Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3878c145c9 | ||
|
|
4acbfbc2d1 | ||
|
|
1ef9a32de7 | ||
|
|
6c738fe323 |
+91
-126
@@ -56,16 +56,6 @@ variables:
|
|||||||
# Some jobs may clean up the build artifacts unless this is set to 0.
|
# Some jobs may clean up the build artifacts unless this is set to 0.
|
||||||
CLEAN_BUILD_ARTIFACTS_ON_SUCCESS: 1
|
CLEAN_BUILD_ARTIFACTS_ON_SUCCESS: 1
|
||||||
|
|
||||||
# DNS Shotgun performance testing defaults
|
|
||||||
SHOTGUN_ROUNDS: 1
|
|
||||||
SHOTGUN_DURATION: 120
|
|
||||||
# allow unlimited improvements against baseline
|
|
||||||
SHOTGUN_EVAL_THRESHOLD_CPU_MIN: '-inf'
|
|
||||||
SHOTGUN_EVAL_THRESHOLD_MEMORY_MIN: '-inf'
|
|
||||||
SHOTGUN_EVAL_THRESHOLD_RCODE_MAX: '+inf'
|
|
||||||
SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_MIN: '-inf'
|
|
||||||
SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_DRIFT_MIN: '-inf'
|
|
||||||
|
|
||||||
default:
|
default:
|
||||||
# Allow all running CI jobs to be automatically canceled when a new
|
# Allow all running CI jobs to be automatically canceled when a new
|
||||||
# version of a branch is pushed.
|
# version of a branch is pushed.
|
||||||
@@ -117,55 +107,16 @@ stages:
|
|||||||
- runner-manager
|
- runner-manager
|
||||||
- aarch64
|
- aarch64
|
||||||
|
|
||||||
.freebsd-autoscaler-13-amd64-tags: &freebsd_autoscaler_13_amd64_tags
|
# Autoscaling GitLab Runner on AWS EC2 (FreeBSD)
|
||||||
|
|
||||||
|
.freebsd-stress-amd64: &freebsd_stress_amd64
|
||||||
tags:
|
tags:
|
||||||
- amd64
|
- bsd-stress-test
|
||||||
- autoscaler
|
|
||||||
- aws
|
- aws
|
||||||
- bsd-stress-test-1
|
- autoscaler
|
||||||
- shell
|
- shell
|
||||||
- stress-test
|
- stress-test
|
||||||
|
|
||||||
.freebsd-autoscaler-14-amd64-tags: &freebsd_autoscaler_14_amd64_tags
|
|
||||||
tags:
|
|
||||||
- amd64
|
- amd64
|
||||||
- autoscaler
|
|
||||||
- aws
|
|
||||||
- bsd-stress-test-2
|
|
||||||
- shell
|
|
||||||
- stress-test
|
|
||||||
|
|
||||||
.freebsd-autoscaler-amd64: &freebsd_autoscaler_amd64
|
|
||||||
variables:
|
|
||||||
CC: clang
|
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
|
||||||
# Even though there's only one job per runtime environment, the GitLab
|
|
||||||
# "instance" executor insists on cloning the Git repository to a path that
|
|
||||||
# contains a variable number from zero to the "maximum concurrent instances
|
|
||||||
# count" allowed on the GitLab Runner. See the "0" directory in this
|
|
||||||
# example path: /home/ec2-user/builds/t1_4FZzvz/0/isc-projects/bind9/.git/.
|
|
||||||
#
|
|
||||||
# This is not a problem for isolated jobs like "stress" tests that depend
|
|
||||||
# on no other jobs. However, it is a problem for jobs that need other jobs'
|
|
||||||
# artifacts. For example, a system test job that has its Git repo cloned to
|
|
||||||
# the "/1/" sub-path will fail if it downloads build job artifacts that
|
|
||||||
# have ./configure output files with "/0/" in its sub-path recorded.
|
|
||||||
GIT_CLONE_PATH: "/home/ec2-user/builds/${CI_PROJECT_PATH}/"
|
|
||||||
# Use MIT Kerberos5 for BIND 9 GSS-API support because of FreeBSD Heimdal
|
|
||||||
# incompatibility; see https://bugs.freebsd.org/275241.
|
|
||||||
EXTRA_CONFIGURE: "${WITH_READLINE_EDITLINE} --with-gssapi=/usr/local/bin/krb5-config"
|
|
||||||
|
|
||||||
# Autoscaling GitLab Runner on AWS EC2 (FreeBSD 13)
|
|
||||||
|
|
||||||
.freebsd-autoscaler-13-amd64: &freebsd_autoscaler_13_amd64
|
|
||||||
<<: *freebsd_autoscaler_amd64
|
|
||||||
<<: *freebsd_autoscaler_13_amd64_tags
|
|
||||||
|
|
||||||
# Autoscaling GitLab Runner on AWS EC2 (FreeBSD 14)
|
|
||||||
|
|
||||||
.freebsd-autoscaler-14-amd64: &freebsd_autoscaler_14_amd64
|
|
||||||
<<: *freebsd_autoscaler_amd64
|
|
||||||
<<: *freebsd_autoscaler_14_amd64_tags
|
|
||||||
|
|
||||||
### Docker Image Templates
|
### Docker Image Templates
|
||||||
|
|
||||||
@@ -253,6 +204,14 @@ stages:
|
|||||||
|
|
||||||
### QCOW2 Image Templates
|
### QCOW2 Image Templates
|
||||||
|
|
||||||
|
.freebsd-13-amd64: &freebsd_13_amd64_image
|
||||||
|
image: "freebsd-13.4-x86_64"
|
||||||
|
<<: *libvirt_amd64
|
||||||
|
|
||||||
|
.freebsd-14-amd64: &freebsd_14_amd64_image
|
||||||
|
image: "freebsd-14.2-x86_64"
|
||||||
|
<<: *libvirt_amd64
|
||||||
|
|
||||||
.openbsd-amd64: &openbsd_amd64_image
|
.openbsd-amd64: &openbsd_amd64_image
|
||||||
image: "openbsd-7.6-x86_64"
|
image: "openbsd-7.6-x86_64"
|
||||||
<<: *libvirt_amd64
|
<<: *libvirt_amd64
|
||||||
@@ -260,18 +219,31 @@ stages:
|
|||||||
### Job Templates
|
### Job Templates
|
||||||
|
|
||||||
.api-pipelines-schedules-tags-triggers-web-triggering-rules: &api_pipelines_schedules_tags_triggers_web_triggering_rules
|
.api-pipelines-schedules-tags-triggers-web-triggering-rules: &api_pipelines_schedules_tags_triggers_web_triggering_rules
|
||||||
rules:
|
only:
|
||||||
- if: '$CI_PIPELINE_SOURCE =~ /^(api|pipeline|schedule|trigger|web)$/'
|
- api
|
||||||
- if: '$CI_COMMIT_TAG != null'
|
- pipelines
|
||||||
|
- schedules
|
||||||
|
- tags
|
||||||
|
- triggers
|
||||||
|
- web
|
||||||
|
|
||||||
.api-pipelines-schedules-triggers-web-triggering-rules: &api_pipelines_schedules_triggers_web_triggering_rules
|
.api-pipelines-schedules-triggers-web-triggering-rules: &api_pipelines_schedules_triggers_web_triggering_rules
|
||||||
rules:
|
only:
|
||||||
- if: '$CI_PIPELINE_SOURCE =~ /^(api|pipeline|schedule|trigger|web)$/'
|
- api
|
||||||
|
- pipelines
|
||||||
|
- schedules
|
||||||
|
- triggers
|
||||||
|
- web
|
||||||
|
|
||||||
.default-triggering-rules: &default_triggering_rules
|
.default-triggering-rules: &default_triggering_rules
|
||||||
rules:
|
only:
|
||||||
- if: '$CI_PIPELINE_SOURCE =~ /^(api|merge_request_event|pipeline|schedule|trigger|web)$/'
|
- api
|
||||||
- if: '$CI_COMMIT_TAG != null'
|
- merge_requests
|
||||||
|
- pipelines
|
||||||
|
- schedules
|
||||||
|
- tags
|
||||||
|
- triggers
|
||||||
|
- web
|
||||||
|
|
||||||
.precheck: &precheck_job
|
.precheck: &precheck_job
|
||||||
<<: *default_triggering_rules
|
<<: *default_triggering_rules
|
||||||
@@ -371,41 +343,18 @@ stages:
|
|||||||
|
|
||||||
.shotgun: &shotgun_job
|
.shotgun: &shotgun_job
|
||||||
<<: *base_image
|
<<: *base_image
|
||||||
|
<<: *api_pipelines_schedules_tags_triggers_web_triggering_rules
|
||||||
stage: performance
|
stage: performance
|
||||||
rules:
|
|
||||||
- &shotgun_rule_mr
|
|
||||||
if: '$CI_MERGE_REQUEST_DIFF_BASE_SHA != null'
|
|
||||||
variables:
|
|
||||||
BASELINE: '$CI_MERGE_REQUEST_DIFF_BASE_SHA'
|
|
||||||
- &shotgun_rule_tag
|
|
||||||
if: '$CI_COMMIT_TAG != null'
|
|
||||||
variables:
|
|
||||||
SHOTGUN_ROUNDS: 3
|
|
||||||
- &shotgun_rule_other
|
|
||||||
if: '$CI_PIPELINE_SOURCE =~ /^(api|pipeline|schedule|trigger|web)$/'
|
|
||||||
# when using data from a single run, the overall instability of the results
|
|
||||||
# causes quite high false positive rate, rerun the test to attemp to reduce those
|
|
||||||
retry: 1
|
|
||||||
script:
|
script:
|
||||||
- if [ -z "$BASELINE" ]; then export BASELINE=$BIND_BASELINE_VERSION; fi # this dotenv variable can't be set in the rules section, because rules are evaluated before any jobs run
|
- if [ -z "$CI_COMMIT_TAG" ]; then export SHOTGUN_ROUNDS=1; else export SHOTGUN_ROUNDS=3; fi
|
||||||
- PIPELINE_ID=$(curl -s -X POST --fail
|
- PIPELINE_ID=$(curl -s -X POST --fail
|
||||||
-F "token=$CI_JOB_TOKEN"
|
-F "token=$CI_JOB_TOKEN"
|
||||||
-F ref=main
|
-F ref=main
|
||||||
-F "variables[SHOTGUN_TEST_VERSION]=['$CI_COMMIT_REF_NAME', '$BASELINE']"
|
-F "variables[SHOTGUN_TEST_VERSION]=['$CI_COMMIT_REF_NAME', '$BIND_BASELINE_VERSION']"
|
||||||
-F "variables[SHOTGUN_DURATION]=300"
|
-F "variables[SHOTGUN_DURATION]=300"
|
||||||
-F "variables[SHOTGUN_ROUNDS]=$SHOTGUN_ROUNDS"
|
-F "variables[SHOTGUN_ROUNDS]=$SHOTGUN_ROUNDS"
|
||||||
-F "variables[SHOTGUN_TRAFFIC_MULTIPLIER]=$SHOTGUN_TRAFFIC_MULTIPLIER"
|
-F "variables[SHOTGUN_TRAFFIC_MULTIPLIER]=$SHOTGUN_TRAFFIC_MULTIPLIER"
|
||||||
-F "variables[SHOTGUN_SCENARIO]=$SHOTGUN_SCENARIO"
|
-F "variables[SHOTGUN_SCENARIO]=$SHOTGUN_SCENARIO"
|
||||||
-F "variables[SHOTGUN_EVAL_THRESHOLD_CPU_MIN]=$SHOTGUN_EVAL_THRESHOLD_CPU_MIN"
|
|
||||||
-F "variables[SHOTGUN_EVAL_THRESHOLD_CPU_MAX]=$SHOTGUN_EVAL_THRESHOLD_CPU_MAX"
|
|
||||||
-F "variables[SHOTGUN_EVAL_THRESHOLD_MEMORY_MIN]=$SHOTGUN_EVAL_THRESHOLD_MEMORY_MIN"
|
|
||||||
-F "variables[SHOTGUN_EVAL_THRESHOLD_MEMORY_MAX]=$SHOTGUN_EVAL_THRESHOLD_MEMORY_MAX"
|
|
||||||
-F "variables[SHOTGUN_EVAL_THRESHOLD_RCODE_MIN]=$SHOTGUN_EVAL_THRESHOLD_RCODE_MIN"
|
|
||||||
-F "variables[SHOTGUN_EVAL_THRESHOLD_RCODE_MAX]=$SHOTGUN_EVAL_THRESHOLD_RCODE_MAX"
|
|
||||||
-F "variables[SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_MIN]=$SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_MIN"
|
|
||||||
-F "variables[SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_MAX]=$SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_MAX"
|
|
||||||
-F "variables[SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_DRIFT_MIN]=$SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_DRIFT_MIN"
|
|
||||||
-F "variables[SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_DRIFT_MAX]=$SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_DRIFT_MAX"
|
|
||||||
https://gitlab.isc.org/api/v4/projects/188/trigger/pipeline | jq .id)
|
https://gitlab.isc.org/api/v4/projects/188/trigger/pipeline | jq .id)
|
||||||
- util/ci-wait-shotgun.py $PIPELINE_ID
|
- util/ci-wait-shotgun.py $PIPELINE_ID
|
||||||
needs:
|
needs:
|
||||||
@@ -562,8 +511,6 @@ misc:
|
|||||||
- if git grep SYSTEMTESTTOP -- ':!.gitlab-ci.yml'; then echo 'Please use relative paths instead of $SYSTEMTESTTOP.'; exit 1; fi
|
- if git grep SYSTEMTESTTOP -- ':!.gitlab-ci.yml'; then echo 'Please use relative paths instead of $SYSTEMTESTTOP.'; exit 1; fi
|
||||||
- bash util/unused-headers.sh
|
- bash util/unused-headers.sh
|
||||||
- bash util/xmllint-html.sh
|
- bash util/xmllint-html.sh
|
||||||
# Check dangling symlinks in the repository
|
|
||||||
- if find . -xtype l | grep .; then exit 1; fi
|
|
||||||
needs: []
|
needs: []
|
||||||
artifacts:
|
artifacts:
|
||||||
paths:
|
paths:
|
||||||
@@ -587,7 +534,7 @@ vulture:
|
|||||||
<<: *precheck_job
|
<<: *precheck_job
|
||||||
needs: []
|
needs: []
|
||||||
script:
|
script:
|
||||||
- vulture --exclude "*ans.py,conftest.py,isctest" --ignore-names "pytestmark" bin/tests/system/
|
- vulture --exclude "*/ans*/ans.py,conftest.py,isctest" --ignore-names "pytestmark" bin/tests/system/
|
||||||
|
|
||||||
ci-variables:
|
ci-variables:
|
||||||
stage: precheck
|
stage: precheck
|
||||||
@@ -672,8 +619,9 @@ danger:
|
|||||||
script:
|
script:
|
||||||
- pip install git+https://gitlab.isc.org/isc-projects/hazard.git
|
- pip install git+https://gitlab.isc.org/isc-projects/hazard.git
|
||||||
- hazard
|
- hazard
|
||||||
rules:
|
only:
|
||||||
- if: '$CI_PIPELINE_SOURCE == "merge_request_event"'
|
refs:
|
||||||
|
- merge_requests
|
||||||
|
|
||||||
checkbashisms:
|
checkbashisms:
|
||||||
<<: *precheck_job
|
<<: *precheck_job
|
||||||
@@ -1341,7 +1289,7 @@ gcc:tsan:
|
|||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Wno-stringop-overread -ggdb -O2 -fsanitize=thread"
|
CFLAGS: "${CFLAGS_COMMON} -Wno-stringop-overread -ggdb -O2 -fsanitize=thread"
|
||||||
LDFLAGS: "-fsanitize=thread -Wl,--disable-new-dtags"
|
LDFLAGS: "-fsanitize=thread"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig"
|
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig"
|
||||||
<<: *tsan_fedora_41_amd64_image
|
<<: *tsan_fedora_41_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -1370,8 +1318,7 @@ clang:tsan:
|
|||||||
variables:
|
variables:
|
||||||
CC: "${CLANG}"
|
CC: "${CLANG}"
|
||||||
CFLAGS: "${CFLAGS_COMMON} -ggdb -O2 -fsanitize=thread"
|
CFLAGS: "${CFLAGS_COMMON} -ggdb -O2 -fsanitize=thread"
|
||||||
# -Wl,--disable-new-dtags ensures that Clang creates valid TSAN reports
|
LDFLAGS: "-fsanitize=thread"
|
||||||
LDFLAGS: "-fsanitize=thread -Wl,--disable-new-dtags"
|
|
||||||
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig"
|
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig"
|
||||||
|
|
||||||
system:clang:tsan:
|
system:clang:tsan:
|
||||||
@@ -1450,19 +1397,27 @@ unit:clang:bookworm:amd64:
|
|||||||
# Jobs for Clang builds on FreeBSD 13 (amd64)
|
# Jobs for Clang builds on FreeBSD 13 (amd64)
|
||||||
|
|
||||||
clang:freebsd13:amd64:
|
clang:freebsd13:amd64:
|
||||||
|
variables:
|
||||||
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
|
# Use MIT Kerberos5 for BIND 9 GSS-API support because of FreeBSD Heimdal
|
||||||
|
# incompatibility; see https://bugs.freebsd.org/275241.
|
||||||
|
EXTRA_CONFIGURE: "${WITH_READLINE_LIBEDIT} --with-gssapi=/usr/local/bin/krb5-config"
|
||||||
|
USER: gitlab-runner
|
||||||
|
<<: *freebsd_13_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
<<: *freebsd_autoscaler_13_amd64
|
|
||||||
|
|
||||||
system:clang:freebsd13:amd64:
|
system:clang:freebsd13:amd64:
|
||||||
|
<<: *freebsd_13_amd64_image
|
||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
<<: *freebsd_autoscaler_13_amd64
|
variables:
|
||||||
|
USER: gitlab-runner
|
||||||
needs:
|
needs:
|
||||||
- job: clang:freebsd13:amd64
|
- job: clang:freebsd13:amd64
|
||||||
artifacts: true
|
artifacts: true
|
||||||
|
|
||||||
unit:clang:freebsd13:amd64:
|
unit:clang:freebsd13:amd64:
|
||||||
|
<<: *freebsd_13_amd64_image
|
||||||
<<: *unit_test_job
|
<<: *unit_test_job
|
||||||
<<: *freebsd_autoscaler_13_amd64
|
|
||||||
needs:
|
needs:
|
||||||
- job: clang:freebsd13:amd64
|
- job: clang:freebsd13:amd64
|
||||||
artifacts: true
|
artifacts: true
|
||||||
@@ -1470,19 +1425,27 @@ unit:clang:freebsd13:amd64:
|
|||||||
# Jobs for Clang builds on FreeBSD 14 (amd64)
|
# Jobs for Clang builds on FreeBSD 14 (amd64)
|
||||||
|
|
||||||
clang:freebsd14:amd64:
|
clang:freebsd14:amd64:
|
||||||
|
variables:
|
||||||
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
|
# Use MIT Kerberos5 for BIND 9 GSS-API support because of FreeBSD Heimdal
|
||||||
|
# incompatibility; see https://bugs.freebsd.org/275241.
|
||||||
|
EXTRA_CONFIGURE: "${WITH_READLINE_EDITLINE} --with-gssapi=/usr/local/bin/krb5-config"
|
||||||
|
USER: gitlab-runner
|
||||||
|
<<: *freebsd_14_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
<<: *freebsd_autoscaler_14_amd64
|
|
||||||
|
|
||||||
system:clang:freebsd14:amd64:
|
system:clang:freebsd14:amd64:
|
||||||
|
<<: *freebsd_14_amd64_image
|
||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
<<: *freebsd_autoscaler_14_amd64
|
variables:
|
||||||
|
USER: gitlab-runner
|
||||||
needs:
|
needs:
|
||||||
- job: clang:freebsd14:amd64
|
- job: clang:freebsd14:amd64
|
||||||
artifacts: true
|
artifacts: true
|
||||||
|
|
||||||
unit:clang:freebsd14:amd64:
|
unit:clang:freebsd14:amd64:
|
||||||
|
<<: *freebsd_14_amd64_image
|
||||||
<<: *unit_test_job
|
<<: *unit_test_job
|
||||||
<<: *freebsd_autoscaler_14_amd64
|
|
||||||
needs:
|
needs:
|
||||||
- job: clang:freebsd14:amd64
|
- job: clang:freebsd14:amd64
|
||||||
artifacts: true
|
artifacts: true
|
||||||
@@ -1531,8 +1494,8 @@ release:
|
|||||||
artifacts: true
|
artifacts: true
|
||||||
- job: docs
|
- job: docs
|
||||||
artifacts: true
|
artifacts: true
|
||||||
rules:
|
only:
|
||||||
- if: '$CI_COMMIT_TAG != null'
|
- tags
|
||||||
artifacts:
|
artifacts:
|
||||||
paths:
|
paths:
|
||||||
- "*-release"
|
- "*-release"
|
||||||
@@ -1575,8 +1538,8 @@ sign:
|
|||||||
needs:
|
needs:
|
||||||
- job: release
|
- job: release
|
||||||
artifacts: true
|
artifacts: true
|
||||||
rules:
|
only:
|
||||||
- if: '$CI_COMMIT_TAG != null'
|
- tags
|
||||||
when: manual
|
when: manual
|
||||||
allow_failure: false
|
allow_failure: false
|
||||||
|
|
||||||
@@ -1628,8 +1591,10 @@ coverity:
|
|||||||
- cov-int.tar.gz
|
- cov-int.tar.gz
|
||||||
expire_in: "1 week"
|
expire_in: "1 week"
|
||||||
when: on_failure
|
when: on_failure
|
||||||
rules:
|
only:
|
||||||
- if: '$COVERITY_SCAN_PROJECT_NAME != null && $COVERITY_SCAN_TOKEN != null'
|
variables:
|
||||||
|
- $COVERITY_SCAN_PROJECT_NAME
|
||||||
|
- $COVERITY_SCAN_TOKEN
|
||||||
|
|
||||||
# Respdiff tests
|
# Respdiff tests
|
||||||
|
|
||||||
@@ -1664,9 +1629,9 @@ respdiff:tsan:
|
|||||||
<<: *default_triggering_rules
|
<<: *default_triggering_rules
|
||||||
<<: *tsan_debian_bookworm_amd64_image
|
<<: *tsan_debian_bookworm_amd64_image
|
||||||
variables:
|
variables:
|
||||||
CC: "${CLANG}"
|
CC: gcc
|
||||||
CFLAGS: "${CFLAGS_COMMON} -ggdb -O2 -fsanitize=thread"
|
CFLAGS: "${CFLAGS_COMMON} -Og -fsanitize=thread"
|
||||||
LDFLAGS: "-fsanitize=thread -Wl,--disable-new-dtags"
|
LDFLAGS: "-fsanitize=thread"
|
||||||
EXTRA_CONFIGURE: "--enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig"
|
EXTRA_CONFIGURE: "--enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig"
|
||||||
MAX_DISAGREEMENTS_PERCENTAGE: "0.15"
|
MAX_DISAGREEMENTS_PERCENTAGE: "0.15"
|
||||||
TSAN_OPTIONS: "${TSAN_OPTIONS_DEBIAN}"
|
TSAN_OPTIONS: "${TSAN_OPTIONS_DEBIAN}"
|
||||||
@@ -1691,6 +1656,9 @@ respdiff-third-party:
|
|||||||
|
|
||||||
# Performance tests
|
# Performance tests
|
||||||
|
|
||||||
|
# Run shotgun:udp right away, but delay other shotgun jobs sligthly in order to
|
||||||
|
# allow re-use of the built container image. Otherwise, the jobs would do the
|
||||||
|
# same builds in parallel rather than re-use the already built image.
|
||||||
shotgun:udp:
|
shotgun:udp:
|
||||||
<<: *shotgun_job
|
<<: *shotgun_job
|
||||||
variables:
|
variables:
|
||||||
@@ -1701,29 +1669,25 @@ shotgun:tcp:
|
|||||||
<<: *shotgun_job
|
<<: *shotgun_job
|
||||||
variables:
|
variables:
|
||||||
SHOTGUN_SCENARIO: tcp
|
SHOTGUN_SCENARIO: tcp
|
||||||
SHOTGUN_TRAFFIC_MULTIPLIER: 12
|
SHOTGUN_TRAFFIC_MULTIPLIER: 13
|
||||||
|
when: delayed
|
||||||
|
start_in: 5 minutes
|
||||||
|
|
||||||
shotgun:dot:
|
shotgun:dot:
|
||||||
<<: *shotgun_job
|
<<: *shotgun_job
|
||||||
variables:
|
variables:
|
||||||
SHOTGUN_SCENARIO: dot
|
SHOTGUN_SCENARIO: dot
|
||||||
SHOTGUN_TRAFFIC_MULTIPLIER: 6
|
SHOTGUN_TRAFFIC_MULTIPLIER: 6
|
||||||
rules: &shotgun_rules_manual_mr
|
when: delayed
|
||||||
- if: '$CI_MERGE_REQUEST_DIFF_BASE_SHA != null'
|
start_in: 5 minutes
|
||||||
variables:
|
|
||||||
BASELINE: '$CI_MERGE_REQUEST_DIFF_BASE_SHA'
|
|
||||||
when: manual # don't run on each MR unless requested
|
|
||||||
allow_failure: true
|
|
||||||
- *shotgun_rule_tag
|
|
||||||
- *shotgun_rule_other
|
|
||||||
|
|
||||||
shotgun:doh-get:
|
shotgun:doh-get:
|
||||||
<<: *shotgun_job
|
<<: *shotgun_job
|
||||||
variables:
|
variables:
|
||||||
SHOTGUN_SCENARIO: doh-get
|
SHOTGUN_SCENARIO: doh-get
|
||||||
SHOTGUN_TRAFFIC_MULTIPLIER: 3
|
SHOTGUN_TRAFFIC_MULTIPLIER: 3
|
||||||
SHOTGUN_EVAL_THRESHOLD_LATENCY_PCTL_MAX: 0.4 # bump from the default due to increased tail-end jitter
|
when: delayed
|
||||||
rules: *shotgun_rules_manual_mr
|
start_in: 5 minutes
|
||||||
|
|
||||||
.stress-test: &stress_test
|
.stress-test: &stress_test
|
||||||
stage: performance
|
stage: performance
|
||||||
@@ -1762,8 +1726,8 @@ fsck:
|
|||||||
- git clone https://gitlab.isc.org/isc-projects/bind9.git bind9-full-clone
|
- git clone https://gitlab.isc.org/isc-projects/bind9.git bind9-full-clone
|
||||||
- cd bind9-full-clone/
|
- cd bind9-full-clone/
|
||||||
- git fsck
|
- git fsck
|
||||||
rules:
|
only:
|
||||||
- if: '$CI_PIPELINE_SOURCE == "schedule"'
|
- schedules
|
||||||
needs: []
|
needs: []
|
||||||
|
|
||||||
gcov:
|
gcov:
|
||||||
@@ -1815,8 +1779,9 @@ pairwise:
|
|||||||
- pairwise-model.txt
|
- pairwise-model.txt
|
||||||
- pairwise-output.*.txt
|
- pairwise-output.*.txt
|
||||||
when: on_failure
|
when: on_failure
|
||||||
rules:
|
only:
|
||||||
- if: '$PAIRWISE_TESTING != null'
|
variables:
|
||||||
|
- $PAIRWISE_TESTING
|
||||||
|
|
||||||
.post_merge_template: &post_merge
|
.post_merge_template: &post_merge
|
||||||
<<: *base_image
|
<<: *base_image
|
||||||
|
|||||||
@@ -761,7 +761,7 @@ cleanup:
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (mctx != NULL) {
|
if (mctx != NULL) {
|
||||||
isc_mem_detach(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
}
|
}
|
||||||
|
|
||||||
return result == ISC_R_SUCCESS ? 0 : 1;
|
return result == ISC_R_SUCCESS ? 0 : 1;
|
||||||
|
|||||||
@@ -577,7 +577,7 @@ main(int argc, char **argv) {
|
|||||||
fprintf(errout, "OK\n");
|
fprintf(errout, "OK\n");
|
||||||
}
|
}
|
||||||
destroy();
|
destroy();
|
||||||
isc_mem_detach(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|
||||||
return (result == ISC_R_SUCCESS) ? 0 : 1;
|
return (result == ISC_R_SUCCESS) ? 0 : 1;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -290,7 +290,7 @@ options {\n\
|
|||||||
isc_mem_stats(mctx, stderr);
|
isc_mem_stats(mctx, stderr);
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_mem_detach(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -296,7 +296,7 @@ nsupdate -k <keyfile>\n");
|
|||||||
isc_mem_stats(mctx, stderr);
|
isc_mem_stats(mctx, stderr);
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_mem_detach(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|||||||
+36
-2
@@ -26,12 +26,16 @@
|
|||||||
#include <unistd.h>
|
#include <unistd.h>
|
||||||
|
|
||||||
#include <openssl/opensslv.h>
|
#include <openssl/opensslv.h>
|
||||||
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
#include <openssl/err.h>
|
||||||
|
#include <openssl/provider.h>
|
||||||
|
#endif
|
||||||
|
|
||||||
#include <isc/async.h>
|
#include <isc/async.h>
|
||||||
#include <isc/attributes.h>
|
#include <isc/attributes.h>
|
||||||
#include <isc/base64.h>
|
#include <isc/base64.h>
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/crypto.h>
|
#include <isc/fips.h>
|
||||||
#include <isc/hex.h>
|
#include <isc/hex.h>
|
||||||
#include <isc/lib.h>
|
#include <isc/lib.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
@@ -163,6 +167,10 @@ static dns_fixedname_t qfn;
|
|||||||
/* Default trust anchors */
|
/* Default trust anchors */
|
||||||
static char anchortext[] = TRUST_ANCHORS;
|
static char anchortext[] = TRUST_ANCHORS;
|
||||||
|
|
||||||
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
static OSSL_PROVIDER *fips = NULL, *base = NULL;
|
||||||
|
#endif
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Static function prototypes
|
* Static function prototypes
|
||||||
*/
|
*/
|
||||||
@@ -1611,7 +1619,24 @@ preparse_args(int argc, char **argv) {
|
|||||||
while (strpbrk(option, single_dash_opts) == &option[0]) {
|
while (strpbrk(option, single_dash_opts) == &option[0]) {
|
||||||
switch (option[0]) {
|
switch (option[0]) {
|
||||||
case 'F':
|
case 'F':
|
||||||
if (isc_crypto_fips_enable() != ISC_R_SUCCESS) {
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
fips = OSSL_PROVIDER_load(NULL, "fips");
|
||||||
|
if (fips == NULL) {
|
||||||
|
ERR_clear_error();
|
||||||
|
fatal("Failed to load FIPS provider");
|
||||||
|
}
|
||||||
|
base = OSSL_PROVIDER_load(NULL, "base");
|
||||||
|
if (base == NULL) {
|
||||||
|
OSSL_PROVIDER_unload(fips);
|
||||||
|
ERR_clear_error();
|
||||||
|
fatal("Failed to load base provider");
|
||||||
|
}
|
||||||
|
#endif
|
||||||
|
/* Already in FIPS mode? */
|
||||||
|
if (isc_fips_mode()) {
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
if (isc_fips_set_mode(1) != ISC_R_SUCCESS) {
|
||||||
fatal("setting FIPS mode failed");
|
fatal("setting FIPS mode failed");
|
||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
@@ -2284,5 +2309,14 @@ cleanup:
|
|||||||
|
|
||||||
isc_managers_destroy(&mctx, &loopmgr, &netmgr);
|
isc_managers_destroy(&mctx, &loopmgr, &netmgr);
|
||||||
|
|
||||||
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
if (base != NULL) {
|
||||||
|
OSSL_PROVIDER_unload(base);
|
||||||
|
}
|
||||||
|
if (fips != NULL) {
|
||||||
|
OSSL_PROVIDER_unload(fips);
|
||||||
|
}
|
||||||
|
#endif
|
||||||
|
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|||||||
+38
-18
@@ -20,8 +20,8 @@
|
|||||||
#include <time.h>
|
#include <time.h>
|
||||||
|
|
||||||
#include <isc/attributes.h>
|
#include <isc/attributes.h>
|
||||||
#include <isc/crypto.h>
|
|
||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
|
#include <isc/fips.h>
|
||||||
#include <isc/lib.h>
|
#include <isc/lib.h>
|
||||||
#include <isc/loop.h>
|
#include <isc/loop.h>
|
||||||
#include <isc/netaddr.h>
|
#include <isc/netaddr.h>
|
||||||
@@ -73,6 +73,14 @@ static bool short_form = false, printcmd = true, plusquest = false,
|
|||||||
static uint32_t splitwidth = 0xffffffff;
|
static uint32_t splitwidth = 0xffffffff;
|
||||||
|
|
||||||
#include <openssl/opensslv.h>
|
#include <openssl/opensslv.h>
|
||||||
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
#include <openssl/err.h>
|
||||||
|
#include <openssl/provider.h>
|
||||||
|
#endif
|
||||||
|
|
||||||
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
static OSSL_PROVIDER *fips = NULL, *base = NULL;
|
||||||
|
#endif
|
||||||
|
|
||||||
/*% opcode text */
|
/*% opcode text */
|
||||||
static const char *const opcodetext[] = {
|
static const char *const opcodetext[] = {
|
||||||
@@ -289,7 +297,6 @@ help(void) {
|
|||||||
" form of answers - global "
|
" form of answers - global "
|
||||||
"option)\n"
|
"option)\n"
|
||||||
" +[no]showbadcookie (Show BADCOOKIE message)\n"
|
" +[no]showbadcookie (Show BADCOOKIE message)\n"
|
||||||
" +[no]showbadvers (Show BADVERS message)\n"
|
|
||||||
" +[no]showsearch (Search with intermediate "
|
" +[no]showsearch (Search with intermediate "
|
||||||
"results)\n"
|
"results)\n"
|
||||||
" +[no]split=## (Split hex/base64 fields "
|
" +[no]split=## (Split hex/base64 fields "
|
||||||
@@ -1773,8 +1780,6 @@ plus_option(char *option, bool is_batchfile, bool *need_clone,
|
|||||||
FULLCHECK("edns");
|
FULLCHECK("edns");
|
||||||
if (!state) {
|
if (!state) {
|
||||||
lookup->edns = -1;
|
lookup->edns = -1;
|
||||||
lookup->original_edns =
|
|
||||||
-1;
|
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
if (value == NULL) {
|
if (value == NULL) {
|
||||||
@@ -1791,7 +1796,6 @@ plus_option(char *option, bool is_batchfile, bool *need_clone,
|
|||||||
goto exit_or_usage;
|
goto exit_or_usage;
|
||||||
}
|
}
|
||||||
lookup->edns = num;
|
lookup->edns = num;
|
||||||
lookup->original_edns = num;
|
|
||||||
break;
|
break;
|
||||||
case 'f':
|
case 'f':
|
||||||
FULLCHECK("ednsflags");
|
FULLCHECK("ednsflags");
|
||||||
@@ -2310,18 +2314,8 @@ plus_option(char *option, bool is_batchfile, bool *need_clone,
|
|||||||
case 'w': /* showsearch */
|
case 'w': /* showsearch */
|
||||||
switch (cmd[4]) {
|
switch (cmd[4]) {
|
||||||
case 'b':
|
case 'b':
|
||||||
switch (cmd[7]) {
|
FULLCHECK("showbadcookie");
|
||||||
case 'c':
|
lookup->showbadcookie = state;
|
||||||
FULLCHECK("showbadcookie");
|
|
||||||
lookup->showbadcookie = state;
|
|
||||||
break;
|
|
||||||
case 'v':
|
|
||||||
FULLCHECK("showbadvers");
|
|
||||||
lookup->showbadvers = state;
|
|
||||||
break;
|
|
||||||
default:
|
|
||||||
goto invalid_option;
|
|
||||||
}
|
|
||||||
break;
|
break;
|
||||||
case 's':
|
case 's':
|
||||||
FULLCHECK("showsearch");
|
FULLCHECK("showsearch");
|
||||||
@@ -2937,7 +2931,24 @@ preparse_args(int argc, char **argv) {
|
|||||||
debugging = true;
|
debugging = true;
|
||||||
break;
|
break;
|
||||||
case 'F':
|
case 'F':
|
||||||
if (isc_crypto_fips_enable() != ISC_R_SUCCESS) {
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
fips = OSSL_PROVIDER_load(NULL, "fips");
|
||||||
|
if (fips == NULL) {
|
||||||
|
ERR_clear_error();
|
||||||
|
fatal("Failed to load FIPS provider");
|
||||||
|
}
|
||||||
|
base = OSSL_PROVIDER_load(NULL, "base");
|
||||||
|
if (base == NULL) {
|
||||||
|
OSSL_PROVIDER_unload(fips);
|
||||||
|
ERR_clear_error();
|
||||||
|
fatal("Failed to load base provider");
|
||||||
|
}
|
||||||
|
#endif
|
||||||
|
/* Already in FIPS mode? */
|
||||||
|
if (isc_fips_mode()) {
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
if (isc_fips_set_mode(1) != ISC_R_SUCCESS) {
|
||||||
fatal("setting FIPS mode failed");
|
fatal("setting FIPS mode failed");
|
||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
@@ -3465,5 +3476,14 @@ main(int argc, char **argv) {
|
|||||||
dig_startup();
|
dig_startup();
|
||||||
dig_shutdown();
|
dig_shutdown();
|
||||||
|
|
||||||
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
if (base != NULL) {
|
||||||
|
OSSL_PROVIDER_unload(base);
|
||||||
|
}
|
||||||
|
if (fips != NULL) {
|
||||||
|
OSSL_PROVIDER_unload(fips);
|
||||||
|
}
|
||||||
|
#endif
|
||||||
|
|
||||||
return exitcode;
|
return exitcode;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -614,12 +614,6 @@ abbreviation is unambiguous; for example, :option:`+cd` is equivalent to
|
|||||||
BADCOOKIE rcode before retrying the request or not. The default
|
BADCOOKIE rcode before retrying the request or not. The default
|
||||||
is to not show the messages.
|
is to not show the messages.
|
||||||
|
|
||||||
.. option:: +showbadvers, +noshowbadvers
|
|
||||||
|
|
||||||
This option toggles whether to show the message containing the
|
|
||||||
BADVERS rcode before retrying the request or not. The default
|
|
||||||
is to not show the messages.
|
|
||||||
|
|
||||||
.. option:: +showsearch, +noshowsearch
|
.. option:: +showsearch, +noshowsearch
|
||||||
|
|
||||||
This option performs [or does not perform] a search showing intermediate results.
|
This option performs [or does not perform] a search showing intermediate results.
|
||||||
|
|||||||
+1
-11
@@ -605,7 +605,6 @@ make_empty_lookup(void) {
|
|||||||
.idnout = idnout,
|
.idnout = idnout,
|
||||||
.udpsize = -1,
|
.udpsize = -1,
|
||||||
.edns = -1,
|
.edns = -1,
|
||||||
.original_edns = -1,
|
|
||||||
.recurse = true,
|
.recurse = true,
|
||||||
.retries = tries,
|
.retries = tries,
|
||||||
.comments = true,
|
.comments = true,
|
||||||
@@ -739,7 +738,6 @@ clone_lookup(dig_lookup_t *lookold, bool servers) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
looknew->showbadcookie = lookold->showbadcookie;
|
looknew->showbadcookie = lookold->showbadcookie;
|
||||||
looknew->showbadvers = lookold->showbadvers;
|
|
||||||
looknew->sendcookie = lookold->sendcookie;
|
looknew->sendcookie = lookold->sendcookie;
|
||||||
looknew->seenbadcookie = lookold->seenbadcookie;
|
looknew->seenbadcookie = lookold->seenbadcookie;
|
||||||
looknew->badcookie = lookold->badcookie;
|
looknew->badcookie = lookold->badcookie;
|
||||||
@@ -766,7 +764,6 @@ clone_lookup(dig_lookup_t *lookold, bool servers) {
|
|||||||
looknew->idnout = lookold->idnout;
|
looknew->idnout = lookold->idnout;
|
||||||
looknew->udpsize = lookold->udpsize;
|
looknew->udpsize = lookold->udpsize;
|
||||||
looknew->edns = lookold->edns;
|
looknew->edns = lookold->edns;
|
||||||
looknew->original_edns = lookold->original_edns;
|
|
||||||
looknew->recurse = lookold->recurse;
|
looknew->recurse = lookold->recurse;
|
||||||
looknew->aaonly = lookold->aaonly;
|
looknew->aaonly = lookold->aaonly;
|
||||||
looknew->adflag = lookold->adflag;
|
looknew->adflag = lookold->adflag;
|
||||||
@@ -1941,7 +1938,6 @@ followup_lookup(dns_message_t *msg, dig_query_t *query, dns_section_t section) {
|
|||||||
}
|
}
|
||||||
domain = dns_fixedname_name(&lookup->fdomain);
|
domain = dns_fixedname_name(&lookup->fdomain);
|
||||||
dns_name_copy(name, domain);
|
dns_name_copy(name, domain);
|
||||||
lookup->edns = lookup->original_edns;
|
|
||||||
}
|
}
|
||||||
debug("adding server %s", namestr);
|
debug("adding server %s", namestr);
|
||||||
num = getaddresses(lookup, namestr, &lresult);
|
num = getaddresses(lookup, namestr, &lresult);
|
||||||
@@ -2460,8 +2456,7 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
lookup->udpsize = DEFAULT_EDNS_BUFSIZE;
|
lookup->udpsize = DEFAULT_EDNS_BUFSIZE;
|
||||||
}
|
}
|
||||||
if (lookup->edns < 0) {
|
if (lookup->edns < 0) {
|
||||||
lookup->original_edns = lookup->edns =
|
lookup->edns = DEFAULT_EDNS_VERSION;
|
||||||
DEFAULT_EDNS_VERSION;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (lookup->nsid) {
|
if (lookup->nsid) {
|
||||||
@@ -4305,11 +4300,6 @@ recv_done(isc_nmhandle_t *handle, isc_result_t eresult, isc_region_t *region,
|
|||||||
if (msg->rcode == dns_rcode_badvers && msg->opt != NULL &&
|
if (msg->rcode == dns_rcode_badvers && msg->opt != NULL &&
|
||||||
(newedns = ednsvers(msg->opt)) < l->edns && l->ednsneg)
|
(newedns = ednsvers(msg->opt)) < l->edns && l->ednsneg)
|
||||||
{
|
{
|
||||||
if (l->showbadvers) {
|
|
||||||
dighost_printmessage(query, &b, msg, true);
|
|
||||||
dighost_received(isc_buffer_usedlength(&b), &peer,
|
|
||||||
query);
|
|
||||||
}
|
|
||||||
/*
|
/*
|
||||||
* Add minimum EDNS version required checks here if needed.
|
* Add minimum EDNS version required checks here if needed.
|
||||||
*/
|
*/
|
||||||
|
|||||||
+3
-4
@@ -117,9 +117,9 @@ struct dig_lookup {
|
|||||||
section_answer, section_authority, section_question,
|
section_answer, section_authority, section_question,
|
||||||
seenbadcookie, sendcookie, servfail_stops,
|
seenbadcookie, sendcookie, servfail_stops,
|
||||||
setqid, /*% use a speciied query ID */
|
setqid, /*% use a speciied query ID */
|
||||||
showbadcookie, showbadvers, stats, tcflag, tcp_keepalive,
|
showbadcookie, stats, tcflag, tcp_keepalive, tcp_mode,
|
||||||
tcp_mode, tcp_mode_set, tls_mode, /*% connect using TLS */
|
tcp_mode_set, tls_mode, /*% connect using TLS */
|
||||||
trace, /*% dig +trace */
|
trace, /*% dig +trace */
|
||||||
trace_root, /*% initial query for either +trace or +nssearch */
|
trace_root, /*% initial query for either +trace or +nssearch */
|
||||||
ttlunits, use_usec, waiting_connect, zflag;
|
ttlunits, use_usec, waiting_connect, zflag;
|
||||||
char textname[MXNAME]; /*% Name we're going to be looking up */
|
char textname[MXNAME]; /*% Name we're going to be looking up */
|
||||||
@@ -148,7 +148,6 @@ struct dig_lookup {
|
|||||||
int nsfound;
|
int nsfound;
|
||||||
int16_t udpsize;
|
int16_t udpsize;
|
||||||
int16_t edns;
|
int16_t edns;
|
||||||
int16_t original_edns;
|
|
||||||
int16_t padding;
|
int16_t padding;
|
||||||
uint32_t ixfr_serial;
|
uint32_t ixfr_serial;
|
||||||
isc_buffer_t rdatabuf;
|
isc_buffer_t rdatabuf;
|
||||||
|
|||||||
+2
-1
@@ -246,7 +246,8 @@ printsection(dns_message_t *msg, dns_section_t sectionid,
|
|||||||
(list_type == dns_rdatatype_any ||
|
(list_type == dns_rdatatype_any ||
|
||||||
rdataset->type == list_type)) ||
|
rdataset->type == list_type)) ||
|
||||||
(list_addresses &&
|
(list_addresses &&
|
||||||
(dns_rdatatype_isaddr(rdataset->type) ||
|
(rdataset->type == dns_rdatatype_a ||
|
||||||
|
rdataset->type == dns_rdatatype_aaaa ||
|
||||||
rdataset->type == dns_rdatatype_ns ||
|
rdataset->type == dns_rdatatype_ns ||
|
||||||
rdataset->type == dns_rdatatype_ptr))))
|
rdataset->type == dns_rdatatype_ptr))))
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -20,6 +20,7 @@
|
|||||||
#include <isc/attributes.h>
|
#include <isc/attributes.h>
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
|
#include <isc/condition.h>
|
||||||
#include <isc/lib.h>
|
#include <isc/lib.h>
|
||||||
#include <isc/loop.h>
|
#include <isc/loop.h>
|
||||||
#include <isc/netaddr.h>
|
#include <isc/netaddr.h>
|
||||||
|
|||||||
@@ -41,14 +41,6 @@ dnssec_keygen_LDADD = \
|
|||||||
$(LDADD) \
|
$(LDADD) \
|
||||||
$(OPENSSL_LIBS)
|
$(OPENSSL_LIBS)
|
||||||
|
|
||||||
dnssec_ksr_CPPFLAGS= \
|
|
||||||
$(AM_CPPFLAGS) \
|
|
||||||
$(OPENSSL_CFLAGS)
|
|
||||||
|
|
||||||
dnssec_ksr_LDADD = \
|
|
||||||
$(LDADD) \
|
|
||||||
$(OPENSSL_LIBS)
|
|
||||||
|
|
||||||
dnssec_signzone_CPPFLAGS = \
|
dnssec_signzone_CPPFLAGS = \
|
||||||
$(AM_CPPFLAGS) \
|
$(AM_CPPFLAGS) \
|
||||||
$(OPENSSL_CFLAGS)
|
$(OPENSSL_CFLAGS)
|
||||||
|
|||||||
@@ -1075,7 +1075,7 @@ cleanup(void) {
|
|||||||
if (print_mem_stats && verbose > 10) {
|
if (print_mem_stats && verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
isc_mem_detach(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -543,7 +543,7 @@ main(int argc, char **argv) {
|
|||||||
if (verbose > 10) {
|
if (verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
isc_mem_detach(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|
||||||
fflush(stdout);
|
fflush(stdout);
|
||||||
if (ferror(stdout)) {
|
if (ferror(stdout)) {
|
||||||
|
|||||||
@@ -456,7 +456,7 @@ main(int argc, char **argv) {
|
|||||||
if (verbose > 10) {
|
if (verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
isc_mem_detach(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|
||||||
fflush(stdout);
|
fflush(stdout);
|
||||||
if (ferror(stdout)) {
|
if (ferror(stdout)) {
|
||||||
|
|||||||
@@ -746,7 +746,7 @@ main(int argc, char **argv) {
|
|||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
isc_mem_free(mctx, label);
|
isc_mem_free(mctx, label);
|
||||||
isc_mem_detach(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|
||||||
if (freeit != NULL) {
|
if (freeit != NULL) {
|
||||||
free(freeit);
|
free(freeit);
|
||||||
|
|||||||
+47
-11
@@ -38,7 +38,7 @@
|
|||||||
#include <isc/attributes.h>
|
#include <isc/attributes.h>
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/crypto.h>
|
#include <isc/fips.h>
|
||||||
#include <isc/lib.h>
|
#include <isc/lib.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
@@ -58,6 +58,11 @@
|
|||||||
|
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
|
|
||||||
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
#include <openssl/err.h>
|
||||||
|
#include <openssl/provider.h>
|
||||||
|
#endif
|
||||||
|
|
||||||
#include "dnssectool.h"
|
#include "dnssectool.h"
|
||||||
|
|
||||||
const char *program = "dnssec-keygen";
|
const char *program = "dnssec-keygen";
|
||||||
@@ -146,7 +151,7 @@ usage(void) {
|
|||||||
fprintf(stderr, " -l <file>: configuration file with dnssec-policy "
|
fprintf(stderr, " -l <file>: configuration file with dnssec-policy "
|
||||||
"statement\n");
|
"statement\n");
|
||||||
fprintf(stderr, " -a <algorithm>:\n");
|
fprintf(stderr, " -a <algorithm>:\n");
|
||||||
if (!isc_crypto_fips_mode()) {
|
if (!isc_fips_mode()) {
|
||||||
fprintf(stderr, " RSASHA1 | NSEC3RSASHA1 |\n");
|
fprintf(stderr, " RSASHA1 | NSEC3RSASHA1 |\n");
|
||||||
}
|
}
|
||||||
fprintf(stderr, " RSASHA256 | RSASHA512 |\n");
|
fprintf(stderr, " RSASHA256 | RSASHA512 |\n");
|
||||||
@@ -154,7 +159,7 @@ usage(void) {
|
|||||||
fprintf(stderr, " ED25519 | ED448\n");
|
fprintf(stderr, " ED25519 | ED448\n");
|
||||||
fprintf(stderr, " -3: use NSEC3-capable algorithm\n");
|
fprintf(stderr, " -3: use NSEC3-capable algorithm\n");
|
||||||
fprintf(stderr, " -b <key size in bits>:\n");
|
fprintf(stderr, " -b <key size in bits>:\n");
|
||||||
if (!isc_crypto_fips_mode()) {
|
if (!isc_fips_mode()) {
|
||||||
fprintf(stderr, " RSASHA1:\t[%d..%d]\n", min_rsa,
|
fprintf(stderr, " RSASHA1:\t[%d..%d]\n", min_rsa,
|
||||||
MAX_RSA);
|
MAX_RSA);
|
||||||
fprintf(stderr, " NSEC3RSASHA1:\t[%d..%d]\n", min_rsa,
|
fprintf(stderr, " NSEC3RSASHA1:\t[%d..%d]\n", min_rsa,
|
||||||
@@ -283,7 +288,7 @@ keygen(keygen_ctx_t *ctx, isc_mem_t *mctx, int argc, char **argv) {
|
|||||||
fatal("unsupported algorithm: %s", algstr);
|
fatal("unsupported algorithm: %s", algstr);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (isc_crypto_fips_mode()) {
|
if (isc_fips_mode()) {
|
||||||
/* verify only in FIPS mode */
|
/* verify only in FIPS mode */
|
||||||
switch (ctx->alg) {
|
switch (ctx->alg) {
|
||||||
case DST_ALG_RSASHA1:
|
case DST_ALG_RSASHA1:
|
||||||
@@ -336,7 +341,7 @@ keygen(keygen_ctx_t *ctx, isc_mem_t *mctx, int argc, char **argv) {
|
|||||||
switch (ctx->alg) {
|
switch (ctx->alg) {
|
||||||
case DST_ALG_RSASHA1:
|
case DST_ALG_RSASHA1:
|
||||||
case DST_ALG_NSEC3RSASHA1:
|
case DST_ALG_NSEC3RSASHA1:
|
||||||
if (isc_crypto_fips_mode()) {
|
if (isc_fips_mode()) {
|
||||||
fatal("key size not specified (-b "
|
fatal("key size not specified (-b "
|
||||||
"option)");
|
"option)");
|
||||||
}
|
}
|
||||||
@@ -496,7 +501,7 @@ keygen(keygen_ctx_t *ctx, isc_mem_t *mctx, int argc, char **argv) {
|
|||||||
switch (ctx->alg) {
|
switch (ctx->alg) {
|
||||||
case DNS_KEYALG_RSASHA1:
|
case DNS_KEYALG_RSASHA1:
|
||||||
case DNS_KEYALG_NSEC3RSASHA1:
|
case DNS_KEYALG_NSEC3RSASHA1:
|
||||||
if (isc_crypto_fips_mode()) {
|
if (isc_fips_mode()) {
|
||||||
fatal("SHA1 based keys not supported in FIPS mode");
|
fatal("SHA1 based keys not supported in FIPS mode");
|
||||||
}
|
}
|
||||||
FALLTHROUGH;
|
FALLTHROUGH;
|
||||||
@@ -842,6 +847,10 @@ main(int argc, char **argv) {
|
|||||||
isc_textregion_t r;
|
isc_textregion_t r;
|
||||||
unsigned char c;
|
unsigned char c;
|
||||||
int ch;
|
int ch;
|
||||||
|
bool set_fips_mode = false;
|
||||||
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
OSSL_PROVIDER *fips = NULL, *base = NULL;
|
||||||
|
#endif
|
||||||
|
|
||||||
keygen_ctx_t ctx = {
|
keygen_ctx_t ctx = {
|
||||||
.options = DST_TYPE_PRIVATE | DST_TYPE_PUBLIC,
|
.options = DST_TYPE_PRIVATE | DST_TYPE_PUBLIC,
|
||||||
@@ -1100,9 +1109,7 @@ main(int argc, char **argv) {
|
|||||||
ctx.prepub = strtottl(isc_commandline_argument);
|
ctx.prepub = strtottl(isc_commandline_argument);
|
||||||
break;
|
break;
|
||||||
case 'F':
|
case 'F':
|
||||||
if (isc_crypto_fips_enable() != ISC_R_SUCCESS) {
|
set_fips_mode = true;
|
||||||
fatal("setting FIPS mode failed");
|
|
||||||
}
|
|
||||||
break;
|
break;
|
||||||
case '?':
|
case '?':
|
||||||
if (isc_commandline_option != '?') {
|
if (isc_commandline_option != '?') {
|
||||||
@@ -1129,11 +1136,32 @@ main(int argc, char **argv) {
|
|||||||
ctx.quiet = true;
|
ctx.quiet = true;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (set_fips_mode) {
|
||||||
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
fips = OSSL_PROVIDER_load(NULL, "fips");
|
||||||
|
if (fips == NULL) {
|
||||||
|
ERR_clear_error();
|
||||||
|
fatal("Failed to load FIPS provider");
|
||||||
|
}
|
||||||
|
base = OSSL_PROVIDER_load(NULL, "base");
|
||||||
|
if (base == NULL) {
|
||||||
|
OSSL_PROVIDER_unload(fips);
|
||||||
|
ERR_clear_error();
|
||||||
|
fatal("Failed to load base provider");
|
||||||
|
}
|
||||||
|
#endif
|
||||||
|
if (!isc_fips_mode()) {
|
||||||
|
if (isc_fips_set_mode(1) != ISC_R_SUCCESS) {
|
||||||
|
fatal("setting FIPS mode failed");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* The DST subsystem will set FIPS mode if requested at build time.
|
* The DST subsystem will set FIPS mode if requested at build time.
|
||||||
* The minimum sizes are both raised to 2048.
|
* The minimum sizes are both raised to 2048.
|
||||||
*/
|
*/
|
||||||
if (isc_crypto_fips_mode()) {
|
if (isc_fips_mode()) {
|
||||||
min_rsa = min_dh = 2048;
|
min_rsa = min_dh = 2048;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1280,8 +1308,16 @@ main(int argc, char **argv) {
|
|||||||
if (verbose > 10) {
|
if (verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
isc_mem_detach(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|
||||||
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
if (base != NULL) {
|
||||||
|
OSSL_PROVIDER_unload(base);
|
||||||
|
}
|
||||||
|
if (fips != NULL) {
|
||||||
|
OSSL_PROVIDER_unload(fips);
|
||||||
|
}
|
||||||
|
#endif
|
||||||
if (freeit != NULL) {
|
if (freeit != NULL) {
|
||||||
free(freeit);
|
free(freeit);
|
||||||
}
|
}
|
||||||
|
|||||||
+27
-6
@@ -18,7 +18,7 @@
|
|||||||
|
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/crypto.h>
|
#include <isc/fips.h>
|
||||||
#include <isc/lex.h>
|
#include <isc/lex.h>
|
||||||
#include <isc/lib.h>
|
#include <isc/lib.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
@@ -362,7 +362,7 @@ create_key(ksr_ctx_t *ksr, dns_kasp_t *kasp, dns_kasp_key_t *kaspkey,
|
|||||||
switch (ksr->alg) {
|
switch (ksr->alg) {
|
||||||
case DST_ALG_RSASHA1:
|
case DST_ALG_RSASHA1:
|
||||||
case DST_ALG_NSEC3RSASHA1:
|
case DST_ALG_NSEC3RSASHA1:
|
||||||
if (isc_crypto_fips_mode()) {
|
if (isc_fips_mode()) {
|
||||||
/* verify-only in FIPS mode */
|
/* verify-only in FIPS mode */
|
||||||
fatal("unsupported algorithm: %s", algstr);
|
fatal("unsupported algorithm: %s", algstr);
|
||||||
}
|
}
|
||||||
@@ -1348,6 +1348,10 @@ main(int argc, char *argv[]) {
|
|||||||
isc_buffer_t buf;
|
isc_buffer_t buf;
|
||||||
int ch;
|
int ch;
|
||||||
char *endp;
|
char *endp;
|
||||||
|
bool set_fips_mode = false;
|
||||||
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
OSSL_PROVIDER *fips = NULL, *base = NULL;
|
||||||
|
#endif
|
||||||
ksr_ctx_t ksr = {
|
ksr_ctx_t ksr = {
|
||||||
.now = isc_stdtime_now(),
|
.now = isc_stdtime_now(),
|
||||||
};
|
};
|
||||||
@@ -1367,9 +1371,7 @@ main(int argc, char *argv[]) {
|
|||||||
ksr.now, &ksr.setend);
|
ksr.now, &ksr.setend);
|
||||||
break;
|
break;
|
||||||
case 'F':
|
case 'F':
|
||||||
if (isc_crypto_fips_enable() != ISC_R_SUCCESS) {
|
set_fips_mode = true;
|
||||||
fatal("setting FIPS mode failed");
|
|
||||||
}
|
|
||||||
break;
|
break;
|
||||||
case 'f':
|
case 'f':
|
||||||
ksr.file = isc_commandline_argument;
|
ksr.file = isc_commandline_argument;
|
||||||
@@ -1423,12 +1425,31 @@ main(int argc, char *argv[]) {
|
|||||||
* The DST subsystem will set FIPS mode if requested at build time.
|
* The DST subsystem will set FIPS mode if requested at build time.
|
||||||
* The minimum sizes are both raised to 2048.
|
* The minimum sizes are both raised to 2048.
|
||||||
*/
|
*/
|
||||||
if (isc_crypto_fips_mode()) {
|
if (isc_fips_mode()) {
|
||||||
min_rsa = min_dh = 2048;
|
min_rsa = min_dh = 2048;
|
||||||
}
|
}
|
||||||
|
|
||||||
setup_logging();
|
setup_logging();
|
||||||
|
|
||||||
|
if (set_fips_mode) {
|
||||||
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
fips = OSSL_PROVIDER_load(NULL, "fips");
|
||||||
|
if (fips == NULL) {
|
||||||
|
fatal("Failed to load FIPS provider");
|
||||||
|
}
|
||||||
|
base = OSSL_PROVIDER_load(NULL, "base");
|
||||||
|
if (base == NULL) {
|
||||||
|
OSSL_PROVIDER_unload(fips);
|
||||||
|
fatal("Failed to load base provider");
|
||||||
|
}
|
||||||
|
#endif
|
||||||
|
if (!isc_fips_mode()) {
|
||||||
|
if (isc_fips_set_mode(1) != ISC_R_SUCCESS) {
|
||||||
|
fatal("setting FIPS mode failed");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/* zone */
|
/* zone */
|
||||||
namestr = argv[1];
|
namestr = argv[1];
|
||||||
name = dns_fixedname_initname(&fname);
|
name = dns_fixedname_initname(&fname);
|
||||||
|
|||||||
@@ -248,7 +248,7 @@ cleanup:
|
|||||||
if (dir != NULL) {
|
if (dir != NULL) {
|
||||||
isc_mem_free(mctx, dir);
|
isc_mem_free(mctx, dir);
|
||||||
}
|
}
|
||||||
isc_mem_detach(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -949,7 +949,7 @@ main(int argc, char **argv) {
|
|||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
isc_mem_free(mctx, directory);
|
isc_mem_free(mctx, directory);
|
||||||
isc_mem_detach(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -42,6 +42,7 @@
|
|||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
|
#include <isc/fips.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/hex.h>
|
#include <isc/hex.h>
|
||||||
#include <isc/lib.h>
|
#include <isc/lib.h>
|
||||||
@@ -89,6 +90,10 @@
|
|||||||
#include <dns/zoneverify.h>
|
#include <dns/zoneverify.h>
|
||||||
|
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
#include <openssl/err.h>
|
||||||
|
#include <openssl/provider.h>
|
||||||
|
#endif
|
||||||
|
|
||||||
#include "dnssectool.h"
|
#include "dnssectool.h"
|
||||||
|
|
||||||
@@ -3375,6 +3380,10 @@ main(int argc, char *argv[]) {
|
|||||||
bool set_optout = false;
|
bool set_optout = false;
|
||||||
bool set_iter = false;
|
bool set_iter = false;
|
||||||
bool nonsecify = false;
|
bool nonsecify = false;
|
||||||
|
bool set_fips_mode = false;
|
||||||
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
OSSL_PROVIDER *fips = NULL, *base = NULL;
|
||||||
|
#endif
|
||||||
|
|
||||||
atomic_init(&shuttingdown, false);
|
atomic_init(&shuttingdown, false);
|
||||||
atomic_init(&finished, false);
|
atomic_init(&finished, false);
|
||||||
@@ -3663,9 +3672,7 @@ main(int argc, char *argv[]) {
|
|||||||
break;
|
break;
|
||||||
|
|
||||||
case 'F':
|
case 'F':
|
||||||
if (isc_crypto_fips_enable() != ISC_R_SUCCESS) {
|
set_fips_mode = true;
|
||||||
fatal("setting FIPS mode failed");
|
|
||||||
}
|
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case '?':
|
case '?':
|
||||||
@@ -3736,6 +3743,27 @@ main(int argc, char *argv[]) {
|
|||||||
|
|
||||||
isc_managers_create(&mctx, nloops, &loopmgr, &netmgr);
|
isc_managers_create(&mctx, nloops, &loopmgr, &netmgr);
|
||||||
|
|
||||||
|
if (set_fips_mode) {
|
||||||
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
fips = OSSL_PROVIDER_load(NULL, "fips");
|
||||||
|
if (fips == NULL) {
|
||||||
|
ERR_clear_error();
|
||||||
|
fatal("Failed to load FIPS provider");
|
||||||
|
}
|
||||||
|
base = OSSL_PROVIDER_load(NULL, "base");
|
||||||
|
if (base == NULL) {
|
||||||
|
OSSL_PROVIDER_unload(fips);
|
||||||
|
ERR_clear_error();
|
||||||
|
fatal("Failed to load base provider");
|
||||||
|
}
|
||||||
|
#endif
|
||||||
|
if (!isc_fips_mode()) {
|
||||||
|
if (isc_fips_set_mode(1) != ISC_R_SUCCESS) {
|
||||||
|
fatal("setting FIPS mode failed");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
setup_logging();
|
setup_logging();
|
||||||
|
|
||||||
argc -= isc_commandline_index;
|
argc -= isc_commandline_index;
|
||||||
@@ -4107,6 +4135,15 @@ main(int argc, char *argv[]) {
|
|||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
if (base != NULL) {
|
||||||
|
OSSL_PROVIDER_unload(base);
|
||||||
|
}
|
||||||
|
if (fips != NULL) {
|
||||||
|
OSSL_PROVIDER_unload(fips);
|
||||||
|
}
|
||||||
|
#endif
|
||||||
|
|
||||||
isc_managers_destroy(&mctx, &loopmgr, &netmgr);
|
isc_managers_destroy(&mctx, &loopmgr, &netmgr);
|
||||||
|
|
||||||
if (printstats) {
|
if (printstats) {
|
||||||
|
|||||||
@@ -330,7 +330,7 @@ main(int argc, char *argv[]) {
|
|||||||
if (verbose > 10) {
|
if (verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
isc_mem_detach(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|
||||||
return result == ISC_R_SUCCESS ? 0 : 1;
|
return result == ISC_R_SUCCESS ? 0 : 1;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -736,6 +736,7 @@ controlkeylist_fromcfg(const cfg_obj_t *keylist, isc_mem_t *mctx,
|
|||||||
key->secret.length = 0;
|
key->secret.length = 0;
|
||||||
ISC_LINK_INIT(key, link);
|
ISC_LINK_INIT(key, link);
|
||||||
ISC_LIST_APPEND(*keyids, key, link);
|
ISC_LIST_APPEND(*keyids, key, link);
|
||||||
|
newstr = NULL;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -25,6 +25,7 @@
|
|||||||
#include <string.h>
|
#include <string.h>
|
||||||
#include <unistd.h>
|
#include <unistd.h>
|
||||||
|
|
||||||
|
#include <isc/condition.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/loop.h>
|
#include <isc/loop.h>
|
||||||
#include <isc/mutex.h>
|
#include <isc/mutex.h>
|
||||||
|
|||||||
@@ -86,6 +86,7 @@ EXTERN named_server_t *named_g_server INIT(NULL);
|
|||||||
/*
|
/*
|
||||||
* Logging.
|
* Logging.
|
||||||
*/
|
*/
|
||||||
|
EXTERN bool named_g_logging INIT(false);
|
||||||
EXTERN unsigned int named_g_debuglevel INIT(0);
|
EXTERN unsigned int named_g_debuglevel INIT(0);
|
||||||
|
|
||||||
/*
|
/*
|
||||||
|
|||||||
@@ -52,6 +52,8 @@ named_log_init(bool safe) {
|
|||||||
named_log_setdefaultsslkeylogfile(lcfg);
|
named_log_setdefaultsslkeylogfile(lcfg);
|
||||||
rcu_read_unlock();
|
rcu_read_unlock();
|
||||||
|
|
||||||
|
named_g_logging = true;
|
||||||
|
|
||||||
return ISC_R_SUCCESS;
|
return ISC_R_SUCCESS;
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
|
|||||||
+111
-44
@@ -30,6 +30,7 @@
|
|||||||
#include <isc/crypto.h>
|
#include <isc/crypto.h>
|
||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
|
#include <isc/fips.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/httpd.h>
|
#include <isc/httpd.h>
|
||||||
#include <isc/lib.h>
|
#include <isc/lib.h>
|
||||||
@@ -90,6 +91,10 @@
|
|||||||
#include <openssl/crypto.h>
|
#include <openssl/crypto.h>
|
||||||
#include <openssl/evp.h>
|
#include <openssl/evp.h>
|
||||||
#include <openssl/opensslv.h>
|
#include <openssl/opensslv.h>
|
||||||
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
#include <openssl/err.h>
|
||||||
|
#include <openssl/provider.h>
|
||||||
|
#endif
|
||||||
#ifdef HAVE_LIBXML2
|
#ifdef HAVE_LIBXML2
|
||||||
#include <libxml/parser.h>
|
#include <libxml/parser.h>
|
||||||
#include <libxml/xmlversion.h>
|
#include <libxml/xmlversion.h>
|
||||||
@@ -129,7 +134,6 @@ static int maxudp = 0;
|
|||||||
/*
|
/*
|
||||||
* -T options:
|
* -T options:
|
||||||
*/
|
*/
|
||||||
static bool cookiealwaysvalid = false;
|
|
||||||
static bool dropedns = false;
|
static bool dropedns = false;
|
||||||
static bool ednsformerr = false;
|
static bool ednsformerr = false;
|
||||||
static bool ednsnotimp = false;
|
static bool ednsnotimp = false;
|
||||||
@@ -151,13 +155,24 @@ static bool transferstuck = false;
|
|||||||
static bool disable6 = false;
|
static bool disable6 = false;
|
||||||
static bool disable4 = false;
|
static bool disable4 = false;
|
||||||
|
|
||||||
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
static OSSL_PROVIDER *fips = NULL, *base = NULL;
|
||||||
|
#endif
|
||||||
|
|
||||||
void
|
void
|
||||||
named_main_earlywarning(const char *format, ...) {
|
named_main_earlywarning(const char *format, ...) {
|
||||||
va_list args;
|
va_list args;
|
||||||
|
|
||||||
va_start(args, format);
|
va_start(args, format);
|
||||||
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
if (named_g_logging) {
|
||||||
ISC_LOG_WARNING, format, args);
|
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
|
ISC_LOG_WARNING, format, args);
|
||||||
|
} else {
|
||||||
|
fprintf(stderr, "%s: ", program_name);
|
||||||
|
vfprintf(stderr, format, args);
|
||||||
|
fprintf(stderr, "\n");
|
||||||
|
fflush(stderr);
|
||||||
|
}
|
||||||
va_end(args);
|
va_end(args);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -166,10 +181,18 @@ named_main_earlyfatal(const char *format, ...) {
|
|||||||
va_list args;
|
va_list args;
|
||||||
|
|
||||||
va_start(args, format);
|
va_start(args, format);
|
||||||
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
if (named_g_logging) {
|
||||||
ISC_LOG_CRITICAL, format, args);
|
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
ISC_LOG_CRITICAL, format, args);
|
||||||
ISC_LOG_CRITICAL, "exiting (due to early fatal error)");
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
|
ISC_LOG_CRITICAL,
|
||||||
|
"exiting (due to early fatal error)");
|
||||||
|
} else {
|
||||||
|
fprintf(stderr, "%s: ", program_name);
|
||||||
|
vfprintf(stderr, format, args);
|
||||||
|
fprintf(stderr, "\n");
|
||||||
|
fflush(stderr);
|
||||||
|
}
|
||||||
va_end(args);
|
va_end(args);
|
||||||
|
|
||||||
_exit(EXIT_FAILURE);
|
_exit(EXIT_FAILURE);
|
||||||
@@ -186,19 +209,26 @@ assertion_failed(const char *file, int line, isc_assertiontype_t type,
|
|||||||
* Handle assertion failures.
|
* Handle assertion failures.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
/*
|
if (named_g_logging) {
|
||||||
* Reset the assertion callback in case it is the log
|
/*
|
||||||
* routines causing the assertion.
|
* Reset the assertion callback in case it is the log
|
||||||
*/
|
* routines causing the assertion.
|
||||||
isc_assertion_setcallback(NULL);
|
*/
|
||||||
|
isc_assertion_setcallback(NULL);
|
||||||
|
|
||||||
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
ISC_LOG_CRITICAL, "%s:%d: %s(%s) failed", file, line,
|
ISC_LOG_CRITICAL, "%s:%d: %s(%s) failed", file,
|
||||||
isc_assertion_typetotext(type), cond);
|
line, isc_assertion_typetotext(type), cond);
|
||||||
isc_backtrace_log(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
isc_backtrace_log(NAMED_LOGCATEGORY_GENERAL,
|
||||||
ISC_LOG_CRITICAL);
|
NAMED_LOGMODULE_MAIN, ISC_LOG_CRITICAL);
|
||||||
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
ISC_LOG_CRITICAL, "exiting (due to assertion failure)");
|
ISC_LOG_CRITICAL,
|
||||||
|
"exiting (due to assertion failure)");
|
||||||
|
} else {
|
||||||
|
fprintf(stderr, "%s:%d: %s(%s) failed\n", file, line,
|
||||||
|
isc_assertion_typetotext(type), cond);
|
||||||
|
fflush(stderr);
|
||||||
|
}
|
||||||
|
|
||||||
if (named_g_coreok) {
|
if (named_g_coreok) {
|
||||||
abort();
|
abort();
|
||||||
@@ -217,20 +247,27 @@ library_fatal_error(const char *file, int line, const char *func,
|
|||||||
* Handle isc_error_fatal() calls from our libraries.
|
* Handle isc_error_fatal() calls from our libraries.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
/*
|
if (named_g_logging) {
|
||||||
* Reset the error callback in case it is the log
|
/*
|
||||||
* routines causing the assertion.
|
* Reset the error callback in case it is the log
|
||||||
*/
|
* routines causing the assertion.
|
||||||
isc_error_setfatal(NULL);
|
*/
|
||||||
|
isc_error_setfatal(NULL);
|
||||||
|
|
||||||
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
ISC_LOG_CRITICAL, "%s:%d:%s(): fatal error: ", file, line,
|
ISC_LOG_CRITICAL,
|
||||||
func);
|
"%s:%d:%s(): fatal error: ", file, line, func);
|
||||||
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
ISC_LOG_CRITICAL, format, args);
|
ISC_LOG_CRITICAL, format, args);
|
||||||
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
ISC_LOG_CRITICAL,
|
ISC_LOG_CRITICAL,
|
||||||
"exiting (due to fatal error in library)");
|
"exiting (due to fatal error in library)");
|
||||||
|
} else {
|
||||||
|
fprintf(stderr, "%s:%d:%s(): fatal error: ", file, line, func);
|
||||||
|
vfprintf(stderr, format, args);
|
||||||
|
fprintf(stderr, "\n");
|
||||||
|
fflush(stderr);
|
||||||
|
}
|
||||||
|
|
||||||
if (named_g_coreok) {
|
if (named_g_coreok) {
|
||||||
abort();
|
abort();
|
||||||
@@ -250,11 +287,19 @@ library_unexpected_error(const char *file, int line, const char *func,
|
|||||||
* Handle isc_error_unexpected() calls from our libraries.
|
* Handle isc_error_unexpected() calls from our libraries.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
if (named_g_logging) {
|
||||||
ISC_LOG_ERROR, "%s:%d:%s(): unexpected error: ", file,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
line, func);
|
ISC_LOG_ERROR,
|
||||||
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
"%s:%d:%s(): unexpected error: ", file, line,
|
||||||
ISC_LOG_ERROR, format, args);
|
func);
|
||||||
|
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
|
ISC_LOG_ERROR, format, args);
|
||||||
|
} else {
|
||||||
|
fprintf(stderr, "%s:%d:%s(): fatal error: ", file, line, func);
|
||||||
|
vfprintf(stderr, format, args);
|
||||||
|
fprintf(stderr, "\n");
|
||||||
|
fflush(stderr);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -653,9 +698,7 @@ parse_T_opt(char *option) {
|
|||||||
* force the server to behave (or misbehave) in
|
* force the server to behave (or misbehave) in
|
||||||
* specified ways for testing purposes.
|
* specified ways for testing purposes.
|
||||||
*/
|
*/
|
||||||
if (!strcmp(option, "cookiealwaysvalid")) {
|
if (!strcmp(option, "dropedns")) {
|
||||||
cookiealwaysvalid = true;
|
|
||||||
} else if (!strcmp(option, "dropedns")) {
|
|
||||||
dropedns = true;
|
dropedns = true;
|
||||||
} else if (!strcmp(option, "ednsformerr")) {
|
} else if (!strcmp(option, "ednsformerr")) {
|
||||||
ednsformerr = true;
|
ednsformerr = true;
|
||||||
@@ -909,7 +952,25 @@ parse_command_line(int argc, char *argv[]) {
|
|||||||
named_main_earlyfatal("option '-X' has been removed");
|
named_main_earlyfatal("option '-X' has been removed");
|
||||||
break;
|
break;
|
||||||
case 'F':
|
case 'F':
|
||||||
if (isc_crypto_fips_enable() != ISC_R_SUCCESS) {
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
fips = OSSL_PROVIDER_load(NULL, "fips");
|
||||||
|
if (fips == NULL) {
|
||||||
|
ERR_clear_error();
|
||||||
|
named_main_earlyfatal(
|
||||||
|
"Failed to load FIPS provider");
|
||||||
|
}
|
||||||
|
base = OSSL_PROVIDER_load(NULL, "base");
|
||||||
|
if (base == NULL) {
|
||||||
|
OSSL_PROVIDER_unload(fips);
|
||||||
|
ERR_clear_error();
|
||||||
|
named_main_earlyfatal(
|
||||||
|
"Failed to load base provider");
|
||||||
|
}
|
||||||
|
#endif
|
||||||
|
if (isc_fips_mode()) { /* Already in FIPS mode. */
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
if (isc_fips_set_mode(1) != ISC_R_SUCCESS) {
|
||||||
named_main_earlyfatal(
|
named_main_earlyfatal(
|
||||||
"setting FIPS mode failed");
|
"setting FIPS mode failed");
|
||||||
}
|
}
|
||||||
@@ -1223,9 +1284,6 @@ setup(void) {
|
|||||||
/*
|
/*
|
||||||
* Modify server context according to command line options
|
* Modify server context according to command line options
|
||||||
*/
|
*/
|
||||||
if (cookiealwaysvalid) {
|
|
||||||
ns_server_setoption(sctx, NS_SERVER_COOKIEALWAYSVALID, true);
|
|
||||||
}
|
|
||||||
if (disable4) {
|
if (disable4) {
|
||||||
ns_server_setoption(sctx, NS_SERVER_DISABLE4, true);
|
ns_server_setoption(sctx, NS_SERVER_DISABLE4, true);
|
||||||
}
|
}
|
||||||
@@ -1516,6 +1574,15 @@ main(int argc, char *argv[]) {
|
|||||||
|
|
||||||
named_os_shutdown();
|
named_os_shutdown();
|
||||||
|
|
||||||
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
|
if (base != NULL) {
|
||||||
|
OSSL_PROVIDER_unload(base);
|
||||||
|
}
|
||||||
|
if (fips != NULL) {
|
||||||
|
OSSL_PROVIDER_unload(fips);
|
||||||
|
}
|
||||||
|
#endif
|
||||||
|
|
||||||
#ifdef HAVE_GPERFTOOLS_PROFILER
|
#ifdef HAVE_GPERFTOOLS_PROFILER
|
||||||
ProfilerStop();
|
ProfilerStop();
|
||||||
#endif /* ifdef HAVE_GPERFTOOLS_PROFILER */
|
#endif /* ifdef HAVE_GPERFTOOLS_PROFILER */
|
||||||
|
|||||||
+7
-17
@@ -38,6 +38,7 @@
|
|||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
|
#include <isc/fips.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/hex.h>
|
#include <isc/hex.h>
|
||||||
#include <isc/hmac.h>
|
#include <isc/hmac.h>
|
||||||
@@ -3762,7 +3763,7 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
|||||||
uint32_t maxbits;
|
uint32_t maxbits;
|
||||||
unsigned int resopts = 0;
|
unsigned int resopts = 0;
|
||||||
dns_zone_t *zone = NULL;
|
dns_zone_t *zone = NULL;
|
||||||
uint32_t clients_per_query, max_clients_per_query;
|
uint32_t max_clients_per_query;
|
||||||
bool empty_zones_enable;
|
bool empty_zones_enable;
|
||||||
const cfg_obj_t *disablelist = NULL;
|
const cfg_obj_t *disablelist = NULL;
|
||||||
isc_stats_t *resstats = NULL;
|
isc_stats_t *resstats = NULL;
|
||||||
@@ -5168,26 +5169,15 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
|||||||
INSIST(result == ISC_R_SUCCESS);
|
INSIST(result == ISC_R_SUCCESS);
|
||||||
view->v6bias = cfg_obj_asuint32(obj) * 1000;
|
view->v6bias = cfg_obj_asuint32(obj) * 1000;
|
||||||
|
|
||||||
obj = NULL;
|
|
||||||
result = named_config_get(maps, "clients-per-query", &obj);
|
|
||||||
INSIST(result == ISC_R_SUCCESS);
|
|
||||||
clients_per_query = cfg_obj_asuint32(obj);
|
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = named_config_get(maps, "max-clients-per-query", &obj);
|
result = named_config_get(maps, "max-clients-per-query", &obj);
|
||||||
INSIST(result == ISC_R_SUCCESS);
|
INSIST(result == ISC_R_SUCCESS);
|
||||||
max_clients_per_query = cfg_obj_asuint32(obj);
|
max_clients_per_query = cfg_obj_asuint32(obj);
|
||||||
|
|
||||||
if (max_clients_per_query < clients_per_query) {
|
obj = NULL;
|
||||||
cfg_obj_log(obj, ISC_LOG_WARNING,
|
result = named_config_get(maps, "clients-per-query", &obj);
|
||||||
"configured clients-per-query (%u) exceeds "
|
INSIST(result == ISC_R_SUCCESS);
|
||||||
"max-clients-per-query (%u); automatically "
|
dns_resolver_setclientsperquery(view->resolver, cfg_obj_asuint32(obj),
|
||||||
"adjusting max-clients-per-query to (%u)",
|
|
||||||
clients_per_query, max_clients_per_query,
|
|
||||||
clients_per_query);
|
|
||||||
max_clients_per_query = clients_per_query;
|
|
||||||
}
|
|
||||||
dns_resolver_setclientsperquery(view->resolver, clients_per_query,
|
|
||||||
max_clients_per_query);
|
max_clients_per_query);
|
||||||
|
|
||||||
/*
|
/*
|
||||||
@@ -9387,7 +9377,7 @@ view_loaded(void *arg) {
|
|||||||
|
|
||||||
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
ISC_LOG_NOTICE, "FIPS mode is %s",
|
ISC_LOG_NOTICE, "FIPS mode is %s",
|
||||||
isc_crypto_fips_mode() ? "enabled" : "disabled");
|
isc_fips_mode() ? "enabled" : "disabled");
|
||||||
|
|
||||||
#if HAVE_LIBSYSTEMD
|
#if HAVE_LIBSYSTEMD
|
||||||
sd_notifyf(0,
|
sd_notifyf(0,
|
||||||
|
|||||||
@@ -1603,7 +1603,7 @@ xfrin_xmlrender(dns_zone_t *zone, void *arg) {
|
|||||||
isc_sockaddr_format(addrp, addr_buf, sizeof(addr_buf));
|
isc_sockaddr_format(addrp, addr_buf, sizeof(addr_buf));
|
||||||
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR addr_buf));
|
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR addr_buf));
|
||||||
} else if (is_presoa) {
|
} else if (is_presoa) {
|
||||||
dns_zone_getsourceaddr(zone, &addr);
|
addr = dns_zone_getsourceaddr(zone);
|
||||||
isc_sockaddr_format(&addr, addr_buf, sizeof(addr_buf));
|
isc_sockaddr_format(&addr, addr_buf, sizeof(addr_buf));
|
||||||
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR addr_buf));
|
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR addr_buf));
|
||||||
} else {
|
} else {
|
||||||
@@ -1617,13 +1617,9 @@ xfrin_xmlrender(dns_zone_t *zone, void *arg) {
|
|||||||
isc_sockaddr_format(addrp, addr_buf, sizeof(addr_buf));
|
isc_sockaddr_format(addrp, addr_buf, sizeof(addr_buf));
|
||||||
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR addr_buf));
|
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR addr_buf));
|
||||||
} else if (is_presoa) {
|
} else if (is_presoa) {
|
||||||
if (dns_zone_getprimaryaddr(zone, &addr) == ISC_R_SUCCESS) {
|
addr = dns_zone_getprimaryaddr(zone);
|
||||||
isc_sockaddr_format(&addr, addr_buf, sizeof(addr_buf));
|
isc_sockaddr_format(&addr, addr_buf, sizeof(addr_buf));
|
||||||
TRY0(xmlTextWriterWriteString(writer,
|
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR addr_buf));
|
||||||
ISC_XMLCHAR addr_buf));
|
|
||||||
} else {
|
|
||||||
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR "-"));
|
|
||||||
}
|
|
||||||
} else {
|
} else {
|
||||||
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR "-"));
|
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR "-"));
|
||||||
}
|
}
|
||||||
@@ -2660,7 +2656,7 @@ xfrin_jsonrender(dns_zone_t *zone, void *arg) {
|
|||||||
json_object_object_add(xfrinobj, "localaddr",
|
json_object_object_add(xfrinobj, "localaddr",
|
||||||
json_object_new_string(addr_buf));
|
json_object_new_string(addr_buf));
|
||||||
} else if (is_presoa) {
|
} else if (is_presoa) {
|
||||||
dns_zone_getsourceaddr(zone, &addr);
|
addr = dns_zone_getsourceaddr(zone);
|
||||||
isc_sockaddr_format(&addr, addr_buf, sizeof(addr_buf));
|
isc_sockaddr_format(&addr, addr_buf, sizeof(addr_buf));
|
||||||
json_object_object_add(xfrinobj, "localaddr",
|
json_object_object_add(xfrinobj, "localaddr",
|
||||||
json_object_new_string(addr_buf));
|
json_object_new_string(addr_buf));
|
||||||
@@ -2675,15 +2671,10 @@ xfrin_jsonrender(dns_zone_t *zone, void *arg) {
|
|||||||
json_object_object_add(xfrinobj, "remoteaddr",
|
json_object_object_add(xfrinobj, "remoteaddr",
|
||||||
json_object_new_string(addr_buf));
|
json_object_new_string(addr_buf));
|
||||||
} else if (is_presoa) {
|
} else if (is_presoa) {
|
||||||
if (dns_zone_getprimaryaddr(zone, &addr) == ISC_R_SUCCESS) {
|
addr = dns_zone_getprimaryaddr(zone);
|
||||||
isc_sockaddr_format(&addr, addr_buf, sizeof(addr_buf));
|
isc_sockaddr_format(&addr, addr_buf, sizeof(addr_buf));
|
||||||
json_object_object_add(
|
json_object_object_add(xfrinobj, "remoteaddr",
|
||||||
xfrinobj, "remoteaddr",
|
json_object_new_string(addr_buf));
|
||||||
json_object_new_string(addr_buf));
|
|
||||||
} else {
|
|
||||||
json_object_object_add(xfrinobj, "remoteaddr",
|
|
||||||
json_object_new_string("-"));
|
|
||||||
}
|
|
||||||
} else {
|
} else {
|
||||||
json_object_object_add(xfrinobj, "remoteaddr",
|
json_object_object_add(xfrinobj, "remoteaddr",
|
||||||
json_object_new_string("-"));
|
json_object_new_string("-"));
|
||||||
|
|||||||
@@ -1279,22 +1279,22 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = named_config_get(maps, "parental-source", &obj);
|
result = named_config_get(maps, "parental-source", &obj);
|
||||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||||
dns_zone_setparentalsrc4(zone, cfg_obj_assockaddr(obj));
|
CHECK(dns_zone_setparentalsrc4(zone, cfg_obj_assockaddr(obj)));
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = named_config_get(maps, "parental-source-v6", &obj);
|
result = named_config_get(maps, "parental-source-v6", &obj);
|
||||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||||
dns_zone_setparentalsrc6(zone, cfg_obj_assockaddr(obj));
|
CHECK(dns_zone_setparentalsrc6(zone, cfg_obj_assockaddr(obj)));
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = named_config_get(maps, "notify-source", &obj);
|
result = named_config_get(maps, "notify-source", &obj);
|
||||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||||
dns_zone_setnotifysrc4(zone, cfg_obj_assockaddr(obj));
|
CHECK(dns_zone_setnotifysrc4(zone, cfg_obj_assockaddr(obj)));
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = named_config_get(maps, "notify-source-v6", &obj);
|
result = named_config_get(maps, "notify-source-v6", &obj);
|
||||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||||
dns_zone_setnotifysrc6(zone, cfg_obj_assockaddr(obj));
|
CHECK(dns_zone_setnotifysrc6(zone, cfg_obj_assockaddr(obj)));
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = named_config_get(maps, "notify-to-soa", &obj);
|
result = named_config_get(maps, "notify-to-soa", &obj);
|
||||||
@@ -1938,12 +1938,14 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = named_config_get(maps, "transfer-source", &obj);
|
result = named_config_get(maps, "transfer-source", &obj);
|
||||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||||
dns_zone_setxfrsource4(mayberaw, cfg_obj_assockaddr(obj));
|
CHECK(dns_zone_setxfrsource4(mayberaw,
|
||||||
|
cfg_obj_assockaddr(obj)));
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = named_config_get(maps, "transfer-source-v6", &obj);
|
result = named_config_get(maps, "transfer-source-v6", &obj);
|
||||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||||
dns_zone_setxfrsource6(mayberaw, cfg_obj_assockaddr(obj));
|
CHECK(dns_zone_setxfrsource6(mayberaw,
|
||||||
|
cfg_obj_assockaddr(obj)));
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
(void)named_config_get(maps, "try-tcp-refresh", &obj);
|
(void)named_config_get(maps, "try-tcp-refresh", &obj);
|
||||||
|
|||||||
@@ -28,7 +28,6 @@ options {
|
|||||||
} except-from {
|
} except-from {
|
||||||
"example";
|
"example";
|
||||||
};
|
};
|
||||||
qname-minimization disabled; // Regression test for GL #4652
|
|
||||||
};
|
};
|
||||||
|
|
||||||
trust-anchors { };
|
trust-anchors { };
|
||||||
|
|||||||
@@ -131,13 +131,11 @@ status=$((status + ret))
|
|||||||
echo_i "checking that log-report-channel zones fail if '*._er/TXT' is missing ($n)"
|
echo_i "checking that log-report-channel zones fail if '*._er/TXT' is missing ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
$CHECKZONE -R fail example zones/er.db >test.out2.$n 2>&1 || ret=1
|
$CHECKZONE -R fail example zones/er.db >test.out2.$n 2>&1 || ret=1
|
||||||
grep -F "no '*._er/TXT' wildcard found" test.out2.$n >/dev/null && ret=1
|
grep -F "no '*._er/TXT' wildcard found" test.out4.$n >/dev/null && ret=1
|
||||||
$CHECKZONE example zones/er-missing.db >test.out3.$n 2>&1 || ret=1
|
$CHECKZONE example zones/er-missing.db >test.out3.$n 2>&1 || ret=1
|
||||||
grep -F "no '*._er/TXT' wildcard found" test.out3.$n >/dev/null && ret=1
|
grep -F "no '*._er/TXT' wildcard found" test.out4.$n >/dev/null && ret=1
|
||||||
$CHECKZONE -R fail example zones/er-missing.db >test.out4.$n 2>&1 && ret=1
|
$CHECKZONE -R fail example zones/er-missing.db >test.out4.$n 2>&1 && ret=1
|
||||||
grep -F "no '*._er/TXT' wildcard found" test.out4.$n >/dev/null || ret=1
|
grep -F "no '*._er/TXT' wildcard found" test.out4.$n >/dev/null || ret=1
|
||||||
n=$((n + 1))
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|
||||||
echo_i "checking that raw zone with bad class is handled ($n)"
|
echo_i "checking that raw zone with bad class is handled ($n)"
|
||||||
|
|||||||
@@ -308,7 +308,6 @@ def logger(request, system_test_name):
|
|||||||
@pytest.fixture(scope="module")
|
@pytest.fixture(scope="module")
|
||||||
def expected_artifacts(request):
|
def expected_artifacts(request):
|
||||||
common_artifacts = [
|
common_artifacts = [
|
||||||
"*/.hypothesis", # drop after Ubuntu 20.04 Focal Fossa gets removed from CI
|
|
||||||
".libs/*", # possible build artifacts, see GL #5055
|
".libs/*", # possible build artifacts, see GL #5055
|
||||||
"ns*/named.conf",
|
"ns*/named.conf",
|
||||||
"ns*/named.memstats",
|
"ns*/named.memstats",
|
||||||
|
|||||||
@@ -361,23 +361,6 @@ grep "status: NOERROR," dig.out.test$n >/dev/null || ret=1
|
|||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|
||||||
n=$((n + 1))
|
|
||||||
echo_i "Restart NS4 with -T cookiealwaysvalid ($n)"
|
|
||||||
stop_server ns4
|
|
||||||
touch ns4/named.cookiealwaysvalid
|
|
||||||
start_server --noclean --restart --port ${PORT} ns4 || ret=1
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
|
||||||
status=$((status + ret))
|
|
||||||
|
|
||||||
n=$((n + 1))
|
|
||||||
echo_i "test NS6 cookie on NS4 with -T cookiealwaysvalid (expect success) ($n)"
|
|
||||||
ret=0
|
|
||||||
$DIG $DIGOPTS +cookie=$ns6cookie -b 10.53.0.4 +nobadcookie soa . @10.53.0.4 >dig.out.test$n || ret=1
|
|
||||||
grep "; COOKIE:.*(good)" dig.out.test$n >/dev/null || ret=1
|
|
||||||
grep "status: NOERROR," dig.out.test$n >/dev/null || ret=1
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
|
||||||
status=$((status + ret))
|
|
||||||
|
|
||||||
n=$((n + 1))
|
n=$((n + 1))
|
||||||
echo_i "check that test server is correctly configured ($n)"
|
echo_i "check that test server is correctly configured ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
@@ -569,21 +552,16 @@ sys.exit(1)'; then
|
|||||||
$DIG $DIGOPTS @10.53.0.1 tsig. >dig.out.test$n.1 || ret=1
|
$DIG $DIGOPTS @10.53.0.1 tsig. >dig.out.test$n.1 || ret=1
|
||||||
grep "status: NOERROR" dig.out.test$n.1 >/dev/null || ret=1
|
grep "status: NOERROR" dig.out.test$n.1 >/dev/null || ret=1
|
||||||
rndc_dumpdb ns1
|
rndc_dumpdb ns1
|
||||||
# prime cache with NS response for QNAME minimisation
|
|
||||||
grep "$pat" ns1/named_dump.db.test$n >/dev/null || ret=1
|
grep "$pat" ns1/named_dump.db.test$n >/dev/null || ret=1
|
||||||
$DIG $DIGOPTS @10.53.0.1 NS nocookie.tsig >dig.out.test$n.2 || ret=1
|
|
||||||
grep "status: NOERROR" dig.out.test$n.2 >/dev/null || ret=1
|
|
||||||
# check the disabled server response
|
# check the disabled server response
|
||||||
nextpart ns1/named.run >/dev/null
|
nextpart ns1/named.run >/dev/null
|
||||||
$DIG $DIGOPTS @10.53.0.1 nocookie.tsig >dig.out.test$n.3 || ret=1
|
$DIG $DIGOPTS @10.53.0.1 nocookie.tsig >dig.out.test$n.2 || ret=1
|
||||||
grep "status: NOERROR" dig.out.test$n.3 >/dev/null || ret=1
|
grep "status: NOERROR" dig.out.test$n.2 >/dev/null || ret=1
|
||||||
grep 'A.10\.53\.0\.9' dig.out.test$n.3 >/dev/null || ret=1
|
grep 'A.10\.53\.0\.9' dig.out.test$n.2 >/dev/null || ret=1
|
||||||
grep 'A.10\.53\.0\.10' dig.out.test$n.3 >/dev/null || ret=1
|
grep 'A.10\.53\.0\.10' dig.out.test$n.2 >/dev/null || ret=1
|
||||||
nextpart ns1/named.run >named.run.test$n
|
nextpart ns1/named.run >named.run.test$n
|
||||||
count=$(grep -c ') [0-9][0-9]* NOERROR 0' named.run.test$n)
|
count=$(grep -c ') [0-9][0-9]* NOERROR 0' named.run.test$n)
|
||||||
test $count -eq 2 || ret=1
|
test $count -eq 2 || ret=1
|
||||||
count=$(grep -c '^; COOKIE: ................................' named.run.test$n)
|
|
||||||
test $count -eq 1 || ret=1
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -19,7 +19,6 @@ pytestmark = pytest.mark.extra_artifacts(
|
|||||||
"ans*/ans.run",
|
"ans*/ans.run",
|
||||||
"ans*/query.log",
|
"ans*/query.log",
|
||||||
"ns1/named_dump.db*",
|
"ns1/named_dump.db*",
|
||||||
"ns4/named.cookiealwaysvalid",
|
|
||||||
]
|
]
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|||||||
@@ -1135,16 +1135,6 @@ if [ -x "$DIG" ]; then
|
|||||||
grep "; EDNS: version: 0, flags:; udp: 1232" dig.out.test$n >/dev/null || ret=1
|
grep "; EDNS: version: 0, flags:; udp: 1232" dig.out.test$n >/dev/null || ret=1
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|
||||||
n=$((n + 1))
|
|
||||||
echo_i "check that dig +showbadvers works ($n)"
|
|
||||||
dig_with_opts @10.53.0.3 +edns=1 +qr +showbadvers a.example >dig.out.test$n 2>&1 || ret=1
|
|
||||||
grep "; EDNS: version: 1, flags:; udp: 1232" dig.out.test$n >/dev/null || ret=1
|
|
||||||
grep "; EDNS: version: 0, flags:; udp: 1232" dig.out.test$n >/dev/null || ret=1
|
|
||||||
grep -F "status: BADVERS" dig.out.test$n >/dev/null || ret=1
|
|
||||||
grep -F "status: NOERROR" dig.out.test$n >/dev/null || ret=1
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
|
||||||
status=$((status + ret))
|
|
||||||
else
|
else
|
||||||
echo_i "$DIG is needed, so skipping these dig tests"
|
echo_i "$DIG is needed, so skipping these dig tests"
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -64,7 +64,7 @@ for subdomain in digest-alg-unsupported ds-unsupported secure badds \
|
|||||||
kskonly update-nsec3 auto-nsec auto-nsec3 secure.below-cname \
|
kskonly update-nsec3 auto-nsec auto-nsec3 secure.below-cname \
|
||||||
ttlpatch split-dnssec split-smart expired expiring upper lower \
|
ttlpatch split-dnssec split-smart expired expiring upper lower \
|
||||||
dnskey-unknown dnskey-unsupported dnskey-unsupported-2 \
|
dnskey-unknown dnskey-unsupported dnskey-unsupported-2 \
|
||||||
dnskey-nsec3-unknown managed-future future revkey \
|
dnskey-nsec3-unknown managed-future revkey \
|
||||||
dname-at-apex-nsec3 occluded rsasha1 rsasha1-1024; do
|
dname-at-apex-nsec3 occluded rsasha1 rsasha1-1024; do
|
||||||
cp "../ns3/dsset-$subdomain.example." .
|
cp "../ns3/dsset-$subdomain.example." .
|
||||||
done
|
done
|
||||||
|
|||||||
@@ -1,6 +0,0 @@
|
|||||||
; This is a key-signing key, keyid 23640, for .
|
|
||||||
; Created: 20250310185208 (Mon Mar 10 18:52:08 2025)
|
|
||||||
; Publish: 20250310185208 (Mon Mar 10 18:52:08 2025)
|
|
||||||
; Activate: 20250310185208 (Mon Mar 10 18:52:08 2025)
|
|
||||||
; Revoke: 20250310185208 (Mon Mar 10 18:52:08 2025)
|
|
||||||
. IN DNSKEY 257 3 13 uKwpRtMH+9iuUk/Xj6LciIP5ZckaBtXaUqxUxzJYexXjvxGZGX4470Jv hq2NCI3HBZQNaCCP/h9sluhIzRGPTA==
|
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
Private-key-format: v1.3
|
|
||||||
Algorithm: 13 (ECDSAP256SHA256)
|
|
||||||
PrivateKey: m5udfGNSijISQ8Tfp4kx09O1em4PErLUw/mCj3SKmqw=
|
|
||||||
Created: 20250310185208
|
|
||||||
Publish: 20250310185208
|
|
||||||
Activate: 20250310185208
|
|
||||||
Revoke: 20250310185208
|
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
; This is a zone-signing key, keyid 23768, for .
|
|
||||||
; Created: 20250310185208 (Mon Mar 10 18:52:08 2025)
|
|
||||||
; Publish: 20250310185208 (Mon Mar 10 18:52:08 2025)
|
|
||||||
; Activate: 20250310185208 (Mon Mar 10 18:52:08 2025)
|
|
||||||
. IN DNSKEY 256 3 13 TFelYtTRBWeA9A307vvuWIcaNwW4txW4RgSELtsi46ZQs24ncRxmxtFf uJuPyVXePNiE4HNI9CIowGUsn5WuBw==
|
|
||||||
@@ -1,37 +0,0 @@
|
|||||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
;
|
|
||||||
; SPDX-License-Identifier: MPL-2.0
|
|
||||||
;
|
|
||||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
;
|
|
||||||
; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
; information regarding copyright ownership.
|
|
||||||
|
|
||||||
; This is a zone which has two DNSKEY records, both of which have
|
|
||||||
; existing private key files available. They should be loaded automatically
|
|
||||||
; and the zone correctly signed.
|
|
||||||
;
|
|
||||||
$TTL 30 ; 30 seconds
|
|
||||||
. IN SOA a.root.servers.nil. each.isc.org. (
|
|
||||||
2000042101 ; serial
|
|
||||||
600 ; refresh (10 minutes)
|
|
||||||
600 ; retry (10 minutes)
|
|
||||||
1200 ; expire (20 minutes)
|
|
||||||
600 ; minimum (10 minutes)
|
|
||||||
)
|
|
||||||
NS a.root-servers.nil.
|
|
||||||
DNSKEY 256 3 13 (
|
|
||||||
TFelYtTRBWeA9A307vvuWIcaNwW4txW4RgSELtsi46ZQ
|
|
||||||
s24ncRxmxtFfuJuPyVXePNiE4HNI9CIowGUsn5WuBw==
|
|
||||||
) ; ZSK; alg = ECDSAP256SHA256 ; key id = 23768
|
|
||||||
DNSKEY 257 3 13 (
|
|
||||||
OSmhpULEDCUzHCBeDU5uJXzkCcGuW2qrkQznKRPGhRZN
|
|
||||||
j7ZUIGInGzM5Um5m02ULWt8tKbi55NJUeifKWegQ0g==
|
|
||||||
) ; KSK; alg = ECDSAP256SHA256 ; key id = 22255
|
|
||||||
DNSKEY 385 3 13 (
|
|
||||||
uKwpRtMH+9iuUk/Xj6LciIP5ZckaBtXaUqxUxzJYexXj
|
|
||||||
vxGZGX4470Jvhq2NCI3HBZQNaCCP/h9sluhIzRGPTA==
|
|
||||||
) ; revoked KSK; alg = ECDSAP256SHA256 ; key id = 23768
|
|
||||||
a.root-servers.nil. A 10.53.0.1
|
|
||||||
@@ -1564,18 +1564,6 @@ n=$((n + 1))
|
|||||||
test "$ret" -eq 0 || echo_i "failed"
|
test "$ret" -eq 0 || echo_i "failed"
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|
||||||
echo_ic "revoked KSK ID collides with ZSK ($n)"
|
|
||||||
ret=0
|
|
||||||
# signing should fail, but should not coredump
|
|
||||||
(
|
|
||||||
cd signer/general || exit 0
|
|
||||||
rm -f signed.zone
|
|
||||||
$SIGNER -S -f signed.zone -o . test12.zone >signer.out.$n
|
|
||||||
) && ret=1
|
|
||||||
n=$((n + 1))
|
|
||||||
test "$ret" -eq 0 || echo_i "failed"
|
|
||||||
status=$((status + ret))
|
|
||||||
|
|
||||||
echo_ic "check that dnssec-signzone rejects excessive NSEC3 iterations ($n)"
|
echo_ic "check that dnssec-signzone rejects excessive NSEC3 iterations ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
(
|
(
|
||||||
@@ -2191,7 +2179,7 @@ echo_i "checking RRSIG query from cache ($n)"
|
|||||||
ret=0
|
ret=0
|
||||||
dig_with_opts normalthenrrsig.secure.example. @10.53.0.4 a >/dev/null || ret=1
|
dig_with_opts normalthenrrsig.secure.example. @10.53.0.4 a >/dev/null || ret=1
|
||||||
ans=$(dig_with_opts +short normalthenrrsig.secure.example. @10.53.0.4 rrsig) || ret=1
|
ans=$(dig_with_opts +short normalthenrrsig.secure.example. @10.53.0.4 rrsig) || ret=1
|
||||||
expect=$(dig_with_opts +short normalthenrrsig.secure.example. @10.53.0.3 rrsig | grep -E '^(A|NSEC)') || ret=1
|
expect=$(dig_with_opts +short normalthenrrsig.secure.example. @10.53.0.3 rrsig | grep '^A') || ret=1
|
||||||
test "$ans" = "$expect" || ret=1
|
test "$ans" = "$expect" || ret=1
|
||||||
# also check that RA is set
|
# also check that RA is set
|
||||||
dig_with_opts normalthenrrsig.secure.example. @10.53.0.4 rrsig >dig.out.ns4.test$n || ret=1
|
dig_with_opts normalthenrrsig.secure.example. @10.53.0.4 rrsig >dig.out.ns4.test$n || ret=1
|
||||||
@@ -2871,19 +2859,6 @@ dig_with_opts +noauth expired.example. +dnssec @10.53.0.4 soa >dig.out.ns4.test$
|
|||||||
grep "SERVFAIL" dig.out.ns4.test$n >/dev/null || ret=1
|
grep "SERVFAIL" dig.out.ns4.test$n >/dev/null || ret=1
|
||||||
grep "flags:.*ad.*QUERY" dig.out.ns4.test$n >/dev/null && ret=1
|
grep "flags:.*ad.*QUERY" dig.out.ns4.test$n >/dev/null && ret=1
|
||||||
grep "expired.example/.*: RRSIG has expired" ns4/named.run >/dev/null || ret=1
|
grep "expired.example/.*: RRSIG has expired" ns4/named.run >/dev/null || ret=1
|
||||||
grep "; EDE: 7 (Signature Expired): (expired.example/DNSKEY)" dig.out.ns4.test$n >/dev/null || ret=1
|
|
||||||
n=$((n + 1))
|
|
||||||
test "$ret" -eq 0 || echo_i "failed"
|
|
||||||
status=$((status + ret))
|
|
||||||
|
|
||||||
status=$((status + ret))
|
|
||||||
echo_i "checking signatures in the future do not validate ($n)"
|
|
||||||
ret=0
|
|
||||||
dig_with_opts +noauth future.example. +dnssec @10.53.0.4 soa >dig.out.ns4.test$n || ret=1
|
|
||||||
grep "SERVFAIL" dig.out.ns4.test$n >/dev/null || ret=1
|
|
||||||
grep "flags:.*ad.*QUERY" dig.out.ns4.test$n >/dev/null && ret=1
|
|
||||||
grep "future.example/.*: RRSIG validity period has not begun" ns4/named.run >/dev/null || ret=1
|
|
||||||
grep "; EDE: 8 (Signature Not Yet Valid): (future.example/DNSKEY)" dig.out.ns4.test$n >/dev/null || ret=1
|
|
||||||
n=$((n + 1))
|
n=$((n + 1))
|
||||||
test "$ret" -eq 0 || echo_i "failed"
|
test "$ret" -eq 0 || echo_i "failed"
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
@@ -3780,7 +3755,7 @@ status=$((status + ret))
|
|||||||
echo_i "checking EDE code 1 for bad alg mnemonic ($n)"
|
echo_i "checking EDE code 1 for bad alg mnemonic ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
dig_with_opts @10.53.0.4 badalg.secure.example >dig.out.ns4.test$n || ret=1
|
dig_with_opts @10.53.0.4 badalg.secure.example >dig.out.ns4.test$n || ret=1
|
||||||
grep "; EDE: 1 (Unsupported DNSKEY Algorithm): (ECDSAP256SHA256 badalg.secure.example/NSEC)" dig.out.ns4.test$n >/dev/null || ret=1
|
grep "; EDE: 1 (Unsupported DNSKEY Algorithm): (ECDSAP256SHA256 badalg.secure.example/A)" dig.out.ns4.test$n >/dev/null || ret=1
|
||||||
grep "flags:.*ad.*QUERY" dig.out.ns4.test$n >/dev/null && ret=1
|
grep "flags:.*ad.*QUERY" dig.out.ns4.test$n >/dev/null && ret=1
|
||||||
n=$((n + 1))
|
n=$((n + 1))
|
||||||
test "$ret" -eq 0 || echo_i "failed"
|
test "$ret" -eq 0 || echo_i "failed"
|
||||||
|
|||||||
@@ -232,7 +232,9 @@ addrdataset(dns_db_t *db, dns_dbnode_t *node, dns_dbversion_t *version,
|
|||||||
dns_fixedname_init(&name);
|
dns_fixedname_init(&name);
|
||||||
CHECK(dns__db_addrdataset(sampledb->db, node, version, now, rdataset,
|
CHECK(dns__db_addrdataset(sampledb->db, node, version, now, rdataset,
|
||||||
options, addedrdataset DNS__DB_FLARG_PASS));
|
options, addedrdataset DNS__DB_FLARG_PASS));
|
||||||
if (dns_rdatatype_isaddr(rdataset->type)) {
|
if (rdataset->type == dns_rdatatype_a ||
|
||||||
|
rdataset->type == dns_rdatatype_aaaa)
|
||||||
|
{
|
||||||
CHECK(dns_db_nodefullname(sampledb->db, node,
|
CHECK(dns_db_nodefullname(sampledb->db, node,
|
||||||
dns_fixedname_name(&name)));
|
dns_fixedname_name(&name)));
|
||||||
CHECK(syncptrs(sampledb->inst, dns_fixedname_name(&name),
|
CHECK(syncptrs(sampledb->inst, dns_fixedname_name(&name),
|
||||||
@@ -261,7 +263,9 @@ subtractrdataset(dns_db_t *db, dns_dbnode_t *node, dns_dbversion_t *version,
|
|||||||
goto cleanup;
|
goto cleanup;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (dns_rdatatype_isaddr(rdataset->type)) {
|
if (rdataset->type == dns_rdatatype_a ||
|
||||||
|
rdataset->type == dns_rdatatype_aaaa)
|
||||||
|
{
|
||||||
CHECK(dns_db_nodefullname(sampledb->db, node,
|
CHECK(dns_db_nodefullname(sampledb->db, node,
|
||||||
dns_fixedname_name(&name)));
|
dns_fixedname_name(&name)));
|
||||||
CHECK(syncptrs(sampledb->inst, dns_fixedname_name(&name),
|
CHECK(syncptrs(sampledb->inst, dns_fixedname_name(&name),
|
||||||
|
|||||||
@@ -23,7 +23,7 @@
|
|||||||
#include <openssl/provider.h>
|
#include <openssl/provider.h>
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
#include <isc/crypto.h>
|
#include <isc/fips.h>
|
||||||
#include <isc/lib.h>
|
#include <isc/lib.h>
|
||||||
#include <isc/md.h>
|
#include <isc/md.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
@@ -134,7 +134,7 @@ main(int argc, char **argv) {
|
|||||||
return 1;
|
return 1;
|
||||||
#endif
|
#endif
|
||||||
#else
|
#else
|
||||||
if (isc_crypto_fips_mode()) {
|
if (isc_fips_mode()) {
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
return 0;
|
return 0;
|
||||||
#else
|
#else
|
||||||
@@ -149,7 +149,7 @@ main(int argc, char **argv) {
|
|||||||
#if defined(ENABLE_FIPS_MODE)
|
#if defined(ENABLE_FIPS_MODE)
|
||||||
return 0;
|
return 0;
|
||||||
#else
|
#else
|
||||||
return isc_crypto_fips_mode() ? 0 : 1;
|
return isc_fips_mode() ? 0 : 1;
|
||||||
#endif
|
#endif
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1,52 +0,0 @@
|
|||||||
/*
|
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
*
|
|
||||||
* SPDX-License-Identifier: MPL-2.0
|
|
||||||
*
|
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
|
||||||
|
|
||||||
options {
|
|
||||||
query-source address 10.53.0.5;
|
|
||||||
notify-source 10.53.0.5;
|
|
||||||
transfer-source 10.53.0.5;
|
|
||||||
port @PORT@;
|
|
||||||
directory ".";
|
|
||||||
pid-file "named.pid";
|
|
||||||
listen-on { 10.53.0.5; };
|
|
||||||
listen-on-v6 { none; };
|
|
||||||
recursion yes;
|
|
||||||
dnssec-validation yes;
|
|
||||||
notify yes;
|
|
||||||
stale-answer-enable yes;
|
|
||||||
stale-cache-enable yes;
|
|
||||||
stale-answer-client-timeout 0;
|
|
||||||
/* max-clients-per-query < clients-per-query */
|
|
||||||
clients-per-query 10;
|
|
||||||
max-clients-per-query 5;
|
|
||||||
};
|
|
||||||
|
|
||||||
trust-anchors { };
|
|
||||||
|
|
||||||
server 10.53.0.4 {
|
|
||||||
edns no;
|
|
||||||
};
|
|
||||||
|
|
||||||
key rndc_key {
|
|
||||||
secret "1234abcd8765";
|
|
||||||
algorithm @DEFAULT_HMAC@;
|
|
||||||
};
|
|
||||||
|
|
||||||
controls {
|
|
||||||
inet 10.53.0.5 port @CONTROLPORT@ allow { any; } keys { rndc_key; };
|
|
||||||
};
|
|
||||||
|
|
||||||
zone "." {
|
|
||||||
type hint;
|
|
||||||
file "root.hint";
|
|
||||||
};
|
|
||||||
@@ -328,14 +328,5 @@ echo_i "$zspill clients spilled (expected $expected)"
|
|||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|
||||||
n=$((n + 1))
|
|
||||||
echo_i "checking a warning is logged if max-clients-per-query < clients-per-query ($n)"
|
|
||||||
ret=0
|
|
||||||
copy_setports ns5/named3.conf.in ns5/named.conf
|
|
||||||
rndc_reconfig ns5 10.53.0.5
|
|
||||||
wait_for_message ns5/named.run "configured clients-per-query (10) exceeds max-clients-per-query (5); automatically adjusting max-clients-per-query to (10)" || ret=1
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
|
||||||
status=$((status + ret))
|
|
||||||
|
|
||||||
echo_i "exit status: $status"
|
echo_i "exit status: $status"
|
||||||
[ $status -eq 0 ] || exit 1
|
[ $status -eq 0 ] || exit 1
|
||||||
|
|||||||
@@ -224,20 +224,6 @@ class DnsProtocol(enum.Enum):
|
|||||||
TCP = enum.auto()
|
TCP = enum.auto()
|
||||||
|
|
||||||
|
|
||||||
@dataclass(frozen=True)
|
|
||||||
class Peer:
|
|
||||||
"""
|
|
||||||
Pretty-printed connection endpoint.
|
|
||||||
"""
|
|
||||||
|
|
||||||
host: str
|
|
||||||
port: int
|
|
||||||
|
|
||||||
def __str__(self) -> str:
|
|
||||||
host = f"[{self.host}]" if ":" in self.host else self.host
|
|
||||||
return f"{host}:{self.port}"
|
|
||||||
|
|
||||||
|
|
||||||
@dataclass
|
@dataclass
|
||||||
class QueryContext:
|
class QueryContext:
|
||||||
"""
|
"""
|
||||||
@@ -246,7 +232,7 @@ class QueryContext:
|
|||||||
|
|
||||||
query: dns.message.Message
|
query: dns.message.Message
|
||||||
response: dns.message.Message
|
response: dns.message.Message
|
||||||
peer: Peer
|
peer: Tuple[str, int]
|
||||||
protocol: DnsProtocol
|
protocol: DnsProtocol
|
||||||
zone: Optional[dns.zone.Zone] = None
|
zone: Optional[dns.zone.Zone] = None
|
||||||
soa: Optional[dns.rrset.RRset] = None
|
soa: Optional[dns.rrset.RRset] = None
|
||||||
@@ -527,110 +513,56 @@ class AsyncDnsServer(AsyncServer):
|
|||||||
self._zone_tree.add(zone)
|
self._zone_tree.add(zone)
|
||||||
|
|
||||||
async def _handle_udp(
|
async def _handle_udp(
|
||||||
self, wire: bytes, addr: Tuple[str, int], transport: asyncio.DatagramTransport
|
self, wire: bytes, peer: Tuple[str, int], transport: asyncio.DatagramTransport
|
||||||
) -> None:
|
) -> None:
|
||||||
logging.debug("Received UDP message: %s", wire.hex())
|
logging.debug("Received UDP message: %s", wire.hex())
|
||||||
peer = Peer(addr[0], addr[1])
|
|
||||||
responses = self._handle_query(wire, peer, DnsProtocol.UDP)
|
responses = self._handle_query(wire, peer, DnsProtocol.UDP)
|
||||||
async for response in responses:
|
async for response in responses:
|
||||||
transport.sendto(response, addr)
|
transport.sendto(response, peer)
|
||||||
|
|
||||||
async def _handle_tcp(
|
async def _handle_tcp(
|
||||||
self, reader: asyncio.StreamReader, writer: asyncio.StreamWriter
|
self, reader: asyncio.StreamReader, writer: asyncio.StreamWriter
|
||||||
) -> None:
|
) -> None:
|
||||||
peer_info = writer.get_extra_info("peername")
|
wire_length_bytes = await reader.read(2)
|
||||||
peer = Peer(peer_info[0], peer_info[1])
|
|
||||||
logging.debug("Accepted TCP connection from %s", peer)
|
|
||||||
|
|
||||||
while True:
|
|
||||||
try:
|
|
||||||
wire = await self._read_tcp_query(reader, peer)
|
|
||||||
if not wire:
|
|
||||||
break
|
|
||||||
await self._send_tcp_response(writer, peer, wire)
|
|
||||||
except ConnectionResetError:
|
|
||||||
logging.error("TCP connection from %s reset by peer", peer)
|
|
||||||
return
|
|
||||||
|
|
||||||
logging.debug("Closing TCP connection from %s", peer)
|
|
||||||
writer.close()
|
|
||||||
await writer.wait_closed()
|
|
||||||
|
|
||||||
async def _read_tcp_query(
|
|
||||||
self, reader: asyncio.StreamReader, peer: Peer
|
|
||||||
) -> Optional[bytes]:
|
|
||||||
wire_length = await self._read_tcp_query_wire_length(reader, peer)
|
|
||||||
if not wire_length:
|
|
||||||
return None
|
|
||||||
|
|
||||||
return await self._read_tcp_query_wire(reader, peer, wire_length)
|
|
||||||
|
|
||||||
async def _read_tcp_query_wire_length(
|
|
||||||
self, reader: asyncio.StreamReader, peer: Peer
|
|
||||||
) -> Optional[int]:
|
|
||||||
logging.debug("Receiving TCP message length from %s...", peer)
|
|
||||||
|
|
||||||
wire_length_bytes = await self._read_tcp_octets(reader, peer, 2)
|
|
||||||
if not wire_length_bytes:
|
|
||||||
return None
|
|
||||||
|
|
||||||
(wire_length,) = struct.unpack("!H", wire_length_bytes)
|
(wire_length,) = struct.unpack("!H", wire_length_bytes)
|
||||||
|
logging.debug("Receiving TCP message (%d octets)...", wire_length)
|
||||||
|
|
||||||
return wire_length
|
wire = await reader.read(wire_length)
|
||||||
|
full_message = wire_length_bytes + wire
|
||||||
|
logging.debug("Received complete TCP message: %s", full_message.hex())
|
||||||
|
|
||||||
async def _read_tcp_query_wire(
|
peer = writer.get_extra_info("peername")
|
||||||
self, reader: asyncio.StreamReader, peer: Peer, wire_length: int
|
|
||||||
) -> Optional[bytes]:
|
|
||||||
logging.debug("Receiving TCP message (%d octets) from %s...", wire_length, peer)
|
|
||||||
|
|
||||||
wire = await self._read_tcp_octets(reader, peer, wire_length)
|
|
||||||
if not wire:
|
|
||||||
return None
|
|
||||||
|
|
||||||
logging.debug("Received complete TCP message from %s: %s", peer, wire.hex())
|
|
||||||
|
|
||||||
return wire
|
|
||||||
|
|
||||||
async def _read_tcp_octets(
|
|
||||||
self, reader: asyncio.StreamReader, peer: Peer, expected: int
|
|
||||||
) -> Optional[bytes]:
|
|
||||||
buffer = b""
|
|
||||||
|
|
||||||
while len(buffer) < expected:
|
|
||||||
chunk = await reader.read(expected - len(buffer))
|
|
||||||
if not chunk:
|
|
||||||
if buffer:
|
|
||||||
logging.debug(
|
|
||||||
"Received short TCP message (%d octets) from %s: %s",
|
|
||||||
len(buffer),
|
|
||||||
peer,
|
|
||||||
buffer.hex(),
|
|
||||||
)
|
|
||||||
else:
|
|
||||||
logging.debug("Received disconnect from %s", peer)
|
|
||||||
return None
|
|
||||||
|
|
||||||
logging.debug("Received %d TCP octets from %s", len(chunk), peer)
|
|
||||||
buffer += chunk
|
|
||||||
|
|
||||||
return buffer
|
|
||||||
|
|
||||||
async def _send_tcp_response(
|
|
||||||
self, writer: asyncio.StreamWriter, peer: Peer, wire: bytes
|
|
||||||
) -> None:
|
|
||||||
responses = self._handle_query(wire, peer, DnsProtocol.TCP)
|
responses = self._handle_query(wire, peer, DnsProtocol.TCP)
|
||||||
async for response in responses:
|
async for response in responses:
|
||||||
writer.write(response)
|
writer.write(response)
|
||||||
await writer.drain()
|
try:
|
||||||
|
await writer.drain()
|
||||||
|
except ConnectionResetError:
|
||||||
|
logging.error(
|
||||||
|
"TCP connection from %s reset by peer", self._format_peer(peer)
|
||||||
|
)
|
||||||
|
return
|
||||||
|
|
||||||
def _log_query(self, qctx: QueryContext, peer: Peer, protocol: DnsProtocol) -> None:
|
writer.close()
|
||||||
|
await writer.wait_closed()
|
||||||
|
|
||||||
|
def _format_peer(self, peer: Tuple[str, int]) -> str:
|
||||||
|
host = peer[0]
|
||||||
|
port = peer[1]
|
||||||
|
if "::" in host:
|
||||||
|
host = f"[{host}]"
|
||||||
|
return f"{host}:{port}"
|
||||||
|
|
||||||
|
def _log_query(
|
||||||
|
self, qctx: QueryContext, peer: Tuple[str, int], protocol: DnsProtocol
|
||||||
|
) -> None:
|
||||||
logging.info(
|
logging.info(
|
||||||
"Received %s/%s/%s (ID=%d) query from %s (%s)",
|
"Received %s/%s/%s (ID=%d) query from %s (%s)",
|
||||||
qctx.qname.to_text(omit_final_dot=True),
|
qctx.qname.to_text(omit_final_dot=True),
|
||||||
dns.rdataclass.to_text(qctx.qclass),
|
dns.rdataclass.to_text(qctx.qclass),
|
||||||
dns.rdatatype.to_text(qctx.qtype),
|
dns.rdatatype.to_text(qctx.qtype),
|
||||||
qctx.query.id,
|
qctx.query.id,
|
||||||
peer,
|
self._format_peer(peer),
|
||||||
protocol.name,
|
protocol.name,
|
||||||
)
|
)
|
||||||
logging.debug(
|
logging.debug(
|
||||||
@@ -641,14 +573,14 @@ class AsyncDnsServer(AsyncServer):
|
|||||||
self,
|
self,
|
||||||
qctx: QueryContext,
|
qctx: QueryContext,
|
||||||
response: Optional[Union[dns.message.Message, bytes]],
|
response: Optional[Union[dns.message.Message, bytes]],
|
||||||
peer: Peer,
|
peer: Tuple[str, int],
|
||||||
protocol: DnsProtocol,
|
protocol: DnsProtocol,
|
||||||
) -> None:
|
) -> None:
|
||||||
if not response:
|
if not response:
|
||||||
logging.info(
|
logging.info(
|
||||||
"Not sending a response to query (ID=%d) from %s (%s)",
|
"Not sending a response to query (ID=%d) from %s (%s)",
|
||||||
qctx.query.id,
|
qctx.query.id,
|
||||||
peer,
|
self._format_peer(peer),
|
||||||
protocol.name,
|
protocol.name,
|
||||||
)
|
)
|
||||||
return
|
return
|
||||||
@@ -674,7 +606,7 @@ class AsyncDnsServer(AsyncServer):
|
|||||||
len(response.authority),
|
len(response.authority),
|
||||||
len(response.additional),
|
len(response.additional),
|
||||||
qctx.query.id,
|
qctx.query.id,
|
||||||
peer,
|
self._format_peer(peer),
|
||||||
protocol.name,
|
protocol.name,
|
||||||
)
|
)
|
||||||
logging.debug(
|
logging.debug(
|
||||||
@@ -686,13 +618,13 @@ class AsyncDnsServer(AsyncServer):
|
|||||||
"Sending response (%d bytes) to a query (ID=%d) from %s (%s)",
|
"Sending response (%d bytes) to a query (ID=%d) from %s (%s)",
|
||||||
len(response),
|
len(response),
|
||||||
qctx.query.id,
|
qctx.query.id,
|
||||||
peer,
|
self._format_peer(peer),
|
||||||
protocol.name,
|
protocol.name,
|
||||||
)
|
)
|
||||||
logging.debug("[OUT] %s", response.hex())
|
logging.debug("[OUT] %s", response.hex())
|
||||||
|
|
||||||
async def _handle_query(
|
async def _handle_query(
|
||||||
self, wire: bytes, peer: Peer, protocol: DnsProtocol
|
self, wire: bytes, peer: Tuple[str, int], protocol: DnsProtocol
|
||||||
) -> AsyncGenerator[bytes, None]:
|
) -> AsyncGenerator[bytes, None]:
|
||||||
"""
|
"""
|
||||||
Yield wire data to send as a response over the established transport.
|
Yield wire data to send as a response over the established transport.
|
||||||
|
|||||||
@@ -130,7 +130,7 @@ $KEYGEN -G -k rsasha256 -l policies/kasp.conf $zone >keygen.out.$zone.2 2>&1
|
|||||||
zone="multisigner-model2.kasp"
|
zone="multisigner-model2.kasp"
|
||||||
echo_i "setting up zone: $zone"
|
echo_i "setting up zone: $zone"
|
||||||
KSK=$($KEYGEN -a $DEFAULT_ALGORITHM -f KSK -L 3600 -M 32768:65535 $zone 2>keygen.out.$zone.1)
|
KSK=$($KEYGEN -a $DEFAULT_ALGORITHM -f KSK -L 3600 -M 32768:65535 $zone 2>keygen.out.$zone.1)
|
||||||
ZSK=$($KEYGEN -a $DEFAULT_ALGORITHM -L 3600 -M 32768:65535 $zone 2>keygen.out.$zone.2)
|
ZSK=$($KEYGEN -a $DEFAULT_ALGORITHM -L 3600 $zone -M 32768:65535 2>keygen.out.$zone.2)
|
||||||
cat "${KSK}.key" | grep -v ";.*" >>"${zone}.db"
|
cat "${KSK}.key" | grep -v ";.*" >>"${zone}.db"
|
||||||
cat "${ZSK}.key" | grep -v ";.*" >>"${zone}.db"
|
cat "${ZSK}.key" | grep -v ";.*" >>"${zone}.db"
|
||||||
# Import the ZSK sets of the other providers into their DNSKEY RRset.
|
# Import the ZSK sets of the other providers into their DNSKEY RRset.
|
||||||
@@ -350,9 +350,10 @@ setup step2.enable-dnssec.autosign
|
|||||||
TpubN="now-900s"
|
TpubN="now-900s"
|
||||||
# RRSIG TTL: 12 hour (43200 seconds)
|
# RRSIG TTL: 12 hour (43200 seconds)
|
||||||
# zone-propagation-delay: 5 minutes (300 seconds)
|
# zone-propagation-delay: 5 minutes (300 seconds)
|
||||||
|
# retire-safety: 20 minutes (1200 seconds)
|
||||||
# Already passed time: -900 seconds
|
# Already passed time: -900 seconds
|
||||||
# Total: 42600 seconds
|
# Total: 43800 seconds
|
||||||
TsbmN="now+42600s"
|
TsbmN="now+43800s"
|
||||||
keytimes="-P ${TpubN} -P sync ${TsbmN} -A ${TpubN}"
|
keytimes="-P ${TpubN} -P sync ${TsbmN} -A ${TpubN}"
|
||||||
CSK=$($KEYGEN -k enable-dnssec -l policies/autosign.conf $keytimes $zone 2>keygen.out.$zone.1)
|
CSK=$($KEYGEN -k enable-dnssec -l policies/autosign.conf $keytimes $zone 2>keygen.out.$zone.1)
|
||||||
$SETTIME -s -g $O -k $R $TpubN -r $R $TpubN -d $H $TpubN -z $R $TpubN "$CSK" >settime.out.$zone.1 2>&1
|
$SETTIME -s -g $O -k $R $TpubN -r $R $TpubN -d $H $TpubN -z $R $TpubN "$CSK" >settime.out.$zone.1 2>&1
|
||||||
@@ -364,10 +365,10 @@ $SIGNER -S -z -x -s now-1h -e now+30d -o $zone -O raw -f "${zonefile}.signed" $i
|
|||||||
# Step 3:
|
# Step 3:
|
||||||
# The zone signatures have been published long enough to become OMNIPRESENT.
|
# The zone signatures have been published long enough to become OMNIPRESENT.
|
||||||
setup step3.enable-dnssec.autosign
|
setup step3.enable-dnssec.autosign
|
||||||
# Passed time since publications: 42600 + 900 = 43500 seconds.
|
# Passed time since publications: 43800 + 900 = 44700 seconds.
|
||||||
TpubN="now-43500s"
|
TpubN="now-44700s"
|
||||||
# The key is secure for using in chain of trust when the DNSKEY is OMNIPRESENT.
|
# The key is secure for using in chain of trust when the DNSKEY is OMNIPRESENT.
|
||||||
TcotN="now-42600s"
|
TcotN="now-43800s"
|
||||||
# We can submit the DS now.
|
# We can submit the DS now.
|
||||||
TsbmN="now"
|
TsbmN="now"
|
||||||
keytimes="-P ${TpubN} -P sync ${TsbmN} -A ${TpubN}"
|
keytimes="-P ${TpubN} -P sync ${TsbmN} -A ${TpubN}"
|
||||||
|
|||||||
@@ -127,9 +127,9 @@ setup step2.algorithm-roll.kasp
|
|||||||
# The time passed since the new algorithm keys have been introduced is 3 hours.
|
# The time passed since the new algorithm keys have been introduced is 3 hours.
|
||||||
TactN="now-3h"
|
TactN="now-3h"
|
||||||
TpubN1="now-3h"
|
TpubN1="now-3h"
|
||||||
# Tsbm(N+1) = TpubN1 + Ipub = now + TTLsig + Dprp =
|
# Tsbm(N+1) = TpubN1 + Ipub = now + TTLsig + Dprp + publish-safety =
|
||||||
# now - 3h + 6h + 1h = now + 4h
|
# now - 3h + 6h + 1h + 1h = now + 5h
|
||||||
TsbmN1="now+4h"
|
TsbmN1="now+5h"
|
||||||
ksk1times="-P ${TactN} -A ${TactN} -P sync ${TactN} -I now"
|
ksk1times="-P ${TactN} -A ${TactN} -P sync ${TactN} -I now"
|
||||||
zsk1times="-P ${TactN} -A ${TactN} -I now"
|
zsk1times="-P ${TactN} -A ${TactN} -I now"
|
||||||
ksk2times="-P ${TpubN1} -A ${TpubN1} -P sync ${TsbmN1}"
|
ksk2times="-P ${TpubN1} -A ${TpubN1} -P sync ${TsbmN1}"
|
||||||
@@ -156,11 +156,11 @@ $SIGNER -S -x -s now-1h -e now+2w -o $zone -O raw -f "${zonefile}.signed" $infil
|
|||||||
# Step 3:
|
# Step 3:
|
||||||
# The zone signatures are also OMNIPRESENT.
|
# The zone signatures are also OMNIPRESENT.
|
||||||
setup step3.algorithm-roll.kasp
|
setup step3.algorithm-roll.kasp
|
||||||
# The time passed since the new algorithm keys have been introduced is 7 hours.
|
# The time passed since the new algorithm keys have been introduced is 9 hours.
|
||||||
TactN="now-7h"
|
TactN="now-9h"
|
||||||
TretN="now-3h"
|
TretN="now-6h"
|
||||||
TpubN1="now-7h"
|
TpubN1="now-9h"
|
||||||
TsbmN1="now"
|
TsbmN1="now-1h"
|
||||||
ksk1times="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
|
ksk1times="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
|
||||||
zsk1times="-P ${TactN} -A ${TactN} -I ${TretN}"
|
zsk1times="-P ${TactN} -A ${TactN} -I ${TretN}"
|
||||||
ksk2times="-P ${TpubN1} -A ${TpubN1} -P sync ${TsbmN1}"
|
ksk2times="-P ${TpubN1} -A ${TpubN1} -P sync ${TsbmN1}"
|
||||||
@@ -188,11 +188,11 @@ $SIGNER -S -x -s now-1h -e now+2w -o $zone -O raw -f "${zonefile}.signed" $infil
|
|||||||
# The DS is swapped and can become OMNIPRESENT.
|
# The DS is swapped and can become OMNIPRESENT.
|
||||||
setup step4.algorithm-roll.kasp
|
setup step4.algorithm-roll.kasp
|
||||||
# The time passed since the DS has been swapped is 29 hours.
|
# The time passed since the DS has been swapped is 29 hours.
|
||||||
TactN="now-36h"
|
TactN="now-38h"
|
||||||
TretN="now-33h"
|
TretN="now-35h"
|
||||||
TpubN1="now-36h"
|
TpubN1="now-38h"
|
||||||
TsbmN1="now-29h"
|
TsbmN1="now-30h"
|
||||||
TactN1="now-27h"
|
TactN1="now-29h"
|
||||||
ksk1times="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
|
ksk1times="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
|
||||||
zsk1times="-P ${TactN} -A ${TactN} -I ${TretN}"
|
zsk1times="-P ${TactN} -A ${TactN} -I ${TretN}"
|
||||||
ksk2times="-P ${TpubN1} -A ${TpubN1} -P sync ${TsbmN1}"
|
ksk2times="-P ${TpubN1} -A ${TpubN1} -P sync ${TsbmN1}"
|
||||||
@@ -220,12 +220,12 @@ $SIGNER -S -x -s now-1h -e now+2w -o $zone -O raw -f "${zonefile}.signed" $infil
|
|||||||
# The DNSKEY is removed long enough to be HIDDEN.
|
# The DNSKEY is removed long enough to be HIDDEN.
|
||||||
setup step5.algorithm-roll.kasp
|
setup step5.algorithm-roll.kasp
|
||||||
# The time passed since the DNSKEY has been removed is 2 hours.
|
# The time passed since the DNSKEY has been removed is 2 hours.
|
||||||
TactN="now-38h"
|
TactN="now-40h"
|
||||||
TretN="now-35h"
|
TretN="now-37h"
|
||||||
TremN="now-2h"
|
TremN="now-2h"
|
||||||
TpubN1="now-38h"
|
TpubN1="now-40h"
|
||||||
TsbmN1="now-31h"
|
TsbmN1="now-32h"
|
||||||
TactN1="now-29h"
|
TactN1="now-31h"
|
||||||
ksk1times="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
|
ksk1times="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
|
||||||
zsk1times="-P ${TactN} -A ${TactN} -I ${TretN}"
|
zsk1times="-P ${TactN} -A ${TactN} -I ${TretN}"
|
||||||
ksk2times="-P ${TpubN1} -A ${TpubN1} -P sync ${TsbmN1}"
|
ksk2times="-P ${TpubN1} -A ${TpubN1} -P sync ${TsbmN1}"
|
||||||
@@ -253,13 +253,13 @@ $SIGNER -S -x -s now-1h -e now+2w -o $zone -O raw -f "${zonefile}.signed" $infil
|
|||||||
# The RRSIGs have been removed long enough to be HIDDEN.
|
# The RRSIGs have been removed long enough to be HIDDEN.
|
||||||
setup step6.algorithm-roll.kasp
|
setup step6.algorithm-roll.kasp
|
||||||
# Additional time passed: 7h.
|
# Additional time passed: 7h.
|
||||||
TactN="now-45h"
|
TactN="now-47h"
|
||||||
TretN="now-42h"
|
TretN="now-44h"
|
||||||
TremN="now-7h"
|
TremN="now-7h"
|
||||||
TpubN1="now-45h"
|
TpubN1="now-47h"
|
||||||
TsbmN1="now-38h"
|
TsbmN1="now-39h"
|
||||||
TactN1="now-36h"
|
TactN1="now-38h"
|
||||||
TdeaN="now-7h"
|
TdeaN="now-9h"
|
||||||
ksk1times="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
|
ksk1times="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
|
||||||
zsk1times="-P ${TactN} -A ${TactN} -I ${TretN}"
|
zsk1times="-P ${TactN} -A ${TactN} -I ${TretN}"
|
||||||
ksk2times="-P ${TpubN1} -A ${TpubN1} -P sync ${TsbmN1}"
|
ksk2times="-P ${TpubN1} -A ${TpubN1} -P sync ${TsbmN1}"
|
||||||
@@ -324,11 +324,11 @@ $SIGNER -S -x -z -s now-1h -e now+2w -o $zone -O raw -f "${zonefile}.signed" $in
|
|||||||
# Step 3:
|
# Step 3:
|
||||||
# The zone signatures are also OMNIPRESENT.
|
# The zone signatures are also OMNIPRESENT.
|
||||||
setup step3.csk-algorithm-roll.kasp
|
setup step3.csk-algorithm-roll.kasp
|
||||||
# The time passed since the new algorithm keys have been introduced is 7 hours.
|
# The time passed since the new algorithm keys have been introduced is 9 hours.
|
||||||
TactN="now-7h"
|
TactN="now-9h"
|
||||||
TretN="now-3h"
|
TretN="now-6h"
|
||||||
TpubN1="now-7h"
|
TpubN1="now-9h"
|
||||||
TactN1="now-3h"
|
TactN1="now-6h"
|
||||||
csktimes="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
|
csktimes="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
|
||||||
newtimes="-P ${TpubN1} -A ${TpubN1}"
|
newtimes="-P ${TpubN1} -A ${TpubN1}"
|
||||||
CSK1=$($KEYGEN -k csk-algoroll -l policies/csk1.conf $csktimes $zone 2>keygen.out.$zone.1)
|
CSK1=$($KEYGEN -k csk-algoroll -l policies/csk1.conf $csktimes $zone 2>keygen.out.$zone.1)
|
||||||
@@ -347,10 +347,10 @@ $SIGNER -S -x -z -s now-1h -e now+2w -o $zone -O raw -f "${zonefile}.signed" $in
|
|||||||
# The DS is swapped and can become OMNIPRESENT.
|
# The DS is swapped and can become OMNIPRESENT.
|
||||||
setup step4.csk-algorithm-roll.kasp
|
setup step4.csk-algorithm-roll.kasp
|
||||||
# The time passed since the DS has been swapped is 29 hours.
|
# The time passed since the DS has been swapped is 29 hours.
|
||||||
TactN="now-36h"
|
TactN="now-38h"
|
||||||
TretN="now-33h"
|
TretN="now-35h"
|
||||||
TpubN1="now-36h"
|
TpubN1="now-38h"
|
||||||
TactN1="now-33h"
|
TactN1="now-35h"
|
||||||
TsubN1="now-29h"
|
TsubN1="now-29h"
|
||||||
csktimes="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
|
csktimes="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
|
||||||
newtimes="-P ${TpubN1} -A ${TpubN1}"
|
newtimes="-P ${TpubN1} -A ${TpubN1}"
|
||||||
@@ -370,11 +370,11 @@ $SIGNER -S -x -z -s now-1h -e now+2w -o $zone -O raw -f "${zonefile}.signed" $in
|
|||||||
# The DNSKEY is removed long enough to be HIDDEN.
|
# The DNSKEY is removed long enough to be HIDDEN.
|
||||||
setup step5.csk-algorithm-roll.kasp
|
setup step5.csk-algorithm-roll.kasp
|
||||||
# The time passed since the DNSKEY has been removed is 2 hours.
|
# The time passed since the DNSKEY has been removed is 2 hours.
|
||||||
TactN="now-38h"
|
TactN="now-40h"
|
||||||
TretN="now-35h"
|
TretN="now-37h"
|
||||||
TremN="now-2h"
|
TremN="now-2h"
|
||||||
TpubN1="now-38h"
|
TpubN1="now-40h"
|
||||||
TactN1="now-35h"
|
TactN1="now-37h"
|
||||||
TsubN1="now-31h"
|
TsubN1="now-31h"
|
||||||
csktimes="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
|
csktimes="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
|
||||||
newtimes="-P ${TpubN1} -A ${TpubN1}"
|
newtimes="-P ${TpubN1} -A ${TpubN1}"
|
||||||
@@ -394,12 +394,12 @@ $SIGNER -S -x -z -s now-1h -e now+2w -o $zone -O raw -f "${zonefile}.signed" $in
|
|||||||
# The RRSIGs have been removed long enough to be HIDDEN.
|
# The RRSIGs have been removed long enough to be HIDDEN.
|
||||||
setup step6.csk-algorithm-roll.kasp
|
setup step6.csk-algorithm-roll.kasp
|
||||||
# Additional time passed: 7h.
|
# Additional time passed: 7h.
|
||||||
TactN="now-45h"
|
TactN="now-47h"
|
||||||
TretN="now-42h"
|
TretN="now-44h"
|
||||||
TdeaN="now-9h"
|
TdeaN="now-9h"
|
||||||
TremN="now-7h"
|
TremN="now-7h"
|
||||||
TpubN1="now-45h"
|
TpubN1="now-47h"
|
||||||
TactN1="now-42h"
|
TactN1="now-44h"
|
||||||
TsubN1="now-38h"
|
TsubN1="now-38h"
|
||||||
csktimes="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
|
csktimes="-P ${TactN} -A ${TactN} -P sync ${TactN} -I ${TretN}"
|
||||||
newtimes="-P ${TpubN1} -A ${TpubN1}"
|
newtimes="-P ${TpubN1} -A ${TpubN1}"
|
||||||
|
|||||||
+125
-120
@@ -275,8 +275,9 @@ set_keytimes_csk_policy() {
|
|||||||
set_keytime "KEY1" "ACTIVE" "${created}"
|
set_keytime "KEY1" "ACTIVE" "${created}"
|
||||||
# The DS can be published if the DNSKEY and RRSIG records are
|
# The DS can be published if the DNSKEY and RRSIG records are
|
||||||
# OMNIPRESENT. This happens after max-zone-ttl (1d) plus
|
# OMNIPRESENT. This happens after max-zone-ttl (1d) plus
|
||||||
# zone-propagation-delay (300s) = 86400 + 300 = 86700.
|
# publish-safety (1h) plus zone-propagation-delay (300s) =
|
||||||
set_addkeytime "KEY1" "SYNCPUBLISH" "${created}" 86700
|
# 86400 + 3600 + 300 = 90300.
|
||||||
|
set_addkeytime "KEY1" "SYNCPUBLISH" "${created}" 90300
|
||||||
# Key lifetime is unlimited, so not setting RETIRED and REMOVED.
|
# Key lifetime is unlimited, so not setting RETIRED and REMOVED.
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -768,8 +769,9 @@ set_keytimes_algorithm_policy() {
|
|||||||
|
|
||||||
# The DS can be published if the DNSKEY and RRSIG records are
|
# The DS can be published if the DNSKEY and RRSIG records are
|
||||||
# OMNIPRESENT. This happens after max-zone-ttl (1d) plus
|
# OMNIPRESENT. This happens after max-zone-ttl (1d) plus
|
||||||
# zone-propagation-delay (300s) = 86400 + 300 = 86700.
|
# publish-safety (1h) plus zone-propagation-delay (300s) =
|
||||||
set_addkeytime "KEY1" "SYNCPUBLISH" "${published}" 86700
|
# 86400 + 3600 + 300 = 90300.
|
||||||
|
set_addkeytime "KEY1" "SYNCPUBLISH" "${published}" 90300
|
||||||
# Key lifetime is 10 years, 315360000 seconds.
|
# Key lifetime is 10 years, 315360000 seconds.
|
||||||
set_addkeytime "KEY1" "RETIRED" "${published}" 315360000
|
set_addkeytime "KEY1" "RETIRED" "${published}" 315360000
|
||||||
# The key is removed after the retire time plus DS TTL (1d),
|
# The key is removed after the retire time plus DS TTL (1d),
|
||||||
@@ -1718,10 +1720,10 @@ published=$(awk '{print $3}' <published.test${n}.key1)
|
|||||||
set_keytime "KEY1" "PUBLISHED" "${published}"
|
set_keytime "KEY1" "PUBLISHED" "${published}"
|
||||||
set_keytime "KEY1" "ACTIVE" "${published}"
|
set_keytime "KEY1" "ACTIVE" "${published}"
|
||||||
published=$(key_get KEY1 PUBLISHED)
|
published=$(key_get KEY1 PUBLISHED)
|
||||||
# The DS can be published if the zone is fully signed.
|
# The DS can be published if the DNSKEY and RRSIG records are OMNIPRESENT.
|
||||||
# This happens after max-zone-ttl (1d) plus
|
# This happens after max-zone-ttl (1d) plus publish-safety (1h) plus
|
||||||
# zone-propagation-delay (300s) = 86400 + 300 = 86700.
|
# zone-propagation-delay (300s) = 86400 + 3600 + 300 = 90300.
|
||||||
set_addkeytime "KEY1" "SYNCPUBLISH" "${published}" 86700
|
set_addkeytime "KEY1" "SYNCPUBLISH" "${published}" 90300
|
||||||
# Key lifetime is 6 months, 315360000 seconds.
|
# Key lifetime is 6 months, 315360000 seconds.
|
||||||
set_addkeytime "KEY1" "RETIRED" "${published}" 16070400
|
set_addkeytime "KEY1" "RETIRED" "${published}" 16070400
|
||||||
# The key is removed after the retire time plus DS TTL (1d), parent
|
# The key is removed after the retire time plus DS TTL (1d), parent
|
||||||
@@ -2484,9 +2486,9 @@ set_keytime "KEY1" "PUBLISHED" "${created}"
|
|||||||
set_keytime "KEY1" "ACTIVE" "${created}"
|
set_keytime "KEY1" "ACTIVE" "${created}"
|
||||||
# - The DS can be published if the DNSKEY and RRSIG records are
|
# - The DS can be published if the DNSKEY and RRSIG records are
|
||||||
# OMNIPRESENT. This happens after max-zone-ttl (12h) plus
|
# OMNIPRESENT. This happens after max-zone-ttl (12h) plus
|
||||||
# plus zone-propagation-delay (5m) =
|
# publish-safety (5m) plus zone-propagation-delay (5m) =
|
||||||
# 43200 + 300 = 43500.
|
# 43200 + 300 + 300 = 43800.
|
||||||
set_addkeytime "KEY1" "SYNCPUBLISH" "${created}" 43500
|
set_addkeytime "KEY1" "SYNCPUBLISH" "${created}" 43800
|
||||||
# - Key lifetime is unlimited, so not setting RETIRED and REMOVED.
|
# - Key lifetime is unlimited, so not setting RETIRED and REMOVED.
|
||||||
|
|
||||||
# Various signing policy checks.
|
# Various signing policy checks.
|
||||||
@@ -2554,7 +2556,7 @@ check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
|
|||||||
created=$(key_get KEY1 CREATED)
|
created=$(key_get KEY1 CREATED)
|
||||||
set_addkeytime "KEY1" "PUBLISHED" "${created}" -900
|
set_addkeytime "KEY1" "PUBLISHED" "${created}" -900
|
||||||
set_addkeytime "KEY1" "ACTIVE" "${created}" -900
|
set_addkeytime "KEY1" "ACTIVE" "${created}" -900
|
||||||
set_addkeytime "KEY1" "SYNCPUBLISH" "${created}" 42600
|
set_addkeytime "KEY1" "SYNCPUBLISH" "${created}" 43800
|
||||||
|
|
||||||
# Continue signing policy checks.
|
# Continue signing policy checks.
|
||||||
check_keytimes
|
check_keytimes
|
||||||
@@ -2564,8 +2566,8 @@ dnssec_verify
|
|||||||
|
|
||||||
# Next key event is when the zone signatures become OMNIPRESENT: max-zone-ttl
|
# Next key event is when the zone signatures become OMNIPRESENT: max-zone-ttl
|
||||||
# plus zone propagation delay plus retire safety minus the already elapsed
|
# plus zone propagation delay plus retire safety minus the already elapsed
|
||||||
# 900 seconds: 12h + 300s + 20m - 900 = 43500 - 900 = 42600 seconds
|
# 900 seconds: 12h + 300s + 20m - 900 = 44700 - 900 = 43800 seconds
|
||||||
check_next_key_event 42600
|
check_next_key_event 43800
|
||||||
|
|
||||||
#
|
#
|
||||||
# Zone: step3.enable-dnssec.autosign.
|
# Zone: step3.enable-dnssec.autosign.
|
||||||
@@ -2582,10 +2584,10 @@ check_keys
|
|||||||
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
|
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
|
||||||
|
|
||||||
# Set expected key times:
|
# Set expected key times:
|
||||||
# - The key was published and activated 43500 seconds ago (with settime).
|
# - The key was published and activated 44700 seconds ago (with settime).
|
||||||
created=$(key_get KEY1 CREATED)
|
created=$(key_get KEY1 CREATED)
|
||||||
set_addkeytime "KEY1" "PUBLISHED" "${created}" -43500
|
set_addkeytime "KEY1" "PUBLISHED" "${created}" -44700
|
||||||
set_addkeytime "KEY1" "ACTIVE" "${created}" -43500
|
set_addkeytime "KEY1" "ACTIVE" "${created}" -44700
|
||||||
set_keytime "KEY1" "SYNCPUBLISH" "${created}"
|
set_keytime "KEY1" "SYNCPUBLISH" "${created}"
|
||||||
|
|
||||||
# Continue signing policy checks.
|
# Continue signing policy checks.
|
||||||
@@ -2601,8 +2603,8 @@ check_cdslog "$DIR" "$ZONE" KEY1
|
|||||||
rndc_checkds "$SERVER" "$DIR" KEY1 "now" "published" "$ZONE"
|
rndc_checkds "$SERVER" "$DIR" KEY1 "now" "published" "$ZONE"
|
||||||
# Next key event is when the DS can move to the OMNIPRESENT state. This occurs
|
# Next key event is when the DS can move to the OMNIPRESENT state. This occurs
|
||||||
# when the parent propagation delay have passed, plus the DS TTL and retire
|
# when the parent propagation delay have passed, plus the DS TTL and retire
|
||||||
# safety delay: 1h + 2h = 3h = 10800 seconds
|
# safety delay: 1h + 2h + 20m = 3h20m = 12000 seconds
|
||||||
check_next_key_event 10800
|
check_next_key_event 12000
|
||||||
|
|
||||||
#
|
#
|
||||||
# Zone: step4.enable-dnssec.autosign.
|
# Zone: step4.enable-dnssec.autosign.
|
||||||
@@ -4386,9 +4388,9 @@ check_subdomain
|
|||||||
dnssec_verify
|
dnssec_verify
|
||||||
|
|
||||||
# Next key event is when the DS becomes HIDDEN. This happens after the
|
# Next key event is when the DS becomes HIDDEN. This happens after the
|
||||||
# parent propagation delay, and DS TTL:
|
# parent propagation delay, retire safety delay, and DS TTL:
|
||||||
# 1h + 1d = 25h = 90000 seconds.
|
# 1h + 1h + 1d = 26h = 93600 seconds.
|
||||||
check_next_key_event 90000
|
check_next_key_event 93600
|
||||||
|
|
||||||
#
|
#
|
||||||
# Zone: step2.going-insecure.kasp
|
# Zone: step2.going-insecure.kasp
|
||||||
@@ -4454,8 +4456,8 @@ dnssec_verify
|
|||||||
|
|
||||||
# Next key event is when the DS becomes HIDDEN. This happens after the
|
# Next key event is when the DS becomes HIDDEN. This happens after the
|
||||||
# parent propagation delay, retire safety delay, and DS TTL:
|
# parent propagation delay, retire safety delay, and DS TTL:
|
||||||
# 1h + 1d = 25h = 90000 seconds.
|
# 1h + 1h + 1d = 26h = 93600 seconds.
|
||||||
check_next_key_event 90000
|
check_next_key_event 93600
|
||||||
|
|
||||||
#
|
#
|
||||||
# Zone: step2.going-insecure-dynamic.kasp
|
# Zone: step2.going-insecure-dynamic.kasp
|
||||||
@@ -4649,11 +4651,12 @@ set_addkeytime "KEY2" "REMOVED" "${retired}" "${IretZSK}"
|
|||||||
created=$(key_get KEY3 CREATED)
|
created=$(key_get KEY3 CREATED)
|
||||||
set_keytime "KEY3" "PUBLISHED" "${created}"
|
set_keytime "KEY3" "PUBLISHED" "${created}"
|
||||||
set_keytime "KEY3" "ACTIVE" "${created}"
|
set_keytime "KEY3" "ACTIVE" "${created}"
|
||||||
# - It takes TTLsig + Dprp to propagate the zone.
|
# - It takes TTLsig + Dprp + publish-safety hours to propagate the zone.
|
||||||
# TTLsig: 6h (39600 seconds)
|
# TTLsig: 6h (39600 seconds)
|
||||||
# Dprp: 1h (3600 seconds)
|
# Dprp: 1h (3600 seconds)
|
||||||
# Ipub: 7h (25200 seconds)
|
# publish-safety: 1h (3600 seconds)
|
||||||
Ipub=25200
|
# Ipub: 8h (28800 seconds)
|
||||||
|
Ipub=28800
|
||||||
set_addkeytime "KEY3" "SYNCPUBLISH" "${created}" "${Ipub}"
|
set_addkeytime "KEY3" "SYNCPUBLISH" "${created}" "${Ipub}"
|
||||||
# - The new ZSK is published and activated.
|
# - The new ZSK is published and activated.
|
||||||
created=$(key_get KEY4 CREATED)
|
created=$(key_get KEY4 CREATED)
|
||||||
@@ -4722,12 +4725,12 @@ dnssec_verify
|
|||||||
|
|
||||||
# Next key event is when all zone signatures are signed with the new
|
# Next key event is when all zone signatures are signed with the new
|
||||||
# algorithm. This is the max-zone-ttl plus zone propagation delay
|
# algorithm. This is the max-zone-ttl plus zone propagation delay
|
||||||
# 6h + 1h. But three hours have already passed (the time it took to
|
# plus retire safety: 6h + 1h + 2h. But three hours have already passed
|
||||||
# make the DNSKEY omnipresent), so the next event should be scheduled
|
# (the time it took to make the DNSKEY omnipresent), so the next event
|
||||||
# in 4 hour: 14400 seconds. Prevent intermittent
|
# should be scheduled in 6 hour: 21600 seconds. Prevent intermittent
|
||||||
# false positives on slow platforms by subtracting the number of seconds
|
# false positives on slow platforms by subtracting the number of seconds
|
||||||
# which passed between key creation and invoking 'rndc reconfig'.
|
# which passed between key creation and invoking 'rndc reconfig'.
|
||||||
next_time=$((14400 - time_passed))
|
next_time=$((21600 - time_passed))
|
||||||
check_next_key_event $next_time
|
check_next_key_event $next_time
|
||||||
|
|
||||||
#
|
#
|
||||||
@@ -4750,28 +4753,28 @@ check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
|
|||||||
check_cdslog "$DIR" "$ZONE" KEY3
|
check_cdslog "$DIR" "$ZONE" KEY3
|
||||||
|
|
||||||
# Set expected key times:
|
# Set expected key times:
|
||||||
# - The old keys were activated 7 hours ago (25200 seconds).
|
# - The old keys were activated 9 hours ago (32400 seconds).
|
||||||
rollover_predecessor_keytimes -25200
|
rollover_predecessor_keytimes -32400
|
||||||
# - And retired 3 hours ago (10800 seconds).
|
# - And retired 6 hours ago (21600 seconds).
|
||||||
created=$(key_get KEY1 CREATED)
|
created=$(key_get KEY1 CREATED)
|
||||||
set_addkeytime "KEY1" "RETIRED" "${created}" -10800
|
set_addkeytime "KEY1" "RETIRED" "${created}" -21600
|
||||||
retired=$(key_get KEY1 RETIRED)
|
retired=$(key_get KEY1 RETIRED)
|
||||||
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretKSK}"
|
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretKSK}"
|
||||||
|
|
||||||
created=$(key_get KEY2 CREATED)
|
created=$(key_get KEY2 CREATED)
|
||||||
set_addkeytime "KEY2" "RETIRED" "${created}" -10800
|
set_addkeytime "KEY2" "RETIRED" "${created}" -21600
|
||||||
retired=$(key_get KEY2 RETIRED)
|
retired=$(key_get KEY2 RETIRED)
|
||||||
set_addkeytime "KEY2" "REMOVED" "${retired}" "${IretZSK}"
|
set_addkeytime "KEY2" "REMOVED" "${retired}" "${IretZSK}"
|
||||||
# - The new keys are published 7 hours ago.
|
# - The new keys are published 9 hours ago.
|
||||||
created=$(key_get KEY3 CREATED)
|
created=$(key_get KEY3 CREATED)
|
||||||
set_addkeytime "KEY3" "PUBLISHED" "${created}" -25200
|
set_addkeytime "KEY3" "PUBLISHED" "${created}" -32400
|
||||||
set_addkeytime "KEY3" "ACTIVE" "${created}" -25200
|
set_addkeytime "KEY3" "ACTIVE" "${created}" -32400
|
||||||
published=$(key_get KEY3 PUBLISHED)
|
published=$(key_get KEY3 PUBLISHED)
|
||||||
set_addkeytime "KEY3" "SYNCPUBLISH" "${published}" ${Ipub}
|
set_addkeytime "KEY3" "SYNCPUBLISH" "${published}" ${Ipub}
|
||||||
|
|
||||||
created=$(key_get KEY4 CREATED)
|
created=$(key_get KEY4 CREATED)
|
||||||
set_addkeytime "KEY4" "PUBLISHED" "${created}" -25200
|
set_addkeytime "KEY4" "PUBLISHED" "${created}" -32400
|
||||||
set_addkeytime "KEY4" "ACTIVE" "${created}" -25200
|
set_addkeytime "KEY4" "ACTIVE" "${created}" -32400
|
||||||
|
|
||||||
# Continue signing policy checks.
|
# Continue signing policy checks.
|
||||||
check_keytimes
|
check_keytimes
|
||||||
@@ -4784,9 +4787,9 @@ dnssec_verify
|
|||||||
rndc_checkds "$SERVER" "$DIR" KEY1 "now" "withdrawn" "$ZONE"
|
rndc_checkds "$SERVER" "$DIR" KEY1 "now" "withdrawn" "$ZONE"
|
||||||
rndc_checkds "$SERVER" "$DIR" KEY3 "now" "published" "$ZONE"
|
rndc_checkds "$SERVER" "$DIR" KEY3 "now" "published" "$ZONE"
|
||||||
# Next key event is when the DS becomes OMNIPRESENT. This happens after the
|
# Next key event is when the DS becomes OMNIPRESENT. This happens after the
|
||||||
# parent propagation delay, and DS TTL:
|
# parent propagation delay, retire safety delay, and DS TTL:
|
||||||
# 1h + 2h = 3h = 10800 seconds.
|
# 1h + 2h + 2h = 5h = 18000 seconds.
|
||||||
check_next_key_event 10800
|
check_next_key_event 18000
|
||||||
|
|
||||||
#
|
#
|
||||||
# Zone: step4.algorithm-roll.kasp
|
# Zone: step4.algorithm-roll.kasp
|
||||||
@@ -4813,29 +4816,29 @@ wait_for_done_signing
|
|||||||
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
|
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
|
||||||
|
|
||||||
# Set expected key times:
|
# Set expected key times:
|
||||||
# - The old keys were activated 36 hours ago (129600 seconds).
|
# - The old keys were activated 38 hours ago (136800 seconds).
|
||||||
rollover_predecessor_keytimes -129600
|
rollover_predecessor_keytimes -136800
|
||||||
# - And retired 33 hours ago (118800 seconds).
|
# - And retired 35 hours ago (126000 seconds).
|
||||||
created=$(key_get KEY1 CREATED)
|
created=$(key_get KEY1 CREATED)
|
||||||
set_addkeytime "KEY1" "RETIRED" "${created}" -118800
|
set_addkeytime "KEY1" "RETIRED" "${created}" -126000
|
||||||
retired=$(key_get KEY1 RETIRED)
|
retired=$(key_get KEY1 RETIRED)
|
||||||
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretKSK}"
|
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretKSK}"
|
||||||
|
|
||||||
created=$(key_get KEY2 CREATED)
|
created=$(key_get KEY2 CREATED)
|
||||||
set_addkeytime "KEY2" "RETIRED" "${created}" -118800
|
set_addkeytime "KEY2" "RETIRED" "${created}" -126000
|
||||||
retired=$(key_get KEY2 RETIRED)
|
retired=$(key_get KEY2 RETIRED)
|
||||||
set_addkeytime "KEY2" "REMOVED" "${retired}" "${IretZSK}"
|
set_addkeytime "KEY2" "REMOVED" "${retired}" "${IretZSK}"
|
||||||
|
|
||||||
# - The new keys are published 36 hours ago.
|
# - The new keys are published 38 hours ago.
|
||||||
created=$(key_get KEY3 CREATED)
|
created=$(key_get KEY3 CREATED)
|
||||||
set_addkeytime "KEY3" "PUBLISHED" "${created}" -129600
|
set_addkeytime "KEY3" "PUBLISHED" "${created}" -136800
|
||||||
set_addkeytime "KEY3" "ACTIVE" "${created}" -129600
|
set_addkeytime "KEY3" "ACTIVE" "${created}" -136800
|
||||||
published=$(key_get KEY3 PUBLISHED)
|
published=$(key_get KEY3 PUBLISHED)
|
||||||
set_addkeytime "KEY3" "SYNCPUBLISH" "${published}" ${Ipub}
|
set_addkeytime "KEY3" "SYNCPUBLISH" "${published}" ${Ipub}
|
||||||
|
|
||||||
created=$(key_get KEY4 CREATED)
|
created=$(key_get KEY4 CREATED)
|
||||||
set_addkeytime "KEY4" "PUBLISHED" "${created}" -129600
|
set_addkeytime "KEY4" "PUBLISHED" "${created}" -136800
|
||||||
set_addkeytime "KEY4" "ACTIVE" "${created}" -129600
|
set_addkeytime "KEY4" "ACTIVE" "${created}" -136800
|
||||||
|
|
||||||
# Continue signing policy checks.
|
# Continue signing policy checks.
|
||||||
check_keytimes
|
check_keytimes
|
||||||
@@ -4864,29 +4867,29 @@ wait_for_done_signing
|
|||||||
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
|
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
|
||||||
|
|
||||||
# Set expected key times:
|
# Set expected key times:
|
||||||
# - The old keys were activated 38 hours ago (136800 seconds)
|
# - The old keys were activated 40 hours ago (144000 seconds)
|
||||||
rollover_predecessor_keytimes -136800
|
rollover_predecessor_keytimes -144000
|
||||||
# - And retired 35 hours ago (126000 seconds).
|
# - And retired 37 hours ago (133200 seconds).
|
||||||
created=$(key_get KEY1 CREATED)
|
created=$(key_get KEY1 CREATED)
|
||||||
set_addkeytime "KEY1" "RETIRED" "${created}" -126000
|
set_addkeytime "KEY1" "RETIRED" "${created}" -133200
|
||||||
retired=$(key_get KEY1 RETIRED)
|
retired=$(key_get KEY1 RETIRED)
|
||||||
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretKSK}"
|
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretKSK}"
|
||||||
|
|
||||||
created=$(key_get KEY2 CREATED)
|
created=$(key_get KEY2 CREATED)
|
||||||
set_addkeytime "KEY2" "RETIRED" "${created}" -126000
|
set_addkeytime "KEY2" "RETIRED" "${created}" -133200
|
||||||
retired=$(key_get KEY2 RETIRED)
|
retired=$(key_get KEY2 RETIRED)
|
||||||
set_addkeytime "KEY2" "REMOVED" "${retired}" "${IretZSK}"
|
set_addkeytime "KEY2" "REMOVED" "${retired}" "${IretZSK}"
|
||||||
|
|
||||||
# The new keys are published 40 hours ago.
|
# The new keys are published 40 hours ago.
|
||||||
created=$(key_get KEY3 CREATED)
|
created=$(key_get KEY3 CREATED)
|
||||||
set_addkeytime "KEY3" "PUBLISHED" "${created}" -136800
|
set_addkeytime "KEY3" "PUBLISHED" "${created}" -144000
|
||||||
set_addkeytime "KEY3" "ACTIVE" "${created}" -136800
|
set_addkeytime "KEY3" "ACTIVE" "${created}" -144000
|
||||||
published=$(key_get KEY3 PUBLISHED)
|
published=$(key_get KEY3 PUBLISHED)
|
||||||
set_addkeytime "KEY3" "SYNCPUBLISH" "${published}" ${Ipub}
|
set_addkeytime "KEY3" "SYNCPUBLISH" "${published}" ${Ipub}
|
||||||
|
|
||||||
created=$(key_get KEY4 CREATED)
|
created=$(key_get KEY4 CREATED)
|
||||||
set_addkeytime "KEY4" "PUBLISHED" "${created}" -136800
|
set_addkeytime "KEY4" "PUBLISHED" "${created}" -144000
|
||||||
set_addkeytime "KEY4" "ACTIVE" "${created}" -136800
|
set_addkeytime "KEY4" "ACTIVE" "${created}" -144000
|
||||||
|
|
||||||
# Continue signing policy checks.
|
# Continue signing policy checks.
|
||||||
check_keytimes
|
check_keytimes
|
||||||
@@ -4895,12 +4898,12 @@ check_subdomain
|
|||||||
dnssec_verify
|
dnssec_verify
|
||||||
|
|
||||||
# Next key event is when the RSASHA1 signatures become HIDDEN. This happens
|
# Next key event is when the RSASHA1 signatures become HIDDEN. This happens
|
||||||
# after the max-zone-ttl plus zone propagation delay (6h + 1h)
|
# after the max-zone-ttl plus zone propagation delay plus retire safety
|
||||||
# minus the time already passed since the UNRETENTIVE state has
|
# (6h + 1h + 2h) minus the time already passed since the UNRETENTIVE state has
|
||||||
# been reached (2h): 7h - 2h = 5h = 18000 seconds. Prevent intermittent
|
# been reached (2h): 9h - 2h = 7h = 25200 seconds. Prevent intermittent
|
||||||
# false positives on slow platforms by subtracting the number of seconds
|
# false positives on slow platforms by subtracting the number of seconds
|
||||||
# which passed between key creation and invoking 'rndc reconfig'.
|
# which passed between key creation and invoking 'rndc reconfig'.
|
||||||
next_time=$((18000 - time_passed))
|
next_time=$((25200 - time_passed))
|
||||||
check_next_key_event $next_time
|
check_next_key_event $next_time
|
||||||
|
|
||||||
#
|
#
|
||||||
@@ -4918,29 +4921,29 @@ wait_for_done_signing
|
|||||||
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
|
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
|
||||||
|
|
||||||
# Set expected key times:
|
# Set expected key times:
|
||||||
# - The old keys were activated 45 hours ago (162000 seconds)
|
# - The old keys were activated 47 hours ago (169200 seconds)
|
||||||
rollover_predecessor_keytimes -162000
|
rollover_predecessor_keytimes -169200
|
||||||
# - And retired 42 hours ago (151200 seconds).
|
# - And retired 44 hours ago (158400 seconds).
|
||||||
created=$(key_get KEY1 CREATED)
|
created=$(key_get KEY1 CREATED)
|
||||||
set_addkeytime "KEY1" "RETIRED" "${created}" -151200
|
set_addkeytime "KEY1" "RETIRED" "${created}" -158400
|
||||||
retired=$(key_get KEY1 RETIRED)
|
retired=$(key_get KEY1 RETIRED)
|
||||||
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretKSK}"
|
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretKSK}"
|
||||||
|
|
||||||
created=$(key_get KEY2 CREATED)
|
created=$(key_get KEY2 CREATED)
|
||||||
set_addkeytime "KEY2" "RETIRED" "${created}" -151200
|
set_addkeytime "KEY2" "RETIRED" "${created}" -158400
|
||||||
retired=$(key_get KEY2 RETIRED)
|
retired=$(key_get KEY2 RETIRED)
|
||||||
set_addkeytime "KEY2" "REMOVED" "${retired}" "${IretZSK}"
|
set_addkeytime "KEY2" "REMOVED" "${retired}" "${IretZSK}"
|
||||||
|
|
||||||
# The new keys are published 47 hours ago.
|
# The new keys are published 47 hours ago.
|
||||||
created=$(key_get KEY3 CREATED)
|
created=$(key_get KEY3 CREATED)
|
||||||
set_addkeytime "KEY3" "PUBLISHED" "${created}" -162000
|
set_addkeytime "KEY3" "PUBLISHED" "${created}" -169200
|
||||||
set_addkeytime "KEY3" "ACTIVE" "${created}" -162000
|
set_addkeytime "KEY3" "ACTIVE" "${created}" -169200
|
||||||
published=$(key_get KEY3 PUBLISHED)
|
published=$(key_get KEY3 PUBLISHED)
|
||||||
set_addkeytime "KEY3" "SYNCPUBLISH" "${published}" ${Ipub}
|
set_addkeytime "KEY3" "SYNCPUBLISH" "${published}" ${Ipub}
|
||||||
|
|
||||||
created=$(key_get KEY4 CREATED)
|
created=$(key_get KEY4 CREATED)
|
||||||
set_addkeytime "KEY4" "PUBLISHED" "${created}" -162000
|
set_addkeytime "KEY4" "PUBLISHED" "${created}" -169200
|
||||||
set_addkeytime "KEY4" "ACTIVE" "${created}" -162000
|
set_addkeytime "KEY4" "ACTIVE" "${created}" -169200
|
||||||
|
|
||||||
# Continue signing policy checks.
|
# Continue signing policy checks.
|
||||||
check_keytimes
|
check_keytimes
|
||||||
@@ -5023,8 +5026,9 @@ set_keytime "KEY2" "ACTIVE" "${created}"
|
|||||||
# - It takes TTLsig + Dprp + publish-safety hours to propagate the zone.
|
# - It takes TTLsig + Dprp + publish-safety hours to propagate the zone.
|
||||||
# TTLsig: 6h (39600 seconds)
|
# TTLsig: 6h (39600 seconds)
|
||||||
# Dprp: 1h (3600 seconds)
|
# Dprp: 1h (3600 seconds)
|
||||||
# Ipub: 7h (25200 seconds)
|
# publish-safety: 1h (3600 seconds)
|
||||||
Ipub=25200
|
# Ipub: 8h (28800 seconds)
|
||||||
|
Ipub=28800
|
||||||
set_addkeytime "KEY2" "SYNCPUBLISH" "${created}" "${Ipub}"
|
set_addkeytime "KEY2" "SYNCPUBLISH" "${created}" "${Ipub}"
|
||||||
|
|
||||||
# Continue signing policy checks.
|
# Continue signing policy checks.
|
||||||
@@ -5078,13 +5082,14 @@ check_apex
|
|||||||
check_subdomain
|
check_subdomain
|
||||||
dnssec_verify
|
dnssec_verify
|
||||||
|
|
||||||
# Next key event is when all zone signatures are signed with the new algorithm.
|
# Next key event is when all zone signatures are signed with the new
|
||||||
# This is the max-zone-ttl plus zone propagation delay: 6h + 1h. But three
|
# algorithm. This is the max-zone-ttl plus zone propagation delay
|
||||||
# hours have already passed (the time it took to make the DNSKEY omnipresent),
|
# plus retire safety: 6h + 1h + 2h. But three hours have already passed
|
||||||
# so the next event should be scheduled in 4 hour: 14400 seconds. Prevent
|
# (the time it took to make the DNSKEY omnipresent), so the next event
|
||||||
# intermittent false positives on slow platforms by subtracting the number of
|
# should be scheduled in 6 hour: 21600 seconds. Prevent intermittent
|
||||||
# seconds which passed between key creation and invoking 'rndc reconfig'.
|
# false positives on slow platforms by subtracting the number of seconds
|
||||||
next_time=$((14400 - time_passed))
|
# which passed between key creation and invoking 'rndc reconfig'.
|
||||||
|
next_time=$((21600 - time_passed))
|
||||||
check_next_key_event $next_time
|
check_next_key_event $next_time
|
||||||
|
|
||||||
#
|
#
|
||||||
@@ -5109,17 +5114,17 @@ check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
|
|||||||
check_cdslog "$DIR" "$ZONE" KEY2
|
check_cdslog "$DIR" "$ZONE" KEY2
|
||||||
|
|
||||||
# Set expected key times:
|
# Set expected key times:
|
||||||
# - The old key was activated 7 hours ago (25200 seconds).
|
# - The old key was activated 9 hours ago (32400 seconds).
|
||||||
csk_rollover_predecessor_keytimes -25200
|
csk_rollover_predecessor_keytimes -32400
|
||||||
# - And was retired 3 hours ago (10800 seconds).
|
# - And was retired 6 hours ago (21600 seconds).
|
||||||
created=$(key_get KEY1 CREATED)
|
created=$(key_get KEY1 CREATED)
|
||||||
set_addkeytime "KEY1" "RETIRED" "${created}" -10800
|
set_addkeytime "KEY1" "RETIRED" "${created}" -21600
|
||||||
retired=$(key_get KEY1 RETIRED)
|
retired=$(key_get KEY1 RETIRED)
|
||||||
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretCSK}"
|
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretCSK}"
|
||||||
# - The new key was published 9 hours ago.
|
# - The new key was published 9 hours ago.
|
||||||
created=$(key_get KEY2 CREATED)
|
created=$(key_get KEY2 CREATED)
|
||||||
set_addkeytime "KEY2" "PUBLISHED" "${created}" -25200
|
set_addkeytime "KEY2" "PUBLISHED" "${created}" -32400
|
||||||
set_addkeytime "KEY2" "ACTIVE" "${created}" -25200
|
set_addkeytime "KEY2" "ACTIVE" "${created}" -32400
|
||||||
published=$(key_get KEY2 PUBLISHED)
|
published=$(key_get KEY2 PUBLISHED)
|
||||||
set_addkeytime "KEY2" "SYNCPUBLISH" "${published}" "${Ipub}"
|
set_addkeytime "KEY2" "SYNCPUBLISH" "${published}" "${Ipub}"
|
||||||
|
|
||||||
@@ -5133,9 +5138,9 @@ dnssec_verify
|
|||||||
rndc_checkds "$SERVER" "$DIR" KEY1 "now" "withdrawn" "$ZONE"
|
rndc_checkds "$SERVER" "$DIR" KEY1 "now" "withdrawn" "$ZONE"
|
||||||
rndc_checkds "$SERVER" "$DIR" KEY2 "now" "published" "$ZONE"
|
rndc_checkds "$SERVER" "$DIR" KEY2 "now" "published" "$ZONE"
|
||||||
# Next key event is when the DS becomes OMNIPRESENT. This happens after the
|
# Next key event is when the DS becomes OMNIPRESENT. This happens after the
|
||||||
# parent propagation delay, and DS TTL:
|
# parent propagation delay, retire safety delay, and DS TTL:
|
||||||
# 1h + 2h = 3h = 10800 seconds.
|
# 1h + 2h + 2h = 5h = 18000 seconds.
|
||||||
check_next_key_event 10800
|
check_next_key_event 18000
|
||||||
|
|
||||||
#
|
#
|
||||||
# Zone: step4.csk-algorithm-roll.kasp
|
# Zone: step4.csk-algorithm-roll.kasp
|
||||||
@@ -5159,17 +5164,17 @@ wait_for_done_signing
|
|||||||
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
|
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
|
||||||
|
|
||||||
# Set expected key times:
|
# Set expected key times:
|
||||||
# - The old keys were activated 36 hours ago (129600 seconds).
|
# - The old key was activated 38 hours ago (136800 seconds)
|
||||||
csk_rollover_predecessor_keytimes -129600
|
csk_rollover_predecessor_keytimes -136800
|
||||||
# - And retired 33 hours ago (118800 seconds).
|
# - And retired 35 hours ago (126000 seconds).
|
||||||
created=$(key_get KEY1 CREATED)
|
created=$(key_get KEY1 CREATED)
|
||||||
set_addkeytime "KEY1" "RETIRED" "${created}" -118800
|
set_addkeytime "KEY1" "RETIRED" "${created}" -126000
|
||||||
retired=$(key_get KEY1 RETIRED)
|
retired=$(key_get KEY1 RETIRED)
|
||||||
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretCSK}"
|
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretCSK}"
|
||||||
# - The new key was published 36 hours ago.
|
# - The new key was published 38 hours ago.
|
||||||
created=$(key_get KEY2 CREATED)
|
created=$(key_get KEY2 CREATED)
|
||||||
set_addkeytime "KEY2" "PUBLISHED" "${created}" -129600
|
set_addkeytime "KEY2" "PUBLISHED" "${created}" -136800
|
||||||
set_addkeytime "KEY2" "ACTIVE" "${created}" -129600
|
set_addkeytime "KEY2" "ACTIVE" "${created}" -136800
|
||||||
published=$(key_get KEY2 PUBLISHED)
|
published=$(key_get KEY2 PUBLISHED)
|
||||||
set_addkeytime "KEY2" "SYNCPUBLISH" "${published}" ${Ipub}
|
set_addkeytime "KEY2" "SYNCPUBLISH" "${published}" ${Ipub}
|
||||||
|
|
||||||
@@ -5199,17 +5204,17 @@ wait_for_done_signing
|
|||||||
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
|
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
|
||||||
|
|
||||||
# Set expected key times:
|
# Set expected key times:
|
||||||
# - The old key was activated 38 hours ago (136800 seconds)
|
# - The old key was activated 40 hours ago (144000 seconds)
|
||||||
csk_rollover_predecessor_keytimes -136800
|
csk_rollover_predecessor_keytimes -144000
|
||||||
# - And retired 35 hours ago (126000 seconds).
|
# - And retired 37 hours ago (133200 seconds).
|
||||||
created=$(key_get KEY1 CREATED)
|
created=$(key_get KEY1 CREATED)
|
||||||
set_addkeytime "KEY1" "RETIRED" "${created}" -126000
|
set_addkeytime "KEY1" "RETIRED" "${created}" -133200
|
||||||
retired=$(key_get KEY1 RETIRED)
|
retired=$(key_get KEY1 RETIRED)
|
||||||
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretCSK}"
|
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretCSK}"
|
||||||
# - The new key was published 38 hours ago.
|
# - The new key was published 40 hours ago.
|
||||||
created=$(key_get KEY2 CREATED)
|
created=$(key_get KEY2 CREATED)
|
||||||
set_addkeytime "KEY2" "PUBLISHED" "${created}" -136800
|
set_addkeytime "KEY2" "PUBLISHED" "${created}" -144000
|
||||||
set_addkeytime "KEY2" "ACTIVE" "${created}" -136800
|
set_addkeytime "KEY2" "ACTIVE" "${created}" -144000
|
||||||
published=$(key_get KEY2 PUBLISHED)
|
published=$(key_get KEY2 PUBLISHED)
|
||||||
set_addkeytime "KEY2" "SYNCPUBLISH" "${published}" ${Ipub}
|
set_addkeytime "KEY2" "SYNCPUBLISH" "${published}" ${Ipub}
|
||||||
|
|
||||||
@@ -5220,12 +5225,12 @@ check_subdomain
|
|||||||
dnssec_verify
|
dnssec_verify
|
||||||
|
|
||||||
# Next key event is when the RSASHA1 signatures become HIDDEN. This happens
|
# Next key event is when the RSASHA1 signatures become HIDDEN. This happens
|
||||||
# after the max-zone-ttl plus zone propagation delay (6h + 1h) minus the
|
# after the max-zone-ttl plus zone propagation delay plus retire safety
|
||||||
# time already passed since the UNRETENTIVE state has been reached (2h):
|
# (6h + 1h + 2h) minus the time already passed since the UNRETENTIVE state has
|
||||||
# 7h - 2h = 5h = 18000 seconds. Prevent intermittent false positives on slow
|
# been reached (2h): 9h - 2h = 7h = 25200 seconds. Prevent intermittent
|
||||||
# platforms by subtracting the number of seconds which passed between key
|
# false positives on slow platforms by subtracting the number of seconds
|
||||||
# creation and invoking 'rndc reconfig'.
|
# which passed between key creation and invoking 'rndc reconfig'.
|
||||||
next_time=$((18000 - time_passed))
|
next_time=$((25200 - time_passed))
|
||||||
check_next_key_event $next_time
|
check_next_key_event $next_time
|
||||||
|
|
||||||
#
|
#
|
||||||
@@ -5243,17 +5248,17 @@ wait_for_done_signing
|
|||||||
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
|
check_dnssecstatus "$SERVER" "$POLICY" "$ZONE"
|
||||||
|
|
||||||
# Set expected key times:
|
# Set expected key times:
|
||||||
# - The old keys were activated 45 hours ago (162000 seconds)
|
# - The old keys were activated 47 hours ago (169200 seconds)
|
||||||
csk_rollover_predecessor_keytimes -162000
|
csk_rollover_predecessor_keytimes -169200
|
||||||
# - And retired 42 hours ago (151200 seconds).
|
# - And retired 44 hours ago (158400 seconds).
|
||||||
created=$(key_get KEY1 CREATED)
|
created=$(key_get KEY1 CREATED)
|
||||||
set_addkeytime "KEY1" "RETIRED" "${created}" -151200
|
set_addkeytime "KEY1" "RETIRED" "${created}" -158400
|
||||||
retired=$(key_get KEY1 RETIRED)
|
retired=$(key_get KEY1 RETIRED)
|
||||||
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretCSK}"
|
set_addkeytime "KEY1" "REMOVED" "${retired}" "${IretCSK}"
|
||||||
# - The new key was published 47 hours ago.
|
# - The new key was published 47 hours ago.
|
||||||
created=$(key_get KEY2 CREATED)
|
created=$(key_get KEY2 CREATED)
|
||||||
set_addkeytime "KEY2" "PUBLISHED" "${created}" -162000
|
set_addkeytime "KEY2" "PUBLISHED" "${created}" -169200
|
||||||
set_addkeytime "KEY2" "ACTIVE" "${created}" -162000
|
set_addkeytime "KEY2" "ACTIVE" "${created}" -169200
|
||||||
published=$(key_get KEY2 PUBLISHED)
|
published=$(key_get KEY2 PUBLISHED)
|
||||||
set_addkeytime "KEY2" "SYNCPUBLISH" "${published}" ${Ipub}
|
set_addkeytime "KEY2" "SYNCPUBLISH" "${published}" ${Ipub}
|
||||||
|
|
||||||
|
|||||||
@@ -597,10 +597,6 @@ def test_ksr_common(servers):
|
|||||||
selected += 1
|
selected += 1
|
||||||
if "Generating" in output:
|
if "Generating" in output:
|
||||||
generated += 1
|
generated += 1
|
||||||
# Subtract if there was a key collision.
|
|
||||||
if "collide" in output:
|
|
||||||
generated -= 1
|
|
||||||
|
|
||||||
assert selected == 2
|
assert selected == 2
|
||||||
assert generated == 2
|
assert generated == 2
|
||||||
for index, key in enumerate(overlapping_zsks):
|
for index, key in enumerate(overlapping_zsks):
|
||||||
|
|||||||
@@ -111,7 +111,7 @@ cleanup:
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (mctx != NULL) {
|
if (mctx != NULL) {
|
||||||
isc_mem_detach(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
}
|
}
|
||||||
|
|
||||||
return result != ISC_R_SUCCESS ? 1 : 0;
|
return result != ISC_R_SUCCESS ? 1 : 0;
|
||||||
|
|||||||
@@ -385,7 +385,7 @@ $DIG $DIGOPTS @10.53.0.3 foo.initially-unavailable. A >dig.out.ns3.test$n.1 2>&1
|
|||||||
grep "NOERROR" dig.out.ns3.test$n.1 >/dev/null || ret=1
|
grep "NOERROR" dig.out.ns3.test$n.1 >/dev/null || ret=1
|
||||||
grep "flags:.* ad" dig.out.ns3.test$n.1 >/dev/null || ret=1
|
grep "flags:.* ad" dig.out.ns3.test$n.1 >/dev/null || ret=1
|
||||||
# Sanity check: the authoritative server should have been queried.
|
# Sanity check: the authoritative server should have been queried.
|
||||||
nextpart ns2/named.run | grep "query 'foo.initially-unavailable/NS/IN'" >/dev/null || ret=1
|
nextpart ns2/named.run | grep "query 'foo.initially-unavailable/A/IN'" >/dev/null || ret=1
|
||||||
# Reconfigure ns2 so that the zone can be mirrored on ns3.
|
# Reconfigure ns2 so that the zone can be mirrored on ns3.
|
||||||
sed '/^zone "initially-unavailable" {$/,/^};$/ {
|
sed '/^zone "initially-unavailable" {$/,/^};$/ {
|
||||||
s/10.53.0.254/10.53.0.3/
|
s/10.53.0.254/10.53.0.3/
|
||||||
@@ -403,7 +403,7 @@ $DIG $DIGOPTS @10.53.0.3 foo.initially-unavailable. A >dig.out.ns3.test$n.2 2>&1
|
|||||||
grep "NOERROR" dig.out.ns3.test$n.2 >/dev/null || ret=1
|
grep "NOERROR" dig.out.ns3.test$n.2 >/dev/null || ret=1
|
||||||
grep "flags:.* ad" dig.out.ns3.test$n.2 >/dev/null || ret=1
|
grep "flags:.* ad" dig.out.ns3.test$n.2 >/dev/null || ret=1
|
||||||
# Ensure the authoritative server was not queried.
|
# Ensure the authoritative server was not queried.
|
||||||
nextpart ns2/named.run | grep "query 'foo.initially-unavailable/NS/IN'" >/dev/null && ret=1
|
nextpart ns2/named.run | grep "query 'foo.initially-unavailable/A/IN'" >/dev/null && ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|
||||||
@@ -434,7 +434,7 @@ $DIG $DIGOPTS @10.53.0.3 foo.initially-unavailable. A >dig.out.ns3.test$n 2>&1 |
|
|||||||
grep "NOERROR" dig.out.ns3.test$n >/dev/null || ret=1
|
grep "NOERROR" dig.out.ns3.test$n >/dev/null || ret=1
|
||||||
grep "flags:.* ad" dig.out.ns3.test$n >/dev/null || ret=1
|
grep "flags:.* ad" dig.out.ns3.test$n >/dev/null || ret=1
|
||||||
# Sanity check: the authoritative server should have been queried.
|
# Sanity check: the authoritative server should have been queried.
|
||||||
nextpart ns2/named.run | grep "query 'foo.initially-unavailable/NS/IN'" >/dev/null || ret=1
|
nextpart ns2/named.run | grep "query 'foo.initially-unavailable/A/IN'" >/dev/null || ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|
||||||
|
|||||||
@@ -1,17 +0,0 @@
|
|||||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
;
|
|
||||||
; SPDX-License-Identifier: MPL-2.0
|
|
||||||
;
|
|
||||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
;
|
|
||||||
; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
; information regarding copyright ownership.
|
|
||||||
|
|
||||||
@ 30 SOA ns2.good. hostmaster.arpa. 2018050100 1 1 1 1
|
|
||||||
@ 30 NS ns2.good.
|
|
||||||
|
|
||||||
8.2.6.0 60 NS ns3.good.
|
|
||||||
|
|
||||||
1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.f.4.0 1 PTR nee.com.
|
|
||||||
Regular → Executable
+436
-91
@@ -1,111 +1,456 @@
|
|||||||
"""
|
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
#
|
||||||
|
# SPDX-License-Identifier: MPL-2.0
|
||||||
|
#
|
||||||
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
#
|
||||||
|
# See the COPYRIGHT file distributed with this work for additional
|
||||||
|
# information regarding copyright ownership.
|
||||||
|
|
||||||
SPDX-License-Identifier: MPL-2.0
|
from __future__ import print_function
|
||||||
|
import os
|
||||||
|
import sys
|
||||||
|
import signal
|
||||||
|
import socket
|
||||||
|
import select
|
||||||
|
from datetime import datetime, timedelta
|
||||||
|
import time
|
||||||
|
import functools
|
||||||
|
|
||||||
This Source Code Form is subject to the terms of the Mozilla Public
|
import dns, dns.message, dns.query, dns.flags
|
||||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
from dns.rdatatype import *
|
||||||
file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
from dns.rdataclass import *
|
||||||
|
from dns.rcode import *
|
||||||
See the COPYRIGHT file distributed with this work for additional
|
from dns.name import *
|
||||||
information regarding copyright ownership.
|
|
||||||
"""
|
|
||||||
|
|
||||||
from typing import AsyncGenerator
|
|
||||||
|
|
||||||
import dns.message
|
|
||||||
import dns.name
|
|
||||||
import dns.rcode
|
|
||||||
import dns.rdataclass
|
|
||||||
import dns.rdatatype
|
|
||||||
|
|
||||||
from isctest.asyncserver import (
|
|
||||||
AsyncDnsServer,
|
|
||||||
DnsResponseSend,
|
|
||||||
DomainHandler,
|
|
||||||
QueryContext,
|
|
||||||
ResponseAction,
|
|
||||||
)
|
|
||||||
|
|
||||||
from qmin_ans import (
|
|
||||||
DelayedResponseHandler,
|
|
||||||
EntRcodeChanger,
|
|
||||||
QueryLogHandler,
|
|
||||||
log_query,
|
|
||||||
)
|
|
||||||
|
|
||||||
|
|
||||||
class QueryLogger(QueryLogHandler):
|
# Log query to file
|
||||||
domains = ["1.0.0.2.ip6.arpa.", "fwd.", "good."]
|
def logquery(type, qname):
|
||||||
|
with open("qlog", "a") as f:
|
||||||
|
f.write("%s %s\n", type, qname)
|
||||||
|
|
||||||
|
|
||||||
class BadHandler(EntRcodeChanger):
|
def endswith(domain, labels):
|
||||||
domains = ["bad."]
|
return domain.endswith("." + labels) or domain == labels
|
||||||
rcode = dns.rcode.NXDOMAIN
|
|
||||||
|
|
||||||
|
|
||||||
class UglyHandler(EntRcodeChanger):
|
############################################################################
|
||||||
domains = ["ugly."]
|
# Respond to a DNS query.
|
||||||
rcode = dns.rcode.FORMERR
|
# For good. it serves:
|
||||||
|
# ns2.good. IN A 10.53.0.2
|
||||||
|
# zoop.boing.good. NS ns3.good.
|
||||||
|
# ns3.good. IN A 10.53.0.3
|
||||||
|
# too.many.labels.a.b.c.d.e.f.g.h.i.j.k.l.m.n.o.p.q.r.s.t.u.v.w.x.y.z.good. A 192.0.2.2
|
||||||
|
# it responds properly (with NODATA empty response) to non-empty terminals
|
||||||
|
#
|
||||||
|
# For slow. it works the same as for good., but each response is delayed by 400 milliseconds
|
||||||
|
#
|
||||||
|
# For bad. it works the same as for good., but returns NXDOMAIN to non-empty terminals
|
||||||
|
#
|
||||||
|
# For ugly. it works the same as for good., but returns garbage to non-empty terminals
|
||||||
|
#
|
||||||
|
# For 1.0.0.2.ip6.arpa it serves
|
||||||
|
# 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa. IN PTR nee.com.
|
||||||
|
# 8.2.6.0.1.0.0.2.ip6.arpa IN NS ns3.good
|
||||||
|
# 1.0.0.2.ip6.arpa. IN NS ns2.good
|
||||||
|
# ip6.arpa. IN NS ns2.good
|
||||||
|
#
|
||||||
|
# For stale. it serves:
|
||||||
|
# a.b. NS ns.a.b.stale.
|
||||||
|
# ns.a.b.stale. IN A 10.53.0.3
|
||||||
|
# b. NS ns.b.stale.
|
||||||
|
# ns.b.stale. IN A 10.53.0.4
|
||||||
|
############################################################################
|
||||||
|
def create_response(msg):
|
||||||
|
m = dns.message.from_wire(msg)
|
||||||
|
qname = m.question[0].name.to_text()
|
||||||
|
lqname = qname.lower()
|
||||||
|
labels = lqname.split(".")
|
||||||
|
|
||||||
|
# get qtype
|
||||||
|
rrtype = m.question[0].rdtype
|
||||||
|
typename = dns.rdatatype.to_text(rrtype)
|
||||||
|
if typename == "A" or typename == "AAAA":
|
||||||
|
typename = "ADDR"
|
||||||
|
bad = False
|
||||||
|
ugly = False
|
||||||
|
slow = False
|
||||||
|
|
||||||
|
# log this query
|
||||||
|
with open("query.log", "a") as f:
|
||||||
|
f.write("%s %s\n" % (typename, lqname))
|
||||||
|
print("%s %s" % (typename, lqname), end=" ")
|
||||||
|
|
||||||
|
r = dns.message.make_response(m)
|
||||||
|
r.set_rcode(NOERROR)
|
||||||
|
|
||||||
|
if endswith(lqname, "1.0.0.2.ip6.arpa."):
|
||||||
|
# Direct query - give direct answer
|
||||||
|
if endswith(lqname, "8.2.6.0.1.0.0.2.ip6.arpa."):
|
||||||
|
# Delegate to ns3
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"8.2.6.0.1.0.0.2.ip6.arpa.", 60, IN, NS, "ns3.good."
|
||||||
|
)
|
||||||
|
)
|
||||||
|
r.additional.append(
|
||||||
|
dns.rrset.from_text("ns3.good.", 60, IN, A, "10.53.0.3")
|
||||||
|
)
|
||||||
|
elif (
|
||||||
|
lqname
|
||||||
|
== "1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa."
|
||||||
|
and rrtype == PTR
|
||||||
|
):
|
||||||
|
# Direct query - give direct answer
|
||||||
|
r.answer.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.",
|
||||||
|
1,
|
||||||
|
IN,
|
||||||
|
PTR,
|
||||||
|
"nee.com.",
|
||||||
|
)
|
||||||
|
)
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
elif lqname == "1.0.0.2.ip6.arpa." and rrtype == NS:
|
||||||
|
# NS query at the apex
|
||||||
|
r.answer.append(
|
||||||
|
dns.rrset.from_text("1.0.0.2.ip6.arpa.", 30, IN, NS, "ns2.good.")
|
||||||
|
)
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
elif endswith(
|
||||||
|
"1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.",
|
||||||
|
lqname,
|
||||||
|
):
|
||||||
|
# NODATA answer
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"1.0.0.2.ip6.arpa.",
|
||||||
|
30,
|
||||||
|
IN,
|
||||||
|
SOA,
|
||||||
|
"ns2.good. hostmaster.arpa. 2018050100 1 1 1 1",
|
||||||
|
)
|
||||||
|
)
|
||||||
|
else:
|
||||||
|
# NXDOMAIN
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"1.0.0.2.ip6.arpa.",
|
||||||
|
30,
|
||||||
|
IN,
|
||||||
|
SOA,
|
||||||
|
"ns2.good. hostmaster.arpa. 2018050100 1 1 1 1",
|
||||||
|
)
|
||||||
|
)
|
||||||
|
r.set_rcode(NXDOMAIN)
|
||||||
|
return r
|
||||||
|
elif endswith(lqname, "ip6.arpa."):
|
||||||
|
if lqname == "ip6.arpa." and rrtype == NS:
|
||||||
|
# NS query at the apex
|
||||||
|
r.answer.append(dns.rrset.from_text("ip6.arpa.", 30, IN, NS, "ns2.good."))
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
elif endswith("1.0.0.2.ip6.arpa.", lqname):
|
||||||
|
# NODATA answer
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"ip6.arpa.",
|
||||||
|
30,
|
||||||
|
IN,
|
||||||
|
SOA,
|
||||||
|
"ns2.good. hostmaster.arpa. 2018050100 1 1 1 1",
|
||||||
|
)
|
||||||
|
)
|
||||||
|
else:
|
||||||
|
# NXDOMAIN
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"ip6.arpa.",
|
||||||
|
30,
|
||||||
|
IN,
|
||||||
|
SOA,
|
||||||
|
"ns2.good. hostmaster.arpa. 2018050100 1 1 1 1",
|
||||||
|
)
|
||||||
|
)
|
||||||
|
r.set_rcode(NXDOMAIN)
|
||||||
|
return r
|
||||||
|
elif endswith(lqname, "stale."):
|
||||||
|
if endswith(lqname, "a.b.stale."):
|
||||||
|
# Delegate to ns.a.b.stale.
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text("a.b.stale.", 2, IN, NS, "ns.a.b.stale.")
|
||||||
|
)
|
||||||
|
r.additional.append(
|
||||||
|
dns.rrset.from_text("ns.a.b.stale.", 2, IN, A, "10.53.0.3")
|
||||||
|
)
|
||||||
|
elif endswith(lqname, "b.stale."):
|
||||||
|
# Delegate to ns.b.stale.
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text("b.stale.", 2, IN, NS, "ns.b.stale.")
|
||||||
|
)
|
||||||
|
r.additional.append(
|
||||||
|
dns.rrset.from_text("ns.b.stale.", 2, IN, A, "10.53.0.4")
|
||||||
|
)
|
||||||
|
elif lqname == "stale." and rrtype == NS:
|
||||||
|
# NS query at the apex.
|
||||||
|
r.answer.append(dns.rrset.from_text("stale.", 2, IN, NS, "ns2.stale."))
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
elif lqname == "stale." and rrtype == SOA:
|
||||||
|
# SOA query at the apex.
|
||||||
|
r.answer.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"stale.", 2, IN, SOA, "ns2.stale. hostmaster.stale. 1 2 3 4 5"
|
||||||
|
)
|
||||||
|
)
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
elif lqname == "stale.":
|
||||||
|
# NODATA answer
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"stale.", 2, IN, SOA, "ns2.stale. hostmaster.arpa. 1 2 3 4 5"
|
||||||
|
)
|
||||||
|
)
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
elif lqname == "ns2.stale.":
|
||||||
|
if rrtype == A:
|
||||||
|
r.additional.append(
|
||||||
|
dns.rrset.from_text("ns.b.stale.", 2, IN, A, "10.53.0.2")
|
||||||
|
)
|
||||||
|
else:
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"stale.", 2, IN, SOA, "ns2.stale. hostmaster.arpa. 1 2 3 4 5"
|
||||||
|
)
|
||||||
|
)
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
else:
|
||||||
|
# NXDOMAIN
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"stale.", 2, IN, SOA, "ns2.stale. hostmaster.arpa. 1 2 3 4 5"
|
||||||
|
)
|
||||||
|
)
|
||||||
|
r.set_rcode(NXDOMAIN)
|
||||||
|
return r
|
||||||
|
elif endswith(lqname, "bad."):
|
||||||
|
bad = True
|
||||||
|
suffix = "bad."
|
||||||
|
lqname = lqname[:-4]
|
||||||
|
elif endswith(lqname, "ugly."):
|
||||||
|
ugly = True
|
||||||
|
suffix = "ugly."
|
||||||
|
lqname = lqname[:-5]
|
||||||
|
elif endswith(lqname, "good."):
|
||||||
|
suffix = "good."
|
||||||
|
lqname = lqname[:-5]
|
||||||
|
elif endswith(lqname, "slow."):
|
||||||
|
slow = True
|
||||||
|
suffix = "slow."
|
||||||
|
lqname = lqname[:-5]
|
||||||
|
elif endswith(lqname, "fwd."):
|
||||||
|
suffix = "fwd."
|
||||||
|
lqname = lqname[:-4]
|
||||||
|
else:
|
||||||
|
r.set_rcode(REFUSED)
|
||||||
|
return r
|
||||||
|
|
||||||
|
# Good/bad/ugly differs only in how we treat non-empty terminals
|
||||||
|
if endswith(lqname, "zoop.boing."):
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text("zoop.boing." + suffix, 1, IN, NS, "ns3." + suffix)
|
||||||
|
)
|
||||||
|
elif (
|
||||||
|
lqname == "many.labels.a.b.c.d.e.f.g.h.i.j.k.l.m.n.o.p.q.r.s.t.u.v.w.x.y.z."
|
||||||
|
and rrtype == A
|
||||||
|
):
|
||||||
|
r.answer.append(dns.rrset.from_text(lqname + suffix, 1, IN, A, "192.0.2.2"))
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
elif lqname == "" and rrtype == NS:
|
||||||
|
r.answer.append(dns.rrset.from_text(suffix, 30, IN, NS, "ns2." + suffix))
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
elif lqname == "ns2.":
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
if rrtype == A:
|
||||||
|
r.answer.append(
|
||||||
|
dns.rrset.from_text("ns2." + suffix, 30, IN, A, "10.53.0.2")
|
||||||
|
)
|
||||||
|
elif rrtype == AAAA:
|
||||||
|
r.answer.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"ns2." + suffix, 30, IN, AAAA, "fd92:7065:b8e:ffff::2"
|
||||||
|
)
|
||||||
|
)
|
||||||
|
else:
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
suffix,
|
||||||
|
30,
|
||||||
|
IN,
|
||||||
|
SOA,
|
||||||
|
"ns2." + suffix + " hostmaster.arpa. 2018050100 1 1 1 1",
|
||||||
|
)
|
||||||
|
)
|
||||||
|
elif lqname == "ns3.":
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
if rrtype == A:
|
||||||
|
r.answer.append(
|
||||||
|
dns.rrset.from_text("ns3." + suffix, 30, IN, A, "10.53.0.3")
|
||||||
|
)
|
||||||
|
elif lqname == "ns3." and rrtype == AAAA:
|
||||||
|
r.answer.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"ns3." + suffix, 30, IN, AAAA, "fd92:7065:b8e:ffff::3"
|
||||||
|
)
|
||||||
|
)
|
||||||
|
else:
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
suffix,
|
||||||
|
30,
|
||||||
|
IN,
|
||||||
|
SOA,
|
||||||
|
"ns2." + suffix + " hostmaster.arpa. 2018050100 1 1 1 1",
|
||||||
|
)
|
||||||
|
)
|
||||||
|
elif lqname == "ns4.":
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
if rrtype == A:
|
||||||
|
r.answer.append(
|
||||||
|
dns.rrset.from_text("ns4." + suffix, 30, IN, A, "10.53.0.4")
|
||||||
|
)
|
||||||
|
elif rrtype == AAAA:
|
||||||
|
r.answer.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"ns4." + suffix, 30, IN, AAAA, "fd92:7065:b8e:ffff::4"
|
||||||
|
)
|
||||||
|
)
|
||||||
|
else:
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
suffix,
|
||||||
|
30,
|
||||||
|
IN,
|
||||||
|
SOA,
|
||||||
|
"ns2." + suffix + " hostmaster.arpa. 2018050100 1 1 1 1",
|
||||||
|
)
|
||||||
|
)
|
||||||
|
elif lqname == "a.bit.longer.ns.name." and rrtype == A:
|
||||||
|
r.answer.append(
|
||||||
|
dns.rrset.from_text("a.bit.longer.ns.name." + suffix, 1, IN, A, "10.53.0.4")
|
||||||
|
)
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
elif lqname == "a.bit.longer.ns.name." and rrtype == AAAA:
|
||||||
|
r.answer.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"a.bit.longer.ns.name." + suffix, 1, IN, AAAA, "fd92:7065:b8e:ffff::4"
|
||||||
|
)
|
||||||
|
)
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
else:
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
suffix,
|
||||||
|
1,
|
||||||
|
IN,
|
||||||
|
SOA,
|
||||||
|
"ns2." + suffix + " hostmaster.arpa. 2018050100 1 1 1 1",
|
||||||
|
)
|
||||||
|
)
|
||||||
|
if bad or not (
|
||||||
|
endswith("icky.icky.icky.ptang.zoop.boing.", lqname)
|
||||||
|
or endswith(
|
||||||
|
"many.labels.a.b.c.d.e.f.g.h.i.j.k.l.m.n.o.p.q.r.s.t.u.v.w.x.y.z.",
|
||||||
|
lqname,
|
||||||
|
)
|
||||||
|
or endswith("a.bit.longer.ns.name.", lqname)
|
||||||
|
):
|
||||||
|
r.set_rcode(NXDOMAIN)
|
||||||
|
if ugly:
|
||||||
|
r.set_rcode(FORMERR)
|
||||||
|
if slow:
|
||||||
|
time.sleep(0.2)
|
||||||
|
return r
|
||||||
|
|
||||||
|
|
||||||
class SlowHandler(DelayedResponseHandler):
|
def sigterm(signum, frame):
|
||||||
domains = ["slow."]
|
print("Shutting down now...")
|
||||||
delay = 0.2
|
os.remove("ans.pid")
|
||||||
|
running = False
|
||||||
|
sys.exit(0)
|
||||||
|
|
||||||
|
|
||||||
def send_delegation(
|
############################################################################
|
||||||
qctx: QueryContext, zone_cut: dns.name.Name, target_addr: str
|
# Main
|
||||||
) -> ResponseAction:
|
#
|
||||||
"""
|
# Set up responder and control channel, open the pid file, and start
|
||||||
Delegate `zone_cut` to a single in-bailiwick name server, `ns.<zone_cut>`,
|
# the main loop, listening for queries on the query channel or commands
|
||||||
with a single IPv4 glue record (provided in `target_addr`) included in the
|
# on the control channel and acting on them.
|
||||||
ADDITIONAL section.
|
############################################################################
|
||||||
"""
|
ip4 = "10.53.0.2"
|
||||||
ns_name = "ns." + zone_cut.to_text()
|
ip6 = "fd92:7065:b8e:ffff::2"
|
||||||
ns_rrset = dns.rrset.from_text(
|
|
||||||
zone_cut, 2, dns.rdataclass.IN, dns.rdatatype.NS, ns_name
|
|
||||||
)
|
|
||||||
a_rrset = dns.rrset.from_text(
|
|
||||||
ns_name, 2, dns.rdataclass.IN, dns.rdatatype.A, target_addr
|
|
||||||
)
|
|
||||||
|
|
||||||
response = dns.message.make_response(qctx.query)
|
try:
|
||||||
response.set_rcode(dns.rcode.NOERROR)
|
port = int(os.environ["PORT"])
|
||||||
response.authority.append(ns_rrset)
|
except:
|
||||||
response.additional.append(a_rrset)
|
port = 5300
|
||||||
|
|
||||||
return DnsResponseSend(response, authoritative=False)
|
query4_socket = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
|
||||||
|
query4_socket.bind((ip4, port))
|
||||||
|
|
||||||
|
havev6 = True
|
||||||
|
try:
|
||||||
|
query6_socket = socket.socket(socket.AF_INET6, socket.SOCK_DGRAM)
|
||||||
|
try:
|
||||||
|
query6_socket.bind((ip6, port))
|
||||||
|
except:
|
||||||
|
query6_socket.close()
|
||||||
|
havev6 = False
|
||||||
|
except:
|
||||||
|
havev6 = False
|
||||||
|
|
||||||
class StaleHandler(DomainHandler):
|
signal.signal(signal.SIGTERM, sigterm)
|
||||||
"""
|
|
||||||
`a.b.stale` is a subdomain of `b.stale` and these two subdomains need to be
|
|
||||||
delegated to different name servers. Therefore, their delegations cannot
|
|
||||||
be placed in the zone file because the zone cut at `b.stale` would occlude
|
|
||||||
the one at `a.b.stale`. Generate these delegations dynamically depending
|
|
||||||
on the QNAME.
|
|
||||||
"""
|
|
||||||
|
|
||||||
domains = ["stale."]
|
f = open("ans.pid", "w")
|
||||||
|
pid = os.getpid()
|
||||||
|
print(pid, file=f)
|
||||||
|
f.close()
|
||||||
|
|
||||||
async def get_responses(
|
running = True
|
||||||
self, qctx: QueryContext
|
|
||||||
) -> AsyncGenerator[ResponseAction, None]:
|
|
||||||
log_query(qctx)
|
|
||||||
a_b_stale = dns.name.from_text("a.b.stale.")
|
|
||||||
b_stale = dns.name.from_text("b.stale.")
|
|
||||||
if qctx.qname.is_subdomain(a_b_stale):
|
|
||||||
yield send_delegation(qctx, a_b_stale, "10.53.0.3")
|
|
||||||
elif qctx.qname.is_subdomain(b_stale):
|
|
||||||
yield send_delegation(qctx, b_stale, "10.53.0.4")
|
|
||||||
|
|
||||||
|
print("Listening on %s port %d" % (ip4, port))
|
||||||
|
if havev6:
|
||||||
|
print("Listening on %s port %d" % (ip6, port))
|
||||||
|
print("Ctrl-c to quit")
|
||||||
|
|
||||||
if __name__ == "__main__":
|
if havev6:
|
||||||
server = AsyncDnsServer()
|
input = [query4_socket, query6_socket]
|
||||||
server.install_response_handler(QueryLogger())
|
else:
|
||||||
server.install_response_handler(BadHandler())
|
input = [query4_socket]
|
||||||
server.install_response_handler(UglyHandler())
|
|
||||||
server.install_response_handler(SlowHandler())
|
while running:
|
||||||
server.install_response_handler(StaleHandler())
|
try:
|
||||||
server.run()
|
inputready, outputready, exceptready = select.select(input, [], [])
|
||||||
|
except select.error as e:
|
||||||
|
break
|
||||||
|
except socket.error as e:
|
||||||
|
break
|
||||||
|
except KeyboardInterrupt:
|
||||||
|
break
|
||||||
|
|
||||||
|
for s in inputready:
|
||||||
|
if s == query4_socket or s == query6_socket:
|
||||||
|
print(
|
||||||
|
"Query received on %s" % (ip4 if s == query4_socket else ip6), end=" "
|
||||||
|
)
|
||||||
|
# Handle incoming queries
|
||||||
|
msg = s.recvfrom(65535)
|
||||||
|
rsp = create_response(msg[0])
|
||||||
|
if rsp:
|
||||||
|
print(dns.rcode.to_text(rsp.rcode()))
|
||||||
|
s.sendto(rsp.to_wire(), msg[1])
|
||||||
|
else:
|
||||||
|
print("NO RESPONSE")
|
||||||
|
if not running:
|
||||||
|
break
|
||||||
|
|||||||
@@ -1 +0,0 @@
|
|||||||
good.db
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
good.db
|
|
||||||
@@ -1,26 +0,0 @@
|
|||||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
;
|
|
||||||
; SPDX-License-Identifier: MPL-2.0
|
|
||||||
;
|
|
||||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
;
|
|
||||||
; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
; information regarding copyright ownership.
|
|
||||||
|
|
||||||
@ 1 SOA ns2 hostmaster.arpa. 2018050100 1 1 1 1
|
|
||||||
|
|
||||||
@ 30 NS ns2
|
|
||||||
ns2 30 A 10.53.0.2
|
|
||||||
30 AAAA fd92:7065:b8e:ffff::2
|
|
||||||
|
|
||||||
zoop.boing 30 NS ns3
|
|
||||||
ns3 30 A 10.53.0.3
|
|
||||||
30 AAAA fd92:7065:b8e:ffff::3
|
|
||||||
|
|
||||||
ns4 30 A 10.53.0.4
|
|
||||||
30 AAAA fd92:7065:b8e:ffff::4
|
|
||||||
|
|
||||||
a.bit.longer.ns.name 1 A 10.53.0.4
|
|
||||||
1 AAAA fd92:7065:b8e:ffff::4
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
good.db
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
;
|
|
||||||
; SPDX-License-Identifier: MPL-2.0
|
|
||||||
;
|
|
||||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
;
|
|
||||||
; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
; information regarding copyright ownership.
|
|
||||||
|
|
||||||
@ 2 SOA ns2 hostmaster.stale. 1 2 3 4 5
|
|
||||||
@ 2 NS ns2
|
|
||||||
ns2 2 A 10.53.0.2
|
|
||||||
2 AAAA fd92:7065:b8e:ffff::2
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
good.db
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
;
|
|
||||||
; SPDX-License-Identifier: MPL-2.0
|
|
||||||
;
|
|
||||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
;
|
|
||||||
; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
; information regarding copyright ownership.
|
|
||||||
|
|
||||||
@ 30 SOA ns3.good. hostmaster.arpa. 2018050100 1 1 1 1
|
|
||||||
@ 30 NS ns3.good.
|
|
||||||
|
|
||||||
1.1.1.1 60 NS ns4.good.
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
;
|
|
||||||
; SPDX-License-Identifier: MPL-2.0
|
|
||||||
;
|
|
||||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
;
|
|
||||||
; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
; information regarding copyright ownership.
|
|
||||||
|
|
||||||
@ 1 SOA ns hostmaster.a.b.stale. 1 2 3 4 5
|
|
||||||
@ 1 NS ns
|
|
||||||
@ 1 TXT "peekaboo"
|
|
||||||
ns 1 A 10.53.0.3
|
|
||||||
Regular → Executable
+273
-34
@@ -1,46 +1,285 @@
|
|||||||
"""
|
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
#
|
||||||
|
# SPDX-License-Identifier: MPL-2.0
|
||||||
|
#
|
||||||
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
#
|
||||||
|
# See the COPYRIGHT file distributed with this work for additional
|
||||||
|
# information regarding copyright ownership.
|
||||||
|
|
||||||
SPDX-License-Identifier: MPL-2.0
|
from __future__ import print_function
|
||||||
|
import os
|
||||||
|
import sys
|
||||||
|
import signal
|
||||||
|
import socket
|
||||||
|
import select
|
||||||
|
from datetime import datetime, timedelta
|
||||||
|
import time
|
||||||
|
import functools
|
||||||
|
|
||||||
This Source Code Form is subject to the terms of the Mozilla Public
|
import dns, dns.message, dns.query, dns.flags
|
||||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
from dns.rdatatype import *
|
||||||
file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
from dns.rdataclass import *
|
||||||
|
from dns.rcode import *
|
||||||
See the COPYRIGHT file distributed with this work for additional
|
from dns.name import *
|
||||||
information regarding copyright ownership.
|
|
||||||
"""
|
|
||||||
|
|
||||||
import dns.rcode
|
|
||||||
|
|
||||||
from isctest.asyncserver import AsyncDnsServer
|
|
||||||
|
|
||||||
from qmin_ans import DelayedResponseHandler, EntRcodeChanger, QueryLogHandler
|
|
||||||
|
|
||||||
|
|
||||||
class QueryLogger(QueryLogHandler):
|
# Log query to file
|
||||||
domains = ["8.2.6.0.1.0.0.2.ip6.arpa.", "a.b.stale.", "zoop.boing.good."]
|
def logquery(type, qname):
|
||||||
|
with open("qlog", "a") as f:
|
||||||
|
f.write("%s %s\n", type, qname)
|
||||||
|
|
||||||
|
|
||||||
class ZoopBoingBadHandler(EntRcodeChanger):
|
def endswith(domain, labels):
|
||||||
domains = ["zoop.boing.bad."]
|
return domain.endswith("." + labels) or domain == labels
|
||||||
rcode = dns.rcode.NXDOMAIN
|
|
||||||
|
|
||||||
|
|
||||||
class ZoopBoingUglyHandler(EntRcodeChanger):
|
############################################################################
|
||||||
domains = ["zoop.boing.ugly."]
|
# Respond to a DNS query.
|
||||||
rcode = dns.rcode.FORMERR
|
# For good. it serves:
|
||||||
|
# zoop.boing.good. NS ns3.good.
|
||||||
|
# icky.ptang.zoop.boing.good. NS a.bit.longer.ns.name.good.
|
||||||
|
# it responds properly (with NODATA empty response) to non-empty terminals
|
||||||
|
#
|
||||||
|
# For slow. it works the same as for good., but each response is delayed by 400 milliseconds
|
||||||
|
#
|
||||||
|
# For bad. it works the same as for good., but returns NXDOMAIN to non-empty terminals
|
||||||
|
#
|
||||||
|
# For ugly. it works the same as for good., but returns garbage to non-empty terminals
|
||||||
|
#
|
||||||
|
# For stale. it serves:
|
||||||
|
# a.b.stale. IN TXT peekaboo (resolver did not do qname minimization)
|
||||||
|
############################################################################
|
||||||
|
def create_response(msg):
|
||||||
|
m = dns.message.from_wire(msg)
|
||||||
|
qname = m.question[0].name.to_text()
|
||||||
|
lqname = qname.lower()
|
||||||
|
labels = lqname.split(".")
|
||||||
|
suffix = ""
|
||||||
|
|
||||||
|
# get qtype
|
||||||
|
rrtype = m.question[0].rdtype
|
||||||
|
typename = dns.rdatatype.to_text(rrtype)
|
||||||
|
if typename == "A" or typename == "AAAA":
|
||||||
|
typename = "ADDR"
|
||||||
|
bad = False
|
||||||
|
ugly = False
|
||||||
|
slow = False
|
||||||
|
|
||||||
|
# log this query
|
||||||
|
with open("query.log", "a") as f:
|
||||||
|
f.write("%s %s\n" % (typename, lqname))
|
||||||
|
print("%s %s" % (typename, lqname), end=" ")
|
||||||
|
|
||||||
|
r = dns.message.make_response(m)
|
||||||
|
r.set_rcode(NOERROR)
|
||||||
|
|
||||||
|
ip6req = False
|
||||||
|
|
||||||
|
if endswith(lqname, "bad."):
|
||||||
|
bad = True
|
||||||
|
suffix = "bad."
|
||||||
|
lqname = lqname[:-4]
|
||||||
|
elif endswith(lqname, "ugly."):
|
||||||
|
ugly = True
|
||||||
|
suffix = "ugly."
|
||||||
|
lqname = lqname[:-5]
|
||||||
|
elif endswith(lqname, "good."):
|
||||||
|
suffix = "good."
|
||||||
|
lqname = lqname[:-5]
|
||||||
|
elif endswith(lqname, "slow."):
|
||||||
|
slow = True
|
||||||
|
suffix = "slow."
|
||||||
|
lqname = lqname[:-5]
|
||||||
|
elif endswith(lqname, "8.2.6.0.1.0.0.2.ip6.arpa."):
|
||||||
|
ip6req = True
|
||||||
|
elif endswith(lqname, "a.b.stale."):
|
||||||
|
if lqname == "a.b.stale.":
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
if rrtype == TXT:
|
||||||
|
# Direct query.
|
||||||
|
r.answer.append(dns.rrset.from_text(lqname, 1, IN, TXT, "peekaboo"))
|
||||||
|
elif rrtype == NS:
|
||||||
|
# NS a.b.
|
||||||
|
r.answer.append(dns.rrset.from_text(lqname, 1, IN, NS, "ns.a.b.stale."))
|
||||||
|
r.additional.append(
|
||||||
|
dns.rrset.from_text("ns.a.b.stale.", 1, IN, A, "10.53.0.3")
|
||||||
|
)
|
||||||
|
elif rrtype == SOA:
|
||||||
|
# SOA a.b.
|
||||||
|
r.answer.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
lqname, 1, IN, SOA, "a.b.stale. hostmaster.a.b.stale. 1 2 3 4 5"
|
||||||
|
)
|
||||||
|
)
|
||||||
|
else:
|
||||||
|
# NODATA.
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
lqname, 1, IN, SOA, "a.b.stale. hostmaster.a.b.stale. 1 2 3 4 5"
|
||||||
|
)
|
||||||
|
)
|
||||||
|
elif lqname == "ns.a.b.stale.":
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
if rrtype == A:
|
||||||
|
r.answer.append(
|
||||||
|
dns.rrset.from_text("ns.a.b.stale.", 1, IN, A, "10.53.0.3")
|
||||||
|
)
|
||||||
|
else:
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
lqname, 1, IN, SOA, "a.b.stale. hostmaster.a.b.stale. 1 2 3 4 5"
|
||||||
|
)
|
||||||
|
)
|
||||||
|
else:
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
lqname, 1, IN, SOA, "a.b.stale. hostmaster.a.b.stale. 1 2 3 4 5"
|
||||||
|
)
|
||||||
|
)
|
||||||
|
r.set_rcode(NXDOMAIN)
|
||||||
|
# NXDOMAIN.
|
||||||
|
return r
|
||||||
|
else:
|
||||||
|
r.set_rcode(REFUSED)
|
||||||
|
return r
|
||||||
|
|
||||||
|
# Good/bad differs only in how we treat non-empty terminals
|
||||||
|
if lqname == "zoop.boing." and rrtype == NS:
|
||||||
|
r.answer.append(
|
||||||
|
dns.rrset.from_text(lqname + suffix, 1, IN, NS, "ns3." + suffix)
|
||||||
|
)
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
elif endswith(lqname, "icky.ptang.zoop.boing."):
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"icky.ptang.zoop.boing." + suffix,
|
||||||
|
1,
|
||||||
|
IN,
|
||||||
|
NS,
|
||||||
|
"a.bit.longer.ns.name." + suffix,
|
||||||
|
)
|
||||||
|
)
|
||||||
|
elif endswith("icky.ptang.zoop.boing.", lqname):
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"zoop.boing." + suffix,
|
||||||
|
1,
|
||||||
|
IN,
|
||||||
|
SOA,
|
||||||
|
"ns3." + suffix + " hostmaster.arpa. 2018050100 1 1 1 1",
|
||||||
|
)
|
||||||
|
)
|
||||||
|
if bad:
|
||||||
|
r.set_rcode(NXDOMAIN)
|
||||||
|
if ugly:
|
||||||
|
r.set_rcode(FORMERR)
|
||||||
|
elif endswith(lqname, "zoop.boing."):
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"zoop.boing." + suffix,
|
||||||
|
1,
|
||||||
|
IN,
|
||||||
|
SOA,
|
||||||
|
"ns3." + suffix + " hostmaster.arpa. 2018050100 1 1 1 1",
|
||||||
|
)
|
||||||
|
)
|
||||||
|
r.set_rcode(NXDOMAIN)
|
||||||
|
elif ip6req:
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"1.1.1.1.8.2.6.0.1.0.0.2.ip6.arpa.", 60, IN, NS, "ns4.good."
|
||||||
|
)
|
||||||
|
)
|
||||||
|
r.additional.append(dns.rrset.from_text("ns4.good.", 60, IN, A, "10.53.0.4"))
|
||||||
|
else:
|
||||||
|
r.set_rcode(REFUSED)
|
||||||
|
|
||||||
|
if slow:
|
||||||
|
time.sleep(0.4)
|
||||||
|
return r
|
||||||
|
|
||||||
|
|
||||||
class ZoopBoingSlowHandler(DelayedResponseHandler):
|
def sigterm(signum, frame):
|
||||||
domains = ["zoop.boing.slow."]
|
print("Shutting down now...")
|
||||||
delay = 0.4
|
os.remove("ans.pid")
|
||||||
|
running = False
|
||||||
|
sys.exit(0)
|
||||||
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
############################################################################
|
||||||
server = AsyncDnsServer()
|
# Main
|
||||||
server.install_response_handler(QueryLogger())
|
#
|
||||||
server.install_response_handler(ZoopBoingBadHandler())
|
# Set up responder and control channel, open the pid file, and start
|
||||||
server.install_response_handler(ZoopBoingUglyHandler())
|
# the main loop, listening for queries on the query channel or commands
|
||||||
server.install_response_handler(ZoopBoingSlowHandler())
|
# on the control channel and acting on them.
|
||||||
server.run()
|
############################################################################
|
||||||
|
ip4 = "10.53.0.3"
|
||||||
|
ip6 = "fd92:7065:b8e:ffff::3"
|
||||||
|
|
||||||
|
try:
|
||||||
|
port = int(os.environ["PORT"])
|
||||||
|
except:
|
||||||
|
port = 5300
|
||||||
|
|
||||||
|
query4_socket = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
|
||||||
|
query4_socket.bind((ip4, port))
|
||||||
|
|
||||||
|
havev6 = True
|
||||||
|
try:
|
||||||
|
query6_socket = socket.socket(socket.AF_INET6, socket.SOCK_DGRAM)
|
||||||
|
try:
|
||||||
|
query6_socket.bind((ip6, port))
|
||||||
|
except:
|
||||||
|
query6_socket.close()
|
||||||
|
havev6 = False
|
||||||
|
except:
|
||||||
|
havev6 = False
|
||||||
|
|
||||||
|
signal.signal(signal.SIGTERM, sigterm)
|
||||||
|
|
||||||
|
f = open("ans.pid", "w")
|
||||||
|
pid = os.getpid()
|
||||||
|
print(pid, file=f)
|
||||||
|
f.close()
|
||||||
|
|
||||||
|
running = True
|
||||||
|
|
||||||
|
print("Listening on %s port %d" % (ip4, port))
|
||||||
|
if havev6:
|
||||||
|
print("Listening on %s port %d" % (ip6, port))
|
||||||
|
print("Ctrl-c to quit")
|
||||||
|
|
||||||
|
if havev6:
|
||||||
|
input = [query4_socket, query6_socket]
|
||||||
|
else:
|
||||||
|
input = [query4_socket]
|
||||||
|
|
||||||
|
while running:
|
||||||
|
try:
|
||||||
|
inputready, outputready, exceptready = select.select(input, [], [])
|
||||||
|
except select.error as e:
|
||||||
|
break
|
||||||
|
except socket.error as e:
|
||||||
|
break
|
||||||
|
except KeyboardInterrupt:
|
||||||
|
break
|
||||||
|
|
||||||
|
for s in inputready:
|
||||||
|
if s == query4_socket or s == query6_socket:
|
||||||
|
print(
|
||||||
|
"Query received on %s" % (ip4 if s == query4_socket else ip6), end=" "
|
||||||
|
)
|
||||||
|
# Handle incoming queries
|
||||||
|
msg = s.recvfrom(65535)
|
||||||
|
rsp = create_response(msg[0])
|
||||||
|
if rsp:
|
||||||
|
print(dns.rcode.to_text(rsp.rcode()))
|
||||||
|
s.sendto(rsp.to_wire(), msg[1])
|
||||||
|
else:
|
||||||
|
print("NO RESPONSE")
|
||||||
|
if not running:
|
||||||
|
break
|
||||||
|
|||||||
@@ -1,14 +0,0 @@
|
|||||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
;
|
|
||||||
; SPDX-License-Identifier: MPL-2.0
|
|
||||||
;
|
|
||||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
;
|
|
||||||
; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
; information regarding copyright ownership.
|
|
||||||
|
|
||||||
@ 1 SOA ns3.bad. hostmaster.arpa. 2018050100 1 1 1 1
|
|
||||||
@ 1 NS ns3.bad.
|
|
||||||
icky.ptang 1 NS a.bit.longer.ns.name.bad.
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
;
|
|
||||||
; SPDX-License-Identifier: MPL-2.0
|
|
||||||
;
|
|
||||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
;
|
|
||||||
; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
; information regarding copyright ownership.
|
|
||||||
|
|
||||||
@ 1 SOA ns3.good. hostmaster.arpa. 2018050100 1 1 1 1
|
|
||||||
@ 1 NS ns3.good.
|
|
||||||
icky.ptang 1 NS a.bit.longer.ns.name.good.
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
;
|
|
||||||
; SPDX-License-Identifier: MPL-2.0
|
|
||||||
;
|
|
||||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
;
|
|
||||||
; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
; information regarding copyright ownership.
|
|
||||||
|
|
||||||
@ 1 SOA ns3.slow. hostmaster.arpa. 2018050100 1 1 1 1
|
|
||||||
@ 1 NS ns3.slow.
|
|
||||||
icky.ptang 1 NS a.bit.longer.ns.name.slow.
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
;
|
|
||||||
; SPDX-License-Identifier: MPL-2.0
|
|
||||||
;
|
|
||||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
;
|
|
||||||
; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
; information regarding copyright ownership.
|
|
||||||
|
|
||||||
@ 1 SOA ns3.ugly. hostmaster.arpa. 2018050100 1 1 1 1
|
|
||||||
@ 1 NS ns3.ugly.
|
|
||||||
icky.ptang 1 NS a.bit.longer.ns.name.ugly.
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
;
|
|
||||||
; SPDX-License-Identifier: MPL-2.0
|
|
||||||
;
|
|
||||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
;
|
|
||||||
; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
; information regarding copyright ownership.
|
|
||||||
|
|
||||||
@ 30 SOA ns4.good. hostmaster.arpa. 2018050100 1 1 1 1
|
|
||||||
@ 30 NS ns4.good.
|
|
||||||
|
|
||||||
test1.test2.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.9.0.9.4 1 TXT "long_ip6_name"
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
;
|
|
||||||
; SPDX-License-Identifier: MPL-2.0
|
|
||||||
;
|
|
||||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
;
|
|
||||||
; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
; information regarding copyright ownership.
|
|
||||||
|
|
||||||
@ 1 SOA ns hostmaster.a.b.stale. 1 2 3 4 5
|
|
||||||
@ 1 NS ns
|
|
||||||
ns 1 A 10.53.0.4
|
|
||||||
@ 1 TXT "hooray"
|
|
||||||
Regular → Executable
+330
-79
@@ -1,93 +1,344 @@
|
|||||||
"""
|
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
#
|
||||||
|
# SPDX-License-Identifier: MPL-2.0
|
||||||
|
#
|
||||||
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
#
|
||||||
|
# See the COPYRIGHT file distributed with this work for additional
|
||||||
|
# information regarding copyright ownership.
|
||||||
|
|
||||||
SPDX-License-Identifier: MPL-2.0
|
from __future__ import print_function
|
||||||
|
import os
|
||||||
|
import sys
|
||||||
|
import signal
|
||||||
|
import socket
|
||||||
|
import select
|
||||||
|
from datetime import datetime, timedelta
|
||||||
|
import time
|
||||||
|
import functools
|
||||||
|
|
||||||
This Source Code Form is subject to the terms of the Mozilla Public
|
import dns, dns.message, dns.query, dns.flags
|
||||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
from dns.rdatatype import *
|
||||||
file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
from dns.rdataclass import *
|
||||||
|
from dns.rcode import *
|
||||||
See the COPYRIGHT file distributed with this work for additional
|
from dns.name import *
|
||||||
information regarding copyright ownership.
|
|
||||||
"""
|
|
||||||
|
|
||||||
from typing import AsyncGenerator
|
|
||||||
|
|
||||||
import dns.rcode
|
|
||||||
|
|
||||||
from isctest.asyncserver import (
|
|
||||||
AsyncDnsServer,
|
|
||||||
DnsResponseSend,
|
|
||||||
DomainHandler,
|
|
||||||
QueryContext,
|
|
||||||
ResponseAction,
|
|
||||||
)
|
|
||||||
|
|
||||||
from qmin_ans import DelayedResponseHandler, EntRcodeChanger, QueryLogHandler, log_query
|
|
||||||
|
|
||||||
|
|
||||||
class QueryLogger(QueryLogHandler):
|
# Log query to file
|
||||||
domains = [
|
def logquery(type, qname):
|
||||||
"1.1.1.1.8.2.6.0.1.0.0.2.ip6.arpa.",
|
with open("qlog", "a") as f:
|
||||||
"icky.ptang.zoop.boing.good.",
|
f.write("%s %s\n", type, qname)
|
||||||
]
|
|
||||||
|
|
||||||
|
|
||||||
class StaleHandler(DomainHandler):
|
def endswith(domain, labels):
|
||||||
"""
|
return domain.endswith("." + labels) or domain == labels
|
||||||
The test code relies on this server returning non-minimal (i.e. including
|
|
||||||
address records in the ADDITIONAL section) responses to NS queries for
|
|
||||||
`b.stale` and `a.b.stale`. While this logic (returning non-minimal
|
|
||||||
responses to NS queries) could be implemented in AsyncDnsServer itself,
|
|
||||||
doing so breaks a lot of other checks in this system test. Therefore, only
|
|
||||||
these two zones behave in this particular way, thanks to a custom response
|
|
||||||
handler implemented below.
|
|
||||||
"""
|
|
||||||
|
|
||||||
domains = ["b.stale", "a.b.stale"]
|
|
||||||
|
|
||||||
async def get_responses(
|
|
||||||
self, qctx: QueryContext
|
|
||||||
) -> AsyncGenerator[ResponseAction, None]:
|
|
||||||
log_query(qctx)
|
|
||||||
|
|
||||||
if qctx.qtype == dns.rdatatype.NS:
|
|
||||||
assert qctx.zone
|
|
||||||
assert qctx.response.answer[0]
|
|
||||||
|
|
||||||
for nameserver in qctx.response.answer[0]:
|
|
||||||
if not nameserver.target.is_subdomain(qctx.response.answer[0].name):
|
|
||||||
continue
|
|
||||||
glue_a = qctx.zone.get_rrset(nameserver.target, dns.rdatatype.A)
|
|
||||||
if glue_a:
|
|
||||||
qctx.response.additional.append(glue_a)
|
|
||||||
glue_aaaa = qctx.zone.get_rrset(nameserver.target, dns.rdatatype.AAAA)
|
|
||||||
if glue_aaaa:
|
|
||||||
qctx.response.additional.append(glue_aaaa)
|
|
||||||
|
|
||||||
yield DnsResponseSend(qctx.response)
|
|
||||||
|
|
||||||
|
|
||||||
class IckyPtangZoopBoingBadHandler(EntRcodeChanger):
|
############################################################################
|
||||||
domains = ["icky.ptang.zoop.boing.bad."]
|
# Respond to a DNS query.
|
||||||
rcode = dns.rcode.NXDOMAIN
|
# For good. it serves:
|
||||||
|
# icky.ptang.zoop.boing.good. NS a.bit.longer.ns.name.
|
||||||
|
# icky.icky.icky.ptang.zoop.boing.good. A 192.0.2.1
|
||||||
|
# more.icky.icky.icky.ptang.zoop.boing.good. A 192.0.2.2
|
||||||
|
# it responds properly (with NODATA empty response) to non-empty terminals
|
||||||
|
#
|
||||||
|
# For slow. it works the same as for good., but each response is delayed by 400 milliseconds
|
||||||
|
#
|
||||||
|
# For bad. it works the same as for good., but returns NXDOMAIN to non-empty terminals
|
||||||
|
#
|
||||||
|
# For ugly. it works the same as for good., but returns garbage to non-empty terminals
|
||||||
|
#
|
||||||
|
# For stale. it serves:
|
||||||
|
# a.b.stale. IN TXT hooray (resolver did do qname minimization)
|
||||||
|
############################################################################
|
||||||
|
def create_response(msg):
|
||||||
|
m = dns.message.from_wire(msg)
|
||||||
|
qname = m.question[0].name.to_text()
|
||||||
|
lqname = qname.lower()
|
||||||
|
labels = lqname.split(".")
|
||||||
|
suffix = ""
|
||||||
|
|
||||||
|
# get qtype
|
||||||
|
rrtype = m.question[0].rdtype
|
||||||
|
typename = dns.rdatatype.to_text(rrtype)
|
||||||
|
if typename == "A" or typename == "AAAA":
|
||||||
|
typename = "ADDR"
|
||||||
|
bad = False
|
||||||
|
slow = False
|
||||||
|
ugly = False
|
||||||
|
|
||||||
|
# log this query
|
||||||
|
with open("query.log", "a") as f:
|
||||||
|
f.write("%s %s\n" % (typename, lqname))
|
||||||
|
print("%s %s" % (typename, lqname), end=" ")
|
||||||
|
|
||||||
|
r = dns.message.make_response(m)
|
||||||
|
r.set_rcode(NOERROR)
|
||||||
|
|
||||||
|
ip6req = False
|
||||||
|
|
||||||
|
if endswith(lqname, "bad."):
|
||||||
|
bad = True
|
||||||
|
suffix = "bad."
|
||||||
|
lqname = lqname[:-4]
|
||||||
|
elif endswith(lqname, "ugly."):
|
||||||
|
ugly = True
|
||||||
|
suffix = "ugly."
|
||||||
|
lqname = lqname[:-5]
|
||||||
|
elif endswith(lqname, "good."):
|
||||||
|
suffix = "good."
|
||||||
|
lqname = lqname[:-5]
|
||||||
|
elif endswith(lqname, "slow."):
|
||||||
|
slow = True
|
||||||
|
suffix = "slow."
|
||||||
|
lqname = lqname[:-5]
|
||||||
|
elif endswith(lqname, "1.1.1.1.8.2.6.0.1.0.0.2.ip6.arpa."):
|
||||||
|
ip6req = True
|
||||||
|
elif endswith(lqname, "b.stale."):
|
||||||
|
if lqname == "a.b.stale.":
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
if rrtype == TXT:
|
||||||
|
# Direct query.
|
||||||
|
r.answer.append(dns.rrset.from_text(lqname, 1, IN, TXT, "hooray"))
|
||||||
|
elif rrtype == NS:
|
||||||
|
# NS a.b.
|
||||||
|
r.answer.append(dns.rrset.from_text(lqname, 1, IN, NS, "ns.a.b.stale."))
|
||||||
|
r.additional.append(
|
||||||
|
dns.rrset.from_text("ns.a.b.stale.", 1, IN, A, "10.53.0.3")
|
||||||
|
)
|
||||||
|
elif rrtype == SOA:
|
||||||
|
# SOA a.b.
|
||||||
|
r.answer.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
lqname, 1, IN, SOA, "a.b.stale. hostmaster.a.b.stale. 1 2 3 4 5"
|
||||||
|
)
|
||||||
|
)
|
||||||
|
else:
|
||||||
|
# NODATA.
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
lqname, 1, IN, SOA, "a.b.stale. hostmaster.a.b.stale. 1 2 3 4 5"
|
||||||
|
)
|
||||||
|
)
|
||||||
|
elif lqname == "ns.a.b.stale.":
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
if rrtype == A:
|
||||||
|
r.answer.append(
|
||||||
|
dns.rrset.from_text("ns.a.b.stale.", 1, IN, A, "10.53.0.3")
|
||||||
|
)
|
||||||
|
else:
|
||||||
|
# NODATA.
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
lqname, 1, IN, SOA, "a.b.stale. hostmaster.a.b.stale. 1 2 3 4 5"
|
||||||
|
)
|
||||||
|
)
|
||||||
|
elif lqname == "b.stale.":
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
if rrtype == NS:
|
||||||
|
# NS b.
|
||||||
|
r.answer.append(dns.rrset.from_text(lqname, 1, IN, NS, "ns.b.stale."))
|
||||||
|
r.additional.append(
|
||||||
|
dns.rrset.from_text("ns.b.stale.", 1, IN, A, "10.53.0.4")
|
||||||
|
)
|
||||||
|
elif rrtype == SOA:
|
||||||
|
# SOA b.
|
||||||
|
r.answer.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
lqname, 1, IN, SOA, "b.stale. hostmaster.b.stale. 1 2 3 4 5"
|
||||||
|
)
|
||||||
|
)
|
||||||
|
else:
|
||||||
|
# NODATA.
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
lqname, 1, IN, SOA, "b.stale. hostmaster.b.stale. 1 2 3 4 5"
|
||||||
|
)
|
||||||
|
)
|
||||||
|
elif lqname == "ns.b.stale.":
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
if rrtype == A:
|
||||||
|
# SOA a.b.
|
||||||
|
r.answer.append(
|
||||||
|
dns.rrset.from_text("ns.a.b.stale.", 1, IN, A, "10.53.0.4")
|
||||||
|
)
|
||||||
|
else:
|
||||||
|
# NODATA.
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
lqname, 1, IN, SOA, "b.stale. hostmaster.b.stale. 1 2 3 4 5"
|
||||||
|
)
|
||||||
|
)
|
||||||
|
else:
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
lqname, 1, IN, SOA, "b.stale. hostmaster.b.stale. 1 2 3 4 5"
|
||||||
|
)
|
||||||
|
)
|
||||||
|
r.set_rcode(NXDOMAIN)
|
||||||
|
# NXDOMAIN.
|
||||||
|
return r
|
||||||
|
else:
|
||||||
|
r.set_rcode(REFUSED)
|
||||||
|
return r
|
||||||
|
|
||||||
|
# Good/bad differs only in how we treat non-empty terminals
|
||||||
|
if lqname == "icky.icky.icky.ptang.zoop.boing." and rrtype == A:
|
||||||
|
r.answer.append(dns.rrset.from_text(lqname + suffix, 1, IN, A, "192.0.2.1"))
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
elif lqname == "more.icky.icky.icky.ptang.zoop.boing." and rrtype == A:
|
||||||
|
r.answer.append(dns.rrset.from_text(lqname + suffix, 1, IN, A, "192.0.2.2"))
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
elif lqname == "icky.ptang.zoop.boing." and rrtype == NS:
|
||||||
|
r.answer.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
lqname + suffix, 1, IN, NS, "a.bit.longer.ns.name." + suffix
|
||||||
|
)
|
||||||
|
)
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
elif endswith(lqname, "icky.ptang.zoop.boing."):
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"icky.ptang.zoop.boing." + suffix,
|
||||||
|
1,
|
||||||
|
IN,
|
||||||
|
SOA,
|
||||||
|
"ns2." + suffix + " hostmaster.arpa. 2018050100 1 1 1 1",
|
||||||
|
)
|
||||||
|
)
|
||||||
|
if bad or not endswith("more.icky.icky.icky.ptang.zoop.boing.", lqname):
|
||||||
|
r.set_rcode(NXDOMAIN)
|
||||||
|
if ugly:
|
||||||
|
r.set_rcode(FORMERR)
|
||||||
|
elif ip6req:
|
||||||
|
r.flags |= dns.flags.AA
|
||||||
|
if (
|
||||||
|
lqname
|
||||||
|
== "test1.test2.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.9.0.9.4.1.1.1.1.8.2.6.0.1.0.0.2.ip6.arpa."
|
||||||
|
and rrtype == TXT
|
||||||
|
):
|
||||||
|
r.answer.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"test1.test2.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.9.0.9.4.1.1.1.1.8.2.6.0.1.0.0.2.ip6.arpa.",
|
||||||
|
1,
|
||||||
|
IN,
|
||||||
|
TXT,
|
||||||
|
"long_ip6_name",
|
||||||
|
)
|
||||||
|
)
|
||||||
|
elif endswith(
|
||||||
|
"0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.9.0.9.4.1.1.1.1.8.2.6.0.1.0.0.2.ip6.arpa.",
|
||||||
|
lqname,
|
||||||
|
):
|
||||||
|
# NODATA answer
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"1.1.1.1.8.2.6.0.1.0.0.2.ip6.arpa.",
|
||||||
|
60,
|
||||||
|
IN,
|
||||||
|
SOA,
|
||||||
|
"ns4.good. hostmaster.arpa. 2018050100 120 30 320 16",
|
||||||
|
)
|
||||||
|
)
|
||||||
|
else:
|
||||||
|
# NXDOMAIN
|
||||||
|
r.authority.append(
|
||||||
|
dns.rrset.from_text(
|
||||||
|
"1.1.1.1.8.2.6.0.1.0.0.2.ip6.arpa.",
|
||||||
|
60,
|
||||||
|
IN,
|
||||||
|
SOA,
|
||||||
|
"ns4.good. hostmaster.arpa. 2018050100 120 30 320 16",
|
||||||
|
)
|
||||||
|
)
|
||||||
|
r.set_rcode(NXDOMAIN)
|
||||||
|
else:
|
||||||
|
r.set_rcode(REFUSED)
|
||||||
|
|
||||||
|
if slow:
|
||||||
|
time.sleep(0.4)
|
||||||
|
return r
|
||||||
|
|
||||||
|
|
||||||
class IckyPtangZoopBoingUglyHandler(EntRcodeChanger):
|
def sigterm(signum, frame):
|
||||||
domains = ["icky.ptang.zoop.boing.ugly."]
|
print("Shutting down now...")
|
||||||
rcode = dns.rcode.FORMERR
|
os.remove("ans.pid")
|
||||||
|
running = False
|
||||||
|
sys.exit(0)
|
||||||
|
|
||||||
|
|
||||||
class IckyPtangZoopBoingSlowHandler(DelayedResponseHandler):
|
############################################################################
|
||||||
domains = ["icky.ptang.zoop.boing.slow."]
|
# Main
|
||||||
delay = 0.4
|
#
|
||||||
|
# Set up responder and control channel, open the pid file, and start
|
||||||
|
# the main loop, listening for queries on the query channel or commands
|
||||||
|
# on the control channel and acting on them.
|
||||||
|
############################################################################
|
||||||
|
ip4 = "10.53.0.4"
|
||||||
|
ip6 = "fd92:7065:b8e:ffff::4"
|
||||||
|
|
||||||
|
try:
|
||||||
|
port = int(os.environ["PORT"])
|
||||||
|
except:
|
||||||
|
port = 5300
|
||||||
|
|
||||||
if __name__ == "__main__":
|
query4_socket = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
|
||||||
server = AsyncDnsServer()
|
query4_socket.bind((ip4, port))
|
||||||
server.install_response_handler(QueryLogger())
|
|
||||||
server.install_response_handler(StaleHandler())
|
havev6 = True
|
||||||
server.install_response_handler(IckyPtangZoopBoingBadHandler())
|
try:
|
||||||
server.install_response_handler(IckyPtangZoopBoingUglyHandler())
|
query6_socket = socket.socket(socket.AF_INET6, socket.SOCK_DGRAM)
|
||||||
server.install_response_handler(IckyPtangZoopBoingSlowHandler())
|
try:
|
||||||
server.run()
|
query6_socket.bind((ip6, port))
|
||||||
|
except:
|
||||||
|
query6_socket.close()
|
||||||
|
havev6 = False
|
||||||
|
except:
|
||||||
|
havev6 = False
|
||||||
|
|
||||||
|
signal.signal(signal.SIGTERM, sigterm)
|
||||||
|
|
||||||
|
f = open("ans.pid", "w")
|
||||||
|
pid = os.getpid()
|
||||||
|
print(pid, file=f)
|
||||||
|
f.close()
|
||||||
|
|
||||||
|
running = True
|
||||||
|
|
||||||
|
print("Listening on %s port %d" % (ip4, port))
|
||||||
|
if havev6:
|
||||||
|
print("Listening on %s port %d" % (ip6, port))
|
||||||
|
print("Ctrl-c to quit")
|
||||||
|
|
||||||
|
if havev6:
|
||||||
|
input = [query4_socket, query6_socket]
|
||||||
|
else:
|
||||||
|
input = [query4_socket]
|
||||||
|
|
||||||
|
while running:
|
||||||
|
try:
|
||||||
|
inputready, outputready, exceptready = select.select(input, [], [])
|
||||||
|
except select.error as e:
|
||||||
|
break
|
||||||
|
except socket.error as e:
|
||||||
|
break
|
||||||
|
except KeyboardInterrupt:
|
||||||
|
break
|
||||||
|
|
||||||
|
for s in inputready:
|
||||||
|
if s == query4_socket or s == query6_socket:
|
||||||
|
print(
|
||||||
|
"Query received on %s" % (ip4 if s == query4_socket else ip6), end=" "
|
||||||
|
)
|
||||||
|
# Handle incoming queries
|
||||||
|
msg = s.recvfrom(65535)
|
||||||
|
rsp = create_response(msg[0])
|
||||||
|
if rsp:
|
||||||
|
print(dns.rcode.to_text(rsp.rcode()))
|
||||||
|
s.sendto(rsp.to_wire(), msg[1])
|
||||||
|
else:
|
||||||
|
print("NO RESPONSE")
|
||||||
|
if not running:
|
||||||
|
break
|
||||||
|
|||||||
@@ -1,16 +0,0 @@
|
|||||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
;
|
|
||||||
; SPDX-License-Identifier: MPL-2.0
|
|
||||||
;
|
|
||||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
;
|
|
||||||
; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
; information regarding copyright ownership.
|
|
||||||
|
|
||||||
@ 1 SOA ns hostmaster.b.stale. 1 2 3 4 5
|
|
||||||
@ 1 NS ns
|
|
||||||
ns 1 A 10.53.0.4
|
|
||||||
a 1 NS ns.a
|
|
||||||
ns.a 1 A 10.53.0.4
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
;
|
|
||||||
; SPDX-License-Identifier: MPL-2.0
|
|
||||||
;
|
|
||||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
;
|
|
||||||
; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
; information regarding copyright ownership.
|
|
||||||
|
|
||||||
@ 1 SOA ns4.bad. hostmaster.arpa. 2018050100 1 1 1 1
|
|
||||||
@ 1 NS a.bit.longer.ns.name.bad.
|
|
||||||
icky.icky 1 A 192.0.2.1
|
|
||||||
more.icky.icky 1 A 192.0.2.2
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
;
|
|
||||||
; SPDX-License-Identifier: MPL-2.0
|
|
||||||
;
|
|
||||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
;
|
|
||||||
; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
; information regarding copyright ownership.
|
|
||||||
|
|
||||||
@ 1 SOA ns4.good. hostmaster.arpa. 2018050100 1 1 1 1
|
|
||||||
@ 1 NS a.bit.longer.ns.name.good.
|
|
||||||
icky.icky 1 A 192.0.2.1
|
|
||||||
more.icky.icky 1 A 192.0.2.2
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
;
|
|
||||||
; SPDX-License-Identifier: MPL-2.0
|
|
||||||
;
|
|
||||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
;
|
|
||||||
; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
; information regarding copyright ownership.
|
|
||||||
|
|
||||||
@ 1 SOA ns4.slow. hostmaster.arpa. 2018050100 1 1 1 1
|
|
||||||
@ 1 NS a.bit.longer.ns.name.slow.
|
|
||||||
icky.icky 1 A 192.0.2.1
|
|
||||||
more.icky.icky 1 A 192.0.2.2
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
;
|
|
||||||
; SPDX-License-Identifier: MPL-2.0
|
|
||||||
;
|
|
||||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
;
|
|
||||||
; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
; information regarding copyright ownership.
|
|
||||||
|
|
||||||
@ 1 SOA ns4.ugly. hostmaster.arpa. 2018050100 1 1 1 1
|
|
||||||
@ 1 NS a.bit.longer.ns.name.ugly.
|
|
||||||
icky.icky 1 A 192.0.2.1
|
|
||||||
more.icky.icky 1 A 192.0.2.2
|
|
||||||
@@ -1,107 +0,0 @@
|
|||||||
"""
|
|
||||||
Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
|
|
||||||
SPDX-License-Identifier: MPL-2.0
|
|
||||||
|
|
||||||
This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
|
|
||||||
See the COPYRIGHT file distributed with this work for additional
|
|
||||||
information regarding copyright ownership.
|
|
||||||
"""
|
|
||||||
|
|
||||||
from typing import AsyncGenerator
|
|
||||||
|
|
||||||
import abc
|
|
||||||
|
|
||||||
import dns.rcode
|
|
||||||
import dns.rdataclass
|
|
||||||
import dns.rdatatype
|
|
||||||
|
|
||||||
from isctest.asyncserver import (
|
|
||||||
DnsResponseSend,
|
|
||||||
DomainHandler,
|
|
||||||
QueryContext,
|
|
||||||
ResponseAction,
|
|
||||||
)
|
|
||||||
|
|
||||||
from isctest.compat import dns_rcode
|
|
||||||
|
|
||||||
|
|
||||||
def log_query(qctx: QueryContext) -> None:
|
|
||||||
"""
|
|
||||||
Log a received DNS query to a text file inspected by `tests.sh`. AAAA and
|
|
||||||
A queries are logged identically because the relative order in which they
|
|
||||||
are received does not matter.
|
|
||||||
"""
|
|
||||||
qname = qctx.qname.to_text()
|
|
||||||
qtype = dns.rdatatype.to_text(qctx.qtype)
|
|
||||||
if qtype in ("A", "AAAA"):
|
|
||||||
qtype = "ADDR"
|
|
||||||
|
|
||||||
with open("query.log", "a", encoding="utf-8") as query_log:
|
|
||||||
print(f"{qtype} {qname}", file=query_log)
|
|
||||||
|
|
||||||
|
|
||||||
class QueryLogHandler(DomainHandler):
|
|
||||||
"""
|
|
||||||
Log all received DNS queries to a text file. Use the zone file for
|
|
||||||
preparing responses.
|
|
||||||
"""
|
|
||||||
|
|
||||||
async def get_responses(
|
|
||||||
self, qctx: QueryContext
|
|
||||||
) -> AsyncGenerator[ResponseAction, None]:
|
|
||||||
log_query(qctx)
|
|
||||||
yield DnsResponseSend(qctx.response)
|
|
||||||
|
|
||||||
|
|
||||||
class EntRcodeChanger(DomainHandler):
|
|
||||||
"""
|
|
||||||
Log all received DNS queries to a text file. Use the zone file for
|
|
||||||
preparing responses, but override the RCODE returned for empty
|
|
||||||
non-terminals (ENTs) to the value specified by the child class. This
|
|
||||||
emulates broken authoritative servers.
|
|
||||||
"""
|
|
||||||
|
|
||||||
@property
|
|
||||||
@abc.abstractmethod
|
|
||||||
def rcode(self) -> dns_rcode:
|
|
||||||
raise NotImplementedError
|
|
||||||
|
|
||||||
async def get_responses(
|
|
||||||
self, qctx: QueryContext
|
|
||||||
) -> AsyncGenerator[ResponseAction, None]:
|
|
||||||
assert qctx.zone
|
|
||||||
|
|
||||||
log_query(qctx)
|
|
||||||
|
|
||||||
if (
|
|
||||||
qctx.response.rcode() == dns.rcode.NOERROR
|
|
||||||
and not qctx.response.answer
|
|
||||||
and qctx.response.authority
|
|
||||||
and qctx.response.authority[0].rdtype == dns.rdatatype.SOA
|
|
||||||
and not qctx.zone.get_node(qctx.qname)
|
|
||||||
):
|
|
||||||
qctx.response.set_rcode(self.rcode)
|
|
||||||
yield DnsResponseSend(qctx.response)
|
|
||||||
|
|
||||||
|
|
||||||
class DelayedResponseHandler(DomainHandler):
|
|
||||||
"""
|
|
||||||
Log all received DNS queries to a text file. Use the zone file for
|
|
||||||
preparing responses, but delay sending every answer by the amount of time
|
|
||||||
specified (in seconds) by the child class. This emulates network delays.
|
|
||||||
"""
|
|
||||||
|
|
||||||
@property
|
|
||||||
@abc.abstractmethod
|
|
||||||
def delay(self) -> float:
|
|
||||||
raise NotImplementedError
|
|
||||||
|
|
||||||
async def get_responses(
|
|
||||||
self, qctx: QueryContext
|
|
||||||
) -> AsyncGenerator[ResponseAction, None]:
|
|
||||||
log_query(qctx)
|
|
||||||
yield DnsResponseSend(qctx.response, delay=self.delay)
|
|
||||||
@@ -127,14 +127,12 @@ ADDR a.bit.longer.ns.name.good.
|
|||||||
ADDR ns2.good.
|
ADDR ns2.good.
|
||||||
ADDR ns3.good.
|
ADDR ns3.good.
|
||||||
ADDR ns3.good.
|
ADDR ns3.good.
|
||||||
NS a.bit.longer.ns.name.good.
|
|
||||||
NS bit.longer.ns.name.good.
|
NS bit.longer.ns.name.good.
|
||||||
NS boing.good.
|
NS boing.good.
|
||||||
NS good.
|
NS good.
|
||||||
NS longer.ns.name.good.
|
NS longer.ns.name.good.
|
||||||
NS name.good.
|
NS name.good.
|
||||||
NS ns.name.good.
|
NS ns.name.good.
|
||||||
NS ns3.good.
|
|
||||||
NS zoop.boing.good.
|
NS zoop.boing.good.
|
||||||
__EOF
|
__EOF
|
||||||
cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1
|
cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1
|
||||||
@@ -167,13 +165,11 @@ ADDR a.bit.longer.ns.name.good.
|
|||||||
ADDR ns2.good.
|
ADDR ns2.good.
|
||||||
ADDR ns3.good.
|
ADDR ns3.good.
|
||||||
ADDR ns3.good.
|
ADDR ns3.good.
|
||||||
NS a.bit.longer.ns.name.good.
|
|
||||||
NS bit.longer.ns.name.good.
|
NS bit.longer.ns.name.good.
|
||||||
NS boing.good.
|
NS boing.good.
|
||||||
NS longer.ns.name.good.
|
NS longer.ns.name.good.
|
||||||
NS name.good.
|
NS name.good.
|
||||||
NS ns.name.good.
|
NS ns.name.good.
|
||||||
NS ns3.good.
|
|
||||||
NS zoop.boing.good.
|
NS zoop.boing.good.
|
||||||
__EOF
|
__EOF
|
||||||
cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1
|
cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1
|
||||||
@@ -225,7 +221,6 @@ ADDR ns3.bad.
|
|||||||
ADDR ns3.bad.
|
ADDR ns3.bad.
|
||||||
NS boing.bad.
|
NS boing.bad.
|
||||||
NS name.bad.
|
NS name.bad.
|
||||||
NS ns3.bad.
|
|
||||||
__EOF
|
__EOF
|
||||||
cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1
|
cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1
|
||||||
ADDR icky.icky.icky.ptang.zoop.boing.bad.
|
ADDR icky.icky.icky.ptang.zoop.boing.bad.
|
||||||
@@ -276,7 +271,6 @@ ADDR ns3.ugly.
|
|||||||
NS boing.ugly.
|
NS boing.ugly.
|
||||||
NS name.ugly.
|
NS name.ugly.
|
||||||
NS name.ugly.
|
NS name.ugly.
|
||||||
NS ns3.ugly.
|
|
||||||
__EOF
|
__EOF
|
||||||
echo "ADDR icky.icky.icky.ptang.zoop.boing.ugly." | diff ans3/query.log - >/dev/null || ret=1
|
echo "ADDR icky.icky.icky.ptang.zoop.boing.ugly." | diff ans3/query.log - >/dev/null || ret=1
|
||||||
echo "ADDR icky.icky.icky.ptang.zoop.boing.ugly." | diff ans4/query.log - >/dev/null || ret=1
|
echo "ADDR icky.icky.icky.ptang.zoop.boing.ugly." | diff ans4/query.log - >/dev/null || ret=1
|
||||||
@@ -308,13 +302,11 @@ ADDR a.bit.longer.ns.name.slow.
|
|||||||
ADDR ns2.slow.
|
ADDR ns2.slow.
|
||||||
ADDR ns3.slow.
|
ADDR ns3.slow.
|
||||||
ADDR ns3.slow.
|
ADDR ns3.slow.
|
||||||
NS a.bit.longer.ns.name.slow.
|
|
||||||
NS bit.longer.ns.name.slow.
|
NS bit.longer.ns.name.slow.
|
||||||
NS boing.slow.
|
NS boing.slow.
|
||||||
NS longer.ns.name.slow.
|
NS longer.ns.name.slow.
|
||||||
NS name.slow.
|
NS name.slow.
|
||||||
NS ns.name.slow.
|
NS ns.name.slow.
|
||||||
NS ns3.slow.
|
|
||||||
NS slow.
|
NS slow.
|
||||||
NS zoop.boing.slow.
|
NS zoop.boing.slow.
|
||||||
__EOF
|
__EOF
|
||||||
@@ -348,7 +340,6 @@ NS 8.f.4.0.1.0.0.2.ip6.arpa.
|
|||||||
NS 0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
|
NS 0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
|
||||||
NS 0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
|
NS 0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
|
||||||
NS 0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
|
NS 0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
|
||||||
NS 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
|
|
||||||
PTR 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
|
PTR 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.f.4.0.1.0.0.2.ip6.arpa.
|
||||||
__EOF
|
__EOF
|
||||||
for ans in ans2 ans3 ans4; do mv -f $ans/query.log query-$ans-$n.log 2>/dev/null || true; done
|
for ans in ans2 ans3 ans4; do mv -f $ans/query.log query-$ans-$n.log 2>/dev/null || true; done
|
||||||
@@ -371,14 +362,12 @@ ADDR a.bit.longer.ns.name.good.
|
|||||||
ADDR ns2.good.
|
ADDR ns2.good.
|
||||||
ADDR ns3.good.
|
ADDR ns3.good.
|
||||||
ADDR ns3.good.
|
ADDR ns3.good.
|
||||||
NS a.bit.longer.ns.name.good.
|
|
||||||
NS bit.longer.ns.name.good.
|
NS bit.longer.ns.name.good.
|
||||||
NS boing.good.
|
NS boing.good.
|
||||||
NS good.
|
NS good.
|
||||||
NS longer.ns.name.good.
|
NS longer.ns.name.good.
|
||||||
NS name.good.
|
NS name.good.
|
||||||
NS ns.name.good.
|
NS ns.name.good.
|
||||||
NS ns3.good.
|
|
||||||
NS zoop.boing.good.
|
NS zoop.boing.good.
|
||||||
__EOF
|
__EOF
|
||||||
cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1
|
cat <<__EOF | diff ans3/query.log - >/dev/null || ret=1
|
||||||
@@ -460,7 +449,6 @@ grep "a\.b\.stale\..*1.*IN.*TXT.*hooray" dig.out.test$n >/dev/null || ret=1
|
|||||||
sleep 1
|
sleep 1
|
||||||
sort ans2/query.log >ans2/query.log.sorted
|
sort ans2/query.log >ans2/query.log.sorted
|
||||||
cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1
|
cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1
|
||||||
ADDR ns.a.b.stale.
|
|
||||||
ADDR ns.b.stale.
|
ADDR ns.b.stale.
|
||||||
ADDR ns2.stale.
|
ADDR ns2.stale.
|
||||||
NS b.stale.
|
NS b.stale.
|
||||||
@@ -469,9 +457,7 @@ __EOF
|
|||||||
test -f ans3/query.log && ret=1
|
test -f ans3/query.log && ret=1
|
||||||
sort ans4/query.log >ans4/query.log.sorted
|
sort ans4/query.log >ans4/query.log.sorted
|
||||||
cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1
|
cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1
|
||||||
ADDR ns.a.b.stale.
|
|
||||||
ADDR ns.b.stale.
|
ADDR ns.b.stale.
|
||||||
NS a.b.stale.
|
|
||||||
NS b.stale.
|
NS b.stale.
|
||||||
TXT a.b.stale.
|
TXT a.b.stale.
|
||||||
__EOF
|
__EOF
|
||||||
@@ -490,7 +476,6 @@ grep "a\.b\.stale\..*1.*IN.*TXT.*hooray" dig.out.test$n >/dev/null || ret=1
|
|||||||
sleep 1
|
sleep 1
|
||||||
sort ans2/query.log >ans2/query.log.sorted
|
sort ans2/query.log >ans2/query.log.sorted
|
||||||
cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1
|
cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1
|
||||||
ADDR ns.a.b.stale.
|
|
||||||
ADDR ns.b.stale.
|
ADDR ns.b.stale.
|
||||||
ADDR ns2.stale.
|
ADDR ns2.stale.
|
||||||
NS b.stale.
|
NS b.stale.
|
||||||
@@ -498,9 +483,7 @@ __EOF
|
|||||||
test -f ans3/query.log && ret=1
|
test -f ans3/query.log && ret=1
|
||||||
sort ans4/query.log >ans4/query.log.sorted
|
sort ans4/query.log >ans4/query.log.sorted
|
||||||
cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1
|
cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1
|
||||||
ADDR ns.a.b.stale.
|
|
||||||
ADDR ns.b.stale.
|
ADDR ns.b.stale.
|
||||||
NS a.b.stale.
|
|
||||||
TXT a.b.stale.
|
TXT a.b.stale.
|
||||||
__EOF
|
__EOF
|
||||||
for ans in ans2 ans3 ans4; do mv -f $ans/query.log query-$ans-$n.log 2>/dev/null || true; done
|
for ans in ans2 ans3 ans4; do mv -f $ans/query.log query-$ans-$n.log 2>/dev/null || true; done
|
||||||
@@ -536,7 +519,6 @@ grep "a\.b\.stale\..*1.*IN.*TXT.*hooray" dig.out.test$n >/dev/null || ret=1
|
|||||||
sleep 1
|
sleep 1
|
||||||
sort ans2/query.log >ans2/query.log.sorted
|
sort ans2/query.log >ans2/query.log.sorted
|
||||||
cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1
|
cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1
|
||||||
ADDR ns.a.b.stale.
|
|
||||||
ADDR ns.b.stale.
|
ADDR ns.b.stale.
|
||||||
ADDR ns2.stale.
|
ADDR ns2.stale.
|
||||||
NS b.stale.
|
NS b.stale.
|
||||||
@@ -545,9 +527,7 @@ __EOF
|
|||||||
test -f ans3/query.log && ret=1
|
test -f ans3/query.log && ret=1
|
||||||
sort ans4/query.log >ans4/query.log.sorted
|
sort ans4/query.log >ans4/query.log.sorted
|
||||||
cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1
|
cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1
|
||||||
ADDR ns.a.b.stale.
|
|
||||||
ADDR ns.b.stale.
|
ADDR ns.b.stale.
|
||||||
NS a.b.stale.
|
|
||||||
NS b.stale.
|
NS b.stale.
|
||||||
TXT a.b.stale.
|
TXT a.b.stale.
|
||||||
__EOF
|
__EOF
|
||||||
@@ -566,7 +546,6 @@ grep "a\.b\.stale\..*1.*IN.*TXT.*hooray" dig.out.test$n >/dev/null || ret=1
|
|||||||
sleep 1
|
sleep 1
|
||||||
sort ans2/query.log >ans2/query.log.sorted
|
sort ans2/query.log >ans2/query.log.sorted
|
||||||
cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1
|
cat <<__EOF | diff ans2/query.log.sorted - >/dev/null || ret=1
|
||||||
ADDR ns.a.b.stale.
|
|
||||||
ADDR ns.b.stale.
|
ADDR ns.b.stale.
|
||||||
ADDR ns2.stale.
|
ADDR ns2.stale.
|
||||||
NS b.stale.
|
NS b.stale.
|
||||||
@@ -574,9 +553,7 @@ __EOF
|
|||||||
test -f ans3/query.log && ret=1
|
test -f ans3/query.log && ret=1
|
||||||
sort ans4/query.log >ans4/query.log.sorted
|
sort ans4/query.log >ans4/query.log.sorted
|
||||||
cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1
|
cat <<__EOF | diff ans4/query.log.sorted - >/dev/null || ret=1
|
||||||
ADDR ns.a.b.stale.
|
|
||||||
ADDR ns.b.stale.
|
ADDR ns.b.stale.
|
||||||
NS a.b.stale.
|
|
||||||
TXT a.b.stale.
|
TXT a.b.stale.
|
||||||
__EOF
|
__EOF
|
||||||
for ans in ans2 ans3 ans4; do mv -f $ans/query.log query-$ans-$n.log 2>/dev/null || true; done
|
for ans in ans2 ans3 ans4; do mv -f $ans/query.log query-$ans-$n.log 2>/dev/null || true; done
|
||||||
|
|||||||
@@ -9,9 +9,9 @@
|
|||||||
; See the COPYRIGHT file distributed with this work for additional
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
; information regarding copyright ownership.
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
$TTL 120
|
$TTL 60
|
||||||
|
|
||||||
big. IN SOA ns.big. hostmaster.ns.big. 1 0 0 0 120
|
big. IN SOA ns.big. hostmaster.ns.big. 1 0 0 0 60
|
||||||
big. IN NS ns.big.
|
big. IN NS ns.big.
|
||||||
ns.big. IN A 10.53.0.1
|
ns.big. IN A 10.53.0.1
|
||||||
|
|
||||||
|
|||||||
@@ -280,11 +280,11 @@ echo_i "checking that priority names under the max-types-per-name limit get cach
|
|||||||
|
|
||||||
# Query for NXDOMAIN for items on our priority list - these should get cached
|
# Query for NXDOMAIN for items on our priority list - these should get cached
|
||||||
for rrtype in AAAA MX NS; do
|
for rrtype in AAAA MX NS; do
|
||||||
check_manytypes 1 manytypes.big "${rrtype}" NOERROR big SOA 120 || ret=1
|
check_manytypes 1 manytypes.big "${rrtype}" NOERROR big SOA 60 || ret=1
|
||||||
done
|
done
|
||||||
# Wait at least 1 second
|
# Wait at least 1 second
|
||||||
for rrtype in AAAA MX NS; do
|
for rrtype in AAAA MX NS; do
|
||||||
check_manytypes 2 manytypes.big "${rrtype}" NOERROR big SOA "" 120 || ret=1
|
check_manytypes 2 manytypes.big "${rrtype}" NOERROR big SOA "" 60 || ret=1
|
||||||
done
|
done
|
||||||
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
@@ -299,13 +299,13 @@ echo_i "checking that NXDOMAIN names under the max-types-per-name limit get cach
|
|||||||
|
|
||||||
# Query for 10 NXDOMAIN types
|
# Query for 10 NXDOMAIN types
|
||||||
for ntype in $(seq 65270 65279); do
|
for ntype in $(seq 65270 65279); do
|
||||||
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR big SOA 120 || ret=1
|
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR big SOA 60 || ret=1
|
||||||
done
|
done
|
||||||
# Wait at least 1 second
|
# Wait at least 1 second
|
||||||
sleep 1
|
sleep 1
|
||||||
# Query for 10 NXDOMAIN types again - these should be cached
|
# Query for 10 NXDOMAIN types again - these should be cached
|
||||||
for ntype in $(seq 65270 65279); do
|
for ntype in $(seq 65270 65279); do
|
||||||
check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR big SOA "" 120 || ret=1
|
check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR big SOA "" 60 || ret=1
|
||||||
done
|
done
|
||||||
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
@@ -318,13 +318,13 @@ echo_i "checking that existing names under the max-types-per-name limit get cach
|
|||||||
|
|
||||||
# Limited to 10 types - these should be cached and the previous record should be evicted
|
# Limited to 10 types - these should be cached and the previous record should be evicted
|
||||||
for ntype in $(seq 65280 65289); do
|
for ntype in $(seq 65280 65289); do
|
||||||
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 120 || ret=1
|
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 60 || ret=1
|
||||||
done
|
done
|
||||||
# Wait at least one second
|
# Wait at least one second
|
||||||
sleep 1
|
sleep 1
|
||||||
# Limited to 10 types - these should be cached
|
# Limited to 10 types - these should be cached
|
||||||
for ntype in $(seq 65280 65289); do
|
for ntype in $(seq 65280 65289); do
|
||||||
check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" "" 120 || ret=1
|
check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" "" 60 || ret=1
|
||||||
done
|
done
|
||||||
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
@@ -356,11 +356,11 @@ echo_i "checking that priority NXDOMAIN names over the max-types-per-name limit
|
|||||||
|
|
||||||
# Query for NXDOMAIN for items on our priority list - these should get cached
|
# Query for NXDOMAIN for items on our priority list - these should get cached
|
||||||
for rrtype in AAAA MX NS; do
|
for rrtype in AAAA MX NS; do
|
||||||
check_manytypes 1 manytypes.big "${rrtype}" NOERROR big SOA 120 || ret=1
|
check_manytypes 1 manytypes.big "${rrtype}" NOERROR big SOA 60 || ret=1
|
||||||
done
|
done
|
||||||
# Wait at least 1 second
|
# Wait at least 1 second
|
||||||
for rrtype in AAAA MX NS; do
|
for rrtype in AAAA MX NS; do
|
||||||
check_manytypes 2 manytypes.big "${rrtype}" NOERROR big SOA "" 120 || ret=1
|
check_manytypes 2 manytypes.big "${rrtype}" NOERROR big SOA "" 60 || ret=1
|
||||||
done
|
done
|
||||||
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
@@ -372,11 +372,11 @@ ret=0
|
|||||||
echo_i "checking that priority name over the max-types-per-name get cached ($n)"
|
echo_i "checking that priority name over the max-types-per-name get cached ($n)"
|
||||||
|
|
||||||
# Query for an item on our priority list - it should get cached
|
# Query for an item on our priority list - it should get cached
|
||||||
check_manytypes 1 manytypes.big "A" NOERROR manytypes.big A 120 || ret=1
|
check_manytypes 1 manytypes.big "A" NOERROR manytypes.big A 60 || ret=1
|
||||||
# Wait at least 1 second
|
# Wait at least 1 second
|
||||||
sleep 1
|
sleep 1
|
||||||
# Query the same name again - it should be in the cache
|
# Query the same name again - it should be in the cache
|
||||||
check_manytypes 2 manytypes.big "A" NOERROR big manytypes.A "" 120 || ret=1
|
check_manytypes 2 manytypes.big "A" NOERROR big manytypes.A "" 60 || ret=1
|
||||||
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
@@ -389,7 +389,7 @@ ret=0
|
|||||||
echo_i "checking that priority name over the max-types-per-name don't get evicted ($n)"
|
echo_i "checking that priority name over the max-types-per-name don't get evicted ($n)"
|
||||||
|
|
||||||
# Query for an item on our priority list - it should get cached
|
# Query for an item on our priority list - it should get cached
|
||||||
check_manytypes 1 manytypes.big "A" NOERROR manytypes.big A 120 || ret=1
|
check_manytypes 1 manytypes.big "A" NOERROR manytypes.big A 60 || ret=1
|
||||||
# Query for 10 more types - this should not evict A record
|
# Query for 10 more types - this should not evict A record
|
||||||
for ntype in $(seq 65280 65289); do
|
for ntype in $(seq 65280 65289); do
|
||||||
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big || ret=1
|
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big || ret=1
|
||||||
@@ -397,9 +397,9 @@ done
|
|||||||
# Wait at least 1 second
|
# Wait at least 1 second
|
||||||
sleep 1
|
sleep 1
|
||||||
# Query the same name again - it should be in the cache
|
# Query the same name again - it should be in the cache
|
||||||
check_manytypes 2 manytypes.big "A" NOERROR manytypes.big A "" 120 || ret=1
|
check_manytypes 2 manytypes.big "A" NOERROR manytypes.big A "" 60 || ret=1
|
||||||
# This one was first in the list and should have been evicted
|
# This one was first in the list and should have been evicted
|
||||||
check_manytypes 2 manytypes.big "TYPE65280" NOERROR manytypes.big TYPE65280 120 || ret=1
|
check_manytypes 2 manytypes.big "TYPE65280" NOERROR manytypes.big TYPE65280 60 || ret=1
|
||||||
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
@@ -413,21 +413,21 @@ echo_i "checking that non-priority types cause eviction ($n)"
|
|||||||
|
|
||||||
# Everything on top of that will cause the cache eviction
|
# Everything on top of that will cause the cache eviction
|
||||||
for ntype in $(seq 65280 65299); do
|
for ntype in $(seq 65280 65299); do
|
||||||
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 120 || ret=1
|
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 60 || ret=1
|
||||||
done
|
done
|
||||||
# Wait at least one second
|
# Wait at least one second
|
||||||
sleep 1
|
sleep 1
|
||||||
# These should have TTL != 120 now
|
# These should have TTL != 60 now
|
||||||
for ntype in $(seq 65290 65299); do
|
for ntype in $(seq 65290 65299); do
|
||||||
check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" "" 120 || ret=1
|
check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" "" 60 || ret=1
|
||||||
done
|
done
|
||||||
# These should have been evicted
|
# These should have been evicted
|
||||||
for ntype in $(seq 65280 65289); do
|
for ntype in $(seq 65280 65289); do
|
||||||
check_manytypes 3 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 120 || ret=1
|
check_manytypes 3 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 60 || ret=1
|
||||||
done
|
done
|
||||||
# These should have been evicted by the previous block
|
# These should have been evicted by the previous block
|
||||||
for ntype in $(seq 65290 65299); do
|
for ntype in $(seq 65290 65299); do
|
||||||
check_manytypes 4 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 120 || ret=1
|
check_manytypes 4 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 60 || ret=1
|
||||||
done
|
done
|
||||||
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
@@ -442,25 +442,25 @@ echo_i "checking that signed names under the max-types-per-name limit get cached
|
|||||||
|
|
||||||
# Go through the 10 items, this should result in 20 items (type + rrsig(type))
|
# Go through the 10 items, this should result in 20 items (type + rrsig(type))
|
||||||
for ntype in $(seq 65280 65289); do
|
for ntype in $(seq 65280 65289); do
|
||||||
check_manytypes 1 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" 120 || ret=1
|
check_manytypes 1 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" 60 || ret=1
|
||||||
done
|
done
|
||||||
|
|
||||||
# Wait at least one second
|
# Wait at least one second
|
||||||
sleep 1
|
sleep 1
|
||||||
|
|
||||||
# These should have TTL != 120 now
|
# These should have TTL != 60 now
|
||||||
for ntype in $(seq 65285 65289); do
|
for ntype in $(seq 65285 65289); do
|
||||||
check_manytypes 2 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" "" 120 || ret=1
|
check_manytypes 2 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" "" 60 || ret=1
|
||||||
done
|
done
|
||||||
|
|
||||||
# These should have been evicted
|
# These should have been evicted
|
||||||
for ntype in $(seq 65280 65284); do
|
for ntype in $(seq 65280 65284); do
|
||||||
check_manytypes 3 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" 120 || ret=1
|
check_manytypes 3 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" 60 || ret=1
|
||||||
done
|
done
|
||||||
|
|
||||||
# These should have been evicted by the previous block
|
# These should have been evicted by the previous block
|
||||||
for ntype in $(seq 65285 65289); do
|
for ntype in $(seq 65285 65289); do
|
||||||
check_manytypes 4 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" 120 || ret=1
|
check_manytypes 4 manytypes.signed "TYPE${ntype}" NOERROR manytypes.signed "TYPE${ntype}" 60 || ret=1
|
||||||
done
|
done
|
||||||
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
@@ -475,12 +475,12 @@ echo_i "checking that lifting the limit will allow everything to get cached ($n)
|
|||||||
ns3_reset ns3/named6.conf.in
|
ns3_reset ns3/named6.conf.in
|
||||||
|
|
||||||
for ntype in $(seq 65280 65534); do
|
for ntype in $(seq 65280 65534); do
|
||||||
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 120 || ret=1
|
check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" 60 || ret=1
|
||||||
done
|
done
|
||||||
# Wait at least one second
|
# Wait at least one second
|
||||||
sleep 1
|
sleep 1
|
||||||
for ntype in $(seq 65280 65534); do
|
for ntype in $(seq 65280 65534); do
|
||||||
check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" "" 120 || ret=1
|
check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR manytypes.big "TYPE${ntype}" "" 60 || ret=1
|
||||||
done
|
done
|
||||||
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
|
|||||||
@@ -24,6 +24,5 @@ copy_setports ns5/named.conf.in ns5/named.conf
|
|||||||
copy_setports ns6/named.conf.in ns6/named.conf
|
copy_setports ns6/named.conf.in ns6/named.conf
|
||||||
copy_setports ns7/named1.conf.in ns7/named.conf
|
copy_setports ns7/named1.conf.in ns7/named.conf
|
||||||
copy_setports ns9/named.conf.in ns9/named.conf
|
copy_setports ns9/named.conf.in ns9/named.conf
|
||||||
copy_setports ns11/named.conf.in ns11/named.conf
|
|
||||||
|
|
||||||
(cd ns6 && $SHELL keygen.sh)
|
(cd ns6 && $SHELL keygen.sh)
|
||||||
|
|||||||
@@ -43,12 +43,6 @@ grep "status: NOERROR" dig.out.ns1.test${n} >/dev/null || ret=1
|
|||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|
||||||
rndccmd 10.53.0.1 stats || ret=1 # Get the responses, RTT and timeout statistics before the following timeout tests
|
|
||||||
grep -F 'responses received' ns1/named.stats >ns1/named.stats.responses-before || true
|
|
||||||
grep -F 'queries with RTT' ns1/named.stats >ns1/named.stats.rtt-before || true
|
|
||||||
grep -F 'query timeouts' ns1/named.stats >ns1/named.stats.timeouts-before || true
|
|
||||||
mv ns1/named.stats ns1/named.stats-before
|
|
||||||
|
|
||||||
# 'resolver-query-timeout' is set to 5 seconds in ns1, so dig with a lower
|
# 'resolver-query-timeout' is set to 5 seconds in ns1, so dig with a lower
|
||||||
# timeout value should give up earlier than that.
|
# timeout value should give up earlier than that.
|
||||||
n=$((n + 1))
|
n=$((n + 1))
|
||||||
@@ -72,20 +66,6 @@ grep -F "EDE: 22 (No Reachable Authority)" dig.out.ns1.test${n} >/dev/null || re
|
|||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|
||||||
n=$((n + 1))
|
|
||||||
echo_i "checking that the timeout didn't skew the resolver responses counters and did update the timeout counter ($n)"
|
|
||||||
ret=0
|
|
||||||
rndccmd 10.53.0.1 stats || ret=1
|
|
||||||
grep -F 'responses received' ns1/named.stats >ns1/named.stats.responses-after || true
|
|
||||||
grep -F 'queries with RTT' ns1/named.stats >ns1/named.stats.rtt-after || true
|
|
||||||
grep -F 'query timeouts' ns1/named.stats >ns1/named.stats.timeouts-after || true
|
|
||||||
mv ns1/named.stats ns1/named.stats-after
|
|
||||||
diff ns1/named.stats.responses-before ns1/named.stats.responses-after >/dev/null || ret=1
|
|
||||||
diff ns1/named.stats.rtt-before ns1/named.stats.rtt-after >/dev/null || ret=1
|
|
||||||
diff ns1/named.stats.timeouts-before ns1/named.stats.timeouts-after >/dev/null && ret=1
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
|
||||||
status=$((status + ret))
|
|
||||||
|
|
||||||
# 'resolver-query-timeout' is set to 5 seconds in ns1, so named should
|
# 'resolver-query-timeout' is set to 5 seconds in ns1, so named should
|
||||||
# interrupt the non-responsive query and send a SERVFAIL answer before dig's
|
# interrupt the non-responsive query and send a SERVFAIL answer before dig's
|
||||||
# own timeout fires, which is set to 7 seconds. This time, exampleudp.net is
|
# own timeout fires, which is set to 7 seconds. This time, exampleudp.net is
|
||||||
@@ -749,10 +729,10 @@ if ${FEATURETEST} --enable-querytrace; then
|
|||||||
grep "status: SERVFAIL" dig.ns5.out.${n} >/dev/null || ret=1
|
grep "status: SERVFAIL" dig.ns5.out.${n} >/dev/null || ret=1
|
||||||
check_namedrun() {
|
check_namedrun() {
|
||||||
nextpartpeek ns5/named.run >nextpart.out.${n}
|
nextpartpeek ns5/named.run >nextpart.out.${n}
|
||||||
grep 'resolving tcpalso.no-questions/NS for [^:]*: empty question section, accepting it anyway as TC=1' nextpart.out.${n} >/dev/null || return 1
|
grep 'resolving tcpalso.no-questions/A for [^:]*: empty question section, accepting it anyway as TC=1' nextpart.out.${n} >/dev/null || return 1
|
||||||
grep '(tcpalso.no-questions/NS): connecting via TCP' nextpart.out.${n} >/dev/null || return 1
|
grep '(tcpalso.no-questions/A): connecting via TCP' nextpart.out.${n} >/dev/null || return 1
|
||||||
grep 'resolving tcpalso.no-questions/NS for [^:]*: empty question section$' nextpart.out.${n} >/dev/null || return 1
|
grep 'resolving tcpalso.no-questions/A for [^:]*: empty question section$' nextpart.out.${n} >/dev/null || return 1
|
||||||
grep '(tcpalso.no-questions/NS): nextitem' nextpart.out.${n} >/dev/null || return 1
|
grep '(tcpalso.no-questions/A): nextitem' nextpart.out.${n} >/dev/null || return 1
|
||||||
return 0
|
return 0
|
||||||
}
|
}
|
||||||
retry_quiet 12 check_namedrun || ret=1
|
retry_quiet 12 check_namedrun || ret=1
|
||||||
@@ -1035,14 +1015,5 @@ ttl=$(awk '{print $2}' dig.ns1.out.${n})
|
|||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|
||||||
n=$((n + 1))
|
|
||||||
echo_i "client requests recursion but it is disabled - expect EDE 20 code with REFUSED($n)"
|
|
||||||
ret=0
|
|
||||||
dig_with_opts +recurse www.isc.org @10.53.0.11 a >dig.out.ns11.test${n} || ret=1
|
|
||||||
grep "status: REFUSED" dig.out.ns11.test${n} >/dev/null || ret=1
|
|
||||||
grep -F "EDE: 20 (Not Authoritative)" dig.out.ns11.test${n} >/dev/null || ret=1
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
|
||||||
status=$((status + ret))
|
|
||||||
|
|
||||||
echo_i "exit status: $status"
|
echo_i "exit status: $status"
|
||||||
[ $status -eq 0 ] || exit 1
|
[ $status -eq 0 ] || exit 1
|
||||||
|
|||||||
@@ -21,7 +21,6 @@ pytestmark = pytest.mark.extra_artifacts(
|
|||||||
"nextpart.out.*",
|
"nextpart.out.*",
|
||||||
"ans*/ans.run",
|
"ans*/ans.run",
|
||||||
"ans*/query.log",
|
"ans*/query.log",
|
||||||
"ns1/named.stats*",
|
|
||||||
"ns4/tld.db",
|
"ns4/tld.db",
|
||||||
"ns5/trusted.conf",
|
"ns5/trusted.conf",
|
||||||
"ns6/K*",
|
"ns6/K*",
|
||||||
|
|||||||
@@ -102,23 +102,6 @@ def test_rpz_passthru_logging():
|
|||||||
dns.rrset.from_text("allowed.", 300, "IN", "A", "10.53.0.2")
|
dns.rrset.from_text("allowed.", 300, "IN", "A", "10.53.0.2")
|
||||||
]
|
]
|
||||||
|
|
||||||
# Should also generate a log entry into rpz_passthru.txt
|
|
||||||
msg_allowed_any = dns.message.make_query("allowed.", "ANY")
|
|
||||||
res_allowed_any = isctest.query.udp(
|
|
||||||
msg_allowed_any,
|
|
||||||
resolver_ip,
|
|
||||||
source="10.53.0.1",
|
|
||||||
expected_rcode=dns.rcode.NOERROR,
|
|
||||||
)
|
|
||||||
assert res_allowed_any.answer == [
|
|
||||||
dns.rrset.from_text("allowed.", 300, "IN", "A", "10.53.0.2"),
|
|
||||||
dns.rrset.from_text("allowed.", 300, "IN", "NS", "ns1.allowed."),
|
|
||||||
]
|
|
||||||
# The comparison above doesn't compare the TTL values, and we want to
|
|
||||||
# make sure that the "passthru" rpz doesn't cap the TTL with max-policy-ttl.
|
|
||||||
assert res_allowed_any.answer[0].ttl > 200
|
|
||||||
assert res_allowed_any.answer[1].ttl > 200
|
|
||||||
|
|
||||||
# baddomain.com isn't allowed (CNAME .), should return NXDOMAIN
|
# baddomain.com isn't allowed (CNAME .), should return NXDOMAIN
|
||||||
# Should generate a log entry into rpz.txt
|
# Should generate a log entry into rpz.txt
|
||||||
msg_not_allowed = dns.message.make_query("baddomain.", "A")
|
msg_not_allowed = dns.message.make_query("baddomain.", "A")
|
||||||
|
|||||||
@@ -140,7 +140,7 @@ main(int argc, char **argv) {
|
|||||||
printf("%s\n", filename);
|
printf("%s\n", filename);
|
||||||
dst_key_free(&key);
|
dst_key_free(&key);
|
||||||
|
|
||||||
isc_mem_detach(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -115,12 +115,10 @@ sleep 2
|
|||||||
# stale for somewhere between 3500-3599 seconds.
|
# stale for somewhere between 3500-3599 seconds.
|
||||||
echo_i "check rndc dump stale data.example ($n)"
|
echo_i "check rndc dump stale data.example ($n)"
|
||||||
rndc_dumpdb ns1 || ret=1
|
rndc_dumpdb ns1 || ret=1
|
||||||
# add in inherited owner names
|
awk '/; stale since [0-9]*/ { x=$0; getline; print x, $0}' ns1/named_dump.db.test$n \
|
||||||
awk '$1 ~ /^[0-9][0-9]*$/ { $0 = last " " $0 } $1 != ";" { last = $1 } { print }' ns1/named_dump.db.test$n >named_dump.db.test$n
|
|
||||||
awk '/; stale since [0-9]*/ { x=$0; getline; print x, $0}' named_dump.db.test$n \
|
|
||||||
| grep "; stale since [0-9]* data\.example.*3[56]...*TXT.*A text record with a 2 second ttl" >/dev/null 2>&1 || ret=1
|
| grep "; stale since [0-9]* data\.example.*3[56]...*TXT.*A text record with a 2 second ttl" >/dev/null 2>&1 || ret=1
|
||||||
# Also make sure the not expired data does not have a stale comment.
|
# Also make sure the not expired data does not have a stale comment.
|
||||||
awk '/; authanswer/ { x=$0; getline; print x, $0}' named_dump.db.test$n \
|
awk '/; authanswer/ { x=$0; getline; print x, $0}' ns1/named_dump.db.test$n \
|
||||||
| grep "; authanswer longttl\.example.*[56]...*TXT.*A text record with a 600 second ttl" >/dev/null 2>&1 || ret=1
|
| grep "; authanswer longttl\.example.*[56]...*TXT.*A text record with a 600 second ttl" >/dev/null 2>&1 || ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
@@ -1666,15 +1664,16 @@ status=$((status + ret))
|
|||||||
# Check that expired records are dumped.
|
# Check that expired records are dumped.
|
||||||
echo_i "check rndc dump expired data.example ($n)"
|
echo_i "check rndc dump expired data.example ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
# add in inherited owner names
|
awk '/; expired/ { x=$0; getline; print x, $0}' ns5/named_dump.db.test$n \
|
||||||
awk '$1 ~ /^[0-9][0-9]*$/ { $0 = last " " $0 } $1 != ";" { last = $1 } { print }' ns5/named_dump.db.test$n >named_dump.db.test$n
|
| grep "; expired (awaiting cleanup) data\.example\..*A text record with a 2 second ttl" >/dev/null 2>&1 || ret=1
|
||||||
# extract expired records
|
awk '/; expired/ { x=$0; getline; print x, $0}' ns5/named_dump.db.test$n \
|
||||||
awk '/; expired/ { x=$0; getline; print x, $0}' named_dump.db.test$n >expired.test$n
|
| grep "; expired (awaiting cleanup) nodata\.example\." >/dev/null 2>&1 || ret=1
|
||||||
grep "; expired (awaiting cleanup) data\.example\..*A text record with a 2 second ttl" expired.test$n >/dev/null 2>&1 || ret=1
|
awk '/; expired/ { x=$0; getline; print x, $0}' ns5/named_dump.db.test$n \
|
||||||
grep "; expired (awaiting cleanup) nodata\.example\." expired.test$n >/dev/null 2>&1 || ret=1
|
| grep "; expired (awaiting cleanup) nxdomain\.example\." >/dev/null 2>&1 || ret=1
|
||||||
grep "; expired (awaiting cleanup) nxdomain\.example\." expired.test$n >/dev/null 2>&1 || ret=1
|
awk '/; expired/ { x=$0; getline; print x, $0}' ns5/named_dump.db.test$n \
|
||||||
|
| grep "; expired (awaiting cleanup) othertype\.example\." >/dev/null 2>&1 || ret=1
|
||||||
# Also make sure the not expired data does not have an expired comment.
|
# Also make sure the not expired data does not have an expired comment.
|
||||||
awk '/; authanswer/ { x=$0; getline; print x, $0}' named_dump.db.test$n \
|
awk '/; authanswer/ { x=$0; getline; print x, $0}' ns5/named_dump.db.test$n \
|
||||||
| grep "; authanswer longttl\.example.*A text record with a 600 second ttl" >/dev/null 2>&1 || ret=1
|
| grep "; authanswer longttl\.example.*A text record with a 600 second ttl" >/dev/null 2>&1 || ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|||||||
@@ -14,8 +14,6 @@ import pytest
|
|||||||
pytestmark = pytest.mark.extra_artifacts(
|
pytestmark = pytest.mark.extra_artifacts(
|
||||||
[
|
[
|
||||||
"dig.out.*",
|
"dig.out.*",
|
||||||
"expired.test*",
|
|
||||||
"named_dump.db.test*",
|
|
||||||
"rndc.out.*",
|
"rndc.out.*",
|
||||||
"ans*/ans.run",
|
"ans*/ans.run",
|
||||||
"ns*/named.stats*",
|
"ns*/named.stats*",
|
||||||
|
|||||||
@@ -234,7 +234,7 @@ sub construct_ns_command {
|
|||||||
$command = "taskset $taskset $NAMED ";
|
$command = "taskset $taskset $NAMED ";
|
||||||
} elsif ($ENV{'USE_RR'}) {
|
} elsif ($ENV{'USE_RR'}) {
|
||||||
$ENV{'_RR_TRACE_DIR'} = ".";
|
$ENV{'_RR_TRACE_DIR'} = ".";
|
||||||
$command = "$ENV{'TOP_BUILDDIR'}/libtool --mode=execute rr record --chaos $NAMED ";
|
$command = "rr record --chaos $NAMED ";
|
||||||
} else {
|
} else {
|
||||||
$command = "$NAMED ";
|
$command = "$NAMED ";
|
||||||
}
|
}
|
||||||
@@ -264,8 +264,7 @@ sub construct_ns_command {
|
|||||||
|
|
||||||
foreach my $t_option(
|
foreach my $t_option(
|
||||||
"dropedns", "ednsformerr", "ednsnotimp", "ednsrefused",
|
"dropedns", "ednsformerr", "ednsnotimp", "ednsrefused",
|
||||||
"cookiealwaysvalid", "noaa", "noedns", "nosoa",
|
"noaa", "noedns", "nosoa", "maxudp512", "maxudp1460",
|
||||||
"maxudp512", "maxudp1460",
|
|
||||||
) {
|
) {
|
||||||
if (-e "$testdir/$server/named.$t_option") {
|
if (-e "$testdir/$server/named.$t_option") {
|
||||||
$command .= "-T $t_option "
|
$command .= "-T $t_option "
|
||||||
@@ -324,7 +323,7 @@ sub construct_ans_command {
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (-e "$testdir/$server/ans.py") {
|
if (-e "$testdir/$server/ans.py") {
|
||||||
$ENV{'PYTHONPATH'} = $testdir . ":" . $builddir;
|
$ENV{'PYTHONPATH'} = $testdir . ":" . $ENV{'srcdir'};
|
||||||
$command = "$PYTHON -u ans.py 10.53.0.$n $queryport";
|
$command = "$PYTHON -u ans.py 10.53.0.$n $queryport";
|
||||||
} elsif (-e "$testdir/$server/ans.pl") {
|
} elsif (-e "$testdir/$server/ans.pl") {
|
||||||
$command = "$PERL ans.pl";
|
$command = "$PERL ans.pl";
|
||||||
|
|||||||
@@ -414,10 +414,10 @@ for ns in 2 4 5 6; do
|
|||||||
check_status NOERROR dig.out.ns${ns}.test$n || ret=1
|
check_status NOERROR dig.out.ns${ns}.test$n || ret=1
|
||||||
if [ ${synth} = yes ]; then
|
if [ ${synth} = yes ]; then
|
||||||
check_synth_cname b.wild-cname.example. dig.out.ns${ns}.test$n || ret=1
|
check_synth_cname b.wild-cname.example. dig.out.ns${ns}.test$n || ret=1
|
||||||
nextpart ns1/named.run | grep b.wild-cname.example/NS >/dev/null && ret=1
|
nextpart ns1/named.run | grep b.wild-cname.example/A >/dev/null && ret=1
|
||||||
else
|
else
|
||||||
check_nosynth_cname b.wild-cname.example. dig.out.ns${ns}.test$n || ret=1
|
check_nosynth_cname b.wild-cname.example. dig.out.ns${ns}.test$n || ret=1
|
||||||
nextpart ns1/named.run | grep b.wild-cname.example/NS >/dev/null || ret=1
|
nextpart ns1/named.run | grep b.wild-cname.example/A >/dev/null || ret=1
|
||||||
fi
|
fi
|
||||||
grep "ns1.example.*.IN.A" dig.out.ns${ns}.test$n >/dev/null || ret=1
|
grep "ns1.example.*.IN.A" dig.out.ns${ns}.test$n >/dev/null || ret=1
|
||||||
digcomp wildcname.out dig.out.ns${ns}.test$n || ret=1
|
digcomp wildcname.out dig.out.ns${ns}.test$n || ret=1
|
||||||
@@ -470,7 +470,6 @@ for ns in 2 4 5 6; do
|
|||||||
check_nosynth_aaaa b.wild-2-nsec-afterdata.example. dig.out.a.ns${ns}.test$n || ret=1
|
check_nosynth_aaaa b.wild-2-nsec-afterdata.example. dig.out.a.ns${ns}.test$n || ret=1
|
||||||
#
|
#
|
||||||
nextpart ns1/named.run >/dev/null
|
nextpart ns1/named.run >/dev/null
|
||||||
sleep 1
|
|
||||||
dig_with_opts b.wild-2-nsec-afterdata.example. @10.53.0.${ns} TLSA >dig.out.ns${ns}.test$n || ret=1
|
dig_with_opts b.wild-2-nsec-afterdata.example. @10.53.0.${ns} TLSA >dig.out.ns${ns}.test$n || ret=1
|
||||||
check_ad_flag $ad dig.out.ns${ns}.test$n || ret=1
|
check_ad_flag $ad dig.out.ns${ns}.test$n || ret=1
|
||||||
check_status NOERROR dig.out.ns${ns}.test$n || ret=1
|
check_status NOERROR dig.out.ns${ns}.test$n || ret=1
|
||||||
@@ -532,7 +531,7 @@ for ns in 2 4 5 6; do
|
|||||||
check_ad_flag no dig.out.ns${ns}.test$n || ret=1
|
check_ad_flag no dig.out.ns${ns}.test$n || ret=1
|
||||||
check_status NOERROR dig.out.ns${ns}.test$n || ret=1
|
check_status NOERROR dig.out.ns${ns}.test$n || ret=1
|
||||||
check_nosynth_cname b.wild-cname.insecure.example dig.out.ns${ns}.test$n || ret=1
|
check_nosynth_cname b.wild-cname.insecure.example dig.out.ns${ns}.test$n || ret=1
|
||||||
nextpart ns1/named.run | grep b.wild-cname.insecure.example/NS >/dev/null || ret=1
|
nextpart ns1/named.run | grep b.wild-cname.insecure.example/A >/dev/null || ret=1
|
||||||
grep "ns1.insecure.example.*.IN.A" dig.out.ns${ns}.test$n >/dev/null || ret=1
|
grep "ns1.insecure.example.*.IN.A" dig.out.ns${ns}.test$n >/dev/null || ret=1
|
||||||
digcomp insecure.wildcname.out dig.out.ns${ns}.test$n || ret=1
|
digcomp insecure.wildcname.out dig.out.ns${ns}.test$n || ret=1
|
||||||
n=$((n + 1))
|
n=$((n + 1))
|
||||||
|
|||||||
@@ -260,7 +260,7 @@ main(int argc, char *argv[]) {
|
|||||||
if (printmemstats) {
|
if (printmemstats) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
isc_mem_detach(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -425,7 +425,7 @@ cleanup:
|
|||||||
if (message != NULL) {
|
if (message != NULL) {
|
||||||
dns_message_detach(&message);
|
dns_message_detach(&message);
|
||||||
}
|
}
|
||||||
isc_mem_detach(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|
||||||
exit(rv);
|
exit(rv);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -61,7 +61,7 @@ cleanup(void) {
|
|||||||
isc_lex_destroy(&lex);
|
isc_lex_destroy(&lex);
|
||||||
}
|
}
|
||||||
if (mctx != NULL) {
|
if (mctx != NULL) {
|
||||||
isc_mem_detach(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+26
-1
@@ -16,7 +16,7 @@
|
|||||||
#
|
#
|
||||||
m4_define([bind_VERSION_MAJOR], 9)dnl
|
m4_define([bind_VERSION_MAJOR], 9)dnl
|
||||||
m4_define([bind_VERSION_MINOR], 21)dnl
|
m4_define([bind_VERSION_MINOR], 21)dnl
|
||||||
m4_define([bind_VERSION_PATCH], 7)dnl
|
m4_define([bind_VERSION_PATCH], 6)dnl
|
||||||
m4_define([bind_VERSION_EXTRA], -dev)dnl
|
m4_define([bind_VERSION_EXTRA], -dev)dnl
|
||||||
m4_define([bind_DESCRIPTION], [(Development Release)])dnl
|
m4_define([bind_DESCRIPTION], [(Development Release)])dnl
|
||||||
m4_define([bind_SRCID], [m4_esyscmd_s([git rev-parse --short HEAD | cut -b1-7])])dnl
|
m4_define([bind_SRCID], [m4_esyscmd_s([git rev-parse --short HEAD | cut -b1-7])])dnl
|
||||||
@@ -886,6 +886,31 @@ AC_CHECK_HEADERS([execinfo.h],
|
|||||||
[AC_SEARCH_LIBS([backtrace_symbols], [execinfo],
|
[AC_SEARCH_LIBS([backtrace_symbols], [execinfo],
|
||||||
[AC_CHECK_FUNCS([backtrace_symbols])])])
|
[AC_CHECK_FUNCS([backtrace_symbols])])])
|
||||||
|
|
||||||
|
#
|
||||||
|
# We do the IPv6 compilation checking after libtool so that we can put
|
||||||
|
# the right suffix on the files.
|
||||||
|
#
|
||||||
|
AC_MSG_CHECKING([for IPv6 structures])
|
||||||
|
AC_COMPILE_IFELSE(
|
||||||
|
[AC_LANG_PROGRAM(
|
||||||
|
[[
|
||||||
|
#include <sys/types.h>
|
||||||
|
#include <sys/socket.h>
|
||||||
|
#include <netinet/in.h>
|
||||||
|
]],
|
||||||
|
[[
|
||||||
|
struct sockaddr_in6 sin6;
|
||||||
|
struct in6_addr in6;
|
||||||
|
struct in6_pktinfo in6_pi;
|
||||||
|
struct sockaddr_storage storage;
|
||||||
|
in6 = in6addr_any;
|
||||||
|
in6 = in6addr_loopback;
|
||||||
|
sin6.sin6_scope_id = 0;
|
||||||
|
return (0);
|
||||||
|
]])],
|
||||||
|
[AC_MSG_RESULT([yes])],
|
||||||
|
[AC_MSG_FAILURE([IPv6 support is mandatory])])
|
||||||
|
|
||||||
#
|
#
|
||||||
# Allow forcibly disabling TCP Fast Open support as autodetection might yield
|
# Allow forcibly disabling TCP Fast Open support as autodetection might yield
|
||||||
# confusing results on some systems (e.g. FreeBSD; see set_tcp_fastopen()
|
# confusing results on some systems (e.g. FreeBSD; see set_tcp_fastopen()
|
||||||
|
|||||||
@@ -18,7 +18,6 @@ Changelog
|
|||||||
development. Regular users should refer to :ref:`Release Notes <relnotes>`
|
development. Regular users should refer to :ref:`Release Notes <relnotes>`
|
||||||
for changes relevant to them.
|
for changes relevant to them.
|
||||||
|
|
||||||
.. include:: ../changelog/changelog-9.21.6.rst
|
|
||||||
.. include:: ../changelog/changelog-9.21.5.rst
|
.. include:: ../changelog/changelog-9.21.5.rst
|
||||||
.. include:: ../changelog/changelog-9.21.4.rst
|
.. include:: ../changelog/changelog-9.21.4.rst
|
||||||
.. include:: ../changelog/changelog-9.21.3.rst
|
.. include:: ../changelog/changelog-9.21.3.rst
|
||||||
|
|||||||
@@ -218,7 +218,6 @@ latex_logo = "isc-logo.pdf"
|
|||||||
linkcheck_timeout = 10
|
linkcheck_timeout = 10
|
||||||
linkcheck_ignore = [
|
linkcheck_ignore = [
|
||||||
"http://127.0.0.1",
|
"http://127.0.0.1",
|
||||||
"https://dl.acm.org",
|
|
||||||
"https://gitlab.isc.org",
|
"https://gitlab.isc.org",
|
||||||
"https://kb.isc.org",
|
"https://kb.isc.org",
|
||||||
"https://simpleicon.com/",
|
"https://simpleicon.com/",
|
||||||
|
|||||||
@@ -47,7 +47,6 @@ The list of known issues affecting the latest version in the 9.21 branch can be
|
|||||||
found at
|
found at
|
||||||
https://gitlab.isc.org/isc-projects/bind9/-/wikis/Known-Issues-in-BIND-9.21
|
https://gitlab.isc.org/isc-projects/bind9/-/wikis/Known-Issues-in-BIND-9.21
|
||||||
|
|
||||||
.. include:: ../notes/notes-9.21.6.rst
|
|
||||||
.. include:: ../notes/notes-9.21.5.rst
|
.. include:: ../notes/notes-9.21.5.rst
|
||||||
.. include:: ../notes/notes-9.21.4.rst
|
.. include:: ../notes/notes-9.21.4.rst
|
||||||
.. include:: ../notes/notes-9.21.3.rst
|
.. include:: ../notes/notes-9.21.3.rst
|
||||||
|
|||||||
@@ -3660,13 +3660,9 @@ system.
|
|||||||
after 20 minutes if it has remained unchanged.
|
after 20 minutes if it has remained unchanged.
|
||||||
|
|
||||||
If :any:`max-clients-per-query` is set to zero, there is no upper bound, other
|
If :any:`max-clients-per-query` is set to zero, there is no upper bound, other
|
||||||
than that imposed by :any:`recursive-clients`. If the option is set to a
|
than that imposed by :any:`recursive-clients`. If :any:`clients-per-query` is
|
||||||
lower value than :any:`clients-per-query`, the value is adjusted to
|
set to zero, :any:`max-clients-per-query` no longer applies and there is no
|
||||||
:any:`clients-per-query`.
|
upper bound, other than that imposed by :any:`recursive-clients`.
|
||||||
|
|
||||||
If :any:`clients-per-query` is set to zero, :any:`max-clients-per-query` no
|
|
||||||
longer applies and there is no upper bound, other than that imposed by
|
|
||||||
:any:`recursive-clients`.
|
|
||||||
|
|
||||||
.. namedconf:statement:: max-validations-per-fetch
|
.. namedconf:statement:: max-validations-per-fetch
|
||||||
:tags: server
|
:tags: server
|
||||||
|
|||||||
@@ -1,478 +0,0 @@
|
|||||||
.. Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
..
|
|
||||||
.. SPDX-License-Identifier: MPL-2.0
|
|
||||||
..
|
|
||||||
.. This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
.. License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
.. file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
..
|
|
||||||
.. See the COPYRIGHT file distributed with this work for additional
|
|
||||||
.. information regarding copyright ownership.
|
|
||||||
|
|
||||||
BIND 9.21.6
|
|
||||||
-----------
|
|
||||||
|
|
||||||
New Features
|
|
||||||
~~~~~~~~~~~~
|
|
||||||
|
|
||||||
- Implement the min-transfer-rate-in configuration option.
|
|
||||||
``a282f1ba3f``
|
|
||||||
|
|
||||||
A new option 'min-transfer-rate-in <bytes> <minutes>' has been added
|
|
||||||
to the view and zone configurations. It can abort incoming zone
|
|
||||||
transfers which run very slowly due to network related issues, for
|
|
||||||
example. The default value is set to 10240 bytes in 5 minutes.
|
|
||||||
:gl:`#3914` :gl:`!9098`
|
|
||||||
|
|
||||||
- Add digest methods for SIG and RRSIG. ``fd48df20f3``
|
|
||||||
|
|
||||||
ZONEMD digests RRSIG records and potentially digests SIG record. Add
|
|
||||||
digests methods for both record types. :gl:`#5219` :gl:`!10217`
|
|
||||||
|
|
||||||
- Add HTTPS record query to host command line tool. ``d34414c47b``
|
|
||||||
|
|
||||||
The host command was extended to also query for the HTTPS RR type by
|
|
||||||
default. :gl:`!8642`
|
|
||||||
|
|
||||||
Removed Features
|
|
||||||
~~~~~~~~~~~~~~~~
|
|
||||||
|
|
||||||
- Clean up unnecessary code in qpcache. ``74c9ff384e``
|
|
||||||
|
|
||||||
Removed some code from the cache database implementation that was left
|
|
||||||
over from before it and the zone database implementation were
|
|
||||||
separated. :gl:`!9991`
|
|
||||||
|
|
||||||
- Cleanup isc/util.h header and friends. ``239712df16``
|
|
||||||
|
|
||||||
Cleanup short list macros from <isc/util.h>, remove two unused
|
|
||||||
headers, move locking macros to respective headers and use only the
|
|
||||||
C11 static assertion. :gl:`!10196`
|
|
||||||
|
|
||||||
- Remove check for the mandatory IPv6 support. ``daa9c17905``
|
|
||||||
|
|
||||||
IPv6 Advanced Socket API (:rfc:`3542`) is a hard requirement, remove
|
|
||||||
the autoconf check to speed up the ./configure run a little bit.
|
|
||||||
:gl:`!10201`
|
|
||||||
|
|
||||||
- Remove log initialization checks from named. ``1b3e7f52ec``
|
|
||||||
|
|
||||||
Logging initialization check is now redundant as there is a default
|
|
||||||
global log context created during libisc's constructor.
|
|
||||||
|
|
||||||
`isc_log` calls can safely be made at any time outside libisc's
|
|
||||||
constructor. :gl:`!10186`
|
|
||||||
|
|
||||||
Feature Changes
|
|
||||||
~~~~~~~~~~~~~~~
|
|
||||||
|
|
||||||
- Refactor and simplify isc_symtab. ``5559539eb0``
|
|
||||||
|
|
||||||
This commit does several changes to isc_symtab:
|
|
||||||
|
|
||||||
1. Rewrite the isc_symtab to internally use isc_hashmap instead of
|
|
||||||
hand-stiched hashtable.
|
|
||||||
|
|
||||||
2. Create a new isc_symtab_define_and_return() api, which returns
|
|
||||||
the already defined symvalue on ISC_R_EXISTS; this allows users of
|
|
||||||
the API to skip the isc_symtab_lookup()+isc_symtab_define() calls
|
|
||||||
and directly call isc_symtab_define_and_return().
|
|
||||||
|
|
||||||
3. Merge isccc_symtab into isc_symtab - the only missing function
|
|
||||||
was isccc_symtab_foreach() that was merged into isc_symtab API.
|
|
||||||
|
|
||||||
4. Add full set of unit tests for the isc_symtab API. :gl:`#5103`
|
|
||||||
:gl:`!9921`
|
|
||||||
|
|
||||||
- Drop malformed notify messages early instead of decompressing them.
|
|
||||||
``7fce7707db``
|
|
||||||
|
|
||||||
The DNS header shows if a message has multiple questions or invalid
|
|
||||||
NOTIFY sections. We can drop these messages early, right after parsing
|
|
||||||
the question. This matches RFC 9619 for multi-question messages and
|
|
||||||
Unbound's handling of NOTIFY. We still parse the question to include
|
|
||||||
it in our FORMERR response.
|
|
||||||
|
|
||||||
Add drop_msg_early() function to check for these conditions: -
|
|
||||||
Messages with more than one question, as required by RFC 9619 - NOTIFY
|
|
||||||
query messages containing answer sections (like Unbound) - NOTIFY
|
|
||||||
messages containing authority sections (like Unbound) :gl:`#5158`,
|
|
||||||
#3656 :gl:`!10056`
|
|
||||||
|
|
||||||
- Cleanup parts of the isc_mem API. ``4ba1ccfa2e``
|
|
||||||
|
|
||||||
This MR changes custom attach/detach implementation with refcount
|
|
||||||
macros, replaces isc_mem_destroy() with isc_mem_detach(), and does
|
|
||||||
various small cleanups. :gl:`!9456`
|
|
||||||
|
|
||||||
- Move the library initialization and shutdown to executables.
|
|
||||||
``6e0c1f151c``
|
|
||||||
|
|
||||||
Instead of relying on unreliable order of execution of the library
|
|
||||||
constructors and destructors, move them to individual binaries. The
|
|
||||||
advantage is that the execution time and order will remain constant
|
|
||||||
and will not depend on the dynamic load dependency solver.
|
|
||||||
:gl:`!10069`
|
|
||||||
|
|
||||||
- Reduce memory used to store DNS names. ``24db1b1a8a``
|
|
||||||
|
|
||||||
The memory used to internally store the DNS names has been reduced.
|
|
||||||
:gl:`!10140`
|
|
||||||
|
|
||||||
- Unify fips handling to isc_crypto and make the toggle one way.
|
|
||||||
``3de629d6b7``
|
|
||||||
|
|
||||||
Since algorithm fetching is handled purely in libisc, FIPS mode
|
|
||||||
toggling can be purely done in within the library instead of provider
|
|
||||||
fetching in the binary for OpenSSL >=3.0.
|
|
||||||
|
|
||||||
Disabling FIPS mode isn't a realistic requirement and isn't done
|
|
||||||
anywhere in the codebase. Make the FIPS mode toggle enable-only to
|
|
||||||
reflect the situation. :gl:`!9920`
|
|
||||||
|
|
||||||
Bug Fixes
|
|
||||||
~~~~~~~~~
|
|
||||||
|
|
||||||
- Prevent a reference leak when using plugins. ``5604d3a44e``
|
|
||||||
|
|
||||||
The `NS_QUERY_DONE_BEGIN` and `NS_QUERY_DONE_SEND` plugin hooks could
|
|
||||||
cause a reference leak if they returned `NS_HOOK_RETURN` without
|
|
||||||
cleaning up the query context properly. :gl:`#2094` :gl:`!9971`
|
|
||||||
|
|
||||||
- Fix isc_quota bug. ``742d379d88``
|
|
||||||
|
|
||||||
Running jobs which were entered into the isc_quota queue is the
|
|
||||||
responsibility of the isc_quota_release() function, which, when
|
|
||||||
releasing a previously acquired quota, checks whether the queue is
|
|
||||||
empty, and if it's not, it runs a job from the queue without touching
|
|
||||||
the 'quota->used' counter. This mechanism is susceptible to a possible
|
|
||||||
hangup of a newly queued job in case when between the time a decision
|
|
||||||
has been made to queue it (because used >= max) and the time it was
|
|
||||||
actually queued, the last quota was released. Since there is no more
|
|
||||||
quotas to be released (unless arriving in the future), the newly
|
|
||||||
entered job will be stuck in the queue.
|
|
||||||
|
|
||||||
Fix the issue by adding checks in both isc_quota_release() and
|
|
||||||
isc_quota_acquire_cb() to make sure that the described hangup does not
|
|
||||||
happen. Also see code comments. :gl:`#4965` :gl:`!10082`
|
|
||||||
|
|
||||||
- Fix dual-stack-servers configuration option. ``6af708f3b0``
|
|
||||||
|
|
||||||
The dual-stack-servers configuration option was not working as
|
|
||||||
expected; the specified servers were not being used when they should
|
|
||||||
have been, leading to resolution failures. This has been fixed.
|
|
||||||
:gl:`#5019` :gl:`!9708`
|
|
||||||
|
|
||||||
- Implement sig0key-checks-limit and sig0message-checks-limit.
|
|
||||||
``d78ebff861``
|
|
||||||
|
|
||||||
Previously a hard-coded limitation of maximum two key or message
|
|
||||||
verification checks were introduced when checking the message's SIG(0)
|
|
||||||
signature. It was done in order to protect against possible DoS
|
|
||||||
attacks. The logic behind choosing the number 2 was that more than a
|
|
||||||
single key should only be required during key rotations, and in that
|
|
||||||
case two keys are enough. But later it became apparent that there are
|
|
||||||
other use cases too where even more keys are required, see issue
|
|
||||||
number #5050 in GitLab.
|
|
||||||
|
|
||||||
This change introduces two new configuration options for the views,
|
|
||||||
`sig0key-checks-limit` and `sig0message-checks-limit`, which define
|
|
||||||
how many keys are allowed to be checked to find a matching key, and
|
|
||||||
how many message verifications are allowed to take place once a
|
|
||||||
matching key has been found. The latter protects against expensive
|
|
||||||
cryptographic operations when there are keys with colliding tags and
|
|
||||||
algorithm numbers, with default being 2, and the former protects
|
|
||||||
against a bit less expensive key parsing operations and defaults to
|
|
||||||
16. :gl:`#5050` :gl:`!9967`
|
|
||||||
|
|
||||||
- Fix the data race causing a permanent active client increase.
|
|
||||||
``479c366c2b``
|
|
||||||
|
|
||||||
Previously, a data race could cause a newly created fetch context for
|
|
||||||
a new client to be used before it had been fully initialized, which
|
|
||||||
would cause the query to become stuck; queries for the same data would
|
|
||||||
be either paused indefinitely or dropped because of the
|
|
||||||
`clients-per-query` limit. This has been fixed. :gl:`#5053`
|
|
||||||
:gl:`!10146`
|
|
||||||
|
|
||||||
- Fix deferred validation of unsigned DS and DNSKEY records.
|
|
||||||
``ebf1606f38``
|
|
||||||
|
|
||||||
When processing a query with the "checking disabled" bit set (CD=1),
|
|
||||||
`named` stores the unvalidated result in the cache, marked "pending".
|
|
||||||
When the same query is sent with CD=0, the cached data is validated,
|
|
||||||
and either accepted as an answer, or ejected from the cache as
|
|
||||||
invalid. This deferred validation was not attempted for DS and DNSKEY
|
|
||||||
records if they had no cached signatures, causing spurious validation
|
|
||||||
failures. We now complete the deferred validation in this scenario.
|
|
||||||
|
|
||||||
Also, if deferred validation fails, we now re-query the data to find
|
|
||||||
out whether the zone has been corrected since the invalid data was
|
|
||||||
cached. :gl:`#5066` :gl:`!10104`
|
|
||||||
|
|
||||||
- When recording an rr trace, use libtool. ``6320586df0``
|
|
||||||
|
|
||||||
When a system test is run with the `USE_RR` environment variable set
|
|
||||||
to 1, an `rr` trace is now correctly generated for each instance of
|
|
||||||
`named`. :gl:`#5079` :gl:`!10197`
|
|
||||||
|
|
||||||
- Do not cache signatures for rejected data. ``fc3a4d6f89``
|
|
||||||
|
|
||||||
The cache has been updated so that if new data is rejected - for
|
|
||||||
example, because there was already existing data at a higher trust
|
|
||||||
level - then its covering RRSIG will also be rejected. :gl:`#5132`
|
|
||||||
:gl:`!9999`
|
|
||||||
|
|
||||||
- Fix wrong logging severity in do_nsfetch() ``1f6a16e6d0``
|
|
||||||
|
|
||||||
ISC_LOG_WARNING was used while ISC_LOG_DEBUG(3) was implied.
|
|
||||||
:gl:`#5145` :gl:`!10017`
|
|
||||||
|
|
||||||
- Fix RPZ race condition during a reconfiguration. ``5ba811bea2``
|
|
||||||
|
|
||||||
With RPZ in use, `named` could terminate unexpectedly because of a
|
|
||||||
race condition when a reconfiguration command was received using
|
|
||||||
`rndc`. This has been fixed. :gl:`#5146` :gl:`!10079`
|
|
||||||
|
|
||||||
- "CNAME and other data check" not applied to all types. ``b694acbe45``
|
|
||||||
|
|
||||||
An incorrect optimization caused "CNAME and other data" errors not to
|
|
||||||
be detected if certain types were at the same node as a CNAME. This
|
|
||||||
has been fixed. :gl:`#5150` :gl:`!10033`
|
|
||||||
|
|
||||||
- Use named Service Parameter Keys (SvcParamKeys) by default.
|
|
||||||
``3f61a87be3``
|
|
||||||
|
|
||||||
When converting SVCB records to text representation `named` now uses
|
|
||||||
named `SvcParamKeys` values unless backward-compatible mode is
|
|
||||||
activated, in which case the values which were not defined initially
|
|
||||||
in RFC9460 and were added later (see [1]) are converted to opaque
|
|
||||||
"keyNNNN" syntax, like, for example, "key7" instead of "dohpath".
|
|
||||||
|
|
||||||
Also a new `+[no]svcparamkeycompat` option is implemented for `dig`,
|
|
||||||
which enables the backward-compatible mode and uses the opaque syntax,
|
|
||||||
if required for interoperability with other software or scripts. By
|
|
||||||
default, the compatibility mode is disabled.
|
|
||||||
|
|
||||||
[1] https://www.iana.org/assignments/dns-svcb/dns-svcb.xhtml
|
|
||||||
:gl:`#5156` :gl:`!10085`
|
|
||||||
|
|
||||||
- Relax private DNSKEY and RRSIG constraints. ``1bc7016d7a``
|
|
||||||
|
|
||||||
DNSKEY, KEY, RRSIG and SIG constraints have been relaxed to allow
|
|
||||||
empty key and signature material after the algorithm identifier for
|
|
||||||
PRIVATEOID and PRIVATEDNS. It is arguable whether this falls within
|
|
||||||
the expected use of these types as no key material is shared and the
|
|
||||||
signatures are ineffective but these are private algorithms and they
|
|
||||||
can be totally insecure. :gl:`#5167` :gl:`!10083`
|
|
||||||
|
|
||||||
- Delete dead nodes when committing a new version. ``67255da4b3``
|
|
||||||
|
|
||||||
In the qpzone implementation of `dns_db_closeversion()`, if there are
|
|
||||||
changed nodes that have no remaining data, delete them. :gl:`#5169`
|
|
||||||
:gl:`!10089`
|
|
||||||
|
|
||||||
- Revert "Delete dead nodes when committing a new version"
|
|
||||||
``b652d5327c``
|
|
||||||
|
|
||||||
This reverts commit 67255da4b376f65138b299dcd5eb6a3b7f9735a9,
|
|
||||||
reversing changes made to 74c9ff384e695d1b27fa365d1fee84576f869d4c.
|
|
||||||
:gl:`#5169` :gl:`!10224`
|
|
||||||
|
|
||||||
- Fix dns_qp_insert() checks in qpzone. ``d6b63210a8``
|
|
||||||
|
|
||||||
Remove code in the QP zone database to handle failures of
|
|
||||||
`dns_qp_insert()` which can't actually happen. :gl:`#5171`
|
|
||||||
:gl:`!10088`
|
|
||||||
|
|
||||||
- Remove NSEC/DS/NSEC3 RRSIG check from dns_message_parse.
|
|
||||||
``f0785fedf1``
|
|
||||||
|
|
||||||
Previously, when parsing responses, named incorrectly rejected
|
|
||||||
responses without matching RRSIG records for NSEC/DS/NSEC3 records in
|
|
||||||
the authority section. This rejection, if appropriate, should have
|
|
||||||
been left for the validator to determine and has been fixed.
|
|
||||||
:gl:`#5185` :gl:`!10125`
|
|
||||||
|
|
||||||
- Fix TTL issue with ANY queries processed through RPZ "passthru"
|
|
||||||
``23c1fbc609``
|
|
||||||
|
|
||||||
Answers to an "ANY" query which were processed by the RPZ "passthru"
|
|
||||||
policy had the response-policy's `max-policy-ttl` value unexpectedly
|
|
||||||
applied. This has been fixed. :gl:`#5187` :gl:`!10176`
|
|
||||||
|
|
||||||
- Save time when creating a slab from another slab. ``cf981ab13b``
|
|
||||||
|
|
||||||
The `dns_rdataslab_fromrdataset()` function creates a slab from an
|
|
||||||
rdataset. If the source rdataset already uses a slab, then no
|
|
||||||
processing is necessary; we can just copy the existing slab to a new
|
|
||||||
location. :gl:`#5188` :gl:`!10162`
|
|
||||||
|
|
||||||
- Dnssec-signzone needs to check for a NULL key when setting offline.
|
|
||||||
``26f8ee7229``
|
|
||||||
|
|
||||||
dnssec-signzone could dereference a NULL key pointer when resigning a
|
|
||||||
zone. This has been fixed. :gl:`#5192` :gl:`!10161`
|
|
||||||
|
|
||||||
- Acquire the database reference before possibly last node release.
|
|
||||||
``c4868b5bd9``
|
|
||||||
|
|
||||||
Acquire the database reference in the detachnode() to prevent the last
|
|
||||||
reference to be release while the NODE_LOCK being locked. The
|
|
||||||
NODE_LOCK is locked/unlocked inside the RCU critical section, thus it
|
|
||||||
is most probably this should not pose a problem as the database uses
|
|
||||||
call_rcu memory reclamation, but this it is still safer to acquire the
|
|
||||||
reference before releasing the node. :gl:`#5194` :gl:`!10155`
|
|
||||||
|
|
||||||
- Fix a logic error in cache_name() ``02ef8ff01c``
|
|
||||||
|
|
||||||
A change in 6aba56ae8 (checking whether a rejected RRset was identical
|
|
||||||
to the data it would have replaced, so that we could still cache a
|
|
||||||
signature) inadvertently introduced cases where processing of a
|
|
||||||
response would continue when previously it would have been skipped.
|
|
||||||
:gl:`#5197` :gl:`!10157`
|
|
||||||
|
|
||||||
- Fix a bug in the statistics channel when querying zone transfers
|
|
||||||
information. ``e02d73e7e3``
|
|
||||||
|
|
||||||
When querying zone transfers information from the statistics channel
|
|
||||||
there was a rare possibility that `named` could terminate unexpectedly
|
|
||||||
if a zone transfer was in a state when transferring from all the
|
|
||||||
available primary servers had failed earlier. This has been fixed.
|
|
||||||
:gl:`#5198` :gl:`!10182`
|
|
||||||
|
|
||||||
- Fix assertion failure when dumping recursing clients. ``796b662b92``
|
|
||||||
|
|
||||||
Previously, if a new counter was added to the hashtable while dumping
|
|
||||||
recursing clients via the `rndc recursing` command, and
|
|
||||||
`fetches-per-zone` was enabled, an assertion failure could occur. This
|
|
||||||
has been fixed. :gl:`#5200` :gl:`!10164`
|
|
||||||
|
|
||||||
- Validating ADB fetches could cause a crash in import_rdataset()
|
|
||||||
``49ccbe857a``
|
|
||||||
|
|
||||||
Previously, in some cases, the resolver could return rdatasets of type
|
|
||||||
CNAME or DNAME without the result code being set to `DNS_R_CNAME` or
|
|
||||||
`DNS_R_DNAME`. This could trigger an assertion failure in the ADB. The
|
|
||||||
resolver error has been fixed. :gl:`#5201` :gl:`!10172`
|
|
||||||
|
|
||||||
- Call isc__iterated_hash_initialize in isc__work_cb. ``f3458fdf43``
|
|
||||||
|
|
||||||
isc_iterated_hash didn't work in offloaded threads as the per thread
|
|
||||||
initialisation has not been done. This has been fixed. :gl:`#5214`
|
|
||||||
:gl:`!10206`
|
|
||||||
|
|
||||||
- Fix a bug in get_request_transport_type() ``db5166ab99``
|
|
||||||
|
|
||||||
When `dns_remote_done()` is true, calling `dns_remote_curraddr()`
|
|
||||||
asserts. Add a `dns_remote_curraddr()` check before calling
|
|
||||||
`dns_remote_curraddr()`. :gl:`#5215` :gl:`!10222`
|
|
||||||
|
|
||||||
- Clean up dns_rdataslab module. ``948f8d7a98``
|
|
||||||
|
|
||||||
Rdata slabs used in the QP databases are usually prepended with a slab
|
|
||||||
header, but are sometimes "raw", containing only the rdata and no
|
|
||||||
header. Previously, to allow for them to be used both ways, functions
|
|
||||||
that operated on them took a `reservelen` argument, which would be set
|
|
||||||
to either the header length or to zero, and skipped over that many
|
|
||||||
bytes at the beginning of the buffer. Most such functions were never
|
|
||||||
used on the raw form. To make the code clearer, each of these
|
|
||||||
functions now operates on full slabs with headers, and an alternate
|
|
||||||
"raw" version of the function has been added in cases where that was
|
|
||||||
needed.
|
|
||||||
|
|
||||||
In addition, the `dns_rdataslab_merge()` and `_subtract()` functions
|
|
||||||
have been rewritten for clarity and efficiency, and a minor bug has
|
|
||||||
been fixed in `dns_rdataslab_equal()` and `_equalx()`, which could
|
|
||||||
cause an incorrect result if both slabs being compared had zero
|
|
||||||
length. :gl:`!10084`
|
|
||||||
|
|
||||||
- Dump the active resolver fetches from dns_resolver_dumpfetches()
|
|
||||||
``5d0c347e75``
|
|
||||||
|
|
||||||
Previously, active resolver fetches were only dumped when the
|
|
||||||
`fetches-per-zone` configuration option was enabled. Now, active
|
|
||||||
resolver fetches are dumped along with the number of
|
|
||||||
`clients-per-server` counters per resolver fetch. :gl:`!10107`
|
|
||||||
|
|
||||||
- Fix the foundname vs dcname madness in qpcache_findzonecut()
|
|
||||||
``4e68dbf194``
|
|
||||||
|
|
||||||
The qpcache_findzonecut() accepts two "foundnames": 'foundname' and
|
|
||||||
'dcname' could be NULL. Originally, when 'dcname' would be NULL, the
|
|
||||||
'dcname' would be set to 'foundname' which basically means that we
|
|
||||||
were copying the .ndata over itself for no apparent reason.
|
|
||||||
:gl:`!10049`
|
|
||||||
|
|
||||||
- Post [CVE-2024-12705] Performance Drop Fixes, Part 2. ``c8104daf8d``
|
|
||||||
|
|
||||||
This merge request addresses several key performance bottlenecks in
|
|
||||||
the DoH (DNS over HTTPS) implementation by introducing significant
|
|
||||||
optimizations and improvements.
|
|
||||||
|
|
||||||
### Key Improvements
|
|
||||||
|
|
||||||
1. **Simplification and Optimisation of `http_do_bio()` Function**:
|
|
||||||
- The code flow in the `http_do_bio()` function has been significantly
|
|
||||||
simplified. 2. **Flushing HTTP Write Buffer on Outgoing DNS
|
|
||||||
Messages**: - The buffer is flushed and a send operation is
|
|
||||||
performed when there is an outgoing DNS message. 3. **Bumping Active
|
|
||||||
Streams Processing Limit**: - The total number of active streams
|
|
||||||
has been increased to 60% of the total streams limit.
|
|
||||||
|
|
||||||
These changes collectively enhance the performance and reliability of
|
|
||||||
the DoH implementation, making it more efficient and robust for
|
|
||||||
handling high-load scenarios, particularly noticeable in long runs (>=
|
|
||||||
1h) of `stress:long:rpz:doh+udp:linux:*` tests. It improves perf. for
|
|
||||||
tests for BIND 9.18, but it likely will have a positive but less
|
|
||||||
pronounced effect on newer versions as well.
|
|
||||||
|
|
||||||
In essence, the merge request fixes three bottlenecks stacked upon
|
|
||||||
each other.
|
|
||||||
|
|
||||||
*It is a logical continuation of the merge requests !10109.* !10109,
|
|
||||||
unfortunately, did not completely [address the performance drop in
|
|
||||||
9.18](https://gitlab.isc.org/isc-projects/bind9/-/pipelines/221545)
|
|
||||||
for longer runs of the stress test. This merge request [addresses
|
|
||||||
that](https://gitlab.isc.org/isc-projects/bind9/-/pipelines/223661).
|
|
||||||
|
|
||||||
**P.S.**
|
|
||||||
|
|
||||||
The origin of the fixes is, in fact, the branch in !10193. So this MR
|
|
||||||
is a ... *forward port* of them. :gl:`!10192`
|
|
||||||
|
|
||||||
- Post [CVE-2024-12705] Performance Drop Fixes. ``3033d127d2``
|
|
||||||
|
|
||||||
This merge request fixes a [performance
|
|
||||||
drop](https://gitlab.isc.org/isc-projects/bind9/-/pipelines/216728)
|
|
||||||
after merging the fixes for #4795, in particular in 9.18.
|
|
||||||
|
|
||||||
The MR [fixes the
|
|
||||||
problem](https://gitlab.isc.org/isc-projects/bind9/-/pipelines/219825)
|
|
||||||
without affecting performance for the newer versions, in particular
|
|
||||||
for [the development version](https://gitlab.isc.org/isc-projects/bind
|
|
||||||
9/-/pipelines/220619). :gl:`!10109`
|
|
||||||
|
|
||||||
- Remove 'target' from dns_adb. ``764eb65cf6``
|
|
||||||
|
|
||||||
When a server name turns out to be a CNAME or DNAME, the ADB does not
|
|
||||||
use it, but the `dns_adbname` structure still stored a copy of the
|
|
||||||
target name. This is unnecessary and the code has been removed.
|
|
||||||
:gl:`!10149`
|
|
||||||
|
|
||||||
- Simplify some dns_name API calls. ``e16560a650``
|
|
||||||
|
|
||||||
Several functions in the `dns_name` module have had parameters
|
|
||||||
removed, that were rarely or never used: - `dns_name_fromtext()` and
|
|
||||||
`dns_name_concatenate()` no longer take a target buffer. -
|
|
||||||
`dns_name_towire()` no longer takes a compression offset pointer; this
|
|
||||||
is now part of the compression context. - `dns_name_towire()` with a
|
|
||||||
`NULL` compression context will copy name data directly into a buffer
|
|
||||||
with no processing. :gl:`!10152`
|
|
||||||
|
|
||||||
- Sync the TSAN CC, CFLAGS and LDFLAGS in the respdiff:tsan job.
|
|
||||||
``22b5442722``
|
|
||||||
|
|
||||||
:gl:`!10209`
|
|
||||||
|
|
||||||
|
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user