Compare commits

..
Author SHA1 Message Date
Ondřej Surý 8fdbf3171a Revert "Skip the runtime ellipsis test"
This reverts commit 161e02845f.
2019-11-26 12:13:07 +01:00
Evan HuntandOndřej Surý 8fa02de98d fixed a test failure, some other shell cleanup 2019-11-26 12:11:59 +01:00
Ondřej Surý cff65624e0 Detect cores on FreeBSD 2019-11-26 12:11:59 +01:00
Ondřej Surý ca4b4bf421 Request exclusive access when crashing via fatal()
When loading the configuration fails, there might be already other tasks
running and calling OpenSSL library functions.  The OpenSSL on_exit
handler is called when exiting the main process and there's a timing
race between the on_exit function that destroys OpenSSL allocated
resources (threads, locks, ...) and other tasks accessing the very same
resources leading to a crash in the system threading library. Therefore,
the fatal() function needs to request exlusive access to the task
manager to finish the already running tasks and exit only when no other
tasks are running.
2019-11-26 12:11:59 +01:00
Ondřej SurýandOndřej Surý bc66044246 Instead of sleeping for a fixed time, wait for named to log specific message in a loop 2019-11-26 12:11:59 +01:00
Ondřej SurýandOndřej Surý d52fa06bc1 Use pre-prepared long command line for better portability 2019-11-26 12:11:59 +01:00
Ondřej SurýandOndřej Surý 34a4ceeb1c Make runtime/tests.sh shellcheck and set -e clean
This mostly comprises of:

* using $(...) instead of `...`
* changing the directories in subshell and not ignoring `cd` return code
* handling every error gracefully instead of ignoring the return code
2019-11-26 12:11:06 +01:00
Ondřej SurýandOndřej Surý 207b449fab Further improve the runtime tests to look for a specific instead of generic error 2019-11-26 12:11:06 +01:00
Ondřej SurýandOndřej Surý d953cabb26 The PATH_MAX on macOS is 1024, we can't override conffile path to test for ellipsis 2019-11-26 12:11:06 +01:00
Ondřej SurýandOndřej Surý 6d319355b8 Fix couple of no-op tests to actually test something (configuration files were missing) 2019-11-26 12:11:06 +01:00
Ondřej SurýandOndřej Surý 161e02845f Skip the runtime ellipsis test 2019-11-26 12:11:06 +01:00
Ondřej SurýandOndřej Surý c89ceb5ad3 runtime test: make the pidfiles match the names of configuration files 2019-11-26 12:11:06 +01:00
Ondřej SurýandOndřej Surý 01688a6cf5 runtime test: use helper function that kills named and waits for the finish 2019-11-26 12:11:06 +01:00
518 changed files with 9885 additions and 11020 deletions
-8
View File
@@ -1,10 +1,2 @@
*.sln.in eol=crlf *.sln.in eol=crlf
*.vcxproj.* eol=crlf *.vcxproj.* eol=crlf
.gitignore export-ignore
/conftools export-ignore
/doc/design export-ignore
/doc/dev export-ignore
/util/** export-ignore
/util/bindkeys.pl -export-ignore
/util/mksymtbl.pl -export-ignore
-1
View File
@@ -60,4 +60,3 @@ timestamp
/compile_commands.json /compile_commands.json
/cppcheck_html/ /cppcheck_html/
/cppcheck.results /cppcheck.results
/tsan
+85 -360
View File
@@ -18,20 +18,9 @@ variables:
MAKE: make MAKE: make
CONFIGURE: ./configure CONFIGURE: ./configure
SCAN_BUILD: scan-build-9 SCAN_BUILD: scan-build-9
SYMBOLIZER: /usr/lib/llvm-9/bin/llvm-symbolizer
ASAN_SYMBOLIZER_PATH: "$SYMBOLIZER"
CFLAGS_COMMON: -fno-omit-frame-pointer -fno-optimize-sibling-calls -O1 -g -Wall -Wextra CFLAGS_COMMON: -fno-omit-frame-pointer -fno-optimize-sibling-calls -O1 -g -Wall -Wextra
# Pass run-time flags to AddressSanitizer to get core dumps on error.
ASAN_OPTIONS_COMMON: abort_on_error=1:disable_coredump=0:unmap_shadow_on_exit=1
TARBALL_COMPRESSOR: xz
TARBALL_EXTENSION: xz
# limit jobs when debugging cppcheck
DEBUG_CPPCHECK: 1
stages: stages:
- precheck - precheck
- build - build
@@ -40,7 +29,6 @@ stages:
- docs - docs
- push - push
- postcheck - postcheck
- release
### Runner Tag Templates ### Runner Tag Templates
@@ -70,8 +58,8 @@ stages:
# Alpine Linux # Alpine Linux
.alpine-3.11-amd64: &alpine_3_11_amd64_image .alpine-3.10-amd64: &alpine_3_10_amd64_image
image: "$CI_REGISTRY_IMAGE:alpine-3.11-amd64" image: "$CI_REGISTRY_IMAGE:alpine-3.10-amd64"
<<: *linux_amd64 <<: *linux_amd64
# CentOS # CentOS
@@ -114,16 +102,10 @@ stages:
image: "$CI_REGISTRY_IMAGE:debian-sid-i386" image: "$CI_REGISTRY_IMAGE:debian-sid-i386"
<<: *linux_i386 <<: *linux_i386
# openSUSE Tumbleweed
.tumbleweed-latest-amd64: &tumbleweed_latest_amd64_image
image: "$CI_REGISTRY_IMAGE:tumbleweed-latest-amd64"
<<: *linux_amd64
# Fedora # Fedora
.fedora-31-amd64: &fedora_31_amd64_image .fedora-30-amd64: &fedora_30_amd64_image
image: "$CI_REGISTRY_IMAGE:fedora-31-amd64" image: "$CI_REGISTRY_IMAGE:fedora-30-amd64"
<<: *linux_amd64 <<: *linux_amd64
# Ubuntu # Ubuntu
@@ -151,14 +133,12 @@ stages:
- merge_requests - merge_requests
- tags - tags
- web - web
- schedules
.release-branch-triggering-rules: &release_branch_triggering_rules .release-branch-triggering-rules: &release_branch_triggering_rules
only: only:
- merge_requests - merge_requests
- tags - tags
- web - web
- schedules
- master@isc-projects/bind9 - master@isc-projects/bind9
- /^v9_[1-9][0-9]$/@isc-projects/bind9 - /^v9_[1-9][0-9]$/@isc-projects/bind9
@@ -179,7 +159,7 @@ stages:
- configure - configure
- ltmain.sh - ltmain.sh
- m4/libtool.m4 - m4/libtool.m4
expire_in: "1 day" expire_in: "1 week"
.configure: &configure | .configure: &configure |
${CONFIGURE} \ ${CONFIGURE} \
@@ -194,13 +174,12 @@ stages:
--without-make-clean \ --without-make-clean \
$EXTRA_CONFIGURE \ $EXTRA_CONFIGURE \
|| cat config.log || cat config.log
.build: &build_job .build: &build_job
<<: *default_triggering_rules <<: *default_triggering_rules
stage: build stage: build
before_script: before_script:
- test -w "${CCACHE_DIR}" && export PATH="/usr/lib/ccache:${PATH}" - test -w "${CCACHE_DIR}" && export PATH="/usr/lib/ccache:${PATH}"
- test -n "${OOT_BUILD_WORKSPACE}" && mkdir "${OOT_BUILD_WORKSPACE}" && cd "${OOT_BUILD_WORKSPACE}"
script: script:
- *configure - *configure
- ${MAKE} -j${BUILD_PARALLEL_JOBS:-1} -k all V=1 - ${MAKE} -j${BUILD_PARALLEL_JOBS:-1} -k all V=1
@@ -211,43 +190,7 @@ stages:
- autoreconf:sid:amd64 - autoreconf:sid:amd64
artifacts: artifacts:
untracked: true untracked: true
expire_in: "1 day" expire_in: "1 week"
except:
variables:
- $DEBUG_CPPCHECK == "1"
.windows_build: &windows_build_job
stage: build
tags:
- windows
- amd64
script:
- 'Push-Location "C:/Program Files (x86)/Microsoft Visual Studio/2017/BuildTools/VC/Auxiliary/Build"'
- '& cmd.exe /C "vcvarsall.bat x64 & set" | Foreach-Object { if ($_ -match "(.*?)=(.*)") { Set-Item -force -path "Env:\$($matches[1])" -value "$($matches[2])" } }'
- 'Pop-Location'
- 'Set-Location win32utils'
- '& "C:/Strawberry/perl/bin/perl.exe" Configure
"with-tools-version=15.0"
"with-platform-toolset=v141"
"with-platform-version=10.0.17763.0"
"with-vcredist=C:/Program Files (x86)/Microsoft Visual Studio/2017/BuildTools/VC/Redist/MSVC/14.16.27012/vcredist_x64.exe"
"with-openssl=C:/OpenSSL"
"with-libxml2=C:/libxml2"
"with-libuv=C:/libuv"
"without-python"
"with-system-tests"
x64'
- 'Set-Item -path "Env:CL" -value "/MP$([Math]::Truncate($BUILD_PARALLEL_JOBS/2))"'
- '& msbuild.exe /maxCpuCount:2 /t:Build /p:Configuration=$VSCONF bind9.sln'
dependencies: []
needs:
- autoreconf:sid:amd64
artifacts:
untracked: true
expire_in: "1 day"
except:
variables:
- $DEBUG_CPPCHECK == "1"
.setup_interfaces: &setup_interfaces | .setup_interfaces: &setup_interfaces |
if [ "$(id -u)" -eq "0" ]; then if [ "$(id -u)" -eq "0" ]; then
@@ -257,11 +200,12 @@ stages:
fi fi
.setup_softhsm: &setup_softhsm | .setup_softhsm: &setup_softhsm |
sh -x bin/tests/prepare-softhsm2.sh sh -x util/prepare-softhsm2.sh
.system_test: &system_test_job .system_test: &system_test_job
<<: *default_triggering_rules <<: *default_triggering_rules
stage: system stage: system
retry: 2
before_script: before_script:
- *setup_interfaces - *setup_interfaces
- *setup_softhsm - *setup_softhsm
@@ -270,11 +214,8 @@ stages:
- test -s bin/tests/system/systests.output - test -s bin/tests/system/systests.output
artifacts: artifacts:
untracked: true untracked: true
expire_in: "1 day" expire_in: "1 week"
when: on_failure when: on_failure
except:
variables:
- $DEBUG_CPPCHECK == "1"
.kyua_report: &kyua_report_html | .kyua_report: &kyua_report_html |
kyua --logfile /dev/null report-html \ kyua --logfile /dev/null report-html \
@@ -283,30 +224,6 @@ stages:
--results-filter "" \ --results-filter "" \
--output kyua_html --output kyua_html
.windows_system_test: &windows_system_test_job
stage: system
tags:
- windows
- amd64
script:
- 'Push-Location bin/tests/system'
- '$ifIndex = Get-NetIPInterface -AddressFamily IPv4 -InterfaceMetric 75 | Select-Object -ExpandProperty ifIndex'
- '& C:/tools/cygwin/bin/sed.exe -i "s/^exit.*/netsh interface ipv4 set dnsservers $ifIndex dhcp/; s/\(name\|interface\)=Loopback/$ifIndex/;" ifconfig.bat'
- '& C:/tools/cygwin/bin/sed.exe -i "s/kill -f/kill -W/;" conf.sh stop.pl'
- '& cmd.exe /C ifconfig.bat up; ""'
- 'Start-Sleep 2'
- '$Env:Path = "C:/tools/cygwin/bin;$Env:Path"'
- '& sh.exe runall.sh $TEST_PARALLEL_JOBS'
- 'If (Test-Path C:/CrashDumps/*) { dir C:/CrashDumps; Throw }'
artifacts:
untracked: true
expire_in: "1 day"
when: on_failure
only:
- schedules
- tags
- web
.unit_test: &unit_test_job .unit_test: &unit_test_job
<<: *default_triggering_rules <<: *default_triggering_rules
stage: unit stage: unit
@@ -321,19 +238,14 @@ stages:
- kyua.log - kyua.log
- kyua.results - kyua.results
- kyua_html/ - kyua_html/
expire_in: "1 day" expire_in: "1 week"
when: on_failure when: on_failure
except:
variables:
- $DEBUG_CPPCHECK == "1"
.cppcheck_args: &run_cppcheck | .cppcheck_args: &run_cppcheck |
cppcheck --enable=warning,performance,portability,information,missingInclude \ cppcheck --enable=warning,performance,portability,information,missingInclude \
--dump \
--include=config.h \ --include=config.h \
--quiet \ --quiet \
--std=c11 \ --std=c11 \
--library=std.cfg \
--language=c \ --language=c \
--project=compile_commands.json \ --project=compile_commands.json \
--error-exitcode=2 \ --error-exitcode=2 \
@@ -342,7 +254,6 @@ stages:
--output-file=cppcheck.results \ --output-file=cppcheck.results \
--relative-paths="$CI_PROJECT_DIR" \ --relative-paths="$CI_PROJECT_DIR" \
--inline-suppr \ --inline-suppr \
-U DOXYGEN \
--suppressions-list=util/suppressions.txt --suppressions-list=util/suppressions.txt
.cppcheck_report: &cppcheck_report_html | .cppcheck_report: &cppcheck_report_html |
@@ -361,12 +272,11 @@ stages:
after_script: after_script:
- *cppcheck_report_html - *cppcheck_report_html
artifacts: artifacts:
untracked: true
paths: paths:
- compile_commands.json - compile_commands.json
- cppcheck.results - cppcheck.results
- cppcheck_html/ - cppcheck_html/
expire_in: "1 day" expire_in: "1 week"
when: on_failure when: on_failure
### Job Definitions ### Job Definitions
@@ -383,11 +293,8 @@ misc:sid:amd64:
- sh util/checklibs.sh > checklibs.out - sh util/checklibs.sh > checklibs.out
- sh util/tabify-changes < CHANGES > CHANGES.tmp - sh util/tabify-changes < CHANGES > CHANGES.tmp
- diff -urNap CHANGES CHANGES.tmp - diff -urNap CHANGES CHANGES.tmp
- perl util/check-changes CHANGES
- test ! -f CHANGES.SE || sh util/tabify-changes < CHANGES.SE > CHANGES.tmp
- test ! -f CHANGES.SE || diff -urNap CHANGES.SE CHANGES.tmp
- test ! -f CHANGES.SE || perl util/check-changes master=0 CHANGES.SE
- rm CHANGES.tmp - rm CHANGES.tmp
- perl util/check-changes CHANGES
- perl -w util/merge_copyrights - perl -w util/merge_copyrights
- diff -urNap util/copyrights util/newcopyrights - diff -urNap util/copyrights util/newcopyrights
- rm util/newcopyrights - rm util/newcopyrights
@@ -400,7 +307,7 @@ misc:sid:amd64:
paths: paths:
- util/newcopyrights - util/newcopyrights
- checklibs.out - checklibs.out
expire_in: "1 day" expire_in: "1 week"
when: on_failure when: on_failure
🐞:sid:amd64: 🐞:sid:amd64:
@@ -410,23 +317,6 @@ misc:sid:amd64:
- util/check-cocci - util/check-cocci
- if test "$(git status --porcelain | grep -Ev '\?\?' | wc -l)" -gt "0"; then git status --short; exit 1; fi - if test "$(git status --porcelain | grep -Ev '\?\?' | wc -l)" -gt "0"; then git status --short; exit 1; fi
tarball-create:sid:amd64:
<<: *debian_sid_amd64_image
stage: precheck
script:
- source version
- export BIND_DIRECTORY="bind-${MAJORVER}.${MINORVER}.${PATCHVER}${RELEASETYPE}${RELEASEVER}"
- git archive --prefix="${BIND_DIRECTORY}/" --output="${BIND_DIRECTORY}.tar" HEAD
- mkdir "${BIND_DIRECTORY}"
- echo "SRCID=$(git rev-list --max-count=1 HEAD | cut -b1-7)" > "${BIND_DIRECTORY}/srcid"
- tar --append --file="${BIND_DIRECTORY}.tar" "${BIND_DIRECTORY}/srcid"
- ${TARBALL_COMPRESSOR} "${BIND_DIRECTORY}.tar"
artifacts:
paths:
- bind-*.tar.${TARBALL_EXTENSION}
only:
- tags
# Jobs for doc builds on Debian Sid (amd64) # Jobs for doc builds on Debian Sid (amd64)
docs:sid:amd64: docs:sid:amd64:
@@ -444,10 +334,7 @@ docs:sid:amd64:
artifacts: artifacts:
paths: paths:
- doc/arm/ - doc/arm/
expire_in: "1 day" expire_in: "1 month"
except:
variables:
- $DEBUG_CPPCHECK == "1"
push:docs:sid:amd64: push:docs:sid:amd64:
<<: *debian_sid_amd64_image <<: *debian_sid_amd64_image
@@ -459,29 +346,29 @@ push:docs:sid:amd64:
- master@isc-projects/bind9 - master@isc-projects/bind9
- /^v9_[1-9][0-9]$/@isc-projects/bind9 - /^v9_[1-9][0-9]$/@isc-projects/bind9
# Jobs for regular GCC builds on Alpine Linux 3.11 (amd64) # Jobs for regular GCC builds on Alpine Linux 3.10 (amd64)
gcc:alpine3.11:amd64: gcc:alpine3.10:amd64:
variables: variables:
CC: gcc CC: gcc
CFLAGS: "${CFLAGS_COMMON}" CFLAGS: "${CFLAGS_COMMON}"
EXTRA_CONFIGURE: "--enable-dnstap" EXTRA_CONFIGURE: "--enable-dnstap"
<<: *alpine_3_11_amd64_image <<: *alpine_3_10_amd64_image
<<: *build_job <<: *build_job
system:gcc:alpine3.11:amd64: system:gcc:alpine3.10:amd64:
<<: *alpine_3_11_amd64_image <<: *alpine_3_10_amd64_image
<<: *system_test_job <<: *system_test_job
dependencies: dependencies:
- gcc:alpine3.11:amd64 - gcc:alpine3.10:amd64
needs: ["gcc:alpine3.11:amd64"] needs: ["gcc:alpine3.10:amd64"]
unit:gcc:alpine3.11:amd64: unit:gcc:alpine3.10:amd64:
<<: *alpine_3_11_amd64_image <<: *alpine_3_10_amd64_image
<<: *unit_test_job <<: *unit_test_job
dependencies: dependencies:
- gcc:alpine3.11:amd64 - gcc:alpine3.10:amd64
needs: ["gcc:alpine3.11:amd64"] needs: ["gcc:alpine3.10:amd64"]
# Jobs for regular GCC builds on CentOS 6 (amd64) # Jobs for regular GCC builds on CentOS 6 (amd64)
@@ -654,11 +541,8 @@ scan-build:buster:amd64:
artifacts: artifacts:
paths: paths:
- scan-build.reports/ - scan-build.reports/
expire_in: "1 day" expire_in: "1 week"
when: on_failure when: on_failure
except:
variables:
- $DEBUG_CPPCHECK == "1"
# Jobs for regular GCC builds on Debian Sid (amd64) # Jobs for regular GCC builds on Debian Sid (amd64)
@@ -669,7 +553,6 @@ gcc:sid:amd64:
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2" EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
RUN_MAKE_INSTALL: 1 RUN_MAKE_INSTALL: 1
MAKE: bear make MAKE: bear make
DEBUG_CPPCHECK: 0
<<: *debian_sid_amd64_image <<: *debian_sid_amd64_image
<<: *build_job <<: *build_job
@@ -694,61 +577,6 @@ cppcheck:gcc:sid:amd64:
- gcc:sid:amd64 - gcc:sid:amd64
needs: ["gcc:sid:amd64"] needs: ["gcc:sid:amd64"]
# Job for out-of-tree GCC build on Debian Sid (amd64)
oot:sid:amd64:
variables:
CC: gcc
CFLAGS: "${CFLAGS_COMMON} -O3"
CONFIGURE: ../configure
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
RUN_MAKE_INSTALL: 1
OOT_BUILD_WORKSPACE: workspace
<<: *debian_sid_amd64_image
<<: *build_job
# Jobs for tarball GCC builds on Debian Sid (amd64)
tarball:sid:amd64:
variables:
CC: gcc
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
RUN_MAKE_INSTALL: 1
<<: *debian_sid_amd64_image
<<: *build_job
before_script:
- tar --extract --file bind-*.tar.${TARBALL_EXTENSION}
- rm -f bind-*.tar.${TARBALL_EXTENSION}
- cd bind-*
dependencies:
- tarball-create:sid:amd64
needs: ["tarball-create:sid:amd64"]
only:
- tags
system:tarball:sid:amd64:
<<: *debian_sid_amd64_image
<<: *system_test_job
before_script:
- cd bind-*
- *setup_interfaces
dependencies:
- tarball:sid:amd64
needs: ["tarball:sid:amd64"]
only:
- tags
unit:tarball:sid:amd64:
<<: *debian_sid_amd64_image
<<: *unit_test_job
before_script:
- cd bind-*
dependencies:
- tarball:sid:amd64
needs: ["tarball:sid:amd64"]
only:
- tags
# Jobs for regular GCC builds on Debian Sid (i386) # Jobs for regular GCC builds on Debian Sid (i386)
gcc:sid:i386: gcc:sid:i386:
@@ -773,53 +601,29 @@ unit:gcc:sid:i386:
- gcc:sid:i386 - gcc:sid:i386
needs: ["gcc:sid:i386"] needs: ["gcc:sid:i386"]
# Jobs for regular GCC builds on openSUSE Tumbleweed (amd64) # Jobs for regular GCC builds on Fedora 30 (amd64)
gcc:tumbleweed:amd64: gcc:fedora30:amd64:
variables:
CC: gcc
CFLAGS: "${CFLAGS_COMMON}"
EXTRA_CONFIGURE: "--with-libidn2"
<<: *tumbleweed_latest_amd64_image
<<: *build_job
system:gcc:tumbleweed:amd64:
<<: *tumbleweed_latest_amd64_image
<<: *system_test_job
dependencies:
- gcc:tumbleweed:amd64
needs: ["gcc:tumbleweed:amd64"]
unit:gcc:tumbleweed:amd64:
<<: *tumbleweed_latest_amd64_image
<<: *unit_test_job
dependencies:
- gcc:tumbleweed:amd64
needs: ["gcc:tumbleweed:amd64"]
# Jobs for regular GCC builds on Fedora 31 (amd64)
gcc:fedora31:amd64:
variables: variables:
CC: gcc CC: gcc
CFLAGS: "${CFLAGS_COMMON} -O1" CFLAGS: "${CFLAGS_COMMON} -O1"
EXTRA_CONFIGURE: "--with-libidn2" EXTRA_CONFIGURE: "--with-libidn2"
<<: *fedora_31_amd64_image <<: *fedora_30_amd64_image
<<: *build_job <<: *build_job
system:gcc:fedora31:amd64: system:gcc:fedora30:amd64:
<<: *fedora_31_amd64_image <<: *fedora_30_amd64_image
<<: *system_test_job <<: *system_test_job
dependencies: dependencies:
- gcc:fedora31:amd64 - gcc:fedora30:amd64
needs: ["gcc:fedora31:amd64"] needs: ["gcc:fedora30:amd64"]
unit:gcc:fedora31:amd64: unit:gcc:fedora30:amd64:
<<: *fedora_31_amd64_image <<: *fedora_30_amd64_image
<<: *unit_test_job <<: *unit_test_job
dependencies: dependencies:
- gcc:fedora31:amd64 - gcc:fedora30:amd64
needs: ["gcc:fedora31:amd64"] needs: ["gcc:fedora30:amd64"]
# Jobs for regular GCC builds on Ubuntu 16.04 Xenial Xerus (amd64) # Jobs for regular GCC builds on Ubuntu 16.04 Xenial Xerus (amd64)
@@ -874,6 +678,7 @@ unit:gcc:bionic:amd64:
asan:sid:amd64: asan:sid:amd64:
variables: variables:
CC: gcc CC: gcc
ASAN_OPTIONS: "detect_leaks=0"
CFLAGS: "${CFLAGS_COMMON} -fsanitize=address,undefined -DISC_MEM_USE_INTERNAL_MALLOC=0" CFLAGS: "${CFLAGS_COMMON} -fsanitize=address,undefined -DISC_MEM_USE_INTERNAL_MALLOC=0"
LDFLAGS: "-fsanitize=address,undefined" LDFLAGS: "-fsanitize=address,undefined"
EXTRA_CONFIGURE: "--with-libidn2" EXTRA_CONFIGURE: "--with-libidn2"
@@ -881,8 +686,6 @@ asan:sid:amd64:
<<: *build_job <<: *build_job
system:asan:sid:amd64: system:asan:sid:amd64:
variables:
ASAN_OPTIONS: ${ASAN_OPTIONS_COMMON}
<<: *debian_sid_amd64_image <<: *debian_sid_amd64_image
<<: *system_test_job <<: *system_test_job
dependencies: dependencies:
@@ -890,71 +693,12 @@ system:asan:sid:amd64:
needs: ["asan:sid:amd64"] needs: ["asan:sid:amd64"]
unit:asan:sid:amd64: unit:asan:sid:amd64:
variables:
ASAN_OPTIONS: ${ASAN_OPTIONS_COMMON}
<<: *debian_sid_amd64_image <<: *debian_sid_amd64_image
<<: *unit_test_job <<: *unit_test_job
dependencies: dependencies:
- asan:sid:amd64 - asan:sid:amd64
needs: ["asan:sid:amd64"] needs: ["asan:sid:amd64"]
# Jobs for GCC builds with TSAN enabled on Debian Sid (amd64)
tsan:buster:amd64:
<<: *debian_buster_amd64_image
<<: *build_job
variables:
CC: clang-9
CFLAGS: "${CFLAGS_COMMON} -fsanitize=thread -DISC_MEM_USE_INTERNAL_MALLOC=0"
LDFLAGS: "-fsanitize=thread"
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock"
system:tsan:buster:amd64:
variables:
TSAN_OPTIONS: "second_deadlock_stack=1 history_size=7 log_exe_name=true log_path=tsan external_symbolizer_path=$SYMBOLIZER exitcode=0"
before_script:
- *setup_interfaces
- echo $TSAN_OPTIONS
<<: *debian_buster_amd64_image
<<: *system_test_job
dependencies:
- tsan:buster:amd64
needs: ["tsan:buster:amd64"]
allow_failure: true
after_script:
- find bin -name 'tsan.*' -exec python3 util/parse_tsan.py {} \;
artifacts:
expire_in: "1 day"
paths:
- bin/tests/system/*/tsan.*
- bin/tests/system/*/*/tsan.*
- tsan/
when: on_failure
unit:tsan:buster:amd64:
variables:
TSAN_OPTIONS: "second_deadlock_stack=1 history_size=7 log_exe_name=true log_path=tsan external_symbolizer_path=$SYMBOLIZER"
before_script:
- echo $TSAN_OPTIONS
- lib/isc/tests/result_test
<<: *debian_buster_amd64_image
<<: *unit_test_job
dependencies:
- tsan:buster:amd64
needs: ["tsan:buster:amd64"]
allow_failure: true
after_script:
- find lib -name 'tsan.*' -exec python3 util/parse_tsan.py {} \;
artifacts:
expire_in: "1 day"
paths:
- lib/*/tests/tsan.*
- tsan/
- kyua.log
- kyua.results
- kyua_html/
when: on_failure
rwlock:sid:amd64: rwlock:sid:amd64:
variables: variables:
CC: gcc CC: gcc
@@ -1112,7 +856,6 @@ system:clang:openbsd6.5:amd64:
- clang:openbsd6.5:amd64 - clang:openbsd6.5:amd64
needs: ["clang:openbsd6.5:amd64"] needs: ["clang:openbsd6.5:amd64"]
only: only:
- schedules
- tags - tags
- web - web
@@ -1143,80 +886,62 @@ unit:nolibtool:sid:amd64:
# Jobs for Visual Studio 2017 builds on Windows (amd64) # Jobs for Visual Studio 2017 builds on Windows (amd64)
msvc:windows:amd64: msvc:windows:amd64:
<<: *windows_build_job
<<: *default_triggering_rules <<: *default_triggering_rules
stage: build
tags:
- windows
- amd64
variables: variables:
VSCONF: Release VSCONF: Release
script:
- 'Push-Location "C:/Program Files (x86)/Microsoft Visual Studio/2017/BuildTools/VC/Auxiliary/Build"'
- '& cmd.exe /C "vcvarsall.bat x64 & set" | Foreach-Object { if ($_ -match "(.*?)=(.*)") { Set-Item -force -path "Env:\$($matches[1])" -value "$($matches[2])" } }'
- 'Pop-Location'
- 'Set-Location win32utils'
- '& "C:/Strawberry/perl/bin/perl.exe" Configure
"with-tools-version=15.0"
"with-platform-toolset=v141"
"with-platform-version=10.0.17763.0"
"with-vcredist=C:/Program Files (x86)/Microsoft Visual Studio/2017/BuildTools/VC/Redist/MSVC/14.16.27012/vcredist_x64.exe"
"with-openssl=C:/OpenSSL"
"with-libxml2=C:/libxml2"
"with-libuv=C:/libuv"
"without-python"
"with-system-tests"
x64'
- 'Set-Item -path "Env:CL" -value "/MP$([Math]::Truncate($BUILD_PARALLEL_JOBS/2))"'
- '& msbuild.exe /maxCpuCount:2 /t:Build /p:Configuration=$VSCONF bind9.sln'
dependencies: []
needs:
- autoreconf:sid:amd64
artifacts:
untracked: true
expire_in: "1 week"
system:msvc:windows:amd64: system:msvc:windows:amd64:
<<: *windows_system_test_job stage: system
tags:
- windows
- amd64
variables: variables:
VSCONF: Release VSCONF: Release
script:
- 'Push-Location bin/tests/system'
- '$ifIndex = Get-NetIPInterface -AddressFamily IPv4 -InterfaceMetric 75 | Select-Object -ExpandProperty ifIndex'
- '& C:/tools/cygwin/bin/sed.exe -i "s/^exit.*/netsh interface ipv4 set dnsservers $ifIndex dhcp/; s/\(name\|interface\)=Loopback/$ifIndex/;" ifconfig.bat'
- '& C:/tools/cygwin/bin/sed.exe -i "s/kill -f/kill -W/;" conf.sh stop.pl'
- '& cmd.exe /C ifconfig.bat up; ""'
- 'Start-Sleep 2'
- '$Env:Path = "C:/tools/cygwin/bin;$Env:Path"'
- '& sh.exe runall.sh $TEST_PARALLEL_JOBS'
- 'If (Test-Path C:/CrashDumps/*) { dir C:/CrashDumps; Throw }'
dependencies: dependencies:
- msvc:windows:amd64 - msvc:windows:amd64
needs: ["msvc:windows:amd64"] needs: ["msvc:windows:amd64"]
except: artifacts:
variables: untracked: true
- $DEBUG_CPPCHECK == "1" expire_in: "1 week"
when: on_failure
msvc-debug:windows:amd64:
<<: *windows_build_job
variables:
VSCONF: Debug
only: only:
- schedules
- tags - tags
- web - web
system:msvc-debug:windows:amd64:
<<: *windows_system_test_job
variables:
VSCONF: Debug
dependencies:
- msvc-debug:windows:amd64
needs: ["msvc-debug:windows:amd64"]
except:
variables:
- $DEBUG_CPPCHECK == "1"
# Job producing a release tarball
release:sid:amd64:
<<: *debian_sid_amd64_image
stage: release
script:
# Determine BIND version
- source version
- export BIND_DIRECTORY="bind-${MAJORVER}.${MINORVER}.${PATCHVER}${RELEASETYPE}${RELEASEVER}"
# Remove redundant files and system test utilities from Windows build artifacts
- find Build/Release/ -name "*.pdb" -print -delete
- find Build/Debug/ \( -name "*.bsc" -o -name "*.idb" \) -print -delete
- find Build/ -regextype posix-extended -regex "Build/.*/($(find bin/tests/ -type f | sed -nE "s|^bin/tests(/system)?/win32/(.*)\.vcxproj$|\2|p" | paste -d"|" -s))\..*" -print -delete
# Create Windows zips
- openssl dgst -sha256 "${BIND_DIRECTORY}.tar.${TARBALL_EXTENSION}" | tee Build/Release/SHA256 Build/Debug/SHA256
- ( cd Build/Release; zip "../../BIND${BIND_DIRECTORY#bind-}.x64.zip" * )
- ( cd Build/Debug; zip "../../BIND${BIND_DIRECTORY#bind-}.debug.x64.zip" * )
# Prepare release tarball contents (tarballs + zips + documentation)
- mkdir -p release/doc/arm
- pushd release
- mv "../${BIND_DIRECTORY}.tar.${TARBALL_EXTENSION}" ../BIND*.zip .
- tar --extract --file="${BIND_DIRECTORY}.tar.${TARBALL_EXTENSION}"
- mv "${BIND_DIRECTORY}"/{CHANGES*,COPYRIGHT,LICENSE,README,srcid} .
- mv "${BIND_DIRECTORY}"/doc/arm/{Bv9ARM{*.html,.pdf},man.*,notes.{html,pdf,txt}} doc/arm/
- rm -rf "${BIND_DIRECTORY}"
- cp doc/arm/notes.html "RELEASE-NOTES-${BIND_DIRECTORY}.html"
- cp doc/arm/notes.pdf "RELEASE-NOTES-${BIND_DIRECTORY}.pdf"
- cp doc/arm/notes.txt "RELEASE-NOTES-${BIND_DIRECTORY}.txt"
- popd
# Create release tarball
- tar --create --file="${CI_COMMIT_TAG}.tar.gz" --gzip release/
dependencies:
- tarball-create:sid:amd64
- msvc:windows:amd64
- msvc-debug:windows:amd64
only:
- tags
artifacts:
paths:
- "*.tar.gz"
expire_in: "1 day"
+11 -11
View File
@@ -2,6 +2,8 @@
**Tagging Deadline:** **Tagging Deadline:**
**ASN Deadline:**
**Public Release:** **Public Release:**
## Release Checklist ## Release Checklist
@@ -10,7 +12,6 @@
- [ ] ***(QA)*** Check whether all issues assigned to the release milestone are resolved[^1]. - [ ] ***(QA)*** Check whether all issues assigned to the release milestone are resolved[^1].
- [ ] ***(QA)*** Ensure that there are no outstanding merge requests in the private repository[^1] (Subscription Edition only). - [ ] ***(QA)*** Ensure that there are no outstanding merge requests in the private repository[^1] (Subscription Edition only).
- [ ] ***(QA)*** Ensure all merge requests marked for backporting have been indeed backported.
## Before the Tagging Deadline ## Before the Tagging Deadline
@@ -32,22 +33,21 @@
## Before the ASN Deadline (for ASN Releases) or the Public Release Date (for Regular Releases) ## Before the ASN Deadline (for ASN Releases) or the Public Release Date (for Regular Releases)
- [ ] ***(QA)*** Verify GitLab CI results for the tags created and prepare a QA report for the releases to be published. - [ ] ***(QA)*** Run the `make release` Jenkins jobs to produce the tarballs and zips.
- [ ] ***(QA)*** Request signatures for the tarballs, providing their location and checksums. - [ ] ***(QA)*** Verify the results of `make release` Jenkins jobs and prepare a QA report for the releases to be published.
- [ ] ***(Signers)*** Validate tarball checksums, sign tarballs, and upload signatures. - [ ] ***(QA)*** Request signatures for the tarballs.
- [ ] ***(QA)*** Verify tarball signatures and check tarball checksums again. - [ ] ***(Signers)*** Sign the tarballs.
- [ ] ***(QA)*** Check tarball signatures.
- [ ] ***(QA)*** Notify Support that the releases are ready for publication.
- [ ] ***(Support)*** Pre-publish ASN and/or Subscription Edition tarballs so that packages can be built. - [ ] ***(Support)*** Pre-publish ASN and/or Subscription Edition tarballs so that packages can be built.
- [ ] ***(QA)*** Build and test ASN and/or Subscription Edition packages. - [ ] ***(QA)*** Build and test ASN and/or Subscription Edition packages.
- [ ] ***(QA)*** Notify Support that the releases have been prepared.
- [ ] ***(Support)*** Send out ASNs (if applicable). - [ ] ***(Support)*** Send out ASNs (if applicable).
## On the Day of Public Release ## On the Day of Public Release
- [ ] ***(Support)*** Wait for clearance from Security Officer to proceed with the public release (if applicable). - [ ] ***(Support)*** Publish the releases according to the release schedule.
- [ ] ***(Support)*** Place tarballs in public location on FTP site. - [ ] ***(Support)*** Write release email to *bind9-announce*.
- [ ] ***(Support)*** Publish links to downloads on ISC website. - [ ] ***(Support)*** Write email to *bind9-users* (if a major release).
- [ ] ***(Support)*** Write release email to *bind-announce*.
- [ ] ***(Support)*** Write email to *bind-users* (if a major release).
- [ ] ***(Support)*** Update tickets in case of waiting support customers. - [ ] ***(Support)*** Update tickets in case of waiting support customers.
- [ ] ***(QA)*** Build and test any outstanding private packages. - [ ] ***(QA)*** Build and test any outstanding private packages.
- [ ] ***(QA)*** Build public packages (`*.deb`, RPMs). - [ ] ***(QA)*** Build public packages (`*.deb`, RPMs).
+1 -82
View File
@@ -1,85 +1,4 @@
5350. [bug] When a view was configured with class CHAOS, the 5326. [bug] Add python dependancy on 'distutils.core' to configure.
server could crash while processing a query for a
non-existent record. [GL #1540]
5349. [bug] Fix a race in task_pause/unpause. [GL #1571]
5348. [bug] dnssec-settime -Psync was not being honoured.
[GL !2893]
--- 9.15.8 released ---
5347. [bug] Fixed a bug that could cause an intermittent crash
in validator.c when validating a negative cache
entry. [GL #1561]
5346. [bug] Make hazard pointer array allocations dynamic, fixing
a bug that caused named to crash on machines with more
than 40 cores. [GL #1493]
5345. [func] Key-style trust anchors and DS-style trust anchors
can now both be used for the same name. [GL #1237]
5344. [bug] Handle accept() errors properly in netmgr. [GL !2880]
5343. [func] Add statistics counters to the netmgr. [GL #1311]
5342. [bug] Disable pktinfo for IPv6 and bind to each interface
explicitly instead, because libuv doesn't support
pktinfo control messages. [GL #1558]
5341. [func] Simplify passing the bound TCP socket to child
threads by using isc_uv_export/import functions.
[GL !2825]
5340. [bug] Don't deadlock when binding to a TCP socket fails.
[GL #1499]
5339. [bug] With some libmaxminddb versions, named could erroneously
match an IP address not belonging to any subnet defined
in a given GeoIP2 database to one of the existing
entries in that database. [GL #1552]
5338. [bug] Fix line spacing in `rndc secroots`.
Thanks to Tony Finch. [GL !2478]
5337. [func] 'named -V' now reports maxminddb and protobuf-c
versions. [GL !2686]
--- 9.15.7 released ---
5336. [bug] The TCP high-water statistic could report an
incorrect value on startup. [GL #1392]
5335. [func] Make TCP listening code multithreaded. [GL !2659]
5334. [doc] Update documentation with dnssec-policy clarifications.
Also change some defaults. [GL !2711]
5333. [bug] Fix duration printing on Solaris when value is not
an ISO 8601 duration. [GL #1460]
5332. [func] Renamed "dnssec-keys" configuration statement
to the more descriptive "trust-anchors". [GL !2702]
5331. [func] Use compiler-provided mechanisms for thread local
storage, and make the requirement for such mechanisms
explicit in configure. [GL #1444]
5330. [bug] 'configure --without-python' was ineffective if
PYTHON was set in the environment. [GL #1434]
5329. [bug] Reconfiguring named caused memory to be leaked when any
GeoIP2 database was in use. [GL #1445]
5328. [bug] rbtdb.c:rdataset_{get,set}ownercase failed to obtain
a node lock. [GL #1417]
5327. [func] Added a statistics counter to track queries
dropped because the recursive-clients quota was
exceeded. [GL #1399]
5326. [bug] Add Python dependency on 'distutils.core' to configure.
'distutils.core' is required for installation. 'distutils.core' is required for installation.
[GL #1397] [GL #1397]
+1 -1
View File
@@ -1,4 +1,4 @@
Copyright (C) 1996-2020 Internet Systems Consortium, Inc. ("ISC") Copyright (C) 1996-2019 Internet Systems Consortium, Inc. ("ISC")
This Source Code Form is subject to the terms of the Mozilla Public This Source Code Form is subject to the terms of the Mozilla Public
License, v. 2.0. If a copy of the MPL was not distributed with this License, v. 2.0. If a copy of the MPL was not distributed with this
+1 -1
View File
@@ -150,7 +150,7 @@ releases. New features include:
- "rndc modzone" reconfigures a single zone, without requiring the entire - "rndc modzone" reconfigures a single zone, without requiring the entire
server to be reconfigured. server to be reconfigured.
- "rndc showzone" displays the current configuration of a zone. - "rndc showzone" displays the current configuration of a zone.
- "rndc managed-keys" can be used to check the status of RFC 5011 managed - "rndc managed-keys" can be used to check the status of RFC 5001 managed
trust anchors, or to force trust anchors to be refreshed. trust anchors, or to force trust anchors to be refreshed.
- "max-cache-size" can now be set to a percentage of available memory. The - "max-cache-size" can now be set to a percentage of available memory. The
default is 90%. default is 90%.
+16 -26
View File
@@ -5,28 +5,16 @@ Supported platforms
In general, this version of BIND will build and run on any POSIX-compliant In general, this version of BIND will build and run on any POSIX-compliant
system with a C11-compliant C compiler, BSD-style sockets with system with a C11-compliant C compiler, BSD-style sockets with
RFC-compliant IPv6 support, POSIX-compliant threads, the libuv RFC-compliant IPv6 support, POSIX-compliant threads, the libuv
asynchronous I/O library, and the OpenSSL cryptography library. asynchronous I/O library, and the OpenSSL cryptography library. Atomic
operations support from the compiler is needed, either in the form of
builtin operations, C11 atomics, or the Interlocked family of functions on
Windows.
The following C11 features are used in BIND 9: BIND 9.15 requires fairly recent version of libuv library to run (>= 1.x).
For some of the older systems listed below, you will have to install
* Atomic operations support from the compiler is needed, either in the updated libuv package from sources such as EPEL, PPA and other native
form of builtin operations, C11 atomics, or the Interlocked family of sources for updated packages. The other option is to install libuv from
functions on Windows. sources.
* Thread Local Storage support from the compiler is needed, either in
the form of C11 _Thread_local/thread_local, the __thread GCC
extension, or the __declspec(thread) MSVC extension on Windows.
BIND 9.15 requires a fairly recent version of libuv (at least 1.x). For
some of the older systems listed below, you will have to install an
updated libuv package from sources such as EPEL, PPA, or other native
sources for updated packages. The other option is to build and install
libuv from source.
Certain optional BIND features have additional library dependencies. These
include libxml2 and libjson-c for statistics, libmaxminddb for
geolocation, libfstrm and libprotobuf-c for DNSTAP, and libidn2 for
internationalized domain name conversion.
ISC regularly tests BIND on many operating systems and architectures, but ISC regularly tests BIND on many operating systems and architectures, but
lacks the resources to test all of them. Consequently, ISC is only able to lacks the resources to test all of them. Consequently, ISC is only able to
@@ -39,7 +27,7 @@ following systems:
* Debian 9, 10 * Debian 9, 10
* Ubuntu LTS 16.04, 18.04 * Ubuntu LTS 16.04, 18.04
* Fedora 31 * Fedora 30
* Red Hat Enterprise Linux / CentOS 7, 8 * Red Hat Enterprise Linux / CentOS 7, 8
* FreeBSD 11.3, 12.0 * FreeBSD 11.3, 12.0
* OpenBSD 6.5 * OpenBSD 6.5
@@ -70,10 +58,10 @@ Server 2012 R2, none of these are tested regularly by ISC.
Community maintained Community maintained
These systems may not all have the required dependencies for building BIND These systems may not all have easily available the required dependencies
easily available, although it will be possible in many cases to compile for building BIND although it will be possible in many cases to compile
those directly from source. The community and interested parties may wish those directly from source. The community and interested parties may wish
to help with maintenance, and we welcome patch contributions, although we to help with maintenance and we welcome patch contributions, although we
cannot guarantee that we will accept them. All contributions will be cannot guarantee that we will accept them. All contributions will be
assessed against the risk of adverse effect on officially supported assessed against the risk of adverse effect on officially supported
platforms. platforms.
@@ -96,4 +84,6 @@ These are platforms on which BIND 9.15 is known not to build or run:
* Platforms that don't support atomic operations (via compiler or * Platforms that don't support atomic operations (via compiler or
library) library)
* Linux without NPTL (Native POSIX Thread Library) * Linux without NPTL (Native POSIX Thread Library)
* Platforms on which libuv cannot be compiled * Platforms where libuv cannot be compiled
Platform quirks
+17 -30
View File
@@ -13,28 +13,14 @@
In general, this version of BIND will build and run on any POSIX-compliant In general, this version of BIND will build and run on any POSIX-compliant
system with a C11-compliant C compiler, BSD-style sockets with RFC-compliant system with a C11-compliant C compiler, BSD-style sockets with RFC-compliant
IPv6 support, POSIX-compliant threads, the `libuv` asynchronous I/O library, IPv6 support, POSIX-compliant threads, the `libuv` asynchronous I/O library,
and the OpenSSL cryptography library. and the OpenSSL cryptography library. Atomic operations support from the
compiler is needed, either in the form of builtin operations, C11 atomics,
or the `Interlocked` family of functions on Windows.
The following C11 features are used in BIND 9: BIND 9.15 requires fairly recent version of libuv library to run (>= 1.x). For
some of the older systems listed below, you will have to install updated libuv
* Atomic operations support from the compiler is needed, either in the form of package from sources such as EPEL, PPA and other native sources for updated
builtin operations, C11 atomics, or the `Interlocked` family of functions on packages. The other option is to install libuv from sources.
Windows.
* Thread Local Storage support from the compiler is needed, either in the form
of C11 `_Thread_local`/`thread_local`, the `__thread` GCC extension, or
the `__declspec(thread)` MSVC extension on Windows.
BIND 9.15 requires a fairly recent version of `libuv` (at least 1.x). For
some of the older systems listed below, you will have to install an updated
`libuv` package from sources such as EPEL, PPA, or other native sources for
updated packages. The other option is to build and install `libuv` from
source.
Certain optional BIND features have additional library dependencies.
These include `libxml2` and `libjson-c` for statistics, `libmaxminddb` for
geolocation, `libfstrm` and `libprotobuf-c` for DNSTAP, and `libidn2` for
internationalized domain name conversion.
ISC regularly tests BIND on many operating systems and architectures, but ISC regularly tests BIND on many operating systems and architectures, but
lacks the resources to test all of them. Consequently, ISC is only able to lacks the resources to test all of them. Consequently, ISC is only able to
@@ -47,7 +33,7 @@ following systems:
* Debian 9, 10 * Debian 9, 10
* Ubuntu LTS 16.04, 18.04 * Ubuntu LTS 16.04, 18.04
* Fedora 31 * Fedora 30
* Red Hat Enterprise Linux / CentOS 7, 8 * Red Hat Enterprise Linux / CentOS 7, 8
* FreeBSD 11.3, 12.0 * FreeBSD 11.3, 12.0
* OpenBSD 6.5 * OpenBSD 6.5
@@ -77,13 +63,12 @@ Server 2012 R2, none of these are tested regularly by ISC.
### Community maintained ### Community maintained
These systems may not all have the required dependencies for building BIND These systems may not all have easily available the required dependencies for
easily available, although it will be possible in many cases to compile building BIND although it will be possible in many cases to compile those
those directly from source. The community and interested parties may wish directly from source. The community and interested parties may wish to help with
to help with maintenance, and we welcome patch contributions, although we maintenance and we welcome patch contributions, although we cannot guarantee
cannot guarantee that we will accept them. All contributions will be that we will accept them. All contributions will be assessed against the risk
assessed against the risk of adverse effect on officially supported of adverse effect on officially supported platforms.
platforms.
* Platforms past or close to their respective EOL dates, such as: * Platforms past or close to their respective EOL dates, such as:
* Ubuntu 14.04, 18.10 * Ubuntu 14.04, 18.10
@@ -102,4 +87,6 @@ These are platforms on which BIND 9.15 is known *not* to build or run:
* Platforms that don't support IPv6 Advanced Socket API (RFC 3542) * Platforms that don't support IPv6 Advanced Socket API (RFC 3542)
* Platforms that don't support atomic operations (via compiler or library) * Platforms that don't support atomic operations (via compiler or library)
* Linux without NPTL (Native POSIX Thread Library) * Linux without NPTL (Native POSIX Thread Library)
* Platforms on which `libuv` cannot be compiled * Platforms where libuv cannot be compiled
## Platform quirks
+12 -13
View File
@@ -111,13 +111,13 @@ BIND 9.15 features
BIND 9.15 is the newest development branch of BIND 9. It includes a number BIND 9.15 is the newest development branch of BIND 9. It includes a number
of changes from BIND 9.14 and earlier releases. New features include: of changes from BIND 9.14 and earlier releases. New features include:
* New dnssec-policy statement to configure a key and signing policy for * New "dnssec-policy" statement to configure a key and signing policy
zones, enabling automatic key regeneration and rollover. for zones, enabling automatic key regeneration and rollover.
* New network manager based on libuv. * New new network manager based on libuv.
* Added support for the new GeoIP2 geolocation API, libmaxminddb. * Support for the new GeoIP2 geolocation API
* Improved DNSSEC trust anchor configuration using the trust-anchors * Improved DNSSEC trust anchor configuration using dnssec-keys,
statement, permitting configuration of trust anchors in DS as well as permitting configuration of trust anchors in DS as well as DNSKEY
DNSKEY format. format.
* YAML output for dig, mdig, and delv. * YAML output for dig, mdig, and delv.
Building BIND Building BIND
@@ -136,8 +136,8 @@ including RHEL/CentOS, Fedora, Debian, Ubuntu, SLES, openSUSE, Slackware,
Alpine, FreeBSD, NetBSD, OpenBSD, macOS, Solaris, OpenIndiana, OmniOS CE, Alpine, FreeBSD, NetBSD, OpenBSD, macOS, Solaris, OpenIndiana, OmniOS CE,
HP-UX, and OpenWRT. HP-UX, and OpenWRT.
BIND is also available for Windows Server 2012 R2 and higher. See BIND is also available for Windows Server 2008 and higher. See win32utils/
win32utils/build.txt for details on building for Windows systems. build.txt for details on building for Windows systems.
To build on a UNIX or Linux system, use: To build on a UNIX or Linux system, use:
@@ -180,10 +180,9 @@ Dependencies
Portions of BIND that are written in Python, including dnssec-keymgr, Portions of BIND that are written in Python, including dnssec-keymgr,
dnssec-coverage, dnssec-checkds, and some of the system tests, require the dnssec-coverage, dnssec-checkds, and some of the system tests, require the
argparse, ply and distutils.core modules to be available. argparse is a argparse and ply modules to be available. argparse is a standard module as
standard module as of Python 2.7 and Python 3.2. ply is available from of Python 2.7 and Python 3.2. ply is available from https://
https://pypi.python.org/pypi/ply. distutils.core is required for pypi.python.org/pypi/ply.
installation.
Compile-time options Compile-time options
+6 -6
View File
@@ -127,12 +127,12 @@ BIND 9.15 is the newest development branch of BIND 9. It includes a
number of changes from BIND 9.14 and earlier releases. New features number of changes from BIND 9.14 and earlier releases. New features
include: include:
* New `dnssec-policy` statement to configure a key and signing policy * New "dnssec-policy" statement to configure a key and signing policy
for zones, enabling automatic key regeneration and rollover. for zones, enabling automatic key regeneration and rollover.
* New network manager based on libuv. * New new network manager based on libuv.
* Added support for the new GeoIP2 geolocation API, `libmaxminddb`. * Support for the new GeoIP2 geolocation API
* Improved DNSSEC trust anchor configuration using the `trust-anchors` * Improved DNSSEC trust anchor configuration using `dnssec-keys`,
statement, permitting configuration of trust anchors in DS as well as permitting configuration of trust anchors in DS as well as
DNSKEY format. DNSKEY format.
* YAML output for `dig`, `mdig`, and `delv`. * YAML output for `dig`, `mdig`, and `delv`.
@@ -153,7 +153,7 @@ UNIX, including RHEL/CentOS, Fedora, Debian, Ubuntu, SLES, openSUSE,
Slackware, Alpine, FreeBSD, NetBSD, OpenBSD, macOS, Solaris, Slackware, Alpine, FreeBSD, NetBSD, OpenBSD, macOS, Solaris,
OpenIndiana, OmniOS CE, HP-UX, and OpenWRT. OpenIndiana, OmniOS CE, HP-UX, and OpenWRT.
BIND is also available for Windows Server 2012 R2 and higher. See BIND is also available for Windows Server 2008 and higher. See
`win32utils/build.txt` for details on building for Windows `win32utils/build.txt` for details on building for Windows
systems. systems.
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2000-2002, 2004, 2005, 2007, 2009, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2000-2002, 2004, 2005, 2007, 2009, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -148,5 +148,5 @@ BIND 9 Administrator Reference Manual\&.
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2000-2002, 2004, 2005, 2007, 2009, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2000-2002, 2004, 2005, 2007, 2009, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
+2
View File
@@ -709,6 +709,8 @@ main(int argc, char **argv) {
cfg_parser_destroy(&parser); cfg_parser_destroy(&parser);
dns_name_destroy();
isc_log_destroy(&logc); isc_log_destroy(&logc);
isc_mem_destroy(&mctx); isc_mem_destroy(&mctx);
-1
View File
@@ -41,7 +41,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2000-2002, 2004, 2005, 2007, 2009, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2000-2002, 2004, 2005, 2007, 2009, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2000-2002, 2004-2007, 2009-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2000-2002, 2004-2007, 2009-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -325,5 +325,5 @@ BIND 9 Administrator Reference Manual\&.
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2000-2002, 2004-2007, 2009-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2000-2002, 2004-2007, 2009-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
+2 -2
View File
@@ -85,9 +85,9 @@ usage(void) {
static void static void
destroy(void) { destroy(void) {
if (zone != NULL) { if (zone != NULL)
dns_zone_detach(&zone); dns_zone_detach(&zone);
} dns_name_destroy();
} }
/*% main processing routine */ /*% main processing routine */
-1
View File
@@ -44,7 +44,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2000-2002, 2004-2007, 2009-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2000-2002, 2004-2007, 2009-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2009, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2009, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -144,5 +144,5 @@ BIND 9 Administrator Reference Manual\&.
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2009, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2009, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
-1
View File
@@ -38,7 +38,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2009, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2009, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -206,5 +206,5 @@ BIND 9 Administrator Reference Manual\&.
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2001, 2003-2005, 2007, 2009, 2013-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2001, 2003-2005, 2007, 2009, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
-1
View File
@@ -45,7 +45,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
+3 -3
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2014-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2014-2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -144,7 +144,7 @@ options\&.
Note: When reading the trust anchor file, Note: When reading the trust anchor file,
\fBdelv\fR \fBdelv\fR
treats treats
\fBtrust\-anchors\fR\fBinitial\-key\fR \fBdnssec\-keys\fR\fBinitial\-key\fR
and and
\fBstatic\-key\fR \fBstatic\-key\fR
entries identically\&. That is, even if a key is configured with entries identically\&. That is, even if a key is configured with
@@ -433,5 +433,5 @@ RFC5155\&.
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2014-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2014-2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
+22 -23
View File
@@ -140,7 +140,7 @@ static dns_fixedname_t afn;
static dns_name_t *anchor_name = NULL; static dns_name_t *anchor_name = NULL;
/* Default bind.keys contents */ /* Default bind.keys contents */
static char anchortext[] = TRUST_ANCHORS; static char anchortext[] = DNSSEC_KEYS;
/* /*
* Static function prototypes * Static function prototypes
@@ -498,17 +498,14 @@ printdata(dns_rdataset_t *rdataset, dns_name_t *owner,
dns_rdata_reset(&rdata); dns_rdata_reset(&rdata);
} }
} else { } else {
dns_indent_t indent = { " ", 2 };
if (!yaml && (rdataset->attributes & if (!yaml && (rdataset->attributes &
DNS_RDATASETATTR_NEGATIVE) != 0) DNS_RDATASETATTR_NEGATIVE) != 0)
{ {
isc_buffer_putstr(&target, "; "); isc_buffer_putstr(&target, "; ");
} }
result = dns_master_rdatasettotext(owner, rdataset, result = dns_master_rdatasettotext(owner, rdataset,
style, style, &target);
yaml ? &indent :
NULL,
&target);
} }
if (result == ISC_R_NOSPACE) { if (result == ISC_R_NOSPACE) {
@@ -540,6 +537,8 @@ setup_style(dns_master_style_t **stylep) {
styleflags |= DNS_STYLEFLAG_REL_OWNER; styleflags |= DNS_STYLEFLAG_REL_OWNER;
if (yaml) { if (yaml) {
styleflags |= DNS_STYLEFLAG_YAML; styleflags |= DNS_STYLEFLAG_YAML;
dns_master_indentstr = " ";
dns_master_indent = 2;
} else { } else {
if (showcomments) { if (showcomments) {
styleflags |= DNS_STYLEFLAG_COMMENT; styleflags |= DNS_STYLEFLAG_COMMENT;
@@ -614,7 +613,7 @@ static isc_result_t
key_fromconfig(const cfg_obj_t *key, dns_client_t *client) { key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
dns_rdata_dnskey_t dnskey; dns_rdata_dnskey_t dnskey;
dns_rdata_ds_t ds; dns_rdata_ds_t ds;
uint32_t rdata1, rdata2, rdata3; uint32_t n1, n2, n3;
const char *datastr = NULL, *keynamestr = NULL, *atstr = NULL; const char *datastr = NULL, *keynamestr = NULL, *atstr = NULL;
unsigned char data[4096]; unsigned char data[4096];
isc_buffer_t databuf; isc_buffer_t databuf;
@@ -655,13 +654,13 @@ key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
delv_log(ISC_LOG_DEBUG(3), "adding trust anchor %s", trust_anchor); delv_log(ISC_LOG_DEBUG(3), "adding trust anchor %s", trust_anchor);
/* if DNSKEY, flags; if DS, key tag */ /* if DNSKEY, flags; if DS, key tag */
rdata1 = cfg_obj_asuint32(cfg_tuple_get(key, "rdata1")); n1 = cfg_obj_asuint32(cfg_tuple_get(key, "n1"));
/* if DNSKEY, protocol; if DS, algorithm */ /* if DNSKEY, protocol; if DS, algorithm */
rdata2 = cfg_obj_asuint32(cfg_tuple_get(key, "rdata2")); n2 = cfg_obj_asuint32(cfg_tuple_get(key, "n2"));
/* if DNSKEY, algorithm; if DS, digest type */ /* if DNSKEY, algorithm; if DS, digest type */
rdata3 = cfg_obj_asuint32(cfg_tuple_get(key, "rdata3")); n3 = cfg_obj_asuint32(cfg_tuple_get(key, "n3"));
/* What type of trust anchor is this? */ /* What type of trust anchor is this? */
atstr = cfg_obj_asstring(cfg_tuple_get(key, "anchortype")); atstr = cfg_obj_asstring(cfg_tuple_get(key, "anchortype"));
@@ -684,13 +683,13 @@ key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
isc_buffer_init(&databuf, data, sizeof(data)); isc_buffer_init(&databuf, data, sizeof(data));
isc_buffer_init(&rrdatabuf, rrdata, sizeof(rrdata)); isc_buffer_init(&rrdatabuf, rrdata, sizeof(rrdata));
if (rdata1 > 0xffff) { if (n1 > 0xffff) {
CHECK(ISC_R_RANGE); CHECK(ISC_R_RANGE);
} }
if (rdata2 > 0xff) { if (n2 > 0xff) {
CHECK(ISC_R_RANGE); CHECK(ISC_R_RANGE);
} }
if (rdata3 > 0xff) { if (n3 > 0xff) {
CHECK(ISC_R_RANGE); CHECK(ISC_R_RANGE);
} }
@@ -704,9 +703,9 @@ key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
ISC_LINK_INIT(&dnskey.common, link); ISC_LINK_INIT(&dnskey.common, link);
dnskey.flags = (uint16_t)rdata1; dnskey.flags = (uint16_t)n1;
dnskey.protocol = (uint8_t)rdata2; dnskey.protocol = (uint8_t)n2;
dnskey.algorithm = (uint8_t)rdata3; dnskey.algorithm = (uint8_t)n3;
datastr = cfg_obj_asstring(cfg_tuple_get(key, "data")); datastr = cfg_obj_asstring(cfg_tuple_get(key, "data"));
CHECK(isc_base64_decodestring(datastr, &databuf)); CHECK(isc_base64_decodestring(datastr, &databuf));
@@ -729,9 +728,9 @@ key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
ISC_LINK_INIT(&ds.common, link); ISC_LINK_INIT(&ds.common, link);
ds.key_tag = (uint16_t)rdata1; ds.key_tag = (uint16_t)n1;
ds.algorithm = (uint8_t)rdata2; ds.algorithm = (uint8_t)n2;
ds.digest_type = (uint8_t)rdata3; ds.digest_type = (uint8_t)n3;
datastr = cfg_obj_asstring(cfg_tuple_get(key, "data")); datastr = cfg_obj_asstring(cfg_tuple_get(key, "data"));
CHECK(isc_hex_decodestring(datastr, &databuf)); CHECK(isc_hex_decodestring(datastr, &databuf));
@@ -819,7 +818,7 @@ setup_dnsseckeys(dns_client_t *client) {
cfg_parser_t *parser = NULL; cfg_parser_t *parser = NULL;
const cfg_obj_t *trusted_keys = NULL; const cfg_obj_t *trusted_keys = NULL;
const cfg_obj_t *managed_keys = NULL; const cfg_obj_t *managed_keys = NULL;
const cfg_obj_t *trust_anchors = NULL; const cfg_obj_t *dnssec_keys = NULL;
cfg_obj_t *bindkeys = NULL; cfg_obj_t *bindkeys = NULL;
const char *filename = anchorfile; const char *filename = anchorfile;
@@ -878,7 +877,7 @@ setup_dnsseckeys(dns_client_t *client) {
INSIST(bindkeys != NULL); INSIST(bindkeys != NULL);
cfg_map_get(bindkeys, "trusted-keys", &trusted_keys); cfg_map_get(bindkeys, "trusted-keys", &trusted_keys);
cfg_map_get(bindkeys, "managed-keys", &managed_keys); cfg_map_get(bindkeys, "managed-keys", &managed_keys);
cfg_map_get(bindkeys, "trust-anchors", &trust_anchors); cfg_map_get(bindkeys, "dnssec-keys", &dnssec_keys);
if (trusted_keys != NULL) { if (trusted_keys != NULL) {
CHECK(load_keys(trusted_keys, client)); CHECK(load_keys(trusted_keys, client));
@@ -886,8 +885,8 @@ setup_dnsseckeys(dns_client_t *client) {
if (managed_keys != NULL) { if (managed_keys != NULL) {
CHECK(load_keys(managed_keys, client)); CHECK(load_keys(managed_keys, client));
} }
if (trust_anchors != NULL) { if (dnssec_keys != NULL) {
CHECK(load_keys(trust_anchors, client)); CHECK(load_keys(dnssec_keys, client));
} }
result = ISC_R_SUCCESS; result = ISC_R_SUCCESS;
+1 -2
View File
@@ -40,7 +40,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
@@ -216,7 +215,7 @@
</para> </para>
<para> <para>
Note: When reading the trust anchor file, Note: When reading the trust anchor file,
<command>delv</command> treats <option>trust-anchors</option> <command>delv</command> treats <option>dnssec-keys</option>
<option>initial-key</option> and <option>static-key</option> <option>initial-key</option> and <option>static-key</option>
entries identically. That is, even if a key is configured entries identically. That is, even if a key is configured
with <command>initial-key</command>, indicating that it is with <command>initial-key</command>, indicating that it is
+2 -2
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2014-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2014-2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -197,7 +197,7 @@
</p> </p>
<p> <p>
Note: When reading the trust anchor file, Note: When reading the trust anchor file,
<span class="command"><strong>delv</strong></span> treats <code class="option">trust-anchors</code> <span class="command"><strong>delv</strong></span> treats <code class="option">dnssec-keys</code>
<code class="option">initial-key</code> and <code class="option">static-key</code> <code class="option">initial-key</code> and <code class="option">static-key</code>
entries identically. That is, even if a key is configured entries identically. That is, even if a key is configured
with <span class="command"><strong>initial-key</strong></span>, indicating that it is with <span class="command"><strong>initial-key</strong></span>, indicating that it is
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2000-2011, 2013-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2000-2011, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -849,5 +849,5 @@ There are probably too many query options\&.
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2000-2011, 2013-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2000-2011, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
+15 -18
View File
@@ -54,7 +54,7 @@
dig_lookup_t *default_lookup = NULL; dig_lookup_t *default_lookup = NULL;
static atomic_uintptr_t batchname = ATOMIC_VAR_INIT(0); static char *batchname = NULL;
static FILE *batchfp = NULL; static FILE *batchfp = NULL;
static char *argv0; static char *argv0;
static int addresscount = 0; static int addresscount = 0;
@@ -487,8 +487,8 @@ printmessage(dig_query_t *query, const isc_buffer_t *msgbuf,
styleflags |= DNS_STYLEFLAG_REL_OWNER; styleflags |= DNS_STYLEFLAG_REL_OWNER;
if (yaml) { if (yaml) {
msg->indent.string = " "; dns_master_indentstr = " ";
msg->indent.count = 3; dns_master_indent = 3;
styleflags |= DNS_STYLEFLAG_YAML; styleflags |= DNS_STYLEFLAG_YAML;
} else { } else {
if (query->lookup->comments) { if (query->lookup->comments) {
@@ -1874,7 +1874,7 @@ dash_option(char *option, char *next, dig_lookup_t **lookup,
value); value);
return (value_from_next); return (value_from_next);
case 'f': case 'f':
atomic_store(&batchname, (uintptr_t)value); batchname = value;
return (value_from_next); return (value_from_next);
case 'k': case 'k':
strlcpy(keyfile, value, sizeof(keyfile)); strlcpy(keyfile, value, sizeof(keyfile));
@@ -2327,15 +2327,13 @@ parse_args(bool is_batchfile, bool config_only,
* first entry, then trust the callback in dighost_shutdown * first entry, then trust the callback in dighost_shutdown
* to get the rest * to get the rest
*/ */
char *filename = (char *)atomic_load(&batchname); if ((batchname != NULL) && !(is_batchfile)) {
if ((filename != NULL) && !(is_batchfile)) { if (strcmp(batchname, "-") == 0)
if (strcmp(filename, "-") == 0) {
batchfp = stdin; batchfp = stdin;
} else { else
batchfp = fopen(filename, "r"); batchfp = fopen(batchname, "r");
}
if (batchfp == NULL) { if (batchfp == NULL) {
perror(filename); perror(batchname);
if (exitcode < 8) if (exitcode < 8)
exitcode = 8; exitcode = 8;
fatal("couldn't open specified batch file"); fatal("couldn't open specified batch file");
@@ -2390,14 +2388,14 @@ query_finished(void) {
int bargc; int bargc;
char *bargv[16]; char *bargv[16];
if (atomic_load(&batchname) == 0) { if (batchname == NULL) {
isc_app_shutdown(); isc_app_shutdown();
return; return;
} }
fflush(stdout); fflush(stdout);
if (feof(batchfp)) { if (feof(batchfp)) {
atomic_store(&batchname, 0); batchname = NULL;
isc_app_shutdown(); isc_app_shutdown();
if (batchfp != stdin) if (batchfp != stdin)
fclose(batchfp); fclose(batchfp);
@@ -2411,7 +2409,7 @@ query_finished(void) {
parse_args(true, false, bargc, (char **)bargv); parse_args(true, false, bargc, (char **)bargv);
start_lookup(); start_lookup();
} else { } else {
atomic_store(&batchname, 0); batchname = NULL;
if (batchfp != stdin) if (batchfp != stdin)
fclose(batchfp); fclose(batchfp);
isc_app_shutdown(); isc_app_shutdown();
@@ -2541,11 +2539,10 @@ void dig_query_start()
void void
dig_shutdown() { dig_shutdown() {
destroy_lookup(default_lookup); destroy_lookup(default_lookup);
if (atomic_load(&batchname) != 0) { if (batchname != NULL) {
if (batchfp != stdin) { if (batchfp != stdin)
fclose(batchfp); fclose(batchfp);
} batchname = NULL;
atomic_store(&batchname, 0);
} }
cancel_all(); cancel_all();
destroy_libs(); destroy_libs();
-1
View File
@@ -53,7 +53,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2000-2011, 2013-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2000-2011, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
+1
View File
@@ -4252,6 +4252,7 @@ destroy_libs(void) {
result = dns_name_settotextfilter(NULL); result = dns_name_settotextfilter(NULL);
check_result(result, "dns_name_settotextfilter"); check_result(result, "dns_name_settotextfilter");
#endif /* HAVE_LIBIDN2 */ #endif /* HAVE_LIBIDN2 */
dns_name_destroy();
if (commctx != NULL) { if (commctx != NULL) {
debug("freeing commctx"); debug("freeing commctx");
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2000-2002, 2004, 2005, 2007-2009, 2014-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2000-2002, 2004, 2005, 2007-2009, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -269,5 +269,5 @@ runs\&.
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2000-2002, 2004, 2005, 2007-2009, 2014-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2000-2002, 2004, 2005, 2007-2009, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
-1
View File
@@ -48,7 +48,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2000-2002, 2004, 2005, 2007-2009, 2014-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2000-2002, 2004, 2005, 2007-2009, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2004-2007, 2010, 2013-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2004-2007, 2010, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -301,5 +301,5 @@ runs or when the standard output is not a tty\&.
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2004-2007, 2010, 2013-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2004-2007, 2010, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
+22 -29
View File
@@ -72,7 +72,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
@@ -308,7 +307,7 @@ nslookup -query=hinfo -timeout=10
The class specifies the protocol group of the information. The class specifies the protocol group of the information.
</para> </para>
<para> <para>
(Default = IN; abbreviation = cl) (Default = IN; abbreviation = cl)
</para> </para>
</listitem> </listitem>
@@ -318,10 +317,10 @@ nslookup -query=hinfo -timeout=10
<term><constant><replaceable><optional>no</optional></replaceable>debug</constant></term> <term><constant><replaceable><optional>no</optional></replaceable>debug</constant></term>
<listitem> <listitem>
<para> <para>
Turn on or off the display of the full response packet and Turn on or off the display of the full response packet and
any intermediate response packets when searching. any intermediate response packets when searching.
</para> </para>
<para> <para>
(Default = nodebug; abbreviation = <optional>no</optional>deb) (Default = nodebug; abbreviation = <optional>no</optional>deb)
</para> </para>
</listitem> </listitem>
@@ -332,9 +331,9 @@ nslookup -query=hinfo -timeout=10
<listitem> <listitem>
<para> <para>
Turn debugging mode on or off. This displays more about Turn debugging mode on or off. This displays more about
what nslookup is doing. what nslookup is doing.
</para> </para>
<para> <para>
(Default = nod2) (Default = nod2)
</para> </para>
</listitem> </listitem>
@@ -358,7 +357,7 @@ nslookup -query=hinfo -timeout=10
names in the domain search list to the request until an names in the domain search list to the request until an
answer is received. answer is received.
</para> </para>
<para> <para>
(Default = search) (Default = search)
</para> </para>
</listitem> </listitem>
@@ -370,7 +369,7 @@ nslookup -query=hinfo -timeout=10
<para> <para>
Change the default TCP/UDP name server port to <replaceable>value</replaceable>. Change the default TCP/UDP name server port to <replaceable>value</replaceable>.
</para> </para>
<para> <para>
(Default = 53; abbreviation = po) (Default = 53; abbreviation = po)
</para> </para>
</listitem> </listitem>
@@ -389,15 +388,9 @@ nslookup -query=hinfo -timeout=10
<para> <para>
Change the type of the information query. Change the type of the information query.
</para> </para>
<para> <para>
(Default = A and then AAAA; abbreviations = q, ty) (Default = A; abbreviations = q, ty)
</para> </para>
<para>
<emphasis role="bold">Note:</emphasis> It is
only possible to specify one query type, only
the default behavior looks up both when an
alternative is not specified.
</para>
</listitem> </listitem>
</varlistentry> </varlistentry>
@@ -409,7 +402,7 @@ nslookup -query=hinfo -timeout=10
have the have the
information. information.
</para> </para>
<para> <para>
(Default = recurse; abbreviation = [no]rec) (Default = recurse; abbreviation = [no]rec)
</para> </para>
</listitem> </listitem>
@@ -419,9 +412,9 @@ nslookup -query=hinfo -timeout=10
<term><constant>ndots=</constant><replaceable>number</replaceable></term> <term><constant>ndots=</constant><replaceable>number</replaceable></term>
<listitem> <listitem>
<para> <para>
Set the number of dots (label separators) in a domain Set the number of dots (label separators) in a domain
that will disable searching. Absolute names always that will disable searching. Absolute names always
stop searching. stop searching.
</para> </para>
</listitem> </listitem>
</varlistentry> </varlistentry>
@@ -452,7 +445,7 @@ nslookup -query=hinfo -timeout=10
Always use a virtual circuit when sending requests to the Always use a virtual circuit when sending requests to the
server. server.
</para> </para>
<para> <para>
(Default = novc) (Default = novc)
</para> </para>
</listitem> </listitem>
@@ -462,15 +455,15 @@ nslookup -query=hinfo -timeout=10
<term><constant><replaceable><optional>no</optional></replaceable>fail</constant></term> <term><constant><replaceable><optional>no</optional></replaceable>fail</constant></term>
<listitem> <listitem>
<para> <para>
Try the next nameserver if a nameserver responds with Try the next nameserver if a nameserver responds with
SERVFAIL or a referral (nofail) or terminate query SERVFAIL or a referral (nofail) or terminate query
(fail) on such a response. (fail) on such a response.
</para> </para>
<para> <para>
(Default = nofail) (Default = nofail)
</para> </para>
</listitem> </listitem>
</varlistentry> </varlistentry>
</variablelist> </variablelist>
</para> </para>
+1 -1
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2004-2007, 2010, 2013-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2004-2007, 2010, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2017-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2017-2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -293,5 +293,5 @@ RFC 7344\&.
.RE .RE
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2017-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2017-2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
+1 -1
View File
@@ -372,7 +372,7 @@ formatset(dns_rdataset_t *rdataset) {
result = isc_buffer_allocate(mctx, &buf, MAX_CDS_RDATA_TEXT_SIZE); result = isc_buffer_allocate(mctx, &buf, MAX_CDS_RDATA_TEXT_SIZE);
check_result(result, "printing DS records"); check_result(result, "printing DS records");
result = dns_master_rdatasettotext(name, rdataset, style, NULL, buf); result = dns_master_rdatasettotext(name, rdataset, style, buf);
if ((result == ISC_R_SUCCESS) && isc_buffer_availablelength(buf) < 1) { if ((result == ISC_R_SUCCESS) && isc_buffer_availablelength(buf) < 1) {
result = ISC_R_NOSPACE; result = ISC_R_NOSPACE;
-1
View File
@@ -41,7 +41,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2017-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2017-2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2008-2012, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2008-2012, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -222,5 +222,5 @@ RFC 7344
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2008-2012, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2008-2012, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
+1
View File
@@ -517,6 +517,7 @@ main(int argc, char **argv) {
} }
cleanup_logging(&log); cleanup_logging(&log);
dst_lib_destroy(); dst_lib_destroy();
dns_name_destroy();
if (verbose > 10) { if (verbose > 10) {
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
} }
-1
View File
@@ -42,7 +42,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2008-2012, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2008-2012, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2013-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2013-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -134,5 +134,5 @@ RFC 5011\&.
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2013-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2013-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
+1
View File
@@ -439,6 +439,7 @@ main(int argc, char **argv) {
dns_rdataset_disassociate(&rdataset); dns_rdataset_disassociate(&rdataset);
cleanup_logging(&log); cleanup_logging(&log);
dst_lib_destroy(); dst_lib_destroy();
dns_name_destroy();
if (verbose > 10) if (verbose > 10)
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
isc_mem_destroy(&mctx); isc_mem_destroy(&mctx);
-1
View File
@@ -39,7 +39,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2013-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2013-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2008-2012, 2014-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2008-2012, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -307,5 +307,5 @@ The PKCS#11 URI Scheme (draft\-pechanec\-pkcs11uri\-13)\&.
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2008-2012, 2014-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2008-2012, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
+1
View File
@@ -694,6 +694,7 @@ main(int argc, char **argv) {
cleanup_logging(&log); cleanup_logging(&log);
dst_lib_destroy(); dst_lib_destroy();
dns_name_destroy();
if (verbose > 10) if (verbose > 10)
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
isc_mem_free(mctx, label); isc_mem_free(mctx, label);
-1
View File
@@ -44,7 +44,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2008-2012, 2014-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2008-2012, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2000-2005, 2007-2012, 2014-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2000-2005, 2007-2012, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -374,5 +374,5 @@ RFC 4034\&.
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2000-2005, 2007-2012, 2014-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2000-2005, 2007-2012, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
+1
View File
@@ -1222,6 +1222,7 @@ main(int argc, char **argv) {
cleanup_logging(&log); cleanup_logging(&log);
dst_lib_destroy(); dst_lib_destroy();
dns_name_destroy();
if (verbose > 10) if (verbose > 10)
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
isc_mem_destroy(&mctx); isc_mem_destroy(&mctx);
-1
View File
@@ -51,7 +51,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2000-2005, 2007-2012, 2014-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2000-2005, 2007-2012, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2009, 2011, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2009, 2011, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -99,5 +99,5 @@ RFC 5011\&.
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2009, 2011, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2009, 2011, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
-1
View File
@@ -39,7 +39,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2009, 2011, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2009, 2011, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2009-2011, 2014-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2009-2011, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -251,5 +251,5 @@ RFC 5011\&.
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2009-2011, 2014-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2009-2011, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
-1
View File
@@ -41,7 +41,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2009-2011, 2014-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2009-2011, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2000-2009, 2011-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2000-2009, 2011-2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -470,5 +470,5 @@ RFC 4641\&.
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2000-2009, 2011-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2000-2009, 2011-2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
+2 -2
View File
@@ -246,8 +246,7 @@ dumpnode(dns_name_t *name, dns_dbnode_t *node) {
for (;;) { for (;;) {
result = dns_master_rdatasettotext(name, &rds, result = dns_master_rdatasettotext(name, &rds,
masterstyle, NULL, masterstyle, buffer);
buffer);
if (result != ISC_R_NOSPACE) if (result != ISC_R_NOSPACE)
break; break;
@@ -3922,6 +3921,7 @@ main(int argc, char *argv[]) {
cleanup_logging(&log); cleanup_logging(&log);
dst_lib_destroy(); dst_lib_destroy();
dns_name_destroy();
if (verbose > 10) if (verbose > 10)
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
isc_mem_destroy(&mctx); isc_mem_destroy(&mctx);
-1
View File
@@ -51,7 +51,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2000-2009, 2011-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2000-2009, 2011-2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2012, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2012, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -120,5 +120,5 @@ RFC 4033\&.
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2012, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2012, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
+1
View File
@@ -335,6 +335,7 @@ main(int argc, char *argv[]) {
cleanup_logging(&log); cleanup_logging(&log);
dst_lib_destroy(); dst_lib_destroy();
dns_name_destroy();
if (verbose > 10) if (verbose > 10)
isc_mem_stats(mctx, stdout); isc_mem_stats(mctx, stdout);
isc_mem_destroy(&mctx); isc_mem_destroy(&mctx);
-1
View File
@@ -38,7 +38,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2012, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2012, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
+5 -2
View File
@@ -296,7 +296,7 @@ view \"_bind\" chaos {\n\
# BEGIN DNSSEC KEYS\n" # BEGIN DNSSEC KEYS\n"
/* Imported from bind.keys.h: */ /* Imported from bind.keys.h: */
TRUST_ANCHORS DNSSEC_KEYS
"# END MANAGED KEYS\n\ "# END MANAGED KEYS\n\
\n\ \n\
@@ -800,7 +800,10 @@ named_config_getipandkeylist(const cfg_obj_t *config, const cfg_obj_t *list,
dns_rootname, 0, NULL); dns_rootname, 0, NULL);
if (result != ISC_R_SUCCESS) if (result != ISC_R_SUCCESS)
goto cleanup; goto cleanup;
dns_name_dup(dns_fixedname_name(&fname), mctx, keys[i - 1]); result = dns_name_dup(dns_fixedname_name(&fname), mctx,
keys[i - 1]);
if (result != ISC_R_SUCCESS)
goto cleanup;
} }
if (pushed != 0) { if (pushed != 0) {
pushed--; pushed--;
+4 -8
View File
@@ -113,7 +113,8 @@ named_geoip_load(char *dir) {
#endif #endif
} }
void named_geoip_unload(void) { void
named_geoip_shutdown(void) {
#ifdef HAVE_GEOIP2 #ifdef HAVE_GEOIP2
if (named_g_geoip->country != NULL) { if (named_g_geoip->country != NULL) {
MMDB_close(named_g_geoip->country); MMDB_close(named_g_geoip->country);
@@ -135,12 +136,7 @@ void named_geoip_unload(void) {
MMDB_close(named_g_geoip->domain); MMDB_close(named_g_geoip->domain);
named_g_geoip->domain = NULL; named_g_geoip->domain = NULL;
} }
#endif
}
void
named_geoip_shutdown(void) {
#ifdef HAVE_GEOIP2
named_geoip_unload();
#endif /* HAVE_GEOIP2 */ #endif /* HAVE_GEOIP2 */
dns_geoip_shutdown();
} }
-3
View File
@@ -19,8 +19,5 @@ named_geoip_init(void);
void void
named_geoip_load(char *dir); named_geoip_load(char *dir);
void
named_geoip_unload(void);
void void
named_geoip_shutdown(void); named_geoip_shutdown(void);
+11 -32
View File
@@ -23,7 +23,6 @@
#include <isc/dir.h> #include <isc/dir.h>
#include <isc/file.h> #include <isc/file.h>
#include <isc/hash.h> #include <isc/hash.h>
#include <isc/hp.h>
#include <isc/httpd.h> #include <isc/httpd.h>
#include <isc/netmgr.h> #include <isc/netmgr.h>
#include <isc/os.h> #include <isc/os.h>
@@ -60,10 +59,6 @@
#include <json_c_version.h> #include <json_c_version.h>
#endif /* HAVE_JSON_C */ #endif /* HAVE_JSON_C */
#ifdef HAVE_GEOIP2
#include <maxminddb.h>
#endif
/* /*
* Defining NAMED_MAIN provides storage declarations (rather than extern) * Defining NAMED_MAIN provides storage declarations (rather than extern)
* for variables in named/globals.h. * for variables in named/globals.h.
@@ -121,7 +116,7 @@ LIBDNS_EXTERNAL_DATA extern unsigned int dns_zone_mkey_month;
static bool want_stats = false; static bool want_stats = false;
static char program_name[NAME_MAX] = "named"; static char program_name[NAME_MAX] = "named";
static char absolute_conffile[PATH_MAX]; static char absolute_conffile[PATH_MAX];
static char saved_command_line[4096] = { 0 }; static char saved_command_line[8192] = { 0 };
static char ellipsis[5] = { 0 }; static char ellipsis[5] = { 0 };
static char version[512]; static char version[512];
static unsigned int maxsocks = 0; static unsigned int maxsocks = 0;
@@ -141,6 +136,7 @@ static bool nonearest = false;
static bool nosoa = false; static bool nosoa = false;
static bool notcp = false; static bool notcp = false;
static bool sigvalinsecs = false; static bool sigvalinsecs = false;
static unsigned int delay = 0;
/* /*
* -4 and -6 * -4 and -6
@@ -552,17 +548,6 @@ OPENSSL_VERSION_NUMBER >= 0x10100000L /* 1.1.0 or higher */
ZLIB_VERSION); ZLIB_VERSION);
printf("linked to zlib version: %s\n", printf("linked to zlib version: %s\n",
zlibVersion()); zlibVersion());
#endif
#if defined(HAVE_GEOIP2)
/* Unfortunately, no version define on link time */
printf("linked to maxminddb version: %s\n",
MMDB_lib_version());
#endif
#if defined(HAVE_DNSTAP)
printf("compiled with protobuf-c version: %s\n",
PROTOBUF_C_VERSION);
printf("linked to protobuf-c version: %s\n",
protobuf_c_version());
#endif #endif
printf("threads support is enabled\n\n"); printf("threads support is enabled\n\n");
@@ -637,10 +622,14 @@ parse_T_opt(char *option) {
/* /*
* force the server to behave (or misbehave) in * force the server to behave (or misbehave) in
* specified ways for testing purposes. * specified ways for testing purposes.
* delay=xxxx: delay client responses by xxxx ms to
* simulate remote servers.
* dscp=x: check that dscp values are as * dscp=x: check that dscp values are as
* expected and assert otherwise. * expected and assert otherwise.
*/ */
if (!strcmp(option, "dropedns")) { if (!strncmp(option, "delay=", 6)) {
delay = atoi(option + 6);
} else if (!strcmp(option, "dropedns")) {
dropedns = true; dropedns = true;
} else if (!strncmp(option, "dscp=", 5)) { } else if (!strncmp(option, "dscp=", 5)) {
isc_dscp_check_value = atoi(option + 5); isc_dscp_check_value = atoi(option + 5);
@@ -903,12 +892,6 @@ create_managers(void) {
"using %u UDP listener%s per interface", "using %u UDP listener%s per interface",
named_g_udpdisp, named_g_udpdisp == 1 ? "" : "s"); named_g_udpdisp, named_g_udpdisp == 1 ? "" : "s");
/*
* We have ncpus network threads, ncpus worker threads, ncpus
* old network threads - make it 4x just to be safe. The memory
* impact is neglible.
*/
isc_hp_init(4*named_g_cpus);
named_g_nm = isc_nm_start(named_g_mctx, named_g_cpus); named_g_nm = isc_nm_start(named_g_mctx, named_g_cpus);
if (named_g_nm == NULL) { if (named_g_nm == NULL) {
UNEXPECTED_ERROR(__FILE__, __LINE__, UNEXPECTED_ERROR(__FILE__, __LINE__,
@@ -1313,6 +1296,8 @@ setup(void) {
ns_server_setoption(sctx, NS_SERVER_NOTCP, true); ns_server_setoption(sctx, NS_SERVER_NOTCP, true);
if (sigvalinsecs) if (sigvalinsecs)
ns_server_setoption(sctx, NS_SERVER_SIGVALINSECS, true); ns_server_setoption(sctx, NS_SERVER_SIGVALINSECS, true);
named_g_server->sctx->delay = delay;
} }
static void static void
@@ -1344,6 +1329,8 @@ cleanup(void) {
dlz_dlopen_clear(); dlz_dlopen_clear();
#endif #endif
dns_name_destroy();
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL, isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
NAMED_LOGMODULE_MAIN, NAMED_LOGMODULE_MAIN,
ISC_LOG_NOTICE, "exiting"); ISC_LOG_NOTICE, "exiting");
@@ -1456,10 +1443,6 @@ main(int argc, char *argv[]) {
setvbuf(stderr, NULL, _IOFBF, BUFSIZ); setvbuf(stderr, NULL, _IOFBF, BUFSIZ);
#endif #endif
#ifdef HAVE_LIBXML2
xmlInitThreads();
#endif /* HAVE_LIBXML2 */
/* /*
* Record version in core image. * Record version in core image.
* strings named.core | grep "named version:" * strings named.core | grep "named version:"
@@ -1592,10 +1575,6 @@ main(int argc, char *argv[]) {
named_os_shutdown(); named_os_shutdown();
#ifdef HAVE_LIBXML2
xmlCleanupThreads();
#endif /* HAVE_LIBXML2 */
#ifdef HAVE_GPERFTOOLS_PROFILER #ifdef HAVE_GPERFTOOLS_PROFILER
ProfilerStop(); ProfilerStop();
#endif #endif
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2000, 2001, 2003-2009, 2011, 2013-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2000, 2001, 2003-2009, 2011, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -378,5 +378,5 @@ BIND 9 Administrator Reference Manual\&.
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2000, 2001, 2003-2009, 2011, 2013-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2000, 2001, 2003-2009, 2011, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
+23 -23
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2004-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2004-2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -97,6 +97,20 @@ dlz \fIstring\fR {
.if n \{\ .if n \{\
.RE .RE
.\} .\}
.SH "DNSSEC-KEYS"
.sp
.if n \{\
.RS 4
.\}
.nf
dnssec\-keys { \fIstring\fR ( static\-key |
initial\-key | static\-ds | initial\-ds )
\fIinteger\fR \fIinteger\fR \fIinteger\fR
\fIquoted_string\fR; \&.\&.\&. };
.fi
.if n \{\
.RE
.\}
.SH "DYNDB" .SH "DYNDB"
.sp .sp
.if n \{\ .if n \{\
@@ -150,7 +164,7 @@ logging {
.\} .\}
.SH "MANAGED-KEYS" .SH "MANAGED-KEYS"
.PP .PP
Deprecated \- see TRUST\-ANCHORS\&. Deprecated \- see DNSSEC\-KEYS\&.
.sp .sp
.if n \{\ .if n \{\
.RS 4 .RS 4
@@ -551,23 +565,9 @@ statistics\-channels {
.if n \{\ .if n \{\
.RE .RE
.\} .\}
.SH "TRUST-ANCHORS"
.sp
.if n \{\
.RS 4
.\}
.nf
trust\-anchors { \fIstring\fR ( static\-key |
initial\-key | static\-ds | initial\-ds )
\fIinteger\fR \fIinteger\fR \fIinteger\fR
\fIquoted_string\fR; \&.\&.\&. };
.fi
.if n \{\
.RE
.\}
.SH "TRUSTED-KEYS" .SH "TRUSTED-KEYS"
.PP .PP
Deprecated \- see TRUST\-ANCHORS\&. Deprecated \- see DNSSEC\-KEYS\&.
.sp .sp
.if n \{\ .if n \{\
.RS 4 .RS 4
@@ -655,6 +655,10 @@ view \fIstring\fR [ \fIclass\fR ] {
dnsrps\-options { \fIunspecified\-text\fR }; dnsrps\-options { \fIunspecified\-text\fR };
dnssec\-accept\-expired \fIboolean\fR; dnssec\-accept\-expired \fIboolean\fR;
dnssec\-dnskey\-kskonly \fIboolean\fR; dnssec\-dnskey\-kskonly \fIboolean\fR;
dnssec\-keys { \fIstring\fR ( static\-key |
initial\-key | static\-ds | initial\-ds
) \fIinteger\fR \fIinteger\fR \fIinteger\fR
\fIquoted_string\fR; \&.\&.\&. };
dnssec\-loadkeys\-interval \fIinteger\fR; dnssec\-loadkeys\-interval \fIinteger\fR;
dnssec\-must\-be\-secure \fIstring\fR \fIboolean\fR; dnssec\-must\-be\-secure \fIstring\fR \fIboolean\fR;
dnssec\-secure\-to\-insecure \fIboolean\fR; dnssec\-secure\-to\-insecure \fIboolean\fR;
@@ -845,10 +849,6 @@ view \fIstring\fR [ \fIclass\fR ] {
transfer\-source\-v6 ( \fIipv6_address\fR | * ) [ port ( \fIinteger\fR | * ) transfer\-source\-v6 ( \fIipv6_address\fR | * ) [ port ( \fIinteger\fR | * )
] [ dscp \fIinteger\fR ]; ] [ dscp \fIinteger\fR ];
trust\-anchor\-telemetry \fIboolean\fR; // experimental trust\-anchor\-telemetry \fIboolean\fR; // experimental
trust\-anchors { \fIstring\fR ( static\-key |
initial\-key | static\-ds | initial\-ds
) \fIinteger\fR \fIinteger\fR \fIinteger\fR
\fIquoted_string\fR; \&.\&.\&. };
trusted\-keys { \fIstring\fR trusted\-keys { \fIstring\fR
\fIinteger\fR \fIinteger\fR \fIinteger\fR \fIinteger\fR
\fIinteger\fR \fIinteger\fR
@@ -1074,7 +1074,7 @@ zone \fIstring\fR [ \fIclass\fR ] {
.\} .\}
.nf .nf
dnssec\-policy \fIstring\fR { dnssec\-policy \fIstring\fR {
dnskey\-ttl \fIduration\fR; dnskey\-ttl \fIttlval\fR;
keys { ( csk | ksk | zsk ) key\-directory lifetime \fIduration\fR algorithm \fIinteger\fR [ \fIinteger\fR ] ; \&.\&.\&. }; keys { ( csk | ksk | zsk ) key\-directory lifetime \fIduration\fR algorithm \fIinteger\fR [ \fIinteger\fR ] ; \&.\&.\&. };
parent\-ds\-ttl \fIduration\fR; parent\-ds\-ttl \fIduration\fR;
parent\-propagation\-delay \fIduration\fR; parent\-propagation\-delay \fIduration\fR;
@@ -1107,5 +1107,5 @@ BIND 9 Administrator Reference Manual\&.
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2004-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2004-2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
+16 -17
View File
@@ -49,7 +49,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
@@ -111,6 +110,15 @@ dlz <replaceable>string</replaceable> {
</literallayout> </literallayout>
</refsection> </refsection>
<refsection><info><title>DNSSEC-KEYS</title></info>
<literallayout class="normal">
dnssec-keys { <replaceable>string</replaceable> ( static-key |
initial-key | static-ds | initial-ds )
<replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
<replaceable>quoted_string</replaceable>; ... };
</literallayout>
</refsection>
<refsection><info><title>DYNDB</title></info> <refsection><info><title>DYNDB</title></info>
<literallayout class="normal"> <literallayout class="normal">
dyndb <replaceable>string</replaceable> <replaceable>quoted_string</replaceable> { dyndb <replaceable>string</replaceable> <replaceable>quoted_string</replaceable> {
@@ -148,7 +156,7 @@ logging {
</refsection> </refsection>
<refsection><info><title>MANAGED-KEYS</title></info> <refsection><info><title>MANAGED-KEYS</title></info>
<para>Deprecated - see TRUST-ANCHORS.</para> <para>Deprecated - see DNSSEC-KEYS.</para>
<literallayout class="normal"> <literallayout class="normal">
managed-keys { <replaceable>string</replaceable> ( static-key managed-keys { <replaceable>string</replaceable> ( static-key
| initial-key | static-ds | | initial-key | static-ds |
@@ -519,17 +527,8 @@ statistics-channels {
</literallayout> </literallayout>
</refsection> </refsection>
<refsection><info><title>TRUST-ANCHORS</title></info>
<literallayout class="normal">
trust-anchors { <replaceable>string</replaceable> ( static-key |
initial-key | static-ds | initial-ds )
<replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
<replaceable>quoted_string</replaceable>; ... };
</literallayout>
</refsection>
<refsection><info><title>TRUSTED-KEYS</title></info> <refsection><info><title>TRUSTED-KEYS</title></info>
<para>Deprecated - see TRUST-ANCHORS.</para> <para>Deprecated - see DNSSEC-KEYS.</para>
<literallayout class="normal"> <literallayout class="normal">
trusted-keys { <replaceable>string</replaceable> <replaceable>integer</replaceable> trusted-keys { <replaceable>string</replaceable> <replaceable>integer</replaceable>
<replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
@@ -608,6 +607,10 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
dnsrps-options { <replaceable>unspecified-text</replaceable> }; dnsrps-options { <replaceable>unspecified-text</replaceable> };
dnssec-accept-expired <replaceable>boolean</replaceable>; dnssec-accept-expired <replaceable>boolean</replaceable>;
dnssec-dnskey-kskonly <replaceable>boolean</replaceable>; dnssec-dnskey-kskonly <replaceable>boolean</replaceable>;
dnssec-keys { <replaceable>string</replaceable> ( static-key |
initial-key | static-ds | initial-ds
) <replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
<replaceable>quoted_string</replaceable>; ... };
dnssec-loadkeys-interval <replaceable>integer</replaceable>; dnssec-loadkeys-interval <replaceable>integer</replaceable>;
dnssec-must-be-secure <replaceable>string</replaceable> <replaceable>boolean</replaceable>; dnssec-must-be-secure <replaceable>string</replaceable> <replaceable>boolean</replaceable>;
dnssec-secure-to-insecure <replaceable>boolean</replaceable>; dnssec-secure-to-insecure <replaceable>boolean</replaceable>;
@@ -798,10 +801,6 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
transfer-source-v6 ( <replaceable>ipv6_address</replaceable> | * ) [ port ( <replaceable>integer</replaceable> | * ) transfer-source-v6 ( <replaceable>ipv6_address</replaceable> | * ) [ port ( <replaceable>integer</replaceable> | * )
] [ dscp <replaceable>integer</replaceable> ]; ] [ dscp <replaceable>integer</replaceable> ];
trust-anchor-telemetry <replaceable>boolean</replaceable>; // experimental trust-anchor-telemetry <replaceable>boolean</replaceable>; // experimental
trust-anchors { <replaceable>string</replaceable> ( static-key |
initial-key | static-ds | initial-ds
) <replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
<replaceable>quoted_string</replaceable>; ... };
trusted-keys { <replaceable>string</replaceable> trusted-keys { <replaceable>string</replaceable>
<replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
<replaceable>integer</replaceable> <replaceable>integer</replaceable>
@@ -1018,7 +1017,7 @@ zone <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
<literallayout class="normal"> <literallayout class="normal">
dnssec-policy <replaceable>string</replaceable> { dnssec-policy <replaceable>string</replaceable> {
dnskey-ttl <replaceable>duration</replaceable>; dnskey-ttl <replaceable>ttlval</replaceable>;
keys { ( csk | ksk | zsk ) key-directory lifetime <replaceable>duration</replaceable> algorithm <replaceable>integer</replaceable> [ <replaceable>integer</replaceable> ] ; ... }; keys { ( csk | ksk | zsk ) key-directory lifetime <replaceable>duration</replaceable> algorithm <replaceable>integer</replaceable> [ <replaceable>integer</replaceable> ] ; ... };
parent-ds-ttl <replaceable>duration</replaceable>; parent-ds-ttl <replaceable>duration</replaceable>;
parent-propagation-delay <replaceable>duration</replaceable>; parent-propagation-delay <replaceable>duration</replaceable>;
+27 -27
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2004-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2004-2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -92,7 +92,17 @@ dlz
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.11"></a><h2>DYNDB</h2> <a name="id-1.11"></a><h2>DNSSEC-KEYS</h2>
<div class="literallayout"><p><br>
dnssec-keys { <em class="replaceable"><code>string</code></em> ( static-key |<br>
    initial-key | static-ds | initial-ds )<br>
    <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>quoted_string</code></em>; ... };<br>
</p></div>
</div>
<div class="refsection">
<a name="id-1.12"></a><h2>DYNDB</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
dyndb <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>quoted_string</code></em> {<br> dyndb <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>quoted_string</code></em> {<br>
    <em class="replaceable"><code>unspecified-text</code></em> };<br>     <em class="replaceable"><code>unspecified-text</code></em> };<br>
@@ -100,7 +110,7 @@ dyndb
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.12"></a><h2>KEY</h2> <a name="id-1.13"></a><h2>KEY</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
key <em class="replaceable"><code>string</code></em> {<br> key <em class="replaceable"><code>string</code></em> {<br>
algorithm <em class="replaceable"><code>string</code></em>;<br> algorithm <em class="replaceable"><code>string</code></em>;<br>
@@ -110,7 +120,7 @@ key
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.13"></a><h2>LOGGING</h2> <a name="id-1.14"></a><h2>LOGGING</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
logging {<br> logging {<br>
category <em class="replaceable"><code>string</code></em> { <em class="replaceable"><code>string</code></em>; ... };<br> category <em class="replaceable"><code>string</code></em> { <em class="replaceable"><code>string</code></em>; ... };<br>
@@ -131,8 +141,8 @@ logging
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.14"></a><h2>MANAGED-KEYS</h2> <a name="id-1.15"></a><h2>MANAGED-KEYS</h2>
<p>Deprecated - see TRUST-ANCHORS.</p> <p>Deprecated - see DNSSEC-KEYS.</p>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
managed-keys { <em class="replaceable"><code>string</code></em> ( static-key<br> managed-keys { <em class="replaceable"><code>string</code></em> ( static-key<br>
    | initial-key | static-ds |<br>     | initial-key | static-ds |<br>
@@ -142,7 +152,7 @@ managed-keys
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.15"></a><h2>MASTERS</h2> <a name="id-1.16"></a><h2>MASTERS</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
masters <em class="replaceable"><code>string</code></em> [ port <em class="replaceable"><code>integer</code></em> ] [ dscp<br> masters <em class="replaceable"><code>string</code></em> [ port <em class="replaceable"><code>integer</code></em> ] [ dscp<br>
    <em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [<br>     <em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [<br>
@@ -152,7 +162,7 @@ masters
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.16"></a><h2>OPTIONS</h2> <a name="id-1.17"></a><h2>OPTIONS</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
options {<br> options {<br>
allow-new-zones <em class="replaceable"><code>boolean</code></em>;<br> allow-new-zones <em class="replaceable"><code>boolean</code></em>;<br>
@@ -451,7 +461,7 @@ options
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.17"></a><h2>PLUGIN</h2> <a name="id-1.18"></a><h2>PLUGIN</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
plugin ( query ) <em class="replaceable"><code>string</code></em> [ { <em class="replaceable"><code>unspecified-text</code></em><br> plugin ( query ) <em class="replaceable"><code>string</code></em> [ { <em class="replaceable"><code>unspecified-text</code></em><br>
    } ];<br>     } ];<br>
@@ -459,7 +469,7 @@ plugin
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.18"></a><h2>SERVER</h2> <a name="id-1.19"></a><h2>SERVER</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
server <em class="replaceable"><code>netprefix</code></em> {<br> server <em class="replaceable"><code>netprefix</code></em> {<br>
bogus <em class="replaceable"><code>boolean</code></em>;<br> bogus <em class="replaceable"><code>boolean</code></em>;<br>
@@ -497,7 +507,7 @@ server
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.19"></a><h2>STATISTICS-CHANNELS</h2> <a name="id-1.20"></a><h2>STATISTICS-CHANNELS</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
statistics-channels {<br> statistics-channels {<br>
inet ( <em class="replaceable"><code>ipv4_address</code></em> | <em class="replaceable"><code>ipv6_address</code></em> |<br> inet ( <em class="replaceable"><code>ipv4_address</code></em> | <em class="replaceable"><code>ipv6_address</code></em> |<br>
@@ -508,19 +518,9 @@ statistics-channels
</p></div> </p></div>
</div> </div>
<div class="refsection">
<a name="id-1.20"></a><h2>TRUST-ANCHORS</h2>
<div class="literallayout"><p><br>
trust-anchors { <em class="replaceable"><code>string</code></em> ( static-key |<br>
    initial-key | static-ds | initial-ds )<br>
    <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>quoted_string</code></em>; ... };<br>
</p></div>
</div>
<div class="refsection"> <div class="refsection">
<a name="id-1.21"></a><h2>TRUSTED-KEYS</h2> <a name="id-1.21"></a><h2>TRUSTED-KEYS</h2>
<p>Deprecated - see TRUST-ANCHORS.</p> <p>Deprecated - see DNSSEC-KEYS.</p>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
trusted-keys { <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>integer</code></em><br> trusted-keys { <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>     <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
@@ -600,6 +600,10 @@ view
dnsrps-options { <em class="replaceable"><code>unspecified-text</code></em> };<br> dnsrps-options { <em class="replaceable"><code>unspecified-text</code></em> };<br>
dnssec-accept-expired <em class="replaceable"><code>boolean</code></em>;<br> dnssec-accept-expired <em class="replaceable"><code>boolean</code></em>;<br>
dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br> dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br>
dnssec-keys { <em class="replaceable"><code>string</code></em> ( static-key |<br>
    initial-key | static-ds | initial-ds<br>
    ) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>quoted_string</code></em>; ... };<br>
dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br> dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br>
dnssec-must-be-secure <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>boolean</code></em>;<br> dnssec-must-be-secure <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>boolean</code></em>;<br>
dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br> dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br>
@@ -790,10 +794,6 @@ view
transfer-source-v6 ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * )<br> transfer-source-v6 ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * )<br>
    ] [ dscp <em class="replaceable"><code>integer</code></em> ];<br>     ] [ dscp <em class="replaceable"><code>integer</code></em> ];<br>
trust-anchor-telemetry <em class="replaceable"><code>boolean</code></em>; // experimental<br> trust-anchor-telemetry <em class="replaceable"><code>boolean</code></em>; // experimental<br>
trust-anchors { <em class="replaceable"><code>string</code></em> ( static-key |<br>
    initial-key | static-ds | initial-ds<br>
    ) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>quoted_string</code></em>; ... };<br>
trusted-keys { <em class="replaceable"><code>string</code></em><br> trusted-keys { <em class="replaceable"><code>string</code></em><br>
    <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>     <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>integer</code></em><br>     <em class="replaceable"><code>integer</code></em><br>
@@ -1012,7 +1012,7 @@ zone
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
dnssec-policy <em class="replaceable"><code>string</code></em> {<br> dnssec-policy <em class="replaceable"><code>string</code></em> {<br>
dnskey-ttl <em class="replaceable"><code>duration</code></em>;<br> dnskey-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
keys { ( csk | ksk | zsk ) key-directory lifetime <em class="replaceable"><code>duration</code></em> algorithm <em class="replaceable"><code>integer</code></em> [ <em class="replaceable"><code>integer</code></em> ] ; ... };<br> keys { ( csk | ksk | zsk ) key-directory lifetime <em class="replaceable"><code>duration</code></em> algorithm <em class="replaceable"><code>integer</code></em> [ <em class="replaceable"><code>integer</code></em> ] ; ... };<br>
parent-ds-ttl <em class="replaceable"><code>duration</code></em>;<br> parent-ds-ttl <em class="replaceable"><code>duration</code></em>;<br>
parent-propagation-delay <em class="replaceable"><code>duration</code></em>;<br> parent-propagation-delay <em class="replaceable"><code>duration</code></em>;<br>
-1
View File
@@ -49,7 +49,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2000, 2001, 2003-2009, 2011, 2013-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2000, 2001, 2003-2009, 2011, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
+174 -137
View File
@@ -68,7 +68,6 @@
#include <dns/events.h> #include <dns/events.h>
#include <dns/forward.h> #include <dns/forward.h>
#include <dns/fixedname.h> #include <dns/fixedname.h>
#include <dns/geoip.h>
#include <dns/journal.h> #include <dns/journal.h>
#include <dns/kasp.h> #include <dns/kasp.h>
#include <dns/keytable.h> #include <dns/keytable.h>
@@ -700,13 +699,12 @@ configure_view_nametable(const cfg_obj_t *vconfig, const cfg_obj_t *config,
} }
static isc_result_t static isc_result_t
ta_fromconfig(const cfg_obj_t *key, bool *initialp, const char **namestrp, ta_fromconfig(const cfg_obj_t *key, bool *initialp, dst_key_t **keyp,
unsigned char *digest, dns_rdata_ds_t *ds) dns_rdata_ds_t **dsp, const char **namestrp, isc_mem_t *mctx)
{ {
isc_result_t result;
dns_rdata_dnskey_t keystruct; dns_rdata_dnskey_t keystruct;
dns_rdata_t rdata = DNS_RDATA_INIT; dns_rdata_ds_t *ds = NULL;
uint32_t rdata1, rdata2, rdata3; uint32_t n1, n2, n3;
const char *datastr = NULL, *namestr = NULL; const char *datastr = NULL, *namestr = NULL;
unsigned char data[4096]; unsigned char data[4096];
isc_buffer_t databuf; isc_buffer_t databuf;
@@ -716,6 +714,8 @@ ta_fromconfig(const cfg_obj_t *key, bool *initialp, const char **namestrp,
dns_fixedname_t fname; dns_fixedname_t fname;
dns_name_t *name = NULL; dns_name_t *name = NULL;
isc_buffer_t namebuf; isc_buffer_t namebuf;
isc_result_t result;
dst_key_t *dstkey = NULL;
const char *atstr = NULL; const char *atstr = NULL;
enum { enum {
INIT_DNSKEY, INIT_DNSKEY,
@@ -725,17 +725,18 @@ ta_fromconfig(const cfg_obj_t *key, bool *initialp, const char **namestrp,
TRUSTED TRUSTED
} anchortype; } anchortype;
REQUIRE(keyp != NULL && *keyp == NULL);
REQUIRE(dsp != NULL && *dsp == NULL);
REQUIRE(namestrp != NULL && *namestrp == NULL); REQUIRE(namestrp != NULL && *namestrp == NULL);
REQUIRE(ds != NULL);
/* if DNSKEY, flags; if DS, key tag */ /* if DNSKEY, flags; if DS, key tag */
rdata1 = cfg_obj_asuint32(cfg_tuple_get(key, "rdata1")); n1 = cfg_obj_asuint32(cfg_tuple_get(key, "n1"));
/* if DNSKEY, protocol; if DS, algorithm */ /* if DNSKEY, protocol; if DS, algorithm */
rdata2 = cfg_obj_asuint32(cfg_tuple_get(key, "rdata2")); n2 = cfg_obj_asuint32(cfg_tuple_get(key, "n2"));
/* if DNSKEY, algorithm; if DS, digest type */ /* if DNSKEY, algorithm; if DS, digest type */
rdata3 = cfg_obj_asuint32(cfg_tuple_get(key, "rdata3")); n3 = cfg_obj_asuint32(cfg_tuple_get(key, "n3"));
namestr = cfg_obj_asstring(cfg_tuple_get(key, "name")); namestr = cfg_obj_asstring(cfg_tuple_get(key, "name"));
*namestrp = namestr; *namestrp = namestr;
@@ -773,13 +774,6 @@ ta_fromconfig(const cfg_obj_t *key, bool *initialp, const char **namestrp,
isc_buffer_init(&databuf, data, sizeof(data)); isc_buffer_init(&databuf, data, sizeof(data));
isc_buffer_init(&rrdatabuf, rrdata, sizeof(rrdata)); isc_buffer_init(&rrdatabuf, rrdata, sizeof(rrdata));
*ds = (dns_rdata_ds_t){
.common.rdclass = dns_rdataclass_in,
.common.rdtype = dns_rdatatype_ds
};
ISC_LINK_INIT(&ds->common, link);
switch(anchortype) { switch(anchortype) {
case INIT_DNSKEY: case INIT_DNSKEY:
case STATIC_DNSKEY: case STATIC_DNSKEY:
@@ -798,26 +792,22 @@ ta_fromconfig(const cfg_obj_t *key, bool *initialp, const char **namestrp,
ISC_LINK_INIT(&keystruct.common, link); ISC_LINK_INIT(&keystruct.common, link);
if (rdata1 > 0xffff) { if (n1 > 0xffff) {
CHECKM(ISC_R_RANGE, "key flags"); CHECKM(ISC_R_RANGE, "key flags");
} }
if (rdata1 & DNS_KEYFLAG_REVOKE) { if (n1 & DNS_KEYFLAG_REVOKE) {
CHECKM(DST_R_BADKEYTYPE, "key flags revoke bit set"); CHECKM(DST_R_BADKEYTYPE, "key flags revoke bit set");
} }
if (rdata2 > 0xff) { if (n2 > 0xff) {
CHECKM(ISC_R_RANGE, "key protocol"); CHECKM(ISC_R_RANGE, "key protocol");
} }
if (rdata3 > 0xff) { if (n3> 0xff) {
CHECKM(ISC_R_RANGE, "key algorithm"); CHECKM(ISC_R_RANGE, "key algorithm");
} }
keystruct.flags = (uint16_t)rdata1; keystruct.flags = (uint16_t)n1;
keystruct.protocol = (uint8_t)rdata2; keystruct.protocol = (uint8_t)n2;
keystruct.algorithm = (uint8_t)rdata3; keystruct.algorithm = (uint8_t)n3;
if (!dst_algorithm_supported(keystruct.algorithm)) {
CHECK(DST_R_UNSUPPORTEDALG);
}
datastr = cfg_obj_asstring(cfg_tuple_get(key, "data")); datastr = cfg_obj_asstring(cfg_tuple_get(key, "data"));
CHECK(isc_base64_decodestring(datastr, &databuf)); CHECK(isc_base64_decodestring(datastr, &databuf));
@@ -825,28 +815,37 @@ ta_fromconfig(const cfg_obj_t *key, bool *initialp, const char **namestrp,
keystruct.datalen = r.length; keystruct.datalen = r.length;
keystruct.data = r.base; keystruct.data = r.base;
CHECK(dns_rdata_fromstruct(&rdata, keystruct.common.rdclass, CHECK(dns_rdata_fromstruct(NULL, keystruct.common.rdclass,
keystruct.common.rdtype, keystruct.common.rdtype,
&keystruct, &rrdatabuf)); &keystruct, &rrdatabuf));
CHECK(dns_ds_fromkeyrdata(name, &rdata, DNS_DSDIGEST_SHA256, CHECK(dst_key_fromdns(name, dns_rdataclass_in,
digest, ds)); &rrdatabuf, mctx, &dstkey));
*keyp = dstkey;
break; break;
case INIT_DS: case INIT_DS:
case STATIC_DS: case STATIC_DS:
if (rdata1 > 0xffff) { ds = isc_mem_get(mctx, sizeof(*ds));
ds->common.rdclass = dns_rdataclass_in;
ds->common.rdtype = dns_rdatatype_ds;
ds->mctx = NULL;
ISC_LINK_INIT(&ds->common, link);
if (n1 > 0xffff) {
CHECKM(ISC_R_RANGE, "key tag"); CHECKM(ISC_R_RANGE, "key tag");
} }
if (rdata2 > 0xff) { if (n2 > 0xff) {
CHECKM(ISC_R_RANGE, "key algorithm"); CHECKM(ISC_R_RANGE, "key algorithm");
} }
if (rdata3 > 0xff) { if (n3 > 0xff) {
CHECKM(ISC_R_RANGE, "digest type"); CHECKM(ISC_R_RANGE, "digest type");
} }
ds->key_tag = (uint16_t)rdata1; ds->key_tag = (uint16_t)n1;
ds->algorithm = (uint8_t)rdata2; ds->algorithm = (uint8_t)n2;
ds->digest_type = (uint8_t)rdata3; ds->digest_type = (uint8_t)n3;
datastr = cfg_obj_asstring(cfg_tuple_get(key, "data")); datastr = cfg_obj_asstring(cfg_tuple_get(key, "data"));
CHECK(isc_hex_decodestring(datastr, &databuf)); CHECK(isc_hex_decodestring(datastr, &databuf));
@@ -868,20 +867,15 @@ ta_fromconfig(const cfg_obj_t *key, bool *initialp, const char **namestrp,
CHECK(ISC_R_UNEXPECTEDEND); CHECK(ISC_R_UNEXPECTEDEND);
} }
break; break;
default:
cfg_obj_log(key, named_g_lctx, ISC_LOG_ERROR,
"key '%s': "
"unknown ds digest type %u",
namestr, ds->digest_type);
result = ISC_R_FAILURE;
goto cleanup;
break;
} }
ds->mctx = mctx;
ds->length = r.length; ds->length = r.length;
ds->digest = digest; ds->digest = isc_mem_allocate(mctx, r.length);
memmove(ds->digest, r.base, r.length); memmove(ds->digest, r.base, r.length);
*dsp = ds;
ds = NULL;
break; break;
default: default:
@@ -892,6 +886,15 @@ ta_fromconfig(const cfg_obj_t *key, bool *initialp, const char **namestrp,
return (ISC_R_SUCCESS); return (ISC_R_SUCCESS);
cleanup: cleanup:
if (dstkey != NULL) {
dst_key_free(&dstkey);
}
if (ds != NULL) {
dns_rdata_freestruct(ds);
isc_mem_put(mctx, ds, sizeof(*ds));
}
return (result); return (result);
} }
@@ -909,30 +912,46 @@ ta_fromconfig(const cfg_obj_t *key, bool *initialp, const char **namestrp,
static isc_result_t static isc_result_t
process_key(const cfg_obj_t *key, dns_keytable_t *secroots, process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
const dns_name_t *keyname_match, dns_resolver_t *resolver, const dns_name_t *keyname_match, dns_resolver_t *resolver,
bool managed) bool managed, isc_mem_t *mctx)
{ {
dns_fixedname_t fkeyname; dns_fixedname_t fkeyname;
dns_name_t *keyname = NULL; dns_name_t *keyname = NULL;
const char *namestr = NULL; const char *namestr = NULL;
dns_rdata_ds_t ds; dst_key_t *dstkey = NULL;
dns_rdata_ds_t *ds = NULL;
unsigned int keyalg;
isc_result_t result; isc_result_t result;
bool initializing = managed; bool initializing = managed;
unsigned char digest[ISC_MAX_MD_SIZE];
isc_buffer_t b;
result = ta_fromconfig(key, &initializing, &namestr, digest, &ds); result = ta_fromconfig(key, &initializing, &dstkey, &ds,
&namestr, mctx);
switch (result) { switch (result) {
case ISC_R_SUCCESS: case ISC_R_SUCCESS:
/* /*
* Trust anchor was parsed correctly. * Trust anchor was parsed correctly. If dstkey is
* not NULL, then it was a key anchor, its algorithm
* is supported by the crypto library, and it is not
* revoked. If dstkey is NULL, then it was a DS
* trust anchor instead.
*/ */
isc_buffer_constinit(&b, namestr, strlen(namestr)); if (dstkey != NULL) {
isc_buffer_add(&b, strlen(namestr)); keyname = dst_key_name(dstkey);
keyname = dns_fixedname_initname(&fkeyname); keyalg = dst_key_alg(dstkey);
result = dns_name_fromtext(keyname, &b, dns_rootname, 0, NULL); } else {
if (result != ISC_R_SUCCESS) { isc_buffer_t b;
return (result);
INSIST(ds != NULL);
isc_buffer_constinit(&b, namestr, strlen(namestr));
isc_buffer_add(&b, strlen(namestr));
keyname = dns_fixedname_initname(&fkeyname);
result = dns_name_fromtext(keyname, &b,
dns_rootname, 0, NULL);
if (result != ISC_R_SUCCESS) {
return (result);
}
keyalg = ds->algorithm;
} }
break; break;
case DST_R_UNSUPPORTEDALG: case DST_R_UNSUPPORTEDALG:
@@ -983,8 +1002,7 @@ process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
* its owner name. If it does not, do not load the key and log a * its owner name. If it does not, do not load the key and log a
* warning, but do not prevent further keys from being processed. * warning, but do not prevent further keys from being processed.
*/ */
if (!dns_resolver_algorithm_supported(resolver, keyname, ds.algorithm)) if (!dns_resolver_algorithm_supported(resolver, keyname, keyalg)) {
{
cfg_obj_log(key, named_g_lctx, ISC_LOG_WARNING, cfg_obj_log(key, named_g_lctx, ISC_LOG_WARNING,
"ignoring %s for '%s': algorithm is disabled", "ignoring %s for '%s': algorithm is disabled",
initializing ? "initial-key" : "static-key", initializing ? "initial-key" : "static-key",
@@ -993,16 +1011,35 @@ process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
} }
/* /*
* Add the key to 'secroots'. Keys from a "trust-anchors" or * Add the key to 'secroots'. Keys from a "dnssec-keys" or
* "managed-keys" statement may be either static or initializing * "managed-keys" statement may be either static or initializing
* keys. If it's not initializing, we don't want to treat it as * keys. If it's not initializing, we don't want to treat it as
* managed, so we use 'initializing' twice here, for both the * managed, so we use 'initializing' twice here, for both the
* 'managed' and 'initializing' arguments to dns_keytable_add(). * 'managed' and 'initializing' arguments to dns_keytable_add().
*/ */
result = dns_keytable_add(secroots, initializing, initializing, result = dns_keytable_add(secroots, initializing,
keyname, &ds); initializing, keyname,
dstkey != NULL ? &dstkey : NULL,
ds);
done: done:
/*
* Ensure 'dstkey' does not leak. Note that if dns_keytable_add()
* succeeds, ownership of the key structure is transferred to the key
* table, i.e. 'dstkey' is set to NULL.
*/
if (dstkey != NULL) {
dst_key_free(&dstkey);
}
/*
* Free 'ds'.
*/
if (ds != NULL) {
dns_rdata_freestruct(ds);
isc_mem_put(mctx, ds, sizeof(*ds));
}
return (result); return (result);
} }
@@ -1013,7 +1050,7 @@ process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
*/ */
static isc_result_t static isc_result_t
load_view_keys(const cfg_obj_t *keys, dns_view_t *view, bool managed, load_view_keys(const cfg_obj_t *keys, dns_view_t *view, bool managed,
const dns_name_t *keyname) const dns_name_t *keyname, isc_mem_t *mctx)
{ {
const cfg_listelt_t *elt, *elt2; const cfg_listelt_t *elt, *elt2;
const cfg_obj_t *keylist; const cfg_obj_t *keylist;
@@ -1032,8 +1069,9 @@ load_view_keys(const cfg_obj_t *keys, dns_view_t *view, bool managed,
elt2 != NULL; elt2 != NULL;
elt2 = cfg_list_next(elt2)) elt2 = cfg_list_next(elt2))
{ {
CHECK(process_key(cfg_listelt_value(elt2), secroots, CHECK(process_key(cfg_listelt_value(elt2),
keyname, view->resolver, managed)); secroots, keyname, view->resolver,
managed, mctx));
} }
} }
@@ -1085,9 +1123,9 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
const cfg_obj_t *view_keys = NULL; const cfg_obj_t *view_keys = NULL;
const cfg_obj_t *global_keys = NULL; const cfg_obj_t *global_keys = NULL;
const cfg_obj_t *view_managed_keys = NULL; const cfg_obj_t *view_managed_keys = NULL;
const cfg_obj_t *view_trust_anchors = NULL; const cfg_obj_t *view_dnssec_keys = NULL;
const cfg_obj_t *global_managed_keys = NULL; const cfg_obj_t *global_managed_keys = NULL;
const cfg_obj_t *global_trust_anchors = NULL; const cfg_obj_t *global_dnssec_keys = NULL;
const cfg_obj_t *maps[4]; const cfg_obj_t *maps[4];
const cfg_obj_t *voptions = NULL; const cfg_obj_t *voptions = NULL;
const cfg_obj_t *options = NULL; const cfg_obj_t *options = NULL;
@@ -1108,11 +1146,11 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
(void) cfg_map_get(voptions, "trusted-keys", (void) cfg_map_get(voptions, "trusted-keys",
&view_keys); &view_keys);
/* managed-keys and trust-anchors are synonyms. */ /* managed-keys and dnssec-keys are synonyms. */
(void) cfg_map_get(voptions, "managed-keys", (void) cfg_map_get(voptions, "managed-keys",
&view_managed_keys); &view_managed_keys);
(void) cfg_map_get(voptions, "trust-anchors", (void) cfg_map_get(voptions, "dnssec-keys",
&view_trust_anchors); &view_dnssec_keys);
maps[i++] = voptions; maps[i++] = voptions;
} }
@@ -1121,10 +1159,9 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
if (config != NULL) { if (config != NULL) {
(void)cfg_map_get(config, "trusted-keys", &global_keys); (void)cfg_map_get(config, "trusted-keys", &global_keys);
/* managed-keys and trust-anchors are synonyms. */ /* managed-keys and dnssec-keys are synonyms. */
(void)cfg_map_get(config, "managed-keys", &global_managed_keys); (void)cfg_map_get(config, "managed-keys", &global_managed_keys);
(void)cfg_map_get(config, "trust-anchors", (void)cfg_map_get(config, "dnssec-keys", &global_dnssec_keys);
&global_trust_anchors);
(void)cfg_map_get(config, "options", &options); (void)cfg_map_get(config, "options", &options);
if (options != NULL) { if (options != NULL) {
@@ -1156,7 +1193,7 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
/* /*
* If bind.keys exists and is populated, it overrides * If bind.keys exists and is populated, it overrides
* the trust-anchors clause hard-coded in named_g_config. * the dnssec-keys clause hard-coded in named_g_config.
*/ */
if (bindkeys != NULL) { if (bindkeys != NULL) {
isc_log_write(named_g_lctx, DNS_LOGCATEGORY_SECURITY, isc_log_write(named_g_lctx, DNS_LOGCATEGORY_SECURITY,
@@ -1165,7 +1202,7 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
"from '%s'", "from '%s'",
view->name, named_g_server->bindkeysfile); view->name, named_g_server->bindkeysfile);
(void)cfg_map_get(bindkeys, "trust-anchors", (void)cfg_map_get(bindkeys, "dnssec-keys",
&builtin_keys); &builtin_keys);
if (builtin_keys == NULL) { if (builtin_keys == NULL) {
@@ -1185,13 +1222,13 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
"using built-in root key for view %s", "using built-in root key for view %s",
view->name); view->name);
(void)cfg_map_get(named_g_config, "trust-anchors", (void)cfg_map_get(named_g_config, "dnssec-keys",
&builtin_keys); &builtin_keys);
} }
if (builtin_keys != NULL) { if (builtin_keys != NULL) {
CHECK(load_view_keys(builtin_keys, view, true, CHECK(load_view_keys(builtin_keys, view, true,
dns_rootname)); dns_rootname, mctx));
} }
if (!keyloaded(view, dns_rootname)) { if (!keyloaded(view, dns_rootname)) {
@@ -1204,13 +1241,17 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
} }
if (view->rdclass == dns_rdataclass_in) { if (view->rdclass == dns_rdataclass_in) {
CHECK(load_view_keys(view_keys, view, false, NULL)); CHECK(load_view_keys(view_keys, view, false, NULL, mctx));
CHECK(load_view_keys(view_trust_anchors, view, true, NULL)); CHECK(load_view_keys(view_dnssec_keys, view, true, NULL,
CHECK(load_view_keys(view_managed_keys, view, true, NULL)); mctx));
CHECK(load_view_keys(view_managed_keys, view, true, NULL,
mctx));
CHECK(load_view_keys(global_keys, view, false, NULL)); CHECK(load_view_keys(global_keys, view, false, NULL, mctx));
CHECK(load_view_keys(global_trust_anchors, view, true, NULL)); CHECK(load_view_keys(global_dnssec_keys, view, true,
CHECK(load_view_keys(global_managed_keys, view, true, NULL)); NULL, mctx));
CHECK(load_view_keys(global_managed_keys, view, true,
NULL, mctx));
} }
/* /*
@@ -6784,7 +6825,11 @@ struct dotat_arg {
* reported in the TAT query. * reported in the TAT query.
*/ */
static isc_result_t static isc_result_t
get_tat_qname(dns_name_t *target, dns_name_t *keyname, dns_keynode_t *keynode) { get_tat_qname(dns_name_t *target, dns_name_t *keyname,
dns_keytable_t *keytable, dns_keynode_t *keynode)
{
dns_keynode_t *firstnode = keynode;
dns_keynode_t *nextnode = NULL;
dns_rdataset_t *dsset = NULL; dns_rdataset_t *dsset = NULL;
unsigned int i, n = 0; unsigned int i, n = 0;
uint16_t ids[12]; uint16_t ids[12];
@@ -6811,6 +6856,23 @@ get_tat_qname(dns_name_t *target, dns_name_t *keyname, dns_keynode_t *keynode) {
n++; n++;
} }
} }
} else {
do {
dst_key_t *key = dns_keynode_key(keynode);
if (key != NULL) {
if (n < (sizeof(ids)/sizeof(ids[0]))) {
ids[n] = dst_key_id(key);
n++;
}
}
nextnode = NULL;
(void)dns_keytable_nextkeynode(keytable, keynode,
&nextnode);
if (keynode != firstnode) {
dns_keytable_detachkeynode(keytable, &keynode);
}
keynode = nextnode;
} while (keynode != NULL);
} }
if (n == 0) { if (n == 0) {
@@ -6866,7 +6928,7 @@ dotat(dns_keytable_t *keytable, dns_keynode_t *keynode,
task = dotat_arg->task; task = dotat_arg->task;
tatname = dns_fixedname_initname(&fixed); tatname = dns_fixedname_initname(&fixed);
result = get_tat_qname(tatname, keyname, keynode); result = get_tat_qname(tatname, keyname, keytable, keynode);
if (result != ISC_R_SUCCESS) { if (result != ISC_R_SUCCESS) {
return; return;
} }
@@ -7341,7 +7403,7 @@ configure_session_key(const cfg_obj_t **maps, named_server_t *server,
server->session_keyname = isc_mem_get(mctx, server->session_keyname = isc_mem_get(mctx,
sizeof(dns_name_t)); sizeof(dns_name_t));
dns_name_init(server->session_keyname, NULL); dns_name_init(server->session_keyname, NULL);
dns_name_dup(keyname, mctx, server->session_keyname); CHECK(dns_name_dup(keyname, mctx, server->session_keyname));
server->session_keyfile = isc_mem_strdup(mctx, keyfile); server->session_keyfile = isc_mem_strdup(mctx, keyfile);
@@ -8276,11 +8338,6 @@ load_configuration(const char *filename, named_server_t *server,
isc_socketmgr_setreserved(named_g_socketmgr, reserved); isc_socketmgr_setreserved(named_g_socketmgr, reserved);
#if defined(HAVE_GEOIP2) #if defined(HAVE_GEOIP2)
/*
* Release any previously opened GeoIP2 databases.
*/
named_geoip_unload();
/* /*
* Initialize GeoIP databases from the configured location. * Initialize GeoIP databases from the configured location.
* This should happen before configuring any ACLs, so that we * This should happen before configuring any ACLs, so that we
@@ -9680,6 +9737,9 @@ shutdown_server(isc_task_t *task, isc_event_t *event) {
dns_tsigkey_detach(&named_g_sessionkey); dns_tsigkey_detach(&named_g_sessionkey);
dns_name_free(&named_g_sessionkeyname, server->mctx); dns_name_free(&named_g_sessionkeyname, server->mctx);
} }
#ifdef HAVE_DNSTAP
dns_dt_shutdown();
#endif
#if defined(HAVE_GEOIP2) #if defined(HAVE_GEOIP2)
named_geoip_shutdown(); named_geoip_shutdown();
#endif /* HAVE_GEOIP2 */ #endif /* HAVE_GEOIP2 */
@@ -9803,7 +9863,7 @@ named_server_create(isc_mem_t *mctx, named_server_t **serverp) {
/* /*
* GeoIP must be initialized before the interface * GeoIP must be initialized before the interface
* manager (which includes the ACL environment) * manager (which includes the ACL environment)
* is created. * is created
*/ */
named_geoip_init(); named_geoip_init();
#endif /* HAVE_GEOIP2 */ #endif /* HAVE_GEOIP2 */
@@ -9869,7 +9929,6 @@ named_server_create(isc_mem_t *mctx, named_server_t **serverp) {
isc_sockstatscounter_max), isc_sockstatscounter_max),
"isc_stats_create"); "isc_stats_create");
isc_socketmgr_setstats(named_g_socketmgr, server->sockstats); isc_socketmgr_setstats(named_g_socketmgr, server->sockstats);
isc_nm_setstats(named_g_nm, server->sockstats);
CHECKFATAL(isc_stats_create(named_g_mctx, &server->zonestats, CHECKFATAL(isc_stats_create(named_g_mctx, &server->zonestats,
dns_zonestatscounter_max), dns_zonestatscounter_max),
@@ -11047,20 +11106,17 @@ named_server_dumpsecroots(named_server_t *server, isc_lex_t *lex,
FILE *fp = NULL; FILE *fp = NULL;
isc_time_t now; isc_time_t now;
char tbuf[64]; char tbuf[64];
unsigned int used = isc_buffer_usedlength(*text);
bool first = true;
/* Skip the command name. */ /* Skip the command name. */
ptr = next_token(lex, text); ptr = next_token(lex, text);
if (ptr == NULL) { if (ptr == NULL)
return (ISC_R_UNEXPECTEDEND); return (ISC_R_UNEXPECTEDEND);
}
/* "-" here means print the output instead of dumping to file */ /* "-" here means print the output instead of dumping to file */
ptr = next_token(lex, text); ptr = next_token(lex, text);
if (ptr != NULL && strcmp(ptr, "-") == 0) { if (ptr != NULL && strcmp(ptr, "-") == 0)
ptr = next_token(lex, text); ptr = next_token(lex, text);
} else { else {
result = isc_stdio_open(server->secrootsfile, "w", &fp); result = isc_stdio_open(server->secrootsfile, "w", &fp);
if (result != ISC_R_SUCCESS) { if (result != ISC_R_SUCCESS) {
(void) putstr(text, "could not open "); (void) putstr(text, "could not open ");
@@ -11075,85 +11131,66 @@ named_server_dumpsecroots(named_server_t *server, isc_lex_t *lex,
CHECK(putstr(text, "secure roots as of ")); CHECK(putstr(text, "secure roots as of "));
CHECK(putstr(text, tbuf)); CHECK(putstr(text, tbuf));
CHECK(putstr(text, ":\n")); CHECK(putstr(text, ":\n"));
used = isc_buffer_usedlength(*text);
do { do {
for (view = ISC_LIST_HEAD(server->viewlist); for (view = ISC_LIST_HEAD(server->viewlist);
view != NULL; view != NULL;
view = ISC_LIST_NEXT(view, link)) view = ISC_LIST_NEXT(view, link))
{ {
if (ptr != NULL && strcmp(view->name, ptr) != 0) { if (ptr != NULL && strcmp(view->name, ptr) != 0)
continue; continue;
} if (secroots != NULL)
if (secroots != NULL) {
dns_keytable_detach(&secroots); dns_keytable_detach(&secroots);
}
result = dns_view_getsecroots(view, &secroots); result = dns_view_getsecroots(view, &secroots);
if (result == ISC_R_NOTFOUND) { if (result == ISC_R_NOTFOUND) {
result = ISC_R_SUCCESS; result = ISC_R_SUCCESS;
continue; continue;
} }
if (first || used != isc_buffer_usedlength(*text)) { CHECK(putstr(text, "\n Start view "));
CHECK(putstr(text, "\n"));
first = false;
}
CHECK(putstr(text, " Start view "));
CHECK(putstr(text, view->name)); CHECK(putstr(text, view->name));
CHECK(putstr(text, "\n Secure roots:\n\n")); CHECK(putstr(text, "\n Secure roots:\n\n"));
used = isc_buffer_usedlength(*text);
CHECK(dns_keytable_totext(secroots, text)); CHECK(dns_keytable_totext(secroots, text));
if (ntatable != NULL) { if (ntatable != NULL)
dns_ntatable_detach(&ntatable); dns_ntatable_detach(&ntatable);
}
result = dns_view_getntatable(view, &ntatable); result = dns_view_getntatable(view, &ntatable);
if (result == ISC_R_NOTFOUND) { if (result == ISC_R_NOTFOUND) {
result = ISC_R_SUCCESS; result = ISC_R_SUCCESS;
continue; continue;
} }
if (used != isc_buffer_usedlength(*text)) { CHECK(putstr(text, "\n Negative trust anchors:\n\n"));
CHECK(putstr(text, "\n"));
}
CHECK(putstr(text, " Negative trust anchors:\n\n"));
used = isc_buffer_usedlength(*text);
CHECK(dns_ntatable_totext(ntatable, NULL, text)); CHECK(dns_ntatable_totext(ntatable, NULL, text));
} }
if (ptr != NULL)
if (ptr != NULL) {
ptr = next_token(lex, text); ptr = next_token(lex, text);
}
} while (ptr != NULL); } while (ptr != NULL);
cleanup: cleanup:
if (secroots != NULL) { if (isc_buffer_usedlength(*text) > 0) {
dns_keytable_detach(&secroots); if (fp != NULL)
}
if (ntatable != NULL) {
dns_ntatable_detach(&ntatable);
}
if (fp != NULL) {
if (used != isc_buffer_usedlength(*text)) {
(void)putstr(text, "\n"); (void)putstr(text, "\n");
} else
(void)putnull(text);
}
if (secroots != NULL)
dns_keytable_detach(&secroots);
if (ntatable != NULL)
dns_ntatable_detach(&ntatable);
if (fp != NULL) {
fprintf(fp, "%.*s", (int) isc_buffer_usedlength(*text), fprintf(fp, "%.*s", (int) isc_buffer_usedlength(*text),
(char *) isc_buffer_base(*text)); (char *) isc_buffer_base(*text));
isc_buffer_clear(*text); isc_buffer_clear(*text);
(void)isc_stdio_close(fp); (void)isc_stdio_close(fp);
} else if (isc_buffer_usedlength(*text) > 0) {
(void)putnull(text);
} }
if (result == ISC_R_SUCCESS)
if (result == ISC_R_SUCCESS) {
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL, isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO, NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
"dumpsecroots complete"); "dumpsecroots complete");
} else { else
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL, isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR, NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
"dumpsecroots failed: %s", "dumpsecroots failed: %s",
dns_result_totext(result)); dns_result_totext(result));
}
return (result); return (result);
} }
+8 -3
View File
@@ -324,9 +324,6 @@ init_desc(void) {
"QryUsedStale"); "QryUsedStale");
SET_NSSTATDESC(prefetch, "queries triggered prefetch", "Prefetch"); SET_NSSTATDESC(prefetch, "queries triggered prefetch", "Prefetch");
SET_NSSTATDESC(keytagopt, "Keytag option received", "KeyTagOpt"); SET_NSSTATDESC(keytagopt, "Keytag option received", "KeyTagOpt");
SET_NSSTATDESC(reclimitdropped,
"queries dropped due to recursive client limit",
"RecLimitDropped");
INSIST(i == ns_statscounter_max); INSIST(i == ns_statscounter_max);
@@ -3593,6 +3590,10 @@ named_statschannels_configure(named_server_t *server, const cfg_obj_t *config,
ISC_LIST_INIT(new_listeners); ISC_LIST_INIT(new_listeners);
#ifdef HAVE_LIBXML2
xmlInitThreads();
#endif /* HAVE_LIBXML2 */
/* /*
* Get the list of named.conf 'statistics-channels' statements. * Get the list of named.conf 'statistics-channels' statements.
*/ */
@@ -3725,6 +3726,10 @@ named_statschannels_shutdown(named_server_t *server) {
ISC_LIST_UNLINK(server->statschannels, listener, link); ISC_LIST_UNLINK(server->statschannels, listener, link);
shutdown_listener(listener); shutdown_listener(listener);
} }
#ifdef HAVE_LIBXML2
xmlCleanupThreads();
#endif /* HAVE_LIBXML2 */
} }
isc_result_t isc_result_t
+2 -1
View File
@@ -85,7 +85,7 @@ named_tkeyctx_fromconfig(const cfg_obj_t *options, isc_mem_t *mctx,
RETERR(dns_name_fromtext(name, &b, dns_rootname, 0, NULL)); RETERR(dns_name_fromtext(name, &b, dns_rootname, 0, NULL));
tctx->domain = isc_mem_get(mctx, sizeof(dns_name_t)); tctx->domain = isc_mem_get(mctx, sizeof(dns_name_t));
dns_name_init(tctx->domain, NULL); dns_name_init(tctx->domain, NULL);
dns_name_dup(name, mctx, tctx->domain); RETERR(dns_name_dup(name, mctx, tctx->domain));
} }
obj = NULL; obj = NULL;
@@ -114,3 +114,4 @@ named_tkeyctx_fromconfig(const cfg_obj_t *options, isc_mem_t *mctx,
dns_tkeyctx_destroy(&tctx); dns_tkeyctx_destroy(&tctx);
return (result); return (result);
} }
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2000-2012, 2014-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2000-2012, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -519,5 +519,5 @@ The TSIG key is redundantly stored in two separate files\&. This is a consequenc
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2000-2012, 2014-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2000-2012, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
+3
View File
@@ -3210,6 +3210,9 @@ cleanup(void) {
ddebug("Shutting down timer manager"); ddebug("Shutting down timer manager");
isc_timermgr_destroy(&timermgr); isc_timermgr_destroy(&timermgr);
ddebug("Destroying name state");
dns_name_destroy();
ddebug("Removing log context"); ddebug("Removing log context");
isc_log_destroy(&glctx); isc_log_destroy(&glctx);
-1
View File
@@ -50,7 +50,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2000-2012, 2014-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2000-2012, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2009, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2009, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -93,5 +93,5 @@ Specify how long to pause before carrying out key destruction\&. The default is
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2009, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2009, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
+1 -1
View File
@@ -124,7 +124,7 @@ main(int argc, char *argv[]) {
if (errflg || (id && (label != NULL))) { if (errflg || (id && (label != NULL))) {
fprintf(stderr, "Usage:\n"); fprintf(stderr, "Usage:\n");
fprintf(stderr, "\tpkcs11-destroy [-m module] [-s slot] " fprintf(stderr, "\tpkcs11-destroy [-m module] [-s slot] "
"{-i id | -l label} [-p pin] [-w waittime]\n"); "[-i id | -l label] [-p pin] [-w waittime]\n");
exit(1); exit(1);
} }
-1
View File
@@ -38,7 +38,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2009, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2009, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2009, 2014-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2009, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -116,5 +116,5 @@ Open the session with the given PKCS#11 slot\&. The default is slot 0\&.
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2009, 2014-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2009, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
-1
View File
@@ -39,7 +39,6 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -1,6 +1,6 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<!-- <!--
- Copyright (C) 2009, 2014-2020 Internet Systems Consortium, Inc. ("ISC") - Copyright (C) 2009, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
- -
- This Source Code Form is subject to the terms of the Mozilla Public - This Source Code Form is subject to the terms of the Mozilla Public
- License, v. 2.0. If a copy of the MPL was not distributed with this - License, v. 2.0. If a copy of the MPL was not distributed with this
+2 -2
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2009, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") .\" Copyright (C) 2009, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
.\" .\"
.\" This Source Code Form is subject to the terms of the Mozilla Public .\" This Source Code Form is subject to the terms of the Mozilla Public
.\" License, v. 2.0. If a copy of the MPL was not distributed with this .\" License, v. 2.0. If a copy of the MPL was not distributed with this
@@ -94,5 +94,5 @@ will prompt for it\&.
\fBInternet Systems Consortium, Inc\&.\fR \fBInternet Systems Consortium, Inc\&.\fR
.SH "COPYRIGHT" .SH "COPYRIGHT"
.br .br
Copyright \(co 2009, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC") Copyright \(co 2009, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
.br .br
-1
View File
@@ -38,7 +38,6 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>

Some files were not shown because too many files have changed in this diff Show More