Compare commits
392
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a768277b24 | ||
|
|
4bd14084ea | ||
|
|
23106798be | ||
|
|
ad902a0f09 | ||
|
|
ef33c28c0a | ||
|
|
87ba699f4f | ||
|
|
9c7683872b | ||
|
|
3c12b263e3 | ||
|
|
31192119d7 | ||
|
|
a832204ec9 | ||
|
|
343c10f964 | ||
|
|
04ef1f730e | ||
|
|
5866c4a3be | ||
|
|
feddbcce10 | ||
|
|
d427a20056 | ||
|
|
6a6dd6ff0a | ||
|
|
f7f068dc64 | ||
|
|
26c28bd7b5 | ||
|
|
fb852e1d31 | ||
|
|
b3bc26af7d | ||
|
|
32a453674a | ||
|
|
c07df818c5 | ||
|
|
96e119cd19 | ||
|
|
4ed3238eac | ||
|
|
1ceea908b6 | ||
|
|
e5f31ce242 | ||
|
|
549ddca256 | ||
|
|
1d21552ed7 | ||
|
|
a402ffbced | ||
|
|
6c578e75d6 | ||
|
|
fd08918df5 | ||
|
|
aa42c8676f | ||
|
|
0a22024c27 | ||
|
|
323be476b8 | ||
|
|
1134f077fd | ||
|
|
1d55bd943b | ||
|
|
fa9ba8c5f8 | ||
|
|
22f499cdc4 | ||
|
|
e923e62f6c | ||
|
|
c9a9bc5437 | ||
|
|
91322d72c2 | ||
|
|
ff133ebabd | ||
|
|
27f0d104d3 | ||
|
|
ff006a1730 | ||
|
|
f9ef5120c1 | ||
|
|
c8205bfa0e | ||
|
|
2d2b8e7c02 | ||
|
|
dd754a974c | ||
|
|
8cb394e047 | ||
|
|
4a67cdabfe | ||
|
|
d4c4f6a669 | ||
|
|
1f5c47e4e6 | ||
|
|
10dd78126a | ||
|
|
de49699b66 | ||
|
|
57673de99e | ||
|
|
10b2620ec5 | ||
|
|
c4b8b831c0 | ||
|
|
ca1b0f1539 | ||
|
|
b8e4b6d303 | ||
|
|
d1d58a2e78 | ||
|
|
c070bab169 | ||
|
|
6da018dcce | ||
|
|
b1c424ddf3 | ||
|
|
61e8e13c91 | ||
|
|
044a72cca9 | ||
|
|
11add69198 | ||
|
|
230d79c191 | ||
|
|
045478ad6a | ||
|
|
5f6eb014aa | ||
|
|
dd46559a19 | ||
|
|
22e0272063 | ||
|
|
84aa74a111 | ||
|
|
6278899a38 | ||
|
|
fcd6962e8b | ||
|
|
dad6572093 | ||
|
|
9ac1f6a9bc | ||
|
|
96c4010fe5 | ||
|
|
2c796bb9c8 | ||
|
|
bd3d9f33dc | ||
|
|
dd8db89525 | ||
|
|
ed98f65479 | ||
|
|
a69433ba40 | ||
|
|
a7b78f3a40 | ||
|
|
c3a351275b | ||
|
|
8bbf3eb5f3 | ||
|
|
9af47af0f7 | ||
|
|
4722196b13 | ||
|
|
e0380d437d | ||
|
|
f59067807e | ||
|
|
d47d2b3fe0 | ||
|
|
78543ad5a7 | ||
|
|
25d35029eb | ||
|
|
0c9c755952 | ||
|
|
56ee60e130 | ||
|
|
d9594cffab | ||
|
|
2ca4d35037 | ||
|
|
337cc878fa | ||
|
|
888dfd78c7 | ||
|
|
9225c67835 | ||
|
|
daca5e8912 | ||
|
|
48973c3ec6 | ||
|
|
01684cc219 | ||
|
|
33d0e8d168 | ||
|
|
0ede73b9f1 | ||
|
|
6095811461 | ||
|
|
045173f8a7 | ||
|
|
56abe27b9e | ||
|
|
f3270a6d88 | ||
|
|
9d14522469 | ||
|
|
01cc80376e | ||
|
|
2164b6926f | ||
|
|
a347641782 | ||
|
|
3f85b0fe3b | ||
|
|
f34df4ef90 | ||
|
|
dd425254a7 | ||
|
|
f036e0bc7f | ||
|
|
2eb5c29c83 | ||
|
|
273d21fc93 | ||
|
|
ca487a5db0 | ||
|
|
586415fea2 | ||
|
|
62971d4a3c | ||
|
|
727272934e | ||
|
|
bc1c0d2ef4 | ||
|
|
713b77c70e | ||
|
|
41c9a5e428 | ||
|
|
334350a75a | ||
|
|
3df3dadaf2 | ||
|
|
1b1b11a3fe | ||
|
|
d7362ff16d | ||
|
|
ac67436758 | ||
|
|
2fd5ba6507 | ||
|
|
e51c8613e4 | ||
|
|
df26656e4b | ||
|
|
2a8c0282da | ||
|
|
62c448beaf | ||
|
|
8452404bd7 | ||
|
|
f6d7b8c20d | ||
|
|
3e743da1bd | ||
|
|
aa811801cb | ||
|
|
e4d30cb007 | ||
|
|
2e748ba397 | ||
|
|
be8c589f28 | ||
|
|
ba2376b9e0 | ||
|
|
99ca842e0a | ||
|
|
8d15bef0dd | ||
|
|
d5350db5bc | ||
|
|
8e43f5e860 | ||
|
|
f85bb0691c | ||
|
|
b01d26c608 | ||
|
|
4005cc3864 | ||
|
|
8b75833aaa | ||
|
|
53f229f499 | ||
|
|
915616a34e | ||
|
|
dd29e2550c | ||
|
|
80d69ba04c | ||
|
|
7ae055cef1 | ||
|
|
7e49689746 | ||
|
|
9d446142d8 | ||
|
|
3429c35f52 | ||
|
|
9b93e5d684 | ||
|
|
73dd849655 | ||
|
|
7dc8e720ff | ||
|
|
031ee9e279 | ||
|
|
d7f7014803 | ||
|
|
a238f37239 | ||
|
|
3c492b3ef1 | ||
|
|
a92d973430 | ||
|
|
6c7e50c267 | ||
|
|
9bb966d579 | ||
|
|
262b52a154 | ||
|
|
eeb8b80547 | ||
|
|
c59ab04f6f | ||
|
|
191887ef2b | ||
|
|
f9aba90342 | ||
|
|
eb0d5a9526 | ||
|
|
c8538c50b4 | ||
|
|
790476332e | ||
|
|
88ad7b85e6 | ||
|
|
c2dcd95966 | ||
|
|
852a2d834f | ||
|
|
fd126553d4 | ||
|
|
1532a34658 | ||
|
|
a53a0a8df1 | ||
|
|
439fe9bc3c | ||
|
|
ba6af6d507 | ||
|
|
0b2555e8cf | ||
|
|
f9537a6f2a | ||
|
|
c9f019c931 | ||
|
|
fec73c7e79 | ||
|
|
a69afb37e0 | ||
|
|
9a2a819817 | ||
|
|
e151eb3aa3 | ||
|
|
1e043a011b | ||
|
|
cde7f982eb | ||
|
|
5a4076fc40 | ||
|
|
82e9287459 | ||
|
|
46fcd927e7 | ||
|
|
e4c82fc7ae | ||
|
|
a43bb41909 | ||
|
|
a25f49f153 | ||
|
|
38cb43bc86 | ||
|
|
e3eb55fd1c | ||
|
|
04d8fc0143 | ||
|
|
94d9ffd4a2 | ||
|
|
6707a8558b | ||
|
|
8e212e96af | ||
|
|
b096a038e3 | ||
|
|
5ef9233326 | ||
|
|
8980d219c7 | ||
|
|
e0f394bbc4 | ||
|
|
9d932c6ddc | ||
|
|
23a60ecd15 | ||
|
|
bc212cf163 | ||
|
|
76421c885e | ||
|
|
18b71e9c25 | ||
|
|
4fb94906fa | ||
|
|
94bc07cf05 | ||
|
|
9b242cc707 | ||
|
|
952955aa4c | ||
|
|
10954a11de | ||
|
|
aaeea046ed | ||
|
|
52733368fd | ||
|
|
6b7629f323 | ||
|
|
aa863855f5 | ||
|
|
e576baad9d | ||
|
|
70a71de9c9 | ||
|
|
57fbc57b2e | ||
|
|
a3e42f8599 | ||
|
|
51c9ea98a3 | ||
|
|
c6a08a727d | ||
|
|
f2b41e11b4 | ||
|
|
38264b6a4d | ||
|
|
f0fa6f0245 | ||
|
|
49f245f7c0 | ||
|
|
72786a27c7 | ||
|
|
4292d5bdfe | ||
|
|
550b82e27b | ||
|
|
30e126ad02 | ||
|
|
500527b4da | ||
|
|
232297142d | ||
|
|
dc8fe44224 | ||
|
|
88ff6b846c | ||
|
|
20488d6ad3 | ||
|
|
bf760383e8 | ||
|
|
dd62275152 | ||
|
|
abc2ab9223 | ||
|
|
6ffa2ddae0 | ||
|
|
ce53db34d6 | ||
|
|
f2040a0039 | ||
|
|
532bf267af | ||
|
|
4b6113379a | ||
|
|
029e32c01a | ||
|
|
0c85c4c424 | ||
|
|
ba99bdbf6f | ||
|
|
23b1caabae | ||
|
|
8acdccc955 | ||
|
|
94eda43ab2 | ||
|
|
a0f7d28967 | ||
|
|
2ac7748d2b | ||
|
|
db1b344020 | ||
|
|
fcdf0d3bc3 | ||
|
|
4a8670ddaf | ||
|
|
12c9a767eb | ||
|
|
852c5cde5a | ||
|
|
c50fb6f30d | ||
|
|
107e6997fb | ||
|
|
ec4883ff52 | ||
|
|
649cb54400 | ||
|
|
305ca032a0 | ||
|
|
355b7899ee | ||
|
|
11207eacd5 | ||
|
|
2cd8fc02b0 | ||
|
|
9b0b045554 | ||
|
|
bde5c7632a | ||
|
|
92059fc7db | ||
|
|
aca18b8b5b | ||
|
|
d9f862337a | ||
|
|
954731cfa3 | ||
|
|
a3b02d627f | ||
|
|
68488dd98c | ||
|
|
32ee08e21a | ||
|
|
14bc22d7a4 | ||
|
|
093af1c00a | ||
|
|
6237be992f | ||
|
|
3ef106f69d | ||
|
|
1ce582ca47 | ||
|
|
18efb2456f | ||
|
|
953d704bd2 | ||
|
|
e7771dc902 | ||
|
|
8e142e6e80 | ||
|
|
c99381ce20 | ||
|
|
1036338a10 | ||
|
|
730226b674 | ||
|
|
881b635141 | ||
|
|
83b50bb901 | ||
|
|
ad6f65649a | ||
|
|
c5a4bc8bcc | ||
|
|
c2928c2ed4 | ||
|
|
5ab7d1c920 | ||
|
|
654c64c60b | ||
|
|
a14445d472 | ||
|
|
bcd049f116 | ||
|
|
78db46d746 | ||
|
|
e31bcac441 | ||
|
|
70c060120f | ||
|
|
1ba814a28c | ||
|
|
72d81c4768 | ||
|
|
cc1b77a0c7 | ||
|
|
c5e7152cf0 | ||
|
|
064e314df7 | ||
|
|
2064e01cd0 | ||
|
|
451ed397f0 | ||
|
|
2b4f0f03f5 | ||
|
|
a9182c89a6 | ||
|
|
f59fd49fd8 | ||
|
|
344d66aaff | ||
|
|
21d751dfc7 | ||
|
|
e24bc324b4 | ||
|
|
9dcf229634 | ||
|
|
1b13123c45 | ||
|
|
05c13e50d3 | ||
|
|
b232e8585a | ||
|
|
f27c0c3257 | ||
|
|
4fa2dfe72e | ||
|
|
b4cdd00fa3 | ||
|
|
efa5639934 | ||
|
|
69c1ee1ce9 | ||
|
|
d8e6b32a18 | ||
|
|
2b2e97a815 | ||
|
|
02de51d957 | ||
|
|
49c62f3e8e | ||
|
|
fc6d0a932b | ||
|
|
28d32ca7da | ||
|
|
97a2733ef9 | ||
|
|
3e74f894d4 | ||
|
|
fba5ce8a75 | ||
|
|
af35a186d0 | ||
|
|
eedbd6ecf5 | ||
|
|
41a79d068c | ||
|
|
e9a869f51e | ||
|
|
aa1d6a46ab | ||
|
|
267794244f | ||
|
|
f8ef2c0439 | ||
|
|
e645d2ef1e | ||
|
|
df72c52239 | ||
|
|
72201badf0 | ||
|
|
c53bfb30e8 | ||
|
|
3ff60b881f | ||
|
|
f4fbca6e16 | ||
|
|
11ecf7901b | ||
|
|
030674b2a3 | ||
|
|
2ac2d83265 | ||
|
|
e7662c4c63 | ||
|
|
1a1e52b7fe | ||
|
|
488eef63ca | ||
|
|
35ea733e2c | ||
|
|
18eef20241 | ||
|
|
bc5bd577d7 | ||
|
|
4e03bfac86 | ||
|
|
cc0089c66b | ||
|
|
d97710acdc | ||
|
|
7c703c851f | ||
|
|
ae5d316f64 | ||
|
|
55896df79d | ||
|
|
29dcdeba1b | ||
|
|
45ab0603eb | ||
|
|
3551d3ffd2 | ||
|
|
002c328437 | ||
|
|
0580d9cd8c | ||
|
|
e7602e2d51 | ||
|
|
ed37c63e2b | ||
|
|
4aaef76c58 | ||
|
|
a22e61d554 | ||
|
|
aab691d512 | ||
|
|
600128ac27 | ||
|
|
d02a14c795 | ||
|
|
1d739a95dd | ||
|
|
42b2290c3a | ||
|
|
6ca78bc57d | ||
|
|
98de853740 | ||
|
|
827746e89b | ||
|
|
1c73ea491b | ||
|
|
a0e8a11cc6 | ||
|
|
ef55dbf4fc | ||
|
|
9499adeb5e | ||
|
|
2e89dd7cb8 | ||
|
|
93a336e248 | ||
|
|
b02c3e4f8e | ||
|
|
c91dc92410 | ||
|
|
a87ac96b56 | ||
|
|
7fffa5abba | ||
|
|
53120279b5 |
@@ -1,6 +1,8 @@
|
||||
*.sln.in eol=crlf
|
||||
*.vcxproj.* eol=crlf
|
||||
|
||||
/fuzz/dns_rdata_fromwire_text.in/input-* -text
|
||||
|
||||
.gitignore export-ignore
|
||||
/conftools export-ignore
|
||||
/doc/design export-ignore
|
||||
|
||||
+120
-112
@@ -31,6 +31,12 @@ variables:
|
||||
|
||||
AM_COLOR_TESTS: always
|
||||
|
||||
WITHOUT_READLINE: "--without-readline"
|
||||
WITH_READLINE: "--with-readline"
|
||||
WITH_READLINE_EDITLINE: "--with-readline=editline"
|
||||
WITH_READLINE_LIBEDIT: "--with-readline=libedit"
|
||||
WITH_READLINE_READLINE: "--with-readline=readline"
|
||||
|
||||
stages:
|
||||
- autoconf
|
||||
- precheck
|
||||
@@ -44,9 +50,7 @@ stages:
|
||||
|
||||
### Runner Tag Templates
|
||||
|
||||
# Note: BSD runners extract the operating system version to use from job name
|
||||
|
||||
.freebsd-amd64: &freebsd_amd64
|
||||
.libvirt-amd64: &libvirt_amd64
|
||||
tags:
|
||||
- libvirt
|
||||
- amd64
|
||||
@@ -56,21 +60,11 @@ stages:
|
||||
- linux
|
||||
- amd64
|
||||
|
||||
.linux-arm64: &linux_arm64
|
||||
tags:
|
||||
- linux
|
||||
- arm64
|
||||
|
||||
.linux-i386: &linux_i386
|
||||
tags:
|
||||
- linux
|
||||
- i386
|
||||
|
||||
.openbsd-amd64: &openbsd_amd64
|
||||
tags:
|
||||
- libvirt
|
||||
- amd64
|
||||
|
||||
### Docker Image Templates
|
||||
|
||||
# Alpine Linux
|
||||
@@ -81,10 +75,6 @@ stages:
|
||||
|
||||
# CentOS
|
||||
|
||||
.centos-centos6-amd64: ¢os_centos6_amd64_image
|
||||
image: "$CI_REGISTRY_IMAGE:centos-centos6-amd64"
|
||||
<<: *linux_amd64
|
||||
|
||||
.centos-centos7-amd64: ¢os_centos7_amd64_image
|
||||
image: "$CI_REGISTRY_IMAGE:centos-centos7-amd64"
|
||||
<<: *linux_amd64
|
||||
@@ -107,10 +97,6 @@ stages:
|
||||
image: "$CI_REGISTRY_IMAGE:debian-sid-amd64"
|
||||
<<: *linux_amd64
|
||||
|
||||
.debian-sid-arm64: &debian_sid_arm64_image
|
||||
image: "$CI_REGISTRY_IMAGE:debian-sid-arm64"
|
||||
<<: *linux_arm64
|
||||
|
||||
.debian-sid-i386: &debian_sid_i386_image
|
||||
image: "$CI_REGISTRY_IMAGE:debian-sid-i386"
|
||||
<<: *linux_i386
|
||||
@@ -143,6 +129,20 @@ stages:
|
||||
.base: &base_image
|
||||
<<: *debian_buster_amd64_image
|
||||
|
||||
### QCOW2 Image Templates
|
||||
|
||||
.freebsd-11-amd64: &freebsd_11_amd64_image
|
||||
image: "freebsd-11.4-x86_64"
|
||||
<<: *libvirt_amd64
|
||||
|
||||
.freebsd-12-amd64: &freebsd_12_amd64_image
|
||||
image: "freebsd-12.1-x86_64"
|
||||
<<: *libvirt_amd64
|
||||
|
||||
.openbsd-amd64: &openbsd_amd64_image
|
||||
image: "openbsd-6.7-x86_64"
|
||||
<<: *libvirt_amd64
|
||||
|
||||
### Job Templates
|
||||
|
||||
.default-triggering-rules: &default_triggering_rules
|
||||
@@ -180,16 +180,28 @@ stages:
|
||||
${CONFIGURE} \
|
||||
--disable-maintainer-mode \
|
||||
--enable-developer \
|
||||
--with-libtool \
|
||||
--with-cmocka \
|
||||
--with-libxml2 \
|
||||
--with-json-c \
|
||||
--prefix=$HOME/.local \
|
||||
--without-make-clean \
|
||||
--with-python=python3 \
|
||||
$EXTRA_CONFIGURE \
|
||||
|| cat config.log
|
||||
|
||||
.check_readline_setup: &check_readline_setup |
|
||||
if [[ -n "${WITHOUT_READLINE}" ]]; then \
|
||||
! grep "^#define HAVE_READLINE" config.h; \
|
||||
elif [[ -n "${WITH_READLINE}" ]]; then \
|
||||
grep -e "^#define HAVE_READLINE_READLINE" \
|
||||
-e "^#define HAVE_READLINE_LIBEDIT" \
|
||||
-e "^#define HAVE_READLINE_EDITLINE" config.h; \
|
||||
elif [[ -n "${WITH_READLINE_EDITLINE}" ]]; then \
|
||||
grep "^#define HAVE_READLINE_EDITLINE" config.h; \
|
||||
elif [[ -n "${WITH_READLINE_LIBEDIT}" ]]; then \
|
||||
grep "^#define HAVE_READLINE_LIBEDIT" config.h; \
|
||||
elif [[ -n "${WITH_READLINE_READLINE}" ]]; then \
|
||||
grep "^#define HAVE_READLINE_READLINE" config.h; \
|
||||
fi
|
||||
|
||||
.build: &build_job
|
||||
<<: *default_triggering_rules
|
||||
stage: build
|
||||
@@ -198,6 +210,7 @@ stages:
|
||||
- test -n "${OOT_BUILD_WORKSPACE}" && mkdir "${OOT_BUILD_WORKSPACE}" && cd "${OOT_BUILD_WORKSPACE}"
|
||||
script:
|
||||
- *configure
|
||||
- *check_readline_setup
|
||||
- make -j${BUILD_PARALLEL_JOBS:-1} -k all V=1
|
||||
- test -z "${RUN_MAKE_INSTALL}" || make install
|
||||
- test -z "${RUN_MAKE_INSTALL}" || sh util/check-make-install
|
||||
@@ -257,8 +270,9 @@ stages:
|
||||
- *setup_softhsm
|
||||
script:
|
||||
- cd bin/tests/system
|
||||
- make -j${TEST_PARALLEL_JOBS:-1} -k check V=1 || make -j${TEST_PARALLEL_JOBS:-1} -k recheck V=1
|
||||
- make -j${TEST_PARALLEL_JOBS:-1} -k check V=1
|
||||
after_script:
|
||||
- test -d bind-* && cd bind-*
|
||||
- cat bin/tests/system/test-suite.log
|
||||
|
||||
.system_test: &system_test_job
|
||||
@@ -397,6 +411,7 @@ misc:
|
||||
- xmllint --noout --nonet `git ls-files '*.xml' '*.docbook'`
|
||||
- sh util/check-win32util-configure
|
||||
- sh util/check-categories.sh
|
||||
- if git grep SYSTEMTESTTOP -- ':!.gitlab-ci.yml'; then echo 'Please use relative paths instead of $SYSTEMTESTTOP.'; exit 1; fi
|
||||
needs: []
|
||||
artifacts:
|
||||
paths:
|
||||
@@ -460,9 +475,14 @@ pylint:
|
||||
tarball-create:
|
||||
stage: precheck
|
||||
<<: *base_image
|
||||
<<: *default_triggering_rules
|
||||
script:
|
||||
- *configure
|
||||
- ./configure --enable-maintainer-mode
|
||||
- make maintainer-clean
|
||||
- autoreconf -fi
|
||||
- ./configure --enable-maintainer-mode
|
||||
- make -j${BUILD_PARALLEL_JOBS:-1} all V=1
|
||||
- if test "$(git status --porcelain | grep -Ev '\?\?' | wc -l)" -gt "0"; then git status --short; exit 1; fi
|
||||
- make -j${BUILD_PARALLEL_JOBS:-1} dist V=1
|
||||
artifacts:
|
||||
paths:
|
||||
@@ -470,8 +490,6 @@ tarball-create:
|
||||
needs:
|
||||
- job: autoreconf
|
||||
artifacts: true
|
||||
only:
|
||||
- tags
|
||||
|
||||
# Jobs for doc builds on Debian 10 "buster" (amd64)
|
||||
|
||||
@@ -514,7 +532,7 @@ gcc:alpine3.12:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "${CFLAGS_COMMON}"
|
||||
EXTRA_CONFIGURE: "--enable-dnstap"
|
||||
EXTRA_CONFIGURE: "--enable-dnstap ${WITHOUT_READLINE}"
|
||||
<<: *alpine_3_12_amd64_image
|
||||
<<: *build_job
|
||||
|
||||
@@ -532,30 +550,6 @@ unit:gcc:alpine3.12:amd64:
|
||||
- job: gcc:alpine3.12:amd64
|
||||
artifacts: true
|
||||
|
||||
# Jobs for regular GCC builds on CentOS 6 (amd64)
|
||||
|
||||
gcc:centos6:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "${CFLAGS_COMMON}"
|
||||
EXTRA_CONFIGURE: "--with-libidn2 --disable-warn-error --without-python"
|
||||
<<: *centos_centos6_amd64_image
|
||||
<<: *build_job
|
||||
|
||||
system:gcc:centos6:amd64:
|
||||
<<: *centos_centos6_amd64_image
|
||||
<<: *system_test_job
|
||||
needs:
|
||||
- job: gcc:centos6:amd64
|
||||
artifacts: true
|
||||
|
||||
unit:gcc:centos6:amd64:
|
||||
<<: *centos_centos6_amd64_image
|
||||
<<: *unit_test_job
|
||||
needs:
|
||||
- job: gcc:centos6:amd64
|
||||
artifacts: true
|
||||
|
||||
# Jobs for regular GCC builds on CentOS 7 (amd64)
|
||||
|
||||
gcc:centos7:amd64:
|
||||
@@ -586,7 +580,7 @@ gcc:centos8:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "${CFLAGS_COMMON}"
|
||||
EXTRA_CONFIGURE: "--with-libidn2"
|
||||
EXTRA_CONFIGURE: "--enable-buffer-useinline --with-libidn2"
|
||||
<<: *centos_centos8_amd64_image
|
||||
<<: *build_job
|
||||
|
||||
@@ -633,6 +627,7 @@ gcc:buster:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "${CFLAGS_COMMON}"
|
||||
EXTRA_CONFIGURE: "${WITH_READLINE_LIBEDIT}"
|
||||
<<: *debian_buster_amd64_image
|
||||
<<: *build_job
|
||||
|
||||
@@ -742,6 +737,7 @@ gcc:tarball:
|
||||
- job: tarball-create
|
||||
artifacts: true
|
||||
only:
|
||||
- schedules
|
||||
- tags
|
||||
|
||||
system:gcc:tarball:
|
||||
@@ -754,6 +750,7 @@ system:gcc:tarball:
|
||||
- job: gcc:tarball
|
||||
artifacts: true
|
||||
only:
|
||||
- schedules
|
||||
- tags
|
||||
|
||||
unit:gcc:tarball:
|
||||
@@ -765,39 +762,16 @@ unit:gcc:tarball:
|
||||
- job: gcc:tarball
|
||||
artifacts: true
|
||||
only:
|
||||
- schedules
|
||||
- tags
|
||||
|
||||
# Jobs for regular GCC builds on Debian "sid" (arm64)
|
||||
|
||||
gcc:sid:arm64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
||||
EXTRA_CONFIGURE: "--with-libidn2"
|
||||
<<: *debian_sid_arm64_image
|
||||
<<: *build_job
|
||||
|
||||
system:gcc:sid:arm64:
|
||||
<<: *debian_sid_arm64_image
|
||||
<<: *system_test_job
|
||||
needs:
|
||||
- job: gcc:sid:arm64
|
||||
artifacts: true
|
||||
|
||||
unit:gcc:sid:arm64:
|
||||
<<: *debian_sid_arm64_image
|
||||
<<: *unit_test_job
|
||||
needs:
|
||||
- job: gcc:sid:arm64
|
||||
artifacts: true
|
||||
|
||||
# Jobs for regular GCC builds on Debian "sid" (i386)
|
||||
|
||||
gcc:sid:i386:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "${CFLAGS_COMMON}"
|
||||
EXTRA_CONFIGURE: "--with-libidn2 --without-python"
|
||||
EXTRA_CONFIGURE: "--with-libidn2"
|
||||
<<: *debian_sid_i386_image
|
||||
<<: *build_job
|
||||
|
||||
@@ -821,7 +795,7 @@ gcc:tumbleweed:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "${CFLAGS_COMMON}"
|
||||
EXTRA_CONFIGURE: "--with-libidn2 --with-python --with-gssapi=/usr/lib/mit/bin/krb5-config"
|
||||
EXTRA_CONFIGURE: "--with-libidn2 ${WITH_READLINE_READLINE}"
|
||||
<<: *tumbleweed_latest_amd64_image
|
||||
<<: *build_job
|
||||
|
||||
@@ -1029,7 +1003,6 @@ clang:buster:amd64:
|
||||
variables:
|
||||
CC: ${CLANG}
|
||||
CFLAGS: "${CFLAGS_COMMON} -Wenum-conversion"
|
||||
EXTRA_CONFIGURE: "--with-python=python3"
|
||||
<<: *debian_buster_amd64_image
|
||||
<<: *build_job
|
||||
|
||||
@@ -1095,78 +1068,76 @@ unit:gcc:softhsm2.6:
|
||||
- job: gcc:softhsm2.6
|
||||
artifacts: true
|
||||
|
||||
# Jobs for Clang builds on FreeBSD 11.4 (amd64)
|
||||
# Jobs for Clang builds on FreeBSD 11 (amd64)
|
||||
|
||||
clang:freebsd11.4:amd64:
|
||||
clang:freebsd11:amd64:
|
||||
variables:
|
||||
CFLAGS: "${CFLAGS_COMMON}"
|
||||
EXTRA_CONFIGURE: "${WITH_READLINE}"
|
||||
USER: gitlab-runner
|
||||
# Temporarily disable LMDB support [GL #1976]
|
||||
EXTRA_CONFIGURE: "--without-lmdb"
|
||||
<<: *freebsd_amd64
|
||||
<<: *freebsd_11_amd64_image
|
||||
<<: *build_job
|
||||
|
||||
system:clang:freebsd11.4:amd64:
|
||||
<<: *freebsd_amd64
|
||||
system:clang:freebsd11:amd64:
|
||||
<<: *freebsd_11_amd64_image
|
||||
<<: *system_test_job
|
||||
variables:
|
||||
USER: gitlab-runner
|
||||
TEST_PARALLEL_JOBS: 4
|
||||
needs:
|
||||
- job: clang:freebsd11.4:amd64
|
||||
- job: clang:freebsd11:amd64
|
||||
artifacts: true
|
||||
|
||||
unit:clang:freebsd11.4:amd64:
|
||||
<<: *freebsd_amd64
|
||||
unit:clang:freebsd11:amd64:
|
||||
<<: *freebsd_11_amd64_image
|
||||
<<: *unit_test_job
|
||||
needs:
|
||||
- job: clang:freebsd11.4:amd64
|
||||
- job: clang:freebsd11:amd64
|
||||
artifacts: true
|
||||
|
||||
# Jobs for Clang builds on FreeBSD 12.1 (amd64)
|
||||
# Jobs for Clang builds on FreeBSD 12 (amd64)
|
||||
|
||||
clang:freebsd12.1:amd64:
|
||||
clang:freebsd12:amd64:
|
||||
variables:
|
||||
CFLAGS: "${CFLAGS_COMMON}"
|
||||
# Temporarily disable LMDB support [GL #1976]
|
||||
EXTRA_CONFIGURE: "--enable-dnstap --without-lmdb"
|
||||
EXTRA_CONFIGURE: "--enable-dnstap ${WITH_READLINE_EDITLINE}"
|
||||
USER: gitlab-runner
|
||||
<<: *freebsd_amd64
|
||||
<<: *freebsd_12_amd64_image
|
||||
<<: *build_job
|
||||
|
||||
system:clang:freebsd12.1:amd64:
|
||||
<<: *freebsd_amd64
|
||||
system:clang:freebsd12:amd64:
|
||||
<<: *freebsd_12_amd64_image
|
||||
<<: *system_test_job
|
||||
variables:
|
||||
USER: gitlab-runner
|
||||
TEST_PARALLEL_JOBS: 4
|
||||
needs:
|
||||
- job: clang:freebsd12.1:amd64
|
||||
- job: clang:freebsd12:amd64
|
||||
artifacts: true
|
||||
|
||||
unit:clang:freebsd12.1:amd64:
|
||||
<<: *freebsd_amd64
|
||||
unit:clang:freebsd12:amd64:
|
||||
<<: *freebsd_12_amd64_image
|
||||
<<: *unit_test_job
|
||||
needs:
|
||||
- job: clang:freebsd12.1:amd64
|
||||
- job: clang:freebsd12:amd64
|
||||
artifacts: true
|
||||
|
||||
# Jobs for Clang builds on OpenBSD 6.7 (amd64)
|
||||
# Jobs for Clang builds on OpenBSD (amd64)
|
||||
|
||||
clang:openbsd6.7:amd64:
|
||||
clang:openbsd:amd64:
|
||||
variables:
|
||||
CC: clang
|
||||
USER: gitlab-runner
|
||||
<<: *openbsd_amd64
|
||||
<<: *openbsd_amd64_image
|
||||
<<: *build_job
|
||||
|
||||
system:clang:openbsd6.7:amd64:
|
||||
<<: *openbsd_amd64
|
||||
system:clang:openbsd:amd64:
|
||||
<<: *openbsd_amd64_image
|
||||
<<: *system_test_job
|
||||
variables:
|
||||
USER: gitlab-runner
|
||||
needs:
|
||||
- job: clang:openbsd6.7:amd64
|
||||
- job: clang:openbsd:amd64
|
||||
artifacts: true
|
||||
only:
|
||||
- schedules
|
||||
@@ -1218,6 +1189,8 @@ release:
|
||||
- find Build/ -regextype posix-extended -regex "Build/.*/($(find bin/tests/ -type f | sed -nE "s|^bin/tests(/system)?/win32/(.*)\.vcxproj$|\2|p" | paste -d"|" -s))\..*" -print -delete
|
||||
# Create Windows zips
|
||||
- openssl dgst -sha256 "${BIND_DIRECTORY}.tar.${TARBALL_EXTENSION}" | tee Build/Release/SHA256 Build/Debug/SHA256
|
||||
- cp "doc/arm/_build/latex/Bv9ARM.pdf" Build/Release/
|
||||
- cp "doc/arm/_build/latex/Bv9ARM.pdf" Build/Debug/
|
||||
- ( cd Build/Release; zip "../../BIND${BIND_DIRECTORY#bind-}.x64.zip" * )
|
||||
- ( cd Build/Debug; zip "../../BIND${BIND_DIRECTORY#bind-}.debug.x64.zip" * )
|
||||
# Prepare release tarball contents (tarballs + zips + documentation)
|
||||
@@ -1319,13 +1292,13 @@ respdiff:
|
||||
BIND_BASELINE_VERSION: v9_11_3
|
||||
script:
|
||||
- autoreconf -fi
|
||||
- ./configure --without-make-clean
|
||||
- ./configure
|
||||
- make -j${BUILD_PARALLEL_JOBS:-1} V=1
|
||||
- *setup_interfaces
|
||||
- git clone --depth 1 https://gitlab-ci-token:${CI_JOB_TOKEN}@gitlab.isc.org/isc-private/bind-qa.git
|
||||
- git clone --branch "${BIND_BASELINE_VERSION}" --depth 1 https://gitlab.isc.org/isc-projects/bind9.git refbind
|
||||
- cd refbind/
|
||||
- ./configure --without-make-clean
|
||||
- ./configure
|
||||
- make -j${BUILD_PARALLEL_JOBS:-1} V=1
|
||||
- cd ../bind-qa/bind9/respdiff
|
||||
- bash respdiff.sh -q "${PWD}/100k_mixed.txt" -c 3 -w "${PWD}/rspworkdir" "${CI_PROJECT_DIR}/refbind" "${CI_PROJECT_DIR}"
|
||||
@@ -1352,7 +1325,8 @@ abi-check:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
||||
BIND_BASELINE_VERSION: v9_17_2
|
||||
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
|
||||
BIND_BASELINE_VERSION: v9_17_4
|
||||
script:
|
||||
- *configure
|
||||
- make -j${BUILD_PARALLEL_JOBS:-1} V=1
|
||||
@@ -1372,3 +1346,37 @@ abi-check:
|
||||
only:
|
||||
- main@isc-projects/bind9
|
||||
- /^v9_[1-9][0-9]$/@isc-projects/bind9
|
||||
|
||||
gcov:
|
||||
<<: *base_image
|
||||
stage: build
|
||||
needs:
|
||||
- job: autoreconf
|
||||
artifacts: true
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "${CFLAGS_COMMON} --coverage -O0"
|
||||
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
|
||||
script:
|
||||
- *configure
|
||||
- *setup_interfaces
|
||||
- *setup_softhsm
|
||||
- make -j${BUILD_PARALLEL_JOBS:-1} -k all V=1
|
||||
- make -j${TEST_PARALLEL_JOBS:-1} -k unit V=1 || true
|
||||
- make -C bin/tests/system -j${TEST_PARALLEL_JOBS:-1} -k check V=1 || cat bin/tests/system/test-suite.log
|
||||
# *.gcno and *.gcda files generated for shared library objects are created
|
||||
# in directories in which gcovr is unable to process them properly
|
||||
# (.../.libs/...). Move such *.gcno and *.gcda files one level higher.
|
||||
- find . -regex ".*/\.libs/.*\.\(gcda\|gcno\)" -execdir mv "{}" .. \;
|
||||
# Help gcovr process the nasty tricks in lib/dns/code.h, where we include C
|
||||
# source files from lib/dns/rdata/*/, using an even nastier trick.
|
||||
- find lib/dns/rdata/* -name "*.c" -execdir cp -f "{}" ../../ \;
|
||||
- gcovr --root . --exclude-directories bin/tests --exclude-directories doc --exclude-directories libltdl --exclude-directories lib/samples --exclude 'lib/.*/tests/.*' --html-details -o coverage.html
|
||||
- gcovr --root . --exclude-directories bin/tests --exclude-directories doc --exclude-directories libltdl --exclude-directories lib/samples --exclude 'lib/.*/tests/.*' -o coverage.txt
|
||||
- tail -n 3 coverage.txt
|
||||
artifacts:
|
||||
paths:
|
||||
- coverage*.html
|
||||
only:
|
||||
- main@isc-projects/bind9
|
||||
- /^v9_[1-9][0-9]$/@isc-projects/bind9
|
||||
|
||||
@@ -67,6 +67,7 @@
|
||||
- [ ] ***(SwEng)*** Push tags for the published releases to the public repository.
|
||||
- [ ] ***(QA)*** For each maintained branch, update the `BIND_BASELINE_VERSION` variable for the `abi-check` job in `.gitlab-ci.yml` to the latest published BIND version tag for a given branch.
|
||||
- [ ] ***(QA)*** Prepare empty release notes for the next set of releases.
|
||||
- [ ] ***(QA)*** Sanitize all confidential issues assigned to the release milestone and make them public.
|
||||
- [ ] ***(QA)*** Update QA tools used in GitLab CI (e.g. Flake8, PyLint) by modifying the relevant `Dockerfile`.
|
||||
|
||||
[^1]: If not, use the time remaining until the tagging deadline to ensure all outstanding issues are either resolved or moved to a different milestone.
|
||||
|
||||
@@ -1,15 +1,185 @@
|
||||
5461. [bug] The header STALE attribute was not being updated with
|
||||
the write lock being held leading to incorrect
|
||||
statistics. Convert the header attributes to use atomic
|
||||
operations. [GL #1475]
|
||||
5503. [bug] Cleaned up reference counting of network manager
|
||||
handles, now using isc_nmhandle_attach() and _detach()
|
||||
instead of _ref() and _unref(). [GL #2122]
|
||||
|
||||
5502. [func] 'dig +bufsize=0' no longer disables EDNS. [GL #2054]
|
||||
|
||||
5501. [func] Log CDS/CDNSKEY publication. [GL #1748]
|
||||
|
||||
5500. [bug] Fix (non-)publication of CDS and CDNSKEY records.
|
||||
[GL #2103]
|
||||
|
||||
5499. [func] Add '-P ds' and '-D ds' arguments to dnssec-settime.
|
||||
|
||||
5498. [test] The --with-gperftools-profiler configure option was
|
||||
removed. [GL !4045]
|
||||
|
||||
5497. [placeholder]
|
||||
|
||||
5496. [bug] The rate limiter needs to hold a reference to its task.
|
||||
[GL #2081]
|
||||
|
||||
5495. [bug] With query minimization enabled, named failed to
|
||||
resolve ip6.arpa. names that had more labels after the
|
||||
IPv6 part. [GL #1847]
|
||||
|
||||
5494. [bug] Silence the EPROTO syslog message on older systems.
|
||||
[GL #1928]
|
||||
|
||||
5493. [bug] Fix off-by-one error when calculating new hashtable
|
||||
size. [GL #2104]
|
||||
|
||||
5492. [bug] Tighten LOC parsing to reject period and/or m as a
|
||||
value. Correct handling of negative altitudes which
|
||||
are not whole metres. [GL #2074]
|
||||
|
||||
5491. [bug] rbtversion->glue_table_size could be read without the
|
||||
appropriate lock being held. [GL #2080]
|
||||
|
||||
5490. [func] Refactor the readline support to use pkg-config and
|
||||
add support for editline library. [GL !3942]
|
||||
|
||||
5489. [bug] Named failed to reject some invalid records resulting
|
||||
in records that, after being printed, could not be
|
||||
loaded or would result in DNSSEC validation failures
|
||||
when re-read from zone files as the wire format
|
||||
differed. The covered records records are: CERT,
|
||||
IPSECKEY, NSEC3, NSEC3PARAM, NXT, SIG, TLSA, WKS, and
|
||||
X25. [GL !3953]
|
||||
|
||||
5488. [bug] nta needed to have a weak reference on view to prevent
|
||||
the view being deleted while nta tests are being
|
||||
performed. [GL #2067]
|
||||
|
||||
5487. [cleanup] Update managed keys log messages to be less confusing.
|
||||
[GL #2027]
|
||||
|
||||
5486. [func] Add 'rndc dnssec -checkds' command to tell named
|
||||
that the DS record has been published in the parent.
|
||||
[GL #1613]
|
||||
|
||||
--- 9.17.4 released ---
|
||||
|
||||
5485. [placeholder]
|
||||
|
||||
5484. [func] Expire zero TTL records quickly rather than using them
|
||||
for stale answers. [GL #1829]
|
||||
|
||||
5483. [func] Keeping "stale" answers in cache has been disabled by
|
||||
default and can be re-enabled with a new configuration
|
||||
option "stale-cache-enable". [GL #1712]
|
||||
|
||||
5482. [bug] If the Duplicate Address Detection (DAD) mechanism had
|
||||
not yet finished after adding a new IPv6 address to the
|
||||
system, BIND 9 would fail to bind to IPv6 addresses in a
|
||||
tentative state. [GL #2038]
|
||||
|
||||
5481. [security] "update-policy" rules of type "subdomain" were
|
||||
incorrectly treated as "zonesub" rules, which allowed
|
||||
keys used in "subdomain" rules to update names outside
|
||||
of the specified subdomains. The problem was fixed by
|
||||
making sure "subdomain" rules are again processed as
|
||||
described in the ARM. (CVE-2020-8624) [GL #2055]
|
||||
|
||||
5480. [security] When BIND 9 was compiled with native PKCS#11 support, it
|
||||
was possible to trigger an assertion failure in code
|
||||
determining the number of bits in the PKCS#11 RSA public
|
||||
key with a specially crafted packet. (CVE-2020-8623)
|
||||
[GL #2037]
|
||||
|
||||
5479. [security] named could crash in certain query resolution scenarios
|
||||
where QNAME minimization and forwarding were both
|
||||
enabled. (CVE-2020-8621) [GL #1997]
|
||||
|
||||
5478. [security] It was possible to trigger an assertion failure by
|
||||
sending a specially crafted large TCP DNS message.
|
||||
(CVE-2020-8620) [GL #1996]
|
||||
|
||||
5477. [bug] The idle timeout for connected TCP sockets, which was
|
||||
previously set to a high fixed value, is now derived
|
||||
from the client query processing timeout configured for
|
||||
a resolver. [GL #2024]
|
||||
|
||||
5476. [security] It was possible to trigger an assertion failure when
|
||||
verifying the response to a TSIG-signed request.
|
||||
(CVE-2020-8622) [GL #2028]
|
||||
|
||||
5475. [bug] Wildcard RPZ passthru rules could incorrectly be
|
||||
overridden by other rules that were loaded from RPZ
|
||||
zones which appeared later in the "response-policy"
|
||||
statement. This has been fixed. [GL #1619]
|
||||
|
||||
5474. [bug] dns_rdata_hip_next() failed to return ISC_R_NOMORE
|
||||
when it should have. [GL !3880]
|
||||
|
||||
5473. [func] The RBT hash table implementation has been changed
|
||||
to use a faster hash function (HalfSipHash2-4) and
|
||||
Fibonacci hashing for better distribution. Setting
|
||||
"max-cache-size" now preallocates a fixed-size hash
|
||||
table so that rehashing does not cause resolution
|
||||
brownouts while the hash table is grown. [GL #1775]
|
||||
|
||||
5472. [func] The statistics channel has been updated to use the
|
||||
new network manager. [GL #2022]
|
||||
|
||||
5471. [bug] The introduction of KASP support inadvertently caused
|
||||
the second field of "sig-validity-interval" to always be
|
||||
calculated in hours, even in cases when it should have
|
||||
been calculated in days. This has been fixed. (Thanks to
|
||||
Tony Finch.) [GL !3735]
|
||||
|
||||
5470. [port] gsskrb5_register_acceptor_identity() is now only called
|
||||
if gssapi_krb5.h is present. [GL #1995]
|
||||
|
||||
5469. [port] On illumos, a constant called SEC is already defined in
|
||||
<sys/time.h>, which conflicts with an identically named
|
||||
constant in libbind9. This conflict has been resolved.
|
||||
[GL #1993]
|
||||
|
||||
5468. [bug] Addressed potential double unlock in process_fd().
|
||||
[GL #2005]
|
||||
|
||||
5467. [func] The control channel and the rndc utility have been
|
||||
updated to use the new network manager. To support
|
||||
this, the network manager was updated to enable
|
||||
the initiation of client TCP connections. Its
|
||||
internal reference counting has been refactored.
|
||||
|
||||
Note: As a side effect of this change, rndc cannot
|
||||
currently be used with UNIX-domain sockets, and its
|
||||
default timeout has changed from 60 seconds to 30.
|
||||
These will be addressed in a future release.
|
||||
[GL #1759]
|
||||
|
||||
5466. [bug] Addressed an error in recursive clients stats reporting.
|
||||
[GL #1719]
|
||||
|
||||
5465. [func] Added fallback to built-in trust-anchors, managed-keys,
|
||||
or trusted-keys if the bindkeys-file (bind.keys) cannot
|
||||
be parsed. [GL #1235]
|
||||
|
||||
5464. [bug] Requesting more than 128 files to be saved when rolling
|
||||
dnstap log files caused a buffer overflow. This has been
|
||||
fixed. [GL #1989]
|
||||
|
||||
5463. [placeholder]
|
||||
|
||||
5462. [bug] Move LMDB locking from LMDB itself to named. [GL #1976]
|
||||
|
||||
5461. [bug] The STALE rdataset header attribute was updated while
|
||||
the write lock was not being held, leading to incorrect
|
||||
statistics. The header attributes are now converted to
|
||||
use atomic operations. [GL #1475]
|
||||
|
||||
5460. [cleanup] tsig-keygen was previously an alias for
|
||||
ddns-confgen and was documented in the ddns-confgen
|
||||
man page. This has been reversed; tsig-keygen is
|
||||
now the primary name. [GL #1998]
|
||||
|
||||
5459. [bug] Bad isc_mem_put() size when an invalid type was
|
||||
specified in a update-policy rule. [GL #1990]
|
||||
5459. [bug] Fixed bad isc_mem_put() size when an invalid type was
|
||||
specified in an "update-policy" rule. [GL #1990]
|
||||
|
||||
--- 9.17.3 released ---
|
||||
|
||||
5458. [bug] Prevent a theoretically possible NULL dereference caused
|
||||
by a data race between zone_maintenance() and
|
||||
@@ -19,23 +189,21 @@
|
||||
|
||||
5456. [func] Added "primaries" as a synonym for "masters" in
|
||||
named.conf, and "primary-only" as a synonym for
|
||||
"master-only" in the parameters to "notify",
|
||||
in order to bring terminology up to date with
|
||||
RFC 8499. [GL #1948]
|
||||
"master-only" in the parameters to "notify", to bring
|
||||
terminology up-to-date with RFC 8499. [GL #1948]
|
||||
|
||||
5455. [bug] `named` could crash when cleaning dead nodes
|
||||
in lib/dns/rbtdb.c that have been reused meanwhile.
|
||||
[GL #1968]
|
||||
5455. [bug] named could crash when cleaning dead nodes in
|
||||
lib/dns/rbtdb.c that were being reused. [GL #1968]
|
||||
|
||||
5454. [bug] Address a startup crash happening when server is
|
||||
under load and root zone is not yet loaded. [GL #1862]
|
||||
5454. [bug] Address a startup crash that occurred when the server
|
||||
was under load and the root zone had not yet been
|
||||
loaded. [GL #1862]
|
||||
|
||||
5453. [bug] `named` would crash on shutdown when new `rndc`
|
||||
connection is received at the same time as
|
||||
shutting down. [GL #1747]
|
||||
5453. [bug] named crashed on shutdown when a new rndc connection was
|
||||
received during shutdown. [GL #1747]
|
||||
|
||||
5452. [bug] The "blackhole" ACL was accidentally disabled with
|
||||
respect to client queries. [GL #1936]
|
||||
5452. [bug] The "blackhole" ACL was accidentally disabled for client
|
||||
queries. [GL #1936]
|
||||
|
||||
5451. [func] Add 'rndc dnssec -status' command. [GL #1612]
|
||||
|
||||
@@ -53,14 +221,14 @@
|
||||
|
||||
5446. [bug] The validator could fail to accept a properly signed
|
||||
RRset if an unsupported algorithm appeared earlier in
|
||||
the DNSKEY RRset than a supported algorithm. It could
|
||||
the DNSKEY RRset than a supported algorithm. It could
|
||||
also stop if it detected a malformed public key.
|
||||
[GL #1689]
|
||||
|
||||
5445. [cleanup] Disable and disallow static linking. [GL #1933]
|
||||
|
||||
5444. [bug] 'rndc dnstap -roll <value>' was not limiting the
|
||||
number of saved files to <value>. [GL !3728]
|
||||
5444. [bug] 'rndc dnstap -roll <value>' did not limit the number of
|
||||
saved files to <value>. [GL !3728]
|
||||
|
||||
5443. [bug] The "primary" and "secondary" keywords, when used
|
||||
as parameters for "check-names", were not
|
||||
@@ -73,8 +241,8 @@
|
||||
|
||||
5440. [placeholder]
|
||||
|
||||
5439. [bug] The dsset returned by dns_keynode_dsset() was not
|
||||
thread safe. [GL #1926]
|
||||
5439. [bug] The DS RRset returned by dns_keynode_dsset() was used in
|
||||
a non-thread-safe manner. [GL #1926]
|
||||
|
||||
--- 9.17.2 released ---
|
||||
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
include $(top_srcdir)/Makefile.top
|
||||
|
||||
SUBDIRS = . libltdl lib doc bin
|
||||
SUBDIRS = . libltdl lib doc bin fuzz
|
||||
|
||||
BUILT_SOURCES = bind.keys.h
|
||||
CLEANFILES = bind.keys.h
|
||||
|
||||
@@ -33,6 +33,11 @@ LIBISC_CFLAGS += \
|
||||
$(LIBXML2_CFLAGS)
|
||||
endif HAVE_LIBXML2
|
||||
|
||||
if HAVE_READLINE
|
||||
LIBISC_CFLAGS += \
|
||||
$(READLINE_CFLAGS)
|
||||
endif HAVE_READLINE
|
||||
|
||||
LIBISC_LIBS = $(top_builddir)/lib/isc/libisc.la
|
||||
|
||||
LIBDNS_CFLAGS = \
|
||||
|
||||
@@ -185,9 +185,8 @@ command:
|
||||
Building on macOS assumes that the "Command Tools for Xcode" are installed.
|
||||
These can be downloaded from
|
||||
[https://developer.apple.com/download/more/](https://developer.apple.com/download/more/)
|
||||
or, if you have Xcode already installed, you can run
|
||||
`xcode-select--install`. (Note that an Apple ID may be required to access the download
|
||||
page.)
|
||||
or, if you have Xcode already installed, you can run `xcode-select --install`.
|
||||
(Note that an Apple ID may be required to access the download page.)
|
||||
|
||||
#### <a name="dependencies"> Dependencies
|
||||
|
||||
@@ -208,9 +207,6 @@ installed:
|
||||
|
||||
To see a full list of configuration options, run `configure --help`.
|
||||
|
||||
To build shared libraries, specify `--with-libtool` on the `configure`
|
||||
command line.
|
||||
|
||||
For the server to support DNSSEC, you need to build it with crypto support.
|
||||
To use OpenSSL, you should have OpenSSL 1.0.2e or newer installed. If the
|
||||
OpenSSL library is installed in a nonstandard location, specify the prefix
|
||||
|
||||
@@ -28,7 +28,7 @@ tsig-keygen, ddns-confgen - TSIG key generation tool
|
||||
|
||||
Synopsis
|
||||
~~~~~~~~
|
||||
:program:`tsig-keygen` [**-a** algorithm] [**-h**] [**-r** randomfile] [**-s** name]
|
||||
:program:`tsig-keygen` [**-a** algorithm] [**-h**] [**-r** randomfile] [name]
|
||||
|
||||
:program:`ddns-confgen` [**-a** algorithm] [**-h**] [**-k** keyname] [**-q**] [**-r** randomfile] [**-s** name] [**-z** zone]
|
||||
|
||||
|
||||
+7
-3
@@ -25,6 +25,10 @@ libdighost_la_SOURCES = \
|
||||
|
||||
bin_PROGRAMS = dig host nslookup
|
||||
|
||||
nslookup_LDADD = \
|
||||
$(LDADD) \
|
||||
$(READLINE_LIB)
|
||||
nslookup_LDADD = \
|
||||
$(LDADD)
|
||||
|
||||
if HAVE_READLINE
|
||||
nslookup_LDADD += \
|
||||
$(READLINE_LIBS)
|
||||
endif HAVE_READLINE
|
||||
|
||||
+18
-18
@@ -185,7 +185,7 @@ help(void) {
|
||||
" +[no]besteffort (Try to parse even "
|
||||
"illegal "
|
||||
"messages)\n"
|
||||
" +bufsize=### (Set EDNS0 Max UDP packet "
|
||||
" +bufsize[=###] (Set EDNS0 Max UDP packet "
|
||||
"size)\n"
|
||||
" +[no]cdflag (Set checking disabled "
|
||||
"flag in query)\n"
|
||||
@@ -642,7 +642,6 @@ printmessage(dig_query_t *query, const isc_buffer_t *msgbuf, dns_message_t *msg,
|
||||
if (yaml) {
|
||||
enum { Q = 0x1, R = 0x2 }; /* Q:query; R:ecursive */
|
||||
unsigned int tflag = 0;
|
||||
isc_sockaddr_t saddr;
|
||||
char sockstr[ISC_SOCKADDR_FORMATSIZE];
|
||||
uint16_t sport;
|
||||
char *hash;
|
||||
@@ -713,10 +712,9 @@ printmessage(dig_query_t *query, const isc_buffer_t *msgbuf, dns_message_t *msg,
|
||||
printf(" response_port: %u\n", sport);
|
||||
}
|
||||
|
||||
if (query->sock != NULL &&
|
||||
isc_socket_getsockname(query->sock, &saddr) ==
|
||||
ISC_R_SUCCESS)
|
||||
{
|
||||
if (query->handle != NULL) {
|
||||
isc_sockaddr_t saddr =
|
||||
isc_nmhandle_localaddr(query->handle);
|
||||
sport = isc_sockaddr_getport(&saddr);
|
||||
isc_sockaddr_format(&saddr, sockstr, sizeof(sockstr));
|
||||
hash = strchr(sockstr, '#');
|
||||
@@ -1047,12 +1045,13 @@ plus_option(char *option, bool is_batchfile, dig_lookup_t *lookup) {
|
||||
break;
|
||||
case 'u': /* bufsize */
|
||||
FULLCHECK("bufsize");
|
||||
if (value == NULL) {
|
||||
goto need_value;
|
||||
}
|
||||
if (!state) {
|
||||
goto invalid_option;
|
||||
}
|
||||
if (value == NULL) {
|
||||
lookup->udpsize = DEFAULT_EDNS_BUFSIZE;
|
||||
break;
|
||||
}
|
||||
result = parse_uint(&num, value, COMMSIZE,
|
||||
"buffer size");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
@@ -1099,7 +1098,7 @@ plus_option(char *option, bool is_batchfile, dig_lookup_t *lookup) {
|
||||
case 'o': /* cookie */
|
||||
FULLCHECK("cookie");
|
||||
if (state && lookup->edns == -1) {
|
||||
lookup->edns = 0;
|
||||
lookup->edns = DEFAULT_EDNS_VERSION;
|
||||
}
|
||||
lookup->sendcookie = state;
|
||||
if (value != NULL) {
|
||||
@@ -1138,7 +1137,7 @@ plus_option(char *option, bool is_batchfile, dig_lookup_t *lookup) {
|
||||
FULLCHECK("dnssec");
|
||||
dnssec:
|
||||
if (state && lookup->edns == -1) {
|
||||
lookup->edns = 0;
|
||||
lookup->edns = DEFAULT_EDNS_VERSION;
|
||||
}
|
||||
lookup->dnssec = state;
|
||||
break;
|
||||
@@ -1190,7 +1189,8 @@ plus_option(char *option, bool is_batchfile, dig_lookup_t *lookup) {
|
||||
break;
|
||||
}
|
||||
if (value == NULL) {
|
||||
lookup->edns = 0;
|
||||
lookup->edns =
|
||||
DEFAULT_EDNS_VERSION;
|
||||
break;
|
||||
}
|
||||
result = parse_uint(&num, value,
|
||||
@@ -1405,7 +1405,7 @@ plus_option(char *option, bool is_batchfile, dig_lookup_t *lookup) {
|
||||
case 'i': /* nsid */
|
||||
FULLCHECK("nsid");
|
||||
if (state && lookup->edns == -1) {
|
||||
lookup->edns = 0;
|
||||
lookup->edns = DEFAULT_EDNS_VERSION;
|
||||
}
|
||||
lookup->nsid = state;
|
||||
break;
|
||||
@@ -1475,7 +1475,7 @@ plus_option(char *option, bool is_batchfile, dig_lookup_t *lookup) {
|
||||
case 'p':
|
||||
FULLCHECK("padding");
|
||||
if (state && lookup->edns == -1) {
|
||||
lookup->edns = 0;
|
||||
lookup->edns = DEFAULT_EDNS_VERSION;
|
||||
}
|
||||
if (value == NULL) {
|
||||
goto need_value;
|
||||
@@ -1661,7 +1661,7 @@ plus_option(char *option, bool is_batchfile, dig_lookup_t *lookup) {
|
||||
break;
|
||||
}
|
||||
if (lookup->edns == -1) {
|
||||
lookup->edns = 0;
|
||||
lookup->edns = DEFAULT_EDNS_VERSION;
|
||||
}
|
||||
if (lookup->ecs_addr != NULL) {
|
||||
isc_mem_free(mctx, lookup->ecs_addr);
|
||||
@@ -1967,10 +1967,10 @@ dash_option(char *option, char *next, dig_lookup_t **lookup,
|
||||
srcport = 0;
|
||||
}
|
||||
if (have_ipv6 && inet_pton(AF_INET6, value, &in6) == 1) {
|
||||
isc_sockaddr_fromin6(&bind_address, &in6, srcport);
|
||||
isc_sockaddr_fromin6(&localaddr, &in6, srcport);
|
||||
isc_net_disableipv4();
|
||||
} else if (have_ipv4 && inet_pton(AF_INET, value, &in4) == 1) {
|
||||
isc_sockaddr_fromin(&bind_address, &in4, srcport);
|
||||
isc_sockaddr_fromin(&localaddr, &in4, srcport);
|
||||
isc_net_disableipv6();
|
||||
} else {
|
||||
if (hash != NULL) {
|
||||
@@ -2276,7 +2276,7 @@ parse_args(bool is_batchfile, bool config_only, int argc, char **argv) {
|
||||
debug("making new lookup");
|
||||
default_lookup = make_empty_lookup();
|
||||
default_lookup->adflag = true;
|
||||
default_lookup->edns = 0;
|
||||
default_lookup->edns = DEFAULT_EDNS_VERSION;
|
||||
default_lookup->sendcookie = true;
|
||||
|
||||
#ifndef NOPOSIX
|
||||
|
||||
+4
-6
@@ -251,12 +251,10 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
This option attempts to display the contents of messages which are malformed. The
|
||||
default is to not display malformed answers.
|
||||
|
||||
``+bufsize=B``
|
||||
This option sets the UDP message buffer size advertised using EDNS0 to ``B``
|
||||
bytes. The maximum and minimum sizes of this buffer are 65535 and 0,
|
||||
respectively. Values outside this range are rounded up or down
|
||||
appropriately. Values other than zero cause an EDNS query to be
|
||||
sent.
|
||||
``+bufsize[=B]``
|
||||
This option sets the UDP message buffer size advertised using EDNS0 to
|
||||
``B`` bytes. The maximum and minimum sizes of this buffer are 65535 and
|
||||
0, respectively. ``+bufsize`` restores the default buffer size.
|
||||
|
||||
``+[no]cdflag``
|
||||
This option sets [or does not set] the CD (checking disabled) bit in the query. This
|
||||
|
||||
+334
-430
File diff suppressed because it is too large
Load Diff
+11
-5
@@ -71,6 +71,10 @@
|
||||
#define SERVER_TIMEOUT 1
|
||||
|
||||
#define LOOKUP_LIMIT 64
|
||||
|
||||
#define DEFAULT_EDNS_VERSION 0
|
||||
#define DEFAULT_EDNS_BUFSIZE 4096
|
||||
|
||||
/*%
|
||||
* Lookup_limit is just a limiter, keeping too many lookups from being
|
||||
* created. It's job is mainly to prevent the program from running away
|
||||
@@ -141,7 +145,7 @@ struct dig_lookup {
|
||||
dig_query_t *xfr_q;
|
||||
uint32_t retries;
|
||||
int nsfound;
|
||||
uint16_t udpsize;
|
||||
int16_t udpsize;
|
||||
int16_t edns;
|
||||
int16_t padding;
|
||||
uint32_t ixfr_serial;
|
||||
@@ -168,7 +172,7 @@ struct dig_query {
|
||||
unsigned int magic;
|
||||
dig_lookup_t *lookup;
|
||||
bool waiting_connect, pending_free, waiting_senddone, first_pass,
|
||||
first_soa_rcvd, second_rr_rcvd, first_repeat_rcvd, recv_made,
|
||||
first_soa_rcvd, second_rr_rcvd, first_repeat_rcvd,
|
||||
warn_id, timedout;
|
||||
uint32_t first_rr_serial;
|
||||
uint32_t second_rr_serial;
|
||||
@@ -177,9 +181,11 @@ struct dig_query {
|
||||
bool ixfr_axfr;
|
||||
char *servname;
|
||||
char *userarg;
|
||||
isc_buffer_t recvbuf, lengthbuf, tmpsendbuf, sendbuf;
|
||||
isc_buffer_t sendbuf;
|
||||
char *recvspace, *tmpsendspace, lengthspace[4];
|
||||
isc_socket_t *sock;
|
||||
isc_nmhandle_t *handle;
|
||||
isc_nmhandle_t *readhandle;
|
||||
isc_nmhandle_t *sendhandle;
|
||||
ISC_LINK(dig_query_t) link;
|
||||
ISC_LINK(dig_query_t) clink;
|
||||
isc_sockaddr_t sockaddr;
|
||||
@@ -221,7 +227,7 @@ extern int sendcount;
|
||||
extern int ndots;
|
||||
extern int lookup_counter;
|
||||
extern int exitcode;
|
||||
extern isc_sockaddr_t bind_address;
|
||||
extern isc_sockaddr_t localaddr;
|
||||
extern char keynametext[MXNAME];
|
||||
extern char keyfile[MXNAME];
|
||||
extern char keysecret[MXNAME];
|
||||
|
||||
+12
-42
@@ -22,6 +22,7 @@
|
||||
#include <isc/netaddr.h>
|
||||
#include <isc/parseint.h>
|
||||
#include <isc/print.h>
|
||||
#include <isc/readline.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/task.h>
|
||||
#include <isc/util.h>
|
||||
@@ -38,22 +39,6 @@
|
||||
|
||||
#include "dighost.h"
|
||||
|
||||
#if defined(HAVE_READLINE)
|
||||
#if defined(HAVE_EDIT_READLINE_READLINE_H)
|
||||
#include <edit/readline/readline.h>
|
||||
#if defined(HAVE_EDIT_READLINE_HISTORY_H)
|
||||
#include <edit/readline/history.h>
|
||||
#endif /* if defined(HAVE_EDIT_READLINE_HISTORY_H) */
|
||||
#elif defined(HAVE_EDITLINE_READLINE_H)
|
||||
#include <editline/readline.h>
|
||||
#elif defined(HAVE_READLINE_READLINE_H)
|
||||
#include <readline/readline.h>
|
||||
#if defined(HAVE_READLINE_HISTORY_H)
|
||||
#include <readline/history.h>
|
||||
#endif /* if defined(HAVE_READLINE_HISTORY_H) */
|
||||
#endif /* if defined(HAVE_EDIT_READLINE_READLINE_H) */
|
||||
#endif /* if defined(HAVE_READLINE) */
|
||||
|
||||
static bool short_form = true, tcpmode = false, tcpmode_set = false,
|
||||
identify = false, stats = true, comments = true,
|
||||
section_question = true, section_answer = true,
|
||||
@@ -787,7 +772,6 @@ addlookup(char *opt) {
|
||||
lookup->recurse = recurse;
|
||||
lookup->aaonly = aaonly;
|
||||
lookup->retries = tries;
|
||||
lookup->udpsize = 0;
|
||||
lookup->setqid = false;
|
||||
lookup->qid = 0;
|
||||
lookup->comments = comments;
|
||||
@@ -848,38 +832,27 @@ do_next_command(char *input) {
|
||||
|
||||
static void
|
||||
get_next_command(void) {
|
||||
char *buf;
|
||||
char *ptr;
|
||||
char cmdlinebuf[COMMSIZE];
|
||||
char *cmdline, *ptr = NULL;
|
||||
|
||||
fflush(stdout);
|
||||
buf = isc_mem_allocate(mctx, COMMSIZE);
|
||||
isc_app_block();
|
||||
if (interactive) {
|
||||
#ifdef HAVE_READLINE
|
||||
ptr = readline("> ");
|
||||
if (ptr != NULL) {
|
||||
cmdline = ptr = readline("> ");
|
||||
if (ptr != NULL && *ptr != 0) {
|
||||
add_history(ptr);
|
||||
}
|
||||
#else /* ifdef HAVE_READLINE */
|
||||
fprintf(stderr, "> ");
|
||||
fflush(stderr);
|
||||
ptr = fgets(buf, COMMSIZE, stdin);
|
||||
#endif /* ifdef HAVE_READLINE */
|
||||
} else {
|
||||
ptr = fgets(buf, COMMSIZE, stdin);
|
||||
cmdline = fgets(cmdlinebuf, COMMSIZE, stdin);
|
||||
}
|
||||
isc_app_unblock();
|
||||
if (ptr == NULL) {
|
||||
if (cmdline == NULL) {
|
||||
in_use = false;
|
||||
} else {
|
||||
do_next_command(ptr);
|
||||
do_next_command(cmdline);
|
||||
}
|
||||
#ifdef HAVE_READLINE
|
||||
if (interactive) {
|
||||
if (ptr != NULL) {
|
||||
free(ptr);
|
||||
}
|
||||
#endif /* ifdef HAVE_READLINE */
|
||||
isc_mem_free(mctx, buf);
|
||||
}
|
||||
|
||||
ISC_NORETURN static void
|
||||
@@ -942,13 +915,10 @@ flush_lookup_list(void) {
|
||||
while (l != NULL) {
|
||||
q = ISC_LIST_HEAD(l->q);
|
||||
while (q != NULL) {
|
||||
if (q->sock != NULL) {
|
||||
isc_socket_cancel(q->sock, NULL,
|
||||
ISC_SOCKCANCEL_ALL);
|
||||
isc_socket_detach(&q->sock);
|
||||
if (q->handle != NULL) {
|
||||
isc_nm_cancelread(q->handle);
|
||||
isc_nmhandle_detach(&q->handle);
|
||||
}
|
||||
isc_buffer_invalidate(&q->recvbuf);
|
||||
isc_buffer_invalidate(&q->lengthbuf);
|
||||
qp = q;
|
||||
q = ISC_LIST_NEXT(q, link);
|
||||
ISC_LIST_DEQUEUE(l->q, qp, link);
|
||||
|
||||
@@ -75,6 +75,8 @@ usage(void) {
|
||||
fprintf(stderr, "Timing options:\n");
|
||||
fprintf(stderr, " -P date/[+-]offset/none: set/unset key "
|
||||
"publication date\n");
|
||||
fprintf(stderr, " -P ds date/[+-]offset/none: set/unset "
|
||||
"DS publication date\n");
|
||||
fprintf(stderr, " -P sync date/[+-]offset/none: set/unset "
|
||||
"CDS and CDNSKEY publication date\n");
|
||||
fprintf(stderr, " -A date/[+-]offset/none: set/unset key "
|
||||
@@ -85,6 +87,8 @@ usage(void) {
|
||||
"inactivation date\n");
|
||||
fprintf(stderr, " -D date/[+-]offset/none: set/unset key "
|
||||
"deletion date\n");
|
||||
fprintf(stderr, " -D ds date/[+-]offset/none: set/unset "
|
||||
"DS deletion date\n");
|
||||
fprintf(stderr, " -D sync date/[+-]offset/none: set/unset "
|
||||
"CDS and CDNSKEY deletion date\n");
|
||||
fprintf(stderr, " -S <key>: generate a successor to an existing "
|
||||
@@ -243,6 +247,10 @@ main(int argc, char **argv) {
|
||||
bool unsetsyncadd = false, setsyncadd = false;
|
||||
bool unsetsyncdel = false, setsyncdel = false;
|
||||
bool printsyncadd = false, printsyncdel = false;
|
||||
isc_stdtime_t dsadd = 0, dsdel = 0;
|
||||
bool unsetdsadd = false, setdsadd = false;
|
||||
bool unsetdsdel = false, setdsdel = false;
|
||||
bool printdsadd = false, printdsdel = false;
|
||||
|
||||
options = DST_TYPE_PUBLIC | DST_TYPE_PRIVATE | DST_TYPE_STATE;
|
||||
|
||||
@@ -290,6 +298,18 @@ main(int argc, char **argv) {
|
||||
unsetsyncdel = !setsyncdel;
|
||||
break;
|
||||
}
|
||||
/* -Dds ? */
|
||||
if (isoptarg("ds", argv, usage)) {
|
||||
if (unsetdsdel || setdsdel) {
|
||||
fatal("-D ds specified more than once");
|
||||
}
|
||||
|
||||
changed = true;
|
||||
dsdel = strtotime(isc_commandline_argument, now,
|
||||
now, &setdsdel);
|
||||
unsetdsdel = !setdsdel;
|
||||
break;
|
||||
}
|
||||
/* -Ddnskey ? */
|
||||
(void)isoptarg("dnskey", argv, usage);
|
||||
if (setdel || unsetdel) {
|
||||
@@ -394,6 +414,19 @@ main(int argc, char **argv) {
|
||||
unsetsyncadd = !setsyncadd;
|
||||
break;
|
||||
}
|
||||
/* -Pds ? */
|
||||
if (isoptarg("ds", argv, usage)) {
|
||||
if (unsetdsadd || setdsadd) {
|
||||
fatal("-P ds specified more than once");
|
||||
}
|
||||
|
||||
changed = true;
|
||||
dsadd = strtotime(isc_commandline_argument, now,
|
||||
now, &setdsadd);
|
||||
unsetdsadd = !setdsadd;
|
||||
break;
|
||||
}
|
||||
/* -Pdnskey ? */
|
||||
(void)isoptarg("dnskey", argv, usage);
|
||||
if (setpub || unsetpub) {
|
||||
fatal("-P specified more than once");
|
||||
@@ -415,6 +448,8 @@ main(int argc, char **argv) {
|
||||
printdel = true;
|
||||
printsyncadd = true;
|
||||
printsyncdel = true;
|
||||
printdsadd = true;
|
||||
printdsdel = true;
|
||||
break;
|
||||
}
|
||||
|
||||
@@ -432,6 +467,11 @@ main(int argc, char **argv) {
|
||||
printsyncdel = true;
|
||||
break;
|
||||
}
|
||||
if (!strncmp(p, "ds", 2)) {
|
||||
p += 2;
|
||||
printdsdel = true;
|
||||
break;
|
||||
}
|
||||
printdel = true;
|
||||
break;
|
||||
case 'I':
|
||||
@@ -443,6 +483,11 @@ main(int argc, char **argv) {
|
||||
printsyncadd = true;
|
||||
break;
|
||||
}
|
||||
if (!strncmp(p, "ds", 2)) {
|
||||
p += 2;
|
||||
printdsadd = true;
|
||||
break;
|
||||
}
|
||||
printpub = true;
|
||||
break;
|
||||
case 'R':
|
||||
@@ -777,6 +822,18 @@ main(int argc, char **argv) {
|
||||
dst_key_unsettime(key, DST_TIME_SYNCDELETE);
|
||||
}
|
||||
|
||||
if (setdsadd) {
|
||||
dst_key_settime(key, DST_TIME_DSPUBLISH, dsadd);
|
||||
} else if (unsetdsadd) {
|
||||
dst_key_unsettime(key, DST_TIME_DSPUBLISH);
|
||||
}
|
||||
|
||||
if (setdsdel) {
|
||||
dst_key_settime(key, DST_TIME_DSDELETE, dsdel);
|
||||
} else if (unsetdsdel) {
|
||||
dst_key_unsettime(key, DST_TIME_DSDELETE);
|
||||
}
|
||||
|
||||
if (setttl) {
|
||||
dst_key_setttl(key, ttl);
|
||||
}
|
||||
@@ -894,6 +951,14 @@ main(int argc, char **argv) {
|
||||
stdout);
|
||||
}
|
||||
|
||||
if (printdsadd) {
|
||||
printtime(key, DST_TIME_DSPUBLISH, "DS Publish", epoch, stdout);
|
||||
}
|
||||
|
||||
if (printdsdel) {
|
||||
printtime(key, DST_TIME_DSDELETE, "DS Delete", epoch, stdout);
|
||||
}
|
||||
|
||||
if (changed) {
|
||||
writekey(key, directory, write_state);
|
||||
if (predecessor != NULL && prevkey != NULL) {
|
||||
|
||||
@@ -29,7 +29,7 @@ dnssec-settime: set the key timing metadata for a DNSSEC key
|
||||
Synopsis
|
||||
~~~~~~~~
|
||||
|
||||
:program:`dnssec-settime` [**-f**] [**-K** directory] [**-L** ttl] [**-P** date/offset] [**-P** sync date/offset] [**-A** date/offset] [**-R** date/offset] [**-I** date/offset] [**-D** date/offset] [**-D** sync date/offset] [**-S** key] [**-i** interval] [**-h**] [**-V**] [**-v** level] [**-E** engine] {keyfile} [**-s**] [**-g** state] [**-d** state date/offset] [**-k** state date/offset] [**-r** state date/offset] [**-z** state date/offset]
|
||||
:program:`dnssec-settime` [**-f**] [**-K** directory] [**-L** ttl] [**-P** date/offset] [**-P** ds date/offset] [**-P** sync date/offset] [**-A** date/offset] [**-R** date/offset] [**-I** date/offset] [**-D** date/offset] [**-D** ds date/offset] [**-D** sync date/offset] [**-S** key] [**-i** interval] [**-h**] [**-V**] [**-v** level] [**-E** engine] {keyfile} [**-s**] [**-g** state] [**-d** state date/offset] [**-k** state date/offset] [**-r** state date/offset] [**-z** state date/offset]
|
||||
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
@@ -126,6 +126,10 @@ explicitly prevent a date from being set, use ``none`` or ``never``.
|
||||
that date, the key is included in the zone but is not used
|
||||
to sign it.
|
||||
|
||||
``-P ds date/offset``
|
||||
This option sets the date on which DS records that match this key have been
|
||||
seen in the parent zone.
|
||||
|
||||
``-P sync date/offset``
|
||||
This option sets the date on which CDS and CDNSKEY records that match this key
|
||||
are to be published to the zone.
|
||||
@@ -149,6 +153,10 @@ explicitly prevent a date from being set, use ``none`` or ``never``.
|
||||
key is no longer included in the zone. (However, it may remain in the key
|
||||
repository.)
|
||||
|
||||
``-D ds date/offset``
|
||||
This option sets the date on which the DS records that match this key have
|
||||
been seen removed from the parent zone.
|
||||
|
||||
``-D sync date/offset``
|
||||
This option sets the date on which the CDS and CDNSKEY records that match this
|
||||
key are to be deleted.
|
||||
@@ -215,15 +223,16 @@ associated with a key.
|
||||
``-u``
|
||||
This option indicates that times should be printed in Unix epoch format.
|
||||
|
||||
``-p C/P/Psync/A/R/I/D/Dsync/all``
|
||||
This option prints a specific metadata value or set of metadata values. The ``-p``
|
||||
option may be followed by one or more of the following letters or
|
||||
``-p C/P/Pds/Psync/A/R/I/D/Dds/Dsync/all``
|
||||
This option prints a specific metadata value or set of metadata values.
|
||||
The ``-p`` option may be followed by one or more of the following letters or
|
||||
strings to indicate which value or values to print: ``C`` for the
|
||||
creation date, ``P`` for the publication date, ``Psync`` for the CDS
|
||||
and CDNSKEY publication date, ``A`` for the activation date, ``R``
|
||||
for the revocation date, ``I`` for the inactivation date, ``D`` for
|
||||
the deletion date, and ``Dsync`` for the CDS and CDNSKEY deletion
|
||||
date. To print all of the metadata, use ``all``.
|
||||
creation date, ``P`` for the publication date, ``Pds` for the DS publication
|
||||
date, ``Psync`` for the CDS and CDNSKEY publication date, ``A`` for the
|
||||
activation date, ``R`` for the revocation date, ``I`` for the inactivation
|
||||
date, ``D`` for the deletion date, ``Dds`` for the DS deletion date,
|
||||
and ``Dsync`` for the CDS and CDNSKEY deletion date. To print all of the
|
||||
metadata, use ``all``.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
@@ -15,6 +15,7 @@ AM_CPPFLAGS += \
|
||||
$(LMDB_CFLAGS) \
|
||||
$(MAXMINDDB_CFLAGS) \
|
||||
$(DNSTAP_CFLAGS) \
|
||||
$(LIBUV_CFLAGS) \
|
||||
$(ZLIB_CFLAGS)
|
||||
|
||||
if HAVE_JSON_C
|
||||
@@ -102,6 +103,7 @@ named_LDADD = \
|
||||
$(LMDB_LIBS) \
|
||||
$(MAXMINDDB_LIBS) \
|
||||
$(DNSTAP_LIBS) \
|
||||
$(LIBUV_LIBS) \
|
||||
$(LIBXML2_LIBS) \
|
||||
$(ZLIB_LIBS)
|
||||
|
||||
|
||||
@@ -196,6 +196,7 @@ options {\n\
|
||||
# sortlist <none>\n\
|
||||
stale-answer-enable false;\n\
|
||||
stale-answer-ttl 1; /* 1 second */\n\
|
||||
stale-cache-enable false;\n\
|
||||
synth-from-dnssec no;\n\
|
||||
# topology <none>\n\
|
||||
transfer-format many-answers;\n\
|
||||
|
||||
+434
-477
File diff suppressed because it is too large
Load Diff
@@ -143,6 +143,7 @@ EXTERN bool named_g_memstatistics INIT(false);
|
||||
EXTERN bool named_g_keepstderr INIT(false);
|
||||
|
||||
EXTERN unsigned int named_g_tat_interval INIT(24 * 3600);
|
||||
EXTERN unsigned int named_g_maxcachesize INIT(0);
|
||||
|
||||
#if defined(HAVE_GEOIP2)
|
||||
EXTERN dns_geoip_databases_t *named_g_geoip INIT(NULL);
|
||||
|
||||
@@ -38,6 +38,7 @@
|
||||
#define NAMED_EVENTCLASS ISC_EVENTCLASS(0x4E43)
|
||||
#define NAMED_EVENT_RELOAD (NAMED_EVENTCLASS + 0)
|
||||
#define NAMED_EVENT_DELZONE (NAMED_EVENTCLASS + 1)
|
||||
#define NAMED_EVENT_COMMAND (NAMED_EVENTCLASS + 2)
|
||||
|
||||
/*%
|
||||
* Name server state. Better here than in lots of separate global variables.
|
||||
@@ -80,8 +81,6 @@ struct named_server {
|
||||
uint32_t interface_interval;
|
||||
uint32_t heartbeat_interval;
|
||||
|
||||
isc_mutex_t reload_event_lock;
|
||||
isc_event_t * reload_event;
|
||||
named_reload_t reload_status;
|
||||
|
||||
bool flushonshutdown;
|
||||
|
||||
@@ -16,6 +16,7 @@
|
||||
#include <stdbool.h>
|
||||
#include <stdlib.h>
|
||||
#include <string.h>
|
||||
#include <uv.h>
|
||||
|
||||
#include <isc/app.h>
|
||||
#include <isc/attributes.h>
|
||||
@@ -525,6 +526,9 @@ printversion(bool verbose) {
|
||||
printf("linked to OpenSSL version: %s\n",
|
||||
SSLeay_version(SSLEAY_VERSION));
|
||||
#endif /* OPENSSL_VERSION_NUMBER >= 0x10100000L */
|
||||
printf("compiled with libuv version: %d.%d.%d\n", UV_VERSION_MAJOR,
|
||||
UV_VERSION_MINOR, UV_VERSION_PATCH);
|
||||
printf("linked to libuv version: %s\n", uv_version_string());
|
||||
#ifdef HAVE_LIBXML2
|
||||
printf("compiled with libxml2 version: %s\n", LIBXML_DOTTED_VERSION);
|
||||
printf("linked to libxml2 version: %s\n", xmlParserVersion);
|
||||
@@ -646,6 +650,8 @@ parse_T_opt(char *option) {
|
||||
named_g_nosyslog = true;
|
||||
} else if (!strcmp(option, "notcp")) {
|
||||
notcp = true;
|
||||
} else if (!strncmp(option, "maxcachesize=", 13)) {
|
||||
named_g_maxcachesize = atoi(option + 13);
|
||||
} else if (!strcmp(option, "maxudp512")) {
|
||||
maxudp = 512;
|
||||
} else if (!strcmp(option, "maxudp1460")) {
|
||||
|
||||
@@ -68,7 +68,6 @@ DNSSEC-POLICY
|
||||
max-zone-ttl duration;
|
||||
parent-ds-ttl duration;
|
||||
parent-propagation-delay duration;
|
||||
parent-registration-delay duration;
|
||||
publish-safety duration;
|
||||
retire-safety duration;
|
||||
signatures-refresh duration;
|
||||
@@ -401,6 +400,7 @@ OPTIONS
|
||||
stacksize ( default | unlimited | sizeval );
|
||||
stale-answer-enable boolean;
|
||||
stale-answer-ttl duration;
|
||||
stale-cache-enable boolean;
|
||||
startup-notify-rate integer;
|
||||
statistics-file quoted_string;
|
||||
synth-from-dnssec boolean;
|
||||
@@ -785,6 +785,7 @@ VIEW
|
||||
sortlist { address_match_element; ... };
|
||||
stale-answer-enable boolean;
|
||||
stale-answer-ttl duration;
|
||||
stale-cache-enable boolean;
|
||||
synth-from-dnssec boolean;
|
||||
transfer-format ( many-answers | one-answer );
|
||||
transfer-source ( ipv4_address | * ) [ port ( integer | * ) ] [
|
||||
|
||||
+276
-86
@@ -89,6 +89,7 @@
|
||||
#include <dns/secalg.h>
|
||||
#include <dns/soa.h>
|
||||
#include <dns/stats.h>
|
||||
#include <dns/time.h>
|
||||
#include <dns/tkey.h>
|
||||
#include <dns/tsig.h>
|
||||
#include <dns/ttl.h>
|
||||
@@ -3895,7 +3896,7 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
||||
uint32_t max_cache_size_percent = 0;
|
||||
size_t max_adb_size;
|
||||
uint32_t lame_ttl, fail_ttl;
|
||||
uint32_t max_stale_ttl;
|
||||
uint32_t max_stale_ttl = 0;
|
||||
dns_tsig_keyring_t *ring = NULL;
|
||||
dns_view_t *pview = NULL; /* Production view */
|
||||
isc_mem_t *cmctx = NULL, *hmctx = NULL;
|
||||
@@ -4113,7 +4114,16 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
||||
obj = NULL;
|
||||
result = named_config_get(maps, "max-cache-size", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
if (cfg_obj_isstring(obj)) {
|
||||
/*
|
||||
* If "-T maxcachesize=..." is in effect, it overrides any other
|
||||
* "max-cache-size" setting found in configuration, either implicit or
|
||||
* explicit. For simplicity, the value passed to that command line
|
||||
* option is always treated as the number of bytes to set
|
||||
* "max-cache-size" to.
|
||||
*/
|
||||
if (named_g_maxcachesize != 0) {
|
||||
max_cache_size = named_g_maxcachesize;
|
||||
} else if (cfg_obj_isstring(obj)) {
|
||||
str = cfg_obj_asstring(obj);
|
||||
INSIST(strcasecmp(str, "unlimited") == 0);
|
||||
max_cache_size = 0;
|
||||
@@ -4358,9 +4368,18 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
||||
view->synthfromdnssec = cfg_obj_asboolean(obj);
|
||||
|
||||
obj = NULL;
|
||||
result = named_config_get(maps, "max-stale-ttl", &obj);
|
||||
result = named_config_get(maps, "stale-cache-enable", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
max_stale_ttl = ISC_MAX(cfg_obj_asduration(obj), 1);
|
||||
if (cfg_obj_asboolean(obj)) {
|
||||
obj = NULL;
|
||||
result = named_config_get(maps, "max-stale-ttl", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
max_stale_ttl = ISC_MAX(cfg_obj_asduration(obj), 1);
|
||||
}
|
||||
/*
|
||||
* If 'stale-cache-enable' is false, max_stale_ttl is set to 0,
|
||||
* meaning keeping stale RRsets in cache is disabled.
|
||||
*/
|
||||
|
||||
obj = NULL;
|
||||
result = named_config_get(maps, "stale-answer-enable", &obj);
|
||||
@@ -7574,6 +7593,8 @@ count_newzones(dns_view_t *view, ns_cfgctx_t *nzcfg, int *num_zonesp) {
|
||||
|
||||
REQUIRE(num_zonesp != NULL);
|
||||
|
||||
LOCK(&view->new_zone_lock);
|
||||
|
||||
CHECK(migrate_nzf(view));
|
||||
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
@@ -7596,6 +7617,8 @@ cleanup:
|
||||
*num_zonesp = 0;
|
||||
}
|
||||
|
||||
UNLOCK(&view->new_zone_lock);
|
||||
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
@@ -7924,6 +7947,8 @@ typedef isc_result_t (*newzone_cfg_cb_t)(const cfg_obj_t *zconfig,
|
||||
* Immediately interrupt processing if an error is encountered while
|
||||
* transforming NZD data into a zone configuration object or if "callback"
|
||||
* returns an error.
|
||||
*
|
||||
* Caller must hold 'view->new_zone_lock'.
|
||||
*/
|
||||
static isc_result_t
|
||||
for_all_newzone_cfgs(newzone_cfg_cb_t callback, cfg_obj_t *config,
|
||||
@@ -8032,8 +8057,11 @@ configure_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
LOCK(&view->new_zone_lock);
|
||||
|
||||
result = nzd_open(view, MDB_RDONLY, &txn, &dbi);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
UNLOCK(&view->new_zone_lock);
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
@@ -8059,6 +8087,9 @@ configure_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
}
|
||||
|
||||
(void)nzd_close(&txn, false);
|
||||
|
||||
UNLOCK(&view->new_zone_lock);
|
||||
|
||||
return (result);
|
||||
}
|
||||
|
||||
@@ -8079,6 +8110,8 @@ get_newzone_config(dns_view_t *view, const char *zonename,
|
||||
|
||||
INSIST(zoneconfig != NULL && *zoneconfig == NULL);
|
||||
|
||||
LOCK(&view->new_zone_lock);
|
||||
|
||||
CHECK(nzd_open(view, MDB_RDONLY, &txn, &dbi));
|
||||
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
@@ -8112,6 +8145,8 @@ get_newzone_config(dns_view_t *view, const char *zonename,
|
||||
cleanup:
|
||||
(void)nzd_close(&txn, false);
|
||||
|
||||
UNLOCK(&view->new_zone_lock);
|
||||
|
||||
if (zoneconf != NULL) {
|
||||
cfg_obj_destroy(named_g_addparser, &zoneconf);
|
||||
}
|
||||
@@ -8362,7 +8397,14 @@ load_configuration(const char *filename, named_server_t *server,
|
||||
|
||||
result = cfg_parse_file(bindkeys_parser, server->bindkeysfile,
|
||||
&cfg_type_bindkeys, &bindkeys);
|
||||
CHECK(result);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
|
||||
"unable to parse '%s' error '%s'; using "
|
||||
"built-in keys instead",
|
||||
server->bindkeysfile,
|
||||
isc_result_totext(result));
|
||||
}
|
||||
} else {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
|
||||
@@ -9641,7 +9683,7 @@ load_zones(named_server_t *server, bool init, bool reconfig) {
|
||||
isc_refcount_increment(&zl->refs);
|
||||
result = dns_view_asyncload(view, reconfig, view_loaded, zl);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
(void)isc_refcount_decrement(&zl->refs);
|
||||
isc_refcount_decrement1(&zl->refs);
|
||||
goto cleanup;
|
||||
}
|
||||
}
|
||||
@@ -9913,14 +9955,6 @@ named_server_create(isc_mem_t *mctx, named_server_t **serverp) {
|
||||
&server->in_roothints),
|
||||
"setting up root hints");
|
||||
|
||||
isc_mutex_init(&server->reload_event_lock);
|
||||
|
||||
server->reload_event = isc_event_allocate(
|
||||
named_g_mctx, server, NAMED_EVENT_RELOAD, named_server_reload,
|
||||
server, sizeof(isc_event_t));
|
||||
CHECKFATAL(server->reload_event == NULL ? ISC_R_NOMEMORY
|
||||
: ISC_R_SUCCESS,
|
||||
"allocating reload event");
|
||||
server->reload_status = NAMED_RELOAD_IN_PROGRESS;
|
||||
|
||||
/*
|
||||
@@ -10090,9 +10124,6 @@ named_server_destroy(named_server_t **serverp) {
|
||||
|
||||
dst_lib_destroy();
|
||||
|
||||
isc_event_free(&server->reload_event);
|
||||
isc_mutex_destroy(&server->reload_event_lock);
|
||||
|
||||
INSIST(ISC_LIST_EMPTY(server->kasplist));
|
||||
INSIST(ISC_LIST_EMPTY(server->viewlist));
|
||||
INSIST(ISC_LIST_EMPTY(server->cachelist));
|
||||
@@ -10104,7 +10135,7 @@ named_server_destroy(named_server_t **serverp) {
|
||||
|
||||
static void
|
||||
fatal(named_server_t *server, const char *msg, isc_result_t result) {
|
||||
if (server != NULL) {
|
||||
if (server != NULL && server->task != NULL) {
|
||||
/*
|
||||
* Prevent races between the OpenSSL on_exit registered
|
||||
* function and any other OpenSSL calls from other tasks
|
||||
@@ -10270,7 +10301,7 @@ cleanup:
|
||||
*/
|
||||
static void
|
||||
named_server_reload(isc_task_t *task, isc_event_t *event) {
|
||||
named_server_t *server = (named_server_t *)event->ev_arg;
|
||||
named_server_t *server = (named_server_t *)event->ev_sender;
|
||||
|
||||
INSIST(task == server->task);
|
||||
UNUSED(task);
|
||||
@@ -10280,19 +10311,15 @@ named_server_reload(isc_task_t *task, isc_event_t *event) {
|
||||
"received SIGHUP signal to reload zones");
|
||||
(void)reload(server);
|
||||
|
||||
LOCK(&server->reload_event_lock);
|
||||
INSIST(server->reload_event == NULL);
|
||||
server->reload_event = event;
|
||||
UNLOCK(&server->reload_event_lock);
|
||||
isc_event_free(&event);
|
||||
}
|
||||
|
||||
void
|
||||
named_server_reloadwanted(named_server_t *server) {
|
||||
LOCK(&server->reload_event_lock);
|
||||
if (server->reload_event != NULL) {
|
||||
isc_task_send(server->task, &server->reload_event);
|
||||
}
|
||||
UNLOCK(&server->reload_event_lock);
|
||||
isc_event_t *event = isc_event_allocate(
|
||||
named_g_mctx, server, NAMED_EVENT_RELOAD, named_server_reload,
|
||||
NULL, sizeof(isc_event_t));
|
||||
isc_task_send(server->task, &event);
|
||||
}
|
||||
|
||||
void
|
||||
@@ -12063,12 +12090,10 @@ cleanup:
|
||||
|
||||
isc_result_t
|
||||
named_server_tsiglist(named_server_t *server, isc_buffer_t **text) {
|
||||
isc_result_t result;
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
dns_view_t *view;
|
||||
unsigned int foundkeys = 0;
|
||||
|
||||
result = isc_task_beginexclusive(server->task);
|
||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
for (view = ISC_LIST_HEAD(server->viewlist); view != NULL;
|
||||
view = ISC_LIST_NEXT(view, link))
|
||||
{
|
||||
@@ -12077,7 +12102,6 @@ named_server_tsiglist(named_server_t *server, isc_buffer_t **text) {
|
||||
&foundkeys);
|
||||
RWUNLOCK(&view->statickeys->lock, isc_rwlocktype_read);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
isc_task_endexclusive(server->task);
|
||||
return (result);
|
||||
}
|
||||
RWLOCK(&view->dynamickeys->lock, isc_rwlocktype_read);
|
||||
@@ -12085,11 +12109,9 @@ named_server_tsiglist(named_server_t *server, isc_buffer_t **text) {
|
||||
&foundkeys);
|
||||
RWUNLOCK(&view->dynamickeys->lock, isc_rwlocktype_read);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
isc_task_endexclusive(server->task);
|
||||
return (result);
|
||||
}
|
||||
}
|
||||
isc_task_endexclusive(server->task);
|
||||
|
||||
if (foundkeys == 0) {
|
||||
CHECK(putstr(text, "no tsig keys found."));
|
||||
@@ -12569,8 +12591,6 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
||||
|
||||
nzd_setkey(&key, dns_zone_getorigin(zone), namebuf, sizeof(namebuf));
|
||||
|
||||
LOCK(&view->new_zone_lock);
|
||||
|
||||
if (zconfig == NULL) {
|
||||
/* We're deleting the zone from the database */
|
||||
status = mdb_del(*txnp, dbi, &key, NULL);
|
||||
@@ -12650,8 +12670,6 @@ cleanup:
|
||||
}
|
||||
*txnp = NULL;
|
||||
|
||||
UNLOCK(&view->new_zone_lock);
|
||||
|
||||
if (text != NULL) {
|
||||
isc_buffer_free(&text);
|
||||
}
|
||||
@@ -12659,6 +12677,11 @@ cleanup:
|
||||
return (result);
|
||||
}
|
||||
|
||||
/*
|
||||
* Check whether the new zone database for 'view' can be opened for writing.
|
||||
*
|
||||
* Caller must hold 'view->new_zone_lock'.
|
||||
*/
|
||||
static isc_result_t
|
||||
nzd_writable(dns_view_t *view) {
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
@@ -12688,6 +12711,11 @@ nzd_writable(dns_view_t *view) {
|
||||
return (result);
|
||||
}
|
||||
|
||||
/*
|
||||
* Open the new zone database for 'view' and start a transaction for it.
|
||||
*
|
||||
* Caller must hold 'view->new_zone_lock'.
|
||||
*/
|
||||
static isc_result_t
|
||||
nzd_open(dns_view_t *view, unsigned int flags, MDB_txn **txnp, MDB_dbi *dbi) {
|
||||
int status;
|
||||
@@ -12815,6 +12843,13 @@ cleanup:
|
||||
return (result);
|
||||
}
|
||||
|
||||
/*
|
||||
* If 'commit' is true, commit the new zone database transaction pointed to by
|
||||
* 'txnp'; otherwise, abort that transaction.
|
||||
*
|
||||
* Caller must hold 'view->new_zone_lock' for the view that the transaction
|
||||
* pointed to by 'txnp' was started for.
|
||||
*/
|
||||
static isc_result_t
|
||||
nzd_close(MDB_txn **txnp, bool commit) {
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
@@ -12837,6 +12872,12 @@ nzd_close(MDB_txn **txnp, bool commit) {
|
||||
return (result);
|
||||
}
|
||||
|
||||
/*
|
||||
* Count the zones configured in the new zone database for 'view' and store the
|
||||
* result in 'countp'.
|
||||
*
|
||||
* Caller must hold 'view->new_zone_lock'.
|
||||
*/
|
||||
static isc_result_t
|
||||
nzd_count(dns_view_t *view, int *countp) {
|
||||
isc_result_t result;
|
||||
@@ -12869,6 +12910,10 @@ cleanup:
|
||||
return (result);
|
||||
}
|
||||
|
||||
/*
|
||||
* Migrate zone configuration from an NZF file to an NZD database.
|
||||
* Caller must hold view->new_zone_lock.
|
||||
*/
|
||||
static isc_result_t
|
||||
migrate_nzf(dns_view_t *view) {
|
||||
isc_result_t result;
|
||||
@@ -13228,6 +13273,7 @@ do_addzone(named_server_t *server, ns_cfgctx_t *cfg, dns_view_t *view,
|
||||
MDB_dbi dbi;
|
||||
|
||||
UNUSED(zoneconf);
|
||||
LOCK(&view->new_zone_lock);
|
||||
#endif /* HAVE_LMDB */
|
||||
|
||||
/* Zone shouldn't already exist */
|
||||
@@ -13381,6 +13427,7 @@ cleanup:
|
||||
if (txn != NULL) {
|
||||
(void)nzd_close(&txn, false);
|
||||
}
|
||||
UNLOCK(&view->new_zone_lock);
|
||||
#endif /* HAVE_LMDB */
|
||||
|
||||
if (zone != NULL) {
|
||||
@@ -13404,6 +13451,7 @@ do_modzone(named_server_t *server, ns_cfgctx_t *cfg, dns_view_t *view,
|
||||
#else /* HAVE_LMDB */
|
||||
MDB_txn *txn = NULL;
|
||||
MDB_dbi dbi;
|
||||
LOCK(&view->new_zone_lock);
|
||||
#endif /* HAVE_LMDB */
|
||||
|
||||
/* Zone must already exist */
|
||||
@@ -13601,6 +13649,7 @@ cleanup:
|
||||
if (txn != NULL) {
|
||||
(void)nzd_close(&txn, false);
|
||||
}
|
||||
UNLOCK(&view->new_zone_lock);
|
||||
#endif /* HAVE_LMDB */
|
||||
|
||||
if (zone != NULL) {
|
||||
@@ -13764,6 +13813,7 @@ rmzone(isc_task_t *task, isc_event_t *event) {
|
||||
if (added && cfg != NULL) {
|
||||
#ifdef HAVE_LMDB
|
||||
/* Make sure we can open the NZD database */
|
||||
LOCK(&view->new_zone_lock);
|
||||
result = nzd_open(view, 0, &txn, &dbi);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
@@ -13781,6 +13831,11 @@ rmzone(isc_task_t *task, isc_event_t *event) {
|
||||
"delete zone configuration: %s",
|
||||
isc_result_totext(result));
|
||||
}
|
||||
|
||||
if (txn != NULL) {
|
||||
(void)nzd_close(&txn, false);
|
||||
}
|
||||
UNLOCK(&view->new_zone_lock);
|
||||
#else /* ifdef HAVE_LMDB */
|
||||
result = delete_zoneconf(view, cfg->add_parser, cfg->nzf_config,
|
||||
dns_zone_getorigin(zone),
|
||||
@@ -13870,11 +13925,6 @@ rmzone(isc_task_t *task, isc_event_t *event) {
|
||||
}
|
||||
}
|
||||
|
||||
#ifdef HAVE_LMDB
|
||||
if (txn != NULL) {
|
||||
(void)nzd_close(&txn, false);
|
||||
}
|
||||
#endif /* ifdef HAVE_LMDB */
|
||||
if (raw != NULL) {
|
||||
dns_zone_detach(&raw);
|
||||
}
|
||||
@@ -14110,7 +14160,6 @@ named_server_showzone(named_server_t *server, isc_lex_t *lex,
|
||||
dns_view_t *view = NULL;
|
||||
dns_zone_t *zone = NULL;
|
||||
ns_cfgctx_t *cfg = NULL;
|
||||
bool exclusive = false;
|
||||
#ifdef HAVE_LMDB
|
||||
cfg_obj_t *nzconfig = NULL;
|
||||
#endif /* HAVE_LMDB */
|
||||
@@ -14135,10 +14184,6 @@ named_server_showzone(named_server_t *server, isc_lex_t *lex,
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = isc_task_beginexclusive(server->task);
|
||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
exclusive = true;
|
||||
|
||||
if (!added) {
|
||||
/* Find the view statement */
|
||||
vconfig = find_name_in_list_from_map(cfg->config, "view",
|
||||
@@ -14197,9 +14242,6 @@ cleanup:
|
||||
if (isc_buffer_usedlength(*text) > 0) {
|
||||
(void)putnull(text);
|
||||
}
|
||||
if (exclusive) {
|
||||
isc_task_endexclusive(server->task);
|
||||
}
|
||||
|
||||
return (result);
|
||||
}
|
||||
@@ -14465,6 +14507,23 @@ cleanup:
|
||||
return (result);
|
||||
}
|
||||
|
||||
static inline bool
|
||||
argcheck(char *cmd, const char *full) {
|
||||
size_t l;
|
||||
|
||||
if (cmd == NULL || cmd[0] != '-') {
|
||||
return (false);
|
||||
}
|
||||
|
||||
cmd++;
|
||||
l = strlen(cmd);
|
||||
if (l > strlen(full) || strncasecmp(cmd, full, l) != 0) {
|
||||
return (false);
|
||||
}
|
||||
|
||||
return (true);
|
||||
}
|
||||
|
||||
isc_result_t
|
||||
named_server_dnssec(named_server_t *server, isc_lex_t *lex,
|
||||
isc_buffer_t **text) {
|
||||
@@ -14473,11 +14532,17 @@ named_server_dnssec(named_server_t *server, isc_lex_t *lex,
|
||||
dns_kasp_t *kasp = NULL;
|
||||
dns_dnsseckeylist_t keys;
|
||||
dns_dnsseckey_t *key;
|
||||
const char *ptr;
|
||||
char *ptr;
|
||||
const char *msg = NULL;
|
||||
/* variables for -checkds */
|
||||
bool checkds = false, dspublish = false, use_keyid = false;
|
||||
dns_keytag_t keyid = 0;
|
||||
uint8_t algorithm = 0;
|
||||
/* variables for -status */
|
||||
bool status = false;
|
||||
char output[4096];
|
||||
isc_stdtime_t now;
|
||||
isc_time_t timenow;
|
||||
isc_stdtime_t now, when;
|
||||
isc_time_t timenow, timewhen;
|
||||
const char *dir;
|
||||
|
||||
/* Skip the command name. */
|
||||
@@ -14492,43 +14557,184 @@ named_server_dnssec(named_server_t *server, isc_lex_t *lex,
|
||||
return (ISC_R_UNEXPECTEDEND);
|
||||
}
|
||||
|
||||
if (strcasecmp(ptr, "-status") != 0) {
|
||||
return (DNS_R_SYNTAX);
|
||||
}
|
||||
/* Initialize current time and key list. */
|
||||
TIME_NOW(&timenow);
|
||||
now = isc_time_seconds(&timenow);
|
||||
when = now;
|
||||
|
||||
ISC_LIST_INIT(keys);
|
||||
|
||||
if (strcasecmp(ptr, "-status") == 0) {
|
||||
status = true;
|
||||
} else if (strcasecmp(ptr, "-checkds") == 0) {
|
||||
checkds = true;
|
||||
|
||||
/* Check for options */
|
||||
for (;;) {
|
||||
ptr = next_token(lex, text);
|
||||
if (ptr == NULL) {
|
||||
msg = "Bad format";
|
||||
CHECK(ISC_R_UNEXPECTEDEND);
|
||||
} else if (argcheck(ptr, "alg")) {
|
||||
isc_consttextregion_t alg;
|
||||
ptr = next_token(lex, text);
|
||||
if (ptr == NULL) {
|
||||
msg = "No key algorithm specified";
|
||||
CHECK(ISC_R_UNEXPECTEDEND);
|
||||
}
|
||||
alg.base = ptr;
|
||||
alg.length = strlen(alg.base);
|
||||
result = dns_secalg_fromtext(
|
||||
&algorithm, (isc_textregion_t *)&alg);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
msg = "Bad algorithm";
|
||||
CHECK(DNS_R_SYNTAX);
|
||||
}
|
||||
continue;
|
||||
} else if (argcheck(ptr, "key")) {
|
||||
uint16_t id;
|
||||
ptr = next_token(lex, text);
|
||||
if (ptr == NULL) {
|
||||
msg = "No key identifier specified";
|
||||
CHECK(ISC_R_UNEXPECTEDEND);
|
||||
}
|
||||
CHECK(isc_parse_uint16(&id, ptr, 10));
|
||||
keyid = (dns_keytag_t)id;
|
||||
use_keyid = true;
|
||||
continue;
|
||||
} else if (argcheck(ptr, "when")) {
|
||||
uint32_t tw;
|
||||
ptr = next_token(lex, text);
|
||||
if (ptr == NULL) {
|
||||
msg = "No time specified";
|
||||
CHECK(ISC_R_UNEXPECTEDEND);
|
||||
}
|
||||
CHECK(dns_time32_fromtext(ptr, &tw));
|
||||
when = (isc_stdtime_t)tw;
|
||||
continue;
|
||||
} else if (ptr[0] == '-') {
|
||||
msg = "Unknown option";
|
||||
CHECK(DNS_R_SYNTAX);
|
||||
} else {
|
||||
/*
|
||||
* No arguments provided, so we must be
|
||||
* parsing "published|withdrawn".
|
||||
*/
|
||||
if (strcasecmp(ptr, "published") == 0) {
|
||||
dspublish = true;
|
||||
} else if (strcasecmp(ptr, "withdrawn") != 0) {
|
||||
CHECK(DNS_R_SYNTAX);
|
||||
}
|
||||
}
|
||||
break;
|
||||
}
|
||||
|
||||
if (algorithm > 0 && !use_keyid) {
|
||||
msg = "Key id is required when setting algorithm";
|
||||
CHECK(DNS_R_SYNTAX);
|
||||
}
|
||||
} else {
|
||||
CHECK(DNS_R_SYNTAX);
|
||||
}
|
||||
|
||||
/* Get zone. */
|
||||
CHECK(zone_from_args(server, lex, NULL, &zone, NULL, text, false));
|
||||
if (zone == NULL) {
|
||||
msg = "Zone not found";
|
||||
CHECK(ISC_R_UNEXPECTEDEND);
|
||||
}
|
||||
|
||||
/* Trailing garbage? */
|
||||
ptr = next_token(lex, text);
|
||||
if (ptr != NULL) {
|
||||
msg = "Too many arguments";
|
||||
CHECK(DNS_R_SYNTAX);
|
||||
}
|
||||
|
||||
/* Get dnssec-policy. */
|
||||
kasp = dns_zone_getkasp(zone);
|
||||
if (kasp == NULL) {
|
||||
CHECK(putstr(text, "zone does not have dnssec-policy"));
|
||||
CHECK(putnull(text));
|
||||
msg = "Zone does not have dnssec-policy";
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* -status */
|
||||
TIME_NOW(&timenow);
|
||||
now = isc_time_seconds(&timenow);
|
||||
/* Get DNSSEC keys. */
|
||||
dir = dns_zone_getkeydirectory(zone);
|
||||
LOCK(&kasp->lock);
|
||||
result = dns_dnssec_findmatchingkeys(dns_zone_getorigin(zone), dir, now,
|
||||
dns_zone_getmctx(zone), &keys);
|
||||
UNLOCK(&kasp->lock);
|
||||
|
||||
if (result != ISC_R_SUCCESS && result != ISC_R_NOTFOUND) {
|
||||
goto cleanup;
|
||||
}
|
||||
LOCK(&kasp->lock);
|
||||
dns_keymgr_status(kasp, &keys, now, &output[0], sizeof(output));
|
||||
UNLOCK(&kasp->lock);
|
||||
CHECK(putstr(text, output));
|
||||
|
||||
if (status) {
|
||||
/*
|
||||
* Output the DNSSEC status of the key and signing policy.
|
||||
*/
|
||||
LOCK(&kasp->lock);
|
||||
dns_keymgr_status(kasp, &keys, now, &output[0], sizeof(output));
|
||||
UNLOCK(&kasp->lock);
|
||||
CHECK(putstr(text, output));
|
||||
} else if (checkds) {
|
||||
/*
|
||||
* Mark DS record has been seen, so it may move to the
|
||||
* rumoured state.
|
||||
*/
|
||||
char whenbuf[80];
|
||||
isc_time_set(&timewhen, when, 0);
|
||||
isc_time_formattimestamp(&timewhen, whenbuf, sizeof(whenbuf));
|
||||
|
||||
LOCK(&kasp->lock);
|
||||
if (use_keyid) {
|
||||
result = dns_keymgr_checkds_id(kasp, &keys, dir, when,
|
||||
dspublish, keyid,
|
||||
(unsigned int)algorithm);
|
||||
} else {
|
||||
result = dns_keymgr_checkds(kasp, &keys, dir, when,
|
||||
dspublish);
|
||||
}
|
||||
UNLOCK(&kasp->lock);
|
||||
|
||||
switch (result) {
|
||||
case ISC_R_SUCCESS:
|
||||
if (use_keyid) {
|
||||
char tagbuf[6];
|
||||
snprintf(tagbuf, sizeof(tagbuf), "%u", keyid);
|
||||
CHECK(putstr(text, "KSK "));
|
||||
CHECK(putstr(text, tagbuf));
|
||||
CHECK(putstr(text, ": "));
|
||||
}
|
||||
CHECK(putstr(text, "Marked DS as "));
|
||||
if (dspublish) {
|
||||
CHECK(putstr(text, "published "));
|
||||
} else {
|
||||
CHECK(putstr(text, "withdrawn "));
|
||||
}
|
||||
CHECK(putstr(text, "since "));
|
||||
CHECK(putstr(text, whenbuf));
|
||||
break;
|
||||
case ISC_R_NOTFOUND:
|
||||
CHECK(putstr(text, "No matching KSK found"));
|
||||
break;
|
||||
case ISC_R_FAILURE:
|
||||
CHECK(putstr(text,
|
||||
"Error: multiple possible KSKs found, "
|
||||
"retry command with -key id"));
|
||||
break;
|
||||
default:
|
||||
CHECK(putstr(text, "Error executing checkds command"));
|
||||
break;
|
||||
}
|
||||
}
|
||||
CHECK(putnull(text));
|
||||
|
||||
cleanup:
|
||||
if (msg != NULL) {
|
||||
(void)putstr(text, msg);
|
||||
(void)putnull(text);
|
||||
}
|
||||
|
||||
while (!ISC_LIST_EMPTY(keys)) {
|
||||
key = ISC_LIST_HEAD(keys);
|
||||
ISC_LIST_UNLINK(keys, key, link);
|
||||
@@ -14659,14 +14865,15 @@ named_server_zonestatus(named_server_t *server, isc_lex_t *lex,
|
||||
|
||||
/* Serial number */
|
||||
result = dns_zone_getserial(mayberaw, &serial);
|
||||
/* XXXWPK TODO this is to mirror old behavior with dns_zone_getserial */
|
||||
|
||||
/* This is to mirror old behavior with dns_zone_getserial */
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
serial = 0;
|
||||
}
|
||||
|
||||
snprintf(serbuf, sizeof(serbuf), "%u", serial);
|
||||
if (hasraw) {
|
||||
result = dns_zone_getserial(zone, &signed_serial);
|
||||
/* XXXWPK TODO ut supra */
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
serial = 0;
|
||||
}
|
||||
@@ -14873,23 +15080,6 @@ cleanup:
|
||||
return (result);
|
||||
}
|
||||
|
||||
static inline bool
|
||||
argcheck(char *cmd, const char *full) {
|
||||
size_t l;
|
||||
|
||||
if (cmd == NULL || cmd[0] != '-') {
|
||||
return (false);
|
||||
}
|
||||
|
||||
cmd++;
|
||||
l = strlen(cmd);
|
||||
if (l > strlen(full) || strncasecmp(cmd, full, l) != 0) {
|
||||
return (false);
|
||||
}
|
||||
|
||||
return (true);
|
||||
}
|
||||
|
||||
isc_result_t
|
||||
named_server_nta(named_server_t *server, isc_lex_t *lex, bool readonly,
|
||||
isc_buffer_t **text) {
|
||||
|
||||
+171
-293
@@ -22,7 +22,6 @@
|
||||
#include <isc/socket.h>
|
||||
#include <isc/stats.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/task.h>
|
||||
#include <isc/util.h>
|
||||
|
||||
#include <dns/cache.h>
|
||||
@@ -54,6 +53,14 @@
|
||||
|
||||
#include "xsl_p.h"
|
||||
|
||||
#define CHECK(m) \
|
||||
do { \
|
||||
result = (m); \
|
||||
if (result != ISC_R_SUCCESS) { \
|
||||
goto cleanup; \
|
||||
} \
|
||||
} while (0)
|
||||
|
||||
struct named_statschannel {
|
||||
/* Unlocked */
|
||||
isc_httpdmgr_t *httpdmgr;
|
||||
@@ -170,11 +177,11 @@ static const char *gluecachestats_xmldesc[dns_gluecachestatscounter_max];
|
||||
#define gluecachestats_xmldesc NULL
|
||||
#endif /* EXTENDED_STATS */
|
||||
|
||||
#define TRY0(a) \
|
||||
do { \
|
||||
xmlrc = (a); \
|
||||
if (xmlrc < 0) \
|
||||
goto error; \
|
||||
#define TRY0(a) \
|
||||
do { \
|
||||
xmlrc = (a); \
|
||||
if (xmlrc < 0) \
|
||||
goto cleanup; \
|
||||
} while (0)
|
||||
|
||||
/*%
|
||||
@@ -1424,7 +1431,7 @@ dump_counters(isc_stats_t *stats, isc_statsformat_t type, void *arg,
|
||||
}
|
||||
return (ISC_R_SUCCESS);
|
||||
#ifdef HAVE_LIBXML2
|
||||
error:
|
||||
cleanup:
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"failed at dump_counters()");
|
||||
@@ -1486,7 +1493,7 @@ rdtypestat_dump(dns_rdatastatstype_t type, uint64_t val, void *arg) {
|
||||
}
|
||||
return;
|
||||
#ifdef HAVE_LIBXML2
|
||||
error:
|
||||
cleanup:
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"failed at rdtypestat_dump()");
|
||||
@@ -1574,7 +1581,7 @@ rdatasetstats_dump(dns_rdatastatstype_t type, uint64_t val, void *arg) {
|
||||
}
|
||||
return;
|
||||
#ifdef HAVE_LIBXML2
|
||||
error:
|
||||
cleanup:
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"failed at rdatasetstats_dump()");
|
||||
@@ -1629,7 +1636,7 @@ opcodestat_dump(dns_opcode_t code, uint64_t val, void *arg) {
|
||||
return;
|
||||
|
||||
#ifdef HAVE_LIBXML2
|
||||
error:
|
||||
cleanup:
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"failed at opcodestat_dump()");
|
||||
@@ -1685,7 +1692,7 @@ rcodestat_dump(dns_rcode_t code, uint64_t val, void *arg) {
|
||||
return;
|
||||
|
||||
#ifdef HAVE_LIBXML2
|
||||
error:
|
||||
cleanup:
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"failed at rcodestat_dump()");
|
||||
@@ -1738,7 +1745,7 @@ dnssecsignstat_dump(dns_keytag_t tag, uint64_t val, void *arg) {
|
||||
}
|
||||
return;
|
||||
#ifdef HAVE_LIBXML2
|
||||
error:
|
||||
cleanup:
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"failed at dnssecsignstat_dump()");
|
||||
@@ -1772,6 +1779,7 @@ zone_xmlrender(dns_zone_t *zone, void *arg) {
|
||||
int xmlrc;
|
||||
stats_dumparg_t dumparg;
|
||||
const char *ztype;
|
||||
isc_time_t timestamp;
|
||||
|
||||
statlevel = dns_zone_getstatlevel(zone);
|
||||
if (statlevel == dns_zonestat_none) {
|
||||
@@ -1814,12 +1822,8 @@ zone_xmlrender(dns_zone_t *zone, void *arg) {
|
||||
* master zones, only include the loaded time. For slave zones, also
|
||||
* include the expires and refresh times.
|
||||
*/
|
||||
isc_time_t timestamp;
|
||||
|
||||
result = dns_zone_getloadtime(zone, ×tamp);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dns_zone_getloadtime(zone, ×tamp));
|
||||
|
||||
isc_time_formatISO8601(×tamp, buf, 64);
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "loaded"));
|
||||
@@ -1827,19 +1831,13 @@ zone_xmlrender(dns_zone_t *zone, void *arg) {
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
|
||||
if (dns_zone_gettype(zone) == dns_zone_slave) {
|
||||
result = dns_zone_getexpiretime(zone, ×tamp);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dns_zone_getexpiretime(zone, ×tamp));
|
||||
isc_time_formatISO8601(×tamp, buf, 64);
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "expires"));
|
||||
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR buf));
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
|
||||
result = dns_zone_getrefreshtime(zone, ×tamp);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dns_zone_getrefreshtime(zone, ×tamp));
|
||||
isc_time_formatISO8601(×tamp, buf, 64);
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "refresh"));
|
||||
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR buf));
|
||||
@@ -1862,14 +1860,11 @@ zone_xmlrender(dns_zone_t *zone, void *arg) {
|
||||
ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "rcode"));
|
||||
|
||||
result = dump_counters(zonestats, isc_statsformat_xml,
|
||||
writer, NULL, nsstats_xmldesc,
|
||||
ns_statscounter_max,
|
||||
nsstats_index, nsstat_values,
|
||||
ISC_STATSDUMP_VERBOSE);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dump_counters(zonestats, isc_statsformat_xml,
|
||||
writer, NULL, nsstats_xmldesc,
|
||||
ns_statscounter_max, nsstats_index,
|
||||
nsstat_values,
|
||||
ISC_STATSDUMP_VERBOSE));
|
||||
/* counters type="rcode"*/
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
}
|
||||
@@ -1882,15 +1877,12 @@ zone_xmlrender(dns_zone_t *zone, void *arg) {
|
||||
writer, ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "gluecache"));
|
||||
|
||||
result = dump_counters(
|
||||
CHECK(dump_counters(
|
||||
gluecachestats, isc_statsformat_xml, writer,
|
||||
NULL, gluecachestats_xmldesc,
|
||||
dns_gluecachestatscounter_max,
|
||||
gluecachestats_index, gluecachestats_values,
|
||||
ISC_STATSDUMP_VERBOSE);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
ISC_STATSDUMP_VERBOSE));
|
||||
/* counters type="rcode"*/
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
}
|
||||
@@ -1906,9 +1898,7 @@ zone_xmlrender(dns_zone_t *zone, void *arg) {
|
||||
dumparg.result = ISC_R_SUCCESS;
|
||||
dns_rdatatypestats_dump(rcvquerystats, rdtypestat_dump,
|
||||
&dumparg, 0);
|
||||
if (dumparg.result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dumparg.result);
|
||||
|
||||
/* counters type="qtype"*/
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
@@ -1927,9 +1917,7 @@ zone_xmlrender(dns_zone_t *zone, void *arg) {
|
||||
dns_dnssecsignstats_dump(
|
||||
dnssecsignstats, dns_dnssecsignstats_sign,
|
||||
dnssecsignstat_dump, &dumparg, 0);
|
||||
if (dumparg.result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dumparg.result);
|
||||
|
||||
/* counters type="dnssec-sign"*/
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
@@ -1945,9 +1933,7 @@ zone_xmlrender(dns_zone_t *zone, void *arg) {
|
||||
dns_dnssecsignstats_dump(
|
||||
dnssecsignstats, dns_dnssecsignstats_refresh,
|
||||
dnssecsignstat_dump, &dumparg, 0);
|
||||
if (dumparg.result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dumparg.result);
|
||||
|
||||
/* counters type="dnssec-refresh"*/
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
@@ -1957,7 +1943,7 @@ zone_xmlrender(dns_zone_t *zone, void *arg) {
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* zone */
|
||||
|
||||
return (ISC_R_SUCCESS);
|
||||
error:
|
||||
cleanup:
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"Failed at zone_xmlrender()");
|
||||
@@ -1999,7 +1985,7 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
|
||||
writer = xmlNewTextWriterDoc(&doc, 0);
|
||||
if (writer == NULL) {
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
TRY0(xmlTextWriterStartDocument(writer, NULL, "UTF-8", NULL));
|
||||
TRY0(xmlTextWriterWritePI(writer, ISC_XMLCHAR "xml-stylesheet",
|
||||
@@ -2037,9 +2023,7 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
|
||||
dns_opcodestats_dump(server->sctx->opcodestats, opcodestat_dump,
|
||||
&dumparg, ISC_STATSDUMP_VERBOSE);
|
||||
if (dumparg.result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dumparg.result);
|
||||
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
|
||||
@@ -2049,9 +2033,7 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
|
||||
dns_rcodestats_dump(server->sctx->rcodestats, rcodestat_dump,
|
||||
&dumparg, ISC_STATSDUMP_VERBOSE);
|
||||
if (dumparg.result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dumparg.result);
|
||||
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
|
||||
@@ -2062,23 +2044,19 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
dumparg.result = ISC_R_SUCCESS;
|
||||
dns_rdatatypestats_dump(server->sctx->rcvquerystats,
|
||||
rdtypestat_dump, &dumparg, 0);
|
||||
if (dumparg.result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dumparg.result);
|
||||
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* counters */
|
||||
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "counters"));
|
||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "nsstat"));
|
||||
|
||||
result = dump_counters(ns_stats_get(server->sctx->nsstats),
|
||||
isc_statsformat_xml, writer, NULL,
|
||||
nsstats_xmldesc, ns_statscounter_max,
|
||||
nsstats_index, nsstat_values,
|
||||
ISC_STATSDUMP_VERBOSE);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dump_counters(ns_stats_get(server->sctx->nsstats),
|
||||
isc_statsformat_xml, writer, NULL,
|
||||
nsstats_xmldesc, ns_statscounter_max,
|
||||
nsstats_index, nsstat_values,
|
||||
ISC_STATSDUMP_VERBOSE));
|
||||
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* /nsstat */
|
||||
|
||||
@@ -2086,14 +2064,10 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "zonestat"));
|
||||
|
||||
result = dump_counters(server->zonestats, isc_statsformat_xml,
|
||||
writer, NULL, zonestats_xmldesc,
|
||||
dns_zonestatscounter_max,
|
||||
zonestats_index, zonestat_values,
|
||||
ISC_STATSDUMP_VERBOSE);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dump_counters(server->zonestats, isc_statsformat_xml,
|
||||
writer, NULL, zonestats_xmldesc,
|
||||
dns_zonestatscounter_max, zonestats_index,
|
||||
zonestat_values, ISC_STATSDUMP_VERBOSE));
|
||||
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* /zonestat */
|
||||
|
||||
@@ -2104,13 +2078,11 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "counters"));
|
||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "resstat"));
|
||||
result = dump_counters(
|
||||
server->resolverstats, isc_statsformat_xml, writer,
|
||||
NULL, resstats_xmldesc, dns_resstatscounter_max,
|
||||
resstats_index, resstat_values, 0);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dump_counters(server->resolverstats, isc_statsformat_xml,
|
||||
writer, NULL, resstats_xmldesc,
|
||||
dns_resstatscounter_max, resstats_index,
|
||||
resstat_values, 0));
|
||||
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* resstat */
|
||||
|
||||
#ifdef HAVE_DNSTAP
|
||||
@@ -2127,9 +2099,8 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
dnstapstats_xmldesc, dns_dnstapcounter_max,
|
||||
dnstapstats_index, dnstapstat_values, 0);
|
||||
isc_stats_detach(&dnstapstats);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(result);
|
||||
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* dnstap */
|
||||
}
|
||||
#endif /* ifdef HAVE_DNSTAP */
|
||||
@@ -2140,14 +2111,10 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "sockstat"));
|
||||
|
||||
result = dump_counters(server->sockstats, isc_statsformat_xml,
|
||||
writer, NULL, sockstats_xmldesc,
|
||||
isc_sockstatscounter_max,
|
||||
sockstats_index, sockstat_values,
|
||||
ISC_STATSDUMP_VERBOSE);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dump_counters(server->sockstats, isc_statsformat_xml,
|
||||
writer, NULL, sockstats_xmldesc,
|
||||
isc_sockstatscounter_max, sockstats_index,
|
||||
sockstat_values, ISC_STATSDUMP_VERBOSE));
|
||||
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* /sockstat */
|
||||
}
|
||||
@@ -2161,13 +2128,10 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "request-size"));
|
||||
|
||||
result = dump_counters(
|
||||
CHECK(dump_counters(
|
||||
server->sctx->udpinstats4, isc_statsformat_xml, writer,
|
||||
NULL, udpinsizestats_xmldesc, dns_sizecounter_in_max,
|
||||
udpinsizestats_index, udpinsizestat_values, 0);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
udpinsizestats_index, udpinsizestat_values, 0));
|
||||
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* </counters> */
|
||||
|
||||
@@ -2175,13 +2139,10 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "response-size"));
|
||||
|
||||
result = dump_counters(
|
||||
CHECK(dump_counters(
|
||||
server->sctx->udpoutstats4, isc_statsformat_xml, writer,
|
||||
NULL, udpoutsizestats_xmldesc, dns_sizecounter_out_max,
|
||||
udpoutsizestats_index, udpoutsizestat_values, 0);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
udpoutsizestats_index, udpoutsizestat_values, 0));
|
||||
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* </counters> */
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* </udp> */
|
||||
@@ -2191,27 +2152,20 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "request-size"));
|
||||
|
||||
result = dump_counters(
|
||||
CHECK(dump_counters(
|
||||
server->sctx->tcpinstats4, isc_statsformat_xml, writer,
|
||||
NULL, tcpinsizestats_xmldesc, dns_sizecounter_in_max,
|
||||
tcpinsizestats_index, tcpinsizestat_values, 0);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
tcpinsizestats_index, tcpinsizestat_values, 0));
|
||||
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* </counters> */
|
||||
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "counters"));
|
||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "response-size"));
|
||||
|
||||
result = dump_counters(
|
||||
CHECK(dump_counters(
|
||||
server->sctx->tcpoutstats4, isc_statsformat_xml, writer,
|
||||
NULL, tcpoutsizestats_xmldesc, dns_sizecounter_out_max,
|
||||
tcpoutsizestats_index, tcpoutsizestat_values, 0);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
tcpoutsizestats_index, tcpoutsizestat_values, 0));
|
||||
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* </counters> */
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* </tcp> */
|
||||
@@ -2223,13 +2177,10 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "request-size"));
|
||||
|
||||
result = dump_counters(
|
||||
CHECK(dump_counters(
|
||||
server->sctx->udpinstats6, isc_statsformat_xml, writer,
|
||||
NULL, udpinsizestats_xmldesc, dns_sizecounter_in_max,
|
||||
udpinsizestats_index, udpinsizestat_values, 0);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
udpinsizestats_index, udpinsizestat_values, 0));
|
||||
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* </counters> */
|
||||
|
||||
@@ -2237,13 +2188,10 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "response-size"));
|
||||
|
||||
result = dump_counters(
|
||||
CHECK(dump_counters(
|
||||
server->sctx->udpoutstats6, isc_statsformat_xml, writer,
|
||||
NULL, udpoutsizestats_xmldesc, dns_sizecounter_out_max,
|
||||
udpoutsizestats_index, udpoutsizestat_values, 0);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
udpoutsizestats_index, udpoutsizestat_values, 0));
|
||||
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* </counters> */
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* </udp> */
|
||||
@@ -2253,13 +2201,10 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "request-size"));
|
||||
|
||||
result = dump_counters(
|
||||
CHECK(dump_counters(
|
||||
server->sctx->tcpinstats6, isc_statsformat_xml, writer,
|
||||
NULL, tcpinsizestats_xmldesc, dns_sizecounter_in_max,
|
||||
tcpinsizestats_index, tcpinsizestat_values, 0);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
tcpinsizestats_index, tcpinsizestat_values, 0));
|
||||
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* </counters> */
|
||||
|
||||
@@ -2267,13 +2212,10 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "response-size"));
|
||||
|
||||
result = dump_counters(
|
||||
CHECK(dump_counters(
|
||||
server->sctx->tcpoutstats6, isc_statsformat_xml, writer,
|
||||
NULL, tcpoutsizestats_xmldesc, dns_sizecounter_out_max,
|
||||
tcpoutsizestats_index, tcpoutsizestat_values, 0);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
tcpoutsizestats_index, tcpoutsizestat_values, 0));
|
||||
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* </counters> */
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* </tcp> */
|
||||
@@ -2296,11 +2238,8 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
if ((flags & STATS_XML_ZONES) != 0) {
|
||||
TRY0(xmlTextWriterStartElement(writer,
|
||||
ISC_XMLCHAR "zones"));
|
||||
result = dns_zt_apply(view->zonetable, true, NULL,
|
||||
zone_xmlrender, writer);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dns_zt_apply(view->zonetable, true, NULL,
|
||||
zone_xmlrender, writer));
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* /zones */
|
||||
}
|
||||
|
||||
@@ -2318,9 +2257,7 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
dumparg.result = ISC_R_SUCCESS;
|
||||
dns_rdatatypestats_dump(view->resquerystats,
|
||||
rdtypestat_dump, &dumparg, 0);
|
||||
if (dumparg.result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dumparg.result);
|
||||
}
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
|
||||
@@ -2329,14 +2266,11 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "resstats"));
|
||||
if (view->resstats != NULL) {
|
||||
result = dump_counters(
|
||||
view->resstats, isc_statsformat_xml, writer,
|
||||
NULL, resstats_xmldesc, dns_resstatscounter_max,
|
||||
resstats_index, resstat_values,
|
||||
ISC_STATSDUMP_VERBOSE);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dump_counters(view->resstats, isc_statsformat_xml,
|
||||
writer, NULL, resstats_xmldesc,
|
||||
dns_resstatscounter_max,
|
||||
resstats_index, resstat_values,
|
||||
ISC_STATSDUMP_VERBOSE));
|
||||
}
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* </resstats> */
|
||||
|
||||
@@ -2350,9 +2284,7 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
dumparg.result = ISC_R_SUCCESS;
|
||||
dns_rdatasetstats_dump(cacherrstats, rdatasetstats_dump,
|
||||
&dumparg, 0);
|
||||
if (dumparg.result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dumparg.result);
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* cache */
|
||||
}
|
||||
|
||||
@@ -2361,14 +2293,11 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "adbstat"));
|
||||
if (view->adbstats != NULL) {
|
||||
result = dump_counters(
|
||||
view->adbstats, isc_statsformat_xml, writer,
|
||||
NULL, adbstats_xmldesc, dns_adbstats_max,
|
||||
adbstats_index, adbstat_values,
|
||||
ISC_STATSDUMP_VERBOSE);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dump_counters(view->adbstats, isc_statsformat_xml,
|
||||
writer, NULL, adbstats_xmldesc,
|
||||
dns_adbstats_max, adbstats_index,
|
||||
adbstat_values,
|
||||
ISC_STATSDUMP_VERBOSE));
|
||||
}
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* </adbstats> */
|
||||
|
||||
@@ -2411,12 +2340,12 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||
|
||||
xmlDocDumpFormatMemoryEnc(doc, buf, buflen, "UTF-8", 0);
|
||||
if (*buf == NULL) {
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
xmlFreeDoc(doc);
|
||||
return (ISC_R_SUCCESS);
|
||||
|
||||
error:
|
||||
cleanup:
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"failed generating XML response");
|
||||
@@ -2573,18 +2502,11 @@ render_xml_traffic(const char *url, isc_httpdurl_t *urlinfo,
|
||||
#define STATS_JSON_TRAFFIC 0x20
|
||||
#define STATS_JSON_ALL 0xff
|
||||
|
||||
#define CHECK(m) \
|
||||
do { \
|
||||
result = (m); \
|
||||
if (result != ISC_R_SUCCESS) \
|
||||
goto error; \
|
||||
} while (0)
|
||||
|
||||
#define CHECKMEM(m) \
|
||||
do { \
|
||||
if (m == NULL) { \
|
||||
result = ISC_R_NOMEMORY; \
|
||||
goto error; \
|
||||
goto cleanup; \
|
||||
} \
|
||||
} while (0)
|
||||
|
||||
@@ -2664,27 +2586,18 @@ zone_jsonrender(dns_zone_t *zone, void *arg) {
|
||||
|
||||
isc_time_t timestamp;
|
||||
|
||||
result = dns_zone_getloadtime(zone, ×tamp);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dns_zone_getloadtime(zone, ×tamp));
|
||||
|
||||
isc_time_formatISO8601(×tamp, buf, 64);
|
||||
json_object_object_add(zoneobj, "loaded", json_object_new_string(buf));
|
||||
|
||||
if (dns_zone_gettype(zone) == dns_zone_slave) {
|
||||
result = dns_zone_getexpiretime(zone, ×tamp);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dns_zone_getexpiretime(zone, ×tamp));
|
||||
isc_time_formatISO8601(×tamp, buf, 64);
|
||||
json_object_object_add(zoneobj, "expires",
|
||||
json_object_new_string(buf));
|
||||
|
||||
result = dns_zone_getrefreshtime(zone, ×tamp);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dns_zone_getrefreshtime(zone, ×tamp));
|
||||
isc_time_formatISO8601(×tamp, buf, 64);
|
||||
json_object_object_add(zoneobj, "refresh",
|
||||
json_object_new_string(buf));
|
||||
@@ -2703,7 +2616,7 @@ zone_jsonrender(dns_zone_t *zone, void *arg) {
|
||||
json_object *counters = json_object_new_object();
|
||||
if (counters == NULL) {
|
||||
result = ISC_R_NOMEMORY;
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = dump_counters(zonestats, isc_statsformat_json,
|
||||
@@ -2712,7 +2625,7 @@ zone_jsonrender(dns_zone_t *zone, void *arg) {
|
||||
nsstats_index, nsstat_values, 0);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (json_object_get_object(counters)->count != 0) {
|
||||
@@ -2728,7 +2641,7 @@ zone_jsonrender(dns_zone_t *zone, void *arg) {
|
||||
json_object *counters = json_object_new_object();
|
||||
if (counters == NULL) {
|
||||
result = ISC_R_NOMEMORY;
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = dump_counters(
|
||||
@@ -2738,7 +2651,7 @@ zone_jsonrender(dns_zone_t *zone, void *arg) {
|
||||
gluecachestats_index, gluecachestats_values, 0);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (json_object_get_object(counters)->count != 0) {
|
||||
@@ -2762,7 +2675,7 @@ zone_jsonrender(dns_zone_t *zone, void *arg) {
|
||||
&dumparg, 0);
|
||||
if (dumparg.result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (json_object_get_object(counters)->count != 0) {
|
||||
@@ -2787,7 +2700,7 @@ zone_jsonrender(dns_zone_t *zone, void *arg) {
|
||||
dnssecsignstat_dump, &dumparg, 0);
|
||||
if (dumparg.result != ISC_R_SUCCESS) {
|
||||
json_object_put(sign_counters);
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (json_object_get_object(sign_counters)->count != 0) {
|
||||
@@ -2809,7 +2722,7 @@ zone_jsonrender(dns_zone_t *zone, void *arg) {
|
||||
dnssecsignstat_dump, &dumparg, 0);
|
||||
if (dumparg.result != ISC_R_SUCCESS) {
|
||||
json_object_put(refresh_counters);
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (json_object_get_object(refresh_counters)->count !=
|
||||
@@ -2827,7 +2740,7 @@ zone_jsonrender(dns_zone_t *zone, void *arg) {
|
||||
zoneobj = NULL;
|
||||
result = ISC_R_SUCCESS;
|
||||
|
||||
error:
|
||||
cleanup:
|
||||
if (zoneobj != NULL) {
|
||||
json_object_put(zoneobj);
|
||||
}
|
||||
@@ -2912,7 +2825,7 @@ generatejson(named_server_t *server, size_t *msglen, const char **msg,
|
||||
&dumparg, ISC_STATSDUMP_VERBOSE);
|
||||
if (dumparg.result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (json_object_get_object(counters)->count != 0) {
|
||||
@@ -2931,7 +2844,7 @@ generatejson(named_server_t *server, size_t *msglen, const char **msg,
|
||||
&dumparg, ISC_STATSDUMP_VERBOSE);
|
||||
if (dumparg.result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (json_object_get_object(counters)->count != 0) {
|
||||
@@ -2950,7 +2863,7 @@ generatejson(named_server_t *server, size_t *msglen, const char **msg,
|
||||
rdtypestat_dump, &dumparg, 0);
|
||||
if (dumparg.result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (json_object_get_object(counters)->count != 0) {
|
||||
@@ -2971,7 +2884,7 @@ generatejson(named_server_t *server, size_t *msglen, const char **msg,
|
||||
nsstats_index, nsstat_values, 0);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (json_object_get_object(counters)->count != 0) {
|
||||
@@ -2992,7 +2905,7 @@ generatejson(named_server_t *server, size_t *msglen, const char **msg,
|
||||
zonestats_index, zonestat_values, 0);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (json_object_get_object(counters)->count != 0) {
|
||||
@@ -3014,7 +2927,7 @@ generatejson(named_server_t *server, size_t *msglen, const char **msg,
|
||||
resstats_index, resstat_values, 0);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (json_object_get_object(counters)->count != 0) {
|
||||
@@ -3039,7 +2952,7 @@ generatejson(named_server_t *server, size_t *msglen, const char **msg,
|
||||
isc_stats_detach(&dnstapstats);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (json_object_get_object(counters)->count != 0) {
|
||||
@@ -3069,12 +2982,8 @@ generatejson(named_server_t *server, size_t *msglen, const char **msg,
|
||||
CHECKMEM(za);
|
||||
|
||||
if ((flags & STATS_JSON_ZONES) != 0) {
|
||||
result = dns_zt_apply(view->zonetable, true,
|
||||
NULL, zone_jsonrender,
|
||||
za);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto error;
|
||||
}
|
||||
CHECK(dns_zt_apply(view->zonetable, true, NULL,
|
||||
zone_jsonrender, za));
|
||||
}
|
||||
|
||||
if (json_object_array_length(za) != 0) {
|
||||
@@ -3107,7 +3016,7 @@ generatejson(named_server_t *server, size_t *msglen, const char **msg,
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
result = dumparg.result;
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
json_object_object_add(res, "stats",
|
||||
@@ -3127,7 +3036,7 @@ generatejson(named_server_t *server, size_t *msglen, const char **msg,
|
||||
if (dumparg.result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
result = dumparg.result;
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
json_object_object_add(res, "qtypes",
|
||||
@@ -3147,7 +3056,7 @@ generatejson(named_server_t *server, size_t *msglen, const char **msg,
|
||||
if (dumparg.result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
result = dumparg.result;
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
json_object_object_add(res, "cache",
|
||||
@@ -3161,7 +3070,7 @@ generatejson(named_server_t *server, size_t *msglen, const char **msg,
|
||||
counters);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
json_object_object_add(res, "cachestats",
|
||||
@@ -3182,7 +3091,7 @@ generatejson(named_server_t *server, size_t *msglen, const char **msg,
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
result = dumparg.result;
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
json_object_object_add(res, "adb",
|
||||
@@ -3208,7 +3117,7 @@ generatejson(named_server_t *server, size_t *msglen, const char **msg,
|
||||
sockstats_index, sockstat_values, 0);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (json_object_get_object(counters)->count != 0) {
|
||||
@@ -3224,7 +3133,7 @@ generatejson(named_server_t *server, size_t *msglen, const char **msg,
|
||||
result = isc_socketmgr_renderjson(named_g_socketmgr, sockets);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
json_object_put(sockets);
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
json_object_object_add(bindstats, "socketmgr", sockets);
|
||||
@@ -3237,7 +3146,7 @@ generatejson(named_server_t *server, size_t *msglen, const char **msg,
|
||||
result = isc_taskmgr_renderjson(named_g_taskmgr, tasks);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
json_object_put(tasks);
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
json_object_object_add(bindstats, "taskmgr", tasks);
|
||||
@@ -3250,7 +3159,7 @@ generatejson(named_server_t *server, size_t *msglen, const char **msg,
|
||||
result = isc_mem_renderjson(memory);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
json_object_put(memory);
|
||||
goto error;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
json_object_object_add(bindstats, "memory", memory);
|
||||
@@ -3375,7 +3284,7 @@ generatejson(named_server_t *server, size_t *msglen, const char **msg,
|
||||
|
||||
result = ISC_R_SUCCESS;
|
||||
|
||||
error:
|
||||
cleanup:
|
||||
if (udpreq4 != NULL) {
|
||||
json_object_put(udpreq4);
|
||||
}
|
||||
@@ -3654,7 +3563,7 @@ client_ok(const isc_sockaddr_t *fromaddr, void *arg) {
|
||||
|
||||
static void
|
||||
destroy_listener(void *arg) {
|
||||
named_statschannel_t *listener = arg;
|
||||
named_statschannel_t *listener = (named_statschannel_t *)arg;
|
||||
|
||||
REQUIRE(listener != NULL);
|
||||
REQUIRE(!ISC_LINK_LINKED(listener, link));
|
||||
@@ -3672,22 +3581,15 @@ add_listener(named_server_t *server, named_statschannel_t **listenerp,
|
||||
isc_sockaddr_t *addr, cfg_aclconfctx_t *aclconfctx,
|
||||
const char *socktext) {
|
||||
isc_result_t result;
|
||||
named_statschannel_t *listener;
|
||||
isc_task_t *task = NULL;
|
||||
isc_socket_t *sock = NULL;
|
||||
const cfg_obj_t *allow;
|
||||
named_statschannel_t *listener = NULL;
|
||||
const cfg_obj_t *allow = NULL;
|
||||
dns_acl_t *new_acl = NULL;
|
||||
int pf;
|
||||
|
||||
listener = isc_mem_get(server->mctx, sizeof(*listener));
|
||||
|
||||
listener->httpdmgr = NULL;
|
||||
listener->address = *addr;
|
||||
listener->acl = NULL;
|
||||
listener->mctx = NULL;
|
||||
*listener = (named_statschannel_t){ .address = *addr };
|
||||
ISC_LINK_INIT(listener, link);
|
||||
|
||||
isc_mutex_init(&listener->lock);
|
||||
|
||||
isc_mem_attach(server->mctx, &listener->mctx);
|
||||
|
||||
allow = cfg_tuple_get(listen_params, "allow");
|
||||
@@ -3698,104 +3600,80 @@ add_listener(named_server_t *server, named_statschannel_t **listenerp,
|
||||
} else {
|
||||
result = dns_acl_any(listener->mctx, &new_acl);
|
||||
}
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto cleanup;
|
||||
}
|
||||
CHECK(result);
|
||||
|
||||
dns_acl_attach(new_acl, &listener->acl);
|
||||
dns_acl_detach(&new_acl);
|
||||
|
||||
result = isc_task_create(named_g_taskmgr, 0, &task);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto cleanup;
|
||||
}
|
||||
isc_task_setname(task, "statchannel", NULL);
|
||||
|
||||
result = isc_socket_create(named_g_socketmgr, isc_sockaddr_pf(addr),
|
||||
isc_sockettype_tcp, &sock);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto cleanup;
|
||||
}
|
||||
isc_socket_setname(sock, "statchannel", NULL);
|
||||
|
||||
#ifndef ISC_ALLOW_MAPPED
|
||||
isc_socket_ipv6only(sock, true);
|
||||
#endif /* ifndef ISC_ALLOW_MAPPED */
|
||||
|
||||
result = isc_socket_bind(sock, addr, ISC_SOCKET_REUSEADDRESS);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto cleanup;
|
||||
pf = isc_sockaddr_pf(&listener->address);
|
||||
if ((pf == AF_INET && isc_net_probeipv4() != ISC_R_SUCCESS) ||
|
||||
(pf == AF_INET6 && isc_net_probeipv6() != ISC_R_SUCCESS))
|
||||
{
|
||||
CHECK(ISC_R_FAMILYNOSUPPORT);
|
||||
}
|
||||
|
||||
result = isc_httpdmgr_create(server->mctx, sock, task, client_ok,
|
||||
destroy_listener, listener,
|
||||
named_g_timermgr, &listener->httpdmgr);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto cleanup;
|
||||
}
|
||||
CHECK(isc_httpdmgr_create(named_g_nm, server->mctx, addr, client_ok,
|
||||
destroy_listener, listener,
|
||||
&listener->httpdmgr));
|
||||
|
||||
#ifdef HAVE_LIBXML2
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/", render_xml_all, server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/xml", render_xml_all, server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/xml/v3", render_xml_all,
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/", false, render_xml_all,
|
||||
server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/xml/v3/status",
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/xml", false, render_xml_all,
|
||||
server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/xml/v3", false,
|
||||
render_xml_all, server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/xml/v3/status", false,
|
||||
render_xml_status, server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/xml/v3/server",
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/xml/v3/server", false,
|
||||
render_xml_server, server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/xml/v3/zones",
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/xml/v3/zones", false,
|
||||
render_xml_zones, server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/xml/v3/net", render_xml_net,
|
||||
server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/xml/v3/tasks",
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/xml/v3/net", false,
|
||||
render_xml_net, server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/xml/v3/tasks", false,
|
||||
render_xml_tasks, server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/xml/v3/mem", render_xml_mem,
|
||||
server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/xml/v3/traffic",
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/xml/v3/mem", false,
|
||||
render_xml_mem, server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/xml/v3/traffic", false,
|
||||
render_xml_traffic, server);
|
||||
#endif /* ifdef HAVE_LIBXML2 */
|
||||
#ifdef HAVE_JSON_C
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/json", render_json_all,
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/json", false, render_json_all,
|
||||
server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/json/v1", render_json_all,
|
||||
server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/json/v1/status",
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/json/v1", false,
|
||||
render_json_all, server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/json/v1/status", false,
|
||||
render_json_status, server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/json/v1/server",
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/json/v1/server", false,
|
||||
render_json_server, server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/json/v1/zones",
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/json/v1/zones", false,
|
||||
render_json_zones, server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/json/v1/tasks",
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/json/v1/tasks", false,
|
||||
render_json_tasks, server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/json/v1/net", render_json_net,
|
||||
server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/json/v1/mem", render_json_mem,
|
||||
server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/json/v1/traffic",
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/json/v1/net", false,
|
||||
render_json_net, server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/json/v1/mem", false,
|
||||
render_json_mem, server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/json/v1/traffic", false,
|
||||
render_json_traffic, server);
|
||||
#endif /* ifdef HAVE_JSON_C */
|
||||
isc_httpdmgr_addurl2(listener->httpdmgr, "/bind9.xsl", true, render_xsl,
|
||||
server);
|
||||
isc_httpdmgr_addurl(listener->httpdmgr, "/bind9.xsl", true, render_xsl,
|
||||
server);
|
||||
|
||||
*listenerp = listener;
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_NOTICE,
|
||||
"statistics channel listening on %s", socktext);
|
||||
|
||||
return (ISC_R_SUCCESS);
|
||||
|
||||
cleanup:
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
if (listener->acl != NULL) {
|
||||
dns_acl_detach(&listener->acl);
|
||||
}
|
||||
isc_mutex_destroy(&listener->lock);
|
||||
isc_mem_putanddetach(&listener->mctx, listener,
|
||||
sizeof(*listener));
|
||||
}
|
||||
if (task != NULL) {
|
||||
isc_task_detach(&task);
|
||||
}
|
||||
if (sock != NULL) {
|
||||
isc_socket_detach(&sock);
|
||||
if (listener->acl != NULL) {
|
||||
dns_acl_detach(&listener->acl);
|
||||
}
|
||||
isc_mutex_destroy(&listener->lock);
|
||||
isc_mem_putanddetach(&listener->mctx, listener, sizeof(*listener));
|
||||
|
||||
return (result);
|
||||
}
|
||||
|
||||
@@ -67,7 +67,7 @@
|
||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||
<BrowseInformation>true</BrowseInformation>
|
||||
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||
<AdditionalIncludeDirectories>@OPENSSL_INC@@GSSAPI_INC@@GEOIP_INC@.\;..\..\..\;@LIBXML2_INC@..\win32\include;..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\isccc\include;..\..\..\lib\isccfg\include;..\..\..\lib\bind9\include;..\..\..\lib\ns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||
<AdditionalIncludeDirectories>@LIBUV_INC@@OPENSSL_INC@@GSSAPI_INC@@GEOIP_INC@.\;..\..\..\;@LIBXML2_INC@..\win32\include;..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\isccc\include;..\..\..\lib\isccfg\include;..\..\..\lib\bind9\include;..\..\..\lib\ns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||
<CompileAs>CompileAsC</CompileAs>
|
||||
</ClCompile>
|
||||
<Link>
|
||||
@@ -75,7 +75,7 @@
|
||||
<GenerateDebugInformation>true</GenerateDebugInformation>
|
||||
<OutputFile>..\..\..\Build\$(Configuration)\$(TargetName)$(TargetExt)</OutputFile>
|
||||
<AdditionalLibraryDirectories>..\..\..\lib\isc\win32\$(Configuration);..\..\..\lib\dns\win32\$(Configuration);..\..\..\lib\isccc\win32\$(Configuration);..\..\..\lib\isccfg\win32\$(Configuration);..\..\..\lib\bind9\win32\$(Configuration);..\..\..\lib\ns\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
||||
<AdditionalDependencies>@OPENSSL_LIB@@LIBXML2_LIB@@GSSAPI_LIB@@GEOIP_LIB@libisc.lib;libdns.lib;libisccc.lib;libisccfg.lib;libbind9.lib;libns.lib;version.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
||||
<AdditionalDependencies>@LIBUV_LIB@@OPENSSL_LIB@@LIBXML2_LIB@@GSSAPI_LIB@@GEOIP_LIB@libisc.lib;libdns.lib;libisccc.lib;libisccfg.lib;libbind9.lib;libns.lib;version.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
||||
</Link>
|
||||
<PreBuildEvent>
|
||||
<Command>cd ..
|
||||
@@ -103,7 +103,7 @@ perl -e "print \";\";" >> xsl.c
|
||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||
<AdditionalIncludeDirectories>@OPENSSL_INC@@GSSAPI_INC@@GEOIP_INC@.\;..\..\..\;@LIBXML2_INC@..\win32\include;..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\isccc\include;..\..\..\lib\isccfg\include;..\..\..\lib\bind9\include;..\..\..\lib\ns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||
<AdditionalIncludeDirectories>@LIBUV_INC@@OPENSSL_INC@@GSSAPI_INC@@GEOIP_INC@.\;..\..\..\;@LIBXML2_INC@..\win32\include;..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\isccc\include;..\..\..\lib\isccfg\include;..\..\..\lib\bind9\include;..\..\..\lib\ns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||
<CompileAs>CompileAsC</CompileAs>
|
||||
</ClCompile>
|
||||
<Link>
|
||||
@@ -114,7 +114,7 @@ perl -e "print \";\";" >> xsl.c
|
||||
<OutputFile>..\..\..\Build\$(Configuration)\$(TargetName)$(TargetExt)</OutputFile>
|
||||
<LinkTimeCodeGeneration>Default</LinkTimeCodeGeneration>
|
||||
<AdditionalLibraryDirectories>..\..\..\lib\isc\win32\$(Configuration);..\..\..\lib\dns\win32\$(Configuration);..\..\..\lib\isccc\win32\$(Configuration);..\..\..\lib\isccfg\win32\$(Configuration);..\..\..\lib\bind9\win32\$(Configuration);..\..\..\lib\ns\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
||||
<AdditionalDependencies>@OPENSSL_LIB@@LIBXML2_LIB@@GSSAPI_LIB@@GEOIP_LIB@libisc.lib;libdns.lib;libisccc.lib;libisccfg.lib;libbind9.lib;libns.lib;version.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
||||
<AdditionalDependencies>@LIBUV_LIB@@OPENSSL_LIB@@LIBXML2_LIB@@GSSAPI_LIB@@GEOIP_LIB@libisc.lib;libdns.lib;libisccc.lib;libisccfg.lib;libbind9.lib;libns.lib;version.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
||||
</Link>
|
||||
<PreBuildEvent>
|
||||
<Command>cd ..
|
||||
|
||||
@@ -252,7 +252,8 @@ configure_zone_ssutable(const cfg_obj_t *zconfig, dns_zone_t *zone,
|
||||
|
||||
str = cfg_obj_asstring(matchtype);
|
||||
CHECK(dns_ssu_mtypefromstring(str, &mtype));
|
||||
if (mtype == dns_ssumatchtype_subdomain) {
|
||||
if (mtype == dns_ssumatchtype_subdomain &&
|
||||
strcasecmp(str, "zonesub") == 0) {
|
||||
usezone = true;
|
||||
}
|
||||
|
||||
@@ -1594,11 +1595,11 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
if (cfg_obj_isvoid(resign)) {
|
||||
seconds /= 4;
|
||||
} else if (!sigvalinsecs) {
|
||||
seconds = cfg_obj_asuint32(resign);
|
||||
uint32_t r = cfg_obj_asuint32(resign);
|
||||
if (seconds > 7 * 86400) {
|
||||
seconds *= 86400;
|
||||
seconds = r * 86400;
|
||||
} else {
|
||||
seconds *= 3600;
|
||||
seconds = r * 3600;
|
||||
}
|
||||
} else {
|
||||
seconds = cfg_obj_asuint32(resign);
|
||||
|
||||
@@ -18,8 +18,12 @@ LDADD = \
|
||||
$(LIBISCCFG_LIBS) \
|
||||
$(LIBIRS_LIBS) \
|
||||
$(LIBBIND9_LIBS) \
|
||||
$(READLINE_LIB) \
|
||||
$(GSSAPI_LIBS) \
|
||||
$(KRB5_LIBS)
|
||||
|
||||
if HAVE_READLINE
|
||||
LDADD += \
|
||||
$(READLINE_LIBS)
|
||||
endif
|
||||
|
||||
bin_PROGRAMS = nsupdate
|
||||
|
||||
+8
-28
@@ -36,6 +36,7 @@
|
||||
#include <isc/portset.h>
|
||||
#include <isc/print.h>
|
||||
#include <isc/random.h>
|
||||
#include <isc/readline.h>
|
||||
#include <isc/region.h>
|
||||
#include <isc/sockaddr.h>
|
||||
#include <isc/socket.h>
|
||||
@@ -94,20 +95,6 @@
|
||||
|
||||
#include <bind9/getaddresses.h>
|
||||
|
||||
#if defined(HAVE_READLINE)
|
||||
#if defined(HAVE_EDIT_READLINE_READLINE_H)
|
||||
#include <edit/readline/readline.h>
|
||||
#if defined(HAVE_EDIT_READLINE_HISTORY_H)
|
||||
#include <edit/readline/history.h>
|
||||
#endif /* if defined(HAVE_EDIT_READLINE_HISTORY_H) */
|
||||
#elif defined(HAVE_EDITLINE_READLINE_H)
|
||||
#include <editline/readline.h>
|
||||
#else /* if defined(HAVE_EDIT_READLINE_READLINE_H) */
|
||||
#include <readline/history.h>
|
||||
#include <readline/readline.h>
|
||||
#endif /* if defined(HAVE_EDIT_READLINE_READLINE_H) */
|
||||
#endif /* if defined(HAVE_READLINE) */
|
||||
|
||||
#define MAXCMD (128 * 1024)
|
||||
#define MAXWIRE (64 * 1024)
|
||||
#define PACKETSIZE ((64 * 1024) - 1)
|
||||
@@ -2290,20 +2277,14 @@ static uint16_t
|
||||
get_next_command(void) {
|
||||
uint16_t result = STATUS_QUIT;
|
||||
char cmdlinebuf[MAXCMD];
|
||||
char *cmdline;
|
||||
char *cmdline = NULL, *ptr = NULL;
|
||||
|
||||
isc_app_block();
|
||||
if (interactive) {
|
||||
#ifdef HAVE_READLINE
|
||||
cmdline = readline("> ");
|
||||
if (cmdline != NULL) {
|
||||
add_history(cmdline);
|
||||
cmdline = ptr = readline("> ");
|
||||
if (ptr != NULL && *ptr != 0) {
|
||||
add_history(ptr);
|
||||
}
|
||||
#else /* ifdef HAVE_READLINE */
|
||||
fprintf(stdout, "> ");
|
||||
fflush(stdout);
|
||||
cmdline = fgets(cmdlinebuf, MAXCMD, input);
|
||||
#endif /* ifdef HAVE_READLINE */
|
||||
} else {
|
||||
cmdline = fgets(cmdlinebuf, MAXCMD, input);
|
||||
}
|
||||
@@ -2319,11 +2300,10 @@ get_next_command(void) {
|
||||
(void)nsu_strsep(&tmp, "\r\n");
|
||||
result = do_next_command(cmdline);
|
||||
}
|
||||
#ifdef HAVE_READLINE
|
||||
if (interactive) {
|
||||
free(cmdline);
|
||||
if (ptr != NULL) {
|
||||
free(ptr);
|
||||
}
|
||||
#endif /* ifdef HAVE_READLINE */
|
||||
|
||||
return (result);
|
||||
}
|
||||
|
||||
|
||||
@@ -169,7 +169,7 @@ install_hooks(ns_hooktable_t *hooktable, isc_mem_t *mctx,
|
||||
.action_data = inst,
|
||||
};
|
||||
|
||||
ns_hook_add(hooktable, mctx, -NS_QUERY_QCTX_INITIALIZED, &filter_init);
|
||||
ns_hook_add(hooktable, mctx, NS_QUERY_QCTX_INITIALIZED, &filter_init);
|
||||
ns_hook_add(hooktable, mctx, NS_QUERY_RESPOND_BEGIN, &filter_respbegin);
|
||||
ns_hook_add(hooktable, mctx, NS_QUERY_RESPOND_ANY_FOUND,
|
||||
&filter_respanyfound);
|
||||
|
||||
+153
-123
@@ -24,6 +24,7 @@
|
||||
#include <isc/log.h>
|
||||
#include <isc/mem.h>
|
||||
#include <isc/net.h>
|
||||
#include <isc/netmgr.h>
|
||||
#include <isc/print.h>
|
||||
#include <isc/random.h>
|
||||
#include <isc/refcount.h>
|
||||
@@ -55,11 +56,14 @@
|
||||
|
||||
#define SERVERADDRS 10
|
||||
|
||||
const char *progname;
|
||||
const char *progname = NULL;
|
||||
bool verbose;
|
||||
|
||||
static const char *admin_conffile;
|
||||
static const char *admin_keyfile;
|
||||
static isc_taskmgr_t *taskmgr = NULL;
|
||||
static isc_task_t *rndc_task = NULL;
|
||||
|
||||
static const char *admin_conffile = NULL;
|
||||
static const char *admin_keyfile = NULL;
|
||||
static const char *version = PACKAGE_VERSION;
|
||||
static const char *servername = NULL;
|
||||
static isc_sockaddr_t serveraddrs[SERVERADDRS];
|
||||
@@ -68,27 +72,28 @@ static bool local4set = false, local6set = false;
|
||||
static int nserveraddrs;
|
||||
static int currentaddr = 0;
|
||||
static unsigned int remoteport = 0;
|
||||
static isc_socketmgr_t *socketmgr = NULL;
|
||||
static isc_buffer_t *databuf;
|
||||
static isccc_ccmsg_t ccmsg;
|
||||
static isc_nm_t *netmgr = NULL;
|
||||
static isc_buffer_t *databuf = NULL;
|
||||
static isccc_ccmsg_t rndc_ccmsg;
|
||||
static uint32_t algorithm;
|
||||
static isccc_region_t secret;
|
||||
static bool failed = false;
|
||||
static bool c_flag = false;
|
||||
static isc_mem_t *rndc_mctx;
|
||||
static isc_mem_t *rndc_mctx = NULL;
|
||||
static atomic_uint_fast32_t sends = ATOMIC_VAR_INIT(0);
|
||||
static atomic_uint_fast32_t recvs = ATOMIC_VAR_INIT(0);
|
||||
static atomic_uint_fast32_t connects = ATOMIC_VAR_INIT(0);
|
||||
static char *command;
|
||||
static char *args;
|
||||
static char *command = NULL;
|
||||
static char *args = NULL;
|
||||
static char program[256];
|
||||
static isc_socket_t *sock = NULL;
|
||||
static uint32_t serial;
|
||||
static bool quiet = false;
|
||||
static bool showresult = false;
|
||||
static bool shuttingdown = false;
|
||||
static isc_nmhandle_t *readhandle = NULL, *sendhandle = NULL;
|
||||
|
||||
static void
|
||||
rndc_startconnect(isc_sockaddr_t *addr, isc_task_t *task);
|
||||
rndc_startconnect(isc_sockaddr_t *addr);
|
||||
|
||||
ISC_NORETURN static void
|
||||
usage(int status);
|
||||
@@ -105,6 +110,12 @@ command is one of the following:\n\
|
||||
Add zone to given view. Requires allow-new-zones option.\n\
|
||||
delzone [-clean] zone [class [view]]\n\
|
||||
Removes zone from given view.\n\
|
||||
dnssec -checkds [-key id [-alg algorithm] [-when time] (published|withdrawn) zone [class [view]]\n\
|
||||
Mark the DS record for the KSK of the given zone as seen\n\
|
||||
in the parent. If the zone has multiple KSKs, select a\n\
|
||||
specific key by providing the keytag with -key id and\n\
|
||||
optionally the key's algorithm with -alg algorithm.\n\
|
||||
Requires the zone to have a dnssec-policy.\n\
|
||||
dnssec -status zone [class [view]]\n\
|
||||
Show the DNSSEC signing state for the specified zone.\n\
|
||||
Requires the zone to have a dnssec-policy.\n\
|
||||
@@ -114,7 +125,7 @@ command is one of the following:\n\
|
||||
Close, rename and re-open the DNSTAP output file(s).\n\
|
||||
dumpdb [-all|-cache|-zones|-adb|-bad|-fail] [view ...]\n\
|
||||
Dump cache(s) to the dump file (named_dump.db).\n\
|
||||
flush Flushes all of the server's caches.\n\
|
||||
flush Flushes all of the server's caches.\n\
|
||||
flush [view] Flushes the server's cache for a view.\n\
|
||||
flushname name [view]\n\
|
||||
Flush the given name from the server's cache(s)\n\
|
||||
@@ -278,51 +289,59 @@ get_addresses(const char *host, in_port_t port) {
|
||||
}
|
||||
|
||||
static void
|
||||
rndc_senddone(isc_task_t *task, isc_event_t *event) {
|
||||
isc_socketevent_t *sevent = (isc_socketevent_t *)event;
|
||||
rndc_senddone(isc_nmhandle_t *handle, isc_result_t result, void *arg) {
|
||||
REQUIRE(handle == sendhandle);
|
||||
|
||||
UNUSED(task);
|
||||
UNUSED(arg);
|
||||
|
||||
if (sevent->result != ISC_R_SUCCESS) {
|
||||
fatal("send failed: %s", isc_result_totext(sevent->result));
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
fatal("send failed: %s", isc_result_totext(result));
|
||||
}
|
||||
isc_event_free(&event);
|
||||
|
||||
isc_nmhandle_detach(&sendhandle);
|
||||
if (atomic_fetch_sub_release(&sends, 1) == 1 &&
|
||||
atomic_load_acquire(&recvs) == 0)
|
||||
{
|
||||
isc_socket_detach(&sock);
|
||||
isc_task_shutdown(task);
|
||||
shuttingdown = true;
|
||||
isc_task_shutdown(rndc_task);
|
||||
isc_app_shutdown();
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
rndc_recvdone(isc_task_t *task, isc_event_t *event) {
|
||||
rndc_recvdone(isc_nmhandle_t *handle, isc_result_t result, void *arg) {
|
||||
isccc_ccmsg_t *ccmsg = (isccc_ccmsg_t *)arg;
|
||||
isccc_sexpr_t *response = NULL;
|
||||
isccc_sexpr_t *data;
|
||||
isccc_region_t source;
|
||||
char *errormsg = NULL;
|
||||
char *textmsg = NULL;
|
||||
isc_result_t result;
|
||||
|
||||
REQUIRE(ccmsg != NULL);
|
||||
|
||||
atomic_fetch_sub_release(&recvs, 1);
|
||||
|
||||
if (ccmsg.result == ISC_R_EOF) {
|
||||
fatal("connection to remote host closed\n"
|
||||
"This may indicate that\n"
|
||||
"* the remote server is using an older version of"
|
||||
" the command protocol,\n"
|
||||
if (shuttingdown && (result == ISC_R_EOF || result == ISC_R_CANCELED)) {
|
||||
if (readhandle != NULL) {
|
||||
INSIST(handle == readhandle);
|
||||
isc_nmhandle_detach(&readhandle);
|
||||
}
|
||||
return;
|
||||
} else if (result == ISC_R_EOF) {
|
||||
fatal("connection to remote host closed.\n"
|
||||
"* This may indicate that the\n"
|
||||
"* remote server is using an older\n"
|
||||
"* version of the command protocol,\n"
|
||||
"* this host is not authorized to connect,\n"
|
||||
"* the clocks are not synchronized, or\n"
|
||||
"* the key is invalid.");
|
||||
"* the clocks are not synchronized,\n"
|
||||
"* the key signing algorithm is incorrect,\n"
|
||||
"* or the key is invalid.");
|
||||
} else if (result != ISC_R_SUCCESS && result != ISC_R_CANCELED) {
|
||||
fatal("recv failed: %s", isc_result_totext(result));
|
||||
}
|
||||
|
||||
if (ccmsg.result != ISC_R_SUCCESS) {
|
||||
fatal("recv failed: %s", isc_result_totext(ccmsg.result));
|
||||
}
|
||||
|
||||
source.rstart = isc_buffer_base(&ccmsg.buffer);
|
||||
source.rend = isc_buffer_used(&ccmsg.buffer);
|
||||
source.rstart = isc_buffer_base(ccmsg->buffer);
|
||||
source.rend = isc_buffer_used(ccmsg->buffer);
|
||||
|
||||
DO("parse message",
|
||||
isccc_cc_fromwire(&source, &response, algorithm, &secret));
|
||||
@@ -362,22 +381,23 @@ rndc_recvdone(isc_task_t *task, isc_event_t *event) {
|
||||
}
|
||||
}
|
||||
|
||||
isc_event_free(&event);
|
||||
isccc_sexpr_free(&response);
|
||||
|
||||
if (atomic_load_acquire(&sends) == 0 &&
|
||||
atomic_load_acquire(&recvs) == 0) {
|
||||
isc_socket_detach(&sock);
|
||||
isc_task_shutdown(task);
|
||||
isc_nmhandle_detach(&readhandle);
|
||||
shuttingdown = true;
|
||||
isc_task_shutdown(rndc_task);
|
||||
isc_app_shutdown();
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
rndc_recvnonce(isc_task_t *task, isc_event_t *event) {
|
||||
rndc_recvnonce(isc_nmhandle_t *handle, isc_result_t result, void *arg) {
|
||||
isccc_ccmsg_t *ccmsg = (isccc_ccmsg_t *)arg;
|
||||
isccc_sexpr_t *response = NULL;
|
||||
isccc_sexpr_t *_ctrl;
|
||||
isccc_region_t source;
|
||||
isc_result_t result;
|
||||
uint32_t nonce;
|
||||
isccc_sexpr_t *request = NULL;
|
||||
isccc_time_t now;
|
||||
@@ -385,25 +405,29 @@ rndc_recvnonce(isc_task_t *task, isc_event_t *event) {
|
||||
isccc_sexpr_t *data;
|
||||
isc_buffer_t b;
|
||||
|
||||
REQUIRE(handle == readhandle);
|
||||
REQUIRE(ccmsg != NULL);
|
||||
|
||||
atomic_fetch_sub_release(&recvs, 1);
|
||||
|
||||
if (ccmsg.result == ISC_R_EOF) {
|
||||
fatal("connection to remote host closed\n"
|
||||
"This may indicate that\n"
|
||||
"* the remote server is using an older version of"
|
||||
" the command protocol,\n"
|
||||
if (shuttingdown && result == ISC_R_EOF) {
|
||||
isc_nmhandle_detach(&readhandle);
|
||||
return;
|
||||
} else if (result == ISC_R_EOF) {
|
||||
fatal("connection to remote host closed.\n"
|
||||
"* This may indicate that the\n"
|
||||
"* remote server is using an older\n"
|
||||
"* version of the command protocol,\n"
|
||||
"* this host is not authorized to connect,\n"
|
||||
"* the clocks are not synchronized,\n"
|
||||
"* the key signing algorithm is incorrect, or\n"
|
||||
"* the key is invalid.");
|
||||
"* the key signing algorithm is incorrect\n"
|
||||
"* or the key is invalid.");
|
||||
} else if (result != ISC_R_SUCCESS) {
|
||||
fatal("recv failed: %s", isc_result_totext(result));
|
||||
}
|
||||
|
||||
if (ccmsg.result != ISC_R_SUCCESS) {
|
||||
fatal("recv failed: %s", isc_result_totext(ccmsg.result));
|
||||
}
|
||||
|
||||
source.rstart = isc_buffer_base(&ccmsg.buffer);
|
||||
source.rend = isc_buffer_used(&ccmsg.buffer);
|
||||
source.rstart = isc_buffer_base(ccmsg->buffer);
|
||||
source.rend = isc_buffer_used(ccmsg->buffer);
|
||||
|
||||
DO("parse message",
|
||||
isccc_cc_fromwire(&source, &response, algorithm, &secret));
|
||||
@@ -451,48 +475,47 @@ rndc_recvnonce(isc_task_t *task, isc_event_t *event) {
|
||||
r.base = databuf->base;
|
||||
r.length = databuf->used;
|
||||
|
||||
isccc_ccmsg_cancelread(&ccmsg);
|
||||
DO("schedule recv",
|
||||
isccc_ccmsg_readmessage(&ccmsg, task, rndc_recvdone, NULL));
|
||||
isccc_ccmsg_readmessage(ccmsg, rndc_recvdone, ccmsg));
|
||||
atomic_fetch_add_relaxed(&recvs, 1);
|
||||
DO("send message",
|
||||
isc_socket_send(sock, &r, task, rndc_senddone, NULL));
|
||||
|
||||
if (sendhandle == NULL) {
|
||||
isc_nmhandle_attach(handle, &sendhandle);
|
||||
}
|
||||
DO("send message", isc_nm_send(handle, &r, rndc_senddone, NULL));
|
||||
atomic_fetch_add_relaxed(&sends, 1);
|
||||
|
||||
isc_event_free(&event);
|
||||
isccc_sexpr_free(&response);
|
||||
isccc_sexpr_free(&request);
|
||||
return;
|
||||
}
|
||||
|
||||
static void
|
||||
rndc_connected(isc_task_t *task, isc_event_t *event) {
|
||||
rndc_connected(isc_nmhandle_t *handle, isc_result_t result, void *arg) {
|
||||
isccc_ccmsg_t *ccmsg = (isccc_ccmsg_t *)arg;
|
||||
char socktext[ISC_SOCKADDR_FORMATSIZE];
|
||||
isc_socketevent_t *sevent = (isc_socketevent_t *)event;
|
||||
isccc_sexpr_t *request = NULL;
|
||||
isccc_sexpr_t *data;
|
||||
isccc_time_t now;
|
||||
isc_region_t r;
|
||||
isc_buffer_t b;
|
||||
isc_result_t result;
|
||||
|
||||
REQUIRE(ccmsg != NULL);
|
||||
|
||||
atomic_fetch_sub_release(&connects, 1);
|
||||
|
||||
if (sevent->result != ISC_R_SUCCESS) {
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
isc_sockaddr_format(&serveraddrs[currentaddr], socktext,
|
||||
sizeof(socktext));
|
||||
if (sevent->result != ISC_R_CANCELED &&
|
||||
++currentaddr < nserveraddrs) {
|
||||
if (++currentaddr < nserveraddrs) {
|
||||
notify("connection failed: %s: %s", socktext,
|
||||
isc_result_totext(sevent->result));
|
||||
isc_socket_detach(&sock);
|
||||
isc_event_free(&event);
|
||||
rndc_startconnect(&serveraddrs[currentaddr], task);
|
||||
isc_result_totext(result));
|
||||
rndc_startconnect(&serveraddrs[currentaddr]);
|
||||
return;
|
||||
} else {
|
||||
fatal("connect failed: %s: %s", socktext,
|
||||
isc_result_totext(sevent->result));
|
||||
}
|
||||
|
||||
fatal("connect failed: %s: %s", socktext,
|
||||
isc_result_totext(result));
|
||||
}
|
||||
|
||||
isc_stdtime_get(&now);
|
||||
@@ -519,50 +542,56 @@ rndc_connected(isc_task_t *task, isc_event_t *event) {
|
||||
r.base = databuf->base;
|
||||
r.length = databuf->used;
|
||||
|
||||
isccc_ccmsg_init(rndc_mctx, sock, &ccmsg);
|
||||
isccc_ccmsg_setmaxsize(&ccmsg, 1024 * 1024);
|
||||
isccc_ccmsg_init(rndc_mctx, handle, ccmsg);
|
||||
isccc_ccmsg_setmaxsize(ccmsg, 1024 * 1024);
|
||||
|
||||
if (readhandle == NULL) {
|
||||
isc_nmhandle_attach(handle, &readhandle);
|
||||
}
|
||||
DO("schedule recv",
|
||||
isccc_ccmsg_readmessage(&ccmsg, task, rndc_recvnonce, NULL));
|
||||
isccc_ccmsg_readmessage(ccmsg, rndc_recvnonce, ccmsg));
|
||||
atomic_fetch_add_relaxed(&recvs, 1);
|
||||
DO("send message",
|
||||
isc_socket_send(sock, &r, task, rndc_senddone, NULL));
|
||||
|
||||
if (sendhandle == NULL) {
|
||||
isc_nmhandle_attach(handle, &sendhandle);
|
||||
}
|
||||
DO("send message", isc_nm_send(handle, &r, rndc_senddone, NULL));
|
||||
atomic_fetch_add_relaxed(&sends, 1);
|
||||
isc_event_free(&event);
|
||||
|
||||
isccc_sexpr_free(&request);
|
||||
}
|
||||
|
||||
static void
|
||||
rndc_startconnect(isc_sockaddr_t *addr, isc_task_t *task) {
|
||||
rndc_startconnect(isc_sockaddr_t *addr) {
|
||||
isc_result_t result;
|
||||
int pf;
|
||||
isc_sockettype_t type;
|
||||
|
||||
char socktext[ISC_SOCKADDR_FORMATSIZE];
|
||||
isc_sockaddr_t *local = NULL;
|
||||
|
||||
isc_sockaddr_format(addr, socktext, sizeof(socktext));
|
||||
|
||||
notify("using server %s (%s)", servername, socktext);
|
||||
|
||||
pf = isc_sockaddr_pf(addr);
|
||||
if (pf == AF_INET || pf == AF_INET6) {
|
||||
type = isc_sockettype_tcp;
|
||||
} else {
|
||||
type = isc_sockettype_unix;
|
||||
}
|
||||
DO("create socket", isc_socket_create(socketmgr, pf, type, &sock));
|
||||
switch (isc_sockaddr_pf(addr)) {
|
||||
case AF_INET:
|
||||
DO("bind socket", isc_socket_bind(sock, &local4, 0));
|
||||
local = &local4;
|
||||
break;
|
||||
case AF_INET6:
|
||||
DO("bind socket", isc_socket_bind(sock, &local6, 0));
|
||||
local = &local6;
|
||||
break;
|
||||
case AF_UNIX:
|
||||
/*
|
||||
* TODO: support UNIX domain sockets in netgmr.
|
||||
*/
|
||||
fatal("UNIX domain sockets not currently supported");
|
||||
default:
|
||||
break;
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
}
|
||||
DO("connect",
|
||||
isc_socket_connect(sock, addr, task, rndc_connected, NULL));
|
||||
|
||||
DO("create connection",
|
||||
isc_nm_tcpconnect(netmgr, (isc_nmiface_t *)local,
|
||||
(isc_nmiface_t *)addr, rndc_connected, &rndc_ccmsg,
|
||||
0));
|
||||
atomic_fetch_add_relaxed(&connects, 1);
|
||||
}
|
||||
|
||||
@@ -570,8 +599,10 @@ static void
|
||||
rndc_start(isc_task_t *task, isc_event_t *event) {
|
||||
isc_event_free(&event);
|
||||
|
||||
UNUSED(task);
|
||||
|
||||
currentaddr = 0;
|
||||
rndc_startconnect(&serveraddrs[currentaddr], task);
|
||||
rndc_startconnect(&serveraddrs[currentaddr]);
|
||||
}
|
||||
|
||||
static void
|
||||
@@ -652,7 +683,7 @@ parse_config(isc_mem_t *mctx, isc_log_t *log, const char *keyname,
|
||||
if (servers != NULL) {
|
||||
for (elt = cfg_list_first(servers); elt != NULL;
|
||||
elt = cfg_list_next(elt)) {
|
||||
const char *name;
|
||||
const char *name = NULL;
|
||||
server = cfg_listelt_value(elt);
|
||||
name = cfg_obj_asstring(
|
||||
cfg_map_getname(server));
|
||||
@@ -689,9 +720,11 @@ parse_config(isc_mem_t *mctx, isc_log_t *log, const char *keyname,
|
||||
DO("get config key list", cfg_map_get(config, "key", &keys));
|
||||
for (elt = cfg_list_first(keys); elt != NULL;
|
||||
elt = cfg_list_next(elt)) {
|
||||
const char *name = NULL;
|
||||
|
||||
key = cfg_listelt_value(elt);
|
||||
if (strcasecmp(cfg_obj_asstring(cfg_map_getname(key)),
|
||||
keyname) == 0) {
|
||||
name = cfg_obj_asstring(cfg_map_getname(key));
|
||||
if (strcasecmp(name, keyname) == 0) {
|
||||
break;
|
||||
}
|
||||
}
|
||||
@@ -851,8 +884,6 @@ int
|
||||
main(int argc, char **argv) {
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
bool show_final_mem = false;
|
||||
isc_taskmgr_t *taskmgr = NULL;
|
||||
isc_task_t *task = NULL;
|
||||
isc_log_t *log = NULL;
|
||||
isc_logconfig_t *logconfig = NULL;
|
||||
isc_logdestination_t logdest;
|
||||
@@ -978,19 +1009,23 @@ main(int argc, char **argv) {
|
||||
argc -= isc_commandline_index;
|
||||
argv += isc_commandline_index;
|
||||
|
||||
if (argc < 1) {
|
||||
if (argv[0] == NULL) {
|
||||
usage(1);
|
||||
} else {
|
||||
command = argv[0];
|
||||
if (strcmp(command, "restart") == 0) {
|
||||
fatal("'%s' is not implemented", command);
|
||||
}
|
||||
notify("%s", command);
|
||||
}
|
||||
|
||||
serial = isc_random32();
|
||||
|
||||
isc_mem_create(&rndc_mctx);
|
||||
DO("create socket manager",
|
||||
isc_socketmgr_create(rndc_mctx, &socketmgr));
|
||||
netmgr = isc_nm_start(rndc_mctx, 1);
|
||||
DO("create task manager",
|
||||
isc_taskmgr_create(rndc_mctx, 1, 0, NULL, &taskmgr));
|
||||
DO("create task", isc_task_create(taskmgr, 0, &task));
|
||||
|
||||
isc_taskmgr_create(rndc_mctx, 1, 0, netmgr, &taskmgr));
|
||||
DO("create task", isc_task_create(taskmgr, 0, &rndc_task));
|
||||
isc_log_create(rndc_mctx, &log, &logconfig);
|
||||
isc_log_setcontext(log);
|
||||
isc_log_settag(logconfig, progname);
|
||||
@@ -1008,8 +1043,6 @@ main(int argc, char **argv) {
|
||||
|
||||
isccc_result_register();
|
||||
|
||||
command = *argv;
|
||||
|
||||
isc_buffer_allocate(rndc_mctx, &databuf, 2048);
|
||||
|
||||
/*
|
||||
@@ -1036,32 +1069,30 @@ main(int argc, char **argv) {
|
||||
*p++ = '\0';
|
||||
INSIST(p == args + argslen);
|
||||
|
||||
notify("%s", command);
|
||||
|
||||
if (strcmp(command, "restart") == 0) {
|
||||
fatal("'%s' is not implemented", command);
|
||||
}
|
||||
|
||||
if (nserveraddrs == 0 && servername != NULL) {
|
||||
get_addresses(servername, (in_port_t)remoteport);
|
||||
}
|
||||
|
||||
DO("post event", isc_app_onrun(rndc_mctx, task, rndc_start, NULL));
|
||||
DO("post event", isc_app_onrun(rndc_mctx, rndc_task, rndc_start, NULL));
|
||||
|
||||
result = isc_app_run();
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
fatal("isc_app_run() failed: %s", isc_result_totext(result));
|
||||
}
|
||||
|
||||
if (atomic_load_acquire(&connects) > 0 ||
|
||||
atomic_load_acquire(&sends) > 0 || atomic_load_acquire(&recvs) > 0)
|
||||
{
|
||||
isc_socket_cancel(sock, task, ISC_SOCKCANCEL_ALL);
|
||||
}
|
||||
|
||||
isc_task_detach(&task);
|
||||
isc_task_detach(&rndc_task);
|
||||
isc_taskmgr_destroy(&taskmgr);
|
||||
isc_socketmgr_destroy(&socketmgr);
|
||||
|
||||
isc_nm_destroy(&netmgr);
|
||||
|
||||
/*
|
||||
* Note: when TCP connections are shut down, there will be a final
|
||||
* call to the isccc callback routine with &rndc_ccmsg as its
|
||||
* argument. We therefore need to delay invalidating it until
|
||||
* after the netmgr is destroyed.
|
||||
*/
|
||||
isccc_ccmsg_invalidate(&rndc_ccmsg);
|
||||
|
||||
isc_log_destroy(&log);
|
||||
isc_log_setcontext(NULL);
|
||||
|
||||
@@ -1069,7 +1100,6 @@ main(int argc, char **argv) {
|
||||
cfg_parser_destroy(&pctx);
|
||||
|
||||
isc_mem_put(rndc_mctx, args, argslen);
|
||||
isccc_ccmsg_invalidate(&ccmsg);
|
||||
|
||||
isc_buffer_free(&databuf);
|
||||
|
||||
|
||||
+15
-3
@@ -161,9 +161,21 @@ Currently supported commands are:
|
||||
|
||||
See also ``rndc addzone`` and ``rndc modzone``.
|
||||
|
||||
``dnssec`` [**-status** *zone* [*class* [*view*]]
|
||||
Show the DNSSEC signing state for the specified zone. Requires the
|
||||
zone to have a "dnssec-policy".
|
||||
``dnssec`` ( **-status** | **-checkds** [**-key** *id* [**-alg** *algorithm*]] [**-when** *time*] ( *published* | *withdrawn* )) *zone* [*class* [*view*]]
|
||||
This command allows you to interact with the "dnssec-policy" of a given
|
||||
zone.
|
||||
|
||||
``rndc dnssec -status`` show the DNSSEC signing state for the specified
|
||||
zone.
|
||||
|
||||
``rndc dnssec -checkds`` will let ``named`` know that the DS for the given
|
||||
key has been seen published into or withdrawn from the parent. This is
|
||||
required in order to complete a KSK rollover. If the ``-key id`` argument
|
||||
is specified, look for the key with the given identifier, otherwise if there
|
||||
is only one key acting as a KSK in the zone, assume the DS of that key (if
|
||||
there are multiple keys with the same tag, use ``-alg algorithm`` to
|
||||
select the correct algorithm). The time that the DS has been published or
|
||||
withdrawn is set to now, unless otherwise specified with the argument ``-when time``.
|
||||
|
||||
``dnstap`` ( **-reopen** | **-roll** [*number*] )
|
||||
This command closes and re-opens DNSTAP output files. ``rndc dnstap -reopen`` allows
|
||||
|
||||
@@ -374,7 +374,7 @@ a run of the full test suite (e.g. the tests are started with "runall.sh").
|
||||
|
||||
3. Each script should start with the following lines:
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
"conf.sh" defines a series of environment variables together with functions
|
||||
useful for the test scripts. (conf.sh.win32 is the Windows equivalent of this
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
$SHELL clean.sh
|
||||
$SHELL ${TOP_SRCDIR}/bin/tests/system/genzone.sh 2 3 >ns2/example.db
|
||||
|
||||
@@ -9,10 +9,10 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
DIGOPTS="+tcp +noadd +nosea +nostat +noquest +nocomm +nocmd -p ${PORT}"
|
||||
RNDCCMD="$RNDC -c $SYSTEMTESTTOP/common/rndc.conf -p ${CONTROLPORT} -s"
|
||||
RNDCCMD="$RNDC -c ../common/rndc.conf -p ${CONTROLPORT} -s"
|
||||
|
||||
status=0
|
||||
t=0
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# this server runs named with only one worker thread
|
||||
-m record,size,mctx -c named.conf -d 99 -D additional-ns1 -X named.lock -g -n 1
|
||||
-m record,size,mctx -c named.conf -d 99 -D additional-ns1 -X named.lock -g -n 1 -T maxcachesize=2097152
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
$SHELL clean.sh
|
||||
copy_setports ns1/named1.conf.in ns1/named.conf
|
||||
|
||||
@@ -9,10 +9,10 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
DIGOPTS="-p ${PORT}"
|
||||
RNDCCMD="$RNDC -c $SYSTEMTESTTOP/common/rndc.conf -p ${CONTROLPORT} -s"
|
||||
RNDCCMD="$RNDC -c ../common/rndc.conf -p ${CONTROLPORT} -s"
|
||||
|
||||
status=0
|
||||
n=0
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
cp -f ns1/redirect.db.1 ns1/redirect.db
|
||||
cp -f ns2/redirect.db.1 ns2/redirect.db
|
||||
|
||||
@@ -9,10 +9,10 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
DIGOPTS="+tcp +nosea +nostat +nocmd +norec +noques +noauth +noadd +nostats +dnssec -p ${PORT}"
|
||||
RNDCCMD="$RNDC -c $SYSTEMTESTTOP/common/rndc.conf -p ${CONTROLPORT} -s"
|
||||
RNDCCMD="$RNDC -c ../common/rndc.conf -p ${CONTROLPORT} -s"
|
||||
|
||||
check_zonestatus() (
|
||||
$RNDCCMD "10.53.0.$1" zonestatus -redirect > "zonestatus.out.ns$1.$n" &&
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# this server only has 127.0.0.1 in its localhost/localnets ACLs
|
||||
-m record,size,mctx -c named.conf -d 99 -D allow-query-ns3 -X named.lock -g -T fixedlocal
|
||||
-m record,size,mctx -c named.conf -d 99 -D allow-query-ns3 -X named.lock -g -T maxcachesize=2097152 -T fixedlocal
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
copy_setports ../common/controls.conf.in ns2/controls.conf
|
||||
copy_setports ns1/named.conf.in ns1/named.conf
|
||||
|
||||
@@ -50,7 +50,7 @@
|
||||
# and querying as necessary.
|
||||
#
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
DIGOPTS="+tcp +nosea +nostat +nocmd +norec +noques +noauth +noadd +nostats +dnssec -p ${PORT}"
|
||||
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
copy_setports ns1/named.conf.in ns1/named.conf
|
||||
copy_setports ns2/named.conf.in ns2/named.conf
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
DIGOPTS="+tcp -p ${PORT}"
|
||||
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../../conf.sh
|
||||
|
||||
zone=.
|
||||
zonefile=root.db
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../../conf.sh
|
||||
|
||||
# Have the child generate subdomain keys and pass DS sets to us.
|
||||
( cd ../ns3 && $SHELL keygen.sh )
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../../conf.sh
|
||||
|
||||
SYSTESTDIR=autosign
|
||||
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
copy_setports ns1/named.conf.in ns1/named.conf
|
||||
copy_setports ns2/named.conf.in ns2/named.conf
|
||||
|
||||
@@ -9,13 +9,13 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
status=0
|
||||
n=0
|
||||
|
||||
DIGOPTS="+tcp +noadd +nosea +nostat +nocmd +dnssec -p ${PORT}"
|
||||
RNDCCMD="$RNDC -c $SYSTEMTESTTOP/common/rndc.conf -p ${CONTROLPORT} -s"
|
||||
RNDCCMD="$RNDC -c ../common/rndc.conf -p ${CONTROLPORT} -s"
|
||||
|
||||
# convert private-type records to readable form
|
||||
showprivate () {
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
copy_setports ns1/named.conf.in ns1/named.conf
|
||||
copy_setports ns2/named.conf.in ns2/named.conf
|
||||
|
||||
@@ -7,10 +7,10 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
DIGOPTS="-p ${PORT}"
|
||||
RNDCCMD="$RNDC -c $SYSTEMTESTTOP/common/rndc.conf -p ${CONTROLPORT} -s"
|
||||
RNDCCMD="$RNDC -c ../common/rndc.conf -p ${CONTROLPORT} -s"
|
||||
|
||||
status=0
|
||||
n=0
|
||||
|
||||
@@ -18,7 +18,6 @@ options {
|
||||
listen-on { 10.53.0.2; };
|
||||
listen-on-v6 { none; };
|
||||
notify yes;
|
||||
max-cache-size 80%;
|
||||
disable-empty-zone 127.IN-ADDR.ARPA;
|
||||
recursion yes;
|
||||
dnssec-validation yes;
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
copy_setports ns1/named.conf.in ns1/named.conf
|
||||
copy_setports ns2/named.conf.in ns2/named.conf
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
status=0
|
||||
n=0
|
||||
|
||||
@@ -7,7 +7,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
cp -f ns1/dynamic.db.in ns1/dynamic.db
|
||||
copy_setports ns1/named.conf.in ns1/named.conf
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
DIGOPTS="+tcp +nosea +nostat +noquest +nocomm +nocmd -p ${PORT}"
|
||||
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
$SHELL clean.sh
|
||||
|
||||
|
||||
@@ -12,14 +12,14 @@
|
||||
set -e
|
||||
|
||||
# shellcheck source=conf.sh
|
||||
. "$SYSTEMTESTTOP/conf.sh"
|
||||
. ../conf.sh
|
||||
|
||||
dig_with_opts() {
|
||||
"$DIG" -p "${PORT}" "$@"
|
||||
}
|
||||
|
||||
rndccmd() (
|
||||
"$RNDC" -c "$SYSTEMTESTTOP/common/rndc.conf" -p "${CONTROLPORT}" -s "$@"
|
||||
"$RNDC" -c ../common/rndc.conf -p "${CONTROLPORT}" -s "$@"
|
||||
)
|
||||
|
||||
_wait_for_message() (
|
||||
|
||||
@@ -11,7 +11,7 @@
|
||||
|
||||
set -eu
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
touch empty
|
||||
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
status=0
|
||||
n=0
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../../conf.sh
|
||||
|
||||
zone=example.
|
||||
zonefile=example.db
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
copy_setports ns1/named.conf.in ns1/named.conf
|
||||
copy_setports ns2/named.conf.in ns2/named.conf
|
||||
|
||||
@@ -7,10 +7,10 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
DIGOPTS="-p ${PORT}"
|
||||
RNDCCMD="$RNDC -c $SYSTEMTESTTOP/common/rndc.conf -p ${CONTROLPORT} -s"
|
||||
RNDCCMD="$RNDC -c ../common/rndc.conf -p ${CONTROLPORT} -s"
|
||||
|
||||
sendcmd() {
|
||||
send 10.53.0.4 "${EXTRAPORT1}"
|
||||
|
||||
@@ -24,7 +24,6 @@ dnssec-policy "test" {
|
||||
max-zone-ttl 86400;
|
||||
parent-ds-ttl 7200;
|
||||
parent-propagation-delay PT1H;
|
||||
parent-registration-delay P1D;
|
||||
publish-safety PT3600S;
|
||||
retire-safety PT3600S;
|
||||
signatures-refresh P3D;
|
||||
|
||||
@@ -24,7 +24,6 @@ dnssec-policy "test" {
|
||||
max-zone-ttl 86400;
|
||||
parent-ds-ttl 7200;
|
||||
parent-propagation-delay PT1H;
|
||||
parent-registration-delay P1D;
|
||||
publish-safety PT3600S;
|
||||
retire-safety PT3600S;
|
||||
signatures-refresh P3D;
|
||||
|
||||
@@ -7,7 +7,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
status=0
|
||||
n=0
|
||||
|
||||
@@ -7,7 +7,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
$SHELL clean.sh
|
||||
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
status=0
|
||||
n=1
|
||||
|
||||
@@ -7,7 +7,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
ln -s $CHECKZONE named-compilezone
|
||||
|
||||
|
||||
@@ -7,7 +7,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
status=0
|
||||
n=1
|
||||
|
||||
@@ -17,7 +17,7 @@ set -e
|
||||
# and differ from dnsrpz.conf which is used by dnsrpzd.
|
||||
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
DNSRPS_CMD=../rpz/dnsrps
|
||||
|
||||
@@ -13,8 +13,7 @@
|
||||
# Clean up after system tests.
|
||||
#
|
||||
|
||||
SYSTEMTESTTOP=.
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ./conf.sh
|
||||
|
||||
|
||||
find . -type f \( \
|
||||
@@ -25,7 +24,7 @@ find . -type f \( \
|
||||
|
||||
status=0
|
||||
|
||||
rm -f $SYSTEMTESTTOP/random.data
|
||||
rm -f ../random.data
|
||||
|
||||
for d in $SUBDIRS
|
||||
do
|
||||
|
||||
@@ -9,6 +9,6 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. "$SYSTEMTESTTOP/conf.sh"
|
||||
. ./conf.sh
|
||||
|
||||
[ -x "$TOP_BUILDDIR/bin/pkcs11/pkcs11-destroy" ] && $PK11DEL -w0 > /dev/null 2>&1
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
copy_setports ns1/named.conf.in ns1/named.conf
|
||||
copy_setports ns2/named.conf.in ns2/named.conf
|
||||
|
||||
@@ -9,10 +9,10 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
DIGOPTS="-p ${PORT}"
|
||||
RNDCCMD="$RNDC -c $SYSTEMTESTTOP/common/rndc.conf -p ${CONTROLPORT} -s"
|
||||
RNDCCMD="$RNDC -c ../common/rndc.conf -p ${CONTROLPORT} -s"
|
||||
|
||||
status=0
|
||||
n=0
|
||||
|
||||
@@ -9,6 +9,6 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
copy_setports ns1/named1.conf.in ns1/named.conf
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
status=0
|
||||
n=0
|
||||
|
||||
@@ -1 +1 @@
|
||||
-D delzone-ns2 -X named.lock -m record,size,mctx -c named.conf -g -U 4
|
||||
-D delzone-ns2 -X named.lock -m record,size,mctx -c named.conf -g -U 4 -T maxcachesize=2097152
|
||||
|
||||
@@ -9,6 +9,6 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
$SHELL clean.sh
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
DIGOPTS="+tcp +nosea +nostat +nocmd +norec +noques +noauth +noadd +nostats +dnssec -p 5300"
|
||||
status=0
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
status=0
|
||||
|
||||
|
||||
@@ -10,7 +10,7 @@
|
||||
# information regarding copyright ownership.
|
||||
|
||||
# shellcheck source=conf.sh
|
||||
. "$SYSTEMTESTTOP/conf.sh"
|
||||
. ../../conf.sh
|
||||
|
||||
set -e
|
||||
|
||||
|
||||
@@ -10,7 +10,7 @@
|
||||
# information regarding copyright ownership.
|
||||
|
||||
# shellcheck source=conf.sh
|
||||
. "$SYSTEMTESTTOP/conf.sh"
|
||||
. ../conf.sh
|
||||
|
||||
set -e
|
||||
|
||||
|
||||
@@ -10,7 +10,7 @@
|
||||
# information regarding copyright ownership.
|
||||
|
||||
# shellcheck source=conf.sh
|
||||
. "$SYSTEMTESTTOP/conf.sh"
|
||||
. ../conf.sh
|
||||
|
||||
set -e
|
||||
|
||||
@@ -82,7 +82,7 @@ if [ -x "$NSLOOKUP" -a $checkupdate -eq 1 ] ; then
|
||||
n=$((n+1))
|
||||
echo_i "check nslookup handles UPDATE response ($n)"
|
||||
ret=0
|
||||
"$NSLOOKUP" -q=CNAME "-port=$PORT" foo.bar 10.53.0.7 > nslookup.out.test$n 2>&1 && ret=1
|
||||
"$NSLOOKUP" -q=CNAME -timeout=1 "-port=$PORT" foo.bar 10.53.0.7 > nslookup.out.test$n 2>&1 && ret=1
|
||||
grep "Opcode mismatch" nslookup.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
@@ -94,7 +94,7 @@ if [ -x "$HOST" -a $checkupdate -eq 1 ] ; then
|
||||
n=$((n+1))
|
||||
echo_i "check host handles UPDATE response ($n)"
|
||||
ret=0
|
||||
"$HOST" -t CNAME -p $PORT foo.bar 10.53.0.7 > host.out.test$n 2>&1 && ret=1
|
||||
"$HOST" -W 1 -t CNAME -p $PORT foo.bar 10.53.0.7 > host.out.test$n 2>&1 && ret=1
|
||||
grep "Opcode mismatch" host.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
@@ -108,7 +108,7 @@ if [ -x "$DIG" ] ; then
|
||||
n=$((n+1))
|
||||
echo_i "check dig handles UPDATE response ($n)"
|
||||
ret=0
|
||||
dig_with_opts @10.53.0.7 cname foo.bar > dig.out.test$n 2>&1 && ret=1
|
||||
dig_with_opts @10.53.0.7 +tries=1 +timeout=1 cname foo.bar > dig.out.test$n 2>&1 && ret=1
|
||||
grep "Opcode mismatch" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
@@ -922,7 +922,7 @@ if [ -x "$DIG" ] ; then
|
||||
n=$((n+1))
|
||||
echo_i "check that dig +unexpected works ($n)"
|
||||
ret=0
|
||||
dig_with_opts @10.53.0.6 +unexpected a a.example > dig.out.test$n || ret=1
|
||||
dig_with_opts @10.53.0.6 +tries=1 +time=2 +unexpected a a.example > dig.out.test$n || ret=1
|
||||
grep 'reply from unexpected source' dig.out.test$n > /dev/null || ret=1
|
||||
grep 'status: NOERROR' dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
@@ -946,6 +946,23 @@ if [ -x "$DIG" ] ; then
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "check that dig +bufsize=0 just sets the buffer size to 0 ($n)"
|
||||
ret=0
|
||||
dig_with_opts @10.53.0.3 a.example +bufsize=0 +qr > dig.out.test$n 2>&1 || ret=1
|
||||
grep "EDNS:" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "check that dig +bufsize restores default bufsize ($n)"
|
||||
ret=0
|
||||
dig_with_opts @10.53.0.3 a.example +bufsize=0 +bufsize +qr > dig.out.test$n 2>&1 || ret=1
|
||||
lines=`grep "EDNS:.* udp: 4096" dig.out.test$n | wc -l`
|
||||
test $lines -eq 2 || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
else
|
||||
echo_i "$DIG is needed, so skipping these dig tests"
|
||||
fi
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
if ! $FEATURETEST --with-dlz-filesystem; then
|
||||
echo_i "DLZ filesystem driver not supported"
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
$SHELL clean.sh
|
||||
copy_setports ns1/named.conf.in ns1/named.conf
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
status=0
|
||||
n=0
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
$TSIGKEYGEN ddns-key.example.nil > ns1/ddns.key
|
||||
|
||||
|
||||
@@ -9,13 +9,13 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
status=0
|
||||
n=0
|
||||
|
||||
DIGOPTS="@10.53.0.1 -p ${PORT} +nocookie"
|
||||
RNDCCMD="$RNDC -c $SYSTEMTESTTOP/common/rndc.conf -p ${CONTROLPORT} -s"
|
||||
RNDCCMD="$RNDC -c ../common/rndc.conf -p ${CONTROLPORT} -s"
|
||||
|
||||
newtest() {
|
||||
n=`expr $n + 1`
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../../conf.sh
|
||||
|
||||
zone=signed
|
||||
infile=example.db
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
copy_setports ns1/named.conf.in ns1/named.conf
|
||||
copy_setports ns2/named.conf.in ns2/named.conf
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
status=0
|
||||
n=0
|
||||
|
||||
@@ -10,7 +10,7 @@
|
||||
# information regarding copyright ownership.
|
||||
|
||||
# shellcheck source=conf.sh
|
||||
. "$SYSTEMTESTTOP/conf.sh"
|
||||
. ../../conf.sh
|
||||
|
||||
set -e
|
||||
|
||||
|
||||
@@ -0,0 +1,165 @@
|
||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
; file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
;
|
||||
; See the COPYRIGHT file distributed with this work for additional
|
||||
; information regarding copyright ownership.
|
||||
|
||||
$TTL 300 ; 5 minutes
|
||||
@ IN SOA mname1. . (
|
||||
2000042407 ; serial
|
||||
20 ; refresh (20 seconds)
|
||||
20 ; retry (20 seconds)
|
||||
1814400 ; expire (3 weeks)
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
NS ns2
|
||||
NS ns3
|
||||
ns2 A 10.53.0.2
|
||||
ns3 A 10.53.0.3
|
||||
|
||||
a A 10.0.0.1
|
||||
b A 10.0.0.2
|
||||
d A 10.0.0.4
|
||||
|
||||
; Used for testing ANY queries
|
||||
foo TXT "testing"
|
||||
foo A 10.0.1.0
|
||||
|
||||
bad-cname CNAME a
|
||||
bad-dname DNAME @
|
||||
|
||||
; Used for testing CNAME queries
|
||||
cname1 CNAME cname1-target
|
||||
cname1-target TXT "testing cname"
|
||||
|
||||
cname2 CNAME cname2-target
|
||||
cname2-target TXT "testing cname"
|
||||
|
||||
; Used for testing DNAME queries
|
||||
dname1 DNAME dname1-target
|
||||
foo.dname1-target TXT "testing dname"
|
||||
|
||||
dname2 DNAME dname2-target
|
||||
foo.dname2-target TXT "testing dname"
|
||||
|
||||
; A secure subdomain
|
||||
secure NS ns3.secure
|
||||
ns3.secure A 10.53.0.3
|
||||
|
||||
; An insecure subdomain
|
||||
insecure NS ns.insecure
|
||||
ns.insecure A 10.53.0.3
|
||||
|
||||
; A secure subdomain we're going to inject bogus data into
|
||||
bogus NS ns.bogus
|
||||
ns.bogus A 10.53.0.3
|
||||
|
||||
; A subdomain with a corrupt DS
|
||||
badds NS ns.badds
|
||||
ns.badds A 10.53.0.3
|
||||
|
||||
; A dynamic secure subdomain
|
||||
dynamic NS dynamic
|
||||
dynamic A 10.53.0.3
|
||||
|
||||
; A insecure subdomain
|
||||
mustbesecure NS ns.mustbesecure
|
||||
ns.mustbesecure A 10.53.0.3
|
||||
|
||||
; A subdomain with expired signatures
|
||||
expired NS ns.expired
|
||||
ns.expired A 10.53.0.3
|
||||
|
||||
; A rfc2535 signed zone w/ CNAME
|
||||
rfc2535 NS ns.rfc2535
|
||||
ns.rfc2535 A 10.53.0.3
|
||||
|
||||
z A 10.0.0.26
|
||||
|
||||
keyless NS ns.keyless
|
||||
ns.keyless A 10.53.0.3
|
||||
|
||||
nsec3 NS ns.nsec3
|
||||
ns.nsec3 A 10.53.0.3
|
||||
|
||||
optout NS ns.optout
|
||||
ns.optout A 10.53.0.3
|
||||
|
||||
nsec3-unknown NS ns.nsec3-unknown
|
||||
ns.nsec3-unknown A 10.53.0.3
|
||||
|
||||
optout-unknown NS ns.optout-unknown
|
||||
ns.optout-unknown A 10.53.0.3
|
||||
|
||||
dnskey-unknown NS ns.dnskey-unknown
|
||||
ns.dnskey-unknown A 10.53.0.3
|
||||
|
||||
dnskey-unsupported NS ns.dnskey-unsupported
|
||||
ns.dnskey-unsupported A 10.53.0.3
|
||||
|
||||
dnskey-nsec3-unknown NS ns.dnskey-nsec3-unknown
|
||||
ns.dnskey-nsec3-unknown A 10.53.0.3
|
||||
|
||||
multiple NS ns.multiple
|
||||
ns.multiple A 10.53.0.3
|
||||
|
||||
*.wild A 10.0.0.27
|
||||
|
||||
rsasha256 NS ns.rsasha256
|
||||
ns.rsasha256 A 10.53.0.3
|
||||
|
||||
rsasha512 NS ns.rsasha512
|
||||
ns.rsasha512 A 10.53.0.3
|
||||
|
||||
kskonly NS ns.kskonly
|
||||
ns.kskonly A 10.53.0.3
|
||||
|
||||
update-nsec3 NS ns.update-nsec3
|
||||
ns.update-nsec3 A 10.53.0.3
|
||||
|
||||
auto-nsec NS ns.auto-nsec
|
||||
ns.auto-nsec A 10.53.0.3
|
||||
|
||||
auto-nsec3 NS ns.auto-nsec3
|
||||
ns.auto-nsec3 A 10.53.0.3
|
||||
|
||||
|
||||
below-cname CNAME some.where.else.
|
||||
|
||||
insecure.below-cname NS ns.insecure.below-cname
|
||||
ns.insecure.below-cname A 10.53.0.3
|
||||
|
||||
secure.below-cname NS ns.secure.below-cname
|
||||
ns.secure.below-cname A 10.53.0.3
|
||||
|
||||
ttlpatch NS ns.ttlpatch
|
||||
ns.ttlpatch A 10.53.0.3
|
||||
|
||||
split-dnssec NS ns.split-dnssec
|
||||
ns.split-dnssec A 10.53.0.3
|
||||
|
||||
split-smart NS ns.split-smart
|
||||
ns.split-smart A 10.53.0.3
|
||||
|
||||
upper NS ns.upper
|
||||
ns.upper A 10.53.0.3
|
||||
|
||||
LOWER NS NS.LOWER
|
||||
NS.LOWER A 10.53.0.3
|
||||
|
||||
expiring NS ns.expiring
|
||||
ns.expiring A 10.53.0.3
|
||||
|
||||
future NS ns.future
|
||||
ns.future A 10.53.0.3
|
||||
|
||||
managed-future NS ns.managed-future
|
||||
ns.managed-future A 10.53.0.3
|
||||
|
||||
revkey NS ns.revkey
|
||||
ns.revkey A 10.53.0.3
|
||||
|
||||
dname-at-apex-nsec3 NS ns3
|
||||
@@ -182,4 +182,13 @@ zone "corp" {
|
||||
file "corp.db";
|
||||
};
|
||||
|
||||
zone "hours-vs-days" {
|
||||
type master;
|
||||
file "hours-vs-days.db.signed";
|
||||
auto-dnssec maintain;
|
||||
/* validity 500 days, resign in 499 days */
|
||||
sig-validity-interval 500 499;
|
||||
allow-update { any; };
|
||||
};
|
||||
|
||||
include "trusted.conf";
|
||||
|
||||
@@ -10,7 +10,7 @@
|
||||
# information regarding copyright ownership.
|
||||
|
||||
# shellcheck source=conf.sh
|
||||
. "$SYSTEMTESTTOP/conf.sh"
|
||||
. ../../conf.sh
|
||||
|
||||
set -e
|
||||
|
||||
@@ -308,3 +308,11 @@ sed 's/DNSKEY/CDNSKEY/' "$key1.key" > "$key1.cdnskey"
|
||||
cat "$infile" "$key1.key" "$key2.key" "$key1.cdnskey" "$key1.cds" > "$zonefile"
|
||||
# Don't sign, let auto-dnssec maintain do it.
|
||||
mv $zonefile "$zonefile.signed"
|
||||
|
||||
zone=hours-vs-days
|
||||
infile=hours-vs-days.db.in
|
||||
zonefile=hours-vs-days.db
|
||||
key1=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -n zone -f KSK "$zone")
|
||||
key2=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -n zone "$zone")
|
||||
$SETTIME -P sync now "$key1" > /dev/null
|
||||
cat "$infile" > "$zonefile.signed"
|
||||
|
||||
@@ -10,7 +10,7 @@
|
||||
# information regarding copyright ownership.
|
||||
|
||||
# shellcheck source=conf.sh
|
||||
. "$SYSTEMTESTTOP/conf.sh"
|
||||
. ../../conf.sh
|
||||
|
||||
set -e
|
||||
|
||||
|
||||
@@ -10,7 +10,7 @@
|
||||
# information regarding copyright ownership.
|
||||
|
||||
# shellcheck source=conf.sh
|
||||
. "$SYSTEMTESTTOP/conf.sh"
|
||||
. ../../conf.sh
|
||||
|
||||
set -e
|
||||
|
||||
|
||||
@@ -1 +1 @@
|
||||
-m record,size,mctx -c named.conf -d 99 -D dnssec-ns6 -X named.lock -g -T nonearest -T tat=1
|
||||
-m record,size,mctx -c named.conf -d 99 -D dnssec-ns6 -X named.lock -g -T maxcachesize=2097152 -T nonearest -T tat=1
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user