Compare commits
No commits in common. "c8" and "c9-beta" have entirely different histories.
@ -1,2 +1 @@
|
|||||||
4b45d15edc1e3b7902129ce27baec58a50d76b5c SOURCES/bind-9.11.36.tar.gz
|
30cbd1f3e9d2d47d653498143334128aac1f8fc0 SOURCES/bind-9.16.23.tar.xz
|
||||||
a164fcad1d64d6b5fab5034928cb7260f1fa8fdd SOURCES/random.data
|
|
||||||
|
|||||||
3
.gitignore
vendored
3
.gitignore
vendored
@ -1,2 +1 @@
|
|||||||
SOURCES/bind-9.11.36.tar.gz
|
SOURCES/bind-9.16.23.tar.xz
|
||||||
SOURCES/random.data
|
|
||||||
|
|||||||
@ -1,79 +0,0 @@
|
|||||||
PGSQL BIND SDB driver
|
|
||||||
|
|
||||||
The postgresql BIND SDB driver is of experimental status and should not be
|
|
||||||
used for production systems.
|
|
||||||
|
|
||||||
Usage:
|
|
||||||
|
|
||||||
o Use the named_sdb process ( put ENABLE_SDB=yes in /etc/sysconfig/named )
|
|
||||||
|
|
||||||
o Edit your named.conf to contain a database zone, eg. :
|
|
||||||
|
|
||||||
zone "pgdb.net." IN {
|
|
||||||
type master;
|
|
||||||
database "pgsql bind pgdb localhost pguser pgpasswd";
|
|
||||||
# ^- DB name ^-Table ^-host ^-user ^-password
|
|
||||||
};
|
|
||||||
|
|
||||||
o Create the database zone table
|
|
||||||
The table must contain the columns "name", "rdtype", and "rdata", and
|
|
||||||
is expected to contain a properly constructed zone. The program "zonetodb"
|
|
||||||
creates such a table.
|
|
||||||
|
|
||||||
zonetodb usage:
|
|
||||||
|
|
||||||
zonetodb origin file dbname dbtable
|
|
||||||
|
|
||||||
where
|
|
||||||
origin : zone origin, eg "pgdb.net."
|
|
||||||
file : master zone database file, eg. pgdb.net.db
|
|
||||||
dbname : name of postgresql database
|
|
||||||
dbtable: name of table in database
|
|
||||||
|
|
||||||
Eg. to import this zone in the file 'pgdb.net.db' into the 'bind' database
|
|
||||||
'pgdb' table:
|
|
||||||
|
|
||||||
---
|
|
||||||
#pgdb.net.db:
|
|
||||||
$TTL 1H
|
|
||||||
@ SOA localhost. root.localhost. ( 1
|
|
||||||
3H
|
|
||||||
1H
|
|
||||||
1W
|
|
||||||
1H )
|
|
||||||
NS localhost.
|
|
||||||
host1 A 192.168.2.1
|
|
||||||
host2 A 192.168.2.2
|
|
||||||
host3 A 192.168.2.3
|
|
||||||
host4 A 192.168.2.4
|
|
||||||
host5 A 192.168.2.5
|
|
||||||
host6 A 192.168.2.6
|
|
||||||
host7 A 192.168.2.7
|
|
||||||
---
|
|
||||||
|
|
||||||
Issue this command as the pgsql user authorized to update the bind database:
|
|
||||||
|
|
||||||
# zonetodb pgdb.net. pgdb.net.db bind pgdb
|
|
||||||
|
|
||||||
will create / update the pgdb table in the 'bind' db:
|
|
||||||
|
|
||||||
$ psql -dbind -c 'select * from pgdb;'
|
|
||||||
name | ttl | rdtype | rdata
|
|
||||||
----------------+------+--------+-----------------------------------------------------
|
|
||||||
pgdb.net | 3600 | SOA | localhost. root.localhost. 1 10800 3600 604800 3600
|
|
||||||
pgdb.net | 3600 | NS | localhost.
|
|
||||||
host1.pgdb.net | 3600 | A | 192.168.2.1
|
|
||||||
host2.pgdb.net | 3600 | A | 192.168.2.2
|
|
||||||
host3.pgdb.net | 3600 | A | 192.168.2.3
|
|
||||||
host4.pgdb.net | 3600 | A | 192.168.2.4
|
|
||||||
host5.pgdb.net | 3600 | A | 192.168.2.5
|
|
||||||
host6.pgdb.net | 3600 | A | 192.168.2.6
|
|
||||||
host7.pgdb.net | 3600 | A | 192.168.2.7
|
|
||||||
(9 rows)
|
|
||||||
|
|
||||||
I've tested exactly the above configuration with bind-sdb-9.3.1+ and it works OK.
|
|
||||||
|
|
||||||
NOTE: If you use pgsqldb SDB, ensure the postgresql service is started before the named
|
|
||||||
service .
|
|
||||||
|
|
||||||
USE AT YOUR OWN RISK!
|
|
||||||
@ -1,68 +1,107 @@
|
|||||||
|
From 040227009453b3f0aa7914c7a6a94dc57ad5269b Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Thu, 21 Jan 2021 10:46:20 +0100
|
||||||
|
Subject: [PATCH] Enable custom pkcs11 native build
|
||||||
|
|
||||||
|
Share common parts like libisc, libcc and others. But provide native
|
||||||
|
pkcs11 libraries as a new copy of libdns and libns.
|
||||||
|
---
|
||||||
|
bin/Makefile.in | 2 +-
|
||||||
|
bin/confgen/Makefile.in | 2 +-
|
||||||
|
bin/dnssec-pkcs11/Makefile.in | 39 +++++++++++++++++---------------
|
||||||
|
bin/named-pkcs11/Makefile.in | 33 ++++++++++++++-------------
|
||||||
|
configure.ac | 19 ++++++++++++++++
|
||||||
|
lib/Makefile.in | 2 +-
|
||||||
|
lib/dns-pkcs11/Makefile.in | 22 +++++++++---------
|
||||||
|
lib/dns-pkcs11/tests/Makefile.in | 8 +++----
|
||||||
|
lib/ns-pkcs11/Makefile.in | 26 ++++++++++-----------
|
||||||
|
lib/ns-pkcs11/tests/Makefile.in | 12 +++++-----
|
||||||
|
make/includes.in | 7 ++++++
|
||||||
|
11 files changed, 101 insertions(+), 71 deletions(-)
|
||||||
|
|
||||||
diff --git a/bin/Makefile.in b/bin/Makefile.in
|
diff --git a/bin/Makefile.in b/bin/Makefile.in
|
||||||
index a18b222..26a7e4e 100644
|
index 9ad7f62..094775a 100644
|
||||||
--- a/bin/Makefile.in
|
--- a/bin/Makefile.in
|
||||||
+++ b/bin/Makefile.in
|
+++ b/bin/Makefile.in
|
||||||
@@ -11,8 +11,8 @@ srcdir = @srcdir@
|
@@ -11,7 +11,7 @@ srcdir = @srcdir@
|
||||||
VPATH = @srcdir@
|
VPATH = @srcdir@
|
||||||
top_srcdir = @top_srcdir@
|
top_srcdir = @top_srcdir@
|
||||||
|
|
||||||
-SUBDIRS = named rndc dig delv dnssec tools nsupdate check confgen \
|
-SUBDIRS = named rndc dig delv dnssec tools nsupdate check confgen \
|
||||||
- @NZD_TOOLS@ @PYTHON_TOOLS@ @PKCS11_TOOLS@ tests
|
+SUBDIRS = named named-pkcs11 rndc dig delv dnssec dnssec-pkcs11 tools nsupdate check confgen \
|
||||||
+SUBDIRS = named named-pkcs11 rndc dig delv dnssec dnssec-pkcs11 tools nsupdate \
|
@NZD_TOOLS@ @PYTHON_TOOLS@ @PKCS11_TOOLS@ plugins tests
|
||||||
+ check confgen @NZD_TOOLS@ @PYTHON_TOOLS@ @PKCS11_TOOLS@ tests
|
|
||||||
TARGETS =
|
TARGETS =
|
||||||
|
|
||||||
@BIND9_MAKE_RULES@
|
diff --git a/bin/confgen/Makefile.in b/bin/confgen/Makefile.in
|
||||||
|
index c126bf3..1b7512d 100644
|
||||||
|
--- a/bin/confgen/Makefile.in
|
||||||
|
+++ b/bin/confgen/Makefile.in
|
||||||
|
@@ -22,7 +22,7 @@ VERSION=@BIND9_VERSION@
|
||||||
|
CINCLUDES = -I${srcdir}/include ${ISC_INCLUDES} ${ISCCC_INCLUDES} \
|
||||||
|
${ISCCFG_INCLUDES} ${DNS_INCLUDES} ${BIND9_INCLUDES}
|
||||||
|
|
||||||
|
-CDEFINES = @USE_PKCS11@
|
||||||
|
+CDEFINES =
|
||||||
|
CWARNINGS =
|
||||||
|
|
||||||
|
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
diff --git a/bin/dnssec-pkcs11/Makefile.in b/bin/dnssec-pkcs11/Makefile.in
|
diff --git a/bin/dnssec-pkcs11/Makefile.in b/bin/dnssec-pkcs11/Makefile.in
|
||||||
index 390aa0c..e59a118 100644
|
index ace0e5a..e0f6a00 100644
|
||||||
--- a/bin/dnssec-pkcs11/Makefile.in
|
--- a/bin/dnssec-pkcs11/Makefile.in
|
||||||
+++ b/bin/dnssec-pkcs11/Makefile.in
|
+++ b/bin/dnssec-pkcs11/Makefile.in
|
||||||
@@ -15,18 +15,18 @@ VERSION=@BIND9_VERSION@
|
@@ -15,18 +15,18 @@ VERSION=@BIND9_VERSION@
|
||||||
|
|
||||||
@BIND9_MAKE_INCLUDES@
|
@BIND9_MAKE_INCLUDES@
|
||||||
|
|
||||||
-CINCLUDES = ${DNS_INCLUDES} ${ISC_INCLUDES} @DST_OPENSSL_INC@
|
-CINCLUDES = ${DNS_INCLUDES} ${ISC_INCLUDES} ${ISCCFG_INCLUDES} \
|
||||||
+CINCLUDES = ${DNS_PKCS11_INCLUDES} ${ISC_PKCS11_INCLUDES}
|
+CINCLUDES = ${DNS_PKCS11_INCLUDES} ${ISC_INCLUDES} ${ISCCFG_INCLUDES} \
|
||||||
|
${OPENSSL_CFLAGS}
|
||||||
|
|
||||||
-CDEFINES = -DVERSION=\"${VERSION}\" @USE_PKCS11@ @PKCS11_ENGINE@ \
|
-CDEFINES = -DVERSION=\"${VERSION}\" -DNAMED_CONFFILE=\"${sysconfdir}/named.conf\"
|
||||||
- @CRYPTO@ -DPK11_LIB_LOCATION=\"@PKCS11_PROVIDER@\"
|
+CDEFINES = -DVERSION=\"${VERSION}\" -DNAMED_CONFFILE=\"${sysconfdir}/named.conf\" -DUSE_PKCS11=1
|
||||||
+CDEFINES = -DVERSION=\"${VERSION}\" @PKCS11_ENGINE@ \
|
|
||||||
+ @CRYPTO_PK11@ -DPK11_LIB_LOCATION=\"@PKCS11_PROVIDER@\"
|
|
||||||
CWARNINGS =
|
CWARNINGS =
|
||||||
|
|
||||||
-DNSLIBS = ../../lib/dns/libdns.@A@ ${MAXMINDDB_LIBS} @DNS_CRYPTO_LIBS@
|
-DNSLIBS = ../../lib/dns/libdns.@A@ @NO_LIBTOOL_DNSLIBS@
|
||||||
-ISCLIBS = ../../lib/isc/libisc.@A@
|
+DNSLIBS = ../../lib/dns-pkcs11/libdns-pkcs11.@A@ @NO_LIBTOOL_DNSLIBS@
|
||||||
-ISCNOSYMLIBS = ../../lib/isc/libisc-nosymtbl.@A@
|
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
+DNSLIBS = ../../lib/dns-pkcs11/libdns-pkcs11.@A@ ${MAXMINDDB_LIBS} @DNS_CRYPTO_LIBS@
|
ISCLIBS = ../../lib/isc/libisc.@A@ @NO_LIBTOOL_ISCLIBS@
|
||||||
+ISCLIBS = ../../lib/isc-pkcs11/libisc-pkcs11.@A@
|
ISCNOSYMLIBS = ../../lib/isc/libisc-nosymtbl.@A@ @NO_LIBTOOL_ISCLIBS@
|
||||||
+ISCNOSYMLIBS = ../../lib/isc-pkcs11/libisc-pkcs11-nosymtbl.@A@
|
|
||||||
|
|
||||||
-DNSDEPLIBS = ../../lib/dns/libdns.@A@
|
-DNSDEPLIBS = ../../lib/dns/libdns.@A@
|
||||||
-ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
|
||||||
+DNSDEPLIBS = ../../lib/dns-pkcs11/libdns-pkcs11.@A@
|
+DNSDEPLIBS = ../../lib/dns-pkcs11/libdns-pkcs11.@A@
|
||||||
+ISCDEPLIBS = ../../lib/isc-pkcs11/libisc-pkcs11.@A@
|
ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
||||||
|
ISCCFGDEPLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
|
|
||||||
DEPLIBS = ${DNSDEPLIBS} ${ISCDEPLIBS}
|
@@ -36,12 +36,15 @@ LIBS = ${DNSLIBS} ${ISCCFGLIBS} ${ISCLIBS} @LIBS@
|
||||||
|
|
||||||
@@ -35,10 +35,10 @@ LIBS = ${DNSLIBS} ${ISCLIBS} @LIBS@
|
NOSYMLIBS = ${DNSLIBS} ${ISCCFGLIBS} ${ISCNOSYMLIBS} @LIBS@
|
||||||
NOSYMLIBS = ${DNSLIBS} ${ISCNOSYMLIBS} @LIBS@
|
|
||||||
|
|
||||||
|
+# Add suffix to all targets
|
||||||
|
+EXEEXT = -pkcs11@EXEEXT@
|
||||||
|
+
|
||||||
# Alphabetically
|
# Alphabetically
|
||||||
-TARGETS = dnssec-keygen@EXEEXT@ dnssec-signzone@EXEEXT@ \
|
-TARGETS = dnssec-cds@EXEEXT@ dnssec-dsfromkey@EXEEXT@ \
|
||||||
- dnssec-keyfromlabel@EXEEXT@ dnssec-dsfromkey@EXEEXT@ \
|
- dnssec-importkey@EXEEXT@ dnssec-keyfromlabel@EXEEXT@ \
|
||||||
- dnssec-revoke@EXEEXT@ dnssec-settime@EXEEXT@ \
|
- dnssec-keygen@EXEEXT@ dnssec-revoke@EXEEXT@ \
|
||||||
- dnssec-verify@EXEEXT@ dnssec-importkey@EXEEXT@
|
- dnssec-settime@EXEEXT@ dnssec-signzone@EXEEXT@ \
|
||||||
+TARGETS = dnssec-keygen-pkcs11@EXEEXT@ dnssec-signzone-pkcs11@EXEEXT@ \
|
- dnssec-verify@EXEEXT@
|
||||||
+ dnssec-keyfromlabel-pkcs11@EXEEXT@ dnssec-dsfromkey-pkcs11@EXEEXT@ \
|
+TARGETS = dnssec-cds${EXEEXT} dnssec-dsfromkey${EXEEXT} \
|
||||||
+ dnssec-revoke-pkcs11@EXEEXT@ dnssec-settime-pkcs11@EXEEXT@ \
|
+ dnssec-importkey${EXEEXT} dnssec-keyfromlabel${EXEEXT} \
|
||||||
+ dnssec-verify-pkcs11@EXEEXT@ dnssec-importkey-pkcs11@EXEEXT@
|
+ dnssec-keygen${EXEEXT} dnssec-revoke${EXEEXT} \
|
||||||
|
+ dnssec-settime${EXEEXT} dnssec-signzone${EXEEXT} \
|
||||||
|
+ dnssec-verify${EXEEXT}
|
||||||
|
|
||||||
OBJS = dnssectool.@O@
|
OBJS = dnssectool.@O@
|
||||||
|
|
||||||
@@ -59,15 +59,15 @@ MANOBJS = ${MANPAGES} ${HTMLPAGES}
|
@@ -52,19 +55,19 @@ SRCS = dnssec-cds.c dnssec-dsfromkey.c dnssec-importkey.c \
|
||||||
|
|
||||||
@BIND9_MAKE_RULES@
|
@BIND9_MAKE_RULES@
|
||||||
|
|
||||||
|
-dnssec-cds@EXEEXT@: dnssec-cds.@O@ ${OBJS} ${DEPLIBS}
|
||||||
|
+dnssec-cds-pkcs11@EXEEXT@: dnssec-cds.@O@ ${OBJS} ${DEPLIBS}
|
||||||
|
export BASEOBJS="dnssec-cds.@O@ ${OBJS}"; \
|
||||||
|
${FINALBUILDCMD}
|
||||||
|
|
||||||
-dnssec-dsfromkey@EXEEXT@: dnssec-dsfromkey.@O@ ${OBJS} ${DEPLIBS}
|
-dnssec-dsfromkey@EXEEXT@: dnssec-dsfromkey.@O@ ${OBJS} ${DEPLIBS}
|
||||||
+dnssec-dsfromkey-pkcs11@EXEEXT@: dnssec-dsfromkey.@O@ ${OBJS} ${DEPLIBS}
|
+dnssec-dsfromkey-pkcs11@EXEEXT@: dnssec-dsfromkey.@O@ ${OBJS} ${DEPLIBS}
|
||||||
export BASEOBJS="dnssec-dsfromkey.@O@ ${OBJS}"; \
|
export BASEOBJS="dnssec-dsfromkey.@O@ ${OBJS}"; \
|
||||||
@ -78,7 +117,7 @@ index 390aa0c..e59a118 100644
|
|||||||
export BASEOBJS="dnssec-keygen.@O@ ${OBJS}"; \
|
export BASEOBJS="dnssec-keygen.@O@ ${OBJS}"; \
|
||||||
${FINALBUILDCMD}
|
${FINALBUILDCMD}
|
||||||
|
|
||||||
@@ -75,7 +75,7 @@ dnssec-signzone.@O@: dnssec-signzone.c
|
@@ -72,7 +75,7 @@ dnssec-signzone.@O@: dnssec-signzone.c
|
||||||
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} -DVERSION=\"${VERSION}\" \
|
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} -DVERSION=\"${VERSION}\" \
|
||||||
-c ${srcdir}/dnssec-signzone.c
|
-c ${srcdir}/dnssec-signzone.c
|
||||||
|
|
||||||
@ -87,7 +126,7 @@ index 390aa0c..e59a118 100644
|
|||||||
export BASEOBJS="dnssec-signzone.@O@ ${OBJS}"; \
|
export BASEOBJS="dnssec-signzone.@O@ ${OBJS}"; \
|
||||||
${FINALBUILDCMD}
|
${FINALBUILDCMD}
|
||||||
|
|
||||||
@@ -83,19 +83,19 @@ dnssec-verify.@O@: dnssec-verify.c
|
@@ -80,19 +83,19 @@ dnssec-verify.@O@: dnssec-verify.c
|
||||||
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} -DVERSION=\"${VERSION}\" \
|
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} -DVERSION=\"${VERSION}\" \
|
||||||
-c ${srcdir}/dnssec-verify.c
|
-c ${srcdir}/dnssec-verify.c
|
||||||
|
|
||||||
@ -111,117 +150,70 @@ index 390aa0c..e59a118 100644
|
|||||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||||
dnssec-importkey.@O@ ${OBJS} ${LIBS}
|
dnssec-importkey.@O@ ${OBJS} ${LIBS}
|
||||||
|
|
||||||
@@ -106,16 +106,14 @@ docclean manclean maintainer-clean::
|
|
||||||
|
|
||||||
installdirs:
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
|
||||||
- $(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
|
||||||
|
|
||||||
install-man8: ${MANPAGES}
|
|
||||||
${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man8
|
|
||||||
|
|
||||||
-install:: ${TARGETS} installdirs install-man8
|
|
||||||
+install:: ${TARGETS} installdirs
|
|
||||||
for t in ${TARGETS}; do ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} $$t ${DESTDIR}${sbindir} || exit 1; done
|
|
||||||
|
|
||||||
uninstall::
|
|
||||||
- for m in ${MANPAGES}; do rm -f ${DESTDIR}${mandir}/man8/$$m || exit 1; done
|
|
||||||
for t in ${TARGETS}; do ${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${sbindir}/$$t || exit 1; done
|
|
||||||
|
|
||||||
clean distclean::
|
|
||||||
diff --git a/bin/dnssec/Makefile.in b/bin/dnssec/Makefile.in
|
|
||||||
index 390aa0c..851a008 100644
|
|
||||||
--- a/bin/dnssec/Makefile.in
|
|
||||||
+++ b/bin/dnssec/Makefile.in
|
|
||||||
@@ -17,7 +17,7 @@ VERSION=@BIND9_VERSION@
|
|
||||||
|
|
||||||
CINCLUDES = ${DNS_INCLUDES} ${ISC_INCLUDES} @DST_OPENSSL_INC@
|
|
||||||
|
|
||||||
-CDEFINES = -DVERSION=\"${VERSION}\" @USE_PKCS11@ @PKCS11_ENGINE@ \
|
|
||||||
+CDEFINES = -DVERSION=\"${VERSION}\" \
|
|
||||||
@CRYPTO@ -DPK11_LIB_LOCATION=\"@PKCS11_PROVIDER@\"
|
|
||||||
CWARNINGS =
|
|
||||||
|
|
||||||
diff --git a/bin/named-pkcs11/Makefile.in b/bin/named-pkcs11/Makefile.in
|
diff --git a/bin/named-pkcs11/Makefile.in b/bin/named-pkcs11/Makefile.in
|
||||||
index 277a0f5..52a6375 100644
|
index 98125dd..518a75f 100644
|
||||||
--- a/bin/named-pkcs11/Makefile.in
|
--- a/bin/named-pkcs11/Makefile.in
|
||||||
+++ b/bin/named-pkcs11/Makefile.in
|
+++ b/bin/named-pkcs11/Makefile.in
|
||||||
@@ -43,27 +43,27 @@ DLZDRIVER_INCLUDES = @DLZ_DRIVER_INCLUDES@
|
@@ -37,13 +37,14 @@ DBDRIVER_LIBS =
|
||||||
DLZDRIVER_LIBS = @DLZ_DRIVER_LIBS@
|
|
||||||
|
DLZ_DRIVER_DIR = ${top_srcdir}/contrib/dlz/drivers
|
||||||
|
|
||||||
|
-DLZDRIVER_OBJS = @DLZ_DRIVER_OBJS@
|
||||||
|
-DLZDRIVER_SRCS = @DLZ_DRIVER_SRCS@
|
||||||
|
-DLZDRIVER_INCLUDES = @DLZ_DRIVER_INCLUDES@
|
||||||
|
-DLZDRIVER_LIBS = @DLZ_DRIVER_LIBS@
|
||||||
|
+# Skip building on PKCS11 variant
|
||||||
|
+DLZDRIVER_OBJS =
|
||||||
|
+DLZDRIVER_SRCS =
|
||||||
|
+DLZDRIVER_INCLUDES =
|
||||||
|
+DLZDRIVER_LIBS =
|
||||||
|
|
||||||
CINCLUDES = -I${srcdir}/include -I${srcdir}/unix/include -I. \
|
CINCLUDES = -I${srcdir}/include -I${srcdir}/unix/include -I. \
|
||||||
- ${LWRES_INCLUDES} ${DNS_INCLUDES} ${BIND9_INCLUDES} \
|
- ${NS_INCLUDES} ${DNS_INCLUDES} \
|
||||||
- ${ISCCFG_INCLUDES} ${ISCCC_INCLUDES} ${ISC_INCLUDES} \
|
+ ${NS_PKCS11_INCLUDES} ${DNS_PKCS11_INCLUDES} \
|
||||||
+ ${LWRES_INCLUDES} ${DNS_PKCS11_INCLUDES} ${BIND9_INCLUDES} \
|
${BIND9_INCLUDES} ${ISCCFG_INCLUDES} ${ISCCC_INCLUDES} \
|
||||||
+ ${ISCCFG_INCLUDES} ${ISCCC_INCLUDES} ${ISC_PKCS11_INCLUDES} \
|
${ISC_INCLUDES} ${DLZDRIVER_INCLUDES} \
|
||||||
${DLZDRIVER_INCLUDES} ${DBDRIVER_INCLUDES} ${MAXMINDDB_CFLAGS} \
|
${DBDRIVER_INCLUDES} \
|
||||||
@DST_OPENSSL_INC@
|
@@ -56,24 +57,24 @@ CINCLUDES = -I${srcdir}/include -I${srcdir}/unix/include -I. \
|
||||||
|
${LIBXML2_CFLAGS} \
|
||||||
|
${MAXMINDDB_CFLAGS}
|
||||||
|
|
||||||
-CDEFINES = @CONTRIB_DLZ@ @USE_PKCS11@ @PKCS11_ENGINE@ @CRYPTO@
|
-CDEFINES = @CONTRIB_DLZ@
|
||||||
+CDEFINES = @USE_PKCS11@ @PKCS11_ENGINE@ @CRYPTO_PK11@ @USE_GSSAPI@
|
+CDEFINES =
|
||||||
|
|
||||||
CWARNINGS =
|
CWARNINGS =
|
||||||
|
|
||||||
-DNSLIBS = ../../lib/dns/libdns.@A@ ${MAXMINDDB_LIBS} @DNS_CRYPTO_LIBS@
|
-DNSLIBS = ../../lib/dns/libdns.@A@ @NO_LIBTOOL_DNSLIBS@
|
||||||
+DNSLIBS = ../../lib/dns-pkcs11/libdns-pkcs11.@A@ ${MAXMINDDB_LIBS} @DNS_CRYPTO_LIBS@
|
+DNSLIBS = ../../lib/dns-pkcs11/libdns-pkcs11.@A@ @NO_LIBTOOL_DNSLIBS@
|
||||||
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
ISCCCLIBS = ../../lib/isccc/libisccc.@A@
|
ISCCCLIBS = ../../lib/isccc/libisccc.@A@
|
||||||
-ISCLIBS = ../../lib/isc/libisc.@A@
|
ISCLIBS = ../../lib/isc/libisc.@A@ @NO_LIBTOOL_ISCLIBS@
|
||||||
-ISCNOSYMLIBS = ../../lib/isc/libisc-nosymtbl.@A@
|
ISCNOSYMLIBS = ../../lib/isc/libisc-nosymtbl.@A@ @NO_LIBTOOL_ISCLIBS@
|
||||||
+ISCLIBS = ../../lib/isc-pkcs11/libisc-pkcs11.@A@
|
|
||||||
+ISCNOSYMLIBS = ../../lib/isc-pkcs11/libisc-pkcs11-nosymtbl.@A@
|
|
||||||
LWRESLIBS = ../../lib/lwres/liblwres.@A@
|
|
||||||
BIND9LIBS = ../../lib/bind9/libbind9.@A@
|
BIND9LIBS = ../../lib/bind9/libbind9.@A@
|
||||||
|
-NSLIBS = ../../lib/ns/libns.@A@
|
||||||
|
+NSLIBS = ../../lib/ns-pkcs11/libns-pkcs11.@A@
|
||||||
|
|
||||||
-DNSDEPLIBS = ../../lib/dns/libdns.@A@
|
-DNSDEPLIBS = ../../lib/dns/libdns.@A@
|
||||||
+DNSDEPLIBS = ../../lib/dns-pkcs11/libdns-pkcs11.@A@
|
+DNSDEPLIBS = ../../lib/dns-pkcs11/libdns-pkcs11.@A@
|
||||||
ISCCFGDEPLIBS = ../../lib/isccfg/libisccfg.@A@
|
ISCCFGDEPLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
ISCCCDEPLIBS = ../../lib/isccc/libisccc.@A@
|
ISCCCDEPLIBS = ../../lib/isccc/libisccc.@A@
|
||||||
-ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
||||||
+ISCDEPLIBS = ../../lib/isc-pkcs11/libisc-pkcs11.@A@
|
|
||||||
LWRESDEPLIBS = ../../lib/lwres/liblwres.@A@
|
|
||||||
BIND9DEPLIBS = ../../lib/bind9/libbind9.@A@
|
BIND9DEPLIBS = ../../lib/bind9/libbind9.@A@
|
||||||
|
-NSDEPLIBS = ../../lib/ns/libns.@A@
|
||||||
|
+NSDEPLIBS = ../../lib/ns-pkcs11/libns-pkcs11.@A@
|
||||||
|
|
||||||
@@ -72,15 +72,15 @@ DEPLIBS = ${LWRESDEPLIBS} ${DNSDEPLIBS} ${BIND9DEPLIBS} \
|
DEPLIBS = ${NSDEPLIBS} ${DNSDEPLIBS} ${BIND9DEPLIBS} \
|
||||||
|
${ISCCFGDEPLIBS} ${ISCCCDEPLIBS} ${ISCDEPLIBS}
|
||||||
LIBS = ${LWRESLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
@@ -93,7 +94,7 @@ NOSYMLIBS = ${NSLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
||||||
${ISCCFGLIBS} ${ISCCCLIBS} ${ISCLIBS} \
|
|
||||||
- ${DLZDRIVER_LIBS} ${DBDRIVER_LIBS} @LIBS@
|
|
||||||
+ @LIBS@
|
|
||||||
|
|
||||||
NOSYMLIBS = ${LWRESLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
|
||||||
${ISCCFGLIBS} ${ISCCCLIBS} ${ISCNOSYMLIBS} \
|
|
||||||
- ${DLZDRIVER_LIBS} ${DBDRIVER_LIBS} @LIBS@
|
|
||||||
+ @LIBS@
|
|
||||||
|
|
||||||
SUBDIRS = unix
|
SUBDIRS = unix
|
||||||
|
|
||||||
-TARGETS = named@EXEEXT@ lwresd@EXEEXT@
|
-TARGETS = named@EXEEXT@ feature-test@EXEEXT@
|
||||||
+TARGETS = named-pkcs11@EXEEXT@
|
+TARGETS = named-pkcs11@EXEEXT@ feature-test-pkcs11@EXEEXT@
|
||||||
|
|
||||||
GEOIPLINKOBJS = geoip.@O@
|
|
||||||
GEOIP2LINKOBJS = geoip.@O@
|
GEOIP2LINKOBJS = geoip.@O@
|
||||||
@@ -94,8 +94,7 @@ OBJS = builtin.@O@ client.@O@ config.@O@ control.@O@ \
|
|
||||||
tkeyconf.@O@ tsigconf.@O@ update.@O@ xfrout.@O@ \
|
|
||||||
zoneconf.@O@ \
|
|
||||||
lwaddr.@O@ lwresd.@O@ lwdclient.@O@ lwderror.@O@ lwdgabn.@O@ \
|
|
||||||
- lwdgnba.@O@ lwdgrbn.@O@ lwdnoop.@O@ lwsearch.@O@ \
|
|
||||||
- ${DLZDRIVER_OBJS} ${DBDRIVER_OBJS}
|
|
||||||
+ lwdgnba.@O@ lwdgrbn.@O@ lwdnoop.@O@ lwsearch.@O@
|
|
||||||
|
|
||||||
UOBJS = unix/os.@O@ unix/dlz_dlopen_driver.@O@
|
@@ -151,7 +152,7 @@ server.@O@: server.c
|
||||||
|
|
||||||
@@ -113,8 +112,7 @@ SRCS = builtin.c client.c config.c control.c \
|
|
||||||
tkeyconf.c tsigconf.c update.c xfrout.c \
|
|
||||||
zoneconf.c \
|
|
||||||
lwaddr.c lwresd.c lwdclient.c lwderror.c lwdgabn.c \
|
|
||||||
- lwdgnba.c lwdgrbn.c lwdnoop.c lwsearch.c \
|
|
||||||
- ${DLZDRIVER_SRCS} ${DBDRIVER_SRCS}
|
|
||||||
+ lwdgnba.c lwdgrbn.c lwdnoop.c lwsearch.c
|
|
||||||
|
|
||||||
MANPAGES = named.8 lwresd.8 named.conf.5
|
|
||||||
|
|
||||||
@@ -154,14 +152,14 @@ server.@O@: server.c
|
|
||||||
-DPRODUCT=\"${PRODUCT}\" \
|
-DPRODUCT=\"${PRODUCT}\" \
|
||||||
-DVERSION=\"${VERSION}\" -c ${srcdir}/server.c
|
-DVERSION=\"${VERSION}\" -c ${srcdir}/server.c
|
||||||
|
|
||||||
@ -230,77 +222,38 @@ index 277a0f5..52a6375 100644
|
|||||||
export MAKE_SYMTABLE="yes"; \
|
export MAKE_SYMTABLE="yes"; \
|
||||||
export BASEOBJS="${OBJS} ${UOBJS}"; \
|
export BASEOBJS="${OBJS} ${UOBJS}"; \
|
||||||
${FINALBUILDCMD}
|
${FINALBUILDCMD}
|
||||||
|
@@ -161,7 +162,7 @@ feature-test.@O@: ${top_srcdir}/bin/tests/system/feature-test.c
|
||||||
|
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} \
|
||||||
|
-c ${top_srcdir}/bin/tests/system/feature-test.c
|
||||||
|
|
||||||
-lwresd@EXEEXT@: named@EXEEXT@
|
-feature-test@EXEEXT@: feature-test.@O@
|
||||||
+lwresd@EXEEXT@: named-pkcs11@EXEEXT@
|
+feature-test-pkcs11@EXEEXT@: feature-test.@O@
|
||||||
rm -f lwresd@EXEEXT@
|
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} \
|
||||||
- @LN@ named@EXEEXT@ lwresd@EXEEXT@
|
-o $@ feature-test.@O@ ${ISCLIBS} ${LIBS}
|
||||||
+ @LN@ named-pkcs11@EXEEXT@ lwresd@EXEEXT@
|
|
||||||
|
|
||||||
doc man:: ${MANOBJS}
|
@@ -180,11 +181,11 @@ statschannel.@O@: bind9.xsl.h
|
||||||
|
installdirs:
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
||||||
|
|
||||||
@@ -192,16 +190,11 @@ install-man8: named.8 lwresd.8
|
-install:: named@EXEEXT@ installdirs
|
||||||
|
|
||||||
install-man: install-man5 install-man8
|
|
||||||
|
|
||||||
-install:: named@EXEEXT@ lwresd@EXEEXT@ installdirs install-man
|
|
||||||
- ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named@EXEEXT@ ${DESTDIR}${sbindir}
|
- ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
- (cd ${DESTDIR}${sbindir}; rm -f lwresd@EXEEXT@; @LN@ named@EXEEXT@ lwresd@EXEEXT@)
|
|
||||||
+install:: named-pkcs11@EXEEXT@ installdirs
|
+install:: named-pkcs11@EXEEXT@ installdirs
|
||||||
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named-pkcs11@EXEEXT@ ${DESTDIR}${sbindir}
|
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named-pkcs11@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
|
||||||
uninstall::
|
uninstall::
|
||||||
- rm -f ${DESTDIR}${mandir}/man5/named.conf.5
|
|
||||||
- rm -f ${DESTDIR}${mandir}/man8/lwresd.8
|
|
||||||
- rm -f ${DESTDIR}${mandir}/man8/named.8
|
|
||||||
- rm -f ${DESTDIR}${sbindir}/lwresd@EXEEXT@
|
|
||||||
- ${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${sbindir}/named@EXEEXT@
|
- ${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${sbindir}/named@EXEEXT@
|
||||||
+ ${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${sbindir}/named-pkcs11@EXEEXT@
|
+ ${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${sbindir}/named-pkcs11@EXEEXT@
|
||||||
|
|
||||||
@DLZ_DRIVER_RULES@
|
@DLZ_DRIVER_RULES@
|
||||||
|
|
||||||
diff --git a/bin/named/Makefile.in b/bin/named/Makefile.in
|
|
||||||
index 277a0f5..0e00885 100644
|
|
||||||
--- a/bin/named/Makefile.in
|
|
||||||
+++ b/bin/named/Makefile.in
|
|
||||||
@@ -48,7 +48,7 @@ CINCLUDES = -I${srcdir}/include -I${srcdir}/unix/include -I. \
|
|
||||||
${DLZDRIVER_INCLUDES} ${DBDRIVER_INCLUDES} ${MAXMINDDB_CFLAGS} \
|
|
||||||
@DST_OPENSSL_INC@
|
|
||||||
|
|
||||||
-CDEFINES = @CONTRIB_DLZ@ @USE_PKCS11@ @PKCS11_ENGINE@ @CRYPTO@
|
|
||||||
+CDEFINES = @CONTRIB_DLZ@ @USE_GSSAPI@ @CRYPTO@
|
|
||||||
|
|
||||||
CWARNINGS =
|
|
||||||
|
|
||||||
diff --git a/bin/pkcs11/Makefile.in b/bin/pkcs11/Makefile.in
|
|
||||||
index 2c19e7e..8223d5e 100644
|
|
||||||
--- a/bin/pkcs11/Makefile.in
|
|
||||||
+++ b/bin/pkcs11/Makefile.in
|
|
||||||
@@ -13,13 +13,13 @@ top_srcdir = @top_srcdir@
|
|
||||||
|
|
||||||
@BIND9_MAKE_INCLUDES@
|
|
||||||
|
|
||||||
-CINCLUDES = ${ISC_INCLUDES}
|
|
||||||
+CINCLUDES = ${ISC_PKCS11_INCLUDES}
|
|
||||||
|
|
||||||
CDEFINES =
|
|
||||||
|
|
||||||
-ISCLIBS = ../../lib/isc/libisc.@A@ @ISC_OPENSSL_LIBS@
|
|
||||||
+ISCLIBS = ../../lib/isc-pkcs11/libisc-pkcs11.@A@ @ISC_OPENSSL_LIBS@
|
|
||||||
|
|
||||||
-ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
|
||||||
+ISCDEPLIBS = ../../lib/isc-pkcs11/libisc-pkcs11.@A@
|
|
||||||
|
|
||||||
DEPLIBS = ${ISCDEPLIBS}
|
|
||||||
|
|
||||||
diff --git a/configure.ac b/configure.ac
|
diff --git a/configure.ac b/configure.ac
|
||||||
index 83cad4a..e1e1a32 100644
|
index 032228b..64e3da0 100644
|
||||||
--- a/configure.ac
|
--- a/configure.ac
|
||||||
+++ b/configure.ac
|
+++ b/configure.ac
|
||||||
@@ -1178,12 +1178,14 @@ AC_SUBST(USE_GSSAPI)
|
@@ -1251,12 +1251,14 @@ AC_SUBST(USE_GSSAPI)
|
||||||
AC_SUBST(DST_GSSAPI_INC)
|
AC_SUBST(DST_GSSAPI_INC)
|
||||||
AC_SUBST(DNS_GSSAPI_LIBS)
|
AC_SUBST(DNS_GSSAPI_LIBS)
|
||||||
DNS_CRYPTO_LIBS="$DNS_GSSAPI_LIBS $DNS_CRYPTO_LIBS"
|
DNS_CRYPTO_LIBS="$DNS_GSSAPI_LIBS"
|
||||||
+DNS_CRYPTO_PK11_LIBS="$DNS_GSSAPI_LIBS $DNS_CRYPTO_PK11_LIBS"
|
+DNS_CRYPTO_PK11_LIBS="$DNS_GSSAPI_LIBS $DNS_CRYPTO_PK11_LIBS"
|
||||||
|
|
||||||
#
|
#
|
||||||
@ -311,98 +264,47 @@ index 83cad4a..e1e1a32 100644
|
|||||||
+AC_SUBST(DNS_CRYPTO_PK11_LIBS)
|
+AC_SUBST(DNS_CRYPTO_PK11_LIBS)
|
||||||
|
|
||||||
#
|
#
|
||||||
# was --with-randomdev specified?
|
# was --with-lmdb specified?
|
||||||
@@ -1556,12 +1558,12 @@ AC_ARG_ENABLE(openssl-hash,
|
@@ -2327,6 +2329,8 @@ AC_SUBST(BIND9_DNS_BUILDINCLUDE)
|
||||||
AC_MSG_CHECKING(for OpenSSL library)
|
AC_SUBST(BIND9_NS_BUILDINCLUDE)
|
||||||
OPENSSL_WARNING=
|
AC_SUBST(BIND9_BIND9_BUILDINCLUDE)
|
||||||
openssldirs="/usr /usr/local /usr/local/ssl /opt/local /usr/pkg /usr/sfw"
|
AC_SUBST(BIND9_IRS_BUILDINCLUDE)
|
||||||
-if test "yes" = "$want_native_pkcs11"
|
+AC_SUBST(BIND9_DNS_PKCS11_BUILDINCLUDE)
|
||||||
-then
|
+AC_SUBST(BIND9_NS_PKCS11_BUILDINCLUDE)
|
||||||
- use_openssl="native_pkcs11"
|
if test "X$srcdir" != "X"; then
|
||||||
- want_openssl_hash="no"
|
BIND9_ISC_BUILDINCLUDE="-I${BIND9_TOP_BUILDDIR}/lib/isc/include"
|
||||||
- AC_MSG_RESULT(use of native PKCS11 instead)
|
BIND9_ISCCC_BUILDINCLUDE="-I${BIND9_TOP_BUILDDIR}/lib/isccc/include"
|
||||||
-fi
|
@@ -2335,6 +2339,8 @@ if test "X$srcdir" != "X"; then
|
||||||
+#if test "yes" = "$want_native_pkcs11"
|
BIND9_NS_BUILDINCLUDE="-I${BIND9_TOP_BUILDDIR}/lib/ns/include"
|
||||||
+#then
|
BIND9_BIND9_BUILDINCLUDE="-I${BIND9_TOP_BUILDDIR}/lib/bind9/include"
|
||||||
+# use_openssl="native_pkcs11"
|
BIND9_IRS_BUILDINCLUDE="-I${BIND9_TOP_BUILDDIR}/lib/irs/include"
|
||||||
+# want_openssl_hash="no"
|
+ BIND9_DNS_PKCS11_BUILDINCLUDE="-I${BIND9_TOP_BUILDDIR}/lib/dns-pkcs11/include"
|
||||||
+# AC_MSG_RESULT(use of native PKCS11 instead)
|
+ BIND9_NS_PKCS11_BUILDINCLUDE="-I${BIND9_TOP_BUILDDIR}/lib/ns-pkcs11/include"
|
||||||
+#fi
|
else
|
||||||
|
BIND9_ISC_BUILDINCLUDE=""
|
||||||
if test "auto" = "$use_openssl"
|
BIND9_ISCCC_BUILDINCLUDE=""
|
||||||
then
|
@@ -2343,6 +2349,8 @@ else
|
||||||
@@ -1574,6 +1576,7 @@ then
|
BIND9_NS_BUILDINCLUDE=""
|
||||||
fi
|
BIND9_BIND9_BUILDINCLUDE=""
|
||||||
done
|
BIND9_IRS_BUILDINCLUDE=""
|
||||||
|
+ BIND9_DNS_PKCS11_BUILDINCLUDE=""
|
||||||
|
+ BIND9_NS_PKCS11_BUILDINCLUDE=""
|
||||||
fi
|
fi
|
||||||
+CRYPTO_PK11=""
|
|
||||||
OPENSSL_ECDSA=""
|
|
||||||
OPENSSL_GOST=""
|
|
||||||
OPENSSL_ED25519=""
|
|
||||||
@@ -1595,11 +1598,10 @@ case "$with_gost" in
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
|
|
||||||
-case "$use_openssl" in
|
AC_SUBST_FILE(BIND9_MAKE_INCLUDES)
|
||||||
- native_pkcs11)
|
@@ -2798,8 +2806,11 @@ AC_CONFIG_FILES([
|
||||||
- AC_MSG_RESULT(disabled because of native PKCS11)
|
|
||||||
+if test "$want_native_pkcs11" = "yes"
|
|
||||||
+then
|
|
||||||
DST_OPENSSL_INC=""
|
|
||||||
- CRYPTO="-DPKCS11CRYPTO"
|
|
||||||
+ CRYPTO_PK11="-DPKCS11CRYPTO"
|
|
||||||
CRYPTOLIB="pkcs11"
|
|
||||||
OPENSSLECDSALINKOBJS=""
|
|
||||||
OPENSSLECDSALINKSRCS=""
|
|
||||||
@@ -1609,7 +1611,9 @@ case "$use_openssl" in
|
|
||||||
OPENSSLGOSTLINKSRCS=""
|
|
||||||
OPENSSLLINKOBJS=""
|
|
||||||
OPENSSLLINKSRCS=""
|
|
||||||
- ;;
|
|
||||||
+fi
|
|
||||||
+
|
|
||||||
+case "$use_openssl" in
|
|
||||||
no)
|
|
||||||
AC_MSG_RESULT(no)
|
|
||||||
DST_OPENSSL_INC=""
|
|
||||||
@@ -1641,7 +1645,7 @@ case "$use_openssl" in
|
|
||||||
If you do not want OpenSSL, use --without-openssl])
|
|
||||||
;;
|
|
||||||
*)
|
|
||||||
- if test "yes" = "$want_native_pkcs11"
|
|
||||||
+ if false # test "yes" = "$want_native_pkcs11"
|
|
||||||
then
|
|
||||||
AC_MSG_RESULT()
|
|
||||||
AC_MSG_ERROR([OpenSSL and native PKCS11 cannot be used together.])
|
|
||||||
@@ -2077,6 +2081,7 @@ AC_SUBST(OPENSSL_ED25519)
|
|
||||||
AC_SUBST(OPENSSL_GOST)
|
|
||||||
|
|
||||||
DNS_CRYPTO_LIBS="$DNS_CRYPTO_LIBS $DST_OPENSSL_LIBS"
|
|
||||||
+DNS_CRYPTO_PK11_LIBS="$DNS_CRYPTO_LIBS"
|
|
||||||
|
|
||||||
ISC_PLATFORM_WANTAES="#undef ISC_PLATFORM_WANTAES"
|
|
||||||
if test "yes" = "$with_aes"
|
|
||||||
@@ -2363,6 +2368,7 @@ esac
|
|
||||||
AC_SUBST(PKCS11LINKOBJS)
|
|
||||||
AC_SUBST(PKCS11LINKSRCS)
|
|
||||||
AC_SUBST(CRYPTO)
|
|
||||||
+AC_SUBST(CRYPTO_PK11)
|
|
||||||
AC_SUBST(PKCS11_ECDSA)
|
|
||||||
AC_SUBST(PKCS11_GOST)
|
|
||||||
AC_SUBST(PKCS11_ED25519)
|
|
||||||
@@ -5491,8 +5497,11 @@ AC_CONFIG_FILES([
|
|
||||||
bin/delv/Makefile
|
bin/delv/Makefile
|
||||||
bin/dig/Makefile
|
bin/dig/Makefile
|
||||||
bin/dnssec/Makefile
|
bin/dnssec/Makefile
|
||||||
+ bin/dnssec-pkcs11/Makefile
|
+ bin/dnssec-pkcs11/Makefile
|
||||||
bin/named/Makefile
|
bin/named/Makefile
|
||||||
bin/named/unix/Makefile
|
bin/named/unix/Makefile
|
||||||
+ bin/named-pkcs11/Makefile
|
+ bin/named-pkcs11/Makefile
|
||||||
+ bin/named-pkcs11/unix/Makefile
|
+ bin/named-pkcs11/unix/Makefile
|
||||||
bin/nsupdate/Makefile
|
bin/nsupdate/Makefile
|
||||||
bin/pkcs11/Makefile
|
bin/pkcs11/Makefile
|
||||||
bin/python/Makefile
|
bin/plugins/Makefile
|
||||||
@@ -5565,6 +5574,10 @@ AC_CONFIG_FILES([
|
@@ -2861,6 +2872,10 @@ AC_CONFIG_FILES([
|
||||||
lib/dns/include/dns/Makefile
|
lib/dns/include/dns/Makefile
|
||||||
lib/dns/include/dst/Makefile
|
lib/dns/include/dst/Makefile
|
||||||
lib/dns/tests/Makefile
|
lib/dns/tests/Makefile
|
||||||
@ -413,73 +315,54 @@ index 83cad4a..e1e1a32 100644
|
|||||||
lib/irs/Makefile
|
lib/irs/Makefile
|
||||||
lib/irs/include/Makefile
|
lib/irs/include/Makefile
|
||||||
lib/irs/include/irs/Makefile
|
lib/irs/include/irs/Makefile
|
||||||
@@ -5589,6 +5602,24 @@ AC_CONFIG_FILES([
|
@@ -2893,6 +2908,10 @@ AC_CONFIG_FILES([
|
||||||
lib/isc/unix/include/Makefile
|
lib/ns/include/Makefile
|
||||||
lib/isc/unix/include/isc/Makefile
|
lib/ns/include/ns/Makefile
|
||||||
lib/isc/unix/include/pkcs11/Makefile
|
lib/ns/tests/Makefile
|
||||||
+ lib/isc-pkcs11/$arch/Makefile
|
+ lib/ns-pkcs11/Makefile
|
||||||
+ lib/isc-pkcs11/$arch/include/Makefile
|
+ lib/ns-pkcs11/include/Makefile
|
||||||
+ lib/isc-pkcs11/$arch/include/isc/Makefile
|
+ lib/ns-pkcs11/include/ns/Makefile
|
||||||
+ lib/isc-pkcs11/$thread_dir/Makefile
|
+ lib/ns-pkcs11/tests/Makefile
|
||||||
+ lib/isc-pkcs11/$thread_dir/include/Makefile
|
make/Makefile
|
||||||
+ lib/isc-pkcs11/$thread_dir/include/isc/Makefile
|
make/mkdep
|
||||||
+ lib/isc-pkcs11/Makefile
|
unit/unittest.sh
|
||||||
+ lib/isc-pkcs11/include/Makefile
|
|
||||||
+ lib/isc-pkcs11/include/isc/Makefile
|
|
||||||
+ lib/isc-pkcs11/include/isc/platform.h
|
|
||||||
+ lib/isc-pkcs11/include/pk11/Makefile
|
|
||||||
+ lib/isc-pkcs11/include/pkcs11/Makefile
|
|
||||||
+ lib/isc-pkcs11/tests/Makefile
|
|
||||||
+ lib/isc-pkcs11/nls/Makefile
|
|
||||||
+ lib/isc-pkcs11/unix/Makefile
|
|
||||||
+ lib/isc-pkcs11/unix/include/Makefile
|
|
||||||
+ lib/isc-pkcs11/unix/include/isc/Makefile
|
|
||||||
+ lib/isc-pkcs11/unix/include/pkcs11/Makefile
|
|
||||||
lib/isccc/Makefile
|
|
||||||
lib/isccc/include/Makefile
|
|
||||||
lib/isccc/include/isccc/Makefile
|
|
||||||
diff --git a/lib/Makefile.in b/lib/Makefile.in
|
diff --git a/lib/Makefile.in b/lib/Makefile.in
|
||||||
index f089bea..3ed939b 100644
|
index 833964e..058ba2f 100644
|
||||||
--- a/lib/Makefile.in
|
--- a/lib/Makefile.in
|
||||||
+++ b/lib/Makefile.in
|
+++ b/lib/Makefile.in
|
||||||
@@ -15,7 +15,7 @@ top_srcdir = @top_srcdir@
|
@@ -15,7 +15,7 @@ top_srcdir = @top_srcdir@
|
||||||
# Attempt to disable parallel processing.
|
# Attempt to disable parallel processing.
|
||||||
.NOTPARALLEL:
|
.NOTPARALLEL:
|
||||||
.NO_PARALLEL:
|
.NO_PARALLEL:
|
||||||
-SUBDIRS = isc isccc dns isccfg bind9 lwres irs samples
|
-SUBDIRS = isc isccc dns ns isccfg bind9 irs
|
||||||
+SUBDIRS = isc isc-pkcs11 isccc dns dns-pkcs11 isccfg bind9 lwres irs samples
|
+SUBDIRS = isc isccc dns dns-pkcs11 ns ns-pkcs11 isccfg bind9 irs
|
||||||
TARGETS =
|
TARGETS =
|
||||||
|
|
||||||
@BIND9_MAKE_RULES@
|
@BIND9_MAKE_RULES@
|
||||||
diff --git a/lib/dns-pkcs11/Makefile.in b/lib/dns-pkcs11/Makefile.in
|
diff --git a/lib/dns-pkcs11/Makefile.in b/lib/dns-pkcs11/Makefile.in
|
||||||
index 1d0f5df..98c9ba0 100644
|
index 58bda3c..d6a45df 100644
|
||||||
--- a/lib/dns-pkcs11/Makefile.in
|
--- a/lib/dns-pkcs11/Makefile.in
|
||||||
+++ b/lib/dns-pkcs11/Makefile.in
|
+++ b/lib/dns-pkcs11/Makefile.in
|
||||||
@@ -24,17 +24,17 @@ VERSION=@BIND9_VERSION@
|
@@ -22,7 +22,7 @@ VERSION=@BIND9_VERSION@
|
||||||
|
|
||||||
@BIND9_MAKE_INCLUDES@
|
@BIND9_MAKE_INCLUDES@
|
||||||
|
|
||||||
-CINCLUDES = -I. -I${top_srcdir}/lib/dns -Iinclude ${DNS_INCLUDES} \
|
-CINCLUDES = -I. -I${top_srcdir}/lib/dns -Iinclude ${DNS_INCLUDES} \
|
||||||
- ${ISC_INCLUDES} ${MAXMINDDB_CFLAGS} \
|
|
||||||
+CINCLUDES = -I. -I${top_srcdir}/lib/dns-pkcs11 -Iinclude ${DNS_PKCS11_INCLUDES} \
|
+CINCLUDES = -I. -I${top_srcdir}/lib/dns-pkcs11 -Iinclude ${DNS_PKCS11_INCLUDES} \
|
||||||
+ ${ISC_PKCS11_INCLUDES} ${MAXMINDDB_CFLAGS} \
|
${ISC_INCLUDES} \
|
||||||
@DST_OPENSSL_INC@ @DST_GSSAPI_INC@
|
${FSTRM_CFLAGS} \
|
||||||
|
${OPENSSL_CFLAGS} @DST_GSSAPI_INC@ \
|
||||||
|
@@ -32,7 +32,7 @@ CINCLUDES = -I. -I${top_srcdir}/lib/dns -Iinclude ${DNS_INCLUDES} \
|
||||||
|
${LMDB_CFLAGS} \
|
||||||
|
${MAXMINDDB_CFLAGS}
|
||||||
|
|
||||||
-CDEFINES = -DUSE_MD5 @CRYPTO@ @USE_GSSAPI@
|
-CDEFINES = @USE_GSSAPI@
|
||||||
+CDEFINES = -DUSE_MD5 @CRYPTO_PK11@ @USE_GSSAPI@
|
+CDEFINES = @USE_GSSAPI@ @USE_PKCS11@
|
||||||
|
|
||||||
CWARNINGS =
|
CWARNINGS =
|
||||||
|
|
||||||
-ISCLIBS = ../../lib/isc/libisc.@A@
|
@@ -135,15 +135,15 @@ version.@O@: version.c
|
||||||
+ISCLIBS = ../../lib/isc-pkcs11/libisc-pkcs11.@A@
|
-DMAPAPI=\"${MAPAPI}\" \
|
||||||
|
|
||||||
-ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
|
||||||
+ISCDEPLIBS = ../../lib/isc-pkcs11/libisc-pkcs11.@A@
|
|
||||||
|
|
||||||
LIBS = ${MAXMINDDB_LIBS} @LIBS@
|
|
||||||
|
|
||||||
@@ -148,15 +148,15 @@ version.@O@: version.c
|
|
||||||
-DLIBAGE=${LIBAGE} \
|
|
||||||
-c ${srcdir}/version.c
|
-c ${srcdir}/version.c
|
||||||
|
|
||||||
-libdns.@SA@: ${OBJS}
|
-libdns.@SA@: ${OBJS}
|
||||||
@ -492,13 +375,13 @@ index 1d0f5df..98c9ba0 100644
|
|||||||
${LIBTOOL_MODE_LINK} \
|
${LIBTOOL_MODE_LINK} \
|
||||||
- ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libdns.la -rpath ${libdir} \
|
- ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libdns.la -rpath ${libdir} \
|
||||||
+ ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libdns-pkcs11.la -rpath ${libdir} \
|
+ ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libdns-pkcs11.la -rpath ${libdir} \
|
||||||
-version-info ${LIBINTERFACE}:${LIBREVISION}:${LIBAGE} \
|
-release "${VERSION}" \
|
||||||
- ${OBJS} ${ISCLIBS} @DNS_CRYPTO_LIBS@ ${LIBS}
|
- ${OBJS} ${ISCLIBS} @DNS_CRYPTO_LIBS@ ${LIBS}
|
||||||
+ ${OBJS} ${ISCLIBS} @DNS_CRYPTO_PK11_LIBS@ ${LIBS}
|
+ ${OBJS} ${ISCLIBS} @DNS_CRYPTO_PK11_LIBS@ ${LIBS}
|
||||||
|
|
||||||
include: gen
|
include: gen
|
||||||
${MAKE} include/dns/enumtype.h
|
${MAKE} include/dns/enumtype.h
|
||||||
@@ -187,22 +187,22 @@ gen: gen.c
|
@@ -174,22 +174,22 @@ gen: gen.c
|
||||||
${BUILD_CPPFLAGS} ${BUILD_LDFLAGS} -o $@ ${srcdir}/gen.c \
|
${BUILD_CPPFLAGS} ${BUILD_LDFLAGS} -o $@ ${srcdir}/gen.c \
|
||||||
${BUILD_LIBS} ${LFS_LIBS}
|
${BUILD_LIBS} ${LFS_LIBS}
|
||||||
|
|
||||||
@ -526,89 +409,142 @@ index 1d0f5df..98c9ba0 100644
|
|||||||
rm -f gen code.h include/dns/enumtype.h include/dns/enumclass.h
|
rm -f gen code.h include/dns/enumtype.h include/dns/enumclass.h
|
||||||
rm -f include/dns/rdatastruct.h
|
rm -f include/dns/rdatastruct.h
|
||||||
rm -f dnstap.pb-c.c dnstap.pb-c.h
|
rm -f dnstap.pb-c.c dnstap.pb-c.h
|
||||||
diff --git a/lib/isc-pkcs11/Makefile.in b/lib/isc-pkcs11/Makefile.in
|
diff --git a/lib/dns-pkcs11/tests/Makefile.in b/lib/dns-pkcs11/tests/Makefile.in
|
||||||
index 7e3e9ce..58d7466 100644
|
index 3bb5e01..c96fe7d 100644
|
||||||
--- a/lib/isc-pkcs11/Makefile.in
|
--- a/lib/dns-pkcs11/tests/Makefile.in
|
||||||
+++ b/lib/isc-pkcs11/Makefile.in
|
+++ b/lib/dns-pkcs11/tests/Makefile.in
|
||||||
@@ -23,8 +23,8 @@ CINCLUDES = -I${srcdir}/unix/include \
|
@@ -15,15 +15,15 @@ VERSION=@BIND9_VERSION@
|
||||||
-I${srcdir}/@ISC_THREAD_DIR@/include \
|
|
||||||
-I${srcdir}/@ISC_ARCH_DIR@/include \
|
@BIND9_MAKE_INCLUDES@
|
||||||
-I./include \
|
|
||||||
- -I${srcdir}/include ${DNS_INCLUDES} @ISC_OPENSSL_INC@
|
-CINCLUDES = -I. -Iinclude ${DNS_INCLUDES} ${ISC_INCLUDES} \
|
||||||
-CDEFINES = @CRYPTO@ -DPK11_LIB_LOCATION=\"${PROVIDER}\"
|
+CINCLUDES = -I. -Iinclude ${DNS_PKCS11_INCLUDES} ${ISC_INCLUDES} \
|
||||||
+ -I${srcdir}/include ${DNS_PKCS11_INCLUDES}
|
${FSTRM_CFLAGS} ${OPENSSL_CFLAGS} \
|
||||||
+CDEFINES = @CRYPTO_PK11@ -DPK11_LIB_LOCATION=\"${PROVIDER}\"
|
${PROTOBUF_C_CFLAGS} ${MAXMINDDB_CFLAGS} @CMOCKA_CFLAGS@
|
||||||
|
-CDEFINES = -DTESTS="\"${top_builddir}/lib/dns/tests/\""
|
||||||
|
+CDEFINES = @USE_PKCS11@ -DTESTS="\"${top_builddir}/lib/dns-pkcs11/tests/\""
|
||||||
|
|
||||||
|
ISCLIBS = ../../isc/libisc.@A@ @NO_LIBTOOL_ISCLIBS@
|
||||||
|
ISCDEPLIBS = ../../isc/libisc.@A@
|
||||||
|
-DNSLIBS = ../libdns.@A@ @NO_LIBTOOL_DNSLIBS@
|
||||||
|
-DNSDEPLIBS = ../libdns.@A@
|
||||||
|
+DNSLIBS = ../libdns-pkcs11.@A@ @NO_LIBTOOL_DNSLIBS@
|
||||||
|
+DNSDEPLIBS = ../libdns-pkcs11.@A@
|
||||||
|
|
||||||
|
LIBS = @LIBS@ @CMOCKA_LIBS@
|
||||||
|
|
||||||
|
diff --git a/lib/ns-pkcs11/Makefile.in b/lib/ns-pkcs11/Makefile.in
|
||||||
|
index bc683ce..7a9d2f2 100644
|
||||||
|
--- a/lib/ns-pkcs11/Makefile.in
|
||||||
|
+++ b/lib/ns-pkcs11/Makefile.in
|
||||||
|
@@ -16,12 +16,12 @@ VERSION=@BIND9_VERSION@
|
||||||
|
|
||||||
|
@BIND9_MAKE_INCLUDES@
|
||||||
|
|
||||||
|
-CINCLUDES = -I. -I${top_srcdir}/lib/ns -Iinclude \
|
||||||
|
- ${NS_INCLUDES} ${DNS_INCLUDES} ${ISC_INCLUDES} \
|
||||||
|
+CINCLUDES = -I. -I${top_srcdir}/lib/ns-pkcs11 -Iinclude \
|
||||||
|
+ ${NS_PKCS11_INCLUDES} ${DNS_PKCS11_INCLUDES} ${ISC_INCLUDES} \
|
||||||
|
${OPENSSL_CFLAGS} @DST_GSSAPI_INC@ \
|
||||||
|
${FSTRM_CFLAGS}
|
||||||
|
|
||||||
|
-CDEFINES = -DNAMED_PLUGINDIR=\"${plugindir}\"
|
||||||
|
+CDEFINES = @USE_PKCS11@ -DNAMED_PLUGINDIR=\"${plugindir}\"
|
||||||
|
|
||||||
CWARNINGS =
|
CWARNINGS =
|
||||||
|
|
||||||
# Alphabetically
|
@@ -29,9 +29,9 @@ ISCLIBS = ../../lib/isc/libisc.@A@
|
||||||
@@ -107,40 +107,40 @@ version.@O@: version.c
|
|
||||||
-DLIBAGE=${LIBAGE} \
|
ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
||||||
|
|
||||||
|
-DNSLIBS = ../../lib/dns/libdns.@A@ @NO_LIBTOOL_DNSLIBS@
|
||||||
|
+DNSLIBS = ../../lib/dns-pkcs11/libdns-pkcs11.@A@ @NO_LIBTOOL_DNSLIBS@
|
||||||
|
|
||||||
|
-DNSDEPLIBS = ../../lib/dns/libdns.@A@
|
||||||
|
+DNSDEPLIBS = ../../lib/dns-pkcs11/libdns-pkcs11.@A@
|
||||||
|
|
||||||
|
LIBS = @LIBS@
|
||||||
|
|
||||||
|
@@ -60,28 +60,28 @@ version.@O@: version.c
|
||||||
|
-DMAJOR=\"${MAJOR}\" \
|
||||||
-c ${srcdir}/version.c
|
-c ${srcdir}/version.c
|
||||||
|
|
||||||
-libisc.@SA@: ${OBJS} ${SYMTBLOBJS}
|
-libns.@SA@: ${OBJS}
|
||||||
+libisc-pkcs11.@SA@: ${OBJS} ${SYMTBLOBJS}
|
+libns-pkcs11.@SA@: ${OBJS}
|
||||||
${AR} ${ARFLAGS} $@ ${OBJS} ${SYMTBLOBJS}
|
|
||||||
${RANLIB} $@
|
|
||||||
|
|
||||||
-libisc-nosymtbl.@SA@: ${OBJS}
|
|
||||||
+libisc-pkcs11-nosymtbl.@SA@: ${OBJS}
|
|
||||||
${AR} ${ARFLAGS} $@ ${OBJS}
|
${AR} ${ARFLAGS} $@ ${OBJS}
|
||||||
${RANLIB} $@
|
${RANLIB} $@
|
||||||
|
|
||||||
-libisc.la: ${OBJS} ${SYMTBLOBJS}
|
-libns.la: ${OBJS}
|
||||||
+libisc-pkcs11.la: ${OBJS} ${SYMTBLOBJS}
|
+libns-pkcs11.la: ${OBJS}
|
||||||
${LIBTOOL_MODE_LINK} \
|
${LIBTOOL_MODE_LINK} \
|
||||||
- ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libisc.la -rpath ${libdir} \
|
- ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libns.la -rpath ${libdir} \
|
||||||
+ ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libisc-pkcs11.la -rpath ${libdir} \
|
+ ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libns-pkcs11.la -rpath ${libdir} \
|
||||||
-version-info ${LIBINTERFACE}:${LIBREVISION}:${LIBAGE} \
|
-release "${VERSION}" \
|
||||||
${OBJS} ${SYMTBLOBJS} ${LIBS}
|
- ${OBJS} ${ISCLIBS} ${DNSLIBS} @DNS_CRYPTO_LIBS@ ${LIBS}
|
||||||
|
+ ${OBJS} ${ISCLIBS} ${DNSLIBS} @DNS_CRYPTO_PK11_LIBS@ ${LIBS}
|
||||||
|
|
||||||
-libisc-nosymtbl.la: ${OBJS}
|
-timestamp: libns.@A@
|
||||||
+libisc-pkcs11-nosymtbl.la: ${OBJS}
|
+timestamp: libns-pkcs11.@A@
|
||||||
${LIBTOOL_MODE_LINK} \
|
|
||||||
- ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libisc-nosymtbl.la -rpath ${libdir} \
|
|
||||||
+ ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libisc-pkcs11-nosymtbl.la -rpath ${libdir} \
|
|
||||||
-version-info ${LIBINTERFACE}:${LIBREVISION}:${LIBAGE} \
|
|
||||||
${OBJS} ${LIBS}
|
|
||||||
|
|
||||||
-timestamp: libisc.@A@ libisc-nosymtbl.@A@
|
|
||||||
+timestamp: libisc-pkcs11.@A@ libisc-pkcs11-nosymtbl.@A@
|
|
||||||
touch timestamp
|
touch timestamp
|
||||||
|
|
||||||
-testdirs: libisc.@A@ libisc-nosymtbl.@A@
|
|
||||||
+testdirs: libisc-pkcs11.@A@ libisc-pkcs11-nosymtbl.@A@
|
|
||||||
|
|
||||||
installdirs:
|
installdirs:
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${libdir}
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${libdir}
|
||||||
|
|
||||||
install:: timestamp installdirs
|
install:: timestamp installdirs
|
||||||
- ${LIBTOOL_MODE_INSTALL} ${INSTALL_LIBRARY} libisc.@A@ ${DESTDIR}${libdir}
|
- ${LIBTOOL_MODE_INSTALL} ${INSTALL_LIBRARY} libns.@A@ \
|
||||||
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_LIBRARY} libisc-pkcs11.@A@ ${DESTDIR}${libdir}
|
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_LIBRARY} libns-pkcs11.@A@ \
|
||||||
|
${DESTDIR}${libdir}
|
||||||
|
|
||||||
uninstall::
|
uninstall::
|
||||||
- ${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${libdir}/libisc.@A@
|
- ${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${libdir}/libns.@A@
|
||||||
+ ${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${libdir}/libisc-pkcs11.@A@
|
+ ${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${libdir}/libns-pkcs11.@A@
|
||||||
|
|
||||||
clean distclean::
|
clean distclean::
|
||||||
- rm -f libisc.@A@ libisc-nosymtbl.@A@ libisc.la \
|
- rm -f libns.@A@ timestamp
|
||||||
- libisc-nosymtbl.la timestamp
|
+ rm -f libns-pkcs11.@A@ timestamp
|
||||||
+ rm -f libisc-pkcs11.@A@ libisc-pkcs11-nosymtbl.@A@ libisc-pkcs11.la \
|
diff --git a/lib/ns-pkcs11/tests/Makefile.in b/lib/ns-pkcs11/tests/Makefile.in
|
||||||
+ libisc-pkcs11-nosymtbl.la timestamp
|
index 4c3e694..c1b6d99 100644
|
||||||
|
--- a/lib/ns-pkcs11/tests/Makefile.in
|
||||||
|
+++ b/lib/ns-pkcs11/tests/Makefile.in
|
||||||
|
@@ -17,17 +17,17 @@ VERSION=@BIND9_VERSION@
|
||||||
|
|
||||||
|
WRAP_OPTIONS = -Wl,--wrap=isc__nmhandle_detach -Wl,--wrap=isc__nmhandle_attach
|
||||||
|
|
||||||
|
-CINCLUDES = -I. -Iinclude ${NS_INCLUDES} ${DNS_INCLUDES} ${ISC_INCLUDES} \
|
||||||
|
+CINCLUDES = -I. -Iinclude ${NS_PKCS11_INCLUDES} ${DNS_PKCS11_INCLUDES} ${ISC_INCLUDES} \
|
||||||
|
${OPENSSL_CFLAGS} \
|
||||||
|
@CMOCKA_CFLAGS@
|
||||||
|
-CDEFINES = -DTESTS="\"${top_builddir}/lib/ns/tests/\"" -DNAMED_PLUGINDIR=\"${plugindir}\"
|
||||||
|
+CDEFINES = -DTESTS="\"${top_builddir}/lib/ns-pkcs11/tests/\"" -DNAMED_PLUGINDIR=\"${plugindir}\" @USE_PKCS11@
|
||||||
|
|
||||||
|
ISCLIBS = ../../isc/libisc.@A@ @NO_LIBTOOL_ISCLIBS@
|
||||||
|
ISCDEPLIBS = ../../isc/libisc.@A@
|
||||||
|
-DNSLIBS = ../../dns/libdns.@A@ @NO_LIBTOOL_DNSLIBS@
|
||||||
|
-DNSDEPLIBS = ../../dns/libdns.@A@
|
||||||
|
-NSLIBS = ../libns.@A@
|
||||||
|
-NSDEPLIBS = ../libns.@A@
|
||||||
|
+DNSLIBS = ../../dns-pkcs11/libdns-pkcs11.@A@ @NO_LIBTOOL_DNSLIBS@
|
||||||
|
+DNSDEPLIBS = ../../dns-pkcs11/libdns-pkcs11.@A@
|
||||||
|
+NSLIBS = ../libns-pkcs11.@A@
|
||||||
|
+NSDEPLIBS = ../libns-pkcs11.@A@
|
||||||
|
|
||||||
|
LIBS = @LIBS@ @CMOCKA_LIBS@
|
||||||
|
|
||||||
diff --git a/make/includes.in b/make/includes.in
|
diff --git a/make/includes.in b/make/includes.in
|
||||||
index 66efe68..966671f 100644
|
index b8317d3..b73b0c4 100644
|
||||||
--- a/make/includes.in
|
--- a/make/includes.in
|
||||||
+++ b/make/includes.in
|
+++ b/make/includes.in
|
||||||
@@ -41,3 +41,13 @@ BIND9_INCLUDES = @BIND9_BIND9_BUILDINCLUDE@ \
|
@@ -39,3 +39,10 @@ BIND9_INCLUDES = @BIND9_BIND9_BUILDINCLUDE@ \
|
||||||
|
|
||||||
TEST_INCLUDES = \
|
TEST_INCLUDES = \
|
||||||
-I${top_srcdir}/lib/tests/include
|
-I${top_srcdir}/lib/tests/include
|
||||||
+
|
+
|
||||||
+ISC_PKCS11_INCLUDES = @BIND9_ISC_BUILDINCLUDE@ \
|
+DNS_PKCS11_INCLUDES = @BIND9_DNS_PKCS11_BUILDINCLUDE@ \
|
||||||
+ -I${top_srcdir}/lib/isc-pkcs11 \
|
|
||||||
+ -I${top_srcdir}/lib/isc-pkcs11/include \
|
|
||||||
+ -I${top_srcdir}/lib/isc-pkcs11/unix/include \
|
|
||||||
+ -I${top_srcdir}/lib/isc-pkcs11/@ISC_THREAD_DIR@/include \
|
|
||||||
+ -I${top_srcdir}/lib/isc-pkcs11/@ISC_ARCH_DIR@/include
|
|
||||||
+
|
|
||||||
+DNS_PKCS11_INCLUDES = @BIND9_DNS_BUILDINCLUDE@ \
|
|
||||||
+ -I${top_srcdir}/lib/dns-pkcs11/include
|
+ -I${top_srcdir}/lib/dns-pkcs11/include
|
||||||
|
+
|
||||||
|
+NS_PKCS11_INCLUDES = @BIND9_NS_PKCS11_BUILDINCLUDE@ \
|
||||||
|
+ -I${top_srcdir}/lib/ns-pkcs11/include
|
||||||
|
+
|
||||||
|
--
|
||||||
|
2.26.3
|
||||||
|
|
||||||
|
|||||||
@ -1,310 +0,0 @@
|
|||||||
diff --git a/bin/Makefile.in b/bin/Makefile.in
|
|
||||||
index ce7a2da..4e6a824 100644
|
|
||||||
--- a/bin/Makefile.in
|
|
||||||
+++ b/bin/Makefile.in
|
|
||||||
@@ -11,8 +11,8 @@ srcdir = @srcdir@
|
|
||||||
VPATH = @srcdir@
|
|
||||||
top_srcdir = @top_srcdir@
|
|
||||||
|
|
||||||
-SUBDIRS = named named-pkcs11 rndc dig delv dnssec dnssec-pkcs11 tools nsupdate \
|
|
||||||
- check confgen @NZD_TOOLS@ @PYTHON_TOOLS@ @PKCS11_TOOLS@ tests
|
|
||||||
+SUBDIRS = named named-sdb named-pkcs11 rndc dig delv dnssec dnssec-pkcs11 tools nsupdate \
|
|
||||||
+ check confgen @NZD_TOOLS@ @PYTHON_TOOLS@ @PKCS11_TOOLS@ sdb_tools tests
|
|
||||||
TARGETS =
|
|
||||||
|
|
||||||
@BIND9_MAKE_RULES@
|
|
||||||
diff --git a/bin/named-sdb/Makefile.in b/bin/named-sdb/Makefile.in
|
|
||||||
index 03a72d5..4c1cb6d 100644
|
|
||||||
--- a/bin/named-sdb/Makefile.in
|
|
||||||
+++ b/bin/named-sdb/Makefile.in
|
|
||||||
@@ -30,10 +30,10 @@ VERSION=@BIND9_VERSION@
|
|
||||||
#
|
|
||||||
# Add database drivers here.
|
|
||||||
#
|
|
||||||
-DBDRIVER_OBJS =
|
|
||||||
-DBDRIVER_SRCS =
|
|
||||||
+DBDRIVER_OBJS = ldapdb.@O@ pgsqldb.@O@ sqlitedb.@O@ dirdb.@O@
|
|
||||||
+DBDRIVER_SRCS = ldapdb.c pgsqldb.c sqlitedb.c dirdb.c
|
|
||||||
DBDRIVER_INCLUDES =
|
|
||||||
-DBDRIVER_LIBS =
|
|
||||||
+DBDRIVER_LIBS = -lldap -llber -lsqlite3 -lpq
|
|
||||||
|
|
||||||
DLZ_DRIVER_DIR = ${top_srcdir}/contrib/dlz/drivers
|
|
||||||
|
|
||||||
@@ -80,7 +80,7 @@ NOSYMLIBS = ${LWRESLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
|
||||||
|
|
||||||
SUBDIRS = unix
|
|
||||||
|
|
||||||
-TARGETS = named@EXEEXT@ lwresd@EXEEXT@
|
|
||||||
+TARGETS = named-sdb@EXEEXT@
|
|
||||||
|
|
||||||
GEOIPLINKOBJS = geoip.@O@
|
|
||||||
GEOIP2LINKOBJS = geoip.@O@
|
|
||||||
@@ -154,7 +154,7 @@ server.@O@: server.c
|
|
||||||
-DPRODUCT=\"${PRODUCT}\" \
|
|
||||||
-DVERSION=\"${VERSION}\" -c ${srcdir}/server.c
|
|
||||||
|
|
||||||
-named@EXEEXT@: ${OBJS} ${DEPLIBS}
|
|
||||||
+named-sdb@EXEEXT@: ${OBJS} ${DEPLIBS}
|
|
||||||
export MAKE_SYMTABLE="yes"; \
|
|
||||||
export BASEOBJS="${OBJS} ${UOBJS}"; \
|
|
||||||
${FINALBUILDCMD}
|
|
||||||
@@ -181,8 +181,6 @@ statschannel.@O@: bind9.xsl.h
|
|
||||||
|
|
||||||
installdirs:
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
|
||||||
- $(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man5
|
|
||||||
- $(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
|
||||||
|
|
||||||
install-man5: named.conf.5
|
|
||||||
${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man5
|
|
||||||
@@ -192,16 +190,11 @@ install-man8: named.8 lwresd.8
|
|
||||||
|
|
||||||
install-man: install-man5 install-man8
|
|
||||||
|
|
||||||
-install:: named@EXEEXT@ lwresd@EXEEXT@ installdirs install-man
|
|
||||||
- ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named@EXEEXT@ ${DESTDIR}${sbindir}
|
|
||||||
- (cd ${DESTDIR}${sbindir}; rm -f lwresd@EXEEXT@; @LN@ named@EXEEXT@ lwresd@EXEEXT@)
|
|
||||||
+install:: ${TARGETS} installdirs
|
|
||||||
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named-sdb@EXEEXT@ ${DESTDIR}${sbindir}
|
|
||||||
|
|
||||||
uninstall::
|
|
||||||
- rm -f ${DESTDIR}${mandir}/man5/named.conf.5
|
|
||||||
- rm -f ${DESTDIR}${mandir}/man8/lwresd.8
|
|
||||||
- rm -f ${DESTDIR}${mandir}/man8/named.8
|
|
||||||
- rm -f ${DESTDIR}${sbindir}/lwresd@EXEEXT@
|
|
||||||
- ${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${sbindir}/named@EXEEXT@
|
|
||||||
+ ${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${sbindir}/named-sdb@EXEEXT@
|
|
||||||
|
|
||||||
@DLZ_DRIVER_RULES@
|
|
||||||
|
|
||||||
diff --git a/bin/named-sdb/main.c b/bin/named-sdb/main.c
|
|
||||||
index c9fc3cc..148ebb3 100644
|
|
||||||
--- a/bin/named-sdb/main.c
|
|
||||||
+++ b/bin/named-sdb/main.c
|
|
||||||
@@ -97,6 +97,10 @@
|
|
||||||
* Include header files for database drivers here.
|
|
||||||
*/
|
|
||||||
/* #include "xxdb.h" */
|
|
||||||
+#include "ldapdb.h"
|
|
||||||
+#include "pgsqldb.h"
|
|
||||||
+#include "sqlitedb.h"
|
|
||||||
+#include "dirdb.h"
|
|
||||||
|
|
||||||
#ifdef CONTRIB_DLZ
|
|
||||||
/*
|
|
||||||
@@ -1134,6 +1138,11 @@ setup(void) {
|
|
||||||
ns_main_earlyfatal("isc_app_start() failed: %s",
|
|
||||||
isc_result_totext(result));
|
|
||||||
|
|
||||||
+ ldapdb_clear();
|
|
||||||
+ pgsqldb_clear();
|
|
||||||
+ dirdb_clear();
|
|
||||||
+ sqlitedb_clear();
|
|
||||||
+
|
|
||||||
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
|
||||||
ISC_LOG_NOTICE, "starting %s %s%s%s <id:%s>",
|
|
||||||
ns_g_product, ns_g_version,
|
|
||||||
@@ -1334,6 +1343,75 @@ setup(void) {
|
|
||||||
isc_result_totext(result));
|
|
||||||
#endif
|
|
||||||
|
|
||||||
+ result = ldapdb_init();
|
|
||||||
+ if (result != ISC_R_SUCCESS)
|
|
||||||
+ {
|
|
||||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
|
||||||
+ ISC_LOG_ERROR,
|
|
||||||
+ "SDB ldap module initialisation failed: %s.",
|
|
||||||
+ isc_result_totext(result)
|
|
||||||
+ );
|
|
||||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
|
||||||
+ ISC_LOG_ERROR,
|
|
||||||
+ "SDB ldap zone database will be unavailable."
|
|
||||||
+ );
|
|
||||||
+ }else
|
|
||||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
|
||||||
+ ISC_LOG_NOTICE, "SDB ldap zone database module loaded."
|
|
||||||
+ );
|
|
||||||
+
|
|
||||||
+ result = pgsqldb_init();
|
|
||||||
+ if (result != ISC_R_SUCCESS)
|
|
||||||
+ {
|
|
||||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
|
||||||
+ ISC_LOG_ERROR,
|
|
||||||
+ "SDB pgsql module initialisation failed: %s.",
|
|
||||||
+ isc_result_totext(result)
|
|
||||||
+ );
|
|
||||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
|
||||||
+ ISC_LOG_ERROR,
|
|
||||||
+ "SDB pgsql zone database will be unavailable."
|
|
||||||
+ );
|
|
||||||
+ }else
|
|
||||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
|
||||||
+ ISC_LOG_NOTICE, "SDB postgreSQL DB zone database module loaded."
|
|
||||||
+ );
|
|
||||||
+
|
|
||||||
+ result = sqlitedb_init();
|
|
||||||
+ if (result != ISC_R_SUCCESS)
|
|
||||||
+ {
|
|
||||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
|
||||||
+ ISC_LOG_ERROR,
|
|
||||||
+ "SDB sqlite3 module initialisation failed: %s.",
|
|
||||||
+ isc_result_totext(result)
|
|
||||||
+ );
|
|
||||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
|
||||||
+ ISC_LOG_ERROR,
|
|
||||||
+ "SDB sqlite3 zone database will be unavailable."
|
|
||||||
+ );
|
|
||||||
+ }else
|
|
||||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
|
||||||
+ ISC_LOG_NOTICE, "SDB sqlite3 DB zone database module loaded."
|
|
||||||
+ );
|
|
||||||
+
|
|
||||||
+ result = dirdb_init();
|
|
||||||
+ if (result != ISC_R_SUCCESS)
|
|
||||||
+ {
|
|
||||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
|
||||||
+ ISC_LOG_ERROR,
|
|
||||||
+ "SDB directory DB module initialisation failed: %s.",
|
|
||||||
+ isc_result_totext(result)
|
|
||||||
+ );
|
|
||||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
|
||||||
+ ISC_LOG_ERROR,
|
|
||||||
+ "SDB directory DB zone database will be unavailable."
|
|
||||||
+ );
|
|
||||||
+ }else
|
|
||||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
|
||||||
+ ISC_LOG_NOTICE, "SDB directory DB zone database module loaded."
|
|
||||||
+ );
|
|
||||||
+
|
|
||||||
+
|
|
||||||
ns_server_create(ns_g_mctx, &ns_g_server);
|
|
||||||
|
|
||||||
#ifdef HAVE_LIBSECCOMP
|
|
||||||
@@ -1376,6 +1454,11 @@ cleanup(void) {
|
|
||||||
|
|
||||||
dns_name_destroy();
|
|
||||||
|
|
||||||
+ ldapdb_clear();
|
|
||||||
+ pgsqldb_clear();
|
|
||||||
+ sqlitedb_clear();
|
|
||||||
+ dirdb_clear();
|
|
||||||
+
|
|
||||||
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
|
||||||
ISC_LOG_NOTICE, "exiting");
|
|
||||||
ns_log_shutdown();
|
|
||||||
diff --git a/bin/named/Makefile.in b/bin/named/Makefile.in
|
|
||||||
index 03a72d5..47cc046 100644
|
|
||||||
--- a/bin/named/Makefile.in
|
|
||||||
+++ b/bin/named/Makefile.in
|
|
||||||
@@ -45,10 +45,10 @@ DLZDRIVER_LIBS = @DLZ_DRIVER_LIBS@
|
|
||||||
CINCLUDES = -I${srcdir}/include -I${srcdir}/unix/include -I. \
|
|
||||||
${LWRES_INCLUDES} ${DNS_INCLUDES} ${BIND9_INCLUDES} \
|
|
||||||
${ISCCFG_INCLUDES} ${ISCCC_INCLUDES} ${ISC_INCLUDES} \
|
|
||||||
- ${DLZDRIVER_INCLUDES} ${DBDRIVER_INCLUDES} ${MAXMINDDB_CFLAGS} \
|
|
||||||
+ ${MAXMINDDB_CFLAGS} \
|
|
||||||
@DST_OPENSSL_INC@
|
|
||||||
|
|
||||||
-CDEFINES = @CONTRIB_DLZ@ @USE_GSSAPI@ @CRYPTO@
|
|
||||||
+CDEFINES = @USE_GSSAPI@ @CRYPTO@
|
|
||||||
|
|
||||||
CWARNINGS =
|
|
||||||
|
|
||||||
@@ -72,11 +72,11 @@ DEPLIBS = ${LWRESDEPLIBS} ${DNSDEPLIBS} ${BIND9DEPLIBS} \
|
|
||||||
|
|
||||||
LIBS = ${LWRESLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
|
||||||
${ISCCFGLIBS} ${ISCCCLIBS} ${ISCLIBS} \
|
|
||||||
- ${DLZDRIVER_LIBS} ${DBDRIVER_LIBS} @LIBS@
|
|
||||||
+ @LIBS@
|
|
||||||
|
|
||||||
NOSYMLIBS = ${LWRESLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
|
||||||
${ISCCFGLIBS} ${ISCCCLIBS} ${ISCNOSYMLIBS} \
|
|
||||||
- ${DLZDRIVER_LIBS} ${DBDRIVER_LIBS} @LIBS@
|
|
||||||
+ @LIBS@
|
|
||||||
|
|
||||||
SUBDIRS = unix
|
|
||||||
|
|
||||||
@@ -94,8 +94,7 @@ OBJS = builtin.@O@ client.@O@ config.@O@ control.@O@ \
|
|
||||||
tkeyconf.@O@ tsigconf.@O@ update.@O@ xfrout.@O@ \
|
|
||||||
zoneconf.@O@ \
|
|
||||||
lwaddr.@O@ lwresd.@O@ lwdclient.@O@ lwderror.@O@ lwdgabn.@O@ \
|
|
||||||
- lwdgnba.@O@ lwdgrbn.@O@ lwdnoop.@O@ lwsearch.@O@ \
|
|
||||||
- ${DLZDRIVER_OBJS} ${DBDRIVER_OBJS}
|
|
||||||
+ lwdgnba.@O@ lwdgrbn.@O@ lwdnoop.@O@ lwsearch.@O@
|
|
||||||
|
|
||||||
UOBJS = unix/os.@O@ unix/dlz_dlopen_driver.@O@
|
|
||||||
|
|
||||||
@@ -113,8 +112,7 @@ SRCS = builtin.c client.c config.c control.c \
|
|
||||||
tkeyconf.c tsigconf.c update.c xfrout.c \
|
|
||||||
zoneconf.c \
|
|
||||||
lwaddr.c lwresd.c lwdclient.c lwderror.c lwdgabn.c \
|
|
||||||
- lwdgnba.c lwdgrbn.c lwdnoop.c lwsearch.c \
|
|
||||||
- ${DLZDRIVER_SRCS} ${DBDRIVER_SRCS}
|
|
||||||
+ lwdgnba.c lwdgrbn.c lwdnoop.c lwsearch.c
|
|
||||||
|
|
||||||
MANPAGES = named.8 lwresd.8 named.conf.5
|
|
||||||
|
|
||||||
@@ -203,7 +201,5 @@ uninstall::
|
|
||||||
rm -f ${DESTDIR}${sbindir}/lwresd@EXEEXT@
|
|
||||||
${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${sbindir}/named@EXEEXT@
|
|
||||||
|
|
||||||
-@DLZ_DRIVER_RULES@
|
|
||||||
-
|
|
||||||
named-symtbl.@O@: named-symtbl.c
|
|
||||||
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} -c named-symtbl.c
|
|
||||||
diff --git a/bin/sdb_tools/Makefile.in b/bin/sdb_tools/Makefile.in
|
|
||||||
index c7e0868..95ab742 100644
|
|
||||||
--- a/bin/sdb_tools/Makefile.in
|
|
||||||
+++ b/bin/sdb_tools/Makefile.in
|
|
||||||
@@ -32,11 +32,11 @@ DEPLIBS = ${LWRESDEPLIBS} ${DNSDEPLIBS} ${BIND9DEPLIBS} \
|
|
||||||
LIBS = ${LWRESLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
|
||||||
${ISCCFGLIBS} ${ISCCCLIBS} ${ISCLIBS} ${DBDRIVER_LIBS} @LIBS@
|
|
||||||
|
|
||||||
-TARGETS = zone2ldap@EXEEXT@ zonetodb@EXEEXT@
|
|
||||||
+TARGETS = zone2ldap@EXEEXT@ zonetodb@EXEEXT@ zone2sqlite@EXEEXT@
|
|
||||||
|
|
||||||
-OBJS = zone2ldap.@O@ zonetodb.@O@
|
|
||||||
+OBJS = zone2ldap.@O@ zonetodb.@O@ zone2sqlite.@O@
|
|
||||||
|
|
||||||
-SRCS = zone2ldap.c zonetodb.c
|
|
||||||
+SRCS = zone2ldap.c zonetodb.c zone2sqlite.c
|
|
||||||
|
|
||||||
MANPAGES = zone2ldap.1
|
|
||||||
|
|
||||||
@@ -50,6 +50,9 @@ zone2ldap@EXEEXT@: zone2ldap.@O@ ${DEPLIBS}
|
|
||||||
zonetodb@EXEEXT@: zonetodb.@O@ ${DEPLIBS}
|
|
||||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ zonetodb.@O@ -lpq ${LIBS}
|
|
||||||
|
|
||||||
+zone2sqlite@EXEEXT@: zone2sqlite.@O@ ${DEPLIBS}
|
|
||||||
+ ${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o $@ zone2sqlite.@O@ -lsqlite3 -lssl ${LIBS}
|
|
||||||
+
|
|
||||||
clean distclean manclean maintainer-clean::
|
|
||||||
rm -f ${TARGETS} ${OBJS}
|
|
||||||
|
|
||||||
@@ -60,4 +63,5 @@ installdirs:
|
|
||||||
install:: ${TARGETS} installdirs
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zone2ldap@EXEEXT@ ${DESTDIR}${sbindir}
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zonetodb@EXEEXT@ ${DESTDIR}${sbindir}
|
|
||||||
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zone2sqlite@EXEEXT@ ${DESTDIR}${sbindir}
|
|
||||||
${INSTALL_DATA} ${srcdir}/zone2ldap.1 ${DESTDIR}${mandir}/man1/zone2ldap.1
|
|
||||||
diff --git a/configure.ac b/configure.ac
|
|
||||||
index f85f45f..7d28c52 100644
|
|
||||||
--- a/configure.ac
|
|
||||||
+++ b/configure.ac
|
|
||||||
@@ -5400,6 +5400,8 @@ AC_CONFIG_FILES([
|
|
||||||
bin/named/unix/Makefile
|
|
||||||
bin/named-pkcs11/Makefile
|
|
||||||
bin/named-pkcs11/unix/Makefile
|
|
||||||
+ bin/named-sdb/Makefile
|
|
||||||
+ bin/named-sdb/unix/Makefile
|
|
||||||
bin/nsupdate/Makefile
|
|
||||||
bin/pkcs11/Makefile
|
|
||||||
bin/python/Makefile
|
|
||||||
@@ -5424,6 +5426,7 @@ AC_CONFIG_FILES([
|
|
||||||
bin/python/isc/tests/policy_test.py
|
|
||||||
bin/python/isc/utils.py
|
|
||||||
bin/rndc/Makefile
|
|
||||||
+ bin/sdb_tools/Makefile
|
|
||||||
bin/tests/Makefile
|
|
||||||
bin/tests/headerdep_test.sh
|
|
||||||
bin/tests/optional/Makefile
|
|
||||||
@ -1,18 +0,0 @@
|
|||||||
diff --git a/bin/sdb_tools/zone2ldap.c b/bin/sdb_tools/zone2ldap.c
|
|
||||||
index d56bc56..99c3314 100644
|
|
||||||
--- a/bin/sdb_tools/zone2ldap.c
|
|
||||||
+++ b/bin/sdb_tools/zone2ldap.c
|
|
||||||
@@ -817,11 +817,11 @@ build_dn_from_dc_list (char **dc_list, unsigned int ttl, int flag, char *zone)
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
- strlcat (dn, tmp, sizeof (dn));
|
|
||||||
+ strncat (dn, tmp, sizeof (dn) - strlen (dn));
|
|
||||||
}
|
|
||||||
|
|
||||||
sprintf (tmp, "dc=%s", dc_list[0]);
|
|
||||||
- strlcat (dn, tmp, sizeof (dn));
|
|
||||||
+ strncat (dn, tmp, sizeof (dn) - strlen (dn));
|
|
||||||
|
|
||||||
fflush(NULL);
|
|
||||||
return dn;
|
|
||||||
@ -1,46 +0,0 @@
|
|||||||
From 6c26ede8edcb700caca12c501c6c129801989526 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Mark Andrews <marka@isc.org>
|
|
||||||
Date: Fri, 23 Feb 2024 10:12:47 +1100
|
|
||||||
Subject: [PATCH] Do not use header_prev in expire_lru_headers
|
|
||||||
|
|
||||||
dns__cacherbt_expireheader can unlink / free header_prev underneath
|
|
||||||
it. Use ISC_LIST_TAIL after calling dns__cacherbt_expireheader
|
|
||||||
instead to get the next pointer to be processed.
|
|
||||||
|
|
||||||
(cherry picked from commit 7ce2e86024f022decb2678963538515ca39ab4ab)
|
|
||||||
(cherry picked from commit f88f21b7d890eb80097f4bd434fedb29c2f9ff63)
|
|
||||||
---
|
|
||||||
lib/dns/rbtdb.c | 8 ++++----
|
|
||||||
1 file changed, 4 insertions(+), 4 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/lib/dns/rbtdb.c b/lib/dns/rbtdb.c
|
|
||||||
index cc40eaec60..ee59c1b18b 100644
|
|
||||||
--- a/lib/dns/rbtdb.c
|
|
||||||
+++ b/lib/dns/rbtdb.c
|
|
||||||
@@ -10667,19 +10667,19 @@ update_header(dns_rbtdb_t *rbtdb, rdatasetheader_t *header,
|
|
||||||
static size_t
|
|
||||||
expire_lru_headers(dns_rbtdb_t *rbtdb, unsigned int locknum, size_t purgesize,
|
|
||||||
bool tree_locked) {
|
|
||||||
- rdatasetheader_t *header, *header_prev;
|
|
||||||
+ rdatasetheader_t *header;
|
|
||||||
size_t purged = 0;
|
|
||||||
|
|
||||||
for (header = ISC_LIST_TAIL(rbtdb->rdatasets[locknum]);
|
|
||||||
- header != NULL && purged <= purgesize; header = header_prev)
|
|
||||||
+ header != NULL && purged <= purgesize;
|
|
||||||
+ header = ISC_LIST_TAIL(rbtdb->rdatasets[locknum]))
|
|
||||||
{
|
|
||||||
- header_prev = ISC_LIST_PREV(header, link);
|
|
||||||
/*
|
|
||||||
* Unlink the entry at this point to avoid checking it
|
|
||||||
* again even if it's currently used someone else and
|
|
||||||
* cannot be purged at this moment. This entry won't be
|
|
||||||
* referenced any more (so unlinking is safe) since the
|
|
||||||
- * TTL was reset to 0.
|
|
||||||
+ * TTL will be reset to 0.
|
|
||||||
*/
|
|
||||||
ISC_LIST_UNLINK(rbtdb->rdatasets[locknum], header, link);
|
|
||||||
size_t header_size = rdataset_size(header);
|
|
||||||
--
|
|
||||||
2.43.2
|
|
||||||
|
|
||||||
File diff suppressed because it is too large
Load Diff
@ -1,64 +0,0 @@
|
|||||||
From f0fc9d7999a94da3d471c4e0a35b1f447f25eea6 Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
|
||||||
Date: Mon, 26 Feb 2024 21:08:42 +0100
|
|
||||||
Subject: [PATCH] Add normal task queue also to non-thread version
|
|
||||||
|
|
||||||
Non-thread builds are used by us for dhcp package. Make it working
|
|
||||||
again.
|
|
||||||
|
|
||||||
Related to [GL #4424] and [GL #4459].
|
|
||||||
---
|
|
||||||
lib/isc/task.c | 14 ++++++++------
|
|
||||||
1 file changed, 8 insertions(+), 6 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/lib/isc/task.c b/lib/isc/task.c
|
|
||||||
index cc83269..5315b51 100644
|
|
||||||
--- a/lib/isc/task.c
|
|
||||||
+++ b/lib/isc/task.c
|
|
||||||
@@ -1115,7 +1115,7 @@ dispatch(isc__taskmgr_t *manager, isc_taskqueue_t qid) {
|
|
||||||
}
|
|
||||||
#else /* USE_WORKER_THREADS */
|
|
||||||
if (total_dispatch_count >= DEFAULT_TASKMGR_QUANTUM ||
|
|
||||||
- empty_readyq(manager))
|
|
||||||
+ empty_readyq(manager, qid))
|
|
||||||
break;
|
|
||||||
#endif /* USE_WORKER_THREADS */
|
|
||||||
XTHREADTRACE(isc_msgcat_get(isc_msgcat, ISC_MSGSET_TASK,
|
|
||||||
@@ -1318,11 +1318,11 @@ dispatch(isc__taskmgr_t *manager, isc_taskqueue_t qid) {
|
|
||||||
}
|
|
||||||
|
|
||||||
#ifndef USE_WORKER_THREADS
|
|
||||||
- ISC_LIST_APPENDLIST(manager->ready_tasks, new_ready_tasks, ready_link);
|
|
||||||
- ISC_LIST_APPENDLIST(manager->ready_priority_tasks, new_priority_tasks,
|
|
||||||
+ ISC_LIST_APPENDLIST(manager->ready_tasks[qid], new_ready_tasks, ready_link);
|
|
||||||
+ ISC_LIST_APPENDLIST(manager->ready_priority_tasks[qid], new_priority_tasks,
|
|
||||||
ready_priority_link);
|
|
||||||
manager->tasks_ready += tasks_ready;
|
|
||||||
- if (empty_readyq(manager))
|
|
||||||
+ if (empty_readyq(manager, qid))
|
|
||||||
manager->mode = isc_taskmgrmode_normal;
|
|
||||||
#endif
|
|
||||||
|
|
||||||
@@ -1713,7 +1713,8 @@ isc__taskmgr_ready(isc_taskmgr_t *manager0) {
|
|
||||||
return (false);
|
|
||||||
|
|
||||||
LOCK(&manager->lock);
|
|
||||||
- is_ready = !empty_readyq(manager);
|
|
||||||
+ is_ready = !empty_readyq(manager, isc_taskqueue_normal) ||
|
|
||||||
+ !empty_readyq(manager, isc_taskqueue_slow);
|
|
||||||
UNLOCK(&manager->lock);
|
|
||||||
|
|
||||||
return (is_ready);
|
|
||||||
@@ -1730,7 +1731,8 @@ isc__taskmgr_dispatch(isc_taskmgr_t *manager0) {
|
|
||||||
if (manager == NULL)
|
|
||||||
return (ISC_R_NOTFOUND);
|
|
||||||
|
|
||||||
- dispatch(manager);
|
|
||||||
+ dispatch(manager, isc_taskqueue_normal);
|
|
||||||
+ dispatch(manager, isc_taskqueue_slow);
|
|
||||||
|
|
||||||
return (ISC_R_SUCCESS);
|
|
||||||
}
|
|
||||||
--
|
|
||||||
2.43.2
|
|
||||||
|
|
||||||
@ -1,737 +0,0 @@
|
|||||||
From 4c20ab54ec503f65d8ee0b863cbf41103d95130a Mon Sep 17 00:00:00 2001
|
|
||||||
From: Mark Andrews <marka@isc.org>
|
|
||||||
Date: Wed, 22 Nov 2023 16:59:03 +1100
|
|
||||||
Subject: [PATCH] Fail the DNSSEC validation on the first failure
|
|
||||||
|
|
||||||
Be more strict when encountering DNSSEC validation failures - fail on
|
|
||||||
the first failure. This will break domains that have DNSSEC signing
|
|
||||||
keys with duplicate key ids, but this is something that's much easier
|
|
||||||
to fix on the authoritative side, so we are just going to be strict
|
|
||||||
on the resolver side where it is causing performance problems.
|
|
||||||
|
|
||||||
(cherry picked from commit 8b7ecba9885e163c07c2dd3e1ceab79b2ba89e34)
|
|
||||||
|
|
||||||
Add normal and slow task queues
|
|
||||||
|
|
||||||
Split the task manager queues into normal and slow task queues, so we
|
|
||||||
can move the tasks that blocks processing for a long time (like DNSSEC
|
|
||||||
validation) into the slow queue which doesn't block fast
|
|
||||||
operations (like responding from the cache). This mitigates the whole
|
|
||||||
class of KeyTrap-like issues.
|
|
||||||
|
|
||||||
(cherry picked from commit db083a21726300916fa0b9fd8a433a796fedf636)
|
|
||||||
|
|
||||||
Don't iterate from start every time we select new signing key
|
|
||||||
|
|
||||||
Improve the selecting of the new signing key by remembering where
|
|
||||||
we stopped the iteration and just continue from that place instead
|
|
||||||
of iterating from the start over and over again each time.
|
|
||||||
|
|
||||||
(cherry picked from commit 75faeefcab47e4f1e12b358525190b4be90f97de)
|
|
||||||
|
|
||||||
Optimize selecting the signing key
|
|
||||||
|
|
||||||
Don't parse the crypto data before parsing and matching the id and the
|
|
||||||
algorithm.
|
|
||||||
|
|
||||||
(cherry picked from commit b38552cca7200a72658e482f8407f57516efc5db)
|
|
||||||
|
|
||||||
6322. [security] Specific DNS answers could cause a denial-of-service
|
|
||||||
condition due to DNS validation taking a long time.
|
|
||||||
(CVE-2023-50387) [GL #4424]
|
|
||||||
|
|
||||||
The same code change also addresses another problem:
|
|
||||||
preparing NSEC3 closest encloser proofs could exhaust
|
|
||||||
available CPU resources. (CVE-2023-50868) [GL #4459]
|
|
||||||
---
|
|
||||||
lib/dns/dst_api.c | 25 ++++--
|
|
||||||
lib/dns/include/dns/validator.h | 1 +
|
|
||||||
lib/dns/include/dst/dst.h | 4 +
|
|
||||||
lib/dns/resolver.c | 2 +-
|
|
||||||
lib/dns/validator.c | 97 +++++++++-----------
|
|
||||||
lib/dns/win32/libdns.def.in | 1 +
|
|
||||||
lib/isc/include/isc/task.h | 11 ++-
|
|
||||||
lib/isc/task.c | 153 ++++++++++++++++++++++----------
|
|
||||||
8 files changed, 186 insertions(+), 108 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/lib/dns/dst_api.c b/lib/dns/dst_api.c
|
|
||||||
index 2156384ec1..6bcd99796c 100644
|
|
||||||
--- a/lib/dns/dst_api.c
|
|
||||||
+++ b/lib/dns/dst_api.c
|
|
||||||
@@ -105,6 +105,7 @@ static isc_result_t frombuffer(dns_name_t *name,
|
|
||||||
dns_rdataclass_t rdclass,
|
|
||||||
isc_buffer_t *source,
|
|
||||||
isc_mem_t *mctx,
|
|
||||||
+ bool no_rdata,
|
|
||||||
dst_key_t **keyp);
|
|
||||||
|
|
||||||
static isc_result_t algorithm_status(unsigned int alg);
|
|
||||||
@@ -764,6 +765,13 @@ isc_result_t
|
|
||||||
dst_key_fromdns(dns_name_t *name, dns_rdataclass_t rdclass,
|
|
||||||
isc_buffer_t *source, isc_mem_t *mctx, dst_key_t **keyp)
|
|
||||||
{
|
|
||||||
+ return (dst_key_fromdns_ex(name, rdclass, source, mctx, false, keyp));
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
+isc_result_t
|
|
||||||
+dst_key_fromdns_ex(dns_name_t *name, dns_rdataclass_t rdclass,
|
|
||||||
+ isc_buffer_t *source, isc_mem_t *mctx, bool no_rdata,
|
|
||||||
+ dst_key_t **keyp) {
|
|
||||||
uint8_t alg, proto;
|
|
||||||
uint32_t flags, extflags;
|
|
||||||
dst_key_t *key = NULL;
|
|
||||||
@@ -792,7 +800,7 @@ dst_key_fromdns(dns_name_t *name, dns_rdataclass_t rdclass,
|
|
||||||
}
|
|
||||||
|
|
||||||
result = frombuffer(name, alg, flags, proto, rdclass, source,
|
|
||||||
- mctx, &key);
|
|
||||||
+ mctx, no_rdata, &key);
|
|
||||||
if (result != ISC_R_SUCCESS)
|
|
||||||
return (result);
|
|
||||||
key->key_id = id;
|
|
||||||
@@ -814,7 +822,7 @@ dst_key_frombuffer(dns_name_t *name, unsigned int alg,
|
|
||||||
REQUIRE(dst_initialized);
|
|
||||||
|
|
||||||
result = frombuffer(name, alg, flags, protocol, rdclass, source,
|
|
||||||
- mctx, &key);
|
|
||||||
+ mctx, false, &key);
|
|
||||||
if (result != ISC_R_SUCCESS)
|
|
||||||
return (result);
|
|
||||||
|
|
||||||
@@ -1915,7 +1923,8 @@ computeid(dst_key_t *key) {
|
|
||||||
static isc_result_t
|
|
||||||
frombuffer(dns_name_t *name, unsigned int alg, unsigned int flags,
|
|
||||||
unsigned int protocol, dns_rdataclass_t rdclass,
|
|
||||||
- isc_buffer_t *source, isc_mem_t *mctx, dst_key_t **keyp)
|
|
||||||
+ isc_buffer_t *source, isc_mem_t *mctx, bool no_rdata,
|
|
||||||
+ dst_key_t **keyp)
|
|
||||||
{
|
|
||||||
dst_key_t *key;
|
|
||||||
isc_result_t ret;
|
|
||||||
@@ -1940,10 +1949,12 @@ frombuffer(dns_name_t *name, unsigned int alg, unsigned int flags,
|
|
||||||
return (DST_R_UNSUPPORTEDALG);
|
|
||||||
}
|
|
||||||
|
|
||||||
- ret = key->func->fromdns(key, source);
|
|
||||||
- if (ret != ISC_R_SUCCESS) {
|
|
||||||
- dst_key_free(&key);
|
|
||||||
- return (ret);
|
|
||||||
+ if (!no_rdata) {
|
|
||||||
+ ret = key->func->fromdns(key, source);
|
|
||||||
+ if (ret != ISC_R_SUCCESS) {
|
|
||||||
+ dst_key_free(&key);
|
|
||||||
+ return (ret);
|
|
||||||
+ }
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
diff --git a/lib/dns/include/dns/validator.h b/lib/dns/include/dns/validator.h
|
|
||||||
index cc4478d6d4..b4bf8f29db 100644
|
|
||||||
--- a/lib/dns/include/dns/validator.h
|
|
||||||
+++ b/lib/dns/include/dns/validator.h
|
|
||||||
@@ -160,6 +160,7 @@ struct dns_validator {
|
|
||||||
unsigned int depth;
|
|
||||||
unsigned int authcount;
|
|
||||||
unsigned int authfail;
|
|
||||||
+ bool failed;
|
|
||||||
isc_stdtime_t start;
|
|
||||||
};
|
|
||||||
|
|
||||||
diff --git a/lib/dns/include/dst/dst.h b/lib/dns/include/dst/dst.h
|
|
||||||
index 180c841307..a8be2daf67 100644
|
|
||||||
--- a/lib/dns/include/dst/dst.h
|
|
||||||
+++ b/lib/dns/include/dst/dst.h
|
|
||||||
@@ -435,6 +435,10 @@ dst_key_tofile(const dst_key_t *key, int type, const char *directory);
|
|
||||||
*/
|
|
||||||
|
|
||||||
isc_result_t
|
|
||||||
+dst_key_fromdns_ex(dns_name_t *name, dns_rdataclass_t rdclass,
|
|
||||||
+ isc_buffer_t *source, isc_mem_t *mctx, bool no_rdata,
|
|
||||||
+ dst_key_t **keyp);
|
|
||||||
+isc_result_t
|
|
||||||
dst_key_fromdns(dns_name_t *name, dns_rdataclass_t rdclass,
|
|
||||||
isc_buffer_t *source, isc_mem_t *mctx, dst_key_t **keyp);
|
|
||||||
/*%<
|
|
||||||
diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c
|
|
||||||
index 4f71f48039..487107614c 100644
|
|
||||||
--- a/lib/dns/resolver.c
|
|
||||||
+++ b/lib/dns/resolver.c
|
|
||||||
@@ -9267,7 +9267,7 @@ dns_resolver_create(dns_view_t *view,
|
|
||||||
if (result != ISC_R_SUCCESS)
|
|
||||||
goto cleanup_buckets;
|
|
||||||
res->buckets[i].task = NULL;
|
|
||||||
- result = isc_task_create(taskmgr, 0, &res->buckets[i].task);
|
|
||||||
+ result = isc_task_create(taskmgr, ISC_TASK_QUANTUM_SLOW, &res->buckets[i].task);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
DESTROYLOCK(&res->buckets[i].lock);
|
|
||||||
goto cleanup_buckets;
|
|
||||||
diff --git a/lib/dns/validator.c b/lib/dns/validator.c
|
|
||||||
index 2a5c3caa6a..0b257fe874 100644
|
|
||||||
--- a/lib/dns/validator.c
|
|
||||||
+++ b/lib/dns/validator.c
|
|
||||||
@@ -1207,6 +1207,12 @@ create_validator(dns_validator_t *val, dns_name_t *name, dns_rdatatype_t type,
|
|
||||||
* val->key at it.
|
|
||||||
*
|
|
||||||
* If val->key is non-NULL, this returns the next matching key.
|
|
||||||
+ * If val->key is already non-NULL, start searching from the next position in
|
|
||||||
+ * 'rdataset' to find the *next* key that could have signed 'siginfo', then
|
|
||||||
+ * set val->key to that.
|
|
||||||
+ *
|
|
||||||
+ * Returns ISC_R_SUCCESS if a possible matching key has been found,
|
|
||||||
+ * ISC_R_NOTFOUND if not. Any other value indicates error.
|
|
||||||
*/
|
|
||||||
static isc_result_t
|
|
||||||
get_dst_key(dns_validator_t *val, dns_rdata_rrsig_t *siginfo,
|
|
||||||
@@ -1216,54 +1222,59 @@ get_dst_key(dns_validator_t *val, dns_rdata_rrsig_t *siginfo,
|
|
||||||
isc_buffer_t b;
|
|
||||||
dns_rdata_t rdata = DNS_RDATA_INIT;
|
|
||||||
dst_key_t *oldkey = val->key;
|
|
||||||
- bool foundold;
|
|
||||||
+ bool no_rdata = false;
|
|
||||||
|
|
||||||
- if (oldkey == NULL)
|
|
||||||
- foundold = true;
|
|
||||||
- else {
|
|
||||||
- foundold = false;
|
|
||||||
+ if (oldkey == NULL) {
|
|
||||||
+ result = dns_rdataset_first(rdataset);
|
|
||||||
+ } else {
|
|
||||||
+ dst_key_free(&oldkey);
|
|
||||||
val->key = NULL;
|
|
||||||
+ result = dns_rdataset_next(rdataset);
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+ if (result != ISC_R_SUCCESS) {
|
|
||||||
+ goto done;
|
|
||||||
}
|
|
||||||
|
|
||||||
- result = dns_rdataset_first(rdataset);
|
|
||||||
- if (result != ISC_R_SUCCESS)
|
|
||||||
- goto failure;
|
|
||||||
do {
|
|
||||||
dns_rdataset_current(rdataset, &rdata);
|
|
||||||
|
|
||||||
isc_buffer_init(&b, rdata.data, rdata.length);
|
|
||||||
isc_buffer_add(&b, rdata.length);
|
|
||||||
INSIST(val->key == NULL);
|
|
||||||
- result = dst_key_fromdns(&siginfo->signer, rdata.rdclass, &b,
|
|
||||||
- val->view->mctx, &val->key);
|
|
||||||
+ result = dst_key_fromdns_ex(&siginfo->signer, rdata.rdclass, &b,
|
|
||||||
+ val->view->mctx, no_rdata,
|
|
||||||
+ &val->key);
|
|
||||||
if (result == ISC_R_SUCCESS) {
|
|
||||||
if (siginfo->algorithm ==
|
|
||||||
(dns_secalg_t)dst_key_alg(val->key) &&
|
|
||||||
siginfo->keyid ==
|
|
||||||
(dns_keytag_t)dst_key_id(val->key) &&
|
|
||||||
+ (dst_key_flags(val->key) & DNS_KEYFLAG_REVOKE) ==
|
|
||||||
+ 0 &&
|
|
||||||
dst_key_iszonekey(val->key))
|
|
||||||
{
|
|
||||||
- if (foundold) {
|
|
||||||
- /*
|
|
||||||
- * This is the key we're looking for.
|
|
||||||
- */
|
|
||||||
- return (ISC_R_SUCCESS);
|
|
||||||
- } else if (dst_key_compare(oldkey, val->key)) {
|
|
||||||
- foundold = true;
|
|
||||||
- dst_key_free(&oldkey);
|
|
||||||
+ if (no_rdata) {
|
|
||||||
+ /* Retry with full key */
|
|
||||||
+ dns_rdata_reset(&rdata);
|
|
||||||
+ dst_key_free(&val->key);
|
|
||||||
+ no_rdata = false;
|
|
||||||
+ continue;
|
|
||||||
}
|
|
||||||
+ /* This is the key we're looking for. */
|
|
||||||
+ goto done;
|
|
||||||
}
|
|
||||||
dst_key_free(&val->key);
|
|
||||||
}
|
|
||||||
dns_rdata_reset(&rdata);
|
|
||||||
result = dns_rdataset_next(rdataset);
|
|
||||||
+ no_rdata = true;
|
|
||||||
} while (result == ISC_R_SUCCESS);
|
|
||||||
- if (result == ISC_R_NOMORE)
|
|
||||||
- result = ISC_R_NOTFOUND;
|
|
||||||
|
|
||||||
- failure:
|
|
||||||
- if (oldkey != NULL)
|
|
||||||
- dst_key_free(&oldkey);
|
|
||||||
+done:
|
|
||||||
+ if (result == ISC_R_NOMORE) {
|
|
||||||
+ result = ISC_R_NOTFOUND;
|
|
||||||
+ }
|
|
||||||
|
|
||||||
return (result);
|
|
||||||
}
|
|
||||||
@@ -1633,37 +1644,13 @@ validate(dns_validator_t *val, bool resume) {
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
|
|
||||||
- do {
|
|
||||||
- vresult = verify(val, val->key, &rdata,
|
|
||||||
- val->siginfo->keyid);
|
|
||||||
- if (vresult == ISC_R_SUCCESS)
|
|
||||||
- break;
|
|
||||||
- if (val->keynode != NULL) {
|
|
||||||
- dns_keynode_t *nextnode = NULL;
|
|
||||||
- result = dns_keytable_findnextkeynode(
|
|
||||||
- val->keytable,
|
|
||||||
- val->keynode,
|
|
||||||
- &nextnode);
|
|
||||||
- dns_keytable_detachkeynode(val->keytable,
|
|
||||||
- &val->keynode);
|
|
||||||
- val->keynode = nextnode;
|
|
||||||
- if (result != ISC_R_SUCCESS) {
|
|
||||||
- val->key = NULL;
|
|
||||||
- break;
|
|
||||||
- }
|
|
||||||
- val->key = dns_keynode_key(val->keynode);
|
|
||||||
- if (val->key == NULL)
|
|
||||||
- break;
|
|
||||||
- } else {
|
|
||||||
- if (get_dst_key(val, val->siginfo, val->keyset)
|
|
||||||
- != ISC_R_SUCCESS)
|
|
||||||
- break;
|
|
||||||
- }
|
|
||||||
- } while (1);
|
|
||||||
- if (vresult != ISC_R_SUCCESS)
|
|
||||||
+ vresult = verify(val, val->key, &rdata,
|
|
||||||
+ val->siginfo->keyid);
|
|
||||||
+ if (vresult != ISC_R_SUCCESS) {
|
|
||||||
+ val->failed = true;
|
|
||||||
validator_log(val, ISC_LOG_DEBUG(3),
|
|
||||||
"failed to verify rdataset");
|
|
||||||
- else {
|
|
||||||
+ } else {
|
|
||||||
dns_rdataset_trimttl(event->rdataset,
|
|
||||||
event->sigrdataset,
|
|
||||||
val->siginfo, val->start,
|
|
||||||
@@ -1700,9 +1687,13 @@ validate(dns_validator_t *val, bool resume) {
|
|
||||||
} else {
|
|
||||||
validator_log(val, ISC_LOG_DEBUG(3),
|
|
||||||
"verify failure: %s",
|
|
||||||
- isc_result_totext(result));
|
|
||||||
+ isc_result_totext(vresult));
|
|
||||||
resume = false;
|
|
||||||
}
|
|
||||||
+ if (val->failed) {
|
|
||||||
+ result = ISC_R_NOMORE;
|
|
||||||
+ break;
|
|
||||||
+ }
|
|
||||||
}
|
|
||||||
if (result != ISC_R_NOMORE) {
|
|
||||||
validator_log(val, ISC_LOG_DEBUG(3),
|
|
||||||
diff --git a/lib/dns/win32/libdns.def.in b/lib/dns/win32/libdns.def.in
|
|
||||||
index f597049493..7320653439 100644
|
|
||||||
--- a/lib/dns/win32/libdns.def.in
|
|
||||||
+++ b/lib/dns/win32/libdns.def.in
|
|
||||||
@@ -1439,6 +1439,7 @@ dst_key_format
|
|
||||||
dst_key_free
|
|
||||||
dst_key_frombuffer
|
|
||||||
dst_key_fromdns
|
|
||||||
+dst_key_fromdns_ex
|
|
||||||
dst_key_fromfile
|
|
||||||
dst_key_fromgssapi
|
|
||||||
dst_key_fromlabel
|
|
||||||
diff --git a/lib/isc/include/isc/task.h b/lib/isc/include/isc/task.h
|
|
||||||
index 28e5e25fc6..42f7763869 100644
|
|
||||||
--- a/lib/isc/include/isc/task.h
|
|
||||||
+++ b/lib/isc/include/isc/task.h
|
|
||||||
@@ -98,8 +98,15 @@ ISC_LANG_BEGINDECLS
|
|
||||||
***/
|
|
||||||
|
|
||||||
typedef enum {
|
|
||||||
- isc_taskmgrmode_normal = 0,
|
|
||||||
- isc_taskmgrmode_privileged
|
|
||||||
+ isc_taskqueue_normal = 0,
|
|
||||||
+ isc_taskqueue_slow = 1,
|
|
||||||
+} isc_taskqueue_t;
|
|
||||||
+
|
|
||||||
+#define ISC_TASK_QUANTUM_SLOW 1024
|
|
||||||
+
|
|
||||||
+typedef enum {
|
|
||||||
+ isc_taskmgrmode_normal = 0,
|
|
||||||
+ isc_taskmgrmode_privileged
|
|
||||||
} isc_taskmgrmode_t;
|
|
||||||
|
|
||||||
/*% Task and task manager methods */
|
|
||||||
diff --git a/lib/isc/task.c b/lib/isc/task.c
|
|
||||||
index 048639350b..cc83269df2 100644
|
|
||||||
--- a/lib/isc/task.c
|
|
||||||
+++ b/lib/isc/task.c
|
|
||||||
@@ -107,6 +107,7 @@ struct isc__task {
|
|
||||||
isc_eventlist_t on_shutdown;
|
|
||||||
unsigned int nevents;
|
|
||||||
unsigned int quantum;
|
|
||||||
+ unsigned int qid;
|
|
||||||
unsigned int flags;
|
|
||||||
isc_stdtime_t now;
|
|
||||||
isc_time_t tnow;
|
|
||||||
@@ -141,11 +142,11 @@ struct isc__taskmgr {
|
|
||||||
/* Locked by task manager lock. */
|
|
||||||
unsigned int default_quantum;
|
|
||||||
LIST(isc__task_t) tasks;
|
|
||||||
- isc__tasklist_t ready_tasks;
|
|
||||||
- isc__tasklist_t ready_priority_tasks;
|
|
||||||
+ isc__tasklist_t ready_tasks[2];
|
|
||||||
+ isc__tasklist_t ready_priority_tasks[2];
|
|
||||||
isc_taskmgrmode_t mode;
|
|
||||||
#ifdef ISC_PLATFORM_USETHREADS
|
|
||||||
- isc_condition_t work_available;
|
|
||||||
+ isc_condition_t work_available[2];
|
|
||||||
isc_condition_t exclusive_granted;
|
|
||||||
isc_condition_t paused;
|
|
||||||
#endif /* ISC_PLATFORM_USETHREADS */
|
|
||||||
@@ -247,13 +248,13 @@ isc_taskmgrmode_t
|
|
||||||
isc__taskmgr_mode(isc_taskmgr_t *manager0);
|
|
||||||
|
|
||||||
static inline bool
|
|
||||||
-empty_readyq(isc__taskmgr_t *manager);
|
|
||||||
+empty_readyq(isc__taskmgr_t *manager, isc_taskqueue_t qid);
|
|
||||||
|
|
||||||
static inline isc__task_t *
|
|
||||||
-pop_readyq(isc__taskmgr_t *manager);
|
|
||||||
+pop_readyq(isc__taskmgr_t *manager, isc_taskqueue_t qid);
|
|
||||||
|
|
||||||
static inline void
|
|
||||||
-push_readyq(isc__taskmgr_t *manager, isc__task_t *task);
|
|
||||||
+push_readyq(isc__taskmgr_t *manager, isc__task_t *task, isc_taskqueue_t qid);
|
|
||||||
|
|
||||||
static struct isc__taskmethods {
|
|
||||||
isc_taskmethods_t methods;
|
|
||||||
@@ -324,7 +325,8 @@ task_finished(isc__task_t *task) {
|
|
||||||
* any idle worker threads so they
|
|
||||||
* can exit.
|
|
||||||
*/
|
|
||||||
- BROADCAST(&manager->work_available);
|
|
||||||
+ BROADCAST(&manager->work_available[isc_taskqueue_normal]);
|
|
||||||
+ BROADCAST(&manager->work_available[isc_taskqueue_slow]);
|
|
||||||
}
|
|
||||||
#endif /* USE_WORKER_THREADS */
|
|
||||||
UNLOCK(&manager->lock);
|
|
||||||
@@ -364,7 +366,13 @@ isc__task_create(isc_taskmgr_t *manager0, unsigned int quantum,
|
|
||||||
INIT_LIST(task->events);
|
|
||||||
INIT_LIST(task->on_shutdown);
|
|
||||||
task->nevents = 0;
|
|
||||||
- task->quantum = quantum;
|
|
||||||
+ if (quantum >= ISC_TASK_QUANTUM_SLOW) {
|
|
||||||
+ task->qid = isc_taskqueue_slow;
|
|
||||||
+ task->quantum = quantum - ISC_TASK_QUANTUM_SLOW;
|
|
||||||
+ } else {
|
|
||||||
+ task->qid = isc_taskqueue_normal;
|
|
||||||
+ task->quantum = quantum;
|
|
||||||
+ }
|
|
||||||
task->flags = 0;
|
|
||||||
task->now = 0;
|
|
||||||
isc_time_settoepoch(&task->tnow);
|
|
||||||
@@ -476,11 +484,11 @@ task_ready(isc__task_t *task) {
|
|
||||||
|
|
||||||
LOCK(&manager->lock);
|
|
||||||
LOCK(&task->lock);
|
|
||||||
- push_readyq(manager, task);
|
|
||||||
+ push_readyq(manager, task, task->qid);
|
|
||||||
UNLOCK(&task->lock);
|
|
||||||
#ifdef USE_WORKER_THREADS
|
|
||||||
if (manager->mode == isc_taskmgrmode_normal || has_privilege)
|
|
||||||
- SIGNAL(&manager->work_available);
|
|
||||||
+ SIGNAL(&manager->work_available[task->qid]);
|
|
||||||
#endif /* USE_WORKER_THREADS */
|
|
||||||
UNLOCK(&manager->lock);
|
|
||||||
}
|
|
||||||
@@ -961,13 +969,13 @@ isc__task_getcurrenttimex(isc_task_t *task0, isc_time_t *t) {
|
|
||||||
* Caller must hold the task manager lock.
|
|
||||||
*/
|
|
||||||
static inline bool
|
|
||||||
-empty_readyq(isc__taskmgr_t *manager) {
|
|
||||||
+empty_readyq(isc__taskmgr_t *manager, isc_taskqueue_t qid) {
|
|
||||||
isc__tasklist_t queue;
|
|
||||||
|
|
||||||
if (manager->mode == isc_taskmgrmode_normal)
|
|
||||||
- queue = manager->ready_tasks;
|
|
||||||
+ queue = manager->ready_tasks[qid];
|
|
||||||
else
|
|
||||||
- queue = manager->ready_priority_tasks;
|
|
||||||
+ queue = manager->ready_priority_tasks[qid];
|
|
||||||
|
|
||||||
return (EMPTY(queue));
|
|
||||||
}
|
|
||||||
@@ -981,18 +989,18 @@ empty_readyq(isc__taskmgr_t *manager) {
|
|
||||||
* Caller must hold the task manager lock.
|
|
||||||
*/
|
|
||||||
static inline isc__task_t *
|
|
||||||
-pop_readyq(isc__taskmgr_t *manager) {
|
|
||||||
+pop_readyq(isc__taskmgr_t *manager, isc_taskqueue_t qid) {
|
|
||||||
isc__task_t *task;
|
|
||||||
|
|
||||||
if (manager->mode == isc_taskmgrmode_normal)
|
|
||||||
- task = HEAD(manager->ready_tasks);
|
|
||||||
+ task = HEAD(manager->ready_tasks[qid]);
|
|
||||||
else
|
|
||||||
- task = HEAD(manager->ready_priority_tasks);
|
|
||||||
+ task = HEAD(manager->ready_priority_tasks[qid]);
|
|
||||||
|
|
||||||
if (task != NULL) {
|
|
||||||
- DEQUEUE(manager->ready_tasks, task, ready_link);
|
|
||||||
+ DEQUEUE(manager->ready_tasks[qid], task, ready_link);
|
|
||||||
if (ISC_LINK_LINKED(task, ready_priority_link))
|
|
||||||
- DEQUEUE(manager->ready_priority_tasks, task,
|
|
||||||
+ DEQUEUE(manager->ready_priority_tasks[qid], task,
|
|
||||||
ready_priority_link);
|
|
||||||
}
|
|
||||||
|
|
||||||
@@ -1006,16 +1014,16 @@ pop_readyq(isc__taskmgr_t *manager) {
|
|
||||||
* Caller must hold the task manager lock.
|
|
||||||
*/
|
|
||||||
static inline void
|
|
||||||
-push_readyq(isc__taskmgr_t *manager, isc__task_t *task) {
|
|
||||||
- ENQUEUE(manager->ready_tasks, task, ready_link);
|
|
||||||
+push_readyq(isc__taskmgr_t *manager, isc__task_t *task, isc_taskqueue_t qid) {
|
|
||||||
+ ENQUEUE(manager->ready_tasks[qid], task, ready_link);
|
|
||||||
if ((task->flags & TASK_F_PRIVILEGED) != 0)
|
|
||||||
- ENQUEUE(manager->ready_priority_tasks, task,
|
|
||||||
+ ENQUEUE(manager->ready_priority_tasks[qid], task,
|
|
||||||
ready_priority_link);
|
|
||||||
manager->tasks_ready++;
|
|
||||||
}
|
|
||||||
|
|
||||||
static void
|
|
||||||
-dispatch(isc__taskmgr_t *manager) {
|
|
||||||
+dispatch(isc__taskmgr_t *manager, isc_taskqueue_t qid) {
|
|
||||||
isc__task_t *task;
|
|
||||||
#ifndef USE_WORKER_THREADS
|
|
||||||
unsigned int total_dispatch_count = 0;
|
|
||||||
@@ -1094,13 +1102,13 @@ dispatch(isc__taskmgr_t *manager) {
|
|
||||||
* If a pause has been requested, don't do any work
|
|
||||||
* until it's been released.
|
|
||||||
*/
|
|
||||||
- while ((empty_readyq(manager) || manager->pause_requested ||
|
|
||||||
+ while ((empty_readyq(manager, qid) || manager->pause_requested ||
|
|
||||||
manager->exclusive_requested) && !FINISHED(manager))
|
|
||||||
{
|
|
||||||
XTHREADTRACE(isc_msgcat_get(isc_msgcat,
|
|
||||||
ISC_MSGSET_GENERAL,
|
|
||||||
ISC_MSG_WAIT, "wait"));
|
|
||||||
- WAIT(&manager->work_available, &manager->lock);
|
|
||||||
+ WAIT(&manager->work_available[qid], &manager->lock);
|
|
||||||
XTHREADTRACE(isc_msgcat_get(isc_msgcat,
|
|
||||||
ISC_MSGSET_TASK,
|
|
||||||
ISC_MSG_AWAKE, "awake"));
|
|
||||||
@@ -1113,7 +1121,7 @@ dispatch(isc__taskmgr_t *manager) {
|
|
||||||
XTHREADTRACE(isc_msgcat_get(isc_msgcat, ISC_MSGSET_TASK,
|
|
||||||
ISC_MSG_WORKING, "working"));
|
|
||||||
|
|
||||||
- task = pop_readyq(manager);
|
|
||||||
+ task = pop_readyq(manager, qid);
|
|
||||||
if (task != NULL) {
|
|
||||||
unsigned int dispatch_count = 0;
|
|
||||||
bool done = false;
|
|
||||||
@@ -1278,7 +1286,7 @@ dispatch(isc__taskmgr_t *manager) {
|
|
||||||
*/
|
|
||||||
#ifdef USE_WORKER_THREADS
|
|
||||||
LOCK(&task->lock);
|
|
||||||
- push_readyq(manager, task);
|
|
||||||
+ push_readyq(manager, task, qid);
|
|
||||||
UNLOCK(&task->lock);
|
|
||||||
#else
|
|
||||||
ENQUEUE(new_ready_tasks, task, ready_link);
|
|
||||||
@@ -1297,10 +1305,14 @@ dispatch(isc__taskmgr_t *manager) {
|
|
||||||
* we're stuck. Automatically drop privileges at that
|
|
||||||
* point and continue with the regular ready queue.
|
|
||||||
*/
|
|
||||||
- if (manager->tasks_running == 0 && empty_readyq(manager)) {
|
|
||||||
+ if (manager->tasks_running == 0 && empty_readyq(manager, isc_taskqueue_normal) && empty_readyq(manager, isc_taskqueue_slow)) {
|
|
||||||
manager->mode = isc_taskmgrmode_normal;
|
|
||||||
- if (!empty_readyq(manager))
|
|
||||||
- BROADCAST(&manager->work_available);
|
|
||||||
+ if (!empty_readyq(manager, isc_taskqueue_normal)) {
|
|
||||||
+ BROADCAST(&manager->work_available[isc_taskqueue_normal]);
|
|
||||||
+ }
|
|
||||||
+ if (!empty_readyq(manager, isc_taskqueue_slow)) {
|
|
||||||
+ BROADCAST(&manager->work_available[isc_taskqueue_slow]);
|
|
||||||
+ }
|
|
||||||
}
|
|
||||||
#endif
|
|
||||||
}
|
|
||||||
@@ -1322,13 +1334,37 @@ static isc_threadresult_t
|
|
||||||
#ifdef _WIN32
|
|
||||||
WINAPI
|
|
||||||
#endif
|
|
||||||
-run(void *uap) {
|
|
||||||
+run_normal(void *uap) {
|
|
||||||
isc__taskmgr_t *manager = uap;
|
|
||||||
|
|
||||||
XTHREADTRACE(isc_msgcat_get(isc_msgcat, ISC_MSGSET_GENERAL,
|
|
||||||
ISC_MSG_STARTING, "starting"));
|
|
||||||
|
|
||||||
- dispatch(manager);
|
|
||||||
+ dispatch(manager, isc_taskqueue_normal);
|
|
||||||
+
|
|
||||||
+ XTHREADTRACE(isc_msgcat_get(isc_msgcat, ISC_MSGSET_GENERAL,
|
|
||||||
+ ISC_MSG_EXITING, "exiting"));
|
|
||||||
+
|
|
||||||
+#ifdef OPENSSL_LEAKS
|
|
||||||
+ ERR_remove_state(0);
|
|
||||||
+#endif
|
|
||||||
+
|
|
||||||
+ return ((isc_threadresult_t)0);
|
|
||||||
+}
|
|
||||||
+#endif /* USE_WORKER_THREADS */
|
|
||||||
+
|
|
||||||
+#ifdef USE_WORKER_THREADS
|
|
||||||
+static isc_threadresult_t
|
|
||||||
+#ifdef _WIN32
|
|
||||||
+WINAPI
|
|
||||||
+#endif
|
|
||||||
+run_slow(void *uap) {
|
|
||||||
+ isc__taskmgr_t *manager = uap;
|
|
||||||
+
|
|
||||||
+ XTHREADTRACE(isc_msgcat_get(isc_msgcat, ISC_MSGSET_GENERAL,
|
|
||||||
+ ISC_MSG_STARTING, "starting"));
|
|
||||||
+
|
|
||||||
+ dispatch(manager, isc_taskqueue_slow);
|
|
||||||
|
|
||||||
XTHREADTRACE(isc_msgcat_get(isc_msgcat, ISC_MSGSET_GENERAL,
|
|
||||||
ISC_MSG_EXITING, "exiting"));
|
|
||||||
@@ -1347,7 +1383,8 @@ manager_free(isc__taskmgr_t *manager) {
|
|
||||||
|
|
||||||
#ifdef USE_WORKER_THREADS
|
|
||||||
(void)isc_condition_destroy(&manager->exclusive_granted);
|
|
||||||
- (void)isc_condition_destroy(&manager->work_available);
|
|
||||||
+ (void)isc_condition_destroy(&manager->work_available[isc_taskqueue_normal]);
|
|
||||||
+ (void)isc_condition_destroy(&manager->work_available[isc_taskqueue_slow]);
|
|
||||||
(void)isc_condition_destroy(&manager->paused);
|
|
||||||
isc_mem_free(manager->mctx, manager->threads);
|
|
||||||
#endif /* USE_WORKER_THREADS */
|
|
||||||
@@ -1414,12 +1451,20 @@ isc__taskmgr_create(isc_mem_t *mctx, unsigned int workers,
|
|
||||||
#ifdef USE_WORKER_THREADS
|
|
||||||
manager->workers = 0;
|
|
||||||
manager->threads = isc_mem_allocate(mctx,
|
|
||||||
- workers * sizeof(isc_thread_t));
|
|
||||||
+ 2 * workers * sizeof(isc_thread_t));
|
|
||||||
if (manager->threads == NULL) {
|
|
||||||
result = ISC_R_NOMEMORY;
|
|
||||||
goto cleanup_lock;
|
|
||||||
}
|
|
||||||
- if (isc_condition_init(&manager->work_available) != ISC_R_SUCCESS) {
|
|
||||||
+ if (isc_condition_init(&manager->work_available[isc_taskqueue_normal]) != ISC_R_SUCCESS) {
|
|
||||||
+ UNEXPECTED_ERROR(__FILE__, __LINE__,
|
|
||||||
+ "isc_condition_init() %s",
|
|
||||||
+ isc_msgcat_get(isc_msgcat, ISC_MSGSET_GENERAL,
|
|
||||||
+ ISC_MSG_FAILED, "failed"));
|
|
||||||
+ result = ISC_R_UNEXPECTED;
|
|
||||||
+ goto cleanup_threads;
|
|
||||||
+ }
|
|
||||||
+ if (isc_condition_init(&manager->work_available[isc_taskqueue_slow]) != ISC_R_SUCCESS) {
|
|
||||||
UNEXPECTED_ERROR(__FILE__, __LINE__,
|
|
||||||
"isc_condition_init() %s",
|
|
||||||
isc_msgcat_get(isc_msgcat, ISC_MSGSET_GENERAL,
|
|
||||||
@@ -1448,8 +1493,10 @@ isc__taskmgr_create(isc_mem_t *mctx, unsigned int workers,
|
|
||||||
default_quantum = DEFAULT_DEFAULT_QUANTUM;
|
|
||||||
manager->default_quantum = default_quantum;
|
|
||||||
INIT_LIST(manager->tasks);
|
|
||||||
- INIT_LIST(manager->ready_tasks);
|
|
||||||
- INIT_LIST(manager->ready_priority_tasks);
|
|
||||||
+ INIT_LIST(manager->ready_tasks[isc_taskqueue_normal]);
|
|
||||||
+ INIT_LIST(manager->ready_tasks[isc_taskqueue_slow]);
|
|
||||||
+ INIT_LIST(manager->ready_priority_tasks[isc_taskqueue_normal]);
|
|
||||||
+ INIT_LIST(manager->ready_priority_tasks[isc_taskqueue_slow]);
|
|
||||||
manager->tasks_running = 0;
|
|
||||||
manager->tasks_ready = 0;
|
|
||||||
manager->exclusive_requested = false;
|
|
||||||
@@ -1465,7 +1512,19 @@ isc__taskmgr_create(isc_mem_t *mctx, unsigned int workers,
|
|
||||||
* Start workers.
|
|
||||||
*/
|
|
||||||
for (i = 0; i < workers; i++) {
|
|
||||||
- if (isc_thread_create(run, manager,
|
|
||||||
+ if (isc_thread_create(run_normal, manager,
|
|
||||||
+ &manager->threads[manager->workers]) ==
|
|
||||||
+ ISC_R_SUCCESS) {
|
|
||||||
+ char name[21]; /* thread name limit on Linux */
|
|
||||||
+ snprintf(name, sizeof(name), "isc-worker%04u", i);
|
|
||||||
+ isc_thread_setname(manager->threads[manager->workers],
|
|
||||||
+ name);
|
|
||||||
+ manager->workers++;
|
|
||||||
+ started++;
|
|
||||||
+ }
|
|
||||||
+ }
|
|
||||||
+ for (; i < workers * 2; i++) {
|
|
||||||
+ if (isc_thread_create(run_slow, manager,
|
|
||||||
&manager->threads[manager->workers]) ==
|
|
||||||
ISC_R_SUCCESS) {
|
|
||||||
char name[21]; /* thread name limit on Linux */
|
|
||||||
@@ -1482,7 +1541,7 @@ isc__taskmgr_create(isc_mem_t *mctx, unsigned int workers,
|
|
||||||
manager_free(manager);
|
|
||||||
return (ISC_R_NOTHREADS);
|
|
||||||
}
|
|
||||||
- isc_thread_setconcurrency(workers);
|
|
||||||
+ isc_thread_setconcurrency(workers * 2);
|
|
||||||
#endif /* USE_WORKER_THREADS */
|
|
||||||
#ifdef USE_SHARED_MANAGER
|
|
||||||
manager->refs = 1;
|
|
||||||
@@ -1497,7 +1556,8 @@ isc__taskmgr_create(isc_mem_t *mctx, unsigned int workers,
|
|
||||||
cleanup_exclusivegranted:
|
|
||||||
(void)isc_condition_destroy(&manager->exclusive_granted);
|
|
||||||
cleanup_workavailable:
|
|
||||||
- (void)isc_condition_destroy(&manager->work_available);
|
|
||||||
+ (void)isc_condition_destroy(&manager->work_available[isc_taskqueue_slow]);
|
|
||||||
+ (void)isc_condition_destroy(&manager->work_available[isc_taskqueue_normal]);
|
|
||||||
cleanup_threads:
|
|
||||||
isc_mem_free(mctx, manager->threads);
|
|
||||||
cleanup_lock:
|
|
||||||
@@ -1582,7 +1642,7 @@ isc__taskmgr_destroy(isc_taskmgr_t **managerp) {
|
|
||||||
task = NEXT(task, link)) {
|
|
||||||
LOCK(&task->lock);
|
|
||||||
if (task_shutdown(task))
|
|
||||||
- push_readyq(manager, task);
|
|
||||||
+ push_readyq(manager, task, task->qid);
|
|
||||||
UNLOCK(&task->lock);
|
|
||||||
}
|
|
||||||
#ifdef USE_WORKER_THREADS
|
|
||||||
@@ -1591,7 +1651,8 @@ isc__taskmgr_destroy(isc_taskmgr_t **managerp) {
|
|
||||||
* there's work left to do, and if there are already no tasks left
|
|
||||||
* it will cause the workers to see manager->exiting.
|
|
||||||
*/
|
|
||||||
- BROADCAST(&manager->work_available);
|
|
||||||
+ BROADCAST(&manager->work_available[isc_taskqueue_normal]);
|
|
||||||
+ BROADCAST(&manager->work_available[isc_taskqueue_slow]);
|
|
||||||
UNLOCK(&manager->lock);
|
|
||||||
|
|
||||||
/*
|
|
||||||
@@ -1693,7 +1754,8 @@ isc__taskmgr_resume(isc_taskmgr_t *manager0) {
|
|
||||||
LOCK(&manager->lock);
|
|
||||||
if (manager->pause_requested) {
|
|
||||||
manager->pause_requested = false;
|
|
||||||
- BROADCAST(&manager->work_available);
|
|
||||||
+ BROADCAST(&manager->work_available[isc_taskqueue_normal]);
|
|
||||||
+ BROADCAST(&manager->work_available[isc_taskqueue_slow]);
|
|
||||||
}
|
|
||||||
UNLOCK(&manager->lock);
|
|
||||||
}
|
|
||||||
@@ -1778,7 +1840,8 @@ isc__task_endexclusive(isc_task_t *task0) {
|
|
||||||
LOCK(&manager->lock);
|
|
||||||
REQUIRE(manager->exclusive_requested);
|
|
||||||
manager->exclusive_requested = false;
|
|
||||||
- BROADCAST(&manager->work_available);
|
|
||||||
+ BROADCAST(&manager->work_available[isc_taskqueue_normal]);
|
|
||||||
+ BROADCAST(&manager->work_available[isc_taskqueue_slow]);
|
|
||||||
UNLOCK(&manager->lock);
|
|
||||||
#else
|
|
||||||
UNUSED(task0);
|
|
||||||
@@ -1804,10 +1867,10 @@ isc__task_setprivilege(isc_task_t *task0, bool priv) {
|
|
||||||
|
|
||||||
LOCK(&manager->lock);
|
|
||||||
if (priv && ISC_LINK_LINKED(task, ready_link))
|
|
||||||
- ENQUEUE(manager->ready_priority_tasks, task,
|
|
||||||
+ ENQUEUE(manager->ready_priority_tasks[task->qid], task,
|
|
||||||
ready_priority_link);
|
|
||||||
else if (!priv && ISC_LINK_LINKED(task, ready_priority_link))
|
|
||||||
- DEQUEUE(manager->ready_priority_tasks, task,
|
|
||||||
+ DEQUEUE(manager->ready_priority_tasks[task->qid], task,
|
|
||||||
ready_priority_link);
|
|
||||||
UNLOCK(&manager->lock);
|
|
||||||
}
|
|
||||||
--
|
|
||||||
2.43.2
|
|
||||||
|
|
||||||
@ -1,133 +0,0 @@
|
|||||||
From 0a7909045f9e1bf74c1f0fd561a8ef5f55481e8f Mon Sep 17 00:00:00 2001
|
|
||||||
From: Petr Mensik <pemensik@redhat.com>
|
|
||||||
Date: Mon, 29 Jul 2024 16:20:50 +0200
|
|
||||||
Subject: [PATCH] Allow global runtime definition by DNS_RBTDB_MAX_RTYPES
|
|
||||||
|
|
||||||
Modify rbtdb to not set it only at runtime, but allow setting that also
|
|
||||||
in runtime via environment variable. It is still possible to modify
|
|
||||||
default during the build define. In addition to it allows runtime change
|
|
||||||
also. Can be positive number to set limit, 0 disabled the check.
|
|
||||||
|
|
||||||
Similarly add also DNS_RDATASET_MAX_RECORDS to set maximum number of
|
|
||||||
records for a single name. This must be positive number, 0 is no accepted.
|
|
||||||
|
|
||||||
These replaces max-records-per-type and max-types-per-name in later
|
|
||||||
versions. But can be configured only by environment and can be
|
|
||||||
configured only globally, not in each view or zone.
|
|
||||||
---
|
|
||||||
lib/dns/rbtdb.c | 21 +++++++++++++++++++--
|
|
||||||
lib/dns/rdataslab.c | 24 ++++++++++++++++++++++--
|
|
||||||
2 files changed, 41 insertions(+), 4 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/lib/dns/rbtdb.c b/lib/dns/rbtdb.c
|
|
||||||
index a3cb8dc871..0104c3ee36 100644
|
|
||||||
--- a/lib/dns/rbtdb.c
|
|
||||||
+++ b/lib/dns/rbtdb.c
|
|
||||||
@@ -6320,15 +6320,29 @@ update_recordsandbytes(bool add, rbtdb_version_t *rbtversion,
|
|
||||||
#define DNS_RBTDB_MAX_RTYPES 100
|
|
||||||
#endif /* DNS_RBTDB_MAX_RTYPES */
|
|
||||||
|
|
||||||
+static uint32_t dns_g_rbtdb_max_rtypes = DNS_RBTDB_MAX_RTYPES;
|
|
||||||
+
|
|
||||||
+static void
|
|
||||||
+init_max_rtypes(void) {
|
|
||||||
+ /* Red Hat change, allow setting different max value by environment. */
|
|
||||||
+ const char *max = getenv("DNS_RBTDB_MAX_RTYPES");
|
|
||||||
+ if (max) {
|
|
||||||
+ char *endp = NULL;
|
|
||||||
+ long l = strtol(max, &endp, 10);
|
|
||||||
+ if (max != endp && endp && !*endp && l >= 0)
|
|
||||||
+ dns_g_rbtdb_max_rtypes = l;
|
|
||||||
+ }
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
static bool
|
|
||||||
overmaxtype(dns_rbtdb_t *rbtdb, uint32_t ntypes) {
|
|
||||||
UNUSED(rbtdb);
|
|
||||||
|
|
||||||
- if (DNS_RBTDB_MAX_RTYPES == 0) {
|
|
||||||
+ if (dns_g_rbtdb_max_rtypes == 0) {
|
|
||||||
return (false);
|
|
||||||
}
|
|
||||||
|
|
||||||
- return (ntypes >= DNS_RBTDB_MAX_RTYPES);
|
|
||||||
+ return (ntypes >= dns_g_rbtdb_max_rtypes);
|
|
||||||
}
|
|
||||||
|
|
||||||
static bool
|
|
||||||
@@ -8831,6 +8845,8 @@ static dns_dbmethods_t cache_methods = {
|
|
||||||
getservestalettl
|
|
||||||
};
|
|
||||||
|
|
||||||
+static isc_once_t once_db = ISC_ONCE_INIT;
|
|
||||||
+
|
|
||||||
isc_result_t
|
|
||||||
#ifdef DNS_RBTDB_VERSION64
|
|
||||||
dns_rbtdb64_create
|
|
||||||
@@ -8850,6 +8866,7 @@ dns_rbtdb_create
|
|
||||||
|
|
||||||
/* Keep the compiler happy. */
|
|
||||||
UNUSED(driverarg);
|
|
||||||
+ RUNTIME_CHECK(isc_once_do(&once_db, init_max_rtypes) == ISC_R_SUCCESS);
|
|
||||||
|
|
||||||
rbtdb = isc_mem_get(mctx, sizeof(*rbtdb));
|
|
||||||
if (rbtdb == NULL)
|
|
||||||
diff --git a/lib/dns/rdataslab.c b/lib/dns/rdataslab.c
|
|
||||||
index 347b7d2ce8..9566f79671 100644
|
|
||||||
--- a/lib/dns/rdataslab.c
|
|
||||||
+++ b/lib/dns/rdataslab.c
|
|
||||||
@@ -17,6 +17,7 @@
|
|
||||||
#include <stdlib.h>
|
|
||||||
|
|
||||||
#include <isc/mem.h>
|
|
||||||
+#include <isc/once.h>
|
|
||||||
#include <isc/region.h>
|
|
||||||
#include <isc/string.h> /* Required for HP/UX (and others?) */
|
|
||||||
#include <isc/util.h>
|
|
||||||
@@ -119,6 +120,23 @@ fillin_offsets(unsigned char *offsetbase, unsigned int *offsettable,
|
|
||||||
#define DNS_RDATASET_MAX_RECORDS 100
|
|
||||||
#endif /* DNS_RDATASET_MAX_RECORDS */
|
|
||||||
|
|
||||||
+static unsigned int dns_g_rdataset_max_records = DNS_RDATASET_MAX_RECORDS;
|
|
||||||
+static isc_once_t once = ISC_ONCE_INIT;
|
|
||||||
+
|
|
||||||
+static void
|
|
||||||
+init_max_records(void) {
|
|
||||||
+ /* Red Hat change, allow setting different max value by environment. */
|
|
||||||
+ const char *max = getenv("DNS_RDATASET_MAX_RECORDS");
|
|
||||||
+ if (max) {
|
|
||||||
+ char *endp = NULL;
|
|
||||||
+ long l = strtol(max, &endp, 10);
|
|
||||||
+ if (max != endp && endp && !*endp && l > 0)
|
|
||||||
+ dns_g_rdataset_max_records = l;
|
|
||||||
+ }
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+
|
|
||||||
isc_result_t
|
|
||||||
dns_rdataslab_fromrdataset(dns_rdataset_t *rdataset, isc_mem_t *mctx,
|
|
||||||
isc_region_t *region, unsigned int reservelen)
|
|
||||||
@@ -165,7 +183,9 @@ dns_rdataslab_fromrdataset(dns_rdataset_t *rdataset, isc_mem_t *mctx,
|
|
||||||
return (ISC_R_SUCCESS);
|
|
||||||
}
|
|
||||||
|
|
||||||
- if (nitems > DNS_RDATASET_MAX_RECORDS) {
|
|
||||||
+ RUNTIME_CHECK(isc_once_do(&once, init_max_records) == ISC_R_SUCCESS);
|
|
||||||
+
|
|
||||||
+ if (nitems > dns_g_rdataset_max_records) {
|
|
||||||
return (DNS_R_TOOMANYRECORDS);
|
|
||||||
}
|
|
||||||
|
|
||||||
@@ -662,7 +682,7 @@ dns_rdataslab_merge(unsigned char *oslab, unsigned char *nslab,
|
|
||||||
#endif
|
|
||||||
INSIST(ocount > 0 && ncount > 0);
|
|
||||||
|
|
||||||
- if (ocount + ncount > DNS_RDATASET_MAX_RECORDS) {
|
|
||||||
+ if (ocount + ncount > dns_g_rdataset_max_records) {
|
|
||||||
return (DNS_R_TOOMANYRECORDS);
|
|
||||||
}
|
|
||||||
|
|
||||||
--
|
|
||||||
2.45.2
|
|
||||||
|
|
||||||
File diff suppressed because it is too large
Load Diff
@ -1,61 +0,0 @@
|
|||||||
From 83f283c3aeae99570c9e4c20f10e92ba565fc4be Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
|
||||||
Date: Tue, 7 Oct 2025 16:18:03 +0200
|
|
||||||
Subject: [PATCH] Implement settings limits also in named-checkconf
|
|
||||||
|
|
||||||
Read and parse max-records-per-type and max-types-per-name options in
|
|
||||||
case -z parameter is passed.
|
|
||||||
---
|
|
||||||
bin/check/named-checkconf.c | 27 +++++++++++++++++++++++++--
|
|
||||||
1 file changed, 25 insertions(+), 2 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/bin/check/named-checkconf.c b/bin/check/named-checkconf.c
|
|
||||||
index e5afd52..42ef76c 100644
|
|
||||||
--- a/bin/check/named-checkconf.c
|
|
||||||
+++ b/bin/check/named-checkconf.c
|
|
||||||
@@ -415,6 +415,24 @@ configure_zone(const char *vclass, const char *view,
|
|
||||||
return (result);
|
|
||||||
}
|
|
||||||
|
|
||||||
+/* Red Hat 9.11 specific extension. */
|
|
||||||
+static void
|
|
||||||
+configure_maxrecords(const cfg_obj_t *voptions)
|
|
||||||
+{
|
|
||||||
+ cfg_obj_t *obj;
|
|
||||||
+ isc_result_t result;
|
|
||||||
+
|
|
||||||
+ obj = NULL;
|
|
||||||
+ result = cfg_map_get(voptions, "max-records-per-type", &obj);
|
|
||||||
+ if (result == ISC_R_SUCCESS)
|
|
||||||
+ dns_db_setmaxrrperset(cfg_obj_asuint32(obj));
|
|
||||||
+
|
|
||||||
+ obj = NULL;
|
|
||||||
+ result = cfg_map_get(voptions, "max-types-per-name", &obj);
|
|
||||||
+ if (result == ISC_R_SUCCESS)
|
|
||||||
+ dns_db_setmaxtypepername(cfg_obj_asuint32(obj));
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
/*% configure a view */
|
|
||||||
static isc_result_t
|
|
||||||
configure_view(const char *vclass, const char *view, const cfg_obj_t *config,
|
|
||||||
@@ -431,10 +449,15 @@ configure_view(const char *vclass, const char *view, const cfg_obj_t *config,
|
|
||||||
voptions = cfg_tuple_get(vconfig, "options");
|
|
||||||
|
|
||||||
zonelist = NULL;
|
|
||||||
- if (voptions != NULL)
|
|
||||||
+ if (voptions != NULL) {
|
|
||||||
(void)cfg_map_get(voptions, "zone", &zonelist);
|
|
||||||
- else
|
|
||||||
+ configure_maxrecords(voptions);
|
|
||||||
+ } else {
|
|
||||||
(void)cfg_map_get(config, "zone", &zonelist);
|
|
||||||
+ tresult = cfg_map_get(config, "options", &voptions);
|
|
||||||
+ if (tresult == ISC_R_SUCCESS)
|
|
||||||
+ configure_maxrecords(voptions);
|
|
||||||
+ }
|
|
||||||
|
|
||||||
for (element = cfg_list_first(zonelist);
|
|
||||||
element != NULL;
|
|
||||||
--
|
|
||||||
2.51.0
|
|
||||||
|
|
||||||
@ -1,250 +0,0 @@
|
|||||||
From e0238189d03dc0a6b6092180ba52e74a26816422 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Petr Mensik <pemensik@redhat.com>
|
|
||||||
Date: Thu, 10 Jul 2025 17:31:35 +0200
|
|
||||||
Subject: [PATCH] Minimalistic support for max-records-per-type option
|
|
||||||
|
|
||||||
Just propagate the number to rbtdb in addition to environment. Make
|
|
||||||
environment preferred of both used, because default configuration value
|
|
||||||
would override already changed default.
|
|
||||||
|
|
||||||
Allow also 0 value from the environment.
|
|
||||||
---
|
|
||||||
bin/named/config.c | 1 +
|
|
||||||
bin/named/named.conf.docbook | 1 +
|
|
||||||
bin/named/server.c | 9 +++++++++
|
|
||||||
doc/arm/Bv9ARM-book.xml | 18 ++++++++++++++++++
|
|
||||||
lib/dns/db.c | 6 +++++-
|
|
||||||
lib/dns/include/dns/db.h | 10 ++++++++++
|
|
||||||
lib/dns/include/dns/rdataslab.h | 6 ++++++
|
|
||||||
lib/dns/rbtdb.c | 18 +++++++++++++++++-
|
|
||||||
lib/dns/rbtdb.h | 10 ++++++++++
|
|
||||||
lib/dns/rbtdb64.h | 3 +++
|
|
||||||
lib/isccfg/namedconf.c | 1 +
|
|
||||||
11 files changed, 81 insertions(+), 2 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/bin/named/config.c b/bin/named/config.c
|
|
||||||
index e3731cf..27cf9ee 100644
|
|
||||||
--- a/bin/named/config.c
|
|
||||||
+++ b/bin/named/config.c
|
|
||||||
@@ -243,6 +243,7 @@ options {\n\
|
|
||||||
# max-ixfr-log-size <obsolete>\n\
|
|
||||||
max-journal-size unlimited;\n\
|
|
||||||
max-records 0;\n\
|
|
||||||
+ max-records-per-type 100;\n\
|
|
||||||
max-refresh-time 2419200; /* 4 weeks */\n\
|
|
||||||
max-retry-time 1209600; /* 2 weeks */\n\
|
|
||||||
max-transfer-idle-in 60;\n\
|
|
||||||
diff --git a/bin/named/named.conf.docbook b/bin/named/named.conf.docbook
|
|
||||||
index 31fac33..d7934c7 100644
|
|
||||||
--- a/bin/named/named.conf.docbook
|
|
||||||
+++ b/bin/named/named.conf.docbook
|
|
||||||
@@ -338,6 +338,7 @@ options {
|
|
||||||
max-journal-size ( unlimited | <replaceable>sizeval</replaceable> );
|
|
||||||
max-ncache-ttl <replaceable>integer</replaceable>;
|
|
||||||
max-records <replaceable>integer</replaceable>;
|
|
||||||
+ max-records-per-type <replaceable>integer</replaceable>;
|
|
||||||
max-recursion-depth <replaceable>integer</replaceable>;
|
|
||||||
max-recursion-queries <replaceable>integer</replaceable>;
|
|
||||||
max-refresh-time <replaceable>integer</replaceable>;
|
|
||||||
diff --git a/bin/named/server.c b/bin/named/server.c
|
|
||||||
index afdc4fa..2e88df7 100644
|
|
||||||
--- a/bin/named/server.c
|
|
||||||
+++ b/bin/named/server.c
|
|
||||||
@@ -4606,6 +4606,15 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
|
||||||
cfg_obj_asuint32(obj),
|
|
||||||
max_clients_per_query);
|
|
||||||
|
|
||||||
+ /*
|
|
||||||
+ * This is used for the cache and also as a default value
|
|
||||||
+ * for zone databases.
|
|
||||||
+ */
|
|
||||||
+ obj = NULL;
|
|
||||||
+ result = ns_config_get(maps, "max-records-per-type", &obj);
|
|
||||||
+ INSIST(result == ISC_R_SUCCESS);
|
|
||||||
+ dns_db_setmaxrrperset(cfg_obj_asuint32(obj));
|
|
||||||
+
|
|
||||||
obj = NULL;
|
|
||||||
result = ns_config_get(maps, "max-recursion-depth", &obj);
|
|
||||||
INSIST(result == ISC_R_SUCCESS);
|
|
||||||
diff --git a/doc/arm/Bv9ARM-book.xml b/doc/arm/Bv9ARM-book.xml
|
|
||||||
index 563dced..25acad0 100644
|
|
||||||
--- a/doc/arm/Bv9ARM-book.xml
|
|
||||||
+++ b/doc/arm/Bv9ARM-book.xml
|
|
||||||
@@ -8318,6 +8318,24 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
|
|
||||||
</listitem>
|
|
||||||
</varlistentry>
|
|
||||||
|
|
||||||
+ <varlistentry>
|
|
||||||
+ <term><command>max-records-per-type</command></term>
|
|
||||||
+ <listitem>
|
|
||||||
+ <para>
|
|
||||||
+ This sets the maximum number of resource records that can be stored
|
|
||||||
+ in an RRset in a database. Can be configured in <option>options</option>,
|
|
||||||
+ only.
|
|
||||||
+ </para>
|
|
||||||
+
|
|
||||||
+ <para>
|
|
||||||
+ If set to a positive value, any attempt to cache or to add to a zone
|
|
||||||
+ an RRset with more than the specified number of records will result in
|
|
||||||
+ a failure. If set to 0, there is no cap on RRset size. The default is
|
|
||||||
+ <literal>100</literal>.
|
|
||||||
+ </para>
|
|
||||||
+ </listitem>
|
|
||||||
+ </varlistentry>
|
|
||||||
+
|
|
||||||
<varlistentry>
|
|
||||||
<term><command>recursive-clients</command></term>
|
|
||||||
<listitem>
|
|
||||||
diff --git a/lib/dns/db.c b/lib/dns/db.c
|
|
||||||
index c581646..9e7632a 100644
|
|
||||||
--- a/lib/dns/db.c
|
|
||||||
+++ b/lib/dns/db.c
|
|
||||||
@@ -1130,7 +1130,6 @@ dns_db_nodefullname(dns_db_t *db, dns_dbnode_t *node, dns_name_t *name) {
|
|
||||||
return (ISC_R_NOTIMPLEMENTED);
|
|
||||||
return ((db->methods->nodefullname)(db, node, name));
|
|
||||||
}
|
|
||||||
-
|
|
||||||
isc_result_t
|
|
||||||
dns_db_setservestalettl(dns_db_t *db, dns_ttl_t ttl)
|
|
||||||
{
|
|
||||||
@@ -1152,3 +1151,8 @@ dns_db_getservestalettl(dns_db_t *db, dns_ttl_t *ttl)
|
|
||||||
return ((db->methods->getservestalettl)(db, ttl));
|
|
||||||
return (ISC_R_NOTIMPLEMENTED);
|
|
||||||
}
|
|
||||||
+void
|
|
||||||
+dns_db_setmaxrrperset(uint32_t maxrrperset) {
|
|
||||||
+ dns_rbtdb_setmaxrrperset(maxrrperset);
|
|
||||||
+ dns_rbtdb64_setmaxrrperset(maxrrperset);
|
|
||||||
+}
|
|
||||||
diff --git a/lib/dns/include/dns/db.h b/lib/dns/include/dns/db.h
|
|
||||||
index 452770f..6357bfd 100644
|
|
||||||
--- a/lib/dns/include/dns/db.h
|
|
||||||
+++ b/lib/dns/include/dns/db.h
|
|
||||||
@@ -1718,6 +1718,16 @@ dns_db_getservestalettl(dns_db_t *db, dns_ttl_t *ttl);
|
|
||||||
* \li #ISC_R_NOTIMPLEMENTED - Not supported by this DB implementation.
|
|
||||||
*/
|
|
||||||
|
|
||||||
+void
|
|
||||||
+dns_db_setmaxrrperset(uint32_t maxrrperset);
|
|
||||||
+/*%<
|
|
||||||
+ * Sets the maximum number of records per rrset permitted in a database.
|
|
||||||
+ * 0 implies unlimited.
|
|
||||||
+ *
|
|
||||||
+ * Returns:
|
|
||||||
+ *\li void
|
|
||||||
+ */
|
|
||||||
+
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
|
|
||||||
#endif /* DNS_DB_H */
|
|
||||||
diff --git a/lib/dns/include/dns/rdataslab.h b/lib/dns/include/dns/rdataslab.h
|
|
||||||
index f38d539..40c40a8 100644
|
|
||||||
--- a/lib/dns/include/dns/rdataslab.h
|
|
||||||
+++ b/lib/dns/include/dns/rdataslab.h
|
|
||||||
@@ -173,6 +173,12 @@ dns_rdataslab_equalx(unsigned char *slab1, unsigned char *slab2,
|
|
||||||
*\li true if the slabs are equal, #false otherwise.
|
|
||||||
*/
|
|
||||||
|
|
||||||
+void
|
|
||||||
+dns_rdataslab_setmaxrrperset(uint32_t maxrrperset);
|
|
||||||
+/*%<
|
|
||||||
+ * Set global limit of max-records-per-type value.
|
|
||||||
+ */
|
|
||||||
+
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
|
|
||||||
#endif /* DNS_RDATASLAB_H */
|
|
||||||
diff --git a/lib/dns/rbtdb.c b/lib/dns/rbtdb.c
|
|
||||||
index 5263e7c..388ffdf 100644
|
|
||||||
--- a/lib/dns/rbtdb.c
|
|
||||||
+++ b/lib/dns/rbtdb.c
|
|
||||||
@@ -981,6 +981,7 @@ static bool match_header_version(rbtdb_file_header_t *header);
|
|
||||||
/* Pad to 32 bytes */
|
|
||||||
static char FILE_VERSION[32] = "\0";
|
|
||||||
|
|
||||||
+
|
|
||||||
/*%
|
|
||||||
* 'init_count' is used to initialize 'newheader->count' which inturn
|
|
||||||
* is used to determine where in the cycle rrset-order cyclic starts.
|
|
||||||
@@ -6321,6 +6322,19 @@ update_recordsandbytes(bool add, rbtdb_version_t *rbtversion,
|
|
||||||
#endif /* DNS_RBTDB_MAX_RTYPES */
|
|
||||||
|
|
||||||
static uint32_t dns_g_rbtdb_max_rtypes = DNS_RBTDB_MAX_RTYPES;
|
|
||||||
+static bool dns_g_rbtdb_max_rtypes_fromenv = false;
|
|
||||||
+void
|
|
||||||
+#ifdef DNS_RBTDB_VERSION64
|
|
||||||
+dns_rbtdb64_setmaxtypepername(uint32_t maxrrperset)
|
|
||||||
+#else
|
|
||||||
+dns_rbtdb_setmaxtypepername(uint32_t maxrrperset)
|
|
||||||
+#endif
|
|
||||||
+{
|
|
||||||
+ if (!dns_g_rbtdb_max_rtypes_fromenv) {
|
|
||||||
+ /* Make environment override configuration to avoid resetting to default value. */
|
|
||||||
+ dns_g_rbtdb_max_rtypes = maxrrperset;
|
|
||||||
+ }
|
|
||||||
+}
|
|
||||||
|
|
||||||
static void
|
|
||||||
init_max_rtypes(void) {
|
|
||||||
@@ -6329,8 +6343,10 @@ init_max_rtypes(void) {
|
|
||||||
if (max) {
|
|
||||||
char *endp = NULL;
|
|
||||||
long l = strtol(max, &endp, 10);
|
|
||||||
- if (max != endp && endp && !*endp && l >= 0)
|
|
||||||
+ if (max != endp && endp && !*endp) {
|
|
||||||
dns_g_rbtdb_max_rtypes = l;
|
|
||||||
+ dns_g_rbtdb_max_rtypes_fromenv = true;
|
|
||||||
+ }
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
diff --git a/lib/dns/rbtdb.h b/lib/dns/rbtdb.h
|
|
||||||
index cd84b5b..4f2d890 100644
|
|
||||||
--- a/lib/dns/rbtdb.h
|
|
||||||
+++ b/lib/dns/rbtdb.h
|
|
||||||
@@ -45,6 +45,16 @@ dns_rbtdb_create(isc_mem_t *mctx, dns_name_t *base, dns_dbtype_t type,
|
|
||||||
* \li argc == 0 or argv[0] is a valid memory context.
|
|
||||||
*/
|
|
||||||
|
|
||||||
+void
|
|
||||||
+dns_rbtdb_setmaxtypepername(uint32_t value);
|
|
||||||
+/*%<
|
|
||||||
+ * Set the maximum permissible number of RR types per owner name.
|
|
||||||
+ * 0 implies unlimited.
|
|
||||||
+ *
|
|
||||||
+ * Returns:
|
|
||||||
+ *\li void
|
|
||||||
+ */
|
|
||||||
+
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
|
|
||||||
#endif /* DNS_RBTDB_H */
|
|
||||||
diff --git a/lib/dns/rbtdb64.h b/lib/dns/rbtdb64.h
|
|
||||||
index 33b0115..77ae5b0 100644
|
|
||||||
--- a/lib/dns/rbtdb64.h
|
|
||||||
+++ b/lib/dns/rbtdb64.h
|
|
||||||
@@ -32,6 +32,9 @@ dns_rbtdb64_create(isc_mem_t *mctx, dns_name_t *base, dns_dbtype_t type,
|
|
||||||
dns_rdataclass_t rdclass, unsigned int argc, char *argv[],
|
|
||||||
void *driverarg, dns_db_t **dbp);
|
|
||||||
|
|
||||||
+void
|
|
||||||
+dns_rbtdb64_setmaxtypepername(uint32_t value);
|
|
||||||
+
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
|
|
||||||
#endif /* DNS_RBTDB64_H */
|
|
||||||
diff --git a/lib/isccfg/namedconf.c b/lib/isccfg/namedconf.c
|
|
||||||
index 667111c..fc46a64 100644
|
|
||||||
--- a/lib/isccfg/namedconf.c
|
|
||||||
+++ b/lib/isccfg/namedconf.c
|
|
||||||
@@ -1100,6 +1100,7 @@ options_clauses[] = {
|
|
||||||
{ "lock-file", &cfg_type_qstringornone, 0 },
|
|
||||||
{ "managed-keys-directory", &cfg_type_qstring, 0 },
|
|
||||||
{ "match-mapped-addresses", &cfg_type_boolean, 0 },
|
|
||||||
+ { "max-records-per-type", &cfg_type_uint32, 0 },
|
|
||||||
{ "max-rsa-exponent-size", &cfg_type_uint32, 0 },
|
|
||||||
{ "memstatistics", &cfg_type_boolean, 0 },
|
|
||||||
{ "memstatistics-file", &cfg_type_qstring, 0 },
|
|
||||||
--
|
|
||||||
2.50.0
|
|
||||||
|
|
||||||
@ -1,196 +0,0 @@
|
|||||||
From ba30ef9b8dbe3dacced19d80a8b27854a794b334 Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Ond=C5=99ej=20Sur=C3=BD?= <ondrej@isc.org>
|
|
||||||
Date: Sat, 25 May 2024 11:46:56 +0200
|
|
||||||
Subject: [PATCH] Minimalistic support for max-types-per-name option
|
|
||||||
|
|
||||||
Just add support for parsing of value from options to environment
|
|
||||||
settable number. Keep environment value preferred, overriding
|
|
||||||
configuration file value if present. Should avoid overriding environment
|
|
||||||
set value by just default config value.
|
|
||||||
|
|
||||||
Allow also value 0 from environment.
|
|
||||||
---
|
|
||||||
bin/named/config.c | 1 +
|
|
||||||
bin/named/named.conf.docbook | 1 +
|
|
||||||
bin/named/server.c | 9 +++++++++
|
|
||||||
doc/arm/Bv9ARM-book.xml | 19 +++++++++++++++++++
|
|
||||||
lib/dns/db.c | 12 ++++++++++--
|
|
||||||
lib/dns/include/dns/db.h | 9 +++++++++
|
|
||||||
lib/dns/rdataslab.c | 14 +++++++++++++-
|
|
||||||
lib/isccfg/namedconf.c | 1 +
|
|
||||||
8 files changed, 63 insertions(+), 3 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/bin/named/config.c b/bin/named/config.c
|
|
||||||
index 27cf9ee..c4d44ef 100644
|
|
||||||
--- a/bin/named/config.c
|
|
||||||
+++ b/bin/named/config.c
|
|
||||||
@@ -246,6 +246,7 @@ options {\n\
|
|
||||||
max-records-per-type 100;\n\
|
|
||||||
max-refresh-time 2419200; /* 4 weeks */\n\
|
|
||||||
max-retry-time 1209600; /* 2 weeks */\n\
|
|
||||||
+ max-types-per-name 100;\n\
|
|
||||||
max-transfer-idle-in 60;\n\
|
|
||||||
max-transfer-idle-out 60;\n\
|
|
||||||
max-transfer-time-in 120;\n\
|
|
||||||
diff --git a/bin/named/named.conf.docbook b/bin/named/named.conf.docbook
|
|
||||||
index d7934c7..a4b1d76 100644
|
|
||||||
--- a/bin/named/named.conf.docbook
|
|
||||||
+++ b/bin/named/named.conf.docbook
|
|
||||||
@@ -348,6 +348,7 @@ options {
|
|
||||||
max-transfer-idle-out <replaceable>integer</replaceable>;
|
|
||||||
max-transfer-time-in <replaceable>integer</replaceable>;
|
|
||||||
max-transfer-time-out <replaceable>integer</replaceable>;
|
|
||||||
+ max-types-per-name <replaceable>integer</replaceable>;
|
|
||||||
max-udp-size <replaceable>integer</replaceable>;
|
|
||||||
max-zone-ttl ( unlimited | <replaceable>ttlval</replaceable> );
|
|
||||||
memstatistics <replaceable>boolean</replaceable>;
|
|
||||||
diff --git a/bin/named/server.c b/bin/named/server.c
|
|
||||||
index 2e88df7..2086e41 100644
|
|
||||||
--- a/bin/named/server.c
|
|
||||||
+++ b/bin/named/server.c
|
|
||||||
@@ -4615,6 +4615,15 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
|
||||||
INSIST(result == ISC_R_SUCCESS);
|
|
||||||
dns_db_setmaxrrperset(cfg_obj_asuint32(obj));
|
|
||||||
|
|
||||||
+ /*
|
|
||||||
+ * This is used for the cache and also as a default value
|
|
||||||
+ * for zone databases.
|
|
||||||
+ */
|
|
||||||
+ obj = NULL;
|
|
||||||
+ result = ns_config_get(maps, "max-types-per-name", &obj);
|
|
||||||
+ INSIST(result == ISC_R_SUCCESS);
|
|
||||||
+ dns_db_setmaxtypepername(cfg_obj_asuint32(obj));
|
|
||||||
+
|
|
||||||
obj = NULL;
|
|
||||||
result = ns_config_get(maps, "max-recursion-depth", &obj);
|
|
||||||
INSIST(result == ISC_R_SUCCESS);
|
|
||||||
diff --git a/doc/arm/Bv9ARM-book.xml b/doc/arm/Bv9ARM-book.xml
|
|
||||||
index 25acad0..70fd769 100644
|
|
||||||
--- a/doc/arm/Bv9ARM-book.xml
|
|
||||||
+++ b/doc/arm/Bv9ARM-book.xml
|
|
||||||
@@ -8336,6 +8336,25 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
|
|
||||||
</listitem>
|
|
||||||
</varlistentry>
|
|
||||||
|
|
||||||
+ <varlistentry>
|
|
||||||
+ <term><command>max-types-per-name</command></term>
|
|
||||||
+ <listitem>
|
|
||||||
+ <para>
|
|
||||||
+ This sets the maximum number of resource record types that can be stored
|
|
||||||
+ for a single owner name in a database. Can be configured in <option>options</option>
|
|
||||||
+ only.
|
|
||||||
+ </para>
|
|
||||||
+
|
|
||||||
+ <para>
|
|
||||||
+ If set to a positive value, any attempt to cache or to add to a zone an owner
|
|
||||||
+ name with more than the specified number of resource record types will result
|
|
||||||
+ in a failure. If set to 0, there is no cap on RR types number. The default is
|
|
||||||
+ <literal>100</literal>.
|
|
||||||
+ </para>
|
|
||||||
+ </listitem>
|
|
||||||
+ </varlistentry>
|
|
||||||
+
|
|
||||||
+
|
|
||||||
<varlistentry>
|
|
||||||
<term><command>recursive-clients</command></term>
|
|
||||||
<listitem>
|
|
||||||
diff --git a/lib/dns/db.c b/lib/dns/db.c
|
|
||||||
index 9e7632a..b0f8960 100644
|
|
||||||
--- a/lib/dns/db.c
|
|
||||||
+++ b/lib/dns/db.c
|
|
||||||
@@ -35,6 +35,7 @@
|
|
||||||
#include <dns/master.h>
|
|
||||||
#include <dns/rdata.h>
|
|
||||||
#include <dns/rdataset.h>
|
|
||||||
+#include <dns/rdataslab.h>
|
|
||||||
#include <dns/rdatasetiter.h>
|
|
||||||
#include <dns/result.h>
|
|
||||||
|
|
||||||
@@ -1151,8 +1152,15 @@ dns_db_getservestalettl(dns_db_t *db, dns_ttl_t *ttl)
|
|
||||||
return ((db->methods->getservestalettl)(db, ttl));
|
|
||||||
return (ISC_R_NOTIMPLEMENTED);
|
|
||||||
}
|
|
||||||
+
|
|
||||||
+/* Emulation of more complex changes later. */
|
|
||||||
void
|
|
||||||
dns_db_setmaxrrperset(uint32_t maxrrperset) {
|
|
||||||
- dns_rbtdb_setmaxrrperset(maxrrperset);
|
|
||||||
- dns_rbtdb64_setmaxrrperset(maxrrperset);
|
|
||||||
+ dns_rdataslab_setmaxrrperset(maxrrperset);
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
+void
|
|
||||||
+dns_db_setmaxtypepername(uint32_t value) {
|
|
||||||
+ dns_rbtdb_setmaxtypepername(value);
|
|
||||||
+ dns_rbtdb64_setmaxtypepername(value);
|
|
||||||
}
|
|
||||||
diff --git a/lib/dns/include/dns/db.h b/lib/dns/include/dns/db.h
|
|
||||||
index 6357bfd..f6eae9b 100644
|
|
||||||
--- a/lib/dns/include/dns/db.h
|
|
||||||
+++ b/lib/dns/include/dns/db.h
|
|
||||||
@@ -1728,6 +1728,15 @@ dns_db_setmaxrrperset(uint32_t maxrrperset);
|
|
||||||
*\li void
|
|
||||||
*/
|
|
||||||
|
|
||||||
+void
|
|
||||||
+dns_db_setmaxtypepername(uint32_t value);
|
|
||||||
+/*%<
|
|
||||||
+ * Set the maximum permissible number of RR types per owner name.
|
|
||||||
+ *
|
|
||||||
+ * If 'value' is nonzero, then any subsequent attempt to add an rdataset with a
|
|
||||||
+ * RR type that would exceed the number of already stored RR types will return
|
|
||||||
+ * ISC_R_NOSPACE.
|
|
||||||
+ */
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
|
|
||||||
#endif /* DNS_DB_H */
|
|
||||||
diff --git a/lib/dns/rdataslab.c b/lib/dns/rdataslab.c
|
|
||||||
index 9566f79..8ea9ef4 100644
|
|
||||||
--- a/lib/dns/rdataslab.c
|
|
||||||
+++ b/lib/dns/rdataslab.c
|
|
||||||
@@ -121,8 +121,18 @@ fillin_offsets(unsigned char *offsetbase, unsigned int *offsettable,
|
|
||||||
#endif /* DNS_RDATASET_MAX_RECORDS */
|
|
||||||
|
|
||||||
static unsigned int dns_g_rdataset_max_records = DNS_RDATASET_MAX_RECORDS;
|
|
||||||
+static bool dns_g_rdataset_max_records_fromenv = false;
|
|
||||||
static isc_once_t once = ISC_ONCE_INIT;
|
|
||||||
|
|
||||||
+void
|
|
||||||
+dns_rdataslab_setmaxrrperset(uint32_t maxrrperset)
|
|
||||||
+{
|
|
||||||
+ if (!dns_g_rdataset_max_records_fromenv) {
|
|
||||||
+ /* Make environment override configuration to avoid resetting to default value. */
|
|
||||||
+ dns_g_rdataset_max_records = maxrrperset;
|
|
||||||
+ }
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
static void
|
|
||||||
init_max_records(void) {
|
|
||||||
/* Red Hat change, allow setting different max value by environment. */
|
|
||||||
@@ -130,8 +140,10 @@ init_max_records(void) {
|
|
||||||
if (max) {
|
|
||||||
char *endp = NULL;
|
|
||||||
long l = strtol(max, &endp, 10);
|
|
||||||
- if (max != endp && endp && !*endp && l > 0)
|
|
||||||
+ if (max != endp && endp && !*endp) {
|
|
||||||
dns_g_rdataset_max_records = l;
|
|
||||||
+ dns_g_rdataset_max_records_fromenv = true;
|
|
||||||
+ }
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
diff --git a/lib/isccfg/namedconf.c b/lib/isccfg/namedconf.c
|
|
||||||
index fc46a64..b80bb9c 100644
|
|
||||||
--- a/lib/isccfg/namedconf.c
|
|
||||||
+++ b/lib/isccfg/namedconf.c
|
|
||||||
@@ -1102,6 +1102,7 @@ options_clauses[] = {
|
|
||||||
{ "match-mapped-addresses", &cfg_type_boolean, 0 },
|
|
||||||
{ "max-records-per-type", &cfg_type_uint32, 0 },
|
|
||||||
{ "max-rsa-exponent-size", &cfg_type_uint32, 0 },
|
|
||||||
+ { "max-types-per-name", &cfg_type_uint32, 0 },
|
|
||||||
{ "memstatistics", &cfg_type_boolean, 0 },
|
|
||||||
{ "memstatistics-file", &cfg_type_qstring, 0 },
|
|
||||||
{ "multiple-cnames", &cfg_type_boolean, CFG_CLAUSEFLAG_OBSOLETE },
|
|
||||||
--
|
|
||||||
2.50.0
|
|
||||||
|
|
||||||
@ -1,171 +0,0 @@
|
|||||||
diff --git a/lib/isc/include/isc/result.h b/lib/isc/include/isc/result.h
|
|
||||||
index 0389efa..149cde5 100644
|
|
||||||
--- a/lib/isc/include/isc/result.h
|
|
||||||
+++ b/lib/isc/include/isc/result.h
|
|
||||||
@@ -89,7 +89,8 @@
|
|
||||||
#define ISC_R_DISCFULL 67 /*%< disc full */
|
|
||||||
#define ISC_R_DEFAULT 68 /*%< default */
|
|
||||||
#define ISC_R_IPV4PREFIX 69 /*%< IPv4 prefix */
|
|
||||||
-#define ISC_R_NRESULTS 70
|
|
||||||
+#define ISC_R_TIMESHIFTED 70 /*%< system time changed */
|
|
||||||
+#define ISC_R_NRESULTS 71
|
|
||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
|
||||||
|
|
||||||
diff --git a/lib/isc/include/isc/util.h b/lib/isc/include/isc/util.h
|
|
||||||
index 973c348..cceeb5e 100644
|
|
||||||
--- a/lib/isc/include/isc/util.h
|
|
||||||
+++ b/lib/isc/include/isc/util.h
|
|
||||||
@@ -289,6 +289,10 @@ extern void mock_assert(const int result, const char* const expression,
|
|
||||||
* Time
|
|
||||||
*/
|
|
||||||
#define TIME_NOW(tp) RUNTIME_CHECK(isc_time_now((tp)) == ISC_R_SUCCESS)
|
|
||||||
+#ifdef CLOCK_BOOTTIME
|
|
||||||
+#define TIME_MONOTONIC(tp) RUNTIME_CHECK(isc_time_boottime((tp)) == ISC_R_SUCCESS)
|
|
||||||
+#endif
|
|
||||||
+
|
|
||||||
|
|
||||||
/*%
|
|
||||||
* Alignment
|
|
||||||
diff --git a/lib/isc/result.c b/lib/isc/result.c
|
|
||||||
index a9db132..f33fc6b 100644
|
|
||||||
--- a/lib/isc/result.c
|
|
||||||
+++ b/lib/isc/result.c
|
|
||||||
@@ -105,6 +105,7 @@ static const char *description[ISC_R_NRESULTS] = {
|
|
||||||
"disc full", /*%< 67 */
|
|
||||||
"default", /*%< 68 */
|
|
||||||
"IPv4 prefix", /*%< 69 */
|
|
||||||
+ "time changed", /*%< 70 */
|
|
||||||
};
|
|
||||||
|
|
||||||
static const char *identifier[ISC_R_NRESULTS] = {
|
|
||||||
@@ -178,6 +179,7 @@ static const char *identifier[ISC_R_NRESULTS] = {
|
|
||||||
"ISC_R_DISCFULL",
|
|
||||||
"ISC_R_DEFAULT",
|
|
||||||
"ISC_R_IPV4PREFIX",
|
|
||||||
+ "ISC_R_TIMESHIFTED",
|
|
||||||
};
|
|
||||||
|
|
||||||
#define ISC_RESULT_RESULTSET 2
|
|
||||||
diff --git a/lib/isc/unix/app.c b/lib/isc/unix/app.c
|
|
||||||
index a6e9882..286fe95 100644
|
|
||||||
--- a/lib/isc/unix/app.c
|
|
||||||
+++ b/lib/isc/unix/app.c
|
|
||||||
@@ -442,15 +442,47 @@ isc__app_ctxonrun(isc_appctx_t *ctx0, isc_mem_t *mctx, isc_task_t *task,
|
|
||||||
static isc_result_t
|
|
||||||
evloop(isc__appctx_t *ctx) {
|
|
||||||
isc_result_t result;
|
|
||||||
+ isc_time_t now;
|
|
||||||
+#ifdef CLOCK_BOOTTIME
|
|
||||||
+ isc_time_t monotonic;
|
|
||||||
+ isc_uint64_t diff = 0;
|
|
||||||
+#else
|
|
||||||
+ isc_time_t prev;
|
|
||||||
+ TIME_NOW(&prev);
|
|
||||||
+#endif
|
|
||||||
|
|
||||||
while (!ctx->want_shutdown) {
|
|
||||||
int n;
|
|
||||||
- isc_time_t when, now;
|
|
||||||
+ isc_time_t when;
|
|
||||||
struct timeval tv, *tvp;
|
|
||||||
isc_socketwait_t *swait;
|
|
||||||
bool readytasks;
|
|
||||||
bool call_timer_dispatch = false;
|
|
||||||
|
|
||||||
+ uint64_t us;
|
|
||||||
+
|
|
||||||
+#ifdef CLOCK_BOOTTIME
|
|
||||||
+ // TBD macros for following three lines
|
|
||||||
+ TIME_NOW(&now);
|
|
||||||
+ TIME_MONOTONIC(&monotonic);
|
|
||||||
+ INSIST(now.seconds > monotonic.seconds)
|
|
||||||
+ us = isc_time_microdiff (&now, &monotonic);
|
|
||||||
+ if (us < diff){
|
|
||||||
+ us = diff - us;
|
|
||||||
+ if (us > 1000000){ // ignoring shifts less than one second
|
|
||||||
+ return ISC_R_TIMESHIFTED;
|
|
||||||
+ };
|
|
||||||
+ diff = isc_time_microdiff (&now, &monotonic);
|
|
||||||
+ } else {
|
|
||||||
+ diff = isc_time_microdiff (&now, &monotonic);
|
|
||||||
+ // not implemented
|
|
||||||
+ }
|
|
||||||
+#else
|
|
||||||
+ TIME_NOW(&now);
|
|
||||||
+ if (isc_time_compare (&now, &prev) < 0)
|
|
||||||
+ return ISC_R_TIMESHIFTED;
|
|
||||||
+ TIME_NOW(&prev);
|
|
||||||
+#endif
|
|
||||||
/*
|
|
||||||
* Check the reload (or suspend) case first for exiting the
|
|
||||||
* loop as fast as possible in case:
|
|
||||||
@@ -475,7 +507,6 @@ evloop(isc__appctx_t *ctx) {
|
|
||||||
if (result != ISC_R_SUCCESS)
|
|
||||||
tvp = NULL;
|
|
||||||
else {
|
|
||||||
- uint64_t us;
|
|
||||||
|
|
||||||
TIME_NOW(&now);
|
|
||||||
us = isc_time_microdiff(&when, &now);
|
|
||||||
diff --git a/lib/isc/unix/include/isc/time.h b/lib/isc/unix/include/isc/time.h
|
|
||||||
index b864c29..5dd43c9 100644
|
|
||||||
--- a/lib/isc/unix/include/isc/time.h
|
|
||||||
+++ b/lib/isc/unix/include/isc/time.h
|
|
||||||
@@ -132,6 +132,26 @@ isc_time_isepoch(const isc_time_t *t);
|
|
||||||
*\li 't' is a valid pointer.
|
|
||||||
*/
|
|
||||||
|
|
||||||
+#ifdef CLOCK_BOOTTIME
|
|
||||||
+isc_result_t
|
|
||||||
+isc_time_boottime(isc_time_t *t);
|
|
||||||
+/*%<
|
|
||||||
+ * Set 't' to monotonic time from previous boot
|
|
||||||
+ * it's not affected by system time change. It also
|
|
||||||
+ * includes the time system was suspended
|
|
||||||
+ *
|
|
||||||
+ * Requires:
|
|
||||||
+ *\li 't' is a valid pointer.
|
|
||||||
+ *
|
|
||||||
+ * Returns:
|
|
||||||
+ *
|
|
||||||
+ *\li Success
|
|
||||||
+ *\li Unexpected error
|
|
||||||
+ * Getting the time from the system failed.
|
|
||||||
+ */
|
|
||||||
+#endif /* CLOCK_BOOTTIME */
|
|
||||||
+
|
|
||||||
+
|
|
||||||
isc_result_t
|
|
||||||
isc_time_now(isc_time_t *t);
|
|
||||||
/*%<
|
|
||||||
diff --git a/lib/isc/unix/time.c b/lib/isc/unix/time.c
|
|
||||||
index 8edc9df..fe0bb91 100644
|
|
||||||
--- a/lib/isc/unix/time.c
|
|
||||||
+++ b/lib/isc/unix/time.c
|
|
||||||
@@ -498,3 +498,25 @@ isc_time_formatISO8601ms(const isc_time_t *t, char *buf, unsigned int len) {
|
|
||||||
t->nanoseconds / NS_PER_MS);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+#ifdef CLOCK_BOOTTIME
|
|
||||||
+isc_result_t
|
|
||||||
+isc_time_boottime(isc_time_t *t) {
|
|
||||||
+ struct timespec ts;
|
|
||||||
+
|
|
||||||
+ char strbuf[ISC_STRERRORSIZE];
|
|
||||||
+
|
|
||||||
+ if (clock_gettime (CLOCK_BOOTTIME, &ts) != 0){
|
|
||||||
+ isc__strerror(errno, strbuf, sizeof(strbuf));
|
|
||||||
+ UNEXPECTED_ERROR(__FILE__, __LINE__, "%s", strbuf);
|
|
||||||
+ return (ISC_R_UNEXPECTED);
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+ t->seconds = ts.tv_sec;
|
|
||||||
+ t->nanoseconds = ts.tv_nsec;
|
|
||||||
+
|
|
||||||
+ return (ISC_R_SUCCESS);
|
|
||||||
+
|
|
||||||
+};
|
|
||||||
+#endif
|
|
||||||
@ -1,27 +0,0 @@
|
|||||||
From 37f89ccfc439f8d86c401d9ae10e94e53b924961 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Petr Mensik <pemensik@redhat.com>
|
|
||||||
Date: Tue, 27 Aug 2019 20:39:59 +0200
|
|
||||||
Subject: [PATCH] Do not set engine for native PKCS11
|
|
||||||
|
|
||||||
It resets already set lib_path to pkcs11, which is invalid in native
|
|
||||||
pkcs11 crypto. Engine has to be path to PKCS#11 module.
|
|
||||||
---
|
|
||||||
bin/named/include/named/globals.h | 2 +-
|
|
||||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
|
||||||
|
|
||||||
diff --git a/bin/named/include/named/globals.h b/bin/named/include/named/globals.h
|
|
||||||
index eda2214..2a611d5 100644
|
|
||||||
--- a/bin/named/include/named/globals.h
|
|
||||||
+++ b/bin/named/include/named/globals.h
|
|
||||||
@@ -160,7 +160,7 @@ EXTERN const char * ns_g_defaultdnstap INIT(NULL);
|
|
||||||
|
|
||||||
EXTERN const char * ns_g_username INIT(NULL);
|
|
||||||
|
|
||||||
-#if defined(USE_PKCS11)
|
|
||||||
+#if defined(USE_PKCS11) && !defined(PKCS11CRYPTO)
|
|
||||||
EXTERN const char * ns_g_engine INIT(PKCS11_ENGINE);
|
|
||||||
#else
|
|
||||||
EXTERN const char * ns_g_engine INIT(NULL);
|
|
||||||
--
|
|
||||||
2.20.1
|
|
||||||
|
|
||||||
@ -1,39 +0,0 @@
|
|||||||
diff --git a/configure.ac b/configure.ac
|
|
||||||
index c1bfd62..7c5ad51 100644
|
|
||||||
--- a/configure.ac
|
|
||||||
+++ b/configure.ac
|
|
||||||
@@ -5333,6 +5333,8 @@ AC_SUBST(BUILD_CPPFLAGS)
|
|
||||||
AC_SUBST(BUILD_LDFLAGS)
|
|
||||||
AC_SUBST(BUILD_LIBS)
|
|
||||||
|
|
||||||
+AC_SUBST(LIBDIR_SUFFIX)
|
|
||||||
+
|
|
||||||
#
|
|
||||||
# Commands to run at the end of config.status.
|
|
||||||
# Don't just put these into configure, it won't work right if somebody
|
|
||||||
diff --git a/isc-config.sh.in b/isc-config.sh.in
|
|
||||||
index b5e94ed..d2857e0 100644
|
|
||||||
--- a/isc-config.sh.in
|
|
||||||
+++ b/isc-config.sh.in
|
|
||||||
@@ -13,16 +13,17 @@ prefix=@prefix@
|
|
||||||
exec_prefix=@exec_prefix@
|
|
||||||
exec_prefix_set=
|
|
||||||
includedir=@includedir@
|
|
||||||
+libdir_suffix=@LIBDIR_SUFFIX@
|
|
||||||
arch=$(uname -m)
|
|
||||||
|
|
||||||
case $arch in
|
|
||||||
x86_64 | amd64 | sparc64 | s390x | ppc64)
|
|
||||||
- libdir=/usr/lib64
|
|
||||||
- sec_libdir=/usr/lib
|
|
||||||
+ libdir=/usr/lib64${libdir_suffix}
|
|
||||||
+ sec_libdir=/usr/lib${libdir_suffix}
|
|
||||||
;;
|
|
||||||
* )
|
|
||||||
- libdir=/usr/lib
|
|
||||||
- sec_libdir=/usr/lib64
|
|
||||||
+ libdir=/usr/lib${libdir_suffix}
|
|
||||||
+ sec_libdir=/usr/lib64${libdir_suffix}
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
|
|
||||||
70
SOURCES/bind-9.11-feature-test-named.patch
Normal file
70
SOURCES/bind-9.11-feature-test-named.patch
Normal file
@ -0,0 +1,70 @@
|
|||||||
|
From e9e7069ede766fa5c881517bdae74e2fc6682398 Mon Sep 17 00:00:00 2001
|
||||||
|
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
||||||
|
Date: Wed, 30 Jan 2019 14:37:17 +0100
|
||||||
|
Subject: [PATCH] Create feature-test in source directory
|
||||||
|
|
||||||
|
Feature-test tool is used in system tests to test compiled in changes.
|
||||||
|
Because we build more variants of named with different configuration,
|
||||||
|
compile feature-test for each of them this way.
|
||||||
|
|
||||||
|
Make gsstsig test supported
|
||||||
|
---
|
||||||
|
bin/named/Makefile.in | 14 ++++++++++++--
|
||||||
|
bin/tests/system/conf.sh.in | 2 +-
|
||||||
|
2 files changed, 13 insertions(+), 3 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/bin/named/Makefile.in b/bin/named/Makefile.in
|
||||||
|
index debb906adc..dd894fe934 100644
|
||||||
|
--- a/bin/named/Makefile.in
|
||||||
|
+++ b/bin/named/Makefile.in
|
||||||
|
@@ -56,7 +56,7 @@ CINCLUDES = -I${srcdir}/include -I${srcdir}/unix/include -I. \
|
||||||
|
${LIBXML2_CFLAGS} \
|
||||||
|
${MAXMINDDB_CFLAGS}
|
||||||
|
|
||||||
|
-CDEFINES = @CONTRIB_DLZ@
|
||||||
|
+CDEFINES = @USE_GSSAPI@ @CONTRIB_DLZ@
|
||||||
|
|
||||||
|
CWARNINGS =
|
||||||
|
|
||||||
|
@@ -93,7 +93,7 @@ NOSYMLIBS = ${NSLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
||||||
|
|
||||||
|
SUBDIRS = unix
|
||||||
|
|
||||||
|
-TARGETS = named@EXEEXT@
|
||||||
|
+TARGETS = named@EXEEXT@ feature-test@EXEEXT@
|
||||||
|
|
||||||
|
GEOIP2LINKOBJS = geoip.@O@
|
||||||
|
|
||||||
|
@@ -156,6 +156,16 @@ named@EXEEXT@: ${OBJS} ${DEPLIBS}
|
||||||
|
export BASEOBJS="${OBJS} ${UOBJS}"; \
|
||||||
|
${FINALBUILDCMD}
|
||||||
|
|
||||||
|
+# Bit of hack, do not produce intermediate .o object for featuretest
|
||||||
|
+feature-test.@O@: ${top_srcdir}/bin/tests/system/feature-test.c
|
||||||
|
+ ${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} \
|
||||||
|
+ -c ${top_srcdir}/bin/tests/system/feature-test.c
|
||||||
|
+
|
||||||
|
+feature-test@EXEEXT@: feature-test.@O@
|
||||||
|
+ ${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} \
|
||||||
|
+ -o $@ feature-test.@O@ ${ISCLIBS} ${LIBS}
|
||||||
|
+
|
||||||
|
+
|
||||||
|
clean distclean maintainer-clean::
|
||||||
|
rm -f ${TARGETS} ${OBJS}
|
||||||
|
|
||||||
|
diff --git a/bin/tests/system/conf.sh.in b/bin/tests/system/conf.sh.in
|
||||||
|
index 9a61622143..f69c5be334 100644
|
||||||
|
--- a/bin/tests/system/conf.sh.in
|
||||||
|
+++ b/bin/tests/system/conf.sh.in
|
||||||
|
@@ -38,7 +38,7 @@ DELV=$TOP/bin/delv/delv
|
||||||
|
DIG=$TOP/bin/dig/dig
|
||||||
|
DNSTAPREAD=$TOP/bin/tools/dnstap-read
|
||||||
|
DSFROMKEY=$TOP/bin/dnssec/dnssec-dsfromkey
|
||||||
|
-FEATURETEST=$TOP/bin/tests/system/feature-test
|
||||||
|
+FEATURETEST=$TOP/bin/named/feature-test
|
||||||
|
FSTRM_CAPTURE=@FSTRM_CAPTURE@
|
||||||
|
HOST=$TOP/bin/dig/host
|
||||||
|
IMPORTKEY=$TOP/bin/dnssec/dnssec-importkey
|
||||||
|
--
|
||||||
|
2.45.2
|
||||||
|
|
||||||
@ -1,39 +0,0 @@
|
|||||||
From c928591eb2a3b17c5be0cad56c8e061ebba11a95 Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
|
||||||
Date: Thu, 20 Dec 2018 11:52:12 +0100
|
|
||||||
Subject: [PATCH] Fix implicit declaration warning
|
|
||||||
|
|
||||||
isc_md5_available() function is not declared before its use. Include
|
|
||||||
header providing it in files that use it.
|
|
||||||
---
|
|
||||||
bin/tests/system/tkey/keydelete.c | 1 +
|
|
||||||
lib/dns/tsig.c | 1 +
|
|
||||||
2 files changed, 2 insertions(+)
|
|
||||||
|
|
||||||
diff --git a/bin/tests/system/tkey/keydelete.c b/bin/tests/system/tkey/keydelete.c
|
|
||||||
index 4b5b901..a3dd450 100644
|
|
||||||
--- a/bin/tests/system/tkey/keydelete.c
|
|
||||||
+++ b/bin/tests/system/tkey/keydelete.c
|
|
||||||
@@ -21,6 +21,7 @@
|
|
||||||
#include <isc/hash.h>
|
|
||||||
#include <isc/log.h>
|
|
||||||
#include <isc/mem.h>
|
|
||||||
+#include <isc/md5.h>
|
|
||||||
#include <isc/print.h>
|
|
||||||
#include <isc/sockaddr.h>
|
|
||||||
#include <isc/socket.h>
|
|
||||||
diff --git a/lib/dns/tsig.c b/lib/dns/tsig.c
|
|
||||||
index c37b235..7786801 100644
|
|
||||||
--- a/lib/dns/tsig.c
|
|
||||||
+++ b/lib/dns/tsig.c
|
|
||||||
@@ -18,6 +18,7 @@
|
|
||||||
|
|
||||||
#include <isc/buffer.h>
|
|
||||||
#include <isc/mem.h>
|
|
||||||
+#include <isc/md5.h>
|
|
||||||
#include <isc/print.h>
|
|
||||||
#include <isc/print.h>
|
|
||||||
#include <isc/refcount.h>
|
|
||||||
--
|
|
||||||
2.26.2
|
|
||||||
|
|
||||||
File diff suppressed because it is too large
Load Diff
@ -1,121 +0,0 @@
|
|||||||
From 83b889c238282b210f874a3ad81bb56299767495 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Petr Mensik <pemensik@redhat.com>
|
|
||||||
Date: Mon, 5 Aug 2019 11:54:03 +0200
|
|
||||||
Subject: [PATCH] Allow explicit disabling of autodisabled MD5
|
|
||||||
|
|
||||||
Default security policy might include explicitly disabled RSAMD5
|
|
||||||
algorithm. Current FIPS code automatically disables in FIPS mode. But if
|
|
||||||
RSAMD5 is included in security policy, it fails to start, because that
|
|
||||||
algorithm is not recognized. Allow it disabled, but fail on any
|
|
||||||
other usage.
|
|
||||||
---
|
|
||||||
bin/named/server.c | 4 ++--
|
|
||||||
lib/bind9/check.c | 4 ++++
|
|
||||||
lib/dns/rcode.c | 33 +++++++++++++++------------------
|
|
||||||
3 files changed, 21 insertions(+), 20 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/bin/named/server.c b/bin/named/server.c
|
|
||||||
index 5b57371..51702ab 100644
|
|
||||||
--- a/bin/named/server.c
|
|
||||||
+++ b/bin/named/server.c
|
|
||||||
@@ -1547,12 +1547,12 @@ disable_algorithms(const cfg_obj_t *disabled, dns_resolver_t *resolver) {
|
|
||||||
r.length = strlen(r.base);
|
|
||||||
|
|
||||||
result = dns_secalg_fromtext(&alg, &r);
|
|
||||||
- if (result != ISC_R_SUCCESS) {
|
|
||||||
+ if (result != ISC_R_SUCCESS && result != ISC_R_DISABLED) {
|
|
||||||
uint8_t ui;
|
|
||||||
result = isc_parse_uint8(&ui, r.base, 10);
|
|
||||||
alg = ui;
|
|
||||||
}
|
|
||||||
- if (result != ISC_R_SUCCESS) {
|
|
||||||
+ if (result != ISC_R_SUCCESS && result != ISC_R_DISABLED) {
|
|
||||||
cfg_obj_log(cfg_listelt_value(element),
|
|
||||||
ns_g_lctx, ISC_LOG_ERROR,
|
|
||||||
"invalid algorithm");
|
|
||||||
diff --git a/lib/bind9/check.c b/lib/bind9/check.c
|
|
||||||
index e0803d4..8023784 100644
|
|
||||||
--- a/lib/bind9/check.c
|
|
||||||
+++ b/lib/bind9/check.c
|
|
||||||
@@ -302,6 +302,10 @@ disabled_algorithms(const cfg_obj_t *disabled, isc_log_t *logctx) {
|
|
||||||
r.length = strlen(r.base);
|
|
||||||
|
|
||||||
tresult = dns_secalg_fromtext(&alg, &r);
|
|
||||||
+ if (tresult == ISC_R_DISABLED) {
|
|
||||||
+ // Recognize disabled algorithms, disable it explicitly
|
|
||||||
+ tresult = ISC_R_SUCCESS;
|
|
||||||
+ }
|
|
||||||
if (tresult != ISC_R_SUCCESS) {
|
|
||||||
cfg_obj_log(cfg_listelt_value(element), logctx,
|
|
||||||
ISC_LOG_ERROR, "invalid algorithm '%s'",
|
|
||||||
diff --git a/lib/dns/rcode.c b/lib/dns/rcode.c
|
|
||||||
index f51d548..c49b8d1 100644
|
|
||||||
--- a/lib/dns/rcode.c
|
|
||||||
+++ b/lib/dns/rcode.c
|
|
||||||
@@ -126,7 +126,6 @@
|
|
||||||
#endif
|
|
||||||
|
|
||||||
#define SECALGNAMES \
|
|
||||||
- MD5_SECALGNAMES \
|
|
||||||
DH_SECALGNAMES \
|
|
||||||
DSA_SECALGNAMES \
|
|
||||||
{ DNS_KEYALG_ECC, "ECC", 0 }, \
|
|
||||||
@@ -178,6 +177,7 @@ static struct tbl rcodes[] = { RCODENAMES ERCODENAMES };
|
|
||||||
static struct tbl tsigrcodes[] = { RCODENAMES TSIGRCODENAMES };
|
|
||||||
static struct tbl certs[] = { CERTNAMES };
|
|
||||||
static struct tbl secalgs[] = { SECALGNAMES };
|
|
||||||
+static struct tbl md5_secalgs[] = { MD5_SECALGNAMES };
|
|
||||||
static struct tbl secprotos[] = { SECPROTONAMES };
|
|
||||||
static struct tbl hashalgs[] = { HASHALGNAMES };
|
|
||||||
static struct tbl dsdigests[] = { DSDIGESTNAMES };
|
|
||||||
@@ -358,33 +358,30 @@ dns_cert_totext(dns_cert_t cert, isc_buffer_t *target) {
|
|
||||||
return (dns_mnemonic_totext(cert, target, certs));
|
|
||||||
}
|
|
||||||
|
|
||||||
-static inline struct tbl *
|
|
||||||
-secalgs_tbl_start() {
|
|
||||||
- struct tbl *algs = secalgs;
|
|
||||||
-
|
|
||||||
-#ifndef PK11_MD5_DISABLE
|
|
||||||
- if (!isc_md5_available()) {
|
|
||||||
- while (algs->name != NULL &&
|
|
||||||
- algs->value == DNS_KEYALG_RSAMD5)
|
|
||||||
- ++algs;
|
|
||||||
- }
|
|
||||||
-#endif
|
|
||||||
- return algs;
|
|
||||||
-}
|
|
||||||
-
|
|
||||||
isc_result_t
|
|
||||||
dns_secalg_fromtext(dns_secalg_t *secalgp, isc_textregion_t *source) {
|
|
||||||
unsigned int value;
|
|
||||||
+ isc_result_t result;
|
|
||||||
|
|
||||||
- RETERR(dns_mnemonic_fromtext(&value, source,
|
|
||||||
- secalgs_tbl_start(), 0xff));
|
|
||||||
+ result = dns_mnemonic_fromtext(&value, source,
|
|
||||||
+ secalgs, 0xff);
|
|
||||||
+ if (result != ISC_R_SUCCESS) {
|
|
||||||
+ result = dns_mnemonic_fromtext(&value, source,
|
|
||||||
+ md5_secalgs, 0xff);
|
|
||||||
+ if (result != ISC_R_SUCCESS) {
|
|
||||||
+ return (result);
|
|
||||||
+ } else if (!isc_md5_available()) {
|
|
||||||
+ *secalgp = value;
|
|
||||||
+ return (ISC_R_DISABLED);
|
|
||||||
+ }
|
|
||||||
+ }
|
|
||||||
*secalgp = value;
|
|
||||||
return (ISC_R_SUCCESS);
|
|
||||||
}
|
|
||||||
|
|
||||||
isc_result_t
|
|
||||||
dns_secalg_totext(dns_secalg_t secalg, isc_buffer_t *target) {
|
|
||||||
- return (dns_mnemonic_totext(secalg, target, secalgs_tbl_start()));
|
|
||||||
+ return (dns_mnemonic_totext(secalg, target, secalgs));
|
|
||||||
}
|
|
||||||
|
|
||||||
void
|
|
||||||
--
|
|
||||||
2.20.1
|
|
||||||
|
|
||||||
@ -1,4 +1,4 @@
|
|||||||
From 1dc81c51cd5c70b783aab8b6156aec4cfedd6fe3 Mon Sep 17 00:00:00 2001
|
From 3f04cf343dbeb8819197702ce1be737e26e0638a Mon Sep 17 00:00:00 2001
|
||||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
||||||
Date: Thu, 2 Aug 2018 23:46:45 +0200
|
Date: Thu, 2 Aug 2018 23:46:45 +0200
|
||||||
Subject: [PATCH] FIPS tests changes
|
Subject: [PATCH] FIPS tests changes
|
||||||
@ -76,37 +76,26 @@ Date: Wed Mar 7 10:44:23 2018 +0100
|
|||||||
bin/tests/system/catz/ns2/named.conf.in | 2 +-
|
bin/tests/system/catz/ns2/named.conf.in | 2 +-
|
||||||
bin/tests/system/checkconf/bad-tsig.conf | 2 +-
|
bin/tests/system/checkconf/bad-tsig.conf | 2 +-
|
||||||
bin/tests/system/checkconf/good.conf | 2 +-
|
bin/tests/system/checkconf/good.conf | 2 +-
|
||||||
bin/tests/system/digdelv/ns2/example.db | 15 +++--
|
|
||||||
bin/tests/system/digdelv/tests.sh | 20 +++---
|
|
||||||
bin/tests/system/dlv/ns1/sign.sh | 4 +-
|
|
||||||
bin/tests/system/dlv/ns2/sign.sh | 4 +-
|
|
||||||
bin/tests/system/dlv/ns6/sign.sh | 66 ++++++++++---------
|
|
||||||
bin/tests/system/dnssec/ns2/sign.sh | 8 +--
|
|
||||||
bin/tests/system/dnssec/ns5/trusted.conf.bad | 2 +-
|
|
||||||
bin/tests/system/dnssec/tests.sh | 4 +-
|
|
||||||
bin/tests/system/feature-test.c | 14 ++++
|
bin/tests/system/feature-test.c | 14 ++++
|
||||||
bin/tests/system/filter-aaaa/ns1/sign.sh | 4 +-
|
|
||||||
bin/tests/system/filter-aaaa/ns4/sign.sh | 4 +-
|
|
||||||
bin/tests/system/notify/ns5/named.conf.in | 6 +-
|
bin/tests/system/notify/ns5/named.conf.in | 6 +-
|
||||||
bin/tests/system/notify/tests.sh | 6 +-
|
bin/tests/system/notify/tests.sh | 6 +-
|
||||||
bin/tests/system/nsupdate/ns1/named.conf.in | 2 +-
|
bin/tests/system/nsupdate/ns1/named.conf.in | 2 +-
|
||||||
bin/tests/system/nsupdate/ns2/named.conf.in | 2 +-
|
bin/tests/system/nsupdate/ns2/named.conf.in | 2 +-
|
||||||
bin/tests/system/nsupdate/setup.sh | 7 +-
|
bin/tests/system/nsupdate/setup.sh | 6 +-
|
||||||
bin/tests/system/nsupdate/tests.sh | 11 +++-
|
bin/tests/system/nsupdate/tests.sh | 15 +++--
|
||||||
bin/tests/system/rndc/setup.sh | 2 +-
|
bin/tests/system/rndc/setup.sh | 2 +-
|
||||||
bin/tests/system/rndc/tests.sh | 23 ++++---
|
bin/tests/system/rndc/tests.sh | 23 ++++---
|
||||||
bin/tests/system/tsig/ns1/named.conf.in | 10 +--
|
bin/tests/system/tsig/ns1/named.conf.in | 10 +--
|
||||||
bin/tests/system/tsig/ns1/rndc5.conf.in | 10 +++
|
bin/tests/system/tsig/ns1/rndc5.conf.in | 10 +++
|
||||||
bin/tests/system/tsig/setup.sh | 5 ++
|
bin/tests/system/tsig/setup.sh | 5 ++
|
||||||
bin/tests/system/tsig/tests.sh | 65 +++++++++++-------
|
bin/tests/system/tsig/tests.sh | 65 ++++++++++++-------
|
||||||
bin/tests/system/tsiggss/setup.sh | 2 +-
|
|
||||||
bin/tests/system/upforwd/ns1/named.conf.in | 2 +-
|
bin/tests/system/upforwd/ns1/named.conf.in | 2 +-
|
||||||
bin/tests/system/upforwd/tests.sh | 2 +-
|
bin/tests/system/upforwd/tests.sh | 2 +-
|
||||||
44 files changed, 230 insertions(+), 170 deletions(-)
|
33 files changed, 162 insertions(+), 108 deletions(-)
|
||||||
create mode 100644 bin/tests/system/tsig/ns1/rndc5.conf.in
|
create mode 100644 bin/tests/system/tsig/ns1/rndc5.conf.in
|
||||||
|
|
||||||
diff --git a/bin/tests/system/acl/ns2/named1.conf.in b/bin/tests/system/acl/ns2/named1.conf.in
|
diff --git a/bin/tests/system/acl/ns2/named1.conf.in b/bin/tests/system/acl/ns2/named1.conf.in
|
||||||
index 9999ada..e3f8d0e 100644
|
index 60f22e1..249f672 100644
|
||||||
--- a/bin/tests/system/acl/ns2/named1.conf.in
|
--- a/bin/tests/system/acl/ns2/named1.conf.in
|
||||||
+++ b/bin/tests/system/acl/ns2/named1.conf.in
|
+++ b/bin/tests/system/acl/ns2/named1.conf.in
|
||||||
@@ -33,12 +33,12 @@ options {
|
@@ -33,12 +33,12 @@ options {
|
||||||
@ -125,7 +114,7 @@ index 9999ada..e3f8d0e 100644
|
|||||||
};
|
};
|
||||||
|
|
||||||
diff --git a/bin/tests/system/acl/ns2/named2.conf.in b/bin/tests/system/acl/ns2/named2.conf.in
|
diff --git a/bin/tests/system/acl/ns2/named2.conf.in b/bin/tests/system/acl/ns2/named2.conf.in
|
||||||
index f8ec34e..d2d6ad3 100644
|
index ada97bc..f82d858 100644
|
||||||
--- a/bin/tests/system/acl/ns2/named2.conf.in
|
--- a/bin/tests/system/acl/ns2/named2.conf.in
|
||||||
+++ b/bin/tests/system/acl/ns2/named2.conf.in
|
+++ b/bin/tests/system/acl/ns2/named2.conf.in
|
||||||
@@ -33,12 +33,12 @@ options {
|
@@ -33,12 +33,12 @@ options {
|
||||||
@ -144,7 +133,7 @@ index f8ec34e..d2d6ad3 100644
|
|||||||
};
|
};
|
||||||
|
|
||||||
diff --git a/bin/tests/system/acl/ns2/named3.conf.in b/bin/tests/system/acl/ns2/named3.conf.in
|
diff --git a/bin/tests/system/acl/ns2/named3.conf.in b/bin/tests/system/acl/ns2/named3.conf.in
|
||||||
index 2acb813..6a00344 100644
|
index 97684e4..de6a2e9 100644
|
||||||
--- a/bin/tests/system/acl/ns2/named3.conf.in
|
--- a/bin/tests/system/acl/ns2/named3.conf.in
|
||||||
+++ b/bin/tests/system/acl/ns2/named3.conf.in
|
+++ b/bin/tests/system/acl/ns2/named3.conf.in
|
||||||
@@ -33,17 +33,17 @@ options {
|
@@ -33,17 +33,17 @@ options {
|
||||||
@ -169,7 +158,7 @@ index 2acb813..6a00344 100644
|
|||||||
};
|
};
|
||||||
|
|
||||||
diff --git a/bin/tests/system/acl/ns2/named4.conf.in b/bin/tests/system/acl/ns2/named4.conf.in
|
diff --git a/bin/tests/system/acl/ns2/named4.conf.in b/bin/tests/system/acl/ns2/named4.conf.in
|
||||||
index bca3ee1..5913420 100644
|
index 462b3fa..994b35c 100644
|
||||||
--- a/bin/tests/system/acl/ns2/named4.conf.in
|
--- a/bin/tests/system/acl/ns2/named4.conf.in
|
||||||
+++ b/bin/tests/system/acl/ns2/named4.conf.in
|
+++ b/bin/tests/system/acl/ns2/named4.conf.in
|
||||||
@@ -33,12 +33,12 @@ options {
|
@@ -33,12 +33,12 @@ options {
|
||||||
@ -188,10 +177,10 @@ index bca3ee1..5913420 100644
|
|||||||
};
|
};
|
||||||
|
|
||||||
diff --git a/bin/tests/system/acl/ns2/named5.conf.in b/bin/tests/system/acl/ns2/named5.conf.in
|
diff --git a/bin/tests/system/acl/ns2/named5.conf.in b/bin/tests/system/acl/ns2/named5.conf.in
|
||||||
index 9ef8171..5ae8d38 100644
|
index 728da58..8f00d09 100644
|
||||||
--- a/bin/tests/system/acl/ns2/named5.conf.in
|
--- a/bin/tests/system/acl/ns2/named5.conf.in
|
||||||
+++ b/bin/tests/system/acl/ns2/named5.conf.in
|
+++ b/bin/tests/system/acl/ns2/named5.conf.in
|
||||||
@@ -34,12 +34,12 @@ options {
|
@@ -35,12 +35,12 @@ options {
|
||||||
};
|
};
|
||||||
|
|
||||||
key one {
|
key one {
|
||||||
@ -207,7 +196,7 @@ index 9ef8171..5ae8d38 100644
|
|||||||
};
|
};
|
||||||
|
|
||||||
diff --git a/bin/tests/system/acl/tests.sh b/bin/tests/system/acl/tests.sh
|
diff --git a/bin/tests/system/acl/tests.sh b/bin/tests/system/acl/tests.sh
|
||||||
index 2ee34a0..a73a54e 100644
|
index be59d64..13d5bdc 100644
|
||||||
--- a/bin/tests/system/acl/tests.sh
|
--- a/bin/tests/system/acl/tests.sh
|
||||||
+++ b/bin/tests/system/acl/tests.sh
|
+++ b/bin/tests/system/acl/tests.sh
|
||||||
@@ -22,14 +22,14 @@ echo_i "testing basic ACL processing"
|
@@ -22,14 +22,14 @@ echo_i "testing basic ACL processing"
|
||||||
@ -333,11 +322,11 @@ index 2ee34a0..a73a54e 100644
|
|||||||
|
|
||||||
echo_i "testing allow-query-on ACL processing"
|
echo_i "testing allow-query-on ACL processing"
|
||||||
diff --git a/bin/tests/system/allow-query/ns2/named10.conf.in b/bin/tests/system/allow-query/ns2/named10.conf.in
|
diff --git a/bin/tests/system/allow-query/ns2/named10.conf.in b/bin/tests/system/allow-query/ns2/named10.conf.in
|
||||||
index a579f32..3b8f853 100644
|
index 7d43e36..f7b25f9 100644
|
||||||
--- a/bin/tests/system/allow-query/ns2/named10.conf.in
|
--- a/bin/tests/system/allow-query/ns2/named10.conf.in
|
||||||
+++ b/bin/tests/system/allow-query/ns2/named10.conf.in
|
+++ b/bin/tests/system/allow-query/ns2/named10.conf.in
|
||||||
@@ -12,7 +12,7 @@
|
@@ -10,7 +10,7 @@
|
||||||
controls { /* empty */ };
|
*/
|
||||||
|
|
||||||
key one {
|
key one {
|
||||||
- algorithm hmac-md5;
|
- algorithm hmac-md5;
|
||||||
@ -346,11 +335,11 @@ index a579f32..3b8f853 100644
|
|||||||
};
|
};
|
||||||
|
|
||||||
diff --git a/bin/tests/system/allow-query/ns2/named11.conf.in b/bin/tests/system/allow-query/ns2/named11.conf.in
|
diff --git a/bin/tests/system/allow-query/ns2/named11.conf.in b/bin/tests/system/allow-query/ns2/named11.conf.in
|
||||||
index 166afa1..997ece9 100644
|
index 2952518..121557e 100644
|
||||||
--- a/bin/tests/system/allow-query/ns2/named11.conf.in
|
--- a/bin/tests/system/allow-query/ns2/named11.conf.in
|
||||||
+++ b/bin/tests/system/allow-query/ns2/named11.conf.in
|
+++ b/bin/tests/system/allow-query/ns2/named11.conf.in
|
||||||
@@ -12,12 +12,12 @@
|
@@ -10,12 +10,12 @@
|
||||||
controls { /* empty */ };
|
*/
|
||||||
|
|
||||||
key one {
|
key one {
|
||||||
- algorithm hmac-md5;
|
- algorithm hmac-md5;
|
||||||
@ -365,11 +354,11 @@ index 166afa1..997ece9 100644
|
|||||||
};
|
};
|
||||||
|
|
||||||
diff --git a/bin/tests/system/allow-query/ns2/named12.conf.in b/bin/tests/system/allow-query/ns2/named12.conf.in
|
diff --git a/bin/tests/system/allow-query/ns2/named12.conf.in b/bin/tests/system/allow-query/ns2/named12.conf.in
|
||||||
index 25271a5..a9cb65d 100644
|
index 0c01071..ceabbb5 100644
|
||||||
--- a/bin/tests/system/allow-query/ns2/named12.conf.in
|
--- a/bin/tests/system/allow-query/ns2/named12.conf.in
|
||||||
+++ b/bin/tests/system/allow-query/ns2/named12.conf.in
|
+++ b/bin/tests/system/allow-query/ns2/named12.conf.in
|
||||||
@@ -12,7 +12,7 @@
|
@@ -10,7 +10,7 @@
|
||||||
controls { /* empty */ };
|
*/
|
||||||
|
|
||||||
key one {
|
key one {
|
||||||
- algorithm hmac-md5;
|
- algorithm hmac-md5;
|
||||||
@ -378,11 +367,11 @@ index 25271a5..a9cb65d 100644
|
|||||||
};
|
};
|
||||||
|
|
||||||
diff --git a/bin/tests/system/allow-query/ns2/named30.conf.in b/bin/tests/system/allow-query/ns2/named30.conf.in
|
diff --git a/bin/tests/system/allow-query/ns2/named30.conf.in b/bin/tests/system/allow-query/ns2/named30.conf.in
|
||||||
index c7c8254..f165e65 100644
|
index 4c17292..9cd9d1f 100644
|
||||||
--- a/bin/tests/system/allow-query/ns2/named30.conf.in
|
--- a/bin/tests/system/allow-query/ns2/named30.conf.in
|
||||||
+++ b/bin/tests/system/allow-query/ns2/named30.conf.in
|
+++ b/bin/tests/system/allow-query/ns2/named30.conf.in
|
||||||
@@ -12,7 +12,7 @@
|
@@ -10,7 +10,7 @@
|
||||||
controls { /* empty */ };
|
*/
|
||||||
|
|
||||||
key one {
|
key one {
|
||||||
- algorithm hmac-md5;
|
- algorithm hmac-md5;
|
||||||
@ -391,11 +380,11 @@ index c7c8254..f165e65 100644
|
|||||||
};
|
};
|
||||||
|
|
||||||
diff --git a/bin/tests/system/allow-query/ns2/named31.conf.in b/bin/tests/system/allow-query/ns2/named31.conf.in
|
diff --git a/bin/tests/system/allow-query/ns2/named31.conf.in b/bin/tests/system/allow-query/ns2/named31.conf.in
|
||||||
index 567bbcc..4fd2035 100644
|
index a2690a4..f488730 100644
|
||||||
--- a/bin/tests/system/allow-query/ns2/named31.conf.in
|
--- a/bin/tests/system/allow-query/ns2/named31.conf.in
|
||||||
+++ b/bin/tests/system/allow-query/ns2/named31.conf.in
|
+++ b/bin/tests/system/allow-query/ns2/named31.conf.in
|
||||||
@@ -12,12 +12,12 @@
|
@@ -10,12 +10,12 @@
|
||||||
controls { /* empty */ };
|
*/
|
||||||
|
|
||||||
key one {
|
key one {
|
||||||
- algorithm hmac-md5;
|
- algorithm hmac-md5;
|
||||||
@ -410,11 +399,11 @@ index 567bbcc..4fd2035 100644
|
|||||||
};
|
};
|
||||||
|
|
||||||
diff --git a/bin/tests/system/allow-query/ns2/named32.conf.in b/bin/tests/system/allow-query/ns2/named32.conf.in
|
diff --git a/bin/tests/system/allow-query/ns2/named32.conf.in b/bin/tests/system/allow-query/ns2/named32.conf.in
|
||||||
index b75161f..7b254e6 100644
|
index a0708c8..51fa457 100644
|
||||||
--- a/bin/tests/system/allow-query/ns2/named32.conf.in
|
--- a/bin/tests/system/allow-query/ns2/named32.conf.in
|
||||||
+++ b/bin/tests/system/allow-query/ns2/named32.conf.in
|
+++ b/bin/tests/system/allow-query/ns2/named32.conf.in
|
||||||
@@ -12,7 +12,7 @@
|
@@ -10,7 +10,7 @@
|
||||||
controls { /* empty */ };
|
*/
|
||||||
|
|
||||||
key one {
|
key one {
|
||||||
- algorithm hmac-md5;
|
- algorithm hmac-md5;
|
||||||
@ -423,10 +412,10 @@ index b75161f..7b254e6 100644
|
|||||||
};
|
};
|
||||||
|
|
||||||
diff --git a/bin/tests/system/allow-query/ns2/named40.conf.in b/bin/tests/system/allow-query/ns2/named40.conf.in
|
diff --git a/bin/tests/system/allow-query/ns2/named40.conf.in b/bin/tests/system/allow-query/ns2/named40.conf.in
|
||||||
index 9e17818..22f5001 100644
|
index 687768e..d24d6d2 100644
|
||||||
--- a/bin/tests/system/allow-query/ns2/named40.conf.in
|
--- a/bin/tests/system/allow-query/ns2/named40.conf.in
|
||||||
+++ b/bin/tests/system/allow-query/ns2/named40.conf.in
|
+++ b/bin/tests/system/allow-query/ns2/named40.conf.in
|
||||||
@@ -16,12 +16,12 @@ acl accept { 10.53.0.2; };
|
@@ -14,12 +14,12 @@ acl accept { 10.53.0.2; };
|
||||||
acl badaccept { 10.53.0.1; };
|
acl badaccept { 10.53.0.1; };
|
||||||
|
|
||||||
key one {
|
key one {
|
||||||
@ -442,10 +431,10 @@ index 9e17818..22f5001 100644
|
|||||||
};
|
};
|
||||||
|
|
||||||
diff --git a/bin/tests/system/allow-query/tests.sh b/bin/tests/system/allow-query/tests.sh
|
diff --git a/bin/tests/system/allow-query/tests.sh b/bin/tests/system/allow-query/tests.sh
|
||||||
index 791a1a4..95cd971 100644
|
index fe40635..543c663 100644
|
||||||
--- a/bin/tests/system/allow-query/tests.sh
|
--- a/bin/tests/system/allow-query/tests.sh
|
||||||
+++ b/bin/tests/system/allow-query/tests.sh
|
+++ b/bin/tests/system/allow-query/tests.sh
|
||||||
@@ -190,7 +190,7 @@ rndc_reload
|
@@ -182,7 +182,7 @@ rndc_reload ns2 10.53.0.2
|
||||||
|
|
||||||
echo_i "test $n: key allowed - query allowed"
|
echo_i "test $n: key allowed - query allowed"
|
||||||
ret=0
|
ret=0
|
||||||
@ -454,7 +443,7 @@ index 791a1a4..95cd971 100644
|
|||||||
grep 'status: NOERROR' dig.out.ns2.$n > /dev/null || ret=1
|
grep 'status: NOERROR' dig.out.ns2.$n > /dev/null || ret=1
|
||||||
grep '^a.normal.example' dig.out.ns2.$n > /dev/null || ret=1
|
grep '^a.normal.example' dig.out.ns2.$n > /dev/null || ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
@@ -203,7 +203,7 @@ rndc_reload
|
@@ -195,7 +195,7 @@ rndc_reload ns2 10.53.0.2
|
||||||
|
|
||||||
echo_i "test $n: key not allowed - query refused"
|
echo_i "test $n: key not allowed - query refused"
|
||||||
ret=0
|
ret=0
|
||||||
@ -463,7 +452,7 @@ index 791a1a4..95cd971 100644
|
|||||||
grep 'status: REFUSED' dig.out.ns2.$n > /dev/null || ret=1
|
grep 'status: REFUSED' dig.out.ns2.$n > /dev/null || ret=1
|
||||||
grep '^a.normal.example' dig.out.ns2.$n > /dev/null && ret=1
|
grep '^a.normal.example' dig.out.ns2.$n > /dev/null && ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
@@ -216,7 +216,7 @@ rndc_reload
|
@@ -208,7 +208,7 @@ rndc_reload ns2 10.53.0.2
|
||||||
|
|
||||||
echo_i "test $n: key disallowed - query refused"
|
echo_i "test $n: key disallowed - query refused"
|
||||||
ret=0
|
ret=0
|
||||||
@ -472,7 +461,7 @@ index 791a1a4..95cd971 100644
|
|||||||
grep 'status: REFUSED' dig.out.ns2.$n > /dev/null || ret=1
|
grep 'status: REFUSED' dig.out.ns2.$n > /dev/null || ret=1
|
||||||
grep '^a.normal.example' dig.out.ns2.$n > /dev/null && ret=1
|
grep '^a.normal.example' dig.out.ns2.$n > /dev/null && ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
@@ -349,7 +349,7 @@ rndc_reload
|
@@ -341,7 +341,7 @@ rndc_reload ns2 10.53.0.2
|
||||||
|
|
||||||
echo_i "test $n: views key allowed - query allowed"
|
echo_i "test $n: views key allowed - query allowed"
|
||||||
ret=0
|
ret=0
|
||||||
@ -481,7 +470,7 @@ index 791a1a4..95cd971 100644
|
|||||||
grep 'status: NOERROR' dig.out.ns2.$n > /dev/null || ret=1
|
grep 'status: NOERROR' dig.out.ns2.$n > /dev/null || ret=1
|
||||||
grep '^a.normal.example' dig.out.ns2.$n > /dev/null || ret=1
|
grep '^a.normal.example' dig.out.ns2.$n > /dev/null || ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
@@ -362,7 +362,7 @@ rndc_reload
|
@@ -354,7 +354,7 @@ rndc_reload ns2 10.53.0.2
|
||||||
|
|
||||||
echo_i "test $n: views key not allowed - query refused"
|
echo_i "test $n: views key not allowed - query refused"
|
||||||
ret=0
|
ret=0
|
||||||
@ -490,7 +479,7 @@ index 791a1a4..95cd971 100644
|
|||||||
grep 'status: REFUSED' dig.out.ns2.$n > /dev/null || ret=1
|
grep 'status: REFUSED' dig.out.ns2.$n > /dev/null || ret=1
|
||||||
grep '^a.normal.example' dig.out.ns2.$n > /dev/null && ret=1
|
grep '^a.normal.example' dig.out.ns2.$n > /dev/null && ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
@@ -375,7 +375,7 @@ rndc_reload
|
@@ -367,7 +367,7 @@ rndc_reload ns2 10.53.0.2
|
||||||
|
|
||||||
echo_i "test $n: views key disallowed - query refused"
|
echo_i "test $n: views key disallowed - query refused"
|
||||||
ret=0
|
ret=0
|
||||||
@ -499,7 +488,7 @@ index 791a1a4..95cd971 100644
|
|||||||
grep 'status: REFUSED' dig.out.ns2.$n > /dev/null || ret=1
|
grep 'status: REFUSED' dig.out.ns2.$n > /dev/null || ret=1
|
||||||
grep '^a.normal.example' dig.out.ns2.$n > /dev/null && ret=1
|
grep '^a.normal.example' dig.out.ns2.$n > /dev/null && ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
@@ -508,7 +508,7 @@ status=`expr $status + $ret`
|
@@ -500,7 +500,7 @@ status=`expr $status + $ret`
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo_i "test $n: zone key allowed - query allowed"
|
echo_i "test $n: zone key allowed - query allowed"
|
||||||
ret=0
|
ret=0
|
||||||
@ -508,7 +497,7 @@ index 791a1a4..95cd971 100644
|
|||||||
grep 'status: NOERROR' dig.out.ns2.$n > /dev/null || ret=1
|
grep 'status: NOERROR' dig.out.ns2.$n > /dev/null || ret=1
|
||||||
grep '^a.keyallow.example' dig.out.ns2.$n > /dev/null || ret=1
|
grep '^a.keyallow.example' dig.out.ns2.$n > /dev/null || ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
@@ -518,7 +518,7 @@ status=`expr $status + $ret`
|
@@ -510,7 +510,7 @@ status=`expr $status + $ret`
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo_i "test $n: zone key not allowed - query refused"
|
echo_i "test $n: zone key not allowed - query refused"
|
||||||
ret=0
|
ret=0
|
||||||
@ -517,7 +506,7 @@ index 791a1a4..95cd971 100644
|
|||||||
grep 'status: REFUSED' dig.out.ns2.$n > /dev/null || ret=1
|
grep 'status: REFUSED' dig.out.ns2.$n > /dev/null || ret=1
|
||||||
grep '^a.keyallow.example' dig.out.ns2.$n > /dev/null && ret=1
|
grep '^a.keyallow.example' dig.out.ns2.$n > /dev/null && ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
@@ -528,7 +528,7 @@ status=`expr $status + $ret`
|
@@ -520,7 +520,7 @@ status=`expr $status + $ret`
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo_i "test $n: zone key disallowed - query refused"
|
echo_i "test $n: zone key disallowed - query refused"
|
||||||
ret=0
|
ret=0
|
||||||
@ -527,7 +516,7 @@ index 791a1a4..95cd971 100644
|
|||||||
grep '^a.keydisallow.example' dig.out.ns2.$n > /dev/null && ret=1
|
grep '^a.keydisallow.example' dig.out.ns2.$n > /dev/null && ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
diff --git a/bin/tests/system/catz/ns1/named.conf.in b/bin/tests/system/catz/ns1/named.conf.in
|
diff --git a/bin/tests/system/catz/ns1/named.conf.in b/bin/tests/system/catz/ns1/named.conf.in
|
||||||
index 6856ec7..0ac1fa3 100644
|
index 1218669..e62715e 100644
|
||||||
--- a/bin/tests/system/catz/ns1/named.conf.in
|
--- a/bin/tests/system/catz/ns1/named.conf.in
|
||||||
+++ b/bin/tests/system/catz/ns1/named.conf.in
|
+++ b/bin/tests/system/catz/ns1/named.conf.in
|
||||||
@@ -61,5 +61,5 @@ zone "catalog4.example" {
|
@@ -61,5 +61,5 @@ zone "catalog4.example" {
|
||||||
@ -538,7 +527,7 @@ index 6856ec7..0ac1fa3 100644
|
|||||||
+ algorithm hmac-sha256;
|
+ algorithm hmac-sha256;
|
||||||
};
|
};
|
||||||
diff --git a/bin/tests/system/catz/ns2/named.conf.in b/bin/tests/system/catz/ns2/named.conf.in
|
diff --git a/bin/tests/system/catz/ns2/named.conf.in b/bin/tests/system/catz/ns2/named.conf.in
|
||||||
index dd3a9dc..77b8d96 100644
|
index 30333e6..4005152 100644
|
||||||
--- a/bin/tests/system/catz/ns2/named.conf.in
|
--- a/bin/tests/system/catz/ns2/named.conf.in
|
||||||
+++ b/bin/tests/system/catz/ns2/named.conf.in
|
+++ b/bin/tests/system/catz/ns2/named.conf.in
|
||||||
@@ -70,5 +70,5 @@ zone "catalog4.example" {
|
@@ -70,5 +70,5 @@ zone "catalog4.example" {
|
||||||
@ -549,7 +538,7 @@ index dd3a9dc..77b8d96 100644
|
|||||||
+ algorithm hmac-sha256;
|
+ algorithm hmac-sha256;
|
||||||
};
|
};
|
||||||
diff --git a/bin/tests/system/checkconf/bad-tsig.conf b/bin/tests/system/checkconf/bad-tsig.conf
|
diff --git a/bin/tests/system/checkconf/bad-tsig.conf b/bin/tests/system/checkconf/bad-tsig.conf
|
||||||
index 338dddb..90cd424 100644
|
index 21be03e..e57c308 100644
|
||||||
--- a/bin/tests/system/checkconf/bad-tsig.conf
|
--- a/bin/tests/system/checkconf/bad-tsig.conf
|
||||||
+++ b/bin/tests/system/checkconf/bad-tsig.conf
|
+++ b/bin/tests/system/checkconf/bad-tsig.conf
|
||||||
@@ -11,7 +11,7 @@
|
@@ -11,7 +11,7 @@
|
||||||
@ -562,10 +551,10 @@ index 338dddb..90cd424 100644
|
|||||||
};
|
};
|
||||||
|
|
||||||
diff --git a/bin/tests/system/checkconf/good.conf b/bin/tests/system/checkconf/good.conf
|
diff --git a/bin/tests/system/checkconf/good.conf b/bin/tests/system/checkconf/good.conf
|
||||||
index 2282f87..1359cf3 100644
|
index e09b9e8..2e824b3 100644
|
||||||
--- a/bin/tests/system/checkconf/good.conf
|
--- a/bin/tests/system/checkconf/good.conf
|
||||||
+++ b/bin/tests/system/checkconf/good.conf
|
+++ b/bin/tests/system/checkconf/good.conf
|
||||||
@@ -159,6 +159,6 @@ dyndb "name" "library.so" {
|
@@ -210,6 +210,6 @@ dyndb "name" "library.so" {
|
||||||
system;
|
system;
|
||||||
};
|
};
|
||||||
key "mykey" {
|
key "mykey" {
|
||||||
@ -573,473 +562,40 @@ index 2282f87..1359cf3 100644
|
|||||||
+ algorithm "hmac-sha256";
|
+ algorithm "hmac-sha256";
|
||||||
secret "qwertyuiopasdfgh";
|
secret "qwertyuiopasdfgh";
|
||||||
};
|
};
|
||||||
diff --git a/bin/tests/system/digdelv/ns2/example.db b/bin/tests/system/digdelv/ns2/example.db
|
|
||||||
index b66207a..359b220 100644
|
|
||||||
--- a/bin/tests/system/digdelv/ns2/example.db
|
|
||||||
+++ b/bin/tests/system/digdelv/ns2/example.db
|
|
||||||
@@ -38,12 +38,15 @@ foo SSHFP 2 1 123456789abcdef67890123456789abcdef67890
|
|
||||||
;;
|
|
||||||
;; we are not testing DNSSEC behavior, so we don't care about the semantics
|
|
||||||
;; of the following records.
|
|
||||||
-dnskey 300 DNSKEY 256 3 1 (
|
|
||||||
- AQPTpWyReB/e9Ii6mVGnakS8hX2zkh/iUYAg
|
|
||||||
- +Ge4noWROpTWOIBvm76zeJPWs4Zfqa1IsswD
|
|
||||||
- Ix5Mqeg0zwclz59uecKsKyx5w9IhtZ8plc4R
|
|
||||||
- b9VIE5x7KNHAYTvTO5d4S8M=
|
|
||||||
- )
|
|
||||||
+dnskey 300 DNSKEY 256 3 8 (
|
|
||||||
+ AwEAAaWmCoDpj2K59zcpqnmnQM7IC/XbjS6jIP7uTBR4X7p1bdQJzAeo
|
|
||||||
+ EnMhnpnxPp0j+20eZm4847DB2U+HuHy79Mvqd3aozTmfBJvzjKs9qyba
|
|
||||||
+ zY/ZHn6BDYxNJiFfjSS/VJ1KuQPDbpCzhm2hbvT5s9nSOaG0WyRk+d+R
|
|
||||||
+ qEca11E7ZKkmmNiGlyzMAgfmTTBwgxWBAAhvd9nU1GqD6eQ6Z63hpTc/
|
|
||||||
+ KDIHnFTo7pOcZ4z5urIKUMCMcFytedETlEoR5CIWGPdQq2eIEEMfn5ld
|
|
||||||
+ QqdEZRHVErD9og8aluJ2s767HZb8LzjCfYgBFoT9/n48T75oZLEKtSkG
|
|
||||||
+ /idCeeQlaLU=
|
|
||||||
+ )
|
|
||||||
|
|
||||||
; TTL of 3 weeks
|
|
||||||
weeks 1814400 A 10.53.0.2
|
|
||||||
diff --git a/bin/tests/system/digdelv/tests.sh b/bin/tests/system/digdelv/tests.sh
|
|
||||||
index a3ebc31..0d9b9b8 100644
|
|
||||||
--- a/bin/tests/system/digdelv/tests.sh
|
|
||||||
+++ b/bin/tests/system/digdelv/tests.sh
|
|
||||||
@@ -173,7 +173,7 @@ if [ -x "$DIG" ] ; then
|
|
||||||
echo_i "checking dig +rrcomments works for DNSKEY($n)"
|
|
||||||
ret=0
|
|
||||||
$DIG $DIGOPTS +tcp @10.53.0.3 +rrcomments DNSKEY dnskey.example > dig.out.test$n || ret=1
|
|
||||||
- grep "; ZSK; alg = RSAMD5 ; key id = 30795" < dig.out.test$n > /dev/null || ret=1
|
|
||||||
+ grep "; ZSK; alg = RSASHA256 ; key id = 36895$" < dig.out.test$n > /dev/null || ret=1
|
|
||||||
check_ttl_range dig.out.test$n "DNSKEY" 300 || ret=1
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
|
||||||
status=`expr $status + $ret`
|
|
||||||
@@ -182,7 +182,7 @@ if [ -x "$DIG" ] ; then
|
|
||||||
echo_i "checking dig +short +rrcomments works for DNSKEY ($n)"
|
|
||||||
ret=0
|
|
||||||
$DIG $DIGOPTS +tcp @10.53.0.3 +short +rrcomments DNSKEY dnskey.example > dig.out.test$n || ret=1
|
|
||||||
- grep "; ZSK; alg = RSAMD5 ; key id = 30795" < dig.out.test$n > /dev/null || ret=1
|
|
||||||
+ grep "; ZSK; alg = RSASHA256 ; key id = 36895$" < dig.out.test$n > /dev/null || ret=1
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
|
||||||
status=`expr $status + $ret`
|
|
||||||
|
|
||||||
@@ -190,7 +190,7 @@ if [ -x "$DIG" ] ; then
|
|
||||||
echo_i "checking dig +short +nosplit works($n)"
|
|
||||||
ret=0
|
|
||||||
$DIG $DIGOPTS +tcp @10.53.0.3 +short +nosplit DNSKEY dnskey.example > dig.out.test$n || ret=1
|
|
||||||
- grep "Z8plc4Rb9VIE5x7KNHAYTvTO5d4S8M=$" < dig.out.test$n > /dev/null || ret=1
|
|
||||||
+ grep "T9/n48T75oZLEKtSkG/idCeeQlaLU=$" < dig.out.test$n > /dev/null || ret=1
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
|
||||||
status=`expr $status + $ret`
|
|
||||||
|
|
||||||
@@ -198,7 +198,7 @@ if [ -x "$DIG" ] ; then
|
|
||||||
echo_i "checking dig +short +rrcomments works($n)"
|
|
||||||
ret=0
|
|
||||||
$DIG $DIGOPTS +tcp @10.53.0.3 +short +rrcomments DNSKEY dnskey.example > dig.out.test$n || ret=1
|
|
||||||
- grep "S8M= ; ZSK; alg = RSAMD5 ; key id = 30795$" < dig.out.test$n > /dev/null || ret=1
|
|
||||||
+ grep "aLU= ; ZSK; alg = RSASHA256 ; key id = 36895$" < dig.out.test$n > /dev/null || ret=1
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
|
||||||
status=`expr $status + $ret`
|
|
||||||
|
|
||||||
@@ -215,7 +215,7 @@ if [ -x "$DIG" ] ; then
|
|
||||||
echo_i "checking dig +short +rrcomments works($n)"
|
|
||||||
ret=0
|
|
||||||
$DIG $DIGOPTS +tcp @10.53.0.3 +short +rrcomments DNSKEY dnskey.example > dig.out.test$n || ret=1
|
|
||||||
- grep "S8M= ; ZSK; alg = RSAMD5 ; key id = 30795$" < dig.out.test$n > /dev/null || ret=1
|
|
||||||
+ grep "aLU= ; ZSK; alg = RSASHA256 ; key id = 36895$" < dig.out.test$n > /dev/null || ret=1
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
|
||||||
status=`expr $status + $ret`
|
|
||||||
|
|
||||||
@@ -846,7 +846,7 @@ if [ -x ${DELV} ] ; then
|
|
||||||
echo_i "checking delv +rrcomments works for DNSKEY($n)"
|
|
||||||
ret=0
|
|
||||||
$DELV $DELVOPTS +tcp @10.53.0.3 +rrcomments DNSKEY dnskey.example > delv.out.test$n || ret=1
|
|
||||||
- grep "; ZSK; alg = RSAMD5 ; key id = 30795" < delv.out.test$n > /dev/null || ret=1
|
|
||||||
+ grep "; ZSK; alg = RSASHA256 ; key id = 36895" < delv.out.test$n > /dev/null || ret=1
|
|
||||||
check_ttl_range delv.out.test$n "DNSKEY" 300 || ret=1
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
|
||||||
status=`expr $status + $ret`
|
|
||||||
@@ -855,7 +855,7 @@ if [ -x ${DELV} ] ; then
|
|
||||||
echo_i "checking delv +short +rrcomments works for DNSKEY ($n)"
|
|
||||||
ret=0
|
|
||||||
$DELV $DELVOPTS +tcp @10.53.0.3 +short +rrcomments DNSKEY dnskey.example > delv.out.test$n || ret=1
|
|
||||||
- grep "; ZSK; alg = RSAMD5 ; key id = 30795" < delv.out.test$n > /dev/null || ret=1
|
|
||||||
+ grep "; ZSK; alg = RSASHA256 ; key id = 36895" < delv.out.test$n > /dev/null || ret=1
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
|
||||||
status=`expr $status + $ret`
|
|
||||||
|
|
||||||
@@ -863,7 +863,7 @@ if [ -x ${DELV} ] ; then
|
|
||||||
echo_i "checking delv +short +rrcomments works ($n)"
|
|
||||||
ret=0
|
|
||||||
$DELV $DELVOPTS +tcp @10.53.0.3 +short +rrcomments DNSKEY dnskey.example > delv.out.test$n || ret=1
|
|
||||||
- grep "S8M= ; ZSK; alg = RSAMD5 ; key id = 30795$" < delv.out.test$n > /dev/null || ret=1
|
|
||||||
+ grep "aLU= ; ZSK; alg = RSASHA256 ; key id = 36895$" < delv.out.test$n > /dev/null || ret=1
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
|
||||||
status=`expr $status + $ret`
|
|
||||||
|
|
||||||
@@ -871,7 +871,7 @@ if [ -x ${DELV} ] ; then
|
|
||||||
echo_i "checking delv +short +nosplit works ($n)"
|
|
||||||
ret=0
|
|
||||||
$DELV $DELVOPTS +tcp @10.53.0.3 +short +nosplit DNSKEY dnskey.example > delv.out.test$n || ret=1
|
|
||||||
- grep "Z8plc4Rb9VIE5x7KNHAYTvTO5d4S8M=" < delv.out.test$n > /dev/null || ret=1
|
|
||||||
+ grep "T9/n48T75oZLEKtSkG/idCeeQlaLU=" < delv.out.test$n > /dev/null || ret=1
|
|
||||||
if test `wc -l < delv.out.test$n` != 1 ; then ret=1 ; fi
|
|
||||||
f=`awk '{print NF}' < delv.out.test$n`
|
|
||||||
test "${f:-0}" -eq 14 || ret=1
|
|
||||||
@@ -882,7 +882,7 @@ if [ -x ${DELV} ] ; then
|
|
||||||
echo_i "checking delv +short +nosplit +norrcomments works ($n)"
|
|
||||||
ret=0
|
|
||||||
$DELV $DELVOPTS +tcp @10.53.0.3 +short +nosplit +norrcomments DNSKEY dnskey.example > delv.out.test$n || ret=1
|
|
||||||
- grep "Z8plc4Rb9VIE5x7KNHAYTvTO5d4S8M=$" < delv.out.test$n > /dev/null || ret=1
|
|
||||||
+ grep "T9/n48T75oZLEKtSkG/idCeeQlaLU=$" < delv.out.test$n > /dev/null || ret=1
|
|
||||||
if test `wc -l < delv.out.test$n` != 1 ; then ret=1 ; fi
|
|
||||||
f=`awk '{print NF}' < delv.out.test$n`
|
|
||||||
test "${f:-0}" -eq 4 || ret=1
|
|
||||||
diff --git a/bin/tests/system/dlv/ns1/sign.sh b/bin/tests/system/dlv/ns1/sign.sh
|
|
||||||
index 14ca5db..3f522d0 100755
|
|
||||||
--- a/bin/tests/system/dlv/ns1/sign.sh
|
|
||||||
+++ b/bin/tests/system/dlv/ns1/sign.sh
|
|
||||||
@@ -23,8 +23,8 @@ infile=root.db.in
|
|
||||||
zonefile=root.db
|
|
||||||
outfile=root.signed
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
-keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 1024 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 1024 -n zone $zone 2> /dev/null`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
|
|
||||||
diff --git a/bin/tests/system/dlv/ns2/sign.sh b/bin/tests/system/dlv/ns2/sign.sh
|
|
||||||
index d870798..b0ab372 100755
|
|
||||||
--- a/bin/tests/system/dlv/ns2/sign.sh
|
|
||||||
+++ b/bin/tests/system/dlv/ns2/sign.sh
|
|
||||||
@@ -24,8 +24,8 @@ zonefile=druz.db
|
|
||||||
outfile=druz.pre
|
|
||||||
dlvzone=utld.
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
-keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 1024 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 1024 -n zone $zone 2> /dev/null`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
|
|
||||||
diff --git a/bin/tests/system/dlv/ns6/sign.sh b/bin/tests/system/dlv/ns6/sign.sh
|
|
||||||
index ba39f90..f20a2dd 100755
|
|
||||||
--- a/bin/tests/system/dlv/ns6/sign.sh
|
|
||||||
+++ b/bin/tests/system/dlv/ns6/sign.sh
|
|
||||||
@@ -16,13 +16,15 @@ SYSTESTDIR=dlv
|
|
||||||
|
|
||||||
echo_i "dlv/ns6/sign.sh"
|
|
||||||
|
|
||||||
+bits=1024
|
|
||||||
+
|
|
||||||
zone=grand.child1.utld.
|
|
||||||
infile=child.db.in
|
|
||||||
zonefile=grand.child1.utld.db
|
|
||||||
outfile=grand.child1.signed
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
-keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname1=`$KEYGEN -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
+keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
|
|
||||||
@@ -36,8 +38,8 @@ zonefile=grand.child3.utld.db
|
|
||||||
outfile=grand.child3.signed
|
|
||||||
dlvzone=dlv.utld.
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
-keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname1=`$KEYGEN -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
+keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
|
|
||||||
@@ -51,8 +53,8 @@ zonefile=grand.child4.utld.db
|
|
||||||
outfile=grand.child4.signed
|
|
||||||
dlvzone=dlv.utld.
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
-keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname1=`$KEYGEN -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
+keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
|
|
||||||
@@ -66,8 +68,8 @@ zonefile=grand.child5.utld.db
|
|
||||||
outfile=grand.child5.signed
|
|
||||||
dlvzone=dlv.utld.
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
-keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname1=`$KEYGEN -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
+keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
|
|
||||||
@@ -81,8 +83,8 @@ zonefile=grand.child7.utld.db
|
|
||||||
outfile=grand.child7.signed
|
|
||||||
dlvzone=dlv.utld.
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
-keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname1=`$KEYGEN -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
+keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
|
|
||||||
@@ -96,8 +98,8 @@ zonefile=grand.child8.utld.db
|
|
||||||
outfile=grand.child8.signed
|
|
||||||
dlvzone=dlv.utld.
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
-keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname1=`$KEYGEN -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
+keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
|
|
||||||
@@ -111,8 +113,8 @@ zonefile=grand.child9.utld.db
|
|
||||||
outfile=grand.child9.signed
|
|
||||||
dlvzone=dlv.utld.
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
-keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname1=`$KEYGEN -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
+keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
|
|
||||||
@@ -125,8 +127,8 @@ zonefile=grand.child10.utld.db
|
|
||||||
outfile=grand.child10.signed
|
|
||||||
dlvzone=dlv.utld.
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
-keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname1=`$KEYGEN -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
+keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
|
|
||||||
@@ -138,8 +140,8 @@ infile=child.db.in
|
|
||||||
zonefile=grand.child1.druz.db
|
|
||||||
outfile=grand.child1.druz.signed
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
-keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname1=`$KEYGEN -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
+keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
|
|
||||||
@@ -153,8 +155,8 @@ zonefile=grand.child3.druz.db
|
|
||||||
outfile=grand.child3.druz.signed
|
|
||||||
dlvzone=dlv.druz.
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
-keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname1=`$KEYGEN -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
+keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
|
|
||||||
@@ -168,8 +170,8 @@ zonefile=grand.child4.druz.db
|
|
||||||
outfile=grand.child4.druz.signed
|
|
||||||
dlvzone=dlv.druz.
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
-keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname1=`$KEYGEN -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
+keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
|
|
||||||
@@ -183,8 +185,8 @@ zonefile=grand.child5.druz.db
|
|
||||||
outfile=grand.child5.druz.signed
|
|
||||||
dlvzone=dlv.druz.
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
-keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname1=`$KEYGEN -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
+keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
|
|
||||||
@@ -198,8 +200,8 @@ zonefile=grand.child7.druz.db
|
|
||||||
outfile=grand.child7.druz.signed
|
|
||||||
dlvzone=dlv.druz.
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
-keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname1=`$KEYGEN -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
+keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
|
|
||||||
@@ -213,8 +215,8 @@ zonefile=grand.child8.druz.db
|
|
||||||
outfile=grand.child8.druz.signed
|
|
||||||
dlvzone=dlv.druz.
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
-keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname1=`$KEYGEN -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
+keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
|
|
||||||
@@ -228,8 +230,8 @@ zonefile=grand.child9.druz.db
|
|
||||||
outfile=grand.child9.druz.signed
|
|
||||||
dlvzone=dlv.druz.
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
-keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname1=`$KEYGEN -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
+keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
|
|
||||||
@@ -242,8 +244,8 @@ zonefile=grand.child10.druz.db
|
|
||||||
outfile=grand.child10.druz.signed
|
|
||||||
dlvzone=dlv.druz.
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
-keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname1=`$KEYGEN -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
+keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b $bits -n zone $zone 2> /dev/null`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
|
|
||||||
diff --git a/bin/tests/system/dnssec/ns2/sign.sh b/bin/tests/system/dnssec/ns2/sign.sh
|
|
||||||
index d401823..139c7ad 100644
|
|
||||||
--- a/bin/tests/system/dnssec/ns2/sign.sh
|
|
||||||
+++ b/bin/tests/system/dnssec/ns2/sign.sh
|
|
||||||
@@ -126,8 +126,8 @@ zone=in-addr.arpa.
|
|
||||||
infile=in-addr.arpa.db.in
|
|
||||||
zonefile=in-addr.arpa.db
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -q -r $RANDFILE -a DSA -b 768 -n zone $zone`
|
|
||||||
-keyname2=`$KEYGEN -q -r $RANDFILE -a DSA -b 768 -n zone $zone`
|
|
||||||
+keyname1=`$KEYGEN -q -r $RANDFILE -a DSA -b 1024 -n zone $zone`
|
|
||||||
+keyname2=`$KEYGEN -q -r $RANDFILE -a DSA -b 1024 -n zone $zone`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
$SIGNER -P -g -r $RANDFILE -o $zone -k $keyname1 $zonefile $keyname2 > /dev/null
|
|
||||||
@@ -138,7 +138,7 @@ privzone=private.secure.example
|
|
||||||
privinfile=private.secure.example.db.in
|
|
||||||
privzonefile=private.secure.example.db
|
|
||||||
|
|
||||||
-privkeyname=`$KEYGEN -q -r $RANDFILE -a RSAMD5 -b 768 -n zone $privzone`
|
|
||||||
+privkeyname=`$KEYGEN -q -r $RANDFILE -a RSASHA256 -b 1024 -n zone $privzone`
|
|
||||||
|
|
||||||
cat $privinfile $privkeyname.key >$privzonefile
|
|
||||||
|
|
||||||
@@ -152,7 +152,7 @@ dlvinfile=dlv.db.in
|
|
||||||
dlvzonefile=dlv.db
|
|
||||||
dlvsetfile=dlvset-${privzone}${TP}
|
|
||||||
|
|
||||||
-dlvkeyname=`$KEYGEN -q -r $RANDFILE -a RSAMD5 -b 768 -n zone $dlvzone`
|
|
||||||
+dlvkeyname=`$KEYGEN -q -r $RANDFILE -a RSASHA256 -b 1024 -n zone $dlvzone`
|
|
||||||
|
|
||||||
cat $dlvinfile $dlvkeyname.key $dlvsetfile > $dlvzonefile
|
|
||||||
|
|
||||||
diff --git a/bin/tests/system/dnssec/ns5/trusted.conf.bad b/bin/tests/system/dnssec/ns5/trusted.conf.bad
|
|
||||||
index 75cf699..b4d848c 100644
|
|
||||||
--- a/bin/tests/system/dnssec/ns5/trusted.conf.bad
|
|
||||||
+++ b/bin/tests/system/dnssec/ns5/trusted.conf.bad
|
|
||||||
@@ -10,5 +10,5 @@
|
|
||||||
*/
|
|
||||||
|
|
||||||
trusted-keys {
|
|
||||||
- "." 256 3 1 "AQO6Cl+slAf+iuieDim9L3kujFHQD7s/IOj03ClMOpKYcTXtK4mRpuULVfvWxDi9Ew/gj0xLnnX7z9OJHIxLI+DSrAHd8Dm0XfBEAtVtJSn70GaPZgnLMw1rk5ap2DsEoWk=";
|
|
||||||
+ "." 256 3 8 "AwEAAarwAdjV4gIhpBCjXVAScRFEx3co7k8smJdxrnqoGsl5NB7EZ9jRdgvCXbJn6v8y9jlNWVHvaC8ilhfhLh0A1vLWiWv4ijd/12xcnrY7xpG7Cu3YkxUxaXJ7Jdg/Iw1+9mGgXF1v4UbCIcw/3U3cxyk7OxYg+VSb5KBAQSR0upxV";
|
|
||||||
};
|
|
||||||
diff --git a/bin/tests/system/dnssec/tests.sh b/bin/tests/system/dnssec/tests.sh
|
|
||||||
index 30f7fc5..2f34b6d 100644
|
|
||||||
--- a/bin/tests/system/dnssec/tests.sh
|
|
||||||
+++ b/bin/tests/system/dnssec/tests.sh
|
|
||||||
@@ -3281,8 +3281,8 @@ do
|
|
||||||
alg=`expr $alg + 1`
|
|
||||||
continue;;
|
|
||||||
3) size="-b 512";;
|
|
||||||
- 5) size="-b 512";;
|
|
||||||
- 6) size="-b 512";;
|
|
||||||
+ 5) size="-b 1024";;
|
|
||||||
+ 6) size="-b 1024";;
|
|
||||||
7) size="-b 512";;
|
|
||||||
8) size="-b 512";;
|
|
||||||
10) size="-b 1024";;
|
|
||||||
diff --git a/bin/tests/system/feature-test.c b/bin/tests/system/feature-test.c
|
diff --git a/bin/tests/system/feature-test.c b/bin/tests/system/feature-test.c
|
||||||
index 5e473ab..b08692e 100644
|
index 877504f..577660a 100644
|
||||||
--- a/bin/tests/system/feature-test.c
|
--- a/bin/tests/system/feature-test.c
|
||||||
+++ b/bin/tests/system/feature-test.c
|
+++ b/bin/tests/system/feature-test.c
|
||||||
@@ -19,6 +19,7 @@
|
@@ -14,6 +14,7 @@
|
||||||
|
#include <string.h>
|
||||||
|
#include <unistd.h>
|
||||||
|
|
||||||
|
+#include <isc/md.h>
|
||||||
|
#include <isc/net.h>
|
||||||
#include <isc/print.h>
|
#include <isc/print.h>
|
||||||
#include <isc/util.h>
|
#include <isc/util.h>
|
||||||
#include <isc/net.h>
|
@@ -186,6 +187,19 @@ main(int argc, char **argv) {
|
||||||
+#include <isc/md5.h>
|
#endif /* ifdef DLZ_FILESYSTEM */
|
||||||
#include <dns/edns.h>
|
|
||||||
|
|
||||||
#ifdef WIN32
|
|
||||||
@@ -47,6 +48,7 @@ usage() {
|
|
||||||
fprintf(stderr, "\t--have-geoip\n");
|
|
||||||
fprintf(stderr, "\t--have-libxml2\n");
|
|
||||||
fprintf(stderr, "\t--ipv6only=no\n");
|
|
||||||
+ fprintf(stderr, "\t--md5\n");
|
|
||||||
fprintf(stderr, "\t--rpz-log-qtype-qclass\n");
|
|
||||||
fprintf(stderr, "\t--rpz-nsdname\n");
|
|
||||||
fprintf(stderr, "\t--rpz-nsip\n");
|
|
||||||
@@ -194,6 +196,18 @@ main(int argc, char **argv) {
|
|
||||||
#endif
|
|
||||||
}
|
}
|
||||||
|
|
||||||
+ if (strcmp(argv[1], "--md5") == 0) {
|
+ if (strcmp(argv[1], "--md5") == 0) {
|
||||||
+#ifdef PK11_MD5_DISABLE
|
+ unsigned char digest[ISC_MAX_MD_SIZE];
|
||||||
+ return (1);
|
+ const unsigned char test[] = "test";
|
||||||
+#else
|
+ unsigned int size = sizeof(digest);
|
||||||
+ if (isc_md5_available()) {
|
+
|
||||||
|
+ if (isc_md(ISC_MD_MD5, test, sizeof(test),
|
||||||
|
+ digest, &size) == ISC_R_SUCCESS) {
|
||||||
+ return (0);
|
+ return (0);
|
||||||
+ } else {
|
+ } else {
|
||||||
+ return (1);
|
+ return (1);
|
||||||
+ }
|
+ }
|
||||||
+#endif
|
|
||||||
+ }
|
+ }
|
||||||
+
|
+
|
||||||
if (strcmp(argv[1], "--rpz-nsip") == 0) {
|
if (strcmp(argv[1], "--with-idn") == 0) {
|
||||||
#ifdef ENABLE_RPZ_NSIP
|
#ifdef HAVE_LIBIDN2
|
||||||
return (0);
|
return (0);
|
||||||
diff --git a/bin/tests/system/filter-aaaa/ns1/sign.sh b/bin/tests/system/filter-aaaa/ns1/sign.sh
|
|
||||||
index 479f98c..4d4a765 100755
|
|
||||||
--- a/bin/tests/system/filter-aaaa/ns1/sign.sh
|
|
||||||
+++ b/bin/tests/system/filter-aaaa/ns1/sign.sh
|
|
||||||
@@ -21,8 +21,8 @@ infile=signed.db.in
|
|
||||||
zonefile=signed.db.signed
|
|
||||||
outfile=signed.db.signed
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
-keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 1024 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 1024 -n zone $zone 2> /dev/null`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
|
|
||||||
diff --git a/bin/tests/system/filter-aaaa/ns4/sign.sh b/bin/tests/system/filter-aaaa/ns4/sign.sh
|
|
||||||
index 479f98c..4d4a765 100755
|
|
||||||
--- a/bin/tests/system/filter-aaaa/ns4/sign.sh
|
|
||||||
+++ b/bin/tests/system/filter-aaaa/ns4/sign.sh
|
|
||||||
@@ -21,8 +21,8 @@ infile=signed.db.in
|
|
||||||
zonefile=signed.db.signed
|
|
||||||
outfile=signed.db.signed
|
|
||||||
|
|
||||||
-keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
-keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 768 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname1=`$KEYGEN -r $RANDFILE -a DSA -b 1024 -n zone $zone 2> /dev/null`
|
|
||||||
+keyname2=`$KEYGEN -f KSK -r $RANDFILE -a DSA -b 1024 -n zone $zone 2> /dev/null`
|
|
||||||
|
|
||||||
cat $infile $keyname1.key $keyname2.key >$zonefile
|
|
||||||
|
|
||||||
diff --git a/bin/tests/system/notify/ns5/named.conf.in b/bin/tests/system/notify/ns5/named.conf.in
|
diff --git a/bin/tests/system/notify/ns5/named.conf.in b/bin/tests/system/notify/ns5/named.conf.in
|
||||||
index 157ef16..b802288 100644
|
index 1ee8df4..2b75d9a 100644
|
||||||
--- a/bin/tests/system/notify/ns5/named.conf.in
|
--- a/bin/tests/system/notify/ns5/named.conf.in
|
||||||
+++ b/bin/tests/system/notify/ns5/named.conf.in
|
+++ b/bin/tests/system/notify/ns5/named.conf.in
|
||||||
@@ -10,17 +10,17 @@
|
@@ -10,17 +10,17 @@
|
||||||
@ -1064,7 +620,7 @@ index 157ef16..b802288 100644
|
|||||||
};
|
};
|
||||||
|
|
||||||
diff --git a/bin/tests/system/notify/tests.sh b/bin/tests/system/notify/tests.sh
|
diff --git a/bin/tests/system/notify/tests.sh b/bin/tests/system/notify/tests.sh
|
||||||
index f9fd3f5..916af75 100644
|
index 3d7e0b7..ec4d9a7 100644
|
||||||
--- a/bin/tests/system/notify/tests.sh
|
--- a/bin/tests/system/notify/tests.sh
|
||||||
+++ b/bin/tests/system/notify/tests.sh
|
+++ b/bin/tests/system/notify/tests.sh
|
||||||
@@ -212,16 +212,16 @@ ret=0
|
@@ -212,16 +212,16 @@ ret=0
|
||||||
@ -1088,10 +644,10 @@ index f9fd3f5..916af75 100644
|
|||||||
grep "test string" dig.out.b.ns5.test$n > /dev/null &&
|
grep "test string" dig.out.b.ns5.test$n > /dev/null &&
|
||||||
grep "test string" dig.out.c.ns5.test$n > /dev/null &&
|
grep "test string" dig.out.c.ns5.test$n > /dev/null &&
|
||||||
diff --git a/bin/tests/system/nsupdate/ns1/named.conf.in b/bin/tests/system/nsupdate/ns1/named.conf.in
|
diff --git a/bin/tests/system/nsupdate/ns1/named.conf.in b/bin/tests/system/nsupdate/ns1/named.conf.in
|
||||||
index b0ded3a..cb80269 100644
|
index b51e700..436c97d 100644
|
||||||
--- a/bin/tests/system/nsupdate/ns1/named.conf.in
|
--- a/bin/tests/system/nsupdate/ns1/named.conf.in
|
||||||
+++ b/bin/tests/system/nsupdate/ns1/named.conf.in
|
+++ b/bin/tests/system/nsupdate/ns1/named.conf.in
|
||||||
@@ -32,7 +32,7 @@ controls {
|
@@ -37,7 +37,7 @@ controls {
|
||||||
};
|
};
|
||||||
|
|
||||||
key altkey {
|
key altkey {
|
||||||
@ -1101,10 +657,10 @@ index b0ded3a..cb80269 100644
|
|||||||
};
|
};
|
||||||
|
|
||||||
diff --git a/bin/tests/system/nsupdate/ns2/named.conf.in b/bin/tests/system/nsupdate/ns2/named.conf.in
|
diff --git a/bin/tests/system/nsupdate/ns2/named.conf.in b/bin/tests/system/nsupdate/ns2/named.conf.in
|
||||||
index e6e2382..b0a94e0 100644
|
index da6b3b4..c547e47 100644
|
||||||
--- a/bin/tests/system/nsupdate/ns2/named.conf.in
|
--- a/bin/tests/system/nsupdate/ns2/named.conf.in
|
||||||
+++ b/bin/tests/system/nsupdate/ns2/named.conf.in
|
+++ b/bin/tests/system/nsupdate/ns2/named.conf.in
|
||||||
@@ -33,7 +33,7 @@ controls {
|
@@ -32,7 +32,7 @@ controls {
|
||||||
};
|
};
|
||||||
|
|
||||||
key altkey {
|
key altkey {
|
||||||
@ -1114,31 +670,30 @@ index e6e2382..b0a94e0 100644
|
|||||||
};
|
};
|
||||||
|
|
||||||
diff --git a/bin/tests/system/nsupdate/setup.sh b/bin/tests/system/nsupdate/setup.sh
|
diff --git a/bin/tests/system/nsupdate/setup.sh b/bin/tests/system/nsupdate/setup.sh
|
||||||
index 2b3b154..8240c42 100644
|
index c055da3..4e1242b 100644
|
||||||
--- a/bin/tests/system/nsupdate/setup.sh
|
--- a/bin/tests/system/nsupdate/setup.sh
|
||||||
+++ b/bin/tests/system/nsupdate/setup.sh
|
+++ b/bin/tests/system/nsupdate/setup.sh
|
||||||
@@ -68,7 +68,12 @@ EOF
|
@@ -56,7 +56,11 @@ EOF
|
||||||
|
|
||||||
$DDNSCONFGEN -q -r $RANDFILE -z example.nil > ns1/ddns.key
|
$DDNSCONFGEN -q -z example.nil > ns1/ddns.key
|
||||||
|
|
||||||
-$DDNSCONFGEN -q -r $RANDFILE -a hmac-md5 -k md5-key -z keytests.nil > ns1/md5.key
|
-$DDNSCONFGEN -q -a hmac-md5 -k md5-key -z keytests.nil > ns1/md5.key
|
||||||
+if $FEATURETEST --md5; then
|
+if $FEATURETEST --md5; then
|
||||||
+ $DDNSCONFGEN -q -r $RANDFILE -a hmac-md5 -k md5-key -z keytests.nil > ns1/md5.key
|
+ $DDNSCONFGEN -q -a hmac-md5 -k md5-key -z keytests.nil > ns1/md5.key
|
||||||
+else
|
+else
|
||||||
+ echo -n > ns1/md5.key
|
+ echo -n > ns1/md5.key
|
||||||
+fi
|
+fi
|
||||||
+
|
$DDNSCONFGEN -q -a hmac-sha1 -k sha1-key -z keytests.nil > ns1/sha1.key
|
||||||
$DDNSCONFGEN -q -r $RANDFILE -a hmac-sha1 -k sha1-key -z keytests.nil > ns1/sha1.key
|
$DDNSCONFGEN -q -a hmac-sha224 -k sha224-key -z keytests.nil > ns1/sha224.key
|
||||||
$DDNSCONFGEN -q -r $RANDFILE -a hmac-sha224 -k sha224-key -z keytests.nil > ns1/sha224.key
|
$DDNSCONFGEN -q -a hmac-sha256 -k sha256-key -z keytests.nil > ns1/sha256.key
|
||||||
$DDNSCONFGEN -q -r $RANDFILE -a hmac-sha256 -k sha256-key -z keytests.nil > ns1/sha256.key
|
|
||||||
diff --git a/bin/tests/system/nsupdate/tests.sh b/bin/tests/system/nsupdate/tests.sh
|
diff --git a/bin/tests/system/nsupdate/tests.sh b/bin/tests/system/nsupdate/tests.sh
|
||||||
index 60cf7ee..f8994ff 100755
|
index b35d797..41c128e 100755
|
||||||
--- a/bin/tests/system/nsupdate/tests.sh
|
--- a/bin/tests/system/nsupdate/tests.sh
|
||||||
+++ b/bin/tests/system/nsupdate/tests.sh
|
+++ b/bin/tests/system/nsupdate/tests.sh
|
||||||
@@ -804,7 +804,14 @@ fi
|
@@ -797,7 +797,14 @@ fi
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
ret=0
|
ret=0
|
||||||
echo_i "check TSIG key algorithms ($n)"
|
echo_i "check TSIG key algorithms (nsupdate -k) ($n)"
|
||||||
-for alg in md5 sha1 sha224 sha256 sha384 sha512; do
|
-for alg in md5 sha1 sha224 sha256 sha384 sha512; do
|
||||||
+if $FEATURETEST --md5
|
+if $FEATURETEST --md5
|
||||||
+then
|
+then
|
||||||
@ -1151,7 +706,7 @@ index 60cf7ee..f8994ff 100755
|
|||||||
$NSUPDATE -k ns1/${alg}.key <<END > /dev/null || ret=1
|
$NSUPDATE -k ns1/${alg}.key <<END > /dev/null || ret=1
|
||||||
server 10.53.0.1 ${PORT}
|
server 10.53.0.1 ${PORT}
|
||||||
update add ${alg}.keytests.nil. 600 A 10.10.10.3
|
update add ${alg}.keytests.nil. 600 A 10.10.10.3
|
||||||
@@ -812,7 +819,7 @@ send
|
@@ -805,7 +812,7 @@ send
|
||||||
END
|
END
|
||||||
done
|
done
|
||||||
sleep 2
|
sleep 2
|
||||||
@ -1160,11 +715,29 @@ index 60cf7ee..f8994ff 100755
|
|||||||
$DIG $DIGOPTS +short @10.53.0.1 ${alg}.keytests.nil | grep 10.10.10.3 > /dev/null 2>&1 || ret=1
|
$DIG $DIGOPTS +short @10.53.0.1 ${alg}.keytests.nil | grep 10.10.10.3 > /dev/null 2>&1 || ret=1
|
||||||
done
|
done
|
||||||
if [ $ret -ne 0 ]; then
|
if [ $ret -ne 0 ]; then
|
||||||
|
@@ -816,7 +823,7 @@ fi
|
||||||
|
n=`expr $n + 1`
|
||||||
|
ret=0
|
||||||
|
echo_i "check TSIG key algorithms (nsupdate -y) ($n)"
|
||||||
|
-for alg in md5 sha1 sha224 sha256 sha384 sha512; do
|
||||||
|
+for alg in $ALGS; do
|
||||||
|
secret=$(sed -n 's/.*secret "\(.*\)";.*/\1/p' ns1/${alg}.key)
|
||||||
|
$NSUPDATE -y "hmac-${alg}:${alg}-key:$secret" <<END > /dev/null || ret=1
|
||||||
|
server 10.53.0.1 ${PORT}
|
||||||
|
@@ -825,7 +832,7 @@ send
|
||||||
|
END
|
||||||
|
done
|
||||||
|
sleep 2
|
||||||
|
-for alg in md5 sha1 sha224 sha256 sha384 sha512; do
|
||||||
|
+for alg in $ALGS; do
|
||||||
|
$DIG $DIGOPTS +short @10.53.0.1 ${alg}.keytests.nil | grep 10.10.10.50 > /dev/null 2>&1 || ret=1
|
||||||
|
done
|
||||||
|
if [ $ret -ne 0 ]; then
|
||||||
diff --git a/bin/tests/system/rndc/setup.sh b/bin/tests/system/rndc/setup.sh
|
diff --git a/bin/tests/system/rndc/setup.sh b/bin/tests/system/rndc/setup.sh
|
||||||
index 2eb2cd5..36f5114 100644
|
index b59e7a7..04d5f5a 100644
|
||||||
--- a/bin/tests/system/rndc/setup.sh
|
--- a/bin/tests/system/rndc/setup.sh
|
||||||
+++ b/bin/tests/system/rndc/setup.sh
|
+++ b/bin/tests/system/rndc/setup.sh
|
||||||
@@ -35,7 +35,7 @@ make_key () {
|
@@ -33,7 +33,7 @@ make_key () {
|
||||||
sed 's/allow { 10.53.0.4/allow { any/' >> ns4/named.conf
|
sed 's/allow { 10.53.0.4/allow { any/' >> ns4/named.conf
|
||||||
}
|
}
|
||||||
|
|
||||||
@ -1174,7 +747,7 @@ index 2eb2cd5..36f5114 100644
|
|||||||
make_key 3 ${EXTRAPORT3} hmac-sha224
|
make_key 3 ${EXTRAPORT3} hmac-sha224
|
||||||
make_key 4 ${EXTRAPORT4} hmac-sha256
|
make_key 4 ${EXTRAPORT4} hmac-sha256
|
||||||
diff --git a/bin/tests/system/rndc/tests.sh b/bin/tests/system/rndc/tests.sh
|
diff --git a/bin/tests/system/rndc/tests.sh b/bin/tests/system/rndc/tests.sh
|
||||||
index 4e25e51..cb8934c 100644
|
index 9fd84ed..d0b188f 100644
|
||||||
--- a/bin/tests/system/rndc/tests.sh
|
--- a/bin/tests/system/rndc/tests.sh
|
||||||
+++ b/bin/tests/system/rndc/tests.sh
|
+++ b/bin/tests/system/rndc/tests.sh
|
||||||
@@ -348,15 +348,20 @@ if [ $ret != 0 ]; then echo_i "failed"; fi
|
@@ -348,15 +348,20 @@ if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
@ -1208,7 +781,7 @@ index 4e25e51..cb8934c 100644
|
|||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo_i "testing rndc with hmac-sha1 ($n)"
|
echo_i "testing rndc with hmac-sha1 ($n)"
|
||||||
diff --git a/bin/tests/system/tsig/ns1/named.conf.in b/bin/tests/system/tsig/ns1/named.conf.in
|
diff --git a/bin/tests/system/tsig/ns1/named.conf.in b/bin/tests/system/tsig/ns1/named.conf.in
|
||||||
index 4905ffd..958d9fb 100644
|
index 3470c4f..cf539cd 100644
|
||||||
--- a/bin/tests/system/tsig/ns1/named.conf.in
|
--- a/bin/tests/system/tsig/ns1/named.conf.in
|
||||||
+++ b/bin/tests/system/tsig/ns1/named.conf.in
|
+++ b/bin/tests/system/tsig/ns1/named.conf.in
|
||||||
@@ -21,10 +21,7 @@ options {
|
@@ -21,10 +21,7 @@ options {
|
||||||
@ -1252,20 +825,20 @@ index 0000000..0682194
|
|||||||
+ algorithm hmac-md5-80;
|
+ algorithm hmac-md5-80;
|
||||||
+};
|
+};
|
||||||
diff --git a/bin/tests/system/tsig/setup.sh b/bin/tests/system/tsig/setup.sh
|
diff --git a/bin/tests/system/tsig/setup.sh b/bin/tests/system/tsig/setup.sh
|
||||||
index f42aa79..bfcf4a6 100644
|
index e3b4a45..ae21d04 100644
|
||||||
--- a/bin/tests/system/tsig/setup.sh
|
--- a/bin/tests/system/tsig/setup.sh
|
||||||
+++ b/bin/tests/system/tsig/setup.sh
|
+++ b/bin/tests/system/tsig/setup.sh
|
||||||
@@ -15,3 +15,8 @@ SYSTEMTESTTOP=..
|
@@ -15,3 +15,8 @@ SYSTEMTESTTOP=..
|
||||||
copy_setports ns1/named.conf.in ns1/named.conf
|
$SHELL clean.sh
|
||||||
|
|
||||||
test -r $RANDFILE || $GENRANDOM $RANDOMSIZE $RANDFILE
|
copy_setports ns1/named.conf.in ns1/named.conf
|
||||||
+
|
+
|
||||||
+if $FEATURETEST --md5
|
+if $FEATURETEST --md5
|
||||||
+then
|
+then
|
||||||
+ cat ns1/rndc5.conf.in >> ns1/named.conf
|
+ cat ns1/rndc5.conf.in >> ns1/named.conf
|
||||||
+fi
|
+fi
|
||||||
diff --git a/bin/tests/system/tsig/tests.sh b/bin/tests/system/tsig/tests.sh
|
diff --git a/bin/tests/system/tsig/tests.sh b/bin/tests/system/tsig/tests.sh
|
||||||
index e0c2903..327fa50 100644
|
index 38d842a..668aa6f 100644
|
||||||
--- a/bin/tests/system/tsig/tests.sh
|
--- a/bin/tests/system/tsig/tests.sh
|
||||||
+++ b/bin/tests/system/tsig/tests.sh
|
+++ b/bin/tests/system/tsig/tests.sh
|
||||||
@@ -26,20 +26,25 @@ sha512="jI/Pa4qRu96t76Pns5Z/Ndxbn3QCkwcxLOgt9vgvnJw5wqTRvNyk3FtD6yIMd1dWVlqZ+Y4f
|
@@ -26,20 +26,25 @@ sha512="jI/Pa4qRu96t76Pns5Z/Ndxbn3QCkwcxLOgt9vgvnJw5wqTRvNyk3FtD6yIMd1dWVlqZ+Y4f
|
||||||
@ -1355,19 +928,8 @@ index e0c2903..327fa50 100644
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
echo_i "fetching using hmac-sha1-80 (BADTRUNC)"
|
echo_i "fetching using hmac-sha1-80 (BADTRUNC)"
|
||||||
diff --git a/bin/tests/system/tsiggss/setup.sh b/bin/tests/system/tsiggss/setup.sh
|
|
||||||
index f04c907..09da5f9 100644
|
|
||||||
--- a/bin/tests/system/tsiggss/setup.sh
|
|
||||||
+++ b/bin/tests/system/tsiggss/setup.sh
|
|
||||||
@@ -16,5 +16,5 @@ test -r $RANDFILE || $GENRANDOM $RANDOMSIZE $RANDFILE
|
|
||||||
|
|
||||||
copy_setports ns1/named.conf.in ns1/named.conf
|
|
||||||
|
|
||||||
-key=`$KEYGEN -Cq -K ns1 -a DSA -b 512 -r $RANDFILE -n HOST -T KEY key.example.nil.`
|
|
||||||
+key=`$KEYGEN -Cq -K ns1 -a DSA -b 1024 -r $RANDFILE -n HOST -T KEY key.example.nil.`
|
|
||||||
cat ns1/example.nil.db.in ns1/${key}.key > ns1/example.nil.db
|
|
||||||
diff --git a/bin/tests/system/upforwd/ns1/named.conf.in b/bin/tests/system/upforwd/ns1/named.conf.in
|
diff --git a/bin/tests/system/upforwd/ns1/named.conf.in b/bin/tests/system/upforwd/ns1/named.conf.in
|
||||||
index 4ddd7a4..238f52a 100644
|
index 3873c7c..b359a5a 100644
|
||||||
--- a/bin/tests/system/upforwd/ns1/named.conf.in
|
--- a/bin/tests/system/upforwd/ns1/named.conf.in
|
||||||
+++ b/bin/tests/system/upforwd/ns1/named.conf.in
|
+++ b/bin/tests/system/upforwd/ns1/named.conf.in
|
||||||
@@ -10,7 +10,7 @@
|
@@ -10,7 +10,7 @@
|
||||||
@ -1380,10 +942,10 @@ index 4ddd7a4..238f52a 100644
|
|||||||
};
|
};
|
||||||
|
|
||||||
diff --git a/bin/tests/system/upforwd/tests.sh b/bin/tests/system/upforwd/tests.sh
|
diff --git a/bin/tests/system/upforwd/tests.sh b/bin/tests/system/upforwd/tests.sh
|
||||||
index 1cf8d3b..f4c3216 100644
|
index a50c896..8062d68 100644
|
||||||
--- a/bin/tests/system/upforwd/tests.sh
|
--- a/bin/tests/system/upforwd/tests.sh
|
||||||
+++ b/bin/tests/system/upforwd/tests.sh
|
+++ b/bin/tests/system/upforwd/tests.sh
|
||||||
@@ -68,7 +68,7 @@ if [ $ret != 0 ] ; then echo_i "failed"; status=`expr $status + $ret`; fi
|
@@ -79,7 +79,7 @@ if [ $ret != 0 ] ; then echo_i "failed"; status=`expr $status + $ret`; fi
|
||||||
|
|
||||||
echo_i "updating zone (signed) ($n)"
|
echo_i "updating zone (signed) ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
@ -1393,5 +955,5 @@ index 1cf8d3b..f4c3216 100644
|
|||||||
update add updated.example. 600 A 10.10.10.1
|
update add updated.example. 600 A 10.10.10.1
|
||||||
update add updated.example. 600 TXT Foo
|
update add updated.example. 600 TXT Foo
|
||||||
--
|
--
|
||||||
2.31.1
|
2.26.2
|
||||||
|
|
||||||
|
|||||||
@ -1,92 +0,0 @@
|
|||||||
From ec50eff97c259b5bfbfa4e050d69fe7b39b0f15a Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
|
||||||
Date: Tue, 25 Sep 2018 18:08:46 +0200
|
|
||||||
Subject: [PATCH] Disable IDN from environment as documented
|
|
||||||
|
|
||||||
Manual page of host contained instructions to disable IDN processing
|
|
||||||
when it was built with libidn2. When refactoring IDN support however,
|
|
||||||
support for disabling IDN in host and nslookup was lost. Use also
|
|
||||||
environment variable and document it for nslookup, host and dig.
|
|
||||||
|
|
||||||
Support variable CHARSET=ASCII to disable IDN, supported in downstream
|
|
||||||
RH patch since RHEL 5.
|
|
||||||
---
|
|
||||||
bin/dig/dig.docbook | 4 +++-
|
|
||||||
bin/dig/dighost.c | 5 +++++
|
|
||||||
bin/dig/host.docbook | 2 +-
|
|
||||||
bin/dig/nslookup.docbook | 15 +++++++++++++++
|
|
||||||
4 files changed, 24 insertions(+), 2 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/bin/dig/dig.docbook b/bin/dig/dig.docbook
|
|
||||||
index 5d19301..933af79 100644
|
|
||||||
--- a/bin/dig/dig.docbook
|
|
||||||
+++ b/bin/dig/dig.docbook
|
|
||||||
@@ -1312,7 +1312,9 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
|
|
||||||
reply from the server.
|
|
||||||
If you'd like to turn off the IDN support for some reason, use
|
|
||||||
parameters <parameter>+noidnin</parameter> and
|
|
||||||
- <parameter>+noidnout</parameter>.
|
|
||||||
+ <parameter>+noidnout</parameter> or define
|
|
||||||
+ the <envar>IDN_DISABLE</envar> environment variable.
|
|
||||||
+
|
|
||||||
</para>
|
|
||||||
</refsection>
|
|
||||||
|
|
||||||
diff --git a/bin/dig/dighost.c b/bin/dig/dighost.c
|
|
||||||
index 5eabc1f..73aaab8 100644
|
|
||||||
--- a/bin/dig/dighost.c
|
|
||||||
+++ b/bin/dig/dighost.c
|
|
||||||
@@ -826,6 +826,11 @@ make_empty_lookup(void) {
|
|
||||||
looknew->badcookie = true;
|
|
||||||
#ifdef WITH_IDN_SUPPORT
|
|
||||||
looknew->idnin = isatty(1)?(getenv("IDN_DISABLE") == NULL):false;
|
|
||||||
+ if (looknew->idnin) {
|
|
||||||
+ const char *charset = getenv("CHARSET");
|
|
||||||
+ if (charset && !strcmp(charset, "ASCII"))
|
|
||||||
+ looknew->idnin = false;
|
|
||||||
+ }
|
|
||||||
#else
|
|
||||||
looknew->idnin = false;
|
|
||||||
#endif
|
|
||||||
diff --git a/bin/dig/host.docbook b/bin/dig/host.docbook
|
|
||||||
index da0f8fb..9689b5a 100644
|
|
||||||
--- a/bin/dig/host.docbook
|
|
||||||
+++ b/bin/dig/host.docbook
|
|
||||||
@@ -379,7 +379,7 @@
|
|
||||||
<command>host</command> appropriately converts character encoding of
|
|
||||||
domain name before sending a request to DNS server or displaying a
|
|
||||||
reply from the server.
|
|
||||||
- If you'd like to turn off the IDN support for some reason, defines
|
|
||||||
+ If you'd like to turn off the IDN support for some reason, define
|
|
||||||
the <envar>IDN_DISABLE</envar> environment variable.
|
|
||||||
The IDN support is disabled if the variable is set when
|
|
||||||
<command>host</command> runs.
|
|
||||||
diff --git a/bin/dig/nslookup.docbook b/bin/dig/nslookup.docbook
|
|
||||||
index d46fc2d..6d7d181 100644
|
|
||||||
--- a/bin/dig/nslookup.docbook
|
|
||||||
+++ b/bin/dig/nslookup.docbook
|
|
||||||
@@ -495,6 +495,21 @@ nslookup -query=hinfo -timeout=10
|
|
||||||
</para>
|
|
||||||
</refsection>
|
|
||||||
|
|
||||||
+ <refsection><info><title>IDN SUPPORT</title></info>
|
|
||||||
+
|
|
||||||
+ <para>
|
|
||||||
+ If <command>nslookup</command> has been built with IDN (internationalized
|
|
||||||
+ domain name) support, it can accept and display non-ASCII domain names.
|
|
||||||
+ <command>nslookup</command> appropriately converts character encoding of
|
|
||||||
+ domain name before sending a request to DNS server or displaying a
|
|
||||||
+ reply from the server.
|
|
||||||
+ If you'd like to turn off the IDN support for some reason, define
|
|
||||||
+ the <envar>IDN_DISABLE</envar> environment variable.
|
|
||||||
+ The IDN support is disabled if the variable is set when
|
|
||||||
+ <command>nslookup</command> runs.
|
|
||||||
+ </para>
|
|
||||||
+ </refsection>
|
|
||||||
+
|
|
||||||
<refsection><info><title>FILES</title></info>
|
|
||||||
|
|
||||||
<para><filename>/etc/resolv.conf</filename>
|
|
||||||
--
|
|
||||||
2.20.1
|
|
||||||
|
|
||||||
@ -1,50 +0,0 @@
|
|||||||
From cb6d2019766a6c8c5516fd8859cedf0052f03293 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Petr Mensik <pemensik@redhat.com>
|
|
||||||
Date: Thu, 25 Jul 2019 11:37:57 +0200
|
|
||||||
Subject: [PATCH] Skip support of jsoncpp
|
|
||||||
|
|
||||||
Bind cannot be compiled when jsoncpp-devel is installed. Remove support
|
|
||||||
for jsoncpp, use only json-c-devel. Bind 9.15 has already support for
|
|
||||||
--with-json-c, do not yet introduce it.
|
|
||||||
---
|
|
||||||
configure.ac | 17 ++---------------
|
|
||||||
1 file changed, 2 insertions(+), 15 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/configure.ac b/configure.ac
|
|
||||||
index 6d05337..5ce83b5 100644
|
|
||||||
--- a/configure.ac
|
|
||||||
+++ b/configure.ac
|
|
||||||
@@ -2594,15 +2594,7 @@ case "$use_libjson" in
|
|
||||||
auto|yes)
|
|
||||||
for d in /usr /usr/local /opt/local
|
|
||||||
do
|
|
||||||
- if test -f "${d}/include/json/json.h"
|
|
||||||
- then
|
|
||||||
- if test ${d} != /usr
|
|
||||||
- then
|
|
||||||
- libjson_cflags="-I ${d}/include"
|
|
||||||
- LIBS="$LIBS -L${d}/lib"
|
|
||||||
- fi
|
|
||||||
- have_libjson="yes"
|
|
||||||
- elif test -f "${d}/include/json-c/json.h"
|
|
||||||
+ if test -f "${d}/include/json-c/json.h"
|
|
||||||
then
|
|
||||||
if test ${d} != /usr
|
|
||||||
then
|
|
||||||
@@ -2615,12 +2607,7 @@ case "$use_libjson" in
|
|
||||||
done
|
|
||||||
;;
|
|
||||||
*)
|
|
||||||
- if test -f "${use_libjson}/include/json/json.h"
|
|
||||||
- then
|
|
||||||
- libjson_cflags="-I${use_libjson}/include"
|
|
||||||
- LIBS="$LIBS -L${use_libjson}/lib"
|
|
||||||
- have_libjson="yes"
|
|
||||||
- elif test -f "${use_libjson}/include/json-c/json.h"
|
|
||||||
+ if test -f "${use_libjson}/include/json-c/json.h"
|
|
||||||
then
|
|
||||||
libjson_cflags="-I${use_libjson}/include"
|
|
||||||
LIBS="$LIBS -L${use_libjson}/lib"
|
|
||||||
--
|
|
||||||
2.20.1
|
|
||||||
|
|
||||||
@ -1,4 +1,4 @@
|
|||||||
From a9b5785f174cf7fd74891fa64f6b69b9a9b55466 Mon Sep 17 00:00:00 2001
|
From 1241f2005d08673c28a595c5a6cd61350b95a929 Mon Sep 17 00:00:00 2001
|
||||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
||||||
Date: Tue, 2 Jan 2018 18:13:07 +0100
|
Date: Tue, 2 Jan 2018 18:13:07 +0100
|
||||||
Subject: [PATCH] Fix pkcs11 variants atf tests
|
Subject: [PATCH] Fix pkcs11 variants atf tests
|
||||||
@ -7,19 +7,16 @@ Add dns-pkcs11 tests Makefile to configure
|
|||||||
|
|
||||||
Add pkcs11 Kyuafile, fix dh_test to pass in pkcs11 mode
|
Add pkcs11 Kyuafile, fix dh_test to pass in pkcs11 mode
|
||||||
---
|
---
|
||||||
configure.ac | 1 +
|
configure.ac | 1 +
|
||||||
lib/Kyuafile | 2 ++
|
lib/Kyuafile | 2 ++
|
||||||
lib/dns-pkcs11/tests/Makefile.in | 10 +++++-----
|
lib/dns-pkcs11/tests/dh_test.c | 3 ++-
|
||||||
lib/dns-pkcs11/tests/dh_test.c | 3 ++-
|
3 files changed, 5 insertions(+), 1 deletion(-)
|
||||||
lib/isc-pkcs11/tests/Makefile.in | 6 +++---
|
|
||||||
lib/isc-pkcs11/tests/hash_test.c | 32 +++++++++++++++++++++++++-------
|
|
||||||
6 files changed, 38 insertions(+), 16 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/configure.ac b/configure.ac
|
diff --git a/configure.ac b/configure.ac
|
||||||
index 62ecf56..0940a7d 100644
|
index d80ae31..0fb9328 100644
|
||||||
--- a/configure.ac
|
--- a/configure.ac
|
||||||
+++ b/configure.ac
|
+++ b/configure.ac
|
||||||
@@ -5476,6 +5476,7 @@ AC_CONFIG_FILES([
|
@@ -3090,6 +3090,7 @@ AC_CONFIG_FILES([
|
||||||
lib/dns-pkcs11/include/Makefile
|
lib/dns-pkcs11/include/Makefile
|
||||||
lib/dns-pkcs11/include/dns/Makefile
|
lib/dns-pkcs11/include/dns/Makefile
|
||||||
lib/dns-pkcs11/include/dst/Makefile
|
lib/dns-pkcs11/include/dst/Makefile
|
||||||
@ -28,7 +25,7 @@ index 62ecf56..0940a7d 100644
|
|||||||
lib/irs/include/Makefile
|
lib/irs/include/Makefile
|
||||||
lib/irs/include/irs/Makefile
|
lib/irs/include/irs/Makefile
|
||||||
diff --git a/lib/Kyuafile b/lib/Kyuafile
|
diff --git a/lib/Kyuafile b/lib/Kyuafile
|
||||||
index 7c8bab0..eec9564 100644
|
index 39ce986..037e5ef 100644
|
||||||
--- a/lib/Kyuafile
|
--- a/lib/Kyuafile
|
||||||
+++ b/lib/Kyuafile
|
+++ b/lib/Kyuafile
|
||||||
@@ -2,8 +2,10 @@ syntax(2)
|
@@ -2,8 +2,10 @@ syntax(2)
|
||||||
@ -38,37 +35,15 @@ index 7c8bab0..eec9564 100644
|
|||||||
+include('dns-pkcs11/Kyuafile')
|
+include('dns-pkcs11/Kyuafile')
|
||||||
include('irs/Kyuafile')
|
include('irs/Kyuafile')
|
||||||
include('isc/Kyuafile')
|
include('isc/Kyuafile')
|
||||||
+include('isc-pkcs11/Kyuafile')
|
|
||||||
include('isccc/Kyuafile')
|
include('isccc/Kyuafile')
|
||||||
include('isccfg/Kyuafile')
|
include('isccfg/Kyuafile')
|
||||||
include('lwres/Kyuafile')
|
include('ns/Kyuafile')
|
||||||
diff --git a/lib/dns-pkcs11/tests/Makefile.in b/lib/dns-pkcs11/tests/Makefile.in
|
+include('ns-pkcs11/Kyuafile')
|
||||||
index 22a06a8..5df5b15 100644
|
|
||||||
--- a/lib/dns-pkcs11/tests/Makefile.in
|
|
||||||
+++ b/lib/dns-pkcs11/tests/Makefile.in
|
|
||||||
@@ -17,12 +17,12 @@ VERSION=@BIND9_VERSION@
|
|
||||||
|
|
||||||
CINCLUDES = -I. -Iinclude ${DNS_INCLUDES} ${ISC_INCLUDES} \
|
|
||||||
@DST_OPENSSL_INC@ ${MAXMINDDB_CFLAGS}
|
|
||||||
-CDEFINES = @CRYPTO@ -DTESTS="\"${top_builddir}/lib/dns/tests/\""
|
|
||||||
+CDEFINES = @CRYPTO_PK11@ -DTESTS="\"${top_builddir}/lib/dns-pkcs11/tests/\""
|
|
||||||
|
|
||||||
-ISCLIBS = ../../isc/libisc.@A@
|
|
||||||
-ISCDEPLIBS = ../../isc/libisc.@A@
|
|
||||||
-DNSLIBS = ../libdns.@A@ ${MAXMINDDB_LIBS} @DNS_CRYPTO_LIBS@
|
|
||||||
-DNSDEPLIBS = ../libdns.@A@
|
|
||||||
+ISCLIBS = ../../isc-pkcs11/libisc-pkcs11.@A@
|
|
||||||
+ISCDEPLIBS = ../../isc-pkcs11/libisc-pkcs11.@A@
|
|
||||||
+DNSLIBS = ../libdns-pkcs11.@A@ ${MAXMINDDB_LIBS} @DNS_CRYPTO_LIBS@
|
|
||||||
+DNSDEPLIBS = ../libdns-pkcs11.@A@
|
|
||||||
|
|
||||||
LIBS = @LIBS@ @CMOCKA_LIBS@
|
|
||||||
CFLAGS = @CFLAGS@ @CMOCKA_CFLAGS@
|
|
||||||
diff --git a/lib/dns-pkcs11/tests/dh_test.c b/lib/dns-pkcs11/tests/dh_test.c
|
diff --git a/lib/dns-pkcs11/tests/dh_test.c b/lib/dns-pkcs11/tests/dh_test.c
|
||||||
index a5bf46c..9ff2b76 100644
|
index 934e8fd..658d1af 100644
|
||||||
--- a/lib/dns-pkcs11/tests/dh_test.c
|
--- a/lib/dns-pkcs11/tests/dh_test.c
|
||||||
+++ b/lib/dns-pkcs11/tests/dh_test.c
|
+++ b/lib/dns-pkcs11/tests/dh_test.c
|
||||||
@@ -88,7 +88,8 @@ dh_computesecret(void **state) {
|
@@ -87,7 +87,8 @@ dh_computesecret(void **state) {
|
||||||
result = dst_key_computesecret(key, key, &buf);
|
result = dst_key_computesecret(key, key, &buf);
|
||||||
assert_int_equal(result, DST_R_NOTPRIVATEKEY);
|
assert_int_equal(result, DST_R_NOTPRIVATEKEY);
|
||||||
result = key->func->computesecret(key, key, &buf);
|
result = key->func->computesecret(key, key, &buf);
|
||||||
@ -78,115 +53,6 @@ index a5bf46c..9ff2b76 100644
|
|||||||
|
|
||||||
dst_key_free(&key);
|
dst_key_free(&key);
|
||||||
}
|
}
|
||||||
diff --git a/lib/isc-pkcs11/tests/Makefile.in b/lib/isc-pkcs11/tests/Makefile.in
|
|
||||||
index 36d2207..00dfbc9 100644
|
|
||||||
--- a/lib/isc-pkcs11/tests/Makefile.in
|
|
||||||
+++ b/lib/isc-pkcs11/tests/Makefile.in
|
|
||||||
@@ -16,10 +16,10 @@ VERSION=@BIND9_VERSION@
|
|
||||||
@BIND9_MAKE_INCLUDES@
|
|
||||||
|
|
||||||
CINCLUDES = -I. -Iinclude ${ISC_INCLUDES} @ISC_OPENSSL_INC@
|
|
||||||
-CDEFINES = @CRYPTO@ -DTESTS="\"${top_builddir}/lib/isc/tests/\""
|
|
||||||
+CDEFINES = @CRYPTO_PK11@ -DTESTS="\"${top_builddir}/lib/isc-pkcs11/tests/\""
|
|
||||||
|
|
||||||
-ISCLIBS = ../libisc.@A@ @ISC_OPENSSL_LIBS@
|
|
||||||
-ISCDEPLIBS = ../libisc.@A@
|
|
||||||
+ISCLIBS = ../libisc-pkcs11.@A@ @ISC_OPENSSL_LIBS@
|
|
||||||
+ISCDEPLIBS = ../libisc-pkcs11.@A@
|
|
||||||
|
|
||||||
LIBS = @LIBS@ @CMOCKA_LIBS@
|
|
||||||
CFLAGS = @CFLAGS@ @CMOCKA_CFLAGS@
|
|
||||||
diff --git a/lib/isc-pkcs11/tests/hash_test.c b/lib/isc-pkcs11/tests/hash_test.c
|
|
||||||
index 4fafc38..5eb2be2 100644
|
|
||||||
--- a/lib/isc-pkcs11/tests/hash_test.c
|
|
||||||
+++ b/lib/isc-pkcs11/tests/hash_test.c
|
|
||||||
@@ -84,7 +84,7 @@ typedef struct hash_testcase {
|
|
||||||
|
|
||||||
typedef struct hash_test_key {
|
|
||||||
const char *key;
|
|
||||||
- const int len;
|
|
||||||
+ const unsigned len;
|
|
||||||
} hash_test_key_t;
|
|
||||||
|
|
||||||
/* non-hmac tests */
|
|
||||||
@@ -955,8 +955,11 @@ isc_hmacsha1_test(void **state) {
|
|
||||||
hash_test_key_t *test_key = test_keys;
|
|
||||||
|
|
||||||
while (testcase->input != NULL && testcase->result != NULL) {
|
|
||||||
+ int len = ISC_MAX(test_key->len, ISC_SHA1_DIGESTLENGTH);
|
|
||||||
+
|
|
||||||
+ memset(buffer, 0, ISC_SHA1_DIGESTLENGTH);
|
|
||||||
memmove(buffer, test_key->key, test_key->len);
|
|
||||||
- isc_hmacsha1_init(&hmacsha1, buffer, test_key->len);
|
|
||||||
+ isc_hmacsha1_init(&hmacsha1, buffer, len);
|
|
||||||
isc_hmacsha1_update(&hmacsha1,
|
|
||||||
(const uint8_t *) testcase->input,
|
|
||||||
testcase->input_len);
|
|
||||||
@@ -1115,8 +1118,11 @@ isc_hmacsha224_test(void **state) {
|
|
||||||
hash_test_key_t *test_key = test_keys;
|
|
||||||
|
|
||||||
while (testcase->input != NULL && testcase->result != NULL) {
|
|
||||||
+ int len = ISC_MAX(test_key->len, ISC_SHA224_DIGESTLENGTH);
|
|
||||||
+
|
|
||||||
+ memset(buffer, 0, ISC_SHA224_DIGESTLENGTH);
|
|
||||||
memmove(buffer, test_key->key, test_key->len);
|
|
||||||
- isc_hmacsha224_init(&hmacsha224, buffer, test_key->len);
|
|
||||||
+ isc_hmacsha224_init(&hmacsha224, buffer, len);
|
|
||||||
isc_hmacsha224_update(&hmacsha224,
|
|
||||||
(const uint8_t *) testcase->input,
|
|
||||||
testcase->input_len);
|
|
||||||
@@ -1276,8 +1282,11 @@ isc_hmacsha256_test(void **state) {
|
|
||||||
hash_test_key_t *test_key = test_keys;
|
|
||||||
|
|
||||||
while (testcase->input != NULL && testcase->result != NULL) {
|
|
||||||
+ int len = ISC_MAX(test_key->len, ISC_SHA256_DIGESTLENGTH);
|
|
||||||
+
|
|
||||||
+ memset(buffer, 0, ISC_SHA256_DIGESTLENGTH);
|
|
||||||
memmove(buffer, test_key->key, test_key->len);
|
|
||||||
- isc_hmacsha256_init(&hmacsha256, buffer, test_key->len);
|
|
||||||
+ isc_hmacsha256_init(&hmacsha256, buffer, len);
|
|
||||||
isc_hmacsha256_update(&hmacsha256,
|
|
||||||
(const uint8_t *) testcase->input,
|
|
||||||
testcase->input_len);
|
|
||||||
@@ -1443,8 +1452,11 @@ isc_hmacsha384_test(void **state) {
|
|
||||||
hash_test_key_t *test_key = test_keys;
|
|
||||||
|
|
||||||
while (testcase->input != NULL && testcase->result != NULL) {
|
|
||||||
+ int len = ISC_MAX(test_key->len, ISC_SHA384_DIGESTLENGTH);
|
|
||||||
+
|
|
||||||
+ memset(buffer, 0, ISC_SHA384_DIGESTLENGTH);
|
|
||||||
memmove(buffer, test_key->key, test_key->len);
|
|
||||||
- isc_hmacsha384_init(&hmacsha384, buffer, test_key->len);
|
|
||||||
+ isc_hmacsha384_init(&hmacsha384, buffer, len);
|
|
||||||
isc_hmacsha384_update(&hmacsha384,
|
|
||||||
(const uint8_t *) testcase->input,
|
|
||||||
testcase->input_len);
|
|
||||||
@@ -1610,8 +1622,11 @@ isc_hmacsha512_test(void **state) {
|
|
||||||
hash_test_key_t *test_key = test_keys;
|
|
||||||
|
|
||||||
while (testcase->input != NULL && testcase->result != NULL) {
|
|
||||||
+ int len = ISC_MAX(test_key->len, ISC_SHA512_DIGESTLENGTH);
|
|
||||||
+
|
|
||||||
+ memset(buffer, 0, ISC_SHA512_DIGESTLENGTH);
|
|
||||||
memmove(buffer, test_key->key, test_key->len);
|
|
||||||
- isc_hmacsha512_init(&hmacsha512, buffer, test_key->len);
|
|
||||||
+ isc_hmacsha512_init(&hmacsha512, buffer, len);
|
|
||||||
isc_hmacsha512_update(&hmacsha512,
|
|
||||||
(const uint8_t *) testcase->input,
|
|
||||||
testcase->input_len);
|
|
||||||
@@ -1754,8 +1769,11 @@ isc_hmacmd5_test(void **state) {
|
|
||||||
hash_test_key_t *test_key = test_keys;
|
|
||||||
|
|
||||||
while (testcase->input != NULL && testcase->result != NULL) {
|
|
||||||
+ int len = ISC_MAX(test_key->len, ISC_MD5_DIGESTLENGTH);
|
|
||||||
+
|
|
||||||
+ memset(buffer, 0, ISC_MD5_DIGESTLENGTH);
|
|
||||||
memmove(buffer, test_key->key, test_key->len);
|
|
||||||
- isc_hmacmd5_init(&hmacmd5, buffer, test_key->len);
|
|
||||||
+ isc_hmacmd5_init(&hmacmd5, buffer, len);
|
|
||||||
isc_hmacmd5_update(&hmacmd5,
|
|
||||||
(const uint8_t *) testcase->input,
|
|
||||||
testcase->input_len);
|
|
||||||
--
|
--
|
||||||
2.21.1
|
2.20.1
|
||||||
|
|
||||||
|
|||||||
@ -1,256 +0,0 @@
|
|||||||
From 8ca95f47231822df2b9c171a4da1e93ca5b748eb Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
|
||||||
Date: Wed, 25 Jul 2018 12:24:16 +0200
|
|
||||||
Subject: [PATCH] Use make automatic variables to install updated manuals
|
|
||||||
|
|
||||||
Make will choose modified manual from build directory or original from source
|
|
||||||
directory automagically. Take advantage of install tool feature.
|
|
||||||
Install all files in single command instead of iterating on each of them.
|
|
||||||
---
|
|
||||||
bin/check/Makefile.in | 8 +++++---
|
|
||||||
bin/confgen/Makefile.in | 9 +++++----
|
|
||||||
bin/delv/Makefile.in | 6 ++++--
|
|
||||||
bin/dig/Makefile.in | 8 ++++----
|
|
||||||
bin/dnssec/Makefile.in | 6 ++++--
|
|
||||||
bin/named/Makefile.in | 13 +++++++++----
|
|
||||||
bin/pkcs11/Makefile.in | 9 ++++-----
|
|
||||||
bin/python/Makefile.in | 8 ++++----
|
|
||||||
bin/tools/Makefile.in | 25 +++++++++++++++----------
|
|
||||||
9 files changed, 54 insertions(+), 38 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/bin/check/Makefile.in b/bin/check/Makefile.in
|
|
||||||
index c124e80..1174f8d 100644
|
|
||||||
--- a/bin/check/Makefile.in
|
|
||||||
+++ b/bin/check/Makefile.in
|
|
||||||
@@ -83,12 +83,14 @@ installdirs:
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
|
||||||
|
|
||||||
-install:: named-checkconf@EXEEXT@ named-checkzone@EXEEXT@ installdirs
|
|
||||||
+install-man8: ${MANPAGES}
|
|
||||||
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man8
|
|
||||||
+ (cd ${DESTDIR}${mandir}/man8; rm -f named-compilezone.8; ${LINK_PROGRAM} named-checkzone.8 named-compilezone.8)
|
|
||||||
+
|
|
||||||
+install:: named-checkconf@EXEEXT@ named-checkzone@EXEEXT@ installdirs install-man8
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named-checkconf@EXEEXT@ ${DESTDIR}${sbindir}
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named-checkzone@EXEEXT@ ${DESTDIR}${sbindir}
|
|
||||||
(cd ${DESTDIR}${sbindir}; rm -f named-compilezone@EXEEXT@; ${LINK_PROGRAM} named-checkzone@EXEEXT@ named-compilezone@EXEEXT@)
|
|
||||||
- for m in ${MANPAGES}; do ${INSTALL_DATA} ${srcdir}/$$m ${DESTDIR}${mandir}/man8 || exit 1; done
|
|
||||||
- (cd ${DESTDIR}${mandir}/man8; rm -f named-compilezone.8; ${LINK_PROGRAM} named-checkzone.8 named-compilezone.8)
|
|
||||||
|
|
||||||
uninstall::
|
|
||||||
rm -f ${DESTDIR}${mandir}/man8/named-compilezone.8
|
|
||||||
diff --git a/bin/confgen/Makefile.in b/bin/confgen/Makefile.in
|
|
||||||
index 87f13dd..7865c0c 100644
|
|
||||||
--- a/bin/confgen/Makefile.in
|
|
||||||
+++ b/bin/confgen/Makefile.in
|
|
||||||
@@ -95,13 +95,14 @@ installdirs:
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
|
||||||
|
|
||||||
-install:: rndc-confgen@EXEEXT@ ddns-confgen@EXEEXT@ installdirs
|
|
||||||
+install-man8: rndc-confgen.8 ddns-confgen.8
|
|
||||||
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man8
|
|
||||||
+ (cd ${DESTDIR}${mandir}/man8; rm -f tsig-keygen.8; ${LINK_PROGRAM} ddns-confgen.8 tsig-keygen.8)
|
|
||||||
+
|
|
||||||
+install:: rndc-confgen@EXEEXT@ ddns-confgen@EXEEXT@ installdirs install-man8
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} rndc-confgen@EXEEXT@ ${DESTDIR}${sbindir}
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} ddns-confgen@EXEEXT@ ${DESTDIR}${sbindir}
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/rndc-confgen.8 ${DESTDIR}${mandir}/man8
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/ddns-confgen.8 ${DESTDIR}${mandir}/man8
|
|
||||||
(cd ${DESTDIR}${sbindir}; rm -f tsig-keygen@EXEEXT@; ${LINK_PROGRAM} ddns-confgen@EXEEXT@ tsig-keygen@EXEEXT@)
|
|
||||||
- (cd ${DESTDIR}${mandir}/man8; rm -f tsig-keygen.8; ${LINK_PROGRAM} ddns-confgen.8 tsig-keygen.8)
|
|
||||||
|
|
||||||
uninstall::
|
|
||||||
rm -f ${DESTDIR}${mandir}/man8/tsig-keygen.8
|
|
||||||
diff --git a/bin/delv/Makefile.in b/bin/delv/Makefile.in
|
|
||||||
index e2d2802..19361a8 100644
|
|
||||||
--- a/bin/delv/Makefile.in
|
|
||||||
+++ b/bin/delv/Makefile.in
|
|
||||||
@@ -63,10 +63,12 @@ installdirs:
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${bindir}
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man1
|
|
||||||
|
|
||||||
-install:: delv@EXEEXT@ installdirs
|
|
||||||
+install-man1: delv.1
|
|
||||||
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man1
|
|
||||||
+
|
|
||||||
+install:: delv@EXEEXT@ installdirs install-man1
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} \
|
|
||||||
delv@EXEEXT@ ${DESTDIR}${bindir}
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/delv.1 ${DESTDIR}${mandir}/man1
|
|
||||||
|
|
||||||
uninstall::
|
|
||||||
rm -f ${DESTDIR}${mandir}/man1/delv.1
|
|
||||||
diff --git a/bin/dig/Makefile.in b/bin/dig/Makefile.in
|
|
||||||
index a9830a9..d7ac0b6 100644
|
|
||||||
--- a/bin/dig/Makefile.in
|
|
||||||
+++ b/bin/dig/Makefile.in
|
|
||||||
@@ -91,16 +91,16 @@ installdirs:
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${bindir}
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man1
|
|
||||||
|
|
||||||
-install:: dig@EXEEXT@ host@EXEEXT@ nslookup@EXEEXT@ installdirs
|
|
||||||
+install-man1: ${MANPAGES}
|
|
||||||
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man1
|
|
||||||
+
|
|
||||||
+install:: dig@EXEEXT@ host@EXEEXT@ nslookup@EXEEXT@ installdirs install-man1
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} \
|
|
||||||
dig@EXEEXT@ ${DESTDIR}${bindir}
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} \
|
|
||||||
host@EXEEXT@ ${DESTDIR}${bindir}
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} \
|
|
||||||
nslookup@EXEEXT@ ${DESTDIR}${bindir}
|
|
||||||
- for m in ${MANPAGES}; do \
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/$$m ${DESTDIR}${mandir}/man1 || exit 1; \
|
|
||||||
- done
|
|
||||||
|
|
||||||
uninstall::
|
|
||||||
for m in ${MANPAGES}; do \
|
|
||||||
diff --git a/bin/dnssec/Makefile.in b/bin/dnssec/Makefile.in
|
|
||||||
index 2239ad1..ce0a177 100644
|
|
||||||
--- a/bin/dnssec/Makefile.in
|
|
||||||
+++ b/bin/dnssec/Makefile.in
|
|
||||||
@@ -110,9 +110,11 @@ installdirs:
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
|
||||||
|
|
||||||
-install:: ${TARGETS} installdirs
|
|
||||||
+install-man8: ${MANPAGES}
|
|
||||||
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man8
|
|
||||||
+
|
|
||||||
+install:: ${TARGETS} installdirs install-man8
|
|
||||||
for t in ${TARGETS}; do ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} $$t ${DESTDIR}${sbindir} || exit 1; done
|
|
||||||
- for m in ${MANPAGES}; do ${INSTALL_DATA} ${srcdir}/$$m ${DESTDIR}${mandir}/man8 || exit 1; done
|
|
||||||
|
|
||||||
uninstall::
|
|
||||||
for m in ${MANPAGES}; do rm -f ${DESTDIR}${mandir}/man8/$$m || exit 1; done
|
|
||||||
diff --git a/bin/named/Makefile.in b/bin/named/Makefile.in
|
|
||||||
index e1f85a9..d92bc9a 100644
|
|
||||||
--- a/bin/named/Makefile.in
|
|
||||||
+++ b/bin/named/Makefile.in
|
|
||||||
@@ -176,12 +176,17 @@ installdirs:
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man5
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
|
||||||
|
|
||||||
-install:: named@EXEEXT@ lwresd@EXEEXT@ installdirs
|
|
||||||
+install-man5: named.conf.5
|
|
||||||
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man5
|
|
||||||
+
|
|
||||||
+install-man8: named.8 lwresd.8
|
|
||||||
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man8
|
|
||||||
+
|
|
||||||
+install-man: install-man5 install-man8
|
|
||||||
+
|
|
||||||
+install:: named@EXEEXT@ lwresd@EXEEXT@ installdirs install-man
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named@EXEEXT@ ${DESTDIR}${sbindir}
|
|
||||||
(cd ${DESTDIR}${sbindir}; rm -f lwresd@EXEEXT@; @LN@ named@EXEEXT@ lwresd@EXEEXT@)
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/named.8 ${DESTDIR}${mandir}/man8
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/lwresd.8 ${DESTDIR}${mandir}/man8
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/named.conf.5 ${DESTDIR}${mandir}/man5
|
|
||||||
|
|
||||||
uninstall::
|
|
||||||
rm -f ${DESTDIR}${mandir}/man5/named.conf.5
|
|
||||||
diff --git a/bin/pkcs11/Makefile.in b/bin/pkcs11/Makefile.in
|
|
||||||
index ae90616..a058c91 100644
|
|
||||||
--- a/bin/pkcs11/Makefile.in
|
|
||||||
+++ b/bin/pkcs11/Makefile.in
|
|
||||||
@@ -71,7 +71,10 @@ installdirs:
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
|
||||||
|
|
||||||
-install:: ${TARGETS} installdirs
|
|
||||||
+install-man8: ${MANPAGES}
|
|
||||||
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man8
|
|
||||||
+
|
|
||||||
+install:: ${TARGETS} installdirs install-man8
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} pkcs11-list@EXEEXT@ \
|
|
||||||
${DESTDIR}${sbindir}
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} pkcs11-destroy@EXEEXT@ \
|
|
||||||
@@ -80,10 +83,6 @@ install:: ${TARGETS} installdirs
|
|
||||||
${DESTDIR}${sbindir}
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} pkcs11-tokens@EXEEXT@ \
|
|
||||||
${DESTDIR}${sbindir}
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/pkcs11-list.8 ${DESTDIR}${mandir}/man8
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/pkcs11-destroy.8 ${DESTDIR}${mandir}/man8
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/pkcs11-keygen.8 ${DESTDIR}${mandir}/man8
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/pkcs11-tokens.8 ${DESTDIR}${mandir}/man8
|
|
||||||
|
|
||||||
uninstall::
|
|
||||||
rm -f ${DESTDIR}${mandir}/man8/pkcs11-tokens.8
|
|
||||||
diff --git a/bin/python/Makefile.in b/bin/python/Makefile.in
|
|
||||||
index aa678d4..064c404 100644
|
|
||||||
--- a/bin/python/Makefile.in
|
|
||||||
+++ b/bin/python/Makefile.in
|
|
||||||
@@ -47,13 +47,13 @@ installdirs:
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
|
||||||
|
|
||||||
-install:: ${TARGETS} installdirs
|
|
||||||
+install-man8: ${MANPAGES}
|
|
||||||
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man8
|
|
||||||
+
|
|
||||||
+install:: ${TARGETS} installdirs install-man8
|
|
||||||
${INSTALL_SCRIPT} dnssec-checkds ${DESTDIR}${sbindir}
|
|
||||||
${INSTALL_SCRIPT} dnssec-coverage ${DESTDIR}${sbindir}
|
|
||||||
${INSTALL_SCRIPT} dnssec-keymgr ${DESTDIR}${sbindir}
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/dnssec-checkds.8 ${DESTDIR}${mandir}/man8
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/dnssec-coverage.8 ${DESTDIR}${mandir}/man8
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/dnssec-keymgr.8 ${DESTDIR}${mandir}/man8
|
|
||||||
if test -n "${PYTHON}" ; then \
|
|
||||||
if test -n "${DESTDIR}" ; then \
|
|
||||||
${PYTHON} ${srcdir}/setup.py install --root=${DESTDIR} --prefix=${prefix} @PYTHON_INSTALL_LIB@ ; \
|
|
||||||
diff --git a/bin/tools/Makefile.in b/bin/tools/Makefile.in
|
|
||||||
index 7bf2af4..c395bc7 100644
|
|
||||||
--- a/bin/tools/Makefile.in
|
|
||||||
+++ b/bin/tools/Makefile.in
|
|
||||||
@@ -119,17 +119,27 @@ installdirs:
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man1
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
|
||||||
|
|
||||||
-nzd:
|
|
||||||
+nzd-man: named-nzd2nzf.8
|
|
||||||
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man8
|
|
||||||
+
|
|
||||||
+nzd: nzd-man
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named-nzd2nzf@EXEEXT@ \
|
|
||||||
${DESTDIR}${sbindir}
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/named-nzd2nzf.8 ${DESTDIR}${mandir}/man8
|
|
||||||
|
|
||||||
-dnstap:
|
|
||||||
+dnstap-man: dnstap-read.1
|
|
||||||
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man1
|
|
||||||
+
|
|
||||||
+dnstap: dnstap-man
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} dnstap-read@EXEEXT@ \
|
|
||||||
${DESTDIR}${bindir}
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/dnstap-read.1 ${DESTDIR}${mandir}/man1
|
|
||||||
|
|
||||||
-install:: ${TARGETS} installdirs @DNSTAP@ @NZD_TOOLS@
|
|
||||||
+install-man1: arpaname.1 named-rrchecker.1 mdig.1
|
|
||||||
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man1
|
|
||||||
+
|
|
||||||
+install-man8: named-journalprint.8 nsec3hash.8
|
|
||||||
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man8
|
|
||||||
+
|
|
||||||
+install:: ${TARGETS} installdirs @DNSTAP@ @NZD_TOOLS@ install-man1 install-man8
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} arpaname@EXEEXT@ \
|
|
||||||
${DESTDIR}${bindir}
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named-journalprint@EXEEXT@ \
|
|
||||||
@@ -144,13 +154,8 @@ install:: ${TARGETS} installdirs @DNSTAP@ @NZD_TOOLS@
|
|
||||||
${DESTDIR}${sbindir}
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} mdig@EXEEXT@ \
|
|
||||||
${DESTDIR}${bindir}
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/arpaname.1 ${DESTDIR}${mandir}/man1
|
|
||||||
${INSTALL_DATA} ${srcdir}/isc-hmac-fixup.8 ${DESTDIR}${mandir}/man8
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/named-journalprint.8 ${DESTDIR}${mandir}/man8
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/named-rrchecker.1 ${DESTDIR}${mandir}/man1
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/nsec3hash.8 ${DESTDIR}${mandir}/man8
|
|
||||||
${INSTALL_DATA} ${srcdir}/genrandom.8 ${DESTDIR}${mandir}/man8
|
|
||||||
- ${INSTALL_DATA} ${srcdir}/mdig.1 ${DESTDIR}${mandir}/man1
|
|
||||||
|
|
||||||
uninstall::
|
|
||||||
rm -f ${DESTDIR}${mandir}/man1/mdig.1
|
|
||||||
--
|
|
||||||
2.14.4
|
|
||||||
|
|
||||||
@ -1,27 +0,0 @@
|
|||||||
diff --git a/lib/dns/dst_internal.h b/lib/dns/dst_internal.h
|
|
||||||
index 640519a..fc40472 100644
|
|
||||||
--- a/lib/dns/dst_internal.h
|
|
||||||
+++ b/lib/dns/dst_internal.h
|
|
||||||
@@ -59,6 +59,9 @@
|
|
||||||
#include <openssl/objects.h>
|
|
||||||
#include <openssl/rsa.h>
|
|
||||||
#endif
|
|
||||||
+#if PKCS11CRYPTO
|
|
||||||
+#include <pk11/pk11.h>
|
|
||||||
+#endif
|
|
||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
|
||||||
|
|
||||||
diff --git a/lib/isc/include/pk11/internal.h b/lib/isc/include/pk11/internal.h
|
|
||||||
index aa8907a..603712a 100644
|
|
||||||
--- a/lib/isc/include/pk11/internal.h
|
|
||||||
+++ b/lib/isc/include/pk11/internal.h
|
|
||||||
@@ -13,6 +13,8 @@
|
|
||||||
#ifndef PK11_INTERNAL_H
|
|
||||||
#define PK11_INTERNAL_H 1
|
|
||||||
|
|
||||||
+#include <pk11/pk11.h>
|
|
||||||
+
|
|
||||||
/*! \file pk11/internal.h */
|
|
||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
|
||||||
@ -1,120 +0,0 @@
|
|||||||
From 90416594843a56550e40b11561807786219ce1c4 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Evan Hunt <each@isc.org>
|
|
||||||
Date: Mon, 11 Sep 2017 15:01:36 -0700
|
|
||||||
Subject: [PATCH] remap getaddrinfo() to irs_getgetaddrinfo()
|
|
||||||
|
|
||||||
The libirs version of getaddrinfo() cannot be called from within BIND9.
|
|
||||||
|
|
||||||
fix prototypes
|
|
||||||
---
|
|
||||||
lib/irs/include/irs/netdb.h.in | 94 ++++++++++++++++++++++++++++++++++++++++++
|
|
||||||
1 file changed, 94 insertions(+)
|
|
||||||
|
|
||||||
diff --git a/lib/irs/include/irs/netdb.h.in b/lib/irs/include/irs/netdb.h.in
|
|
||||||
index 23dcd37..f36113d 100644
|
|
||||||
--- a/lib/irs/include/irs/netdb.h.in
|
|
||||||
+++ b/lib/irs/include/irs/netdb.h.in
|
|
||||||
@@ -150,6 +150,100 @@ struct addrinfo {
|
|
||||||
#define NI_DGRAM 0x00000010
|
|
||||||
|
|
||||||
/*
|
|
||||||
+ * Define to map into irs_ namespace.
|
|
||||||
+ */
|
|
||||||
+
|
|
||||||
+#define IRS_NAMESPACE
|
|
||||||
+
|
|
||||||
+#ifdef IRS_NAMESPACE
|
|
||||||
+
|
|
||||||
+/*
|
|
||||||
+ * Use our versions not the ones from the C library.
|
|
||||||
+ */
|
|
||||||
+
|
|
||||||
+#ifdef getnameinfo
|
|
||||||
+#undef getnameinfo
|
|
||||||
+#endif
|
|
||||||
+#define getnameinfo irs_getnameinfo
|
|
||||||
+
|
|
||||||
+#ifdef getaddrinfo
|
|
||||||
+#undef getaddrinfo
|
|
||||||
+#endif
|
|
||||||
+#define getaddrinfo irs_getaddrinfo
|
|
||||||
+
|
|
||||||
+#ifdef freeaddrinfo
|
|
||||||
+#undef freeaddrinfo
|
|
||||||
+#endif
|
|
||||||
+#define freeaddrinfo irs_freeaddrinfo
|
|
||||||
+
|
|
||||||
+#ifdef gai_strerror
|
|
||||||
+#undef gai_strerror
|
|
||||||
+#endif
|
|
||||||
+#define gai_strerror irs_gai_strerror
|
|
||||||
+
|
|
||||||
+#endif
|
|
||||||
+
|
|
||||||
+extern int getaddrinfo (const char *name,
|
|
||||||
+ const char *service,
|
|
||||||
+ const struct addrinfo *req,
|
|
||||||
+ struct addrinfo **pai);
|
|
||||||
+extern int getnameinfo (const struct sockaddr *sa,
|
|
||||||
+ socklen_t salen, char *host,
|
|
||||||
+ socklen_t hostlen, char *serv,
|
|
||||||
+ socklen_t servlen, int flags);
|
|
||||||
+extern void freeaddrinfo (struct addrinfo *ai);
|
|
||||||
+extern const char *gai_strerror (int ecode);
|
|
||||||
+
|
|
||||||
+/*
|
|
||||||
+ * Define to map into irs_ namespace.
|
|
||||||
+ */
|
|
||||||
+
|
|
||||||
+#define IRS_NAMESPACE
|
|
||||||
+
|
|
||||||
+#ifdef IRS_NAMESPACE
|
|
||||||
+
|
|
||||||
+/*
|
|
||||||
+ * Use our versions not the ones from the C library.
|
|
||||||
+ */
|
|
||||||
+
|
|
||||||
+#ifdef getnameinfo
|
|
||||||
+#undef getnameinfo
|
|
||||||
+#endif
|
|
||||||
+#define getnameinfo irs_getnameinfo
|
|
||||||
+
|
|
||||||
+#ifdef getaddrinfo
|
|
||||||
+#undef getaddrinfo
|
|
||||||
+#endif
|
|
||||||
+#define getaddrinfo irs_getaddrinfo
|
|
||||||
+
|
|
||||||
+#ifdef freeaddrinfo
|
|
||||||
+#undef freeaddrinfo
|
|
||||||
+#endif
|
|
||||||
+#define freeaddrinfo irs_freeaddrinfo
|
|
||||||
+
|
|
||||||
+#ifdef gai_strerror
|
|
||||||
+#undef gai_strerror
|
|
||||||
+#endif
|
|
||||||
+#define gai_strerror irs_gai_strerror
|
|
||||||
+
|
|
||||||
+int
|
|
||||||
+getaddrinfo(const char *hostname, const char *servname,
|
|
||||||
+ const struct addrinfo *hints, struct addrinfo **res);
|
|
||||||
+
|
|
||||||
+int
|
|
||||||
+getnameinfo(const struct sockaddr *sa, IRS_GETNAMEINFO_SOCKLEN_T salen,
|
|
||||||
+ char *host, IRS_GETNAMEINFO_BUFLEN_T hostlen,
|
|
||||||
+ char *serv, IRS_GETNAMEINFO_BUFLEN_T servlen,
|
|
||||||
+ IRS_GETNAMEINFO_FLAGS_T flags);
|
|
||||||
+
|
|
||||||
+void freeaddrinfo (struct addrinfo *ai);
|
|
||||||
+
|
|
||||||
+IRS_GAISTRERROR_RETURN_T
|
|
||||||
+gai_strerror(int ecode);
|
|
||||||
+
|
|
||||||
+#endif
|
|
||||||
+
|
|
||||||
+/*
|
|
||||||
* Tell Emacs to use C mode on this file.
|
|
||||||
* Local variables:
|
|
||||||
* mode: c
|
|
||||||
--
|
|
||||||
2.9.5
|
|
||||||
|
|
||||||
@ -1,16 +0,0 @@
|
|||||||
diff --git a/lib/dns/dyndb.c b/lib/dns/dyndb.c
|
|
||||||
index 15561ce..e4449b0 100644
|
|
||||||
--- a/lib/dns/dyndb.c
|
|
||||||
+++ b/lib/dns/dyndb.c
|
|
||||||
@@ -133,8 +133,11 @@ load_library(isc_mem_t *mctx, const char *filename, const char *instname,
|
|
||||||
instname, filename);
|
|
||||||
|
|
||||||
flags = RTLD_NOW|RTLD_LOCAL;
|
|
||||||
+#if 0
|
|
||||||
+ /* Shared global namespace is required for dns-pkcs11 library */
|
|
||||||
#if defined(RTLD_DEEPBIND) && !__SANITIZE_ADDRESS__
|
|
||||||
flags |= RTLD_DEEPBIND;
|
|
||||||
+#endif
|
|
||||||
#endif
|
|
||||||
|
|
||||||
handle = dlopen(filename, flags);
|
|
||||||
29
SOURCES/bind-9.11-rh1666814.patch
Normal file
29
SOURCES/bind-9.11-rh1666814.patch
Normal file
@ -0,0 +1,29 @@
|
|||||||
|
From 0f03071080e7fa68433b322359d46abaca2cc5ad Mon Sep 17 00:00:00 2001
|
||||||
|
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
||||||
|
Date: Wed, 16 Jan 2019 16:27:33 +0100
|
||||||
|
Subject: [PATCH] Fix possible crash when loading corrupted file
|
||||||
|
|
||||||
|
Some values passes internal triggers by coincidence. Fix the check and
|
||||||
|
check also first_node_offset before even passing it further.
|
||||||
|
---
|
||||||
|
lib/dns/rbt.c | 4 +++-
|
||||||
|
1 file changed, 3 insertions(+), 1 deletion(-)
|
||||||
|
|
||||||
|
diff --git a/lib/dns/rbt.c b/lib/dns/rbt.c
|
||||||
|
index 5aee5f6..7f2c2d2 100644
|
||||||
|
--- a/lib/dns/rbt.c
|
||||||
|
+++ b/lib/dns/rbt.c
|
||||||
|
@@ -945,7 +945,9 @@ dns_rbt_deserialize_tree(void *base_address, size_t filesize,
|
||||||
|
rbt->root = (dns_rbtnode_t *)((char *)base_address + header_offset +
|
||||||
|
header->first_node_offset);
|
||||||
|
|
||||||
|
- if ((header->nodecount * sizeof(dns_rbtnode_t)) > filesize) {
|
||||||
|
+ if ((header->nodecount * sizeof(dns_rbtnode_t)) > filesize
|
||||||
|
+ || header->first_node_offset > filesize) {
|
||||||
|
+
|
||||||
|
result = ISC_R_INVALIDFILE;
|
||||||
|
goto cleanup;
|
||||||
|
}
|
||||||
|
--
|
||||||
|
2.31.1
|
||||||
|
|
||||||
@ -1,37 +0,0 @@
|
|||||||
From 16c1bd61384e993fef13d7be88fdd34551a2b3ce Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
|
||||||
Date: Wed, 23 Jan 2019 20:12:51 +0100
|
|
||||||
Subject: [PATCH] Use custom random generator only for bind build
|
|
||||||
|
|
||||||
Do not test random entropy on startup when used by DHCP. On most cases
|
|
||||||
random entropy is not even used by DHCP. In cases it is (LDAP SSL), fail
|
|
||||||
whenever it is not available.
|
|
||||||
|
|
||||||
Resolves: rhbz#1668682
|
|
||||||
---
|
|
||||||
lib/dns/openssl_link.c | 2 ++
|
|
||||||
1 file changed, 2 insertions(+)
|
|
||||||
|
|
||||||
diff --git a/lib/dns/openssl_link.c b/lib/dns/openssl_link.c
|
|
||||||
index 91e87d0..2551b0a 100644
|
|
||||||
--- a/lib/dns/openssl_link.c
|
|
||||||
+++ b/lib/dns/openssl_link.c
|
|
||||||
@@ -289,6 +289,7 @@ dst__openssl_init(const char *engine) {
|
|
||||||
#endif
|
|
||||||
#endif /* !defined(OPENSSL_NO_ENGINE) */
|
|
||||||
|
|
||||||
+#ifdef ISC_PLATFORM_USETHREADS
|
|
||||||
/* Protect ourselves against unseeded PRNG */
|
|
||||||
if (RAND_status() != 1) {
|
|
||||||
FATAL_ERROR(__FILE__, __LINE__,
|
|
||||||
@@ -296,6 +297,7 @@ dst__openssl_init(const char *engine) {
|
|
||||||
"cannot be initialized (see the `PRNG not "
|
|
||||||
"seeded' message in the OpenSSL FAQ)");
|
|
||||||
}
|
|
||||||
+#endif /* ISC_PLATFORM_USETHREADS */
|
|
||||||
|
|
||||||
return (ISC_R_SUCCESS);
|
|
||||||
|
|
||||||
--
|
|
||||||
2.20.1
|
|
||||||
|
|
||||||
@ -1,32 +0,0 @@
|
|||||||
From a503519533eb375a5ce1f7566bfc153aac980d87 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Petr Mensik <pemensik@redhat.com>
|
|
||||||
Date: Fri, 9 Jul 2021 20:52:21 +0200
|
|
||||||
Subject: [PATCH] Use proper entropy to initialize tsig keyname
|
|
||||||
|
|
||||||
Random names used on GSS backed nsupdate can conflict in specific
|
|
||||||
situations. That might include starting a lot of machines from
|
|
||||||
containers, where they took all similar time to start. PID and timestamp
|
|
||||||
would be similar and therefore randomness is quite low. Use entropy to
|
|
||||||
generate more random identifier and reduce chance of conflict.
|
|
||||||
---
|
|
||||||
bin/nsupdate/nsupdate.c | 4 +++-
|
|
||||||
1 file changed, 3 insertions(+), 1 deletion(-)
|
|
||||||
|
|
||||||
diff --git a/bin/nsupdate/nsupdate.c b/bin/nsupdate/nsupdate.c
|
|
||||||
index 458aa76..d9e5a2b 100644
|
|
||||||
--- a/bin/nsupdate/nsupdate.c
|
|
||||||
+++ b/bin/nsupdate/nsupdate.c
|
|
||||||
@@ -2941,7 +2941,9 @@ start_gssrequest(dns_name_t *master) {
|
|
||||||
|
|
||||||
keyname = dns_fixedname_initname(&fkname);
|
|
||||||
|
|
||||||
- isc_random_get(&val);
|
|
||||||
+ result = isc_entropy_getdata(entropy, &val, sizeof(val), NULL, 0);
|
|
||||||
+ if (result != ISC_R_SUCCESS)
|
|
||||||
+ isc_random_get(&val);
|
|
||||||
result = isc_string_printf(mykeystr, sizeof(mykeystr), "%u.sig-%s",
|
|
||||||
val, namestr);
|
|
||||||
if (result != ISC_R_SUCCESS)
|
|
||||||
--
|
|
||||||
2.31.1
|
|
||||||
|
|
||||||
@ -1,232 +0,0 @@
|
|||||||
From fff2960981a3294ac641968a17558c8d7eecf74d Mon Sep 17 00:00:00 2001
|
|
||||||
From: Mark Andrews <marka@isc.org>
|
|
||||||
Date: Wed, 24 Aug 2022 12:21:50 +1000
|
|
||||||
Subject: [PATCH] Have dns_zt_apply lock the zone table
|
|
||||||
|
|
||||||
There where a number of places where the zone table should have
|
|
||||||
been locked, but wasn't, when dns_zt_apply was called.
|
|
||||||
|
|
||||||
Added a isc_rwlocktype_t type parameter to dns_zt_apply and adjusted
|
|
||||||
all calls to using it. Removed locks in callers.
|
|
||||||
|
|
||||||
Modified upstream commit for v9_11
|
|
||||||
---
|
|
||||||
bin/named/server.c | 11 ++++++-----
|
|
||||||
bin/named/statschannel.c | 8 ++++----
|
|
||||||
lib/dns/include/dns/zt.h | 4 ++--
|
|
||||||
lib/dns/tests/zt_test.c | 3 ++-
|
|
||||||
lib/dns/view.c | 3 ++-
|
|
||||||
lib/dns/zt.c | 34 +++++++++++++++++++---------------
|
|
||||||
6 files changed, 35 insertions(+), 28 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/bin/named/server.c b/bin/named/server.c
|
|
||||||
index 9826588e6d..0b4b309461 100644
|
|
||||||
--- a/bin/named/server.c
|
|
||||||
+++ b/bin/named/server.c
|
|
||||||
@@ -8723,8 +8723,8 @@ load_configuration(const char *filename, ns_server_t *server,
|
|
||||||
strcmp(view->name, "_bind") != 0)
|
|
||||||
{
|
|
||||||
dns_view_setviewrevert(view);
|
|
||||||
- (void)dns_zt_apply(view->zonetable, false,
|
|
||||||
- removed, view);
|
|
||||||
+ (void)dns_zt_apply(view->zonetable, isc_rwlocktype_read,
|
|
||||||
+ false, removed, view);
|
|
||||||
}
|
|
||||||
dns_view_detach(&view);
|
|
||||||
}
|
|
||||||
@@ -10090,8 +10090,8 @@ add_view_tolist(struct dumpcontext *dctx, dns_view_t *view) {
|
|
||||||
ISC_LIST_INIT(vle->zonelist);
|
|
||||||
ISC_LIST_APPEND(dctx->viewlist, vle, link);
|
|
||||||
if (dctx->dumpzones)
|
|
||||||
- result = dns_zt_apply(view->zonetable, true,
|
|
||||||
- add_zone_tolist, dctx);
|
|
||||||
+ result = dns_zt_apply(view->zonetable, isc_rwlocktype_read,
|
|
||||||
+ true, add_zone_tolist, dctx);
|
|
||||||
return (result);
|
|
||||||
}
|
|
||||||
|
|
||||||
@@ -11367,7 +11367,8 @@ ns_server_sync(ns_server_t *server, isc_lex_t *lex, isc_buffer_t **text) {
|
|
||||||
for (view = ISC_LIST_HEAD(server->viewlist);
|
|
||||||
view != NULL;
|
|
||||||
view = ISC_LIST_NEXT(view, link)) {
|
|
||||||
- result = dns_zt_apply(view->zonetable, false,
|
|
||||||
+ result = dns_zt_apply(view->zonetable,
|
|
||||||
+ isc_rwlocktype_none, false,
|
|
||||||
synczone, &cleanup);
|
|
||||||
if (result != ISC_R_SUCCESS &&
|
|
||||||
tresult == ISC_R_SUCCESS)
|
|
||||||
diff --git a/bin/named/statschannel.c b/bin/named/statschannel.c
|
|
||||||
index 12ab048469..9828df0f4e 100644
|
|
||||||
--- a/bin/named/statschannel.c
|
|
||||||
+++ b/bin/named/statschannel.c
|
|
||||||
@@ -1833,8 +1833,8 @@ generatexml(ns_server_t *server, uint32_t flags,
|
|
||||||
if ((flags & STATS_XML_ZONES) != 0) {
|
|
||||||
TRY0(xmlTextWriterStartElement(writer,
|
|
||||||
ISC_XMLCHAR "zones"));
|
|
||||||
- result = dns_zt_apply(view->zonetable, true,
|
|
||||||
- zone_xmlrender, writer);
|
|
||||||
+ result = dns_zt_apply(view->zonetable, isc_rwlocktype_read,
|
|
||||||
+ true, zone_xmlrender, writer);
|
|
||||||
if (result != ISC_R_SUCCESS)
|
|
||||||
goto error;
|
|
||||||
TRY0(xmlTextWriterEndElement(writer)); /* /zones */
|
|
||||||
@@ -2489,8 +2489,8 @@ generatejson(ns_server_t *server, size_t *msglen,
|
|
||||||
CHECKMEM(za);
|
|
||||||
|
|
||||||
if ((flags & STATS_JSON_ZONES) != 0) {
|
|
||||||
- result = dns_zt_apply(view->zonetable, true,
|
|
||||||
- zone_jsonrender, za);
|
|
||||||
+ result = dns_zt_apply(view->zonetable, isc_rwlocktype_read,
|
|
||||||
+ true, zone_jsonrender, za);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
goto error;
|
|
||||||
}
|
|
||||||
diff --git a/lib/dns/include/dns/zt.h b/lib/dns/include/dns/zt.h
|
|
||||||
index e658e5bb67..94212250da 100644
|
|
||||||
--- a/lib/dns/include/dns/zt.h
|
|
||||||
+++ b/lib/dns/include/dns/zt.h
|
|
||||||
@@ -177,11 +177,11 @@ dns_zt_freezezones(dns_zt_t *zt, bool freeze);
|
|
||||||
*/
|
|
||||||
|
|
||||||
isc_result_t
|
|
||||||
-dns_zt_apply(dns_zt_t *zt, bool stop,
|
|
||||||
+dns_zt_apply(dns_zt_t *zt, isc_rwlocktype_t lock, bool stop,
|
|
||||||
isc_result_t (*action)(dns_zone_t *, void *), void *uap);
|
|
||||||
|
|
||||||
isc_result_t
|
|
||||||
-dns_zt_apply2(dns_zt_t *zt, bool stop, isc_result_t *sub,
|
|
||||||
+dns_zt_apply2(dns_zt_t *zt, isc_rwlocktype_t lock, bool stop, isc_result_t *sub,
|
|
||||||
isc_result_t (*action)(dns_zone_t *, void *), void *uap);
|
|
||||||
/*%<
|
|
||||||
* Apply a given 'action' to all zone zones in the table.
|
|
||||||
diff --git a/lib/dns/tests/zt_test.c b/lib/dns/tests/zt_test.c
|
|
||||||
index 3f1e812d60..ee75303a50 100644
|
|
||||||
--- a/lib/dns/tests/zt_test.c
|
|
||||||
+++ b/lib/dns/tests/zt_test.c
|
|
||||||
@@ -145,7 +145,8 @@ apply(void **state) {
|
|
||||||
assert_non_null(view->zonetable);
|
|
||||||
|
|
||||||
assert_int_equal(nzones, 0);
|
|
||||||
- result = dns_zt_apply(view->zonetable, false, count_zone, &nzones);
|
|
||||||
+ result = dns_zt_apply2(view->zonetable, isc_rwlocktype_read, false, NULL,
|
|
||||||
+ count_zone, &nzones);
|
|
||||||
assert_int_equal(result, ISC_R_SUCCESS);
|
|
||||||
assert_int_equal(nzones, 1);
|
|
||||||
|
|
||||||
diff --git a/lib/dns/view.c b/lib/dns/view.c
|
|
||||||
index f01b4dea0f..bd1ced2863 100644
|
|
||||||
--- a/lib/dns/view.c
|
|
||||||
+++ b/lib/dns/view.c
|
|
||||||
@@ -676,7 +676,8 @@ dns_view_dialup(dns_view_t *view) {
|
|
||||||
REQUIRE(DNS_VIEW_VALID(view));
|
|
||||||
REQUIRE(view->zonetable != NULL);
|
|
||||||
|
|
||||||
- (void)dns_zt_apply(view->zonetable, false, dialup, NULL);
|
|
||||||
+ (void)dns_zt_apply2(view->zonetable, isc_rwlocktype_read, false, NULL,
|
|
||||||
+ dialup, NULL);
|
|
||||||
}
|
|
||||||
|
|
||||||
void
|
|
||||||
diff --git a/lib/dns/zt.c b/lib/dns/zt.c
|
|
||||||
index 3f12e247e0..af65740325 100644
|
|
||||||
--- a/lib/dns/zt.c
|
|
||||||
+++ b/lib/dns/zt.c
|
|
||||||
@@ -202,7 +202,8 @@ flush(dns_zone_t *zone, void *uap) {
|
|
||||||
static void
|
|
||||||
zt_destroy(dns_zt_t *zt) {
|
|
||||||
if (zt->flush) {
|
|
||||||
- (void)dns_zt_apply(zt, false, flush, NULL);
|
|
||||||
+ (void)dns_zt_apply(zt, isc_rwlocktype_none,
|
|
||||||
+ false, flush, NULL);
|
|
||||||
}
|
|
||||||
isc_refcount_destroy(&zt->references);
|
|
||||||
dns_rbt_destroy(&zt->table);
|
|
||||||
@@ -249,9 +250,7 @@ dns_zt_load(dns_zt_t *zt, bool stop) {
|
|
||||||
|
|
||||||
REQUIRE(VALID_ZT(zt));
|
|
||||||
|
|
||||||
- RWLOCK(&zt->rwlock, isc_rwlocktype_read);
|
|
||||||
- result = dns_zt_apply(zt, stop, load, NULL);
|
|
||||||
- RWUNLOCK(&zt->rwlock, isc_rwlocktype_read);
|
|
||||||
+ result = dns_zt_apply2(zt, isc_rwlocktype_read, stop, NULL, load, NULL);
|
|
||||||
return (result);
|
|
||||||
}
|
|
||||||
|
|
||||||
@@ -293,7 +292,7 @@ dns_zt_asyncload2(dns_zt_t *zt, dns_zt_allloaded_t alldone, void *arg,
|
|
||||||
* Prevent loads_pending going to zero while kicking off the loads.
|
|
||||||
*/
|
|
||||||
zt->loads_pending++;
|
|
||||||
- result = dns_zt_apply2(zt, false, NULL, asyncload, ¶ms);
|
|
||||||
+ result = dns_zt_apply2(zt, isc_rwlocktype_none, false, NULL, asyncload, ¶ms);
|
|
||||||
pending = --zt->loads_pending;
|
|
||||||
if (pending != 0) {
|
|
||||||
zt->loaddone = alldone;
|
|
||||||
@@ -342,9 +341,7 @@ dns_zt_loadnew(dns_zt_t *zt, bool stop) {
|
|
||||||
|
|
||||||
REQUIRE(VALID_ZT(zt));
|
|
||||||
|
|
||||||
- RWLOCK(&zt->rwlock, isc_rwlocktype_read);
|
|
||||||
- result = dns_zt_apply(zt, stop, loadnew, NULL);
|
|
||||||
- RWUNLOCK(&zt->rwlock, isc_rwlocktype_read);
|
|
||||||
+ result = dns_zt_apply(zt, isc_rwlocktype_read, stop, loadnew, NULL);
|
|
||||||
return (result);
|
|
||||||
}
|
|
||||||
|
|
||||||
@@ -366,9 +363,7 @@ dns_zt_freezezones(dns_zt_t *zt, bool freeze) {
|
|
||||||
|
|
||||||
REQUIRE(VALID_ZT(zt));
|
|
||||||
|
|
||||||
- RWLOCK(&zt->rwlock, isc_rwlocktype_read);
|
|
||||||
- result = dns_zt_apply2(zt, false, &tresult, freezezones, &freeze);
|
|
||||||
- RWUNLOCK(&zt->rwlock, isc_rwlocktype_read);
|
|
||||||
+ result = dns_zt_apply2(zt, isc_rwlocktype_read, false, &tresult, freezezones, &freeze);
|
|
||||||
if (tresult == ISC_R_NOTFOUND)
|
|
||||||
tresult = ISC_R_SUCCESS;
|
|
||||||
return ((result == ISC_R_SUCCESS) ? tresult : result);
|
|
||||||
@@ -490,14 +485,14 @@ dns_zt_setviewrevert(dns_zt_t *zt) {
|
|
||||||
}
|
|
||||||
|
|
||||||
isc_result_t
|
|
||||||
-dns_zt_apply(dns_zt_t *zt, bool stop,
|
|
||||||
+dns_zt_apply(dns_zt_t *zt, isc_rwlocktype_t lock, bool stop,
|
|
||||||
isc_result_t (*action)(dns_zone_t *, void *), void *uap)
|
|
||||||
{
|
|
||||||
- return (dns_zt_apply2(zt, stop, NULL, action, uap));
|
|
||||||
+ return (dns_zt_apply2(zt, lock, stop, NULL, action, uap));
|
|
||||||
}
|
|
||||||
|
|
||||||
isc_result_t
|
|
||||||
-dns_zt_apply2(dns_zt_t *zt, bool stop, isc_result_t *sub,
|
|
||||||
+dns_zt_apply2(dns_zt_t *zt, isc_rwlocktype_t lock, bool stop, isc_result_t *sub,
|
|
||||||
isc_result_t (*action)(dns_zone_t *, void *), void *uap)
|
|
||||||
{
|
|
||||||
dns_rbtnode_t *node;
|
|
||||||
@@ -508,6 +503,10 @@ dns_zt_apply2(dns_zt_t *zt, bool stop, isc_result_t *sub,
|
|
||||||
REQUIRE(VALID_ZT(zt));
|
|
||||||
REQUIRE(action != NULL);
|
|
||||||
|
|
||||||
+ if (lock != isc_rwlocktype_none) {
|
|
||||||
+ RWLOCK(&zt->rwlock, lock);
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
dns_rbtnodechain_init(&chain, zt->mctx);
|
|
||||||
result = dns_rbtnodechain_first(&chain, zt->table, NULL, NULL);
|
|
||||||
if (result == ISC_R_NOTFOUND) {
|
|
||||||
@@ -538,8 +537,13 @@ dns_zt_apply2(dns_zt_t *zt, bool stop, isc_result_t *sub,
|
|
||||||
|
|
||||||
cleanup:
|
|
||||||
dns_rbtnodechain_invalidate(&chain);
|
|
||||||
- if (sub != NULL)
|
|
||||||
+ if (sub != NULL) {
|
|
||||||
*sub = tresult;
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+ if (lock != isc_rwlocktype_none) {
|
|
||||||
+ RWUNLOCK(&zt->rwlock, lock);
|
|
||||||
+ }
|
|
||||||
|
|
||||||
return (result);
|
|
||||||
}
|
|
||||||
--
|
|
||||||
2.37.2
|
|
||||||
|
|
||||||
@ -1,26 +0,0 @@
|
|||||||
From c8f5b31f0637315c1c45d0287f05fcad2250f40f Mon Sep 17 00:00:00 2001
|
|
||||||
From: Petr Mensik <pemensik@redhat.com>
|
|
||||||
Date: Thu, 13 Oct 2022 15:35:46 +0200
|
|
||||||
Subject: [PATCH] Add include to rwlocktype_t to dns/zt.h
|
|
||||||
|
|
||||||
It got broken as part of bug #2101712 fix. Introduced new definition,
|
|
||||||
which passes during bind build, but breaks bind-dyndb-ldap build.
|
|
||||||
---
|
|
||||||
lib/dns/include/dns/zt.h | 1 +
|
|
||||||
1 file changed, 1 insertion(+)
|
|
||||||
|
|
||||||
diff --git a/lib/dns/include/dns/zt.h b/lib/dns/include/dns/zt.h
|
|
||||||
index 9421225..64c24d6 100644
|
|
||||||
--- a/lib/dns/include/dns/zt.h
|
|
||||||
+++ b/lib/dns/include/dns/zt.h
|
|
||||||
@@ -18,6 +18,7 @@
|
|
||||||
#include <stdbool.h>
|
|
||||||
|
|
||||||
#include <isc/lang.h>
|
|
||||||
+#include <isc/rwlock.h>
|
|
||||||
|
|
||||||
#include <dns/types.h>
|
|
||||||
|
|
||||||
--
|
|
||||||
2.37.3
|
|
||||||
|
|
||||||
File diff suppressed because it is too large
Load Diff
@ -1,780 +0,0 @@
|
|||||||
From af3b530773231f8cff6548e36962ad1f25e38c5d Mon Sep 17 00:00:00 2001
|
|
||||||
From: Evan Hunt <each@isc.org>
|
|
||||||
Date: Thu, 28 Sep 2017 10:09:22 -0700
|
|
||||||
Subject: [PATCH] completed and corrected the crypto-random change
|
|
||||||
|
|
||||||
4724. [func] By default, BIND now uses the random number
|
|
||||||
functions provided by the crypto library (i.e.,
|
|
||||||
OpenSSL or a PKCS#11 provider) as a source of
|
|
||||||
randomness rather than /dev/random. This is
|
|
||||||
suitable for virtual machine environments
|
|
||||||
which have limited entropy pools and lack
|
|
||||||
hardware random number generators.
|
|
||||||
|
|
||||||
This can be overridden by specifying another
|
|
||||||
entropy source via the "random-device" option
|
|
||||||
in named.conf, or via the -r command line option;
|
|
||||||
however, for functions requiring full cryptographic
|
|
||||||
strength, such as DNSSEC key generation, this
|
|
||||||
cannot be overridden. In particular, the -r
|
|
||||||
command line option no longer has any effect on
|
|
||||||
dnssec-keygen.
|
|
||||||
|
|
||||||
This can be disabled by building with
|
|
||||||
"configure --disable-crypto-rand".
|
|
||||||
[RT #31459] [RT #46047]
|
|
||||||
---
|
|
||||||
bin/confgen/keygen.c | 12 +++---
|
|
||||||
bin/dnssec/dnssec-keygen.docbook | 24 +++++++----
|
|
||||||
bin/dnssec/dnssectool.c | 12 +++---
|
|
||||||
bin/named/client.c | 3 +-
|
|
||||||
bin/named/config.c | 4 +-
|
|
||||||
bin/named/controlconf.c | 19 +++++---
|
|
||||||
bin/named/include/named/server.h | 2 +
|
|
||||||
bin/named/interfacemgr.c | 1 +
|
|
||||||
bin/named/query.c | 1 +
|
|
||||||
bin/named/server.c | 52 ++++++++++++++--------
|
|
||||||
bin/nsupdate/nsupdate.c | 4 +-
|
|
||||||
bin/tests/system/pipelined/pipequeries.c | 4 +-
|
|
||||||
bin/tests/system/tkey/keycreate.c | 4 +-
|
|
||||||
bin/tests/system/tkey/keydelete.c | 5 +--
|
|
||||||
doc/arm/Bv9ARM-book.xml | 55 +++++++++++++++++-------
|
|
||||||
doc/arm/notes-rh-changes.xml | 42 ++++++++++++++++++
|
|
||||||
doc/arm/notes.xml | 1 +
|
|
||||||
lib/dns/dst_api.c | 4 +-
|
|
||||||
lib/dns/include/dst/dst.h | 14 +++++-
|
|
||||||
lib/dns/openssl_link.c | 3 +-
|
|
||||||
lib/isc/include/isc/entropy.h | 48 +++++++++++++++------
|
|
||||||
lib/isc/include/isc/random.h | 26 +++++++----
|
|
||||||
lib/isccfg/namedconf.c | 2 +-
|
|
||||||
23 files changed, 240 insertions(+), 102 deletions(-)
|
|
||||||
create mode 100644 doc/arm/notes-rh-changes.xml
|
|
||||||
|
|
||||||
diff --git a/bin/confgen/keygen.c b/bin/confgen/keygen.c
|
|
||||||
index bd269e7..1ac775f 100644
|
|
||||||
--- a/bin/confgen/keygen.c
|
|
||||||
+++ b/bin/confgen/keygen.c
|
|
||||||
@@ -161,17 +161,15 @@ generate_key(isc_mem_t *mctx, const char *randomfile, dns_secalg_t alg,
|
|
||||||
|
|
||||||
DO("create entropy context", isc_entropy_create(mctx, &ectx));
|
|
||||||
|
|
||||||
- if (randomfile != NULL && strcmp(randomfile, "keyboard") == 0) {
|
|
||||||
- randomfile = NULL;
|
|
||||||
- open_keyboard = ISC_ENTROPY_KEYBOARDYES;
|
|
||||||
- }
|
|
||||||
#ifdef ISC_PLATFORM_CRYPTORANDOM
|
|
||||||
- if (randomfile != NULL &&
|
|
||||||
- strcmp(randomfile, ISC_PLATFORM_CRYPTORANDOM) == 0) {
|
|
||||||
- randomfile = NULL;
|
|
||||||
+ if (randomfile == NULL) {
|
|
||||||
isc_entropy_usehook(ectx, true);
|
|
||||||
}
|
|
||||||
#endif
|
|
||||||
+ if (randomfile != NULL && strcmp(randomfile, "keyboard") == 0) {
|
|
||||||
+ randomfile = NULL;
|
|
||||||
+ open_keyboard = ISC_ENTROPY_KEYBOARDYES;
|
|
||||||
+ }
|
|
||||||
DO("start entropy source", isc_entropy_usebestsource(ectx,
|
|
||||||
&entropy_source,
|
|
||||||
randomfile,
|
|
||||||
diff --git a/bin/dnssec/dnssec-keygen.docbook b/bin/dnssec/dnssec-keygen.docbook
|
|
||||||
index bd19e1d..2c09b30 100644
|
|
||||||
--- a/bin/dnssec/dnssec-keygen.docbook
|
|
||||||
+++ b/bin/dnssec/dnssec-keygen.docbook
|
|
||||||
@@ -349,15 +349,23 @@
|
|
||||||
<term>-r <replaceable class="parameter">randomdev</replaceable></term>
|
|
||||||
<listitem>
|
|
||||||
<para>
|
|
||||||
- Specifies the source of randomness. If the operating
|
|
||||||
- system does not provide a <filename>/dev/random</filename>
|
|
||||||
- or equivalent device, the default source of randomness
|
|
||||||
- is keyboard input. <filename>randomdev</filename>
|
|
||||||
- specifies
|
|
||||||
+ Specifies a source of randomness. Normally, when generating
|
|
||||||
+ DNSSEC keys, this option has no effect; the random number
|
|
||||||
+ generation function provided by the cryptographic library will
|
|
||||||
+ be used.
|
|
||||||
+ </para>
|
|
||||||
+ <para>
|
|
||||||
+ If that behavior is disabled at compile time, however,
|
|
||||||
+ the specified file will be used as entropy source
|
|
||||||
+ for key generation. <filename>randomdev</filename> is
|
|
||||||
the name of a character device or file containing random
|
|
||||||
- data to be used instead of the default. The special value
|
|
||||||
- <filename>keyboard</filename> indicates that keyboard
|
|
||||||
- input should be used.
|
|
||||||
+ data to be used. The special value <filename>keyboard</filename>
|
|
||||||
+ indicates that keyboard input should be used.
|
|
||||||
+ </para>
|
|
||||||
+ <para>
|
|
||||||
+ The default is <filename>/dev/random</filename> if the
|
|
||||||
+ operating system provides it or an equivalent device;
|
|
||||||
+ if not, the default source of randomness is keyboard input.
|
|
||||||
</para>
|
|
||||||
</listitem>
|
|
||||||
</varlistentry>
|
|
||||||
diff --git a/bin/dnssec/dnssectool.c b/bin/dnssec/dnssectool.c
|
|
||||||
index 2a0f9c6..6fcd411 100644
|
|
||||||
--- a/bin/dnssec/dnssectool.c
|
|
||||||
+++ b/bin/dnssec/dnssectool.c
|
|
||||||
@@ -241,18 +241,16 @@ setup_entropy(isc_mem_t *mctx, const char *randomfile, isc_entropy_t **ectx) {
|
|
||||||
ISC_LIST_INIT(sources);
|
|
||||||
}
|
|
||||||
|
|
||||||
+#ifdef ISC_PLATFORM_CRYPTORANDOM
|
|
||||||
+ if (randomfile == NULL) {
|
|
||||||
+ isc_entropy_usehook(*ectx, true);
|
|
||||||
+ }
|
|
||||||
+#endif
|
|
||||||
if (randomfile != NULL && strcmp(randomfile, "keyboard") == 0) {
|
|
||||||
usekeyboard = ISC_ENTROPY_KEYBOARDYES;
|
|
||||||
randomfile = NULL;
|
|
||||||
}
|
|
||||||
|
|
||||||
-#ifdef ISC_PLATFORM_CRYPTORANDOM
|
|
||||||
- if (randomfile != NULL &&
|
|
||||||
- strcmp(randomfile, ISC_PLATFORM_CRYPTORANDOM) == 0) {
|
|
||||||
- randomfile = NULL;
|
|
||||||
- isc_entropy_usehook(*ectx, true);
|
|
||||||
- }
|
|
||||||
-#endif
|
|
||||||
result = isc_entropy_usebestsource(*ectx, &source, randomfile,
|
|
||||||
usekeyboard);
|
|
||||||
|
|
||||||
diff --git a/bin/named/client.c b/bin/named/client.c
|
|
||||||
index 4a50ad9..4d140e8 100644
|
|
||||||
--- a/bin/named/client.c
|
|
||||||
+++ b/bin/named/client.c
|
|
||||||
@@ -1768,7 +1768,8 @@ ns_client_addopt(ns_client_t *client, dns_message_t *message,
|
|
||||||
|
|
||||||
isc_buffer_init(&buf, cookie, sizeof(cookie));
|
|
||||||
isc_stdtime_get(&now);
|
|
||||||
- isc_random_get(&nonce);
|
|
||||||
+ nonce = ((isc_rng_random(ns_g_server->rngctx) << 16) |
|
|
||||||
+ isc_rng_random(ns_g_server->rngctx));
|
|
||||||
|
|
||||||
compute_cookie(client, now, nonce, ns_g_server->secret, &buf);
|
|
||||||
|
|
||||||
diff --git a/bin/named/config.c b/bin/named/config.c
|
|
||||||
index 9b343fa..5e663c6 100644
|
|
||||||
--- a/bin/named/config.c
|
|
||||||
+++ b/bin/named/config.c
|
|
||||||
@@ -98,7 +98,9 @@ options {\n\
|
|
||||||
# pid-file \"" NS_LOCALSTATEDIR "/run/named/named.pid\"; /* or /lwresd.pid */\n\
|
|
||||||
port 53;\n\
|
|
||||||
prefetch 2 9;\n"
|
|
||||||
-#ifdef PATH_RANDOMDEV
|
|
||||||
+#if defined(ISC_PLATFORM_CRYPTORANDOM)
|
|
||||||
+" random-device none;\n"
|
|
||||||
+#elif defined(PATH_RANDOMDEV)
|
|
||||||
" random-device \"" PATH_RANDOMDEV "\";\n"
|
|
||||||
#endif
|
|
||||||
" recursing-file \"named.recursing\";\n\
|
|
||||||
diff --git a/bin/named/controlconf.c b/bin/named/controlconf.c
|
|
||||||
index 9fdf49b..42128dc 100644
|
|
||||||
--- a/bin/named/controlconf.c
|
|
||||||
+++ b/bin/named/controlconf.c
|
|
||||||
@@ -327,9 +327,10 @@ log_invalid(isccc_ccmsg_t *ccmsg, isc_result_t result) {
|
|
||||||
|
|
||||||
static void
|
|
||||||
control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
|
||||||
- controlconnection_t *conn;
|
|
||||||
- controllistener_t *listener;
|
|
||||||
- controlkey_t *key;
|
|
||||||
+ controlconnection_t *conn = NULL;
|
|
||||||
+ controllistener_t *listener = NULL;
|
|
||||||
+ ns_server_t *server = NULL;
|
|
||||||
+ controlkey_t *key = NULL;
|
|
||||||
isccc_sexpr_t *request = NULL;
|
|
||||||
isccc_sexpr_t *response = NULL;
|
|
||||||
uint32_t algorithm;
|
|
||||||
@@ -340,16 +341,17 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
|
||||||
isc_buffer_t *text;
|
|
||||||
isc_result_t result;
|
|
||||||
isc_result_t eresult;
|
|
||||||
- isccc_sexpr_t *_ctrl;
|
|
||||||
+ isccc_sexpr_t *_ctrl = NULL;
|
|
||||||
isccc_time_t sent;
|
|
||||||
isccc_time_t exp;
|
|
||||||
uint32_t nonce;
|
|
||||||
- isccc_sexpr_t *data;
|
|
||||||
+ isccc_sexpr_t *data = NULL;
|
|
||||||
|
|
||||||
REQUIRE(event->ev_type == ISCCC_EVENT_CCMSG);
|
|
||||||
|
|
||||||
conn = event->ev_arg;
|
|
||||||
listener = conn->listener;
|
|
||||||
+ server = listener->controls->server;
|
|
||||||
algorithm = DST_ALG_UNKNOWN;
|
|
||||||
secret.rstart = NULL;
|
|
||||||
text = NULL;
|
|
||||||
@@ -462,8 +464,11 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
|
||||||
* Establish nonce.
|
|
||||||
*/
|
|
||||||
if (conn->nonce == 0) {
|
|
||||||
- while (conn->nonce == 0)
|
|
||||||
- isc_random_get(&conn->nonce);
|
|
||||||
+ while (conn->nonce == 0) {
|
|
||||||
+ uint16_t r1 = isc_rng_random(server->rngctx);
|
|
||||||
+ uint16_t r2 = isc_rng_random(server->rngctx);
|
|
||||||
+ conn->nonce = (r1 << 16) | r2;
|
|
||||||
+ }
|
|
||||||
eresult = ISC_R_SUCCESS;
|
|
||||||
} else
|
|
||||||
eresult = ns_control_docommand(request, listener->readonly, &text);
|
|
||||||
diff --git a/bin/named/include/named/server.h b/bin/named/include/named/server.h
|
|
||||||
index 4fd0194..0ba2627 100644
|
|
||||||
--- a/bin/named/include/named/server.h
|
|
||||||
+++ b/bin/named/include/named/server.h
|
|
||||||
@@ -20,6 +20,7 @@
|
|
||||||
#include <isc/log.h>
|
|
||||||
#include <isc/magic.h>
|
|
||||||
#include <isc/quota.h>
|
|
||||||
+#include <isc/random.h>
|
|
||||||
#include <isc/sockaddr.h>
|
|
||||||
#include <isc/types.h>
|
|
||||||
#include <isc/xml.h>
|
|
||||||
@@ -135,6 +136,7 @@ struct ns_server {
|
|
||||||
char * lockfile;
|
|
||||||
|
|
||||||
uint16_t transfer_tcp_message_size;
|
|
||||||
+ isc_rng_t * rngctx;
|
|
||||||
};
|
|
||||||
|
|
||||||
struct ns_altsecret {
|
|
||||||
diff --git a/bin/named/interfacemgr.c b/bin/named/interfacemgr.c
|
|
||||||
index 93aac31..e12fad9 100644
|
|
||||||
--- a/bin/named/interfacemgr.c
|
|
||||||
+++ b/bin/named/interfacemgr.c
|
|
||||||
@@ -17,6 +17,7 @@
|
|
||||||
|
|
||||||
#include <isc/interfaceiter.h>
|
|
||||||
#include <isc/os.h>
|
|
||||||
+#include <isc/random.h>
|
|
||||||
#include <isc/string.h>
|
|
||||||
#include <isc/task.h>
|
|
||||||
#include <isc/util.h>
|
|
||||||
diff --git a/bin/named/query.c b/bin/named/query.c
|
|
||||||
index 58b5914..edf42d2 100644
|
|
||||||
--- a/bin/named/query.c
|
|
||||||
+++ b/bin/named/query.c
|
|
||||||
@@ -20,6 +20,7 @@
|
|
||||||
#include <isc/mem.h>
|
|
||||||
#include <isc/platform.h>
|
|
||||||
#include <isc/print.h>
|
|
||||||
+#include <isc/random.h>
|
|
||||||
#include <isc/rwlock.h>
|
|
||||||
#include <isc/serial.h>
|
|
||||||
#include <isc/stats.h>
|
|
||||||
diff --git a/bin/named/server.c b/bin/named/server.c
|
|
||||||
index b2ae57c..cca7fe8 100644
|
|
||||||
--- a/bin/named/server.c
|
|
||||||
+++ b/bin/named/server.c
|
|
||||||
@@ -8279,21 +8279,32 @@ load_configuration(const char *filename, ns_server_t *server,
|
|
||||||
* Open the source of entropy.
|
|
||||||
*/
|
|
||||||
if (first_time) {
|
|
||||||
+ const char *randomdev = NULL;
|
|
||||||
+ int level = ISC_LOG_ERROR;
|
|
||||||
obj = NULL;
|
|
||||||
result = ns_config_get(maps, "random-device", &obj);
|
|
||||||
- if (result != ISC_R_SUCCESS) {
|
|
||||||
+ if (result == ISC_R_SUCCESS) {
|
|
||||||
+ if (!cfg_obj_isvoid(obj)) {
|
|
||||||
+ level = ISC_LOG_INFO;
|
|
||||||
+ randomdev = cfg_obj_asstring(obj);
|
|
||||||
+ }
|
|
||||||
+ }
|
|
||||||
+ if (randomdev == NULL) {
|
|
||||||
+#ifdef ISC_PLATFORM_CRYPTORANDOM
|
|
||||||
+ isc_entropy_usehook(ns_g_entropy, true);
|
|
||||||
+#else
|
|
||||||
+ if ((obj != NULL) && !cfg_obj_isvoid(obj))
|
|
||||||
+ level = ISC_LOG_INFO;
|
|
||||||
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL,
|
|
||||||
- NS_LOGMODULE_SERVER, ISC_LOG_INFO,
|
|
||||||
+ NS_LOGMODULE_SERVER, level,
|
|
||||||
"no source of entropy found");
|
|
||||||
+ if ((obj == NULL) || cfg_obj_isvoid(obj)) {
|
|
||||||
+ CHECK(ISC_R_FAILURE);
|
|
||||||
+ }
|
|
||||||
+#endif
|
|
||||||
} else {
|
|
||||||
- const char *randomdev = cfg_obj_asstring(obj);
|
|
||||||
-#ifdef ISC_PLATFORM_CRYPTORANDOM
|
|
||||||
- if (strcmp(randomdev, ISC_PLATFORM_CRYPTORANDOM) == 0)
|
|
||||||
- isc_entropy_usehook(ns_g_entropy, true);
|
|
||||||
-#else
|
|
||||||
- int level = ISC_LOG_ERROR;
|
|
||||||
result = isc_entropy_createfilesource(ns_g_entropy,
|
|
||||||
- randomdev);
|
|
||||||
+ randomdev);
|
|
||||||
#ifdef PATH_RANDOMDEV
|
|
||||||
if (ns_g_fallbackentropy != NULL) {
|
|
||||||
level = ISC_LOG_INFO;
|
|
||||||
@@ -8304,8 +8315,8 @@ load_configuration(const char *filename, ns_server_t *server,
|
|
||||||
NS_LOGCATEGORY_GENERAL,
|
|
||||||
NS_LOGMODULE_SERVER,
|
|
||||||
level,
|
|
||||||
- "could not open entropy source "
|
|
||||||
- "%s: %s",
|
|
||||||
+ "could not open "
|
|
||||||
+ "entropy source %s: %s",
|
|
||||||
randomdev,
|
|
||||||
isc_result_totext(result));
|
|
||||||
}
|
|
||||||
@@ -8325,7 +8336,6 @@ load_configuration(const char *filename, ns_server_t *server,
|
|
||||||
}
|
|
||||||
isc_entropy_detach(&ns_g_fallbackentropy);
|
|
||||||
}
|
|
||||||
-#endif
|
|
||||||
#endif
|
|
||||||
}
|
|
||||||
|
|
||||||
@@ -9097,6 +9107,7 @@ ns_server_create(isc_mem_t *mctx, ns_server_t **serverp) {
|
|
||||||
server->in_roothints = NULL;
|
|
||||||
server->blackholeacl = NULL;
|
|
||||||
server->keepresporder = NULL;
|
|
||||||
+ server->rngctx = NULL;
|
|
||||||
|
|
||||||
/* Must be first. */
|
|
||||||
CHECKFATAL(dst_lib_init2(ns_g_mctx, ns_g_entropy,
|
|
||||||
@@ -9123,6 +9134,9 @@ ns_server_create(isc_mem_t *mctx, ns_server_t **serverp) {
|
|
||||||
CHECKFATAL(dns_tkeyctx_create(ns_g_mctx, ns_g_entropy,
|
|
||||||
&server->tkeyctx),
|
|
||||||
"creating TKEY context");
|
|
||||||
+ server->rngctx = NULL;
|
|
||||||
+ CHECKFATAL(isc_rng_create(ns_g_mctx, ns_g_entropy, &server->rngctx),
|
|
||||||
+ "creating random numbers context");
|
|
||||||
|
|
||||||
/*
|
|
||||||
* Setup the server task, which is responsible for coordinating
|
|
||||||
@@ -9329,7 +9343,8 @@ ns_server_destroy(ns_server_t **serverp) {
|
|
||||||
|
|
||||||
if (server->zonemgr != NULL)
|
|
||||||
dns_zonemgr_detach(&server->zonemgr);
|
|
||||||
-
|
|
||||||
+ if (server->rngctx != NULL)
|
|
||||||
+ isc_rng_detach(&server->rngctx);
|
|
||||||
if (server->tkeyctx != NULL)
|
|
||||||
dns_tkeyctx_destroy(&server->tkeyctx);
|
|
||||||
|
|
||||||
@@ -13366,10 +13381,10 @@ newzone_cfgctx_destroy(void **cfgp) {
|
|
||||||
|
|
||||||
static isc_result_t
|
|
||||||
generate_salt(unsigned char *salt, size_t saltlen) {
|
|
||||||
- int i, n;
|
|
||||||
+ size_t i, n;
|
|
||||||
union {
|
|
||||||
unsigned char rnd[256];
|
|
||||||
- uint32_t rnd32[64];
|
|
||||||
+ uint16_t rnd16[128];
|
|
||||||
} rnd;
|
|
||||||
unsigned char text[512 + 1];
|
|
||||||
isc_region_t r;
|
|
||||||
@@ -13379,9 +13394,10 @@ generate_salt(unsigned char *salt, size_t saltlen) {
|
|
||||||
if (saltlen > 256U)
|
|
||||||
return (ISC_R_RANGE);
|
|
||||||
|
|
||||||
- n = (int) (saltlen + sizeof(uint32_t) - 1) / sizeof(uint32_t);
|
|
||||||
- for (i = 0; i < n; i++)
|
|
||||||
- isc_random_get(&rnd.rnd32[i]);
|
|
||||||
+ n = (saltlen + sizeof(uint16_t) - 1) / sizeof(uint16_t);
|
|
||||||
+ for (i = 0; i < n; i++) {
|
|
||||||
+ rnd.rnd16[i] = isc_rng_random(ns_g_server->rngctx);
|
|
||||||
+ }
|
|
||||||
|
|
||||||
memmove(salt, rnd.rnd, saltlen);
|
|
||||||
|
|
||||||
diff --git a/bin/nsupdate/nsupdate.c b/bin/nsupdate/nsupdate.c
|
|
||||||
index 7f15cbc..458aa76 100644
|
|
||||||
--- a/bin/nsupdate/nsupdate.c
|
|
||||||
+++ b/bin/nsupdate/nsupdate.c
|
|
||||||
@@ -289,9 +289,7 @@ setup_entropy(isc_mem_t *mctx, const char *randomfile, isc_entropy_t **ectx) {
|
|
||||||
}
|
|
||||||
|
|
||||||
#ifdef ISC_PLATFORM_CRYPTORANDOM
|
|
||||||
- if (randomfile != NULL &&
|
|
||||||
- strcmp(randomfile, ISC_PLATFORM_CRYPTORANDOM) == 0) {
|
|
||||||
- randomfile = NULL;
|
|
||||||
+ if (randomfile == NULL) {
|
|
||||||
isc_entropy_usehook(*ectx, true);
|
|
||||||
}
|
|
||||||
#endif
|
|
||||||
diff --git a/bin/tests/system/pipelined/pipequeries.c b/bin/tests/system/pipelined/pipequeries.c
|
|
||||||
index 95b65bf..7a81d4e 100644
|
|
||||||
--- a/bin/tests/system/pipelined/pipequeries.c
|
|
||||||
+++ b/bin/tests/system/pipelined/pipequeries.c
|
|
||||||
@@ -280,9 +280,7 @@ main(int argc, char *argv[]) {
|
|
||||||
ectx = NULL;
|
|
||||||
RUNCHECK(isc_entropy_create(mctx, &ectx));
|
|
||||||
#ifdef ISC_PLATFORM_CRYPTORANDOM
|
|
||||||
- if (randomfile != NULL &&
|
|
||||||
- strcmp(randomfile, ISC_PLATFORM_CRYPTORANDOM) == 0) {
|
|
||||||
- randomfile = NULL;
|
|
||||||
+ if (randomfile == NULL) {
|
|
||||||
isc_entropy_usehook(ectx, true);
|
|
||||||
}
|
|
||||||
#endif
|
|
||||||
diff --git a/bin/tests/system/tkey/keycreate.c b/bin/tests/system/tkey/keycreate.c
|
|
||||||
index 3236968..4fa77b6 100644
|
|
||||||
--- a/bin/tests/system/tkey/keycreate.c
|
|
||||||
+++ b/bin/tests/system/tkey/keycreate.c
|
|
||||||
@@ -255,9 +255,7 @@ main(int argc, char *argv[]) {
|
|
||||||
ectx = NULL;
|
|
||||||
RUNCHECK(isc_entropy_create(mctx, &ectx));
|
|
||||||
#ifdef ISC_PLATFORM_CRYPTORANDOM
|
|
||||||
- if (randomfile != NULL &&
|
|
||||||
- strcmp(randomfile, ISC_PLATFORM_CRYPTORANDOM) == 0) {
|
|
||||||
- randomfile = NULL;
|
|
||||||
+ if (randomfile == NULL) {
|
|
||||||
isc_entropy_usehook(ectx, true);
|
|
||||||
}
|
|
||||||
#endif
|
|
||||||
diff --git a/bin/tests/system/tkey/keydelete.c b/bin/tests/system/tkey/keydelete.c
|
|
||||||
index 43fb6b0..105e151 100644
|
|
||||||
--- a/bin/tests/system/tkey/keydelete.c
|
|
||||||
+++ b/bin/tests/system/tkey/keydelete.c
|
|
||||||
@@ -171,6 +171,7 @@ main(int argc, char **argv) {
|
|
||||||
randomfile = argv[2];
|
|
||||||
argv += 2;
|
|
||||||
argc -= 2;
|
|
||||||
+ POST(argc);
|
|
||||||
}
|
|
||||||
keyname = argv[1];
|
|
||||||
|
|
||||||
@@ -182,9 +183,7 @@ main(int argc, char **argv) {
|
|
||||||
ectx = NULL;
|
|
||||||
RUNCHECK(isc_entropy_create(mctx, &ectx));
|
|
||||||
#ifdef ISC_PLATFORM_CRYPTORANDOM
|
|
||||||
- if (randomfile != NULL &&
|
|
||||||
- strcmp(randomfile, ISC_PLATFORM_CRYPTORANDOM) == 0) {
|
|
||||||
- randomfile = NULL;
|
|
||||||
+ if (randomfile == NULL) {
|
|
||||||
isc_entropy_usehook(ectx, true);
|
|
||||||
}
|
|
||||||
#endif
|
|
||||||
diff --git a/doc/arm/Bv9ARM-book.xml b/doc/arm/Bv9ARM-book.xml
|
|
||||||
index ca98726..1f9df2c 100644
|
|
||||||
--- a/doc/arm/Bv9ARM-book.xml
|
|
||||||
+++ b/doc/arm/Bv9ARM-book.xml
|
|
||||||
@@ -5034,22 +5034,45 @@ badresp:1,adberr:0,findfail:0,valfail:0]
|
|
||||||
<term><command>random-device</command></term>
|
|
||||||
<listitem>
|
|
||||||
<para>
|
|
||||||
- This specifies a source of entropy to be used by the server. Entropy is
|
|
||||||
- primarily needed
|
|
||||||
- for DNSSEC operations, such as TKEY transactions and dynamic
|
|
||||||
- update of signed
|
|
||||||
- zones. This option specifies the device (or file) from which
|
|
||||||
- to read
|
|
||||||
- entropy. If it is a file, operations requiring entropy will
|
|
||||||
- fail when the
|
|
||||||
- file has been exhausted. If <command>random-device</command> is not specified, the default value
|
|
||||||
- is
|
|
||||||
- <filename>/dev/random</filename>
|
|
||||||
- (or equivalent) when present, and none otherwise. The
|
|
||||||
- <command>random-device</command> option takes
|
|
||||||
- effect during
|
|
||||||
- the initial configuration load at server startup time and
|
|
||||||
- is ignored on subsequent reloads.
|
|
||||||
+ Specifies a source of entropy to be used by the server.
|
|
||||||
+ This is a device or file from which to read entropy.
|
|
||||||
+ If it is a file, operations requiring entropy
|
|
||||||
+ will fail when the file has been exhausted.
|
|
||||||
+ </para>
|
|
||||||
+ <para>
|
|
||||||
+ Entropy is needed for cryptographic operations such as
|
|
||||||
+ TKEY transactions, dynamic update of signed zones, and
|
|
||||||
+ generation of TSIG session keys. It is also used for
|
|
||||||
+ seeding and stirring the pseudo-random number generator,
|
|
||||||
+ which is used for less critical functions requiring
|
|
||||||
+ randomness such as generation of DNS message transaction
|
|
||||||
+ ID's.
|
|
||||||
+ </para>
|
|
||||||
+ <para>
|
|
||||||
+ If <command>random-device</command> is not specified, or
|
|
||||||
+ if it is set to <literal>none</literal>, entropy will be
|
|
||||||
+ read from the random number generation function supplied
|
|
||||||
+ by the cryptographic library with which BIND was linked
|
|
||||||
+ (i.e. OpenSSL or a PKCS#11 provider).
|
|
||||||
+ </para>
|
|
||||||
+ <para>
|
|
||||||
+ The <command>random-device</command> option takes
|
|
||||||
+ effect during the initial configuration load at server
|
|
||||||
+ startup time and is ignored on subsequent reloads.
|
|
||||||
+ </para>
|
|
||||||
+ <para>
|
|
||||||
+ If BIND is built with
|
|
||||||
+ <command>configure --disable-crypto-rand</command>, then
|
|
||||||
+ entropy is <emphasis>not</emphasis> sourced from the
|
|
||||||
+ cryptographic library. In this case, if
|
|
||||||
+ <command>random-device</command> is not specified, the
|
|
||||||
+ default value is the system random device,
|
|
||||||
+ <filename>/dev/random</filename> or the equivalent.
|
|
||||||
+ This default can be overridden with
|
|
||||||
+ <command>configure --with-randomdev</command>.
|
|
||||||
+ If no system random device exists, then no entropy source
|
|
||||||
+ will be configured, and <command>named</command> will only
|
|
||||||
+ be able to use pseudo-random numbers.
|
|
||||||
</para>
|
|
||||||
</listitem>
|
|
||||||
</varlistentry>
|
|
||||||
diff --git a/doc/arm/notes-rh-changes.xml b/doc/arm/notes-rh-changes.xml
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000..89a4961
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/doc/arm/notes-rh-changes.xml
|
|
||||||
@@ -0,0 +1,42 @@
|
|
||||||
+<!--
|
|
||||||
+ - Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
+ -
|
|
||||||
+ - This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
+ - License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
+ - file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|
||||||
+ -
|
|
||||||
+ - See the COPYRIGHT file distributed with this work for additional
|
|
||||||
+ - information regarding copyright ownership.
|
|
||||||
+-->
|
|
||||||
+
|
|
||||||
+<section xml:id="relnotes_rh_changes"><info><title>Red Hat Specific Changes</title></info>
|
|
||||||
+ <itemizedlist>
|
|
||||||
+ <listitem>
|
|
||||||
+ <para>
|
|
||||||
+ By default, BIND now uses the random number generation functions
|
|
||||||
+ in the cryptographic library (i.e., OpenSSL or a PKCS#11
|
|
||||||
+ provider) as a source of high-quality randomness rather than
|
|
||||||
+ <filename>/dev/random</filename>. This is suitable for virtual
|
|
||||||
+ machine environments, which may have limited entropy pools and
|
|
||||||
+ lack hardware random number generators.
|
|
||||||
+ </para>
|
|
||||||
+ <para>
|
|
||||||
+ This can be overridden by specifying another entropy source via
|
|
||||||
+ the <command>random-device</command> option in
|
|
||||||
+ <filename>named.conf</filename>, or via the <command>-r</command>
|
|
||||||
+ command line option. However, for functions requiring full
|
|
||||||
+ cryptographic strength, such as DNSSEC key generation, this
|
|
||||||
+ <emphasis>cannot</emphasis> be overridden. In particular, the
|
|
||||||
+ <command>-r</command> command line option no longer has any
|
|
||||||
+ effect on <command>dnssec-keygen</command>.
|
|
||||||
+ </para>
|
|
||||||
+ <para>
|
|
||||||
+ This can be disabled by building with
|
|
||||||
+ <command>configure --disable-crypto-rand</command>, in which
|
|
||||||
+ case <filename>/dev/random</filename> will be the default
|
|
||||||
+ entropy source. [RT #31459] [RT #46047]
|
|
||||||
+ </para>
|
|
||||||
+ </listitem>
|
|
||||||
+ </itemizedlist>
|
|
||||||
+</section>
|
|
||||||
+
|
|
||||||
diff --git a/doc/arm/notes.xml b/doc/arm/notes.xml
|
|
||||||
index a5e42c0..f8cb1f9 100644
|
|
||||||
--- a/doc/arm/notes.xml
|
|
||||||
+++ b/doc/arm/notes.xml
|
|
||||||
@@ -47,6 +47,7 @@
|
|
||||||
<xi:include xmlns:xi="http://www.w3.org/2001/XInclude" href="notes-9.11.1.xml"/>
|
|
||||||
<xi:include xmlns:xi="http://www.w3.org/2001/XInclude" href="notes-9.11.0.xml"/>
|
|
||||||
|
|
||||||
+ <xi:include xmlns:xi="http://www.w3.org/2001/XInclude" href="notes-rh-changes.xml"/>
|
|
||||||
<xi:include xmlns:xi="http://www.w3.org/2001/XInclude" href="notes-eol.xml"/>
|
|
||||||
<xi:include xmlns:xi="http://www.w3.org/2001/XInclude" href="notes-thankyou.xml"/>
|
|
||||||
</section>
|
|
||||||
diff --git a/lib/dns/dst_api.c b/lib/dns/dst_api.c
|
|
||||||
index aa54afc..2156384 100644
|
|
||||||
--- a/lib/dns/dst_api.c
|
|
||||||
+++ b/lib/dns/dst_api.c
|
|
||||||
@@ -2017,10 +2017,12 @@ dst__entropy_getdata(void *buf, unsigned int len, bool pseudo) {
|
|
||||||
else
|
|
||||||
flags |= ISC_ENTROPY_BLOCKING;
|
|
||||||
#ifdef ISC_PLATFORM_CRYPTORANDOM
|
|
||||||
+ /* get entropy directly from crypto provider */
|
|
||||||
return (dst_random_getdata(buf, len, NULL, flags));
|
|
||||||
#else
|
|
||||||
+ /* get entropy from entropy source or hook function */
|
|
||||||
return (isc_entropy_getdata(dst_entropy_pool, buf, len, NULL, flags));
|
|
||||||
-#endif
|
|
||||||
+#endif /* ISC_PLATFORM_CRYPTORANDOM */
|
|
||||||
#endif /* PKCS11CRYPTO */
|
|
||||||
}
|
|
||||||
|
|
||||||
diff --git a/lib/dns/include/dst/dst.h b/lib/dns/include/dst/dst.h
|
|
||||||
index 3aba028..180c841 100644
|
|
||||||
--- a/lib/dns/include/dst/dst.h
|
|
||||||
+++ b/lib/dns/include/dst/dst.h
|
|
||||||
@@ -163,8 +163,18 @@ isc_result_t
|
|
||||||
dst_random_getdata(void *data, unsigned int length,
|
|
||||||
unsigned int *returned, unsigned int flags);
|
|
||||||
/*%<
|
|
||||||
- * \brief Return data from the crypto random generator.
|
|
||||||
- * Specialization of isc_entropy_getdata().
|
|
||||||
+ * Gets random data from the random generator provided by the
|
|
||||||
+ * crypto library, if BIND was built with --enable-crypto-rand.
|
|
||||||
+ *
|
|
||||||
+ * See isc_entropy_getdata() for parameter usage. Normally when
|
|
||||||
+ * this function is available, it will be set up as a hook in the
|
|
||||||
+ * entropy context, so that isc_entropy_getdata() is a front-end to
|
|
||||||
+ * this function.
|
|
||||||
+ *
|
|
||||||
+ * Returns:
|
|
||||||
+ * \li ISC_R_SUCCESS on success
|
|
||||||
+ * \li ISC_R_NOTIMPLEMENTED if BIND is built with --disable-crypto-rand
|
|
||||||
+ * \li DST_R_OPENSSLFAILURE, DST_R_CRYPTOFAILURE, or other codes on error
|
|
||||||
*/
|
|
||||||
|
|
||||||
bool
|
|
||||||
diff --git a/lib/dns/openssl_link.c b/lib/dns/openssl_link.c
|
|
||||||
index 3f4f822..cfdc757 100644
|
|
||||||
--- a/lib/dns/openssl_link.c
|
|
||||||
+++ b/lib/dns/openssl_link.c
|
|
||||||
@@ -484,7 +484,8 @@ dst__openssl_getengine(const char *engine) {
|
|
||||||
|
|
||||||
isc_result_t
|
|
||||||
dst_random_getdata(void *data, unsigned int length,
|
|
||||||
- unsigned int *returned, unsigned int flags) {
|
|
||||||
+ unsigned int *returned, unsigned int flags)
|
|
||||||
+{
|
|
||||||
#ifdef ISC_PLATFORM_CRYPTORANDOM
|
|
||||||
#ifndef DONT_REQUIRE_DST_LIB_INIT
|
|
||||||
INSIST(dst__memory_pool != NULL);
|
|
||||||
diff --git a/lib/isc/include/isc/entropy.h b/lib/isc/include/isc/entropy.h
|
|
||||||
index f32c9dc..bed276b 100644
|
|
||||||
--- a/lib/isc/include/isc/entropy.h
|
|
||||||
+++ b/lib/isc/include/isc/entropy.h
|
|
||||||
@@ -189,9 +189,8 @@ isc_entropy_createcallbacksource(isc_entropy_t *ent,
|
|
||||||
/*!<
|
|
||||||
* \brief Create an entropy source that is polled via a callback.
|
|
||||||
*
|
|
||||||
- * This would
|
|
||||||
- * be used when keyboard input is used, or a GUI input method. It can
|
|
||||||
- * also be used to hook in any external entropy source.
|
|
||||||
+ * This would be used when keyboard input is used, or a GUI input method.
|
|
||||||
+ * It can also be used to hook in any external entropy source.
|
|
||||||
*
|
|
||||||
* Samples are added via isc_entropy_addcallbacksample(), below.
|
|
||||||
* _addcallbacksample() is the only function which may be called from
|
|
||||||
@@ -232,15 +231,32 @@ isc_result_t
|
|
||||||
isc_entropy_getdata(isc_entropy_t *ent, void *data, unsigned int length,
|
|
||||||
unsigned int *returned, unsigned int flags);
|
|
||||||
/*!<
|
|
||||||
- * \brief Extract data from the entropy pool. This may load the pool from various
|
|
||||||
- * sources.
|
|
||||||
+ * \brief Get random data from entropy pool 'ent'.
|
|
||||||
*
|
|
||||||
- * Do this by stirring the pool and returning a part of hash as randomness.
|
|
||||||
- * Note that no secrets are given away here since parts of the hash are
|
|
||||||
- * xored together before returned.
|
|
||||||
+ * If a hook has been set up using isc_entropy_sethook() and
|
|
||||||
+ * isc_entropy_usehook(), then the hook function will be called to get
|
|
||||||
+ * random data.
|
|
||||||
*
|
|
||||||
- * Honor the request from the caller to only return good data, any data,
|
|
||||||
- * etc.
|
|
||||||
+ * Otherwise, randomness is extracted from the entropy pool set up in BIND.
|
|
||||||
+ * This may cause the pool to be loaded from various sources. Ths is done
|
|
||||||
+ * by stirring the pool and returning a part of hash as randomness.
|
|
||||||
+ * (Note that no secrets are given away here since parts of the hash are
|
|
||||||
+ * XORed together before returning.)
|
|
||||||
+ *
|
|
||||||
+ * 'flags' may contain ISC_ENTROPY_GOODONLY, ISC_ENTROPY_PARTIAL, or
|
|
||||||
+ * ISC_ENTROPY_BLOCKING. These will be honored if the hook function is
|
|
||||||
+ * not in use. If it is, the flags will be passed to the hook function
|
|
||||||
+ * but it may ignore them.
|
|
||||||
+ *
|
|
||||||
+ * Up to 'length' bytes of randomness are retrieved and copied into 'data'.
|
|
||||||
+ * (If 'returned' is not NULL, and the number of bytes copied is less than
|
|
||||||
+ * 'length' - which may happen if ISC_ENTROPY_PARTIAL was used - then the
|
|
||||||
+ * number of bytes copied will be stored in *returned.)
|
|
||||||
+ *
|
|
||||||
+ * Returns:
|
|
||||||
+ * \li ISC_R_SUCCESS on success
|
|
||||||
+ * \li ISC_R_NOENTROPY if entropy pool is empty
|
|
||||||
+ * \li other error codes are possible when a hook is in use
|
|
||||||
*/
|
|
||||||
|
|
||||||
void
|
|
||||||
@@ -305,13 +321,21 @@ isc_entropy_usebestsource(isc_entropy_t *ectx, isc_entropysource_t **source,
|
|
||||||
void
|
|
||||||
isc_entropy_usehook(isc_entropy_t *ectx, bool onoff);
|
|
||||||
/*!<
|
|
||||||
- * \brief Mark/unmark the given entropy structure as being hooked.
|
|
||||||
+ * \brief Configure entropy context 'ectx' to use the hook function
|
|
||||||
+ *
|
|
||||||
+ * Sets the entropy context to call the hook function for random number
|
|
||||||
+ * generation, if such a function has been configured via
|
|
||||||
+ * isc_entropy_sethook(), whenever isc_entropy_getdata() is called.
|
|
||||||
*/
|
|
||||||
|
|
||||||
void
|
|
||||||
isc_entropy_sethook(isc_entropy_getdata_t myhook);
|
|
||||||
/*!<
|
|
||||||
- * \brief Set the getdata hook (e.g., for a crypto random generator).
|
|
||||||
+ * \brief Set the hook function.
|
|
||||||
+ *
|
|
||||||
+ * The hook function is a global value: only one hook function
|
|
||||||
+ * can be set in the system. Individual entropy contexts may be
|
|
||||||
+ * configured to use it, or not, by calling isc_entropy_usehook().
|
|
||||||
*/
|
|
||||||
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
diff --git a/lib/isc/include/isc/random.h b/lib/isc/include/isc/random.h
|
|
||||||
index f38e80d..3cb1c56 100644
|
|
||||||
--- a/lib/isc/include/isc/random.h
|
|
||||||
+++ b/lib/isc/include/isc/random.h
|
|
||||||
@@ -19,13 +19,23 @@
|
|
||||||
#include <isc/mutex.h>
|
|
||||||
|
|
||||||
/*! \file isc/random.h
|
|
||||||
- * \brief Implements a random state pool which will let the caller return a
|
|
||||||
- * series of possibly non-reproducible random values.
|
|
||||||
+ * \brief Implements pseudo random number generators.
|
|
||||||
*
|
|
||||||
- * Note that the
|
|
||||||
- * strength of these numbers is not all that high, and should not be
|
|
||||||
- * used in cryptography functions. It is useful for jittering values
|
|
||||||
- * a bit here and there, such as timeouts, etc.
|
|
||||||
+ * Two pseudo-random number generators are implemented, in isc_random_*
|
|
||||||
+ * and isc_rng_*. Neither one is very strong; they should not be used
|
|
||||||
+ * in cryptography functions.
|
|
||||||
+ *
|
|
||||||
+ * isc_random_* is based on arc4random if it is available on the system.
|
|
||||||
+ * Otherwise it is based on the posix srand() and rand() functions.
|
|
||||||
+ * It is useful for jittering values a bit here and there, such as
|
|
||||||
+ * timeouts, etc, but should not be relied upon to generate
|
|
||||||
+ * unpredictable sequences (for example, when choosing transaction IDs).
|
|
||||||
+ *
|
|
||||||
+ * isc_rng_* is based on ChaCha20, and is seeded and stirred from the
|
|
||||||
+ * system entropy source. It is stronger than isc_random_* and can
|
|
||||||
+ * be used for generating unpredictable sequences. It is still not as
|
|
||||||
+ * good as using system entropy directly (see entropy.h) and should not
|
|
||||||
+ * be used for cryptographic functions such as key generation.
|
|
||||||
*/
|
|
||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
|
||||||
@@ -113,8 +123,8 @@ isc_rng_random(isc_rng_t *rngctx);
|
|
||||||
uint16_t
|
|
||||||
isc_rng_uniformrandom(isc_rng_t *rngctx, uint16_t upper_bound);
|
|
||||||
/*%<
|
|
||||||
- * Returns a uniformly distributed pseudo random 16-bit unsigned
|
|
||||||
- * integer.
|
|
||||||
+ * Returns a uniformly distributed pseudo-random 16-bit unsigned integer
|
|
||||||
+ * less than 'upper_bound'.
|
|
||||||
*/
|
|
||||||
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
diff --git a/lib/isccfg/namedconf.c b/lib/isccfg/namedconf.c
|
|
||||||
index e74c93b..212194e 100644
|
|
||||||
--- a/lib/isccfg/namedconf.c
|
|
||||||
+++ b/lib/isccfg/namedconf.c
|
|
||||||
@@ -1109,7 +1109,7 @@ options_clauses[] = {
|
|
||||||
{ "pid-file", &cfg_type_qstringornone, 0 },
|
|
||||||
{ "port", &cfg_type_uint32, 0 },
|
|
||||||
{ "querylog", &cfg_type_boolean, 0 },
|
|
||||||
- { "random-device", &cfg_type_qstring, 0 },
|
|
||||||
+ { "random-device", &cfg_type_qstringornone, 0 },
|
|
||||||
{ "recursing-file", &cfg_type_qstring, 0 },
|
|
||||||
{ "recursive-clients", &cfg_type_uint32, 0 },
|
|
||||||
{ "reserved-sockets", &cfg_type_uint32, 0 },
|
|
||||||
--
|
|
||||||
2.26.2
|
|
||||||
|
|
||||||
File diff suppressed because it is too large
Load Diff
@ -1,65 +0,0 @@
|
|||||||
From 8a7bff93037432fcfe8532752e89f150ea3030a4 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Petr Mensik <pemensik@redhat.com>
|
|
||||||
Date: Mon, 9 Oct 2023 19:00:12 +0200
|
|
||||||
Subject: [PATCH] Do not keep stale records by default
|
|
||||||
|
|
||||||
By default set max-stale-ttl to 0, unless stale-answer-enable yes. This
|
|
||||||
were enabled by mistake when backporting fix for CVE-2023-2828. It
|
|
||||||
causes increased cache usage on servers not wanting to serve stale
|
|
||||||
records. Fix that by setting smart defaults based on stale answers
|
|
||||||
enabled with possible manual tuning.
|
|
||||||
---
|
|
||||||
bin/named/server.c | 25 +++++++++++++++++++------
|
|
||||||
1 file changed, 19 insertions(+), 6 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/bin/named/server.c b/bin/named/server.c
|
|
||||||
index 7af90d0..afdc4fa 100644
|
|
||||||
--- a/bin/named/server.c
|
|
||||||
+++ b/bin/named/server.c
|
|
||||||
@@ -3295,7 +3295,7 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
|
||||||
size_t max_acache_size;
|
|
||||||
size_t max_adb_size;
|
|
||||||
uint32_t lame_ttl, fail_ttl;
|
|
||||||
- uint32_t max_stale_ttl;
|
|
||||||
+ uint32_t max_stale_ttl = 0;
|
|
||||||
dns_tsig_keyring_t *ring = NULL;
|
|
||||||
dns_view_t *pview = NULL; /* Production view */
|
|
||||||
isc_mem_t *cmctx = NULL, *hmctx = NULL;
|
|
||||||
@@ -3739,16 +3739,29 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
|
||||||
if (view->maxncachettl > 7 * 24 * 3600)
|
|
||||||
view->maxncachettl = 7 * 24 * 3600;
|
|
||||||
|
|
||||||
- obj = NULL;
|
|
||||||
- result = ns_config_get(maps, "max-stale-ttl", &obj);
|
|
||||||
- INSIST(result == ISC_R_SUCCESS);
|
|
||||||
- max_stale_ttl = cfg_obj_asuint32(obj);
|
|
||||||
-
|
|
||||||
obj = NULL;
|
|
||||||
result = ns_config_get(maps, "stale-answer-enable", &obj);
|
|
||||||
INSIST(result == ISC_R_SUCCESS);
|
|
||||||
view->staleanswersenable = cfg_obj_asboolean(obj);
|
|
||||||
|
|
||||||
+ // RHEL-11785 -- set the stale-ttl to non-zero value only if enabled
|
|
||||||
+ obj = NULL;
|
|
||||||
+ if (view->staleanswersenable) {
|
|
||||||
+ result = ns_config_get(maps, "max-stale-ttl", &obj);
|
|
||||||
+ INSIST(result == ISC_R_SUCCESS);
|
|
||||||
+ max_stale_ttl = cfg_obj_asuint32(obj);
|
|
||||||
+ /*
|
|
||||||
+ * If 'stale-answer-enable' is false, max_stale_ttl is set
|
|
||||||
+ * to 0, meaning keeping stale RRsets in cache is disabled.
|
|
||||||
+ */
|
|
||||||
+ } else {
|
|
||||||
+ /* Do not use default value if stale is disabled,
|
|
||||||
+ * but allow manual overriding, like 'stale-cache-enable' */
|
|
||||||
+ result = ns_config_get(optionmaps, "max-stale-ttl", &obj);
|
|
||||||
+ if (result == ISC_R_SUCCESS)
|
|
||||||
+ max_stale_ttl = cfg_obj_asuint32(obj);
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
result = dns_viewlist_find(&ns_g_server->viewlist, view->name,
|
|
||||||
view->rdclass, &pview);
|
|
||||||
if (result == ISC_R_SUCCESS) {
|
|
||||||
--
|
|
||||||
2.41.0
|
|
||||||
|
|
||||||
65
SOURCES/bind-9.11-tests-variants.patch
Normal file
65
SOURCES/bind-9.11-tests-variants.patch
Normal file
@ -0,0 +1,65 @@
|
|||||||
|
From 607cec78382b016aad0fe041f2e1895b6896c647 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Fri, 1 Mar 2019 15:48:20 +0100
|
||||||
|
Subject: [PATCH] Make alternative named builds testable in system tests
|
||||||
|
|
||||||
|
Red Hat has alternative variant builds of named, which are not ever
|
||||||
|
tested by system tests. New variables make it relatively easy to test
|
||||||
|
alternative variants.
|
||||||
|
|
||||||
|
For sdb variant use:
|
||||||
|
export NAMED_VARIANT=-sdb DNSSEC_VARIANT=
|
||||||
|
|
||||||
|
For pkcs variant use:
|
||||||
|
export NAMED_VARIANT=-pkcs11 DNSSEC_VARIANT=-pkcs11
|
||||||
|
---
|
||||||
|
bin/tests/system/conf.sh.in | 18 +++++++++---------
|
||||||
|
1 file changed, 9 insertions(+), 9 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/bin/tests/system/conf.sh.in b/bin/tests/system/conf.sh.in
|
||||||
|
index d859909..9152f07 100644
|
||||||
|
--- a/bin/tests/system/conf.sh.in
|
||||||
|
+++ b/bin/tests/system/conf.sh.in
|
||||||
|
@@ -37,17 +37,17 @@ DDNSCONFGEN=$TOP/bin/confgen/ddns-confgen
|
||||||
|
DELV=$TOP/bin/delv/delv
|
||||||
|
DIG=$TOP/bin/dig/dig
|
||||||
|
DNSTAPREAD=$TOP/bin/tools/dnstap-read
|
||||||
|
-DSFROMKEY=$TOP/bin/dnssec/dnssec-dsfromkey
|
||||||
|
-FEATURETEST=$TOP/bin/named/feature-test
|
||||||
|
+DSFROMKEY=$TOP/bin/dnssec${DNSSEC_VARIANT}/dnssec-dsfromkey${DNSSEC_VARIANT}
|
||||||
|
+FEATURETEST=$TOP/bin/named${NAMED_VARIANT}/feature-test${NAMED_VARIANT}
|
||||||
|
FSTRM_CAPTURE=@FSTRM_CAPTURE@
|
||||||
|
HOST=$TOP/bin/dig/host
|
||||||
|
-IMPORTKEY=$TOP/bin/dnssec/dnssec-importkey
|
||||||
|
+IMPORTKEY=$TOP/bin/dnssec${DNSSEC_VARIANT}/dnssec-importkey${DNSSEC_VARIANT}
|
||||||
|
JOURNALPRINT=$TOP/bin/tools/named-journalprint
|
||||||
|
-KEYFRLAB=$TOP/bin/dnssec/dnssec-keyfromlabel
|
||||||
|
-KEYGEN=$TOP/bin/dnssec/dnssec-keygen
|
||||||
|
+KEYFRLAB=$TOP/bin/dnssec${DNSSEC_VARIANT}/dnssec-keyfromlabel${DNSSEC_VARIANT}
|
||||||
|
+KEYGEN=$TOP/bin/dnssec${DNSSEC_VARIANT}/dnssec-keygen${DNSSEC_VARIANT}
|
||||||
|
KEYMGR=$TOP/bin/python/dnssec-keymgr
|
||||||
|
MDIG=$TOP/bin/tools/mdig
|
||||||
|
-NAMED=$TOP/bin/named/named
|
||||||
|
+NAMED=$TOP/bin/named${NAMED_VARIANT}/named${NAMED_VARIANT}
|
||||||
|
NSEC3HASH=$TOP/bin/tools/nsec3hash
|
||||||
|
NSLOOKUP=$TOP/bin/dig/nslookup
|
||||||
|
NSUPDATE=$TOP/bin/nsupdate/nsupdate
|
||||||
|
@@ -56,12 +56,12 @@ PK11DEL="$TOP/bin/pkcs11/pkcs11-destroy -s ${SLOT:-0} -p ${HSMPIN:-1234} -w 0"
|
||||||
|
PK11GEN="$TOP/bin/pkcs11/pkcs11-keygen -q -s ${SLOT:-0} -p ${HSMPIN:-1234}"
|
||||||
|
PK11LIST="$TOP/bin/pkcs11/pkcs11-list -s ${SLOT:-0} -p ${HSMPIN:-1234}"
|
||||||
|
RESOLVE=$TOP/bin/tests/system/resolve
|
||||||
|
-REVOKE=$TOP/bin/dnssec/dnssec-revoke
|
||||||
|
+REVOKE=$TOP/bin/dnssec${DNSSEC_VARIANT}/dnssec-revoke${DNSSEC_VARIANT}
|
||||||
|
RNDC=$TOP/bin/rndc/rndc
|
||||||
|
RNDCCONFGEN=$TOP/bin/confgen/rndc-confgen
|
||||||
|
RRCHECKER=$TOP/bin/tools/named-rrchecker
|
||||||
|
-SETTIME=$TOP/bin/dnssec/dnssec-settime
|
||||||
|
-SIGNER=$TOP/bin/dnssec/dnssec-signzone
|
||||||
|
+SETTIME=$TOP/bin/dnssec${DNSSEC_VARIANT}/dnssec-settime${DNSSEC_VARIANT}
|
||||||
|
+SIGNER=$TOP/bin/dnssec${DNSSEC_VARIANT}/dnssec-signzone${DNSSEC_VARIANT}
|
||||||
|
TSIGKEYGEN=$TOP/bin/confgen/tsig-keygen
|
||||||
|
VERIFY=$TOP/bin/dnssec/dnssec-verify
|
||||||
|
WIRETEST=$TOP/bin/tests/wire_test
|
||||||
|
--
|
||||||
|
2.26.3
|
||||||
|
|
||||||
@ -1,30 +0,0 @@
|
|||||||
From 373f07148217a8e70e33446f5108fb42d1079ba6 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Petr Mensik <pemensik@redhat.com>
|
|
||||||
Date: Thu, 21 Feb 2019 22:42:27 +0100
|
|
||||||
Subject: [PATCH] Disable random_test
|
|
||||||
|
|
||||||
It fails too often on some architecture, failing the whole build along.
|
|
||||||
Because it runs two times for pkcs11 and normal build and any of
|
|
||||||
subtests can occasionally fail, stop it.
|
|
||||||
|
|
||||||
It can be used again by defining 'unstable' variable in Kyuafile.
|
|
||||||
---
|
|
||||||
lib/isc/tests/Kyuafile | 2 +-
|
|
||||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
|
||||||
|
|
||||||
diff --git a/lib/isc/tests/Kyuafile b/lib/isc/tests/Kyuafile
|
|
||||||
index 4cd2574..9df2340 100644
|
|
||||||
--- a/lib/isc/tests/Kyuafile
|
|
||||||
+++ b/lib/isc/tests/Kyuafile
|
|
||||||
@@ -19,7 +19,7 @@ tap_test_program{name='pool_test'}
|
|
||||||
tap_test_program{name='print_test'}
|
|
||||||
tap_test_program{name='queue_test'}
|
|
||||||
tap_test_program{name='radix_test'}
|
|
||||||
-tap_test_program{name='random_test'}
|
|
||||||
+tap_test_program{name='random_test', required_configs='unstable'}
|
|
||||||
tap_test_program{name='regex_test'}
|
|
||||||
tap_test_program{name='result_test'}
|
|
||||||
tap_test_program{name='safe_test'}
|
|
||||||
--
|
|
||||||
2.20.1
|
|
||||||
|
|
||||||
@ -1,195 +0,0 @@
|
|||||||
From 9683a4d2524b870c4cee09259cb5eb7b8075a507 Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
|
||||||
Date: Tue, 18 Dec 2018 16:06:26 +0100
|
|
||||||
Subject: [PATCH] Make absolute hostname by dns API instead of strings
|
|
||||||
|
|
||||||
Duplicate all strings in dc_list. Free allocated memory on each record.
|
|
||||||
---
|
|
||||||
bin/sdb_tools/zone2ldap.c | 70 +++++++++++++++++++++++++--------------
|
|
||||||
1 file changed, 45 insertions(+), 25 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/bin/sdb_tools/zone2ldap.c b/bin/sdb_tools/zone2ldap.c
|
|
||||||
index d59936c..9ba73b8 100644
|
|
||||||
--- a/bin/sdb_tools/zone2ldap.c
|
|
||||||
+++ b/bin/sdb_tools/zone2ldap.c
|
|
||||||
@@ -84,6 +84,10 @@ int get_attr_list_size (char **tmp);
|
|
||||||
/* Get a DN */
|
|
||||||
char *build_dn_from_dc_list (char **dc_list, unsigned int ttl, int flag, char *zone);
|
|
||||||
|
|
||||||
+/* Free a DN list */
|
|
||||||
+static void
|
|
||||||
+free_dc_list(char **dc_list);
|
|
||||||
+
|
|
||||||
/* Add to RR list */
|
|
||||||
void add_to_rr_list (char *dn, char *name, char *type, char *data,
|
|
||||||
unsigned int ttl, unsigned int flags);
|
|
||||||
@@ -120,6 +124,7 @@ static char dNSTTL []="dNSTTL";
|
|
||||||
static char zoneName []="zoneName";
|
|
||||||
static char dc []="dc";
|
|
||||||
static char sameZone []="@";
|
|
||||||
+static char dot []=".";
|
|
||||||
/* LDAPMod mod_values: */
|
|
||||||
static char *objectClasses []= { &(topClass[0]), &(dNSZoneClass[0]), NULL };
|
|
||||||
static char *topObjectClasses []= { &(topClass[0]), &(dcObjectClass[0]), &(dNSZoneClass[0]), NULL };
|
|
||||||
@@ -391,6 +396,8 @@ main (int argc, char **argv)
|
|
||||||
}
|
|
||||||
|
|
||||||
}
|
|
||||||
+
|
|
||||||
+ free_dc_list(dc_list);
|
|
||||||
}
|
|
||||||
else
|
|
||||||
{
|
|
||||||
@@ -446,12 +453,18 @@ generate_ldap (dns_name_t * dnsname, dns_rdata_t * rdata, unsigned int ttl)
|
|
||||||
char data[2048];
|
|
||||||
char **dc_list;
|
|
||||||
char *dn;
|
|
||||||
+ size_t argzone_len;
|
|
||||||
+ bool omit_dot;
|
|
||||||
|
|
||||||
isc_buffer_t buff;
|
|
||||||
isc_result_t result;
|
|
||||||
|
|
||||||
isc_buffer_init (&buff, name, sizeof (name));
|
|
||||||
result = dns_name_totext (dnsname, true, &buff);
|
|
||||||
+ argzone_len = strlen(argzone);
|
|
||||||
+ /* If argzone is absolute, output absolute name too */
|
|
||||||
+ omit_dot = (!(argzone_len > 0 && argzone[argzone_len-1] == '.'));
|
|
||||||
+ result = dns_name_totext (dnsname, omit_dot, &buff);
|
|
||||||
isc_result_check (result, "dns_name_totext");
|
|
||||||
name[isc_buffer_usedlength (&buff)] = 0;
|
|
||||||
|
|
||||||
@@ -473,6 +486,7 @@ generate_ldap (dns_name_t * dnsname, dns_rdata_t * rdata, unsigned int ttl)
|
|
||||||
printf ("Adding %s (%s %s) to run queue list.\n", dn, type, data);
|
|
||||||
|
|
||||||
add_to_rr_list (dn, dc_list[len], (char*)type, (char*)data, ttl, DNS_OBJECT);
|
|
||||||
+ free_dc_list(dc_list);
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
@@ -533,12 +547,9 @@ add_to_rr_list (char *dn, char *name, char *type,
|
|
||||||
if (tmp->attrs == (LDAPMod **) NULL)
|
|
||||||
fatal("calloc");
|
|
||||||
|
|
||||||
- for (i = 0; i < (int)flags; i++)
|
|
||||||
- {
|
|
||||||
- tmp->attrs[i] = (LDAPMod *) malloc (sizeof (LDAPMod));
|
|
||||||
- if (tmp->attrs[i] == (LDAPMod *) NULL)
|
|
||||||
- fatal("malloc");
|
|
||||||
- }
|
|
||||||
+ tmp->attrs[0] = (LDAPMod *) malloc (sizeof (LDAPMod));
|
|
||||||
+ if (tmp->attrs[0] == (LDAPMod *) NULL)
|
|
||||||
+ fatal("malloc");
|
|
||||||
tmp->attrs[0]->mod_op = LDAP_MOD_ADD;
|
|
||||||
tmp->attrs[0]->mod_type = objectClass;
|
|
||||||
|
|
||||||
@@ -554,9 +565,18 @@ add_to_rr_list (char *dn, char *name, char *type,
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
+ for (i = 1; i < (int)flags-1; i++)
|
|
||||||
+ {
|
|
||||||
+ tmp->attrs[i] = (LDAPMod *) malloc (sizeof (LDAPMod));
|
|
||||||
+ if (tmp->attrs[i] == (LDAPMod *) NULL)
|
|
||||||
+ fatal("malloc");
|
|
||||||
+ }
|
|
||||||
+ tmp->attrs[i] = NULL;
|
|
||||||
+
|
|
||||||
+
|
|
||||||
tmp->attrs[1]->mod_op = LDAP_MOD_ADD;
|
|
||||||
tmp->attrs[1]->mod_type = relativeDomainName;
|
|
||||||
- tmp->attrs[1]->mod_values = (char **) calloc (sizeof (char *), 2);
|
|
||||||
+ tmp->attrs[1]->mod_values = (char **) calloc (sizeof (char *), 3);
|
|
||||||
|
|
||||||
if (tmp->attrs[1]->mod_values == (char **)NULL)
|
|
||||||
fatal("calloc");
|
|
||||||
@@ -701,24 +721,16 @@ hostname_to_dn_list (char *hostname, char *zone, unsigned int flags)
|
|
||||||
{
|
|
||||||
char *tmp;
|
|
||||||
int i = 0;
|
|
||||||
+ int j = 0;
|
|
||||||
char *hname=0L, *last=0L;
|
|
||||||
int hlen=strlen(hostname), zlen=(strlen(zone));
|
|
||||||
|
|
||||||
/* printf("hostname: %s zone: %s\n",hostname, zone); */
|
|
||||||
- hname=0L;
|
|
||||||
if(flags == DNS_OBJECT)
|
|
||||||
{
|
|
||||||
- if( (zone[ zlen - 1 ] == '.') && (hostname[hlen - 1] != '.') )
|
|
||||||
- {
|
|
||||||
- hname=(char*)malloc(hlen + 1);
|
|
||||||
- hlen += 1;
|
|
||||||
- sprintf(hname, "%s.", hostname);
|
|
||||||
- hostname = hname;
|
|
||||||
- }
|
|
||||||
if(strcmp(hostname, zone) == 0)
|
|
||||||
{
|
|
||||||
- if( hname == 0 )
|
|
||||||
- hname=strdup(hostname);
|
|
||||||
+ hname= strdup(hostname);
|
|
||||||
last = strdup(sameZone);
|
|
||||||
}else
|
|
||||||
{
|
|
||||||
@@ -726,8 +738,6 @@ hostname_to_dn_list (char *hostname, char *zone, unsigned int flags)
|
|
||||||
||( strcmp( hostname + (hlen - zlen), zone ) != 0)
|
|
||||||
)
|
|
||||||
{
|
|
||||||
- if( hname != 0 )
|
|
||||||
- free(hname);
|
|
||||||
hname=(char*)malloc( hlen + zlen + 1);
|
|
||||||
if( *zone == '.' )
|
|
||||||
sprintf(hname, "%s%s", hostname, zone);
|
|
||||||
@@ -735,8 +745,7 @@ hostname_to_dn_list (char *hostname, char *zone, unsigned int flags)
|
|
||||||
sprintf(hname,"%s",zone);
|
|
||||||
}else
|
|
||||||
{
|
|
||||||
- if( hname == 0 )
|
|
||||||
- hname = strdup(hostname);
|
|
||||||
+ hname = strdup(hostname);
|
|
||||||
}
|
|
||||||
last = hname;
|
|
||||||
}
|
|
||||||
@@ -749,18 +758,21 @@ hostname_to_dn_list (char *hostname, char *zone, unsigned int flags)
|
|
||||||
for (tmp = strrchr (hname, '.'); tmp != (char *) 0;
|
|
||||||
tmp = strrchr (hname, '.'))
|
|
||||||
{
|
|
||||||
- if( *( tmp + 1 ) != '\0' )
|
|
||||||
+ tmp[0] = '\0';
|
|
||||||
+ if( tmp[1] != '\0' )
|
|
||||||
{
|
|
||||||
- *tmp = '\0';
|
|
||||||
dn_buffer[i++] = ++tmp;
|
|
||||||
}else
|
|
||||||
{ /* trailing '.' ! */
|
|
||||||
- dn_buffer[i++] = strdup(".");
|
|
||||||
- *tmp = '\0';
|
|
||||||
+ dn_buffer[i++] = dot;
|
|
||||||
if( tmp == hname )
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
+ for (j=0; j<i; j++)
|
|
||||||
+ {
|
|
||||||
+ dn_buffer[j] = strdup(dn_buffer[j]);
|
|
||||||
+ }
|
|
||||||
if( ( last != hname ) && (tmp != hname) )
|
|
||||||
dn_buffer[i++] = hname;
|
|
||||||
dn_buffer[i++] = last;
|
|
||||||
@@ -820,6 +832,14 @@ build_dn_from_dc_list (char **dc_list, unsigned int ttl, int flag, char *zone)
|
|
||||||
return dn;
|
|
||||||
}
|
|
||||||
|
|
||||||
+static void
|
|
||||||
+free_dc_list(char **dc_list)
|
|
||||||
+{
|
|
||||||
+ for (; *dc_list; dc_list++) {
|
|
||||||
+ free(*dc_list);
|
|
||||||
+ *dc_list=NULL;
|
|
||||||
+ }
|
|
||||||
+}
|
|
||||||
|
|
||||||
/* Initialize LDAP Conn */
|
|
||||||
void
|
|
||||||
--
|
|
||||||
2.21.1
|
|
||||||
|
|
||||||
83
SOURCES/bind-9.14-config-pkcs11.patch
Normal file
83
SOURCES/bind-9.14-config-pkcs11.patch
Normal file
@ -0,0 +1,83 @@
|
|||||||
|
From e6ab9c67f0a14adc23c1067e03a106da1b1651b7 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Fri, 18 Oct 2019 21:30:52 +0200
|
||||||
|
Subject: [PATCH] Move USE_PKCS11 and USE_OPENSSL out of config.h
|
||||||
|
|
||||||
|
Building two variants with the same common code requires to unset
|
||||||
|
USE_PKCS11 on part of build. That is not possible with config.h value.
|
||||||
|
Move it as normal define to CDEFINES.
|
||||||
|
---
|
||||||
|
bin/confgen/Makefile.in | 2 +-
|
||||||
|
configure.ac | 8 ++++++--
|
||||||
|
lib/dns/dst_internal.h | 12 +++++++++---
|
||||||
|
3 files changed, 16 insertions(+), 6 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/bin/confgen/Makefile.in b/bin/confgen/Makefile.in
|
||||||
|
index 1b7512d..c126bf3 100644
|
||||||
|
--- a/bin/confgen/Makefile.in
|
||||||
|
+++ b/bin/confgen/Makefile.in
|
||||||
|
@@ -22,7 +22,7 @@ VERSION=@BIND9_VERSION@
|
||||||
|
CINCLUDES = -I${srcdir}/include ${ISC_INCLUDES} ${ISCCC_INCLUDES} \
|
||||||
|
${ISCCFG_INCLUDES} ${DNS_INCLUDES} ${BIND9_INCLUDES}
|
||||||
|
|
||||||
|
-CDEFINES =
|
||||||
|
+CDEFINES = @USE_PKCS11@
|
||||||
|
CWARNINGS =
|
||||||
|
|
||||||
|
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
|
diff --git a/configure.ac b/configure.ac
|
||||||
|
index f5483fe..08a7d8a 100644
|
||||||
|
--- a/configure.ac
|
||||||
|
+++ b/configure.ac
|
||||||
|
@@ -935,10 +935,14 @@ AC_SUBST([PKCS11_TEST])
|
||||||
|
AC_SUBST([PKCS11_TOOLS])
|
||||||
|
AC_SUBST([PKCS11_MANS])
|
||||||
|
|
||||||
|
+USE_PKCS11='-DUSE_PKCS11=0'
|
||||||
|
+USE_OPENSSL='-DUSE_OPENSSL=0'
|
||||||
|
AC_SUBST([CRYPTO])
|
||||||
|
AS_CASE([$CRYPTO],
|
||||||
|
- [pkcs11],[AC_DEFINE([USE_PKCS11], [1], [define if PKCS11 is used for Public-Key Cryptography])],
|
||||||
|
- [AC_DEFINE([USE_OPENSSL], [1], [define if OpenSSL is used for Public-Key Cryptography])])
|
||||||
|
+ [pkcs11],[USE_PKCS11='-DUSE_PKCS11=1'],
|
||||||
|
+ [USE_OPENSSL='-DUSE_OPENSSL=1'])
|
||||||
|
+AC_SUBST(USE_PKCS11)
|
||||||
|
+AC_SUBST(USE_OPENSSL)
|
||||||
|
|
||||||
|
# preparation for automake
|
||||||
|
# AM_CONDITIONAL([PKCS11_TOOLS], [test "$with_native_pkcs11" = "yes"])
|
||||||
|
diff --git a/lib/dns/dst_internal.h b/lib/dns/dst_internal.h
|
||||||
|
index 2c3b4a3..55e9dc4 100644
|
||||||
|
--- a/lib/dns/dst_internal.h
|
||||||
|
+++ b/lib/dns/dst_internal.h
|
||||||
|
@@ -38,6 +38,13 @@
|
||||||
|
#include <isc/stdtime.h>
|
||||||
|
#include <isc/types.h>
|
||||||
|
|
||||||
|
+#ifndef USE_PKCS11
|
||||||
|
+#define USE_PKCS11 0
|
||||||
|
+#endif
|
||||||
|
+#ifndef USE_OPENSSL
|
||||||
|
+#define USE_OPENSSL (! USE_PKCS11)
|
||||||
|
+#endif
|
||||||
|
+
|
||||||
|
#if USE_PKCS11
|
||||||
|
#include <pk11/pk11.h>
|
||||||
|
#include <pk11/site.h>
|
||||||
|
@@ -116,11 +123,10 @@ struct dst_key {
|
||||||
|
void *generic;
|
||||||
|
dns_gss_ctx_id_t gssctx;
|
||||||
|
DH *dh;
|
||||||
|
-#if USE_OPENSSL
|
||||||
|
- EVP_PKEY *pkey;
|
||||||
|
-#endif /* if USE_OPENSSL */
|
||||||
|
#if USE_PKCS11
|
||||||
|
pk11_object_t *pkey;
|
||||||
|
+#else
|
||||||
|
+ EVP_PKEY *pkey;
|
||||||
|
#endif /* if USE_PKCS11 */
|
||||||
|
dst_hmac_key_t *hmac_key;
|
||||||
|
} keydata; /*%< pointer to key in crypto pkg fmt */
|
||||||
|
--
|
||||||
|
2.26.2
|
||||||
|
|
||||||
@ -1,58 +0,0 @@
|
|||||||
From 6d6acf236841da5c2511f8afcd3e4a89af4c5658 Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Witold=20Kr=C4=99cicki?= <wpk@isc.org>
|
|
||||||
Date: Fri, 14 Feb 2020 09:18:48 +0100
|
|
||||||
Subject: [PATCH] Use RESOLVER_NTASKS_PERCPU - 32 for regular tuning, 8 for
|
|
||||||
small
|
|
||||||
|
|
||||||
Modify original upstream commit 0d80266f7e3, add high limit of used
|
|
||||||
tasks. Minimum would be lower on machines with few cpus, but maximum
|
|
||||||
would stay unchanged. Should prevent negatives of this change.
|
|
||||||
|
|
||||||
Signed-off-by: Petr Mensik <pemensik@redhat.com>
|
|
||||||
---
|
|
||||||
bin/named/server.c | 12 ++++++++----
|
|
||||||
1 file changed, 8 insertions(+), 4 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/bin/named/server.c b/bin/named/server.c
|
|
||||||
index 39b1124..94b4daa 100644
|
|
||||||
--- a/bin/named/server.c
|
|
||||||
+++ b/bin/named/server.c
|
|
||||||
@@ -148,11 +148,13 @@
|
|
||||||
#endif
|
|
||||||
|
|
||||||
#ifdef TUNE_LARGE
|
|
||||||
-#define RESOLVER_NTASKS 523
|
|
||||||
+#define RESOLVER_NTASKS_MAX 523
|
|
||||||
+#define RESOLVER_NTASKS_PERCPU 32
|
|
||||||
#define UDPBUFFERS 32768
|
|
||||||
#define EXCLBUFFERS 32768
|
|
||||||
#else
|
|
||||||
-#define RESOLVER_NTASKS 31
|
|
||||||
+#define RESOLVER_NTASKS_MAX 31
|
|
||||||
+#define RESOLVER_NTASKS_PERCPU 8
|
|
||||||
#define UDPBUFFERS 1000
|
|
||||||
#define EXCLBUFFERS 4096
|
|
||||||
#endif /* TUNE_LARGE */
|
|
||||||
@@ -3318,7 +3320,7 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
|
||||||
ns_cache_t *nsc;
|
|
||||||
bool zero_no_soattl;
|
|
||||||
dns_acl_t *clients = NULL, *mapped = NULL, *excluded = NULL;
|
|
||||||
- unsigned int query_timeout, ndisp;
|
|
||||||
+ unsigned int query_timeout, ndisp, ntasks;
|
|
||||||
bool old_rpz_ok = false;
|
|
||||||
isc_dscp_t dscp4 = -1, dscp6 = -1;
|
|
||||||
dns_dyndbctx_t *dctx = NULL;
|
|
||||||
@@ -3926,7 +3928,9 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
|
||||||
dns_view_setresquerystats(view, resquerystats);
|
|
||||||
|
|
||||||
ndisp = 4 * ISC_MIN(ns_g_udpdisp, MAX_UDP_DISPATCH);
|
|
||||||
- CHECK(dns_view_createresolver(view, ns_g_taskmgr, RESOLVER_NTASKS,
|
|
||||||
+ ntasks = ISC_MIN(RESOLVER_NTASKS_PERCPU * ns_g_cpus,
|
|
||||||
+ RESOLVER_NTASKS_MAX);
|
|
||||||
+ CHECK(dns_view_createresolver(view, ns_g_taskmgr, ntasks,
|
|
||||||
ndisp, ns_g_socketmgr, ns_g_timermgr,
|
|
||||||
resopts, ns_g_dispatchmgr,
|
|
||||||
dispatch4, dispatch6));
|
|
||||||
--
|
|
||||||
2.34.1
|
|
||||||
|
|
||||||
@ -1,4 +1,4 @@
|
|||||||
From 800ef75553881527e2406f22887e976bb1ba3bfe Mon Sep 17 00:00:00 2001
|
From bd8fdeb2d1ece6db6dfe9fdc024f3a81440c1c0c Mon Sep 17 00:00:00 2001
|
||||||
From: Mark Andrews <marka@isc.org>
|
From: Mark Andrews <marka@isc.org>
|
||||||
Date: Tue, 18 Jan 2022 00:19:47 +1100
|
Date: Tue, 18 Jan 2022 00:19:47 +1100
|
||||||
Subject: [PATCH] Add tests for forwarder cache poisoning scenarios
|
Subject: [PATCH] Add tests for forwarder cache poisoning scenarios
|
||||||
@ -15,43 +15,39 @@ Subject: [PATCH] Add tests for forwarder cache poisoning scenarios
|
|||||||
not cached (this was already working correctly, but was not explicitly
|
not cached (this was already working correctly, but was not explicitly
|
||||||
tested before).
|
tested before).
|
||||||
|
|
||||||
- v9_11 backport: Revert primary/secondary to master/slave,
|
|
||||||
backport rndc helper, backport ns8 config.
|
|
||||||
|
|
||||||
(cherry picked from commit bf3fffff67e1de78e9387a93674d471bf4291604)
|
(cherry picked from commit bf3fffff67e1de78e9387a93674d471bf4291604)
|
||||||
(cherry picked from commit 29f08170f05c2c96fb67f3b561b46aa0bae356f7)
|
(cherry picked from commit 59d1eb3ff810145c8098a0a4fbf93ef4380ad739)
|
||||||
---
|
---
|
||||||
bin/tests/system/forward/ans11/ans.py | 136 ++++++++++++++++++
|
bin/tests/system/forward/ans11/ans.py | 136 ++++++++++++++++++
|
||||||
bin/tests/system/forward/clean.sh | 2 +
|
bin/tests/system/forward/clean.sh | 2 +
|
||||||
bin/tests/system/forward/ns1/diditwork.net.db | 20 +++
|
bin/tests/system/forward/ns1/diditwork.net.db | 22 +++
|
||||||
bin/tests/system/forward/ns1/named.conf.in | 20 +++
|
bin/tests/system/forward/ns1/named.conf.in | 20 +++
|
||||||
bin/tests/system/forward/ns1/net.example.lll | 13 ++
|
bin/tests/system/forward/ns1/net.example.lll | 15 ++
|
||||||
bin/tests/system/forward/ns1/spoofed.net.db | 20 +++
|
bin/tests/system/forward/ns1/spoofed.net.db | 22 +++
|
||||||
bin/tests/system/forward/ns1/sub.local.net.db | 20 +++
|
bin/tests/system/forward/ns1/sub.local.net.db | 22 +++
|
||||||
bin/tests/system/forward/ns10/fakenet.zone | 15 ++
|
bin/tests/system/forward/ns10/fakenet.zone | 17 +++
|
||||||
bin/tests/system/forward/ns10/fakenet2.zone | 13 ++
|
bin/tests/system/forward/ns10/fakenet2.zone | 15 ++
|
||||||
.../system/forward/ns10/fakesublocalnet.zone | 13 ++
|
.../system/forward/ns10/fakesublocalnet.zone | 15 ++
|
||||||
.../system/forward/ns10/fakesublocaltld.zone | 13 ++
|
.../system/forward/ns10/fakesublocaltld.zone | 15 ++
|
||||||
bin/tests/system/forward/ns10/named.conf.in | 51 +++++++
|
bin/tests/system/forward/ns10/named.conf.in | 53 +++++++
|
||||||
bin/tests/system/forward/ns10/net.example.lll | 13 ++
|
bin/tests/system/forward/ns10/net.example.lll | 15 ++
|
||||||
bin/tests/system/forward/ns10/spoofednet.zone | 14 ++
|
bin/tests/system/forward/ns10/spoofednet.zone | 16 +++
|
||||||
|
bin/tests/system/forward/ns2/tld.db | 6 +
|
||||||
bin/tests/system/forward/ns4/named.conf.in | 5 +
|
bin/tests/system/forward/ns4/named.conf.in | 5 +
|
||||||
bin/tests/system/forward/ns4/sibling.tld.db | 20 +++
|
bin/tests/system/forward/ns4/sibling.tld.db | 22 +++
|
||||||
bin/tests/system/forward/ns8/named.conf.in | 33 +++++
|
bin/tests/system/forward/ns8/named.conf.in | 5 +
|
||||||
bin/tests/system/forward/ns8/root.db | 11 ++
|
bin/tests/system/forward/ns8/sub.local.tld.db | 15 ++
|
||||||
bin/tests/system/forward/ns8/sub.local.tld.db | 13 ++
|
bin/tests/system/forward/ns9/local.net.db | 16 +++
|
||||||
bin/tests/system/forward/ns9/local.net.db | 14 ++
|
bin/tests/system/forward/ns9/local.tld.db | 15 ++
|
||||||
bin/tests/system/forward/ns9/local.tld.db | 13 ++
|
bin/tests/system/forward/ns9/named1.conf.in | 67 +++++++++
|
||||||
bin/tests/system/forward/ns9/named1.conf.in | 65 +++++++++
|
bin/tests/system/forward/ns9/named2.conf.in | 70 +++++++++
|
||||||
bin/tests/system/forward/ns9/named2.conf.in | 68 +++++++++
|
bin/tests/system/forward/ns9/named3.conf.in | 50 +++++++
|
||||||
bin/tests/system/forward/ns9/named3.conf.in | 48 +++++++
|
bin/tests/system/forward/ns9/named4.conf.in | 47 ++++++
|
||||||
bin/tests/system/forward/ns9/named4.conf.in | 45 ++++++
|
bin/tests/system/forward/ns9/root.db | 13 ++
|
||||||
bin/tests/system/forward/ns9/root.db | 11 ++
|
bin/tests/system/forward/setup.sh | 2 +
|
||||||
bin/tests/system/forward/prereq.sh | 14 ++
|
bin/tests/system/forward/tests.sh | 122 ++++++++++++++++
|
||||||
bin/tests/system/forward/setup.sh | 3 +
|
|
||||||
bin/tests/system/forward/tests.sh | 126 ++++++++++++++++
|
|
||||||
bin/tests/system/ifconfig.sh | 8 +-
|
bin/tests/system/ifconfig.sh | 8 +-
|
||||||
30 files changed, 856 insertions(+), 4 deletions(-)
|
29 files changed, 844 insertions(+), 4 deletions(-)
|
||||||
create mode 100644 bin/tests/system/forward/ans11/ans.py
|
create mode 100644 bin/tests/system/forward/ans11/ans.py
|
||||||
create mode 100644 bin/tests/system/forward/ns1/diditwork.net.db
|
create mode 100644 bin/tests/system/forward/ns1/diditwork.net.db
|
||||||
create mode 100644 bin/tests/system/forward/ns1/net.example.lll
|
create mode 100644 bin/tests/system/forward/ns1/net.example.lll
|
||||||
@ -65,8 +61,6 @@ Subject: [PATCH] Add tests for forwarder cache poisoning scenarios
|
|||||||
create mode 100644 bin/tests/system/forward/ns10/net.example.lll
|
create mode 100644 bin/tests/system/forward/ns10/net.example.lll
|
||||||
create mode 100644 bin/tests/system/forward/ns10/spoofednet.zone
|
create mode 100644 bin/tests/system/forward/ns10/spoofednet.zone
|
||||||
create mode 100644 bin/tests/system/forward/ns4/sibling.tld.db
|
create mode 100644 bin/tests/system/forward/ns4/sibling.tld.db
|
||||||
create mode 100644 bin/tests/system/forward/ns8/named.conf.in
|
|
||||||
create mode 100644 bin/tests/system/forward/ns8/root.db
|
|
||||||
create mode 100644 bin/tests/system/forward/ns8/sub.local.tld.db
|
create mode 100644 bin/tests/system/forward/ns8/sub.local.tld.db
|
||||||
create mode 100644 bin/tests/system/forward/ns9/local.net.db
|
create mode 100644 bin/tests/system/forward/ns9/local.net.db
|
||||||
create mode 100644 bin/tests/system/forward/ns9/local.tld.db
|
create mode 100644 bin/tests/system/forward/ns9/local.tld.db
|
||||||
@ -78,20 +72,20 @@ Subject: [PATCH] Add tests for forwarder cache poisoning scenarios
|
|||||||
|
|
||||||
diff --git a/bin/tests/system/forward/ans11/ans.py b/bin/tests/system/forward/ans11/ans.py
|
diff --git a/bin/tests/system/forward/ans11/ans.py b/bin/tests/system/forward/ans11/ans.py
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..2956cf6eff
|
index 0000000000..1d35b3d3f1
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ans11/ans.py
|
+++ b/bin/tests/system/forward/ans11/ans.py
|
||||||
@@ -0,0 +1,136 @@
|
@@ -0,0 +1,136 @@
|
||||||
+############################################################################
|
|
||||||
+# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+#
|
+#
|
||||||
|
+# SPDX-License-Identifier: MPL-2.0
|
||||||
|
+#
|
||||||
+# This Source Code Form is subject to the terms of the Mozilla Public
|
+# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+# License, v. 2.0. If a copy of the MPL was not distributed with this
|
+# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+#
|
+#
|
||||||
+# See the COPYRIGHT file distributed with this work for additional
|
+# See the COPYRIGHT file distributed with this work for additional
|
||||||
+# information regarding copyright ownership.
|
+# information regarding copyright ownership.
|
||||||
+############################################################################
|
|
||||||
+
|
+
|
||||||
+from __future__ import print_function
|
+from __future__ import print_function
|
||||||
+import os
|
+import os
|
||||||
@ -219,10 +213,10 @@ index 0000000000..2956cf6eff
|
|||||||
+ if not running:
|
+ if not running:
|
||||||
+ break
|
+ break
|
||||||
diff --git a/bin/tests/system/forward/clean.sh b/bin/tests/system/forward/clean.sh
|
diff --git a/bin/tests/system/forward/clean.sh b/bin/tests/system/forward/clean.sh
|
||||||
index 26e4e76db6..26a550db49 100644
|
index bc04eadb2c..b65b092680 100644
|
||||||
--- a/bin/tests/system/forward/clean.sh
|
--- a/bin/tests/system/forward/clean.sh
|
||||||
+++ b/bin/tests/system/forward/clean.sh
|
+++ b/bin/tests/system/forward/clean.sh
|
||||||
@@ -10,8 +10,10 @@
|
@@ -10,10 +10,12 @@
|
||||||
#
|
#
|
||||||
# Clean up after forward tests.
|
# Clean up after forward tests.
|
||||||
#
|
#
|
||||||
@ -233,16 +227,20 @@ index 26e4e76db6..26a550db49 100644
|
|||||||
rm -f ./*/named.run ./*/named.run.prev
|
rm -f ./*/named.run ./*/named.run.prev
|
||||||
+rm -f ./*/named_dump.db
|
+rm -f ./*/named_dump.db
|
||||||
rm -f ./ns*/named.lock
|
rm -f ./ns*/named.lock
|
||||||
|
rm -f ./ns*/managed-keys.bind*
|
||||||
|
rm -f ./ns1/root.db ./ns1/root.db.signed
|
||||||
diff --git a/bin/tests/system/forward/ns1/diditwork.net.db b/bin/tests/system/forward/ns1/diditwork.net.db
|
diff --git a/bin/tests/system/forward/ns1/diditwork.net.db b/bin/tests/system/forward/ns1/diditwork.net.db
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..be9a7f72bc
|
index 0000000000..fd9a46eb0c
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ns1/diditwork.net.db
|
+++ b/bin/tests/system/forward/ns1/diditwork.net.db
|
||||||
@@ -0,0 +1,20 @@
|
@@ -0,0 +1,22 @@
|
||||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+;
|
+;
|
||||||
|
+; SPDX-License-Identifier: MPL-2.0
|
||||||
|
+;
|
||||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
+; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+;
|
+;
|
||||||
+; See the COPYRIGHT file distributed with this work for additional
|
+; See the COPYRIGHT file distributed with this work for additional
|
||||||
@ -260,26 +258,26 @@ index 0000000000..be9a7f72bc
|
|||||||
+ TXT "recursed"
|
+ TXT "recursed"
|
||||||
+ns A 10.53.0.1
|
+ns A 10.53.0.1
|
||||||
diff --git a/bin/tests/system/forward/ns1/named.conf.in b/bin/tests/system/forward/ns1/named.conf.in
|
diff --git a/bin/tests/system/forward/ns1/named.conf.in b/bin/tests/system/forward/ns1/named.conf.in
|
||||||
index 9904f37ef5..1c31d84608 100644
|
index 4aef4e55e5..c5fb2eb172 100644
|
||||||
--- a/bin/tests/system/forward/ns1/named.conf.in
|
--- a/bin/tests/system/forward/ns1/named.conf.in
|
||||||
+++ b/bin/tests/system/forward/ns1/named.conf.in
|
+++ b/bin/tests/system/forward/ns1/named.conf.in
|
||||||
@@ -54,3 +54,23 @@ zone "example5." {
|
@@ -63,3 +63,23 @@ zone "sld.tld" {
|
||||||
zone "example6" {
|
zone "example6" {
|
||||||
type forward;
|
type forward;
|
||||||
};
|
};
|
||||||
+
|
+
|
||||||
+zone "diditwork.net" {
|
+zone "diditwork.net" {
|
||||||
+ type master;
|
+ type primary;
|
||||||
+ file "diditwork.net.db";
|
+ file "diditwork.net.db";
|
||||||
+};
|
+};
|
||||||
+
|
+
|
||||||
+zone "spoofed.net" {
|
+zone "spoofed.net" {
|
||||||
+ type master;
|
+ type primary;
|
||||||
+ file "spoofed.net.db";
|
+ file "spoofed.net.db";
|
||||||
+};
|
+};
|
||||||
+
|
+
|
||||||
+zone "sub.local.net" {
|
+zone "sub.local.net" {
|
||||||
+ type master;
|
+ type primary;
|
||||||
+ file "sub.local.net.db";
|
+ file "sub.local.net.db";
|
||||||
+};
|
+};
|
||||||
+
|
+
|
||||||
@ -289,14 +287,16 @@ index 9904f37ef5..1c31d84608 100644
|
|||||||
+};
|
+};
|
||||||
diff --git a/bin/tests/system/forward/ns1/net.example.lll b/bin/tests/system/forward/ns1/net.example.lll
|
diff --git a/bin/tests/system/forward/ns1/net.example.lll b/bin/tests/system/forward/ns1/net.example.lll
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..d179853fa5
|
index 0000000000..ba0804fd75
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ns1/net.example.lll
|
+++ b/bin/tests/system/forward/ns1/net.example.lll
|
||||||
@@ -0,0 +1,13 @@
|
@@ -0,0 +1,15 @@
|
||||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+;
|
+;
|
||||||
|
+; SPDX-License-Identifier: MPL-2.0
|
||||||
|
+;
|
||||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
+; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+;
|
+;
|
||||||
+; See the COPYRIGHT file distributed with this work for additional
|
+; See the COPYRIGHT file distributed with this work for additional
|
||||||
@ -308,14 +308,16 @@ index 0000000000..d179853fa5
|
|||||||
+didItWork.net.example.lll. TXT "if you can see this record the attack worked"
|
+didItWork.net.example.lll. TXT "if you can see this record the attack worked"
|
||||||
diff --git a/bin/tests/system/forward/ns1/spoofed.net.db b/bin/tests/system/forward/ns1/spoofed.net.db
|
diff --git a/bin/tests/system/forward/ns1/spoofed.net.db b/bin/tests/system/forward/ns1/spoofed.net.db
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..d498d5fa0d
|
index 0000000000..eedc46f5c0
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ns1/spoofed.net.db
|
+++ b/bin/tests/system/forward/ns1/spoofed.net.db
|
||||||
@@ -0,0 +1,20 @@
|
@@ -0,0 +1,22 @@
|
||||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+;
|
+;
|
||||||
|
+; SPDX-License-Identifier: MPL-2.0
|
||||||
|
+;
|
||||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
+; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+;
|
+;
|
||||||
+; See the COPYRIGHT file distributed with this work for additional
|
+; See the COPYRIGHT file distributed with this work for additional
|
||||||
@ -334,14 +336,16 @@ index 0000000000..d498d5fa0d
|
|||||||
+sub TXT "recursed"
|
+sub TXT "recursed"
|
||||||
diff --git a/bin/tests/system/forward/ns1/sub.local.net.db b/bin/tests/system/forward/ns1/sub.local.net.db
|
diff --git a/bin/tests/system/forward/ns1/sub.local.net.db b/bin/tests/system/forward/ns1/sub.local.net.db
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..be9a7f72bc
|
index 0000000000..fd9a46eb0c
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ns1/sub.local.net.db
|
+++ b/bin/tests/system/forward/ns1/sub.local.net.db
|
||||||
@@ -0,0 +1,20 @@
|
@@ -0,0 +1,22 @@
|
||||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+;
|
+;
|
||||||
|
+; SPDX-License-Identifier: MPL-2.0
|
||||||
|
+;
|
||||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
+; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+;
|
+;
|
||||||
+; See the COPYRIGHT file distributed with this work for additional
|
+; See the COPYRIGHT file distributed with this work for additional
|
||||||
@ -360,14 +364,16 @@ index 0000000000..be9a7f72bc
|
|||||||
+ns A 10.53.0.1
|
+ns A 10.53.0.1
|
||||||
diff --git a/bin/tests/system/forward/ns10/fakenet.zone b/bin/tests/system/forward/ns10/fakenet.zone
|
diff --git a/bin/tests/system/forward/ns10/fakenet.zone b/bin/tests/system/forward/ns10/fakenet.zone
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..14e5c777cb
|
index 0000000000..b655a32459
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ns10/fakenet.zone
|
+++ b/bin/tests/system/forward/ns10/fakenet.zone
|
||||||
@@ -0,0 +1,15 @@
|
@@ -0,0 +1,17 @@
|
||||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+;
|
+;
|
||||||
|
+; SPDX-License-Identifier: MPL-2.0
|
||||||
|
+;
|
||||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
+; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+;
|
+;
|
||||||
+; See the COPYRIGHT file distributed with this work for additional
|
+; See the COPYRIGHT file distributed with this work for additional
|
||||||
@ -381,14 +387,16 @@ index 0000000000..14e5c777cb
|
|||||||
+ns.spoofed.net. A 10.53.0.10
|
+ns.spoofed.net. A 10.53.0.10
|
||||||
diff --git a/bin/tests/system/forward/ns10/fakenet2.zone b/bin/tests/system/forward/ns10/fakenet2.zone
|
diff --git a/bin/tests/system/forward/ns10/fakenet2.zone b/bin/tests/system/forward/ns10/fakenet2.zone
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..7ca28a934e
|
index 0000000000..cd1e6e9944
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ns10/fakenet2.zone
|
+++ b/bin/tests/system/forward/ns10/fakenet2.zone
|
||||||
@@ -0,0 +1,13 @@
|
@@ -0,0 +1,15 @@
|
||||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+;
|
+;
|
||||||
|
+; SPDX-License-Identifier: MPL-2.0
|
||||||
|
+;
|
||||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
+; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+;
|
+;
|
||||||
+; See the COPYRIGHT file distributed with this work for additional
|
+; See the COPYRIGHT file distributed with this work for additional
|
||||||
@ -400,14 +408,16 @@ index 0000000000..7ca28a934e
|
|||||||
+net2. DNAME net.example.lll.
|
+net2. DNAME net.example.lll.
|
||||||
diff --git a/bin/tests/system/forward/ns10/fakesublocalnet.zone b/bin/tests/system/forward/ns10/fakesublocalnet.zone
|
diff --git a/bin/tests/system/forward/ns10/fakesublocalnet.zone b/bin/tests/system/forward/ns10/fakesublocalnet.zone
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..6caa071891
|
index 0000000000..160b5332b2
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ns10/fakesublocalnet.zone
|
+++ b/bin/tests/system/forward/ns10/fakesublocalnet.zone
|
||||||
@@ -0,0 +1,13 @@
|
@@ -0,0 +1,15 @@
|
||||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+;
|
+;
|
||||||
|
+; SPDX-License-Identifier: MPL-2.0
|
||||||
|
+;
|
||||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
+; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+;
|
+;
|
||||||
+; See the COPYRIGHT file distributed with this work for additional
|
+; See the COPYRIGHT file distributed with this work for additional
|
||||||
@ -419,14 +429,16 @@ index 0000000000..6caa071891
|
|||||||
+sub.local.net. TXT "if you see this attacker overrode local delegation"
|
+sub.local.net. TXT "if you see this attacker overrode local delegation"
|
||||||
diff --git a/bin/tests/system/forward/ns10/fakesublocaltld.zone b/bin/tests/system/forward/ns10/fakesublocaltld.zone
|
diff --git a/bin/tests/system/forward/ns10/fakesublocaltld.zone b/bin/tests/system/forward/ns10/fakesublocaltld.zone
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..6a431de47f
|
index 0000000000..f78cbc77f6
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ns10/fakesublocaltld.zone
|
+++ b/bin/tests/system/forward/ns10/fakesublocaltld.zone
|
||||||
@@ -0,0 +1,13 @@
|
@@ -0,0 +1,15 @@
|
||||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+;
|
+;
|
||||||
|
+; SPDX-License-Identifier: MPL-2.0
|
||||||
|
+;
|
||||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
+; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+;
|
+;
|
||||||
+; See the COPYRIGHT file distributed with this work for additional
|
+; See the COPYRIGHT file distributed with this work for additional
|
||||||
@ -438,15 +450,17 @@ index 0000000000..6a431de47f
|
|||||||
+ns.sub.local.tld. 3600 IN A 10.53.0.8
|
+ns.sub.local.tld. 3600 IN A 10.53.0.8
|
||||||
diff --git a/bin/tests/system/forward/ns10/named.conf.in b/bin/tests/system/forward/ns10/named.conf.in
|
diff --git a/bin/tests/system/forward/ns10/named.conf.in b/bin/tests/system/forward/ns10/named.conf.in
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..025c108418
|
index 0000000000..1f318dd867
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ns10/named.conf.in
|
+++ b/bin/tests/system/forward/ns10/named.conf.in
|
||||||
@@ -0,0 +1,51 @@
|
@@ -0,0 +1,53 @@
|
||||||
+/*
|
+/*
|
||||||
+ * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+ * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+ *
|
+ *
|
||||||
|
+ * SPDX-License-Identifier: MPL-2.0
|
||||||
|
+ *
|
||||||
+ * This Source Code Form is subject to the terms of the Mozilla Public
|
+ * This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
|
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+ * file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+ * file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+ *
|
+ *
|
||||||
+ * See the COPYRIGHT file distributed with this work for additional
|
+ * See the COPYRIGHT file distributed with this work for additional
|
||||||
@ -495,14 +509,16 @@ index 0000000000..025c108418
|
|||||||
+};
|
+};
|
||||||
diff --git a/bin/tests/system/forward/ns10/net.example.lll b/bin/tests/system/forward/ns10/net.example.lll
|
diff --git a/bin/tests/system/forward/ns10/net.example.lll b/bin/tests/system/forward/ns10/net.example.lll
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..d179853fa5
|
index 0000000000..ba0804fd75
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ns10/net.example.lll
|
+++ b/bin/tests/system/forward/ns10/net.example.lll
|
||||||
@@ -0,0 +1,13 @@
|
@@ -0,0 +1,15 @@
|
||||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+;
|
+;
|
||||||
|
+; SPDX-License-Identifier: MPL-2.0
|
||||||
|
+;
|
||||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
+; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+;
|
+;
|
||||||
+; See the COPYRIGHT file distributed with this work for additional
|
+; See the COPYRIGHT file distributed with this work for additional
|
||||||
@ -514,14 +530,16 @@ index 0000000000..d179853fa5
|
|||||||
+didItWork.net.example.lll. TXT "if you can see this record the attack worked"
|
+didItWork.net.example.lll. TXT "if you can see this record the attack worked"
|
||||||
diff --git a/bin/tests/system/forward/ns10/spoofednet.zone b/bin/tests/system/forward/ns10/spoofednet.zone
|
diff --git a/bin/tests/system/forward/ns10/spoofednet.zone b/bin/tests/system/forward/ns10/spoofednet.zone
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..13921a08cd
|
index 0000000000..fb70a4372b
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ns10/spoofednet.zone
|
+++ b/bin/tests/system/forward/ns10/spoofednet.zone
|
||||||
@@ -0,0 +1,14 @@
|
@@ -0,0 +1,16 @@
|
||||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+;
|
+;
|
||||||
|
+; SPDX-License-Identifier: MPL-2.0
|
||||||
|
+;
|
||||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
+; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+;
|
+;
|
||||||
+; See the COPYRIGHT file distributed with this work for additional
|
+; See the COPYRIGHT file distributed with this work for additional
|
||||||
@ -532,29 +550,45 @@ index 0000000000..13921a08cd
|
|||||||
+spoofed.net. NS ns.spoofed.net.
|
+spoofed.net. NS ns.spoofed.net.
|
||||||
+ns.spoofed.net. A 10.53.0.10
|
+ns.spoofed.net. A 10.53.0.10
|
||||||
+spoofed.net. TXT "this record is clearly spoofed"
|
+spoofed.net. TXT "this record is clearly spoofed"
|
||||||
|
diff --git a/bin/tests/system/forward/ns2/tld.db b/bin/tests/system/forward/ns2/tld.db
|
||||||
|
index 61b6569b07..819210dc05 100644
|
||||||
|
--- a/bin/tests/system/forward/ns2/tld.db
|
||||||
|
+++ b/bin/tests/system/forward/ns2/tld.db
|
||||||
|
@@ -10,3 +10,9 @@ $TTL 300 ; 5 minutes
|
||||||
|
ns A 10.53.0.2
|
||||||
|
sld NS ns.sld
|
||||||
|
ns.sld A 10.53.0.1
|
||||||
|
+local NS ns.local
|
||||||
|
+ns.local A 10.53.0.9
|
||||||
|
+sibling NS ns.sibling
|
||||||
|
+ns.sibling A 10.53.0.4
|
||||||
|
+sibling NS ns.sub.local
|
||||||
|
+ns.sub.local A 10.53.0.10
|
||||||
diff --git a/bin/tests/system/forward/ns4/named.conf.in b/bin/tests/system/forward/ns4/named.conf.in
|
diff --git a/bin/tests/system/forward/ns4/named.conf.in b/bin/tests/system/forward/ns4/named.conf.in
|
||||||
index d42a9eb797..6db65e71bc 100644
|
index 855b4bfb82..85349aa97e 100644
|
||||||
--- a/bin/tests/system/forward/ns4/named.conf.in
|
--- a/bin/tests/system/forward/ns4/named.conf.in
|
||||||
+++ b/bin/tests/system/forward/ns4/named.conf.in
|
+++ b/bin/tests/system/forward/ns4/named.conf.in
|
||||||
@@ -60,3 +60,8 @@ zone "malicious." {
|
@@ -60,3 +60,8 @@ zone "malicious." {
|
||||||
type master;
|
type primary;
|
||||||
file "malicious.db";
|
file "malicious.db";
|
||||||
};
|
};
|
||||||
+
|
+
|
||||||
+zone "sibling.tld" {
|
+zone "sibling.tld" {
|
||||||
+ type master;
|
+ type primary;
|
||||||
+ file "sibling.tld.db";
|
+ file "sibling.tld.db";
|
||||||
+};
|
+};
|
||||||
diff --git a/bin/tests/system/forward/ns4/sibling.tld.db b/bin/tests/system/forward/ns4/sibling.tld.db
|
diff --git a/bin/tests/system/forward/ns4/sibling.tld.db b/bin/tests/system/forward/ns4/sibling.tld.db
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..58037d093b
|
index 0000000000..fe080ae974
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ns4/sibling.tld.db
|
+++ b/bin/tests/system/forward/ns4/sibling.tld.db
|
||||||
@@ -0,0 +1,20 @@
|
@@ -0,0 +1,22 @@
|
||||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+;
|
+;
|
||||||
|
+; SPDX-License-Identifier: MPL-2.0
|
||||||
|
+;
|
||||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
+; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+;
|
+;
|
||||||
+; See the COPYRIGHT file distributed with this work for additional
|
+; See the COPYRIGHT file distributed with this work for additional
|
||||||
@ -572,71 +606,30 @@ index 0000000000..58037d093b
|
|||||||
+
|
+
|
||||||
+ns IN A 10.53.0.4
|
+ns IN A 10.53.0.4
|
||||||
diff --git a/bin/tests/system/forward/ns8/named.conf.in b/bin/tests/system/forward/ns8/named.conf.in
|
diff --git a/bin/tests/system/forward/ns8/named.conf.in b/bin/tests/system/forward/ns8/named.conf.in
|
||||||
new file mode 100644
|
index 531ff59ece..f752eae885 100644
|
||||||
index 0000000000..9260f69ded
|
--- a/bin/tests/system/forward/ns8/named.conf.in
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/forward/ns8/named.conf.in
|
+++ b/bin/tests/system/forward/ns8/named.conf.in
|
||||||
@@ -0,0 +1,33 @@
|
@@ -26,3 +26,8 @@ zone "." {
|
||||||
+/*
|
type hint;
|
||||||
+ * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
file "root.db";
|
||||||
+ *
|
};
|
||||||
+ * This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
+ * file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
+ *
|
|
||||||
+ * See the COPYRIGHT file distributed with this work for additional
|
|
||||||
+ * information regarding copyright ownership.
|
|
||||||
+ */
|
|
||||||
+
|
|
||||||
+options {
|
|
||||||
+ query-source address 10.53.0.8;
|
|
||||||
+ notify-source 10.53.0.8;
|
|
||||||
+ transfer-source 10.53.0.8;
|
|
||||||
+ port @PORT@;
|
|
||||||
+ pid-file "named.pid";
|
|
||||||
+ listen-on { 10.53.0.8; };
|
|
||||||
+ listen-on-v6 { none; };
|
|
||||||
+ forwarders { 10.53.0.2; }; // returns referrals
|
|
||||||
+ forward first;
|
|
||||||
+ dnssec-validation yes;
|
|
||||||
+};
|
|
||||||
+
|
|
||||||
+zone "." {
|
|
||||||
+ type hint;
|
|
||||||
+ file "root.db";
|
|
||||||
+};
|
|
||||||
+
|
+
|
||||||
+zone "sub.local.tld" {
|
+zone "sub.local.tld" {
|
||||||
+ type master;
|
+ type primary;
|
||||||
+ file "sub.local.tld.db";
|
+ file "sub.local.tld.db";
|
||||||
+};
|
+};
|
||||||
diff --git a/bin/tests/system/forward/ns8/root.db b/bin/tests/system/forward/ns8/root.db
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..4f30322270
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/forward/ns8/root.db
|
|
||||||
@@ -0,0 +1,11 @@
|
|
||||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
+;
|
|
||||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
+;
|
|
||||||
+; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
+; information regarding copyright ownership.
|
|
||||||
+
|
|
||||||
+. NS a.root-servers.nil.
|
|
||||||
+a.root-servers.nil. A 10.53.0.1
|
|
||||||
diff --git a/bin/tests/system/forward/ns8/sub.local.tld.db b/bin/tests/system/forward/ns8/sub.local.tld.db
|
diff --git a/bin/tests/system/forward/ns8/sub.local.tld.db b/bin/tests/system/forward/ns8/sub.local.tld.db
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..eb20683ae9
|
index 0000000000..f2234c754e
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ns8/sub.local.tld.db
|
+++ b/bin/tests/system/forward/ns8/sub.local.tld.db
|
||||||
@@ -0,0 +1,13 @@
|
@@ -0,0 +1,15 @@
|
||||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+;
|
+;
|
||||||
|
+; SPDX-License-Identifier: MPL-2.0
|
||||||
|
+;
|
||||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
+; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+;
|
+;
|
||||||
+; See the COPYRIGHT file distributed with this work for additional
|
+; See the COPYRIGHT file distributed with this work for additional
|
||||||
@ -648,14 +641,16 @@ index 0000000000..eb20683ae9
|
|||||||
+ns.sub.local.tld. 3600 IN A 10.53.0.8
|
+ns.sub.local.tld. 3600 IN A 10.53.0.8
|
||||||
diff --git a/bin/tests/system/forward/ns9/local.net.db b/bin/tests/system/forward/ns9/local.net.db
|
diff --git a/bin/tests/system/forward/ns9/local.net.db b/bin/tests/system/forward/ns9/local.net.db
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..2c971e1e93
|
index 0000000000..af0d2a5a67
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ns9/local.net.db
|
+++ b/bin/tests/system/forward/ns9/local.net.db
|
||||||
@@ -0,0 +1,14 @@
|
@@ -0,0 +1,16 @@
|
||||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+;
|
+;
|
||||||
|
+; SPDX-License-Identifier: MPL-2.0
|
||||||
|
+;
|
||||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
+; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+;
|
+;
|
||||||
+; See the COPYRIGHT file distributed with this work for additional
|
+; See the COPYRIGHT file distributed with this work for additional
|
||||||
@ -668,14 +663,16 @@ index 0000000000..2c971e1e93
|
|||||||
+sub.local.net. 3600 IN NS ns.spoofed.net. ; attacker will try to override this
|
+sub.local.net. 3600 IN NS ns.spoofed.net. ; attacker will try to override this
|
||||||
diff --git a/bin/tests/system/forward/ns9/local.tld.db b/bin/tests/system/forward/ns9/local.tld.db
|
diff --git a/bin/tests/system/forward/ns9/local.tld.db b/bin/tests/system/forward/ns9/local.tld.db
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..59403915fb
|
index 0000000000..876a9139da
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ns9/local.tld.db
|
+++ b/bin/tests/system/forward/ns9/local.tld.db
|
||||||
@@ -0,0 +1,13 @@
|
@@ -0,0 +1,15 @@
|
||||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+;
|
+;
|
||||||
|
+; SPDX-License-Identifier: MPL-2.0
|
||||||
|
+;
|
||||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
+; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+;
|
+;
|
||||||
+; See the COPYRIGHT file distributed with this work for additional
|
+; See the COPYRIGHT file distributed with this work for additional
|
||||||
@ -687,15 +684,17 @@ index 0000000000..59403915fb
|
|||||||
+ns.sub.local.tld. 3600 IN A 10.53.0.8
|
+ns.sub.local.tld. 3600 IN A 10.53.0.8
|
||||||
diff --git a/bin/tests/system/forward/ns9/named1.conf.in b/bin/tests/system/forward/ns9/named1.conf.in
|
diff --git a/bin/tests/system/forward/ns9/named1.conf.in b/bin/tests/system/forward/ns9/named1.conf.in
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..943e037d09
|
index 0000000000..be9a43842f
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ns9/named1.conf.in
|
+++ b/bin/tests/system/forward/ns9/named1.conf.in
|
||||||
@@ -0,0 +1,65 @@
|
@@ -0,0 +1,67 @@
|
||||||
+/*
|
+/*
|
||||||
+ * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+ * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+ *
|
+ *
|
||||||
|
+ * SPDX-License-Identifier: MPL-2.0
|
||||||
|
+ *
|
||||||
+ * This Source Code Form is subject to the terms of the Mozilla Public
|
+ * This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
|
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+ * file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+ * file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+ *
|
+ *
|
||||||
+ * See the COPYRIGHT file distributed with this work for additional
|
+ * See the COPYRIGHT file distributed with this work for additional
|
||||||
@ -752,21 +751,23 @@ index 0000000000..943e037d09
|
|||||||
+};
|
+};
|
||||||
+
|
+
|
||||||
+zone "local.net." {
|
+zone "local.net." {
|
||||||
+ type master;
|
+ type primary;
|
||||||
+ file "local.net.db";
|
+ file "local.net.db";
|
||||||
+ forwarders {};
|
+ forwarders {};
|
||||||
+};
|
+};
|
||||||
diff --git a/bin/tests/system/forward/ns9/named2.conf.in b/bin/tests/system/forward/ns9/named2.conf.in
|
diff --git a/bin/tests/system/forward/ns9/named2.conf.in b/bin/tests/system/forward/ns9/named2.conf.in
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..5a17d1998a
|
index 0000000000..2c40b42a0c
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ns9/named2.conf.in
|
+++ b/bin/tests/system/forward/ns9/named2.conf.in
|
||||||
@@ -0,0 +1,68 @@
|
@@ -0,0 +1,70 @@
|
||||||
+/*
|
+/*
|
||||||
+ * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+ * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+ *
|
+ *
|
||||||
|
+ * SPDX-License-Identifier: MPL-2.0
|
||||||
|
+ *
|
||||||
+ * This Source Code Form is subject to the terms of the Mozilla Public
|
+ * This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
|
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+ * file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+ * file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+ *
|
+ *
|
||||||
+ * See the COPYRIGHT file distributed with this work for additional
|
+ * See the COPYRIGHT file distributed with this work for additional
|
||||||
@ -826,21 +827,23 @@ index 0000000000..5a17d1998a
|
|||||||
+};
|
+};
|
||||||
+
|
+
|
||||||
+zone "local.net." {
|
+zone "local.net." {
|
||||||
+ type master;
|
+ type primary;
|
||||||
+ file "local.net.db";
|
+ file "local.net.db";
|
||||||
+ forwarders {};
|
+ forwarders {};
|
||||||
+};
|
+};
|
||||||
diff --git a/bin/tests/system/forward/ns9/named3.conf.in b/bin/tests/system/forward/ns9/named3.conf.in
|
diff --git a/bin/tests/system/forward/ns9/named3.conf.in b/bin/tests/system/forward/ns9/named3.conf.in
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..1e70d1ae51
|
index 0000000000..576f57c10b
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ns9/named3.conf.in
|
+++ b/bin/tests/system/forward/ns9/named3.conf.in
|
||||||
@@ -0,0 +1,48 @@
|
@@ -0,0 +1,50 @@
|
||||||
+/*
|
+/*
|
||||||
+ * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+ * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+ *
|
+ *
|
||||||
|
+ * SPDX-License-Identifier: MPL-2.0
|
||||||
|
+ *
|
||||||
+ * This Source Code Form is subject to the terms of the Mozilla Public
|
+ * This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
|
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+ * file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+ * file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+ *
|
+ *
|
||||||
+ * See the COPYRIGHT file distributed with this work for additional
|
+ * See the COPYRIGHT file distributed with this work for additional
|
||||||
@ -880,21 +883,23 @@ index 0000000000..1e70d1ae51
|
|||||||
+};
|
+};
|
||||||
+
|
+
|
||||||
+zone "local.net." {
|
+zone "local.net." {
|
||||||
+ type master;
|
+ type primary;
|
||||||
+ file "local.net.db";
|
+ file "local.net.db";
|
||||||
+ forwarders {};
|
+ forwarders {};
|
||||||
+};
|
+};
|
||||||
diff --git a/bin/tests/system/forward/ns9/named4.conf.in b/bin/tests/system/forward/ns9/named4.conf.in
|
diff --git a/bin/tests/system/forward/ns9/named4.conf.in b/bin/tests/system/forward/ns9/named4.conf.in
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..6f7b1075b5
|
index 0000000000..5cd7d84109
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ns9/named4.conf.in
|
+++ b/bin/tests/system/forward/ns9/named4.conf.in
|
||||||
@@ -0,0 +1,45 @@
|
@@ -0,0 +1,47 @@
|
||||||
+/*
|
+/*
|
||||||
+ * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+ * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+ *
|
+ *
|
||||||
|
+ * SPDX-License-Identifier: MPL-2.0
|
||||||
|
+ *
|
||||||
+ * This Source Code Form is subject to the terms of the Mozilla Public
|
+ * This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
|
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+ * file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+ * file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+ *
|
+ *
|
||||||
+ * See the COPYRIGHT file distributed with this work for additional
|
+ * See the COPYRIGHT file distributed with this work for additional
|
||||||
@ -932,19 +937,21 @@ index 0000000000..6f7b1075b5
|
|||||||
+};
|
+};
|
||||||
+
|
+
|
||||||
+zone "local.tld." {
|
+zone "local.tld." {
|
||||||
+ type master;
|
+ type primary;
|
||||||
+ file "local.tld.db";
|
+ file "local.tld.db";
|
||||||
+};
|
+};
|
||||||
diff --git a/bin/tests/system/forward/ns9/root.db b/bin/tests/system/forward/ns9/root.db
|
diff --git a/bin/tests/system/forward/ns9/root.db b/bin/tests/system/forward/ns9/root.db
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000000..4f30322270
|
index 0000000000..2cbdff5977
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/forward/ns9/root.db
|
+++ b/bin/tests/system/forward/ns9/root.db
|
||||||
@@ -0,0 +1,11 @@
|
@@ -0,0 +1,13 @@
|
||||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
+;
|
+;
|
||||||
|
+; SPDX-License-Identifier: MPL-2.0
|
||||||
|
+;
|
||||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
+; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
+;
|
+;
|
||||||
+; See the COPYRIGHT file distributed with this work for additional
|
+; See the COPYRIGHT file distributed with this work for additional
|
||||||
@ -952,61 +959,27 @@ index 0000000000..4f30322270
|
|||||||
+
|
+
|
||||||
+. NS a.root-servers.nil.
|
+. NS a.root-servers.nil.
|
||||||
+a.root-servers.nil. A 10.53.0.1
|
+a.root-servers.nil. A 10.53.0.1
|
||||||
diff --git a/bin/tests/system/forward/prereq.sh b/bin/tests/system/forward/prereq.sh
|
|
||||||
index d2ca8fc2bf..53fb5817df 100644
|
|
||||||
--- a/bin/tests/system/forward/prereq.sh
|
|
||||||
+++ b/bin/tests/system/forward/prereq.sh
|
|
||||||
@@ -12,6 +12,20 @@
|
|
||||||
SYSTEMTESTTOP=..
|
|
||||||
. $SYSTEMTESTTOP/conf.sh
|
|
||||||
|
|
||||||
+if test -n "$PYTHON"
|
|
||||||
+then
|
|
||||||
+ if $PYTHON -c "import dns" 2> /dev/null
|
|
||||||
+ then
|
|
||||||
+ :
|
|
||||||
+ else
|
|
||||||
+ echo_i "This test requires the dnspython module." >&2
|
|
||||||
+ exit 1
|
|
||||||
+ fi
|
|
||||||
+else
|
|
||||||
+ echo_i "This test requires Python and the dnspython module." >&2
|
|
||||||
+ exit 1
|
|
||||||
+fi
|
|
||||||
+
|
|
||||||
if $PERL -e 'use Net::DNS;' 2>/dev/null
|
|
||||||
then
|
|
||||||
:
|
|
||||||
diff --git a/bin/tests/system/forward/setup.sh b/bin/tests/system/forward/setup.sh
|
diff --git a/bin/tests/system/forward/setup.sh b/bin/tests/system/forward/setup.sh
|
||||||
index 87452b9a88..18e81d277d 100644
|
index 21cf67b782..a56dd3c03f 100644
|
||||||
--- a/bin/tests/system/forward/setup.sh
|
--- a/bin/tests/system/forward/setup.sh
|
||||||
+++ b/bin/tests/system/forward/setup.sh
|
+++ b/bin/tests/system/forward/setup.sh
|
||||||
@@ -18,3 +18,6 @@ copy_setports ns3/named.conf.in ns3/named.conf
|
@@ -19,6 +19,8 @@ copy_setports ns4/named.conf.in ns4/named.conf
|
||||||
copy_setports ns4/named.conf.in ns4/named.conf
|
|
||||||
copy_setports ns5/named.conf.in ns5/named.conf
|
copy_setports ns5/named.conf.in ns5/named.conf
|
||||||
copy_setports ns7/named.conf.in ns7/named.conf
|
copy_setports ns7/named.conf.in ns7/named.conf
|
||||||
+copy_setports ns8/named.conf.in ns8/named.conf
|
copy_setports ns8/named.conf.in ns8/named.conf
|
||||||
+copy_setports ns9/named1.conf.in ns9/named.conf
|
+copy_setports ns9/named1.conf.in ns9/named.conf
|
||||||
+copy_setports ns10/named.conf.in ns10/named.conf
|
+copy_setports ns10/named.conf.in ns10/named.conf
|
||||||
|
|
||||||
|
(
|
||||||
|
cd ns1
|
||||||
diff --git a/bin/tests/system/forward/tests.sh b/bin/tests/system/forward/tests.sh
|
diff --git a/bin/tests/system/forward/tests.sh b/bin/tests/system/forward/tests.sh
|
||||||
index e3549c5bc7..ce9b309a27 100644
|
index 6096b06ca7..dfbaf887f7 100644
|
||||||
--- a/bin/tests/system/forward/tests.sh
|
--- a/bin/tests/system/forward/tests.sh
|
||||||
+++ b/bin/tests/system/forward/tests.sh
|
+++ b/bin/tests/system/forward/tests.sh
|
||||||
@@ -19,6 +19,10 @@ sendcmd() (
|
@@ -253,5 +253,127 @@ grep "status: SERVFAIL" dig.out.$n.f1 > /dev/null || ret=1
|
||||||
"$PERL" ../send.pl 10.53.0.6 "$EXTRAPORT1"
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
)
|
|
||||||
|
|
||||||
+rndccmd() {
|
|
||||||
+ "$RNDC" -c ../common/rndc.conf -p "$CONTROLPORT" -s "$@"
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
root=10.53.0.1
|
|
||||||
hidden=10.53.0.2
|
|
||||||
f1=10.53.0.3
|
|
||||||
@@ -223,5 +227,127 @@ if [ $ret != 0 ]; then echo_i "failed"; fi
|
|
||||||
status=$((status+ret))
|
status=$((status+ret))
|
||||||
|
|
||||||
|
|
||||||
+#
|
+#
|
||||||
+# Check various spoofed response scenarios. The same tests will be
|
+# Check various spoofed response scenarios. The same tests will be
|
||||||
+# run twice, with "forward first" and "forward only" configurations.
|
+# run twice, with "forward first" and "forward only" configurations.
|
||||||
@ -1132,7 +1105,7 @@ index e3549c5bc7..ce9b309a27 100644
|
|||||||
echo_i "exit status: $status"
|
echo_i "exit status: $status"
|
||||||
[ $status -eq 0 ] || exit 1
|
[ $status -eq 0 ] || exit 1
|
||||||
diff --git a/bin/tests/system/ifconfig.sh b/bin/tests/system/ifconfig.sh
|
diff --git a/bin/tests/system/ifconfig.sh b/bin/tests/system/ifconfig.sh
|
||||||
index d0eb9fa61d..8b9212c3e0 100755
|
index e078f3313b..2a4d955caf 100755
|
||||||
--- a/bin/tests/system/ifconfig.sh
|
--- a/bin/tests/system/ifconfig.sh
|
||||||
+++ b/bin/tests/system/ifconfig.sh
|
+++ b/bin/tests/system/ifconfig.sh
|
||||||
@@ -12,10 +12,10 @@
|
@@ -12,10 +12,10 @@
|
||||||
@ -1148,7 +1121,7 @@ index d0eb9fa61d..8b9212c3e0 100755
|
|||||||
# fd92:7065:b8e:99ff::{1..2}
|
# fd92:7065:b8e:99ff::{1..2}
|
||||||
# fd92:7065:b8e:ff::{1..2}
|
# fd92:7065:b8e:ff::{1..2}
|
||||||
#
|
#
|
||||||
@@ -65,7 +65,7 @@ case "$1" in
|
@@ -55,7 +55,7 @@ case "$1" in
|
||||||
2) ipv6="00" ;;
|
2) ipv6="00" ;;
|
||||||
*) ipv6="" ;;
|
*) ipv6="" ;;
|
||||||
esac
|
esac
|
||||||
@ -1157,7 +1130,7 @@ index d0eb9fa61d..8b9212c3e0 100755
|
|||||||
do
|
do
|
||||||
[ $i -gt 0 -a $ns -gt 2 ] && break
|
[ $i -gt 0 -a $ns -gt 2 ] && break
|
||||||
int=`expr $i \* 10 + $ns`
|
int=`expr $i \* 10 + $ns`
|
||||||
@@ -165,7 +165,7 @@ case "$1" in
|
@@ -160,7 +160,7 @@ case "$1" in
|
||||||
2) ipv6="00" ;;
|
2) ipv6="00" ;;
|
||||||
*) ipv6="" ;;
|
*) ipv6="" ;;
|
||||||
esac
|
esac
|
||||||
@ -1,12 +1,12 @@
|
|||||||
From 1f5cb247ecd20ba57c472138f94856aa83caf042 Mon Sep 17 00:00:00 2001
|
From 5b2798e01346cd77741873091babf6c4a3128449 Mon Sep 17 00:00:00 2001
|
||||||
From: Mark Andrews <marka@isc.org>
|
From: Mark Andrews <marka@isc.org>
|
||||||
Date: Tue, 1 Mar 2022 09:48:05 +1100
|
Date: Wed, 19 Jan 2022 17:38:18 +1100
|
||||||
Subject: [PATCH] Add additional name checks when using a forwarder
|
Subject: [PATCH] Add additional name checks when using a forwarder
|
||||||
|
|
||||||
When using a forwarder, check that the owner name of response
|
When using a forwarder, check that the owner name of response
|
||||||
records are within the bailiwick of the forwarded name space.
|
records are within the bailiwick of the forwarded name space.
|
||||||
|
|
||||||
(cherry picked from commit e8df2802ac62016ea68585893eb4310fc3329028)
|
(cherry picked from commit 24155213be59faad17f0215ecf73ea49ab781e5b)
|
||||||
|
|
||||||
Check that the forward declaration is unchanged and not overridden
|
Check that the forward declaration is unchanged and not overridden
|
||||||
|
|
||||||
@ -16,7 +16,7 @@ check that there are no subsidiary forwarded namespaces which would
|
|||||||
take precedence. To be safe, we don't cache any responses if the
|
take precedence. To be safe, we don't cache any responses if the
|
||||||
forwarding configuration has changed since the query was sent.
|
forwarding configuration has changed since the query was sent.
|
||||||
|
|
||||||
(cherry picked from commit 590f8698fc876d6d72f75cf35359e7546c3af972)
|
(cherry picked from commit 3fc7accd88cd0890f8f57bb13765876774298ba3)
|
||||||
|
|
||||||
Check cached names for possible "forward only" clause
|
Check cached names for possible "forward only" clause
|
||||||
|
|
||||||
@ -26,7 +26,7 @@ that would take precedence. Such names would normally be allowed by
|
|||||||
baliwick rules, but a "forward only" zone introduces a new baliwick
|
baliwick rules, but a "forward only" zone introduces a new baliwick
|
||||||
scope.
|
scope.
|
||||||
|
|
||||||
(cherry picked from commit 4a144fae16e70517be894a971cef1d085ee68ebe)
|
(cherry picked from commit ea06552a3d1fed56f7d3a13710e084ec79797b78)
|
||||||
|
|
||||||
Look for zones deeper than the current domain or forward name
|
Look for zones deeper than the current domain or forward name
|
||||||
|
|
||||||
@ -35,50 +35,42 @@ source of truth for the name. If the owner name for the glue
|
|||||||
record would be answered by a locally configured zone, do not
|
record would be answered by a locally configured zone, do not
|
||||||
cache.
|
cache.
|
||||||
|
|
||||||
(cherry picked from commit 42f8c538d3fb9d075b98d82688aeb71621798754)
|
(cherry picked from commit 71b24210542730355149130770deea3e58d8527a)
|
||||||
|
|
||||||
Avoid use of compound literals
|
|
||||||
|
|
||||||
Compound literals are not used in BIND 9.11, in order to ensure backward
|
|
||||||
compatibility with ancient compilers. Rework the relevant parts of the
|
|
||||||
BIND 9.11 backport of the CVE-2021-25220 fix so that compound literals
|
|
||||||
are not used.
|
|
||||||
|
|
||||||
(cherry picked from commit d4b1efbcbd4dfb8c6ef303968992440c5bdeed15)
|
|
||||||
---
|
---
|
||||||
lib/dns/resolver.c | 130 +++++++++++++++++++++++++++++++++++++++++++--
|
lib/dns/resolver.c | 128 +++++++++++++++++++++++++++++++++++++++++++--
|
||||||
1 file changed, 125 insertions(+), 5 deletions(-)
|
1 file changed, 123 insertions(+), 5 deletions(-)
|
||||||
|
|
||||||
diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c
|
diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c
|
||||||
index c912f3aea8..2c68973899 100644
|
index a7bc661bb7..7603a07b7b 100644
|
||||||
--- a/lib/dns/resolver.c
|
--- a/lib/dns/resolver.c
|
||||||
+++ b/lib/dns/resolver.c
|
+++ b/lib/dns/resolver.c
|
||||||
@@ -63,6 +63,7 @@
|
@@ -63,6 +63,8 @@
|
||||||
#include <dns/stats.h>
|
#include <dns/stats.h>
|
||||||
#include <dns/tsig.h>
|
#include <dns/tsig.h>
|
||||||
#include <dns/validator.h>
|
#include <dns/validator.h>
|
||||||
+#include <dns/zone.h>
|
+#include <dns/zone.h>
|
||||||
|
+
|
||||||
#ifdef WANT_QUERYTRACE
|
#ifdef WANT_QUERYTRACE
|
||||||
#define RTRACE(m) isc_log_write(dns_lctx, \
|
#define RTRACE(m) \
|
||||||
@@ -312,6 +313,8 @@ struct fetchctx {
|
isc_log_write(dns_lctx, DNS_LOGCATEGORY_RESOLVER, \
|
||||||
bool ns_ttl_ok;
|
@@ -337,6 +339,8 @@ struct fetchctx {
|
||||||
uint32_t ns_ttl;
|
dns_fetch_t *qminfetch;
|
||||||
isc_counter_t * qc;
|
dns_rdataset_t qminrrset;
|
||||||
+ dns_fixedname_t fwdfname;
|
dns_name_t qmindcname;
|
||||||
+ dns_name_t *fwdname;
|
+ dns_fixedname_t fwdfname;
|
||||||
|
+ dns_name_t *fwdname;
|
||||||
|
|
||||||
/*%
|
/*%
|
||||||
* The number of events we're waiting for.
|
* The number of events we're waiting for.
|
||||||
@@ -3393,6 +3396,7 @@ fctx_getaddresses(fetchctx_t *fctx, bool badcache) {
|
@@ -3764,6 +3768,7 @@ fctx_getaddresses(fetchctx_t *fctx, bool badcache) {
|
||||||
if (result == ISC_R_SUCCESS) {
|
if (result == ISC_R_SUCCESS) {
|
||||||
fwd = ISC_LIST_HEAD(forwarders->fwdrs);
|
fwd = ISC_LIST_HEAD(forwarders->fwdrs);
|
||||||
fctx->fwdpolicy = forwarders->fwdpolicy;
|
fctx->fwdpolicy = forwarders->fwdpolicy;
|
||||||
+ dns_name_copy(domain, fctx->fwdname, NULL);
|
+ dns_name_copynf(domain, fctx->fwdname);
|
||||||
if (fctx->fwdpolicy == dns_fwdpolicy_only &&
|
if (fctx->fwdpolicy == dns_fwdpolicy_only &&
|
||||||
isstrictsubdomain(domain, &fctx->domain)) {
|
isstrictsubdomain(domain, &fctx->domain))
|
||||||
fcount_decr(fctx);
|
{
|
||||||
@@ -4422,6 +4426,9 @@ fctx_create(dns_resolver_t *res, dns_name_t *name, dns_rdatatype_t type,
|
@@ -5153,6 +5158,9 @@ fctx_create(dns_resolver_t *res, const dns_name_t *name, dns_rdatatype_t type,
|
||||||
fctx->restarts = 0;
|
fctx->restarts = 0;
|
||||||
fctx->querysent = 0;
|
fctx->querysent = 0;
|
||||||
fctx->referrals = 0;
|
fctx->referrals = 0;
|
||||||
@ -88,20 +80,16 @@ index c912f3aea8..2c68973899 100644
|
|||||||
TIME_NOW(&fctx->start);
|
TIME_NOW(&fctx->start);
|
||||||
fctx->timeouts = 0;
|
fctx->timeouts = 0;
|
||||||
fctx->lamecount = 0;
|
fctx->lamecount = 0;
|
||||||
@@ -4480,8 +4487,10 @@ fctx_create(dns_resolver_t *res, dns_name_t *name, dns_rdatatype_t type,
|
@@ -5215,6 +5223,7 @@ fctx_create(dns_resolver_t *res, const dns_name_t *name, dns_rdatatype_t type,
|
||||||
domain = dns_fixedname_initname(&fixed);
|
fname, &forwarders);
|
||||||
result = dns_fwdtable_find2(fctx->res->view->fwdtable, fwdname,
|
if (result == ISC_R_SUCCESS) {
|
||||||
domain, &forwarders);
|
|
||||||
- if (result == ISC_R_SUCCESS)
|
|
||||||
+ if (result == ISC_R_SUCCESS) {
|
|
||||||
fctx->fwdpolicy = forwarders->fwdpolicy;
|
fctx->fwdpolicy = forwarders->fwdpolicy;
|
||||||
+ dns_name_copy(domain, fctx->fwdname, NULL);
|
+ dns_name_copynf(fname, fctx->fwdname);
|
||||||
+ }
|
}
|
||||||
|
|
||||||
if (fctx->fwdpolicy != dns_fwdpolicy_only) {
|
if (fctx->fwdpolicy != dns_fwdpolicy_only) {
|
||||||
/*
|
@@ -7118,6 +7127,107 @@ mark_related(dns_name_t *name, dns_rdataset_t *rdataset, bool external,
|
||||||
@@ -6231,6 +6240,112 @@ mark_related(dns_name_t *name, dns_rdataset_t *rdataset,
|
}
|
||||||
rdataset->attributes |= DNS_RDATASETATTR_EXTERNAL;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
+/*
|
+/*
|
||||||
@ -111,7 +99,7 @@ index c912f3aea8..2c68973899 100644
|
|||||||
+ * locally served zone.
|
+ * locally served zone.
|
||||||
+ */
|
+ */
|
||||||
+static inline bool
|
+static inline bool
|
||||||
+name_external(dns_name_t *name, dns_rdatatype_t type, fetchctx_t *fctx) {
|
+name_external(const dns_name_t *name, dns_rdatatype_t type, fetchctx_t *fctx) {
|
||||||
+ isc_result_t result;
|
+ isc_result_t result;
|
||||||
+ dns_forwarders_t *forwarders = NULL;
|
+ dns_forwarders_t *forwarders = NULL;
|
||||||
+ dns_fixedname_t fixed, zfixed;
|
+ dns_fixedname_t fixed, zfixed;
|
||||||
@ -122,19 +110,14 @@ index c912f3aea8..2c68973899 100644
|
|||||||
+ dns_zone_t *zone = NULL;
|
+ dns_zone_t *zone = NULL;
|
||||||
+ unsigned int labels;
|
+ unsigned int labels;
|
||||||
+ dns_namereln_t rel;
|
+ dns_namereln_t rel;
|
||||||
+ /*
|
|
||||||
+ * The following two variables do not influence code flow; they are
|
|
||||||
+ * only necessary for calling dns_name_fullcompare().
|
|
||||||
+ */
|
|
||||||
+ int _orderp = 0;
|
|
||||||
+ unsigned int _nlabelsp = 0;
|
|
||||||
+
|
+
|
||||||
+ apex = ISFORWARDER(fctx->addrinfo) ? fctx->fwdname : &fctx->domain;
|
+ apex = ISFORWARDER(fctx->addrinfo) ? fctx->fwdname : &fctx->domain;
|
||||||
+
|
+
|
||||||
+ /*
|
+ /*
|
||||||
+ * The name is outside the queried namespace.
|
+ * The name is outside the queried namespace.
|
||||||
+ */
|
+ */
|
||||||
+ rel = dns_name_fullcompare(name, apex, &_orderp, &_nlabelsp);
|
+ rel = dns_name_fullcompare(name, apex, &(int){ 0 },
|
||||||
|
+ &(unsigned int){ 0U });
|
||||||
+ if (rel != dns_namereln_subdomain && rel != dns_namereln_equal) {
|
+ if (rel != dns_namereln_subdomain && rel != dns_namereln_equal) {
|
||||||
+ return (true);
|
+ return (true);
|
||||||
+ }
|
+ }
|
||||||
@ -159,15 +142,15 @@ index c912f3aea8..2c68973899 100644
|
|||||||
+ */
|
+ */
|
||||||
+ LOCK(&fctx->res->view->lock);
|
+ LOCK(&fctx->res->view->lock);
|
||||||
+ if (fctx->res->view->zonetable != NULL) {
|
+ if (fctx->res->view->zonetable != NULL) {
|
||||||
+ unsigned int options = DNS_ZTFIND_NOEXACT;
|
+ unsigned int options = DNS_ZTFIND_NOEXACT | DNS_ZTFIND_MIRROR;
|
||||||
+ result = dns_zt_find(fctx->res->view->zonetable, name, options,
|
+ result = dns_zt_find(fctx->res->view->zonetable, name, options,
|
||||||
+ zfname, &zone);
|
+ zfname, &zone);
|
||||||
+ if (zone != NULL) {
|
+ if (zone != NULL) {
|
||||||
+ dns_zone_detach(&zone);
|
+ dns_zone_detach(&zone);
|
||||||
+ }
|
+ }
|
||||||
+ if (result == ISC_R_SUCCESS || result == DNS_R_PARTIALMATCH) {
|
+ if (result == ISC_R_SUCCESS || result == DNS_R_PARTIALMATCH) {
|
||||||
+ if (dns_name_fullcompare(zfname, apex, &_orderp,
|
+ if (dns_name_fullcompare(zfname, apex, &(int){ 0 },
|
||||||
+ &_nlabelsp) ==
|
+ &(unsigned int){ 0U }) ==
|
||||||
+ dns_namereln_subdomain)
|
+ dns_namereln_subdomain)
|
||||||
+ {
|
+ {
|
||||||
+ UNLOCK(&fctx->res->view->lock);
|
+ UNLOCK(&fctx->res->view->lock);
|
||||||
@ -180,8 +163,8 @@ index c912f3aea8..2c68973899 100644
|
|||||||
+ /*
|
+ /*
|
||||||
+ * Look for a forward declaration below 'name'.
|
+ * Look for a forward declaration below 'name'.
|
||||||
+ */
|
+ */
|
||||||
+ result = dns_fwdtable_find2(fctx->res->view->fwdtable, name, fname,
|
+ result = dns_fwdtable_find(fctx->res->view->fwdtable, name, fname,
|
||||||
+ &forwarders);
|
+ &forwarders);
|
||||||
+
|
+
|
||||||
+ if (ISFORWARDER(fctx->addrinfo)) {
|
+ if (ISFORWARDER(fctx->addrinfo)) {
|
||||||
+ /*
|
+ /*
|
||||||
@ -211,10 +194,10 @@ index c912f3aea8..2c68973899 100644
|
|||||||
+}
|
+}
|
||||||
+
|
+
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
check_section(void *arg, dns_name_t *addname, dns_rdatatype_t type,
|
check_section(void *arg, const dns_name_t *addname, dns_rdatatype_t type,
|
||||||
dns_section_t section)
|
dns_section_t section) {
|
||||||
@@ -6259,7 +6374,7 @@ check_section(void *arg, dns_name_t *addname, dns_rdatatype_t type,
|
@@ -7144,7 +7254,7 @@ check_section(void *arg, const dns_name_t *addname, dns_rdatatype_t type,
|
||||||
result = dns_message_findname(rmessage, section, addname,
|
result = dns_message_findname(rctx->query->rmessage, section, addname,
|
||||||
dns_rdatatype_any, 0, &name, NULL);
|
dns_rdatatype_any, 0, &name, NULL);
|
||||||
if (result == ISC_R_SUCCESS) {
|
if (result == ISC_R_SUCCESS) {
|
||||||
- external = !dns_name_issubdomain(name, &fctx->domain);
|
- external = !dns_name_issubdomain(name, &fctx->domain);
|
||||||
@ -222,7 +205,7 @@ index c912f3aea8..2c68973899 100644
|
|||||||
if (type == dns_rdatatype_a) {
|
if (type == dns_rdatatype_a) {
|
||||||
for (rdataset = ISC_LIST_HEAD(name->list);
|
for (rdataset = ISC_LIST_HEAD(name->list);
|
||||||
rdataset != NULL;
|
rdataset != NULL;
|
||||||
@@ -7141,6 +7256,13 @@ answer_response(fetchctx_t *fctx, dns_message_t *message) {
|
@@ -8768,6 +8878,13 @@ rctx_answer_scan(respctx_t *rctx) {
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case dns_namereln_subdomain:
|
case dns_namereln_subdomain:
|
||||||
@ -236,19 +219,33 @@ index c912f3aea8..2c68973899 100644
|
|||||||
/*
|
/*
|
||||||
* In-scope DNAME records must have at least
|
* In-scope DNAME records must have at least
|
||||||
* as many labels as the domain being queried.
|
* as many labels as the domain being queried.
|
||||||
@@ -7376,11 +7498,9 @@ answer_response(fetchctx_t *fctx, dns_message_t *message) {
|
@@ -9081,13 +9198,11 @@ rctx_authority_positive(respctx_t *rctx) {
|
||||||
*/
|
DNS_SECTION_AUTHORITY);
|
||||||
result = dns_message_firstname(message, DNS_SECTION_AUTHORITY);
|
|
||||||
while (!done && result == ISC_R_SUCCESS) {
|
while (!done && result == ISC_R_SUCCESS) {
|
||||||
|
dns_name_t *name = NULL;
|
||||||
- bool external;
|
- bool external;
|
||||||
name = NULL;
|
|
||||||
dns_message_currentname(message, DNS_SECTION_AUTHORITY, &name);
|
dns_message_currentname(rctx->query->rmessage,
|
||||||
|
DNS_SECTION_AUTHORITY, &name);
|
||||||
- external = !dns_name_issubdomain(name, &fctx->domain);
|
- external = !dns_name_issubdomain(name, &fctx->domain);
|
||||||
|
|
||||||
- if (!external) {
|
- if (!external) {
|
||||||
+ if (!name_external(name, dns_rdatatype_ns, fctx)) {
|
+ if (!name_external(name, dns_rdatatype_ns, fctx)) {
|
||||||
|
dns_rdataset_t *rdataset = NULL;
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* We expect to find NS or SIG NS rdatasets, and
|
@@ -9474,7 +9589,10 @@ rctx_authority_dnssec(respctx_t *rctx) {
|
||||||
* nothing else.
|
}
|
||||||
|
|
||||||
|
if (!dns_name_issubdomain(name, &fctx->domain)) {
|
||||||
|
- /* Invalid name found; preserve it for logging later */
|
||||||
|
+ /*
|
||||||
|
+ * Invalid name found; preserve it for logging
|
||||||
|
+ * later.
|
||||||
|
+ */
|
||||||
|
rctx->found_name = name;
|
||||||
|
rctx->found_type = ISC_LIST_HEAD(name->list)->type;
|
||||||
|
continue;
|
||||||
--
|
--
|
||||||
2.34.1
|
2.34.1
|
||||||
|
|
||||||
81
SOURCES/bind-9.16-CVE-2022-0396.patch
Normal file
81
SOURCES/bind-9.16-CVE-2022-0396.patch
Normal file
@ -0,0 +1,81 @@
|
|||||||
|
From 33064cd077cf6fa386f0a5a840c2161868da7b3a Mon Sep 17 00:00:00 2001
|
||||||
|
From: =?UTF-8?q?Ond=C5=99ej=20Sur=C3=BD?= <ondrej@isc.org>
|
||||||
|
Date: Tue, 8 Feb 2022 12:42:34 +0100
|
||||||
|
Subject: [PATCH] Run .closehandle_cb asynchrounosly in nmhandle_detach_cb()
|
||||||
|
|
||||||
|
When sock->closehandle_cb is set, we need to run nmhandle_detach_cb()
|
||||||
|
asynchronously to ensure correct order of multiple packets processing in
|
||||||
|
the isc__nm_process_sock_buffer(). When not run asynchronously, it
|
||||||
|
would cause:
|
||||||
|
|
||||||
|
a) out-of-order processing of the return codes from processbuffer();
|
||||||
|
|
||||||
|
b) stack growth because the next TCP DNS message read callback will
|
||||||
|
be called from within the current TCP DNS message read callback.
|
||||||
|
|
||||||
|
The sock->closehandle_cb is set to isc__nm_resume_processing() for TCP
|
||||||
|
sockets which calls isc__nm_process_sock_buffer(). If the read callback
|
||||||
|
(called from isc__nm_process_sock_buffer()->processbuffer()) doesn't
|
||||||
|
attach to the nmhandle (f.e. because it wants to drop the processing or
|
||||||
|
we send the response directly via uv_try_write()), the
|
||||||
|
isc__nm_resume_processing() (via .closehandle_cb) would call
|
||||||
|
isc__nm_process_sock_buffer() recursively.
|
||||||
|
|
||||||
|
The below shortened code path shows how the stack can grow:
|
||||||
|
|
||||||
|
1: ns__client_request(handle, ...);
|
||||||
|
2: isc_nm_tcpdns_sequential(handle);
|
||||||
|
3: ns_query_start(client, handle);
|
||||||
|
4: query_lookup(qctx);
|
||||||
|
5: query_send(qctcx->client);
|
||||||
|
6: isc__nmhandle_detach(&client->reqhandle);
|
||||||
|
7: nmhandle_detach_cb(&handle);
|
||||||
|
8: sock->closehandle_cb(sock); // isc__nm_resume_processing
|
||||||
|
9: isc__nm_process_sock_buffer(sock);
|
||||||
|
10: processbuffer(sock); // isc__nm_tcpdns_processbuffer
|
||||||
|
11: isc_nmhandle_attach(req->handle, &handle);
|
||||||
|
12: isc__nm_readcb(sock, req, ISC_R_SUCCESS);
|
||||||
|
13: isc__nm_async_readcb(NULL, ...);
|
||||||
|
14: uvreq->cb.recv(...); // ns__client_request
|
||||||
|
|
||||||
|
Instead, if 'sock->closehandle_cb' is set, we need to run detach the
|
||||||
|
handle asynchroniously in 'isc__nmhandle_detach', so that on line 8 in
|
||||||
|
the code flow above does not start this recursion. This ensures the
|
||||||
|
correct order when processing multiple packets in the function
|
||||||
|
'isc__nm_process_sock_buffer()' and prevents the stack growth.
|
||||||
|
|
||||||
|
When not run asynchronously, the out-of-order processing leaves the
|
||||||
|
first TCP socket open until all requests on the stream have been
|
||||||
|
processed.
|
||||||
|
|
||||||
|
If the pipelining is disabled on the TCP via `keep-response-order`
|
||||||
|
configuration option, named would keep the first socket in lingering
|
||||||
|
CLOSE_WAIT state when the client sends an incomplete packet and then
|
||||||
|
closes the connection from the client side.
|
||||||
|
|
||||||
|
(cherry picked from commit afee2b5a7bc933a2d987907fc327a9f118fdbd17)
|
||||||
|
---
|
||||||
|
lib/isc/netmgr/netmgr.c | 6 +++++-
|
||||||
|
1 file changed, 5 insertions(+), 1 deletion(-)
|
||||||
|
|
||||||
|
diff --git a/lib/isc/netmgr/netmgr.c b/lib/isc/netmgr/netmgr.c
|
||||||
|
index 3283eb6e4f..0ed3182fb6 100644
|
||||||
|
--- a/lib/isc/netmgr/netmgr.c
|
||||||
|
+++ b/lib/isc/netmgr/netmgr.c
|
||||||
|
@@ -1746,8 +1746,12 @@ isc__nmhandle_detach(isc_nmhandle_t **handlep FLARG) {
|
||||||
|
handle = *handlep;
|
||||||
|
*handlep = NULL;
|
||||||
|
|
||||||
|
+ /*
|
||||||
|
+ * If the closehandle_cb is set, it needs to run asynchronously to
|
||||||
|
+ * ensure correct ordering of the isc__nm_process_sock_buffer().
|
||||||
|
+ */
|
||||||
|
sock = handle->sock;
|
||||||
|
- if (sock->tid == isc_nm_tid()) {
|
||||||
|
+ if (sock->tid == isc_nm_tid() && sock->closehandle_cb == NULL) {
|
||||||
|
nmhandle_detach_cb(&handle FLARG_PASS);
|
||||||
|
} else {
|
||||||
|
isc__netievent_detach_t *event =
|
||||||
|
--
|
||||||
|
2.34.1
|
||||||
|
|
||||||
@ -1,4 +1,4 @@
|
|||||||
From 05cdbc1006cee6daaa29e5423976d56047d22461 Mon Sep 17 00:00:00 2001
|
From bf2ea6d8525bfd96a84dad221ba9e004adb710a8 Mon Sep 17 00:00:00 2001
|
||||||
From: =?UTF-8?q?Micha=C5=82=20K=C4=99pie=C5=84?= <michal@isc.org>
|
From: =?UTF-8?q?Micha=C5=82=20K=C4=99pie=C5=84?= <michal@isc.org>
|
||||||
Date: Thu, 8 Sep 2022 11:11:30 +0200
|
Date: Thu, 8 Sep 2022 11:11:30 +0200
|
||||||
Subject: [PATCH] Bound the amount of work performed for delegations
|
Subject: [PATCH] Bound the amount of work performed for delegations
|
||||||
@ -14,16 +14,15 @@ The limit used (20) is an arbitrary value that is considered to be big
|
|||||||
enough for any sane DNS delegation.
|
enough for any sane DNS delegation.
|
||||||
|
|
||||||
(cherry picked from commit 3a44097fd6c6c260765b628cd1d2c9cb7efb0b2a)
|
(cherry picked from commit 3a44097fd6c6c260765b628cd1d2c9cb7efb0b2a)
|
||||||
(cherry picked from commit bf2ea6d8525bfd96a84dad221ba9e004adb710a8)
|
|
||||||
---
|
---
|
||||||
lib/dns/resolver.c | 12 ++++++++++++
|
lib/dns/resolver.c | 12 ++++++++++++
|
||||||
1 file changed, 12 insertions(+)
|
1 file changed, 12 insertions(+)
|
||||||
|
|
||||||
diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c
|
diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c
|
||||||
index 8ae9a993bb..ac9a9ef5d0 100644
|
index d2cf14bbc8..73a0ee9f77 100644
|
||||||
--- a/lib/dns/resolver.c
|
--- a/lib/dns/resolver.c
|
||||||
+++ b/lib/dns/resolver.c
|
+++ b/lib/dns/resolver.c
|
||||||
@@ -180,6 +180,12 @@
|
@@ -195,6 +195,12 @@
|
||||||
*/
|
*/
|
||||||
#define NS_FAIL_LIMIT 4
|
#define NS_FAIL_LIMIT 4
|
||||||
#define NS_RR_LIMIT 5
|
#define NS_RR_LIMIT 5
|
||||||
@ -36,7 +35,7 @@ index 8ae9a993bb..ac9a9ef5d0 100644
|
|||||||
|
|
||||||
/* Number of hash buckets for zone counters */
|
/* Number of hash buckets for zone counters */
|
||||||
#ifndef RES_DOMAIN_BUCKETS
|
#ifndef RES_DOMAIN_BUCKETS
|
||||||
@@ -3318,6 +3324,7 @@ fctx_getaddresses(fetchctx_t *fctx, bool badcache) {
|
@@ -3711,6 +3717,7 @@ fctx_getaddresses(fetchctx_t *fctx, bool badcache) {
|
||||||
bool need_alternate = false;
|
bool need_alternate = false;
|
||||||
bool all_spilled = true;
|
bool all_spilled = true;
|
||||||
unsigned int no_addresses = 0;
|
unsigned int no_addresses = 0;
|
||||||
@ -44,7 +43,7 @@ index 8ae9a993bb..ac9a9ef5d0 100644
|
|||||||
|
|
||||||
FCTXTRACE5("getaddresses", "fctx->depth=", fctx->depth);
|
FCTXTRACE5("getaddresses", "fctx->depth=", fctx->depth);
|
||||||
|
|
||||||
@@ -3504,6 +3511,11 @@ fctx_getaddresses(fetchctx_t *fctx, bool badcache) {
|
@@ -3902,6 +3909,11 @@ normal_nses:
|
||||||
|
|
||||||
dns_rdata_reset(&rdata);
|
dns_rdata_reset(&rdata);
|
||||||
dns_rdata_freestruct(&ns);
|
dns_rdata_freestruct(&ns);
|
||||||
116
SOURCES/bind-9.16-CVE-2022-3080.patch
Normal file
116
SOURCES/bind-9.16-CVE-2022-3080.patch
Normal file
@ -0,0 +1,116 @@
|
|||||||
|
From 3bcd32572504ac9b92e3c6ec1e2cee3df3b68309 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Tue, 20 Sep 2022 11:34:42 +0200
|
||||||
|
Subject: [PATCH 2/4] Fix CVE-2022-3080
|
||||||
|
|
||||||
|
5960. [security] Fix serve-stale crash that could happen when
|
||||||
|
stale-answer-client-timeout was set to 0 and there was
|
||||||
|
a stale CNAME in the cache for an incoming query.
|
||||||
|
(CVE-2022-3080) [GL #3517]
|
||||||
|
---
|
||||||
|
lib/ns/include/ns/query.h | 1 +
|
||||||
|
lib/ns/query.c | 42 ++++++++++++++++++++++++---------------
|
||||||
|
2 files changed, 27 insertions(+), 16 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/lib/ns/include/ns/query.h b/lib/ns/include/ns/query.h
|
||||||
|
index 4d48cf6..34b3070 100644
|
||||||
|
--- a/lib/ns/include/ns/query.h
|
||||||
|
+++ b/lib/ns/include/ns/query.h
|
||||||
|
@@ -145,6 +145,7 @@ struct query_ctx {
|
||||||
|
bool authoritative; /* authoritative query? */
|
||||||
|
bool want_restart; /* CNAME chain or other
|
||||||
|
* restart needed */
|
||||||
|
+ bool refresh_rrset; /* stale RRset refresh needed */
|
||||||
|
bool need_wildcardproof; /* wildcard proof needed */
|
||||||
|
bool nxrewrite; /* negative answer from RPZ */
|
||||||
|
bool findcoveringnsec; /* lookup covering NSEC */
|
||||||
|
diff --git a/lib/ns/query.c b/lib/ns/query.c
|
||||||
|
index 249321c..a450cb7 100644
|
||||||
|
--- a/lib/ns/query.c
|
||||||
|
+++ b/lib/ns/query.c
|
||||||
|
@@ -5686,7 +5686,6 @@ query_lookup(query_ctx_t *qctx) {
|
||||||
|
bool dbfind_stale = false;
|
||||||
|
bool stale_timeout = false;
|
||||||
|
bool stale_found = false;
|
||||||
|
- bool refresh_rrset = false;
|
||||||
|
bool stale_refresh_window = false;
|
||||||
|
|
||||||
|
CCTRACE(ISC_LOG_DEBUG(3), "query_lookup");
|
||||||
|
@@ -5868,8 +5867,7 @@ query_lookup(query_ctx_t *qctx) {
|
||||||
|
"%s stale answer used, an attempt to "
|
||||||
|
"refresh the RRset will still be made",
|
||||||
|
namebuf);
|
||||||
|
- refresh_rrset = STALE(qctx->rdataset);
|
||||||
|
- qctx->client->nodetach = refresh_rrset;
|
||||||
|
+ qctx->refresh_rrset = STALE(qctx->rdataset);
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
/*
|
||||||
|
@@ -5907,17 +5905,6 @@ query_lookup(query_ctx_t *qctx) {
|
||||||
|
|
||||||
|
result = query_gotanswer(qctx, result);
|
||||||
|
|
||||||
|
- if (refresh_rrset) {
|
||||||
|
- /*
|
||||||
|
- * If we reached this point then it means that we have found a
|
||||||
|
- * stale RRset entry in cache and BIND is configured to allow
|
||||||
|
- * queries to be answered with stale data if no active RRset
|
||||||
|
- * is available, i.e. "stale-anwer-client-timeout 0". But, we
|
||||||
|
- * still need to refresh the RRset.
|
||||||
|
- */
|
||||||
|
- query_refresh_rrset(qctx);
|
||||||
|
- }
|
||||||
|
-
|
||||||
|
cleanup:
|
||||||
|
return (result);
|
||||||
|
}
|
||||||
|
@@ -7737,11 +7724,14 @@ query_addanswer(query_ctx_t *qctx) {
|
||||||
|
|
||||||
|
/*
|
||||||
|
* On normal lookups, clear any rdatasets that were added on a
|
||||||
|
- * lookup due to stale-answer-client-timeout.
|
||||||
|
+ * lookup due to stale-answer-client-timeout. Do not clear if we
|
||||||
|
+ * are going to refresh the RRset, because the stale contents are
|
||||||
|
+ * prioritized.
|
||||||
|
*/
|
||||||
|
if (QUERY_STALEOK(&qctx->client->query) &&
|
||||||
|
- !QUERY_STALETIMEOUT(&qctx->client->query))
|
||||||
|
+ !QUERY_STALETIMEOUT(&qctx->client->query) && !qctx->refresh_rrset)
|
||||||
|
{
|
||||||
|
+ CCTRACE(ISC_LOG_DEBUG(3), "query_clear_stale");
|
||||||
|
query_clear_stale(qctx->client);
|
||||||
|
/*
|
||||||
|
* We can clear the attribute to prevent redundant clearing
|
||||||
|
@@ -11457,9 +11447,29 @@ ns_query_done(query_ctx_t *qctx) {
|
||||||
|
/*
|
||||||
|
* Client may have been detached after query_send(), so
|
||||||
|
* we test and store the flag state here, for safety.
|
||||||
|
+ * If we are refreshing the RRSet, we must not detach from the client
|
||||||
|
+ * in the query_send(), so we need to override the flag.
|
||||||
|
*/
|
||||||
|
+ if (qctx->refresh_rrset) {
|
||||||
|
+ qctx->client->nodetach = true;
|
||||||
|
+ }
|
||||||
|
nodetach = qctx->client->nodetach;
|
||||||
|
query_send(qctx->client);
|
||||||
|
+
|
||||||
|
+ if (qctx->refresh_rrset) {
|
||||||
|
+ /*
|
||||||
|
+ * If we reached this point then it means that we have found a
|
||||||
|
+ * stale RRset entry in cache and BIND is configured to allow
|
||||||
|
+ * queries to be answered with stale data if no active RRset
|
||||||
|
+ * is available, i.e. "stale-anwer-client-timeout 0". But, we
|
||||||
|
+ * still need to refresh the RRset. To prevent adding duplicate
|
||||||
|
+ * RRsets, clear the RRsets from the message before doing the
|
||||||
|
+ * refresh.
|
||||||
|
+ */
|
||||||
|
+ message_clearrdataset(qctx->client->message, 0);
|
||||||
|
+ query_refresh_rrset(qctx);
|
||||||
|
+ }
|
||||||
|
+
|
||||||
|
if (!nodetach) {
|
||||||
|
qctx->detach_client = true;
|
||||||
|
}
|
||||||
|
--
|
||||||
|
2.37.3
|
||||||
|
|
||||||
@ -1,4 +1,4 @@
|
|||||||
From 128b3b676eb9413b4d25fb29c560895cfbbfa92e Mon Sep 17 00:00:00 2001
|
From 18036bb3f435eaa20d60093738c61e5da42a6cfe Mon Sep 17 00:00:00 2001
|
||||||
From: Evan Hunt <each@isc.org>
|
From: Evan Hunt <each@isc.org>
|
||||||
Date: Thu, 1 Sep 2022 16:05:04 -0700
|
Date: Thu, 1 Sep 2022 16:05:04 -0700
|
||||||
Subject: [PATCH] add an update quota
|
Subject: [PATCH] add an update quota
|
||||||
@ -12,229 +12,229 @@ has been exceeded.
|
|||||||
|
|
||||||
(cherry picked from commit 7c47254a140c3e9cf383cda73c7b6a55c4782826)
|
(cherry picked from commit 7c47254a140c3e9cf383cda73c7b6a55c4782826)
|
||||||
---
|
---
|
||||||
bin/named/bind9.xsl | 2 +-
|
bin/named/bind9.xsl | 4 +++-
|
||||||
bin/named/bind9.xsl.h | 8 +++++++-
|
bin/named/bind9.xsl.h | 6 +++++-
|
||||||
bin/named/include/named/server.h | 7 ++++++-
|
bin/named/statschannel.c | 5 +++--
|
||||||
bin/named/server.c | 3 +++
|
doc/arm/reference.rst | 5 +++++
|
||||||
bin/named/statschannel.c | 5 +++--
|
lib/ns/include/ns/server.h | 1 +
|
||||||
bin/named/update.c | 34 +++++++++++++++++++++++++++++++-
|
lib/ns/include/ns/stats.h | 4 +++-
|
||||||
doc/arm/Bv9ARM-book.xml | 15 ++++++++++++++
|
lib/ns/server.c | 2 ++
|
||||||
7 files changed, 68 insertions(+), 6 deletions(-)
|
lib/ns/update.c | 37 ++++++++++++++++++++++++++++++++++++-
|
||||||
|
8 files changed, 58 insertions(+), 6 deletions(-)
|
||||||
|
|
||||||
diff --git a/bin/named/bind9.xsl b/bin/named/bind9.xsl
|
diff --git a/bin/named/bind9.xsl b/bin/named/bind9.xsl
|
||||||
index 9a1c6ff..85fd4c4 100644
|
index 5078115..194625b 100644
|
||||||
--- a/bin/named/bind9.xsl
|
--- a/bin/named/bind9.xsl
|
||||||
+++ b/bin/named/bind9.xsl
|
+++ b/bin/named/bind9.xsl
|
||||||
@@ -12,7 +12,7 @@
|
@@ -12,7 +12,9 @@
|
||||||
|
|
||||||
<xsl:stylesheet xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns="http://www.w3.org/1999/xhtml" version="1.0">
|
<xsl:stylesheet xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns="http://www.w3.org/1999/xhtml" version="1.0">
|
||||||
<xsl:output method="html" indent="yes" version="4.0"/>
|
<xsl:output method="html" indent="yes" version="4.0"/>
|
||||||
- <xsl:template match="statistics[@version="3.8"]">
|
- <xsl:template match="statistics[@version="3.11"]">
|
||||||
+ <xsl:template match="statistics[@version="3.8.1"]">
|
+ <!-- the version number **below** must match version in bin/named/statschannel.c -->
|
||||||
|
+ <!-- don't forget to update "/xml/v<STATS_XML_VERSION_MAJOR>" in the HTTP endpoints listed below -->
|
||||||
|
+ <xsl:template match="statistics[@version="3.11.1"]">
|
||||||
<html>
|
<html>
|
||||||
<head>
|
<head>
|
||||||
<script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/3.4.1/jquery.min.js"></script>
|
<script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/3.4.1/jquery.min.js"></script>
|
||||||
diff --git a/bin/named/bind9.xsl.h b/bin/named/bind9.xsl.h
|
diff --git a/bin/named/bind9.xsl.h b/bin/named/bind9.xsl.h
|
||||||
index 9ce8cd7..5e0a892 100644
|
index e30f7f5..b182742 100644
|
||||||
--- a/bin/named/bind9.xsl.h
|
--- a/bin/named/bind9.xsl.h
|
||||||
+++ b/bin/named/bind9.xsl.h
|
+++ b/bin/named/bind9.xsl.h
|
||||||
@@ -17,7 +17,13 @@ static char xslmsg[] =
|
@@ -20,7 +20,11 @@ static char xslmsg[] =
|
||||||
"\n"
|
"<xsl:stylesheet xmlns:xsl=\"http://www.w3.org/1999/XSL/Transform\" "
|
||||||
"<xsl:stylesheet xmlns:xsl=\"http://www.w3.org/1999/XSL/Transform\" xmlns=\"http://www.w3.org/1999/xhtml\" version=\"1.0\">\n"
|
"xmlns=\"http://www.w3.org/1999/xhtml\" version=\"1.0\">\n"
|
||||||
" <xsl:output method=\"html\" indent=\"yes\" version=\"4.0\"/>\n"
|
" <xsl:output method=\"html\" indent=\"yes\" version=\"4.0\"/>\n"
|
||||||
- " <xsl:template match=\"statistics[@version="3.8"]\">\n"
|
- " <xsl:template match=\"statistics[@version="3.11"]\">\n"
|
||||||
+#if 0
|
|
||||||
+ " <!-- the version number **below** must match version in "
|
+ " <!-- the version number **below** must match version in "
|
||||||
+ "bin/named/statschannel.c -->\n"
|
+ "bin/named/statschannel.c -->\n"
|
||||||
+ " <!-- don't forget to update \"/xml/v<STATS_XML_VERSION_MAJOR>\" in "
|
+ " <!-- don't forget to update \"/xml/v<STATS_XML_VERSION_MAJOR>\" in "
|
||||||
+ "the HTTP endpoints listed below -->\n"
|
+ "the HTTP endpoints listed below -->\n"
|
||||||
+#endif
|
+ " <xsl:template match=\"statistics[@version="3.11.1"]\">\n"
|
||||||
+ " <xsl:template match=\"statistics[@version="3.8.1"]\">\n"
|
|
||||||
" <html>\n"
|
" <html>\n"
|
||||||
" <head>\n"
|
" <head>\n"
|
||||||
" <script type=\"text/javascript\" src=\"https://ajax.googleapis.com/ajax/libs/jquery/3.4.1/jquery.min.js\"></script>\n"
|
" <script type=\"text/javascript\" "
|
||||||
diff --git a/bin/named/include/named/server.h b/bin/named/include/named/server.h
|
|
||||||
index 08a02dc..259acc7 100644
|
|
||||||
--- a/bin/named/include/named/server.h
|
|
||||||
+++ b/bin/named/include/named/server.h
|
|
||||||
@@ -137,6 +137,9 @@ struct ns_server {
|
|
||||||
|
|
||||||
uint16_t transfer_tcp_message_size;
|
|
||||||
isc_rng_t * rngctx;
|
|
||||||
+
|
|
||||||
+/* CVE-2022-3094 */
|
|
||||||
+ isc_quota_t updquota;
|
|
||||||
};
|
|
||||||
|
|
||||||
struct ns_altsecret {
|
|
||||||
@@ -230,7 +233,9 @@ enum {
|
|
||||||
dns_nsstatscounter_trystale = 59,
|
|
||||||
dns_nsstatscounter_usedstale = 60,
|
|
||||||
|
|
||||||
- dns_nsstatscounter_max = 61
|
|
||||||
+ dns_nsstatscounter_updatequota = 61,
|
|
||||||
+
|
|
||||||
+ dns_nsstatscounter_max = 62
|
|
||||||
};
|
|
||||||
|
|
||||||
/*%
|
|
||||||
diff --git a/bin/named/server.c b/bin/named/server.c
|
|
||||||
index 2d2fa0e..f09b895 100644
|
|
||||||
--- a/bin/named/server.c
|
|
||||||
+++ b/bin/named/server.c
|
|
||||||
@@ -9143,6 +9143,8 @@ ns_server_create(isc_mem_t *mctx, ns_server_t **serverp) {
|
|
||||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
|
||||||
result = isc_quota_init(&server->recursionquota, 100);
|
|
||||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
|
||||||
+ result = isc_quota_init(&server->updquota, 100);
|
|
||||||
+ RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
|
||||||
|
|
||||||
result = dns_aclenv_init(mctx, &server->aclenv);
|
|
||||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
|
||||||
@@ -9410,6 +9412,7 @@ ns_server_destroy(ns_server_t **serverp) {
|
|
||||||
|
|
||||||
dns_aclenv_destroy(&server->aclenv);
|
|
||||||
|
|
||||||
+ isc_quota_destroy(&server->updquota);
|
|
||||||
isc_quota_destroy(&server->recursionquota);
|
|
||||||
isc_quota_destroy(&server->tcpquota);
|
|
||||||
isc_quota_destroy(&server->xfroutquota);
|
|
||||||
diff --git a/bin/named/statschannel.c b/bin/named/statschannel.c
|
diff --git a/bin/named/statschannel.c b/bin/named/statschannel.c
|
||||||
index 56a9c21..1e8723c 100644
|
index 832ce93..7361ead 100644
|
||||||
--- a/bin/named/statschannel.c
|
--- a/bin/named/statschannel.c
|
||||||
+++ b/bin/named/statschannel.c
|
+++ b/bin/named/statschannel.c
|
||||||
@@ -300,6 +300,7 @@ init_desc(void) {
|
@@ -335,6 +335,7 @@ init_desc(void) {
|
||||||
SET_NSSTATDESC(reclimitdropped,
|
SET_NSSTATDESC(reclimitdropped,
|
||||||
"queries dropped due to recursive client limit",
|
"queries dropped due to recursive client limit",
|
||||||
"RecLimitDropped");
|
"RecLimitDropped");
|
||||||
+ SET_NSSTATDESC(updatequota, "Update quota exceeded", "UpdateQuota");
|
+ SET_NSSTATDESC(updatequota, "Update quota exceeded", "UpdateQuota");
|
||||||
SET_NSSTATDESC(trystale,
|
|
||||||
"attempts to use stale cache data after lookup failure",
|
INSIST(i == ns_statscounter_max);
|
||||||
"QryTryStale");
|
|
||||||
@@ -1546,7 +1547,7 @@ generatexml(ns_server_t *server, uint32_t flags,
|
@@ -2007,7 +2008,7 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||||
ISC_XMLCHAR "type=\"text/xsl\" href=\"/bind9.xsl\""));
|
"href=\"/bind9.xsl\""));
|
||||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "statistics"));
|
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "statistics"));
|
||||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "version",
|
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "version",
|
||||||
- ISC_XMLCHAR "3.8"));
|
- ISC_XMLCHAR "3.11"));
|
||||||
+ ISC_XMLCHAR "3.8.1"));
|
+ ISC_XMLCHAR "3.11.1"));
|
||||||
|
|
||||||
/* Set common fields for statistics dump */
|
/* Set common fields for statistics dump */
|
||||||
dumparg.type = isc_statsformat_xml;
|
dumparg.type = isc_statsformat_xml;
|
||||||
@@ -2303,7 +2304,7 @@ generatejson(ns_server_t *server, size_t *msglen,
|
@@ -2876,7 +2877,7 @@ generatejson(named_server_t *server, size_t *msglen, const char **msg,
|
||||||
/*
|
/*
|
||||||
* These statistics are included no matter which URL we use.
|
* These statistics are included no matter which URL we use.
|
||||||
*/
|
*/
|
||||||
- obj = json_object_new_string("1.2");
|
- obj = json_object_new_string("1.5");
|
||||||
+ obj = json_object_new_string("1.2.1");
|
+ obj = json_object_new_string("1.5.1");
|
||||||
CHECKMEM(obj);
|
CHECKMEM(obj);
|
||||||
json_object_object_add(bindstats, "json-stats-version", obj);
|
json_object_object_add(bindstats, "json-stats-version", obj);
|
||||||
|
|
||||||
diff --git a/bin/named/update.c b/bin/named/update.c
|
diff --git a/doc/arm/reference.rst b/doc/arm/reference.rst
|
||||||
index 6ad7d27..dccc543 100644
|
index 2d05aec..25c20d7 100644
|
||||||
--- a/bin/named/update.c
|
--- a/doc/arm/reference.rst
|
||||||
+++ b/bin/named/update.c
|
+++ b/doc/arm/reference.rst
|
||||||
@@ -1526,6 +1526,17 @@ send_update_event(ns_client_t *client, dns_zone_t *zone) {
|
@@ -6705,6 +6705,11 @@ Name Server Statistics Counters
|
||||||
isc_task_t *zonetask = NULL;
|
``UpdateBadPrereq``
|
||||||
ns_client_t *evclient;
|
This indicates the number of dynamic updates rejected due to a prerequisite failure.
|
||||||
|
|
||||||
+ result = isc_quota_attach(&ns_g_server->updquota,
|
+``UpdateQuota``
|
||||||
|
+ This indicates the number of times a dynamic update or update
|
||||||
|
+ forwarding request was rejected because the number of pending
|
||||||
|
+ requests exceeded the update quota.
|
||||||
|
+
|
||||||
|
``RateDropped``
|
||||||
|
This indicates the number of responses dropped due to rate limits.
|
||||||
|
|
||||||
|
diff --git a/lib/ns/include/ns/server.h b/lib/ns/include/ns/server.h
|
||||||
|
index 6a1f345..0abb579 100644
|
||||||
|
--- a/lib/ns/include/ns/server.h
|
||||||
|
+++ b/lib/ns/include/ns/server.h
|
||||||
|
@@ -84,6 +84,7 @@ struct ns_server {
|
||||||
|
isc_quota_t recursionquota;
|
||||||
|
isc_quota_t tcpquota;
|
||||||
|
isc_quota_t xfroutquota;
|
||||||
|
+ isc_quota_t updquota;
|
||||||
|
|
||||||
|
/*% Test options and other configurables */
|
||||||
|
uint32_t options;
|
||||||
|
diff --git a/lib/ns/include/ns/stats.h b/lib/ns/include/ns/stats.h
|
||||||
|
index 3c08799..95b15d0 100644
|
||||||
|
--- a/lib/ns/include/ns/stats.h
|
||||||
|
+++ b/lib/ns/include/ns/stats.h
|
||||||
|
@@ -106,7 +106,9 @@ enum {
|
||||||
|
|
||||||
|
ns_statscounter_reclimitdropped = 66,
|
||||||
|
|
||||||
|
- ns_statscounter_max = 67,
|
||||||
|
+ ns_statscounter_updatequota = 67,
|
||||||
|
+
|
||||||
|
+ ns_statscounter_max = 68,
|
||||||
|
};
|
||||||
|
|
||||||
|
void
|
||||||
|
diff --git a/lib/ns/server.c b/lib/ns/server.c
|
||||||
|
index a970a28..540bc2e 100644
|
||||||
|
--- a/lib/ns/server.c
|
||||||
|
+++ b/lib/ns/server.c
|
||||||
|
@@ -52,6 +52,7 @@ ns_server_create(isc_mem_t *mctx, ns_matchview_t matchingview,
|
||||||
|
isc_quota_init(&sctx->xfroutquota, 10);
|
||||||
|
isc_quota_init(&sctx->tcpquota, 10);
|
||||||
|
isc_quota_init(&sctx->recursionquota, 100);
|
||||||
|
+ isc_quota_init(&sctx->updquota, 100);
|
||||||
|
|
||||||
|
CHECKFATAL(dns_tkeyctx_create(mctx, &sctx->tkeyctx));
|
||||||
|
|
||||||
|
@@ -131,6 +132,7 @@ ns_server_detach(ns_server_t **sctxp) {
|
||||||
|
isc_mem_put(sctx->mctx, altsecret, sizeof(*altsecret));
|
||||||
|
}
|
||||||
|
|
||||||
|
+ isc_quota_destroy(&sctx->updquota);
|
||||||
|
isc_quota_destroy(&sctx->recursionquota);
|
||||||
|
isc_quota_destroy(&sctx->tcpquota);
|
||||||
|
isc_quota_destroy(&sctx->xfroutquota);
|
||||||
|
diff --git a/lib/ns/update.c b/lib/ns/update.c
|
||||||
|
index 546b70a..1871438 100644
|
||||||
|
--- a/lib/ns/update.c
|
||||||
|
+++ b/lib/ns/update.c
|
||||||
|
@@ -1544,6 +1544,19 @@ send_update_event(ns_client_t *client, dns_zone_t *zone) {
|
||||||
|
update_event_t *event = NULL;
|
||||||
|
isc_task_t *zonetask = NULL;
|
||||||
|
|
||||||
|
+ result = isc_quota_attach(&client->manager->sctx->updquota,
|
||||||
+ &(isc_quota_t *){ NULL });
|
+ &(isc_quota_t *){ NULL });
|
||||||
+ if (result != ISC_R_SUCCESS) {
|
+ if (result != ISC_R_SUCCESS) {
|
||||||
+ update_log(client, zone, LOGLEVEL_PROTOCOL,
|
+ update_log(client, zone, LOGLEVEL_PROTOCOL,
|
||||||
+ "update failed: too many DNS UPDATEs queued (%s)",
|
+ "update failed: too many DNS UPDATEs queued (%s)",
|
||||||
+ isc_result_totext(result));
|
+ isc_result_totext(result));
|
||||||
+ isc_stats_increment(ns_g_server->nsstats,
|
+ ns_stats_increment(client->manager->sctx->nsstats,
|
||||||
+ dns_nsstatscounter_updatequota);
|
+ ns_statscounter_updatequota);
|
||||||
+ CHECK(DNS_R_DROP);
|
+ ns_client_drop(client, result);
|
||||||
|
+ isc_nmhandle_detach(&client->reqhandle);
|
||||||
|
+ return (DNS_R_DROP);
|
||||||
+ }
|
+ }
|
||||||
+
|
+
|
||||||
event = (update_event_t *)
|
event = (update_event_t *)isc_event_allocate(
|
||||||
isc_event_allocate(client->mctx, client, DNS_EVENT_UPDATE,
|
client->mctx, client, DNS_EVENT_UPDATE, update_action, NULL,
|
||||||
update_action, NULL, sizeof(*event));
|
sizeof(*event));
|
||||||
@@ -1652,7 +1663,12 @@ ns_update_start(ns_client_t *client, isc_result_t sigresult) {
|
@@ -1676,12 +1689,18 @@ failure:
|
||||||
|
dns_zone_gettype(zone) == dns_zone_mirror);
|
||||||
|
inc_stats(client, zone, ns_statscounter_updaterej);
|
||||||
|
}
|
||||||
|
+
|
||||||
|
/*
|
||||||
|
* We failed without having sent an update event to the zone.
|
||||||
* We are still in the client task context, so we can
|
* We are still in the client task context, so we can
|
||||||
* simply give an error response without switching tasks.
|
* simply give an error response without switching tasks.
|
||||||
*/
|
*/
|
||||||
- respond(client, result);
|
- respond(client, result);
|
||||||
+ if (result == DNS_R_DROP) {
|
+ if (result == DNS_R_DROP) {
|
||||||
+ ns_client_next(client, result);
|
+ ns_client_drop(client, result);
|
||||||
+ } else {
|
+ } else {
|
||||||
+ respond(client, result);
|
+ respond(client, result);
|
||||||
+ }
|
+ }
|
||||||
+
|
+
|
||||||
if (zone != NULL)
|
if (zone != NULL) {
|
||||||
dns_zone_detach(&zone);
|
dns_zone_detach(&zone);
|
||||||
}
|
}
|
||||||
@@ -3385,6 +3401,7 @@ updatedone_action(isc_task_t *task, isc_event_t *event) {
|
@@ -3489,6 +3508,7 @@ updatedone_action(isc_task_t *task, isc_event_t *event) {
|
||||||
dns_zone_detach(&uev->zone);
|
|
||||||
client->nupdates--;
|
|
||||||
respond(client, uev->result);
|
respond(client, uev->result);
|
||||||
+ isc_quota_detach(&(isc_quota_t *){ &ns_g_server->updquota });
|
|
||||||
|
+ isc_quota_detach(&(isc_quota_t *){ &client->manager->sctx->updquota });
|
||||||
isc_event_free(&event);
|
isc_event_free(&event);
|
||||||
ns_client_detach(&client);
|
isc_nmhandle_detach(&client->updatehandle);
|
||||||
}
|
}
|
||||||
@@ -3402,6 +3419,8 @@ forward_fail(isc_task_t *task, isc_event_t *event) {
|
@@ -3505,6 +3525,8 @@ forward_fail(isc_task_t *task, isc_event_t *event) {
|
||||||
INSIST(client->nupdates > 0);
|
INSIST(client->nupdates > 0);
|
||||||
client->nupdates--;
|
client->nupdates--;
|
||||||
respond(client, DNS_R_SERVFAIL);
|
respond(client, DNS_R_SERVFAIL);
|
||||||
+
|
+
|
||||||
+ isc_quota_detach(&(isc_quota_t *){ &ns_g_server->updquota });
|
+ isc_quota_detach(&(isc_quota_t *){ &client->manager->sctx->updquota });
|
||||||
isc_event_free(&event);
|
isc_event_free(&event);
|
||||||
ns_client_detach(&client);
|
isc_nmhandle_detach(&client->updatehandle);
|
||||||
}
|
}
|
||||||
@@ -3439,6 +3458,8 @@ forward_done(isc_task_t *task, isc_event_t *event) {
|
@@ -3542,6 +3564,8 @@ forward_done(isc_task_t *task, isc_event_t *event) {
|
||||||
client->nupdates--;
|
client->nupdates--;
|
||||||
ns_client_sendraw(client, uev->answer);
|
ns_client_sendraw(client, uev->answer);
|
||||||
dns_message_detach(&uev->answer);
|
dns_message_detach(&uev->answer);
|
||||||
+
|
+
|
||||||
+ isc_quota_detach(&(isc_quota_t *){ &ns_g_server->updquota });
|
+ isc_quota_detach(&(isc_quota_t *){ &client->manager->sctx->updquota });
|
||||||
isc_event_free(&event);
|
isc_event_free(&event);
|
||||||
ns_client_detach(&client);
|
isc_nmhandle_detach(&client->updatehandle);
|
||||||
}
|
}
|
||||||
@@ -3472,6 +3493,17 @@ send_forward_event(ns_client_t *client, dns_zone_t *zone) {
|
@@ -3576,6 +3600,17 @@ send_forward_event(ns_client_t *client, dns_zone_t *zone) {
|
||||||
|
update_event_t *event = NULL;
|
||||||
isc_task_t *zonetask = NULL;
|
isc_task_t *zonetask = NULL;
|
||||||
ns_client_t *evclient;
|
|
||||||
|
|
||||||
+ result = isc_quota_attach(&ns_g_server->updquota,
|
+ result = isc_quota_attach(&client->manager->sctx->updquota,
|
||||||
+ &(isc_quota_t *){ NULL });
|
+ &(isc_quota_t *){ NULL });
|
||||||
+ if (result != ISC_R_SUCCESS) {
|
+ if (result != ISC_R_SUCCESS) {
|
||||||
+ update_log(client, zone, LOGLEVEL_PROTOCOL,
|
+ update_log(client, zone, LOGLEVEL_PROTOCOL,
|
||||||
+ "update failed: too many DNS UPDATEs queued (%s)",
|
+ "update failed: too many DNS UPDATEs queued (%s)",
|
||||||
+ isc_result_totext(result));
|
+ isc_result_totext(result));
|
||||||
+ isc_stats_increment(ns_g_server->nsstats,
|
+ ns_stats_increment(client->manager->sctx->nsstats,
|
||||||
+ dns_nsstatscounter_updatequota);
|
+ ns_statscounter_updatequota);
|
||||||
+ return (DNS_R_DROP);
|
+ return (DNS_R_DROP);
|
||||||
+ }
|
+ }
|
||||||
+
|
+
|
||||||
/*
|
event = (update_event_t *)isc_event_allocate(
|
||||||
* This may take some time so replace this client.
|
client->mctx, client, DNS_EVENT_UPDATE, forward_action, NULL,
|
||||||
*/
|
sizeof(*event));
|
||||||
diff --git a/doc/arm/Bv9ARM-book.xml b/doc/arm/Bv9ARM-book.xml
|
|
||||||
index c17f168..9aca6d7 100644
|
|
||||||
--- a/doc/arm/Bv9ARM-book.xml
|
|
||||||
+++ b/doc/arm/Bv9ARM-book.xml
|
|
||||||
@@ -15105,6 +15105,21 @@ HOST-127.EXAMPLE. MX 0 .
|
|
||||||
</para>
|
|
||||||
</entry>
|
|
||||||
</row>
|
|
||||||
+ <row rowsep="0">
|
|
||||||
+ <entry colname="1">
|
|
||||||
+ <para><command>UpdateQuota</command></para>
|
|
||||||
+ </entry>
|
|
||||||
+ <entry colname="2">
|
|
||||||
+ <para><command/></para>
|
|
||||||
+ </entry>
|
|
||||||
+ <entry colname="3">
|
|
||||||
+ <para>
|
|
||||||
+ This indicates the number of times a dynamic update or update
|
|
||||||
+ forwarding request was rejected because the number of pending
|
|
||||||
+ requests exceeded the update quota.
|
|
||||||
+ </para>
|
|
||||||
+ </entry>
|
|
||||||
+ </row>
|
|
||||||
<row rowsep="0">
|
|
||||||
<entry colname="1">
|
|
||||||
<para><command>RateDropped</command></para>
|
|
||||||
--
|
--
|
||||||
2.39.2
|
2.39.2
|
||||||
|
|
||||||
|
|||||||
@ -1,4 +1,4 @@
|
|||||||
From d9a03233c6ea11f20c2fbeca87b763673859f8b2 Mon Sep 17 00:00:00 2001
|
From 7fe2204a2e8952bf892e4a70fea2ef5167e1f509 Mon Sep 17 00:00:00 2001
|
||||||
From: Evan Hunt <each@isc.org>
|
From: Evan Hunt <each@isc.org>
|
||||||
Date: Thu, 1 Sep 2022 16:22:46 -0700
|
Date: Thu, 1 Sep 2022 16:22:46 -0700
|
||||||
Subject: [PATCH] add a configuration option for the update quota
|
Subject: [PATCH] add a configuration option for the update quota
|
||||||
@ -7,130 +7,260 @@ add an "update-quota" option to configure the update quota.
|
|||||||
|
|
||||||
(cherry picked from commit f57758a7303ad0034ff2ff08eaaf2ef899630f19)
|
(cherry picked from commit f57758a7303ad0034ff2ff08eaaf2ef899630f19)
|
||||||
---
|
---
|
||||||
bin/named/config.c | 1 +
|
bin/named/config.c | 1 +
|
||||||
bin/named/named.conf.docbook | 2 ++
|
bin/named/named.conf.rst | 9 +++++----
|
||||||
bin/named/server.c | 1 +
|
bin/named/server.c | 1 +
|
||||||
bin/tests/system/checkconf/good.conf | 1 +
|
bin/tests/system/checkconf/good.conf | 1 +
|
||||||
doc/arm/Bv9ARM-book.xml | 11 +++++++++++
|
doc/arm/reference.rst | 7 ++++++-
|
||||||
doc/arm/options.grammar.xml | 1 +
|
doc/man/named.conf.5in | 9 +++++----
|
||||||
doc/misc/options | 1 +
|
doc/misc/master.zoneopt.rst | 2 +-
|
||||||
lib/isccfg/namedconf.c | 1 +
|
doc/misc/options | 1 +
|
||||||
8 files changed, 19 insertions(+)
|
doc/misc/options.active | 1 +
|
||||||
|
doc/misc/options.grammar.rst | 3 ++-
|
||||||
|
doc/misc/slave.zoneopt.rst | 2 +-
|
||||||
|
lib/isccfg/namedconf.c | 1 +
|
||||||
|
12 files changed, 26 insertions(+), 12 deletions(-)
|
||||||
|
|
||||||
diff --git a/bin/named/config.c b/bin/named/config.c
|
diff --git a/bin/named/config.c b/bin/named/config.c
|
||||||
index 62d1e88..e3731cf 100644
|
index 5fedee84d9..494147015f 100644
|
||||||
--- a/bin/named/config.c
|
--- a/bin/named/config.c
|
||||||
+++ b/bin/named/config.c
|
+++ b/bin/named/config.c
|
||||||
@@ -134,6 +134,7 @@ options {\n\
|
@@ -130,6 +130,7 @@ options {\n\
|
||||||
|
transfers-out 10;\n\
|
||||||
transfers-per-ns 2;\n\
|
transfers-per-ns 2;\n\
|
||||||
# treat-cr-as-space <obsolete>;\n\
|
|
||||||
trust-anchor-telemetry yes;\n\
|
trust-anchor-telemetry yes;\n\
|
||||||
+ update-quota 100;\n\
|
+ update-quota 100;\n\
|
||||||
# use-id-pool <obsolete>;\n\
|
|
||||||
# use-ixfr <obsolete>;\n\
|
|
||||||
\n\
|
\n\
|
||||||
diff --git a/bin/named/named.conf.docbook b/bin/named/named.conf.docbook
|
/* view */\n\
|
||||||
index 6565fce..5842cb5 100644
|
allow-new-zones no;\n\
|
||||||
--- a/bin/named/named.conf.docbook
|
diff --git a/bin/named/named.conf.rst b/bin/named/named.conf.rst
|
||||||
+++ b/bin/named/named.conf.docbook
|
index 27eed5ca3e..4c9f9a7370 100644
|
||||||
@@ -455,6 +455,7 @@ options {
|
--- a/bin/named/named.conf.rst
|
||||||
trust-anchor-telemetry <replaceable>boolean</replaceable>; // experimental
|
+++ b/bin/named/named.conf.rst
|
||||||
try-tcp-refresh <replaceable>boolean</replaceable>;
|
@@ -179,7 +179,7 @@ OPTIONS
|
||||||
update-check-ksk <replaceable>boolean</replaceable>;
|
answer-cookie boolean;
|
||||||
+ update-quota <replaceable>integer</replaceable>;
|
attach-cache string;
|
||||||
use-alt-transfer-source <replaceable>boolean</replaceable>;
|
auth-nxdomain boolean; // default changed
|
||||||
use-v4-udp-ports { <replaceable>portrange</replaceable>; ... };
|
- auto-dnssec ( allow | maintain | off );
|
||||||
use-v6-udp-ports { <replaceable>portrange</replaceable>; ... };
|
+ auto-dnssec ( allow | maintain | off );// deprecated
|
||||||
@@ -864,6 +865,7 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
automatic-interface-scan boolean;
|
||||||
type ( delegation-only | forward | hint | master | redirect
|
avoid-v4-udp-ports { portrange; ... };
|
||||||
| slave | static-stub | stub );
|
avoid-v6-udp-ports { portrange; ... };
|
||||||
update-check-ksk <replaceable>boolean</replaceable>;
|
@@ -446,6 +446,7 @@ OPTIONS
|
||||||
+ update-quota <replaceable>integer</replaceable>;
|
trust-anchor-telemetry boolean; // experimental
|
||||||
update-policy ( local | { ( deny | grant ) <replaceable>string</replaceable> (
|
try-tcp-refresh boolean;
|
||||||
6to4-self | external | krb5-self | krb5-selfsub |
|
update-check-ksk boolean;
|
||||||
krb5-subdomain | ms-self | ms-selfsub | ms-subdomain |
|
+ update-quota integer;
|
||||||
|
use-alt-transfer-source boolean;
|
||||||
|
use-v4-udp-ports { portrange; ... };
|
||||||
|
use-v6-udp-ports { portrange; ... };
|
||||||
|
@@ -584,7 +585,7 @@ VIEW
|
||||||
|
* ) ] [ dscp integer ];
|
||||||
|
attach-cache string;
|
||||||
|
auth-nxdomain boolean; // default changed
|
||||||
|
- auto-dnssec ( allow | maintain | off );
|
||||||
|
+ auto-dnssec ( allow | maintain | off );// deprecated
|
||||||
|
cache-file quoted_string;// deprecated
|
||||||
|
catalog-zones { zone string [ default-masters [ port integer ]
|
||||||
|
[ dscp integer ] { ( remote-servers | ipv4_address [ port
|
||||||
|
@@ -859,7 +860,7 @@ VIEW
|
||||||
|
integer | * ) ] [ dscp integer ];
|
||||||
|
alt-transfer-source-v6 ( ipv6_address | * ) [ port (
|
||||||
|
integer | * ) ] [ dscp integer ];
|
||||||
|
- auto-dnssec ( allow | maintain | off );
|
||||||
|
+ auto-dnssec ( allow | maintain | off );// deprecated
|
||||||
|
check-dup-records ( fail | warn | ignore );
|
||||||
|
check-integrity boolean;
|
||||||
|
check-mx ( fail | warn | ignore );
|
||||||
|
@@ -977,7 +978,7 @@ ZONE
|
||||||
|
] [ dscp integer ];
|
||||||
|
alt-transfer-source-v6 ( ipv6_address | * ) [ port ( integer |
|
||||||
|
* ) ] [ dscp integer ];
|
||||||
|
- auto-dnssec ( allow | maintain | off );
|
||||||
|
+ auto-dnssec ( allow | maintain | off );// deprecated
|
||||||
|
check-dup-records ( fail | warn | ignore );
|
||||||
|
check-integrity boolean;
|
||||||
|
check-mx ( fail | warn | ignore );
|
||||||
diff --git a/bin/named/server.c b/bin/named/server.c
|
diff --git a/bin/named/server.c b/bin/named/server.c
|
||||||
index f09b895..7af90d0 100644
|
index 20443ff8a9..78a21d62a2 100644
|
||||||
--- a/bin/named/server.c
|
--- a/bin/named/server.c
|
||||||
+++ b/bin/named/server.c
|
+++ b/bin/named/server.c
|
||||||
@@ -7792,6 +7792,7 @@ load_configuration(const char *filename, ns_server_t *server,
|
@@ -8542,6 +8542,7 @@ load_configuration(const char *filename, named_server_t *server,
|
||||||
configure_server_quota(maps, "tcp-clients", &server->tcpquota);
|
configure_server_quota(maps, "tcp-clients", &server->sctx->tcpquota);
|
||||||
configure_server_quota(maps, "recursive-clients",
|
configure_server_quota(maps, "recursive-clients",
|
||||||
&server->recursionquota);
|
&server->sctx->recursionquota);
|
||||||
+ configure_server_quota(maps, "update-quota", &server->updquota);
|
+ configure_server_quota(maps, "update-quota", &server->sctx->updquota);
|
||||||
|
|
||||||
if (server->recursionquota.max > 1000) {
|
max = isc_quota_getmax(&server->sctx->recursionquota);
|
||||||
int margin = ISC_MAX(100, ns_g_cpus + 1);
|
if (max > 1000) {
|
||||||
diff --git a/bin/tests/system/checkconf/good.conf b/bin/tests/system/checkconf/good.conf
|
diff --git a/bin/tests/system/checkconf/good.conf b/bin/tests/system/checkconf/good.conf
|
||||||
index 1359cf3..5d9b292 100644
|
index b1f7059acf..0ecdb68e95 100644
|
||||||
--- a/bin/tests/system/checkconf/good.conf
|
--- a/bin/tests/system/checkconf/good.conf
|
||||||
+++ b/bin/tests/system/checkconf/good.conf
|
+++ b/bin/tests/system/checkconf/good.conf
|
||||||
@@ -63,6 +63,7 @@ options {
|
@@ -75,6 +75,7 @@ options {
|
||||||
serial-queries 10;
|
recursive-clients 3000;
|
||||||
serial-query-rate 100;
|
serial-query-rate 100;
|
||||||
server-id none;
|
server-id none;
|
||||||
+ update-quota 200;
|
+ update-quota 200;
|
||||||
|
check-names primary warn;
|
||||||
|
check-names secondary ignore;
|
||||||
max-cache-size 20000000000000;
|
max-cache-size 20000000000000;
|
||||||
nta-lifetime 604800;
|
diff --git a/doc/arm/reference.rst b/doc/arm/reference.rst
|
||||||
nta-recheck 604800;
|
index 2603d60251..703663d0ba 100644
|
||||||
diff --git a/doc/arm/Bv9ARM-book.xml b/doc/arm/Bv9ARM-book.xml
|
--- a/doc/arm/reference.rst
|
||||||
index 9aca6d7..acf772b 100644
|
+++ b/doc/arm/reference.rst
|
||||||
--- a/doc/arm/Bv9ARM-book.xml
|
@@ -3151,6 +3151,11 @@ system.
|
||||||
+++ b/doc/arm/Bv9ARM-book.xml
|
value as ``tcp-keepalive-timeout``. This value can be updated at
|
||||||
@@ -8599,6 +8599,17 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
|
runtime by using ``rndc tcp-timeouts``.
|
||||||
</listitem>
|
|
||||||
</varlistentry>
|
|
||||||
|
|
||||||
+ <varlistentry>
|
+``update-quota``
|
||||||
+ <term><command>update-quota</command></term>
|
+ This is the maximum number of simultaneous DNS UPDATE messages that
|
||||||
+ <listitem>
|
+ the server will accept for updating local authoritiative zones or
|
||||||
+ <para>
|
+ forwarding to a primary server. The default is ``100``.
|
||||||
+ This is the maximum number of simultaneous DNS UPDATE messages that
|
|
||||||
+ the server will accept for updating local authoritiative zones or
|
|
||||||
+ forwarding to a primary server. The default is <userinput>100</userinput>.
|
|
||||||
+ </para>
|
|
||||||
+ </listitem>
|
|
||||||
+ </varlistentry>
|
|
||||||
+
|
+
|
||||||
</variablelist>
|
.. _intervals:
|
||||||
|
|
||||||
</section>
|
Periodic Task Intervals
|
||||||
diff --git a/doc/arm/options.grammar.xml b/doc/arm/options.grammar.xml
|
@@ -6840,7 +6845,7 @@ Name Server Statistics Counters
|
||||||
index 793ac0b..1d17ea8 100644
|
``UpdateQuota``
|
||||||
--- a/doc/arm/options.grammar.xml
|
This indicates the number of times a dynamic update or update
|
||||||
+++ b/doc/arm/options.grammar.xml
|
forwarding request was rejected because the number of pending
|
||||||
@@ -277,6 +277,7 @@
|
- requests exceeded the update quota.
|
||||||
<command>trust-anchor-telemetry</command> <replaceable>boolean</replaceable>; // experimental
|
+ requests exceeded ``update-quota``.
|
||||||
<command>try-tcp-refresh</command> <replaceable>boolean</replaceable>;
|
|
||||||
<command>update-check-ksk</command> <replaceable>boolean</replaceable>;
|
``RateDropped``
|
||||||
+ <command>update-quota</command> <replaceable>integer</replaceable>;
|
This indicates the number of responses dropped due to rate limits.
|
||||||
<command>use-alt-transfer-source</command> <replaceable>boolean</replaceable>;
|
diff --git a/doc/man/named.conf.5in b/doc/man/named.conf.5in
|
||||||
<command>use-v4-udp-ports</command> { <replaceable>portrange</replaceable>; ... };
|
index 4c46f47592..c87afa2881 100644
|
||||||
<command>use-v6-udp-ports</command> { <replaceable>portrange</replaceable>; ... };
|
--- a/doc/man/named.conf.5in
|
||||||
|
+++ b/doc/man/named.conf.5in
|
||||||
|
@@ -231,7 +231,7 @@ options {
|
||||||
|
answer\-cookie boolean;
|
||||||
|
attach\-cache string;
|
||||||
|
auth\-nxdomain boolean; // default changed
|
||||||
|
- auto\-dnssec ( allow | maintain | off );
|
||||||
|
+ auto\-dnssec ( allow | maintain | off );// deprecated
|
||||||
|
automatic\-interface\-scan boolean;
|
||||||
|
avoid\-v4\-udp\-ports { portrange; ... };
|
||||||
|
avoid\-v6\-udp\-ports { portrange; ... };
|
||||||
|
@@ -498,6 +498,7 @@ options {
|
||||||
|
trust\-anchor\-telemetry boolean; // experimental
|
||||||
|
try\-tcp\-refresh boolean;
|
||||||
|
update\-check\-ksk boolean;
|
||||||
|
+ update\-quota integer;
|
||||||
|
use\-alt\-transfer\-source boolean;
|
||||||
|
use\-v4\-udp\-ports { portrange; ... };
|
||||||
|
use\-v6\-udp\-ports { portrange; ... };
|
||||||
|
@@ -668,7 +669,7 @@ view string [ class ] {
|
||||||
|
* ) ] [ dscp integer ];
|
||||||
|
attach\-cache string;
|
||||||
|
auth\-nxdomain boolean; // default changed
|
||||||
|
- auto\-dnssec ( allow | maintain | off );
|
||||||
|
+ auto\-dnssec ( allow | maintain | off );// deprecated
|
||||||
|
cache\-file quoted_string;// deprecated
|
||||||
|
catalog\-zones { zone string [ default\-masters [ port integer ]
|
||||||
|
[ dscp integer ] { ( remote\-servers | ipv4_address [ port
|
||||||
|
@@ -943,7 +944,7 @@ view string [ class ] {
|
||||||
|
integer | * ) ] [ dscp integer ];
|
||||||
|
alt\-transfer\-source\-v6 ( ipv6_address | * ) [ port (
|
||||||
|
integer | * ) ] [ dscp integer ];
|
||||||
|
- auto\-dnssec ( allow | maintain | off );
|
||||||
|
+ auto\-dnssec ( allow | maintain | off );// deprecated
|
||||||
|
check\-dup\-records ( fail | warn | ignore );
|
||||||
|
check\-integrity boolean;
|
||||||
|
check\-mx ( fail | warn | ignore );
|
||||||
|
@@ -1065,7 +1066,7 @@ zone string [ class ] {
|
||||||
|
] [ dscp integer ];
|
||||||
|
alt\-transfer\-source\-v6 ( ipv6_address | * ) [ port ( integer |
|
||||||
|
* ) ] [ dscp integer ];
|
||||||
|
- auto\-dnssec ( allow | maintain | off );
|
||||||
|
+ auto\-dnssec ( allow | maintain | off );// deprecated
|
||||||
|
check\-dup\-records ( fail | warn | ignore );
|
||||||
|
check\-integrity boolean;
|
||||||
|
check\-mx ( fail | warn | ignore );
|
||||||
|
diff --git a/doc/misc/master.zoneopt.rst b/doc/misc/master.zoneopt.rst
|
||||||
|
index 8fc7e1b4f0..346d59813e 100644
|
||||||
|
--- a/doc/misc/master.zoneopt.rst
|
||||||
|
+++ b/doc/misc/master.zoneopt.rst
|
||||||
|
@@ -20,7 +20,7 @@
|
||||||
|
also-notify [ port <integer> ] [ dscp <integer> ] { ( <remote-servers> | <ipv4_address> [ port <integer> ] | <ipv6_address> [ port <integer> ] ) [ key <string> ]; ... };
|
||||||
|
alt-transfer-source ( <ipv4_address> | * ) [ port ( <integer> | * ) ] [ dscp <integer> ];
|
||||||
|
alt-transfer-source-v6 ( <ipv6_address> | * ) [ port ( <integer> | * ) ] [ dscp <integer> ];
|
||||||
|
- auto-dnssec ( allow | maintain | off );
|
||||||
|
+ auto-dnssec ( allow | maintain | off ); // deprecated
|
||||||
|
check-dup-records ( fail | warn | ignore );
|
||||||
|
check-integrity <boolean>;
|
||||||
|
check-mx ( fail | warn | ignore );
|
||||||
diff --git a/doc/misc/options b/doc/misc/options
|
diff --git a/doc/misc/options b/doc/misc/options
|
||||||
index fde93c7..e6d6ba6 100644
|
index f57399499a..0dbcf101e1 100644
|
||||||
--- a/doc/misc/options
|
--- a/doc/misc/options
|
||||||
+++ b/doc/misc/options
|
+++ b/doc/misc/options
|
||||||
@@ -357,6 +357,7 @@ options {
|
@@ -404,6 +404,7 @@ options {
|
||||||
trust-anchor-telemetry <boolean>; // experimental
|
trust-anchor-telemetry <boolean>; // experimental
|
||||||
try-tcp-refresh <boolean>;
|
try-tcp-refresh <boolean>;
|
||||||
update-check-ksk <boolean>;
|
update-check-ksk <boolean>;
|
||||||
+ update-quota <integer>;
|
+ update-quota <integer>;
|
||||||
use-alt-transfer-source <boolean>;
|
use-alt-transfer-source <boolean>;
|
||||||
use-id-pool <boolean>; // obsolete
|
use-id-pool <boolean>; // ancient
|
||||||
use-ixfr <boolean>; // obsolete
|
use-ixfr <boolean>; // obsolete
|
||||||
|
diff --git a/doc/misc/options.active b/doc/misc/options.active
|
||||||
|
index 5fc1ab29f4..eb75a86eae 100644
|
||||||
|
--- a/doc/misc/options.active
|
||||||
|
+++ b/doc/misc/options.active
|
||||||
|
@@ -363,6 +363,7 @@ options {
|
||||||
|
trust-anchor-telemetry <boolean>; // experimental
|
||||||
|
try-tcp-refresh <boolean>;
|
||||||
|
update-check-ksk <boolean>;
|
||||||
|
+ update-quota <integer>;
|
||||||
|
use-alt-transfer-source <boolean>;
|
||||||
|
use-v4-udp-ports { <portrange>; ... };
|
||||||
|
use-v6-udp-ports { <portrange>; ... };
|
||||||
|
diff --git a/doc/misc/options.grammar.rst b/doc/misc/options.grammar.rst
|
||||||
|
index 438072c95c..beef35341a 100644
|
||||||
|
--- a/doc/misc/options.grammar.rst
|
||||||
|
+++ b/doc/misc/options.grammar.rst
|
||||||
|
@@ -33,7 +33,7 @@
|
||||||
|
answer-cookie <boolean>;
|
||||||
|
attach-cache <string>;
|
||||||
|
auth-nxdomain <boolean>; // default changed
|
||||||
|
- auto-dnssec ( allow | maintain | off );
|
||||||
|
+ auto-dnssec ( allow | maintain | off ); // deprecated
|
||||||
|
automatic-interface-scan <boolean>;
|
||||||
|
avoid-v4-udp-ports { <portrange>; ... };
|
||||||
|
avoid-v6-udp-ports { <portrange>; ... };
|
||||||
|
@@ -300,6 +300,7 @@
|
||||||
|
trust-anchor-telemetry <boolean>; // experimental
|
||||||
|
try-tcp-refresh <boolean>;
|
||||||
|
update-check-ksk <boolean>;
|
||||||
|
+ update-quota <integer>;
|
||||||
|
use-alt-transfer-source <boolean>;
|
||||||
|
use-v4-udp-ports { <portrange>; ... };
|
||||||
|
use-v6-udp-ports { <portrange>; ... };
|
||||||
|
diff --git a/doc/misc/slave.zoneopt.rst b/doc/misc/slave.zoneopt.rst
|
||||||
|
index cc72dcbf67..468a7f4d9a 100644
|
||||||
|
--- a/doc/misc/slave.zoneopt.rst
|
||||||
|
+++ b/doc/misc/slave.zoneopt.rst
|
||||||
|
@@ -21,7 +21,7 @@
|
||||||
|
also-notify [ port <integer> ] [ dscp <integer> ] { ( <remote-servers> | <ipv4_address> [ port <integer> ] | <ipv6_address> [ port <integer> ] ) [ key <string> ]; ... };
|
||||||
|
alt-transfer-source ( <ipv4_address> | * ) [ port ( <integer> | * ) ] [ dscp <integer> ];
|
||||||
|
alt-transfer-source-v6 ( <ipv6_address> | * ) [ port ( <integer> | * ) ] [ dscp <integer> ];
|
||||||
|
- auto-dnssec ( allow | maintain | off );
|
||||||
|
+ auto-dnssec ( allow | maintain | off ); // deprecated
|
||||||
|
check-names ( fail | warn | ignore );
|
||||||
|
database <string>;
|
||||||
|
dialup ( notify | notify-passive | passive | refresh | <boolean> );
|
||||||
diff --git a/lib/isccfg/namedconf.c b/lib/isccfg/namedconf.c
|
diff --git a/lib/isccfg/namedconf.c b/lib/isccfg/namedconf.c
|
||||||
index b562f95..667111c 100644
|
index 45de0196bf..6e63d86816 100644
|
||||||
--- a/lib/isccfg/namedconf.c
|
--- a/lib/isccfg/namedconf.c
|
||||||
+++ b/lib/isccfg/namedconf.c
|
+++ b/lib/isccfg/namedconf.c
|
||||||
@@ -1136,6 +1136,7 @@ options_clauses[] = {
|
@@ -1267,6 +1267,7 @@ static cfg_clausedef_t options_clauses[] = {
|
||||||
{ "transfers-out", &cfg_type_uint32, 0 },
|
{ "transfers-out", &cfg_type_uint32, 0 },
|
||||||
{ "transfers-per-ns", &cfg_type_uint32, 0 },
|
{ "transfers-per-ns", &cfg_type_uint32, 0 },
|
||||||
{ "treat-cr-as-space", &cfg_type_boolean, CFG_CLAUSEFLAG_OBSOLETE },
|
{ "treat-cr-as-space", &cfg_type_boolean, CFG_CLAUSEFLAG_ANCIENT },
|
||||||
+ { "update-quota", &cfg_type_uint32, 0 },
|
+ { "update-quota", &cfg_type_uint32, 0 },
|
||||||
{ "use-id-pool", &cfg_type_boolean, CFG_CLAUSEFLAG_OBSOLETE },
|
{ "use-id-pool", &cfg_type_boolean, CFG_CLAUSEFLAG_ANCIENT },
|
||||||
{ "use-ixfr", &cfg_type_boolean, CFG_CLAUSEFLAG_OBSOLETE },
|
{ "use-ixfr", &cfg_type_boolean, CFG_CLAUSEFLAG_OBSOLETE },
|
||||||
{ "use-v4-udp-ports", &cfg_type_bracketed_portlist, 0 },
|
{ "use-v4-udp-ports", &cfg_type_bracketed_portlist, 0 },
|
||||||
--
|
--
|
||||||
2.39.2
|
2.39.1
|
||||||
|
|
||||||
|
|||||||
@ -1,4 +1,4 @@
|
|||||||
From cba333b262b7ee0034a66cc93cf27f6c4918eea2 Mon Sep 17 00:00:00 2001
|
From 93b8bd39145566053ad8b22cef597146e9175ea4 Mon Sep 17 00:00:00 2001
|
||||||
From: Evan Hunt <each@isc.org>
|
From: Evan Hunt <each@isc.org>
|
||||||
Date: Tue, 8 Nov 2022 17:32:41 -0800
|
Date: Tue, 8 Nov 2022 17:32:41 -0800
|
||||||
Subject: [PATCH] move update ACL and update-policy checks before quota
|
Subject: [PATCH] move update ACL and update-policy checks before quota
|
||||||
@ -15,29 +15,32 @@ prerequisite checks, not that it must happen exactly then.)
|
|||||||
|
|
||||||
(cherry picked from commit 964f559edb5036880b8e463b8f190b9007ee055d)
|
(cherry picked from commit 964f559edb5036880b8e463b8f190b9007ee055d)
|
||||||
---
|
---
|
||||||
bin/named/update.c | 440 ++++++++++++++++++++++++++++++---------------
|
lib/ns/update.c | 335 ++++++++++++++++++++++++++----------------------
|
||||||
1 file changed, 298 insertions(+), 142 deletions(-)
|
1 file changed, 181 insertions(+), 154 deletions(-)
|
||||||
|
|
||||||
diff --git a/bin/named/update.c b/bin/named/update.c
|
diff --git a/lib/ns/update.c b/lib/ns/update.c
|
||||||
index 8853ee7..4d1fe78 100644
|
index 9a8c309..036184b 100644
|
||||||
--- a/bin/named/update.c
|
--- a/lib/ns/update.c
|
||||||
+++ b/bin/named/update.c
|
+++ b/lib/ns/update.c
|
||||||
@@ -251,6 +251,9 @@ static void updatedone_action(isc_task_t *task, isc_event_t *event);
|
@@ -261,6 +261,9 @@ static void
|
||||||
static isc_result_t send_forward_event(ns_client_t *client, dns_zone_t *zone);
|
forward_done(isc_task_t *task, isc_event_t *event);
|
||||||
static void forward_done(isc_task_t *task, isc_event_t *event);
|
static isc_result_t
|
||||||
static isc_result_t add_rr_prepare_action(void *data, rr_t *rr);
|
add_rr_prepare_action(void *data, rr_t *rr);
|
||||||
+static isc_result_t
|
+static isc_result_t
|
||||||
+rr_exists(dns_db_t *db, dns_dbversion_t *ver, dns_name_t *name,
|
+rr_exists(dns_db_t *db, dns_dbversion_t *ver, dns_name_t *name,
|
||||||
+ const dns_rdata_t *rdata, bool *flag);
|
+ const dns_rdata_t *rdata, bool *flag);
|
||||||
|
|
||||||
/**************************************************************************/
|
/**************************************************************************/
|
||||||
|
|
||||||
@@ -328,23 +331,24 @@ checkqueryacl(ns_client_t *client, dns_acl_t *queryacl, dns_name_t *zonename,
|
@@ -333,25 +336,26 @@ inc_stats(ns_client_t *client, dns_zone_t *zone, isc_statscounter_t counter) {
|
||||||
{
|
static isc_result_t
|
||||||
|
checkqueryacl(ns_client_t *client, dns_acl_t *queryacl, dns_name_t *zonename,
|
||||||
|
dns_acl_t *updateacl, dns_ssutable_t *ssutable) {
|
||||||
|
+ isc_result_t result;
|
||||||
char namebuf[DNS_NAME_FORMATSIZE];
|
char namebuf[DNS_NAME_FORMATSIZE];
|
||||||
char classbuf[DNS_RDATACLASS_FORMATSIZE];
|
char classbuf[DNS_RDATACLASS_FORMATSIZE];
|
||||||
- int level;
|
- int level;
|
||||||
isc_result_t result;
|
- isc_result_t result;
|
||||||
+ bool update_possible =
|
+ bool update_possible =
|
||||||
+ ((updateacl != NULL && !dns_acl_isnone(updateacl)) ||
|
+ ((updateacl != NULL && !dns_acl_isnone(updateacl)) ||
|
||||||
+ ssutable != NULL);
|
+ ssutable != NULL);
|
||||||
@ -50,8 +53,8 @@ index 8853ee7..4d1fe78 100644
|
|||||||
dns_rdataclass_format(client->view->rdclass, classbuf,
|
dns_rdataclass_format(client->view->rdclass, classbuf,
|
||||||
sizeof(classbuf));
|
sizeof(classbuf));
|
||||||
|
|
||||||
- level = (updateacl == NULL && ssutable == NULL) ?
|
- level = (updateacl == NULL && ssutable == NULL) ? ISC_LOG_INFO
|
||||||
- ISC_LOG_INFO : ISC_LOG_ERROR;
|
- : ISC_LOG_ERROR;
|
||||||
-
|
-
|
||||||
ns_client_log(client, NS_LOGCATEGORY_UPDATE_SECURITY,
|
ns_client_log(client, NS_LOGCATEGORY_UPDATE_SECURITY,
|
||||||
NS_LOGMODULE_UPDATE, level,
|
NS_LOGMODULE_UPDATE, level,
|
||||||
@ -62,13 +65,14 @@ index 8853ee7..4d1fe78 100644
|
|||||||
dns_name_format(zonename, namebuf, sizeof(namebuf));
|
dns_name_format(zonename, namebuf, sizeof(namebuf));
|
||||||
dns_rdataclass_format(client->view->rdclass, classbuf,
|
dns_rdataclass_format(client->view->rdclass, classbuf,
|
||||||
sizeof(classbuf));
|
sizeof(classbuf));
|
||||||
@@ -1525,6 +1529,277 @@ send_update_event(ns_client_t *client, dns_zone_t *zone) {
|
@@ -1543,6 +1547,156 @@ send_update_event(ns_client_t *client, dns_zone_t *zone) {
|
||||||
|
isc_result_t result = ISC_R_SUCCESS;
|
||||||
update_event_t *event = NULL;
|
update_event_t *event = NULL;
|
||||||
isc_task_t *zonetask = NULL;
|
isc_task_t *zonetask = NULL;
|
||||||
ns_client_t *evclient;
|
|
||||||
+#if 1
|
|
||||||
+ dns_ssutable_t *ssutable = NULL;
|
+ dns_ssutable_t *ssutable = NULL;
|
||||||
+ dns_message_t *request = client->message;
|
+ dns_message_t *request = client->message;
|
||||||
|
+ dns_aclenv_t *env =
|
||||||
|
+ ns_interfacemgr_getaclenv(client->manager->interface->mgr);
|
||||||
+ dns_rdataclass_t zoneclass;
|
+ dns_rdataclass_t zoneclass;
|
||||||
+ dns_rdatatype_t covers;
|
+ dns_rdatatype_t covers;
|
||||||
+ dns_name_t *zonename = NULL;
|
+ dns_name_t *zonename = NULL;
|
||||||
@ -93,128 +97,8 @@ index 8853ee7..4d1fe78 100644
|
|||||||
+ /*
|
+ /*
|
||||||
+ * Check requestor's permissions.
|
+ * Check requestor's permissions.
|
||||||
+ */
|
+ */
|
||||||
+ if (ssutable == NULL)
|
|
||||||
+ CHECK(checkupdateacl(client, dns_zone_getupdateacl(zone),
|
|
||||||
+ "update", zonename, false, false));
|
|
||||||
+ else if (client->signer == NULL && !TCPCLIENT(client))
|
|
||||||
+ CHECK(checkupdateacl(client, NULL, "update", zonename,
|
|
||||||
+ false, true));
|
|
||||||
+
|
|
||||||
+ if (dns_zone_getupdatedisabled(zone))
|
|
||||||
+ FAILC(DNS_R_REFUSED, "dynamic update temporarily disabled "
|
|
||||||
+ "because the zone is frozen. Use "
|
|
||||||
+ "'rndc thaw' to re-enable updates.");
|
|
||||||
+
|
|
||||||
+ /*
|
|
||||||
+ * Perform the Update Section Prescan.
|
|
||||||
+ */
|
|
||||||
+
|
|
||||||
+ for (result = dns_message_firstname(request, DNS_SECTION_UPDATE);
|
|
||||||
+ result == ISC_R_SUCCESS;
|
|
||||||
+ result = dns_message_nextname(request, DNS_SECTION_UPDATE))
|
|
||||||
+ {
|
|
||||||
+ dns_name_t *name = NULL;
|
|
||||||
+ dns_rdata_t rdata = DNS_RDATA_INIT;
|
|
||||||
+ dns_ttl_t ttl;
|
|
||||||
+ dns_rdataclass_t update_class;
|
|
||||||
+ get_current_rr(request, DNS_SECTION_UPDATE, zoneclass,
|
|
||||||
+ &name, &rdata, &covers, &ttl, &update_class);
|
|
||||||
+
|
|
||||||
+ if (! dns_name_issubdomain(name, zonename))
|
|
||||||
+ FAILC(DNS_R_NOTZONE,
|
|
||||||
+ "update RR is outside zone");
|
|
||||||
+ if (update_class == zoneclass) {
|
|
||||||
+ /*
|
|
||||||
+ * Check for meta-RRs. The RFC2136 pseudocode says
|
|
||||||
+ * check for ANY|AXFR|MAILA|MAILB, but the text adds
|
|
||||||
+ * "or any other QUERY metatype"
|
|
||||||
+ */
|
|
||||||
+ if (dns_rdatatype_ismeta(rdata.type)) {
|
|
||||||
+ FAILC(DNS_R_FORMERR,
|
|
||||||
+ "meta-RR in update");
|
|
||||||
+ }
|
|
||||||
+ result = dns_zone_checknames(zone, name, &rdata);
|
|
||||||
+ if (result != ISC_R_SUCCESS)
|
|
||||||
+ FAIL(DNS_R_REFUSED);
|
|
||||||
+ } else if (update_class == dns_rdataclass_any) {
|
|
||||||
+ if (ttl != 0 || rdata.length != 0 ||
|
|
||||||
+ (dns_rdatatype_ismeta(rdata.type) &&
|
|
||||||
+ rdata.type != dns_rdatatype_any))
|
|
||||||
+ FAILC(DNS_R_FORMERR,
|
|
||||||
+ "meta-RR in update");
|
|
||||||
+ } else if (update_class == dns_rdataclass_none) {
|
|
||||||
+ if (ttl != 0 ||
|
|
||||||
+ dns_rdatatype_ismeta(rdata.type))
|
|
||||||
+ FAILC(DNS_R_FORMERR,
|
|
||||||
+ "meta-RR in update");
|
|
||||||
+ } else {
|
|
||||||
+ update_log(client, zone, ISC_LOG_WARNING,
|
|
||||||
+ "update RR has incorrect class %d",
|
|
||||||
+ update_class);
|
|
||||||
+ FAIL(DNS_R_FORMERR);
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+ /*
|
|
||||||
+ * draft-ietf-dnsind-simple-secure-update-01 says
|
|
||||||
+ * "Unlike traditional dynamic update, the client
|
|
||||||
+ * is forbidden from updating NSEC records."
|
|
||||||
+ */
|
|
||||||
+ if (rdata.type == dns_rdatatype_nsec3) {
|
|
||||||
+ FAILC(DNS_R_REFUSED,
|
|
||||||
+ "explicit NSEC3 updates are not allowed "
|
|
||||||
+ "in secure zones");
|
|
||||||
+ } else if (rdata.type == dns_rdatatype_nsec) {
|
|
||||||
+ FAILC(DNS_R_REFUSED,
|
|
||||||
+ "explicit NSEC updates are not allowed "
|
|
||||||
+ "in secure zones");
|
|
||||||
+ } else if (rdata.type == dns_rdatatype_rrsig &&
|
|
||||||
+ !dns_name_equal(name, zonename)) {
|
|
||||||
+ FAILC(DNS_R_REFUSED,
|
|
||||||
+ "explicit RRSIG updates are currently "
|
|
||||||
+ "not supported in secure zones except "
|
|
||||||
+ "at the apex");
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+ if (ssutable != NULL) {
|
|
||||||
+ isc_netaddr_t netaddr;
|
|
||||||
+ dst_key_t *tsigkey = NULL;
|
|
||||||
+ isc_netaddr_fromsockaddr(&netaddr, &client->peeraddr);
|
|
||||||
+
|
|
||||||
+ if (client->message->tsigkey != NULL)
|
|
||||||
+ tsigkey = client->message->tsigkey->key;
|
|
||||||
+
|
|
||||||
+ if (rdata.type != dns_rdatatype_any) {
|
|
||||||
+ if (!dns_ssutable_checkrules2
|
|
||||||
+ (ssutable, client->signer, name, &netaddr,
|
|
||||||
+ TCPCLIENT(client),
|
|
||||||
+ &ns_g_server->aclenv,
|
|
||||||
+ rdata.type, tsigkey))
|
|
||||||
+ {
|
|
||||||
+ FAILC(DNS_R_REFUSED,
|
|
||||||
+ "rejected by secure update");
|
|
||||||
+ }
|
|
||||||
+ } else {
|
|
||||||
+ if (!ssu_checkall(db, ver, name, ssutable,
|
|
||||||
+ client->signer,
|
|
||||||
+ &netaddr,
|
|
||||||
+ TCPCLIENT(client),
|
|
||||||
+ tsigkey))
|
|
||||||
+ {
|
|
||||||
+ FAILC(DNS_R_REFUSED,
|
|
||||||
+ "rejected by secure update");
|
|
||||||
+ }
|
|
||||||
+ }
|
|
||||||
+ }
|
|
||||||
+ }
|
|
||||||
+ if (result != ISC_R_NOMORE)
|
|
||||||
+ FAIL(result);
|
|
||||||
+
|
|
||||||
+ update_log(client, zone, LOGLEVEL_DEBUG,
|
|
||||||
+ "update section prescan OK");
|
|
||||||
+#if 0
|
|
||||||
+ if (ssutable == NULL) {
|
+ if (ssutable == NULL) {
|
||||||
+ CHECK(checkupdateacl(client, dns_zone_getupdateacl(zone),
|
+ CHECK(checkupdateacl(client, dns_zone_getupdateacl(zone),
|
||||||
+ // zonename
|
|
||||||
+ "update", dns_zone_getorigin(zone), false,
|
+ "update", dns_zone_getorigin(zone), false,
|
||||||
+ false));
|
+ false));
|
||||||
+ } else if (client->signer == NULL && !TCPCLIENT(client)) {
|
+ } else if (client->signer == NULL && !TCPCLIENT(client)) {
|
||||||
@ -335,15 +219,25 @@ index 8853ee7..4d1fe78 100644
|
|||||||
+ }
|
+ }
|
||||||
+
|
+
|
||||||
+ update_log(client, zone, LOGLEVEL_DEBUG, "update section prescan OK");
|
+ update_log(client, zone, LOGLEVEL_DEBUG, "update section prescan OK");
|
||||||
+#endif
|
|
||||||
+#endif
|
|
||||||
|
|
||||||
result = isc_quota_attach(&ns_g_server->updquota,
|
result = isc_quota_attach(&client->manager->sctx->updquota,
|
||||||
&(isc_quota_t *){ NULL });
|
&(isc_quota_t *){ NULL });
|
||||||
@@ -1558,6 +1833,15 @@ send_update_event(ns_client_t *client, dns_zone_t *zone) {
|
@@ -1552,9 +1706,7 @@ send_update_event(ns_client_t *client, dns_zone_t *zone) {
|
||||||
failure:
|
isc_result_totext(result));
|
||||||
if (event != NULL)
|
ns_stats_increment(client->manager->sctx->nsstats,
|
||||||
isc_event_free(ISC_EVENT_PTR(&event));
|
ns_statscounter_updatequota);
|
||||||
|
- ns_client_drop(client, result);
|
||||||
|
- isc_nmhandle_detach(&client->reqhandle);
|
||||||
|
- return (DNS_R_DROP);
|
||||||
|
+ CHECK(DNS_R_DROP);
|
||||||
|
}
|
||||||
|
|
||||||
|
event = (update_event_t *)isc_event_allocate(
|
||||||
|
@@ -1571,6 +1723,16 @@ send_update_event(ns_client_t *client, dns_zone_t *zone) {
|
||||||
|
dns_zone_gettask(zone, &zonetask);
|
||||||
|
isc_task_send(zonetask, ISC_EVENT_PTR(&event));
|
||||||
|
|
||||||
|
+failure:
|
||||||
+ if (db != NULL) {
|
+ if (db != NULL) {
|
||||||
+ dns_db_closeversion(db, &ver, false);
|
+ dns_db_closeversion(db, &ver, false);
|
||||||
+ dns_db_detach(&db);
|
+ dns_db_detach(&db);
|
||||||
@ -356,25 +250,26 @@ index 8853ee7..4d1fe78 100644
|
|||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1644,9 +1928,6 @@ ns_update_start(ns_client_t *client, isc_result_t sigresult) {
|
@@ -1671,9 +1833,6 @@ ns_update_start(ns_client_t *client, isc_nmhandle_t *handle,
|
||||||
CHECK(send_update_event(client, zone));
|
|
||||||
break;
|
break;
|
||||||
case dns_zone_slave:
|
case dns_zone_secondary:
|
||||||
|
case dns_zone_mirror:
|
||||||
- CHECK(checkupdateacl(client, dns_zone_getforwardacl(zone),
|
- CHECK(checkupdateacl(client, dns_zone_getforwardacl(zone),
|
||||||
- "update forwarding", zonename, true,
|
- "update forwarding", zonename, true,
|
||||||
- false));
|
- false));
|
||||||
CHECK(send_forward_event(client, zone));
|
CHECK(send_forward_event(client, zone));
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
@@ -1656,7 +1937,6 @@ ns_update_start(ns_client_t *client, isc_result_t sigresult) {
|
@@ -1685,8 +1844,6 @@ ns_update_start(ns_client_t *client, isc_nmhandle_t *handle,
|
||||||
|
|
||||||
failure:
|
failure:
|
||||||
if (result == DNS_R_REFUSED) {
|
if (result == DNS_R_REFUSED) {
|
||||||
- INSIST(dns_zone_gettype(zone) == dns_zone_slave);
|
- INSIST(dns_zone_gettype(zone) == dns_zone_secondary ||
|
||||||
inc_stats(zone, dns_nsstatscounter_updaterej);
|
- dns_zone_gettype(zone) == dns_zone_mirror);
|
||||||
|
inc_stats(client, zone, ns_statscounter_updaterej);
|
||||||
}
|
}
|
||||||
/*
|
|
||||||
@@ -2520,7 +2800,7 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
@@ -2578,7 +2735,7 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
||||||
dns_rdatatype_t covers;
|
dns_rdatatype_t covers;
|
||||||
dns_message_t *request = client->message;
|
dns_message_t *request = client->message;
|
||||||
dns_rdataclass_t zoneclass;
|
dns_rdataclass_t zoneclass;
|
||||||
@ -383,7 +278,16 @@ index 8853ee7..4d1fe78 100644
|
|||||||
dns_ssutable_t *ssutable = NULL;
|
dns_ssutable_t *ssutable = NULL;
|
||||||
dns_fixedname_t tmpnamefixed;
|
dns_fixedname_t tmpnamefixed;
|
||||||
dns_name_t *tmpname = NULL;
|
dns_name_t *tmpname = NULL;
|
||||||
@@ -2542,14 +2822,7 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
@@ -2590,8 +2747,6 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
||||||
|
dns_ttl_t maxttl = 0;
|
||||||
|
uint32_t maxrecords;
|
||||||
|
uint64_t records;
|
||||||
|
- dns_aclenv_t *env =
|
||||||
|
- ns_interfacemgr_getaclenv(client->manager->interface->mgr);
|
||||||
|
|
||||||
|
INSIST(event->ev_type == DNS_EVENT_UPDATE);
|
||||||
|
|
||||||
|
@@ -2602,14 +2757,7 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
||||||
zonename = dns_db_origin(db);
|
zonename = dns_db_origin(db);
|
||||||
zoneclass = dns_db_class(db);
|
zoneclass = dns_db_class(db);
|
||||||
dns_zone_getssutable(zone, &ssutable);
|
dns_zone_getssutable(zone, &ssutable);
|
||||||
@ -399,25 +303,27 @@ index 8853ee7..4d1fe78 100644
|
|||||||
|
|
||||||
/*
|
/*
|
||||||
* Get old and new versions now that queryacl has been checked.
|
* Get old and new versions now that queryacl has been checked.
|
||||||
@@ -2673,134 +2946,10 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
@@ -2745,135 +2893,10 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
||||||
update_log(client, zone, LOGLEVEL_DEBUG,
|
|
||||||
"prerequisites are OK");
|
update_log(client, zone, LOGLEVEL_DEBUG, "prerequisites are OK");
|
||||||
|
|
||||||
- /*
|
- /*
|
||||||
- * Check Requestor's Permissions. It seems a bit silly to do this
|
- * Check Requestor's Permissions. It seems a bit silly to do this
|
||||||
- * only after prerequisite testing, but that is what RFC2136 says.
|
- * only after prerequisite testing, but that is what RFC2136 says.
|
||||||
- */
|
- */
|
||||||
- if (ssutable == NULL)
|
- if (ssutable == NULL) {
|
||||||
- CHECK(checkupdateacl(client, dns_zone_getupdateacl(zone),
|
- CHECK(checkupdateacl(client, dns_zone_getupdateacl(zone),
|
||||||
- "update", zonename, false, false));
|
- "update", zonename, false, false));
|
||||||
- else if (client->signer == NULL && !TCPCLIENT(client))
|
- } else if (client->signer == NULL && !TCPCLIENT(client)) {
|
||||||
- CHECK(checkupdateacl(client, NULL, "update", zonename,
|
- CHECK(checkupdateacl(client, NULL, "update", zonename, false,
|
||||||
- false, true));
|
- true));
|
||||||
|
- }
|
||||||
-
|
-
|
||||||
- if (dns_zone_getupdatedisabled(zone))
|
- if (dns_zone_getupdatedisabled(zone)) {
|
||||||
- FAILC(DNS_R_REFUSED, "dynamic update temporarily disabled "
|
- FAILC(DNS_R_REFUSED, "dynamic update temporarily disabled "
|
||||||
- "because the zone is frozen. Use "
|
- "because the zone is frozen. Use "
|
||||||
- "'rndc thaw' to re-enable updates.");
|
- "'rndc thaw' to re-enable updates.");
|
||||||
|
- }
|
||||||
-
|
-
|
||||||
- /*
|
- /*
|
||||||
- * Perform the Update Section Prescan.
|
- * Perform the Update Section Prescan.
|
||||||
@ -431,12 +337,12 @@ index 8853ee7..4d1fe78 100644
|
|||||||
- dns_rdata_t rdata = DNS_RDATA_INIT;
|
- dns_rdata_t rdata = DNS_RDATA_INIT;
|
||||||
- dns_ttl_t ttl;
|
- dns_ttl_t ttl;
|
||||||
- dns_rdataclass_t update_class;
|
- dns_rdataclass_t update_class;
|
||||||
- get_current_rr(request, DNS_SECTION_UPDATE, zoneclass,
|
- get_current_rr(request, DNS_SECTION_UPDATE, zoneclass, &name,
|
||||||
- &name, &rdata, &covers, &ttl, &update_class);
|
- &rdata, &covers, &ttl, &update_class);
|
||||||
-
|
-
|
||||||
- if (! dns_name_issubdomain(name, zonename))
|
- if (!dns_name_issubdomain(name, zonename)) {
|
||||||
- FAILC(DNS_R_NOTZONE,
|
- FAILC(DNS_R_NOTZONE, "update RR is outside zone");
|
||||||
- "update RR is outside zone");
|
- }
|
||||||
- if (update_class == zoneclass) {
|
- if (update_class == zoneclass) {
|
||||||
- /*
|
- /*
|
||||||
- * Check for meta-RRs. The RFC2136 pseudocode says
|
- * Check for meta-RRs. The RFC2136 pseudocode says
|
||||||
@ -444,23 +350,23 @@ index 8853ee7..4d1fe78 100644
|
|||||||
- * "or any other QUERY metatype"
|
- * "or any other QUERY metatype"
|
||||||
- */
|
- */
|
||||||
- if (dns_rdatatype_ismeta(rdata.type)) {
|
- if (dns_rdatatype_ismeta(rdata.type)) {
|
||||||
- FAILC(DNS_R_FORMERR,
|
- FAILC(DNS_R_FORMERR, "meta-RR in update");
|
||||||
- "meta-RR in update");
|
|
||||||
- }
|
- }
|
||||||
- result = dns_zone_checknames(zone, name, &rdata);
|
- result = dns_zone_checknames(zone, name, &rdata);
|
||||||
- if (result != ISC_R_SUCCESS)
|
- if (result != ISC_R_SUCCESS) {
|
||||||
- FAIL(DNS_R_REFUSED);
|
- FAIL(DNS_R_REFUSED);
|
||||||
|
- }
|
||||||
- } else if (update_class == dns_rdataclass_any) {
|
- } else if (update_class == dns_rdataclass_any) {
|
||||||
- if (ttl != 0 || rdata.length != 0 ||
|
- if (ttl != 0 || rdata.length != 0 ||
|
||||||
- (dns_rdatatype_ismeta(rdata.type) &&
|
- (dns_rdatatype_ismeta(rdata.type) &&
|
||||||
- rdata.type != dns_rdatatype_any))
|
- rdata.type != dns_rdatatype_any))
|
||||||
- FAILC(DNS_R_FORMERR,
|
- {
|
||||||
- "meta-RR in update");
|
- FAILC(DNS_R_FORMERR, "meta-RR in update");
|
||||||
|
- }
|
||||||
- } else if (update_class == dns_rdataclass_none) {
|
- } else if (update_class == dns_rdataclass_none) {
|
||||||
- if (ttl != 0 ||
|
- if (ttl != 0 || dns_rdatatype_ismeta(rdata.type)) {
|
||||||
- dns_rdatatype_ismeta(rdata.type))
|
- FAILC(DNS_R_FORMERR, "meta-RR in update");
|
||||||
- FAILC(DNS_R_FORMERR,
|
- }
|
||||||
- "meta-RR in update");
|
|
||||||
- } else {
|
- } else {
|
||||||
- update_log(client, zone, ISC_LOG_WARNING,
|
- update_log(client, zone, ISC_LOG_WARNING,
|
||||||
- "update RR has incorrect class %d",
|
- "update RR has incorrect class %d",
|
||||||
@ -474,19 +380,20 @@ index 8853ee7..4d1fe78 100644
|
|||||||
- * is forbidden from updating NSEC records."
|
- * is forbidden from updating NSEC records."
|
||||||
- */
|
- */
|
||||||
- if (rdata.type == dns_rdatatype_nsec3) {
|
- if (rdata.type == dns_rdatatype_nsec3) {
|
||||||
- FAILC(DNS_R_REFUSED,
|
- FAILC(DNS_R_REFUSED, "explicit NSEC3 updates are not "
|
||||||
- "explicit NSEC3 updates are not allowed "
|
- "allowed "
|
||||||
- "in secure zones");
|
- "in secure zones");
|
||||||
- } else if (rdata.type == dns_rdatatype_nsec) {
|
- } else if (rdata.type == dns_rdatatype_nsec) {
|
||||||
- FAILC(DNS_R_REFUSED,
|
- FAILC(DNS_R_REFUSED, "explicit NSEC updates are not "
|
||||||
- "explicit NSEC updates are not allowed "
|
- "allowed "
|
||||||
- "in secure zones");
|
- "in secure zones");
|
||||||
- } else if (rdata.type == dns_rdatatype_rrsig &&
|
- } else if (rdata.type == dns_rdatatype_rrsig &&
|
||||||
- !dns_name_equal(name, zonename)) {
|
- !dns_name_equal(name, zonename)) {
|
||||||
- FAILC(DNS_R_REFUSED,
|
- FAILC(DNS_R_REFUSED, "explicit RRSIG updates are "
|
||||||
- "explicit RRSIG updates are currently "
|
- "currently "
|
||||||
- "not supported in secure zones except "
|
- "not supported in secure zones "
|
||||||
- "at the apex");
|
- "except "
|
||||||
|
- "at the apex");
|
||||||
- }
|
- }
|
||||||
-
|
-
|
||||||
- if (ssutable != NULL) {
|
- if (ssutable != NULL) {
|
||||||
@ -494,49 +401,59 @@ index 8853ee7..4d1fe78 100644
|
|||||||
- dst_key_t *tsigkey = NULL;
|
- dst_key_t *tsigkey = NULL;
|
||||||
- isc_netaddr_fromsockaddr(&netaddr, &client->peeraddr);
|
- isc_netaddr_fromsockaddr(&netaddr, &client->peeraddr);
|
||||||
-
|
-
|
||||||
- if (client->message->tsigkey != NULL)
|
- if (client->message->tsigkey != NULL) {
|
||||||
- tsigkey = client->message->tsigkey->key;
|
- tsigkey = client->message->tsigkey->key;
|
||||||
|
- }
|
||||||
-
|
-
|
||||||
- if (rdata.type != dns_rdatatype_any) {
|
- if (rdata.type != dns_rdatatype_any) {
|
||||||
- if (!dns_ssutable_checkrules2
|
- if (!dns_ssutable_checkrules(
|
||||||
- (ssutable, client->signer, name, &netaddr,
|
- ssutable, client->signer, name,
|
||||||
- TCPCLIENT(client),
|
- &netaddr, TCPCLIENT(client), env,
|
||||||
- &ns_g_server->aclenv,
|
- rdata.type, tsigkey))
|
||||||
- rdata.type, tsigkey))
|
|
||||||
- {
|
- {
|
||||||
- FAILC(DNS_R_REFUSED,
|
- FAILC(DNS_R_REFUSED, "rejected by "
|
||||||
- "rejected by secure update");
|
- "secure update");
|
||||||
- }
|
- }
|
||||||
- } else {
|
- } else {
|
||||||
- if (!ssu_checkall(db, ver, name, ssutable,
|
- if (!ssu_checkall(db, ver, name, ssutable,
|
||||||
- client->signer,
|
- client->signer, &netaddr, env,
|
||||||
- &netaddr,
|
- TCPCLIENT(client), tsigkey))
|
||||||
- TCPCLIENT(client),
|
|
||||||
- tsigkey))
|
|
||||||
- {
|
- {
|
||||||
- FAILC(DNS_R_REFUSED,
|
- FAILC(DNS_R_REFUSED, "rejected by "
|
||||||
- "rejected by secure update");
|
- "secure update");
|
||||||
- }
|
- }
|
||||||
- }
|
- }
|
||||||
- }
|
- }
|
||||||
- }
|
- }
|
||||||
- if (result != ISC_R_NOMORE)
|
- if (result != ISC_R_NOMORE) {
|
||||||
- FAIL(result);
|
- FAIL(result);
|
||||||
|
- }
|
||||||
-
|
-
|
||||||
- update_log(client, zone, LOGLEVEL_DEBUG,
|
- update_log(client, zone, LOGLEVEL_DEBUG, "update section prescan OK");
|
||||||
- "update section prescan OK");
|
|
||||||
-
|
-
|
||||||
/*
|
/*
|
||||||
* Process the Update Section.
|
* Process the Update Section.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
- options = dns_zone_getoptions(zone);
|
- options = dns_zone_getoptions(zone);
|
||||||
options2 = dns_zone_getoptions2(zone);
|
|
||||||
for (result = dns_message_firstname(request, DNS_SECTION_UPDATE);
|
for (result = dns_message_firstname(request, DNS_SECTION_UPDATE);
|
||||||
result == ISC_R_SUCCESS;
|
result == ISC_R_SUCCESS;
|
||||||
@@ -3494,6 +3643,13 @@ send_forward_event(ns_client_t *client, dns_zone_t *zone) {
|
result = dns_message_nextname(request, DNS_SECTION_UPDATE))
|
||||||
|
@@ -3307,10 +3330,7 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
||||||
|
if (result == ISC_R_SUCCESS && records > maxrecords) {
|
||||||
|
update_log(client, zone, ISC_LOG_ERROR,
|
||||||
|
"records in zone (%" PRIu64 ") "
|
||||||
|
- "exceeds"
|
||||||
|
- " max-"
|
||||||
|
- "records"
|
||||||
|
- " (%u)",
|
||||||
|
+ "exceeds max-records (%u)",
|
||||||
|
records, maxrecords);
|
||||||
|
result = DNS_R_TOOMANYRECORDS;
|
||||||
|
goto failure;
|
||||||
|
@@ -3601,6 +3621,13 @@ send_forward_event(ns_client_t *client, dns_zone_t *zone) {
|
||||||
|
update_event_t *event = NULL;
|
||||||
isc_task_t *zonetask = NULL;
|
isc_task_t *zonetask = NULL;
|
||||||
ns_client_t *evclient;
|
|
||||||
|
|
||||||
+ result = checkupdateacl(client, dns_zone_getforwardacl(zone),
|
+ result = checkupdateacl(client, dns_zone_getforwardacl(zone),
|
||||||
+ "update forwarding", dns_zone_getorigin(zone),
|
+ "update forwarding", dns_zone_getorigin(zone),
|
||||||
@ -545,9 +462,9 @@ index 8853ee7..4d1fe78 100644
|
|||||||
+ return (result);
|
+ return (result);
|
||||||
+ }
|
+ }
|
||||||
+
|
+
|
||||||
result = isc_quota_attach(&ns_g_server->updquota,
|
result = isc_quota_attach(&client->manager->sctx->updquota,
|
||||||
&(isc_quota_t *){ NULL });
|
&(isc_quota_t *){ NULL });
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
--
|
--
|
||||||
2.39.2
|
2.39.1
|
||||||
|
|
||||||
|
|||||||
@ -1,4 +1,4 @@
|
|||||||
From 3d84c651f823cb90b73fd736d32ad6de57b11610 Mon Sep 17 00:00:00 2001
|
From 54e281c11ee13eabc3c51d6391a58fc90836000c Mon Sep 17 00:00:00 2001
|
||||||
From: Evan Hunt <each@isc.org>
|
From: Evan Hunt <each@isc.org>
|
||||||
Date: Wed, 9 Nov 2022 21:56:16 -0800
|
Date: Wed, 9 Nov 2022 21:56:16 -0800
|
||||||
Subject: [PATCH] test failure conditions
|
Subject: [PATCH] test failure conditions
|
||||||
@ -15,27 +15,27 @@ many simultaneous updates are processing.
|
|||||||
bin/tests/system/nsupdate/ns1/named.conf.in | 2 +
|
bin/tests/system/nsupdate/ns1/named.conf.in | 2 +
|
||||||
bin/tests/system/nsupdate/tests.sh | 28 +++++++++++++
|
bin/tests/system/nsupdate/tests.sh | 28 +++++++++++++
|
||||||
bin/tests/system/upforwd/clean.sh | 2 +
|
bin/tests/system/upforwd/clean.sh | 2 +
|
||||||
.../ns3/{named.conf.in => named1.conf.in} | 7 +++-
|
.../ns3/{named.conf.in => named1.conf.in} | 13 ++++--
|
||||||
bin/tests/system/upforwd/ns3/named2.conf.in | 41 +++++++++++++++++++
|
bin/tests/system/upforwd/ns3/named2.conf.in | 41 +++++++++++++++++++
|
||||||
bin/tests/system/upforwd/setup.sh | 2 +-
|
bin/tests/system/upforwd/setup.sh | 2 +-
|
||||||
bin/tests/system/upforwd/tests.sh | 40 ++++++++++++++++++
|
bin/tests/system/upforwd/tests.sh | 39 ++++++++++++++++++
|
||||||
7 files changed, 120 insertions(+), 2 deletions(-)
|
7 files changed, 123 insertions(+), 4 deletions(-)
|
||||||
rename bin/tests/system/upforwd/ns3/{named.conf.in => named1.conf.in} (85%)
|
rename bin/tests/system/upforwd/ns3/{named.conf.in => named1.conf.in} (78%)
|
||||||
create mode 100644 bin/tests/system/upforwd/ns3/named2.conf.in
|
create mode 100644 bin/tests/system/upforwd/ns3/named2.conf.in
|
||||||
|
|
||||||
diff --git a/bin/tests/system/nsupdate/ns1/named.conf.in b/bin/tests/system/nsupdate/ns1/named.conf.in
|
diff --git a/bin/tests/system/nsupdate/ns1/named.conf.in b/bin/tests/system/nsupdate/ns1/named.conf.in
|
||||||
index cb80269..228ad6a 100644
|
index 436c97d..83fe884 100644
|
||||||
--- a/bin/tests/system/nsupdate/ns1/named.conf.in
|
--- a/bin/tests/system/nsupdate/ns1/named.conf.in
|
||||||
+++ b/bin/tests/system/nsupdate/ns1/named.conf.in
|
+++ b/bin/tests/system/nsupdate/ns1/named.conf.in
|
||||||
@@ -20,6 +20,7 @@ options {
|
@@ -21,6 +21,7 @@ options {
|
||||||
listen-on-v6 { none; };
|
|
||||||
recursion no;
|
recursion no;
|
||||||
notify yes;
|
notify yes;
|
||||||
|
minimal-responses no;
|
||||||
+ update-quota 1;
|
+ update-quota 1;
|
||||||
};
|
};
|
||||||
|
|
||||||
key rndc_key {
|
acl named-acl {
|
||||||
@@ -76,6 +77,7 @@ zone "other.nil" {
|
@@ -81,6 +82,7 @@ zone "other.nil" {
|
||||||
check-integrity no;
|
check-integrity no;
|
||||||
check-mx warn;
|
check-mx warn;
|
||||||
update-policy local;
|
update-policy local;
|
||||||
@ -44,10 +44,10 @@ index cb80269..228ad6a 100644
|
|||||||
allow-transfer { any; };
|
allow-transfer { any; };
|
||||||
};
|
};
|
||||||
diff --git a/bin/tests/system/nsupdate/tests.sh b/bin/tests/system/nsupdate/tests.sh
|
diff --git a/bin/tests/system/nsupdate/tests.sh b/bin/tests/system/nsupdate/tests.sh
|
||||||
index f8994ff..4cabf8d 100755
|
index b5f562f..13ba577 100755
|
||||||
--- a/bin/tests/system/nsupdate/tests.sh
|
--- a/bin/tests/system/nsupdate/tests.sh
|
||||||
+++ b/bin/tests/system/nsupdate/tests.sh
|
+++ b/bin/tests/system/nsupdate/tests.sh
|
||||||
@@ -1069,6 +1069,34 @@ END
|
@@ -1268,6 +1268,34 @@ END
|
||||||
grep "NSEC3PARAM has excessive iterations (> 150)" nsupdate.out-$n >/dev/null || ret=1
|
grep "NSEC3PARAM has excessive iterations (> 150)" nsupdate.out-$n >/dev/null || ret=1
|
||||||
[ $ret = 0 ] || { echo_i "failed"; status=1; }
|
[ $ret = 0 ] || { echo_i "failed"; status=1; }
|
||||||
|
|
||||||
@ -62,7 +62,7 @@ index f8994ff..4cabf8d 100755
|
|||||||
+ send
|
+ send
|
||||||
+END
|
+END
|
||||||
+} > nsupdate.out.test$n 2>&1
|
+} > nsupdate.out.test$n 2>&1
|
||||||
+grep 'status: REFUSED' nsupdate.out.test$n > /dev/null || ret=1
|
+grep 'failed: REFUSED' nsupdate.out.test$n > /dev/null || ret=1
|
||||||
+[ $ret = 0 ] || { echo_i "failed"; status=1; }
|
+[ $ret = 0 ] || { echo_i "failed"; status=1; }
|
||||||
+
|
+
|
||||||
+n=$((n + 1))
|
+n=$((n + 1))
|
||||||
@ -70,7 +70,7 @@ index f8994ff..4cabf8d 100755
|
|||||||
+echo_i "check that update is rejected if quota is exceeded ($n)"
|
+echo_i "check that update is rejected if quota is exceeded ($n)"
|
||||||
+for loop in 1 2 3 4 5 6 7 8 9 10; do
|
+for loop in 1 2 3 4 5 6 7 8 9 10; do
|
||||||
+{
|
+{
|
||||||
+ $NSUPDATE -l -p ${PORT} -k ns1/session.key > nsupdate.out.test$n-${loop} 2>&1 <<END
|
+ $NSUPDATE -4 -l -p ${PORT} -k ns1/session.key > /dev/null 2>&1 <<END
|
||||||
+ update add txt-$loop.other.nil 3600 IN TXT Whatever
|
+ update add txt-$loop.other.nil 3600 IN TXT Whatever
|
||||||
+ send
|
+ send
|
||||||
+END
|
+END
|
||||||
@ -79,46 +79,60 @@ index f8994ff..4cabf8d 100755
|
|||||||
+wait_for_log 10 "too many DNS UPDATEs queued" ns1/named.run || ret=1
|
+wait_for_log 10 "too many DNS UPDATEs queued" ns1/named.run || ret=1
|
||||||
+[ $ret = 0 ] || { echo_i "failed"; status=1; }
|
+[ $ret = 0 ] || { echo_i "failed"; status=1; }
|
||||||
+
|
+
|
||||||
if $FEATURETEST --gssapi ; then
|
if ! $FEATURETEST --gssapi ; then
|
||||||
n=`expr $n + 1`
|
echo_i "SKIPPED: GSSAPI tests"
|
||||||
ret=0
|
else
|
||||||
diff --git a/bin/tests/system/upforwd/clean.sh b/bin/tests/system/upforwd/clean.sh
|
diff --git a/bin/tests/system/upforwd/clean.sh b/bin/tests/system/upforwd/clean.sh
|
||||||
index 15cf423..832c727 100644
|
index 2025252..12311df 100644
|
||||||
--- a/bin/tests/system/upforwd/clean.sh
|
--- a/bin/tests/system/upforwd/clean.sh
|
||||||
+++ b/bin/tests/system/upforwd/clean.sh
|
+++ b/bin/tests/system/upforwd/clean.sh
|
||||||
@@ -24,3 +24,5 @@ rm -f Ksig0.example2.*
|
@@ -29,3 +29,5 @@ rm -f keyname keyname.err
|
||||||
rm -f keyname
|
|
||||||
rm -f ns*/named.lock
|
rm -f ns*/named.lock
|
||||||
rm -f ns1/example2.db
|
rm -f ns1/example2.db
|
||||||
|
rm -f ns*/managed-keys.bind*
|
||||||
+rm -f nsupdate.out.*
|
+rm -f nsupdate.out.*
|
||||||
+rm -f ns*/named.run.prev
|
+rm -f ns*/named.run.prev
|
||||||
diff --git a/bin/tests/system/upforwd/ns3/named.conf.in b/bin/tests/system/upforwd/ns3/named1.conf.in
|
diff --git a/bin/tests/system/upforwd/ns3/named.conf.in b/bin/tests/system/upforwd/ns3/named1.conf.in
|
||||||
similarity index 85%
|
similarity index 78%
|
||||||
rename from bin/tests/system/upforwd/ns3/named.conf.in
|
rename from bin/tests/system/upforwd/ns3/named.conf.in
|
||||||
rename to bin/tests/system/upforwd/ns3/named1.conf.in
|
rename to bin/tests/system/upforwd/ns3/named1.conf.in
|
||||||
index e81cd1a..83a490f 100644
|
index 7bd13d3..2f690ff 100644
|
||||||
--- a/bin/tests/system/upforwd/ns3/named.conf.in
|
--- a/bin/tests/system/upforwd/ns3/named.conf.in
|
||||||
+++ b/bin/tests/system/upforwd/ns3/named1.conf.in
|
+++ b/bin/tests/system/upforwd/ns3/named1.conf.in
|
||||||
@@ -22,10 +22,15 @@ options {
|
@@ -28,20 +28,27 @@ key rndc_key {
|
||||||
notify yes;
|
|
||||||
};
|
};
|
||||||
|
|
||||||
+include "../../common/rndc.key";
|
controls {
|
||||||
+controls {
|
- inet 10.53.0.3 port @CONTROLPORT@ allow { any; } keys { rndc_key; };
|
||||||
+ inet 10.53.0.3 port @CONTROLPORT@ allow { any; } keys { rndc_key; };
|
+ inet 10.53.0.3 port @CONTROLPORT@ allow { any; } keys { rndc_key; };
|
||||||
+};
|
};
|
||||||
+
|
|
||||||
zone "example" {
|
zone "example" {
|
||||||
type slave;
|
type secondary;
|
||||||
file "example.bk";
|
file "example.bk";
|
||||||
- allow-update-forwarding { any; };
|
- allow-update-forwarding { any; };
|
||||||
+ allow-update-forwarding { 10.53.0.1; };
|
+ allow-update-forwarding { 10.53.0.1; };
|
||||||
masters { 10.53.0.1; };
|
primaries { 10.53.0.1; };
|
||||||
|
};
|
||||||
|
|
||||||
|
zone "example2" {
|
||||||
|
type secondary;
|
||||||
|
file "example2.bk";
|
||||||
|
- allow-update-forwarding { any; };
|
||||||
|
+ allow-update-forwarding { 10.53.0.1; };
|
||||||
|
+ primaries { 10.53.0.1; };
|
||||||
|
+};
|
||||||
|
+
|
||||||
|
+zone "example3" {
|
||||||
|
+ type secondary;
|
||||||
|
+ file "example3.bk";
|
||||||
|
+ allow-update-forwarding { 10.53.0.1; };
|
||||||
|
primaries { 10.53.0.1; };
|
||||||
};
|
};
|
||||||
|
|
||||||
diff --git a/bin/tests/system/upforwd/ns3/named2.conf.in b/bin/tests/system/upforwd/ns3/named2.conf.in
|
diff --git a/bin/tests/system/upforwd/ns3/named2.conf.in b/bin/tests/system/upforwd/ns3/named2.conf.in
|
||||||
new file mode 100644
|
new file mode 100644
|
||||||
index 0000000..992cd69
|
index 0000000..e15459a
|
||||||
--- /dev/null
|
--- /dev/null
|
||||||
+++ b/bin/tests/system/upforwd/ns3/named2.conf.in
|
+++ b/bin/tests/system/upforwd/ns3/named2.conf.in
|
||||||
@@ -0,0 +1,41 @@
|
@@ -0,0 +1,41 @@
|
||||||
@ -150,7 +164,7 @@ index 0000000..992cd69
|
|||||||
+
|
+
|
||||||
+key rndc_key {
|
+key rndc_key {
|
||||||
+ secret "1234abcd8765";
|
+ secret "1234abcd8765";
|
||||||
+ algorithm hmac-sha256;
|
+ algorithm hmac-sha256;
|
||||||
+};
|
+};
|
||||||
+
|
+
|
||||||
+controls {
|
+controls {
|
||||||
@ -158,13 +172,13 @@ index 0000000..992cd69
|
|||||||
+};
|
+};
|
||||||
+
|
+
|
||||||
+zone "example" {
|
+zone "example" {
|
||||||
+ type slave;
|
+ type secondary;
|
||||||
+ file "example.bk";
|
+ file "example.bk";
|
||||||
+ allow-update-forwarding { any; };
|
+ allow-update-forwarding { any; };
|
||||||
+ masters { 10.53.0.1; };
|
+ primaries { 10.53.0.1; };
|
||||||
+};
|
+};
|
||||||
diff --git a/bin/tests/system/upforwd/setup.sh b/bin/tests/system/upforwd/setup.sh
|
diff --git a/bin/tests/system/upforwd/setup.sh b/bin/tests/system/upforwd/setup.sh
|
||||||
index 74c7ba3..928902b 100644
|
index e748078..88ab28d 100644
|
||||||
--- a/bin/tests/system/upforwd/setup.sh
|
--- a/bin/tests/system/upforwd/setup.sh
|
||||||
+++ b/bin/tests/system/upforwd/setup.sh
|
+++ b/bin/tests/system/upforwd/setup.sh
|
||||||
@@ -17,7 +17,7 @@ cp -f ns3/nomaster.db ns3/nomaster1.db
|
@@ -17,7 +17,7 @@ cp -f ns3/nomaster.db ns3/nomaster1.db
|
||||||
@ -174,21 +188,13 @@ index 74c7ba3..928902b 100644
|
|||||||
-copy_setports ns3/named.conf.in ns3/named.conf
|
-copy_setports ns3/named.conf.in ns3/named.conf
|
||||||
+copy_setports ns3/named1.conf.in ns3/named.conf
|
+copy_setports ns3/named1.conf.in ns3/named.conf
|
||||||
|
|
||||||
#
|
if $FEATURETEST --enable-dnstap
|
||||||
# SIG(0) required cryptographic support which may not be configured.
|
then
|
||||||
diff --git a/bin/tests/system/upforwd/tests.sh b/bin/tests/system/upforwd/tests.sh
|
diff --git a/bin/tests/system/upforwd/tests.sh b/bin/tests/system/upforwd/tests.sh
|
||||||
index f4c3216..ebc9ded 100644
|
index 8062d68..20fc46f 100644
|
||||||
--- a/bin/tests/system/upforwd/tests.sh
|
--- a/bin/tests/system/upforwd/tests.sh
|
||||||
+++ b/bin/tests/system/upforwd/tests.sh
|
+++ b/bin/tests/system/upforwd/tests.sh
|
||||||
@@ -17,6 +17,7 @@ SYSTEMTESTTOP=..
|
@@ -80,6 +80,7 @@ if [ $ret != 0 ] ; then echo_i "failed"; status=`expr $status + $ret`; fi
|
||||||
. $SYSTEMTESTTOP/conf.sh
|
|
||||||
|
|
||||||
DIGOPTS="+tcp +noadd +nosea +nostat +noquest +nocomm +nocmd -p ${PORT}"
|
|
||||||
+RNDCCMD="$RNDC -c $SYSTEMTESTTOP/common/rndc.conf -p ${CONTROLPORT} -s"
|
|
||||||
|
|
||||||
status=0
|
|
||||||
n=1
|
|
||||||
@@ -69,6 +70,7 @@ if [ $ret != 0 ] ; then echo_i "failed"; status=`expr $status + $ret`; fi
|
|
||||||
echo_i "updating zone (signed) ($n)"
|
echo_i "updating zone (signed) ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
$NSUPDATE -y hmac-sha256:update.example:c3Ryb25nIGVub3VnaCBmb3IgYSBtYW4gYnV0IG1hZGUgZm9yIGEgd29tYW4K -- - <<EOF || ret=1
|
$NSUPDATE -y hmac-sha256:update.example:c3Ryb25nIGVub3VnaCBmb3IgYSBtYW4gYnV0IG1hZGUgZm9yIGEgd29tYW4K -- - <<EOF || ret=1
|
||||||
@ -196,7 +202,7 @@ index f4c3216..ebc9ded 100644
|
|||||||
server 10.53.0.3 ${PORT}
|
server 10.53.0.3 ${PORT}
|
||||||
update add updated.example. 600 A 10.10.10.1
|
update add updated.example. 600 A 10.10.10.1
|
||||||
update add updated.example. 600 TXT Foo
|
update add updated.example. 600 TXT Foo
|
||||||
@@ -116,6 +118,7 @@ n=`expr $n + 1`
|
@@ -138,6 +139,7 @@ fi
|
||||||
echo_i "updating zone (unsigned) ($n)"
|
echo_i "updating zone (unsigned) ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
$NSUPDATE -- - <<EOF || ret=1
|
$NSUPDATE -- - <<EOF || ret=1
|
||||||
@ -204,7 +210,7 @@ index f4c3216..ebc9ded 100644
|
|||||||
server 10.53.0.3 ${PORT}
|
server 10.53.0.3 ${PORT}
|
||||||
update add unsigned.example. 600 A 10.10.10.1
|
update add unsigned.example. 600 A 10.10.10.1
|
||||||
update add unsigned.example. 600 TXT Foo
|
update add unsigned.example. 600 TXT Foo
|
||||||
@@ -161,6 +164,7 @@ while [ $count -lt 5 -a $ret -eq 0 ]
|
@@ -194,6 +196,7 @@ while [ $count -lt 5 -a $ret -eq 0 ]
|
||||||
do
|
do
|
||||||
(
|
(
|
||||||
$NSUPDATE -- - <<EOF
|
$NSUPDATE -- - <<EOF
|
||||||
@ -212,7 +218,7 @@ index f4c3216..ebc9ded 100644
|
|||||||
server 10.53.0.3 ${PORT}
|
server 10.53.0.3 ${PORT}
|
||||||
zone nomaster
|
zone nomaster
|
||||||
update add unsigned.nomaster. 600 A 10.10.10.1
|
update add unsigned.nomaster. 600 A 10.10.10.1
|
||||||
@@ -181,6 +185,7 @@ then
|
@@ -225,6 +228,7 @@ then
|
||||||
ret=0
|
ret=0
|
||||||
keyname=`cat keyname`
|
keyname=`cat keyname`
|
||||||
$NSUPDATE -k $keyname.private -- - <<EOF
|
$NSUPDATE -k $keyname.private -- - <<EOF
|
||||||
@ -220,8 +226,8 @@ index f4c3216..ebc9ded 100644
|
|||||||
server 10.53.0.3 ${PORT}
|
server 10.53.0.3 ${PORT}
|
||||||
zone example2
|
zone example2
|
||||||
update add unsigned.example2. 600 A 10.10.10.1
|
update add unsigned.example2. 600 A 10.10.10.1
|
||||||
@@ -194,5 +199,40 @@ EOF
|
@@ -249,5 +253,40 @@ EOF
|
||||||
n=`expr $n + 1`
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
+echo_i "attempting an update that should be rejected by ACL ($n)"
|
+echo_i "attempting an update that should be rejected by ACL ($n)"
|
||||||
@ -244,7 +250,7 @@ index f4c3216..ebc9ded 100644
|
|||||||
+echo_i "attempting updates that should exceed quota ($n)"
|
+echo_i "attempting updates that should exceed quota ($n)"
|
||||||
+# lower the update quota to 1.
|
+# lower the update quota to 1.
|
||||||
+copy_setports ns3/named2.conf.in ns3/named.conf
|
+copy_setports ns3/named2.conf.in ns3/named.conf
|
||||||
+$RNDCCMD 10.53.0.3 reconfig
|
+rndc_reconfig ns3 10.53.0.3
|
||||||
+nextpart ns3/named.run > /dev/null
|
+nextpart ns3/named.run > /dev/null
|
||||||
+for loop in 1 2 3 4 5 6 7 8 9 10; do
|
+for loop in 1 2 3 4 5 6 7 8 9 10; do
|
||||||
+{
|
+{
|
||||||
|
|||||||
53
SOURCES/bind-9.16-CVE-2022-3736.patch
Normal file
53
SOURCES/bind-9.16-CVE-2022-3736.patch
Normal file
@ -0,0 +1,53 @@
|
|||||||
|
From 1b6590eafce064cbf70f5afc2fe4d6f1bfdc3804 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Mark Andrews <marka@isc.org>
|
||||||
|
Date: Thu, 27 Oct 2022 13:22:11 +1100
|
||||||
|
Subject: [PATCH] Move the mapping of SIG and RRSIG to ANY
|
||||||
|
|
||||||
|
dns_db_findext() asserts if RRSIG is passed to it and
|
||||||
|
query_lookup_stale() failed to map RRSIG to ANY to prevent this. To
|
||||||
|
avoid cases like this in the future, move the mapping of SIG and RRSIG
|
||||||
|
to ANY for qctx->type to qctx_init().
|
||||||
|
|
||||||
|
(cherry picked from commit 56eae064183488bcf7ff08c3edf59f2e1742c1b6)
|
||||||
|
---
|
||||||
|
lib/ns/query.c | 17 +++++++++--------
|
||||||
|
1 file changed, 9 insertions(+), 8 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/lib/ns/query.c b/lib/ns/query.c
|
||||||
|
index a450cb7..f66bab4 100644
|
||||||
|
--- a/lib/ns/query.c
|
||||||
|
+++ b/lib/ns/query.c
|
||||||
|
@@ -5103,6 +5103,15 @@ qctx_init(ns_client_t *client, dns_fetchevent_t **eventp, dns_rdatatype_t qtype,
|
||||||
|
qctx->result = ISC_R_SUCCESS;
|
||||||
|
qctx->findcoveringnsec = qctx->view->synthfromdnssec;
|
||||||
|
|
||||||
|
+ /*
|
||||||
|
+ * If it's an RRSIG or SIG query, we'll iterate the node.
|
||||||
|
+ */
|
||||||
|
+ if (qctx->qtype == dns_rdatatype_rrsig ||
|
||||||
|
+ qctx->qtype == dns_rdatatype_sig)
|
||||||
|
+ {
|
||||||
|
+ qctx->type = dns_rdatatype_any;
|
||||||
|
+ }
|
||||||
|
+
|
||||||
|
CALL_HOOK_NORETURN(NS_QUERY_QCTX_INITIALIZED, qctx);
|
||||||
|
}
|
||||||
|
|
||||||
|
@@ -5243,14 +5252,6 @@ query_setup(ns_client_t *client, dns_rdatatype_t qtype) {
|
||||||
|
|
||||||
|
CALL_HOOK(NS_QUERY_SETUP, &qctx);
|
||||||
|
|
||||||
|
- /*
|
||||||
|
- * If it's a SIG query, we'll iterate the node.
|
||||||
|
- */
|
||||||
|
- if (qctx.qtype == dns_rdatatype_rrsig ||
|
||||||
|
- qctx.qtype == dns_rdatatype_sig) {
|
||||||
|
- qctx.type = dns_rdatatype_any;
|
||||||
|
- }
|
||||||
|
-
|
||||||
|
/*
|
||||||
|
* Check SERVFAIL cache
|
||||||
|
*/
|
||||||
|
--
|
||||||
|
2.39.1
|
||||||
|
|
||||||
@ -1,7 +1,7 @@
|
|||||||
From 0095b8a6b09173ab5eb48611dc0233d2a6337dc1 Mon Sep 17 00:00:00 2001
|
From df8222fb189708199a185f73543b6e0602c1c72f Mon Sep 17 00:00:00 2001
|
||||||
From: Petr Mensik <pemensik@redhat.com>
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
Date: Tue, 20 Sep 2022 11:21:45 +0200
|
Date: Tue, 20 Sep 2022 11:21:45 +0200
|
||||||
Subject: [PATCH] Fix CVE-2022-38177
|
Subject: [PATCH 3/4] Fix CVE-2022-38177
|
||||||
|
|
||||||
5961. [security] Fix memory leak in ECDSA verify processing.
|
5961. [security] Fix memory leak in ECDSA verify processing.
|
||||||
(CVE-2022-38177) [GL #3487]
|
(CVE-2022-38177) [GL #3487]
|
||||||
@ -10,18 +10,18 @@ Subject: [PATCH] Fix CVE-2022-38177
|
|||||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||||
|
|
||||||
diff --git a/lib/dns/opensslecdsa_link.c b/lib/dns/opensslecdsa_link.c
|
diff --git a/lib/dns/opensslecdsa_link.c b/lib/dns/opensslecdsa_link.c
|
||||||
index 83b5b51..7576e04 100644
|
index ce4c8c4..3847896 100644
|
||||||
--- a/lib/dns/opensslecdsa_link.c
|
--- a/lib/dns/opensslecdsa_link.c
|
||||||
+++ b/lib/dns/opensslecdsa_link.c
|
+++ b/lib/dns/opensslecdsa_link.c
|
||||||
@@ -224,7 +224,7 @@ opensslecdsa_verify(dst_context_t *dctx, const isc_region_t *sig) {
|
@@ -228,7 +228,7 @@ opensslecdsa_verify(dst_context_t *dctx, const isc_region_t *sig) {
|
||||||
siglen = DNS_SIG_ECDSA384SIZE;
|
}
|
||||||
|
|
||||||
if (sig->length != siglen)
|
if (sig->length != siglen) {
|
||||||
- return (DST_R_VERIFYFAILURE);
|
- return (DST_R_VERIFYFAILURE);
|
||||||
+ DST_RET(DST_R_VERIFYFAILURE);
|
+ DST_RET(DST_R_VERIFYFAILURE);
|
||||||
|
}
|
||||||
|
|
||||||
if (!EVP_DigestFinal_ex(evp_md_ctx, digest, &dgstlen))
|
if (!EVP_DigestFinal_ex(evp_md_ctx, digest, &dgstlen)) {
|
||||||
DST_RET (dst__openssl_toresult3(dctx->category,
|
|
||||||
--
|
--
|
||||||
2.37.3
|
2.37.3
|
||||||
|
|
||||||
|
|||||||
@ -1,27 +1,32 @@
|
|||||||
From bb68864bf05d29df644427ec841bc3db6a336519 Mon Sep 17 00:00:00 2001
|
From 132ef295b8407f91e6922f4dfc4f30f1790b61c5 Mon Sep 17 00:00:00 2001
|
||||||
From: Petr Mensik <pemensik@redhat.com>
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
Date: Tue, 20 Sep 2022 11:22:47 +0200
|
Date: Tue, 20 Sep 2022 11:22:47 +0200
|
||||||
Subject: [PATCH] Fix CVE-2022-38178
|
Subject: [PATCH 4/4] Fix CVE-2022-38178
|
||||||
|
|
||||||
5962. [security] Fix memory leak in EdDSA verify processing.
|
5962. [security] Fix memory leak in EdDSA verify processing.
|
||||||
(CVE-2022-38178) [GL #3487]
|
(CVE-2022-38178) [GL #3487]
|
||||||
---
|
---
|
||||||
lib/dns/openssleddsa_link.c | 2 +-
|
lib/dns/openssleddsa_link.c | 4 ++--
|
||||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
1 file changed, 2 insertions(+), 2 deletions(-)
|
||||||
|
|
||||||
diff --git a/lib/dns/openssleddsa_link.c b/lib/dns/openssleddsa_link.c
|
diff --git a/lib/dns/openssleddsa_link.c b/lib/dns/openssleddsa_link.c
|
||||||
index 8b115ec..4f3c2a8 100644
|
index 6a6a74d..3157011 100644
|
||||||
--- a/lib/dns/openssleddsa_link.c
|
--- a/lib/dns/openssleddsa_link.c
|
||||||
+++ b/lib/dns/openssleddsa_link.c
|
+++ b/lib/dns/openssleddsa_link.c
|
||||||
@@ -325,7 +325,7 @@ openssleddsa_verify(dst_context_t *dctx, const isc_region_t *sig) {
|
@@ -234,11 +234,11 @@ openssleddsa_verify(dst_context_t *dctx, const isc_region_t *sig) {
|
||||||
siglen = DNS_SIG_ED448SIZE;
|
}
|
||||||
|
#endif /* if HAVE_OPENSSL_ED448 */
|
||||||
|
if (siglen == 0) {
|
||||||
|
- return (ISC_R_NOTIMPLEMENTED);
|
||||||
|
+ DST_RET(ISC_R_NOTIMPLEMENTED);
|
||||||
|
}
|
||||||
|
|
||||||
if (sig->length != siglen)
|
if (sig->length != siglen) {
|
||||||
- return (DST_R_VERIFYFAILURE);
|
- return (DST_R_VERIFYFAILURE);
|
||||||
+ DST_RET(DST_R_VERIFYFAILURE);
|
+ DST_RET(DST_R_VERIFYFAILURE);
|
||||||
|
}
|
||||||
|
|
||||||
isc_buffer_usedregion(buf, &tbsreg);
|
isc_buffer_usedregion(buf, &tbsreg);
|
||||||
|
|
||||||
--
|
--
|
||||||
2.37.3
|
2.37.3
|
||||||
|
|
||||||
|
|||||||
128
SOURCES/bind-9.16-CVE-2022-3924.patch
Normal file
128
SOURCES/bind-9.16-CVE-2022-3924.patch
Normal file
@ -0,0 +1,128 @@
|
|||||||
|
From 20424b3bfe8d3fae92c11a30e79aeffd26dc2891 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Aram Sargsyan <aram@isc.org>
|
||||||
|
Date: Mon, 14 Nov 2022 12:18:06 +0000
|
||||||
|
Subject: [PATCH] Cancel all fetch events in dns_resolver_cancelfetch()
|
||||||
|
|
||||||
|
Although 'dns_fetch_t' fetch can have two associated events, one for
|
||||||
|
each of 'DNS_EVENT_FETCHDONE' and 'DNS_EVENT_TRYSTALE' types, the
|
||||||
|
dns_resolver_cancelfetch() function is designed in a way that it
|
||||||
|
expects only one existing event, which it must cancel, and when it
|
||||||
|
happens so that 'stale-answer-client-timeout' is enabled and there
|
||||||
|
are two events, only one of them is canceled, and it results in an
|
||||||
|
assertion in dns_resolver_destroyfetch(), when it finds a dangling
|
||||||
|
event.
|
||||||
|
|
||||||
|
Change the logic of dns_resolver_cancelfetch() function so that it
|
||||||
|
cancels both the events (if they exist), and in the right order.
|
||||||
|
|
||||||
|
(cherry picked from commit ec2098ca35039e4f81fd0aa7c525eb960b8f47bf)
|
||||||
|
---
|
||||||
|
lib/dns/resolver.c | 53 +++++++++++++++++++++++++++++++++++-----------
|
||||||
|
lib/ns/query.c | 4 +++-
|
||||||
|
2 files changed, 44 insertions(+), 13 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c
|
||||||
|
index 18585b5..7cbfbb2 100644
|
||||||
|
--- a/lib/dns/resolver.c
|
||||||
|
+++ b/lib/dns/resolver.c
|
||||||
|
@@ -11254,8 +11254,9 @@ void
|
||||||
|
dns_resolver_cancelfetch(dns_fetch_t *fetch) {
|
||||||
|
fetchctx_t *fctx;
|
||||||
|
dns_resolver_t *res;
|
||||||
|
- dns_fetchevent_t *event, *next_event;
|
||||||
|
- isc_task_t *etask;
|
||||||
|
+ dns_fetchevent_t *event = NULL;
|
||||||
|
+ dns_fetchevent_t *event_trystale = NULL;
|
||||||
|
+ dns_fetchevent_t *event_fetchdone = NULL;
|
||||||
|
|
||||||
|
REQUIRE(DNS_FETCH_VALID(fetch));
|
||||||
|
fctx = fetch->private;
|
||||||
|
@@ -11267,32 +11268,60 @@ dns_resolver_cancelfetch(dns_fetch_t *fetch) {
|
||||||
|
LOCK(&res->buckets[fctx->bucketnum].lock);
|
||||||
|
|
||||||
|
/*
|
||||||
|
- * Find the completion event for this fetch (as opposed
|
||||||
|
+ * Find the events for this fetch (as opposed
|
||||||
|
* to those for other fetches that have joined the same
|
||||||
|
- * fctx) and send it with result = ISC_R_CANCELED.
|
||||||
|
+ * fctx) and send them with result = ISC_R_CANCELED.
|
||||||
|
*/
|
||||||
|
- event = NULL;
|
||||||
|
if (fctx->state != fetchstate_done) {
|
||||||
|
+ dns_fetchevent_t *next_event = NULL;
|
||||||
|
for (event = ISC_LIST_HEAD(fctx->events); event != NULL;
|
||||||
|
event = next_event) {
|
||||||
|
next_event = ISC_LIST_NEXT(event, ev_link);
|
||||||
|
if (event->fetch == fetch) {
|
||||||
|
ISC_LIST_UNLINK(fctx->events, event, ev_link);
|
||||||
|
- break;
|
||||||
|
+ switch (event->ev_type) {
|
||||||
|
+ case DNS_EVENT_TRYSTALE:
|
||||||
|
+ INSIST(event_trystale == NULL);
|
||||||
|
+ event_trystale = event;
|
||||||
|
+ break;
|
||||||
|
+ case DNS_EVENT_FETCHDONE:
|
||||||
|
+ INSIST(event_fetchdone == NULL);
|
||||||
|
+ event_fetchdone = event;
|
||||||
|
+ break;
|
||||||
|
+ default:
|
||||||
|
+ ISC_UNREACHABLE();
|
||||||
|
+ }
|
||||||
|
+ if (event_trystale != NULL &&
|
||||||
|
+ event_fetchdone != NULL)
|
||||||
|
+ {
|
||||||
|
+ break;
|
||||||
|
+ }
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
- if (event != NULL) {
|
||||||
|
- etask = event->ev_sender;
|
||||||
|
- event->ev_sender = fctx;
|
||||||
|
- event->result = ISC_R_CANCELED;
|
||||||
|
- isc_task_sendanddetach(&etask, ISC_EVENT_PTR(&event));
|
||||||
|
+
|
||||||
|
+ /*
|
||||||
|
+ * The "trystale" event must be sent before the "fetchdone" event,
|
||||||
|
+ * because the latter clears the "recursing" query attribute, which is
|
||||||
|
+ * required by both events (handled by the same callback function).
|
||||||
|
+ */
|
||||||
|
+ if (event_trystale != NULL) {
|
||||||
|
+ isc_task_t *etask = event_trystale->ev_sender;
|
||||||
|
+ event_trystale->ev_sender = fctx;
|
||||||
|
+ event_trystale->result = ISC_R_CANCELED;
|
||||||
|
+ isc_task_sendanddetach(&etask, ISC_EVENT_PTR(&event_trystale));
|
||||||
|
}
|
||||||
|
+ if (event_fetchdone != NULL) {
|
||||||
|
+ isc_task_t *etask = event_fetchdone->ev_sender;
|
||||||
|
+ event_fetchdone->ev_sender = fctx;
|
||||||
|
+ event_fetchdone->result = ISC_R_CANCELED;
|
||||||
|
+ isc_task_sendanddetach(&etask, ISC_EVENT_PTR(&event_fetchdone));
|
||||||
|
+ }
|
||||||
|
+
|
||||||
|
/*
|
||||||
|
* The fctx continues running even if no fetches remain;
|
||||||
|
* the answer is still cached.
|
||||||
|
*/
|
||||||
|
-
|
||||||
|
UNLOCK(&res->buckets[fctx->bucketnum].lock);
|
||||||
|
}
|
||||||
|
|
||||||
|
diff --git a/lib/ns/query.c b/lib/ns/query.c
|
||||||
|
index f66bab4..4f61374 100644
|
||||||
|
--- a/lib/ns/query.c
|
||||||
|
+++ b/lib/ns/query.c
|
||||||
|
@@ -6021,7 +6021,9 @@ fetch_callback(isc_task_t *task, isc_event_t *event) {
|
||||||
|
CTRACE(ISC_LOG_DEBUG(3), "fetch_callback");
|
||||||
|
|
||||||
|
if (event->ev_type == DNS_EVENT_TRYSTALE) {
|
||||||
|
- query_lookup_stale(client);
|
||||||
|
+ if (devent->result != ISC_R_CANCELED) {
|
||||||
|
+ query_lookup_stale(client);
|
||||||
|
+ }
|
||||||
|
isc_event_free(ISC_EVENT_PTR(&event));
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
--
|
||||||
|
2.39.1
|
||||||
|
|
||||||
@ -1,4 +1,4 @@
|
|||||||
From f3aa755ba5ae5148dd0567357f8c538072e2eabc Mon Sep 17 00:00:00 2001
|
From ed920ea2ae1cc1214b42b82a5149758dbec941a5 Mon Sep 17 00:00:00 2001
|
||||||
From: =?UTF-8?q?Ond=C5=99ej=20Sur=C3=BD?= <ondrej@isc.org>
|
From: =?UTF-8?q?Ond=C5=99ej=20Sur=C3=BD?= <ondrej@isc.org>
|
||||||
Date: Tue, 30 May 2023 08:46:17 +0200
|
Date: Tue, 30 May 2023 08:46:17 +0200
|
||||||
Subject: [PATCH] Improve RBT overmem cache cleaning
|
Subject: [PATCH] Improve RBT overmem cache cleaning
|
||||||
@ -25,24 +25,26 @@ cache going over the configured memory limit (`max-cache-size`).
|
|||||||
|
|
||||||
Additionally, refactor the overmem_purge() function to reduce for-loop
|
Additionally, refactor the overmem_purge() function to reduce for-loop
|
||||||
nesting for readability.
|
nesting for readability.
|
||||||
|
|
||||||
|
(cherry picked from commit f1d9e9ee3859976f403914d20ad2a10855343702)
|
||||||
---
|
---
|
||||||
lib/dns/rbtdb.c | 109 +++++++++++++++++++++++++++++-------------------
|
lib/dns/rbtdb.c | 105 ++++++++++++++++++++++++++++++------------------
|
||||||
1 file changed, 67 insertions(+), 42 deletions(-)
|
1 file changed, 65 insertions(+), 40 deletions(-)
|
||||||
|
|
||||||
diff --git a/lib/dns/rbtdb.c b/lib/dns/rbtdb.c
|
diff --git a/lib/dns/rbtdb.c b/lib/dns/rbtdb.c
|
||||||
index 11203e4..cc40eae 100644
|
index 51178cc877..75f97f5550 100644
|
||||||
--- a/lib/dns/rbtdb.c
|
--- a/lib/dns/rbtdb.c
|
||||||
+++ b/lib/dns/rbtdb.c
|
+++ b/lib/dns/rbtdb.c
|
||||||
@@ -834,7 +834,7 @@ static void update_header(dns_rbtdb_t *rbtdb, rdatasetheader_t *header,
|
@@ -599,7 +599,7 @@ static void
|
||||||
static void expire_header(dns_rbtdb_t *rbtdb, rdatasetheader_t *header,
|
expire_header(dns_rbtdb_t *rbtdb, rdatasetheader_t *header, bool tree_locked,
|
||||||
bool tree_locked, expire_t reason);
|
expire_t reason);
|
||||||
static void overmem_purge(dns_rbtdb_t *rbtdb, unsigned int locknum_start,
|
static void
|
||||||
- isc_stdtime_t now, bool tree_locked);
|
-overmem_purge(dns_rbtdb_t *rbtdb, unsigned int locknum_start, isc_stdtime_t now,
|
||||||
+ size_t purgesize, bool tree_locked);
|
+overmem_purge(dns_rbtdb_t *rbtdb, unsigned int locknum_start, size_t purgesize,
|
||||||
static isc_result_t resign_insert(dns_rbtdb_t *rbtdb, int idx,
|
bool tree_locked);
|
||||||
rdatasetheader_t *newheader);
|
static isc_result_t
|
||||||
static void resign_delete(dns_rbtdb_t *rbtdb, rbtdb_version_t *version,
|
resign_insert(dns_rbtdb_t *rbtdb, int idx, rdatasetheader_t *newheader);
|
||||||
@@ -6937,6 +6937,16 @@ addclosest(dns_rbtdb_t *rbtdb, rdatasetheader_t *newheader,
|
@@ -6802,6 +6802,16 @@ cleanup:
|
||||||
|
|
||||||
static dns_dbmethods_t zone_methods;
|
static dns_dbmethods_t zone_methods;
|
||||||
|
|
||||||
@ -59,23 +61,24 @@ index 11203e4..cc40eae 100644
|
|||||||
static isc_result_t
|
static isc_result_t
|
||||||
addrdataset(dns_db_t *db, dns_dbnode_t *node, dns_dbversion_t *version,
|
addrdataset(dns_db_t *db, dns_dbnode_t *node, dns_dbversion_t *version,
|
||||||
isc_stdtime_t now, dns_rdataset_t *rdataset, unsigned int options,
|
isc_stdtime_t now, dns_rdataset_t *rdataset, unsigned int options,
|
||||||
@@ -7091,7 +7101,8 @@ addrdataset(dns_db_t *db, dns_dbnode_t *node, dns_dbversion_t *version,
|
@@ -6965,7 +6975,8 @@ addrdataset(dns_db_t *db, dns_dbnode_t *node, dns_dbversion_t *version,
|
||||||
}
|
}
|
||||||
|
|
||||||
if (cache_is_overmem)
|
if (cache_is_overmem) {
|
||||||
- overmem_purge(rbtdb, rbtnode->locknum, now, tree_locked);
|
- overmem_purge(rbtdb, rbtnode->locknum, now, tree_locked);
|
||||||
+ overmem_purge(rbtdb, rbtnode->locknum, rdataset_size(newheader),
|
+ overmem_purge(rbtdb, rbtnode->locknum, rdataset_size(newheader),
|
||||||
+ tree_locked);
|
+ tree_locked);
|
||||||
|
}
|
||||||
|
|
||||||
NODE_LOCK(&rbtdb->node_locks[rbtnode->locknum].lock,
|
NODE_LOCK(&rbtdb->node_locks[rbtnode->locknum].lock,
|
||||||
isc_rwlocktype_write);
|
@@ -6984,10 +6995,18 @@ addrdataset(dns_db_t *db, dns_dbnode_t *node, dns_dbversion_t *version,
|
||||||
@@ -7106,9 +7117,19 @@ addrdataset(dns_db_t *db, dns_dbnode_t *node, dns_dbversion_t *version,
|
}
|
||||||
cleanup_dead_nodes(rbtdb, rbtnode->locknum);
|
|
||||||
|
|
||||||
header = isc_heap_element(rbtdb->heaps[rbtnode->locknum], 1);
|
header = isc_heap_element(rbtdb->heaps[rbtnode->locknum], 1);
|
||||||
- if (header && header->rdh_ttl < now - RBTDB_VIRTUAL)
|
- if (header != NULL && header->rdh_ttl + rbtdb->serve_stale_ttl <
|
||||||
- expire_header(rbtdb, header, tree_locked,
|
- now - RBTDB_VIRTUAL)
|
||||||
- expire_ttl);
|
- {
|
||||||
|
- expire_header(rbtdb, header, tree_locked, expire_ttl);
|
||||||
+ if (header != NULL) {
|
+ if (header != NULL) {
|
||||||
+ dns_ttl_t rdh_ttl = header->rdh_ttl;
|
+ dns_ttl_t rdh_ttl = header->rdh_ttl;
|
||||||
+
|
+
|
||||||
@ -88,11 +91,10 @@ index 11203e4..cc40eae 100644
|
|||||||
+ expire_header(rbtdb, header, tree_locked,
|
+ expire_header(rbtdb, header, tree_locked,
|
||||||
+ expire_ttl);
|
+ expire_ttl);
|
||||||
+ }
|
+ }
|
||||||
+ }
|
}
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* If we've been holding a write lock on the tree just for
|
@@ -10531,52 +10550,58 @@ update_header(dns_rbtdb_t *rbtdb, rdatasetheader_t *header, isc_stdtime_t now) {
|
||||||
@@ -10643,54 +10664,58 @@ update_header(dns_rbtdb_t *rbtdb, rdatasetheader_t *header,
|
|
||||||
ISC_LIST_PREPEND(rbtdb->rdatasets[header->node->locknum], header, link);
|
ISC_LIST_PREPEND(rbtdb->rdatasets[header->node->locknum], header, link);
|
||||||
}
|
}
|
||||||
|
|
||||||
@ -142,11 +144,9 @@ index 11203e4..cc40eae 100644
|
|||||||
+ * we're adding A and AAAA glue records of the same NS name).
|
+ * we're adding A and AAAA glue records of the same NS name).
|
||||||
*/
|
*/
|
||||||
static void
|
static void
|
||||||
-overmem_purge(dns_rbtdb_t *rbtdb, unsigned int locknum_start,
|
-overmem_purge(dns_rbtdb_t *rbtdb, unsigned int locknum_start, isc_stdtime_t now,
|
||||||
- isc_stdtime_t now, bool tree_locked)
|
|
||||||
+overmem_purge(dns_rbtdb_t *rbtdb, unsigned int locknum_start, size_t purgesize,
|
+overmem_purge(dns_rbtdb_t *rbtdb, unsigned int locknum_start, size_t purgesize,
|
||||||
+ bool tree_locked)
|
bool tree_locked) {
|
||||||
{
|
|
||||||
- rdatasetheader_t *header, *header_prev;
|
- rdatasetheader_t *header, *header_prev;
|
||||||
unsigned int locknum;
|
unsigned int locknum;
|
||||||
- int purgecount = 2;
|
- int purgecount = 2;
|
||||||
@ -155,20 +155,20 @@ index 11203e4..cc40eae 100644
|
|||||||
for (locknum = (locknum_start + 1) % rbtdb->node_lock_count;
|
for (locknum = (locknum_start + 1) % rbtdb->node_lock_count;
|
||||||
- locknum != locknum_start && purgecount > 0;
|
- locknum != locknum_start && purgecount > 0;
|
||||||
+ locknum != locknum_start && purged <= purgesize;
|
+ locknum != locknum_start && purged <= purgesize;
|
||||||
locknum = (locknum + 1) % rbtdb->node_lock_count) {
|
locknum = (locknum + 1) % rbtdb->node_lock_count)
|
||||||
|
{
|
||||||
NODE_LOCK(&rbtdb->node_locks[locknum].lock,
|
NODE_LOCK(&rbtdb->node_locks[locknum].lock,
|
||||||
isc_rwlocktype_write);
|
isc_rwlocktype_write);
|
||||||
|
|
||||||
- header = isc_heap_element(rbtdb->heaps[locknum], 1);
|
- header = isc_heap_element(rbtdb->heaps[locknum], 1);
|
||||||
- if (header && header->rdh_ttl < now - RBTDB_VIRTUAL) {
|
- if (header && header->rdh_ttl < now - RBTDB_VIRTUAL) {
|
||||||
- expire_header(rbtdb, header, tree_locked,
|
- expire_header(rbtdb, header, tree_locked, expire_ttl);
|
||||||
- expire_ttl);
|
|
||||||
- purgecount--;
|
- purgecount--;
|
||||||
- }
|
- }
|
||||||
-
|
-
|
||||||
- for (header = ISC_LIST_TAIL(rbtdb->rdatasets[locknum]);
|
- for (header = ISC_LIST_TAIL(rbtdb->rdatasets[locknum]);
|
||||||
- header != NULL && purgecount > 0;
|
- header != NULL && purgecount > 0; header = header_prev)
|
||||||
- header = header_prev) {
|
- {
|
||||||
- header_prev = ISC_LIST_PREV(header, link);
|
- header_prev = ISC_LIST_PREV(header, link);
|
||||||
- /*
|
- /*
|
||||||
- * Unlink the entry at this point to avoid checking it
|
- * Unlink the entry at this point to avoid checking it
|
||||||
@ -179,15 +179,14 @@ index 11203e4..cc40eae 100644
|
|||||||
- */
|
- */
|
||||||
- ISC_LIST_UNLINK(rbtdb->rdatasets[locknum], header,
|
- ISC_LIST_UNLINK(rbtdb->rdatasets[locknum], header,
|
||||||
- link);
|
- link);
|
||||||
- expire_header(rbtdb, header, tree_locked,
|
- expire_header(rbtdb, header, tree_locked, expire_lru);
|
||||||
- expire_lru);
|
|
||||||
- purgecount--;
|
- purgecount--;
|
||||||
- }
|
- }
|
||||||
+ purged += expire_lru_headers(rbtdb, locknum, purgesize - purged,
|
+ purged += expire_lru_headers(rbtdb, locknum, purgesize - purged,
|
||||||
+ tree_locked);
|
+ tree_locked);
|
||||||
|
|
||||||
NODE_UNLOCK(&rbtdb->node_locks[locknum].lock,
|
NODE_UNLOCK(&rbtdb->node_locks[locknum].lock,
|
||||||
isc_rwlocktype_write);
|
isc_rwlocktype_write);
|
||||||
--
|
--
|
||||||
2.40.1
|
2.40.1
|
||||||
|
|
||||||
37
SOURCES/bind-9.16-CVE-2023-2911-1.patch
Normal file
37
SOURCES/bind-9.16-CVE-2023-2911-1.patch
Normal file
@ -0,0 +1,37 @@
|
|||||||
|
From e73ecbf039c3b2cd33dd2926691a8a346c9ca574 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Matthijs Mekking <matthijs@isc.org>
|
||||||
|
Date: Tue, 2 Aug 2022 14:21:40 +0200
|
||||||
|
Subject: [PATCH 1/3] Don't enable serve-stale on duplicate queries
|
||||||
|
|
||||||
|
When checking if we should enable serve-stale, add an early out case
|
||||||
|
when the result is an error signalling a duplicate query or a query
|
||||||
|
that would be dropped.
|
||||||
|
|
||||||
|
(cherry picked from commit 059a4c2f4d9d3cff371842f43208d021509314fa)
|
||||||
|
(cherry picked from commit dd7dde5743715dc0dec2defbb92b1a8637977bf9)
|
||||||
|
---
|
||||||
|
lib/ns/query.c | 8 ++++++++
|
||||||
|
1 file changed, 8 insertions(+)
|
||||||
|
|
||||||
|
diff --git a/lib/ns/query.c b/lib/ns/query.c
|
||||||
|
index 4f61374e2c..c169e22bf4 100644
|
||||||
|
--- a/lib/ns/query.c
|
||||||
|
+++ b/lib/ns/query.c
|
||||||
|
@@ -7205,6 +7205,14 @@ query_usestale(query_ctx_t *qctx, isc_result_t result) {
|
||||||
|
return (false);
|
||||||
|
}
|
||||||
|
|
||||||
|
+ if (result == DNS_R_DUPLICATE || result == DNS_R_DROP) {
|
||||||
|
+ /*
|
||||||
|
+ * Don't enable serve-stale if the result signals a duplicate
|
||||||
|
+ * query or query that is being dropped.
|
||||||
|
+ */
|
||||||
|
+ return (false);
|
||||||
|
+ }
|
||||||
|
+
|
||||||
|
qctx_clean(qctx);
|
||||||
|
qctx_freedata(qctx);
|
||||||
|
|
||||||
|
--
|
||||||
|
2.40.1
|
||||||
|
|
||||||
72
SOURCES/bind-9.16-CVE-2023-2911-2.patch
Normal file
72
SOURCES/bind-9.16-CVE-2023-2911-2.patch
Normal file
@ -0,0 +1,72 @@
|
|||||||
|
From 589c06568e3036bfe713d42b53c8e88005ce17e4 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Evan Hunt <each@isc.org>
|
||||||
|
Date: Thu, 25 May 2023 23:53:50 -0700
|
||||||
|
Subject: [PATCH 2/3] Stale answer lookups could loop when over recursion quota
|
||||||
|
|
||||||
|
When a query was aborted because of the recursion quota being exceeded,
|
||||||
|
but triggered a stale answer response and a stale data refresh query,
|
||||||
|
it could cause named to loop back where we are iterating and following
|
||||||
|
a delegation. Having no good answer in cache, we would fall back to
|
||||||
|
using serve-stale again, use the stale data, try to refresh the RRset,
|
||||||
|
and loop back again, without ever terminating until crashing due to
|
||||||
|
stack overflow.
|
||||||
|
|
||||||
|
This happens because in the functions 'query_notfound()' and
|
||||||
|
'query_delegation_recurse()', we check whether we can fall back to
|
||||||
|
serving stale data. We shouldn't do so if we are already refreshing
|
||||||
|
an RRset due to having prioritized stale data in cache.
|
||||||
|
|
||||||
|
In other words, we need to add an extra check to 'query_usestale()' to
|
||||||
|
disallow serving stale data if we are currently refreshing a stale
|
||||||
|
RRset.
|
||||||
|
|
||||||
|
As an additional mitigation to prevent looping, we now use the result
|
||||||
|
code ISC_R_ALREADYRUNNING rather than ISC_R_FAILURE when a recursion
|
||||||
|
loop is encountered, and we check for that condition in
|
||||||
|
'query_usestale()' as well.
|
||||||
|
|
||||||
|
(cherry picked from commit 0101e28f91fb36b6a16a0049d3b3e2b7846f23f0)
|
||||||
|
---
|
||||||
|
lib/ns/query.c | 17 ++++++++++++++---
|
||||||
|
1 file changed, 14 insertions(+), 3 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/lib/ns/query.c b/lib/ns/query.c
|
||||||
|
index c169e22bf4..1eb662ea4d 100644
|
||||||
|
--- a/lib/ns/query.c
|
||||||
|
+++ b/lib/ns/query.c
|
||||||
|
@@ -6229,7 +6229,7 @@ ns_query_recurse(ns_client_t *client, dns_rdatatype_t qtype, dns_name_t *qname,
|
||||||
|
if (recparam_match(&client->query.recparam, qtype, qname, qdomain)) {
|
||||||
|
ns_client_log(client, NS_LOGCATEGORY_CLIENT, NS_LOGMODULE_QUERY,
|
||||||
|
ISC_LOG_INFO, "recursion loop detected");
|
||||||
|
- return (ISC_R_FAILURE);
|
||||||
|
+ return (ISC_R_ALREADYRUNNING);
|
||||||
|
}
|
||||||
|
|
||||||
|
recparam_update(&client->query.recparam, qtype, qname, qdomain);
|
||||||
|
@@ -7205,10 +7205,21 @@ query_usestale(query_ctx_t *qctx, isc_result_t result) {
|
||||||
|
return (false);
|
||||||
|
}
|
||||||
|
|
||||||
|
- if (result == DNS_R_DUPLICATE || result == DNS_R_DROP) {
|
||||||
|
+ if (qctx->refresh_rrset) {
|
||||||
|
+ /*
|
||||||
|
+ * This is a refreshing query, we have already prioritized
|
||||||
|
+ * stale data, so don't enable serve-stale again.
|
||||||
|
+ */
|
||||||
|
+ return (false);
|
||||||
|
+ }
|
||||||
|
+
|
||||||
|
+ if (result == DNS_R_DUPLICATE || result == DNS_R_DROP ||
|
||||||
|
+ result == ISC_R_ALREADYRUNNING)
|
||||||
|
+ {
|
||||||
|
/*
|
||||||
|
* Don't enable serve-stale if the result signals a duplicate
|
||||||
|
- * query or query that is being dropped.
|
||||||
|
+ * query or a query that is being dropped or can't proceed
|
||||||
|
+ * because of a recursion loop.
|
||||||
|
*/
|
||||||
|
return (false);
|
||||||
|
}
|
||||||
|
--
|
||||||
|
2.40.1
|
||||||
|
|
||||||
60
SOURCES/bind-9.16-CVE-2023-2911-3.patch
Normal file
60
SOURCES/bind-9.16-CVE-2023-2911-3.patch
Normal file
@ -0,0 +1,60 @@
|
|||||||
|
From c20e9d30bae58d3120aa7c6a0e5dcae0e7e93dbd Mon Sep 17 00:00:00 2001
|
||||||
|
From: Matthijs Mekking <matthijs@isc.org>
|
||||||
|
Date: Thu, 1 Jun 2023 10:03:48 +0200
|
||||||
|
Subject: [PATCH 3/3] Fix serve-stale hang at shutdown
|
||||||
|
|
||||||
|
The 'refresh_rrset' variable is used to determine if we can detach from
|
||||||
|
the client. This can cause a hang on shutdown. To fix this, move setting
|
||||||
|
of the 'nodetach' variable up to where 'refresh_rrset' is set (in
|
||||||
|
query_lookup(), and thus not in ns_query_done()), and set it to false
|
||||||
|
when actually refreshing the RRset, so that when this lookup is
|
||||||
|
completed, the client will be detached.
|
||||||
|
|
||||||
|
(cherry picked from commit c003c5bc3c68f3e513654b6689e1f60280d14844)
|
||||||
|
---
|
||||||
|
lib/ns/query.c | 13 ++++++++-----
|
||||||
|
1 file changed, 8 insertions(+), 5 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/lib/ns/query.c b/lib/ns/query.c
|
||||||
|
index 1eb662ea4d..4fe3e30f45 100644
|
||||||
|
--- a/lib/ns/query.c
|
||||||
|
+++ b/lib/ns/query.c
|
||||||
|
@@ -5644,6 +5644,7 @@ query_refresh_rrset(query_ctx_t *orig_qctx) {
|
||||||
|
qctx.client->query.dboptions &= ~(DNS_DBFIND_STALETIMEOUT |
|
||||||
|
DNS_DBFIND_STALEOK |
|
||||||
|
DNS_DBFIND_STALEENABLED);
|
||||||
|
+ qctx.client->nodetach = false;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* We'll need some resources...
|
||||||
|
@@ -5868,7 +5869,14 @@ query_lookup(query_ctx_t *qctx) {
|
||||||
|
"%s stale answer used, an attempt to "
|
||||||
|
"refresh the RRset will still be made",
|
||||||
|
namebuf);
|
||||||
|
+
|
||||||
|
qctx->refresh_rrset = STALE(qctx->rdataset);
|
||||||
|
+
|
||||||
|
+ /*
|
||||||
|
+ * If we are refreshing the RRSet, we must not
|
||||||
|
+ * detach from the client in query_send().
|
||||||
|
+ */
|
||||||
|
+ qctx->client->nodetach = qctx->refresh_rrset;
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
/*
|
||||||
|
@@ -11469,12 +11477,7 @@ ns_query_done(query_ctx_t *qctx) {
|
||||||
|
/*
|
||||||
|
* Client may have been detached after query_send(), so
|
||||||
|
* we test and store the flag state here, for safety.
|
||||||
|
- * If we are refreshing the RRSet, we must not detach from the client
|
||||||
|
- * in the query_send(), so we need to override the flag.
|
||||||
|
*/
|
||||||
|
- if (qctx->refresh_rrset) {
|
||||||
|
- qctx->client->nodetach = true;
|
||||||
|
- }
|
||||||
|
nodetach = qctx->client->nodetach;
|
||||||
|
query_send(qctx->client);
|
||||||
|
|
||||||
|
--
|
||||||
|
2.40.1
|
||||||
|
|
||||||
@ -1,23 +1,24 @@
|
|||||||
From 3883ec072e5feed1237dc864854ab95ded7302d6 Mon Sep 17 00:00:00 2001
|
From b137e12dc8118cddee20e372e480a495585e72b6 Mon Sep 17 00:00:00 2001
|
||||||
From: Petr Mensik <pemensik@redhat.com>
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
Date: Tue, 19 Sep 2023 13:14:52 +0200
|
Date: Tue, 19 Sep 2023 12:44:31 +0200
|
||||||
Subject: [PATCH] Backport of CVE-2023-3341 fix
|
Subject: [PATCH] Fix CVE-2023-3341
|
||||||
|
|
||||||
Taken from BIND 9.16.44 change.
|
6245. [security] Limit the amount of recursion that can be performed
|
||||||
|
by isccc_cc_fromwire. (CVE-2023-3341) [GL #4152]
|
||||||
---
|
---
|
||||||
lib/isccc/cc.c | 36 +++++++++++++++++++++++---------
|
lib/isccc/cc.c | 39 ++++++++++++++++++++++++--------
|
||||||
lib/isccc/include/isccc/result.h | 4 +++-
|
lib/isccc/include/isccc/result.h | 4 +++-
|
||||||
lib/isccc/result.c | 4 +++-
|
lib/isccc/result.c | 4 +++-
|
||||||
3 files changed, 32 insertions(+), 12 deletions(-)
|
3 files changed, 35 insertions(+), 12 deletions(-)
|
||||||
|
|
||||||
diff --git a/lib/isccc/cc.c b/lib/isccc/cc.c
|
diff --git a/lib/isccc/cc.c b/lib/isccc/cc.c
|
||||||
index 463a053..a54e60c 100644
|
index 0be28b9057..3744d0f037 100644
|
||||||
--- a/lib/isccc/cc.c
|
--- a/lib/isccc/cc.c
|
||||||
+++ b/lib/isccc/cc.c
|
+++ b/lib/isccc/cc.c
|
||||||
@@ -53,6 +53,10 @@
|
@@ -50,6 +50,10 @@
|
||||||
|
|
||||||
#define MAX_TAGS 256
|
#define MAX_TAGS 256
|
||||||
#define DUP_LIFETIME 900
|
#define DUP_LIFETIME 900
|
||||||
+#ifndef ISCCC_MAXDEPTH
|
+#ifndef ISCCC_MAXDEPTH
|
||||||
+#define ISCCC_MAXDEPTH \
|
+#define ISCCC_MAXDEPTH \
|
||||||
+ 10 /* Big enough for rndc which just sends a string each way. */
|
+ 10 /* Big enough for rndc which just sends a string each way. */
|
||||||
@ -25,7 +26,7 @@ index 463a053..a54e60c 100644
|
|||||||
|
|
||||||
typedef isccc_sexpr_t *sexpr_ptr;
|
typedef isccc_sexpr_t *sexpr_ptr;
|
||||||
|
|
||||||
@@ -573,19 +577,23 @@ verify(isccc_sexpr_t *alist, unsigned char *data, unsigned int length,
|
@@ -480,19 +484,25 @@ verify(isccc_sexpr_t *alist, unsigned char *data, unsigned int length,
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
table_fromwire(isccc_region_t *source, isccc_region_t *secret,
|
table_fromwire(isccc_region_t *source, isccc_region_t *secret,
|
||||||
@ -34,11 +35,13 @@ index 463a053..a54e60c 100644
|
|||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
-list_fromwire(isccc_region_t *source, isccc_sexpr_t **listp);
|
-list_fromwire(isccc_region_t *source, isccc_sexpr_t **listp);
|
||||||
+list_fromwire(isccc_region_t *source, unsigned int depth, isccc_sexpr_t **listp);
|
+list_fromwire(isccc_region_t *source, unsigned int depth,
|
||||||
|
+ isccc_sexpr_t **listp);
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
-value_fromwire(isccc_region_t *source, isccc_sexpr_t **valuep) {
|
-value_fromwire(isccc_region_t *source, isccc_sexpr_t **valuep) {
|
||||||
+value_fromwire(isccc_region_t *source, unsigned int depth, isccc_sexpr_t **valuep) {
|
+value_fromwire(isccc_region_t *source, unsigned int depth,
|
||||||
|
+ isccc_sexpr_t **valuep) {
|
||||||
unsigned int msgtype;
|
unsigned int msgtype;
|
||||||
uint32_t len;
|
uint32_t len;
|
||||||
isccc_sexpr_t *value;
|
isccc_sexpr_t *value;
|
||||||
@ -49,31 +52,31 @@ index 463a053..a54e60c 100644
|
|||||||
+ return (ISCCC_R_MAXDEPTH);
|
+ return (ISCCC_R_MAXDEPTH);
|
||||||
+ }
|
+ }
|
||||||
+
|
+
|
||||||
if (REGION_SIZE(*source) < 1 + 4)
|
if (REGION_SIZE(*source) < 1 + 4) {
|
||||||
return (ISC_R_UNEXPECTEDEND);
|
return (ISC_R_UNEXPECTEDEND);
|
||||||
GET8(msgtype, source->rstart);
|
}
|
||||||
@@ -603,9 +611,9 @@ value_fromwire(isccc_region_t *source, isccc_sexpr_t **valuep) {
|
@@ -513,9 +523,9 @@ value_fromwire(isccc_region_t *source, isccc_sexpr_t **valuep) {
|
||||||
} else
|
|
||||||
result = ISC_R_NOMEMORY;
|
result = ISC_R_NOMEMORY;
|
||||||
} else if (msgtype == ISCCC_CCMSGTYPE_TABLE)
|
}
|
||||||
|
} else if (msgtype == ISCCC_CCMSGTYPE_TABLE) {
|
||||||
- result = table_fromwire(&active, NULL, 0, valuep);
|
- result = table_fromwire(&active, NULL, 0, valuep);
|
||||||
+ result = table_fromwire(&active, NULL, 0, depth + 1, valuep);
|
+ result = table_fromwire(&active, NULL, 0, depth + 1, valuep);
|
||||||
else if (msgtype == ISCCC_CCMSGTYPE_LIST)
|
} else if (msgtype == ISCCC_CCMSGTYPE_LIST) {
|
||||||
- result = list_fromwire(&active, valuep);
|
- result = list_fromwire(&active, valuep);
|
||||||
+ result = list_fromwire(&active, depth + 1, valuep);
|
+ result = list_fromwire(&active, depth + 1, valuep);
|
||||||
else
|
} else {
|
||||||
result = ISCCC_R_SYNTAX;
|
result = ISCCC_R_SYNTAX;
|
||||||
|
}
|
||||||
@@ -614,7 +622,7 @@ value_fromwire(isccc_region_t *source, isccc_sexpr_t **valuep) {
|
@@ -525,7 +535,7 @@ value_fromwire(isccc_region_t *source, isccc_sexpr_t **valuep) {
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
table_fromwire(isccc_region_t *source, isccc_region_t *secret,
|
table_fromwire(isccc_region_t *source, isccc_region_t *secret,
|
||||||
- uint32_t algorithm, isccc_sexpr_t **alistp)
|
- uint32_t algorithm, isccc_sexpr_t **alistp) {
|
||||||
+ uint32_t algorithm, unsigned int depth, isccc_sexpr_t **alistp)
|
+ uint32_t algorithm, unsigned int depth, isccc_sexpr_t **alistp) {
|
||||||
{
|
|
||||||
char key[256];
|
char key[256];
|
||||||
uint32_t len;
|
uint32_t len;
|
||||||
@@ -625,6 +633,10 @@ table_fromwire(isccc_region_t *source, isccc_region_t *secret,
|
isc_result_t result;
|
||||||
|
@@ -535,6 +545,10 @@ table_fromwire(isccc_region_t *source, isccc_region_t *secret,
|
||||||
|
|
||||||
REQUIRE(alistp != NULL && *alistp == NULL);
|
REQUIRE(alistp != NULL && *alistp == NULL);
|
||||||
|
|
||||||
@ -84,21 +87,22 @@ index 463a053..a54e60c 100644
|
|||||||
checksum_rstart = NULL;
|
checksum_rstart = NULL;
|
||||||
first_tag = true;
|
first_tag = true;
|
||||||
alist = isccc_alist_create();
|
alist = isccc_alist_create();
|
||||||
@@ -640,7 +652,7 @@ table_fromwire(isccc_region_t *source, isccc_region_t *secret,
|
@@ -551,7 +565,7 @@ table_fromwire(isccc_region_t *source, isccc_region_t *secret,
|
||||||
GET_MEM(key, len, source->rstart);
|
GET_MEM(key, len, source->rstart);
|
||||||
key[len] = '\0'; /* Ensure NUL termination. */
|
key[len] = '\0'; /* Ensure NUL termination. */
|
||||||
value = NULL;
|
value = NULL;
|
||||||
- result = value_fromwire(source, &value);
|
- result = value_fromwire(source, &value);
|
||||||
+ result = value_fromwire(source, depth + 1, &value);
|
+ result = value_fromwire(source, depth + 1, &value);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
goto bad;
|
goto bad;
|
||||||
if (isccc_alist_define(alist, key, value) == NULL) {
|
}
|
||||||
@@ -673,14 +685,18 @@ table_fromwire(isccc_region_t *source, isccc_region_t *secret,
|
@@ -589,14 +603,19 @@ bad:
|
||||||
}
|
}
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
-list_fromwire(isccc_region_t *source, isccc_sexpr_t **listp) {
|
-list_fromwire(isccc_region_t *source, isccc_sexpr_t **listp) {
|
||||||
+list_fromwire(isccc_region_t *source, unsigned int depth, isccc_sexpr_t **listp) {
|
+list_fromwire(isccc_region_t *source, unsigned int depth,
|
||||||
|
+ isccc_sexpr_t **listp) {
|
||||||
isccc_sexpr_t *list, *value;
|
isccc_sexpr_t *list, *value;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
|
|
||||||
@ -114,9 +118,9 @@ index 463a053..a54e60c 100644
|
|||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
isccc_sexpr_free(&list);
|
isccc_sexpr_free(&list);
|
||||||
return (result);
|
return (result);
|
||||||
@@ -711,7 +727,7 @@ isccc_cc_fromwire(isccc_region_t *source, isccc_sexpr_t **alistp,
|
@@ -628,7 +647,7 @@ isccc_cc_fromwire(isccc_region_t *source, isccc_sexpr_t **alistp,
|
||||||
if (version != 1)
|
|
||||||
return (ISCCC_R_UNKNOWNVERSION);
|
return (ISCCC_R_UNKNOWNVERSION);
|
||||||
|
}
|
||||||
|
|
||||||
- return (table_fromwire(source, secret, algorithm, alistp));
|
- return (table_fromwire(source, secret, algorithm, alistp));
|
||||||
+ return (table_fromwire(source, secret, algorithm, 0, alistp));
|
+ return (table_fromwire(source, secret, algorithm, 0, alistp));
|
||||||
@ -124,43 +128,41 @@ index 463a053..a54e60c 100644
|
|||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
diff --git a/lib/isccc/include/isccc/result.h b/lib/isccc/include/isccc/result.h
|
diff --git a/lib/isccc/include/isccc/result.h b/lib/isccc/include/isccc/result.h
|
||||||
index 6c79dd7..b30b08a 100644
|
index 5346babefc..5b6a876d1c 100644
|
||||||
--- a/lib/isccc/include/isccc/result.h
|
--- a/lib/isccc/include/isccc/result.h
|
||||||
+++ b/lib/isccc/include/isccc/result.h
|
+++ b/lib/isccc/include/isccc/result.h
|
||||||
@@ -47,8 +47,10 @@
|
@@ -46,8 +46,10 @@
|
||||||
#define ISCCC_R_CLOCKSKEW (ISC_RESULTCLASS_ISCCC + 4)
|
#define ISCCC_R_CLOCKSKEW (ISC_RESULTCLASS_ISCCC + 4)
|
||||||
/*% Duplicate */
|
/*% Duplicate */
|
||||||
#define ISCCC_R_DUPLICATE (ISC_RESULTCLASS_ISCCC + 5)
|
#define ISCCC_R_DUPLICATE (ISC_RESULTCLASS_ISCCC + 5)
|
||||||
+/*% Maximum recursion depth */
|
+/*% Maximum recursion depth */
|
||||||
+#define ISCCC_R_MAXDEPTH (ISC_RESULTCLASS_ISCCC + 6)
|
+#define ISCCC_R_MAXDEPTH (ISC_RESULTCLASS_ISCCC + 6)
|
||||||
|
|
||||||
-#define ISCCC_R_NRESULTS 6 /*%< Number of results */
|
-#define ISCCC_R_NRESULTS 6 /*%< Number of results */
|
||||||
+#define ISCCC_R_NRESULTS 7 /*%< Number of results */
|
+#define ISCCC_R_NRESULTS 7 /*%< Number of results */
|
||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
ISC_LANG_BEGINDECLS
|
||||||
|
|
||||||
diff --git a/lib/isccc/result.c b/lib/isccc/result.c
|
diff --git a/lib/isccc/result.c b/lib/isccc/result.c
|
||||||
index 8419bbb..a3a3b9a 100644
|
index 9285435209..1956cb1655 100644
|
||||||
--- a/lib/isccc/result.c
|
--- a/lib/isccc/result.c
|
||||||
+++ b/lib/isccc/result.c
|
+++ b/lib/isccc/result.c
|
||||||
@@ -40,7 +40,8 @@ static const char *text[ISCCC_R_NRESULTS] = {
|
@@ -36,12 +36,14 @@ static const char *text[ISCCC_R_NRESULTS] = {
|
||||||
"bad auth", /* 3 */
|
"bad auth", /* 3 */
|
||||||
"expired", /* 4 */
|
"expired", /* 4 */
|
||||||
"clock skew", /* 5 */
|
"clock skew", /* 5 */
|
||||||
- "duplicate" /* 6 */
|
- "duplicate" /* 6 */
|
||||||
+ "duplicate", /* 6 */
|
+ "duplicate", /* 6 */
|
||||||
+ "max depth", /* 7 */
|
+ "max depth" /* 7 */
|
||||||
};
|
};
|
||||||
|
|
||||||
static const char *ids[ISCCC_R_NRESULTS] = {
|
static const char *ids[ISCCC_R_NRESULTS] = {
|
||||||
@@ -50,6 +51,7 @@ static const char *ids[ISCCC_R_NRESULTS] = {
|
"ISCCC_R_UNKNOWNVERSION", "ISCCC_R_SYNTAX", "ISCCC_R_BADAUTH",
|
||||||
"ISCCC_R_EXPIRED",
|
"ISCCC_R_EXPIRED", "ISCCC_R_CLOCKSKEW", "ISCCC_R_DUPLICATE",
|
||||||
"ISCCC_R_CLOCKSKEW",
|
|
||||||
"ISCCC_R_DUPLICATE",
|
|
||||||
+ "ISCCC_R_MAXDEPTH"
|
+ "ISCCC_R_MAXDEPTH"
|
||||||
};
|
};
|
||||||
|
|
||||||
#define ISCCC_RESULT_RESULTSET 2
|
#define ISCCC_RESULT_RESULTSET 2
|
||||||
--
|
--
|
||||||
2.41.0
|
2.41.0
|
||||||
|
|
||||||
|
|||||||
88
SOURCES/bind-9.16-CVE-2023-4408-test1.patch
Normal file
88
SOURCES/bind-9.16-CVE-2023-4408-test1.patch
Normal file
@ -0,0 +1,88 @@
|
|||||||
|
From d258422d3e653621ce6340ba9af0153f8d4e8c07 Mon Sep 17 00:00:00 2001
|
||||||
|
From: =?UTF-8?q?Ond=C5=99ej=20Sur=C3=BD?= <ondrej@isc.org>
|
||||||
|
Date: Sun, 11 Feb 2024 00:49:32 +0100
|
||||||
|
Subject: [PATCH] Test case insensitive matching in isc_ht hash table
|
||||||
|
implementation
|
||||||
|
|
||||||
|
The case insensitive matching in isc_ht was basically completely broken
|
||||||
|
as only the hashvalue computation was case insensitive, but the key
|
||||||
|
comparison was always case sensitive.
|
||||||
|
|
||||||
|
Import only test part from upstream.
|
||||||
|
|
||||||
|
(cherry picked from commit 175655b771fd17b06dfb8cfb29eaadf0f3b6a8b5)
|
||||||
|
(cherry picked from upstream commit f493a8394102b0aeb101d5dc2f963004c8741175)
|
||||||
|
---
|
||||||
|
lib/isc/tests/ht_test.c | 53 +++++++++++++++++++++++++++++++++++++++++
|
||||||
|
1 file changed, 53 insertions(+)
|
||||||
|
|
||||||
|
diff --git a/lib/isc/tests/ht_test.c b/lib/isc/tests/ht_test.c
|
||||||
|
index 74d95c1..65502b5 100644
|
||||||
|
--- a/lib/isc/tests/ht_test.c
|
||||||
|
+++ b/lib/isc/tests/ht_test.c
|
||||||
|
@@ -334,9 +334,62 @@ isc_ht_iterator_test(void **state) {
|
||||||
|
test_ht_iterator();
|
||||||
|
}
|
||||||
|
|
||||||
|
+static void
|
||||||
|
+isc_ht_case(void **state) {
|
||||||
|
+ UNUSED(state);
|
||||||
|
+
|
||||||
|
+ isc_ht_t *ht = NULL;
|
||||||
|
+ void *f = NULL;
|
||||||
|
+ isc_result_t result = ISC_R_UNSET;
|
||||||
|
+
|
||||||
|
+ unsigned char lower[16] = { "test case" };
|
||||||
|
+ unsigned char same[16] = { "test case" };
|
||||||
|
+ unsigned char upper[16] = { "TEST CASE" };
|
||||||
|
+ unsigned char mixed[16] = { "tEsT CaSe" };
|
||||||
|
+
|
||||||
|
+ isc_ht_init(&ht, test_mctx, 8, ISC_HT_CASE_SENSITIVE);
|
||||||
|
+ assert_non_null(ht);
|
||||||
|
+
|
||||||
|
+ result = isc_ht_add(ht, lower, 16, (void *)lower);
|
||||||
|
+ assert_int_equal(result, ISC_R_SUCCESS);
|
||||||
|
+
|
||||||
|
+ result = isc_ht_add(ht, same, 16, (void *)same);
|
||||||
|
+ assert_int_equal(result, ISC_R_EXISTS);
|
||||||
|
+
|
||||||
|
+ result = isc_ht_add(ht, upper, 16, (void *)upper);
|
||||||
|
+ assert_int_equal(result, ISC_R_SUCCESS);
|
||||||
|
+
|
||||||
|
+ result = isc_ht_find(ht, mixed, 16, &f);
|
||||||
|
+ assert_int_equal(result, ISC_R_NOTFOUND);
|
||||||
|
+ assert_null(f);
|
||||||
|
+
|
||||||
|
+ isc_ht_destroy(&ht);
|
||||||
|
+ assert_null(ht);
|
||||||
|
+
|
||||||
|
+ isc_ht_init(&ht, test_mctx, 8, ISC_HT_CASE_INSENSITIVE);
|
||||||
|
+ assert_non_null(ht);
|
||||||
|
+
|
||||||
|
+ result = isc_ht_add(ht, lower, 16, (void *)lower);
|
||||||
|
+ assert_int_equal(result, ISC_R_SUCCESS);
|
||||||
|
+
|
||||||
|
+ result = isc_ht_add(ht, same, 16, (void *)same);
|
||||||
|
+ assert_int_equal(result, ISC_R_EXISTS);
|
||||||
|
+
|
||||||
|
+ result = isc_ht_add(ht, upper, 16, (void *)upper);
|
||||||
|
+ assert_int_equal(result, ISC_R_EXISTS);
|
||||||
|
+
|
||||||
|
+ result = isc_ht_find(ht, mixed, 16, &f);
|
||||||
|
+ assert_int_equal(result, ISC_R_SUCCESS);
|
||||||
|
+ assert_ptr_equal(f, &lower);
|
||||||
|
+
|
||||||
|
+ isc_ht_destroy(&ht);
|
||||||
|
+ assert_null(ht);
|
||||||
|
+}
|
||||||
|
+
|
||||||
|
int
|
||||||
|
main(void) {
|
||||||
|
const struct CMUnitTest tests[] = {
|
||||||
|
+ cmocka_unit_test(isc_ht_case),
|
||||||
|
cmocka_unit_test(isc_ht_20),
|
||||||
|
cmocka_unit_test(isc_ht_8),
|
||||||
|
cmocka_unit_test(isc_ht_1),
|
||||||
|
--
|
||||||
|
2.43.0
|
||||||
|
|
||||||
75
SOURCES/bind-9.16-CVE-2023-4408-test2.patch
Normal file
75
SOURCES/bind-9.16-CVE-2023-4408-test2.patch
Normal file
@ -0,0 +1,75 @@
|
|||||||
|
From aa1b0fc4b24d26233db30c85ae3609e54e9fa6d2 Mon Sep 17 00:00:00 2001
|
||||||
|
From: =?UTF-8?q?Ond=C5=99ej=20Sur=C3=BD?= <ondrej@isc.org>
|
||||||
|
Date: Sun, 11 Feb 2024 09:13:43 +0100
|
||||||
|
Subject: [PATCH] Add a system test for mixed-case data for the same owner
|
||||||
|
|
||||||
|
We were missing a test where a single owner name would have multiple
|
||||||
|
types with a different case. The generated RRSIGs and NSEC records will
|
||||||
|
then have different case than the signed records and message parser have
|
||||||
|
to cope with that and treat everything as the same owner.
|
||||||
|
|
||||||
|
(cherry picked from commit a114042059ecbbc94ae0f604ca681323a75af480)
|
||||||
|
(cherry picked from upstream commit b9c10a194da3358204f5ba7d91e55332db435614)
|
||||||
|
---
|
||||||
|
bin/tests/system/dnssec/ns3/secure.example.db.in | 5 +++++
|
||||||
|
bin/tests/system/dnssec/ns3/sign.sh | 4 +++-
|
||||||
|
bin/tests/system/dnssec/tests.sh | 15 +++++++++++++++
|
||||||
|
3 files changed, 23 insertions(+), 1 deletion(-)
|
||||||
|
|
||||||
|
diff --git a/bin/tests/system/dnssec/ns3/secure.example.db.in b/bin/tests/system/dnssec/ns3/secure.example.db.in
|
||||||
|
index 27f2b24..599566e 100644
|
||||||
|
--- a/bin/tests/system/dnssec/ns3/secure.example.db.in
|
||||||
|
+++ b/bin/tests/system/dnssec/ns3/secure.example.db.in
|
||||||
|
@@ -45,3 +45,8 @@ rrsigonly A 10.0.0.29
|
||||||
|
cnameandkey CNAME @
|
||||||
|
cnamenokey CNAME @
|
||||||
|
dnameandkey DNAME @
|
||||||
|
+
|
||||||
|
+mixedcase A 10.0.0.30
|
||||||
|
+mixedCASE TXT "mixed case"
|
||||||
|
+MIXEDcase AAAA 2002::
|
||||||
|
+mIxEdCaSe LOC 37 52 56.788 N 121 54 55.02 W 1120m 10m 100m 10m
|
||||||
|
diff --git a/bin/tests/system/dnssec/ns3/sign.sh b/bin/tests/system/dnssec/ns3/sign.sh
|
||||||
|
index 80d412e..d94f382 100644
|
||||||
|
--- a/bin/tests/system/dnssec/ns3/sign.sh
|
||||||
|
+++ b/bin/tests/system/dnssec/ns3/sign.sh
|
||||||
|
@@ -86,7 +86,9 @@ keyname=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -n zone "$zone
|
||||||
|
|
||||||
|
cat "$infile" "$cnameandkey.key" "$dnameandkey.key" "$keyname.key" > "$zonefile"
|
||||||
|
|
||||||
|
-"$SIGNER" -P -o "$zone" "$zonefile" > /dev/null
|
||||||
|
+"$SIGNER" -P -D -o "$zone" "$zonefile" >/dev/null
|
||||||
|
+cat "$zonefile" "$zonefile".signed >"$zonefile".tmp
|
||||||
|
+mv "$zonefile".tmp "$zonefile".signed
|
||||||
|
|
||||||
|
zone=bogus.example.
|
||||||
|
infile=bogus.example.db.in
|
||||||
|
diff --git a/bin/tests/system/dnssec/tests.sh b/bin/tests/system/dnssec/tests.sh
|
||||||
|
index fe95c8d..0c03970 100644
|
||||||
|
--- a/bin/tests/system/dnssec/tests.sh
|
||||||
|
+++ b/bin/tests/system/dnssec/tests.sh
|
||||||
|
@@ -762,6 +762,21 @@ n=$((n+1))
|
||||||
|
test "$ret" -eq 0 || echo_i "failed"
|
||||||
|
status=$((status+ret))
|
||||||
|
|
||||||
|
+echo_i "checking mixed-case positive validation ($n)"
|
||||||
|
+ret=0
|
||||||
|
+for type in a txt aaaa loc; do
|
||||||
|
+ dig_with_opts +noauth mixedcase.secure.example. \
|
||||||
|
+ @10.53.0.3 $type >dig.out.$type.ns3.test$n || ret=1
|
||||||
|
+ dig_with_opts +noauth mixedcase.secure.example. \
|
||||||
|
+ @10.53.0.4 $type >dig.out.$type.ns4.test$n || ret=1
|
||||||
|
+ digcomp --lc dig.out.$type.ns3.test$n dig.out.$type.ns4.test$n || ret=1
|
||||||
|
+ grep "status: NOERROR" dig.out.$type.ns4.test$n >/dev/null || ret=1
|
||||||
|
+ grep "flags:.*ad.*QUERY" dig.out.$type.ns4.test$n >/dev/null || ret=1
|
||||||
|
+done
|
||||||
|
+n=$((n + 1))
|
||||||
|
+test "$ret" -eq 0 || echo_i "failed"
|
||||||
|
+status=$((status + ret))
|
||||||
|
+
|
||||||
|
echo_i "checking multi-stage positive validation NSEC/NSEC3 ($n)"
|
||||||
|
ret=0
|
||||||
|
dig_with_opts +noauth a.nsec3.example. \
|
||||||
|
--
|
||||||
|
2.43.0
|
||||||
|
|
||||||
1735
SOURCES/bind-9.16-CVE-2023-4408.patch
Normal file
1735
SOURCES/bind-9.16-CVE-2023-4408.patch
Normal file
File diff suppressed because it is too large
Load Diff
478
SOURCES/bind-9.16-CVE-2023-50387.patch
Normal file
478
SOURCES/bind-9.16-CVE-2023-50387.patch
Normal file
@ -0,0 +1,478 @@
|
|||||||
|
From c6e05ffc5fb784514ab54938867abaab41126c65 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Mon, 12 Feb 2024 21:09:51 +0100
|
||||||
|
Subject: [PATCH] Prevent increased CPU consumption in DNSSEC validator
|
||||||
|
|
||||||
|
KeyTrap - Extreme CPU consumption in DNSSEC validator. Preparing an
|
||||||
|
NSEC3 closest encloser proof can exhaust CPU resources.
|
||||||
|
|
||||||
|
6322. [security] Specific DNS answers could cause a denial-of-service
|
||||||
|
condition due to DNS validation taking a long time.
|
||||||
|
(CVE-2023-50387) [GL #4424]
|
||||||
|
|
||||||
|
Resolves: CVE-2023-50387 CVE-2023-50868
|
||||||
|
---
|
||||||
|
lib/dns/dst_api.c | 27 +++++++++----
|
||||||
|
lib/dns/include/dns/validator.h | 1 +
|
||||||
|
lib/dns/include/dst/dst.h | 4 ++
|
||||||
|
lib/dns/resolver.c | 4 +-
|
||||||
|
lib/dns/validator.c | 67 +++++++++++++++------------------
|
||||||
|
lib/isc/include/isc/netmgr.h | 3 ++
|
||||||
|
lib/isc/netmgr/netmgr-int.h | 1 +
|
||||||
|
lib/isc/netmgr/netmgr.c | 36 +++++++++++-------
|
||||||
|
lib/isc/netmgr/tcp.c | 6 +--
|
||||||
|
lib/isc/netmgr/tcpdns.c | 4 +-
|
||||||
|
lib/isc/netmgr/udp.c | 6 +--
|
||||||
|
11 files changed, 91 insertions(+), 68 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/lib/dns/dst_api.c b/lib/dns/dst_api.c
|
||||||
|
index 62600dd..3aafd7c 100644
|
||||||
|
--- a/lib/dns/dst_api.c
|
||||||
|
+++ b/lib/dns/dst_api.c
|
||||||
|
@@ -160,7 +160,8 @@ computeid(dst_key_t *key);
|
||||||
|
static isc_result_t
|
||||||
|
frombuffer(const dns_name_t *name, unsigned int alg, unsigned int flags,
|
||||||
|
unsigned int protocol, dns_rdataclass_t rdclass,
|
||||||
|
- isc_buffer_t *source, isc_mem_t *mctx, dst_key_t **keyp);
|
||||||
|
+ isc_buffer_t *source, isc_mem_t *mctx, bool no_rdata,
|
||||||
|
+ dst_key_t **keyp);
|
||||||
|
|
||||||
|
static isc_result_t
|
||||||
|
algorithm_status(unsigned int alg);
|
||||||
|
@@ -745,6 +746,13 @@ dst_key_todns(const dst_key_t *key, isc_buffer_t *target) {
|
||||||
|
isc_result_t
|
||||||
|
dst_key_fromdns(const dns_name_t *name, dns_rdataclass_t rdclass,
|
||||||
|
isc_buffer_t *source, isc_mem_t *mctx, dst_key_t **keyp) {
|
||||||
|
+ return (dst_key_fromdns_ex(name, rdclass, source, mctx, false, keyp));
|
||||||
|
+}
|
||||||
|
+
|
||||||
|
+isc_result_t
|
||||||
|
+dst_key_fromdns_ex(const dns_name_t *name, dns_rdataclass_t rdclass,
|
||||||
|
+ isc_buffer_t *source, isc_mem_t *mctx, bool no_rdata,
|
||||||
|
+ dst_key_t **keyp) {
|
||||||
|
uint8_t alg, proto;
|
||||||
|
uint32_t flags, extflags;
|
||||||
|
dst_key_t *key = NULL;
|
||||||
|
@@ -775,7 +783,7 @@ dst_key_fromdns(const dns_name_t *name, dns_rdataclass_t rdclass,
|
||||||
|
}
|
||||||
|
|
||||||
|
result = frombuffer(name, alg, flags, proto, rdclass, source, mctx,
|
||||||
|
- &key);
|
||||||
|
+ no_rdata, &key);
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
return (result);
|
||||||
|
}
|
||||||
|
@@ -796,7 +804,7 @@ dst_key_frombuffer(const dns_name_t *name, unsigned int alg, unsigned int flags,
|
||||||
|
REQUIRE(dst_initialized);
|
||||||
|
|
||||||
|
result = frombuffer(name, alg, flags, protocol, rdclass, source, mctx,
|
||||||
|
- &key);
|
||||||
|
+ false, &key);
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
return (result);
|
||||||
|
}
|
||||||
|
@@ -2288,7 +2296,8 @@ computeid(dst_key_t *key) {
|
||||||
|
static isc_result_t
|
||||||
|
frombuffer(const dns_name_t *name, unsigned int alg, unsigned int flags,
|
||||||
|
unsigned int protocol, dns_rdataclass_t rdclass,
|
||||||
|
- isc_buffer_t *source, isc_mem_t *mctx, dst_key_t **keyp) {
|
||||||
|
+ isc_buffer_t *source, isc_mem_t *mctx, bool no_rdata,
|
||||||
|
+ dst_key_t **keyp) {
|
||||||
|
dst_key_t *key;
|
||||||
|
isc_result_t ret;
|
||||||
|
|
||||||
|
@@ -2313,10 +2322,12 @@ frombuffer(const dns_name_t *name, unsigned int alg, unsigned int flags,
|
||||||
|
return (DST_R_UNSUPPORTEDALG);
|
||||||
|
}
|
||||||
|
|
||||||
|
- ret = key->func->fromdns(key, source);
|
||||||
|
- if (ret != ISC_R_SUCCESS) {
|
||||||
|
- dst_key_free(&key);
|
||||||
|
- return (ret);
|
||||||
|
+ if (!no_rdata) {
|
||||||
|
+ ret = key->func->fromdns(key, source);
|
||||||
|
+ if (ret != ISC_R_SUCCESS) {
|
||||||
|
+ dst_key_free(&key);
|
||||||
|
+ return (ret);
|
||||||
|
+ }
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
diff --git a/lib/dns/include/dns/validator.h b/lib/dns/include/dns/validator.h
|
||||||
|
index 4744014..fe97e41 100644
|
||||||
|
--- a/lib/dns/include/dns/validator.h
|
||||||
|
+++ b/lib/dns/include/dns/validator.h
|
||||||
|
@@ -148,6 +148,7 @@ struct dns_validator {
|
||||||
|
unsigned int authcount;
|
||||||
|
unsigned int authfail;
|
||||||
|
isc_stdtime_t start;
|
||||||
|
+ bool failed;
|
||||||
|
};
|
||||||
|
|
||||||
|
/*%
|
||||||
|
diff --git a/lib/dns/include/dst/dst.h b/lib/dns/include/dst/dst.h
|
||||||
|
index f454ebb..36770b5 100644
|
||||||
|
--- a/lib/dns/include/dst/dst.h
|
||||||
|
+++ b/lib/dns/include/dst/dst.h
|
||||||
|
@@ -469,6 +469,10 @@ dst_key_tofile(const dst_key_t *key, int type, const char *directory);
|
||||||
|
*/
|
||||||
|
|
||||||
|
isc_result_t
|
||||||
|
+dst_key_fromdns_ex(const dns_name_t *name, dns_rdataclass_t rdclass,
|
||||||
|
+ isc_buffer_t *source, isc_mem_t *mctx, bool no_rdata,
|
||||||
|
+ dst_key_t **keyp);
|
||||||
|
+isc_result_t
|
||||||
|
dst_key_fromdns(const dns_name_t *name, dns_rdataclass_t rdclass,
|
||||||
|
isc_buffer_t *source, isc_mem_t *mctx, dst_key_t **keyp);
|
||||||
|
/*%<
|
||||||
|
diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c
|
||||||
|
index 7cbfbb2..be1d735 100644
|
||||||
|
--- a/lib/dns/resolver.c
|
||||||
|
+++ b/lib/dns/resolver.c
|
||||||
|
@@ -10613,8 +10613,8 @@ dns_resolver_create(dns_view_t *view, isc_taskmgr_t *taskmgr,
|
||||||
|
* Since we have a pool of tasks we bind them to task queues
|
||||||
|
* to spread the load evenly
|
||||||
|
*/
|
||||||
|
- result = isc_task_create_bound(taskmgr, 0,
|
||||||
|
- &res->buckets[i].task, i);
|
||||||
|
+ result = isc_task_create_bound(
|
||||||
|
+ taskmgr, 0, &res->buckets[i].task, ISC_NM_TASK_SLOW(i));
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
isc_mutex_destroy(&res->buckets[i].lock);
|
||||||
|
goto cleanup_buckets;
|
||||||
|
diff --git a/lib/dns/validator.c b/lib/dns/validator.c
|
||||||
|
index e54fc70..e416cc9 100644
|
||||||
|
--- a/lib/dns/validator.c
|
||||||
|
+++ b/lib/dns/validator.c
|
||||||
|
@@ -1098,8 +1098,8 @@ create_validator(dns_validator_t *val, dns_name_t *name, dns_rdatatype_t type,
|
||||||
|
* 'rdataset'. If found, build a dst_key_t for it and point val->key at
|
||||||
|
* it.
|
||||||
|
*
|
||||||
|
- * If val->key is already non-NULL, locate it in the rdataset and then
|
||||||
|
- * search past it for the *next* key that could have signed 'siginfo', then
|
||||||
|
+ * If val->key is already non-NULL, start searching from the next position in
|
||||||
|
+ * 'rdataset' to find the *next* key that could have signed 'siginfo', then
|
||||||
|
* set val->key to that.
|
||||||
|
*
|
||||||
|
* Returns ISC_R_SUCCESS if a possible matching key has been found,
|
||||||
|
@@ -1112,59 +1112,59 @@ select_signing_key(dns_validator_t *val, dns_rdataset_t *rdataset) {
|
||||||
|
isc_buffer_t b;
|
||||||
|
dns_rdata_t rdata = DNS_RDATA_INIT;
|
||||||
|
dst_key_t *oldkey = val->key;
|
||||||
|
- bool foundold;
|
||||||
|
+ bool no_rdata = false;
|
||||||
|
|
||||||
|
if (oldkey == NULL) {
|
||||||
|
- foundold = true;
|
||||||
|
+ result = dns_rdataset_first(rdataset);
|
||||||
|
} else {
|
||||||
|
- foundold = false;
|
||||||
|
+ dst_key_free(&oldkey);
|
||||||
|
val->key = NULL;
|
||||||
|
+ result = dns_rdataset_next(rdataset);
|
||||||
|
}
|
||||||
|
-
|
||||||
|
- result = dns_rdataset_first(rdataset);
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
- goto failure;
|
||||||
|
+ goto done;
|
||||||
|
}
|
||||||
|
+
|
||||||
|
do {
|
||||||
|
dns_rdataset_current(rdataset, &rdata);
|
||||||
|
|
||||||
|
isc_buffer_init(&b, rdata.data, rdata.length);
|
||||||
|
isc_buffer_add(&b, rdata.length);
|
||||||
|
INSIST(val->key == NULL);
|
||||||
|
- result = dst_key_fromdns(&siginfo->signer, rdata.rdclass, &b,
|
||||||
|
- val->view->mctx, &val->key);
|
||||||
|
+ result = dst_key_fromdns_ex(&siginfo->signer, rdata.rdclass, &b,
|
||||||
|
+ val->view->mctx, no_rdata,
|
||||||
|
+ &val->key);
|
||||||
|
if (result == ISC_R_SUCCESS) {
|
||||||
|
if (siginfo->algorithm ==
|
||||||
|
(dns_secalg_t)dst_key_alg(val->key) &&
|
||||||
|
siginfo->keyid ==
|
||||||
|
(dns_keytag_t)dst_key_id(val->key) &&
|
||||||
|
+ (dst_key_flags(val->key) & DNS_KEYFLAG_REVOKE) ==
|
||||||
|
+ 0 &&
|
||||||
|
dst_key_iszonekey(val->key))
|
||||||
|
{
|
||||||
|
- if (foundold) {
|
||||||
|
- /*
|
||||||
|
- * This is the key we're looking for.
|
||||||
|
- */
|
||||||
|
- return (ISC_R_SUCCESS);
|
||||||
|
- } else if (dst_key_compare(oldkey, val->key)) {
|
||||||
|
- foundold = true;
|
||||||
|
- dst_key_free(&oldkey);
|
||||||
|
+ if (no_rdata) {
|
||||||
|
+ /* Retry with full key */
|
||||||
|
+ dns_rdata_reset(&rdata);
|
||||||
|
+ dst_key_free(&val->key);
|
||||||
|
+ no_rdata = false;
|
||||||
|
+ continue;
|
||||||
|
}
|
||||||
|
+ /* This is the key we're looking for. */
|
||||||
|
+ goto done;
|
||||||
|
}
|
||||||
|
dst_key_free(&val->key);
|
||||||
|
}
|
||||||
|
dns_rdata_reset(&rdata);
|
||||||
|
result = dns_rdataset_next(rdataset);
|
||||||
|
+ no_rdata = true;
|
||||||
|
} while (result == ISC_R_SUCCESS);
|
||||||
|
|
||||||
|
+done:
|
||||||
|
if (result == ISC_R_NOMORE) {
|
||||||
|
result = ISC_R_NOTFOUND;
|
||||||
|
}
|
||||||
|
|
||||||
|
-failure:
|
||||||
|
- if (oldkey != NULL) {
|
||||||
|
- dst_key_free(&oldkey);
|
||||||
|
- }
|
||||||
|
-
|
||||||
|
return (result);
|
||||||
|
}
|
||||||
|
|
||||||
|
@@ -1557,20 +1557,9 @@ validate_answer(dns_validator_t *val, bool resume) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
- do {
|
||||||
|
- isc_result_t tresult;
|
||||||
|
- vresult = verify(val, val->key, &rdata,
|
||||||
|
- val->siginfo->keyid);
|
||||||
|
- if (vresult == ISC_R_SUCCESS) {
|
||||||
|
- break;
|
||||||
|
- }
|
||||||
|
-
|
||||||
|
- tresult = select_signing_key(val, val->keyset);
|
||||||
|
- if (tresult != ISC_R_SUCCESS) {
|
||||||
|
- break;
|
||||||
|
- }
|
||||||
|
- } while (1);
|
||||||
|
+ vresult = verify(val, val->key, &rdata, val->siginfo->keyid);
|
||||||
|
if (vresult != ISC_R_SUCCESS) {
|
||||||
|
+ val->failed = true;
|
||||||
|
validator_log(val, ISC_LOG_DEBUG(3),
|
||||||
|
"failed to verify rdataset");
|
||||||
|
} else {
|
||||||
|
@@ -1607,9 +1596,13 @@ validate_answer(dns_validator_t *val, bool resume) {
|
||||||
|
} else {
|
||||||
|
validator_log(val, ISC_LOG_DEBUG(3),
|
||||||
|
"verify failure: %s",
|
||||||
|
- isc_result_totext(result));
|
||||||
|
+ isc_result_totext(vresult));
|
||||||
|
resume = false;
|
||||||
|
}
|
||||||
|
+ if (val->failed) {
|
||||||
|
+ result = ISC_R_NOMORE;
|
||||||
|
+ break;
|
||||||
|
+ }
|
||||||
|
}
|
||||||
|
if (result != ISC_R_NOMORE) {
|
||||||
|
validator_log(val, ISC_LOG_DEBUG(3),
|
||||||
|
diff --git a/lib/isc/include/isc/netmgr.h b/lib/isc/include/isc/netmgr.h
|
||||||
|
index be9fd56..dfabdc8 100644
|
||||||
|
--- a/lib/isc/include/isc/netmgr.h
|
||||||
|
+++ b/lib/isc/include/isc/netmgr.h
|
||||||
|
@@ -455,6 +455,9 @@ isc_nm_tcpdnsconnect(isc_nm_t *mgr, isc_sockaddr_t *local, isc_sockaddr_t *peer,
|
||||||
|
* 'cb'.
|
||||||
|
*/
|
||||||
|
|
||||||
|
+#define ISC_NM_TASK_SLOW_OFFSET -2
|
||||||
|
+#define ISC_NM_TASK_SLOW(i) (ISC_NM_TASK_SLOW_OFFSET - 1 - i)
|
||||||
|
+
|
||||||
|
void
|
||||||
|
isc_nm_task_enqueue(isc_nm_t *mgr, isc_task_t *task, int threadid);
|
||||||
|
/*%<
|
||||||
|
diff --git a/lib/isc/netmgr/netmgr-int.h b/lib/isc/netmgr/netmgr-int.h
|
||||||
|
index f7b54f9..70bb32d 100644
|
||||||
|
--- a/lib/isc/netmgr/netmgr-int.h
|
||||||
|
+++ b/lib/isc/netmgr/netmgr-int.h
|
||||||
|
@@ -673,6 +673,7 @@ struct isc_nm {
|
||||||
|
#ifdef NETMGR_TRACE
|
||||||
|
ISC_LIST(isc_nmsocket_t) active_sockets;
|
||||||
|
#endif
|
||||||
|
+ int nlisteners;
|
||||||
|
};
|
||||||
|
|
||||||
|
typedef enum isc_nmsocket_type {
|
||||||
|
diff --git a/lib/isc/netmgr/netmgr.c b/lib/isc/netmgr/netmgr.c
|
||||||
|
index 0ed3182..898de41 100644
|
||||||
|
--- a/lib/isc/netmgr/netmgr.c
|
||||||
|
+++ b/lib/isc/netmgr/netmgr.c
|
||||||
|
@@ -269,31 +269,34 @@ isc__nm_winsock_destroy(void) {
|
||||||
|
#endif /* WIN32 */
|
||||||
|
|
||||||
|
static void
|
||||||
|
-isc__nm_threadpool_initialize(uint32_t workers) {
|
||||||
|
+isc__nm_threadpool_initialize(uint32_t nworkers) {
|
||||||
|
char buf[11];
|
||||||
|
int r = uv_os_getenv("UV_THREADPOOL_SIZE", buf,
|
||||||
|
&(size_t){ sizeof(buf) });
|
||||||
|
if (r == UV_ENOENT) {
|
||||||
|
- snprintf(buf, sizeof(buf), "%" PRIu32, workers);
|
||||||
|
+ snprintf(buf, sizeof(buf), "%" PRIu32, nworkers);
|
||||||
|
uv_os_setenv("UV_THREADPOOL_SIZE", buf);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
void
|
||||||
|
-isc__netmgr_create(isc_mem_t *mctx, uint32_t workers, isc_nm_t **netmgrp) {
|
||||||
|
+isc__netmgr_create(isc_mem_t *mctx, uint32_t nworkers, isc_nm_t **netmgrp) {
|
||||||
|
isc_nm_t *mgr = NULL;
|
||||||
|
char name[32];
|
||||||
|
|
||||||
|
- REQUIRE(workers > 0);
|
||||||
|
+ REQUIRE(nworkers > 0);
|
||||||
|
|
||||||
|
#ifdef WIN32
|
||||||
|
isc__nm_winsock_initialize();
|
||||||
|
#endif /* WIN32 */
|
||||||
|
|
||||||
|
- isc__nm_threadpool_initialize(workers);
|
||||||
|
+ isc__nm_threadpool_initialize(nworkers);
|
||||||
|
|
||||||
|
mgr = isc_mem_get(mctx, sizeof(*mgr));
|
||||||
|
- *mgr = (isc_nm_t){ .nworkers = workers };
|
||||||
|
+ *mgr = (isc_nm_t){
|
||||||
|
+ .nworkers = nworkers * 2,
|
||||||
|
+ .nlisteners = nworkers,
|
||||||
|
+ };
|
||||||
|
|
||||||
|
isc_mem_attach(mctx, &mgr->mctx);
|
||||||
|
isc_mutex_init(&mgr->lock);
|
||||||
|
@@ -334,11 +337,12 @@ isc__netmgr_create(isc_mem_t *mctx, uint32_t workers, isc_nm_t **netmgrp) {
|
||||||
|
isc_mempool_associatelock(mgr->evpool, &mgr->evlock);
|
||||||
|
isc_mempool_setfillcount(mgr->evpool, 32);
|
||||||
|
|
||||||
|
- isc_barrier_init(&mgr->pausing, workers);
|
||||||
|
- isc_barrier_init(&mgr->resuming, workers);
|
||||||
|
+ isc_barrier_init(&mgr->pausing, mgr->nworkers);
|
||||||
|
+ isc_barrier_init(&mgr->resuming, mgr->nworkers);
|
||||||
|
|
||||||
|
- mgr->workers = isc_mem_get(mctx, workers * sizeof(isc__networker_t));
|
||||||
|
- for (size_t i = 0; i < workers; i++) {
|
||||||
|
+ mgr->workers = isc_mem_get(mctx,
|
||||||
|
+ mgr->nworkers * sizeof(isc__networker_t));
|
||||||
|
+ for (int i = 0; i < mgr->nworkers; i++) {
|
||||||
|
int r;
|
||||||
|
isc__networker_t *worker = &mgr->workers[i];
|
||||||
|
*worker = (isc__networker_t){
|
||||||
|
@@ -373,7 +377,7 @@ isc__netmgr_create(isc_mem_t *mctx, uint32_t workers, isc_nm_t **netmgrp) {
|
||||||
|
mgr->workers_running++;
|
||||||
|
isc_thread_create(nm_thread, &mgr->workers[i], &worker->thread);
|
||||||
|
|
||||||
|
- snprintf(name, sizeof(name), "isc-net-%04zu", i);
|
||||||
|
+ snprintf(name, sizeof(name), "isc-net-%04d", i);
|
||||||
|
isc_thread_setname(worker->thread, name);
|
||||||
|
}
|
||||||
|
|
||||||
|
@@ -848,9 +852,15 @@ isc_nm_task_enqueue(isc_nm_t *nm, isc_task_t *task, int threadid) {
|
||||||
|
isc__networker_t *worker = NULL;
|
||||||
|
|
||||||
|
if (threadid == -1) {
|
||||||
|
- tid = (int)isc_random_uniform(nm->nworkers);
|
||||||
|
+ tid = (int)isc_random_uniform(nm->nlisteners);
|
||||||
|
+ } else if (threadid == ISC_NM_TASK_SLOW_OFFSET) {
|
||||||
|
+ tid = nm->nlisteners +
|
||||||
|
+ (int)isc_random_uniform(nm->nworkers - nm->nlisteners);
|
||||||
|
+ } else if (threadid < ISC_NM_TASK_SLOW_OFFSET) {
|
||||||
|
+ tid = nm->nlisteners + (ISC_NM_TASK_SLOW(threadid) %
|
||||||
|
+ (nm->nworkers - nm->nlisteners));
|
||||||
|
} else {
|
||||||
|
- tid = threadid % nm->nworkers;
|
||||||
|
+ tid = threadid % nm->nlisteners;
|
||||||
|
}
|
||||||
|
|
||||||
|
worker = &nm->workers[tid];
|
||||||
|
diff --git a/lib/isc/netmgr/tcp.c b/lib/isc/netmgr/tcp.c
|
||||||
|
index 5cca9f5..83bd2e2 100644
|
||||||
|
--- a/lib/isc/netmgr/tcp.c
|
||||||
|
+++ b/lib/isc/netmgr/tcp.c
|
||||||
|
@@ -321,7 +321,7 @@ isc_nm_tcpconnect(isc_nm_t *mgr, isc_sockaddr_t *local, isc_sockaddr_t *peer,
|
||||||
|
isc__nm_connectcb(sock, req, result, false);
|
||||||
|
} else {
|
||||||
|
isc__nmsocket_clearcb(sock);
|
||||||
|
- sock->tid = isc_random_uniform(mgr->nworkers);
|
||||||
|
+ sock->tid = isc_random_uniform(mgr->nlisteners);
|
||||||
|
isc__nm_connectcb(sock, req, result, true);
|
||||||
|
}
|
||||||
|
atomic_store(&sock->closed, true);
|
||||||
|
@@ -339,7 +339,7 @@ isc_nm_tcpconnect(isc_nm_t *mgr, isc_sockaddr_t *local, isc_sockaddr_t *peer,
|
||||||
|
isc__nm_put_netievent_tcpconnect(mgr, ievent);
|
||||||
|
} else {
|
||||||
|
atomic_init(&sock->active, false);
|
||||||
|
- sock->tid = isc_random_uniform(mgr->nworkers);
|
||||||
|
+ sock->tid = isc_random_uniform(mgr->nlisteners);
|
||||||
|
isc__nm_enqueue_ievent(&mgr->workers[sock->tid],
|
||||||
|
(isc__netievent_t *)ievent);
|
||||||
|
}
|
||||||
|
@@ -435,7 +435,7 @@ isc_nm_listentcp(isc_nm_t *mgr, isc_sockaddr_t *iface,
|
||||||
|
#if defined(WIN32)
|
||||||
|
sock->nchildren = 1;
|
||||||
|
#else
|
||||||
|
- sock->nchildren = mgr->nworkers;
|
||||||
|
+ sock->nchildren = mgr->nlisteners;
|
||||||
|
#endif
|
||||||
|
children_size = sock->nchildren * sizeof(sock->children[0]);
|
||||||
|
sock->children = isc_mem_get(mgr->mctx, children_size);
|
||||||
|
diff --git a/lib/isc/netmgr/tcpdns.c b/lib/isc/netmgr/tcpdns.c
|
||||||
|
index 188790c..7f13ab2 100644
|
||||||
|
--- a/lib/isc/netmgr/tcpdns.c
|
||||||
|
+++ b/lib/isc/netmgr/tcpdns.c
|
||||||
|
@@ -305,7 +305,7 @@ isc_nm_tcpdnsconnect(isc_nm_t *mgr, isc_sockaddr_t *local, isc_sockaddr_t *peer,
|
||||||
|
isc__nm_put_netievent_tcpdnsconnect(mgr, ievent);
|
||||||
|
} else {
|
||||||
|
atomic_init(&sock->active, false);
|
||||||
|
- sock->tid = isc_random_uniform(mgr->nworkers);
|
||||||
|
+ sock->tid = isc_random_uniform(mgr->nlisteners);
|
||||||
|
isc__nm_enqueue_ievent(&mgr->workers[sock->tid],
|
||||||
|
(isc__netievent_t *)ievent);
|
||||||
|
}
|
||||||
|
@@ -404,7 +404,7 @@ isc_nm_listentcpdns(isc_nm_t *mgr, isc_sockaddr_t *iface,
|
||||||
|
#if defined(WIN32)
|
||||||
|
sock->nchildren = 1;
|
||||||
|
#else
|
||||||
|
- sock->nchildren = mgr->nworkers;
|
||||||
|
+ sock->nchildren = mgr->nlisteners;
|
||||||
|
#endif
|
||||||
|
children_size = sock->nchildren * sizeof(sock->children[0]);
|
||||||
|
sock->children = isc_mem_get(mgr->mctx, children_size);
|
||||||
|
diff --git a/lib/isc/netmgr/udp.c b/lib/isc/netmgr/udp.c
|
||||||
|
index a91c425..f2e161c 100644
|
||||||
|
--- a/lib/isc/netmgr/udp.c
|
||||||
|
+++ b/lib/isc/netmgr/udp.c
|
||||||
|
@@ -126,7 +126,7 @@ isc_nm_listenudp(isc_nm_t *mgr, isc_sockaddr_t *iface, isc_nm_recv_cb_t cb,
|
||||||
|
uv_os_sock_t fd = -1;
|
||||||
|
|
||||||
|
/*
|
||||||
|
- * We are creating mgr->nworkers duplicated sockets, one
|
||||||
|
+ * We are creating mgr->nlisteners duplicated sockets, one
|
||||||
|
* socket for each worker thread.
|
||||||
|
*/
|
||||||
|
sock = isc_mem_get(mgr->mctx, sizeof(isc_nmsocket_t));
|
||||||
|
@@ -136,7 +136,7 @@ isc_nm_listenudp(isc_nm_t *mgr, isc_sockaddr_t *iface, isc_nm_recv_cb_t cb,
|
||||||
|
#if defined(WIN32)
|
||||||
|
sock->nchildren = 1;
|
||||||
|
#else
|
||||||
|
- sock->nchildren = mgr->nworkers;
|
||||||
|
+ sock->nchildren = mgr->nlisteners;
|
||||||
|
#endif
|
||||||
|
|
||||||
|
children_size = sock->nchildren * sizeof(sock->children[0]);
|
||||||
|
@@ -795,7 +795,7 @@ isc_nm_udpconnect(isc_nm_t *mgr, isc_sockaddr_t *local, isc_sockaddr_t *peer,
|
||||||
|
isc__nm_put_netievent_udpconnect(mgr, event);
|
||||||
|
} else {
|
||||||
|
atomic_init(&sock->active, false);
|
||||||
|
- sock->tid = isc_random_uniform(mgr->nworkers);
|
||||||
|
+ sock->tid = isc_random_uniform(mgr->nlisteners);
|
||||||
|
isc__nm_enqueue_ievent(&mgr->workers[sock->tid],
|
||||||
|
(isc__netievent_t *)event);
|
||||||
|
}
|
||||||
|
--
|
||||||
|
2.43.0
|
||||||
|
|
||||||
111
SOURCES/bind-9.16-CVE-2023-5517.patch
Normal file
111
SOURCES/bind-9.16-CVE-2023-5517.patch
Normal file
@ -0,0 +1,111 @@
|
|||||||
|
From bef141d5795429cab745f29f7d080d1e2ea8f164 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Mon, 12 Feb 2024 20:33:41 +0100
|
||||||
|
Subject: [PATCH] Prevent assertion failure when nxdomain-redirect is used with
|
||||||
|
RFC 1918 reverse zones
|
||||||
|
|
||||||
|
6316. [security] Specific queries could trigger an assertion check with
|
||||||
|
nxdomain-redirect enabled. (CVE-2023-5517) [GL #4281]
|
||||||
|
---
|
||||||
|
lib/ns/query.c | 25 ++++++++++++-------------
|
||||||
|
1 file changed, 12 insertions(+), 13 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/lib/ns/query.c b/lib/ns/query.c
|
||||||
|
index 4fe3e30..cc1d179 100644
|
||||||
|
--- a/lib/ns/query.c
|
||||||
|
+++ b/lib/ns/query.c
|
||||||
|
@@ -453,10 +453,10 @@ static void
|
||||||
|
query_addnxrrsetnsec(query_ctx_t *qctx);
|
||||||
|
|
||||||
|
static isc_result_t
|
||||||
|
-query_nxdomain(query_ctx_t *qctx, bool empty_wild);
|
||||||
|
+query_nxdomain(query_ctx_t *qctx, isc_result_t result);
|
||||||
|
|
||||||
|
static isc_result_t
|
||||||
|
-query_redirect(query_ctx_t *qctx);
|
||||||
|
+query_redirect(query_ctx_t *qctx, isc_result_t result);
|
||||||
|
|
||||||
|
static isc_result_t
|
||||||
|
query_ncache(query_ctx_t *qctx, isc_result_t result);
|
||||||
|
@@ -7262,8 +7262,7 @@ query_usestale(query_ctx_t *qctx, isc_result_t result) {
|
||||||
|
* result from the search.
|
||||||
|
*/
|
||||||
|
static isc_result_t
|
||||||
|
-query_gotanswer(query_ctx_t *qctx, isc_result_t res) {
|
||||||
|
- isc_result_t result = res;
|
||||||
|
+query_gotanswer(query_ctx_t *qctx, isc_result_t result) {
|
||||||
|
char errmsg[256];
|
||||||
|
|
||||||
|
CCTRACE(ISC_LOG_DEBUG(3), "query_gotanswer");
|
||||||
|
@@ -7333,16 +7332,16 @@ root_key_sentinel:
|
||||||
|
return (query_nodata(qctx, DNS_R_NXRRSET));
|
||||||
|
|
||||||
|
case DNS_R_EMPTYWILD:
|
||||||
|
- return (query_nxdomain(qctx, true));
|
||||||
|
+ return (query_nxdomain(qctx, DNS_R_EMPTYWILD));
|
||||||
|
|
||||||
|
case DNS_R_NXDOMAIN:
|
||||||
|
- return (query_nxdomain(qctx, false));
|
||||||
|
+ return (query_nxdomain(qctx, DNS_R_NXDOMAIN));
|
||||||
|
|
||||||
|
case DNS_R_COVERINGNSEC:
|
||||||
|
return (query_coveringnsec(qctx));
|
||||||
|
|
||||||
|
case DNS_R_NCACHENXDOMAIN:
|
||||||
|
- result = query_redirect(qctx);
|
||||||
|
+ result = query_redirect(qctx, result);
|
||||||
|
if (result != ISC_R_COMPLETE) {
|
||||||
|
return (result);
|
||||||
|
}
|
||||||
|
@@ -9155,10 +9154,10 @@ query_addnxrrsetnsec(query_ctx_t *qctx) {
|
||||||
|
* Handle NXDOMAIN and empty wildcard responses.
|
||||||
|
*/
|
||||||
|
static isc_result_t
|
||||||
|
-query_nxdomain(query_ctx_t *qctx, bool empty_wild) {
|
||||||
|
+query_nxdomain(query_ctx_t *qctx, isc_result_t result) {
|
||||||
|
dns_section_t section;
|
||||||
|
uint32_t ttl;
|
||||||
|
- isc_result_t result;
|
||||||
|
+ bool empty_wild = (result == DNS_R_EMPTYWILD);
|
||||||
|
|
||||||
|
CCTRACE(ISC_LOG_DEBUG(3), "query_nxdomain");
|
||||||
|
|
||||||
|
@@ -9167,7 +9166,7 @@ query_nxdomain(query_ctx_t *qctx, bool empty_wild) {
|
||||||
|
INSIST(qctx->is_zone || REDIRECT(qctx->client));
|
||||||
|
|
||||||
|
if (!empty_wild) {
|
||||||
|
- result = query_redirect(qctx);
|
||||||
|
+ result = query_redirect(qctx, result);
|
||||||
|
if (result != ISC_R_COMPLETE) {
|
||||||
|
return (result);
|
||||||
|
}
|
||||||
|
@@ -9253,7 +9252,7 @@ cleanup:
|
||||||
|
* redirecting, so query processing should continue past it.
|
||||||
|
*/
|
||||||
|
static isc_result_t
|
||||||
|
-query_redirect(query_ctx_t *qctx) {
|
||||||
|
+query_redirect(query_ctx_t *qctx, isc_result_t saved_result) {
|
||||||
|
isc_result_t result;
|
||||||
|
|
||||||
|
CCTRACE(ISC_LOG_DEBUG(3), "query_redirect");
|
||||||
|
@@ -9294,7 +9293,7 @@ query_redirect(query_ctx_t *qctx) {
|
||||||
|
SAVE(qctx->client->query.redirect.rdataset, qctx->rdataset);
|
||||||
|
SAVE(qctx->client->query.redirect.sigrdataset,
|
||||||
|
qctx->sigrdataset);
|
||||||
|
- qctx->client->query.redirect.result = DNS_R_NCACHENXDOMAIN;
|
||||||
|
+ qctx->client->query.redirect.result = saved_result;
|
||||||
|
dns_name_copynf(qctx->fname,
|
||||||
|
qctx->client->query.redirect.fname);
|
||||||
|
qctx->client->query.redirect.authoritative =
|
||||||
|
@@ -9908,7 +9907,7 @@ query_coveringnsec(query_ctx_t *qctx) {
|
||||||
|
* We now have the proof that we have an NXDOMAIN. Apply
|
||||||
|
* NXDOMAIN redirection if configured.
|
||||||
|
*/
|
||||||
|
- result = query_redirect(qctx);
|
||||||
|
+ result = query_redirect(qctx, DNS_R_COVERINGNSEC);
|
||||||
|
if (result != ISC_R_COMPLETE) {
|
||||||
|
redirected = true;
|
||||||
|
goto cleanup;
|
||||||
|
--
|
||||||
|
2.43.0
|
||||||
|
|
||||||
37
SOURCES/bind-9.16-CVE-2023-5679.patch
Normal file
37
SOURCES/bind-9.16-CVE-2023-5679.patch
Normal file
@ -0,0 +1,37 @@
|
|||||||
|
From 61112d1ce39848e08ec133f280cf8f729cb70d16 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Mon, 12 Feb 2024 20:41:43 +0100
|
||||||
|
Subject: [PATCH] Prevent assertion failure if DNS64 and serve-stale is used
|
||||||
|
|
||||||
|
Enabling both DNS64 and serve-stale may cause an assertion failure
|
||||||
|
during recursive resolution.
|
||||||
|
|
||||||
|
6317. [security] Restore DNS64 state when handling a serve-stale timeout.
|
||||||
|
(CVE-2023-5679) [GL #4334]
|
||||||
|
|
||||||
|
Resolves: CVE-2023-5679
|
||||||
|
---
|
||||||
|
lib/ns/query.c | 7 +++++++
|
||||||
|
1 file changed, 7 insertions(+)
|
||||||
|
|
||||||
|
diff --git a/lib/ns/query.c b/lib/ns/query.c
|
||||||
|
index cc1d179..1993800 100644
|
||||||
|
--- a/lib/ns/query.c
|
||||||
|
+++ b/lib/ns/query.c
|
||||||
|
@@ -5983,6 +5983,13 @@ query_lookup_stale(ns_client_t *client) {
|
||||||
|
query_ctx_t qctx;
|
||||||
|
|
||||||
|
qctx_init(client, NULL, client->query.qtype, &qctx);
|
||||||
|
+ if (DNS64(client)) {
|
||||||
|
+ qctx.qtype = qctx.type = dns_rdatatype_a;
|
||||||
|
+ qctx.dns64 = true;
|
||||||
|
+ }
|
||||||
|
+ if (DNS64EXCLUDE(client)) {
|
||||||
|
+ qctx.dns64_exclude = true;
|
||||||
|
+ }
|
||||||
|
dns_db_attach(client->view->cachedb, &qctx.db);
|
||||||
|
client->query.attributes &= ~NS_QUERYATTR_RECURSIONOK;
|
||||||
|
client->query.dboptions |= DNS_DBFIND_STALETIMEOUT;
|
||||||
|
--
|
||||||
|
2.43.0
|
||||||
|
|
||||||
52
SOURCES/bind-9.16-CVE-2023-6516-test.patch
Normal file
52
SOURCES/bind-9.16-CVE-2023-6516-test.patch
Normal file
@ -0,0 +1,52 @@
|
|||||||
|
From e91ab7758bed0cf3dcf8ed745f91063d7ec4011c Mon Sep 17 00:00:00 2001
|
||||||
|
From: =?UTF-8?q?Micha=C5=82=20K=C4=99pie=C5=84?= <michal@isc.org>
|
||||||
|
Date: Thu, 4 Jan 2024 13:39:27 +0100
|
||||||
|
Subject: [PATCH] Fix map offsets in the "masterformat" system test
|
||||||
|
|
||||||
|
The "masterformat" system test attempts to check named-checkzone
|
||||||
|
behavior when it is fed corrupt map-format zone files. However, despite
|
||||||
|
the RBTDB and RBT structures having evolved over the years, the offsets
|
||||||
|
at which a valid map-format zone file is malformed by the "masterformat"
|
||||||
|
test have not been updated accordingly, causing the relevant checks to
|
||||||
|
introduce a different type of corruption than they were originally meant
|
||||||
|
to cause:
|
||||||
|
|
||||||
|
- the "bad node header" check originally mangled the 'type' member of
|
||||||
|
the rdatasetheader_t structure for cname.example.nil,
|
||||||
|
|
||||||
|
- the "bad node data" check originally mangled the 'serial' and
|
||||||
|
'rdh_ttl' members of the rdatasetheader_t structure for
|
||||||
|
aaaa.example.nil.
|
||||||
|
|
||||||
|
Update the offsets at which the map-format zone file is malformed at by
|
||||||
|
the "masterformat" system test so that the relevant checks fulfill their
|
||||||
|
original purpose again.
|
||||||
|
---
|
||||||
|
bin/tests/system/masterformat/tests.sh | 4 ++--
|
||||||
|
1 file changed, 2 insertions(+), 2 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/bin/tests/system/masterformat/tests.sh b/bin/tests/system/masterformat/tests.sh
|
||||||
|
index 364a0d2..bb4e6ec 100755
|
||||||
|
--- a/bin/tests/system/masterformat/tests.sh
|
||||||
|
+++ b/bin/tests/system/masterformat/tests.sh
|
||||||
|
@@ -295,7 +295,7 @@ status=$((status+ret))
|
||||||
|
echo_i "checking corrupt map files fail to load (bad node header) ($n)"
|
||||||
|
ret=0
|
||||||
|
cp map.5 badmap
|
||||||
|
-stomp badmap 2754 2 99
|
||||||
|
+stomp badmap 3706 2 99
|
||||||
|
$CHECKZONE -D -f map -F text -o text.5 example.nil badmap > /dev/null
|
||||||
|
[ $? = 1 ] || ret=1
|
||||||
|
n=$((n+1))
|
||||||
|
@@ -305,7 +305,7 @@ status=$((status+ret))
|
||||||
|
echo_i "checking corrupt map files fail to load (bad node data) ($n)"
|
||||||
|
ret=0
|
||||||
|
cp map.5 badmap
|
||||||
|
-stomp badmap 2897 5 127
|
||||||
|
+stomp badmap 3137 5 127
|
||||||
|
$CHECKZONE -D -f map -F text -o text.5 example.nil badmap > /dev/null
|
||||||
|
[ $? = 1 ] || ret=1
|
||||||
|
n=$((n+1))
|
||||||
|
--
|
||||||
|
2.44.0
|
||||||
|
|
||||||
283
SOURCES/bind-9.16-CVE-2023-6516.patch
Normal file
283
SOURCES/bind-9.16-CVE-2023-6516.patch
Normal file
@ -0,0 +1,283 @@
|
|||||||
|
From 6e08fef24d7ba491228a4083ea0f0e33253a1043 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Mon, 12 Feb 2024 20:48:57 +0100
|
||||||
|
Subject: [PATCH] Specific recursive query patterns may lead to an
|
||||||
|
out-of-memory condition
|
||||||
|
|
||||||
|
6319. [security] Query patterns that continuously triggered cache
|
||||||
|
database maintenance could exhaust all available memory
|
||||||
|
on the host running named. (CVE-2023-6516) [GL #4383]
|
||||||
|
|
||||||
|
Resolves: CVE-2023-6516
|
||||||
|
---
|
||||||
|
lib/dns/include/dns/rbt.h | 6 ++
|
||||||
|
lib/dns/mapapi | 2 +-
|
||||||
|
lib/dns/rbt.c | 1 +
|
||||||
|
lib/dns/rbtdb.c | 149 +++++++++++++++++++++++++-------------
|
||||||
|
4 files changed, 107 insertions(+), 51 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/lib/dns/include/dns/rbt.h b/lib/dns/include/dns/rbt.h
|
||||||
|
index b67e602..69655b0 100644
|
||||||
|
--- a/lib/dns/include/dns/rbt.h
|
||||||
|
+++ b/lib/dns/include/dns/rbt.h
|
||||||
|
@@ -164,6 +164,12 @@ struct dns_rbtnode {
|
||||||
|
uint16_t locknum; /* note that this is not in the bitfield */
|
||||||
|
isc_refcount_t references;
|
||||||
|
/*@}*/
|
||||||
|
+
|
||||||
|
+ /*%
|
||||||
|
+ * This linked list is used to store nodes from which tree pruning can
|
||||||
|
+ * be started.
|
||||||
|
+ */
|
||||||
|
+ ISC_LINK(dns_rbtnode_t) prunelink;
|
||||||
|
};
|
||||||
|
|
||||||
|
typedef isc_result_t (*dns_rbtfindcallback_t)(dns_rbtnode_t *node,
|
||||||
|
diff --git a/lib/dns/mapapi b/lib/dns/mapapi
|
||||||
|
index 1b502d3..a46e190 100644
|
||||||
|
--- a/lib/dns/mapapi
|
||||||
|
+++ b/lib/dns/mapapi
|
||||||
|
@@ -13,4 +13,4 @@
|
||||||
|
# Whenever releasing a new major release of BIND9, set this value
|
||||||
|
# back to 1.0 when releasing the first alpha. Map files are *never*
|
||||||
|
# compatible across major releases.
|
||||||
|
-MAPAPI=3.0
|
||||||
|
+MAPAPI=4.0
|
||||||
|
diff --git a/lib/dns/rbt.c b/lib/dns/rbt.c
|
||||||
|
index 7f2c2d2..a220368 100644
|
||||||
|
--- a/lib/dns/rbt.c
|
||||||
|
+++ b/lib/dns/rbt.c
|
||||||
|
@@ -2283,6 +2283,7 @@ create_node(isc_mem_t *mctx, const dns_name_t *name, dns_rbtnode_t **nodep) {
|
||||||
|
HASHVAL(node) = 0;
|
||||||
|
|
||||||
|
ISC_LINK_INIT(node, deadlink);
|
||||||
|
+ ISC_LINK_INIT(node, prunelink);
|
||||||
|
|
||||||
|
LOCKNUM(node) = 0;
|
||||||
|
WILD(node) = 0;
|
||||||
|
diff --git a/lib/dns/rbtdb.c b/lib/dns/rbtdb.c
|
||||||
|
index 75f97f5..2707507 100644
|
||||||
|
--- a/lib/dns/rbtdb.c
|
||||||
|
+++ b/lib/dns/rbtdb.c
|
||||||
|
@@ -515,6 +515,10 @@ struct dns_rbtdb {
|
||||||
|
*/
|
||||||
|
rbtnodelist_t *deadnodes;
|
||||||
|
|
||||||
|
+ /* List of nodes from which recursive tree pruning can be started from.
|
||||||
|
+ * Locked by tree_lock. */
|
||||||
|
+ rbtnodelist_t prunenodes;
|
||||||
|
+
|
||||||
|
/*
|
||||||
|
* Heaps. These are used for TTL based expiry in a cache,
|
||||||
|
* or for zone resigning in a zone DB. hmctx is the memory
|
||||||
|
@@ -1060,6 +1064,7 @@ free_rbtdb(dns_rbtdb_t *rbtdb, bool log, isc_event_t *event) {
|
||||||
|
unsigned int i;
|
||||||
|
isc_result_t result;
|
||||||
|
char buf[DNS_NAME_FORMATSIZE];
|
||||||
|
+ dns_rbtnode_t *node = NULL;
|
||||||
|
dns_rbt_t **treep;
|
||||||
|
isc_time_t start;
|
||||||
|
dns_dbonupdatelistener_t *listener, *listener_next;
|
||||||
|
@@ -1086,8 +1091,6 @@ free_rbtdb(dns_rbtdb_t *rbtdb, bool log, isc_event_t *event) {
|
||||||
|
* the overhead of unlinking all nodes here should be negligible.
|
||||||
|
*/
|
||||||
|
for (i = 0; i < rbtdb->node_lock_count; i++) {
|
||||||
|
- dns_rbtnode_t *node;
|
||||||
|
-
|
||||||
|
node = ISC_LIST_HEAD(rbtdb->deadnodes[i]);
|
||||||
|
while (node != NULL) {
|
||||||
|
ISC_LIST_UNLINK(rbtdb->deadnodes[i], node, deadlink);
|
||||||
|
@@ -1095,6 +1098,12 @@ free_rbtdb(dns_rbtdb_t *rbtdb, bool log, isc_event_t *event) {
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
+ node = ISC_LIST_HEAD(rbtdb->prunenodes);
|
||||||
|
+ while (node != NULL) {
|
||||||
|
+ ISC_LIST_UNLINK(rbtdb->prunenodes, node, prunelink);
|
||||||
|
+ node = ISC_LIST_HEAD(rbtdb->prunenodes);
|
||||||
|
+ }
|
||||||
|
+
|
||||||
|
if (event == NULL) {
|
||||||
|
rbtdb->quantum = (rbtdb->task != NULL) ? 100 : 0;
|
||||||
|
}
|
||||||
|
@@ -1934,19 +1943,32 @@ is_leaf(dns_rbtnode_t *node) {
|
||||||
|
node->left == NULL && node->right == NULL);
|
||||||
|
}
|
||||||
|
|
||||||
|
+/*%
|
||||||
|
+ * The tree lock must be held when this function is called as it reads and
|
||||||
|
+ * updates rbtdb->prunenodes.
|
||||||
|
+ */
|
||||||
|
static inline void
|
||||||
|
send_to_prune_tree(dns_rbtdb_t *rbtdb, dns_rbtnode_t *node,
|
||||||
|
isc_rwlocktype_t locktype) {
|
||||||
|
- isc_event_t *ev;
|
||||||
|
- dns_db_t *db;
|
||||||
|
+ bool pruning_queued = (ISC_LIST_HEAD(rbtdb->prunenodes) != NULL);
|
||||||
|
+
|
||||||
|
+ INSIST(locktype == isc_rwlocktype_write);
|
||||||
|
|
||||||
|
- ev = isc_event_allocate(rbtdb->common.mctx, NULL, DNS_EVENT_RBTPRUNE,
|
||||||
|
- prune_tree, node, sizeof(isc_event_t));
|
||||||
|
new_reference(rbtdb, node, locktype);
|
||||||
|
- db = NULL;
|
||||||
|
- attach((dns_db_t *)rbtdb, &db);
|
||||||
|
- ev->ev_sender = db;
|
||||||
|
- isc_task_send(rbtdb->task, &ev);
|
||||||
|
+ INSIST(!ISC_LINK_LINKED(node, prunelink));
|
||||||
|
+ ISC_LIST_APPEND(rbtdb->prunenodes, node, prunelink);
|
||||||
|
+
|
||||||
|
+ if (!pruning_queued) {
|
||||||
|
+ isc_event_t *ev = NULL;
|
||||||
|
+ dns_db_t *db = NULL;
|
||||||
|
+
|
||||||
|
+ attach((dns_db_t *)rbtdb, &db);
|
||||||
|
+
|
||||||
|
+ ev = isc_event_allocate(rbtdb->common.mctx, NULL,
|
||||||
|
+ DNS_EVENT_RBTPRUNE, prune_tree, db,
|
||||||
|
+ sizeof(isc_event_t));
|
||||||
|
+ isc_task_send(rbtdb->task, &ev);
|
||||||
|
+ }
|
||||||
|
}
|
||||||
|
|
||||||
|
/*%
|
||||||
|
@@ -2220,17 +2242,26 @@ restore_locks:
|
||||||
|
}
|
||||||
|
|
||||||
|
/*
|
||||||
|
- * Prune the tree by recursively cleaning-up single leaves. In the worst
|
||||||
|
- * case, the number of iteration is the number of tree levels, which is at
|
||||||
|
- * most the maximum number of domain name labels, i.e, 127. In practice, this
|
||||||
|
- * should be much smaller (only a few times), and even the worst case would be
|
||||||
|
- * acceptable for a single event.
|
||||||
|
+ * Prune the tree by recursively cleaning up single leaves. Go through all
|
||||||
|
+ * nodes stored in the rbtdb->prunenodes list; for each of them, in the worst
|
||||||
|
+ * case, it will be necessary to traverse a number of tree levels equal to the
|
||||||
|
+ * maximum legal number of domain name labels (127); in practice, the number of
|
||||||
|
+ * tree levels to traverse will virtually always be much smaller (a few levels
|
||||||
|
+ * at most). While holding the tree lock throughout this entire operation is
|
||||||
|
+ * less than ideal, so is splitting the latter up by queueing a separate
|
||||||
|
+ * prune_tree() run for each node to start pruning from (as queueing requires
|
||||||
|
+ * allocating memory and can therefore potentially be exploited to exhaust
|
||||||
|
+ * available memory). Also note that actually freeing up the memory used by
|
||||||
|
+ * RBTDB nodes (which is what this function does) is essential to keeping cache
|
||||||
|
+ * memory use in check, so since the tree lock needs to be acquired anyway,
|
||||||
|
+ * freeing as many nodes as possible before the tree lock gets released is
|
||||||
|
+ * prudent.
|
||||||
|
*/
|
||||||
|
static void
|
||||||
|
prune_tree(isc_task_t *task, isc_event_t *event) {
|
||||||
|
- dns_rbtdb_t *rbtdb = event->ev_sender;
|
||||||
|
- dns_rbtnode_t *node = event->ev_arg;
|
||||||
|
- dns_rbtnode_t *parent;
|
||||||
|
+ dns_rbtdb_t *rbtdb = (dns_rbtdb_t *)event->ev_arg;
|
||||||
|
+ dns_rbtnode_t *node = NULL;
|
||||||
|
+ dns_rbtnode_t *parent = NULL;
|
||||||
|
unsigned int locknum;
|
||||||
|
|
||||||
|
UNUSED(task);
|
||||||
|
@@ -2238,44 +2269,60 @@ prune_tree(isc_task_t *task, isc_event_t *event) {
|
||||||
|
isc_event_free(&event);
|
||||||
|
|
||||||
|
RWLOCK(&rbtdb->tree_lock, isc_rwlocktype_write);
|
||||||
|
- locknum = node->locknum;
|
||||||
|
- NODE_LOCK(&rbtdb->node_locks[locknum].lock, isc_rwlocktype_write);
|
||||||
|
- do {
|
||||||
|
- parent = node->parent;
|
||||||
|
- decrement_reference(rbtdb, node, 0, isc_rwlocktype_write,
|
||||||
|
- isc_rwlocktype_write, true);
|
||||||
|
|
||||||
|
- if (parent != NULL && parent->down == NULL) {
|
||||||
|
- /*
|
||||||
|
- * node was the only down child of the parent and has
|
||||||
|
- * just been removed. We'll then need to examine the
|
||||||
|
- * parent. Keep the lock if possible; otherwise,
|
||||||
|
- * release the old lock and acquire one for the parent.
|
||||||
|
- */
|
||||||
|
- if (parent->locknum != locknum) {
|
||||||
|
- NODE_UNLOCK(&rbtdb->node_locks[locknum].lock,
|
||||||
|
- isc_rwlocktype_write);
|
||||||
|
- locknum = parent->locknum;
|
||||||
|
- NODE_LOCK(&rbtdb->node_locks[locknum].lock,
|
||||||
|
- isc_rwlocktype_write);
|
||||||
|
+ while ((node = ISC_LIST_HEAD(rbtdb->prunenodes)) != NULL) {
|
||||||
|
+ locknum = node->locknum;
|
||||||
|
+ NODE_LOCK(&rbtdb->node_locks[locknum].lock,
|
||||||
|
+ isc_rwlocktype_write);
|
||||||
|
+ do {
|
||||||
|
+ if (ISC_LINK_LINKED(node, prunelink)) {
|
||||||
|
+ ISC_LIST_UNLINK(rbtdb->prunenodes, node,
|
||||||
|
+ prunelink);
|
||||||
|
}
|
||||||
|
|
||||||
|
- /*
|
||||||
|
- * We need to gain a reference to the node before
|
||||||
|
- * decrementing it in the next iteration.
|
||||||
|
- */
|
||||||
|
- if (ISC_LINK_LINKED(parent, deadlink)) {
|
||||||
|
- ISC_LIST_UNLINK(rbtdb->deadnodes[locknum],
|
||||||
|
+ parent = node->parent;
|
||||||
|
+ decrement_reference(rbtdb, node, 0,
|
||||||
|
+ isc_rwlocktype_write,
|
||||||
|
+ isc_rwlocktype_write, true);
|
||||||
|
+
|
||||||
|
+ if (parent != NULL && parent->down == NULL) {
|
||||||
|
+ /*
|
||||||
|
+ * node was the only down child of the parent
|
||||||
|
+ * and has just been removed. We'll then need
|
||||||
|
+ * to examine the parent. Keep the lock if
|
||||||
|
+ * possible; otherwise, release the old lock and
|
||||||
|
+ * acquire one for the parent.
|
||||||
|
+ */
|
||||||
|
+ if (parent->locknum != locknum) {
|
||||||
|
+ NODE_UNLOCK(
|
||||||
|
+ &rbtdb->node_locks[locknum].lock,
|
||||||
|
+ isc_rwlocktype_write);
|
||||||
|
+ locknum = parent->locknum;
|
||||||
|
+ NODE_LOCK(
|
||||||
|
+ &rbtdb->node_locks[locknum].lock,
|
||||||
|
+ isc_rwlocktype_write);
|
||||||
|
+ }
|
||||||
|
+
|
||||||
|
+ /*
|
||||||
|
+ * We need to gain a reference to the node
|
||||||
|
+ * before decrementing it in the next iteration.
|
||||||
|
+ */
|
||||||
|
+ if (ISC_LINK_LINKED(parent, deadlink)) {
|
||||||
|
+ ISC_LIST_UNLINK(
|
||||||
|
+ rbtdb->deadnodes[locknum],
|
||||||
|
parent, deadlink);
|
||||||
|
+ }
|
||||||
|
+ new_reference(rbtdb, parent,
|
||||||
|
+ isc_rwlocktype_write);
|
||||||
|
+ } else {
|
||||||
|
+ parent = NULL;
|
||||||
|
}
|
||||||
|
- new_reference(rbtdb, parent, isc_rwlocktype_write);
|
||||||
|
- } else {
|
||||||
|
- parent = NULL;
|
||||||
|
- }
|
||||||
|
|
||||||
|
- node = parent;
|
||||||
|
- } while (node != NULL);
|
||||||
|
- NODE_UNLOCK(&rbtdb->node_locks[locknum].lock, isc_rwlocktype_write);
|
||||||
|
+ node = parent;
|
||||||
|
+ } while (node != NULL);
|
||||||
|
+ NODE_UNLOCK(&rbtdb->node_locks[locknum].lock,
|
||||||
|
+ isc_rwlocktype_write);
|
||||||
|
+ }
|
||||||
|
RWUNLOCK(&rbtdb->tree_lock, isc_rwlocktype_write);
|
||||||
|
|
||||||
|
detach((dns_db_t **)&rbtdb);
|
||||||
|
@@ -8726,6 +8773,8 @@ dns_rbtdb_create(isc_mem_t *mctx, const dns_name_t *origin, dns_dbtype_t type,
|
||||||
|
ISC_LIST_INIT(rbtdb->deadnodes[i]);
|
||||||
|
}
|
||||||
|
|
||||||
|
+ ISC_LIST_INIT(rbtdb->prunenodes);
|
||||||
|
+
|
||||||
|
rbtdb->active = rbtdb->node_lock_count;
|
||||||
|
|
||||||
|
for (i = 0; i < (int)(rbtdb->node_lock_count); i++) {
|
||||||
|
--
|
||||||
|
2.43.0
|
||||||
|
|
||||||
2947
SOURCES/bind-9.16-CVE-2024-1737-records-test.patch
Normal file
2947
SOURCES/bind-9.16-CVE-2024-1737-records-test.patch
Normal file
File diff suppressed because it is too large
Load Diff
27
SOURCES/bind-9.16-CVE-2024-1737-records-test2.patch
Normal file
27
SOURCES/bind-9.16-CVE-2024-1737-records-test2.patch
Normal file
@ -0,0 +1,27 @@
|
|||||||
|
From 7bc5e5abf5a3cd66f11cc649b6ecf4c39c92bd9e Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Fri, 9 Aug 2024 12:32:20 +0200
|
||||||
|
Subject: [PATCH] fixup! Add test for not-loading and not-transfering huge
|
||||||
|
RRSets
|
||||||
|
|
||||||
|
---
|
||||||
|
bin/tests/system/conf.sh.common | 3 +++
|
||||||
|
1 file changed, 3 insertions(+)
|
||||||
|
|
||||||
|
diff --git a/bin/tests/system/conf.sh.common b/bin/tests/system/conf.sh.common
|
||||||
|
index 9fab00f..e617595 100644
|
||||||
|
--- a/bin/tests/system/conf.sh.common
|
||||||
|
+++ b/bin/tests/system/conf.sh.common
|
||||||
|
@@ -301,6 +301,9 @@ DISABLED_ALGORITHM=ECDSAP384SHA384
|
||||||
|
DISABLED_ALGORITHM_NUMBER=14
|
||||||
|
DISABLED_BITS=384
|
||||||
|
|
||||||
|
+# Default HMAC algorithm.
|
||||||
|
+export DEFAULT_HMAC=hmac-sha256
|
||||||
|
+
|
||||||
|
#
|
||||||
|
# Useful functions in test scripts
|
||||||
|
#
|
||||||
|
--
|
||||||
|
2.45.2
|
||||||
|
|
||||||
1152
SOURCES/bind-9.16-CVE-2024-1737-records.patch
Normal file
1152
SOURCES/bind-9.16-CVE-2024-1737-records.patch
Normal file
File diff suppressed because it is too large
Load Diff
6323
SOURCES/bind-9.16-CVE-2024-1737-types-test.patch
Normal file
6323
SOURCES/bind-9.16-CVE-2024-1737-types-test.patch
Normal file
File diff suppressed because it is too large
Load Diff
582
SOURCES/bind-9.16-CVE-2024-1737-types.patch
Normal file
582
SOURCES/bind-9.16-CVE-2024-1737-types.patch
Normal file
@ -0,0 +1,582 @@
|
|||||||
|
From a1c95d5fa479ac722f0cf758c494a37ffe1508c0 Mon Sep 17 00:00:00 2001
|
||||||
|
From: =?UTF-8?q?Ond=C5=99ej=20Sur=C3=BD?= <ondrej@isc.org>
|
||||||
|
Date: Sat, 25 May 2024 11:46:56 +0200
|
||||||
|
Subject: [PATCH] Add a limit to the number of RR types for single name
|
||||||
|
|
||||||
|
Previously, the number of RR types for a single owner name was limited
|
||||||
|
only by the maximum number of the types (64k). As the data structure
|
||||||
|
that holds the RR types for the database node is just a linked list, and
|
||||||
|
there are places where we just walk through the whole list (again and
|
||||||
|
again), adding a large number of RR types for a single owner named with
|
||||||
|
would slow down processing of such name (database node).
|
||||||
|
|
||||||
|
Add a configurable limit to cap the number of the RR types for a single
|
||||||
|
owner. This is enforced at the database (rbtdb, qpzone, qpcache) level
|
||||||
|
and configured with new max-types-per-name configuration option that
|
||||||
|
can be configured globally, per-view and per-zone.
|
||||||
|
|
||||||
|
(cherry picked from commit 00d16211d6368b99f070c1182d8c76b3798ca1db)
|
||||||
|
(cherry picked from commit 89f1779bc28b27adbd00325b974ede7a683f8632)
|
||||||
|
|
||||||
|
fix a memory leak that could occur when signing
|
||||||
|
|
||||||
|
when signatures were not added because of too many types already
|
||||||
|
existing at a node, the diff was not being cleaned up; this led to
|
||||||
|
a memory leak being reported at shutdown.
|
||||||
|
|
||||||
|
(cherry picked from commit 2825bdb1ae5be801e7ed603ba2455ed9a308f1f7)
|
||||||
|
(cherry picked from commit a080317de0efb7f6ffa12415a863729d416007d5)
|
||||||
|
|
||||||
|
Be smarter about refusing to add many RR types to the database
|
||||||
|
|
||||||
|
Instead of outright refusing to add new RR types to the cache, be a bit
|
||||||
|
smarter:
|
||||||
|
|
||||||
|
1. If the new header type is in our priority list, we always add either
|
||||||
|
positive or negative entry at the beginning of the list.
|
||||||
|
|
||||||
|
2. If the new header type is negative entry, and we are over the limit,
|
||||||
|
we mark it as ancient immediately, so it gets evicted from the cache
|
||||||
|
as soon as possible.
|
||||||
|
|
||||||
|
3. Otherwise add the new header after the priority headers (or at the
|
||||||
|
head of the list).
|
||||||
|
|
||||||
|
4. If we are over the limit, evict the last entry on the normal header
|
||||||
|
list.
|
||||||
|
|
||||||
|
(cherry picked from commit 57cd34441a1b4ecc9874a4a106c2c95b8d7a3120)
|
||||||
|
(cherry picked from commit 92a680a3ef708281267e4fd7b1e62b57c929447b)
|
||||||
|
|
||||||
|
Log error when update fails
|
||||||
|
|
||||||
|
The new "too many records" error can make an update fail without the
|
||||||
|
error being logged. This commit fixes that.
|
||||||
|
|
||||||
|
(cherry picked from commit 558923e5405894cf976d102f0d246a28bdbb400c)
|
||||||
|
(cherry picked from commit d72adf4b927d83a2a0ff8e431b911ec1df7aeb88)
|
||||||
|
---
|
||||||
|
bin/named/config.c | 1 +
|
||||||
|
bin/named/server.c | 9 +++++++++
|
||||||
|
bin/named/zoneconf.c | 8 ++++++++
|
||||||
|
bin/tests/system/dyndb/driver/db.c | 3 ++-
|
||||||
|
doc/arm/reference.rst | 12 ++++++++++++
|
||||||
|
lib/dns/cache.c | 12 ++++++++++++
|
||||||
|
lib/dns/db.c | 9 +++++++++
|
||||||
|
lib/dns/dnsrps.c | 3 ++-
|
||||||
|
lib/dns/ecdb.c | 3 ++-
|
||||||
|
lib/dns/include/dns/cache.h | 6 ++++++
|
||||||
|
lib/dns/include/dns/db.h | 11 +++++++++++
|
||||||
|
lib/dns/include/dns/view.h | 7 +++++++
|
||||||
|
lib/dns/include/dns/zone.h | 13 +++++++++++++
|
||||||
|
lib/dns/rbtdb.c | 28 +++++++++++++++++-----------
|
||||||
|
lib/dns/sdb.c | 3 ++-
|
||||||
|
lib/dns/sdlz.c | 3 ++-
|
||||||
|
lib/dns/view.c | 10 ++++++++++
|
||||||
|
lib/dns/zone.c | 16 ++++++++++++++++
|
||||||
|
lib/isccfg/namedconf.c | 3 +++
|
||||||
|
lib/ns/update.c | 15 ++++++++++++---
|
||||||
|
20 files changed, 156 insertions(+), 19 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/bin/named/config.c b/bin/named/config.c
|
||||||
|
index 9cba6f588b..c9888ada65 100644
|
||||||
|
--- a/bin/named/config.c
|
||||||
|
+++ b/bin/named/config.c
|
||||||
|
@@ -218,6 +218,7 @@ options {\n\
|
||||||
|
max-records-per-type 100;\n\
|
||||||
|
max-refresh-time 2419200; /* 4 weeks */\n\
|
||||||
|
max-retry-time 1209600; /* 2 weeks */\n\
|
||||||
|
+ max-types-per-name 100;\n\
|
||||||
|
max-transfer-idle-in 60;\n\
|
||||||
|
max-transfer-idle-out 60;\n\
|
||||||
|
max-transfer-time-in 120;\n\
|
||||||
|
diff --git a/bin/named/server.c b/bin/named/server.c
|
||||||
|
index 7bf5f2664d..4cc69b54a1 100644
|
||||||
|
--- a/bin/named/server.c
|
||||||
|
+++ b/bin/named/server.c
|
||||||
|
@@ -5427,6 +5427,15 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
||||||
|
INSIST(result == ISC_R_SUCCESS);
|
||||||
|
dns_view_setmaxrrperset(view, cfg_obj_asuint32(obj));
|
||||||
|
|
||||||
|
+ /*
|
||||||
|
+ * This is used for the cache and also as a default value
|
||||||
|
+ * for zone databases.
|
||||||
|
+ */
|
||||||
|
+ obj = NULL;
|
||||||
|
+ result = named_config_get(maps, "max-types-per-name", &obj);
|
||||||
|
+ INSIST(result == ISC_R_SUCCESS);
|
||||||
|
+ dns_view_setmaxtypepername(view, cfg_obj_asuint32(obj));
|
||||||
|
+
|
||||||
|
obj = NULL;
|
||||||
|
result = named_config_get(maps, "max-recursion-depth", &obj);
|
||||||
|
INSIST(result == ISC_R_SUCCESS);
|
||||||
|
diff --git a/bin/named/zoneconf.c b/bin/named/zoneconf.c
|
||||||
|
index ae5cc656ee..f6e8c64866 100644
|
||||||
|
--- a/bin/named/zoneconf.c
|
||||||
|
+++ b/bin/named/zoneconf.c
|
||||||
|
@@ -1100,6 +1100,14 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||||
|
dns_zone_setmaxrrperset(zone, 0);
|
||||||
|
}
|
||||||
|
|
||||||
|
+ obj = NULL;
|
||||||
|
+ result = named_config_get(maps, "max-types-per-name", &obj);
|
||||||
|
+ INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||||
|
+ dns_zone_setmaxtypepername(mayberaw, cfg_obj_asuint32(obj));
|
||||||
|
+ if (zone != mayberaw) {
|
||||||
|
+ dns_zone_setmaxtypepername(zone, 0);
|
||||||
|
+ }
|
||||||
|
+
|
||||||
|
if (raw != NULL && filename != NULL) {
|
||||||
|
#define SIGNED ".signed"
|
||||||
|
size_t signedlen = strlen(filename) + sizeof(SIGNED);
|
||||||
|
diff --git a/bin/tests/system/dyndb/driver/db.c b/bin/tests/system/dyndb/driver/db.c
|
||||||
|
index 6725a3bacd..c95fc8212b 100644
|
||||||
|
--- a/bin/tests/system/dyndb/driver/db.c
|
||||||
|
+++ b/bin/tests/system/dyndb/driver/db.c
|
||||||
|
@@ -593,7 +593,8 @@ static dns_dbmethods_t sampledb_methods = {
|
||||||
|
NULL, /* getservestalerefresh */
|
||||||
|
NULL, /* setgluecachestats */
|
||||||
|
NULL, /* adjusthashsize */
|
||||||
|
- NULL /* setmaxrrperset */
|
||||||
|
+ NULL, /* setmaxrrperset */
|
||||||
|
+ NULL /* setmaxtypepername */
|
||||||
|
};
|
||||||
|
|
||||||
|
/* Auxiliary driver functions. */
|
||||||
|
diff --git a/doc/arm/reference.rst b/doc/arm/reference.rst
|
||||||
|
index b1983ef30d..a8a3c7911d 100644
|
||||||
|
--- a/doc/arm/reference.rst
|
||||||
|
+++ b/doc/arm/reference.rst
|
||||||
|
@@ -2902,6 +2902,18 @@ system.
|
||||||
|
a failure. If set to 0, there is no cap on RRset size. The default is
|
||||||
|
100.
|
||||||
|
|
||||||
|
+``max-types-per-name``
|
||||||
|
+ This sets the maximum number of resource record types that can be stored
|
||||||
|
+ for a single owner name in a database. When configured in ``options``
|
||||||
|
+ or ``view``, it controls the cache database, and also sets
|
||||||
|
+ the default value for zone databases, which can be overridden by setting
|
||||||
|
+ it at the ``zone`` level
|
||||||
|
+
|
||||||
|
+ If set to a positive value, any attempt to cache or to add to a zone an owner
|
||||||
|
+ name with more than the specified number of resource record types will result
|
||||||
|
+ in a failure. If set to 0, there is no cap on RR types number. The default is
|
||||||
|
+ 100.
|
||||||
|
+
|
||||||
|
``recursive-clients``
|
||||||
|
This sets the maximum number (a "hard quota") of simultaneous recursive lookups
|
||||||
|
the server performs on behalf of clients. The default is
|
||||||
|
diff --git a/lib/dns/cache.c b/lib/dns/cache.c
|
||||||
|
index 9f0412dbe7..0b474fc313 100644
|
||||||
|
--- a/lib/dns/cache.c
|
||||||
|
+++ b/lib/dns/cache.c
|
||||||
|
@@ -150,6 +150,7 @@ struct dns_cache {
|
||||||
|
/* Access to the on-disk cache file is also locked by 'filelock'. */
|
||||||
|
|
||||||
|
uint32_t maxrrperset;
|
||||||
|
+ uint32_t maxtypepername;
|
||||||
|
};
|
||||||
|
|
||||||
|
/***
|
||||||
|
@@ -178,6 +179,7 @@ cache_create_db(dns_cache_t *cache, dns_db_t **db) {
|
||||||
|
if (result == ISC_R_SUCCESS) {
|
||||||
|
dns_db_setservestalettl(*db, cache->serve_stale_ttl);
|
||||||
|
dns_db_setmaxrrperset(*db, cache->maxrrperset);
|
||||||
|
+ dns_db_setmaxtypepername(*db, cache->maxtypepername);
|
||||||
|
}
|
||||||
|
return (result);
|
||||||
|
}
|
||||||
|
@@ -1290,6 +1292,16 @@ dns_cache_setmaxrrperset(dns_cache_t *cache, uint32_t value) {
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
+void
|
||||||
|
+dns_cache_setmaxtypepername(dns_cache_t *cache, uint32_t value) {
|
||||||
|
+ REQUIRE(VALID_CACHE(cache));
|
||||||
|
+
|
||||||
|
+ cache->maxtypepername = value;
|
||||||
|
+ if (cache->db != NULL) {
|
||||||
|
+ dns_db_setmaxtypepername(cache->db, value);
|
||||||
|
+ }
|
||||||
|
+}
|
||||||
|
+
|
||||||
|
/*
|
||||||
|
* XXX: Much of the following code has been copied in from statschannel.c.
|
||||||
|
* We should refactor this into a generic function in stats.c that can be
|
||||||
|
diff --git a/lib/dns/db.c b/lib/dns/db.c
|
||||||
|
index 8439265a7f..18583d41c2 100644
|
||||||
|
--- a/lib/dns/db.c
|
||||||
|
+++ b/lib/dns/db.c
|
||||||
|
@@ -1131,3 +1131,12 @@ dns_db_setmaxrrperset(dns_db_t *db, uint32_t value) {
|
||||||
|
(db->methods->setmaxrrperset)(db, value);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
+
|
||||||
|
+void
|
||||||
|
+dns_db_setmaxtypepername(dns_db_t *db, uint32_t value) {
|
||||||
|
+ REQUIRE(DNS_DB_VALID(db));
|
||||||
|
+
|
||||||
|
+ if (db->methods->setmaxtypepername != NULL) {
|
||||||
|
+ (db->methods->setmaxtypepername)(db, value);
|
||||||
|
+ }
|
||||||
|
+}
|
||||||
|
diff --git a/lib/dns/dnsrps.c b/lib/dns/dnsrps.c
|
||||||
|
index 539090d1bd..e1a1b21a8b 100644
|
||||||
|
--- a/lib/dns/dnsrps.c
|
||||||
|
+++ b/lib/dns/dnsrps.c
|
||||||
|
@@ -971,7 +971,8 @@ static dns_dbmethods_t rpsdb_db_methods = {
|
||||||
|
NULL, /* getservestalerefresh */
|
||||||
|
NULL, /* setgluecachestats */
|
||||||
|
NULL, /* adjusthashsize */
|
||||||
|
- NULL /* setmaxrrperset */
|
||||||
|
+ NULL, /* setmaxrrperset */
|
||||||
|
+ NULL /* setmaxtypepername */
|
||||||
|
};
|
||||||
|
|
||||||
|
static dns_rdatasetmethods_t rpsdb_rdataset_methods = {
|
||||||
|
diff --git a/lib/dns/ecdb.c b/lib/dns/ecdb.c
|
||||||
|
index bab5da5503..27d03b4e3a 100644
|
||||||
|
--- a/lib/dns/ecdb.c
|
||||||
|
+++ b/lib/dns/ecdb.c
|
||||||
|
@@ -560,7 +560,8 @@ static dns_dbmethods_t ecdb_methods = {
|
||||||
|
NULL, /* getservestalerefresh */
|
||||||
|
NULL, /* setgluecachestats */
|
||||||
|
NULL, /* adjusthashsize */
|
||||||
|
- NULL /* setmaxrrperset */
|
||||||
|
+ NULL, /* setmaxrrperset */
|
||||||
|
+ NULL /* setmaxtypepername */
|
||||||
|
};
|
||||||
|
|
||||||
|
static isc_result_t
|
||||||
|
diff --git a/lib/dns/include/dns/cache.h b/lib/dns/include/dns/cache.h
|
||||||
|
index 3fa2a891e0..72de21600a 100644
|
||||||
|
--- a/lib/dns/include/dns/cache.h
|
||||||
|
+++ b/lib/dns/include/dns/cache.h
|
||||||
|
@@ -343,6 +343,12 @@ dns_cache_setmaxrrperset(dns_cache_t *cache, uint32_t value);
|
||||||
|
* Set the maximum resource records per RRSet that can be cached.
|
||||||
|
*/
|
||||||
|
|
||||||
|
+void
|
||||||
|
+dns_cache_setmaxtypepername(dns_cache_t *cache, uint32_t value);
|
||||||
|
+/*%<
|
||||||
|
+ * Set the maximum resource record types per owner name that can be cached.
|
||||||
|
+ */
|
||||||
|
+
|
||||||
|
#ifdef HAVE_LIBXML2
|
||||||
|
int
|
||||||
|
dns_cache_renderxml(dns_cache_t *cache, void *writer0);
|
||||||
|
diff --git a/lib/dns/include/dns/db.h b/lib/dns/include/dns/db.h
|
||||||
|
index 732bfe473d..411881d48a 100644
|
||||||
|
--- a/lib/dns/include/dns/db.h
|
||||||
|
+++ b/lib/dns/include/dns/db.h
|
||||||
|
@@ -183,6 +183,7 @@ typedef struct dns_dbmethods {
|
||||||
|
isc_result_t (*setgluecachestats)(dns_db_t *db, isc_stats_t *stats);
|
||||||
|
isc_result_t (*adjusthashsize)(dns_db_t *db, size_t size);
|
||||||
|
void (*setmaxrrperset)(dns_db_t *db, uint32_t value);
|
||||||
|
+ void (*setmaxtypepername)(dns_db_t *db, uint32_t value);
|
||||||
|
} dns_dbmethods_t;
|
||||||
|
|
||||||
|
typedef isc_result_t (*dns_dbcreatefunc_t)(isc_mem_t *mctx,
|
||||||
|
@@ -1791,6 +1792,16 @@ dns_db_setmaxrrperset(dns_db_t *db, uint32_t value);
|
||||||
|
* is nonzero, then any subsequent attempt to add an rdataset with
|
||||||
|
* more than 'value' RRs will return ISC_R_NOSPACE.
|
||||||
|
*/
|
||||||
|
+
|
||||||
|
+void
|
||||||
|
+dns_db_setmaxtypepername(dns_db_t *db, uint32_t value);
|
||||||
|
+/*%<
|
||||||
|
+ * Set the maximum permissible number of RR types per owner name.
|
||||||
|
+ *
|
||||||
|
+ * If 'value' is nonzero, then any subsequent attempt to add an rdataset with a
|
||||||
|
+ * RR type that would exceed the number of already stored RR types will return
|
||||||
|
+ * ISC_R_NOSPACE.
|
||||||
|
+ */
|
||||||
|
ISC_LANG_ENDDECLS
|
||||||
|
|
||||||
|
#endif /* DNS_DB_H */
|
||||||
|
diff --git a/lib/dns/include/dns/view.h b/lib/dns/include/dns/view.h
|
||||||
|
index 0d502f4dd2..0a72f58e98 100644
|
||||||
|
--- a/lib/dns/include/dns/view.h
|
||||||
|
+++ b/lib/dns/include/dns/view.h
|
||||||
|
@@ -187,6 +187,7 @@ struct dns_view {
|
||||||
|
uint32_t fail_ttl;
|
||||||
|
dns_badcache_t *failcache;
|
||||||
|
uint32_t maxrrperset;
|
||||||
|
+ uint32_t maxtypepername;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Configurable data for server use only,
|
||||||
|
@@ -1346,6 +1347,12 @@ dns_view_setmaxrrperset(dns_view_t *view, uint32_t value);
|
||||||
|
* Set the maximum resource records per RRSet that can be cached.
|
||||||
|
*/
|
||||||
|
|
||||||
|
+void
|
||||||
|
+dns_view_setmaxtypepername(dns_view_t *view, uint32_t value);
|
||||||
|
+/*%<
|
||||||
|
+ * Set the maximum resource record types per owner name that can be cached.
|
||||||
|
+ */
|
||||||
|
+
|
||||||
|
ISC_LANG_ENDDECLS
|
||||||
|
|
||||||
|
#endif /* DNS_VIEW_H */
|
||||||
|
diff --git a/lib/dns/include/dns/zone.h b/lib/dns/include/dns/zone.h
|
||||||
|
index e902043357..6fca11f3fd 100644
|
||||||
|
--- a/lib/dns/include/dns/zone.h
|
||||||
|
+++ b/lib/dns/include/dns/zone.h
|
||||||
|
@@ -356,6 +356,19 @@ dns_zone_setmaxrrperset(dns_zone_t *zone, uint32_t maxrrperset);
|
||||||
|
*\li void
|
||||||
|
*/
|
||||||
|
|
||||||
|
+void
|
||||||
|
+dns_zone_setmaxtypepername(dns_zone_t *zone, uint32_t maxtypepername);
|
||||||
|
+/*%<
|
||||||
|
+ * Sets the maximum number of resource record types per owner name
|
||||||
|
+ * permitted in a zone. 0 implies unlimited.
|
||||||
|
+ *
|
||||||
|
+ * Requires:
|
||||||
|
+ *\li 'zone' to be valid initialised zone.
|
||||||
|
+ *
|
||||||
|
+ * Returns:
|
||||||
|
+ *\li void
|
||||||
|
+ */
|
||||||
|
+
|
||||||
|
void
|
||||||
|
dns_zone_setmaxttl(dns_zone_t *zone, uint32_t maxttl);
|
||||||
|
/*%<
|
||||||
|
diff --git a/lib/dns/rbtdb.c b/lib/dns/rbtdb.c
|
||||||
|
index ca71bb9c03..ed5015c2d4 100644
|
||||||
|
--- a/lib/dns/rbtdb.c
|
||||||
|
+++ b/lib/dns/rbtdb.c
|
||||||
|
@@ -483,6 +483,7 @@ struct dns_rbtdb {
|
||||||
|
rbtdb_serial_t least_serial;
|
||||||
|
rbtdb_serial_t next_serial;
|
||||||
|
uint32_t maxrrperset;
|
||||||
|
+ uint32_t maxtypepername;
|
||||||
|
rbtdb_version_t *current_version;
|
||||||
|
rbtdb_version_t *future_version;
|
||||||
|
rbtdb_versionlist_t open_versions;
|
||||||
|
@@ -6222,19 +6223,13 @@ update_recordsandxfrsize(bool add, rbtdb_version_t *rbtversion,
|
||||||
|
RWUNLOCK(&rbtversion->rwlock, isc_rwlocktype_write);
|
||||||
|
}
|
||||||
|
|
||||||
|
-#ifndef DNS_RBTDB_MAX_RTYPES
|
||||||
|
-#define DNS_RBTDB_MAX_RTYPES 100
|
||||||
|
-#endif /* DNS_RBTDB_MAX_RTYPES */
|
||||||
|
-
|
||||||
|
static bool
|
||||||
|
overmaxtype(dns_rbtdb_t *rbtdb, uint32_t ntypes) {
|
||||||
|
- UNUSED(rbtdb);
|
||||||
|
-
|
||||||
|
- if (DNS_RBTDB_MAX_RTYPES == 0) {
|
||||||
|
+ if (rbtdb->maxtypepername == 0) {
|
||||||
|
return (false);
|
||||||
|
}
|
||||||
|
|
||||||
|
- return (ntypes >= DNS_RBTDB_MAX_RTYPES);
|
||||||
|
+ return (ntypes >= rbtdb->maxtypepername);
|
||||||
|
}
|
||||||
|
|
||||||
|
static bool
|
||||||
|
@@ -6794,7 +6789,7 @@ find_header:
|
||||||
|
if (!IS_CACHE(rbtdb) && overmaxtype(rbtdb, ntypes)) {
|
||||||
|
free_rdataset(rbtdb, rbtdb->common.mctx,
|
||||||
|
newheader);
|
||||||
|
- return (ISC_R_QUOTA);
|
||||||
|
+ return (DNS_R_TOOMANYRECORDS);
|
||||||
|
}
|
||||||
|
|
||||||
|
newheader->down = NULL;
|
||||||
|
@@ -8623,6 +8618,15 @@ setmaxrrperset(dns_db_t *db, uint32_t maxrrperset) {
|
||||||
|
rbtdb->maxrrperset = maxrrperset;
|
||||||
|
}
|
||||||
|
|
||||||
|
+static void
|
||||||
|
+setmaxtypepername(dns_db_t *db, uint32_t maxtypepername) {
|
||||||
|
+ dns_rbtdb_t *rbtdb = (dns_rbtdb_t *)db;
|
||||||
|
+
|
||||||
|
+ REQUIRE(VALID_RBTDB(rbtdb));
|
||||||
|
+
|
||||||
|
+ rbtdb->maxtypepername = maxtypepername;
|
||||||
|
+}
|
||||||
|
+
|
||||||
|
static dns_stats_t *
|
||||||
|
getrrsetstats(dns_db_t *db) {
|
||||||
|
dns_rbtdb_t *rbtdb = (dns_rbtdb_t *)db;
|
||||||
|
@@ -8747,7 +8751,8 @@ static dns_dbmethods_t zone_methods = { attach,
|
||||||
|
NULL, /* getservestalerefresh */
|
||||||
|
setgluecachestats,
|
||||||
|
adjusthashsize,
|
||||||
|
- setmaxrrperset };
|
||||||
|
+ setmaxrrperset,
|
||||||
|
+ setmaxtypepername };
|
||||||
|
|
||||||
|
static dns_dbmethods_t cache_methods = { attach,
|
||||||
|
detach,
|
||||||
|
@@ -8800,7 +8805,8 @@ static dns_dbmethods_t cache_methods = { attach,
|
||||||
|
getservestalerefresh,
|
||||||
|
NULL,
|
||||||
|
adjusthashsize,
|
||||||
|
- setmaxrrperset };
|
||||||
|
+ setmaxrrperset,
|
||||||
|
+ setmaxtypepername };
|
||||||
|
|
||||||
|
isc_result_t
|
||||||
|
dns_rbtdb_create(isc_mem_t *mctx, const dns_name_t *origin, dns_dbtype_t type,
|
||||||
|
diff --git a/lib/dns/sdb.c b/lib/dns/sdb.c
|
||||||
|
index 84cd324fb4..77a5834b76 100644
|
||||||
|
--- a/lib/dns/sdb.c
|
||||||
|
+++ b/lib/dns/sdb.c
|
||||||
|
@@ -1313,7 +1313,8 @@ static dns_dbmethods_t sdb_methods = {
|
||||||
|
NULL, /* getservestalerefresh */
|
||||||
|
NULL, /* setgluecachestats */
|
||||||
|
NULL, /* adjusthashsize */
|
||||||
|
- NULL /* setmaxrrperset */
|
||||||
|
+ NULL, /* setmaxrrperset */
|
||||||
|
+ NULL /* setmaxtypepername */
|
||||||
|
};
|
||||||
|
|
||||||
|
static isc_result_t
|
||||||
|
diff --git a/lib/dns/sdlz.c b/lib/dns/sdlz.c
|
||||||
|
index 60a1d23b3b..418a4a14ee 100644
|
||||||
|
--- a/lib/dns/sdlz.c
|
||||||
|
+++ b/lib/dns/sdlz.c
|
||||||
|
@@ -1285,7 +1285,8 @@ static dns_dbmethods_t sdlzdb_methods = {
|
||||||
|
NULL, /* getservestalerefresh */
|
||||||
|
NULL, /* setgluecachestats */
|
||||||
|
NULL, /* adjusthashsize */
|
||||||
|
- NULL /* setmaxrrperset */
|
||||||
|
+ NULL, /* setmaxrrperset */
|
||||||
|
+ NULL /* setmaxtypepername */
|
||||||
|
};
|
||||||
|
|
||||||
|
/*
|
||||||
|
diff --git a/lib/dns/view.c b/lib/dns/view.c
|
||||||
|
index a672aa8bc8..98579f03d9 100644
|
||||||
|
--- a/lib/dns/view.c
|
||||||
|
+++ b/lib/dns/view.c
|
||||||
|
@@ -871,6 +871,7 @@ dns_view_setcache(dns_view_t *view, dns_cache_t *cache, bool shared) {
|
||||||
|
INSIST(DNS_DB_VALID(view->cachedb));
|
||||||
|
|
||||||
|
dns_cache_setmaxrrperset(view->cache, view->maxrrperset);
|
||||||
|
+ dns_cache_setmaxtypepername(view->cache, view->maxtypepername);
|
||||||
|
}
|
||||||
|
|
||||||
|
bool
|
||||||
|
@@ -2555,3 +2556,12 @@ dns_view_setmaxrrperset(dns_view_t *view, uint32_t value) {
|
||||||
|
dns_cache_setmaxrrperset(view->cache, value);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
+
|
||||||
|
+void
|
||||||
|
+dns_view_setmaxtypepername(dns_view_t *view, uint32_t value) {
|
||||||
|
+ REQUIRE(DNS_VIEW_VALID(view));
|
||||||
|
+ view->maxtypepername = value;
|
||||||
|
+ if (view->cache != NULL) {
|
||||||
|
+ dns_cache_setmaxtypepername(view->cache, value);
|
||||||
|
+ }
|
||||||
|
+}
|
||||||
|
diff --git a/lib/dns/zone.c b/lib/dns/zone.c
|
||||||
|
index 5c8d97ed18..e1fb9ab50b 100644
|
||||||
|
--- a/lib/dns/zone.c
|
||||||
|
+++ b/lib/dns/zone.c
|
||||||
|
@@ -277,6 +277,7 @@ struct dns_zone {
|
||||||
|
|
||||||
|
uint32_t maxrecords;
|
||||||
|
uint32_t maxrrperset;
|
||||||
|
+ uint32_t maxtypepername;
|
||||||
|
|
||||||
|
isc_sockaddr_t *masters;
|
||||||
|
isc_dscp_t *masterdscps;
|
||||||
|
@@ -9959,6 +9960,7 @@ cleanup:
|
||||||
|
}
|
||||||
|
|
||||||
|
dns_diff_clear(&_sig_diff);
|
||||||
|
+ dns_diff_clear(&post_diff);
|
||||||
|
|
||||||
|
for (i = 0; i < nkeys; i++) {
|
||||||
|
dst_key_free(&zone_keys[i]);
|
||||||
|
@@ -12168,6 +12170,16 @@ dns_zone_setmaxrrperset(dns_zone_t *zone, uint32_t val) {
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
+void
|
||||||
|
+dns_zone_setmaxtypepername(dns_zone_t *zone, uint32_t val) {
|
||||||
|
+ REQUIRE(DNS_ZONE_VALID(zone));
|
||||||
|
+
|
||||||
|
+ zone->maxtypepername = val;
|
||||||
|
+ if (zone->db != NULL) {
|
||||||
|
+ dns_db_setmaxtypepername(zone->db, val);
|
||||||
|
+ }
|
||||||
|
+}
|
||||||
|
+
|
||||||
|
static bool
|
||||||
|
notify_isqueued(dns_zone_t *zone, unsigned int flags, dns_name_t *name,
|
||||||
|
isc_sockaddr_t *addr, dns_tsigkey_t *key) {
|
||||||
|
@@ -14573,6 +14585,8 @@ ns_query(dns_zone_t *zone, dns_rdataset_t *soardataset, dns_stub_t *stub) {
|
||||||
|
}
|
||||||
|
dns_db_settask(stub->db, zone->task);
|
||||||
|
dns_db_setmaxrrperset(stub->db, zone->maxrrperset);
|
||||||
|
+ dns_db_setmaxtypepername(stub->db,
|
||||||
|
+ zone->maxtypepername);
|
||||||
|
}
|
||||||
|
|
||||||
|
result = dns_db_newversion(stub->db, &stub->version);
|
||||||
|
@@ -17295,6 +17309,7 @@ zone_replacedb(dns_zone_t *zone, dns_db_t *db, bool dump) {
|
||||||
|
zone_attachdb(zone, db);
|
||||||
|
dns_db_settask(zone->db, zone->task);
|
||||||
|
dns_db_setmaxrrperset(zone->db, zone->maxrrperset);
|
||||||
|
+ dns_db_setmaxtypepername(zone->db, zone->maxtypepername);
|
||||||
|
DNS_ZONE_SETFLAG(zone, DNS_ZONEFLG_LOADED | DNS_ZONEFLG_NEEDNOTIFY);
|
||||||
|
return (ISC_R_SUCCESS);
|
||||||
|
|
||||||
|
@@ -23444,6 +23459,7 @@ dns_zone_makedb(dns_zone_t *zone, dns_db_t **dbp) {
|
||||||
|
|
||||||
|
dns_db_settask(db, zone->task);
|
||||||
|
dns_db_setmaxrrperset(db, zone->maxrrperset);
|
||||||
|
+ dns_db_setmaxtypepername(db, zone->maxtypepername);
|
||||||
|
|
||||||
|
*dbp = db;
|
||||||
|
|
||||||
|
diff --git a/lib/isccfg/namedconf.c b/lib/isccfg/namedconf.c
|
||||||
|
index dce30537dd..ac9fc2af5e 100644
|
||||||
|
--- a/lib/isccfg/namedconf.c
|
||||||
|
+++ b/lib/isccfg/namedconf.c
|
||||||
|
@@ -2239,6 +2239,9 @@ static cfg_clausedef_t zone_clauses[] = {
|
||||||
|
{ "max-records-per-type", &cfg_type_uint32,
|
||||||
|
CFG_ZONE_PRIMARY | CFG_ZONE_SECONDARY | CFG_ZONE_MIRROR |
|
||||||
|
CFG_ZONE_STUB | CFG_ZONE_STATICSTUB | CFG_ZONE_REDIRECT },
|
||||||
|
+ { "max-types-per-name", &cfg_type_uint32,
|
||||||
|
+ CFG_ZONE_PRIMARY | CFG_ZONE_SECONDARY | CFG_ZONE_MIRROR |
|
||||||
|
+ CFG_ZONE_STUB | CFG_ZONE_STATICSTUB | CFG_ZONE_REDIRECT },
|
||||||
|
{ "max-refresh-time", &cfg_type_uint32,
|
||||||
|
CFG_ZONE_SECONDARY | CFG_ZONE_MIRROR | CFG_ZONE_STUB },
|
||||||
|
{ "max-retry-time", &cfg_type_uint32,
|
||||||
|
diff --git a/lib/ns/update.c b/lib/ns/update.c
|
||||||
|
index c5ce1eaf09..0e0bdc9c03 100644
|
||||||
|
--- a/lib/ns/update.c
|
||||||
|
+++ b/lib/ns/update.c
|
||||||
|
@@ -3112,9 +3112,18 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
||||||
|
dns_diff_clear(&ctx.add_diff);
|
||||||
|
goto failure;
|
||||||
|
}
|
||||||
|
- CHECK(update_one_rr(db, ver, &diff,
|
||||||
|
- DNS_DIFFOP_ADD,
|
||||||
|
- name, ttl, &rdata));
|
||||||
|
+ result = update_one_rr(
|
||||||
|
+ db, ver, &diff, DNS_DIFFOP_ADD,
|
||||||
|
+ name, ttl, &rdata);
|
||||||
|
+ if (result != ISC_R_SUCCESS) {
|
||||||
|
+ update_log(client, zone,
|
||||||
|
+ LOGLEVEL_PROTOCOL,
|
||||||
|
+ "adding an RR "
|
||||||
|
+ "failed: %s",
|
||||||
|
+ isc_result_totext(
|
||||||
|
+ result));
|
||||||
|
+ goto failure;
|
||||||
|
+ }
|
||||||
|
}
|
||||||
|
}
|
||||||
|
} else if (update_class == dns_rdataclass_any) {
|
||||||
|
--
|
||||||
|
2.45.2
|
||||||
|
|
||||||
@ -1,10 +1,7 @@
|
|||||||
From 71df06e2bf3da31c5d542fb33dbda67b21537322 Mon Sep 17 00:00:00 2001
|
From c5357835c98b7b028f8a041b6976bb335c9a4056 Mon Sep 17 00:00:00 2001
|
||||||
From: =?UTF-8?q?Ond=C5=99ej=20Sur=C3=BD?= <ondrej@isc.org>
|
From: =?UTF-8?q?Ond=C5=99ej=20Sur=C3=BD?= <ondrej@isc.org>
|
||||||
Date: Fri, 1 Mar 2024 08:26:07 +0100
|
Date: Fri, 1 Mar 2024 08:26:07 +0100
|
||||||
Subject: [PATCH] [9.11][CVE-2024-1737] Add a limit to the number of RRs in
|
Subject: [PATCH] Add a limit to the number of RRs in RRSets
|
||||||
RRSets
|
|
||||||
|
|
||||||
Add a limit to the number of RRs in RRSets
|
|
||||||
|
|
||||||
Previously, the number of RRs in the RRSets were internally unlimited.
|
Previously, the number of RRs in the RRSets were internally unlimited.
|
||||||
As the data structure that holds the RRs is just a linked list, and
|
As the data structure that holds the RRs is just a linked list, and
|
||||||
@ -19,8 +16,7 @@ following define to CFLAGS:
|
|||||||
-DDNS_RDATASET_MAX_RECORDS=<limit>
|
-DDNS_RDATASET_MAX_RECORDS=<limit>
|
||||||
|
|
||||||
(cherry picked from commit c5c4d00c38530390c9e1ae4c98b65fbbadfe9e5e)
|
(cherry picked from commit c5c4d00c38530390c9e1ae4c98b65fbbadfe9e5e)
|
||||||
(cherry picked from commit 7f705778af729ada7fec36ac4b456c73329bd996)
|
(cherry picked from commit fdabf4b9570a60688f9f7d1e88d885f7a3718bca)
|
||||||
(cherry picked from commit b9b5485b22c364fb88c27aa04bad4c8f616da3fa)
|
|
||||||
|
|
||||||
Add a limit to the number of RR types for single name
|
Add a limit to the number of RR types for single name
|
||||||
|
|
||||||
@ -37,8 +33,7 @@ define to CFLAGS:
|
|||||||
|
|
||||||
-DDNS_RBTDB_MAX_RTYPES=<limit>
|
-DDNS_RBTDB_MAX_RTYPES=<limit>
|
||||||
|
|
||||||
(cherry picked from commit 538b843d84f49ba5125ff545e3d0cf1c8434a8f2)
|
(cherry picked from commit dfcadc2085c8844b5836aff2b5ea51fb60c34868)
|
||||||
(cherry picked from commit 3f10d6eff035702796ba82cd28b9f7cf9836e743)
|
|
||||||
|
|
||||||
Optimize the slabheader placement for certain RRTypes
|
Optimize the slabheader placement for certain RRTypes
|
||||||
|
|
||||||
@ -47,9 +42,7 @@ the beginning of the rdataslab header data graph. The non-priority
|
|||||||
types either go right after the priority types (if any).
|
types either go right after the priority types (if any).
|
||||||
|
|
||||||
(cherry picked from commit 3ac482be7fd058d284e89873021339579fad0615)
|
(cherry picked from commit 3ac482be7fd058d284e89873021339579fad0615)
|
||||||
(cherry picked from commit 23a4652346fb2877d6246b1eebaa967969dbde16)
|
(cherry picked from commit 8ef414a7f38a04cfc11df44adaedaf3126fa3878)
|
||||||
|
|
||||||
[9.11][CVE-2024-1737 (part 2)] Be smarter about refusing to add many RR types to the database
|
|
||||||
|
|
||||||
Expand the list of the priority types
|
Expand the list of the priority types
|
||||||
|
|
||||||
@ -59,7 +52,15 @@ for faster access and to avoid eviction when there are more types than
|
|||||||
the max-types-per-name limit.
|
the max-types-per-name limit.
|
||||||
|
|
||||||
(cherry picked from commit b27c6bcce894786a8e082eafd59eccbf6f2731cb)
|
(cherry picked from commit b27c6bcce894786a8e082eafd59eccbf6f2731cb)
|
||||||
(cherry picked from commit 3e0a67e4bdb253dae3a03a45c1aa117239a3313d)
|
(cherry picked from commit d56d2a32b861e81c2aaaabd309c4c58b629ede32)
|
||||||
|
|
||||||
|
Make the resolver qtype ANY test order agnostic
|
||||||
|
|
||||||
|
Instead of relying on a specific order of the RR types in the databases
|
||||||
|
pick the first RR type as returned from the cache.
|
||||||
|
|
||||||
|
(cherry picked from commit 58f660cf2b800963fa649bc9823a626009db3a7e)
|
||||||
|
(cherry picked from commit c5ebda6deb0997dc520b26fa0639891459de5cb6)
|
||||||
|
|
||||||
Be smarter about refusing to add many RR types to the database
|
Be smarter about refusing to add many RR types to the database
|
||||||
|
|
||||||
@ -80,46 +81,74 @@ smarter:
|
|||||||
list.
|
list.
|
||||||
|
|
||||||
(cherry picked from commit 57cd34441a1b4ecc9874a4a106c2c95b8d7a3120)
|
(cherry picked from commit 57cd34441a1b4ecc9874a4a106c2c95b8d7a3120)
|
||||||
(cherry picked from commit e4d7ce686bb38428eddc7e33b40057d68eca9a6e)
|
(cherry picked from commit 26c9da5f2857b72077c17e06ac79f068c63782cc)
|
||||||
---
|
---
|
||||||
configure | 2 +-
|
bin/tests/system/resolver/tests.sh | 9 ++-
|
||||||
configure.ac | 2 +-
|
configure | 2 +-
|
||||||
lib/dns/rbtdb.c | 114 +++++++++++++++++++++++++++++++++++++++++++-
|
configure.ac | 2 +-
|
||||||
lib/dns/rdataslab.c | 12 +++++
|
lib/dns/rbtdb.c | 125 ++++++++++++++++++++++++++++-
|
||||||
4 files changed, 126 insertions(+), 4 deletions(-)
|
lib/dns/rdataslab.c | 12 +++
|
||||||
|
5 files changed, 144 insertions(+), 6 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/bin/tests/system/resolver/tests.sh b/bin/tests/system/resolver/tests.sh
|
||||||
|
index 6c69c1104e..bd997a61a4 100755
|
||||||
|
--- a/bin/tests/system/resolver/tests.sh
|
||||||
|
+++ b/bin/tests/system/resolver/tests.sh
|
||||||
|
@@ -553,15 +553,20 @@ n=`expr $n + 1`
|
||||||
|
echo_i "check prefetch qtype * (${n})"
|
||||||
|
ret=0
|
||||||
|
$DIG $DIGOPTS @10.53.0.5 fetchall.tld any > dig.out.1.${n} || ret=1
|
||||||
|
-ttl1=`awk '/"A" "short" "ttl"/ { print $2 - 3 }' dig.out.1.${n}`
|
||||||
|
+ttl1=$(awk '/^fetchall.tld/ { print $2 - 3; exit }' dig.out.1.${n})
|
||||||
|
# sleep so we are in prefetch range
|
||||||
|
sleep ${ttl1:-0}
|
||||||
|
# trigger prefetch
|
||||||
|
$DIG $DIGOPTS @10.53.0.5 fetchall.tld any > dig.out.2.${n} || ret=1
|
||||||
|
-ttl2=`awk '/"A" "short" "ttl"/ { print $2 }' dig.out.2.${n}`
|
||||||
|
+ttl2=$(awk '/^fetchall.tld/ { print $2; exit }' dig.out.2.${n})
|
||||||
|
sleep 1
|
||||||
|
# check that the nameserver is still alive
|
||||||
|
$DIG $DIGOPTS @10.53.0.5 fetchall.tld any > dig.out.3.${n} || ret=1
|
||||||
|
+# note that only the first record is prefetched,
|
||||||
|
+# because of the order of the records in the cache
|
||||||
|
+$DIG $DIGOPTS @10.53.0.5 fetchall.tld any >dig.out.3.${n} || ret=1
|
||||||
|
+ttl3=$(awk '/^fetchall.tld/ { print $2; exit }' dig.out.3.${n})
|
||||||
|
+test "${ttl3:-0}" -gt "${ttl2:-1}" || ret=1
|
||||||
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
diff --git a/configure b/configure
|
diff --git a/configure b/configure
|
||||||
index e060e9d..6421c9b 100755
|
index ed2d4869e5..be0f60eaba 100755
|
||||||
--- a/configure
|
--- a/configure
|
||||||
+++ b/configure
|
+++ b/configure
|
||||||
@@ -12189,7 +12189,7 @@ fi
|
@@ -12295,7 +12295,7 @@ fi
|
||||||
|
|
||||||
XTARGETS=
|
XTARGETS=
|
||||||
case "$enable_developer" in
|
if test "$enable_developer" = "yes"; then :
|
||||||
yes)
|
- STD_CDEFINES="$STD_CDEFINES -DISC_MEM_DEFAULTFILL=1 -DISC_LIST_CHECKINIT=1"
|
||||||
- STD_CDEFINES="$STD_CDEFINES -DISC_LIST_CHECKINIT=1"
|
+ STD_CDEFINES="$STD_CDEFINES -DISC_MEM_DEFAULTFILL=1 -DISC_LIST_CHECKINIT=1 -DDNS_RDATASET_MAX_RECORDS=5000 -DDNS_RBTDB_MAX_RTYPES=5000"
|
||||||
+ STD_CDEFINES="$STD_CDEFINES -DISC_LIST_CHECKINIT=1 -DDNS_RDATASET_MAX_RECORDS=5000 -DDNS_RBTDB_MAX_RTYPES=5000"
|
test "${enable_fixed_rrset+set}" = set || enable_fixed_rrset=yes
|
||||||
test "${enable_fixed_rrset+set}" = set || enable_fixed_rrset=yes
|
test "${enable_querytrace+set}" = set || enable_querytrace=yes
|
||||||
test "${enable_querytrace+set}" = set || enable_querytrace=yes
|
test "${with_cmocka+set}" = set || with_cmocka=yes
|
||||||
test "${enable_filter_aaaa+set}" = set || enable_filter_aaaa=yes
|
|
||||||
diff --git a/configure.ac b/configure.ac
|
diff --git a/configure.ac b/configure.ac
|
||||||
index 83cad4a..1c35ce9 100644
|
index 287de41369..3ff4bdd135 100644
|
||||||
--- a/configure.ac
|
--- a/configure.ac
|
||||||
+++ b/configure.ac
|
+++ b/configure.ac
|
||||||
@@ -100,7 +100,7 @@ AC_ARG_ENABLE(developer,
|
@@ -94,7 +94,7 @@ AC_ARG_ENABLE([developer],
|
||||||
|
|
||||||
XTARGETS=
|
XTARGETS=
|
||||||
case "$enable_developer" in
|
AS_IF([test "$enable_developer" = "yes"],
|
||||||
yes)
|
- [STD_CDEFINES="$STD_CDEFINES -DISC_MEM_DEFAULTFILL=1 -DISC_LIST_CHECKINIT=1"
|
||||||
- STD_CDEFINES="$STD_CDEFINES -DISC_LIST_CHECKINIT=1"
|
+ [STD_CDEFINES="$STD_CDEFINES -DISC_MEM_DEFAULTFILL=1 -DISC_LIST_CHECKINIT=1 -DDNS_RDATASET_MAX_RECORDS=5000 -DDNS_RBTDB_MAX_RTYPES=5000"
|
||||||
+ STD_CDEFINES="$STD_CDEFINES -DISC_LIST_CHECKINIT=1 -DDNS_RDATASET_MAX_RECORDS=5000 -DDNS_RBTDB_MAX_RTYPES=5000"
|
test "${enable_fixed_rrset+set}" = set || enable_fixed_rrset=yes
|
||||||
test "${enable_fixed_rrset+set}" = set || enable_fixed_rrset=yes
|
test "${enable_querytrace+set}" = set || enable_querytrace=yes
|
||||||
test "${enable_querytrace+set}" = set || enable_querytrace=yes
|
test "${with_cmocka+set}" = set || with_cmocka=yes
|
||||||
test "${enable_filter_aaaa+set}" = set || enable_filter_aaaa=yes
|
|
||||||
diff --git a/lib/dns/rbtdb.c b/lib/dns/rbtdb.c
|
diff --git a/lib/dns/rbtdb.c b/lib/dns/rbtdb.c
|
||||||
index ee59c1b..a2b2df7 100644
|
index 2707507bd7..e840c0665d 100644
|
||||||
--- a/lib/dns/rbtdb.c
|
--- a/lib/dns/rbtdb.c
|
||||||
+++ b/lib/dns/rbtdb.c
|
+++ b/lib/dns/rbtdb.c
|
||||||
@@ -1183,6 +1183,44 @@ set_ttl(dns_rbtdb_t *rbtdb, rdatasetheader_t *header, dns_ttl_t newttl) {
|
@@ -967,6 +967,48 @@ set_ttl(dns_rbtdb_t *rbtdb, rdatasetheader_t *header, dns_ttl_t newttl) {
|
||||||
isc_heap_decreased(heap, header->heap_index);
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
+static bool
|
+static bool
|
||||||
@ -145,6 +174,10 @@ index ee59c1b..a2b2df7 100644
|
|||||||
+ case RBTDB_RDATATYPE_VALUE(dns_rdatatype_rrsig, dns_rdatatype_cname):
|
+ case RBTDB_RDATATYPE_VALUE(dns_rdatatype_rrsig, dns_rdatatype_cname):
|
||||||
+ case dns_rdatatype_dname:
|
+ case dns_rdatatype_dname:
|
||||||
+ case RBTDB_RDATATYPE_VALUE(dns_rdatatype_rrsig, dns_rdatatype_dname):
|
+ case RBTDB_RDATATYPE_VALUE(dns_rdatatype_rrsig, dns_rdatatype_dname):
|
||||||
|
+ case dns_rdatatype_svcb:
|
||||||
|
+ case RBTDB_RDATATYPE_VALUE(dns_rdatatype_rrsig, dns_rdatatype_svcb):
|
||||||
|
+ case dns_rdatatype_https:
|
||||||
|
+ case RBTDB_RDATATYPE_VALUE(dns_rdatatype_rrsig, dns_rdatatype_https):
|
||||||
+ case dns_rdatatype_dnskey:
|
+ case dns_rdatatype_dnskey:
|
||||||
+ case RBTDB_RDATATYPE_VALUE(dns_rdatatype_rrsig, dns_rdatatype_dnskey):
|
+ case RBTDB_RDATATYPE_VALUE(dns_rdatatype_rrsig, dns_rdatatype_dnskey):
|
||||||
+ case dns_rdatatype_srv:
|
+ case dns_rdatatype_srv:
|
||||||
@ -163,7 +196,7 @@ index ee59c1b..a2b2df7 100644
|
|||||||
/*%
|
/*%
|
||||||
* These functions allow the heap code to rank the priority of each
|
* These functions allow the heap code to rank the priority of each
|
||||||
* element. It returns true if v1 happens "sooner" than v2.
|
* element. It returns true if v1 happens "sooner" than v2.
|
||||||
@@ -6278,6 +6316,30 @@ update_recordsandbytes(bool add, rbtdb_version_t *rbtversion,
|
@@ -6179,6 +6221,30 @@ update_recordsandxfrsize(bool add, rbtdb_version_t *rbtversion,
|
||||||
RWUNLOCK(&rbtversion->rwlock, isc_rwlocktype_write);
|
RWUNLOCK(&rbtversion->rwlock, isc_rwlocktype_write);
|
||||||
}
|
}
|
||||||
|
|
||||||
@ -194,15 +227,15 @@ index ee59c1b..a2b2df7 100644
|
|||||||
/*
|
/*
|
||||||
* write lock on rbtnode must be held.
|
* write lock on rbtnode must be held.
|
||||||
*/
|
*/
|
||||||
@@ -6288,6 +6350,7 @@ add32(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, rbtdb_version_t *rbtversion,
|
@@ -6190,6 +6256,7 @@ add32(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, const dns_name_t *nodename,
|
||||||
{
|
|
||||||
rbtdb_changed_t *changed = NULL;
|
rbtdb_changed_t *changed = NULL;
|
||||||
rdatasetheader_t *topheader, *topheader_prev, *header, *sigheader;
|
rdatasetheader_t *topheader = NULL, *topheader_prev = NULL;
|
||||||
|
rdatasetheader_t *header = NULL, *sigheader = NULL;
|
||||||
+ rdatasetheader_t *prioheader = NULL, *expireheader = NULL;
|
+ rdatasetheader_t *prioheader = NULL, *expireheader = NULL;
|
||||||
unsigned char *merged;
|
unsigned char *merged = NULL;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
bool header_nx;
|
bool header_nx;
|
||||||
@@ -6297,6 +6360,7 @@ add32(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, rbtdb_version_t *rbtversion,
|
@@ -6199,6 +6266,7 @@ add32(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, const dns_name_t *nodename,
|
||||||
rbtdb_rdatatype_t negtype, sigtype;
|
rbtdb_rdatatype_t negtype, sigtype;
|
||||||
dns_trust_t trust;
|
dns_trust_t trust;
|
||||||
int idx;
|
int idx;
|
||||||
@ -210,9 +243,17 @@ index ee59c1b..a2b2df7 100644
|
|||||||
|
|
||||||
/*
|
/*
|
||||||
* Add an rdatasetheader_t to a node.
|
* Add an rdatasetheader_t to a node.
|
||||||
@@ -6429,6 +6493,15 @@ add32(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, rbtdb_version_t *rbtversion,
|
@@ -6272,6 +6340,7 @@ add32(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, const dns_name_t *nodename,
|
||||||
for (topheader = rbtnode->data;
|
topheader = topheader->next) {
|
||||||
topheader != NULL;
|
if (topheader->type == sigtype) {
|
||||||
|
sigheader = topheader;
|
||||||
|
+ break;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
negtype = RBTDB_RDATATYPE_VALUE(covers, 0);
|
||||||
|
@@ -6331,6 +6400,15 @@ add32(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, const dns_name_t *nodename,
|
||||||
|
|
||||||
|
for (topheader = rbtnode->data; topheader != NULL;
|
||||||
topheader = topheader->next) {
|
topheader = topheader->next) {
|
||||||
+ if (IS_CACHE(rbtdb) && ACTIVE(topheader, now)) {
|
+ if (IS_CACHE(rbtdb) && ACTIVE(topheader, now)) {
|
||||||
+ ++ntypes;
|
+ ++ntypes;
|
||||||
@ -224,9 +265,9 @@ index ee59c1b..a2b2df7 100644
|
|||||||
+ prioheader = topheader;
|
+ prioheader = topheader;
|
||||||
+ }
|
+ }
|
||||||
if (topheader->type == newheader->type ||
|
if (topheader->type == newheader->type ||
|
||||||
topheader->type == negtype)
|
topheader->type == negtype) {
|
||||||
break;
|
break;
|
||||||
@@ -6792,9 +6865,46 @@ add32(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, rbtdb_version_t *rbtversion,
|
@@ -6712,9 +6790,52 @@ find_header:
|
||||||
/*
|
/*
|
||||||
* No rdatasets of the given type exist at the node.
|
* No rdatasets of the given type exist at the node.
|
||||||
*/
|
*/
|
||||||
@ -271,17 +312,23 @@ index ee59c1b..a2b2df7 100644
|
|||||||
+
|
+
|
||||||
+ set_ttl(rbtdb, expireheader, 0);
|
+ set_ttl(rbtdb, expireheader, 0);
|
||||||
+ mark_header_ancient(rbtdb, expireheader);
|
+ mark_header_ancient(rbtdb, expireheader);
|
||||||
|
+ /*
|
||||||
|
+ * FIXME: In theory, we should mark the RRSIG
|
||||||
|
+ * and the header at the same time, but there is
|
||||||
|
+ * no direct link between those two header, so
|
||||||
|
+ * we would have to check the whole list again.
|
||||||
|
+ */
|
||||||
+ }
|
+ }
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
diff --git a/lib/dns/rdataslab.c b/lib/dns/rdataslab.c
|
diff --git a/lib/dns/rdataslab.c b/lib/dns/rdataslab.c
|
||||||
index b0f77b1..347b7d2 100644
|
index 1d5e88f745..dda903819a 100644
|
||||||
--- a/lib/dns/rdataslab.c
|
--- a/lib/dns/rdataslab.c
|
||||||
+++ b/lib/dns/rdataslab.c
|
+++ b/lib/dns/rdataslab.c
|
||||||
@@ -115,6 +115,10 @@ fillin_offsets(unsigned char *offsetbase, unsigned int *offsettable,
|
@@ -110,6 +110,10 @@ fillin_offsets(unsigned char *offsetbase, unsigned int *offsettable,
|
||||||
}
|
}
|
||||||
#endif
|
#endif /* if DNS_RDATASET_FIXED */
|
||||||
|
|
||||||
+#ifndef DNS_RDATASET_MAX_RECORDS
|
+#ifndef DNS_RDATASET_MAX_RECORDS
|
||||||
+#define DNS_RDATASET_MAX_RECORDS 100
|
+#define DNS_RDATASET_MAX_RECORDS 100
|
||||||
@ -289,8 +336,8 @@ index b0f77b1..347b7d2 100644
|
|||||||
+
|
+
|
||||||
isc_result_t
|
isc_result_t
|
||||||
dns_rdataslab_fromrdataset(dns_rdataset_t *rdataset, isc_mem_t *mctx,
|
dns_rdataslab_fromrdataset(dns_rdataset_t *rdataset, isc_mem_t *mctx,
|
||||||
isc_region_t *region, unsigned int reservelen)
|
isc_region_t *region, unsigned int reservelen) {
|
||||||
@@ -161,6 +165,10 @@ dns_rdataslab_fromrdataset(dns_rdataset_t *rdataset, isc_mem_t *mctx,
|
@@ -154,6 +158,10 @@ dns_rdataslab_fromrdataset(dns_rdataset_t *rdataset, isc_mem_t *mctx,
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
}
|
}
|
||||||
|
|
||||||
@ -298,11 +345,11 @@ index b0f77b1..347b7d2 100644
|
|||||||
+ return (DNS_R_TOOMANYRECORDS);
|
+ return (DNS_R_TOOMANYRECORDS);
|
||||||
+ }
|
+ }
|
||||||
+
|
+
|
||||||
if (nitems > 0xffff)
|
if (nitems > 0xffff) {
|
||||||
return (ISC_R_NOSPACE);
|
return (ISC_R_NOSPACE);
|
||||||
|
}
|
||||||
@@ -654,6 +662,10 @@ dns_rdataslab_merge(unsigned char *oslab, unsigned char *nslab,
|
@@ -520,6 +528,10 @@ dns_rdataslab_merge(unsigned char *oslab, unsigned char *nslab,
|
||||||
#endif
|
#endif /* if DNS_RDATASET_FIXED */
|
||||||
INSIST(ocount > 0 && ncount > 0);
|
INSIST(ocount > 0 && ncount > 0);
|
||||||
|
|
||||||
+ if (ocount + ncount > DNS_RDATASET_MAX_RECORDS) {
|
+ if (ocount + ncount > DNS_RDATASET_MAX_RECORDS) {
|
||||||
@ -311,7 +358,7 @@ index b0f77b1..347b7d2 100644
|
|||||||
+
|
+
|
||||||
#if DNS_RDATASET_FIXED
|
#if DNS_RDATASET_FIXED
|
||||||
oncount = ncount;
|
oncount = ncount;
|
||||||
#endif
|
#endif /* if DNS_RDATASET_FIXED */
|
||||||
--
|
--
|
||||||
2.45.2
|
2.45.2
|
||||||
|
|
||||||
@ -1,4 +1,4 @@
|
|||||||
From 5ff88892e43c049659a8a5aef8dfd56c3712daf0 Mon Sep 17 00:00:00 2001
|
From 34e92fc88943beeba76aa4e408951cb46d8cdb53 Mon Sep 17 00:00:00 2001
|
||||||
From: Petr Mensik <pemensik@redhat.com>
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
Date: Tue, 16 Jul 2024 19:49:09 +0200
|
Date: Tue, 16 Jul 2024 19:49:09 +0200
|
||||||
Subject: [PATCH] Resolve CVE-2024-1975
|
Subject: [PATCH] Resolve CVE-2024-1975
|
||||||
@ -8,32 +8,16 @@ Subject: [PATCH] Resolve CVE-2024-1975
|
|||||||
|
|
||||||
Resolves: CVE-2024-1975
|
Resolves: CVE-2024-1975
|
||||||
---
|
---
|
||||||
bin/named/client.c | 7 +++
|
|
||||||
bin/tests/system/tsiggss/authsock.pl | 5 ++
|
bin/tests/system/tsiggss/authsock.pl | 5 ++
|
||||||
bin/tests/system/tsiggss/tests.sh | 12 ++--
|
bin/tests/system/tsiggss/tests.sh | 12 ++--
|
||||||
bin/tests/system/upforwd/tests.sh | 21 ++++---
|
bin/tests/system/upforwd/tests.sh | 21 +++---
|
||||||
doc/arm/Bv9ARM-book.xml | 22 +++----
|
doc/arm/general.rst | 6 +-
|
||||||
lib/dns/message.c | 94 +++-------------------------
|
doc/arm/reference.rst | 4 +-
|
||||||
6 files changed, 49 insertions(+), 112 deletions(-)
|
doc/arm/security.rst | 4 +-
|
||||||
|
lib/dns/message.c | 97 ++--------------------------
|
||||||
|
lib/ns/client.c | 7 ++
|
||||||
|
8 files changed, 43 insertions(+), 113 deletions(-)
|
||||||
|
|
||||||
diff --git a/bin/named/client.c b/bin/named/client.c
|
|
||||||
index 368bc94..ea121b3 100644
|
|
||||||
--- a/bin/named/client.c
|
|
||||||
+++ b/bin/named/client.c
|
|
||||||
@@ -3013,6 +3013,13 @@ client_request(isc_task_t *task, isc_event_t *event) {
|
|
||||||
ns_client_log(client, DNS_LOGCATEGORY_SECURITY,
|
|
||||||
NS_LOGMODULE_CLIENT, ISC_LOG_DEBUG(3),
|
|
||||||
"request is signed by a nonauthoritative key");
|
|
||||||
+ } else if (result == DNS_R_NOTVERIFIEDYET &&
|
|
||||||
+ client->message->sig0 != NULL)
|
|
||||||
+ {
|
|
||||||
+ ns_client_log(client, DNS_LOGCATEGORY_SECURITY,
|
|
||||||
+ NS_LOGMODULE_CLIENT, ISC_LOG_DEBUG(3),
|
|
||||||
+ "request has a SIG(0) signature but its support "
|
|
||||||
+ "was removed (CVE-2024-1975)");
|
|
||||||
} else {
|
|
||||||
char tsigrcode[64];
|
|
||||||
isc_buffer_t b;
|
|
||||||
diff --git a/bin/tests/system/tsiggss/authsock.pl b/bin/tests/system/tsiggss/authsock.pl
|
diff --git a/bin/tests/system/tsiggss/authsock.pl b/bin/tests/system/tsiggss/authsock.pl
|
||||||
index ab3833d..0b231ee 100644
|
index ab3833d..0b231ee 100644
|
||||||
--- a/bin/tests/system/tsiggss/authsock.pl
|
--- a/bin/tests/system/tsiggss/authsock.pl
|
||||||
@ -58,7 +42,7 @@ index ab3833d..0b231ee 100644
|
|||||||
my ($version, $req_len) = unpack('N N', $buf);
|
my ($version, $req_len) = unpack('N N', $buf);
|
||||||
|
|
||||||
diff --git a/bin/tests/system/tsiggss/tests.sh b/bin/tests/system/tsiggss/tests.sh
|
diff --git a/bin/tests/system/tsiggss/tests.sh b/bin/tests/system/tsiggss/tests.sh
|
||||||
index 456ce61..d0db388 100644
|
index 632bb87..7977e49 100644
|
||||||
--- a/bin/tests/system/tsiggss/tests.sh
|
--- a/bin/tests/system/tsiggss/tests.sh
|
||||||
+++ b/bin/tests/system/tsiggss/tests.sh
|
+++ b/bin/tests/system/tsiggss/tests.sh
|
||||||
@@ -116,7 +116,7 @@ status=$((status+ret))
|
@@ -116,7 +116,7 @@ status=$((status+ret))
|
||||||
@ -77,28 +61,28 @@ index 456ce61..d0db388 100644
|
|||||||
-echo_i "testing external policy with SIG(0) key ($n)"
|
-echo_i "testing external policy with SIG(0) key ($n)"
|
||||||
+echo_i "testing external policy with unsupported SIG(0) key ($n)"
|
+echo_i "testing external policy with unsupported SIG(0) key ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
-$NSUPDATE -R $RANDFILE -k ns1/Kkey.example.nil.*.private <<END > /dev/null 2>&1 || ret=1
|
-$NSUPDATE -k ns1/Kkey.example.nil.*.private <<END > /dev/null 2>&1 || ret=1
|
||||||
+$NSUPDATE -R $RANDFILE -k ns1/Kkey.example.nil.*.private <<END >nsupdate.out${n} 2>&1 || true
|
+$NSUPDATE -d -k ns1/Kkey.example.nil.*.private <<END >nsupdate.out${n} 2>&1 || true
|
||||||
+debug
|
+debug
|
||||||
server 10.53.0.1 ${PORT}
|
server 10.53.0.1 ${PORT}
|
||||||
zone example.nil
|
zone example.nil
|
||||||
update add fred.example.nil 120 cname foo.bar.
|
update add fred.example.nil 120 cname foo.bar.
|
||||||
send
|
send
|
||||||
END
|
END
|
||||||
+# update must have failed - SIG(0) signer is not supported
|
|
||||||
output=`$DIG $DIGOPTS +short cname fred.example.nil.`
|
output=`$DIG $DIGOPTS +short cname fred.example.nil.`
|
||||||
-[ -n "$output" ] || ret=1
|
-[ -n "$output" ] || ret=1
|
||||||
-[ $ret -eq 0 ] || echo_i "failed"
|
-[ $ret -eq 0 ] || echo_i "failed"
|
||||||
|
+# update must have failed - SIG(0) signer is not supported
|
||||||
+[ -n "$output" ] && ret=1
|
+[ -n "$output" ] && ret=1
|
||||||
+grep -F "signer=key.example.nil" authsock.log >/dev/null && ret=1
|
+grep -F "signer=key.example.nil" authsock.log >/dev/null && ret=1
|
||||||
n=$((n+1))
|
n=$((n+1))
|
||||||
if [ "$ret" -ne 0 ]; then echo_i "failed"; fi
|
if [ "$ret" -ne 0 ]; then echo_i "failed"; fi
|
||||||
status=$((status+ret))
|
status=$((status+ret))
|
||||||
diff --git a/bin/tests/system/upforwd/tests.sh b/bin/tests/system/upforwd/tests.sh
|
diff --git a/bin/tests/system/upforwd/tests.sh b/bin/tests/system/upforwd/tests.sh
|
||||||
index ebc9ded..f5b89d4 100644
|
index 20fc46f..c8fd54b 100644
|
||||||
--- a/bin/tests/system/upforwd/tests.sh
|
--- a/bin/tests/system/upforwd/tests.sh
|
||||||
+++ b/bin/tests/system/upforwd/tests.sh
|
+++ b/bin/tests/system/upforwd/tests.sh
|
||||||
@@ -181,19 +181,22 @@ n=`expr $n + 1`
|
@@ -224,19 +224,22 @@ fi
|
||||||
|
|
||||||
if test -f keyname
|
if test -f keyname
|
||||||
then
|
then
|
||||||
@ -130,83 +114,72 @@ index ebc9ded..f5b89d4 100644
|
|||||||
if [ $ret != 0 ] ; then echo_i "failed"; fi
|
if [ $ret != 0 ] ; then echo_i "failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
diff --git a/doc/arm/Bv9ARM-book.xml b/doc/arm/Bv9ARM-book.xml
|
diff --git a/doc/arm/general.rst b/doc/arm/general.rst
|
||||||
index acf772b..563dced 100644
|
index 225576b..0766dfe 100644
|
||||||
--- a/doc/arm/Bv9ARM-book.xml
|
--- a/doc/arm/general.rst
|
||||||
+++ b/doc/arm/Bv9ARM-book.xml
|
+++ b/doc/arm/general.rst
|
||||||
@@ -2027,7 +2027,7 @@ allow-update { !{ !localnets; any; }; key host1-host2. ;};
|
@@ -534,10 +534,8 @@ than a non-authoritative response. This is considered a feature.
|
||||||
The TKEY process is initiated by a client or server by sending
|
[2] CLASS ANY queries are not supported. This is considered a
|
||||||
a query of type TKEY to a TKEY-aware server. The query must include
|
feature.
|
||||||
an appropriate KEY record in the additional section, and
|
|
||||||
- must be signed using either TSIG or SIG(0) with a previously
|
|
||||||
+ must be signed using TSIG with a previously
|
|
||||||
established key. The server's response, if successful,
|
|
||||||
contains a TKEY record in its answer section. After this transaction,
|
|
||||||
both participants have enough information to calculate a
|
|
||||||
@@ -2050,24 +2050,24 @@ allow-update { !{ !localnets; any; }; key host1-host2. ;};
|
|
||||||
<section xml:id="sig0"><info><title>SIG(0)</title></info>
|
|
||||||
|
|
||||||
<para>
|
-[3] When receiving a query signed with a SIG(0), the server is
|
||||||
- <acronym>BIND</acronym> partially supports DNSSEC SIG(0)
|
-only able to verify the signature if it has the key in its local
|
||||||
+ <acronym>BIND</acronym> partially supported DNSSEC SIG(0)
|
-authoritative data; it cannot do recursion or validation to
|
||||||
transaction signatures as specified in RFC 2535 and RFC 2931.
|
-retrieve unknown keys.
|
||||||
SIG(0) uses public/private keys to authenticate messages. Access control
|
+[3] Support for SIG(0) message verification was removed
|
||||||
- is performed in the same manner as with TSIG keys; privileges can be
|
+as part of the mitigation of CVE-2024-1975.
|
||||||
+ were performed in the same manner as with TSIG keys; privileges can be
|
|
||||||
granted or denied in ACL directives based on the key name.
|
|
||||||
</para>
|
|
||||||
<para>
|
|
||||||
- When a SIG(0) signed message is received, it is only
|
|
||||||
+ When a SIG(0) signed message were received, it were only
|
|
||||||
verified if the key is known and trusted by the server. The
|
|
||||||
- server does not attempt to recursively fetch or validate the
|
|
||||||
+ server did not attempt to recursively fetch or validate the
|
|
||||||
key.
|
|
||||||
</para>
|
|
||||||
<para>
|
|
||||||
- SIG(0) signing of multiple-message TCP streams is not supported.
|
|
||||||
+ SIG(0) signing of multiple-message TCP streams were not supported.
|
|
||||||
</para>
|
|
||||||
<para>
|
|
||||||
- The only tool shipped with <acronym>BIND</acronym> 9 that
|
|
||||||
- generates SIG(0) signed messages is <command>nsupdate</command>.
|
|
||||||
+ Support for SIG(0) message verification was removed
|
|
||||||
+ as part of the mitigation of CVE-2024-1975.
|
|
||||||
</para>
|
|
||||||
</section>
|
|
||||||
|
|
||||||
@@ -12655,7 +12655,7 @@ example.com. NS ns2.example.net.
|
[4] Compliance is with loading and serving of A6 records only. A6 records were moved
|
||||||
either grants or denies permission for one or more
|
to the experimental category by :rfc:`3363`.
|
||||||
names in the zone to be updated by one or more
|
diff --git a/doc/arm/reference.rst b/doc/arm/reference.rst
|
||||||
identities. Identity is determined by the key that
|
index d4ee9d2..ad7ff27 100644
|
||||||
- signed the update request, using either TSIG or SIG(0).
|
--- a/doc/arm/reference.rst
|
||||||
+ signed the update request, using TSIG.
|
+++ b/doc/arm/reference.rst
|
||||||
In most cases, <command>update-policy</command> rules
|
@@ -5789,7 +5789,7 @@ The ``update-policy`` clause allows more fine-grained control over which
|
||||||
only apply to key-based identities. There is no way
|
updates are allowed. It specifies a set of rules, in which each rule
|
||||||
to specify update permissions based on client source
|
either grants or denies permission for one or more names in the zone to
|
||||||
@@ -12742,7 +12742,7 @@ example.com. NS ns2.example.net.
|
be updated by one or more identities. Identity is determined by the key
|
||||||
<para>
|
-that signed the update request, using either TSIG or SIG(0). In most
|
||||||
The <command>identity</command> field must be set to
|
+that signed the update request, using either TSIG. In most
|
||||||
a fully qualified domain name. In most cases, this
|
cases, ``update-policy`` rules only apply to key-based identities. There
|
||||||
- represents the name of the TSIG or SIG(0) key that must be
|
is no way to specify update permissions based on the client source address.
|
||||||
+ represents the name of the TSIG key that must be
|
|
||||||
used to sign the update request. If the specified name is a
|
@@ -5846,7 +5846,7 @@ field), and the type of the record to be updated matches the ``types``
|
||||||
wildcard, it is subject to DNS wildcard expansion, and the
|
field. Details for each rule type are described below.
|
||||||
rule may apply to multiple identities. When a TKEY exchange
|
|
||||||
@@ -15952,7 +15952,7 @@ HOST-127.EXAMPLE. MX 0 .
|
The ``identity`` field must be set to a fully qualified domain name. In
|
||||||
</para>
|
-most cases, this represents the name of the TSIG or SIG(0) key that
|
||||||
<para>
|
+most cases, this represents the name of the TSIG key that
|
||||||
ACLs match clients on the basis of up to three characteristics:
|
must be used to sign the update request. If the specified name is a
|
||||||
- 1) The client's IP address; 2) the TSIG or SIG(0) key that was
|
wildcard, it is subject to DNS wildcard expansion, and the rule may
|
||||||
+ 1) The client's IP address; 2) the TSIG key that was
|
apply to multiple identities. When a TKEY exchange has been used to
|
||||||
used to sign the request, if any; and 3) an address prefix
|
diff --git a/doc/arm/security.rst b/doc/arm/security.rst
|
||||||
encoded in an EDNS Client-Subnet option, if any.
|
index f7c8bd3..e3abfd1 100644
|
||||||
</para>
|
--- a/doc/arm/security.rst
|
||||||
|
+++ b/doc/arm/security.rst
|
||||||
|
@@ -32,7 +32,7 @@ Limiting access to the server by outside parties can help prevent
|
||||||
|
spoofing and denial of service (DoS) attacks against the server.
|
||||||
|
|
||||||
|
ACLs match clients on the basis of up to three characteristics: 1) The
|
||||||
|
-client's IP address; 2) the TSIG or SIG(0) key that was used to sign the
|
||||||
|
+client's IP address; 2) the TSIG key that was used to sign the
|
||||||
|
request, if any; and 3) an address prefix encoded in an EDNS
|
||||||
|
Client-Subnet option, if any.
|
||||||
|
|
||||||
|
@@ -73,7 +73,7 @@ and no queries at all from the networks specified in ``bogusnets``.
|
||||||
|
|
||||||
|
In addition to network addresses and prefixes, which are matched against
|
||||||
|
the source address of the DNS request, ACLs may include ``key``
|
||||||
|
-elements, which specify the name of a TSIG or SIG(0) key.
|
||||||
|
+elements, which specify the name of a TSIG key.
|
||||||
|
|
||||||
|
When BIND 9 is built with GeoIP support, ACLs can also be used for
|
||||||
|
geographic access restrictions. This is done by specifying an ACL
|
||||||
diff --git a/lib/dns/message.c b/lib/dns/message.c
|
diff --git a/lib/dns/message.c b/lib/dns/message.c
|
||||||
index a44eb2d..9ea2b9e 100644
|
index 1993b2e..04315bc 100644
|
||||||
--- a/lib/dns/message.c
|
--- a/lib/dns/message.c
|
||||||
+++ b/lib/dns/message.c
|
+++ b/lib/dns/message.c
|
||||||
@@ -3373,103 +3373,23 @@ dns_message_dumpsig(dns_message_t *msg, char *txt1) {
|
@@ -3287,109 +3287,24 @@ dns_message_dumpsig(dns_message_t *msg, char *txt1) {
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
dns_message_checksig(dns_message_t *msg, dns_view_t *view) {
|
dns_message_checksig(dns_message_t *msg, dns_view_t *view) {
|
||||||
@ -215,9 +188,10 @@ index a44eb2d..9ea2b9e 100644
|
|||||||
|
|
||||||
REQUIRE(DNS_MESSAGE_VALID(msg));
|
REQUIRE(DNS_MESSAGE_VALID(msg));
|
||||||
|
|
||||||
- if (msg->tsigkey == NULL && msg->tsig == NULL && msg->sig0 == NULL)
|
- if (msg->tsigkey == NULL && msg->tsig == NULL && msg->sig0 == NULL) {
|
||||||
+ if (msg->tsigkey == NULL && msg->tsig == NULL)
|
+ if (msg->tsigkey == NULL && msg->tsig == NULL) {
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
|
}
|
||||||
|
|
||||||
INSIST(msg->saved.base != NULL);
|
INSIST(msg->saved.base != NULL);
|
||||||
isc_buffer_init(&msgb, msg->saved.base, msg->saved.length);
|
isc_buffer_init(&msgb, msg->saved.base, msg->saved.length);
|
||||||
@ -226,12 +200,15 @@ index a44eb2d..9ea2b9e 100644
|
|||||||
#ifdef SKAN_MSG_DEBUG
|
#ifdef SKAN_MSG_DEBUG
|
||||||
- dns_message_dumpsig(msg, "dns_message_checksig#1");
|
- dns_message_dumpsig(msg, "dns_message_checksig#1");
|
||||||
+ dns_message_dumpsig(msg, "dns_message_checksig#1");
|
+ dns_message_dumpsig(msg, "dns_message_checksig#1");
|
||||||
#endif
|
#endif /* ifdef SKAN_MSG_DEBUG */
|
||||||
- if (view != NULL)
|
- if (view != NULL) {
|
||||||
- return (dns_view_checksig(view, &msgb, msg));
|
- return (dns_view_checksig(view, &msgb, msg));
|
||||||
- else
|
- } else {
|
||||||
- return (dns_tsig_verify(&msgb, msg, NULL, NULL));
|
- return (dns_tsig_verify(&msgb, msg, NULL, NULL));
|
||||||
- } else {
|
- }
|
||||||
|
+ if (view != NULL) {
|
||||||
|
+ return (dns_view_checksig(view, &msgb, msg));
|
||||||
|
} else {
|
||||||
- dns_rdata_t rdata = DNS_RDATA_INIT;
|
- dns_rdata_t rdata = DNS_RDATA_INIT;
|
||||||
- dns_rdata_sig_t sig;
|
- dns_rdata_sig_t sig;
|
||||||
- dns_rdataset_t keyset;
|
- dns_rdataset_t keyset;
|
||||||
@ -248,19 +225,22 @@ index a44eb2d..9ea2b9e 100644
|
|||||||
- * looked for in the additional section, and the dynamic update
|
- * looked for in the additional section, and the dynamic update
|
||||||
- * meta-records are in the prerequisite and update sections.
|
- * meta-records are in the prerequisite and update sections.
|
||||||
- */
|
- */
|
||||||
- if (rdata.length == 0)
|
- if (rdata.length == 0) {
|
||||||
- return (ISC_R_UNEXPECTEDEND);
|
- return (ISC_R_UNEXPECTEDEND);
|
||||||
|
- }
|
||||||
-
|
-
|
||||||
- result = dns_rdata_tostruct(&rdata, &sig, msg->mctx);
|
- result = dns_rdata_tostruct(&rdata, &sig, msg->mctx);
|
||||||
- if (result != ISC_R_SUCCESS)
|
- if (result != ISC_R_SUCCESS) {
|
||||||
- return (result);
|
- return (result);
|
||||||
|
- }
|
||||||
-
|
-
|
||||||
- dns_rdataset_init(&keyset);
|
- dns_rdataset_init(&keyset);
|
||||||
- if (view == NULL)
|
- if (view == NULL) {
|
||||||
- return (DNS_R_KEYUNAUTHORIZED);
|
- return (DNS_R_KEYUNAUTHORIZED);
|
||||||
|
- }
|
||||||
- result = dns_view_simplefind(view, &sig.signer,
|
- result = dns_view_simplefind(view, &sig.signer,
|
||||||
- dns_rdatatype_key /* SIG(0) */,
|
- dns_rdatatype_key /* SIG(0) */, 0,
|
||||||
- 0, 0, false, &keyset, NULL);
|
- 0, false, &keyset, NULL);
|
||||||
-
|
-
|
||||||
- if (result != ISC_R_SUCCESS) {
|
- if (result != ISC_R_SUCCESS) {
|
||||||
- /* XXXBEW Should possibly create a fetch here */
|
- /* XXXBEW Should possibly create a fetch here */
|
||||||
@ -273,10 +253,8 @@ index a44eb2d..9ea2b9e 100644
|
|||||||
- }
|
- }
|
||||||
- result = dns_rdataset_first(&keyset);
|
- result = dns_rdataset_first(&keyset);
|
||||||
- INSIST(result == ISC_R_SUCCESS);
|
- INSIST(result == ISC_R_SUCCESS);
|
||||||
- for (;
|
- for (; result == ISC_R_SUCCESS;
|
||||||
- result == ISC_R_SUCCESS;
|
- result = dns_rdataset_next(&keyset)) {
|
||||||
- result = dns_rdataset_next(&keyset))
|
|
||||||
- {
|
|
||||||
- dst_key_t *key = NULL;
|
- dst_key_t *key = NULL;
|
||||||
-
|
-
|
||||||
- dns_rdata_reset(&rdata);
|
- dns_rdata_reset(&rdata);
|
||||||
@ -284,10 +262,11 @@ index a44eb2d..9ea2b9e 100644
|
|||||||
- isc_buffer_init(&b, rdata.data, rdata.length);
|
- isc_buffer_init(&b, rdata.data, rdata.length);
|
||||||
- isc_buffer_add(&b, rdata.length);
|
- isc_buffer_add(&b, rdata.length);
|
||||||
-
|
-
|
||||||
- result = dst_key_fromdns(&sig.signer, rdata.rdclass,
|
- result = dst_key_fromdns(&sig.signer, rdata.rdclass, &b,
|
||||||
- &b, view->mctx, &key);
|
- view->mctx, &key);
|
||||||
- if (result != ISC_R_SUCCESS)
|
- if (result != ISC_R_SUCCESS) {
|
||||||
- continue;
|
- continue;
|
||||||
|
- }
|
||||||
- if (dst_key_alg(key) != sig.algorithm ||
|
- if (dst_key_alg(key) != sig.algorithm ||
|
||||||
- dst_key_id(key) != sig.keyid ||
|
- dst_key_id(key) != sig.keyid ||
|
||||||
- !(dst_key_proto(key) == DNS_KEYPROTO_DNSSEC ||
|
- !(dst_key_proto(key) == DNS_KEYPROTO_DNSSEC ||
|
||||||
@ -298,25 +277,42 @@ index a44eb2d..9ea2b9e 100644
|
|||||||
- }
|
- }
|
||||||
- result = dns_dnssec_verifymessage(&msgb, msg, key);
|
- result = dns_dnssec_verifymessage(&msgb, msg, key);
|
||||||
- dst_key_free(&key);
|
- dst_key_free(&key);
|
||||||
- if (result == ISC_R_SUCCESS)
|
- if (result == ISC_R_SUCCESS) {
|
||||||
- break;
|
- break;
|
||||||
|
- }
|
||||||
- }
|
- }
|
||||||
- if (result == ISC_R_NOMORE)
|
- if (result == ISC_R_NOMORE) {
|
||||||
- result = DNS_R_KEYUNAUTHORIZED;
|
- result = DNS_R_KEYUNAUTHORIZED;
|
||||||
|
- }
|
||||||
-
|
-
|
||||||
- freesig:
|
- freesig:
|
||||||
- if (dns_rdataset_isassociated(&keyset))
|
- if (dns_rdataset_isassociated(&keyset)) {
|
||||||
- dns_rdataset_disassociate(&keyset);
|
- dns_rdataset_disassociate(&keyset);
|
||||||
|
- }
|
||||||
- dns_rdata_freestruct(&sig);
|
- dns_rdata_freestruct(&sig);
|
||||||
- return (result);
|
- return (result);
|
||||||
- }
|
|
||||||
+ if (view != NULL)
|
|
||||||
+ return (dns_view_checksig(view, &msgb, msg));
|
|
||||||
+ else
|
|
||||||
+ return (dns_tsig_verify(&msgb, msg, NULL, NULL));
|
+ return (dns_tsig_verify(&msgb, msg, NULL, NULL));
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#define INDENT(sp) \
|
diff --git a/lib/ns/client.c b/lib/ns/client.c
|
||||||
|
index 967e21b..87b8a18 100644
|
||||||
|
--- a/lib/ns/client.c
|
||||||
|
+++ b/lib/ns/client.c
|
||||||
|
@@ -2060,6 +2060,13 @@ ns__client_request(isc_nmhandle_t *handle, isc_result_t eresult,
|
||||||
|
ns_client_log(client, DNS_LOGCATEGORY_SECURITY,
|
||||||
|
NS_LOGMODULE_CLIENT, ISC_LOG_DEBUG(3),
|
||||||
|
"request is signed by a nonauthoritative key");
|
||||||
|
+ } else if (result == DNS_R_NOTVERIFIEDYET &&
|
||||||
|
+ client->message->sig0 != NULL)
|
||||||
|
+ {
|
||||||
|
+ ns_client_log(client, DNS_LOGCATEGORY_SECURITY,
|
||||||
|
+ NS_LOGMODULE_CLIENT, ISC_LOG_DEBUG(3),
|
||||||
|
+ "request has a SIG(0) signature but its support "
|
||||||
|
+ "was removed (CVE-2024-1975)");
|
||||||
|
} else {
|
||||||
|
char tsigrcode[64];
|
||||||
|
isc_buffer_t b;
|
||||||
--
|
--
|
||||||
2.45.2
|
2.45.2
|
||||||
|
|
||||||
40
SOURCES/bind-9.16-isc-mempool-attach.patch
Normal file
40
SOURCES/bind-9.16-isc-mempool-attach.patch
Normal file
@ -0,0 +1,40 @@
|
|||||||
|
From d249889a9c18df7792ca3cd8d97897e4fb5824b5 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Aram Sargsyan <aram@isc.org>
|
||||||
|
Date: Wed, 31 Aug 2022 12:30:38 +0000
|
||||||
|
Subject: [PATCH] Add mctx attach/detach when creating/destroying a memory pool
|
||||||
|
|
||||||
|
This should make sure that the memory context is not destroyed
|
||||||
|
before the memory pool, which is using the context.
|
||||||
|
|
||||||
|
(cherry picked from commit e97c3eea954e055634b72c21325d2611e960ee94)
|
||||||
|
---
|
||||||
|
lib/isc/mem.c | 6 ++++--
|
||||||
|
1 file changed, 4 insertions(+), 2 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/lib/isc/mem.c b/lib/isc/mem.c
|
||||||
|
index f84d300..33ece7a 100644
|
||||||
|
--- a/lib/isc/mem.c
|
||||||
|
+++ b/lib/isc/mem.c
|
||||||
|
@@ -1656,7 +1656,8 @@ isc_mempool_create(isc_mem_t *mctx0, size_t size, isc_mempool_t **mpctxp) {
|
||||||
|
mpctx->common.impmagic = MEMPOOL_MAGIC;
|
||||||
|
mpctx->common.magic = ISCAPI_MPOOL_MAGIC;
|
||||||
|
mpctx->lock = NULL;
|
||||||
|
- mpctx->mctx = mctx;
|
||||||
|
+ mpctx->mctx = NULL;
|
||||||
|
+ isc_mem_attach((isc_mem_t *)mctx, (isc_mem_t **)&mpctx->mctx);
|
||||||
|
/*
|
||||||
|
* Mempools are stored as a linked list of element.
|
||||||
|
*/
|
||||||
|
@@ -1765,7 +1766,8 @@ isc_mempool_destroy(isc_mempool_t **mpctxp) {
|
||||||
|
mpctx->common.impmagic = 0;
|
||||||
|
mpctx->common.magic = 0;
|
||||||
|
|
||||||
|
- isc_mem_put((isc_mem_t *)mpctx->mctx, mpctx, sizeof(isc__mempool_t));
|
||||||
|
+ isc_mem_putanddetach((isc_mem_t **)&mpctx->mctx, mpctx,
|
||||||
|
+ sizeof(isc__mempool_t));
|
||||||
|
|
||||||
|
if (lock != NULL) {
|
||||||
|
UNLOCK(lock);
|
||||||
|
--
|
||||||
|
2.43.2
|
||||||
|
|
||||||
66
SOURCES/bind-9.16-isc_hp-CVE-2023-50387.patch
Normal file
66
SOURCES/bind-9.16-isc_hp-CVE-2023-50387.patch
Normal file
@ -0,0 +1,66 @@
|
|||||||
|
From 103b09187466b2afbff7e204d166d21e2fbb057c Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Wed, 21 Feb 2024 11:54:27 +0100
|
||||||
|
Subject: [PATCH] Downstream specific changes related to KeyTrap
|
||||||
|
|
||||||
|
Fix for CVE-2023-50387 introduced new additional thread. But because
|
||||||
|
isc_hp functions were removed from later bind 9.16 release, their
|
||||||
|
changes did not contain increase of hazard pointers max thread limit.
|
||||||
|
To prevent obscure memory corruption increase thread max size.
|
||||||
|
|
||||||
|
In addition place at least few INSISTs to check this is catched before
|
||||||
|
random memory overwrites begins. It would be quite difficult to track
|
||||||
|
without any check.
|
||||||
|
---
|
||||||
|
lib/isc/hp.c | 3 +++
|
||||||
|
lib/isc/managers.c | 5 +++--
|
||||||
|
2 files changed, 6 insertions(+), 2 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/lib/isc/hp.c b/lib/isc/hp.c
|
||||||
|
index 92d160b..5f9bbf7 100644
|
||||||
|
--- a/lib/isc/hp.c
|
||||||
|
+++ b/lib/isc/hp.c
|
||||||
|
@@ -138,6 +138,7 @@ isc_hp_destroy(isc_hp_t *hp) {
|
||||||
|
|
||||||
|
void
|
||||||
|
isc_hp_clear(isc_hp_t *hp) {
|
||||||
|
+ INSIST(tid() < isc__hp_max_threads);
|
||||||
|
for (int i = 0; i < hp->max_hps; i++) {
|
||||||
|
atomic_store_release(&hp->hp[tid()][i], 0);
|
||||||
|
}
|
||||||
|
@@ -152,6 +153,7 @@ uintptr_t
|
||||||
|
isc_hp_protect(isc_hp_t *hp, int ihp, atomic_uintptr_t *atom) {
|
||||||
|
uintptr_t n = 0;
|
||||||
|
uintptr_t ret;
|
||||||
|
+ INSIST(tid() < isc__hp_max_threads);
|
||||||
|
while ((ret = atomic_load(atom)) != n) {
|
||||||
|
atomic_store(&hp->hp[tid()][ihp], ret);
|
||||||
|
n = ret;
|
||||||
|
@@ -173,6 +175,7 @@ isc_hp_protect_release(isc_hp_t *hp, int ihp, atomic_uintptr_t ptr) {
|
||||||
|
|
||||||
|
void
|
||||||
|
isc_hp_retire(isc_hp_t *hp, uintptr_t ptr) {
|
||||||
|
+ INSIST(tid() < isc__hp_max_threads);
|
||||||
|
hp->rl[tid()]->list[hp->rl[tid()]->size++] = ptr;
|
||||||
|
INSIST(hp->rl[tid()]->size < isc__hp_max_retired);
|
||||||
|
|
||||||
|
diff --git a/lib/isc/managers.c b/lib/isc/managers.c
|
||||||
|
index c39a650..3bdca99 100644
|
||||||
|
--- a/lib/isc/managers.c
|
||||||
|
+++ b/lib/isc/managers.c
|
||||||
|
@@ -25,9 +25,10 @@ isc_managers_create(isc_mem_t *mctx, size_t workers, size_t quantum,
|
||||||
|
|
||||||
|
/*
|
||||||
|
* We have ncpus network threads, ncpus old network threads - make
|
||||||
|
- * it 4x just to be on the safe side.
|
||||||
|
+ * it 4x just to be on the safe side. One additional for slow netmgr
|
||||||
|
+ * thread.
|
||||||
|
*/
|
||||||
|
- isc_hp_init(4 * workers);
|
||||||
|
+ isc_hp_init(5 * workers);
|
||||||
|
|
||||||
|
REQUIRE(netmgrp != NULL && *netmgrp == NULL);
|
||||||
|
isc__netmgr_create(mctx, workers, &netmgr);
|
||||||
|
--
|
||||||
|
2.43.2
|
||||||
|
|
||||||
34
SOURCES/bind-9.16-isc_hp-additional.patch
Normal file
34
SOURCES/bind-9.16-isc_hp-additional.patch
Normal file
@ -0,0 +1,34 @@
|
|||||||
|
From beeb4527b25c8d48842bbc78f100b716df118699 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Tue, 9 Jul 2024 16:06:02 +0200
|
||||||
|
Subject: [PATCH] Increase even further hazard pointers after KeyTrap
|
||||||
|
|
||||||
|
Extends even more change Downstream specific changes related to KeyTrap,
|
||||||
|
which added safety guards into hazard pointers. Because it seems they
|
||||||
|
are not still enough. Add fixed base to accomodate common threads like
|
||||||
|
main app thread and ldap worker threads. Multiply one more, just to be
|
||||||
|
sure. We do not want to hit maximal limit again.
|
||||||
|
---
|
||||||
|
lib/isc/managers.c | 5 +++--
|
||||||
|
1 file changed, 3 insertions(+), 2 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/lib/isc/managers.c b/lib/isc/managers.c
|
||||||
|
index 3bdca99..fffff78 100644
|
||||||
|
--- a/lib/isc/managers.c
|
||||||
|
+++ b/lib/isc/managers.c
|
||||||
|
@@ -26,9 +26,10 @@ isc_managers_create(isc_mem_t *mctx, size_t workers, size_t quantum,
|
||||||
|
/*
|
||||||
|
* We have ncpus network threads, ncpus old network threads - make
|
||||||
|
* it 4x just to be on the safe side. One additional for slow netmgr
|
||||||
|
- * thread.
|
||||||
|
+ * thread. One extra to be safe. Add base for main application thread
|
||||||
|
+ * or bind-dyndb-ldap worker threads.
|
||||||
|
*/
|
||||||
|
- isc_hp_init(5 * workers);
|
||||||
|
+ isc_hp_init(6 + 6 * workers);
|
||||||
|
|
||||||
|
REQUIRE(netmgrp != NULL && *netmgrp == NULL);
|
||||||
|
isc__netmgr_create(mctx, workers, &netmgr);
|
||||||
|
--
|
||||||
|
2.45.2
|
||||||
|
|
||||||
60
SOURCES/bind-9.16-redhat_doc.patch
Normal file
60
SOURCES/bind-9.16-redhat_doc.patch
Normal file
@ -0,0 +1,60 @@
|
|||||||
|
From 3a161af91bffcd457586ab466e32ac8484028763 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Wed, 17 Jun 2020 23:17:13 +0200
|
||||||
|
Subject: [PATCH] Update man named with Red Hat specifics
|
||||||
|
|
||||||
|
This is almost unmodified text and requires revalidation. Some of those
|
||||||
|
statements are no longer correct.
|
||||||
|
---
|
||||||
|
bin/named/named.rst | 35 +++++++++++++++++++++++++++++++++++
|
||||||
|
1 file changed, 35 insertions(+)
|
||||||
|
|
||||||
|
diff --git a/bin/named/named.rst b/bin/named/named.rst
|
||||||
|
index 6fd8f87..3cd6350 100644
|
||||||
|
--- a/bin/named/named.rst
|
||||||
|
+++ b/bin/named/named.rst
|
||||||
|
@@ -228,6 +228,41 @@ Files
|
||||||
|
``/var/run/named/named.pid``
|
||||||
|
The default process-id file.
|
||||||
|
|
||||||
|
+Notes
|
||||||
|
+~~~~~
|
||||||
|
+
|
||||||
|
+**Red Hat SELinux BIND Security Profile:**
|
||||||
|
+
|
||||||
|
+By default, Red Hat ships BIND with the most secure SELinux policy
|
||||||
|
+that will not prevent normal BIND operation and will prevent exploitation
|
||||||
|
+of all known BIND security vulnerabilities. See the selinux(8) man page
|
||||||
|
+for information about SElinux.
|
||||||
|
+
|
||||||
|
+It is not necessary to run named in a chroot environment if the Red Hat
|
||||||
|
+SELinux policy for named is enabled. When enabled, this policy is far
|
||||||
|
+more secure than a chroot environment. Users are recommended to enable
|
||||||
|
+SELinux and remove the bind-chroot package.
|
||||||
|
+
|
||||||
|
+*With this extra security comes some restrictions:*
|
||||||
|
+
|
||||||
|
+By default, the SELinux policy does not allow named to write outside directory
|
||||||
|
+/var/named. That directory used to be read-only for named, but write access is
|
||||||
|
+enabled by default now.
|
||||||
|
+
|
||||||
|
+The "named" group must be granted read privelege to
|
||||||
|
+these files in order for named to be enabled to read them.
|
||||||
|
+Any file updated by named must be writeable by named user or named group.
|
||||||
|
+
|
||||||
|
+Any file created in the zone database file directory is automatically assigned
|
||||||
|
+the SELinux file context *named_zone_t* .
|
||||||
|
+
|
||||||
|
+The Red Hat BIND distribution and SELinux policy creates three directories where
|
||||||
|
+named were allowed to create and modify files: */var/named/slaves*, */var/named/dynamic*
|
||||||
|
+*/var/named/data*. The service is able to write and file under */var/named* with appropriate
|
||||||
|
+permissions. They are used for better organisation of zones and backward compatibility.
|
||||||
|
+Files in these directories are automatically assigned the '*named_cache_t*'
|
||||||
|
+file context, which SELinux always allows named to write.
|
||||||
|
+
|
||||||
|
See Also
|
||||||
|
~~~~~~~~
|
||||||
|
|
||||||
|
--
|
||||||
|
2.26.2
|
||||||
|
|
||||||
216
SOURCES/bind-9.16-rh2101712.patch
Normal file
216
SOURCES/bind-9.16-rh2101712.patch
Normal file
@ -0,0 +1,216 @@
|
|||||||
|
From b1871274cd2c97b63f3b90d608b7f8936d4ff3c5 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Mark Andrews <marka@isc.org>
|
||||||
|
Date: Wed, 24 Aug 2022 12:21:50 +1000
|
||||||
|
Subject: [PATCH] Have dns_zt_apply lock the zone table
|
||||||
|
|
||||||
|
There where a number of places where the zone table should have
|
||||||
|
been locked, but wasn't, when dns_zt_apply was called.
|
||||||
|
|
||||||
|
Added a isc_rwlocktype_t type parameter to dns_zt_apply and adjusted
|
||||||
|
all calls to using it. Removed locks in callers.
|
||||||
|
|
||||||
|
Modified upstream commit for v9_16
|
||||||
|
---
|
||||||
|
bin/named/server.c | 12 +++++++-----
|
||||||
|
bin/named/statschannel.c | 12 +++++++-----
|
||||||
|
lib/dns/include/dns/zt.h | 3 ++-
|
||||||
|
lib/dns/tests/zt_test.c | 4 ++--
|
||||||
|
lib/dns/view.c | 3 ++-
|
||||||
|
lib/dns/zt.c | 29 ++++++++++++++++++-----------
|
||||||
|
6 files changed, 38 insertions(+), 25 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/bin/named/server.c b/bin/named/server.c
|
||||||
|
index 860ccae..c2a5887 100644
|
||||||
|
--- a/bin/named/server.c
|
||||||
|
+++ b/bin/named/server.c
|
||||||
|
@@ -9458,7 +9458,8 @@ cleanup:
|
||||||
|
if (result == ISC_R_SUCCESS && strcmp(view->name, "_bind") != 0)
|
||||||
|
{
|
||||||
|
dns_view_setviewrevert(view);
|
||||||
|
- (void)dns_zt_apply(view->zonetable, false, NULL,
|
||||||
|
+ (void)dns_zt_apply(view->zonetable,
|
||||||
|
+ isc_rwlocktype_read, false, NULL,
|
||||||
|
removed, view);
|
||||||
|
}
|
||||||
|
dns_view_detach(&view);
|
||||||
|
@@ -10901,8 +10902,8 @@ add_view_tolist(struct dumpcontext *dctx, dns_view_t *view) {
|
||||||
|
ISC_LIST_INIT(vle->zonelist);
|
||||||
|
ISC_LIST_APPEND(dctx->viewlist, vle, link);
|
||||||
|
if (dctx->dumpzones) {
|
||||||
|
- result = dns_zt_apply(view->zonetable, true, NULL,
|
||||||
|
- add_zone_tolist, dctx);
|
||||||
|
+ result = dns_zt_apply(view->zonetable, isc_rwlocktype_read,
|
||||||
|
+ true, NULL, add_zone_tolist, dctx);
|
||||||
|
}
|
||||||
|
return (result);
|
||||||
|
}
|
||||||
|
@@ -12248,8 +12249,9 @@ named_server_sync(named_server_t *server, isc_lex_t *lex, isc_buffer_t **text) {
|
||||||
|
for (view = ISC_LIST_HEAD(server->viewlist); view != NULL;
|
||||||
|
view = ISC_LIST_NEXT(view, link))
|
||||||
|
{
|
||||||
|
- result = dns_zt_apply(view->zonetable, false, NULL,
|
||||||
|
- synczone, &cleanup);
|
||||||
|
+ result = dns_zt_apply(view->zonetable,
|
||||||
|
+ isc_rwlocktype_none, false,
|
||||||
|
+ NULL, synczone, &cleanup);
|
||||||
|
if (result != ISC_R_SUCCESS && tresult == ISC_R_SUCCESS)
|
||||||
|
{
|
||||||
|
tresult = result;
|
||||||
|
diff --git a/bin/named/statschannel.c b/bin/named/statschannel.c
|
||||||
|
index 8ff2567..832ce93 100644
|
||||||
|
--- a/bin/named/statschannel.c
|
||||||
|
+++ b/bin/named/statschannel.c
|
||||||
|
@@ -2296,8 +2296,9 @@ generatexml(named_server_t *server, uint32_t flags, int *buflen,
|
||||||
|
if ((flags & STATS_XML_ZONES) != 0) {
|
||||||
|
TRY0(xmlTextWriterStartElement(writer,
|
||||||
|
ISC_XMLCHAR "zones"));
|
||||||
|
- result = dns_zt_apply(view->zonetable, true, NULL,
|
||||||
|
- zone_xmlrender, writer);
|
||||||
|
+ result = dns_zt_apply(view->zonetable,
|
||||||
|
+ isc_rwlocktype_read, true,
|
||||||
|
+ NULL, zone_xmlrender, writer);
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
goto error;
|
||||||
|
}
|
||||||
|
@@ -3069,9 +3070,10 @@ generatejson(named_server_t *server, size_t *msglen, const char **msg,
|
||||||
|
CHECKMEM(za);
|
||||||
|
|
||||||
|
if ((flags & STATS_JSON_ZONES) != 0) {
|
||||||
|
- result = dns_zt_apply(view->zonetable, true,
|
||||||
|
- NULL, zone_jsonrender,
|
||||||
|
- za);
|
||||||
|
+ result = dns_zt_apply(view->zonetable,
|
||||||
|
+ isc_rwlocktype_read,
|
||||||
|
+ true, NULL,
|
||||||
|
+ zone_jsonrender, za);
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
goto error;
|
||||||
|
}
|
||||||
|
diff --git a/lib/dns/include/dns/zt.h b/lib/dns/include/dns/zt.h
|
||||||
|
index 4a1b263..1c6c789 100644
|
||||||
|
--- a/lib/dns/include/dns/zt.h
|
||||||
|
+++ b/lib/dns/include/dns/zt.h
|
||||||
|
@@ -168,7 +168,8 @@ dns_zt_freezezones(dns_zt_t *zt, dns_view_t *view, bool freeze);
|
||||||
|
*/
|
||||||
|
|
||||||
|
isc_result_t
|
||||||
|
-dns_zt_apply(dns_zt_t *zt, bool stop, isc_result_t *sub,
|
||||||
|
+dns_zt_apply(dns_zt_t *zt, isc_rwlocktype_t lock, bool stop,
|
||||||
|
+ isc_result_t *sub,
|
||||||
|
isc_result_t (*action)(dns_zone_t *, void *), void *uap);
|
||||||
|
/*%<
|
||||||
|
* Apply a given 'action' to all zone zones in the table.
|
||||||
|
diff --git a/lib/dns/tests/zt_test.c b/lib/dns/tests/zt_test.c
|
||||||
|
index 7945a0b..bfacb94 100644
|
||||||
|
--- a/lib/dns/tests/zt_test.c
|
||||||
|
+++ b/lib/dns/tests/zt_test.c
|
||||||
|
@@ -136,8 +136,8 @@ apply(void **state) {
|
||||||
|
assert_non_null(view->zonetable);
|
||||||
|
|
||||||
|
assert_int_equal(nzones, 0);
|
||||||
|
- result = dns_zt_apply(view->zonetable, false, NULL, count_zone,
|
||||||
|
- &nzones);
|
||||||
|
+ result = dns_zt_apply(view->zonetable, isc_rwlocktype_read, false,
|
||||||
|
+ NULL, count_zone, &nzones);
|
||||||
|
assert_int_equal(result, ISC_R_SUCCESS);
|
||||||
|
assert_int_equal(nzones, 1);
|
||||||
|
|
||||||
|
diff --git a/lib/dns/view.c b/lib/dns/view.c
|
||||||
|
index 8c7e40a..dcb0f18 100644
|
||||||
|
--- a/lib/dns/view.c
|
||||||
|
+++ b/lib/dns/view.c
|
||||||
|
@@ -704,7 +704,8 @@ dns_view_dialup(dns_view_t *view) {
|
||||||
|
REQUIRE(DNS_VIEW_VALID(view));
|
||||||
|
REQUIRE(view->zonetable != NULL);
|
||||||
|
|
||||||
|
- (void)dns_zt_apply(view->zonetable, false, NULL, dialup, NULL);
|
||||||
|
+ (void)dns_zt_apply(view->zonetable, isc_rwlocktype_read, false,
|
||||||
|
+ NULL, dialup, NULL);
|
||||||
|
}
|
||||||
|
|
||||||
|
void
|
||||||
|
diff --git a/lib/dns/zt.c b/lib/dns/zt.c
|
||||||
|
index 8ca9cd6..1bfc308 100644
|
||||||
|
--- a/lib/dns/zt.c
|
||||||
|
+++ b/lib/dns/zt.c
|
||||||
|
@@ -223,7 +223,8 @@ flush(dns_zone_t *zone, void *uap) {
|
||||||
|
static void
|
||||||
|
zt_destroy(dns_zt_t *zt) {
|
||||||
|
if (atomic_load_acquire(&zt->flush)) {
|
||||||
|
- (void)dns_zt_apply(zt, false, NULL, flush, NULL);
|
||||||
|
+ (void)dns_zt_apply(zt, isc_rwlocktype_none, false, NULL,
|
||||||
|
+ flush, NULL);
|
||||||
|
}
|
||||||
|
dns_rbt_destroy(&zt->table);
|
||||||
|
isc_rwlock_destroy(&zt->rwlock);
|
||||||
|
@@ -265,9 +266,8 @@ dns_zt_load(dns_zt_t *zt, bool stop, bool newonly) {
|
||||||
|
struct zt_load_params params;
|
||||||
|
REQUIRE(VALID_ZT(zt));
|
||||||
|
params.newonly = newonly;
|
||||||
|
- RWLOCK(&zt->rwlock, isc_rwlocktype_read);
|
||||||
|
- result = dns_zt_apply(zt, stop, NULL, load, ¶ms);
|
||||||
|
- RWUNLOCK(&zt->rwlock, isc_rwlocktype_read);
|
||||||
|
+ result = dns_zt_apply(zt, isc_rwlocktype_read, stop, NULL, load,
|
||||||
|
+ ¶ms);
|
||||||
|
return (result);
|
||||||
|
}
|
||||||
|
|
||||||
|
@@ -338,9 +338,8 @@ dns_zt_asyncload(dns_zt_t *zt, bool newonly, dns_zt_allloaded_t alldone,
|
||||||
|
zt->loaddone = alldone;
|
||||||
|
zt->loaddone_arg = arg;
|
||||||
|
|
||||||
|
- RWLOCK(&zt->rwlock, isc_rwlocktype_read);
|
||||||
|
- result = dns_zt_apply(zt, false, NULL, asyncload, zt);
|
||||||
|
- RWUNLOCK(&zt->rwlock, isc_rwlocktype_read);
|
||||||
|
+ result = dns_zt_apply(zt, isc_rwlocktype_read, false, NULL,
|
||||||
|
+ asyncload, zt);
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Have all the loads completed?
|
||||||
|
@@ -386,9 +385,8 @@ dns_zt_freezezones(dns_zt_t *zt, dns_view_t *view, bool freeze) {
|
||||||
|
|
||||||
|
REQUIRE(VALID_ZT(zt));
|
||||||
|
|
||||||
|
- RWLOCK(&zt->rwlock, isc_rwlocktype_read);
|
||||||
|
- result = dns_zt_apply(zt, false, &tresult, freezezones, ¶ms);
|
||||||
|
- RWUNLOCK(&zt->rwlock, isc_rwlocktype_read);
|
||||||
|
+ result = dns_zt_apply(zt, isc_rwlocktype_read, false, &tresult,
|
||||||
|
+ freezezones, ¶ms);
|
||||||
|
if (tresult == ISC_R_NOTFOUND) {
|
||||||
|
tresult = ISC_R_SUCCESS;
|
||||||
|
}
|
||||||
|
@@ -522,7 +520,8 @@ dns_zt_setviewrevert(dns_zt_t *zt) {
|
||||||
|
}
|
||||||
|
|
||||||
|
isc_result_t
|
||||||
|
-dns_zt_apply(dns_zt_t *zt, bool stop, isc_result_t *sub,
|
||||||
|
+dns_zt_apply(dns_zt_t *zt, isc_rwlocktype_t lock, bool stop,
|
||||||
|
+ isc_result_t *sub,
|
||||||
|
isc_result_t (*action)(dns_zone_t *, void *), void *uap) {
|
||||||
|
dns_rbtnode_t *node;
|
||||||
|
dns_rbtnodechain_t chain;
|
||||||
|
@@ -532,6 +531,10 @@ dns_zt_apply(dns_zt_t *zt, bool stop, isc_result_t *sub,
|
||||||
|
REQUIRE(VALID_ZT(zt));
|
||||||
|
REQUIRE(action != NULL);
|
||||||
|
|
||||||
|
+ if (lock != isc_rwlocktype_none) {
|
||||||
|
+ RWLOCK(&zt->rwlock, lock);
|
||||||
|
+ }
|
||||||
|
+
|
||||||
|
dns_rbtnodechain_init(&chain);
|
||||||
|
result = dns_rbtnodechain_first(&chain, zt->table, NULL, NULL);
|
||||||
|
if (result == ISC_R_NOTFOUND) {
|
||||||
|
@@ -568,6 +571,10 @@ cleanup:
|
||||||
|
*sub = tresult;
|
||||||
|
}
|
||||||
|
|
||||||
|
+ if (lock != isc_rwlocktype_none) {
|
||||||
|
+ RWUNLOCK(&zt->rwlock, lock);
|
||||||
|
+ }
|
||||||
|
+
|
||||||
|
return (result);
|
||||||
|
}
|
||||||
|
|
||||||
|
--
|
||||||
|
2.39.2
|
||||||
|
|
||||||
31
SOURCES/bind-9.16-rh2133889.patch
Normal file
31
SOURCES/bind-9.16-rh2133889.patch
Normal file
@ -0,0 +1,31 @@
|
|||||||
|
From 606fc6d4aa8e8884f53f53e72dc1bd7babf37a47 Mon Sep 17 00:00:00 2001
|
||||||
|
From: =?UTF-8?q?Ond=C5=99ej=20Sur=C3=BD?= <ondrej@isc.org>
|
||||||
|
Date: Mon, 16 Jan 2023 11:06:48 +0000
|
||||||
|
Subject: [PATCH] Merge branch 'feature/main/zt-rwlock.h' into 'main'
|
||||||
|
|
||||||
|
Include isc_rwlocktype_t type definition in zt.h
|
||||||
|
|
||||||
|
See merge request isc-projects/bind9!7376
|
||||||
|
|
||||||
|
(cherry picked from commit d7bcdf8bd6c5395726f708535120ce9a97eaa935)
|
||||||
|
|
||||||
|
395d6fca Include isc_rwlocktype_t type definition in zt.h
|
||||||
|
---
|
||||||
|
lib/dns/include/dns/zt.h | 1 +
|
||||||
|
1 file changed, 1 insertion(+)
|
||||||
|
|
||||||
|
diff --git a/lib/dns/include/dns/zt.h b/lib/dns/include/dns/zt.h
|
||||||
|
index 189092bc3b..2964fc971f 100644
|
||||||
|
--- a/lib/dns/include/dns/zt.h
|
||||||
|
+++ b/lib/dns/include/dns/zt.h
|
||||||
|
@@ -19,6 +19,7 @@
|
||||||
|
#include <stdbool.h>
|
||||||
|
|
||||||
|
#include <isc/lang.h>
|
||||||
|
+#include <isc/rwlock.h>
|
||||||
|
|
||||||
|
#include <dns/types.h>
|
||||||
|
|
||||||
|
--
|
||||||
|
2.39.0
|
||||||
|
|
||||||
33
SOURCES/bind-9.16-system-test-cds.patch
Normal file
33
SOURCES/bind-9.16-system-test-cds.patch
Normal file
@ -0,0 +1,33 @@
|
|||||||
|
From 7cc9fd1870e5264abd885ed2c419034945121d0f Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Mon, 19 Feb 2024 22:13:52 +0100
|
||||||
|
Subject: [PATCH] Define variants to empty values
|
||||||
|
|
||||||
|
DNSSEC_VARIANT and NAMED_VARIANT are special Red Hat modifications to
|
||||||
|
allow testing or alternative rebuilds, with support for pkcs11 or sdb.
|
||||||
|
But undefined value breaks some tests, so define them to empty values.
|
||||||
|
That means normal build variant.
|
||||||
|
|
||||||
|
Required to pass upstream test suite cds test correctly.
|
||||||
|
---
|
||||||
|
bin/tests/system/conf.sh.in | 4 ++++
|
||||||
|
1 file changed, 4 insertions(+)
|
||||||
|
|
||||||
|
diff --git a/bin/tests/system/conf.sh.in b/bin/tests/system/conf.sh.in
|
||||||
|
index 7b2b309..c2d6526 100644
|
||||||
|
--- a/bin/tests/system/conf.sh.in
|
||||||
|
+++ b/bin/tests/system/conf.sh.in
|
||||||
|
@@ -24,6 +24,10 @@ TMPDIR=${TMPDIR:-/tmp}
|
||||||
|
# This is not the windows build.
|
||||||
|
CYGWIN=""
|
||||||
|
|
||||||
|
+# RH specific, allow variants testing
|
||||||
|
+: ${DNSSEC_VARIANT:=}
|
||||||
|
+: ${NAMED_VARIANT:=}
|
||||||
|
+
|
||||||
|
# Load common values shared between windows and unix/linux.
|
||||||
|
. $TOP/bin/tests/system/conf.sh.common
|
||||||
|
|
||||||
|
--
|
||||||
|
2.43.2
|
||||||
|
|
||||||
@ -1,4 +1,4 @@
|
|||||||
From 4e595a6b961e73af43350833109ccba0950119f9 Mon Sep 17 00:00:00 2001
|
From c532af966a7328f0e518273bc1f6051bb9d9e995 Mon Sep 17 00:00:00 2001
|
||||||
From: Mark Andrews <marka@isc.org>
|
From: Mark Andrews <marka@isc.org>
|
||||||
Date: Thu, 12 Oct 2023 10:19:38 +1100
|
Date: Thu, 12 Oct 2023 10:19:38 +1100
|
||||||
Subject: [PATCH] Update b.root-servers.net IP addresses
|
Subject: [PATCH] Update b.root-servers.net IP addresses
|
||||||
@ -8,24 +8,46 @@ zone mirror. The official change date is Nov 27, 2023.
|
|||||||
|
|
||||||
(cherry picked from commit 2ca2f7e9852a3d6e93f065c01ea4679f723688f7)
|
(cherry picked from commit 2ca2f7e9852a3d6e93f065c01ea4679f723688f7)
|
||||||
---
|
---
|
||||||
lib/dns/rootns.c | 4 ++--
|
bin/named/config.c | 4 ++--
|
||||||
1 file changed, 2 insertions(+), 2 deletions(-)
|
lib/dns/rootns.c | 4 ++--
|
||||||
|
2 files changed, 4 insertions(+), 4 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/bin/named/config.c b/bin/named/config.c
|
||||||
|
index 8c6f90c..c37015f 100644
|
||||||
|
--- a/bin/named/config.c
|
||||||
|
+++ b/bin/named/config.c
|
||||||
|
@@ -292,14 +292,14 @@ view \"_bind\" chaos {\n\
|
||||||
|
"# END MANAGED KEYS\n\
|
||||||
|
\n\
|
||||||
|
primaries " DEFAULT_IANA_ROOT_ZONE_PRIMARIES " {\n\
|
||||||
|
- 2001:500:200::b; # b.root-servers.net\n\
|
||||||
|
+ 2801:1b8:10::b; # b.root-servers.net\n\
|
||||||
|
2001:500:2::c; # c.root-servers.net\n\
|
||||||
|
2001:500:2f::f; # f.root-servers.net\n\
|
||||||
|
2001:500:12::d0d; # g.root-servers.net\n\
|
||||||
|
2001:7fd::1; # k.root-servers.net\n\
|
||||||
|
2620:0:2830:202::132; # xfr.cjr.dns.icann.org\n\
|
||||||
|
2620:0:2d0:202::132; # xfr.lax.dns.icann.org\n\
|
||||||
|
- 199.9.14.201; # b.root-servers.net\n\
|
||||||
|
+ 170.247.170.2; # b.root-servers.net\n\
|
||||||
|
192.33.4.12; # c.root-servers.net\n\
|
||||||
|
192.5.5.241; # f.root-servers.net\n\
|
||||||
|
192.112.36.4; # g.root-servers.net\n\
|
||||||
diff --git a/lib/dns/rootns.c b/lib/dns/rootns.c
|
diff --git a/lib/dns/rootns.c b/lib/dns/rootns.c
|
||||||
index 9653f3b..d6ff76e 100644
|
index 885c2fb..b06d247 100644
|
||||||
--- a/lib/dns/rootns.c
|
--- a/lib/dns/rootns.c
|
||||||
+++ b/lib/dns/rootns.c
|
+++ b/lib/dns/rootns.c
|
||||||
@@ -56,8 +56,8 @@ static char root_ns[] =
|
@@ -52,8 +52,8 @@ static char root_ns[] =
|
||||||
". 518400 IN NS M.ROOT-SERVERS.NET.\n"
|
". 518400 IN NS M.ROOT-SERVERS.NET.\n"
|
||||||
"A.ROOT-SERVERS.NET. 3600000 IN A 198.41.0.4\n"
|
"A.ROOT-SERVERS.NET. 3600000 IN A 198.41.0.4\n"
|
||||||
"A.ROOT-SERVERS.NET. 3600000 IN AAAA 2001:503:BA3E::2:30\n"
|
"A.ROOT-SERVERS.NET. 3600000 IN AAAA 2001:503:BA3E::2:30\n"
|
||||||
-"B.ROOT-SERVERS.NET. 3600000 IN A 199.9.14.201\n"
|
- "B.ROOT-SERVERS.NET. 3600000 IN A 199.9.14.201\n"
|
||||||
-"B.ROOT-SERVERS.NET. 3600000 IN AAAA 2001:500:200::b\n"
|
- "B.ROOT-SERVERS.NET. 3600000 IN AAAA 2001:500:200::b\n"
|
||||||
+"B.ROOT-SERVERS.NET. 3600000 IN A 170.247.170.2\n"
|
+ "B.ROOT-SERVERS.NET. 3600000 IN A 170.247.170.2\n"
|
||||||
+"B.ROOT-SERVERS.NET. 3600000 IN AAAA 2801:1b8:10::b\n"
|
+ "B.ROOT-SERVERS.NET. 3600000 IN AAAA 2801:1b8:10::b\n"
|
||||||
"C.ROOT-SERVERS.NET. 3600000 IN A 192.33.4.12\n"
|
"C.ROOT-SERVERS.NET. 3600000 IN A 192.33.4.12\n"
|
||||||
"C.ROOT-SERVERS.NET. 3600000 IN AAAA 2001:500:2::c\n"
|
"C.ROOT-SERVERS.NET. 3600000 IN AAAA 2001:500:2::c\n"
|
||||||
"D.ROOT-SERVERS.NET. 3600000 IN A 199.7.91.13\n"
|
"D.ROOT-SERVERS.NET. 3600000 IN A 199.7.91.13\n"
|
||||||
--
|
--
|
||||||
2.43.0
|
2.43.0
|
||||||
|
|
||||||
|
|||||||
17
SOURCES/bind-9.16.23.tar.xz.asc
Normal file
17
SOURCES/bind-9.16.23.tar.xz.asc
Normal file
@ -0,0 +1,17 @@
|
|||||||
|
-----BEGIN PGP SIGNATURE-----
|
||||||
|
Comment: GPGTools - https://gpgtools.org
|
||||||
|
|
||||||
|
iQIzBAABAgAdFiEEqtu6UHTxQC97adVrxbTukxqfnf0FAmGKhMcACgkQxbTukxqf
|
||||||
|
nf1EbQ//YXsBbMtyI3c0MoleSi5zwzcpCTZTWTFHqH5WUiruLMDF453j/Fn2zaSC
|
||||||
|
WuaUnhN61dR+BVtX+D2Y8GiVQFICo5X1nJj0jb/TcflXFq7YLWUAO0NPwPkBL1J4
|
||||||
|
/PA0YCp1zYcvBXIxTKaU7AcBxlKmcGLdZcgCyGU6NSKaOJSxHOWXM460uD/crskB
|
||||||
|
iSPEbMevN9TTJs9webztJNKH/3BuNkOD9SFb6JlUIQqwKx1v8rosgdI7BvgGMZqy
|
||||||
|
s+10+GlIRFFvsX2XkX8BnjDlQ1QdzDOAoyCU+Se9rXDqu+zZf1VN4ReUCSDuPYf9
|
||||||
|
z+GW1EbMxuZzEKrEIJvhnVNNiHqtKVaK6IIUX5bHqgPLEx87HxJMOPmbyBc1kDAe
|
||||||
|
0WCmsITaq62WvKOG8Ho8wLrlG4AAO5+A7xit4bJ4XUtLiqyt+9FUIeEFY9nZb/6O
|
||||||
|
OXK9eBMZHZ++r52RtA+GYZllkNRpzwnULOdR/9svVQuc10/MjnRoFqInzLlqwfwm
|
||||||
|
2q6r372oWn8+MUvjQVBgzprn5BvY+HDo2gNEYEi5QyR3ql2dX/Qz7iUdUfhRvMNL
|
||||||
|
FdPt3B3kktfOV98p/imrIwLwVVWwKBlphntkRxLtSZBs3nbo27F/ND54fixC2eCa
|
||||||
|
epB6FF5IquzQ/MOiz4uql3YexNDQQ+7N2IGPJVMwO2ILAyZDNOQ=
|
||||||
|
=pVtf
|
||||||
|
-----END PGP SIGNATURE-----
|
||||||
@ -1,85 +0,0 @@
|
|||||||
From 8a9b9ff5a8b2443f7df4f60397ad215931ba44f1 Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Ond=C5=99ej=20Sur=C3=BD?= <ondrej@isc.org>
|
|
||||||
Date: Tue, 7 Jan 2025 15:22:40 +0100
|
|
||||||
Subject: [PATCH] Isolate using the -T noaa flag only for part of the resolver
|
|
||||||
test
|
|
||||||
|
|
||||||
Instead of running the whole resolver/ns4 server with -T noaa flag,
|
|
||||||
use it only for the part where it is actually needed. The -T noaa
|
|
||||||
could interfere with other parts of the test because the answers don't
|
|
||||||
have the authoritative-answer bit set, and we could have false
|
|
||||||
positives (or false negatives) in the test because the authoritative
|
|
||||||
server doesn't follow the DNS protocol for all the tests in the resolver
|
|
||||||
system test.
|
|
||||||
|
|
||||||
(cherry picked from commit e51d4d3b88af00d6667f2055087ebfc47fb3107c)
|
|
||||||
---
|
|
||||||
bin/tests/system/conf.sh.in | 12 ++++++++++++
|
|
||||||
bin/tests/system/resolver/ns4/named.noaa | 5 -----
|
|
||||||
bin/tests/system/resolver/tests.sh | 8 ++++++++
|
|
||||||
3 files changed, 20 insertions(+), 5 deletions(-)
|
|
||||||
delete mode 100644 bin/tests/system/resolver/ns4/named.noaa
|
|
||||||
|
|
||||||
diff --git a/bin/tests/system/conf.sh.in b/bin/tests/system/conf.sh.in
|
|
||||||
index 06852f5..f77f7de 100644
|
|
||||||
--- a/bin/tests/system/conf.sh.in
|
|
||||||
+++ b/bin/tests/system/conf.sh.in
|
|
||||||
@@ -305,6 +305,18 @@ digcomp() {
|
|
||||||
return $result
|
|
||||||
}
|
|
||||||
|
|
||||||
+start_server() {
|
|
||||||
+ $PERL "$SYSTEMTESTTOP/start.pl" "$SYSTESTDIR" "$@"
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
+stop_server() {
|
|
||||||
+ $PERL "$SYSTEMTESTTOP/stop.pl" "$SYSTESTDIR" "$@"
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
+send() {
|
|
||||||
+ $PERL "$SYSTEMTESTTOP/send.pl" "$@"
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
#
|
|
||||||
# Useful functions in test scripts
|
|
||||||
#
|
|
||||||
diff --git a/bin/tests/system/resolver/ns4/named.noaa b/bin/tests/system/resolver/ns4/named.noaa
|
|
||||||
deleted file mode 100644
|
|
||||||
index 3b121ad..0000000
|
|
||||||
--- a/bin/tests/system/resolver/ns4/named.noaa
|
|
||||||
+++ /dev/null
|
|
||||||
@@ -1,5 +0,0 @@
|
|
||||||
-Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
-
|
|
||||||
-See COPYRIGHT in the source root or https://isc.org/copyright.html for terms.
|
|
||||||
-
|
|
||||||
-Add -T noaa.
|
|
||||||
diff --git a/bin/tests/system/resolver/tests.sh b/bin/tests/system/resolver/tests.sh
|
|
||||||
index 6eb52fe..bf37467 100755
|
|
||||||
--- a/bin/tests/system/resolver/tests.sh
|
|
||||||
+++ b/bin/tests/system/resolver/tests.sh
|
|
||||||
@@ -281,6 +281,10 @@ done
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
|
||||||
status=`expr $status + $ret`
|
|
||||||
|
|
||||||
+stop_server ns4
|
|
||||||
+touch ns4/named.noaa
|
|
||||||
+start_server --noclean --restart --port ${PORT} ns4 || ret=1
|
|
||||||
+
|
|
||||||
n=`expr $n + 1`
|
|
||||||
echo_i "RT21594 regression test check setup ($n)"
|
|
||||||
ret=0
|
|
||||||
@@ -317,6 +321,10 @@ grep "status: NXDOMAIN" dig.ns5.out.${n} > /dev/null || ret=1
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
|
||||||
status=`expr $status + $ret`
|
|
||||||
|
|
||||||
+stop_server ns4
|
|
||||||
+rm ns4/named.noaa
|
|
||||||
+start_server --noclean --restart --port ${PORT} ns4 || ret=1
|
|
||||||
+
|
|
||||||
n=`expr $n + 1`
|
|
||||||
echo_i "check that replacement of additional data by a negative cache no data entry clears the additional RRSIGs ($n)"
|
|
||||||
ret=0
|
|
||||||
--
|
|
||||||
2.48.1
|
|
||||||
|
|
||||||
@ -1,151 +0,0 @@
|
|||||||
From ca6c3446ef07d89fd3a28b6979d947af2ab5754f Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Ond=C5=99ej=20Sur=C3=BD?= <ondrej@isc.org>
|
|
||||||
Date: Thu, 14 Nov 2024 10:37:29 +0100
|
|
||||||
Subject: [PATCH] Limit the additional processing for large RDATA sets
|
|
||||||
|
|
||||||
When answering queries, don't add data to the additional section if
|
|
||||||
the answer has more than 13 names in the RDATA. This limits the
|
|
||||||
number of lookups into the database(s) during a single client query,
|
|
||||||
reducing query processing load.
|
|
||||||
|
|
||||||
Also, don't append any additional data to type=ANY queries. The
|
|
||||||
answer to ANY is already big enough.
|
|
||||||
|
|
||||||
(cherry picked from commit a1982cf1bb95c818aa7b58988b5611dec80f2408)
|
|
||||||
PatchNumber: 47
|
|
||||||
---
|
|
||||||
bin/named/query.c | 14 ++++++++------
|
|
||||||
bin/tests/system/additional/tests.sh | 2 +-
|
|
||||||
lib/dns/include/dns/rdataset.h | 12 ++++++++++++
|
|
||||||
lib/dns/rdataset.c | 12 ++++++++++++
|
|
||||||
4 files changed, 33 insertions(+), 7 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/bin/named/query.c b/bin/named/query.c
|
|
||||||
index 51a29a8..e023d74 100644
|
|
||||||
--- a/bin/named/query.c
|
|
||||||
+++ b/bin/named/query.c
|
|
||||||
@@ -1835,9 +1835,10 @@ query_addadditional(void *arg, dns_name_t *name, dns_rdatatype_t qtype) {
|
|
||||||
* section, it's helpful if we add the SRV additional data
|
|
||||||
* as well.
|
|
||||||
*/
|
|
||||||
- eresult = dns_rdataset_additionaldata(trdataset,
|
|
||||||
- query_addadditional,
|
|
||||||
- client);
|
|
||||||
+ eresult = dns_rdataset_additionaldata2(trdataset,
|
|
||||||
+ query_addadditional,
|
|
||||||
+ client,
|
|
||||||
+ DNS_RDATASET_MAXADDITIONAL);
|
|
||||||
}
|
|
||||||
|
|
||||||
cleanup:
|
|
||||||
@@ -2432,7 +2433,7 @@ query_addrdataset(ns_client_t *client, dns_name_t *fname,
|
|
||||||
rdataset->rdclass);
|
|
||||||
rdataset->attributes |= DNS_RDATASETATTR_LOADORDER;
|
|
||||||
|
|
||||||
- if (NOADDITIONAL(client))
|
|
||||||
+ if (NOADDITIONAL(client) || client->query.qtype == dns_rdatatype_any)
|
|
||||||
return;
|
|
||||||
|
|
||||||
/*
|
|
||||||
@@ -2442,8 +2443,9 @@ query_addrdataset(ns_client_t *client, dns_name_t *fname,
|
|
||||||
*/
|
|
||||||
additionalctx.client = client;
|
|
||||||
additionalctx.rdataset = rdataset;
|
|
||||||
- (void)dns_rdataset_additionaldata(rdataset, query_addadditional2,
|
|
||||||
- &additionalctx);
|
|
||||||
+ (void)dns_rdataset_additionaldata2(rdataset, query_addadditional2,
|
|
||||||
+ &additionalctx,
|
|
||||||
+ DNS_RDATASET_MAXADDITIONAL);
|
|
||||||
CTRACE(ISC_LOG_DEBUG(3), "query_addrdataset: done");
|
|
||||||
}
|
|
||||||
|
|
||||||
diff --git a/bin/tests/system/additional/tests.sh b/bin/tests/system/additional/tests.sh
|
|
||||||
index 6400723..a33cc8a 100644
|
|
||||||
--- a/bin/tests/system/additional/tests.sh
|
|
||||||
+++ b/bin/tests/system/additional/tests.sh
|
|
||||||
@@ -261,7 +261,7 @@ n=`expr $n + 1`
|
|
||||||
echo_i "testing with 'minimal-any no;' ($n)"
|
|
||||||
ret=0
|
|
||||||
$DIG $DIGOPTS -t ANY www.rt.example @10.53.0.1 > dig.out.$n || ret=1
|
|
||||||
-grep "ANSWER: 3, AUTHORITY: 1, ADDITIONAL: 2" dig.out.$n > /dev/null || ret=1
|
|
||||||
+grep "ANSWER: 3, AUTHORITY: 1, ADDITIONAL: 1" dig.out.$n > /dev/null || ret=1
|
|
||||||
if [ $ret -eq 1 ] ; then
|
|
||||||
echo_i "failed"; status=`expr status + 1`
|
|
||||||
fi
|
|
||||||
diff --git a/lib/dns/include/dns/rdataset.h b/lib/dns/include/dns/rdataset.h
|
|
||||||
index 710e97c..b3532f6 100644
|
|
||||||
--- a/lib/dns/include/dns/rdataset.h
|
|
||||||
+++ b/lib/dns/include/dns/rdataset.h
|
|
||||||
@@ -53,6 +53,8 @@
|
|
||||||
#include <dns/types.h>
|
|
||||||
#include <dns/rdatastruct.h>
|
|
||||||
|
|
||||||
+#define DNS_RDATASET_MAXADDITIONAL 13
|
|
||||||
+
|
|
||||||
ISC_LANG_BEGINDECLS
|
|
||||||
|
|
||||||
typedef enum {
|
|
||||||
@@ -501,13 +503,23 @@ dns_rdataset_additionaldata(dns_rdataset_t *rdataset,
|
|
||||||
*\li If a call to dns_rdata_additionaldata() is not successful, the
|
|
||||||
* result returned will be the result of dns_rdataset_additionaldata().
|
|
||||||
*
|
|
||||||
+ *\li If 'limit' is non-zero and the number of the rdatasets is larger
|
|
||||||
+ * than 'limit', no additional data will be processed.
|
|
||||||
+ *
|
|
||||||
* Returns:
|
|
||||||
*
|
|
||||||
*\li #ISC_R_SUCCESS
|
|
||||||
*
|
|
||||||
+ *\li #DNS_R_TOOMANYRECORDS in case rdataset count is larger than 'limit'
|
|
||||||
+ *
|
|
||||||
*\li Any error that dns_rdata_additionaldata() can return.
|
|
||||||
*/
|
|
||||||
|
|
||||||
+isc_result_t
|
|
||||||
+dns_rdataset_additionaldata2(dns_rdataset_t *rdataset,
|
|
||||||
+ dns_additionaldatafunc_t add, void *arg,
|
|
||||||
+ size_t limit);
|
|
||||||
+
|
|
||||||
isc_result_t
|
|
||||||
dns_rdataset_getnoqname(dns_rdataset_t *rdataset, dns_name_t *name,
|
|
||||||
dns_rdataset_t *neg, dns_rdataset_t *negsig);
|
|
||||||
diff --git a/lib/dns/rdataset.c b/lib/dns/rdataset.c
|
|
||||||
index b42dea5..5160acf 100644
|
|
||||||
--- a/lib/dns/rdataset.c
|
|
||||||
+++ b/lib/dns/rdataset.c
|
|
||||||
@@ -28,6 +28,7 @@
|
|
||||||
#include <dns/ncache.h>
|
|
||||||
#include <dns/rdata.h>
|
|
||||||
#include <dns/rdataset.h>
|
|
||||||
+#include <dns/result.h>
|
|
||||||
|
|
||||||
static const char *trustnames[] = {
|
|
||||||
"none",
|
|
||||||
@@ -608,6 +609,13 @@ dns_rdataset_towire(dns_rdataset_t *rdataset,
|
|
||||||
isc_result_t
|
|
||||||
dns_rdataset_additionaldata(dns_rdataset_t *rdataset,
|
|
||||||
dns_additionaldatafunc_t add, void *arg)
|
|
||||||
+{
|
|
||||||
+ return dns_rdataset_additionaldata2(rdataset, add, arg, 0);
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
+isc_result_t
|
|
||||||
+dns_rdataset_additionaldata2(dns_rdataset_t *rdataset,
|
|
||||||
+ dns_additionaldatafunc_t add, void *arg, size_t limit)
|
|
||||||
{
|
|
||||||
dns_rdata_t rdata = DNS_RDATA_INIT;
|
|
||||||
isc_result_t result;
|
|
||||||
@@ -620,6 +628,10 @@ dns_rdataset_additionaldata(dns_rdataset_t *rdataset,
|
|
||||||
REQUIRE(DNS_RDATASET_VALID(rdataset));
|
|
||||||
REQUIRE((rdataset->attributes & DNS_RDATASETATTR_QUESTION) == 0);
|
|
||||||
|
|
||||||
+ if (limit != 0 && dns_rdataset_count(rdataset) > limit) {
|
|
||||||
+ return DNS_R_TOOMANYRECORDS;
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
result = dns_rdataset_first(rdataset);
|
|
||||||
if (result != ISC_R_SUCCESS)
|
|
||||||
return (result);
|
|
||||||
--
|
|
||||||
2.48.1
|
|
||||||
|
|
||||||
29
SOURCES/bind-9.18-CVE-2024-4076.patch
Normal file
29
SOURCES/bind-9.18-CVE-2024-4076.patch
Normal file
@ -0,0 +1,29 @@
|
|||||||
|
From 274463c5b71db87a615694889da23837ba48db9a Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Tue, 16 Jul 2024 19:49:26 +0200
|
||||||
|
Subject: [PATCH] Resolve CVE-2024-4076
|
||||||
|
|
||||||
|
6403. [security] qctx-zversion was not being cleared when it should have
|
||||||
|
been leading to an assertion failure if it needed to be
|
||||||
|
reused. (CVE-2024-4076) [GL #4507]
|
||||||
|
|
||||||
|
Resolves: CVE-2024-4076
|
||||||
|
---
|
||||||
|
lib/ns/query.c | 1 +
|
||||||
|
1 file changed, 1 insertion(+)
|
||||||
|
|
||||||
|
diff --git a/lib/ns/query.c b/lib/ns/query.c
|
||||||
|
index 537d332..be4cbb6 100644
|
||||||
|
--- a/lib/ns/query.c
|
||||||
|
+++ b/lib/ns/query.c
|
||||||
|
@@ -5325,6 +5325,7 @@ qctx_freedata(query_ctx_t *qctx) {
|
||||||
|
ns_client_releasename(qctx->client, &qctx->zfname);
|
||||||
|
dns_db_detachnode(qctx->zdb, &qctx->znode);
|
||||||
|
dns_db_detach(&qctx->zdb);
|
||||||
|
+ qctx->zversion = NULL;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (qctx->event != NULL && !qctx->client->nodetach) {
|
||||||
|
--
|
||||||
|
2.45.2
|
||||||
|
|
||||||
@ -1,63 +0,0 @@
|
|||||||
srcdir = @srcdir@
|
|
||||||
VPATH = @srcdir@
|
|
||||||
top_srcdir = @top_srcdir@
|
|
||||||
|
|
||||||
VERSION=@BIND9_VERSION@
|
|
||||||
|
|
||||||
@BIND9_MAKE_INCLUDES@
|
|
||||||
|
|
||||||
CINCLUDES = -I${srcdir}/include -I${srcdir}/unix/include \
|
|
||||||
${LWRES_INCLUDES} ${DNS_INCLUDES} ${BIND9_INCLUDES} \
|
|
||||||
${ISCCFG_INCLUDES} ${ISCCC_INCLUDES} ${ISC_INCLUDES}
|
|
||||||
|
|
||||||
CDEFINES = -DBIND9
|
|
||||||
|
|
||||||
DNSLIBS = ../../lib/dns/libdns.@A@ @DNS_CRYPTO_LIBS@
|
|
||||||
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
|
||||||
ISCCCLIBS = ../../lib/isccc/libisccc.@A@
|
|
||||||
ISCLIBS = ../../lib/isc/libisc.@A@
|
|
||||||
LWRESLIBS = ../../lib/lwres/liblwres.@A@
|
|
||||||
BIND9LIBS = ../../lib/bind9/libbind9.@A@
|
|
||||||
|
|
||||||
DNSDEPLIBS = ../../lib/dns/libdns.@A@
|
|
||||||
ISCCFGDEPLIBS = ../../lib/isccfg/libisccfg.@A@
|
|
||||||
ISCCCDEPLIBS = ../../lib/isccc/libisccc.@A@
|
|
||||||
ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
|
||||||
LWRESDEPLIBS = ../../lib/lwres/liblwres.@A@
|
|
||||||
BIND9DEPLIBS = ../../lib/bind9/libbind9.@A@
|
|
||||||
|
|
||||||
DEPLIBS = ${LWRESDEPLIBS} ${DNSDEPLIBS} ${BIND9DEPLIBS} \
|
|
||||||
${ISCCFGDEPLIBS} ${ISCCCDEPLIBS} ${ISCDEPLIBS}
|
|
||||||
|
|
||||||
LIBS = ${LWRESLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
|
||||||
${ISCCFGLIBS} ${ISCCCLIBS} ${ISCLIBS} ${DBDRIVER_LIBS} @LIBS@
|
|
||||||
|
|
||||||
TARGETS = zone2ldap@EXEEXT@ zonetodb@EXEEXT@
|
|
||||||
|
|
||||||
OBJS = zone2ldap.@O@ zonetodb.@O@
|
|
||||||
|
|
||||||
SRCS = zone2ldap.c zonetodb.c
|
|
||||||
|
|
||||||
MANPAGES = zone2ldap.1
|
|
||||||
|
|
||||||
EXT_CFLAGS =
|
|
||||||
|
|
||||||
@BIND9_MAKE_RULES@
|
|
||||||
|
|
||||||
zone2ldap@EXEEXT@: zone2ldap.@O@ ${DEPLIBS}
|
|
||||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ zone2ldap.@O@ -lldap -llber ${LIBS}
|
|
||||||
|
|
||||||
zonetodb@EXEEXT@: zonetodb.@O@ ${DEPLIBS}
|
|
||||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ zonetodb.@O@ -lpq ${LIBS}
|
|
||||||
|
|
||||||
clean distclean manclean maintainer-clean::
|
|
||||||
rm -f ${TARGETS} ${OBJS}
|
|
||||||
|
|
||||||
installdirs:
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man1
|
|
||||||
|
|
||||||
install:: ${TARGETS} installdirs
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zone2ldap@EXEEXT@ ${DESTDIR}${sbindir}
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zonetodb@EXEEXT@ ${DESTDIR}${sbindir}
|
|
||||||
${INSTALL_DATA} ${srcdir}/zone2ldap.1 ${DESTDIR}${mandir}/man1/zone2ldap.1
|
|
||||||
@ -1,98 +0,0 @@
|
|||||||
From facdbb0f2a266c6a3a1fa823afaa09cbd3fc38a5 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Petr Mensik <pemensik@redhat.com>
|
|
||||||
Date: Thu, 26 Nov 2020 12:13:10 +0100
|
|
||||||
Subject: [PATCH] Note specific Red Hat changes in manual page
|
|
||||||
|
|
||||||
Change docbook template instead of generated manual page. Remove
|
|
||||||
system-config-bind reference, package were discontinued.
|
|
||||||
---
|
|
||||||
bin/named/named.docbook | 73 +++++++++++++++++++++++++++++++++++++++++
|
|
||||||
1 file changed, 73 insertions(+)
|
|
||||||
|
|
||||||
diff --git a/bin/named/named.docbook b/bin/named/named.docbook
|
|
||||||
index 7e743a9..802bec3 100644
|
|
||||||
--- a/bin/named/named.docbook
|
|
||||||
+++ b/bin/named/named.docbook
|
|
||||||
@@ -516,6 +516,79 @@
|
|
||||||
|
|
||||||
</refsection>
|
|
||||||
|
|
||||||
+ <refsection><info><title>NOTES</title></info>
|
|
||||||
+ <refsection><info><title>Red Hat SELinux BIND Security Profile</title></info>
|
|
||||||
+
|
|
||||||
+ <para>
|
|
||||||
+ By default, Red Hat ships BIND with the most secure SELinux policy
|
|
||||||
+ that will not prevent normal BIND operation and will prevent exploitation
|
|
||||||
+ of all known BIND security vulnerabilities . See the selinux(8) man page
|
|
||||||
+ for information about SElinux.
|
|
||||||
+ </para>
|
|
||||||
+
|
|
||||||
+ <para>
|
|
||||||
+ It is not necessary to run named in a chroot environment if the Red Hat
|
|
||||||
+ SELinux policy for named is enabled. When enabled, this policy is far
|
|
||||||
+ more secure than a chroot environment. Users are recommended to enable
|
|
||||||
+ SELinux and remove the bind-chroot package.
|
|
||||||
+ </para>
|
|
||||||
+
|
|
||||||
+ <para>
|
|
||||||
+ With this extra security comes some restrictions:
|
|
||||||
+ </para>
|
|
||||||
+
|
|
||||||
+ <para>
|
|
||||||
+ By default, the SELinux policy allows named to write any master
|
|
||||||
+ zone database files. Only the root user may create files in the $ROOTDIR/var/named
|
|
||||||
+ zone database file directory (the options { "directory" } option), where
|
|
||||||
+ $ROOTDIR is set in /etc/sysconfig/named.
|
|
||||||
+ </para>
|
|
||||||
+
|
|
||||||
+ <para>
|
|
||||||
+ The "named" group must be granted read privelege to
|
|
||||||
+ these files in order for named to be enabled to read them.
|
|
||||||
+ </para>
|
|
||||||
+
|
|
||||||
+ <para>
|
|
||||||
+ Any file created in the zone database file directory is automatically assigned
|
|
||||||
+ the SELinux file context named_zone_t .
|
|
||||||
+ </para>
|
|
||||||
+
|
|
||||||
+ <para>
|
|
||||||
+ By default, SELinux prevents any role from modifying named_zone_t files; this
|
|
||||||
+ means that files in the zone database directory cannot be modified by dynamic
|
|
||||||
+ DNS (DDNS) updates or zone transfers.
|
|
||||||
+ </para>
|
|
||||||
+
|
|
||||||
+ <para>
|
|
||||||
+ The Red Hat BIND distribution and SELinux policy creates three directories where
|
|
||||||
+ named is allowed to create and modify files: /var/named/slaves, /var/named/dynamic
|
|
||||||
+ /var/named/data. By placing files you want named to modify, such as
|
|
||||||
+ slave or DDNS updateable zone files and database / statistics dump files in
|
|
||||||
+ these directories, named will work normally and no further operator action is
|
|
||||||
+ required. Files in these directories are automatically assigned the 'named_cache_t'
|
|
||||||
+ file context, which SELinux allows named to write.
|
|
||||||
+ </para>
|
|
||||||
+ </refsection>
|
|
||||||
+
|
|
||||||
+ <refsection><info><title>Red Hat BIND SDB support</title></info>
|
|
||||||
+
|
|
||||||
+ <para>
|
|
||||||
+ Red Hat ships named with compiled in Simplified Database Backend modules that ISC
|
|
||||||
+ provides in the "contrib/sdb" directory. Install bind-sdb package if you want use them.
|
|
||||||
+ </para>
|
|
||||||
+
|
|
||||||
+ <para>
|
|
||||||
+ The SDB modules for LDAP, PostGreSQL, DirDB and SQLite are compiled into <command>named-sdb</command>.
|
|
||||||
+ </para>
|
|
||||||
+
|
|
||||||
+ <para>
|
|
||||||
+ See the documentation for the various SDB modules in /usr/share/doc/bind-sdb-*/ .
|
|
||||||
+ </para>
|
|
||||||
+ </refsection>
|
|
||||||
+
|
|
||||||
+ </refsection>
|
|
||||||
+
|
|
||||||
<refsection><info><title>SEE ALSO</title></info>
|
|
||||||
|
|
||||||
<para><citetitle>RFC 1033</citetitle>,
|
|
||||||
--
|
|
||||||
2.26.2
|
|
||||||
|
|
||||||
@ -1,511 +0,0 @@
|
|||||||
diff --git a/bin/sdb_tools/Makefile.in b/bin/sdb_tools/Makefile.in
|
|
||||||
index 95ab742..5059a17 100644
|
|
||||||
--- a/bin/sdb_tools/Makefile.in
|
|
||||||
+++ b/bin/sdb_tools/Makefile.in
|
|
||||||
@@ -32,11 +32,11 @@ DEPLIBS = ${LWRESDEPLIBS} ${DNSDEPLIBS} ${BIND9DEPLIBS} \
|
|
||||||
LIBS = ${LWRESLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
|
||||||
${ISCCFGLIBS} ${ISCCCLIBS} ${ISCLIBS} ${DBDRIVER_LIBS} @LIBS@
|
|
||||||
|
|
||||||
-TARGETS = zone2ldap@EXEEXT@ zonetodb@EXEEXT@ zone2sqlite@EXEEXT@
|
|
||||||
+TARGETS = zone2ldap@EXEEXT@ zonetodb@EXEEXT@ zone2sqlite@EXEEXT@ ldap2zone@EXEEXT@
|
|
||||||
|
|
||||||
-OBJS = zone2ldap.@O@ zonetodb.@O@ zone2sqlite.@O@
|
|
||||||
+OBJS = zone2ldap.@O@ zonetodb.@O@ zone2sqlite.@O@ ldap2zone.@O@
|
|
||||||
|
|
||||||
-SRCS = zone2ldap.c zonetodb.c zone2sqlite.c
|
|
||||||
+SRCS = zone2ldap.c zonetodb.c zone2sqlite.c ldap2zone.c
|
|
||||||
|
|
||||||
MANPAGES = zone2ldap.1
|
|
||||||
|
|
||||||
@@ -47,6 +47,9 @@ EXT_CFLAGS =
|
|
||||||
zone2ldap@EXEEXT@: zone2ldap.@O@ ${DEPLIBS}
|
|
||||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ zone2ldap.@O@ -lldap -llber ${LIBS}
|
|
||||||
|
|
||||||
+ldap2zone@EXEEXT@: ldap2zone.@O@ ${DEPLIBS}
|
|
||||||
+ ${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o $@ ldap2zone.@O@ -lldap -llber ${LIBS}
|
|
||||||
+
|
|
||||||
zonetodb@EXEEXT@: zonetodb.@O@ ${DEPLIBS}
|
|
||||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ zonetodb.@O@ -lpq ${LIBS}
|
|
||||||
|
|
||||||
@@ -64,4 +67,5 @@ install:: ${TARGETS} installdirs
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zone2ldap@EXEEXT@ ${DESTDIR}${sbindir}
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zonetodb@EXEEXT@ ${DESTDIR}${sbindir}
|
|
||||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zone2sqlite@EXEEXT@ ${DESTDIR}${sbindir}
|
|
||||||
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} ldap2zone@EXEEXT@ ${DESTDIR}${sbindir}
|
|
||||||
${INSTALL_DATA} ${srcdir}/zone2ldap.1 ${DESTDIR}${mandir}/man1/zone2ldap.1
|
|
||||||
diff --git a/bin/sdb_tools/zone2ldap.c b/bin/sdb_tools/zone2ldap.c
|
|
||||||
index e0e9207..d59936c 100644
|
|
||||||
--- a/bin/sdb_tools/zone2ldap.c
|
|
||||||
+++ b/bin/sdb_tools/zone2ldap.c
|
|
||||||
@@ -73,7 +73,7 @@ void add_ldap_values (ldap_info * ldinfo);
|
|
||||||
void init_ldap_conn (void);
|
|
||||||
|
|
||||||
/* Ldap error checking */
|
|
||||||
-void ldap_result_check (const char *msg, char *dn, int err);
|
|
||||||
+void ldap_result_check (const char *msg, const char *dn, int err);
|
|
||||||
|
|
||||||
/* Put a hostname into a char ** array */
|
|
||||||
char **hostname_to_dn_list (char *hostname, char *zone, unsigned int flags);
|
|
||||||
@@ -82,7 +82,7 @@ char **hostname_to_dn_list (char *hostname, char *zone, unsigned int flags);
|
|
||||||
int get_attr_list_size (char **tmp);
|
|
||||||
|
|
||||||
/* Get a DN */
|
|
||||||
-char *build_dn_from_dc_list (char **dc_list, unsigned int ttl, int flag);
|
|
||||||
+char *build_dn_from_dc_list (char **dc_list, unsigned int ttl, int flag, char *zone);
|
|
||||||
|
|
||||||
/* Add to RR list */
|
|
||||||
void add_to_rr_list (char *dn, char *name, char *type, char *data,
|
|
||||||
@@ -104,11 +104,26 @@ void
|
|
||||||
init_ldap_conn ();
|
|
||||||
void usage();
|
|
||||||
|
|
||||||
-char *argzone, *ldapbase, *binddn, *bindpw = NULL;
|
|
||||||
-const char *ldapsystem = "localhost";
|
|
||||||
-static const char *objectClasses[] =
|
|
||||||
- { "top", "dNSZone", NULL };
|
|
||||||
-static const char *topObjectClasses[] = { "top", NULL };
|
|
||||||
+static char *argzone, *ldapbase, *binddn, *bindpw = NULL;
|
|
||||||
+
|
|
||||||
+/* these are needed to placate gcc4's const-ness const-ernations : */
|
|
||||||
+static char localhost[] = "localhost";
|
|
||||||
+static char *ldapsystem=&(localhost[0]);
|
|
||||||
+/* dnszone schema class names: */
|
|
||||||
+static char topClass [] ="top";
|
|
||||||
+static char dNSZoneClass[] ="dNSZone";
|
|
||||||
+static char objectClass [] ="objectClass";
|
|
||||||
+static char dcObjectClass[]="dcObject";
|
|
||||||
+/* dnszone schema attribute names: */
|
|
||||||
+static char relativeDomainName[]="relativeDomainName";
|
|
||||||
+static char dNSTTL []="dNSTTL";
|
|
||||||
+static char zoneName []="zoneName";
|
|
||||||
+static char dc []="dc";
|
|
||||||
+static char sameZone []="@";
|
|
||||||
+/* LDAPMod mod_values: */
|
|
||||||
+static char *objectClasses []= { &(topClass[0]), &(dNSZoneClass[0]), NULL };
|
|
||||||
+static char *topObjectClasses []= { &(topClass[0]), &(dcObjectClass[0]), &(dNSZoneClass[0]), NULL };
|
|
||||||
+static char *dn_buffer [64]={NULL};
|
|
||||||
LDAP *conn;
|
|
||||||
unsigned int debug = 0;
|
|
||||||
|
|
||||||
@@ -120,7 +135,7 @@ static void
|
|
||||||
fatal(const char *msg) {
|
|
||||||
perror(msg);
|
|
||||||
if (conn != NULL)
|
|
||||||
- ldap_unbind_s(conn);
|
|
||||||
+ ldap_unbind_ext_s(conn, NULL, NULL);
|
|
||||||
exit(1);
|
|
||||||
}
|
|
||||||
|
|
||||||
@@ -132,12 +147,13 @@ main (int argc, char **argv)
|
|
||||||
isc_result_t result;
|
|
||||||
char *basedn;
|
|
||||||
ldap_info *tmp;
|
|
||||||
- LDAPMod *base_attrs[2];
|
|
||||||
- LDAPMod base;
|
|
||||||
+ LDAPMod *base_attrs[5];
|
|
||||||
+ LDAPMod base, dcBase, znBase, rdnBase;
|
|
||||||
isc_buffer_t buff;
|
|
||||||
char *zonefile=0L;
|
|
||||||
char fullbasedn[1024];
|
|
||||||
char *ctmp;
|
|
||||||
+ char *zn, *dcp[2], *znp[2], *rdn[2];
|
|
||||||
dns_fixedname_t fixedzone, fixedname;
|
|
||||||
dns_rdataset_t rdataset;
|
|
||||||
char **dc_list;
|
|
||||||
@@ -150,7 +166,7 @@ main (int argc, char **argv)
|
|
||||||
extern char *optarg;
|
|
||||||
extern int optind, opterr, optopt;
|
|
||||||
int create_base = 0;
|
|
||||||
- int topt;
|
|
||||||
+ int topt, dcn, zdn, znlen;
|
|
||||||
|
|
||||||
if (argc < 2)
|
|
||||||
{
|
|
||||||
@@ -158,7 +174,7 @@ main (int argc, char **argv)
|
|
||||||
exit (-1);
|
|
||||||
}
|
|
||||||
|
|
||||||
- while ((topt = getopt (argc, argv, "D:w:b:z:f:h:?dcv")) != -1)
|
|
||||||
+ while ((topt = getopt (argc, argv, "D:Ww:b:z:f:h:?dcv")) != -1)
|
|
||||||
{
|
|
||||||
switch (topt)
|
|
||||||
{
|
|
||||||
@@ -181,6 +197,9 @@ main (int argc, char **argv)
|
|
||||||
if (bindpw == NULL)
|
|
||||||
fatal("strdup");
|
|
||||||
break;
|
|
||||||
+ case 'W':
|
|
||||||
+ bindpw = getpass("Enter LDAP Password: ");
|
|
||||||
+ break;
|
|
||||||
case 'b':
|
|
||||||
ldapbase = strdup (optarg);
|
|
||||||
if (ldapbase == NULL)
|
|
||||||
@@ -302,17 +321,51 @@ main (int argc, char **argv)
|
|
||||||
printf ("Creating base zone DN %s\n", argzone);
|
|
||||||
|
|
||||||
dc_list = hostname_to_dn_list (argzone, argzone, DNS_TOP);
|
|
||||||
- basedn = build_dn_from_dc_list (dc_list, 0, NO_SPEC);
|
|
||||||
+ basedn = build_dn_from_dc_list (dc_list, 0, NO_SPEC, argzone);
|
|
||||||
+ if (debug)
|
|
||||||
+ printf ("base DN %s\n", basedn);
|
|
||||||
|
|
||||||
- for (ctmp = &basedn[strlen (basedn)]; ctmp >= &basedn[0]; ctmp--)
|
|
||||||
+ for (ctmp = &basedn[strlen (basedn)], dcn=0; ctmp >= &basedn[0]; ctmp--)
|
|
||||||
{
|
|
||||||
if ((*ctmp == ',') || (ctmp == &basedn[0]))
|
|
||||||
{
|
|
||||||
base.mod_op = LDAP_MOD_ADD;
|
|
||||||
- base.mod_type = (char*)"objectClass";
|
|
||||||
+ base.mod_type = objectClass;
|
|
||||||
base.mod_values = (char**)topObjectClasses;
|
|
||||||
base_attrs[0] = (void*)&base;
|
|
||||||
- base_attrs[1] = NULL;
|
|
||||||
+
|
|
||||||
+ dcBase.mod_op = LDAP_MOD_ADD;
|
|
||||||
+ dcBase.mod_type = dc;
|
|
||||||
+ dcp[0]=dc_list[dcn];
|
|
||||||
+ dcp[1]=0L;
|
|
||||||
+ dcBase.mod_values=dcp;
|
|
||||||
+ base_attrs[1] = (void*)&dcBase;
|
|
||||||
+
|
|
||||||
+ znBase.mod_op = LDAP_MOD_ADD;
|
|
||||||
+ znBase.mod_type = zoneName;
|
|
||||||
+ for( zdn = dcn, znlen = 0; zdn >= 0; zdn-- )
|
|
||||||
+ znlen += strlen(dc_list[zdn])+1;
|
|
||||||
+ znp[0] = (char*)malloc(znlen+1);
|
|
||||||
+ znp[1] = 0L;
|
|
||||||
+ for( zdn = dcn, zn=znp[0]; zdn >= 0; zdn-- )
|
|
||||||
+ zn+=sprintf(zn,"%s%s",dc_list[zdn],
|
|
||||||
+ ((zdn > 0) && (*(dc_list[zdn-1])!='.')) ? "." : ""
|
|
||||||
+ );
|
|
||||||
+
|
|
||||||
+ znBase.mod_values = znp;
|
|
||||||
+ base_attrs[2] = (void*)&znBase;
|
|
||||||
+
|
|
||||||
+ rdnBase.mod_op = LDAP_MOD_ADD;
|
|
||||||
+ rdnBase.mod_type = relativeDomainName;
|
|
||||||
+ rdn[0] = strdup(sameZone);
|
|
||||||
+ rdn[1] = 0L;
|
|
||||||
+ rdnBase.mod_values = rdn;
|
|
||||||
+ base_attrs[3] = (void*)&rdnBase;
|
|
||||||
+
|
|
||||||
+ dcn++;
|
|
||||||
+
|
|
||||||
+ base.mod_values = topObjectClasses;
|
|
||||||
+ base_attrs[4] = NULL;
|
|
||||||
|
|
||||||
if (ldapbase)
|
|
||||||
{
|
|
||||||
@@ -329,6 +382,10 @@ main (int argc, char **argv)
|
|
||||||
else
|
|
||||||
sprintf (fullbasedn, "%s", ctmp);
|
|
||||||
}
|
|
||||||
+
|
|
||||||
+ if( debug )
|
|
||||||
+ printf("Full base dn: %s\n", fullbasedn);
|
|
||||||
+
|
|
||||||
result = ldap_add_s (conn, fullbasedn, base_attrs);
|
|
||||||
ldap_result_check ("initial ldap_add_s", fullbasedn, result);
|
|
||||||
}
|
|
||||||
@@ -408,14 +465,14 @@ generate_ldap (dns_name_t * dnsname, dns_rdata_t * rdata, unsigned int ttl)
|
|
||||||
isc_result_check (result, "dns_rdata_totext");
|
|
||||||
data[isc_buffer_usedlength (&buff)] = 0;
|
|
||||||
|
|
||||||
- dc_list = hostname_to_dn_list (name, argzone, DNS_OBJECT);
|
|
||||||
+ dc_list = hostname_to_dn_list ((char*)name, argzone, DNS_OBJECT);
|
|
||||||
len = (get_attr_list_size (dc_list) - 2);
|
|
||||||
- dn = build_dn_from_dc_list (dc_list, ttl, WI_SPEC);
|
|
||||||
+ dn = build_dn_from_dc_list (dc_list, ttl, WI_SPEC, argzone);
|
|
||||||
|
|
||||||
if (debug)
|
|
||||||
printf ("Adding %s (%s %s) to run queue list.\n", dn, type, data);
|
|
||||||
|
|
||||||
- add_to_rr_list (dn, dc_list[len], type, data, ttl, DNS_OBJECT);
|
|
||||||
+ add_to_rr_list (dn, dc_list[len], (char*)type, (char*)data, ttl, DNS_OBJECT);
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
@@ -455,7 +512,8 @@ add_to_rr_list (char *dn, char *name, char *type,
|
|
||||||
int attrlist;
|
|
||||||
char ldap_type_buffer[128];
|
|
||||||
char charttl[64];
|
|
||||||
-
|
|
||||||
+ char *zn;
|
|
||||||
+ int znlen;
|
|
||||||
|
|
||||||
if ((tmp = locate_by_dn (dn)) == NULL)
|
|
||||||
{
|
|
||||||
@@ -482,10 +540,10 @@ add_to_rr_list (char *dn, char *name, char *type,
|
|
||||||
fatal("malloc");
|
|
||||||
}
|
|
||||||
tmp->attrs[0]->mod_op = LDAP_MOD_ADD;
|
|
||||||
- tmp->attrs[0]->mod_type = (char*)"objectClass";
|
|
||||||
+ tmp->attrs[0]->mod_type = objectClass;
|
|
||||||
|
|
||||||
if (flags == DNS_OBJECT)
|
|
||||||
- tmp->attrs[0]->mod_values = (char**)objectClasses;
|
|
||||||
+ tmp->attrs[0]->mod_values = objectClasses;
|
|
||||||
else
|
|
||||||
{
|
|
||||||
tmp->attrs[0]->mod_values = (char**)topObjectClasses;
|
|
||||||
@@ -497,7 +555,7 @@ add_to_rr_list (char *dn, char *name, char *type,
|
|
||||||
}
|
|
||||||
|
|
||||||
tmp->attrs[1]->mod_op = LDAP_MOD_ADD;
|
|
||||||
- tmp->attrs[1]->mod_type = (char*)"relativeDomainName";
|
|
||||||
+ tmp->attrs[1]->mod_type = relativeDomainName;
|
|
||||||
tmp->attrs[1]->mod_values = (char **) calloc (sizeof (char *), 2);
|
|
||||||
|
|
||||||
if (tmp->attrs[1]->mod_values == (char **)NULL)
|
|
||||||
@@ -526,7 +584,7 @@ add_to_rr_list (char *dn, char *name, char *type,
|
|
||||||
fatal("strdup");
|
|
||||||
|
|
||||||
tmp->attrs[3]->mod_op = LDAP_MOD_ADD;
|
|
||||||
- tmp->attrs[3]->mod_type = (char*)"dNSTTL";
|
|
||||||
+ tmp->attrs[3]->mod_type = dNSTTL;
|
|
||||||
tmp->attrs[3]->mod_values = (char **) calloc (sizeof (char *), 2);
|
|
||||||
|
|
||||||
if (tmp->attrs[3]->mod_values == (char **)NULL)
|
|
||||||
@@ -539,14 +597,25 @@ add_to_rr_list (char *dn, char *name, char *type,
|
|
||||||
if (tmp->attrs[3]->mod_values[0] == NULL)
|
|
||||||
fatal("strdup");
|
|
||||||
|
|
||||||
+ znlen=strlen(gbl_zone);
|
|
||||||
+ if ( gbl_zone[znlen-1] == '.' )
|
|
||||||
+ { /* ldapdb MUST search by relative zone name */
|
|
||||||
+ zn = (char*)malloc(znlen);
|
|
||||||
+ memcpy(zn, gbl_zone, znlen-1);
|
|
||||||
+ zn[znlen-1]='\0';
|
|
||||||
+ }else
|
|
||||||
+ {
|
|
||||||
+ zn = gbl_zone;
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
tmp->attrs[4]->mod_op = LDAP_MOD_ADD;
|
|
||||||
- tmp->attrs[4]->mod_type = (char*)"zoneName";
|
|
||||||
+ tmp->attrs[4]->mod_type = zoneName;
|
|
||||||
tmp->attrs[4]->mod_values = (char **)calloc(sizeof(char *), 2);
|
|
||||||
|
|
||||||
if (tmp->attrs[4]->mod_values == (char **)NULL)
|
|
||||||
fatal("calloc");
|
|
||||||
|
|
||||||
- tmp->attrs[4]->mod_values[0] = gbl_zone;
|
|
||||||
+ tmp->attrs[4]->mod_values[0] = zn;
|
|
||||||
tmp->attrs[4]->mod_values[1] = NULL;
|
|
||||||
|
|
||||||
tmp->attrs[5] = NULL;
|
|
||||||
@@ -557,7 +626,7 @@ add_to_rr_list (char *dn, char *name, char *type,
|
|
||||||
else
|
|
||||||
{
|
|
||||||
|
|
||||||
- for (i = 0; tmp->attrs[i] != NULL; i++)
|
|
||||||
+ for (i = 0; tmp->attrs[i] != NULL; i++)
|
|
||||||
{
|
|
||||||
sprintf (ldap_type_buffer, "%sRecord", type);
|
|
||||||
if (!strncmp
|
|
||||||
@@ -631,44 +700,70 @@ char **
|
|
||||||
hostname_to_dn_list (char *hostname, char *zone, unsigned int flags)
|
|
||||||
{
|
|
||||||
char *tmp;
|
|
||||||
- static char *dn_buffer[64];
|
|
||||||
int i = 0;
|
|
||||||
- char *zname;
|
|
||||||
- char *hnamebuff;
|
|
||||||
-
|
|
||||||
- zname = strdup (hostname);
|
|
||||||
- if (zname == NULL)
|
|
||||||
- fatal("strdup");
|
|
||||||
-
|
|
||||||
- if (flags == DNS_OBJECT)
|
|
||||||
- {
|
|
||||||
-
|
|
||||||
- if (strlen (zname) != strlen (zone))
|
|
||||||
- {
|
|
||||||
- tmp = &zname[strlen (zname) - strlen (zone)];
|
|
||||||
- *--tmp = '\0';
|
|
||||||
- hnamebuff = strdup (zname);
|
|
||||||
- if (hnamebuff == NULL)
|
|
||||||
- fatal("strdup");
|
|
||||||
- zname = ++tmp;
|
|
||||||
- }
|
|
||||||
- else
|
|
||||||
- hnamebuff = (char*)"@";
|
|
||||||
- }
|
|
||||||
- else
|
|
||||||
- {
|
|
||||||
- zname = zone;
|
|
||||||
- hnamebuff = NULL;
|
|
||||||
- }
|
|
||||||
-
|
|
||||||
- for (tmp = strrchr (zname, '.'); tmp != (char *) 0;
|
|
||||||
- tmp = strrchr (zname, '.'))
|
|
||||||
- {
|
|
||||||
- *tmp++ = '\0';
|
|
||||||
- dn_buffer[i++] = tmp;
|
|
||||||
- }
|
|
||||||
- dn_buffer[i++] = zname;
|
|
||||||
- dn_buffer[i++] = hnamebuff;
|
|
||||||
+ char *hname=0L, *last=0L;
|
|
||||||
+ int hlen=strlen(hostname), zlen=(strlen(zone));
|
|
||||||
+
|
|
||||||
+/* printf("hostname: %s zone: %s\n",hostname, zone); */
|
|
||||||
+ hname=0L;
|
|
||||||
+ if(flags == DNS_OBJECT)
|
|
||||||
+ {
|
|
||||||
+ if( (zone[ zlen - 1 ] == '.') && (hostname[hlen - 1] != '.') )
|
|
||||||
+ {
|
|
||||||
+ hname=(char*)malloc(hlen + 1);
|
|
||||||
+ hlen += 1;
|
|
||||||
+ sprintf(hname, "%s.", hostname);
|
|
||||||
+ hostname = hname;
|
|
||||||
+ }
|
|
||||||
+ if(strcmp(hostname, zone) == 0)
|
|
||||||
+ {
|
|
||||||
+ if( hname == 0 )
|
|
||||||
+ hname=strdup(hostname);
|
|
||||||
+ last = strdup(sameZone);
|
|
||||||
+ }else
|
|
||||||
+ {
|
|
||||||
+ if( (hlen < zlen)
|
|
||||||
+ ||( strcmp( hostname + (hlen - zlen), zone ) != 0)
|
|
||||||
+ )
|
|
||||||
+ {
|
|
||||||
+ if( hname != 0 )
|
|
||||||
+ free(hname);
|
|
||||||
+ hname=(char*)malloc( hlen + zlen + 1);
|
|
||||||
+ if( *zone == '.' )
|
|
||||||
+ sprintf(hname, "%s%s", hostname, zone);
|
|
||||||
+ else
|
|
||||||
+ sprintf(hname,"%s",zone);
|
|
||||||
+ }else
|
|
||||||
+ {
|
|
||||||
+ if( hname == 0 )
|
|
||||||
+ hname = strdup(hostname);
|
|
||||||
+ }
|
|
||||||
+ last = hname;
|
|
||||||
+ }
|
|
||||||
+ }else
|
|
||||||
+ { /* flags == DNS_TOP */
|
|
||||||
+ hname = strdup(zone);
|
|
||||||
+ last = hname;
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+ for (tmp = strrchr (hname, '.'); tmp != (char *) 0;
|
|
||||||
+ tmp = strrchr (hname, '.'))
|
|
||||||
+ {
|
|
||||||
+ if( *( tmp + 1 ) != '\0' )
|
|
||||||
+ {
|
|
||||||
+ *tmp = '\0';
|
|
||||||
+ dn_buffer[i++] = ++tmp;
|
|
||||||
+ }else
|
|
||||||
+ { /* trailing '.' ! */
|
|
||||||
+ dn_buffer[i++] = strdup(".");
|
|
||||||
+ *tmp = '\0';
|
|
||||||
+ if( tmp == hname )
|
|
||||||
+ break;
|
|
||||||
+ }
|
|
||||||
+ }
|
|
||||||
+ if( ( last != hname ) && (tmp != hname) )
|
|
||||||
+ dn_buffer[i++] = hname;
|
|
||||||
+ dn_buffer[i++] = last;
|
|
||||||
dn_buffer[i] = NULL;
|
|
||||||
|
|
||||||
return dn_buffer;
|
|
||||||
@@ -680,30 +775,38 @@ hostname_to_dn_list (char *hostname, char *zone, unsigned int flags)
|
|
||||||
* exception of "@"/SOA. */
|
|
||||||
|
|
||||||
char *
|
|
||||||
-build_dn_from_dc_list (char **dc_list, unsigned int ttl, int flag)
|
|
||||||
+build_dn_from_dc_list (char **dc_list, unsigned int ttl, int flag, char *zone)
|
|
||||||
{
|
|
||||||
int size;
|
|
||||||
- int x;
|
|
||||||
- static char dn[1024];
|
|
||||||
- char tmp[128];
|
|
||||||
+ int x, znlen;
|
|
||||||
+ static char dn[DNS_NAME_MAXTEXT*3/2];
|
|
||||||
+ char tmp[DNS_NAME_MAXTEXT*3/2];
|
|
||||||
+ char zn[DNS_NAME_MAXTEXT+1];
|
|
||||||
|
|
||||||
bzero (tmp, sizeof (tmp));
|
|
||||||
bzero (dn, sizeof (dn));
|
|
||||||
size = get_attr_list_size (dc_list);
|
|
||||||
+ znlen = strlen(zone);
|
|
||||||
+ if ( zone[znlen-1] == '.' )
|
|
||||||
+ { /* ldapdb MUST search by relative zone name */
|
|
||||||
+ memcpy(&(zn[0]),zone,znlen-1);
|
|
||||||
+ zn[znlen-1]='\0';
|
|
||||||
+ zone = zn;
|
|
||||||
+ }
|
|
||||||
for (x = size - 2; x > 0; x--)
|
|
||||||
{
|
|
||||||
if (flag == WI_SPEC)
|
|
||||||
{
|
|
||||||
if (x == (size - 2) && (strncmp (dc_list[x], "@", 1) == 0) && (ttl))
|
|
||||||
- sprintf (tmp, "relativeDomainName=%s + dNSTTL=%u,", dc_list[x], ttl);
|
|
||||||
+ snprintf (tmp, sizeof(tmp), "zoneName=%s + relativeDomainName=%s,", zone, dc_list[x]);
|
|
||||||
else if (x == (size - 2))
|
|
||||||
- sprintf(tmp, "relativeDomainName=%s,",dc_list[x]);
|
|
||||||
+ snprintf(tmp, sizeof(tmp), "zoneName=%s + relativeDomainName=%s,", zone, dc_list[x]);
|
|
||||||
else
|
|
||||||
- sprintf(tmp,"dc=%s,", dc_list[x]);
|
|
||||||
+ snprintf(tmp, sizeof(tmp), "dc=%s,", dc_list[x]);
|
|
||||||
}
|
|
||||||
else
|
|
||||||
{
|
|
||||||
- sprintf(tmp, "dc=%s,", dc_list[x]);
|
|
||||||
+ snprintf(tmp, sizeof(tmp), "dc=%s,", dc_list[x]);
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
@@ -732,19 +835,18 @@ init_ldap_conn ()
|
|
||||||
}
|
|
||||||
|
|
||||||
result = ldap_simple_bind_s (conn, binddn, bindpw);
|
|
||||||
- ldap_result_check ("ldap_simple_bind_s", (char*)"LDAP Bind", result);
|
|
||||||
+ ldap_result_check ("ldap_simple_bind_s", "LDAP Bind", result);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Like isc_result_check, only for LDAP */
|
|
||||||
void
|
|
||||||
-ldap_result_check (const char *msg, char *dn, int err)
|
|
||||||
+ldap_result_check (const char *msg, const char *dn, int err)
|
|
||||||
{
|
|
||||||
if ((err != LDAP_SUCCESS) && (err != LDAP_ALREADY_EXISTS))
|
|
||||||
{
|
|
||||||
- fprintf(stderr, "Error while adding %s (%s):\n",
|
|
||||||
- dn, msg);
|
|
||||||
- ldap_perror (conn, dn);
|
|
||||||
- ldap_unbind_s (conn);
|
|
||||||
+ fprintf(stderr, "Error while adding %s (%s):\n%s",
|
|
||||||
+ dn, msg, ldap_err2string(err));
|
|
||||||
+ ldap_unbind_ext_s (conn, NULL, NULL);
|
|
||||||
exit (-1);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -758,16 +860,15 @@ add_ldap_values (ldap_info * ldinfo)
|
|
||||||
int result;
|
|
||||||
char dnbuffer[1024];
|
|
||||||
|
|
||||||
-
|
|
||||||
if (ldapbase != NULL)
|
|
||||||
sprintf (dnbuffer, "%s,%s", ldinfo->dn, ldapbase);
|
|
||||||
else
|
|
||||||
sprintf (dnbuffer, "%s", ldinfo->dn);
|
|
||||||
|
|
||||||
result = ldap_add_s (conn, dnbuffer, ldinfo->attrs);
|
|
||||||
- ldap_result_check ("ldap_add_s", dnbuffer, result);
|
|
||||||
-}
|
|
||||||
+ ldap_result_check ("ldap_add_s", dnbuffer, result);
|
|
||||||
|
|
||||||
+}
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
@@ -776,5 +877,5 @@ void
|
|
||||||
usage ()
|
|
||||||
{
|
|
||||||
fprintf (stderr,
|
|
||||||
- "zone2ldap -D [BIND DN] -w [BIND PASSWORD] -b [BASE DN] -z [ZONE] -f [ZONE FILE] -h [LDAP HOST] "
|
|
||||||
+ "zone2ldap -D [BIND DN] [-w BIND PASSWORD | -W:prompt] -b [BASE DN] -z [ZONE] -f [ZONE FILE] -h [LDAP HOST] "
|
|
||||||
"[-c Create LDAP Base structure][-d Debug Output (lots !)] \n ");}
|
|
||||||
@ -1,230 +0,0 @@
|
|||||||
diff --git a/contrib/sdb/bdb/bdb.c b/contrib/sdb/bdb/bdb.c
|
|
||||||
index 23594bb..b3c6619 100644
|
|
||||||
--- a/contrib/sdb/bdb/bdb.c
|
|
||||||
+++ b/contrib/sdb/bdb/bdb.c
|
|
||||||
@@ -43,7 +43,7 @@
|
|
||||||
#include <dns/lib.h>
|
|
||||||
#include <dns/ttl.h>
|
|
||||||
|
|
||||||
-#include <named/bdb.h>
|
|
||||||
+#include "bdb.h"
|
|
||||||
#include <named/globals.h>
|
|
||||||
#include <named/config.h>
|
|
||||||
|
|
||||||
diff --git a/contrib/sdb/ldap/zone2ldap.c b/contrib/sdb/ldap/zone2ldap.c
|
|
||||||
index 07c89bc..23dd873 100644
|
|
||||||
--- a/contrib/sdb/ldap/zone2ldap.c
|
|
||||||
+++ b/contrib/sdb/ldap/zone2ldap.c
|
|
||||||
@@ -63,16 +63,16 @@ typedef struct LDAP_INFO
|
|
||||||
ldap_info;
|
|
||||||
|
|
||||||
/* usage Info */
|
|
||||||
-void usage ();
|
|
||||||
+void usage (void);
|
|
||||||
|
|
||||||
/* Add to the ldap dit */
|
|
||||||
void add_ldap_values (ldap_info * ldinfo);
|
|
||||||
|
|
||||||
/* Init an ldap connection */
|
|
||||||
-void init_ldap_conn ();
|
|
||||||
+void init_ldap_conn (void);
|
|
||||||
|
|
||||||
/* Ldap error checking */
|
|
||||||
-void ldap_result_check (char *msg, char *dn, int err);
|
|
||||||
+void ldap_result_check (const char *msg, char *dn, int err);
|
|
||||||
|
|
||||||
/* Put a hostname into a char ** array */
|
|
||||||
char **hostname_to_dn_list (char *hostname, char *zone, unsigned int flags);
|
|
||||||
@@ -88,7 +88,7 @@ void add_to_rr_list (char *dn, char *name, char *type, char *data,
|
|
||||||
unsigned int ttl, unsigned int flags);
|
|
||||||
|
|
||||||
/* Error checking */
|
|
||||||
-void isc_result_check (isc_result_t res, char *errorstr);
|
|
||||||
+void isc_result_check (isc_result_t res, const char *errorstr);
|
|
||||||
|
|
||||||
/* Generate LDIF Format files */
|
|
||||||
void generate_ldap (dns_name_t * dnsname, dns_rdata_t * rdata,
|
|
||||||
@@ -97,11 +97,17 @@ void generate_ldap (dns_name_t * dnsname, dns_rdata_t * rdata,
|
|
||||||
/* head pointer to the list */
|
|
||||||
ldap_info *ldap_info_base = NULL;
|
|
||||||
|
|
||||||
+ldap_info *
|
|
||||||
+locate_by_dn (char *dn);
|
|
||||||
+void
|
|
||||||
+init_ldap_conn ();
|
|
||||||
+void usage();
|
|
||||||
+
|
|
||||||
char *argzone, *ldapbase, *binddn, *bindpw = NULL;
|
|
||||||
-char *ldapsystem = "localhost";
|
|
||||||
-static char *objectClasses[] =
|
|
||||||
+const char *ldapsystem = "localhost";
|
|
||||||
+static const char *objectClasses[] =
|
|
||||||
{ "top", "dNSZone", NULL };
|
|
||||||
-static char *topObjectClasses[] = { "top", NULL };
|
|
||||||
+static const char *topObjectClasses[] = { "top", NULL };
|
|
||||||
LDAP *conn;
|
|
||||||
unsigned int debug = 0;
|
|
||||||
|
|
||||||
@@ -128,7 +134,7 @@ main (int argc, char **argv)
|
|
||||||
LDAPMod *base_attrs[2];
|
|
||||||
LDAPMod base;
|
|
||||||
isc_buffer_t buff;
|
|
||||||
- char *zonefile;
|
|
||||||
+ char *zonefile=0L;
|
|
||||||
char fullbasedn[1024];
|
|
||||||
char *ctmp;
|
|
||||||
dns_fixedname_t fixedzone, fixedname;
|
|
||||||
@@ -304,9 +310,9 @@ main (int argc, char **argv)
|
|
||||||
if ((*ctmp == ',') || (ctmp == &basedn[0]))
|
|
||||||
{
|
|
||||||
base.mod_op = LDAP_MOD_ADD;
|
|
||||||
- base.mod_type = "objectClass";
|
|
||||||
- base.mod_values = topObjectClasses;
|
|
||||||
- base_attrs[0] = &base;
|
|
||||||
+ base.mod_type = (char*)"objectClass";
|
|
||||||
+ base.mod_values = (char**)topObjectClasses;
|
|
||||||
+ base_attrs[0] = (void*)&base;
|
|
||||||
base_attrs[1] = NULL;
|
|
||||||
|
|
||||||
if (ldapbase)
|
|
||||||
@@ -363,7 +369,7 @@ main (int argc, char **argv)
|
|
||||||
* I should probably rename this function, as not to cause any
|
|
||||||
* confusion with the isc* routines. Will exit on error. */
|
|
||||||
void
|
|
||||||
-isc_result_check (isc_result_t res, char *errorstr)
|
|
||||||
+isc_result_check (isc_result_t res, const char *errorstr)
|
|
||||||
{
|
|
||||||
if (res != ISC_R_SUCCESS)
|
|
||||||
{
|
|
||||||
@@ -470,20 +476,20 @@ add_to_rr_list (char *dn, char *name, char *type,
|
|
||||||
if (tmp->attrs == (LDAPMod **) NULL)
|
|
||||||
fatal("calloc");
|
|
||||||
|
|
||||||
- for (i = 0; i < flags; i++)
|
|
||||||
+ for (i = 0; i < (int)flags; i++)
|
|
||||||
{
|
|
||||||
tmp->attrs[i] = (LDAPMod *) malloc (sizeof (LDAPMod));
|
|
||||||
if (tmp->attrs[i] == (LDAPMod *) NULL)
|
|
||||||
fatal("malloc");
|
|
||||||
}
|
|
||||||
tmp->attrs[0]->mod_op = LDAP_MOD_ADD;
|
|
||||||
- tmp->attrs[0]->mod_type = "objectClass";
|
|
||||||
+ tmp->attrs[0]->mod_type = (char*)"objectClass";
|
|
||||||
|
|
||||||
if (flags == DNS_OBJECT)
|
|
||||||
- tmp->attrs[0]->mod_values = objectClasses;
|
|
||||||
+ tmp->attrs[0]->mod_values = (char**)objectClasses;
|
|
||||||
else
|
|
||||||
{
|
|
||||||
- tmp->attrs[0]->mod_values = topObjectClasses;
|
|
||||||
+ tmp->attrs[0]->mod_values = (char**)topObjectClasses;
|
|
||||||
tmp->attrs[1] = NULL;
|
|
||||||
tmp->attrcnt = 2;
|
|
||||||
tmp->next = ldap_info_base;
|
|
||||||
@@ -492,7 +498,7 @@ add_to_rr_list (char *dn, char *name, char *type,
|
|
||||||
}
|
|
||||||
|
|
||||||
tmp->attrs[1]->mod_op = LDAP_MOD_ADD;
|
|
||||||
- tmp->attrs[1]->mod_type = "relativeDomainName";
|
|
||||||
+ tmp->attrs[1]->mod_type = (char*)"relativeDomainName";
|
|
||||||
tmp->attrs[1]->mod_values = (char **) calloc (sizeof (char *), 2);
|
|
||||||
|
|
||||||
if (tmp->attrs[1]->mod_values == (char **)NULL)
|
|
||||||
@@ -521,7 +527,7 @@ add_to_rr_list (char *dn, char *name, char *type,
|
|
||||||
fatal("strdup");
|
|
||||||
|
|
||||||
tmp->attrs[3]->mod_op = LDAP_MOD_ADD;
|
|
||||||
- tmp->attrs[3]->mod_type = "dNSTTL";
|
|
||||||
+ tmp->attrs[3]->mod_type = (char*)"dNSTTL";
|
|
||||||
tmp->attrs[3]->mod_values = (char **) calloc (sizeof (char *), 2);
|
|
||||||
|
|
||||||
if (tmp->attrs[3]->mod_values == (char **)NULL)
|
|
||||||
@@ -535,7 +541,7 @@ add_to_rr_list (char *dn, char *name, char *type,
|
|
||||||
fatal("strdup");
|
|
||||||
|
|
||||||
tmp->attrs[4]->mod_op = LDAP_MOD_ADD;
|
|
||||||
- tmp->attrs[4]->mod_type = "zoneName";
|
|
||||||
+ tmp->attrs[4]->mod_type = (char*)"zoneName";
|
|
||||||
tmp->attrs[4]->mod_values = (char **)calloc(sizeof(char *), 2);
|
|
||||||
|
|
||||||
if (tmp->attrs[4]->mod_values == (char **)NULL)
|
|
||||||
@@ -648,7 +654,7 @@ hostname_to_dn_list (char *hostname, char *zone, unsigned int flags)
|
|
||||||
zname = ++tmp;
|
|
||||||
}
|
|
||||||
else
|
|
||||||
- hnamebuff = "@";
|
|
||||||
+ hnamebuff = (char*)"@";
|
|
||||||
}
|
|
||||||
else
|
|
||||||
{
|
|
||||||
@@ -727,12 +733,12 @@ init_ldap_conn ()
|
|
||||||
}
|
|
||||||
|
|
||||||
result = ldap_simple_bind_s (conn, binddn, bindpw);
|
|
||||||
- ldap_result_check ("ldap_simple_bind_s", "LDAP Bind", result);
|
|
||||||
+ ldap_result_check ("ldap_simple_bind_s", (char*)"LDAP Bind", result);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Like isc_result_check, only for LDAP */
|
|
||||||
void
|
|
||||||
-ldap_result_check (char *msg, char *dn, int err)
|
|
||||||
+ldap_result_check (const char *msg, char *dn, int err)
|
|
||||||
{
|
|
||||||
if ((err != LDAP_SUCCESS) && (err != LDAP_ALREADY_EXISTS))
|
|
||||||
{
|
|
||||||
diff --git a/contrib/sdb/pgsql/pgsqldb.c b/contrib/sdb/pgsql/pgsqldb.c
|
|
||||||
index 50d3cba..516eb9f 100644
|
|
||||||
--- a/contrib/sdb/pgsql/pgsqldb.c
|
|
||||||
+++ b/contrib/sdb/pgsql/pgsqldb.c
|
|
||||||
@@ -23,7 +23,7 @@
|
|
||||||
#include <string.h>
|
|
||||||
#include <stdlib.h>
|
|
||||||
|
|
||||||
-#include <pgsql/libpq-fe.h>
|
|
||||||
+#include <libpq-fe.h>
|
|
||||||
|
|
||||||
#include <isc/mem.h>
|
|
||||||
#include <isc/print.h>
|
|
||||||
diff --git a/contrib/sdb/pgsql/zonetodb.c b/contrib/sdb/pgsql/zonetodb.c
|
|
||||||
index b8f5912..ff2d135 100644
|
|
||||||
--- a/contrib/sdb/pgsql/zonetodb.c
|
|
||||||
+++ b/contrib/sdb/pgsql/zonetodb.c
|
|
||||||
@@ -37,7 +37,7 @@
|
|
||||||
#include <dns/rdatatype.h>
|
|
||||||
#include <dns/result.h>
|
|
||||||
|
|
||||||
-#include <pgsql/libpq-fe.h>
|
|
||||||
+#include <libpq-fe.h>
|
|
||||||
|
|
||||||
/*
|
|
||||||
* Generate a PostgreSQL table from a zone.
|
|
||||||
@@ -54,6 +54,9 @@ char *dbname, *dbtable;
|
|
||||||
char str[10240];
|
|
||||||
|
|
||||||
void
|
|
||||||
+closeandexit(int status);
|
|
||||||
+
|
|
||||||
+void
|
|
||||||
closeandexit(int status) {
|
|
||||||
if (conn != NULL)
|
|
||||||
PQfinish(conn);
|
|
||||||
@@ -61,6 +64,9 @@ closeandexit(int status) {
|
|
||||||
}
|
|
||||||
|
|
||||||
void
|
|
||||||
+check_result(isc_result_t result, const char *message);
|
|
||||||
+
|
|
||||||
+void
|
|
||||||
check_result(isc_result_t result, const char *message) {
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
fprintf(stderr, "%s: %s\n", message,
|
|
||||||
@@ -84,7 +90,8 @@ quotestring(const unsigned char *source, unsigned char *dest) {
|
|
||||||
}
|
|
||||||
*dest++ = 0;
|
|
||||||
}
|
|
||||||
-
|
|
||||||
+void
|
|
||||||
+addrdata(dns_name_t *name, dns_ttl_t ttl, dns_rdata_t *rdata);
|
|
||||||
void
|
|
||||||
addrdata(dns_name_t *name, dns_ttl_t ttl, dns_rdata_t *rdata) {
|
|
||||||
unsigned char namearray[DNS_NAME_MAXTEXT + 1];
|
|
||||||
@ -1,8 +1,10 @@
|
|||||||
--- bind-9.5.0b2/bin/named/Makefile.in.pie 2008-02-11 17:21:47.000000000 +0100
|
diff --git a/bin/named/Makefile.in b/bin/named/Makefile.in
|
||||||
+++ bind-9.5.0b2/bin/named/Makefile.in 2008-02-11 17:22:10.000000000 +0100
|
index eb622d1..37053a7 100644
|
||||||
@@ -100,8 +100,12 @@ HTMLPAGES = named.html lwresd.html named
|
--- a/bin/named/Makefile.in
|
||||||
|
+++ b/bin/named/Makefile.in
|
||||||
MANOBJS = ${MANPAGES} ${HTMLPAGES}
|
@@ -117,8 +117,12 @@ SRCS = builtin.c config.c control.c \
|
||||||
|
tkeyconf.c tsigconf.c zoneconf.c \
|
||||||
|
${DLZDRIVER_SRCS} ${DBDRIVER_SRCS}
|
||||||
|
|
||||||
+EXT_CFLAGS = -fpie
|
+EXT_CFLAGS = -fpie
|
||||||
+
|
+
|
||||||
@ -13,10 +15,11 @@
|
|||||||
main.@O@: main.c
|
main.@O@: main.c
|
||||||
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} \
|
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} \
|
||||||
-DVERSION=\"${VERSION}\" \
|
-DVERSION=\"${VERSION}\" \
|
||||||
diff -up bind-9.5.0b2/bin/named/unix/Makefile.in.pie bind-9.5.0b2/bin/named/unix/Makefile.in
|
diff --git a/bin/named/unix/Makefile.in b/bin/named/unix/Makefile.in
|
||||||
--- bind-9.5.0b2/bin/named/unix/Makefile.in.pie 2008-02-11 17:22:21.000000000 +0100
|
index fd9ca8d..f1c102c 100644
|
||||||
+++ bind-9.5.0b2/bin/named/unix/Makefile.in 2008-02-11 17:23:00.000000000 +0100
|
--- a/bin/named/unix/Makefile.in
|
||||||
@@ -19,6 +19,8 @@ srcdir = @srcdir@
|
+++ b/bin/named/unix/Makefile.in
|
||||||
|
@@ -11,6 +11,8 @@ srcdir = @srcdir@
|
||||||
VPATH = @srcdir@
|
VPATH = @srcdir@
|
||||||
top_srcdir = @top_srcdir@
|
top_srcdir = @top_srcdir@
|
||||||
|
|
||||||
|
|||||||
@ -1,54 +0,0 @@
|
|||||||
diff --git a/config.h.in b/config.h.in
|
|
||||||
index 4ecaa8f..2f65ccc 100644
|
|
||||||
--- a/config.h.in
|
|
||||||
+++ b/config.h.in
|
|
||||||
@@ -600,7 +600,7 @@ int sigwait(const unsigned int *set, int *sig);
|
|
||||||
#undef PREFER_GOSTASN1
|
|
||||||
|
|
||||||
/* The size of `void *', as computed by sizeof. */
|
|
||||||
-#undef SIZEOF_VOID_P
|
|
||||||
+/* #undef SIZEOF_VOID_P */
|
|
||||||
|
|
||||||
/* Define to 1 if you have the ANSI C header files. */
|
|
||||||
#undef STDC_HEADERS
|
|
||||||
diff --git a/isc-config.sh.in b/isc-config.sh.in
|
|
||||||
index a8a0a89..b5e94ed 100644
|
|
||||||
--- a/isc-config.sh.in
|
|
||||||
+++ b/isc-config.sh.in
|
|
||||||
@@ -13,7 +13,18 @@ prefix=@prefix@
|
|
||||||
exec_prefix=@exec_prefix@
|
|
||||||
exec_prefix_set=
|
|
||||||
includedir=@includedir@
|
|
||||||
-libdir=@libdir@
|
|
||||||
+arch=$(uname -m)
|
|
||||||
+
|
|
||||||
+case $arch in
|
|
||||||
+ x86_64 | amd64 | sparc64 | s390x | ppc64)
|
|
||||||
+ libdir=/usr/lib64
|
|
||||||
+ sec_libdir=/usr/lib
|
|
||||||
+ ;;
|
|
||||||
+ * )
|
|
||||||
+ libdir=/usr/lib
|
|
||||||
+ sec_libdir=/usr/lib64
|
|
||||||
+ ;;
|
|
||||||
+esac
|
|
||||||
|
|
||||||
usage()
|
|
||||||
{
|
|
||||||
@@ -132,6 +143,16 @@ if test x"$echo_libs" = x"true"; then
|
|
||||||
if test x"${exec_prefix_set}" = x"true"; then
|
|
||||||
libs="-L${exec_prefix}/lib"
|
|
||||||
else
|
|
||||||
+ if [ ! -x $libdir/libisc.so ] ; then
|
|
||||||
+ if [ ! -x $sec_libdir/libisc.so ] ; then
|
|
||||||
+ echo "Error: ISC libs not found in $libdir"
|
|
||||||
+ if [ -d $sec_libdir ] ; then
|
|
||||||
+ echo "Error: ISC libs not found in $sec_libdir"
|
|
||||||
+ fi
|
|
||||||
+ exit 1
|
|
||||||
+ fi
|
|
||||||
+ libdir=$sec_libdir
|
|
||||||
+ fi
|
|
||||||
libs="-L${libdir}"
|
|
||||||
fi
|
|
||||||
if test x"$libirs" = x"true" ; then
|
|
||||||
@ -1,42 +0,0 @@
|
|||||||
diff --git a/bin/dig/dighost.c b/bin/dig/dighost.c
|
|
||||||
index c06c804..e75b8b7 100644
|
|
||||||
--- a/bin/dig/dighost.c
|
|
||||||
+++ b/bin/dig/dighost.c
|
|
||||||
@@ -1816,6 +1816,13 @@ clear_query(dig_query_t *query) {
|
|
||||||
|
|
||||||
if (query->timer != NULL)
|
|
||||||
isc_timer_detach(&query->timer);
|
|
||||||
+
|
|
||||||
+ if (query->waiting_senddone) {
|
|
||||||
+ debug("send_done not yet called");
|
|
||||||
+ query->pending_free = true;
|
|
||||||
+ return;
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
lookup = query->lookup;
|
|
||||||
|
|
||||||
if (lookup->current_query == query)
|
|
||||||
@@ -1841,10 +1848,7 @@ clear_query(dig_query_t *query) {
|
|
||||||
isc_mempool_put(commctx, query->recvspace);
|
|
||||||
isc_buffer_invalidate(&query->recvbuf);
|
|
||||||
isc_buffer_invalidate(&query->lengthbuf);
|
|
||||||
- if (query->waiting_senddone)
|
|
||||||
- query->pending_free = true;
|
|
||||||
- else
|
|
||||||
- isc_mem_free(mctx, query);
|
|
||||||
+ isc_mem_free(mctx, query);
|
|
||||||
}
|
|
||||||
|
|
||||||
/*%
|
|
||||||
@@ -2895,9 +2899,9 @@ send_done(isc_task_t *_task, isc_event_t *event) {
|
|
||||||
isc_event_free(&event);
|
|
||||||
|
|
||||||
if (query->pending_free)
|
|
||||||
- isc_mem_free(mctx, query);
|
|
||||||
+ clear_query(query);
|
|
||||||
|
|
||||||
- check_if_done();
|
|
||||||
+ check_next_lookup(l);
|
|
||||||
UNLOCK_LOOKUP;
|
|
||||||
}
|
|
||||||
|
|
||||||
@ -1,23 +0,0 @@
|
|||||||
diff -up bind-9.6.0b1/contrib/sdb/ldap/ldapdb.c.old-api bind-9.6.0b1/contrib/sdb/ldap/ldapdb.c
|
|
||||||
--- bind-9.6.0b1/contrib/sdb/ldap/ldapdb.c.old-api 2008-11-24 13:28:13.000000000 +0100
|
|
||||||
+++ bind-9.6.0b1/contrib/sdb/ldap/ldapdb.c 2008-11-24 13:28:23.000000000 +0100
|
|
||||||
@@ -25,6 +25,7 @@
|
|
||||||
/* Using LDAPv3 by default, change this if you want v2 */
|
|
||||||
#ifndef LDAPDB_LDAP_VERSION
|
|
||||||
#define LDAPDB_LDAP_VERSION 3
|
|
||||||
+#define LDAP_DEPRECATED 1
|
|
||||||
#endif
|
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
diff -up bind-9.6.0b1/contrib/sdb/ldap/zone2ldap.c.old-api bind-9.6.0b1/contrib/sdb/ldap/zone2ldap.c
|
|
||||||
--- bind-9.6.0b1/contrib/sdb/ldap/zone2ldap.c.old-api 2008-11-24 13:29:05.000000000 +0100
|
|
||||||
+++ bind-9.6.0b1/contrib/sdb/ldap/zone2ldap.c 2008-11-24 13:29:14.000000000 +0100
|
|
||||||
@@ -13,6 +13,8 @@
|
|
||||||
* ditched dNSDomain2 schema support. Version 0.3-ALPHA
|
|
||||||
*/
|
|
||||||
|
|
||||||
+#define LDAP_DEPRECATED 1
|
|
||||||
+
|
|
||||||
#include <errno.h>
|
|
||||||
#include <string.h>
|
|
||||||
#include <stdlib.h>
|
|
||||||
@ -1,81 +1,34 @@
|
|||||||
diff --git a/lib/isc/include/isc/stdio.h b/lib/isc/include/isc/stdio.h
|
|
||||||
index 1f44b5a..a3625f9 100644
|
|
||||||
--- a/lib/isc/include/isc/stdio.h
|
|
||||||
+++ b/lib/isc/include/isc/stdio.h
|
|
||||||
@@ -69,6 +69,9 @@ isc_stdio_sync(FILE *f);
|
|
||||||
* direct counterpart in the stdio library.
|
|
||||||
*/
|
|
||||||
|
|
||||||
+isc_result_t
|
|
||||||
+isc_stdio_fgetc(FILE *f, int *ret);
|
|
||||||
+
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
|
|
||||||
#endif /* ISC_STDIO_H */
|
|
||||||
diff --git a/lib/isc/lex.c b/lib/isc/lex.c
|
diff --git a/lib/isc/lex.c b/lib/isc/lex.c
|
||||||
index a8955bc..fc6103b 100644
|
index cd44fe3..5b7c539 100644
|
||||||
--- a/lib/isc/lex.c
|
--- a/lib/isc/lex.c
|
||||||
+++ b/lib/isc/lex.c
|
+++ b/lib/isc/lex.c
|
||||||
@@ -434,17 +434,14 @@ isc_lex_gettoken(isc_lex_t *lex, unsigned int options, isc_token_t *tokenp) {
|
@@ -27,6 +27,8 @@
|
||||||
if (source->is_file) {
|
#include <isc/string.h>
|
||||||
stream = source->input;
|
#include <isc/util.h>
|
||||||
|
|
||||||
-#if defined(HAVE_FLOCKFILE) && defined(HAVE_GETCUNLOCKED)
|
+#include "../errno2result.h"
|
||||||
- c = getc_unlocked(stream);
|
|
||||||
-#else
|
|
||||||
- c = getc(stream);
|
|
||||||
-#endif
|
|
||||||
- if (c == EOF) {
|
|
||||||
- if (ferror(stream)) {
|
|
||||||
- source->result = ISC_R_IOERROR;
|
|
||||||
- result = source->result;
|
|
||||||
+ result = isc_stdio_fgetc(stream, &c);
|
|
||||||
+
|
+
|
||||||
+ if (result != ISC_R_SUCCESS) {
|
typedef struct inputsource {
|
||||||
+ if (result != ISC_R_EOF) {
|
isc_result_t result;
|
||||||
+ source->result = result;
|
bool is_file;
|
||||||
|
@@ -422,7 +424,7 @@ isc_lex_gettoken(isc_lex_t *lex, unsigned int options, isc_token_t *tokenp) {
|
||||||
|
#endif /* if defined(HAVE_FLOCKFILE) && defined(HAVE_GETC_UNLOCKED) */
|
||||||
|
if (c == EOF) {
|
||||||
|
if (ferror(stream)) {
|
||||||
|
- source->result = ISC_R_IOERROR;
|
||||||
|
+ source->result = isc__errno2result(errno);
|
||||||
|
result = source->result;
|
||||||
goto done;
|
goto done;
|
||||||
}
|
}
|
||||||
+
|
|
||||||
source->at_eof = true;
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
diff --git a/lib/isc/unix/errno2result.c b/lib/isc/unix/errno2result.c
|
diff --git a/lib/isc/unix/errno2result.c b/lib/isc/unix/errno2result.c
|
||||||
index 2f12bcc..5bfd648 100644
|
index e3e2644..5e58600 100644
|
||||||
--- a/lib/isc/unix/errno2result.c
|
--- a/lib/isc/unix/errno2result.c
|
||||||
+++ b/lib/isc/unix/errno2result.c
|
+++ b/lib/isc/unix/errno2result.c
|
||||||
@@ -40,6 +40,7 @@ isc___errno2result(int posixerrno, bool dolog,
|
@@ -37,6 +37,7 @@ isc___errno2result(int posixerrno, bool dolog, const char *file,
|
||||||
case EINVAL: /* XXX sometimes this is not for files */
|
case EINVAL: /* XXX sometimes this is not for files */
|
||||||
case ENAMETOOLONG:
|
case ENAMETOOLONG:
|
||||||
case EBADF:
|
case EBADF:
|
||||||
+ case EISDIR:
|
+ case EISDIR:
|
||||||
return (ISC_R_INVALIDFILE);
|
return (ISC_R_INVALIDFILE);
|
||||||
case ENOENT:
|
case ENOENT:
|
||||||
return (ISC_R_FILENOTFOUND);
|
return (ISC_R_FILENOTFOUND);
|
||||||
diff --git a/lib/isc/unix/stdio.c b/lib/isc/unix/stdio.c
|
|
||||||
index e60fa65..77f0b13 100644
|
|
||||||
--- a/lib/isc/unix/stdio.c
|
|
||||||
+++ b/lib/isc/unix/stdio.c
|
|
||||||
@@ -149,3 +149,22 @@ isc_stdio_sync(FILE *f) {
|
|
||||||
return (isc__errno2result(errno));
|
|
||||||
}
|
|
||||||
|
|
||||||
+isc_result_t
|
|
||||||
+isc_stdio_fgetc(FILE *f, int *ret) {
|
|
||||||
+ int r;
|
|
||||||
+ isc_result_t result = ISC_R_SUCCESS;
|
|
||||||
+
|
|
||||||
+#if defined(HAVE_FLOCKFILE) && defined(HAVE_GETCUNLOCKED)
|
|
||||||
+ r = fgetc_unlocked(f);
|
|
||||||
+#else
|
|
||||||
+ r = fgets(f);
|
|
||||||
+#endif
|
|
||||||
+
|
|
||||||
+ if (r == EOF)
|
|
||||||
+ result = ferror(f) ? isc__errno2result(errno) : ISC_R_EOF;
|
|
||||||
+
|
|
||||||
+ *ret = r;
|
|
||||||
+
|
|
||||||
+ return result;
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
|
|||||||
@ -1,51 +0,0 @@
|
|||||||
diff --git a/configure.ac b/configure.ac
|
|
||||||
index 26c509e..c1bfd62 100644
|
|
||||||
--- a/configure.ac
|
|
||||||
+++ b/configure.ac
|
|
||||||
@@ -4152,6 +4152,10 @@ if test "yes" = "$use_atomic"; then
|
|
||||||
AC_MSG_RESULT($arch)
|
|
||||||
fi
|
|
||||||
|
|
||||||
+if test ! "$arch" = "x86_64" -a "$have_xaddq" = "yes"; then
|
|
||||||
+ AC_MSG_ERROR([XADDQ present but disabled by Fedora patch!])
|
|
||||||
+fi
|
|
||||||
+
|
|
||||||
if test "yes" = "$have_atomic"; then
|
|
||||||
AC_MSG_CHECKING([compiler support for inline assembly code])
|
|
||||||
|
|
||||||
diff --git a/lib/isc/include/isc/platform.h.in b/lib/isc/include/isc/platform.h.in
|
|
||||||
index c902d46..9c7c342 100644
|
|
||||||
--- a/lib/isc/include/isc/platform.h.in
|
|
||||||
+++ b/lib/isc/include/isc/platform.h.in
|
|
||||||
@@ -284,19 +284,25 @@
|
|
||||||
* If the "xaddq" operation (64bit xadd) is available on this architecture,
|
|
||||||
* ISC_PLATFORM_HAVEXADDQ will be defined.
|
|
||||||
*/
|
|
||||||
-@ISC_PLATFORM_HAVEXADDQ@
|
|
||||||
|
|
||||||
/*
|
|
||||||
- * If the 32-bit "atomic swap" operation is available on this
|
|
||||||
- * architecture, ISC_PLATFORM_HAVEATOMICSTORE" will be defined.
|
|
||||||
+ * If the 64-bit "atomic swap" operation is available on this
|
|
||||||
+ * architecture, ISC_PLATFORM_HAVEATOMICSTOREQ" will be defined.
|
|
||||||
*/
|
|
||||||
-@ISC_PLATFORM_HAVEATOMICSTORE@
|
|
||||||
+
|
|
||||||
+#ifdef __x86_64__
|
|
||||||
+#define ISC_PLATFORM_HAVEXADDQ 1
|
|
||||||
+#define ISC_PLATFORM_HAVEATOMICSTOREQ 1
|
|
||||||
+#else
|
|
||||||
+#undef ISC_PLATFORM_HAVEXADDQ
|
|
||||||
+#undef ISC_PLATFORM_HAVEATOMICSTOREQ
|
|
||||||
+#endif
|
|
||||||
|
|
||||||
/*
|
|
||||||
- * If the 64-bit "atomic swap" operation is available on this
|
|
||||||
+ * If the 32-bit "atomic swap" operation is available on this
|
|
||||||
* architecture, ISC_PLATFORM_HAVEATOMICSTORE" will be defined.
|
|
||||||
*/
|
|
||||||
-@ISC_PLATFORM_HAVEATOMICSTOREQ@
|
|
||||||
+@ISC_PLATFORM_HAVEATOMICSTORE@
|
|
||||||
|
|
||||||
/*
|
|
||||||
* If the "compare-and-exchange" operation is available on this architecture,
|
|
||||||
@ -1,31 +1,31 @@
|
|||||||
diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c
|
diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c
|
||||||
index ecb3ddb..f7f73cd 100644
|
index 31549c6..65a14b6 100644
|
||||||
--- a/lib/dns/resolver.c
|
--- a/lib/dns/resolver.c
|
||||||
+++ b/lib/dns/resolver.c
|
+++ b/lib/dns/resolver.c
|
||||||
@@ -1456,7 +1456,7 @@ log_edns(fetchctx_t *fctx) {
|
@@ -1762,7 +1762,7 @@ log_edns(fetchctx_t *fctx) {
|
||||||
*/
|
*/
|
||||||
dns_name_format(&fctx->domain, domainbuf, sizeof(domainbuf));
|
dns_name_format(&fctx->domain, domainbuf, sizeof(domainbuf));
|
||||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_EDNS_DISABLED,
|
isc_log_write(dns_lctx, DNS_LOGCATEGORY_EDNS_DISABLED,
|
||||||
- DNS_LOGMODULE_RESOLVER, ISC_LOG_INFO,
|
- DNS_LOGMODULE_RESOLVER, ISC_LOG_INFO,
|
||||||
+ DNS_LOGMODULE_RESOLVER, ISC_LOG_DEBUG(1),
|
+ DNS_LOGMODULE_RESOLVER, ISC_LOG_DEBUG(1),
|
||||||
"success resolving '%s' (in '%s'?) after %s",
|
"success resolving '%s' (in '%s'?) after %s", fctx->info,
|
||||||
fctx->info, domainbuf, fctx->reason);
|
domainbuf, fctx->reason);
|
||||||
|
}
|
||||||
@@ -4667,7 +4667,7 @@ log_lame(fetchctx_t *fctx, dns_adbaddrinfo_t *addrinfo) {
|
@@ -5298,7 +5298,7 @@ log_lame(fetchctx_t *fctx, dns_adbaddrinfo_t *addrinfo) {
|
||||||
dns_name_format(&fctx->domain, domainbuf, sizeof(domainbuf));
|
dns_name_format(&fctx->domain, domainbuf, sizeof(domainbuf));
|
||||||
isc_sockaddr_format(&addrinfo->sockaddr, addrbuf, sizeof(addrbuf));
|
isc_sockaddr_format(&addrinfo->sockaddr, addrbuf, sizeof(addrbuf));
|
||||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_LAME_SERVERS,
|
isc_log_write(dns_lctx, DNS_LOGCATEGORY_LAME_SERVERS,
|
||||||
- DNS_LOGMODULE_RESOLVER, ISC_LOG_INFO,
|
- DNS_LOGMODULE_RESOLVER, ISC_LOG_INFO,
|
||||||
+ DNS_LOGMODULE_RESOLVER, ISC_LOG_DEBUG(1),
|
+ DNS_LOGMODULE_RESOLVER, ISC_LOG_DEBUG(1),
|
||||||
"lame server resolving '%s' (in '%s'?): %s",
|
"lame server resolving '%s' (in '%s'?): %s", namebuf,
|
||||||
namebuf, domainbuf, addrbuf);
|
domainbuf, addrbuf);
|
||||||
}
|
}
|
||||||
@@ -4685,7 +4685,7 @@ log_formerr(fetchctx_t *fctx, const char *format, ...) {
|
@@ -5316,7 +5316,7 @@ log_formerr(fetchctx_t *fctx, const char *format, ...) {
|
||||||
isc_sockaddr_format(&fctx->addrinfo->sockaddr, nsbuf, sizeof(nsbuf));
|
isc_sockaddr_format(&fctx->addrinfo->sockaddr, nsbuf, sizeof(nsbuf));
|
||||||
|
|
||||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_RESOLVER,
|
isc_log_write(dns_lctx, DNS_LOGCATEGORY_RESOLVER,
|
||||||
- DNS_LOGMODULE_RESOLVER, ISC_LOG_NOTICE,
|
- DNS_LOGMODULE_RESOLVER, ISC_LOG_NOTICE,
|
||||||
+ DNS_LOGMODULE_RESOLVER, ISC_LOG_DEBUG(1),
|
+ DNS_LOGMODULE_RESOLVER, ISC_LOG_DEBUG(1),
|
||||||
"DNS format error from %s resolving %s for %s: %s",
|
"DNS format error from %s resolving %s for %s: %s", nsbuf,
|
||||||
nsbuf, fctx->info, fctx->clientstr, msgbuf);
|
fctx->info, fctx->clientstr, msgbuf);
|
||||||
}
|
}
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Loading…
Reference in New Issue
Block a user