Compare commits
1264
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ebe2d5a7c4 | ||
|
|
ed52fa4b5c | ||
|
|
01c428ba9b | ||
|
|
d52223bb46 | ||
|
|
8bb1cafc41 | ||
|
|
486c46fc4a | ||
|
|
815d262772 | ||
|
|
4bc9225347 | ||
|
|
b92267d550 | ||
|
|
04ede92bfb | ||
|
|
6346ab5f33 | ||
|
|
719feaeb75 | ||
|
|
718764e219 | ||
|
|
6e7ac05d83 | ||
|
|
418997429f | ||
|
|
27e0271e84 | ||
|
|
28580b7746 | ||
|
|
40cf3a243e | ||
|
|
66a4f92adf | ||
|
|
88d632d262 | ||
|
|
7d7c33d5d5 | ||
|
|
2d27e6f0a1 | ||
|
|
368659f669 | ||
|
|
8511a94ad1 | ||
|
|
aabb65d542 | ||
|
|
982b29bcca | ||
|
|
f5caf976d7 | ||
|
|
0c4543e12b | ||
|
|
7b87fd35b8 | ||
|
|
ca0dfdcad0 | ||
|
|
0e2a65d51f | ||
|
|
ad51e63b6b | ||
|
|
8dcf43a66b | ||
|
|
3ac01535e0 | ||
|
|
a0007b7ce4 | ||
|
|
f8a7f274e0 | ||
|
|
c56a88ec07 | ||
|
|
7ecbfb6c0f | ||
|
|
418b9e4549 | ||
|
|
510dca6f52 | ||
|
|
8ef7b7f3f6 | ||
|
|
4bbc0f1871 | ||
|
|
538a0a40a2 | ||
|
|
f8c849e224 | ||
|
|
94df856897 | ||
|
|
08c12c5bb3 | ||
|
|
1948b2b113 | ||
|
|
20301d55b4 | ||
|
|
250dcb4cf5 | ||
|
|
4875b50dca | ||
|
|
d0b01398ca | ||
|
|
507151045b | ||
|
|
cbd66826af | ||
|
|
c7357336cb | ||
|
|
97c432334e | ||
|
|
ba291c35f7 | ||
|
|
b09318463a | ||
|
|
99a87dacc3 | ||
|
|
177bcb466b | ||
|
|
4d0520004a | ||
|
|
8a680487db | ||
|
|
d87ad693fc | ||
|
|
344a6d0ff6 | ||
|
|
9d362f90ef | ||
|
|
99f7557bf0 | ||
|
|
4447547f3a | ||
|
|
13ec0fb278 | ||
|
|
b4c8e92f7f | ||
|
|
b8ee0d56f0 | ||
|
|
a538dc4e86 | ||
|
|
022b5c5a36 | ||
|
|
83d29eff29 | ||
|
|
5c3477af38 | ||
|
|
5cb56973ea | ||
|
|
2a9280e202 | ||
|
|
ae6942e3d1 | ||
|
|
58253bddc4 | ||
|
|
67354524be | ||
|
|
5ce4bd8335 | ||
|
|
3634531310 | ||
|
|
6f2f231905 | ||
|
|
fa24231908 | ||
|
|
f7db7f3fb1 | ||
|
|
36978a7d7f | ||
|
|
e43785b60d | ||
|
|
dca8635e1d | ||
|
|
e933a1bd23 | ||
|
|
0bab451b04 | ||
|
|
5e12264e75 | ||
|
|
2adff8836c | ||
|
|
ce6521e13d | ||
|
|
566e361484 | ||
|
|
120b3648f9 | ||
|
|
6421f9a9aa | ||
|
|
11156f82ba | ||
|
|
db6fa15ef0 | ||
|
|
080a964a3f | ||
|
|
0d228cec61 | ||
|
|
5a17fe2916 | ||
|
|
ebce5dc2fe | ||
|
|
998b76837a | ||
|
|
b3ac666ce5 | ||
|
|
a89eda002e | ||
|
|
232d4387e2 | ||
|
|
d230b29aba | ||
|
|
7b8b5e34b6 | ||
|
|
298c514fff | ||
|
|
8dc5d5e460 | ||
|
|
aed0e61611 | ||
|
|
59b6d8259a | ||
|
|
c72279e756 | ||
|
|
fa94d768cb | ||
|
|
68cd13fff2 | ||
|
|
cfe548a265 | ||
|
|
b0ce139d9f | ||
|
|
2a5780de8a | ||
|
|
e1aeb1569a | ||
|
|
6fbe9050cb | ||
|
|
88dbebcebc | ||
|
|
252ad65e46 | ||
|
|
6101a43bde | ||
|
|
9ef82979c4 | ||
|
|
d65ec15e06 | ||
|
|
0415ca35ad | ||
|
|
69ec1b7eb3 | ||
|
|
767c53c304 | ||
|
|
9ff097ed39 | ||
|
|
e1ebedbb23 | ||
|
|
0dba2713de | ||
|
|
3e358ada3e | ||
|
|
816496b221 | ||
|
|
2a9a5e1871 | ||
|
|
b4074b6255 | ||
|
|
5c024f7877 | ||
|
|
62fd1414b6 | ||
|
|
6cf976e1d8 | ||
|
|
b1bf820fc4 | ||
|
|
d3345cc201 | ||
|
|
28ad0be64e | ||
|
|
bca5861af8 | ||
|
|
2294423014 | ||
|
|
a04f049f99 | ||
|
|
62127c7094 | ||
|
|
e7ae6a19c9 | ||
|
|
8b56b8956f | ||
|
|
e7b025d893 | ||
|
|
1662b369c5 | ||
|
|
ccfdf96d56 | ||
|
|
bf5d3ae42a | ||
|
|
f1e91e8855 | ||
|
|
3bd51537a4 | ||
|
|
c72fcab80b | ||
|
|
2d6f7c8c0a | ||
|
|
ed56f598d6 | ||
|
|
beb705aeb1 | ||
|
|
6034083cae | ||
|
|
67542fde0e | ||
|
|
5622622793 | ||
|
|
2e7459026e | ||
|
|
0f94937f44 | ||
|
|
58f4058b00 | ||
|
|
aef875b27e | ||
|
|
c81ae07342 | ||
|
|
f9f8465fdd | ||
|
|
e088ebb8f1 | ||
|
|
bf34d65771 | ||
|
|
71a7aaa631 | ||
|
|
1dd754dcdf | ||
|
|
af3e516f77 | ||
|
|
66e50468dd | ||
|
|
f9b52f6df4 | ||
|
|
2284b84d74 | ||
|
|
e0ca4072db | ||
|
|
bf64a0d5d9 | ||
|
|
5f23979aa8 | ||
|
|
4fcd03af9f | ||
|
|
29317a7e0e | ||
|
|
ba5af4569a | ||
|
|
c73ee3f002 | ||
|
|
b44c682a95 | ||
|
|
5bcf679b73 | ||
|
|
024383c7cf | ||
|
|
0914f30711 | ||
|
|
98b5a9d109 | ||
|
|
0c6681ddd5 | ||
|
|
caa3ad8d57 | ||
|
|
2fff8b8280 | ||
|
|
00c93a6214 | ||
|
|
d99f88add1 | ||
|
|
537266cadc | ||
|
|
fbfed7400f | ||
|
|
975d00c10d | ||
|
|
375e2c913a | ||
|
|
705671ffd3 | ||
|
|
a77b091952 | ||
|
|
070c022f10 | ||
|
|
f052a01ff2 | ||
|
|
ea22548bea | ||
|
|
9d330c054e | ||
|
|
b5bb149d7b | ||
|
|
52cb865cf0 | ||
|
|
05ab656e4a | ||
|
|
0f4a4d46ab | ||
|
|
9c89fcb69c | ||
|
|
77abeb5330 | ||
|
|
3a1c3a8ac5 | ||
|
|
c4fadc8861 | ||
|
|
e062b72f78 | ||
|
|
57442fd5ef | ||
|
|
81c2f6a713 | ||
|
|
eeb8892daa | ||
|
|
1dd74a0744 | ||
|
|
8f4e45ad7e | ||
|
|
5eb0f23677 | ||
|
|
ddad355529 | ||
|
|
e27a76aad5 | ||
|
|
ca904804e4 | ||
|
|
c9ea41d79f | ||
|
|
42783087f5 | ||
|
|
8907d8fa04 | ||
|
|
8a0af354df | ||
|
|
d904beeb3b | ||
|
|
9011c72c56 | ||
|
|
9a13b1536d | ||
|
|
db30f4bdcb | ||
|
|
aeb7938001 | ||
|
|
887ef2682c | ||
|
|
118d241075 | ||
|
|
634ba650ab | ||
|
|
a687db7ce8 | ||
|
|
d145b64cac | ||
|
|
037b8b129d | ||
|
|
6716d12cf8 | ||
|
|
420ed91d3e | ||
|
|
07555e64d9 | ||
|
|
3f42cf2f3e | ||
|
|
60318da786 | ||
|
|
a0735eeac5 | ||
|
|
e672951ed2 | ||
|
|
713a5e3080 | ||
|
|
c6b3c1984c | ||
|
|
2391def779 | ||
|
|
a76b380643 | ||
|
|
28b3569d62 | ||
|
|
dec509888a | ||
|
|
bb93c85427 | ||
|
|
db0008c448 | ||
|
|
155a0ce6e3 | ||
|
|
90f35c2f2a | ||
|
|
33b14d31c7 | ||
|
|
2a31bd5310 | ||
|
|
8a01e8aa04 | ||
|
|
4a253e12fc | ||
|
|
3e072511de | ||
|
|
cffe96e267 | ||
|
|
7405bdffd4 | ||
|
|
ec6e40f040 | ||
|
|
1744a23d0f | ||
|
|
e0258ba438 | ||
|
|
f703353673 | ||
|
|
1f8dc520d4 | ||
|
|
2b91038561 | ||
|
|
83a97deac2 | ||
|
|
d8eb00152d | ||
|
|
7e26a2a646 | ||
|
|
0a7e6db2db | ||
|
|
1a76f45e1c | ||
|
|
c01dec514a | ||
|
|
0ac645e2ac | ||
|
|
6710007f47 | ||
|
|
a95a9de45c | ||
|
|
ea8564f68a | ||
|
|
55f580c7fc | ||
|
|
872a5b83f6 | ||
|
|
59c0977bed | ||
|
|
f7e10e70a0 | ||
|
|
7cc05aa300 | ||
|
|
ab8729140b | ||
|
|
ee591e0b22 | ||
|
|
b2d8ce4705 | ||
|
|
1cfd513f9d | ||
|
|
659e104902 | ||
|
|
208e504ca5 | ||
|
|
e07831f779 | ||
|
|
14414ddb1c | ||
|
|
5b3760d8c9 | ||
|
|
d97dd31599 | ||
|
|
d4d3b96d76 | ||
|
|
2d886db90f | ||
|
|
f9760f7b6a | ||
|
|
f8c47598b8 | ||
|
|
d9936b218d | ||
|
|
aa02826aac | ||
|
|
289caa2d15 | ||
|
|
cf22a43354 | ||
|
|
cf50039c14 | ||
|
|
fff7eac50a | ||
|
|
8665a8cb0f | ||
|
|
d30cacd81f | ||
|
|
addef6048d | ||
|
|
209b1d150c | ||
|
|
4074b8e734 | ||
|
|
3d3839a090 | ||
|
|
3f2bb545e8 | ||
|
|
b8c8a39cad | ||
|
|
8cf205fb19 | ||
|
|
2b65fc1d03 | ||
|
|
32adfbfda1 | ||
|
|
f23354f758 | ||
|
|
82ff9ea3af | ||
|
|
72197bed03 | ||
|
|
e4d304b70b | ||
|
|
bcc9b414b4 | ||
|
|
0283e51131 | ||
|
|
eb0e8ace24 | ||
|
|
4076852d29 | ||
|
|
6ceb29d4d4 | ||
|
|
87459aee74 | ||
|
|
737176b36d | ||
|
|
fc271a843e | ||
|
|
a05cae6d35 | ||
|
|
664e11f0b1 | ||
|
|
7d161d3bc7 | ||
|
|
016c431750 | ||
|
|
24e79a68e1 | ||
|
|
ce9c1558a6 | ||
|
|
23d4dc13e1 | ||
|
|
0f3264c8d1 | ||
|
|
6372b6a6ac | ||
|
|
8e08a2273c | ||
|
|
6475e22cc9 | ||
|
|
97669cab1f | ||
|
|
afc121fa04 | ||
|
|
c368f28dad | ||
|
|
0e30609d7b | ||
|
|
9e8947d9e6 | ||
|
|
878c2e6886 | ||
|
|
3cff31d890 | ||
|
|
271ca7318a | ||
|
|
3e760796d3 | ||
|
|
786fd60130 | ||
|
|
500bde4952 | ||
|
|
f519a84ce3 | ||
|
|
249ad82c6a | ||
|
|
f172f06ff2 | ||
|
|
bf46736ab1 | ||
|
|
2005c3b37b | ||
|
|
c09c2bf800 | ||
|
|
43581a71ab | ||
|
|
9a7d202077 | ||
|
|
e934a311cb | ||
|
|
6b3c17b9b0 | ||
|
|
3a99b15a3b | ||
|
|
fc35763283 | ||
|
|
1d3e690c6d | ||
|
|
4a0df5485f | ||
|
|
4a5b30c24c | ||
|
|
89cdd1df3c | ||
|
|
f1d6c77ecc | ||
|
|
a5862555f0 | ||
|
|
8b90c4fdad | ||
|
|
7adca0ea2f | ||
|
|
9dcc44d7b3 | ||
|
|
da1e0ac742 | ||
|
|
9a0529a96f | ||
|
|
5badfc7e00 | ||
|
|
40cb2bedb4 | ||
|
|
bdc1f27e0d | ||
|
|
dc2a0aa7aa | ||
|
|
28c49640dc | ||
|
|
5d9d317c9e | ||
|
|
1607e06895 | ||
|
|
0c29196c73 | ||
|
|
349ce61d6f | ||
|
|
22b059eab3 | ||
|
|
59dd3b3cd9 | ||
|
|
193f3d1ca9 | ||
|
|
deff06e6fb | ||
|
|
8112383b78 | ||
|
|
f42d2c9abd | ||
|
|
9c114f36da | ||
|
|
1783d66b34 | ||
|
|
458298c4e5 | ||
|
|
60d19b2f15 | ||
|
|
65f40aa682 | ||
|
|
c7b391ca28 | ||
|
|
94985fd194 | ||
|
|
1fa2ce7eae | ||
|
|
1725667f4c | ||
|
|
7539c231d4 | ||
|
|
cdaf0ab79a | ||
|
|
7a631df470 | ||
|
|
d47f76b56f | ||
|
|
29d019169b | ||
|
|
4f640b0d8f | ||
|
|
420ebb7c68 | ||
|
|
1a1b126148 | ||
|
|
7ae2fa27e9 | ||
|
|
cbf0854acc | ||
|
|
2df8b98734 | ||
|
|
40696c4c38 | ||
|
|
d12d8fb46f | ||
|
|
5c93f443de | ||
|
|
7fe86a5425 | ||
|
|
0d4b663cac | ||
|
|
1c3ed2a83d | ||
|
|
fcb738fca3 | ||
|
|
f148623ce2 | ||
|
|
2a4e20810b | ||
|
|
00be0f9f61 | ||
|
|
426f57c5a5 | ||
|
|
6259f4406c | ||
|
|
b356686ecb | ||
|
|
57708b0d58 | ||
|
|
efe4d210bd | ||
|
|
af3250a9f8 | ||
|
|
c22617106a | ||
|
|
063c7af445 | ||
|
|
473a9235ee | ||
|
|
b1d16c1585 | ||
|
|
2e4a791f95 | ||
|
|
9a727082a0 | ||
|
|
ea3d8dcea8 | ||
|
|
fc53f564ca | ||
|
|
f731b5d665 | ||
|
|
7d4a878ba7 | ||
|
|
4cda4fd158 | ||
|
|
be9adba550 | ||
|
|
aa4681bfe2 | ||
|
|
ccfba88285 | ||
|
|
e951a79d90 | ||
|
|
d63d2149c5 | ||
|
|
a59640bf27 | ||
|
|
4462e59079 | ||
|
|
2ed540c845 | ||
|
|
9925249931 | ||
|
|
fc7043d7d1 | ||
|
|
705c6a0dac | ||
|
|
e6e075b0cd | ||
|
|
048fdf005a | ||
|
|
cef715b655 | ||
|
|
2b58801b9a | ||
|
|
68461c7c6a | ||
|
|
5497de6931 | ||
|
|
b06cacc7c2 | ||
|
|
f86c5d30de | ||
|
|
95c5f1d17b | ||
|
|
140a27777d | ||
|
|
2775a809a5 | ||
|
|
1ff207c2fa | ||
|
|
2332ff8177 | ||
|
|
262c39b236 | ||
|
|
cf3d41ae05 | ||
|
|
f6c156b17b | ||
|
|
2f012d936b | ||
|
|
72731dacf0 | ||
|
|
2a446e8c5a | ||
|
|
07fb9eb785 | ||
|
|
a53c45b2b8 | ||
|
|
aa25aeaf60 | ||
|
|
ab898a16e9 | ||
|
|
c11b1369d1 | ||
|
|
14731fe09a | ||
|
|
bd113f8c65 | ||
|
|
2f99b54e8e | ||
|
|
6452b4fe60 | ||
|
|
19b3dc94bc | ||
|
|
ec9bd141da | ||
|
|
b1e32169ac | ||
|
|
ae51efb990 | ||
|
|
827572e191 | ||
|
|
b0b4ba7533 | ||
|
|
1aba9fe678 | ||
|
|
4b6dbe4a33 | ||
|
|
c6d486af36 | ||
|
|
b03bc0ce07 | ||
|
|
56cfdd53eb | ||
|
|
546c2bf791 | ||
|
|
bfcc5ae79a | ||
|
|
61a8e638bc | ||
|
|
bb43cee996 | ||
|
|
42e4f5af68 | ||
|
|
6e1a46a037 | ||
|
|
59bb4e3ec5 | ||
|
|
6c7f722d31 | ||
|
|
2b0addd3ca | ||
|
|
fce2de524a | ||
|
|
593e8b883a | ||
|
|
c2d6c92f4e | ||
|
|
fcc2a57e13 | ||
|
|
82ca32f90c | ||
|
|
fcdafc1e30 | ||
|
|
938b1008d9 | ||
|
|
4d1a442f75 | ||
|
|
9d5ed744c4 | ||
|
|
3a0a70e615 | ||
|
|
bbb069be94 | ||
|
|
df12b3bd87 | ||
|
|
f1263d2aa4 | ||
|
|
808ccba21d | ||
|
|
b1d21f6c93 | ||
|
|
02a47637b9 | ||
|
|
efb3fa669f | ||
|
|
8a452b6a9c | ||
|
|
034f775ae1 | ||
|
|
a81eb361e1 | ||
|
|
80f20cb452 | ||
|
|
bd97dba011 | ||
|
|
c5d57a13ac | ||
|
|
6c13b8d885 | ||
|
|
81c3cb9b92 | ||
|
|
76b9429c87 | ||
|
|
2962817bb9 | ||
|
|
6318e18861 | ||
|
|
93ee06cbe3 | ||
|
|
a57519d043 | ||
|
|
494143860b | ||
|
|
050f125a57 | ||
|
|
400a1b6604 | ||
|
|
d36adf470f | ||
|
|
f87ded540a | ||
|
|
7262eb86f2 | ||
|
|
14017b28ba | ||
|
|
02c591aad0 | ||
|
|
7532e26044 | ||
|
|
01188f73f1 | ||
|
|
3c7a239b15 | ||
|
|
ad710eea92 | ||
|
|
c0fb34e815 | ||
|
|
fb97995450 | ||
|
|
48fa594028 | ||
|
|
979916e20e | ||
|
|
20837e74f5 | ||
|
|
049b59f8e0 | ||
|
|
6f2e211d39 | ||
|
|
532d27b392 | ||
|
|
d9aab4060c | ||
|
|
1c9f629c18 | ||
|
|
72d6be2c11 | ||
|
|
f92affe176 | ||
|
|
5c0fc20d6e | ||
|
|
4825890477 | ||
|
|
bb47bc7e0d | ||
|
|
f61a7c87bf | ||
|
|
f89d221b96 | ||
|
|
2678fccde3 | ||
|
|
562460463b | ||
|
|
3bdffda78b | ||
|
|
577272cf79 | ||
|
|
21386ce160 | ||
|
|
43530eb819 | ||
|
|
2dc8bf19c8 | ||
|
|
660a209ee4 | ||
|
|
40a029f2dd | ||
|
|
9870509cb1 | ||
|
|
a7dffc6229 | ||
|
|
3c8afd5708 | ||
|
|
90c7b82b9a | ||
|
|
385c32efe6 | ||
|
|
d0667b2311 | ||
|
|
8486ce1efa | ||
|
|
79207ee45a | ||
|
|
1798037524 | ||
|
|
297be37080 | ||
|
|
1da14e066c | ||
|
|
5cf7059f70 | ||
|
|
5ae0e2c8b7 | ||
|
|
9632b6b895 | ||
|
|
3b166e2b8d | ||
|
|
f4429c1c31 | ||
|
|
f27d63b090 | ||
|
|
92f60809e8 | ||
|
|
f5d0f49584 | ||
|
|
8faf9c895c | ||
|
|
4fb38bd451 | ||
|
|
dc0ecf08db | ||
|
|
dc19dcbc23 | ||
|
|
114c14f8ad | ||
|
|
1c9200af08 | ||
|
|
965f2d0185 | ||
|
|
604419a812 | ||
|
|
2b738509c3 | ||
|
|
48501bde9b | ||
|
|
3d78993c6d | ||
|
|
ba04898379 | ||
|
|
5cd4c4c456 | ||
|
|
f16fa4a863 | ||
|
|
20167392a8 | ||
|
|
1d216bfaa7 | ||
|
|
536e99a1de | ||
|
|
d25d637046 | ||
|
|
b39ee56af9 | ||
|
|
8c850a29ed | ||
|
|
5b6d25a1d6 | ||
|
|
da31aff2f2 | ||
|
|
e8ca2abed7 | ||
|
|
31cc97e660 | ||
|
|
81d9d7a10e | ||
|
|
07780c8255 | ||
|
|
9fe2553f05 | ||
|
|
3c82377686 | ||
|
|
944b254385 | ||
|
|
6c1ab8a02a | ||
|
|
301f6ffbbe | ||
|
|
a12cb1d567 | ||
|
|
1cbf451a13 | ||
|
|
13b6b67fe5 | ||
|
|
f7b096ab4f | ||
|
|
4df6c1fd9c | ||
|
|
4c6e572df4 | ||
|
|
9e4b25fc3e | ||
|
|
0376a287fb | ||
|
|
ea364efbb0 | ||
|
|
7314547af7 | ||
|
|
389ac8aab0 | ||
|
|
541b9722d8 | ||
|
|
e5dfd3a975 | ||
|
|
ddaeaddf2b | ||
|
|
f1e733e612 | ||
|
|
e15a3cf717 | ||
|
|
23de6c3ccd | ||
|
|
a6f7fdcc03 | ||
|
|
789d3bcb49 | ||
|
|
d7e8610d31 | ||
|
|
b823f2e897 | ||
|
|
7e82141918 | ||
|
|
c4dc5966e0 | ||
|
|
a2ace9a70e | ||
|
|
3a2ab30095 | ||
|
|
6f10e05eb0 | ||
|
|
9429f5a831 | ||
|
|
0899d16ebd | ||
|
|
77dbac88cb | ||
|
|
d3b889dffa | ||
|
|
4fe662aeb2 | ||
|
|
d2e440ca30 | ||
|
|
3a97f30ba8 | ||
|
|
404df30f4f | ||
|
|
544d0efa38 | ||
|
|
1f2635d3f7 | ||
|
|
fc0ec772f2 | ||
|
|
802760773c | ||
|
|
b3128b8b85 | ||
|
|
92554adb45 | ||
|
|
ef1d581f17 | ||
|
|
9bd4da7fa7 | ||
|
|
d2adaab485 | ||
|
|
760e3b39ec | ||
|
|
162827e0bf | ||
|
|
8957a18df8 | ||
|
|
082e0ef4e3 | ||
|
|
b6d496d538 | ||
|
|
a3553875ab | ||
|
|
f2c63f2b65 | ||
|
|
166b112d6d | ||
|
|
0bdc099a35 | ||
|
|
dab21eb4ea | ||
|
|
21f8d40dbd | ||
|
|
45b2fd65df | ||
|
|
ad5008ef7e | ||
|
|
5d32433b95 | ||
|
|
74f38b2a47 | ||
|
|
7f8843a706 | ||
|
|
67213ca3d0 | ||
|
|
d55494b8e9 | ||
|
|
fe8e624501 | ||
|
|
38608796ed | ||
|
|
4f50133a80 | ||
|
|
158987ef54 | ||
|
|
ebc1e4fc69 | ||
|
|
52539ef0dd | ||
|
|
d813808a01 | ||
|
|
e6ce766900 | ||
|
|
33170a4b2b | ||
|
|
eb5ec16173 | ||
|
|
fd368cec2a | ||
|
|
d8e3f8e0c7 | ||
|
|
1c53cf56c8 | ||
|
|
2cc262c093 | ||
|
|
d3e140c996 | ||
|
|
76a378884f | ||
|
|
8b6418238d | ||
|
|
2bce032ba3 | ||
|
|
0374545137 | ||
|
|
5cdc5206b7 | ||
|
|
c810393bd8 | ||
|
|
0d245c66ab | ||
|
|
bbf8ac9ff2 | ||
|
|
32c3c16b3e | ||
|
|
955ab023df | ||
|
|
e926d4c3d3 | ||
|
|
f183f4c0cd | ||
|
|
1aae495985 | ||
|
|
e9908a145e | ||
|
|
276e28f813 | ||
|
|
71f4918fd8 | ||
|
|
99db4fd6c7 | ||
|
|
ffc65cc90d | ||
|
|
b239c8294a | ||
|
|
9578f883b7 | ||
|
|
c29090b732 | ||
|
|
4fe43c36f6 | ||
|
|
a6237c895b | ||
|
|
873a2046fb | ||
|
|
0a6b6bad04 | ||
|
|
dabe7f50bb | ||
|
|
4f7715809f | ||
|
|
a633d2683d | ||
|
|
28048a043b | ||
|
|
68e6aed6e8 | ||
|
|
9351aa7eb4 | ||
|
|
adcd4ef11a | ||
|
|
19bcb91965 | ||
|
|
d827d56a9a | ||
|
|
71eeac3530 | ||
|
|
5394228fbc | ||
|
|
2b7d9d2de0 | ||
|
|
a1e2170ad5 | ||
|
|
b55d4c95ea | ||
|
|
05d2776f6f | ||
|
|
01ec618ac9 | ||
|
|
433604d76a | ||
|
|
90eba8a49d | ||
|
|
cb37fd823f | ||
|
|
f4762fcad9 | ||
|
|
8327cdb88f | ||
|
|
a3edcadfff | ||
|
|
afb83ac1b4 | ||
|
|
d8f2a1639e | ||
|
|
9c2af695af | ||
|
|
f2d8c4a4c3 | ||
|
|
e3b573b7f3 | ||
|
|
8c76634f88 | ||
|
|
b6891aadbe | ||
|
|
64789313e5 | ||
|
|
23ff87c758 | ||
|
|
49c8cf9ee9 | ||
|
|
15483f9fdb | ||
|
|
f04c17137b | ||
|
|
8bedd9647f | ||
|
|
69f3cb5abc | ||
|
|
dc271ec7b2 | ||
|
|
7526edc767 | ||
|
|
ca84283333 | ||
|
|
4c4327348e | ||
|
|
e6555b0467 | ||
|
|
f02216f5b3 | ||
|
|
edafc0c3db | ||
|
|
9a41f786b1 | ||
|
|
2831d2c54a | ||
|
|
f110daaa3d | ||
|
|
41ea0390ba | ||
|
|
dedf4ed091 | ||
|
|
30cd5217f7 | ||
|
|
adc6ae37d8 | ||
|
|
84725456e2 | ||
|
|
a2bebc4a4c | ||
|
|
bf98702c19 | ||
|
|
65391557db | ||
|
|
0448ed5d25 | ||
|
|
e2c3f8059e | ||
|
|
f0e95648a7 | ||
|
|
a7b7a4ebc3 | ||
|
|
a7faeb01e4 | ||
|
|
1ca168b58e | ||
|
|
6f1b09965f | ||
|
|
23450c23fd | ||
|
|
b6384e6f77 | ||
|
|
de05f7d061 | ||
|
|
12e0477d4e | ||
|
|
4a0e09466a | ||
|
|
0ac5af5388 | ||
|
|
4558760720 | ||
|
|
637c1919f4 | ||
|
|
8334a91b6e | ||
|
|
7de2c6e6d5 | ||
|
|
d468b1b7b2 | ||
|
|
2c94a0e56d | ||
|
|
3a32066d65 | ||
|
|
75c071f74b | ||
|
|
4556ad3a27 | ||
|
|
3181d0e359 | ||
|
|
c7e266b7e5 | ||
|
|
c1ff5c2b94 | ||
|
|
624f83d8a4 | ||
|
|
85db2b5fb3 | ||
|
|
10b4a0c3a4 | ||
|
|
6e94a29e5d | ||
|
|
ae4505a4df | ||
|
|
48abcd3eb7 | ||
|
|
64d6c8a117 | ||
|
|
d26b922ede | ||
|
|
ef1b4800df | ||
|
|
a0749e59c0 | ||
|
|
2cada81ec8 | ||
|
|
39dc76a38e | ||
|
|
709220567f | ||
|
|
b9eb3de20b | ||
|
|
fe6b6eebd7 | ||
|
|
adc3f2c0fd | ||
|
|
9ab3b369d9 | ||
|
|
772069cf5a | ||
|
|
309b912841 | ||
|
|
4443aa0498 | ||
|
|
bbf6ef807d | ||
|
|
16928bab3c | ||
|
|
aa90bac01e | ||
|
|
31a2f82193 | ||
|
|
16d5d93e6b | ||
|
|
dcc11f87a8 | ||
|
|
30d6e6e907 | ||
|
|
45deeddf4c | ||
|
|
50955b73e0 | ||
|
|
9db88ce113 | ||
|
|
ba32081c81 | ||
|
|
80b9b52e66 | ||
|
|
fa4dd81093 | ||
|
|
d781f497a8 | ||
|
|
bc8ea50d3d | ||
|
|
ff3b08ec81 | ||
|
|
8731a2bd2f | ||
|
|
6f4375f230 | ||
|
|
92cfa37c08 | ||
|
|
3325fd0475 | ||
|
|
e452be91d1 | ||
|
|
6190092461 | ||
|
|
d0e1d4d7d9 | ||
|
|
2de90cd1e2 | ||
|
|
32b80357ef | ||
|
|
b1adfffae4 | ||
|
|
f1f26a6b11 | ||
|
|
e226dac88b | ||
|
|
dc0b6c4b41 | ||
|
|
8a45eeebb8 | ||
|
|
caab1c53fe | ||
|
|
d4034b48fd | ||
|
|
1c5bb4f2fa | ||
|
|
ee4bbc8454 | ||
|
|
e6b773cc58 | ||
|
|
271c4c7ffa | ||
|
|
10eef33fc6 | ||
|
|
0185931d6c | ||
|
|
81067e90d6 | ||
|
|
03ec481ee8 | ||
|
|
c784d4e923 | ||
|
|
144a3203a6 | ||
|
|
f568dad6c7 | ||
|
|
79274d455a | ||
|
|
8e74bfb604 | ||
|
|
88a4de3c24 | ||
|
|
d91df50b67 | ||
|
|
4851d3ab04 | ||
|
|
981fd9903a | ||
|
|
a056c117e3 | ||
|
|
033d6a1bd6 | ||
|
|
3eab85ca54 | ||
|
|
c5adbd722d | ||
|
|
5827b4fdfb | ||
|
|
557bcc2092 | ||
|
|
c60eaaf9b3 | ||
|
|
40c8ecc0fa | ||
|
|
634a4da584 | ||
|
|
16f5a913ce | ||
|
|
fa1a6c6307 | ||
|
|
64b0479a91 | ||
|
|
b1e43ff790 | ||
|
|
d12aa0b824 | ||
|
|
c0720b90ed | ||
|
|
69eb0e5d05 | ||
|
|
82a58ff9e1 | ||
|
|
763a2f8ca5 | ||
|
|
e21fa8e696 | ||
|
|
0221086519 | ||
|
|
982b1c2bf5 | ||
|
|
170d98a946 | ||
|
|
576e48e28a | ||
|
|
c06cb90773 | ||
|
|
2f5baf12a4 | ||
|
|
4fcb6c8e56 | ||
|
|
6e5e27c38d | ||
|
|
5fdde4ba84 | ||
|
|
5059b393e8 | ||
|
|
6f1decf127 | ||
|
|
c16aed9c46 | ||
|
|
2df065894d | ||
|
|
8461bb0931 | ||
|
|
6ddb448306 | ||
|
|
b4c3f617ac | ||
|
|
9684cfdd70 | ||
|
|
7b24967b88 | ||
|
|
8e7439ec0f | ||
|
|
4a767cd9f7 | ||
|
|
09614bff12 | ||
|
|
a95e47ee20 | ||
|
|
f9a89df8bd | ||
|
|
6dcb47e37f | ||
|
|
dd19fbaf81 | ||
|
|
fecfd60f6f | ||
|
|
f408773d47 | ||
|
|
567fd24a2c | ||
|
|
7c381839d0 | ||
|
|
77b34b5d52 | ||
|
|
e78fa9b174 | ||
|
|
d8acf6268a | ||
|
|
a84724de8d | ||
|
|
aa43623600 | ||
|
|
6a7e484e78 | ||
|
|
a168158d5d | ||
|
|
8a81d00586 | ||
|
|
57668dc1bb | ||
|
|
cd315d4cf6 | ||
|
|
0bec7785b0 | ||
|
|
bddb70a271 | ||
|
|
69826a6a2f | ||
|
|
e755e96fb0 | ||
|
|
5888f62c20 | ||
|
|
728125a771 | ||
|
|
fd23bc509d | ||
|
|
5388cb942f | ||
|
|
fec88e4410 | ||
|
|
6b12e2e17c | ||
|
|
33d87af0c2 | ||
|
|
8f5368cf3a | ||
|
|
b4845dce99 | ||
|
|
ea40db6143 | ||
|
|
7c200913aa | ||
|
|
4b5f84562a | ||
|
|
5ba2fbd94a | ||
|
|
8edb532ca2 | ||
|
|
319b5920c7 | ||
|
|
39836315b6 | ||
|
|
87f44cc52c | ||
|
|
ca740427b1 | ||
|
|
6019bdb044 | ||
|
|
a095cd0ef5 | ||
|
|
60df7a9c76 | ||
|
|
e6ecafcb9d | ||
|
|
eceb191186 | ||
|
|
f08cd68a1d | ||
|
|
07072c9456 | ||
|
|
5c6d6dd33b | ||
|
|
afd002e89a | ||
|
|
1224c3b69b | ||
|
|
0f26f976fa | ||
|
|
70e5a7403f | ||
|
|
ce9cad6bb0 | ||
|
|
ba45786b38 | ||
|
|
7b52c2ad3c | ||
|
|
c09ec5e889 | ||
|
|
6043e41fcf | ||
|
|
ba5d2a97ee | ||
|
|
9cc89798c8 | ||
|
|
6133734cec | ||
|
|
ec5347e2c7 | ||
|
|
bc16aea153 | ||
|
|
2f8d63983c | ||
|
|
2f60dbd378 | ||
|
|
c656e22ad4 | ||
|
|
599a98b25c | ||
|
|
47ee25b1f5 | ||
|
|
baf089619a | ||
|
|
685b8245ce | ||
|
|
32391301db | ||
|
|
44fe61bf92 | ||
|
|
fe9c7901d5 | ||
|
|
0cedbe4ab5 | ||
|
|
67432b46f8 | ||
|
|
f05a4bf2bf | ||
|
|
bf45f72ed3 | ||
|
|
1fbc81572c | ||
|
|
7643153c58 | ||
|
|
685eab0b8d | ||
|
|
c115370fcb | ||
|
|
ad226e3da3 | ||
|
|
3644c4e407 | ||
|
|
baf1819ca2 | ||
|
|
c247e3f281 | ||
|
|
bce5102f05 | ||
|
|
b7255af352 | ||
|
|
122c58bd11 | ||
|
|
12351e0500 | ||
|
|
07c4ea8470 | ||
|
|
4d2a6960a7 | ||
|
|
a706ae1129 | ||
|
|
8897cb3976 | ||
|
|
92c3a103f6 | ||
|
|
ecd12b0acc | ||
|
|
02a7eada71 | ||
|
|
83ef207a84 | ||
|
|
9f4a452a3d | ||
|
|
bd40cbcd09 | ||
|
|
05e80c4825 | ||
|
|
6f2bb2e16a | ||
|
|
e078f002c0 | ||
|
|
b29934bcce | ||
|
|
d1199d9c06 | ||
|
|
6dd9692f45 | ||
|
|
03f421ff1f | ||
|
|
03e2010cbb | ||
|
|
6d446ab8ff | ||
|
|
5e4bd2736b | ||
|
|
de8e5f2c8d | ||
|
|
af1e00675f | ||
|
|
f7b41fd929 | ||
|
|
feac7b8b38 | ||
|
|
56874aef38 | ||
|
|
10d5ba588d | ||
|
|
7c5dfcc60a | ||
|
|
fc8197c3ce | ||
|
|
0f8c9b5eed | ||
|
|
bc6af069c8 | ||
|
|
49ebcb1aa2 | ||
|
|
4bb0f1046f | ||
|
|
68df4d65c6 | ||
|
|
78a29357bb | ||
|
|
7b20f674e7 | ||
|
|
ab6e5af4cd | ||
|
|
1415fce15f | ||
|
|
1de1f3d416 | ||
|
|
a8644ebab6 | ||
|
|
f1e095b6ec | ||
|
|
6ef6702d40 | ||
|
|
f3139b9d76 | ||
|
|
24f34e5107 | ||
|
|
30753c7590 | ||
|
|
ba1f7fd08e | ||
|
|
79e3817e2c | ||
|
|
b9b2aaf114 | ||
|
|
2d78cc9624 | ||
|
|
eea8cd8d1a | ||
|
|
5d4c32d816 | ||
|
|
9860862ced | ||
|
|
404bc0354a | ||
|
|
25e2824175 | ||
|
|
c0fd27f8c0 | ||
|
|
34e9f5c3b6 | ||
|
|
e1d85f9eef | ||
|
|
85c594efe4 | ||
|
|
2dea9e50bd | ||
|
|
13b7886097 | ||
|
|
9393ba5cda | ||
|
|
c58821f710 | ||
|
|
77e3635776 | ||
|
|
b4bfa6a806 | ||
|
|
b390a8decd | ||
|
|
b1ab15bd2b | ||
|
|
4d24b89e77 | ||
|
|
a6e859f990 | ||
|
|
63aaac8137 | ||
|
|
20d31c6312 | ||
|
|
a82d87b5a6 | ||
|
|
a1b05dea35 | ||
|
|
5f892c2c7e | ||
|
|
f0d2f86154 | ||
|
|
7b317dde56 | ||
|
|
c84ebdd23e | ||
|
|
959bdc628d | ||
|
|
95b78df937 | ||
|
|
79b17708e2 | ||
|
|
0f78f78064 | ||
|
|
db529702d0 | ||
|
|
a106fa4c3d | ||
|
|
89ca06489b | ||
|
|
bc0a4c01be | ||
|
|
88d6f71666 | ||
|
|
e3cd1f08cf | ||
|
|
682994b090 | ||
|
|
4e365d69f5 | ||
|
|
8a9a62fd2b | ||
|
|
cb8c4d7a32 | ||
|
|
ed65c1a469 | ||
|
|
2ceec0bfa1 | ||
|
|
fe3220466e | ||
|
|
c8a9272548 | ||
|
|
eab10e13c5 | ||
|
|
40aadb6a14 | ||
|
|
ea153228e2 | ||
|
|
65b26a4dc8 | ||
|
|
e170d16505 | ||
|
|
dda87a1740 | ||
|
|
77397daf05 | ||
|
|
51cce67bf5 | ||
|
|
af1e34f918 | ||
|
|
66f01dfc70 | ||
|
|
94900cdf1c | ||
|
|
c6517a8071 | ||
|
|
6747d1ee75 | ||
|
|
b3eac24995 | ||
|
|
e9e1725545 | ||
|
|
85c99bd3c3 | ||
|
|
337e70ead9 | ||
|
|
f0a1b8c857 | ||
|
|
7bb6254999 | ||
|
|
9b2e5dcf3c | ||
|
|
a5d7c242b5 | ||
|
|
f6da30bb54 | ||
|
|
ea0952b6d0 | ||
|
|
5c8e17f6cf | ||
|
|
4b0697fdff | ||
|
|
63d08d2299 | ||
|
|
8b9fc7617b | ||
|
|
d71e2e0c61 | ||
|
|
ddf779ee2d | ||
|
|
9b42dd8679 | ||
|
|
6e0813213c | ||
|
|
1eada89535 | ||
|
|
927205c1f3 | ||
|
|
561a29af8c | ||
|
|
ab874d16f0 | ||
|
|
bea931e17b | ||
|
|
5c3f74701c | ||
|
|
c4d1177af0 | ||
|
|
e25f795cf5 | ||
|
|
5a0e7b77ee | ||
|
|
9a8f76e238 | ||
|
|
1f5cf26443 | ||
|
|
bb4e20398f | ||
|
|
a674416f68 | ||
|
|
c5ad4bd367 | ||
|
|
d8de612c85 | ||
|
|
0e268a5497 | ||
|
|
e176b9ad28 | ||
|
|
e2d30bdcc6 | ||
|
|
40a54f2ebe | ||
|
|
b741e9f1f9 | ||
|
|
b90f03ba35 | ||
|
|
eca2c8e606 | ||
|
|
1de5f8f809 | ||
|
|
33e5073624 | ||
|
|
c292243ee4 | ||
|
|
db1f5a63ba | ||
|
|
201f604356 | ||
|
|
7a253b705c | ||
|
|
3281665bd3 | ||
|
|
9fd12ce000 | ||
|
|
51e456cc0e | ||
|
|
a070512005 | ||
|
|
2488182e0d | ||
|
|
590a8a649a | ||
|
|
62f24e605a | ||
|
|
e97a617861 | ||
|
|
9c2f3d6620 | ||
|
|
98bc396af5 | ||
|
|
e67697ce31 | ||
|
|
e034e05c14 | ||
|
|
f6476fa522 | ||
|
|
cd1e58c339 | ||
|
|
f6421a43ca | ||
|
|
4c209b2252 | ||
|
|
a05f23d07e | ||
|
|
db100c22d6 | ||
|
|
fd7c65dce9 | ||
|
|
540169180b | ||
|
|
13eef8e57b | ||
|
|
22a9ed6dd9 | ||
|
|
443d64e70a | ||
|
|
b4a6c53c4b | ||
|
|
57dff913d2 | ||
|
|
429e23d2f5 | ||
|
|
c6a98f2a4b | ||
|
|
a2746b1c76 | ||
|
|
5709e14017 | ||
|
|
3a6600c8d3 | ||
|
|
def139d70e | ||
|
|
1604889e37 | ||
|
|
78cb432395 | ||
|
|
a0a360197e | ||
|
|
586a788f4d | ||
|
|
be439d7135 | ||
|
|
58916129d5 | ||
|
|
9d949b8a4d | ||
|
|
c5c825bf07 | ||
|
|
aaa42824d2 | ||
|
|
b30e0c20e5 | ||
|
|
5de9c44690 | ||
|
|
43da756591 | ||
|
|
c1297b6025 | ||
|
|
a404eb87dc | ||
|
|
028212dcfa | ||
|
|
7a9e277152 | ||
|
|
5ca904e1e9 | ||
|
|
04e2f8b626 | ||
|
|
bf3370abb2 | ||
|
|
2f47684e81 | ||
|
|
a15d37e5c3 | ||
|
|
91d5404fb8 | ||
|
|
552bbdd1fd | ||
|
|
9c33579709 | ||
|
|
9459ddefbb | ||
|
|
c31d980b95 | ||
|
|
aa230f2fb6 | ||
|
|
d7152b81f9 | ||
|
|
25820cf1d1 | ||
|
|
fedc63915d | ||
|
|
a9c790c7dd | ||
|
|
4480cc1fbd | ||
|
|
c6b37e560d | ||
|
|
98c588a831 | ||
|
|
0a19afabe8 | ||
|
|
3d65ba10e3 | ||
|
|
261a8854cc | ||
|
|
fdb125b4db | ||
|
|
cf914b6298 | ||
|
|
278a75dbfe | ||
|
|
184d77489a | ||
|
|
bac1bc9841 | ||
|
|
3235148493 | ||
|
|
99cce386a4 | ||
|
|
ba5f402650 | ||
|
|
858ad8db23 | ||
|
|
04eba969cb | ||
|
|
04797bf517 | ||
|
|
68b30890eb | ||
|
|
819b98479e | ||
|
|
113e0b7819 | ||
|
|
6dfc78fab6 | ||
|
|
8cb6fd7cf8 | ||
|
|
471cf28bb0 | ||
|
|
fe6be8063f | ||
|
|
6c345e3152 | ||
|
|
bd65dafcc2 | ||
|
|
013a64b79f | ||
|
|
87bff9accd | ||
|
|
555d01f4c0 | ||
|
|
ee911d0ab5 | ||
|
|
65085946d4 | ||
|
|
edcd4afc02 | ||
|
|
b5f690e161 | ||
|
|
67a00bc40b | ||
|
|
efb9ed0078 | ||
|
|
cb33110f69 | ||
|
|
e915144258 | ||
|
|
e658d019b5 | ||
|
|
37d373d886 | ||
|
|
072eaf055b | ||
|
|
62ea33ba1a | ||
|
|
ab41e5d1c7 | ||
|
|
e2a5e7f282 | ||
|
|
5c549718d8 | ||
|
|
f949b6761d | ||
|
|
c0a659b353 | ||
|
|
8ce463bc15 | ||
|
|
aa36b6ed29 | ||
|
|
6a1cf2b7b0 | ||
|
|
b2a5eff087 | ||
|
|
73c1cc15cc | ||
|
|
c51b419ad4 | ||
|
|
7dbbf4799a | ||
|
|
1b5a345334 | ||
|
|
3b57fc2abf | ||
|
|
3e79333aa3 | ||
|
|
8032425ffd | ||
|
|
2d4cb13dfb | ||
|
|
bdf9b9caac | ||
|
|
b130bf8b4e | ||
|
|
74daa484b0 | ||
|
|
7a3c2d189e | ||
|
|
af3849840c | ||
|
|
a56f5ada43 | ||
|
|
ceeb18e690 | ||
|
|
adea559405 | ||
|
|
f6056ad067 | ||
|
|
b9dcad9a3c | ||
|
|
0d41c38606 |
@@ -1,3 +1,384 @@
|
||||
--- 9.3.5-P2-W2 released ---
|
||||
|
||||
2436. [security] win32: UDP client handler can be shutdown. [RT #18576]
|
||||
|
||||
--- 9.3.5-P2-W1 released ---
|
||||
|
||||
2432. [bug] More Windows socket handling improvements. Stop
|
||||
using I/O events and use IO Completion Ports
|
||||
throughout. Rewrite the receive path logic to make
|
||||
it easier to support multiple simultaneous
|
||||
requestrs in the future. Add stricter consistency
|
||||
checking as a compile-time option (define
|
||||
ISC_SOCKET_CONSISTENCY_CHECKS; defaults to off).
|
||||
|
||||
2420. [bug] Windows socket handling cleanup. Let the io
|
||||
completion event send out cancelled read/write
|
||||
done events, which keeps us from writing to memeory
|
||||
we no longer have ownership of. Add debugging
|
||||
socket_log() function. Rework TCP socket handling
|
||||
to not leak sockets.
|
||||
|
||||
--- 9.3.5-P2 released ---
|
||||
|
||||
2406. [bug] Some operating systems have FD_SETSIZE set to a
|
||||
low value by default, which can cause resource
|
||||
exhaustion when many simultaneous connections are
|
||||
open. Linux in particular makes it difficult to
|
||||
increase this value. To use more sockets with
|
||||
select(), set ISC_SOCKET_FDSETSIZE. Example:
|
||||
STD_CDEFINES="-DISC_SOCKET_FDSETSIZE=4096" ./configure
|
||||
(This should not be necessary in most cases, and
|
||||
never for an authoritative-only server.) [RT #18328]
|
||||
|
||||
2404. [port] hpux: files unlimited support.
|
||||
|
||||
2403. [bug] TSIG context leak. [RT #18341]
|
||||
|
||||
2402. [port] Support Solaris 2.11 and over. [RT #18362]
|
||||
|
||||
2401. [bug] Expect to get E[MN]FILE errno internal_accept()
|
||||
(from accept() or fcntl() system calls). [RT #18358]
|
||||
|
||||
2399. [bug] Abort timeout queries to reduce the number of open
|
||||
UDP sockets. [RT #18367]
|
||||
|
||||
2398. [bug] Improve file descriptor management. New,
|
||||
temporary, named.conf option reserved-sockets,
|
||||
default 512. [RT #18344]
|
||||
|
||||
2396. [bug] Don't set SO_REUSEADDR for randomized ports.
|
||||
[RT #18336]
|
||||
|
||||
2395. [port] Avoid warning and no effect from "files unlimited"
|
||||
on Linux when running as root. [RT #18335]
|
||||
|
||||
2394. [bug] Default configuration options set the limit for
|
||||
open files to 'unlimited' as described in the
|
||||
documentation. [RT #18331]
|
||||
|
||||
2392. [bug] remove 'grep -q' from acl test script, some platforms
|
||||
don't support it. [RT #18253]
|
||||
|
||||
--- 9.3.5-P1 released ---
|
||||
|
||||
2375. [security] Fully randomize UDP query ports to improve
|
||||
forgery resilience. [RT #17949]
|
||||
|
||||
--- 9.3.5 released ---
|
||||
|
||||
--- 9.3.5rc2 released ---
|
||||
|
||||
2338. [bug] check_ds() could be called with a non DS rdataset.
|
||||
[RT #17598]
|
||||
|
||||
2337. [bug] BUILD_LDFLAGS was not being correctly set. [RT #17614]
|
||||
|
||||
--- 9.3.5rc1 released ---
|
||||
|
||||
2328. [maint] Add AAAA addresses for A.ROOT-SERVERS.NET,
|
||||
F.ROOT-SERVERS.NET, H.ROOT-SERVERS.NET,
|
||||
J.ROOT-SERVERS.NET, K.ROOT-SERVERS.NET and
|
||||
M.ROOT-SERVERS.NET.
|
||||
|
||||
2323. [port] tru64: namespace clash. [RT #17547]
|
||||
|
||||
2322. [port] MacOS: work around the limitation of setrlimit()
|
||||
for RLIMIT_NOFILE. [RT #17526]
|
||||
|
||||
2321. [bug] Silence Coverity warnings in lib/dns/master.c,
|
||||
lib/dns/rbtdb.c, lib/isccfg/namedconf.c,
|
||||
lib/dns/tsig.c and bin/dnssec/dnssec-signzone.c.
|
||||
|
||||
2319. [bug] Silence Coverity warnings in
|
||||
lib/dns/rdata/in_1/apl_42.c. [RT #17469]
|
||||
|
||||
2318. [port] sunos fixes for libbind. [RT #17514]
|
||||
|
||||
2314. [bug] Uninitialized memory use on error path in
|
||||
bin/named/lwdnoop.c. [RT #17476]
|
||||
|
||||
2313. [cleanup] Silence Coverity warnings. Handle private stacks.
|
||||
[RT #17447] [RT #17478]
|
||||
|
||||
2312. [cleanup] Silence Coverity warning in lib/isc/unix/socket.c.
|
||||
[RT #17458]
|
||||
|
||||
2311. [func] Update ACL regression test. [RT #17462]
|
||||
|
||||
2310. [bug] dig, host, nslookup: flush stdout before emitting
|
||||
debug/fatal messages. [RT #17501]
|
||||
|
||||
2308. [cleanup] Silence Coverity warning in bin/named/controlconf.c.
|
||||
[RT #17495]
|
||||
|
||||
2307. [bug] Remove infinite loop from lib/dns/sdb.c. [RT #17496]
|
||||
|
||||
2305. [security] inet_network() buffer overflow. CVE-2008-0122.
|
||||
|
||||
2304. [bug] Check returns from all dns_rdata_tostruct() calls.
|
||||
[RT #17460]
|
||||
|
||||
2303. [bug] Remove unnecessary code from bin/named/lwdgnba.c.
|
||||
[RT #17471]
|
||||
|
||||
2302. [bug] Fix memset() calls in lib/tests/t_api.c. [RT #17472]
|
||||
|
||||
2301. [bug] Remove resource leak and fix error messages in
|
||||
bin/tests/system/lwresd/lwtest.c. [RT #17474]
|
||||
|
||||
2300. [bug] Fixed failure to close open file in
|
||||
bin/tests/names/t_names.c. [RT #17473]
|
||||
|
||||
2299. [bug] Remove unnecessary NULL check in
|
||||
bin/nsupdate/nsupdate.c. [RT #17475]
|
||||
|
||||
2298. [bug] isc_mutex_lock() failure not caught in
|
||||
bin/tests/timers/t_timers.c. [RT #17468]
|
||||
|
||||
2297. [bug] isc_entropy_createfilesource() failure not caught in
|
||||
bin/tests/dst/t_dst.c. [RT #17467]
|
||||
|
||||
2296. [port] Allow docbook stylesheet location to be specified to
|
||||
configure. [RT #17457]
|
||||
|
||||
2295. [bug] Silence static overrun error in bin/named/lwaddr.c.
|
||||
[RT #17459]
|
||||
|
||||
2293. [func] Add ACL regression test. [RT #17375]
|
||||
|
||||
2292. [bug] Log if the working directory is not writable.
|
||||
[RT #17312]
|
||||
|
||||
2291. [bug] PR_SET_DUMPABLE may be set too late. Also report
|
||||
failure to set PR_SET_DUMPABLE. [RT #17312]
|
||||
|
||||
2290. [bug] Let AD in the query signal that the client wants AD
|
||||
set in the response. [RT #17301]
|
||||
|
||||
2288. [port] win32: mark service as running when we have finished
|
||||
loading. [RT #17441]
|
||||
|
||||
2287. [bug] Use 'volatile' if the compiler supports it. [RT #17413]
|
||||
|
||||
2284. [bug] Memory leak in UPDATE prerequisite processing.
|
||||
[RT #17377]
|
||||
|
||||
2283. [bug] TSIG keys were not attaching to the memory
|
||||
context. TSIG keys should use the rings
|
||||
memory context rather than the clients memory
|
||||
context. [RT #17377]
|
||||
|
||||
2279. [bug] Use setsockopt(SO_NOSIGPIPE), when available,
|
||||
to protect applications from receiving spurious
|
||||
SIGPIPE signals when using the resolver.
|
||||
|
||||
2277. [bug] Empty zone names were not correctly being caught at
|
||||
in the post parse checks. [RT #17357]
|
||||
|
||||
--- 9.3.5b1 released ---
|
||||
|
||||
2273. [bug] Adjust log level to WARNING when saving inconsistant
|
||||
stub/slave master and journal files. [RT# 17279]
|
||||
|
||||
2272. [bug] Handle illegal dnssec-lookaside trust-anchor names.
|
||||
[RT #17262]
|
||||
|
||||
2270. [bug] dns_db_closeversion() version->writer could be reset
|
||||
before it is tested. [RT #17290]
|
||||
|
||||
2269. [contrib] dbus memory leaks and missing va_end calls. [RT #17232]
|
||||
|
||||
2265. [bug] Test that the memory context's basic_table is non NULL
|
||||
before freeing. [RT #17265]
|
||||
|
||||
2262. [bug] Error status from all but the last view could be
|
||||
lost. [RT #17292]
|
||||
|
||||
2258. [bug] Fallback from IXFR/TSIG to SOA/AXFR/TSIG broken.
|
||||
[RT #17241]
|
||||
|
||||
2257. [bug] win32: Use the full path to vcredist_x86.exe when
|
||||
calling it. [RT #17222]
|
||||
|
||||
2256. [bug] win32: Correctly register the installation location of
|
||||
bindevt.dll. [RT #17159]
|
||||
|
||||
2255. [maint] L.ROOT-SERVERS.NET is now 199.7.83.42.
|
||||
|
||||
2254. [bug] timer.c:dispatch() failed to lock timer->lock
|
||||
when reading timer->idle allowing it to see
|
||||
intermediate values as timer->idle was reset by
|
||||
isc_timer_touch(). [RT #17243]
|
||||
|
||||
2251. [doc] Update memstatistics-file documentation to reflect
|
||||
reality. Note there is behaviour change for BIND 9.5.
|
||||
[RT #17113]
|
||||
|
||||
2249. [bug] Only set Authentic Data bit if client requested
|
||||
DNSSEC, per RFC 3655 [RT #17175]
|
||||
|
||||
2248. [cleanup] Fix several errors reported by Coverity. [RT #17160]
|
||||
|
||||
2247. [doc] Sort doc/misc/options. [RT #17067]
|
||||
|
||||
2246. [bug] Make the startup of test servers (ans.pl) more
|
||||
robust. [RT #17147]
|
||||
|
||||
2245. [bug] Validating lack of DS records at trust anchors wasn't
|
||||
working. [RT #17151]
|
||||
|
||||
2238. [bug] It was possible to trigger a REQUIRE when a
|
||||
validation was cancelled. [RT #17106]
|
||||
|
||||
2237. [bug] libbind: res_init() was not thread aware. [RT #17123]
|
||||
|
||||
2236. [bug] dnssec-signzone failed to preserve the case of
|
||||
of wildcard owner names. [RT #17085]
|
||||
|
||||
2234. [port] Correct some compiler warnings on SCO OSr5 [RT #17134]
|
||||
|
||||
2229. [bug] Null pointer dereference on query pool creation
|
||||
failure. [RT #17133]
|
||||
|
||||
2232. [bug] dns_adb_findaddrinfo() could fail and return
|
||||
ISC_R_SUCCESS. [RT #17137]
|
||||
|
||||
2230. [bug] We could INSIST reading a corrupted journal.
|
||||
[RT #17132]
|
||||
|
||||
2228. [contrib] contrib: Change 2188 was incomplete.
|
||||
|
||||
2227. [cleanup] Tidied up the FAQ. [RT #17121]
|
||||
|
||||
2226. [bug] Fix build error. [RT #17124]
|
||||
|
||||
2225. [bug] More support for systems with no IPv4 addresses.
|
||||
[RT #17111]
|
||||
|
||||
2224. [bug] Defer journal compaction if a xfrin is in progress.
|
||||
[RT #17119]
|
||||
|
||||
2223. [bug] Make a new journal when compacting. [RT #17119]
|
||||
|
||||
2221. [bug] Set the event result code to reflect the actual
|
||||
record returned to caller when a cache update is
|
||||
rejected due to a more credible answer existing.
|
||||
[RT #17017]
|
||||
|
||||
2220. [bug] win32: Address a race condition in final shutdown of
|
||||
the Windows socket code. [RT #17028]
|
||||
|
||||
2218. [bug] Remove unnecessary REQUIRE from dns_validator_create().
|
||||
[RT #16976]
|
||||
|
||||
2216. [cleanup] Fix a number of errors reported by Coverity.
|
||||
[RT #17094]
|
||||
|
||||
2214. [bug] Deregister OpenSSL lock callback when cleaning
|
||||
up. [RT #17098]
|
||||
|
||||
2213. [bug] SIG0 diagnostic failure messages were looking at the
|
||||
wrong status code. [RT #17101]
|
||||
|
||||
2210. [bug] Deleting class specific records via UPDATE could
|
||||
fail. [RT #17074]
|
||||
|
||||
2209. [port] osx: linking against user supplied static OpenSSL
|
||||
libraries failed as the system ones were still being
|
||||
found. [RT #17078]
|
||||
|
||||
2208. [port] win32: make sure both build methods produce the
|
||||
same output. [RT #17058]
|
||||
|
||||
2205. [bug] libbind: change #2119 broke thread support. [RT #16982]
|
||||
|
||||
2200. [bug] The search for cached NSEC records was stopping to
|
||||
early leading to excessive DLV queries. [RT #16930]
|
||||
|
||||
2199. [bug] win32: don't call WSAStartup() while loading dlls.
|
||||
[RT #16911]
|
||||
|
||||
2198. [bug] win32: RegCloseKey() could be called when
|
||||
RegOpenKeyEx() failed. [RT #16911]
|
||||
|
||||
2197. [bug] Add INSIST to catch negative responses which are
|
||||
not setting the event result code appropriately.
|
||||
[RT #16909]
|
||||
|
||||
2196. [port] win32: yield processor while waiting for once to
|
||||
to complete. [RT #16958]
|
||||
|
||||
2194. [bug] Close journal before calling 'done' in xfrin.c.
|
||||
|
||||
2189. [bug] Handle socket() returning EINTR. [RT #15949]
|
||||
|
||||
2188. [contrib] queryperf: autoconf changes to make the search for
|
||||
libresolv or libbind more robust. [RT #16299]
|
||||
|
||||
2187. [bug] query_addds(), query_addwildcardproof() and
|
||||
query_addnxrrsetnsec() should take a version
|
||||
arguement. [RT #16368]
|
||||
|
||||
2186. [port] cygwin: libbind: check for struct sockaddr_storage
|
||||
independently of IPv6. [RT #16482]
|
||||
|
||||
2185. [port] sunos: libbind: check for ssize_t, memmove() and
|
||||
memchr(). [RT #16463]
|
||||
|
||||
2183. [bug] dnssec-signzone didn't handle offline private keys
|
||||
well. [RT #16832]
|
||||
|
||||
2182. [bug] dns_dispatch_createtcp() and dispatch_createudp()
|
||||
could return ISC_R_SUCCESS when they ran out of
|
||||
memory. [RT #16365]
|
||||
|
||||
2181. [port] sunos: libbind: add paths.h from BIND 8. [RT #16462]
|
||||
|
||||
2180. [cleanup] Remove bit test from 'compress_test' as they
|
||||
are no longer needed. [RT #16497]
|
||||
|
||||
2178. [bug] 'rndc reload' of a slave or stub zone resulted in
|
||||
a reference leak. [RT #16867]
|
||||
|
||||
2177. [bug] Array bounds overrun on read (rcodetext) at
|
||||
debug level 10+. [RT #16798]
|
||||
|
||||
2176. [contrib] dbus update to handle race condition during
|
||||
initialisation (Bugzilla 235809). [RT #16842]
|
||||
|
||||
2175. [bug] win32: windows broadcast condition variable support
|
||||
was broken. [RT #16592]
|
||||
|
||||
2174. [bug] I/O errors should always be fatal when reading
|
||||
master files. [RT #16825]
|
||||
|
||||
2173. [port] win32: When compiling with MSVS 2005 SP1 we also
|
||||
need to ship Microsoft.VC80.MFCLOC.
|
||||
|
||||
2172. [bug] query_addsoa() was being called with a non zone db.
|
||||
[RT #16834]
|
||||
|
||||
2171. [bug] Handle breaks in DNSSEC trust chains where the parent
|
||||
servers are not DS aware (DS queries to the parent
|
||||
return a referral to the child).
|
||||
|
||||
2169. [bug] host, nslookup: when reporting NXDOMAIN report the
|
||||
given name and not the last name searched for.
|
||||
[RT #16763]
|
||||
|
||||
2168. [bug] nsupdate: in non-interactive mode treat syntax errors
|
||||
as fatal errors. [RT #16785]
|
||||
|
||||
2166. [bug] When running in batch mode, dig could misinterpret
|
||||
a server address as a name to be looked up, causing
|
||||
unexpected output. [RT #16743]
|
||||
|
||||
2161. [bug] 'rndc flush' could report a false success. [RT #16698]
|
||||
|
||||
2160. [bug] libisc wasn't handling NULL ifa_addr pointers returned
|
||||
from getifaddrs(). [RT #16708]
|
||||
|
||||
2156. [bug] Fix node reference leaks in lookup.c:lookup_find(),
|
||||
resolver.c:validated() and resolver.c:cache_name().
|
||||
Fix a memory leak in rbtdb.c:free_noqname().
|
||||
@@ -89,6 +470,18 @@
|
||||
|
||||
2109. [port] libbind: silence aix 5.3 compiler warnings. [RT #16502]
|
||||
|
||||
--- 9.3.4-P1 released ---
|
||||
|
||||
2203. [security] Query id generation was cryptographically weak.
|
||||
[RT # 16915]
|
||||
|
||||
2193. [port] win32: BINDInstall.exe is now linked statically.
|
||||
[RT #16906]
|
||||
|
||||
2192. [port] win32: use vcredist_x86.exe to install Visual
|
||||
Studio's redistributable dlls if building with
|
||||
Visual Stdio 2005 or later.
|
||||
|
||||
--- 9.3.4 released ---
|
||||
|
||||
2126. [security] Serialise validation of type ANY responses. [RT #16555]
|
||||
@@ -354,7 +747,7 @@
|
||||
hex strings with comments. [RT #15814]
|
||||
|
||||
1974. [doc] List each of the zone types and associated zone
|
||||
options seperately in the ARM.
|
||||
options separately in the ARM.
|
||||
|
||||
1972. [contrib] DBUS dynamic forwarders integation from
|
||||
Jason Vas Dias <jvdias@redhat.com>.
|
||||
@@ -486,7 +879,7 @@
|
||||
query order sensitive. [RT #14933]
|
||||
|
||||
1905. [bug] Strings returned from cfg_obj_asstring() should be
|
||||
treated as read-only. [RT #15256]
|
||||
treated as read-only. [RT #15256]
|
||||
|
||||
1901. [cleanup] Don't add DNSKEY records to the additional section.
|
||||
|
||||
@@ -1331,7 +1724,7 @@
|
||||
1568. [bug] nsupdate now reports that the update failed in
|
||||
interactive mode. [RT# 10236]
|
||||
|
||||
1567. [bug] B.ROOT-SERVERS.NET is now 192.228.79.201.
|
||||
1567. [maint] B.ROOT-SERVERS.NET is now 192.228.79.201.
|
||||
|
||||
1566. [port] Support for the cmsg framework on Solaris and HP/UX.
|
||||
This also solved the problem that match-destinations
|
||||
@@ -2274,7 +2667,7 @@
|
||||
1399. [bug] Use serial number arithmetic when testing SIG
|
||||
timestamps. [RT #4268]
|
||||
|
||||
1397. [bug] J.ROOT-SERVERS.NET is now 192.58.128.30.
|
||||
1397. [maint] J.ROOT-SERVERS.NET is now 192.58.128.30.
|
||||
|
||||
1389. [bug] named could fail to rotate long log files. [RT #3666]
|
||||
|
||||
@@ -5822,7 +6215,7 @@
|
||||
and has been removed.
|
||||
|
||||
170. [cleanup] Remove inter server consistancy checks from zone,
|
||||
these should return as a seperate module in 9.1.
|
||||
these should return as a separate module in 9.1.
|
||||
dns_zone_checkservers(), dns_zone_checkparents(),
|
||||
dns_zone_checkchildren(), dns_zone_checkglue().
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
Copyright (C) 1996-2003 Internet Software Consortium.
|
||||
|
||||
Permission to use, copy, modify, and distribute this software for any
|
||||
Permission to use, copy, modify, and/or distribute this software for any
|
||||
purpose with or without fee is hereby granted, provided that the above
|
||||
copyright notice and this permission notice appear in all copies.
|
||||
|
||||
@@ -13,7 +13,7 @@ LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
$Id: COPYRIGHT,v 1.6.2.2.8.5 2007/01/08 02:45:03 marka Exp $
|
||||
$Id: COPYRIGHT,v 1.6.2.2.8.7 2008/01/02 23:45:32 tbox Exp $
|
||||
|
||||
Portions Copyright (C) 1996-2001 Nominum, Inc.
|
||||
|
||||
|
||||
+2
-2
@@ -1,7 +1,7 @@
|
||||
# Copyright (C) 2004, 2006, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 1998-2003 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and distribute this software for any
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
@@ -13,7 +13,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: Makefile.in,v 1.41.2.2.2.6 2007/01/18 00:06:04 marka Exp $
|
||||
# $Id: Makefile.in,v 1.41.2.2.2.7 2007/08/28 07:19:07 tbox Exp $
|
||||
|
||||
srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,12 +15,11 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: check-tool.c,v 1.4.12.9 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: check-tool.c,v 1.4.12.11 2007/09/13 05:18:07 each Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
#include <stdio.h>
|
||||
#include <string.h>
|
||||
|
||||
#include "check-tool.h"
|
||||
#include <isc/util.h>
|
||||
@@ -29,6 +28,7 @@
|
||||
#include <isc/log.h>
|
||||
#include <isc/region.h>
|
||||
#include <isc/stdio.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/types.h>
|
||||
|
||||
#include <dns/fixedname.h>
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: check-tool.h,v 1.2.12.7 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: check-tool.h,v 1.2.12.8 2007/08/28 07:19:07 tbox Exp $ */
|
||||
|
||||
#ifndef CHECK_TOOL_H
|
||||
#define CHECK_TOOL_H
|
||||
|
||||
@@ -13,7 +13,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: named-checkconf.8,v 1.11.12.11 2007/01/18 04:20:22 marka Exp $
|
||||
.\" $Id: named-checkconf.8,v 1.11.12.13 2007/06/20 02:26:23 marka Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
@@ -42,7 +42,7 @@ checks the syntax, but not the semantics, of a named configuration file.
|
||||
.PP
|
||||
\-t \fIdirectory\fR
|
||||
.RS 4
|
||||
chroot to
|
||||
Chroot to
|
||||
\fIdirectory\fR
|
||||
so that include directives in the configuration file are processed as if run by a similarly chrooted named.
|
||||
.RE
|
||||
@@ -56,7 +56,7 @@ program and exit.
|
||||
.PP
|
||||
\-z
|
||||
.RS 4
|
||||
Perform a check load the master zonefiles found in
|
||||
Perform a test load of all master zones found in
|
||||
\fInamed.conf\fR.
|
||||
.RE
|
||||
.PP
|
||||
@@ -77,6 +77,7 @@ returns an exit status of 1 if errors were detected and 0 otherwise.
|
||||
.SH "SEE ALSO"
|
||||
.PP
|
||||
\fBnamed\fR(8),
|
||||
\fBnamed\-checkzone\fR(8),
|
||||
BIND 9 Administrator Reference Manual.
|
||||
.SH "AUTHOR"
|
||||
.PP
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: named-checkconf.c,v 1.12.12.13 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: named-checkconf.c,v 1.12.12.14 2007/08/28 07:19:07 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
|
||||
@@ -5,7 +5,7 @@
|
||||
- Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
-
|
||||
- Permission to use, copy, modify, and distribute this software for any
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
@@ -18,7 +18,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: named-checkconf.docbook,v 1.3.2.1.8.10 2007/01/29 22:14:52 sra Exp $ -->
|
||||
<!-- $Id: named-checkconf.docbook,v 1.3.2.1.8.13 2007/08/28 07:19:07 tbox Exp $ -->
|
||||
|
||||
<refentry>
|
||||
<refentryinfo>
|
||||
@@ -79,7 +79,7 @@
|
||||
<term>-t <replaceable class="parameter">directory</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
chroot to <filename>directory</filename> so that include
|
||||
Chroot to <filename>directory</filename> so that include
|
||||
directives in the configuration file are processed as if
|
||||
run by a similarly chrooted named.
|
||||
</para>
|
||||
@@ -100,7 +100,7 @@
|
||||
<term>-z</term>
|
||||
<listitem>
|
||||
<para>
|
||||
Perform a check load the master zonefiles found in
|
||||
Perform a test load of all master zones found in
|
||||
<filename>named.conf</filename>.
|
||||
</para>
|
||||
</listitem>
|
||||
@@ -144,6 +144,9 @@
|
||||
<refentrytitle>named</refentrytitle>
|
||||
<manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>named-checkzone</refentrytitle><manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citetitle>BIND 9 Administrator Reference Manual</citetitle>.
|
||||
</para>
|
||||
</refsect1>
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: named-checkconf.html,v 1.5.2.1.4.19 2007/01/26 23:27:33 marka Exp $ -->
|
||||
<!-- $Id: named-checkconf.html,v 1.5.2.1.4.21 2007/06/20 02:26:23 marka Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
@@ -43,7 +43,7 @@
|
||||
<div class="variablelist"><dl>
|
||||
<dt><span class="term">-t <em class="replaceable"><code>directory</code></em></span></dt>
|
||||
<dd><p>
|
||||
chroot to <code class="filename">directory</code> so that include
|
||||
Chroot to <code class="filename">directory</code> so that include
|
||||
directives in the configuration file are processed as if
|
||||
run by a similarly chrooted named.
|
||||
</p></dd>
|
||||
@@ -54,7 +54,7 @@
|
||||
</p></dd>
|
||||
<dt><span class="term">-z</span></dt>
|
||||
<dd><p>
|
||||
Perform a check load the master zonefiles found in
|
||||
Perform a test load of all master zones found in
|
||||
<code class="filename">named.conf</code>.
|
||||
</p></dd>
|
||||
<dt><span class="term">-j</span></dt>
|
||||
@@ -79,11 +79,12 @@
|
||||
<a name="id2543492"></a><h2>SEE ALSO</h2>
|
||||
<p>
|
||||
<span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">named-checkzone</span>(8)</span>,
|
||||
<em class="citetitle">BIND 9 Administrator Reference Manual</em>.
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543515"></a><h2>AUTHOR</h2>
|
||||
<a name="id2543524"></a><h2>AUTHOR</h2>
|
||||
<p>
|
||||
<span class="corpauthor">Internet Systems Consortium</span>
|
||||
</p>
|
||||
|
||||
@@ -13,7 +13,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: named-checkzone.8,v 1.11.2.1.8.14 2007/01/18 04:20:22 marka Exp $
|
||||
.\" $Id: named-checkzone.8,v 1.11.2.1.8.16 2007/06/20 02:26:23 marka Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
@@ -99,7 +99,7 @@ Write zone output to
|
||||
.PP
|
||||
\-t \fIdirectory\fR
|
||||
.RS 4
|
||||
chroot to
|
||||
Chroot to
|
||||
\fIdirectory\fR
|
||||
so that include directives in the configuration file are processed as if run by a similarly chrooted named.
|
||||
.RE
|
||||
@@ -133,6 +133,7 @@ returns an exit status of 1 if errors were detected and 0 otherwise.
|
||||
.SH "SEE ALSO"
|
||||
.PP
|
||||
\fBnamed\fR(8),
|
||||
\fBnamed\-checkconf\fR(8),
|
||||
RFC 1035,
|
||||
BIND 9 Administrator Reference Manual.
|
||||
.SH "AUTHOR"
|
||||
|
||||
@@ -5,7 +5,7 @@
|
||||
- Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
-
|
||||
- Permission to use, copy, modify, and distribute this software for any
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
@@ -18,7 +18,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: named-checkzone.docbook,v 1.3.2.2.8.16 2007/01/29 22:14:52 sra Exp $ -->
|
||||
<!-- $Id: named-checkzone.docbook,v 1.3.2.2.8.19 2007/08/28 07:19:07 tbox Exp $ -->
|
||||
|
||||
<refentry>
|
||||
<refentryinfo>
|
||||
@@ -170,7 +170,7 @@
|
||||
<term>-t <replaceable class="parameter">directory</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
chroot to <filename>directory</filename> so that include
|
||||
Chroot to <filename>directory</filename> so that include
|
||||
directives in the configuration file are processed as if
|
||||
run by a similarly chrooted named.
|
||||
</para>
|
||||
@@ -235,6 +235,9 @@
|
||||
<refentrytitle>named</refentrytitle>
|
||||
<manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>named-checkconf</refentrytitle><manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citetitle>RFC 1035</citetitle>,
|
||||
<citetitle>BIND 9 Administrator Reference Manual</citetitle>.
|
||||
</para>
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: named-checkzone.html,v 1.5.2.2.4.21 2007/01/26 23:27:33 marka Exp $ -->
|
||||
<!-- $Id: named-checkzone.html,v 1.5.2.2.4.23 2007/06/20 02:26:23 marka Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
@@ -85,7 +85,7 @@
|
||||
</p></dd>
|
||||
<dt><span class="term">-t <em class="replaceable"><code>directory</code></em></span></dt>
|
||||
<dd><p>
|
||||
chroot to <code class="filename">directory</code> so that include
|
||||
Chroot to <code class="filename">directory</code> so that include
|
||||
directives in the configuration file are processed as if
|
||||
run by a similarly chrooted named.
|
||||
</p></dd>
|
||||
@@ -121,12 +121,13 @@
|
||||
<a name="id2543713"></a><h2>SEE ALSO</h2>
|
||||
<p>
|
||||
<span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">named-checkconf</span>(8)</span>,
|
||||
<em class="citetitle">RFC 1035</em>,
|
||||
<em class="citetitle">BIND 9 Administrator Reference Manual</em>.
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543739"></a><h2>AUTHOR</h2>
|
||||
<a name="id2543748"></a><h2>AUTHOR</h2>
|
||||
<p>
|
||||
<span class="corpauthor">Internet Systems Consortium</span>
|
||||
</p>
|
||||
|
||||
+2
-2
@@ -1,7 +1,7 @@
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and distribute this software for any
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
@@ -13,7 +13,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: Makefile.in,v 1.25.12.14 2007/01/18 00:06:04 marka Exp $
|
||||
# $Id: Makefile.in,v 1.25.12.15 2007/08/28 07:19:07 tbox Exp $
|
||||
|
||||
srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
|
||||
+12
-12
@@ -13,7 +13,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: dig.1,v 1.14.2.4.2.15 2007/01/30 00:11:47 marka Exp $
|
||||
.\" $Id: dig.1,v 1.14.2.4.2.18 2007/05/16 06:10:54 marka Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
@@ -50,7 +50,7 @@ Although
|
||||
\fBdig\fR
|
||||
is normally used with command\-line arguments, it also has a batch mode of operation for reading lookup requests from a file. A brief summary of its command\-line arguments and options is printed when the
|
||||
\fB\-h\fR
|
||||
option is given. Unlike earlier versions, the BIND9 implementation of
|
||||
option is given. Unlike earlier versions, the BIND 9 implementation of
|
||||
\fBdig\fR
|
||||
allows multiple lookups to be issued from the command line.
|
||||
.PP
|
||||
@@ -126,14 +126,14 @@ The default query class (IN for internet) is overridden by the
|
||||
\fB\-c\fR
|
||||
option.
|
||||
\fIclass\fR
|
||||
is any valid class, such as HS for Hesiod records or CH for CHAOSNET records.
|
||||
is any valid class, such as HS for Hesiod records or CH for Chaosnet records.
|
||||
.PP
|
||||
The
|
||||
\fB\-f\fR
|
||||
option makes
|
||||
\fBdig \fR
|
||||
operate in batch mode by reading a list of lookup requests to process from the file
|
||||
\fIfilename\fR. The file contains a number of queries, one per line. Each entry in the file should be organised in the same way they would be presented as queries to
|
||||
\fIfilename\fR. The file contains a number of queries, one per line. Each entry in the file should be organized in the same way they would be presented as queries to
|
||||
\fBdig\fR
|
||||
using the command\-line interface.
|
||||
.PP
|
||||
@@ -158,7 +158,7 @@ to only use IPv6 query transport.
|
||||
The
|
||||
\fB\-t\fR
|
||||
option sets the query type to
|
||||
\fItype\fR. It can be any valid query type which is supported in BIND9. The default query type "A", unless the
|
||||
\fItype\fR. It can be any valid query type which is supported in BIND 9. The default query type is "A", unless the
|
||||
\fB\-x\fR
|
||||
option is supplied to indicate a reverse lookup. A zone transfer can be requested by specifying a type of AXFR. When an incremental zone transfer (IXFR) is required,
|
||||
\fItype\fR
|
||||
@@ -166,7 +166,7 @@ is set to
|
||||
ixfr=N. The incremental zone transfer will contain the changes made to the zone since the serial number in the zone's SOA record was
|
||||
\fIN\fR.
|
||||
.PP
|
||||
Reverse lookups \- mapping addresses to names \- are simplified by the
|
||||
Reverse lookups \(em mapping addresses to names \(em are simplified by the
|
||||
\fB\-x\fR
|
||||
option.
|
||||
\fIaddr\fR
|
||||
@@ -217,7 +217,7 @@ to negate the meaning of that keyword. Other keywords assign values to options l
|
||||
.PP
|
||||
\fB+[no]tcp\fR
|
||||
.RS 4
|
||||
Use [do not use] TCP when querying name servers. The default behaviour is to use UDP unless an AXFR or IXFR query is requested, in which case a TCP connection is used.
|
||||
Use [do not use] TCP when querying name servers. The default behavior is to use UDP unless an AXFR or IXFR query is requested, in which case a TCP connection is used.
|
||||
.RE
|
||||
.PP
|
||||
\fB+[no]vc\fR
|
||||
@@ -314,7 +314,7 @@ makes iterative queries to resolve the name being looked up. It will follow refe
|
||||
.PP
|
||||
\fB+[no]cmd\fR
|
||||
.RS 4
|
||||
toggles the printing of the initial comment in the output identifying the version of
|
||||
Toggles the printing of the initial comment in the output identifying the version of
|
||||
\fBdig\fR
|
||||
and the query options that have been applied. This comment is printed by default.
|
||||
.RE
|
||||
@@ -338,7 +338,7 @@ Toggle the display of comment lines in the output. The default is to print comme
|
||||
.PP
|
||||
\fB+[no]stats\fR
|
||||
.RS 4
|
||||
This query option toggles the printing of statistics: when the query was made, the size of the reply and so on. The default behaviour is to print the query statistics.
|
||||
This query option toggles the printing of statistics: when the query was made, the size of the reply and so on. The default behavior is to print the query statistics.
|
||||
.RE
|
||||
.PP
|
||||
\fB+[no]qr\fR
|
||||
@@ -375,7 +375,7 @@ Set or clear all display flags.
|
||||
.RS 4
|
||||
Sets the timeout for a query to
|
||||
\fIT\fR
|
||||
seconds. The default time out is 5 seconds. An attempt to set
|
||||
seconds. The default timeout is 5 seconds. An attempt to set
|
||||
\fIT\fR
|
||||
to less than 1 will result in a query timeout of 1 second being applied.
|
||||
.RE
|
||||
@@ -428,7 +428,7 @@ output.
|
||||
.PP
|
||||
\fB+[no]fail\fR
|
||||
.RS 4
|
||||
Do not try the next server if you receive a SERVFAIL. The default is to not try the next server which is the reverse of normal stub resolver behaviour.
|
||||
Do not try the next server if you receive a SERVFAIL. The default is to not try the next server which is the reverse of normal stub resolver behavior.
|
||||
.RE
|
||||
.PP
|
||||
\fB+[no]besteffort\fR
|
||||
@@ -464,7 +464,7 @@ Requires dig be compiled with \-DDIG_SIGCHASE.
|
||||
.PP
|
||||
\fB+[no]topdown\fR
|
||||
.RS 4
|
||||
When chasing DNSSEC signature chains perform a top down validation. Requires dig be compiled with \-DDIG_SIGCHASE.
|
||||
When chasing DNSSEC signature chains perform a top\-down validation. Requires dig be compiled with \-DDIG_SIGCHASE.
|
||||
.RE
|
||||
.SH "MULTIPLE QUERIES"
|
||||
.PP
|
||||
|
||||
+52
-65
@@ -1,8 +1,8 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2006 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: dig.c,v 1.157.2.13.2.31 2006/07/22 23:52:57 marka Exp $ */
|
||||
/* $Id: dig.c,v 1.157.2.13.2.35 2007/08/28 07:19:07 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
#include <stdlib.h>
|
||||
@@ -625,42 +625,6 @@ printgreeting(int argc, char **argv, dig_lookup_t *lookup) {
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
* Reorder an argument list so that server names all come at the end.
|
||||
* This is a bit of a hack, to allow batch-mode processing to properly
|
||||
* handle the server options.
|
||||
*/
|
||||
static void
|
||||
reorder_args(int argc, char *argv[]) {
|
||||
int i, j;
|
||||
char *ptr;
|
||||
int end;
|
||||
|
||||
debug("reorder_args()");
|
||||
end = argc - 1;
|
||||
while (argv[end][0] == '@') {
|
||||
end--;
|
||||
if (end == 0)
|
||||
return;
|
||||
}
|
||||
debug("arg[end]=%s", argv[end]);
|
||||
for (i = 1; i < end - 1; i++) {
|
||||
if (argv[i][0] == '@') {
|
||||
debug("arg[%d]=%s", i, argv[i]);
|
||||
ptr = argv[i];
|
||||
for (j = i + 1; j < end; j++) {
|
||||
debug("Moving %s to %d", argv[j], j - 1);
|
||||
argv[j - 1] = argv[j];
|
||||
}
|
||||
debug("moving %s to end, %d", ptr, end - 1);
|
||||
argv[end - 1] = ptr;
|
||||
end--;
|
||||
if (end < 1)
|
||||
return;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
static isc_uint32_t
|
||||
parse_uint(char *arg, const char *desc, isc_uint32_t max) {
|
||||
isc_result_t result;
|
||||
@@ -1054,7 +1018,8 @@ static const char *single_dash_opts = "46dhimnv";
|
||||
static const char *dash_opts = "46bcdfhikmnptvyx";
|
||||
static isc_boolean_t
|
||||
dash_option(char *option, char *next, dig_lookup_t **lookup,
|
||||
isc_boolean_t *open_type_class)
|
||||
isc_boolean_t *open_type_class, isc_boolean_t *need_clone,
|
||||
int argc, char **argv, isc_boolean_t *firstarg)
|
||||
{
|
||||
char opt, *value, *ptr;
|
||||
isc_result_t result;
|
||||
@@ -1245,7 +1210,9 @@ dash_option(char *option, char *next, dig_lookup_t **lookup,
|
||||
keysecret[sizeof(keysecret)-1]=0;
|
||||
return (value_from_next);
|
||||
case 'x':
|
||||
*lookup = clone_lookup(default_lookup, ISC_TRUE);
|
||||
if (*need_clone)
|
||||
*lookup = clone_lookup(default_lookup, ISC_TRUE);
|
||||
*need_clone = ISC_TRUE;
|
||||
if (get_reverse(textname, sizeof(textname), value,
|
||||
ip6_int, ISC_FALSE) == ISC_R_SUCCESS) {
|
||||
strncpy((*lookup)->textname, textname,
|
||||
@@ -1259,6 +1226,10 @@ dash_option(char *option, char *next, dig_lookup_t **lookup,
|
||||
if (!(*lookup)->rdclassset)
|
||||
(*lookup)->rdclass = dns_rdataclass_in;
|
||||
(*lookup)->new_search = ISC_TRUE;
|
||||
if (*firstarg) {
|
||||
printgreeting(argc, argv, *lookup);
|
||||
*firstarg = ISC_FALSE;
|
||||
}
|
||||
ISC_LIST_APPEND(lookup_list, *lookup, link);
|
||||
} else {
|
||||
fprintf(stderr, "Invalid IP address %s\n", value);
|
||||
@@ -1349,6 +1320,8 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
|
||||
char rcfile[256];
|
||||
#endif
|
||||
char *input;
|
||||
int i;
|
||||
isc_boolean_t need_clone = ISC_TRUE;
|
||||
|
||||
/*
|
||||
* The semantics for parsing the args is a bit complex; if
|
||||
@@ -1396,7 +1369,9 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
|
||||
bargv[0] = argv[0];
|
||||
argv0 = argv[0];
|
||||
|
||||
reorder_args(bargc, (char **)bargv);
|
||||
for(i = 0; i < bargc; i++)
|
||||
debug(".digrc argv %d: %s",
|
||||
i, bargv[i]);
|
||||
parse_args(ISC_TRUE, ISC_TRUE, bargc,
|
||||
(char **)bargv);
|
||||
}
|
||||
@@ -1405,7 +1380,12 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
|
||||
#endif
|
||||
}
|
||||
|
||||
lookup = default_lookup;
|
||||
if (is_batchfile && !config_only) {
|
||||
/* Processing '-f batchfile'. */
|
||||
lookup = clone_lookup(default_lookup, ISC_TRUE);
|
||||
need_clone = ISC_FALSE;
|
||||
} else
|
||||
lookup = default_lookup;
|
||||
|
||||
rc = argc;
|
||||
rv = argv;
|
||||
@@ -1421,13 +1401,17 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
|
||||
} else if (rv[0][0] == '-') {
|
||||
if (rc <= 1) {
|
||||
if (dash_option(&rv[0][1], NULL,
|
||||
&lookup, &open_type_class)) {
|
||||
&lookup, &open_type_class,
|
||||
&need_clone, argc, argv,
|
||||
&firstarg)) {
|
||||
rc--;
|
||||
rv++;
|
||||
}
|
||||
} else {
|
||||
if (dash_option(&rv[0][1], rv[1],
|
||||
&lookup, &open_type_class)) {
|
||||
&lookup, &open_type_class,
|
||||
&need_clone, argc, argv,
|
||||
&firstarg)) {
|
||||
rc--;
|
||||
rv++;
|
||||
}
|
||||
@@ -1495,21 +1479,29 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
|
||||
continue;
|
||||
}
|
||||
}
|
||||
|
||||
if (!config_only) {
|
||||
lookup = clone_lookup(default_lookup,
|
||||
ISC_TRUE);
|
||||
if (need_clone)
|
||||
lookup = clone_lookup(default_lookup,
|
||||
ISC_TRUE);
|
||||
need_clone = ISC_TRUE;
|
||||
strncpy(lookup->textname, rv[0],
|
||||
sizeof(lookup->textname));
|
||||
lookup->textname[sizeof(lookup->textname)-1]=0;
|
||||
lookup->trace_root = ISC_TF(lookup->trace ||
|
||||
lookup->ns_search_only);
|
||||
lookup->new_search = ISC_TRUE;
|
||||
if (firstarg) {
|
||||
printgreeting(argc, argv, lookup);
|
||||
firstarg = ISC_FALSE;
|
||||
}
|
||||
ISC_LIST_APPEND(lookup_list, lookup, link);
|
||||
debug("looking up %s", lookup->textname);
|
||||
}
|
||||
/* XXX Error message */
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
* If we have a batchfile, seed the lookup list with the
|
||||
* first entry, then trust the callback in dighost_shutdown
|
||||
@@ -1544,15 +1536,20 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
|
||||
bargv[0] = argv[0];
|
||||
argv0 = argv[0];
|
||||
|
||||
reorder_args(bargc, (char **)bargv);
|
||||
for(i = 0; i < bargc; i++)
|
||||
debug("batch argv %d: %s", i, bargv[i]);
|
||||
parse_args(ISC_TRUE, ISC_FALSE, bargc, (char **)bargv);
|
||||
return;
|
||||
}
|
||||
return;
|
||||
}
|
||||
/*
|
||||
* If no lookup specified, search for root
|
||||
*/
|
||||
if ((lookup_list.head == NULL) && !config_only) {
|
||||
lookup = clone_lookup(default_lookup, ISC_TRUE);
|
||||
if (need_clone)
|
||||
lookup = clone_lookup(default_lookup, ISC_TRUE);
|
||||
need_clone = ISC_TRUE;
|
||||
lookup->trace_root = ISC_TF(lookup->trace ||
|
||||
lookup->ns_search_only);
|
||||
lookup->new_search = ISC_TRUE;
|
||||
@@ -1564,10 +1561,9 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
|
||||
firstarg = ISC_FALSE;
|
||||
}
|
||||
ISC_LIST_APPEND(lookup_list, lookup, link);
|
||||
} else if (!config_only && firstarg) {
|
||||
printgreeting(argc, argv, lookup);
|
||||
firstarg = ISC_FALSE;
|
||||
}
|
||||
if (!need_clone)
|
||||
destroy_lookup(lookup);
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -1581,7 +1577,7 @@ dighost_shutdown(void) {
|
||||
int bargc;
|
||||
char *bargv[16];
|
||||
char *input;
|
||||
|
||||
int i;
|
||||
|
||||
if (batchname == NULL) {
|
||||
isc_app_shutdown();
|
||||
@@ -1609,7 +1605,8 @@ dighost_shutdown(void) {
|
||||
|
||||
bargv[0] = argv0;
|
||||
|
||||
reorder_args(bargc, (char **)bargv);
|
||||
for(i = 0; i < bargc; i++)
|
||||
debug("batch argv %d: %s", i, bargv[i]);
|
||||
parse_args(ISC_TRUE, ISC_FALSE, bargc, (char **)bargv);
|
||||
start_lookup();
|
||||
} else {
|
||||
@@ -1624,7 +1621,6 @@ dighost_shutdown(void) {
|
||||
int
|
||||
main(int argc, char **argv) {
|
||||
isc_result_t result;
|
||||
dig_server_t *s, *s2;
|
||||
|
||||
ISC_LIST_INIT(lookup_list);
|
||||
ISC_LIST_INIT(server_list);
|
||||
@@ -1645,16 +1641,7 @@ main(int argc, char **argv) {
|
||||
result = isc_app_onrun(mctx, global_task, onrun_callback, NULL);
|
||||
check_result(result, "isc_app_onrun");
|
||||
isc_app_run();
|
||||
s = ISC_LIST_HEAD(default_lookup->my_server_list);
|
||||
while (s != NULL) {
|
||||
debug("freeing server %p belonging to %p",
|
||||
s, default_lookup);
|
||||
s2 = s;
|
||||
s = ISC_LIST_NEXT(s, link);
|
||||
ISC_LIST_DEQUEUE(default_lookup->my_server_list, s2, link);
|
||||
isc_mem_free(mctx, s2);
|
||||
}
|
||||
isc_mem_free(mctx, default_lookup);
|
||||
destroy_lookup(default_lookup);
|
||||
if (batchname != NULL) {
|
||||
if (batchfp != stdin)
|
||||
fclose(batchfp);
|
||||
|
||||
+13
-13
@@ -5,7 +5,7 @@
|
||||
- Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
-
|
||||
- Permission to use, copy, modify, and distribute this software for any
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
@@ -18,7 +18,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: dig.docbook,v 1.4.2.7.4.16 2007/01/29 23:57:18 marka Exp $ -->
|
||||
<!-- $Id: dig.docbook,v 1.4.2.7.4.20 2007/08/28 07:19:07 tbox Exp $ -->
|
||||
|
||||
<refentry>
|
||||
|
||||
@@ -103,7 +103,7 @@ Although <command>dig</command> is normally used with command-line
|
||||
arguments, it also has a batch mode of operation for reading lookup
|
||||
requests from a file. A brief summary of its command-line arguments
|
||||
and options is printed when the <option>-h</option> option is given.
|
||||
Unlike earlier versions, the BIND9 implementation of
|
||||
Unlike earlier versions, the BIND 9 implementation of
|
||||
<command>dig</command> allows multiple lookups to be issued from the
|
||||
command line.
|
||||
</para>
|
||||
@@ -188,14 +188,14 @@ may be specified by appending "#<port>"
|
||||
<para>
|
||||
The default query class (IN for internet) is overridden by the
|
||||
<option>-c</option> option. <parameter>class</parameter> is any valid
|
||||
class, such as HS for Hesiod records or CH for CHAOSNET records.
|
||||
class, such as HS for Hesiod records or CH for Chaosnet records.
|
||||
</para>
|
||||
|
||||
<para>
|
||||
The <option>-f</option> option makes <command>dig </command> operate
|
||||
in batch mode by reading a list of lookup requests to process from the
|
||||
file <parameter>filename</parameter>. The file contains a number of
|
||||
queries, one per line. Each entry in the file should be organised in
|
||||
queries, one per line. Each entry in the file should be organized in
|
||||
the same way they would be presented as queries to
|
||||
<command>dig</command> using the command-line interface.
|
||||
</para>
|
||||
@@ -218,7 +218,7 @@ use IPv4 query transport. The <option>-6</option> option forces
|
||||
<para>
|
||||
The <option>-t</option> option sets the query type to
|
||||
<parameter>type</parameter>. It can be any valid query type which is
|
||||
supported in BIND9. The default query type "A", unless the
|
||||
supported in BIND 9. The default query type is "A", unless the
|
||||
<option>-x</option> option is supplied to indicate a reverse lookup.
|
||||
A zone transfer can be requested by specifying a type of AXFR. When
|
||||
an incremental zone transfer (IXFR) is required,
|
||||
@@ -229,7 +229,7 @@ since the serial number in the zone's SOA record was
|
||||
</para>
|
||||
|
||||
<para>
|
||||
Reverse lookups - mapping addresses to names - are simplified by the
|
||||
Reverse lookups — mapping addresses to names — are simplified by the
|
||||
<option>-x</option> option. <parameter>addr</parameter> is an IPv4
|
||||
address in dotted-decimal notation, or a colon-delimited IPv6 address.
|
||||
When this option is used, there is no need to provide the
|
||||
@@ -292,7 +292,7 @@ The query options are:
|
||||
<varlistentry><term><option>+[no]tcp</option></term>
|
||||
<listitem><para>
|
||||
Use [do not use] TCP when querying name servers. The default
|
||||
behaviour is to use UDP unless an AXFR or IXFR query is requested, in
|
||||
behavior is to use UDP unless an AXFR or IXFR query is requested, in
|
||||
which case a TCP connection is used.
|
||||
</para></listitem></varlistentry>
|
||||
|
||||
@@ -393,7 +393,7 @@ resolve the lookup.
|
||||
|
||||
<varlistentry><term><option>+[no]cmd</option></term>
|
||||
<listitem><para>
|
||||
toggles the printing of the initial comment in the output identifying
|
||||
Toggles the printing of the initial comment in the output identifying
|
||||
the version of <command>dig</command> and the query options that have
|
||||
been applied. This comment is printed by default.
|
||||
</para></listitem></varlistentry>
|
||||
@@ -421,7 +421,7 @@ print comments.
|
||||
<varlistentry><term><option>+[no]stats</option></term>
|
||||
<listitem><para>
|
||||
This query option toggles the printing of statistics: when the query
|
||||
was made, the size of the reply and so on. The default behaviour is
|
||||
was made, the size of the reply and so on. The default behavior is
|
||||
to print the query statistics.
|
||||
</para></listitem></varlistentry>
|
||||
|
||||
@@ -464,7 +464,7 @@ Set or clear all display flags.
|
||||
<listitem><para>
|
||||
|
||||
Sets the timeout for a query to
|
||||
<parameter>T</parameter> seconds. The default time out is 5 seconds.
|
||||
<parameter>T</parameter> seconds. The default timeout is 5 seconds.
|
||||
An attempt to set <parameter>T</parameter> to less than 1 will result
|
||||
in a query timeout of 1 second being applied.
|
||||
</para></listitem></varlistentry>
|
||||
@@ -518,7 +518,7 @@ of the <command>dig</command> output.
|
||||
<listitem><para>
|
||||
Do not try the next server if you receive a SERVFAIL. The default is
|
||||
to not try the next server which is the reverse of normal stub resolver
|
||||
behaviour.
|
||||
behavior.
|
||||
</para></listitem></varlistentry>
|
||||
|
||||
<varlistentry><term><option>+[no]besteffort</option></term>
|
||||
@@ -560,7 +560,7 @@ Chase DNSSEC signature chains. Requires dig be compiled with
|
||||
|
||||
<varlistentry><term><option>+[no]topdown</option></term>
|
||||
<listitem><para>
|
||||
When chasing DNSSEC signature chains perform a top down validation.
|
||||
When chasing DNSSEC signature chains perform a top-down validation.
|
||||
Requires dig be compiled with -DDIG_SIGCHASE.
|
||||
</para></listitem></varlistentry>
|
||||
|
||||
|
||||
+16
-16
@@ -14,7 +14,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: dig.html,v 1.6.2.4.2.20 2007/01/30 00:11:47 marka Exp $ -->
|
||||
<!-- $Id: dig.html,v 1.6.2.4.2.23 2007/05/16 06:10:54 marka Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
@@ -49,7 +49,7 @@ Although <span><strong class="command">dig</strong></span> is normally used with
|
||||
arguments, it also has a batch mode of operation for reading lookup
|
||||
requests from a file. A brief summary of its command-line arguments
|
||||
and options is printed when the <code class="option">-h</code> option is given.
|
||||
Unlike earlier versions, the BIND9 implementation of
|
||||
Unlike earlier versions, the BIND 9 implementation of
|
||||
<span><strong class="command">dig</strong></span> allows multiple lookups to be issued from the
|
||||
command line.
|
||||
</p>
|
||||
@@ -123,13 +123,13 @@ may be specified by appending "#<port>"
|
||||
<p>
|
||||
The default query class (IN for internet) is overridden by the
|
||||
<code class="option">-c</code> option. <em class="parameter"><code>class</code></em> is any valid
|
||||
class, such as HS for Hesiod records or CH for CHAOSNET records.
|
||||
class, such as HS for Hesiod records or CH for Chaosnet records.
|
||||
</p>
|
||||
<p>
|
||||
The <code class="option">-f</code> option makes <span><strong class="command">dig </strong></span> operate
|
||||
in batch mode by reading a list of lookup requests to process from the
|
||||
file <em class="parameter"><code>filename</code></em>. The file contains a number of
|
||||
queries, one per line. Each entry in the file should be organised in
|
||||
queries, one per line. Each entry in the file should be organized in
|
||||
the same way they would be presented as queries to
|
||||
<span><strong class="command">dig</strong></span> using the command-line interface.
|
||||
</p>
|
||||
@@ -149,7 +149,7 @@ use IPv4 query transport. The <code class="option">-6</code> option forces
|
||||
<p>
|
||||
The <code class="option">-t</code> option sets the query type to
|
||||
<em class="parameter"><code>type</code></em>. It can be any valid query type which is
|
||||
supported in BIND9. The default query type "A", unless the
|
||||
supported in BIND 9. The default query type is "A", unless the
|
||||
<code class="option">-x</code> option is supplied to indicate a reverse lookup.
|
||||
A zone transfer can be requested by specifying a type of AXFR. When
|
||||
an incremental zone transfer (IXFR) is required,
|
||||
@@ -159,7 +159,7 @@ since the serial number in the zone's SOA record was
|
||||
<em class="parameter"><code>N</code></em>.
|
||||
</p>
|
||||
<p>
|
||||
Reverse lookups - mapping addresses to names - are simplified by the
|
||||
Reverse lookups — mapping addresses to names — are simplified by the
|
||||
<code class="option">-x</code> option. <em class="parameter"><code>addr</code></em> is an IPv4
|
||||
address in dotted-decimal notation, or a colon-delimited IPv6 address.
|
||||
When this option is used, there is no need to provide the
|
||||
@@ -215,7 +215,7 @@ The query options are:
|
||||
<dt><span class="term"><code class="option">+[no]tcp</code></span></dt>
|
||||
<dd><p>
|
||||
Use [do not use] TCP when querying name servers. The default
|
||||
behaviour is to use UDP unless an AXFR or IXFR query is requested, in
|
||||
behavior is to use UDP unless an AXFR or IXFR query is requested, in
|
||||
which case a TCP connection is used.
|
||||
</p></dd>
|
||||
<dt><span class="term"><code class="option">+[no]vc</code></span></dt>
|
||||
@@ -301,7 +301,7 @@ resolve the lookup.
|
||||
</p></dd>
|
||||
<dt><span class="term"><code class="option">+[no]cmd</code></span></dt>
|
||||
<dd><p>
|
||||
toggles the printing of the initial comment in the output identifying
|
||||
Toggles the printing of the initial comment in the output identifying
|
||||
the version of <span><strong class="command">dig</strong></span> and the query options that have
|
||||
been applied. This comment is printed by default.
|
||||
</p></dd>
|
||||
@@ -325,7 +325,7 @@ print comments.
|
||||
<dt><span class="term"><code class="option">+[no]stats</code></span></dt>
|
||||
<dd><p>
|
||||
This query option toggles the printing of statistics: when the query
|
||||
was made, the size of the reply and so on. The default behaviour is
|
||||
was made, the size of the reply and so on. The default behavior is
|
||||
to print the query statistics.
|
||||
</p></dd>
|
||||
<dt><span class="term"><code class="option">+[no]qr</code></span></dt>
|
||||
@@ -361,7 +361,7 @@ Set or clear all display flags.
|
||||
<dd><p>
|
||||
|
||||
Sets the timeout for a query to
|
||||
<em class="parameter"><code>T</code></em> seconds. The default time out is 5 seconds.
|
||||
<em class="parameter"><code>T</code></em> seconds. The default timeout is 5 seconds.
|
||||
An attempt to set <em class="parameter"><code>T</code></em> to less than 1 will result
|
||||
in a query timeout of 1 second being applied.
|
||||
</p></dd>
|
||||
@@ -408,7 +408,7 @@ of the <span><strong class="command">dig</strong></span> output.
|
||||
<dd><p>
|
||||
Do not try the next server if you receive a SERVFAIL. The default is
|
||||
to not try the next server which is the reverse of normal stub resolver
|
||||
behaviour.
|
||||
behavior.
|
||||
</p></dd>
|
||||
<dt><span class="term"><code class="option">+[no]besteffort</code></span></dt>
|
||||
<dd><p>
|
||||
@@ -443,7 +443,7 @@ Chase DNSSEC signature chains. Requires dig be compiled with
|
||||
</dd>
|
||||
<dt><span class="term"><code class="option">+[no]topdown</code></span></dt>
|
||||
<dd><p>
|
||||
When chasing DNSSEC signature chains perform a top down validation.
|
||||
When chasing DNSSEC signature chains perform a top-down validation.
|
||||
Requires dig be compiled with -DDIG_SIGCHASE.
|
||||
</p></dd>
|
||||
</dl></div>
|
||||
@@ -452,7 +452,7 @@ Requires dig be compiled with -DDIG_SIGCHASE.
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2544552"></a><h2>MULTIPLE QUERIES</h2>
|
||||
<a name="id2544553"></a><h2>MULTIPLE QUERIES</h2>
|
||||
<p>
|
||||
The BIND 9 implementation of <span><strong class="command">dig </strong></span> supports
|
||||
specifying multiple queries on the command line (in addition to
|
||||
@@ -493,7 +493,7 @@ will not print the initial query when it looks up the NS records for
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2544611"></a><h2>FILES</h2>
|
||||
<a name="id2544612"></a><h2>FILES</h2>
|
||||
<p>
|
||||
<code class="filename">/etc/resolv.conf</code>
|
||||
</p>
|
||||
@@ -502,7 +502,7 @@ will not print the initial query when it looks up the NS records for
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2544630"></a><h2>SEE ALSO</h2>
|
||||
<a name="id2544631"></a><h2>SEE ALSO</h2>
|
||||
<p>
|
||||
<span class="citerefentry"><span class="refentrytitle">host</span>(1)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
|
||||
@@ -511,7 +511,7 @@ will not print the initial query when it looks up the NS records for
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2544737"></a><h2>BUGS </h2>
|
||||
<a name="id2544738"></a><h2>BUGS </h2>
|
||||
<p>
|
||||
There are probably too many query options.
|
||||
</p>
|
||||
|
||||
+63
-52
@@ -1,8 +1,8 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: dighost.c,v 1.221.2.19.2.40 2007/02/27 01:07:15 marka Exp $ */
|
||||
/* $Id: dighost.c,v 1.221.2.19.2.46.4.2 2008/07/23 23:16:25 marka Exp $ */
|
||||
|
||||
/*
|
||||
* Notice to programmers: Do not use this code as an example of how to
|
||||
@@ -462,6 +462,7 @@ void
|
||||
fatal(const char *format, ...) {
|
||||
va_list args;
|
||||
|
||||
fflush(stdout);
|
||||
fprintf(stderr, "%s: ", progname);
|
||||
va_start(args, format);
|
||||
vfprintf(stderr, format, args);
|
||||
@@ -479,6 +480,7 @@ debug(const char *format, ...) {
|
||||
va_list args;
|
||||
|
||||
if (debugging) {
|
||||
fflush(stdout);
|
||||
va_start(args, format);
|
||||
vfprintf(stderr, format, args);
|
||||
va_end(args);
|
||||
@@ -591,7 +593,7 @@ set_nameserver(char *opt) {
|
||||
opt, isc_result_totext(result));
|
||||
|
||||
flush_server_list();
|
||||
|
||||
|
||||
for (i = 0; i < count; i++) {
|
||||
isc_netaddr_fromsockaddr(&netaddr, &sockaddrs[i]);
|
||||
isc_netaddr_format(&netaddr, tmp, sizeof(tmp));
|
||||
@@ -858,7 +860,7 @@ setup_text_key(void) {
|
||||
result = isc_base64_decodestring(keysecret, &secretbuf);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto failure;
|
||||
|
||||
|
||||
secretsize = isc_buffer_usedlength(&secretbuf);
|
||||
|
||||
result = dns_name_fromtext(&keyname, namebuf,
|
||||
@@ -968,7 +970,7 @@ setup_system(void) {
|
||||
domain = NULL;
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
if (ndots == -1) {
|
||||
ndots = lwconf->ndots;
|
||||
debug("ndots is %d.", ndots);
|
||||
@@ -1027,7 +1029,7 @@ clear_searchlist(void) {
|
||||
void
|
||||
set_search_domain(char *domain) {
|
||||
dig_searchlist_t *search;
|
||||
|
||||
|
||||
clear_searchlist();
|
||||
search = make_searchlist_entry(domain);
|
||||
ISC_LIST_APPEND(search_list, search, link);
|
||||
@@ -1213,9 +1215,7 @@ clear_query(dig_query_t *query) {
|
||||
*/
|
||||
static isc_boolean_t
|
||||
try_clear_lookup(dig_lookup_t *lookup) {
|
||||
dig_server_t *s;
|
||||
dig_query_t *q;
|
||||
void *ptr;
|
||||
|
||||
REQUIRE(lookup != NULL);
|
||||
|
||||
@@ -1236,7 +1236,16 @@ try_clear_lookup(dig_lookup_t *lookup) {
|
||||
* At this point, we know there are no queries on the lookup,
|
||||
* so can make it go away also.
|
||||
*/
|
||||
debug("cleared");
|
||||
destroy_lookup(lookup);
|
||||
return (ISC_TRUE);
|
||||
}
|
||||
|
||||
void
|
||||
destroy_lookup(dig_lookup_t *lookup) {
|
||||
dig_server_t *s;
|
||||
void *ptr;
|
||||
|
||||
debug("destroy");
|
||||
s = ISC_LIST_HEAD(lookup->my_server_list);
|
||||
while (s != NULL) {
|
||||
debug("freeing server %p belonging to %p", s, lookup);
|
||||
@@ -1261,7 +1270,6 @@ try_clear_lookup(dig_lookup_t *lookup) {
|
||||
dst_context_destroy(&lookup->tsigctx);
|
||||
|
||||
isc_mem_free(mctx, lookup);
|
||||
return (ISC_TRUE);
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -1340,7 +1348,7 @@ start_lookup(void) {
|
||||
current_lookup->qrdtype_sigchase
|
||||
= current_lookup->qrdtype;
|
||||
current_lookup->qrdtype = dns_rdatatype_ns;
|
||||
|
||||
|
||||
current_lookup->rdclass_sigchase
|
||||
= current_lookup->rdclass;
|
||||
current_lookup->rdclass_sigchaseset
|
||||
@@ -1419,7 +1427,7 @@ followup_lookup(dns_message_t *msg, dig_query_t *query, dns_section_t section)
|
||||
INSIST(!free_now);
|
||||
|
||||
debug("following up %s", query->lookup->textname);
|
||||
|
||||
|
||||
for (result = dns_message_firstname(msg, section);
|
||||
result == ISC_R_SUCCESS;
|
||||
result = dns_message_nextname(msg, section)) {
|
||||
@@ -1454,7 +1462,8 @@ followup_lookup(dns_message_t *msg, dig_query_t *query, dns_section_t section)
|
||||
dns_rdataset_current(rdataset, &rdata);
|
||||
|
||||
query->lookup->nsfound++;
|
||||
(void)dns_rdata_tostruct(&rdata, &ns, NULL);
|
||||
result = dns_rdata_tostruct(&rdata, &ns, NULL);
|
||||
check_result(result, "dns_rdata_tostruct");
|
||||
dns_name_format(&ns.name, namestr, sizeof(namestr));
|
||||
dns_rdata_freestruct(&ns);
|
||||
|
||||
@@ -1910,7 +1919,7 @@ send_done(isc_task_t *_task, isc_event_t *event) {
|
||||
|
||||
for (b = ISC_LIST_HEAD(sevent->bufferlist);
|
||||
b != NULL;
|
||||
b = ISC_LIST_HEAD(sevent->bufferlist))
|
||||
b = ISC_LIST_HEAD(sevent->bufferlist))
|
||||
ISC_LIST_DEQUEUE(sevent->bufferlist, b, link);
|
||||
|
||||
query = event->ev_arg;
|
||||
@@ -1990,7 +1999,7 @@ bringup_timer(dig_query_t *query, unsigned int default_timeout) {
|
||||
&l->interval, global_task, connect_timeout,
|
||||
l, &l->timer);
|
||||
check_result(result, "isc_timer_create");
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
connect_done(isc_task_t *task, isc_event_t *event);
|
||||
@@ -2012,7 +2021,7 @@ send_tcp_connect(dig_query_t *query) {
|
||||
query->waiting_connect = ISC_TRUE;
|
||||
query->lookup->current_query = query;
|
||||
get_address(query->servname, port, &query->sockaddr);
|
||||
|
||||
|
||||
if (specified_source &&
|
||||
(isc_sockaddr_pf(&query->sockaddr) !=
|
||||
isc_sockaddr_pf(&bind_address))) {
|
||||
@@ -2038,14 +2047,15 @@ send_tcp_connect(dig_query_t *query) {
|
||||
sockcount++;
|
||||
debug("sockcount=%d", sockcount);
|
||||
if (specified_source)
|
||||
result = isc_socket_bind(query->sock, &bind_address);
|
||||
result = isc_socket_bind(query->sock, &bind_address,
|
||||
ISC_SOCKET_REUSEADDRESS);
|
||||
else {
|
||||
if ((isc_sockaddr_pf(&query->sockaddr) == AF_INET) &&
|
||||
have_ipv4)
|
||||
isc_sockaddr_any(&bind_any);
|
||||
else
|
||||
isc_sockaddr_any6(&bind_any);
|
||||
result = isc_socket_bind(query->sock, &bind_any);
|
||||
result = isc_socket_bind(query->sock, &bind_any, 0);
|
||||
}
|
||||
check_result(result, "isc_socket_bind");
|
||||
bringup_timer(query, TCP_TIMEOUT);
|
||||
@@ -2092,11 +2102,12 @@ send_udp(dig_query_t *query) {
|
||||
sockcount++;
|
||||
debug("sockcount=%d", sockcount);
|
||||
if (specified_source) {
|
||||
result = isc_socket_bind(query->sock, &bind_address);
|
||||
result = isc_socket_bind(query->sock, &bind_address,
|
||||
ISC_SOCKET_REUSEADDRESS);
|
||||
} else {
|
||||
isc_sockaddr_anyofpf(&bind_any,
|
||||
isc_sockaddr_pf(&query->sockaddr));
|
||||
result = isc_socket_bind(query->sock, &bind_any);
|
||||
result = isc_socket_bind(query->sock, &bind_any, 0);
|
||||
}
|
||||
check_result(result, "isc_socket_bind");
|
||||
|
||||
@@ -2481,7 +2492,8 @@ check_for_more_data(dig_query_t *query, dns_message_t *msg,
|
||||
goto next_rdata;
|
||||
/* Now we have an SOA. Work with it. */
|
||||
debug("got an SOA");
|
||||
(void)dns_rdata_tostruct(&rdata, &soa, NULL);
|
||||
result = dns_rdata_tostruct(&rdata, &soa, NULL);
|
||||
check_result(result, "dns_rdata_tostruct");
|
||||
serial = soa.serial;
|
||||
dns_rdata_freestruct(&soa);
|
||||
if (!query->first_soa_rcvd) {
|
||||
@@ -2793,7 +2805,7 @@ recv_done(isc_task_t *task, isc_event_t *event) {
|
||||
check_next_lookup(l);
|
||||
UNLOCK_LOOKUP;
|
||||
return;
|
||||
}
|
||||
}
|
||||
if (msg->rcode == dns_rcode_servfail && !l->servfail_stops) {
|
||||
dig_query_t *next = ISC_LIST_NEXT(query, link);
|
||||
if (l->current_query == query)
|
||||
@@ -2945,11 +2957,11 @@ recv_done(isc_task_t *task, isc_event_t *event) {
|
||||
|
||||
isc_buffer_usedregion(b, &r);
|
||||
result = isc_buffer_allocate(mctx, &buf, r.length);
|
||||
|
||||
|
||||
check_result(result, "isc_buffer_allocate");
|
||||
result = isc_buffer_copyregion(buf, &r);
|
||||
check_result(result, "isc_buffer_copyregion");
|
||||
|
||||
|
||||
result = dns_message_parse(msg_temp, buf, 0);
|
||||
|
||||
isc_buffer_free(&buf);
|
||||
@@ -3229,7 +3241,7 @@ destroy_libs(void) {
|
||||
#endif
|
||||
|
||||
debug("Destroy memory");
|
||||
|
||||
|
||||
#endif
|
||||
if (memdebugging != 0)
|
||||
isc_mem_stats(mctx, stderr);
|
||||
@@ -3273,7 +3285,7 @@ dump_database_section(dns_message_t *msg, int section)
|
||||
dns_message_currentname(msg, section, &msg_name);
|
||||
|
||||
for (rdataset = ISC_LIST_HEAD(msg_name->list); rdataset != NULL;
|
||||
rdataset = ISC_LIST_NEXT(rdataset, link)) {
|
||||
rdataset = ISC_LIST_NEXT(rdataset, link)) {
|
||||
dns_name_print(msg_name, stdout);
|
||||
printf("\n");
|
||||
print_rdataset(msg_name, rdataset, mctx);
|
||||
@@ -3296,7 +3308,7 @@ dump_database(void) {
|
||||
if (dns_message_firstname(msg->msg, DNS_SECTION_AUTHORITY)
|
||||
== ISC_R_SUCCESS)
|
||||
dump_database_section(msg->msg, DNS_SECTION_AUTHORITY);
|
||||
|
||||
|
||||
if (dns_message_firstname(msg->msg, DNS_SECTION_ADDITIONAL)
|
||||
== ISC_R_SUCCESS)
|
||||
dump_database_section(msg->msg, DNS_SECTION_ADDITIONAL);
|
||||
@@ -3328,7 +3340,7 @@ search_type(dns_name_t *name, dns_rdatatype_t type, dns_rdatatype_t covers) {
|
||||
if ((siginfo.covered == covers) ||
|
||||
(covers == dns_rdatatype_any)) {
|
||||
dns_rdata_reset(&sigrdata);
|
||||
dns_rdata_freestruct(&siginfo);
|
||||
dns_rdata_freestruct(&siginfo);
|
||||
return (rdataset);
|
||||
}
|
||||
dns_rdata_reset(&sigrdata);
|
||||
@@ -3535,7 +3547,7 @@ opentmpkey(isc_mem_t *mctx, const char *file, char **tempp, FILE **fp) {
|
||||
isc_mem_free(mctx, tempname);
|
||||
return (ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
|
||||
x = cp--;
|
||||
while (cp >= tempname && *cp == 'X') {
|
||||
isc_random_get(&which);
|
||||
@@ -3547,12 +3559,12 @@ opentmpkey(isc_mem_t *mctx, const char *file, char **tempp, FILE **fp) {
|
||||
tempnamekey = isc_mem_allocate(mctx, tempnamekeylen);
|
||||
if (tempnamekey == NULL)
|
||||
return (ISC_R_NOMEMORY);
|
||||
|
||||
|
||||
memset(tempnamekey, 0, tempnamekeylen);
|
||||
strncpy(tempnamekey, tempname, tempnamelen);
|
||||
strcat(tempnamekey ,".key");
|
||||
|
||||
|
||||
|
||||
if (isc_file_exists(tempnamekey)) {
|
||||
isc_mem_free(mctx, tempnamekey);
|
||||
isc_mem_free(mctx, tempname);
|
||||
@@ -3573,7 +3585,7 @@ opentmpkey(isc_mem_t *mctx, const char *file, char **tempp, FILE **fp) {
|
||||
|
||||
cleanup:
|
||||
isc_mem_free(mctx, tempname);
|
||||
|
||||
|
||||
return (result);
|
||||
}
|
||||
|
||||
@@ -3720,9 +3732,8 @@ prepare_lookup(dns_name_t *name)
|
||||
|
||||
dns_rdataset_current(chase_nsrdataset, &rdata);
|
||||
|
||||
(void)dns_rdata_tostruct(&rdata, &ns, NULL);
|
||||
|
||||
|
||||
result = dns_rdata_tostruct(&rdata, &ns, NULL);
|
||||
check_result(result, "dns_rdata_tostruct");
|
||||
|
||||
#ifdef __FOLLOW_GLUE__
|
||||
|
||||
@@ -3749,7 +3760,7 @@ prepare_lookup(dns_name_t *name)
|
||||
|
||||
|
||||
srv = make_server(namestr, namestr);
|
||||
|
||||
|
||||
ISC_LIST_APPEND(lookup->my_server_list,
|
||||
srv, link);
|
||||
}
|
||||
@@ -3779,7 +3790,7 @@ prepare_lookup(dns_name_t *name)
|
||||
|
||||
|
||||
srv = make_server(namestr, namestr);
|
||||
|
||||
|
||||
ISC_LIST_APPEND(lookup->my_server_list,
|
||||
srv, link);
|
||||
}
|
||||
@@ -3791,7 +3802,7 @@ prepare_lookup(dns_name_t *name)
|
||||
dns_name_print(&ns.name, stdout);
|
||||
printf("\n");
|
||||
srv = make_server(namestr, namestr);
|
||||
|
||||
|
||||
ISC_LIST_APPEND(lookup->my_server_list, srv, link);
|
||||
|
||||
#endif
|
||||
@@ -3963,7 +3974,7 @@ contains_trusted_key(dns_name_t *name, dns_rdataset_t *rdataset,
|
||||
do {
|
||||
dns_rdataset_current(rdataset, &rdata);
|
||||
INSIST(rdata.type == dns_rdatatype_dnskey);
|
||||
|
||||
|
||||
result = dns_dnssec_keyfromrdata(name, &rdata,
|
||||
mctx, &dnsseckey);
|
||||
check_result(result, "dns_dnssec_keyfromrdata");
|
||||
@@ -3973,7 +3984,7 @@ contains_trusted_key(dns_name_t *name, dns_rdataset_t *rdataset,
|
||||
if (dst_key_compare(tk_list.key[i], dnsseckey)
|
||||
== ISC_TRUE) {
|
||||
dns_rdata_reset(&rdata);
|
||||
|
||||
|
||||
printf(";; Ok, find a Trusted Key in the "
|
||||
"DNSKEY RRset: %d\n",
|
||||
dst_key_id(dnsseckey));
|
||||
@@ -4018,7 +4029,7 @@ sigchase_verify_sig(dns_name_t *name, dns_rdataset_t *rdataset,
|
||||
do {
|
||||
dns_rdataset_current(keyrdataset, &keyrdata);
|
||||
INSIST(keyrdata.type == dns_rdatatype_dnskey);
|
||||
|
||||
|
||||
result = dns_dnssec_keyfromrdata(name, &keyrdata,
|
||||
mctx, &dnsseckey);
|
||||
check_result(result, "dns_dnssec_keyfromrdata");
|
||||
@@ -4114,12 +4125,12 @@ sigchase_verify_ds(dns_name_t *name, dns_rdataset_t *keyrdataset,
|
||||
|
||||
result = dns_rdataset_first(keyrdataset);
|
||||
check_result(result, "empty KEY dataset");
|
||||
dns_rdata_init(&keyrdata);
|
||||
dns_rdata_init(&keyrdata);
|
||||
|
||||
do {
|
||||
dns_rdataset_current(keyrdataset, &keyrdata);
|
||||
INSIST(keyrdata.type == dns_rdatatype_dnskey);
|
||||
|
||||
|
||||
result = dns_dnssec_keyfromrdata(name, &keyrdata,
|
||||
mctx, &dnsseckey);
|
||||
check_result(result, "dns_dnssec_keyfromrdata");
|
||||
@@ -4146,8 +4157,8 @@ sigchase_verify_ds(dns_name_t *name, dns_rdataset_t *keyrdataset,
|
||||
" new DS rdata\n");
|
||||
return (result);
|
||||
}
|
||||
|
||||
|
||||
|
||||
|
||||
if (dns_rdata_compare(&dsrdata,
|
||||
&newdsrdata) == 0) {
|
||||
printf(";; OK a DS valids a DNSKEY"
|
||||
@@ -4155,7 +4166,7 @@ sigchase_verify_ds(dns_name_t *name, dns_rdataset_t *keyrdataset,
|
||||
printf(";; Now verify that this"
|
||||
" DNSKEY validates the "
|
||||
"DNSKEY RRset\n");
|
||||
|
||||
|
||||
result = sigchase_verify_sig_key(name,
|
||||
keyrdataset,
|
||||
dnsseckey,
|
||||
@@ -4166,7 +4177,7 @@ sigchase_verify_ds(dns_name_t *name, dns_rdataset_t *keyrdataset,
|
||||
dns_rdata_reset(&newdsrdata);
|
||||
dns_rdata_reset(&dsrdata);
|
||||
dst_key_free(&dnsseckey);
|
||||
|
||||
|
||||
return (result);
|
||||
}
|
||||
} else {
|
||||
@@ -4391,7 +4402,7 @@ sigchase_td(dns_message_t *msg)
|
||||
chase_sigrdataset = NULL;
|
||||
have_response = ISC_FALSE;
|
||||
have_delegation_ns = ISC_FALSE;
|
||||
|
||||
|
||||
dns_name_init(&tmp_name, NULL);
|
||||
result = child_of_zone(&chase_name, &chase_current_name,
|
||||
&tmp_name);
|
||||
@@ -4473,7 +4484,7 @@ sigchase_td(dns_message_t *msg)
|
||||
|
||||
|
||||
prepare_lookup(&chase_authority_name);
|
||||
|
||||
|
||||
have_response = ISC_FALSE;
|
||||
have_delegation_ns = ISC_FALSE;
|
||||
delegation_follow = ISC_TRUE;
|
||||
@@ -4788,7 +4799,7 @@ sigchase_bu(dns_message_t *msg)
|
||||
}
|
||||
printf(";; An NSEC prove the non-existence of a answers,"
|
||||
" Now we want validate this NSEC\n");
|
||||
|
||||
|
||||
dup_name(&rdata_name, &chase_name, mctx);
|
||||
free_name(&rdata_name, mctx);
|
||||
chase_rdataset = rdataset;
|
||||
@@ -5040,7 +5051,7 @@ prove_nx_type(dns_message_t *msg, dns_name_t *name, dns_rdataset_t *nsecset,
|
||||
|
||||
ret = dns_rdataset_first(nsecset);
|
||||
check_result(ret,"dns_rdataset_first");
|
||||
|
||||
|
||||
dns_rdataset_current(nsecset, &nsec);
|
||||
|
||||
ret = dns_nsec_typepresent(&nsec, type);
|
||||
|
||||
+3
-3
@@ -13,7 +13,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: host.1,v 1.11.2.1.4.11 2007/01/18 04:20:22 marka Exp $
|
||||
.\" $Id: host.1,v 1.11.2.1.4.12 2007/05/09 03:32:36 marka Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
@@ -130,7 +130,7 @@ makes. This should mean that the name server receiving the query will not attemp
|
||||
\fB\-r\fR
|
||||
option enables
|
||||
\fBhost\fR
|
||||
to mimic the behaviour of a name server by making non\-recursive queries and expecting to receive answers to those queries that are usually referrals to other name servers.
|
||||
to mimic the behavior of a name server by making non\-recursive queries and expecting to receive answers to those queries that are usually referrals to other name servers.
|
||||
.PP
|
||||
By default
|
||||
\fBhost\fR
|
||||
@@ -152,7 +152,7 @@ The
|
||||
\fB\-t\fR
|
||||
option is used to select the query type.
|
||||
\fItype\fR
|
||||
can be any recognised query type: CNAME, NS, SOA, SIG, KEY, AXFR, etc. When no query type is specified,
|
||||
can be any recognized query type: CNAME, NS, SOA, SIG, KEY, AXFR, etc. When no query type is specified,
|
||||
\fBhost\fR
|
||||
automatically selects an appropriate query type. By default it looks for A records, but if the
|
||||
\fB\-C\fR
|
||||
|
||||
+7
-5
@@ -1,8 +1,8 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2006 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: host.c,v 1.76.2.5.2.16 2006/05/23 04:43:47 marka Exp $ */
|
||||
/* $Id: host.c,v 1.76.2.5.2.19 2007/08/28 07:19:07 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
#include <limits.h>
|
||||
@@ -410,8 +410,10 @@ printmessage(dig_query_t *query, dns_message_t *msg, isc_boolean_t headers) {
|
||||
if (msg->rcode != 0) {
|
||||
char namestr[DNS_NAME_FORMATSIZE];
|
||||
dns_name_format(query->lookup->name, namestr, sizeof(namestr));
|
||||
printf("Host %s not found: %d(%s)\n", namestr,
|
||||
msg->rcode, rcodetext[msg->rcode]);
|
||||
printf("Host %s not found: %d(%s)\n",
|
||||
(msg->rcode != dns_rcode_nxdomain) ? namestr :
|
||||
query->lookup->textname, msg->rcode,
|
||||
rcodetext[msg->rcode]);
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
|
||||
@@ -5,7 +5,7 @@
|
||||
- Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
-
|
||||
- Permission to use, copy, modify, and distribute this software for any
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
@@ -18,7 +18,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: host.docbook,v 1.2.2.2.4.10 2007/01/29 22:14:53 sra Exp $ -->
|
||||
<!-- $Id: host.docbook,v 1.2.2.2.4.12 2007/08/28 07:19:07 tbox Exp $ -->
|
||||
|
||||
<refentry>
|
||||
|
||||
@@ -162,7 +162,7 @@ desired — bit in the query which <command>host</command> makes.
|
||||
This should mean that the name server receiving the query will not
|
||||
attempt to resolve <parameter>name</parameter>. The
|
||||
<option>-r</option> option enables <command>host</command> to mimic
|
||||
the behaviour of a name server by making non-recursive queries and
|
||||
the behavior of a name server by making non-recursive queries and
|
||||
expecting to receive answers to those queries that are usually
|
||||
referrals to other name servers.
|
||||
</para>
|
||||
@@ -182,7 +182,7 @@ use IPv4 query transport. The <option>-6</option> option forces
|
||||
|
||||
<para>
|
||||
The <option>-t</option> option is used to select the query type.
|
||||
<parameter>type</parameter> can be any recognised query type: CNAME,
|
||||
<parameter>type</parameter> can be any recognized query type: CNAME,
|
||||
NS, SOA, SIG, KEY, AXFR, etc. When no query type is specified,
|
||||
<command>host</command> automatically selects an appropriate query
|
||||
type. By default it looks for A records, but if the
|
||||
|
||||
+3
-3
@@ -14,7 +14,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: host.html,v 1.4.2.1.4.18 2007/01/26 23:27:33 marka Exp $ -->
|
||||
<!-- $Id: host.html,v 1.4.2.1.4.19 2007/05/09 03:32:36 marka Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
@@ -114,7 +114,7 @@ desired — bit in the query which <span><strong class="command">host</stron
|
||||
This should mean that the name server receiving the query will not
|
||||
attempt to resolve <em class="parameter"><code>name</code></em>. The
|
||||
<code class="option">-r</code> option enables <span><strong class="command">host</strong></span> to mimic
|
||||
the behaviour of a name server by making non-recursive queries and
|
||||
the behavior of a name server by making non-recursive queries and
|
||||
expecting to receive answers to those queries that are usually
|
||||
referrals to other name servers.
|
||||
</p>
|
||||
@@ -131,7 +131,7 @@ use IPv4 query transport. The <code class="option">-6</code> option forces
|
||||
</p>
|
||||
<p>
|
||||
The <code class="option">-t</code> option is used to select the query type.
|
||||
<em class="parameter"><code>type</code></em> can be any recognised query type: CNAME,
|
||||
<em class="parameter"><code>type</code></em> can be any recognized query type: CNAME,
|
||||
NS, SOA, SIG, KEY, AXFR, etc. When no query type is specified,
|
||||
<span><strong class="command">host</strong></span> automatically selects an appropriate query
|
||||
type. By default it looks for A records, but if the
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2006 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: dig.h,v 1.71.2.6.2.15 2006/12/07 06:07:56 marka Exp $ */
|
||||
/* $Id: dig.h,v 1.71.2.6.2.18 2007/08/28 07:19:07 tbox Exp $ */
|
||||
|
||||
#ifndef DIG_H
|
||||
#define DIG_H
|
||||
@@ -283,6 +283,9 @@ check_result(isc_result_t result, const char *msg);
|
||||
void
|
||||
setup_lookup(dig_lookup_t *lookup);
|
||||
|
||||
void
|
||||
destroy_lookup(dig_lookup_t *lookup);
|
||||
|
||||
void
|
||||
do_lookup(dig_lookup_t *lookup);
|
||||
|
||||
|
||||
+3
-3
@@ -12,7 +12,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: nslookup.1,v 1.1.6.10 2007/01/30 00:11:47 marka Exp $
|
||||
.\" $Id: nslookup.1,v 1.1.6.12 2007/05/16 06:10:54 marka Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
@@ -158,7 +158,7 @@ The class specifies the protocol group of the information.
|
||||
.PP
|
||||
\fB\fI[no]\fR\fR\fBdebug\fR
|
||||
.RS 4
|
||||
Turn debugging mode on. A lot more information is printed about the packet sent to the server and the resulting answer.
|
||||
Turn on or off the display of the full response packet and any intermediate response packets when searching.
|
||||
.sp
|
||||
(Default = nodebug; abbreviation =
|
||||
[no]deb)
|
||||
@@ -166,7 +166,7 @@ Turn debugging mode on. A lot more information is printed about the packet sent
|
||||
.PP
|
||||
\fB\fI[no]\fR\fR\fBd2\fR
|
||||
.RS 4
|
||||
Turn debugging mode on. A lot more information is printed about the packet sent to the server and the resulting answer.
|
||||
Turn debugging mode on or off. This displays more about what nslookup is doing.
|
||||
.sp
|
||||
(Default = nod2)
|
||||
.RE
|
||||
|
||||
+6
-5
@@ -1,8 +1,8 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2006 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: nslookup.c,v 1.90.2.4.2.12 2006/06/09 23:50:53 marka Exp $ */
|
||||
/* $Id: nslookup.c,v 1.90.2.4.2.15 2007/08/28 07:19:07 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -409,8 +409,9 @@ printmessage(dig_query_t *query, dns_message_t *msg, isc_boolean_t headers) {
|
||||
char nametext[DNS_NAME_FORMATSIZE];
|
||||
dns_name_format(query->lookup->name,
|
||||
nametext, sizeof(nametext));
|
||||
printf("** server can't find %s: %s\n", nametext,
|
||||
rcodetext[msg->rcode]);
|
||||
printf("** server can't find %s: %s\n",
|
||||
(msg->rcode != dns_rcode_nxdomain) ? nametext :
|
||||
query->lookup->textname, rcodetext[msg->rcode]);
|
||||
debug("returning with rcode == 0");
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
<!--
|
||||
- Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Permission to use, copy, modify, and distribute this software for any
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
@@ -17,7 +17,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: nslookup.docbook,v 1.3.6.10 2007/01/29 23:57:18 marka Exp $ -->
|
||||
<!-- $Id: nslookup.docbook,v 1.3.6.13 2007/08/28 07:19:07 tbox Exp $ -->
|
||||
|
||||
<!--
|
||||
- Copyright (c) 1985, 1989
|
||||
@@ -222,18 +222,16 @@ the lookups. Valid keywords are:
|
||||
|
||||
<varlistentry><term><constant><replaceable><optional>no</optional></replaceable>debug</constant></term>
|
||||
<listitem><para>
|
||||
Turn debugging mode on. A lot more information is
|
||||
printed about the packet sent to the server and the
|
||||
resulting answer.
|
||||
Turn on or off the display of the full response packet and
|
||||
any intermediate response packets when searching.
|
||||
</para><para>
|
||||
(Default = nodebug; abbreviation = <optional>no</optional>deb)
|
||||
</para></listitem></varlistentry>
|
||||
|
||||
<varlistentry><term><constant><replaceable><optional>no</optional></replaceable>d2</constant></term>
|
||||
<listitem><para>
|
||||
Turn debugging mode on. A lot more information is
|
||||
printed about the packet sent to the server and the
|
||||
resulting answer.
|
||||
Turn debugging mode on or off. This displays more about
|
||||
what nslookup is doing.
|
||||
</para><para>
|
||||
(Default = nod2)
|
||||
</para></listitem></varlistentry>
|
||||
|
||||
@@ -13,7 +13,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: nslookup.html,v 1.1.6.16 2007/01/30 00:11:47 marka Exp $ -->
|
||||
<!-- $Id: nslookup.html,v 1.1.6.18 2007/05/16 06:10:54 marka Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
@@ -151,9 +151,8 @@ the lookups. Valid keywords are:
|
||||
<dt><span class="term"><code class="constant"><em class="replaceable"><code>[<span class="optional">no</span>]</code></em>debug</code></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Turn debugging mode on. A lot more information is
|
||||
printed about the packet sent to the server and the
|
||||
resulting answer.
|
||||
Turn on or off the display of the full response packet and
|
||||
any intermediate response packets when searching.
|
||||
</p>
|
||||
<p>
|
||||
(Default = nodebug; abbreviation = [<span class="optional">no</span>]deb)
|
||||
@@ -162,9 +161,8 @@ the lookups. Valid keywords are:
|
||||
<dt><span class="term"><code class="constant"><em class="replaceable"><code>[<span class="optional">no</span>]</code></em>d2</code></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Turn debugging mode on. A lot more information is
|
||||
printed about the packet sent to the server and the
|
||||
resulting answer.
|
||||
Turn debugging mode on or off. This displays more about
|
||||
what nslookup is doing.
|
||||
</p>
|
||||
<p>
|
||||
(Default = nod2)
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
# Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and distribute this software for any
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
@@ -13,7 +13,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: Makefile.in,v 1.19.12.14 2007/01/18 00:06:04 marka Exp $
|
||||
# $Id: Makefile.in,v 1.19.12.15 2007/08/28 07:19:07 tbox Exp $
|
||||
|
||||
srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
|
||||
@@ -13,7 +13,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: dnssec-keygen.8,v 1.19.12.12 2007/01/30 00:11:47 marka Exp $
|
||||
.\" $Id: dnssec-keygen.8,v 1.19.12.13 2007/05/09 03:32:36 marka Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
@@ -37,7 +37,7 @@ dnssec\-keygen \- DNSSEC key generation tool
|
||||
.SH "DESCRIPTION"
|
||||
.PP
|
||||
\fBdnssec\-keygen\fR
|
||||
generates keys for DNSSEC (Secure DNS), as defined in RFC 2535 and RFC <TBA\\>. It can also generate keys for use with TSIG (Transaction Signatures), as defined in RFC 2845.
|
||||
generates keys for DNSSEC (Secure DNS), as defined in RFC 2535 and RFC 4034. It can also generate keys for use with TSIG (Transaction Signatures), as defined in RFC 2845.
|
||||
.SH "OPTIONS"
|
||||
.PP
|
||||
\-a \fIalgorithm\fR
|
||||
@@ -147,7 +147,7 @@ is the numeric representation of the algorithm.
|
||||
is the key identifier (or footprint).
|
||||
.PP
|
||||
\fBdnssec\-keygen\fR
|
||||
creates two file, with names based on the printed string.
|
||||
creates two files, with names based on the printed string.
|
||||
\fIKnnnn.+aaa+iiiii.key\fR
|
||||
contains the public key, and
|
||||
\fIKnnnn.+aaa+iiiii.private\fR
|
||||
@@ -159,13 +159,13 @@ file contains a DNS KEY record that can be inserted into a zone file (directly o
|
||||
.PP
|
||||
The
|
||||
\fI.private\fR
|
||||
file contains algorithm specific fields. For obvious security reasons, this file does not have general read permission.
|
||||
file contains algorithm\-specific fields. For obvious security reasons, this file does not have general read permission.
|
||||
.PP
|
||||
Both
|
||||
\fI.key\fR
|
||||
and
|
||||
\fI.private\fR
|
||||
files are generated for symmetric encryption algorithm such as HMAC\-MD5, even though the public and private key are equivalent.
|
||||
files are generated for symmetric encryption algorithms such as HMAC\-MD5, even though the public and private key are equivalent.
|
||||
.SH "EXAMPLE"
|
||||
.PP
|
||||
To generate a 768\-bit DSA key for the domain
|
||||
@@ -182,7 +182,7 @@ In this example,
|
||||
creates the files
|
||||
\fIKexample.com.+003+26160.key\fR
|
||||
and
|
||||
\fIKexample.com.+003+26160.private\fR
|
||||
\fIKexample.com.+003+26160.private\fR.
|
||||
.SH "SEE ALSO"
|
||||
.PP
|
||||
\fBdnssec\-signzone\fR(8),
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
* Portions Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
* Portions Copyright (C) 1995-2000 by Network Associates, Inc.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -16,7 +16,7 @@
|
||||
* IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: dnssec-keygen.c,v 1.48.2.1.10.13 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: dnssec-keygen.c,v 1.48.2.1.10.14 2007/08/28 07:19:07 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
|
||||
@@ -5,7 +5,7 @@
|
||||
- Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
-
|
||||
- Permission to use, copy, modify, and distribute this software for any
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
@@ -18,7 +18,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: dnssec-keygen.docbook,v 1.3.12.11 2007/01/29 23:57:18 marka Exp $ -->
|
||||
<!-- $Id: dnssec-keygen.docbook,v 1.3.12.13 2007/08/28 07:19:07 tbox Exp $ -->
|
||||
|
||||
<refentry>
|
||||
<refentryinfo>
|
||||
@@ -77,7 +77,7 @@
|
||||
<title>DESCRIPTION</title>
|
||||
<para>
|
||||
<command>dnssec-keygen</command> generates keys for DNSSEC
|
||||
(Secure DNS), as defined in RFC 2535 and RFC <TBA\>. It can also generate
|
||||
(Secure DNS), as defined in RFC 2535 and RFC 4034. It can also generate
|
||||
keys for use with TSIG (Transaction Signatures), as
|
||||
defined in RFC 2845.
|
||||
</para>
|
||||
@@ -283,7 +283,7 @@
|
||||
</listitem>
|
||||
</itemizedlist>
|
||||
<para>
|
||||
<command>dnssec-keygen</command> creates two file, with names based
|
||||
<command>dnssec-keygen</command> creates two files, with names based
|
||||
on the printed string. <filename>Knnnn.+aaa+iiiii.key</filename>
|
||||
contains the public key, and
|
||||
<filename>Knnnn.+aaa+iiiii.private</filename> contains the private
|
||||
@@ -295,13 +295,13 @@
|
||||
statement).
|
||||
</para>
|
||||
<para>
|
||||
The <filename>.private</filename> file contains algorithm specific
|
||||
The <filename>.private</filename> file contains algorithm-specific
|
||||
fields. For obvious security reasons, this file does not have
|
||||
general read permission.
|
||||
</para>
|
||||
<para>
|
||||
Both <filename>.key</filename> and <filename>.private</filename>
|
||||
files are generated for symmetric encryption algorithm such as
|
||||
files are generated for symmetric encryption algorithms such as
|
||||
HMAC-MD5, even though the public and private key are equivalent.
|
||||
</para>
|
||||
</refsect1>
|
||||
@@ -325,7 +325,7 @@
|
||||
<para>
|
||||
In this example, <command>dnssec-keygen</command> creates
|
||||
the files <filename>Kexample.com.+003+26160.key</filename> and
|
||||
<filename>Kexample.com.+003+26160.private</filename>
|
||||
<filename>Kexample.com.+003+26160.private</filename>.
|
||||
</para>
|
||||
</refsect1>
|
||||
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: dnssec-keygen.html,v 1.5.2.1.4.18 2007/01/30 00:11:47 marka Exp $ -->
|
||||
<!-- $Id: dnssec-keygen.html,v 1.5.2.1.4.19 2007/05/09 03:32:36 marka Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
@@ -35,7 +35,7 @@
|
||||
<a name="id2543462"></a><h2>DESCRIPTION</h2>
|
||||
<p>
|
||||
<span><strong class="command">dnssec-keygen</strong></span> generates keys for DNSSEC
|
||||
(Secure DNS), as defined in RFC 2535 and RFC <TBA\>. It can also generate
|
||||
(Secure DNS), as defined in RFC 2535 and RFC 4034. It can also generate
|
||||
keys for use with TSIG (Transaction Signatures), as
|
||||
defined in RFC 2845.
|
||||
</p>
|
||||
@@ -164,7 +164,7 @@
|
||||
</p></li>
|
||||
</ul></div>
|
||||
<p>
|
||||
<span><strong class="command">dnssec-keygen</strong></span> creates two file, with names based
|
||||
<span><strong class="command">dnssec-keygen</strong></span> creates two files, with names based
|
||||
on the printed string. <code class="filename">Knnnn.+aaa+iiiii.key</code>
|
||||
contains the public key, and
|
||||
<code class="filename">Knnnn.+aaa+iiiii.private</code> contains the private
|
||||
@@ -176,18 +176,18 @@
|
||||
statement).
|
||||
</p>
|
||||
<p>
|
||||
The <code class="filename">.private</code> file contains algorithm specific
|
||||
The <code class="filename">.private</code> file contains algorithm-specific
|
||||
fields. For obvious security reasons, this file does not have
|
||||
general read permission.
|
||||
</p>
|
||||
<p>
|
||||
Both <code class="filename">.key</code> and <code class="filename">.private</code>
|
||||
files are generated for symmetric encryption algorithm such as
|
||||
files are generated for symmetric encryption algorithms such as
|
||||
HMAC-MD5, even though the public and private key are equivalent.
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543832"></a><h2>EXAMPLE</h2>
|
||||
<a name="id2543900"></a><h2>EXAMPLE</h2>
|
||||
<p>
|
||||
To generate a 768-bit DSA key for the domain
|
||||
<strong class="userinput"><code>example.com</code></strong>, the following command would be
|
||||
@@ -205,11 +205,11 @@
|
||||
<p>
|
||||
In this example, <span><strong class="command">dnssec-keygen</strong></span> creates
|
||||
the files <code class="filename">Kexample.com.+003+26160.key</code> and
|
||||
<code class="filename">Kexample.com.+003+26160.private</code>
|
||||
<code class="filename">Kexample.com.+003+26160.private</code>.
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543878"></a><h2>SEE ALSO</h2>
|
||||
<a name="id2543946"></a><h2>SEE ALSO</h2>
|
||||
<p>
|
||||
<span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
|
||||
<em class="citetitle">BIND 9 Administrator Reference Manual</em>,
|
||||
|
||||
@@ -13,7 +13,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: dnssec-signzone.8,v 1.23.2.1.4.13 2007/01/30 00:11:47 marka Exp $
|
||||
.\" $Id: dnssec-signzone.8,v 1.23.2.1.4.14 2007/05/09 03:32:36 marka Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
@@ -95,7 +95,7 @@ is specified, 30 days from the start time is used as a default.
|
||||
.RS 4
|
||||
The name of the output file containing the signed zone. The default is to append
|
||||
\fI.signed\fR
|
||||
to the input file.
|
||||
to the input filename.
|
||||
.RE
|
||||
.PP
|
||||
\-h
|
||||
@@ -106,7 +106,7 @@ Prints a short summary of the options and arguments to
|
||||
.PP
|
||||
\-i \fIinterval\fR
|
||||
.RS 4
|
||||
When a previously signed zone is passed as input, records may be resigned. The
|
||||
When a previously\-signed zone is passed as input, records may be resigned. The
|
||||
\fBinterval\fR
|
||||
option specifies the cycle interval as an offset from the current time (in seconds). If a RRSIG record expires after the cycle interval, it is retained. Otherwise, it is considered to be expiring soon, and it will be replaced.
|
||||
.sp
|
||||
@@ -167,29 +167,44 @@ The file containing the zone to be signed.
|
||||
.PP
|
||||
key
|
||||
.RS 4
|
||||
The keys used to sign the zone. If no keys are specified, the default all zone keys that have private key files in the current directory.
|
||||
Specify which keys should be used to sign the zone. If no keys are specified, then the zone will be examined for DNSKEY records at the zone apex. If these are found and there are matching private keys, in the current directory, then these will be used for signing.
|
||||
.RE
|
||||
.SH "EXAMPLE"
|
||||
.PP
|
||||
The following command signs the
|
||||
\fBexample.com\fR
|
||||
zone with the DSA key generated in the
|
||||
zone with the DSA key generated by
|
||||
\fBdnssec\-keygen\fR
|
||||
man page. The zone's keys must be in the zone. If there are
|
||||
(Kexample.com.+003+17247). The zone's keys must be in the master file (\fIdb.example.com\fR). This invocation looks for
|
||||
\fIkeyset\fR
|
||||
files associated with child zones, they must be in the current directory.
|
||||
\fBexample.com\fR, the following command would be issued:
|
||||
files, in the current directory, so that DS records can be generated from them (\fB\-g\fR).
|
||||
.sp
|
||||
.RS 4
|
||||
.nf
|
||||
% dnssec\-signzone \-g \-o example.com db.example.com \\
|
||||
Kexample.com.+003+17247
|
||||
db.example.com.signed
|
||||
%
|
||||
.fi
|
||||
.RE
|
||||
.PP
|
||||
\fBdnssec\-signzone \-o example.com db.example.com Kexample.com.+003+26160\fR
|
||||
.PP
|
||||
The command would print a string of the form:
|
||||
.PP
|
||||
In this example,
|
||||
In the above example,
|
||||
\fBdnssec\-signzone\fR
|
||||
creates the file
|
||||
\fIdb.example.com.signed\fR. This file should be referenced in a zone statement in a
|
||||
\fInamed.conf\fR
|
||||
file.
|
||||
.PP
|
||||
This example re\-signs a previously signed zone with default parameters. The private keys are assumed to be in the current directory.
|
||||
.sp
|
||||
.RS 4
|
||||
.nf
|
||||
% cp db.example.com.signed db.example.com
|
||||
% dnssec\-signzone \-o example.com db.example.com
|
||||
db.example.com.signed
|
||||
%
|
||||
.fi
|
||||
.RE
|
||||
.SH "SEE ALSO"
|
||||
.PP
|
||||
\fBdnssec\-keygen\fR(8),
|
||||
|
||||
@@ -1,9 +1,9 @@
|
||||
/*
|
||||
* Portions Copyright (C) 2004-2006 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Portions Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Portions Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
* Portions Copyright (C) 1995-2000 by Network Associates, Inc.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -16,7 +16,7 @@
|
||||
* IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: dnssec-signzone.c,v 1.139.2.2.4.23 2006/01/04 23:50:19 marka Exp $ */
|
||||
/* $Id: dnssec-signzone.c,v 1.139.2.2.4.29 2008/01/30 01:51:54 marka Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -159,37 +159,6 @@ dumpnode(dns_name_t *name, dns_dbnode_t *node) {
|
||||
check_result(result, "dns_master_dumpnodetostream");
|
||||
}
|
||||
|
||||
static void
|
||||
dumpdb(dns_db_t *db) {
|
||||
dns_dbiterator_t *dbiter = NULL;
|
||||
dns_dbnode_t *node;
|
||||
dns_fixedname_t fname;
|
||||
dns_name_t *name;
|
||||
isc_result_t result;
|
||||
|
||||
dbiter = NULL;
|
||||
result = dns_db_createiterator(db, ISC_FALSE, &dbiter);
|
||||
check_result(result, "dns_db_createiterator()");
|
||||
|
||||
dns_fixedname_init(&fname);
|
||||
name = dns_fixedname_name(&fname);
|
||||
node = NULL;
|
||||
|
||||
for (result = dns_dbiterator_first(dbiter);
|
||||
result == ISC_R_SUCCESS;
|
||||
result = dns_dbiterator_next(dbiter))
|
||||
{
|
||||
result = dns_dbiterator_current(dbiter, &node, name);
|
||||
check_result(result, "dns_dbiterator_current()");
|
||||
dumpnode(name, node);
|
||||
dns_db_detachnode(db, &node);
|
||||
}
|
||||
if (result != ISC_R_NOMORE)
|
||||
fatal("iterating database: %s", isc_result_totext(result));
|
||||
|
||||
dns_dbiterator_destroy(&dbiter);
|
||||
}
|
||||
|
||||
static signer_key_t *
|
||||
newkeystruct(dst_key_t *dstkey, isc_boolean_t signwithkey) {
|
||||
signer_key_t *key;
|
||||
@@ -974,7 +943,7 @@ active_node(dns_dbnode_t *node) {
|
||||
fatal("rdataset iteration failed: %s",
|
||||
isc_result_totext(result));
|
||||
} else {
|
||||
/*
|
||||
/*
|
||||
* Delete RRSIGs for types that no longer exist.
|
||||
*/
|
||||
result = dns_db_allrdatasets(gdb, node, gversion, 0, &rdsiter2);
|
||||
@@ -1382,7 +1351,7 @@ loadzonekeys(dns_db_t *db) {
|
||||
for (i = 0; i < nkeys; i++) {
|
||||
signer_key_t *key;
|
||||
|
||||
key = newkeystruct(keys[i], ISC_TRUE);
|
||||
key = newkeystruct(keys[i], dst_key_isprivate(keys[i]));
|
||||
ISC_LIST_APPEND(keylist, key, link);
|
||||
}
|
||||
dns_db_detachnode(db, &node);
|
||||
@@ -1506,7 +1475,7 @@ writeset(const char *prefix, dns_rdatatype_t type) {
|
||||
unsigned char dsbuf[DNS_DS_BUFFERSIZE];
|
||||
unsigned char keybuf[DST_KEY_MAXSIZE];
|
||||
unsigned int filenamelen;
|
||||
const dns_master_style_t *style =
|
||||
const dns_master_style_t *style =
|
||||
(type == dns_rdatatype_dnskey) ? masterstyle : dsstyle;
|
||||
|
||||
isc_buffer_init(&namebuf, namestr, sizeof(namestr));
|
||||
@@ -1692,13 +1661,13 @@ print_stats(isc_time_t *timer_start, isc_time_t *timer_finish) {
|
||||
printf("Signatures successfully verified: %10d\n", nverified);
|
||||
printf("Signatures unsuccessfully verified: %10d\n", nverifyfailed);
|
||||
runtime_ms = runtime_us / 1000;
|
||||
printf("Runtime in seconds: %7u.%03u\n",
|
||||
(unsigned int) (runtime_ms / 1000),
|
||||
printf("Runtime in seconds: %7u.%03u\n",
|
||||
(unsigned int) (runtime_ms / 1000),
|
||||
(unsigned int) (runtime_ms % 1000));
|
||||
if (runtime_us > 0) {
|
||||
sig_ms = ((isc_uint64_t)nsigned * 1000000000) / runtime_us;
|
||||
printf("Signatures per second: %7u.%03u\n",
|
||||
(unsigned int) sig_ms / 1000,
|
||||
(unsigned int) sig_ms / 1000,
|
||||
(unsigned int) sig_ms % 1000);
|
||||
}
|
||||
}
|
||||
@@ -1720,7 +1689,6 @@ main(int argc, char *argv[]) {
|
||||
isc_boolean_t free_output = ISC_FALSE;
|
||||
int tempfilelen;
|
||||
dns_rdataclass_t rdclass;
|
||||
dns_db_t *udb = NULL;
|
||||
isc_task_t **tasks = NULL;
|
||||
isc_buffer_t b;
|
||||
int len;
|
||||
@@ -1776,7 +1744,7 @@ main(int argc, char *argv[]) {
|
||||
"positive");
|
||||
break;
|
||||
|
||||
case 'l':
|
||||
case 'l':
|
||||
dns_fixedname_init(&dlv_fixed);
|
||||
len = strlen(isc_commandline_argument);
|
||||
isc_buffer_init(&b, isc_commandline_argument, len);
|
||||
@@ -1904,7 +1872,7 @@ main(int argc, char *argv[]) {
|
||||
result = dns_master_stylecreate(&dsstyle, DNS_STYLEFLAG_NO_TTL,
|
||||
0, 24, 0, 0, 0, 8, mctx);
|
||||
check_result(result, "dns_master_stylecreate");
|
||||
|
||||
|
||||
|
||||
gdb = NULL;
|
||||
TIME_NOW(&timer_start);
|
||||
@@ -1926,8 +1894,8 @@ main(int argc, char *argv[]) {
|
||||
DST_TYPE_PRIVATE,
|
||||
mctx, &newkey);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("cannot load dnskey %s: %s", argv[i],
|
||||
isc_result_totext(result));
|
||||
fatal("cannot load dnskey %s: %s", argv[i],
|
||||
isc_result_totext(result));
|
||||
|
||||
key = ISC_LIST_HEAD(keylist);
|
||||
while (key != NULL) {
|
||||
@@ -1935,7 +1903,7 @@ main(int argc, char *argv[]) {
|
||||
if (dst_key_id(dkey) == dst_key_id(newkey) &&
|
||||
dst_key_alg(dkey) == dst_key_alg(newkey) &&
|
||||
dns_name_equal(dst_key_name(dkey),
|
||||
dst_key_name(newkey)))
|
||||
dst_key_name(newkey)))
|
||||
{
|
||||
if (!dst_key_isprivate(dkey))
|
||||
fatal("cannot sign zone with "
|
||||
@@ -1964,7 +1932,7 @@ main(int argc, char *argv[]) {
|
||||
mctx, &newkey);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("cannot load dnskey %s: %s", dskeyfile[i],
|
||||
isc_result_totext(result));
|
||||
isc_result_totext(result));
|
||||
|
||||
key = ISC_LIST_HEAD(keylist);
|
||||
while (key != NULL) {
|
||||
@@ -1972,7 +1940,7 @@ main(int argc, char *argv[]) {
|
||||
if (dst_key_id(dkey) == dst_key_id(newkey) &&
|
||||
dst_key_alg(dkey) == dst_key_alg(newkey) &&
|
||||
dns_name_equal(dst_key_name(dkey),
|
||||
dst_key_name(newkey)))
|
||||
dst_key_name(newkey)))
|
||||
{
|
||||
/* Override key flags. */
|
||||
key->issigningkey = ISC_TRUE;
|
||||
@@ -2074,11 +2042,6 @@ main(int argc, char *argv[]) {
|
||||
isc_mem_put(mctx, tasks, ntasks * sizeof(isc_task_t *));
|
||||
postsign();
|
||||
|
||||
if (udb != NULL) {
|
||||
dumpdb(udb);
|
||||
dns_db_detach(&udb);
|
||||
}
|
||||
|
||||
result = isc_stdio_close(fp);
|
||||
check_result(result, "isc_stdio_close");
|
||||
removefile = ISC_FALSE;
|
||||
|
||||
@@ -5,7 +5,7 @@
|
||||
- Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
-
|
||||
- Permission to use, copy, modify, and distribute this software for any
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
@@ -18,7 +18,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: dnssec-signzone.docbook,v 1.2.2.2.4.13 2007/01/29 23:57:18 marka Exp $ -->
|
||||
<!-- $Id: dnssec-signzone.docbook,v 1.2.2.2.4.16 2007/08/28 07:19:07 tbox Exp $ -->
|
||||
|
||||
<refentry>
|
||||
<refentryinfo>
|
||||
@@ -189,7 +189,7 @@
|
||||
<para>
|
||||
The name of the output file containing the signed zone. The
|
||||
default is to append <filename>.signed</filename> to the
|
||||
input file.
|
||||
input filename.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
@@ -208,7 +208,7 @@
|
||||
<term>-i <replaceable class="parameter">interval</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
When a previously signed zone is passed as input, records
|
||||
When a previously-signed zone is passed as input, records
|
||||
may be resigned. The <option>interval</option> option
|
||||
specifies the cycle interval as an offset from the current
|
||||
time (in seconds). If a RRSIG record expires after the
|
||||
@@ -316,9 +316,11 @@
|
||||
<term>key</term>
|
||||
<listitem>
|
||||
<para>
|
||||
The keys used to sign the zone. If no keys are specified, the
|
||||
default all zone keys that have private key files in the
|
||||
current directory.
|
||||
Specify which keys should be used to sign the zone. If
|
||||
no keys are specified, then the zone will be examined
|
||||
for DNSKEY records at the zone apex. If these are found and
|
||||
there are matching private keys, in the current directory,
|
||||
then these will be used for signing.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
@@ -329,26 +331,31 @@
|
||||
<refsect1>
|
||||
<title>EXAMPLE</title>
|
||||
<para>
|
||||
The following command signs the <userinput>example.com</userinput>
|
||||
zone with the DSA key generated in the <command>dnssec-keygen</command>
|
||||
man page. The zone's keys must be in the zone. If there are
|
||||
<filename>keyset</filename> files associated with child zones,
|
||||
they must be in the current directory.
|
||||
<userinput>example.com</userinput>, the following command would be
|
||||
issued:
|
||||
The following command signs the <userinput>example.com</userinput>
|
||||
zone with the DSA key generated by <command>dnssec-keygen</command>
|
||||
(Kexample.com.+003+17247). The zone's keys must be in the master
|
||||
file (<filename>db.example.com</filename>). This invocation looks
|
||||
for <filename>keyset</filename> files, in the current directory,
|
||||
so that DS records can be generated from them (<command>-g</command>).
|
||||
</para>
|
||||
<programlisting>% dnssec-signzone -g -o example.com db.example.com \
|
||||
Kexample.com.+003+17247
|
||||
db.example.com.signed
|
||||
%</programlisting>
|
||||
<para>
|
||||
In the above example, <command>dnssec-signzone</command> creates
|
||||
the file <filename>db.example.com.signed</filename>. This
|
||||
file should be referenced in a zone statement in a
|
||||
<filename>named.conf</filename> file.
|
||||
</para>
|
||||
<para>
|
||||
<userinput>dnssec-signzone -o example.com db.example.com Kexample.com.+003+26160</userinput>
|
||||
</para>
|
||||
<para>
|
||||
The command would print a string of the form:
|
||||
</para>
|
||||
<para>
|
||||
In this example, <command>dnssec-signzone</command> creates
|
||||
the file <filename>db.example.com.signed</filename>. This file
|
||||
should be referenced in a zone statement in a
|
||||
<filename>named.conf</filename> file.
|
||||
This example re-signs a previously signed zone with default parameters.
|
||||
The private keys are assumed to be in the current directory.
|
||||
</para>
|
||||
<programlisting>% cp db.example.com.signed db.example.com
|
||||
% dnssec-signzone -o example.com db.example.com
|
||||
db.example.com.signed
|
||||
%</programlisting>
|
||||
</refsect1>
|
||||
|
||||
<refsect1>
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: dnssec-signzone.html,v 1.4.2.1.4.19 2007/01/30 00:11:47 marka Exp $ -->
|
||||
<!-- $Id: dnssec-signzone.html,v 1.4.2.1.4.20 2007/05/09 03:32:36 marka Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
@@ -98,7 +98,7 @@
|
||||
<dd><p>
|
||||
The name of the output file containing the signed zone. The
|
||||
default is to append <code class="filename">.signed</code> to the
|
||||
input file.
|
||||
input filename.
|
||||
</p></dd>
|
||||
<dt><span class="term">-h</span></dt>
|
||||
<dd><p>
|
||||
@@ -108,7 +108,7 @@
|
||||
<dt><span class="term">-i <em class="replaceable"><code>interval</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
When a previously signed zone is passed as input, records
|
||||
When a previously-signed zone is passed as input, records
|
||||
may be resigned. The <code class="option">interval</code> option
|
||||
specifies the cycle interval as an offset from the current
|
||||
time (in seconds). If a RRSIG record expires after the
|
||||
@@ -172,38 +172,45 @@
|
||||
</p></dd>
|
||||
<dt><span class="term">key</span></dt>
|
||||
<dd><p>
|
||||
The keys used to sign the zone. If no keys are specified, the
|
||||
default all zone keys that have private key files in the
|
||||
current directory.
|
||||
Specify which keys should be used to sign the zone. If
|
||||
no keys are specified, then the zone will be examined
|
||||
for DNSKEY records at the zone apex. If these are found and
|
||||
there are matching private keys, in the current directory,
|
||||
then these will be used for signing.
|
||||
</p></dd>
|
||||
</dl></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543873"></a><h2>EXAMPLE</h2>
|
||||
<a name="id2543874"></a><h2>EXAMPLE</h2>
|
||||
<p>
|
||||
The following command signs the <strong class="userinput"><code>example.com</code></strong>
|
||||
zone with the DSA key generated in the <span><strong class="command">dnssec-keygen</strong></span>
|
||||
man page. The zone's keys must be in the zone. If there are
|
||||
<code class="filename">keyset</code> files associated with child zones,
|
||||
they must be in the current directory.
|
||||
<strong class="userinput"><code>example.com</code></strong>, the following command would be
|
||||
issued:
|
||||
The following command signs the <strong class="userinput"><code>example.com</code></strong>
|
||||
zone with the DSA key generated by <span><strong class="command">dnssec-keygen</strong></span>
|
||||
(Kexample.com.+003+17247). The zone's keys must be in the master
|
||||
file (<code class="filename">db.example.com</code>). This invocation looks
|
||||
for <code class="filename">keyset</code> files, in the current directory,
|
||||
so that DS records can be generated from them (<span><strong class="command">-g</strong></span>).
|
||||
</p>
|
||||
<pre class="programlisting">% dnssec-signzone -g -o example.com db.example.com \
|
||||
Kexample.com.+003+17247
|
||||
db.example.com.signed
|
||||
%</pre>
|
||||
<p>
|
||||
In the above example, <span><strong class="command">dnssec-signzone</strong></span> creates
|
||||
the file <code class="filename">db.example.com.signed</code>. This
|
||||
file should be referenced in a zone statement in a
|
||||
<code class="filename">named.conf</code> file.
|
||||
</p>
|
||||
<p>
|
||||
<strong class="userinput"><code>dnssec-signzone -o example.com db.example.com Kexample.com.+003+26160</code></strong>
|
||||
</p>
|
||||
<p>
|
||||
The command would print a string of the form:
|
||||
</p>
|
||||
<p>
|
||||
In this example, <span><strong class="command">dnssec-signzone</strong></span> creates
|
||||
the file <code class="filename">db.example.com.signed</code>. This file
|
||||
should be referenced in a zone statement in a
|
||||
<code class="filename">named.conf</code> file.
|
||||
This example re-signs a previously signed zone with default parameters.
|
||||
The private keys are assumed to be in the current directory.
|
||||
</p>
|
||||
<pre class="programlisting">% cp db.example.com.signed db.example.com
|
||||
% dnssec-signzone -o example.com db.example.com
|
||||
db.example.com.signed
|
||||
%</pre>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543923"></a><h2>SEE ALSO</h2>
|
||||
<a name="id2543993"></a><h2>SEE ALSO</h2>
|
||||
<p>
|
||||
<span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
|
||||
<em class="citetitle">BIND 9 Administrator Reference Manual</em>,
|
||||
@@ -211,7 +218,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543949"></a><h2>AUTHOR</h2>
|
||||
<a name="id2544020"></a><h2>AUTHOR</h2>
|
||||
<p>
|
||||
<span class="corpauthor">Internet Systems Consortium</span>
|
||||
</p>
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 1998-2003 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and distribute this software for any
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
@@ -13,7 +13,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: Makefile.in,v 1.74.12.13 2007/01/18 00:06:04 marka Exp $
|
||||
# $Id: Makefile.in,v 1.74.12.14 2007/08/28 07:19:08 tbox Exp $
|
||||
|
||||
srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
|
||||
+2
-2
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: aclconf.c,v 1.27.12.9 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: aclconf.c,v 1.27.12.10 2007/08/28 07:19:08 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
|
||||
+37
-29
@@ -1,8 +1,8 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: client.c,v 1.176.2.13.4.33 2007/02/26 23:45:55 tbox Exp $ */
|
||||
/* $Id: client.c,v 1.176.2.13.4.38.4.2 2008/07/23 07:28:11 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -256,7 +256,7 @@ exit_check(ns_client_t *client) {
|
||||
*
|
||||
* Keep the view attached until any outstanding updates complete.
|
||||
*/
|
||||
if (client->nupdates == 0 &&
|
||||
if (client->nupdates == 0 &&
|
||||
client->newstate == NS_CLIENTSTATE_FREED && client->view != NULL)
|
||||
dns_view_detach(&client->view);
|
||||
|
||||
@@ -786,7 +786,7 @@ client_sendpkg(ns_client_t *client, isc_buffer_t *buffer) {
|
||||
isc_netaddr_fromsockaddr(&netaddr, &client->peeraddr);
|
||||
if (ns_g_server->blackholeacl != NULL &&
|
||||
dns_acl_match(&netaddr, NULL,
|
||||
ns_g_server->blackholeacl,
|
||||
ns_g_server->blackholeacl,
|
||||
&ns_g_server->aclenv,
|
||||
&match, NULL) == ISC_R_SUCCESS &&
|
||||
match > 0)
|
||||
@@ -803,7 +803,7 @@ client_sendpkg(ns_client_t *client, isc_buffer_t *buffer) {
|
||||
isc_buffer_usedregion(buffer, &r);
|
||||
|
||||
CTRACE("sendto");
|
||||
|
||||
|
||||
result = isc_socket_sendto2(socket, &r, client->task,
|
||||
address, pktinfo,
|
||||
client->sendevent, sockflags);
|
||||
@@ -1077,8 +1077,8 @@ ns_client_error(ns_client_t *client, isc_result_t result) {
|
||||
/*
|
||||
* FORMERR loop avoidance: If we sent a FORMERR message
|
||||
* with the same ID to the same client less than two
|
||||
* seconds ago, assume that we are in an infinite error
|
||||
* packet dialog with a server for some protocol whose
|
||||
* seconds ago, assume that we are in an infinite error
|
||||
* packet dialog with a server for some protocol whose
|
||||
* error responses look enough like DNS queries to
|
||||
* elicit a FORMERR response. Drop a packet to break
|
||||
* the loop.
|
||||
@@ -1149,7 +1149,7 @@ client_addopt(ns_client_t *client) {
|
||||
rdatalist->ttl = (client->extflags & DNS_MESSAGEEXTFLAG_REPLYPRESERVE);
|
||||
|
||||
/*
|
||||
* No ENDS options in the default case.
|
||||
* No EDNS options in the default case.
|
||||
*/
|
||||
rdata->data = NULL;
|
||||
rdata->length = 0;
|
||||
@@ -1413,7 +1413,7 @@ client_request(isc_task_t *task, isc_event_t *event) {
|
||||
}
|
||||
|
||||
/*
|
||||
* Do we understand this version of ENDS?
|
||||
* Do we understand this version of EDNS?
|
||||
*
|
||||
* XXXRTH need library support for this!
|
||||
*/
|
||||
@@ -1443,7 +1443,7 @@ client_request(isc_task_t *task, isc_event_t *event) {
|
||||
* For IPv6 UDP queries, we get this from the pktinfo structure (if
|
||||
* supported).
|
||||
* If all the attempts fail (this can happen due to memory shortage,
|
||||
* etc), we regard this as an error for safety.
|
||||
* etc), we regard this as an error for safety.
|
||||
*/
|
||||
if ((client->interface->flags & NS_INTERFACEFLAG_ANYADDR) == 0)
|
||||
isc_netaddr_fromsockaddr(&destaddr, &client->interface->addr);
|
||||
@@ -1504,7 +1504,7 @@ client_request(isc_task_t *task, isc_event_t *event) {
|
||||
view);
|
||||
if (sigresult == ISC_R_SUCCESS)
|
||||
tsig = client->message->tsigname;
|
||||
|
||||
|
||||
if (allowed(&netaddr, tsig, view->matchclients) &&
|
||||
allowed(&destaddr, tsig, view->matchdestinations) &&
|
||||
!((client->message->flags & DNS_MESSAGEFLAG_RD)
|
||||
@@ -1574,21 +1574,29 @@ client_request(isc_task_t *task, isc_event_t *event) {
|
||||
char tsigrcode[64];
|
||||
isc_buffer_t b;
|
||||
dns_name_t *name = NULL;
|
||||
dns_rcode_t status;
|
||||
isc_result_t tresult;
|
||||
|
||||
isc_buffer_init(&b, tsigrcode, sizeof(tsigrcode) - 1);
|
||||
RUNTIME_CHECK(dns_tsigrcode_totext(client->message->tsigstatus,
|
||||
&b) == ISC_R_SUCCESS);
|
||||
tsigrcode[isc_buffer_usedlength(&b)] = '\0';
|
||||
/* There is a signature, but it is bad. */
|
||||
if (dns_message_gettsig(client->message, &name) != NULL) {
|
||||
char namebuf[DNS_NAME_FORMATSIZE];
|
||||
dns_name_format(name, namebuf, sizeof(namebuf));
|
||||
status = client->message->tsigstatus;
|
||||
isc_buffer_init(&b, tsigrcode, sizeof(tsigrcode) - 1);
|
||||
tresult = dns_tsigrcode_totext(status, &b);
|
||||
INSIST(tresult == ISC_R_SUCCESS);
|
||||
tsigrcode[isc_buffer_usedlength(&b)] = '\0';
|
||||
ns_client_log(client, DNS_LOGCATEGORY_SECURITY,
|
||||
NS_LOGMODULE_CLIENT, ISC_LOG_ERROR,
|
||||
"request has invalid signature: "
|
||||
"TSIG %s: %s (%s)", namebuf,
|
||||
isc_result_totext(result), tsigrcode);
|
||||
} else {
|
||||
status = client->message->sig0status;
|
||||
isc_buffer_init(&b, tsigrcode, sizeof(tsigrcode) - 1);
|
||||
tresult = dns_tsigrcode_totext(status, &b);
|
||||
INSIST(tresult == ISC_R_SUCCESS);
|
||||
tsigrcode[isc_buffer_usedlength(&b)] = '\0';
|
||||
ns_client_log(client, DNS_LOGCATEGORY_SECURITY,
|
||||
NS_LOGMODULE_CLIENT, ISC_LOG_ERROR,
|
||||
"request has invalid signature: %s (%s)",
|
||||
@@ -1627,7 +1635,7 @@ client_request(isc_task_t *task, isc_event_t *event) {
|
||||
|
||||
ns_client_log(client, DNS_LOGCATEGORY_SECURITY, NS_LOGMODULE_CLIENT,
|
||||
ISC_LOG_DEBUG(3), ra ? "recursion available" :
|
||||
"recursion not available");
|
||||
"recursion not available");
|
||||
|
||||
/*
|
||||
* Dispatch the request.
|
||||
@@ -1941,7 +1949,7 @@ client_newconn(isc_task_t *task, isc_event_t *event) {
|
||||
|
||||
if (ns_g_server->blackholeacl != NULL &&
|
||||
dns_acl_match(&netaddr, NULL,
|
||||
ns_g_server->blackholeacl,
|
||||
ns_g_server->blackholeacl,
|
||||
&ns_g_server->aclenv,
|
||||
&match, NULL) == ISC_R_SUCCESS &&
|
||||
match > 0)
|
||||
@@ -2311,7 +2319,7 @@ ns_client_checkacl(ns_client_t *client,
|
||||
isc_result_t result =
|
||||
ns_client_checkaclsilent(client, acl, default_allow);
|
||||
|
||||
if (result == ISC_R_SUCCESS)
|
||||
if (result == ISC_R_SUCCESS)
|
||||
ns_client_log(client, DNS_LOGCATEGORY_SECURITY,
|
||||
NS_LOGMODULE_CLIENT, ISC_LOG_DEBUG(3),
|
||||
"%s approved", opname);
|
||||
@@ -2367,16 +2375,16 @@ ns_client_log(ns_client_t *client, isc_logcategory_t *category,
|
||||
|
||||
void
|
||||
ns_client_aclmsg(const char *msg, dns_name_t *name, dns_rdatatype_t type,
|
||||
dns_rdataclass_t rdclass, char *buf, size_t len)
|
||||
dns_rdataclass_t rdclass, char *buf, size_t len)
|
||||
{
|
||||
char namebuf[DNS_NAME_FORMATSIZE];
|
||||
char typebuf[DNS_RDATATYPE_FORMATSIZE];
|
||||
char classbuf[DNS_RDATACLASS_FORMATSIZE];
|
||||
char namebuf[DNS_NAME_FORMATSIZE];
|
||||
char typebuf[DNS_RDATATYPE_FORMATSIZE];
|
||||
char classbuf[DNS_RDATACLASS_FORMATSIZE];
|
||||
|
||||
dns_name_format(name, namebuf, sizeof(namebuf));
|
||||
dns_rdatatype_format(type, typebuf, sizeof(typebuf));
|
||||
dns_rdataclass_format(rdclass, classbuf, sizeof(classbuf));
|
||||
(void)snprintf(buf, len, "%s '%s/%s/%s'", msg, namebuf, typebuf,
|
||||
dns_name_format(name, namebuf, sizeof(namebuf));
|
||||
dns_rdatatype_format(type, typebuf, sizeof(typebuf));
|
||||
dns_rdataclass_format(rdclass, classbuf, sizeof(classbuf));
|
||||
(void)snprintf(buf, len, "%s '%s/%s/%s'", msg, namebuf, typebuf,
|
||||
classbuf);
|
||||
}
|
||||
|
||||
@@ -2404,7 +2412,7 @@ ns_client_dumpmessage(ns_client_t *client, const char *reason) {
|
||||
isc_mem_put(client->mctx, buf, len);
|
||||
len += 1024;
|
||||
} else if (result == ISC_R_SUCCESS)
|
||||
ns_client_log(client, NS_LOGCATEGORY_UNMATCHED,
|
||||
ns_client_log(client, NS_LOGCATEGORY_UNMATCHED,
|
||||
NS_LOGMODULE_CLIENT, ISC_LOG_DEBUG(1),
|
||||
"%s\n%.*s", reason,
|
||||
(int)isc_buffer_usedlength(&buffer),
|
||||
@@ -2424,7 +2432,7 @@ ns_client_dumprecursing(FILE *f, ns_clientmgr_t *manager) {
|
||||
const char *sep;
|
||||
|
||||
REQUIRE(VALID_MANAGER(manager));
|
||||
|
||||
|
||||
LOCK(&manager->lock);
|
||||
client = ISC_LIST_HEAD(manager->recursing);
|
||||
while (client != NULL) {
|
||||
|
||||
+10
-9
@@ -1,8 +1,8 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2006 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2006-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2001-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,12 +15,11 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: config.c,v 1.11.2.4.8.32 2006/02/28 06:32:53 marka Exp $ */
|
||||
/* $Id: config.c,v 1.11.2.4.8.36.4.3 2008/07/23 23:47:49 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
#include <stdlib.h>
|
||||
#include <string.h>
|
||||
|
||||
#include <isc/buffer.h>
|
||||
#include <isc/log.h>
|
||||
@@ -28,6 +27,7 @@
|
||||
#include <isc/region.h>
|
||||
#include <isc/result.h>
|
||||
#include <isc/sockaddr.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/util.h>
|
||||
|
||||
#include <isccfg/namedconf.h>
|
||||
@@ -48,7 +48,7 @@ options {\n\
|
||||
#ifndef WIN32
|
||||
" coresize default;\n\
|
||||
datasize default;\n\
|
||||
files default;\n\
|
||||
files unlimited;\n\
|
||||
stacksize default;\n"
|
||||
#endif
|
||||
" deallocate-on-exit true;\n\
|
||||
@@ -94,6 +94,7 @@ options {\n\
|
||||
use-id-pool true;\n\
|
||||
use-ixfr true;\n\
|
||||
edns-udp-size 4096;\n\
|
||||
reserved-sockets 512;\n\
|
||||
\n\
|
||||
/* view */\n\
|
||||
allow-notify {none;};\n\
|
||||
@@ -159,7 +160,7 @@ options {\n\
|
||||
"
|
||||
|
||||
"#\n\
|
||||
# Zones in the \"_bind\" view are NOT counted is the count of zones.\n\
|
||||
# Zones in the \"_bind\" view are NOT counted in the count of zones.\n\
|
||||
#\n\
|
||||
view \"_bind\" chaos {\n\
|
||||
recursion no;\n\
|
||||
@@ -501,7 +502,7 @@ ns_config_getipandkeylist(const cfg_obj_t *config, const cfg_obj_t *list,
|
||||
tresult = get_masters_def(config, listname, &list);
|
||||
if (tresult == ISC_R_NOTFOUND) {
|
||||
cfg_obj_log(addr, ns_g_lctx, ISC_LOG_ERROR,
|
||||
"masters \"%s\" not found", listname);
|
||||
"masters \"%s\" not found", listname);
|
||||
|
||||
result = tresult;
|
||||
goto cleanup;
|
||||
@@ -579,7 +580,7 @@ ns_config_getipandkeylist(const cfg_obj_t *config, const cfg_obj_t *list,
|
||||
if (keys[i] == NULL)
|
||||
goto cleanup;
|
||||
dns_name_init(keys[i], NULL);
|
||||
|
||||
|
||||
keystr = cfg_obj_asstring(key);
|
||||
isc_buffer_init(&b, keystr, strlen(keystr));
|
||||
isc_buffer_add(&b, strlen(keystr));
|
||||
@@ -635,7 +636,7 @@ ns_config_getipandkeylist(const cfg_obj_t *config, const cfg_obj_t *list,
|
||||
isc_mem_put(mctx, lists, listcount * sizeof(*lists));
|
||||
if (stack != NULL)
|
||||
isc_mem_put(mctx, stack, stackcount * sizeof(*stack));
|
||||
|
||||
|
||||
INSIST(keycount == addrcount);
|
||||
|
||||
*addrsp = addrs;
|
||||
|
||||
+4
-4
@@ -1,8 +1,8 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2005 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2001-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,15 +15,15 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: control.c,v 1.7.2.2.2.14 2005/04/29 01:04:47 marka Exp $ */
|
||||
/* $Id: control.c,v 1.7.2.2.2.16 2007/09/13 23:45:58 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
#include <string.h>
|
||||
|
||||
#include <isc/app.h>
|
||||
#include <isc/event.h>
|
||||
#include <isc/mem.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/timer.h>
|
||||
#include <isc/util.h>
|
||||
|
||||
|
||||
+42
-48
@@ -1,8 +1,8 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2006 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2006, 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2001-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: controlconf.c,v 1.28.2.9.2.11 2006/12/07 04:52:50 marka Exp $ */
|
||||
/* $Id: controlconf.c,v 1.28.2.9.2.13.4.2 2008/07/23 23:16:25 marka Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -337,9 +337,9 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
||||
listener = conn->listener;
|
||||
secret.rstart = NULL;
|
||||
|
||||
/* Is the server shutting down? */
|
||||
if (listener->controls->shuttingdown)
|
||||
goto cleanup;
|
||||
/* Is the server shutting down? */
|
||||
if (listener->controls->shuttingdown)
|
||||
goto cleanup;
|
||||
|
||||
if (conn->ccmsg.result != ISC_R_SUCCESS) {
|
||||
if (conn->ccmsg.result != ISC_R_CANCELED &&
|
||||
@@ -356,9 +356,6 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
||||
{
|
||||
ccregion.rstart = isc_buffer_base(&conn->ccmsg.buffer);
|
||||
ccregion.rend = isc_buffer_used(&conn->ccmsg.buffer);
|
||||
if (secret.rstart != NULL)
|
||||
isc_mem_put(listener->mctx, secret.rstart,
|
||||
REGION_SIZE(secret));
|
||||
secret.rstart = isc_mem_get(listener->mctx, key->secret.length);
|
||||
if (secret.rstart == NULL)
|
||||
goto cleanup;
|
||||
@@ -367,7 +364,8 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
||||
result = isccc_cc_fromwire(&ccregion, &request, &secret);
|
||||
if (result == ISC_R_SUCCESS)
|
||||
break;
|
||||
else if (result == ISCCC_R_BADAUTH) {
|
||||
isc_mem_put(listener->mctx, secret.rstart, REGION_SIZE(secret));
|
||||
if (result == ISCCC_R_BADAUTH) {
|
||||
/*
|
||||
* For some reason, request is non-NULL when
|
||||
* isccc_cc_fromwire returns ISCCC_R_BADAUTH.
|
||||
@@ -388,7 +386,7 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
||||
/* We shouldn't be getting a reply. */
|
||||
if (isccc_cc_isreply(request)) {
|
||||
log_invalid(&conn->ccmsg, ISC_R_FAILURE);
|
||||
goto cleanup;
|
||||
goto cleanup_request;
|
||||
}
|
||||
|
||||
isc_stdtime_get(&now);
|
||||
@@ -399,17 +397,17 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
||||
_ctrl = isccc_alist_lookup(request, "_ctrl");
|
||||
if (_ctrl == NULL) {
|
||||
log_invalid(&conn->ccmsg, ISC_R_FAILURE);
|
||||
goto cleanup;
|
||||
goto cleanup_request;
|
||||
}
|
||||
|
||||
if (isccc_cc_lookupuint32(_ctrl, "_tim", &sent) == ISC_R_SUCCESS) {
|
||||
if ((sent + CLOCKSKEW) < now || (sent - CLOCKSKEW) > now) {
|
||||
log_invalid(&conn->ccmsg, ISCCC_R_CLOCKSKEW);
|
||||
goto cleanup;
|
||||
goto cleanup_request;
|
||||
}
|
||||
} else {
|
||||
log_invalid(&conn->ccmsg, ISC_R_FAILURE);
|
||||
goto cleanup;
|
||||
goto cleanup_request;
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -418,7 +416,7 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
||||
if (isccc_cc_lookupuint32(_ctrl, "_exp", &exp) == ISC_R_SUCCESS &&
|
||||
now > exp) {
|
||||
log_invalid(&conn->ccmsg, ISCCC_R_EXPIRED);
|
||||
goto cleanup;
|
||||
goto cleanup_request;
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -428,16 +426,16 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
||||
result = isccc_cc_checkdup(listener->controls->symtab, request, now);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
if (result == ISC_R_EXISTS)
|
||||
result = ISCCC_R_DUPLICATE;
|
||||
result = ISCCC_R_DUPLICATE;
|
||||
log_invalid(&conn->ccmsg, result);
|
||||
goto cleanup;
|
||||
goto cleanup_request;
|
||||
}
|
||||
|
||||
if (conn->nonce != 0 &&
|
||||
(isccc_cc_lookupuint32(_ctrl, "_nonce", &nonce) != ISC_R_SUCCESS ||
|
||||
conn->nonce != nonce)) {
|
||||
log_invalid(&conn->ccmsg, ISCCC_R_BADAUTH);
|
||||
goto cleanup;
|
||||
goto cleanup_request;
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -451,7 +449,7 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
||||
|
||||
result = isccc_cc_createresponse(request, now, now + 60, &response);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto cleanup;
|
||||
goto cleanup_request;
|
||||
if (eresult != ISC_R_SUCCESS) {
|
||||
isccc_sexpr_t *data;
|
||||
|
||||
@@ -459,7 +457,7 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
||||
if (data != NULL) {
|
||||
const char *estr = isc_result_totext(eresult);
|
||||
if (isccc_cc_definestring(data, "err", estr) == NULL)
|
||||
goto cleanup;
|
||||
goto cleanup_response;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -470,20 +468,20 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
||||
if (data != NULL) {
|
||||
char *str = (char *)isc_buffer_base(&text);
|
||||
if (isccc_cc_definestring(data, "text", str) == NULL)
|
||||
goto cleanup;
|
||||
goto cleanup_response;
|
||||
}
|
||||
}
|
||||
|
||||
_ctrl = isccc_alist_lookup(response, "_ctrl");
|
||||
if (_ctrl == NULL ||
|
||||
isccc_cc_defineuint32(_ctrl, "_nonce", conn->nonce) == NULL)
|
||||
goto cleanup;
|
||||
goto cleanup_response;
|
||||
|
||||
ccregion.rstart = conn->buffer + 4;
|
||||
ccregion.rend = conn->buffer + sizeof(conn->buffer);
|
||||
result = isccc_cc_towire(response, &ccregion, &secret);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto cleanup;
|
||||
goto cleanup_response;
|
||||
isc_buffer_init(&b, conn->buffer, 4);
|
||||
len = sizeof(conn->buffer) - REGION_SIZE(ccregion);
|
||||
isc_buffer_putuint32(&b, len - 4);
|
||||
@@ -492,31 +490,27 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
||||
|
||||
result = isc_socket_send(conn->sock, &r, task, control_senddone, conn);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto cleanup;
|
||||
goto cleanup_response;
|
||||
conn->sending = ISC_TRUE;
|
||||
|
||||
if (secret.rstart != NULL)
|
||||
isc_mem_put(listener->mctx, secret.rstart,
|
||||
REGION_SIZE(secret));
|
||||
if (request != NULL)
|
||||
isccc_sexpr_free(&request);
|
||||
if (response != NULL)
|
||||
isccc_sexpr_free(&response);
|
||||
isc_mem_put(listener->mctx, secret.rstart, REGION_SIZE(secret));
|
||||
isccc_sexpr_free(&request);
|
||||
isccc_sexpr_free(&response);
|
||||
return;
|
||||
|
||||
cleanup_response:
|
||||
isccc_sexpr_free(&response);
|
||||
|
||||
cleanup_request:
|
||||
isccc_sexpr_free(&request);
|
||||
isc_mem_put(listener->mctx, secret.rstart, REGION_SIZE(secret));
|
||||
|
||||
cleanup:
|
||||
if (secret.rstart != NULL)
|
||||
isc_mem_put(listener->mctx, secret.rstart,
|
||||
REGION_SIZE(secret));
|
||||
isc_socket_detach(&conn->sock);
|
||||
isccc_ccmsg_invalidate(&conn->ccmsg);
|
||||
conn->ccmsg_valid = ISC_FALSE;
|
||||
maybe_free_connection(conn);
|
||||
maybe_free_listener(listener);
|
||||
if (request != NULL)
|
||||
isccc_sexpr_free(&request);
|
||||
if (response != NULL)
|
||||
isccc_sexpr_free(&response);
|
||||
}
|
||||
|
||||
static void
|
||||
@@ -540,7 +534,7 @@ newconnection(controllistener_t *listener, isc_socket_t *sock) {
|
||||
conn = isc_mem_get(listener->mctx, sizeof(*conn));
|
||||
if (conn == NULL)
|
||||
return (ISC_R_NOMEMORY);
|
||||
|
||||
|
||||
conn->sock = sock;
|
||||
isccc_ccmsg_init(listener->mctx, sock, &conn->ccmsg);
|
||||
conn->ccmsg_valid = ISC_TRUE;
|
||||
@@ -651,7 +645,7 @@ ns_controls_shutdown(ns_controls_t *controls) {
|
||||
|
||||
static isc_result_t
|
||||
cfgkeylist_find(const cfg_obj_t *keylist, const char *keyname,
|
||||
const cfg_obj_t **objp)
|
||||
const cfg_obj_t **objp)
|
||||
{
|
||||
const cfg_listelt_t *element;
|
||||
const char *str;
|
||||
@@ -799,7 +793,7 @@ register_keys(const cfg_obj_t *control, const cfg_obj_t *keylist,
|
||||
if (result != ISC_R_SUCCESS) \
|
||||
goto cleanup; \
|
||||
} while (0)
|
||||
|
||||
|
||||
static isc_result_t
|
||||
get_rndckey(isc_mem_t *mctx, controlkeylist_t *keyids) {
|
||||
isc_result_t result;
|
||||
@@ -819,14 +813,14 @@ get_rndckey(isc_mem_t *mctx, controlkeylist_t *keyids) {
|
||||
CHECK(cfg_map_get(config, "key", &key));
|
||||
|
||||
keyid = isc_mem_get(mctx, sizeof(*keyid));
|
||||
if (keyid == NULL)
|
||||
if (keyid == NULL)
|
||||
CHECK(ISC_R_NOMEMORY);
|
||||
keyid->keyname = isc_mem_strdup(mctx,
|
||||
cfg_obj_asstring(cfg_map_getname(key)));
|
||||
keyid->secret.base = NULL;
|
||||
keyid->secret.length = 0;
|
||||
ISC_LINK_INIT(keyid, link);
|
||||
if (keyid->keyname == NULL)
|
||||
if (keyid->keyname == NULL)
|
||||
CHECK(ISC_R_NOMEMORY);
|
||||
|
||||
CHECK(bind9_check_key(key, ns_g_lctx));
|
||||
@@ -882,7 +876,7 @@ get_rndckey(isc_mem_t *mctx, controlkeylist_t *keyids) {
|
||||
cfg_parser_destroy(&pctx);
|
||||
return (result);
|
||||
}
|
||||
|
||||
|
||||
/*
|
||||
* Ensures that both '*global_keylistp' and '*control_keylistp' are
|
||||
* valid or both are NULL.
|
||||
@@ -936,7 +930,7 @@ update_listener(ns_controls_t *cp, controllistener_t **listenerp,
|
||||
*listenerp = NULL;
|
||||
return;
|
||||
}
|
||||
|
||||
|
||||
/*
|
||||
* There is already a listener for this sockaddr.
|
||||
* Update the access list and key information.
|
||||
@@ -1112,8 +1106,8 @@ add_listener(ns_controls_t *cp, controllistener_t **listenerp,
|
||||
&listener->sock);
|
||||
|
||||
if (result == ISC_R_SUCCESS)
|
||||
result = isc_socket_bind(listener->sock,
|
||||
&listener->address);
|
||||
result = isc_socket_bind(listener->sock, &listener->address,
|
||||
ISC_SOCKET_REUSEADDRESS);
|
||||
|
||||
if (result == ISC_R_SUCCESS)
|
||||
result = control_listen(listener);
|
||||
@@ -1264,7 +1258,7 @@ ns_controls_configure(ns_controls_t *cp, const cfg_obj_t *config,
|
||||
isc_sockaddr_setport(&addr, NS_CONTROL_PORT);
|
||||
|
||||
isc_sockaddr_format(&addr, socktext, sizeof(socktext));
|
||||
|
||||
|
||||
update_listener(cp, &listener, NULL, NULL,
|
||||
&addr, NULL, socktext);
|
||||
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2001, 2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: builtin.h,v 1.1.204.5 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: builtin.h,v 1.1.204.6 2007/08/28 07:19:08 tbox Exp $ */
|
||||
|
||||
#ifndef NAMED_BUILTIN_H
|
||||
#define NAMED_BUILTIN_H 1
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2006, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2001-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: config.h,v 1.4.12.8 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: config.h,v 1.4.12.9 2007/08/28 07:19:08 tbox Exp $ */
|
||||
|
||||
#ifndef NAMED_CONFIG_H
|
||||
#define NAMED_CONFIG_H 1
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: interfacemgr.h,v 1.23.24.9 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: interfacemgr.h,v 1.23.24.10 2007/08/28 07:19:08 tbox Exp $ */
|
||||
|
||||
#ifndef NAMED_INTERFACEMGR_H
|
||||
#define NAMED_INTERFACEMGR_H 1
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: log.h,v 1.19.12.5 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: log.h,v 1.19.12.6 2007/08/28 07:19:08 tbox Exp $ */
|
||||
|
||||
#ifndef NAMED_LOG_H
|
||||
#define NAMED_LOG_H 1
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: main.h,v 1.8.2.2.8.6 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: main.h,v 1.8.2.2.8.7 2007/08/28 07:19:08 tbox Exp $ */
|
||||
|
||||
#ifndef NAMED_MAIN_H
|
||||
#define NAMED_MAIN_H 1
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: query.h,v 1.28.2.3.8.8 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: query.h,v 1.28.2.3.8.9 2007/08/28 07:19:08 tbox Exp $ */
|
||||
|
||||
#ifndef NAMED_QUERY_H
|
||||
#define NAMED_QUERY_H 1
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2006, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: zoneconf.h,v 1.16.2.2.8.5 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: zoneconf.h,v 1.16.2.2.8.6 2007/08/28 07:19:08 tbox Exp $ */
|
||||
|
||||
#ifndef NS_ZONECONF_H
|
||||
#define NS_ZONECONF_H 1
|
||||
|
||||
+11
-10
@@ -1,8 +1,8 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2006, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2006-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: interfacemgr.c,v 1.59.2.5.8.20 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: interfacemgr.c,v 1.59.2.5.8.21.4.3 2008/07/23 23:16:25 marka Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -83,7 +83,7 @@ ns_interfacemgr_create(isc_mem_t *mctx, isc_taskmgr_t *taskmgr,
|
||||
mgr->generation = 1;
|
||||
mgr->listenon4 = NULL;
|
||||
mgr->listenon6 = NULL;
|
||||
|
||||
|
||||
ISC_LIST_INIT(mgr->interfaces);
|
||||
|
||||
/*
|
||||
@@ -298,7 +298,8 @@ ns_interface_accepttcp(ns_interface_t *ifp) {
|
||||
#ifndef ISC_ALLOW_MAPPED
|
||||
isc_socket_ipv6only(ifp->tcpsocket, ISC_TRUE);
|
||||
#endif
|
||||
result = isc_socket_bind(ifp->tcpsocket, &ifp->addr);
|
||||
result = isc_socket_bind(ifp->tcpsocket, &ifp->addr,
|
||||
ISC_SOCKET_REUSEADDRESS);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
isc_log_write(IFMGR_COMMON_LOGARGS, ISC_LOG_ERROR,
|
||||
"binding TCP socket: %s",
|
||||
@@ -313,7 +314,7 @@ ns_interface_accepttcp(ns_interface_t *ifp) {
|
||||
goto tcp_listen_failure;
|
||||
}
|
||||
|
||||
/*
|
||||
/*
|
||||
* If/when there a multiple filters listen to the
|
||||
* result.
|
||||
*/
|
||||
@@ -500,7 +501,7 @@ setup_locals(ns_interfacemgr_t *mgr, isc_interface_t *interface) {
|
||||
unsigned int prefixlen;
|
||||
|
||||
family = interface->address.family;
|
||||
|
||||
|
||||
elt.type = dns_aclelementtype_ipprefix;
|
||||
elt.negative = ISC_FALSE;
|
||||
elt.u.ip_prefix.address = interface->address;
|
||||
@@ -651,7 +652,7 @@ do_scan(ns_interfacemgr_t *mgr, ns_listenlist_t *ext_listen,
|
||||
{
|
||||
isc_interface_t interface;
|
||||
ns_listenlist_t *ll;
|
||||
unsigned int family;
|
||||
unsigned int family;
|
||||
|
||||
result = isc_interfaceiter_current(iter, &interface);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
@@ -827,7 +828,7 @@ do_scan(ns_interfacemgr_t *mgr, ns_listenlist_t *ext_listen,
|
||||
UNEXPECTED_ERROR(__FILE__, __LINE__,
|
||||
"interface iteration failed: %s",
|
||||
isc_result_totext(result));
|
||||
else
|
||||
else
|
||||
result = ISC_R_SUCCESS;
|
||||
cleanup_iter:
|
||||
isc_interfaceiter_destroy(&iter);
|
||||
@@ -858,7 +859,7 @@ ns_interfacemgr_scan0(ns_interfacemgr_t *mgr, ns_listenlist_t *ext_listen,
|
||||
|
||||
/*
|
||||
* Warn if we are not listening on any interface, unless
|
||||
* we're in lwresd-only mode, in which case that is to
|
||||
* we're in lwresd-only mode, in which case that is to
|
||||
* be expected.
|
||||
*/
|
||||
if (ext_listen == NULL &&
|
||||
|
||||
+2
-2
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: log.c,v 1.33.2.1.10.8 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: log.c,v 1.33.2.1.10.9 2007/08/28 07:19:08 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
|
||||
+2
-2
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2006, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2001, 2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: logconf.c,v 1.30.2.3.10.6 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: logconf.c,v 1.30.2.3.10.7 2007/08/28 07:19:08 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
|
||||
+4
-4
@@ -1,8 +1,8 @@
|
||||
/*
|
||||
* Copyright (C) 2004 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: lwaddr.c,v 1.3.208.1 2004/03/06 10:21:18 marka Exp $ */
|
||||
/* $Id: lwaddr.c,v 1.3.208.3 2008/01/11 23:45:30 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -79,7 +79,7 @@ lwaddr_lwresaddr_fromnetaddr(lwres_addr_t *la, isc_netaddr_t *na) {
|
||||
} else {
|
||||
la->family = LWRES_ADDRTYPE_V6;
|
||||
la->length = 16;
|
||||
memcpy(la->address, &na->type.in, 16);
|
||||
memcpy(la->address, &na->type.in6, 16);
|
||||
}
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000, 2001, 2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: lwdclient.c,v 1.13.12.7 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: lwdclient.c,v 1.13.12.8 2007/08/28 07:19:08 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
|
||||
+2
-2
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2006, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000, 2001, 2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: lwdgabn.c,v 1.13.12.7 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: lwdgabn.c,v 1.13.12.8 2007/08/28 07:19:08 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
|
||||
+3
-5
@@ -1,8 +1,8 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2007, 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: lwdgnba.c,v 1.13.2.1.2.7 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: lwdgnba.c,v 1.13.2.1.2.10 2008/01/14 23:45:30 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -218,8 +218,6 @@ ns_lwdclient_processgnba(ns_lwdclient_t *client, lwres_buffer_t *b) {
|
||||
b, &client->pkt, &req);
|
||||
if (result != LWRES_R_SUCCESS)
|
||||
goto out;
|
||||
if (req->addr.address == NULL)
|
||||
goto out;
|
||||
|
||||
client->options = 0;
|
||||
if (req->addr.family == LWRES_ADDRTYPE_V4) {
|
||||
|
||||
+11
-12
@@ -1,8 +1,8 @@
|
||||
/*
|
||||
* Copyright (C) 2004 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: lwdnoop.c,v 1.6.208.1 2004/03/06 10:21:19 marka Exp $ */
|
||||
/* $Id: lwdnoop.c,v 1.6.208.3 2008/01/22 23:26:39 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -42,7 +42,7 @@ ns_lwdclient_processnoop(ns_lwdclient_t *client, lwres_buffer_t *b) {
|
||||
result = lwres_nooprequest_parse(client->clientmgr->lwctx,
|
||||
b, &client->pkt, &req);
|
||||
if (result != LWRES_R_SUCCESS)
|
||||
goto out;
|
||||
goto send_error;
|
||||
|
||||
client->pkt.recvlength = LWRES_RECVLENGTH;
|
||||
client->pkt.authtype = 0; /* XXXMLG */
|
||||
@@ -55,7 +55,7 @@ ns_lwdclient_processnoop(ns_lwdclient_t *client, lwres_buffer_t *b) {
|
||||
lwres = lwres_noopresponse_render(client->clientmgr->lwctx, &resp,
|
||||
&client->pkt, &lwb);
|
||||
if (lwres != LWRES_R_SUCCESS)
|
||||
goto out;
|
||||
goto cleanup_req;
|
||||
|
||||
r.base = lwb.base;
|
||||
r.length = lwb.used;
|
||||
@@ -63,7 +63,7 @@ ns_lwdclient_processnoop(ns_lwdclient_t *client, lwres_buffer_t *b) {
|
||||
client->sendlength = r.length;
|
||||
result = ns_lwdclient_sendreply(client, &r);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto out;
|
||||
goto cleanup_lwb;
|
||||
|
||||
/*
|
||||
* We can now destroy request.
|
||||
@@ -74,13 +74,12 @@ ns_lwdclient_processnoop(ns_lwdclient_t *client, lwres_buffer_t *b) {
|
||||
|
||||
return;
|
||||
|
||||
out:
|
||||
if (req != NULL)
|
||||
lwres_nooprequest_free(client->clientmgr->lwctx, &req);
|
||||
cleanup_lwb:
|
||||
lwres_context_freemem(client->clientmgr->lwctx, lwb.base, lwb.length);
|
||||
|
||||
if (lwb.base != NULL)
|
||||
lwres_context_freemem(client->clientmgr->lwctx,
|
||||
lwb.base, lwb.length);
|
||||
cleanup_req:
|
||||
lwres_nooprequest_free(client->clientmgr->lwctx, &req);
|
||||
|
||||
send_error:
|
||||
ns_lwdclient_errorpktsend(client, LWRES_R_FAILURE);
|
||||
}
|
||||
|
||||
+54
-5
@@ -13,7 +13,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: lwresd.8,v 1.13.208.8 2007/01/30 00:11:47 marka Exp $
|
||||
.\" $Id: lwresd.8,v 1.13.208.10 2007/05/16 06:10:54 marka Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
@@ -33,7 +33,7 @@
|
||||
lwresd \- lightweight resolver daemon
|
||||
.SH "SYNOPSIS"
|
||||
.HP 7
|
||||
\fBlwresd\fR [\fB\-C\ \fR\fB\fIconfig\-file\fR\fR] [\fB\-d\ \fR\fB\fIdebug\-level\fR\fR] [\fB\-f\fR] [\fB\-g\fR] [\fB\-i\ \fR\fB\fIpid\-file\fR\fR] [\fB\-n\ \fR\fB\fI#cpus\fR\fR] [\fB\-P\ \fR\fB\fIport\fR\fR] [\fB\-p\ \fR\fB\fIport\fR\fR] [\fB\-s\fR] [\fB\-t\ \fR\fB\fIdirectory\fR\fR] [\fB\-u\ \fR\fB\fIuser\fR\fR] [\fB\-v\fR]
|
||||
\fBlwresd\fR [\fB\-c\ \fR\fB\fIconfig\-file\fR\fR] [\fB\-C\ \fR\fB\fIconfig\-file\fR\fR] [\fB\-d\ \fR\fB\fIdebug\-level\fR\fR] [\fB\-f\fR] [\fB\-g\fR] [\fB\-i\ \fR\fB\fIpid\-file\fR\fR] [\fB\-m\ \fR\fB\fIflag\fR\fR] [\fB\-n\ \fR\fB\fI#cpus\fR\fR] [\fB\-P\ \fR\fB\fIport\fR\fR] [\fB\-p\ \fR\fB\fIport\fR\fR] [\fB\-s\fR] [\fB\-t\ \fR\fB\fIdirectory\fR\fR] [\fB\-u\ \fR\fB\fIuser\fR\fR] [\fB\-v\fR] [\fB\-4\fR] [\fB\-6\fR]
|
||||
.SH "DESCRIPTION"
|
||||
.PP
|
||||
\fBlwresd\fR
|
||||
@@ -61,12 +61,44 @@ entries are present, or if forwarding fails,
|
||||
resolves the queries autonomously starting at the root name servers, using a built\-in list of root server hints.
|
||||
.SH "OPTIONS"
|
||||
.PP
|
||||
\-4
|
||||
.RS 4
|
||||
Use IPv4 only even if the host machine is capable of IPv6.
|
||||
\fB\-4\fR
|
||||
and
|
||||
\fB\-6\fR
|
||||
are mutually exclusive.
|
||||
.RE
|
||||
.PP
|
||||
\-6
|
||||
.RS 4
|
||||
Use IPv6 only even if the host machine is capable of IPv4.
|
||||
\fB\-4\fR
|
||||
and
|
||||
\fB\-6\fR
|
||||
are mutually exclusive.
|
||||
.RE
|
||||
.PP
|
||||
\-c \fIconfig\-file\fR
|
||||
.RS 4
|
||||
Use
|
||||
\fIconfig\-file\fR
|
||||
as the configuration file instead of the default,
|
||||
\fI/etc/lwresd.conf\fR.
|
||||
<term>\-c</term>
|
||||
can not be used with
|
||||
<term>\-C</term>.
|
||||
.RE
|
||||
.PP
|
||||
\-C \fIconfig\-file\fR
|
||||
.RS 4
|
||||
Use
|
||||
\fIconfig\-file\fR
|
||||
as the configuration file instead of the default,
|
||||
\fI/etc/resolv.conf\fR.
|
||||
<term>\-C</term>
|
||||
can not be used with
|
||||
<term>\-c</term>.
|
||||
.RE
|
||||
.PP
|
||||
\-d \fIdebug\-level\fR
|
||||
@@ -88,6 +120,23 @@ Run the server in the foreground and force all logging to
|
||||
\fIstderr\fR.
|
||||
.RE
|
||||
.PP
|
||||
\-i \fIpid\-file\fR
|
||||
.RS 4
|
||||
Use
|
||||
\fIpid\-file\fR
|
||||
as the PID file instead of the default,
|
||||
\fI/var/run/lwresd.pid\fR.
|
||||
.RE
|
||||
.PP
|
||||
\-m \fIflag\fR
|
||||
.RS 4
|
||||
Turn on memory usage debugging flags. Possible flags are
|
||||
\fIusage\fR,
|
||||
\fItrace\fR, and
|
||||
\fIrecord\fR. These correspond to the ISC_MEM_DEBUGXXXX flags described in
|
||||
\fI<isc/mem.h>\fR.
|
||||
.RE
|
||||
.PP
|
||||
\-n \fI#cpus\fR
|
||||
.RS 4
|
||||
Create
|
||||
@@ -122,7 +171,7 @@ This option is mainly of interest to BIND 9 developers and may be removed or cha
|
||||
.PP
|
||||
\-t \fIdirectory\fR
|
||||
.RS 4
|
||||
\fBchroot()\fR
|
||||
\fBChroot\fR
|
||||
to
|
||||
\fIdirectory\fR
|
||||
after processing the command line arguments, but before reading the configuration file.
|
||||
@@ -131,14 +180,14 @@ after processing the command line arguments, but before reading the configuratio
|
||||
This option should be used in conjunction with the
|
||||
\fB\-u\fR
|
||||
option, as chrooting a process running as root doesn't enhance security on most systems; the way
|
||||
\fBchroot()\fR
|
||||
\fBchroot(2)\fR
|
||||
is defined allows a process with root privileges to escape a chroot jail.
|
||||
.RE
|
||||
.RE
|
||||
.PP
|
||||
\-u \fIuser\fR
|
||||
.RS 4
|
||||
\fBsetuid()\fR
|
||||
\fBSetuid\fR
|
||||
to
|
||||
\fIuser\fR
|
||||
after completing privileged operations, such as creating sockets that listen on privileged ports.
|
||||
|
||||
+6
-5
@@ -1,8 +1,8 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2006 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2006, 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: lwresd.c,v 1.37.2.2.2.8 2006/02/28 06:32:53 marka Exp $ */
|
||||
/* $Id: lwresd.c,v 1.37.2.2.2.8.14.3 2008/07/23 23:16:26 marka Exp $ */
|
||||
|
||||
/*
|
||||
* Main program for the Lightweight Resolver Daemon.
|
||||
@@ -223,7 +223,7 @@ ns_lwresd_parseeresolvconf(isc_mem_t *mctx, cfg_parser_t *pctx,
|
||||
for (i = 0; i < lwc->searchnxt; i++) {
|
||||
CHECK(buffer_putstr(&b, "\t\t\""));
|
||||
CHECK(buffer_putstr(&b, lwc->search[i]));
|
||||
CHECK(buffer_putstr(&b, "\";\n"));
|
||||
CHECK(buffer_putstr(&b, "\";\n"));
|
||||
}
|
||||
CHECK(buffer_putstr(&b, "\t};\n"));
|
||||
}
|
||||
@@ -569,7 +569,8 @@ listener_bind(ns_lwreslistener_t *listener, isc_sockaddr_t *address) {
|
||||
return (result);
|
||||
}
|
||||
|
||||
result = isc_socket_bind(sock, &listener->address);
|
||||
result = isc_socket_bind(sock, &listener->address,
|
||||
ISC_SOCKET_REUSEADDRESS);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
char socktext[ISC_SOCKADDR_FORMATSIZE];
|
||||
isc_sockaddr_format(&listener->address, socktext,
|
||||
|
||||
+91
-26
@@ -1,11 +1,11 @@
|
||||
<!DOCTYPE book PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
|
||||
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
|
||||
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
|
||||
[<!ENTITY mdash "—">]>
|
||||
<!--
|
||||
- Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
-
|
||||
- Permission to use, copy, modify, and distribute this software for any
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
@@ -18,7 +18,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: lwresd.docbook,v 1.6.208.6 2007/01/29 23:57:18 marka Exp $ -->
|
||||
<!-- $Id: lwresd.docbook,v 1.6.208.9 2007/08/28 07:19:08 tbox Exp $ -->
|
||||
|
||||
<refentry>
|
||||
<refentryinfo>
|
||||
@@ -53,11 +53,13 @@
|
||||
<refsynopsisdiv>
|
||||
<cmdsynopsis>
|
||||
<command>lwresd</command>
|
||||
<arg><option>-c <replaceable class="parameter">config-file</replaceable></option></arg>
|
||||
<arg><option>-C <replaceable class="parameter">config-file</replaceable></option></arg>
|
||||
<arg><option>-d <replaceable class="parameter">debug-level</replaceable></option></arg>
|
||||
<arg><option>-f</option></arg>
|
||||
<arg><option>-g</option></arg>
|
||||
<arg><option>-i <replaceable class="parameter">pid-file</replaceable></option></arg>
|
||||
<arg><option>-m <replaceable class="parameter">flag</replaceable></option></arg>
|
||||
<arg><option>-n <replaceable class="parameter">#cpus</replaceable></option></arg>
|
||||
<arg><option>-P <replaceable class="parameter">port</replaceable></option></arg>
|
||||
<arg><option>-p <replaceable class="parameter">port</replaceable></option></arg>
|
||||
@@ -65,6 +67,8 @@
|
||||
<arg><option>-t <replaceable class="parameter">directory</replaceable></option></arg>
|
||||
<arg><option>-u <replaceable class="parameter">user</replaceable></option></arg>
|
||||
<arg><option>-v</option></arg>
|
||||
<arg><option>-4</option></arg>
|
||||
<arg><option>-6</option></arg>
|
||||
</cmdsynopsis>
|
||||
</refsynopsisdiv>
|
||||
|
||||
@@ -108,15 +112,51 @@
|
||||
<title>OPTIONS</title>
|
||||
|
||||
<variablelist>
|
||||
|
||||
<varlistentry>
|
||||
<term>-4</term>
|
||||
<listitem>
|
||||
<para>
|
||||
Use IPv4 only even if the host machine is capable of IPv6.
|
||||
<option>-4</option> and <option>-6</option> are mutually
|
||||
exclusive.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-6</term>
|
||||
<listitem>
|
||||
<para>
|
||||
Use IPv6 only even if the host machine is capable of IPv4.
|
||||
<option>-4</option> and <option>-6</option> are mutually
|
||||
exclusive.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<!-- this is in source but not mentioned? does this matter? -->
|
||||
<varlistentry>
|
||||
<term>-c <replaceable class="parameter">config-file</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Use <replaceable class="parameter">config-file</replaceable> as the
|
||||
configuration file instead of the default,
|
||||
<filename>/etc/lwresd.conf</filename>.
|
||||
<term>-c</term> can not be used with <term>-C</term>.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-C <replaceable class="parameter">config-file</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Use <replaceable
|
||||
class="parameter">config-file</replaceable> as the
|
||||
configuration file instead of the default,
|
||||
<filename>/etc/resolv.conf</filename>.
|
||||
</para>
|
||||
Use <replaceable class="parameter">config-file</replaceable> as the
|
||||
configuration file instead of the default,
|
||||
<filename>/etc/resolv.conf</filename>.
|
||||
<term>-C</term> can not be used with <term>-c</term>.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
@@ -128,7 +168,7 @@
|
||||
class="parameter">debug-level</replaceable>.
|
||||
Debugging traces from <command>lwresd</command> become
|
||||
more verbose as the debug level increases.
|
||||
</para>
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
@@ -137,7 +177,7 @@
|
||||
<listitem>
|
||||
<para>
|
||||
Run the server in the foreground (i.e. do not daemonize).
|
||||
</para>
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
@@ -147,7 +187,32 @@
|
||||
<para>
|
||||
Run the server in the foreground and force all logging
|
||||
to <filename>stderr</filename>.
|
||||
</para>
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-i <replaceable class="parameter">pid-file</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Use <replaceable class="parameter">pid-file</replaceable> as the
|
||||
PID file instead of the default,
|
||||
<filename>/var/run/lwresd.pid</filename>.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-m <replaceable class="parameter">flag</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Turn on memory usage debugging flags. Possible flags are
|
||||
<replaceable class="parameter">usage</replaceable>,
|
||||
<replaceable class="parameter">trace</replaceable>, and
|
||||
<replaceable class="parameter">record</replaceable>.
|
||||
These correspond to the ISC_MEM_DEBUGXXXX flags described in
|
||||
<filename><isc/mem.h></filename>.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
@@ -162,7 +227,7 @@
|
||||
number of CPUs present and create one thread per CPU.
|
||||
If it is unable to determine the number of CPUs, a
|
||||
single worker thread will be created.
|
||||
</para>
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
@@ -173,7 +238,7 @@
|
||||
Listen for lightweight resolver queries on port
|
||||
<replaceable class="parameter">port</replaceable>. If
|
||||
not specified, the default is port 921.
|
||||
</para>
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
@@ -187,7 +252,7 @@
|
||||
way of testing the lightweight resolver daemon with a
|
||||
name server that listens for queries on a non-standard
|
||||
port number.
|
||||
</para>
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
@@ -197,7 +262,7 @@
|
||||
<para>
|
||||
Write memory usage statistics to <filename>stdout</filename>
|
||||
on exit.
|
||||
</para>
|
||||
</para>
|
||||
<note>
|
||||
<para>
|
||||
This option is mainly of interest to BIND 9 developers
|
||||
@@ -211,17 +276,17 @@
|
||||
<term>-t <replaceable class="parameter">directory</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
<function>chroot()</function> to <replaceable
|
||||
<function>Chroot</function> to <replaceable
|
||||
class="parameter">directory</replaceable> after
|
||||
processing the command line arguments, but before
|
||||
reading the configuration file.
|
||||
</para>
|
||||
</para>
|
||||
<warning>
|
||||
<para>
|
||||
This option should be used in conjunction with the
|
||||
<option>-u</option> option, as chrooting a process
|
||||
running as root doesn't enhance security on most
|
||||
systems; the way <function>chroot()</function> is
|
||||
systems; the way <function>chroot(2)</function> is
|
||||
defined allows a process with root privileges to
|
||||
escape a chroot jail.
|
||||
</para>
|
||||
@@ -233,11 +298,11 @@
|
||||
<term>-u <replaceable class="parameter">user</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
<function>setuid()</function> to <replaceable
|
||||
<function>Setuid</function> to <replaceable
|
||||
class="parameter">user</replaceable> after completing
|
||||
privileged operations, such as creating sockets that
|
||||
listen on privileged ports.
|
||||
</para>
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
@@ -246,7 +311,7 @@
|
||||
<listitem>
|
||||
<para>
|
||||
Report the version number and exit.
|
||||
</para>
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
@@ -264,7 +329,7 @@
|
||||
<listitem>
|
||||
<para>
|
||||
The default configuration file.
|
||||
</para>
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
@@ -273,7 +338,7 @@
|
||||
<listitem>
|
||||
<para>
|
||||
The default process-id file.
|
||||
</para>
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
@@ -287,15 +352,15 @@
|
||||
<citerefentry>
|
||||
<refentrytitle>named</refentrytitle>
|
||||
<manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>lwres</refentrytitle>
|
||||
<manvolnum>3</manvolnum>
|
||||
</citerefentry>,
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>resolver</refentrytitle>
|
||||
<manvolnum>5</manvolnum>
|
||||
</citerefentry>.
|
||||
</citerefentry>.
|
||||
</para>
|
||||
</refsect1>
|
||||
|
||||
|
||||
+61
-26
@@ -14,7 +14,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: lwresd.html,v 1.4.2.1.4.13 2007/01/30 00:11:47 marka Exp $ -->
|
||||
<!-- $Id: lwresd.html,v 1.4.2.1.4.15 2007/05/16 06:10:55 marka Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
@@ -29,10 +29,10 @@
|
||||
</div>
|
||||
<div class="refsynopsisdiv">
|
||||
<h2>Synopsis</h2>
|
||||
<div class="cmdsynopsis"><p><code class="command">lwresd</code> [<code class="option">-C <em class="replaceable"><code>config-file</code></em></code>] [<code class="option">-d <em class="replaceable"><code>debug-level</code></em></code>] [<code class="option">-f</code>] [<code class="option">-g</code>] [<code class="option">-i <em class="replaceable"><code>pid-file</code></em></code>] [<code class="option">-n <em class="replaceable"><code>#cpus</code></em></code>] [<code class="option">-P <em class="replaceable"><code>port</code></em></code>] [<code class="option">-p <em class="replaceable"><code>port</code></em></code>] [<code class="option">-s</code>] [<code class="option">-t <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-u <em class="replaceable"><code>user</code></em></code>] [<code class="option">-v</code>]</p></div>
|
||||
<div class="cmdsynopsis"><p><code class="command">lwresd</code> [<code class="option">-c <em class="replaceable"><code>config-file</code></em></code>] [<code class="option">-C <em class="replaceable"><code>config-file</code></em></code>] [<code class="option">-d <em class="replaceable"><code>debug-level</code></em></code>] [<code class="option">-f</code>] [<code class="option">-g</code>] [<code class="option">-i <em class="replaceable"><code>pid-file</code></em></code>] [<code class="option">-m <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-n <em class="replaceable"><code>#cpus</code></em></code>] [<code class="option">-P <em class="replaceable"><code>port</code></em></code>] [<code class="option">-p <em class="replaceable"><code>port</code></em></code>] [<code class="option">-s</code>] [<code class="option">-t <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-u <em class="replaceable"><code>user</code></em></code>] [<code class="option">-v</code>] [<code class="option">-4</code>] [<code class="option">-6</code>]</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543426"></a><h2>DESCRIPTION</h2>
|
||||
<a name="id2543451"></a><h2>DESCRIPTION</h2>
|
||||
<p>
|
||||
<span><strong class="command">lwresd</strong></span> is the daemon providing name lookup
|
||||
services to clients that use the BIND 9 lightweight resolver
|
||||
@@ -67,29 +67,64 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543475"></a><h2>OPTIONS</h2>
|
||||
<a name="id2543500"></a><h2>OPTIONS</h2>
|
||||
<div class="variablelist"><dl>
|
||||
<dt><span class="term">-4</span></dt>
|
||||
<dd><p>
|
||||
Use IPv4 only even if the host machine is capable of IPv6.
|
||||
<code class="option">-4</code> and <code class="option">-6</code> are mutually
|
||||
exclusive.
|
||||
</p></dd>
|
||||
<dt><span class="term">-6</span></dt>
|
||||
<dd><p>
|
||||
Use IPv6 only even if the host machine is capable of IPv4.
|
||||
<code class="option">-4</code> and <code class="option">-6</code> are mutually
|
||||
exclusive.
|
||||
</p></dd>
|
||||
<dt><span class="term">-c <em class="replaceable"><code>config-file</code></em></span></dt>
|
||||
<dd><p>
|
||||
Use <em class="replaceable"><code>config-file</code></em> as the
|
||||
configuration file instead of the default,
|
||||
<code class="filename">/etc/lwresd.conf</code>.
|
||||
<font color="red"><term>-c</term></font> can not be used with <font color="red"><term>-C</term></font>.
|
||||
</p></dd>
|
||||
<dt><span class="term">-C <em class="replaceable"><code>config-file</code></em></span></dt>
|
||||
<dd><p>
|
||||
Use <em class="replaceable"><code>config-file</code></em> as the
|
||||
configuration file instead of the default,
|
||||
<code class="filename">/etc/resolv.conf</code>.
|
||||
</p></dd>
|
||||
Use <em class="replaceable"><code>config-file</code></em> as the
|
||||
configuration file instead of the default,
|
||||
<code class="filename">/etc/resolv.conf</code>.
|
||||
<font color="red"><term>-C</term></font> can not be used with <font color="red"><term>-c</term></font>.
|
||||
</p></dd>
|
||||
<dt><span class="term">-d <em class="replaceable"><code>debug-level</code></em></span></dt>
|
||||
<dd><p>
|
||||
Set the daemon's debug level to <em class="replaceable"><code>debug-level</code></em>.
|
||||
Debugging traces from <span><strong class="command">lwresd</strong></span> become
|
||||
more verbose as the debug level increases.
|
||||
</p></dd>
|
||||
</p></dd>
|
||||
<dt><span class="term">-f</span></dt>
|
||||
<dd><p>
|
||||
Run the server in the foreground (i.e. do not daemonize).
|
||||
</p></dd>
|
||||
</p></dd>
|
||||
<dt><span class="term">-g</span></dt>
|
||||
<dd><p>
|
||||
Run the server in the foreground and force all logging
|
||||
to <code class="filename">stderr</code>.
|
||||
</p></dd>
|
||||
</p></dd>
|
||||
<dt><span class="term">-i <em class="replaceable"><code>pid-file</code></em></span></dt>
|
||||
<dd><p>
|
||||
Use <em class="replaceable"><code>pid-file</code></em> as the
|
||||
PID file instead of the default,
|
||||
<code class="filename">/var/run/lwresd.pid</code>.
|
||||
</p></dd>
|
||||
<dt><span class="term">-m <em class="replaceable"><code>flag</code></em></span></dt>
|
||||
<dd><p>
|
||||
Turn on memory usage debugging flags. Possible flags are
|
||||
<em class="replaceable"><code>usage</code></em>,
|
||||
<em class="replaceable"><code>trace</code></em>, and
|
||||
<em class="replaceable"><code>record</code></em>.
|
||||
These correspond to the ISC_MEM_DEBUGXXXX flags described in
|
||||
<code class="filename"><isc/mem.h></code>.
|
||||
</p></dd>
|
||||
<dt><span class="term">-n <em class="replaceable"><code>#cpus</code></em></span></dt>
|
||||
<dd><p>
|
||||
Create <em class="replaceable"><code>#cpus</code></em> worker threads
|
||||
@@ -98,13 +133,13 @@
|
||||
number of CPUs present and create one thread per CPU.
|
||||
If it is unable to determine the number of CPUs, a
|
||||
single worker thread will be created.
|
||||
</p></dd>
|
||||
</p></dd>
|
||||
<dt><span class="term">-P <em class="replaceable"><code>port</code></em></span></dt>
|
||||
<dd><p>
|
||||
Listen for lightweight resolver queries on port
|
||||
<em class="replaceable"><code>port</code></em>. If
|
||||
not specified, the default is port 921.
|
||||
</p></dd>
|
||||
</p></dd>
|
||||
<dt><span class="term">-p <em class="replaceable"><code>port</code></em></span></dt>
|
||||
<dd><p>
|
||||
Send DNS lookups to port <em class="replaceable"><code>port</code></em>. If not
|
||||
@@ -112,13 +147,13 @@
|
||||
way of testing the lightweight resolver daemon with a
|
||||
name server that listens for queries on a non-standard
|
||||
port number.
|
||||
</p></dd>
|
||||
</p></dd>
|
||||
<dt><span class="term">-s</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Write memory usage statistics to <code class="filename">stdout</code>
|
||||
on exit.
|
||||
</p>
|
||||
</p>
|
||||
<div class="note" style="margin-left: 0.5in; margin-right: 0.5in;">
|
||||
<h3 class="title">Note</h3>
|
||||
<p>
|
||||
@@ -130,17 +165,17 @@
|
||||
<dt><span class="term">-t <em class="replaceable"><code>directory</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
<code class="function">chroot()</code> to <em class="replaceable"><code>directory</code></em> after
|
||||
<code class="function">Chroot</code> to <em class="replaceable"><code>directory</code></em> after
|
||||
processing the command line arguments, but before
|
||||
reading the configuration file.
|
||||
</p>
|
||||
</p>
|
||||
<div class="warning" style="margin-left: 0.5in; margin-right: 0.5in;">
|
||||
<h3 class="title">Warning</h3>
|
||||
<p>
|
||||
This option should be used in conjunction with the
|
||||
<code class="option">-u</code> option, as chrooting a process
|
||||
running as root doesn't enhance security on most
|
||||
systems; the way <code class="function">chroot()</code> is
|
||||
systems; the way <code class="function">chroot(2)</code> is
|
||||
defined allows a process with root privileges to
|
||||
escape a chroot jail.
|
||||
</p>
|
||||
@@ -148,31 +183,31 @@
|
||||
</dd>
|
||||
<dt><span class="term">-u <em class="replaceable"><code>user</code></em></span></dt>
|
||||
<dd><p>
|
||||
<code class="function">setuid()</code> to <em class="replaceable"><code>user</code></em> after completing
|
||||
<code class="function">Setuid</code> to <em class="replaceable"><code>user</code></em> after completing
|
||||
privileged operations, such as creating sockets that
|
||||
listen on privileged ports.
|
||||
</p></dd>
|
||||
</p></dd>
|
||||
<dt><span class="term">-v</span></dt>
|
||||
<dd><p>
|
||||
Report the version number and exit.
|
||||
</p></dd>
|
||||
</p></dd>
|
||||
</dl></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543744"></a><h2>FILES</h2>
|
||||
<a name="id2543915"></a><h2>FILES</h2>
|
||||
<div class="variablelist"><dl>
|
||||
<dt><span class="term"><code class="filename">/etc/resolv.conf</code></span></dt>
|
||||
<dd><p>
|
||||
The default configuration file.
|
||||
</p></dd>
|
||||
</p></dd>
|
||||
<dt><span class="term"><code class="filename">/var/run/lwresd.pid</code></span></dt>
|
||||
<dd><p>
|
||||
The default process-id file.
|
||||
</p></dd>
|
||||
</p></dd>
|
||||
</dl></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543783"></a><h2>SEE ALSO</h2>
|
||||
<a name="id2543955"></a><h2>SEE ALSO</h2>
|
||||
<p>
|
||||
<span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">lwres</span>(3)</span>,
|
||||
@@ -180,7 +215,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543821"></a><h2>AUTHOR</h2>
|
||||
<a name="id2543993"></a><h2>AUTHOR</h2>
|
||||
<p>
|
||||
<span class="corpauthor">Internet Systems Consortium</span>
|
||||
</p>
|
||||
|
||||
+18
-7
@@ -13,7 +13,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: named.8,v 1.17.208.11 2007/01/30 00:11:47 marka Exp $
|
||||
.\" $Id: named.8,v 1.17.208.14 2007/06/20 02:26:23 marka Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
@@ -33,7 +33,7 @@
|
||||
named \- Internet domain name server
|
||||
.SH "SYNOPSIS"
|
||||
.HP 6
|
||||
\fBnamed\fR [\fB\-4\fR] [\fB\-6\fR] [\fB\-c\ \fR\fB\fIconfig\-file\fR\fR] [\fB\-d\ \fR\fB\fIdebug\-level\fR\fR] [\fB\-f\fR] [\fB\-g\fR] [\fB\-n\ \fR\fB\fI#cpus\fR\fR] [\fB\-p\ \fR\fB\fIport\fR\fR] [\fB\-s\fR] [\fB\-t\ \fR\fB\fIdirectory\fR\fR] [\fB\-u\ \fR\fB\fIuser\fR\fR] [\fB\-v\fR] [\fB\-x\ \fR\fB\fIcache\-file\fR\fR]
|
||||
\fBnamed\fR [\fB\-4\fR] [\fB\-6\fR] [\fB\-c\ \fR\fB\fIconfig\-file\fR\fR] [\fB\-d\ \fR\fB\fIdebug\-level\fR\fR] [\fB\-f\fR] [\fB\-g\fR] [\fB\-m\ \fR\fB\fIflag\fR\fR] [\fB\-n\ \fR\fB\fI#cpus\fR\fR] [\fB\-p\ \fR\fB\fIport\fR\fR] [\fB\-s\fR] [\fB\-t\ \fR\fB\fIdirectory\fR\fR] [\fB\-u\ \fR\fB\fIuser\fR\fR] [\fB\-v\fR] [\fB\-x\ \fR\fB\fIcache\-file\fR\fR]
|
||||
.SH "DESCRIPTION"
|
||||
.PP
|
||||
\fBnamed\fR
|
||||
@@ -94,6 +94,15 @@ Run the server in the foreground and force all logging to
|
||||
\fIstderr\fR.
|
||||
.RE
|
||||
.PP
|
||||
\-m \fIflag\fR
|
||||
.RS 4
|
||||
Turn on memory usage debugging flags. Possible flags are
|
||||
\fIusage\fR,
|
||||
\fItrace\fR, and
|
||||
\fIrecord\fR. These correspond to the ISC_MEM_DEBUGXXXX flags described in
|
||||
\fI<isc/mem.h>\fR.
|
||||
.RE
|
||||
.PP
|
||||
\-n \fI#cpus\fR
|
||||
.RS 4
|
||||
Create
|
||||
@@ -122,7 +131,7 @@ This option is mainly of interest to BIND 9 developers and may be removed or cha
|
||||
.PP
|
||||
\-t \fIdirectory\fR
|
||||
.RS 4
|
||||
\fBchroot()\fR
|
||||
\fBChroot\fR
|
||||
to
|
||||
\fIdirectory\fR
|
||||
after processing the command line arguments, but before reading the configuration file.
|
||||
@@ -131,14 +140,14 @@ after processing the command line arguments, but before reading the configuratio
|
||||
This option should be used in conjunction with the
|
||||
\fB\-u\fR
|
||||
option, as chrooting a process running as root doesn't enhance security on most systems; the way
|
||||
\fBchroot()\fR
|
||||
\fBchroot(2)\fR
|
||||
is defined allows a process with root privileges to escape a chroot jail.
|
||||
.RE
|
||||
.RE
|
||||
.PP
|
||||
\-u \fIuser\fR
|
||||
.RS 4
|
||||
\fBsetuid()\fR
|
||||
\fBSetuid\fR
|
||||
to
|
||||
\fIuser\fR
|
||||
after completing privileged operations, such as creating sockets that listen on privileged ports.
|
||||
@@ -147,13 +156,13 @@ after completing privileged operations, such as creating sockets that listen on
|
||||
On Linux,
|
||||
\fBnamed\fR
|
||||
uses the kernel's capability mechanism to drop all root privileges except the ability to
|
||||
\fBbind()\fR
|
||||
\fBbind(2)\fR
|
||||
to a privileged port and set process resource limits. Unfortunately, this means that the
|
||||
\fB\-u\fR
|
||||
option only works when
|
||||
\fBnamed\fR
|
||||
is run on kernel 2.2.18 or later, or kernel 2.3.99\-pre3 or later, since previous kernels did not allow privileges to be retained after
|
||||
\fBsetuid()\fR.
|
||||
\fBsetuid(2)\fR.
|
||||
.RE
|
||||
.RE
|
||||
.PP
|
||||
@@ -211,6 +220,8 @@ The default process\-id file.
|
||||
RFC 1033,
|
||||
RFC 1034,
|
||||
RFC 1035,
|
||||
\fBnamed\-checkconf\fR(8),
|
||||
\fBnamed\-checkzone\fR(8),
|
||||
\fBrndc\fR(8),
|
||||
\fBlwresd\fR(8),
|
||||
\fBnamed.conf\fR(5),
|
||||
|
||||
@@ -12,7 +12,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: named.conf.5,v 1.1.4.12 2007/01/30 00:11:47 marka Exp $
|
||||
.\" $Id: named.conf.5,v 1.1.4.14 2007/06/20 02:26:23 marka Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
@@ -460,8 +460,9 @@ zone \fIstring\fR \fIoptional_class\fR {
|
||||
.SH "SEE ALSO"
|
||||
.PP
|
||||
\fBnamed\fR(8),
|
||||
\fBnamed\-checkconf\fR(8),
|
||||
\fBrndc\fR(8),
|
||||
\fBBIND 9 Administrator Reference Manual\fR().
|
||||
BIND 9 Administrator Reference Manual
|
||||
.SH "COPYRIGHT"
|
||||
Copyright \(co 2004\-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
.br
|
||||
|
||||
@@ -2,9 +2,9 @@
|
||||
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
|
||||
[<!ENTITY mdash "—">]>
|
||||
<!--
|
||||
- Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Permission to use, copy, modify, and distribute this software for any
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
@@ -17,7 +17,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: named.conf.docbook,v 1.1.4.10 2007/01/29 23:57:18 marka Exp $ -->
|
||||
<!-- $Id: named.conf.docbook,v 1.1.4.13.4.2 2008/07/23 23:47:49 tbox Exp $ -->
|
||||
|
||||
<refentry>
|
||||
<refentryinfo>
|
||||
@@ -36,6 +36,7 @@
|
||||
<year>2005</year>
|
||||
<year>2006</year>
|
||||
<year>2007</year>
|
||||
<year>2008</year>
|
||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||
</copyright>
|
||||
</docinfo>
|
||||
@@ -201,6 +202,7 @@ options {
|
||||
port <replaceable>integer</replaceable>;
|
||||
querylog <replaceable>boolean</replaceable>;
|
||||
recursing-file <replaceable>quoted_string</replaceable>;
|
||||
reserved-sockets <replaceable>integer</replaceable>;
|
||||
random-device <replaceable>quoted_string</replaceable>;
|
||||
recursive-clients <replaceable>integer</replaceable>;
|
||||
serial-query-rate <replaceable>integer</replaceable>;
|
||||
@@ -523,20 +525,21 @@ zone <replaceable>string</replaceable> <replaceable>optional_class</replaceable>
|
||||
</para>
|
||||
</refsect1>
|
||||
|
||||
<refsect1>
|
||||
<title>SEE ALSO</title>
|
||||
<para>
|
||||
<citerefentry>
|
||||
<refentrytitle>named</refentrytitle><manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>rndc</refentrytitle><manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>BIND 9 Administrator Reference Manual</refentrytitle>
|
||||
</citerefentry>.
|
||||
</para>
|
||||
</refsect1>
|
||||
<refsect1>
|
||||
<title>SEE ALSO</title>
|
||||
<para>
|
||||
<citerefentry>
|
||||
<refentrytitle>named</refentrytitle><manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>named-checkconf</refentrytitle><manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>rndc</refentrytitle><manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citetitle>BIND 9 Administrator Reference Manual</citetitle>
|
||||
</para>
|
||||
</refsect1>
|
||||
|
||||
</refentry>
|
||||
<!--
|
||||
|
||||
@@ -13,7 +13,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: named.conf.html,v 1.1.4.18 2007/01/30 00:11:48 marka Exp $ -->
|
||||
<!-- $Id: named.conf.html,v 1.1.4.20 2007/06/20 02:26:23 marka Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
@@ -492,10 +492,11 @@ zone
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2545101"></a><h2>SEE ALSO</h2>
|
||||
<p>
|
||||
<span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">rndc</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">BIND 9 Administrator Reference Manual</span></span>.
|
||||
</p>
|
||||
<span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">named-checkconf</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">rndc</span>(8)</span>,
|
||||
<em class="citetitle">BIND 9 Administrator Reference Manual</em>
|
||||
</p>
|
||||
</div>
|
||||
</div></body>
|
||||
</html>
|
||||
|
||||
+30
-7
@@ -5,7 +5,7 @@
|
||||
- Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2000, 2001, 2003 Internet Software Consortium.
|
||||
-
|
||||
- Permission to use, copy, modify, and distribute this software for any
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
@@ -18,7 +18,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: named.docbook,v 1.5.98.9 2007/01/29 23:57:18 marka Exp $ -->
|
||||
<!-- $Id: named.docbook,v 1.5.98.13 2007/08/28 07:19:08 tbox Exp $ -->
|
||||
|
||||
<refentry>
|
||||
<refentryinfo>
|
||||
@@ -61,6 +61,7 @@
|
||||
<arg><option>-d <replaceable class="parameter">debug-level</replaceable></option></arg>
|
||||
<arg><option>-f</option></arg>
|
||||
<arg><option>-g</option></arg>
|
||||
<arg><option>-m <replaceable class="parameter">flag</replaceable></option></arg>
|
||||
<arg><option>-n <replaceable class="parameter">#cpus</replaceable></option></arg>
|
||||
<arg><option>-p <replaceable class="parameter">port</replaceable></option></arg>
|
||||
<arg><option>-s</option></arg>
|
||||
@@ -161,6 +162,20 @@
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-m <replaceable class="parameter">flag</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Turn on memory usage debugging flags. Possible flags are
|
||||
<replaceable class="parameter">usage</replaceable>,
|
||||
<replaceable class="parameter">trace</replaceable>, and
|
||||
<replaceable class="parameter">record</replaceable>.
|
||||
These correspond to the ISC_MEM_DEBUGXXXX flags described in
|
||||
<filename><isc/mem.h></filename>.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-n <replaceable class="parameter">#cpus</replaceable></term>
|
||||
<listitem>
|
||||
@@ -206,7 +221,7 @@
|
||||
<term>-t <replaceable class="parameter">directory</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
<function>chroot()</function> to <replaceable
|
||||
<function>Chroot</function> to <replaceable
|
||||
class="parameter">directory</replaceable> after
|
||||
processing the command line arguments, but before
|
||||
reading the configuration file.
|
||||
@@ -216,7 +231,7 @@
|
||||
This option should be used in conjunction with the
|
||||
<option>-u</option> option, as chrooting a process
|
||||
running as root doesn't enhance security on most
|
||||
systems; the way <function>chroot()</function> is
|
||||
systems; the way <function>chroot(2)</function> is
|
||||
defined allows a process with root privileges to
|
||||
escape a chroot jail.
|
||||
</para>
|
||||
@@ -228,7 +243,7 @@
|
||||
<term>-u <replaceable class="parameter">user</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
<function>setuid()</function> to <replaceable
|
||||
<function>Setuid</function> to <replaceable
|
||||
class="parameter">user</replaceable> after completing
|
||||
privileged operations, such as creating sockets that
|
||||
listen on privileged ports.
|
||||
@@ -237,13 +252,13 @@
|
||||
<para>
|
||||
On Linux, <command>named</command> uses the kernel's
|
||||
capability mechanism to drop all root privileges
|
||||
except the ability to <function>bind()</function> to a
|
||||
except the ability to <function>bind(2)</function> to a
|
||||
privileged port and set process resource limits.
|
||||
Unfortunately, this means that the <option>-u</option>
|
||||
option only works when <command>named</command> is run
|
||||
on kernel 2.2.18 or later, or kernel 2.3.99-pre3 or
|
||||
later, since previous kernels did not allow privileges
|
||||
to be retained after <function>setuid()</function>.
|
||||
to be retained after <function>setuid(2)</function>.
|
||||
</para>
|
||||
</note>
|
||||
</listitem>
|
||||
@@ -359,6 +374,14 @@
|
||||
<citetitle>RFC 1033</citetitle>,
|
||||
<citetitle>RFC 1034</citetitle>,
|
||||
<citetitle>RFC 1035</citetitle>,
|
||||
<citerefentry>
|
||||
<refentrytitle>named-checkconf</refentrytitle>
|
||||
<manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>named-checkzone</refentrytitle>
|
||||
<manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>rndc</refentrytitle>
|
||||
<manvolnum>8</manvolnum>
|
||||
|
||||
+25
-14
@@ -14,7 +14,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: named.html,v 1.4.2.1.4.16 2007/01/30 00:11:47 marka Exp $ -->
|
||||
<!-- $Id: named.html,v 1.4.2.1.4.19 2007/06/20 02:26:23 marka Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
@@ -29,10 +29,10 @@
|
||||
</div>
|
||||
<div class="refsynopsisdiv">
|
||||
<h2>Synopsis</h2>
|
||||
<div class="cmdsynopsis"><p><code class="command">named</code> [<code class="option">-4</code>] [<code class="option">-6</code>] [<code class="option">-c <em class="replaceable"><code>config-file</code></em></code>] [<code class="option">-d <em class="replaceable"><code>debug-level</code></em></code>] [<code class="option">-f</code>] [<code class="option">-g</code>] [<code class="option">-n <em class="replaceable"><code>#cpus</code></em></code>] [<code class="option">-p <em class="replaceable"><code>port</code></em></code>] [<code class="option">-s</code>] [<code class="option">-t <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-u <em class="replaceable"><code>user</code></em></code>] [<code class="option">-v</code>] [<code class="option">-x <em class="replaceable"><code>cache-file</code></em></code>]</p></div>
|
||||
<div class="cmdsynopsis"><p><code class="command">named</code> [<code class="option">-4</code>] [<code class="option">-6</code>] [<code class="option">-c <em class="replaceable"><code>config-file</code></em></code>] [<code class="option">-d <em class="replaceable"><code>debug-level</code></em></code>] [<code class="option">-f</code>] [<code class="option">-g</code>] [<code class="option">-m <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-n <em class="replaceable"><code>#cpus</code></em></code>] [<code class="option">-p <em class="replaceable"><code>port</code></em></code>] [<code class="option">-s</code>] [<code class="option">-t <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-u <em class="replaceable"><code>user</code></em></code>] [<code class="option">-v</code>] [<code class="option">-x <em class="replaceable"><code>cache-file</code></em></code>]</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543432"></a><h2>DESCRIPTION</h2>
|
||||
<a name="id2543441"></a><h2>DESCRIPTION</h2>
|
||||
<p>
|
||||
<span><strong class="command">named</strong></span> is a Domain Name System (DNS) server,
|
||||
part of the BIND 9 distribution from ISC. For more
|
||||
@@ -46,7 +46,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543458"></a><h2>OPTIONS</h2>
|
||||
<a name="id2543466"></a><h2>OPTIONS</h2>
|
||||
<div class="variablelist"><dl>
|
||||
<dt><span class="term">-4</span></dt>
|
||||
<dd><p>
|
||||
@@ -87,6 +87,15 @@
|
||||
Run the server in the foreground and force all logging
|
||||
to <code class="filename">stderr</code>.
|
||||
</p></dd>
|
||||
<dt><span class="term">-m <em class="replaceable"><code>flag</code></em></span></dt>
|
||||
<dd><p>
|
||||
Turn on memory usage debugging flags. Possible flags are
|
||||
<em class="replaceable"><code>usage</code></em>,
|
||||
<em class="replaceable"><code>trace</code></em>, and
|
||||
<em class="replaceable"><code>record</code></em>.
|
||||
These correspond to the ISC_MEM_DEBUGXXXX flags described in
|
||||
<code class="filename"><isc/mem.h></code>.
|
||||
</p></dd>
|
||||
<dt><span class="term">-n <em class="replaceable"><code>#cpus</code></em></span></dt>
|
||||
<dd><p>
|
||||
Create <em class="replaceable"><code>#cpus</code></em> worker threads
|
||||
@@ -117,7 +126,7 @@
|
||||
<dt><span class="term">-t <em class="replaceable"><code>directory</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
<code class="function">chroot()</code> to <em class="replaceable"><code>directory</code></em> after
|
||||
<code class="function">Chroot</code> to <em class="replaceable"><code>directory</code></em> after
|
||||
processing the command line arguments, but before
|
||||
reading the configuration file.
|
||||
</p>
|
||||
@@ -127,7 +136,7 @@
|
||||
This option should be used in conjunction with the
|
||||
<code class="option">-u</code> option, as chrooting a process
|
||||
running as root doesn't enhance security on most
|
||||
systems; the way <code class="function">chroot()</code> is
|
||||
systems; the way <code class="function">chroot(2)</code> is
|
||||
defined allows a process with root privileges to
|
||||
escape a chroot jail.
|
||||
</p>
|
||||
@@ -136,7 +145,7 @@
|
||||
<dt><span class="term">-u <em class="replaceable"><code>user</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
<code class="function">setuid()</code> to <em class="replaceable"><code>user</code></em> after completing
|
||||
<code class="function">Setuid</code> to <em class="replaceable"><code>user</code></em> after completing
|
||||
privileged operations, such as creating sockets that
|
||||
listen on privileged ports.
|
||||
</p>
|
||||
@@ -145,13 +154,13 @@
|
||||
<p>
|
||||
On Linux, <span><strong class="command">named</strong></span> uses the kernel's
|
||||
capability mechanism to drop all root privileges
|
||||
except the ability to <code class="function">bind()</code> to a
|
||||
except the ability to <code class="function">bind(2)</code> to a
|
||||
privileged port and set process resource limits.
|
||||
Unfortunately, this means that the <code class="option">-u</code>
|
||||
option only works when <span><strong class="command">named</strong></span> is run
|
||||
on kernel 2.2.18 or later, or kernel 2.3.99-pre3 or
|
||||
later, since previous kernels did not allow privileges
|
||||
to be retained after <code class="function">setuid()</code>.
|
||||
to be retained after <code class="function">setuid(2)</code>.
|
||||
</p>
|
||||
</div>
|
||||
</dd>
|
||||
@@ -177,7 +186,7 @@
|
||||
</dl></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543806"></a><h2>SIGNALS</h2>
|
||||
<a name="id2543851"></a><h2>SIGNALS</h2>
|
||||
<p>
|
||||
In routine operation, signals should not be used to control
|
||||
the nameserver; <span><strong class="command">rndc</strong></span> should be used
|
||||
@@ -198,7 +207,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543853"></a><h2>CONFIGURATION</h2>
|
||||
<a name="id2543898"></a><h2>CONFIGURATION</h2>
|
||||
<p>
|
||||
The <span><strong class="command">named</strong></span> configuration file is too complex
|
||||
to describe in detail here. A complete description is
|
||||
@@ -207,7 +216,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543870"></a><h2>FILES</h2>
|
||||
<a name="id2543915"></a><h2>FILES</h2>
|
||||
<div class="variablelist"><dl>
|
||||
<dt><span class="term"><code class="filename">/etc/named.conf</code></span></dt>
|
||||
<dd><p>
|
||||
@@ -220,11 +229,13 @@
|
||||
</dl></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543910"></a><h2>SEE ALSO</h2>
|
||||
<a name="id2543955"></a><h2>SEE ALSO</h2>
|
||||
<p>
|
||||
<em class="citetitle">RFC 1033</em>,
|
||||
<em class="citetitle">RFC 1034</em>,
|
||||
<em class="citetitle">RFC 1035</em>,
|
||||
<span class="citerefentry"><span class="refentrytitle">named-checkconf</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">named-checkzone</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">rndc</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">lwresd</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">named.conf</span>(5)</span>,
|
||||
@@ -232,7 +243,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543962"></a><h2>AUTHOR</h2>
|
||||
<a name="id2544026"></a><h2>AUTHOR</h2>
|
||||
<p>
|
||||
<span class="corpauthor">Internet Systems Consortium</span>
|
||||
</p>
|
||||
|
||||
+60
-31
@@ -1,8 +1,8 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2006 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: query.c,v 1.198.2.13.4.44 2006/12/07 04:38:19 marka Exp $ */
|
||||
/* $Id: query.c,v 1.198.2.13.4.53 2008/01/17 23:45:27 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -479,7 +479,7 @@ ns_query_init(ns_client_t *client) {
|
||||
client->query.authdb = NULL;
|
||||
client->query.authzone = NULL;
|
||||
client->query.authdbset = ISC_FALSE;
|
||||
client->query.isreferral = ISC_FALSE;
|
||||
client->query.isreferral = ISC_FALSE;
|
||||
query_reset(client, ISC_FALSE);
|
||||
result = query_newdbversion(client, 3);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
@@ -561,13 +561,13 @@ query_getzonedb(ns_client_t *client, dns_name_t *name, dns_rdatatype_t qtype,
|
||||
if (result == ISC_R_SUCCESS || result == DNS_R_PARTIALMATCH)
|
||||
result = dns_zone_getdb(zone, &db);
|
||||
|
||||
if (result != ISC_R_SUCCESS)
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto fail;
|
||||
|
||||
/*
|
||||
* This limits our searching to the zone where the first name
|
||||
* (the query target) was looked for. This prevents following
|
||||
* CNAMES or DNAMES into other zones and prevents returning
|
||||
* CNAMES or DNAMES into other zones and prevents returning
|
||||
* additional data from other zones.
|
||||
*/
|
||||
if (!client->view->additionalfromauth &&
|
||||
@@ -745,7 +745,7 @@ query_getcachedb(ns_client_t *client, dns_name_t *name, dns_rdatatype_t qtype,
|
||||
if (check_acl) {
|
||||
isc_boolean_t log = ISC_TF((options & DNS_GETDB_NOLOG) == 0);
|
||||
char msg[NS_CLIENT_ACLMSGSIZE("query (cache)")];
|
||||
|
||||
|
||||
result = ns_client_checkaclsilent(client,
|
||||
client->view->queryacl,
|
||||
ISC_TRUE);
|
||||
@@ -1735,7 +1735,9 @@ query_addbestns(ns_client_t *client) {
|
||||
}
|
||||
|
||||
static void
|
||||
query_addds(ns_client_t *client, dns_db_t *db, dns_dbnode_t *node) {
|
||||
query_addds(ns_client_t *client, dns_db_t *db, dns_dbnode_t *node,
|
||||
dns_dbversion_t *version)
|
||||
{
|
||||
dns_name_t *rname;
|
||||
dns_rdataset_t *rdataset, *sigrdataset;
|
||||
isc_result_t result;
|
||||
@@ -1756,12 +1758,12 @@ query_addds(ns_client_t *client, dns_db_t *db, dns_dbnode_t *node) {
|
||||
/*
|
||||
* Look for the DS record, which may or may not be present.
|
||||
*/
|
||||
result = dns_db_findrdataset(db, node, NULL, dns_rdatatype_ds, 0,
|
||||
result = dns_db_findrdataset(db, node, version, dns_rdatatype_ds, 0,
|
||||
client->now, rdataset, sigrdataset);
|
||||
/*
|
||||
* If we didn't find it, look for an NSEC. */
|
||||
if (result == ISC_R_NOTFOUND)
|
||||
result = dns_db_findrdataset(db, node, NULL,
|
||||
result = dns_db_findrdataset(db, node, version,
|
||||
dns_rdatatype_nsec, 0, client->now,
|
||||
rdataset, sigrdataset);
|
||||
if (result != ISC_R_SUCCESS && result != ISC_R_NOTFOUND)
|
||||
@@ -1800,7 +1802,8 @@ query_addds(ns_client_t *client, dns_db_t *db, dns_dbnode_t *node) {
|
||||
|
||||
static void
|
||||
query_addwildcardproof(ns_client_t *client, dns_db_t *db,
|
||||
dns_name_t *name, isc_boolean_t ispositive)
|
||||
dns_dbversion_t *version, dns_name_t *name,
|
||||
isc_boolean_t ispositive)
|
||||
{
|
||||
isc_buffer_t *dbuf, b;
|
||||
dns_name_t *fname;
|
||||
@@ -1881,7 +1884,7 @@ query_addwildcardproof(ns_client_t *client, dns_db_t *db,
|
||||
if (fname == NULL || rdataset == NULL || sigrdataset == NULL)
|
||||
goto cleanup;
|
||||
|
||||
result = dns_db_find(db, name, NULL, dns_rdatatype_nsec, options,
|
||||
result = dns_db_find(db, name, version, dns_rdatatype_nsec, options,
|
||||
0, &node, fname, rdataset, sigrdataset);
|
||||
if (node != NULL)
|
||||
dns_db_detachnode(db, &node);
|
||||
@@ -1922,7 +1925,7 @@ query_addwildcardproof(ns_client_t *client, dns_db_t *db,
|
||||
name = wname;
|
||||
goto again;
|
||||
}
|
||||
}
|
||||
}
|
||||
cleanup:
|
||||
if (rdataset != NULL)
|
||||
query_putrdataset(client, &rdataset);
|
||||
@@ -1933,8 +1936,9 @@ query_addwildcardproof(ns_client_t *client, dns_db_t *db,
|
||||
}
|
||||
|
||||
static void
|
||||
query_addnxrrsetnsec(ns_client_t *client, dns_db_t *db, dns_name_t **namep,
|
||||
dns_rdataset_t **rdatasetp, dns_rdataset_t **sigrdatasetp)
|
||||
query_addnxrrsetnsec(ns_client_t *client, dns_db_t *db,
|
||||
dns_dbversion_t *version, dns_name_t **namep,
|
||||
dns_rdataset_t **rdatasetp, dns_rdataset_t **sigrdatasetp)
|
||||
{
|
||||
dns_name_t *name;
|
||||
dns_rdataset_t *sigrdataset;
|
||||
@@ -1971,8 +1975,7 @@ query_addnxrrsetnsec(ns_client_t *client, dns_db_t *db, dns_name_t **namep,
|
||||
return;
|
||||
|
||||
/* XXX */
|
||||
query_addwildcardproof(client, db,
|
||||
client->query.qname,
|
||||
query_addwildcardproof(client, db, version, client->query.qname,
|
||||
ISC_TRUE);
|
||||
|
||||
/*
|
||||
@@ -2193,7 +2196,7 @@ static isc_result_t
|
||||
rdata_tonetaddr(const dns_rdata_t *rdata, isc_netaddr_t *netaddr) {
|
||||
struct in_addr ina;
|
||||
struct in6_addr in6a;
|
||||
|
||||
|
||||
switch (rdata->type) {
|
||||
case dns_rdatatype_a:
|
||||
INSIST(rdata->length == 4);
|
||||
@@ -2246,7 +2249,7 @@ setup_query_sortlist(ns_client_t *client) {
|
||||
isc_netaddr_t netaddr;
|
||||
dns_rdatasetorderfunc_t order = NULL;
|
||||
const void *order_arg = NULL;
|
||||
|
||||
|
||||
isc_netaddr_fromsockaddr(&netaddr, &client->peeraddr);
|
||||
switch (ns_sortlist_setup(client->view->sortlist,
|
||||
&netaddr, &order_arg)) {
|
||||
@@ -2434,7 +2437,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
|
||||
goto resume;
|
||||
}
|
||||
|
||||
|
||||
/*
|
||||
* Not returning from recursion.
|
||||
*/
|
||||
@@ -2527,7 +2530,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
|
||||
if (is_zone)
|
||||
authoritative = ISC_TRUE;
|
||||
|
||||
|
||||
if (event == NULL && client->query.restarts == 0) {
|
||||
if (is_zone) {
|
||||
dns_zone_attach(zone, &client->query.authzone);
|
||||
@@ -2723,7 +2726,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
dbuf, DNS_SECTION_AUTHORITY);
|
||||
client->query.gluedb = NULL;
|
||||
if (WANTDNSSEC(client) && dns_db_issecure(db))
|
||||
query_addds(client, db, node);
|
||||
query_addds(client, db, node, version);
|
||||
} else {
|
||||
/*
|
||||
* We might have a better answer or delegation
|
||||
@@ -2824,7 +2827,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
client->query.attributes &=
|
||||
~NS_QUERYATTR_CACHEGLUEOK;
|
||||
if (WANTDNSSEC(client))
|
||||
query_addds(client, db, node);
|
||||
query_addds(client, db, node, version);
|
||||
}
|
||||
}
|
||||
goto cleanup;
|
||||
@@ -2861,8 +2864,9 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
*/
|
||||
if (WANTDNSSEC(client)) {
|
||||
if (dns_rdataset_isassociated(rdataset))
|
||||
query_addnxrrsetnsec(client, db, &fname,
|
||||
&rdataset, &sigrdataset);
|
||||
query_addnxrrsetnsec(client, db, version,
|
||||
&fname, &rdataset,
|
||||
&sigrdataset);
|
||||
}
|
||||
goto cleanup;
|
||||
case DNS_R_EMPTYWILD:
|
||||
@@ -2907,7 +2911,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
query_addrrset(client, &fname, &rdataset,
|
||||
&sigrdataset,
|
||||
NULL, DNS_SECTION_AUTHORITY);
|
||||
query_addwildcardproof(client, db,
|
||||
query_addwildcardproof(client, db, version,
|
||||
client->query.qname,
|
||||
ISC_FALSE);
|
||||
}
|
||||
@@ -3212,6 +3216,21 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
* an error unless we were searching for
|
||||
* glue. Ugh.
|
||||
*/
|
||||
if (!is_zone) {
|
||||
authoritative = ISC_FALSE;
|
||||
dns_rdatasetiter_destroy(&rdsiter);
|
||||
if (RECURSIONOK(client)) {
|
||||
result = query_recurse(client,
|
||||
qtype,
|
||||
NULL,
|
||||
NULL);
|
||||
if (result == ISC_R_SUCCESS)
|
||||
client->query.attributes |=
|
||||
NS_QUERYATTR_RECURSING;
|
||||
else
|
||||
QUERY_ERROR(DNS_R_SERVFAIL); }
|
||||
goto addauth;
|
||||
}
|
||||
/*
|
||||
* We were searching for SIG records in
|
||||
* a nonsecure zone. Send a "no error,
|
||||
@@ -3249,7 +3268,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
noqname = rdataset;
|
||||
else
|
||||
noqname = NULL;
|
||||
/*
|
||||
/*
|
||||
* BIND 8 priming queries need the additional section.
|
||||
*/
|
||||
if (is_zone && qtype == dns_rdatatype_ns &&
|
||||
@@ -3292,7 +3311,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
* DNSSEC wildcard proofs.
|
||||
*/
|
||||
if (need_wildcardproof && dns_db_issecure(db))
|
||||
query_addwildcardproof(client, db,
|
||||
query_addwildcardproof(client, db, version,
|
||||
dns_fixedname_name(&wildcardname),
|
||||
ISC_TRUE);
|
||||
cleanup:
|
||||
@@ -3411,6 +3430,7 @@ ns_query_start(ns_client_t *client) {
|
||||
dns_rdataset_t *rdataset;
|
||||
ns_client_t *qclient;
|
||||
dns_rdatatype_t qtype;
|
||||
isc_boolean_t want_ad;
|
||||
|
||||
CTRACE("ns_query_start");
|
||||
|
||||
@@ -3429,10 +3449,10 @@ ns_query_start(ns_client_t *client) {
|
||||
|
||||
if ((message->flags & DNS_MESSAGEFLAG_RD) != 0)
|
||||
client->query.attributes |= NS_QUERYATTR_WANTRECURSION;
|
||||
|
||||
|
||||
if ((client->extflags & DNS_MESSAGEEXTFLAG_DO) != 0)
|
||||
client->attributes |= NS_CLIENTATTR_WANTDNSSEC;
|
||||
|
||||
|
||||
if (client->view->minimalresponses)
|
||||
client->query.attributes |= (NS_QUERYATTR_NOAUTHORITY |
|
||||
NS_QUERYATTR_NOADDITIONAL);
|
||||
@@ -3543,6 +3563,15 @@ ns_query_start(ns_client_t *client) {
|
||||
if (message->flags & DNS_MESSAGEFLAG_CD)
|
||||
client->query.attributes &= ~NS_QUERYATTR_SECURE;
|
||||
|
||||
/*
|
||||
* Set 'want_ad' if the client has set AD in the query.
|
||||
* This allows AD to be returned on queries without DO set.
|
||||
*/
|
||||
if ((message->flags & DNS_MESSAGEFLAG_AD) != 0)
|
||||
want_ad = ISC_TRUE;
|
||||
else
|
||||
want_ad = ISC_FALSE;
|
||||
|
||||
/*
|
||||
* This is an ordinary query.
|
||||
*/
|
||||
@@ -3562,7 +3591,7 @@ ns_query_start(ns_client_t *client) {
|
||||
* Set AD. We must clear it if we add non-validated data to a
|
||||
* response.
|
||||
*/
|
||||
if (client->view->enablednssec)
|
||||
if (WANTDNSSEC(client) || want_ad)
|
||||
message->flags |= DNS_MESSAGEFLAG_AD;
|
||||
|
||||
qclient = NULL;
|
||||
|
||||
+157
-76
@@ -1,8 +1,8 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2006 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,11 +15,12 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: server.c,v 1.339.2.15.2.71 2006/12/07 05:24:05 marka Exp $ */
|
||||
/* $Id: server.c,v 1.339.2.15.2.78.4.3 2008/07/23 23:47:49 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
#include <stdlib.h>
|
||||
#include <unistd.h>
|
||||
|
||||
#include <isc/app.h>
|
||||
#include <isc/base64.h>
|
||||
@@ -382,7 +383,7 @@ configure_view_dnsseckeys(const cfg_obj_t *vconfig, const cfg_obj_t *config,
|
||||
*target = keytable; /* Transfer ownership. */
|
||||
keytable = NULL;
|
||||
result = ISC_R_SUCCESS;
|
||||
|
||||
|
||||
cleanup:
|
||||
return (result);
|
||||
}
|
||||
@@ -398,7 +399,7 @@ mustbesecure(const cfg_obj_t *mbs, dns_resolver_t *resolver)
|
||||
isc_boolean_t value;
|
||||
isc_result_t result;
|
||||
isc_buffer_t b;
|
||||
|
||||
|
||||
dns_fixedname_init(&fixed);
|
||||
name = dns_fixedname_name(&fixed);
|
||||
for (element = cfg_list_first(mbs);
|
||||
@@ -416,7 +417,7 @@ mustbesecure(const cfg_obj_t *mbs, dns_resolver_t *resolver)
|
||||
}
|
||||
|
||||
result = ISC_R_SUCCESS;
|
||||
|
||||
|
||||
cleanup:
|
||||
return (result);
|
||||
}
|
||||
@@ -484,6 +485,14 @@ get_view_querysource_dispatch(const cfg_obj_t **maps,
|
||||
attrs |= DNS_DISPATCHATTR_IPV6;
|
||||
break;
|
||||
}
|
||||
|
||||
if (isc_sockaddr_getport(&sa) != 0) {
|
||||
INSIST(obj != NULL);
|
||||
cfg_obj_log(obj, ns_g_lctx, ISC_LOG_INFO,
|
||||
"using specific query-source port suppresses port "
|
||||
"randomization and can be insecure.");
|
||||
}
|
||||
|
||||
attrmask = 0;
|
||||
attrmask |= DNS_DISPATCHATTR_UDP;
|
||||
attrmask |= DNS_DISPATCHATTR_TCP;
|
||||
@@ -493,7 +502,7 @@ get_view_querysource_dispatch(const cfg_obj_t **maps,
|
||||
disp = NULL;
|
||||
result = dns_dispatch_getudp(ns_g_dispatchmgr, ns_g_socketmgr,
|
||||
ns_g_taskmgr, &sa, 4096,
|
||||
1000, 32768, 16411, 16433,
|
||||
1024, 32768, 16411, 16433,
|
||||
attrs, attrmask, &disp);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
isc_sockaddr_t any;
|
||||
@@ -545,7 +554,7 @@ configure_order(dns_order_t *order, const cfg_obj_t *ent) {
|
||||
return (result);
|
||||
|
||||
obj = cfg_tuple_get(ent, "name");
|
||||
if (cfg_obj_isstring(obj))
|
||||
if (cfg_obj_isstring(obj))
|
||||
str = cfg_obj_asstring(obj);
|
||||
else
|
||||
str = "*";
|
||||
@@ -938,7 +947,7 @@ configure_view(dns_view_t *view, const cfg_obj_t *config,
|
||||
if (lame_ttl > 1800)
|
||||
lame_ttl = 1800;
|
||||
dns_resolver_setlamettl(view->resolver, lame_ttl);
|
||||
|
||||
|
||||
/*
|
||||
* Set the resolver's EDNS UDP size.
|
||||
*/
|
||||
@@ -951,7 +960,7 @@ configure_view(dns_view_t *view, const cfg_obj_t *config,
|
||||
if (udpsize > 4096)
|
||||
udpsize = 4096;
|
||||
dns_resolver_setudpsize(view->resolver, (isc_uint16_t)udpsize);
|
||||
|
||||
|
||||
/*
|
||||
* Set supported DNSSEC algorithms.
|
||||
*/
|
||||
@@ -975,7 +984,7 @@ configure_view(dns_view_t *view, const cfg_obj_t *config,
|
||||
(void)ns_config_get(maps, "forward", &forwardtype);
|
||||
(void)ns_config_get(maps, "forwarders", &forwarders);
|
||||
if (forwarders != NULL)
|
||||
CHECK(configure_forward(config, view, dns_rootname,
|
||||
CHECK(configure_forward(config, view, dns_rootname,
|
||||
forwarders, forwardtype));
|
||||
|
||||
/*
|
||||
@@ -995,7 +1004,7 @@ configure_view(dns_view_t *view, const cfg_obj_t *config,
|
||||
/*
|
||||
* If we still have no hints, this is a non-IN view with no
|
||||
* "hints zone" configured. Issue a warning, except if this
|
||||
* is a root server. Root servers never need to consult
|
||||
* is a root server. Root servers never need to consult
|
||||
* their hints, so it's no point requiring users to configure
|
||||
* them.
|
||||
*/
|
||||
@@ -1118,7 +1127,7 @@ configure_view(dns_view_t *view, const cfg_obj_t *config,
|
||||
view->transfer_format = dns_one_answer;
|
||||
else
|
||||
INSIST(0);
|
||||
|
||||
|
||||
/*
|
||||
* Set sources where additional data and CNAME/DNAME
|
||||
* targets for authoritative answers may be found.
|
||||
@@ -1186,7 +1195,7 @@ configure_view(dns_view_t *view, const cfg_obj_t *config,
|
||||
result = ns_config_get(maps, "provide-ixfr", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
view->provideixfr = cfg_obj_asboolean(obj);
|
||||
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "dnssec-enable", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
@@ -1615,7 +1624,7 @@ configure_zone(const cfg_obj_t *config, const cfg_obj_t *zconfig,
|
||||
"name"));
|
||||
else
|
||||
vname = "<default view>";
|
||||
|
||||
|
||||
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL,
|
||||
NS_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"zone '%s': wrong class for view '%s'",
|
||||
@@ -1865,7 +1874,9 @@ scan_interfaces(ns_server_t *server, isc_boolean_t verbose) {
|
||||
}
|
||||
|
||||
static isc_result_t
|
||||
add_listenelt(isc_mem_t *mctx, ns_listenlist_t *list, isc_sockaddr_t *addr) {
|
||||
add_listenelt(isc_mem_t *mctx, ns_listenlist_t *list, isc_sockaddr_t *addr,
|
||||
isc_boolean_t wcardport_ok)
|
||||
{
|
||||
ns_listenelt_t *lelt = NULL;
|
||||
dns_acl_t *src_acl = NULL;
|
||||
dns_aclelement_t aelt;
|
||||
@@ -1875,7 +1886,8 @@ add_listenelt(isc_mem_t *mctx, ns_listenlist_t *list, isc_sockaddr_t *addr) {
|
||||
REQUIRE(isc_sockaddr_pf(addr) == AF_INET6);
|
||||
|
||||
isc_sockaddr_any6(&any_sa6);
|
||||
if (!isc_sockaddr_equal(&any_sa6, addr)) {
|
||||
if (!isc_sockaddr_equal(&any_sa6, addr) &&
|
||||
(wcardport_ok || isc_sockaddr_getport(addr) != 0)) {
|
||||
aelt.type = dns_aclelementtype_ipprefix;
|
||||
aelt.negative = ISC_FALSE;
|
||||
aelt.u.ip_prefix.prefixlen = 128;
|
||||
@@ -1934,7 +1946,16 @@ adjust_interfaces(ns_server_t *server, isc_mem_t *mctx) {
|
||||
result = dns_dispatch_getlocaladdress(dispatch6, &addr);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto fail;
|
||||
result = add_listenelt(mctx, list, &addr);
|
||||
|
||||
/*
|
||||
* We always add non-wildcard address regardless of whether
|
||||
* the port is 'any' (the fourth arg is TRUE): if the port is
|
||||
* specific, we need to add it since it may conflict with a
|
||||
* listening interface; if it's zero, we'll dynamically open
|
||||
* query ports, and some of them may override an existing
|
||||
* wildcard IPv6 port.
|
||||
*/
|
||||
result = add_listenelt(mctx, list, &addr, ISC_TRUE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto fail;
|
||||
}
|
||||
@@ -1964,18 +1985,18 @@ adjust_interfaces(ns_server_t *server, isc_mem_t *mctx) {
|
||||
continue;
|
||||
|
||||
addrp = dns_zone_getnotifysrc6(zone);
|
||||
result = add_listenelt(mctx, list, addrp);
|
||||
result = add_listenelt(mctx, list, addrp, ISC_FALSE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto fail;
|
||||
|
||||
addrp = dns_zone_getxfrsource6(zone);
|
||||
result = add_listenelt(mctx, list, addrp);
|
||||
result = add_listenelt(mctx, list, addrp, ISC_FALSE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto fail;
|
||||
}
|
||||
|
||||
ns_interfacemgr_adjust(server->interfacemgr, list, ISC_TRUE);
|
||||
|
||||
|
||||
clean:
|
||||
ns_listenlist_detach(&list);
|
||||
return;
|
||||
@@ -2049,7 +2070,7 @@ setstring(ns_server_t *server, char **field, const char *value) {
|
||||
|
||||
*field = copy;
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
* Replace the current value of '*field', a dynamically allocated
|
||||
@@ -2091,7 +2112,7 @@ set_limit(const cfg_obj_t **maps, const char *configname,
|
||||
result = isc_resource_setlimit(resourceid, value);
|
||||
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_SERVER,
|
||||
result == ISC_R_SUCCESS ?
|
||||
ISC_LOG_DEBUG(3) : ISC_LOG_WARNING,
|
||||
ISC_LOG_DEBUG(3) : ISC_LOG_WARNING,
|
||||
"set maximum %s to %" ISC_PRINT_QUADFORMAT "d: %s",
|
||||
description, value, isc_result_totext(result));
|
||||
}
|
||||
@@ -2120,7 +2141,7 @@ portlist_fromconf(dns_portlist_t *portlist, unsigned int family,
|
||||
element = cfg_list_next(element)) {
|
||||
const cfg_obj_t *obj = cfg_listelt_value(element);
|
||||
in_port_t port = (in_port_t)cfg_obj_asuint32(obj);
|
||||
|
||||
|
||||
result = dns_portlist_add(portlist, family, port);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
break;
|
||||
@@ -2132,33 +2153,35 @@ static isc_result_t
|
||||
load_configuration(const char *filename, ns_server_t *server,
|
||||
isc_boolean_t first_time)
|
||||
{
|
||||
isc_result_t result;
|
||||
cfg_parser_t *parser = NULL;
|
||||
cfg_obj_t *config;
|
||||
const cfg_obj_t *options;
|
||||
const cfg_obj_t *views;
|
||||
const cfg_obj_t *obj;
|
||||
const cfg_obj_t *v4ports, *v6ports;
|
||||
const cfg_obj_t *maps[3];
|
||||
const cfg_obj_t *builtin_views;
|
||||
cfg_parser_t *parser = NULL;
|
||||
const cfg_listelt_t *element;
|
||||
const cfg_obj_t *builtin_views;
|
||||
const cfg_obj_t *maps[3];
|
||||
const cfg_obj_t *obj;
|
||||
const cfg_obj_t *options;
|
||||
const cfg_obj_t *v4ports, *v6ports;
|
||||
const cfg_obj_t *views;
|
||||
dns_view_t *view = NULL;
|
||||
dns_view_t *view_next;
|
||||
dns_viewlist_t viewlist;
|
||||
dns_viewlist_t tmpviewlist;
|
||||
ns_aclconfctx_t aclconfctx;
|
||||
isc_uint32_t interface_interval;
|
||||
isc_uint32_t heartbeat_interval;
|
||||
isc_uint32_t udpsize;
|
||||
dns_viewlist_t viewlist;
|
||||
in_port_t listen_port;
|
||||
int i;
|
||||
isc_resourcevalue_t files;
|
||||
isc_result_t result;
|
||||
isc_uint32_t heartbeat_interval;
|
||||
isc_uint32_t interface_interval;
|
||||
isc_uint32_t reserved;
|
||||
isc_uint32_t udpsize;
|
||||
ns_aclconfctx_t aclconfctx;
|
||||
|
||||
ns_aclconfctx_init(&aclconfctx);
|
||||
ISC_LIST_INIT(viewlist);
|
||||
|
||||
/* Ensure exclusive access to configuration data. */
|
||||
result = isc_task_beginexclusive(server->task);
|
||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
|
||||
/*
|
||||
* Parse the global default pseudo-config file.
|
||||
@@ -2210,6 +2233,15 @@ load_configuration(const char *filename, ns_server_t *server,
|
||||
}
|
||||
CHECK(result);
|
||||
|
||||
/*
|
||||
* Check that the working directory is writable.
|
||||
*/
|
||||
if (access(".", W_OK) != 0) {
|
||||
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL,
|
||||
NS_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"the working directory is not writable");
|
||||
}
|
||||
|
||||
/*
|
||||
* Check the validity of the configuration.
|
||||
*/
|
||||
@@ -2231,6 +2263,43 @@ load_configuration(const char *filename, ns_server_t *server,
|
||||
*/
|
||||
set_limits(maps);
|
||||
|
||||
/*
|
||||
* Sanity check on "files" limit.
|
||||
*/
|
||||
result = isc_resource_curlimit(isc_resource_openfiles, &files);
|
||||
if (result == ISC_R_SUCCESS && files < FD_SETSIZE) {
|
||||
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL,
|
||||
NS_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
||||
"the 'files' limit (%" ISC_PRINT_QUADFORMAT "u) "
|
||||
"is less than FD_SETSIZE (%d), increase "
|
||||
"'files' in named.conf or recompile with a "
|
||||
"smaller FD_SETSIZE.", files, FD_SETSIZE);
|
||||
if (files > FD_SETSIZE)
|
||||
files = FD_SETSIZE;
|
||||
} else
|
||||
files = FD_SETSIZE;
|
||||
|
||||
/*
|
||||
* Set the number of socket reserved for TCP, stdio etc.
|
||||
*/
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "reserved-sockets", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
reserved = cfg_obj_asuint32(obj);
|
||||
if (files < 128U) /* Prevent underflow. */
|
||||
reserved = 0;
|
||||
else if (reserved > files - 128U) /* Mimimum UDP space. */
|
||||
reserved = files - 128;
|
||||
if (reserved < 128U) /* Mimimum TCP/stdio space. */
|
||||
reserved = 128;
|
||||
if (reserved + 128U > files) {
|
||||
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL,
|
||||
NS_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
||||
"less than 128 UDP sockets available after "
|
||||
"applying 'reserved-sockets' and 'files'");
|
||||
}
|
||||
isc__socketmgr_setreserved(ns_g_socketmgr, reserved);
|
||||
|
||||
/*
|
||||
* Configure various server options.
|
||||
*/
|
||||
@@ -2671,7 +2740,7 @@ load_configuration(const char *filename, ns_server_t *server,
|
||||
ns_os_writepidfile(lwresd_g_defaultpidfile, first_time);
|
||||
else
|
||||
ns_os_writepidfile(ns_g_defaultpidfile, first_time);
|
||||
|
||||
|
||||
obj = NULL;
|
||||
if (options != NULL &&
|
||||
cfg_map_get(options, "memstatistics-file", &obj) == ISC_R_SUCCESS)
|
||||
@@ -2805,7 +2874,7 @@ load_zones(ns_server_t *server, isc_boolean_t stop) {
|
||||
*/
|
||||
CHECK(dns_zonemgr_forcemaint(server->zonemgr));
|
||||
cleanup:
|
||||
isc_task_endexclusive(server->task);
|
||||
isc_task_endexclusive(server->task);
|
||||
return (result);
|
||||
}
|
||||
|
||||
@@ -2833,7 +2902,7 @@ load_new_zones(ns_server_t *server, isc_boolean_t stop) {
|
||||
*/
|
||||
dns_zonemgr_resumexfrs(server->zonemgr);
|
||||
cleanup:
|
||||
isc_task_endexclusive(server->task);
|
||||
isc_task_endexclusive(server->task);
|
||||
return (result);
|
||||
}
|
||||
|
||||
@@ -2887,7 +2956,7 @@ run_server(isc_task_t *task, isc_event_t *event) {
|
||||
ISC_LOG_NOTICE, "running");
|
||||
}
|
||||
|
||||
void
|
||||
void
|
||||
ns_server_flushonshutdown(ns_server_t *server, isc_boolean_t flush) {
|
||||
|
||||
REQUIRE(NS_SERVER_VALID(server));
|
||||
@@ -3019,7 +3088,7 @@ ns_server_create(isc_mem_t *mctx, ns_server_t **serverp) {
|
||||
|
||||
server->interface_timer = NULL;
|
||||
server->heartbeat_timer = NULL;
|
||||
|
||||
|
||||
server->interface_interval = 0;
|
||||
server->heartbeat_interval = 0;
|
||||
|
||||
@@ -3042,7 +3111,7 @@ ns_server_create(isc_mem_t *mctx, ns_server_t **serverp) {
|
||||
|
||||
server->hostname_set = ISC_FALSE;
|
||||
server->hostname = NULL;
|
||||
server->version_set = ISC_FALSE;
|
||||
server->version_set = ISC_FALSE;
|
||||
server->version = NULL;
|
||||
server->server_usehostname = ISC_FALSE;
|
||||
server->server_id = NULL;
|
||||
@@ -3198,7 +3267,7 @@ ns_add_reserved_dispatch(ns_server_t *server, const isc_sockaddr_t *addr) {
|
||||
result = dns_dispatch_getudp(ns_g_dispatchmgr, ns_g_socketmgr,
|
||||
ns_g_taskmgr, &dispatch->addr, 4096,
|
||||
1000, 32768, 16411, 16433,
|
||||
attrs, attrmask, &dispatch->dispatch);
|
||||
attrs, attrmask, &dispatch->dispatch);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto cleanup;
|
||||
|
||||
@@ -3301,7 +3370,7 @@ next_token(char **stringp, const char *delim) {
|
||||
break;
|
||||
} while (*res == '\0');
|
||||
return (res);
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
* Find the zone specified in the control channel command 'args',
|
||||
@@ -3359,14 +3428,14 @@ zone_from_args(ns_server_t *server, char *args, dns_zone_t **zonep) {
|
||||
} else {
|
||||
rdclass = dns_rdataclass_in;
|
||||
}
|
||||
|
||||
|
||||
if (viewtxt == NULL)
|
||||
viewtxt = "_default";
|
||||
result = dns_viewlist_find(&server->viewlist, viewtxt,
|
||||
rdclass, &view);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto fail1;
|
||||
|
||||
|
||||
result = dns_zt_find(view->zonetable, dns_fixedname_name(&name),
|
||||
0, NULL, zonep);
|
||||
/* Partial match? */
|
||||
@@ -3385,7 +3454,7 @@ ns_server_retransfercommand(ns_server_t *server, char *args) {
|
||||
isc_result_t result;
|
||||
dns_zone_t *zone = NULL;
|
||||
dns_zonetype_t type;
|
||||
|
||||
|
||||
result = zone_from_args(server, args, &zone);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
return (result);
|
||||
@@ -3398,7 +3467,7 @@ ns_server_retransfercommand(ns_server_t *server, char *args) {
|
||||
result = ISC_R_NOTFOUND;
|
||||
dns_zone_detach(&zone);
|
||||
return (result);
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
* Act on a "reload" command from the command channel.
|
||||
@@ -3409,7 +3478,7 @@ ns_server_reloadcommand(ns_server_t *server, char *args, isc_buffer_t *text) {
|
||||
dns_zone_t *zone = NULL;
|
||||
dns_zonetype_t type;
|
||||
const char *msg = NULL;
|
||||
|
||||
|
||||
result = zone_from_args(server, args, &zone);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
return (result);
|
||||
@@ -3421,11 +3490,12 @@ ns_server_reloadcommand(ns_server_t *server, char *args, isc_buffer_t *text) {
|
||||
type = dns_zone_gettype(zone);
|
||||
if (type == dns_zone_slave || type == dns_zone_stub) {
|
||||
dns_zone_refresh(zone);
|
||||
dns_zone_detach(&zone);
|
||||
msg = "zone refresh queued";
|
||||
} else {
|
||||
result = dns_zone_load(zone);
|
||||
dns_zone_detach(&zone);
|
||||
switch (result) {
|
||||
switch (result) {
|
||||
case ISC_R_SUCCESS:
|
||||
msg = "zone reload successful";
|
||||
break;
|
||||
@@ -3447,7 +3517,7 @@ ns_server_reloadcommand(ns_server_t *server, char *args, isc_buffer_t *text) {
|
||||
isc_buffer_putmem(text, (const unsigned char *)msg,
|
||||
strlen(msg) + 1);
|
||||
return (result);
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
* Act on a "reconfig" command from the command channel.
|
||||
@@ -3485,17 +3555,17 @@ ns_server_refreshcommand(ns_server_t *server, char *args, isc_buffer_t *text) {
|
||||
isc_buffer_putmem(text, msg1, sizeof(msg1));
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
|
||||
dns_zone_detach(&zone);
|
||||
if (sizeof(msg2) <= isc_buffer_availablelength(text))
|
||||
isc_buffer_putmem(text, msg2, sizeof(msg2));
|
||||
return (ISC_R_FAILURE);
|
||||
}
|
||||
}
|
||||
|
||||
isc_result_t
|
||||
ns_server_togglequerylog(ns_server_t *server) {
|
||||
server->log_queries = server->log_queries ? ISC_FALSE : ISC_TRUE;
|
||||
|
||||
|
||||
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL,
|
||||
NS_LOGMODULE_SERVER, ISC_LOG_INFO,
|
||||
"query logging is now %s",
|
||||
@@ -3599,15 +3669,15 @@ ns_server_dumpstats(ns_server_t *server) {
|
||||
|
||||
CHECKMF(isc_stdio_open(server->statsfile, "a", &fp),
|
||||
"could not open statistics dump file", server->statsfile);
|
||||
|
||||
|
||||
ncounters = DNS_STATS_NCOUNTERS;
|
||||
fprintf(fp, "+++ Statistics Dump +++ (%lu)\n", (unsigned long)now);
|
||||
|
||||
|
||||
for (i = 0; i < ncounters; i++)
|
||||
fprintf(fp, "%s %" ISC_PRINT_QUADFORMAT "u\n",
|
||||
dns_statscounter_names[i],
|
||||
server->querystats[i]);
|
||||
|
||||
|
||||
zone = NULL;
|
||||
for (result = dns_zone_first(server->zonemgr, &zone);
|
||||
result == ISC_R_SUCCESS;
|
||||
@@ -3618,7 +3688,7 @@ ns_server_dumpstats(ns_server_t *server) {
|
||||
char zonename[DNS_NAME_FORMATSIZE];
|
||||
dns_view_t *view;
|
||||
char *viewname;
|
||||
|
||||
|
||||
dns_name_format(dns_zone_getorigin(zone),
|
||||
zonename, sizeof(zonename));
|
||||
view = dns_zone_getview(zone);
|
||||
@@ -3638,7 +3708,7 @@ ns_server_dumpstats(ns_server_t *server) {
|
||||
if (result == ISC_R_NOMORE)
|
||||
result = ISC_R_SUCCESS;
|
||||
CHECK(result);
|
||||
|
||||
|
||||
fprintf(fp, "--- Statistics Dump --- (%lu)\n", (unsigned long)now);
|
||||
|
||||
cleanup:
|
||||
@@ -3666,7 +3736,7 @@ static isc_result_t
|
||||
add_view_tolist(struct dumpcontext *dctx, dns_view_t *view) {
|
||||
struct viewlistentry *vle;
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
|
||||
|
||||
/*
|
||||
* Prevent duplicate views.
|
||||
*/
|
||||
@@ -3729,7 +3799,7 @@ dumpdone(void *arg, isc_result_t result) {
|
||||
struct dumpcontext *dctx = arg;
|
||||
char buf[1024+32];
|
||||
const dns_master_style_t *style;
|
||||
|
||||
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto cleanup;
|
||||
if (dctx->mdctx != NULL)
|
||||
@@ -3886,7 +3956,7 @@ ns_server_dumpdb(ns_server_t *server, char *args) {
|
||||
dctx->dumpzones = ISC_TRUE;
|
||||
dctx->dumpcache = ISC_FALSE;
|
||||
ptr = next_token(&args, " \t");
|
||||
}
|
||||
}
|
||||
|
||||
nextview:
|
||||
for (view = ISC_LIST_HEAD(server->viewlist);
|
||||
@@ -3961,7 +4031,8 @@ isc_result_t
|
||||
ns_server_flushcache(ns_server_t *server, char *args) {
|
||||
char *ptr, *viewname;
|
||||
dns_view_t *view;
|
||||
isc_boolean_t flushed = ISC_FALSE;
|
||||
isc_boolean_t flushed;
|
||||
isc_boolean_t found;
|
||||
isc_result_t result;
|
||||
|
||||
/* Skip the command name. */
|
||||
@@ -3974,23 +4045,28 @@ ns_server_flushcache(ns_server_t *server, char *args) {
|
||||
|
||||
result = isc_task_beginexclusive(server->task);
|
||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
flushed = ISC_TRUE;
|
||||
found = ISC_FALSE;
|
||||
for (view = ISC_LIST_HEAD(server->viewlist);
|
||||
view != NULL;
|
||||
view = ISC_LIST_NEXT(view, link))
|
||||
{
|
||||
if (viewname != NULL && strcasecmp(viewname, view->name) != 0)
|
||||
continue;
|
||||
found = ISC_TRUE;
|
||||
result = dns_view_flushcache(view);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto out;
|
||||
flushed = ISC_TRUE;
|
||||
flushed = ISC_FALSE;
|
||||
}
|
||||
if (flushed)
|
||||
if (flushed && found) {
|
||||
result = ISC_R_SUCCESS;
|
||||
else
|
||||
result = ISC_R_FAILURE;
|
||||
out:
|
||||
isc_task_endexclusive(server->task);
|
||||
} else {
|
||||
if (!found)
|
||||
result = ISC_R_NOTFOUND;
|
||||
else
|
||||
result = ISC_R_FAILURE;
|
||||
}
|
||||
isc_task_endexclusive(server->task);
|
||||
return (result);
|
||||
}
|
||||
|
||||
@@ -3998,7 +4074,8 @@ isc_result_t
|
||||
ns_server_flushname(ns_server_t *server, char *args) {
|
||||
char *ptr, *target, *viewname;
|
||||
dns_view_t *view;
|
||||
isc_boolean_t flushed = ISC_FALSE;
|
||||
isc_boolean_t flushed;
|
||||
isc_boolean_t found;
|
||||
isc_result_t result;
|
||||
isc_buffer_t b;
|
||||
dns_fixedname_t fixed;
|
||||
@@ -4028,21 +4105,25 @@ ns_server_flushname(ns_server_t *server, char *args) {
|
||||
result = isc_task_beginexclusive(server->task);
|
||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
flushed = ISC_TRUE;
|
||||
found = ISC_FALSE;
|
||||
for (view = ISC_LIST_HEAD(server->viewlist);
|
||||
view != NULL;
|
||||
view = ISC_LIST_NEXT(view, link))
|
||||
{
|
||||
if (viewname != NULL && strcasecmp(viewname, view->name) != 0)
|
||||
continue;
|
||||
found = ISC_TRUE;
|
||||
result = dns_view_flushname(view, name);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
flushed = ISC_FALSE;
|
||||
}
|
||||
if (flushed)
|
||||
if (flushed && found)
|
||||
result = ISC_R_SUCCESS;
|
||||
else if (!found)
|
||||
result = ISC_R_NOTFOUND;
|
||||
else
|
||||
result = ISC_R_FAILURE;
|
||||
isc_task_endexclusive(server->task);
|
||||
isc_task_endexclusive(server->task);
|
||||
return (result);
|
||||
}
|
||||
|
||||
@@ -4093,7 +4174,7 @@ ns_server_freeze(ns_server_t *server, isc_boolean_t freeze, char *args) {
|
||||
char *journal;
|
||||
const char *vname, *sep;
|
||||
isc_boolean_t frozen;
|
||||
|
||||
|
||||
result = zone_from_args(server, args, &zone);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
return (result);
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2006, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000, 2001, 2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: sortlist.c,v 1.5.12.8 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: sortlist.c,v 1.5.12.9 2007/08/28 07:19:08 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2006, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2001, 2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: tsigconf.c,v 1.21.208.8 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: tsigconf.c,v 1.21.208.9 2007/08/28 07:19:08 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 1999-2001, 2003 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and distribute this software for any
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
@@ -13,7 +13,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: Makefile.in,v 1.6.12.5 2007/01/18 00:06:04 marka Exp $
|
||||
# $Id: Makefile.in,v 1.6.12.6 2007/08/28 07:19:08 tbox Exp $
|
||||
|
||||
srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: os.h,v 1.14.2.2.8.11 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: os.h,v 1.14.2.2.8.12 2007/08/28 07:19:08 tbox Exp $ */
|
||||
|
||||
#ifndef NS_OS_H
|
||||
#define NS_OS_H 1
|
||||
|
||||
+13
-9
@@ -1,8 +1,8 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: os.c,v 1.46.2.4.8.26 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: os.c,v 1.46.2.4.8.30 2008/01/17 23:45:27 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
#include <stdarg.h>
|
||||
@@ -324,7 +324,7 @@ ns_os_daemonize(void) {
|
||||
/*
|
||||
* Wait for the child to finish loading for the first time.
|
||||
* This would be so much simpler if fork() worked once we
|
||||
* were multi-threaded.
|
||||
* were multi-threaded.
|
||||
*/
|
||||
(void)close(dfd[1]);
|
||||
do {
|
||||
@@ -494,15 +494,19 @@ ns_os_changeuser(void) {
|
||||
ns_main_earlyfatal("setuid(): %s", strbuf);
|
||||
}
|
||||
|
||||
#if defined(HAVE_LINUX_CAPABILITY_H) && !defined(HAVE_LINUXTHREADS)
|
||||
linux_minprivs();
|
||||
#endif
|
||||
#if defined(HAVE_SYS_PRCTL_H) && defined(PR_SET_DUMPABLE)
|
||||
/*
|
||||
* Restore the ability of named to drop core after the setuid()
|
||||
* call has disabled it.
|
||||
*/
|
||||
prctl(PR_SET_DUMPABLE,1,0,0,0);
|
||||
if (prctl(PR_SET_DUMPABLE,1,0,0,0) < 0) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
ns_main_earlywarning("prctl(PR_SET_DUMPABLE) failed: %s",
|
||||
strbuf);
|
||||
}
|
||||
#endif
|
||||
#if defined(HAVE_LINUX_CAPABILITY_H) && !defined(HAVE_LINUXTHREADS)
|
||||
linux_minprivs();
|
||||
#endif
|
||||
}
|
||||
|
||||
@@ -663,7 +667,7 @@ ns_os_shutdownmsg(char *command, isc_buffer_t *text) {
|
||||
ptr = next_token(&input, " \t");
|
||||
if (ptr == NULL)
|
||||
return;
|
||||
|
||||
|
||||
if (strcmp(ptr, "-p") != 0)
|
||||
return;
|
||||
|
||||
|
||||
+20
-13
@@ -1,8 +1,8 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2006 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: update.c,v 1.88.2.5.2.29 2006/01/06 00:01:42 marka Exp $ */
|
||||
/* $Id: update.c,v 1.88.2.5.2.35 2008/01/17 23:45:27 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -112,7 +112,7 @@
|
||||
} \
|
||||
update_log(client, zone, LOGLEVEL_PROTOCOL, \
|
||||
"update %s: %s (%s)", _what, \
|
||||
msg, isc_result_totext(result)); \
|
||||
msg, isc_result_totext(result)); \
|
||||
if (result != ISC_R_SUCCESS) goto failure; \
|
||||
} while (0)
|
||||
|
||||
@@ -401,7 +401,7 @@ foreach_node_rr_action(void *data, dns_rdataset_t *rdataset) {
|
||||
result = dns_rdataset_next(rdataset))
|
||||
{
|
||||
rr_t rr = { 0, DNS_RDATA_INIT };
|
||||
|
||||
|
||||
dns_rdataset_current(rdataset, &rr.rdata);
|
||||
rr.ttl = rdataset->ttl;
|
||||
result = (*ctx->rr_action)(ctx->rr_action_data, &rr);
|
||||
@@ -841,10 +841,14 @@ temp_check(isc_mem_t *mctx, dns_diff_t *temp, dns_db_t *db,
|
||||
/* A new unique name begins here. */
|
||||
node = NULL;
|
||||
result = dns_db_findnode(db, name, ISC_FALSE, &node);
|
||||
if (result == ISC_R_NOTFOUND)
|
||||
if (result == ISC_R_NOTFOUND) {
|
||||
dns_diff_clear(&trash);
|
||||
return (DNS_R_NXRRSET);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
}
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
dns_diff_clear(&trash);
|
||||
return (result);
|
||||
}
|
||||
|
||||
/* A new unique type begins here. */
|
||||
while (t != NULL && dns_name_equal(&t->name, name)) {
|
||||
@@ -852,7 +856,7 @@ temp_check(isc_mem_t *mctx, dns_diff_t *temp, dns_db_t *db,
|
||||
dns_rdataset_t rdataset;
|
||||
dns_diff_t d_rrs; /* Database RRs with
|
||||
this name and type */
|
||||
dns_diff_t u_rrs; /* Update RRs with
|
||||
dns_diff_t u_rrs; /* Update RRs with
|
||||
this name and type */
|
||||
|
||||
*typep = type = t->rdata.type;
|
||||
@@ -872,6 +876,7 @@ temp_check(isc_mem_t *mctx, dns_diff_t *temp, dns_db_t *db,
|
||||
&rdataset, NULL);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
dns_db_detachnode(db, &node);
|
||||
dns_diff_clear(&trash);
|
||||
return (DNS_R_NXRRSET);
|
||||
}
|
||||
|
||||
@@ -1117,7 +1122,7 @@ typedef struct {
|
||||
|
||||
static isc_result_t
|
||||
add_rr_prepare_action(void *data, rr_t *rr) {
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
add_rr_prepare_ctx_t *ctx = data;
|
||||
dns_difftuple_t *tuple = NULL;
|
||||
isc_boolean_t equal;
|
||||
@@ -1631,6 +1636,8 @@ add_sigs(dns_db_t *db, dns_dbversion_t *ver, dns_name_t *name,
|
||||
dns_db_detachnode(db, &node);
|
||||
|
||||
for (i = 0; i < nkeys; i++) {
|
||||
if (!dst_key_isprivate(keys[i]))
|
||||
continue;
|
||||
/* Calculate the signature, creating a RRSIG RDATA. */
|
||||
CHECK(dns_dnssec_sign(name, &rdataset, keys[i],
|
||||
&inception, &expire,
|
||||
@@ -1710,7 +1717,7 @@ update_signatures(ns_client_t *client, dns_zone_t *zone, dns_db_t *db,
|
||||
CHECK(dns_db_findnode(db, dns_db_origin(db), ISC_FALSE, &node));
|
||||
dns_rdataset_init(&rdataset);
|
||||
CHECK(dns_db_findrdataset(db, node, newver, dns_rdatatype_soa, 0,
|
||||
(isc_stdtime_t) 0, &rdataset, NULL));
|
||||
(isc_stdtime_t) 0, &rdataset, NULL));
|
||||
CHECK(dns_rdataset_first(&rdataset));
|
||||
dns_rdataset_current(&rdataset, &rdata);
|
||||
CHECK(dns_rdata_tostruct(&rdata, &soa, NULL));
|
||||
@@ -2306,7 +2313,7 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
||||
else if (client->signer == NULL)
|
||||
CHECK(checkupdateacl(client, NULL, "update", zonename,
|
||||
ISC_FALSE));
|
||||
|
||||
|
||||
if (dns_zone_getupdatedisabled(zone))
|
||||
FAILC(DNS_R_REFUSED, "dynamic update temporarily disabled");
|
||||
|
||||
@@ -2701,7 +2708,7 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
||||
* The reason for failure should have been logged at this point.
|
||||
*/
|
||||
if (ver != NULL) {
|
||||
update_log(client, zone, LOGLEVEL_DEBUG,
|
||||
update_log(client, zone, LOGLEVEL_DEBUG,
|
||||
"rolling back");
|
||||
dns_db_closeversion(db, &ver, ISC_FALSE);
|
||||
}
|
||||
@@ -2753,7 +2760,7 @@ updatedone_action(isc_task_t *task, isc_event_t *event) {
|
||||
|
||||
static void
|
||||
forward_fail(isc_task_t *task, isc_event_t *event) {
|
||||
ns_client_t *client = (ns_client_t *)event->ev_arg;
|
||||
ns_client_t *client = (ns_client_t *)event->ev_arg;
|
||||
|
||||
UNUSED(task);
|
||||
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: os.h,v 1.1.2.2.8.12 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: os.h,v 1.1.2.2.8.13 2007/08/28 07:19:08 tbox Exp $ */
|
||||
|
||||
#ifndef NS_OS_H
|
||||
#define NS_OS_H 1
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: ntservice.c,v 1.3.2.1.10.5 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: ntservice.c,v 1.3.2.1.10.6 2007/08/28 07:19:08 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
#include <stdio.h>
|
||||
|
||||
+16
-6
@@ -1,8 +1,8 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2005, 2007, 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: os.c,v 1.5.2.3.8.14 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: os.c,v 1.5.2.3.8.18 2008/01/17 23:45:27 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
#include <stdarg.h>
|
||||
@@ -51,7 +51,7 @@ static int devnullfd = -1;
|
||||
|
||||
static BOOL Initialized = FALSE;
|
||||
|
||||
static char *version_error =
|
||||
static char *version_error =
|
||||
"named requires Windows 2000 Service Pack 2 or later to run correctly";
|
||||
|
||||
void
|
||||
@@ -83,7 +83,7 @@ version_check(const char *progname) {
|
||||
if(isc_win32os_versioncheck(5, 0, 2, 0) < 0)
|
||||
if (ntservice_isservice())
|
||||
NTReportError(progname, version_error);
|
||||
else
|
||||
else
|
||||
fprintf(stderr, "%s\n", version_error);
|
||||
}
|
||||
|
||||
@@ -103,7 +103,16 @@ void
|
||||
ns_os_init(const char *progname) {
|
||||
ns_paths_init();
|
||||
setup_syslog(progname);
|
||||
ntservice_init();
|
||||
/*
|
||||
* XXXMPA. We may need to split ntservice_init() in two and
|
||||
* just mark as running in ns_os_started(). If we do that
|
||||
* this is where the first part of ntservice_init() should be
|
||||
* called from.
|
||||
*
|
||||
* XXX970 Remove comment if no problems by 9.7.0.
|
||||
*
|
||||
* ntservice_init();
|
||||
*/
|
||||
version_check(progname);
|
||||
}
|
||||
|
||||
@@ -285,4 +294,5 @@ ns_os_tzset(void) {
|
||||
|
||||
void
|
||||
ns_os_started(void) {
|
||||
ntservice_init();
|
||||
}
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and distribute this software for any
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
@@ -13,7 +13,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: Makefile.in,v 1.15.12.12 2007/01/18 00:06:04 marka Exp $
|
||||
# $Id: Makefile.in,v 1.15.12.13 2007/08/28 07:19:08 tbox Exp $
|
||||
|
||||
srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
|
||||
@@ -13,7 +13,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: nsupdate.8,v 1.24.2.2.2.12 2007/01/30 00:11:48 marka Exp $
|
||||
.\" $Id: nsupdate.8,v 1.24.2.2.2.13 2007/05/09 03:32:36 marka Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
@@ -55,7 +55,7 @@ operate in debug mode. This provides tracing information about the update reques
|
||||
.PP
|
||||
Transaction signatures can be used to authenticate the Dynamic DNS updates. These use the TSIG resource record type described in RFC2845 or the SIG(0) record described in RFC3535 and RFC2931. TSIG relies on a shared secret that should only be known to
|
||||
\fBnsupdate\fR
|
||||
and the name server. Currently, the only supported encryption algorithm for TSIG is HMAC\-MD5, which is defined in RFC 2104. Once other algorithms are defined for TSIG, applications will need to ensure they select the appropriate algorithm as well as the key when authenticating each other. For instance suitable
|
||||
and the name server. Currently, the only supported encryption algorithm for TSIG is HMAC\-MD5, which is defined in RFC 2104. Once other algorithms are defined for TSIG, applications will need to ensure they select the appropriate algorithm as well as the key when authenticating each other. For instance, suitable
|
||||
\fBkey\fR
|
||||
and
|
||||
\fBserver\fR
|
||||
@@ -106,15 +106,15 @@ use a TCP connection. This may be preferable when a batch of update requests is
|
||||
.PP
|
||||
The
|
||||
\fB\-t\fR
|
||||
option sets the maximum time a update request can take before it is aborted. The default is 300 seconds. Zero can be used to disable the timeout.
|
||||
option sets the maximum time an update request can take before it is aborted. The default is 300 seconds. Zero can be used to disable the timeout.
|
||||
.PP
|
||||
The
|
||||
\fB\-u\fR
|
||||
option sets the UDP retry interval. The default is 3 seconds. If zero the interval will be computed from the timeout interval and number of UDP retries.
|
||||
option sets the UDP retry interval. The default is 3 seconds. If zero, the interval will be computed from the timeout interval and number of UDP retries.
|
||||
.PP
|
||||
The
|
||||
\fB\-r\fR
|
||||
option sets the number of UDP retries. The default is 3. If zero only one update request will be made.
|
||||
option sets the number of UDP retries. The default is 3. If zero, only one update request will be made.
|
||||
.SH "INPUT FORMAT"
|
||||
.PP
|
||||
\fBnsupdate\fR
|
||||
@@ -164,13 +164,13 @@ will attempt determine the correct zone to update based on the rest of the input
|
||||
.RS 4
|
||||
Specify the default class. If no
|
||||
\fIclass\fR
|
||||
is specified the default class is
|
||||
is specified, the default class is
|
||||
\fIIN\fR.
|
||||
.RE
|
||||
.PP
|
||||
\fBkey\fR {name} {secret}
|
||||
.RS 4
|
||||
Specifies that all updates are to be TSIG signed using the
|
||||
Specifies that all updates are to be TSIG\-signed using the
|
||||
\fIkeyname\fR
|
||||
\fIkeysecret\fR
|
||||
pair. The
|
||||
@@ -293,9 +293,9 @@ zone. Notice that the input in each example contains a trailing blank line so th
|
||||
.PP
|
||||
Any A records for
|
||||
\fBoldhost.example.com\fR
|
||||
are deleted. and an A record for
|
||||
are deleted. And an A record for
|
||||
\fBnewhost.example.com\fR
|
||||
it IP address 172.16.1.1 is added. The newly\-added record has a 1 day TTL (86400 seconds)
|
||||
with IP address 172.16.1.1 is added. The newly\-added record has a 1 day TTL (86400 seconds).
|
||||
.sp
|
||||
.RS 4
|
||||
.nf
|
||||
|
||||
+18
-16
@@ -1,8 +1,8 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2006 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: nsupdate.c,v 1.103.2.15.2.24 2006/12/07 05:39:26 marka Exp $ */
|
||||
/* $Id: nsupdate.c,v 1.103.2.15.2.30 2008/01/17 23:45:27 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -1038,7 +1038,7 @@ evaluate_key(char *cmdline) {
|
||||
secret = isc_mem_allocate(mctx, secretlen);
|
||||
if (secret == NULL)
|
||||
fatal("out of memory");
|
||||
|
||||
|
||||
isc_buffer_init(&secretbuf, secret, secretlen);
|
||||
result = isc_base64_decodestring(secretstr, &secretbuf);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
@@ -1104,8 +1104,8 @@ evaluate_class(char *cmdline) {
|
||||
}
|
||||
|
||||
r.base = word;
|
||||
r.length = strlen(word);
|
||||
result = dns_rdataclass_fromtext(&rdclass, &r);
|
||||
r.length = strlen(word);
|
||||
result = dns_rdataclass_fromtext(&rdclass, &r);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
fprintf(stderr, "could not parse class name: %s\n", word);
|
||||
return (STATUS_SYNTAX);
|
||||
@@ -1289,8 +1289,7 @@ update_addordelete(char *cmdline, isc_boolean_t isdelete) {
|
||||
failure:
|
||||
if (name != NULL)
|
||||
dns_message_puttempname(updatemsg, &name);
|
||||
if (rdata != NULL)
|
||||
dns_message_puttemprdata(updatemsg, &rdata);
|
||||
dns_message_puttemprdata(updatemsg, &rdata);
|
||||
return (STATUS_SYNTAX);
|
||||
}
|
||||
|
||||
@@ -1324,7 +1323,7 @@ show_message(dns_message_t *msg) {
|
||||
|
||||
ddebug("show_message()");
|
||||
bufsz = INITTEXT;
|
||||
do {
|
||||
do {
|
||||
if (bufsz > MAXTEXT) {
|
||||
fprintf(stderr, "could not allocate large enough "
|
||||
"buffer to display message\n");
|
||||
@@ -1409,8 +1408,11 @@ user_interaction(void) {
|
||||
isc_uint16_t result = STATUS_MORE;
|
||||
|
||||
ddebug("user_interaction()");
|
||||
while ((result == STATUS_MORE) || (result == STATUS_SYNTAX))
|
||||
while ((result == STATUS_MORE) || (result == STATUS_SYNTAX)) {
|
||||
result = get_next_command();
|
||||
if (!interactive && result == STATUS_SYNTAX)
|
||||
fatal("syntax error");
|
||||
}
|
||||
if (result == STATUS_SEND)
|
||||
return (ISC_TRUE);
|
||||
return (ISC_FALSE);
|
||||
@@ -1503,7 +1505,7 @@ update_completed(isc_task_t *task, isc_event_t *event) {
|
||||
char buf[64];
|
||||
isc_buffer_t b;
|
||||
dns_rdataset_t *rds;
|
||||
|
||||
|
||||
isc_buffer_init(&b, buf, sizeof(buf) - 1);
|
||||
result = dns_rcode_totext(answer->rcode, &b);
|
||||
check_result(result, "dns_rcode_totext");
|
||||
@@ -1519,7 +1521,7 @@ update_completed(isc_task_t *task, isc_event_t *event) {
|
||||
int bufsz;
|
||||
|
||||
bufsz = INITTEXT;
|
||||
do {
|
||||
do {
|
||||
if (bufsz > MAXTEXT) {
|
||||
fprintf(stderr, "could not allocate large "
|
||||
"enough buffer to display message\n");
|
||||
@@ -1618,7 +1620,7 @@ recvsoa(isc_task_t *task, isc_event_t *event) {
|
||||
ddebug("recvsoa()");
|
||||
|
||||
requests--;
|
||||
|
||||
|
||||
REQUIRE(event->ev_type == DNS_EVENT_REQUESTDONE);
|
||||
reqev = (dns_requestevent_t *)event;
|
||||
request = reqev->request;
|
||||
@@ -1735,7 +1737,7 @@ recvsoa(isc_task_t *task, isc_event_t *event) {
|
||||
section = DNS_SECTION_ANSWER;
|
||||
else if (pass == 1)
|
||||
section = DNS_SECTION_AUTHORITY;
|
||||
else
|
||||
else
|
||||
goto droplabel;
|
||||
|
||||
result = dns_message_firstname(rcvmsg, section);
|
||||
@@ -1764,7 +1766,7 @@ recvsoa(isc_task_t *task, isc_event_t *event) {
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
result = dns_message_nextname(rcvmsg, section);
|
||||
}
|
||||
|
||||
@@ -1829,7 +1831,7 @@ recvsoa(isc_task_t *task, isc_event_t *event) {
|
||||
dns_message_destroy(&rcvmsg);
|
||||
ddebug("Out of recvsoa");
|
||||
return;
|
||||
|
||||
|
||||
droplabel:
|
||||
result = dns_message_firstname(soaquery, DNS_SECTION_QUESTION);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
|
||||
@@ -5,7 +5,7 @@
|
||||
- Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
-
|
||||
- Permission to use, copy, modify, and distribute this software for any
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
@@ -18,7 +18,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: nsupdate.docbook,v 1.8.2.3.2.14 2007/01/29 23:57:18 marka Exp $ -->
|
||||
<!-- $Id: nsupdate.docbook,v 1.8.2.3.2.16 2007/08/28 07:19:08 tbox Exp $ -->
|
||||
|
||||
<refentry>
|
||||
<refentryinfo>
|
||||
@@ -113,7 +113,7 @@ HMAC-MD5, which is defined in RFC 2104.
|
||||
Once other algorithms are defined for TSIG, applications will need to
|
||||
ensure they select the appropriate algorithm as well as the key when
|
||||
authenticating each other.
|
||||
For instance suitable
|
||||
For instance, suitable
|
||||
<type>key</type>
|
||||
and
|
||||
<type>server</type>
|
||||
@@ -185,16 +185,16 @@ option makes
|
||||
use a TCP connection.
|
||||
This may be preferable when a batch of update requests is made.
|
||||
</para>
|
||||
<para>The <option>-t</option> option sets the maximum time a update request can
|
||||
<para>The <option>-t</option> option sets the maximum time an update request can
|
||||
take before it is aborted. The default is 300 seconds. Zero can be used
|
||||
to disable the timeout.
|
||||
</para>
|
||||
<para>The <option>-u</option> option sets the UDP retry interval. The default is
|
||||
3 seconds. If zero the interval will be computed from the timeout interval
|
||||
3 seconds. If zero, the interval will be computed from the timeout interval
|
||||
and number of UDP retries.
|
||||
</para>
|
||||
<para>The <option>-r</option> option sets the number of UDP retries. The default is
|
||||
3. If zero only one update request will be made.
|
||||
3. If zero, only one update request will be made.
|
||||
</para>
|
||||
</refsect1>
|
||||
|
||||
@@ -294,7 +294,7 @@ will attempt determine the correct zone to update based on the rest of the input
|
||||
<listitem>
|
||||
<para>
|
||||
Specify the default class.
|
||||
If no <parameter>class</parameter> is specified the default class is
|
||||
If no <parameter>class</parameter> is specified, the default class is
|
||||
<parameter>IN</parameter>.
|
||||
</para>
|
||||
</listitem>
|
||||
@@ -307,7 +307,7 @@ If no <parameter>class</parameter> is specified the default class is
|
||||
</term>
|
||||
<listitem>
|
||||
<para>
|
||||
Specifies that all updates are to be TSIG signed using the
|
||||
Specifies that all updates are to be TSIG-signed using the
|
||||
<parameter>keyname</parameter> <parameter>keysecret</parameter> pair.
|
||||
The <command>key</command> command
|
||||
overrides any key specified on the command line via
|
||||
@@ -524,10 +524,10 @@ master name server for
|
||||
Any A records for
|
||||
<type>oldhost.example.com</type>
|
||||
are deleted.
|
||||
and an A record for
|
||||
And an A record for
|
||||
<type>newhost.example.com</type>
|
||||
it IP address 172.16.1.1 is added.
|
||||
The newly-added record has a 1 day TTL (86400 seconds)
|
||||
with IP address 172.16.1.1 is added.
|
||||
The newly-added record has a 1 day TTL (86400 seconds).
|
||||
<programlisting>
|
||||
# nsupdate
|
||||
> prereq nxdomain nickname.example.com
|
||||
|
||||
+10
-10
@@ -14,7 +14,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: nsupdate.html,v 1.9.2.3.2.19 2007/01/30 00:11:48 marka Exp $ -->
|
||||
<!-- $Id: nsupdate.html,v 1.9.2.3.2.20 2007/05/09 03:32:36 marka Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
@@ -77,7 +77,7 @@ HMAC-MD5, which is defined in RFC 2104.
|
||||
Once other algorithms are defined for TSIG, applications will need to
|
||||
ensure they select the appropriate algorithm as well as the key when
|
||||
authenticating each other.
|
||||
For instance suitable
|
||||
For instance, suitable
|
||||
<span class="type">key</span>
|
||||
and
|
||||
<span class="type">server</span>
|
||||
@@ -147,16 +147,16 @@ option makes
|
||||
use a TCP connection.
|
||||
This may be preferable when a batch of update requests is made.
|
||||
</p>
|
||||
<p>The <code class="option">-t</code> option sets the maximum time a update request can
|
||||
<p>The <code class="option">-t</code> option sets the maximum time an update request can
|
||||
take before it is aborted. The default is 300 seconds. Zero can be used
|
||||
to disable the timeout.
|
||||
</p>
|
||||
<p>The <code class="option">-u</code> option sets the UDP retry interval. The default is
|
||||
3 seconds. If zero the interval will be computed from the timeout interval
|
||||
3 seconds. If zero, the interval will be computed from the timeout interval
|
||||
and number of UDP retries.
|
||||
</p>
|
||||
<p>The <code class="option">-r</code> option sets the number of UDP retries. The default is
|
||||
3. If zero only one update request will be made.
|
||||
3. If zero, only one update request will be made.
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
@@ -243,7 +243,7 @@ will attempt determine the correct zone to update based on the rest of the input
|
||||
</span></dt>
|
||||
<dd><p>
|
||||
Specify the default class.
|
||||
If no <em class="parameter"><code>class</code></em> is specified the default class is
|
||||
If no <em class="parameter"><code>class</code></em> is specified, the default class is
|
||||
<em class="parameter"><code>IN</code></em>.
|
||||
</p></dd>
|
||||
<dt><span class="term">
|
||||
@@ -252,7 +252,7 @@ If no <em class="parameter"><code>class</code></em> is specified the default cla
|
||||
{secret}
|
||||
</span></dt>
|
||||
<dd><p>
|
||||
Specifies that all updates are to be TSIG signed using the
|
||||
Specifies that all updates are to be TSIG-signed using the
|
||||
<em class="parameter"><code>keyname</code></em> <em class="parameter"><code>keysecret</code></em> pair.
|
||||
The <span><strong class="command">key</strong></span> command
|
||||
overrides any key specified on the command line via
|
||||
@@ -424,10 +424,10 @@ master name server for
|
||||
Any A records for
|
||||
<span class="type">oldhost.example.com</span>
|
||||
are deleted.
|
||||
and an A record for
|
||||
And an A record for
|
||||
<span class="type">newhost.example.com</span>
|
||||
it IP address 172.16.1.1 is added.
|
||||
The newly-added record has a 1 day TTL (86400 seconds)
|
||||
with IP address 172.16.1.1 is added.
|
||||
The newly-added record has a 1 day TTL (86400 seconds).
|
||||
</p>
|
||||
<pre class="programlisting">
|
||||
# nsupdate
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and distribute this software for any
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
@@ -13,7 +13,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: Makefile.in,v 1.32.2.3.8.11 2007/01/18 00:14:31 marka Exp $
|
||||
# $Id: Makefile.in,v 1.32.2.3.8.12 2007/08/28 07:19:08 tbox Exp $
|
||||
|
||||
srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
|
||||
@@ -5,7 +5,7 @@
|
||||
- Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2001, 2003 Internet Software Consortium.
|
||||
-
|
||||
- Permission to use, copy, modify, and distribute this software for any
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
@@ -18,7 +18,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: rndc-confgen.docbook,v 1.3.2.1.4.7 2007/01/29 23:57:18 marka Exp $ -->
|
||||
<!-- $Id: rndc-confgen.docbook,v 1.3.2.1.4.8 2007/08/28 07:19:08 tbox Exp $ -->
|
||||
|
||||
<refentry>
|
||||
<refentryinfo>
|
||||
|
||||
+11
-9
@@ -13,7 +13,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: rndc.8,v 1.24.206.8 2007/01/30 00:11:48 marka Exp $
|
||||
.\" $Id: rndc.8,v 1.24.206.12 2007/12/14 22:37:11 marka Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
@@ -47,8 +47,7 @@ is invoked with no command line options or arguments, it prints a short summary
|
||||
communicates with the name server over a TCP connection, sending commands authenticated with digital signatures. In the current versions of
|
||||
\fBrndc\fR
|
||||
and
|
||||
\fBnamed\fR
|
||||
named the only supported authentication algorithm is HMAC\-MD5, which uses a shared secret on each end of the connection. This provides TSIG\-style authentication for the command request and the name server's response. All commands sent over the channel must be signed by a key_id known to the server.
|
||||
\fBnamed\fR, the only supported authentication algorithm is HMAC\-MD5, which uses a shared secret on each end of the connection. This provides TSIG\-style authentication for the command request and the name server's response. All commands sent over the channel must be signed by a key_id known to the server.
|
||||
.PP
|
||||
\fBrndc\fR
|
||||
reads a configuration file to determine how to contact the name server and decide what algorithm and key it should use.
|
||||
@@ -78,7 +77,9 @@ does not exist.
|
||||
.RS 4
|
||||
\fIserver\fR
|
||||
is the name or address of the server which matches a server statement in the configuration file for
|
||||
\fBrndc\fR. If no server is supplied on the command line, the host named by the default\-server clause in the option statement of the configuration file will be used.
|
||||
\fBrndc\fR. If no server is supplied on the command line, the host named by the default\-server clause in the options statement of the
|
||||
\fBrndc\fR
|
||||
configuration file will be used.
|
||||
.RE
|
||||
.PP
|
||||
\-p \fIport\fR
|
||||
@@ -93,14 +94,14 @@ instead of BIND 9's default control channel port, 953.
|
||||
Enable verbose logging.
|
||||
.RE
|
||||
.PP
|
||||
\-y \fIkeyid\fR
|
||||
\-y \fIkey_id\fR
|
||||
.RS 4
|
||||
Use the key
|
||||
\fIkeyid\fR
|
||||
\fIkey_id\fR
|
||||
from the configuration file.
|
||||
\fIkeyid\fR
|
||||
\fIkey_id\fR
|
||||
must be known by named with the same algorithm and secret string in order for control message validation to succeed. If no
|
||||
\fIkeyid\fR
|
||||
\fIkey_id\fR
|
||||
is specified,
|
||||
\fBrndc\fR
|
||||
will first look for a key clause in the server statement of the server being used, or if no server statement is present for that host, then the default\-key clause of the options statement. Note that the configuration file contains shared secrets which are used to send authenticated control commands to name servers. It should therefore not have general read or write access.
|
||||
@@ -125,8 +126,9 @@ Several error messages could be clearer.
|
||||
.SH "SEE ALSO"
|
||||
.PP
|
||||
\fBrndc.conf\fR(5),
|
||||
\fBrndc\-confgen\fR(8),
|
||||
\fBnamed\fR(8),
|
||||
\fBnamed.conf\fR(5)
|
||||
\fBnamed.conf\fR(5),
|
||||
\fBndc\fR(8),
|
||||
BIND 9 Administrator Reference Manual.
|
||||
.SH "AUTHOR"
|
||||
|
||||
@@ -13,7 +13,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: rndc.conf.5,v 1.21.206.8 2007/01/30 00:11:48 marka Exp $
|
||||
.\" $Id: rndc.conf.5,v 1.21.206.9 2007/05/09 03:32:36 marka Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
@@ -128,7 +128,7 @@ To generate a random secret with
|
||||
.PP
|
||||
A complete
|
||||
\fIrndc.conf\fR
|
||||
file, including the randomly generated key, will be written to the standard output. Commented out
|
||||
file, including the randomly generated key, will be written to the standard output. Commented\-out
|
||||
\fBkey\fR
|
||||
and
|
||||
\fBcontrols\fR
|
||||
|
||||
@@ -5,7 +5,7 @@
|
||||
- Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
-
|
||||
- Permission to use, copy, modify, and distribute this software for any
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
@@ -18,7 +18,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: rndc.conf.docbook,v 1.4.206.6 2007/01/29 23:57:18 marka Exp $ -->
|
||||
<!-- $Id: rndc.conf.docbook,v 1.4.206.8 2007/08/28 07:19:08 tbox Exp $ -->
|
||||
|
||||
<refentry>
|
||||
<refentryinfo>
|
||||
@@ -167,7 +167,7 @@
|
||||
<para>
|
||||
A complete <filename>rndc.conf</filename> file, including the
|
||||
randomly generated key, will be written to the standard
|
||||
output. Commented out <option>key</option> and
|
||||
output. Commented-out <option>key</option> and
|
||||
<option>controls</option> statements for
|
||||
<filename>named.conf</filename> are also printed.
|
||||
</para>
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: rndc.conf.html,v 1.5.2.1.4.16 2007/01/30 00:11:48 marka Exp $ -->
|
||||
<!-- $Id: rndc.conf.html,v 1.5.2.1.4.17 2007/05/09 03:32:36 marka Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
@@ -139,7 +139,7 @@
|
||||
<p>
|
||||
A complete <code class="filename">rndc.conf</code> file, including the
|
||||
randomly generated key, will be written to the standard
|
||||
output. Commented out <code class="option">key</code> and
|
||||
output. Commented-out <code class="option">key</code> and
|
||||
<code class="option">controls</code> statements for
|
||||
<code class="filename">named.conf</code> are also printed.
|
||||
</p>
|
||||
|
||||
+19
-16
@@ -5,7 +5,7 @@
|
||||
- Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
-
|
||||
- Permission to use, copy, modify, and distribute this software for any
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
@@ -18,7 +18,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: rndc.docbook,v 1.7.206.6 2007/01/29 23:57:18 marka Exp $ -->
|
||||
<!-- $Id: rndc.docbook,v 1.7.206.11 2007/12/14 20:56:36 marka Exp $ -->
|
||||
|
||||
<refentry>
|
||||
<refentryinfo>
|
||||
@@ -78,7 +78,7 @@
|
||||
<command>rndc</command> communicates with the name server
|
||||
over a TCP connection, sending commands authenticated with
|
||||
digital signatures. In the current versions of
|
||||
<command>rndc</command> and <command>named</command> named
|
||||
<command>rndc</command> and <command>named</command>,
|
||||
the only supported authentication algorithm is HMAC-MD5,
|
||||
which uses a shared secret on each end of the connection.
|
||||
This provides TSIG-style authentication for the command
|
||||
@@ -125,14 +125,13 @@
|
||||
<varlistentry>
|
||||
<term>-s <replaceable class="parameter">server</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
<replaceable class="parameter">server</replaceable> is
|
||||
the name or address of the server which matches a
|
||||
server statement in the configuration file for
|
||||
<command>rndc</command>. If no server is supplied on the
|
||||
command line, the host named by the default-server clause
|
||||
in the option statement of the configuration file will be
|
||||
used.
|
||||
<para><replaceable class="parameter">server</replaceable> is
|
||||
the name or address of the server which matches a
|
||||
server statement in the configuration file for
|
||||
<command>rndc</command>. If no server is supplied on the
|
||||
command line, the host named by the default-server clause
|
||||
in the options statement of the <command>rndc</command>
|
||||
configuration file will be used.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
@@ -158,15 +157,15 @@
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-y <replaceable class="parameter">keyid</replaceable></term>
|
||||
<term>-y <replaceable class="parameter">key_id</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Use the key <replaceable class="parameter">keyid</replaceable>
|
||||
Use the key <replaceable class="parameter">key_id</replaceable>
|
||||
from the configuration file.
|
||||
<replaceable class="parameter">keyid</replaceable> must be
|
||||
<replaceable class="parameter">key_id</replaceable> must be
|
||||
known by named with the same algorithm and secret string
|
||||
in order for control message validation to succeed.
|
||||
If no <replaceable class="parameter">keyid</replaceable>
|
||||
If no <replaceable class="parameter">key_id</replaceable>
|
||||
is specified, <command>rndc</command> will first look
|
||||
for a key clause in the server statement of the server
|
||||
being used, or if no server statement is present for that
|
||||
@@ -211,6 +210,10 @@
|
||||
<refentrytitle>rndc.conf</refentrytitle>
|
||||
<manvolnum>5</manvolnum>
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>rndc-confgen</refentrytitle>
|
||||
<manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>named</refentrytitle>
|
||||
<manvolnum>8</manvolnum>
|
||||
@@ -218,7 +221,7 @@
|
||||
<citerefentry>
|
||||
<refentrytitle>named.conf</refentrytitle>
|
||||
<manvolnum>5</manvolnum>
|
||||
</citerefentry>
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>ndc</refentrytitle>
|
||||
<manvolnum>8</manvolnum>
|
||||
|
||||
+18
-18
@@ -14,7 +14,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: rndc.html,v 1.7.2.1.4.15 2007/01/30 00:11:48 marka Exp $ -->
|
||||
<!-- $Id: rndc.html,v 1.7.2.1.4.19 2007/12/14 22:37:11 marka Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
@@ -46,7 +46,7 @@
|
||||
<span><strong class="command">rndc</strong></span> communicates with the name server
|
||||
over a TCP connection, sending commands authenticated with
|
||||
digital signatures. In the current versions of
|
||||
<span><strong class="command">rndc</strong></span> and <span><strong class="command">named</strong></span> named
|
||||
<span><strong class="command">rndc</strong></span> and <span><strong class="command">named</strong></span>,
|
||||
the only supported authentication algorithm is HMAC-MD5,
|
||||
which uses a shared secret on each end of the connection.
|
||||
This provides TSIG-style authentication for the command
|
||||
@@ -79,14 +79,13 @@
|
||||
does not exist.
|
||||
</p></dd>
|
||||
<dt><span class="term">-s <em class="replaceable"><code>server</code></em></span></dt>
|
||||
<dd><p>
|
||||
<em class="replaceable"><code>server</code></em> is
|
||||
the name or address of the server which matches a
|
||||
server statement in the configuration file for
|
||||
<span><strong class="command">rndc</strong></span>. If no server is supplied on the
|
||||
command line, the host named by the default-server clause
|
||||
in the option statement of the configuration file will be
|
||||
used.
|
||||
<dd><p><em class="replaceable"><code>server</code></em> is
|
||||
the name or address of the server which matches a
|
||||
server statement in the configuration file for
|
||||
<span><strong class="command">rndc</strong></span>. If no server is supplied on the
|
||||
command line, the host named by the default-server clause
|
||||
in the options statement of the <span><strong class="command">rndc</strong></span>
|
||||
configuration file will be used.
|
||||
</p></dd>
|
||||
<dt><span class="term">-p <em class="replaceable"><code>port</code></em></span></dt>
|
||||
<dd><p>
|
||||
@@ -98,14 +97,14 @@
|
||||
<dd><p>
|
||||
Enable verbose logging.
|
||||
</p></dd>
|
||||
<dt><span class="term">-y <em class="replaceable"><code>keyid</code></em></span></dt>
|
||||
<dt><span class="term">-y <em class="replaceable"><code>key_id</code></em></span></dt>
|
||||
<dd><p>
|
||||
Use the key <em class="replaceable"><code>keyid</code></em>
|
||||
Use the key <em class="replaceable"><code>key_id</code></em>
|
||||
from the configuration file.
|
||||
<em class="replaceable"><code>keyid</code></em> must be
|
||||
<em class="replaceable"><code>key_id</code></em> must be
|
||||
known by named with the same algorithm and secret string
|
||||
in order for control message validation to succeed.
|
||||
If no <em class="replaceable"><code>keyid</code></em>
|
||||
If no <em class="replaceable"><code>key_id</code></em>
|
||||
is specified, <span><strong class="command">rndc</strong></span> will first look
|
||||
for a key clause in the server statement of the server
|
||||
being used, or if no server statement is present for that
|
||||
@@ -123,7 +122,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543616"></a><h2>LIMITATIONS</h2>
|
||||
<a name="id2543619"></a><h2>LIMITATIONS</h2>
|
||||
<p>
|
||||
<span><strong class="command">rndc</strong></span> does not yet support all the commands of
|
||||
the BIND 8 <span><strong class="command">ndc</strong></span> utility.
|
||||
@@ -137,17 +136,18 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543644"></a><h2>SEE ALSO</h2>
|
||||
<a name="id2543648"></a><h2>SEE ALSO</h2>
|
||||
<p>
|
||||
<span class="citerefentry"><span class="refentrytitle">rndc.conf</span>(5)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">rndc-confgen</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">named.conf</span>(5)</span>
|
||||
<span class="citerefentry"><span class="refentrytitle">named.conf</span>(5)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">ndc</span>(8)</span>,
|
||||
<em class="citetitle">BIND 9 Administrator Reference Manual</em>.
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543697"></a><h2>AUTHOR</h2>
|
||||
<a name="id2543709"></a><h2>AUTHOR</h2>
|
||||
<p>
|
||||
<span class="corpauthor">Internet Systems Consortium</span>
|
||||
</p>
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2001, 2003 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and distribute this software for any
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
@@ -13,7 +13,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: Makefile.in,v 1.1.12.5 2007/01/18 00:06:04 marka Exp $
|
||||
# $Id: Makefile.in,v 1.1.12.6 2007/08/28 07:19:08 tbox Exp $
|
||||
|
||||
srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
|
||||
+2
-2
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2001, 2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: os.c,v 1.2.12.5 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: os.c,v 1.2.12.6 2007/08/28 07:19:08 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: byaddr_test.c,v 1.22.22.5 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: byaddr_test.c,v 1.22.22.6 2007/08/28 07:19:09 tbox Exp $ */
|
||||
|
||||
/*
|
||||
* Principal Author: Bob Halley
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2001-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: cfg_test.c,v 1.11.2.1.10.5 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: cfg_test.c,v 1.11.2.1.10.6 2007/08/28 07:19:09 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2006, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2001, 2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: compress_test.c,v 1.24.12.8 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: compress_test.c,v 1.24.12.10 2007/08/28 07:19:09 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -39,11 +39,6 @@ unsigned char plain[] = "\003yyy\003foo\0\003bar\003yyy\003foo\0\003"
|
||||
/*
|
||||
* Result concatenate (plain1, plain2, plain2, plain3).
|
||||
*/
|
||||
unsigned char bit1[] = "\101\010b";
|
||||
unsigned char bit2[] = "\101\014b\260";
|
||||
unsigned char bit3[] = "\101\020b\264";
|
||||
unsigned char bit[] = "\101\010b\0\101\014b\260\0\101\014b\260\0\101\020b\264";
|
||||
|
||||
int raw = 0;
|
||||
int verbose = 0;
|
||||
|
||||
@@ -90,25 +85,6 @@ main(int argc, char *argv[]) {
|
||||
sizeof(plain));
|
||||
test(DNS_COMPRESS_ALL, &name1, &name2, &name3, plain, sizeof(plain));
|
||||
|
||||
dns_name_init(&name1, NULL);
|
||||
region.base = bit1;
|
||||
region.length = sizeof(bit1);
|
||||
dns_name_fromregion(&name1, ®ion);
|
||||
|
||||
dns_name_init(&name2, NULL);
|
||||
region.base = bit2;
|
||||
region.length = sizeof(bit2);
|
||||
dns_name_fromregion(&name2, ®ion);
|
||||
|
||||
dns_name_init(&name3, NULL);
|
||||
region.base = bit3;
|
||||
region.length = sizeof(bit3);
|
||||
dns_name_fromregion(&name3, ®ion);
|
||||
|
||||
test(DNS_COMPRESS_NONE, &name1, &name2, &name3, bit, sizeof(bit));
|
||||
test(DNS_COMPRESS_GLOBAL14, &name1, &name2, &name3, bit, sizeof(bit));
|
||||
test(DNS_COMPRESS_ALL, &name1, &name2, &name3, bit, sizeof(bit));
|
||||
|
||||
return (0);
|
||||
}
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and distribute this software for any
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
@@ -13,7 +13,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: Makefile.in,v 1.21.12.9 2007/01/18 00:06:04 marka Exp $
|
||||
# $Id: Makefile.in,v 1.21.12.10 2007/08/28 07:19:09 tbox Exp $
|
||||
|
||||
srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
|
||||
+2
-2
@@ -2,7 +2,7 @@
|
||||
* Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2001, 2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: db_test.c,v 1.56.12.8 2007/01/18 00:06:04 marka Exp $ */
|
||||
/* $Id: db_test.c,v 1.56.12.9 2007/08/28 07:19:09 tbox Exp $ */
|
||||
|
||||
/*
|
||||
* Principal Author: Bob Halley
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user