Compare commits

...
194 Commits
Author SHA1 Message Date
W.C.A. Wijngaards 8ee0bca833 - Fix stat_values.tdir test to have less test failures. 2026-08-11 10:07:38 +02:00
W.C.A. Wijngaards c58e6add2b - Fix #1492 from zacek: Data race in log_init() on
key_created/log_lock when calling ub_ctx_create()
  concurrently from multiple threads.
2026-08-11 09:42:30 +02:00
W.C.A. Wijngaards 93a56205cf - Fix #1489 from jplesnik: Replace removed Python 2 C API
macros for SWIG 4.5.0 compatibility.
2026-08-07 08:57:32 +02:00
W.C.A. Wijngaards 709f622658 Note issue number in Changlog entry. 2026-08-06 17:15:55 +02:00
akhanin-dnsfandGitHub 307fc6f062 - Fix bounds check in packed_rr_to_string, it checked the (#1488)
assembled rr length against the output string length
  dest_len, instead of against the size of the rr buffer it
  writes into. Callers in cachedump.c and remote.c pass a
  dest_len larger than that buffer.
- Unit test for packed_rr_to_string.
2026-08-06 17:04:05 +02:00
W.C.A. Wijngaards 8b33c5d7ff - Fix #1487: regression in 1.26.0, ipsecmod is now always
partly enabled.
2026-08-06 09:46:18 +02:00
W.C.A. Wijngaards 36bd52afb9 Fix typo in Changelog. 2026-08-06 09:08:33 +02:00
W.C.A. Wijngaards b7d13ff12b - Fix ##1485: the list_forwards command omits port numbers.
The list_forwards and list_stubs commands for
  unbound-control print port and tls auth name.
2026-08-06 09:08:17 +02:00
W.C.A. Wijngaards bdfcfb861f - Fix to set makedist.sh to not wget config.sub and
config.guess from git repo. The fetch times out, and the
  version from libtoolize is much more recent now than
  that it was when the wget was added.
2026-08-04 10:04:34 +02:00
W.C.A. Wijngaards b444deffd2 Note 1.26.0 release. 2026-08-04 10:01:59 +02:00
W.C.A. Wijngaards ff28b7e5cf - For #1483: The failure reason when an NSEC NXDOMAIN is
encountered when looking for an insecure delegation, is
  fixed to mention the NSEC records, instead of nonexistent
  NSEC3 records, that it attempted.
2026-07-31 09:53:47 +02:00
W.C.A. Wijngaards 79b84bbc91 - Fix #1482: DNS-over-QUIC doesn't work with simple config.
That fixes interface-automatic for use with doq service.
2026-07-30 08:24:42 +02:00
W.C.A. Wijngaards cbfc3b0342 - Tag for 1.26.0rc1. The repo continues with version 1.26.1. 2026-07-28 09:45:59 +02:00
W.C.A. Wijngaards a45da353d3 - Fix to call OPENSSL_cleanup on exit when that is defined. 2026-07-24 17:04:38 +02:00
W.C.A. Wijngaards c21e3ee929 Changelog note for #1479
- Merge #1479 from psumbera: Fix pthread detection on
  Solaris 11.4.
2026-07-24 15:35:55 +02:00
8a38bed262 Fix pthread detection on Solaris 11.4 (#1479)
AX_PTHREAD requires _REENTRANT to confirm that pthread support is enabled.
Solaris 11.4 headers no longer use the macro, and GCC 16 therefore no
longer defines it for -pthread.

Detect XPG7 support in the target headers and require _REENTRANT only on
older Solaris releases. The existing pthread compile and link test remains
the final capability check.

This follows the canonical Autoconf Archive change:
https://github.com/autoconf-archive/autoconf-archive/pull/341

Regenerate configure with Autoconf 2.71.

Tested on Solaris 11.4 with GCC 15.2 and GCC 16.1. The Autoconf Archive
change was also tested on Solaris 11.3.

Co-authored-by: Rainer Orth <ro@CeBiTec.Uni-Bielefeld.DE>
2026-07-24 15:34:18 +02:00
W.C.A. Wijngaards 7cc7a43ff6 Changelog note for #1481.
- Fix #1481: Fix to use tls-port after referral if
  tls-upstream is set.
2026-07-24 15:32:20 +02:00
W.C.A. Wijngaards 9bd8df0149 - Fix to use tls-port after referral if tls-upstream is set. 2026-07-24 15:31:06 +02:00
W.C.A. Wijngaards 8f7411057f - Fix sign of comparison warning in shared ports setup. 2026-07-24 14:44:44 +02:00
W.C.A. Wijngaards ca1fe4f82a - Fix to guard access to shared ports interface array during
set up, for analyzer.
2026-07-24 14:38:46 +02:00
W.C.A. Wijngaards e183c2c506 - Fix unused variable warnings in shared_ports_fetch_random
and shared_ports_return_port when compiled without threads.
2026-07-24 14:37:17 +02:00
W.C.A. Wijngaards 52b18fc6f5 Changelog entry for #1480
- Merge #1480 from petrvaganoff: authzone: fix memory leak in
  xfer_set_masters() error path.
2026-07-24 12:25:34 +02:00
Petr VaganovandGitHub e6d00725c2 authzone: fix memory leak in xfer_set_masters() error path (#1480)
Added memory deallocation for the `file` and `host` fields of the
`auth_master` node in the event of a URL/allocation error, and
unlinked the partially created node from the masters list by
resetting the link that pointed to it.

Signed-off-by: Petr Vaganov <petrvaganoff@gmail.com>
2026-07-24 12:24:49 +02:00
W.C.A. Wijngaards e597711824 - Fix lock test protect for auth zone change.
- Fix to lock shared_ports structure during initialisation.
- Fix to lock anchor structure when file is set for it in
2026-07-24 12:13:09 +02:00
W.C.A. Wijngaards e1e646c6fc - Fix to allow test fake sha1 on systems with possible sha1
support.
- Fix to use sha256 for unbound-anchor unit test.
- Fix unbound-anchor check for return value of
  X509_NAME_get_text_by_NID of the emailaddress.
2026-07-24 11:50:15 +02:00
W.C.A. Wijngaards fc3b5b4f63 - Update generated man pages. 2026-07-24 10:03:41 +02:00
W.C.A. Wijngaards 1e904a3ce5 - set code repository version to 1.26.0. 2026-07-24 09:45:49 +02:00
W.C.A. Wijngaards 79e100a7fb - Fix #1477: respip + dns64: dns64 uses A records modified by
respip instead of original A records. Adds local-zone types
  block_a_wdata and block_aaaa_wdata, that are like block_a
  and block_aaaa, and uses local-data if present.
2026-07-24 09:29:17 +02:00
W.C.A. Wijngaards a65d3d7283 - Unit test for block_a and block_aaaa. 2026-07-24 09:03:45 +02:00
W.C.A. Wijngaards 3b8766aa43 Changelog note for #1433
- Merge #1433 from jisakiel: Add new static zone type
  block_aaaa to suppress AAAA queries.
2026-07-24 08:53:30 +02:00
c8b3c89a39 Add new static zone type block_aaaa to suppress AAAA queries (#1433)
Following d5b9a790f lead for block_a - this would allow suppressing AAAA queries instead for sticking to IPV4.

Co-authored-by: Jisakiel <jisakiel@users.noreply.github.com>
2026-07-24 08:52:20 +02:00
W.C.A. Wijngaards a05d460e66 - Fix mesh cycle detection for configuration with respip CNAME
loop and tagged clients. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-07-23 16:28:45 +02:00
W.C.A. Wijngaards 5eb362a6c0 - Fix that the aggressive negative cache does not insert NSEC
records with overreaching next owner name. Also the result
  is not above the trust anchor's bailiwick. Also RRSIGS are
  not considered valid when an NSEC next owner name is not
  under the signer zone name. Thanks to Qifan Zhang, Palo
  Alto Networks, for the report.
2026-07-23 16:17:59 +02:00
W.C.A. Wijngaards 0735cb28d1 - Fix that for NSEC3 proofs the NSEC3 zone, as the b32.name is
checked to be the same as the signer name. Also RRSIGs are
  not considered valid when an NSEC3 is not b32.signerzone.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-07-23 15:54:59 +02:00
W.C.A. Wijngaards 737c28e836 Changelog entry for #1478
- Merge #1478 from petrvaganoff: pythonmod: add check return
  value after ftell().
2026-07-23 10:22:53 +02:00
Petr VaganovandGitHub 1bab2dfafa pythonmod: add check return value after ftell() (#1478)
Variable 'flen', which might receive a negative value at pythonmod.c:493
by calling function 'ftell', is used without checking at pythonmod.c:508
by calling function 'fread'.

Found by the static analyzer Svace (ISP RAS).

Signed-off-by: Petr Vaganov <petrvaganoff@gmail.com>
2026-07-23 10:22:02 +02:00
W.C.A. Wijngaards 22e2c5b6d1 - Updated credits for Xuanchao Xie in 22 july changelog. 2026-07-23 10:01:10 +02:00
W.C.A. Wijngaards 914dbfea4e - iana portlist update. 2026-07-22 14:12:34 +02:00
W.C.A. Wijngaards cf5e6e89a5 - Fix error in log printout in fix for CVE-2026-50248, when the
primary name is bogus.
2026-07-22 12:16:49 +02:00
W.C.A. Wijngaards 4941edf275 - Unit test for CVE-2026-56416. 2026-07-22 12:06:00 +02:00
W.C.A. Wijngaards b08723ef97 - Unit test for CVE-2026-55973. 2026-07-22 12:04:35 +02:00
W.C.A. Wijngaards c163fbc505 - Unit test for CVE-2026-55717. 2026-07-22 12:03:48 +02:00
W.C.A. Wijngaards eed3f1ab38 - Unit test for CVE-2026-50248. 2026-07-22 12:00:19 +02:00
W.C.A. Wijngaards 63501f51bb - Unit test for CVE-2026-50243. 2026-07-22 11:59:36 +02:00
W.C.A. Wijngaards 1ae2570bda - Unit test for CVE-2026-46582. 2026-07-22 11:58:18 +02:00
W.C.A. Wijngaards 9ad825b267 - Unit test for CVE-2026-50045. 2026-07-22 11:57:13 +02:00
W.C.A. Wijngaards 3d5e6c0692 - Unit test for CVE-2026-44690. 2026-07-22 11:56:08 +02:00
W.C.A. Wijngaards 23e19ca6fc - Unit test for CVE-2026-44687. 2026-07-22 11:55:09 +02:00
W.C.A. Wijngaards 9f757aa9f3 - Unit test for CVE-2026-42955. 2026-07-22 11:54:00 +02:00
W.C.A. Wijngaards 1df6c170ff Changelog entry for 1.25.2.
- Set the repository to 1.25.3, it continues with the previous
  changes.
2026-07-22 11:38:48 +02:00
W.C.A. Wijngaards 7a95bedc26 Fix conflict merge fixup. 2026-07-22 11:36:06 +02:00
W.C.A. Wijngaards ae685bc33d Move repo to version 1.25.3. 2026-07-22 11:34:48 +02:00
W.C.A. Wijngaards 91ac449bcd Merge branch 'branch-1.25.2' 2026-07-22 11:33:54 +02:00
W.C.A. Wijngaards 25b2543e5e Changelog note for #1476
- Merge #1476 from petrvaganoff: ipsecmod: fix possible deref
  on null after reply_find_answer_rrset().
2026-07-21 11:57:14 +02:00
Petr VaganovandGitHub 7133e0d32a ipsecmod: fix possible deref on null after reply_find_answer_rrset() (#1476)
Return value of a function 'reply_find_answer_rrset' is dereferenced at
ipsecmod.c:438 without checking for NULL, but it is usually checked for
this function (10/12).

Found by the static analyzer Svace (ISP	RAS).

Signed-off-by: Petr Vaganov <petrvaganoff@gmail.com>
2026-07-21 11:56:29 +02:00
W.C.A. Wijngaards fac7584830 - Fix #1474: DoQ responses are never padded - pad-responses
does not apply to comm_doq (RFC 9250 §5.4 MUST).
2026-07-20 10:14:26 +02:00
W.C.A. Wijngaards 87f9258fb4 Changelog entry for #1475
- Merge #1475 from petrvaganoff: ipsecmod: fix deref on null
  in ipsecmod-whitelist after OOM.
2026-07-20 10:05:45 +02:00
Petr VaganovandGitHub a2fe5356b5 ipsecmod: fix deref on null in ipsecmod-whitelist after OOM (#1475)
DEREF_OF_NULL.RET.STAT Return value of a function 'rbtree_create'
is dereferenced at ipsecmod-whitelist.c:105 without checking for
NULL, but it is usually checked for this function (5/6).

In ipsecmod_whitelist_apply_cfg(), the return value of rbtree_create()
is not checked for NULL before being used.

Found by the static analyzer Svace (ISP	RAS).

Signed-off-by: Petr Vaganov <petrvaganoff@gmail.com>
2026-07-20 10:04:47 +02:00
W.C.A. Wijngaards ad9b12a863 - Fix unit test for malformed svcb for test on Windows. 2026-07-09 09:52:09 +02:00
W.C.A. Wijngaards 61ca4111a1 Changelog note and explanation comment for #1383
- Merge #1383 from jdek: Fix randomness generation on
  macOS/iOS under chroot.
2026-07-09 09:21:56 +02:00
J. DekkerandGitHub 71a971d70c - Fix randomness generation on macOS/iOS under chroot (#1383)
SecRandomCopyBytes() has existed since macOS 10.7 (2011) and iOS 2.0 (2008), and is the primary API for cryptographic random numbers.
2026-07-09 09:19:42 +02:00
W.C.A. Wijngaards ba4f8478e6 Add changelog note for #1087, remove copyright line as discussed, and
compile fixes for newer local_zones_lookup, unused variable warnings
fixed, and also manual page description of the feature.
- Merge #1087: Overload `local_data_remove` to support removing
  specific records.
2026-07-02 15:04:51 +02:00
R. Christian McDonaldandGitHub 374a18cc5b Overload local_data_remove to support removing specific records (#1087)
Here we overload the `local_data_remove` control command to support
deleting specific records. Curently, this command deletes all records
for a given zone. The modification works by attempting to parse the
command argument first as a complete record and then as just a domain
name, if the first attempt failed.

This preserves the command's behavior, while also supporting removing
specific records from the zone tree.

Signed-off-by: R. Christian McDonald <rcm@rcm.sh>
2026-07-02 14:55:54 +02:00
W.C.A. Wijngaards f35561287a - iana portlist updated. 2026-06-30 12:38:33 +02:00
W.C.A. Wijngaards 672b9659cf - Fix #1469: dohclient: DoH POST missing content-length → :status
400 from strict resolvers (Cloudflare, Mullvad).
2026-06-30 12:14:00 +02:00
W.C.A. Wijngaards 1978add0cd - Merge #1467: daemon: fix DEREF_AFTER_NULL.EX.COND on
worker_init. This fixes error handling if the worker
  stat_timer allocation has an out of memory error. That
  makes the server not crash later, attempting to use it.
2026-06-26 13:44:27 +02:00
Petr VaganovandGitHub 6cbcea3ac7 daemon: fix DEREF_AFTER_NULL.EX.COND on worker_init (#1467)
Found by the static analyzer Svace (ISP RAS).

After having been compared to a NULL value at worker.c:2216,
pointer 'worker->stat_timer' is passed in call to function
'worker_restart_timer' at worker.c:2319,where it is
dereferenced at worker.c:2029.

Fix that stat_timer creation failure in worker_init does
not continue with a NULL timer that causes a crash later.

Signed-off-by: Petr Vaganov <petrvaganoff@gmail.com>
2026-06-26 13:42:29 +02:00
W.C.A. Wijngaards 65e23d4b6f - Merge #1465 from dag-erling: Add libunbound/remote.h. Add
a shared header containing prototypes for functions that
  both ends of a remote control connection need to implement.
2026-06-25 11:16:01 +02:00
Dag-Erling SmørgravandGitHub fbe41cdef9 Add libunbound/remote.h (#1465)
Add a shared header containing prototypes for functions that both ends
of a remote control connection need to implement.
2026-06-25 11:14:37 +02:00
W.C.A. Wijngaards 01a95108b3 - Fix warning about file_string_matches in unbound-checkconf. 2026-06-19 09:30:46 +02:00
W.C.A. Wijngaards f75d11821f - Fix to update github ci actions/checkout to v7. 2026-06-19 09:25:39 +02:00
W.C.A. Wijngaards 6aa5cfc903 - Fix for #1457: fix thread setname for thread start of
dnstap, and fast_reload.
2026-06-19 08:37:23 +02:00
Yorgos Thessalonikefs f6931c794e - Fix memory leak on DNAME 0TTL records. 2026-06-17 17:30:21 +02:00
W.C.A. Wijngaards 4c5082ad05 - Fix that fast_reload does not terminate the server if
random init for DNS cookies fails. The data is only random
  generated if cookies are enabled, and the random data
  is necessary. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-06-17 16:15:15 +02:00
W.C.A. Wijngaards 5fb892a097 - Fix that fast_reload does not terminate the server
on config read failure after malloc failure. Thanks to
  Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 16:10:48 +02:00
W.C.A. Wijngaards 55e9532d16 - Fix after malloc failure for stats, then it drains the pipe
so the internal messaging stays correct. Also it does
  not exit the server if stats pipe communication fails.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 16:05:45 +02:00
W.C.A. Wijngaards fff6657cea - Fix that fast_reload does not terminate the server
on malloc failure for dnstap, or if gethostname fails.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 16:02:21 +02:00
W.C.A. Wijngaards 45d1e75caf - Fix to check for malloc failure in rpz response create,
for nodata and nxdomain, so it does not crash later.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 15:59:29 +02:00
W.C.A. Wijngaards b806f16c8b - Fix to check the return value of auth_xfer_create
during fast_reload auth-zone add and change processing.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 15:57:30 +02:00
W.C.A. Wijngaards 8d3348c71b - Fix that malloc failure during edns subnet addrtree
insert is checked, so it does not crash later. Thanks to
  Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 15:55:33 +02:00
W.C.A. Wijngaards e2cc14681e - Fix that malloc failure for rpz_strip_nsdname is
checked and handled, so that it does not crash later.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 15:53:28 +02:00
W.C.A. Wijngaards 5ae979bb6e - Fix that on malloc failure during accept of TCP, the
socket is not left to cause a read event loop. It uses
  slow-accept to delay accepting new connections, if
  that fails it drops the new connections. When the tcp
  connection usage is full, it waits for 50msec, to allow
  existing queries to be resolved. Thanks to Qifan Zhang,
  Palo Alto Networks, for the report.
2026-06-17 15:37:04 +02:00
W.C.A. Wijngaards 8f2fbd66fc - Fix that malloc failure for ngtcp2_conn_server_new
cleans up reference that older ngtcp2 versions can leave.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 15:33:06 +02:00
W.C.A. Wijngaards b5909d8d22 - Fix that malloc failure in doq connection setup, does
not crash in doq connection delete later. Thanks to Qifan
  Zhang, Palo Alto Networks, for the report.
2026-06-17 15:29:48 +02:00
W.C.A. Wijngaards fa8e94f155 - Fix that malloc failure for new_local_rrset for RPZ qname
trigger RR insert does not crash. It does not link a
  partial RRset, and logs an error on failure, and cleans
  up the dname allocation. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-06-17 15:26:56 +02:00
W.C.A. Wijngaards cb5683aeae - Fix that malloc failure in dns64_inform_super does
not set up a half-built reply for cache store, that could
  lead to a crash. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-06-17 15:23:25 +02:00
W.C.A. Wijngaards c9715724ec - Fix that unbound-control auth_zone_reload stops the
server answering from the zone after a failure to read.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 15:20:22 +02:00
W.C.A. Wijngaards 78d9cfffd8 - Fix that malloc failure in auth-zone insert rr does
not create an empty node and does not cause an infinite
  loop. Thanks to Qifan Zhang, Palo Alto Networks, for
  the report.
2026-06-17 15:16:21 +02:00
W.C.A. Wijngaards b47b1d048d - Fix that unbound-checkconf checks if an auth-zone download
can overwrite another file, by filename collision.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 15:11:42 +02:00
W.C.A. Wijngaards 740952fb82 - Fix to remove debug from auth_transfer_limit test. 2026-06-17 11:38:24 +02:00
W.C.A. Wijngaards 5c550f4548 - Fix that after fast_reload the disown of the auth zone
transfer task cleans the chunk list. Also fix the
  auth_transfer_limit test to use a forwarder for each type
  of failure, so the one is not blocked by the other waiting.
2026-06-17 11:37:06 +02:00
W.C.A. Wijngaards 3d78cb8d9a - Fix for #1462: Fix that auth primary host name lookup
allows CNAMEs.
2026-06-16 11:13:47 +02:00
W.C.A. Wijngaards 1ab75c0043 - Fix after malloc failure the rrset_insert_rr in
localzone processing, during RPZ qname trigger processing,
  the RRset retains its previous data correcly. Thanks to
  Qifan Zhang, Palo Alto Networks, for the report.
2026-06-16 10:59:37 +02:00
W.C.A. Wijngaards bebc8d516b - Fix incorrect cleanup after an allocation failure for
a delegation point in a region. Thanks to Qifan Zhang,
  Palo Alto Networks, for the report.
2026-06-16 10:56:36 +02:00
W.C.A. Wijngaards a7debe7ff6 - Fix that after shared memory cannot be created, from
`shm-enable`, the server does not crash. Thanks to Qifan
  Zhang, Palo Alto Networks, for the report.
2026-06-16 10:53:40 +02:00
W.C.A. Wijngaards 215e3920ef - Fix that after malloc failure in find_tag_datas, the
local_alias is cleaned up. Thanks to Qifan Zhang, Palo
  Alto Networks, for the report.
2026-06-16 10:51:49 +02:00
W.C.A. Wijngaards aabf28aef5 - Fix incorrect cleanup after an allocation failure for
a delegation point. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-06-16 10:49:50 +02:00
W.C.A. Wijngaards aa09835c90 - Fix for neater solution to clear log thread id after
worker init failure. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-06-16 10:48:17 +02:00
W.C.A. Wijngaards 9b9e13b665 - Fix that libunbound pipe functions fail with error after
an event base is set. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-06-16 10:44:41 +02:00
W.C.A. Wijngaards f72e11ef5b - Fix locking in libunbound ub_ctx_set_event call.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-16 10:42:39 +02:00
W.C.A. Wijngaards a45e54555d - Fix that dnscrypt configuration does not crash, due to
inconsistency between secret and public keys. Also
  duplicate files are skipped. Thanks to Qifan Zhang, Palo
  Alto Networks, for the report.
2026-06-16 10:40:10 +02:00
W.C.A. Wijngaards 4693c00c9f - Fix that after malloc failure in RPZ load a half built
list does not crash later. The newly created RRset is
  linked after creation has succeeded. Thanks to Qifan Zhang,
  Palo Alto Networks, for the report.
2026-06-16 10:35:41 +02:00
W.C.A. Wijngaards 8fe23e0297 - Fix that for a zonefile only zone, if that file does not
exist on server start, the server continues to start with
  a warning log message. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-06-16 10:26:25 +02:00
W.C.A. Wijngaards 8557788699 - Fix that after malloc failure a half-built local_alias does
not crash the server. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-06-16 10:12:19 +02:00
W.C.A. Wijngaards 81a19ebeb3 - Fix that a signed wildcard NSEC, is checked before use,
so it does not allow insecure DS proofs inappropriately.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-16 10:09:00 +02:00
W.C.A. Wijngaards 299df5ec77 - Fix that dns64 does not ignore the forward-no-cache and
`stub-no-cache` options. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-06-16 09:52:46 +02:00
W.C.A. Wijngaards 6f9b6db7be - Fix that auth-zone, and RPZ zones, do not allow out-of-zone
records. These are records that are not under the zone apex.
  The out-of-zone records are dropped from the zone contents.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-16 09:48:10 +02:00
W.C.A. Wijngaards 96f15b9160 - Fix that a half-written trust anchor file does not crash
the server at runtime. It unlinks a wrong file from the list.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-16 09:45:10 +02:00
W.C.A. Wijngaards 159384c2a9 - Fix that when SVCB records cannot be written out, and
are written in unknown format, that the zone read allows
  such unknown format SVCB records. Thanks to Qifan Zhang,
  Palo Alto Networks, for the report.
2026-06-16 09:36:33 +02:00
W.C.A. Wijngaards 621fc91453 - Fix to disallow $INCLUDE for secondary zones. Start up
of server continues if a secondary zone fails to load.
  Failed loads clear the zone data, so there is no partial
  zone. Thanks to Qifan Zhang, Palo Alto Networks, for
  the report.
2026-06-16 09:30:52 +02:00
W.C.A. Wijngaards 543c49f76c - Fix that dns64 bypasses rpz-passthru rule during
synthesis. This restricted more than necessary. Thanks to
  Qifan Zhang, Palo Alto Networks, for the report.
2026-06-15 16:50:42 +02:00
W.C.A. Wijngaards d0a760a587 - Fix misconfigured ipsecmod hook causing path name
similarity with other file. The ipsecmod is changed for
  exec of the hook. The ipsecmod hook, if a script, has to
  start now with a line like `#!/bin/sh`. Thanks to Qifan
  Zhang, Palo Alto Networks, for the report.
2026-06-15 16:45:53 +02:00
W.C.A. Wijngaards f68cca4097 - Fix DNAME synthesis from cache that keeps use of 0TTL
entries in a sliding window. It did not surpass RRSIG
  expiry. Thanks to Qifan Zhang, Palo Alto Networks, for
  the report.
2026-06-15 16:39:34 +02:00
W.C.A. Wijngaards 3129357874 - Fix log of an aliased qname, to not use freed region
memory. Thanks to Qifan Zhang, Palo Alto Networks, for
  the report.
2026-06-15 16:34:17 +02:00
W.C.A. Wijngaards fc09352df6 - Fix that fast_reload does not terminate the server for
errors in config, for key files. Thanks to Qifan Zhang,
  Palo Alto Networks, for the report.
2026-06-15 16:31:37 +02:00
W.C.A. Wijngaards 06da5d45a3 - Fix integer overflow for very high values of
`sock-queue-timeout`. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-06-15 16:28:30 +02:00
W.C.A. Wijngaards 69524cadad - Fix erroneous DNS error report values after bogus AAAA
query caused error information that was not cleared by
  a successful A subquery. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-06-15 16:26:35 +02:00
W.C.A. Wijngaards 98e95d80e6 - Fix integer overflow in infra-cache-max-rtt calculation.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-15 16:22:50 +02:00
W.C.A. Wijngaards 2f8aa8a43a - Fix for fast_reload that removes an auth zone while its
lookups are in progress, for a primary name. Also after the
  change, it no longer picks up the old results. Thanks to
  Qifan Zhang, Palo Alto Networks, for the report.
2026-06-15 16:18:56 +02:00
W.C.A. Wijngaards 56e60e37ae - Fix that fast_reload when a zonemd verification lookup
it in progress with subnet loaded, deregisters the
  callback. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-06-15 16:16:50 +02:00
W.C.A. Wijngaards 8f5348ab47 - Fix that misconfigured iter-scrub-ns: 0 causes request
failures. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-06-15 16:04:24 +02:00
W.C.A. Wijngaards c5d693b21c - Fix buffer overflow when configured with lower than
default size and http transfer. Thanks to Qifan Zhang,
  Palo Alto Networks, for the report.
2026-06-15 16:01:51 +02:00
W.C.A. Wijngaards 27e3ac55b9 - Fix assertion failure for long HTTP header that fills
buffer. Thanks to Qifan Zhang, Palo Alto Networks, for
  the report.
2026-06-15 15:54:37 +02:00
W.C.A. Wijngaards 7879218773 Fix comment. 2026-06-15 15:53:00 +02:00
W.C.A. Wijngaards 1354624ba4 - Fix perform a full transfer every number of incremental
transfers, to stop increasing memory usage, for auth-zone
  and rpz zones. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-06-15 15:51:03 +02:00
W.C.A. Wijngaards 153f8d5353 - Fix to add max-transfer-size and max-transfer-time that
limit auth-zone and rpz transfer amount and time taken.
  Default is disabled. This hardens against unbounded
  transfers. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-06-15 15:45:03 +02:00
W.C.A. Wijngaards a1cecf7462 - Fix that for auth-zone and rpz zones the allow-notify
addresses and netblocks are available from start, and
  fix the probe step skip.
2026-06-12 11:48:14 +02:00
W.C.A. Wijngaards e2dac8a00a - Fix compile for OpenSSL 1.0.2 and before in server cleanup. 2026-06-11 17:31:19 +02:00
W.C.A. Wijngaards ecd41bef27 - Fix #1437: Fix compile with OpenSSL 4.0.1. 2026-06-11 17:31:01 +02:00
W.C.A. Wijngaards fd2131687a - Fix for #1306: configure checks if the ngtcp2_crypto_ossl
header file is available, and prints an error otherwise.
2026-06-11 11:43:46 +02:00
W.C.A. Wijngaards 316b9ab4fc - Fix for #1306: configure detects specifically the call to
SSL_set_quic_tls_early_data_enabled and
  SSL_set_quic_early_data_enabled, so the correct one is used.
2026-06-11 11:04:50 +02:00
W.C.A. Wijngaards d45daaf313 - Fix warnings with gcc in compat/inet_pton.c. 2026-06-10 16:43:41 +02:00
W.C.A. Wijngaards db1c6d6557 - Fix pythonmod script read for numeric overflow. 2026-06-10 11:24:02 +02:00
W.C.A. Wijngaards e7a713a525 - Fix unit test for ecs to check for malloc success. 2026-06-09 16:41:37 +02:00
Alex BandandGitHub 39e67508c9 change mailing list to forum 2026-06-08 21:48:04 +02:00
W.C.A. Wijngaards 3eab974ca2 - Fix that dns64 cleans up the allocated message if the adjust
routines fail, and checks if there is a reply before cache
  store, also unbound checks if A and AAAA are malformed
  for auth-zones. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-06-03 14:56:20 +02:00
W.C.A. Wijngaards b1d1dcb3b6 - Fix that dump_cache has a larger buffer for records,
and it checks that an owner name does not collide with BADRR
  on the input, and changes verbosity on the log of failure in
  rrset to string.  Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-06-03 14:51:16 +02:00
W.C.A. Wijngaards 10cb62aca2 - Fix that validation canonicalization of domain names
in rdata checks for buffer bounds. Thanks to Qifan Zhang,
  Palo Alto Networks, for the report.
2026-06-03 14:48:06 +02:00
W.C.A. Wijngaards 6da73aba38 - Fix fast_reload for when a ZONEMD lookup is in progress.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-03 14:42:47 +02:00
W.C.A. Wijngaards 1b1b9626ee - Fix negative cache NSEC3 nodata proof, to use the correct
message size. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-06-03 14:40:17 +02:00
W.C.A. Wijngaards 8bc074043a - Fix PROXYv2 header read and consume, it checks the header
size. Thanks to Qifan Zhang, Palo Alto Networks for
  the report.
2026-06-03 14:37:37 +02:00
W.C.A. Wijngaards 04a6322aa4 - Fix ipset module to use larger domain name buffers, and
check buffer lengths. Thanks to Qifan Zhang, Palo Alto
  Networks for the report.
2026-06-03 14:35:06 +02:00
W.C.A. Wijngaards 5748f518d1 - Fix that quotation and escaping works the same in auth-zone
url content, as in the zonefile read. Thanks to Qifan Zhang,
  Palo Alto Networks for the report.
2026-06-03 14:32:14 +02:00
W.C.A. Wijngaards d05eff4d54 - Fix parse of svcbparam ech, it had incorrect length. Thanks
to Qifan Zhang, Palo Alto Networks for the report.
2026-06-03 14:05:48 +02:00
Yorgos Thessalonikefs 4544eaa4cc - Fix const as reported by newest compiler warnings. 2026-06-03 14:00:04 +02:00
W.C.A. Wijngaards 5d0770d0ad - Fix negative cache to work with NSEC3 records without salt.
Thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern
  Polytechnical University, for the report.
2026-06-03 13:56:31 +02:00
W.C.A. Wijngaards 7f4beb846e - Fix that the processing of class responses does not have
a heap use-after-free. That could happen if at least two
  distinct classes are configured for resolution. Thanks
  to Qifan Zhang, Palo Alto Networks for the report.
  In addition, thanks to Xin Wang, Jiapeng Li, and Jiajia
  Liu, Northwestern Polytechnical University, for also
  reporting this.
2026-06-03 12:14:30 +02:00
W.C.A. Wijngaards 8e8c04e1b9 - Fix unit test to check for new icannbundle.pem. 2026-05-29 12:10:40 +02:00
W.C.A. Wijngaards bf0da2ed21 - Update icannbundle.pem certificates in unbound-anchor. It
has the public keys for 2009 to 2029 and for 2025 to 2045.
2026-05-29 12:10:07 +02:00
W.C.A. Wijngaards 670ece06df - iana portlist updated. 2026-05-29 11:54:40 +02:00
W.C.A. Wijngaards 9e41903be8 - Fix header_seen detection for trust anchor files, so that it
detects the id line.
2026-05-29 11:54:03 +02:00
W.C.A. Wijngaards 57f92cc97e - Fix #1457: race condition causes segfault when starting
threads.
2026-05-28 09:34:04 +02:00
W.C.A. Wijngaards c0741ccc68 - Fix analyzer warning in mesh_new_client. 2026-05-27 16:03:15 +02:00
W.C.A. Wijngaards fb2745024a - Fix that validator caps number of ANY RRsets it can
validate, and the wait timer is shortened. Thanks to Qifan
  Zhang, Palo Alto Networks, for the report.
2026-05-27 13:38:10 +02:00
W.C.A. Wijngaards 0c15ddd133 - Fix ipset module for name too long checks, race conditions
on local name buffer, and for socket close race condition.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-05-27 13:34:32 +02:00
W.C.A. Wijngaards b53504049c - Fix that dns64 with subnetcache does not write ECS scoped
answers to global cache. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-05-27 13:31:11 +02:00
W.C.A. Wijngaards a5324e58eb - Fix, in depth, for respip rewrite of dns64 responses. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
2026-05-27 13:28:41 +02:00
W.C.A. Wijngaards 963cd68535 - Fix manual to document ratelimit, that it is for target
nameservers for a domain, and keeps queries limited. Thanks
  to Qifan Zhang, Palo Alto Networks, for the report.
2026-05-27 13:24:44 +02:00
W.C.A. Wijngaards 047df73887 - Fix to decrement the per-netblock tcp connection limits, so
it keeps usable. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-05-27 13:20:35 +02:00
W.C.A. Wijngaards d2e1ea7d19 - Fix to reset the tcp-timeout before applying a load based
reduction. Thanks to Qifan Zhang, Palo Alto Networks, for the
  report.
2026-05-27 13:17:35 +02:00
W.C.A. Wijngaards fbbe95ba5b - Fix that msgencode insert_query has the correct assertion,
for a local_alias. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-05-27 12:20:04 +02:00
W.C.A. Wijngaards 758c649611 - Fix that the ratelimit is decremented on successful
referrals. Thanks to Qifan Zhang, Palo Alto Networks, for
  the report.
2026-05-27 12:16:23 +02:00
W.C.A. Wijngaards a23f95f620 - Fix to limit the DSNS per-label walk in the iterator. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
2026-05-27 12:12:39 +02:00
W.C.A. Wijngaards 5363570df0 - Fix for autotrust state-file line overflow, that can give
hold-down bypass. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-05-27 12:09:01 +02:00
W.C.A. Wijngaards 368857a45b - Fix for mesh new client and mesh new callback to rollback the
added address, tcp mesh state and callback when there is a failure
  to initialize. This fixes the mesh accounting of reply addresses.
  Thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern
  Polytechnical University, for the report
2026-05-26 16:20:11 +02:00
W.C.A. Wijngaards 40b16d0565 - Fix for signed same-owner CNAME and ordinary RRset responses.
Thanks to Xin Wang and Jiajia Liu, Northwestern Polytechnical
  University, for the report.
2026-05-20 16:30:37 +02:00
W.C.A. Wijngaards 08e901a1ac - Fix cleaning up DoH session. The same query can be on multiple
streams in a session. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-05-20 15:04:12 +02:00
W.C.A. Wijngaards bc703c9129 - Fix lame server detection, for selfpointed glue records.
Thanks to Shuhan Zhang, Dan Li, and Baojun Liu from Tsinghua
  University for the report.
2026-05-20 15:01:42 +02:00
W.C.A. Wijngaards 9ce52de6c1 - Fix in depth for serve-expired responses from cachedb, that it
does not store bogus. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-05-20 14:58:26 +02:00
W.C.A. Wijngaards b3aa262477 Remove the debug file. 2026-05-20 12:43:08 +02:00
W.C.A. Wijngaards 25e112c674 - Unit test for CVE-2026-44390. 2026-05-20 12:42:04 +02:00
W.C.A. Wijngaards 0d2282d551 - Unit test for CVE-2026-42960. 2026-05-20 12:40:32 +02:00
W.C.A. Wijngaards b5f21f4165 - Unit test for CVE-2026-40622. 2026-05-20 12:37:17 +02:00
W.C.A. Wijngaards d357935f66 - Unit test for CVE-2026-42959. 2026-05-20 12:35:38 +02:00
W.C.A. Wijngaards 9d2e0f1c02 - Unit test for CVE-2026-42944. 2026-05-20 12:34:16 +02:00
W.C.A. Wijngaards b46ff5c18e - Unit test for CVE-2026-33278. 2026-05-20 12:32:43 +02:00
W.C.A. Wijngaards f597105800 - Tag for 1.25.1 release, it contains the security fixes on 1.25.0.
the code repository continues with in addition the previous fixes,
  for 1.25.2.
2026-05-20 11:31:53 +02:00
W.C.A. Wijngaards 3692517a41 Merge branch 'branch-1.25.1' 2026-05-20 11:19:56 +02:00
W.C.A. Wijngaards a58bd6cb1e - Fix for mixed class referrals, the resolver uses the query
class. Thanks to Xin Wang and Jiajia Liu, Northwestern
  Polytechnical University, for the report.
2026-05-18 16:42:39 +02:00
W.C.A. Wijngaards 4bad944ae4 - Fix DNSKEY size calculation for noncanonical RSA DNSKEYs
with leading zeroes for n. Thanks to Xin Wang and Jiajia Liu,
  Northwestern Polytechnical University, for the report.
2026-05-15 16:22:59 +02:00
W.C.A. Wijngaards 594182f109 - Fix DNSSEC validation with libnettle for noncanonical RSA
DNSKEYs with leading zeroes for n. Thanks to Xin Wang and
  Jiajia Liu, Northwestern Polytechnical University, for
  the report.
2026-05-15 16:20:52 +02:00
W.C.A. Wijngaards 53c261cb33 - Fix for allocation-failure hardening of rrset cache wildcard
storage and canonical NSEC owner replacement. Thanks to Xin
  Wang and Jiajia Liu, Northwestern Polytechnical University,
  for the report.
2026-05-15 16:00:58 +02:00
W.C.A. Wijngaards 8703d9a5be - Fix that for dns64 answers, the AAAA query is checked to be
DNSSEC validated, when DNSSEC is enabled. This improves
  the RFC6147 conformance of Unbound. Thanks to Xin Wang
  and Jiajia Liu, Northwestern Polytechnical University, for
  the report. In addition, thanks to Qifan Zhang, Palo Alto
  Networks, for reporting it.
2026-05-15 15:43:18 +02:00
W.C.A. Wijngaards aa9f1e68ff - Fix val_find_DS for robustness, to check the result of
packet_rrset_copy_region before using it. Thanks to Xin Wang
  and Jiajia Liu, Northwestern Polytechnical University, for
  the report.
2026-05-15 14:27:18 +02:00
W.C.A. Wijngaards 84a4f556b1 Merge branch 'master' of github.com:NLnetLabs/unbound 2026-05-15 08:42:40 +02:00
W.C.A. Wijngaards 5b166dbf0a - Fix man page entry for so-sndbuf, it is for responses sent out. 2026-05-15 08:42:27 +02:00
Yorgos Thessalonikefs 9e2233b821 - Fix another comment for EDNS fallback buffer size. 2026-05-14 13:11:17 +02:00
Yorgos Thessalonikefs 13716dc8be - Fix comment and verbose logging for EDNS fallback buffer size. 2026-05-11 20:39:38 +02:00
W.C.A. Wijngaards 8ada1bd88d - Fix to relax assertions after the TTL 0 handling change.
This relaxes an assertion in cachedb (it fails instead),
  and for packet_rrset_copy_region.
2026-05-08 10:09:41 +02:00
W.C.A. Wijngaards 9c80bb9fb0 - Fix to clean up log ids after a failure to start a worker thread. 2026-05-07 14:42:29 +02:00
W.C.A. Wijngaards 33e2863862 - Fix for Heap Out-of-Bounds Write via size_t-to-int Truncation
in setup_if() - outside_network_create(). This fixes that
  large values for num_ports do not overflow and create
  invalid references after integer truncation. Thanks
  to Karnakar Reddy (@karnakarreddi) for the report.
2026-05-07 14:40:48 +02:00
W.C.A. Wijngaards 027e23a11d - iana portlist updated. 2026-05-01 11:25:49 +02:00
W.C.A. Wijngaards 62e8db1c6a - Fix windows 64bit build for libssp dependency. 2026-04-29 15:06:09 +02:00
W.C.A. Wijngaards 581b2f31bc - tag for 1.25.0. The code repository continues with 1.25.1 in
development.
2026-04-29 12:10:23 +02:00
190 changed files with 16212 additions and 1149 deletions
+1 -1
View File
@@ -173,7 +173,7 @@ jobs:
cross_platform_config: "--enable-debug --disable-flto --with-libevent --disable-static"
steps:
- uses: actions/checkout@v6
- uses: actions/checkout@v7
with:
submodules: false
persist-credentials: false
+1 -1
View File
@@ -12,7 +12,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/checkout@v7
with:
persist-credentials: false
- name: configure
+1 -1
View File
@@ -10,7 +10,7 @@ Unbound is a validating, recursive, caching DNS resolver. It is designed to be
fast and lean and incorporates modern features based on open standards. If you
have any feedback, we would love to hear from you. Dont hesitate to
[create an issue on Github](https://github.com/NLnetLabs/unbound/issues/new)
or post a message on the [Unbound mailing list](https://lists.nlnetlabs.nl/mailman/listinfo/unbound-users).
or post a message on our [community forum](https://community.nlnetlabs.nl/).
You can learn more about Unbound by reading our
[documentation](https://unbound.docs.nlnetlabs.nl/).
+17 -2
View File
@@ -87,7 +87,7 @@
# modified version of the Autoconf Macro, you may extend this special
# exception to the GPL to apply to your modified version as well.
#serial 31
#serial 32
AU_ALIAS([ACX_PTHREAD], [AX_PTHREAD])
AC_DEFUN([AX_PTHREAD], [
@@ -249,7 +249,22 @@ AS_IF([test "x$ax_pthread_clang" = "xyes"],
# correctly enabled
case $host_os in
darwin* | hpux* | linux* | osf* | solaris*)
solaris*)
# Solaris 11.4 introduced XPG7 support and did away with the need for
# _REENTRANT.
AC_EGREP_CPP([AX_PTHREAD_SOLARIS__REENTRANT],
[
# undef _XOPEN_SOURCE
# include <sys/feature_tests.h>
# if _XOPEN_VERSION < 700
AX_PTHREAD_SOLARIS__REENTRANT
# endif
],
[ax_pthread_check_macro="_REENTRANT"],
[ax_pthread_check_macro="--"])
;;
darwin* | hpux* | linux* | osf*)
ax_pthread_check_macro="_REENTRANT"
;;
+11
View File
@@ -401,6 +401,12 @@ prep_data(struct module_qstate* qstate, struct sldns_buffer* buf)
FLAGS_GET_RCODE(qstate->return_msg->rep->flags) !=
LDNS_RCODE_YXDOMAIN)
return 0;
/* Do not persist data the validator has not yet seen, or has rejected.
* Otherwise an expired blob could maybe reach clients via
* serve-expired. */
if(qstate->env->need_to_validate &&
qstate->return_msg->rep->security == sec_status_bogus)
return 0;
/* We don't store the reply if its TTL is 0. This is probably coming
* from upstream and it is not meant to be stored. */
if(qstate->return_msg->rep->ttl == 0)
@@ -863,6 +869,11 @@ cachedb_handle_query(struct module_qstate* qstate,
return;
}
/* No 0TTL answers escaping from external cache. */
if(qstate->return_msg->rep->ttl == 0) {
qstate->return_msg = NULL;
qstate->ext_state[id] = module_wait_module;
return;
}
log_assert(qstate->return_msg->rep->ttl > 0);
qstate->is_cachedb_answer = 1;
/* we are done with the query */
+9 -382
View File
@@ -20,398 +20,25 @@
* http://man.openbsd.org/getentropy.2
*/
#include <TargetConditionals.h>
#include <sys/types.h>
#include <sys/param.h>
#include <sys/ioctl.h>
#include <sys/resource.h>
#include <sys/syscall.h>
#include <sys/sysctl.h>
#include <sys/statvfs.h>
#include <sys/socket.h>
#include <sys/mount.h>
#include <sys/mman.h>
#include <sys/stat.h>
#include <sys/time.h>
#include <stdlib.h>
#include <stdint.h>
#include <stdio.h>
#include <termios.h>
#include <fcntl.h>
#include <signal.h>
#include <string.h>
/* Modified to use SecRandomCopyBytes. It is from macOS 10.7 (2011) and
* iOS 2.0 (2008), and is the primary API for cryptographic random numbers. */
#include <errno.h>
#include <unistd.h>
#include <time.h>
#include <mach/mach_time.h>
#include <mach/mach_host.h>
#include <mach/host_info.h>
#if TARGET_OS_OSX
#include <sys/socketvar.h>
#include <sys/vmmeter.h>
#endif
#include <netinet/in.h>
#include <netinet/tcp.h>
#if TARGET_OS_OSX
#include <netinet/udp.h>
#include <netinet/ip_var.h>
#include <netinet/tcp_var.h>
#include <netinet/udp_var.h>
#endif
#include <CommonCrypto/CommonDigest.h>
#define SHA512_Update(a, b, c) (CC_SHA512_Update((a), (b), (c)))
#define SHA512_Init(xxx) (CC_SHA512_Init((xxx)))
#define SHA512_Final(xxx, yyy) (CC_SHA512_Final((xxx), (yyy)))
#define SHA512_CTX CC_SHA512_CTX
#define SHA512_DIGEST_LENGTH CC_SHA512_DIGEST_LENGTH
#define REPEAT 5
#define min(a, b) (((a) < (b)) ? (a) : (b))
#define HX(a, b) \
do { \
if ((a)) \
HD(errno); \
else \
HD(b); \
} while (0)
#define HR(x, l) (SHA512_Update(&ctx, (char *)(x), (l)))
#define HD(x) (SHA512_Update(&ctx, (char *)&(x), sizeof (x)))
#define HF(x) (SHA512_Update(&ctx, (char *)&(x), sizeof (void*)))
#include <Security/SecRandom.h>
int getentropy(void *buf, size_t len);
static int getentropy_urandom(void *buf, size_t len);
static int getentropy_fallback(void *buf, size_t len);
int
getentropy(void *buf, size_t len)
{
int ret = -1;
if (len > 256) {
errno = EIO;
return (-1);
goto error;
}
/*
* Try to get entropy with /dev/urandom
*
* This can fail if the process is inside a chroot or if file
* descriptors are exhausted.
*/
ret = getentropy_urandom(buf, len);
if (ret != -1)
return (ret);
/*
* Entropy collection via /dev/urandom and sysctl have failed.
*
* No other API exists for collecting entropy, and we have
* no failsafe way to get it on OSX that is not sensitive
* to resource exhaustion.
*
* We have very few options:
* - Even syslog_r is unsafe to call at this low level, so
* there is no way to alert the user or program.
* - Cannot call abort() because some systems have unsafe
* corefiles.
* - Could raise(SIGKILL) resulting in silent program termination.
* - Return EIO, to hint that arc4random's stir function
* should raise(SIGKILL)
* - Do the best under the circumstances....
*
* This code path exists to bring light to the issue that OSX
* does not provide a failsafe API for entropy collection.
*
* We hope this demonstrates that OSX should consider
* providing a new failsafe API which works in a chroot or
* when file descriptors are exhausted.
*/
#undef FAIL_INSTEAD_OF_TRYING_FALLBACK
#ifdef FAIL_INSTEAD_OF_TRYING_FALLBACK
raise(SIGKILL);
#endif
ret = getentropy_fallback(buf, len);
if (ret != -1)
return (ret);
if (SecRandomCopyBytes(kSecRandomDefault, len, buf) == errSecSuccess) {
return 0;
}
error:
errno = EIO;
return (ret);
}
static int
getentropy_urandom(void *buf, size_t len)
{
struct stat st;
size_t i;
int fd, flags;
int save_errno = errno;
start:
flags = O_RDONLY;
#ifdef O_NOFOLLOW
flags |= O_NOFOLLOW;
#endif
#ifdef O_CLOEXEC
flags |= O_CLOEXEC;
#endif
fd = open("/dev/urandom", flags, 0);
if (fd == -1) {
if (errno == EINTR)
goto start;
goto nodevrandom;
}
#ifndef O_CLOEXEC
fcntl(fd, F_SETFD, fcntl(fd, F_GETFD) | FD_CLOEXEC);
#endif
/* Lightly verify that the device node looks sane */
if (fstat(fd, &st) == -1 || !S_ISCHR(st.st_mode)) {
close(fd);
goto nodevrandom;
}
for (i = 0; i < len; ) {
size_t wanted = len - i;
ssize_t ret = read(fd, (char *)buf + i, wanted);
if (ret == -1) {
if (errno == EAGAIN || errno == EINTR)
continue;
close(fd);
goto nodevrandom;
}
i += ret;
}
close(fd);
errno = save_errno;
return (0); /* satisfied */
nodevrandom:
errno = EIO;
return (-1);
}
#if TARGET_OS_OSX
static int tcpmib[] = { CTL_NET, AF_INET, IPPROTO_TCP, TCPCTL_STATS };
static int udpmib[] = { CTL_NET, AF_INET, IPPROTO_UDP, UDPCTL_STATS };
static int ipmib[] = { CTL_NET, AF_INET, IPPROTO_IP, IPCTL_STATS };
#endif
static int kmib[] = { CTL_KERN, KERN_USRSTACK };
static int hwmib[] = { CTL_HW, HW_USERMEM };
static int
getentropy_fallback(void *buf, size_t len)
{
uint8_t results[SHA512_DIGEST_LENGTH];
int save_errno = errno, e, pgs = getpagesize(), faster = 0, repeat;
static int cnt;
struct timespec ts;
struct timeval tv;
struct rusage ru;
sigset_t sigset;
struct stat st;
SHA512_CTX ctx;
static pid_t lastpid;
pid_t pid;
size_t i, ii, m;
char *p;
#if TARGET_OS_OSX
struct tcpstat tcpstat;
struct udpstat udpstat;
struct ipstat ipstat;
#endif
u_int64_t mach_time;
unsigned int idata;
void *addr;
pid = getpid();
if (lastpid == pid) {
faster = 1;
repeat = 2;
} else {
faster = 0;
lastpid = pid;
repeat = REPEAT;
}
for (i = 0; i < len; ) {
int j;
SHA512_Init(&ctx);
for (j = 0; j < repeat; j++) {
HX((e = gettimeofday(&tv, NULL)) == -1, tv);
if (e != -1) {
cnt += (int)tv.tv_sec;
cnt += (int)tv.tv_usec;
}
mach_time = mach_absolute_time();
HD(mach_time);
ii = sizeof(addr);
HX(sysctl(kmib, sizeof(kmib) / sizeof(kmib[0]),
&addr, &ii, NULL, 0) == -1, addr);
ii = sizeof(idata);
HX(sysctl(hwmib, sizeof(hwmib) / sizeof(hwmib[0]),
&idata, &ii, NULL, 0) == -1, idata);
#if TARGET_OS_OSX
ii = sizeof(tcpstat);
HX(sysctl(tcpmib, sizeof(tcpmib) / sizeof(tcpmib[0]),
&tcpstat, &ii, NULL, 0) == -1, tcpstat);
ii = sizeof(udpstat);
HX(sysctl(udpmib, sizeof(udpmib) / sizeof(udpmib[0]),
&udpstat, &ii, NULL, 0) == -1, udpstat);
ii = sizeof(ipstat);
HX(sysctl(ipmib, sizeof(ipmib) / sizeof(ipmib[0]),
&ipstat, &ii, NULL, 0) == -1, ipstat);
#endif
HX((pid = getpid()) == -1, pid);
HX((pid = getsid(pid)) == -1, pid);
HX((pid = getppid()) == -1, pid);
HX((pid = getpgid(0)) == -1, pid);
HX((e = getpriority(0, 0)) == -1, e);
if (!faster) {
ts.tv_sec = 0;
ts.tv_nsec = 1;
(void) nanosleep(&ts, NULL);
}
HX(sigpending(&sigset) == -1, sigset);
HX(sigprocmask(SIG_BLOCK, NULL, &sigset) == -1,
sigset);
HF(getentropy); /* an addr in this library */
HF(printf); /* an addr in libc */
p = (char *)&p;
HD(p); /* an addr on stack */
p = (char *)&errno;
HD(p); /* the addr of errno */
if (i == 0) {
struct sockaddr_storage ss;
struct statvfs stvfs;
struct termios tios;
struct statfs stfs;
socklen_t ssl;
off_t off;
/*
* Prime-sized mappings encourage fragmentation;
* thus exposing some address entropy.
*/
struct mm {
size_t npg;
void *p;
} mm[] = {
{ 17, MAP_FAILED }, { 3, MAP_FAILED },
{ 11, MAP_FAILED }, { 2, MAP_FAILED },
{ 5, MAP_FAILED }, { 3, MAP_FAILED },
{ 7, MAP_FAILED }, { 1, MAP_FAILED },
{ 57, MAP_FAILED }, { 3, MAP_FAILED },
{ 131, MAP_FAILED }, { 1, MAP_FAILED },
};
for (m = 0; m < sizeof mm/sizeof(mm[0]); m++) {
HX(mm[m].p = mmap(NULL,
mm[m].npg * pgs,
PROT_READ|PROT_WRITE,
MAP_PRIVATE|MAP_ANON, -1,
(off_t)0), mm[m].p);
if (mm[m].p != MAP_FAILED) {
size_t mo;
/* Touch some memory... */
p = mm[m].p;
mo = cnt %
(mm[m].npg * pgs - 1);
p[mo] = 1;
cnt += (int)((long)(mm[m].p)
/ pgs);
}
/* Check cnts and times... */
mach_time = mach_absolute_time();
HD(mach_time);
cnt += (int)mach_time;
HX((e = getrusage(RUSAGE_SELF,
&ru)) == -1, ru);
if (e != -1) {
cnt += (int)ru.ru_utime.tv_sec;
cnt += (int)ru.ru_utime.tv_usec;
}
}
for (m = 0; m < sizeof mm/sizeof(mm[0]); m++) {
if (mm[m].p != MAP_FAILED)
munmap(mm[m].p, mm[m].npg * pgs);
mm[m].p = MAP_FAILED;
}
HX(stat(".", &st) == -1, st);
HX(statvfs(".", &stvfs) == -1, stvfs);
HX(statfs(".", &stfs) == -1, stfs);
HX(stat("/", &st) == -1, st);
HX(statvfs("/", &stvfs) == -1, stvfs);
HX(statfs("/", &stfs) == -1, stfs);
HX((e = fstat(0, &st)) == -1, st);
if (e == -1) {
if (S_ISREG(st.st_mode) ||
S_ISFIFO(st.st_mode) ||
S_ISSOCK(st.st_mode)) {
HX(fstatvfs(0, &stvfs) == -1,
stvfs);
HX(fstatfs(0, &stfs) == -1,
stfs);
HX((off = lseek(0, (off_t)0,
SEEK_CUR)) < 0, off);
}
if (S_ISCHR(st.st_mode)) {
HX(tcgetattr(0, &tios) == -1,
tios);
} else if (S_ISSOCK(st.st_mode)) {
memset(&ss, 0, sizeof ss);
ssl = sizeof(ss);
HX(getpeername(0,
(void *)&ss, &ssl) == -1,
ss);
}
}
HX((e = getrusage(RUSAGE_CHILDREN,
&ru)) == -1, ru);
if (e != -1) {
cnt += (int)ru.ru_utime.tv_sec;
cnt += (int)ru.ru_utime.tv_usec;
}
} else {
/* Subsequent hashes absorb previous result */
HD(results);
}
HX((e = gettimeofday(&tv, NULL)) == -1, tv);
if (e != -1) {
cnt += (int)tv.tv_sec;
cnt += (int)tv.tv_usec;
}
HD(cnt);
}
SHA512_Final(results, &ctx);
memcpy((char *)buf + i, results, min(sizeof(results), len - i));
i += min(sizeof(results), len - i);
}
explicit_bzero(&ctx, sizeof ctx);
explicit_bzero(results, sizeof results);
errno = save_errno;
return (0); /* satisfied */
return -1;
}
+3 -10
View File
@@ -59,10 +59,7 @@ static int inet_pton6 (const char *src, uint8_t *dst);
* Paul Vixie, 1996.
*/
int
inet_pton(af, src, dst)
int af;
const char *src;
void *dst;
inet_pton(int af, const char *src, void *dst)
{
switch (af) {
case AF_INET:
@@ -91,9 +88,7 @@ inet_pton(af, src, dst)
* Paul Vixie, 1996.
*/
static int
inet_pton4(src, dst)
const char *src;
uint8_t *dst;
inet_pton4(const char *src, uint8_t *dst)
{
static const char digits[] = "0123456789";
int saw_digit, octets, ch;
@@ -145,9 +140,7 @@ inet_pton4(src, dst)
* Paul Vixie, 1996.
*/
static int
inet_pton6(src, dst)
const char *src;
uint8_t *dst;
inet_pton6(const char *src, uint8_t *dst)
{
static const char xdigits_l[] = "0123456789abcdef",
xdigits_u[] = "0123456789ABCDEF";
+32
View File
@@ -31,6 +31,9 @@
/* Whether daemon is deprecated */
#undef DEPRECATED_DAEMON
/* Whether X509_NAME_get_text_by_NID is deprecated */
#undef DEPRECATED_X509_NAME_GET_TEXT_BY_NID
/* Deprecate RSA 1024 bit length, makes that an unsupported key */
#undef DEPRECATE_RSA_1024
@@ -60,6 +63,9 @@
/* Define to 1 if you have the <arpa/inet.h> header file. */
#undef HAVE_ARPA_INET_H
/* Define to 1 if you have the `ASN1_STRING_get0_data' function. */
#undef HAVE_ASN1_STRING_GET0_DATA
/* Whether the C compiler accepts the "fallthrough" attribute */
#undef HAVE_ATTR_FALLTHROUGH
@@ -140,6 +146,10 @@
to 0 if you don't. */
#undef HAVE_DECL_NGTCP2_CRYPTO_ENCRYPT_CB
/* Define to 1 if you have the declaration of `ngtcp2_crypto_ossl_ctx_new',
and to 0 if you don't. */
#undef HAVE_DECL_NGTCP2_CRYPTO_OSSL_CTX_NEW
/* Define to 1 if you have the declaration of `NID_ED25519', and to 0 if you
don't. */
#undef HAVE_DECL_NID_ED25519
@@ -289,6 +299,12 @@
/* Define to 1 if you have the `FIPS_mode' function. */
#undef HAVE_FIPS_MODE
/* Define to 1 if you have the `fnmatch' function. */
#undef HAVE_FNMATCH
/* Define to 1 if you have the <fnmatch.h> header file. */
#undef HAVE_FNMATCH_H
/* Define to 1 if you have the `fork' function. */
#undef HAVE_FORK
@@ -513,6 +529,9 @@
/* Define to 1 if you have the <openssl/bn.h> header file. */
#undef HAVE_OPENSSL_BN_H
/* Define to 1 if you have the `OPENSSL_cleanup' function. */
#undef HAVE_OPENSSL_CLEANUP
/* Define to 1 if you have the `OPENSSL_config' function. */
#undef HAVE_OPENSSL_CONFIG
@@ -685,9 +704,16 @@
/* Define to 1 if you have the `SSL_is_quic' function. */
#undef HAVE_SSL_IS_QUIC
/* Define to 1 if you have the `SSL_set1_dnsname' function. */
#undef HAVE_SSL_SET1_DNSNAME
/* Define to 1 if you have the `SSL_set1_host' function. */
#undef HAVE_SSL_SET1_HOST
/* Define to 1 if you have the `SSL_set_quic_tls_early_data_enabled' function.
*/
#undef HAVE_SSL_SET_QUIC_TLS_EARLY_DATA_ENABLED
/* Define to 1 if you have the <stdarg.h> header file. */
#undef HAVE_STDARG_H
@@ -852,6 +878,12 @@
/* Define to 1 if you have the <ws2tcpip.h> header file. */
#undef HAVE_WS2TCPIP_H
/* Define to 1 if you have the `X509_get_key_usage' function. */
#undef HAVE_X509_GET_KEY_USAGE
/* Define to 1 if you have the `X509_NAME_get_text_by_NID' function. */
#undef HAVE_X509_NAME_GET_TEXT_BY_NID
/* Define to 1 if you have the `X509_VERIFY_PARAM_set1_host' function. */
#undef HAVE_X509_VERIFY_PARAM_SET1_HOST
Vendored
+150 -14
View File
@@ -1,6 +1,6 @@
#! /bin/sh
# Guess values for system-dependent variables and create Makefiles.
# Generated by GNU Autoconf 2.71 for unbound 1.25.2.
# Generated by GNU Autoconf 2.71 for unbound 1.26.1.
#
# Report bugs to <unbound-bugs@nlnetlabs.nl or https://github.com/NLnetLabs/unbound/issues>.
#
@@ -622,8 +622,8 @@ MAKEFLAGS=
# Identity of this package.
PACKAGE_NAME='unbound'
PACKAGE_TARNAME='unbound'
PACKAGE_VERSION='1.25.2'
PACKAGE_STRING='unbound 1.25.2'
PACKAGE_VERSION='1.26.1'
PACKAGE_STRING='unbound 1.26.1'
PACKAGE_BUGREPORT='unbound-bugs@nlnetlabs.nl or https://github.com/NLnetLabs/unbound/issues'
PACKAGE_URL=''
@@ -1513,7 +1513,7 @@ if test "$ac_init_help" = "long"; then
# Omit some internal or obsolete options to make the list less imposing.
# This message is too long to be a string in the A/UX 3.1 sh.
cat <<_ACEOF
\`configure' configures unbound 1.25.2 to adapt to many kinds of systems.
\`configure' configures unbound 1.26.1 to adapt to many kinds of systems.
Usage: $0 [OPTION]... [VAR=VALUE]...
@@ -1579,7 +1579,7 @@ fi
if test -n "$ac_init_help"; then
case $ac_init_help in
short | recursive ) echo "Configuration of unbound 1.25.2:";;
short | recursive ) echo "Configuration of unbound 1.26.1:";;
esac
cat <<\_ACEOF
@@ -1832,7 +1832,7 @@ fi
test -n "$ac_init_help" && exit $ac_status
if $ac_init_version; then
cat <<\_ACEOF
unbound configure 1.25.2
unbound configure 1.26.1
generated by GNU Autoconf 2.71
Copyright (C) 2021 Free Software Foundation, Inc.
@@ -2489,7 +2489,7 @@ cat >config.log <<_ACEOF
This file contains any messages produced by compilers while
running configure, to aid debugging if configure makes a mistake.
It was created by unbound $as_me 1.25.2, which was
It was created by unbound $as_me 1.26.1, which was
generated by GNU Autoconf 2.71. Invocation command line was
$ $0$ac_configure_args_raw
@@ -3251,13 +3251,13 @@ ac_compiler_gnu=$ac_cv_c_compiler_gnu
UNBOUND_VERSION_MAJOR=1
UNBOUND_VERSION_MINOR=25
UNBOUND_VERSION_MINOR=26
UNBOUND_VERSION_MICRO=2
UNBOUND_VERSION_MICRO=1
LIBUNBOUND_CURRENT=9
LIBUNBOUND_REVISION=38
LIBUNBOUND_REVISION=40
LIBUNBOUND_AGE=1
# 1.0.0 had 0:12:0
# 1.0.1 had 0:13:0
@@ -3363,6 +3363,8 @@ LIBUNBOUND_AGE=1
# 1.25.0 had 9:36:1
# 1.25.1 had 9:37:1
# 1.25.2 had 9:38:1
# 1.26.0 had 9:39:1
# 1.26.1 had 9:40:1
# Current -- the number of the binary API that we're implementing
# Revision -- which iteration of the implementation of the binary
@@ -16005,6 +16007,13 @@ if test "x$ac_cv_header_glob_h" = xyes
then :
printf "%s\n" "#define HAVE_GLOB_H 1" >>confdefs.h
fi
ac_fn_c_check_header_compile "$LINENO" "fnmatch.h" "ac_cv_header_fnmatch_h" "$ac_includes_default
"
if test "x$ac_cv_header_fnmatch_h" = xyes
then :
printf "%s\n" "#define HAVE_FNMATCH_H 1" >>confdefs.h
fi
ac_fn_c_check_header_compile "$LINENO" "grp.h" "ac_cv_header_grp_h" "$ac_includes_default
"
@@ -18407,7 +18416,31 @@ fi
# correctly enabled
case $host_os in
darwin* | hpux* | linux* | osf* | solaris*)
solaris*)
# Solaris 11.4 introduced XPG7 support and did away with the need for
# _REENTRANT.
cat confdefs.h - <<_ACEOF >conftest.$ac_ext
/* end confdefs.h. */
# undef _XOPEN_SOURCE
# include <sys/feature_tests.h>
# if _XOPEN_VERSION < 700
AX_PTHREAD_SOLARIS__REENTRANT
# endif
_ACEOF
if (eval "$ac_cpp conftest.$ac_ext") 2>&5 |
$EGREP "AX_PTHREAD_SOLARIS__REENTRANT" >/dev/null 2>&1
then :
ax_pthread_check_macro="_REENTRANT"
else $as_nop
ax_pthread_check_macro="--"
fi
rm -rf conftest*
;;
darwin* | hpux* | linux* | osf*)
ax_pthread_check_macro="_REENTRANT"
;;
@@ -21061,6 +21094,12 @@ then :
printf "%s\n" "#define HAVE_BIO_SET_CALLBACK_EX 1" >>confdefs.h
fi
ac_fn_c_check_func "$LINENO" "OPENSSL_cleanup" "ac_cv_func_OPENSSL_cleanup"
if test "x$ac_cv_func_OPENSSL_cleanup" = xyes
then :
printf "%s\n" "#define HAVE_OPENSSL_CLEANUP 1" >>confdefs.h
fi
# these check_funcs need -lssl
@@ -21089,6 +21128,24 @@ if test "x$ac_cv_func_SSL_get0_peername" = xyes
then :
printf "%s\n" "#define HAVE_SSL_GET0_PEERNAME 1" >>confdefs.h
fi
ac_fn_c_check_func "$LINENO" "SSL_set1_dnsname" "ac_cv_func_SSL_set1_dnsname"
if test "x$ac_cv_func_SSL_set1_dnsname" = xyes
then :
printf "%s\n" "#define HAVE_SSL_SET1_DNSNAME 1" >>confdefs.h
fi
ac_fn_c_check_func "$LINENO" "X509_get_key_usage" "ac_cv_func_X509_get_key_usage"
if test "x$ac_cv_func_X509_get_key_usage" = xyes
then :
printf "%s\n" "#define HAVE_X509_GET_KEY_USAGE 1" >>confdefs.h
fi
ac_fn_c_check_func "$LINENO" "ASN1_STRING_get0_data" "ac_cv_func_ASN1_STRING_get0_data"
if test "x$ac_cv_func_ASN1_STRING_get0_data" = xyes
then :
printf "%s\n" "#define HAVE_ASN1_STRING_GET0_DATA 1" >>confdefs.h
fi
ac_fn_c_check_func "$LINENO" "X509_VERIFY_PARAM_set1_host" "ac_cv_func_X509_VERIFY_PARAM_set1_host"
if test "x$ac_cv_func_X509_VERIFY_PARAM_set1_host" = xyes
@@ -21133,6 +21190,54 @@ then :
fi
ac_fn_c_check_func "$LINENO" "X509_NAME_get_text_by_NID" "ac_cv_func_X509_NAME_get_text_by_NID"
if test "x$ac_cv_func_X509_NAME_get_text_by_NID" = xyes
then :
printf "%s\n" "#define HAVE_X509_NAME_GET_TEXT_BY_NID 1" >>confdefs.h
fi
if test $ac_cv_func_X509_NAME_get_text_by_NID = yes; then
{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking if X509_NAME_get_text_by_NID is deprecated" >&5
printf %s "checking if X509_NAME_get_text_by_NID is deprecated... " >&6; }
cache=`echo X509_NAME_get_text_by_NID | sed 'y%.=/+-%___p_%'`
if eval test \${cv_cc_deprecated_$cache+y}
then :
printf %s "(cached) " >&6
else $as_nop
echo '
#include "openssl/x509.h"
' >conftest.c
echo 'void f(void){
(void)X509_NAME_get_text_by_NID(NULL, 0, NULL, 0); }' >>conftest.c
if test -z "`$CC $CPPFLAGS $CFLAGS -c conftest.c 2>&1 | grep -e deprecated -e unavailable`"; then
eval "cv_cc_deprecated_$cache=no"
else
eval "cv_cc_deprecated_$cache=yes"
fi
rm -f conftest conftest.o conftest.c
fi
if eval "test \"`echo '$cv_cc_deprecated_'$cache`\" = yes"; then
{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: yes" >&5
printf "%s\n" "yes" >&6; }
printf "%s\n" "#define DEPRECATED_X509_NAME_GET_TEXT_BY_NID 1" >>confdefs.h
:
else
{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5
printf "%s\n" "no" >&6; }
:
fi
fi
LIBS="$BAKLIBS"
ac_fn_check_decl "$LINENO" "SSL_COMP_get_compression_methods" "ac_cv_have_decl_SSL_COMP_get_compression_methods" "
@@ -22639,6 +22744,24 @@ then :
printf "%s\n" "#define USE_NGTCP2_CRYPTO_OSSL 1" >>confdefs.h
ac_fn_check_decl "$LINENO" "ngtcp2_crypto_ossl_ctx_new" "ac_cv_have_decl_ngtcp2_crypto_ossl_ctx_new" "$ac_includes_default
#include <ngtcp2/ngtcp2_crypto_ossl.h>
" "$ac_c_undeclared_builtin_options" "CFLAGS"
if test "x$ac_cv_have_decl_ngtcp2_crypto_ossl_ctx_new" = xyes
then :
ac_have_decl=1
else $as_nop
ac_have_decl=0
fi
printf "%s\n" "#define HAVE_DECL_NGTCP2_CRYPTO_OSSL_CTX_NEW $ac_have_decl" >>confdefs.h
if test $ac_have_decl = 1
then :
else $as_nop
as_fn_error $? "No declaration of ngtcp2_crypto_ossl_ctx_new in the ngtcp2_crypto_ossl header file. Perhaps the ngtcp2_crypto_ossl devel header files need to be installed." "$LINENO" 5
fi
else $as_nop
@@ -22818,6 +22941,13 @@ else $as_nop
fi
done
ac_fn_c_check_func "$LINENO" "SSL_set_quic_tls_early_data_enabled" "ac_cv_func_SSL_set_quic_tls_early_data_enabled"
if test "x$ac_cv_func_SSL_set_quic_tls_early_data_enabled" = xyes
then :
printf "%s\n" "#define HAVE_SSL_SET_QUIC_TLS_EARLY_DATA_ENABLED 1" >>confdefs.h
fi
LIBS="$BAKLIBS"
ac_fn_c_check_type "$LINENO" "struct ngtcp2_version_cid" "ac_cv_type_struct_ngtcp2_version_cid" "$ac_includes_default
@@ -23780,6 +23910,12 @@ if test "x$ac_cv_func_glob" = xyes
then :
printf "%s\n" "#define HAVE_GLOB 1" >>confdefs.h
fi
ac_fn_c_check_func "$LINENO" "fnmatch" "ac_cv_func_fnmatch"
if test "x$ac_cv_func_fnmatch" = xyes
then :
printf "%s\n" "#define HAVE_FNMATCH 1" >>confdefs.h
fi
ac_fn_c_check_func "$LINENO" "initgroups" "ac_cv_func_initgroups"
if test "x$ac_cv_func_initgroups" = xyes
@@ -25576,7 +25712,7 @@ printf "%s\n" "#define MAXSYSLOGMSGLEN 10240" >>confdefs.h
version=1.25.2
version=1.26.1
{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for build time" >&5
printf %s "checking for build time... " >&6; }
@@ -26106,7 +26242,7 @@ cat >>$CONFIG_STATUS <<\_ACEOF || ac_write_fail=1
# report actual input values of CONFIG_FILES etc. instead of their
# values after options handling.
ac_log="
This file was extended by unbound $as_me 1.25.2, which was
This file was extended by unbound $as_me 1.26.1, which was
generated by GNU Autoconf 2.71. Invocation command line was
CONFIG_FILES = $CONFIG_FILES
@@ -26174,7 +26310,7 @@ ac_cs_config_escaped=`printf "%s\n" "$ac_cs_config" | sed "s/^ //; s/'/'\\\\\\\\
cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1
ac_cs_config='$ac_cs_config_escaped'
ac_cs_version="\\
unbound config.status 1.25.2
unbound config.status 1.26.1
configured by $0, generated by GNU Autoconf 2.71,
with options \\"\$ac_cs_config\\"
+20 -7
View File
@@ -11,15 +11,15 @@ sinclude(dnscrypt/dnscrypt.m4)
# must be numbers. ac_defun because of later processing
m4_define([VERSION_MAJOR],[1])
m4_define([VERSION_MINOR],[25])
m4_define([VERSION_MICRO],[2])
m4_define([VERSION_MINOR],[26])
m4_define([VERSION_MICRO],[1])
AC_INIT([unbound],m4_defn([VERSION_MAJOR]).m4_defn([VERSION_MINOR]).m4_defn([VERSION_MICRO]),[unbound-bugs@nlnetlabs.nl or https://github.com/NLnetLabs/unbound/issues],[unbound])
AC_SUBST(UNBOUND_VERSION_MAJOR, [VERSION_MAJOR])
AC_SUBST(UNBOUND_VERSION_MINOR, [VERSION_MINOR])
AC_SUBST(UNBOUND_VERSION_MICRO, [VERSION_MICRO])
LIBUNBOUND_CURRENT=9
LIBUNBOUND_REVISION=38
LIBUNBOUND_REVISION=40
LIBUNBOUND_AGE=1
# 1.0.0 had 0:12:0
# 1.0.1 had 0:13:0
@@ -125,6 +125,8 @@ LIBUNBOUND_AGE=1
# 1.25.0 had 9:36:1
# 1.25.1 had 9:37:1
# 1.25.2 had 9:38:1
# 1.26.0 had 9:39:1
# 1.26.1 had 9:40:1
# Current -- the number of the binary API that we're implementing
# Revision -- which iteration of the implementation of the binary
@@ -483,7 +485,7 @@ PKG_PROG_PKG_CONFIG
fi
# Checks for header files.
AC_CHECK_HEADERS([stdarg.h stdbool.h netinet/in.h netinet/tcp.h sys/param.h sys/select.h sys/socket.h sys/un.h sys/uio.h sys/resource.h arpa/inet.h syslog.h netdb.h sys/wait.h pwd.h glob.h grp.h login_cap.h winsock2.h ws2tcpip.h endian.h sys/endian.h libkern/OSByteOrder.h sys/ipc.h sys/shm.h ifaddrs.h poll.h],,, [AC_INCLUDES_DEFAULT])
AC_CHECK_HEADERS([stdarg.h stdbool.h netinet/in.h netinet/tcp.h sys/param.h sys/select.h sys/socket.h sys/un.h sys/uio.h sys/resource.h arpa/inet.h syslog.h netdb.h sys/wait.h pwd.h glob.h fnmatch.h grp.h login_cap.h winsock2.h ws2tcpip.h endian.h sys/endian.h libkern/OSByteOrder.h sys/ipc.h sys/shm.h ifaddrs.h poll.h],,, [AC_INCLUDES_DEFAULT])
# net/if.h portability for Darwin see:
# https://www.gnu.org/software/autoconf/manual/autoconf-2.69/html_node/Header-Portability.html
AC_CHECK_HEADERS([net/if.h],,, [
@@ -1080,12 +1082,19 @@ else
AC_MSG_RESULT([no])
fi
AC_CHECK_HEADERS([openssl/conf.h openssl/engine.h openssl/bn.h openssl/dh.h openssl/dsa.h openssl/rsa.h openssl/core_names.h openssl/param_build.h],,, [AC_INCLUDES_DEFAULT])
AC_CHECK_FUNCS([OPENSSL_config EVP_sha1 EVP_sha256 EVP_sha512 FIPS_mode EVP_default_properties_is_fips_enabled EVP_MD_CTX_new OpenSSL_add_all_digests OPENSSL_init_crypto EVP_cleanup ENGINE_cleanup ERR_load_crypto_strings CRYPTO_cleanup_all_ex_data ERR_free_strings RAND_cleanup DSA_SIG_set0 EVP_dss1 EVP_DigestVerify EVP_aes_256_cbc EVP_EncryptInit_ex HMAC_Init_ex CRYPTO_THREADID_set_callback EVP_MAC_CTX_set_params OSSL_PARAM_BLD_new BIO_set_callback_ex])
AC_CHECK_FUNCS([OPENSSL_config EVP_sha1 EVP_sha256 EVP_sha512 FIPS_mode EVP_default_properties_is_fips_enabled EVP_MD_CTX_new OpenSSL_add_all_digests OPENSSL_init_crypto EVP_cleanup ENGINE_cleanup ERR_load_crypto_strings CRYPTO_cleanup_all_ex_data ERR_free_strings RAND_cleanup DSA_SIG_set0 EVP_dss1 EVP_DigestVerify EVP_aes_256_cbc EVP_EncryptInit_ex HMAC_Init_ex CRYPTO_THREADID_set_callback EVP_MAC_CTX_set_params OSSL_PARAM_BLD_new BIO_set_callback_ex OPENSSL_cleanup])
# these check_funcs need -lssl
BAKLIBS="$LIBS"
LIBS="-lssl $LIBS"
AC_CHECK_FUNCS([OPENSSL_init_ssl SSL_CTX_set_security_level SSL_set1_host SSL_get0_peername X509_VERIFY_PARAM_set1_host SSL_CTX_set_ciphersuites SSL_CTX_set_tlsext_ticket_key_evp_cb SSL_CTX_set_alpn_select_cb SSL_get0_alpn_selected SSL_CTX_set_alpn_protos SSL_get1_peer_certificate])
AC_CHECK_FUNCS([OPENSSL_init_ssl SSL_CTX_set_security_level SSL_set1_host SSL_get0_peername SSL_set1_dnsname X509_get_key_usage ASN1_STRING_get0_data X509_VERIFY_PARAM_set1_host SSL_CTX_set_ciphersuites SSL_CTX_set_tlsext_ticket_key_evp_cb SSL_CTX_set_alpn_select_cb SSL_get0_alpn_selected SSL_CTX_set_alpn_protos SSL_get1_peer_certificate])
AC_CHECK_FUNCS([X509_NAME_get_text_by_NID])
if test $ac_cv_func_X509_NAME_get_text_by_NID = yes; then
ACX_FUNC_DEPRECATED([X509_NAME_get_text_by_NID], [
(void)X509_NAME_get_text_by_NID(NULL, 0, NULL, 0);], [
#include "openssl/x509.h"
])
fi
LIBS="$BAKLIBS"
AC_CHECK_DECLS([SSL_COMP_get_compression_methods,sk_SSL_COMP_pop_free,SSL_CTX_set_ecdh_auto,SSL_CTX_set_tmp_ecdh], [], [], [
@@ -1704,6 +1713,9 @@ if test x_$withval = x_yes -o x_$withval != x_no; then
AC_CHECK_LIB([ngtcp2_crypto_ossl], [ngtcp2_crypto_encrypt_cb], [
LIBS="$LIBS -lngtcp2_crypto_ossl"
AC_DEFINE(USE_NGTCP2_CRYPTO_OSSL, 1, [Define this to use ngtcp2_crypto_ossl.])
AC_CHECK_DECLS([ngtcp2_crypto_ossl_ctx_new], [], [AC_MSG_ERROR([No declaration of ngtcp2_crypto_ossl_ctx_new in the ngtcp2_crypto_ossl header file. Perhaps the ngtcp2_crypto_ossl devel header files need to be installed.])], [AC_INCLUDES_DEFAULT
#include <ngtcp2/ngtcp2_crypto_ossl.h>
])
], [
AC_CHECK_LIB([ngtcp2_crypto_openssl], [ngtcp2_crypto_encrypt_cb], [ LIBS="$LIBS -lngtcp2_crypto_openssl" ], [
AC_CHECK_LIB([ngtcp2_crypto_quictls], [ngtcp2_crypto_encrypt_cb], [ LIBS="$LIBS -lngtcp2_crypto_quictls" ])
@@ -1715,6 +1727,7 @@ if test x_$withval = x_yes -o x_$withval != x_no; then
BAKLIBS="$LIBS"
LIBS="-lssl $LIBS"
AC_CHECK_FUNCS([SSL_is_quic], [], [AC_MSG_ERROR([No QUIC support detected in OpenSSL. Need OpenSSL version with QUIC support to enable DNS over QUIC with libngtcp2.])])
AC_CHECK_FUNCS([SSL_set_quic_tls_early_data_enabled])
LIBS="$BAKLIBS"
AC_CHECK_TYPES([struct ngtcp2_version_cid, ngtcp2_encryption_level],,,[AC_INCLUDES_DEFAULT
@@ -1928,7 +1941,7 @@ AC_LINK_IFELSE([AC_LANG_PROGRAM([
AC_MSG_RESULT(no))
AC_SEARCH_LIBS([setusercontext], [util])
AC_CHECK_FUNCS([tzset sigprocmask fcntl getpwnam endpwent getrlimit setrlimit setsid chroot kill chown sleep usleep random srandom recvmsg sendmsg writev socketpair glob initgroups strftime localtime_r setusercontext _beginthreadex endservent endprotoent fsync shmget accept4 getifaddrs if_nametoindex poll gettid])
AC_CHECK_FUNCS([tzset sigprocmask fcntl getpwnam endpwent getrlimit setrlimit setsid chroot kill chown sleep usleep random srandom recvmsg sendmsg writev socketpair glob fnmatch initgroups strftime localtime_r setusercontext _beginthreadex endservent endprotoent fsync shmget accept4 getifaddrs if_nametoindex poll gettid])
AC_CHECK_FUNCS([setresuid],,[AC_CHECK_FUNCS([setreuid])])
AC_CHECK_FUNCS([setresgid],,[AC_CHECK_FUNCS([setregid])])
+2 -2
View File
@@ -99,7 +99,7 @@ static void
dump_rrset_line(struct config_strlist_head* txt, struct ub_packed_rrset_key* k,
time_t now, size_t i)
{
char s[65535];
char s[65535*4+2048];
if(!packed_rr_to_string(k, i, now, s, sizeof(s))) {
spool_txt_string(txt, "BADRR\n");
return;
@@ -455,7 +455,7 @@ load_rr(RES* ssl, sldns_buffer* buf, struct regional* region,
/* read the line */
if(!ssl_read_buf(ssl, buf))
return 0;
if(strncmp((char*)sldns_buffer_begin(buf), "BADRR\n", 6) == 0) {
if(strcmp((char*)sldns_buffer_begin(buf), "BADRR") == 0) {
*go_on = 0;
return 1;
}
+29 -11
View File
@@ -217,7 +217,8 @@ setup_listen_sslctx(void** ctx, int is_dot, int is_doh,
(cfg->tls_session_ticket_keys.first &&
cfg->tls_session_ticket_keys.first->str[0] != 0),
is_dot, is_doh, cfg->tls_protocols))) {
fatal_exit("could not set up listen SSL_CTX");
log_err("could not set up listen SSL_CTX");
*ctx = NULL;
}
}
#endif /* HAVE_SSL */
@@ -259,7 +260,8 @@ void* daemon_setup_listen_quic_sslctx(struct daemon* daemon,
pem += strlen(chroot);
if(!(ctx = quic_sslctx_create(key, pem, NULL))) {
fatal_exit("could not set up quic SSL_CTX");
log_err("could not set up quic SSL_CTX");
return NULL;
}
return ctx;
}
@@ -277,8 +279,10 @@ void* daemon_setup_connect_dot_sslctx(struct daemon* daemon,
bundle += strlen(chroot);
if(!(ctx = connect_sslctx_create(NULL, NULL, bundle,
cfg->tls_win_cert)))
fatal_exit("could not set up connect SSL_CTX");
cfg->tls_win_cert))) {
log_err("could not set up connect SSL_CTX");
return NULL;
}
return ctx;
}
#endif /* HAVE_SSL */
@@ -308,16 +312,22 @@ daemon_setup_sslctxs(struct daemon* daemon, struct config_file* cfg)
}
daemon->listen_dot_sslctx = daemon_setup_listen_dot_sslctx(
daemon, cfg);
if(!daemon->listen_dot_sslctx)
fatal_exit("Could not set up listen dot sslctx");
#ifdef HAVE_NGHTTP2_NGHTTP2_H
if(cfg_has_https(cfg)) {
daemon->listen_doh_sslctx =
daemon_setup_listen_doh_sslctx(daemon, cfg);
if(!daemon->listen_doh_sslctx)
fatal_exit("Could not set up listen doh sslctx");
}
#endif
#ifdef HAVE_NGTCP2
if(cfg_has_quic(cfg)) {
daemon->listen_quic_sslctx =
daemon_setup_listen_quic_sslctx(daemon, cfg);
if(!daemon->listen_quic_sslctx)
fatal_exit("Could not set up listen quic sslctx");
}
#endif /* HAVE_NGTCP2 */
@@ -350,6 +360,8 @@ daemon_setup_sslctxs(struct daemon* daemon, struct config_file* cfg)
}
daemon->connect_dot_sslctx = daemon_setup_connect_dot_sslctx(
daemon, cfg);
if(!daemon->connect_dot_sslctx)
fatal_exit("could not setup connect dot sslctx");
#else /* HAVE_SSL */
(void)daemon;(void)cfg;
#endif /* HAVE_SSL */
@@ -921,13 +933,14 @@ thread_start(void* arg)
{
struct worker* worker = (struct worker*)arg;
int port_num = 0;
log_assert(worker->thr_id);
set_log_thread_id(worker, worker->daemon->cfg);
{
char name[16]; /* seems to be the safest size between
different OSes */
snprintf(name, sizeof(name), "unbound/%u", worker->thread_num);
ub_thread_setname(worker->thr_id, name);
/* worker->thr_id can be written to after the thread was made
* by the creating thread, so this uses pthread_self. */
ub_thread_setname(ub_thread_self(), name);
}
ub_thread_blocksigs();
#ifdef THREADS_DISABLED
@@ -942,8 +955,9 @@ thread_start(void* arg)
port_num = 0;
#endif
if(!worker_init(worker, worker->daemon->cfg,
worker->daemon->ports[port_num], 0))
worker->daemon->ports[port_num], 0)) {
fatal_exit("Could not initialize thread");
}
worker_work(worker);
return NULL;
@@ -1105,8 +1119,9 @@ daemon_fork(struct daemon* daemon)
#if defined(HAVE_EV_LOOP) || defined(HAVE_EV_DEFAULT_LOOP)
/* in libev the first inited base gets signals */
if(!worker_init(daemon->workers[0], daemon->cfg, daemon->ports[0], 1))
if(!worker_init(daemon->workers[0], daemon->cfg, daemon->ports[0], 1)) {
fatal_exit("Could not initialize main thread");
}
#endif
/* Now create the threads and init the workers.
@@ -1119,8 +1134,9 @@ daemon_fork(struct daemon* daemon)
*/
#if !(defined(HAVE_EV_LOOP) || defined(HAVE_EV_DEFAULT_LOOP))
/* libevent has the last inited base get signals (or any base) */
if(!worker_init(daemon->workers[0], daemon->cfg, daemon->ports[0], 1))
if(!worker_init(daemon->workers[0], daemon->cfg, daemon->ports[0], 1)) {
fatal_exit("Could not initialize main thread");
}
#endif
signal_handling_playback(daemon->workers[0]);
@@ -1164,7 +1180,6 @@ daemon_cleanup(struct daemon* daemon)
/* before stopping main worker, handle signals ourselves, so we
don't die on multiple reload signals for example. */
signal_handling_record();
log_thread_set(NULL);
/* clean up caches because
* a) RRset IDs will be recycled after a reload, causing collisions
* b) validation config can change, thus rrset, msg, keycache clear
@@ -1270,7 +1285,7 @@ daemon_delete(struct daemon* daemon)
# if HAVE_DECL_SSL_COMP_GET_COMPRESSION_METHODS && HAVE_DECL_SK_SSL_COMP_POP_FREE
# ifndef S_SPLINT_S
# if OPENSSL_VERSION_NUMBER < 0x10100000
sk_SSL_COMP_pop_free(comp_meth, (void(*)())CRYPTO_free);
sk_SSL_COMP_pop_free(comp_meth, (void(*)(SSL_COMP*))CRYPTO_free);
# endif
# endif
# endif
@@ -1293,6 +1308,9 @@ daemon_delete(struct daemon* daemon)
# if defined(HAVE_SSL) && defined(OPENSSL_THREADS) && !defined(THREADS_DISABLED)
ub_openssl_lock_delete();
# endif
#ifdef HAVE_OPENSSL_CLEANUP
OPENSSL_cleanup();
#endif
#ifndef HAVE_ARC4RANDOM
_ARC4_LOCK_DESTROY();
#endif
+271 -17
View File
@@ -307,7 +307,7 @@ add_open(const char* ip, int nr, struct listen_port** list, int noproto_is_err,
#endif
}
} else {
char* s = strchr(ip, '@');
const char* s = strchr(ip, '@');
char newif[128];
if(s) {
/* override port with ifspec@port */
@@ -1533,18 +1533,95 @@ do_datas_add(struct daemon_remote* rc, RES* ssl, struct worker* worker)
(void)ssl_printf(ssl, "added %d datas\n", num);
}
static int
perform_data_remove_rr(RES* ssl, struct local_zones* local_zones,
uint8_t* rr, size_t len, size_t dname_len, char *arg)
{
uint16_t rr_class, rr_type;
int labs;
struct local_zone* z;
struct local_data* ld;
uint8_t *rdata;
size_t rdata_len, index;
struct packed_rrset_data* d;
struct local_rrset* p;
rdata = sldns_wirerr_get_rdatawl(rr, len, dname_len);
rdata_len = ((size_t)sldns_wirerr_get_rdatalen(rr, len, dname_len))+2;
labs = dname_count_labels(rr);
rr_class = sldns_wirerr_get_class(rr, len, dname_len);
rr_type = sldns_wirerr_get_type(rr, len, dname_len);
z = local_zones_lookup(local_zones, rr, dname_len,
labs, rr_class, rr_type, 1);
if (!z) {
ssl_printf(ssl, "error no zone for rr %s\n", arg);
return 0;
}
ld = local_zone_find_data(z, rr, dname_len, labs);
if (!ld) {
ssl_printf(ssl, "error no local data for rr %s\n", arg);
return 0;
}
p = ld->rrsets;
while (p && ntohs(p->rrset->rk.type) != rr_type) {
p = p->next;
}
if (!p) {
ssl_printf(ssl, "error no rrset for rr %s\n", arg);
return 0;
}
d = (struct packed_rrset_data*)p->rrset->entry.data;
if (!packed_rrset_find_rr(d, rdata, rdata_len, &index)) {
ssl_printf(ssl, "error rr %s not found in rrset\n", arg);
return 0;
}
if (!local_rrset_remove_rr(d, index)) {
ssl_printf(ssl, "error unable to delete rr %s\n", arg);
return 0;
}
return 1;
}
/** Remove RR data */
static int
perform_data_remove(RES* ssl, struct local_zones* zones, char* arg)
{
uint8_t* nm;
int nmlabs;
size_t nmlen;
if(!parse_arg_name(ssl, arg, &nm, &nmlen, &nmlabs))
uint8_t rr[LDNS_RR_BUF_SIZE], *nm;
size_t len = sizeof(rr);
int status, nmlabs;
size_t nmlen, dname_len;
/* try to parse as a rr first */
status = sldns_str2wire_rr_buf(arg, rr, &len, &dname_len, 3600,
NULL, 0, NULL, 0);
/* try to parse as a domain name second */
if (status != 0) {
if (parse_arg_name(ssl, arg, &nm, &nmlen, &nmlabs)) {
local_zones_del_data(zones, nm,
nmlen, nmlabs, LDNS_RR_CLASS_IN);
free(nm);
return 1;
}
ssl_printf(ssl, "error cannot parse rr %s at %d: %s\n", arg,
LDNS_WIREPARSE_OFFSET(status),
sldns_get_errorstr_parse(status));
return 0;
local_zones_del_data(zones, nm,
nmlen, nmlabs, LDNS_RR_CLASS_IN);
free(nm);
}
/* handle the rr case */
if (!perform_data_remove_rr(ssl, zones, rr, len, dname_len, arg))
return 0;
return 1;
}
@@ -2315,6 +2392,9 @@ zone_del_rrset(struct lruhash_entry* e, void* arg)
(struct packed_rrset_data*)e->data;
if(d->ttl > inf->expired) {
d->ttl = inf->expired;
if(d->ttl_add > inf->expired)
d->ttl_add = inf->expired; /* for 0TTL rrsets,
means that d->ttl_add <= d->ttl */
inf->num_rrsets++;
}
}
@@ -2601,7 +2681,7 @@ static int
ssl_print_name_dp(RES* ssl, const char* str, uint8_t* nm, uint16_t dclass,
struct delegpt* dp)
{
char buf[LDNS_MAX_DOMAINLEN];
char buf[LDNS_MAX_DOMAINLEN], portstr[128], tls_auth_name[256];
struct delegpt_ns* ns;
struct delegpt_addr* a;
int f = 0;
@@ -2616,13 +2696,32 @@ ssl_print_name_dp(RES* ssl, const char* str, uint8_t* nm, uint16_t dclass,
}
for(ns = dp->nslist; ns; ns = ns->next) {
dname_str(ns->name, buf);
if(!ssl_printf(ssl, "%s%s", (f?" ":""), buf))
if(ns->port != UNBOUND_DNS_PORT)
snprintf(portstr, sizeof(portstr), "@%d", ns->port);
else portstr[0]=0;
if(ns->tls_auth_name)
snprintf(tls_auth_name, sizeof(tls_auth_name), "#%s",
ns->tls_auth_name);
else tls_auth_name[0]=0;
if(!ssl_printf(ssl, "%s%s%s%s", (f?" ":""), buf, portstr,
tls_auth_name))
return 0;
f = 1;
}
for(a = dp->target_list; a; a = a->next_target) {
int port = (unsigned)((a->addr.ss_family == AF_INET) ?
ntohs(((struct sockaddr_in*)&a->addr)->sin_port) :
ntohs(((struct sockaddr_in6*)&a->addr)->sin6_port));
addr_to_str(&a->addr, a->addrlen, buf, sizeof(buf));
if(!ssl_printf(ssl, "%s%s", (f?" ":""), buf))
if(port != UNBOUND_DNS_PORT)
snprintf(portstr, sizeof(portstr), "@%d", port);
else portstr[0]=0;
if(a->tls_auth_name)
snprintf(tls_auth_name, sizeof(tls_auth_name), "#%s",
a->tls_auth_name);
else tls_auth_name[0]=0;
if(!ssl_printf(ssl, "%s%s%s%s", (f?" ":""), buf, portstr,
tls_auth_name))
return 0;
f = 1;
}
@@ -3238,6 +3337,10 @@ do_auth_zone_reload(RES* ssl, struct worker* worker, char* arg)
return;
}
if(!auth_zone_read_zonefile(z, worker->env.cfg)) {
/* The old tree was already cleared. Do not answer from the
* failed load. */
z->zone_expired = 1;
auth_zone_clear_data(z);
lock_rw_unlock(&z->lock);
if(xfr) {
lock_basic_unlock(&xfr->lock);
@@ -3249,6 +3352,7 @@ do_auth_zone_reload(RES* ssl, struct worker* worker, char* arg)
z->zone_expired = 0;
if(xfr) {
xfr->zone_expired = 0;
xfr->num_ixfrs = 0;
if(!xfr_find_soa(z, xfr)) {
if(z->data.count == 0) {
lock_rw_unlock(&z->lock);
@@ -4941,6 +5045,74 @@ fr_check_changed_cfg_str2list(struct config_str2list* cmp1,
}
}
/** fast reload thread, check if config str3list has changed. */
#define FR_CHECK_CHANGED_CFG_STR3LIST(desc, var, buff) do { \
fr_check_changed_cfg_str3list(cfg->var, newcfg->var, desc, buff,\
sizeof(buff)); \
} while(0);
static void
fr_check_changed_cfg_str3list(struct config_str3list* cmp1,
struct config_str3list* cmp2, const char* desc, char* str, size_t len)
{
struct config_str3list* p1 = cmp1, *p2 = cmp2;
while(p1 && p2) {
if((!p1->str && p2->str) ||
(p1->str && !p2->str) ||
(p1->str && p2->str && strcmp(p1->str, p2->str) != 0)) {
/* The str3list is different. */
fr_add_incompatible_option(desc, str, len);
return;
}
if((!p1->str2 && p2->str2) ||
(p1->str2 && !p2->str2) ||
(p1->str2 && p2->str2 &&
strcmp(p1->str2, p2->str2) != 0)) {
/* The str3list is different. */
fr_add_incompatible_option(desc, str, len);
return;
}
if((!p1->str3 && p2->str3) ||
(p1->str3 && !p2->str3) ||
(p1->str3 && p2->str3 &&
strcmp(p1->str3, p2->str3) != 0)) {
/* The str3list is different. */
fr_add_incompatible_option(desc, str, len);
return;
}
p1 = p1->next;
p2 = p2->next;
}
if((!p1 && p2) || (p1 && !p2)) {
fr_add_incompatible_option(desc, str, len);
}
}
/** fast reload thread, check tag datas. */
static int
fr_check_tag_datas(struct fast_reload_thread* fr, struct config_file* newcfg)
{
char changed_str[1024];
struct config_file* cfg = fr->worker->env.cfg;
changed_str[0]=0;
/* Check for tag_datas in acl_addr. */
FR_CHECK_CHANGED_CFG_STR3LIST("interface-tag-data", interface_tag_datas, changed_str);
FR_CHECK_CHANGED_CFG_STR3LIST("access-control-tag-data", acl_tag_datas, changed_str);
if(changed_str[0] != 0) {
if(fr->fr_drop_mesh)
return 1; /* already dropping queries */
fr->fr_drop_mesh = 1;
fr->worker->daemon->fast_reload_drop_mesh = fr->fr_drop_mesh;
if(!fr_output_printf(fr, "recursion referenced data has changed, with: '%s"
"', and the queries have to be dropped"
", setting '+d'\n", changed_str))
return 0;
fr_send_notification(fr, fast_reload_notification_printout);
}
return 1;
}
/** fast reload thread, check compatible config items */
static int
fr_check_compat_cfg(struct fast_reload_thread* fr, struct config_file* newcfg)
@@ -5477,6 +5649,23 @@ xfr_masterlist_equal(struct auth_master* list1, struct auth_master* list2)
return 0;
}
/** See if configuration has changed. */
static int
xfr_config_equal(struct auth_xfer* xfr1, struct auth_xfer* xfr2)
{
if(xfr1 == NULL && xfr2 == NULL)
return 1;
if(xfr1 == NULL && xfr2 != NULL)
return 0;
if(xfr1 != NULL && xfr2 == NULL)
return 0;
if(xfr1->max_transfer_size != xfr2->max_transfer_size)
return 0;
if(xfr1->max_transfer_time != xfr2->max_transfer_time)
return 0;
return 1;
}
/** See if the list of masters has changed. */
static int
xfr_masters_equal(struct auth_xfer* xfr1, struct auth_xfer* xfr2)
@@ -5565,8 +5754,31 @@ auth_zones_check_changes(struct fast_reload_thread* fr,
&old_serial)!=0);
have_new = (auth_zone_get_serial(new_z,
&new_serial)!=0);
/* A change in primaries, also means it is different
* and the change makes it fire new transfers, from
* the new primaries. */
/* Treat as changed when the old zone has an
* outstanding ZONEMD DS/DNSKEY mesh callback.
* This will make the worker pickup change code
* remove the mesh callback, before the old zone is
* deleted. Also it makes a new zonemd lookup.
* The new lookup is needed, because the new zone
* entry needs to have a valid zonemd result,
* and if that is bad, needs to be invalidated.
* Also if there is a race event where the
* outstanding callback makes the zone invalid,
* before fast-reload completes, the change makes
* the new zone entry have a new zonemd lookup,
* to then invalidate that new zone.
* There is also a brief operational window at
* program start when a zonemd has to be looked
* up on-line, where the zone is operational.
* And this copies that for such a race event.
*/
if(have_old != have_new || old_serial != new_serial
|| !xfr_masters_equal(old_xfr, new_xfr)) {
|| !xfr_masters_equal(old_xfr, new_xfr)
|| !xfr_config_equal(old_xfr, new_xfr)
|| old_z->zonemd_callback_env != NULL) {
/* The zone has been changed. */
if(!fr_add_auth_zone_change(fr, old_z, new_z,
0, 0, 1)) {
@@ -5639,6 +5851,8 @@ ct_create_sslctxs(struct fast_reload_construct* ct,
/* Leave listen ctxs and file str at NULL */
ct->connect_dot_sslctx = daemon_setup_connect_dot_sslctx(
daemon, newcfg);
if(!ct->connect_dot_sslctx)
return 0;
return 1;
}
@@ -5648,20 +5862,28 @@ ct_create_sslctxs(struct fast_reload_construct* ct,
pem += strlen(chroot);
ct->listen_dot_sslctx = daemon_setup_listen_dot_sslctx(daemon, newcfg);
if(!ct->listen_dot_sslctx)
return 0;
#ifdef HAVE_NGHTTP2_NGHTTP2_H
if(cfg_has_https(newcfg)) {
ct->listen_doh_sslctx = daemon_setup_listen_doh_sslctx(
daemon, newcfg);
if(!ct->listen_doh_sslctx)
return 0;
}
#endif
#ifdef HAVE_NGTCP2
if(cfg_has_quic(newcfg)) {
ct->listen_quic_sslctx = daemon_setup_listen_quic_sslctx(
daemon, newcfg);
if(!ct->listen_quic_sslctx)
return 0;
}
#endif /* HAVE_NGTCP2 */
ct->connect_dot_sslctx = daemon_setup_connect_dot_sslctx(daemon,
newcfg);
if(!ct->connect_dot_sslctx)
return 0;
/* Store mtime and names */
ct->ssl_service_key = strdup(newcfg->ssl_service_key);
@@ -6631,9 +6853,12 @@ fr_reload_config(struct fast_reload_thread* fr, struct config_file* newcfg,
}
#ifdef USE_DNSTAP
if(env->cfg->dnstap) {
if(!fr->fr_nopause)
dt_apply_cfg(daemon->dtenv, env->cfg);
else dt_apply_logcfg(daemon->dtenv, env->cfg);
if(!fr->fr_nopause) {
if(!dt_apply_cfg(daemon->dtenv, env->cfg))
log_warn("fast_reload: dnstap identity/version metadata not updated due to allocation failure");
} else {
dt_apply_logcfg(daemon->dtenv, env->cfg);
}
}
#endif
fr_adjust_cache(env, ct->oldcfg);
@@ -6773,6 +6998,10 @@ fr_load_config(struct fast_reload_thread* fr, struct timeval* time_read,
config_delete(newcfg);
return 0;
}
if(!fr_check_tag_datas(fr, newcfg)) {
config_delete(newcfg);
return 0;
}
if(!fr_check_compat_cfg(fr, newcfg)) {
config_delete(newcfg);
return 0;
@@ -6864,7 +7093,7 @@ static void* fast_reload_thread_main(void* arg)
#endif
log_thread_set(&fast_reload_thread->threadnum);
ub_thread_setname(fast_reload_thread->tid, name);
ub_thread_setname(ub_thread_self(), name);
(void)name; /* When setname is not defined, ignore the name variable. */
verbose(VERB_ALGO, "start fast reload thread");
@@ -7587,7 +7816,8 @@ auth_zone_zonemd_stop_lookup(struct auth_zone* z, struct mesh_area* mesh)
qinfo.local_alias = NULL;
mesh_remove_callback(mesh, &qinfo, qflags,
&auth_zonemd_dnskey_lookup_callback, z);
&auth_zonemd_dnskey_lookup_callback, z,
z->zonemd_callback_unique_info);
}
/** Pick up the auth zone locks. */
@@ -7696,6 +7926,9 @@ auth_xfr_pickup_config(struct auth_xfer* loadxfr, struct auth_xfer* xfr)
log_assert(loadxfr->namelabs == xfr->namelabs);
log_assert(loadxfr->dclass == xfr->dclass);
xfr->max_transfer_size = loadxfr->max_transfer_size;
xfr->max_transfer_time = loadxfr->max_transfer_time;
/* The lists can be swapped in, the other xfr struct will be deleted
* afterwards. */
probe_masters = xfr->task_probe->masters;
@@ -7720,6 +7953,16 @@ fr_worker_auth_add(struct worker* worker, struct fast_reload_auth_change* item,
/* The xfr item needs to be created. The auth zones lock
* is held to make this possible. */
xfr = auth_xfer_create(worker->env.auth_zones, item->new_z);
if(!xfr) {
log_err("out of memory in fr_worker_auth_add");
lock_rw_unlock(&item->new_z->lock);
lock_rw_unlock(&worker->env.auth_zones->lock);
lock_rw_unlock(&worker->daemon->fast_reload_thread->old_auth_zones->lock);
if(loadxfr) {
lock_basic_unlock(&loadxfr->lock);
}
return;
}
auth_xfr_pickup_config(loadxfr, xfr);
/* Serial information is copied into the xfr struct. */
if(!xfr_find_soa(item->new_z, xfr)) {
@@ -7789,6 +8032,17 @@ fr_worker_auth_cha(struct worker* worker, struct fast_reload_auth_change* item)
} else if(loadxfr && !xfr) {
/* Create the xfr. */
xfr = auth_xfer_create(worker->env.auth_zones, item->new_z);
if(!xfr) {
log_err("out of memory in fr_worker_auth_cha");
lock_rw_unlock(&item->new_z->lock);
lock_rw_unlock(&item->old_z->lock);
lock_rw_unlock(&worker->daemon->fast_reload_thread->old_auth_zones->lock);
lock_rw_unlock(&worker->env.auth_zones->lock);
if(loadxfr) {
lock_basic_unlock(&loadxfr->lock);
}
return;
}
auth_xfr_pickup_config(loadxfr, xfr);
item->new_z->zone_is_slave = 1;
}
+1 -7
View File
@@ -49,6 +49,7 @@
#include <openssl/ssl.h>
#endif
#include "util/locks.h"
#include "libunbound/remote.h"
struct config_file;
struct listen_list;
struct listen_port;
@@ -365,13 +366,6 @@ void fast_reload_thread_start(RES* ssl, struct worker* worker,
*/
void fast_reload_thread_stop(struct fast_reload_thread* fast_reload_thread);
/** fast reload thread commands to remote service thread event callback */
void fast_reload_service_cb(int fd, short bits, void* arg);
/** fast reload callback for the remote control client connection */
int fast_reload_client_callback(struct comm_point* c, void* arg, int err,
struct comm_reply* rep);
/** fast reload printq delete list */
void fast_reload_printq_list_delete(struct fast_reload_printq* list);
+22 -6
View File
@@ -422,12 +422,28 @@ void server_stats_obtain(struct worker* worker, struct worker* who,
# endif
#endif
);
log_err("server_stats_obtain: no response from worker %d "
"(stats timeout); returning zero stats for this worker",
who->thread_num);
/* A later reply from the worker, would be sizeof stats reply,
* and the worker_handle_control_cmd routine discards if
* it is not a 4byte command, when that is received here. */
memset(s, 0, sizeof(*s));
return;
}
if(!tube_read_msg(worker->cmd, &reply, &len, 0)) {
log_err("server_stats_obtain: failed to read stats from worker "
"(tube read error); returning zero stats for this worker");
memset(s, 0, sizeof(*s));
return;
}
if(len != (uint32_t)sizeof(*s)) {
log_err("server_stats_obtain: wrong stats length %d (expected %d); "
"discarding", (int)len, (int)sizeof(*s));
free(reply);
memset(s, 0, sizeof(*s));
return;
}
if(!tube_read_msg(worker->cmd, &reply, &len, 0))
fatal_exit("failed to read stats over cmd channel");
if(len != (uint32_t)sizeof(*s))
fatal_exit("stats on cmd channel wrong length %d %d",
(int)len, (int)sizeof(*s));
memcpy(s, reply, (size_t)len);
free(reply);
}
@@ -439,7 +455,7 @@ void server_stats_reply(struct worker* worker, int reset)
verbose(VERB_ALGO, "write stats replymsg");
if(!tube_write_msg(worker->daemon->workers[0]->cmd,
(uint8_t*)&s, sizeof(s), 0))
fatal_exit("could not write stat values over cmd channel");
log_err("could not write stat values over cmd channel");
}
void server_stats_add(struct ub_stats_info* total, struct ub_stats_info* a)
+28 -13
View File
@@ -501,7 +501,9 @@ worker_handle_control_cmd(struct tube* ATTR_UNUSED(tube), uint8_t* msg,
return;
}
if(len != sizeof(uint32_t)) {
fatal_exit("bad control msg length %d", (int)len);
verbose(VERB_ALGO, "bad control msg length %d", (int)len);
free(msg);
return;
}
cmd = sldns_read_uint32(msg);
free(msg);
@@ -714,7 +716,8 @@ apply_respip_action(struct worker* worker, const struct query_info* qinfo,
struct respip_client_info* cinfo, struct reply_info* rep,
struct sockaddr_storage* addr, socklen_t addrlen,
struct ub_packed_rrset_key** alias_rrset,
struct reply_info** encode_repp, struct auth_zones* az)
struct reply_info** encode_repp, struct auth_zones* az,
int* rpz_passthru)
{
struct respip_action_info actinfo = {0, 0, 0, 0, NULL, 0, NULL};
actinfo.action = respip_none;
@@ -725,7 +728,7 @@ apply_respip_action(struct worker* worker, const struct query_info* qinfo,
return 1;
if(!respip_rewrite_reply(qinfo, cinfo, rep, encode_repp, &actinfo,
alias_rrset, 0, worker->scratchpad, az, NULL,
alias_rrset, 0, worker->scratchpad, az, rpz_passthru,
worker->env.views, worker->env.respip_set))
return 0;
@@ -772,7 +775,7 @@ answer_from_cache(struct worker* worker, struct query_info* qinfo,
int* is_secure_answer, struct ub_packed_rrset_key** alias_rrset,
struct reply_info** partial_repp,
struct reply_info* rep, uint16_t id, uint16_t flags,
struct comm_reply* repinfo, struct edns_data* edns)
struct comm_reply* repinfo, struct edns_data* edns, int* rpz_passthru)
{
time_t timenow = *worker->env.now;
uint16_t udpsize = edns->udp_size;
@@ -882,7 +885,7 @@ answer_from_cache(struct worker* worker, struct query_info* qinfo,
if((worker->daemon->use_response_ip || worker->daemon->use_rpz) &&
!partial_rep && !apply_respip_action(worker, qinfo, cinfo, rep,
&repinfo->client_addr, repinfo->client_addrlen, alias_rrset,
&encode_rep, worker->env.auth_zones)) {
&encode_rep, worker->env.auth_zones, rpz_passthru)) {
goto bail_out;
} else if(partial_rep &&
!respip_merge_cname(partial_rep, qinfo, rep, cinfo,
@@ -1494,6 +1497,8 @@ worker_handle_request(struct comm_point* c, void* arg, int error,
struct reply_info* partial_rep = NULL;
struct query_info* lookup_qinfo = &qinfo;
struct query_info qinfo_tmp; /* placeholder for lookup_qinfo */
uint8_t* alias_orig_qname = NULL; /* original qname for logs, if
a local_alias is used to change the qname. */
struct respip_client_info* cinfo = NULL, cinfo_tmp;
struct timeval wait_time;
struct check_request_result check_result = {0,0};
@@ -1511,7 +1516,7 @@ worker_handle_request(struct comm_point* c, void* arg, int error,
if (worker->stats.max_query_time_us < wait_queue_time)
worker->stats.max_query_time_us = wait_queue_time;
if(wait_queue_time >
(long long)(worker->env.cfg->sock_queue_timeout * 1000000)) {
(long long)worker->env.cfg->sock_queue_timeout * 1000000) {
/* count and drop queries that were sitting in the socket queue too long */
worker->stats.num_queries_timed_out++;
return 0;
@@ -1936,6 +1941,11 @@ worker_handle_request(struct comm_point* c, void* arg, int error,
/* If we've found a local alias, replace the qname with the alias
* target before resolving it. */
if(qinfo.local_alias) {
if(qinfo.local_alias->rrset &&
qinfo.local_alias->rrset->rk.dname)
/* Store the original qname, used for logs, since
* local_alias can be removed by region_free_all. */
alias_orig_qname = qinfo.local_alias->rrset->rk.dname;
if(!local_alias_shallow_copy_qname(qinfo.local_alias, &qinfo.qname,
&qinfo.qname_len)) {
regional_free_all(worker->scratchpad);
@@ -1983,7 +1993,7 @@ lookup_cache:
&alias_rrset, &partial_rep, rep,
*(uint16_t*)(void *)sldns_buffer_begin(c->buffer),
sldns_buffer_read_u16_at(c->buffer, 2), repinfo,
&edns)) {
&edns, &rpz_passthru)) {
/* prefetch it if the prefetch TTL expired.
* Note that if there is more than one pass
* its qname must be that used for cache
@@ -2101,11 +2111,10 @@ send_reply_rc:
{
struct timeval tv;
memset(&tv, 0, sizeof(tv));
if(qinfo.local_alias && qinfo.local_alias->rrset &&
qinfo.local_alias->rrset->rk.dname) {
if(alias_orig_qname) {
/* log original qname, before the local alias was
* used to resolve that CNAME to something else */
qinfo.qname = qinfo.local_alias->rrset->rk.dname;
qinfo.qname = alias_orig_qname;
log_reply_info(NO_VERBOSE, &qinfo,
&repinfo->client_addr, repinfo->client_addrlen,
tv, 1, c->buffer,
@@ -2374,6 +2383,8 @@ worker_init(struct worker* worker, struct config_file *cfg,
worker_stat_timer_cb, worker);
if(!worker->stat_timer) {
log_err("could not create statistics timer");
worker_delete(worker);
return 0;
}
/* we use the msg_buffer_size as a good estimate for what the
@@ -2526,6 +2537,8 @@ worker_delete(struct worker* worker)
/* don't touch worker->alloc, as it's maintained in daemon */
regional_destroy(worker->env.scratch);
regional_destroy(worker->scratchpad);
/* The thread id can reference this worker's id value, so clear it. */
log_thread_set(NULL);
free(worker);
}
@@ -2534,7 +2547,8 @@ worker_send_query(struct query_info* qinfo, uint16_t flags, int dnssec,
int want_dnssec, int nocaps, int check_ratelimit,
struct sockaddr_storage* addr, socklen_t addrlen, uint8_t* zone,
size_t zonelen, int tcp_upstream, int ssl_upstream, char* tls_auth_name,
struct module_qstate* q, int* was_ratelimited)
struct module_qstate* q, int* was_ratelimited,
int* ratelimit_incremented)
{
struct worker* worker = q->env->worker;
struct outbound_entry* e = (struct outbound_entry*)regional_alloc(
@@ -2546,7 +2560,7 @@ worker_send_query(struct query_info* qinfo, uint16_t flags, int dnssec,
want_dnssec, nocaps, check_ratelimit, tcp_upstream,
ssl_upstream, tls_auth_name, addr, addrlen, zone, zonelen, q,
worker_handle_service_reply, e, worker->back->udp_buff, q->env,
was_ratelimited);
was_ratelimited, ratelimit_incremented);
if(!e->qsent) {
return NULL;
}
@@ -2595,7 +2609,8 @@ struct outbound_entry* libworker_send_query(
struct sockaddr_storage* ATTR_UNUSED(addr), socklen_t ATTR_UNUSED(addrlen),
uint8_t* ATTR_UNUSED(zone), size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream),
int ATTR_UNUSED(ssl_upstream), char* ATTR_UNUSED(tls_auth_name),
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited))
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited),
int* ATTR_UNUSED(ratelimit_incremented))
{
log_assert(0);
return 0;
+59 -8
View File
@@ -643,6 +643,12 @@ handle_event_moddone(struct module_qstate* qstate, int id)
qstate->return_msg->rep &&
reply_find_answer_rrset(&qstate->qinfo, qstate->return_msg->rep);
int synth_qname = 0;
if(could_synth && !has_data && qstate->env->need_to_validate &&
qstate->return_msg && qstate->return_msg->rep &&
qstate->return_msg->rep->security == sec_status_bogus) {
verbose(VERB_ALGO, "dns64: bogus AAAA reply not synthesized");
could_synth = 0;
}
if(could_synth &&
(!has_data ||
@@ -654,8 +660,11 @@ handle_event_moddone(struct module_qstate* qstate, int id)
/* Store the response in cache. */
if( (!iq || !iq->started_no_cache_store) &&
!qstate->rpz_applied && !qstate->rpz_passthru &&
!qstate->is_subnet_answer &&
qstate->return_msg &&
qstate->return_msg->rep &&
!qstate->fwd_stub_no_cache &&
!dns_cache_store(
qstate->env, &qstate->qinfo, qstate->return_msg->rep,
0, qstate->prefetch_leeway, 0, NULL,
@@ -717,8 +726,15 @@ dns64_operate(struct module_qstate* qstate, enum module_ev event, int id,
}
if(qstate->ext_state[id] == module_finished) {
iq = (struct dns64_qstate*)qstate->minfo[id];
if(iq && iq->state != DNS64_INTERNAL_QUERY)
qstate->no_cache_store = iq->started_no_cache_store;
if(iq && iq->state != DNS64_INTERNAL_QUERY) {
if(qstate->fwd_stub_no_cache) {
/* If the forward/stub has no cache, then
* continue with the query with no cache. */
qstate->no_cache_store = qstate->fwd_stub_no_cache;
} else {
qstate->no_cache_store = iq->started_no_cache_store;
}
}
}
}
@@ -825,6 +841,7 @@ dns64_adjust_a(int id, struct module_qstate* super, struct module_qstate* qstate
size_t i, s;
struct packed_rrset_data* fd, *dd;
struct ub_packed_rrset_key* fk, *dk;
int allocated_return_msg = 0;
verbose(VERB_ALGO, "converting A answers to AAAA answers");
@@ -840,6 +857,7 @@ dns64_adjust_a(int id, struct module_qstate* super, struct module_qstate* qstate
return;
memset(super->return_msg, 0, sizeof(*super->return_msg));
super->return_msg->qinfo = super->qinfo;
allocated_return_msg = 1;
}
rep = qstate->return_msg->rep;
@@ -852,11 +870,14 @@ dns64_adjust_a(int id, struct module_qstate* super, struct module_qstate* qstate
rep->serve_expired_norec_ttl,
rep->an_numrrsets, rep->ns_numrrsets, rep->ar_numrrsets,
rep->rrset_count, rep->security, LDNS_EDE_NONE);
if(!cp)
if(!cp) {
if(allocated_return_msg) super->return_msg = NULL;
return;
}
/* allocate ub_key structures special or not */
if(!reply_info_alloc_rrset_keys(cp, NULL, super->region)) {
if(allocated_return_msg) super->return_msg = NULL;
return;
}
@@ -871,8 +892,10 @@ dns64_adjust_a(int id, struct module_qstate* super, struct module_qstate* qstate
if(i<rep->an_numrrsets && fk->rk.type == htons(LDNS_RR_TYPE_A)) {
/* also sets dk->entry.hash */
dns64_synth_aaaa_data(fk, fd, dk, &dd, super->region, dns64_env);
if(!dd)
if(!dd) {
if(allocated_return_msg) super->return_msg = NULL;
return;
}
/* Delete negative AAAA record from cache stored by
* the iterator module */
rrset_cache_remove(super->env->rrset_cache, dk->rk.dname,
@@ -889,15 +912,19 @@ dns64_adjust_a(int id, struct module_qstate* super, struct module_qstate* qstate
dk->rk.dname = (uint8_t*)regional_alloc_init(super->region,
fk->rk.dname, fk->rk.dname_len);
if(!dk->rk.dname)
if(!dk->rk.dname) {
if(allocated_return_msg) super->return_msg = NULL;
return;
}
s = packed_rrset_sizeof(fd);
dd = (struct packed_rrset_data*)regional_alloc_init(
super->region, fd, s);
if(!dd)
if(!dd) {
if(allocated_return_msg) super->return_msg = NULL;
return;
}
}
packed_rrset_ptr_fixup(dd);
@@ -928,8 +955,10 @@ dns64_adjust_ptr(struct module_qstate* qstate, struct module_qstate* super)
return;
super->return_msg->qinfo = super->qinfo;
if (!(super->return_msg->rep = reply_info_copy(qstate->return_msg->rep,
NULL, super->region)))
NULL, super->region))) {
super->return_msg = NULL;
return;
}
/*
* Adjust the domain name of the answer RR set so that it matches the
@@ -998,6 +1027,21 @@ dns64_inform_super(struct module_qstate* qstate, int id,
/* Use return code from A query in response to client. */
if (super->return_rcode != LDNS_RCODE_NOERROR)
super->return_rcode = qstate->return_rcode;
/* RPZ applied to the subquery need to then change (not cache)
* the super query. With the super query not cached, it is
* going to run the state machine modules on incoming queries,
* that fetch the subquery (cache) response, and modify it
* according to the rpz policy. That makes the synthesized
* super query also adjusted by rpz policies. But loses cache
* hits. Even though the subquery likely is answered from cache,
* internally in its state machine process. */
if(qstate->rpz_applied)
super->rpz_applied = 1;
if(qstate->rpz_passthru)
super->rpz_passthru = 1;
/* Since the super qstate has a new response, its errinf is removed. */
super->errinf = NULL;
/* Generate a response suitable for the original query. */
if (qstate->qinfo.qtype == LDNS_RR_TYPE_A) {
@@ -1006,9 +1050,16 @@ dns64_inform_super(struct module_qstate* qstate, int id,
log_assert(qstate->qinfo.qtype == LDNS_RR_TYPE_PTR);
dns64_adjust_ptr(qstate, super);
}
/* If the sub-query has no cache store, then also the super query. */
if(qstate->fwd_stub_no_cache)
super->fwd_stub_no_cache = 1;
/* Store the generated response in cache. */
if ( (!super_dq || !super_dq->started_no_cache_store) &&
if ( super->return_msg && super->return_msg->rep &&
(!super_dq || !super_dq->started_no_cache_store) &&
!qstate->fwd_stub_no_cache &&
!super->rpz_applied && !super->rpz_passthru &&
!super->is_subnet_answer &&
!dns_cache_store(super->env, &super->qinfo, super->return_msg->rep,
0, super->prefetch_leeway, 0, NULL, super->query_flags,
qstate->qstarttime, qstate->is_valrec))
+8 -1
View File
@@ -842,7 +842,14 @@ dnsc_parse_keys(struct dnsc_env *env, struct config_file *cfg)
if(memcmp(current_keypair->crypt_publickey,
env->signed_certs[c].server_publickey,
crypto_box_PUBLICKEYBYTES) == 0) {
dnsccert *current_cert = &env->certs[cert_id++];
dnsccert* current_cert;
if(cert_id >= env->signed_certs_count) {
log_err("dnscrypt: secret key %s matches a cert that "
"is already bound to another key (duplicate "
"dnscrypt-secret-key?)", head->str);
return -1;
}
current_cert = &env->certs[cert_id++];
found_cert = 1;
current_cert->keypair = current_keypair;
memcpy(current_cert->magic_query,
+36 -17
View File
@@ -176,26 +176,29 @@ dt_create(struct config_file* cfg)
env->dtio = dt_io_thread_create();
if(!env->dtio) {
log_err("malloc failure");
free(env);
dt_delete(env);
return NULL;
}
if(!dt_io_thread_apply_cfg(env->dtio, cfg)) {
dt_io_thread_delete(env->dtio);
free(env);
dt_delete(env);
return NULL;
}
if(!dt_apply_cfg(env, cfg)) {
dt_delete(env);
return NULL;
}
dt_apply_cfg(env, cfg);
return env;
}
static void
static int
dt_apply_identity(struct dt_env *env, struct config_file *cfg)
{
char buf[MAXHOSTNAMELEN+1];
if (!cfg->dnstap_send_identity) {
free(env->identity);
env->identity = NULL;
return;
env->len_identity = 0;
return 1;
}
free(env->identity);
if (cfg->dnstap_identity == NULL || cfg->dnstap_identity[0] == 0) {
@@ -203,36 +206,49 @@ dt_apply_identity(struct dt_env *env, struct config_file *cfg)
buf[MAXHOSTNAMELEN] = 0;
env->identity = strdup(buf);
} else {
fatal_exit("dt_apply_identity: gethostname() failed");
log_err("dt_apply_identity: gethostname() failed: %s",
strerror(errno));
env->identity = NULL;
env->len_identity = 0;
return 0;
}
} else {
env->identity = strdup(cfg->dnstap_identity);
}
if (env->identity == NULL)
fatal_exit("dt_apply_identity: strdup() failed");
if (env->identity == NULL) {
log_err("dt_apply_identity: strdup() failed");
env->len_identity = 0;
return 0;
}
env->len_identity = (unsigned int)strlen(env->identity);
verbose(VERB_OPS, "dnstap identity field set to \"%s\"",
env->identity);
return 1;
}
static void
static int
dt_apply_version(struct dt_env *env, struct config_file *cfg)
{
if (!cfg->dnstap_send_version) {
free(env->version);
env->version = NULL;
return;
env->len_version = 0;
return 1;
}
free(env->version);
if (cfg->dnstap_version == NULL || cfg->dnstap_version[0] == 0)
env->version = strdup(PACKAGE_STRING);
else
env->version = strdup(cfg->dnstap_version);
if (env->version == NULL)
fatal_exit("dt_apply_version: strdup() failed");
if (env->version == NULL) {
log_err("dt_apply_version: strdup() failed");
env->len_version = 0;
return 0;
}
env->len_version = (unsigned int)strlen(env->version);
verbose(VERB_OPS, "dnstap version field set to \"%s\"",
env->version);
return 1;
}
void
@@ -276,15 +292,18 @@ dt_apply_logcfg(struct dt_env *env, struct config_file *cfg)
lock_basic_unlock(&env->sample_lock);
}
void
int
dt_apply_cfg(struct dt_env *env, struct config_file *cfg)
{
if (!cfg->dnstap)
return;
return 1;
dt_apply_identity(env, cfg);
dt_apply_version(env, cfg);
dt_apply_logcfg(env, cfg);
if(!dt_apply_identity(env, cfg))
return 0;
if(!dt_apply_version(env, cfg))
return 0;
return 1;
}
int
+2 -2
View File
@@ -102,9 +102,9 @@ dt_create(struct config_file* cfg);
* Apply config settings.
* @param env: dnstap environment object.
* @param cfg: new config settings.
* @return false on failure.
*/
void
dt_apply_cfg(struct dt_env *env, struct config_file *cfg);
int dt_apply_cfg(struct dt_env *env, struct config_file *cfg);
/**
* Apply config settings for log enable for message types.
+1 -1
View File
@@ -2144,7 +2144,7 @@ static void* dnstap_io(void* arg)
#endif
log_thread_set(&dtio->threadnum);
ub_thread_setname(dtio->tid, name);
ub_thread_setname(ub_thread_self(), name);
/* setup */
verbose(VERB_ALGO, "start dnstap io thread");
+4 -2
View File
@@ -1659,7 +1659,8 @@ struct outbound_entry* worker_send_query(
socklen_t ATTR_UNUSED(addrlen), uint8_t* ATTR_UNUSED(zone),
size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream),
int ATTR_UNUSED(ssl_upstream), char* ATTR_UNUSED(tls_auth_name),
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited))
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited),
int* ATTR_UNUSED(ratelimit_incremented))
{
log_assert(0);
return 0;
@@ -1693,7 +1694,8 @@ struct outbound_entry* libworker_send_query(
socklen_t ATTR_UNUSED(addrlen), uint8_t* ATTR_UNUSED(zone),
size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream),
int ATTR_UNUSED(ssl_upstream), char* ATTR_UNUSED(tls_auth_name),
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited))
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited),
int* ATTR_UNUSED(ratelimit_incremented))
{
log_assert(0);
return 0;
+622
View File
@@ -1,3 +1,552 @@
11 August 2026: Wouter
- Fix #1492 from zacek: Data race in log_init() on
key_created/log_lock when calling ub_ctx_create()
concurrently from multiple threads.
- Fix stat_values.tdir test to have less test failures.
7 August 2026: Wouter
- Fix #1489 from jplesnik: Replace removed Python 2 C API
macros for SWIG 4.5.0 compatibility.
6 August 2026: Alex Khanin
- Fix #1488: bounds check in packed_rr_to_string, it checked
the assembled rr length against the output string length
dest_len, instead of against the size of the rr buffer it
writes into. Callers in cachedump.c and remote.c pass a
dest_len larger than that buffer.
- Unit test for packed_rr_to_string.
6 August 2026: Wouter
- Fix #1485: the list_forwards command omits port numbers.
The list_forwards and list_stubs commands for
unbound-control print port and tls auth name.
- Fix #1487: regression in 1.26.0, ipsecmod is now always
partly enabled.
4 August 2026: Wouter
- Fix to set makedist.sh to not wget config.sub and
config.guess from git repo. The fetch times out, and the
version from libtoolize is much more recent now than
that it was when the wget was added.
31 July 2026: Wouter
- For #1483: The failure reason when an NSEC NXDOMAIN is
encountered when looking for an insecure delegation, is
fixed to mention the NSEC records, instead of nonexistent
NSEC3 records, that it attempted.
30 July 2026: Wouter
- Fix #1482: DNS-over-QUIC doesn't work with simple config.
That fixes interface-automatic for use with doq service.
28 July 2026: Wouter
- Tag for 1.26.0rc1. The repo continues with version 1.26.1.
This became 1.26.0 on 4 aug 2026.
24 July 2026: Wouter
- Merge #1433 from jisakiel: Add new static zone type
block_aaaa to suppress AAAA queries.
- Unit test for block_a and block_aaaa.
- Fix #1477: respip + dns64: dns64 uses A records modified by
respip instead of original A records. Adds local-zone types
block_a_wdata and block_aaaa_wdata, that are like block_a
and block_aaaa, and uses local-data if present.
- set code repository version to 1.26.0.
- Update generated man pages.
- Fix to allow test fake sha1 on systems with possible sha1
support.
- Fix to use sha256 for unbound-anchor unit test.
- Fix unbound-anchor check for return value of
X509_NAME_get_text_by_NID of the emailaddress.
- Fix lock test protect for auth zone change.
- Fix to lock shared_ports structure during initialisation.
- Fix to lock anchor structure when file is set for it in
parse of the header.
- Merge #1480 from petrvaganoff: authzone: fix memory leak in
xfer_set_masters() error path.
- Fix unused variable warnings in shared_ports_fetch_random
and shared_ports_return_port when compiled without threads.
- Fix to guard access to shared ports interface array during
set up, for analyzer.
- Fix sign of comparison warning in shared ports setup.
- Fix #1481: Fix to use tls-port after referral if
tls-upstream is set.
- Merge #1479 from psumbera: Fix pthread detection on
Solaris 11.4.
- Fix to call OPENSSL_cleanup on exit when that is defined.
23 July 2026: Wouter
- Updated credits for Xuanchao Xie in 22 july changelog.
- Merge #1478 from petrvaganoff: pythonmod: add check return
value after ftell().
- Fix that for NSEC3 proofs the NSEC3 zone, as the b32.name is
checked to be the same as the signer name. Also RRSIGs are
not considered valid when an NSEC3 is not b32.signerzone.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that the aggressive negative cache does not insert NSEC
records with overreaching next owner name. Also the result
is not above the trust anchor's bailiwick. Also RRSIGS are
not considered valid when an NSEC next owner name is not
under the signer zone name. Thanks to Qifan Zhang, Palo
Alto Networks, for the report.
- Fix mesh cycle detection for configuration with respip CNAME
loop and tagged clients. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
22 July 2026: Wouter
- Release tag for 1.25.2, with the security commits:
- Fix CVE-2026-14586, Assertion in libngtcp2 when under pressure
in high concurrency DNS-over-QUIC environments. Thanks to Kunta
Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University,
for the report.
- Fix CVE-2026-32665, Remote DNS-over-QUIC denial of
service due to `quic-size` budget bypass. Thanks to N0zoM1z0
(https://github.com/N0zoM1z0) for the report. In addition, thanks to
Kunta Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University,
for also reporting this issue. In addition, thanks to Qifan Zhang,
Palo Alto Networks, for also reporting this issue. In addition,
thanks to Xuanchao Xie, Lutong Chen, and Kaiping Xue of the
University of Science and Technology of China (USTC), for also
reporting this issue.
- Fix CVE-2026-40691, Packet of death for DNSCrypt over TCP. Thanks
to Qifan Zhang, Palo Alto Networks, for the report. In addition,
thanks to Trung Nguyen (@everping) of CyStack, for also reporting
this issue.
- Fix CVE-2026-41637, Degradation of resolution service from
improperly accounted client-terminated DNS-over-QUIC queries. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
- Fix CVE-2026-42955, Extra fix for CVE-2026-40622 to also clamp
the TTL of A/AAAA records disallowing a one-time 'ghost domain'
delegation renewal via glue records. Thanks to Qifan Zhang, Palo
Alto Networks, for the report.
- Fix CVE-2026-44621, Libunbound applications configured with
'unwanted-reply-threshold' could eventually be abruptly
terminated. Thanks to Qifan Zhang, Palo Alto Networks, for the
report.
- Fix CVE-2026-44687, Off-by-one error in 'harden-below-nxdomain'
logic can shadow a stub/forward zone by a legitimate parent's
NXDOMAIN. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix CVE-2026-44690, Cross-zone wildcard cache poisoning via
RRSIG.labels manipulation. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix CVE-2026-46582, A wildcard replay, as another piece of data,
triggers poisoning in the serve expired reply path. Thanks to
Qifan Zhang, Palo Alto Networks, for the report.
- Fix CVE-2026-50045, 'max-global-quota' reset by DNSSEC validation
restarts. Thanks to Kunjie Shang, University of Science and
Technology of China, for the report.
- Fix CVE-2026-50046, Possible heap use-after-free in an error path
when a DoT forwarded query is jostled out. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
- Fix CVE-2026-50243, 'response-ip'/'rpz' can rewrite BOGUS answers
instead of returning SERVFAIL. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix CVE-2026-50248, BOGUS configured primary hostname accepted for
XFR in auth/rpz zones. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix CVE-2026-50251, Attacker supplied `0.0.0.0`/`::` glue triggers
defensive full-cache flush. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix CVE-2026-50252, Possible cache poisoning attack by mapping
source port population per thread. Thanks to Inbal Schussheim and
Amit Klein, Hebrew University, for the report.
- Fix CVE-2026-52863, Memory corruption could lead to crash and
denial of service. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix CVE-2026-54478, DNS Cookie bypass when combined with
proxy-protocol use. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix CVE-2026-55708, Privacy/configuration issue when adding local
data in views through 'unbound-control'. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
- Fix CVE-2026-55717, 'serve-expired-client-timeout' and 'response-ip'
CNAME redirect could lead to a crash. Thanks to Qifan Zhang, Palo
Alto Networks, for the report. In addition, thanks to Xin Wang,
Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University,
for also reporting this issue.
- Fix CVE-2026-55973, 'dns-error-reporting: yes' leads to stack buffer
overflow. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix CVE-2026-55990, Packet of death for a DNSCrypt misconfigured
Unbound. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix CVE-2026-55991, Remote DNS-over-QUIC (DoQ) flow-control
assertion failure in libngtcp2. Thanks to Qifan Zhang, Palo Alto
Networks, for the report. In addition, thanks to Xuanchao Xie,
Lutong Chen, and Kaiping Xue of the University of Science and
Technology of China (USTC), for also reporting this issue.
- Fix CVE-2026-56416, Possible heap buffer overflow when validator
canonicalizes RDATA that contains domain name. Thanks to Qifan
Zhang, Palo Alto Networks, for the report.
- Fix CVE-2026-56444, Degradation of resolution service when
'discard-timeout' and 'serve-expired-client-timeout' are combined in
unusual configuration. Thanks to Qifan Zhang, Palo Alto Networks,
for the report. In addition, thanks to Xin Wang, Jiapeng Li,
and Jiajia Liu, Northwestern Polytechnical University, for also
reporting this issue. In addition, thanks to Haruki Oyama (Waseda
University), for also reporting this issue.
- Set the repository to 1.25.3, it continues with the previous
changes.
- Unit test for CVE-2026-42955.
- Unit test for CVE-2026-44687.
- Unit test for CVE-2026-44690.
- Unit test for CVE-2026-46582.
- Unit test for CVE-2026-50045.
- Unit test for CVE-2026-50243.
- Unit test for CVE-2026-50248.
- Unit test for CVE-2026-55717.
- Unit test for CVE-2026-55973.
- Unit test for CVE-2026-56416.
- Fix error in log printout in fix for CVE-2026-50248, when the
primary name is bogus.
- iana portlist update.
21 July 2026: Wouter
- Merge #1476 from petrvaganoff: ipsecmod: fix possible deref
on null after reply_find_answer_rrset().
20 July 2026: Wouter
- Merge #1475 from petrvaganoff: ipsecmod: fix deref on null
in ipsecmod-whitelist after OOM.
- Fix #1474: DoQ responses are never padded - pad-responses
does not apply to comm_doq (RFC 9250 §5.4 MUST).
9 July 2026: Wouter
- Merge #1383 from jdek: Fix randomness generation on
macOS/iOS under chroot.
- Fix unit test for malformed svcb for test on Windows.
2 July 2026: Wouter
- Merge #1087: Overload `local_data_remove` to support removing
specific records.
30 June 2026: Wouter
- Fix #1469: dohclient: DoH POST missing content-length → :status
400 from strict resolvers (Cloudflare, Mullvad).
- iana portlist updated.
26 June 2026: Wouter
- Merge #1467: daemon: fix DEREF_AFTER_NULL.EX.COND on
worker_init. This fixes error handling if the worker
stat_timer allocation has an out of memory error. That
makes the server not crash later, attempting to use it.
24 June 2026: Wouter
- Merge #1465 from dag-erling: Add libunbound/remote.h. Add
a shared header containing prototypes for functions that
both ends of a remote control connection need to implement.
19 June 2026: Wouter
- Fix for #1457: fix thread setname for thread start of
dnstap, and fast_reload.
- Fix to update github ci actions/checkout to v7.
- Fix warning about file_string_matches in unbound-checkconf.
17 June 2026: Wouter
- Fix that after fast_reload the disown of the auth zone
transfer task cleans the chunk list. Also fix the
auth_transfer_limit test to use a forwarder for each type
of failure, so the one is not blocked by the other waiting.
- Fix to remove debug from auth_transfer_limit test.
- Fix that unbound-checkconf checks if an auth-zone download
can overwrite another file, by filename collision.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that malloc failure in auth-zone insert rr does
not create an empty node and does not cause an infinite
loop. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
- Fix that unbound-control auth_zone_reload stops the
server answering from the zone after a failure to read.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that malloc failure in dns64_inform_super does
not set up a half-built reply for cache store, that could
lead to a crash. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix that malloc failure for new_local_rrset for RPZ qname
trigger RR insert does not crash. It does not link a
partial RRset, and logs an error on failure, and cleans
up the dname allocation. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix that malloc failure in doq connection setup, does
not crash in doq connection delete later. Thanks to Qifan
Zhang, Palo Alto Networks, for the report.
- Fix that malloc failure for ngtcp2_conn_server_new
cleans up reference that older ngtcp2 versions can leave.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that on malloc failure during accept of TCP, the
socket is not left to cause a read event loop. It uses
slow-accept to delay accepting new connections, if
that fails it drops the new connections. When the tcp
connection usage is full, it waits for 50msec, to allow
existing queries to be resolved. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
- Fix that malloc failure for rpz_strip_nsdname is
checked and handled, so that it does not crash later.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that malloc failure during edns subnet addrtree
insert is checked, so it does not crash later. Thanks to
Qifan Zhang, Palo Alto Networks, for the report.
- Fix to check the return value of auth_xfer_create
during fast_reload auth-zone add and change processing.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix to check for malloc failure in rpz response create,
for nodata and nxdomain, so it does not crash later.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that fast_reload does not terminate the server
on malloc failure for dnstap, or if gethostname fails.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix after malloc failure for stats, then it drains the pipe
so the internal messaging stays correct. Also it does
not exit the server if stats pipe communication fails.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that fast_reload does not terminate the server
on config read failure after malloc failure. Thanks to
Qifan Zhang, Palo Alto Networks, for the report.
- Fix that fast_reload does not terminate the server if
random init for DNS cookies fails. The data is only random
generated if cookies are enabled, and the random data
is necessary. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
17 June 2026: Yorgos
- Fix memory leak on DNAME 0TTL records.
16 June 2026: Wouter
- Fix to disallow $INCLUDE for secondary zones. Start up
of server continues if a secondary zone fails to load.
Failed loads clear the zone data, so there is no partial
zone. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
- Fix that when SVCB records cannot be written out, and
are written in unknown format, that the zone read allows
such unknown format SVCB records. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
- Fix that a half-written trust anchor file does not crash
the server at runtime. It unlinks a wrong file from the list.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that auth-zone, and RPZ zones, do not allow out-of-zone
records. These are records that are not under the zone apex.
The out-of-zone records are dropped from the zone contents.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that dns64 does not ignore the `forward-no-cache` and
`stub-no-cache` options. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix that a signed wildcard NSEC, is checked before use,
so it does not allow insecure DS proofs inappropriately.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that after malloc failure a half-built local_alias does
not crash the server. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix that for a zonefile only zone, if that file does not
exist on server start, the server continues to start with
a warning log message. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix that after malloc failure in RPZ load a half built
list does not crash later. The newly created RRset is
linked after creation has succeeded. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
- Fix that dnscrypt configuration does not crash, due to
inconsistency between secret and public keys. Also
duplicate files are skipped. Thanks to Qifan Zhang, Palo
Alto Networks, for the report.
- Fix locking in libunbound ub_ctx_set_event call.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that libunbound pipe functions fail with error after
an event base is set. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix for neater solution to clear log thread id after
worker init failure. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix incorrect cleanup after an allocation failure for
a delegation point. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix that after malloc failure in find_tag_datas, the
local_alias is cleaned up. Thanks to Qifan Zhang, Palo
Alto Networks, for the report.
- Fix that after shared memory cannot be created, from
`shm-enable`, the server does not crash. Thanks to Qifan
Zhang, Palo Alto Networks, for the report.
- Fix incorrect cleanup after an allocation failure for
a delegation point in a region. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
- Fix after malloc failure the rrset_insert_rr in
localzone processing, during RPZ qname trigger processing,
the RRset retains its previous data correcly. Thanks to
Qifan Zhang, Palo Alto Networks, for the report.
- Fix for #1462: Fix that auth primary host name lookup
allows CNAMEs.
15 June 2026: Wouter
- Fix to add `max-transfer-size` and `max-transfer-time` that
limit auth-zone and rpz transfer amount and time taken.
Default is disabled. This hardens against unbounded
transfers. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix perform a full transfer every number of incremental
transfers, to stop increasing memory usage, for rpz
zones. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
- Fix assertion failure for long HTTP header that fills
buffer. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
- Fix buffer overflow when configured with lower than
default size and http transfer. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
- Fix that misconfigured `iter-scrub-ns: 0` causes request
failures. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix that fast_reload when a zonemd verification lookup
it in progress with subnet loaded, deregisters the
callback. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix for fast_reload that removes an auth zone while its
lookups are in progress, for a primary name. Also after the
change, it no longer picks up the old results. Thanks to
Qifan Zhang, Palo Alto Networks, for the report.
- Fix integer overflow in infra-cache-max-rtt calculation.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix erroneous DNS error report values after bogus AAAA
query caused error information that was not cleared by
a successful A subquery. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix integer overflow for very high values of
`sock-queue-timeout`. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix that fast_reload does not terminate the server for
errors in config, for key files. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
- Fix log of an aliased qname, to not use freed region
memory. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
- Fix DNAME synthesis from cache that keeps use of 0TTL
entries in a sliding window. It did not surpass RRSIG
expiry. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
- Fix misconfigured ipsecmod hook causing path name
similarity with other file. The ipsecmod is changed for
exec of the hook. The ipsecmod hook, if a script, has to
start now with a line like `#!/bin/sh`. Thanks to Qifan
Zhang, Palo Alto Networks, for the report.
- Fix that dns64 bypasses rpz-passthru rule during
synthesis. This restricted more than necessary. Thanks to
Qifan Zhang, Palo Alto Networks, for the report.
12 June 2026: Wouter
- Fix that for auth-zone and rpz zones the allow-notify
addresses and netblocks are available from start, and
fix the probe step skip.
11 June 2026: Wouter
- Fix for #1306: configure detects specifically the call to
SSL_set_quic_tls_early_data_enabled and
SSL_set_quic_early_data_enabled, so the correct one is used.
- Fix for #1306: configure checks if the ngtcp2_crypto_ossl
header file is available, and prints an error otherwise.
- Fix #1437: Fix compile with OpenSSL 4.0.1.
- Fix compile for OpenSSL 1.0.2 and before in server cleanup.
10 June 2026: Wouter
- Fix pythonmod script read for numeric overflow.
- Fix warnings with gcc in compat/inet_pton.c.
9 June 2026: Wouter
- Fix unit test for ecs to check for malloc success.
3 June 2026: Wouter
- Fix that the processing of class responses does not have
a heap use-after-free. That could happen if at least two
distinct classes are configured for resolution. Thanks
to Qifan Zhang, Palo Alto Networks for the report.
In addition, thanks to Xin Wang, Jiapeng Li, and Jiajia
Liu, Northwestern Polytechnical University, for also
reporting this.
- Fix negative cache to work with NSEC3 records without salt.
Thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern
Polytechnical University, for the report.
- Fix parse of svcbparam ech, it had incorrect length. Thanks
to Qifan Zhang, Palo Alto Networks for the report.
- Fix that quotation and escaping works the same in auth-zone
url content, as in the zonefile read. Thanks to Qifan Zhang,
Palo Alto Networks for the report.
- Fix ipset module to use larger domain name buffers, and
check buffer lengths. Thanks to Qifan Zhang, Palo Alto
Networks for the report.
- Fix PROXYv2 header read and consume, it checks the header
size. Thanks to Qifan Zhang, Palo Alto Networks for
the report.
- Fix negative cache NSEC3 nodata proof, to use the correct
message size. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix fast_reload for when a ZONEMD lookup is in progress.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that validation canonicalization of domain names
in rdata checks for buffer bounds. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
- Fix that dump_cache has a larger buffer for records,
and it checks that an owner name does not collide with BADRR
on the input, and changes verbosity on the log of failure in
rrset to string. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix that dns64 cleans up the allocated message if the adjust
routines fail, and checks if there is a reply before cache
store, also unbound checks if A and AAAA are malformed
for auth-zones. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
3 June 2026: Yorgos
- Fix const as reported by newest compiler warnings.
29 May 2026: Wouter
- Fix header_seen detection for trust anchor files, so that it
detects the id line.
- iana portlist updated.
- Update icannbundle.pem certificates in unbound-anchor. It
has the public keys for 2009 to 2029 and for 2025 to 2045.
- Fix unit test to check for new icannbundle.pem.
28 May 2026: Wouter
- Fix #1457: race condition causes segfault when starting
threads.
27 May 2026: Wouter
- Fix for autotrust state-file line overflow, that can give
hold-down bypass. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix to limit the DSNS per-label walk in the iterator. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that the ratelimit is decremented on successful
referrals. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
- Fix that msgencode insert_query has the correct assertion,
for a local_alias. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix to reset the tcp-timeout before applying a load based
reduction. Thanks to Qifan Zhang, Palo Alto Networks, for the
report.
- Fix to decrement the per-netblock tcp connection limits, so
it keeps usable. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix manual to document ratelimit, that it is for target
nameservers for a domain, and keeps queries limited. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
- Fix, in depth, for respip rewrite of dns64 responses. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that dns64 with subnetcache does not write ECS scoped
answers to global cache. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix ipset module for name too long checks, race conditions
on local name buffer, and for socket close race condition.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that validator caps number of ANY RRsets it can
validate, and the wait timer is shortened. Thanks to Qifan
Zhang, Palo Alto Networks, for the report.
- Fix analyzer warning in mesh_new_client.
26 May 2026: Wouter
- Fix for mesh new client and mesh new callback to rollback the
added address, tcp mesh state and callback when there is a failure
to initialize. This fixes the mesh accounting of reply addresses.
Thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern
Polytechnical University, for the report
20 May 2026: Wouter
- Fix CVE-2026-33278, Possible remote code execution during DNSSEC
validation. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
@@ -27,6 +576,79 @@
Networks, for the report.
- Fix CVE-2026-44608, Use after free and crash in RPZ code. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
- Tag for 1.25.1 release, it contains the security fixes on 1.25.0.
the code repository continues with in addition the previous fixes,
for 1.25.2.
- Unit test for CVE-2026-33278.
- Unit test for CVE-2026-42944.
- Unit test for CVE-2026-42959.
- Unit test for CVE-2026-40622.
- Unit test for CVE-2026-42960.
- Fix in depth for serve-expired responses from cachedb, that it
does not store bogus. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix lame server detection, for selfpointed glue records.
Thanks to Shuhan Zhang, Dan Li, and Baojun Liu from Tsinghua
University for the report.
- Fix cleaning up DoH session. The same query can be on multiple
streams in a session. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix for signed same-owner CNAME and ordinary RRset responses.
Thanks to Xin Wang and Jiajia Liu, Northwestern Polytechnical
University, for the report.
18 May 2026: Wouter
- Fix for mixed class referrals, the resolver uses the query
class. Thanks to Xin Wang and Jiajia Liu, Northwestern
Polytechnical University, for the report.
15 May 2026: Wouter
- Fix man page entry for so-sndbuf, it is for responses sent out.
- Fix val_find_DS for robustness, to check the result of
packet_rrset_copy_region before using it. Thanks to Xin Wang
and Jiajia Liu, Northwestern Polytechnical University, for
the report.
- Fix that for dns64 answers, the AAAA query is checked to be
DNSSEC validated, when DNSSEC is enabled. This improves
the RFC6147 conformance of Unbound. Thanks to Xin Wang
and Jiajia Liu, Northwestern Polytechnical University, for
the report. In addition, thanks to Qifan Zhang, Palo Alto
Networks, for reporting it.
- Fix for allocation-failure hardening of rrset cache wildcard
storage and canonical NSEC owner replacement. Thanks to Xin
Wang and Jiajia Liu, Northwestern Polytechnical University,
for the report.
- Fix DNSSEC validation with libnettle for noncanonical RSA
DNSKEYs with leading zeroes for n. Thanks to Xin Wang and
Jiajia Liu, Northwestern Polytechnical University, for
the report.
- Fix DNSKEY size calculation for noncanonical RSA DNSKEYs
with leading zeroes for n. Thanks to Xin Wang and Jiajia Liu,
Northwestern Polytechnical University, for the report.
11 May 2026: Yorgos
- Fix comment and verbose logging for EDNS fallback buffer size.
8 May 2026: Wouter
- Fix to relax assertions after the TTL 0 handling change.
This relaxes an assertion in cachedb (it fails instead),
and for packet_rrset_copy_region.
7 May 2026: Wouter
- Fix for Heap Out-of-Bounds Write via size_t-to-int Truncation
in setup_if() - outside_network_create(). This fixes that
large values for num_ports do not overflow and create
invalid references after integer truncation. Thanks
to Karnakar Reddy (@karnakarreddi) for the report.
- Fix to clean up log ids after a failure to start a worker thread.
1 May 2026: Wouter
- iana portlist updated.
29 April 2026: Wouter
- tag for 1.25.0. The code repository continues with 1.25.1 in
development.
- Fix windows 64bit build for libssp dependency.
23 April 2026: Wouter
- Merge #1441: Fix buffer overrun in
+9
View File
@@ -899,6 +899,10 @@ server:
# that name
# o block_a resolves all records normally but returns
# NODATA for A queries and ignores local data for that name
# o block_aaaa similarly to block_a, resolves all records normally but
# returns NODATA for AAAA queries and ignores local data for that name
# o block_a_wdata like block_a but uses local data if present.
# o block_aaaa_wdata like block_aaaa but uses local data if present.
# o always_null returns 0.0.0.0 or ::0 for any name in the zone.
# o noview breaks out of that view towards global local-zones.
#
@@ -1287,6 +1291,9 @@ remote-control:
# zonemd-check: no
# zonemd-reject-absence: no
# zonefile: "example.org.zone"
# max-transfer-size: 0
# max-transfer-time: 0
# Views
# Create named views. Name must be unique.
@@ -1453,3 +1460,5 @@ remote-control:
# rpz-signal-nxdomain-ra: no
# for-downstream: no
# tags: "example"
# max-transfer-size: 0
# max-transfer-time: 0
+2
View File
@@ -354,6 +354,8 @@ If the name already has no items, nothing happens.
Often results in NXDOMAIN for the name (in a static zone), but if the name
has become an empty nonterminal (there is still data in domain names below
the removed name), NOERROR nodata answers are the result for that name.
With a specific RR instead of a domain name, that specific record is
removed from the local data, and not all the RR data.
.UNINDENT
.INDENT 0.0
.TP
+2
View File
@@ -347,6 +347,8 @@ There are several commands that the server understands.
Often results in NXDOMAIN for the name (in a static zone), but if the name
has become an empty nonterminal (there is still data in domain names below
the removed name), NOERROR nodata answers are the result for that name.
With a specific RR instead of a domain name, that specific record is
removed from the local data, and not all the RR data.
@@UAHL@unbound-control.commands@local_zones@@
+107 -1
View File
@@ -691,7 +691,7 @@ Default: 0 (use system value)
.TP
.B so\-sndbuf: \fI<number>\fP
If not 0, then set the SO_SNDBUF socket option to get more buffer space on
UDP port 53 outgoing queries.
UDP port 53 outgoing responses.
This for very busy servers handles spikes in answer traffic, otherwise:
.INDENT 7.0
.INDENT 3.5
@@ -2312,6 +2312,13 @@ The defensive action is to clear the rrset and message caches, hopefully
flushing away any poison.
A value of 10 million is suggested.
.sp
It is useful to add 0.0.0.0/8 and \(aq::\(aq to the
\fI\%do\-not\-query\-address\fP list.
Otherwise they may be answered, from localhost, and the different source
makes an unwanted reply that unnecessarily ticks up.
The \fI\%do\-not\-query\-localhost\fP
option includes them, the zero subnets, when it is enabled.
.sp
Default: 0 (disabled)
.UNINDENT
.INDENT 0.0
@@ -2362,6 +2369,8 @@ If yes, deny queries of type ANY with an empty response.
If disabled, Unbound responds with a short list of resource records if some
can be found in the cache and makes the upstream type ANY query if there
are none.
The option stops the DNSSEC validation from processing, possibly lengthy,
ANY responses, when the option is enabled.
.sp
Default: no
.UNINDENT
@@ -2910,6 +2919,9 @@ The types are
\fI\%inform_redirect\fP,
\fI\%always_transparent\fP,
\fI\%block_a\fP,
\fI\%block_aaaa\fP,
\fI\%block_a_wdata\fP,
\fI\%block_aaaa_wdata\fP,
\fI\%always_refuse\fP,
\fI\%always_nxdomain\fP,
\fI\%always_null\fP,
@@ -3100,6 +3112,32 @@ use IPv6 protocol and avoid any queries to IPv4.
.UNINDENT
.INDENT 7.0
.TP
.B block_aaaa
Like \fI\%transparent\fP or
\fI\%block_a\fP, but
ignores local data and resolves normally all query types excluding AAAA.
For AAAA queries it unconditionally returns NODATA.
Useful in cases when there is a need to explicitly force all apps to
use IPv4 protocol and avoid any queries to IPv6.
.UNINDENT
.INDENT 7.0
.TP
.B block_a_wdata
Like \fI\%block_a\fP, but
uses local data if present.
If there is local data that is returned, and it acts like transparent.
For A queries it returns NODATA.
.UNINDENT
.INDENT 7.0
.TP
.B block_aaaa_wdata
Like \fI\%block_aaaa\fP, but
uses local data if present.
If there is local data that is returned, and it acts like transparent.
For AAAA queries it returns NODATA.
.UNINDENT
.INDENT 7.0
.TP
.B always_refuse
Like \fI\%refuse\fP, but ignores
local data and refuses the query.
@@ -3567,6 +3605,18 @@ For example, 1000 may be a suitable value to stop the server from being
overloaded with random names, and keeps unbound from sending traffic to the
nameservers for those zones.
.sp
It is intended to count the number of queries towards the nameservers
for the zone, and keep those queries limited.
When there is a delegation that needs a lot of lookups, those are
charged in the counters for the destination, the target name, of
the NS records.
Since that is where the nameserver lookup queries are sent to.
That keeps the target, the victim domain, from having many queries.
With the \fI\%ratelimit\-factor\fP, some
genuine queries that are also made to the target zone, can filter
through, and then end up in cache, where the genuine answers have
a chance to collect, keeping up service to some extent.
.sp
\fBNOTE:\fP
.INDENT 7.0
.INDENT 3.5
@@ -4594,6 +4644,32 @@ If not given then no zonefile is used.
If the file does not exist or is empty, Unbound will attempt to fetch zone
data (eg. from the primary servers).
.UNINDENT
.INDENT 0.0
.TP
.B max\-transfer\-size: \fI<number>\fP
Number of bytes size of the maximum zone transfer size.
Larger transfers, over AXFR, IXFR and HTTP, are not allowed.
A plain number is in bytes, append \(aqk\(aq, \(aqm\(aq or \(aqg\(aq for kilobytes, megabytes
or gigabytes (1024*1024 bytes in a megabyte).
The value \fB0\fP disables the feature.
.sp
Only consider for untrusted/misbehaving primaries that could hog resources
and bring down the resolver.
.sp
Default: 0
.UNINDENT
.INDENT 0.0
.TP
.B max\-transfer\-time: \fI<msec>\fP
Maximum time in milliseconds that a zone transfer is allowed to take from
the start.
The value \fB0\fP disables the feature.
.sp
Only consider for untrusted/misbehaving primaries that could hog resources
and bring down the resolver.
.sp
Default: 0
.UNINDENT
.SH VIEW OPTIONS
.sp
These options are part of the \fBview:\fP section.
@@ -5806,6 +5882,10 @@ from a webserver that would work.
If you specify the hostname, you cannot use the domain from the zonefile,
because it may not have that when retrieving that data, instead use a plain
IP address to avoid a circular dependency on retrieving that IP address.
.sp
Every number of IXFR transfers, a full AXFR is performed.
This is to consolidate the rpz memory, that would otherwise grow.
The fixed value is after 5 IXFR transfers.
.UNINDENT
.INDENT 0.0
.TP
@@ -5928,6 +6008,32 @@ Enclose list of tags in quotes (\fB\(dq\(dq\fP) and put spaces between tags.
If no tags are specified the policies from this section will be applied for
all clients.
.UNINDENT
.INDENT 0.0
.TP
.B max\-transfer\-size: \fI<number>\fP
Number of bytes size of the maximum zone transfer size.
Larger transfers, over AXFR, IXFR and HTTP, are not allowed.
A plain number is in bytes, append \(aqk\(aq, \(aqm\(aq or \(aqg\(aq for kilobytes, megabytes
or gigabytes (1024*1024 bytes in a megabyte).
The value \fB0\fP disables the feature.
.sp
Only consider for untrusted/misbehaving primaries that could hog resources
and bring down the resolver.
.sp
Default: 0
.UNINDENT
.INDENT 0.0
.TP
.B max\-transfer\-time: \fI<msec>\fP
Maximum time in milliseconds that a zone transfer is allowed to take from
the start.
The value \fB0\fP disables the feature.
.sp
Only consider for untrusted/misbehaving primaries that could hog resources
and bring down the resolver.
.sp
Default: 0
.UNINDENT
.SH MEMORY CONTROL EXAMPLE
.sp
In the example config settings below memory usage is reduced.
+92 -1
View File
@@ -642,7 +642,7 @@ These options are part of the ``server:`` section.
@@UAHL@unbound.conf@so-sndbuf@@: *<number>*
If not 0, then set the SO_SNDBUF socket option to get more buffer space on
UDP port 53 outgoing queries.
UDP port 53 outgoing responses.
This for very busy servers handles spikes in answer traffic, otherwise:
.. code-block:: text
@@ -2107,6 +2107,8 @@ These options are part of the ``server:`` section.
If disabled, Unbound responds with a short list of resource records if some
can be found in the cache and makes the upstream type ANY query if there
are none.
The option stops the DNSSEC validation from processing, possibly lengthy,
ANY responses, when the option is enabled.
Default: no
@@ -2590,6 +2592,9 @@ These options are part of the ``server:`` section.
:ref:`inform_redirect<unbound.conf.local-zone.type.inform_redirect>`,
:ref:`always_transparent<unbound.conf.local-zone.type.always_transparent>`,
:ref:`block_a<unbound.conf.local-zone.type.block_a>`,
:ref:`block_aaaa<unbound.conf.local-zone.type.block_aaaa>`,
:ref:`block_a_wdata<unbound.conf.local-zone.type.block_a_wdata>`,
:ref:`block_aaaa_wdata<unbound.conf.local-zone.type.block_aaaa_wdata>`,
:ref:`always_refuse<unbound.conf.local-zone.type.always_refuse>`,
:ref:`always_nxdomain<unbound.conf.local-zone.type.always_nxdomain>`,
:ref:`always_null<unbound.conf.local-zone.type.always_null>`,
@@ -2739,6 +2744,26 @@ These options are part of the ``server:`` section.
Useful in cases when there is a need to explicitly force all apps to
use IPv6 protocol and avoid any queries to IPv4.
@@UAHL@unbound.conf.local-zone.type@block_aaaa@@
Like :ref:`transparent<unbound.conf.local-zone.type.transparent>` or
:ref:`block_a<unbound.conf.local-zone.type.block_a>`, but
ignores local data and resolves normally all query types excluding AAAA.
For AAAA queries it unconditionally returns NODATA.
Useful in cases when there is a need to explicitly force all apps to
use IPv4 protocol and avoid any queries to IPv6.
@@UAHL@unbound.conf.local-zone.type@block_a_wdata@@
Like :ref:`block_a<unbound.conf.local-zone.type.block_a>`, but
uses local data if present.
If there is local data that is returned, and it acts like transparent.
For A queries it returns NODATA.
@@UAHL@unbound.conf.local-zone.type@block_aaaa_wdata@@
Like :ref:`block_aaaa<unbound.conf.local-zone.type.block_aaaa>`, but
uses local data if present.
If there is local data that is returned, and it acts like transparent.
For AAAA queries it returns NODATA.
@@UAHL@unbound.conf.local-zone.type@always_refuse@@
Like :ref:`refuse<unbound.conf.local-zone.type.refuse>`, but ignores
local data and refuses the query.
@@ -3085,6 +3110,18 @@ These options are part of the ``server:`` section.
overloaded with random names, and keeps unbound from sending traffic to the
nameservers for those zones.
It is intended to count the number of queries towards the nameservers
for the zone, and keep those queries limited.
When there is a delegation that needs a lot of lookups, those are
charged in the counters for the destination, the target name, of
the NS records.
Since that is where the nameserver lookup queries are sent to.
That keeps the target, the victim domain, from having many queries.
With the :ref:`ratelimit-factor<unbound.conf.ratelimit-factor>`, some
genuine queries that are also made to the target zone, can filter
through, and then end up in cache, where the genuine answers have
a chance to collect, keeping up service to some extent.
.. note:: Configured forwarders are excluded from ratelimiting.
Default: 0
@@ -4018,6 +4055,31 @@ fallback activates to fetch from the upstream instead of the SERVFAIL.
If the file does not exist or is empty, Unbound will attempt to fetch zone
data (eg. from the primary servers).
@@UAHL@unbound.conf.auth@max-transfer-size@@: *<number>*
Number of bytes size of the maximum zone transfer size.
Larger transfers, over AXFR, IXFR and HTTP, are not allowed.
A plain number is in bytes, append 'k', 'm' or 'g' for kilobytes, megabytes
or gigabytes (1024*1024 bytes in a megabyte).
The value ``0`` disables the feature.
Only consider for untrusted/misbehaving primaries that could hog resources
and bring down the resolver.
Default: 0
@@UAHL@unbound.conf.auth@max-transfer-time@@: *<msec>*
Maximum time in milliseconds that a zone transfer is allowed to take from
the start.
The value ``0`` disables the feature.
Only consider for untrusted/misbehaving primaries that could hog resources
and bring down the resolver.
Default: 0
.. _unbound.conf.view:
View Options
@@ -5098,6 +5160,10 @@ answer queries with that content.
because it may not have that when retrieving that data, instead use a plain
IP address to avoid a circular dependency on retrieving that IP address.
Every number of IXFR transfers, a full AXFR is performed.
This is to consolidate the rpz memory, that would otherwise grow.
The fixed value is after 5 IXFR transfers.
@@UAHL@unbound.conf.rpz@master@@: *<IP address or host name>*
Alternate syntax for :ref:`primary<unbound.conf.rpz.primary>`.
@@ -5198,6 +5264,31 @@ answer queries with that content.
If no tags are specified the policies from this section will be applied for
all clients.
@@UAHL@unbound.conf.rpz@max-transfer-size@@: *<number>*
Number of bytes size of the maximum zone transfer size.
Larger transfers, over AXFR, IXFR and HTTP, are not allowed.
A plain number is in bytes, append 'k', 'm' or 'g' for kilobytes, megabytes
or gigabytes (1024*1024 bytes in a megabyte).
The value ``0`` disables the feature.
Only consider for untrusted/misbehaving primaries that could hog resources
and bring down the resolver.
Default: 0
@@UAHL@unbound.conf.rpz@max-transfer-time@@: *<msec>*
Maximum time in milliseconds that a zone transfer is allowed to take from
the start.
The value ``0`` disables the feature.
Only consider for untrusted/misbehaving primaries that could hog resources
and bring down the resolver.
Default: 0
Memory Control Example
----------------------
+1
View File
@@ -459,6 +459,7 @@ addrtree_insert(struct addrtree *tree, const addrkey_t *addr,
/* Data is stored in other leafnode */
node = newnode;
newnode = node_create(tree, elem, scope, ttl);
if (!newnode) return;
if (!edge_create(newnode, addr, sourcemask, node,
index^1)) {
clean_node(tree, newnode);
+3
View File
@@ -1015,6 +1015,7 @@ subnetmod_operate(struct module_qstate *qstate, enum module_ev event,
subnet_ecs_opt_list_append(&sq->ecs_client_out,
&qstate->edns_opts_front_out, qstate,
qstate->region);
qstate->is_subnet_answer = 1;
}
sq->wait_subquery_done = 0;
qstate->ext_state[id] = module_finished;
@@ -1094,6 +1095,7 @@ subnetmod_operate(struct module_qstate *qstate, enum module_ev event,
qstate->env->cfg->prefetch)) {
sne->num_msg_cache++;
lock_rw_unlock(&sne->biglock);
qstate->is_subnet_answer = 1;
verbose(VERB_QUERY, "subnetcache: answered from cache");
qstate->ext_state[id] = module_finished;
@@ -1165,6 +1167,7 @@ subnetmod_operate(struct module_qstate *qstate, enum module_ev event,
subnet_ecs_opt_list_append(&sq->ecs_client_out,
&qstate->edns_opts_front_out, qstate,
qstate->region);
qstate->is_subnet_answer = 1;
if(verbosity >= VERB_ALGO) {
subnet_log_print("reply has edns subnet",
edns_opt_list_find(
+2
View File
@@ -100,6 +100,8 @@ ipsecmod_whitelist_apply_cfg(struct ipsecmod_env* ie,
struct config_file* cfg)
{
ie->whitelist = rbtree_create(name_tree_compare);
if (!ie->whitelist)
return 0;
if(!read_whitelist(ie->whitelist, cfg))
return 0;
name_tree_init_parents(ie->whitelist);
+91 -37
View File
@@ -51,18 +51,28 @@
#include "util/config_file.h"
#include "services/cache/dns.h"
#include "sldns/wire2str.h"
#ifdef HAVE_SYS_WAIT_H
#include <sys/wait.h>
#endif
/** Apply configuration to ipsecmod module 'global' state. */
static int
ipsecmod_apply_cfg(struct ipsecmod_env* ipsecmod_env, struct config_file* cfg)
{
if(cfg->ipsecmod_whitelist &&
!ipsecmod_whitelist_apply_cfg(ipsecmod_env, cfg))
return 0;
if(!cfg->ipsecmod_enabled)
return 1;
if(!cfg->ipsecmod_hook || (cfg->ipsecmod_hook && !cfg->ipsecmod_hook[0])) {
log_err("ipsecmod: missing ipsecmod-hook.");
return 0;
}
if(cfg->ipsecmod_whitelist &&
!ipsecmod_whitelist_apply_cfg(ipsecmod_env, cfg))
if(access(cfg->ipsecmod_hook, X_OK) != 0) {
log_err("ipsecmod: ipsecmod-hook '%s' is not an executable file: %s",
cfg->ipsecmod_hook, strerror(errno));
return 0;
}
return 1;
}
@@ -250,27 +260,16 @@ call_hook(struct module_qstate* qstate, struct ipsecmod_qstate* iq,
struct ipsecmod_env* ATTR_UNUSED(ie))
{
size_t slen, tempdata_len, tempstring_len, i;
char str[65535], *s, *tempstring;
char qname_s[LDNS_MAX_DOMAINLEN*5+16], ttl_s[32], a_s[32768], k_s[32768];
char *s, *tempstring;
int w = 0, w_temp, qtype;
struct ub_packed_rrset_key* rrset_key;
struct packed_rrset_data* rrset_data;
uint8_t *tempdata;
pid_t pid;
int st;
char* argv[6];
/* Check if a shell is available */
if(system(NULL) == 0) {
log_err("ipsecmod: no shell available for ipsecmod-hook");
return 0;
}
/* Zero the buffer. */
s = str;
slen = sizeof(str);
memset(s, 0, slen);
/* Copy the hook into the buffer. */
w += sldns_str_print(&s, &slen, "%s", qstate->env->cfg->ipsecmod_hook);
/* Put space into the buffer. */
w += sldns_str_print(&s, &slen, " ");
/* Copy the qname into the buffer. */
tempstring = sldns_wire2str_dname(qstate->qinfo.qname,
qstate->qinfo.qname_len);
@@ -283,17 +282,24 @@ call_hook(struct module_qstate* qstate, struct ipsecmod_qstate* iq,
free(tempstring);
return 0;
}
w += sldns_str_print(&s, &slen, "\"%s\"", tempstring);
if(strlen(tempstring)+1 > sizeof(qname_s)) {
log_err("ipsecmod: string too long");
free(tempstring);
return 0;
}
snprintf(qname_s, sizeof(qname_s), "%s", tempstring);
free(tempstring);
/* Put space into the buffer. */
w += sldns_str_print(&s, &slen, " ");
/* Copy the IPSECKEY TTL into the buffer. */
rrset_data = (struct packed_rrset_data*)iq->ipseckey_rrset->entry.data;
w += sldns_str_print(&s, &slen, "\"%ld\"", (long)rrset_data->ttl);
/* Put space into the buffer. */
w += sldns_str_print(&s, &slen, " ");
snprintf(ttl_s, sizeof(ttl_s), "%ld", (long)rrset_data->ttl);
rrset_key = reply_find_answer_rrset(&qstate->return_msg->qinfo,
qstate->return_msg->rep);
if(!rrset_key) {
log_err("ipsecmod: could not find answer rrset for A/AAAA");
return 0;
}
/* Double check that the records are indeed A/AAAA.
* This should never happen as this function is only executed for A/AAAA
* queries but make sure we don't pass anything other than A/AAAA to the
@@ -304,9 +310,15 @@ call_hook(struct module_qstate* qstate, struct ipsecmod_qstate* iq,
return 0;
}
rrset_data = (struct packed_rrset_data*)rrset_key->entry.data;
/* Copy the A/AAAA record(s) into the buffer. Start and end this section
* with a double quote. */
w += sldns_str_print(&s, &slen, "\"");
if(!rrset_data) {
log_err("ipsecmod: Answer has no data");
return 0;
}
/* Copy the A/AAAA record(s) into the buffer. */
w = 0;
s = a_s;
slen = sizeof(a_s);
memset(s, 0, slen);
for(i=0; i<rrset_data->count; i++) {
if(i > 0) {
/* Put space into the buffer. */
@@ -322,7 +334,7 @@ call_hook(struct module_qstate* qstate, struct ipsecmod_qstate* iq,
} else if((size_t)w_temp >= slen) {
s = NULL; /* We do not want str to point outside of buffer. */
slen = 0;
log_err("ipsecmod: shell command too long");
log_err("ipsecmod: command addr argument too long");
return 0;
} else {
s += w_temp;
@@ -330,12 +342,17 @@ call_hook(struct module_qstate* qstate, struct ipsecmod_qstate* iq,
w += w_temp;
}
}
w += sldns_str_print(&s, &slen, "\"");
/* Put space into the buffer. */
w += sldns_str_print(&s, &slen, " ");
if(w >= (int)sizeof(a_s)) {
log_err("ipsecmod: command addr argument too long");
return 0;
}
/* Copy the IPSECKEY record(s) into the buffer. Start and end this section
* with a double quote. */
w += sldns_str_print(&s, &slen, "\"");
w = 0;
s = k_s;
slen = sizeof(k_s);
memset(s, 0, slen);
rrset_data = (struct packed_rrset_data*)iq->ipseckey_rrset->entry.data;
for(i=0; i<rrset_data->count; i++) {
if(i > 0) {
@@ -362,15 +379,44 @@ call_hook(struct module_qstate* qstate, struct ipsecmod_qstate* iq,
w += w_temp;
}
}
w += sldns_str_print(&s, &slen, "\"");
if(w >= (int)sizeof(str)) {
log_err("ipsecmod: shell command too long");
if(w >= (int)sizeof(k_s)) {
log_err("ipsecmod: command ipseckey argument too long");
return 0;
}
verbose(VERB_ALGO, "ipsecmod: shell command: '%s'", str);
/* ipsecmod-hook should return 0 on success. */
if(system(str) != 0)
/* exec the ipsecmod-hook */
argv[0] = qstate->env->cfg->ipsecmod_hook;
argv[1] = qname_s;
argv[2] = ttl_s;
argv[3] = a_s;
argv[4] = k_s;
argv[5] = NULL;
verbose(VERB_ALGO, "ipsecmod: exec %s \"%s\" %s \"%s\" \"%s\"",
argv[0], argv[1], argv[2], argv[3], argv[4]);
if((pid = fork()) < 0) {
log_err("ipsecmod: for exec, can not fork: %s",
strerror(errno));
return 0;
}
if(pid == 0) {
if(execv(argv[0], argv) < 0)
fprintf(stderr, "ipsecmod: execv: %s\n",
strerror(errno));
_exit(127);
}
while(1) {
if(waitpid(pid, &st, 0) < 0) {
if(errno == EINTR)
continue;
log_err("ipsecmod: wait_pid: %s", strerror(errno));
}
break;
}
if(!(WIFEXITED(st) && WEXITSTATUS(st) == 0)) {
/* the command failed */
return 0;
}
return 1;
}
@@ -435,6 +481,12 @@ ipsecmod_handle_query(struct module_qstate* qstate,
* ipsecmod_max_ttl. */
rrset_key = reply_find_answer_rrset(&qstate->return_msg->qinfo,
qstate->return_msg->rep);
if(!rrset_key) {
log_err("ipsecmod: reply-find-answer failed");
errinf(qstate, "ipsecmod: reply-find-answer failed");
ipsecmod_error(qstate, id);
return;
}
rrset_data = (struct packed_rrset_data*)rrset_key->entry.data;
if(rrset_data->ttl > (time_t)qstate->env->cfg->ipsecmod_max_ttl) {
/* Update TTL for rrset to fixed value. */
@@ -576,6 +628,8 @@ ipsecmod_inform_super(struct module_qstate* qstate, int id,
verbose(VERB_ALGO, "super has no ipsecmod state");
return;
}
if(!siq->enabled)
return;
if(qstate->return_msg) {
struct ub_packed_rrset_key* rrset_key = reply_find_answer_rrset(
+17 -14
View File
@@ -143,7 +143,7 @@ static int add_to_ipset(filter_dev dev, const char *setname, const void *ipaddr,
struct nlmsghdr *nlh;
struct nfgenmsg *nfg;
struct nlattr *nested[2];
static char buffer[BUFF_LEN];
char buffer[BUFF_LEN];
if (strlen(setname) >= IPSET_MAXNAMELEN) {
errno = ENAMETOOLONG;
@@ -208,13 +208,6 @@ ipset_add_rrset_data(struct ipset_env *ie,
ret = add_to_ipset((filter_dev)ie->dev, setname, rr_data + 2, af);
if (ret < 0) {
log_err("ipset: could not add %s into %s", dname, setname);
#if HAVE_NET_PFVAR_H
/* don't close as we might not be able to open again due to dropped privs */
#else
mnl_socket_close((filter_dev)ie->dev);
ie->dev = NULL;
#endif
break;
}
}
@@ -226,15 +219,15 @@ ipset_check_zones_for_rrset(struct module_env *env, struct ipset_env *ie,
struct ub_packed_rrset_key *rrset, const char *qname, int qlen,
const char *setname, int af)
{
static char dname[BUFF_LEN];
char dname[LDNS_MAX_DOMAINLEN*4+16];
const char *ds, *qs;
int dlen, plen;
struct config_strlist *p;
struct packed_rrset_data *d;
dlen = sldns_wire2str_dname_buf(rrset->rk.dname, rrset->rk.dname_len, dname, BUFF_LEN);
if (dlen == 0) {
dlen = sldns_wire2str_dname_buf(rrset->rk.dname, rrset->rk.dname_len, dname, sizeof(dname));
if (dlen == 0 || dlen >= (int)sizeof(dname)) {
log_err("bad domain name");
return -1;
}
@@ -276,7 +269,7 @@ static int ipset_update(struct module_env *env, struct dns_msg *return_msg,
const char *setname;
struct ub_packed_rrset_key *rrset;
int af;
static char qname[BUFF_LEN];
char qname[LDNS_MAX_DOMAINLEN*4+16];
int qlen;
#ifdef HAVE_NET_PFVAR_H
@@ -292,8 +285,8 @@ static int ipset_update(struct module_env *env, struct dns_msg *return_msg,
#endif
qlen = sldns_wire2str_dname_buf(qinfo.qname, qinfo.qname_len,
qname, BUFF_LEN);
if(qlen == 0) {
qname, sizeof(qname));
if(qlen == 0 || qlen >= (int)sizeof(qname)) {
log_err("bad domain name");
return -1;
}
@@ -372,6 +365,16 @@ int ipset_init(struct module_env* env, int id) {
ipset_env->name_v4 = env->cfg->ipset_name_v4;
ipset_env->name_v6 = env->cfg->ipset_name_v6;
#ifndef HAVE_NET_PFVAR_H
if (ipset_env->name_v4 && strlen(ipset_env->name_v4) >= IPSET_MAXNAMELEN) {
log_err("ipset: name-v4 exceeds IPSET_MAXNAMELEN (%d)", IPSET_MAXNAMELEN);
return 0;
}
if (ipset_env->name_v6 && strlen(ipset_env->name_v6) >= IPSET_MAXNAMELEN) {
log_err("ipset: name-v6 exceeds IPSET_MAXNAMELEN (%d)", IPSET_MAXNAMELEN);
return 0;
}
#endif
ipset_env->v4_enabled = !ipset_env->name_v4 || (strlen(ipset_env->name_v4) == 0) ? 0 : 1;
ipset_env->v6_enabled = !ipset_env->name_v6 || (strlen(ipset_env->name_v6) == 0) ? 0 : 1;
+31 -24
View File
@@ -118,10 +118,10 @@ delegpt_add_ns(struct delegpt* dp, struct regional* region, uint8_t* name,
sizeof(struct delegpt_ns));
if(!ns)
return 0;
ns->next = dp->nslist;
ns->namelen = len;
dp->nslist = ns;
ns->name = regional_alloc_init(region, name, ns->namelen);
if(!ns->name)
return 0;
ns->cache_lookup_count = 0;
ns->resolved = 0;
ns->got4 = 0;
@@ -137,7 +137,9 @@ delegpt_add_ns(struct delegpt* dp, struct regional* region, uint8_t* name,
} else {
ns->tls_auth_name = NULL;
}
return ns->name != 0;
ns->next = dp->nslist;
dp->nslist = ns;
return 1;
}
struct delegpt_ns*
@@ -223,11 +225,7 @@ delegpt_add_addr(struct delegpt* dp, struct regional* region,
sizeof(struct delegpt_addr));
if(!a)
return 0;
a->next_target = dp->target_list;
dp->target_list = a;
a->next_result = 0;
a->next_usable = dp->usable_list;
dp->usable_list = a;
memcpy(&a->addr, addr, addrlen);
a->addrlen = addrlen;
a->attempts = 0;
@@ -241,6 +239,10 @@ delegpt_add_addr(struct delegpt* dp, struct regional* region,
} else {
a->tls_auth_name = NULL;
}
a->next_target = dp->target_list;
dp->target_list = a;
a->next_usable = dp->usable_list;
dp->usable_list = a;
return 1;
}
@@ -398,30 +400,33 @@ delegpt_count_missing_targets(struct delegpt* dp, int* alllame)
/** find NS rrset in given list */
static struct ub_packed_rrset_key*
find_NS(struct reply_info* rep, size_t from, size_t to)
find_NS(struct reply_info* rep, size_t from, size_t to, uint16_t qclass)
{
size_t i;
for(i=from; i<to; i++) {
if(ntohs(rep->rrsets[i]->rk.type) == LDNS_RR_TYPE_NS)
if(ntohs(rep->rrsets[i]->rk.type) == LDNS_RR_TYPE_NS &&
ntohs(rep->rrsets[i]->rk.rrset_class) == qclass)
return rep->rrsets[i];
}
return NULL;
}
struct delegpt*
delegpt_from_message(struct dns_msg* msg, struct regional* region)
delegpt_from_message(struct dns_msg* msg, struct regional* region, int port)
{
struct ub_packed_rrset_key* ns_rrset = NULL;
struct delegpt* dp;
size_t i;
/* look for NS records in the authority section... */
ns_rrset = find_NS(msg->rep, msg->rep->an_numrrsets,
msg->rep->an_numrrsets+msg->rep->ns_numrrsets);
msg->rep->an_numrrsets+msg->rep->ns_numrrsets,
msg->qinfo.qclass);
/* In some cases (even legitimate, perfectly legal cases), the
* NS set for the "referral" might be in the answer section. */
if(!ns_rrset)
ns_rrset = find_NS(msg->rep, 0, msg->rep->an_numrrsets);
ns_rrset = find_NS(msg->rep, 0, msg->rep->an_numrrsets,
msg->qinfo.qclass);
/* If there was no NS rrset in the authority section, then this
* wasn't a referral message. (It might not actually be a
@@ -436,7 +441,7 @@ delegpt_from_message(struct dns_msg* msg, struct regional* region)
dp->has_parent_side_NS = 1; /* created from message */
if(!delegpt_set_name(dp, region, ns_rrset->rk.dname))
return NULL;
if(!delegpt_rrset_add_ns(dp, region, ns_rrset, 0))
if(!delegpt_rrset_add_ns(dp, region, ns_rrset, 0, port))
return NULL;
/* add glue, A and AAAA in answer and additional section */
@@ -447,10 +452,12 @@ delegpt_from_message(struct dns_msg* msg, struct regional* region)
i < (msg->rep->an_numrrsets+msg->rep->ns_numrrsets))
continue;
if(ntohs(s->rk.type) == LDNS_RR_TYPE_A) {
if(ntohs(s->rk.type) == LDNS_RR_TYPE_A &&
ntohs(s->rk.rrset_class) == msg->qinfo.qclass) {
if(!delegpt_add_rrset_A(dp, region, s, 0, NULL))
return NULL;
} else if(ntohs(s->rk.type) == LDNS_RR_TYPE_AAAA) {
} else if(ntohs(s->rk.type) == LDNS_RR_TYPE_AAAA &&
ntohs(s->rk.rrset_class) == msg->qinfo.qclass) {
if(!delegpt_add_rrset_AAAA(dp, region, s, 0, NULL))
return NULL;
}
@@ -460,7 +467,7 @@ delegpt_from_message(struct dns_msg* msg, struct regional* region)
int
delegpt_rrset_add_ns(struct delegpt* dp, struct regional* region,
struct ub_packed_rrset_key* ns_rrset, uint8_t lame)
struct ub_packed_rrset_key* ns_rrset, uint8_t lame, int port)
{
struct packed_rrset_data* nsdata = (struct packed_rrset_data*)
ns_rrset->entry.data;
@@ -475,7 +482,7 @@ delegpt_rrset_add_ns(struct delegpt* dp, struct regional* region,
continue; /* bad format */
/* add rdata of NS (= wirefmt dname), skip rdatalen bytes */
if(!delegpt_add_ns(dp, region, nsdata->rr_data[i]+2, lame,
NULL, UNBOUND_DNS_PORT))
NULL, (port==-1?UNBOUND_DNS_PORT:port)))
return 0;
}
return 1;
@@ -534,7 +541,7 @@ delegpt_add_rrset(struct delegpt* dp, struct regional* region,
if(!rrset)
return 1;
if(ntohs(rrset->rk.type) == LDNS_RR_TYPE_NS)
return delegpt_rrset_add_ns(dp, region, rrset, lame);
return delegpt_rrset_add_ns(dp, region, rrset, lame, -1);
else if(ntohs(rrset->rk.type) == LDNS_RR_TYPE_A)
return delegpt_add_rrset_A(dp, region, rrset, lame, additions);
else if(ntohs(rrset->rk.type) == LDNS_RR_TYPE_AAAA)
@@ -659,8 +666,6 @@ int delegpt_add_ns_mlc(struct delegpt* dp, uint8_t* name, uint8_t lame,
free(ns);
return 0;
}
ns->next = dp->nslist;
dp->nslist = ns;
ns->cache_lookup_count = 0;
ns->resolved = 0;
ns->got4 = 0;
@@ -679,6 +684,8 @@ int delegpt_add_ns_mlc(struct delegpt* dp, uint8_t* name, uint8_t lame,
} else {
ns->tls_auth_name = NULL;
}
ns->next = dp->nslist;
dp->nslist = ns;
return 1;
}
@@ -704,11 +711,7 @@ int delegpt_add_addr_mlc(struct delegpt* dp, struct sockaddr_storage* addr,
a = (struct delegpt_addr*)malloc(sizeof(struct delegpt_addr));
if(!a)
return 0;
a->next_target = dp->target_list;
dp->target_list = a;
a->next_result = 0;
a->next_usable = dp->usable_list;
dp->usable_list = a;
memcpy(&a->addr, addr, addrlen);
a->addrlen = addrlen;
a->attempts = 0;
@@ -724,6 +727,10 @@ int delegpt_add_addr_mlc(struct delegpt* dp, struct sockaddr_storage* addr,
} else {
a->tls_auth_name = NULL;
}
a->next_target = dp->target_list;
dp->target_list = a;
a->next_usable = dp->usable_list;
dp->usable_list = a;
return 1;
}
+4 -2
View File
@@ -221,10 +221,11 @@ int delegpt_add_ns(struct delegpt* dp, struct regional* regional,
* @param regional: where to allocate the info.
* @param ns_rrset: NS rrset.
* @param lame: rrset is lame, disprefer it.
* @param port: port or -1 if not set.
* @return 0 on alloc error.
*/
int delegpt_rrset_add_ns(struct delegpt* dp, struct regional* regional,
struct ub_packed_rrset_key* ns_rrset, uint8_t lame);
struct ub_packed_rrset_key* ns_rrset, uint8_t lame, int port);
/**
* Add target address to the delegation point.
@@ -365,11 +366,12 @@ size_t delegpt_count_targets(struct delegpt* dp);
*
* @param msg: the dns message, referral.
* @param regional: where to allocate delegation point.
* @param port: if not -1 specifies a port number.
* @return new delegation point or NULL on alloc error, or if the
* message was not appropriate.
*/
struct delegpt* delegpt_from_message(struct dns_msg* msg,
struct regional* regional);
struct regional* regional, int port);
/**
* Mark negative return in delegation point for specific nameserver.
+18 -7
View File
@@ -107,7 +107,7 @@ response_type_from_cache(struct dns_msg* msg,
enum response_type
response_type_from_server(int rdset,
struct dns_msg* msg, struct query_info* request, struct delegpt* dp,
int* empty_nodata_found)
int* empty_nodata_found, int msg_lame_empty, int msg_lame_referral)
{
uint8_t* origzone = (uint8_t*)"\000"; /* the default */
struct ub_packed_rrset_key* s;
@@ -122,6 +122,10 @@ response_type_from_server(int rdset,
/* If the message is NXDOMAIN, then it answers the question. */
if(FLAGS_GET_RCODE(msg->rep->flags) == LDNS_RCODE_NXDOMAIN) {
if(msg->rep->an_numrrsets == 0 &&
msg->rep->ns_numrrsets == 0 &&
msg_lame_empty)
return RESPONSE_TYPE_LAME;
/* make sure its not recursive when we don't want it to */
if( (msg->rep->flags&BIT_RA) &&
!(msg->rep->flags&BIT_AA) && !rdset)
@@ -143,6 +147,10 @@ response_type_from_server(int rdset,
if(FLAGS_GET_RCODE(msg->rep->flags) != LDNS_RCODE_NOERROR)
return RESPONSE_TYPE_THROWAWAY;
if(msg->rep->an_numrrsets == 0 && msg->rep->ns_numrrsets == 0 &&
msg_lame_empty)
return RESPONSE_TYPE_LAME;
/* Note: TC bit has already been handled */
if(dp) {
@@ -249,13 +257,16 @@ response_type_from_server(int rdset,
* which gives ns==zone delegation from cache
* without AA bit as well, with nodata nosoa*/
/* real answer must be +AA and SOA RFC(2308),
* so this is wrong, and we SERVFAIL it if
* this is the only possible reply, if it
* is misdeployed the THROWAWAY makes us pick
* the next server from the selection */
if(msg->rep->an_numrrsets==0 &&
* this is picked up as lame_referral by the
* sanitize step, so it can spot if there
* was data in the answer section before
* removal. If such data is then removed we
* do not want to turn that answer into lame.
* But if it was not there, it can be lame. */
if(msg_lame_referral &&
msg->rep->an_numrrsets==0 &&
!(msg->rep->flags&BIT_AA) && !rdset)
return RESPONSE_TYPE_THROWAWAY;
return RESPONSE_TYPE_LAME;
return RESPONSE_TYPE_ANSWER;
}
/* If we are getting a referral upwards (or to
+5 -1
View File
@@ -120,10 +120,14 @@ enum response_type response_type_from_cache(struct dns_msg* msg,
* @param dp: The delegation point that was being queried
* when the response was returned.
* @param empty_nodata_found: flag to keep track of empty nodata detection.
* @param msg_lame_empty: The scrubber indicates that this empty message
* is lame, before it became empty.
* @param msg_lame_referral: returned true if the reply has a referral before
* scrub.
* @return the response type (CNAME or ANSWER).
*/
enum response_type response_type_from_server(int rdset,
struct dns_msg* msg, struct query_info* request, struct delegpt* dp,
int* empty_nodata_found);
int* empty_nodata_found, int msg_lame_empty, int msg_lame_referral);
#endif /* ITERATOR_ITER_RESPTYPE_H */
+73 -3
View File
@@ -316,6 +316,20 @@ synth_cname_rrset(uint8_t** sname, size_t* snamelen, uint8_t* alias,
return cn;
}
/** Check if the packet has type NS in answer or authority section */
static int
pkt_contains_ns(struct msg_parse* msg)
{
struct rrset_parse* rrset;
for(rrset = msg->rrset_first; rrset; rrset = rrset->rrset_all_next) {
if(rrset->type == LDNS_RR_TYPE_NS &&
(rrset->section == LDNS_SECTION_ANSWER ||
rrset->section == LDNS_SECTION_AUTHORITY))
return 1;
}
return 0;
}
/** check if DNAME applies to a name */
static int
pkt_strict_sub(sldns_buffer* pkt, uint8_t* sname, uint8_t* dr)
@@ -394,6 +408,8 @@ shorten_rrset(sldns_buffer* pkt, struct rrset_parse* rrset, int count)
struct rr_parse* rr = rrset->rr_first, *prev = NULL;
if(!rr)
return;
if(count < 1)
return; /* cannot leave a still-linked rrset_parse with rr_count == 0 */
for(i=0; i<count; i++) {
prev = rr;
rr = rr->next;
@@ -478,6 +494,7 @@ scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg,
size_t snamelen = qinfo->qname_len;
struct rrset_parse* rrset, *prev, *nsset=NULL;
int cname_length = 0; /* number of CNAMEs, or DNAMEs */
int has_answer = 0; /* if answer section contains nonCNAME,nonDNAME */
if(FLAGS_GET_RCODE(msg->flags) != LDNS_RCODE_NOERROR &&
FLAGS_GET_RCODE(msg->flags) != LDNS_RCODE_NXDOMAIN &&
@@ -519,6 +536,11 @@ scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg,
(unsigned)rrset->rr_count);
return 0;
}
if(has_answer) {
remove_rrset("normalize: removing DNAME redirection after answer:",
pkt, msg, prev, &rrset);
continue;
}
if(!synth_cname(sname, snamelen, rrset, alias,
&aliaslen, pkt)) {
verbose(VERB_ALGO, "synthesized CNAME "
@@ -569,6 +591,11 @@ scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg,
if(rrset->type == LDNS_RR_TYPE_CNAME) {
struct rrset_parse* nx = rrset->rrset_all_next;
uint8_t* oldsname = sname;
if(has_answer) {
remove_rrset("normalize: removing redirection after answer:",
pkt, msg, prev, &rrset);
continue;
}
cname_length++;
/* see if the next one is a DNAME, if so, swap them */
if(nx && nx->section == LDNS_SECTION_ANSWER &&
@@ -647,6 +674,7 @@ scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg,
* will be removed by sanitize, so no additional for them */
if(dname_pkt_compare(pkt, qinfo->qname, rrset->dname) == 0)
mark_additional_rrset(pkt, msg, rrset);
has_answer = 1;
prev = rrset;
rrset = rrset->rrset_all_next;
@@ -732,6 +760,11 @@ scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg,
"RRset:", pkt, msg, prev, &rrset);
continue;
}
if(ntohs(rrset->rrset_class) != qinfo->qclass) {
remove_rrset("normalize: removing other class "
"RRset:", pkt, msg, prev, &rrset);
continue;
}
if(nsset == NULL) {
nsset = rrset;
} else {
@@ -968,12 +1001,20 @@ scrub_sanitize_rr_length(sldns_buffer* pkt, struct msg_parse* msg,
* @param env: module environment with config and cache.
* @param ie: iterator environment with private address data.
* @param qstate: for setting errinf for EDE error messages.
* @param pkt_before_NS: if the packet had type NS before scrub. If that
* is removed now, that indicates this may have been lame.
* @param msg_lame_empty: returned true if the empty packet is lame.
* @param msg_lame_referral: returned true if the reply has a referral before
* scrub.
* @param rdset: if RD bit was sent in query sent by unbound.
* @return 0 on error.
*/
static int
scrub_sanitize(sldns_buffer* pkt, struct msg_parse* msg,
struct query_info* qinfo, uint8_t* zonename, struct module_env* env,
struct iter_env* ie, struct module_qstate* qstate)
struct iter_env* ie, struct module_qstate* qstate,
int pkt_before_NS, int* msg_lame_empty, int* msg_lame_referral,
int rdset)
{
int del_addi = 0; /* if additional-holding rrsets are deleted, we
do not trust the normalized additional-A-AAAA any more */
@@ -1130,6 +1171,21 @@ scrub_sanitize(sldns_buffer* pkt, struct msg_parse* msg,
prev = rrset;
rrset = rrset->rrset_all_next;
}
/* If the packet is empty now, but it was not before. And there
* was type NS in authority, then that indicates the answer is lame. */
if(msg->rrset_first == NULL && pkt_before_NS) {
*msg_lame_empty = 1;
verbose(VERB_ALGO, "sanitize: empty message had referral to NS before, marked as lame");
} else if(pkt_before_NS && msg->an_rrsets==0 &&
!(msg->flags&BIT_AA) && !rdset) {
/* If the packet is now a referral, not really a nodata,
* then if it was also with an empty answer section before,
* it is also lame. */
*msg_lame_referral = 1;
verbose(VERB_ALGO, "sanitize: message has referral not answer, marked as lame");
}
return 1;
}
@@ -1137,11 +1193,15 @@ int
scrub_message(sldns_buffer* pkt, struct msg_parse* msg,
struct query_info* qinfo, uint8_t* zonename, struct regional* region,
struct module_env* env, struct module_qstate* qstate,
struct iter_env* ie)
struct iter_env* ie, int* msg_lame_empty, int* msg_lame_referral,
int rdset)
{
int pkt_before_NS;
/* basic sanity checks */
log_nametypeclass(VERB_ALGO, "scrub for", zonename, LDNS_RR_TYPE_NS,
qinfo->qclass);
*msg_lame_empty = 0;
*msg_lame_referral = 0;
if(msg->qdcount > 1)
return 0;
if( !(msg->flags&BIT_QR) )
@@ -1166,11 +1226,21 @@ scrub_message(sldns_buffer* pkt, struct msg_parse* msg,
return 0;
}
/* If the packet contains type NS in authority before scrub,
* like a self referral. With the answer section empty, it
* was not AA, the query was not sent with RD, with NS in auth,
* and no SOA in auth. For a negative answer, type SOA is present.
* This detects certain lameness if after has removed that. */
pkt_before_NS = msg->an_rrsets == 0 &&
!(msg->flags&BIT_AA) && !rdset &&
pkt_contains_ns(msg) && !soa_in_auth(msg);
/* normalize the response, this cleans up the additional. */
if(!scrub_normalize(pkt, msg, qinfo, region, env, zonename))
return 0;
/* delete all out-of-zone information */
if(!scrub_sanitize(pkt, msg, qinfo, zonename, env, ie, qstate))
if(!scrub_sanitize(pkt, msg, qinfo, zonename, env, ie, qstate,
pkt_before_NS, msg_lame_empty, msg_lame_referral, rdset))
return 0;
return 1;
}
+6 -1
View File
@@ -62,11 +62,16 @@ struct module_qstate;
* @param env: module environment with config settings and cache.
* @param qstate: for setting errinf for EDE error messages.
* @param ie: iterator module environment data.
* @param msg_lame_empty: returned true if the empty packet is lame.
* @param msg_lame_referral: returned true if the reply has a referral before
* scrub.
* @param rdset: if RD bit was sent in query sent by unbound.
* @return: false if the message is total waste. true if scrubbed with success.
*/
int scrub_message(struct sldns_buffer* pkt, struct msg_parse* msg,
struct query_info* qinfo, uint8_t* zonename, struct regional* regional,
struct module_env* env, struct module_qstate* qstate,
struct iter_env* ie);
struct iter_env* ie, int* msg_lame_empty, int* msg_lame_referral,
int rdset);
#endif /* ITERATOR_ITER_SCRUB_H */
+10 -1
View File
@@ -1313,7 +1313,8 @@ iter_lookup_parent_NS_from_cache(struct module_env* env, struct delegpt* dp,
log_rrset_key(VERB_ALGO, "found parent-side NS in cache", akey);
dp->has_parent_side_NS = 1;
/* and mark the new names as lame */
if(!delegpt_rrset_add_ns(dp, region, akey, 1)) {
if(!delegpt_rrset_add_ns(dp, region, akey, 1,
deleg_port_number(env))) {
lock_rw_unlock(&akey->entry.lock);
return 0;
}
@@ -1703,3 +1704,11 @@ iter_make_minimal(struct reply_info* rep)
rep->ar_numrrsets = 0;
rep->rrset_count -= rem;
}
int
deleg_port_number(struct module_env* env)
{
if(env->cfg->ssl_upstream)
return env->cfg->ssl_port;
return -1;
}
+3
View File
@@ -483,4 +483,7 @@ void limit_nsec_ttl(struct dns_msg* msg);
*/
void iter_make_minimal(struct reply_info* rep);
/** See if we need a different port number */
int deleg_port_number(struct module_env* env);
#endif /* ITERATOR_ITER_UTILS_H */
+66 -18
View File
@@ -1511,6 +1511,7 @@ processInitRequest(struct module_qstate* qstate, struct iter_qstate* iq,
verbose(VERB_ALGO, "no-cache set, going to the network");
qstate->no_cache_lookup = 1;
qstate->no_cache_store = 1;
qstate->fwd_stub_no_cache = 1;
msg = NULL;
} else if(qstate->blacklist) {
/* if cache, or anything else, was blacklisted then
@@ -1530,7 +1531,7 @@ processInitRequest(struct module_qstate* qstate, struct iter_qstate* iq,
msg = val_neg_getmsg(qstate->env->neg_cache, &iq->qchase,
qstate->region, qstate->env->rrset_cache,
qstate->env->scratch_buffer,
*qstate->env->now, 1/*add SOA*/, NULL,
*qstate->env->now, 1/*add SOA*/, dpname,
qstate->env->cfg);
}
/* item taken from cache does not match our query name, thus
@@ -2391,6 +2392,12 @@ processDSNSFind(struct module_qstate* qstate, struct iter_qstate* iq, int id)
/* go up one (more) step, until we hit the dp, if so, end */
dname_remove_label(&iq->dsns_point, &iq->dsns_point_len);
if(++iq->dsns_count > MAX_DSNS_FIND_COUNT) {
verbose(VERB_QUERY, "DS NS search exceeded %d labels",
MAX_DSNS_FIND_COUNT);
errinf(qstate, "DS NS search exceeded label limit");
return error_response_cache(qstate, id, LDNS_RCODE_SERVFAIL);
}
if(query_dname_compare(iq->dsns_point, iq->dp->name) == 0) {
/* there was no inbetween nameserver, use the old delegation
* point again. And this time, because dsns_point is nonNULL
@@ -3073,7 +3080,9 @@ processQueryTargets(struct module_qstate* qstate, struct iter_qstate* iq,
/* Do not check ratelimit for forwarding queries or if we already got a
* pass. */
sq_check_ratelimit = (!(iq->chase_flags & BIT_RD) && !iq->ratelimit_ok);
sq_check_ratelimit = ((!(iq->chase_flags & BIT_RD) &&
!iq->ratelimit_ok));
iq->ratelimit_incremented = 0;
/* We have a valid target. */
if(verbosity >= VERB_QUERY) {
log_query_info(VERB_QUERY, "sending query:", &iq->qinfo_out);
@@ -3099,7 +3108,8 @@ processQueryTargets(struct module_qstate* qstate, struct iter_qstate* iq,
iq->dp->name, iq->dp->namelen,
(iq->dp->tcp_upstream || qstate->env->cfg->tcp_upstream),
(iq->dp->ssl_upstream || qstate->env->cfg->ssl_upstream),
target->tls_auth_name, qstate, &sq_was_ratelimited);
target->tls_auth_name, qstate, &sq_was_ratelimited,
&iq->ratelimit_incremented);
if(!outq) {
if(sq_was_ratelimited) {
lock_basic_lock(&ie->queries_ratelimit_lock);
@@ -3137,7 +3147,6 @@ find_NS(struct reply_info* rep, size_t from, size_t to)
return NULL;
}
/**
* Process the query response. All queries end up at this state first. This
* process generally consists of analyzing the response and routing the
@@ -3179,7 +3188,8 @@ processQueryResponse(struct module_qstate* qstate, struct iter_qstate* iq,
orig_empty_nodata_found = iq->empty_nodata_found;
type = response_type_from_server(
(int)((iq->chase_flags&BIT_RD) || iq->chase_to_rd),
iq->response, &iq->qinfo_out, iq->dp, &iq->empty_nodata_found);
iq->response, &iq->qinfo_out, iq->dp, &iq->empty_nodata_found,
iq->msg_lame_empty, iq->msg_lame_referral);
iq->chase_to_rd = 0;
/* remove TC flag, if this is erroneously set by TCP upstream */
iq->response->rep->flags &= ~BIT_TC;
@@ -3457,7 +3467,14 @@ processQueryResponse(struct module_qstate* qstate, struct iter_qstate* iq,
iq->deleg_msg = iq->response;
/* Keep current delegation point for label comparison */
old_dp = iq->dp;
iq->dp = delegpt_from_message(iq->response, qstate->region);
/* A referral reply is "pleasant", refund the
* parent dp's rate charge before descending to the child. */
if(iq->ratelimit_incremented)
infra_ratelimit_dec(qstate->env->infra_cache,
old_dp->name, old_dp->namelen,
*qstate->env->now);
iq->dp = delegpt_from_message(iq->response, qstate->region,
deleg_port_number(qstate->env));
if (qstate->env->cfg->qname_minimisation)
iq->minimisation_state = INIT_MINIMISE_STATE;
if(!iq->dp) {
@@ -3734,7 +3751,8 @@ prime_supers(struct module_qstate* qstate, int id, struct module_qstate* forq)
log_assert(qstate->is_priming || foriq->wait_priming_stub);
log_assert(qstate->return_rcode == LDNS_RCODE_NOERROR);
/* Convert our response to a delegation point */
dp = delegpt_from_message(qstate->return_msg, forq->region);
dp = delegpt_from_message(qstate->return_msg, forq->region,
deleg_port_number(forq->env));
if(!dp) {
/* if there is no convertible delegation point, then
* the ANSWER type was (presumably) a negative answer. */
@@ -3785,7 +3803,8 @@ processPrimeResponse(struct module_qstate* qstate, int id)
iq->response->rep->flags &= ~(BIT_RD|BIT_RA); /* ignore rec-lame */
type = response_type_from_server(
(int)((iq->chase_flags&BIT_RD) || iq->chase_to_rd),
iq->response, &iq->qchase, iq->dp, NULL);
iq->response, &iq->qchase, iq->dp, NULL, iq->msg_lame_empty,
iq->msg_lame_referral);
if(type == RESPONSE_TYPE_ANSWER) {
qstate->return_rcode = LDNS_RCODE_NOERROR;
qstate->return_msg = iq->response;
@@ -3949,7 +3968,8 @@ processDSNSResponse(struct module_qstate* qstate, int id,
/* else, store as DP and continue at querytargets */
foriq->state = QUERYTARGETS_STATE;
foriq->dp = delegpt_from_message(qstate->return_msg, forq->region);
foriq->dp = delegpt_from_message(qstate->return_msg, forq->region,
deleg_port_number(forq->env));
if(!foriq->dp) {
log_err("out of memory in dsns dp alloc");
errinf(qstate, "malloc failure, in DS search");
@@ -3998,7 +4018,7 @@ processClassResponse(struct module_qstate* qstate, int id,
/* if there are records, copy RCODE */
/* lower sec_state if this message is lower */
if(from->rep->rrset_count != 0) {
size_t n = from->rep->rrset_count+to->rep->rrset_count;
size_t i, n = from->rep->rrset_count+to->rep->rrset_count;
struct ub_packed_rrset_key** dest, **d;
/* copy appropriate rcode */
to->rep->flags = from->rep->flags;
@@ -4020,24 +4040,49 @@ processClassResponse(struct module_qstate* qstate, int id,
memcpy(dest, to->rep->rrsets, to->rep->an_numrrsets
* sizeof(dest[0]));
dest += to->rep->an_numrrsets;
memcpy(dest, from->rep->rrsets, from->rep->an_numrrsets
* sizeof(dest[0]));
for(i=0; i<from->rep->an_numrrsets; i++) {
dest[i] = packed_rrset_copy_region(
from->rep->rrsets[i], forq->region, 0);
if(!dest[i]) {
log_err("malloc failed in collect ANY");
foriq->state = FINISHED_STATE;
return;
}
}
dest += from->rep->an_numrrsets;
/* copy NS */
memcpy(dest, to->rep->rrsets+to->rep->an_numrrsets,
to->rep->ns_numrrsets * sizeof(dest[0]));
dest += to->rep->ns_numrrsets;
memcpy(dest, from->rep->rrsets+from->rep->an_numrrsets,
from->rep->ns_numrrsets * sizeof(dest[0]));
for(i=0; i<from->rep->ns_numrrsets; i++) {
dest[i] = packed_rrset_copy_region(
from->rep->rrsets[
from->rep->an_numrrsets+i],
forq->region, 0);
if(!dest[i]) {
log_err("malloc failed in collect ANY");
foriq->state = FINISHED_STATE;
return;
}
}
dest += from->rep->ns_numrrsets;
/* copy AR */
memcpy(dest, to->rep->rrsets+to->rep->an_numrrsets+
to->rep->ns_numrrsets,
to->rep->ar_numrrsets * sizeof(dest[0]));
dest += to->rep->ar_numrrsets;
memcpy(dest, from->rep->rrsets+from->rep->an_numrrsets+
from->rep->ns_numrrsets,
from->rep->ar_numrrsets * sizeof(dest[0]));
for(i=0; i<from->rep->ar_numrrsets; i++) {
dest[i] = packed_rrset_copy_region(
from->rep->rrsets[
from->rep->an_numrrsets+
from->rep->ns_numrrsets+i],
forq->region, 0);
if(!dest[i]) {
log_err("malloc failed in collect ANY");
foriq->state = FINISHED_STATE;
return;
}
}
/* update counts */
to->rep->rrsets = d;
to->rep->an_numrrsets += from->rep->an_numrrsets;
@@ -4395,7 +4440,10 @@ process_response(struct module_qstate* qstate, struct iter_qstate* iq,
/* normalize and sanitize: easy to delete items from linked lists */
if(!scrub_message(pkt, prs, &iq->qinfo_out, iq->dp->name,
qstate->env->scratch, qstate->env, qstate, ie)) {
qstate->env->scratch, qstate->env, qstate, ie,
&iq->msg_lame_empty, &iq->msg_lame_referral,
(int)((iq->chase_flags&BIT_RD) || iq->chase_to_rd)
)) {
/* if 0x20 enabled, start fallback, but we have no message */
if(event == module_event_capsfail && !iq->caps_fallback) {
iq->caps_fallback = 1;
+18
View File
@@ -104,6 +104,11 @@ extern int BLACKLIST_PENALTY;
#define RTT_BAND 400
/** Number of retries for empty nodata packets before it is accepted. */
#define EMPTY_NODATA_RETRY_COUNT 2
/** max label-strip iterations in DSNS_FIND_STATE (RFC 4035 4.2 parent-NS
* search) before giving up; bounds upstream NS sends per client DS.
* Means the max number of labels in grandchild to the grandparent zone that
* are co-hosted. */
#define MAX_DSNS_FIND_COUNT 20
/**
* Iterator global state for nat64.
@@ -375,6 +380,10 @@ struct iter_qstate {
/** if true, already tested for ratelimiting and passed the test */
int ratelimit_ok;
/** If the last query, that may be a referral, incremented the
* ratelimit counter. */
int ratelimit_incremented;
/**
* The query must store NS records from referrals as parentside RRs
* Enabled once it hits resolution problems, to throttle retries.
@@ -399,6 +408,8 @@ struct iter_qstate {
uint8_t* dsns_point;
/** length of the dname in dsns_point */
size_t dsns_point_len;
/** number of label-strip iterations performed in DSNS_FIND_STATE */
int dsns_count;
/**
* expected dnssec information for this iteration step.
@@ -434,6 +445,13 @@ struct iter_qstate {
* already so that it is accepted later. */
int empty_nodata_found;
/** Store if the answer was empty, but lame, before it became empty.*/
int msg_lame_empty;
/** Store if the answer was a referral, to self, before scrub. So the
* it is not some sort of answer. */
int msg_lame_referral;
/** list of pending queries to authoritative servers. */
struct outbound_list outlist;
+2
View File
@@ -167,6 +167,8 @@ struct ctx_query {
ub_event_callback_type cb_event;
/** for async query, the callback user arg */
void* cb_arg;
/** for async query the unique info */
void* unique_info;
/** answer message, result from resolver lookup. */
uint8_t* msg;
+17
View File
@@ -571,6 +571,8 @@ ub_ctx_async(struct ub_ctx* ctx, int dothread)
int
ub_poll(struct ub_ctx* ctx)
{
if(!ctx || ctx->event_base)
return UB_INITFAIL;
/* no need to hold lock while testing for readability. */
return tube_poll(ctx->rr_pipe);
}
@@ -578,6 +580,8 @@ ub_poll(struct ub_ctx* ctx)
int
ub_fd(struct ub_ctx* ctx)
{
if(!ctx || ctx->event_base)
return -1;
return tube_read_fd(ctx->rr_pipe);
}
@@ -672,6 +676,8 @@ ub_process(struct ub_ctx* ctx)
int r;
uint8_t* msg;
uint32_t len;
if(!ctx || ctx->event_base)
return UB_INITFAIL;
while(1) {
msg = NULL;
lock_basic_lock(&ctx->rrpipe_lock);
@@ -700,6 +706,8 @@ ub_wait(struct ub_ctx* ctx)
int r;
uint8_t* msg;
uint32_t len;
if(!ctx || ctx->event_base)
return UB_INITFAIL;
/* this is basically the same loop as _process(), but with changes.
* holds the rrpipe lock and waits with tube_wait */
while(1) {
@@ -837,6 +845,8 @@ ub_resolve_async(struct ub_ctx* ctx, const char* name, int rrtype,
struct ctx_query* q;
uint8_t* msg = NULL;
uint32_t len = 0;
if(!ctx || ctx->event_base)
return UB_INITFAIL;
if(async_id)
*async_id = 0;
@@ -1467,8 +1477,15 @@ ub_ctx_set_event(struct ub_ctx* ctx, struct event_base* base) {
lock_basic_lock(&ctx->cfglock);
/* destroy the current worker - safe to pass in NULL */
/* Unlock the cfglock during libworker_delete_event, since it
* calls context_release_alloc, that wants to lock cfglock again.
* Since the event base is used from one thread, the one that
* called this function, it is safe to do so. */
lock_basic_unlock(&ctx->cfglock);
libworker_delete_event(ctx->event_worker);
ctx->event_worker = NULL;
lock_basic_lock(&ctx->cfglock);
new_base = ub_libevent_event_base(base);
if (new_base)
ctx->event_base = new_base;
+11 -6
View File
@@ -651,7 +651,8 @@ int libworker_fg(struct ub_ctx* ctx, struct ctx_query* q)
}
/* process new query */
if(!mesh_new_callback(w->env->mesh, &qinfo, qflags, &edns,
w->back->udp_buff, qid, libworker_fg_done_cb, q, 0)) {
w->back->udp_buff, qid, libworker_fg_done_cb, q, 0,
&q->unique_info)) {
free(qinfo.qname);
return UB_NOMEM;
}
@@ -732,7 +733,8 @@ int libworker_attach_mesh(struct ub_ctx* ctx, struct ctx_query* q,
if(async_id)
*async_id = q->querynum;
if(!mesh_new_callback(w->env->mesh, &qinfo, qflags, &edns,
w->back->udp_buff, qid, libworker_event_done_cb, q, 0)) {
w->back->udp_buff, qid, libworker_event_done_cb, q, 0,
&q->unique_info)) {
free(qinfo.qname);
return UB_NOMEM;
}
@@ -870,7 +872,8 @@ handle_newq(struct libworker* w, uint8_t* buf, uint32_t len)
q->w = w;
/* process new query */
if(!mesh_new_callback(w->env->mesh, &qinfo, qflags, &edns,
w->back->udp_buff, qid, libworker_bg_done_cb, q, 0)) {
w->back->udp_buff, qid, libworker_bg_done_cb, q, 0,
&q->unique_info)) {
add_bg_result(w, q, NULL, UB_NOMEM, NULL, 0);
}
free(qinfo.qname);
@@ -888,7 +891,8 @@ struct outbound_entry* libworker_send_query(struct query_info* qinfo,
int check_ratelimit,
struct sockaddr_storage* addr, socklen_t addrlen, uint8_t* zone,
size_t zonelen, int tcp_upstream, int ssl_upstream, char* tls_auth_name,
struct module_qstate* q, int* was_ratelimited)
struct module_qstate* q, int* was_ratelimited,
int* ratelimit_incremented)
{
struct libworker* w = (struct libworker*)q->env->worker;
struct outbound_entry* e = (struct outbound_entry*)regional_alloc(
@@ -900,7 +904,7 @@ struct outbound_entry* libworker_send_query(struct query_info* qinfo,
want_dnssec, nocaps, check_ratelimit, tcp_upstream, ssl_upstream,
tls_auth_name, addr, addrlen, zone, zonelen, q,
libworker_handle_service_reply, e, w->back->udp_buff, q->env,
was_ratelimited);
was_ratelimited, ratelimit_incremented);
if(!e->qsent) {
return NULL;
}
@@ -985,7 +989,8 @@ struct outbound_entry* worker_send_query(struct query_info* ATTR_UNUSED(qinfo),
struct sockaddr_storage* ATTR_UNUSED(addr), socklen_t ATTR_UNUSED(addrlen),
uint8_t* ATTR_UNUSED(zone), size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream),
int ATTR_UNUSED(ssl_upstream), char* ATTR_UNUSED(tls_auth_name),
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited))
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited),
int* ATTR_UNUSED(ratelimit_incremented))
{
log_assert(0);
return 0;
+65
View File
@@ -0,0 +1,65 @@
/*
* libunbound/remote.h - prototypes for remote control methods.
*
* Copyright (c) 2026, NLnet Labs. All rights reserved.
*
* This software is open source.
*
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions
* are met:
*
* Redistributions of source code must retain the above copyright notice,
* this list of conditions and the following disclaimer.
*
* Redistributions in binary form must reproduce the above copyright notice,
* this list of conditions and the following disclaimer in the documentation
* and/or other materials provided with the distribution.
*
* Neither the name of the NLNET LABS nor the names of its contributors may
* be used to endorse or promote products derived from this software without
* specific prior written permission.
*
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
* "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
* LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
* A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
* HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
* SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED
* TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
* PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
* LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
* NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
* SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
*/
/**
* \file
*
* This file declares the methods that must be implemented to use the
* remote control service.
*/
#ifndef LIBUNBOUND_REMOTE_H
#define LIBUNBOUND_REMOTE_H
struct comm_reply;
struct comm_point;
/** fast reload thread commands to remote service thread event callback */
void fast_reload_service_cb(int fd, short bits, void* arg);
/** fast reload callback for the remote control client connection */
int fast_reload_client_callback(struct comm_point* c, void* arg, int err,
struct comm_reply* rep);
/** handle remote control accept callbacks */
int remote_accept_callback(struct comm_point*, void*, int, struct comm_reply*);
/** handle remote control data callbacks */
int remote_control_callback(struct comm_point*, void*, int, struct comm_reply*);
/** routine to printout option values over SSL */
void remote_get_opt_ssl(char* line, void* arg);
#endif /* LIBUNBOUND_REMOTE_H */
+8 -11
View File
@@ -70,6 +70,8 @@ struct query_info;
* @param q: which query state to reactivate upon return.
* @param was_ratelimited: it will signal back if the query failed to pass the
* ratelimit check.
* @param ratelimit_incremented: set to true if the ratelimit counter
* was increased.
* @return: false on failure (memory or socket related). no query was
* sent.
*/
@@ -78,7 +80,8 @@ struct outbound_entry* libworker_send_query(struct query_info* qinfo,
int check_ratelimit,
struct sockaddr_storage* addr, socklen_t addrlen, uint8_t* zone,
size_t zonelen, int tcp_upstream, int ssl_upstream, char* tls_auth_name,
struct module_qstate* q, int* was_ratelimited);
struct module_qstate* q, int* was_ratelimited,
int* ratelimit_incremented);
/** process incoming serviced query replies from the network */
int libworker_handle_service_reply(struct comm_point* c, void* arg, int error,
@@ -126,6 +129,8 @@ void worker_sighandler(int sig, void* arg);
* @param q: which query state to reactivate upon return.
* @param was_ratelimited: it will signal back if the query failed to pass the
* ratelimit check.
* @param ratelimit_incremented: set to true if the ratelimit counter
* was increased.
* @return: false on failure (memory or socket related). no query was
* sent.
*/
@@ -134,7 +139,8 @@ struct outbound_entry* worker_send_query(struct query_info* qinfo,
int check_ratelimit,
struct sockaddr_storage* addr, socklen_t addrlen, uint8_t* zone,
size_t zonelen, int tcp_upstream, int ssl_upstream, char* tls_auth_name,
struct module_qstate* q, int* was_ratelimited);
struct module_qstate* q, int* was_ratelimited,
int* ratelimit_incremented);
/**
* process control messages from the main thread. Frees the control
@@ -171,13 +177,4 @@ void worker_start_accept(void* arg);
/** stop accept callback handler */
void worker_stop_accept(void* arg);
/** handle remote control accept callbacks */
int remote_accept_callback(struct comm_point*, void*, int, struct comm_reply*);
/** handle remote control data callbacks */
int remote_control_callback(struct comm_point*, void*, int, struct comm_reply*);
/** routine to printout option values over SSL */
void remote_get_opt_ssl(char* line, void* arg);
#endif /* LIBUNBOUND_WORKER_H */
+8
View File
@@ -466,9 +466,13 @@ if [ "$DOWIN" = "yes" ]; then
|| error_cleanup "Could not configure"
set +x
else
# Add -l:libssp:a to statically link libssp if possible.
# Put it at the end of LIBS, to satisfy also linked in
# dependencies.
set -x
$configure --enable-debug --enable-static-exe --disable-flto --disable-gost $* $cross_flag \
|| error_cleanup "Could not configure"
sed -i Makefile -e 's/^\(LIBS=.*\)$/\1 -l:libssp.a/'
set +x
fi
info "Calling make"
@@ -485,6 +489,7 @@ if [ "$DOWIN" = "yes" ]; then
|| error_cleanup "Could not configure"
set +x
else
# Do not add -l:libssp:a statically because it is a shared build.
set -x
$configure --enable-debug --disable-flto --disable-gost $* $shared_cross_flag \
|| error_cleanup "Could not configure"
@@ -603,6 +608,8 @@ rm -rf .git .travis.yml .gitattributes .github .gitignore || error_cleanup "Fail
info "Adding libtool utils (libtoolize)."
libtoolize -c --install || libtoolize -c || error_cleanup "Libtoolize failed."
# Turn this off, if the git repo times out for lookups.
if test "updateconfigsub" = "false"; then
# https://www.gnu.org/software/gettext/manual/html_node/config_002eguess.html
info "Updating config.guess and config.sub"
wget -O config.guess 'https://git.savannah.gnu.org/gitweb/?p=config.git;a=blob_plain;f=config.guess;hb=HEAD'
@@ -616,6 +623,7 @@ if [ `uname -s | grep -i -c darwin` -ne 0 ]; then
xattr -d com.apple.quarantine config.sub
fi
fi
fi
info "Building configure script (autoreconf)."
autoreconf -f || error_cleanup "Autoconf failed."
+16 -15
View File
@@ -79,7 +79,7 @@
i+(int)((unsigned int)name[i]) < len) {
memmove(buf, name + i + 1, (unsigned int)name[i]);
buf[(unsigned int)name[i]] = 0;
PyList_SetItem(list, cnt, PyString_FromString(buf));
PyList_SetItem(list, cnt, PyUnicode_FromString(buf));
}
i += ((unsigned int)name[i]) + 1;
cnt++;
@@ -96,7 +96,7 @@
list = PyList_New(len);
for (i=0; i < len; i++) {
PyList_SET_ITEM(list, i, PyString_FromString(array[i]));
PyList_SET_ITEM(list, i, PyUnicode_FromString(array[i]));
}
return list;
}
@@ -207,7 +207,7 @@ struct query_info {
char buf[LDNS_MAX_DOMAINLEN];
buf[0] = '\0';
dname_str((uint8_t*)PyBytes_AsString(dname), buf);
return PyString_FromString(buf);
return PyUnicode_FromString(buf);
}
%}
@@ -345,7 +345,7 @@ struct packed_rrset_data {
PyObject* _get_data_rr_len(struct packed_rrset_data* d, int idx) {
if ((d != NULL) && (idx >= 0) &&
((size_t)idx < (d->count+d->rrsig_count)))
return PyInt_FromLong(d->rr_len[idx]);
return PyLong_FromLong(d->rr_len[idx]);
return Py_None;
}
void _set_data_rr_ttl(struct packed_rrset_data* d, int idx, uint32_t ttl)
@@ -357,7 +357,7 @@ struct packed_rrset_data {
PyObject* _get_data_rr_ttl(struct packed_rrset_data* d, int idx) {
if ((d != NULL) && (idx >= 0) &&
((size_t)idx < (d->count+d->rrsig_count)))
return PyInt_FromLong(d->rr_ttl[idx]);
return PyLong_FromLong(d->rr_ttl[idx]);
return Py_None;
}
PyObject* _get_data_rr_data(struct packed_rrset_data* d, int idx) {
@@ -555,12 +555,12 @@ struct sockaddr_storage {};
if (ss->ss_family == AF_INET) {
const struct sockaddr_in *sa4 = (struct sockaddr_in *)ss;
return PyInt_FromLong(ntohs(sa4->sin_port));
return PyLong_FromLong(ntohs(sa4->sin_port));
}
if (ss->ss_family == AF_INET6) {
const struct sockaddr_in6 *sa6 = (struct sockaddr_in6 *)ss;
return PyInt_FromLong(ntohs(sa6->sin6_port));
return PyLong_FromLong(ntohs(sa6->sin6_port));
}
return Py_None;
@@ -574,7 +574,7 @@ struct sockaddr_storage {};
}
sa6 = (struct sockaddr_in6 *)ss;
return PyInt_FromLong(ntohl(sa6->sin6_flowinfo));
return PyLong_FromLong(ntohl(sa6->sin6_flowinfo));
}
PyObject *_sockaddr_storage_scope_id(const struct sockaddr_storage *ss) {
@@ -585,7 +585,7 @@ struct sockaddr_storage {};
}
sa6 = (struct sockaddr_in6 *)ss;
return PyInt_FromLong(ntohl(sa6->sin6_scope_id));
return PyLong_FromLong(ntohl(sa6->sin6_scope_id));
}
%}
@@ -661,7 +661,7 @@ struct edns_option {
%inline %{
PyObject* _edns_option_opt_code_get(struct edns_option* option) {
uint16_t opt_code = option->opt_code;
return PyInt_FromLong(opt_code);
return PyLong_FromLong(opt_code);
}
PyObject* _edns_option_opt_data_get(struct edns_option* option) {
@@ -729,7 +729,8 @@ struct module_env {
int check_ratelimit,
struct sockaddr_storage* addr, socklen_t addrlen,
uint8_t* zone, size_t zonelen, int tcp_upstream, int ssl_upstream,
char* tls_auth_name, struct module_qstate* q, int* was_ratelimited);
char* tls_auth_name, struct module_qstate* q, int* was_ratelimited,
int* ratelimit_incremented);
void (*detach_subs)(struct module_qstate* qstate);
int (*attach_sub)(struct module_qstate* qstate,
struct query_info* qinfo, struct respip_client_info* cinfo,
@@ -1626,7 +1627,7 @@ int edns_opt_list_append(struct edns_option** list, uint16_t code, size_t len,
}
result = PyObject_Call(func, py_args, py_kwargs);
if (result) {
res = PyInt_AsLong(result);
res = PyLong_AsLong(result);
}
out:
Py_XDECREF(py_edns);
@@ -1710,7 +1711,7 @@ out:
}
result = PyObject_Call(func, py_args, py_kwargs);
if (result) {
res = PyInt_AsLong(result);
res = PyLong_AsLong(result);
}
out:
Py_XDECREF(py_qinfo);
@@ -1764,7 +1765,7 @@ out:
}
result = PyObject_Call(func, py_args, py_kwargs);
if (result) {
res = PyInt_AsLong(result);
res = PyLong_AsLong(result);
}
out:
Py_XDECREF(py_qstate);
@@ -1813,7 +1814,7 @@ out:
}
result = PyObject_Call(func, py_args, py_kwargs);
if (result) {
res = PyInt_AsLong(result);
res = PyLong_AsLong(result);
}
out:
Py_XDECREF(py_qstate);
+18 -5
View File
@@ -246,14 +246,14 @@ log_py_err(void)
}
/* And it should be a string all ready to go - duplicate it. */
if (!PyString_Check(obResult) && !PyUnicode_Check(obResult)) {
if (!PyBytes_Check(obResult) && !PyUnicode_Check(obResult)) {
log_err("pythonmod: cannot print exception, "
"StringIO.getvalue() result did not String_Check"
" or Unicode_Check");
goto cleanup;
}
if(PyString_Check(obResult)) {
result = PyString_AsString(obResult);
if(PyBytes_Check(obResult)) {
result = PyBytes_AsString(obResult);
} else {
ascstr = PyUnicode_AsASCIIString(obResult);
result = PyBytes_AsString(ascstr);
@@ -450,7 +450,7 @@ int pythonmod_init(struct module_env* env, int id)
pe->data = PyDict_New();
/* add the script filename to the global "mod_env" for trivial access */
fname = PyString_FromString(pe->fname);
fname = PyUnicode_FromString(pe->fname);
if(PyDict_SetItemString(pe->data, "script", fname) < 0) {
log_err("pythonmod: could not add item to dictionary");
Py_XDECREF(fname);
@@ -487,10 +487,23 @@ int pythonmod_init(struct module_env* env, int id)
/* for python 3.9 and newer */
char* fstr = NULL;
size_t flen = 0;
long pos = 0;
log_err("pythonmod: can't parse Python script %s", pe->fname);
/* print the error to logs too, run it again */
fseek(script_py, 0, SEEK_END);
flen = (size_t)ftell(script_py);
pos = ftell(script_py);
if (pos == -1L) {
log_err("ftell failed to print parse error: %s: %s",
pe->fname, strerror(errno));
goto fail_close_file;
}
flen = (size_t)pos;
#ifdef SIZE_MAX
if(flen > SIZE_MAX-2) {
log_err("script file too large");
goto fail_close_file;
}
#endif
fstr = malloc(flen+1);
if(!fstr) {
log_err("malloc failure to print parse error");
+32 -21
View File
@@ -899,27 +899,34 @@ respip_rewrite_reply(const struct query_info* qinfo,
int rpz_cname_override = 0;
char* log_name = NULL;
if(!cinfo)
goto done;
ctaglist = cinfo->taglist;
ctaglen = cinfo->taglen;
tag_actions = cinfo->tag_actions;
tag_actions_size = cinfo->tag_actions_size;
tag_datas = cinfo->tag_datas;
tag_datas_size = cinfo->tag_datas_size;
if(cinfo->view) {
view = cinfo->view;
lock_rw_rdlock(&view->lock);
} else if(cinfo->view_name) {
view = views_find_view(views, cinfo->view_name, 0);
if(!view) {
/* If the view no longer exists, the rewrite can not
* be processed further. */
verbose(VERB_ALGO, "respip: failed because view %s no "
"longer exists", cinfo->view_name);
return 0;
if(!cinfo) {
/* Internal mesh sub-query (e.g. dns64 A lookup): no
* per-client view/tags, but global response-ip and RPZ
* rpz-ip must still apply. */
ctaglist = NULL; ctaglen = 0;
tag_actions = NULL; tag_actions_size = 0;
tag_datas = NULL; tag_datas_size = 0;
} else {
ctaglist = cinfo->taglist;
ctaglen = cinfo->taglen;
tag_actions = cinfo->tag_actions;
tag_actions_size = cinfo->tag_actions_size;
tag_datas = cinfo->tag_datas;
tag_datas_size = cinfo->tag_datas_size;
if(cinfo->view) {
view = cinfo->view;
lock_rw_rdlock(&view->lock);
} else if(cinfo->view_name) {
view = views_find_view(views, cinfo->view_name, 0);
if(!view) {
/* If the view no longer exists, the rewrite can not
* be processed further. */
verbose(VERB_ALGO, "respip: failed because view %s no "
"longer exists", cinfo->view_name);
return 0;
}
/* The view is rdlocked by views_find_view. */
}
/* The view is rdlocked by views_find_view. */
}
log_assert(ipset);
@@ -1157,8 +1164,10 @@ respip_operate(struct module_qstate* qstate, enum module_ev event, int id,
* clients. */
qstate->is_drop = 1;
} else if(alias_rrset) {
if(!generate_cname_request(qstate, alias_rrset))
if(!generate_cname_request(qstate, alias_rrset)) {
errinf(qstate, "Could not generate CNAME request");
goto servfail;
}
next_state = module_wait_subquery;
}
qstate->return_msg->rep = new_rep;
@@ -1172,6 +1181,7 @@ respip_operate(struct module_qstate* qstate, enum module_ev event, int id,
servfail:
qstate->return_rcode = LDNS_RCODE_SERVFAIL;
qstate->return_msg = NULL;
qstate->ext_state[id] = module_finished;
}
int
@@ -1268,6 +1278,7 @@ respip_inform_super(struct module_qstate* qstate, int id,
return;
fail:
errinf(super, "CNAME lookup failed");
super->return_rcode = LDNS_RCODE_SERVFAIL;
super->return_msg = NULL;
return;
+290 -59
View File
@@ -55,6 +55,7 @@
#include "util/log.h"
#include "util/module.h"
#include "util/random.h"
#include "util/timeval_func.h"
#include "services/cache/dns.h"
#include "services/outside_network.h"
#include "services/listen_dnsport.h"
@@ -95,6 +96,8 @@
/** number of timeouts before we fallback from IXFR to AXFR,
* because some versions of servers (eg. dnsmasq) drop IXFR packets. */
#define NUM_TIMEOUTS_FALLBACK_IXFR 3
/** number of IXFRs before an AXFR is performed, to consolidate RPZ memory. */
#define NUM_IXFR_BEFORE_AXFR 5
/** pick up nextprobe task to start waiting to perform transfer actions */
static void xfr_set_timeout(struct auth_xfer* xfr, struct module_env* env,
@@ -106,6 +109,9 @@ static void xfr_probe_send_or_end(struct auth_xfer* xfr,
* or transfer task if nothing to probe, or false if already in progress */
static int xfr_start_probe(struct auth_xfer* xfr, struct module_env* env,
struct auth_master* spec);
/** copy the master addresses from the task_probe lookups to the allow_notify
* list of masters */
static void probe_copy_masters_for_allow_notify(struct auth_xfer* xfr);
/** delete xfer structure (not its tree entry) */
void auth_xfer_delete(struct auth_xfer* xfr);
@@ -432,7 +438,12 @@ auth_zone_create(struct auth_zones* az, uint8_t* nm, size_t nmlen,
rbtree_init(&z->data, &auth_data_cmp);
lock_rw_init(&z->lock);
lock_protect(&z->lock, &z->name, sizeof(*z)-sizeof(rbnode_type)-
sizeof(&z->rpz_az_next)-sizeof(&z->rpz_az_prev));
sizeof(z->rpz_az_next)-sizeof(z->rpz_az_prev)-
sizeof(z->max_transfer_size)-sizeof(z->max_transfer_size));
lock_protect(&z->lock, &z->max_transfer_size,
sizeof(z->max_transfer_size));
lock_protect(&z->lock, &z->max_transfer_time,
sizeof(z->max_transfer_time));
lock_rw_wrlock(&z->lock);
/* z lock protects all, except rbtree itself and the rpz linked list
* pointers, which are protected using az->lock */
@@ -1175,6 +1186,22 @@ az_insert_rr(struct auth_zone* z, uint8_t* rr, size_t rr_len,
log_err("wrong class for RR");
return 0;
}
if(rr_type == LDNS_RR_TYPE_A && rdatalen != 6 /* 2 + 4 */) {
log_err("malformed A record");
return 0;
} else if(rr_type == LDNS_RR_TYPE_AAAA && rdatalen != 18 /* 2 + 16 */) {
log_err("malformed AAAA record");
return 0;
}
if(!dname_subdomain_c(dname, z->name)) {
char nm[LDNS_MAX_DOMAINLEN], zn[LDNS_MAX_DOMAINLEN];
dname_str(dname, nm);
dname_str(z->name, zn);
verbose(VERB_ALGO, "auth-zone %s: dropping out-of-zone RR "
"%s", zn, nm);
if(duplicate) *duplicate=1; /* treat as bad insert */
return 1;
}
if(!(node=az_domain_find_or_create(z, dname, dname_len))) {
log_err("cannot create domain");
return 0;
@@ -1182,6 +1209,10 @@ az_insert_rr(struct auth_zone* z, uint8_t* rr, size_t rr_len,
if(!az_domain_add_rr(node, rr_type, rr_ttl, rdata, rdatalen,
duplicate)) {
log_err("cannot add RR to domain");
if(node->rrsets == NULL) {
(void)rbtree_delete(&z->data, node);
auth_data_delete(node);
}
return 0;
}
if(z->rpz) {
@@ -1505,6 +1536,11 @@ az_parse_file(struct auth_zone* z, FILE* in, uint8_t* rr, size_t rrbuflen,
"exceeded", fname, state->lineno);
return 0;
}
/* A $INCLUDE is not expected for a secondary zone. */
if(z->zone_is_slave) {
log_err("%s:%d $INCLUDE not allowed for secondary zone", fname, state->lineno);
return 0;
}
/* skip spaces */
while(*incfile == ' ' || *incfile == '\t')
incfile++;
@@ -1570,6 +1606,16 @@ az_parse_file(struct auth_zone* z, FILE* in, uint8_t* rr, size_t rrbuflen,
return 1;
}
void auth_zone_clear_data(struct auth_zone* z)
{
/* clear the data tree */
traverse_postorder(&z->data, auth_data_del, NULL);
rbtree_init(&z->data, &auth_data_cmp);
/* clear the RPZ policies */
if(z->rpz)
rpz_clear(z->rpz);
}
int
auth_zone_read_zonefile(struct auth_zone* z, struct config_file* cfg)
{
@@ -1592,10 +1638,16 @@ auth_zone_read_zonefile(struct auth_zone* z, struct config_file* cfg)
in = fopen(zfilename, "r");
if(!in) {
char* n = sldns_wire2str_dname(z->name, z->namelen);
if(z->zone_is_slave && errno == ENOENT) {
/* we fetch the zone contents later, no file yet */
verbose(VERB_ALGO, "no zonefile %s for %s",
zfilename, n?n:"error");
if(errno == ENOENT) {
/* For a secondary, fetch the zone contents later, no
* file yet. For a primary, no way to fetch the zone,
* so warn. */
if(z->zone_is_slave)
verbose(VERB_ALGO, "no zonefile %s for %s",
zfilename, n?n:"error");
else
log_warn("no zonefile %s for %s",
zfilename, n?n:"error");
free(n);
return 1;
}
@@ -1798,9 +1850,11 @@ auth_zones_read_zones(struct auth_zones* az, struct config_file* cfg,
RBTREE_FOR(z, struct auth_zone*, &az->ztree) {
lock_rw_wrlock(&z->lock);
if(!auth_zone_read_zonefile(z, cfg)) {
/* For both secondary and primary zones, not fatal.
* This keeps the server up. */
auth_zone_clear_data(z);
lock_rw_unlock(&z->lock);
lock_rw_unlock(&az->lock);
return 0;
continue;
}
if(z->zonefile && z->zonefile[0]!=0 && env)
zonemd_offline_verify(z, env, mods);
@@ -2076,6 +2130,7 @@ auth_xfer_setup(struct auth_zone* z, struct auth_xfer* x)
if(!xfr_find_soa(z, x)) {
return 1;
}
x->is_rpz = (z->rpz!=NULL);
/* nothing for probe, nextprobe and transfer tasks */
return 1;
}
@@ -2135,6 +2190,9 @@ auth_zones_cfg(struct auth_zones* az, struct config_auth* c)
}
return 0;
}
/* Populate the xfer related options early since we may create one now */
z->max_transfer_size = c->max_transfer_size;
z->max_transfer_time = c->max_transfer_time;
if(c->masters || c->urls) {
if(!(x=auth_zones_find_or_add_xfer(az, z))) {
lock_rw_unlock(&az->lock);
@@ -2168,7 +2226,12 @@ auth_zones_cfg(struct auth_zones* az, struct config_auth* c)
z->zonemd_reject_absence = c->zonemd_reject_absence;
if(c->isrpz && !z->rpz){
if(!(z->rpz = rpz_create(c))){
fatal_exit("Could not setup RPZ zones");
log_err("Could not setup RPZ zones");
if(x) {
lock_basic_unlock(&x->lock);
}
lock_rw_unlock(&z->lock);
lock_rw_unlock(&az->rpz_lock);
return 0;
}
lock_protect(&z->lock, &z->rpz->local_zones, sizeof(*z->rpz));
@@ -2206,6 +2269,10 @@ auth_zones_cfg(struct auth_zones* az, struct config_auth* c)
lock_rw_unlock(&z->lock);
return 0;
}
/* Pick up allow notify entries, early. This works for
* addresses and netblocks. */
if(!x->allow_notify_list)
probe_copy_masters_for_allow_notify(x);
lock_basic_unlock(&x->lock);
}
@@ -2313,6 +2380,7 @@ auth_chunks_delete(struct auth_transfer* at)
}
at->chunks_first = NULL;
at->chunks_last = NULL;
at->chunks_total = 0;
}
/** free master addr list */
@@ -2644,7 +2712,7 @@ az_empty_nonterminal(struct auth_zone* z, struct query_info* qinfo,
while(next && (rbnode_type*)next != RBTREE_NULL && next->rrsets == NULL) {
/* the next name has empty rrsets, is an empty nonterminal
* itself, see if there exists something below it */
next = (struct auth_data*)rbtree_next(&node->node);
next = (struct auth_data*)rbtree_next(&next->node);
}
if((rbnode_type*)next == RBTREE_NULL || !next) {
/* there is no next node, so something below it cannot
@@ -4298,7 +4366,7 @@ xfr_create_ixfr_packet(struct auth_xfer* xfr, sldns_buffer* buf, uint16_t id,
{
struct query_info qinfo;
uint32_t serial;
int have_zone;
int have_zone, get_full = 0;
have_zone = xfr->have_zone;
serial = xfr->serial;
@@ -4311,7 +4379,18 @@ xfr_create_ixfr_packet(struct auth_xfer* xfr, sldns_buffer* buf, uint16_t id,
xfr->task_transfer->on_ixfr_is_axfr = 0;
xfr->task_transfer->on_ixfr = 1;
qinfo.qtype = LDNS_RR_TYPE_IXFR;
if(!have_zone || xfr->task_transfer->ixfr_fail || !master->ixfr) {
if(xfr->num_ixfrs >= NUM_IXFR_BEFORE_AXFR && xfr->is_rpz) {
/* For the RPZ, an IXFR is going to grow regions, and a
* full transfer, zonefile read, AXFR and HTTP clear the
* region, but IXFR does not. That memory keeps growing,
* and getting a full transfer with AXFR here resets that.
* The rpz->client_set->region, rpz->ns_set->region and
* rpz->respip_set->region need to be reset, they are for
* rpz-client-ip, rpz-nsip and rpz-ip. */
get_full = 1;
}
if(!have_zone || xfr->task_transfer->ixfr_fail || !master->ixfr
|| get_full) {
qinfo.qtype = LDNS_RR_TYPE_AXFR;
xfr->task_transfer->ixfr_fail = 0;
xfr->task_transfer->on_ixfr = 0;
@@ -4462,29 +4541,31 @@ chunkline_get_line(struct auth_chunk** chunk, size_t* chunk_pos,
}
/** count number of open and closed parenthesis in a chunkline */
static int
int
chunkline_count_parens(sldns_buffer* buf, size_t start)
{
size_t end = sldns_buffer_position(buf);
size_t i;
int count = 0;
int squote = 0, dquote = 0;
int dquote = 0;
char prev_c = 0;
for(i=start; i<end; i++) {
char c = (char)sldns_buffer_read_u8_at(buf, i);
if(squote && c != '\'') continue;
if(dquote && c != '"') continue;
if(c == '"')
if(dquote && !(c == '"' && prev_c != '\\')) {
prev_c = (prev_c == '\\' && c == '\\') ? 0 : c;
continue;
}
if(c == '"' && prev_c != '\\')
dquote = !dquote; /* skip quoted part */
else if(c == '\'')
squote = !squote; /* skip quoted part */
else if(c == '(')
else if(c == '(' && prev_c != '\\')
count ++;
else if(c == ')')
else if(c == ')' && prev_c != '\\')
count --;
else if(c == ';') {
else if(c == ';' && prev_c != '\\') {
/* rest is a comment */
return count;
}
prev_c = (prev_c == '\\' && c == '\\') ? 0 : c;
}
return count;
}
@@ -4495,20 +4576,22 @@ chunkline_remove_trailcomment(sldns_buffer* buf, size_t start)
{
size_t end = sldns_buffer_position(buf);
size_t i;
int squote = 0, dquote = 0;
int dquote = 0;
char prev_c = 0;
for(i=start; i<end; i++) {
char c = (char)sldns_buffer_read_u8_at(buf, i);
if(squote && c != '\'') continue;
if(dquote && c != '"') continue;
if(c == '"')
if(dquote && !(c == '"' && prev_c != '\\')) {
prev_c = (prev_c == '\\' && c == '\\') ? 0 : c;
continue;
}
if(c == '"' && prev_c != '\\')
dquote = !dquote; /* skip quoted part */
else if(c == '\'')
squote = !squote; /* skip quoted part */
else if(c == ';') {
else if(c == ';' && prev_c != '\\') {
/* rest is a comment */
sldns_buffer_set_position(buf, i);
return;
}
prev_c = (prev_c == '\\' && c == '\\') ? 0 : c;
}
/* nothing to remove */
}
@@ -4932,6 +5015,8 @@ apply_ixfr(struct auth_xfer* xfr, struct auth_zone* z,
int delmode = 0;
int softfail = 0;
xfr->num_ixfrs++;
/* start RR iterator over chunklist of packets */
chunk_rrlist_start(xfr, &rr_chunk, &rr_num, &rr_pos);
while(!chunk_rrlist_end(rr_chunk, rr_num)) {
@@ -5067,16 +5152,11 @@ apply_axfr(struct auth_xfer* xfr, struct auth_zone* z,
size_t rr_counter = 0;
int have_end_soa = 0;
/* clear the data tree */
traverse_postorder(&z->data, auth_data_del, NULL);
rbtree_init(&z->data, &auth_data_cmp);
/* clear the RPZ policies */
if(z->rpz)
rpz_clear(z->rpz);
auth_zone_clear_data(z);
xfr->have_zone = 0;
xfr->serial = 0;
xfr->soa_zone_acquired = 0;
xfr->num_ixfrs = 0;
/* insert all RRs in to the zone */
/* insert the SOA only once, skip the last one */
@@ -5169,16 +5249,11 @@ apply_http(struct auth_xfer* xfr, struct auth_zone* z,
return 0;
}
/* clear the data tree */
traverse_postorder(&z->data, auth_data_del, NULL);
rbtree_init(&z->data, &auth_data_cmp);
/* clear the RPZ policies */
if(z->rpz)
rpz_clear(z->rpz);
auth_zone_clear_data(z);
xfr->have_zone = 0;
xfr->serial = 0;
xfr->soa_zone_acquired = 0;
xfr->num_ixfrs = 0;
chunk = xfr->task_transfer->chunks_first;
chunk_pos = 0;
@@ -5359,6 +5434,7 @@ xfr_process_chunk_list(struct auth_xfer* xfr, struct module_env* env,
/* apply data */
if(xfr->task_transfer->master->http) {
if(!apply_http(xfr, z, env->scratch_buffer)) {
auth_zone_clear_data(z);
lock_rw_unlock(&z->lock);
verbose(VERB_ALGO, "http from %s: could not store data",
xfr->task_transfer->master->host);
@@ -5367,6 +5443,7 @@ xfr_process_chunk_list(struct auth_xfer* xfr, struct module_env* env,
} else if(xfr->task_transfer->on_ixfr &&
!xfr->task_transfer->on_ixfr_is_axfr) {
if(!apply_ixfr(xfr, z, env->scratch_buffer)) {
auth_zone_clear_data(z);
lock_rw_unlock(&z->lock);
verbose(VERB_ALGO, "xfr from %s: could not store IXFR"
" data", xfr->task_transfer->master->host);
@@ -5375,6 +5452,7 @@ xfr_process_chunk_list(struct auth_xfer* xfr, struct module_env* env,
}
} else {
if(!apply_axfr(xfr, z, env->scratch_buffer)) {
auth_zone_clear_data(z);
lock_rw_unlock(&z->lock);
verbose(VERB_ALGO, "xfr from %s: could not store AXFR"
" data", xfr->task_transfer->master->host);
@@ -5391,6 +5469,7 @@ xfr_process_chunk_list(struct auth_xfer* xfr, struct module_env* env,
}
z->soa_zone_acquired = *env->now;
xfr->soa_zone_acquired = *env->now;
xfr->is_rpz = (z->rpz!=NULL);
/* release xfr lock while verifying zonemd because it may have
* to spawn lookups in the state machines */
@@ -5440,16 +5519,50 @@ xfr_process_chunk_list(struct auth_xfer* xfr, struct module_env* env,
return 1;
}
/** Stop lookup using callback */
static void
xfr_stop_lookup(struct auth_master** lookup_target, void* lookup_unique_info,
int lookup_aaaa, uint16_t dclass, struct mesh_area* mesh,
mesh_cb_func_type cb, void* cb_arg)
{
struct query_info qinfo;
uint8_t dname[LDNS_MAX_DOMAINLEN+1];
if(!*lookup_target) return;
qinfo.qname_len = sizeof(dname);
if(sldns_str2wire_dname_buf((*lookup_target)->host, dname,
&qinfo.qname_len) != 0) {
*lookup_target = NULL;
return;
}
qinfo.qname = dname;
qinfo.qclass = dclass;
qinfo.qtype = lookup_aaaa ? LDNS_RR_TYPE_AAAA : LDNS_RR_TYPE_A;
qinfo.local_alias = NULL;
log_query_info(VERB_ALGO, "removing xfr callback", &qinfo);
mesh_remove_callback(mesh, &qinfo, BIT_RD, cb, cb_arg,
lookup_unique_info);
*lookup_target = NULL;
}
/** disown task_transfer. caller must hold xfr.lock */
static void
xfr_transfer_disown(struct auth_xfer* xfr)
{
/* remove data chunks */
auth_chunks_delete(xfr->task_transfer);
/* remove timer (from this worker's event base) */
comm_timer_delete(xfr->task_transfer->timer);
xfr->task_transfer->timer = NULL;
/* remove the commpoint */
comm_point_delete(xfr->task_transfer->cp);
xfr->task_transfer->cp = NULL;
if(xfr->task_transfer->env)
xfr_stop_lookup(&xfr->task_transfer->lookup_target,
xfr->task_transfer->lookup_unique_info,
xfr->task_transfer->lookup_aaaa, xfr->dclass,
xfr->task_transfer->env->mesh,
&auth_xfer_transfer_lookup_callback, xfr);
/* we don't own this item anymore */
xfr->task_transfer->worker = NULL;
xfr->task_transfer->env = NULL;
@@ -5516,7 +5629,8 @@ xfr_transfer_lookup_host(struct auth_xfer* xfr, struct module_env* env)
* called straight away */
lock_basic_unlock(&xfr->lock);
if(!mesh_new_callback(env->mesh, &qinfo, qflags, &edns, buf, 0,
&auth_xfer_transfer_lookup_callback, xfr, 0)) {
&auth_xfer_transfer_lookup_callback, xfr, 0,
&xfr->task_transfer->lookup_unique_info)) {
lock_basic_lock(&xfr->lock);
log_err("out of memory lookup up master %s", master->host);
return 0;
@@ -5574,6 +5688,7 @@ xfr_transfer_init_fetch(struct auth_xfer* xfr, struct module_env* env)
t.tv_sec = timeout/1000;
t.tv_usec = (timeout%1000)*1000;
#endif
xfr->task_transfer->start_time = *env->now_tv;
if(master->http) {
/* perform http fetch */
@@ -5743,6 +5858,31 @@ xfr_master_add_addrs(struct auth_master* m, struct ub_packed_rrset_key* rrset,
}
}
/** check if the lookup target name equals the found answer name. */
static int
xfer_target_equals_answer_name(struct auth_master* lookup_target,
struct ub_packed_rrset_key* answer, struct query_info* rq,
struct reply_info* rep)
{
uint8_t qname[LDNS_MAX_DOMAINLEN+1];
size_t qname_len;
if(!lookup_target) return 0;
if(!answer) return 0;
qname_len = sizeof(qname);
if(sldns_str2wire_dname_buf(lookup_target->host, qname, &qname_len)
!= 0) {
verbose(VERB_ALGO, "xfer_target_equals_answer_name: could not parse auth host name");
return 0;
}
if(query_dname_compare(answer->rk.dname, qname) == 0)
return 1;
/* It could be a CNAME. */
if(reply_find_rrset_section_an(rep, qname, qname_len,
LDNS_RR_TYPE_CNAME, rq->qclass))
return 1;
return 0;
}
/** callback for task_transfer lookup of host name, of A or AAAA */
void auth_xfer_transfer_lookup_callback(void* arg, int rcode, sldns_buffer* buf,
enum sec_status sec, char* why_bogus, int ATTR_UNUSED(was_ratelimited))
@@ -5781,21 +5921,29 @@ void auth_xfer_transfer_lookup_callback(void* arg, int rcode, sldns_buffer* buf,
/* parsed successfully */
struct ub_packed_rrset_key* answer =
reply_find_answer_rrset(&rq, rep);
if(answer) {
if(answer && xfer_target_equals_answer_name(
xfr->task_transfer->lookup_target, answer,
&rq, rep)) {
xfr_master_add_addrs(xfr->task_transfer->
lookup_target, answer, wanted_qtype);
} else if(answer) {
if(verbosity >= VERB_ALGO) {
char zname[LDNS_MAX_DOMAINLEN];
dname_str(xfr->name, zname);
verbose(VERB_ALGO, "auth zone %s host %s type %s transfer lookup has mismatch in answer name", zname, ((xfr->task_transfer->lookup_target && xfr->task_transfer->lookup_target->host) ? xfr->task_transfer->lookup_target->host : "null"), (xfr->task_transfer->lookup_aaaa?"AAAA":"A"));
}
} else {
if(verbosity >= VERB_ALGO) {
char zname[LDNS_MAX_DOMAINLEN];
dname_str(xfr->name, zname);
verbose(VERB_ALGO, "auth zone %s host %s type %s transfer lookup has nodata", zname, xfr->task_transfer->lookup_target->host, (xfr->task_transfer->lookup_aaaa?"AAAA":"A"));
verbose(VERB_ALGO, "auth zone %s host %s type %s transfer lookup has nodata", zname, ((xfr->task_transfer->lookup_target && xfr->task_transfer->lookup_target->host) ? xfr->task_transfer->lookup_target->host : "null"), (xfr->task_transfer->lookup_aaaa?"AAAA":"A"));
}
}
} else {
if(verbosity >= VERB_ALGO) {
char zname[LDNS_MAX_DOMAINLEN];
dname_str(xfr->name, zname);
verbose(VERB_ALGO, "auth zone %s host %s type %s transfer lookup has no answer", zname, xfr->task_transfer->lookup_target->host, (xfr->task_transfer->lookup_aaaa?"AAAA":"A"));
verbose(VERB_ALGO, "auth zone %s host %s type %s transfer lookup has no answer", zname, ((xfr->task_transfer->lookup_target && xfr->task_transfer->lookup_target->host) ? xfr->task_transfer->lookup_target->host : "null"), (xfr->task_transfer->lookup_aaaa?"AAAA":"A"));
}
}
regional_free_all(temp);
@@ -5803,10 +5951,11 @@ void auth_xfer_transfer_lookup_callback(void* arg, int rcode, sldns_buffer* buf,
if(verbosity >= VERB_ALGO) {
char zname[LDNS_MAX_DOMAINLEN];
dname_str(xfr->name, zname);
verbose(VERB_ALGO, "auth zone %s host %s type %s transfer lookup failed", zname, xfr->task_transfer->lookup_target->host, (xfr->task_transfer->lookup_aaaa?"AAAA":"A"));
verbose(VERB_ALGO, "auth zone %s host %s type %s transfer lookup failed", zname, ((xfr->task_transfer->lookup_target && xfr->task_transfer->lookup_target->host) ? xfr->task_transfer->lookup_target->host : "null"), (xfr->task_transfer->lookup_aaaa?"AAAA":"A"));
}
}
if(xfr->task_transfer->lookup_target->list &&
if(xfr->task_transfer->lookup_target &&
xfr->task_transfer->lookup_target->list &&
xfr->task_transfer->lookup_target == xfr_transfer_current_master(xfr))
xfr->task_transfer->scan_addr = xfr->task_transfer->lookup_target->list;
@@ -6136,6 +6285,7 @@ xfer_link_data(sldns_buffer* pkt, struct auth_xfer* xfr)
if(xfr->task_transfer->chunks_last)
xfr->task_transfer->chunks_last->next = e;
xfr->task_transfer->chunks_last = e;
xfr->task_transfer->chunks_total += e->len;
return 1;
}
@@ -6231,6 +6381,15 @@ auth_xfer_transfer_timer_callback(void* arg)
xfr_transfer_nexttarget_or_end(xfr, env);
}
/** return the time taken by the transfer */
static int
auth_xfer_transfer_time_taken(struct auth_xfer* xfr, struct module_env* env)
{
struct timeval delta;
timeval_subtract(&delta, env->now_tv, &xfr->task_transfer->start_time);
return ((int)delta.tv_sec)*1000 + ((int)delta.tv_usec)/1000;
}
/** callback for task_transfer tcp connections */
int
auth_xfer_transfer_tcp_callback(struct comm_point* c, void* arg, int err,
@@ -6297,6 +6456,15 @@ auth_xfer_transfer_tcp_callback(struct comm_point* c, void* arg, int err,
xfr->task_transfer->master->host);
goto failed;
}
if(xfr->max_transfer_size > 0 &&
xfr->task_transfer->chunks_total > xfr->max_transfer_size) {
char zname[LDNS_MAX_DOMAINLEN];
dname_str(xfr->name, zname);
log_err("auth zone %s transfer from %s exceeded %u bytes, aborting",
zname, xfr->task_transfer->master->host,
(unsigned)xfr->max_transfer_size);
goto failed;
}
/* if the transfer is done now, disconnect and process the list */
if(transferdone) {
comm_point_delete(xfr->task_transfer->cp);
@@ -6305,6 +6473,16 @@ auth_xfer_transfer_tcp_callback(struct comm_point* c, void* arg, int err,
return 0;
}
if(xfr->max_transfer_time > 0 &&
auth_xfer_transfer_time_taken(xfr, env) > xfr->max_transfer_time) {
char zname[LDNS_MAX_DOMAINLEN];
dname_str(xfr->name, zname);
log_err("auth zone %s transfer from %s exceeded %u msec total running time, aborting",
zname, xfr->task_transfer->master->host,
(unsigned)xfr->max_transfer_time);
goto failed;
}
/* if we want to read more messages, setup the commpoint to read
* a DNS packet, and the timeout */
lock_basic_unlock(&xfr->lock);
@@ -6360,6 +6538,16 @@ auth_xfer_transfer_http_callback(struct comm_point* c, void* arg, int err,
xfr->task_transfer->master->host);
goto failed;
}
if(xfr->max_transfer_size > 0 &&
xfr->task_transfer->chunks_total > xfr->max_transfer_size) {
char zname[LDNS_MAX_DOMAINLEN];
dname_str(xfr->name, zname);
log_err("auth zone %s http %s/%s exceeded %u bytes, aborting",
zname, xfr->task_transfer->master->host,
xfr->task_transfer->master->file,
(unsigned)xfr->max_transfer_size);
goto failed;
}
}
/* if the transfer is done now, disconnect and process the list */
if(err == NETEVENT_DONE) {
@@ -6371,6 +6559,17 @@ auth_xfer_transfer_http_callback(struct comm_point* c, void* arg, int err,
return 0;
}
if(xfr->max_transfer_time > 0 &&
auth_xfer_transfer_time_taken(xfr, env) > xfr->max_transfer_time) {
char zname[LDNS_MAX_DOMAINLEN];
dname_str(xfr->name, zname);
log_err("auth zone %s transfer http %s/%s exceeded %u msec total running time, aborting",
zname, xfr->task_transfer->master->host,
xfr->task_transfer->master->file,
(unsigned)xfr->max_transfer_time);
goto failed;
}
/* if we want to read more messages, setup the commpoint to read
* a DNS packet, and the timeout */
lock_basic_unlock(&xfr->lock);
@@ -6413,6 +6612,12 @@ xfr_probe_disown(struct auth_xfer* xfr)
/* remove the commpoint */
comm_point_delete(xfr->task_probe->cp);
xfr->task_probe->cp = NULL;
if(xfr->task_probe->env)
xfr_stop_lookup(&xfr->task_probe->lookup_target,
xfr->task_probe->lookup_unique_info,
xfr->task_probe->lookup_aaaa, xfr->dclass,
xfr->task_probe->env->mesh,
&auth_xfer_probe_lookup_callback, xfr);
/* we don't own this item anymore */
xfr->task_probe->worker = NULL;
xfr->task_probe->env = NULL;
@@ -6719,7 +6924,8 @@ xfr_probe_lookup_host(struct auth_xfer* xfr, struct module_env* env)
* called straight away */
lock_basic_unlock(&xfr->lock);
if(!mesh_new_callback(env->mesh, &qinfo, qflags, &edns, buf, 0,
&auth_xfer_probe_lookup_callback, xfr, 0)) {
&auth_xfer_probe_lookup_callback, xfr, 0,
&xfr->task_probe->lookup_unique_info)) {
lock_basic_lock(&xfr->lock);
log_err("out of memory lookup up master %s", master->host);
return 0;
@@ -6856,7 +7062,7 @@ void auth_xfer_probe_lookup_callback(void* arg, int rcode, sldns_buffer* buf,
char zname[LDNS_MAX_DOMAINLEN];
dname_str(xfr->name, zname);
verbose(VERB_OPS, "auth zone %s: primary %s address probe lookup is DNSSEC bogus: %s",
zname, xfr->task_transfer->lookup_target->host,
zname, xfr->task_probe->lookup_target->host,
(why_bogus?why_bogus:""));
}
/* fall through to next-lookup / next-master */
@@ -6874,21 +7080,29 @@ void auth_xfer_probe_lookup_callback(void* arg, int rcode, sldns_buffer* buf,
/* parsed successfully */
struct ub_packed_rrset_key* answer =
reply_find_answer_rrset(&rq, rep);
if(answer) {
if(answer && xfer_target_equals_answer_name(
xfr->task_probe->lookup_target, answer,
&rq, rep)) {
xfr_master_add_addrs(xfr->task_probe->
lookup_target, answer, wanted_qtype);
} else if(answer) {
if(verbosity >= VERB_ALGO) {
char zname[LDNS_MAX_DOMAINLEN];
dname_str(xfr->name, zname);
verbose(VERB_ALGO, "auth zone %s host %s type %s probe lookup has mismatch in answer name", zname, ((xfr->task_probe->lookup_target && xfr->task_probe->lookup_target->host) ? xfr->task_probe->lookup_target->host : "null"), (xfr->task_probe->lookup_aaaa?"AAAA":"A"));
}
} else {
if(verbosity >= VERB_ALGO) {
char zname[LDNS_MAX_DOMAINLEN];
dname_str(xfr->name, zname);
verbose(VERB_ALGO, "auth zone %s host %s type %s probe lookup has nodata", zname, xfr->task_probe->lookup_target->host, (xfr->task_probe->lookup_aaaa?"AAAA":"A"));
verbose(VERB_ALGO, "auth zone %s host %s type %s probe lookup has nodata", zname, ((xfr->task_probe->lookup_target && xfr->task_probe->lookup_target->host) ? xfr->task_probe->lookup_target->host : "null"), (xfr->task_probe->lookup_aaaa?"AAAA":"A"));
}
}
} else {
if(verbosity >= VERB_ALGO) {
char zname[LDNS_MAX_DOMAINLEN];
dname_str(xfr->name, zname);
verbose(VERB_ALGO, "auth zone %s host %s type %s probe lookup has no address", zname, xfr->task_probe->lookup_target->host, (xfr->task_probe->lookup_aaaa?"AAAA":"A"));
verbose(VERB_ALGO, "auth zone %s host %s type %s probe lookup has no address", zname, ((xfr->task_probe->lookup_target && xfr->task_probe->lookup_target->host) ? xfr->task_probe->lookup_target->host : "null"), (xfr->task_probe->lookup_aaaa?"AAAA":"A"));
}
}
regional_free_all(temp);
@@ -6896,10 +7110,11 @@ void auth_xfer_probe_lookup_callback(void* arg, int rcode, sldns_buffer* buf,
if(verbosity >= VERB_ALGO) {
char zname[LDNS_MAX_DOMAINLEN];
dname_str(xfr->name, zname);
verbose(VERB_ALGO, "auth zone %s host %s type %s probe lookup failed", zname, xfr->task_probe->lookup_target->host, (xfr->task_probe->lookup_aaaa?"AAAA":"A"));
verbose(VERB_ALGO, "auth zone %s host %s type %s probe lookup failed", zname, ((xfr->task_probe->lookup_target && xfr->task_probe->lookup_target->host) ? xfr->task_probe->lookup_target->host : "null"), (xfr->task_probe->lookup_aaaa?"AAAA":"A"));
}
}
if(xfr->task_probe->lookup_target->list &&
if(xfr->task_probe->lookup_target &&
xfr->task_probe->lookup_target->list &&
xfr->task_probe->lookup_target == xfr_probe_current_master(xfr))
xfr->task_probe->scan_addr = xfr->task_probe->lookup_target->list;
@@ -6966,8 +7181,8 @@ xfr_start_probe(struct auth_xfer* xfr, struct module_env* env,
if(!have_probe_targets(xfr->task_probe->masters) &&
xfr->task_probe->masters != NULL)
xfr->task_probe->only_lookup = 1;
if(!(xfr->task_probe->only_lookup &&
xfr->task_probe->masters != NULL)) {
if(!xfr->task_probe->only_lookup &&
!have_probe_targets(xfr->task_probe->masters)) {
/* useless to pick up task_probe, no masters to
* probe. Instead attempt to pick up task transfer */
if(xfr->task_transfer->worker == NULL) {
@@ -7170,6 +7385,8 @@ auth_xfer_new(struct auth_zone* z)
xfr->namelen = z->namelen;
xfr->namelabs = z->namelabs;
xfr->dclass = z->dclass;
xfr->max_transfer_size = z->max_transfer_size;
xfr->max_transfer_time = z->max_transfer_time;
xfr->task_nextprobe = (struct auth_nextprobe*)calloc(1,
sizeof(struct auth_nextprobe));
@@ -7379,35 +7596,48 @@ xfer_set_masters(struct auth_master** list, struct config_auth* c,
{
struct auth_master* m;
struct config_strlist* p;
struct auth_master** tail;
/* list points to the first, or next pointer for the new element */
while(*list) {
list = &( (*list)->next );
}
if(with_http)
for(p = c->urls; p; p = p->next) {
tail = list;
m = auth_master_new(&list);
if(!m) return 0;
m->http = 1;
if(!parse_url(p->str, &m->host, &m->file, &m->port, &m->ssl))
if(!parse_url(p->str, &m->host, &m->file, &m->port, &m->ssl)) {
free(m->host);
free(m->file);
free(m);
*tail = NULL;
return 0;
}
}
for(p = c->masters; p; p = p->next) {
tail = list;
m = auth_master_new(&list);
if(!m) return 0;
m->ixfr = 1; /* this flag is not configurable */
m->host = strdup(p->str);
if(!m->host) {
log_err("malloc failure");
free(m);
*tail = NULL;
return 0;
}
}
for(p = c->allow_notify; p; p = p->next) {
tail = list;
m = auth_master_new(&list);
if(!m) return 0;
m->allow_notify = 1;
m->host = strdup(p->str);
if(!m->host) {
log_err("malloc failure");
free(m);
*tail = NULL;
return 0;
}
}
@@ -8561,7 +8791,8 @@ zonemd_lookup_dnskey(struct auth_zone* z, struct module_env* env)
/* the callback can be called straight away */
lock_rw_unlock(&z->lock);
if(!mesh_new_callback(env->mesh, &qinfo, qflags, &edns, buf, 0,
&auth_zonemd_dnskey_lookup_callback, z, 0)) {
&auth_zonemd_dnskey_lookup_callback, z, 0,
&z->zonemd_callback_unique_info)) {
lock_rw_wrlock(&z->lock);
log_err("out of memory lookup of %s for zonemd",
(fetch_ds?"DS":"DNSKEY"));
+29
View File
@@ -144,6 +144,8 @@ struct auth_zone {
struct module_env* zonemd_callback_env;
/** for the zonemd callback, the type of data looked up */
uint16_t zonemd_callback_qtype;
/** for the zonemd callback, the unique info */
void* zonemd_callback_unique_info;
/** zone has been deleted */
int zone_deleted;
/** deletelist pointer, unused normally except during delete */
@@ -153,6 +155,10 @@ struct auth_zone {
struct auth_zone* rpz_az_next;
/** previous auth zone containing RPZ data, or NULL */
struct auth_zone* rpz_az_prev;
/** The maximum auth zone transfer size, in bytes. */
size_t max_transfer_size;
/** The maximum auth zone transfer time taken, in msec. */
int max_transfer_time;
};
/**
@@ -283,6 +289,15 @@ struct auth_xfer {
* this is renewed every SOA probe and transfer. On zone load
* from zonefile it is also set (with probe set soon to check) */
time_t lease_time;
/** The maximum auth zone transfer size, in bytes. */
size_t max_transfer_size;
/** The maximum auth zone transfer time taken, in msec. */
int max_transfer_time;
/** the zone is an rpz zone */
int is_rpz;
/** the number of IXFRs since the last full transfer. */
int num_ixfrs;
};
/**
@@ -331,6 +346,8 @@ struct auth_probe {
/** for the hostname lookups, which master is current */
struct auth_master* lookup_target;
/** for the lookup, the callback unique info */
void* lookup_unique_info;
/** are we looking up A or AAAA, first A, then AAAA (if ip6 enabled) */
int lookup_aaaa;
/** we only want to do lookups for making config work (for notify),
@@ -379,12 +396,18 @@ struct auth_transfer {
struct auth_chunk* chunks_first;
/** last element in chunks list (to append new data at the end) */
struct auth_chunk* chunks_last;
/** running total of bytes held in chunks_first..chunks_last */
size_t chunks_total;
/** start time of the transfer */
struct timeval start_time;
/** list of upstream masters for this zone, from config */
struct auth_master* masters;
/** for the hostname lookups, which master is current */
struct auth_master* lookup_target;
/** for the lookup, the callback unique info */
void* lookup_unique_info;
/** are we looking up A or AAAA, first A, then AAAA (if ip6 enabled) */
int lookup_aaaa;
@@ -828,4 +851,10 @@ void auth_xfer_delete(struct auth_xfer* xfr);
*/
void xfr_disown_tasks(struct auth_xfer* xfr, struct worker* worker);
/** count number of open and closed parenthesis in a chunkline */
int chunkline_count_parens(struct sldns_buffer* buf, size_t start);
/** Clear data in auth zone */
void auth_zone_clear_data(struct auth_zone* z);
#endif /* SERVICES_AUTHZONE_H */
+13 -1
View File
@@ -43,6 +43,7 @@
#include "iterator/iter_utils.h"
#include "validator/val_nsec.h"
#include "validator/val_utils.h"
#include "iterator/iter_utils.h"
#include "services/cache/dns.h"
#include "services/cache/rrset.h"
#include "util/data/msgparse.h"
@@ -586,8 +587,12 @@ dns_cache_find_delegation(struct module_env* env, uint8_t* qname,
return NULL;
}
}
if(!delegpt_rrset_add_ns(dp, region, nskey, 0))
if(!delegpt_rrset_add_ns(dp, region, nskey, 0,
deleg_port_number(env))) {
lock_rw_unlock(&nskey->entry.lock);
log_err("find_delegation: addns out of memory");
return NULL;
}
lock_rw_unlock(&nskey->entry.lock); /* first unlock before next lookup*/
/* find and add DS/NSEC (if any) */
if(msg)
@@ -782,11 +787,16 @@ synth_dname_msg(struct ub_packed_rrset_key* rrset, struct regional* region,
uint8_t* newname, *dtarg = NULL;
size_t newlen, dtarglen;
time_t rr_ttl;
int graceperiod = 0;
if(TTL_IS_EXPIRED(d->ttl, now)) {
/* Allow TTL=0 DNAME from upstream within grace period */
if(!(rrset->rk.flags & PACKED_RRSET_UPSTREAM_0TTL))
return NULL;
rr_ttl = 0;
/* Since PACKED_RRSET_UPSTREAM_0TTL set the flag that
* the grace period has been applied, this stops the rrset
* from getting stored back into the cache with a bigger TTL.*/
graceperiod = 1;
} else {
rr_ttl = d->ttl - now;
}
@@ -814,6 +824,8 @@ synth_dname_msg(struct ub_packed_rrset_key* rrset, struct regional* region,
msg->rep->rrsets[0] = packed_rrset_copy_region(rrset, region, now);
if(!msg->rep->rrsets[0]) /* copy DNAME */
return NULL;
if(graceperiod)
msg->rep->rrsets[0]->rk.flags |= PACKED_RRSET_0TTL_GRACE;
/* synth CNAME rrset */
get_cname_target(rrset, &dtarg, &dtarglen);
if(!dtarg)
+16 -5
View File
@@ -215,6 +215,13 @@ rrset_cache_update(struct rrset_cache* r, struct rrset_ref* ref,
int equal = 0;
log_assert(ref->id != 0 && k->id != 0);
log_assert(k->rk.dname != NULL);
if((k->rk.flags&PACKED_RRSET_0TTL_GRACE) !=0) {
log_nametypeclass(VERB_ALGO, "rrset store of PACKED_RRSET_0TTL_GRACE rrset skipped", k->rk.dname, rrset_type, ntohs(k->rk.rrset_class));
ub_packed_rrset_parsedelete(k, alloc);
return 0; /* Do not store 0TTL items after apply of
the grace ttl amount.
This means the ref was not changed by the call. */
}
/* looks up item with a readlock - no editing! */
if((e=slabhash_lookup(&r->table, h, k, 0)) != 0) {
/* return id and key as they will be used in the cache
@@ -291,6 +298,8 @@ void rrset_cache_update_wildcard(struct rrset_cache* rrset_cache,
{
struct rrset_ref ref;
uint8_t wc_dname[LDNS_MAX_DOMAINLEN+3];
uint8_t* new_dname;
size_t new_dname_len;
/* See if the RRSIG signer name allows this wildcard,
* the new rrset should fall within the zone of the RRSIG signer(s). */
@@ -310,14 +319,16 @@ void rrset_cache_update_wildcard(struct rrset_cache* rrset_cache,
wc_dname[1] = (uint8_t)'*';
memmove(wc_dname+2, ce, ce_len);
free(rrset->rk.dname);
rrset->rk.dname_len = ce_len + 2;
rrset->rk.dname = (uint8_t*)memdup(wc_dname, rrset->rk.dname_len);
if(!rrset->rk.dname) {
alloc_special_release(alloc, rrset);
new_dname_len = ce_len + 2;
new_dname = (uint8_t*)memdup(wc_dname, new_dname_len);
if(!new_dname) {
ub_packed_rrset_parsedelete(rrset, alloc);
log_err("memdup failure in rrset_cache_update_wildcard");
return;
}
free(rrset->rk.dname);
rrset->rk.dname = new_dname;
rrset->rk.dname_len = new_dname_len;
rrset->entry.hash = rrset_key_hash(&rrset->rk);
ref.key = rrset;
+30 -10
View File
@@ -1125,7 +1125,7 @@ make_sock_port(int stype, const char* ifname, int port,
int use_systemd, int dscp, struct unbound_socket* ub_sock,
const char* additional)
{
char* s = strchr(ifname, '@');
const char* s = strchr(ifname, '@');
if(s) {
/* override port with ifspec@port */
int port;
@@ -1341,13 +1341,33 @@ ports_create_if(const char* ifname, int do_auto, int do_udp, int do_tcp,
if((is_doq) && !(is_https || is_ssl)) do_tcp = 0;
if(do_auto) {
enum listen_type auto_port_type;
ub_sock = calloc(1, sizeof(struct unbound_socket));
if(!ub_sock)
return 0;
if(is_dnscrypt) {
auto_port_type = listen_type_udpancil_dnscrypt;
add = "udpancil_dnscrypt";
} else if(is_doq) {
auto_port_type = listen_type_doq;
add = "doq";
if(if_listens_on(ifname, port, 53, NULL)) {
log_err("DNS over QUIC is strictly not "
"allowed on port 53 as per RFC 9250. "
"Port 53 is for DNS datagrams. Error "
"for interface '%s'.", ifname);
free(ub_sock->addr);
free(ub_sock);
return 0;
}
} else {
auto_port_type = listen_type_udpancil;
add = "udpancil";
}
if((s = make_sock_port(SOCK_DGRAM, ifname, port, hints, 1,
&noip6, rcv, snd, reuseport, transparent,
tcp_mss, nodelay, freebind, use_systemd, dscp, ub_sock,
(is_dnscrypt?"udpancil_dnscrypt":"udpancil"))) == -1) {
add)) == -1) {
free(ub_sock->addr);
free(ub_sock);
if(noip6) {
@@ -1366,9 +1386,7 @@ ports_create_if(const char* ifname, int do_auto, int do_udp, int do_tcp,
if (sock_queue_timeout && !set_recvtimestamp(s)) {
log_warn("socket timestamping is not available");
}
if(!port_insert(list, s, is_dnscrypt
?listen_type_udpancil_dnscrypt:listen_type_udpancil,
is_pp2, ub_sock)) {
if(!port_insert(list, s, auto_port_type, is_pp2, ub_sock)) {
sock_close(s);
free(ub_sock->addr);
free(ub_sock);
@@ -2167,7 +2185,7 @@ void tcp_req_info_clear(struct tcp_req_info* req)
while(open) {
nopen = open->next;
mesh_state_remove_reply(open->mesh, open->mesh_state, req->cp,
NULL);
NULL, NULL);
free(open);
open = nopen;
}
@@ -3617,7 +3635,7 @@ stream_tree_del(rbnode_type* node, void* arg)
stream = (struct doq_stream*)node;
if(stream->mesh_state) {
mesh_state_remove_reply(stream->mesh, stream->mesh_state,
args->conn->doq_socket->cp, stream);
args->conn->doq_socket->cp, NULL, stream);
stream->mesh_state = NULL;
}
if(stream->in)
@@ -3639,7 +3657,8 @@ doq_conn_delete(struct doq_conn* conn, struct doq_table* table)
lock_rw_unlock(&conn->table->conid_lock);
/* Remove the app data from ngtcp2 before SSL_free of conn->ssl,
* because the ngtcp2 conn is deleted. */
SSL_set_app_data(conn->ssl, NULL);
if(conn->ssl)
SSL_set_app_data(conn->ssl, NULL);
if(conn->stream_tree.count != 0) {
struct doq_stream_tree_del_args args;
memset(&args, 0, sizeof(args));
@@ -3956,7 +3975,7 @@ doq_stream_close(struct doq_conn* conn, struct doq_stream* stream,
stream->is_closed = 1;
if(stream->mesh_state) {
mesh_state_remove_reply(stream->mesh, stream->mesh_state,
conn->doq_socket->cp, stream);
conn->doq_socket->cp, NULL, stream);
stream->mesh_state = NULL;
}
doq_stream_off_write_list(conn, stream);
@@ -4851,7 +4870,7 @@ doq_ssl_server_setup(SSL_CTX* ctx, struct doq_conn* conn)
SSL_set_app_data(ssl, conn);
#endif
SSL_set_accept_state(ssl);
#ifdef USE_NGTCP2_CRYPTO_OSSL
#ifdef HAVE_SSL_SET_QUIC_TLS_EARLY_DATA_ENABLED
SSL_set_quic_tls_early_data_enabled(ssl, 1);
#else
SSL_set_quic_early_data_enabled(ssl, 1);
@@ -4960,6 +4979,7 @@ doq_conn_setup(struct doq_conn* conn, uint8_t* scid, size_t scidlen,
rv = ngtcp2_conn_server_new(&conn->conn, &scid_cid, &sv_scid, &path,
conn->version, &callbacks, &settings, &params, NULL, conn);
if(rv != 0) {
conn->conn = NULL;
lock_rw_unlock(&conn->table->conid_lock);
log_err("ngtcp2_conn_server_new failed: %s",
ngtcp2_strerror(rv));
+56 -11
View File
@@ -386,8 +386,6 @@ new_local_rrset(struct regional* region, struct local_data* node,
log_err("out of memory");
return NULL;
}
rrset->next = node->rrsets;
node->rrsets = rrset;
rrset->rrset = (struct ub_packed_rrset_key*)
regional_alloc_zero(region, sizeof(*rrset->rrset));
if(!rrset->rrset) {
@@ -408,6 +406,8 @@ new_local_rrset(struct regional* region, struct local_data* node,
rrset->rrset->rk.dname_len = node->namelen;
rrset->rrset->rk.type = htons(rrtype);
rrset->rrset->rk.rrset_class = htons(rrclass);
rrset->next = node->rrsets;
node->rrsets = rrset;
return rrset;
}
@@ -431,6 +431,10 @@ rrset_insert_rr(struct regional* region, struct packed_rrset_data* pd,
pd->rr_ttl = regional_alloc(region, sizeof(*pd->rr_ttl)*pd->count);
pd->rr_data = regional_alloc(region, sizeof(*pd->rr_data)*pd->count);
if(!pd->rr_len || !pd->rr_ttl || !pd->rr_data) {
pd->count--;
pd->rr_len = oldlen;
pd->rr_ttl = oldttl;
pd->rr_data = olddata;
log_err("out of memory");
return 0;
}
@@ -446,6 +450,10 @@ rrset_insert_rr(struct regional* region, struct packed_rrset_data* pd,
pd->rr_ttl[0] = ttl;
pd->rr_data[0] = regional_alloc_init(region, rdata, rdata_len);
if(!pd->rr_data[0]) {
pd->count--;
pd->rr_len = oldlen;
pd->rr_ttl = oldttl;
pd->rr_data = olddata;
log_err("out of memory");
return 0;
}
@@ -671,7 +679,9 @@ lz_enter_rr_str(struct local_zones* zones, const char* rr)
z = local_zones_lookup(zones, rr_name, len, labs, rr_class, rr_type, 1);
if(!z) {
lock_rw_unlock(&zones->lock);
fatal_exit("internal error: no zone for rr %s", rr);
log_err("internal error: no zone for rr %s", rr);
free(rr_name);
return 0;
}
lock_rw_wrlock(&z->lock);
lock_rw_unlock(&zones->lock);
@@ -1500,8 +1510,10 @@ find_tag_datas(struct query_info* qinfo, struct config_strlist* list,
return 0; /* out of memory */
qinfo->local_alias->rrset =
regional_alloc_init(temp, r, sizeof(*r));
if(!qinfo->local_alias->rrset)
if(!qinfo->local_alias->rrset) {
qinfo->local_alias = NULL;
return 0; /* out of memory */
}
}
return result;
}
@@ -1567,13 +1579,17 @@ local_data_answer(struct local_zone* z, struct module_env* env,
return 0; /* out of memory */
qinfo->local_alias->rrset = regional_alloc_init(
temp, lr->rrset, sizeof(*lr->rrset));
if(!qinfo->local_alias->rrset)
if(!qinfo->local_alias->rrset) {
qinfo->local_alias = NULL;
return 0; /* out of memory */
}
qinfo->local_alias->rrset->rk.dname = qinfo->qname;
qinfo->local_alias->rrset->rk.dname_len = qinfo->qname_len;
get_cname_target(lr->rrset, &ctarget, &ctargetlen);
if(!ctargetlen)
if(!ctargetlen) {
qinfo->local_alias = NULL;
return 0; /* invalid cname */
}
if(dname_is_wild(ctarget)) {
/* synthesize cname target */
struct packed_rrset_data* d, *lr_d;
@@ -1602,8 +1618,10 @@ local_data_answer(struct local_zone* z, struct module_env* env,
sizeof(struct packed_rrset_data) + sizeof(size_t) +
sizeof(uint8_t*) + sizeof(time_t) + sizeof(uint16_t)
+ newtargetlen);
if(!d)
if(!d) {
qinfo->local_alias = NULL;
return 0; /* out of memory */
}
lr_d = (struct packed_rrset_data*)lr->rrset->entry.data;
qinfo->local_alias->rrset->entry.data = d;
d->ttl = lr_d->rr_ttl[0]; /* RFC6672-like behavior:
@@ -1650,7 +1668,7 @@ local_zone_does_not_cover(struct local_zone* z, struct query_info* qinfo,
struct local_data key;
struct local_data* ld = NULL;
struct local_rrset* lr = NULL;
if(z->type == local_zone_always_transparent || z->type == local_zone_block_a)
if(z->type == local_zone_always_transparent || z->type == local_zone_block_a || z->type == local_zone_block_aaaa)
return 1;
if(z->type != local_zone_transparent
&& z->type != local_zone_typetransparent
@@ -1661,7 +1679,9 @@ local_zone_does_not_cover(struct local_zone* z, struct query_info* qinfo,
key.namelen = qinfo->qname_len;
key.namelabs = labs;
ld = (struct local_data*)rbtree_search(&z->data, &key.node);
if(z->type == local_zone_transparent || z->type == local_zone_inform)
if(z->type == local_zone_transparent || z->type == local_zone_inform
|| z->type == local_zone_block_a_wdata
|| z->type == local_zone_block_aaaa_wdata)
return (ld == NULL);
if(ld)
lr = local_data_find_type(ld, qinfo->qtype, 1);
@@ -1727,7 +1747,8 @@ local_zones_zone_answer(struct local_zone* z, struct module_env* env,
|| lz_type == local_zone_always_transparent) {
/* no NODATA or NXDOMAINS for this zone type */
return 0;
} else if(lz_type == local_zone_block_a) {
} else if(lz_type == local_zone_block_a ||
lz_type == local_zone_block_a_wdata) {
/* Return NODATA for all A queries */
if(qinfo->qtype == LDNS_RR_TYPE_A) {
local_error_encode(qinfo, env, edns, repinfo, buf, temp,
@@ -1736,6 +1757,17 @@ local_zones_zone_answer(struct local_zone* z, struct module_env* env,
return 1;
}
return 0;
} else if(lz_type == local_zone_block_aaaa ||
lz_type == local_zone_block_aaaa_wdata) {
/* Return NODATA for all AAAA queries */
if(qinfo->qtype == LDNS_RR_TYPE_AAAA) {
local_error_encode(qinfo, env, edns, repinfo, buf, temp,
LDNS_RCODE_NOERROR, (LDNS_RCODE_NOERROR|BIT_AA),
LDNS_EDE_NONE, NULL);
return 1;
}
return 0;
} else if(lz_type == local_zone_always_null) {
/* 0.0.0.0 or ::0 or noerror/nodata for this zone type,
@@ -1904,7 +1936,10 @@ local_zones_answer(struct local_zones* zones, struct module_env* env,
lzt == local_zone_typetransparent ||
lzt == local_zone_inform ||
lzt == local_zone_always_transparent ||
lzt == local_zone_block_a) &&
lzt == local_zone_block_a ||
lzt == local_zone_block_aaaa ||
lzt == local_zone_block_a_wdata ||
lzt == local_zone_block_aaaa_wdata) &&
local_zone_does_not_cover(z, qinfo, labs)) {
lock_rw_unlock(&z->lock);
z = NULL;
@@ -1953,6 +1988,7 @@ local_zones_answer(struct local_zones* zones, struct module_env* env,
if(lzt != local_zone_always_refuse
&& lzt != local_zone_always_transparent
&& lzt != local_zone_block_a
&& lzt != local_zone_block_aaaa
&& lzt != local_zone_always_nxdomain
&& lzt != local_zone_always_nodata
&& lzt != local_zone_always_deny
@@ -1984,6 +2020,9 @@ const char* local_zone_type2str(enum localzone_type t)
case local_zone_inform_redirect: return "inform_redirect";
case local_zone_always_transparent: return "always_transparent";
case local_zone_block_a: return "block_a";
case local_zone_block_aaaa: return "block_aaaa";
case local_zone_block_a_wdata: return "block_a_wdata";
case local_zone_block_aaaa_wdata: return "block_aaaa_wdata";
case local_zone_always_refuse: return "always_refuse";
case local_zone_always_nxdomain: return "always_nxdomain";
case local_zone_always_nodata: return "always_nodata";
@@ -2020,6 +2059,12 @@ int local_zone_str2type(const char* type, enum localzone_type* t)
*t = local_zone_always_transparent;
else if(strcmp(type, "block_a") == 0)
*t = local_zone_block_a;
else if(strcmp(type, "block_aaaa") == 0)
*t = local_zone_block_aaaa;
else if(strcmp(type, "block_a_wdata") == 0)
*t = local_zone_block_a_wdata;
else if(strcmp(type, "block_aaaa_wdata") == 0)
*t = local_zone_block_aaaa_wdata;
else if(strcmp(type, "always_refuse") == 0)
*t = local_zone_always_refuse;
else if(strcmp(type, "always_nxdomain") == 0)
+6
View File
@@ -93,6 +93,12 @@ enum localzone_type {
local_zone_always_transparent,
/** resolve normally, even when there is local data but return NODATA for A queries */
local_zone_block_a,
/** resolve normally, even when there is local data, but return NODATA for AAAA queries */
local_zone_block_aaaa,
/** resolve normally, use local data, else return NODATA for A queries */
local_zone_block_a_wdata,
/** resolve normally, use local data, else return NODATA for AAAA queries */
local_zone_block_aaaa_wdata,
/** answer with error, even when there is local data */
local_zone_always_refuse,
/** answer with nxdomain, even when there is local data */
+137 -56
View File
@@ -424,6 +424,44 @@ mesh_serve_expired_init(struct mesh_state* mstate, int timeout)
return 1;
}
/** remove a reply without accounting, rollback the add reply. */
static void
mesh_remove_reply_without_accounting(struct mesh_state* s,
struct mesh_reply* todel)
{
struct mesh_reply* r, *prev = NULL;
for(r = s->reply_list; r; r = r->next) {
if(r == todel) {
if(prev)
prev->next = r->next;
else s->reply_list = r->next;
r->next = NULL;
/* todel is allocated in region */
return;
}
prev = r;
}
}
/** remove a callback without accounting, rollback the add reply. */
static void
mesh_remove_callback_without_accounting(struct mesh_state* s,
struct mesh_cb* todel)
{
struct mesh_cb* r, *prev = NULL;
for(r = s->cb_list; r; r = r->next) {
if(r == todel) {
if(prev)
prev->next = r->next;
else s->cb_list = r->next;
r->next = NULL;
/* todel is allocated in region */
return;
}
prev = r;
}
}
void mesh_new_client(struct mesh_area* mesh, struct query_info* qinfo,
struct respip_client_info* cinfo, uint16_t qflags,
struct edns_data* edns, struct comm_reply* rep, uint16_t qid,
@@ -433,7 +471,8 @@ void mesh_new_client(struct mesh_area* mesh, struct query_info* qinfo,
int unique = unique_mesh_state(edns->opt_list_in, mesh->env);
int was_detached = 0;
int was_noreply = 0;
int added = 0;
int added = 0, added_reply_without_accounting = 0, added_tcp = 0;
struct mesh_reply* repadded = NULL;
int timeout = mesh->env->cfg->serve_expired?
mesh->env->cfg->serve_expired_client_timeout:0;
struct sldns_buffer* r_buffer = rep->c->buffer;
@@ -544,16 +583,18 @@ void mesh_new_client(struct mesh_area* mesh, struct query_info* qinfo,
}
}
/* add reply to s */
if(!mesh_state_add_reply(s, edns, rep, qid, qflags, qinfo)) {
if(!mesh_state_add_reply(s, edns, rep, qid, qflags, qinfo, &repadded)) {
log_err("mesh_new_client: out of memory; SERVFAIL");
goto servfail_mem;
}
added_reply_without_accounting = 1;
if(rep->c->tcp_req_info) {
if(!tcp_req_info_add_meshstate(rep->c->tcp_req_info, mesh, s)) {
log_err("mesh_new_client: out of memory add tcpreqinfo");
goto servfail_mem;
}
}
added_tcp = 1;
if(rep->c->use_h2) {
http2_stream_add_meshstate(rep->c->h2_stream, mesh, s);
} else if(rep->c->type == comm_doq && rep->doq_stream) {
@@ -575,6 +616,8 @@ void mesh_new_client(struct mesh_area* mesh, struct query_info* qinfo,
}
}
#endif
/* Since the acccounting now happens,
* added_reply_without_accounting = 0; but that is not used. */
infra_wait_limit_inc(mesh->env->infra_cache, rep, *mesh->env->now,
mesh->env->cfg);
/* update statistics */
@@ -614,6 +657,11 @@ servfail_mem:
else if(rep->c->type == comm_doq && rep->doq_stream)
doq_stream_remove_mesh_state(rep->doq_stream);
comm_point_send_reply(rep);
if(added_reply_without_accounting) {
mesh_remove_reply_without_accounting(s, repadded);
if(added_tcp && rep->c->tcp_req_info)
tcp_req_info_remove_mesh_state(rep->c->tcp_req_info, s);
}
if(added)
mesh_state_delete(&s->s);
return;
@@ -622,7 +670,8 @@ servfail_mem:
int
mesh_new_callback(struct mesh_area* mesh, struct query_info* qinfo,
uint16_t qflags, struct edns_data* edns, sldns_buffer* buf,
uint16_t qid, mesh_cb_func_type cb, void* cb_arg, int rpz_passthru)
uint16_t qid, mesh_cb_func_type cb, void* cb_arg, int rpz_passthru,
void** unique_info)
{
struct mesh_state* s = NULL;
int unique = unique_mesh_state(edns->opt_list_in, mesh->env);
@@ -631,6 +680,7 @@ mesh_new_callback(struct mesh_area* mesh, struct query_info* qinfo,
int was_detached = 0;
int was_noreply = 0;
int added = 0;
struct mesh_cb* add_cb = NULL;
uint16_t mesh_flags = qflags&(BIT_RD|BIT_CD);
if(!unique)
s = mesh_area_find(mesh, NULL, qinfo, mesh_flags, 0, 0);
@@ -676,13 +726,14 @@ mesh_new_callback(struct mesh_area* mesh, struct query_info* qinfo,
}
}
/* add reply to s */
if(!mesh_state_add_cb(s, edns, buf, cb, cb_arg, qid, qflags)) {
if(!mesh_state_add_cb(s, edns, buf, cb, cb_arg, qid, qflags, &add_cb)) {
if(added)
mesh_state_delete(&s->s);
return 0;
}
/* add serve expired timer if not already there */
if(timeout && !mesh_serve_expired_init(s, timeout)) {
mesh_remove_callback_without_accounting(s, add_cb);
if(added)
mesh_state_delete(&s->s);
return 0;
@@ -693,6 +744,7 @@ mesh_new_callback(struct mesh_area* mesh, struct query_info* qinfo,
(mesh->env->cachedb_enabled &&
mesh->env->cfg->cachedb_check_when_serve_expired)) {
if(!mesh_serve_expired_init(s, -1)) {
mesh_remove_callback_without_accounting(s, add_cb);
if(added)
mesh_state_delete(&s->s);
return 0;
@@ -708,6 +760,8 @@ mesh_new_callback(struct mesh_area* mesh, struct query_info* qinfo,
mesh->num_reply_states ++;
}
mesh->num_reply_addrs++;
if(unique_info)
*unique_info = s->unique;
if(added)
mesh_run(mesh, s, module_event_new, NULL);
return 1;
@@ -911,32 +965,9 @@ void mesh_report_reply(struct mesh_area* mesh, struct outbound_entry* e,
mesh_run(mesh, e->qstate->mesh_info, event, e);
}
/** copy strlist to region */
static struct config_strlist*
cfg_region_strlist_copy(struct regional* region, struct config_strlist* list)
{
struct config_strlist* result = NULL, *last = NULL, *s = list;
while(s) {
struct config_strlist* n = regional_alloc_zero(region,
sizeof(*n));
if(!n)
return NULL;
n->str = regional_strdup(region, s->str);
if(!n->str)
return NULL;
if(last)
last->next = n;
else result = n;
last = n;
s = s->next;
}
return result;
}
struct respip_client_info*
mesh_copy_client_info(struct regional* region, struct respip_client_info* cinfo)
{
size_t i;
struct respip_client_info* client_info;
client_info = regional_alloc_init(region, cinfo, sizeof(*cinfo));
if(!client_info)
@@ -955,20 +986,13 @@ mesh_copy_client_info(struct regional* region, struct respip_client_info* cinfo)
if(!client_info->tag_actions)
return NULL;
}
if(cinfo->tag_datas) {
client_info->tag_datas = regional_alloc_zero(region,
sizeof(struct config_strlist*)*cinfo->tag_datas_size);
if(!client_info->tag_datas)
return NULL;
for(i=0; i<cinfo->tag_datas_size; i++) {
if(cinfo->tag_datas[i]) {
client_info->tag_datas[i] = cfg_region_strlist_copy(
region, cinfo->tag_datas[i]);
if(!client_info->tag_datas[i])
return NULL;
}
}
}
/* tag_datas is owned by the matched acl_addr in config_file; its
* lifetime is until config reload, which tears down all mesh states
* first. Keep the original pointer so client_info_compare()
* can recognise two states from the same ACL entry. */
/* fast reload insists on dropping the queries when interface-tag-data
* or access-control-tag-data are changed. */
/* client_info->tag_datas already copied by regional_alloc_init above */
if(cinfo->view) {
/* Do not copy the view pointer but store a name instead.
* The name is looked up later when done, this means that
@@ -1090,14 +1114,6 @@ mesh_state_cleanup(struct mesh_state* mstate)
if(!mstate->replies_sent) {
struct mesh_reply* rep = mstate->reply_list;
struct mesh_cb* cb;
/* One http2 stream could bring down its comm_point along with
* the other streams which could share the same query. Do all
* the http2 stream bookkeeping upfront. */
for(; rep; rep=rep->next) {
if(rep->query_reply.c->use_h2)
http2_stream_remove_mesh_state(rep->h2_stream);
}
rep = mstate->reply_list;
/* in tcp_req_info, the mstates linked are removed, but
* the reply_list is now NULL, so the remove-from-empty-list
* takes no time and also it does not do the mesh accounting */
@@ -1241,6 +1257,9 @@ int mesh_add_sub(struct module_qstate* qstate, struct query_info* qinfo,
log_err("mesh_attach_sub: out of memory");
return 0;
}
/* inherit RPZ passthru from the parent so respip on the sub
* sees the same client-IP/qname PASSTHRU decision */
(*sub)->s.rpz_passthru = qstate->rpz_passthru;
#ifdef UNBOUND_DEBUG
n =
#else
@@ -1763,7 +1782,8 @@ void mesh_query_done(struct mesh_state* mstate)
}
}
if(mstate->reply_list && mstate->s.env->cfg->dns_error_reporting)
if(mstate->reply_list && mstate->s.env->cfg->dns_error_reporting
&& (!rep || rep->security != sec_status_secure))
dns_error_reporting(&mstate->s, rep);
for(r = mstate->reply_list; r; r = r->next) {
@@ -1946,6 +1966,25 @@ struct mesh_state* mesh_area_find(struct mesh_area* mesh,
return result;
}
struct mesh_state* mesh_area_find_unique(struct mesh_area* mesh,
struct respip_client_info* cinfo, struct query_info* qinfo,
uint16_t qflags, int prime, int valrec, void* unique_info)
{
struct mesh_state key;
struct mesh_state* result;
key.node.key = &key;
key.s.is_priming = prime;
key.s.is_valrec = valrec;
key.s.qinfo = *qinfo;
key.s.query_flags = qflags;
key.unique = (struct mesh_state*)unique_info;
key.s.client_info = cinfo;
result = (struct mesh_state*)rbtree_search(&mesh->all, &key);
return result;
}
/** remove mesh state callback */
int mesh_state_del_cb(struct mesh_state* s, mesh_cb_func_type cb, void* cb_arg)
{
@@ -1967,7 +2006,7 @@ int mesh_state_del_cb(struct mesh_state* s, mesh_cb_func_type cb, void* cb_arg)
int mesh_state_add_cb(struct mesh_state* s, struct edns_data* edns,
sldns_buffer* buf, mesh_cb_func_type cb, void* cb_arg,
uint16_t qid, uint16_t qflags)
uint16_t qid, uint16_t qflags, struct mesh_cb** result)
{
struct mesh_cb* r = regional_alloc(s->s.region,
sizeof(struct mesh_cb));
@@ -1991,13 +2030,14 @@ int mesh_state_add_cb(struct mesh_state* s, struct edns_data* edns,
r->qflags = qflags;
r->next = s->cb_list;
s->cb_list = r;
*result = r;
return 1;
}
int mesh_state_add_reply(struct mesh_state* s, struct edns_data* edns,
struct comm_reply* rep, uint16_t qid, uint16_t qflags,
const struct query_info* qinfo)
const struct query_info* qinfo, struct mesh_reply** result)
{
struct mesh_reply* r = regional_alloc(s->s.region,
sizeof(struct mesh_reply));
@@ -2078,6 +2118,7 @@ int mesh_state_add_reply(struct mesh_state* s, struct edns_data* edns,
r->local_alias = NULL;
s->reply_list = r;
*result = r;
return 1;
}
@@ -2235,8 +2276,29 @@ void mesh_run(struct mesh_area* mesh, struct mesh_state* mstate,
enum module_ev ev, struct outbound_entry* e)
{
enum module_ext_state s;
int numrun = 0;
verbose(VERB_ALGO, "mesh_run: start");
while(mstate) {
if(numrun++ > MESH_MAX_RUN_ITER) {
/* These modules are too much to activate, stop them.*/
log_err("Too many module run iterations, deleting");
while(mstate) {
/* notify supers */
if(mstate->super_set.count > 0) {
verbose(VERB_ALGO, "notify supers of failure");
mstate->s.return_msg = NULL;
mstate->s.return_rcode = LDNS_RCODE_SERVFAIL;
mesh_walk_supers(mesh, mstate);
}
mesh_state_delete(&mstate->s);
if(mesh->run.count > 0) {
/* pop random element off the runnable tree */
mstate = (struct mesh_state*)mesh->run.root->key;
(void)rbtree_delete(&mesh->run, mstate);
} else mstate = NULL;
}
break;
}
/* run the module */
fptr_ok(fptr_whitelist_mod_operate(
mesh->mods.mod[mstate->s.curmod]->operate));
@@ -2388,7 +2450,8 @@ void mesh_list_remove(struct mesh_state* m, struct mesh_state** fp,
}
void mesh_state_remove_reply(struct mesh_area* mesh, struct mesh_state* m,
struct comm_point* cp, struct doq_stream* doq_stream)
struct comm_point* cp, struct http2_stream* h2_stream,
struct doq_stream* doq_stream)
{
struct mesh_reply* n, *prev = NULL;
n = m->reply_list;
@@ -2397,6 +2460,7 @@ void mesh_state_remove_reply(struct mesh_area* mesh, struct mesh_state* m,
if(!n) return; /* nothing to remove, also no accounting needed */
while(n) {
if(n->query_reply.c == cp
&& (!h2_stream || n->h2_stream == h2_stream)
&& (!doq_stream || n->query_reply.doq_stream == doq_stream)) {
/* unlink it */
if(prev) prev->next = n->next;
@@ -2692,13 +2756,30 @@ int mesh_jostle_exceeded(struct mesh_area* mesh)
}
void mesh_remove_callback(struct mesh_area* mesh, struct query_info* qinfo,
uint16_t qflags, mesh_cb_func_type cb, void* cb_arg)
uint16_t qflags, mesh_cb_func_type cb, void* cb_arg, void* unique_info)
{
struct mesh_state* s = NULL;
s = mesh_area_find(mesh, NULL, qinfo, qflags&(BIT_RD|BIT_CD), 0, 0);
if(!s) return;
if(!mesh_state_del_cb(s, cb, cb_arg)) return;
if(s && mesh_state_del_cb(s, cb, cb_arg))
goto removed;
if(unique_info) {
s = mesh_area_find_unique(mesh, NULL, qinfo,
qflags&(BIT_RD|BIT_CD), 0, 0, unique_info);
if(s && mesh_state_del_cb(s, cb, cb_arg))
goto removed;
}
/* mesh_area_find builds key.unique=NULL and cannot match a state
* created with mesh_state_make_unique (e.g. subnetcache sets
* env->unique_mesh). Fall back to a linear scan; cb+cb_arg is an
* exact key (mesh_state_del_cb compares both).
* This works for both lookups for zonemd and for hostname authzone. */
RBTREE_FOR(s, struct mesh_state*, &mesh->all) {
if(s->cb_list && mesh_state_del_cb(s, cb, cb_arg))
goto removed;
}
return;
removed:
/* It was in the list and removed. */
log_assert(mesh->num_reply_addrs > 0);
mesh->num_reply_addrs--;
+38 -5
View File
@@ -69,6 +69,13 @@ struct respip_client_info;
*/
#define MESH_MAX_ACTIVATION 10000
/**
* Maximum number of mesh state run items. These are different modules
* activated during a mesh run. Any more is likely an infinite loop
* in the module. It is then terminated, and states are deleted.
*/
#define MESH_MAX_RUN_ITER 10000
/**
* Max number of references-to-references-to-references.. search size.
* Any more is treated like 'too large', and the creation of a new
@@ -342,11 +349,14 @@ void mesh_new_client(struct mesh_area* mesh, struct query_info* qinfo,
* @param cb_arg: callback user arg.
* @param rpz_passthru: if true, the rpz passthru was previously found and
* further rpz processing is stopped.
* @param unique_info: if nonnull, unique info is passed back to be used
* for the callback remove call. It does not need to be deallocated.
* @return 0 on error.
*/
int mesh_new_callback(struct mesh_area* mesh, struct query_info* qinfo,
uint16_t qflags, struct edns_data* edns, struct sldns_buffer* buf,
uint16_t qid, mesh_cb_func_type cb, void* cb_arg, int rpz_passthru);
uint16_t qid, mesh_cb_func_type cb, void* cb_arg, int rpz_passthru,
void** unique_info);
/**
* New prefetch message. Create new query state if needed.
@@ -543,6 +553,23 @@ struct mesh_state* mesh_area_find(struct mesh_area* mesh,
struct respip_client_info* cinfo, struct query_info* qinfo,
uint16_t qflags, int prime, int valrec);
/**
* Find a unique mesh state in the mesh area. Pass relevant flags.
*
* @param mesh: the mesh area to look in.
* @param cinfo: if non-NULL client specific info that may affect IP-based
* actions that apply to the query result.
* @param qinfo: what query
* @param qflags: if RD / CD bit is set or not.
* @param prime: if it is a priming query.
* @param valrec: if it is a validation-recursion query.
* @param unique_info: the unique info for the state. NULL can be passed.
* @return: mesh state or NULL if not found.
*/
struct mesh_state* mesh_area_find_unique(struct mesh_area* mesh,
struct respip_client_info* cinfo, struct query_info* qinfo,
uint16_t qflags, int prime, int valrec, void* unique_info);
/**
* Setup attachment super/sub relation between super and sub mesh state.
* The relation must not be present when calling the function.
@@ -562,11 +589,12 @@ int mesh_state_attachment(struct mesh_state* super, struct mesh_state* sub);
* @param qid: ID of reply.
* @param qflags: original query flags.
* @param qinfo: original query info.
* @param result: the allocated reply structure, for rollback.
* @return: 0 on alloc error.
*/
int mesh_state_add_reply(struct mesh_state* s, struct edns_data* edns,
struct comm_reply* rep, uint16_t qid, uint16_t qflags,
const struct query_info* qinfo);
const struct query_info* qinfo, struct mesh_reply** result);
/**
* Create new callback structure and attach it to a mesh state.
@@ -578,11 +606,12 @@ int mesh_state_add_reply(struct mesh_state* s, struct edns_data* edns,
* @param cb_arg: callback user arg.
* @param qid: ID of reply.
* @param qflags: original query flags.
* @param result: the allocated callback structure, for rollback.
* @return: 0 on alloc error.
*/
int mesh_state_add_cb(struct mesh_state* s, struct edns_data* edns,
struct sldns_buffer* buf, mesh_cb_func_type cb, void* cb_arg,
uint16_t qid, uint16_t qflags);
uint16_t qid, uint16_t qflags, struct mesh_cb** result);
/**
* Run the mesh. Run all runnable mesh states. Which can create new
@@ -683,11 +712,14 @@ void mesh_list_remove(struct mesh_state* m, struct mesh_state** fp,
* @param mesh: to update the counters.
* @param m: the mesh state.
* @param cp: the comm_point to remove from the list.
* @param h2_stream: if not NULL, it specifies the h2_stream to match
* for the delete.
* @param doq_stream: if not NULL, it specifies the doq_stream to match
* for the delete.
*/
void mesh_state_remove_reply(struct mesh_area* mesh, struct mesh_state* m,
struct comm_point* cp, struct doq_stream* doq_stream);
struct comm_point* cp, struct http2_stream* h2_stream,
struct doq_stream* doq_stream);
/** Callback for when the serve expired client timer has run out. Tries to
* find an expired answer in the cache and reply that to the client.
@@ -734,9 +766,10 @@ void mesh_respond_serve_expired(struct mesh_state* mstate);
* @param qflags: flags from client query.
* @param cb: callback function.
* @param cb_arg: callback user arg.
* @param unique_info: if not NULL, used to find a unique state for removal.
*/
void mesh_remove_callback(struct mesh_area* mesh, struct query_info* qinfo,
uint16_t qflags, mesh_cb_func_type cb, void* cb_arg);
uint16_t qflags, mesh_cb_func_type cb, void* cb_arg, void* unique_info);
/** Copy the client info to the query region. */
struct respip_client_info* mesh_copy_client_info(struct regional* region,
+63 -8
View File
@@ -1702,6 +1702,12 @@ static int setup_if(struct port_if* pif, const char* addrstr, size_t numfd,
!netblockstrtoaddr(addrstr, UNBOUND_DNS_PORT,
&pif->addr, &pif->addrlen, &pif->pfxlen))
return 0;
#ifdef INT_MAX
if(numfd > (size_t)INT_MAX) {
log_err("num_ports exceeds INT_MAX");
return 0;
}
#endif
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
pif->shpif = shared_ports_find_if(shp, &pif->addr, pif->addrlen,
pif->pfxlen);
@@ -1777,6 +1783,13 @@ outside_network_create(struct comm_base *base, size_t bufsize,
outside_network_delete(outnet);
return NULL;
}
#ifdef INT_MAX
if(num_ports > (size_t)INT_MAX) {
log_err("outgoing num_ports exceeds INT_MAX");
outside_network_delete(outnet);
return NULL;
}
#endif
#ifndef INET6
do_ip6 = 0;
#endif
@@ -3349,9 +3362,9 @@ serviced_udp_callback(struct comm_point* c, void* arg, int error,
if(error == NETEVENT_TIMEOUT) {
if(sq->status == serviced_query_UDP_EDNS && sq->last_rtt < 5000 &&
(serviced_query_udp_size(sq, serviced_query_UDP_EDNS_FRAG) < serviced_query_udp_size(sq, serviced_query_UDP_EDNS))) {
/* fallback to 1480/1280 */
/* fallback to 1472/1232 */
sq->status = serviced_query_UDP_EDNS_FRAG;
log_name_addr(VERB_ALGO, "try edns1xx0", sq->qbuf+10,
log_name_addr(VERB_ALGO, "try edns1xx2", sq->qbuf+10,
&sq->addr, sq->addrlen);
if(!serviced_udp_send(sq, c->buffer)) {
serviced_callbacks(sq, NETEVENT_CLOSED, c, rep);
@@ -3488,7 +3501,8 @@ outnet_serviced_query(struct outside_network* outnet,
char* tls_auth_name, struct sockaddr_storage* addr, socklen_t addrlen,
uint8_t* zone, size_t zonelen, struct module_qstate* qstate,
comm_point_callback_type* callback, void* callback_arg,
sldns_buffer* buff, struct module_env* env, int* was_ratelimited)
sldns_buffer* buff, struct module_env* env, int* was_ratelimited,
int* ratelimit_incremented)
{
struct serviced_query* sq;
struct service_callback* cb;
@@ -3560,6 +3574,7 @@ outnet_serviced_query(struct outside_network* outnet,
"delegation point", zone,
LDNS_RR_TYPE_NS, LDNS_RR_CLASS_IN);
}
*ratelimit_incremented = 1;
}
/* make new serviced query entry */
sq = serviced_create(outnet, buff, dnssec, want_dnssec, nocaps,
@@ -3765,7 +3780,33 @@ setup_comm_ssl(struct comm_point* cp, struct outside_network* outnet,
(void)SSL_set_tlsext_host_name(cp->ssl, host);
}
#endif
#ifdef HAVE_SSL_SET1_HOST
#ifdef HAVE_SSL_SET1_DNSNAME
if((SSL_CTX_get_verify_mode(outnet->sslctx)&SSL_VERIFY_PEER)) {
/* because we set SSL_VERIFY_PEER, in netevent in
* ssl_handshake, it'll check if the certificate
* verification has succeeded */
/* SSL_VERIFY_PEER is set on the sslctx */
/* and the certificates to verify with are loaded into
* it with SSL_load_verify_locations or
* SSL_CTX_set_default_verify_paths */
/* setting the hostname makes openssl verify the
* host name in the x509 certificate in the
* SSL connection*/
struct sockaddr_storage tmpaddr;
socklen_t tmpaddrlen = (socklen_t)sizeof(tmpaddr);
if(ipstrtoaddr(host, UNBOUND_DNS_PORT, &tmpaddr, &tmpaddrlen)) {
if(!SSL_set1_ipaddr(cp->ssl, host)) {
log_err("SSL_set1_ipaddr failed");
return 0;
}
} else {
if(!SSL_set1_dnsname(cp->ssl, host)) {
log_err("SSL_set1_dnsname failed");
return 0;
}
}
}
#elif defined(HAVE_SSL_SET1_HOST)
if((SSL_CTX_get_verify_mode(outnet->sslctx)&SSL_VERIFY_PEER)) {
/* because we set SSL_VERIFY_PEER, in netevent in
* ssl_handshake, it'll check if the certificate
@@ -3894,7 +3935,8 @@ outnet_comm_point_for_http(struct outside_network* outnet,
/* outnet_tcp_connect has closed fd on error for us */
return 0;
}
cp = comm_point_create_http_out(outnet->base, 65552, cb, cb_arg,
cp = comm_point_create_http_out(outnet->base,
sldns_buffer_capacity(outnet->udp_buff), cb, cb_arg,
outnet->udp_buff);
if(!cp) {
log_err("malloc failure");
@@ -4085,13 +4127,15 @@ static int shared_ports_alloc_ifs(struct shared_ports* shp, char** ifs,
size_t done_4 = 0, done_6 = 0;
int i;
for(i=0; i<num_ifs; i++) {
if(str_is_ip6(ifs[i]) && do_ip6) {
if(str_is_ip6(ifs[i]) && do_ip6 &&
(int)done_6 < shp->num_ip6) {
if(!shared_ports_setup_if(&shp->ip6_ifs[done_6],
ifs[i], availports, numavailports))
return 0;
done_6++;
}
if(!str_is_ip6(ifs[i]) && do_ip4) {
if(!str_is_ip6(ifs[i]) && do_ip4 &&
(int)done_4 < shp->num_ip4) {
if(!shared_ports_setup_if(&shp->ip4_ifs[done_4],
ifs[i], availports, numavailports))
return 0;
@@ -4112,16 +4156,21 @@ struct shared_ports* shared_ports_create(char** ifs, int num_ifs, int do_ip4,
return NULL;
}
lock_basic_init(&shp->lock);
lock_protect(&shp->lock, shp, sizeof(*shp));
lock_protect(&shp->lock, &shp->ip4_ifs, sizeof(shp->ip4_ifs));
lock_protect(&shp->lock, &shp->num_ip4, sizeof(shp->num_ip4));
lock_protect(&shp->lock, &shp->ip6_ifs, sizeof(shp->ip6_ifs));
lock_protect(&shp->lock, &shp->num_ip6, sizeof(shp->num_ip6));
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
/* Allocate interfaces */
lock_basic_lock(&shp->lock);
if(!shared_ports_alloc_ifs(shp, ifs, num_ifs, do_ip4, do_ip6,
availports, numavailports)) {
log_err("malloc failed");
shared_ports_delete(shp);
return NULL;
}
lock_basic_unlock(&shp->lock);
#else
(void)ifs; (void)num_ifs; (void)do_ip4; (void)do_ip6;
(void)availports; (void)numavailports;
@@ -4199,6 +4248,9 @@ int shared_ports_fetch_random(struct shared_ports* shp,
int portno = 0, my_port = 0;
if(!shpif)
return 0;
# ifdef THREADS_DISABLED
(void)shp;
# endif
lock_basic_lock(&shp->lock);
if(udp_connect) {
/* if we connect() we cannot reuse fds for a port. */
@@ -4256,6 +4308,9 @@ void shared_ports_return_port(struct shared_ports* shp,
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
if(!shpif)
return;
# ifdef THREADS_DISABLED
(void)shp;
# endif
lock_basic_lock(&shp->lock);
log_assert(shpif->inuse > 0);
shpif->avail_ports[shpif->avail_total - shpif->inuse] = port;
+5 -2
View File
@@ -538,7 +538,7 @@ struct serviced_query {
serviced_query_UDP_EDNS_fallback,
/** probe to test TCP noEDNS0 (EDNS gives FORMERRorNOTIMP) */
serviced_query_TCP_EDNS_fallback,
/** send UDP query with EDNS1480 (or 1280) */
/** send UDP query with EDNS1472 (or 1232) */
serviced_query_UDP_EDNS_FRAG
}
/** variable with current status */
@@ -697,6 +697,8 @@ void pending_delete(struct outside_network* outnet, struct pending* p);
* @param env: the module environment.
* @param was_ratelimited: it will signal back if the query failed to pass the
* ratelimit check.
* @param ratelimit_incremented: set to true if the ratelimit counter
* was increased.
* @return 0 on error, or pointer to serviced query that is used to answer
* this serviced query may be shared with other callbacks as well.
*/
@@ -706,7 +708,8 @@ struct serviced_query* outnet_serviced_query(struct outside_network* outnet,
char* tls_auth_name, struct sockaddr_storage* addr, socklen_t addrlen,
uint8_t* zone, size_t zonelen, struct module_qstate* qstate,
comm_point_callback_type* callback, void* callback_arg,
struct sldns_buffer* buff, struct module_env* env, int* was_ratelimited);
struct sldns_buffer* buff, struct module_env* env, int* was_ratelimited,
int* ratelimit_incremented);
/**
* Remove service query callback.
+33 -17
View File
@@ -721,13 +721,22 @@ rpz_insert_local_zones_trigger(struct local_zones* lz, uint8_t* dname,
char* rrstr = sldns_wire2str_rr(rr, rr_len);
if(rrstr == NULL) {
log_err("malloc error while inserting rpz nsdname trigger");
free(dname);
if(!newzone)
free(dname);
lock_rw_unlock(&lz->lock);
return;
}
lock_rw_wrlock(&z->lock);
local_zone_enter_rr(z, dname, dnamelen, dnamelabs, rrtype,
rrclass, ttl, rdata, rdata_len, rrstr);
if(!local_zone_enter_rr(z, dname, dnamelen, dnamelabs, rrtype,
rrclass, ttl, rdata, rdata_len, rrstr)) {
log_err("rpz: could not enter local-data: %s", rrstr);
if(!newzone)
free(dname);
lock_rw_unlock(&z->lock);
lock_rw_unlock(&lz->lock);
free(rrstr);
return;
}
lock_rw_unlock(&z->lock);
free(rrstr);
}
@@ -805,8 +814,9 @@ rpz_insert_nsdname_trigger(struct rpz* r, uint8_t* dname, size_t dnamelen,
uint8_t* dname_stripped = NULL;
size_t dnamelen_stripped = 0;
rpz_strip_nsdname_suffix(dname, dnamelen, &dname_stripped,
&dnamelen_stripped);
if(!rpz_strip_nsdname_suffix(dname, dnamelen, &dname_stripped,
&dnamelen_stripped))
return;
if(a == RPZ_INVALID_ACTION) {
verbose(VERB_ALGO, "rpz: skipping invalid action");
free(dname_stripped);
@@ -904,8 +914,8 @@ rpz_report_rrset_error(const char* msg, uint8_t* rr, size_t rr_len) {
/* from localzone.c; difference is we don't have a dname */
static struct local_rrset*
rpz_clientip_new_rrset(struct regional* region,
struct clientip_synthesized_rr* raddr, uint16_t rrtype, uint16_t rrclass)
rpz_clientip_new_rrset(struct regional* region, uint16_t rrtype,
uint16_t rrclass)
{
struct packed_rrset_data* pd;
struct local_rrset* rrset = (struct local_rrset*)
@@ -914,8 +924,6 @@ rpz_clientip_new_rrset(struct regional* region,
log_err("out of memory");
return NULL;
}
rrset->next = raddr->data;
raddr->data = rrset;
rrset->rrset = (struct ub_packed_rrset_key*)
regional_alloc_zero(region, sizeof(*rrset->rrset));
if(rrset->rrset == NULL) {
@@ -954,12 +962,18 @@ rpz_clientip_enter_rr(struct regional* region, struct clientip_synthesized_rr* r
return 0;
}
rrset = rpz_clientip_new_rrset(region, raddr, rrtype, rrclass);
if(raddr->data == NULL) {
rrset = rpz_clientip_new_rrset(region, rrtype, rrclass);
if(rrset == NULL) {
return 0;
}
return rrset_insert_rr(region, rrset->rrset->entry.data, rdata, rdata_len, ttl, "");
if(!rrset_insert_rr(region, rrset->rrset->entry.data, rdata, rdata_len, ttl, ""))
return 0;
/* Link in now that the allocations have succeeded. */
rrset->next = raddr->data;
raddr->data = rrset;
return 1;
}
static int
@@ -982,7 +996,6 @@ rpz_clientip_insert_trigger_rr(struct clientip_synthesized_rrset* set, struct so
lock_rw_wrlock(&node->lock);
lock_rw_unlock(&set->lock);
node->action = a;
if(a == RPZ_LOCAL_DATA_ACTION) {
if(!rpz_clientip_enter_rr(set->region, node, rrtype,
rrclass, ttl, rdata, rdata_len)) {
@@ -992,6 +1005,7 @@ rpz_clientip_insert_trigger_rr(struct clientip_synthesized_rrset* set, struct so
}
}
node->action = a;
lock_rw_unlock(&node->lock);
@@ -1977,8 +1991,9 @@ rpz_synthesize_nodata(struct rpz* ATTR_UNUSED(r), struct module_qstate* ms,
0, /* total */
sec_status_insecure,
LDNS_EDE_NONE);
if(msg->rep)
msg->rep->authoritative = 1;
if(!msg->rep)
return NULL;
msg->rep->authoritative = 1;
if(!rpz_add_soa(msg->rep, ms, az))
return NULL;
return msg;
@@ -2008,8 +2023,9 @@ rpz_synthesize_nxdomain(struct rpz* r, struct module_qstate* ms,
0, /* total */
sec_status_insecure,
LDNS_EDE_NONE);
if(msg->rep)
msg->rep->authoritative = 1;
if(!msg->rep)
return NULL;
msg->rep->authoritative = 1;
if(!rpz_add_soa(msg->rep, ms, az))
return NULL;
return msg;
+11 -2
View File
@@ -67,19 +67,28 @@ sldns_rr_dnskey_key_size_raw(const unsigned char* keydata,
case LDNS_RSASHA512:
#endif
if (len > 0) {
size_t nlen, offset;
if (keydata[0] == 0) {
/* big exponent */
if (len > 3) {
memmove(&int16, keydata + 1, 2);
exp = ntohs(int16);
return (len - exp - 3)*8;
offset = 3;
} else {
return 0;
}
} else {
exp = keydata[0];
return (len-exp-1)*8;
offset = 1;
}
if(exp+offset > len)
return 0;
nlen = len - exp - offset;
/* prefixed zeroes mean a smaller value */
while(nlen > 0 &&
keydata[len-nlen] == 0)
nlen--;
return nlen*8;
} else {
return 0;
}
+6 -4
View File
@@ -842,7 +842,8 @@ rrinternal_parse_rdata(sldns_buffer* strbuf, char* token, size_t token_len,
sldns_write_uint16(rr+dname_len+8, (uint16_t)(rr_cur_len-dname_len-10));
*rr_len = rr_cur_len;
/* SVCB/HTTPS handling */
if (rr_type == LDNS_RR_TYPE_SVCB || rr_type == LDNS_RR_TYPE_HTTPS) {
if ((rr_type == LDNS_RR_TYPE_SVCB || rr_type == LDNS_RR_TYPE_HTTPS)
&& !was_unknown_rr_format) {
size_t rdata_len = rr_cur_len - dname_len - 10;
uint8_t *rdata = rr+dname_len + 10;
@@ -1201,7 +1202,7 @@ sldns_str2wire_svcbparam_ipv4hint(const char* val, uint8_t* rd, size_t* rd_len)
{
size_t count;
char ip_str[INET_ADDRSTRLEN+1];
char *next_ip_str;
const char *next_ip_str;
size_t i;
for (i = 0, count = 1; val[i]; i++) {
@@ -1256,7 +1257,7 @@ sldns_str2wire_svcbparam_ipv6hint(const char* val, uint8_t* rd, size_t* rd_len)
{
size_t count;
char ip_str[INET6_ADDRSTRLEN+1];
char *next_ip_str;
const char *next_ip_str;
size_t i;
for (i = 0, count = 1; val[i]; i++) {
@@ -1317,7 +1318,7 @@ static int
sldns_str2wire_svcbparam_mandatory(const char* val, uint8_t* rd, size_t* rd_len)
{
size_t i, count, val_len;
char* next_key;
const char* next_key;
val_len = strlen(val);
@@ -1410,6 +1411,7 @@ sldns_str2wire_svcbparam_ech_value(const char* val, uint8_t* rd, size_t* rd_len)
return LDNS_WIREPARSE_ERR_BUFFER_TOO_SMALL;
sldns_write_uint16(rd, SVCB_KEY_ECH);
sldns_write_uint16(rd + 2, 0);
*rd_len = 4;
return LDNS_WIREPARSE_ERR_OK;
}
+165 -11
View File
@@ -156,7 +156,7 @@ char* wsa_strerror(int err);
#endif
static const char ICANN_UPDATE_CA[] =
/* The ICANN CA fetched at 24 Sep 2010. Valid to 2028 */
/* The ICANN CA fetched at 29 May 2026. Valid to 20 Mar 2045 */
"-----BEGIN CERTIFICATE-----\n"
"MIIDdzCCAl+gAwIBAgIBATANBgkqhkiG9w0BAQsFADBdMQ4wDAYDVQQKEwVJQ0FO\n"
"TjEmMCQGA1UECxMdSUNBTk4gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkxFjAUBgNV\n"
@@ -177,6 +177,40 @@ static const char ICANN_UPDATE_CA[] =
"15nu5JBSewrCkYqYYmaxyOC3WrVGfHZxVI7MpIFcGdvSb2a1uyuua8l0BKgk3ujF\n"
"0/wsHNeP22qNyVO+XVBzrM8fk8BSUFuiT/6tZTYXRtEt5aKQZgXbKU5dUF3jT9qg\n"
"j/Br5BZw3X/zd325TvnswzMC1+ljLzHnQGGk\n"
"-----END CERTIFICATE-----\n"
"\n"
"-----BEGIN CERTIFICATE-----\n"
"MIIFsTCCA5mgAwIBAgIUQFsYkgroBoe69HKQPy8/DQuiLwgwDQYJKoZIhvcNAQEN\n"
"BQAwYDELMAkGA1UEBhMCVVMxDjAMBgNVBAoMBUlDQU5OMSYwJAYDVQQLDB1JQ0FO\n"
"TiBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTEZMBcGA1UEAwwQSUNBTk4gUm9vdCBD\n"
"QSB2MjAeFw0yNTAzMjAyMTA0MjZaFw00NTAzMjAyMTA0MjZaMGAxCzAJBgNVBAYT\n"
"AlVTMQ4wDAYDVQQKDAVJQ0FOTjEmMCQGA1UECwwdSUNBTk4gQ2VydGlmaWNhdGlv\n"
"biBBdXRob3JpdHkxGTAXBgNVBAMMEElDQU5OIFJvb3QgQ0EgdjIwggIiMA0GCSqG\n"
"SIb3DQEBAQUAA4ICDwAwggIKAoICAQCepDjrubjR7en/uZWo7MAnzFIIvUPYEc7b\n"
"+AlefdlEDQ1JEmpfrvt/4CX9lJ9ShIBR6zwrQeDvrj5XZ2kEjbJ8Nnc6sM/ojdyr\n"
"5jSLqcDPH9fJg7jCW02KF8CtqWsnqcW6jjTIZcCWkg9lEixdF8QAjIEgJtZte+Yh\n"
"XeyN0KD2EaO8U5Id0bLvMyphuO1OCGKzDtetcX8K7SvoshdJx3lPIlYzqXl0nVAY\n"
"iCeNdeDzTNjEOHYJOP6dYoZI8nKRJltMkZcCCjBE2vQuSMY2w4pOlWk1skHjMWXj\n"
"QsZzngXuNG56zialL0TPEDVWjWRjzOnruHUAs4KUY8Zs+Nt8JdSlXMi825PKoKpp\n"
"ESs7/ZG1mPjVOYp7Z7ntrRjJFgnUBjWzVPOx4yHiJj1ur+OpqP18oP5YfqY+tKmz\n"
"7vlfRGGOEd08a0XgZISDNKpMAovn5pRUHTWPCCjc28tns9ODPvr1cQi+QSwTv+v8\n"
"wnA5etGrsead88Rv/ieaq5ikMJTRDfW4d9SY2uPcMGvfU6VdQLRhQkzEVTQNAJ1R\n"
"i2lOoJbbjwnK+OU9OhST/OqdjJDJAhTAstdUnrr8WBU80xM75MIaaTjSBCvZ1wro\n"
"pAi2hYb0tedTH6WarSW3MH9HcEoGGzs2GD3hDB0a2eCp+TdAs8Up944SjY7UV4Jx\n"
"sOC7TxbmkQIDAQABo2MwYTAdBgNVHQ4EFgQU+1EuMRuOZ/ecsfYzNQ+yGZsxZrMw\n"
"HwYDVR0jBBgwFoAU+1EuMRuOZ/ecsfYzNQ+yGZsxZrMwDwYDVR0TAQH/BAUwAwEB\n"
"/zAOBgNVHQ8BAf8EBAMCAf4wDQYJKoZIhvcNAQENBQADggIBACz38SkKR1WsEZnX\n"
"x1BKaS5/oQPw+7quDQCKGoD2Vz7CR7yQh4zQn/Hh0173vKvRWcwN2io0iLJ1ysv5\n"
"jXBLeWZh3djiQlXP3iWp4s01SiUwmFssxi3SD1IT2jNosk1xcVWthle9zth7Y8Mp\n"
"iUJYnHobP7tX7H2g+I8Rqw2sEX/yPSYMYcdH5a1xRMPOLHTyOaCgevRBBBtXkiAJ\n"
"Ob9QKZTaFaXntPXBKNSGkVb2d+2qKyJMrwd0KNI+SVSoIgNDAxkNOdi9x6X6ETW2\n"
"4aYFsytohFVkNUXx2eFYRim4yjnD8PHIvDQSofLfSAC5TOERtwUFd+Mw3/di+HCm\n"
"50OJPyoxZLjWQCCfNUZzgZZOe+zT6lgBiV3KB0UuuAdq7jGUeH/328HJDi30BvNj\n"
"+TNb9Hmpm+ZDguM+f8p7GxapX8AVNu/xErtl4msYiVJrr1qqV+qLLEMwIz0raujG\n"
"FFDd6N43wgduffbU20pThry0Y7rku5+RZjUZe/T7ZL+NUKiqXAPufrkqVkjX/8T+\n"
"wyNZz8KkiQwkJthojpppa79FDxn/A2M8tt+FQqIONAUPR2m5nurVgftQH0z5ZtDB\n"
"YykUlkUiPOJNXoDOIkbpA7lW2wezeY4te+EiSeUZSE541N5QBwaItaonIZsIgn6C\n"
"pMnwChV9468oRE20bdqq9+Go7g4E\n"
"-----END CERTIFICATE-----\n";
static const char DS_TRUST_ANCHOR[] =
@@ -1674,18 +1708,116 @@ static unsigned long
get_usage_of_ex(X509* cert)
{
unsigned long val = 0;
#ifdef HAVE_X509_GET_KEY_USAGE
val = X509_get_key_usage(cert);
if (val == UINT32_MAX)
return 0;
#else
ASN1_BIT_STRING* s;
if((s=X509_get_ext_d2i(cert, NID_key_usage, NULL, NULL))) {
if(s->length > 0) {
val = s->data[0];
if(s->length > 1)
val |= s->data[1] << 8;
# ifdef HAVE_ASN1_STRING_GET0_DATA
const unsigned char *data = ASN1_STRING_get0_data(s);
# else
const unsigned char *data = ASN1_STRING_data(s);
# endif
int len = ASN1_STRING_length(s);
if(len > 0) {
val = data[0];
if(len > 1)
val |= data[1] << 8;
}
ASN1_BIT_STRING_free(s);
}
#endif
return val;
}
#if !defined(HAVE_X509_NAME_GET_TEXT_BY_NID) || defined(DEPRECATED_X509_NAME_GET_TEXT_BY_NID)
/** print verbose output about name extension data. */
static void
print_name_ext(
#if OPENSSL_VERSION_NUMBER >= 0x40000000
const
#endif
X509_NAME* nm, int nid, const char* str)
{
int lastpos = -1;
for(;;) {
#if OPENSSL_VERSION_NUMBER >= 0x40000000
const
#endif
X509_NAME_ENTRY* ne;
#if OPENSSL_VERSION_NUMBER >= 0x40000000
const
#endif
ASN1_STRING *asn;
const unsigned char *data;
char buf[1024];
lastpos = X509_NAME_get_index_by_NID(nm, nid, lastpos);
if(lastpos == -1 || lastpos == -2)
break;
ne = X509_NAME_get_entry(nm, lastpos);
if(!ne) continue;
asn = X509_NAME_ENTRY_get_data(ne);
if(!asn) continue;
# ifdef HAVE_ASN1_STRING_GET0_DATA
data = ASN1_STRING_get0_data(asn);
# else
data = ASN1_STRING_data(asn);
# endif
if(!data) continue;
if(ASN1_STRING_length(asn) > (int)sizeof(buf)-1) continue;
memcpy(buf, data, ASN1_STRING_length(asn));
buf[ASN1_STRING_length(asn)]=0;
printf("%s: %s\n", str, buf);
}
}
#endif /* X509_NAME_GET_TEXT_BY_NID */
#if !defined(HAVE_X509_NAME_GET_TEXT_BY_NID) || defined(DEPRECATED_X509_NAME_GET_TEXT_BY_NID)
/** see if the valid emailaddr is present. */
static int
has_valid_emailaddr(
#if OPENSSL_VERSION_NUMBER >= 0x40000000
const
#endif
X509_NAME* nm, const char* p7signer)
{
int lastpos = -1;
for(;;) {
#if OPENSSL_VERSION_NUMBER >= 0x40000000
const
#endif
X509_NAME_ENTRY* ne;
#if OPENSSL_VERSION_NUMBER >= 0x40000000
const
#endif
ASN1_STRING *asn;
const unsigned char *data;
lastpos = X509_NAME_get_index_by_NID(nm,
NID_pkcs9_emailAddress, lastpos);
if(lastpos == -1 || lastpos == -2)
break;
ne = X509_NAME_get_entry(nm, lastpos);
if(!ne) continue;
asn = X509_NAME_ENTRY_get_data(ne);
if(!asn) continue;
# ifdef HAVE_ASN1_STRING_GET0_DATA
data = ASN1_STRING_get0_data(asn);
# else
data = ASN1_STRING_data(asn);
# endif
if(!data) continue;
if(ASN1_STRING_length(asn) == (int)strlen(p7signer) &&
strncmp((char*)data, p7signer, strlen(p7signer)) == 0)
return 1; /* match */
}
return 0;
}
#endif /* X509_NAME_GET_TEXT_BY_NID */
/** get valid signers from the list of signers in the signature */
static STACK_OF(X509)*
get_valid_signers(PKCS7* p7, const char* p7signer)
@@ -1705,6 +1837,9 @@ get_valid_signers(PKCS7* p7, const char* p7signer)
return NULL;
}
for(i=0; i<sk_X509_num(signers); i++) {
#if OPENSSL_VERSION_NUMBER >= 0x40000000
const
#endif
X509_NAME* nm = X509_get_subject_name(
sk_X509_value(signers, i));
char buf[1024];
@@ -1717,17 +1852,29 @@ get_valid_signers(PKCS7* p7, const char* p7signer)
(int)sizeof(buf));
printf("signer %d: Subject: %s\n", i,
nmline?nmline:"no subject");
#if !defined(HAVE_X509_NAME_GET_TEXT_BY_NID) || defined(DEPRECATED_X509_NAME_GET_TEXT_BY_NID)
if(verb >= 3) {
print_name_ext(nm, NID_commonName,
"commonName");
print_name_ext(nm, NID_pkcs9_emailAddress,
"emailAddress");
}
#else
if(verb >= 3 && X509_NAME_get_text_by_NID(nm,
NID_commonName, buf, (int)sizeof(buf)))
NID_commonName, buf, (int)sizeof(buf)) > 0)
printf("commonName: %s\n", buf);
if(verb >= 3 && X509_NAME_get_text_by_NID(nm,
NID_pkcs9_emailAddress, buf, (int)sizeof(buf)))
NID_pkcs9_emailAddress, buf, (int)sizeof(buf)) > 0)
printf("emailAddress: %s\n", buf);
#endif
}
if(verb) {
int ku_loc = X509_get_ext_by_NID(
sk_X509_value(signers, i), NID_key_usage, -1);
if(verb >= 3 && ku_loc >= 0) {
#if OPENSSL_VERSION_NUMBER >= 0x40000000
const
#endif
X509_EXTENSION *ex = X509_get_ext(
sk_X509_value(signers, i), ku_loc);
if(ex) {
@@ -1741,16 +1888,23 @@ get_valid_signers(PKCS7* p7, const char* p7signer)
/* there is no name to check, return all records */
if(verb) printf("did not check commonName of signer\n");
} else {
if(!X509_NAME_get_text_by_NID(nm,
#if !defined(HAVE_X509_NAME_GET_TEXT_BY_NID) || defined(DEPRECATED_X509_NAME_GET_TEXT_BY_NID)
if(!has_valid_emailaddr(nm, p7signer)) {
if(verb) printf("removed cert with wrong emailaddress\n");
continue; /* wrong name, skip it */
}
#else
if(X509_NAME_get_text_by_NID(nm,
NID_pkcs9_emailAddress,
buf, (int)sizeof(buf))) {
if(verb) printf("removed cert with no name\n");
buf, (int)sizeof(buf)) <= 0) {
if(verb) printf("removed cert with no emailaddress\n");
continue; /* no name, no use */
}
if(strcmp(buf, p7signer) != 0) {
if(verb) printf("removed cert with wrong name\n");
if(verb) printf("removed cert with wrong emailaddress\n");
continue; /* wrong name, skip it */
}
#endif
}
/* check that the key usage allows digital signatures
+120
View File
@@ -73,6 +73,9 @@
#ifdef HAVE_GLOB_H
#include <glob.h>
#endif
#ifdef HAVE_FNMATCH_H
#include <fnmatch.h>
#endif
#ifdef WITH_PYTHONMODULE
#include "pythonmod/pythonmod.h"
#endif
@@ -728,6 +731,122 @@ check_modules_exist(const char* module_conf)
}
}
#ifdef USE_IPSECMOD
/** Compare filename with string, true if it matches the name. */
static int
file_string_matches(char* str, char* fname, struct config_file* cfg)
{
char* f;
if(!str || str[0] == 0)
return 0;
/* compare name after chroot and working dir are applied */
f = fname_after_chroot(str, cfg, 1);
if(!f) fatal_exit("out of memory");
if(strcmp(fname, f) == 0) {
free(f);
return 1;
}
free(f);
return 0;
}
#endif /* USE_IPSECMOD */
/** Compare filename with list of files, true if list contains the name. */
static int
file_list_contains(struct config_strlist* list, char* fname,
struct config_file* cfg)
{
struct config_strlist* s;
char* f;
for(s = list; s; s = s->next) {
if(!s->str || s->str[0] == 0)
continue; /* skip if no file name */
/* compare names after chroot and working dir are applied */
f = fname_after_chroot(s->str, cfg, 1);
if(!f) fatal_exit("out of memory");
if(strcmp(fname, f) == 0) {
free(f);
return 1;
}
free(f);
}
return 0;
}
/** Compare filename with list of files, true if list contains the name,
* with glob compare. */
static int
file_list_contains_wild(struct config_strlist* list, char* fname,
struct config_file* cfg)
{
struct config_strlist* s;
char* f;
for(s = list; s; s = s->next) {
if(!s->str || s->str[0] == 0)
continue; /* skip if no file name */
/* compare names after chroot and working dir are applied */
f = fname_after_chroot(s->str, cfg, 1);
if(!f) fatal_exit("out of memory");
if(strcmp(fname, f) == 0) {
free(f);
return 1;
}
#ifdef HAVE_FNMATCH
if(fnmatch(f, fname, 0) == 0) {
log_err("trusted-keys-file: \"%s\" matches zonefile '%s'",
s->str, fname);
free(f);
return 1;
}
#endif
free(f);
}
return 0;
}
/** Check if the auth-zone/rpz zonefile: conflicts with other files,
* so it would overwrite that file. Refuse it aliasing any read-side bootstrap
* file. */
static void
check_file_clobber(struct config_file* cfg)
{
struct config_auth* p;
char* zfile, *sourceopt = NULL;
for(p = cfg->auths; p; p = p->next) {
if(!p->name || p->name[0] == 0)
continue; /* skip if no name */
if(!p->zonefile || p->zonefile[0]==0)
continue; /* no zone file */
zfile = fname_after_chroot(p->zonefile, cfg, 1);
if(!zfile) fatal_exit("out of memory");
if(file_list_contains(cfg->auto_trust_anchor_file_list, zfile,
cfg))
sourceopt = "auto-trust-anchor-file";
else if(file_list_contains(cfg->trust_anchor_file_list, zfile,
cfg))
sourceopt = "trust-anchor-file";
else if(file_list_contains_wild(cfg->trusted_keys_file_list,
zfile, cfg))
sourceopt = "trusted-keys-file";
else if(file_list_contains(cfg->root_hints, zfile, cfg))
sourceopt = "root-hints";
else if(file_list_contains(cfg->tls_session_ticket_keys.first,
zfile, cfg))
sourceopt = "tls-session-ticket-keys";
#ifdef USE_IPSECMOD
if(cfg->ipsecmod_enabled &&
file_string_matches(cfg->ipsecmod_hook, zfile, cfg))
sourceopt = "ipsecmod-hook";
#endif
if(sourceopt)
fatal_exit("auth-zone '%s': zonefile \"%s\" "
"is the same path as a %s option. "
"The auth-zone transfer would overwrite it.",
p->name, p->zonefile, sourceopt);
free(zfile);
}
}
/** check configuration for errors */
static void
morechecks(struct config_file* cfg)
@@ -822,6 +941,7 @@ morechecks(struct config_file* cfg)
cfg->chrootdir, cfg);
}
#endif
check_file_clobber(cfg);
/* remove chroot setting so that modules are not stripping pathnames */
free(cfg->chrootdir);
cfg->chrootdir = NULL;
+3 -2
View File
@@ -43,6 +43,7 @@
#include "config.h"
#include "libunbound/context.h"
#include "libunbound/worker.h"
#include "libunbound/remote.h"
#include "util/fptr_wlist.h"
#include "util/log.h"
#include "services/mesh.h"
@@ -102,7 +103,7 @@ struct outbound_entry* worker_send_query(
socklen_t ATTR_UNUSED(addrlen), uint8_t* ATTR_UNUSED(zone),
size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream), int ATTR_UNUSED(ssl_upstream),
char* ATTR_UNUSED(tls_auth_name), struct module_qstate* ATTR_UNUSED(q),
int* ATTR_UNUSED(was_ratelimited))
int* ATTR_UNUSED(was_ratelimited), int* ATTR_UNUSED(ratelimit_incremented))
{
log_assert(0);
return 0;
@@ -142,7 +143,7 @@ struct outbound_entry* libworker_send_query(
socklen_t ATTR_UNUSED(addrlen), uint8_t* ATTR_UNUSED(zone),
size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream), int ATTR_UNUSED(ssl_upstream),
char* ATTR_UNUSED(tls_auth_name), struct module_qstate* ATTR_UNUSED(q),
int* ATTR_UNUSED(was_ratelimited))
int* ATTR_UNUSED(was_ratelimited), int* ATTR_UNUSED(ratelimit_incremented))
{
log_assert(0);
return 0;
+12 -3
View File
@@ -146,7 +146,9 @@ submit_query(struct http2_session* h2_session, struct sldns_buffer* buf)
{
int32_t stream_id;
struct http2_stream* h2_stream;
nghttp2_nv headers[5];
nghttp2_nv headers[6];
size_t num_headers = 5;
char clen[16];
char* qb64;
size_t qb64_size;
size_t qb64_expected_size;
@@ -194,9 +196,16 @@ submit_query(struct http2_session* h2_session, struct sldns_buffer* buf)
headers[3].value = (uint8_t*)h2_session->authority;
headers[4].name = (uint8_t*)"content-type";
headers[4].value = (uint8_t*)h2_session->content_type;
if(h2_session->post) {
snprintf(clen, sizeof(clen), "%u",
(unsigned)sldns_buffer_remaining(buf));
headers[5].name = (uint8_t*)"content-length";
headers[5].value = (uint8_t*)clen;
num_headers = 6;
}
printf("Request headers\n");
for(i=0; i<sizeof(headers)/sizeof(headers[0]); i++) {
for(i=0; i<num_headers; i++) {
headers[i].namelen = strlen((char*)headers[i].name);
headers[i].valuelen = strlen((char*)headers[i].value);
headers[i].flags = NGHTTP2_NV_FLAG_NONE;
@@ -204,7 +213,7 @@ submit_query(struct http2_session* h2_session, struct sldns_buffer* buf)
}
stream_id = nghttp2_submit_request(h2_session->session, NULL, headers,
sizeof(headers)/sizeof(headers[0]),
num_headers,
(h2_session->post) ? &data_prd : NULL, h2_stream);
if(stream_id < 0) {
printf("Failed to submit nghttp2 request");
+10 -5
View File
@@ -1137,8 +1137,11 @@ static struct ngtcp2_conn* conn_client_setup(struct doq_client_data* data)
client_chosen_version, &cbs, &settings, &params,
NULL, /* ngtcp2_mem allocator, use default */
data /* callback argument */);
if(!conn) fatal_exit("could not ngtcp2_conn_client_new: %s",
ngtcp2_strerror(rv));
if(rv!=0) {
conn = NULL;
fatal_exit("could not ngtcp2_conn_client_new: %s",
ngtcp2_strerror(rv));
}
data->cc_algo = settings.cc_algo;
return conn;
}
@@ -2098,7 +2101,7 @@ early_data_setup_session(struct doq_client_data* data)
SSL_SESSION_free(session);
return 0;
}
#ifdef USE_NGTCP2_CRYPTO_OSSL
#ifdef HAVE_SSL_SET_QUIC_TLS_EARLY_DATA_ENABLED
SSL_set_quic_tls_early_data_enabled(data->ssl, 1);
#else
SSL_set_quic_early_data_enabled(data->ssl, 1);
@@ -2595,7 +2598,8 @@ struct outbound_entry* worker_send_query(
socklen_t ATTR_UNUSED(addrlen), uint8_t* ATTR_UNUSED(zone),
size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream),
int ATTR_UNUSED(ssl_upstream), char* ATTR_UNUSED(tls_auth_name),
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited))
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited),
int* ATTR_UNUSED(ratelimit_incremented))
{
log_assert(0);
return 0;
@@ -2629,7 +2633,8 @@ struct outbound_entry* libworker_send_query(
socklen_t ATTR_UNUSED(addrlen), uint8_t* ATTR_UNUSED(zone),
size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream),
int ATTR_UNUSED(ssl_upstream), char* ATTR_UNUSED(tls_auth_name),
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited))
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited),
int* ATTR_UNUSED(ratelimit_incremented))
{
log_assert(0);
return 0;
+2 -1
View File
@@ -1276,7 +1276,8 @@ struct serviced_query* outnet_serviced_query(struct outside_network* outnet,
socklen_t addrlen, uint8_t* zone, size_t zonelen,
struct module_qstate* qstate, comm_point_callback_type* callback,
void* callback_arg, sldns_buffer* ATTR_UNUSED(buff),
struct module_env* env, int* ATTR_UNUSED(was_ratelimited))
struct module_env* env, int* ATTR_UNUSED(was_ratelimited),
int* ATTR_UNUSED(ratelimit_incremented))
{
struct replay_runtime* runtime = (struct replay_runtime*)outnet->base;
struct fake_pending* pend = (struct fake_pending*)calloc(1,
+33
View File
@@ -1027,6 +1027,38 @@ authzone_query_test(void)
check_queries("example.com", zone_example_com, example_com_queries);
}
/** Test chunkline_count_parens output */
static void
authzone_chunkline_count_parens_test(void)
{
sldns_buffer* buf;
if(vbmp) printf("Testing chunkline_count_parens\n");
buf = sldns_buffer_new(1024);
if(!buf) fatal_exit("out of memory");
/* Check that escaped characters are handled, '\x', and in quotes. */
sldns_buffer_printf(buf, "TXT \"x\" \\(");
unit_assert(chunkline_count_parens(buf, 0) == 0);
sldns_buffer_clear(buf);
sldns_buffer_printf(buf, "TXT ';x' (");
unit_assert(chunkline_count_parens(buf, 0) == 0);
sldns_buffer_clear(buf);
sldns_buffer_printf(buf, "TXT \"a;b\" (");
unit_assert(chunkline_count_parens(buf, 0) == 1);
sldns_buffer_clear(buf);
sldns_buffer_printf(buf, "TXT \\) )");
unit_assert(chunkline_count_parens(buf, 0) == -1);
sldns_buffer_clear(buf);
sldns_buffer_printf(buf, "TXT \"a\\\\\" \"(\" ");
unit_assert(chunkline_count_parens(buf, 0) == 0);
sldns_buffer_free(buf);
}
/** test authzone code */
void
authzone_test(void)
@@ -1036,4 +1068,5 @@ authzone_test(void)
authzone_compare_serial();
authzone_read_test();
authzone_query_test();
authzone_chunkline_count_parens_test();
}
+1
View File
@@ -141,6 +141,7 @@ static addrlen_t randomkey(addrkey_t **k, int maxlen)
int bits = rand() % maxlen;
int bytes = bits/8 + (bits%8>0); /*ceil*/
*k = (addrkey_t *) malloc(bytes * sizeof(addrkey_t));
if(!*k) fatal_exit("out of memory");
for (byte = 0; byte < bytes; byte++) {
(*k)[byte] = (addrkey_t)(rand() & 0xFF);
}
+14
View File
@@ -279,10 +279,24 @@ b64_test(void)
unit_assert(result == -1);
}
/** test SVCB ech svcparam */
static void
svcb_ech_test(void)
{
uint8_t rr[LDNS_RR_BUF_SIZE];
size_t rr_len = sizeof(rr), dname_len = 0;
int e = sldns_str2wire_rr_buf("x. 300 IN HTTPS 1 . ech=0",
rr, &rr_len, &dname_len, 300, NULL, 0, NULL, 0);
unit_assert(e == LDNS_WIREPARSE_ERR_OK);
unit_assert(rr_len == dname_len + 10 /* type,class,ttl,rdatalen */ + 7 /* rdata */);
unit_assert(sldns_read_uint16(rr + dname_len + 8 /* rdlen */) == 7);
}
void
ldns_test(void)
{
unit_show_feature("sldns");
rr_tests();
b64_test();
svcb_ech_test();
}
+87
View File
@@ -1337,6 +1337,89 @@ static void mesh_test(void)
free(c1);
}
#include "util/data/packed_rrset.h"
#include "sldns/sbuffer.h"
/** packed_rrset unit tests */
static void packed_rrset_test(void)
{
/* packed_rr_to_string assembles the dname, type, class, ttl and
* rdata of one rr into a buffer of 65535 bytes. Check that it
* refuses an rr that does not fit in there, also when the caller
* passes a dest_len that is larger than that, like the callers in
* daemon/cachedump.c and daemon/remote.c do. Without the check it
* writes past the end of the assembly buffer. */
uint8_t smalldname[] = "\003www\007example\003com";
uint8_t smallrdata[] = {0, 4, 1, 2, 3, 4};
uint8_t maxdname[LDNS_MAX_DOMAINLEN];
struct ub_packed_rrset_key rrk;
struct packed_rrset_data d;
uint8_t* rr_data[1];
size_t rr_len[1];
time_t rr_ttl[1];
size_t dest_len = 65535*4+2048; /* the size daemon/cachedump.c uses */
char* dest = (char*)malloc(dest_len);
int i;
unit_show_func("util/data/packed_rrset.c", "packed_rr_to_string");
if(!dest) fatal_exit("out of memory");
memset(&rrk, 0, sizeof(rrk));
memset(&d, 0, sizeof(d));
rrk.entry.data = &d;
rrk.rk.rrset_class = htons(LDNS_RR_CLASS_IN);
d.count = 1;
d.rr_len = rr_len;
d.rr_ttl = rr_ttl;
d.rr_data = rr_data;
rr_ttl[0] = 3600;
/* an ordinary rr is printed, also with the large dest_len */
rrk.rk.dname = smalldname;
rrk.rk.dname_len = sizeof(smalldname);
rrk.rk.type = htons(LDNS_RR_TYPE_A);
rr_data[0] = smallrdata;
rr_len[0] = sizeof(smallrdata);
unit_assert(packed_rr_to_string(&rrk, 0, 0, dest, dest_len) == 1);
unit_assert(strstr(dest, "1.2.3.4") != NULL);
/* a dname of the maximum length, 127 labels of one character */
for(i=0; i<127; i++) {
maxdname[i*2] = 1;
maxdname[i*2+1] = (uint8_t)'a';
}
maxdname[254] = 0;
rrk.rk.dname = maxdname;
rrk.rk.dname_len = sizeof(maxdname);
rrk.rk.type = htons(LDNS_RR_TYPE_TXT);
/* 255+2+2+4+65272 is exactly 65535, that still fits */
rr_len[0] = 65535 - 255 - 8;
rr_data[0] = (uint8_t*)calloc(1, rr_len[0]);
if(!rr_data[0]) fatal_exit("out of memory");
sldns_write_uint16(rr_data[0], (uint16_t)(rr_len[0]-2));
unit_assert(packed_rr_to_string(&rrk, 0, 0, dest, dest_len) == 1);
free(rr_data[0]);
/* one more byte of rdata does not fit and must be refused */
rr_len[0] = 65535 - 255 - 8 + 1;
rr_data[0] = (uint8_t*)calloc(1, rr_len[0]);
if(!rr_data[0]) fatal_exit("out of memory");
sldns_write_uint16(rr_data[0], (uint16_t)(rr_len[0]-2));
unit_assert(packed_rr_to_string(&rrk, 0, 0, dest, dest_len) == 0);
unit_assert(dest[0] == 0);
free(rr_data[0]);
/* the largest rdata an rr can hold, well over the buffer */
rr_len[0] = 2 + 65535;
rr_data[0] = (uint8_t*)calloc(1, rr_len[0]);
if(!rr_data[0]) fatal_exit("out of memory");
sldns_write_uint16(rr_data[0], 65535);
unit_assert(packed_rr_to_string(&rrk, 0, 0, dest, dest_len) == 0);
unit_assert(dest[0] == 0);
free(rr_data[0]);
free(dest);
}
void unit_show_func(const char* file, const char* func)
{
printf("test %s:%s\n", file, func);
@@ -1409,6 +1492,7 @@ main(int argc, char* argv[])
zonemd_test();
tcpreuse_test();
msgparse_test();
packed_rrset_test();
edns_ede_answer_encode_test();
localzone_test();
mesh_test();
@@ -1445,6 +1529,9 @@ main(int argc, char* argv[])
# ifdef HAVE_RAND_CLEANUP
RAND_cleanup();
# endif
#ifdef HAVE_OPENSSL_CLEANUP
OPENSSL_cleanup();
#endif
#elif defined(HAVE_NSS)
if(NSS_Shutdown() != SECSuccess)
fatal_exit("could not shutdown NSS");
@@ -2,6 +2,7 @@
server:
do-not-query-localhost: no
fake-sha1: yes
verbosity: 8
forward-zone:
name: "."
forward-addr: "127.0.0.1@@TOPORT@"
+3 -1
View File
@@ -35,11 +35,13 @@ function check_insecure() {
# test with good start key, and must do 5011 (no URL possible)
echo "*** TEST 1 ***"
echo $DS > root.key
$PRE/unbound-anchor -x "notexist.xml" -s "notexist.p7s" $OPTS
cat root.key
$PRE/unbound-anchor -x "notexist.xml" -s "notexist.p7s" $OPTS -vvvv
if test $? != 0; then
echo "Exitcode not OK"
exit 1
fi
cat root.key
check_works
# save for test 5
cp root.key root.key.probed
Binary file not shown.
Binary file not shown.
+201
View File
@@ -0,0 +1,201 @@
#!/bin/sh
# run in temp dir.
# Then for petal, move into basedir.
# For test_cert.key and test_cert.pem, rename the output files to that.
# And run signit.sh for both signature files, by commenting infile and outfile.
# for test_cert.pem it has emailAddress and keyUsage, but petal.pem does not
# need that.
# settings:
# directory for files
DESTDIR=.
# issuer and subject name for certificates
SERVERNAME=petal
CLIENTNAME=petal
# validity period for certificates
DAYS=7200
# size of keys in bits
BITS=3072
# hash algorithm
HASH=sha256
# base name for unbound server keys
SVR_BASE=petal
# base name for unbound-control keys
CTL_BASE=petal
# flag to recreate generated certificates
RECREATE=0
# we want -rw-r----- access (say you run this as root: grp=yes (server), all=no).
umask 0027
# end of options
set -eu
cleanup() {
echo "removing artifacts"
rm -rf \
server.cnf \
client.cnf \
"${SVR_BASE}_trust.pem" \
"${CTL_BASE}_trust.pem" \
"${SVR_BASE}_trust.srl"
}
fatal() {
printf "fatal error: $*\n" >/dev/stderr
exit 1
}
usage() {
cat <<EOF
usage: $0 OPTIONS
OPTIONS
-d <dir> used directory to store keys and certificates (default: $DESTDIR)
-h show help notice
-r recreate certificates
EOF
}
OPTIND=1
while getopts 'd:hr' arg; do
case "$arg" in
d) DESTDIR="$OPTARG" ;;
h) usage; exit 1 ;;
r) RECREATE=1 ;;
?) fatal "'$arg' unknown option" ;;
esac
done
shift $((OPTIND - 1))
if ! openssl version </dev/null >/dev/null 2>&1; then
echo "$0 requires openssl to be installed for keys/certificates generation." >&2
exit 1
fi
echo "setup in directory $DESTDIR"
cd "$DESTDIR"
trap cleanup INT
# ===
# Generate server certificate
# ===
# generate private key; do no recreate it if they already exist.
if [ ! -f "$SVR_BASE.key" ]; then
openssl genrsa -out "$SVR_BASE.key" "$BITS"
fi
cat >server.cnf <<EOF
[req]
default_bits=$BITS
default_md=$HASH
prompt=no
distinguished_name=req_distinguished_name
x509_extensions=v3_ca
[req_distinguished_name]
commonName=$SERVERNAME
emailAddress=$SERVERNAME
[v3_ca]
subjectKeyIdentifier=hash
authorityKeyIdentifier=keyid:always,issuer:always
basicConstraints=critical,CA:TRUE,pathlen:0
subjectAltName=DNS:$SERVERNAME
keyUsage = digitalSignature, keyCertSign
EOF
[ -f server.cnf ] || fatal "cannot create openssl configuration"
if [ ! -f "$SVR_BASE.pem" -o $RECREATE -eq 1 ]; then
openssl req \
-new -x509 \
-key "$SVR_BASE.key" \
-config server.cnf \
-days "$DAYS" \
-out "$SVR_BASE.pem"
[ ! -f "SVR_BASE.pem" ] || fatal "cannot create server certificate"
fi
# ===
# Generate client certificate
# ===
# generate private key; do no recreate it if they already exist.
if [ ! -f "$CTL_BASE.key" ]; then
openssl genrsa -out "$CTL_BASE.key" "$BITS"
fi
cat >client.cnf <<EOF
[req]
default_bits=$BITS
default_md=$HASH
prompt=no
distinguished_name=req_distinguished_name
req_extensions=v3_req
[req_distinguished_name]
commonName=$CLIENTNAME
[v3_req]
basicConstraints=critical,CA:FALSE
subjectAltName=DNS:$CLIENTNAME
EOF
[ -f client.cnf ] || fatal "cannot create openssl configuration"
if [ ! -f "$CTL_BASE.pem" -o $RECREATE -eq 1 ]; then
openssl x509 \
-addtrust serverAuth \
-in "$SVR_BASE.pem" \
-out "${SVR_BASE}_trust.pem"
openssl req \
-new \
-config client.cnf \
-key "$CTL_BASE.key" \
| openssl x509 \
-req \
-days "$DAYS" \
-CA "${SVR_BASE}_trust.pem" \
-CAkey "$SVR_BASE.key" \
-CAcreateserial \
-$HASH \
-extfile client.cnf \
-extensions v3_req \
-out "$CTL_BASE.pem"
[ ! -f "CTL_BASE.pem" ] || fatal "cannot create signed client certificate"
fi
# remove unused permissions
chmod o-rw \
"$SVR_BASE.pem" \
"$SVR_BASE.key"
chmod g+r,o-rw \
"$CTL_BASE.pem" \
"$CTL_BASE.key"
cleanup
echo "Setup success. Certificates created. Enable in unbound.conf file to use"
# create trusted usage pem
# openssl x509 -in $CTL_BASE.pem -addtrust clientAuth -out $CTL_BASE"_trust.pem"
# see details with openssl x509 -noout -text < $SVR_BASE.pem
# echo "create $CTL_BASE""_browser.pfx (web client certificate)"
# echo "create webbrowser PKCS#12 .PFX certificate file. In Firefox import in:"
# echo "preferences - advanced - encryption - view certificates - your certs"
# echo "empty password is used, simply click OK on the password dialog box."
# openssl pkcs12 -export -in $CTL_BASE"_trust.pem" -inkey $CTL_BASE.key -name "unbound remote control client cert" -out $CTL_BASE"_browser.pfx" -password "pass:" || error "could not create browser certificate"
+40 -21
View File
@@ -1,21 +1,40 @@
-----BEGIN RSA PRIVATE KEY-----
MIIDfQIBAAKBwQC1xQ/Kca6zszZbcCtdOTIH2Uy2gOy/DfabMUU7TmNPm0dVE0NJ
RuN+Rm304SonpwghfP2/ULZNnuDgpG03/32yI7k/VzG6iA4hiF7tT/KAAWC/+2l1
QCsawCV2bSrFK0VhcZr7ALqXd8vkDaQ867K029ypjOQtAJ85qdO3mERy7TGtdUcu
O6hLeVet419YeQ2F8cfNxn63d7bOzNGLPW5xwaCd3UcgD+Ib0k4xfFvbinvPQUeU
J/i4YDWexFYSL+ECAwEAAQKBwCLXXQl+9O+5AEhSnd1Go1Jh0pSA7eBJOuXQcebG
Rb7ykp+6C4G2NtDziwwPRNdI6wQQQ0sym18RfyVQHydGr78/nbiIbB3HCn5e92Mh
mefzW6ow9Kvm2txLzGKA1lvoyRbNm81jnG/eygi3u7Nqd5PNv+4dHj2RkTlmxOeh
qnDMVP5md8uZPv6lYNnrnIzvLCR5vnPNdVwn89AqzI85IcDZdy0R9ZX4NBbsDgAU
6ig6uXuRXvSGiyJ/OUXSrnogaQJhAOjvkHUhVZQkPOxO90TNH4j0GdKKtbSWxIdz
lKfuJeBAEqs0TL+C6vbS81Xw3W1alyDdUBk3rJMOBqW6Ryq5HNL+j5H+Jfsh7fvc
Yle+5wHGci0P9zCFZCrY8It7n9XFIwJhAMfEi6oJa2G8waPJ1bQhxka82Tf9pnKM
XCn/1BBOFjVIx5F842cpA+zp5a62GENTGYPQTTRBB/2/ZwnW5aIkrlg54AtmbqBZ
Oh+2kJdJQD/tfoVmc5soUE2ScTHadK5RKwJhAN4w9kjkXS+MSZjX0kIMsBIBVkhh
C+aREjJqa9ir7/Ey7RvmLXdYuCxtGLRXp7/R8+rjcK49Tx6O+IRJZe042mfhbq3C
EhS1Tr86f4xXix9EXlDhs9bSxrOgcAN9Dv/opQJhAK7eBcPaav0rVfYh/8emqQHS
3fJ9Pu6WnzbEksWTFS2ff9KDGCx9YspIFJ5TF/oXDAaumGZdZrlgirm6O1kr8tGY
F97i04PZl1+bWAaWQH+1TUNI43m2WFUPE7coG2tb8QJgcddDg9VlXliZqgcETZfJ
kJmYETxrcSn3ao6v116N8yxhEgUgjkmsCTiFgx36iDVnXwK6PIt+sIu8MC7eYNa3
berrv/M21K0LRn20IWRxvUobG070weHCAgkko7fTWgr2
-----END RSA PRIVATE KEY-----
-----BEGIN PRIVATE KEY-----
MIIG/gIBADANBgkqhkiG9w0BAQEFAASCBugwggbkAgEAAoIBgQDiNGqbEmyFI9QF
EvWcU36irjzp1W+VMuMHGD5PDYy5ib1QIrUcUQPvWydV4er/6gnpv6VQ+dfOeVlr
Acu73kdh+N0u5UgjIY9CJnoN12eEGjTrVFlHoA2Ur/TMbN3DW20Nbyi5LUJ8KrGl
Yg8tPbLqGvfJsIYTspBEzgQcJg5ZTD3YA2ZESrbZe2sOunri0j1myv+EoTqB4nPb
ShHx8i11IJpUoBEoHoSyMQgEgYJqbmqCHaTGJWNxHUUhI5MmTPEzyrG6T0B3v5Pb
y1eFOyAU+I4SCs0fqHPg4DbPlNTe/MEBm2LQAVrUFjcFx+Cq75oOa9sVp6xvBmYN
nMiwGgLJYjN7l0lhRQEtao6tEGQUYbmpKoLQJMsKs6bjs6HK5TXMzQUfHATirmjE
C1Fcb/eKJ27HNiKS+uw2g9Tpu/af2qKl3ePNUioPbMYtgGhu5csD22heGeilNVtN
8D47kU0SveXjokV476CecW0SZnN9rVrvd0IqtnU9fMoAQyZE6ScCAwEAAQKCAYAk
0//fS3qbmp+0S8ftMbLWbaPBNly6X9SSnSHX4Q7eTkyiNWRjPdV0LNUUqHmIPORs
SCV0L5kxJpSmVV6EMcZRbyEjt3StM5ONY5JPmphh65peDheTD73mTVd/yOG6IrJ4
k3Z/35yJdrIBiRuLdBYjA00Aa1sI7fOLIDePFasUYtNWzgbia3+lnPBrL3U+ZJhW
mgpL36wU5XeTZlXRnGpGPY6i5ISmkYFtOYpioWtIRL3WfVkMYZ31FpzgrlgQzknQ
lrKN2g7/3q0uLlbasgCsAK50hL2f2xxzsALDCGFjDJbwdIZKfdoxRbgS0L7q7gj0
SUK4fc1obR5qHc2lTuCSzPpionq022ElC0DChupiosyXN4GxNZ2Dwoln4Y5s2YXo
+VTtyYbVEib15WbhHorvfg0QUO00Nwqu+LVTVUXueNre2n507fSiOhCIpbPUWDGz
RoeRFEP0T9+mzQgXr56TAiYunIat1qVxXrwaSWSXEfInGUTkdRUC4rctv7KJ1nEC
gcEA8jDTh1OLBG3/JkQxQNOoqFUFssPlJ+z3LcyaNT6bM5lH5Vwn3sGOFWOMLILD
f/qbGG/1VPVfoCEY1NEkYsocOMtkLIJrIdtD5DOnWz1JJE7Zh2AoWWfIfXd9v5sh
m1fB3SVa6D9JtGoDnKttMl25Tqf6YehVo35Axxar74k3kC/vuZrp/81iZscdRsyK
kQh9fPXl4Oqw2cUYdx3L8UprLS4JguvR0zXvbukJ75DjLZELvjnxBbA1vdtyQz58
2uk1AoHBAO8aP5h08kwTIJCXS6uyAJ0F8F/30srAtchSpzsC3YEEs/Z+43D7W1RR
Obw4KhVjjmFeh83U8pdEuUEjv3ua52+uoUCqTywe+o180owiWsTDSXVtDHiUD7bu
x+nRnpk3flZD28GHKLdWMmJvd8DzMgsa9fJIucMYT7xQHzxCW+4nhhBckX9LEH7i
Jo6MaVuh8b6NuZXOBgU3cp20GTZ3SwRNkKOigctQVZT4A1Vf4ioLrVyhv/LVLBC+
UvoIu82wawKBwQDakMXU8sgaj0ocNp5caqdigphJ5BACIBBR/LuOIZnezw3bJ3ez
x+l51ATEhp33+SnOu/sjWO2bjULjjHrRzKP7fVJB+NDGFSMH5rW52W0Qnzggu96u
EMMWt6d8K3wAvQnvka6gubzCXIo18V7yfTKmkWGcyhe/HElJYmR4H9VNAnXNgsh6
Wdfb+QWqxxymFotpImD6wdIoNX8GwJU0hHyEoW9j/320ppAV/6k/0fmzPZrjaVbi
U0uss0ZC+TmkNaECgcB9L6gGYYyOyiDts1k6LvtlOzvMc0uZPmau2J+YJPrmVxkG
QQ9CE0iRD+oDowBdrH9aeYzu9sSA8Mlx0o6p38O21J625bSILDwQoj72gfI2PO0U
HyE9bIABzmk7AbZhEA4Eiojffa2St/2vTh9MFcioydfln7Aq9mqg9O41taS+P1FQ
9bZ0CFA9rphzYA61nEee9kMprPG3/3zyFt5whuru+NF261m7onb8hRHxvD8EtpJx
AnsmX/gvWAbHxJTXr7sCgcEAp6QAysy0/sgRYvzBkqv05kz4xBqy2a4ZKjnMLEWY
7MicZiQrkSsEjMNDy20rjXfZbhDJWGVjBOZ1QsYehKhGAIoORXID9B3aZ32m//VU
IUxkLcrIPLPmfdzZvlRPnQc/TAZNe41BGBa4WlDwTFE9TdpVtTzjW1ac5yBN7sa+
V7YbBSiOhP+NuqQFQM01aaZCmOetcj70B4SwJVzswhITS0O+7ZAvicGJiQKTUvUY
ijWm+Luu3QYDc2HBMwUAmHT5
-----END PRIVATE KEY-----
+23 -12
View File
@@ -1,14 +1,25 @@
-----BEGIN CERTIFICATE-----
MIICFzCCAUACCQDO660L5y5LGDANBgkqhkiG9w0BAQUFADAQMQ4wDAYDVQQDEwVw
ZXRhbDAeFw0xMDA5MzAxMzQzMDFaFw0zMDA2MTcxMzQzMDFaMBAxDjAMBgNVBAMT
BXBldGFsMIHfMA0GCSqGSIb3DQEBAQUAA4HNADCByQKBwQC1xQ/Kca6zszZbcCtd
OTIH2Uy2gOy/DfabMUU7TmNPm0dVE0NJRuN+Rm304SonpwghfP2/ULZNnuDgpG03
/32yI7k/VzG6iA4hiF7tT/KAAWC/+2l1QCsawCV2bSrFK0VhcZr7ALqXd8vkDaQ8
67K029ypjOQtAJ85qdO3mERy7TGtdUcuO6hLeVet419YeQ2F8cfNxn63d7bOzNGL
PW5xwaCd3UcgD+Ib0k4xfFvbinvPQUeUJ/i4YDWexFYSL+ECAwEAATANBgkqhkiG
9w0BAQUFAAOBwQBBkX9KDP2RXbg+xPmdJ4P6CwvA5x1LZwC++ydVx4NlvT0pWicD
ZUnXjcWAJlkeOuUBAqFG7WHTrXpUUAjmdqFVq2yFjteUYBdrFz0RDB2jM9feeKYO
mTgxdZyT9a6humxCxt5VfgT02axLjm/2AqCyFPMbf4PASoJDln01AEuZLZ8Xl2gV
bYHMnHTGoD1Hu6FNEzRgkMC6XT8X3YjHvzQhpc/qL5wEfEsinQGdX4twsuWbf8xd
q7miNnkO8vd0maw=
MIIERDCCAqygAwIBAgIUY5FZe4tAZd0ITNbceavVGLvEe2QwDQYJKoZIhvcNAQEL
BQAwEDEOMAwGA1UEAwwFcGV0YWwwHhcNMjYwNzI0MDkwNTMyWhcNNDYwNDEwMDkw
NTMyWjAQMQ4wDAYDVQQDDAVwZXRhbDCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCC
AYoCggGBAOI0apsSbIUj1AUS9ZxTfqKuPOnVb5Uy4wcYPk8NjLmJvVAitRxRA+9b
J1Xh6v/qCem/pVD51855WWsBy7veR2H43S7lSCMhj0Imeg3XZ4QaNOtUWUegDZSv
9Mxs3cNbbQ1vKLktQnwqsaViDy09suoa98mwhhOykETOBBwmDllMPdgDZkRKttl7
aw66euLSPWbK/4ShOoHic9tKEfHyLXUgmlSgESgehLIxCASBgmpuaoIdpMYlY3Ed
RSEjkyZM8TPKsbpPQHe/k9vLV4U7IBT4jhIKzR+oc+DgNs+U1N78wQGbYtABWtQW
NwXH4Krvmg5r2xWnrG8GZg2cyLAaAsliM3uXSWFFAS1qjq0QZBRhuakqgtAkywqz
puOzocrlNczNBR8cBOKuaMQLUVxv94onbsc2IpL67DaD1Om79p/aoqXd481SKg9s
xi2AaG7lywPbaF4Z6KU1W03wPjuRTRK95eOiRXjvoJ5xbRJmc32tWu93Qiq2dT18
ygBDJkTpJwIDAQABo4GVMIGSMB0GA1UdDgQWBBSLQ6cvFrU2JiedggRXjiUemV3h
QzBLBgNVHSMERDBCgBSLQ6cvFrU2JiedggRXjiUemV3hQ6EUpBIwEDEOMAwGA1UE
AwwFcGV0YWyCFGORWXuLQGXdCEzW3Hmr1Ri7xHtkMBIGA1UdEwEB/wQIMAYBAf8C
AQAwEAYDVR0RBAkwB4IFcGV0YWwwDQYJKoZIhvcNAQELBQADggGBANj5PXClrk76
UddT6aniB/VbErfu1MwfyYSGhE4y5VVJVyD+wHYECswdm2IIo/v/4I+4KWgAcGPk
u+j1B2iXN8sQTe500+KMSRFfaxdbwlX42+oDKwRoz8pwMzETyZYQA4PAE5j2rnjb
n9USomWzvwavo7GRE6VauBcSAekrNFDjPw43tElmr2TTz4lUFXlvBlQvcbloJ4OU
60ek8d1erlsLXzAtf4kCFH1aiII0g0fA448gnIOIgT9LiV88smKNDPVqusw9TBd5
/f1R8ETy7jcIJ9TU34dy6S39s4aUjWUAZMV1TIH3wJPDsE6+1yD5OC5b50akIwpJ
jO9naDRvgaHIWxJRcREXd+H7IlybL+l+Qq4L4RX583cdL/rZEWdnESgbDq7EkEPn
ZbpjdM4oNGUlXsrZw0/GFgzYlN2MBFiLht6y2iBbhFxPb2SM3Xx/M5YnsNLym+I/
m9mck/aeeSEyJ2uIfFfVndfPfqmKxwvoPu0OCv/ppsi+xTvhE6B/UQ==
-----END CERTIFICATE-----
+40 -21
View File
@@ -1,21 +1,40 @@
-----BEGIN RSA PRIVATE KEY-----
MIIDfAIBAAKBwQC48GhhmIU66TZKc3QiyF4L5bsm8Aly/y2SzLP+GACepK0OcOtD
i2sXrTtoJDvGOPZ9ICqmIy8u/Q/cK26txNEeZFcClLcYF/U+NaqjEwrwkHEIgc3g
8qnKrhzM61I8foAWVT7cqxFHDKYuClNITXk1i//Yzpnf9wvVKQ51W9UOtm/WA7g4
IDHCuAjocyyNC3B7XqYawFDOsdMI4ZW7hC0hIRQOvBkvbvY8WxmsSkdd30u1KmoI
Sg4y6OvnikrEEQkCAwEAAQKBwQC3hQlv37RF82sGkm8qnP6Ge+AuEYCu9v44cJ4k
hZkH1I5OiEtN6anKAwOyolIWsCwZmrP3zW5jCIiWiRr5oReLOzMEwqK2a//XTdYY
oSr38b3ZHUY59VP8Zq75woMGuNed35kAmGxzDRP1gI/TmvTvaHlqYyvxBtxnZJij
Za1CrT+a9JvR6hI8xXrE33CF0T6JO1v3v0HeBuve5+83cCHKo+GyqIBjL3FJgefZ
EsPz6rGnPDKTYgMyaljFV3LI5ikCYQDlaBnyiWk1C7tYO5x3CRoHoiuiiREZCncK
QkSxjiDoSP0rc+3BQp2kG3yy6S9mN4qMQPELEtBa6bORogxNK+Pxg8TRI/+xgeFt
bod5Bd4pfl6Y5hXm21JwELFlOzPI3PMCYQDOYK6Z7vegiOJyyAJXMjcI07H8S0Gr
SZW8f4tHRzO+RrRpR5ANzarELX7nF/Qj5mPXiZNiiMDGocxqkNzIa5HFLOqBhRkv
o7yC1Cj582dUBFHyEbsZxR6UMTPLdE3UaRMCYACC1Nv3dmaJ2ib+KwEQ4h/2Ooao
K4OUxGMfdqu2l1gtIXNBVNxDW7qL3SFA57wgj4x0cJUHu7MYJjBC3igl2uIk2wFk
RSOOGIR35JFec/o/r9JDYPUcs/hP8TU6hokCBQJgHbH/rZqa+vh3TPjGjXFmRdjg
JWNWwaTG7OaVTd5K7bgSwYtQiQvs5Gl/dxUVRg0ilKLxGB6BTpN9bGAHxLbltK9v
1s8l/praxyBr/PsvBQHSILi4aU7ZxY0G3OGRSV0NAmBx28Msdgc0yHh3qSkbwVEr
gr7av1iOH73ee+o4CmMWXYUBHOMW5Su0s0QHjNGDMiRiRoCvzYqdLcJj9/sFJxOT
CM35WGGeKDMNubX7C6YroQ91q7kUmhi7HHY3QOyhCDU=
-----END RSA PRIVATE KEY-----
-----BEGIN PRIVATE KEY-----
MIIG/gIBADANBgkqhkiG9w0BAQEFAASCBugwggbkAgEAAoIBgQC7Tr0JP6gVKA2Z
wtpcBmd27WquMfhdfePva0mV6oc+eE+py2gwHBUAVhMnnYAwT/7ziC0a7pel43tS
NSHgr0oSUZJC2x+gYMKZ341Q+qNFUJTTv+hG41uKwGfcx02+0HuVU1A9m60PNtE2
oc83Au8RwyPgcuzWwk3hmX6XUrZmz0vrUxbniLF9xl0gWeFFFWVeioItYDVAKxtl
Ufrb5/9ju3mzfnEtWWEl+qfraA8DFA10BZRVUBKNB7aGc8KDRBwC4yQBHtIu8ob1
9DGNe2lYnMCHPFR3dsCHjBYbuGf+J66uAxtMu0IygwI3inNtBUTnQ/QVv2fQNJc2
vL9ic1BHSwi5byPld3igVCc35wmKLgKX0WtQKcuxI1BwYfaMK+jTZl6mQcE4AuMk
tvhWbbLn7UQxNAe6X2JKM/M7ds1dIjyfL6nuB1yESX+FiRpjOMuRV1BwrPLJNOfl
C9QkIRgoy1C9WxZUcigeDAApooDls4H/Q16tWdHj8toQWvYKVqMCAwEAAQKCAYBF
/w+/pA1BEr26Z0nIuA/0Lpb+T+g7r+79Kr/OCV3PJ5DFqCDgUa47eO8hj8c2xr5E
7e/FL8J2GMOeHgLx/y+UFu2slEyGV4KBlDwwNenL3mgvlXjM/OvZtztZExXnp+t3
CzJiQ4nxtI+Mdf2E1lDW93Cx0ODXBLesBft7u0o0s2TwpRVbIwcJNJbanxwDABLo
uKQbJuffefx76Z3wjgsvjwDU5fyPcOZQFhKoczOg995rLCaZlxnHoElCh4H6Ifod
K9LQAERjLicBtSThAuO+0us353y3dJ6lY3iYsi2u69UBcvFSepzKjFsx/FPv8B8N
QMmwpfEZvB4ODM7VvZkvmQZcN3HHopRJWVFWkTkCX5A0RXCXO+AaQV+AVJWnGCxj
dyV6L1qBK/HsyOto9KGIHN1VFj+n4hTthNPWkDE7CkA7gAMomNvmlf6zNOrbwzro
LznDK7OQC5Qqoge0R+u/l2xgqzIl8hl5jtmwhi6kT47HBBQ1dBKa6M4rNIFRr9EC
gcEA9CTQHdAax7XcoeETto/TMKKfv0QyfIivscr250/87GNjzsKCK2MxHZ50jmtF
7Q7iYhepRuvhbvF9h4BwK7fUbi/KQAW4qiVxqi+MfQkoVYdvnLgekhdmnrThqWmf
p4ZTZ0tBe29m713WdozHZv6nNcyIrt0JXrVvIFDDpil/6ETHa+y6OMiePc8gklDD
VVCwKpq+F+taFBzfgqNHkdnaMlP/I/35KEQyhV07aLJhR1leExoGkmc7eaK6WqVD
iQqZAoHBAMRnVukeUNiSPZmC3IyyfD8iMXnjyPmb/+a9LmwaVOs4yjdBUmGTx+ZV
mnDb94d3ijyshysbjCc8ebZ7FxuXoaIJ7JWYOgTeMJs1JOAoEVsHBtd1W/RpQ8Hr
NegSwP4cmCzXAQOtenZnCC2QveHlngxk7rUiayj7G4awrJLtyW9Z9WAUokm810Nq
muUXhHxRobc40H65+qyCuPODKz3wO4Lt5VaYd4vR+wkUFc0IghmRX0HVlVe/q9gA
JgXwRPfMmwKBwDWRzkh8XSPs95hddqHcNQ664CproFhK9aIhUsO2fVyxAjlf3IgA
n8pL9m85goJdfbbgUjhJkZFyU4Tj3bj6ARacTdh2aOqMhMA+5qiY1czOhuLwU2Ti
1ZWFQu6VSn7Lrok/rgKTkxZ6lJA2m5oxziaz1lnoDiJF1ThWAFf5SyN/0/IOY14K
Rw5w4Ei6h+G0brMqeQNulLlNDI3xncaW8pWQcK9JDt6S+DLjHiH+4fFx3n56e26s
UBSEbDdvg74SIQKBwQCrCRM2j5/3+eKK/Nrz67snf692Zlduh9uiJL14hrXM4fe3
hrsnHnrGq2WDQwucfQ11KQnNEIBM6u1TbH4DGVk4s0vEOnzMIHJTt0QVsM7sZoIe
v6UEg2buSNb48tv+bwhWhCXt/fTXh4InrBSv1DZ+tKbsNrz7QzIFaXXfvhPdVInK
0i1B6aHMo9mgB4roeG5MEL4AnhUehfhql5/goIQy0NkXQE9bA9GJZmRV2ULy4RYD
TuxvLguIXxi9sy9cXGECgcEA2MCZvKU9hml/4n1/dEiNvSGEA9rz92Vzsb50yeRM
3yLTaYe5koVNbag+IpqpCNP4T2xNnWIxv7ceqB78wxWykadF0z5T5I+/HBPYWLms
mpQPr7grVqcX5gqxJoUwWwxvKLwh5KjqjRX43turXOWlsSHMVNH6KMLt1K3OtArs
OMROcUcXBJc2hvr+YBeHOpIC1ZlawIr5BRi2FICN7TeIiE3h7VFY0ucAyOOKvfH9
FzIeEhSTR60ZN1HtILhRJmjG
-----END PRIVATE KEY-----
+25 -13
View File
@@ -1,15 +1,27 @@
-----BEGIN CERTIFICATE-----
MIICWTCCAYKgAwIBAgIJAN5YIkuCvJf5MA0GCSqGSIb3DQEBBQUAMCYxDjAMBgNV
BAMTBXBldGFsMRQwEgYJKoZIhvcNAQkBFgVwZXRhbDAeFw0xMzAxMTcxMTUyNDVa
Fw0zMjEwMDQxMTUyNDVaMCYxDjAMBgNVBAMTBXBldGFsMRQwEgYJKoZIhvcNAQkB
FgVwZXRhbDCB3zANBgkqhkiG9w0BAQEFAAOBzQAwgckCgcEAuPBoYZiFOuk2SnN0
IsheC+W7JvAJcv8tksyz/hgAnqStDnDrQ4trF607aCQ7xjj2fSAqpiMvLv0P3Ctu
rcTRHmRXApS3GBf1PjWqoxMK8JBxCIHN4PKpyq4czOtSPH6AFlU+3KsRRwymLgpT
SE15NYv/2M6Z3/cL1SkOdVvVDrZv1gO4OCAxwrgI6HMsjQtwe16mGsBQzrHTCOGV
u4QtISEUDrwZL272PFsZrEpHXd9LtSpqCEoOMujr54pKxBEJAgMBAAGjDzANMAsG
A1UdDwQEAwIChDANBgkqhkiG9w0BAQUFAAOBwQCaA3ys5hDPMNV1oXIxH6u2KfAX
C9tYJId/SR0x8whsZuNaSEZAgImdM5dnyWdjey8Pio772E9/F2aUBGFkdadZx4My
d7hBfEi/NECEKs86k9g0ijbin41NKtnajb6GwyNQ9vDx7Z5FS8BZ3CD0BZIdCQUE
gKuDSWBROQU3tqrjdk2QTwGQkj2mgzT871Jn1MwZw0mczPjS1y469Ejym8wi3uCd
EboDOoGBCpmUQbxBv6JI75cUCdmNNEwjQjZ0XQw=
MIIEkzCCAvugAwIBAgIUSAvgFLH//MkCJQDFBcJfyjrVJYswDQYJKoZIhvcNAQEL
BQAwJjEOMAwGA1UEAwwFcGV0YWwxFDASBgkqhkiG9w0BCQEWBXBldGFsMB4XDTI2
MDcyNDA5NDEyNloXDTQ2MDQxMDA5NDEyNlowJjEOMAwGA1UEAwwFcGV0YWwxFDAS
BgkqhkiG9w0BCQEWBXBldGFsMIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKC
AYEAu069CT+oFSgNmcLaXAZndu1qrjH4XX3j72tJleqHPnhPqctoMBwVAFYTJ52A
ME/+84gtGu6XpeN7UjUh4K9KElGSQtsfoGDCmd+NUPqjRVCU07/oRuNbisBn3MdN
vtB7lVNQPZutDzbRNqHPNwLvEcMj4HLs1sJN4Zl+l1K2Zs9L61MW54ixfcZdIFnh
RRVlXoqCLWA1QCsbZVH62+f/Y7t5s35xLVlhJfqn62gPAxQNdAWUVVASjQe2hnPC
g0QcAuMkAR7SLvKG9fQxjXtpWJzAhzxUd3bAh4wWG7hn/ieurgMbTLtCMoMCN4pz
bQVE50P0Fb9n0DSXNry/YnNQR0sIuW8j5Xd4oFQnN+cJii4Cl9FrUCnLsSNQcGH2
jCvo02ZepkHBOALjJLb4Vm2y5+1EMTQHul9iSjPzO3bNXSI8ny+p7gdchEl/hYka
YzjLkVdQcKzyyTTn5QvUJCEYKMtQvVsWVHIoHgwAKaKA5bOB/0NerVnR4/LaEFr2
ClajAgMBAAGjgbgwgbUwHQYDVR0OBBYEFHTJazw63SRJUbZ3slMXV9O9L7JIMGEG
A1UdIwRaMFiAFHTJazw63SRJUbZ3slMXV9O9L7JIoSqkKDAmMQ4wDAYDVQQDDAVw
ZXRhbDEUMBIGCSqGSIb3DQEJARYFcGV0YWyCFEgL4BSx//zJAiUAxQXCX8o61SWL
MBIGA1UdEwEB/wQIMAYBAf8CAQAwEAYDVR0RBAkwB4IFcGV0YWwwCwYDVR0PBAQD
AgKEMA0GCSqGSIb3DQEBCwUAA4IBgQBYyONVmgUv8mpGTp2U+12e715VDGQLRNEu
TjGBgpVF4Vebw8E+L++Fzbd0iJVq0o1WzcM3SxdgPr/AZCqgbzHeRx3ZmE/7QNtF
w+IvOU35VQAYlA3Caz2gYoTLYaCyPF1ZwH7cbviI1pdv1jWotHVYbK/hFXHx1GaF
as3AHGAr1lGFFrnt0pA3G1VJACGEHOFZRxeDAwnyl9VN/JC8uujaSekA98fzspvk
fQYTfOAhR4qd9smwg/af/cgJHcFeMbfLWYmeLa01zMR1NypBOdVJQOXCn9bBn6xW
Niwa9JitzJaK0hRccdOEerw0UI/5s5xCKIYepn5MZ7RlWfarjBTZbVvyzkMMSFa4
qB39pqLTQtxq3KLDpTs76Q+U9UyuQuxuC2kNyPHmpYgCT/2Aaiezx80GMeEL3XCJ
L+vmo/3jU6miAXEFZRBCe1z8bwEWb1RiEHh/pVxRbIMRgtGfCQoQwHpZyx9VUWd0
ZBYZlQ0Ql1YGPEuEWkobTBppzHsaIX8=
-----END CERTIFICATE-----
@@ -0,0 +1,32 @@
server:
verbosity: 7
# num-threads: 1
interface: 127.0.0.1
port: @PORT@
use-syslog: no
directory: ""
pidfile: "unbound.pid"
chroot: ""
username: ""
do-not-query-localhost: no
use-caps-for-id: no
auth-zone:
name: "example.com"
for-upstream: yes
for-downstream: yes
master: "127.0.0.1@@TOPORT@"
max-transfer-size: 512
max-transfer-time: 2000
auth-zone:
name: "example2.com"
for-upstream: yes
for-downstream: yes
master: "127.0.0.1@@TOPORT2@"
max-transfer-size: 512
max-transfer-time: 2000
remote-control:
control-enable: yes
control-interface: @CONTROL_PATH@/controlpipe.@CONTROL_PID@
control-use-cert: no
@@ -0,0 +1,16 @@
BaseName: auth_transfer_limit
Version: 1.0
Description: Test limit of authority zone transfer.
CreationDate: Tue May 12 03:00:00 PM CEST 2026
Maintainer: dr. W.C.A. Wijngaards
Category:
Component:
CmdDepends:
Depends:
Help:
Pre: auth_transfer_limit.pre
Post: auth_transfer_limit.post
Test: auth_transfer_limit.test
AuxFiles:
Passed:
Failure:
@@ -0,0 +1,16 @@
# #-- auth_transfer_limit.post --#
# source the master var file when it's there
[ -f ../.tpkg.var.master ] && source ../.tpkg.var.master
# source the test var file when it's there
[ -f .tpkg.var.test ] && source .tpkg.var.test
#
# do your teardown here
. ../common.sh
kill_pid $FWD_PID
kill_pid $FWD2_PID
kill_pid $UNBOUND_PID
rm -f $CONTROL_PATH/controlpipe.$CONTROL_PID
echo "> cat logfiles"
cat fwd.log
cat fwd2.log
cat unbound.log
@@ -0,0 +1,54 @@
# #-- auth_transfer_limit.pre--#
# source the master var file when it's there
[ -f ../.tpkg.var.master ] && source ../.tpkg.var.master
# use .tpkg.var.test for in test variable passing
[ -f .tpkg.var.test ] && source .tpkg.var.test
PRE="../.."
. ../common.sh
if grep -e "define HAVE_PTHREAD 1" -e "define HAVE_SOLARIS_THREADS 1" -e "define HAVE_WINDOWS_THREADS 1" $PRE/config.h; then
TEST_FAST_RELOAD="yes"
else
TEST_FAST_RELOAD="no"
fi
echo "TEST_FAST_RELOAD=$TEST_FAST_RELOAD" >> .tpkg.var.test
get_random_port 3
UNBOUND_PORT=$RND_PORT
FWD_PORT=$(($RND_PORT + 1))
FWD2_PORT=$(($RND_PORT + 2))
echo "UNBOUND_PORT=$UNBOUND_PORT" >> .tpkg.var.test
echo "FWD_PORT=$FWD_PORT" >> .tpkg.var.test
echo "FWD2_PORT=$FWD2_PORT" >> .tpkg.var.test
# start forwarders
get_ldns_testns
$LDNS_TESTNS -p $FWD_PORT auth_transfer_limit.testns >fwd.log 2>&1 &
FWD_PID=$!
echo "FWD_PID=$FWD_PID" >> .tpkg.var.test
$LDNS_TESTNS -p $FWD2_PORT auth_transfer_limit.testns2 >fwd2.log 2>&1 &
FWD2_PID=$!
echo "FWD2_PID=$FWD2_PID" >> .tpkg.var.test
# make config file
CONTROL_PATH=/tmp
CONTROL_PID=$$
sed -e 's/@PORT\@/'$UNBOUND_PORT'/' \
-e 's/@TOPORT\@/'$FWD_PORT'/' \
-e 's/@TOPORT2\@/'$FWD2_PORT'/' \
-e 's?@CONTROL_PATH\@?'$CONTROL_PATH'?' \
-e 's/@CONTROL_PID@/'$CONTROL_PID'/' \
< auth_transfer_limit.conf > ub.conf
# start unbound in the background
$PRE/unbound -d -c ub.conf >unbound.log 2>&1 &
UNBOUND_PID=$!
echo "UNBOUND_PID=$UNBOUND_PID" >> .tpkg.var.test
echo "CONTROL_PATH=$CONTROL_PATH" >> .tpkg.var.test
echo "CONTROL_PID=$CONTROL_PID" >> .tpkg.var.test
cat .tpkg.var.test
wait_ldns_testns_up fwd.log
wait_ldns_testns_up fwd2.log
wait_unbound_up unbound.log
@@ -0,0 +1,100 @@
# #-- auth_transfer_limit.test --#
# source the master var file when it's there
[ -f ../.tpkg.var.master ] && source ../.tpkg.var.master
# use .tpkg.var.test for in test variable passing
[ -f .tpkg.var.test ] && source .tpkg.var.test
PRE="../.."
. ../common.sh
# do the test
teststep "wait for unbound to transfer"
sleep 3
teststep "check log for max-transfer-size"
if grep "auth zone example.com. transfer.*exceeded 512 bytes" unbound.log; then
echo "OK"
else
echo "Not OK"
exit 1
fi
teststep "check log for max-transfer-time"
if grep "auth zone example2.com. transfer.*exceeded 2000 msec" unbound.log; then
echo "OK"
else
echo "Not OK"
exit 1
fi
if test "$TEST_FAST_RELOAD" == "yes"; then
teststep "Testing with fast_reload"
cp ub.conf ub.conf.old
sed -e 's/max-transfer-size: 512/max-transfer-size: 500/' -e 's/max-transfer-time: 2000/max-transfer-time: 1000/' < ub.conf.old > ub.conf
teststep "unbound-control status"
$PRE/unbound-control -c ub.conf status
if test $? -ne 0; then
echo "wrong exit value."
exit 1
else
echo "exit value: OK"
fi
teststep "unbound-control fast_reload +vvdp"
$PRE/unbound-control -c ub.conf fast_reload +vvdp 2>&1 | tee output
if test $? -ne 0; then
echo "wrong exit value."
exit 1
else
echo "exit value: OK"
fi
wait_logfile unbound.log "start fast reload thread" 60
wait_logfile unbound.log "stop fast reload thread" 60
wait_logfile unbound.log "joined with fastreload thread" 60
if grep "ok" output; then
echo "OK"
else
echo "output not correct"
exit 1
fi
teststep "wait for unbound to transfer"
sleep 3
$PRE/unbound-control -c ub.conf auth_zone_transfer example.com 2>&1
if test $? -ne 0; then
echo "wrong exit value."
exit 1
else
echo "exit value: OK"
fi
$PRE/unbound-control -c ub.conf auth_zone_transfer example2.com 2>&1
if test $? -ne 0; then
echo "wrong exit value."
exit 1
else
echo "exit value: OK"
fi
teststep "wait for unbound to transfer"
sleep 3
teststep "check log for max-transfer-size"
if grep "auth zone example.com. transfer.*exceeded 500 bytes" unbound.log; then
echo "OK"
else
echo "Not OK"
exit 1
fi
teststep "check log for max-transfer-time"
if grep "auth zone example2.com. transfer.*exceeded 1000 msec" unbound.log; then
echo "OK"
else
echo "Not OK"
exit 1
fi
fi
exit 0
@@ -0,0 +1,38 @@
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
example.com. IN SOA
SECTION ANSWER
example.com. IN SOA ns.example.com. hostmaster.example.com. 1 3600 900 86400 3600
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
example.com. IN AXFR
SECTION ANSWER
example.com. IN SOA ns.example.com. hostmaster.example.com. 1 3600 900 86400 3600
example.com. IN NS ns.example.net.
; too big!
EXTRA_PACKET
REPLY QR AA NOERROR
SECTION QUESTION
example.com. IN AXFR
SECTION ANSWER
large01.example.com. IN TXT "123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789"
large02.example.com. IN TXT "123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789"
large03.example.com. IN TXT "123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789"
large04.example.com. IN TXT "123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789"
large05.example.com. IN TXT "123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789"
EXTRA_PACKET
REPLY QR AA NOERROR
SECTION QUESTION
example.com. IN AXFR
SECTION ANSWER
www.example.com. IN A 1.2.3.4
example.com. IN SOA ns.example.com. hostmaster.example.com. 1 3600 900 86400 3600
ENTRY_END
@@ -0,0 +1,35 @@
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
example2.com. IN SOA
SECTION ANSWER
example2.com. IN SOA ns.example2.com. hostmaster.example2.com. 1 3600 900 86400 3600
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
example2.com. IN AXFR
SECTION ANSWER
example2.com. IN SOA ns.example2.com. hostmaster.example2.com. 1 3600 900 86400 3600
example2.com. IN NS ns.example2.net.
EXTRA_PACKET
REPLY QR AA NOERROR
; too slow
ADJUST packet_sleep=3
SECTION QUESTION
example2.com. IN AXFR
SECTION ANSWER
extra.example2.com. IN A 1.2.3.5
EXTRA_PACKET
REPLY QR AA NOERROR
SECTION QUESTION
example2.com. IN AXFR
SECTION ANSWER
www.example2.com. IN A 1.2.3.4
example2.com. IN SOA ns.example2.com. hostmaster.example2.com. 1 3600 900 86400 3600
ENTRY_END
+294
View File
@@ -0,0 +1,294 @@
; config options
server:
trust-anchor: "example.net. 3600 IN DS 29332 8 2 fe9d2d1f797b8dbe717febca0b7ff2125e0bdc819eb529008aad5630e61d4d99"
val-override-date: "20201020135527"
target-fetch-policy: "0 0 0 0 0"
fake-sha1: yes
trust-anchor-signaling: no
target-fetch-policy: "0 0 0 0 0"
qname-minimisation: no
auth-zone:
name: "example.com."
master: ns.example.net.
for-downstream: yes
for-upstream: yes
## fallback-enabled: no
## this line generates zonefile: \n"/tmp/xxx.example.com"\n
zonefile:
TEMPFILE_NAME example.com
## this is the inline file /tmp/xxx.example.com
## the tempfiles are deleted when the testrun is over.
TEMPFILE_CONTENTS example.com
TEMPFILE_END
stub-zone:
name: "."
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
CONFIG_END
SCENARIO_BEGIN Test authority zone with bogus host name lookup
; K.ROOT-SERVERS.NET.
RANGE_BEGIN 0 100
ADDRESS 193.0.14.129
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR NOERROR
SECTION QUESTION
. IN NS
SECTION ANSWER
. IN NS K.ROOT-SERVERS.NET.
SECTION ADDITIONAL
K.ROOT-SERVERS.NET. IN A 193.0.14.129
ENTRY_END
ENTRY_BEGIN
MATCH opcode subdomain
ADJUST copy_id copy_query
REPLY QR NOERROR
SECTION QUESTION
com. IN NS
SECTION AUTHORITY
com. IN NS a.gtld-servers.net.
SECTION ADDITIONAL
a.gtld-servers.net. IN A 192.5.6.30
ENTRY_END
ENTRY_BEGIN
MATCH opcode subdomain
ADJUST copy_id copy_query
REPLY QR NOERROR
SECTION QUESTION
example.net. IN A
SECTION ANSWER
SECTION AUTHORITY
example.net. IN NS ns2.example.net.
SECTION ADDITIONAL
ns2.example.net. IN A 1.2.3.45
ENTRY_END
RANGE_END
; a.gtld-servers.net.
RANGE_BEGIN 0 100
ADDRESS 192.5.6.30
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR NOERROR
SECTION QUESTION
com. IN NS
SECTION ANSWER
com. IN NS a.gtld-servers.net.
SECTION ADDITIONAL
a.gtld-servers.net. IN A 192.5.6.30
ENTRY_END
ENTRY_BEGIN
MATCH opcode subdomain
ADJUST copy_id copy_query
REPLY QR NOERROR
SECTION QUESTION
example.com. IN NS
SECTION AUTHORITY
example.com. IN NS ns.example.com.
SECTION ADDITIONAL
ns.example.com. IN A 1.2.3.44
ENTRY_END
RANGE_END
; ns.example.com.
RANGE_BEGIN 0 100
ADDRESS 1.2.3.44
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR NOERROR
SECTION QUESTION
example.com. IN NS
SECTION ANSWER
example.com. IN NS ns.example.com.
SECTION ADDITIONAL
ns.example.com. IN A 1.2.3.44
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR NOERROR
SECTION QUESTION
ns.example.com. IN A
SECTION ANSWER
ns.example.com. IN A 1.2.3.44
SECTION AUTHORITY
example.com. IN NS ns.example.com.
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR NOERROR
SECTION QUESTION
ns.example.com. IN AAAA
SECTION AUTHORITY
example.com. IN NS ns.example.com.
SECTION ADDITIONAL
www.example.com. IN A 1.2.3.44
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR NOERROR
SECTION QUESTION
example.com. IN NS
SECTION ANSWER
example.com. IN NS ns.example.com.
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR NOERROR
SECTION QUESTION
www.example.com. IN A
SECTION ANSWER
www.example.com. IN A 10.20.30.40
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR NOERROR
SECTION QUESTION
example.com. IN SOA
SECTION ANSWER
; serial, refresh, retry, expire, minimum
example.com. IN SOA ns.example.com. hostmaster.example.com. 1 3600 900 86400 3600
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
example.com. IN AXFR
SECTION ANSWER
example.com. IN SOA ns.example.com. hostmaster.example.com. 1 3600 900 86400 3600
example.com. IN NS ns.example.com.
www.example.com. IN A 1.2.3.4
example.com. IN SOA ns.example.com. hostmaster.example.com. 1 3600 900 86400 3600
ENTRY_END
RANGE_END
; ns2.example.net
RANGE_BEGIN 0 100
ADDRESS 1.2.3.45
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
ns2.example.net. IN A
SECTION ANSWER
ns2.example.net. 3600 IN A 1.2.3.45
ns2.example.net. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 29332 example.net. ttH0qGYFJp0zfoqb6h9cDGhkosucRPI64gd3+i7gwAcbOtfGJhHR7+NQ7uH+gRRv4lzPEiWP6zM7IiSeC1o+gW/Y2u6J1a330KzikT1YxIWGQJ825NU3PJ5ifTC8IgrN8HFwBuof3K4x/ftdA9VRcyCbFicazOD4RLlbhffMpoVQKyRa/NqHT8mSWLPry9q9skgdyRk17f65i0sdSCEyCXv8+vX6vBxaMF3in+zQxvnA9nyB4omwLLJZx3jaF0+lSiBcx3u20DTbCC/cyjxJArhLlv1N5U3GRUpFXl1d7k0FmacQCP4H5UXSzy6vf6XoQwtfIgNzwYgFN5RuCdJ71w==
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
ns2.example.net. IN AAAA
SECTION ANSWER
SECTION AUTHORITY
example.net. 3600 IN SOA ns.example.com. root.example.com. 4 14400 3600 604800 3600
example.net. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 29332 example.net. OWDPS0sJQOhZlqKUbdL8OVwT0u1e1asbjW+9dMRxIF/VoxxRaYIqD/lsn1U+irRrbIPDp9wxDdFu7ChddB1n2/do/by9xuIMLD00mkxSJduxMjRl/8hWvhBV6j8jqU0pbsxS3Oolcju8imrobEqqCDi1YVD6OQuBzwnQ7trF9mfANv208pDA4chWXWUimFETKzpc3aLarcm3qVnb53AQhggyLow/ZLG1egbwaGn3pcf+kPHw+G4MSOR1TtS0mWKiPgdYRiqSS+AqrZUu/ZuAKAGweKeIypDgm6RZC5M4FmRA+f8gZg2rI2Xog6TLt0qrjD8ARwXkyBq8wL3G0Ihkew==
ns2.example.net. 3600 IN NSEC ns3.example.net. A RRSIG NSEC
ns2.example.net. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 29332 example.net. MMDdm3yz6Ocreg8HE7Cf9EnIJ5NFCVzEv+I9zBeUR90pFBlrBY4LqmMxC5GXoEEc1iql5XpPkIspsWTkCUSWutoiDh4Vlg54HrZ4ONy8GzVzg5ePcuXT51nYq1xjfDx4Yi124GT/QKx4+B7HFoyFfoRT1Kf+uP3c7F7qK+VB3FrBBQpl7f6dX87qO23Bb+Vp+L0RPCmuLkhdnrM34bB6jT1lGwgsD4upDy81XKSH6uces8D/fvl0+Evzcy3gkKlxY6uzV53cUD0FM9AVg7/ZWXwQe5n7PIU9gzQ3xtnH5MA8fG6iUyVQJixjqzEqjJdh2PMJA31qTT2X6LQO95ZM2w==
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
example.net. IN DNSKEY
SECTION ANSWER
example.net. 3600 IN DNSKEY 257 3 8 AwEAAb4WMOTBLTFvmBra5m6SK4VfViOzmvyUAU0qv861ZQXeEFvwlndqNU9rwRsMxrSWAYs5nHErKDn49usC/HyxxW1477iGFHhfgL4mjNreJm9zft2QFB1VLbRbEPYdDMLCn4co0qnG7/KG8W2i8Pym1L7f+aREwbLo+/716AS2PbaKMhfWLKLiq5wnBcUClQMNzCiwhqxDJp1oePqfkVdeUgXOtgi0dYRIKyQFhJ5VWJ22npoi/Gif0XLCADAlAwRLKc8o/yJkCxskzgpHpw5Cki1lclg0aq4ssOuPRQ+ne6IHYCz9D2mwzulblhLFamKdq7aHzNt4NlyxhpANVFiKLD8= ;{id = 29332 (ksk), size = 2048b}
example.net. 3600 IN RRSIG DNSKEY 8 2 3600 20201116135527 20201019135527 29332 example.net. a0AqvyBN1Dr1Try1RBjbWjhaaTj3WGpSBywSxLu09bElAFinC3kUgk/WTjfsIIxruUHmzVgPssYeb5g79rdaz7YanSi06LQsnEjMS+hexSU6TXBCtJnhA8taKPlPj+qBRQL/Ptju72upty6Mw8eMG05QOQOa2WC5mPLgo2k6PmgsBMyW3Rhn+lldlmz1NZIZ3udDHs6xxX6Gjio67ogGm0MUbWRZo68oGt/xYv6JzZAVzZROlWvs5D+pf1Mrfzn3yOMJ0jh2XTXJAiw3vX+i2k/P/Yfscm7BWULJ7fBx+0JcDuYccd2mj9ijmD7KuM/laFSIUvxAixu7gV2TDrKEjw==
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
ns.example.net. IN A
SECTION ANSWER
ns.example.net. IN A 1.2.3.44
; bad RRSIG
ns.example.net. 3600 IN RRSIG A 8 2 3600 20201116135527 20201019135527 29332 example.net. a0AqvyBN1Dr1Try1RBjbWjhaaTj3WGpSBywSxLu09bElAFinC3kUgk/WTjfsIIxruUHmzVgPssYeb5g79rdaz7YanSi06LQsnEjMS+hexSU6TXBCtJnhA8taKPlPj+qBRQL/Ptju72upty6Mw8eMG05QOQOa2WC5mPLgo2k6PmgsBMyW3Rhn+lldlmz1NZIZ3udDHs6xxX6Gjio67ogGm0MUbWRZo68oGt/xYv6JzZAVzZROlWvs5D+pf1Mrfzn3yOMJ0jh2XTXJAiw3vX+i2k/P/Yfscm7BWULJ7fBx+0JcDuYccd2mj9ijmD7KuM/laFSIUvxAixu7gV2TDrKEjw==
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
ns.example.net. IN AAAA
SECTION ANSWER
SECTION AUTHORITY
example.net. 3600 IN SOA ns.example.com. root.example.com. 4 14400 3600 604800 3600
example.net. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 29332 example.net. OWDPS0sJQOhZlqKUbdL8OVwT0u1e1asbjW+9dMRxIF/VoxxRaYIqD/lsn1U+irRrbIPDp9wxDdFu7ChddB1n2/do/by9xuIMLD00mkxSJduxMjRl/8hWvhBV6j8jqU0pbsxS3Oolcju8imrobEqqCDi1YVD6OQuBzwnQ7trF9mfANv208pDA4chWXWUimFETKzpc3aLarcm3qVnb53AQhggyLow/ZLG1egbwaGn3pcf+kPHw+G4MSOR1TtS0mWKiPgdYRiqSS+AqrZUu/ZuAKAGweKeIypDgm6RZC5M4FmRA+f8gZg2rI2Xog6TLt0qrjD8ARwXkyBq8wL3G0Ihkew==
ns.example.net. 3600 IN NSEC ns2.example.net. A RRSIG NSEC
ns.example.net. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 29332 example.net. bwmn1nX0amfcIK6+NXdX7i3VvebPGpVLd0Ry0P+5JbiLCO3lI8kbXxpQh2jpIAKAdfSq+WZPGAhwOSOTVak1mEcYf5xLvmiKWmGz0LH8RTCzQTAlcQTnuybmQWuwBjIXaetVQ1ADiJZK57M41d5lOE0KqWe5xfAHE+UhMOQ6JhQwLFK/QfQJB7ke1itM/qfsJHgdb/rbT7v7G8Nd342NMCZEgzP/wFyZ3JRP0XY5D7K71IuFZd9NfxXkKRMn5UM/lMDITqE3MknzXnsKJcH9SpoykKMya9SsrwI+IuOxpQkyiyd+N33H3di4uWI1MiWdayQnR2D3HhHi1Vdp42CDxQ==
ENTRY_END
RANGE_END
STEP 1 QUERY
ENTRY_BEGIN
REPLY RD
SECTION QUESTION
www.example.com. IN A
ENTRY_END
; recursion happens here.
STEP 20 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR AA RD RA SERVFAIL
SECTION QUESTION
www.example.com. IN A
SECTION ANSWER
ENTRY_END
STEP 30 TIME_PASSES ELAPSE 10
STEP 40 TRAFFIC
STEP 50 QUERY
ENTRY_BEGIN
REPLY RD
SECTION QUESTION
www.example.com. IN A
ENTRY_END
; The bogus host was not used.
STEP 60 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR AA RD RA SERVFAIL
SECTION QUESTION
www.example.com. IN A
SECTION ANSWER
ENTRY_END
; the zonefile was updated with new contents
STEP 70 CHECK_TEMPFILE example.com
FILE_BEGIN
FILE_END
SCENARIO_END
+609
View File
@@ -0,0 +1,609 @@
; config options
; The island of trust is at test.
server:
trust-anchor: "test. DS 1444 8 2 8a87d067fd09a5965244fe2e317dd26d182c468e0a7f26ecc4c7b479bf89db9b"
val-override-date: "20201020135527"
target-fetch-policy: "0 0 0 0 0"
qname-minimisation: no
fake-sha1: yes
trust-anchor-signaling: no
minimal-responses: no
iter-scrub-promiscuous: no
local-zone: test. nodefault
log-servfail: yes
module-config: "dns64 validator iterator"
dns64-prefix: 64:ff9b::0/96
stub-zone:
name: "."
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
CONFIG_END
SCENARIO_BEGIN Test DNS64 with DNSSEC validation.
; valid.example.test. both AAAA and A are DNSSEC valid
; invaaaa.example.test. AAAA is invalid, A is DNSSEC valid
; inva.example.test. AAAA is valid, A is DNSSEC invalid
; invboth.example.test. AAAA is invalid, A is DNSSEC invalid
; hasaaaa.example.test. has an AAAA record.
; queries with and without CD flag.
; K.ROOT-SERVERS.NET.
RANGE_BEGIN 0 300
ADDRESS 193.0.14.129
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR NOERROR
SECTION QUESTION
. IN NS
SECTION ANSWER
. IN NS K.ROOT-SERVERS.NET.
SECTION ADDITIONAL
K.ROOT-SERVERS.NET. IN A 193.0.14.129
ENTRY_END
ENTRY_BEGIN
MATCH opcode subdomain
ADJUST copy_id copy_query
REPLY QR NOERROR
SECTION QUESTION
test. IN NS
SECTION AUTHORITY
test. IN NS ns.test.
SECTION ADDITIONAL
ns.test. IN A 1.2.3.5
ENTRY_END
RANGE_END
; ns.test
RANGE_BEGIN 0 300
ADDRESS 1.2.3.5
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
test. IN NS
SECTION ANSWER
test. IN NS ns.test
test. 3600 IN RRSIG NS 8 1 3600 20201116135527 20201019135527 1444 test. RGCxIO32TbbLTk6xZmTr+fjYPH50hntBxeOQ2DIj2pDsmjALcHYtVkOfpfk2EhOhHZd+9PLuoJPbJh6a9NqLSFeBvr0XZoCZoQ2g0tCHUNHcH5EVjA2TuYBQem6DVYnPLJ3914aRx0uA1j42b8dC2xsam/XkOo7U+dLbUW2Os1s=
SECTION ADDITIONAL
ns.test. IN A 1.2.3.5
ns.test. 3600 IN RRSIG A 8 2 3600 20201116135527 20201019135527 1444 test. GskCc4/k6GjH9V9Jz2V5L2XLiizbOeWkB0feSbf+aN859S3vxVvtuqkvIgwY4LafUO1QAn/pUcv9zA7rcFO++rlg+8t6gvZTo9p3v0bfeIv2uJDsfSBD5jDh0WXlxjekfnrKrQp7zE+GiA93tWwKUWKPvxXDgP+n886e6WcbHJw=
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
ns.test. IN A
SECTION ANSWER
ns.test. IN A 1.2.3.5
ns.test. 3600 IN RRSIG A 8 2 3600 20201116135527 20201019135527 1444 test. GskCc4/k6GjH9V9Jz2V5L2XLiizbOeWkB0feSbf+aN859S3vxVvtuqkvIgwY4LafUO1QAn/pUcv9zA7rcFO++rlg+8t6gvZTo9p3v0bfeIv2uJDsfSBD5jDh0WXlxjekfnrKrQp7zE+GiA93tWwKUWKPvxXDgP+n886e6WcbHJw=
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
ns.test. IN AAAA
SECTION AUTHORITY
test. 3600 IN SOA ns.test. host.test. 20201 3600 1800 604800 3600
test. 3600 IN RRSIG SOA 8 1 3600 20201116135527 20201019135527 1444 test. IZJIDmEgf0W7A5G7hvvZ2hUqJ9Trbv1/i7ySapDmPbYV9lVCmHHobySxO01yDhI2/Pvpsvxqrm1Tiv3BxH8uzZ4keKgiQjBsSy4htAsFct9I4E7ly2glPj/Fm3oun3PsjJDv5QYhx0KS7w4IQKU7Nc9pfJc92uoUI5bdoC1pRGw=
ns.test. 3600 IN NSEC nz.test. A RRSIG
ns.test. 3600 IN RRSIG NSEC 8 2 3600 20201116135527 20201019135527 1444 test. PElArVB3KPg8KHAP7lzcNbhFuXNxTsHNTn1dZVncB5qmWRdIaeKpaXDjpH0JSXMaelGFS+/QhuQ6Hmw9+4VyZFRqMzGhw4agUR/2bxABHcDIG4ZpUwyeSP61ATTfHUkQVxaH2wjCWI/tfmesdP2xVE4GXyUvCIBxU914MkZbULU=
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
test. IN DNSKEY
SECTION ANSWER
test. 3600 IN DNSKEY 257 3 8 AwEAAbd9WqjzE2Pynz21OG5doSf9hFzMr5dhzz2waZ3vTa+0o5r7AjTAqmA1yH/B3+aAMihUm5ucZSfVqo7+kOaRE8yFj9aivOmA1n1+JLevJq/oyvQyjxQN2Qb89LyaNUT5oKZIiL+uyyhNW3KDR3SSbQ/GBwQNDHVcZi+JDR3RC0r7 ;{id = 1444 (ksk), size = 1024b}
test. 3600 IN RRSIG DNSKEY 8 1 3600 20201116135527 20201019135527 1444 test. UmRMS4iG9NBBHZYOtpwFFcJgbEb5SfHSgHd9XRe/8pTWM31WSDayn5ViPOBMqI1T5TXg2amc13dDI574xIM2oKMus3b5cBW72jJLW13jprBtslO6P8BMWb4HNnvLrJtQjwf3ErRirtTxinLmywQtmyr1cdthyG3Gp4N7i90fHSc=
SECTION ADDITIONAL
ENTRY_END
ENTRY_BEGIN
MATCH opcode qname qtype
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
example.test. IN DS
SECTION ANSWER
example.test. 3600 IN DS 55567 8 2 a2d578906330a10a57d40462257b6ce038bad3f7bf4a45c46c46086e20a94b39
example.test. 3600 IN RRSIG DS 8 2 3600 20201116135527 20201019135527 1444 test. P7+FTYW2qHuJ4I1YbuvseEz5X1lOYAraGEHB3C5y0OOCQFmhmSiFRdquNi2NlpcS6FXLdsE0EU+Bo1+0atTG4EkMWXbpF21lrtbB51BdsnlX4Mzc/o375fvjiOMwmF6wPCUaOUN62jrVrhsE/hedaVyDphDToqL17ETohwgUO2I=
ENTRY_END
ENTRY_BEGIN
MATCH opcode subdomain
ADJUST copy_id copy_query
REPLY QR NOERROR
SECTION QUESTION
example.test. IN NS
SECTION AUTHORITY
example.test. IN NS ns.example.test.
example.test. 3600 IN DS 55567 8 2 a2d578906330a10a57d40462257b6ce038bad3f7bf4a45c46c46086e20a94b39
example.test. 3600 IN RRSIG DS 8 2 3600 20201116135527 20201019135527 1444 test. P7+FTYW2qHuJ4I1YbuvseEz5X1lOYAraGEHB3C5y0OOCQFmhmSiFRdquNi2NlpcS6FXLdsE0EU+Bo1+0atTG4EkMWXbpF21lrtbB51BdsnlX4Mzc/o375fvjiOMwmF6wPCUaOUN62jrVrhsE/hedaVyDphDToqL17ETohwgUO2I=
SECTION ADDITIONAL
ns.example.test. IN A 1.2.3.4
ENTRY_END
RANGE_END
; ns.example.test.
RANGE_BEGIN 0 300
ADDRESS 1.2.3.4
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR NOERROR
SECTION QUESTION
example.test. IN NS
SECTION ANSWER
example.test. IN NS ns.example.test.
example.test. 3600 IN RRSIG NS 8 2 3600 20201116135527 20201019135527 55567 example.test. l1JT0wMlK0YI7/CWHzexf/k0iafUhCgN+BdgjBXIRXmSQNf4HDTiAkbcWL2/15qtnp12nQy9JeiTdSQ3vtPoHAJX4C5uTWaze4ms+Wrrf+n92sLCjacP9x50uuicH3URT6cKb1QCAPwlvlWxIlZjAMYFScSns7+C441NMJT8aE4=
SECTION ADDITIONAL
ns.example.test. IN A 1.2.3.4
ns.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. 2PWaVaccZFQgfPKXNsdEGYUVaashCAj1ZhBo9XRt5eQKUFvZcauBjMnXIuxZFyWeootn1fZGw6GuPI5W48Y0FDx38H6adprkFgQikso2Y64jDdDMWznSo38Z/XqP+U0+kq4vmwonvmEMpm7hKnNEXvhqGKyGzyBwb+CZVJ2L8Eo=
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
ns.example.test. IN A
SECTION ANSWER
ns.example.test. IN A 1.2.3.4
ns.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. 2PWaVaccZFQgfPKXNsdEGYUVaashCAj1ZhBo9XRt5eQKUFvZcauBjMnXIuxZFyWeootn1fZGw6GuPI5W48Y0FDx38H6adprkFgQikso2Y64jDdDMWznSo38Z/XqP+U0+kq4vmwonvmEMpm7hKnNEXvhqGKyGzyBwb+CZVJ2L8Eo=
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
ns.example.test. IN AAAA
SECTION AUTHORITY
example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8=
ns.example.test. 3600 IN NSEC nz.example.test. A RRSIG
ns.example.test. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 55567 example.test. v/5aO/n8Ow21y7LE7JKZsFkUJU5MjIfadVRm2Tdb8f3RLwYDdBTs3aWeeEQdCRSUF61TmfJM1jIxlWQPuHbqzGnjSk7adw9gFpP7wFwoqG3/xdCFHoxo/3/1F/4Ankey3sDgKgOFsgnu40TlL36mGPYszeK+/2o3SAx2GM+3BdU=
ENTRY_END
; response to DNSKEY priming query
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR NOERROR
SECTION QUESTION
example.test. IN DNSKEY
SECTION ANSWER
example.test. 3600 IN DNSKEY 257 3 8 AwEAAdug/L739i0mgN2nuK/bhxu3wFn5Ud9nK2+XUmZQlPUEZUC5YZvm1rfMmEWTGBn87fFxEu/kjFZHJ55JLzqsbbpVHLbmKCTT2gYR2FV2WDKROGKuYbVkJIXdKAjJ0ONuK507NinYvlWXIoxHn22KAWOd9wKgSTNHBlmGkX+ts3hh ;{id = 55567 (ksk), size = 1024b}
example.test. 3600 IN RRSIG DNSKEY 8 2 3600 20201116135527 20201019135527 55567 example.test. IbWMC6quOuZFNPAVxQLqCJ9nLhindBo826rnLcg5yMgs9dGUSPOCXAfHTmbgJAUNs9HTFfrJWNvasnETs0UOpmEuifGwWdH1OlME7Gny4RL2QmITUFeMW81Jz1tiVQxFXl6yxT0jxOxvz+bqMHlrz+8IeWQXcO+GZTPu8ueq30g=
ENTRY_END
; response to query of interest
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
valid.example.test. AAAA
SECTION ANSWER
SECTION AUTHORITY
example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8=
valid.example.test. 3600 IN NSEC valid2.example.test. A RRSIG NSEC
valid.example.test. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 55567 example.test. GgwpBUFe6s1OLhunIQt5IXPMc51bScvWApWC7j0GbqL3FvtDyHDW4+vBxSh4lxX+262wGkw4OksRXIq0jNm313s8RUKmfszKeNfOr7KwubNeTZnU8dhl7RwIbBAYzqv2KPT7fPX7Vi3sKYDbJrU+KJUBohueJdGf4Y6Ixcb6sqY=
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
valid.example.test. A
SECTION ANSWER
valid.example.test. 3600 IN A 192.0.2.1
valid.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. hZx175Bx+TmOZjv021Y5Os4254guBqMWLk9A1ixCM0B7v9s9WxMBidDvjiWO6dwjkvC4v8dfcoCWvoFfgwBNUFQQV9xDrqB06Oo4qyMftpyQrV/FsHrHQ7OlxaX/P5vhuPtQvLMj/J67P7WWIewqZV9SKP4I1vFX+c5L/uO/8Ts=
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
invaaaa.example.test. AAAA
SECTION ANSWER
SECTION AUTHORITY
example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8=
invaaaa.example.test. 3600 IN NSEC invaaaa2.example.test. A RRSIG NSEC
; signature on the NSEC is invalidated: (wrong keytag)
; correct is:
; invaaaa.example.test. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 55567 example.test. Xsc0PJbV3dYo6EweR5e/o4ROVNpJkWNdrDXNrU9vwwCOFrfdvkoOLCnmejpHM5V+v8yNt43l4gcurut8GU4hzBD2gdx1SdMV6k3Uv8UYRrQhidIwEynQRqaDhdAt7lCqTvKAn2iTHbHU9Fss0ezL01aYaCVTyPTeGZP6CgSzGU0=
invaaaa.example.test. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 11567 example.test. Xsc0PJbV3dYo6EweR5e/o4ROVNpJkWNdrDXNrU9vwwCOFrfdvkoOLCnmejpHM5V+v8yNt43l4gcurut8GU4hzBD2gdx1SdMV6k3Uv8UYRrQhidIwEynQRqaDhdAt7lCqTvKAn2iTHbHU9Fss0ezL01aYaCVTyPTeGZP6CgSzGU0=
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
invaaaa.example.test. A
SECTION ANSWER
invaaaa.example.test. 3600 IN A 192.0.2.2
invaaaa.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. vNWrVbz9L8eaBXIulg+zswK02cjy+stKxHhedDclVqduavv7+6ZV7idFY+zlHZU6KxrfjGB8/UFMkdpOlcgrAy0D9YQAVjm2zCKzx6f3GSenlNWMlhwgeAJb+ozP/cmrZ+ctqF7id9q4E5P08yTPHEqEcdXDMG0iTEuSvel/p7I=
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
inva.example.test. AAAA
SECTION ANSWER
SECTION AUTHORITY
example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8=
inva.example.test. 3600 IN NSEC inva2.example.test. A RRSIG NSEC
inva.example.test. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 55567 example.test. 1Rltlowol5kpdPYUuOt4GQJJjUr7UvJQGuhJ58Tuwxsd1rt/M+HAM61lzE2z6xcT2ezw5ja60lzNQsMiFYP0JCwcT6874X4er4+544O6fwFVcZPEh9jTOEH5TsjiYT1OltIsPf8LSUchRAo8LMSbHBpfFHe6JPZiyvBs4N60/hM=
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
inva.example.test. A
SECTION ANSWER
inva.example.test. 3600 IN A 192.0.2.3
; signature is invalidated: (wrong keytag)
; correct is:
;inva.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. CrBrpUkdpdDv/rg6u5I/Ja5FOHUvTl8g0wxymHfrm+qQMCJ86CHdsON6g8JyCE4HsZ6ZXEc9/s5Qxnse/awlEKGjvM6SYRbXhhbjJDDY2MoitwYXLAocq2gM0tqZeKMnYZzMRiRdhaL4XvwubHAtD/gU/RiF2/uequViwlaFo8w=
inva.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 11567 example.test. CrBrpUkdpdDv/rg6u5I/Ja5FOHUvTl8g0wxymHfrm+qQMCJ86CHdsON6g8JyCE4HsZ6ZXEc9/s5Qxnse/awlEKGjvM6SYRbXhhbjJDDY2MoitwYXLAocq2gM0tqZeKMnYZzMRiRdhaL4XvwubHAtD/gU/RiF2/uequViwlaFo8w=
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
invboth.example.test. AAAA
SECTION ANSWER
SECTION AUTHORITY
example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8=
invboth.example.test. 3600 IN NSEC invboth2.example.test. A RRSIG NSEC
; signature on the NSEC is invalidated: (wrong keytag)
; correct is:
;invboth.example.test. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 55567 example.test. w7oGj0Tb3o30iIknVEVToQ39DCQVUx9yV2mm1SkR4MBc4zj3eZRRoL40lHPrIndFRsrBxm7+pxdy29Nw+diWdQj5NnsEsPDSPRvkb04xaah22/zd7lmjLLx3qtFCZpEVbsLUGQAy546NmVlv65/TghlTFA3e6dOFtiwQhdWskyg=
invboth.example.test. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 11567 example.test. w7oGj0Tb3o30iIknVEVToQ39DCQVUx9yV2mm1SkR4MBc4zj3eZRRoL40lHPrIndFRsrBxm7+pxdy29Nw+diWdQj5NnsEsPDSPRvkb04xaah22/zd7lmjLLx3qtFCZpEVbsLUGQAy546NmVlv65/TghlTFA3e6dOFtiwQhdWskyg=
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
invboth.example.test. A
SECTION ANSWER
invboth.example.test. 3600 IN A 192.0.2.4
; signature is invalidated: (wrong keytag)
; correct is:
;invboth.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. Dt7oT9T55C83sIo8P21SzpB9WWBvEllrj0QXzCkO5Jb7XFtt7YwNnBmRMwbLbRol3YUVCkGaY/mSrATuP5xiq0sPulr8togzKWD0QOAJrxOnuk40ffkp1zrwiqkH7tRy5S9wQUx+vUt7RT1PcEqWufI4XRPmbhFuPXIMM1i8Te8=
invboth.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 11567 example.test. Dt7oT9T55C83sIo8P21SzpB9WWBvEllrj0QXzCkO5Jb7XFtt7YwNnBmRMwbLbRol3YUVCkGaY/mSrATuP5xiq0sPulr8togzKWD0QOAJrxOnuk40ffkp1zrwiqkH7tRy5S9wQUx+vUt7RT1PcEqWufI4XRPmbhFuPXIMM1i8Te8=
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
hasaaaa.example.test. AAAA
SECTION ANSWER
hasaaaa.example.test. 3600 IN AAAA 2001::db8:5
hasaaaa.example.test. 3600 IN RRSIG AAAA 8 3 3600 20201116135527 20201019135527 55567 example.test. eat6Eh6Sqy9OE+BUIdUzzKuToqFn7K62oLbNUcj+JG/mlv85xeM3fKGbbwyR1mDbt/mghLfcchxWDoXtWJtYbItFVpRn4UyIuqK2w4igUb/Ic7iKoBJ4ZWlfYadE5MnAhVSQ094yAj3iUWydqQXVmTJ4UAJ3ouyzCJS8LojzZS8=
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
hasaaaa.example.test. A
SECTION ANSWER
hasaaaa.example.test. 3600 IN A 192.0.2.5
hasaaaa.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. Lh0DMv541AunEERFv3Zck1JE4fCC48V247y5+4O/ciblzc67VDjlCnp2BAXtjoYgWmvRqtxgPMzttALbHN2YxweX0Tq6/Ji0iyvLepC6a0+LjT45KPAmXYEigX/oxyUX7bxKXJ0k+Tm9FdnesDMGuoDuk7gVYi9Bdrst8DWULJc=
ENTRY_END
RANGE_END
STEP 1 QUERY
ENTRY_BEGIN
REPLY RD DO
SECTION QUESTION
valid.example.test. IN AAAA
ENTRY_END
STEP 2 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA AD DO NOERROR
SECTION QUESTION
valid.example.test. IN AAAA
SECTION ANSWER
valid.example.test. 0 IN AAAA 64:ff9b::c000:201
ENTRY_END
; from cache
STEP 10 QUERY
ENTRY_BEGIN
REPLY RD DO
SECTION QUESTION
valid.example.test. IN AAAA
ENTRY_END
STEP 11 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA AD DO NOERROR
SECTION QUESTION
valid.example.test. IN AAAA
SECTION ANSWER
valid.example.test. 0 IN AAAA 64:ff9b::c000:201
ENTRY_END
; with cd flag
STEP 20 QUERY
ENTRY_BEGIN
REPLY RD CD DO
SECTION QUESTION
valid.example.test. IN AAAA
ENTRY_END
STEP 21 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA AD CD DO NOERROR
SECTION QUESTION
valid.example.test. IN AAAA
SECTION ANSWER
SECTION AUTHORITY
example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8= ;{id = 55567}
valid.example.test. 3600 IN NSEC valid2.example.test. A RRSIG NSEC
valid.example.test. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 55567 example.test. GgwpBUFe6s1OLhunIQt5IXPMc51bScvWApWC7j0GbqL3FvtDyHDW4+vBxSh4lxX+262wGkw4OksRXIq0jNm313s8RUKmfszKeNfOr7KwubNeTZnU8dhl7RwIbBAYzqv2KPT7fPX7Vi3sKYDbJrU+KJUBohueJdGf4Y6Ixcb6sqY= ;{id = 55567}
ENTRY_END
; invaaaa.example.test.
STEP 30 QUERY
ENTRY_BEGIN
REPLY RD DO
SECTION QUESTION
invaaaa.example.test. IN AAAA
ENTRY_END
STEP 31 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA DO SERVFAIL
SECTION QUESTION
invaaaa.example.test. IN AAAA
SECTION ANSWER
; It is not: invaaaa.example.test. 3600 IN AAAA 64:ff9b::c000:202
ENTRY_END
; from cache
STEP 40 QUERY
ENTRY_BEGIN
REPLY RD DO
SECTION QUESTION
invaaaa.example.test. IN AAAA
ENTRY_END
STEP 41 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA DO SERVFAIL
SECTION QUESTION
invaaaa.example.test. IN AAAA
SECTION ANSWER
ENTRY_END
; with cd flag
STEP 50 QUERY
ENTRY_BEGIN
REPLY RD CD DO
SECTION QUESTION
invaaaa.example.test. IN AAAA
ENTRY_END
STEP 51 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA CD DO NOERROR
SECTION QUESTION
invaaaa.example.test. IN AAAA
SECTION ANSWER
SECTION AUTHORITY
example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8= ;{id = 55567}
invaaaa.example.test. 60 IN NSEC invaaaa2.example.test. A RRSIG NSEC
invaaaa.example.test. 60 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 11567 example.test. Xsc0PJbV3dYo6EweR5e/o4ROVNpJkWNdrDXNrU9vwwCOFrfdvkoOLCnmejpHM5V+v8yNt43l4gcurut8GU4hzBD2gdx1SdMV6k3Uv8UYRrQhidIwEynQRqaDhdAt7lCqTvKAn2iTHbHU9Fss0ezL01aYaCVTyPTeGZP6CgSzGU0= ;{id = 11567}
ENTRY_END
; inva.example.test.
STEP 60 QUERY
ENTRY_BEGIN
REPLY RD DO
SECTION QUESTION
inva.example.test. IN AAAA
ENTRY_END
STEP 61 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA DO SERVFAIL
SECTION QUESTION
inva.example.test. IN AAAA
SECTION ANSWER
ENTRY_END
; from cache
STEP 70 QUERY
ENTRY_BEGIN
REPLY RD DO
SECTION QUESTION
inva.example.test. IN AAAA
ENTRY_END
STEP 71 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA DO SERVFAIL
SECTION QUESTION
inva.example.test. IN AAAA
SECTION ANSWER
ENTRY_END
; with cd flag
STEP 80 QUERY
ENTRY_BEGIN
REPLY RD CD DO
SECTION QUESTION
inva.example.test. IN AAAA
ENTRY_END
STEP 81 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA AD CD DO NOERROR
SECTION QUESTION
inva.example.test. IN AAAA
SECTION ANSWER
SECTION AUTHORITY
example.test. 0 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
example.test. 0 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8= ;{id = 55567}
inva.example.test. 0 IN NSEC inva2.example.test. A RRSIG NSEC
inva.example.test. 0 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 55567 example.test. 1Rltlowol5kpdPYUuOt4GQJJjUr7UvJQGuhJ58Tuwxsd1rt/M+HAM61lzE2z6xcT2ezw5ja60lzNQsMiFYP0JCwcT6874X4er4+544O6fwFVcZPEh9jTOEH5TsjiYT1OltIsPf8LSUchRAo8LMSbHBpfFHe6JPZiyvBs4N60/hM= ;{id = 55567}
ENTRY_END
; invboth.example.test.
STEP 90 QUERY
ENTRY_BEGIN
REPLY RD DO
SECTION QUESTION
invboth.example.test. IN AAAA
ENTRY_END
STEP 91 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA DO SERVFAIL
SECTION QUESTION
invboth.example.test. IN AAAA
SECTION ANSWER
ENTRY_END
; from cache
STEP 100 QUERY
ENTRY_BEGIN
REPLY RD DO
SECTION QUESTION
invboth.example.test. IN AAAA
ENTRY_END
STEP 101 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA DO SERVFAIL
SECTION QUESTION
invboth.example.test. IN AAAA
SECTION ANSWER
ENTRY_END
; with cd flag
STEP 110 QUERY
ENTRY_BEGIN
REPLY RD CD DO
SECTION QUESTION
invboth.example.test. IN AAAA
ENTRY_END
STEP 111 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA CD DO NOERROR
SECTION QUESTION
invboth.example.test. IN AAAA
SECTION ANSWER
SECTION AUTHORITY
example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8= ;{id = 55567}
invboth.example.test. 60 IN NSEC invboth2.example.test. A RRSIG NSEC
invboth.example.test. 60 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 11567 example.test. w7oGj0Tb3o30iIknVEVToQ39DCQVUx9yV2mm1SkR4MBc4zj3eZRRoL40lHPrIndFRsrBxm7+pxdy29Nw+diWdQj5NnsEsPDSPRvkb04xaah22/zd7lmjLLx3qtFCZpEVbsLUGQAy546NmVlv65/TghlTFA3e6dOFtiwQhdWskyg= ;{id = 11567}
ENTRY_END
; hasaaaa.example.test.
STEP 120 QUERY
ENTRY_BEGIN
REPLY RD DO
SECTION QUESTION
hasaaaa.example.test. IN AAAA
ENTRY_END
STEP 121 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA AD DO NOERROR
SECTION QUESTION
hasaaaa.example.test. IN AAAA
SECTION ANSWER
hasaaaa.example.test. 0 IN AAAA 2001::db8:5
hasaaaa.example.test. 0 IN RRSIG AAAA 8 3 3600 20201116135527 20201019135527 55567 example.test. eat6Eh6Sqy9OE+BUIdUzzKuToqFn7K62oLbNUcj+JG/mlv85xeM3fKGbbwyR1mDbt/mghLfcchxWDoXtWJtYbItFVpRn4UyIuqK2w4igUb/Ic7iKoBJ4ZWlfYadE5MnAhVSQ094yAj3iUWydqQXVmTJ4UAJ3ouyzCJS8LojzZS8= ;{id = 55567}
ENTRY_END
; from cache
STEP 130 QUERY
ENTRY_BEGIN
REPLY RD DO
SECTION QUESTION
hasaaaa.example.test. IN AAAA
ENTRY_END
STEP 131 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA AD DO NOERROR
SECTION QUESTION
hasaaaa.example.test. IN AAAA
SECTION ANSWER
hasaaaa.example.test. 0 IN AAAA 2001::db8:5
hasaaaa.example.test. 0 IN RRSIG AAAA 8 3 3600 20201116135527 20201019135527 55567 example.test. eat6Eh6Sqy9OE+BUIdUzzKuToqFn7K62oLbNUcj+JG/mlv85xeM3fKGbbwyR1mDbt/mghLfcchxWDoXtWJtYbItFVpRn4UyIuqK2w4igUb/Ic7iKoBJ4ZWlfYadE5MnAhVSQ094yAj3iUWydqQXVmTJ4UAJ3ouyzCJS8LojzZS8= ;{id = 55567}
ENTRY_END
; with cd flag
STEP 140 QUERY
ENTRY_BEGIN
REPLY RD CD DO
SECTION QUESTION
hasaaaa.example.test. IN AAAA
ENTRY_END
STEP 141 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA AD CD DO NOERROR
SECTION QUESTION
hasaaaa.example.test. IN AAAA
SECTION ANSWER
hasaaaa.example.test. 0 IN AAAA 2001::db8:5
hasaaaa.example.test. 0 IN RRSIG AAAA 8 3 3600 20201116135527 20201019135527 55567 example.test. eat6Eh6Sqy9OE+BUIdUzzKuToqFn7K62oLbNUcj+JG/mlv85xeM3fKGbbwyR1mDbt/mghLfcchxWDoXtWJtYbItFVpRn4UyIuqK2w4igUb/Ic7iKoBJ4ZWlfYadE5MnAhVSQ094yAj3iUWydqQXVmTJ4UAJ3ouyzCJS8LojzZS8= ;{id = 55567}
ENTRY_END
SCENARIO_END
+209
View File
@@ -0,0 +1,209 @@
; config options go here.
server:
target-fetch-policy: "0 0 0 0 0"
qname-minimisation: no
minimal-responses: yes
module-config: "dns64 iterator"
dns64-prefix: 64:ff9b::0/96
forward-zone: name: "." forward-addr: 216.0.0.1
forward-no-cache: yes
CONFIG_END
SCENARIO_BEGIN Test DNS64 with forward zone with forward-no-cache set.
RANGE_BEGIN 0 15
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR RD RA NOERROR
SECTION QUESTION
www.example.com. IN A
SECTION ANSWER
www.example.com. IN A 10.20.30.40
ENTRY_END
RANGE_END
RANGE_BEGIN 15 25
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR RD RA NOERROR
SECTION QUESTION
www.example.com. IN A
SECTION ANSWER
www.example.com. IN A 10.20.30.41
ENTRY_END
RANGE_END
RANGE_BEGIN 25 35
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR RD RA NOERROR
SECTION QUESTION
www2.example.com. IN A
SECTION ANSWER
www2.example.com. IN A 10.20.30.42
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR RD RA NOERROR
SECTION QUESTION
www2.example.com. IN AAAA
SECTION ANSWER
SECTION AUTHORITY
example.com. 300 IN SOA ns.example.com. host.example.com. 5 86400 7200 604800 300
ENTRY_END
RANGE_END
RANGE_BEGIN 35 45
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR RD RA NOERROR
SECTION QUESTION
www2.example.com. IN A
SECTION ANSWER
www2.example.com. IN A 10.20.30.43
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR RD RA NOERROR
SECTION QUESTION
www2.example.com. IN AAAA
SECTION ANSWER
SECTION AUTHORITY
example.com. 300 IN SOA ns.example.com. host.example.com. 5 86400 7200 604800 300
ENTRY_END
RANGE_END
RANGE_BEGIN 45 55
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR RD RA NOERROR
SECTION QUESTION
www3.example.com. IN AAAA
SECTION ANSWER
www3.example.com. 3600 IN AAAA 2001:db8::5
ENTRY_END
RANGE_END
RANGE_BEGIN 55 65
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR RD RA NOERROR
SECTION QUESTION
www3.example.com. IN AAAA
SECTION ANSWER
www3.example.com. 3600 IN AAAA 2001:db8::6
ENTRY_END
RANGE_END
; query for A record
STEP 10 QUERY
ENTRY_BEGIN
REPLY RD
SECTION QUESTION
www.example.com. IN A
ENTRY_END
STEP 11 CHECK_ANSWER
ENTRY_BEGIN
REPLY QR RD RA
MATCH opcode qname qtype all
SECTION QUESTION
www.example.com. IN A
SECTION ANSWER
www.example.com. IN A 10.20.30.40
ENTRY_END
; the upstream has changed, ask for A record again
STEP 20 QUERY
ENTRY_BEGIN
REPLY RD
SECTION QUESTION
www.example.com. IN A
ENTRY_END
STEP 21 CHECK_ANSWER
ENTRY_BEGIN
REPLY QR RD RA
MATCH opcode qname qtype all
SECTION QUESTION
www.example.com. IN A
SECTION ANSWER
www.example.com. IN A 10.20.30.41
ENTRY_END
; query for synthesized AAAA record
STEP 30 QUERY
ENTRY_BEGIN
REPLY RD
SECTION QUESTION
www2.example.com. IN AAAA
ENTRY_END
STEP 31 CHECK_ANSWER
ENTRY_BEGIN
REPLY QR RD RA
MATCH opcode qname qtype all
SECTION QUESTION
www2.example.com. IN AAAA
SECTION ANSWER
www2.example.com. 3600 IN AAAA 64:ff9b::a14:1e2a
ENTRY_END
; the upstream has changed, query for synthesized AAAA again.
STEP 40 QUERY
ENTRY_BEGIN
REPLY RD
SECTION QUESTION
www2.example.com. IN AAAA
ENTRY_END
STEP 41 CHECK_ANSWER
ENTRY_BEGIN
REPLY QR RD RA
MATCH opcode qname qtype all
SECTION QUESTION
www2.example.com. IN AAAA
SECTION ANSWER
www2.example.com. 3600 IN AAAA 64:ff9b::a14:1e2b
ENTRY_END
; query for AAAA record, that is present, no synthesis.
STEP 50 QUERY
ENTRY_BEGIN
REPLY RD
SECTION QUESTION
www3.example.com. IN AAAA
ENTRY_END
STEP 51 CHECK_ANSWER
ENTRY_BEGIN
REPLY QR RD RA
MATCH opcode qname qtype all
SECTION QUESTION
www3.example.com. IN AAAA
SECTION ANSWER
www3.example.com. 3600 IN AAAA 2001:db8::5
ENTRY_END
; the upstream has changed, query for AAAA record again (no synthesis).
STEP 60 QUERY
ENTRY_BEGIN
REPLY RD
SECTION QUESTION
www3.example.com. IN AAAA
ENTRY_END
STEP 61 CHECK_ANSWER
ENTRY_BEGIN
REPLY QR RD RA
MATCH opcode qname qtype all
SECTION QUESTION
www3.example.com. IN AAAA
SECTION ANSWER
www3.example.com. 3600 IN AAAA 2001:db8::6
ENTRY_END
SCENARIO_END
+288
View File
@@ -0,0 +1,288 @@
; config options
server:
target-fetch-policy: "0 0 0 0 0"
qname-minimisation: no
minimal-responses: yes
log-servfail: yes
module-config: "dns64 respip iterator"
; or
; module-config: "respip dns64 iterator"
dns64-prefix: 64:ff9b::/96
; possibly as well:
; response-ip: 192.0.2.66/32 always_nxdomain
rpz:
name: "rpz.example.com."
rpz-log: yes
rpz-log-name: "rpz.example.com"
zonefile:
TEMPFILE_NAME rpz.example.com
TEMPFILE_CONTENTS rpz.example.com
$ORIGIN example.com.
rpz 3600 IN SOA ns1.rpz.gotham.com. hostmaster.rpz.example.com. (
1379078166 28800 7200 604800 7200 )
3600 IN NS ns1.rpz.example.com.
3600 IN NS ns2.rpz.example.com.
$ORIGIN rpz.example.com.
; block 192.0.2.66/32
32.66.2.0.192.rpz-ip IN CNAME .
TEMPFILE_END
stub-zone:
name: "."
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
CONFIG_END
SCENARIO_BEGIN Test RPZ filtered query with DNS64 enabled.
; K.ROOT-SERVERS.NET.
RANGE_BEGIN 0 100
ADDRESS 193.0.14.129
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR NOERROR
SECTION QUESTION
. IN NS
SECTION ANSWER
. IN NS K.ROOT-SERVERS.NET.
SECTION ADDITIONAL
K.ROOT-SERVERS.NET. IN A 193.0.14.129
ENTRY_END
ENTRY_BEGIN
MATCH opcode subdomain
ADJUST copy_id copy_query
REPLY QR NOERROR
SECTION QUESTION
tld. IN NS
SECTION AUTHORITY
tld. IN NS ns.tld.
SECTION ADDITIONAL
ns.tld. IN A 1.2.3.5
ENTRY_END
RANGE_END
; ns.tld
RANGE_BEGIN 0 100
ADDRESS 1.2.3.5
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
tld. IN NS
SECTION ANSWER
tld. IN NS ns.tld
SECTION ADDITIONAL
ns.tld. IN A 1.2.3.5
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
ns.tld. IN A
SECTION ANSWER
ns.tld. IN A 1.2.3.5
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
ns.tld. IN AAAA
SECTION AUTHORITY
tld. 3600 IN SOA ns.tld. host.tld. 20201 3600 1800 604800 3600
ENTRY_END
ENTRY_BEGIN
MATCH opcode subdomain
ADJUST copy_id copy_query
REPLY QR NOERROR
SECTION QUESTION
example.tld. IN NS
SECTION AUTHORITY
example.tld. 5 IN NS ns.example.tld.
SECTION ADDITIONAL
ns.example.tld. 5 IN A 1.2.3.4
ENTRY_END
RANGE_END
; ns.example.tld.
RANGE_BEGIN 0 100
ADDRESS 1.2.3.4
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR NOERROR
SECTION QUESTION
example.tld. IN NS
SECTION ANSWER
example.tld. 86400 IN NS ns.example.tld.
SECTION ADDITIONAL
ns.example.tld. 86400 IN A 1.2.3.4
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
ns.example.tld. IN A
SECTION ANSWER
ns.example.tld. IN A 1.2.3.4
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
ns.example.tld. IN AAAA
SECTION AUTHORITY
example.tld. 3600 IN SOA ns.example.tld. host.example.tld. 20301 3600 1800 604800 3600
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
bad.example.tld. IN A
SECTION ANSWER
bad.example.tld. IN A 192.0.2.66
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
bad.example.tld. IN AAAA
SECTION AUTHORITY
example.tld. 3600 IN SOA ns.example.tld. host.example.tld. 20301 3600 1800 604800 3600
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
synth.example.tld. IN A
SECTION ANSWER
synth.example.tld. IN A 203.0.113.5
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
synth.example.tld. IN AAAA
SECTION AUTHORITY
example.tld. 3600 IN SOA ns.example.tld. host.example.tld. 20301 3600 1800 604800 3600
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
clean.example.tld. IN A
SECTION ANSWER
clean.example.tld. IN A 203.0.113.5
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
clean.example.tld. IN AAAA
SECTION AUTHORITY
example.tld. 3600 IN SOA ns.example.tld. host.example.tld. 20301 3600 1800 604800 3600
ENTRY_END
RANGE_END
STEP 1 QUERY
ENTRY_BEGIN
REPLY RD NOERROR
SECTION QUESTION
bad.example.tld. IN A
ENTRY_END
; RPZ works on A query
STEP 2 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA NXDOMAIN
SECTION QUESTION
bad.example.tld. IN A
SECTION ANSWER
ENTRY_END
STEP 10 QUERY
ENTRY_BEGIN
REPLY RD NOERROR
SECTION QUESTION
synth.example.tld. IN AAAA
ENTRY_END
; DNS64 synthesizes an unblocked address.
STEP 11 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA NOERROR
SECTION QUESTION
synth.example.tld. IN AAAA
SECTION ANSWER
synth.example.tld. 3600 IN AAAA 64:ff9b::cb00:7105
ENTRY_END
STEP 20 QUERY
ENTRY_BEGIN
REPLY RD NOERROR
SECTION QUESTION
bad.example.tld. IN AAAA
ENTRY_END
; synthesized AAAA for A that is blocked by RPZ.
STEP 21 CHECK_ANSWER
;ENTRY_BEGIN
;MATCH all
;REPLY QR RD RA NXDOMAIN
;SECTION QUESTION
;bad.example.tld. IN AAAA
;SECTION ANSWER
;ENTRY_END
ENTRY_BEGIN
MATCH all
REPLY QR RD RA NOERROR
SECTION QUESTION
bad.example.tld. IN AAAA
SECTION AUTHORITY
example.tld. 3600 IN SOA ns.example.tld. host.example.tld. 20301 3600 1800 604800 3600
ENTRY_END
STEP 30 QUERY
ENTRY_BEGIN
REPLY RD NOERROR
SECTION QUESTION
bad.example.tld. IN AAAA
ENTRY_END
; same from cache.
STEP 31 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA NOERROR
SECTION QUESTION
bad.example.tld. IN AAAA
SECTION AUTHORITY
example.tld. 3600 IN SOA ns.example.tld. host.example.tld. 20301 3600 1800 604800 3600
ENTRY_END
SCENARIO_END
+1202
View File
File diff suppressed because it is too large Load Diff
+221
View File
@@ -0,0 +1,221 @@
; Test DNS Error Reporting.
server:
module-config: "validator iterator"
trust-anchor-signaling: no
target-fetch-policy: "0 0 0 0 0"
verbosity: 4
qname-minimisation: no
minimal-responses: no
rrset-roundrobin: no
trust-anchor: "test. DS 1444 8 2 8a87d067fd09a5965244fe2e317dd26d182c468e0a7f26ecc4c7b479bf89db9b"
val-override-date: "20201020135527"
ede: no # It is not needed for dns-error-reporting; only for clients to receive EDEs
dns-error-reporting: yes
do-ip6: no
local-zone: test. nodefault
log-servfail: yes
stub-zone:
name: test
stub-addr: 1.2.3.5
stub-zone:
name: an.agent
stub-addr: 0.0.0.2
CONFIG_END
SCENARIO_BEGIN Test DNS Error Reporting with agent domain len malformed.
; ns.test
RANGE_BEGIN 0 100
ADDRESS 1.2.3.5
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
test. IN NS
SECTION ANSWER
test. IN NS ns.test
test. 3600 IN RRSIG NS 8 1 3600 20201116135527 20201019135527 1444 test. RGCxIO32TbbLTk6xZmTr+fjYPH50hntBxeOQ2DIj2pDsmjALcHYtVkOfpfk2EhOhHZd+9PLuoJPbJh6a9NqLSFeBvr0XZoCZoQ2g0tCHUNHcH5EVjA2TuYBQem6DVYnPLJ3914aRx0uA1j42b8dC2xsam/XkOo7U+dLbUW2Os1s=
SECTION ADDITIONAL
ns.test. IN A 1.2.3.5
ns.test. 3600 IN RRSIG A 8 2 3600 20201116135527 20201019135527 1444 test. GskCc4/k6GjH9V9Jz2V5L2XLiizbOeWkB0feSbf+aN859S3vxVvtuqkvIgwY4LafUO1QAn/pUcv9zA7rcFO++rlg+8t6gvZTo9p3v0bfeIv2uJDsfSBD5jDh0WXlxjekfnrKrQp7zE+GiA93tWwKUWKPvxXDgP+n886e6WcbHJw=
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
ns.test. IN A
SECTION ANSWER
ns.test. IN A 1.2.3.5
ns.test. 3600 IN RRSIG A 8 2 3600 20201116135527 20201019135527 1444 test. GskCc4/k6GjH9V9Jz2V5L2XLiizbOeWkB0feSbf+aN859S3vxVvtuqkvIgwY4LafUO1QAn/pUcv9zA7rcFO++rlg+8t6gvZTo9p3v0bfeIv2uJDsfSBD5jDh0WXlxjekfnrKrQp7zE+GiA93tWwKUWKPvxXDgP+n886e6WcbHJw=
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
ns.test. IN AAAA
SECTION AUTHORITY
test. 3600 IN SOA ns.test. host.test. 20201 3600 1800 604800 3600
test. 3600 IN RRSIG SOA 8 1 3600 20201116135527 20201019135527 1444 test. IZJIDmEgf0W7A5G7hvvZ2hUqJ9Trbv1/i7ySapDmPbYV9lVCmHHobySxO01yDhI2/Pvpsvxqrm1Tiv3BxH8uzZ4keKgiQjBsSy4htAsFct9I4E7ly2glPj/Fm3oun3PsjJDv5QYhx0KS7w4IQKU7Nc9pfJc92uoUI5bdoC1pRGw=
ns.test. 3600 IN NSEC nz.test. A RRSIG
ns.test. 3600 IN RRSIG NSEC 8 2 3600 20201116135527 20201019135527 1444 test. PElArVB3KPg8KHAP7lzcNbhFuXNxTsHNTn1dZVncB5qmWRdIaeKpaXDjpH0JSXMaelGFS+/QhuQ6Hmw9+4VyZFRqMzGhw4agUR/2bxABHcDIG4ZpUwyeSP61ATTfHUkQVxaH2wjCWI/tfmesdP2xVE4GXyUvCIBxU914MkZbULU=
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
test. IN DNSKEY
SECTION ANSWER
test. 3600 IN DNSKEY 257 3 8 AwEAAbd9WqjzE2Pynz21OG5doSf9hFzMr5dhzz2waZ3vTa+0o5r7AjTAqmA1yH/B3+aAMihUm5ucZSfVqo7+kOaRE8yFj9aivOmA1n1+JLevJq/oyvQyjxQN2Qb89LyaNUT5oKZIiL+uyyhNW3KDR3SSbQ/GBwQNDHVcZi+JDR3RC0r7 ;{id = 1444 (ksk), size = 1024b}
test. 3600 IN RRSIG DNSKEY 8 1 3600 20201116135527 20201019135527 1444 test. UmRMS4iG9NBBHZYOtpwFFcJgbEb5SfHSgHd9XRe/8pTWM31WSDayn5ViPOBMqI1T5TXg2amc13dDI574xIM2oKMus3b5cBW72jJLW13jprBtslO6P8BMWb4HNnvLrJtQjwf3ErRirtTxinLmywQtmyr1cdthyG3Gp4N7i90fHSc=
SECTION ADDITIONAL
ENTRY_END
ENTRY_BEGIN
MATCH opcode qname qtype
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
example.test. IN DS
SECTION ANSWER
example.test. 3600 IN DS 55567 8 2 a2d578906330a10a57d40462257b6ce038bad3f7bf4a45c46c46086e20a94b39
example.test. 3600 IN RRSIG DS 8 2 3600 20201116135527 20201019135527 1444 test. P7+FTYW2qHuJ4I1YbuvseEz5X1lOYAraGEHB3C5y0OOCQFmhmSiFRdquNi2NlpcS6FXLdsE0EU+Bo1+0atTG4EkMWXbpF21lrtbB51BdsnlX4Mzc/o375fvjiOMwmF6wPCUaOUN62jrVrhsE/hedaVyDphDToqL17ETohwgUO2I=
ENTRY_END
ENTRY_BEGIN
MATCH opcode subdomain
ADJUST copy_id copy_query
REPLY QR NOERROR
SECTION QUESTION
example.test. IN NS
SECTION AUTHORITY
example.test. IN NS ns.example.test.
example.test. 3600 IN DS 55567 8 2 a2d578906330a10a57d40462257b6ce038bad3f7bf4a45c46c46086e20a94b39
example.test. 3600 IN RRSIG DS 8 2 3600 20201116135527 20201019135527 1444 test. P7+FTYW2qHuJ4I1YbuvseEz5X1lOYAraGEHB3C5y0OOCQFmhmSiFRdquNi2NlpcS6FXLdsE0EU+Bo1+0atTG4EkMWXbpF21lrtbB51BdsnlX4Mzc/o375fvjiOMwmF6wPCUaOUN62jrVrhsE/hedaVyDphDToqL17ETohwgUO2I=
SECTION ADDITIONAL
ns.example.test. IN A 1.2.3.4
ENTRY_END
RANGE_END
; ns.example.test.
RANGE_BEGIN 0 100
ADDRESS 1.2.3.4
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR NOERROR
SECTION QUESTION
example.test. IN NS
SECTION ANSWER
example.test. IN NS ns.example.test.
example.test. 3600 IN RRSIG NS 8 2 3600 20201116135527 20201019135527 55567 example.test. l1JT0wMlK0YI7/CWHzexf/k0iafUhCgN+BdgjBXIRXmSQNf4HDTiAkbcWL2/15qtnp12nQy9JeiTdSQ3vtPoHAJX4C5uTWaze4ms+Wrrf+n92sLCjacP9x50uuicH3URT6cKb1QCAPwlvlWxIlZjAMYFScSns7+C441NMJT8aE4=
SECTION ADDITIONAL
ns.example.test. IN A 1.2.3.4
ns.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. 2PWaVaccZFQgfPKXNsdEGYUVaashCAj1ZhBo9XRt5eQKUFvZcauBjMnXIuxZFyWeootn1fZGw6GuPI5W48Y0FDx38H6adprkFgQikso2Y64jDdDMWznSo38Z/XqP+U0+kq4vmwonvmEMpm7hKnNEXvhqGKyGzyBwb+CZVJ2L8Eo=
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
ns.example.test. IN A
SECTION ANSWER
ns.example.test. IN A 1.2.3.4
ns.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. 2PWaVaccZFQgfPKXNsdEGYUVaashCAj1ZhBo9XRt5eQKUFvZcauBjMnXIuxZFyWeootn1fZGw6GuPI5W48Y0FDx38H6adprkFgQikso2Y64jDdDMWznSo38Z/XqP+U0+kq4vmwonvmEMpm7hKnNEXvhqGKyGzyBwb+CZVJ2L8Eo=
ENTRY_END
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
ns.example.test. IN AAAA
SECTION AUTHORITY
example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8=
ns.example.test. 3600 IN NSEC nz.example.test. A RRSIG
example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
ENTRY_END
; response to DNSKEY priming query
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR NOERROR
SECTION QUESTION
example.test. IN DNSKEY
SECTION ANSWER
example.test. 3600 IN DNSKEY 257 3 8 AwEAAdug/L739i0mgN2nuK/bhxu3wFn5Ud9nK2+XUmZQlPUEZUC5YZvm1rfMmEWTGBn87fFxEu/kjFZHJ55JLzqsbbpVHLbmKCTT2gYR2FV2WDKROGKuYbVkJIXdKAjJ0ONuK507NinYvlWXIoxHn22KAWOd9wKgSTNHBlmGkX+ts3hh ;{id = 55567 (ksk), size = 1024b}
example.test. 3600 IN RRSIG DNSKEY 8 2 3600 20201116135527 20201019135527 55567 example.test. IbWMC6quOuZFNPAVxQLqCJ9nLhindBo826rnLcg5yMgs9dGUSPOCXAfHTmbgJAUNs9HTFfrJWNvasnETs0UOpmEuifGwWdH1OlME7Gny4RL2QmITUFeMW81Jz1tiVQxFXl6yxT0jxOxvz+bqMHlrz+8IeWQXcO+GZTPu8ueq30g=
ENTRY_END
; response to query of interest
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
www.example.test. IN A
SECTION ANSWER
www.example.test. 3600 IN A 10.20.30.40
; valid signature
;www.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. OQEgDcpez8Bvdwd+hxA3v63FWJhutWkv9w+k+8RLcWv34WPhebsf7CBV74ggY2c+HafvYiuIFfhdF5CX28YQjxqWVzFgE6bEA6spPc6qdHiQaY/096/4SLCDcL+2EtOqcR/uZGj5uNhhaCJ9UjscBKfEZmHUOAMXKmjsvl0I/+I=
; invalid: expired signature
www.example.test. 3600 IN RRSIG A 8 3 3600 20200816135527 20200719135527 55567 example.test. DNM4PJALboBNDe5pJ2NScYqYYmmpq8E0NogjbDNithIcQ7HtzkssLIR46DiPb/B7QIhBRpfQ6sUwMb4l+NDhm82DxaecEwnAV6Y0zYK6dZ5jI7e8rDI2hkW/LO75qSZ8Y1I9pgX5uyeBCon42IVjc3vyYbRbFNv1xgJs5rk308U=
SECTION ADDITIONAL
HEX_EDNSDATA_BEGIN
; This dns error reporting option is malformed, with garbage at end.
00 12 ; opt-code (Report-Channel)
00 28 ; opt-len 10 + 30
02 61 6E 05 61 67 65 6E 74 00 ; an.agent.
ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ; 30 0xFF tail
ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
HEX_EDNSDATA_END
ENTRY_END
RANGE_END
; an.agent
RANGE_BEGIN 10 20
ADDRESS 0.0.0.2
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR NOERROR
SECTION QUESTION
_er.1.www.example.test.7._er.an.agent. IN TXT
SECTION ANSWER
_er.1.www.example.test.7._er.an.agent. IN TXT "OK"
ENTRY_END
RANGE_END
; Query again
STEP 10 QUERY
ENTRY_BEGIN
REPLY RD
SECTION QUESTION
www.example.test. IN A
ENTRY_END
; Check that validation failed
; (a DNS Error Report query should have been generated)
STEP 11 CHECK_ANSWER
ENTRY_BEGIN
MATCH all
REPLY QR RD RA SERVFAIL
SECTION QUESTION
www.example.test. IN A
ENTRY_END
; answer the reporting agent reply.
STEP 20 TRAFFIC
SCENARIO_END
+3
View File
@@ -0,0 +1,3 @@
example.com. IN SOA ns.example.com. hostmaster.example.com. 1 3600 900 86400 3600
example.com. IN NS ns.example.net.
www.example.com. IN A 1.2.3.4
@@ -0,0 +1,34 @@
server:
verbosity: 7
# num-threads: 1
interface: 127.0.0.1
port: @PORT@
use-syslog: no
directory: ""
pidfile: "unbound.pid"
chroot: ""
username: ""
do-not-query-localhost: no
use-caps-for-id: no
stub-zone:
name: "."
stub-addr: 127.0.0.1@@TOPORT@
remote-control:
control-enable: yes
control-interface: @CONTROL_PATH@/controlpipe.@CONTROL_PID@
control-use-cert: no
auth-zone:
name: "example.com"
for-upstream: yes
for-downstream: yes
allow-notify: notif.example.net
zonefile: "example.com.zone"
master: "127.0.0.1@@TOPORT@"
auth-zone:
name: "example2.com"
for-upstream: yes
for-downstream: yes
master: prim.example.net

Some files were not shown because too many files have changed in this diff Show More