Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
b9e33d9cce | ||
|
|
e94465e304 | ||
|
|
8b9e2015f3 | ||
|
|
f64da6cabb | ||
|
|
6954eceb80 | ||
|
|
378774821a | ||
|
|
40562e37ee | ||
|
|
e7256edf67 | ||
|
|
7edff5d2bb | ||
|
|
5fd05a6d88 | ||
|
|
3009554a0b | ||
|
|
7545b00842 | ||
|
|
396772811a | ||
|
|
c0494994f0 | ||
|
|
1970f078cf | ||
|
|
376d5996a1 | ||
|
|
65a483106e | ||
|
|
5f308740df | ||
|
|
a8c1bfd673 | ||
|
|
18c7fa2f93 | ||
|
|
3f8c9d92af | ||
|
|
393135d693 | ||
|
|
82354deeb1 | ||
|
|
c22b540e4c | ||
|
|
d92d70ac5d | ||
|
|
00ff44c7c2 | ||
|
|
2f13e0ef98 | ||
|
|
a80dc538bd | ||
|
|
40a90fbf89 | ||
|
|
31b6ae485e | ||
|
|
19f6a63184 | ||
|
|
14e9925868 | ||
|
|
7bc5d7f5e8 | ||
|
|
1dc8208a89 | ||
|
|
6ead410268 | ||
|
|
a573b93b46 | ||
|
|
165df18f75 | ||
|
|
9bb32395b2 | ||
|
|
8993ecd06a | ||
|
|
2f4e0e5a81 | ||
|
|
78e1d7cdde | ||
|
|
ba613d22bf | ||
|
|
858228febe | ||
|
|
5b2b9340fe | ||
|
|
6035d557c4 | ||
|
|
900215654b | ||
|
|
445cabb392 | ||
|
|
a197094d76 | ||
|
|
f975d0acaa | ||
|
|
656eed7c9b | ||
|
|
7a0188774f |
@@ -1,3 +1,42 @@
|
||||
4830. [bug] Failure to configure ATF when requested did not cause
|
||||
an error in top-level configure script. [RT #46655]
|
||||
|
||||
4829. [bug] isc_heap_delete did not zero the index value when
|
||||
the heap was created with a callback to do that.
|
||||
[RT #46709]
|
||||
|
||||
4828. [bug] Do not use thread-local storage for storing LMDB reader
|
||||
locktable slots. [RT #46556]
|
||||
|
||||
4827. [misc] Add a precommit check script util/checklibs.sh
|
||||
[RT #46215]
|
||||
|
||||
4826. [cleanup] Prevent potential build failures in bin/confgen/ and
|
||||
bin/named/ when using parallel make. [RT #46648]
|
||||
|
||||
4825. [bug] Prevent a bogus "error during managed-keys processing
|
||||
(no more)" warning from being logged. [RT #46645]
|
||||
|
||||
4824. [port] Add iOS hooks to dig. [RT #42011]
|
||||
|
||||
4823. [test] Refactor reclimit system test to improve its
|
||||
reliability and speed. [RT #46632]
|
||||
|
||||
4822. [bug] Use resign_sooner in dns_db_setsigningtime. [RT #46473]
|
||||
|
||||
4821. [bug] When resigning ensure that the SOA's expire time is
|
||||
always later that the resigning time of other records.
|
||||
[RT #46473]
|
||||
|
||||
4820. [bug] dns_db_subtractrdataset should transfer the resigning
|
||||
information to the new header. [RT #46473]
|
||||
|
||||
4819. [bug] Fully backout the transaction when adding a RRset
|
||||
to the resigning / removal heaps fails. [RT #46473]
|
||||
|
||||
4818. [test] The logfileconfig system test could intermittently
|
||||
report false negatives on some platforms. [RT #46615]
|
||||
|
||||
4817. [cleanup] Use DNS_NAME_INITABSOLUTE and DNS_NAME_INITNONABSOLUTE.
|
||||
[RT #45433]
|
||||
|
||||
|
||||
@@ -25,4 +25,6 @@ Setting Description
|
||||
Disable the use of inline functions to implement
|
||||
-DISC_BUFFER_USEINLINE=0 the isc_buffer API: this reduces performance but
|
||||
may be useful when debugging
|
||||
-DISC_HEAP_CHECK Test heap consistency after every heap
|
||||
operation; used when debugging
|
||||
|
||||
|
||||
@@ -22,3 +22,4 @@ Some of these settings are:
|
||||
|`-DNS_RUN_PID_DIR=0`|Create default PID files in `${localstatedir}/run` rather than `${localstatedir}/run/named/`|
|
||||
|`-DNS_RPZ_MAX_ZONES=64`|Increase the maximum number of configurable response policy zones from 32 to 64; this is the highest possible setting|
|
||||
|`-DISC_BUFFER_USEINLINE=0`|Disable the use of inline functions to implement the `isc_buffer` API: this reduces performance but may be useful when debugging |
|
||||
|`-DISC_HEAP_CHECK`|Test heap consistency after every heap operation; used when debugging|
|
||||
|
||||
@@ -8,6 +8,10 @@ srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
top_srcdir = @top_srcdir@
|
||||
|
||||
# Attempt to disable parallel processing.
|
||||
.NOTPARALLEL:
|
||||
.NO_PARALLEL:
|
||||
|
||||
VERSION=@BIND9_VERSION@
|
||||
|
||||
@BIND9_MAKE_INCLUDES@
|
||||
@@ -64,11 +68,11 @@ rndc-confgen.@O@: rndc-confgen.c
|
||||
ddns-confgen.@O@: ddns-confgen.c
|
||||
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} -c ${srcdir}/ddns-confgen.c
|
||||
|
||||
rndc-confgen@EXEEXT@: rndc-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS} ${CONFDEPLIBS}
|
||||
rndc-confgen@EXEEXT@: rndc-confgen.@O@ util.@O@ keygen.@O@ ${CONFDEPLIBS}
|
||||
export BASEOBJS="rndc-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS}"; \
|
||||
${FINALBUILDCMD}
|
||||
|
||||
ddns-confgen@EXEEXT@: ddns-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS} ${CONFDEPLIBS}
|
||||
ddns-confgen@EXEEXT@: ddns-confgen.@O@ util.@O@ keygen.@O@ ${CONFDEPLIBS}
|
||||
export BASEOBJS="ddns-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS}"; \
|
||||
${FINALBUILDCMD}
|
||||
|
||||
|
||||
+72
-30
@@ -109,6 +109,11 @@ print_usage(FILE *fp) {
|
||||
" [ host [@local-server] {local-d-opt} [...]]\n", fp);
|
||||
}
|
||||
|
||||
#if TARGET_OS_IPHONE
|
||||
static void usage(void) {
|
||||
fprintf(stderr, "Press <Help> for complete list of options\n");
|
||||
}
|
||||
#else
|
||||
ISC_PLATFORM_NORETURN_PRE static void
|
||||
usage(void) ISC_PLATFORM_NORETURN_POST;
|
||||
|
||||
@@ -119,6 +124,7 @@ usage(void) {
|
||||
"for complete list of options\n", stderr);
|
||||
exit(1);
|
||||
}
|
||||
#endif
|
||||
|
||||
/*% version */
|
||||
static void
|
||||
@@ -818,8 +824,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
goto invalid_option;
|
||||
result = parse_uint(&num, value, COMMSIZE,
|
||||
"buffer size");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse buffer size");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse buffer size");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->udpsize = num;
|
||||
break;
|
||||
default:
|
||||
@@ -864,8 +872,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
if (value != NULL) {
|
||||
n = strlcpy(hexcookie, value,
|
||||
sizeof(hexcookie));
|
||||
if (n >= sizeof(hexcookie))
|
||||
fatal("COOKIE data too large");
|
||||
if (n >= sizeof(hexcookie)) {
|
||||
warn("COOKIE data too large");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->cookie = hexcookie;
|
||||
} else
|
||||
lookup->cookie = NULL;
|
||||
@@ -916,8 +926,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
if (value == NULL)
|
||||
goto need_value;
|
||||
result = parse_uint(&num, value, 0x3f, "DSCP");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse DSCP value");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse DSCP value");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->dscp = num;
|
||||
break;
|
||||
default:
|
||||
@@ -946,9 +958,11 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
value,
|
||||
255,
|
||||
"edns");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse "
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse "
|
||||
"edns");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->edns = num;
|
||||
break;
|
||||
case 'f':
|
||||
@@ -965,9 +979,11 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
value,
|
||||
0xffff,
|
||||
"ednsflags");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse "
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse "
|
||||
"ednsflags");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->ednsflags = num;
|
||||
break;
|
||||
case 'n':
|
||||
@@ -980,10 +996,12 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
lookup->ednsoptscnt = 0;
|
||||
break;
|
||||
}
|
||||
if (value == NULL)
|
||||
fatal("ednsopt no "
|
||||
"code point "
|
||||
"specified");
|
||||
if (value == NULL) {
|
||||
warn("ednsopt no "
|
||||
"code point "
|
||||
"specified");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
code = next_token(&value, ":");
|
||||
save_opt(lookup, code, value);
|
||||
break;
|
||||
@@ -1098,8 +1116,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
if (!state)
|
||||
goto invalid_option;
|
||||
result = parse_uint(&num, value, MAXNDOTS, "ndots");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse ndots");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse ndots");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
ndots = num;
|
||||
break;
|
||||
case 's':
|
||||
@@ -1161,8 +1181,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
break;
|
||||
}
|
||||
result = parse_uint(&num, value, 15, "opcode");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse opcode");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse opcode");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->opcode = (dns_opcode_t)num;
|
||||
break;
|
||||
default:
|
||||
@@ -1176,8 +1198,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
if (value == NULL)
|
||||
goto need_value;
|
||||
result = parse_uint(&num, value, 512, "padding");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse padding");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse padding");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->padding = (isc_uint16_t)num;
|
||||
break;
|
||||
case 'q':
|
||||
@@ -1216,8 +1240,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
goto invalid_option;
|
||||
result = parse_uint(&lookup->retries, value,
|
||||
MAXTRIES - 1, "retries");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse retries");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse retries");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->retries++;
|
||||
break;
|
||||
default:
|
||||
@@ -1300,8 +1326,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
*/
|
||||
if (splitwidth)
|
||||
splitwidth += 3;
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse split");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse split");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
break;
|
||||
case 't': /* stats */
|
||||
FULLCHECK("stats");
|
||||
@@ -1325,8 +1353,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
lookup->ecs_addr = NULL;
|
||||
}
|
||||
result = parse_netprefix(&lookup->ecs_addr, value);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse client");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse client");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
break;
|
||||
default:
|
||||
goto invalid_option;
|
||||
@@ -1349,8 +1379,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
goto invalid_option;
|
||||
result = parse_uint(&timeout, value, MAXTIMEOUT,
|
||||
"timeout");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse timeout");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse timeout");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
if (timeout == 0)
|
||||
timeout = 1;
|
||||
break;
|
||||
@@ -1386,8 +1418,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
goto invalid_option;
|
||||
result = parse_uint(&lookup->retries, value,
|
||||
MAXTRIES, "tries");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse tries");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse tries");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
if (lookup->retries == 0)
|
||||
lookup->retries = 1;
|
||||
break;
|
||||
@@ -1444,11 +1478,19 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
default:
|
||||
invalid_option:
|
||||
need_value:
|
||||
#if TARGET_OS_IPHONE
|
||||
exit_or_usage:
|
||||
#endif
|
||||
fprintf(stderr, "Invalid option: +%s\n",
|
||||
option);
|
||||
usage();
|
||||
}
|
||||
return;
|
||||
|
||||
#if ! TARGET_OS_IPHONE
|
||||
exit_or_usage:
|
||||
digexit();
|
||||
#endif
|
||||
}
|
||||
|
||||
/*%
|
||||
|
||||
+47
-7
@@ -375,6 +375,46 @@ get_reverse(char *reverse, size_t len, char *value, isc_boolean_t ip6_int,
|
||||
}
|
||||
}
|
||||
|
||||
void (*dighost_pre_exit_hook)(void) = NULL;
|
||||
|
||||
#if TARGET_OS_IPHONE
|
||||
void
|
||||
warn(const char *format, ...) {
|
||||
va_list args;
|
||||
|
||||
fflush(stdout);
|
||||
fprintf(stderr, ";; Warning: ");
|
||||
va_start(args, format);
|
||||
vfprintf(stderr, format, args);
|
||||
va_end(args);
|
||||
fprintf(stderr, "\n");
|
||||
}
|
||||
#else
|
||||
void
|
||||
warn(const char *format, ...) {
|
||||
va_list args;
|
||||
|
||||
fflush(stdout);
|
||||
fprintf(stderr, "%s: ", progname);
|
||||
va_start(args, format);
|
||||
vfprintf(stderr, format, args);
|
||||
va_end(args);
|
||||
fprintf(stderr, "\n");
|
||||
}
|
||||
#endif
|
||||
|
||||
void
|
||||
digexit(void) {
|
||||
if (exitcode < 10)
|
||||
exitcode = 10;
|
||||
if (fatalexit != 0)
|
||||
exitcode = fatalexit;
|
||||
if (dighost_pre_exit_hook != NULL) {
|
||||
dighost_pre_exit_hook();
|
||||
}
|
||||
exit(exitcode);
|
||||
}
|
||||
|
||||
void
|
||||
fatal(const char *format, ...) {
|
||||
va_list args;
|
||||
@@ -385,11 +425,7 @@ fatal(const char *format, ...) {
|
||||
vfprintf(stderr, format, args);
|
||||
va_end(args);
|
||||
fprintf(stderr, "\n");
|
||||
if (exitcode < 10)
|
||||
exitcode = 10;
|
||||
if (fatalexit != 0)
|
||||
exitcode = fatalexit;
|
||||
exit(exitcode);
|
||||
digexit();
|
||||
}
|
||||
|
||||
void
|
||||
@@ -1382,7 +1418,7 @@ dig_ednsoptname_t optnames[] = {
|
||||
void
|
||||
save_opt(dig_lookup_t *lookup, char *code, char *value) {
|
||||
isc_result_t result;
|
||||
isc_uint32_t num;
|
||||
isc_uint32_t num = 0;
|
||||
isc_buffer_t b;
|
||||
isc_boolean_t found = ISC_FALSE;
|
||||
unsigned int i;
|
||||
@@ -2161,9 +2197,13 @@ setup_lookup(dig_lookup_t *lookup) {
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
dns_message_puttempname(lookup->sendmsg,
|
||||
&lookup->name);
|
||||
fatal("'%s' is not a legal name "
|
||||
warn("'%s' is not a legal name "
|
||||
"(%s)", lookup->textname,
|
||||
isc_result_totext(result));
|
||||
#if TARGET_OS_IPHONE
|
||||
check_next_lookup(current_lookup);
|
||||
return (ISC_FALSE);
|
||||
#endif
|
||||
}
|
||||
}
|
||||
dns_name_format(lookup->name, store, sizeof(store));
|
||||
|
||||
@@ -26,6 +26,10 @@
|
||||
#include <isc/sockaddr.h>
|
||||
#include <isc/socket.h>
|
||||
|
||||
#ifdef __APPLE__
|
||||
#include <TargetConditionals.h>
|
||||
#endif
|
||||
|
||||
#define MXSERV 20
|
||||
#define MXNAME (DNS_NAME_MAXTEXT+1)
|
||||
#define MXRD 32
|
||||
@@ -282,6 +286,13 @@ ISC_PLATFORM_NORETURN_PRE void
|
||||
fatal(const char *format, ...)
|
||||
ISC_FORMAT_PRINTF(1, 2) ISC_PLATFORM_NORETURN_POST;
|
||||
|
||||
void
|
||||
warn(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||
|
||||
ISC_PLATFORM_NORETURN_PRE void
|
||||
digexit(void)
|
||||
ISC_PLATFORM_NORETURN_POST;
|
||||
|
||||
void
|
||||
debug(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||
|
||||
@@ -384,6 +395,9 @@ extern void
|
||||
extern void
|
||||
(*dighost_shutdown)(void);
|
||||
|
||||
extern void
|
||||
(*dighost_pre_exit_hook)(void);
|
||||
|
||||
void save_opt(dig_lookup_t *lookup, char *code, char *value);
|
||||
|
||||
void setup_file_key(void);
|
||||
|
||||
@@ -8,6 +8,10 @@ srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
top_srcdir = @top_srcdir@
|
||||
|
||||
# Attempt to disable parallel processing.
|
||||
.NOTPARALLEL:
|
||||
.NO_PARALLEL:
|
||||
|
||||
VERSION=@BIND9_VERSION@
|
||||
|
||||
@BIND9_PRODUCT@
|
||||
@@ -130,7 +134,7 @@ server.@O@: server.c
|
||||
-DPRODUCT=\"${PRODUCT}\" \
|
||||
-DVERSION=\"${VERSION}\" -c ${srcdir}/server.c
|
||||
|
||||
named@EXEEXT@: ${OBJS} ${UOBJS} ${DEPLIBS}
|
||||
named@EXEEXT@: ${OBJS} ${DEPLIBS}
|
||||
export MAKE_SYMTABLE="yes"; \
|
||||
export BASEOBJS="${OBJS} ${UOBJS}"; \
|
||||
${FINALBUILDCMD}
|
||||
|
||||
@@ -26,6 +26,8 @@
|
||||
int scmp_syscalls[] = {
|
||||
SCMP_SYS(access),
|
||||
SCMP_SYS(open),
|
||||
SCMP_SYS(openat),
|
||||
SCMP_SYS(lseek),
|
||||
SCMP_SYS(clock_gettime),
|
||||
SCMP_SYS(time),
|
||||
SCMP_SYS(read),
|
||||
@@ -54,6 +56,7 @@ int scmp_syscalls[] = {
|
||||
#ifdef HAVE_GETRANDOM
|
||||
SCMP_SYS(getrandom),
|
||||
#endif
|
||||
SCMP_SYS(rename),
|
||||
SCMP_SYS(unlink),
|
||||
SCMP_SYS(socket),
|
||||
SCMP_SYS(sendto),
|
||||
@@ -72,7 +75,6 @@ int scmp_syscalls[] = {
|
||||
SCMP_SYS(getsockopt),
|
||||
SCMP_SYS(getsockname),
|
||||
SCMP_SYS(lstat),
|
||||
SCMP_SYS(lseek),
|
||||
SCMP_SYS(getgid),
|
||||
SCMP_SYS(getegid),
|
||||
SCMP_SYS(getuid),
|
||||
@@ -83,9 +85,7 @@ int scmp_syscalls[] = {
|
||||
SCMP_SYS(setuid),
|
||||
SCMP_SYS(prctl),
|
||||
SCMP_SYS(epoll_wait),
|
||||
SCMP_SYS(openat),
|
||||
SCMP_SYS(getdents),
|
||||
SCMP_SYS(rename),
|
||||
SCMP_SYS(utimes),
|
||||
SCMP_SYS(dup),
|
||||
#endif
|
||||
@@ -93,6 +93,8 @@ int scmp_syscalls[] = {
|
||||
const char *scmp_syscall_names[] = {
|
||||
"access",
|
||||
"open",
|
||||
"openat",
|
||||
"lseek",
|
||||
"clock_gettime",
|
||||
"time",
|
||||
"read",
|
||||
@@ -121,6 +123,7 @@ const char *scmp_syscall_names[] = {
|
||||
#ifdef HAVE_GETRANDOM
|
||||
"getrandom",
|
||||
#endif
|
||||
"rename",
|
||||
"unlink",
|
||||
"socket",
|
||||
"sendto",
|
||||
@@ -139,7 +142,6 @@ const char *scmp_syscall_names[] = {
|
||||
"getsockopt",
|
||||
"getsockname",
|
||||
"lstat",
|
||||
"lseek",
|
||||
"getgid",
|
||||
"getegid",
|
||||
"getuid",
|
||||
@@ -150,9 +152,7 @@ const char *scmp_syscall_names[] = {
|
||||
"setuid",
|
||||
"prctl",
|
||||
"epoll_wait",
|
||||
"openat",
|
||||
"getdents",
|
||||
"rename",
|
||||
"utimes",
|
||||
"dup",
|
||||
#endif
|
||||
|
||||
+294
-284
@@ -511,44 +511,32 @@ nzf_append(dns_view_t *view, const cfg_obj_t *zconfig);
|
||||
*/
|
||||
static isc_result_t
|
||||
configure_view_acl(const cfg_obj_t *vconfig, const cfg_obj_t *config,
|
||||
const cfg_obj_t *gconfig, const char *aclname,
|
||||
const char *acltuplename, cfg_aclconfctx_t *actx,
|
||||
isc_mem_t *mctx, dns_acl_t **aclp)
|
||||
const char *aclname, const char *acltuplename,
|
||||
cfg_aclconfctx_t *actx, isc_mem_t *mctx, dns_acl_t **aclp)
|
||||
{
|
||||
isc_result_t result;
|
||||
const cfg_obj_t *maps[4];
|
||||
const cfg_obj_t *maps[3];
|
||||
const cfg_obj_t *aclobj = NULL;
|
||||
int i = 0;
|
||||
|
||||
if (*aclp != NULL) {
|
||||
if (*aclp != NULL)
|
||||
dns_acl_detach(aclp);
|
||||
}
|
||||
if (vconfig != NULL) {
|
||||
if (vconfig != NULL)
|
||||
maps[i++] = cfg_tuple_get(vconfig, "options");
|
||||
}
|
||||
if (config != NULL) {
|
||||
const cfg_obj_t *options = NULL;
|
||||
(void)cfg_map_get(config, "options", &options);
|
||||
if (options != NULL) {
|
||||
if (options != NULL)
|
||||
maps[i++] = options;
|
||||
}
|
||||
}
|
||||
if (gconfig != NULL) {
|
||||
const cfg_obj_t *options = NULL;
|
||||
(void)cfg_map_get(gconfig, "options", &options);
|
||||
if (options != NULL) {
|
||||
maps[i++] = options;
|
||||
}
|
||||
}
|
||||
maps[i] = NULL;
|
||||
|
||||
(void)named_config_get(maps, aclname, &aclobj);
|
||||
if (aclobj == NULL) {
|
||||
if (aclobj == NULL)
|
||||
/*
|
||||
* No value available. *aclp == NULL.
|
||||
*/
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
if (acltuplename != NULL) {
|
||||
/*
|
||||
@@ -3718,9 +3706,13 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
||||
CHECKM(named_config_getport(config, &port), "port");
|
||||
dns_view_setdstport(view, port);
|
||||
|
||||
CHECK(configure_view_acl(vconfig, config, named_g_config,
|
||||
"allow-query", NULL, actx,
|
||||
CHECK(configure_view_acl(vconfig, config, "allow-query", NULL, actx,
|
||||
named_g_mctx, &view->queryacl));
|
||||
if (view->queryacl == NULL) {
|
||||
CHECK(configure_view_acl(NULL, named_g_config, "allow-query",
|
||||
NULL, actx, named_g_mctx,
|
||||
&view->queryacl));
|
||||
}
|
||||
|
||||
/*
|
||||
* Make the list of response policy zone names for a view that
|
||||
@@ -4603,16 +4595,11 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
||||
|
||||
/*
|
||||
* Configure the "match-clients" and "match-destinations" ACL.
|
||||
* (These are only meaningful at the view level, but 'config'
|
||||
* must be passed so that named ACLs defined at the global level
|
||||
* can be retrieved.)
|
||||
*/
|
||||
CHECK(configure_view_acl(vconfig, config, NULL, "match-clients",
|
||||
NULL, actx, named_g_mctx,
|
||||
&view->matchclients));
|
||||
CHECK(configure_view_acl(vconfig, config, NULL, "match-destinations",
|
||||
NULL, actx, named_g_mctx,
|
||||
&view->matchdestinations));
|
||||
CHECK(configure_view_acl(vconfig, config, "match-clients", NULL, actx,
|
||||
named_g_mctx, &view->matchclients));
|
||||
CHECK(configure_view_acl(vconfig, config, "match-destinations", NULL,
|
||||
actx, named_g_mctx, &view->matchdestinations));
|
||||
|
||||
/*
|
||||
* Configure the "match-recursive-only" option.
|
||||
@@ -4681,85 +4668,70 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
view->trust_anchor_telemetry = cfg_obj_asboolean(obj);
|
||||
|
||||
CHECK(configure_view_acl(vconfig, config, named_g_config,
|
||||
"allow-query-cache-on", NULL, actx,
|
||||
named_g_mctx, &view->cacheonacl));
|
||||
/*
|
||||
* Set "allow-query-cache", "allow-recursion", and
|
||||
* "allow-recursion-on" acls if configured in named.conf.
|
||||
* (Ignore the global defaults for now, because these ACLs
|
||||
* can inherit from each other when only some of them set at
|
||||
* the options/view level.)
|
||||
* Set "allow-query-cache", "allow-query-cache-on",
|
||||
* "allow-recursion", and "allow-recursion-on" acls if
|
||||
* configured in named.conf.
|
||||
*/
|
||||
CHECK(configure_view_acl(vconfig, config, NULL, "allow-query-cache",
|
||||
NULL, actx, named_g_mctx, &view->cacheacl));
|
||||
|
||||
if (strcmp(view->name, "_bind") != 0 &&
|
||||
view->rdclass != dns_rdataclass_chaos)
|
||||
{
|
||||
CHECK(configure_view_acl(vconfig, config, NULL,
|
||||
"allow-recursion", NULL, actx,
|
||||
named_g_mctx, &view->recursionacl));
|
||||
CHECK(configure_view_acl(vconfig, config, NULL,
|
||||
"allow-recursion-on", NULL, actx,
|
||||
named_g_mctx, &view->recursiononacl));
|
||||
CHECK(configure_view_acl(vconfig, config, "allow-query-cache", NULL,
|
||||
actx, named_g_mctx, &view->cacheacl));
|
||||
CHECK(configure_view_acl(vconfig, config, "allow-query-cache-on", NULL,
|
||||
actx, named_g_mctx, &view->cacheonacl));
|
||||
if (view->cacheonacl == NULL)
|
||||
CHECK(configure_view_acl(NULL, named_g_config,
|
||||
"allow-query-cache-on", NULL, actx,
|
||||
named_g_mctx, &view->cacheonacl));
|
||||
if (strcmp(view->name, "_bind") != 0) {
|
||||
CHECK(configure_view_acl(vconfig, config, "allow-recursion",
|
||||
NULL, actx, named_g_mctx,
|
||||
&view->recursionacl));
|
||||
CHECK(configure_view_acl(vconfig, config, "allow-recursion-on",
|
||||
NULL, actx, named_g_mctx,
|
||||
&view->recursiononacl));
|
||||
}
|
||||
|
||||
if (view->recursion) {
|
||||
/*
|
||||
* "allow-query-cache" inherits from "allow-recursion" if set,
|
||||
* otherwise from "allow-query" if set.
|
||||
* "allow-recursion" inherits from "allow-query-cache" if set,
|
||||
* otherwise from "allow-query" if set.
|
||||
*/
|
||||
if (view->cacheacl == NULL) {
|
||||
if (view->recursionacl != NULL) {
|
||||
dns_acl_attach(view->recursionacl,
|
||||
&view->cacheacl);
|
||||
} else if (view->queryacl != NULL) {
|
||||
dns_acl_attach(view->queryacl,
|
||||
&view->cacheacl);
|
||||
}
|
||||
}
|
||||
if (view->recursionacl == NULL) {
|
||||
if (view->cacheacl != NULL) {
|
||||
dns_acl_attach(view->cacheacl,
|
||||
&view->recursionacl);
|
||||
} else if (view->queryacl != NULL) {
|
||||
dns_acl_attach(view->queryacl,
|
||||
&view->recursionacl);
|
||||
}
|
||||
}
|
||||
/*
|
||||
* "allow-query-cache" inherits from "allow-recursion" if set,
|
||||
* otherwise from "allow-query" if set.
|
||||
* "allow-recursion" inherits from "allow-query-cache" if set,
|
||||
* otherwise from "allow-query" if set.
|
||||
*/
|
||||
if (view->cacheacl == NULL && view->recursionacl != NULL) {
|
||||
dns_acl_attach(view->recursionacl, &view->cacheacl);
|
||||
}
|
||||
|
||||
/*
|
||||
* If any are still unset, we now get default "allow-recursion",
|
||||
* "allow-recursion-on" and "allow-query-cache" ACLs from
|
||||
* the global config.
|
||||
*/
|
||||
if (view->recursionacl == NULL) {
|
||||
CHECK(configure_view_acl(NULL, NULL, named_g_config,
|
||||
"allow-recursion", NULL,
|
||||
actx, named_g_mctx,
|
||||
&view->recursionacl));
|
||||
}
|
||||
if (view->recursiononacl == NULL) {
|
||||
CHECK(configure_view_acl(NULL, NULL, named_g_config,
|
||||
"allow-recursion-on", NULL,
|
||||
actx, named_g_mctx,
|
||||
&view->recursiononacl));
|
||||
}
|
||||
if (view->cacheacl == NULL) {
|
||||
CHECK(configure_view_acl(NULL, NULL, named_g_config,
|
||||
if (view->cacheacl == NULL && view->recursion) {
|
||||
dns_acl_attach(view->queryacl, &view->cacheacl);
|
||||
}
|
||||
|
||||
if (view->recursion &&
|
||||
view->recursionacl == NULL && view->cacheacl != NULL)
|
||||
{
|
||||
dns_acl_attach(view->cacheacl, &view->recursionacl);
|
||||
}
|
||||
|
||||
/*
|
||||
* Set default "allow-recursion", "allow-recursion-on" and
|
||||
* "allow-query-cache" acls.
|
||||
*/
|
||||
if (view->recursionacl == NULL && view->recursion)
|
||||
CHECK(configure_view_acl(NULL, named_g_config,
|
||||
"allow-recursion", NULL,
|
||||
actx, named_g_mctx,
|
||||
&view->recursionacl));
|
||||
if (view->recursiononacl == NULL && view->recursion)
|
||||
CHECK(configure_view_acl(NULL, named_g_config,
|
||||
"allow-recursion-on", NULL,
|
||||
actx, named_g_mctx,
|
||||
&view->recursiononacl));
|
||||
if (view->cacheacl == NULL) {
|
||||
if (view->recursion)
|
||||
CHECK(configure_view_acl(NULL, named_g_config,
|
||||
"allow-query-cache", NULL,
|
||||
actx, named_g_mctx,
|
||||
&view->cacheacl));
|
||||
}
|
||||
} else if (view->cacheacl == NULL) {
|
||||
/*
|
||||
* We're not recursive; if "allow-query-cache" hasn't been
|
||||
* set at the options/view level, set it to none.
|
||||
*/
|
||||
CHECK(dns_acl_none(mctx, &view->cacheacl));
|
||||
else
|
||||
CHECK(dns_acl_none(mctx, &view->cacheacl));
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -4767,14 +4739,14 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
||||
* clients. This causes case not always to be preserved,
|
||||
* and is needed by some broken clients.
|
||||
*/
|
||||
CHECK(configure_view_acl(vconfig, config, named_g_config,
|
||||
"no-case-compress", NULL, actx,
|
||||
named_g_mctx, &view->nocasecompress));
|
||||
CHECK(configure_view_acl(vconfig, config, "no-case-compress", NULL,
|
||||
actx, named_g_mctx, &view->nocasecompress));
|
||||
|
||||
/*
|
||||
* Disable name compression completely, this is a tradeoff
|
||||
* between CPU and network usage.
|
||||
*/
|
||||
|
||||
obj = NULL;
|
||||
result = named_config_get(maps, "message-compression", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
@@ -4783,9 +4755,8 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
||||
/*
|
||||
* Filter setting on addresses in the answer section.
|
||||
*/
|
||||
CHECK(configure_view_acl(vconfig, config, named_g_config,
|
||||
"deny-answer-addresses", "acl",
|
||||
actx, named_g_mctx,
|
||||
CHECK(configure_view_acl(vconfig, config, "deny-answer-addresses",
|
||||
"acl", actx, named_g_mctx,
|
||||
&view->denyansweracl));
|
||||
CHECK(configure_view_nametable(vconfig, config, "deny-answer-addresses",
|
||||
"except-from", named_g_mctx,
|
||||
@@ -4808,36 +4779,26 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
||||
&view->sortlist));
|
||||
|
||||
/*
|
||||
* Configure default allow-notify, allow-update
|
||||
* and allow-update-forwarding ACLs, so they can be
|
||||
* inherited by zones. (Note these cannot be set at
|
||||
* options/view level.)
|
||||
* Configure default allow-transfer, allow-notify, allow-update
|
||||
* and allow-update-forwarding ACLs, if set, so they can be
|
||||
* inherited by zones.
|
||||
*/
|
||||
if (view->notifyacl == NULL) {
|
||||
CHECK(configure_view_acl(vconfig, config, named_g_config,
|
||||
if (view->notifyacl == NULL)
|
||||
CHECK(configure_view_acl(NULL, named_g_config,
|
||||
"allow-notify", NULL, actx,
|
||||
named_g_mctx, &view->notifyacl));
|
||||
}
|
||||
if (view->updateacl == NULL) {
|
||||
CHECK(configure_view_acl(NULL, NULL, named_g_config,
|
||||
"allow-update", NULL, actx,
|
||||
named_g_mctx, &view->updateacl));
|
||||
}
|
||||
if (view->upfwdacl == NULL) {
|
||||
CHECK(configure_view_acl(NULL, NULL, named_g_config,
|
||||
"allow-update-forwarding", NULL, actx,
|
||||
named_g_mctx, &view->upfwdacl));
|
||||
}
|
||||
|
||||
/*
|
||||
* Configure default allow-transer ACL so it can be inherited
|
||||
* by zones. (Note this *can* be set at options or view level.)
|
||||
*/
|
||||
if (view->transferacl == NULL) {
|
||||
CHECK(configure_view_acl(vconfig, config, named_g_config,
|
||||
if (view->transferacl == NULL)
|
||||
CHECK(configure_view_acl(NULL, named_g_config,
|
||||
"allow-transfer", NULL, actx,
|
||||
named_g_mctx, &view->transferacl));
|
||||
}
|
||||
if (view->updateacl == NULL)
|
||||
CHECK(configure_view_acl(NULL, named_g_config,
|
||||
"allow-update", NULL, actx,
|
||||
named_g_mctx, &view->updateacl));
|
||||
if (view->upfwdacl == NULL)
|
||||
CHECK(configure_view_acl(NULL, named_g_config,
|
||||
"allow-update-forwarding", NULL, actx,
|
||||
named_g_mctx, &view->upfwdacl));
|
||||
|
||||
obj = NULL;
|
||||
result = named_config_get(maps, "provide-ixfr", &obj);
|
||||
@@ -4960,9 +4921,8 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
||||
INSIST(0);
|
||||
}
|
||||
|
||||
CHECK(configure_view_acl(vconfig, config, named_g_config,
|
||||
"filter-aaaa", NULL, actx,
|
||||
named_g_mctx, &view->aaaa_acl));
|
||||
CHECK(configure_view_acl(vconfig, config, "filter-aaaa", NULL,
|
||||
actx, named_g_mctx, &view->aaaa_acl));
|
||||
|
||||
obj = NULL;
|
||||
result = named_config_get(maps, "prefetch", &obj);
|
||||
@@ -6056,7 +6016,7 @@ configure_zone(const cfg_obj_t *config, const cfg_obj_t *zconfig,
|
||||
* Add the zone to its view in the new view list.
|
||||
*/
|
||||
if (!modify)
|
||||
CHECK(dns_view_addzone(view, zone));
|
||||
CHECK(dns_view_addzone(view, zone));
|
||||
|
||||
if (zone_is_catz) {
|
||||
/*
|
||||
@@ -7373,18 +7333,128 @@ data_to_cfg(dns_view_t *view, MDB_val *key, MDB_val *data,
|
||||
return (result);
|
||||
}
|
||||
|
||||
/*%
|
||||
* Prototype for a callback which can be used with for_all_newzone_cfgs().
|
||||
*/
|
||||
typedef isc_result_t (*newzone_cfg_cb_t)(const cfg_obj_t *zconfig,
|
||||
cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
isc_mem_t *mctx, dns_view_t *view,
|
||||
cfg_aclconfctx_t *actx);
|
||||
|
||||
/*%
|
||||
* For each zone found in a NZD opened by the caller, create an object
|
||||
* representing its configuration and invoke "callback" with the created
|
||||
* object, "config", "vconfig", "mctx", "view" and "actx" as arguments (all
|
||||
* these are non-global variables required to invoke configure_zone()).
|
||||
* Immediately interrupt processing if an error is encountered while
|
||||
* transforming NZD data into a zone configuration object or if "callback"
|
||||
* returns an error.
|
||||
*/
|
||||
static isc_result_t
|
||||
for_all_newzone_cfgs(newzone_cfg_cb_t callback, cfg_obj_t *config,
|
||||
cfg_obj_t *vconfig, isc_mem_t *mctx, dns_view_t *view,
|
||||
cfg_aclconfctx_t *actx, MDB_txn *txn, MDB_dbi dbi)
|
||||
{
|
||||
const cfg_obj_t *zconfig, *zlist = NULL;
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
cfg_obj_t *zconfigobj = NULL;
|
||||
isc_buffer_t *text = NULL;
|
||||
MDB_cursor *cursor = NULL;
|
||||
MDB_val data, key;
|
||||
int status;
|
||||
|
||||
status = mdb_cursor_open(txn, dbi, &cursor);
|
||||
if (status != MDB_SUCCESS) {
|
||||
return (ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
for (status = mdb_cursor_get(cursor, &key, &data, MDB_FIRST);
|
||||
status == MDB_SUCCESS;
|
||||
status = mdb_cursor_get(cursor, &key, &data, MDB_NEXT))
|
||||
{
|
||||
/*
|
||||
* Create a configuration object from data fetched from NZD.
|
||||
*/
|
||||
result = data_to_cfg(view, &key, &data, &text, &zconfigobj);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
break;
|
||||
}
|
||||
|
||||
/*
|
||||
* Extract zone configuration from configuration object.
|
||||
*/
|
||||
result = cfg_map_get(zconfigobj, "zone", &zlist);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
break;
|
||||
} else if (!cfg_obj_islist(zlist)) {
|
||||
result = ISC_R_FAILURE;
|
||||
break;
|
||||
}
|
||||
zconfig = cfg_listelt_value(cfg_list_first(zlist));
|
||||
|
||||
/*
|
||||
* Invoke callback.
|
||||
*/
|
||||
result = callback(zconfig, config, vconfig, mctx, view, actx);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
break;
|
||||
}
|
||||
|
||||
/*
|
||||
* Destroy the configuration object created in this iteration.
|
||||
*/
|
||||
cfg_obj_destroy(named_g_addparser, &zconfigobj);
|
||||
}
|
||||
|
||||
if (text != NULL) {
|
||||
isc_buffer_free(&text);
|
||||
}
|
||||
if (zconfigobj != NULL) {
|
||||
cfg_obj_destroy(named_g_addparser, &zconfigobj);
|
||||
}
|
||||
mdb_cursor_close(cursor);
|
||||
|
||||
return (result);
|
||||
}
|
||||
|
||||
/*%
|
||||
* Attempt to configure a zone found in NZD and return the result.
|
||||
*/
|
||||
static isc_result_t
|
||||
configure_newzone(const cfg_obj_t *zconfig, cfg_obj_t *config,
|
||||
cfg_obj_t *vconfig, isc_mem_t *mctx, dns_view_t *view,
|
||||
cfg_aclconfctx_t *actx)
|
||||
{
|
||||
return (configure_zone(config, zconfig, vconfig, mctx, view,
|
||||
&named_g_server->viewlist, actx, ISC_TRUE,
|
||||
ISC_FALSE, ISC_FALSE));
|
||||
}
|
||||
|
||||
/*%
|
||||
* Revert new view assignment for a zone found in NZD.
|
||||
*/
|
||||
static isc_result_t
|
||||
configure_newzone_revert(const cfg_obj_t *zconfig, cfg_obj_t *config,
|
||||
cfg_obj_t *vconfig, isc_mem_t *mctx, dns_view_t *view,
|
||||
cfg_aclconfctx_t *actx)
|
||||
{
|
||||
UNUSED(config);
|
||||
UNUSED(vconfig);
|
||||
UNUSED(mctx);
|
||||
UNUSED(actx);
|
||||
|
||||
configure_zone_setviewcommit(ISC_R_FAILURE, zconfig, view);
|
||||
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
static isc_result_t
|
||||
configure_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
isc_mem_t *mctx, cfg_aclconfctx_t *actx)
|
||||
{
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
int status;
|
||||
isc_buffer_t *text = NULL;
|
||||
cfg_obj_t *zoneconf = NULL;
|
||||
MDB_cursor *cursor = NULL;
|
||||
isc_result_t result;
|
||||
MDB_txn *txn = NULL;
|
||||
MDB_dbi dbi;
|
||||
MDB_val key, data;
|
||||
|
||||
if (view->new_zone_config == NULL) {
|
||||
return (ISC_R_SUCCESS);
|
||||
@@ -7401,82 +7471,22 @@ configure_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
"for view '%s'",
|
||||
view->new_zone_db, view->name);
|
||||
|
||||
status = mdb_cursor_open(txn, dbi, &cursor);
|
||||
if (status != 0) {
|
||||
result = ISC_R_FAILURE;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
while (mdb_cursor_get(cursor, &key, &data, MDB_NEXT) == 0) {
|
||||
const cfg_obj_t *zlist = NULL;
|
||||
const cfg_obj_t *zoneobj = NULL;
|
||||
|
||||
result = data_to_cfg(view, &key, &data, &text, &zoneconf);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
CHECK(cfg_map_get(zoneconf, "zone", &zlist));
|
||||
if (!cfg_obj_islist(zlist)) {
|
||||
CHECK(ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
zoneobj = cfg_listelt_value(cfg_list_first(zlist));
|
||||
CHECK(configure_zone(config, zoneobj, vconfig, mctx,
|
||||
view, &named_g_server->viewlist, actx,
|
||||
ISC_TRUE, ISC_FALSE, ISC_FALSE));
|
||||
|
||||
cfg_obj_destroy(named_g_addparser, &zoneconf);
|
||||
}
|
||||
|
||||
result = ISC_R_SUCCESS;
|
||||
|
||||
cleanup:
|
||||
if (zoneconf != NULL) {
|
||||
cfg_obj_destroy(named_g_addparser, &zoneconf);
|
||||
}
|
||||
if (cursor != NULL) {
|
||||
mdb_cursor_close(cursor);
|
||||
cursor = NULL;
|
||||
}
|
||||
result = for_all_newzone_cfgs(configure_newzone, config, vconfig, mctx,
|
||||
view, actx, txn, dbi);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
status = mdb_cursor_open(txn, dbi, &cursor);
|
||||
if (status != 0) {
|
||||
goto cleanup2;
|
||||
}
|
||||
while (mdb_cursor_get(cursor, &key, &data, MDB_NEXT) == 0) {
|
||||
const cfg_obj_t *zlist = NULL;
|
||||
const cfg_obj_t *zconfig = NULL;
|
||||
isc_result_t result2;
|
||||
|
||||
result2 = data_to_cfg(view, &key, &data, &text,
|
||||
&zoneconf);
|
||||
if (result2 != ISC_R_SUCCESS) {
|
||||
goto cleanup2;
|
||||
}
|
||||
|
||||
result2 = cfg_map_get(zoneconf, "zone", &zlist);
|
||||
if (result2 != ISC_R_SUCCESS) {
|
||||
goto cleanup2;
|
||||
}
|
||||
|
||||
zconfig = cfg_listelt_value(cfg_list_first(zlist));
|
||||
configure_zone_setviewcommit(result, zconfig, view);
|
||||
|
||||
cfg_obj_destroy(named_g_addparser, &zoneconf);
|
||||
}
|
||||
/*
|
||||
* An error was encountered while attempting to configure zones
|
||||
* found in NZD. As this error may have been caused by a
|
||||
* configure_zone() failure, try restoring a sane configuration
|
||||
* by reattaching all zones found in NZD to the old view. If
|
||||
* this also fails, too bad, there is nothing more we can do in
|
||||
* terms of trying to make things right.
|
||||
*/
|
||||
(void) for_all_newzone_cfgs(configure_newzone_revert, config,
|
||||
vconfig, mctx, view, actx, txn,
|
||||
dbi);
|
||||
}
|
||||
|
||||
cleanup2:
|
||||
if (text != NULL) {
|
||||
isc_buffer_free(&text);
|
||||
}
|
||||
if (zoneconf != NULL) {
|
||||
cfg_obj_destroy(named_g_addparser, &zoneconf);
|
||||
}
|
||||
if (cursor != NULL) {
|
||||
mdb_cursor_close(cursor);
|
||||
}
|
||||
(void) nzd_close(&txn, ISC_FALSE);
|
||||
return (result);
|
||||
}
|
||||
@@ -7520,8 +7530,9 @@ get_newzone_config(dns_view_t *view, const char *zonename,
|
||||
key.mv_size = strlen(zname);
|
||||
|
||||
status = mdb_get(txn, dbi, &key, &data);
|
||||
if (status != 0)
|
||||
if (status != MDB_SUCCESS) {
|
||||
CHECK(ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
CHECK(data_to_cfg(view, &key, &data, &text, &zoneconf));
|
||||
|
||||
@@ -7887,11 +7898,7 @@ load_configuration(const char *filename, named_server_t *server,
|
||||
|
||||
isc_quota_soft(&server->sctx->recursionquota, softquota);
|
||||
|
||||
/*
|
||||
* Set "blackhole". Only legal at options level; there is
|
||||
* no default.
|
||||
*/
|
||||
CHECK(configure_view_acl(NULL, config, NULL, "blackhole", NULL,
|
||||
CHECK(configure_view_acl(NULL, config, "blackhole", NULL,
|
||||
named_g_aclconfctx, named_g_mctx,
|
||||
&server->sctx->blackholeacl));
|
||||
if (server->sctx->blackholeacl != NULL) {
|
||||
@@ -7899,11 +7906,7 @@ load_configuration(const char *filename, named_server_t *server,
|
||||
server->sctx->blackholeacl);
|
||||
}
|
||||
|
||||
/*
|
||||
* Set "blackhole". Only legal at options or global defaults level.
|
||||
*/
|
||||
CHECK(configure_view_acl(NULL, config, named_g_config,
|
||||
"keep-response-order", NULL,
|
||||
CHECK(configure_view_acl(NULL, config, "keep-response-order", NULL,
|
||||
named_g_aclconfctx, named_g_mctx,
|
||||
&server->sctx->keepresporder));
|
||||
|
||||
@@ -11901,7 +11904,7 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
||||
if (zconfig == NULL) {
|
||||
/* We're deleting the zone from the database */
|
||||
status = mdb_del(*txnp, dbi, &key, NULL);
|
||||
if (status != 0 && status != MDB_NOTFOUND) {
|
||||
if (status != MDB_SUCCESS && status != MDB_NOTFOUND) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER,
|
||||
@@ -11911,8 +11914,9 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
||||
namebuf, mdb_strerror(status));
|
||||
result = ISC_R_FAILURE;
|
||||
goto cleanup;
|
||||
} else if (status != MDB_NOTFOUND)
|
||||
} else if (status != MDB_NOTFOUND) {
|
||||
commit = ISC_TRUE;
|
||||
}
|
||||
} else {
|
||||
/* We're creating or overwriting the zone */
|
||||
const cfg_obj_t *zoptions;
|
||||
@@ -11947,7 +11951,7 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
||||
data.mv_size = isc_buffer_usedlength(text);
|
||||
|
||||
status = mdb_put(*txnp, dbi, &key, &data, 0);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER,
|
||||
@@ -11965,11 +11969,11 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
||||
result = ISC_R_SUCCESS;
|
||||
|
||||
cleanup:
|
||||
if (!commit || result != ISC_R_SUCCESS)
|
||||
if (!commit || result != ISC_R_SUCCESS) {
|
||||
(void) mdb_txn_abort(*txnp);
|
||||
else {
|
||||
} else {
|
||||
status = mdb_txn_commit(*txnp);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER,
|
||||
@@ -11984,8 +11988,10 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
||||
|
||||
UNLOCK(&view->new_zone_lock);
|
||||
|
||||
if (text != NULL)
|
||||
if (text != NULL) {
|
||||
isc_buffer_free(&text);
|
||||
}
|
||||
|
||||
return (result);
|
||||
}
|
||||
|
||||
@@ -11999,7 +12005,7 @@ nzd_writable(dns_view_t *view) {
|
||||
REQUIRE(view != NULL);
|
||||
|
||||
status = mdb_txn_begin((MDB_env *) view->new_zone_dbenv, 0, 0, &txn);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
||||
"mdb_txn_begin: %s",
|
||||
@@ -12008,7 +12014,7 @@ nzd_writable(dns_view_t *view) {
|
||||
}
|
||||
|
||||
status = mdb_dbi_open(txn, NULL, 0, &dbi);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
||||
"mdb_dbi_open: %s",
|
||||
@@ -12031,7 +12037,7 @@ nzd_open(dns_view_t *view, unsigned int flags, MDB_txn **txnp, MDB_dbi *dbi) {
|
||||
|
||||
status = mdb_txn_begin((MDB_env *) view->new_zone_dbenv, 0,
|
||||
flags, &txn);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||
ISC_LOG_WARNING, "mdb_txn_begin: %s",
|
||||
@@ -12040,7 +12046,7 @@ nzd_open(dns_view_t *view, unsigned int flags, MDB_txn **txnp, MDB_dbi *dbi) {
|
||||
}
|
||||
|
||||
status = mdb_dbi_open(txn, NULL, 0, dbi);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||
ISC_LOG_WARNING, "mdb_dbi_open: %s",
|
||||
@@ -12051,9 +12057,10 @@ nzd_open(dns_view_t *view, unsigned int flags, MDB_txn **txnp, MDB_dbi *dbi) {
|
||||
*txnp = txn;
|
||||
|
||||
cleanup:
|
||||
if (status != 0) {
|
||||
if (txn != NULL)
|
||||
if (status != MDB_SUCCESS) {
|
||||
if (txn != NULL) {
|
||||
mdb_txn_abort(txn);
|
||||
}
|
||||
return (ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
@@ -12067,38 +12074,34 @@ nzd_open(dns_view_t *view, unsigned int flags, MDB_txn **txnp, MDB_dbi *dbi) {
|
||||
*/
|
||||
static void
|
||||
nzd_env_close(dns_view_t *view) {
|
||||
if (view->new_zone_dbenv != NULL) {
|
||||
const char *dbpath = NULL;
|
||||
isc_boolean_t have_dbpath = ISC_FALSE;
|
||||
char dbpath_copy[PATH_MAX];
|
||||
char lockpath[PATH_MAX];
|
||||
int ret;
|
||||
const char *dbpath = NULL;
|
||||
char dbpath_copy[PATH_MAX];
|
||||
char lockpath[PATH_MAX];
|
||||
int status, ret;
|
||||
|
||||
if (mdb_env_get_path(view->new_zone_dbenv, &dbpath) == 0) {
|
||||
have_dbpath = ISC_TRUE;
|
||||
snprintf(lockpath, sizeof(lockpath), "%s-lock",
|
||||
dbpath);
|
||||
strlcpy(dbpath_copy, dbpath, sizeof(dbpath_copy));
|
||||
}
|
||||
|
||||
mdb_env_close((MDB_env *) view->new_zone_dbenv);
|
||||
view->new_zone_dbenv = NULL;
|
||||
|
||||
if (have_dbpath) {
|
||||
/*
|
||||
* Database files must be owned by the eventual user, not
|
||||
* by root.
|
||||
*/
|
||||
ret = chown(dbpath_copy, ns_os_uid(), -1);
|
||||
UNUSED(ret);
|
||||
|
||||
/*
|
||||
* Some platforms need the lockfile not to exist when we
|
||||
* reopen the environment.
|
||||
*/
|
||||
(void) isc_file_remove(lockpath);
|
||||
}
|
||||
if (view->new_zone_dbenv == NULL) {
|
||||
return;
|
||||
}
|
||||
|
||||
status = mdb_env_get_path(view->new_zone_dbenv, &dbpath);
|
||||
INSIST(status == MDB_SUCCESS);
|
||||
snprintf(lockpath, sizeof(lockpath), "%s-lock", dbpath);
|
||||
strlcpy(dbpath_copy, dbpath, sizeof(dbpath_copy));
|
||||
mdb_env_close((MDB_env *) view->new_zone_dbenv);
|
||||
|
||||
/*
|
||||
* Database files must be owned by the eventual user, not by root.
|
||||
*/
|
||||
ret = chown(dbpath_copy, ns_os_uid(), -1);
|
||||
UNUSED(ret);
|
||||
|
||||
/*
|
||||
* Some platforms need the lockfile not to exist when we reopen the
|
||||
* environment.
|
||||
*/
|
||||
(void) isc_file_remove(lockpath);
|
||||
|
||||
view->new_zone_dbenv = NULL;
|
||||
}
|
||||
|
||||
static isc_result_t
|
||||
@@ -12114,7 +12117,7 @@ nzd_env_reopen(dns_view_t *view) {
|
||||
nzd_env_close(view);
|
||||
|
||||
status = mdb_env_create(&env);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
|
||||
ISC_LOGMODULE_OTHER, ISC_LOG_ERROR,
|
||||
"mdb_env_create failed: %s",
|
||||
@@ -12124,7 +12127,7 @@ nzd_env_reopen(dns_view_t *view) {
|
||||
|
||||
if (view->new_zone_mapsize != 0ULL) {
|
||||
status = mdb_env_set_mapsize(env, view->new_zone_mapsize);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
|
||||
ISC_LOGMODULE_OTHER, ISC_LOG_ERROR,
|
||||
"mdb_env_set_mapsize failed: %s",
|
||||
@@ -12133,9 +12136,8 @@ nzd_env_reopen(dns_view_t *view) {
|
||||
}
|
||||
}
|
||||
|
||||
status = mdb_env_open(env, view->new_zone_db,
|
||||
MDB_NOSUBDIR|MDB_CREATE, 0600);
|
||||
if (status != 0) {
|
||||
status = mdb_env_open(env, view->new_zone_db, DNS_LMDB_FLAGS, 0600);
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
|
||||
ISC_LOGMODULE_OTHER, ISC_LOG_ERROR,
|
||||
"mdb_env_open of '%s' failed: %s",
|
||||
@@ -12164,10 +12166,12 @@ nzd_close(MDB_txn **txnp, isc_boolean_t commit) {
|
||||
if (*txnp != NULL) {
|
||||
if (commit) {
|
||||
status = mdb_txn_commit(*txnp);
|
||||
if (status != 0)
|
||||
if (status != MDB_SUCCESS) {
|
||||
result = ISC_R_FAILURE;
|
||||
} else
|
||||
}
|
||||
} else {
|
||||
mdb_txn_abort(*txnp);
|
||||
}
|
||||
*txnp = NULL;
|
||||
}
|
||||
|
||||
@@ -12185,11 +12189,12 @@ nzd_count(dns_view_t *view, int *countp) {
|
||||
REQUIRE(countp != NULL);
|
||||
|
||||
result = nzd_open(view, MDB_RDONLY, &txn, &dbi);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
status = mdb_stat(txn, dbi, &statbuf);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||
ISC_LOG_WARNING, "mdb_stat: %s",
|
||||
@@ -12262,8 +12267,9 @@ migrate_nzf(dns_view_t *view) {
|
||||
|
||||
zonelist = NULL;
|
||||
CHECK(cfg_map_get(nzf_config, "zone", &zonelist));
|
||||
if (!cfg_obj_islist(zonelist))
|
||||
if (!cfg_obj_islist(zonelist)) {
|
||||
CHECK(ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
CHECK(nzd_open(view, 0, &txn, &dbi));
|
||||
|
||||
@@ -12314,7 +12320,7 @@ migrate_nzf(dns_view_t *view) {
|
||||
data.mv_size = isc_buffer_usedlength(text);
|
||||
|
||||
status = mdb_put(txn, dbi, &key, &data, MDB_NOOVERWRITE);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER,
|
||||
@@ -12343,15 +12349,19 @@ migrate_nzf(dns_view_t *view) {
|
||||
}
|
||||
|
||||
cleanup:
|
||||
if (result != ISC_R_SUCCESS)
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
(void) nzd_close(&txn, ISC_FALSE);
|
||||
else
|
||||
} else {
|
||||
result = nzd_close(&txn, commit);
|
||||
}
|
||||
|
||||
if (text != NULL)
|
||||
if (text != NULL) {
|
||||
isc_buffer_free(&text);
|
||||
if (nzf_config != NULL)
|
||||
}
|
||||
|
||||
if (nzf_config != NULL) {
|
||||
cfg_obj_destroy(named_g_addparser, &nzf_config);
|
||||
}
|
||||
|
||||
return (result);
|
||||
}
|
||||
|
||||
@@ -15,5 +15,3 @@ rm -f ns2/example.db ns2/tsigzone.db ns2/example.db.jnl ns2/named.conf
|
||||
rm -f */named.memstats
|
||||
rm -f */named.run
|
||||
rm -f ns*/named.lock
|
||||
rm -f ns*/_default.nzf
|
||||
rm -f ns*/_default.nzd*
|
||||
|
||||
@@ -1,10 +0,0 @@
|
||||
$TTL 300 ; 5 minutes
|
||||
@ IN SOA ns root (
|
||||
2000082401 ; serial
|
||||
1800 ; refresh (30 minutes)
|
||||
1800 ; retry (30 minutes)
|
||||
1814400 ; expire (3 weeks)
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
NS ns
|
||||
ns A 10.53.0.3
|
||||
@@ -1,22 +0,0 @@
|
||||
options {
|
||||
query-source address 10.53.0.3;
|
||||
notify-source 10.53.0.3;
|
||||
transfer-source 10.53.0.3;
|
||||
port 5300;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.3; };
|
||||
listen-on-v6 { none; };
|
||||
recursion no;
|
||||
notify no;
|
||||
allow-new-zones yes;
|
||||
allow-transfer { none; };
|
||||
};
|
||||
|
||||
controls {
|
||||
inet 10.53.0.3 port 9953 allow { any; } keys { rndc_key; };
|
||||
};
|
||||
|
||||
key rndc_key {
|
||||
secret "1234abcd8765";
|
||||
algorithm hmac-sha256;
|
||||
};
|
||||
@@ -1,10 +0,0 @@
|
||||
$TTL 300 ; 5 minutes
|
||||
@ IN SOA ns root (
|
||||
2000082401 ; serial
|
||||
1800 ; refresh (30 minutes)
|
||||
1800 ; retry (30 minutes)
|
||||
1814400 ; expire (3 weeks)
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
NS ns
|
||||
ns A 10.53.0.4
|
||||
@@ -1,10 +0,0 @@
|
||||
$TTL 300 ; 5 minutes
|
||||
@ IN SOA ns root (
|
||||
2000082401 ; serial
|
||||
1800 ; refresh (30 minutes)
|
||||
1800 ; retry (30 minutes)
|
||||
1814400 ; expire (3 weeks)
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
NS ns
|
||||
ns A 10.53.0.4
|
||||
@@ -1,27 +0,0 @@
|
||||
options {
|
||||
query-source address 10.53.0.4;
|
||||
notify-source 10.53.0.4;
|
||||
transfer-source 10.53.0.4;
|
||||
port 5300;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.4; };
|
||||
listen-on-v6 { none; };
|
||||
recursion no;
|
||||
notify no;
|
||||
allow-new-zones yes;
|
||||
allow-transfer { none; };
|
||||
};
|
||||
|
||||
controls {
|
||||
inet 10.53.0.4 port 9953 allow { any; } keys { rndc_key; };
|
||||
};
|
||||
|
||||
key rndc_key {
|
||||
secret "1234abcd8765";
|
||||
algorithm hmac-sha256;
|
||||
};
|
||||
|
||||
zone "existing" {
|
||||
type master;
|
||||
file "existing.db";
|
||||
};
|
||||
@@ -172,65 +172,5 @@ t=`expr $t + 1`
|
||||
$DIG example. soa @10.53.0.2 +subnet="192.0.2.128/32" -p 5300 > dig.out.${t}
|
||||
grep "CLIENT-SUBNET.*192.0.2.128/32/24" dig.out.${t} > /dev/null || { echo "I:test $t failed" ; status=1; }
|
||||
|
||||
# AXFR tests against ns3
|
||||
|
||||
echo "I:testing allow-transfer ACLs against ns3 (no existing zones)"
|
||||
|
||||
echo "I:calling addzone example.com on ns3"
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 addzone 'example.com {type master; file "example.db"; }; '
|
||||
|
||||
sleep 1
|
||||
|
||||
t=`expr $t + 1`
|
||||
ret=0
|
||||
echo "I:checking AXFR of example.com from ns3 with ACL allow-transfer { none; }; (${t})"
|
||||
$DIG @10.53.0.3 -p 5300 example.com axfr > dig.out.${t} 2>&1
|
||||
grep "Transfer failed." dig.out.${t} >/dev/null 2>&1 || ret=1
|
||||
[ $ret -eq 0 ] || echo "I:failed"
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:calling rndc reconfig"
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 reconfig
|
||||
|
||||
sleep 1
|
||||
|
||||
t=`expr $t + 1`
|
||||
ret=0
|
||||
echo "I:re-checking AXFR of example.com from ns3 with ACL allow-transfer { none; }; (${t})"
|
||||
$DIG @10.53.0.3 -p 5300 example.com axfr > dig.out.${t} 2>&1
|
||||
grep "Transfer failed." dig.out.${t} >/dev/null 2>&1 || ret=1
|
||||
[ $ret -eq 0 ] || echo "I:failed"
|
||||
status=`expr $status + $ret`
|
||||
|
||||
# AXFR tests against ns4
|
||||
|
||||
echo "I:testing allow-transfer ACLs against ns4 (1 pre-existing zone)"
|
||||
|
||||
echo "I:calling addzone example.com on ns4"
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.4 -p 9953 addzone 'example.com {type master; file "example.db"; }; '
|
||||
|
||||
sleep 1
|
||||
|
||||
t=`expr $t + 1`
|
||||
ret=0
|
||||
echo "I:checking AXFR of example.com from ns4 with ACL allow-transfer { none; }; (${t})"
|
||||
$DIG @10.53.0.4 -p 5300 example.com axfr > dig.out.${t} 2>&1
|
||||
grep "Transfer failed." dig.out.${t} >/dev/null 2>&1 || ret=1
|
||||
[ $ret -eq 0 ] || echo "I:failed"
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:calling rndc reconfig"
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.4 -p 9953 reconfig
|
||||
|
||||
sleep 1
|
||||
|
||||
t=`expr $t + 1`
|
||||
ret=0
|
||||
echo "I:re-checking AXFR of example.com from ns4 with ACL allow-transfer { none; }; (${t})"
|
||||
$DIG @10.53.0.4 -p 5300 example.com axfr > dig.out.${t} 2>&1
|
||||
grep "Transfer failed." dig.out.${t} >/dev/null 2>&1 || ret=1
|
||||
[ $ret -eq 0 ] || echo "I:failed"
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:exit status: $status"
|
||||
[ $status -eq 0 ] || exit 1
|
||||
|
||||
@@ -10,4 +10,4 @@ my $target = shift;
|
||||
my $file = shift;
|
||||
my $mtime = time - (stat $file)[9];
|
||||
die "bad mtime $mtime"
|
||||
unless abs($mtime - $target) < 3;
|
||||
unless abs($mtime - $target) < 10;
|
||||
|
||||
@@ -35,6 +35,19 @@ PIDFILE="${THISDIR}/${CONFDIR}/named.pid"
|
||||
myRNDC="$RNDC -c ${THISDIR}/${CONFDIR}/rndc.conf"
|
||||
myNAMED="$NAMED -c ${THISDIR}/${CONFDIR}/named.conf -m record,size,mctx -T clienttest -T nosyslog -d 99 -X named.lock -U 4"
|
||||
|
||||
# Test given condition. If true, test again after a second. Used for testing
|
||||
# filesystem-dependent conditions in order to prevent false negatives caused by
|
||||
# directory contents not being synchronized immediately after rename() returns.
|
||||
test_with_retry() {
|
||||
if test "$@"; then
|
||||
sleep 1
|
||||
if test "$@"; then
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
return 1
|
||||
}
|
||||
|
||||
waitforpidfile() {
|
||||
for _w in 1 2 3 4 5 6 7 8 9 10
|
||||
do
|
||||
@@ -48,9 +61,10 @@ n=0
|
||||
|
||||
cd $CONFDIR
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I:testing log file validity (named -g + only plain files allowed) ($n)"
|
||||
echo "I:testing log file validity (named -g + only plain files allowed)"
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: testing plain file (named -g) ($n)"
|
||||
# First run with a known good config.
|
||||
echo > $PLAINFILE
|
||||
cp $PLAINCONF named.conf
|
||||
@@ -58,9 +72,9 @@ $myRNDC reconfig > rndc.out.test$n 2>&1
|
||||
grep "reloading configuration failed" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing plain file succeeded"
|
||||
echo "I: testing plain file succeeded"
|
||||
else
|
||||
echo "I: testing plain file failed (unexpected)"
|
||||
echo "I: testing plain file failed (unexpected)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
fi
|
||||
@@ -79,14 +93,14 @@ then
|
||||
grep "checking logging configuration failed: invalid file" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing directory as file succeeded (UNEXPECTED)"
|
||||
echo "I: testing directory as file succeeded (UNEXPECTED)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
else
|
||||
echo "I: testing directory as log file failed (expected)"
|
||||
echo "I: testing directory as log file failed (expected)"
|
||||
fi
|
||||
else
|
||||
echo "I: skipping directory test (unable to create directory)"
|
||||
echo "I: skipping directory test (unable to create directory)"
|
||||
fi
|
||||
|
||||
# Now try pipe file, expect failure
|
||||
@@ -103,14 +117,14 @@ then
|
||||
grep "checking logging configuration failed: invalid file" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing pipe file as log file succeeded (UNEXPECTED)"
|
||||
echo "I: testing pipe file as log file succeeded (UNEXPECTED)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
else
|
||||
echo "I: testing pipe file as log file failed (expected)"
|
||||
echo "I: testing pipe file as log file failed (expected)"
|
||||
fi
|
||||
else
|
||||
echo "I: skipping pipe test (unable to create pipe)"
|
||||
echo "I: skipping pipe test (unable to create pipe)"
|
||||
fi
|
||||
|
||||
# Now try symlink file to plain file, expect success
|
||||
@@ -129,14 +143,14 @@ then
|
||||
grep "reloading configuration failed" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing symlink to plain file succeeded"
|
||||
echo "I: testing symlink to plain file succeeded"
|
||||
else
|
||||
echo "I: testing symlink to plain file failed (unexpected)"
|
||||
echo "I: testing symlink to plain file failed (unexpected)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
fi
|
||||
else
|
||||
echo "I: skipping symlink test (unable to create symlink)"
|
||||
echo "I: skipping symlink test (unable to create symlink)"
|
||||
fi
|
||||
# Stop the server and run through a series of tests with various config
|
||||
# files while controlling the stop/start of the server.
|
||||
@@ -155,9 +169,10 @@ fi
|
||||
|
||||
status=0
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I:testing log file validity (only plain files allowed) ($n)"
|
||||
echo "I:testing log file validity (only plain files allowed)"
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: testing plain file (named -g) ($n)"
|
||||
# First run with a known good config.
|
||||
echo > $PLAINFILE
|
||||
cp $PLAINCONF named.conf
|
||||
@@ -165,9 +180,9 @@ $myRNDC reconfig > rndc.out.test$n 2>&1
|
||||
grep "reloading configuration failed" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing plain file succeeded"
|
||||
echo "I: testing plain file succeeded"
|
||||
else
|
||||
echo "I: testing plain file failed (unexpected)"
|
||||
echo "I: testing plain file failed (unexpected)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
fi
|
||||
@@ -186,14 +201,14 @@ then
|
||||
grep "configuring logging: invalid file" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing directory as file succeeded (UNEXPECTED)"
|
||||
echo "I: testing directory as file succeeded (UNEXPECTED)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
else
|
||||
echo "I: testing directory as log file failed (expected)"
|
||||
echo "I: testing directory as log file failed (expected)"
|
||||
fi
|
||||
else
|
||||
echo "I: skipping directory test (unable to create directory)"
|
||||
echo "I: skipping directory test (unable to create directory)"
|
||||
fi
|
||||
|
||||
# Now try pipe file, expect failure
|
||||
@@ -210,14 +225,14 @@ then
|
||||
grep "configuring logging: invalid file" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing pipe file as log file succeeded (UNEXPECTED)"
|
||||
echo "I: testing pipe file as log file succeeded (UNEXPECTED)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
else
|
||||
echo "I: testing pipe file as log file failed (expected)"
|
||||
echo "I: testing pipe file as log file failed (expected)"
|
||||
fi
|
||||
else
|
||||
echo "I: skipping pipe test (unable to create pipe)"
|
||||
echo "I: skipping pipe test (unable to create pipe)"
|
||||
fi
|
||||
|
||||
# Now try symlink file to plain file, expect success
|
||||
@@ -237,18 +252,18 @@ then
|
||||
grep "reloading configuration failed" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing symlink to plain file succeeded"
|
||||
echo "I: testing symlink to plain file succeeded"
|
||||
else
|
||||
echo "I: testing symlink to plain file failed (unexpected)"
|
||||
echo "I: testing symlink to plain file failed (unexpected)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
fi
|
||||
else
|
||||
echo "I: skipping symlink test (unable to create symlink)"
|
||||
echo "I: skipping symlink test (unable to create symlink)"
|
||||
fi
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: testing default logfile using named -L file ($n)"
|
||||
echo "I:testing default logfile using named -L file ($n)"
|
||||
# Now stop the server again and test the -L option
|
||||
rm -f $DLFILE
|
||||
$PERL ../../stop.pl .. ns1
|
||||
@@ -256,7 +271,7 @@ if ! test -f $PIDFILE; then
|
||||
cp $PLAINCONF named.conf
|
||||
$myNAMED -L $DLFILE > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]; then
|
||||
echo "I:failed to start $myNAMED"
|
||||
echo "I: failed to start $myNAMED"
|
||||
echo "I:exit status: $status"
|
||||
exit $status
|
||||
fi
|
||||
@@ -272,7 +287,7 @@ if ! test -f $PIDFILE; then
|
||||
exit 1
|
||||
fi
|
||||
else
|
||||
echo "I:failed to cleanly stop $myNAMED"
|
||||
echo "I: failed to cleanly stop $myNAMED"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
fi
|
||||
@@ -284,9 +299,9 @@ echo "I: testing iso8601 timestamp ($n)"
|
||||
cp $ISOCONF named.conf
|
||||
$myRNDC reconfig > rndc.out.test$n 2>&1
|
||||
if grep '^....-..-..T..:..:..\.... ' $ISOFILE > /dev/null; then
|
||||
echo "I: testing iso8601 timestamp succeeded"
|
||||
echo "I: testing iso8601 timestamp succeeded"
|
||||
else
|
||||
echo "I: testing iso8601 timestamp failed"
|
||||
echo "I: testing iso8601 timestamp failed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
|
||||
@@ -295,14 +310,14 @@ echo "I: testing iso8601-utc timestamp ($n)"
|
||||
cp $ISOCONFUTC named.conf
|
||||
$myRNDC reconfig > rndc.out.test$n 2>&1
|
||||
if grep '^....-..-..T..:..:..\....Z' $ISOUTCFILE > /dev/null; then
|
||||
echo "I: testing iso8601-utc timestamp succeeded"
|
||||
echo "I: testing iso8601-utc timestamp succeeded"
|
||||
else
|
||||
echo "I: testing iso8601-utc timestamp failed"
|
||||
echo "I: testing iso8601-utc timestamp failed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: testing explict versions ($n)"
|
||||
echo "I: testing explicit versions ($n)"
|
||||
cp $VERSCONF named.conf
|
||||
# a seconds since epoch version number
|
||||
touch $VERSFILE.1480039317
|
||||
@@ -313,27 +328,27 @@ t2=`$PERL -e 'print time()."\n";'`
|
||||
t=`expr ${t2:-0} - ${t1:-0}`
|
||||
if test ${t:-1000} -gt 5
|
||||
then
|
||||
echo "I: testing explict versions failed cleanup of old entries took too long ($t secs)"
|
||||
echo "I: testing explicit versions failed: cleanup of old entries took too long ($t secs)"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if ! grep "status: NOERROR" dig.out.test$n > /dev/null
|
||||
then
|
||||
echo "I: testing explict versions failed DiG lookup failed"
|
||||
echo "I: testing explicit versions failed: DiG lookup failed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if test -f $VERSFILE.1480039317
|
||||
if test_with_retry -f $VERSFILE.1480039317
|
||||
then
|
||||
echo "I: testing explict versions failed $VERSFILE.1480039317 not removed"
|
||||
echo "I: testing explicit versions failed: $VERSFILE.1480039317 not removed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if test -f $VERSFILE.5
|
||||
if test_with_retry -f $VERSFILE.5
|
||||
then
|
||||
echo "I: testing explict versions failed $VERSFILE.5 exists"
|
||||
echo "I: testing explicit versions failed: $VERSFILE.5 exists"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if test ! -f $VERSFILE.4
|
||||
if test_with_retry ! -f $VERSFILE.4
|
||||
then
|
||||
echo "I: testing explict versions failed $VERSFILE.4 does not exist"
|
||||
echo "I: testing explicit versions failed: $VERSFILE.4 does not exist"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
|
||||
@@ -349,17 +364,17 @@ t2=`$PERL -e 'print time()."\n";'`
|
||||
t=`expr ${t2:-0} - ${t1:-0}`
|
||||
if test ${t:-1000} -gt 5
|
||||
then
|
||||
echo "I: testing timestamped versions failed cleanup of old entries took too long ($t secs)"
|
||||
echo "I: testing timestamped versions failed: cleanup of old entries took too long ($t secs)"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if ! grep "status: NOERROR" dig.out.test$n > /dev/null
|
||||
then
|
||||
echo "I: testing timestamped versions failed DiG lookup failed"
|
||||
echo "I: testing timestamped versions failed: DiG lookup failed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if test -f $TSFILE.1480039317
|
||||
if test_with_retry -f $TSFILE.1480039317
|
||||
then
|
||||
echo "I: testing timestamped versions failed $TSFILE.1480039317 not removed"
|
||||
echo "I: testing timestamped versions failed: $TSFILE.1480039317 not removed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
|
||||
@@ -375,22 +390,22 @@ t2=`$PERL -e 'print time()."\n";'`
|
||||
t=`expr ${t2:-0} - ${t1:-0}`
|
||||
if test ${t:-1000} -gt 5
|
||||
then
|
||||
echo "I: testing unlimited versions failed took too long ($t secs)"
|
||||
echo "I: testing unlimited versions failed: took too long ($t secs)"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if ! grep "status: NOERROR" dig.out.test$n > /dev/null
|
||||
then
|
||||
echo "I: testing unlimited versions failed DiG lookup failed"
|
||||
echo "I: testing unlimited versions failed: DiG lookup failed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if test ! -f $UNLIMITEDFILE.1480039317
|
||||
if test_with_retry ! -f $UNLIMITEDFILE.1480039317
|
||||
then
|
||||
echo "I: testing unlimited versions failed $UNLIMITEDFILE.1480039317 removed"
|
||||
echo "I: testing unlimited versions failed: $UNLIMITEDFILE.1480039317 removed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if test ! -f $UNLIMITEDFILE.4
|
||||
if test_with_retry ! -f $UNLIMITEDFILE.4
|
||||
then
|
||||
echo "I: testing unlimited versions failed $UNLIMITEDFILE.4 does not"
|
||||
echo "I: testing unlimited versions failed: $UNLIMITEDFILE.4 does not exist"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
|
||||
|
||||
@@ -22,9 +22,7 @@ wait_for_log() {
|
||||
|
||||
mkeys_reconfig_on() {
|
||||
nsidx=$1
|
||||
nextpart ns${nsidx}/named.run > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 reconfig . | sed "s/^/I: ns${nsidx} /"
|
||||
wait_for_log "running" ns${nsidx}/named.run
|
||||
}
|
||||
|
||||
mkeys_reload_on() {
|
||||
@@ -71,9 +69,7 @@ mkeys_status_on() {
|
||||
|
||||
mkeys_flush_on() {
|
||||
nsidx=$1
|
||||
nextpart ns${nsidx}/named.run > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 flush | sed "s/^/I: ns${nsidx} /"
|
||||
wait_for_log "flushing caches in all views succeeded" ns${nsidx}/named.run
|
||||
}
|
||||
|
||||
mkeys_secroots_on() {
|
||||
@@ -693,7 +689,7 @@ ret=0
|
||||
# compare against the known key.
|
||||
tathex=`grep "query '_ta-[0-9a-f][0-9a-f]*/NULL/IN' approved" ns1/named.run | awk '{print $6; exit 0}' | sed -e 's/(_ta-\([0-9a-f][0-9a-f]*\)):/\1/'`
|
||||
tatkey=`$PERL -e 'printf("%d\n", hex(@ARGV[0]));' $tathex`
|
||||
realkey=`$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 secroots - | grep '; managed' | sed 's#.*SHA256/\([0-9][0-9]*\) ; managed.*#\1#'`
|
||||
realkey=`$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 secroots - | sed -n 's#.*SHA256/\([0-9][0-9]*\) ; .*managed.*#\1#p'`
|
||||
[ "$tatkey" -eq "$realkey" ] || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
@@ -20,6 +20,7 @@ options {
|
||||
listen-on-v6 { none; };
|
||||
recursion yes;
|
||||
notify yes;
|
||||
serial-query-rate 1; // workaround for KB AA-01213
|
||||
};
|
||||
|
||||
key altkey {
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
Copyright (C) 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
Copyright (C) 2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
|
||||
This Source Code Form is subject to the terms of the Mozilla Public
|
||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -7,8 +7,9 @@ file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
system test for recursion limits
|
||||
|
||||
ns1 -- root server
|
||||
ans2 -- delegate to ns1.(n+1).example.com for all n, up to
|
||||
the value specified in ans.limit (or forever if limit is 0)
|
||||
ans2 -- for example.org: delegate to ns1.(n+1).example.org for all n, up to the
|
||||
value specified in ans.limit (or forever if limit is 0)
|
||||
for example.net: delegate every query to 15 more name servers, with
|
||||
"victim" address
|
||||
ns3 -- resolver under test
|
||||
ans4 -- delegates every query to 16 more name servers, with "victim" address
|
||||
ans7 -- "victim" server
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/usr/bin/env perl
|
||||
#
|
||||
# Copyright (C) 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -10,9 +10,17 @@ use strict;
|
||||
use warnings;
|
||||
|
||||
use IO::File;
|
||||
use Getopt::Long;
|
||||
use Net::DNS::Nameserver;
|
||||
use Time::HiRes qw(usleep nanosleep);
|
||||
use IO::Socket;
|
||||
use Net::DNS;
|
||||
|
||||
my $localaddr = "10.53.0.2";
|
||||
my $limit = getlimit();
|
||||
my $no_more_waiting = 0;
|
||||
my @delayed_response;
|
||||
my $timeout;
|
||||
|
||||
my $udpsock = IO::Socket::INET->new(LocalAddr => "$localaddr",
|
||||
LocalPort => 5300, Proto => "udp", Reuse => 1) or die "$!";
|
||||
|
||||
my $pidf = new IO::File "ans.pid", "w" or die "cannot open pid file: $!";
|
||||
print $pidf "$$\n" or die "cannot write pid file: $!";
|
||||
@@ -39,21 +47,18 @@ sub getlimit {
|
||||
return 0;
|
||||
}
|
||||
|
||||
my $localaddr = "10.53.0.2";
|
||||
my $localport = 5300;
|
||||
my $verbose = 0;
|
||||
my $limit = getlimit();
|
||||
|
||||
# If $wait == 0 is returned, returned reply will be sent immediately.
|
||||
# If $wait == 1 is returned, sending the returned reply might be delayed; see
|
||||
# comments inside handle_UDP() for details.
|
||||
sub reply_handler {
|
||||
my ($qname, $qclass, $qtype, $peerhost, $query, $conn) = @_;
|
||||
my ($rcode, @ans, @auth, @add);
|
||||
my ($qname, $qclass, $qtype) = @_;
|
||||
my ($rcode, @ans, @auth, @add, $wait);
|
||||
|
||||
print ("request: $qname/$qtype\n");
|
||||
STDOUT->flush();
|
||||
|
||||
$wait = 0;
|
||||
$count += 1;
|
||||
# Sleep 100ms to make sure that named sends both A and AAAA queries.
|
||||
usleep(100000);
|
||||
|
||||
if ($qname eq "count" ) {
|
||||
if ($qtype eq "TXT") {
|
||||
@@ -95,6 +100,7 @@ sub reply_handler {
|
||||
$rcode = "NOERROR";
|
||||
} elsif ($qname =~ /^ns1\.(\d+)\.example\.org$/) {
|
||||
my $next = $1 + 1;
|
||||
$wait = 1;
|
||||
if ($limit == 0 || (! $send_response && $next <= $limit)) {
|
||||
my $rr = new Net::DNS::RR("$1.example.org 86400 $qclass NS ns1.$next.example.org");
|
||||
push @auth, $rr;
|
||||
@@ -108,24 +114,114 @@ sub reply_handler {
|
||||
}
|
||||
}
|
||||
$rcode = "NOERROR";
|
||||
} elsif ($qname eq "direct.example.net" ) {
|
||||
if ($qtype eq "A") {
|
||||
my ($ttl, $rdata) = (3600, $localaddr);
|
||||
my $rr = new Net::DNS::RR("$qname $ttl $qclass $qtype $rdata");
|
||||
push @ans, $rr;
|
||||
}
|
||||
$rcode = "NOERROR";
|
||||
} elsif( $qname =~ /^ns1\.(\d+)\.example\.net$/ ) {
|
||||
my $next = ($1 + 1) * 16;
|
||||
for (my $i = 1; $i < 16; $i++) {
|
||||
my $s = $next + $i;
|
||||
my $rr = new Net::DNS::RR("$1.example.net 86400 $qclass NS ns1.$s.example.net");
|
||||
push @auth, $rr;
|
||||
$rr = new Net::DNS::RR("ns1.$s.example.net 86400 $qclass A 10.53.0.7");
|
||||
push @add, $rr;
|
||||
}
|
||||
$rcode = "NOERROR";
|
||||
} else {
|
||||
$rcode = "NXDOMAIN";
|
||||
}
|
||||
|
||||
# mark the answer as authoritive (by setting the 'aa' flag
|
||||
return ($rcode, \@ans, \@auth, \@add, { aa => 1 });
|
||||
return ($rcode, \@ans, \@auth, \@add, $wait);
|
||||
}
|
||||
|
||||
GetOptions(
|
||||
'port=i' => \$localport,
|
||||
'verbose!' => \$verbose,
|
||||
);
|
||||
sub handleUDP {
|
||||
my ($buf, $peer) = @_;
|
||||
my ($request, $rcode, $ans, $auth, $add, $wait);
|
||||
|
||||
my $ns = Net::DNS::Nameserver->new(
|
||||
LocalAddr => $localaddr,
|
||||
LocalPort => $localport,
|
||||
ReplyHandler => \&reply_handler,
|
||||
Verbose => $verbose,
|
||||
);
|
||||
$request = new Net::DNS::Packet(\$buf, 0);
|
||||
$@ and die $@;
|
||||
|
||||
$ns->main_loop;
|
||||
my ($question) = $request->question;
|
||||
my $qname = $question->qname;
|
||||
my $qclass = $question->qclass;
|
||||
my $qtype = $question->qtype;
|
||||
|
||||
($rcode, $ans, $auth, $add, $wait) = reply_handler($qname, $qclass, $qtype);
|
||||
|
||||
my $reply = $request->reply();
|
||||
|
||||
$reply->header->rcode($rcode);
|
||||
$reply->header->aa(@$ans ? 1 : 0);
|
||||
$reply->header->id($request->header->id);
|
||||
$reply->{answer} = $ans if $ans;
|
||||
$reply->{authority} = $auth if $auth;
|
||||
$reply->{additional} = $add if $add;
|
||||
|
||||
if ($wait) {
|
||||
# reply_handler() asked us to delay sending this reply until
|
||||
# another reply with $wait == 1 is generated or a timeout
|
||||
# occurs.
|
||||
if (@delayed_response) {
|
||||
# A delayed reply is already queued, so we can now send
|
||||
# both the delayed reply and the current reply.
|
||||
send_delayed_response();
|
||||
return $reply;
|
||||
} elsif ($no_more_waiting) {
|
||||
# It was determined before that there is no point in
|
||||
# waiting for "accompanying" queries. Thus, send the
|
||||
# current reply immediately.
|
||||
return $reply;
|
||||
} else {
|
||||
# No delayed reply is queued and the client is expected
|
||||
# to send an "accompanying" query shortly. Do not send
|
||||
# the current reply right now, just save it for later
|
||||
# and wait for an "accompanying" query to be received.
|
||||
@delayed_response = ($reply, $peer);
|
||||
$timeout = 0.5;
|
||||
return;
|
||||
}
|
||||
} else {
|
||||
# Send reply immediately.
|
||||
return $reply;
|
||||
}
|
||||
}
|
||||
|
||||
sub send_delayed_response {
|
||||
my ($reply, $peer) = @delayed_response;
|
||||
# Truncation to 512 bytes is required for triggering "NS explosion" on
|
||||
# builds without IPv6 support
|
||||
$udpsock->send($reply->data(512), 0, $peer);
|
||||
undef @delayed_response;
|
||||
undef $timeout;
|
||||
}
|
||||
|
||||
# Main
|
||||
my $rin;
|
||||
my $rout;
|
||||
for (;;) {
|
||||
$rin = '';
|
||||
vec($rin, fileno($udpsock), 1) = 1;
|
||||
|
||||
select($rout = $rin, undef, undef, $timeout);
|
||||
|
||||
if (vec($rout, fileno($udpsock), 1)) {
|
||||
my ($buf, $peer, $reply);
|
||||
$udpsock->recv($buf, 512);
|
||||
$peer = $udpsock->peername();
|
||||
$reply = handleUDP($buf, $peer);
|
||||
# Truncation to 512 bytes is required for triggering "NS
|
||||
# explosion" on builds without IPv6 support
|
||||
$udpsock->send($reply->data(512), 0, $peer) if $reply;
|
||||
} else {
|
||||
# An "accompanying" query was expected to come in, but did not.
|
||||
# Assume the client never sends "accompanying" queries to
|
||||
# prevent pointlessly waiting for them ever again.
|
||||
$no_more_waiting = 1;
|
||||
# Send the delayed reply to the query which caused us to wait.
|
||||
send_delayed_response();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,89 +0,0 @@
|
||||
#!/usr/bin/env perl
|
||||
#
|
||||
# Copyright (C) 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
use strict;
|
||||
use warnings;
|
||||
|
||||
use IO::File;
|
||||
use Getopt::Long;
|
||||
use Net::DNS::Nameserver;
|
||||
|
||||
my $pidf = new IO::File "ans.pid", "w" or die "cannot open pid file: $!";
|
||||
print $pidf "$$\n" or die "cannot write pid file: $!";
|
||||
$pidf->close or die "cannot close pid file: $!";
|
||||
sub rmpid { unlink "ans.pid"; exit 1; };
|
||||
|
||||
$SIG{INT} = \&rmpid;
|
||||
$SIG{TERM} = \&rmpid;
|
||||
|
||||
my $count = 0;
|
||||
my $send_response = 0;
|
||||
|
||||
my $localaddr = "10.53.0.4";
|
||||
my $localport = 5300;
|
||||
my $verbose = 0;
|
||||
|
||||
sub reply_handler {
|
||||
my ($qname, $qclass, $qtype, $peerhost, $query, $conn) = @_;
|
||||
my ($rcode, @ans, @auth, @add);
|
||||
|
||||
print ("request: $qname/$qtype\n");
|
||||
STDOUT->flush();
|
||||
|
||||
$count += 1;
|
||||
|
||||
if ($qname eq "count" ) {
|
||||
if ($qtype eq "TXT") {
|
||||
my ($ttl, $rdata) = (0, "$count");
|
||||
my $rr = new Net::DNS::RR("$qname $ttl $qclass $qtype $rdata");
|
||||
push @ans, $rr;
|
||||
print ("\tcount: $count\n");
|
||||
}
|
||||
$rcode = "NOERROR";
|
||||
} elsif ($qname eq "reset" ) {
|
||||
$count = 0;
|
||||
$send_response = 0;
|
||||
$rcode = "NOERROR";
|
||||
} elsif ($qname eq "direct.example.net" ) {
|
||||
if ($qtype eq "A") {
|
||||
my ($ttl, $rdata) = (3600, $localaddr);
|
||||
my $rr = new Net::DNS::RR("$qname $ttl $qclass $qtype $rdata");
|
||||
push @ans, $rr;
|
||||
}
|
||||
$rcode = "NOERROR";
|
||||
} elsif( $qname =~ /^ns1\.(\d+)\.example\.net$/ ) {
|
||||
my $next = ($1 + 1) * 16;
|
||||
for (my $i = 1; $i < 16; $i++) {
|
||||
my $s = $next + $i;
|
||||
my $rr = new Net::DNS::RR("$1.example.net 86400 $qclass NS ns1.$s.example.net");
|
||||
push @auth, $rr;
|
||||
$rr = new Net::DNS::RR("ns1.$s.example.net 86400 $qclass A 10.53.0.7");
|
||||
push @add, $rr;
|
||||
}
|
||||
$rcode = "NOERROR";
|
||||
} else {
|
||||
$rcode = "NXDOMAIN";
|
||||
}
|
||||
|
||||
# mark the answer as authoritive (by setting the 'aa' flag
|
||||
return ($rcode, \@ans, \@auth, \@add, { aa => 1 });
|
||||
}
|
||||
|
||||
GetOptions(
|
||||
'port=i' => \$localport,
|
||||
'verbose!' => \$verbose,
|
||||
);
|
||||
|
||||
my $ns = Net::DNS::Nameserver->new(
|
||||
LocalAddr => $localaddr,
|
||||
LocalPort => $localport,
|
||||
ReplyHandler => \&reply_handler,
|
||||
Verbose => $verbose,
|
||||
);
|
||||
|
||||
$ns->main_loop;
|
||||
@@ -1,4 +1,4 @@
|
||||
; Copyright (C) 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
; Copyright (C) 2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -11,4 +11,4 @@ ns.tld1. 60 IN A 10.53.0.1
|
||||
example.org. 60 IN NS direct.example.org.
|
||||
direct.example.org. 60 IN A 10.53.0.2
|
||||
example.net. 60 IN NS direct.example.net.
|
||||
direct.example.net. 60 IN A 10.53.0.4
|
||||
direct.example.net. 60 IN A 10.53.0.2
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2015, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2015-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -9,6 +9,20 @@
|
||||
SYSTEMTESTTOP=..
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
|
||||
if $PERL -e 'use Net::DNS;' 2>/dev/null
|
||||
then
|
||||
if $PERL -e 'use Net::DNS; die if ($Net::DNS::VERSION <= 0.78);' 2>/dev/null
|
||||
then
|
||||
:
|
||||
else
|
||||
echo "I:Net::DNS versions up to 0.78 have a bug that causes this test to fail: please update." >&2
|
||||
exit 1
|
||||
fi
|
||||
else
|
||||
echo "I:This test requires the Net::DNS library." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if $PERL -e 'use Net::DNS::Nameserver;' 2>/dev/null
|
||||
then
|
||||
:
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -14,101 +14,107 @@ DIGOPTS="-p 5300"
|
||||
status=0
|
||||
n=0
|
||||
|
||||
ns3_reset() {
|
||||
cp $1 ns3/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 reconfig 2>&1 | sed 's/^/I:ns3 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush | sed 's/^/I: ns3 /'
|
||||
}
|
||||
|
||||
ns3_sends_aaaa_queries() {
|
||||
if grep "started AAAA fetch" ns3/named.run >/dev/null; then
|
||||
return 0
|
||||
else
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# Check whether the number of queries ans2 received from ns3 (this value is
|
||||
# read from dig output stored in file $1) is as expected. The expected query
|
||||
# count is variable:
|
||||
# - if ns3 sends AAAA queries, the query count should equal $2,
|
||||
# - if ns3 does not send AAAA queries, the query count should equal $3.
|
||||
check_query_count() {
|
||||
count=`sed 's/[^0-9]//g;' $1`
|
||||
expected_count_with_aaaa=$2
|
||||
expected_count_without_aaaa=$3
|
||||
|
||||
if ns3_sends_aaaa_queries; then
|
||||
expected_count=$expected_count_with_aaaa
|
||||
else
|
||||
expected_count=$expected_count_without_aaaa
|
||||
fi
|
||||
|
||||
if [ $count -ne $expected_count ]; then
|
||||
echo "I: count ($count) != $expected_count"
|
||||
ret=1
|
||||
fi
|
||||
}
|
||||
|
||||
echo "I: set max-recursion-depth=12"
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt excessive-depth lookup ($n)"
|
||||
echo "I: attempt excessive-depth lookup ($n)"
|
||||
ret=0
|
||||
echo "1000" > ans2/ans.limit
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect1.example.org > dig.out.1.test$n || ret=1
|
||||
grep "status: SERVFAIL" dig.out.1.test$n > /dev/null || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
eval count=`cat dig.out.2.test$n`
|
||||
if [ "$TESTSOCK6" != "false" ]
|
||||
then
|
||||
[ $count -eq 26 ] || { ret=1; echo "I: count ($count) != 26"; }
|
||||
else
|
||||
[ $count -eq 14 ] || { ret=1; echo "I: count ($count) != 14"; }
|
||||
fi
|
||||
check_query_count dig.out.2.test$n 26 14
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
ret=0
|
||||
sleep 2
|
||||
echo "12" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named1.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect2.example.org > dig.out.1.test$n || ret=1
|
||||
grep "status: NOERROR" dig.out.1.test$n > /dev/null || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
eval count=`cat dig.out.2.test$n`
|
||||
if [ "$TESTSOCK6" != "false" ]
|
||||
then
|
||||
[ $count -eq 49 ] || { ret=1; echo "I: count ($count) != 49"; }
|
||||
else
|
||||
[ $count -eq 26 ] || { ret=1; echo "I: count ($count) != 26"; }
|
||||
fi
|
||||
check_query_count dig.out.2.test$n 49 26
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:reset max-recursion-depth"
|
||||
cp ns3/named2.conf ns3/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||
sleep 2
|
||||
echo "I: set max-recursion-depth=5"
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt excessive-depth lookup ($n)"
|
||||
echo "I: attempt excessive-depth lookup ($n)"
|
||||
ret=0
|
||||
echo "12" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named2.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect3.example.org > dig.out.1.test$n || ret=1
|
||||
grep "status: SERVFAIL" dig.out.1.test$n > /dev/null || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
eval count=`cat dig.out.2.test$n`
|
||||
if [ "$TESTSOCK6" != "false" ]
|
||||
then
|
||||
[ $count -eq 12 ] || { ret=1; echo "I: count ($count) != 12"; }
|
||||
else
|
||||
[ $count -eq 7 ] || { ret=1; echo "I: count ($count) != 7"; }
|
||||
fi
|
||||
check_query_count dig.out.2.test$n 12 7
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
ret=0
|
||||
echo "5" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named2.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect4.example.org > dig.out.1.test$n || ret=1
|
||||
grep "status: NOERROR" dig.out.1.test$n > /dev/null || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
eval count=`cat dig.out.2.test$n`
|
||||
if [ "$TESTSOCK6" != "false" ]
|
||||
then
|
||||
[ $count -eq 21 ] || { ret=1; echo "I: count ($count) != 21"; }
|
||||
else
|
||||
[ $count -eq 12 ] || { ret=1; echo "I: count ($count) != 12"; }
|
||||
fi
|
||||
check_query_count dig.out.2.test$n 21 12
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:reset max-recursion-depth"
|
||||
cp ns3/named3.conf ns3/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||
sleep 2
|
||||
echo "I: set max-recursion-depth=100, max-recursion-queries=50"
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt excessive-queries lookup ($n)"
|
||||
echo "I: attempt excessive-queries lookup ($n)"
|
||||
ret=0
|
||||
echo "13" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named3.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect5.example.org > dig.out.1.test$n || ret=1
|
||||
if [ "$TESTSOCK6" != "false" ]
|
||||
then
|
||||
if ns3_sends_aaaa_queries; then
|
||||
grep "status: SERVFAIL" dig.out.1.test$n > /dev/null || ret=1
|
||||
fi
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
@@ -118,10 +124,10 @@ if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
ret=0
|
||||
echo "12" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named3.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect6.example.org > dig.out.1.test$n || ret=1
|
||||
grep "status: NOERROR" dig.out.1.test$n > /dev/null || ret=1
|
||||
@@ -131,20 +137,16 @@ eval count=`cat dig.out.2.test$n`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:reset max-recursion-queries"
|
||||
cp ns3/named4.conf ns3/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||
sleep 2
|
||||
echo "I: set max-recursion-depth=100, max-recursion-queries=40"
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt excessive-queries lookup ($n)"
|
||||
echo "I: attempt excessive-queries lookup ($n)"
|
||||
ret=0
|
||||
echo "10" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named4.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect7.example.org > dig.out.1.test$n || ret=1
|
||||
if [ "$TESTSOCK6" != "false" ]
|
||||
then
|
||||
if ns3_sends_aaaa_queries; then
|
||||
grep "status: SERVFAIL" dig.out.1.test$n > /dev/null || ret=1
|
||||
fi
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
@@ -154,10 +156,10 @@ if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
ret=0
|
||||
echo "9" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named4.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect8.example.org > dig.out.1.test$n || ret=1
|
||||
grep "status: NOERROR" dig.out.1.test$n > /dev/null || ret=1
|
||||
@@ -170,10 +172,10 @@ status=`expr $status + $ret`
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempting NS explosion ($n)"
|
||||
ret=0
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named4.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.3 ns1.1.example.net > dig.out.1.test$n || ret=1
|
||||
sleep 2
|
||||
$DIG $DIGOPTS +short @10.53.0.4 count txt > dig.out.2.test$n || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
eval count=`cat dig.out.2.test$n`
|
||||
[ $count -lt 50 ] || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.7 count txt > dig.out.3.test$n || ret=1
|
||||
|
||||
@@ -16,6 +16,8 @@
|
||||
#include <stdlib.h>
|
||||
#include <lmdb.h>
|
||||
|
||||
#include <dns/view.h>
|
||||
|
||||
#include <isc/print.h>
|
||||
|
||||
int
|
||||
@@ -36,42 +38,43 @@ main (int argc, char *argv[]) {
|
||||
path = argv[1];
|
||||
|
||||
status = mdb_env_create(&env);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
fprintf(stderr, "named-nzd2nzf: mdb_env_create: %s",
|
||||
mdb_strerror(status));
|
||||
exit(1);
|
||||
}
|
||||
|
||||
status = mdb_env_open(env, path,
|
||||
MDB_RDONLY|MDB_NOTLS|MDB_NOSUBDIR, 0600);
|
||||
if (status != 0) {
|
||||
status = mdb_env_open(env, path, DNS_LMDB_FLAGS, 0600);
|
||||
if (status != MDB_SUCCESS) {
|
||||
fprintf(stderr, "named-nzd2nzf: mdb_env_open: %s",
|
||||
mdb_strerror(status));
|
||||
exit(1);
|
||||
}
|
||||
|
||||
status = mdb_txn_begin(env, 0, MDB_RDONLY, &txn);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
fprintf(stderr, "named-nzd2nzf: mdb_txn_begin: %s",
|
||||
mdb_strerror(status));
|
||||
exit(1);
|
||||
}
|
||||
|
||||
status = mdb_dbi_open(txn, NULL, 0, &dbi);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
fprintf(stderr, "named-nzd2nzf: mdb_dbi_open: %s",
|
||||
mdb_strerror(status));
|
||||
exit(1);
|
||||
}
|
||||
|
||||
status = mdb_cursor_open(txn, dbi, &cursor);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
fprintf(stderr, "named-nzd2nzf: mdb_cursor_open: %s",
|
||||
mdb_strerror(status));
|
||||
exit(1);
|
||||
}
|
||||
|
||||
while (mdb_cursor_get(cursor, &key, &data, MDB_NEXT) == 0) {
|
||||
for (status = mdb_cursor_get(cursor, &key, &data, MDB_FIRST);
|
||||
status == MDB_SUCCESS;
|
||||
status = mdb_cursor_get(cursor, &key, &data, MDB_NEXT)) {
|
||||
if (key.mv_data == NULL || key.mv_size == 0 ||
|
||||
data.mv_data == NULL || data.mv_size == 0)
|
||||
{
|
||||
|
||||
@@ -22920,7 +22920,11 @@ else
|
||||
fi
|
||||
|
||||
|
||||
for ac_prog in mysql_config
|
||||
mysql_include=""
|
||||
mysql_lib=""
|
||||
if test "$use_dlz_mysql" = "yes"
|
||||
then
|
||||
for ac_prog in mysql_config
|
||||
do
|
||||
# Extract the first word of "$ac_prog", so it can be a program name with args.
|
||||
set dummy $ac_prog; ac_word=$2
|
||||
@@ -22962,11 +22966,6 @@ fi
|
||||
test -n "$MYSQL_CONFIG" && break
|
||||
done
|
||||
|
||||
|
||||
mysql_include=""
|
||||
mysql_lib=""
|
||||
if test "$use_dlz_mysql" = "yes"
|
||||
then
|
||||
if test -n "$MYSQL_CONFIG"
|
||||
then
|
||||
mysql_include=`${MYSQL_CONFIG} --include`
|
||||
|
||||
+1
-1
@@ -4821,7 +4821,7 @@ if test "yes" = "$atf"; then
|
||||
*) srcdir="../../$srcdir";;
|
||||
esac
|
||||
${SHELL} "${srcdir}${srcdir:+/unit/atf-src/}./configure" --enable-tools --disable-shared MISSING=: --prefix $atfdir;
|
||||
) ],
|
||||
) || AC_MSG_ERROR([Failed to configure ATF.]) ],
|
||||
[atfdir=`pwd`/unit/atf])
|
||||
AC_MSG_RESULT(building ATF from bind9/unit/atf-src)
|
||||
fi
|
||||
|
||||
@@ -132,12 +132,11 @@ AC_ARG_WITH(dlz_mysql,
|
||||
(Required to use MySQL with DLZ)]),
|
||||
use_dlz_mysql="$withval", use_dlz_mysql="no")
|
||||
|
||||
AC_CHECK_PROGS(MYSQL_CONFIG, mysql_config)
|
||||
|
||||
mysql_include=""
|
||||
mysql_lib=""
|
||||
if test "$use_dlz_mysql" = "yes"
|
||||
then
|
||||
AC_CHECK_PROGS(MYSQL_CONFIG, mysql_config)
|
||||
if test -n "$MYSQL_CONFIG"
|
||||
then
|
||||
mysql_include=`${MYSQL_CONFIG} --include`
|
||||
|
||||
@@ -734,14 +734,6 @@
|
||||
|
||||
<section xml:id="relnotes_bugs"><info><title>Bug Fixes</title></info>
|
||||
<itemizedlist>
|
||||
<listitem>
|
||||
<para>
|
||||
Zones created with <command>rndc addzone</command> could
|
||||
temporarily fail to inherit the <command>allow-transfer</command>
|
||||
ACL set in the <command>options</command> section of
|
||||
<filename>named.conf</filename>. [RT #46603]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
The introduction of <command>libns</command> caused a bug
|
||||
|
||||
@@ -238,6 +238,7 @@ dns_cache_create3(isc_mem_t *cmctx, isc_mem_t *hmctx, isc_taskmgr_t *taskmgr,
|
||||
cache->references = 1;
|
||||
cache->live_tasks = 0;
|
||||
cache->rdclass = rdclass;
|
||||
cache->serve_stale_ttl = 0;
|
||||
|
||||
cache->stats = NULL;
|
||||
result = isc_stats_create(cmctx, &cache->stats,
|
||||
|
||||
@@ -15,6 +15,7 @@
|
||||
#include <isc/mem.h>
|
||||
#include <isc/stdlib.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/util.h>
|
||||
|
||||
#include <dns/db.h>
|
||||
#define LIBRPZ_LIB_OPEN DNSRPS_LIB_OPEN
|
||||
|
||||
@@ -237,6 +237,25 @@ struct dns_view {
|
||||
#define DNS_VIEWATTR_ADBSHUTDOWN 0x02
|
||||
#define DNS_VIEWATTR_REQSHUTDOWN 0x04
|
||||
|
||||
#ifdef HAVE_LMDB
|
||||
#include <lmdb.h>
|
||||
/*
|
||||
* MDB_NOTLS is used to prevent problems after configuration is reloaded, due
|
||||
* to the way LMDB's use of thread-local storage (TLS) interacts with the BIND9
|
||||
* thread model.
|
||||
*/
|
||||
#define DNS_LMDB_COMMON_FLAGS (MDB_CREATE | MDB_NOSUBDIR | MDB_NOTLS)
|
||||
#ifndef __OpenBSD__
|
||||
#define DNS_LMDB_FLAGS (DNS_LMDB_COMMON_FLAGS)
|
||||
#else /* __OpenBSD__ */
|
||||
/*
|
||||
* OpenBSD does not have a unified buffer cache, which requires both reads and
|
||||
* writes to be performed using mmap().
|
||||
*/
|
||||
#define DNS_LMDB_FLAGS (DNS_LMDB_COMMON_FLAGS | MDB_WRITEMAP)
|
||||
#endif /* __OpenBSD__ */
|
||||
#endif /* HAVE_LMDB */
|
||||
|
||||
isc_result_t
|
||||
dns_view_create(isc_mem_t *mctx, dns_rdataclass_t rdclass,
|
||||
const char *name, dns_view_t **viewp);
|
||||
|
||||
+182
-106
@@ -149,7 +149,10 @@ typedef isc_uint64_t rbtdb_serial_t;
|
||||
#define add_changed add_changed64
|
||||
#define add_empty_wildcards add_empty_wildcards64
|
||||
#define add_wildcard_magic add_wildcard_magic64
|
||||
#define addclosest addclosest64
|
||||
#define addnoqname addnoqname64
|
||||
#define addrdataset addrdataset64
|
||||
#define adjust_quantum adjust_quantum64
|
||||
#define allocate_version allocate_tversion64
|
||||
#define allrdatasets allrdatasets64
|
||||
#define attach attach64
|
||||
@@ -162,9 +165,14 @@ typedef isc_uint64_t rbtdb_serial_t;
|
||||
#define cache_findzonecut cache_findzonecut64
|
||||
#define cache_zonecut_callback cache_zonecut_callback64
|
||||
#define check_stale_header check_stale_header64
|
||||
#define clean_cache_node clean_cache_node64
|
||||
#define clean_stale_headers clean_stale_headers64
|
||||
#define clean_zone_node clean_zone_node64
|
||||
#define cleanup_dead_nodes cleanup_dead_nodes64
|
||||
#define cleanup_dead_nodes_callback cleanup_dead_nodes_callback64
|
||||
#define cleanup_nondirty cleanup_nondirty64
|
||||
#define closeversion closeversion64
|
||||
#define cname_and_other_data cname_and_other_data64
|
||||
#define createiterator createiterator64
|
||||
#define currentversion currentversion64
|
||||
#define dbiterator_current dbiterator_current64
|
||||
@@ -177,9 +185,11 @@ typedef isc_uint64_t rbtdb_serial_t;
|
||||
#define dbiterator_prev dbiterator_prev64
|
||||
#define dbiterator_seek dbiterator_seek64
|
||||
#define decrement_reference decrement_reference64
|
||||
#define delegating_type delegating_type64
|
||||
#define delete_callback delete_callback64
|
||||
#define delete_node delete_node64
|
||||
#define deleterdataset deleterdataset64
|
||||
#define dereference_iter_node dereference_iter_node64
|
||||
#define deserialize32 deserialize64
|
||||
#define detach detach64
|
||||
#define detachnode detachnode64
|
||||
@@ -190,6 +200,7 @@ typedef isc_uint64_t rbtdb_serial_t;
|
||||
#define find_closest_nsec find_closest_nsec64
|
||||
#define find_coveringnsec find_coveringnsec64
|
||||
#define find_deepest_zonecut find_deepest_zonecut64
|
||||
#define find_wildcard find_wildcard64
|
||||
#define findnode findnode64
|
||||
#define findnodeintree findnodeintree64
|
||||
#define findnsec3node findnsec3node64
|
||||
@@ -209,26 +220,33 @@ typedef isc_uint64_t rbtdb_serial_t;
|
||||
#define glue_nsdname_cb glue_nsdname_cb64
|
||||
#define hashsize hashsize64
|
||||
#define init_file_version init_file_version64
|
||||
#define init_rdataset init_rdataset64
|
||||
#define isdnssec isdnssec64
|
||||
#define ispersistent ispersistent64
|
||||
#define issecure issecure64
|
||||
#define iszonesecure iszonesecure64
|
||||
#define loading_addrdataset loading_addrdataset64
|
||||
#define loadnode loadnode64
|
||||
#define make_least_version make_least_version64
|
||||
#define mark_header_ancient mark_header_ancient64
|
||||
#define mark_stale_header mark_stale_header64
|
||||
#define match_header_version match_header_version64
|
||||
#define matchparams matchparams64
|
||||
#define maybe_free_rbtdb maybe_free_rbtdb64
|
||||
#define need_headerupdate need_headerupdate64
|
||||
#define new_rdataset new_rdataset64
|
||||
#define new_reference new_reference64
|
||||
#define newversion newversion64
|
||||
#define nodecount nodecount64
|
||||
#define nodefullname nodefullname64
|
||||
#define overmem overmem64
|
||||
#define overmem_purge overmem_purge64
|
||||
#define previous_closest_nsec previous_closest_nsec64
|
||||
#define printnode printnode64
|
||||
#define prune_tree prune_tree64
|
||||
#define rbt_datafixer rbt_datafixer64
|
||||
#define rbt_datawriter rbt_datawriter64
|
||||
#define rbtdb_write_header rbtdb_write_header64
|
||||
#define rbtdb_zero_header rbtdb_zero_header64
|
||||
#define rdataset_addglue rdataset_addglue64
|
||||
#define rdataset_clearprefetch rdataset_clearprefetch64
|
||||
@@ -249,15 +267,20 @@ typedef isc_uint64_t rbtdb_serial_t;
|
||||
#define rdatasetiter_first rdatasetiter_first64
|
||||
#define rdatasetiter_next rdatasetiter_next64
|
||||
#define reactivate_node reactivate_node64
|
||||
#define reference_iter_node reference_iter_node64
|
||||
#define rehash_gluetable rehash_gluetable64
|
||||
#define resign_delete resign_delete64
|
||||
#define resign_insert resign_insert64
|
||||
#define resign_sooner resign_sooner64
|
||||
#define resigned resigned64
|
||||
#define resume_iteration resume_iteration64
|
||||
#define rollback_node rollback_node64
|
||||
#define serialize serialize64
|
||||
#define set_index set_index64
|
||||
#define set_ttl set_ttl64
|
||||
#define setcachestats setcachestats64
|
||||
#define setgluecachestats setgluecachestats64
|
||||
#define setnsec3parameters setnsec3parameters64
|
||||
#define setownercase setownercase64
|
||||
#define setservestalettl setservestalettl64
|
||||
#define setsigningtime setsigningtime64
|
||||
@@ -268,7 +291,9 @@ typedef isc_uint64_t rbtdb_serial_t;
|
||||
#define update_cachestats update_cachestats64
|
||||
#define update_header update_header64
|
||||
#define update_newheader update_newheader64
|
||||
#define update_recordsandbytes update_recordsandbytes64
|
||||
#define update_rrsetstats update_rrsetstats64
|
||||
#define valid_glue valid_glue64
|
||||
#define zone_find zone_find64
|
||||
#define zone_findrdataset zone_findrdataset64
|
||||
#define zone_findzonecut zone_findzonecut64
|
||||
@@ -6100,6 +6125,22 @@ resign_delete(dns_rbtdb_t *rbtdb, rbtdb_version_t *version,
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
update_recordsandbytes(isc_boolean_t add, rbtdb_version_t *rbtversion,
|
||||
rdatasetheader_t *header)
|
||||
{
|
||||
unsigned char *hdr = (unsigned char *)header;
|
||||
size_t hdrsize = sizeof (*header);
|
||||
|
||||
if (add) {
|
||||
rbtversion->records += dns_rdataslab_count(hdr, hdrsize);
|
||||
rbtversion->bytes += dns_rdataslab_size(hdr, hdrsize);
|
||||
} else {
|
||||
rbtversion->records -= dns_rdataslab_count(hdr, hdrsize);
|
||||
rbtversion->bytes -= dns_rdataslab_size(hdr, hdrsize);
|
||||
}
|
||||
}
|
||||
|
||||
static isc_result_t
|
||||
add32(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, rbtdb_version_t *rbtversion,
|
||||
rdatasetheader_t *newheader, unsigned int options, isc_boolean_t loading,
|
||||
@@ -6438,41 +6479,8 @@ add32(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, rbtdb_version_t *rbtversion,
|
||||
}
|
||||
INSIST(rbtversion == NULL ||
|
||||
rbtversion->serial >= topheader->serial);
|
||||
if (topheader_prev != NULL)
|
||||
topheader_prev->next = newheader;
|
||||
else
|
||||
rbtnode->data = newheader;
|
||||
newheader->next = topheader->next;
|
||||
if (rbtversion != NULL)
|
||||
RWLOCK(&rbtversion->rwlock, isc_rwlocktype_write);
|
||||
if (rbtversion != NULL && !header_nx) {
|
||||
rbtversion->records -=
|
||||
dns_rdataslab_count((unsigned char *)header,
|
||||
sizeof(*header));
|
||||
rbtversion->bytes -=
|
||||
dns_rdataslab_size((unsigned char *)header,
|
||||
sizeof(*header));
|
||||
}
|
||||
if (rbtversion != NULL && !newheader_nx) {
|
||||
rbtversion->records +=
|
||||
dns_rdataslab_count((unsigned char *)newheader,
|
||||
sizeof(*newheader));
|
||||
rbtversion->bytes +=
|
||||
dns_rdataslab_size((unsigned char *)newheader,
|
||||
sizeof(*newheader));
|
||||
}
|
||||
if (rbtversion != NULL)
|
||||
RWUNLOCK(&rbtversion->rwlock, isc_rwlocktype_write);
|
||||
if (loading) {
|
||||
/*
|
||||
* There are no other references to 'header' when
|
||||
* loading, so we MAY clean up 'header' now.
|
||||
* Since we don't generate changed records when
|
||||
* loading, we MUST clean up 'header' now.
|
||||
*/
|
||||
newheader->down = NULL;
|
||||
free_rdataset(rbtdb, rbtdb->common.mctx, header);
|
||||
|
||||
idx = newheader->node->locknum;
|
||||
if (IS_CACHE(rbtdb)) {
|
||||
if (ZEROTTL(newheader))
|
||||
@@ -6482,14 +6490,82 @@ add32(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, rbtdb_version_t *rbtversion,
|
||||
ISC_LIST_PREPEND(rbtdb->rdatasets[idx],
|
||||
newheader, link);
|
||||
INSIST(rbtdb->heaps != NULL);
|
||||
(void)isc_heap_insert(rbtdb->heaps[idx],
|
||||
result = isc_heap_insert(rbtdb->heaps[idx],
|
||||
newheader);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
free_rdataset(rbtdb,
|
||||
rbtdb->common.mctx,
|
||||
newheader);
|
||||
return (result);
|
||||
}
|
||||
} else if (RESIGN(newheader)) {
|
||||
result = resign_insert(rbtdb, idx, newheader);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
free_rdataset(rbtdb,
|
||||
rbtdb->common.mctx,
|
||||
newheader);
|
||||
return (result);
|
||||
}
|
||||
/*
|
||||
* Don't call resign_delete as we don't need
|
||||
* to reverse the delete. The free_rdataset
|
||||
* call below will clean up the heap entry.
|
||||
*/
|
||||
}
|
||||
|
||||
/*
|
||||
* There are no other references to 'header' when
|
||||
* loading, so we MAY clean up 'header' now.
|
||||
* Since we don't generate changed records when
|
||||
* loading, we MUST clean up 'header' now.
|
||||
*/
|
||||
if (topheader_prev != NULL)
|
||||
topheader_prev->next = newheader;
|
||||
else
|
||||
rbtnode->data = newheader;
|
||||
newheader->next = topheader->next;
|
||||
if (rbtversion != NULL && !header_nx) {
|
||||
RWLOCK(&rbtversion->rwlock,
|
||||
isc_rwlocktype_write);
|
||||
update_recordsandbytes(ISC_FALSE, rbtversion,
|
||||
header);
|
||||
RWUNLOCK(&rbtversion->rwlock,
|
||||
isc_rwlocktype_write);
|
||||
}
|
||||
free_rdataset(rbtdb, rbtdb->common.mctx, header);
|
||||
} else {
|
||||
idx = newheader->node->locknum;
|
||||
if (IS_CACHE(rbtdb)) {
|
||||
INSIST(rbtdb->heaps != NULL);
|
||||
result = isc_heap_insert(rbtdb->heaps[idx],
|
||||
newheader);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
free_rdataset(rbtdb,
|
||||
rbtdb->common.mctx,
|
||||
newheader);
|
||||
return (result);
|
||||
}
|
||||
if (ZEROTTL(newheader))
|
||||
ISC_LIST_APPEND(rbtdb->rdatasets[idx],
|
||||
newheader, link);
|
||||
else
|
||||
ISC_LIST_PREPEND(rbtdb->rdatasets[idx],
|
||||
newheader, link);
|
||||
} else if (RESIGN(newheader)) {
|
||||
result = resign_insert(rbtdb, idx, newheader);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
free_rdataset(rbtdb,
|
||||
rbtdb->common.mctx,
|
||||
newheader);
|
||||
return (result);
|
||||
}
|
||||
resign_delete(rbtdb, rbtversion, header);
|
||||
}
|
||||
if (topheader_prev != NULL)
|
||||
topheader_prev->next = newheader;
|
||||
else
|
||||
rbtnode->data = newheader;
|
||||
newheader->next = topheader->next;
|
||||
newheader->down = topheader;
|
||||
topheader->next = newheader;
|
||||
rbtnode->dirty = 1;
|
||||
@@ -6503,29 +6579,13 @@ add32(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, rbtdb_version_t *rbtversion,
|
||||
mark_header_ancient(rbtdb, sigheader);
|
||||
}
|
||||
}
|
||||
idx = newheader->node->locknum;
|
||||
if (IS_CACHE(rbtdb)) {
|
||||
if (ZEROTTL(newheader))
|
||||
ISC_LIST_APPEND(rbtdb->rdatasets[idx],
|
||||
newheader, link);
|
||||
else
|
||||
ISC_LIST_PREPEND(rbtdb->rdatasets[idx],
|
||||
newheader, link);
|
||||
/*
|
||||
* XXXMLG We don't check the return value
|
||||
* here. If it fails, we will not do TTL
|
||||
* based expiry on this node. However, we
|
||||
* will do it on the LRU side, so memory
|
||||
* will not leak... for long.
|
||||
*/
|
||||
INSIST(rbtdb->heaps != NULL);
|
||||
(void)isc_heap_insert(rbtdb->heaps[idx],
|
||||
newheader);
|
||||
} else if (RESIGN(newheader)) {
|
||||
resign_delete(rbtdb, rbtversion, header);
|
||||
result = resign_insert(rbtdb, idx, newheader);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
return (result);
|
||||
if (rbtversion != NULL && !header_nx) {
|
||||
RWLOCK(&rbtversion->rwlock,
|
||||
isc_rwlocktype_write);
|
||||
update_recordsandbytes(ISC_FALSE, rbtversion,
|
||||
header);
|
||||
RWUNLOCK(&rbtversion->rwlock,
|
||||
isc_rwlocktype_write);
|
||||
}
|
||||
}
|
||||
} else {
|
||||
@@ -6542,6 +6602,30 @@ add32(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, rbtdb_version_t *rbtversion,
|
||||
return (DNS_R_UNCHANGED);
|
||||
}
|
||||
|
||||
idx = newheader->node->locknum;
|
||||
if (IS_CACHE(rbtdb)) {
|
||||
result = isc_heap_insert(rbtdb->heaps[idx], newheader);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
free_rdataset(rbtdb, rbtdb->common.mctx,
|
||||
newheader);
|
||||
return (result);
|
||||
}
|
||||
if (ZEROTTL(newheader))
|
||||
ISC_LIST_APPEND(rbtdb->rdatasets[idx],
|
||||
newheader, link);
|
||||
else
|
||||
ISC_LIST_PREPEND(rbtdb->rdatasets[idx],
|
||||
newheader, link);
|
||||
} else if (RESIGN(newheader)) {
|
||||
result = resign_insert(rbtdb, idx, newheader);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
free_rdataset(rbtdb, rbtdb->common.mctx,
|
||||
newheader);
|
||||
return (result);
|
||||
}
|
||||
resign_delete(rbtdb, rbtversion, header);
|
||||
}
|
||||
|
||||
if (topheader != NULL) {
|
||||
/*
|
||||
* We have an list of rdatasets of the given type,
|
||||
@@ -6572,31 +6656,12 @@ add32(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, rbtdb_version_t *rbtversion,
|
||||
newheader->down = NULL;
|
||||
rbtnode->data = newheader;
|
||||
}
|
||||
if (rbtversion != NULL && !newheader_nx) {
|
||||
RWLOCK(&rbtversion->rwlock, isc_rwlocktype_write);
|
||||
rbtversion->records +=
|
||||
dns_rdataslab_count((unsigned char *)newheader,
|
||||
sizeof(*newheader));
|
||||
rbtversion->bytes +=
|
||||
dns_rdataslab_size((unsigned char *)newheader,
|
||||
sizeof(*newheader));
|
||||
RWUNLOCK(&rbtversion->rwlock, isc_rwlocktype_write);
|
||||
}
|
||||
idx = newheader->node->locknum;
|
||||
if (IS_CACHE(rbtdb)) {
|
||||
if (ZEROTTL(newheader))
|
||||
ISC_LIST_APPEND(rbtdb->rdatasets[idx],
|
||||
newheader, link);
|
||||
else
|
||||
ISC_LIST_PREPEND(rbtdb->rdatasets[idx],
|
||||
newheader, link);
|
||||
isc_heap_insert(rbtdb->heaps[idx], newheader);
|
||||
} else if (RESIGN(newheader)) {
|
||||
resign_delete(rbtdb, rbtversion, header);
|
||||
result = resign_insert(rbtdb, idx, newheader);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
return (result);
|
||||
}
|
||||
}
|
||||
|
||||
if (rbtversion != NULL && !newheader_nx) {
|
||||
RWLOCK(&rbtversion->rwlock, isc_rwlocktype_write);
|
||||
update_recordsandbytes(ISC_TRUE, rbtversion, newheader);
|
||||
RWUNLOCK(&rbtversion->rwlock, isc_rwlocktype_write);
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -7041,6 +7106,19 @@ subtractrdataset(dns_db_t *db, dns_dbnode_t *node, dns_dbversion_t *version,
|
||||
newheader = (rdatasetheader_t *)subresult;
|
||||
init_rdataset(rbtdb, newheader);
|
||||
update_newheader(newheader, header);
|
||||
if (RESIGN(header)) {
|
||||
newheader->attributes |= RDATASET_ATTR_RESIGN;
|
||||
newheader->resign = header->resign;
|
||||
newheader->resign_lsb = header->resign_lsb;
|
||||
result = resign_insert(rbtdb, rbtnode->locknum,
|
||||
newheader);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
free_rdataset(rbtdb,
|
||||
rbtdb->common.mctx,
|
||||
newheader);
|
||||
goto unlock;
|
||||
}
|
||||
}
|
||||
/*
|
||||
* We have to set the serial since the rdataslab
|
||||
* subtraction routine copies the reserved portion of
|
||||
@@ -7052,12 +7130,7 @@ subtractrdataset(dns_db_t *db, dns_dbnode_t *node, dns_dbversion_t *version,
|
||||
* to additional info. We need to clear these fields
|
||||
* to avoid having duplicated references.
|
||||
*/
|
||||
rbtversion->records +=
|
||||
dns_rdataslab_count((unsigned char *)newheader,
|
||||
sizeof(*newheader));
|
||||
rbtversion->bytes +=
|
||||
dns_rdataslab_size((unsigned char *)newheader,
|
||||
sizeof(*newheader));
|
||||
update_recordsandbytes(ISC_TRUE, rbtversion, newheader);
|
||||
} else if (result == DNS_R_NXRRSET) {
|
||||
/*
|
||||
* This subtraction would remove all of the rdata;
|
||||
@@ -7092,12 +7165,7 @@ subtractrdataset(dns_db_t *db, dns_dbnode_t *node, dns_dbversion_t *version,
|
||||
* topheader.
|
||||
*/
|
||||
INSIST(rbtversion->serial >= topheader->serial);
|
||||
rbtversion->records -=
|
||||
dns_rdataslab_count((unsigned char *)header,
|
||||
sizeof(*header));
|
||||
rbtversion->bytes -=
|
||||
dns_rdataslab_size((unsigned char *)header,
|
||||
sizeof(*header));
|
||||
update_recordsandbytes(ISC_FALSE, rbtversion, header);
|
||||
if (topheader_prev != NULL)
|
||||
topheader_prev->next = newheader;
|
||||
else
|
||||
@@ -8066,9 +8134,8 @@ getsize(dns_db_t *db, dns_dbversion_t *version, isc_uint64_t *records,
|
||||
static isc_result_t
|
||||
setsigningtime(dns_db_t *db, dns_rdataset_t *rdataset, isc_stdtime_t resign) {
|
||||
dns_rbtdb_t *rbtdb = (dns_rbtdb_t *)db;
|
||||
isc_stdtime_t oldresign;
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
rdatasetheader_t *header;
|
||||
rdatasetheader_t *header, oldheader;
|
||||
|
||||
REQUIRE(VALID_RBTDB(rbtdb));
|
||||
REQUIRE(!IS_CACHE(rbtdb));
|
||||
@@ -8080,22 +8147,31 @@ setsigningtime(dns_db_t *db, dns_rdataset_t *rdataset, isc_stdtime_t resign) {
|
||||
NODE_LOCK(&rbtdb->node_locks[header->node->locknum].lock,
|
||||
isc_rwlocktype_write);
|
||||
|
||||
oldresign = (header->resign << 1) | header->resign_lsb;
|
||||
header->resign = (isc_stdtime_t)(dns_time64_from32(resign) >> 1);
|
||||
header->resign_lsb = resign & 0x1;
|
||||
oldheader = *header;
|
||||
/*
|
||||
* Only break the heap invariant (by adjusting resign and resign_lsb)
|
||||
* if we are going to be restoring it by calling isc_heap_increased
|
||||
* or isc_heap_decreased.
|
||||
*/
|
||||
if (resign != 0) {
|
||||
header->resign =
|
||||
(isc_stdtime_t)(dns_time64_from32(resign) >> 1);
|
||||
header->resign_lsb = resign & 0x1;
|
||||
}
|
||||
if (header->heap_index != 0) {
|
||||
INSIST(RESIGN(header));
|
||||
if (resign == 0) {
|
||||
isc_heap_delete(rbtdb->heaps[header->node->locknum],
|
||||
header->heap_index);
|
||||
header->heap_index = 0;
|
||||
} else if (resign < oldresign)
|
||||
} else if (resign_sooner(header, &oldheader)) {
|
||||
isc_heap_increased(rbtdb->heaps[header->node->locknum],
|
||||
header->heap_index);
|
||||
else if (resign > oldresign)
|
||||
} else if (resign_sooner(&oldheader, header)) {
|
||||
isc_heap_decreased(rbtdb->heaps[header->node->locknum],
|
||||
header->heap_index);
|
||||
} else if (resign && header->heap_index == 0) {
|
||||
}
|
||||
} else if (resign != 0) {
|
||||
header->attributes |= RDATASET_ATTR_RESIGN;
|
||||
result = resign_insert(rbtdb, header->node->locknum, header);
|
||||
}
|
||||
@@ -8255,7 +8331,7 @@ setservestalettl(dns_db_t *db, dns_ttl_t ttl) {
|
||||
|
||||
/* currently no bounds checking. 0 means disable. */
|
||||
rbtdb->serve_stale_ttl = ttl;
|
||||
return ISC_R_SUCCESS;
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
static isc_result_t
|
||||
@@ -8266,7 +8342,7 @@ getservestalettl(dns_db_t *db, dns_ttl_t *ttl) {
|
||||
REQUIRE(IS_CACHE(rbtdb));
|
||||
|
||||
*ttl = rbtdb->serve_stale_ttl;
|
||||
return ISC_R_SUCCESS;
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
|
||||
@@ -9755,7 +9831,7 @@ static const unsigned char charmask[] = {
|
||||
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00
|
||||
};
|
||||
|
||||
static unsigned char maptolower[] = {
|
||||
static const unsigned char maptolower[] = {
|
||||
0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07,
|
||||
0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f,
|
||||
0x10, 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17,
|
||||
|
||||
+2
-1
@@ -3030,8 +3030,8 @@ fctx_finddone(isc_task_t *task, isc_event_t *event) {
|
||||
* The fetch is waiting for a name to be found.
|
||||
*/
|
||||
INSIST(!SHUTTINGDOWN(fctx));
|
||||
fctx->attributes &= ~FCTX_ATTR_ADDRWAIT;
|
||||
if (event->ev_type == DNS_EVENT_ADBMOREADDRESSES) {
|
||||
fctx->attributes &= ~FCTX_ATTR_ADDRWAIT;
|
||||
want_try = ISC_TRUE;
|
||||
} else {
|
||||
fctx->findfail++;
|
||||
@@ -3041,6 +3041,7 @@ fctx_finddone(isc_task_t *task, isc_event_t *event) {
|
||||
* know the answer. There's nothing to do but
|
||||
* fail the fctx.
|
||||
*/
|
||||
fctx->attributes &= ~FCTX_ATTR_ADDRWAIT;
|
||||
want_done = ISC_TRUE;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -103,19 +103,19 @@ nsec3param_salttotext_test(const nsec3param_salttotext_test_params_t *params) {
|
||||
ATF_CHECK_EQ_MSG(result, ISC_R_NOSPACE,
|
||||
"\"%s\": expected a %lu-byte target buffer to be "
|
||||
"rejected, got %s\n",
|
||||
params->nsec3param_text, length - 1,
|
||||
params->nsec3param_text, (unsigned long)(length - 1),
|
||||
isc_result_totext(result));
|
||||
result = dns_nsec3param_salttotext(&nsec3param, salt, length);
|
||||
ATF_CHECK_EQ_MSG(result, ISC_R_NOSPACE,
|
||||
"\"%s\": expected a %lu-byte target buffer to be "
|
||||
"rejected, got %s\n",
|
||||
params->nsec3param_text, length,
|
||||
params->nsec3param_text, (unsigned long)length,
|
||||
isc_result_totext(result));
|
||||
result = dns_nsec3param_salttotext(&nsec3param, salt, length + 1);
|
||||
ATF_CHECK_EQ_MSG(result, ISC_R_SUCCESS,
|
||||
"\"%s\": expected a %lu-byte target buffer to be "
|
||||
"accepted, got %s\n",
|
||||
params->nsec3param_text, length + 1,
|
||||
params->nsec3param_text, (unsigned long)(length + 1),
|
||||
isc_result_totext(result));
|
||||
}
|
||||
|
||||
|
||||
@@ -239,7 +239,7 @@ check_wire_ok_single(const wire_ok_t *wire_ok, dns_rdataclass_t rdclass,
|
||||
wire_ok->lineno,
|
||||
dns_test_tohex(wire_ok->data, wire_ok->len,
|
||||
hex, sizeof(hex)),
|
||||
wire_ok->len);
|
||||
(unsigned long)wire_ok->len);
|
||||
} else {
|
||||
ATF_REQUIRE_MSG(result != ISC_R_SUCCESS,
|
||||
"line %d: %s (%lu): "
|
||||
@@ -247,7 +247,7 @@ check_wire_ok_single(const wire_ok_t *wire_ok, dns_rdataclass_t rdclass,
|
||||
wire_ok->lineno,
|
||||
dns_test_tohex(wire_ok->data, wire_ok->len,
|
||||
hex, sizeof(hex)),
|
||||
wire_ok->len);
|
||||
(unsigned long)wire_ok->len);
|
||||
}
|
||||
/*
|
||||
* If data was parsed correctly, perform two-way conversion checks
|
||||
|
||||
+10
-8
@@ -519,8 +519,10 @@ destroy(dns_view_t *view) {
|
||||
view->new_zone_dir = NULL;
|
||||
}
|
||||
#ifdef HAVE_LMDB
|
||||
if (view->new_zone_dbenv != NULL)
|
||||
if (view->new_zone_dbenv != NULL) {
|
||||
mdb_env_close((MDB_env *) view->new_zone_dbenv);
|
||||
view->new_zone_dbenv = NULL;
|
||||
}
|
||||
if (view->new_zone_db != NULL) {
|
||||
isc_mem_free(view->mctx, view->new_zone_db);
|
||||
view->new_zone_db = NULL;
|
||||
@@ -2102,7 +2104,7 @@ dns_view_setnewzones(dns_view_t *view, isc_boolean_t allow, void *cfgctx,
|
||||
}
|
||||
|
||||
status = mdb_env_create(&env);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
|
||||
ISC_LOGMODULE_OTHER, ISC_LOG_ERROR,
|
||||
"mdb_env_create failed: %s",
|
||||
@@ -2112,19 +2114,18 @@ dns_view_setnewzones(dns_view_t *view, isc_boolean_t allow, void *cfgctx,
|
||||
|
||||
if (mapsize != 0ULL) {
|
||||
status = mdb_env_set_mapsize(env, mapsize);
|
||||
view->new_zone_mapsize = mapsize;
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
|
||||
ISC_LOGMODULE_OTHER, ISC_LOG_ERROR,
|
||||
"mdb_env_set_mapsize failed: %s",
|
||||
mdb_strerror(status));
|
||||
CHECK(ISC_R_FAILURE);
|
||||
}
|
||||
view->new_zone_mapsize = mapsize;
|
||||
}
|
||||
|
||||
status = mdb_env_open(env, view->new_zone_db,
|
||||
MDB_NOSUBDIR|MDB_CREATE, 0600);
|
||||
if (status != 0) {
|
||||
status = mdb_env_open(env, view->new_zone_db, DNS_LMDB_FLAGS, 0600);
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
|
||||
ISC_LOGMODULE_OTHER, ISC_LOG_ERROR,
|
||||
"mdb_env_open of '%s' failed: %s",
|
||||
@@ -2151,8 +2152,9 @@ dns_view_setnewzones(dns_view_t *view, isc_boolean_t allow, void *cfgctx,
|
||||
isc_mem_free(view->mctx, view->new_zone_db);
|
||||
view->new_zone_db = NULL;
|
||||
}
|
||||
if (env != NULL)
|
||||
if (env != NULL) {
|
||||
mdb_env_close(env);
|
||||
}
|
||||
#endif /* HAVE_LMDB */
|
||||
view->new_zone_config = NULL;
|
||||
view->cfg_destroy = NULL;
|
||||
|
||||
@@ -3,6 +3,12 @@ LIBRARY libdns
|
||||
; Exported Functions
|
||||
EXPORTS
|
||||
|
||||
; test only
|
||||
dns__rbt_checkproperties
|
||||
dns__rbt_getheight
|
||||
dns__rbtnode_getdistance
|
||||
dns__zone_loadpending
|
||||
|
||||
dns_acl_allowed
|
||||
dns_acl_any
|
||||
dns_acl_attach
|
||||
|
||||
+12
-1
@@ -6533,7 +6533,7 @@ zone_resigninc(dns_zone_t *zone) {
|
||||
* we still want some clustering to occur.
|
||||
*/
|
||||
isc_random_get(&jitter);
|
||||
expire = soaexpire - jitter % 3600;
|
||||
expire = soaexpire - jitter % 3600 - 1;
|
||||
stop = now + 5;
|
||||
|
||||
check_ksk = DNS_ZONE_OPTION(zone, DNS_ZONEOPT_UPDATECHECKKSK);
|
||||
@@ -9604,6 +9604,17 @@ keyfetch_done(isc_task_t *task, isc_event_t *event) {
|
||||
|
||||
DNS_ZONE_SETFLAG(zone, DNS_ZONEFLG_LOADED);
|
||||
zone_needdump(zone, 30);
|
||||
} else if (result == ISC_R_NOMORE) {
|
||||
/*
|
||||
* If "updatekey" was true for all keys found in the DNSKEY
|
||||
* response and the previous update of those keys happened
|
||||
* during the same second (only possible if a key refresh was
|
||||
* externally triggered), it may happen that all relevant
|
||||
* update_one_rr() calls will return ISC_R_SUCCESS, but
|
||||
* diff.tuples will remain empty. Reset result to
|
||||
* ISC_R_SUCCESS to prevent a bogus warning from being logged.
|
||||
*/
|
||||
result = ISC_R_SUCCESS;
|
||||
}
|
||||
|
||||
failure:
|
||||
|
||||
+21
-1
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 1997-2001, 2004-2007, 2010-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1997-2001, 2004-2007, 2010-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -63,6 +63,18 @@ struct isc_heap {
|
||||
isc_heapindex_t index;
|
||||
};
|
||||
|
||||
#ifdef ISC_HEAP_CHECK
|
||||
static void
|
||||
heap_check(isc_heap_t *heap) {
|
||||
unsigned int i;
|
||||
for (i = 1; i <= heap->last; i++) {
|
||||
INSIST(HEAPCONDITION(i));
|
||||
}
|
||||
}
|
||||
#else
|
||||
#define heap_check(x) (void)0
|
||||
#endif
|
||||
|
||||
isc_result_t
|
||||
isc_heap_create(isc_mem_t *mctx, isc_heapcompare_t compare,
|
||||
isc_heapindex_t idx, unsigned int size_increment,
|
||||
@@ -149,6 +161,7 @@ float_up(isc_heap_t *heap, unsigned int i, void *elt) {
|
||||
(heap->index)(heap->array[i], i);
|
||||
|
||||
INSIST(HEAPCONDITION(i));
|
||||
heap_check(heap);
|
||||
}
|
||||
|
||||
static void
|
||||
@@ -174,6 +187,7 @@ sink_down(isc_heap_t *heap, unsigned int i, void *elt) {
|
||||
(heap->index)(heap->array[i], i);
|
||||
|
||||
INSIST(HEAPCONDITION(i));
|
||||
heap_check(heap);
|
||||
}
|
||||
|
||||
isc_result_t
|
||||
@@ -182,6 +196,7 @@ isc_heap_insert(isc_heap_t *heap, void *elt) {
|
||||
|
||||
REQUIRE(VALID_HEAP(heap));
|
||||
|
||||
heap_check(heap);
|
||||
new_last = heap->last + 1;
|
||||
RUNTIME_CHECK(new_last > 0); /* overflow check */
|
||||
if (new_last >= heap->size && !resize(heap))
|
||||
@@ -201,9 +216,13 @@ isc_heap_delete(isc_heap_t *heap, unsigned int idx) {
|
||||
REQUIRE(VALID_HEAP(heap));
|
||||
REQUIRE(idx >= 1 && idx <= heap->last);
|
||||
|
||||
heap_check(heap);
|
||||
if (heap->index != NULL)
|
||||
(heap->index)(heap->array[idx], 0);
|
||||
if (idx == heap->last) {
|
||||
heap->array[heap->last] = NULL;
|
||||
heap->last--;
|
||||
heap_check(heap);
|
||||
} else {
|
||||
elt = heap->array[heap->last];
|
||||
heap->array[heap->last] = NULL;
|
||||
@@ -239,6 +258,7 @@ isc_heap_element(isc_heap_t *heap, unsigned int idx) {
|
||||
REQUIRE(VALID_HEAP(heap));
|
||||
REQUIRE(idx >= 1);
|
||||
|
||||
heap_check(heap);
|
||||
if (idx <= heap->last)
|
||||
return (heap->array[idx]);
|
||||
return (NULL);
|
||||
|
||||
@@ -925,13 +925,13 @@ ISC_LANG_ENDDECLS
|
||||
do { \
|
||||
unsigned int _length; \
|
||||
unsigned char *_cp; \
|
||||
_length = strlen(_source); \
|
||||
_length = (unsigned int)strlen(_source); \
|
||||
if (ISC_UNLIKELY((_b)->autore)) { \
|
||||
isc_buffer_t *_tmp = _b; \
|
||||
ISC_REQUIRE(isc_buffer_reserve(&_tmp, _length) \
|
||||
== ISC_R_SUCCESS); \
|
||||
} \
|
||||
ISC_REQUIRE(isc_buffer_availablelength(_b) >= (unsigned int) _length); \
|
||||
ISC_REQUIRE(isc_buffer_availablelength(_b) >= _length); \
|
||||
_cp = isc_buffer_used(_b); \
|
||||
memmove(_cp, (_source), _length); \
|
||||
(_b)->used += (_length); \
|
||||
|
||||
@@ -730,10 +730,9 @@ isc__mem_register(void);
|
||||
* usually do not have to care about this function: it would call
|
||||
* isc_lib_register(), which internally calls this function.
|
||||
*/
|
||||
|
||||
void
|
||||
isc__mem_printactive(isc_mem_t *mctx, FILE *file);
|
||||
void
|
||||
isc__mem_printallactive(FILE *file);
|
||||
/*%<
|
||||
* For internal use by the isc module and its unit tests, these functions
|
||||
* print lists of active memory blocks for a single memory context or for
|
||||
|
||||
@@ -305,8 +305,6 @@ unsigned int
|
||||
isc__mempool_getfillcount(isc_mempool_t *mpctx);
|
||||
void
|
||||
isc__mem_printactive(isc_mem_t *ctx0, FILE *file);
|
||||
void
|
||||
isc__mem_printallactive(FILE *file);
|
||||
unsigned int
|
||||
isc__mem_references(isc_mem_t *ctx0);
|
||||
|
||||
|
||||
@@ -8,6 +8,7 @@ tp: counter_test
|
||||
tp: errno_test
|
||||
tp: file_test
|
||||
tp: hash_test
|
||||
tp: heap_test
|
||||
tp: ht_test
|
||||
tp: inet_ntop_test
|
||||
tp: lex_test
|
||||
|
||||
+16
-11
@@ -26,21 +26,22 @@ LIBS = @LIBS@ @ATFLIBS@
|
||||
|
||||
OBJS = isctest.@O@
|
||||
SRCS = isctest.c aes_test.c buffer_test.c counter_test.c \
|
||||
errno_test.c file_test.c hash_test.c ht_test.c \
|
||||
inet_ntop_test.c lex_test.c mem_test.c netaddr_test.c \
|
||||
parse_test.c pool_test.c print_test.c queue_test.c \
|
||||
radix_test.c random_test.c regex_test.c result_test.c \
|
||||
safe_test.c sockaddr_test.c socket_test.c socket_test.c \
|
||||
symtab_test.c task_test.c taskpool_test.c time_test.c
|
||||
errno_test.c file_test.c hash_test.c heap_test.c \
|
||||
ht_test.c inet_ntop_test.c lex_test.c mem_test.c \
|
||||
netaddr_test.c parse_test.c pool_test.c print_test.c \
|
||||
queue_test.c radix_test.c random_test.c regex_test.c \
|
||||
result_test.c safe_test.c sockaddr_test.c \
|
||||
socket_test.c socket_test.c symtab_test.c task_test.c \
|
||||
taskpool_test.c time_test.c
|
||||
|
||||
SUBDIRS =
|
||||
TARGETS = aes_test@EXEEXT@ buffer_test@EXEEXT@ counter_test@EXEEXT@ \
|
||||
errno_test@EXEEXT@ file_test@EXEEXT@ hash_test@EXEEXT@ \
|
||||
ht_test@EXEEXT@ inet_ntop_test@EXEEXT@ lex_test@EXEEXT@ \
|
||||
mem_test@EXEEXT@ netaddr_test@EXEEXT@ parse_test@EXEEXT@ \
|
||||
pool_test@EXEEXT@ print_test@EXEEXT@ queue_test@EXEEXT@ \
|
||||
radix_test@EXEEXT@ random_test@EXEEXT@ regex_test@EXEEXT@ \
|
||||
result_test@EXEEXT@ safe_test@EXEEXT@ \
|
||||
heap_test@EXEEXT@ ht_test@EXEEXT@ inet_ntop_test@EXEEXT@ \
|
||||
lex_test@EXEEXT@ mem_test@EXEEXT@ netaddr_test@EXEEXT@ \
|
||||
parse_test@EXEEXT@ pool_test@EXEEXT@ print_test@EXEEXT@ \
|
||||
queue_test@EXEEXT@ radix_test@EXEEXT@ random_test@EXEEXT@ \
|
||||
regex_test@EXEEXT@ result_test@EXEEXT@ safe_test@EXEEXT@ \
|
||||
sockaddr_test@EXEEXT@ socket_test@EXEEXT@ \
|
||||
socket_test@EXEEXT@ symtab_test@EXEEXT@ task_test@EXEEXT@ \
|
||||
taskpool_test@EXEEXT@ time_test@EXEEXT@
|
||||
@@ -71,6 +72,10 @@ hash_test@EXEEXT@: hash_test.@O@ ${ISCDEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||
hash_test.@O@ ${ISCLIBS} ${LIBS}
|
||||
|
||||
heap_test@EXEEXT@: heap_test.@O@ ${ISCDEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||
heap_test.@O@ ${ISCLIBS} ${LIBS}
|
||||
|
||||
ht_test@EXEEXT@: ht_test.@O@ ${ISCDEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||
ht_test.@O@ ${ISCLIBS} ${LIBS}
|
||||
|
||||
@@ -0,0 +1,83 @@
|
||||
/*
|
||||
* Copyright (C) 2011-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
/* ! \file */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
#include <atf-c.h>
|
||||
|
||||
#include <stdio.h>
|
||||
#include <string.h>
|
||||
|
||||
#include <isc/heap.h>
|
||||
#include <isc/mem.h>
|
||||
|
||||
#include <isc/util.h>
|
||||
|
||||
struct e {
|
||||
unsigned int value;
|
||||
unsigned int index;
|
||||
};
|
||||
|
||||
static isc_boolean_t
|
||||
compare(void *p1, void *p2) {
|
||||
struct e *e1 = p1;
|
||||
struct e *e2 = p2;
|
||||
|
||||
return (ISC_TF(e1->value < e2->value));
|
||||
}
|
||||
|
||||
static void
|
||||
idx(void *p, unsigned int i) {
|
||||
struct e *e = p;
|
||||
|
||||
e->index = i;
|
||||
}
|
||||
|
||||
ATF_TC(isc_heap_delete);
|
||||
ATF_TC_HEAD(isc_heap_delete, tc) {
|
||||
atf_tc_set_md_var(tc, "descr", "test isc_heap_delete");
|
||||
}
|
||||
ATF_TC_BODY(isc_heap_delete, tc) {
|
||||
isc_mem_t *mctx = NULL;
|
||||
isc_heap_t *heap = NULL;
|
||||
isc_result_t result;
|
||||
struct e e1 = { 100, 0 };
|
||||
|
||||
UNUSED(tc);
|
||||
|
||||
result = isc_mem_create(0, 0, &mctx);
|
||||
ATF_REQUIRE_EQ(result, ISC_R_SUCCESS);
|
||||
|
||||
result = isc_heap_create(mctx, compare, idx, 0, &heap);
|
||||
ATF_REQUIRE_EQ(result, ISC_R_SUCCESS);
|
||||
ATF_REQUIRE(heap != NULL);
|
||||
|
||||
isc_heap_insert(heap, &e1);
|
||||
ATF_REQUIRE_EQ(result, ISC_R_SUCCESS);
|
||||
ATF_REQUIRE_EQ(e1.index, 1);
|
||||
|
||||
isc_heap_delete(heap, e1.index);
|
||||
ATF_CHECK_EQ(e1.index, 0);
|
||||
|
||||
isc_heap_destroy(&heap);
|
||||
ATF_REQUIRE_EQ(heap, NULL);
|
||||
|
||||
isc_mem_detach(&mctx);
|
||||
ATF_REQUIRE_EQ(mctx, NULL);
|
||||
}
|
||||
|
||||
/*
|
||||
* Main
|
||||
*/
|
||||
ATF_TP_ADD_TCS(tp) {
|
||||
ATF_TP_ADD_TC(tp, isc_heap_delete);
|
||||
|
||||
return (atf_no_error());
|
||||
}
|
||||
@@ -1,41 +1,43 @@
|
||||
; These symbols are not needed by the WIN32 build, but build-tarballs
|
||||
; will complain if they aren't present here.
|
||||
isc__hash_setvec
|
||||
isc_socket_accept
|
||||
isc_socket_attach
|
||||
isc_socket_bind
|
||||
isc_socket_cancel
|
||||
isc_socket_cleanunix
|
||||
isc_socket_close
|
||||
isc_socket_connect
|
||||
isc_socket_create
|
||||
isc_socket_detach
|
||||
isc_socket_dscp
|
||||
isc_socket_dup
|
||||
isc_socket_fdwatchcreate
|
||||
isc_socket_fdwatchpoke
|
||||
isc_socket_create
|
||||
isc_socket_dup
|
||||
isc_socket_cancel
|
||||
isc_socket_attach
|
||||
isc_socket_detach
|
||||
isc_socket_open
|
||||
isc_socket_close
|
||||
isc_socket_bind
|
||||
isc_socket_filter
|
||||
isc_socket_listen
|
||||
isc_socket_accept
|
||||
isc_socket_connect
|
||||
isc_socket_getpeername
|
||||
isc_socket_getsockname
|
||||
isc_socket_gettype
|
||||
isc_socket_ipv6only
|
||||
isc_socket_listen
|
||||
isc_socket_open
|
||||
isc_socket_permunix
|
||||
isc_socket_recv
|
||||
isc_socket_recvv
|
||||
isc_socket_recv2
|
||||
isc_socket_recvv
|
||||
isc_socket_register
|
||||
isc_socket_send
|
||||
isc_socket_sendto
|
||||
isc_socket_sendv
|
||||
isc_socket_sendto2
|
||||
isc_socket_sendtov
|
||||
isc_socket_sendtov2
|
||||
isc_socket_sendto2
|
||||
isc_socket_sendv
|
||||
isc_socketmgr_create
|
||||
isc_socketmgr_create2
|
||||
isc_socketmgr_destroy
|
||||
isc_socket_gettype
|
||||
isc_socket_ipv6only
|
||||
isc_socket_dscp
|
||||
isc_socket_cleanunix
|
||||
isc_socket_permunix
|
||||
isc_socket_register
|
||||
isc_print_vsnprintf
|
||||
isc_print_snprintf
|
||||
isc_print_sprintf
|
||||
isc_socketmgr_setstats
|
||||
isc_print_fprintf
|
||||
isc_print_printf
|
||||
isc_print_snprintf
|
||||
isc_print_sprintf
|
||||
isc_print_vsnprintf
|
||||
|
||||
@@ -51,9 +51,11 @@ isc__buffer_remainingregion
|
||||
isc__buffer_setactive
|
||||
isc__buffer_subtract
|
||||
isc__buffer_usedregion
|
||||
isc__hash_setvec
|
||||
isc__mem_allocate
|
||||
isc__mem_free
|
||||
isc__mem_get
|
||||
isc__mem_printactive
|
||||
isc__mem_put
|
||||
isc__mem_putanddetach
|
||||
isc__mem_reallocate
|
||||
@@ -105,6 +107,8 @@ isc__task_getname
|
||||
isc__task_gettag
|
||||
isc__task_unsendrange
|
||||
isc__taskmgr_mode
|
||||
isc__taskmgr_pause
|
||||
isc__taskmgr_resume
|
||||
@IF AES
|
||||
isc_aes128_crypt
|
||||
isc_aes192_crypt
|
||||
@@ -211,6 +215,7 @@ isc_entropy_status
|
||||
isc_entropy_stopcallbacksources
|
||||
isc_entropy_usebestsource
|
||||
isc_entropy_usehook
|
||||
isc_errno_toresult
|
||||
isc_error_fatal
|
||||
isc_error_runtimecheck
|
||||
isc_error_setfatal
|
||||
@@ -458,6 +463,8 @@ isc_mutexblock_init
|
||||
isc_net_aton
|
||||
isc_net_disableipv4
|
||||
isc_net_disableipv6
|
||||
isc_net_enableipv4
|
||||
isc_net_enableipv6
|
||||
isc_net_getudpportrange
|
||||
isc_net_ntop
|
||||
isc_net_probe_ipv6only
|
||||
@@ -626,6 +633,9 @@ isc_sockaddr_totext
|
||||
isc_sockaddr_v6fromin
|
||||
isc_socket_socketevent
|
||||
isc_socketmgr_createinctx
|
||||
@IF NOTYET
|
||||
isc_socketmgr_renderjson
|
||||
@END NOTYET
|
||||
@IF LIBXML2
|
||||
isc_socketmgr_renderxml
|
||||
@END LIBXML2
|
||||
|
||||
@@ -3,6 +3,12 @@ LIBRARY libns
|
||||
; Exported Functions
|
||||
EXPORTS
|
||||
|
||||
ns__client_request
|
||||
ns__clientmgr_getclient
|
||||
ns__interfacemgr_getif
|
||||
ns__interfacemgr_nextif
|
||||
ns__query_sfcache
|
||||
ns__query_start
|
||||
ns_client_aclmsg
|
||||
ns_client_addopt
|
||||
ns_client_attach
|
||||
|
||||
Executable
+128
@@ -0,0 +1,128 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
status=0
|
||||
|
||||
#
|
||||
# Check for missing #include <isc/print.h> or "print_p.h"
|
||||
#
|
||||
list=`git grep -l snprintf lib bin |
|
||||
grep '\.c$' |
|
||||
grep -vE -e '(lib/bind|lib/dns/rdata|lib/dns/gen.c)' \
|
||||
-e '(lib/isc/win32/time.c|dlzexternal/driver.c)' |
|
||||
xargs grep -EL "(isc/print.h|print_p.h)" 2> /dev/null`
|
||||
[ -n "$list" ] && {
|
||||
status=1
|
||||
echo 'Missing #include <isc/print.h> or #include "print_p.h":'
|
||||
echo "$list"
|
||||
}
|
||||
|
||||
#
|
||||
# Check for missing #include <isc/string.h>"
|
||||
#
|
||||
list=`git grep -lw strsep lib bin |
|
||||
grep '\.c$' |
|
||||
grep -vE -e '(lib/bind|lib/dns/rdata|lib/dns/gen.c)' \
|
||||
-e '(lib/isc/win32/time.c)' |
|
||||
xargs grep -L "<isc/string.h>"`
|
||||
[ -n "$list" ] && {
|
||||
status=1
|
||||
echo 'Missing #include <isc/string.h>:'
|
||||
echo "$list"
|
||||
}
|
||||
|
||||
#
|
||||
# Check for missing #include <inttypes.h>"
|
||||
#
|
||||
list=`git grep -l uintptr_t lib bin |
|
||||
grep '\.c$' |
|
||||
grep -vE -e '(lib/bind|lib/dns/rdata|lib/dns/gen.c)' \
|
||||
-e '(lib/isc/win32/time.c)' |
|
||||
xargs grep -L "<inttypes.h>"`
|
||||
[ -n "$list" ] && {
|
||||
status=1
|
||||
echo 'Missing #include <inttypes.h>:'
|
||||
echo "$list"
|
||||
}
|
||||
|
||||
#
|
||||
# Check for missing #include <config.h>
|
||||
#
|
||||
list=`git ls-files -c bin lib | grep '\.c$' |
|
||||
xargs grep -L '#include ["<]config.h[">]' |
|
||||
grep -vE -e '(/win32/|bin/pkcs11/|lib/dns/rdata|lib/bind/)' \
|
||||
-e '(ifiter_|lib/dns/gen.c|lib/dns/spnego_asn1.c)' \
|
||||
-e '(lib/dns/rbtdb64.c|lib/isc/entropy.c|lib/isc/fsaccess.c)' \
|
||||
-e '(bin/tests/virtual-time/vtwrapper.c|symtbl.c|version.c)'`
|
||||
[ -n "$list" ] && {
|
||||
status=1
|
||||
echo 'Missing #include "config.h":'
|
||||
echo "$list"
|
||||
}
|
||||
|
||||
list=`git ls-files -c lib bin | grep '\.vcxproj\.in$' |
|
||||
xargs grep -L '<ProjectGuid>' |
|
||||
awk '{a[$2]++;} END { for (g in a) if (a[g] != 1) print g;}'`
|
||||
[ -n "$list" ] && {
|
||||
status=1
|
||||
echo 'duplicate <ProjectGuid>'"'"'s:'
|
||||
echo "$list"
|
||||
}
|
||||
|
||||
for lib in `git ls-files -c lib |
|
||||
sed -n 's;^lib/\([^/]*\)/win32/.*\.def.*$;\1;p' |
|
||||
sort -u`
|
||||
do
|
||||
def=`git ls-files -c lib |
|
||||
grep lib/${lib}/win32/lib${lib}.def |
|
||||
sort |
|
||||
tail -n 1`
|
||||
test -z "$def" && continue;
|
||||
test -f "$def" || continue;
|
||||
dirs=
|
||||
test -d lib/$lib/include && dirs="$dirs lib/$lib/include"
|
||||
test -d lib/$lib/win32/include && dirs="$dirs lib/$lib/win32/include"
|
||||
test -z "$dirs" && continue;
|
||||
pat=$lib
|
||||
test $lib = dns && pat='\(dns\|dst\)'
|
||||
pat="^${pat}_[a-z0-9_]*("
|
||||
list=`git ls-files -c $dirs | grep '\.h$' |
|
||||
xargs grep "$pat" |
|
||||
sed -e 's/.*://' -e 's/(.*//' |
|
||||
while read p
|
||||
do
|
||||
case $p in
|
||||
isc__app_register) continue;; # internal
|
||||
isc__mem_register) continue;; # internal
|
||||
isc__task_register) continue;; # internal
|
||||
isc__taskmgr_dispatch) continue;; # internal
|
||||
isc__timer_register) continue;; # internal
|
||||
isc_ntsecurity_getaccountgroups) continue;; # internal
|
||||
isc__taskmgr_dispatch) continue;; # no threads
|
||||
isc__taskmgr_ready) continue;; # no threads
|
||||
isc_socketmgr_getmaxsockets) p=isc__socketmgr_getmaxsockets;;
|
||||
esac
|
||||
grep -q "^${p}"'$' $def && continue
|
||||
test $lib = isc -a -f lib/isc/win32/libisc.def.exclude &&
|
||||
grep -q "^${p}"'$' lib/isc/win32/libisc.def.exclude &&
|
||||
continue
|
||||
if test -d lib/$lib/win32
|
||||
then
|
||||
grep -q "^$p(" lib/$lib/*.c lib/$lib/win32/*.c && echo "$p"
|
||||
else
|
||||
grep -q "^$p(" lib/$lib/*.c && echo "$p"
|
||||
fi
|
||||
done`
|
||||
[ -n "$list" ] && {
|
||||
status=1
|
||||
echo "Missing from ${def}:"
|
||||
echo "$list"
|
||||
}
|
||||
done
|
||||
|
||||
exit $status
|
||||
+8
-8
@@ -1845,22 +1845,21 @@
|
||||
./bin/tests/system/pkcs11ssl/setup.sh SH 2014,2016
|
||||
./bin/tests/system/pkcs11ssl/tests.sh SH 2014,2016
|
||||
./bin/tests/system/pkcs11ssl/usepkcs11 X 2014
|
||||
./bin/tests/system/reclimit/README TXT.BRIEF 2014,2016
|
||||
./bin/tests/system/reclimit/ans2/ans.pl PERL 2014,2015,2016
|
||||
./bin/tests/system/reclimit/ans4/ans.pl PERL 2014,2016
|
||||
./bin/tests/system/reclimit/README TXT.BRIEF 2014,2016,2017
|
||||
./bin/tests/system/reclimit/ans2/ans.pl PERL 2014,2015,2016,2017
|
||||
./bin/tests/system/reclimit/ans7/ans.pl PERL 2014,2016
|
||||
./bin/tests/system/reclimit/clean.sh SH 2014,2016
|
||||
./bin/tests/system/reclimit/ns1/named.conf CONF-C 2014,2016
|
||||
./bin/tests/system/reclimit/ns1/root.db ZONE 2014,2016
|
||||
./bin/tests/system/reclimit/ns1/root.db ZONE 2014,2016,2017
|
||||
./bin/tests/system/reclimit/ns3/.gitignore X 2014
|
||||
./bin/tests/system/reclimit/ns3/hints.db ZONE 2014,2016
|
||||
./bin/tests/system/reclimit/ns3/named1.conf CONF-C 2014,2016
|
||||
./bin/tests/system/reclimit/ns3/named2.conf CONF-C 2014,2016
|
||||
./bin/tests/system/reclimit/ns3/named3.conf CONF-C 2014,2016
|
||||
./bin/tests/system/reclimit/ns3/named4.conf CONF-C 2014,2016
|
||||
./bin/tests/system/reclimit/prereq.sh SH 2015,2016
|
||||
./bin/tests/system/reclimit/prereq.sh SH 2015,2016,2017
|
||||
./bin/tests/system/reclimit/setup.sh SH 2014,2016
|
||||
./bin/tests/system/reclimit/tests.sh SH 2014,2015,2016
|
||||
./bin/tests/system/reclimit/tests.sh SH 2014,2015,2016,2017
|
||||
./bin/tests/system/redirect/clean.sh SH 2011,2012,2013,2014,2015,2016
|
||||
./bin/tests/system/redirect/conf/bad1.conf CONF-C 2011,2016
|
||||
./bin/tests/system/redirect/conf/bad2.conf CONF-C 2011,2016
|
||||
@@ -3749,7 +3748,7 @@
|
||||
./lib/isc/event.c C 1998,1999,2000,2001,2004,2005,2007,2014,2016
|
||||
./lib/isc/fsaccess.c C 2000,2001,2004,2005,2007,2016,2017
|
||||
./lib/isc/hash.c C 2003,2004,2005,2006,2007,2009,2013,2014,2015,2016,2017
|
||||
./lib/isc/heap.c C 1997,1998,1999,2000,2001,2004,2005,2006,2007,2010,2011,2012,2013,2014,2015,2016
|
||||
./lib/isc/heap.c C 1997,1998,1999,2000,2001,2004,2005,2006,2007,2010,2011,2012,2013,2014,2015,2016,2017
|
||||
./lib/isc/hex.c C 2000,2001,2002,2003,2004,2005,2007,2008,2013,2014,2015,2016
|
||||
./lib/isc/hmacmd5.c C 2000,2001,2004,2005,2006,2007,2009,2013,2014,2015,2016,2017
|
||||
./lib/isc/hmacsha.c C 2005,2006,2007,2009,2011,2012,2013,2014,2015,2016,2017
|
||||
@@ -4059,7 +4058,7 @@
|
||||
./lib/isc/win32/ipv6.c C 1999,2000,2001,2004,2007,2016
|
||||
./lib/isc/win32/keyboard.c C 2000,2001,2004,2007,2016
|
||||
./lib/isc/win32/libgen.h C 2009,2016
|
||||
./lib/isc/win32/libisc.def.exclude X 2015
|
||||
./lib/isc/win32/libisc.def.exclude X 2015,2017
|
||||
./lib/isc/win32/libisc.def.in X 2001,2002,2003,2004,2005,2006,2007,2008,2009,2010,2011,2012,2013,2014,2015,2016,2017
|
||||
./lib/isc/win32/libisc.vcxproj.filters.in X 2013,2014,2015,2016
|
||||
./lib/isc/win32/libisc.vcxproj.in X 2013,2014,2015,2016,2017
|
||||
@@ -4579,6 +4578,7 @@
|
||||
./util/check-instincludes.sh SH 2000,2001,2004,2007,2012,2016
|
||||
./util/check-pullups.pl PERL 2001,2002,2003,2004,2007,2012,2016
|
||||
./util/check-sources.pl PERL 2000,2001,2004,2007,2012,2013,2016
|
||||
./util/checklibs.sh SH 2017
|
||||
./util/commit-arm.sh SH 2012,2016
|
||||
./util/copyrights X 1998,1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2010,2011,2012,2013,2014,2015,2016,2017
|
||||
./util/file_year.sh SH 2012,2016
|
||||
|
||||
Reference in New Issue
Block a user