <replaceable>boolean</replaceable>; dnssec-secure-to-insecure <replaceable>boolean</replaceable>;
@@ -798,10 +801,6 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
transfer-source-v6 ( <replaceable>ipv6_address</replaceable> | * ) [ port ( <replaceable>integer</replaceable> | * ) transfer-source-v6 ( <replaceable>ipv6_address</replaceable> | * ) [ port ( <replaceable>integer</replaceable> | * )
] [ dscp <replaceable>integer</replaceable> ]; ] [ dscp <replaceable>integer</replaceable> ];
trust-anchor-telemetry <replaceable>boolean</replaceable>; // experimental trust-anchor-telemetry <replaceable>boolean</replaceable>; // experimental
trust-anchors { <replaceable>string</replaceable> ( static-key |
initial-key | static-ds | initial-ds
) <replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
<replaceable>quoted_string</replaceable>; ... };
trusted-keys { <replaceable>string</replaceable> trusted-keys { <replaceable>string</replaceable>
<replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
<replaceable>integer</replaceable> <replaceable>integer</replaceable>
@@ -1018,7 +1017,7 @@ zone <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
<literallayout class="normal"> <literallayout class="normal">
dnssec-policy <replaceable>string</replaceable> { dnssec-policy <replaceable>string</replaceable> {
dnskey-ttl <replaceable>duration</replaceable>; dnskey-ttl <replaceable>ttlval</replaceable>;
keys { ( csk | ksk | zsk ) key-directory lifetime <replaceable>duration</replaceable> algorithm <replaceable>integer</replaceable> [ <replaceable>integer</replaceable> ] ; ... }; keys { ( csk | ksk | zsk ) key-directory lifetime <replaceable>duration</replaceable> algorithm <replaceable>integer</replaceable> [ <replaceable>integer</replaceable> ] ; ... };
parent-ds-ttl <replaceable>duration</replaceable>; parent-ds-ttl <replaceable>duration</replaceable>;
parent-propagation-delay <replaceable>duration</replaceable>; parent-propagation-delay <replaceable>duration</replaceable>;
+26 -26
View File
@@ -92,7 +92,17 @@ dlz
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.11"></a><h2>DYNDB</h2> <a name="id-1.11"></a><h2>DNSSEC-KEYS</h2>
<div class="literallayout"><p><br>
dnssec-keys { <em class="replaceable"><code>string</code></em> ( static-key |<br>
    initial-key | static-ds | initial-ds )<br>
    <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>quoted_string</code></em>; ... };<br>
</p></div>
</div>
<div class="refsection">
<a name="id-1.12"></a><h2>DYNDB</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
dyndb <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>quoted_string</code></em> {<br> dyndb <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>quoted_string</code></em> {<br>
    <em class="replaceable"><code>unspecified-text</code></em> };<br>     <em class="replaceable"><code>unspecified-text</code></em> };<br>
@@ -100,7 +110,7 @@ dyndb
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.12"></a><h2>KEY</h2> <a name="id-1.13"></a><h2>KEY</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
key <em class="replaceable"><code>string</code></em> {<br> key <em class="replaceable"><code>string</code></em> {<br>
algorithm <em class="replaceable"><code>string</code></em>;<br> algorithm <em class="replaceable"><code>string</code></em>;<br>
@@ -110,7 +120,7 @@ key
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.13"></a><h2>LOGGING</h2> <a name="id-1.14"></a><h2>LOGGING</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
logging {<br> logging {<br>
category <em class="replaceable"><code>string</code></em> { <em class="replaceable"><code>string</code></em>; ... };<br> category <em class="replaceable"><code>string</code></em> { <em class="replaceable"><code>string</code></em>; ... };<br>
@@ -131,8 +141,8 @@ logging
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.14"></a><h2>MANAGED-KEYS</h2> <a name="id-1.15"></a><h2>MANAGED-KEYS</h2>
<p>Deprecated - see TRUST-ANCHORS.</p> <p>Deprecated - see DNSSEC-KEYS.</p>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
managed-keys { <em class="replaceable"><code>string</code></em> ( static-key<br> managed-keys { <em class="replaceable"><code>string</code></em> ( static-key<br>
    | initial-key | static-ds |<br>     | initial-key | static-ds |<br>
@@ -142,7 +152,7 @@ managed-keys
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.15"></a><h2>MASTERS</h2> <a name="id-1.16"></a><h2>MASTERS</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
masters <em class="replaceable"><code>string</code></em> [ port <em class="replaceable"><code>integer</code></em> ] [ dscp<br> masters <em class="replaceable"><code>string</code></em> [ port <em class="replaceable"><code>integer</code></em> ] [ dscp<br>
    <em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [<br>     <em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [<br>
@@ -152,7 +162,7 @@ masters
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.16"></a><h2>OPTIONS</h2> <a name="id-1.17"></a><h2>OPTIONS</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
options {<br> options {<br>
allow-new-zones <em class="replaceable"><code>boolean</code></em>;<br> allow-new-zones <em class="replaceable"><code>boolean</code></em>;<br>
@@ -451,7 +461,7 @@ options
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.17"></a><h2>PLUGIN</h2> <a name="id-1.18"></a><h2>PLUGIN</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
plugin ( query ) <em class="replaceable"><code>string</code></em> [ { <em class="replaceable"><code>unspecified-text</code></em><br> plugin ( query ) <em class="replaceable"><code>string</code></em> [ { <em class="replaceable"><code>unspecified-text</code></em><br>
    } ];<br>     } ];<br>
@@ -459,7 +469,7 @@ plugin
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.18"></a><h2>SERVER</h2> <a name="id-1.19"></a><h2>SERVER</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
server <em class="replaceable"><code>netprefix</code></em> {<br> server <em class="replaceable"><code>netprefix</code></em> {<br>
bogus <em class="replaceable"><code>boolean</code></em>;<br> bogus <em class="replaceable"><code>boolean</code></em>;<br>
@@ -497,7 +507,7 @@ server
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.19"></a><h2>STATISTICS-CHANNELS</h2> <a name="id-1.20"></a><h2>STATISTICS-CHANNELS</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
statistics-channels {<br> statistics-channels {<br>
inet ( <em class="replaceable"><code>ipv4_address</code></em> | <em class="replaceable"><code>ipv6_address</code></em> |<br> inet ( <em class="replaceable"><code>ipv4_address</code></em> | <em class="replaceable"><code>ipv6_address</code></em> |<br>
@@ -508,19 +518,9 @@ statistics-channels
</p></div> </p></div>
</div> </div>
<div class="refsection">
<a name="id-1.20"></a><h2>TRUST-ANCHORS</h2>
<div class="literallayout"><p><br>
trust-anchors { <em class="replaceable"><code>string</code></em> ( static-key |<br>
    initial-key | static-ds | initial-ds )<br>
    <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>quoted_string</code></em>; ... };<br>
</p></div>
</div>
<div class="refsection"> <div class="refsection">
<a name="id-1.21"></a><h2>TRUSTED-KEYS</h2> <a name="id-1.21"></a><h2>TRUSTED-KEYS</h2>
<p>Deprecated - see TRUST-ANCHORS.</p> <p>Deprecated - see DNSSEC-KEYS.</p>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
trusted-keys { <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>integer</code></em><br> trusted-keys { <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>     <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
@@ -600,6 +600,10 @@ view
dnsrps-options { <em class="replaceable"><code>unspecified-text</code></em> };<br> dnsrps-options { <em class="replaceable"><code>unspecified-text</code></em> };<br>
dnssec-accept-expired <em class="replaceable"><code>boolean</code></em>;<br> dnssec-accept-expired <em class="replaceable"><code>boolean</code></em>;<br>
dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br> dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br>
dnssec-keys { <em class="replaceable"><code>string</code></em> ( static-key |<br>
    initial-key | static-ds | initial-ds<br>
    ) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>quoted_string</code></em>; ... };<br>
dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br> dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br>
dnssec-must-be-secure <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>boolean</code></em>;<br> dnssec-must-be-secure <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>boolean</code></em>;<br>
dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br> dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br>
@@ -790,10 +794,6 @@ view
transfer-source-v6 ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * )<br> transfer-source-v6 ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * )<br>
    ] [ dscp <em class="replaceable"><code>integer</code></em> ];<br>     ] [ dscp <em class="replaceable"><code>integer</code></em> ];<br>
trust-anchor-telemetry <em class="replaceable"><code>boolean</code></em>; // experimental<br> trust-anchor-telemetry <em class="replaceable"><code>boolean</code></em>; // experimental<br>
trust-anchors { <em class="replaceable"><code>string</code></em> ( static-key |<br>
    initial-key | static-ds | initial-ds<br>
    ) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>quoted_string</code></em>; ... };<br>
trusted-keys { <em class="replaceable"><code>string</code></em><br> trusted-keys { <em class="replaceable"><code>string</code></em><br>
    <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>     <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>integer</code></em><br>     <em class="replaceable"><code>integer</code></em><br>
@@ -1012,7 +1012,7 @@ zone
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
dnssec-policy <em class="replaceable"><code>string</code></em> {<br> dnssec-policy <em class="replaceable"><code>string</code></em> {<br>
dnskey-ttl <em class="replaceable"><code>duration</code></em>;<br> dnskey-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
keys { ( csk | ksk | zsk ) key-directory lifetime <em class="replaceable"><code>duration</code></em> algorithm <em class="replaceable"><code>integer</code></em> [ <em class="replaceable"><code>integer</code></em> ] ; ... };<br> keys { ( csk | ksk | zsk ) key-directory lifetime <em class="replaceable"><code>duration</code></em> algorithm <em class="replaceable"><code>integer</code></em> [ <em class="replaceable"><code>integer</code></em> ] ; ... };<br>
parent-ds-ttl <em class="replaceable"><code>duration</code></em>;<br> parent-ds-ttl <em class="replaceable"><code>duration</code></em>;<br>
parent-propagation-delay <em class="replaceable"><code>duration</code></em>;<br> parent-propagation-delay <em class="replaceable"><code>duration</code></em>;<br>
-1
View File
@@ -49,7 +49,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+35 -47
View File
@@ -68,7 +68,6 @@
#include <dns/events.h> #include <dns/events.h>
#include <dns/forward.h> #include <dns/forward.h>
#include <dns/fixedname.h> #include <dns/fixedname.h>
#include <dns/geoip.h>
#include <dns/journal.h> #include <dns/journal.h>
#include <dns/kasp.h> #include <dns/kasp.h>
#include <dns/keytable.h> #include <dns/keytable.h>
@@ -705,7 +704,7 @@ ta_fromconfig(const cfg_obj_t *key, bool *initialp, dst_key_t **keyp,
{ {
dns_rdata_dnskey_t keystruct; dns_rdata_dnskey_t keystruct;
dns_rdata_ds_t *ds = NULL; dns_rdata_ds_t *ds = NULL;
uint32_t rdata1, rdata2, rdata3; uint32_t n1, n2, n3;
const char *datastr = NULL, *namestr = NULL; const char *datastr = NULL, *namestr = NULL;
unsigned char data[4096]; unsigned char data[4096];
isc_buffer_t databuf; isc_buffer_t databuf;
@@ -731,13 +730,13 @@ ta_fromconfig(const cfg_obj_t *key, bool *initialp, dst_key_t **keyp,
REQUIRE(namestrp != NULL && *namestrp == NULL); REQUIRE(namestrp != NULL && *namestrp == NULL);
/* if DNSKEY, flags; if DS, key tag */ /* if DNSKEY, flags; if DS, key tag */
rdata1 = cfg_obj_asuint32(cfg_tuple_get(key, "rdata1")); n1 = cfg_obj_asuint32(cfg_tuple_get(key, "n1"));
/* if DNSKEY, protocol; if DS, algorithm */ /* if DNSKEY, protocol; if DS, algorithm */
rdata2 = cfg_obj_asuint32(cfg_tuple_get(key, "rdata2")); n2 = cfg_obj_asuint32(cfg_tuple_get(key, "n2"));
/* if DNSKEY, algorithm; if DS, digest type */ /* if DNSKEY, algorithm; if DS, digest type */
rdata3 = cfg_obj_asuint32(cfg_tuple_get(key, "rdata3")); n3 = cfg_obj_asuint32(cfg_tuple_get(key, "n3"));
namestr = cfg_obj_asstring(cfg_tuple_get(key, "name")); namestr = cfg_obj_asstring(cfg_tuple_get(key, "name"));
*namestrp = namestr; *namestrp = namestr;
@@ -793,22 +792,22 @@ ta_fromconfig(const cfg_obj_t *key, bool *initialp, dst_key_t **keyp,
ISC_LINK_INIT(&keystruct.common, link); ISC_LINK_INIT(&keystruct.common, link);
if (rdata1 > 0xffff) { if (n1 > 0xffff) {
CHECKM(ISC_R_RANGE, "key flags"); CHECKM(ISC_R_RANGE, "key flags");
} }
if (rdata1 & DNS_KEYFLAG_REVOKE) { if (n1 & DNS_KEYFLAG_REVOKE) {
CHECKM(DST_R_BADKEYTYPE, "key flags revoke bit set"); CHECKM(DST_R_BADKEYTYPE, "key flags revoke bit set");
} }
if (rdata2 > 0xff) { if (n2 > 0xff) {
CHECKM(ISC_R_RANGE, "key protocol"); CHECKM(ISC_R_RANGE, "key protocol");
} }
if (rdata3> 0xff) { if (n3> 0xff) {
CHECKM(ISC_R_RANGE, "key algorithm"); CHECKM(ISC_R_RANGE, "key algorithm");
} }
keystruct.flags = (uint16_t)rdata1; keystruct.flags = (uint16_t)n1;
keystruct.protocol = (uint8_t)rdata2; keystruct.protocol = (uint8_t)n2;
keystruct.algorithm = (uint8_t)rdata3; keystruct.algorithm = (uint8_t)n3;
datastr = cfg_obj_asstring(cfg_tuple_get(key, "data")); datastr = cfg_obj_asstring(cfg_tuple_get(key, "data"));
CHECK(isc_base64_decodestring(datastr, &databuf)); CHECK(isc_base64_decodestring(datastr, &databuf));
@@ -834,19 +833,19 @@ ta_fromconfig(const cfg_obj_t *key, bool *initialp, dst_key_t **keyp,
ISC_LINK_INIT(&ds->common, link); ISC_LINK_INIT(&ds->common, link);
if (rdata1 > 0xffff) { if (n1 > 0xffff) {
CHECKM(ISC_R_RANGE, "key tag"); CHECKM(ISC_R_RANGE, "key tag");
} }
if (rdata2 > 0xff) { if (n2 > 0xff) {
CHECKM(ISC_R_RANGE, "key algorithm"); CHECKM(ISC_R_RANGE, "key algorithm");
} }
if (rdata3 > 0xff) { if (n3 > 0xff) {
CHECKM(ISC_R_RANGE, "digest type"); CHECKM(ISC_R_RANGE, "digest type");
} }
ds->key_tag = (uint16_t)rdata1; ds->key_tag = (uint16_t)n1;
ds->algorithm = (uint8_t)rdata2; ds->algorithm = (uint8_t)n2;
ds->digest_type = (uint8_t)rdata3; ds->digest_type = (uint8_t)n3;
datastr = cfg_obj_asstring(cfg_tuple_get(key, "data")); datastr = cfg_obj_asstring(cfg_tuple_get(key, "data"));
CHECK(isc_hex_decodestring(datastr, &databuf)); CHECK(isc_hex_decodestring(datastr, &databuf));
@@ -868,14 +867,6 @@ ta_fromconfig(const cfg_obj_t *key, bool *initialp, dst_key_t **keyp,
CHECK(ISC_R_UNEXPECTEDEND); CHECK(ISC_R_UNEXPECTEDEND);
} }
break; break;
default:
cfg_obj_log(key, named_g_lctx, ISC_LOG_ERROR,
"key '%s': "
"unknown ds digest type %u",
namestr, ds->digest_type);
result = ISC_R_FAILURE;
goto cleanup;
break;
} }
ds->mctx = mctx; ds->mctx = mctx;
@@ -1020,7 +1011,7 @@ process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
} }
/* /*
* Add the key to 'secroots'. Keys from a "trust-anchors" or * Add the key to 'secroots'. Keys from a "dnssec-keys" or
* "managed-keys" statement may be either static or initializing * "managed-keys" statement may be either static or initializing
* keys. If it's not initializing, we don't want to treat it as * keys. If it's not initializing, we don't want to treat it as
* managed, so we use 'initializing' twice here, for both the * managed, so we use 'initializing' twice here, for both the
@@ -1132,9 +1123,9 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
const cfg_obj_t *view_keys = NULL; const cfg_obj_t *view_keys = NULL;
const cfg_obj_t *global_keys = NULL; const cfg_obj_t *global_keys = NULL;
const cfg_obj_t *view_managed_keys = NULL; const cfg_obj_t *view_managed_keys = NULL;
const cfg_obj_t *view_trust_anchors = NULL; const cfg_obj_t *view_dnssec_keys = NULL;
const cfg_obj_t *global_managed_keys = NULL; const cfg_obj_t *global_managed_keys = NULL;
const cfg_obj_t *global_trust_anchors = NULL; const cfg_obj_t *global_dnssec_keys = NULL;
const cfg_obj_t *maps[4]; const cfg_obj_t *maps[4];
const cfg_obj_t *voptions = NULL; const cfg_obj_t *voptions = NULL;
const cfg_obj_t *options = NULL; const cfg_obj_t *options = NULL;
@@ -1155,11 +1146,11 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
(void) cfg_map_get(voptions, "trusted-keys", (void) cfg_map_get(voptions, "trusted-keys",
&view_keys); &view_keys);
/* managed-keys and trust-anchors are synonyms. */ /* managed-keys and dnssec-keys are synonyms. */
(void) cfg_map_get(voptions, "managed-keys", (void) cfg_map_get(voptions, "managed-keys",
&view_managed_keys); &view_managed_keys);
(void) cfg_map_get(voptions, "trust-anchors", (void) cfg_map_get(voptions, "dnssec-keys",
&view_trust_anchors); &view_dnssec_keys);
maps[i++] = voptions; maps[i++] = voptions;
} }
@@ -1168,10 +1159,9 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
if (config != NULL) { if (config != NULL) {
(void)cfg_map_get(config, "trusted-keys", &global_keys); (void)cfg_map_get(config, "trusted-keys", &global_keys);
/* managed-keys and trust-anchors are synonyms. */ /* managed-keys and dnssec-keys are synonyms. */
(void)cfg_map_get(config, "managed-keys", &global_managed_keys); (void)cfg_map_get(config, "managed-keys", &global_managed_keys);
(void)cfg_map_get(config, "trust-anchors", (void)cfg_map_get(config, "dnssec-keys", &global_dnssec_keys);
&global_trust_anchors);
(void)cfg_map_get(config, "options", &options); (void)cfg_map_get(config, "options", &options);
if (options != NULL) { if (options != NULL) {
@@ -1203,7 +1193,7 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
/* /*
* If bind.keys exists and is populated, it overrides * If bind.keys exists and is populated, it overrides
* the trust-anchors clause hard-coded in named_g_config. * the dnssec-keys clause hard-coded in named_g_config.
*/ */
if (bindkeys != NULL) { if (bindkeys != NULL) {
isc_log_write(named_g_lctx, DNS_LOGCATEGORY_SECURITY, isc_log_write(named_g_lctx, DNS_LOGCATEGORY_SECURITY,
@@ -1212,7 +1202,7 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
"from '%s'", "from '%s'",
view->name, named_g_server->bindkeysfile); view->name, named_g_server->bindkeysfile);
(void)cfg_map_get(bindkeys, "trust-anchors", (void)cfg_map_get(bindkeys, "dnssec-keys",
&builtin_keys); &builtin_keys);
if (builtin_keys == NULL) { if (builtin_keys == NULL) {
@@ -1232,7 +1222,7 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
"using built-in root key for view %s", "using built-in root key for view %s",
view->name); view->name);
(void)cfg_map_get(named_g_config, "trust-anchors", (void)cfg_map_get(named_g_config, "dnssec-keys",
&builtin_keys); &builtin_keys);
} }
@@ -1252,13 +1242,13 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
if (view->rdclass == dns_rdataclass_in) { if (view->rdclass == dns_rdataclass_in) {
CHECK(load_view_keys(view_keys, view, false, NULL, mctx)); CHECK(load_view_keys(view_keys, view, false, NULL, mctx));
CHECK(load_view_keys(view_trust_anchors, view, true, NULL, CHECK(load_view_keys(view_dnssec_keys, view, true, NULL,
mctx)); mctx));
CHECK(load_view_keys(view_managed_keys, view, true, NULL, CHECK(load_view_keys(view_managed_keys, view, true, NULL,
mctx)); mctx));
CHECK(load_view_keys(global_keys, view, false, NULL, mctx)); CHECK(load_view_keys(global_keys, view, false, NULL, mctx));
CHECK(load_view_keys(global_trust_anchors, view, true, CHECK(load_view_keys(global_dnssec_keys, view, true,
NULL, mctx)); NULL, mctx));
CHECK(load_view_keys(global_managed_keys, view, true, CHECK(load_view_keys(global_managed_keys, view, true,
NULL, mctx)); NULL, mctx));
@@ -7413,7 +7403,7 @@ configure_session_key(const cfg_obj_t **maps, named_server_t *server,
server->session_keyname = isc_mem_get(mctx, server->session_keyname = isc_mem_get(mctx,
sizeof(dns_name_t)); sizeof(dns_name_t));
dns_name_init(server->session_keyname, NULL); dns_name_init(server->session_keyname, NULL);
dns_name_dup(keyname, mctx, server->session_keyname); CHECK(dns_name_dup(keyname, mctx, server->session_keyname));
server->session_keyfile = isc_mem_strdup(mctx, keyfile); server->session_keyfile = isc_mem_strdup(mctx, keyfile);
@@ -8348,11 +8338,6 @@ load_configuration(const char *filename, named_server_t *server,
isc_socketmgr_setreserved(named_g_socketmgr, reserved); isc_socketmgr_setreserved(named_g_socketmgr, reserved);
#if defined(HAVE_GEOIP2) #if defined(HAVE_GEOIP2)
/*
* Release any previously opened GeoIP2 databases.
*/
named_geoip_unload();
/* /*
* Initialize GeoIP databases from the configured location. * Initialize GeoIP databases from the configured location.
* This should happen before configuring any ACLs, so that we * This should happen before configuring any ACLs, so that we
@@ -9752,6 +9737,9 @@ shutdown_server(isc_task_t *task, isc_event_t *event) {
dns_tsigkey_detach(&named_g_sessionkey); dns_tsigkey_detach(&named_g_sessionkey);
dns_name_free(&named_g_sessionkeyname, server->mctx); dns_name_free(&named_g_sessionkeyname, server->mctx);
} }
#ifdef HAVE_DNSTAP
dns_dt_shutdown();
#endif
#if defined(HAVE_GEOIP2) #if defined(HAVE_GEOIP2)
named_geoip_shutdown(); named_geoip_shutdown();
#endif /* HAVE_GEOIP2 */ #endif /* HAVE_GEOIP2 */
@@ -9875,7 +9863,7 @@ named_server_create(isc_mem_t *mctx, named_server_t **serverp) {
/* /*
* GeoIP must be initialized before the interface * GeoIP must be initialized before the interface
* manager (which includes the ACL environment) * manager (which includes the ACL environment)
* is created. * is created
*/ */
named_geoip_init(); named_geoip_init();
#endif /* HAVE_GEOIP2 */ #endif /* HAVE_GEOIP2 */
+8 -3
View File
@@ -324,9 +324,6 @@ init_desc(void) {
"QryUsedStale"); "QryUsedStale");
SET_NSSTATDESC(prefetch, "queries triggered prefetch", "Prefetch"); SET_NSSTATDESC(prefetch, "queries triggered prefetch", "Prefetch");
SET_NSSTATDESC(keytagopt, "Keytag option received", "KeyTagOpt"); SET_NSSTATDESC(keytagopt, "Keytag option received", "KeyTagOpt");
SET_NSSTATDESC(reclimitdropped,
"queries dropped due to recursive client limit",
"RecLimitDropped");
INSIST(i == ns_statscounter_max); INSIST(i == ns_statscounter_max);
@@ -3593,6 +3590,10 @@ named_statschannels_configure(named_server_t *server, const cfg_obj_t *config,
ISC_LIST_INIT(new_listeners); ISC_LIST_INIT(new_listeners);
#ifdef HAVE_LIBXML2
xmlInitThreads();
#endif /* HAVE_LIBXML2 */
/* /*
* Get the list of named.conf 'statistics-channels' statements. * Get the list of named.conf 'statistics-channels' statements.
*/ */
@@ -3725,6 +3726,10 @@ named_statschannels_shutdown(named_server_t *server) {
ISC_LIST_UNLINK(server->statschannels, listener, link); ISC_LIST_UNLINK(server->statschannels, listener, link);
shutdown_listener(listener); shutdown_listener(listener);
} }
#ifdef HAVE_LIBXML2
xmlCleanupThreads();
#endif /* HAVE_LIBXML2 */
} }
isc_result_t isc_result_t
+2 -1
View File
@@ -85,7 +85,7 @@ named_tkeyctx_fromconfig(const cfg_obj_t *options, isc_mem_t *mctx,
RETERR(dns_name_fromtext(name, &b, dns_rootname, 0, NULL)); RETERR(dns_name_fromtext(name, &b, dns_rootname, 0, NULL));
tctx->domain = isc_mem_get(mctx, sizeof(dns_name_t)); tctx->domain = isc_mem_get(mctx, sizeof(dns_name_t));
dns_name_init(tctx->domain, NULL); dns_name_init(tctx->domain, NULL);
dns_name_dup(name, mctx, tctx->domain); RETERR(dns_name_dup(name, mctx, tctx->domain));
} }
obj = NULL; obj = NULL;
@@ -114,3 +114,4 @@ named_tkeyctx_fromconfig(const cfg_obj_t *options, isc_mem_t *mctx,
dns_tkeyctx_destroy(&tctx); dns_tkeyctx_destroy(&tctx);
return (result); return (result);
} }
+3
View File
@@ -3210,6 +3210,9 @@ cleanup(void) {
ddebug("Shutting down timer manager"); ddebug("Shutting down timer manager");
isc_timermgr_destroy(&timermgr); isc_timermgr_destroy(&timermgr);
ddebug("Destroying name state");
dns_name_destroy();
ddebug("Removing log context"); ddebug("Removing log context");
isc_log_destroy(&glctx); isc_log_destroy(&glctx);
-1
View File
@@ -50,7 +50,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -124,7 +124,7 @@ main(int argc, char *argv[]) {
if (errflg || (id && (label != NULL))) { if (errflg || (id && (label != NULL))) {
fprintf(stderr, "Usage:\n"); fprintf(stderr, "Usage:\n");
fprintf(stderr, "\tpkcs11-destroy [-m module] [-s slot] " fprintf(stderr, "\tpkcs11-destroy [-m module] [-s slot] "
"{-i id | -l label} [-p pin] [-w waittime]\n"); "[-i id | -l label] [-p pin] [-w waittime]\n");
exit(1); exit(1);
} }
-1
View File
@@ -38,7 +38,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
-1
View File
@@ -39,7 +39,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
-1
View File
@@ -38,7 +38,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
-1
View File
@@ -37,7 +37,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
-1
View File
@@ -33,7 +33,6 @@
<copyright> <copyright>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
-1
View File
@@ -40,7 +40,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
-1
View File
@@ -38,7 +38,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
-1
View File
@@ -35,7 +35,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -516,7 +516,7 @@ timer\&.
\fBsecroots \fR\fB[\-]\fR\fB \fR\fB[\fIview \&.\&.\&.\fR]\fR \fBsecroots \fR\fB[\-]\fR\fB \fR\fB[\fIview \&.\&.\&.\fR]\fR
.RS 4 .RS 4
Dump the security roots (i\&.e\&., trust anchors configured via Dump the security roots (i\&.e\&., trust anchors configured via
\fBtrust\-anchors\fR \fBdnssec\-keys\fR
statements, or the managed\-keys or trusted\-keys statements (both deprecated), or via statements, or the managed\-keys or trusted\-keys statements (both deprecated), or via
\fBdnssec\-validation auto\fR) and negative trust anchors for the specified views\&. If no view is specified, all views are dumped\&. Security roots will indicate whether they are configured as trusted keys, managed keys, or initializing managed keys (managed keys that have not yet been updated by a successful key refresh query)\&. \fBdnssec\-validation auto\fR) and negative trust anchors for the specified views\&. If no view is specified, all views are dumped\&. Security roots will indicate whether they are configured as trusted keys, managed keys, or initializing managed keys (managed keys that have not yet been updated by a successful key refresh query)\&.
.sp .sp
+2
View File
@@ -1022,6 +1022,8 @@ main(int argc, char **argv) {
isc_mem_put(rndc_mctx, args, argslen); isc_mem_put(rndc_mctx, args, argslen);
isccc_ccmsg_invalidate(&ccmsg); isccc_ccmsg_invalidate(&ccmsg);
dns_name_destroy();
isc_buffer_free(&databuf); isc_buffer_free(&databuf);
if (show_final_mem) if (show_final_mem)
-1
View File
@@ -43,7 +43,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -2
View File
@@ -44,7 +44,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
@@ -774,7 +773,7 @@
<listitem> <listitem>
<para> <para>
Dump the security roots (i.e., trust anchors Dump the security roots (i.e., trust anchors
configured via <command>trust-anchors</command> statements, or the configured via <command>dnssec-keys</command> statements, or the
managed-keys or trusted-keys statements (both deprecated), or managed-keys or trusted-keys statements (both deprecated), or
via <command>dnssec-validation auto</command>) and negative trust via <command>dnssec-validation auto</command>) and negative trust
anchors for the specified views. If no view is specified, all anchors for the specified views. If no view is specified, all
+1 -1
View File
@@ -654,7 +654,7 @@
<dd> <dd>
<p> <p>
Dump the security roots (i.e., trust anchors Dump the security roots (i.e., trust anchors
configured via <span class="command"><strong>trust-anchors</strong></span> statements, or the configured via <span class="command"><strong>dnssec-keys</strong></span> statements, or the
managed-keys or trusted-keys statements (both deprecated), or managed-keys or trusted-keys statements (both deprecated), or
via <span class="command"><strong>dnssec-validation auto</strong></span>) and negative trust via <span class="command"><strong>dnssec-validation auto</strong></span>) and negative trust
anchors for the specified views. If no view is specified, all anchors for the specified views. If no view is specified, all
+2 -1
View File
@@ -244,7 +244,8 @@ lookup(const char *target) {
result = dns_name_fromtext(&name, &t, dns_rootname, 0, &namebuf); result = dns_name_fromtext(&name, &t, dns_rootname, 0, &namebuf);
check_result(result, "dns_name_fromtext %s", target); check_result(result, "dns_name_fromtext %s", target);
dns_name_dup(&name, mctx, &client->name); result = dns_name_dup(&name, mctx, &client->name);
check_result(result, "dns_name_dup %s", target);
options = 0; options = 0;
options |= DNS_ADBFIND_INET; options |= DNS_ADBFIND_INET;
+1 -1
View File
@@ -5,7 +5,7 @@ named.lock
named.pid named.pid
named.run named.run
/feature-test /feature-test
/test.output.* **/test.output
/systests.output /systests.output
/random.data /random.data
parallel.mk parallel.mk
+1 -1
View File
@@ -64,7 +64,7 @@ parallel.mk:
test: parallel.mk subdirs test: parallel.mk subdirs
@$(MAKE) -f parallel.mk check @$(MAKE) -f parallel.mk check
@$(SHELL) ./runsequential.sh @$(SHELL) ./runsequential.sh -r
@$(SHELL) ./testsummary.sh @$(SHELL) ./testsummary.sh
check: test check: test
+66 -18
View File
@@ -98,6 +98,19 @@ Optional flags are:
ports 7900 through 7999). If not specified, the test will ports 7900 through 7999). If not specified, the test will
have ports 5000 to 5099 available to it. have ports 5000 to 5099 available to it.
-r The "runall" flag. This is related to cleaning up after
the tests (see "Maintenance Notes" below). If specified,
it prevents a copy of the test's output listing from being
deleted when the directory is cleaned up after the test
completes. (The test's output listing comprises messages
produced by the test during its execution; it does not
include the output files produced by utilities such as
"dig" or "rndc", nor any logging output from named itself.)
It is usually only used when "run.sh" is being called
during a run of the entire test suite. Note that if "-n"
is specified on the "run.sh" command line, the test output
is retained even if this option is omitted.
Arguments are: Arguments are:
test-name Mandatory. The name of the test, which is the name of the test-name Mandatory. The name of the test, which is the name of the
@@ -240,12 +253,22 @@ Re-Running the Tests
--- ---
If there is a requirement to re-run a test (or the entire test suite), the If there is a requirement to re-run a test (or the entire test suite), the
files produced by the tests should be deleted first. Normally, these files are files produced by the tests should be deleted first. Normally, these files are
deleted if the test succeeds but are retained on error. The run.sh script deleted if the test succeeds but are retained on error.
automatically calls a given test's clean.sh script before invoking its setup.sh
script. Deletion of files produced by an individual test can be done with the command:
sh clean.sh [-r] <test-name>
The optional flag is:
-r The "runall" flag. This is related to cleaning up after
the tests (see "Maintenance Notes" below). If specified,
it prevents a copy of the test's output listing from being
deleted when the directory is cleaned after the test
completes.
Deletion of the files produced by the set of tests (e.g. after the execution Deletion of the files produced by the set of tests (e.g. after the execution
of "runall.sh") can be carried out using the command: of "runall.sh") can be deleted by the command:
sh cleanall.sh sh cleanall.sh
@@ -686,7 +709,7 @@ the ports are assigned when the tests are run. This is achieved by having the
when "make check" is run, and contains a target for each test of the form: when "make check" is run, and contains a target for each test of the form:
<test-name>: <test-name>:
@$(SHELL) run.sh -p <baseport> <test-name> @$(SHELL) run.sh -r -p <baseport> <test-name>
The <baseport> is unique and the values of <baseport> for each test are The <baseport> is unique and the values of <baseport> for each test are
separated by at least 100 ports. separated by at least 100 ports.
@@ -694,27 +717,52 @@ separated by at least 100 ports.
Cleaning Up From Tests Cleaning Up From Tests
--- ---
When a test is run, up to three different types of files are created: When a test is run, files are created in the test directory. These files fall
into three categories:
1. Files generated by the test itself, e.g. output from "dig" and "rndc", are 1. Files generated by the test itself, e.g. output from "dig" and "rndc".
stored in the test directory.
2. Files produced by named which may not be cleaned up if named exits 2. Files produced by named which may not be cleaned up if named exits
abnormally, e.g. core files, PID files etc., are stored in the test directory. abnormally, e.g. core files, PID files etc.
3. A file "test.output.<test-name>" containing the text written to stdout by the 3. The file "test.output" containing the text written to stdout by the test.
test is written to bin/tests/system/. This file is only produced when the test This is only produced when the test is run as part of the entire test suite
is run as part of the entire test suite (e.g. via "runall.sh"). (e.g. via "runall.sh").
If the test fails, all these files are retained. But if the test succeeds, If the test fails, all these files are retained. But if the test succeeds,
they are cleaned up at different times: they are cleaned up at different times:
1. Files generated by the test itself are cleaned up by the test's own 1. Files generated by the test itself are cleaned up by the test's own
"clean.sh", which is called from "run.sh". "clean.sh". This is called from the system's "clean.sh", which in turn is
called from "run.sh".
2. Files that may not be cleaned up if named exits abnormally can be removed 2. Files that may not be cleaned up if named exits abnormally are removed
using the "cleanall.sh" script. by the system's "clean.sh".
3. "test.output.*" files are deleted when the test suite ends. At this point, 3. "test.output" files are deleted when the test suite ends. At this point,
the file "testsummary.sh" is called which concatenates all the "test.output.*" the file "testsummary.sh" is called which concatenates all the "test.output"
files into a single "systests.output" file before deleting them. files into a single "systest.output" file before deleting them.
A complication arises with the "test.output" file however:
1. "clean.sh" is called by "run.sh" if the test ends successfully. For
this reason, "clean.sh" cannot delete "test.output" as, if the test is
being run as part of a test suite, the file must be retained.
2. If the deletion of "test.output" were to be solely the responsibility of
"testsummary.sh", should a test suite terminate abnormally, cleaning up a test
directory with "sh clean.sh <test-directory>" would leave the file present.
3. An additional step could be added to "cleanall.sh" (which calls the
system's "clean.sh" for each test) to remove the "test.output" file. However,
although the file would be deleted should all test directories be cleaned,
it would still mean that running "clean.sh" on a particular test directory
could leave the file present.
To get round this, the system's "clean.sh" script takes an optional flag, "-r"
(the "runall" flag). When the test suite is run, each invocation of "run.sh"
is passed the runall flag. In turn, "run.sh" passes the flag to "clean.sh",
which causes that script not to delete the "tests.output" file. In other
words, when the system's "clean.sh" is invoked standalone on a test directory
(or as part of a run of "cleanall.sh"), it will delete the "test.output" if it
is present. When invoked during a run of the entire test suite, it won't.
+29 -31
View File
@@ -9,34 +9,32 @@
# See the COPYRIGHT file distributed with this work for additional # See the COPYRIGHT file distributed with this work for additional
# information regarding copyright ownership. # information regarding copyright ownership.
rm -f ./dig.out.* rm -f dig.out.*
rm -f ./rndc.out* rm -f rndc.out*
rm -f ./showzone.out* rm -f showzone.out*
rm -f ./zonestatus.out* rm -f zonestatus.out*
rm -f ./*/named.conf rm -f */named.conf
rm -f ./*/named.memstats rm -f */named.memstats
rm -f ./ns1/*.nzf ./ns1/*.nzf~ rm -f ns1/*.nzf ns1/*.nzf~
rm -f ./ns1/*.nzd ./ns1/*.nzd-lock rm -f ns1/*.nzd ns1/*.nzd-lock
rm -f ./ns2/*.nzf ./ns2/*.nzf~ rm -f ns2/*.nzf ns2/*.nzf~
rm -f ./ns2/*.nzd ./ns2/*.nzd-lock rm -f ns2/*.nzd ns2/*.nzd-lock
rm -f ./ns3/*.nzf ./ns3/*.nzf~ rm -f ns3/*.nzf ns3/*.nzf~
rm -f ./ns3/*.nzd ./ns3/*.nzd-lock rm -f ns3/*.nzd ns3/*.nzd-lock
rm -f ./ns2/core* rm -f ns2/core*
rm -f ./ns2/inline.db.jbk rm -f ns2/inline.db.jbk
rm -f ./ns2/inline.db.signed rm -f ns2/inline.db.signed
rm -f ./ns2/inlineslave.bk* rm -f ns2/inlineslave.bk*
rm -rf ./ns2/new-zones rm -rf ns2/new-zones
rm -f ./ns*/named.lock rm -f ns*/named.lock
rm -f ./ns*/named.run ./ns*/named.run.prev rm -f ns*/named.run
rm -f ./ns2/nzf-* rm -f ns2/nzf-*
rm -f ./ns3/named.conf rm -f ns3/named.conf
rm -f ./ns3/*.nzf ./ns3/*.nzf~ rm -f ns3/*.nzf ns3/*.nzf~
rm -f ./ns3/*.nzd ns3/*.nzd-lock rm -f ns3/*.nzd ns3/*.nzd-lock
rm -f ./ns3/inlineslave.db rm -f ns3/inlineslave.db
rm -f ./ns1/redirect.db rm -f ns1/redirect.db
rm -f ./ns2/redirect.db rm -f ns2/redirect.db
rm -f ./ns2/redirect.bk rm -f ns2/redirect.bk
rm -f ./ns3/redirect.db rm -f ns3/redirect.db
rm -f ./ns*/managed-keys.bind* ns*/*.mkeys* rm -f ns*/managed-keys.bind* ns*/*.mkeys*
rm -f ./nzd2nzf.out.*
rm -f ./wait_for_message.*
+2
View File
@@ -12,6 +12,8 @@
SYSTEMTESTTOP=.. SYSTEMTESTTOP=..
. $SYSTEMTESTTOP/conf.sh . $SYSTEMTESTTOP/conf.sh
$SHELL clean.sh
cp -f ns1/redirect.db.1 ns1/redirect.db cp -f ns1/redirect.db.1 ns1/redirect.db
cp -f ns2/redirect.db.1 ns2/redirect.db cp -f ns2/redirect.db.1 ns2/redirect.db
cp -f ns3/redirect.db.1 ns3/redirect.db cp -f ns3/redirect.db.1 ns3/redirect.db
+140 -157
View File
@@ -15,12 +15,6 @@ SYSTEMTESTTOP=..
DIGOPTS="+tcp +nosea +nostat +nocmd +norec +noques +noauth +noadd +nostats +dnssec -p ${PORT}" DIGOPTS="+tcp +nosea +nostat +nocmd +norec +noques +noauth +noadd +nostats +dnssec -p ${PORT}"
RNDCCMD="$RNDC -c $SYSTEMTESTTOP/common/rndc.conf -p ${CONTROLPORT} -s" RNDCCMD="$RNDC -c $SYSTEMTESTTOP/common/rndc.conf -p ${CONTROLPORT} -s"
check_zonestatus() (
$RNDCCMD "10.53.0.$1" zonestatus -redirect > "zonestatus.out.ns$1.$n" &&
grep "type: redirect" "zonestatus.out.ns$1.$n" > /dev/null &&
grep "serial: 1" "zonestatus.out.ns$1.$n" > /dev/null
)
status=0 status=0
n=0 n=0
@@ -55,30 +49,25 @@ fi
echo_i "adding new zone ($n)" echo_i "adding new zone ($n)"
ret=0 ret=0
$RNDCCMD 10.53.0.2 addzone 'added.example { type master; file "added.db"; };' 2>&1 | sed 's/^/I:ns2 /' $RNDCCMD 10.53.0.2 addzone 'added.example { type master; file "added.db"; };' 2>&1 | sed 's/^/I:ns2 /'
_check_adding_new_zone () ( $DIG $DIGOPTS @10.53.0.2 a.added.example a > dig.out.ns2.$n || ret=1
$DIG $DIGOPTS @10.53.0.2 a.added.example a > dig.out.ns2.$n && grep 'status: NOERROR' dig.out.ns2.$n > /dev/null || ret=1
grep 'status: NOERROR' dig.out.ns2.$n > /dev/null && grep '^a.added.example' dig.out.ns2.$n > /dev/null || ret=1
grep '^a.added.example' dig.out.ns2.$n > /dev/null
)
retry_quiet 10 _check_adding_new_zone || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
nextpart ns2/named.run >/dev/null
echo_i "checking addzone errors are logged correctly" echo_i "checking addzone errors are logged correctly"
ret=0 ret=0
$RNDCCMD 10.53.0.2 addzone bad.example '{ type mister; };' 2>&1 | grep 'unexpected token' > /dev/null 2>&1 || ret=1 $RNDCCMD 10.53.0.2 addzone bad.example '{ type mister; };' 2>&1 | grep 'unexpected token' > /dev/null 2>&1 || ret=1
wait_for_log_peek 20 "addzone: 'mister' unexpected" ns2/named.run || ret=1 grep "addzone: 'mister' unexpected" ns2/named.run >/dev/null 2>&1 || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
nextpart ns2/named.run >/dev/null
echo_i "checking modzone errors are logged correctly" echo_i "checking modzone errors are logged correctly"
ret=0 ret=0
$RNDCCMD 10.53.0.2 modzone added.example '{ type mister; };' 2>&1 | grep 'unexpected token' > /dev/null 2>&1 || ret=1 $RNDCCMD 10.53.0.2 modzone added.example '{ type mister; };' 2>&1 | grep 'unexpected token' > /dev/null 2>&1 || ret=1
wait_for_log_peek 20 "modzone: 'mister' unexpected" ns2/named.run || ret=1 grep "modzone: 'mister' unexpected" ns2/named.run >/dev/null 2>&1 || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -86,12 +75,9 @@ status=`expr $status + $ret`
echo_i "adding a zone that requires quotes ($n)" echo_i "adding a zone that requires quotes ($n)"
ret=0 ret=0
$RNDCCMD 10.53.0.2 addzone '"32/1.0.0.127-in-addr.added.example" { check-names ignore; type master; file "added.db"; };' 2>&1 | sed 's/^/I:ns2 /' $RNDCCMD 10.53.0.2 addzone '"32/1.0.0.127-in-addr.added.example" { check-names ignore; type master; file "added.db"; };' 2>&1 | sed 's/^/I:ns2 /'
_check_zone_that_requires_quotes() ( $DIG $DIGOPTS @10.53.0.2 "a.32/1.0.0.127-in-addr.added.example" a > dig.out.ns2.$n || ret=1
$DIG $DIGOPTS @10.53.0.2 "a.32/1.0.0.127-in-addr.added.example" a > dig.out.ns2.$n && grep 'status: NOERROR' dig.out.ns2.$n > /dev/null || ret=1
grep 'status: NOERROR' dig.out.ns2.$n > /dev/null && grep '^a.32/1.0.0.127-in-addr.added.example' dig.out.ns2.$n > /dev/null || ret=1
grep '^a.32/1.0.0.127-in-addr.added.example' dig.out.ns2.$n > /dev/null
)
retry_quiet 10 _check_zone_that_requires_quotes || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -99,12 +85,9 @@ status=`expr $status + $ret`
echo_i "adding a zone with a quote in the name ($n)" echo_i "adding a zone with a quote in the name ($n)"
ret=0 ret=0
$RNDCCMD 10.53.0.2 addzone '"foo\"bar.example" { check-names ignore; type master; file "added.db"; };' 2>&1 | sed 's/^/I:ns2 /' $RNDCCMD 10.53.0.2 addzone '"foo\"bar.example" { check-names ignore; type master; file "added.db"; };' 2>&1 | sed 's/^/I:ns2 /'
_check_zone_with_a_quote() ( $DIG $DIGOPTS @10.53.0.2 "a.foo\"bar.example" a > dig.out.ns2.$n || ret=1
$DIG $DIGOPTS @10.53.0.2 "a.foo\"bar.example" a > dig.out.ns2.$n && grep 'status: NOERROR' dig.out.ns2.$n > /dev/null || ret=1
grep 'status: NOERROR' dig.out.ns2.$n > /dev/null && grep '^a.foo\\"bar.example' dig.out.ns2.$n > /dev/null || ret=1
grep '^a.foo\\"bar.example' dig.out.ns2.$n > /dev/null
)
retry_quiet 10 _check_zone_with_a_quote || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -152,24 +135,21 @@ fi
echo_i "deleting previously added zone ($n)" echo_i "deleting previously added zone ($n)"
ret=0 ret=0
$RNDCCMD 10.53.0.2 delzone previous.example 2>&1 | sed 's/^/I:ns2 /' $RNDCCMD 10.53.0.2 delzone previous.example 2>&1 | sed 's/^/I:ns2 /'
_check_deleting_previously_added_zone() ( $DIG $DIGOPTS @10.53.0.2 a.previous.example a > dig.out.ns2.$n
$DIG $DIGOPTS @10.53.0.2 a.previous.example a > dig.out.ns2.$n && grep 'status: REFUSED' dig.out.ns2.$n > /dev/null || ret=1
grep 'status: REFUSED' dig.out.ns2.$n > /dev/null && grep '^a.previous.example' dig.out.ns2.$n > /dev/null && ret=1
! grep '^a.previous.example' dig.out.ns2.$n > /dev/null
)
retry_quiet 10 _check_deleting_previously_added_zone || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
check_nzd2nzf() (
$NZD2NZF ns2/_default.nzd > nzd2nzf.out.$n &&
! grep previous.example nzd2nzf.out.$n > /dev/null
)
if [ -n "$NZD" ]; then if [ -n "$NZD" ]; then
echo_i "checking zone was deleted from NZD ($n)" echo_i "checking zone was deleted from NZD ($n)"
retry_quiet 10 check_nzd2nzf || ret=1 for i in 0 1 2 3 4 5 6 7 8 9; do
ret=0
$NZD2NZF ns2/_default.nzd | grep previous.example > /dev/null && ret=1
[ $ret = 0 ] && break
sleep 1
done
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
fi fi
@@ -187,12 +167,9 @@ fi
echo_i "deleting newly added zone added.example ($n)" echo_i "deleting newly added zone added.example ($n)"
ret=0 ret=0
$RNDCCMD 10.53.0.2 delzone added.example 2>&1 | sed 's/^/I:ns2 /' $RNDCCMD 10.53.0.2 delzone added.example 2>&1 | sed 's/^/I:ns2 /'
_check_deleting_newly_added_zone() ( $DIG $DIGOPTS @10.53.0.2 a.added.example a > dig.out.ns2.$n
$DIG $DIGOPTS @10.53.0.2 a.added.example a > dig.out.ns2.$n && grep 'status: REFUSED' dig.out.ns2.$n > /dev/null || ret=1
grep 'status: REFUSED' dig.out.ns2.$n > /dev/null && grep '^a.added.example' dig.out.ns2.$n > /dev/null && ret=1
! grep '^a.added.example' dig.out.ns2.$n > /dev/null
)
retry_quiet 10 _check_deleting_newly_added_zone || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -200,12 +177,9 @@ status=`expr $status + $ret`
echo_i "deleting newly added zone with escaped quote ($n)" echo_i "deleting newly added zone with escaped quote ($n)"
ret=0 ret=0
$RNDCCMD 10.53.0.2 delzone "foo\\\"bar.example" 2>&1 | sed 's/^/I:ns2 /' $RNDCCMD 10.53.0.2 delzone "foo\\\"bar.example" 2>&1 | sed 's/^/I:ns2 /'
_check_deleting_newly_added_zone_quote() ( $DIG $DIGOPTS @10.53.0.2 "a.foo\"bar.example" a > dig.out.ns2.$n
$DIG $DIGOPTS @10.53.0.2 "a.foo\"bar.example" a > dig.out.ns2.$n && grep 'status: REFUSED' dig.out.ns2.$n > /dev/null || ret=1
grep 'status: REFUSED' dig.out.ns2.$n > /dev/null && grep "^a.foo\"bar.example" dig.out.ns2.$n > /dev/null && ret=1
! grep "^a.foo\"bar.example" dig.out.ns2.$n > /dev/null
)
retry_quiet 10 _check_deleting_newly_added_zone_quote || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -251,7 +225,9 @@ ret=0
sleep 1 sleep 1
cp -f ns1/redirect.db.2 ns1/redirect.db cp -f ns1/redirect.db.2 ns1/redirect.db
$RNDCCMD 10.53.0.1 reload -redirect > rndc.out.ns1.$n $RNDCCMD 10.53.0.1 reload -redirect > rndc.out.ns1.$n
retry_quiet 5 check_zonestatus 1 || ret=1 $RNDCCMD 10.53.0.1 zonestatus -redirect > zonestatus.out.ns1.$n
grep "type: redirect" zonestatus.out.ns1.$n > /dev/null || ret=1
grep "serial: 1" zonestatus.out.ns1.$n > /dev/null || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -259,27 +235,27 @@ status=`expr $status + $ret`
echo_i "delete a normally-loaded zone ($n)" echo_i "delete a normally-loaded zone ($n)"
ret=0 ret=0
$RNDCCMD 10.53.0.2 delzone normal.example > rndc.out.ns2.$n 2>&1 $RNDCCMD 10.53.0.2 delzone normal.example > rndc.out.ns2.$n 2>&1
grep "is no longer active and will be deleted" rndc.out.ns2.$n > /dev/null || ret=11 $DIG $DIGOPTS @10.53.0.2 a.normal.example a > dig.out.ns2.$n
grep "is no longer active and will be deleted" rndc.out.ns2.$n > /dev/null || ret=1
grep "To keep it from returning when the server is restarted" rndc.out.ns2.$n > /dev/null || ret=1 grep "To keep it from returning when the server is restarted" rndc.out.ns2.$n > /dev/null || ret=1
grep "must also be removed from named.conf." rndc.out.ns2.$n > /dev/null || ret=1 grep "must also be removed from named.conf." rndc.out.ns2.$n > /dev/null || ret=1
_check_delete_normally_loaded_zone() (
$DIG $DIGOPTS @10.53.0.2 a.normal.example a > dig.out.ns2.$n &&
grep 'status: REFUSED' dig.out.ns2.$n > /dev/null
)
retry_quiet 5 _check_delete_normally_loaded_zone || ret=1
grep 'status: REFUSED' dig.out.ns2.$n > /dev/null || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
echo_i "attempting to add master zone with inline signing ($n)" echo_i "attempting to add master zone with inline signing ($n)"
$RNDCCMD 10.53.0.2 addzone 'inline.example { type master; file "inline.db"; inline-signing yes; };' 2>&1 | sed 's/^/I:ns2 /' $RNDCCMD 10.53.0.2 addzone 'inline.example { type master; file "inline.db"; inline-signing yes; };' 2>&1 | sed 's/^/I:ns2 /'
_check_add_master_zone_with_inline() ( for i in 1 2 3 4 5
$DIG $DIGOPTS @10.53.0.2 a.inline.example a > dig.out.ns2.$n && do
grep 'status: NOERROR' dig.out.ns2.$n > /dev/null && ret=0
grep '^a.inline.example' dig.out.ns2.$n > /dev/null $DIG $DIGOPTS @10.53.0.2 a.inline.example a > dig.out.ns2.$n || ret=1
) grep 'status: NOERROR' dig.out.ns2.$n > /dev/null || ret=1
retry_quiet 5 _check_add_master_zone_with_inline || ret=1 grep '^a.inline.example' dig.out.ns2.$n > /dev/null || ret=1
[ $ret = 0 ] && break
sleep 1
done
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -294,20 +270,27 @@ status=`expr $status + $ret`
echo_i "attempting to add slave zone with inline signing ($n)" echo_i "attempting to add slave zone with inline signing ($n)"
$RNDCCMD 10.53.0.2 addzone 'inlineslave.example { type slave; masters { 10.53.0.1; }; file "inlineslave.bk"; inline-signing yes; };' 2>&1 | sed 's/^/I:ns2 /' $RNDCCMD 10.53.0.2 addzone 'inlineslave.example { type slave; masters { 10.53.0.1; }; file "inlineslave.bk"; inline-signing yes; };' 2>&1 | sed 's/^/I:ns2 /'
_check_add_slave_with_inline() ( for i in 1 2 3 4 5
$DIG $DIGOPTS @10.53.0.2 a.inlineslave.example a > dig.out.ns2.$n && do
grep 'status: NOERROR' dig.out.ns2.$n > /dev/null && ret=0
grep '^a.inlineslave.example' dig.out.ns2.$n > /dev/null $DIG $DIGOPTS @10.53.0.2 a.inlineslave.example a > dig.out.ns2.$n || ret=1
) grep 'status: NOERROR' dig.out.ns2.$n > /dev/null || ret=1
retry_quiet 5 _check_add_slave_with_inline || ret=1 grep '^a.inlineslave.example' dig.out.ns2.$n > /dev/null || ret=1
[ $ret = 0 ] && break
sleep 1
done
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
echo_i "attempting to delete slave zone with inline signing ($n)" echo_i "attempting to delete slave zone with inline signing ($n)"
ret=0 ret=0
retry_quiet 10 test -f ns2/inlineslave.bk.signed -a -f ns2/inlineslave.bk || ret=1 for i in 0 1 2 3 4 5 6 7 8 9
$RNDCCMD 10.53.0.2 delzone inlineslave.example > rndc.out2.test$n 2>&1 || ret=1 do
test -f ns2/inlineslave.bk.signed -a -f ns2/inlineslave.bk && break
sleep 1
done
$RNDCCMD 10.53.0.2 delzone inlineslave.example 2>&1 > rndc.out2.test$n
test -f inlineslave.bk || test -f inlineslave.bk ||
grep '^inlineslave.bk$' rndc.out2.test$n > /dev/null || { grep '^inlineslave.bk$' rndc.out2.test$n > /dev/null || {
echo_i "failed to report inlineslave.bk"; ret=1; echo_i "failed to report inlineslave.bk"; ret=1;
@@ -321,30 +304,43 @@ status=`expr $status + $ret`
echo_i "restoring slave zone with inline signing ($n)" echo_i "restoring slave zone with inline signing ($n)"
$RNDCCMD 10.53.0.2 addzone 'inlineslave.example { type slave; masters { 10.53.0.1; }; file "inlineslave.bk"; inline-signing yes; };' 2>&1 | sed 's/^/I:ns2 /' $RNDCCMD 10.53.0.2 addzone 'inlineslave.example { type slave; masters { 10.53.0.1; }; file "inlineslave.bk"; inline-signing yes; };' 2>&1 | sed 's/^/I:ns2 /'
_check_restoring_slave_with_inline() ( for i in 1 2 3 4 5
$DIG $DIGOPTS @10.53.0.2 a.inlineslave.example a > dig.out.ns2.$n && do
grep 'status: NOERROR' dig.out.ns2.$n > /dev/null && ret=0
grep '^a.inlineslave.example' dig.out.ns2.$n > /dev/null $DIG $DIGOPTS @10.53.0.2 a.inlineslave.example a > dig.out.ns2.$n || ret=1
) grep 'status: NOERROR' dig.out.ns2.$n > /dev/null || ret=1
retry_quiet 5 _check_restoring_slave_with_inline || ret=1 grep '^a.inlineslave.example' dig.out.ns2.$n > /dev/null || ret=1
[ $ret = 0 ] && break
sleep 1
done
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
echo_i "deleting slave zone with automatic zone file removal ($n)" echo_i "deleting slave zone with automatic zone file removal ($n)"
ret=0 ret=0
retry_quiet 10 test -f ns2/inlineslave.bk.signed -a -f ns2/inlineslave.bk || ret=1 for i in 0 1 2 3 4 5 6 7 8 9
$RNDCCMD 10.53.0.2 delzone -clean inlineslave.example > /dev/null 2>&1 do
retry_quiet 10 test ! -f ns2/inlineslave.bk.signed -a ! -f ns2/inlineslave.bk test -f ns2/inlineslave.bk.signed -a -f ns2/inlineslave.bk && break
sleep 1
done
$RNDCCMD 10.53.0.2 delzone -clean inlineslave.example 2>&1 > /dev/null
for i in 0 1 2 3 4 5 6 7 8 9
do
ret=0
test -f ns2/inlineslave.bk.signed -a -f ns2/inlineslave.bk && ret=1
[ $ret = 0 ] && break
sleep 1
done
n=`expr $n + 1` n=`expr $n + 1`
status=`expr $status + $ret` status=`expr $status + $ret`
echo_i "modifying zone configuration ($n)" echo_i "modifying zone configuration ($n)"
ret=0 ret=0
$RNDCCMD 10.53.0.2 addzone 'mod.example { type master; file "added.db"; };' 2>&1 | sed 's/^/ns2 /' | cat_i $RNDCCMD 10.53.0.2 addzone 'mod.example { type master; file "added.db"; };' 2>&1 | sed 's/^/I:ns2 /'
$DIG +norec $DIGOPTS @10.53.0.2 mod.example ns > dig.out.ns2.1.$n || ret=1 $DIG +norec $DIGOPTS @10.53.0.2 mod.example ns > dig.out.ns2.1.$n || ret=1
grep 'status: NOERROR' dig.out.ns2.1.$n > /dev/null || ret=1 grep 'status: NOERROR' dig.out.ns2.1.$n > /dev/null || ret=1
$RNDCCMD 10.53.0.2 modzone 'mod.example { type master; file "added.db"; allow-query { none; }; };' 2>&1 | sed 's/^/ns2 /' | cat_i $RNDCCMD 10.53.0.2 modzone 'mod.example { type master; file "added.db"; allow-query { none; }; };' 2>&1 | sed 's/^/I:ns2 /'
$DIG +norec $DIGOPTS @10.53.0.2 mod.example ns > dig.out.ns2.2.$n || ret=1 $DIG +norec $DIGOPTS @10.53.0.2 mod.example ns > dig.out.ns2.2.$n || ret=1
$RNDCCMD 10.53.0.2 showzone mod.example | grep 'allow-query { "none"; };' > /dev/null 2>&1 || ret=1 $RNDCCMD 10.53.0.2 showzone mod.example | grep 'allow-query { "none"; };' > /dev/null 2>&1 || ret=1
n=`expr $n + 1` n=`expr $n + 1`
@@ -368,14 +364,11 @@ status=`expr $status + $ret`
echo_i "check that adding a 'master redirect' zone works ($n)" echo_i "check that adding a 'master redirect' zone works ($n)"
ret=0 ret=0
$RNDCCMD 10.53.0.2 addzone '"." { type redirect; file "redirect.db"; };' > rndc.out.ns2.$n 2>&1 || ret=1 $RNDCCMD 10.53.0.2 addzone '"." { type redirect; file "redirect.db"; };' > rndc.out.ns2.$n 2>&1 || ret=1
_check_add_master_redirect() ( $RNDCCMD 10.53.0.2 showzone -redirect > showzone.out.ns2.$n 2>&1 || ret=1
$RNDCCMD 10.53.0.2 showzone -redirect > showzone.out.ns2.$n 2>&1 && grep "type redirect;" showzone.out.ns2.$n > /dev/null || ret=1
grep "type redirect;" showzone.out.ns2.$n > /dev/null && $RNDCCMD 10.53.0.2 zonestatus -redirect > zonestatus.out.ns2.$n 2>&1 || ret=1
$RNDCCMD 10.53.0.2 zonestatus -redirect > zonestatus.out.ns2.$n 2>&1 && grep "type: redirect" zonestatus.out.ns2.$n > /dev/null || ret=1
grep "type: redirect" zonestatus.out.ns2.$n > /dev/null && grep "serial: 0" zonestatus.out.ns2.$n > /dev/null || ret=1
grep "serial: 0" zonestatus.out.ns2.$n > /dev/null
)
retry_quiet 10 _check_add_master_redirect || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -385,7 +378,9 @@ ret=0
sleep 1 sleep 1
cp -f ns2/redirect.db.2 ns2/redirect.db cp -f ns2/redirect.db.2 ns2/redirect.db
$RNDCCMD 10.53.0.2 reload -redirect > rndc.out.ns2.$n $RNDCCMD 10.53.0.2 reload -redirect > rndc.out.ns2.$n
retry_quiet 10 check_zonestatus 2 || ret=1 $RNDCCMD 10.53.0.2 zonestatus -redirect > zonestatus.out.ns2.$n 2>&1 || ret=1
grep "type: redirect" zonestatus.out.ns2.$n > /dev/null || ret=1
grep "serial: 1" zonestatus.out.ns2.$n > /dev/null || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -400,11 +395,8 @@ status=`expr $status + $ret`
echo_i "check that deleting a 'master redirect' zone works ($n)" echo_i "check that deleting a 'master redirect' zone works ($n)"
ret=0 ret=0
$RNDCCMD 10.53.0.2 delzone -redirect > rndc.out.ns2.$n 2>&1 || ret=1 $RNDCCMD 10.53.0.2 delzone -redirect > rndc.out.ns2.$n 2>&1 || ret=1
_check_deleting_master_redirect() ( $RNDCCMD 10.53.0.2 showzone -redirect > showzone.out.ns2.$n 2>&1
$RNDCCMD 10.53.0.2 showzone -redirect > showzone.out.ns2.$n 2>&1 || true grep 'not found' showzone.out.ns2.$n > /dev/null || ret=1
grep 'not found' showzone.out.ns2.$n > /dev/null
)
retry_quiet 10 _check_deleting_master_redirect || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -412,14 +404,12 @@ status=`expr $status + $ret`
echo_i "check that adding a 'slave redirect' zone works ($n)" echo_i "check that adding a 'slave redirect' zone works ($n)"
ret=0 ret=0
$RNDCCMD 10.53.0.2 addzone '"." { type redirect; masters { 10.53.0.3;}; file "redirect.bk"; };' > rndc.out.ns2.$n 2>&1 || ret=1 $RNDCCMD 10.53.0.2 addzone '"." { type redirect; masters { 10.53.0.3;}; file "redirect.bk"; };' > rndc.out.ns2.$n 2>&1 || ret=1
_check_adding_slave_redirect() ( $RNDCCMD 10.53.0.2 showzone -redirect > showzone.out.ns2.$n 2>&1 || ret=1
$RNDCCMD 10.53.0.2 showzone -redirect > showzone.out.ns2.$n 2>&1 && grep "type redirect;" showzone.out.ns2.$n > /dev/null || ret=1
grep "type redirect;" showzone.out.ns2.$n > /dev/null && sleep 1
$RNDCCMD 10.53.0.2 zonestatus -redirect > zonestatus.out.ns2.$n 2>&1 && $RNDCCMD 10.53.0.2 zonestatus -redirect > zonestatus.out.ns2.$n 2>&1 || ret=1
grep "type: redirect" zonestatus.out.ns2.$n > /dev/null && grep "type: redirect" zonestatus.out.ns2.$n > /dev/null || ret=1
grep "serial: 0" zonestatus.out.ns2.$n > /dev/null grep "serial: 0" zonestatus.out.ns2.$n > /dev/null || ret=1
)
retry_quiet 10 _check_adding_slave_redirect || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -428,13 +418,12 @@ echo_i "check that retransfering a added 'slave redirect' zone works ($n)"
ret=0 ret=0
cp -f ns3/redirect.db.2 ns3/redirect.db cp -f ns3/redirect.db.2 ns3/redirect.db
$RNDCCMD 10.53.0.3 reload . > showzone.out.ns3.$n 2>&1 || ret=1 $RNDCCMD 10.53.0.3 reload . > showzone.out.ns3.$n 2>&1 || ret=1
_check_retransfering_slave_redirect() ( sleep 1
$RNDCCMD 10.53.0.2 retransfer -redirect > rndc.out.ns2.$n 2>&1 && $RNDCCMD 10.53.0.2 retransfer -redirect > rndc.out.ns2.$n 2>&1 || ret=1
$RNDCCMD 10.53.0.2 zonestatus -redirect > zonestatus.out.ns2.$n 2>&1 && sleep 1
grep "type: redirect" zonestatus.out.ns2.$n > /dev/null && $RNDCCMD 10.53.0.2 zonestatus -redirect > zonestatus.out.ns2.$n 2>&1 || ret=1
grep "serial: 1" zonestatus.out.ns2.$n > /dev/null grep "type: redirect" zonestatus.out.ns2.$n > /dev/null || ret=1
) grep "serial: 1" zonestatus.out.ns2.$n > /dev/null || ret=1
retry_quiet 10 _check_retransfering_slave_redirect || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -442,11 +431,8 @@ status=`expr $status + $ret`
echo_i "check that deleting a 'slave redirect' zone works ($n)" echo_i "check that deleting a 'slave redirect' zone works ($n)"
ret=0 ret=0
$RNDCCMD 10.53.0.2 delzone -redirect > rndc.out.ns2.$n 2>&1 || ret=1 $RNDCCMD 10.53.0.2 delzone -redirect > rndc.out.ns2.$n 2>&1 || ret=1
_check_deleting_slave_redirect() ( $RNDCCMD 10.53.0.2 showzone -redirect > showzone.out.ns2.$n 2>&1
$RNDCCMD 10.53.0.2 showzone -redirect > showzone.out.ns2.$n 2>&1 || true grep 'not found' showzone.out.ns2.$n > /dev/null || ret=1
grep 'not found' showzone.out.ns2.$n > /dev/null
)
retry_quiet 10 _check_deleting_slave_redirect || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -531,30 +517,31 @@ fi
echo_i "checking rndc reload causes named to reload the external view's new zone config ($n)" echo_i "checking rndc reload causes named to reload the external view's new zone config ($n)"
ret=0 ret=0
$RNDCCMD 10.53.0.2 reload 2>&1 | sed 's/^/ns2 /' | cat_i $RNDCCMD 10.53.0.2 reload 2>&1 | sed 's/^/I:ns2 /'
_check_rndc_reload_external_view_config() ( $DIG +norec $DIGOPTS @10.53.0.2 -b 10.53.0.2 a.added.example a > dig.out.ns2.int.$n || ret=1
$DIG +norec $DIGOPTS @10.53.0.2 -b 10.53.0.2 a.added.example a > dig.out.ns2.int.$n && grep 'status: NOERROR' dig.out.ns2.int.$n > /dev/null || ret=1
grep 'status: NOERROR' dig.out.ns2.int.$n > /dev/null && $DIG +norec $DIGOPTS @10.53.0.4 -b 10.53.0.4 a.added.example a > dig.out.ns2.ext.$n || ret=1
$DIG +norec $DIGOPTS @10.53.0.4 -b 10.53.0.4 a.added.example a > dig.out.ns2.ext.$n && grep 'status: NOERROR' dig.out.ns2.ext.$n > /dev/null || ret=1
grep 'status: NOERROR' dig.out.ns2.ext.$n > /dev/null && grep '^a.added.example' dig.out.ns2.ext.$n > /dev/null || ret=1
grep '^a.added.example' dig.out.ns2.ext.$n > /dev/null
)
retry_quiet 10 _check_rndc_reload_external_view_config || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
echo_i "checking rndc showzone with newly added zone ($n)" echo_i "checking rndc showzone with newly added zone ($n)"
_check_rndc_showzone_newly_added() ( # loop because showzone may complain if zones are still being
if [ -z "$NZD" ]; then # loaded from the NZDB at this point.
expected='zone "added.example" in external { type master; file "added.db"; };' for try in 0 1 2 3 4 5; do
else ret=0
expected='zone "added.example" { type master; file "added.db"; };' $RNDCCMD 10.53.0.2 showzone added.example in external > rndc.out.ns2.$n 2>/dev/null
fi if [ -z "$NZD" ]; then
$RNDCCMD 10.53.0.2 showzone added.example in external > rndc.out.ns2.$n 2>/dev/null && expected='zone "added.example" in external { type master; file "added.db"; };'
[ "`cat rndc.out.ns2.$n`" = "$expected" ] else
) expected='zone "added.example" { type master; file "added.db"; };'
retry_quiet 10 _check_rndc_showzone_newly_added || ret=1 fi
[ "`cat rndc.out.ns2.$n`" = "$expected" ] || ret=1
[ $ret -eq 0 ] && break
sleep 1
done
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -562,12 +549,9 @@ status=`expr $status + $ret`
echo_i "deleting newly added zone ($n)" echo_i "deleting newly added zone ($n)"
ret=0 ret=0
$RNDCCMD 10.53.0.2 delzone 'added.example in external' 2>&1 | sed 's/^/I:ns2 /' $RNDCCMD 10.53.0.2 delzone 'added.example in external' 2>&1 | sed 's/^/I:ns2 /'
_check_deleting_newly_added_zone() ( $DIG $DIGOPTS @10.53.0.4 -b 10.53.0.4 a.added.example a > dig.out.ns2.$n || ret=1
$DIG $DIGOPTS @10.53.0.4 -b 10.53.0.4 a.added.example a > dig.out.ns2.$n && grep 'status: REFUSED' dig.out.ns2.$n > /dev/null || ret=1
grep 'status: REFUSED' dig.out.ns2.$n > /dev/null && grep '^a.added.example' dig.out.ns2.$n > /dev/null && ret=1
! grep '^a.added.example' dig.out.ns2.$n > /dev/null
)
retry_quiet 10 _check_deleting_newly_added_zone || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -597,14 +581,11 @@ status=`expr $status + $ret`
echo_i "adding new zone again to external view ($n)" echo_i "adding new zone again to external view ($n)"
ret=0 ret=0
$RNDCCMD 10.53.0.2 addzone 'added.example in external { type master; file "added.db"; };' 2>&1 | sed 's/^/I:ns2 /' $RNDCCMD 10.53.0.2 addzone 'added.example in external { type master; file "added.db"; };' 2>&1 | sed 's/^/I:ns2 /'
_check_adding_new_zone_again_external() ( $DIG +norec $DIGOPTS @10.53.0.2 -b 10.53.0.2 a.added.example a > dig.out.ns2.int.$n || ret=1
$DIG +norec $DIGOPTS @10.53.0.2 -b 10.53.0.2 a.added.example a > dig.out.ns2.int.$n && grep 'status: NOERROR' dig.out.ns2.int.$n > /dev/null || ret=1
grep 'status: NOERROR' dig.out.ns2.int.$n > /dev/null && $DIG +norec $DIGOPTS @10.53.0.4 -b 10.53.0.4 a.added.example a > dig.out.ns2.ext.$n || ret=1
$DIG +norec $DIGOPTS @10.53.0.4 -b 10.53.0.4 a.added.example a > dig.out.ns2.ext.$n && grep 'status: NOERROR' dig.out.ns2.ext.$n > /dev/null || ret=1
grep 'status: NOERROR' dig.out.ns2.ext.$n > /dev/null && grep '^a.added.example' dig.out.ns2.ext.$n > /dev/null || ret=1
grep '^a.added.example' dig.out.ns2.ext.$n > /dev/null
)
retry_quiet 10 _check_adding_new_zone_again_external || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -709,18 +690,20 @@ then
status=`expr $status + $ret` status=`expr $status + $ret`
fi fi
_check_version_bind() (
$DIG $DIGOPTS @10.53.0.3 version.bind txt ch > dig.out.test$n &&
grep "status: NOERROR" dig.out.test$n > /dev/null
)
echo_i "check that named restarts with multiple added zones ($n)" echo_i "check that named restarts with multiple added zones ($n)"
ret=0 ret=0
$RNDCCMD 10.53.0.3 addzone "test4.baz" '{ type master; file "e.db"; };' > /dev/null 2>&1 || ret=1 $RNDCCMD 10.53.0.3 addzone "test4.baz" '{ type master; file "e.db"; };' > /dev/null 2>&1 || ret=1
$RNDCCMD 10.53.0.3 addzone "test5.baz" '{ type master; file "e.db"; };' > /dev/null 2>&1 || ret=1 $RNDCCMD 10.53.0.3 addzone "test5.baz" '{ type master; file "e.db"; };' > /dev/null 2>&1 || ret=1
$PERL $SYSTEMTESTTOP/stop.pl addzone ns3 $PERL $SYSTEMTESTTOP/stop.pl addzone ns3
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart --port ${PORT} addzone ns3 || ret=1 $PERL $SYSTEMTESTTOP/start.pl --noclean --restart --port ${PORT} addzone ns3 || ret=1
retry_quiet 10 _check_version_bind || ret=1 for try in 0 1 2 3 4 5 6 7 8 9; do
iret=0
$DIG $DIGOPTS @10.53.0.3 version.bind txt ch > dig.out.test$n || iret=1
grep "status: NOERROR" dig.out.test$n > /dev/null || iret=1
[ "$iret" -eq 0 ] && break
sleep 1
done
[ "$iret" -ne 0 ] && ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
n=`expr $n + 1` n=`expr $n + 1`
+2
View File
@@ -12,6 +12,8 @@
SYSTEMTESTTOP=.. SYSTEMTESTTOP=..
. $SYSTEMTESTTOP/conf.sh . $SYSTEMTESTTOP/conf.sh
$SHELL clean.sh
copy_setports ../common/controls.conf.in ns2/controls.conf copy_setports ../common/controls.conf.in ns2/controls.conf
copy_setports ns1/named.conf.in ns1/named.conf copy_setports ns1/named.conf.in ns1/named.conf
copy_setports ns2/named01.conf.in ns2/named.conf copy_setports ns2/named01.conf.in ns2/named.conf
+1
View File
@@ -12,5 +12,6 @@
SYSTEMTESTTOP=.. SYSTEMTESTTOP=..
. $SYSTEMTESTTOP/conf.sh . $SYSTEMTESTTOP/conf.sh
$SHELL clean.sh
copy_setports ns1/named.conf.in ns1/named.conf copy_setports ns1/named.conf.in ns1/named.conf
copy_setports ns2/named.conf.in ns2/named.conf copy_setports ns2/named.conf.in ns2/named.conf
+1 -2
View File
@@ -14,7 +14,7 @@ rm -f */core
rm -f */example.bk rm -f */example.bk
rm -f */named.conf rm -f */named.conf
rm -f */named.memstats rm -f */named.memstats
rm -f */named.run* rm -f */named.run
rm -f */trusted.conf */private.conf rm -f */trusted.conf */private.conf
rm -f activate-now-publish-1day.key rm -f activate-now-publish-1day.key
rm -f active.key inact.key del.key delzsk.key unpub.key standby.key rev.key rm -f active.key inact.key del.key delzsk.key unpub.key standby.key rev.key
@@ -63,7 +63,6 @@ rm -f ns3/secure.nsec3.example.db
rm -f ns3/secure.optout.example.db rm -f ns3/secure.optout.example.db
rm -f ns3/sync.example.db rm -f ns3/sync.example.db
rm -f ns3/ttl*.db rm -f ns3/ttl*.db
rm -f ns3/settime.out.*
rm -f nsupdate.out rm -f nsupdate.out
rm -f settime.out.* rm -f settime.out.*
rm -f signing.out.* rm -f signing.out.*
@@ -101,8 +101,6 @@ zone "jitter.nsec3.example" {
allow-update { any; }; allow-update { any; };
auto-dnssec maintain; auto-dnssec maintain;
sig-validity-interval 10 2; sig-validity-interval 10 2;
sig-signing-nodes 1000;
sig-signing-signatures 100;
}; };
zone "secure.nsec3.example" { zone "secure.nsec3.example" {
@@ -189,8 +187,6 @@ zone "oldsigs.example" {
allow-update { any; }; allow-update { any; };
auto-dnssec maintain; auto-dnssec maintain;
sig-validity-interval 10 2; sig-validity-interval 10 2;
sig-signing-nodes 1000;
sig-signing-signatures 100;
}; };
zone "prepub.example" { zone "prepub.example" {
+2
View File
@@ -12,6 +12,8 @@
SYSTEMTESTTOP=.. SYSTEMTESTTOP=..
. $SYSTEMTESTTOP/conf.sh . $SYSTEMTESTTOP/conf.sh
$SHELL clean.sh
copy_setports ns1/named.conf.in ns1/named.conf copy_setports ns1/named.conf.in ns1/named.conf
copy_setports ns2/named.conf.in ns2/named.conf copy_setports ns2/named.conf.in ns2/named.conf
copy_setports ns3/named.conf.in ns3/named.conf copy_setports ns3/named.conf.in ns3/named.conf
+86 -108
View File
@@ -50,13 +50,6 @@ checkprivate () {
return 1 return 1
} }
# wait until notifies for zone $1 are sent by server $2. This is an indication
# that the zone is signed with the active keys, and the changes have been
# committed.
wait_for_notifies () {
wait_for_log 10 "zone ${1}/IN: sending notifies" "${2}/named.run" || return 1
}
freq() { freq() {
_file=$1 _file=$1
# remove first and last line that has incomplete set and skews the distribution # remove first and last line that has incomplete set and skews the distribution
@@ -79,16 +72,12 @@ checkjitter () {
_expiretimes=$(freq "$_file" | awk '{print $1}') _expiretimes=$(freq "$_file" | awk '{print $1}')
_count=0 _count=0
# Check if we have at least 5 days # Check if we have at least 8 days
# This number has been tuned for `sig-validity-interval 10 2`, as
# 1. 1. signature expiration dates should be spread out across at most 8 (10-2) days
# 2. we remove first and last day to remove frequency outlier, we are left with 6 (8-2) days
# 3. we substract one more day to allow test pass on day boundaries, etc. leaving us with 5 (6-1) days
for _num in $_expiretimes for _num in $_expiretimes
do do
_count=$((_count+1)) _count=$((_count+1))
done done
if [ "$_count" -lt 5 ]; then if [ "$_count" -lt 8 ]; then
echo_i "error: not enough categories" echo_i "error: not enough categories"
return 1 return 1
fi fi
@@ -114,15 +103,11 @@ checkjitter () {
_low=$((_mean-_limit)) _low=$((_mean-_limit))
_high=$((_mean+_limit)) _high=$((_mean+_limit))
# Find outliers. # Find outliers.
echo_i "checking whether all frequencies fall into <$_low;$_high> range" echo_i "checking whether all frequencies falls into <$_low;$_high> interval"
for _num in $_expiretimes for _num in $_expiretimes
do do
if [ $_num -gt $_high ]; then if [ $_num -gt $_high ] || [ $_num -lt $_low ]; then
echo_i "error: too many RRSIG records ($_num) in expiration bucket" echo_i "error: too many RRSIG records ($_num) with the same expiration time"
_ret=1
fi
if [ $_num -lt $_low ]; then
echo_i "error: too few RRSIG records ($_num) in expiration bucket"
_ret=1 _ret=1
fi fi
done done
@@ -188,9 +173,6 @@ do
$DIG $DIGOPTS $z @10.53.0.3 axfr | awk '$4 == "RRSIG" {print $9}' | sort | uniq -c | cat_i $DIG $DIGOPTS $z @10.53.0.3 axfr | awk '$4 == "RRSIG" {print $9}' | sort | uniq -c | cat_i
done done
# Set logfile offset for wait_for_log usage.
nextpartreset ns3/named.run
# #
# Check that DNSKEY is initially signed with a KSK and not a ZSK. # Check that DNSKEY is initially signed with a KSK and not a ZSK.
# #
@@ -221,8 +203,8 @@ test $count -eq 3 || ret=1
awk='$4 == "RRSIG" && $5 == "DNSKEY" { printf "%05u\n", $11 }' awk='$4 == "RRSIG" && $5 == "DNSKEY" { printf "%05u\n", $11 }'
id=`awk "${awk}" dig.out.ns3.test$n` id=`awk "${awk}" dig.out.ns3.test$n`
$SETTIME -D now+5 ns3/Kinacksk3.example.+007+${id} > settime.out.test$n || ret=1 $SETTIME -D now+5 ns3/Kinacksk3.example.+007+${id} > /dev/null 2>&1
($RNDCCMD 10.53.0.3 loadkeys inacksk3.example 2>&1 | sed 's/^/ns3 /' | cat_i) || ret=1 $RNDCCMD 10.53.0.3 loadkeys inacksk3.example 2>&1 | sed 's/^/ns3 /' | cat_i
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
@@ -249,8 +231,8 @@ count=`awk 'BEGIN { count = 0 }
END {print count}' dig.out.ns3.test$n` END {print count}' dig.out.ns3.test$n`
test $count -eq 3 || ret=1 test $count -eq 3 || ret=1
id=`awk '$4 == "RRSIG" && $5 == "CNAME" { printf "%05u\n", $11 }' dig.out.ns3.test$n` id=`awk '$4 == "RRSIG" && $5 == "CNAME" { printf "%05u\n", $11 }' dig.out.ns3.test$n`
$SETTIME -D now+5 ns3/Kinaczsk3.example.+007+${id} > settime.out.test$n || ret=1 $SETTIME -D now+5 ns3/Kinaczsk3.example.+007+${id} > /dev/null 2>&1
($RNDCCMD 10.53.0.3 loadkeys inaczsk3.example 2>&1 | sed 's/^/ns3 /' | cat_i) || ret=1 $RNDCCMD 10.53.0.3 loadkeys inaczsk3.example 2>&1 | sed 's/^/ns3 /' | cat_i
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -346,9 +328,9 @@ status=`expr $status + $ret`
echo_i "signing preset nsec3 zone" echo_i "signing preset nsec3 zone"
zsk=`cat autozsk.key` zsk=`cat autozsk.key`
ksk=`cat autoksk.key` ksk=`cat autoksk.key`
$SETTIME -K ns3 -P now -A now $zsk > settime.out.test$n.zsk || ret=1 $SETTIME -K ns3 -P now -A now $zsk > /dev/null 2>&1
$SETTIME -K ns3 -P now -A now $ksk > settime.out.test$n.ksk || ret=1 $SETTIME -K ns3 -P now -A now $ksk > /dev/null 2>&1
($RNDCCMD 10.53.0.3 loadkeys autonsec3.example. 2>&1 | sed 's/^/ns3 /' | cat_i) || ret=1 $RNDCCMD 10.53.0.3 loadkeys autonsec3.example. 2>&1 | sed 's/^/ns3 /' | cat_i
echo_i "waiting for changes to take effect" echo_i "waiting for changes to take effect"
sleep 3 sleep 3
@@ -401,30 +383,24 @@ status=`expr $status + $ret`
# Send rndc sync command to ns1, ns2 and ns3, to force the dynamically # Send rndc sync command to ns1, ns2 and ns3, to force the dynamically
# signed zones to be dumped to their zone files # signed zones to be dumped to their zone files
echo_i "dumping zone files" echo_i "dumping zone files"
($RNDCCMD 10.53.0.1 sync 2>&1 | sed 's/^/ns1 /' | cat_i) || ret=1 $RNDCCMD 10.53.0.1 sync 2>&1 | sed 's/^/ns1 /' | cat_i
($RNDCCMD 10.53.0.2 sync 2>&1 | sed 's/^/ns2 /' | cat_i) || ret=1 $RNDCCMD 10.53.0.2 sync 2>&1 | sed 's/^/ns2 /' | cat_i
($RNDCCMD 10.53.0.3 sync 2>&1 | sed 's/^/ns3 /' | cat_i) || ret=1 $RNDCCMD 10.53.0.3 sync 2>&1 | sed 's/^/ns3 /' | cat_i
now="$(TZ=UTC date +%Y%m%d%H%M%S)"
check_expiry() (
$DIG $DIGOPTS AXFR oldsigs.example @10.53.0.3 > dig.out.test$n
nearest_expiration="$(awk '$4 == "RRSIG" { print $9 }' < dig.out.test$n | sort -n | head -1)"
if [ "$nearest_expiration" -le "$now" ]; then
echo_i "failed: $nearest_expiration <= $now"
return 1
fi
)
echo_i "checking expired signatures were updated ($n)" echo_i "checking expired signatures were updated ($n)"
retry 10 check_expiry || ret=1 for i in 1 2 3 4 5 6 7 8 9
$DIG $DIGOPTS +noauth a.oldsigs.example. @10.53.0.3 a > dig.out.ns3.test$n || ret=1 do
$DIG $DIGOPTS +noauth a.oldsigs.example. @10.53.0.4 a > dig.out.ns4.test$n || ret=1 ret=0
digcomp dig.out.ns3.test$n dig.out.ns4.test$n || ret=1 $DIG $DIGOPTS +noauth a.oldsigs.example. @10.53.0.3 a > dig.out.ns3.test$n || ret=1
grep "flags:.*ad.*QUERY" dig.out.ns4.test$n > /dev/null || ret=1 $DIG $DIGOPTS +noauth a.oldsigs.example. @10.53.0.4 a > dig.out.ns4.test$n || ret=1
digcomp dig.out.ns3.test$n dig.out.ns4.test$n || ret=1
grep "flags:.*ad.*QUERY" dig.out.ns4.test$n > /dev/null || ret=1
[ $ret = 0 ] && break
sleep 1
done
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
# Check jitter distribution. # Check jitter distribution.
echo_i "checking expired signatures were jittered correctly ($n)" echo_i "checking expired signatures were jittered correctly ($n)"
ret=0 ret=0
@@ -502,7 +478,7 @@ echo_i "checking TTLs of imported DNSKEYs (no default) ($n)"
ret=0 ret=0
$DIG $DIGOPTS +tcp +noall +answer dnskey ttl1.example. @10.53.0.3 > dig.out.ns3.test$n || ret=1 $DIG $DIGOPTS +tcp +noall +answer dnskey ttl1.example. @10.53.0.3 > dig.out.ns3.test$n || ret=1
[ -s dig.out.ns3.test$n ] || ret=1 [ -s dig.out.ns3.test$n ] || ret=1
(awk 'BEGIN {r=0} $2 != 300 {r=1; print "found TTL " $2} END {exit r}' dig.out.ns3.test$n | cat_i) || ret=1 awk 'BEGIN {r=0} $2 != 300 {r=1; print "found TTL " $2} END {exit r}' dig.out.ns3.test$n || ret=1 | cat_i
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -511,7 +487,7 @@ echo_i "checking TTLs of imported DNSKEYs (with default) ($n)"
ret=0 ret=0
$DIG $DIGOPTS +tcp +noall +answer dnskey ttl2.example. @10.53.0.3 > dig.out.ns3.test$n || ret=1 $DIG $DIGOPTS +tcp +noall +answer dnskey ttl2.example. @10.53.0.3 > dig.out.ns3.test$n || ret=1
[ -s dig.out.ns3.test$n ] || ret=1 [ -s dig.out.ns3.test$n ] || ret=1
(awk 'BEGIN {r=0} $2 != 60 {r=1; print "found TTL " $2} END {exit r}' dig.out.ns3.test$n | cat_i) || ret=1 awk 'BEGIN {r=0} $2 != 60 {r=1; print "found TTL " $2} END {exit r}' dig.out.ns3.test$n || ret=1 | cat_i
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -520,7 +496,7 @@ echo_i "checking TTLs of imported DNSKEYs (mismatched) ($n)"
ret=0 ret=0
$DIG $DIGOPTS +tcp +noall +answer dnskey ttl3.example. @10.53.0.3 > dig.out.ns3.test$n || ret=1 $DIG $DIGOPTS +tcp +noall +answer dnskey ttl3.example. @10.53.0.3 > dig.out.ns3.test$n || ret=1
[ -s dig.out.ns3.test$n ] || ret=1 [ -s dig.out.ns3.test$n ] || ret=1
(awk 'BEGIN {r=0} $2 != 30 {r=1; print "found TTL " $2} END {exit r}' dig.out.ns3.test$n | cat_i) || ret=1 awk 'BEGIN {r=0} $2 != 30 {r=1; print "found TTL " $2} END {exit r}' dig.out.ns3.test$n || ret=1 | cat_i
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -529,7 +505,7 @@ echo_i "checking TTLs of imported DNSKEYs (existing RRset) ($n)"
ret=0 ret=0
$DIG $DIGOPTS +tcp +noall +answer dnskey ttl4.example. @10.53.0.3 > dig.out.ns3.test$n || ret=1 $DIG $DIGOPTS +tcp +noall +answer dnskey ttl4.example. @10.53.0.3 > dig.out.ns3.test$n || ret=1
[ -s dig.out.ns3.test$n ] || ret=1 [ -s dig.out.ns3.test$n ] || ret=1
(awk 'BEGIN {r=0} $2 != 30 {r=1; print "found TTL " $2} END {exit r}' dig.out.ns3.test$n | cat_i) || ret=1 awk 'BEGIN {r=0} $2 != 30 {r=1; print "found TTL " $2} END {exit r}' dig.out.ns3.test$n || ret=1 | cat_i
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -1020,10 +996,10 @@ status=`expr $status + $ret`
echo_i "checking secure-to-insecure transition, scheduled ($n)" echo_i "checking secure-to-insecure transition, scheduled ($n)"
ret=0 ret=0
file="ns3/`cat del1.key`.key" file="ns3/`cat del1.key`.key"
$SETTIME -I now -D now $file > settime.out.test$n.1 || ret=1 $SETTIME -I now -D now $file > /dev/null
file="ns3/`cat del2.key`.key" file="ns3/`cat del2.key`.key"
$SETTIME -I now -D now $file > settime.out.test$n.2 || ret=1 $SETTIME -I now -D now $file > /dev/null
($RNDCCMD 10.53.0.3 sign secure-to-insecure2.example. 2>&1 | sed 's/^/ns3 /' | cat_i) || ret=1 $RNDCCMD 10.53.0.3 sign secure-to-insecure2.example. 2>&1 | sed 's/^/ns3 /' | cat_i
for i in 0 1 2 3 4 5 6 7 8 9; do for i in 0 1 2 3 4 5 6 7 8 9; do
ret=0 ret=0
$DIG $DIGOPTS axfr secure-to-insecure2.example @10.53.0.3 > dig.out.ns3.test$n || ret=1 $DIG $DIGOPTS axfr secure-to-insecure2.example @10.53.0.3 > dig.out.ns3.test$n || ret=1
@@ -1049,19 +1025,21 @@ END
# Create DNSSEC keys in the zone directory. # Create DNSSEC keys in the zone directory.
$KEYGEN -a rsasha1 -3 -q -K ns3 jitter.nsec3.example > /dev/null $KEYGEN -a rsasha1 -3 -q -K ns3 jitter.nsec3.example > /dev/null
# Trigger zone signing. # Trigger zone signing.
($RNDCCMD 10.53.0.3 sign jitter.nsec3.example. 2>&1 | sed 's/^/ns3 /' | cat_i) || ret=1 $RNDCCMD 10.53.0.3 sign jitter.nsec3.example. 2>&1 | sed 's/^/ns3 /' | cat_i
# Wait until zone has been signed. # Wait until zone has been signed.
check_if_nsec3param_exists() { i=0
$DIG $DIGOPTS NSEC3PARAM jitter.nsec3.example @10.53.0.3 > dig.out.ns3.1.test$n || return 1 while [ "$i" -lt 20 ]; do
grep -q "^jitter\.nsec3\.example\..*NSEC3PARAM" dig.out.ns3.1.test$n || return 1 failed=0
} $DIG $DIGOPTS axfr jitter.nsec3.example @10.53.0.3 > dig.out.ns3.test$n || failed=1
retry_quiet 40 check_if_nsec3param_exists || { grep "NSEC3PARAM" dig.out.ns3.test$n > /dev/null || failed=1
echo_i "error: NSEC3PARAM not present yet" [ $failed -eq 0 ] && break
ret=1 echo_i "waiting ... ($i)"
} sleep $((i/5))
$DIG $DIGOPTS AXFR jitter.nsec3.example @10.53.0.3 > dig.out.ns3.2.test$n || ret=1 i=$((i+1))
done
[ $failed != 0 ] && echo_i "error: no NSEC3PARAM found in AXFR" && ret=1
# Check jitter distribution. # Check jitter distribution.
checkjitter dig.out.ns3.2.test$n || ret=1 checkjitter dig.out.ns3.test$n || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -1073,7 +1051,7 @@ oldinception=`$DIG $DIGOPTS +short soa prepub.example @10.53.0.3 | awk '/SOA/ {p
$KEYGEN -a rsasha1 -3 -q -K ns3 -P 0 -A +6d -I +38d -D +45d prepub.example > /dev/null $KEYGEN -a rsasha1 -3 -q -K ns3 -P 0 -A +6d -I +38d -D +45d prepub.example > /dev/null
($RNDCCMD 10.53.0.3 sign prepub.example 2>&1 | sed 's/^/ns1 /' | cat_i) || ret=1 $RNDCCMD 10.53.0.3 sign prepub.example 2>&1 | sed 's/^/ns1 /' | cat_i
newserial=$oldserial newserial=$oldserial
try=0 try=0
while [ $oldserial -eq $newserial -a $try -lt 42 ] while [ $oldserial -eq $newserial -a $try -lt 42 ]
@@ -1104,19 +1082,19 @@ oldfile=`cat active.key`
oldid=$(keyfile_to_key_id "$(cat active.key)") oldid=$(keyfile_to_key_id "$(cat active.key)")
newfile=`cat standby.key` newfile=`cat standby.key`
newid=$(keyfile_to_key_id "$(cat standby.key)") newid=$(keyfile_to_key_id "$(cat standby.key)")
$SETTIME -K ns1 -I now+2s -D now+25 $oldfile > settime.out.test$n.1 || ret=1 $SETTIME -K ns1 -I now+2s -D now+25 $oldfile > /dev/null
$SETTIME -K ns1 -i 0 -S $oldfile $newfile > settime.out.test$n.2 || ret=1 $SETTIME -K ns1 -i 0 -S $oldfile $newfile > /dev/null
# note previous zone serial number # note previous zone serial number
oldserial=`$DIG $DIGOPTS +short soa . @10.53.0.1 | awk '{print $3}'` oldserial=`$DIG $DIGOPTS +short soa . @10.53.0.1 | awk '{print $3}'`
($RNDCCMD 10.53.0.1 loadkeys . 2>&1 | sed 's/^/ns1 /' | cat_i) || ret=1 $RNDCCMD 10.53.0.1 loadkeys . 2>&1 | sed 's/^/ns1 /' | cat_i
sleep 4 sleep 4
echo_i "revoking key to duplicated key ID" echo_i "revoking key to duplicated key ID"
$SETTIME -R now -K ns2 Kbar.+005+30676.key > settime.out.test$n.3 || ret=1 $SETTIME -R now -K ns2 Kbar.+005+30676.key > /dev/null 2>&1
($RNDCCMD 10.53.0.2 loadkeys bar. 2>&1 | sed 's/^/ns2 /' | cat_i) || ret=1 $RNDCCMD 10.53.0.2 loadkeys bar. 2>&1 | sed 's/^/ns2 /' | cat_i
echo_i "waiting for changes to take effect" echo_i "waiting for changes to take effect"
sleep 5 sleep 5
@@ -1169,7 +1147,7 @@ n=`expr $n + 1`
status=`expr $status + $ret` status=`expr $status + $ret`
echo_i "forcing full sign" echo_i "forcing full sign"
($RNDCCMD 10.53.0.1 sign . 2>&1 | sed 's/^/ns1 /' | cat_i) || ret=1 $RNDCCMD 10.53.0.1 sign . 2>&1 | sed 's/^/ns1 /' | cat_i
echo_i "waiting for change to take effect" echo_i "waiting for change to take effect"
sleep 5 sleep 5
@@ -1195,10 +1173,8 @@ ret=0
zsk=`cat delayzsk.key` zsk=`cat delayzsk.key`
ksk=`cat delayksk.key` ksk=`cat delayksk.key`
# publication and activation times should be unset # publication and activation times should be unset
$SETTIME -K ns3 -pA -pP $zsk > settime.out.test$n.zsk || ret=1 $SETTIME -K ns3 -pA -pP $zsk | grep -v UNSET > /dev/null 2>&1 && ret=1
grep -v UNSET settime.out.test$n.zsk >/dev/null && ret=1 $SETTIME -K ns3 -pA -pP $ksk | grep -v UNSET > /dev/null 2>&1 && ret=1
$SETTIME -K ns3 -pA -pP $ksk > settime.out.test$n.ksk || ret=1
grep -v UNSET settime.out.test$n.ksk >/dev/null && ret=1
$DIG $DIGOPTS +noall +answer dnskey delay.example. @10.53.0.3 > dig.out.ns3.test$n || ret=1 $DIG $DIGOPTS +noall +answer dnskey delay.example. @10.53.0.3 > dig.out.ns3.test$n || ret=1
# DNSKEY not expected: # DNSKEY not expected:
awk 'BEGIN {r=1} $4=="DNSKEY" {r=0} END {exit r}' dig.out.ns3.test$n && ret=1 awk 'BEGIN {r=1} $4=="DNSKEY" {r=0} END {exit r}' dig.out.ns3.test$n && ret=1
@@ -1208,14 +1184,12 @@ status=`expr $status + $ret`
echo_i "checking scheduled key publication, not activation ($n)" echo_i "checking scheduled key publication, not activation ($n)"
ret=0 ret=0
# Ensure initial zone is loaded. $SETTIME -K ns3 -P now+3s -A none $zsk > /dev/null 2>&1
wait_for_notifies "delay.example" "ns3" || ret=1 $SETTIME -K ns3 -P now+3s -A none $ksk > /dev/null 2>&1
$SETTIME -K ns3 -P now+3s -A none $zsk > settime.out.test$n.zsk || ret=1 $RNDCCMD 10.53.0.3 loadkeys delay.example. 2>&1 | sed 's/^/ns2 /' | cat_i
$SETTIME -K ns3 -P now+3s -A none $ksk > settime.out.test$n.ksk || ret=1
($RNDCCMD 10.53.0.3 loadkeys delay.example. 2>&1 | sed 's/^/ns2 /' | cat_i) || ret=1
echo_i "waiting for changes to take effect" echo_i "waiting for changes to take effect"
sleep 3 sleep 5
wait_for_notifies "delay.example" "ns3" || ret=1
$DIG $DIGOPTS +noall +answer dnskey delay.example. @10.53.0.3 > dig.out.ns3.test$n || ret=1 $DIG $DIGOPTS +noall +answer dnskey delay.example. @10.53.0.3 > dig.out.ns3.test$n || ret=1
# DNSKEY expected: # DNSKEY expected:
@@ -1228,12 +1202,13 @@ status=`expr $status + $ret`
echo_i "checking scheduled key activation ($n)" echo_i "checking scheduled key activation ($n)"
ret=0 ret=0
$SETTIME -K ns3 -A now+3s $zsk > settime.out.test$n.zsk || ret=1 $SETTIME -K ns3 -A now+3s $zsk > /dev/null 2>&1
$SETTIME -K ns3 -A now+3s $ksk > settime.out.test$n.ksk || ret=1 $SETTIME -K ns3 -A now+3s $ksk > /dev/null 2>&1
($RNDCCMD 10.53.0.3 loadkeys delay.example. 2>&1 | sed 's/^/ns2 /' | cat_i) || ret=1 $RNDCCMD 10.53.0.3 loadkeys delay.example. 2>&1 | sed 's/^/ns2 /' | cat_i
echo_i "waiting for changes to take effect" echo_i "waiting for changes to take effect"
sleep 3 sleep 5
wait_for_notifies "delay.example" "ns3" || ret=1
$DIG $DIGOPTS +noall +answer dnskey delay.example. @10.53.0.3 > dig.out.ns3.1.test$n || ret=1 $DIG $DIGOPTS +noall +answer dnskey delay.example. @10.53.0.3 > dig.out.ns3.1.test$n || ret=1
# DNSKEY expected: # DNSKEY expected:
awk 'BEGIN {r=1} $4=="DNSKEY" {r=0} END {exit r}' dig.out.ns3.1.test$n || ret=1 awk 'BEGIN {r=1} $4=="DNSKEY" {r=0} END {exit r}' dig.out.ns3.1.test$n || ret=1
@@ -1343,7 +1318,7 @@ status=`expr $status + $ret`
echo_i "forcing full sign with unreadable keys ($n)" echo_i "forcing full sign with unreadable keys ($n)"
ret=0 ret=0
chmod 0 ns1/K.+*+*.key ns1/K.+*+*.private || ret=1 chmod 0 ns1/K.+*+*.key ns1/K.+*+*.private || ret=1
($RNDCCMD 10.53.0.1 sign . 2>&1 | sed 's/^/ns1 /' | cat_i) || ret=1 $RNDCCMD 10.53.0.1 sign . 2>&1 | sed 's/^/ns1 /' | cat_i
$DIG $DIGOPTS . @10.53.0.1 dnskey > dig.out.ns1.test$n || ret=1 $DIG $DIGOPTS . @10.53.0.1 dnskey > dig.out.ns1.test$n || ret=1
grep "status: NOERROR" dig.out.ns1.test$n > /dev/null || ret=1 grep "status: NOERROR" dig.out.ns1.test$n > /dev/null || ret=1
n=`expr $n + 1` n=`expr $n + 1`
@@ -1353,11 +1328,11 @@ status=`expr $status + $ret`
echo_i "test turning on auto-dnssec during reconfig ($n)" echo_i "test turning on auto-dnssec during reconfig ($n)"
ret=0 ret=0
# first create a zone that doesn't have auto-dnssec # first create a zone that doesn't have auto-dnssec
($RNDCCMD 10.53.0.3 addzone reconf.example '{ type master; file "reconf.example.db"; };' 2>&1 | sed 's/^/ns3 /' | cat_i) || ret=1 $RNDCCMD 10.53.0.3 addzone reconf.example '{ type master; file "reconf.example.db"; };' 2>&1 | sed 's/^/ns3 /' | cat_i
rekey_calls=`grep "zone reconf.example.*next key event" ns3/named.run | wc -l` rekey_calls=`grep "zone reconf.example.*next key event" ns3/named.run | wc -l`
[ "$rekey_calls" -eq 0 ] || ret=1 [ "$rekey_calls" -eq 0 ] || ret=1
# ...then we add auto-dnssec and reconfigure # ...then we add auto-dnssec and reconfigure
($RNDCCMD 10.53.0.3 modzone reconf.example '{ type master; file "reconf.example.db"; allow-update { any; }; auto-dnssec maintain; };' 2>&1 | sed 's/^/ns3 /' | cat_i) || ret=1 $RNDCCMD 10.53.0.3 modzone reconf.example '{ type master; file "reconf.example.db"; allow-update { any; }; auto-dnssec maintain; };' 2>&1 | sed 's/^/ns3 /' | cat_i
rndc_reconfig ns3 10.53.0.3 rndc_reconfig ns3 10.53.0.3
for i in 0 1 2 3 4 5 6 7 8 9; do for i in 0 1 2 3 4 5 6 7 8 9; do
lret=0 lret=0
@@ -1379,6 +1354,7 @@ $DIG $DIGOPTS @10.53.0.3 sync.example cdnskey > dig.out.ns3.cdnskeytest$n
grep -i "sync.example.*in.cds.*[1-9][0-9]* " dig.out.ns3.cdstest$n > /dev/null || ret=1 grep -i "sync.example.*in.cds.*[1-9][0-9]* " dig.out.ns3.cdstest$n > /dev/null || ret=1
grep -i "sync.example.*in.cdnskey.*257 " dig.out.ns3.cdnskeytest$n > /dev/null || ret=1 grep -i "sync.example.*in.cdnskey.*257 " dig.out.ns3.cdnskeytest$n > /dev/null || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ "$lret" != 0 ]; then ret=$lret; fi
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -1413,35 +1389,37 @@ if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
echo_i "setting CDS and CDNSKEY deletion times and calling 'rndc loadkeys'" echo_i "setting CDS and CDNSKEY deletion times and calling 'rndc loadkeys'"
$SETTIME -D sync now `cat sync.key` > settime.out.test$n || ret=1 $SETTIME -D sync now+2 `cat sync.key` > /dev/null
($RNDCCMD 10.53.0.3 loadkeys sync.example | sed 's/^/ns3 /' | cat_i) || ret=1 $RNDCCMD 10.53.0.3 loadkeys sync.example | sed 's/^/ns3 /' | cat_i
echo_i "waiting for deletion to occur"
sleep 3
echo_i "checking that the CDS and CDNSKEY are deleted ($n)" echo_i "checking that the CDS and CDNSKEY are deleted ($n)"
ret=0 ret=0
ensure_cds_and_cdnskey_are_deleted() { $DIG $DIGOPTS @10.53.0.3 sync.example cds > dig.out.ns3.cdstest$n
$DIG $DIGOPTS @10.53.0.3 sync.example. CDS > dig.out.ns3.cdstest$n || return 1 $DIG $DIGOPTS @10.53.0.3 sync.example cdnskey > dig.out.ns3.cdnskeytest$n
awk '$1 == "sync.example." && $4 == "CDS" { exit 1; }' dig.out.ns3.cdstest$n || return 1 grep -i "sync.example.*in.cds.*[1-9][0-9]* " dig.out.ns3.cdstest$n > /dev/null && ret=1
$DIG $DIGOPTS @10.53.0.3 sync.example. CDNSKEY > dig.out.ns3.cdnskeytest$n || return 1 grep -i "sync.example.*in.cdnskey.*257 " dig.out.ns3.cdnskeytest$n > /dev/null && ret=1
awk '$1 == "sync.example." && $4 == "CDNSKEY" { exit 1; }' dig.out.ns3.cdnskeytest$n || return 1
}
retry 10 ensure_cds_and_cdnskey_are_deleted || ret=1
n=`expr $n + 1` n=`expr $n + 1`
if [ "$lret" != 0 ]; then ret=$lret; fi
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
echo_i "check that dnssec-settime -p Dsync works ($n)" echo_i "check that dnssec-settime -p Dsync works ($n)"
ret=0 ret=0
$SETTIME -p Dsync `cat sync.key` > settime.out.test$n || ret=1 $SETTIME -p Dsync `cat sync.key` > settime.out.$n|| ret=0
grep "SYNC Delete:" settime.out.test$n >/dev/null || ret=1 grep "SYNC Delete:" settime.out.$n >/dev/null || ret=0
n=`expr $n + 1` n=`expr $n + 1`
if [ "$lret" != 0 ]; then ret=$lret; fi
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
echo_i "check that dnssec-settime -p Psync works ($n)" echo_i "check that dnssec-settime -p Psync works ($n)"
ret=0 ret=0
$SETTIME -p Psync `cat sync.key` > settime.out.test$n || ret=1 $SETTIME -p Psync `cat sync.key` > settime.out.$n|| ret=0
grep "SYNC Publish:" settime.out.test$n >/dev/null || ret=1 grep "SYNC Publish:" settime.out.$n >/dev/null || ret=0
n=`expr $n + 1` n=`expr $n + 1`
if [ "$lret" != 0 ]; then ret=$lret; fi
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -1547,9 +1525,9 @@ if [ $_ret -ne 0 ]; then
fi fi
# Mark the inactive ZSK as pending removal. # Mark the inactive ZSK as pending removal.
file="ns3/`cat delzsk.key`.key" file="ns3/`cat delzsk.key`.key"
$SETTIME -D now-1h $file > settime.out.test$n || ret=1 $SETTIME -D now-1h $file > settime.out.test$n 2>&1 || ret=1
# Trigger removal of the inactive ZSK and wait until its completion. # Trigger removal of the inactive ZSK and wait until its completion.
($RNDCCMD 10.53.0.3 loadkeys delzsk.example 2>&1 | sed 's/^/ns3 /' | cat_i) || ret=1 $RNDCCMD 10.53.0.3 loadkeys delzsk.example 2>&1 | sed 's/^/ns3 /' | cat_i
for i in 0 1 2 3 4 5 6 7 8 9; do for i in 0 1 2 3 4 5 6 7 8 9; do
_ret=1 _ret=1
$RNDCCMD 10.53.0.3 signing -list delzsk.example > signing.out.3.test$n 2>&1 $RNDCCMD 10.53.0.3 signing -list delzsk.example > signing.out.3.test$n 2>&1
+1
View File
@@ -12,6 +12,7 @@
SYSTEMTESTTOP=.. SYSTEMTESTTOP=..
. $SYSTEMTESTTOP/conf.sh . $SYSTEMTESTTOP/conf.sh
$SHELL clean.sh
copy_setports ns1/named.conf.in ns1/named.conf copy_setports ns1/named.conf.in ns1/named.conf
copy_setports ns2/named.conf.in ns2/named.conf copy_setports ns2/named.conf.in ns2/named.conf
copy_setports ns3/named.conf.in ns3/named.conf copy_setports ns3/named.conf.in ns3/named.conf
+1
View File
@@ -12,5 +12,6 @@
SYSTEMTESTTOP=.. SYSTEMTESTTOP=..
. $SYSTEMTESTTOP/conf.sh . $SYSTEMTESTTOP/conf.sh
$SHELL clean.sh
copy_setports ns1/named.conf.in ns1/named.conf copy_setports ns1/named.conf.in ns1/named.conf
copy_setports ns2/named.conf.in ns2/named.conf copy_setports ns2/named.conf.in ns2/named.conf
+2
View File
@@ -10,6 +10,8 @@
SYSTEMTESTTOP=.. SYSTEMTESTTOP=..
. $SYSTEMTESTTOP/conf.sh . $SYSTEMTESTTOP/conf.sh
$SHELL clean.sh
cp -f ns1/dynamic.db.in ns1/dynamic.db cp -f ns1/dynamic.db.in ns1/dynamic.db
copy_setports ns1/named.conf.in ns1/named.conf copy_setports ns1/named.conf.in ns1/named.conf
copy_setports ns2/named.conf.in ns2/named.conf copy_setports ns2/named.conf.in ns2/named.conf
-2
View File
@@ -14,7 +14,6 @@ rm -f ns*/named.lock
rm -f ns*/named.memstats rm -f ns*/named.memstats
rm -f ns*/named.conf rm -f ns*/named.conf
rm -f ns*/named.run rm -f ns*/named.run
rm -f ns*/named.run.prev
rm -f ns1/*dom*example.db rm -f ns1/*dom*example.db
rm -f ns2/__catz__*db rm -f ns2/__catz__*db
rm -f ns2/named.conf.tmp rm -f ns2/named.conf.tmp
@@ -24,4 +23,3 @@ rm -f ns[123]/catalog[1234].example.db
rm -rf ns2/zonedir rm -rf ns2/zonedir
rm -f ns*/*.nzd ns*/*.nzd-lock rm -f ns*/*.nzd ns*/*.nzd-lock
rm -f ns*/managed-keys.bind* rm -f ns*/managed-keys.bind*
rm -f wait_for_message.*
File diff suppressed because it is too large Load Diff
+2
View File
@@ -14,6 +14,8 @@ set -eu
SYSTEMTESTTOP=.. SYSTEMTESTTOP=..
. $SYSTEMTESTTOP/conf.sh . $SYSTEMTESTTOP/conf.sh
$SHELL clean.sh
touch empty touch empty
Z=cds.test Z=cds.test
+2
View File
@@ -12,6 +12,8 @@
SYSTEMTESTTOP=.. SYSTEMTESTTOP=..
. $SYSTEMTESTTOP/conf.sh . $SYSTEMTESTTOP/conf.sh
$SHELL clean.sh
copy_setports ns1/named.conf.in ns1/named.conf copy_setports ns1/named.conf.in ns1/named.conf
copy_setports ns2/named.conf.in ns2/named.conf copy_setports ns2/named.conf.in ns2/named.conf
copy_setports ns5/named.conf.in ns5/named.conf copy_setports ns5/named.conf.in ns5/named.conf
+1 -1
View File
@@ -9,7 +9,7 @@
* information regarding copyright ownership. * information regarding copyright ownership.
*/ */
trust-anchors { dnssec-keys {
example. initial-ds 60724 5 1 "D74CF845955A0DFE604AF215E948E67D2EA94FF3"; example. initial-ds 60724 5 1 "D74CF845955A0DFE604AF215E948E67D2EA94FF3";
example. initial-key 257 3 5 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbody0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQYfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX2STtkE0hNJ/R6JYKmD2EH7k1nyqJd08ibrEt55DuV4BiUjyyERdVbsuwE60jVqAwCKyVBYXb2sI+zv1yPNDBIANd6KTgnq6YWzx5ZodQP3W4K7Z/Bk3EKmVCvrTKZK/ADLAKaL0/6DD07+1jXA4BiNyoZTLTapkudkGad+Rn6zqCkwuMmrU="; example. initial-key 257 3 5 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbody0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQYfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX2STtkE0hNJ/R6JYKmD2EH7k1nyqJd08ibrEt55DuV4BiUjyyERdVbsuwE60jVqAwCKyVBYXb2sI+zv1yPNDBIANd6KTgnq6YWzx5ZodQP3W4K7Z/Bk3EKmVCvrTKZK/ADLAKaL0/6DD07+1jXA4BiNyoZTLTapkudkGad+Rn6zqCkwuMmrU=";
}; };
+1 -1
View File
@@ -9,7 +9,7 @@
* information regarding copyright ownership. * information regarding copyright ownership.
*/ */
trust-anchors { dnssec-keys {
example. static-ds 60724 5 1 "D74CF845955A0DFE604AF215E948E67D2EA94FF3"; example. static-ds 60724 5 1 "D74CF845955A0DFE604AF215E948E67D2EA94FF3";
example. static-key 257 3 5 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbody0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQYfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX2STtkE0hNJ/R6JYKmD2EH7k1nyqJd08ibrEt55DuV4BiUjyyERdVbsuwE60jVqAwCKyVBYXb2sI+zv1yPNDBIANd6KTgnq6YWzx5ZodQP3W4K7Z/Bk3EKmVCvrTKZK/ADLAKaL0/6DD07+1jXA4BiNyoZTLTapkudkGad+Rn6zqCkwuMmrU="; example. static-key 257 3 5 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbody0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQYfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX2STtkE0hNJ/R6JYKmD2EH7k1nyqJd08ibrEt55DuV4BiUjyyERdVbsuwE60jVqAwCKyVBYXb2sI+zv1yPNDBIANd6KTgnq6YWzx5ZodQP3W4K7Z/Bk3EKmVCvrTKZK/ADLAKaL0/6DD07+1jXA4BiNyoZTLTapkudkGad+Rn6zqCkwuMmrU=";
}; };
@@ -13,7 +13,7 @@ options {
dnssec-validation yes; dnssec-validation yes;
}; };
trust-anchors { dnssec-keys {
example. initial-key 257 3 8 "AwEAAawvFp8GlBx8Qt6yaIqXkDe+nMkSk2HkTAG7qlVBo++AQwZ1j3Xl example. initial-key 257 3 8 "AwEAAawvFp8GlBx8Qt6yaIqXkDe+nMkSk2HkTAG7qlVBo++AQwZ1j3Xl
25IN4jsw0VTMbKUbafw9DYsVzztIwx1sNkKRLo6qP9SSkBL8RicQaafG 25IN4jsw0VTMbKUbafw9DYsVzztIwx1sNkKRLo6qP9SSkBL8RicQaafG
tURtsYI3oqte5qqLve1CUpRD8J06Pg1xkOxsDlz9sQAyiQrOyvMbykJY tURtsYI3oqte5qqLve1CUpRD8J06Pg1xkOxsDlz9sQAyiQrOyvMbykJY
@@ -23,7 +23,7 @@ trust-anchors {
NQyrszHhWUU="; NQyrszHhWUU=";
}; };
trust-anchors { dnssec-keys {
example. static-key 257 3 8 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbod example. static-key 257 3 8 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbod
y0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQ y0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQ
YfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX YfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX
@@ -13,7 +13,7 @@ options {
dnssec-validation yes; dnssec-validation yes;
}; };
trust-anchors { dnssec-keys {
. initial-key 257 3 8 "AwEAAawvFp8GlBx8Qt6yaIqXkDe+nMkSk2HkTAG7qlVBo++AQwZ1j3Xl . initial-key 257 3 8 "AwEAAawvFp8GlBx8Qt6yaIqXkDe+nMkSk2HkTAG7qlVBo++AQwZ1j3Xl
25IN4jsw0VTMbKUbafw9DYsVzztIwx1sNkKRLo6qP9SSkBL8RicQaafG 25IN4jsw0VTMbKUbafw9DYsVzztIwx1sNkKRLo6qP9SSkBL8RicQaafG
tURtsYI3oqte5qqLve1CUpRD8J06Pg1xkOxsDlz9sQAyiQrOyvMbykJY tURtsYI3oqte5qqLve1CUpRD8J06Pg1xkOxsDlz9sQAyiQrOyvMbykJY
@@ -9,7 +9,7 @@
* information regarding copyright ownership. * information regarding copyright ownership.
*/ */
trust-anchors { dnssec-keys {
# This key (19036) is to be phased out starting in 2017. It will # This key (19036) is to be phased out starting in 2017. It will
# remain in the root zone for some time after its successor key # remain in the root zone for some time after its successor key
# has been added. It will remain this file until it is removed from # has been added. It will remain this file until it is removed from
@@ -9,7 +9,7 @@
* information regarding copyright ownership. * information regarding copyright ownership.
*/ */
trust-anchors { dnssec-keys {
example. initial-ds 60724 5 1 "D74CF845955A0DFE604AF215E948E67D2EA94FF3"; example. initial-ds 60724 5 1 "D74CF845955A0DFE604AF215E948E67D2EA94FF3";
example. static-ds 60724 5 2 "29E79B9064EE1A11DF3BFF19581DDFED7952C22CC204ACE17B6007EB1437E9E6"; example. static-ds 60724 5 2 "29E79B9064EE1A11DF3BFF19581DDFED7952C22CC204ACE17B6007EB1437E9E6";
}; };
@@ -9,7 +9,7 @@
* information regarding copyright ownership. * information regarding copyright ownership.
*/ */
trust-anchors { dnssec-keys {
example. initial-ds 60724 5 1 "D74CF845955A0DFE604AF215E948E67D2EA94FF3"; example. initial-ds 60724 5 1 "D74CF845955A0DFE604AF215E948E67D2EA94FF3";
example. static-key 257 3 5 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbody0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQYfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX2STtkE0hNJ/R6JYKmD2EH7k1nyqJd08ibrEt55DuV4BiUjyyERdVbsuwE60jVqAwCKyVBYXb2sI+zv1yPNDBIANd6KTgnq6YWzx5ZodQP3W4K7Z/Bk3EKmVCvrTKZK/ADLAKaL0/6DD07+1jXA4BiNyoZTLTapkudkGad+Rn6zqCkwuMmrU="; example. static-key 257 3 5 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbody0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQYfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX2STtkE0hNJ/R6JYKmD2EH7k1nyqJd08ibrEt55DuV4BiUjyyERdVbsuwE60jVqAwCKyVBYXb2sI+zv1yPNDBIANd6KTgnq6YWzx5ZodQP3W4K7Z/Bk3EKmVCvrTKZK/ADLAKaL0/6DD07+1jXA4BiNyoZTLTapkudkGad+Rn6zqCkwuMmrU=";
}; };
@@ -9,7 +9,7 @@
* information regarding copyright ownership. * information regarding copyright ownership.
*/ */
trust-anchors { dnssec-keys {
example. static-ds 60724 5 1 "D74CF845955A0DFE604AF215E948E67D2EA94FF3"; example. static-ds 60724 5 1 "D74CF845955A0DFE604AF215E948E67D2EA94FF3";
example. initial-key 257 3 5 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbody0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQYfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX2STtkE0hNJ/R6JYKmD2EH7k1nyqJd08ibrEt55DuV4BiUjyyERdVbsuwE60jVqAwCKyVBYXb2sI+zv1yPNDBIANd6KTgnq6YWzx5ZodQP3W4K7Z/Bk3EKmVCvrTKZK/ADLAKaL0/6DD07+1jXA4BiNyoZTLTapkudkGad+Rn6zqCkwuMmrU="; example. initial-key 257 3 5 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbody0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQYfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX2STtkE0hNJ/R6JYKmD2EH7k1nyqJd08ibrEt55DuV4BiUjyyERdVbsuwE60jVqAwCKyVBYXb2sI+zv1yPNDBIANd6KTgnq6YWzx5ZodQP3W4K7Z/Bk3EKmVCvrTKZK/ADLAKaL0/6DD07+1jXA4BiNyoZTLTapkudkGad+Rn6zqCkwuMmrU=";
}; };
@@ -9,7 +9,7 @@
* information regarding copyright ownership. * information regarding copyright ownership.
*/ */
trust-anchors { dnssec-keys {
example. initial-key 257 3 5 "AwEAAawvFp8GlBx8Qt6yaIqXkDe+nMkSk2HkTAG7qlVBo++AQwZ1j3Xl25IN4jsw0VTMbKUbafw9DYsVzztIwx1sNkKRLo6qP9SSkBL8RicQaafGtURtsYI3oqte5qqLve1CUpRD8J06Pg1xkOxsDlz9sQAyiQrOyvMbykJYkYrFYGLzYAgl/JtMyVVYlBl9pqxQuAPKYPOuO1axaad/wLN3+wTy/hcJfpvJpqzXlDF9bI5RmpoX/7geZ06vpcYJEoT0xkkmPlEl0ZjEDrm/WIaSWG0/CEDpHcOXFz4OEczMVpY+lnuFfKybwF1WHFn2BwVEOS6cMM6ukIjINQyrszHhWUU="; example. initial-key 257 3 5 "AwEAAawvFp8GlBx8Qt6yaIqXkDe+nMkSk2HkTAG7qlVBo++AQwZ1j3Xl25IN4jsw0VTMbKUbafw9DYsVzztIwx1sNkKRLo6qP9SSkBL8RicQaafGtURtsYI3oqte5qqLve1CUpRD8J06Pg1xkOxsDlz9sQAyiQrOyvMbykJYkYrFYGLzYAgl/JtMyVVYlBl9pqxQuAPKYPOuO1axaad/wLN3+wTy/hcJfpvJpqzXlDF9bI5RmpoX/7geZ06vpcYJEoT0xkkmPlEl0ZjEDrm/WIaSWG0/CEDpHcOXFz4OEczMVpY+lnuFfKybwF1WHFn2BwVEOS6cMM6ukIjINQyrszHhWUU=";
example. static-key 257 3 5 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbody0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQYfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX2STtkE0hNJ/R6JYKmD2EH7k1nyqJd08ibrEt55DuV4BiUjyyERdVbsuwE60jVqAwCKyVBYXb2sI+zv1yPNDBIANd6KTgnq6YWzx5ZodQP3W4K7Z/Bk3EKmVCvrTKZK/ADLAKaL0/6DD07+1jXA4BiNyoZTLTapkudkGad+Rn6zqCkwuMmrU="; example. static-key 257 3 5 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbody0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQYfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX2STtkE0hNJ/R6JYKmD2EH7k1nyqJd08ibrEt55DuV4BiUjyyERdVbsuwE60jVqAwCKyVBYXb2sI+zv1yPNDBIANd6KTgnq6YWzx5ZodQP3W4K7Z/Bk3EKmVCvrTKZK/ADLAKaL0/6DD07+1jXA4BiNyoZTLTapkudkGad+Rn6zqCkwuMmrU=";
}; };
@@ -13,7 +13,7 @@ options {
dnssec-validation auto; dnssec-validation auto;
}; };
trust-anchors { dnssec-keys {
. static-key 257 3 8 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbod . static-key 257 3 8 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbod
y0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQ y0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQ
YfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX YfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX
@@ -9,7 +9,7 @@
* information regarding copyright ownership. * information regarding copyright ownership.
*/ */
trust-anchors { dnssec-keys {
# This key (19036) is to be phased out starting in 2017. It will # This key (19036) is to be phased out starting in 2017. It will
# remain in the root zone for some time after its successor key # remain in the root zone for some time after its successor key
# has been added. It will remain this file until it is removed from # has been added. It will remain this file until it is removed from
@@ -9,7 +9,7 @@
* information regarding copyright ownership. * information regarding copyright ownership.
*/ */
trust-anchors { dnssec-keys {
# This key (19036) is to be phased out starting in 2017. It will # This key (19036) is to be phased out starting in 2017. It will
# remain in the root zone for some time after its successor key # remain in the root zone for some time after its successor key
# has been added. It will remain this file until it is removed from # has been added. It will remain this file until it is removed from

Some files were not shown because too many files have changed in this diff Show More