Compare commits
401
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
24638c3098 | ||
|
|
f93934dea7 | ||
|
|
8b8149cdd2 | ||
|
|
3efa17ee01 | ||
|
|
136ed023fd | ||
|
|
00a3d91e2d | ||
|
|
a018b4e36f | ||
|
|
b82957376d | ||
|
|
81b3c5d908 | ||
|
|
e430ce7039 | ||
|
|
f466e32fdb | ||
|
|
473cbd4e87 | ||
|
|
23b2ce56e5 | ||
|
|
8a96a3af6a | ||
|
|
6370e9b311 | ||
|
|
91bc0b439a | ||
|
|
8b55d0709d | ||
|
|
d2e0043ec3 | ||
|
|
2cec1de43b | ||
|
|
5929ba0f54 | ||
|
|
cb3ffac9a7 | ||
|
|
bfe338b965 | ||
|
|
3808567de1 | ||
|
|
35ef25e5ea | ||
|
|
149b3d552e | ||
|
|
f47bc5923f | ||
|
|
dc3578ee84 | ||
|
|
da0e48b611 | ||
|
|
0d4accd07f | ||
|
|
b9246418e8 | ||
|
|
d0c8c6d7ef | ||
|
|
31650d9440 | ||
|
|
ed81b3ae93 | ||
|
|
29263b115b | ||
|
|
7de939609b | ||
|
|
c6cb9d83dd | ||
|
|
b409cba48b | ||
|
|
19b23b3ed8 | ||
|
|
c62b6c82c0 | ||
|
|
3be2d25e54 | ||
|
|
9bc152dd25 | ||
|
|
0962fbd200 | ||
|
|
8ff039e3eb | ||
|
|
ff69d07fed | ||
|
|
b343484ddb | ||
|
|
7289090683 | ||
|
|
6bb4070685 | ||
|
|
0367c60759 | ||
|
|
0d2482c62e | ||
|
|
61faffd06f | ||
|
|
004a5329e2 | ||
|
|
903534c9a9 | ||
|
|
3f61f69c52 | ||
|
|
7ba966ee9a | ||
|
|
3e11c4a873 | ||
|
|
911daeb306 | ||
|
|
5af53a329f | ||
|
|
8a09d54d6b | ||
|
|
d57fa148af | ||
|
|
9afcdc2b18 | ||
|
|
5a2df8caf5 | ||
|
|
b65533beff | ||
|
|
8e0244d300 | ||
|
|
78d48f7ae2 | ||
|
|
d42ea08f16 | ||
|
|
7ea6b16d0d | ||
|
|
43f0b0e8eb | ||
|
|
15b2f0125d | ||
|
|
a45e39d114 | ||
|
|
c900300f21 | ||
|
|
d32b65b699 | ||
|
|
338d4c8dd3 | ||
|
|
fa5d85f29d | ||
|
|
6f86885304 | ||
|
|
4cd73e2536 | ||
|
|
ad329ddcaa | ||
|
|
c7e8b7cf63 | ||
|
|
cada2de31f | ||
|
|
f99da39934 | ||
|
|
d61712d14e | ||
|
|
b37c15d244 | ||
|
|
60f5f2a9d9 | ||
|
|
0b9ce9c05b | ||
|
|
5b832126b3 | ||
|
|
5a79b36f56 | ||
|
|
5c5d4eb40a | ||
|
|
73b950dc29 | ||
|
|
146743d5a3 | ||
|
|
edf0e6415a | ||
|
|
d1c64d588b | ||
|
|
3165261ecd | ||
|
|
a133a33b65 | ||
|
|
642a1b985d | ||
|
|
99b18bab7e | ||
|
|
397e007a8e | ||
|
|
49505cb93d | ||
|
|
c05a823e8b | ||
|
|
d40b722d46 | ||
|
|
bb653d37e0 | ||
|
|
62469afe71 | ||
|
|
266530d473 | ||
|
|
d165466125 | ||
|
|
c088772191 | ||
|
|
e7decd7a65 | ||
|
|
035289be71 | ||
|
|
c5bc0a1805 | ||
|
|
25bf77fac6 | ||
|
|
0c347fb321 | ||
|
|
329e5eee9b | ||
|
|
479c7d5a61 | ||
|
|
125059caef | ||
|
|
8dbd57116b | ||
|
|
f37eb33f29 | ||
|
|
7bb6d82505 | ||
|
|
b9bb0528f6 | ||
|
|
7b756350f5 | ||
|
|
ec62fc1399 | ||
|
|
bfa206beec | ||
|
|
d504f4f20b | ||
|
|
1ce163795e | ||
|
|
2e3068ed60 | ||
|
|
61cf599fbf | ||
|
|
30d20b110e | ||
|
|
2190aa904f | ||
|
|
63e058c29e | ||
|
|
037382c4a5 | ||
|
|
445722d2bf | ||
|
|
afe093258c | ||
|
|
ecd2b79106 | ||
|
|
edbb219fda | ||
|
|
748d98e387 | ||
|
|
367154c1de | ||
|
|
0598381236 | ||
|
|
2299aba5c2 | ||
|
|
d8a6ff5c3e | ||
|
|
8d6b0bcc6b | ||
|
|
bca3d09354 | ||
|
|
51d7c2973c | ||
|
|
779de4ec34 | ||
|
|
14d2040934 | ||
|
|
3bca3cb5cf | ||
|
|
cf53eac46e | ||
|
|
fd8e1d161f | ||
|
|
558ec133ea | ||
|
|
ab517fc6e4 | ||
|
|
e44652a173 | ||
|
|
7860b6519d | ||
|
|
aa408051d6 | ||
|
|
520500d1b3 | ||
|
|
679e90a57d | ||
|
|
091d738c72 | ||
|
|
8506102216 | ||
|
|
043f11de3f | ||
|
|
b2dda86254 | ||
|
|
a8a689531f | ||
|
|
957af59cf8 | ||
|
|
e53cb61cf7 | ||
|
|
db9d3b8207 | ||
|
|
019f3ca185 | ||
|
|
5714164f6f | ||
|
|
411e78d92d | ||
|
|
0e17d40843 | ||
|
|
7e429463f5 | ||
|
|
e4e36e6f37 | ||
|
|
993ba7cc7f | ||
|
|
759948fffe | ||
|
|
5bfed08b25 | ||
|
|
5567407a82 | ||
|
|
50539ae389 | ||
|
|
c795cfec54 | ||
|
|
6f6b53041c | ||
|
|
2b37b2ed74 | ||
|
|
ec2fc7680a | ||
|
|
d0d6ad0c52 | ||
|
|
8bb9568467 | ||
|
|
920530b7a3 | ||
|
|
2855ec8f5f | ||
|
|
661981be7b | ||
|
|
59f4fdebc0 | ||
|
|
8071384324 | ||
|
|
2fbf9757b8 | ||
|
|
dda5ba53df | ||
|
|
2d12e1142a | ||
|
|
122a142241 | ||
|
|
b03e90e0d4 | ||
|
|
9c06717429 | ||
|
|
930a7515c2 | ||
|
|
7cb9af430e | ||
|
|
d02d6af2b9 | ||
|
|
2a46396f29 | ||
|
|
ebd669a830 | ||
|
|
656e04f48a | ||
|
|
75021765f8 | ||
|
|
867066aa53 | ||
|
|
936975a9ae | ||
|
|
b330eb0af8 | ||
|
|
5275b6bc83 | ||
|
|
2310c322c0 | ||
|
|
43c81e2e24 | ||
|
|
d00ff78a3e | ||
|
|
ac395b058c | ||
|
|
480dcdef9a | ||
|
|
bf69e8f149 | ||
|
|
c31cd67788 | ||
|
|
3e4d153453 | ||
|
|
acdc57259f | ||
|
|
482eed2e31 | ||
|
|
2c7088a48d | ||
|
|
37274bebe1 | ||
|
|
f4e0d0e460 | ||
|
|
86f1ec34dc | ||
|
|
f73a19bb3e | ||
|
|
391e743c30 | ||
|
|
069c6c2265 | ||
|
|
596903a6b7 | ||
|
|
b732da695e | ||
|
|
8efe101742 | ||
|
|
3e86c3190d | ||
|
|
507824e524 | ||
|
|
713f430349 | ||
|
|
d197c583dd | ||
|
|
4301d90ca2 | ||
|
|
730fd32ee6 | ||
|
|
c9b23221c4 | ||
|
|
f6dd701b83 | ||
|
|
e4e9616a14 | ||
|
|
a47707c59d | ||
|
|
53cdd247bb | ||
|
|
8b70722fcb | ||
|
|
c2c9d8f01b | ||
|
|
8e86e55af1 | ||
|
|
f6fb9a4969 | ||
|
|
bc802359b0 | ||
|
|
9e7cd68d9f | ||
|
|
39aef50b9b | ||
|
|
f202937078 | ||
|
|
0d010ddebe | ||
|
|
104f3b82fb | ||
|
|
7e3b425dc2 | ||
|
|
c5588babaf | ||
|
|
05d78671bb | ||
|
|
825f3d68c5 | ||
|
|
af7db89513 | ||
|
|
d3b7e92783 | ||
|
|
cd92a145a3 | ||
|
|
f58ed932d8 | ||
|
|
7f2513a5aa | ||
|
|
e6f2f2a5e6 | ||
|
|
ab2abfc8b0 | ||
|
|
ed766efc15 | ||
|
|
1d1bc3a148 | ||
|
|
c11b736e44 | ||
|
|
ee00bddf94 | ||
|
|
684f3eb8e6 | ||
|
|
ced1eb358d | ||
|
|
9abedb7757 | ||
|
|
50b8d9b674 | ||
|
|
5dd3c41676 | ||
|
|
e6a7695600 | ||
|
|
7facf967ac | ||
|
|
327e890910 | ||
|
|
b620b7e911 | ||
|
|
cd54f9d4b9 | ||
|
|
495cf18c75 | ||
|
|
ef7aba7072 | ||
|
|
1688c96bda | ||
|
|
2ebcafd8c2 | ||
|
|
227add4c3e | ||
|
|
a26055f03e | ||
|
|
5beae5faf9 | ||
|
|
6b720bfe1a | ||
|
|
bad8b03188 | ||
|
|
a68a77ca86 | ||
|
|
6573276bad | ||
|
|
a84d54c6ff | ||
|
|
5fafb0e7f7 | ||
|
|
2a76352b37 | ||
|
|
9397251eb3 | ||
|
|
5dbb560747 | ||
|
|
dcee04f70c | ||
|
|
13941c8ca7 | ||
|
|
96ccd962b7 | ||
|
|
8ccfbcfe72 | ||
|
|
4d77eafd13 | ||
|
|
c43b74c28b | ||
|
|
00739e99f6 | ||
|
|
c54880e3fa | ||
|
|
7a705a3ea4 | ||
|
|
8def0c3b12 | ||
|
|
3835d75f00 | ||
|
|
37dbd57c16 | ||
|
|
026024a6ae | ||
|
|
a513d4c07f | ||
|
|
b1c99c4458 | ||
|
|
10147efc87 | ||
|
|
4c363393ff | ||
|
|
827a153d99 | ||
|
|
4efdb8b00a | ||
|
|
cc4f99bc6d | ||
|
|
f158884344 | ||
|
|
c33bf0de8d | ||
|
|
246d5ccbc9 | ||
|
|
b26079fdaf | ||
|
|
afe406be39 | ||
|
|
912eaf6cb9 | ||
|
|
b9cbd3bc76 | ||
|
|
1dd76fe780 | ||
|
|
8986dda74a | ||
|
|
35d93624a5 | ||
|
|
20ac13fb23 | ||
|
|
e7ef0a60ab | ||
|
|
7838ca3f67 | ||
|
|
1e1334a322 | ||
|
|
33f4ee7c36 | ||
|
|
47338c2c87 | ||
|
|
0aee38e510 | ||
|
|
2dc2abd00d | ||
|
|
1661278b34 | ||
|
|
63b787effe | ||
|
|
621149c50a | ||
|
|
d6a79cce53 | ||
|
|
5f47c2b567 | ||
|
|
34589811c5 | ||
|
|
63b8a75de9 | ||
|
|
e48f4e8101 | ||
|
|
3d1179501a | ||
|
|
402ca316ae | ||
|
|
b156531b29 | ||
|
|
ea2a5909a5 | ||
|
|
3b0de4773b | ||
|
|
b28e5ff721 | ||
|
|
bca63437a1 | ||
|
|
5857a4d397 | ||
|
|
111e285214 | ||
|
|
6d1c7beb15 | ||
|
|
f78beca942 | ||
|
|
93d7d221bd | ||
|
|
fadf461761 | ||
|
|
393d7fa78e | ||
|
|
09b03d58c7 | ||
|
|
5843b29f47 | ||
|
|
0b56763df3 | ||
|
|
fa35c67301 | ||
|
|
a49b2a3568 | ||
|
|
b51c9eb797 | ||
|
|
b80a0faf0b | ||
|
|
8fd7da2a9e | ||
|
|
020fda92b4 | ||
|
|
cb5238cc62 | ||
|
|
89ab9e948d | ||
|
|
7751c7eca6 | ||
|
|
580f872fe1 | ||
|
|
b621f1d88e | ||
|
|
40f392c124 | ||
|
|
d7ace928b5 | ||
|
|
fc84bf80e4 | ||
|
|
25cb39b7fc | ||
|
|
8302db407c | ||
|
|
5ff1fbe155 | ||
|
|
2e55a2ac69 | ||
|
|
88dfe50289 | ||
|
|
7a191400f9 | ||
|
|
5d26b8b71e | ||
|
|
56c1f4aef2 | ||
|
|
78aa4466fe | ||
|
|
48d39f7c30 | ||
|
|
6427d625ea | ||
|
|
e8dbc5db92 | ||
|
|
0dcc93d87a | ||
|
|
53a5f50e9d | ||
|
|
c32ddf9672 | ||
|
|
0d69afd764 | ||
|
|
10602b1bbb | ||
|
|
e874632488 | ||
|
|
d9d882816a | ||
|
|
14a76ae498 | ||
|
|
25845a866e | ||
|
|
129973ebb0 | ||
|
|
1cec0b0448 | ||
|
|
2237895bb4 | ||
|
|
93326e3e18 | ||
|
|
b2dc6edeb8 | ||
|
|
645cd0496e | ||
|
|
f72563cc4a | ||
|
|
bbcce1bfc1 | ||
|
|
a64ecc5fdd | ||
|
|
bcc99213a5 | ||
|
|
91be111dc7 | ||
|
|
7cbb052649 | ||
|
|
3f1a843695 | ||
|
|
0ec8b99ea3 | ||
|
|
e9b6031e0c | ||
|
|
951280bca5 | ||
|
|
1c95eeeb3f | ||
|
|
c2b23fa2de | ||
|
|
a8258d1c53 | ||
|
|
9f90c1c65e | ||
|
|
63247d8a73 | ||
|
|
315d3d771f | ||
|
|
8b153abd3c | ||
|
|
0f93a755d1 |
@@ -1540,3 +1540,5 @@ ffbe6b95371c99b7fb05e6de17a8d6b7bf4f629f
|
|||||||
79d93600116faabd89798522817ad95a69684fff
|
79d93600116faabd89798522817ad95a69684fff
|
||||||
# Reformat sources with up-to-date clang-format-18
|
# Reformat sources with up-to-date clang-format-18
|
||||||
b7de2c7cb959fa35099d72c3f9b13938348c74e6
|
b7de2c7cb959fa35099d72c3f9b13938348c74e6
|
||||||
|
# Reformat sources with up-to-date clang-format-19
|
||||||
|
ff69d07fed2619a9bedf5ccc18cf106b7dd49bef
|
||||||
|
|||||||
+1
-1
@@ -10,4 +10,4 @@
|
|||||||
/util/** export-ignore
|
/util/** export-ignore
|
||||||
/util/bindkeys.pl -export-ignore
|
/util/bindkeys.pl -export-ignore
|
||||||
/util/check-make-install.in -export-ignore
|
/util/check-make-install.in -export-ignore
|
||||||
/util/mksymtbl.pl -export-ignore
|
/util/dtrace.sh -export-ignore
|
||||||
|
|||||||
Symlink
+1
@@ -0,0 +1 @@
|
|||||||
|
contrib/gitchangelog/changelog.rc.py
|
||||||
+100
-85
@@ -15,7 +15,7 @@ variables:
|
|||||||
TEST_PARALLEL_JOBS: 4
|
TEST_PARALLEL_JOBS: 4
|
||||||
|
|
||||||
CONFIGURE: ./configure
|
CONFIGURE: ./configure
|
||||||
CLANG_VERSION: 18
|
CLANG_VERSION: 19
|
||||||
CLANG: "clang-${CLANG_VERSION}"
|
CLANG: "clang-${CLANG_VERSION}"
|
||||||
SCAN_BUILD: "scan-build-${CLANG_VERSION}"
|
SCAN_BUILD: "scan-build-${CLANG_VERSION}"
|
||||||
LLVM_SYMBOLIZER: "/usr/lib/llvm-${CLANG_VERSION}/bin/llvm-symbolizer"
|
LLVM_SYMBOLIZER: "/usr/lib/llvm-${CLANG_VERSION}/bin/llvm-symbolizer"
|
||||||
@@ -64,6 +64,13 @@ default:
|
|||||||
# See: https://docs.gitlab.com/ee/ci/pipelines/settings.html#auto-cancel-redundant-pipelines
|
# See: https://docs.gitlab.com/ee/ci/pipelines/settings.html#auto-cancel-redundant-pipelines
|
||||||
interruptible: true
|
interruptible: true
|
||||||
|
|
||||||
|
# AWS can interrupt the spot instance anytime, so let's retry the job when
|
||||||
|
# the interruption event happens to avoid a pipeline failure.
|
||||||
|
retry:
|
||||||
|
max: 2
|
||||||
|
when:
|
||||||
|
- runner_system_failure
|
||||||
|
|
||||||
stages:
|
stages:
|
||||||
- autoconf
|
- autoconf
|
||||||
- precheck
|
- precheck
|
||||||
@@ -140,10 +147,6 @@ stages:
|
|||||||
|
|
||||||
# Debian
|
# Debian
|
||||||
|
|
||||||
.debian-bullseye-amd64: &debian_bullseye_amd64_image
|
|
||||||
image: "$CI_REGISTRY_IMAGE:debian-bullseye-amd64"
|
|
||||||
<<: *linux_amd64
|
|
||||||
|
|
||||||
.debian-bookworm-amd64: &debian_bookworm_amd64_image
|
.debian-bookworm-amd64: &debian_bookworm_amd64_image
|
||||||
image: "$CI_REGISTRY_IMAGE:debian-bookworm-amd64"
|
image: "$CI_REGISTRY_IMAGE:debian-bookworm-amd64"
|
||||||
<<: *linux_amd64
|
<<: *linux_amd64
|
||||||
@@ -207,7 +210,7 @@ stages:
|
|||||||
<<: *libvirt_amd64
|
<<: *libvirt_amd64
|
||||||
|
|
||||||
.freebsd-14-amd64: &freebsd_14_amd64_image
|
.freebsd-14-amd64: &freebsd_14_amd64_image
|
||||||
image: "freebsd-14.0-x86_64"
|
image: "freebsd-14.1-x86_64"
|
||||||
<<: *libvirt_amd64
|
<<: *libvirt_amd64
|
||||||
|
|
||||||
.openbsd-amd64: &openbsd_amd64_image
|
.openbsd-amd64: &openbsd_amd64_image
|
||||||
@@ -513,18 +516,6 @@ misc:
|
|||||||
- checklibs.out
|
- checklibs.out
|
||||||
when: on_failure
|
when: on_failure
|
||||||
|
|
||||||
changes:
|
|
||||||
<<: *precheck_job
|
|
||||||
except:
|
|
||||||
- pipelines
|
|
||||||
script:
|
|
||||||
- sh util/tabify-changes < CHANGES > CHANGES.tmp
|
|
||||||
- diff -urNap CHANGES CHANGES.tmp
|
|
||||||
- perl util/check-changes CHANGES
|
|
||||||
- sh util/check-line-length.sh CHANGES
|
|
||||||
- rm CHANGES.tmp
|
|
||||||
needs: []
|
|
||||||
|
|
||||||
black:
|
black:
|
||||||
<<: *precheck_job
|
<<: *precheck_job
|
||||||
needs: []
|
needs: []
|
||||||
@@ -581,7 +572,7 @@ pylint:
|
|||||||
variables:
|
variables:
|
||||||
PYTHONPATH: "${CI_PROJECT_DIR}/bin/tests/system"
|
PYTHONPATH: "${CI_PROJECT_DIR}/bin/tests/system"
|
||||||
script:
|
script:
|
||||||
- pylint --rcfile $CI_PROJECT_DIR/.pylintrc $(git ls-files '*.py' | grep -vE '(ans\.py|dangerfile\.py|^bin/tests/system/)')
|
- pylint --rcfile $CI_PROJECT_DIR/.pylintrc $(git ls-files '*.py' | grep -vE '(ans\.py|dangerfile\.py|^bin/tests/system/|^contrib/)')
|
||||||
# Ignore Pylint wrong-import-position error in system test to enable use of pytest.importorskip
|
# Ignore Pylint wrong-import-position error in system test to enable use of pytest.importorskip
|
||||||
- pylint --rcfile $CI_PROJECT_DIR/.pylintrc --disable=wrong-import-position $(git ls-files 'bin/tests/system/*.py' | grep -vE 'ans\.py')
|
- pylint --rcfile $CI_PROJECT_DIR/.pylintrc --disable=wrong-import-position $(git ls-files 'bin/tests/system/*.py' | grep -vE 'ans\.py')
|
||||||
|
|
||||||
@@ -656,6 +647,28 @@ tarball-create:
|
|||||||
|
|
||||||
# Jobs for doc builds on Debian 12 "bookworm" (amd64)
|
# Jobs for doc builds on Debian 12 "bookworm" (amd64)
|
||||||
|
|
||||||
|
changelog:
|
||||||
|
<<: *base_image
|
||||||
|
<<: *docs_job
|
||||||
|
rules:
|
||||||
|
- if: '$CI_MERGE_REQUEST_TITLE =~ /\s(dev|usr|pkg):/'
|
||||||
|
variables:
|
||||||
|
GIT_AUTHOR_NAME: $GITLAB_USER_NAME
|
||||||
|
GIT_AUTHOR_EMAIL: $GITLAB_USER_EMAIL
|
||||||
|
GIT_COMMITTER_NAME: $GITLAB_USER_NAME
|
||||||
|
GIT_COMMITTER_EMAIL: $GITLAB_USER_EMAIL
|
||||||
|
before_script:
|
||||||
|
- echo -e "$CI_MERGE_REQUEST_TITLE\n" > commitmsg
|
||||||
|
- sed -i 's/^Draft:\s*//' commitmsg
|
||||||
|
- echo -e "$CI_MERGE_REQUEST_DESCRIPTION" >> commitmsg
|
||||||
|
- git commit --allow-empty -F commitmsg
|
||||||
|
- ./contrib/gitchangelog/gitchangelog.py HEAD^..HEAD
|
||||||
|
needs:
|
||||||
|
- job: autoreconf
|
||||||
|
artifacts: true
|
||||||
|
artifacts:
|
||||||
|
untracked: true
|
||||||
|
|
||||||
docs:
|
docs:
|
||||||
<<: *default_triggering_rules
|
<<: *default_triggering_rules
|
||||||
<<: *base_image
|
<<: *base_image
|
||||||
@@ -688,7 +701,6 @@ cross-version-config-tests:
|
|||||||
# Disable option checking to prevent problems with new default options in
|
# Disable option checking to prevent problems with new default options in
|
||||||
# the &configure anchor.
|
# the &configure anchor.
|
||||||
EXTRA_CONFIGURE: "--disable-option-checking"
|
EXTRA_CONFIGURE: "--disable-option-checking"
|
||||||
PYTEST: "/usr/bin/pytest-3"
|
|
||||||
script:
|
script:
|
||||||
- *configure
|
- *configure
|
||||||
- *setup_interfaces
|
- *setup_interfaces
|
||||||
@@ -698,16 +710,17 @@ cross-version-config-tests:
|
|||||||
- autoreconf -fi
|
- autoreconf -fi
|
||||||
- *configure
|
- *configure
|
||||||
- make -j${BUILD_PARALLEL_JOBS:-1}
|
- make -j${BUILD_PARALLEL_JOBS:-1}
|
||||||
|
- *find_pytest
|
||||||
|
# The cross-version-config-tests job would fail when a system test is
|
||||||
|
# removed from the upcoming release. To avoid this, remove the system test
|
||||||
|
# also from the $BIND_BASELINE_VERSION.
|
||||||
|
- find bin/tests/system/ -mindepth 1 -maxdepth 1 -type d -exec sh -c 'test -e ../"$0" || rm -rfv -- "$0"' {} \;
|
||||||
- cd bin/tests/system
|
- cd bin/tests/system
|
||||||
# Run the setup phase of all system tests in the most recently tagged BIND 9
|
# Run the setup phase of all system tests in the most recently tagged BIND 9
|
||||||
# release using the binaries built for the current BIND 9 version. This
|
# release using the binaries built for the current BIND 9 version. This
|
||||||
# intends to detect obvious backward compatibility issues with the latter.
|
# intends to detect obvious backward compatibility issues with the latter.
|
||||||
- >
|
- >
|
||||||
if [ -f isctest/vars/autoconf.py ]; then
|
echo "${CI_PROJECT_DIR}" > isctest/vars/.ac_vars/TOP_BUILDDIR
|
||||||
echo "${CI_PROJECT_DIR}" > isctest/vars/.ac_vars/TOP_BUILDDIR
|
|
||||||
else
|
|
||||||
sed -i -E "s|(export TOP_BUILDDIR)=.*|\1=${CI_PROJECT_DIR}|" conf.sh;
|
|
||||||
fi
|
|
||||||
- >
|
- >
|
||||||
"$PYTEST" --setup-only --junit-xml="$CI_PROJECT_DIR"/junit.xml -n "${TEST_PARALLEL_JOBS:-1}"
|
"$PYTEST" --setup-only --junit-xml="$CI_PROJECT_DIR"/junit.xml -n "${TEST_PARALLEL_JOBS:-1}"
|
||||||
needs:
|
needs:
|
||||||
@@ -1248,9 +1261,9 @@ unit:clang:asan:
|
|||||||
gcc:tsan:
|
gcc:tsan:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "${CFLAGS_COMMON} -fsanitize=thread"
|
CFLAGS: "${CFLAGS_COMMON} -Wno-stringop-overread -ggdb -O2 -fsanitize=thread"
|
||||||
LDFLAGS: "-fsanitize=thread"
|
LDFLAGS: "-fsanitize=thread"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock --without-jemalloc"
|
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig"
|
||||||
<<: *tsan_fedora_40_amd64_image
|
<<: *tsan_fedora_40_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
|
|
||||||
@@ -1277,9 +1290,9 @@ clang:tsan:
|
|||||||
<<: *build_job
|
<<: *build_job
|
||||||
variables:
|
variables:
|
||||||
CC: "${CLANG}"
|
CC: "${CLANG}"
|
||||||
CFLAGS: "${CFLAGS_COMMON} -fsanitize=thread"
|
CFLAGS: "${CFLAGS_COMMON} -ggdb -O2 -fsanitize=thread"
|
||||||
LDFLAGS: "-fsanitize=thread"
|
LDFLAGS: "-fsanitize=thread"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock --without-jemalloc"
|
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig"
|
||||||
|
|
||||||
system:clang:tsan:
|
system:clang:tsan:
|
||||||
variables:
|
variables:
|
||||||
@@ -1299,54 +1312,33 @@ unit:clang:tsan:
|
|||||||
- job: clang:tsan
|
- job: clang:tsan
|
||||||
artifacts: true
|
artifacts: true
|
||||||
|
|
||||||
# Jobs for Debian 11 "bullseye" (amd64)
|
generate-tsan-stress-test-configs:
|
||||||
|
<<: *base_image
|
||||||
|
<<: *default_triggering_rules
|
||||||
|
stage: system
|
||||||
|
script:
|
||||||
|
- util/generate-tsan-stress-jobs.py > tsan-stress-test-configs.yml
|
||||||
|
artifacts:
|
||||||
|
paths:
|
||||||
|
- tsan-stress-test-configs.yml
|
||||||
|
needs: []
|
||||||
|
when: manual
|
||||||
|
|
||||||
clang:bullseye:amd64:
|
tsan:stress:
|
||||||
|
<<: *default_triggering_rules
|
||||||
|
stage: postcheck
|
||||||
variables:
|
variables:
|
||||||
CC: ${CLANG}
|
PARENT_PIPELINE_ID: $CI_PIPELINE_ID
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Wenum-conversion"
|
trigger:
|
||||||
<<: *debian_bullseye_amd64_image
|
include:
|
||||||
<<: *build_job
|
- artifact: tsan-stress-test-configs.yml
|
||||||
|
job: generate-tsan-stress-test-configs
|
||||||
system:clang:bullseye:amd64:
|
|
||||||
<<: *debian_bullseye_amd64_image
|
|
||||||
<<: *system_test_job
|
|
||||||
needs:
|
needs:
|
||||||
- job: clang:bullseye:amd64
|
- job: generate-tsan-stress-test-configs
|
||||||
artifacts: true
|
artifacts: true
|
||||||
|
- job: gcc:tsan
|
||||||
unit:clang:bullseye:amd64:
|
|
||||||
<<: *debian_bullseye_amd64_image
|
|
||||||
<<: *unit_test_job
|
|
||||||
needs:
|
|
||||||
- job: clang:bullseye:amd64
|
|
||||||
artifacts: true
|
artifacts: true
|
||||||
|
- job: clang:tsan
|
||||||
gcc:bullseye:amd64:
|
|
||||||
variables:
|
|
||||||
CC: gcc
|
|
||||||
CFLAGS: "${CFLAGS_COMMON}"
|
|
||||||
# See https://gitlab.isc.org/isc-projects/bind9/-/issues/3444
|
|
||||||
EXTRA_CONFIGURE: "--with-libidn2 --without-jemalloc --disable-leak-detection"
|
|
||||||
<<: *debian_bullseye_amd64_image
|
|
||||||
<<: *build_job
|
|
||||||
|
|
||||||
system:gcc:bullseye:amd64:
|
|
||||||
# Set up environment variables that allow the "keyfromlabel" system test to be run
|
|
||||||
variables:
|
|
||||||
OPENSSL_CONF: "/var/tmp/etc/openssl.cnf"
|
|
||||||
SOFTHSM2_CONF: "/var/tmp/softhsm2/softhsm2.conf"
|
|
||||||
<<: *debian_bullseye_amd64_image
|
|
||||||
<<: *system_test_job
|
|
||||||
needs:
|
|
||||||
- job: gcc:bullseye:amd64
|
|
||||||
artifacts: true
|
|
||||||
|
|
||||||
unit:gcc:bullseye:amd64:
|
|
||||||
<<: *debian_bullseye_amd64_image
|
|
||||||
<<: *unit_test_job
|
|
||||||
needs:
|
|
||||||
- job: gcc:bullseye:amd64
|
|
||||||
artifacts: true
|
artifacts: true
|
||||||
|
|
||||||
# Jobs for Clang builds on Debian 12 "bookworm" (amd64)
|
# Jobs for Clang builds on Debian 12 "bookworm" (amd64)
|
||||||
@@ -1363,10 +1355,6 @@ clang:bookworm:amd64:
|
|||||||
<<: *build_job
|
<<: *build_job
|
||||||
|
|
||||||
system:clang:bookworm:amd64:
|
system:clang:bookworm:amd64:
|
||||||
# Set up environment variables that allow the "keyfromlabel" system test to be run
|
|
||||||
variables:
|
|
||||||
OPENSSL_CONF: "/var/tmp/etc/openssl.cnf"
|
|
||||||
SOFTHSM2_CONF: "/var/tmp/softhsm2/softhsm2.conf"
|
|
||||||
<<: *debian_bookworm_amd64_image
|
<<: *debian_bookworm_amd64_image
|
||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
needs:
|
needs:
|
||||||
@@ -1614,7 +1602,7 @@ respdiff:tsan:
|
|||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "${CFLAGS_COMMON} -Og -fsanitize=thread"
|
CFLAGS: "${CFLAGS_COMMON} -Og -fsanitize=thread"
|
||||||
LDFLAGS: "-fsanitize=thread"
|
LDFLAGS: "-fsanitize=thread"
|
||||||
EXTRA_CONFIGURE: "--disable-dnsrps --enable-pthread-rwlock --without-jemalloc"
|
EXTRA_CONFIGURE: "--disable-dnsrps --enable-pthread-rwlock --without-jemalloc PKG_CONFIG_PATH=/opt/tsan/lib/pkgconfig"
|
||||||
MAX_DISAGREEMENTS_PERCENTAGE: "0.5"
|
MAX_DISAGREEMENTS_PERCENTAGE: "0.5"
|
||||||
TSAN_OPTIONS: "${TSAN_OPTIONS_DEBIAN}"
|
TSAN_OPTIONS: "${TSAN_OPTIONS_DEBIAN}"
|
||||||
script:
|
script:
|
||||||
@@ -1679,6 +1667,10 @@ shotgun:dot:
|
|||||||
<<: *stress_test
|
<<: *stress_test
|
||||||
artifacts:
|
artifacts:
|
||||||
untracked: true
|
untracked: true
|
||||||
|
exclude:
|
||||||
|
- "output/ns4/*.dtq*"
|
||||||
|
- "output/ns4/large-delta-rpz*.local"
|
||||||
|
- "output/rpz_*"
|
||||||
when: always
|
when: always
|
||||||
only:
|
only:
|
||||||
- merge_requests
|
- merge_requests
|
||||||
@@ -1997,23 +1989,46 @@ pairwise:
|
|||||||
variables:
|
variables:
|
||||||
- $PAIRWISE_TESTING
|
- $PAIRWISE_TESTING
|
||||||
|
|
||||||
backports:
|
.post_merge_template: &post_merge
|
||||||
<<: *base_image
|
<<: *base_image
|
||||||
stage: postmerge
|
stage: postmerge
|
||||||
rules:
|
needs: []
|
||||||
- if: '$CI_PIPELINE_SOURCE == "push" && ($CI_COMMIT_REF_NAME =~ /^bind-9.[0-9]+$/ || $CI_COMMIT_REF_NAME == $CI_DEFAULT_BRANCH)'
|
# post-merge processes should run even if another MR was merged while the job was running (or queued)
|
||||||
|
interruptible: false
|
||||||
variables:
|
variables:
|
||||||
# automated commits will inherit identification from the user who pressed Merge button
|
# automated commits will inherit identification from the user who pressed Merge button
|
||||||
GIT_COMMITTER_NAME: $GITLAB_USER_NAME
|
GIT_COMMITTER_NAME: $GITLAB_USER_NAME
|
||||||
GIT_COMMITTER_EMAIL: $GITLAB_USER_EMAIL
|
GIT_COMMITTER_EMAIL: $GITLAB_USER_EMAIL
|
||||||
# avoid leftover branches from previous jobs
|
# avoid leftover branches from previous jobs
|
||||||
GIT_STRATEGY: clone
|
GIT_STRATEGY: clone
|
||||||
# assumed max depth of a MR for backport
|
# assumed max depth of a MR for backport or a rebased force-push
|
||||||
GIT_DEPTH: 200
|
GIT_DEPTH: 1000
|
||||||
|
before_script:
|
||||||
|
# force-pushes should not trigger process automation (happens only in -sub branches)
|
||||||
|
- >
|
||||||
|
echo "previous branch tip: $CI_COMMIT_BEFORE_SHA"
|
||||||
|
- set +o pipefail; git log --format='%H' | grep --silent "$CI_COMMIT_BEFORE_SHA" && PREVIOUS_TIP_REACHABLE=1
|
||||||
|
- test "$PREVIOUS_TIP_REACHABLE" != "1" && echo "force-push detected, stop" && exit 1
|
||||||
|
# non-fast-forward merges are disabled so we have to have merge commit on top
|
||||||
|
- MERGE_REQUEST_ID="$(git log -1 --format='%b' | sed --silent -e 's/^See merge request [^!]\+!//p')"
|
||||||
|
- >
|
||||||
|
: stop if this is not a merge request
|
||||||
|
- test "$MERGE_REQUEST_ID" -ge 0
|
||||||
|
- git clone --depth 1 https://gitlab.isc.org/isc-projects/bind9-qa.git
|
||||||
|
|
||||||
|
backports:
|
||||||
|
<<: *post_merge
|
||||||
|
rules:
|
||||||
|
# -sub branches are handled manually
|
||||||
|
- if: '$CI_PIPELINE_SOURCE == "push" && ($CI_COMMIT_REF_NAME =~ /^bind-9.[0-9]+$/ || $CI_COMMIT_REF_NAME == $CI_DEFAULT_BRANCH)'
|
||||||
script:
|
script:
|
||||||
# CI job token is not sufficient for push operations
|
# CI job token is not sufficient for push operations
|
||||||
- git remote get-url origin | sed -e "s/gitlab-ci-token:$CI_JOB_TOKEN/oauth2:$BIND_TEAM_WRITE_TOKEN/" | xargs git remote set-url --push origin
|
- git remote get-url origin | sed -e "s/gitlab-ci-token:$CI_JOB_TOKEN/oauth2:$BIND_TEAM_WRITE_TOKEN/" | xargs git remote set-url --push origin
|
||||||
# force-pushing is disabled so we have to have merge request on top
|
|
||||||
- MERGE_REQUEST_ID="$(git log -1 --format='%b' | sed --silent -e 's/^See merge request [^!]\+!//p')"
|
|
||||||
- git clone --depth 1 https://gitlab.isc.org/isc-projects/bind9-qa.git
|
|
||||||
- bind9-qa/releng/backport_mr.py $CI_PROJECT_ID "$MERGE_REQUEST_ID"
|
- bind9-qa/releng/backport_mr.py $CI_PROJECT_ID "$MERGE_REQUEST_ID"
|
||||||
|
|
||||||
|
merged-metadata:
|
||||||
|
<<: *post_merge
|
||||||
|
rules:
|
||||||
|
- if: '$CI_PIPELINE_SOURCE == "push" && ($CI_COMMIT_REF_NAME =~ /^bind-9.[0-9]+(-sub)?$/ || $CI_COMMIT_REF_NAME =~ /^bind-9.[0-9]+.[0-9]+-release$/ || $CI_COMMIT_REF_NAME == $CI_DEFAULT_BRANCH)'
|
||||||
|
script:
|
||||||
|
- bind9-qa/releng/after_merge.py "$CI_PROJECT_ID" "$MERGE_REQUEST_ID"
|
||||||
|
|||||||
@@ -12,12 +12,14 @@ confidential!
|
|||||||
| Deputy Incident Manager: | @user |
|
| Deputy Incident Manager: | @user |
|
||||||
| Public Disclosure Date: | YYYY-MM-DD |
|
| Public Disclosure Date: | YYYY-MM-DD |
|
||||||
| CVSS Score: | [0.0][cvss_score] |
|
| CVSS Score: | [0.0][cvss_score] |
|
||||||
|
| CWE: | [CWE-NNN][cwe_category]
|
||||||
| Security Advisory: | isc-private/printing-press!NNN |
|
| Security Advisory: | isc-private/printing-press!NNN |
|
||||||
| Mattermost Channel: | [CVE-YYYY-NNNN][mattermost_url] |
|
| Mattermost Channel: | [CVE-YYYY-NNNN][mattermost_url] |
|
||||||
| Support Ticket: | [URL] |
|
| Support Ticket: | [URL] |
|
||||||
| Release Checklist: | #NNNN |
|
| Release Checklist: | #NNNN |
|
||||||
|
|
||||||
[cvss_score]: https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:X/AC:X/PR:X/UI:X/S:X/C:X/I:X/A:X&version=3.1
|
[cvss_score]: https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:X/AC:X/PR:X/UI:X/S:X/C:X/I:X/A:X&version=3.1
|
||||||
|
[cwe_category]: https://cwe.mitre.org/data/definitions/NNN.html
|
||||||
[mattermost_url]:
|
[mattermost_url]:
|
||||||
|
|
||||||
:bulb: **Click [here][checklist_explanations] (internal resource) for general information about the security incident handling process.**
|
:bulb: **Click [here][checklist_explanations] (internal resource) for general information about the security incident handling process.**
|
||||||
@@ -30,12 +32,12 @@ confidential!
|
|||||||
- [ ] [:link:][step_respond] **(IM)** Respond to the bug reporter
|
- [ ] [:link:][step_respond] **(IM)** Respond to the bug reporter
|
||||||
- [ ] [:link:][step_public_mrs] **(SwEng)** Ensure there are no public merge requests which inadvertently disclose the issue
|
- [ ] [:link:][step_public_mrs] **(SwEng)** Ensure there are no public merge requests which inadvertently disclose the issue
|
||||||
- [ ] [:link:][step_assign_cve_id] **(IM)** Assign a CVE identifier
|
- [ ] [:link:][step_assign_cve_id] **(IM)** Assign a CVE identifier
|
||||||
- [ ] [:link:][step_note_cve_info] **(SwEng)** Update this issue with the assigned CVE identifier and the CVSS score
|
- [ ] [:link:][step_note_cve_info] **(SwEng)** Update this issue with the assigned CVE identifier, the CVSS score, and CWE category
|
||||||
- [ ] [:link:][step_versions_affected] **(SwEng)** Determine the range of product versions affected (including the Subscription Edition)
|
- [ ] [:link:][step_versions_affected] **(SwEng)** Determine the range of product versions affected (including the Subscription Edition)
|
||||||
- [ ] [:link:][step_workarounds] **(SwEng)** Determine whether workarounds for the problem exist
|
- [ ] [:link:][step_workarounds] **(SwEng)** Determine whether workarounds for the problem exist
|
||||||
- [ ] [:link:][step_coordinate] **(SwEng)** If necessary, coordinate with other parties
|
- [ ] [:link:][step_coordinate] **(SwEng)** If necessary, coordinate with other parties
|
||||||
- [ ] [:link:][step_earliest_prepare] **(Support)** Prepare "earliest" notification text and hand it off to Marketing
|
- [ ] [:link:][step_earliest_prepare] **(Support)** Prepare "earliest" notification text
|
||||||
- [ ] [:link:][step_earliest_send] **(Marketing)** Update "earliest" notification document in SF portal and send bulk email to earliest customers
|
- [ ] [:link:][step_earliest_send] **(Support)** Update "earliest" notification ticket in support portal Earliest queue which will notify earliest customers
|
||||||
- [ ] [:link:][step_advisory_mr] **(Support)** Create a merge request for the Security Advisory and include all readily available information in it
|
- [ ] [:link:][step_advisory_mr] **(Support)** Create a merge request for the Security Advisory and include all readily available information in it
|
||||||
- [ ] [:link:][step_reproducer_mr] **(SwEng)** Prepare a private merge request containing a system test reproducing the problem
|
- [ ] [:link:][step_reproducer_mr] **(SwEng)** Prepare a private merge request containing a system test reproducing the problem
|
||||||
- [ ] [:link:][step_notify_support] **(SwEng)** Notify Support when a reproducer is ready
|
- [ ] [:link:][step_notify_support] **(SwEng)** Notify Support when a reproducer is ready
|
||||||
@@ -46,18 +48,19 @@ confidential!
|
|||||||
- [ ] [:link:][step_backports] **(SwEng)** Prepare backports of the merge request addressing the problem for all affected (and still maintained) branches of a given product
|
- [ ] [:link:][step_backports] **(SwEng)** Prepare backports of the merge request addressing the problem for all affected (and still maintained) branches of a given product
|
||||||
- [ ] [:link:][step_finish_advisory] **(Support)** Finish preparing the Security Advisory
|
- [ ] [:link:][step_finish_advisory] **(Support)** Finish preparing the Security Advisory
|
||||||
- [ ] [:link:][step_meta_issue] **(QA)** Create (or update) the private issue containing links to fixes & reproducers for all CVEs fixed in a given release cycle
|
- [ ] [:link:][step_meta_issue] **(QA)** Create (or update) the private issue containing links to fixes & reproducers for all CVEs fixed in a given release cycle
|
||||||
- [ ] [:link:][step_changes] **(QA)** (BIND 9 only) Reserve a block of `CHANGES` placeholders once the complete set of vulnerabilities fixed in a given release cycle is determined
|
|
||||||
- [ ] [:link:][step_merge_fixes] **(QA)** Merge the CVE fixes in CVE identifier order
|
- [ ] [:link:][step_merge_fixes] **(QA)** Merge the CVE fixes in CVE identifier order
|
||||||
- [ ] [:link:][step_patches] **(QA)** Prepare a standalone patch for the last stable release of each affected (and still maintained) product branch
|
- [ ] [:link:][step_patches] **(QA)** Prepare a standalone patch for the last stable release of each affected (and still maintained) product branch
|
||||||
- [ ] [:link:][step_asn_releases] **(QA)** Prepare ASN releases (as outlined in the Release Checklist)
|
- [ ] [:link:][step_asn_releases] **(QA)** Prepare ASN releases (as outlined in the Release Checklist)
|
||||||
|
|
||||||
### At T-5
|
### At T-5
|
||||||
|
|
||||||
- [ ] [:link:][step_asn_documents] **(Marketing)** Update the text on the T-5 (from the Printing Press project) and "earliest" ASN documents in the SF portal
|
- [ ] [:link:][step_asn_links] **(Marketing)** (BIND 9 only) Update the BIND -S information document in the support portal with download links to the new versions
|
||||||
- [ ] [:link:][step_asn_links] **(Marketing)** (BIND 9 only) Update the BIND -S information document in SF with download links to the new versions
|
- [ ] [:link:][step_asn_send] **(Support)** Notify eligible customers by adding a ticket to the 5 Day queue in RT with the text of the advisory (earliest, and T-5)
|
||||||
- [ ] [:link:][step_asn_send] **(Marketing)** Bulk email eligible customers to check the SF portal
|
|
||||||
- [ ] [:link:][step_preannouncement] **(Marketing)** (BIND 9 only) Send a pre-announcement email to the *bind-announce* mailing list to alert users that the upcoming release will include security fixes
|
- [ ] [:link:][step_preannouncement] **(Marketing)** (BIND 9 only) Send a pre-announcement email to the *bind-announce* mailing list to alert users that the upcoming release will include security fixes
|
||||||
|
|
||||||
|
### At T-3
|
||||||
|
- [ ] [:link:][step_asn_send] **(Support)** Notify eligible customers by adding a ticket to the 3 Day queue in RT with the text of the advisory (T-3)
|
||||||
|
|
||||||
### At T-1
|
### At T-1
|
||||||
|
|
||||||
- [ ] [:link:][step_packager_emails] **(First IM)** Send notifications to OS packagers
|
- [ ] [:link:][step_packager_emails] **(First IM)** Send notifications to OS packagers
|
||||||
@@ -72,8 +75,8 @@ confidential!
|
|||||||
- [ ] [:link:][step_mitre] **(First IM)** Advise MITRE about the disclosed CVEs
|
- [ ] [:link:][step_mitre] **(First IM)** Advise MITRE about the disclosed CVEs
|
||||||
- [ ] [:link:][step_merge_advisory] **(First IM)** Merge the Security Advisory merge request
|
- [ ] [:link:][step_merge_advisory] **(First IM)** Merge the Security Advisory merge request
|
||||||
- [ ] [:link:][step_embargo_end] **(IM)** Inform original reporter (if external) that the security disclosure process is complete
|
- [ ] [:link:][step_embargo_end] **(IM)** Inform original reporter (if external) that the security disclosure process is complete
|
||||||
- [ ] [:link:][step_asn_clear] **(Marketing)** Update the SF portal to clear the ASN
|
- [ ] [:link:][step_asn_clear] **(Support)** Update the tickets in the ASN queues in RT that the embargo is lifted
|
||||||
- [ ] [:link:][step_customers] **(Marketing)** Email ASN recipients that the embargo is lifted
|
- [ ] [:link:][step_customers] **(Marketing)** Open a ticket in the <software name> Announce queue that the release is published
|
||||||
|
|
||||||
### After Public Disclosure
|
### After Public Disclosure
|
||||||
|
|
||||||
@@ -83,7 +86,7 @@ confidential!
|
|||||||
[step_respond]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#respond-to-the-bug-reporter
|
[step_respond]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#respond-to-the-bug-reporter
|
||||||
[step_public_mrs]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#ensure-there-are-no-public-merge-requests-which-inadvertently-disclose-the-issue
|
[step_public_mrs]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#ensure-there-are-no-public-merge-requests-which-inadvertently-disclose-the-issue
|
||||||
[step_assign_cve_id]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#assign-a-cve-identifier
|
[step_assign_cve_id]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#assign-a-cve-identifier
|
||||||
[step_note_cve_info]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#update-this-issue-with-the-assigned-cve-identifier-and-the-cvss-score
|
[step_note_cve_info]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#update-this-issue-with-the-assigned-cve-identifier-the-cvss-score-and-the-cwe-category
|
||||||
[step_versions_affected]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#determine-the-range-of-product-versions-affected-including-the-subscription-edition
|
[step_versions_affected]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#determine-the-range-of-product-versions-affected-including-the-subscription-edition
|
||||||
[step_workarounds]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#determine-whether-workarounds-for-the-problem-exist
|
[step_workarounds]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#determine-whether-workarounds-for-the-problem-exist
|
||||||
[step_coordinate]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#if-necessary-coordinate-with-other-parties
|
[step_coordinate]: https://gitlab.isc.org/isc-private/isc-wiki/-/wikis/Security-Incident-Handling-Checklist-Explanations#if-necessary-coordinate-with-other-parties
|
||||||
|
|||||||
@@ -1,4 +1,10 @@
|
|||||||
[MASTER]
|
[IMPORTS]
|
||||||
|
|
||||||
|
deprecated-modules=
|
||||||
|
dns.resolver,
|
||||||
|
|
||||||
|
[MESSAGES CONTROL]
|
||||||
|
|
||||||
disable=
|
disable=
|
||||||
C0103, # invalid-name
|
C0103, # invalid-name
|
||||||
C0114, # missing-module-docstring
|
C0114, # missing-module-docstring
|
||||||
|
|||||||
@@ -191,6 +191,8 @@ Files: **/.clang-format
|
|||||||
.readthedocs.yaml
|
.readthedocs.yaml
|
||||||
.tsan-suppress
|
.tsan-suppress
|
||||||
.uncrustify.cfg
|
.uncrustify.cfg
|
||||||
|
contrib/gitchangelog/changelog.rc.py
|
||||||
|
contrib/gitchangelog/relnotes.rc.py
|
||||||
doc/misc/*.zoneopt
|
doc/misc/*.zoneopt
|
||||||
doc/misc/options
|
doc/misc/options
|
||||||
doc/misc/rndc.grammar
|
doc/misc/rndc.grammar
|
||||||
|
|||||||
@@ -26,4 +26,3 @@ Some of these settings are:
|
|||||||
| `-DISC_MEM_TRACKLINES=0` | Don't track memory allocations by file and line number; this improves performance but makes debugging more difficult |
|
| `-DISC_MEM_TRACKLINES=0` | Don't track memory allocations by file and line number; this improves performance but makes debugging more difficult |
|
||||||
| `-DNAMED_RUN_PID_DIR=0` | Create default PID files in `${localstatedir}/run` rather than `${localstatedir}/run/named/` |
|
| `-DNAMED_RUN_PID_DIR=0` | Create default PID files in `${localstatedir}/run` rather than `${localstatedir}/run/named/` |
|
||||||
| `-DNS_CLIENT_DROPPORT=0` | Disable dropping queries from particular well-known ports |
|
| `-DNS_CLIENT_DROPPORT=0` | Disable dropping queries from particular well-known ports |
|
||||||
| `-DOPENSSL_API_COMPAT=10100` | Build using the deprecated OpenSSL APIs so that the `engine` API is available when building with OpenSSL 3.0.0 for PKCS#11 support |
|
|
||||||
|
|||||||
@@ -20,7 +20,6 @@ information regarding copyright ownership.
|
|||||||
1. [Building BIND](#build)
|
1. [Building BIND](#build)
|
||||||
1. [Automated testing](#testing)
|
1. [Automated testing](#testing)
|
||||||
1. [Documentation](#doc)
|
1. [Documentation](#doc)
|
||||||
1. [Change log](#changes)
|
|
||||||
1. [Acknowledgments](#ack)
|
1. [Acknowledgments](#ack)
|
||||||
|
|
||||||
### <a name="intro"/> Introduction
|
### <a name="intro"/> Introduction
|
||||||
@@ -49,8 +48,7 @@ ongoing maintenance and improvement. BIND is open source software
|
|||||||
licensed under the terms of the Mozilla Public License, version 2.0.
|
licensed under the terms of the Mozilla Public License, version 2.0.
|
||||||
|
|
||||||
For a detailed list of changes made throughout the history of BIND 9, see
|
For a detailed list of changes made throughout the history of BIND 9, see
|
||||||
the file [CHANGES](CHANGES). See [below](#changes) for details on the
|
the [changelog](doc/arm/changelog.rst).
|
||||||
CHANGES file format.
|
|
||||||
|
|
||||||
For up-to-date versions and release notes, see
|
For up-to-date versions and release notes, see
|
||||||
[https://www.isc.org/download/](https://www.isc.org/download/).
|
[https://www.isc.org/download/](https://www.isc.org/download/).
|
||||||
@@ -163,35 +161,6 @@ can be found in the ISC Knowledgebase at
|
|||||||
Additional information on various subjects can be found in other
|
Additional information on various subjects can be found in other
|
||||||
`README` files throughout the source tree.
|
`README` files throughout the source tree.
|
||||||
|
|
||||||
### <a name="changes"/> Change log
|
|
||||||
|
|
||||||
A detailed list of all changes that have been made throughout the
|
|
||||||
development of BIND 9 is included in the file CHANGES, with the most recent
|
|
||||||
changes listed first. Change notes include tags indicating the category of
|
|
||||||
the change that was made; these categories are:
|
|
||||||
|
|
||||||
|Category |Description |
|
|
||||||
|-------------- |-----------------------------------------------|
|
|
||||||
| [func] | New feature |
|
|
||||||
| [bug] | General bug fix |
|
|
||||||
| [security] | Fix for a significant security flaw |
|
|
||||||
| [experimental] | Used for new features when the syntax or other aspects of the design are still in flux and may change |
|
|
||||||
| [port] | Portability enhancement |
|
|
||||||
| [maint] | Updates to built-in data such as root server addresses and keys |
|
|
||||||
| [tuning] | Changes to built-in configuration defaults and constants to improve performance |
|
|
||||||
| [performance] | Other changes to improve server performance |
|
|
||||||
| [protocol] | Updates to the DNS protocol such as new RR types |
|
|
||||||
| [test] | Changes to the automatic tests, not affecting server functionality |
|
|
||||||
| [cleanup] | Minor corrections and refactoring |
|
|
||||||
| [doc] | Documentation |
|
|
||||||
| [contrib] | Changes to the contributed tools and libraries in the 'contrib' subdirectory |
|
|
||||||
| [placeholder] | Used in the main development branch to reserve change numbers for use in other branches, e.g., when fixing a bug that only exists in older releases |
|
|
||||||
|
|
||||||
In general, [func] and [experimental] tags only appear in new-feature
|
|
||||||
releases (i.e., those with version numbers ending in zero). Some new
|
|
||||||
functionality may be backported to older releases on a case-by-case basis.
|
|
||||||
All other change types may be applied to all currently supported releases.
|
|
||||||
|
|
||||||
#### Bug report identifiers
|
#### Bug report identifiers
|
||||||
|
|
||||||
Most notes in the CHANGES file include a reference to a bug report or
|
Most notes in the CHANGES file include a reference to a bug report or
|
||||||
|
|||||||
+6
-35
@@ -33,7 +33,6 @@
|
|||||||
#include <dns/db.h>
|
#include <dns/db.h>
|
||||||
#include <dns/dbiterator.h>
|
#include <dns/dbiterator.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/log.h>
|
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/rdata.h>
|
#include <dns/rdata.h>
|
||||||
#include <dns/rdataclass.h>
|
#include <dns/rdataclass.h>
|
||||||
@@ -43,10 +42,6 @@
|
|||||||
#include <dns/types.h>
|
#include <dns/types.h>
|
||||||
#include <dns/zone.h>
|
#include <dns/zone.h>
|
||||||
|
|
||||||
#include <isccfg/log.h>
|
|
||||||
|
|
||||||
#include <ns/log.h>
|
|
||||||
|
|
||||||
#include "check-tool.h"
|
#include "check-tool.h"
|
||||||
|
|
||||||
#ifndef CHECK_SIBLING
|
#ifndef CHECK_SIBLING
|
||||||
@@ -97,13 +92,6 @@ dns_zoneopt_t zone_options = DNS_ZONEOPT_CHECKNS | DNS_ZONEOPT_CHECKMX |
|
|||||||
DNS_ZONEOPT_CHECKSVCB | DNS_ZONEOPT_CHECKWILDCARD |
|
DNS_ZONEOPT_CHECKSVCB | DNS_ZONEOPT_CHECKWILDCARD |
|
||||||
DNS_ZONEOPT_WARNMXCNAME | DNS_ZONEOPT_WARNSRVCNAME;
|
DNS_ZONEOPT_WARNMXCNAME | DNS_ZONEOPT_WARNSRVCNAME;
|
||||||
|
|
||||||
/*
|
|
||||||
* This needs to match the list in bin/named/log.c.
|
|
||||||
*/
|
|
||||||
static isc_logcategory_t categories[] = { { "", 0 },
|
|
||||||
{ "unmatched", 0 },
|
|
||||||
{ NULL, 0 } };
|
|
||||||
|
|
||||||
static isc_symtab_t *symtab = NULL;
|
static isc_symtab_t *symtab = NULL;
|
||||||
static isc_mem_t *sym_mctx;
|
static isc_mem_t *sym_mctx;
|
||||||
|
|
||||||
@@ -549,30 +537,13 @@ checksrv(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
setup_logging(isc_mem_t *mctx, FILE *errout, isc_log_t **logp) {
|
setup_logging(FILE *errout) {
|
||||||
isc_logdestination_t destination;
|
isc_logconfig_t *logconfig = isc_logconfig_get();
|
||||||
isc_logconfig_t *logconfig = NULL;
|
isc_log_createandusechannel(
|
||||||
isc_log_t *log = NULL;
|
logconfig, "default_stderr", ISC_LOG_TOFILEDESC,
|
||||||
|
ISC_LOG_DYNAMIC, ISC_LOGDESTINATION_FILE(errout), 0,
|
||||||
|
ISC_LOGCATEGORY_DEFAULT, ISC_LOGMODULE_DEFAULT);
|
||||||
|
|
||||||
isc_log_create(mctx, &log, &logconfig);
|
|
||||||
isc_log_registercategories(log, categories);
|
|
||||||
isc_log_setcontext(log);
|
|
||||||
dns_log_init(log);
|
|
||||||
dns_log_setcontext(log);
|
|
||||||
cfg_log_init(log);
|
|
||||||
ns_log_init(log);
|
|
||||||
|
|
||||||
destination.file.stream = errout;
|
|
||||||
destination.file.name = NULL;
|
|
||||||
destination.file.versions = ISC_LOG_ROLLNEVER;
|
|
||||||
destination.file.maximum_size = 0;
|
|
||||||
isc_log_createchannel(logconfig, "stderr", ISC_LOG_TOFILEDESC,
|
|
||||||
ISC_LOG_DYNAMIC, &destination, 0);
|
|
||||||
|
|
||||||
RUNTIME_CHECK(isc_log_usechannel(logconfig, "stderr", NULL, NULL) ==
|
|
||||||
ISC_R_SUCCESS);
|
|
||||||
|
|
||||||
*logp = log;
|
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -29,7 +29,7 @@
|
|||||||
ISC_LANG_BEGINDECLS
|
ISC_LANG_BEGINDECLS
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
setup_logging(isc_mem_t *mctx, FILE *errout, isc_log_t **logp);
|
setup_logging(FILE *errout);
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
load_zone(isc_mem_t *mctx, const char *zonename, const char *filename,
|
load_zone(isc_mem_t *mctx, const char *zonename, const char *filename,
|
||||||
|
|||||||
+14
-21
@@ -30,7 +30,6 @@
|
|||||||
|
|
||||||
#include <dns/db.h>
|
#include <dns/db.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/log.h>
|
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/rdataclass.h>
|
#include <dns/rdataclass.h>
|
||||||
#include <dns/rootns.h>
|
#include <dns/rootns.h>
|
||||||
@@ -44,8 +43,6 @@
|
|||||||
|
|
||||||
static const char *program = "named-checkconf";
|
static const char *program = "named-checkconf";
|
||||||
|
|
||||||
isc_log_t *logc = NULL;
|
|
||||||
|
|
||||||
#define CHECK(r) \
|
#define CHECK(r) \
|
||||||
do { \
|
do { \
|
||||||
result = (r); \
|
result = (r); \
|
||||||
@@ -54,7 +51,7 @@ isc_log_t *logc = NULL;
|
|||||||
} while (0)
|
} while (0)
|
||||||
|
|
||||||
/*% usage */
|
/*% usage */
|
||||||
noreturn static void
|
ISC_NORETURN static void
|
||||||
usage(void);
|
usage(void);
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -83,7 +80,7 @@ directory_callback(const char *clausename, const cfg_obj_t *obj, void *arg) {
|
|||||||
directory = cfg_obj_asstring(obj);
|
directory = cfg_obj_asstring(obj);
|
||||||
result = isc_dir_chdir(directory);
|
result = isc_dir_chdir(directory);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(obj, logc, ISC_LOG_ERROR,
|
cfg_obj_log(obj, ISC_LOG_ERROR,
|
||||||
"change directory to '%s' failed: %s\n", directory,
|
"change directory to '%s' failed: %s\n", directory,
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
return (result);
|
return (result);
|
||||||
@@ -593,11 +590,11 @@ main(int argc, char **argv) {
|
|||||||
const char *conffile = NULL;
|
const char *conffile = NULL;
|
||||||
isc_mem_t *mctx = NULL;
|
isc_mem_t *mctx = NULL;
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
isc_result_t result = ISC_R_SUCCESS;
|
||||||
bool cleanup_dst = true;
|
|
||||||
bool load_zones = false;
|
bool load_zones = false;
|
||||||
bool list_zones = false;
|
bool list_zones = false;
|
||||||
bool print = false;
|
bool print = false;
|
||||||
bool nodeprecate = false;
|
bool nodeprecate = false;
|
||||||
|
bool allconfigs = false;
|
||||||
unsigned int flags = 0;
|
unsigned int flags = 0;
|
||||||
unsigned int checkflags = BIND_CHECK_PLUGINS | BIND_CHECK_ALGORITHMS;
|
unsigned int checkflags = BIND_CHECK_PLUGINS | BIND_CHECK_ALGORITHMS;
|
||||||
|
|
||||||
@@ -606,7 +603,7 @@ main(int argc, char **argv) {
|
|||||||
/*
|
/*
|
||||||
* Process memory debugging argument first.
|
* Process memory debugging argument first.
|
||||||
*/
|
*/
|
||||||
#define CMDLINE_FLAGS "acdhijlm:t:pvxz"
|
#define CMDLINE_FLAGS "acdhijlm:nt:pvxz"
|
||||||
while ((c = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != -1) {
|
while ((c = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != -1) {
|
||||||
switch (c) {
|
switch (c) {
|
||||||
case 'm':
|
case 'm':
|
||||||
@@ -660,6 +657,10 @@ main(int argc, char **argv) {
|
|||||||
case 'm':
|
case 'm':
|
||||||
break;
|
break;
|
||||||
|
|
||||||
|
case 'n':
|
||||||
|
allconfigs = true;
|
||||||
|
break;
|
||||||
|
|
||||||
case 't':
|
case 't':
|
||||||
result = isc_dir_chroot(isc_commandline_argument);
|
result = isc_dir_chroot(isc_commandline_argument);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
@@ -726,20 +727,20 @@ main(int argc, char **argv) {
|
|||||||
conffile = NAMED_CONFFILE;
|
conffile = NAMED_CONFFILE;
|
||||||
}
|
}
|
||||||
|
|
||||||
CHECK(setup_logging(mctx, stdout, &logc));
|
CHECK(setup_logging(stdout));
|
||||||
|
|
||||||
CHECK(dst_lib_init(mctx, NULL));
|
CHECK(cfg_parser_create(mctx, &parser));
|
||||||
cleanup_dst = true;
|
|
||||||
|
|
||||||
CHECK(cfg_parser_create(mctx, logc, &parser));
|
|
||||||
|
|
||||||
if (nodeprecate) {
|
if (nodeprecate) {
|
||||||
cfg_parser_setflags(parser, CFG_PCTX_NODEPRECATED, true);
|
cfg_parser_setflags(parser, CFG_PCTX_NODEPRECATED, true);
|
||||||
}
|
}
|
||||||
|
if (allconfigs) {
|
||||||
|
cfg_parser_setflags(parser, CFG_PCTX_ALLCONFIGS, true);
|
||||||
|
}
|
||||||
cfg_parser_setcallback(parser, directory_callback, NULL);
|
cfg_parser_setcallback(parser, directory_callback, NULL);
|
||||||
|
|
||||||
CHECK(cfg_parse_file(parser, conffile, &cfg_type_namedconf, &config));
|
CHECK(cfg_parse_file(parser, conffile, &cfg_type_namedconf, &config));
|
||||||
CHECK(isccfg_check_namedconf(config, checkflags, logc, mctx));
|
CHECK(isccfg_check_namedconf(config, checkflags, mctx));
|
||||||
if (load_zones || list_zones) {
|
if (load_zones || list_zones) {
|
||||||
CHECK(load_zones_fromconfig(config, mctx, list_zones));
|
CHECK(load_zones_fromconfig(config, mctx, list_zones));
|
||||||
}
|
}
|
||||||
@@ -757,14 +758,6 @@ cleanup:
|
|||||||
cfg_parser_destroy(&parser);
|
cfg_parser_destroy(&parser);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (cleanup_dst) {
|
|
||||||
dst_lib_destroy();
|
|
||||||
}
|
|
||||||
|
|
||||||
if (logc != NULL) {
|
|
||||||
isc_log_destroy(&logc);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (mctx != NULL) {
|
if (mctx != NULL) {
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ named-checkconf - named configuration file syntax checking tool
|
|||||||
Synopsis
|
Synopsis
|
||||||
~~~~~~~~
|
~~~~~~~~
|
||||||
|
|
||||||
:program:`named-checkconf` [**-achjlvz**] [**-p** [**-x** ]] [**-t** directory] {filename}
|
:program:`named-checkconf` [**-achjlnvz**] [**-p** [**-x** ]] [**-t** directory] {filename}
|
||||||
|
|
||||||
Description
|
Description
|
||||||
~~~~~~~~~~~
|
~~~~~~~~~~~
|
||||||
@@ -71,6 +71,10 @@ Options
|
|||||||
|
|
||||||
This option ignores warnings on deprecated options.
|
This option ignores warnings on deprecated options.
|
||||||
|
|
||||||
|
.. option:: -n
|
||||||
|
|
||||||
|
Do not error on options that are disabled in this build.
|
||||||
|
|
||||||
.. option:: -p
|
.. option:: -p
|
||||||
|
|
||||||
This option prints out the :iscman:`named.conf` and included files in canonical form if
|
This option prints out the :iscman:`named.conf` and included files in canonical form if
|
||||||
|
|||||||
@@ -31,7 +31,6 @@
|
|||||||
|
|
||||||
#include <dns/db.h>
|
#include <dns/db.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/log.h>
|
|
||||||
#include <dns/master.h>
|
#include <dns/master.h>
|
||||||
#include <dns/masterdump.h>
|
#include <dns/masterdump.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
@@ -62,7 +61,7 @@ static enum { progmode_check, progmode_compile } progmode;
|
|||||||
} \
|
} \
|
||||||
} while (0)
|
} while (0)
|
||||||
|
|
||||||
noreturn static void
|
ISC_NORETURN static void
|
||||||
usage(void);
|
usage(void);
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -95,7 +94,6 @@ main(int argc, char **argv) {
|
|||||||
int c;
|
int c;
|
||||||
char *origin = NULL;
|
char *origin = NULL;
|
||||||
const char *filename = NULL;
|
const char *filename = NULL;
|
||||||
isc_log_t *lctx = NULL;
|
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
char classname_in[] = "IN";
|
char classname_in[] = "IN";
|
||||||
char *classname = classname_in;
|
char *classname = classname_in;
|
||||||
@@ -525,8 +523,7 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
isc_mem_create(&mctx);
|
isc_mem_create(&mctx);
|
||||||
if (!quiet) {
|
if (!quiet) {
|
||||||
RUNTIME_CHECK(setup_logging(mctx, errout, &lctx) ==
|
RUNTIME_CHECK(setup_logging(errout) == ISC_R_SUCCESS);
|
||||||
ISC_R_SUCCESS);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
origin = argv[isc_commandline_index++];
|
origin = argv[isc_commandline_index++];
|
||||||
@@ -566,9 +563,6 @@ main(int argc, char **argv) {
|
|||||||
fprintf(errout, "OK\n");
|
fprintf(errout, "OK\n");
|
||||||
}
|
}
|
||||||
destroy();
|
destroy();
|
||||||
if (lctx != NULL) {
|
|
||||||
isc_log_destroy(&lctx);
|
|
||||||
}
|
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|
||||||
return ((result == ISC_R_SUCCESS) ? 0 : 1);
|
return ((result == ISC_R_SUCCESS) ? 0 : 1);
|
||||||
|
|||||||
@@ -120,8 +120,6 @@ generate_key(isc_mem_t *mctx, dns_secalg_t alg, int keysize,
|
|||||||
fatal("unsupported algorithm %d\n", alg);
|
fatal("unsupported algorithm %d\n", alg);
|
||||||
}
|
}
|
||||||
|
|
||||||
DO("initialize dst library", dst_lib_init(mctx, NULL));
|
|
||||||
|
|
||||||
DO("generate key",
|
DO("generate key",
|
||||||
dst_key_generate(dns_rootname, alg, keysize, 0, 0, DNS_KEYPROTO_ANY,
|
dst_key_generate(dns_rootname, alg, keysize, 0, 0, DNS_KEYPROTO_ANY,
|
||||||
dns_rdataclass_in, NULL, mctx, &key, NULL));
|
dns_rdataclass_in, NULL, mctx, &key, NULL));
|
||||||
@@ -132,14 +130,12 @@ generate_key(isc_mem_t *mctx, dns_secalg_t alg, int keysize,
|
|||||||
|
|
||||||
isc_buffer_usedregion(&key_rawbuffer, &key_rawregion);
|
isc_buffer_usedregion(&key_rawbuffer, &key_rawregion);
|
||||||
|
|
||||||
DO("bsse64 encode secret",
|
DO("base64 encode secret",
|
||||||
isc_base64_totext(&key_rawregion, -1, "", key_txtbuffer));
|
isc_base64_totext(&key_rawregion, -1, "", key_txtbuffer));
|
||||||
|
|
||||||
if (key != NULL) {
|
if (key != NULL) {
|
||||||
dst_key_free(&key);
|
dst_key_free(&key);
|
||||||
}
|
}
|
||||||
|
|
||||||
dst_lib_destroy();
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/*%
|
/*%
|
||||||
|
|||||||
@@ -60,7 +60,7 @@ bool verbose = false;
|
|||||||
|
|
||||||
const char *keyfile, *keydef;
|
const char *keyfile, *keydef;
|
||||||
|
|
||||||
noreturn static void
|
ISC_NORETURN static void
|
||||||
usage(int status);
|
usage(int status);
|
||||||
|
|
||||||
static void
|
static void
|
||||||
|
|||||||
@@ -53,7 +53,7 @@ const char *progname;
|
|||||||
static enum { progmode_keygen, progmode_confgen } progmode;
|
static enum { progmode_keygen, progmode_confgen } progmode;
|
||||||
bool verbose = false; /* needed by util.c but not used here */
|
bool verbose = false; /* needed by util.c but not used here */
|
||||||
|
|
||||||
noreturn static void
|
ISC_NORETURN static void
|
||||||
usage(int status);
|
usage(int status);
|
||||||
|
|
||||||
static void
|
static void
|
||||||
|
|||||||
+1
-1
@@ -36,7 +36,7 @@ ISC_LANG_BEGINDECLS
|
|||||||
void
|
void
|
||||||
notify(const char *fmt, ...) ISC_FORMAT_PRINTF(1, 2);
|
notify(const char *fmt, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||||
|
|
||||||
noreturn void
|
ISC_NORETURN void
|
||||||
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||||
|
|
||||||
ISC_LANG_ENDDECLS
|
ISC_LANG_ENDDECLS
|
||||||
|
|||||||
+74
-83
@@ -52,7 +52,6 @@
|
|||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/keytable.h>
|
#include <dns/keytable.h>
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
#include <dns/log.h>
|
|
||||||
#include <dns/masterdump.h>
|
#include <dns/masterdump.h>
|
||||||
#include <dns/message.h>
|
#include <dns/message.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
@@ -70,7 +69,6 @@
|
|||||||
|
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
|
|
||||||
#include <isccfg/log.h>
|
|
||||||
#include <isccfg/namedconf.h>
|
#include <isccfg/namedconf.h>
|
||||||
|
|
||||||
#include <ns/client.h>
|
#include <ns/client.h>
|
||||||
@@ -88,10 +86,12 @@
|
|||||||
|
|
||||||
#define MAXNAME (DNS_NAME_MAXTEXT + 1)
|
#define MAXNAME (DNS_NAME_MAXTEXT + 1)
|
||||||
|
|
||||||
|
#define MAX_QUERIES 32
|
||||||
|
#define MAX_RESTARTS 11
|
||||||
|
|
||||||
/* Variables used internally by delv. */
|
/* Variables used internally by delv. */
|
||||||
char *progname = NULL;
|
char *progname = NULL;
|
||||||
static isc_mem_t *mctx = NULL;
|
static isc_mem_t *mctx = NULL;
|
||||||
static isc_log_t *lctx = NULL;
|
|
||||||
static dns_view_t *view = NULL;
|
static dns_view_t *view = NULL;
|
||||||
static ns_server_t *sctx = NULL;
|
static ns_server_t *sctx = NULL;
|
||||||
static ns_interface_t *ifp = NULL;
|
static ns_interface_t *ifp = NULL;
|
||||||
@@ -130,6 +130,9 @@ static bool showcomments = true, showdnssec = true, showtrust = true,
|
|||||||
multiline = false, short_form = false, print_unknown_format = false,
|
multiline = false, short_form = false, print_unknown_format = false,
|
||||||
yaml = false, fulltrace = false;
|
yaml = false, fulltrace = false;
|
||||||
|
|
||||||
|
static uint32_t maxqueries = MAX_QUERIES;
|
||||||
|
static uint32_t restarts = MAX_RESTARTS;
|
||||||
|
|
||||||
static bool resolve_trace = false, validator_trace = false,
|
static bool resolve_trace = false, validator_trace = false,
|
||||||
message_trace = false, send_trace = false;
|
message_trace = false, send_trace = false;
|
||||||
|
|
||||||
@@ -250,7 +253,7 @@ usage(void) {
|
|||||||
exit(EXIT_FAILURE);
|
exit(EXIT_FAILURE);
|
||||||
}
|
}
|
||||||
|
|
||||||
noreturn static void
|
ISC_NORETURN static void
|
||||||
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -281,12 +284,6 @@ warn(const char *format, ...) {
|
|||||||
fprintf(stderr, "\n");
|
fprintf(stderr, "\n");
|
||||||
}
|
}
|
||||||
|
|
||||||
static isc_logcategory_t categories[] = { { "delv", 0 }, { NULL, 0 } };
|
|
||||||
#define LOGCATEGORY_DEFAULT (&categories[0])
|
|
||||||
#define LOGMODULE_DEFAULT (&modules[0])
|
|
||||||
|
|
||||||
static isc_logmodule_t modules[] = { { "delv", 0 }, { NULL, 0 } };
|
|
||||||
|
|
||||||
static void
|
static void
|
||||||
delv_log(int level, const char *fmt, ...) ISC_FORMAT_PRINTF(2, 3);
|
delv_log(int level, const char *fmt, ...) ISC_FORMAT_PRINTF(2, 3);
|
||||||
|
|
||||||
@@ -295,15 +292,15 @@ delv_log(int level, const char *fmt, ...) {
|
|||||||
va_list ap;
|
va_list ap;
|
||||||
char msgbuf[2048];
|
char msgbuf[2048];
|
||||||
|
|
||||||
if (!isc_log_wouldlog(lctx, level)) {
|
if (!isc_log_wouldlog(level)) {
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
va_start(ap, fmt);
|
va_start(ap, fmt);
|
||||||
|
|
||||||
vsnprintf(msgbuf, sizeof(msgbuf), fmt, ap);
|
vsnprintf(msgbuf, sizeof(msgbuf), fmt, ap);
|
||||||
isc_log_write(lctx, LOGCATEGORY_DEFAULT, LOGMODULE_DEFAULT, level, "%s",
|
isc_log_write(DELV_LOGCATEGORY_DEFAULT, DELV_LOGMODULE_DEFAULT, level,
|
||||||
msgbuf);
|
"%s", msgbuf);
|
||||||
va_end(ap);
|
va_end(ap);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -311,76 +308,45 @@ static int loglevel = 0;
|
|||||||
|
|
||||||
static void
|
static void
|
||||||
setup_logging(FILE *errout) {
|
setup_logging(FILE *errout) {
|
||||||
isc_result_t result;
|
|
||||||
isc_logdestination_t destination;
|
|
||||||
isc_logconfig_t *logconfig = NULL;
|
|
||||||
int packetlevel = 10;
|
int packetlevel = 10;
|
||||||
|
|
||||||
isc_log_create(mctx, &lctx, &logconfig);
|
isc_log_setdebuglevel(loglevel);
|
||||||
isc_log_registercategories(lctx, categories);
|
|
||||||
isc_log_registermodules(lctx, modules);
|
|
||||||
isc_log_setcontext(lctx);
|
|
||||||
dns_log_init(lctx);
|
|
||||||
dns_log_setcontext(lctx);
|
|
||||||
cfg_log_init(lctx);
|
|
||||||
|
|
||||||
destination.file.stream = errout;
|
isc_logconfig_t *logconfig = isc_logconfig_get();
|
||||||
destination.file.name = NULL;
|
|
||||||
destination.file.versions = ISC_LOG_ROLLNEVER;
|
|
||||||
destination.file.maximum_size = 0;
|
|
||||||
isc_log_createchannel(logconfig, "stderr", ISC_LOG_TOFILEDESC,
|
|
||||||
ISC_LOG_DYNAMIC, &destination,
|
|
||||||
ISC_LOG_PRINTPREFIX);
|
|
||||||
|
|
||||||
isc_log_setdebuglevel(lctx, loglevel);
|
|
||||||
isc_log_settag(logconfig, ";; ");
|
isc_log_settag(logconfig, ";; ");
|
||||||
|
|
||||||
result = isc_log_usechannel(logconfig, "stderr",
|
isc_log_createandusechannel(
|
||||||
ISC_LOGCATEGORY_DEFAULT, NULL);
|
logconfig, "default_stderr", ISC_LOG_TOFILEDESC,
|
||||||
if (result != ISC_R_SUCCESS) {
|
ISC_LOG_DYNAMIC, ISC_LOGDESTINATION_FILE(errout),
|
||||||
fatal("Couldn't attach to log channel 'stderr'");
|
ISC_LOG_PRINTPREFIX, ISC_LOGCATEGORY_DEFAULT,
|
||||||
}
|
ISC_LOGMODULE_DEFAULT);
|
||||||
|
|
||||||
if (resolve_trace && loglevel < 1) {
|
if (resolve_trace && loglevel < 1) {
|
||||||
isc_log_createchannel(logconfig, "resolver", ISC_LOG_TOFILEDESC,
|
isc_log_createandusechannel(
|
||||||
ISC_LOG_DEBUG(1), &destination,
|
logconfig, "resolver", ISC_LOG_TOFILEDESC,
|
||||||
ISC_LOG_PRINTPREFIX);
|
ISC_LOG_DEBUG(1), ISC_LOGDESTINATION_FILE(errout),
|
||||||
|
ISC_LOG_PRINTPREFIX, DNS_LOGCATEGORY_RESOLVER,
|
||||||
result = isc_log_usechannel(logconfig, "resolver",
|
DNS_LOGMODULE_RESOLVER);
|
||||||
DNS_LOGCATEGORY_RESOLVER,
|
|
||||||
DNS_LOGMODULE_RESOLVER);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
fatal("Couldn't attach to log channel 'resolver'");
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (validator_trace && loglevel < 3) {
|
if (validator_trace && loglevel < 3) {
|
||||||
isc_log_createchannel(logconfig, "validator",
|
isc_log_createandusechannel(
|
||||||
ISC_LOG_TOFILEDESC, ISC_LOG_DEBUG(3),
|
logconfig, "validator", ISC_LOG_TOFILEDESC,
|
||||||
&destination, ISC_LOG_PRINTPREFIX);
|
ISC_LOG_DEBUG(3), ISC_LOGDESTINATION_FILE(errout),
|
||||||
|
ISC_LOG_PRINTPREFIX, DNS_LOGCATEGORY_DNSSEC,
|
||||||
result = isc_log_usechannel(logconfig, "validator",
|
DNS_LOGMODULE_VALIDATOR);
|
||||||
DNS_LOGCATEGORY_DNSSEC,
|
|
||||||
DNS_LOGMODULE_VALIDATOR);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
fatal("Couldn't attach to log channel 'validator'");
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (send_trace) {
|
if (send_trace) {
|
||||||
packetlevel = 11;
|
packetlevel = 11;
|
||||||
}
|
}
|
||||||
if ((message_trace || send_trace) && loglevel < packetlevel) {
|
if ((message_trace || send_trace) && loglevel < packetlevel) {
|
||||||
isc_log_createchannel(logconfig, "messages", ISC_LOG_TOFILEDESC,
|
isc_log_createandusechannel(
|
||||||
ISC_LOG_DEBUG(packetlevel), &destination,
|
logconfig, "messages", ISC_LOG_TOFILEDESC,
|
||||||
ISC_LOG_PRINTPREFIX);
|
ISC_LOG_DEBUG(packetlevel),
|
||||||
|
ISC_LOGDESTINATION_FILE(errout), ISC_LOG_PRINTPREFIX,
|
||||||
result = isc_log_usechannel(logconfig, "messages",
|
DNS_LOGCATEGORY_RESOLVER, DNS_LOGMODULE_PACKETS);
|
||||||
DNS_LOGCATEGORY_RESOLVER,
|
|
||||||
DNS_LOGMODULE_PACKETS);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
fatal("Couldn't attach to log channel 'messagse'");
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -810,14 +776,14 @@ key_fromconfig(const cfg_obj_t *key, dns_client_t *client, dns_view_t *toview) {
|
|||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
if (result == DST_R_NOCRYPTO) {
|
if (result == DST_R_NOCRYPTO) {
|
||||||
cfg_obj_log(key, lctx, ISC_LOG_ERROR, "no crypto support");
|
cfg_obj_log(key, ISC_LOG_ERROR, "no crypto support");
|
||||||
} else if (result == DST_R_UNSUPPORTEDALG) {
|
} else if (result == DST_R_UNSUPPORTEDALG) {
|
||||||
cfg_obj_log(key, lctx, ISC_LOG_WARNING,
|
cfg_obj_log(key, ISC_LOG_WARNING,
|
||||||
"skipping trusted key '%s': %s", keynamestr,
|
"skipping trusted key '%s': %s", keynamestr,
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
result = ISC_R_SUCCESS;
|
result = ISC_R_SUCCESS;
|
||||||
} else if (result != ISC_R_SUCCESS) {
|
} else if (result != ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(key, lctx, ISC_LOG_ERROR,
|
cfg_obj_log(key, ISC_LOG_ERROR,
|
||||||
"failed to add trusted key '%s': %s", keynamestr,
|
"failed to add trusted key '%s': %s", keynamestr,
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
result = ISC_R_FAILURE;
|
result = ISC_R_FAILURE;
|
||||||
@@ -872,7 +838,7 @@ setup_dnsseckeys(dns_client_t *client, dns_view_t *toview) {
|
|||||||
CHECK(convert_name(&afn, &anchor_name, trust_anchor));
|
CHECK(convert_name(&afn, &anchor_name, trust_anchor));
|
||||||
}
|
}
|
||||||
|
|
||||||
CHECK(cfg_parser_create(mctx, dns_lctx, &parser));
|
CHECK(cfg_parser_create(mctx, &parser));
|
||||||
|
|
||||||
if (anchorfile != NULL) {
|
if (anchorfile != NULL) {
|
||||||
if (access(anchorfile, R_OK) != 0) {
|
if (access(anchorfile, R_OK) != 0) {
|
||||||
@@ -1191,6 +1157,23 @@ plus_option(char *option) {
|
|||||||
break;
|
break;
|
||||||
case 'm':
|
case 'm':
|
||||||
switch (cmd[1]) {
|
switch (cmd[1]) {
|
||||||
|
case 'a': /* maxqueries */
|
||||||
|
FULLCHECK("maxqueries");
|
||||||
|
if (value == NULL) {
|
||||||
|
goto need_value;
|
||||||
|
}
|
||||||
|
if (!state) {
|
||||||
|
goto invalid_option;
|
||||||
|
}
|
||||||
|
result = parse_uint(&maxqueries, value, UINT_MAX,
|
||||||
|
"maxqueries");
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
fatal("Couldn't parse maxqueries");
|
||||||
|
}
|
||||||
|
if (maxqueries == 0) {
|
||||||
|
fatal("maxqueries must be nonzero");
|
||||||
|
}
|
||||||
|
break;
|
||||||
case 't': /* mtrace */
|
case 't': /* mtrace */
|
||||||
FULLCHECK("mtrace");
|
FULLCHECK("mtrace");
|
||||||
message_trace = state;
|
message_trace = state;
|
||||||
@@ -1243,6 +1226,22 @@ plus_option(char *option) {
|
|||||||
break;
|
break;
|
||||||
case 'r':
|
case 'r':
|
||||||
switch (cmd[1]) {
|
switch (cmd[1]) {
|
||||||
|
case 'e': /* restarts */
|
||||||
|
FULLCHECK("restarts");
|
||||||
|
if (value == NULL) {
|
||||||
|
goto need_value;
|
||||||
|
}
|
||||||
|
if (!state) {
|
||||||
|
goto invalid_option;
|
||||||
|
}
|
||||||
|
result = parse_uint(&restarts, value, 255, "restarts");
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
fatal("Couldn't parse restarts");
|
||||||
|
}
|
||||||
|
if (restarts == 0) {
|
||||||
|
fatal("restarts must be between 1..255");
|
||||||
|
}
|
||||||
|
break;
|
||||||
case 'o': /* root */
|
case 'o': /* root */
|
||||||
FULLCHECK("root");
|
FULLCHECK("root");
|
||||||
if (state && no_sigs) {
|
if (state && no_sigs) {
|
||||||
@@ -1370,10 +1369,7 @@ plus_option(char *option) {
|
|||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
invalid_option:
|
invalid_option:
|
||||||
/*
|
need_value:
|
||||||
* We can also add a "need_value:" case here if we ever
|
|
||||||
* add a plus-option that requires a specified value
|
|
||||||
*/
|
|
||||||
fprintf(stderr, "Invalid option: +%s\n", option);
|
fprintf(stderr, "Invalid option: +%s\n", option);
|
||||||
usage();
|
usage();
|
||||||
}
|
}
|
||||||
@@ -1898,6 +1894,7 @@ run_resolve(void *arg) {
|
|||||||
/* Create client */
|
/* Create client */
|
||||||
CHECK(dns_client_create(mctx, loopmgr, netmgr, 0, tlsctx_client_cache,
|
CHECK(dns_client_create(mctx, loopmgr, netmgr, 0, tlsctx_client_cache,
|
||||||
&client, srcaddr4, srcaddr6));
|
&client, srcaddr4, srcaddr6));
|
||||||
|
dns_client_setmaxrestarts(client, restarts);
|
||||||
|
|
||||||
/* Set the nameserver */
|
/* Set the nameserver */
|
||||||
if (server != NULL) {
|
if (server != NULL) {
|
||||||
@@ -2154,7 +2151,7 @@ run_server(void *arg) {
|
|||||||
isc_sockaddr_any(&any);
|
isc_sockaddr_any(&any);
|
||||||
CHECK(dns_dispatch_createudp(dispatchmgr, &any, &dispatch));
|
CHECK(dns_dispatch_createudp(dispatchmgr, &any, &dispatch));
|
||||||
CHECK(ns_interfacemgr_create(mctx, sctx, loopmgr, netmgr, dispatchmgr,
|
CHECK(ns_interfacemgr_create(mctx, sctx, loopmgr, netmgr, dispatchmgr,
|
||||||
NULL, false, &interfacemgr));
|
NULL, &interfacemgr));
|
||||||
|
|
||||||
CHECK(dns_view_create(mctx, dispatchmgr, dns_rdataclass_in, "_default",
|
CHECK(dns_view_create(mctx, dispatchmgr, dns_rdataclass_in, "_default",
|
||||||
&view));
|
&view));
|
||||||
@@ -2162,6 +2159,7 @@ run_server(void *arg) {
|
|||||||
dns_view_setcache(view, cache, false);
|
dns_view_setcache(view, cache, false);
|
||||||
dns_cache_detach(&cache);
|
dns_cache_detach(&cache);
|
||||||
dns_view_setdstport(view, destport);
|
dns_view_setdstport(view, destport);
|
||||||
|
dns_view_setmaxrestarts(view, restarts);
|
||||||
|
|
||||||
CHECK(dns_rootns_create(mctx, dns_rdataclass_in, hintfile, &roothints));
|
CHECK(dns_rootns_create(mctx, dns_rdataclass_in, hintfile, &roothints));
|
||||||
dns_view_sethints(view, roothints);
|
dns_view_sethints(view, roothints);
|
||||||
@@ -2175,6 +2173,7 @@ run_server(void *arg) {
|
|||||||
|
|
||||||
CHECK(dns_view_createresolver(view, netmgr, 0, tlsctx_client_cache,
|
CHECK(dns_view_createresolver(view, netmgr, 0, tlsctx_client_cache,
|
||||||
dispatch, NULL));
|
dispatch, NULL));
|
||||||
|
dns_resolver_setmaxqueries(view->resolver, maxqueries);
|
||||||
|
|
||||||
isc_stats_create(mctx, &resstats, dns_resstatscounter_max);
|
isc_stats_create(mctx, &resstats, dns_resstatscounter_max);
|
||||||
dns_resolver_setstats(view->resolver, resstats);
|
dns_resolver_setstats(view->resolver, resstats);
|
||||||
@@ -2220,11 +2219,6 @@ main(int argc, char *argv[]) {
|
|||||||
isc_managers_create(&mctx, 1, &loopmgr, &netmgr);
|
isc_managers_create(&mctx, 1, &loopmgr, &netmgr);
|
||||||
loop = isc_loop_main(loopmgr);
|
loop = isc_loop_main(loopmgr);
|
||||||
|
|
||||||
result = dst_lib_init(mctx, NULL);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
fatal("dst_lib_init failed: %d", result);
|
|
||||||
}
|
|
||||||
|
|
||||||
parse_args(argc, argv);
|
parse_args(argc, argv);
|
||||||
|
|
||||||
CHECK(setup_style());
|
CHECK(setup_style());
|
||||||
@@ -2266,9 +2260,6 @@ cleanup:
|
|||||||
dns_master_styledestroy(&style, mctx);
|
dns_master_styledestroy(&style, mctx);
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_log_destroy(&lctx);
|
|
||||||
dst_lib_destroy();
|
|
||||||
|
|
||||||
isc_managers_destroy(&mctx, &loopmgr, &netmgr);
|
isc_managers_destroy(&mctx, &loopmgr, &netmgr);
|
||||||
|
|
||||||
return (0);
|
return (0);
|
||||||
|
|||||||
@@ -337,6 +337,18 @@ assign values to options like the timeout interval. They have the form
|
|||||||
they are replaced by the string ``[omitted]`` or, in the DNSKEY case, the
|
they are replaced by the string ``[omitted]`` or, in the DNSKEY case, the
|
||||||
key ID is displayed as the replacement, e.g. ``[ key id = value ]``.
|
key ID is displayed as the replacement, e.g. ``[ key id = value ]``.
|
||||||
|
|
||||||
|
.. option:: +restarts
|
||||||
|
|
||||||
|
When name server mode (``delv +ns``) is in use, this option sets the
|
||||||
|
maximum number of CNAME queries to follow before terminating resolution.
|
||||||
|
This prevents ``delv`` from hanging in the event of a CNAME loop.
|
||||||
|
The default is 11.
|
||||||
|
|
||||||
|
.. option:: +maxqueries
|
||||||
|
|
||||||
|
This option specifies the maximum number of queries to send to resolve
|
||||||
|
a name before giving up. The default is 32.
|
||||||
|
|
||||||
.. option:: +trust, +notrust
|
.. option:: +trust, +notrust
|
||||||
|
|
||||||
This option controls whether to display the trust level when printing a record.
|
This option controls whether to display the trust level when printing a record.
|
||||||
|
|||||||
+4
-9
@@ -111,7 +111,7 @@ usage(void) {
|
|||||||
fprintf(stderr, "Press <Help> for complete list of options\n");
|
fprintf(stderr, "Press <Help> for complete list of options\n");
|
||||||
}
|
}
|
||||||
#else /* if TARGET_OS_IPHONE */
|
#else /* if TARGET_OS_IPHONE */
|
||||||
noreturn static void
|
ISC_NORETURN static void
|
||||||
usage(void);
|
usage(void);
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -748,8 +748,7 @@ printmessage(dig_query_t *query, const isc_buffer_t *msgbuf, dns_message_t *msg,
|
|||||||
char *hash;
|
char *hash;
|
||||||
int pf;
|
int pf;
|
||||||
|
|
||||||
printf("-\n");
|
printf("- type: MESSAGE\n");
|
||||||
printf(" type: MESSAGE\n");
|
|
||||||
printf(" message:\n");
|
printf(" message:\n");
|
||||||
|
|
||||||
if (isquery) {
|
if (isquery) {
|
||||||
@@ -3306,8 +3305,7 @@ dig_error(const char *format, ...) {
|
|||||||
va_list args;
|
va_list args;
|
||||||
|
|
||||||
if (yaml) {
|
if (yaml) {
|
||||||
printf("-\n");
|
printf("- type: DIG_ERROR\n");
|
||||||
printf(" type: DIG_ERROR\n");
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Print an indent before a literal block quote.
|
* Print an indent before a literal block quote.
|
||||||
@@ -3324,10 +3322,7 @@ dig_error(const char *format, ...) {
|
|||||||
va_start(args, format);
|
va_start(args, format);
|
||||||
vprintf(format, args);
|
vprintf(format, args);
|
||||||
va_end(args);
|
va_end(args);
|
||||||
|
printf("\n"); /* We get the error without a newline */
|
||||||
if (!yaml) {
|
|
||||||
printf("\n");
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
static void
|
static void
|
||||||
|
|||||||
+22
-33
@@ -61,7 +61,6 @@
|
|||||||
|
|
||||||
#include <dns/byaddr.h>
|
#include <dns/byaddr.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/log.h>
|
|
||||||
#include <dns/message.h>
|
#include <dns/message.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/opcode.h>
|
#include <dns/opcode.h>
|
||||||
@@ -93,14 +92,12 @@ static bool cancel_now = false;
|
|||||||
|
|
||||||
bool check_ra = false, have_ipv4 = false, have_ipv6 = false,
|
bool check_ra = false, have_ipv4 = false, have_ipv6 = false,
|
||||||
specified_source = false, free_now = false, usesearch = false,
|
specified_source = false, free_now = false, usesearch = false,
|
||||||
showsearch = false, is_dst_up = false, keep_open = false, verbose = false,
|
showsearch = false, keep_open = false, verbose = false, yaml = false;
|
||||||
yaml = false;
|
|
||||||
in_port_t port = 53;
|
in_port_t port = 53;
|
||||||
bool port_set = false;
|
bool port_set = false;
|
||||||
unsigned int timeout = 0;
|
unsigned int timeout = 0;
|
||||||
unsigned int extrabytes;
|
unsigned int extrabytes;
|
||||||
isc_mem_t *mctx = NULL;
|
isc_mem_t *mctx = NULL;
|
||||||
isc_log_t *lctx = NULL;
|
|
||||||
isc_nm_t *netmgr = NULL;
|
isc_nm_t *netmgr = NULL;
|
||||||
isc_loopmgr_t *loopmgr = NULL;
|
isc_loopmgr_t *loopmgr = NULL;
|
||||||
isc_loop_t *mainloop = NULL;
|
isc_loop_t *mainloop = NULL;
|
||||||
@@ -1097,7 +1094,7 @@ read_confkey(void) {
|
|||||||
return (ISC_R_FILENOTFOUND);
|
return (ISC_R_FILENOTFOUND);
|
||||||
}
|
}
|
||||||
|
|
||||||
result = cfg_parser_create(mctx, NULL, &pctx);
|
result = cfg_parser_create(mctx, &pctx);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
goto cleanup;
|
goto cleanup;
|
||||||
}
|
}
|
||||||
@@ -1362,22 +1359,15 @@ setup_libs(void) {
|
|||||||
|
|
||||||
isc_managers_create(&mctx, 1, &loopmgr, &netmgr);
|
isc_managers_create(&mctx, 1, &loopmgr, &netmgr);
|
||||||
|
|
||||||
isc_log_create(mctx, &lctx, &logconfig);
|
logconfig = isc_logconfig_get();
|
||||||
isc_log_setcontext(lctx);
|
isc_log_createandusechannel(logconfig, "debug", ISC_LOG_TOFILEDESC,
|
||||||
dns_log_init(lctx);
|
ISC_LOG_DYNAMIC, ISC_LOGDESTINATION_STDERR,
|
||||||
dns_log_setcontext(lctx);
|
ISC_LOG_PRINTTIME, ISC_LOGCATEGORY_DEFAULT,
|
||||||
|
ISC_LOGMODULE_DEFAULT);
|
||||||
result = isc_log_usechannel(logconfig, "default_debug", NULL, NULL);
|
isc_log_setdebuglevel(0);
|
||||||
check_result(result, "isc_log_usechannel");
|
|
||||||
|
|
||||||
isc_log_setdebuglevel(lctx, 0);
|
|
||||||
|
|
||||||
isc_mem_setname(mctx, "dig");
|
isc_mem_setname(mctx, "dig");
|
||||||
mainloop = isc_loop_main(loopmgr);
|
mainloop = isc_loop_main(loopmgr);
|
||||||
|
|
||||||
result = dst_lib_init(mctx, NULL);
|
|
||||||
check_result(result, "dst_lib_init");
|
|
||||||
is_dst_up = true;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
typedef struct dig_ednsoptname {
|
typedef struct dig_ednsoptname {
|
||||||
@@ -3231,7 +3221,7 @@ udp_ready(isc_nmhandle_t *handle, isc_result_t eresult, void *arg) {
|
|||||||
start_udp(next);
|
start_udp(next);
|
||||||
check_if_done();
|
check_if_done();
|
||||||
} else {
|
} else {
|
||||||
dighost_error("no servers could be reached\n");
|
dighost_error("no servers could be reached");
|
||||||
clear_current_lookup();
|
clear_current_lookup();
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -3423,10 +3413,10 @@ force_next(dig_query_t *query) {
|
|||||||
isc_netaddr_fromsockaddr(&netaddr, &query->sockaddr);
|
isc_netaddr_fromsockaddr(&netaddr, &query->sockaddr);
|
||||||
isc_netaddr_format(&netaddr, buf, sizeof(buf));
|
isc_netaddr_format(&netaddr, buf, sizeof(buf));
|
||||||
|
|
||||||
dighost_error("no response from %s\n", buf);
|
dighost_error("no response from %s", buf);
|
||||||
} else {
|
} else {
|
||||||
printf("%s", l->cmdline);
|
printf("%s", l->cmdline);
|
||||||
dighost_error("no servers could be reached\n");
|
dighost_error("no servers could be reached");
|
||||||
}
|
}
|
||||||
|
|
||||||
if (exitcode < 9) {
|
if (exitcode < 9) {
|
||||||
@@ -3650,7 +3640,7 @@ tcp_connected(isc_nmhandle_t *handle, isc_result_t eresult, void *arg) {
|
|||||||
start_tcp(next);
|
start_tcp(next);
|
||||||
check_if_done();
|
check_if_done();
|
||||||
} else {
|
} else {
|
||||||
dighost_error("no servers could be reached\n");
|
dighost_error("no servers could be reached");
|
||||||
clear_current_lookup();
|
clear_current_lookup();
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -4103,7 +4093,7 @@ recv_done(isc_nmhandle_t *handle, isc_result_t eresult, isc_region_t *region,
|
|||||||
* and cancel the lookup.
|
* and cancel the lookup.
|
||||||
*/
|
*/
|
||||||
printf("%s", l->cmdline);
|
printf("%s", l->cmdline);
|
||||||
dighost_error("no servers could be reached\n");
|
dighost_error("no servers could be reached");
|
||||||
|
|
||||||
if (exitcode < 9) {
|
if (exitcode < 9) {
|
||||||
exitcode = 9;
|
exitcode = 9;
|
||||||
@@ -4237,7 +4227,15 @@ recv_done(isc_nmhandle_t *handle, isc_result_t eresult, isc_region_t *region,
|
|||||||
goto keep_query;
|
goto keep_query;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (msg->counts[DNS_SECTION_QUESTION] != 0) {
|
if (msg->counts[DNS_SECTION_QUESTION] == 0) {
|
||||||
|
if (l->doing_xfr) {
|
||||||
|
if (query->msg_count == 0) {
|
||||||
|
dighost_warning("missing question section");
|
||||||
|
}
|
||||||
|
} else if (!l->header_only && msg->opcode == dns_opcode_query) {
|
||||||
|
dighost_warning("missing question section");
|
||||||
|
}
|
||||||
|
} else {
|
||||||
match = true;
|
match = true;
|
||||||
for (result = dns_message_firstname(msg, DNS_SECTION_QUESTION);
|
for (result = dns_message_firstname(msg, DNS_SECTION_QUESTION);
|
||||||
result == ISC_R_SUCCESS && match;
|
result == ISC_R_SUCCESS && match;
|
||||||
@@ -4714,12 +4712,6 @@ cleanup_openssl_refs(void) {
|
|||||||
debug("freeing SIG(0) key %p", sig0key);
|
debug("freeing SIG(0) key %p", sig0key);
|
||||||
dst_key_free(&sig0key);
|
dst_key_free(&sig0key);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (is_dst_up) {
|
|
||||||
debug("destroy DST lib");
|
|
||||||
dst_lib_destroy();
|
|
||||||
is_dst_up = false;
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/*%
|
/*%
|
||||||
@@ -4750,9 +4742,6 @@ destroy_libs(void) {
|
|||||||
isc_buffer_free(&namebuf);
|
isc_buffer_free(&namebuf);
|
||||||
}
|
}
|
||||||
|
|
||||||
debug("Removing log context");
|
|
||||||
isc_log_destroy(&lctx);
|
|
||||||
|
|
||||||
debug("Destroy memory");
|
debug("Destroy memory");
|
||||||
if (memdebugging != 0) {
|
if (memdebugging != 0) {
|
||||||
isc_mem_stats(mctx, stderr);
|
isc_mem_stats(mctx, stderr);
|
||||||
|
|||||||
+2
-2
@@ -293,13 +293,13 @@ getaddresses(dig_lookup_t *lookup, const char *host, isc_result_t *resultp);
|
|||||||
isc_result_t
|
isc_result_t
|
||||||
get_reverse(char *reverse, size_t len, char *value, bool strict);
|
get_reverse(char *reverse, size_t len, char *value, bool strict);
|
||||||
|
|
||||||
noreturn void
|
ISC_NORETURN void
|
||||||
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||||
|
|
||||||
void
|
void
|
||||||
warn(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
warn(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||||
|
|
||||||
noreturn void
|
ISC_NORETURN void
|
||||||
digexit(void);
|
digexit(void);
|
||||||
|
|
||||||
void
|
void
|
||||||
|
|||||||
+2
-1
@@ -99,7 +99,7 @@ rcode_totext(dns_rcode_t rcode) {
|
|||||||
return (totext.deconsttext);
|
return (totext.deconsttext);
|
||||||
}
|
}
|
||||||
|
|
||||||
noreturn static void
|
ISC_NORETURN static void
|
||||||
show_usage(void);
|
show_usage(void);
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -183,6 +183,7 @@ retry:
|
|||||||
result = dns_rdata_totext(rdata, NULL, b);
|
result = dns_rdata_totext(rdata, NULL, b);
|
||||||
if (result == ISC_R_NOSPACE) {
|
if (result == ISC_R_NOSPACE) {
|
||||||
isc_buffer_free(&b);
|
isc_buffer_free(&b);
|
||||||
|
INSIST(bufsize <= (UINT_MAX / 2));
|
||||||
bufsize *= 2;
|
bufsize *= 2;
|
||||||
goto retry;
|
goto retry;
|
||||||
}
|
}
|
||||||
|
|||||||
+2
-1
@@ -189,6 +189,7 @@ printrdata(dns_rdata_t *rdata) {
|
|||||||
check_result(result, "dns_rdata_totext");
|
check_result(result, "dns_rdata_totext");
|
||||||
}
|
}
|
||||||
isc_buffer_free(&b);
|
isc_buffer_free(&b);
|
||||||
|
INSIST(size <= (UINT_MAX / 2));
|
||||||
size *= 2;
|
size *= 2;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -835,7 +836,7 @@ fgets_next_command(void *arg) {
|
|||||||
cmdline = fgets(cmdlinebuf, COMMSIZE, stdin);
|
cmdline = fgets(cmdlinebuf, COMMSIZE, stdin);
|
||||||
}
|
}
|
||||||
|
|
||||||
noreturn static void
|
ISC_NORETURN static void
|
||||||
usage(void);
|
usage(void);
|
||||||
|
|
||||||
static void
|
static void
|
||||||
|
|||||||
+3
-19
@@ -29,6 +29,7 @@
|
|||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
#include <isc/serial.h>
|
#include <isc/serial.h>
|
||||||
@@ -43,7 +44,6 @@
|
|||||||
#include <dns/ds.h>
|
#include <dns/ds.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
#include <dns/log.h>
|
|
||||||
#include <dns/master.h>
|
#include <dns/master.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/rdata.h>
|
#include <dns/rdata.h>
|
||||||
@@ -63,7 +63,6 @@ const char *program = "dnssec-cds";
|
|||||||
/*
|
/*
|
||||||
* Infrastructure
|
* Infrastructure
|
||||||
*/
|
*/
|
||||||
static isc_log_t *lctx = NULL;
|
|
||||||
static isc_mem_t *mctx = NULL;
|
static isc_mem_t *mctx = NULL;
|
||||||
|
|
||||||
/*
|
/*
|
||||||
@@ -144,7 +143,6 @@ static dns_dbnode_t *parent_node = NULL;
|
|||||||
static dns_db_t *update_db = NULL;
|
static dns_db_t *update_db = NULL;
|
||||||
static dns_dbnode_t *update_node = NULL;
|
static dns_dbnode_t *update_node = NULL;
|
||||||
static dns_dbversion_t *update_version = NULL;
|
static dns_dbversion_t *update_version = NULL;
|
||||||
static bool cleanup_dst = false;
|
|
||||||
static bool print_mem_stats = false;
|
static bool print_mem_stats = false;
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -1029,7 +1027,7 @@ nsdiff(uint32_t ttl, dns_rdataset_t *oldset, dns_rdataset_t *newset) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
noreturn static void
|
ISC_NORETURN static void
|
||||||
usage(void);
|
usage(void);
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -1071,12 +1069,6 @@ cleanup(void) {
|
|||||||
free_keytable(&new_key_tbl);
|
free_keytable(&new_key_tbl);
|
||||||
}
|
}
|
||||||
free_all_sets();
|
free_all_sets();
|
||||||
if (lctx != NULL) {
|
|
||||||
cleanup_logging(&lctx);
|
|
||||||
}
|
|
||||||
if (cleanup_dst) {
|
|
||||||
dst_lib_destroy();
|
|
||||||
}
|
|
||||||
if (mctx != NULL) {
|
if (mctx != NULL) {
|
||||||
if (print_mem_stats && verbose > 10) {
|
if (print_mem_stats && verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
@@ -1090,7 +1082,6 @@ main(int argc, char *argv[]) {
|
|||||||
const char *child_path = NULL;
|
const char *child_path = NULL;
|
||||||
const char *ds_path = NULL;
|
const char *ds_path = NULL;
|
||||||
const char *inplace = NULL;
|
const char *inplace = NULL;
|
||||||
isc_result_t result;
|
|
||||||
bool prefer_cdnskey = false;
|
bool prefer_cdnskey = false;
|
||||||
bool nsupdate = false;
|
bool nsupdate = false;
|
||||||
uint32_t ttl = 0;
|
uint32_t ttl = 0;
|
||||||
@@ -1178,14 +1169,7 @@ main(int argc, char *argv[]) {
|
|||||||
dtype[0] = DNS_DSDIGEST_SHA256;
|
dtype[0] = DNS_DSDIGEST_SHA256;
|
||||||
}
|
}
|
||||||
|
|
||||||
setup_logging(mctx, &lctx);
|
setup_logging();
|
||||||
|
|
||||||
result = dst_lib_init(mctx, NULL);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
fatal("could not initialize dst: %s",
|
|
||||||
isc_result_totext(result));
|
|
||||||
}
|
|
||||||
cleanup_dst = true;
|
|
||||||
|
|
||||||
if (ds_path == NULL) {
|
if (ds_path == NULL) {
|
||||||
fatal("missing -d DS pathname");
|
fatal("missing -d DS pathname");
|
||||||
|
|||||||
@@ -22,6 +22,7 @@
|
|||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
#include <isc/string.h>
|
#include <isc/string.h>
|
||||||
@@ -33,7 +34,6 @@
|
|||||||
#include <dns/ds.h>
|
#include <dns/ds.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
#include <dns/log.h>
|
|
||||||
#include <dns/master.h>
|
#include <dns/master.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/rdata.h>
|
#include <dns/rdata.h>
|
||||||
@@ -324,7 +324,7 @@ emits(bool showall, bool cds, dns_rdata_t *rdata) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
noreturn static void
|
ISC_NORETURN static void
|
||||||
usage(void);
|
usage(void);
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -368,7 +368,6 @@ main(int argc, char **argv) {
|
|||||||
bool usekeyset = false;
|
bool usekeyset = false;
|
||||||
bool showall = false;
|
bool showall = false;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
isc_log_t *log = NULL;
|
|
||||||
dns_rdataset_t rdataset;
|
dns_rdataset_t rdataset;
|
||||||
dns_rdata_t rdata;
|
dns_rdata_t rdata;
|
||||||
|
|
||||||
@@ -489,13 +488,7 @@ main(int argc, char **argv) {
|
|||||||
fatal("extraneous arguments");
|
fatal("extraneous arguments");
|
||||||
}
|
}
|
||||||
|
|
||||||
result = dst_lib_init(mctx, NULL);
|
setup_logging();
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
fatal("could not initialize dst: %s",
|
|
||||||
isc_result_totext(result));
|
|
||||||
}
|
|
||||||
|
|
||||||
setup_logging(mctx, &log);
|
|
||||||
|
|
||||||
dns_rdataset_init(&rdataset);
|
dns_rdataset_init(&rdataset);
|
||||||
|
|
||||||
@@ -548,8 +541,6 @@ main(int argc, char **argv) {
|
|||||||
if (dns_rdataset_isassociated(&rdataset)) {
|
if (dns_rdataset_isassociated(&rdataset)) {
|
||||||
dns_rdataset_disassociate(&rdataset);
|
dns_rdataset_disassociate(&rdataset);
|
||||||
}
|
}
|
||||||
cleanup_logging(&log);
|
|
||||||
dst_lib_destroy();
|
|
||||||
if (verbose > 10) {
|
if (verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -20,6 +20,7 @@
|
|||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
#include <isc/string.h>
|
#include <isc/string.h>
|
||||||
@@ -31,7 +32,6 @@
|
|||||||
#include <dns/ds.h>
|
#include <dns/ds.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
#include <dns/log.h>
|
|
||||||
#include <dns/master.h>
|
#include <dns/master.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/rdata.h>
|
#include <dns/rdata.h>
|
||||||
@@ -262,7 +262,7 @@ emit(const char *dir, dns_rdata_t *rdata) {
|
|||||||
dst_key_free(&key);
|
dst_key_free(&key);
|
||||||
}
|
}
|
||||||
|
|
||||||
noreturn static void
|
ISC_NORETURN static void
|
||||||
usage(void);
|
usage(void);
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -299,7 +299,6 @@ main(int argc, char **argv) {
|
|||||||
char *endp;
|
char *endp;
|
||||||
int ch;
|
int ch;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
isc_log_t *log = NULL;
|
|
||||||
dns_rdataset_t rdataset;
|
dns_rdataset_t rdataset;
|
||||||
dns_rdata_t rdata;
|
dns_rdata_t rdata;
|
||||||
isc_stdtime_t now = isc_stdtime_now();
|
isc_stdtime_t now = isc_stdtime_now();
|
||||||
@@ -408,13 +407,7 @@ main(int argc, char **argv) {
|
|||||||
fatal("extraneous arguments");
|
fatal("extraneous arguments");
|
||||||
}
|
}
|
||||||
|
|
||||||
result = dst_lib_init(mctx, NULL);
|
setup_logging();
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
fatal("could not initialize dst: %s",
|
|
||||||
isc_result_totext(result));
|
|
||||||
}
|
|
||||||
|
|
||||||
setup_logging(mctx, &log);
|
|
||||||
|
|
||||||
dns_rdataset_init(&rdataset);
|
dns_rdataset_init(&rdataset);
|
||||||
|
|
||||||
@@ -458,8 +451,6 @@ main(int argc, char **argv) {
|
|||||||
if (dns_rdataset_isassociated(&rdataset)) {
|
if (dns_rdataset_isassociated(&rdataset)) {
|
||||||
dns_rdataset_disassociate(&rdataset);
|
dns_rdataset_disassociate(&rdataset);
|
||||||
}
|
}
|
||||||
cleanup_logging(&log);
|
|
||||||
dst_lib_destroy();
|
|
||||||
if (verbose > 10) {
|
if (verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -21,6 +21,7 @@
|
|||||||
#include <isc/attributes.h>
|
#include <isc/attributes.h>
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/region.h>
|
#include <isc/region.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
@@ -30,7 +31,6 @@
|
|||||||
#include <dns/dnssec.h>
|
#include <dns/dnssec.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
#include <dns/log.h>
|
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/rdataclass.h>
|
#include <dns/rdataclass.h>
|
||||||
#include <dns/secalg.h>
|
#include <dns/secalg.h>
|
||||||
@@ -43,7 +43,9 @@
|
|||||||
|
|
||||||
const char *program = "dnssec-keyfromlabel";
|
const char *program = "dnssec-keyfromlabel";
|
||||||
|
|
||||||
noreturn static void
|
static uint16_t tag_min = 0, tag_max = 0xffff;
|
||||||
|
|
||||||
|
ISC_NORETURN static void
|
||||||
usage(void);
|
usage(void);
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -63,13 +65,12 @@ usage(void) {
|
|||||||
" ED25519 | ED448\n");
|
" ED25519 | ED448\n");
|
||||||
fprintf(stderr, " -3: use NSEC3-capable algorithm\n");
|
fprintf(stderr, " -3: use NSEC3-capable algorithm\n");
|
||||||
fprintf(stderr, " -c class (default: IN)\n");
|
fprintf(stderr, " -c class (default: IN)\n");
|
||||||
fprintf(stderr, " -E <engine>:\n");
|
|
||||||
fprintf(stderr, " name of an OpenSSL engine to use\n");
|
|
||||||
fprintf(stderr, " -f keyflag: KSK | REVOKE\n");
|
fprintf(stderr, " -f keyflag: KSK | REVOKE\n");
|
||||||
fprintf(stderr, " -K directory: directory in which to place "
|
fprintf(stderr, " -K directory: directory in which to place "
|
||||||
"key files\n");
|
"key files\n");
|
||||||
fprintf(stderr, " -k: generate a TYPE=KEY key\n");
|
fprintf(stderr, " -k: generate a TYPE=KEY key\n");
|
||||||
fprintf(stderr, " -L ttl: default key TTL\n");
|
fprintf(stderr, " -L ttl: default key TTL\n");
|
||||||
|
fprintf(stderr, " -M <min>:<max>: allowed Key ID range\n");
|
||||||
fprintf(stderr, " -n nametype: ZONE | HOST | ENTITY | USER | "
|
fprintf(stderr, " -n nametype: ZONE | HOST | ENTITY | USER | "
|
||||||
"OTHER\n");
|
"OTHER\n");
|
||||||
fprintf(stderr, " (DNSKEY generation defaults to ZONE\n");
|
fprintf(stderr, " (DNSKEY generation defaults to ZONE\n");
|
||||||
@@ -112,7 +113,6 @@ main(int argc, char **argv) {
|
|||||||
const char *directory = NULL;
|
const char *directory = NULL;
|
||||||
const char *predecessor = NULL;
|
const char *predecessor = NULL;
|
||||||
dst_key_t *prevkey = NULL;
|
dst_key_t *prevkey = NULL;
|
||||||
const char *engine = NULL;
|
|
||||||
char *classname = NULL;
|
char *classname = NULL;
|
||||||
char *endp;
|
char *endp;
|
||||||
dst_key_t *key = NULL;
|
dst_key_t *key = NULL;
|
||||||
@@ -128,7 +128,6 @@ main(int argc, char **argv) {
|
|||||||
isc_textregion_t r;
|
isc_textregion_t r;
|
||||||
char filename[255];
|
char filename[255];
|
||||||
isc_buffer_t buf;
|
isc_buffer_t buf;
|
||||||
isc_log_t *log = NULL;
|
|
||||||
dns_rdataclass_t rdclass;
|
dns_rdataclass_t rdclass;
|
||||||
int options = DST_TYPE_PRIVATE | DST_TYPE_PUBLIC;
|
int options = DST_TYPE_PRIVATE | DST_TYPE_PUBLIC;
|
||||||
char *label = NULL;
|
char *label = NULL;
|
||||||
@@ -160,7 +159,7 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
isc_commandline_errprint = false;
|
isc_commandline_errprint = false;
|
||||||
|
|
||||||
#define CMDLINE_FLAGS "3A:a:Cc:D:E:Ff:GhI:i:kK:L:l:n:P:p:R:S:t:v:Vy"
|
#define CMDLINE_FLAGS "3A:a:Cc:D:E:Ff:GhI:i:kK:L:l:M:n:P:p:R:S:t:v:Vy"
|
||||||
while ((ch = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != -1) {
|
while ((ch = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != -1) {
|
||||||
switch (ch) {
|
switch (ch) {
|
||||||
case '3':
|
case '3':
|
||||||
@@ -176,7 +175,7 @@ main(int argc, char **argv) {
|
|||||||
classname = isc_commandline_argument;
|
classname = isc_commandline_argument;
|
||||||
break;
|
break;
|
||||||
case 'E':
|
case 'E':
|
||||||
engine = isc_commandline_argument;
|
fatal("%s", isc_result_totext(DST_R_NOENGINE));
|
||||||
break;
|
break;
|
||||||
case 'f':
|
case 'f':
|
||||||
c = (unsigned char)(isc_commandline_argument[0]);
|
c = (unsigned char)(isc_commandline_argument[0]);
|
||||||
@@ -207,6 +206,20 @@ main(int argc, char **argv) {
|
|||||||
case 'l':
|
case 'l':
|
||||||
label = isc_mem_strdup(mctx, isc_commandline_argument);
|
label = isc_mem_strdup(mctx, isc_commandline_argument);
|
||||||
break;
|
break;
|
||||||
|
case 'M': {
|
||||||
|
unsigned long ul;
|
||||||
|
tag_min = ul = strtoul(isc_commandline_argument, &endp,
|
||||||
|
10);
|
||||||
|
if (*endp != ':' || ul > 0xffff) {
|
||||||
|
fatal("-M range invalid");
|
||||||
|
}
|
||||||
|
tag_max = ul = strtoul(endp + 1, &endp, 10);
|
||||||
|
if (*endp != '\0' || ul > 0xffff || tag_max <= tag_min)
|
||||||
|
{
|
||||||
|
fatal("-M range invalid");
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
}
|
||||||
case 'n':
|
case 'n':
|
||||||
nametype = isc_commandline_argument;
|
nametype = isc_commandline_argument;
|
||||||
break;
|
break;
|
||||||
@@ -335,12 +348,7 @@ main(int argc, char **argv) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
ret = dst_lib_init(mctx, engine);
|
setup_logging();
|
||||||
if (ret != ISC_R_SUCCESS) {
|
|
||||||
fatal("could not initialize dst: %s", isc_result_totext(ret));
|
|
||||||
}
|
|
||||||
|
|
||||||
setup_logging(mctx, &log);
|
|
||||||
|
|
||||||
if (predecessor == NULL) {
|
if (predecessor == NULL) {
|
||||||
if (label == NULL) {
|
if (label == NULL) {
|
||||||
@@ -595,8 +603,8 @@ main(int argc, char **argv) {
|
|||||||
isc_buffer_init(&buf, filename, sizeof(filename) - 1);
|
isc_buffer_init(&buf, filename, sizeof(filename) - 1);
|
||||||
|
|
||||||
/* associate the key */
|
/* associate the key */
|
||||||
ret = dst_key_fromlabel(name, alg, flags, protocol, rdclass, engine,
|
ret = dst_key_fromlabel(name, alg, flags, protocol, rdclass, label,
|
||||||
label, NULL, mctx, &key);
|
NULL, mctx, &key);
|
||||||
|
|
||||||
if (ret != ISC_R_SUCCESS) {
|
if (ret != ISC_R_SUCCESS) {
|
||||||
char namestr[DNS_NAME_FORMATSIZE];
|
char namestr[DNS_NAME_FORMATSIZE];
|
||||||
@@ -686,7 +694,8 @@ main(int argc, char **argv) {
|
|||||||
* is a risk of ID collision due to this key or another key
|
* is a risk of ID collision due to this key or another key
|
||||||
* being revoked.
|
* being revoked.
|
||||||
*/
|
*/
|
||||||
if (key_collision(key, name, directory, mctx, &exact)) {
|
if (key_collision(key, name, directory, mctx, tag_min, tag_max, &exact))
|
||||||
|
{
|
||||||
isc_buffer_clear(&buf);
|
isc_buffer_clear(&buf);
|
||||||
ret = dst_key_buildfilename(key, 0, directory, &buf);
|
ret = dst_key_buildfilename(key, 0, directory, &buf);
|
||||||
if (ret != ISC_R_SUCCESS) {
|
if (ret != ISC_R_SUCCESS) {
|
||||||
@@ -731,8 +740,6 @@ main(int argc, char **argv) {
|
|||||||
dst_key_free(&prevkey);
|
dst_key_free(&prevkey);
|
||||||
}
|
}
|
||||||
|
|
||||||
cleanup_logging(&log);
|
|
||||||
dst_lib_destroy();
|
|
||||||
if (verbose > 10) {
|
if (verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ dnssec-keyfromlabel - DNSSEC key generation tool
|
|||||||
Synopsis
|
Synopsis
|
||||||
~~~~~~~~
|
~~~~~~~~
|
||||||
|
|
||||||
:program:`dnssec-keyfromlabel` {**-l** label} [**-3**] [**-a** algorithm] [**-A** date/offset] [**-c** class] [**-D** date/offset] [**-D** sync date/offset] [**-E** engine] [**-f** flag] [**-G**] [**-I** date/offset] [**-i** interval] [**-k**] [**-K** directory] [**-L** ttl] [**-n** nametype] [**-P** date/offset] [**-P** sync date/offset] [**-p** protocol] [**-R** date/offset] [**-S** key] [**-t** type] [**-v** level] [**-V**] [**-y**] {name}
|
:program:`dnssec-keyfromlabel` {**-l** label} [**-3**] [**-a** algorithm] [**-A** date/offset] [**-c** class] [**-D** date/offset] [**-D** sync date/offset] [**-f** flag] [**-G**] [**-I** date/offset] [**-i** interval] [**-k**] [**-K** directory] [**-L** ttl] [**-M** tag_min:tag_max] [**-n** nametype] [**-P** date/offset] [**-P** sync date/offset] [**-p** protocol] [**-R** date/offset] [**-S** key] [**-t** type] [**-v** level] [**-V**] [**-y**] {name}
|
||||||
|
|
||||||
Description
|
Description
|
||||||
~~~~~~~~~~~
|
~~~~~~~~~~~
|
||||||
@@ -63,22 +63,12 @@ Options
|
|||||||
versions, then the NSEC3 version is used; for example,
|
versions, then the NSEC3 version is used; for example,
|
||||||
``dnssec-keygen -3a RSASHA1`` specifies the NSEC3RSASHA1 algorithm.
|
``dnssec-keygen -3a RSASHA1`` specifies the NSEC3RSASHA1 algorithm.
|
||||||
|
|
||||||
.. option:: -E engine
|
|
||||||
|
|
||||||
This option specifies the cryptographic hardware to use.
|
|
||||||
|
|
||||||
When BIND 9 is built with OpenSSL, this needs to be set to the OpenSSL
|
|
||||||
engine identifier that drives the cryptographic accelerator or
|
|
||||||
hardware service module (usually ``pkcs11``).
|
|
||||||
|
|
||||||
.. option:: -l label
|
.. option:: -l label
|
||||||
|
|
||||||
This option specifies the label for a key pair in the crypto hardware.
|
This option specifies the label for a key pair in the crypto hardware.
|
||||||
|
|
||||||
When BIND 9 is built with OpenSSL-based PKCS#11 support, the label is
|
When BIND 9 is built with OpenSSL-based PKCS#11 support, the label is
|
||||||
an arbitrary string that identifies a particular key. It may be
|
an arbitrary string that identifies a particular key.
|
||||||
preceded by an optional OpenSSL engine name, followed by a colon, as
|
|
||||||
in ``pkcs11:keylabel``.
|
|
||||||
|
|
||||||
.. option:: -n nametype
|
.. option:: -n nametype
|
||||||
|
|
||||||
@@ -133,6 +123,18 @@ Options
|
|||||||
place, in which case the existing TTL would take precedence. Setting
|
place, in which case the existing TTL would take precedence. Setting
|
||||||
the default TTL to ``0`` or ``none`` removes it.
|
the default TTL to ``0`` or ``none`` removes it.
|
||||||
|
|
||||||
|
.. option:: -M tag_min:tag_max
|
||||||
|
|
||||||
|
This option sets the range of key tag values
|
||||||
|
that ``dnssec-keyfromlabel`` will accept. If the key tag of the new
|
||||||
|
key or the key tag of the revoked version of the new key is
|
||||||
|
outside this range, the new key will be rejected. This is
|
||||||
|
designed to be used when generating keys in a multi-signer
|
||||||
|
scenario, where each operator is given a range of key tags to
|
||||||
|
prevent collisions among different operators. The valid
|
||||||
|
values for ``tag_min`` and ``tag_max`` are [0..65535]. The
|
||||||
|
default allows all key tag values to be accepted.
|
||||||
|
|
||||||
.. option:: -p protocol
|
.. option:: -p protocol
|
||||||
|
|
||||||
This option sets the protocol value for the key. The protocol is a number between
|
This option sets the protocol value for the key. The protocol is a number between
|
||||||
|
|||||||
+42
-31
@@ -39,6 +39,7 @@
|
|||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/fips.h>
|
#include <isc/fips.h>
|
||||||
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/region.h>
|
#include <isc/region.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
@@ -49,14 +50,13 @@
|
|||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/kasp.h>
|
#include <dns/kasp.h>
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
#include <dns/log.h>
|
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/rdataclass.h>
|
#include <dns/rdataclass.h>
|
||||||
#include <dns/secalg.h>
|
#include <dns/secalg.h>
|
||||||
|
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L && OPENSSL_API_LEVEL >= 30000
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
#include <openssl/err.h>
|
#include <openssl/err.h>
|
||||||
#include <openssl/provider.h>
|
#include <openssl/provider.h>
|
||||||
#endif
|
#endif
|
||||||
@@ -72,9 +72,7 @@ const char *program = "dnssec-keygen";
|
|||||||
static int min_rsa = 1024;
|
static int min_rsa = 1024;
|
||||||
static int min_dh = 128;
|
static int min_dh = 128;
|
||||||
|
|
||||||
isc_log_t *lctx = NULL;
|
ISC_NORETURN static void
|
||||||
|
|
||||||
noreturn static void
|
|
||||||
usage(void);
|
usage(void);
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -91,6 +89,8 @@ struct keygen_ctx {
|
|||||||
char *type;
|
char *type;
|
||||||
int protocol;
|
int protocol;
|
||||||
int size;
|
int size;
|
||||||
|
uint16_t tag_min;
|
||||||
|
uint16_t tag_max;
|
||||||
int signatory;
|
int signatory;
|
||||||
dns_rdataclass_t rdclass;
|
dns_rdataclass_t rdclass;
|
||||||
int options;
|
int options;
|
||||||
@@ -176,11 +176,10 @@ usage(void) {
|
|||||||
fprintf(stderr, " (DNSKEY generation defaults to ZONE)\n");
|
fprintf(stderr, " (DNSKEY generation defaults to ZONE)\n");
|
||||||
fprintf(stderr, " -c <class>: (default: IN)\n");
|
fprintf(stderr, " -c <class>: (default: IN)\n");
|
||||||
fprintf(stderr, " -d <digest bits> (0 => max, default)\n");
|
fprintf(stderr, " -d <digest bits> (0 => max, default)\n");
|
||||||
fprintf(stderr, " -E <engine>:\n");
|
|
||||||
fprintf(stderr, " name of an OpenSSL engine to use\n");
|
|
||||||
fprintf(stderr, " -f <keyflag>: ZSK | KSK | REVOKE\n");
|
fprintf(stderr, " -f <keyflag>: ZSK | KSK | REVOKE\n");
|
||||||
fprintf(stderr, " -F: FIPS mode\n");
|
fprintf(stderr, " -F: FIPS mode\n");
|
||||||
fprintf(stderr, " -L <ttl>: default key TTL\n");
|
fprintf(stderr, " -L <ttl>: default key TTL\n");
|
||||||
|
fprintf(stderr, " -M <min>:<max>: allowed Key ID range\n");
|
||||||
fprintf(stderr, " -p <protocol>: (default: 3 [dnssec])\n");
|
fprintf(stderr, " -p <protocol>: (default: 3 [dnssec])\n");
|
||||||
fprintf(stderr, " -s <strength>: strength value this key signs DNS "
|
fprintf(stderr, " -s <strength>: strength value this key signs DNS "
|
||||||
"records with (default: 0)\n");
|
"records with (default: 0)\n");
|
||||||
@@ -253,7 +252,6 @@ keygen(keygen_ctx_t *ctx, isc_mem_t *mctx, int argc, char **argv) {
|
|||||||
char filename[255];
|
char filename[255];
|
||||||
char algstr[DNS_SECALG_FORMATSIZE];
|
char algstr[DNS_SECALG_FORMATSIZE];
|
||||||
uint16_t flags = 0;
|
uint16_t flags = 0;
|
||||||
int param = 0;
|
|
||||||
bool null_key = false;
|
bool null_key = false;
|
||||||
bool conflict = false;
|
bool conflict = false;
|
||||||
bool show_progress = false;
|
bool show_progress = false;
|
||||||
@@ -614,12 +612,12 @@ keygen(keygen_ctx_t *ctx, isc_mem_t *mctx, int argc, char **argv) {
|
|||||||
ctx->keystore, name, ctx->policy, ctx->rdclass,
|
ctx->keystore, name, ctx->policy, ctx->rdclass,
|
||||||
mctx, ctx->alg, ctx->size, flags, &key);
|
mctx, ctx->alg, ctx->size, flags, &key);
|
||||||
} else if (!ctx->quiet && show_progress) {
|
} else if (!ctx->quiet && show_progress) {
|
||||||
ret = dst_key_generate(name, ctx->alg, ctx->size, param,
|
ret = dst_key_generate(name, ctx->alg, ctx->size, 0,
|
||||||
flags, ctx->protocol,
|
flags, ctx->protocol,
|
||||||
ctx->rdclass, NULL, mctx, &key,
|
ctx->rdclass, NULL, mctx, &key,
|
||||||
&progress);
|
&progress);
|
||||||
} else {
|
} else {
|
||||||
ret = dst_key_generate(name, ctx->alg, ctx->size, param,
|
ret = dst_key_generate(name, ctx->alg, ctx->size, 0,
|
||||||
flags, ctx->protocol,
|
flags, ctx->protocol,
|
||||||
ctx->rdclass, NULL, mctx, &key,
|
ctx->rdclass, NULL, mctx, &key,
|
||||||
NULL);
|
NULL);
|
||||||
@@ -758,7 +756,9 @@ keygen(keygen_ctx_t *ctx, isc_mem_t *mctx, int argc, char **argv) {
|
|||||||
* if there is a risk of ID collision due to this key
|
* if there is a risk of ID collision due to this key
|
||||||
* or another key being revoked.
|
* or another key being revoked.
|
||||||
*/
|
*/
|
||||||
if (key_collision(key, name, ctx->directory, mctx, NULL)) {
|
if (key_collision(key, name, ctx->directory, mctx, ctx->tag_min,
|
||||||
|
ctx->tag_max, NULL))
|
||||||
|
{
|
||||||
conflict = true;
|
conflict = true;
|
||||||
if (null_key) {
|
if (null_key) {
|
||||||
dst_key_free(&key);
|
dst_key_free(&key);
|
||||||
@@ -843,11 +843,10 @@ main(int argc, char **argv) {
|
|||||||
isc_mem_t *mctx = NULL;
|
isc_mem_t *mctx = NULL;
|
||||||
isc_result_t ret;
|
isc_result_t ret;
|
||||||
isc_textregion_t r;
|
isc_textregion_t r;
|
||||||
const char *engine = NULL;
|
|
||||||
unsigned char c;
|
unsigned char c;
|
||||||
int ch;
|
int ch;
|
||||||
bool set_fips_mode = false;
|
bool set_fips_mode = false;
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L && OPENSSL_API_LEVEL >= 30000
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
OSSL_PROVIDER *fips = NULL, *base = NULL;
|
OSSL_PROVIDER *fips = NULL, *base = NULL;
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
@@ -868,8 +867,8 @@ main(int argc, char **argv) {
|
|||||||
/*
|
/*
|
||||||
* Process memory debugging argument first.
|
* Process memory debugging argument first.
|
||||||
*/
|
*/
|
||||||
#define CMDLINE_FLAGS \
|
#define CMDLINE_FLAGS \
|
||||||
"3A:a:b:Cc:D:d:E:Ff:GhI:i:K:k:L:l:m:n:P:p:qR:r:S:s:" \
|
"3A:a:b:Cc:D:d:E:Ff:GhI:i:K:k:L:l:M:m:n:P:p:qR:r:S:s:" \
|
||||||
"T:t:v:V"
|
"T:t:v:V"
|
||||||
while ((ch = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != -1) {
|
while ((ch = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != -1) {
|
||||||
switch (ch) {
|
switch (ch) {
|
||||||
@@ -922,7 +921,7 @@ main(int argc, char **argv) {
|
|||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
case 'E':
|
case 'E':
|
||||||
engine = isc_commandline_argument;
|
fatal("%s", isc_result_totext(DST_R_NOENGINE));
|
||||||
break;
|
break;
|
||||||
case 'f':
|
case 'f':
|
||||||
c = (unsigned char)(isc_commandline_argument[0]);
|
c = (unsigned char)(isc_commandline_argument[0]);
|
||||||
@@ -958,6 +957,21 @@ main(int argc, char **argv) {
|
|||||||
case 'n':
|
case 'n':
|
||||||
ctx.nametype = isc_commandline_argument;
|
ctx.nametype = isc_commandline_argument;
|
||||||
break;
|
break;
|
||||||
|
case 'M': {
|
||||||
|
unsigned long ul;
|
||||||
|
ctx.tag_min = ul = strtoul(isc_commandline_argument,
|
||||||
|
&endp, 10);
|
||||||
|
if (*endp != ':' || ul > 0xffff) {
|
||||||
|
fatal("-M range invalid");
|
||||||
|
}
|
||||||
|
ctx.tag_max = ul = strtoul(endp + 1, &endp, 10);
|
||||||
|
if (*endp != '\0' || ul > 0xffff ||
|
||||||
|
ctx.tag_max <= ctx.tag_min)
|
||||||
|
{
|
||||||
|
fatal("-M range invalid");
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
}
|
||||||
case 'm':
|
case 'm':
|
||||||
break;
|
break;
|
||||||
case 'p':
|
case 'p':
|
||||||
@@ -1121,7 +1135,7 @@ main(int argc, char **argv) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (set_fips_mode) {
|
if (set_fips_mode) {
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L && OPENSSL_API_LEVEL >= 30000
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
fips = OSSL_PROVIDER_load(NULL, "fips");
|
fips = OSSL_PROVIDER_load(NULL, "fips");
|
||||||
if (fips == NULL) {
|
if (fips == NULL) {
|
||||||
ERR_clear_error();
|
ERR_clear_error();
|
||||||
@@ -1141,20 +1155,15 @@ main(int argc, char **argv) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
ret = dst_lib_init(mctx, engine);
|
|
||||||
if (ret != ISC_R_SUCCESS) {
|
|
||||||
fatal("could not initialize dst: %s", isc_result_totext(ret));
|
|
||||||
}
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* After dst_lib_init which will set FIPS mode if requested
|
* The DST subsystem will set FIPS mode if requested at build time.
|
||||||
* at build time. The minumums are both raised to 2048.
|
* The minimum sizes are both raised to 2048.
|
||||||
*/
|
*/
|
||||||
if (isc_fips_mode()) {
|
if (isc_fips_mode()) {
|
||||||
min_rsa = min_dh = 2048;
|
min_rsa = min_dh = 2048;
|
||||||
}
|
}
|
||||||
|
|
||||||
setup_logging(mctx, &lctx);
|
setup_logging();
|
||||||
|
|
||||||
ctx.rdclass = strtoclass(classname);
|
ctx.rdclass = strtoclass(classname);
|
||||||
|
|
||||||
@@ -1226,6 +1235,8 @@ main(int argc, char **argv) {
|
|||||||
ctx.ksk = true;
|
ctx.ksk = true;
|
||||||
ctx.zsk = true;
|
ctx.zsk = true;
|
||||||
ctx.lifetime = 0;
|
ctx.lifetime = 0;
|
||||||
|
ctx.tag_min = 0;
|
||||||
|
ctx.tag_max = 0xffff;
|
||||||
|
|
||||||
keygen(&ctx, mctx, argc, argv);
|
keygen(&ctx, mctx, argc, argv);
|
||||||
} else {
|
} else {
|
||||||
@@ -1234,7 +1245,7 @@ main(int argc, char **argv) {
|
|||||||
dns_kasp_t *kasp = NULL;
|
dns_kasp_t *kasp = NULL;
|
||||||
dns_kasp_key_t *kaspkey = NULL;
|
dns_kasp_key_t *kaspkey = NULL;
|
||||||
|
|
||||||
RUNTIME_CHECK(cfg_parser_create(mctx, lctx, &parser) ==
|
RUNTIME_CHECK(cfg_parser_create(mctx, &parser) ==
|
||||||
ISC_R_SUCCESS);
|
ISC_R_SUCCESS);
|
||||||
if (cfg_parse_file(parser, ctx.configfile,
|
if (cfg_parse_file(parser, ctx.configfile,
|
||||||
&cfg_type_namedconf,
|
&cfg_type_namedconf,
|
||||||
@@ -1245,8 +1256,8 @@ main(int argc, char **argv) {
|
|||||||
ctx.policy, ctx.configfile);
|
ctx.policy, ctx.configfile);
|
||||||
}
|
}
|
||||||
|
|
||||||
kasp_from_conf(config, mctx, lctx, ctx.policy,
|
kasp_from_conf(config, mctx, ctx.policy, ctx.directory,
|
||||||
ctx.directory, engine, &kasp);
|
&kasp);
|
||||||
if (kasp == NULL) {
|
if (kasp == NULL) {
|
||||||
fatal("failed to load dnssec-policy '%s'",
|
fatal("failed to load dnssec-policy '%s'",
|
||||||
ctx.policy);
|
ctx.policy);
|
||||||
@@ -1274,6 +1285,8 @@ main(int argc, char **argv) {
|
|||||||
if (ctx.keystore != NULL) {
|
if (ctx.keystore != NULL) {
|
||||||
check_keystore_options(&ctx);
|
check_keystore_options(&ctx);
|
||||||
}
|
}
|
||||||
|
ctx.tag_min = dns_kasp_key_tagmin(kaspkey);
|
||||||
|
ctx.tag_max = dns_kasp_key_tagmax(kaspkey);
|
||||||
if ((ctx.ksk && !ctx.wantksk && ctx.wantzsk) ||
|
if ((ctx.ksk && !ctx.wantksk && ctx.wantzsk) ||
|
||||||
(ctx.zsk && !ctx.wantzsk && ctx.wantksk))
|
(ctx.zsk && !ctx.wantzsk && ctx.wantksk))
|
||||||
{
|
{
|
||||||
@@ -1290,14 +1303,12 @@ main(int argc, char **argv) {
|
|||||||
keygen(&ctx, mctx, argc, argv);
|
keygen(&ctx, mctx, argc, argv);
|
||||||
}
|
}
|
||||||
|
|
||||||
cleanup_logging(&lctx);
|
|
||||||
dst_lib_destroy();
|
|
||||||
if (verbose > 10) {
|
if (verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L && OPENSSL_API_LEVEL >= 30000
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
if (base != NULL) {
|
if (base != NULL) {
|
||||||
OSSL_PROVIDER_unload(base);
|
OSSL_PROVIDER_unload(base);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ dnssec-keygen: DNSSEC key generation tool
|
|||||||
Synopsis
|
Synopsis
|
||||||
~~~~~~~~
|
~~~~~~~~
|
||||||
|
|
||||||
:program:`dnssec-keygen` [**-3**] [**-A** date/offset] [**-a** algorithm] [**-b** keysize] [**-C**] [**-c** class] [**-D** date/offset] [**-d** bits] [**-D** sync date/offset] [**-E** engine] [**-f** flag] [**-F**] [**-G**] [**-h**] [**-I** date/offset] [**-i** interval] [**-K** directory] [**-k** policy] [**-L** ttl] [**-l** file] [**-n** nametype] [**-P** date/offset] [**-P** sync date/offset] [**-p** protocol] [**-q**] [**-R** date/offset] [**-S** key] [**-s** strength] [**-T** rrtype] [**-t** type] [**-V**] [**-v** level] {name}
|
:program:`dnssec-keygen` [**-3**] [**-A** date/offset] [**-a** algorithm] [**-b** keysize] [**-C**] [**-c** class] [**-D** date/offset] [**-d** bits] [**-D** sync date/offset] [**-f** flag] [**-F**] [**-G**] [**-h**] [**-I** date/offset] [**-i** interval] [**-K** directory] [**-k** policy] [**-L** ttl] [**-l** file] [**-M** tag_min:tag_max] [**-n** nametype] [**-P** date/offset] [**-P** sync date/offset] [**-p** protocol] [**-q**] [**-R** date/offset] [**-S** key] [**-s** strength] [**-T** rrtype] [**-t** type] [**-V**] [**-v** level] {name}
|
||||||
|
|
||||||
Description
|
Description
|
||||||
~~~~~~~~~~~
|
~~~~~~~~~~~
|
||||||
@@ -94,14 +94,6 @@ Options
|
|||||||
and 4096 bits. This option is ignored for algorithms ECDSAP256SHA256,
|
and 4096 bits. This option is ignored for algorithms ECDSAP256SHA256,
|
||||||
ECDSAP384SHA384, ED25519, and ED448.
|
ECDSAP384SHA384, ED25519, and ED448.
|
||||||
|
|
||||||
.. option:: -E engine
|
|
||||||
|
|
||||||
This option specifies the cryptographic hardware to use, when applicable.
|
|
||||||
|
|
||||||
When BIND 9 is built with OpenSSL, this needs to be set to the OpenSSL
|
|
||||||
engine identifier that drives the cryptographic accelerator or
|
|
||||||
hardware service module (usually ``pkcs11``).
|
|
||||||
|
|
||||||
.. option:: -f flag
|
.. option:: -f flag
|
||||||
|
|
||||||
This option sets the specified flag in the flag field of the KEY/DNSKEY record.
|
This option sets the specified flag in the flag field of the KEY/DNSKEY record.
|
||||||
@@ -158,6 +150,19 @@ Options
|
|||||||
This option provides a configuration file that contains a ``dnssec-policy`` statement
|
This option provides a configuration file that contains a ``dnssec-policy`` statement
|
||||||
(matching the policy set with :option:`-k`).
|
(matching the policy set with :option:`-k`).
|
||||||
|
|
||||||
|
.. option:: -M tag_min:tag_max
|
||||||
|
|
||||||
|
This option sets the range of acceptable key tag values that ``dnssec-keygen``
|
||||||
|
will produce. If the key tag of the new key or the key tag of
|
||||||
|
the revoked version of the new key is outside this range,
|
||||||
|
the new key will be rejected and another new key will be generated.
|
||||||
|
This is designed to be used when generating keys in a multi-signer
|
||||||
|
scenario, where each operator is given a range of key tags to
|
||||||
|
prevent collisions among different operators. The valid values
|
||||||
|
for ``tag_min`` and ``tag_max`` are [0..65535]. The default allows all
|
||||||
|
key tag values to be produced. This option is ignored when ``-k policy``
|
||||||
|
is specified.
|
||||||
|
|
||||||
.. option:: -n nametype
|
.. option:: -n nametype
|
||||||
|
|
||||||
This option specifies the owner type of the key. The value of ``nametype`` must
|
This option specifies the owner type of the key. The value of ``nametype`` must
|
||||||
|
|||||||
+12
-18
@@ -39,9 +39,7 @@ const char *program = "dnssec-ksr";
|
|||||||
/*
|
/*
|
||||||
* Infrastructure
|
* Infrastructure
|
||||||
*/
|
*/
|
||||||
static isc_log_t *lctx = NULL;
|
|
||||||
static isc_mem_t *mctx = NULL;
|
static isc_mem_t *mctx = NULL;
|
||||||
const char *engine = NULL;
|
|
||||||
/*
|
/*
|
||||||
* The domain we are working on
|
* The domain we are working on
|
||||||
*/
|
*/
|
||||||
@@ -122,7 +120,6 @@ usage(int ret) {
|
|||||||
fprintf(stderr, "Version: %s\n", PACKAGE_VERSION);
|
fprintf(stderr, "Version: %s\n", PACKAGE_VERSION);
|
||||||
fprintf(stderr, "\n");
|
fprintf(stderr, "\n");
|
||||||
fprintf(stderr, "Options:\n");
|
fprintf(stderr, "Options:\n");
|
||||||
fprintf(stderr, " -E <engine>: name of an OpenSSL engine to use\n");
|
|
||||||
fprintf(stderr, " -e <date/offset>: end date\n");
|
fprintf(stderr, " -e <date/offset>: end date\n");
|
||||||
fprintf(stderr, " -F: FIPS mode\n");
|
fprintf(stderr, " -F: FIPS mode\n");
|
||||||
fprintf(stderr, " -f: KSR file to sign\n");
|
fprintf(stderr, " -f: KSR file to sign\n");
|
||||||
@@ -166,15 +163,14 @@ getkasp(ksr_ctx_t *ksr, dns_kasp_t **kasp) {
|
|||||||
cfg_parser_t *parser = NULL;
|
cfg_parser_t *parser = NULL;
|
||||||
cfg_obj_t *config = NULL;
|
cfg_obj_t *config = NULL;
|
||||||
|
|
||||||
RUNTIME_CHECK(cfg_parser_create(mctx, lctx, &parser) == ISC_R_SUCCESS);
|
RUNTIME_CHECK(cfg_parser_create(mctx, &parser) == ISC_R_SUCCESS);
|
||||||
if (cfg_parse_file(parser, ksr->configfile, &cfg_type_namedconf,
|
if (cfg_parse_file(parser, ksr->configfile, &cfg_type_namedconf,
|
||||||
&config) != ISC_R_SUCCESS)
|
&config) != ISC_R_SUCCESS)
|
||||||
{
|
{
|
||||||
fatal("unable to load dnssec-policy '%s' from '%s'",
|
fatal("unable to load dnssec-policy '%s' from '%s'",
|
||||||
ksr->policy, ksr->configfile);
|
ksr->policy, ksr->configfile);
|
||||||
}
|
}
|
||||||
kasp_from_conf(config, mctx, lctx, ksr->policy, ksr->keydir, engine,
|
kasp_from_conf(config, mctx, ksr->policy, ksr->keydir, kasp);
|
||||||
kasp);
|
|
||||||
if (*kasp == NULL) {
|
if (*kasp == NULL) {
|
||||||
fatal("failed to load dnssec-policy '%s'", ksr->policy);
|
fatal("failed to load dnssec-policy '%s'", ksr->policy);
|
||||||
}
|
}
|
||||||
@@ -440,7 +436,10 @@ create_zsk(ksr_ctx_t *ksr, dns_kasp_key_t *kaspkey, dns_dnsseckeylist_t *keys,
|
|||||||
}
|
}
|
||||||
|
|
||||||
/* Do not overwrite an existing key. */
|
/* Do not overwrite an existing key. */
|
||||||
if (key_collision(key, name, ksr->keydir, mctx, NULL)) {
|
if (key_collision(key, name, ksr->keydir, mctx,
|
||||||
|
dns_kasp_key_tagmin(kaspkey),
|
||||||
|
dns_kasp_key_tagmax(kaspkey), NULL))
|
||||||
|
{
|
||||||
conflict = true;
|
conflict = true;
|
||||||
if (verbose > 0) {
|
if (verbose > 0) {
|
||||||
isc_buffer_clear(&buf);
|
isc_buffer_clear(&buf);
|
||||||
@@ -1198,7 +1197,7 @@ main(int argc, char *argv[]) {
|
|||||||
int ch;
|
int ch;
|
||||||
char *endp;
|
char *endp;
|
||||||
bool set_fips_mode = false;
|
bool set_fips_mode = false;
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L && OPENSSL_API_LEVEL >= 30000
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
OSSL_PROVIDER *fips = NULL, *base = NULL;
|
OSSL_PROVIDER *fips = NULL, *base = NULL;
|
||||||
#endif
|
#endif
|
||||||
ksr_ctx_t ksr = {
|
ksr_ctx_t ksr = {
|
||||||
@@ -1213,7 +1212,7 @@ main(int argc, char *argv[]) {
|
|||||||
while ((ch = isc_commandline_parse(argc, argv, OPTIONS)) != -1) {
|
while ((ch = isc_commandline_parse(argc, argv, OPTIONS)) != -1) {
|
||||||
switch (ch) {
|
switch (ch) {
|
||||||
case 'E':
|
case 'E':
|
||||||
engine = isc_commandline_argument;
|
fatal("%s", isc_result_totext(DST_R_NOENGINE));
|
||||||
break;
|
break;
|
||||||
case 'e':
|
case 'e':
|
||||||
ksr.end = strtotime(isc_commandline_argument, ksr.now,
|
ksr.end = strtotime(isc_commandline_argument, ksr.now,
|
||||||
@@ -1267,23 +1266,18 @@ main(int argc, char *argv[]) {
|
|||||||
fatal("must provide a command and zone name");
|
fatal("must provide a command and zone name");
|
||||||
}
|
}
|
||||||
|
|
||||||
ret = dst_lib_init(mctx, engine);
|
|
||||||
if (ret != ISC_R_SUCCESS) {
|
|
||||||
fatal("could not initialize dst: %s", isc_result_totext(ret));
|
|
||||||
}
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* After dst_lib_init which will set FIPS mode if requested
|
* The DST subsystem will set FIPS mode if requested at build time.
|
||||||
* at build time. The minumums are both raised to 2048.
|
* The minimum sizes are both raised to 2048.
|
||||||
*/
|
*/
|
||||||
if (isc_fips_mode()) {
|
if (isc_fips_mode()) {
|
||||||
min_rsa = min_dh = 2048;
|
min_rsa = min_dh = 2048;
|
||||||
}
|
}
|
||||||
|
|
||||||
setup_logging(mctx, &lctx);
|
setup_logging();
|
||||||
|
|
||||||
if (set_fips_mode) {
|
if (set_fips_mode) {
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L && OPENSSL_API_LEVEL >= 30000
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
fips = OSSL_PROVIDER_load(NULL, "fips");
|
fips = OSSL_PROVIDER_load(NULL, "fips");
|
||||||
if (fips == NULL) {
|
if (fips == NULL) {
|
||||||
fatal("Failed to load FIPS provider");
|
fatal("Failed to load FIPS provider");
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ dnssec-ksr - Create signed key response (SKR) files for offline KSK setups
|
|||||||
Synopsis
|
Synopsis
|
||||||
~~~~~~~~
|
~~~~~~~~
|
||||||
|
|
||||||
:program:`dnssec-ksr` [**-E** engine] [**-e** date/offset] [**-F**] [**-h**] [**-i** date/offset] [**-K** directory] [**-k** policy] [**-l** file] [**-V**] [**-v** level] {command} {zone}
|
:program:`dnssec-ksr` [**-e** date/offset] [**-F**] [**-h**] [**-i** date/offset] [**-K** directory] [**-k** policy] [**-l** file] [**-V**] [**-v** level] {command} {zone}
|
||||||
|
|
||||||
Description
|
Description
|
||||||
~~~~~~~~~~~
|
~~~~~~~~~~~
|
||||||
@@ -40,14 +40,6 @@ server.
|
|||||||
Options
|
Options
|
||||||
~~~~~~~
|
~~~~~~~
|
||||||
|
|
||||||
.. option:: -E engine
|
|
||||||
|
|
||||||
This option specifies the cryptographic hardware to use, when applicable.
|
|
||||||
|
|
||||||
When BIND 9 is built with OpenSSL, this needs to be set to the OpenSSL
|
|
||||||
engine identifier that drives the cryptographic accelerator or
|
|
||||||
hardware service module (usually ``pkcs11``).
|
|
||||||
|
|
||||||
.. option:: -e date/offset
|
.. option:: -e date/offset
|
||||||
|
|
||||||
This option sets the end date for which keys or SKRs need to be generated
|
This option sets the end date for which keys or SKRs need to be generated
|
||||||
|
|||||||
@@ -38,7 +38,7 @@ const char *program = "dnssec-revoke";
|
|||||||
|
|
||||||
static isc_mem_t *mctx = NULL;
|
static isc_mem_t *mctx = NULL;
|
||||||
|
|
||||||
noreturn static void
|
ISC_NORETURN static void
|
||||||
usage(void);
|
usage(void);
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -46,7 +46,6 @@ usage(void) {
|
|||||||
fprintf(stderr, "Usage:\n");
|
fprintf(stderr, "Usage:\n");
|
||||||
fprintf(stderr, " %s [options] keyfile\n\n", program);
|
fprintf(stderr, " %s [options] keyfile\n\n", program);
|
||||||
fprintf(stderr, "Version: %s\n", PACKAGE_VERSION);
|
fprintf(stderr, "Version: %s\n", PACKAGE_VERSION);
|
||||||
fprintf(stderr, " -E engine: specify OpenSSL engine\n");
|
|
||||||
fprintf(stderr, " -f: force overwrite\n");
|
fprintf(stderr, " -f: force overwrite\n");
|
||||||
fprintf(stderr, " -h: help\n");
|
fprintf(stderr, " -h: help\n");
|
||||||
fprintf(stderr, " -K directory: use directory for key files\n");
|
fprintf(stderr, " -K directory: use directory for key files\n");
|
||||||
@@ -64,7 +63,6 @@ usage(void) {
|
|||||||
int
|
int
|
||||||
main(int argc, char **argv) {
|
main(int argc, char **argv) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
const char *engine = NULL;
|
|
||||||
char const *filename = NULL;
|
char const *filename = NULL;
|
||||||
char *dir = NULL;
|
char *dir = NULL;
|
||||||
char newname[1024], oldname[1024];
|
char newname[1024], oldname[1024];
|
||||||
@@ -89,7 +87,7 @@ main(int argc, char **argv) {
|
|||||||
while ((ch = isc_commandline_parse(argc, argv, "E:fK:rRhv:V")) != -1) {
|
while ((ch = isc_commandline_parse(argc, argv, "E:fK:rRhv:V")) != -1) {
|
||||||
switch (ch) {
|
switch (ch) {
|
||||||
case 'E':
|
case 'E':
|
||||||
engine = isc_commandline_argument;
|
fatal("%s", isc_result_totext(DST_R_NOENGINE));
|
||||||
break;
|
break;
|
||||||
case 'f':
|
case 'f':
|
||||||
force = true;
|
force = true;
|
||||||
@@ -159,12 +157,6 @@ main(int argc, char **argv) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
result = dst_lib_init(mctx, engine);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
fatal("Could not initialize dst: %s",
|
|
||||||
isc_result_totext(result));
|
|
||||||
}
|
|
||||||
|
|
||||||
result = dst_key_fromnamedfile(
|
result = dst_key_fromnamedfile(
|
||||||
filename, dir, DST_TYPE_PUBLIC | DST_TYPE_PRIVATE, mctx, &key);
|
filename, dir, DST_TYPE_PUBLIC | DST_TYPE_PRIVATE, mctx, &key);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
@@ -248,7 +240,6 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
dst_key_free(&key);
|
dst_key_free(&key);
|
||||||
dst_lib_destroy();
|
|
||||||
if (verbose > 10) {
|
if (verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ dnssec-revoke - set the REVOKED bit on a DNSSEC key
|
|||||||
Synopsis
|
Synopsis
|
||||||
~~~~~~~~
|
~~~~~~~~
|
||||||
|
|
||||||
:program:`dnssec-revoke` [**-hr**] [**-v** level] [**-V**] [**-K** directory] [**-E** engine] [**-f**] [**-R**] {keyfile}
|
:program:`dnssec-revoke` [**-hr**] [**-v** level] [**-V**] [**-K** directory] [**-f**] [**-R**] {keyfile}
|
||||||
|
|
||||||
Description
|
Description
|
||||||
~~~~~~~~~~~
|
~~~~~~~~~~~
|
||||||
@@ -53,14 +53,6 @@ Options
|
|||||||
|
|
||||||
This option prints version information.
|
This option prints version information.
|
||||||
|
|
||||||
.. option:: -E engine
|
|
||||||
|
|
||||||
This option specifies the cryptographic hardware to use, when applicable.
|
|
||||||
|
|
||||||
When BIND 9 is built with OpenSSL, this needs to be set to the OpenSSL
|
|
||||||
engine identifier that drives the cryptographic accelerator or
|
|
||||||
hardware service module (usually ``pkcs11``).
|
|
||||||
|
|
||||||
.. option:: -f
|
.. option:: -f
|
||||||
|
|
||||||
This option indicates a forced overwrite and causes :program:`dnssec-revoke` to write the new key pair,
|
This option indicates a forced overwrite and causes :program:`dnssec-revoke` to write the new key pair,
|
||||||
|
|||||||
@@ -25,6 +25,7 @@
|
|||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
#include <isc/string.h>
|
#include <isc/string.h>
|
||||||
@@ -32,7 +33,6 @@
|
|||||||
#include <isc/util.h>
|
#include <isc/util.h>
|
||||||
|
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
#include <dns/log.h>
|
|
||||||
|
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
|
|
||||||
@@ -42,7 +42,7 @@ const char *program = "dnssec-settime";
|
|||||||
|
|
||||||
static isc_mem_t *mctx = NULL;
|
static isc_mem_t *mctx = NULL;
|
||||||
|
|
||||||
noreturn static void
|
ISC_NORETURN static void
|
||||||
usage(void);
|
usage(void);
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -51,7 +51,6 @@ usage(void) {
|
|||||||
fprintf(stderr, " %s [options] keyfile\n\n", program);
|
fprintf(stderr, " %s [options] keyfile\n\n", program);
|
||||||
fprintf(stderr, "Version: %s\n", PACKAGE_VERSION);
|
fprintf(stderr, "Version: %s\n", PACKAGE_VERSION);
|
||||||
fprintf(stderr, "General options:\n");
|
fprintf(stderr, "General options:\n");
|
||||||
fprintf(stderr, " -E engine: specify OpenSSL engine\n");
|
|
||||||
fprintf(stderr, " -f: force update of old-style "
|
fprintf(stderr, " -f: force update of old-style "
|
||||||
"keys\n");
|
"keys\n");
|
||||||
fprintf(stderr, " -K directory: set key file location\n");
|
fprintf(stderr, " -K directory: set key file location\n");
|
||||||
@@ -186,7 +185,6 @@ writekey(dst_key_t *key, const char *directory, bool write_state) {
|
|||||||
int
|
int
|
||||||
main(int argc, char **argv) {
|
main(int argc, char **argv) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
const char *engine = NULL;
|
|
||||||
const char *filename = NULL;
|
const char *filename = NULL;
|
||||||
char *directory = NULL;
|
char *directory = NULL;
|
||||||
char keystr[DST_KEY_FORMATSIZE];
|
char keystr[DST_KEY_FORMATSIZE];
|
||||||
@@ -228,7 +226,6 @@ main(int argc, char **argv) {
|
|||||||
bool epoch = false;
|
bool epoch = false;
|
||||||
bool changed = false;
|
bool changed = false;
|
||||||
bool write_state = false;
|
bool write_state = false;
|
||||||
isc_log_t *log = NULL;
|
|
||||||
isc_stdtime_t syncadd = 0, syncdel = 0;
|
isc_stdtime_t syncadd = 0, syncdel = 0;
|
||||||
bool unsetsyncadd = false, setsyncadd = false;
|
bool unsetsyncadd = false, setsyncadd = false;
|
||||||
bool unsetsyncdel = false, setsyncdel = false;
|
bool unsetsyncdel = false, setsyncdel = false;
|
||||||
@@ -247,7 +244,7 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
isc_mem_create(&mctx);
|
isc_mem_create(&mctx);
|
||||||
|
|
||||||
setup_logging(mctx, &log);
|
setup_logging();
|
||||||
|
|
||||||
isc_commandline_errprint = false;
|
isc_commandline_errprint = false;
|
||||||
|
|
||||||
@@ -314,7 +311,7 @@ main(int argc, char **argv) {
|
|||||||
&setdstime);
|
&setdstime);
|
||||||
break;
|
break;
|
||||||
case 'E':
|
case 'E':
|
||||||
engine = isc_commandline_argument;
|
fatal("%s", isc_result_totext(DST_R_NOENGINE));
|
||||||
break;
|
break;
|
||||||
case 'f':
|
case 'f':
|
||||||
force = true;
|
force = true;
|
||||||
@@ -555,12 +552,6 @@ main(int argc, char **argv) {
|
|||||||
fatal("Options -g, -d, -k, -r and -z require -s to be set");
|
fatal("Options -g, -d, -k, -r and -z require -s to be set");
|
||||||
}
|
}
|
||||||
|
|
||||||
result = dst_lib_init(mctx, engine);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
fatal("Could not initialize dst: %s",
|
|
||||||
isc_result_totext(result));
|
|
||||||
}
|
|
||||||
|
|
||||||
if (predecessor != NULL) {
|
if (predecessor != NULL) {
|
||||||
int major, minor;
|
int major, minor;
|
||||||
|
|
||||||
@@ -952,11 +943,9 @@ main(int argc, char **argv) {
|
|||||||
dst_key_free(&prevkey);
|
dst_key_free(&prevkey);
|
||||||
}
|
}
|
||||||
dst_key_free(&key);
|
dst_key_free(&key);
|
||||||
dst_lib_destroy();
|
|
||||||
if (verbose > 10) {
|
if (verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
cleanup_logging(&log);
|
|
||||||
isc_mem_free(mctx, directory);
|
isc_mem_free(mctx, directory);
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ dnssec-settime: set the key timing metadata for a DNSSEC key
|
|||||||
Synopsis
|
Synopsis
|
||||||
~~~~~~~~
|
~~~~~~~~
|
||||||
|
|
||||||
:program:`dnssec-settime` [**-f**] [**-K** directory] [**-L** ttl] [**-P** date/offset] [**-P** ds date/offset] [**-P** sync date/offset] [**-A** date/offset] [**-R** date/offset] [**-I** date/offset] [**-D** date/offset] [**-D** ds date/offset] [**-D** sync date/offset] [**-S** key] [**-i** interval] [**-h**] [**-V**] [**-v** level] [**-E** engine] {keyfile} [**-s**] [**-g** state] [**-d** state date/offset] [**-k** state date/offset] [**-r** state date/offset] [**-z** state date/offset]
|
:program:`dnssec-settime` [**-f**] [**-K** directory] [**-L** ttl] [**-P** date/offset] [**-P** ds date/offset] [**-P** sync date/offset] [**-A** date/offset] [**-R** date/offset] [**-I** date/offset] [**-D** date/offset] [**-D** ds date/offset] [**-D** sync date/offset] [**-S** key] [**-i** interval] [**-h**] [**-V**] [**-v** level] {keyfile} [**-s**] [**-g** state] [**-d** state date/offset] [**-k** state date/offset] [**-r** state date/offset] [**-z** state date/offset]
|
||||||
|
|
||||||
Description
|
Description
|
||||||
~~~~~~~~~~~
|
~~~~~~~~~~~
|
||||||
@@ -97,14 +97,6 @@ Options
|
|||||||
|
|
||||||
This option sets the debugging level.
|
This option sets the debugging level.
|
||||||
|
|
||||||
.. option:: -E engine
|
|
||||||
|
|
||||||
This option specifies the cryptographic hardware to use, when applicable.
|
|
||||||
|
|
||||||
When BIND 9 is built with OpenSSL, this needs to be set to the OpenSSL
|
|
||||||
engine identifier that drives the cryptographic accelerator or
|
|
||||||
hardware service module (usually ``pkcs11``).
|
|
||||||
|
|
||||||
Timing Options
|
Timing Options
|
||||||
~~~~~~~~~~~~~~
|
~~~~~~~~~~~~~~
|
||||||
|
|
||||||
|
|||||||
@@ -45,6 +45,7 @@
|
|||||||
#include <isc/fips.h>
|
#include <isc/fips.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/hex.h>
|
#include <isc/hex.h>
|
||||||
|
#include <isc/log.h>
|
||||||
#include <isc/loop.h>
|
#include <isc/loop.h>
|
||||||
#include <isc/managers.h>
|
#include <isc/managers.h>
|
||||||
#include <isc/md.h>
|
#include <isc/md.h>
|
||||||
@@ -70,7 +71,6 @@
|
|||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/kasp.h>
|
#include <dns/kasp.h>
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
#include <dns/log.h>
|
|
||||||
#include <dns/master.h>
|
#include <dns/master.h>
|
||||||
#include <dns/masterdump.h>
|
#include <dns/masterdump.h>
|
||||||
#include <dns/nsec.h>
|
#include <dns/nsec.h>
|
||||||
@@ -88,7 +88,7 @@
|
|||||||
#include <dns/zoneverify.h>
|
#include <dns/zoneverify.h>
|
||||||
|
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L && OPENSSL_API_LEVEL >= 30000
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
#include <openssl/err.h>
|
#include <openssl/err.h>
|
||||||
#include <openssl/provider.h>
|
#include <openssl/provider.h>
|
||||||
#endif
|
#endif
|
||||||
@@ -140,10 +140,10 @@ static dns_masterformat_t inputformat = dns_masterformat_text;
|
|||||||
static dns_masterformat_t outputformat = dns_masterformat_text;
|
static dns_masterformat_t outputformat = dns_masterformat_text;
|
||||||
static uint32_t rawversion = 1, serialnum = 0;
|
static uint32_t rawversion = 1, serialnum = 0;
|
||||||
static bool snset = false;
|
static bool snset = false;
|
||||||
static unsigned int nsigned = 0, nretained = 0, ndropped = 0;
|
static atomic_uint_fast32_t nsigned = 0, nretained = 0, ndropped = 0;
|
||||||
static unsigned int nverified = 0, nverifyfailed = 0;
|
static atomic_uint_fast32_t nverified = 0, nverifyfailed = 0;
|
||||||
static const char *directory = NULL, *dsdir = NULL;
|
static const char *directory = NULL, *dsdir = NULL;
|
||||||
static isc_mutex_t namelock, statslock;
|
static isc_mutex_t namelock;
|
||||||
static isc_nm_t *netmgr = NULL;
|
static isc_nm_t *netmgr = NULL;
|
||||||
static isc_loopmgr_t *loopmgr = NULL;
|
static isc_loopmgr_t *loopmgr = NULL;
|
||||||
static dns_db_t *gdb; /* The database */
|
static dns_db_t *gdb; /* The database */
|
||||||
@@ -182,11 +182,9 @@ static dns_ttl_t maxttl = 0;
|
|||||||
static bool no_max_check = false;
|
static bool no_max_check = false;
|
||||||
static const char *sync_records = "cdnskey,cds:sha-256";
|
static const char *sync_records = "cdnskey,cds:sha-256";
|
||||||
|
|
||||||
#define INCSTAT(counter) \
|
#define INCSTAT(counter) \
|
||||||
if (printstats) { \
|
if (printstats) { \
|
||||||
LOCK(&statslock); \
|
atomic_fetch_add_relaxed(&counter, 1); \
|
||||||
counter++; \
|
|
||||||
UNLOCK(&statslock); \
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/*%
|
/*%
|
||||||
@@ -320,9 +318,8 @@ signwithkey(dns_name_t *name, dns_rdataset_t *rdataset, dst_key_t *key,
|
|||||||
}
|
}
|
||||||
|
|
||||||
tuple = NULL;
|
tuple = NULL;
|
||||||
result = dns_difftuple_create(mctx, DNS_DIFFOP_ADDRESIGN, name, ttl,
|
dns_difftuple_create(mctx, DNS_DIFFOP_ADDRESIGN, name, ttl, &trdata,
|
||||||
&trdata, &tuple);
|
&tuple);
|
||||||
check_result(result, "dns_difftuple_create");
|
|
||||||
dns_diff_append(add, &tuple);
|
dns_diff_append(add, &tuple);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -634,24 +631,20 @@ signset(dns_diff_t *del, dns_diff_t *add, dns_dbnode_t *node, dns_name_t *name,
|
|||||||
if (sigset.ttl != ttl) {
|
if (sigset.ttl != ttl) {
|
||||||
vbprintf(2, "\tfixing ttl %s\n", sigstr);
|
vbprintf(2, "\tfixing ttl %s\n", sigstr);
|
||||||
tuple = NULL;
|
tuple = NULL;
|
||||||
result = dns_difftuple_create(
|
dns_difftuple_create(mctx, DNS_DIFFOP_DELRESIGN,
|
||||||
mctx, DNS_DIFFOP_DELRESIGN, name,
|
name, sigset.ttl,
|
||||||
sigset.ttl, &sigrdata, &tuple);
|
&sigrdata, &tuple);
|
||||||
check_result(result, "dns_difftuple_create");
|
|
||||||
dns_diff_append(del, &tuple);
|
dns_diff_append(del, &tuple);
|
||||||
result = dns_difftuple_create(
|
dns_difftuple_create(mctx, DNS_DIFFOP_ADDRESIGN,
|
||||||
mctx, DNS_DIFFOP_ADDRESIGN, name, ttl,
|
name, ttl, &sigrdata,
|
||||||
&sigrdata, &tuple);
|
&tuple);
|
||||||
check_result(result, "dns_difftuple_create");
|
|
||||||
dns_diff_append(add, &tuple);
|
dns_diff_append(add, &tuple);
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
tuple = NULL;
|
tuple = NULL;
|
||||||
vbprintf(2, "\tremoving signature by %s\n", sigstr);
|
vbprintf(2, "\tremoving signature by %s\n", sigstr);
|
||||||
result = dns_difftuple_create(
|
dns_difftuple_create(mctx, DNS_DIFFOP_DELRESIGN, name,
|
||||||
mctx, DNS_DIFFOP_DELRESIGN, name, sigset.ttl,
|
sigset.ttl, &sigrdata, &tuple);
|
||||||
&sigrdata, &tuple);
|
|
||||||
check_result(result, "dns_difftuple_create");
|
|
||||||
dns_diff_append(del, &tuple);
|
dns_diff_append(del, &tuple);
|
||||||
INCSTAT(ndropped);
|
INCSTAT(ndropped);
|
||||||
}
|
}
|
||||||
@@ -1080,9 +1073,8 @@ loadds(dns_name_t *name, uint32_t ttl, dns_rdataset_t *dsset) {
|
|||||||
dsbuf, &ds);
|
dsbuf, &ds);
|
||||||
check_result(result, "dns_ds_buildrdata");
|
check_result(result, "dns_ds_buildrdata");
|
||||||
|
|
||||||
result = dns_difftuple_create(mctx, DNS_DIFFOP_ADDRESIGN, name,
|
dns_difftuple_create(mctx, DNS_DIFFOP_ADDRESIGN, name, ttl, &ds,
|
||||||
ttl, &ds, &tuple);
|
&tuple);
|
||||||
check_result(result, "dns_difftuple_create");
|
|
||||||
dns_diff_append(&diff, &tuple);
|
dns_diff_append(&diff, &tuple);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -2201,10 +2193,9 @@ rrset_cleanup(dns_name_t *name, dns_rdataset_t *rdataset, dns_diff_t *add,
|
|||||||
{
|
{
|
||||||
vbprintf(2, "removing duplicate at %s/%s\n",
|
vbprintf(2, "removing duplicate at %s/%s\n",
|
||||||
namestr, typestr);
|
namestr, typestr);
|
||||||
result = dns_difftuple_create(
|
dns_difftuple_create(mctx, DNS_DIFFOP_DELRESIGN,
|
||||||
mctx, DNS_DIFFOP_DELRESIGN, name,
|
name, rdataset->ttl,
|
||||||
rdataset->ttl, &rdata2, &tuple);
|
&rdata2, &tuple);
|
||||||
check_result(result, "dns_difftuple_create");
|
|
||||||
dns_diff_append(del, &tuple);
|
dns_diff_append(del, &tuple);
|
||||||
} else if (set_maxttl && rdataset->ttl > maxttl) {
|
} else if (set_maxttl && rdataset->ttl > maxttl) {
|
||||||
vbprintf(2,
|
vbprintf(2,
|
||||||
@@ -2212,16 +2203,14 @@ rrset_cleanup(dns_name_t *name, dns_rdataset_t *rdataset, dns_diff_t *add,
|
|||||||
"from %d to %d\n",
|
"from %d to %d\n",
|
||||||
namestr, typestr, rdataset->ttl,
|
namestr, typestr, rdataset->ttl,
|
||||||
maxttl);
|
maxttl);
|
||||||
result = dns_difftuple_create(
|
dns_difftuple_create(mctx, DNS_DIFFOP_DELRESIGN,
|
||||||
mctx, DNS_DIFFOP_DELRESIGN, name,
|
name, rdataset->ttl,
|
||||||
rdataset->ttl, &rdata2, &tuple);
|
&rdata2, &tuple);
|
||||||
check_result(result, "dns_difftuple_create");
|
|
||||||
dns_diff_append(del, &tuple);
|
dns_diff_append(del, &tuple);
|
||||||
tuple = NULL;
|
tuple = NULL;
|
||||||
result = dns_difftuple_create(
|
dns_difftuple_create(mctx, DNS_DIFFOP_ADDRESIGN,
|
||||||
mctx, DNS_DIFFOP_ADDRESIGN, name,
|
name, maxttl, &rdata2,
|
||||||
maxttl, &rdata2, &tuple);
|
&tuple);
|
||||||
check_result(result, "dns_difftuple_create");
|
|
||||||
dns_diff_append(add, &tuple);
|
dns_diff_append(add, &tuple);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -3154,15 +3143,13 @@ writeset(const char *prefix, dns_rdatatype_t type) {
|
|||||||
DNS_DSDIGEST_SHA256, dsbuf,
|
DNS_DSDIGEST_SHA256, dsbuf,
|
||||||
&ds);
|
&ds);
|
||||||
check_result(result, "dns_ds_buildrdata");
|
check_result(result, "dns_ds_buildrdata");
|
||||||
result = dns_difftuple_create(mctx,
|
dns_difftuple_create(mctx, DNS_DIFFOP_ADDRESIGN, name,
|
||||||
DNS_DIFFOP_ADDRESIGN,
|
0, &ds, &tuple);
|
||||||
name, 0, &ds, &tuple);
|
|
||||||
} else {
|
} else {
|
||||||
result = dns_difftuple_create(
|
dns_difftuple_create(mctx, DNS_DIFFOP_ADDRESIGN,
|
||||||
mctx, DNS_DIFFOP_ADDRESIGN, gorigin,
|
gorigin, zone_soa_min_ttl, &rdata,
|
||||||
zone_soa_min_ttl, &rdata, &tuple);
|
&tuple);
|
||||||
}
|
}
|
||||||
check_result(result, "dns_difftuple_create");
|
|
||||||
dns_diff_append(&diff, &tuple);
|
dns_diff_append(&diff, &tuple);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -3212,7 +3199,7 @@ print_version(FILE *fp) {
|
|||||||
fprintf(fp, "; %s version %s\n", program, PACKAGE_VERSION);
|
fprintf(fp, "; %s version %s\n", program, PACKAGE_VERSION);
|
||||||
}
|
}
|
||||||
|
|
||||||
noreturn static void
|
ISC_NORETURN static void
|
||||||
usage(void);
|
usage(void);
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -3274,8 +3261,6 @@ usage(void) {
|
|||||||
fprintf(stderr, "\t-a:\t");
|
fprintf(stderr, "\t-a:\t");
|
||||||
fprintf(stderr, "verify generated signatures\n");
|
fprintf(stderr, "verify generated signatures\n");
|
||||||
fprintf(stderr, "\t-c class (IN)\n");
|
fprintf(stderr, "\t-c class (IN)\n");
|
||||||
fprintf(stderr, "\t-E engine:\n");
|
|
||||||
fprintf(stderr, "\t\tname of an OpenSSL engine to use\n");
|
|
||||||
fprintf(stderr, "\t-P:\t");
|
fprintf(stderr, "\t-P:\t");
|
||||||
fprintf(stderr, "disable post-sign verification\n");
|
fprintf(stderr, "disable post-sign verification\n");
|
||||||
fprintf(stderr, "\t-Q:\t");
|
fprintf(stderr, "\t-Q:\t");
|
||||||
@@ -3322,21 +3307,24 @@ print_stats(isc_time_t *timer_start, isc_time_t *timer_finish,
|
|||||||
uint64_t sig_ms; /* Signatures per millisecond */
|
uint64_t sig_ms; /* Signatures per millisecond */
|
||||||
FILE *out = output_stdout ? stderr : stdout;
|
FILE *out = output_stdout ? stderr : stdout;
|
||||||
|
|
||||||
fprintf(out, "Signatures generated: %10u\n", nsigned);
|
fprintf(out, "Signatures generated: %10" PRIuFAST32 "\n",
|
||||||
fprintf(out, "Signatures retained: %10u\n", nretained);
|
atomic_load(&nsigned));
|
||||||
fprintf(out, "Signatures dropped: %10u\n", ndropped);
|
fprintf(out, "Signatures retained: %10" PRIuFAST32 "\n",
|
||||||
fprintf(out, "Signatures successfully verified: %10u\n", nverified);
|
atomic_load(&nretained));
|
||||||
fprintf(out,
|
fprintf(out, "Signatures dropped: %10" PRIuFAST32 "\n",
|
||||||
"Signatures unsuccessfully "
|
atomic_load(&ndropped));
|
||||||
"verified: %10u\n",
|
fprintf(out, "Signatures successfully verified: %10" PRIuFAST32 "\n",
|
||||||
nverifyfailed);
|
atomic_load(&nverified));
|
||||||
|
fprintf(out, "Signatures unsuccessfully verified: %10" PRIuFAST32 "\n",
|
||||||
|
atomic_load(&nverifyfailed));
|
||||||
|
|
||||||
time_us = isc_time_microdiff(sign_finish, sign_start);
|
time_us = isc_time_microdiff(sign_finish, sign_start);
|
||||||
time_ms = time_us / 1000;
|
time_ms = time_us / 1000;
|
||||||
fprintf(out, "Signing time in seconds: %7u.%03u\n",
|
fprintf(out, "Signing time in seconds: %7u.%03u\n",
|
||||||
(unsigned int)(time_ms / 1000), (unsigned int)(time_ms % 1000));
|
(unsigned int)(time_ms / 1000), (unsigned int)(time_ms % 1000));
|
||||||
if (time_us > 0) {
|
if (time_us > 0) {
|
||||||
sig_ms = ((uint64_t)nsigned * 1000000000) / time_us;
|
sig_ms = ((uint64_t)atomic_load(&nsigned) * 1000000000) /
|
||||||
|
time_us;
|
||||||
fprintf(out, "Signatures per second: %7u.%03u\n",
|
fprintf(out, "Signatures per second: %7u.%03u\n",
|
||||||
(unsigned int)sig_ms / 1000,
|
(unsigned int)sig_ms / 1000,
|
||||||
(unsigned int)sig_ms % 1000);
|
(unsigned int)sig_ms % 1000);
|
||||||
@@ -3363,8 +3351,6 @@ main(int argc, char *argv[]) {
|
|||||||
isc_time_t sign_start, sign_finish;
|
isc_time_t sign_start, sign_finish;
|
||||||
dns_dnsseckey_t *key;
|
dns_dnsseckey_t *key;
|
||||||
isc_result_t result, vresult;
|
isc_result_t result, vresult;
|
||||||
isc_log_t *log = NULL;
|
|
||||||
const char *engine = NULL;
|
|
||||||
bool free_output = false;
|
bool free_output = false;
|
||||||
int tempfilelen = 0;
|
int tempfilelen = 0;
|
||||||
dns_rdataclass_t rdclass;
|
dns_rdataclass_t rdclass;
|
||||||
@@ -3375,7 +3361,7 @@ main(int argc, char *argv[]) {
|
|||||||
bool set_iter = false;
|
bool set_iter = false;
|
||||||
bool nonsecify = false;
|
bool nonsecify = false;
|
||||||
bool set_fips_mode = false;
|
bool set_fips_mode = false;
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L && OPENSSL_API_LEVEL >= 30000
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
OSSL_PROVIDER *fips = NULL, *base = NULL;
|
OSSL_PROVIDER *fips = NULL, *base = NULL;
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
@@ -3472,7 +3458,7 @@ main(int argc, char *argv[]) {
|
|||||||
break;
|
break;
|
||||||
|
|
||||||
case 'E':
|
case 'E':
|
||||||
engine = isc_commandline_argument;
|
fatal("%s", isc_result_totext(DST_R_NOENGINE));
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case 'e':
|
case 'e':
|
||||||
@@ -3739,7 +3725,7 @@ main(int argc, char *argv[]) {
|
|||||||
isc_managers_create(&mctx, nloops, &loopmgr, &netmgr);
|
isc_managers_create(&mctx, nloops, &loopmgr, &netmgr);
|
||||||
|
|
||||||
if (set_fips_mode) {
|
if (set_fips_mode) {
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L && OPENSSL_API_LEVEL >= 30000
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
fips = OSSL_PROVIDER_load(NULL, "fips");
|
fips = OSSL_PROVIDER_load(NULL, "fips");
|
||||||
if (fips == NULL) {
|
if (fips == NULL) {
|
||||||
ERR_clear_error();
|
ERR_clear_error();
|
||||||
@@ -3759,13 +3745,7 @@ main(int argc, char *argv[]) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
result = dst_lib_init(mctx, engine);
|
setup_logging();
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
fatal("could not initialize dst: %s",
|
|
||||||
isc_result_totext(result));
|
|
||||||
}
|
|
||||||
|
|
||||||
setup_logging(mctx, &log);
|
|
||||||
|
|
||||||
argc -= isc_commandline_index;
|
argc -= isc_commandline_index;
|
||||||
argv += isc_commandline_index;
|
argv += isc_commandline_index;
|
||||||
@@ -4047,10 +4027,6 @@ main(int argc, char *argv[]) {
|
|||||||
|
|
||||||
isc_mutex_init(&namelock);
|
isc_mutex_init(&namelock);
|
||||||
|
|
||||||
if (printstats) {
|
|
||||||
isc_mutex_init(&statslock);
|
|
||||||
}
|
|
||||||
|
|
||||||
presign();
|
presign();
|
||||||
sign_start = isc_time_now();
|
sign_start = isc_time_now();
|
||||||
signapex();
|
signapex();
|
||||||
@@ -4136,13 +4112,11 @@ main(int argc, char *argv[]) {
|
|||||||
|
|
||||||
dns_master_styledestroy(&dsstyle, mctx);
|
dns_master_styledestroy(&dsstyle, mctx);
|
||||||
|
|
||||||
cleanup_logging(&log);
|
|
||||||
dst_lib_destroy();
|
|
||||||
if (verbose > 10) {
|
if (verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L && OPENSSL_API_LEVEL >= 30000
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
if (base != NULL) {
|
if (base != NULL) {
|
||||||
OSSL_PROVIDER_unload(base);
|
OSSL_PROVIDER_unload(base);
|
||||||
}
|
}
|
||||||
@@ -4157,7 +4131,6 @@ main(int argc, char *argv[]) {
|
|||||||
timer_finish = isc_time_now();
|
timer_finish = isc_time_now();
|
||||||
print_stats(&timer_start, &timer_finish, &sign_start,
|
print_stats(&timer_start, &timer_finish, &sign_start,
|
||||||
&sign_finish);
|
&sign_finish);
|
||||||
isc_mutex_destroy(&statslock);
|
|
||||||
}
|
}
|
||||||
isc_mutex_destroy(&namelock);
|
isc_mutex_destroy(&namelock);
|
||||||
|
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ dnssec-signzone - DNSSEC zone signing tool
|
|||||||
Synopsis
|
Synopsis
|
||||||
~~~~~~~~
|
~~~~~~~~
|
||||||
|
|
||||||
:program:`dnssec-signzone` [**-a**] [**-c** class] [**-d** directory] [**-D**] [**-E** engine] [**-e** end-time] [**-f** output-file] [**-F**] [**-g**] [**-G sync-records**] [**-h**] [**-i** interval] [**-I** input-format] [**-j** jitter] [**-J** filename] [**-K** directory] [**-k** key] [**-L** serial] [**-M** maxttl] [**-N** soa-serial-format] [**-o** origin] [**-O** output-format] [**-P**] [**-Q**] [**-q**] [**-R**] [**-S**] [**-s** start-time] [**-T** ttl] [**-t**] [**-u**] [**-v** level] [**-V**] [**-X** extended end-time] [**-x**] [**-z**] [**-3** salt] [**-H** iterations] [**-A**] {zonefile} [key...]
|
:program:`dnssec-signzone` [**-a**] [**-c** class] [**-d** directory] [**-D**] [**-e** end-time] [**-f** output-file] [**-F**] [**-g**] [**-G sync-records**] [**-h**] [**-i** interval] [**-I** input-format] [**-j** jitter] [**-J** filename] [**-K** directory] [**-k** key] [**-L** serial] [**-M** maxttl] [**-N** soa-serial-format] [**-o** origin] [**-O** output-format] [**-P**] [**-Q**] [**-q**] [**-R**] [**-S**] [**-s** start-time] [**-T** ttl] [**-t**] [**-u**] [**-v** level] [**-V**] [**-X** extended end-time] [**-x**] [**-z**] [**-3** salt] [**-H** iterations] [**-A**] {zonefile} [key...]
|
||||||
|
|
||||||
Description
|
Description
|
||||||
~~~~~~~~~~~
|
~~~~~~~~~~~
|
||||||
@@ -62,15 +62,6 @@ Options
|
|||||||
``$INCLUDE``. This option cannot be combined with :option:`-O raw <-O>`
|
``$INCLUDE``. This option cannot be combined with :option:`-O raw <-O>`
|
||||||
or serial-number updating.
|
or serial-number updating.
|
||||||
|
|
||||||
.. option:: -E engine
|
|
||||||
|
|
||||||
This option specifies the hardware to use for cryptographic
|
|
||||||
operations, such as a secure key store used for signing, when applicable.
|
|
||||||
|
|
||||||
When BIND 9 is built with OpenSSL, this needs to be set to the OpenSSL
|
|
||||||
engine identifier that drives the cryptographic accelerator or
|
|
||||||
hardware service module (usually ``pkcs11``).
|
|
||||||
|
|
||||||
.. option:: -F
|
.. option:: -F
|
||||||
|
|
||||||
This options turns on FIPS (US Federal Information Processing Standards)
|
This options turns on FIPS (US Federal Information Processing Standards)
|
||||||
|
|||||||
@@ -23,6 +23,7 @@
|
|||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/hex.h>
|
#include <isc/hex.h>
|
||||||
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/mutex.h>
|
#include <isc/mutex.h>
|
||||||
#include <isc/os.h>
|
#include <isc/os.h>
|
||||||
@@ -42,7 +43,6 @@
|
|||||||
#include <dns/ds.h>
|
#include <dns/ds.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
#include <dns/log.h>
|
|
||||||
#include <dns/master.h>
|
#include <dns/master.h>
|
||||||
#include <dns/masterdump.h>
|
#include <dns/masterdump.h>
|
||||||
#include <dns/nsec.h>
|
#include <dns/nsec.h>
|
||||||
@@ -136,7 +136,7 @@ loadzone(char *file, char *origin, dns_rdataclass_t rdclass, dns_db_t **db) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
noreturn static void
|
ISC_NORETURN static void
|
||||||
usage(void);
|
usage(void);
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -157,8 +157,6 @@ usage(void) {
|
|||||||
fprintf(stderr, "\t-I format:\n");
|
fprintf(stderr, "\t-I format:\n");
|
||||||
fprintf(stderr, "\t\tfile format of input zonefile (text)\n");
|
fprintf(stderr, "\t\tfile format of input zonefile (text)\n");
|
||||||
fprintf(stderr, "\t-c class (IN)\n");
|
fprintf(stderr, "\t-c class (IN)\n");
|
||||||
fprintf(stderr, "\t-E engine:\n");
|
|
||||||
fprintf(stderr, "\t\tname of an OpenSSL engine to use\n");
|
|
||||||
fprintf(stderr, "\t-x:\tDNSKEY record signed with KSKs only, "
|
fprintf(stderr, "\t-x:\tDNSKEY record signed with KSKs only, "
|
||||||
"not ZSKs\n");
|
"not ZSKs\n");
|
||||||
fprintf(stderr, "\t-z:\tAll records signed with KSKs\n");
|
fprintf(stderr, "\t-z:\tAll records signed with KSKs\n");
|
||||||
@@ -170,8 +168,6 @@ main(int argc, char *argv[]) {
|
|||||||
char *origin = NULL, *file = NULL;
|
char *origin = NULL, *file = NULL;
|
||||||
char *inputformatstr = NULL;
|
char *inputformatstr = NULL;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
isc_log_t *log = NULL;
|
|
||||||
const char *engine = NULL;
|
|
||||||
char *classname = NULL;
|
char *classname = NULL;
|
||||||
dns_rdataclass_t rdclass;
|
dns_rdataclass_t rdclass;
|
||||||
char *endp;
|
char *endp;
|
||||||
@@ -215,7 +211,7 @@ main(int argc, char *argv[]) {
|
|||||||
break;
|
break;
|
||||||
|
|
||||||
case 'E':
|
case 'E':
|
||||||
engine = isc_commandline_argument;
|
fatal("%s", isc_result_totext(DST_R_NOENGINE));
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case 'I':
|
case 'I':
|
||||||
@@ -275,17 +271,11 @@ main(int argc, char *argv[]) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
result = dst_lib_init(mctx, engine);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
fatal("could not initialize dst: %s",
|
|
||||||
isc_result_totext(result));
|
|
||||||
}
|
|
||||||
|
|
||||||
now = isc_stdtime_now();
|
now = isc_stdtime_now();
|
||||||
|
|
||||||
rdclass = strtoclass(classname);
|
rdclass = strtoclass(classname);
|
||||||
|
|
||||||
setup_logging(mctx, &log);
|
setup_logging();
|
||||||
|
|
||||||
argc -= isc_commandline_index;
|
argc -= isc_commandline_index;
|
||||||
argv += isc_commandline_index;
|
argv += isc_commandline_index;
|
||||||
@@ -335,8 +325,6 @@ main(int argc, char *argv[]) {
|
|||||||
dns_db_closeversion(gdb, &gversion, false);
|
dns_db_closeversion(gdb, &gversion, false);
|
||||||
dns_db_detach(&gdb);
|
dns_db_detach(&gdb);
|
||||||
|
|
||||||
cleanup_logging(&log);
|
|
||||||
dst_lib_destroy();
|
|
||||||
if (verbose > 10) {
|
if (verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ dnssec-verify - DNSSEC zone verification tool
|
|||||||
Synopsis
|
Synopsis
|
||||||
~~~~~~~~
|
~~~~~~~~
|
||||||
|
|
||||||
:program:`dnssec-verify` [**-c** class] [**-E** engine] [**-I** input-format] [**-J** filename] [**-o** origin] [**-q**] [**-v** level] [**-V**] [**-x**] [**-z**] {zonefile}
|
:program:`dnssec-verify` [**-c** class] [**-I** input-format] [**-J** filename] [**-o** origin] [**-q**] [**-v** level] [**-V**] [**-x**] [**-z**] {zonefile}
|
||||||
|
|
||||||
Description
|
Description
|
||||||
~~~~~~~~~~~
|
~~~~~~~~~~~
|
||||||
@@ -37,14 +37,6 @@ Options
|
|||||||
|
|
||||||
This option specifies the DNS class of the zone.
|
This option specifies the DNS class of the zone.
|
||||||
|
|
||||||
.. option:: -E engine
|
|
||||||
|
|
||||||
This option specifies the cryptographic hardware to use, when applicable.
|
|
||||||
|
|
||||||
When BIND 9 is built with OpenSSL, this needs to be set to the OpenSSL
|
|
||||||
engine identifier that drives the cryptographic accelerator or
|
|
||||||
hardware service module (usually ``pkcs11``).
|
|
||||||
|
|
||||||
.. option:: -I input-format
|
.. option:: -I input-format
|
||||||
|
|
||||||
This option sets the format of the input zone file. Possible formats are ``text``
|
This option sets the format of the input zone file. Possible formats are ``text``
|
||||||
|
|||||||
+31
-47
@@ -29,6 +29,7 @@
|
|||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/heap.h>
|
#include <isc/heap.h>
|
||||||
#include <isc/list.h>
|
#include <isc/list.h>
|
||||||
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
#include <isc/string.h>
|
#include <isc/string.h>
|
||||||
@@ -43,7 +44,6 @@
|
|||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/journal.h>
|
#include <dns/journal.h>
|
||||||
#include <dns/keyvalues.h>
|
#include <dns/keyvalues.h>
|
||||||
#include <dns/log.h>
|
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/nsec.h>
|
#include <dns/nsec.h>
|
||||||
#include <dns/nsec3.h>
|
#include <dns/nsec3.h>
|
||||||
@@ -128,10 +128,8 @@ sig_format(dns_rdata_rrsig_t *sig, char *cp, unsigned int size) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
void
|
void
|
||||||
setup_logging(isc_mem_t *mctx, isc_log_t **logp) {
|
setup_logging(void) {
|
||||||
isc_logdestination_t destination;
|
|
||||||
isc_logconfig_t *logconfig = NULL;
|
isc_logconfig_t *logconfig = NULL;
|
||||||
isc_log_t *log = NULL;
|
|
||||||
int level;
|
int level;
|
||||||
|
|
||||||
if (verbose < 0) {
|
if (verbose < 0) {
|
||||||
@@ -153,10 +151,8 @@ setup_logging(isc_mem_t *mctx, isc_log_t **logp) {
|
|||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_log_create(mctx, &log, &logconfig);
|
logconfig = isc_logconfig_get();
|
||||||
isc_log_setcontext(log);
|
|
||||||
dns_log_init(log);
|
|
||||||
dns_log_setcontext(log);
|
|
||||||
isc_log_settag(logconfig, program);
|
isc_log_settag(logconfig, program);
|
||||||
|
|
||||||
/*
|
/*
|
||||||
@@ -165,36 +161,11 @@ setup_logging(isc_mem_t *mctx, isc_log_t **logp) {
|
|||||||
* - the program name and logging level are printed
|
* - the program name and logging level are printed
|
||||||
* - no time stamp is printed
|
* - no time stamp is printed
|
||||||
*/
|
*/
|
||||||
destination.file.stream = stderr;
|
isc_log_createandusechannel(
|
||||||
destination.file.name = NULL;
|
logconfig, "default_stderr", ISC_LOG_TOFILEDESC, level,
|
||||||
destination.file.versions = ISC_LOG_ROLLNEVER;
|
ISC_LOGDESTINATION_STDERR,
|
||||||
destination.file.maximum_size = 0;
|
ISC_LOG_PRINTTAG | ISC_LOG_PRINTLEVEL, ISC_LOGCATEGORY_DEFAULT,
|
||||||
isc_log_createchannel(logconfig, "stderr", ISC_LOG_TOFILEDESC, level,
|
ISC_LOGMODULE_DEFAULT);
|
||||||
&destination,
|
|
||||||
ISC_LOG_PRINTTAG | ISC_LOG_PRINTLEVEL);
|
|
||||||
|
|
||||||
RUNTIME_CHECK(isc_log_usechannel(logconfig, "stderr", NULL, NULL) ==
|
|
||||||
ISC_R_SUCCESS);
|
|
||||||
|
|
||||||
*logp = log;
|
|
||||||
}
|
|
||||||
|
|
||||||
void
|
|
||||||
cleanup_logging(isc_log_t **logp) {
|
|
||||||
isc_log_t *log;
|
|
||||||
|
|
||||||
REQUIRE(logp != NULL);
|
|
||||||
|
|
||||||
log = *logp;
|
|
||||||
*logp = NULL;
|
|
||||||
|
|
||||||
if (log == NULL) {
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
isc_log_destroy(&log);
|
|
||||||
isc_log_setcontext(NULL);
|
|
||||||
dns_log_setcontext(NULL);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
static isc_stdtime_t
|
static isc_stdtime_t
|
||||||
@@ -479,7 +450,7 @@ set_keyversion(dst_key_t *key) {
|
|||||||
|
|
||||||
bool
|
bool
|
||||||
key_collision(dst_key_t *dstkey, dns_name_t *name, const char *dir,
|
key_collision(dst_key_t *dstkey, dns_name_t *name, const char *dir,
|
||||||
isc_mem_t *mctx, bool *exact) {
|
isc_mem_t *mctx, uint16_t min, uint16_t max, bool *exact) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
bool conflict = false;
|
bool conflict = false;
|
||||||
dns_dnsseckeylist_t matchkeys;
|
dns_dnsseckeylist_t matchkeys;
|
||||||
@@ -497,6 +468,21 @@ key_collision(dst_key_t *dstkey, dns_name_t *name, const char *dir,
|
|||||||
rid = dst_key_rid(dstkey);
|
rid = dst_key_rid(dstkey);
|
||||||
alg = dst_key_alg(dstkey);
|
alg = dst_key_alg(dstkey);
|
||||||
|
|
||||||
|
if (min != max) {
|
||||||
|
if (id < min || id > max) {
|
||||||
|
fprintf(stderr, "Key ID %d outside of [%u..%u]\n", id,
|
||||||
|
min, max);
|
||||||
|
return (true);
|
||||||
|
}
|
||||||
|
if (rid < min || rid > max) {
|
||||||
|
fprintf(stderr,
|
||||||
|
"Revoked Key ID %d (for tag %d) outside of "
|
||||||
|
"[%u..%u]\n",
|
||||||
|
rid, id, min, max);
|
||||||
|
return (true);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
ISC_LIST_INIT(matchkeys);
|
ISC_LIST_INIT(matchkeys);
|
||||||
result = dns_dnssec_findmatchingkeys(name, NULL, dir, NULL, now, mctx,
|
result = dns_dnssec_findmatchingkeys(name, NULL, dir, NULL, now, mctx,
|
||||||
&matchkeys);
|
&matchkeys);
|
||||||
@@ -604,9 +590,8 @@ cleanup:
|
|||||||
}
|
}
|
||||||
|
|
||||||
void
|
void
|
||||||
kasp_from_conf(cfg_obj_t *config, isc_mem_t *mctx, isc_log_t *lctx,
|
kasp_from_conf(cfg_obj_t *config, isc_mem_t *mctx, const char *name,
|
||||||
const char *name, const char *keydir, const char *engine,
|
const char *keydir, dns_kasp_t **kaspp) {
|
||||||
dns_kasp_t **kaspp) {
|
|
||||||
isc_result_t result = ISC_R_NOTFOUND;
|
isc_result_t result = ISC_R_NOTFOUND;
|
||||||
const cfg_listelt_t *element;
|
const cfg_listelt_t *element;
|
||||||
const cfg_obj_t *kasps = NULL;
|
const cfg_obj_t *kasps = NULL;
|
||||||
@@ -625,8 +610,7 @@ kasp_from_conf(cfg_obj_t *config, isc_mem_t *mctx, isc_log_t *lctx,
|
|||||||
{
|
{
|
||||||
cfg_obj_t *kconfig = cfg_listelt_value(element);
|
cfg_obj_t *kconfig = cfg_listelt_value(element);
|
||||||
ks = NULL;
|
ks = NULL;
|
||||||
result = cfg_keystore_fromconfig(kconfig, mctx, lctx, engine,
|
result = cfg_keystore_fromconfig(kconfig, mctx, &kslist, NULL);
|
||||||
&kslist, NULL);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("failed to configure key-store '%s': %s",
|
fatal("failed to configure key-store '%s': %s",
|
||||||
cfg_obj_asstring(cfg_tuple_get(kconfig, "name")),
|
cfg_obj_asstring(cfg_tuple_get(kconfig, "name")),
|
||||||
@@ -635,7 +619,7 @@ kasp_from_conf(cfg_obj_t *config, isc_mem_t *mctx, isc_log_t *lctx,
|
|||||||
}
|
}
|
||||||
/* Default key-directory key store. */
|
/* Default key-directory key store. */
|
||||||
ks = NULL;
|
ks = NULL;
|
||||||
(void)cfg_keystore_fromconfig(NULL, mctx, lctx, engine, &kslist, &ks);
|
(void)cfg_keystore_fromconfig(NULL, mctx, &kslist, &ks);
|
||||||
INSIST(ks != NULL);
|
INSIST(ks != NULL);
|
||||||
if (keydir != NULL) {
|
if (keydir != NULL) {
|
||||||
/* '-K keydir' takes priority */
|
/* '-K keydir' takes priority */
|
||||||
@@ -655,8 +639,8 @@ kasp_from_conf(cfg_obj_t *config, isc_mem_t *mctx, isc_log_t *lctx,
|
|||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
result = cfg_kasp_fromconfig(kconfig, NULL, true, mctx, lctx,
|
result = cfg_kasp_fromconfig(kconfig, NULL, true, mctx, &kslist,
|
||||||
&kslist, &kasplist, &kasp);
|
&kasplist, &kasp);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("failed to configure dnssec-policy '%s': %s",
|
fatal("failed to configure dnssec-policy '%s': %s",
|
||||||
cfg_obj_asstring(cfg_tuple_get(kconfig, "name")),
|
cfg_obj_asstring(cfg_tuple_get(kconfig, "name")),
|
||||||
|
|||||||
+6
-10
@@ -54,7 +54,7 @@ extern uint8_t dtype[8];
|
|||||||
|
|
||||||
typedef void(fatalcallback_t)(void);
|
typedef void(fatalcallback_t)(void);
|
||||||
|
|
||||||
noreturn void
|
ISC_NORETURN void
|
||||||
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||||
|
|
||||||
void
|
void
|
||||||
@@ -66,7 +66,7 @@ check_result(isc_result_t result, const char *message);
|
|||||||
void
|
void
|
||||||
vbprintf(int level, const char *fmt, ...) ISC_FORMAT_PRINTF(2, 3);
|
vbprintf(int level, const char *fmt, ...) ISC_FORMAT_PRINTF(2, 3);
|
||||||
|
|
||||||
noreturn void
|
ISC_NORETURN void
|
||||||
version(const char *program);
|
version(const char *program);
|
||||||
|
|
||||||
void
|
void
|
||||||
@@ -75,10 +75,7 @@ sig_format(dns_rdata_rrsig_t *sig, char *cp, unsigned int size);
|
|||||||
(DNS_NAME_FORMATSIZE + DNS_SECALG_FORMATSIZE + sizeof("65535"))
|
(DNS_NAME_FORMATSIZE + DNS_SECALG_FORMATSIZE + sizeof("65535"))
|
||||||
|
|
||||||
void
|
void
|
||||||
setup_logging(isc_mem_t *mctx, isc_log_t **logp);
|
setup_logging(void);
|
||||||
|
|
||||||
void
|
|
||||||
cleanup_logging(isc_log_t **logp);
|
|
||||||
|
|
||||||
dns_ttl_t
|
dns_ttl_t
|
||||||
strtottl(const char *str);
|
strtottl(const char *str);
|
||||||
@@ -109,7 +106,7 @@ set_keyversion(dst_key_t *key);
|
|||||||
|
|
||||||
bool
|
bool
|
||||||
key_collision(dst_key_t *key, dns_name_t *name, const char *dir,
|
key_collision(dst_key_t *key, dns_name_t *name, const char *dir,
|
||||||
isc_mem_t *mctx, bool *exact);
|
isc_mem_t *mctx, uint16_t min, uint16_t max, bool *exact);
|
||||||
|
|
||||||
bool
|
bool
|
||||||
isoptarg(const char *arg, char **argv, void (*usage)(void));
|
isoptarg(const char *arg, char **argv, void (*usage)(void));
|
||||||
@@ -118,6 +115,5 @@ void
|
|||||||
loadjournal(isc_mem_t *mctx, dns_db_t *db, const char *journal);
|
loadjournal(isc_mem_t *mctx, dns_db_t *db, const char *journal);
|
||||||
|
|
||||||
void
|
void
|
||||||
kasp_from_conf(cfg_obj_t *config, isc_mem_t *mctx, isc_log_t *lctx,
|
kasp_from_conf(cfg_obj_t *config, isc_mem_t *mctx, const char *name,
|
||||||
const char *name, const char *keydir, const char *engine,
|
const char *keydir, dns_kasp_t **kaspp);
|
||||||
dns_kasp_t **kaspp);
|
|
||||||
|
|||||||
+14
-12
@@ -63,7 +63,6 @@ options {\n\
|
|||||||
geoip-directory \".\";\n"
|
geoip-directory \".\";\n"
|
||||||
#endif /* if defined(HAVE_GEOIP2) */
|
#endif /* if defined(HAVE_GEOIP2) */
|
||||||
"\
|
"\
|
||||||
heartbeat-interval 60;\n\
|
|
||||||
interface-interval 60;\n\
|
interface-interval 60;\n\
|
||||||
listen-on {any;};\n\
|
listen-on {any;};\n\
|
||||||
listen-on-v6 {any;};\n\
|
listen-on-v6 {any;};\n\
|
||||||
@@ -170,7 +169,8 @@ options {\n\
|
|||||||
max-clients-per-query 100;\n\
|
max-clients-per-query 100;\n\
|
||||||
max-ncache-ttl 10800; /* 3 hours */\n\
|
max-ncache-ttl 10800; /* 3 hours */\n\
|
||||||
max-recursion-depth 7;\n\
|
max-recursion-depth 7;\n\
|
||||||
max-recursion-queries 100;\n\
|
max-recursion-queries 32;\n\
|
||||||
|
max-query-restarts 11;\n\
|
||||||
max-stale-ttl 86400; /* 1 day */\n\
|
max-stale-ttl 86400; /* 1 day */\n\
|
||||||
message-compression yes;\n\
|
message-compression yes;\n\
|
||||||
min-ncache-ttl 0; /* 0 hours */\n\
|
min-ncache-ttl 0; /* 0 hours */\n\
|
||||||
@@ -189,6 +189,7 @@ options {\n\
|
|||||||
recursion true;\n\
|
recursion true;\n\
|
||||||
request-expire true;\n\
|
request-expire true;\n\
|
||||||
request-ixfr true;\n\
|
request-ixfr true;\n\
|
||||||
|
request-ixfr-max-diffs 0;\n\
|
||||||
require-server-cookie no;\n\
|
require-server-cookie no;\n\
|
||||||
root-key-sentinel yes;\n\
|
root-key-sentinel yes;\n\
|
||||||
servfail-ttl 1;\n\
|
servfail-ttl 1;\n\
|
||||||
@@ -215,7 +216,6 @@ options {\n\
|
|||||||
check-sibling yes;\n\
|
check-sibling yes;\n\
|
||||||
check-srv-cname warn;\n\
|
check-srv-cname warn;\n\
|
||||||
check-wildcard yes;\n\
|
check-wildcard yes;\n\
|
||||||
dialup no;\n\
|
|
||||||
dnssec-loadkeys-interval 60;\n\
|
dnssec-loadkeys-interval 60;\n\
|
||||||
# forward <none>\n\
|
# forward <none>\n\
|
||||||
# forwarders <none>\n\
|
# forwarders <none>\n\
|
||||||
@@ -298,6 +298,7 @@ dnssec-policy \"default\" {\n\
|
|||||||
cds-digest-types { 2; };\n\
|
cds-digest-types { 2; };\n\
|
||||||
dnskey-ttl " DNS_KASP_KEY_TTL ";\n\
|
dnskey-ttl " DNS_KASP_KEY_TTL ";\n\
|
||||||
inline-signing yes;\n\
|
inline-signing yes;\n\
|
||||||
|
offline-ksk no;\n\
|
||||||
publish-safety " DNS_KASP_PUBLISH_SAFETY "; \n\
|
publish-safety " DNS_KASP_PUBLISH_SAFETY "; \n\
|
||||||
retire-safety " DNS_KASP_RETIRE_SAFETY "; \n\
|
retire-safety " DNS_KASP_RETIRE_SAFETY "; \n\
|
||||||
purge-keys " DNS_KASP_PURGE_KEYS "; \n\
|
purge-keys " DNS_KASP_PURGE_KEYS "; \n\
|
||||||
@@ -355,7 +356,9 @@ named_config_parsedefaults(cfg_parser_t *parser, cfg_obj_t **conf) {
|
|||||||
isc_buffer_init(&b, defaultconf, sizeof(defaultconf) - 1);
|
isc_buffer_init(&b, defaultconf, sizeof(defaultconf) - 1);
|
||||||
isc_buffer_add(&b, sizeof(defaultconf) - 1);
|
isc_buffer_add(&b, sizeof(defaultconf) - 1);
|
||||||
return (cfg_parse_buffer(parser, &b, __FILE__, 0, &cfg_type_namedconf,
|
return (cfg_parse_buffer(parser, &b, __FILE__, 0, &cfg_type_namedconf,
|
||||||
CFG_PCTX_NODEPRECATED, conf));
|
CFG_PCTX_NODEPRECATED | CFG_PCTX_NOOBSOLETE |
|
||||||
|
CFG_PCTX_NOEXPERIMENTAL,
|
||||||
|
conf));
|
||||||
}
|
}
|
||||||
|
|
||||||
const char *
|
const char *
|
||||||
@@ -448,8 +451,8 @@ named_config_getclass(const cfg_obj_t *classobj, dns_rdataclass_t defclass,
|
|||||||
r.length = strlen(r.base);
|
r.length = strlen(r.base);
|
||||||
result = dns_rdataclass_fromtext(classp, &r);
|
result = dns_rdataclass_fromtext(classp, &r);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(classobj, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(classobj, ISC_LOG_ERROR, "unknown class '%s'",
|
||||||
"unknown class '%s'", r.base);
|
r.base);
|
||||||
}
|
}
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
@@ -468,8 +471,8 @@ named_config_gettype(const cfg_obj_t *typeobj, dns_rdatatype_t deftype,
|
|||||||
r.length = strlen(r.base);
|
r.length = strlen(r.base);
|
||||||
result = dns_rdatatype_fromtext(typep, &r);
|
result = dns_rdatatype_fromtext(typep, &r);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(typeobj, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(typeobj, ISC_LOG_ERROR, "unknown type '%s'",
|
||||||
"unknown type '%s'", r.base);
|
r.base);
|
||||||
}
|
}
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
@@ -660,7 +663,7 @@ newlist:
|
|||||||
if (cfg_obj_isuint32(portobj)) {
|
if (cfg_obj_isuint32(portobj)) {
|
||||||
uint32_t val = cfg_obj_asuint32(portobj);
|
uint32_t val = cfg_obj_asuint32(portobj);
|
||||||
if (val > UINT16_MAX) {
|
if (val > UINT16_MAX) {
|
||||||
cfg_obj_log(portobj, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(portobj, ISC_LOG_ERROR,
|
||||||
"port '%u' out of range", val);
|
"port '%u' out of range", val);
|
||||||
result = ISC_R_RANGE;
|
result = ISC_R_RANGE;
|
||||||
goto cleanup;
|
goto cleanup;
|
||||||
@@ -715,7 +718,7 @@ resume:
|
|||||||
tresult = named_config_getremotesdef(config, listtype,
|
tresult = named_config_getremotesdef(config, listtype,
|
||||||
listname, &list);
|
listname, &list);
|
||||||
if (tresult == ISC_R_NOTFOUND) {
|
if (tresult == ISC_R_NOTFOUND) {
|
||||||
cfg_obj_log(addr, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(addr, ISC_LOG_ERROR,
|
||||||
"%s \"%s\" not found", listtype,
|
"%s \"%s\" not found", listtype,
|
||||||
listname);
|
listname);
|
||||||
|
|
||||||
@@ -887,8 +890,7 @@ named_config_getport(const cfg_obj_t *config, const char *type,
|
|||||||
result = named_config_get(maps, type, &portobj);
|
result = named_config_get(maps, type, &portobj);
|
||||||
INSIST(result == ISC_R_SUCCESS);
|
INSIST(result == ISC_R_SUCCESS);
|
||||||
if (cfg_obj_asuint32(portobj) >= UINT16_MAX) {
|
if (cfg_obj_asuint32(portobj) >= UINT16_MAX) {
|
||||||
cfg_obj_log(portobj, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(portobj, ISC_LOG_ERROR, "port '%u' out of range",
|
||||||
"port '%u' out of range",
|
|
||||||
cfg_obj_asuint32(portobj));
|
cfg_obj_asuint32(portobj));
|
||||||
return (ISC_R_RANGE);
|
return (ISC_R_RANGE);
|
||||||
}
|
}
|
||||||
|
|||||||
+12
-6
@@ -16,6 +16,7 @@
|
|||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
|
|
||||||
#include <isc/lex.h>
|
#include <isc/lex.h>
|
||||||
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
#include <isc/string.h>
|
#include <isc/string.h>
|
||||||
@@ -134,7 +135,7 @@ named_control_docommand(isccc_sexpr_t *message, bool readonly,
|
|||||||
!command_compare(command, NAMED_COMMAND_TESTGEN) &&
|
!command_compare(command, NAMED_COMMAND_TESTGEN) &&
|
||||||
!command_compare(command, NAMED_COMMAND_ZONESTATUS))
|
!command_compare(command, NAMED_COMMAND_ZONESTATUS))
|
||||||
{
|
{
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_CONTROL, log_level,
|
NAMED_LOGMODULE_CONTROL, log_level,
|
||||||
"rejecting restricted control channel "
|
"rejecting restricted control channel "
|
||||||
"command '%s'",
|
"command '%s'",
|
||||||
@@ -143,9 +144,9 @@ named_control_docommand(isccc_sexpr_t *message, bool readonly,
|
|||||||
goto cleanup;
|
goto cleanup;
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_CONTROL,
|
||||||
NAMED_LOGMODULE_CONTROL, log_level,
|
log_level, "received control channel command '%s'",
|
||||||
"received control channel command '%s'", cmdline);
|
cmdline);
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* After the lengthy "halt" and "stop", the commands are
|
* After the lengthy "halt" and "stop", the commands are
|
||||||
@@ -201,6 +202,9 @@ named_control_docommand(isccc_sexpr_t *message, bool readonly,
|
|||||||
command_compare(command, NAMED_COMMAND_MODZONE))
|
command_compare(command, NAMED_COMMAND_MODZONE))
|
||||||
{
|
{
|
||||||
result = named_server_changezone(named_g_server, cmdline, text);
|
result = named_server_changezone(named_g_server, cmdline, text);
|
||||||
|
} else if (command_compare(command, NAMED_COMMAND_CLOSELOGS)) {
|
||||||
|
isc_log_closefilelogs();
|
||||||
|
result = ISC_R_SUCCESS;
|
||||||
} else if (command_compare(command, NAMED_COMMAND_DELZONE)) {
|
} else if (command_compare(command, NAMED_COMMAND_DELZONE)) {
|
||||||
result = named_server_delzone(named_g_server, lex, text);
|
result = named_server_delzone(named_g_server, lex, text);
|
||||||
} else if (command_compare(command, NAMED_COMMAND_DNSSEC)) {
|
} else if (command_compare(command, NAMED_COMMAND_DNSSEC)) {
|
||||||
@@ -224,6 +228,8 @@ named_control_docommand(isccc_sexpr_t *message, bool readonly,
|
|||||||
result = named_server_flushnode(named_g_server, lex, true);
|
result = named_server_flushnode(named_g_server, lex, true);
|
||||||
} else if (command_compare(command, NAMED_COMMAND_FREEZE)) {
|
} else if (command_compare(command, NAMED_COMMAND_FREEZE)) {
|
||||||
result = named_server_freeze(named_g_server, true, lex, text);
|
result = named_server_freeze(named_g_server, true, lex, text);
|
||||||
|
} else if (command_compare(command, NAMED_COMMAND_SKR)) {
|
||||||
|
result = named_server_skr(named_g_server, lex, text);
|
||||||
} else if (command_compare(command, NAMED_COMMAND_LOADKEYS) ||
|
} else if (command_compare(command, NAMED_COMMAND_LOADKEYS) ||
|
||||||
command_compare(command, NAMED_COMMAND_SIGN))
|
command_compare(command, NAMED_COMMAND_SIGN))
|
||||||
{
|
{
|
||||||
@@ -234,7 +240,7 @@ named_control_docommand(isccc_sexpr_t *message, bool readonly,
|
|||||||
result = named_server_notifycommand(named_g_server, lex, text);
|
result = named_server_notifycommand(named_g_server, lex, text);
|
||||||
} else if (command_compare(command, NAMED_COMMAND_NOTRACE)) {
|
} else if (command_compare(command, NAMED_COMMAND_NOTRACE)) {
|
||||||
named_g_debuglevel = 0;
|
named_g_debuglevel = 0;
|
||||||
isc_log_setdebuglevel(named_g_lctx, named_g_debuglevel);
|
isc_log_setdebuglevel(named_g_debuglevel);
|
||||||
result = ISC_R_SUCCESS;
|
result = ISC_R_SUCCESS;
|
||||||
} else if (command_compare(command, NAMED_COMMAND_NTA)) {
|
} else if (command_compare(command, NAMED_COMMAND_NTA)) {
|
||||||
result = named_server_nta(named_g_server, lex, readonly, text);
|
result = named_server_nta(named_g_server, lex, readonly, text);
|
||||||
@@ -283,7 +289,7 @@ named_control_docommand(isccc_sexpr_t *message, bool readonly,
|
|||||||
} else if (command_compare(command, NAMED_COMMAND_ZONESTATUS)) {
|
} else if (command_compare(command, NAMED_COMMAND_ZONESTATUS)) {
|
||||||
result = named_server_zonestatus(named_g_server, lex, text);
|
result = named_server_zonestatus(named_g_server, lex, text);
|
||||||
} else {
|
} else {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_CONTROL, ISC_LOG_WARNING,
|
NAMED_LOGMODULE_CONTROL, ISC_LOG_WARNING,
|
||||||
"unknown control channel command '%s'", command);
|
"unknown control channel command '%s'", command);
|
||||||
result = DNS_R_UNKNOWNCOMMAND;
|
result = DNS_R_UNKNOWNCOMMAND;
|
||||||
|
|||||||
+38
-46
@@ -225,9 +225,9 @@ shutdown_listener(controllistener_t *listener) {
|
|||||||
|
|
||||||
char socktext[ISC_SOCKADDR_FORMATSIZE];
|
char socktext[ISC_SOCKADDR_FORMATSIZE];
|
||||||
isc_sockaddr_format(&listener->address, socktext, sizeof(socktext));
|
isc_sockaddr_format(&listener->address, socktext, sizeof(socktext));
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_CONTROL,
|
||||||
NAMED_LOGMODULE_CONTROL, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "stopping command channel on %s",
|
||||||
"stopping command channel on %s", socktext);
|
socktext);
|
||||||
|
|
||||||
isc_nm_stoplistening(listener->sock);
|
isc_nm_stoplistening(listener->sock);
|
||||||
isc_nmsocket_close(&listener->sock);
|
isc_nmsocket_close(&listener->sock);
|
||||||
@@ -272,7 +272,7 @@ control_senddone(isc_nmhandle_t *handle, isc_result_t result, void *arg) {
|
|||||||
isc_sockaddr_t peeraddr = isc_nmhandle_peeraddr(handle);
|
isc_sockaddr_t peeraddr = isc_nmhandle_peeraddr(handle);
|
||||||
|
|
||||||
isc_sockaddr_format(&peeraddr, socktext, sizeof(socktext));
|
isc_sockaddr_format(&peeraddr, socktext, sizeof(socktext));
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_CONTROL, ISC_LOG_WARNING,
|
NAMED_LOGMODULE_CONTROL, ISC_LOG_WARNING,
|
||||||
"error sending command response to %s: %s",
|
"error sending command response to %s: %s",
|
||||||
socktext, isc_result_totext(result));
|
socktext, isc_result_totext(result));
|
||||||
@@ -291,9 +291,8 @@ log_invalid(isccc_ccmsg_t *ccmsg, isc_result_t result) {
|
|||||||
isc_sockaddr_t peeraddr = isc_nmhandle_peeraddr(ccmsg->handle);
|
isc_sockaddr_t peeraddr = isc_nmhandle_peeraddr(ccmsg->handle);
|
||||||
|
|
||||||
isc_sockaddr_format(&peeraddr, socktext, sizeof(socktext));
|
isc_sockaddr_format(&peeraddr, socktext, sizeof(socktext));
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_CONTROL,
|
||||||
NAMED_LOGMODULE_CONTROL, ISC_LOG_ERROR,
|
ISC_LOG_ERROR, "invalid command from %s: %s", socktext,
|
||||||
"invalid command from %s: %s", socktext,
|
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -588,9 +587,8 @@ conn_free(controlconnection_t *conn) {
|
|||||||
}
|
}
|
||||||
#endif /* ifdef ENABLE_AFL */
|
#endif /* ifdef ENABLE_AFL */
|
||||||
|
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_CONTROL,
|
||||||
NAMED_LOGMODULE_CONTROL, ISC_LOG_DEBUG(3),
|
ISC_LOG_DEBUG(3), "freeing control connection");
|
||||||
"freeing control connection");
|
|
||||||
|
|
||||||
isc_mem_put(listener->mctx, conn, sizeof(*conn));
|
isc_mem_put(listener->mctx, conn, sizeof(*conn));
|
||||||
|
|
||||||
@@ -601,7 +599,7 @@ static void
|
|||||||
newconnection(controllistener_t *listener, isc_nmhandle_t *handle) {
|
newconnection(controllistener_t *listener, isc_nmhandle_t *handle) {
|
||||||
/* Don't create new connection if we are shutting down */
|
/* Don't create new connection if we are shutting down */
|
||||||
if (listener->shuttingdown) {
|
if (listener->shuttingdown) {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_CONTROL, ISC_LOG_DEBUG(3),
|
NAMED_LOGMODULE_CONTROL, ISC_LOG_DEBUG(3),
|
||||||
"rejected new control connection: %s",
|
"rejected new control connection: %s",
|
||||||
isc_result_totext(ISC_R_SHUTTINGDOWN));
|
isc_result_totext(ISC_R_SHUTTINGDOWN));
|
||||||
@@ -609,9 +607,8 @@ newconnection(controllistener_t *listener, isc_nmhandle_t *handle) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
controlconnection_t *conn = isc_mem_get(listener->mctx, sizeof(*conn));
|
controlconnection_t *conn = isc_mem_get(listener->mctx, sizeof(*conn));
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_CONTROL,
|
||||||
NAMED_LOGMODULE_CONTROL, ISC_LOG_DEBUG(3),
|
ISC_LOG_DEBUG(3), "allocate new control connection");
|
||||||
"allocate new control connection");
|
|
||||||
|
|
||||||
*conn = (controlconnection_t){
|
*conn = (controlconnection_t){
|
||||||
.alg = DST_ALG_UNKNOWN,
|
.alg = DST_ALG_UNKNOWN,
|
||||||
@@ -648,7 +645,7 @@ control_newconn(isc_nmhandle_t *handle, isc_result_t result, void *arg) {
|
|||||||
if (!address_ok(&peeraddr, listener)) {
|
if (!address_ok(&peeraddr, listener)) {
|
||||||
char socktext[ISC_SOCKADDR_FORMATSIZE];
|
char socktext[ISC_SOCKADDR_FORMATSIZE];
|
||||||
isc_sockaddr_format(&peeraddr, socktext, sizeof(socktext));
|
isc_sockaddr_format(&peeraddr, socktext, sizeof(socktext));
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_CONTROL, ISC_LOG_WARNING,
|
NAMED_LOGMODULE_CONTROL, ISC_LOG_WARNING,
|
||||||
"rejected command channel message from %s",
|
"rejected command channel message from %s",
|
||||||
socktext);
|
socktext);
|
||||||
@@ -760,7 +757,7 @@ register_keys(const cfg_obj_t *control, const cfg_obj_t *keylist,
|
|||||||
|
|
||||||
result = cfgkeylist_find(keylist, keyid->keyname, &keydef);
|
result = cfgkeylist_find(keylist, keyid->keyname, &keydef);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(control, named_g_lctx, ISC_LOG_WARNING,
|
cfg_obj_log(control, ISC_LOG_WARNING,
|
||||||
"couldn't find key '%s' for use with "
|
"couldn't find key '%s' for use with "
|
||||||
"command channel %s",
|
"command channel %s",
|
||||||
keyid->keyname, socktext);
|
keyid->keyname, socktext);
|
||||||
@@ -783,8 +780,7 @@ register_keys(const cfg_obj_t *control, const cfg_obj_t *keylist,
|
|||||||
result = named_config_getkeyalgorithm(algstr, &algtype,
|
result = named_config_getkeyalgorithm(algstr, &algtype,
|
||||||
NULL);
|
NULL);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(control, named_g_lctx,
|
cfg_obj_log(control, ISC_LOG_WARNING,
|
||||||
ISC_LOG_WARNING,
|
|
||||||
"unsupported algorithm '%s' in "
|
"unsupported algorithm '%s' in "
|
||||||
"key '%s' for use with command "
|
"key '%s' for use with command "
|
||||||
"channel %s",
|
"channel %s",
|
||||||
@@ -799,8 +795,7 @@ register_keys(const cfg_obj_t *control, const cfg_obj_t *keylist,
|
|||||||
result = isc_base64_decodestring(secretstr, &b);
|
result = isc_base64_decodestring(secretstr, &b);
|
||||||
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(keydef, named_g_lctx,
|
cfg_obj_log(keydef, ISC_LOG_WARNING,
|
||||||
ISC_LOG_WARNING,
|
|
||||||
"secret for key '%s' on "
|
"secret for key '%s' on "
|
||||||
"command channel %s: %s",
|
"command channel %s: %s",
|
||||||
keyid->keyname, socktext,
|
keyid->keyname, socktext,
|
||||||
@@ -834,14 +829,14 @@ get_rndckey(isc_mem_t *mctx, controlkeylist_t *keyids) {
|
|||||||
unsigned int algtype;
|
unsigned int algtype;
|
||||||
isc_buffer_t b;
|
isc_buffer_t b;
|
||||||
|
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_CONTROL,
|
||||||
NAMED_LOGMODULE_CONTROL, ISC_LOG_INFO,
|
ISC_LOG_INFO, "configuring command channel from '%s'",
|
||||||
"configuring command channel from '%s'", named_g_keyfile);
|
named_g_keyfile);
|
||||||
if (!isc_file_exists(named_g_keyfile)) {
|
if (!isc_file_exists(named_g_keyfile)) {
|
||||||
return (ISC_R_FILENOTFOUND);
|
return (ISC_R_FILENOTFOUND);
|
||||||
}
|
}
|
||||||
|
|
||||||
CHECK(cfg_parser_create(mctx, named_g_lctx, &pctx));
|
CHECK(cfg_parser_create(mctx, &pctx));
|
||||||
CHECK(cfg_parse_file(pctx, named_g_keyfile, &cfg_type_rndckey,
|
CHECK(cfg_parse_file(pctx, named_g_keyfile, &cfg_type_rndckey,
|
||||||
&config));
|
&config));
|
||||||
CHECK(cfg_map_get(config, "key", &key));
|
CHECK(cfg_map_get(config, "key", &key));
|
||||||
@@ -857,7 +852,7 @@ get_rndckey(isc_mem_t *mctx, controlkeylist_t *keyids) {
|
|||||||
CHECK(ISC_R_NOMEMORY);
|
CHECK(ISC_R_NOMEMORY);
|
||||||
}
|
}
|
||||||
|
|
||||||
CHECK(isccfg_check_key(key, named_g_lctx));
|
CHECK(isccfg_check_key(key));
|
||||||
|
|
||||||
(void)cfg_map_get(key, "algorithm", &algobj);
|
(void)cfg_map_get(key, "algorithm", &algobj);
|
||||||
(void)cfg_map_get(key, "secret", &secretobj);
|
(void)cfg_map_get(key, "secret", &secretobj);
|
||||||
@@ -868,7 +863,7 @@ get_rndckey(isc_mem_t *mctx, controlkeylist_t *keyids) {
|
|||||||
|
|
||||||
result = named_config_getkeyalgorithm(algstr, &algtype, NULL);
|
result = named_config_getkeyalgorithm(algstr, &algtype, NULL);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(key, named_g_lctx, ISC_LOG_WARNING,
|
cfg_obj_log(key, ISC_LOG_WARNING,
|
||||||
"unsupported algorithm '%s' in "
|
"unsupported algorithm '%s' in "
|
||||||
"key '%s' for use with command "
|
"key '%s' for use with command "
|
||||||
"channel",
|
"channel",
|
||||||
@@ -881,7 +876,7 @@ get_rndckey(isc_mem_t *mctx, controlkeylist_t *keyids) {
|
|||||||
result = isc_base64_decodestring(secretstr, &b);
|
result = isc_base64_decodestring(secretstr, &b);
|
||||||
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(key, named_g_lctx, ISC_LOG_WARNING,
|
cfg_obj_log(key, ISC_LOG_WARNING,
|
||||||
"secret for key '%s' on command channel: %s",
|
"secret for key '%s' on command channel: %s",
|
||||||
keyid->keyname, isc_result_totext(result));
|
keyid->keyname, isc_result_totext(result));
|
||||||
goto cleanup;
|
goto cleanup;
|
||||||
@@ -1009,12 +1004,12 @@ update_listener(named_controls_t *cp, controllistener_t **listenerp,
|
|||||||
* sake of avoiding this message would be too much trouble.
|
* sake of avoiding this message would be too much trouble.
|
||||||
*/
|
*/
|
||||||
if (control != NULL) {
|
if (control != NULL) {
|
||||||
cfg_obj_log(control, named_g_lctx, ISC_LOG_WARNING,
|
cfg_obj_log(control, ISC_LOG_WARNING,
|
||||||
"couldn't install new keys for "
|
"couldn't install new keys for "
|
||||||
"command channel %s: %s",
|
"command channel %s: %s",
|
||||||
socktext, isc_result_totext(result));
|
socktext, isc_result_totext(result));
|
||||||
} else {
|
} else {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_CONTROL, ISC_LOG_WARNING,
|
NAMED_LOGMODULE_CONTROL, ISC_LOG_WARNING,
|
||||||
"couldn't install new keys for "
|
"couldn't install new keys for "
|
||||||
"command channel %s: %s",
|
"command channel %s: %s",
|
||||||
@@ -1027,9 +1022,8 @@ update_listener(named_controls_t *cp, controllistener_t **listenerp,
|
|||||||
*/
|
*/
|
||||||
if (control != NULL && type == isc_socktype_tcp) {
|
if (control != NULL && type == isc_socktype_tcp) {
|
||||||
allow = cfg_tuple_get(control, "allow");
|
allow = cfg_tuple_get(control, "allow");
|
||||||
result = cfg_acl_fromconfig(allow, config, named_g_lctx,
|
result = cfg_acl_fromconfig(allow, config, aclconfctx,
|
||||||
aclconfctx, listener->mctx, 0,
|
listener->mctx, 0, &new_acl);
|
||||||
&new_acl);
|
|
||||||
} else {
|
} else {
|
||||||
result = dns_acl_any(listener->mctx, &new_acl);
|
result = dns_acl_any(listener->mctx, &new_acl);
|
||||||
}
|
}
|
||||||
@@ -1049,12 +1043,12 @@ update_listener(named_controls_t *cp, controllistener_t **listenerp,
|
|||||||
dns_acl_detach(&new_acl);
|
dns_acl_detach(&new_acl);
|
||||||
/* XXXDCL say the old acl is still used? */
|
/* XXXDCL say the old acl is still used? */
|
||||||
} else if (control != NULL) {
|
} else if (control != NULL) {
|
||||||
cfg_obj_log(control, named_g_lctx, ISC_LOG_WARNING,
|
cfg_obj_log(control, ISC_LOG_WARNING,
|
||||||
"couldn't install new acl for "
|
"couldn't install new acl for "
|
||||||
"command channel %s: %s",
|
"command channel %s: %s",
|
||||||
socktext, isc_result_totext(result));
|
socktext, isc_result_totext(result));
|
||||||
} else {
|
} else {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_CONTROL, ISC_LOG_WARNING,
|
NAMED_LOGMODULE_CONTROL, ISC_LOG_WARNING,
|
||||||
"couldn't install new acl for "
|
"couldn't install new acl for "
|
||||||
"command channel %s: %s",
|
"command channel %s: %s",
|
||||||
@@ -1101,8 +1095,8 @@ add_listener(named_controls_t *cp, controllistener_t **listenerp,
|
|||||||
const cfg_obj_t *readonly = NULL;
|
const cfg_obj_t *readonly = NULL;
|
||||||
|
|
||||||
allow = cfg_tuple_get(control, "allow");
|
allow = cfg_tuple_get(control, "allow");
|
||||||
CHECK(cfg_acl_fromconfig(allow, config, named_g_lctx,
|
CHECK(cfg_acl_fromconfig(allow, config, aclconfctx, mctx, 0,
|
||||||
aclconfctx, mctx, 0, &new_acl));
|
&new_acl));
|
||||||
|
|
||||||
readonly = cfg_tuple_get(control, "read-only");
|
readonly = cfg_tuple_get(control, "read-only");
|
||||||
if (!cfg_obj_isvoid(readonly)) {
|
if (!cfg_obj_isvoid(readonly)) {
|
||||||
@@ -1128,7 +1122,7 @@ add_listener(named_controls_t *cp, controllistener_t **listenerp,
|
|||||||
} else {
|
} else {
|
||||||
result = get_rndckey(mctx, &listener->keys);
|
result = get_rndckey(mctx, &listener->keys);
|
||||||
if (result != ISC_R_SUCCESS && control != NULL) {
|
if (result != ISC_R_SUCCESS && control != NULL) {
|
||||||
cfg_obj_log(control, named_g_lctx, ISC_LOG_WARNING,
|
cfg_obj_log(control, ISC_LOG_WARNING,
|
||||||
"couldn't install keys for "
|
"couldn't install keys for "
|
||||||
"command channel %s: %s",
|
"command channel %s: %s",
|
||||||
socktext, isc_result_totext(result));
|
socktext, isc_result_totext(result));
|
||||||
@@ -1146,9 +1140,9 @@ add_listener(named_controls_t *cp, controllistener_t **listenerp,
|
|||||||
&listener->address, control_newconn, listener, 5,
|
&listener->address, control_newconn, listener, 5,
|
||||||
NULL, &listener->sock));
|
NULL, &listener->sock));
|
||||||
|
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_CONTROL,
|
||||||
NAMED_LOGMODULE_CONTROL, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "command channel listening on %s",
|
||||||
"command channel listening on %s", socktext);
|
socktext);
|
||||||
*listenerp = listener;
|
*listenerp = listener;
|
||||||
return;
|
return;
|
||||||
|
|
||||||
@@ -1159,11 +1153,11 @@ cleanup:
|
|||||||
|
|
||||||
shuttingdown:
|
shuttingdown:
|
||||||
if (control != NULL) {
|
if (control != NULL) {
|
||||||
cfg_obj_log(control, named_g_lctx, ISC_LOG_WARNING,
|
cfg_obj_log(control, ISC_LOG_WARNING,
|
||||||
"couldn't add command channel %s: %s", socktext,
|
"couldn't add command channel %s: %s", socktext,
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
} else {
|
} else {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_CONTROL, ISC_LOG_NOTICE,
|
NAMED_LOGMODULE_CONTROL, ISC_LOG_NOTICE,
|
||||||
"couldn't add command channel %s: %s", socktext,
|
"couldn't add command channel %s: %s", socktext,
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
@@ -1208,8 +1202,7 @@ named_controls_configure(named_controls_t *cp, const cfg_obj_t *config,
|
|||||||
|
|
||||||
(void)cfg_map_get(controls, "unix", &unixcontrols);
|
(void)cfg_map_get(controls, "unix", &unixcontrols);
|
||||||
if (unixcontrols != NULL) {
|
if (unixcontrols != NULL) {
|
||||||
cfg_obj_log(controls, named_g_lctx,
|
cfg_obj_log(controls, ISC_LOG_ERROR,
|
||||||
ISC_LOG_ERROR,
|
|
||||||
"UNIX domain sockets are not "
|
"UNIX domain sockets are not "
|
||||||
"supported");
|
"supported");
|
||||||
return (ISC_R_FAILURE);
|
return (ISC_R_FAILURE);
|
||||||
@@ -1245,8 +1238,7 @@ named_controls_configure(named_controls_t *cp, const cfg_obj_t *config,
|
|||||||
isc_sockaddr_format(&addr, socktext,
|
isc_sockaddr_format(&addr, socktext,
|
||||||
sizeof(socktext));
|
sizeof(socktext));
|
||||||
|
|
||||||
isc_log_write(named_g_lctx,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGCATEGORY_GENERAL,
|
|
||||||
NAMED_LOGMODULE_CONTROL,
|
NAMED_LOGMODULE_CONTROL,
|
||||||
ISC_LOG_DEBUG(9),
|
ISC_LOG_DEBUG(9),
|
||||||
"processing control channel %s",
|
"processing control channel %s",
|
||||||
|
|||||||
@@ -17,13 +17,13 @@
|
|||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
#include <string.h>
|
#include <string.h>
|
||||||
|
|
||||||
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
#include <isc/util.h>
|
#include <isc/util.h>
|
||||||
#include <isc/uv.h>
|
#include <isc/uv.h>
|
||||||
|
|
||||||
#include <dns/dlz_dlopen.h>
|
#include <dns/dlz_dlopen.h>
|
||||||
#include <dns/log.h>
|
|
||||||
|
|
||||||
#include <dlz/dlz_dlopen_driver.h>
|
#include <dlz/dlz_dlopen_driver.h>
|
||||||
#include <named/globals.h>
|
#include <named/globals.h>
|
||||||
@@ -80,7 +80,7 @@ static void
|
|||||||
dlopen_log(int level, const char *fmt, ...) {
|
dlopen_log(int level, const char *fmt, ...) {
|
||||||
va_list ap;
|
va_list ap;
|
||||||
va_start(ap, fmt);
|
va_start(ap, fmt);
|
||||||
isc_log_vwrite(dns_lctx, DNS_LOGCATEGORY_DATABASE, DNS_LOGMODULE_DLZ,
|
isc_log_vwrite(DNS_LOGCATEGORY_DATABASE, DNS_LOGMODULE_DLZ,
|
||||||
ISC_LOG_DEBUG(level), fmt, ap);
|
ISC_LOG_DEBUG(level), fmt, ap);
|
||||||
va_end(ap);
|
va_end(ap);
|
||||||
}
|
}
|
||||||
|
|||||||
+1
-2
@@ -26,13 +26,12 @@
|
|||||||
#include <unistd.h>
|
#include <unistd.h>
|
||||||
|
|
||||||
#include <isc/condition.h>
|
#include <isc/condition.h>
|
||||||
|
#include <isc/log.h>
|
||||||
#include <isc/loop.h>
|
#include <isc/loop.h>
|
||||||
#include <isc/mutex.h>
|
#include <isc/mutex.h>
|
||||||
#include <isc/thread.h>
|
#include <isc/thread.h>
|
||||||
#include <isc/util.h>
|
#include <isc/util.h>
|
||||||
|
|
||||||
#include <dns/log.h>
|
|
||||||
|
|
||||||
#include <named/globals.h>
|
#include <named/globals.h>
|
||||||
#include <named/log.h>
|
#include <named/log.h>
|
||||||
#include <named/server.h>
|
#include <named/server.h>
|
||||||
|
|||||||
+10
-10
@@ -39,8 +39,8 @@ open_geoip2(const char *dir, const char *dbfile, MMDB_s *mmdb) {
|
|||||||
|
|
||||||
n = snprintf(pathbuf, sizeof(pathbuf), "%s/%s", dir, dbfile);
|
n = snprintf(pathbuf, sizeof(pathbuf), "%s/%s", dir, dbfile);
|
||||||
if (n >= sizeof(pathbuf)) {
|
if (n >= sizeof(pathbuf)) {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
ISC_LOG_ERROR,
|
||||||
"GeoIP2 database '%s/%s': path too long", dir,
|
"GeoIP2 database '%s/%s': path too long", dir,
|
||||||
dbfile);
|
dbfile);
|
||||||
return (NULL);
|
return (NULL);
|
||||||
@@ -48,14 +48,14 @@ open_geoip2(const char *dir, const char *dbfile, MMDB_s *mmdb) {
|
|||||||
|
|
||||||
ret = MMDB_open(pathbuf, MMDB_MODE_MMAP, mmdb);
|
ret = MMDB_open(pathbuf, MMDB_MODE_MMAP, mmdb);
|
||||||
if (ret == MMDB_SUCCESS) {
|
if (ret == MMDB_SUCCESS) {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
|
ISC_LOG_INFO, "opened GeoIP2 database '%s'",
|
||||||
"opened GeoIP2 database '%s'", pathbuf);
|
pathbuf);
|
||||||
return (mmdb);
|
return (mmdb);
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_DEBUG(1),
|
ISC_LOG_DEBUG(1),
|
||||||
"unable to open GeoIP2 database '%s' (status %d)",
|
"unable to open GeoIP2 database '%s' (status %d)",
|
||||||
pathbuf, ret);
|
pathbuf, ret);
|
||||||
|
|
||||||
@@ -79,9 +79,9 @@ named_geoip_load(char *dir) {
|
|||||||
#if defined(HAVE_GEOIP2)
|
#if defined(HAVE_GEOIP2)
|
||||||
REQUIRE(dir != NULL);
|
REQUIRE(dir != NULL);
|
||||||
|
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
|
ISC_LOG_INFO, "looking for GeoIP2 databases in '%s'",
|
||||||
"looking for GeoIP2 databases in '%s'", dir);
|
dir);
|
||||||
|
|
||||||
named_g_geoip->country = open_geoip2(dir, "GeoIP2-Country.mmdb",
|
named_g_geoip->country = open_geoip2(dir, "GeoIP2-Country.mmdb",
|
||||||
&geoip_country);
|
&geoip_country);
|
||||||
|
|||||||
@@ -28,48 +28,50 @@
|
|||||||
|
|
||||||
#define NAMED_CONTROL_PORT 953
|
#define NAMED_CONTROL_PORT 953
|
||||||
|
|
||||||
#define NAMED_COMMAND_STOP "stop"
|
#define NAMED_COMMAND_ADDZONE "addzone"
|
||||||
#define NAMED_COMMAND_HALT "halt"
|
#define NAMED_COMMAND_CLOSELOGS "closelogs"
|
||||||
#define NAMED_COMMAND_RELOAD "reload"
|
#define NAMED_COMMAND_DELZONE "delzone"
|
||||||
#define NAMED_COMMAND_RECONFIG "reconfig"
|
#define NAMED_COMMAND_DNSSEC "dnssec"
|
||||||
#define NAMED_COMMAND_REFRESH "refresh"
|
#define NAMED_COMMAND_DNSTAP "dnstap"
|
||||||
#define NAMED_COMMAND_RETRANSFER "retransfer"
|
#define NAMED_COMMAND_DNSTAPREOPEN "dnstap-reopen"
|
||||||
#define NAMED_COMMAND_DUMPSTATS "stats"
|
|
||||||
#define NAMED_COMMAND_QUERYLOG "querylog"
|
|
||||||
#define NAMED_COMMAND_DUMPDB "dumpdb"
|
#define NAMED_COMMAND_DUMPDB "dumpdb"
|
||||||
#define NAMED_COMMAND_SECROOTS "secroots"
|
#define NAMED_COMMAND_DUMPSTATS "stats"
|
||||||
#define NAMED_COMMAND_TRACE "trace"
|
#define NAMED_COMMAND_FETCHLIMIT "fetchlimit"
|
||||||
#define NAMED_COMMAND_NOTRACE "notrace"
|
|
||||||
#define NAMED_COMMAND_FLUSH "flush"
|
#define NAMED_COMMAND_FLUSH "flush"
|
||||||
#define NAMED_COMMAND_FLUSHNAME "flushname"
|
#define NAMED_COMMAND_FLUSHNAME "flushname"
|
||||||
#define NAMED_COMMAND_FLUSHTREE "flushtree"
|
#define NAMED_COMMAND_FLUSHTREE "flushtree"
|
||||||
#define NAMED_COMMAND_STATUS "status"
|
|
||||||
#define NAMED_COMMAND_FREEZE "freeze"
|
#define NAMED_COMMAND_FREEZE "freeze"
|
||||||
#define NAMED_COMMAND_UNFREEZE "unfreeze"
|
#define NAMED_COMMAND_HALT "halt"
|
||||||
#define NAMED_COMMAND_THAW "thaw"
|
|
||||||
#define NAMED_COMMAND_RECURSING "recursing"
|
|
||||||
#define NAMED_COMMAND_NULL "null"
|
|
||||||
#define NAMED_COMMAND_NOTIFY "notify"
|
|
||||||
#define NAMED_COMMAND_VALIDATION "validation"
|
|
||||||
#define NAMED_COMMAND_SCAN "scan"
|
|
||||||
#define NAMED_COMMAND_SIGN "sign"
|
|
||||||
#define NAMED_COMMAND_LOADKEYS "loadkeys"
|
#define NAMED_COMMAND_LOADKEYS "loadkeys"
|
||||||
#define NAMED_COMMAND_ADDZONE "addzone"
|
|
||||||
#define NAMED_COMMAND_MODZONE "modzone"
|
|
||||||
#define NAMED_COMMAND_DELZONE "delzone"
|
|
||||||
#define NAMED_COMMAND_SHOWZONE "showzone"
|
|
||||||
#define NAMED_COMMAND_SYNC "sync"
|
|
||||||
#define NAMED_COMMAND_SIGNING "signing"
|
|
||||||
#define NAMED_COMMAND_DNSSEC "dnssec"
|
|
||||||
#define NAMED_COMMAND_ZONESTATUS "zonestatus"
|
|
||||||
#define NAMED_COMMAND_NTA "nta"
|
|
||||||
#define NAMED_COMMAND_TESTGEN "testgen"
|
|
||||||
#define NAMED_COMMAND_MKEYS "managed-keys"
|
#define NAMED_COMMAND_MKEYS "managed-keys"
|
||||||
#define NAMED_COMMAND_DNSTAPREOPEN "dnstap-reopen"
|
#define NAMED_COMMAND_MODZONE "modzone"
|
||||||
#define NAMED_COMMAND_DNSTAP "dnstap"
|
#define NAMED_COMMAND_NOTIFY "notify"
|
||||||
#define NAMED_COMMAND_TCPTIMEOUTS "tcp-timeouts"
|
#define NAMED_COMMAND_NOTRACE "notrace"
|
||||||
|
#define NAMED_COMMAND_NTA "nta"
|
||||||
|
#define NAMED_COMMAND_NULL "null"
|
||||||
|
#define NAMED_COMMAND_QUERYLOG "querylog"
|
||||||
|
#define NAMED_COMMAND_RECONFIG "reconfig"
|
||||||
|
#define NAMED_COMMAND_RECURSING "recursing"
|
||||||
|
#define NAMED_COMMAND_REFRESH "refresh"
|
||||||
|
#define NAMED_COMMAND_RELOAD "reload"
|
||||||
|
#define NAMED_COMMAND_RETRANSFER "retransfer"
|
||||||
|
#define NAMED_COMMAND_SCAN "scan"
|
||||||
|
#define NAMED_COMMAND_SECROOTS "secroots"
|
||||||
#define NAMED_COMMAND_SERVESTALE "serve-stale"
|
#define NAMED_COMMAND_SERVESTALE "serve-stale"
|
||||||
#define NAMED_COMMAND_FETCHLIMIT "fetchlimit"
|
#define NAMED_COMMAND_SHOWZONE "showzone"
|
||||||
|
#define NAMED_COMMAND_SIGN "sign"
|
||||||
|
#define NAMED_COMMAND_SIGNING "signing"
|
||||||
|
#define NAMED_COMMAND_SKR "skr"
|
||||||
|
#define NAMED_COMMAND_STATUS "status"
|
||||||
|
#define NAMED_COMMAND_STOP "stop"
|
||||||
|
#define NAMED_COMMAND_SYNC "sync"
|
||||||
|
#define NAMED_COMMAND_TCPTIMEOUTS "tcp-timeouts"
|
||||||
|
#define NAMED_COMMAND_TESTGEN "testgen"
|
||||||
|
#define NAMED_COMMAND_THAW "thaw"
|
||||||
|
#define NAMED_COMMAND_TRACE "trace"
|
||||||
|
#define NAMED_COMMAND_UNFREEZE "unfreeze"
|
||||||
|
#define NAMED_COMMAND_VALIDATION "validation"
|
||||||
|
#define NAMED_COMMAND_ZONESTATUS "zonestatus"
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
named_controls_create(named_server_t *server, named_controls_t **ctrlsp);
|
named_controls_create(named_server_t *server, named_controls_t **ctrlsp);
|
||||||
|
|||||||
@@ -86,10 +86,8 @@ EXTERN named_server_t *named_g_server INIT(NULL);
|
|||||||
/*
|
/*
|
||||||
* Logging.
|
* Logging.
|
||||||
*/
|
*/
|
||||||
EXTERN isc_log_t *named_g_lctx INIT(NULL);
|
EXTERN bool named_g_logging INIT(false);
|
||||||
EXTERN isc_logcategory_t *named_g_categories INIT(NULL);
|
EXTERN unsigned int named_g_debuglevel INIT(0);
|
||||||
EXTERN isc_logmodule_t *named_g_modules INIT(NULL);
|
|
||||||
EXTERN unsigned int named_g_debuglevel INIT(0);
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Current configuration information.
|
* Current configuration information.
|
||||||
@@ -129,8 +127,6 @@ EXTERN const char *named_g_defaultpidfile INIT(NAMED_LOCALSTATEDIR "/run/"
|
|||||||
|
|
||||||
EXTERN const char *named_g_username INIT(NULL);
|
EXTERN const char *named_g_username INIT(NULL);
|
||||||
|
|
||||||
EXTERN const char *named_g_engine INIT(NULL);
|
|
||||||
|
|
||||||
EXTERN isc_time_t named_g_boottime;
|
EXTERN isc_time_t named_g_boottime;
|
||||||
EXTERN isc_time_t named_g_configtime;
|
EXTERN isc_time_t named_g_configtime;
|
||||||
EXTERN bool named_g_memstatistics INIT(false);
|
EXTERN bool named_g_memstatistics INIT(false);
|
||||||
|
|||||||
@@ -18,22 +18,8 @@
|
|||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/types.h>
|
#include <isc/types.h>
|
||||||
|
|
||||||
#include <dns/log.h>
|
|
||||||
|
|
||||||
#include <named/globals.h> /* Required for named_g_(categories|modules). */
|
#include <named/globals.h> /* Required for named_g_(categories|modules). */
|
||||||
|
|
||||||
/* Unused slot 0. */
|
|
||||||
#define NAMED_LOGCATEGORY_UNMATCHED (&named_g_categories[1])
|
|
||||||
|
|
||||||
/*
|
|
||||||
* Backwards compatibility.
|
|
||||||
*/
|
|
||||||
#define NAMED_LOGCATEGORY_GENERAL ISC_LOGCATEGORY_GENERAL
|
|
||||||
|
|
||||||
#define NAMED_LOGMODULE_MAIN (&named_g_modules[0])
|
|
||||||
#define NAMED_LOGMODULE_SERVER (&named_g_modules[1])
|
|
||||||
#define NAMED_LOGMODULE_CONTROL (&named_g_modules[2])
|
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
named_log_init(bool safe);
|
named_log_init(bool safe);
|
||||||
/*%
|
/*%
|
||||||
@@ -79,6 +65,3 @@ named_log_setunmatchedcategory(isc_logconfig_t *lcfg);
|
|||||||
/*%
|
/*%
|
||||||
* Set up "category unmatched" to go to the right places.
|
* Set up "category unmatched" to go to the right places.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
void
|
|
||||||
named_log_shutdown(void);
|
|
||||||
|
|||||||
@@ -26,7 +26,7 @@
|
|||||||
*/
|
*/
|
||||||
#define NAMED_MAIN_ARGS "46A:c:Cd:D:E:fFgL:M:m:n:N:p:sS:t:T:U:u:vVx:X:"
|
#define NAMED_MAIN_ARGS "46A:c:Cd:D:E:fFgL:M:m:n:N:p:sS:t:T:U:u:vVx:X:"
|
||||||
|
|
||||||
noreturn void
|
ISC_NORETURN void
|
||||||
named_main_earlyfatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
named_main_earlyfatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||||
|
|
||||||
void
|
void
|
||||||
|
|||||||
@@ -39,10 +39,13 @@ void
|
|||||||
named_os_inituserinfo(const char *username);
|
named_os_inituserinfo(const char *username);
|
||||||
|
|
||||||
void
|
void
|
||||||
named_os_changeuser(void);
|
named_os_changeuser(bool permanent);
|
||||||
|
|
||||||
|
void
|
||||||
|
named_os_restoreuser(void);
|
||||||
|
|
||||||
uid_t
|
uid_t
|
||||||
ns_os_uid(void);
|
named_os_uid(void);
|
||||||
|
|
||||||
void
|
void
|
||||||
named_os_adjustnofile(void);
|
named_os_adjustnofile(void);
|
||||||
|
|||||||
@@ -75,7 +75,6 @@ struct named_server {
|
|||||||
isc_timer_t *tat_timer;
|
isc_timer_t *tat_timer;
|
||||||
|
|
||||||
uint32_t interface_interval;
|
uint32_t interface_interval;
|
||||||
uint32_t heartbeat_interval;
|
|
||||||
|
|
||||||
atomic_int reload_status;
|
atomic_int reload_status;
|
||||||
|
|
||||||
@@ -108,6 +107,7 @@ struct named_server {
|
|||||||
isc_tlsctx_cache_t *tlsctx_client_cache;
|
isc_tlsctx_cache_t *tlsctx_client_cache;
|
||||||
|
|
||||||
isc_signal_t *sighup;
|
isc_signal_t *sighup;
|
||||||
|
isc_signal_t *sigusr1;
|
||||||
};
|
};
|
||||||
|
|
||||||
#define NAMED_SERVER_MAGIC ISC_MAGIC('S', 'V', 'E', 'R')
|
#define NAMED_SERVER_MAGIC ISC_MAGIC('S', 'V', 'E', 'R')
|
||||||
@@ -375,3 +375,9 @@ named_server_servestale(named_server_t *server, isc_lex_t *lex,
|
|||||||
isc_result_t
|
isc_result_t
|
||||||
named_server_fetchlimit(named_server_t *server, isc_lex_t *lex,
|
named_server_fetchlimit(named_server_t *server, isc_lex_t *lex,
|
||||||
isc_buffer_t **text);
|
isc_buffer_t **text);
|
||||||
|
|
||||||
|
/*%
|
||||||
|
* Import SKR file for offline KSK signing.
|
||||||
|
*/
|
||||||
|
isc_result_t
|
||||||
|
named_server_skr(named_server_t *server, isc_lex_t *lex, isc_buffer_t **text);
|
||||||
|
|||||||
+23
-68
@@ -15,67 +15,29 @@
|
|||||||
|
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
|
|
||||||
|
#include <isc/log.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
#include <isc/util.h>
|
#include <isc/util.h>
|
||||||
|
|
||||||
#include <dns/log.h>
|
|
||||||
|
|
||||||
#include <isccfg/log.h>
|
|
||||||
|
|
||||||
#include <ns/log.h>
|
|
||||||
|
|
||||||
#include <named/log.h>
|
#include <named/log.h>
|
||||||
|
|
||||||
#ifndef ISC_FACILITY
|
#ifndef ISC_FACILITY
|
||||||
#define ISC_FACILITY LOG_DAEMON
|
#define ISC_FACILITY LOG_DAEMON
|
||||||
#endif /* ifndef ISC_FACILITY */
|
#endif /* ifndef ISC_FACILITY */
|
||||||
|
|
||||||
/*%
|
|
||||||
* When adding a new category, be sure to add the appropriate
|
|
||||||
* \#define to <named/log.h> and to update the list in
|
|
||||||
* bin/check/check-tool.c.
|
|
||||||
*/
|
|
||||||
static isc_logcategory_t categories[] = { { "", 0 },
|
|
||||||
{ "unmatched", 0 },
|
|
||||||
{ NULL, 0 } };
|
|
||||||
|
|
||||||
/*%
|
|
||||||
* When adding a new module, be sure to add the appropriate
|
|
||||||
* \#define to <dns/log.h>.
|
|
||||||
*/
|
|
||||||
static isc_logmodule_t modules[] = {
|
|
||||||
{ "main", 0 }, { "server", 0 }, { "control", 0 }, { NULL, 0 }
|
|
||||||
};
|
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
named_log_init(bool safe) {
|
named_log_init(bool safe) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
isc_logconfig_t *lcfg = NULL;
|
isc_logconfig_t *lcfg = NULL;
|
||||||
isc_mem_t *log_mctx = NULL;
|
|
||||||
|
|
||||||
named_g_categories = categories;
|
|
||||||
named_g_modules = modules;
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Setup a logging context.
|
* This is not technically needed, as we are calling named_log_init()
|
||||||
|
* only at the start of named process. But since the named binary is
|
||||||
|
* the only place that also calls isc_logconfig_set(), this is a good
|
||||||
|
* hygiene.
|
||||||
*/
|
*/
|
||||||
isc_mem_create(&log_mctx);
|
rcu_read_lock();
|
||||||
isc_mem_setname(log_mctx, "named_log");
|
lcfg = isc_logconfig_get();
|
||||||
isc_log_create(log_mctx, &named_g_lctx, &lcfg);
|
|
||||||
isc_mem_detach(&log_mctx);
|
|
||||||
|
|
||||||
/*
|
|
||||||
* named-checktool.c:setup_logging() needs to be kept in sync.
|
|
||||||
*/
|
|
||||||
isc_log_registercategories(named_g_lctx, named_g_categories);
|
|
||||||
isc_log_registermodules(named_g_lctx, named_g_modules);
|
|
||||||
isc_log_setcontext(named_g_lctx);
|
|
||||||
dns_log_init(named_g_lctx);
|
|
||||||
dns_log_setcontext(named_g_lctx);
|
|
||||||
cfg_log_init(named_g_lctx);
|
|
||||||
ns_log_init(named_g_lctx);
|
|
||||||
ns_log_setcontext(named_g_lctx);
|
|
||||||
|
|
||||||
if (safe) {
|
if (safe) {
|
||||||
named_log_setsafechannels(lcfg);
|
named_log_setsafechannels(lcfg);
|
||||||
} else {
|
} else {
|
||||||
@@ -88,13 +50,14 @@ named_log_init(bool safe) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
named_log_setdefaultsslkeylogfile(lcfg);
|
named_log_setdefaultsslkeylogfile(lcfg);
|
||||||
|
rcu_read_unlock();
|
||||||
|
|
||||||
|
named_g_logging = true;
|
||||||
|
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
isc_log_destroy(&named_g_lctx);
|
rcu_read_unlock();
|
||||||
isc_log_setcontext(NULL);
|
|
||||||
dns_log_setcontext(NULL);
|
|
||||||
|
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
@@ -139,7 +102,7 @@ named_log_setdefaultchannels(isc_logconfig_t *lcfg) {
|
|||||||
/*
|
/*
|
||||||
* Set the initial debug level.
|
* Set the initial debug level.
|
||||||
*/
|
*/
|
||||||
isc_log_setdebuglevel(named_g_lctx, named_g_debuglevel);
|
isc_log_setdebuglevel(named_g_debuglevel);
|
||||||
}
|
}
|
||||||
|
|
||||||
void
|
void
|
||||||
@@ -154,9 +117,9 @@ named_log_setsafechannels(isc_logconfig_t *lcfg) {
|
|||||||
* Setting the debug level to zero should get the output
|
* Setting the debug level to zero should get the output
|
||||||
* discarded a bit faster.
|
* discarded a bit faster.
|
||||||
*/
|
*/
|
||||||
isc_log_setdebuglevel(named_g_lctx, 0);
|
isc_log_setdebuglevel(0);
|
||||||
} else {
|
} else {
|
||||||
isc_log_setdebuglevel(named_g_lctx, named_g_debuglevel);
|
isc_log_setdebuglevel(named_g_debuglevel);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (named_g_logfile != NULL) {
|
if (named_g_logfile != NULL) {
|
||||||
@@ -199,7 +162,6 @@ named_log_setdefaultsslkeylogfile(isc_logconfig_t *lcfg) {
|
|||||||
.maximum_size = 100 * 1024 * 1024,
|
.maximum_size = 100 * 1024 * 1024,
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
isc_result_t result;
|
|
||||||
|
|
||||||
if (sslkeylogfile_path == NULL ||
|
if (sslkeylogfile_path == NULL ||
|
||||||
strcmp(sslkeylogfile_path, "config") == 0)
|
strcmp(sslkeylogfile_path, "config") == 0)
|
||||||
@@ -207,11 +169,10 @@ named_log_setdefaultsslkeylogfile(isc_logconfig_t *lcfg) {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_log_createchannel(lcfg, "default_sslkeylogfile", ISC_LOG_TOFILE,
|
isc_log_createandusechannel(lcfg, "default_sslkeylogfile",
|
||||||
ISC_LOG_INFO, &destination, 0);
|
ISC_LOG_TOFILE, ISC_LOG_INFO, &destination,
|
||||||
result = isc_log_usechannel(lcfg, "default_sslkeylogfile",
|
0, ISC_LOGCATEGORY_SSLKEYLOG,
|
||||||
ISC_LOGCATEGORY_SSLKEYLOG, NULL);
|
ISC_LOGMODULE_DEFAULT);
|
||||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
@@ -219,7 +180,8 @@ named_log_setdefaultcategory(isc_logconfig_t *lcfg) {
|
|||||||
isc_result_t result = ISC_R_SUCCESS;
|
isc_result_t result = ISC_R_SUCCESS;
|
||||||
|
|
||||||
result = isc_log_usechannel(lcfg, "default_debug",
|
result = isc_log_usechannel(lcfg, "default_debug",
|
||||||
ISC_LOGCATEGORY_DEFAULT, NULL);
|
ISC_LOGCATEGORY_DEFAULT,
|
||||||
|
ISC_LOGMODULE_DEFAULT);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
goto cleanup;
|
goto cleanup;
|
||||||
}
|
}
|
||||||
@@ -228,11 +190,11 @@ named_log_setdefaultcategory(isc_logconfig_t *lcfg) {
|
|||||||
if (named_g_logfile != NULL) {
|
if (named_g_logfile != NULL) {
|
||||||
result = isc_log_usechannel(lcfg, "default_logfile",
|
result = isc_log_usechannel(lcfg, "default_logfile",
|
||||||
ISC_LOGCATEGORY_DEFAULT,
|
ISC_LOGCATEGORY_DEFAULT,
|
||||||
NULL);
|
ISC_LOGMODULE_DEFAULT);
|
||||||
} else if (!named_g_nosyslog) {
|
} else if (!named_g_nosyslog) {
|
||||||
result = isc_log_usechannel(lcfg, "default_syslog",
|
result = isc_log_usechannel(lcfg, "default_syslog",
|
||||||
ISC_LOGCATEGORY_DEFAULT,
|
ISC_LOGCATEGORY_DEFAULT,
|
||||||
NULL);
|
ISC_LOGMODULE_DEFAULT);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -245,13 +207,6 @@ named_log_setunmatchedcategory(isc_logconfig_t *lcfg) {
|
|||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
|
|
||||||
result = isc_log_usechannel(lcfg, "null", NAMED_LOGCATEGORY_UNMATCHED,
|
result = isc_log_usechannel(lcfg, "null", NAMED_LOGCATEGORY_UNMATCHED,
|
||||||
NULL);
|
ISC_LOGMODULE_DEFAULT);
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
|
||||||
void
|
|
||||||
named_log_shutdown(void) {
|
|
||||||
isc_log_destroy(&named_g_lctx);
|
|
||||||
isc_log_setcontext(NULL);
|
|
||||||
dns_log_setcontext(NULL);
|
|
||||||
}
|
|
||||||
|
|||||||
+7
-11
@@ -24,7 +24,6 @@
|
|||||||
#include <isc/util.h>
|
#include <isc/util.h>
|
||||||
|
|
||||||
#include <isccfg/cfg.h>
|
#include <isccfg/cfg.h>
|
||||||
#include <isccfg/log.h>
|
|
||||||
|
|
||||||
#include <named/log.h>
|
#include <named/log.h>
|
||||||
#include <named/logconf.h>
|
#include <named/logconf.h>
|
||||||
@@ -44,15 +43,14 @@ static isc_result_t
|
|||||||
category_fromconf(const cfg_obj_t *ccat, isc_logconfig_t *logconfig) {
|
category_fromconf(const cfg_obj_t *ccat, isc_logconfig_t *logconfig) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
const char *catname;
|
const char *catname;
|
||||||
isc_logcategory_t *category;
|
isc_logcategory_t category;
|
||||||
isc_logmodule_t *module;
|
|
||||||
const cfg_obj_t *destinations = NULL;
|
const cfg_obj_t *destinations = NULL;
|
||||||
const cfg_listelt_t *element = NULL;
|
const cfg_listelt_t *element = NULL;
|
||||||
|
|
||||||
catname = cfg_obj_asstring(cfg_tuple_get(ccat, "name"));
|
catname = cfg_obj_asstring(cfg_tuple_get(ccat, "name"));
|
||||||
category = isc_log_categorybyname(named_g_lctx, catname);
|
category = isc_log_categorybyname(catname);
|
||||||
if (category == NULL) {
|
if (category == ISC_LOGCATEGORY_INVALID) {
|
||||||
cfg_obj_log(ccat, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(ccat, ISC_LOG_ERROR,
|
||||||
"unknown logging category '%s' ignored", catname);
|
"unknown logging category '%s' ignored", catname);
|
||||||
/*
|
/*
|
||||||
* Allow further processing by returning success.
|
* Allow further processing by returning success.
|
||||||
@@ -64,8 +62,6 @@ category_fromconf(const cfg_obj_t *ccat, isc_logconfig_t *logconfig) {
|
|||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
}
|
}
|
||||||
|
|
||||||
module = NULL;
|
|
||||||
|
|
||||||
destinations = cfg_tuple_get(ccat, "destinations");
|
destinations = cfg_tuple_get(ccat, "destinations");
|
||||||
for (element = cfg_list_first(destinations); element != NULL;
|
for (element = cfg_list_first(destinations); element != NULL;
|
||||||
element = cfg_list_next(element))
|
element = cfg_list_next(element))
|
||||||
@@ -74,9 +70,9 @@ category_fromconf(const cfg_obj_t *ccat, isc_logconfig_t *logconfig) {
|
|||||||
const char *channelname = cfg_obj_asstring(channel);
|
const char *channelname = cfg_obj_asstring(channel);
|
||||||
|
|
||||||
result = isc_log_usechannel(logconfig, channelname, category,
|
result = isc_log_usechannel(logconfig, channelname, category,
|
||||||
module);
|
ISC_LOGMODULE_DEFAULT);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
isc_log_write(named_g_lctx, CFG_LOGCATEGORY_CONFIG,
|
isc_log_write(CFG_LOGCATEGORY_CONFIG,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||||
"logging channel '%s': %s", channelname,
|
"logging channel '%s': %s", channelname,
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
@@ -127,7 +123,7 @@ channel_fromconf(const cfg_obj_t *channel, isc_logconfig_t *logconfig) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (i != 1) {
|
if (i != 1) {
|
||||||
cfg_obj_log(channel, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(channel, ISC_LOG_ERROR,
|
||||||
"channel '%s': exactly one of file, syslog, "
|
"channel '%s': exactly one of file, syslog, "
|
||||||
"null, and stderr must be present",
|
"null, and stderr must be present",
|
||||||
channelname);
|
channelname);
|
||||||
|
|||||||
+130
-176
@@ -88,7 +88,7 @@
|
|||||||
#include <openssl/crypto.h>
|
#include <openssl/crypto.h>
|
||||||
#include <openssl/evp.h>
|
#include <openssl/evp.h>
|
||||||
#include <openssl/opensslv.h>
|
#include <openssl/opensslv.h>
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L && OPENSSL_API_LEVEL >= 30000
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
#include <openssl/err.h>
|
#include <openssl/err.h>
|
||||||
#include <openssl/provider.h>
|
#include <openssl/provider.h>
|
||||||
#endif
|
#endif
|
||||||
@@ -152,7 +152,7 @@ static bool transferstuck = false;
|
|||||||
static bool disable6 = false;
|
static bool disable6 = false;
|
||||||
static bool disable4 = false;
|
static bool disable4 = false;
|
||||||
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L && OPENSSL_API_LEVEL >= 30000
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
static OSSL_PROVIDER *fips = NULL, *base = NULL;
|
static OSSL_PROVIDER *fips = NULL, *base = NULL;
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
@@ -161,10 +161,9 @@ named_main_earlywarning(const char *format, ...) {
|
|||||||
va_list args;
|
va_list args;
|
||||||
|
|
||||||
va_start(args, format);
|
va_start(args, format);
|
||||||
if (named_g_lctx != NULL) {
|
if (named_g_logging) {
|
||||||
isc_log_vwrite(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_WARNING, format,
|
ISC_LOG_WARNING, format, args);
|
||||||
args);
|
|
||||||
} else {
|
} else {
|
||||||
fprintf(stderr, "%s: ", program_name);
|
fprintf(stderr, "%s: ", program_name);
|
||||||
vfprintf(stderr, format, args);
|
vfprintf(stderr, format, args);
|
||||||
@@ -179,12 +178,11 @@ named_main_earlyfatal(const char *format, ...) {
|
|||||||
va_list args;
|
va_list args;
|
||||||
|
|
||||||
va_start(args, format);
|
va_start(args, format);
|
||||||
if (named_g_lctx != NULL) {
|
if (named_g_logging) {
|
||||||
isc_log_vwrite(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_CRITICAL, format,
|
ISC_LOG_CRITICAL, format, args);
|
||||||
args);
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
ISC_LOG_CRITICAL,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_CRITICAL,
|
|
||||||
"exiting (due to early fatal error)");
|
"exiting (due to early fatal error)");
|
||||||
} else {
|
} else {
|
||||||
fprintf(stderr, "%s: ", program_name);
|
fprintf(stderr, "%s: ", program_name);
|
||||||
@@ -197,7 +195,7 @@ named_main_earlyfatal(const char *format, ...) {
|
|||||||
_exit(EXIT_FAILURE);
|
_exit(EXIT_FAILURE);
|
||||||
}
|
}
|
||||||
|
|
||||||
noreturn static void
|
ISC_NORETURN static void
|
||||||
assertion_failed(const char *file, int line, isc_assertiontype_t type,
|
assertion_failed(const char *file, int line, isc_assertiontype_t type,
|
||||||
const char *cond);
|
const char *cond);
|
||||||
|
|
||||||
@@ -208,21 +206,20 @@ assertion_failed(const char *file, int line, isc_assertiontype_t type,
|
|||||||
* Handle assertion failures.
|
* Handle assertion failures.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
if (named_g_lctx != NULL) {
|
if (named_g_logging) {
|
||||||
/*
|
/*
|
||||||
* Reset the assertion callback in case it is the log
|
* Reset the assertion callback in case it is the log
|
||||||
* routines causing the assertion.
|
* routines causing the assertion.
|
||||||
*/
|
*/
|
||||||
isc_assertion_setcallback(NULL);
|
isc_assertion_setcallback(NULL);
|
||||||
|
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_CRITICAL,
|
ISC_LOG_CRITICAL, "%s:%d: %s(%s) failed", file,
|
||||||
"%s:%d: %s(%s) failed", file, line,
|
line, isc_assertion_typetotext(type), cond);
|
||||||
isc_assertion_typetotext(type), cond);
|
isc_backtrace_log(NAMED_LOGCATEGORY_GENERAL,
|
||||||
isc_backtrace_log(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_CRITICAL);
|
NAMED_LOGMODULE_MAIN, ISC_LOG_CRITICAL);
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_CRITICAL,
|
ISC_LOG_CRITICAL,
|
||||||
"exiting (due to assertion failure)");
|
"exiting (due to assertion failure)");
|
||||||
} else {
|
} else {
|
||||||
fprintf(stderr, "%s:%d: %s(%s) failed\n", file, line,
|
fprintf(stderr, "%s:%d: %s(%s) failed\n", file, line,
|
||||||
@@ -236,7 +233,7 @@ assertion_failed(const char *file, int line, isc_assertiontype_t type,
|
|||||||
_exit(EXIT_FAILURE);
|
_exit(EXIT_FAILURE);
|
||||||
}
|
}
|
||||||
|
|
||||||
noreturn static void
|
ISC_NORETURN static void
|
||||||
library_fatal_error(const char *file, int line, const char *func,
|
library_fatal_error(const char *file, int line, const char *func,
|
||||||
const char *format, va_list args) ISC_FORMAT_PRINTF(3, 0);
|
const char *format, va_list args) ISC_FORMAT_PRINTF(3, 0);
|
||||||
|
|
||||||
@@ -247,21 +244,20 @@ library_fatal_error(const char *file, int line, const char *func,
|
|||||||
* Handle isc_error_fatal() calls from our libraries.
|
* Handle isc_error_fatal() calls from our libraries.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
if (named_g_lctx != NULL) {
|
if (named_g_logging) {
|
||||||
/*
|
/*
|
||||||
* Reset the error callback in case it is the log
|
* Reset the error callback in case it is the log
|
||||||
* routines causing the assertion.
|
* routines causing the assertion.
|
||||||
*/
|
*/
|
||||||
isc_error_setfatal(NULL);
|
isc_error_setfatal(NULL);
|
||||||
|
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_CRITICAL,
|
ISC_LOG_CRITICAL,
|
||||||
"%s:%d:%s(): fatal error: ", file, line, func);
|
"%s:%d:%s(): fatal error: ", file, line, func);
|
||||||
isc_log_vwrite(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_CRITICAL, format,
|
ISC_LOG_CRITICAL, format, args);
|
||||||
args);
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
ISC_LOG_CRITICAL,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_CRITICAL,
|
|
||||||
"exiting (due to fatal error in library)");
|
"exiting (due to fatal error in library)");
|
||||||
} else {
|
} else {
|
||||||
fprintf(stderr, "%s:%d:%s(): fatal error: ", file, line, func);
|
fprintf(stderr, "%s:%d:%s(): fatal error: ", file, line, func);
|
||||||
@@ -288,14 +284,13 @@ library_unexpected_error(const char *file, int line, const char *func,
|
|||||||
* Handle isc_error_unexpected() calls from our libraries.
|
* Handle isc_error_unexpected() calls from our libraries.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
if (named_g_lctx != NULL) {
|
if (named_g_logging) {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_ERROR,
|
ISC_LOG_ERROR,
|
||||||
"%s:%d:%s(): unexpected error: ", file, line,
|
"%s:%d:%s(): unexpected error: ", file, line,
|
||||||
func);
|
func);
|
||||||
isc_log_vwrite(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_vwrite(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_ERROR, format,
|
ISC_LOG_ERROR, format, args);
|
||||||
args);
|
|
||||||
} else {
|
} else {
|
||||||
fprintf(stderr, "%s:%d:%s(): fatal error: ", file, line, func);
|
fprintf(stderr, "%s:%d:%s(): fatal error: ", file, line, func);
|
||||||
vfprintf(stderr, format, args);
|
vfprintf(stderr, format, args);
|
||||||
@@ -307,7 +302,7 @@ library_unexpected_error(const char *file, int line, const char *func,
|
|||||||
static void
|
static void
|
||||||
usage(void) {
|
usage(void) {
|
||||||
fprintf(stderr, "usage: named [-4|-6] [-c conffile] [-d debuglevel] "
|
fprintf(stderr, "usage: named [-4|-6] [-c conffile] [-d debuglevel] "
|
||||||
"[-D comment] [-E engine]\n"
|
"[-D comment]\n"
|
||||||
" [-f|-g] [-L logfile] [-n number_of_cpus] "
|
" [-f|-g] [-L logfile] [-n number_of_cpus] "
|
||||||
"[-p port] [-s]\n"
|
"[-p port] [-s]\n"
|
||||||
" [-S sockets] [-t chrootdir] [-u "
|
" [-S sockets] [-t chrootdir] [-u "
|
||||||
@@ -510,9 +505,8 @@ list_hmac_algorithms(isc_buffer_t *b) {
|
|||||||
|
|
||||||
static void
|
static void
|
||||||
logit(isc_buffer_t *b) {
|
logit(isc_buffer_t *b) {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE, "%.*s",
|
ISC_LOG_NOTICE, "%.*s", (int)isc_buffer_usedlength(b),
|
||||||
(int)isc_buffer_usedlength(b),
|
|
||||||
(char *)isc_buffer_base(b));
|
(char *)isc_buffer_base(b));
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -556,8 +550,6 @@ format_supported_algorithms(void (*emit)(isc_buffer_t *b)) {
|
|||||||
static void
|
static void
|
||||||
printversion(bool verbose) {
|
printversion(bool verbose) {
|
||||||
char rndcconf[PATH_MAX], *dot = NULL;
|
char rndcconf[PATH_MAX], *dot = NULL;
|
||||||
isc_mem_t *mctx = NULL;
|
|
||||||
isc_result_t result;
|
|
||||||
isc_buffer_t b;
|
isc_buffer_t b;
|
||||||
char buf[512];
|
char buf[512];
|
||||||
#if defined(HAVE_GEOIP2)
|
#if defined(HAVE_GEOIP2)
|
||||||
@@ -590,16 +582,8 @@ printversion(bool verbose) {
|
|||||||
printf("compiled by Solaris Studio %x\n", __SUNPRO_C);
|
printf("compiled by Solaris Studio %x\n", __SUNPRO_C);
|
||||||
#endif /* ifdef __SUNPRO_C */
|
#endif /* ifdef __SUNPRO_C */
|
||||||
printf("compiled with OpenSSL version: %s\n", OPENSSL_VERSION_TEXT);
|
printf("compiled with OpenSSL version: %s\n", OPENSSL_VERSION_TEXT);
|
||||||
#if !defined(LIBRESSL_VERSION_NUMBER) && \
|
|
||||||
OPENSSL_VERSION_NUMBER >= 0x10100000L /* 1.1.0 or higher */
|
|
||||||
printf("linked to OpenSSL version: %s\n",
|
printf("linked to OpenSSL version: %s\n",
|
||||||
OpenSSL_version(OPENSSL_VERSION));
|
OpenSSL_version(OPENSSL_VERSION));
|
||||||
|
|
||||||
#else /* if !defined(LIBRESSL_VERSION_NUMBER) && OPENSSL_VERSION_NUMBER >= \
|
|
||||||
* 0x10100000L */
|
|
||||||
printf("linked to OpenSSL version: %s\n",
|
|
||||||
SSLeay_version(SSLEAY_VERSION));
|
|
||||||
#endif /* OPENSSL_VERSION_NUMBER >= 0x10100000L */
|
|
||||||
printf("compiled with libuv version: %d.%d.%d\n", UV_VERSION_MAJOR,
|
printf("compiled with libuv version: %d.%d.%d\n", UV_VERSION_MAJOR,
|
||||||
UV_VERSION_MINOR, UV_VERSION_PATCH);
|
UV_VERSION_MINOR, UV_VERSION_PATCH);
|
||||||
printf("linked to libuv version: %s\n", uv_version_string());
|
printf("linked to libuv version: %s\n", uv_version_string());
|
||||||
@@ -639,17 +623,9 @@ printversion(bool verbose) {
|
|||||||
#endif /* if defined(HAVE_DNSTAP) */
|
#endif /* if defined(HAVE_DNSTAP) */
|
||||||
printf("threads support is enabled\n");
|
printf("threads support is enabled\n");
|
||||||
|
|
||||||
isc_mem_create(&mctx);
|
isc_buffer_init(&b, buf, sizeof(buf));
|
||||||
result = dst_lib_init(mctx, named_g_engine);
|
format_supported_algorithms(printit);
|
||||||
if (result == ISC_R_SUCCESS) {
|
printf("\n");
|
||||||
isc_buffer_init(&b, buf, sizeof(buf));
|
|
||||||
format_supported_algorithms(printit);
|
|
||||||
printf("\n");
|
|
||||||
dst_lib_destroy();
|
|
||||||
} else {
|
|
||||||
printf("DST initialization failure: %s\n",
|
|
||||||
isc_result_totext(result));
|
|
||||||
}
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* The default rndc.conf and rndc.key paths are in the same
|
* The default rndc.conf and rndc.key paths are in the same
|
||||||
@@ -673,7 +649,9 @@ printversion(bool verbose) {
|
|||||||
printf(" named PID file: %s\n", named_g_defaultpidfile);
|
printf(" named PID file: %s\n", named_g_defaultpidfile);
|
||||||
#if defined(HAVE_GEOIP2)
|
#if defined(HAVE_GEOIP2)
|
||||||
#define RTC(x) RUNTIME_CHECK((x) == ISC_R_SUCCESS)
|
#define RTC(x) RUNTIME_CHECK((x) == ISC_R_SUCCESS)
|
||||||
RTC(cfg_parser_create(mctx, named_g_lctx, &parser));
|
isc_mem_t *mctx = NULL;
|
||||||
|
isc_mem_create(&mctx);
|
||||||
|
RTC(cfg_parser_create(mctx, &parser));
|
||||||
RTC(named_config_parsedefaults(parser, &config));
|
RTC(named_config_parsedefaults(parser, &config));
|
||||||
RTC(cfg_map_get(config, "options", &defaults));
|
RTC(cfg_map_get(config, "options", &defaults));
|
||||||
RTC(cfg_map_get(defaults, "geoip-directory", &obj));
|
RTC(cfg_map_get(defaults, "geoip-directory", &obj));
|
||||||
@@ -902,7 +880,8 @@ parse_command_line(int argc, char *argv[]) {
|
|||||||
/* Descriptive comment for 'ps'. */
|
/* Descriptive comment for 'ps'. */
|
||||||
break;
|
break;
|
||||||
case 'E':
|
case 'E':
|
||||||
named_g_engine = isc_commandline_argument;
|
named_main_earlyfatal(
|
||||||
|
"%s", isc_result_totext(DST_R_NOENGINE));
|
||||||
break;
|
break;
|
||||||
case 'f':
|
case 'f':
|
||||||
named_g_foreground = true;
|
named_g_foreground = true;
|
||||||
@@ -968,7 +947,7 @@ parse_command_line(int argc, char *argv[]) {
|
|||||||
named_main_earlyfatal("option '-X' has been removed");
|
named_main_earlyfatal("option '-X' has been removed");
|
||||||
break;
|
break;
|
||||||
case 'F':
|
case 'F':
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L && OPENSSL_API_LEVEL >= 30000
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
fips = OSSL_PROVIDER_load(NULL, "fips");
|
fips = OSSL_PROVIDER_load(NULL, "fips");
|
||||||
if (fips == NULL) {
|
if (fips == NULL) {
|
||||||
ERR_clear_error();
|
ERR_clear_error();
|
||||||
@@ -1032,11 +1011,11 @@ create_managers(void) {
|
|||||||
named_g_cpus = named_g_cpus_detected;
|
named_g_cpus = named_g_cpus_detected;
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_log_write(
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
named_g_lctx, NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
ISC_LOG_INFO, "found %u CPU%s, using %u worker thread%s",
|
||||||
ISC_LOG_INFO, "found %u CPU%s, using %u worker thread%s",
|
named_g_cpus_detected,
|
||||||
named_g_cpus_detected, named_g_cpus_detected == 1 ? "" : "s",
|
named_g_cpus_detected == 1 ? "" : "s", named_g_cpus,
|
||||||
named_g_cpus, named_g_cpus == 1 ? "" : "s");
|
named_g_cpus == 1 ? "" : "s");
|
||||||
|
|
||||||
isc_managers_create(&named_g_mctx, named_g_cpus, &named_g_loopmgr,
|
isc_managers_create(&named_g_mctx, named_g_cpus, &named_g_loopmgr,
|
||||||
&named_g_netmgr);
|
&named_g_netmgr);
|
||||||
@@ -1116,150 +1095,129 @@ setup(void) {
|
|||||||
named_os_daemonize();
|
named_os_daemonize();
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "starting %s%s <id:%s>", PACKAGE_STRING,
|
||||||
"starting %s%s <id:%s>", PACKAGE_STRING,
|
|
||||||
PACKAGE_DESCRIPTION, PACKAGE_SRCID);
|
PACKAGE_DESCRIPTION, PACKAGE_SRCID);
|
||||||
|
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE, "running on %s",
|
ISC_LOG_NOTICE, "running on %s", named_os_uname());
|
||||||
named_os_uname());
|
|
||||||
|
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE, "built with %s",
|
ISC_LOG_NOTICE, "built with %s", PACKAGE_CONFIGARGS);
|
||||||
PACKAGE_CONFIGARGS);
|
|
||||||
|
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "running as: %s%s%s", program_name,
|
||||||
"running as: %s%s%s", program_name, saved_command_line,
|
saved_command_line, ellipsis);
|
||||||
ellipsis);
|
|
||||||
#ifdef __clang__
|
#ifdef __clang__
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "compiled by CLANG %s", __VERSION__);
|
||||||
"compiled by CLANG %s", __VERSION__);
|
|
||||||
#else /* ifdef __clang__ */
|
#else /* ifdef __clang__ */
|
||||||
#if defined(__ICC) || defined(__INTEL_COMPILER)
|
#if defined(__ICC) || defined(__INTEL_COMPILER)
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "compiled by ICC %s", __VERSION__);
|
||||||
"compiled by ICC %s", __VERSION__);
|
|
||||||
#else /* if defined(__ICC) || defined(__INTEL_COMPILER) */
|
#else /* if defined(__ICC) || defined(__INTEL_COMPILER) */
|
||||||
#ifdef __GNUC__
|
#ifdef __GNUC__
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "compiled by GCC %s", __VERSION__);
|
||||||
"compiled by GCC %s", __VERSION__);
|
|
||||||
#endif /* ifdef __GNUC__ */
|
#endif /* ifdef __GNUC__ */
|
||||||
#endif /* if defined(__ICC) || defined(__INTEL_COMPILER) */
|
#endif /* if defined(__ICC) || defined(__INTEL_COMPILER) */
|
||||||
#endif /* ifdef __clang__ */
|
#endif /* ifdef __clang__ */
|
||||||
#ifdef __SUNPRO_C
|
#ifdef __SUNPRO_C
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "compiled by Solaris Studio %x",
|
||||||
"compiled by Solaris Studio %x", __SUNPRO_C);
|
__SUNPRO_C);
|
||||||
#endif /* ifdef __SUNPRO_C */
|
#endif /* ifdef __SUNPRO_C */
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "compiled with OpenSSL version: %s",
|
||||||
"compiled with OpenSSL version: %s",
|
|
||||||
OPENSSL_VERSION_TEXT);
|
OPENSSL_VERSION_TEXT);
|
||||||
#if !defined(LIBRESSL_VERSION_NUMBER) && \
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
OPENSSL_VERSION_NUMBER >= 0x10100000L /* 1.1.0 or higher */
|
ISC_LOG_NOTICE, "linked to OpenSSL version: %s",
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
|
||||||
"linked to OpenSSL version: %s",
|
|
||||||
OpenSSL_version(OPENSSL_VERSION));
|
OpenSSL_version(OPENSSL_VERSION));
|
||||||
#else /* if !defined(LIBRESSL_VERSION_NUMBER) && OPENSSL_VERSION_NUMBER >= \
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
* 0x10100000L */
|
ISC_LOG_NOTICE, "compiled with libuv version: %d.%d.%d",
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
UV_VERSION_MAJOR, UV_VERSION_MINOR, UV_VERSION_PATCH);
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
"linked to OpenSSL version: %s",
|
ISC_LOG_NOTICE, "linked to libuv version: %s",
|
||||||
SSLeay_version(SSLEAY_VERSION));
|
uv_version_string());
|
||||||
#endif /* OPENSSL_VERSION_NUMBER >= 0x10100000L */
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
ISC_LOG_NOTICE, "compiled with %s version: %s",
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
RCU_FLAVOR, RCU_VERSION);
|
||||||
"compiled with libuv version: %d.%d.%d", UV_VERSION_MAJOR,
|
|
||||||
UV_VERSION_MINOR, UV_VERSION_PATCH);
|
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
|
||||||
"linked to libuv version: %s", uv_version_string());
|
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
|
||||||
"compiled with %s version: %s", RCU_FLAVOR, RCU_VERSION);
|
|
||||||
#if defined(JEMALLOC_VERSION)
|
#if defined(JEMALLOC_VERSION)
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE,
|
||||||
"compiled with jemalloc version: %u.%u.%u",
|
"compiled with jemalloc version: %u.%u.%u",
|
||||||
JEMALLOC_VERSION_MAJOR, JEMALLOC_VERSION_MINOR,
|
JEMALLOC_VERSION_MAJOR, JEMALLOC_VERSION_MINOR,
|
||||||
JEMALLOC_VERSION_BUGFIX);
|
JEMALLOC_VERSION_BUGFIX);
|
||||||
#elif defined(M_VERSION)
|
#elif defined(M_VERSION)
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE,
|
||||||
"compiled with system jemalloc version: %u", M_VERSION);
|
"compiled with system jemalloc version: %u", M_VERSION);
|
||||||
#endif
|
#endif
|
||||||
#if HAVE_LIBNGHTTP2
|
#if HAVE_LIBNGHTTP2
|
||||||
nghttp2_info *nginfo = NULL;
|
nghttp2_info *nginfo = NULL;
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "compiled with libnghttp2 version: %s",
|
||||||
"compiled with libnghttp2 version: %s", NGHTTP2_VERSION);
|
NGHTTP2_VERSION);
|
||||||
nginfo = nghttp2_version(1);
|
nginfo = nghttp2_version(1);
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "linked to libnghttp2 version: %s",
|
||||||
"linked to libnghttp2 version: %s", nginfo->version_str);
|
nginfo->version_str);
|
||||||
#endif
|
#endif
|
||||||
#ifdef HAVE_LIBXML2
|
#ifdef HAVE_LIBXML2
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "compiled with libxml2 version: %s",
|
||||||
"compiled with libxml2 version: %s",
|
|
||||||
LIBXML_DOTTED_VERSION);
|
LIBXML_DOTTED_VERSION);
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "linked to libxml2 version: %s",
|
||||||
"linked to libxml2 version: %s", xmlParserVersion);
|
xmlParserVersion);
|
||||||
#endif /* ifdef HAVE_LIBXML2 */
|
#endif /* ifdef HAVE_LIBXML2 */
|
||||||
#if defined(HAVE_JSON_C)
|
#if defined(HAVE_JSON_C)
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "compiled with json-c version: %s",
|
||||||
"compiled with json-c version: %s", JSON_C_VERSION);
|
JSON_C_VERSION);
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "linked to json-c version: %s",
|
||||||
"linked to json-c version: %s", json_c_version());
|
json_c_version());
|
||||||
#endif /* if defined(HAVE_JSON_C) */
|
#endif /* if defined(HAVE_JSON_C) */
|
||||||
#if defined(HAVE_ZLIB) && defined(ZLIB_VERSION)
|
#if defined(HAVE_ZLIB) && defined(ZLIB_VERSION)
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "compiled with zlib version: %s",
|
||||||
"compiled with zlib version: %s", ZLIB_VERSION);
|
ZLIB_VERSION);
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "linked to zlib version: %s",
|
||||||
"linked to zlib version: %s", zlibVersion());
|
zlibVersion());
|
||||||
#endif /* if defined(HAVE_ZLIB) && defined(ZLIB_VERSION) */
|
#endif /* if defined(HAVE_ZLIB) && defined(ZLIB_VERSION) */
|
||||||
#if defined(HAVE_GEOIP2)
|
#if defined(HAVE_GEOIP2)
|
||||||
/* Unfortunately, no version define on link time */
|
/* Unfortunately, no version define on link time */
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "linked to maxminddb version: %s",
|
||||||
"linked to maxminddb version: %s", MMDB_lib_version());
|
MMDB_lib_version());
|
||||||
#endif /* if defined(HAVE_GEOIP2) */
|
#endif /* if defined(HAVE_GEOIP2) */
|
||||||
#if defined(HAVE_DNSTAP)
|
#if defined(HAVE_DNSTAP)
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "compiled with protobuf-c version: %s",
|
||||||
"compiled with protobuf-c version: %s",
|
|
||||||
PROTOBUF_C_VERSION);
|
PROTOBUF_C_VERSION);
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "linked to protobuf-c version: %s",
|
||||||
"linked to protobuf-c version: %s", protobuf_c_version());
|
protobuf_c_version());
|
||||||
#endif /* if defined(HAVE_DNSTAP) */
|
#endif /* if defined(HAVE_DNSTAP) */
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE,
|
||||||
"----------------------------------------------------");
|
"----------------------------------------------------");
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE,
|
||||||
"BIND 9 is maintained by Internet Systems Consortium,");
|
"BIND 9 is maintained by Internet Systems Consortium,");
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE,
|
||||||
"Inc. (ISC), a non-profit 501(c)(3) public-benefit ");
|
"Inc. (ISC), a non-profit 501(c)(3) public-benefit ");
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE,
|
||||||
"corporation. Support and training for BIND 9 are ");
|
"corporation. Support and training for BIND 9 are ");
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE,
|
||||||
"available at https://www.isc.org/support");
|
"available at https://www.isc.org/support");
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE,
|
||||||
"----------------------------------------------------");
|
"----------------------------------------------------");
|
||||||
|
|
||||||
/*
|
/*
|
||||||
@@ -1316,10 +1274,6 @@ setup(void) {
|
|||||||
ENSURE(named_g_server != NULL);
|
ENSURE(named_g_server != NULL);
|
||||||
sctx = named_g_server->sctx;
|
sctx = named_g_server->sctx;
|
||||||
|
|
||||||
/*
|
|
||||||
* Report supported algorithms now that dst_lib_init() has
|
|
||||||
* been called via named_server_create().
|
|
||||||
*/
|
|
||||||
format_supported_algorithms(logit);
|
format_supported_algorithms(logit);
|
||||||
|
|
||||||
/*
|
/*
|
||||||
@@ -1395,9 +1349,8 @@ cleanup(void) {
|
|||||||
*/
|
*/
|
||||||
dlz_dlopen_clear();
|
dlz_dlopen_clear();
|
||||||
|
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE, "exiting");
|
ISC_LOG_NOTICE, "exiting");
|
||||||
named_log_shutdown();
|
|
||||||
}
|
}
|
||||||
|
|
||||||
static char *memstats = NULL;
|
static char *memstats = NULL;
|
||||||
@@ -1567,6 +1520,7 @@ main(int argc, char *argv[]) {
|
|||||||
* Start things running
|
* Start things running
|
||||||
*/
|
*/
|
||||||
isc_signal_start(named_g_server->sighup);
|
isc_signal_start(named_g_server->sighup);
|
||||||
|
isc_signal_start(named_g_server->sigusr1);
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Pause the loop manager in fatal.
|
* Pause the loop manager in fatal.
|
||||||
@@ -1622,7 +1576,7 @@ main(int argc, char *argv[]) {
|
|||||||
|
|
||||||
named_os_shutdown();
|
named_os_shutdown();
|
||||||
|
|
||||||
#if OPENSSL_VERSION_NUMBER >= 0x30000000L && OPENSSL_API_LEVEL >= 30000
|
#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||||
if (base != NULL) {
|
if (base != NULL) {
|
||||||
OSSL_PROVIDER_unload(base);
|
OSSL_PROVIDER_unload(base);
|
||||||
}
|
}
|
||||||
|
|||||||
+1
-10
@@ -21,7 +21,7 @@ named - Internet domain name server
|
|||||||
Synopsis
|
Synopsis
|
||||||
~~~~~~~~
|
~~~~~~~~
|
||||||
|
|
||||||
:program:`named` [ [**-4**] | [**-6**] ] [**-c** config-file] [**-C**] [**-d** debug-level] [**-D** string] [**-E** engine-name] [**-f**] [**-g**] [**-L** logfile] [**-M** option] [**-m** flag] [**-n** #cpus] [**-p** port] [**-s**] [**-t** directory] [**-u** user] [**-v**] [**-V**] ]
|
:program:`named` [ [**-4**] | [**-6**] ] [**-c** config-file] [**-C**] [**-d** debug-level] [**-D** string] [**-f**] [**-g**] [**-L** logfile] [**-M** option] [**-m** flag] [**-n** #cpus] [**-p** port] [**-s**] [**-t** directory] [**-u** user] [**-v**] [**-V**] ]
|
||||||
|
|
||||||
Description
|
Description
|
||||||
~~~~~~~~~~~
|
~~~~~~~~~~~
|
||||||
@@ -73,15 +73,6 @@ Options
|
|||||||
This option specifies a string that is used to identify a instance of :program:`named`
|
This option specifies a string that is used to identify a instance of :program:`named`
|
||||||
in a process listing. The contents of ``string`` are not examined.
|
in a process listing. The contents of ``string`` are not examined.
|
||||||
|
|
||||||
.. option:: -E engine-name
|
|
||||||
|
|
||||||
When applicable, this option specifies the hardware to use for cryptographic
|
|
||||||
operations, such as a secure key store used for signing.
|
|
||||||
|
|
||||||
When BIND 9 is built with OpenSSL, this needs to be set to the OpenSSL
|
|
||||||
engine identifier that drives the cryptographic accelerator or
|
|
||||||
hardware service module (usually ``pkcs11``).
|
|
||||||
|
|
||||||
.. option:: -f
|
.. option:: -f
|
||||||
|
|
||||||
This option runs the server in the foreground (i.e., do not daemonize).
|
This option runs the server in the foreground (i.e., do not daemonize).
|
||||||
|
|||||||
+38
-126
@@ -61,6 +61,9 @@ static struct passwd *runas_pw = NULL;
|
|||||||
static bool done_setuid = false;
|
static bool done_setuid = false;
|
||||||
static int dfd[2] = { -1, -1 };
|
static int dfd[2] = { -1, -1 };
|
||||||
|
|
||||||
|
static uid_t saved_uid = (uid_t)-1;
|
||||||
|
static gid_t saved_gid = (gid_t)-1;
|
||||||
|
|
||||||
#if HAVE_LIBCAP
|
#if HAVE_LIBCAP
|
||||||
|
|
||||||
static bool non_root = false;
|
static bool non_root = false;
|
||||||
@@ -249,115 +252,6 @@ linux_keepcaps(void) {
|
|||||||
|
|
||||||
#endif /* HAVE_LIBCAP */
|
#endif /* HAVE_LIBCAP */
|
||||||
|
|
||||||
/*
|
|
||||||
* First define compatibility shims if {set,get}res{uid,gid} are not available
|
|
||||||
*/
|
|
||||||
|
|
||||||
#if !HAVE_GETRESGID
|
|
||||||
static int
|
|
||||||
getresgid(gid_t *rgid, gid_t *egid, gid_t *sgid) {
|
|
||||||
*rgid = -1;
|
|
||||||
*egid = getegid();
|
|
||||||
*sgid = -1;
|
|
||||||
|
|
||||||
return (0);
|
|
||||||
}
|
|
||||||
#endif /* !HAVE_GETRESGID */
|
|
||||||
|
|
||||||
#if !HAVE_SETRESGID
|
|
||||||
static int
|
|
||||||
setresgid(gid_t rgid, gid_t egid, gid_t sgid) {
|
|
||||||
REQUIRE(rgid == (gid_t)-1);
|
|
||||||
REQUIRE(sgid == (gid_t)-1);
|
|
||||||
|
|
||||||
#if HAVE_SETREGID
|
|
||||||
return (setregid(rgid, egid));
|
|
||||||
#else /* HAVE_SETREGID */
|
|
||||||
return (setegid(egid));
|
|
||||||
#endif /* HAVE_SETREGID */
|
|
||||||
}
|
|
||||||
#endif /* !HAVE_SETRESGID */
|
|
||||||
|
|
||||||
#if !HAVE_GETRESUID
|
|
||||||
static int
|
|
||||||
getresuid(uid_t *ruid, uid_t *euid, uid_t *suid) {
|
|
||||||
*ruid = -1;
|
|
||||||
*euid = geteuid();
|
|
||||||
*suid = -1;
|
|
||||||
|
|
||||||
return (0);
|
|
||||||
}
|
|
||||||
#endif /* !HAVE_GETRESUID */
|
|
||||||
|
|
||||||
#if !HAVE_SETRESUID
|
|
||||||
static int
|
|
||||||
setresuid(uid_t ruid, uid_t euid, uid_t suid) {
|
|
||||||
REQUIRE(ruid == (uid_t)-1);
|
|
||||||
REQUIRE(suid == (uid_t)-1);
|
|
||||||
|
|
||||||
#if HAVE_SETREGID
|
|
||||||
return (setregid(ruid, euid));
|
|
||||||
#else /* HAVE_SETREGID */
|
|
||||||
return (setegid(euid));
|
|
||||||
#endif /* HAVE_SETREGID */
|
|
||||||
}
|
|
||||||
#endif /* !HAVE_SETRESUID */
|
|
||||||
|
|
||||||
static int
|
|
||||||
set_effective_gid(gid_t gid) {
|
|
||||||
gid_t oldgid;
|
|
||||||
|
|
||||||
if (getresgid(&(gid_t){ 0 }, &oldgid, &(gid_t){ 0 }) == -1) {
|
|
||||||
return (-1);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (oldgid == gid) {
|
|
||||||
return (0);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (setresgid(-1, gid, -1) == -1) {
|
|
||||||
return (-1);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (getresgid(&(gid_t){ 0 }, &oldgid, &(gid_t){ 0 }) == -1) {
|
|
||||||
return (-1);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (oldgid != gid) {
|
|
||||||
return (-1);
|
|
||||||
}
|
|
||||||
|
|
||||||
return (0);
|
|
||||||
}
|
|
||||||
|
|
||||||
static int
|
|
||||||
set_effective_uid(uid_t uid) {
|
|
||||||
uid_t olduid;
|
|
||||||
|
|
||||||
if (getresuid(&(uid_t){ 0 }, &olduid, &(uid_t){ 0 }) == -1) {
|
|
||||||
return (-1);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (olduid == uid) {
|
|
||||||
return (0);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (setresuid(-1, uid, -1) == -1) {
|
|
||||||
return (-1);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (getresuid(&(uid_t){ 0 }, &olduid, &(uid_t){ 0 }) == -1) {
|
|
||||||
return (-1);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (olduid != uid) {
|
|
||||||
return (-1);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Success */
|
|
||||||
return (0);
|
|
||||||
}
|
|
||||||
|
|
||||||
static void
|
static void
|
||||||
setperms(uid_t uid, gid_t gid) {
|
setperms(uid_t uid, gid_t gid) {
|
||||||
char strbuf[ISC_STRERRORSIZE];
|
char strbuf[ISC_STRERRORSIZE];
|
||||||
@@ -366,13 +260,13 @@ setperms(uid_t uid, gid_t gid) {
|
|||||||
* Drop the gid privilege first, because in some cases the gid privilege
|
* Drop the gid privilege first, because in some cases the gid privilege
|
||||||
* cannot be dropped after the uid privilege has been dropped.
|
* cannot be dropped after the uid privilege has been dropped.
|
||||||
*/
|
*/
|
||||||
if (set_effective_gid(gid) == -1) {
|
if (setegid(gid) == -1) {
|
||||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||||
named_main_earlywarning("unable to set effective gid to %d: %s",
|
named_main_earlywarning("unable to set effective gid to %d: %s",
|
||||||
gid, strbuf);
|
gid, strbuf);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (set_effective_uid(uid) == -1) {
|
if (seteuid(uid) == -1) {
|
||||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||||
named_main_earlywarning("unable to set effective uid to %d: %s",
|
named_main_earlywarning("unable to set effective uid to %d: %s",
|
||||||
uid, strbuf);
|
uid, strbuf);
|
||||||
@@ -570,20 +464,41 @@ named_os_inituserinfo(const char *username) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
void
|
void
|
||||||
named_os_changeuser(void) {
|
named_os_restoreuser(void) {
|
||||||
|
if (runas_pw == NULL || done_setuid) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
REQUIRE(saved_uid != (uid_t)-1);
|
||||||
|
REQUIRE(saved_gid != (gid_t)-1);
|
||||||
|
|
||||||
|
setperms(saved_uid, saved_gid);
|
||||||
|
}
|
||||||
|
|
||||||
|
void
|
||||||
|
named_os_changeuser(bool permanent) {
|
||||||
char strbuf[ISC_STRERRORSIZE];
|
char strbuf[ISC_STRERRORSIZE];
|
||||||
if (runas_pw == NULL || done_setuid) {
|
if (runas_pw == NULL || done_setuid) {
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (!permanent) {
|
||||||
|
saved_uid = getuid();
|
||||||
|
saved_gid = getgid();
|
||||||
|
|
||||||
|
setperms(runas_pw->pw_uid, runas_pw->pw_gid);
|
||||||
|
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
done_setuid = true;
|
done_setuid = true;
|
||||||
|
|
||||||
if (setgid(runas_pw->pw_gid) < 0) {
|
if (setgid(runas_pw->pw_gid) == -1) {
|
||||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||||
named_main_earlyfatal("setgid(): %s", strbuf);
|
named_main_earlyfatal("setgid(): %s", strbuf);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (setuid(runas_pw->pw_uid) < 0) {
|
if (setuid(runas_pw->pw_uid) == -1) {
|
||||||
strerror_r(errno, strbuf, sizeof(strbuf));
|
strerror_r(errno, strbuf, sizeof(strbuf));
|
||||||
named_main_earlyfatal("setuid(): %s", strbuf);
|
named_main_earlyfatal("setuid(): %s", strbuf);
|
||||||
}
|
}
|
||||||
@@ -604,7 +519,7 @@ named_os_changeuser(void) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
uid_t
|
uid_t
|
||||||
ns_os_uid(void) {
|
named_os_uid(void) {
|
||||||
if (runas_pw == NULL) {
|
if (runas_pw == NULL) {
|
||||||
return (0);
|
return (0);
|
||||||
}
|
}
|
||||||
@@ -626,8 +541,8 @@ named_os_adjustnofile(void) {
|
|||||||
rlim_old = rl.rlim_cur;
|
rlim_old = rl.rlim_cur;
|
||||||
|
|
||||||
if (rl.rlim_cur == rl.rlim_max) {
|
if (rl.rlim_cur == rl.rlim_max) {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE,
|
||||||
"the limit on open files is already at the "
|
"the limit on open files is already at the "
|
||||||
"maximum allowed value: "
|
"maximum allowed value: "
|
||||||
"%" PRIu64,
|
"%" PRIu64,
|
||||||
@@ -641,8 +556,8 @@ named_os_adjustnofile(void) {
|
|||||||
goto fail;
|
goto fail;
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_MAIN,
|
||||||
NAMED_LOGMODULE_MAIN, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE,
|
||||||
"adjusted limit on open files from "
|
"adjusted limit on open files from "
|
||||||
"%" PRIu64 " to "
|
"%" PRIu64 " to "
|
||||||
"%" PRIu64,
|
"%" PRIu64,
|
||||||
@@ -660,7 +575,7 @@ void
|
|||||||
named_os_minprivs(void) {
|
named_os_minprivs(void) {
|
||||||
#if HAVE_LIBCAP
|
#if HAVE_LIBCAP
|
||||||
linux_keepcaps();
|
linux_keepcaps();
|
||||||
named_os_changeuser();
|
named_os_changeuser(true);
|
||||||
linux_minprivs();
|
linux_minprivs();
|
||||||
#endif /* HAVE_LIBCAP */
|
#endif /* HAVE_LIBCAP */
|
||||||
}
|
}
|
||||||
@@ -787,19 +702,16 @@ named_os_openfile(const char *filename, mode_t mode, bool switch_user) {
|
|||||||
free(f);
|
free(f);
|
||||||
|
|
||||||
if (switch_user && runas_pw != NULL) {
|
if (switch_user && runas_pw != NULL) {
|
||||||
uid_t olduid = getuid();
|
|
||||||
gid_t oldgid = getgid();
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Set UID/GID to the one we'll be running with
|
* Temporarily set UID/GID to the one we'll be running with
|
||||||
* eventually.
|
* eventually.
|
||||||
*/
|
*/
|
||||||
setperms(runas_pw->pw_uid, runas_pw->pw_gid);
|
named_os_changeuser(false);
|
||||||
|
|
||||||
fd = safe_open(filename, mode, false);
|
fd = safe_open(filename, mode, false);
|
||||||
|
|
||||||
/* Restore UID/GID to previous uid/gid */
|
/* Restore UID/GID to previous uid/gid */
|
||||||
setperms(olduid, oldgid);
|
named_os_restoreuser();
|
||||||
|
|
||||||
if (fd == -1) {
|
if (fd == -1) {
|
||||||
fd = safe_open(filename, mode, false);
|
fd = safe_open(filename, mode, false);
|
||||||
|
|||||||
+785
-705
File diff suppressed because it is too large
Load Diff
+69
-60
@@ -472,6 +472,8 @@ init_desc(void) {
|
|||||||
"ClientQuota");
|
"ClientQuota");
|
||||||
SET_RESSTATDESC(nextitem, "waited for next item", "NextItem");
|
SET_RESSTATDESC(nextitem, "waited for next item", "NextItem");
|
||||||
SET_RESSTATDESC(priming, "priming queries", "Priming");
|
SET_RESSTATDESC(priming, "priming queries", "Priming");
|
||||||
|
SET_RESSTATDESC(forwardonlyfail, "all forwarders failed",
|
||||||
|
"ForwardOnlyFail");
|
||||||
|
|
||||||
INSIST(i == dns_resstatscounter_max);
|
INSIST(i == dns_resstatscounter_max);
|
||||||
|
|
||||||
@@ -936,9 +938,8 @@ dump_counters(isc_statsformat_t type, void *arg, const char *category,
|
|||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
#ifdef HAVE_LIBXML2
|
#ifdef HAVE_LIBXML2
|
||||||
cleanup:
|
cleanup:
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
ISC_LOG_ERROR, "failed at dump_counters()");
|
||||||
"failed at dump_counters()");
|
|
||||||
return (ISC_R_FAILURE);
|
return (ISC_R_FAILURE);
|
||||||
#endif /* ifdef HAVE_LIBXML2 */
|
#endif /* ifdef HAVE_LIBXML2 */
|
||||||
}
|
}
|
||||||
@@ -999,9 +1000,8 @@ rdtypestat_dump(dns_rdatastatstype_t type, uint64_t val, void *arg) {
|
|||||||
return;
|
return;
|
||||||
#ifdef HAVE_LIBXML2
|
#ifdef HAVE_LIBXML2
|
||||||
cleanup:
|
cleanup:
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
ISC_LOG_ERROR, "failed at rdtypestat_dump()");
|
||||||
"failed at rdtypestat_dump()");
|
|
||||||
dumparg->result = ISC_R_FAILURE;
|
dumparg->result = ISC_R_FAILURE;
|
||||||
return;
|
return;
|
||||||
#endif /* ifdef HAVE_LIBXML2 */
|
#endif /* ifdef HAVE_LIBXML2 */
|
||||||
@@ -1088,9 +1088,8 @@ rdatasetstats_dump(dns_rdatastatstype_t type, uint64_t val, void *arg) {
|
|||||||
return;
|
return;
|
||||||
#ifdef HAVE_LIBXML2
|
#ifdef HAVE_LIBXML2
|
||||||
cleanup:
|
cleanup:
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
ISC_LOG_ERROR, "failed at rdatasetstats_dump()");
|
||||||
"failed at rdatasetstats_dump()");
|
|
||||||
dumparg->result = ISC_R_FAILURE;
|
dumparg->result = ISC_R_FAILURE;
|
||||||
#endif /* ifdef HAVE_LIBXML2 */
|
#endif /* ifdef HAVE_LIBXML2 */
|
||||||
}
|
}
|
||||||
@@ -1143,9 +1142,8 @@ opcodestat_dump(dns_opcode_t code, uint64_t val, void *arg) {
|
|||||||
|
|
||||||
#ifdef HAVE_LIBXML2
|
#ifdef HAVE_LIBXML2
|
||||||
cleanup:
|
cleanup:
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
ISC_LOG_ERROR, "failed at opcodestat_dump()");
|
||||||
"failed at opcodestat_dump()");
|
|
||||||
dumparg->result = ISC_R_FAILURE;
|
dumparg->result = ISC_R_FAILURE;
|
||||||
return;
|
return;
|
||||||
#endif /* ifdef HAVE_LIBXML2 */
|
#endif /* ifdef HAVE_LIBXML2 */
|
||||||
@@ -1199,9 +1197,8 @@ rcodestat_dump(dns_rcode_t code, uint64_t val, void *arg) {
|
|||||||
|
|
||||||
#ifdef HAVE_LIBXML2
|
#ifdef HAVE_LIBXML2
|
||||||
cleanup:
|
cleanup:
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
ISC_LOG_ERROR, "failed at rcodestat_dump()");
|
||||||
"failed at rcodestat_dump()");
|
|
||||||
dumparg->result = ISC_R_FAILURE;
|
dumparg->result = ISC_R_FAILURE;
|
||||||
return;
|
return;
|
||||||
#endif /* ifdef HAVE_LIBXML2 */
|
#endif /* ifdef HAVE_LIBXML2 */
|
||||||
@@ -1256,9 +1253,8 @@ dnssecsignstat_dump(uint32_t kval, uint64_t val, void *arg) {
|
|||||||
return;
|
return;
|
||||||
#ifdef HAVE_LIBXML2
|
#ifdef HAVE_LIBXML2
|
||||||
cleanup:
|
cleanup:
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
ISC_LOG_ERROR, "failed at dnssecsignstat_dump()");
|
||||||
"failed at dnssecsignstat_dump()");
|
|
||||||
dumparg->result = ISC_R_FAILURE;
|
dumparg->result = ISC_R_FAILURE;
|
||||||
return;
|
return;
|
||||||
#endif /* ifdef HAVE_LIBXML2 */
|
#endif /* ifdef HAVE_LIBXML2 */
|
||||||
@@ -1452,9 +1448,8 @@ zone_xmlrender(dns_zone_t *zone, void *arg) {
|
|||||||
|
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
cleanup:
|
cleanup:
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
ISC_LOG_ERROR, "Failed at zone_xmlrender()");
|
||||||
"Failed at zone_xmlrender()");
|
|
||||||
return (ISC_R_FAILURE);
|
return (ISC_R_FAILURE);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1725,9 +1720,8 @@ cleanup:
|
|||||||
dns_xfrin_detach(&xfr);
|
dns_xfrin_detach(&xfr);
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
ISC_LOG_ERROR, "Failed at xfrin_xmlrender()");
|
||||||
"Failed at xfrin_xmlrender()");
|
|
||||||
|
|
||||||
return (ISC_R_FAILURE);
|
return (ISC_R_FAILURE);
|
||||||
}
|
}
|
||||||
@@ -2134,9 +2128,8 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
|||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
ISC_LOG_ERROR, "failed generating XML response");
|
||||||
"failed generating XML response");
|
|
||||||
if (writer != NULL) {
|
if (writer != NULL) {
|
||||||
xmlFreeTextWriter(writer);
|
xmlFreeTextWriter(writer);
|
||||||
}
|
}
|
||||||
@@ -2173,9 +2166,8 @@ render_xml(uint32_t flags, void *arg, unsigned int *retcode,
|
|||||||
*freecb = wrap_xmlfree;
|
*freecb = wrap_xmlfree;
|
||||||
*freecb_args = NULL;
|
*freecb_args = NULL;
|
||||||
} else {
|
} else {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
ISC_LOG_ERROR, "failed at rendering XML()");
|
||||||
"failed at rendering XML()");
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return (result);
|
return (result);
|
||||||
@@ -3376,9 +3368,8 @@ render_json(uint32_t flags, void *arg, unsigned int *retcode,
|
|||||||
*freecb = wrap_jsonfree;
|
*freecb = wrap_jsonfree;
|
||||||
*freecb_args = bindstats;
|
*freecb_args = bindstats;
|
||||||
} else {
|
} else {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
ISC_LOG_ERROR, "failed at rendering JSON()");
|
||||||
"failed at rendering JSON()");
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return (result);
|
return (result);
|
||||||
@@ -3474,6 +3465,11 @@ render_json_traffic(const isc_httpd_t *httpd, const isc_httpdurl_t *urlinfo,
|
|||||||
|
|
||||||
#endif /* HAVE_JSON_C */
|
#endif /* HAVE_JSON_C */
|
||||||
|
|
||||||
|
#if HAVE_LIBXML2
|
||||||
|
/*
|
||||||
|
* This is only needed if we have libxml2 and was confusingly returned if
|
||||||
|
* neither of libxml2 or json-c is configured.
|
||||||
|
*/
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
render_xsl(const isc_httpd_t *httpd, const isc_httpdurl_t *urlinfo, void *args,
|
render_xsl(const isc_httpd_t *httpd, const isc_httpdurl_t *urlinfo, void *args,
|
||||||
unsigned int *retcode, const char **retmsg, const char **mimetype,
|
unsigned int *retcode, const char **retmsg, const char **mimetype,
|
||||||
@@ -3529,18 +3525,20 @@ send:
|
|||||||
end:
|
end:
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
}
|
}
|
||||||
|
#endif
|
||||||
|
|
||||||
static void
|
static void
|
||||||
shutdown_listener(named_statschannel_t *listener) {
|
shutdown_listener(named_statschannel_t *listener) {
|
||||||
char socktext[ISC_SOCKADDR_FORMATSIZE];
|
char socktext[ISC_SOCKADDR_FORMATSIZE];
|
||||||
isc_sockaddr_format(&listener->address, socktext, sizeof(socktext));
|
isc_sockaddr_format(&listener->address, socktext, sizeof(socktext));
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "stopping statistics channel on %s",
|
||||||
"stopping statistics channel on %s", socktext);
|
socktext);
|
||||||
|
|
||||||
isc_httpdmgr_shutdown(&listener->httpdmgr);
|
isc_httpdmgr_shutdown(&listener->httpdmgr);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#if defined(HAVE_LIBXML2) || defined(HAVE_JSON_C)
|
||||||
static bool
|
static bool
|
||||||
client_ok(const isc_sockaddr_t *fromaddr, void *arg) {
|
client_ok(const isc_sockaddr_t *fromaddr, void *arg) {
|
||||||
named_statschannel_t *listener = arg;
|
named_statschannel_t *listener = arg;
|
||||||
@@ -3565,13 +3563,15 @@ client_ok(const isc_sockaddr_t *fromaddr, void *arg) {
|
|||||||
UNLOCK(&listener->lock);
|
UNLOCK(&listener->lock);
|
||||||
|
|
||||||
isc_sockaddr_format(fromaddr, socktext, sizeof(socktext));
|
isc_sockaddr_format(fromaddr, socktext, sizeof(socktext));
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
ISC_LOG_WARNING, "rejected statistics connection from %s",
|
||||||
"rejected statistics connection from %s", socktext);
|
socktext);
|
||||||
|
|
||||||
return (false);
|
return (false);
|
||||||
}
|
}
|
||||||
|
#endif
|
||||||
|
|
||||||
|
#if defined(HAVE_LIBXML2) || defined(HAVE_JSON_C)
|
||||||
static void
|
static void
|
||||||
destroy_listener(void *arg) {
|
destroy_listener(void *arg) {
|
||||||
named_statschannel_t *listener = (named_statschannel_t *)arg;
|
named_statschannel_t *listener = (named_statschannel_t *)arg;
|
||||||
@@ -3585,12 +3585,24 @@ destroy_listener(void *arg) {
|
|||||||
isc_mutex_destroy(&listener->lock);
|
isc_mutex_destroy(&listener->lock);
|
||||||
isc_mem_putanddetach(&listener->mctx, listener, sizeof(*listener));
|
isc_mem_putanddetach(&listener->mctx, listener, sizeof(*listener));
|
||||||
}
|
}
|
||||||
|
#endif
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
add_listener(named_server_t *server, named_statschannel_t **listenerp,
|
add_listener(named_server_t *server, named_statschannel_t **listenerp,
|
||||||
const cfg_obj_t *listen_params, const cfg_obj_t *config,
|
const cfg_obj_t *listen_params, const cfg_obj_t *config,
|
||||||
isc_sockaddr_t *addr, cfg_aclconfctx_t *aclconfctx,
|
isc_sockaddr_t *addr, cfg_aclconfctx_t *aclconfctx,
|
||||||
const char *socktext) {
|
const char *socktext) {
|
||||||
|
#if !defined(HAVE_LIBXML2) && !defined(HAVE_JSON_C)
|
||||||
|
UNUSED(server);
|
||||||
|
UNUSED(listenerp);
|
||||||
|
UNUSED(listen_params);
|
||||||
|
UNUSED(config);
|
||||||
|
UNUSED(addr);
|
||||||
|
UNUSED(aclconfctx);
|
||||||
|
UNUSED(socktext);
|
||||||
|
|
||||||
|
return (ISC_R_NOTIMPLEMENTED);
|
||||||
|
#else
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
named_statschannel_t *listener = NULL;
|
named_statschannel_t *listener = NULL;
|
||||||
const cfg_obj_t *allow = NULL;
|
const cfg_obj_t *allow = NULL;
|
||||||
@@ -3605,9 +3617,8 @@ add_listener(named_server_t *server, named_statschannel_t **listenerp,
|
|||||||
|
|
||||||
allow = cfg_tuple_get(listen_params, "allow");
|
allow = cfg_tuple_get(listen_params, "allow");
|
||||||
if (allow != NULL && cfg_obj_islist(allow)) {
|
if (allow != NULL && cfg_obj_islist(allow)) {
|
||||||
result = cfg_acl_fromconfig(allow, config, named_g_lctx,
|
result = cfg_acl_fromconfig(allow, config, aclconfctx,
|
||||||
aclconfctx, listener->mctx, 0,
|
listener->mctx, 0, &new_acl);
|
||||||
&new_acl);
|
|
||||||
} else {
|
} else {
|
||||||
result = dns_acl_any(listener->mctx, &new_acl);
|
result = dns_acl_any(listener->mctx, &new_acl);
|
||||||
}
|
}
|
||||||
@@ -3656,6 +3667,8 @@ add_listener(named_server_t *server, named_statschannel_t **listenerp,
|
|||||||
isc_httpdmgr_addurl(listener->httpdmgr,
|
isc_httpdmgr_addurl(listener->httpdmgr,
|
||||||
"/xml/v" STATS_XML_VERSION_MAJOR "/traffic", false,
|
"/xml/v" STATS_XML_VERSION_MAJOR "/traffic", false,
|
||||||
render_xml_traffic, server);
|
render_xml_traffic, server);
|
||||||
|
isc_httpdmgr_addurl(listener->httpdmgr, "/bind9.xsl", true, render_xsl,
|
||||||
|
server);
|
||||||
#endif /* ifdef HAVE_LIBXML2 */
|
#endif /* ifdef HAVE_LIBXML2 */
|
||||||
#ifdef HAVE_JSON_C
|
#ifdef HAVE_JSON_C
|
||||||
isc_httpdmgr_addurl(listener->httpdmgr, "/json", false, render_json_all,
|
isc_httpdmgr_addurl(listener->httpdmgr, "/json", false, render_json_all,
|
||||||
@@ -3685,13 +3698,11 @@ add_listener(named_server_t *server, named_statschannel_t **listenerp,
|
|||||||
"/json/v" STATS_JSON_VERSION_MAJOR "/traffic",
|
"/json/v" STATS_JSON_VERSION_MAJOR "/traffic",
|
||||||
false, render_json_traffic, server);
|
false, render_json_traffic, server);
|
||||||
#endif /* ifdef HAVE_JSON_C */
|
#endif /* ifdef HAVE_JSON_C */
|
||||||
isc_httpdmgr_addurl(listener->httpdmgr, "/bind9.xsl", true, render_xsl,
|
|
||||||
server);
|
|
||||||
|
|
||||||
*listenerp = listener;
|
*listenerp = listener;
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_NOTICE,
|
ISC_LOG_NOTICE, "statistics channel listening on %s",
|
||||||
"statistics channel listening on %s", socktext);
|
socktext);
|
||||||
|
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
|
|
||||||
@@ -3703,6 +3714,7 @@ cleanup:
|
|||||||
isc_mem_putanddetach(&listener->mctx, listener, sizeof(*listener));
|
isc_mem_putanddetach(&listener->mctx, listener, sizeof(*listener));
|
||||||
|
|
||||||
return (result);
|
return (result);
|
||||||
|
#endif
|
||||||
}
|
}
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -3733,9 +3745,8 @@ update_listener(named_server_t *server, named_statschannel_t **listenerp,
|
|||||||
*/
|
*/
|
||||||
allow = cfg_tuple_get(listen_params, "allow");
|
allow = cfg_tuple_get(listen_params, "allow");
|
||||||
if (allow != NULL && cfg_obj_islist(allow)) {
|
if (allow != NULL && cfg_obj_islist(allow)) {
|
||||||
result = cfg_acl_fromconfig(allow, config, named_g_lctx,
|
result = cfg_acl_fromconfig(allow, config, aclconfctx,
|
||||||
aclconfctx, listener->mctx, 0,
|
listener->mctx, 0, &new_acl);
|
||||||
&new_acl);
|
|
||||||
} else {
|
} else {
|
||||||
result = dns_acl_any(listener->mctx, &new_acl);
|
result = dns_acl_any(listener->mctx, &new_acl);
|
||||||
}
|
}
|
||||||
@@ -3749,7 +3760,7 @@ update_listener(named_server_t *server, named_statschannel_t **listenerp,
|
|||||||
|
|
||||||
UNLOCK(&listener->lock);
|
UNLOCK(&listener->lock);
|
||||||
} else {
|
} else {
|
||||||
cfg_obj_log(listen_params, named_g_lctx, ISC_LOG_WARNING,
|
cfg_obj_log(listen_params, ISC_LOG_WARNING,
|
||||||
"couldn't install new acl for "
|
"couldn't install new acl for "
|
||||||
"statistics channel %s: %s",
|
"statistics channel %s: %s",
|
||||||
socktext, isc_result_totext(result));
|
socktext, isc_result_totext(result));
|
||||||
@@ -3786,20 +3797,20 @@ named_statschannels_configure(named_server_t *server, const cfg_obj_t *config,
|
|||||||
*/
|
*/
|
||||||
if (statschannellist != NULL) {
|
if (statschannellist != NULL) {
|
||||||
#ifndef EXTENDED_STATS
|
#ifndef EXTENDED_STATS
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
ISC_LOG_WARNING,
|
||||||
"statistics-channels specified but not effective "
|
"statistics-channels specified but not effective "
|
||||||
"due to missing XML and/or JSON library");
|
"due to missing XML and/or JSON library");
|
||||||
#else /* EXTENDED_STATS */
|
#else /* EXTENDED_STATS */
|
||||||
#ifndef HAVE_LIBXML2
|
#ifndef HAVE_LIBXML2
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
ISC_LOG_WARNING,
|
||||||
"statistics-channels: XML library missing, "
|
"statistics-channels: XML library missing, "
|
||||||
"only JSON stats will be available");
|
"only JSON stats will be available");
|
||||||
#endif /* !HAVE_LIBXML2 */
|
#endif /* !HAVE_LIBXML2 */
|
||||||
#ifndef HAVE_JSON_C
|
#ifndef HAVE_JSON_C
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
ISC_LOG_WARNING,
|
||||||
"statistics-channels: JSON library missing, "
|
"statistics-channels: JSON library missing, "
|
||||||
"only XML stats will be available");
|
"only XML stats will be available");
|
||||||
#endif /* !HAVE_JSON_C */
|
#endif /* !HAVE_JSON_C */
|
||||||
@@ -3838,8 +3849,7 @@ named_statschannels_configure(named_server_t *server, const cfg_obj_t *config,
|
|||||||
isc_sockaddr_format(&addr, socktext,
|
isc_sockaddr_format(&addr, socktext,
|
||||||
sizeof(socktext));
|
sizeof(socktext));
|
||||||
|
|
||||||
isc_log_write(named_g_lctx,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGCATEGORY_GENERAL,
|
|
||||||
NAMED_LOGMODULE_SERVER,
|
NAMED_LOGMODULE_SERVER,
|
||||||
ISC_LOG_DEBUG(9),
|
ISC_LOG_DEBUG(9),
|
||||||
"processing statistics "
|
"processing statistics "
|
||||||
@@ -3870,7 +3880,6 @@ named_statschannels_configure(named_server_t *server, const cfg_obj_t *config,
|
|||||||
if (r != ISC_R_SUCCESS) {
|
if (r != ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(
|
cfg_obj_log(
|
||||||
listen_params,
|
listen_params,
|
||||||
named_g_lctx,
|
|
||||||
ISC_LOG_WARNING,
|
ISC_LOG_WARNING,
|
||||||
"couldn't allocate "
|
"couldn't allocate "
|
||||||
"statistics channel"
|
"statistics channel"
|
||||||
|
|||||||
@@ -38,9 +38,9 @@
|
|||||||
} while (0)
|
} while (0)
|
||||||
|
|
||||||
#include <named/log.h>
|
#include <named/log.h>
|
||||||
#define LOG(msg) \
|
#define LOG(msg) \
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL, \
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER, \
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR, "%s", msg)
|
ISC_LOG_ERROR, "%s", msg)
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
named_tkeyctx_fromconfig(const cfg_obj_t *options, isc_mem_t *mctx,
|
named_tkeyctx_fromconfig(const cfg_obj_t *options, isc_mem_t *mctx,
|
||||||
|
|||||||
@@ -133,8 +133,7 @@ add_doh_transports(const cfg_obj_t *transportlist, dns_transport_list_t *list) {
|
|||||||
|
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
failure:
|
failure:
|
||||||
cfg_obj_log(doh, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(doh, ISC_LOG_ERROR, "configuring DoH '%s': %s", dohid,
|
||||||
"configuring DoH '%s': %s", dohid,
|
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
|
|
||||||
return (result);
|
return (result);
|
||||||
@@ -187,8 +186,7 @@ add_tls_transports(const cfg_obj_t *transportlist, dns_transport_list_t *list) {
|
|||||||
|
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
failure:
|
failure:
|
||||||
cfg_obj_log(tls, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(tls, ISC_LOG_ERROR, "configuring tls '%s': %s", tlsid,
|
||||||
"configuring tls '%s': %s", tlsid,
|
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
|
|
||||||
return (result);
|
return (result);
|
||||||
|
|||||||
@@ -85,7 +85,7 @@ add_initial_keys(const cfg_obj_t *list, dns_tsigkeyring_t *ring,
|
|||||||
if (named_config_getkeyalgorithm(algstr, &alg, &bits) !=
|
if (named_config_getkeyalgorithm(algstr, &alg, &bits) !=
|
||||||
ISC_R_SUCCESS)
|
ISC_R_SUCCESS)
|
||||||
{
|
{
|
||||||
cfg_obj_log(algobj, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(algobj, ISC_LOG_ERROR,
|
||||||
"key '%s': has a "
|
"key '%s': has a "
|
||||||
"unsupported algorithm '%s'",
|
"unsupported algorithm '%s'",
|
||||||
keyid, algstr);
|
keyid, algstr);
|
||||||
@@ -129,8 +129,8 @@ failure:
|
|||||||
if (secret != NULL) {
|
if (secret != NULL) {
|
||||||
isc_mem_put(mctx, secret, secretalloc);
|
isc_mem_put(mctx, secret, secretalloc);
|
||||||
}
|
}
|
||||||
cfg_obj_log(key, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(key, ISC_LOG_ERROR, "configuring key '%s': %s", keyid,
|
||||||
"configuring key '%s': %s", keyid, isc_result_totext(ret));
|
isc_result_totext(ret));
|
||||||
return (ret);
|
return (ret);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+29
-57
@@ -16,6 +16,7 @@
|
|||||||
|
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
#include <isc/stats.h>
|
#include <isc/stats.h>
|
||||||
@@ -28,7 +29,6 @@
|
|||||||
#include <dns/ipkeylist.h>
|
#include <dns/ipkeylist.h>
|
||||||
#include <dns/journal.h>
|
#include <dns/journal.h>
|
||||||
#include <dns/kasp.h>
|
#include <dns/kasp.h>
|
||||||
#include <dns/log.h>
|
|
||||||
#include <dns/masterdump.h>
|
#include <dns/masterdump.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/nsec3.h>
|
#include <dns/nsec3.h>
|
||||||
@@ -175,8 +175,8 @@ configure_zone_acl(const cfg_obj_t *zconfig, const cfg_obj_t *vconfig,
|
|||||||
}
|
}
|
||||||
|
|
||||||
parse_acl:
|
parse_acl:
|
||||||
result = cfg_acl_fromconfig(aclobj, config, named_g_lctx, actx,
|
result = cfg_acl_fromconfig(aclobj, config, actx, named_g_mctx, 0,
|
||||||
named_g_mctx, 0, &acl);
|
&acl);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
@@ -262,7 +262,7 @@ configure_zone_ssutable(const cfg_obj_t *zconfig, dns_zone_t *zone,
|
|||||||
result = dns_name_fromtext(dns_fixedname_name(&fident), &b,
|
result = dns_name_fromtext(dns_fixedname_name(&fident), &b,
|
||||||
dns_rootname, 0, NULL);
|
dns_rootname, 0, NULL);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(identity, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(identity, ISC_LOG_ERROR,
|
||||||
"'%s' is not a valid name", str);
|
"'%s' is not a valid name", str);
|
||||||
goto cleanup;
|
goto cleanup;
|
||||||
}
|
}
|
||||||
@@ -278,8 +278,7 @@ configure_zone_ssutable(const cfg_obj_t *zconfig, dns_zone_t *zone,
|
|||||||
result = dns_name_fromtext(dns_fixedname_name(&fname),
|
result = dns_name_fromtext(dns_fixedname_name(&fname),
|
||||||
&b, dns_rootname, 0, NULL);
|
&b, dns_rootname, 0, NULL);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(identity, named_g_lctx,
|
cfg_obj_log(identity, ISC_LOG_ERROR,
|
||||||
ISC_LOG_ERROR,
|
|
||||||
"'%s' is not a valid name", str);
|
"'%s' is not a valid name", str);
|
||||||
goto cleanup;
|
goto cleanup;
|
||||||
}
|
}
|
||||||
@@ -315,8 +314,7 @@ configure_zone_ssutable(const cfg_obj_t *zconfig, dns_zone_t *zone,
|
|||||||
if (max > 0xffff || end[0] != /*(*/ ')' ||
|
if (max > 0xffff || end[0] != /*(*/ ')' ||
|
||||||
end[1] != 0)
|
end[1] != 0)
|
||||||
{
|
{
|
||||||
cfg_obj_log(identity, named_g_lctx,
|
cfg_obj_log(identity, ISC_LOG_ERROR,
|
||||||
ISC_LOG_ERROR,
|
|
||||||
"'%s' is not a valid count",
|
"'%s' is not a valid count",
|
||||||
bracket);
|
bracket);
|
||||||
isc_mem_cput(mctx, types, n,
|
isc_mem_cput(mctx, types, n,
|
||||||
@@ -330,8 +328,7 @@ configure_zone_ssutable(const cfg_obj_t *zconfig, dns_zone_t *zone,
|
|||||||
|
|
||||||
result = dns_rdatatype_fromtext(&types[i++].type, &r);
|
result = dns_rdatatype_fromtext(&types[i++].type, &r);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(identity, named_g_lctx,
|
cfg_obj_log(identity, ISC_LOG_ERROR,
|
||||||
ISC_LOG_ERROR,
|
|
||||||
"'%.*s' is not a valid type",
|
"'%.*s' is not a valid type",
|
||||||
(int)r.length, str);
|
(int)r.length, str);
|
||||||
isc_mem_cput(mctx, types, n, sizeof(*types));
|
isc_mem_cput(mctx, types, n, sizeof(*types));
|
||||||
@@ -357,7 +354,7 @@ configure_zone_ssutable(const cfg_obj_t *zconfig, dns_zone_t *zone,
|
|||||||
dns_ssuruletype_t any = { dns_rdatatype_any, 0 };
|
dns_ssuruletype_t any = { dns_rdatatype_any, 0 };
|
||||||
|
|
||||||
if (named_g_server->session_keyname == NULL) {
|
if (named_g_server->session_keyname == NULL) {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||||
"failed to enable auto DDNS policy "
|
"failed to enable auto DDNS policy "
|
||||||
"for zone %s: session key not found",
|
"for zone %s: session key not found",
|
||||||
@@ -415,14 +412,14 @@ configure_staticstub_serveraddrs(const cfg_obj_t *zconfig, dns_zone_t *zone,
|
|||||||
|
|
||||||
sa = cfg_obj_assockaddr(address);
|
sa = cfg_obj_assockaddr(address);
|
||||||
if (isc_sockaddr_getport(sa) != 0) {
|
if (isc_sockaddr_getport(sa) != 0) {
|
||||||
cfg_obj_log(zconfig, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(zconfig, ISC_LOG_ERROR,
|
||||||
"port is not configurable for "
|
"port is not configurable for "
|
||||||
"static stub server-addresses");
|
"static stub server-addresses");
|
||||||
return (ISC_R_FAILURE);
|
return (ISC_R_FAILURE);
|
||||||
}
|
}
|
||||||
isc_netaddr_fromsockaddr(&na, sa);
|
isc_netaddr_fromsockaddr(&na, sa);
|
||||||
if (isc_netaddr_getzone(&na) != 0) {
|
if (isc_netaddr_getzone(&na) != 0) {
|
||||||
cfg_obj_log(zconfig, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(zconfig, ISC_LOG_ERROR,
|
||||||
"scoped address is not allowed "
|
"scoped address is not allowed "
|
||||||
"for static stub "
|
"for static stub "
|
||||||
"server-addresses");
|
"server-addresses");
|
||||||
@@ -508,14 +505,14 @@ configure_staticstub_servernames(const cfg_obj_t *zconfig, dns_zone_t *zone,
|
|||||||
isc_buffer_add(&b, strlen(str));
|
isc_buffer_add(&b, strlen(str));
|
||||||
result = dns_name_fromtext(nsname, &b, dns_rootname, 0, NULL);
|
result = dns_name_fromtext(nsname, &b, dns_rootname, 0, NULL);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(zconfig, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(zconfig, ISC_LOG_ERROR,
|
||||||
"server-name '%s' is not a valid "
|
"server-name '%s' is not a valid "
|
||||||
"name",
|
"name",
|
||||||
str);
|
str);
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
if (dns_name_issubdomain(nsname, dns_zone_getorigin(zone))) {
|
if (dns_name_issubdomain(nsname, dns_zone_getorigin(zone))) {
|
||||||
cfg_obj_log(zconfig, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(zconfig, ISC_LOG_ERROR,
|
||||||
"server-name '%s' must not be a "
|
"server-name '%s' must not be a "
|
||||||
"subdomain of zone name '%s'",
|
"subdomain of zone name '%s'",
|
||||||
str, zname);
|
str, zname);
|
||||||
@@ -602,8 +599,8 @@ configure_staticstub(const cfg_obj_t *zconfig, dns_zone_t *zone,
|
|||||||
* to trigger delegation.
|
* to trigger delegation.
|
||||||
*/
|
*/
|
||||||
if (ISC_LIST_EMPTY(rdatalist_ns.rdata)) {
|
if (ISC_LIST_EMPTY(rdatalist_ns.rdata)) {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
ISC_LOG_ERROR,
|
||||||
"No NS record is configured for a "
|
"No NS record is configured for a "
|
||||||
"static-stub zone '%s'",
|
"static-stub zone '%s'",
|
||||||
zname);
|
zname);
|
||||||
@@ -854,7 +851,7 @@ process_notifytype(dns_notifytype_t ntype, dns_zonetype_t ztype,
|
|||||||
* hierarchy supplied in 'maps'.
|
* hierarchy supplied in 'maps'.
|
||||||
*/
|
*/
|
||||||
if (named_config_get(maps, "notify", &obj) == ISC_R_SUCCESS) {
|
if (named_config_get(maps, "notify", &obj) == ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(obj, named_g_lctx, ISC_LOG_INFO,
|
cfg_obj_log(obj, ISC_LOG_INFO,
|
||||||
"'notify explicit;' will be used for mirror zone "
|
"'notify explicit;' will be used for mirror zone "
|
||||||
"'%s'",
|
"'%s'",
|
||||||
zname);
|
zname);
|
||||||
@@ -889,7 +886,6 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
static char dlz_dbtype[] = "dlz";
|
static char dlz_dbtype[] = "dlz";
|
||||||
char *cpval = default_dbtype;
|
char *cpval = default_dbtype;
|
||||||
isc_mem_t *mctx = dns_zone_getmctx(zone);
|
isc_mem_t *mctx = dns_zone_getmctx(zone);
|
||||||
dns_dialuptype_t dialup = dns_dialuptype_no;
|
|
||||||
dns_zonetype_t ztype;
|
dns_zonetype_t ztype;
|
||||||
int i;
|
int i;
|
||||||
int32_t journal_size;
|
int32_t journal_size;
|
||||||
@@ -975,7 +971,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
size_t len;
|
size_t len;
|
||||||
|
|
||||||
if (cpval != default_dbtype) {
|
if (cpval != default_dbtype) {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||||
"zone '%s': both 'database' and 'dlz' "
|
"zone '%s': both 'database' and 'dlz' "
|
||||||
"specified",
|
"specified",
|
||||||
@@ -1018,9 +1014,9 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
if (ztype == dns_zone_primary && cpval == default_dbtype &&
|
if (ztype == dns_zone_primary && cpval == default_dbtype &&
|
||||||
filename == NULL)
|
filename == NULL)
|
||||||
{
|
{
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
ISC_LOG_ERROR, "zone '%s': 'file' not specified",
|
||||||
"zone '%s': 'file' not specified", zname);
|
zname);
|
||||||
CHECK(ISC_R_FAILURE);
|
CHECK(ISC_R_FAILURE);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1049,7 +1045,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
const char *masterstylestr = cfg_obj_asstring(obj);
|
const char *masterstylestr = cfg_obj_asstring(obj);
|
||||||
|
|
||||||
if (masterformat != dns_masterformat_text) {
|
if (masterformat != dns_masterformat_text) {
|
||||||
cfg_obj_log(obj, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(obj, ISC_LOG_ERROR,
|
||||||
"zone '%s': 'masterfile-style' "
|
"zone '%s': 'masterfile-style' "
|
||||||
"can only be used with "
|
"can only be used with "
|
||||||
"'masterfile-format text'",
|
"'masterfile-format text'",
|
||||||
@@ -1135,34 +1131,6 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
zone, dns_zone_setqueryonacl,
|
zone, dns_zone_setqueryonacl,
|
||||||
dns_zone_clearqueryonacl));
|
dns_zone_clearqueryonacl));
|
||||||
|
|
||||||
obj = NULL;
|
|
||||||
result = named_config_get(maps, "dialup", &obj);
|
|
||||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
|
||||||
if (cfg_obj_isboolean(obj)) {
|
|
||||||
if (cfg_obj_asboolean(obj)) {
|
|
||||||
dialup = dns_dialuptype_yes;
|
|
||||||
} else {
|
|
||||||
dialup = dns_dialuptype_no;
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
const char *dialupstr = cfg_obj_asstring(obj);
|
|
||||||
if (strcasecmp(dialupstr, "notify") == 0) {
|
|
||||||
dialup = dns_dialuptype_notify;
|
|
||||||
} else if (strcasecmp(dialupstr, "notify-passive") == 0) {
|
|
||||||
dialup = dns_dialuptype_notifypassive;
|
|
||||||
} else if (strcasecmp(dialupstr, "refresh") == 0) {
|
|
||||||
dialup = dns_dialuptype_refresh;
|
|
||||||
} else if (strcasecmp(dialupstr, "passive") == 0) {
|
|
||||||
dialup = dns_dialuptype_passive;
|
|
||||||
} else {
|
|
||||||
UNREACHABLE();
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if (raw != NULL) {
|
|
||||||
dns_zone_setdialup(raw, dialup);
|
|
||||||
}
|
|
||||||
dns_zone_setdialup(zone, dialup);
|
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = named_config_get(maps, "zone-statistics", &obj);
|
result = named_config_get(maps, "zone-statistics", &obj);
|
||||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||||
@@ -1233,8 +1201,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
&kasp);
|
&kasp);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(
|
cfg_obj_log(
|
||||||
obj, named_g_lctx,
|
obj, ISC_LOG_ERROR,
|
||||||
ISC_LOG_ERROR,
|
|
||||||
"dnssec-policy '%s' not found ",
|
"dnssec-policy '%s' not found ",
|
||||||
kaspname);
|
kaspname);
|
||||||
CHECK(result);
|
CHECK(result);
|
||||||
@@ -1360,7 +1327,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
} else {
|
} else {
|
||||||
uint64_t value = cfg_obj_asuint64(obj);
|
uint64_t value = cfg_obj_asuint64(obj);
|
||||||
if (value > DNS_JOURNAL_SIZE_MAX) {
|
if (value > DNS_JOURNAL_SIZE_MAX) {
|
||||||
cfg_obj_log(obj, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(obj, ISC_LOG_ERROR,
|
||||||
"'max-journal-size "
|
"'max-journal-size "
|
||||||
"%" PRId64 "' "
|
"%" PRId64 "' "
|
||||||
"is too large",
|
"is too large",
|
||||||
@@ -1422,6 +1389,11 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
INSIST(result == ISC_R_SUCCESS);
|
INSIST(result == ISC_R_SUCCESS);
|
||||||
dns_zone_setrequestixfr(zone, cfg_obj_asboolean(obj));
|
dns_zone_setrequestixfr(zone, cfg_obj_asboolean(obj));
|
||||||
|
|
||||||
|
obj = NULL;
|
||||||
|
result = named_config_get(maps, "request-ixfr-max-diffs", &obj);
|
||||||
|
INSIST(result == ISC_R_SUCCESS);
|
||||||
|
dns_zone_setrequestixfrmaxdiffs(zone, cfg_obj_asuint32(obj));
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
checknames(ztype, maps, &obj);
|
checknames(ztype, maps, &obj);
|
||||||
INSIST(obj != NULL);
|
INSIST(obj != NULL);
|
||||||
@@ -1505,7 +1477,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
} else {
|
} else {
|
||||||
uint64_t value = cfg_obj_asuint64(obj);
|
uint64_t value = cfg_obj_asuint64(obj);
|
||||||
if (value > DNS_JOURNAL_SIZE_MAX) {
|
if (value > DNS_JOURNAL_SIZE_MAX) {
|
||||||
cfg_obj_log(obj, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(obj, ISC_LOG_ERROR,
|
||||||
"'max-journal-size "
|
"'max-journal-size "
|
||||||
"%" PRId64 "' "
|
"%" PRId64 "' "
|
||||||
"is too large",
|
"is too large",
|
||||||
@@ -1546,7 +1518,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
|
|
||||||
updateacl = dns_zone_getupdateacl(mayberaw);
|
updateacl = dns_zone_getupdateacl(mayberaw);
|
||||||
if (updateacl != NULL && dns_acl_isinsecure(updateacl)) {
|
if (updateacl != NULL && dns_acl_isinsecure(updateacl)) {
|
||||||
isc_log_write(named_g_lctx, DNS_LOGCATEGORY_SECURITY,
|
isc_log_write(DNS_LOGCATEGORY_SECURITY,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
NAMED_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
||||||
"zone '%s' allows unsigned updates "
|
"zone '%s' allows unsigned updates "
|
||||||
"from remote hosts, which is insecure",
|
"from remote hosts, which is insecure",
|
||||||
|
|||||||
+13
-32
@@ -52,7 +52,6 @@
|
|||||||
#include <dns/dispatch.h>
|
#include <dns/dispatch.h>
|
||||||
#include <dns/dnssec.h>
|
#include <dns/dnssec.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/log.h>
|
|
||||||
#include <dns/masterdump.h>
|
#include <dns/masterdump.h>
|
||||||
#include <dns/message.h>
|
#include <dns/message.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
@@ -117,14 +116,12 @@ static bool debugging = false, ddebugging = false;
|
|||||||
static bool memdebugging = false;
|
static bool memdebugging = false;
|
||||||
static bool have_ipv4 = false;
|
static bool have_ipv4 = false;
|
||||||
static bool have_ipv6 = false;
|
static bool have_ipv6 = false;
|
||||||
static bool is_dst_up = false;
|
|
||||||
static bool use_tls = false;
|
static bool use_tls = false;
|
||||||
static bool usevc = false;
|
static bool usevc = false;
|
||||||
static bool usegsstsig = false;
|
static bool usegsstsig = false;
|
||||||
static bool local_only = false;
|
static bool local_only = false;
|
||||||
static isc_nm_t *netmgr = NULL;
|
static isc_nm_t *netmgr = NULL;
|
||||||
static isc_loopmgr_t *loopmgr = NULL;
|
static isc_loopmgr_t *loopmgr = NULL;
|
||||||
static isc_log_t *glctx = NULL;
|
|
||||||
static isc_mem_t *gmctx = NULL;
|
static isc_mem_t *gmctx = NULL;
|
||||||
static dns_dispatchmgr_t *dispatchmgr = NULL;
|
static dns_dispatchmgr_t *dispatchmgr = NULL;
|
||||||
static dns_requestmgr_t *requestmgr = NULL;
|
static dns_requestmgr_t *requestmgr = NULL;
|
||||||
@@ -199,7 +196,7 @@ send_update(dns_name_t *zonename, isc_sockaddr_t *primary);
|
|||||||
static void
|
static void
|
||||||
getinput(void *arg);
|
getinput(void *arg);
|
||||||
|
|
||||||
noreturn static void
|
ISC_NORETURN static void
|
||||||
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -560,7 +557,7 @@ failure:
|
|||||||
* Get a key from a named.conf format keyfile
|
* Get a key from a named.conf format keyfile
|
||||||
*/
|
*/
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
read_sessionkey(isc_mem_t *mctx, isc_log_t *lctx) {
|
read_sessionkey(isc_mem_t *mctx) {
|
||||||
cfg_parser_t *pctx = NULL;
|
cfg_parser_t *pctx = NULL;
|
||||||
cfg_obj_t *sessionkey = NULL;
|
cfg_obj_t *sessionkey = NULL;
|
||||||
const cfg_obj_t *key = NULL;
|
const cfg_obj_t *key = NULL;
|
||||||
@@ -576,7 +573,7 @@ read_sessionkey(isc_mem_t *mctx, isc_log_t *lctx) {
|
|||||||
return (ISC_R_FILENOTFOUND);
|
return (ISC_R_FILENOTFOUND);
|
||||||
}
|
}
|
||||||
|
|
||||||
result = cfg_parser_create(mctx, lctx, &pctx);
|
result = cfg_parser_create(mctx, &pctx);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
goto cleanup;
|
goto cleanup;
|
||||||
}
|
}
|
||||||
@@ -623,7 +620,7 @@ cleanup:
|
|||||||
}
|
}
|
||||||
|
|
||||||
static void
|
static void
|
||||||
setup_keyfile(isc_mem_t *mctx, isc_log_t *lctx) {
|
setup_keyfile(isc_mem_t *mctx) {
|
||||||
dst_key_t *dstkey = NULL;
|
dst_key_t *dstkey = NULL;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
dst_algorithm_t hmac_alg = DST_ALG_UNKNOWN;
|
dst_algorithm_t hmac_alg = DST_ALG_UNKNOWN;
|
||||||
@@ -640,7 +637,7 @@ setup_keyfile(isc_mem_t *mctx, isc_log_t *lctx) {
|
|||||||
|
|
||||||
/* If that didn't work, try reading it as a session.key keyfile */
|
/* If that didn't work, try reading it as a session.key keyfile */
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
result = read_sessionkey(mctx, lctx);
|
result = read_sessionkey(mctx);
|
||||||
if (result == ISC_R_SUCCESS) {
|
if (result == ISC_R_SUCCESS) {
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
@@ -813,15 +810,12 @@ setup_system(void *arg ISC_ATTR_UNUSED) {
|
|||||||
|
|
||||||
ddebug("setup_system()");
|
ddebug("setup_system()");
|
||||||
|
|
||||||
isc_log_create(gmctx, &glctx, &logconfig);
|
logconfig = isc_logconfig_get();
|
||||||
isc_log_setcontext(glctx);
|
isc_log_createandusechannel(logconfig, "debug", ISC_LOG_TOFILEDESC,
|
||||||
dns_log_init(glctx);
|
ISC_LOG_DYNAMIC, ISC_LOGDESTINATION_STDERR,
|
||||||
dns_log_setcontext(glctx);
|
ISC_LOG_PRINTTIME, ISC_LOGCATEGORY_DEFAULT,
|
||||||
|
ISC_LOGMODULE_DEFAULT);
|
||||||
result = isc_log_usechannel(logconfig, "default_debug", NULL, NULL);
|
isc_log_setdebuglevel(logdebuglevel);
|
||||||
check_result(result, "isc_log_usechannel");
|
|
||||||
|
|
||||||
isc_log_setdebuglevel(glctx, logdebuglevel);
|
|
||||||
|
|
||||||
result = irs_resconf_load(gmctx, resolvconf, &resconf);
|
result = irs_resconf_load(gmctx, resolvconf, &resconf);
|
||||||
if (result != ISC_R_SUCCESS && result != ISC_R_FILENOTFOUND) {
|
if (result != ISC_R_SUCCESS && result != ISC_R_FILENOTFOUND) {
|
||||||
@@ -926,10 +920,6 @@ setup_system(void *arg ISC_ATTR_UNUSED) {
|
|||||||
result = dns_dispatchmgr_create(gmctx, loopmgr, netmgr, &dispatchmgr);
|
result = dns_dispatchmgr_create(gmctx, loopmgr, netmgr, &dispatchmgr);
|
||||||
check_result(result, "dns_dispatchmgr_create");
|
check_result(result, "dns_dispatchmgr_create");
|
||||||
|
|
||||||
result = dst_lib_init(gmctx, NULL);
|
|
||||||
check_result(result, "dst_lib_init");
|
|
||||||
is_dst_up = true;
|
|
||||||
|
|
||||||
set_source_ports(dispatchmgr);
|
set_source_ports(dispatchmgr);
|
||||||
|
|
||||||
if (have_ipv6) {
|
if (have_ipv6) {
|
||||||
@@ -978,13 +968,13 @@ setup_system(void *arg ISC_ATTR_UNUSED) {
|
|||||||
if (keystr != NULL) {
|
if (keystr != NULL) {
|
||||||
setup_keystr();
|
setup_keystr();
|
||||||
} else if (local_only) {
|
} else if (local_only) {
|
||||||
result = read_sessionkey(gmctx, glctx);
|
result = read_sessionkey(gmctx);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("can't read key from %s: %s\n", keyfile,
|
fatal("can't read key from %s: %s\n", keyfile,
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
}
|
}
|
||||||
} else if (keyfile != NULL) {
|
} else if (keyfile != NULL) {
|
||||||
setup_keyfile(gmctx, glctx);
|
setup_keyfile(gmctx);
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_mutex_init(&answer_lock);
|
isc_mutex_init(&answer_lock);
|
||||||
@@ -3493,9 +3483,6 @@ cleanup(void) {
|
|||||||
}
|
}
|
||||||
#endif /* ifdef HAVE_GSSAPI */
|
#endif /* ifdef HAVE_GSSAPI */
|
||||||
|
|
||||||
ddebug("Removing log context");
|
|
||||||
isc_log_destroy(&glctx);
|
|
||||||
|
|
||||||
ddebug("Destroying memory context");
|
ddebug("Destroying memory context");
|
||||||
if (memdebugging) {
|
if (memdebugging) {
|
||||||
isc_mem_stats(gmctx, stderr);
|
isc_mem_stats(gmctx, stderr);
|
||||||
@@ -3503,12 +3490,6 @@ cleanup(void) {
|
|||||||
|
|
||||||
isc_mutex_destroy(&answer_lock);
|
isc_mutex_destroy(&answer_lock);
|
||||||
|
|
||||||
if (is_dst_up) {
|
|
||||||
ddebug("Destroy DST lib");
|
|
||||||
dst_lib_destroy();
|
|
||||||
is_dst_up = false;
|
|
||||||
}
|
|
||||||
|
|
||||||
ddebug("Shutting down managers");
|
ddebug("Shutting down managers");
|
||||||
isc_managers_destroy(&gmctx, &loopmgr, &netmgr);
|
isc_managers_destroy(&gmctx, &loopmgr, &netmgr);
|
||||||
}
|
}
|
||||||
|
|||||||
+15
-20
@@ -32,7 +32,6 @@
|
|||||||
#include <dns/acl.h>
|
#include <dns/acl.h>
|
||||||
#include <dns/db.h>
|
#include <dns/db.h>
|
||||||
#include <dns/enumtype.h>
|
#include <dns/enumtype.h>
|
||||||
#include <dns/log.h>
|
|
||||||
#include <dns/message.h>
|
#include <dns/message.h>
|
||||||
#include <dns/rdataset.h>
|
#include <dns/rdataset.h>
|
||||||
#include <dns/types.h>
|
#include <dns/types.h>
|
||||||
@@ -44,7 +43,6 @@
|
|||||||
|
|
||||||
#include <ns/client.h>
|
#include <ns/client.h>
|
||||||
#include <ns/hooks.h>
|
#include <ns/hooks.h>
|
||||||
#include <ns/log.h>
|
|
||||||
#include <ns/query.h>
|
#include <ns/query.h>
|
||||||
#include <ns/types.h>
|
#include <ns/types.h>
|
||||||
|
|
||||||
@@ -231,8 +229,7 @@ parse_filter_a_on(const cfg_obj_t *param_obj, const char *param_name,
|
|||||||
}
|
}
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
check_syntax(cfg_obj_t *fmap, const void *cfg, isc_mem_t *mctx, isc_log_t *lctx,
|
check_syntax(cfg_obj_t *fmap, const void *cfg, isc_mem_t *mctx, void *actx) {
|
||||||
void *actx) {
|
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
isc_result_t result = ISC_R_SUCCESS;
|
||||||
const cfg_obj_t *aclobj = NULL;
|
const cfg_obj_t *aclobj = NULL;
|
||||||
dns_acl_t *acl = NULL;
|
dns_acl_t *acl = NULL;
|
||||||
@@ -243,20 +240,20 @@ check_syntax(cfg_obj_t *fmap, const void *cfg, isc_mem_t *mctx, isc_log_t *lctx,
|
|||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
|
||||||
CHECK(cfg_acl_fromconfig(aclobj, (const cfg_obj_t *)cfg, lctx,
|
CHECK(cfg_acl_fromconfig(aclobj, (const cfg_obj_t *)cfg,
|
||||||
(cfg_aclconfctx_t *)actx, mctx, 0, &acl));
|
(cfg_aclconfctx_t *)actx, mctx, 0, &acl));
|
||||||
|
|
||||||
CHECK(parse_filter_a_on(fmap, "filter-a-on-v6", &f6));
|
CHECK(parse_filter_a_on(fmap, "filter-a-on-v6", &f6));
|
||||||
CHECK(parse_filter_a_on(fmap, "filter-a-on-v4", &f4));
|
CHECK(parse_filter_a_on(fmap, "filter-a-on-v4", &f4));
|
||||||
|
|
||||||
if ((f4 != NONE || f6 != NONE) && dns_acl_isnone(acl)) {
|
if ((f4 != NONE || f6 != NONE) && dns_acl_isnone(acl)) {
|
||||||
cfg_obj_log(aclobj, lctx, ISC_LOG_WARNING,
|
cfg_obj_log(aclobj, ISC_LOG_WARNING,
|
||||||
"\"filter-a\" is 'none;' but "
|
"\"filter-a\" is 'none;' but "
|
||||||
"either filter-a-on-v6 or filter-a-on-v4 "
|
"either filter-a-on-v6 or filter-a-on-v4 "
|
||||||
"is enabled");
|
"is enabled");
|
||||||
result = ISC_R_FAILURE;
|
result = ISC_R_FAILURE;
|
||||||
} else if (f4 == NONE && f6 == NONE && !dns_acl_isnone(acl)) {
|
} else if (f4 == NONE && f6 == NONE && !dns_acl_isnone(acl)) {
|
||||||
cfg_obj_log(aclobj, lctx, ISC_LOG_WARNING,
|
cfg_obj_log(aclobj, ISC_LOG_WARNING,
|
||||||
"\"filter-a\" is set but "
|
"\"filter-a\" is set but "
|
||||||
"neither filter-a-on-v6 or filter-a-on-v4 "
|
"neither filter-a-on-v6 or filter-a-on-v4 "
|
||||||
"is enabled");
|
"is enabled");
|
||||||
@@ -274,28 +271,28 @@ cleanup:
|
|||||||
static isc_result_t
|
static isc_result_t
|
||||||
parse_parameters(filter_instance_t *inst, const char *parameters,
|
parse_parameters(filter_instance_t *inst, const char *parameters,
|
||||||
const void *cfg, const char *cfg_file, unsigned long cfg_line,
|
const void *cfg, const char *cfg_file, unsigned long cfg_line,
|
||||||
isc_mem_t *mctx, isc_log_t *lctx, void *actx) {
|
isc_mem_t *mctx, void *actx) {
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
isc_result_t result = ISC_R_SUCCESS;
|
||||||
cfg_parser_t *parser = NULL;
|
cfg_parser_t *parser = NULL;
|
||||||
cfg_obj_t *param_obj = NULL;
|
cfg_obj_t *param_obj = NULL;
|
||||||
const cfg_obj_t *obj = NULL;
|
const cfg_obj_t *obj = NULL;
|
||||||
isc_buffer_t b;
|
isc_buffer_t b;
|
||||||
|
|
||||||
CHECK(cfg_parser_create(mctx, lctx, &parser));
|
CHECK(cfg_parser_create(mctx, &parser));
|
||||||
|
|
||||||
isc_buffer_constinit(&b, parameters, strlen(parameters));
|
isc_buffer_constinit(&b, parameters, strlen(parameters));
|
||||||
isc_buffer_add(&b, strlen(parameters));
|
isc_buffer_add(&b, strlen(parameters));
|
||||||
CHECK(cfg_parse_buffer(parser, &b, cfg_file, cfg_line,
|
CHECK(cfg_parse_buffer(parser, &b, cfg_file, cfg_line,
|
||||||
&cfg_type_parameters, 0, ¶m_obj));
|
&cfg_type_parameters, 0, ¶m_obj));
|
||||||
|
|
||||||
CHECK(check_syntax(param_obj, cfg, mctx, lctx, actx));
|
CHECK(check_syntax(param_obj, cfg, mctx, actx));
|
||||||
|
|
||||||
CHECK(parse_filter_a_on(param_obj, "filter-a-on-v6", &inst->v6_a));
|
CHECK(parse_filter_a_on(param_obj, "filter-a-on-v6", &inst->v6_a));
|
||||||
CHECK(parse_filter_a_on(param_obj, "filter-a-on-v4", &inst->v4_a));
|
CHECK(parse_filter_a_on(param_obj, "filter-a-on-v4", &inst->v4_a));
|
||||||
|
|
||||||
result = cfg_map_get(param_obj, "filter-a", &obj);
|
result = cfg_map_get(param_obj, "filter-a", &obj);
|
||||||
if (result == ISC_R_SUCCESS) {
|
if (result == ISC_R_SUCCESS) {
|
||||||
CHECK(cfg_acl_fromconfig(obj, (const cfg_obj_t *)cfg, lctx,
|
CHECK(cfg_acl_fromconfig(obj, (const cfg_obj_t *)cfg,
|
||||||
(cfg_aclconfctx_t *)actx, mctx, 0,
|
(cfg_aclconfctx_t *)actx, mctx, 0,
|
||||||
&inst->a_acl));
|
&inst->a_acl));
|
||||||
} else {
|
} else {
|
||||||
@@ -327,13 +324,12 @@ cleanup:
|
|||||||
*/
|
*/
|
||||||
isc_result_t
|
isc_result_t
|
||||||
plugin_register(const char *parameters, const void *cfg, const char *cfg_file,
|
plugin_register(const char *parameters, const void *cfg, const char *cfg_file,
|
||||||
unsigned long cfg_line, isc_mem_t *mctx, isc_log_t *lctx,
|
unsigned long cfg_line, isc_mem_t *mctx, void *actx,
|
||||||
void *actx, ns_hooktable_t *hooktable, void **instp) {
|
ns_hooktable_t *hooktable, void **instp) {
|
||||||
filter_instance_t *inst = NULL;
|
filter_instance_t *inst = NULL;
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
isc_result_t result = ISC_R_SUCCESS;
|
||||||
|
|
||||||
isc_log_write(lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_HOOKS,
|
isc_log_write(NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_HOOKS, ISC_LOG_INFO,
|
||||||
ISC_LOG_INFO,
|
|
||||||
"registering 'filter-a' "
|
"registering 'filter-a' "
|
||||||
"module from %s:%lu, %s parameters",
|
"module from %s:%lu, %s parameters",
|
||||||
cfg_file, cfg_line, parameters != NULL ? "with" : "no");
|
cfg_file, cfg_line, parameters != NULL ? "with" : "no");
|
||||||
@@ -344,7 +340,7 @@ plugin_register(const char *parameters, const void *cfg, const char *cfg_file,
|
|||||||
|
|
||||||
if (parameters != NULL) {
|
if (parameters != NULL) {
|
||||||
CHECK(parse_parameters(inst, parameters, cfg, cfg_file,
|
CHECK(parse_parameters(inst, parameters, cfg, cfg_file,
|
||||||
cfg_line, mctx, lctx, actx));
|
cfg_line, mctx, actx));
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_ht_init(&inst->ht, mctx, 1, ISC_HT_CASE_SENSITIVE);
|
isc_ht_init(&inst->ht, mctx, 1, ISC_HT_CASE_SENSITIVE);
|
||||||
@@ -367,21 +363,20 @@ cleanup:
|
|||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
plugin_check(const char *parameters, const void *cfg, const char *cfg_file,
|
plugin_check(const char *parameters, const void *cfg, const char *cfg_file,
|
||||||
unsigned long cfg_line, isc_mem_t *mctx, isc_log_t *lctx,
|
unsigned long cfg_line, isc_mem_t *mctx, void *actx) {
|
||||||
void *actx) {
|
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
isc_result_t result = ISC_R_SUCCESS;
|
||||||
cfg_parser_t *parser = NULL;
|
cfg_parser_t *parser = NULL;
|
||||||
cfg_obj_t *param_obj = NULL;
|
cfg_obj_t *param_obj = NULL;
|
||||||
isc_buffer_t b;
|
isc_buffer_t b;
|
||||||
|
|
||||||
CHECK(cfg_parser_create(mctx, lctx, &parser));
|
CHECK(cfg_parser_create(mctx, &parser));
|
||||||
|
|
||||||
isc_buffer_constinit(&b, parameters, strlen(parameters));
|
isc_buffer_constinit(&b, parameters, strlen(parameters));
|
||||||
isc_buffer_add(&b, strlen(parameters));
|
isc_buffer_add(&b, strlen(parameters));
|
||||||
CHECK(cfg_parse_buffer(parser, &b, cfg_file, cfg_line,
|
CHECK(cfg_parse_buffer(parser, &b, cfg_file, cfg_line,
|
||||||
&cfg_type_parameters, 0, ¶m_obj));
|
&cfg_type_parameters, 0, ¶m_obj));
|
||||||
|
|
||||||
CHECK(check_syntax(param_obj, cfg, mctx, lctx, actx));
|
CHECK(check_syntax(param_obj, cfg, mctx, actx));
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
if (param_obj != NULL) {
|
if (param_obj != NULL) {
|
||||||
|
|||||||
+15
-20
@@ -32,7 +32,6 @@
|
|||||||
#include <dns/acl.h>
|
#include <dns/acl.h>
|
||||||
#include <dns/db.h>
|
#include <dns/db.h>
|
||||||
#include <dns/enumtype.h>
|
#include <dns/enumtype.h>
|
||||||
#include <dns/log.h>
|
|
||||||
#include <dns/message.h>
|
#include <dns/message.h>
|
||||||
#include <dns/rdataset.h>
|
#include <dns/rdataset.h>
|
||||||
#include <dns/types.h>
|
#include <dns/types.h>
|
||||||
@@ -44,7 +43,6 @@
|
|||||||
|
|
||||||
#include <ns/client.h>
|
#include <ns/client.h>
|
||||||
#include <ns/hooks.h>
|
#include <ns/hooks.h>
|
||||||
#include <ns/log.h>
|
|
||||||
#include <ns/query.h>
|
#include <ns/query.h>
|
||||||
#include <ns/types.h>
|
#include <ns/types.h>
|
||||||
|
|
||||||
@@ -232,8 +230,7 @@ parse_filter_aaaa_on(const cfg_obj_t *param_obj, const char *param_name,
|
|||||||
}
|
}
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
check_syntax(cfg_obj_t *fmap, const void *cfg, isc_mem_t *mctx, isc_log_t *lctx,
|
check_syntax(cfg_obj_t *fmap, const void *cfg, isc_mem_t *mctx, void *actx) {
|
||||||
void *actx) {
|
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
isc_result_t result = ISC_R_SUCCESS;
|
||||||
const cfg_obj_t *aclobj = NULL;
|
const cfg_obj_t *aclobj = NULL;
|
||||||
dns_acl_t *acl = NULL;
|
dns_acl_t *acl = NULL;
|
||||||
@@ -244,20 +241,20 @@ check_syntax(cfg_obj_t *fmap, const void *cfg, isc_mem_t *mctx, isc_log_t *lctx,
|
|||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
|
||||||
CHECK(cfg_acl_fromconfig(aclobj, (const cfg_obj_t *)cfg, lctx,
|
CHECK(cfg_acl_fromconfig(aclobj, (const cfg_obj_t *)cfg,
|
||||||
(cfg_aclconfctx_t *)actx, mctx, 0, &acl));
|
(cfg_aclconfctx_t *)actx, mctx, 0, &acl));
|
||||||
|
|
||||||
CHECK(parse_filter_aaaa_on(fmap, "filter-aaaa-on-v4", &f4));
|
CHECK(parse_filter_aaaa_on(fmap, "filter-aaaa-on-v4", &f4));
|
||||||
CHECK(parse_filter_aaaa_on(fmap, "filter-aaaa-on-v6", &f6));
|
CHECK(parse_filter_aaaa_on(fmap, "filter-aaaa-on-v6", &f6));
|
||||||
|
|
||||||
if ((f4 != NONE || f6 != NONE) && dns_acl_isnone(acl)) {
|
if ((f4 != NONE || f6 != NONE) && dns_acl_isnone(acl)) {
|
||||||
cfg_obj_log(aclobj, lctx, ISC_LOG_WARNING,
|
cfg_obj_log(aclobj, ISC_LOG_WARNING,
|
||||||
"\"filter-aaaa\" is 'none;' but "
|
"\"filter-aaaa\" is 'none;' but "
|
||||||
"either filter-aaaa-on-v4 or filter-aaaa-on-v6 "
|
"either filter-aaaa-on-v4 or filter-aaaa-on-v6 "
|
||||||
"is enabled");
|
"is enabled");
|
||||||
result = ISC_R_FAILURE;
|
result = ISC_R_FAILURE;
|
||||||
} else if (f4 == NONE && f6 == NONE && !dns_acl_isnone(acl)) {
|
} else if (f4 == NONE && f6 == NONE && !dns_acl_isnone(acl)) {
|
||||||
cfg_obj_log(aclobj, lctx, ISC_LOG_WARNING,
|
cfg_obj_log(aclobj, ISC_LOG_WARNING,
|
||||||
"\"filter-aaaa\" is set but "
|
"\"filter-aaaa\" is set but "
|
||||||
"neither filter-aaaa-on-v4 or filter-aaaa-on-v6 "
|
"neither filter-aaaa-on-v4 or filter-aaaa-on-v6 "
|
||||||
"is enabled");
|
"is enabled");
|
||||||
@@ -275,21 +272,21 @@ cleanup:
|
|||||||
static isc_result_t
|
static isc_result_t
|
||||||
parse_parameters(filter_instance_t *inst, const char *parameters,
|
parse_parameters(filter_instance_t *inst, const char *parameters,
|
||||||
const void *cfg, const char *cfg_file, unsigned long cfg_line,
|
const void *cfg, const char *cfg_file, unsigned long cfg_line,
|
||||||
isc_mem_t *mctx, isc_log_t *lctx, void *actx) {
|
isc_mem_t *mctx, void *actx) {
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
isc_result_t result = ISC_R_SUCCESS;
|
||||||
cfg_parser_t *parser = NULL;
|
cfg_parser_t *parser = NULL;
|
||||||
cfg_obj_t *param_obj = NULL;
|
cfg_obj_t *param_obj = NULL;
|
||||||
const cfg_obj_t *obj = NULL;
|
const cfg_obj_t *obj = NULL;
|
||||||
isc_buffer_t b;
|
isc_buffer_t b;
|
||||||
|
|
||||||
CHECK(cfg_parser_create(mctx, lctx, &parser));
|
CHECK(cfg_parser_create(mctx, &parser));
|
||||||
|
|
||||||
isc_buffer_constinit(&b, parameters, strlen(parameters));
|
isc_buffer_constinit(&b, parameters, strlen(parameters));
|
||||||
isc_buffer_add(&b, strlen(parameters));
|
isc_buffer_add(&b, strlen(parameters));
|
||||||
CHECK(cfg_parse_buffer(parser, &b, cfg_file, cfg_line,
|
CHECK(cfg_parse_buffer(parser, &b, cfg_file, cfg_line,
|
||||||
&cfg_type_parameters, 0, ¶m_obj));
|
&cfg_type_parameters, 0, ¶m_obj));
|
||||||
|
|
||||||
CHECK(check_syntax(param_obj, cfg, mctx, lctx, actx));
|
CHECK(check_syntax(param_obj, cfg, mctx, actx));
|
||||||
|
|
||||||
CHECK(parse_filter_aaaa_on(param_obj, "filter-aaaa-on-v4",
|
CHECK(parse_filter_aaaa_on(param_obj, "filter-aaaa-on-v4",
|
||||||
&inst->v4_aaaa));
|
&inst->v4_aaaa));
|
||||||
@@ -298,7 +295,7 @@ parse_parameters(filter_instance_t *inst, const char *parameters,
|
|||||||
|
|
||||||
result = cfg_map_get(param_obj, "filter-aaaa", &obj);
|
result = cfg_map_get(param_obj, "filter-aaaa", &obj);
|
||||||
if (result == ISC_R_SUCCESS) {
|
if (result == ISC_R_SUCCESS) {
|
||||||
CHECK(cfg_acl_fromconfig(obj, (const cfg_obj_t *)cfg, lctx,
|
CHECK(cfg_acl_fromconfig(obj, (const cfg_obj_t *)cfg,
|
||||||
(cfg_aclconfctx_t *)actx, mctx, 0,
|
(cfg_aclconfctx_t *)actx, mctx, 0,
|
||||||
&inst->aaaa_acl));
|
&inst->aaaa_acl));
|
||||||
} else {
|
} else {
|
||||||
@@ -330,13 +327,12 @@ cleanup:
|
|||||||
*/
|
*/
|
||||||
isc_result_t
|
isc_result_t
|
||||||
plugin_register(const char *parameters, const void *cfg, const char *cfg_file,
|
plugin_register(const char *parameters, const void *cfg, const char *cfg_file,
|
||||||
unsigned long cfg_line, isc_mem_t *mctx, isc_log_t *lctx,
|
unsigned long cfg_line, isc_mem_t *mctx, void *actx,
|
||||||
void *actx, ns_hooktable_t *hooktable, void **instp) {
|
ns_hooktable_t *hooktable, void **instp) {
|
||||||
filter_instance_t *inst = NULL;
|
filter_instance_t *inst = NULL;
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
isc_result_t result = ISC_R_SUCCESS;
|
||||||
|
|
||||||
isc_log_write(lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_HOOKS,
|
isc_log_write(NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_HOOKS, ISC_LOG_INFO,
|
||||||
ISC_LOG_INFO,
|
|
||||||
"registering 'filter-aaaa' "
|
"registering 'filter-aaaa' "
|
||||||
"module from %s:%lu, %s parameters",
|
"module from %s:%lu, %s parameters",
|
||||||
cfg_file, cfg_line, parameters != NULL ? "with" : "no");
|
cfg_file, cfg_line, parameters != NULL ? "with" : "no");
|
||||||
@@ -348,7 +344,7 @@ plugin_register(const char *parameters, const void *cfg, const char *cfg_file,
|
|||||||
|
|
||||||
if (parameters != NULL) {
|
if (parameters != NULL) {
|
||||||
CHECK(parse_parameters(inst, parameters, cfg, cfg_file,
|
CHECK(parse_parameters(inst, parameters, cfg, cfg_file,
|
||||||
cfg_line, mctx, lctx, actx));
|
cfg_line, mctx, actx));
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_ht_init(&inst->ht, mctx, 1, ISC_HT_CASE_SENSITIVE);
|
isc_ht_init(&inst->ht, mctx, 1, ISC_HT_CASE_SENSITIVE);
|
||||||
@@ -371,21 +367,20 @@ cleanup:
|
|||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
plugin_check(const char *parameters, const void *cfg, const char *cfg_file,
|
plugin_check(const char *parameters, const void *cfg, const char *cfg_file,
|
||||||
unsigned long cfg_line, isc_mem_t *mctx, isc_log_t *lctx,
|
unsigned long cfg_line, isc_mem_t *mctx, void *actx) {
|
||||||
void *actx) {
|
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
isc_result_t result = ISC_R_SUCCESS;
|
||||||
cfg_parser_t *parser = NULL;
|
cfg_parser_t *parser = NULL;
|
||||||
cfg_obj_t *param_obj = NULL;
|
cfg_obj_t *param_obj = NULL;
|
||||||
isc_buffer_t b;
|
isc_buffer_t b;
|
||||||
|
|
||||||
CHECK(cfg_parser_create(mctx, lctx, &parser));
|
CHECK(cfg_parser_create(mctx, &parser));
|
||||||
|
|
||||||
isc_buffer_constinit(&b, parameters, strlen(parameters));
|
isc_buffer_constinit(&b, parameters, strlen(parameters));
|
||||||
isc_buffer_add(&b, strlen(parameters));
|
isc_buffer_add(&b, strlen(parameters));
|
||||||
CHECK(cfg_parse_buffer(parser, &b, cfg_file, cfg_line,
|
CHECK(cfg_parse_buffer(parser, &b, cfg_file, cfg_line,
|
||||||
&cfg_type_parameters, 0, ¶m_obj));
|
&cfg_type_parameters, 0, ¶m_obj));
|
||||||
|
|
||||||
CHECK(check_syntax(param_obj, cfg, mctx, lctx, actx));
|
CHECK(check_syntax(param_obj, cfg, mctx, actx));
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
if (param_obj != NULL) {
|
if (param_obj != NULL) {
|
||||||
|
|||||||
+14
-21
@@ -87,7 +87,7 @@ static int32_t timeout = RNDC_TIMEOUT;
|
|||||||
static void
|
static void
|
||||||
rndc_startconnect(isc_sockaddr_t *addr);
|
rndc_startconnect(isc_sockaddr_t *addr);
|
||||||
|
|
||||||
noreturn static void
|
ISC_NORETURN static void
|
||||||
usage(int status);
|
usage(int status);
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -132,6 +132,9 @@ command is one of the following:\n\
|
|||||||
halt Stop the server without saving pending updates.\n\
|
halt Stop the server without saving pending updates.\n\
|
||||||
halt -p Stop the server without saving pending updates reporting\n\
|
halt -p Stop the server without saving pending updates reporting\n\
|
||||||
process id.\n\
|
process id.\n\
|
||||||
|
skr -import file zone [class [view]]\n\
|
||||||
|
Import a SKR file for the specified zone, for offline KSK\n\
|
||||||
|
signing.\n\
|
||||||
loadkeys zone [class [view]]\n\
|
loadkeys zone [class [view]]\n\
|
||||||
Update keys without signing immediately.\n\
|
Update keys without signing immediately.\n\
|
||||||
managed-keys refresh [class [view]]\n\
|
managed-keys refresh [class [view]]\n\
|
||||||
@@ -526,8 +529,8 @@ rndc_start(void *arg) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
static void
|
static void
|
||||||
parse_config(isc_mem_t *mctx, isc_log_t *log, const char *keyname,
|
parse_config(isc_mem_t *mctx, const char *keyname, cfg_parser_t **pctxp,
|
||||||
cfg_parser_t **pctxp, cfg_obj_t **configp) {
|
cfg_obj_t **configp) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
const char *conffile = admin_conffile;
|
const char *conffile = admin_conffile;
|
||||||
const cfg_obj_t *addresses = NULL;
|
const cfg_obj_t *addresses = NULL;
|
||||||
@@ -570,7 +573,7 @@ parse_config(isc_mem_t *mctx, isc_log_t *log, const char *keyname,
|
|||||||
admin_keyfile, admin_conffile);
|
admin_keyfile, admin_conffile);
|
||||||
}
|
}
|
||||||
|
|
||||||
DO("create parser", cfg_parser_create(mctx, log, pctxp));
|
DO("create parser", cfg_parser_create(mctx, pctxp));
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* The parser will output its own errors, so DO() is not used.
|
* The parser will output its own errors, so DO() is not used.
|
||||||
@@ -806,9 +809,7 @@ int
|
|||||||
main(int argc, char **argv) {
|
main(int argc, char **argv) {
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
isc_result_t result = ISC_R_SUCCESS;
|
||||||
bool show_final_mem = false;
|
bool show_final_mem = false;
|
||||||
isc_log_t *log = NULL;
|
|
||||||
isc_logconfig_t *logconfig = NULL;
|
isc_logconfig_t *logconfig = NULL;
|
||||||
isc_logdestination_t logdest;
|
|
||||||
cfg_parser_t *pctx = NULL;
|
cfg_parser_t *pctx = NULL;
|
||||||
cfg_obj_t *config = NULL;
|
cfg_obj_t *config = NULL;
|
||||||
const char *keyname = NULL;
|
const char *keyname = NULL;
|
||||||
@@ -954,20 +955,15 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
isc_nm_settimeouts(netmgr, timeout, timeout, timeout, 0);
|
isc_nm_settimeouts(netmgr, timeout, timeout, timeout, 0);
|
||||||
|
|
||||||
isc_log_create(rndc_mctx, &log, &logconfig);
|
logconfig = isc_logconfig_get();
|
||||||
isc_log_setcontext(log);
|
|
||||||
isc_log_settag(logconfig, progname);
|
isc_log_settag(logconfig, progname);
|
||||||
logdest.file.stream = stderr;
|
isc_log_createandusechannel(
|
||||||
logdest.file.name = NULL;
|
logconfig, "default_stderr", ISC_LOG_TOFILEDESC, ISC_LOG_INFO,
|
||||||
logdest.file.versions = ISC_LOG_ROLLNEVER;
|
ISC_LOGDESTINATION_STDERR,
|
||||||
logdest.file.maximum_size = 0;
|
ISC_LOG_PRINTTAG | ISC_LOG_PRINTLEVEL, ISC_LOGCATEGORY_DEFAULT,
|
||||||
isc_log_createchannel(logconfig, "stderr", ISC_LOG_TOFILEDESC,
|
ISC_LOGMODULE_DEFAULT);
|
||||||
ISC_LOG_INFO, &logdest,
|
|
||||||
ISC_LOG_PRINTTAG | ISC_LOG_PRINTLEVEL);
|
|
||||||
DO("enabling log channel",
|
|
||||||
isc_log_usechannel(logconfig, "stderr", NULL, NULL));
|
|
||||||
|
|
||||||
parse_config(rndc_mctx, log, keyname, &pctx, &config);
|
parse_config(rndc_mctx, keyname, &pctx, &config);
|
||||||
|
|
||||||
isc_buffer_allocate(rndc_mctx, &databuf, 2048);
|
isc_buffer_allocate(rndc_mctx, &databuf, 2048);
|
||||||
|
|
||||||
@@ -1003,9 +999,6 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
isccc_ccmsg_invalidate(&rndc_ccmsg);
|
isccc_ccmsg_invalidate(&rndc_ccmsg);
|
||||||
|
|
||||||
isc_log_destroy(&log);
|
|
||||||
isc_log_setcontext(NULL);
|
|
||||||
|
|
||||||
cfg_obj_destroy(pctx, &config);
|
cfg_obj_destroy(pctx, &config);
|
||||||
cfg_parser_destroy(&pctx);
|
cfg_parser_destroy(&pctx);
|
||||||
|
|
||||||
|
|||||||
+18
-2
@@ -152,6 +152,15 @@ Currently supported commands are:
|
|||||||
|
|
||||||
See also :option:`rndc delzone` and :option:`rndc modzone`.
|
See also :option:`rndc delzone` and :option:`rndc modzone`.
|
||||||
|
|
||||||
|
.. option:: closelogs
|
||||||
|
|
||||||
|
This command closes currently open log files. It is intended to be used
|
||||||
|
by external log rotation tools following this proceedure.
|
||||||
|
|
||||||
|
1) rename the log files
|
||||||
|
2) run ``rndc closelogs``
|
||||||
|
3) optionally compress the log files
|
||||||
|
|
||||||
.. option:: delzone [-clean] zone [class [view]]
|
.. option:: delzone [-clean] zone [class [view]]
|
||||||
|
|
||||||
This command deletes a zone while the server is running.
|
This command deletes a zone while the server is running.
|
||||||
@@ -257,6 +266,11 @@ Currently supported commands are:
|
|||||||
|
|
||||||
See also :option:`rndc stop`.
|
See also :option:`rndc stop`.
|
||||||
|
|
||||||
|
.. option:: skr -import file zone [class [view]]
|
||||||
|
|
||||||
|
This command allows you to import a SKR file for the specified zone, to
|
||||||
|
support offline KSK signing.
|
||||||
|
|
||||||
.. option:: loadkeys [zone [class [view]]]
|
.. option:: loadkeys [zone [class [view]]]
|
||||||
|
|
||||||
This command fetches all DNSSEC keys for the given zone from the key directory. If
|
This command fetches all DNSSEC keys for the given zone from the key directory. If
|
||||||
@@ -444,14 +458,16 @@ Currently supported commands are:
|
|||||||
|
|
||||||
.. program:: rndc
|
.. program:: rndc
|
||||||
|
|
||||||
.. option:: retransfer zone [class [view]]
|
.. option:: retransfer [-force] zone [class [view]]
|
||||||
|
|
||||||
This command retransfers the given secondary zone from the primary server.
|
This command retransfers the given secondary zone from the primary server.
|
||||||
|
|
||||||
If the zone is configured to use ``inline-signing``, the signed
|
If the zone is configured to use ``inline-signing``, the signed
|
||||||
version of the zone is discarded; after the retransfer of the
|
version of the zone is discarded; after the retransfer of the
|
||||||
unsigned version is complete, the signed version is regenerated
|
unsigned version is complete, the signed version is regenerated
|
||||||
with new signatures.
|
with new signatures. With the optional ``-force`` argument provided
|
||||||
|
if there is an ongoing zone transfer it will be aborted before a new zone
|
||||||
|
transfer is scheduled.
|
||||||
|
|
||||||
.. option:: scan
|
.. option:: scan
|
||||||
|
|
||||||
|
|||||||
+1
-1
@@ -36,7 +36,7 @@ ISC_LANG_BEGINDECLS
|
|||||||
void
|
void
|
||||||
notify(const char *fmt, ...) ISC_FORMAT_PRINTF(1, 2);
|
notify(const char *fmt, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||||
|
|
||||||
noreturn void
|
ISC_NORETURN void
|
||||||
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||||
|
|
||||||
ISC_LANG_ENDDECLS
|
ISC_LANG_ENDDECLS
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
#!/usr/bin/env python
|
#!/usr/bin/env python3
|
||||||
#
|
#
|
||||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
|
|||||||
@@ -9,6 +9,7 @@ named.lock
|
|||||||
named.pid
|
named.pid
|
||||||
named.run
|
named.run
|
||||||
/feature-test
|
/feature-test
|
||||||
|
/legacy.run.sh
|
||||||
/makejournal
|
/makejournal
|
||||||
/random.data
|
/random.data
|
||||||
/*.log
|
/*.log
|
||||||
|
|||||||
@@ -95,8 +95,8 @@ TESTS = \
|
|||||||
checknames \
|
checknames \
|
||||||
checkzone \
|
checkzone \
|
||||||
cookie \
|
cookie \
|
||||||
|
cpu \
|
||||||
database \
|
database \
|
||||||
dialup \
|
|
||||||
digdelv \
|
digdelv \
|
||||||
dispatch \
|
dispatch \
|
||||||
dlzexternal \
|
dlzexternal \
|
||||||
|
|||||||
@@ -157,10 +157,7 @@ $DSFROMKEY $ksk.key >dsset-${zone}.
|
|||||||
# None of these algorithms are supported for signing in FIPS mode
|
# None of these algorithms are supported for signing in FIPS mode
|
||||||
# as they are MD5 and SHA1 based.
|
# as they are MD5 and SHA1 based.
|
||||||
#
|
#
|
||||||
if (
|
if [ $RSASHA1_SUPPORTED = 1 ]; then
|
||||||
cd ..
|
|
||||||
$SHELL ../testcrypto.sh -q RSASHA1
|
|
||||||
); then
|
|
||||||
setup nsec-only.example
|
setup nsec-only.example
|
||||||
cp $infile $zonefile
|
cp $infile $zonefile
|
||||||
ksk=$($KEYGEN -q -a RSASHA1 -fk $zone 2>kg.out) || dumpit kg.out
|
ksk=$($KEYGEN -q -a RSASHA1 -fk $zone 2>kg.out) || dumpit kg.out
|
||||||
|
|||||||
@@ -892,7 +892,7 @@ checkprivate nsec3.nsec3.example 10.53.0.3 || ret=1
|
|||||||
checkprivate nsec3.optout.example 10.53.0.3 || ret=1
|
checkprivate nsec3.optout.example 10.53.0.3 || ret=1
|
||||||
checkprivate nsec3-to-nsec.example 10.53.0.3 2 || ret=1 # automatically removed
|
checkprivate nsec3-to-nsec.example 10.53.0.3 2 || ret=1 # automatically removed
|
||||||
checkprivate nsec3-to-nsec3.example 10.53.0.3 2 || ret=1 # automatically removed
|
checkprivate nsec3-to-nsec3.example 10.53.0.3 2 || ret=1 # automatically removed
|
||||||
if $SHELL ../testcrypto.sh -q RSASHA1; then
|
if [ $RSASHA1_SUPPORTED = 1 ]; then
|
||||||
checkprivate nsec-only.example 10.53.0.3 || ret=1
|
checkprivate nsec-only.example 10.53.0.3 || ret=1
|
||||||
fi
|
fi
|
||||||
checkprivate oldsigs.example 10.53.0.3 2 || ret=1 # pre-signed
|
checkprivate oldsigs.example 10.53.0.3 2 || ret=1 # pre-signed
|
||||||
@@ -1252,7 +1252,7 @@ del=$(grep "DNSKEY .* is now deleted" ns2/named.run | wc -l)
|
|||||||
[ "$del" -eq 0 ] || ret=1
|
[ "$del" -eq 0 ] || ret=1
|
||||||
pub=$(grep "DNSKEY .* is now published" ns3/named.run | grep -v "CDNSKEY" | wc -l)
|
pub=$(grep "DNSKEY .* is now published" ns3/named.run | grep -v "CDNSKEY" | wc -l)
|
||||||
act=$(grep "DNSKEY .* is now active" ns3/named.run | wc -l)
|
act=$(grep "DNSKEY .* is now active" ns3/named.run | wc -l)
|
||||||
if $SHELL ../testcrypto.sh -q RSASHA1; then
|
if [ $RSASHA1_SUPPORTED = 1 ]; then
|
||||||
# Include two log lines for nsec-only zone.
|
# Include two log lines for nsec-only zone.
|
||||||
[ "$pub" -eq 53 ] || ret=1
|
[ "$pub" -eq 53 ] || ret=1
|
||||||
[ "$act" -eq 53 ] || ret=1
|
[ "$act" -eq 53 ] || ret=1
|
||||||
|
|||||||
@@ -29,6 +29,7 @@ options {
|
|||||||
notify no;
|
notify no;
|
||||||
notify-delay 0;
|
notify-delay 0;
|
||||||
recursion no;
|
recursion no;
|
||||||
|
#T5 allow-query { 10.53.0.99; };
|
||||||
serial-query-rate 100;
|
serial-query-rate 100;
|
||||||
dnssec-validation no;
|
dnssec-validation no;
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -702,6 +702,23 @@ wait_for_soa @10.53.0.2 dom3.example. dig.out.test$n || ret=1
|
|||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|
||||||
|
# GL #4733
|
||||||
|
n=$((n + 1))
|
||||||
|
echo_i "reconfiguring secondary - checking if catz member zones are reconfigured ($n)"
|
||||||
|
ret=0
|
||||||
|
sed -e "s/^#T5//" <ns2/named1.conf.in >ns2/named.conf.tmp
|
||||||
|
copy_setports ns2/named.conf.tmp ns2/named.conf
|
||||||
|
rndccmd 10.53.0.2 reconfig || ret=1
|
||||||
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
|
status=$((status + ret))
|
||||||
|
|
||||||
|
n=$((n + 1))
|
||||||
|
echo_i "checking that dom3.example. is refused by secondary because of an activated allow-query ($n)"
|
||||||
|
ret=0
|
||||||
|
wait_for_no_soa @10.53.0.2 dom3.example. dig.out.test$n || ret=1
|
||||||
|
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||||
|
status=$((status + ret))
|
||||||
|
|
||||||
n=$((n + 1))
|
n=$((n + 1))
|
||||||
echo_i "reconfiguring secondary - reverting the bad configuration ($n)"
|
echo_i "reconfiguring secondary - reverting the bad configuration ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
|
|||||||
@@ -37,11 +37,28 @@ key rndc_key {
|
|||||||
algorithm @DEFAULT_HMAC@;
|
algorithm @DEFAULT_HMAC@;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
key restart16 {
|
||||||
|
secret "1234abcd8765";
|
||||||
|
algorithm @DEFAULT_HMAC@;
|
||||||
|
};
|
||||||
|
|
||||||
controls {
|
controls {
|
||||||
inet 10.53.0.7 port @CONTROLPORT@ allow { any; } keys { rndc_key; };
|
inet 10.53.0.7 port @CONTROLPORT@ allow { any; } keys { rndc_key; };
|
||||||
};
|
};
|
||||||
|
|
||||||
zone "." {
|
view restart16 {
|
||||||
type hint;
|
match-clients { key restart16; none; };
|
||||||
file "root.hint";
|
max-query-restarts 16;
|
||||||
|
|
||||||
|
zone "." {
|
||||||
|
type hint;
|
||||||
|
file "root.hint";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
view default {
|
||||||
|
zone "." {
|
||||||
|
type hint;
|
||||||
|
file "root.hint";
|
||||||
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -439,12 +439,24 @@ if [ $ret != 0 ]; then echo_i "failed"; fi
|
|||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|
||||||
n=$((n + 1))
|
n=$((n + 1))
|
||||||
echo_i "checking CNAME loops are detected ($n)"
|
echo_i "checking CNAME loops are detected (resolver) ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
$RNDCCMD 10.53.0.7 null --- start test$n --- 2>&1 | sed 's/^/ns7 /' | cat_i
|
$RNDCCMD 10.53.0.7 null --- start test$n --- 2>&1 | sed 's/^/ns7 /' | cat_i
|
||||||
$DIG $DIGOPTS @10.53.0.7 loop.example >dig.out.test$n
|
$DIG $DIGOPTS @10.53.0.7 loop.example >dig.out.1.test$n
|
||||||
grep "status: NOERROR" dig.out.test$n >/dev/null || ret=1
|
grep "status: NOERROR" dig.out.1.test$n >/dev/null || ret=1
|
||||||
grep "ANSWER: 17" dig.out.test$n >/dev/null || ret=1
|
grep "ANSWER: 12" dig.out.1.test$n >/dev/null || ret=1
|
||||||
|
# also check with max-query-restarts 16:
|
||||||
|
$DIG $DIGOPTS @10.53.0.7 -y "${DEFAULT_HMAC}:restart16:1234abcd8765" loop.example >dig.out.2.test$n
|
||||||
|
grep "status: NOERROR" dig.out.2.test$n >/dev/null || ret=1
|
||||||
|
grep "ANSWER: 17" dig.out.2.test$n >/dev/null || ret=1
|
||||||
|
|
||||||
|
n=$((n + 1))
|
||||||
|
echo_i "checking CNAME loops are detected (auth) ($n)"
|
||||||
|
ret=0
|
||||||
|
$DIG $DIGOPTS @10.53.0.2 loop.example >dig.out.test$n
|
||||||
|
grep "status: SERVFAIL" dig.out.test$n >/dev/null || ret=1
|
||||||
|
grep "max. restarts reached" dig.out.test$n >/dev/null || ret=1
|
||||||
|
grep "ANSWER: 12" dig.out.test$n >/dev/null || ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status + ret))
|
status=$((status + ret))
|
||||||
|
|
||||||
|
|||||||
+4
-7
@@ -11,12 +11,9 @@
|
|||||||
* information regarding copyright ownership.
|
* information regarding copyright ownership.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Ancient options are fatal.
|
||||||
|
*/
|
||||||
options {
|
options {
|
||||||
avoid-v4-udp-ports {
|
avoid-v4-udp-ports { range 1 1023; };
|
||||||
1935;
|
|
||||||
2605;
|
|
||||||
4321;
|
|
||||||
6514;
|
|
||||||
range 8610 8614;
|
|
||||||
};
|
|
||||||
};
|
};
|
||||||
+4
-21
@@ -11,26 +11,9 @@
|
|||||||
* information regarding copyright ownership.
|
* information regarding copyright ownership.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
controls { /* empty */ };
|
/*
|
||||||
|
* Ancient options are fatal.
|
||||||
|
*/
|
||||||
options {
|
options {
|
||||||
query-source address 10.53.0.2;
|
avoid-v6-udp-ports { range 1 1023; };
|
||||||
notify-source 10.53.0.2;
|
|
||||||
transfer-source 10.53.0.2;
|
|
||||||
port 5300;
|
|
||||||
pid-file "named.pid";
|
|
||||||
listen-on { 10.53.0.2; };
|
|
||||||
listen-on-v6 { none; };
|
|
||||||
heartbeat-interval 2;
|
|
||||||
recursion no;
|
|
||||||
};
|
|
||||||
zone "." {
|
|
||||||
type hint;
|
|
||||||
file "hint";
|
|
||||||
};
|
|
||||||
zone "example." {
|
|
||||||
type stub;
|
|
||||||
dialup notify;
|
|
||||||
notify no;
|
|
||||||
file "example.bk";
|
|
||||||
// primaries { 10.53.0.1; };
|
|
||||||
};
|
};
|
||||||
+1
-5
@@ -11,12 +11,8 @@
|
|||||||
* information regarding copyright ownership.
|
* information regarding copyright ownership.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
options {
|
|
||||||
port 5300;
|
|
||||||
};
|
|
||||||
|
|
||||||
zone example {
|
zone example {
|
||||||
type secondary;
|
type secondary;
|
||||||
primaries { 1.2.3.4; };
|
primaries { 1.2.3.4; };
|
||||||
notify-source 10.53.0.1 port 100;
|
notify-source 10.53.0.1 port 5300;
|
||||||
};
|
};
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: MPL-2.0
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
server 1.2.3.4 {
|
||||||
|
query-source 10.10.10.10 port 5353;
|
||||||
|
};
|
||||||
+4
-25
@@ -11,30 +11,9 @@
|
|||||||
* information regarding copyright ownership.
|
* information regarding copyright ownership.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
controls { /* empty */ };
|
/*
|
||||||
|
* Ancient options are fatal.
|
||||||
|
*/
|
||||||
options {
|
options {
|
||||||
query-source address 10.53.0.3;
|
use-v4-udp-ports { range 1024 65535; };
|
||||||
notify-source 10.53.0.3;
|
|
||||||
transfer-source 10.53.0.3;
|
|
||||||
port @PORT@;
|
|
||||||
pid-file "named.pid";
|
|
||||||
listen-on { 10.53.0.3; };
|
|
||||||
listen-on-v6 { none; };
|
|
||||||
heartbeat-interval 1;
|
|
||||||
recursion no;
|
|
||||||
dnssec-validation no;
|
|
||||||
};
|
|
||||||
|
|
||||||
zone "." {
|
|
||||||
type hint;
|
|
||||||
file "hint.db";
|
|
||||||
};
|
|
||||||
|
|
||||||
zone "example." {
|
|
||||||
type secondary;
|
|
||||||
dialup refresh;
|
|
||||||
notify no;
|
|
||||||
file "example.bk";
|
|
||||||
primaries { 10.53.0.2; };
|
|
||||||
};
|
};
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: MPL-2.0
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Ancient options are fatal.
|
||||||
|
*/
|
||||||
|
options {
|
||||||
|
use-v6-udp-ports { range 1024 65535; };
|
||||||
|
};
|
||||||
@@ -16,4 +16,9 @@
|
|||||||
*/
|
*/
|
||||||
options {
|
options {
|
||||||
fake-iquery yes;
|
fake-iquery yes;
|
||||||
|
|
||||||
|
use-v4-udp-ports { range 1024 65535; };
|
||||||
|
use-v6-udp-ports { range 1024 65535; };
|
||||||
|
avoid-v4-udp-ports { range 1 1023; };
|
||||||
|
avoid-v6-udp-ports { range 1 1023; };
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -0,0 +1,18 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: MPL-2.0
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
dnssec-policy reverse-order {
|
||||||
|
keys {
|
||||||
|
csk lifetime unlimited algorithm rsasha256 tag-range 32767 0 2048;
|
||||||
|
};
|
||||||
|
};
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: MPL-2.0
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
dnssec-policy too-big-start {
|
||||||
|
keys {
|
||||||
|
csk lifetime unlimited algorithm rsasha256 tag-range 65536 0 2048;
|
||||||
|
};
|
||||||
|
};
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: MPL-2.0
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
dnssec-policy too-big-end {
|
||||||
|
keys {
|
||||||
|
csk lifetime unlimited algorithm rsasha256 tag-range 0 65536 2048;
|
||||||
|
};
|
||||||
|
};
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: MPL-2.0
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
dnssec-policy start-equals-end {
|
||||||
|
keys {
|
||||||
|
csk lifetime unlimited algorithm rsasha256 tag-range 0 0 2048;
|
||||||
|
};
|
||||||
|
};
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: MPL-2.0
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
/*
|
||||||
|
* request-ixfr clause is not allowed in zone of type primary.
|
||||||
|
*/
|
||||||
|
|
||||||
|
zone dummy {
|
||||||
|
type primary;
|
||||||
|
request-ixfr-max-diffs 100;
|
||||||
|
file "xxxx";
|
||||||
|
};
|
||||||
@@ -11,22 +11,10 @@
|
|||||||
* information regarding copyright ownership.
|
* information regarding copyright ownership.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
server 1.2.3.4 {
|
|
||||||
query-source 10.10.10.10 port 5353;
|
|
||||||
};
|
|
||||||
|
|
||||||
options {
|
options {
|
||||||
dnssec-validation yes;
|
dnssec-validation yes;
|
||||||
max-zone-ttl 600;
|
max-zone-ttl 600;
|
||||||
|
|
||||||
dialup yes;
|
|
||||||
heartbeat-interval 60;
|
|
||||||
|
|
||||||
use-v4-udp-ports { range 1024 65535; };
|
|
||||||
use-v6-udp-ports { range 1024 65535; };
|
|
||||||
avoid-v4-udp-ports { range 1 1023; };
|
|
||||||
avoid-v6-udp-ports { range 1 1023; };
|
|
||||||
|
|
||||||
dnssec-must-be-secure mustbesecure.example yes;
|
dnssec-must-be-secure mustbesecure.example yes;
|
||||||
|
|
||||||
sortlist { };
|
sortlist { };
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user