mirror of
https://github.com/NLnetLabs/unbound.git
synced 2026-09-30 21:54:57 +02:00
- Fix for the serve expired DNSSEC information fix, it would not allow
current delegation information be updated in cache. The fix allows current delegation and validation recursion information to be updated, but as a consequence no longer has certain expired information around for later dnssec valid expired responses.
This commit is contained in:
+12
-2
@@ -693,10 +693,11 @@ dns_copy_msg(struct dns_msg* from, struct regional* region)
|
||||
void
|
||||
iter_dns_store(struct module_env* env, struct query_info* msgqinf,
|
||||
struct reply_info* msgrep, int is_referral, time_t leeway, int pside,
|
||||
struct regional* region, uint16_t flags, time_t qstarttime)
|
||||
struct regional* region, uint16_t flags, time_t qstarttime,
|
||||
int is_valrec)
|
||||
{
|
||||
if(!dns_cache_store(env, msgqinf, msgrep, is_referral, leeway,
|
||||
pside, region, flags, qstarttime))
|
||||
pside, region, flags, qstarttime, is_valrec))
|
||||
log_err("out of memory: cannot store data in cache");
|
||||
}
|
||||
|
||||
@@ -1606,3 +1607,12 @@ limit_nsec_ttl(struct dns_msg* msg)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
void
|
||||
iter_make_minimal(struct reply_info* rep)
|
||||
{
|
||||
size_t rem = rep->ns_numrrsets + rep->ar_numrrsets;
|
||||
rep->ns_numrrsets = 0;
|
||||
rep->ar_numrrsets = 0;
|
||||
rep->rrset_count -= rem;
|
||||
}
|
||||
|
||||
+10
-1
@@ -142,6 +142,7 @@ struct dns_msg* dns_copy_msg(struct dns_msg* from, struct regional* regional);
|
||||
* @param region: to copy modified (cache is better) rrs back to.
|
||||
* @param flags: with BIT_CD for dns64 AAAA translated queries.
|
||||
* @param qstarttime: time of query start.
|
||||
* @param is_valrec: if the query is validation recursion and does not get
|
||||
* return void, because we are not interested in alloc errors,
|
||||
* the iterator and validator can operate on the results in their
|
||||
* scratch space (the qstate.region) and are not dependent on the cache.
|
||||
@@ -150,7 +151,8 @@ struct dns_msg* dns_copy_msg(struct dns_msg* from, struct regional* regional);
|
||||
*/
|
||||
void iter_dns_store(struct module_env* env, struct query_info* qinf,
|
||||
struct reply_info* rep, int is_referral, time_t leeway, int pside,
|
||||
struct regional* region, uint16_t flags, time_t qstarttime);
|
||||
struct regional* region, uint16_t flags, time_t qstarttime,
|
||||
int is_valrec);
|
||||
|
||||
/**
|
||||
* Select randomly with n/m probability.
|
||||
@@ -435,4 +437,11 @@ void iterator_set_ip46_support(struct module_stack* mods,
|
||||
*/
|
||||
void limit_nsec_ttl(struct dns_msg* msg);
|
||||
|
||||
/**
|
||||
* Make the response minimal. Removed authority and additional section,
|
||||
* that works when there is an answer in the answer section.
|
||||
* @param rep: reply to modify.
|
||||
*/
|
||||
void iter_make_minimal(struct reply_info* rep);
|
||||
|
||||
#endif /* ITERATOR_ITER_UTILS_H */
|
||||
|
||||
+16
-5
@@ -368,7 +368,7 @@ error_response_cache(struct module_qstate* qstate, int id, int rcode)
|
||||
err.security = sec_status_indeterminate;
|
||||
verbose(VERB_ALGO, "store error response in message cache");
|
||||
iter_dns_store(qstate->env, &qstate->qinfo, &err, 0, 0, 0, NULL,
|
||||
qstate->query_flags, qstate->qstarttime);
|
||||
qstate->query_flags, qstate->qstarttime, qstate->is_valrec);
|
||||
return error_response(qstate, id, rcode);
|
||||
}
|
||||
|
||||
@@ -3296,6 +3296,16 @@ processQueryResponse(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
iq->num_target_queries = 0;
|
||||
return processDSNSFind(qstate, iq, id);
|
||||
}
|
||||
if(iq->qchase.qtype == LDNS_RR_TYPE_DNSKEY && SERVE_EXPIRED
|
||||
&& qstate->is_valrec &&
|
||||
reply_find_answer_rrset(&iq->qchase, iq->response->rep) != NULL) {
|
||||
/* clean out the authority section, if any, so it
|
||||
* does not overwrite dnssec valid data in the
|
||||
* validation recursion lookup. */
|
||||
verbose(VERB_ALGO, "make DNSKEY minimal for serve "
|
||||
"expired");
|
||||
iter_make_minimal(iq->response->rep);
|
||||
}
|
||||
if(!qstate->no_cache_store)
|
||||
iter_dns_store(qstate->env, &iq->response->qinfo,
|
||||
iq->response->rep,
|
||||
@@ -3303,7 +3313,7 @@ processQueryResponse(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
qstate->prefetch_leeway,
|
||||
iq->dp&&iq->dp->has_parent_side_NS,
|
||||
qstate->region, qstate->query_flags,
|
||||
qstate->qstarttime);
|
||||
qstate->qstarttime, qstate->is_valrec);
|
||||
/* close down outstanding requests to be discarded */
|
||||
outbound_list_clear(&iq->outlist);
|
||||
iq->num_current_queries = 0;
|
||||
@@ -3397,7 +3407,7 @@ processQueryResponse(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
/* no prefetch-leeway, since its not the answer */
|
||||
iter_dns_store(qstate->env, &iq->response->qinfo,
|
||||
iq->response->rep, 1, 0, 0, NULL, 0,
|
||||
qstate->qstarttime);
|
||||
qstate->qstarttime, qstate->is_valrec);
|
||||
if(iq->store_parent_NS)
|
||||
iter_store_parentside_NS(qstate->env,
|
||||
iq->response->rep);
|
||||
@@ -3527,7 +3537,8 @@ processQueryResponse(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
iter_dns_store(qstate->env, &iq->response->qinfo,
|
||||
iq->response->rep, 1, qstate->prefetch_leeway,
|
||||
iq->dp&&iq->dp->has_parent_side_NS, NULL,
|
||||
qstate->query_flags, qstate->qstarttime);
|
||||
qstate->query_flags, qstate->qstarttime,
|
||||
qstate->is_valrec);
|
||||
/* set the current request's qname to the new value. */
|
||||
iq->qchase.qname = sname;
|
||||
iq->qchase.qname_len = snamelen;
|
||||
@@ -4154,7 +4165,7 @@ processFinished(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
iq->response->rep, 0, qstate->prefetch_leeway,
|
||||
iq->dp&&iq->dp->has_parent_side_NS,
|
||||
qstate->region, qstate->query_flags,
|
||||
qstate->qstarttime);
|
||||
qstate->qstarttime, qstate->is_valrec);
|
||||
}
|
||||
}
|
||||
qstate->return_rcode = LDNS_RCODE_NOERROR;
|
||||
|
||||
Reference in New Issue
Block a user