mirror of
https://github.com/NLnetLabs/unbound.git
synced 2026-08-17 21:25:50 +02:00
Compare commits
194
Commits
branch-1.25.2
...
master
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8ee0bca833 | ||
|
|
c58e6add2b | ||
|
|
93a56205cf | ||
|
|
709f622658 | ||
|
|
307fc6f062 | ||
|
|
8b33c5d7ff | ||
|
|
36bd52afb9 | ||
|
|
b7d13ff12b | ||
|
|
bdfcfb861f | ||
|
|
b444deffd2 | ||
|
|
ff28b7e5cf | ||
|
|
79b84bbc91 | ||
|
|
cbfc3b0342 | ||
|
|
a45da353d3 | ||
|
|
c21e3ee929 | ||
|
|
8a38bed262 | ||
|
|
7cc7a43ff6 | ||
|
|
9bd8df0149 | ||
|
|
8f7411057f | ||
|
|
ca1fe4f82a | ||
|
|
e183c2c506 | ||
|
|
52b18fc6f5 | ||
|
|
e6d00725c2 | ||
|
|
e597711824 | ||
|
|
e1e646c6fc | ||
|
|
fc3b5b4f63 | ||
|
|
1e904a3ce5 | ||
|
|
79e100a7fb | ||
|
|
a65d3d7283 | ||
|
|
3b8766aa43 | ||
|
|
c8b3c89a39 | ||
|
|
a05d460e66 | ||
|
|
5eb362a6c0 | ||
|
|
0735cb28d1 | ||
|
|
737c28e836 | ||
|
|
1bab2dfafa | ||
|
|
22e2c5b6d1 | ||
|
|
914dbfea4e | ||
|
|
cf5e6e89a5 | ||
|
|
4941edf275 | ||
|
|
b08723ef97 | ||
|
|
c163fbc505 | ||
|
|
eed3f1ab38 | ||
|
|
63501f51bb | ||
|
|
1ae2570bda | ||
|
|
9ad825b267 | ||
|
|
3d5e6c0692 | ||
|
|
23e19ca6fc | ||
|
|
9f757aa9f3 | ||
|
|
1df6c170ff | ||
|
|
7a95bedc26 | ||
|
|
ae685bc33d | ||
|
|
91ac449bcd | ||
|
|
25b2543e5e | ||
|
|
7133e0d32a | ||
|
|
fac7584830 | ||
|
|
87f9258fb4 | ||
|
|
a2fe5356b5 | ||
|
|
ad9b12a863 | ||
|
|
61ca4111a1 | ||
|
|
71a971d70c | ||
|
|
ba4f8478e6 | ||
|
|
374a18cc5b | ||
|
|
f35561287a | ||
|
|
672b9659cf | ||
|
|
1978add0cd | ||
|
|
6cbcea3ac7 | ||
|
|
65e23d4b6f | ||
|
|
fbe41cdef9 | ||
|
|
01a95108b3 | ||
|
|
f75d11821f | ||
|
|
6aa5cfc903 | ||
|
|
f6931c794e | ||
|
|
4c5082ad05 | ||
|
|
5fb892a097 | ||
|
|
55e9532d16 | ||
|
|
fff6657cea | ||
|
|
45d1e75caf | ||
|
|
b806f16c8b | ||
|
|
8d3348c71b | ||
|
|
e2cc14681e | ||
|
|
5ae979bb6e | ||
|
|
8f2fbd66fc | ||
|
|
b5909d8d22 | ||
|
|
fa8e94f155 | ||
|
|
cb5683aeae | ||
|
|
c9715724ec | ||
|
|
78d9cfffd8 | ||
|
|
b47b1d048d | ||
|
|
740952fb82 | ||
|
|
5c550f4548 | ||
|
|
3d78cb8d9a | ||
|
|
1ab75c0043 | ||
|
|
bebc8d516b | ||
|
|
a7debe7ff6 | ||
|
|
215e3920ef | ||
|
|
aabf28aef5 | ||
|
|
aa09835c90 | ||
|
|
9b9e13b665 | ||
|
|
f72e11ef5b | ||
|
|
a45e54555d | ||
|
|
4693c00c9f | ||
|
|
8fe23e0297 | ||
|
|
8557788699 | ||
|
|
81a19ebeb3 | ||
|
|
299df5ec77 | ||
|
|
6f9b6db7be | ||
|
|
96f15b9160 | ||
|
|
159384c2a9 | ||
|
|
621fc91453 | ||
|
|
543c49f76c | ||
|
|
d0a760a587 | ||
|
|
f68cca4097 | ||
|
|
3129357874 | ||
|
|
fc09352df6 | ||
|
|
06da5d45a3 | ||
|
|
69524cadad | ||
|
|
98e95d80e6 | ||
|
|
2f8aa8a43a | ||
|
|
56e60e37ae | ||
|
|
8f5348ab47 | ||
|
|
c5d693b21c | ||
|
|
27e3ac55b9 | ||
|
|
7879218773 | ||
|
|
1354624ba4 | ||
|
|
153f8d5353 | ||
|
|
a1cecf7462 | ||
|
|
e2dac8a00a | ||
|
|
ecd41bef27 | ||
|
|
fd2131687a | ||
|
|
316b9ab4fc | ||
|
|
d45daaf313 | ||
|
|
db1c6d6557 | ||
|
|
e7a713a525 | ||
|
|
39e67508c9 | ||
|
|
3eab974ca2 | ||
|
|
b1d1dcb3b6 | ||
|
|
10cb62aca2 | ||
|
|
6da73aba38 | ||
|
|
1b1b9626ee | ||
|
|
8bc074043a | ||
|
|
04a6322aa4 | ||
|
|
5748f518d1 | ||
|
|
d05eff4d54 | ||
|
|
4544eaa4cc | ||
|
|
5d0770d0ad | ||
|
|
7f4beb846e | ||
|
|
8e8c04e1b9 | ||
|
|
bf0da2ed21 | ||
|
|
670ece06df | ||
|
|
9e41903be8 | ||
|
|
57f92cc97e | ||
|
|
c0741ccc68 | ||
|
|
fb2745024a | ||
|
|
0c15ddd133 | ||
|
|
b53504049c | ||
|
|
a5324e58eb | ||
|
|
963cd68535 | ||
|
|
047df73887 | ||
|
|
d2e1ea7d19 | ||
|
|
fbbe95ba5b | ||
|
|
758c649611 | ||
|
|
a23f95f620 | ||
|
|
5363570df0 | ||
|
|
368857a45b | ||
|
|
40b16d0565 | ||
|
|
08e901a1ac | ||
|
|
bc703c9129 | ||
|
|
9ce52de6c1 | ||
|
|
b3aa262477 | ||
|
|
25e112c674 | ||
|
|
0d2282d551 | ||
|
|
b5f21f4165 | ||
|
|
d357935f66 | ||
|
|
9d2e0f1c02 | ||
|
|
b46ff5c18e | ||
|
|
f597105800 | ||
|
|
3692517a41 | ||
|
|
a58bd6cb1e | ||
|
|
4bad944ae4 | ||
|
|
594182f109 | ||
|
|
53c261cb33 | ||
|
|
8703d9a5be | ||
|
|
aa9f1e68ff | ||
|
|
84a4f556b1 | ||
|
|
5b166dbf0a | ||
|
|
9e2233b821 | ||
|
|
13716dc8be | ||
|
|
8ada1bd88d | ||
|
|
9c80bb9fb0 | ||
|
|
33e2863862 | ||
|
|
027e23a11d | ||
|
|
62e8db1c6a | ||
|
|
581b2f31bc |
@@ -173,7 +173,7 @@ jobs:
|
||||
cross_platform_config: "--enable-debug --disable-flto --with-libevent --disable-static"
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v7
|
||||
with:
|
||||
submodules: false
|
||||
persist-credentials: false
|
||||
|
||||
@@ -12,7 +12,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v7
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: configure
|
||||
|
||||
@@ -10,7 +10,7 @@ Unbound is a validating, recursive, caching DNS resolver. It is designed to be
|
||||
fast and lean and incorporates modern features based on open standards. If you
|
||||
have any feedback, we would love to hear from you. Don’t hesitate to
|
||||
[create an issue on Github](https://github.com/NLnetLabs/unbound/issues/new)
|
||||
or post a message on the [Unbound mailing list](https://lists.nlnetlabs.nl/mailman/listinfo/unbound-users).
|
||||
or post a message on our [community forum](https://community.nlnetlabs.nl/).
|
||||
You can learn more about Unbound by reading our
|
||||
[documentation](https://unbound.docs.nlnetlabs.nl/).
|
||||
|
||||
|
||||
+17
-2
@@ -87,7 +87,7 @@
|
||||
# modified version of the Autoconf Macro, you may extend this special
|
||||
# exception to the GPL to apply to your modified version as well.
|
||||
|
||||
#serial 31
|
||||
#serial 32
|
||||
|
||||
AU_ALIAS([ACX_PTHREAD], [AX_PTHREAD])
|
||||
AC_DEFUN([AX_PTHREAD], [
|
||||
@@ -249,7 +249,22 @@ AS_IF([test "x$ax_pthread_clang" = "xyes"],
|
||||
# correctly enabled
|
||||
|
||||
case $host_os in
|
||||
darwin* | hpux* | linux* | osf* | solaris*)
|
||||
solaris*)
|
||||
# Solaris 11.4 introduced XPG7 support and did away with the need for
|
||||
# _REENTRANT.
|
||||
|
||||
AC_EGREP_CPP([AX_PTHREAD_SOLARIS__REENTRANT],
|
||||
[
|
||||
# undef _XOPEN_SOURCE
|
||||
# include <sys/feature_tests.h>
|
||||
# if _XOPEN_VERSION < 700
|
||||
AX_PTHREAD_SOLARIS__REENTRANT
|
||||
# endif
|
||||
],
|
||||
[ax_pthread_check_macro="_REENTRANT"],
|
||||
[ax_pthread_check_macro="--"])
|
||||
;;
|
||||
darwin* | hpux* | linux* | osf*)
|
||||
ax_pthread_check_macro="_REENTRANT"
|
||||
;;
|
||||
|
||||
|
||||
@@ -401,6 +401,12 @@ prep_data(struct module_qstate* qstate, struct sldns_buffer* buf)
|
||||
FLAGS_GET_RCODE(qstate->return_msg->rep->flags) !=
|
||||
LDNS_RCODE_YXDOMAIN)
|
||||
return 0;
|
||||
/* Do not persist data the validator has not yet seen, or has rejected.
|
||||
* Otherwise an expired blob could maybe reach clients via
|
||||
* serve-expired. */
|
||||
if(qstate->env->need_to_validate &&
|
||||
qstate->return_msg->rep->security == sec_status_bogus)
|
||||
return 0;
|
||||
/* We don't store the reply if its TTL is 0. This is probably coming
|
||||
* from upstream and it is not meant to be stored. */
|
||||
if(qstate->return_msg->rep->ttl == 0)
|
||||
@@ -863,6 +869,11 @@ cachedb_handle_query(struct module_qstate* qstate,
|
||||
return;
|
||||
}
|
||||
/* No 0TTL answers escaping from external cache. */
|
||||
if(qstate->return_msg->rep->ttl == 0) {
|
||||
qstate->return_msg = NULL;
|
||||
qstate->ext_state[id] = module_wait_module;
|
||||
return;
|
||||
}
|
||||
log_assert(qstate->return_msg->rep->ttl > 0);
|
||||
qstate->is_cachedb_answer = 1;
|
||||
/* we are done with the query */
|
||||
|
||||
+9
-382
@@ -20,398 +20,25 @@
|
||||
* http://man.openbsd.org/getentropy.2
|
||||
*/
|
||||
|
||||
#include <TargetConditionals.h>
|
||||
#include <sys/types.h>
|
||||
#include <sys/param.h>
|
||||
#include <sys/ioctl.h>
|
||||
#include <sys/resource.h>
|
||||
#include <sys/syscall.h>
|
||||
#include <sys/sysctl.h>
|
||||
#include <sys/statvfs.h>
|
||||
#include <sys/socket.h>
|
||||
#include <sys/mount.h>
|
||||
#include <sys/mman.h>
|
||||
#include <sys/stat.h>
|
||||
#include <sys/time.h>
|
||||
#include <stdlib.h>
|
||||
#include <stdint.h>
|
||||
#include <stdio.h>
|
||||
#include <termios.h>
|
||||
#include <fcntl.h>
|
||||
#include <signal.h>
|
||||
#include <string.h>
|
||||
/* Modified to use SecRandomCopyBytes. It is from macOS 10.7 (2011) and
|
||||
* iOS 2.0 (2008), and is the primary API for cryptographic random numbers. */
|
||||
#include <errno.h>
|
||||
#include <unistd.h>
|
||||
#include <time.h>
|
||||
#include <mach/mach_time.h>
|
||||
#include <mach/mach_host.h>
|
||||
#include <mach/host_info.h>
|
||||
#if TARGET_OS_OSX
|
||||
#include <sys/socketvar.h>
|
||||
#include <sys/vmmeter.h>
|
||||
#endif
|
||||
#include <netinet/in.h>
|
||||
#include <netinet/tcp.h>
|
||||
#if TARGET_OS_OSX
|
||||
#include <netinet/udp.h>
|
||||
#include <netinet/ip_var.h>
|
||||
#include <netinet/tcp_var.h>
|
||||
#include <netinet/udp_var.h>
|
||||
#endif
|
||||
#include <CommonCrypto/CommonDigest.h>
|
||||
#define SHA512_Update(a, b, c) (CC_SHA512_Update((a), (b), (c)))
|
||||
#define SHA512_Init(xxx) (CC_SHA512_Init((xxx)))
|
||||
#define SHA512_Final(xxx, yyy) (CC_SHA512_Final((xxx), (yyy)))
|
||||
#define SHA512_CTX CC_SHA512_CTX
|
||||
#define SHA512_DIGEST_LENGTH CC_SHA512_DIGEST_LENGTH
|
||||
|
||||
#define REPEAT 5
|
||||
#define min(a, b) (((a) < (b)) ? (a) : (b))
|
||||
|
||||
#define HX(a, b) \
|
||||
do { \
|
||||
if ((a)) \
|
||||
HD(errno); \
|
||||
else \
|
||||
HD(b); \
|
||||
} while (0)
|
||||
|
||||
#define HR(x, l) (SHA512_Update(&ctx, (char *)(x), (l)))
|
||||
#define HD(x) (SHA512_Update(&ctx, (char *)&(x), sizeof (x)))
|
||||
#define HF(x) (SHA512_Update(&ctx, (char *)&(x), sizeof (void*)))
|
||||
#include <Security/SecRandom.h>
|
||||
|
||||
int getentropy(void *buf, size_t len);
|
||||
|
||||
static int getentropy_urandom(void *buf, size_t len);
|
||||
static int getentropy_fallback(void *buf, size_t len);
|
||||
|
||||
int
|
||||
getentropy(void *buf, size_t len)
|
||||
{
|
||||
int ret = -1;
|
||||
|
||||
if (len > 256) {
|
||||
errno = EIO;
|
||||
return (-1);
|
||||
goto error;
|
||||
}
|
||||
|
||||
/*
|
||||
* Try to get entropy with /dev/urandom
|
||||
*
|
||||
* This can fail if the process is inside a chroot or if file
|
||||
* descriptors are exhausted.
|
||||
*/
|
||||
ret = getentropy_urandom(buf, len);
|
||||
if (ret != -1)
|
||||
return (ret);
|
||||
|
||||
/*
|
||||
* Entropy collection via /dev/urandom and sysctl have failed.
|
||||
*
|
||||
* No other API exists for collecting entropy, and we have
|
||||
* no failsafe way to get it on OSX that is not sensitive
|
||||
* to resource exhaustion.
|
||||
*
|
||||
* We have very few options:
|
||||
* - Even syslog_r is unsafe to call at this low level, so
|
||||
* there is no way to alert the user or program.
|
||||
* - Cannot call abort() because some systems have unsafe
|
||||
* corefiles.
|
||||
* - Could raise(SIGKILL) resulting in silent program termination.
|
||||
* - Return EIO, to hint that arc4random's stir function
|
||||
* should raise(SIGKILL)
|
||||
* - Do the best under the circumstances....
|
||||
*
|
||||
* This code path exists to bring light to the issue that OSX
|
||||
* does not provide a failsafe API for entropy collection.
|
||||
*
|
||||
* We hope this demonstrates that OSX should consider
|
||||
* providing a new failsafe API which works in a chroot or
|
||||
* when file descriptors are exhausted.
|
||||
*/
|
||||
#undef FAIL_INSTEAD_OF_TRYING_FALLBACK
|
||||
#ifdef FAIL_INSTEAD_OF_TRYING_FALLBACK
|
||||
raise(SIGKILL);
|
||||
#endif
|
||||
ret = getentropy_fallback(buf, len);
|
||||
if (ret != -1)
|
||||
return (ret);
|
||||
if (SecRandomCopyBytes(kSecRandomDefault, len, buf) == errSecSuccess) {
|
||||
return 0;
|
||||
}
|
||||
|
||||
error:
|
||||
errno = EIO;
|
||||
return (ret);
|
||||
}
|
||||
|
||||
static int
|
||||
getentropy_urandom(void *buf, size_t len)
|
||||
{
|
||||
struct stat st;
|
||||
size_t i;
|
||||
int fd, flags;
|
||||
int save_errno = errno;
|
||||
|
||||
start:
|
||||
|
||||
flags = O_RDONLY;
|
||||
#ifdef O_NOFOLLOW
|
||||
flags |= O_NOFOLLOW;
|
||||
#endif
|
||||
#ifdef O_CLOEXEC
|
||||
flags |= O_CLOEXEC;
|
||||
#endif
|
||||
fd = open("/dev/urandom", flags, 0);
|
||||
if (fd == -1) {
|
||||
if (errno == EINTR)
|
||||
goto start;
|
||||
goto nodevrandom;
|
||||
}
|
||||
#ifndef O_CLOEXEC
|
||||
fcntl(fd, F_SETFD, fcntl(fd, F_GETFD) | FD_CLOEXEC);
|
||||
#endif
|
||||
|
||||
/* Lightly verify that the device node looks sane */
|
||||
if (fstat(fd, &st) == -1 || !S_ISCHR(st.st_mode)) {
|
||||
close(fd);
|
||||
goto nodevrandom;
|
||||
}
|
||||
for (i = 0; i < len; ) {
|
||||
size_t wanted = len - i;
|
||||
ssize_t ret = read(fd, (char *)buf + i, wanted);
|
||||
|
||||
if (ret == -1) {
|
||||
if (errno == EAGAIN || errno == EINTR)
|
||||
continue;
|
||||
close(fd);
|
||||
goto nodevrandom;
|
||||
}
|
||||
i += ret;
|
||||
}
|
||||
close(fd);
|
||||
errno = save_errno;
|
||||
return (0); /* satisfied */
|
||||
nodevrandom:
|
||||
errno = EIO;
|
||||
return (-1);
|
||||
}
|
||||
|
||||
#if TARGET_OS_OSX
|
||||
static int tcpmib[] = { CTL_NET, AF_INET, IPPROTO_TCP, TCPCTL_STATS };
|
||||
static int udpmib[] = { CTL_NET, AF_INET, IPPROTO_UDP, UDPCTL_STATS };
|
||||
static int ipmib[] = { CTL_NET, AF_INET, IPPROTO_IP, IPCTL_STATS };
|
||||
#endif
|
||||
static int kmib[] = { CTL_KERN, KERN_USRSTACK };
|
||||
static int hwmib[] = { CTL_HW, HW_USERMEM };
|
||||
|
||||
static int
|
||||
getentropy_fallback(void *buf, size_t len)
|
||||
{
|
||||
uint8_t results[SHA512_DIGEST_LENGTH];
|
||||
int save_errno = errno, e, pgs = getpagesize(), faster = 0, repeat;
|
||||
static int cnt;
|
||||
struct timespec ts;
|
||||
struct timeval tv;
|
||||
struct rusage ru;
|
||||
sigset_t sigset;
|
||||
struct stat st;
|
||||
SHA512_CTX ctx;
|
||||
static pid_t lastpid;
|
||||
pid_t pid;
|
||||
size_t i, ii, m;
|
||||
char *p;
|
||||
#if TARGET_OS_OSX
|
||||
struct tcpstat tcpstat;
|
||||
struct udpstat udpstat;
|
||||
struct ipstat ipstat;
|
||||
#endif
|
||||
u_int64_t mach_time;
|
||||
unsigned int idata;
|
||||
void *addr;
|
||||
|
||||
pid = getpid();
|
||||
if (lastpid == pid) {
|
||||
faster = 1;
|
||||
repeat = 2;
|
||||
} else {
|
||||
faster = 0;
|
||||
lastpid = pid;
|
||||
repeat = REPEAT;
|
||||
}
|
||||
for (i = 0; i < len; ) {
|
||||
int j;
|
||||
SHA512_Init(&ctx);
|
||||
for (j = 0; j < repeat; j++) {
|
||||
HX((e = gettimeofday(&tv, NULL)) == -1, tv);
|
||||
if (e != -1) {
|
||||
cnt += (int)tv.tv_sec;
|
||||
cnt += (int)tv.tv_usec;
|
||||
}
|
||||
|
||||
mach_time = mach_absolute_time();
|
||||
HD(mach_time);
|
||||
|
||||
ii = sizeof(addr);
|
||||
HX(sysctl(kmib, sizeof(kmib) / sizeof(kmib[0]),
|
||||
&addr, &ii, NULL, 0) == -1, addr);
|
||||
|
||||
ii = sizeof(idata);
|
||||
HX(sysctl(hwmib, sizeof(hwmib) / sizeof(hwmib[0]),
|
||||
&idata, &ii, NULL, 0) == -1, idata);
|
||||
|
||||
#if TARGET_OS_OSX
|
||||
ii = sizeof(tcpstat);
|
||||
HX(sysctl(tcpmib, sizeof(tcpmib) / sizeof(tcpmib[0]),
|
||||
&tcpstat, &ii, NULL, 0) == -1, tcpstat);
|
||||
|
||||
ii = sizeof(udpstat);
|
||||
HX(sysctl(udpmib, sizeof(udpmib) / sizeof(udpmib[0]),
|
||||
&udpstat, &ii, NULL, 0) == -1, udpstat);
|
||||
|
||||
ii = sizeof(ipstat);
|
||||
HX(sysctl(ipmib, sizeof(ipmib) / sizeof(ipmib[0]),
|
||||
&ipstat, &ii, NULL, 0) == -1, ipstat);
|
||||
#endif
|
||||
|
||||
HX((pid = getpid()) == -1, pid);
|
||||
HX((pid = getsid(pid)) == -1, pid);
|
||||
HX((pid = getppid()) == -1, pid);
|
||||
HX((pid = getpgid(0)) == -1, pid);
|
||||
HX((e = getpriority(0, 0)) == -1, e);
|
||||
|
||||
if (!faster) {
|
||||
ts.tv_sec = 0;
|
||||
ts.tv_nsec = 1;
|
||||
(void) nanosleep(&ts, NULL);
|
||||
}
|
||||
|
||||
HX(sigpending(&sigset) == -1, sigset);
|
||||
HX(sigprocmask(SIG_BLOCK, NULL, &sigset) == -1,
|
||||
sigset);
|
||||
|
||||
HF(getentropy); /* an addr in this library */
|
||||
HF(printf); /* an addr in libc */
|
||||
p = (char *)&p;
|
||||
HD(p); /* an addr on stack */
|
||||
p = (char *)&errno;
|
||||
HD(p); /* the addr of errno */
|
||||
|
||||
if (i == 0) {
|
||||
struct sockaddr_storage ss;
|
||||
struct statvfs stvfs;
|
||||
struct termios tios;
|
||||
struct statfs stfs;
|
||||
socklen_t ssl;
|
||||
off_t off;
|
||||
|
||||
/*
|
||||
* Prime-sized mappings encourage fragmentation;
|
||||
* thus exposing some address entropy.
|
||||
*/
|
||||
struct mm {
|
||||
size_t npg;
|
||||
void *p;
|
||||
} mm[] = {
|
||||
{ 17, MAP_FAILED }, { 3, MAP_FAILED },
|
||||
{ 11, MAP_FAILED }, { 2, MAP_FAILED },
|
||||
{ 5, MAP_FAILED }, { 3, MAP_FAILED },
|
||||
{ 7, MAP_FAILED }, { 1, MAP_FAILED },
|
||||
{ 57, MAP_FAILED }, { 3, MAP_FAILED },
|
||||
{ 131, MAP_FAILED }, { 1, MAP_FAILED },
|
||||
};
|
||||
|
||||
for (m = 0; m < sizeof mm/sizeof(mm[0]); m++) {
|
||||
HX(mm[m].p = mmap(NULL,
|
||||
mm[m].npg * pgs,
|
||||
PROT_READ|PROT_WRITE,
|
||||
MAP_PRIVATE|MAP_ANON, -1,
|
||||
(off_t)0), mm[m].p);
|
||||
if (mm[m].p != MAP_FAILED) {
|
||||
size_t mo;
|
||||
|
||||
/* Touch some memory... */
|
||||
p = mm[m].p;
|
||||
mo = cnt %
|
||||
(mm[m].npg * pgs - 1);
|
||||
p[mo] = 1;
|
||||
cnt += (int)((long)(mm[m].p)
|
||||
/ pgs);
|
||||
}
|
||||
|
||||
/* Check cnts and times... */
|
||||
mach_time = mach_absolute_time();
|
||||
HD(mach_time);
|
||||
cnt += (int)mach_time;
|
||||
|
||||
HX((e = getrusage(RUSAGE_SELF,
|
||||
&ru)) == -1, ru);
|
||||
if (e != -1) {
|
||||
cnt += (int)ru.ru_utime.tv_sec;
|
||||
cnt += (int)ru.ru_utime.tv_usec;
|
||||
}
|
||||
}
|
||||
|
||||
for (m = 0; m < sizeof mm/sizeof(mm[0]); m++) {
|
||||
if (mm[m].p != MAP_FAILED)
|
||||
munmap(mm[m].p, mm[m].npg * pgs);
|
||||
mm[m].p = MAP_FAILED;
|
||||
}
|
||||
|
||||
HX(stat(".", &st) == -1, st);
|
||||
HX(statvfs(".", &stvfs) == -1, stvfs);
|
||||
HX(statfs(".", &stfs) == -1, stfs);
|
||||
|
||||
HX(stat("/", &st) == -1, st);
|
||||
HX(statvfs("/", &stvfs) == -1, stvfs);
|
||||
HX(statfs("/", &stfs) == -1, stfs);
|
||||
|
||||
HX((e = fstat(0, &st)) == -1, st);
|
||||
if (e == -1) {
|
||||
if (S_ISREG(st.st_mode) ||
|
||||
S_ISFIFO(st.st_mode) ||
|
||||
S_ISSOCK(st.st_mode)) {
|
||||
HX(fstatvfs(0, &stvfs) == -1,
|
||||
stvfs);
|
||||
HX(fstatfs(0, &stfs) == -1,
|
||||
stfs);
|
||||
HX((off = lseek(0, (off_t)0,
|
||||
SEEK_CUR)) < 0, off);
|
||||
}
|
||||
if (S_ISCHR(st.st_mode)) {
|
||||
HX(tcgetattr(0, &tios) == -1,
|
||||
tios);
|
||||
} else if (S_ISSOCK(st.st_mode)) {
|
||||
memset(&ss, 0, sizeof ss);
|
||||
ssl = sizeof(ss);
|
||||
HX(getpeername(0,
|
||||
(void *)&ss, &ssl) == -1,
|
||||
ss);
|
||||
}
|
||||
}
|
||||
|
||||
HX((e = getrusage(RUSAGE_CHILDREN,
|
||||
&ru)) == -1, ru);
|
||||
if (e != -1) {
|
||||
cnt += (int)ru.ru_utime.tv_sec;
|
||||
cnt += (int)ru.ru_utime.tv_usec;
|
||||
}
|
||||
} else {
|
||||
/* Subsequent hashes absorb previous result */
|
||||
HD(results);
|
||||
}
|
||||
|
||||
HX((e = gettimeofday(&tv, NULL)) == -1, tv);
|
||||
if (e != -1) {
|
||||
cnt += (int)tv.tv_sec;
|
||||
cnt += (int)tv.tv_usec;
|
||||
}
|
||||
|
||||
HD(cnt);
|
||||
}
|
||||
|
||||
SHA512_Final(results, &ctx);
|
||||
memcpy((char *)buf + i, results, min(sizeof(results), len - i));
|
||||
i += min(sizeof(results), len - i);
|
||||
}
|
||||
explicit_bzero(&ctx, sizeof ctx);
|
||||
explicit_bzero(results, sizeof results);
|
||||
errno = save_errno;
|
||||
return (0); /* satisfied */
|
||||
return -1;
|
||||
}
|
||||
|
||||
+3
-10
@@ -59,10 +59,7 @@ static int inet_pton6 (const char *src, uint8_t *dst);
|
||||
* Paul Vixie, 1996.
|
||||
*/
|
||||
int
|
||||
inet_pton(af, src, dst)
|
||||
int af;
|
||||
const char *src;
|
||||
void *dst;
|
||||
inet_pton(int af, const char *src, void *dst)
|
||||
{
|
||||
switch (af) {
|
||||
case AF_INET:
|
||||
@@ -91,9 +88,7 @@ inet_pton(af, src, dst)
|
||||
* Paul Vixie, 1996.
|
||||
*/
|
||||
static int
|
||||
inet_pton4(src, dst)
|
||||
const char *src;
|
||||
uint8_t *dst;
|
||||
inet_pton4(const char *src, uint8_t *dst)
|
||||
{
|
||||
static const char digits[] = "0123456789";
|
||||
int saw_digit, octets, ch;
|
||||
@@ -145,9 +140,7 @@ inet_pton4(src, dst)
|
||||
* Paul Vixie, 1996.
|
||||
*/
|
||||
static int
|
||||
inet_pton6(src, dst)
|
||||
const char *src;
|
||||
uint8_t *dst;
|
||||
inet_pton6(const char *src, uint8_t *dst)
|
||||
{
|
||||
static const char xdigits_l[] = "0123456789abcdef",
|
||||
xdigits_u[] = "0123456789ABCDEF";
|
||||
|
||||
+32
@@ -31,6 +31,9 @@
|
||||
/* Whether daemon is deprecated */
|
||||
#undef DEPRECATED_DAEMON
|
||||
|
||||
/* Whether X509_NAME_get_text_by_NID is deprecated */
|
||||
#undef DEPRECATED_X509_NAME_GET_TEXT_BY_NID
|
||||
|
||||
/* Deprecate RSA 1024 bit length, makes that an unsupported key */
|
||||
#undef DEPRECATE_RSA_1024
|
||||
|
||||
@@ -60,6 +63,9 @@
|
||||
/* Define to 1 if you have the <arpa/inet.h> header file. */
|
||||
#undef HAVE_ARPA_INET_H
|
||||
|
||||
/* Define to 1 if you have the `ASN1_STRING_get0_data' function. */
|
||||
#undef HAVE_ASN1_STRING_GET0_DATA
|
||||
|
||||
/* Whether the C compiler accepts the "fallthrough" attribute */
|
||||
#undef HAVE_ATTR_FALLTHROUGH
|
||||
|
||||
@@ -140,6 +146,10 @@
|
||||
to 0 if you don't. */
|
||||
#undef HAVE_DECL_NGTCP2_CRYPTO_ENCRYPT_CB
|
||||
|
||||
/* Define to 1 if you have the declaration of `ngtcp2_crypto_ossl_ctx_new',
|
||||
and to 0 if you don't. */
|
||||
#undef HAVE_DECL_NGTCP2_CRYPTO_OSSL_CTX_NEW
|
||||
|
||||
/* Define to 1 if you have the declaration of `NID_ED25519', and to 0 if you
|
||||
don't. */
|
||||
#undef HAVE_DECL_NID_ED25519
|
||||
@@ -289,6 +299,12 @@
|
||||
/* Define to 1 if you have the `FIPS_mode' function. */
|
||||
#undef HAVE_FIPS_MODE
|
||||
|
||||
/* Define to 1 if you have the `fnmatch' function. */
|
||||
#undef HAVE_FNMATCH
|
||||
|
||||
/* Define to 1 if you have the <fnmatch.h> header file. */
|
||||
#undef HAVE_FNMATCH_H
|
||||
|
||||
/* Define to 1 if you have the `fork' function. */
|
||||
#undef HAVE_FORK
|
||||
|
||||
@@ -513,6 +529,9 @@
|
||||
/* Define to 1 if you have the <openssl/bn.h> header file. */
|
||||
#undef HAVE_OPENSSL_BN_H
|
||||
|
||||
/* Define to 1 if you have the `OPENSSL_cleanup' function. */
|
||||
#undef HAVE_OPENSSL_CLEANUP
|
||||
|
||||
/* Define to 1 if you have the `OPENSSL_config' function. */
|
||||
#undef HAVE_OPENSSL_CONFIG
|
||||
|
||||
@@ -685,9 +704,16 @@
|
||||
/* Define to 1 if you have the `SSL_is_quic' function. */
|
||||
#undef HAVE_SSL_IS_QUIC
|
||||
|
||||
/* Define to 1 if you have the `SSL_set1_dnsname' function. */
|
||||
#undef HAVE_SSL_SET1_DNSNAME
|
||||
|
||||
/* Define to 1 if you have the `SSL_set1_host' function. */
|
||||
#undef HAVE_SSL_SET1_HOST
|
||||
|
||||
/* Define to 1 if you have the `SSL_set_quic_tls_early_data_enabled' function.
|
||||
*/
|
||||
#undef HAVE_SSL_SET_QUIC_TLS_EARLY_DATA_ENABLED
|
||||
|
||||
/* Define to 1 if you have the <stdarg.h> header file. */
|
||||
#undef HAVE_STDARG_H
|
||||
|
||||
@@ -852,6 +878,12 @@
|
||||
/* Define to 1 if you have the <ws2tcpip.h> header file. */
|
||||
#undef HAVE_WS2TCPIP_H
|
||||
|
||||
/* Define to 1 if you have the `X509_get_key_usage' function. */
|
||||
#undef HAVE_X509_GET_KEY_USAGE
|
||||
|
||||
/* Define to 1 if you have the `X509_NAME_get_text_by_NID' function. */
|
||||
#undef HAVE_X509_NAME_GET_TEXT_BY_NID
|
||||
|
||||
/* Define to 1 if you have the `X509_VERIFY_PARAM_set1_host' function. */
|
||||
#undef HAVE_X509_VERIFY_PARAM_SET1_HOST
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#! /bin/sh
|
||||
# Guess values for system-dependent variables and create Makefiles.
|
||||
# Generated by GNU Autoconf 2.71 for unbound 1.25.2.
|
||||
# Generated by GNU Autoconf 2.71 for unbound 1.26.1.
|
||||
#
|
||||
# Report bugs to <unbound-bugs@nlnetlabs.nl or https://github.com/NLnetLabs/unbound/issues>.
|
||||
#
|
||||
@@ -622,8 +622,8 @@ MAKEFLAGS=
|
||||
# Identity of this package.
|
||||
PACKAGE_NAME='unbound'
|
||||
PACKAGE_TARNAME='unbound'
|
||||
PACKAGE_VERSION='1.25.2'
|
||||
PACKAGE_STRING='unbound 1.25.2'
|
||||
PACKAGE_VERSION='1.26.1'
|
||||
PACKAGE_STRING='unbound 1.26.1'
|
||||
PACKAGE_BUGREPORT='unbound-bugs@nlnetlabs.nl or https://github.com/NLnetLabs/unbound/issues'
|
||||
PACKAGE_URL=''
|
||||
|
||||
@@ -1513,7 +1513,7 @@ if test "$ac_init_help" = "long"; then
|
||||
# Omit some internal or obsolete options to make the list less imposing.
|
||||
# This message is too long to be a string in the A/UX 3.1 sh.
|
||||
cat <<_ACEOF
|
||||
\`configure' configures unbound 1.25.2 to adapt to many kinds of systems.
|
||||
\`configure' configures unbound 1.26.1 to adapt to many kinds of systems.
|
||||
|
||||
Usage: $0 [OPTION]... [VAR=VALUE]...
|
||||
|
||||
@@ -1579,7 +1579,7 @@ fi
|
||||
|
||||
if test -n "$ac_init_help"; then
|
||||
case $ac_init_help in
|
||||
short | recursive ) echo "Configuration of unbound 1.25.2:";;
|
||||
short | recursive ) echo "Configuration of unbound 1.26.1:";;
|
||||
esac
|
||||
cat <<\_ACEOF
|
||||
|
||||
@@ -1832,7 +1832,7 @@ fi
|
||||
test -n "$ac_init_help" && exit $ac_status
|
||||
if $ac_init_version; then
|
||||
cat <<\_ACEOF
|
||||
unbound configure 1.25.2
|
||||
unbound configure 1.26.1
|
||||
generated by GNU Autoconf 2.71
|
||||
|
||||
Copyright (C) 2021 Free Software Foundation, Inc.
|
||||
@@ -2489,7 +2489,7 @@ cat >config.log <<_ACEOF
|
||||
This file contains any messages produced by compilers while
|
||||
running configure, to aid debugging if configure makes a mistake.
|
||||
|
||||
It was created by unbound $as_me 1.25.2, which was
|
||||
It was created by unbound $as_me 1.26.1, which was
|
||||
generated by GNU Autoconf 2.71. Invocation command line was
|
||||
|
||||
$ $0$ac_configure_args_raw
|
||||
@@ -3251,13 +3251,13 @@ ac_compiler_gnu=$ac_cv_c_compiler_gnu
|
||||
|
||||
UNBOUND_VERSION_MAJOR=1
|
||||
|
||||
UNBOUND_VERSION_MINOR=25
|
||||
UNBOUND_VERSION_MINOR=26
|
||||
|
||||
UNBOUND_VERSION_MICRO=2
|
||||
UNBOUND_VERSION_MICRO=1
|
||||
|
||||
|
||||
LIBUNBOUND_CURRENT=9
|
||||
LIBUNBOUND_REVISION=38
|
||||
LIBUNBOUND_REVISION=40
|
||||
LIBUNBOUND_AGE=1
|
||||
# 1.0.0 had 0:12:0
|
||||
# 1.0.1 had 0:13:0
|
||||
@@ -3363,6 +3363,8 @@ LIBUNBOUND_AGE=1
|
||||
# 1.25.0 had 9:36:1
|
||||
# 1.25.1 had 9:37:1
|
||||
# 1.25.2 had 9:38:1
|
||||
# 1.26.0 had 9:39:1
|
||||
# 1.26.1 had 9:40:1
|
||||
|
||||
# Current -- the number of the binary API that we're implementing
|
||||
# Revision -- which iteration of the implementation of the binary
|
||||
@@ -16005,6 +16007,13 @@ if test "x$ac_cv_header_glob_h" = xyes
|
||||
then :
|
||||
printf "%s\n" "#define HAVE_GLOB_H 1" >>confdefs.h
|
||||
|
||||
fi
|
||||
ac_fn_c_check_header_compile "$LINENO" "fnmatch.h" "ac_cv_header_fnmatch_h" "$ac_includes_default
|
||||
"
|
||||
if test "x$ac_cv_header_fnmatch_h" = xyes
|
||||
then :
|
||||
printf "%s\n" "#define HAVE_FNMATCH_H 1" >>confdefs.h
|
||||
|
||||
fi
|
||||
ac_fn_c_check_header_compile "$LINENO" "grp.h" "ac_cv_header_grp_h" "$ac_includes_default
|
||||
"
|
||||
@@ -18407,7 +18416,31 @@ fi
|
||||
# correctly enabled
|
||||
|
||||
case $host_os in
|
||||
darwin* | hpux* | linux* | osf* | solaris*)
|
||||
solaris*)
|
||||
# Solaris 11.4 introduced XPG7 support and did away with the need for
|
||||
# _REENTRANT.
|
||||
|
||||
cat confdefs.h - <<_ACEOF >conftest.$ac_ext
|
||||
/* end confdefs.h. */
|
||||
|
||||
# undef _XOPEN_SOURCE
|
||||
# include <sys/feature_tests.h>
|
||||
# if _XOPEN_VERSION < 700
|
||||
AX_PTHREAD_SOLARIS__REENTRANT
|
||||
# endif
|
||||
|
||||
_ACEOF
|
||||
if (eval "$ac_cpp conftest.$ac_ext") 2>&5 |
|
||||
$EGREP "AX_PTHREAD_SOLARIS__REENTRANT" >/dev/null 2>&1
|
||||
then :
|
||||
ax_pthread_check_macro="_REENTRANT"
|
||||
else $as_nop
|
||||
ax_pthread_check_macro="--"
|
||||
fi
|
||||
rm -rf conftest*
|
||||
|
||||
;;
|
||||
darwin* | hpux* | linux* | osf*)
|
||||
ax_pthread_check_macro="_REENTRANT"
|
||||
;;
|
||||
|
||||
@@ -21061,6 +21094,12 @@ then :
|
||||
printf "%s\n" "#define HAVE_BIO_SET_CALLBACK_EX 1" >>confdefs.h
|
||||
|
||||
fi
|
||||
ac_fn_c_check_func "$LINENO" "OPENSSL_cleanup" "ac_cv_func_OPENSSL_cleanup"
|
||||
if test "x$ac_cv_func_OPENSSL_cleanup" = xyes
|
||||
then :
|
||||
printf "%s\n" "#define HAVE_OPENSSL_CLEANUP 1" >>confdefs.h
|
||||
|
||||
fi
|
||||
|
||||
|
||||
# these check_funcs need -lssl
|
||||
@@ -21089,6 +21128,24 @@ if test "x$ac_cv_func_SSL_get0_peername" = xyes
|
||||
then :
|
||||
printf "%s\n" "#define HAVE_SSL_GET0_PEERNAME 1" >>confdefs.h
|
||||
|
||||
fi
|
||||
ac_fn_c_check_func "$LINENO" "SSL_set1_dnsname" "ac_cv_func_SSL_set1_dnsname"
|
||||
if test "x$ac_cv_func_SSL_set1_dnsname" = xyes
|
||||
then :
|
||||
printf "%s\n" "#define HAVE_SSL_SET1_DNSNAME 1" >>confdefs.h
|
||||
|
||||
fi
|
||||
ac_fn_c_check_func "$LINENO" "X509_get_key_usage" "ac_cv_func_X509_get_key_usage"
|
||||
if test "x$ac_cv_func_X509_get_key_usage" = xyes
|
||||
then :
|
||||
printf "%s\n" "#define HAVE_X509_GET_KEY_USAGE 1" >>confdefs.h
|
||||
|
||||
fi
|
||||
ac_fn_c_check_func "$LINENO" "ASN1_STRING_get0_data" "ac_cv_func_ASN1_STRING_get0_data"
|
||||
if test "x$ac_cv_func_ASN1_STRING_get0_data" = xyes
|
||||
then :
|
||||
printf "%s\n" "#define HAVE_ASN1_STRING_GET0_DATA 1" >>confdefs.h
|
||||
|
||||
fi
|
||||
ac_fn_c_check_func "$LINENO" "X509_VERIFY_PARAM_set1_host" "ac_cv_func_X509_VERIFY_PARAM_set1_host"
|
||||
if test "x$ac_cv_func_X509_VERIFY_PARAM_set1_host" = xyes
|
||||
@@ -21133,6 +21190,54 @@ then :
|
||||
|
||||
fi
|
||||
|
||||
ac_fn_c_check_func "$LINENO" "X509_NAME_get_text_by_NID" "ac_cv_func_X509_NAME_get_text_by_NID"
|
||||
if test "x$ac_cv_func_X509_NAME_get_text_by_NID" = xyes
|
||||
then :
|
||||
printf "%s\n" "#define HAVE_X509_NAME_GET_TEXT_BY_NID 1" >>confdefs.h
|
||||
|
||||
fi
|
||||
|
||||
if test $ac_cv_func_X509_NAME_get_text_by_NID = yes; then
|
||||
|
||||
|
||||
{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking if X509_NAME_get_text_by_NID is deprecated" >&5
|
||||
printf %s "checking if X509_NAME_get_text_by_NID is deprecated... " >&6; }
|
||||
cache=`echo X509_NAME_get_text_by_NID | sed 'y%.=/+-%___p_%'`
|
||||
if eval test \${cv_cc_deprecated_$cache+y}
|
||||
then :
|
||||
printf %s "(cached) " >&6
|
||||
else $as_nop
|
||||
|
||||
echo '
|
||||
#include "openssl/x509.h"
|
||||
' >conftest.c
|
||||
echo 'void f(void){
|
||||
(void)X509_NAME_get_text_by_NID(NULL, 0, NULL, 0); }' >>conftest.c
|
||||
if test -z "`$CC $CPPFLAGS $CFLAGS -c conftest.c 2>&1 | grep -e deprecated -e unavailable`"; then
|
||||
eval "cv_cc_deprecated_$cache=no"
|
||||
else
|
||||
eval "cv_cc_deprecated_$cache=yes"
|
||||
fi
|
||||
rm -f conftest conftest.o conftest.c
|
||||
|
||||
fi
|
||||
|
||||
if eval "test \"`echo '$cv_cc_deprecated_'$cache`\" = yes"; then
|
||||
{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: yes" >&5
|
||||
printf "%s\n" "yes" >&6; }
|
||||
|
||||
printf "%s\n" "#define DEPRECATED_X509_NAME_GET_TEXT_BY_NID 1" >>confdefs.h
|
||||
|
||||
:
|
||||
|
||||
else
|
||||
{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5
|
||||
printf "%s\n" "no" >&6; }
|
||||
:
|
||||
|
||||
fi
|
||||
|
||||
fi
|
||||
LIBS="$BAKLIBS"
|
||||
|
||||
ac_fn_check_decl "$LINENO" "SSL_COMP_get_compression_methods" "ac_cv_have_decl_SSL_COMP_get_compression_methods" "
|
||||
@@ -22639,6 +22744,24 @@ then :
|
||||
|
||||
printf "%s\n" "#define USE_NGTCP2_CRYPTO_OSSL 1" >>confdefs.h
|
||||
|
||||
ac_fn_check_decl "$LINENO" "ngtcp2_crypto_ossl_ctx_new" "ac_cv_have_decl_ngtcp2_crypto_ossl_ctx_new" "$ac_includes_default
|
||||
#include <ngtcp2/ngtcp2_crypto_ossl.h>
|
||||
|
||||
" "$ac_c_undeclared_builtin_options" "CFLAGS"
|
||||
if test "x$ac_cv_have_decl_ngtcp2_crypto_ossl_ctx_new" = xyes
|
||||
then :
|
||||
ac_have_decl=1
|
||||
else $as_nop
|
||||
ac_have_decl=0
|
||||
fi
|
||||
printf "%s\n" "#define HAVE_DECL_NGTCP2_CRYPTO_OSSL_CTX_NEW $ac_have_decl" >>confdefs.h
|
||||
if test $ac_have_decl = 1
|
||||
then :
|
||||
|
||||
else $as_nop
|
||||
as_fn_error $? "No declaration of ngtcp2_crypto_ossl_ctx_new in the ngtcp2_crypto_ossl header file. Perhaps the ngtcp2_crypto_ossl devel header files need to be installed." "$LINENO" 5
|
||||
fi
|
||||
|
||||
|
||||
else $as_nop
|
||||
|
||||
@@ -22818,6 +22941,13 @@ else $as_nop
|
||||
fi
|
||||
|
||||
done
|
||||
ac_fn_c_check_func "$LINENO" "SSL_set_quic_tls_early_data_enabled" "ac_cv_func_SSL_set_quic_tls_early_data_enabled"
|
||||
if test "x$ac_cv_func_SSL_set_quic_tls_early_data_enabled" = xyes
|
||||
then :
|
||||
printf "%s\n" "#define HAVE_SSL_SET_QUIC_TLS_EARLY_DATA_ENABLED 1" >>confdefs.h
|
||||
|
||||
fi
|
||||
|
||||
LIBS="$BAKLIBS"
|
||||
|
||||
ac_fn_c_check_type "$LINENO" "struct ngtcp2_version_cid" "ac_cv_type_struct_ngtcp2_version_cid" "$ac_includes_default
|
||||
@@ -23780,6 +23910,12 @@ if test "x$ac_cv_func_glob" = xyes
|
||||
then :
|
||||
printf "%s\n" "#define HAVE_GLOB 1" >>confdefs.h
|
||||
|
||||
fi
|
||||
ac_fn_c_check_func "$LINENO" "fnmatch" "ac_cv_func_fnmatch"
|
||||
if test "x$ac_cv_func_fnmatch" = xyes
|
||||
then :
|
||||
printf "%s\n" "#define HAVE_FNMATCH 1" >>confdefs.h
|
||||
|
||||
fi
|
||||
ac_fn_c_check_func "$LINENO" "initgroups" "ac_cv_func_initgroups"
|
||||
if test "x$ac_cv_func_initgroups" = xyes
|
||||
@@ -25576,7 +25712,7 @@ printf "%s\n" "#define MAXSYSLOGMSGLEN 10240" >>confdefs.h
|
||||
|
||||
|
||||
|
||||
version=1.25.2
|
||||
version=1.26.1
|
||||
|
||||
{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for build time" >&5
|
||||
printf %s "checking for build time... " >&6; }
|
||||
@@ -26106,7 +26242,7 @@ cat >>$CONFIG_STATUS <<\_ACEOF || ac_write_fail=1
|
||||
# report actual input values of CONFIG_FILES etc. instead of their
|
||||
# values after options handling.
|
||||
ac_log="
|
||||
This file was extended by unbound $as_me 1.25.2, which was
|
||||
This file was extended by unbound $as_me 1.26.1, which was
|
||||
generated by GNU Autoconf 2.71. Invocation command line was
|
||||
|
||||
CONFIG_FILES = $CONFIG_FILES
|
||||
@@ -26174,7 +26310,7 @@ ac_cs_config_escaped=`printf "%s\n" "$ac_cs_config" | sed "s/^ //; s/'/'\\\\\\\\
|
||||
cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1
|
||||
ac_cs_config='$ac_cs_config_escaped'
|
||||
ac_cs_version="\\
|
||||
unbound config.status 1.25.2
|
||||
unbound config.status 1.26.1
|
||||
configured by $0, generated by GNU Autoconf 2.71,
|
||||
with options \\"\$ac_cs_config\\"
|
||||
|
||||
|
||||
+20
-7
@@ -11,15 +11,15 @@ sinclude(dnscrypt/dnscrypt.m4)
|
||||
|
||||
# must be numbers. ac_defun because of later processing
|
||||
m4_define([VERSION_MAJOR],[1])
|
||||
m4_define([VERSION_MINOR],[25])
|
||||
m4_define([VERSION_MICRO],[2])
|
||||
m4_define([VERSION_MINOR],[26])
|
||||
m4_define([VERSION_MICRO],[1])
|
||||
AC_INIT([unbound],m4_defn([VERSION_MAJOR]).m4_defn([VERSION_MINOR]).m4_defn([VERSION_MICRO]),[unbound-bugs@nlnetlabs.nl or https://github.com/NLnetLabs/unbound/issues],[unbound])
|
||||
AC_SUBST(UNBOUND_VERSION_MAJOR, [VERSION_MAJOR])
|
||||
AC_SUBST(UNBOUND_VERSION_MINOR, [VERSION_MINOR])
|
||||
AC_SUBST(UNBOUND_VERSION_MICRO, [VERSION_MICRO])
|
||||
|
||||
LIBUNBOUND_CURRENT=9
|
||||
LIBUNBOUND_REVISION=38
|
||||
LIBUNBOUND_REVISION=40
|
||||
LIBUNBOUND_AGE=1
|
||||
# 1.0.0 had 0:12:0
|
||||
# 1.0.1 had 0:13:0
|
||||
@@ -125,6 +125,8 @@ LIBUNBOUND_AGE=1
|
||||
# 1.25.0 had 9:36:1
|
||||
# 1.25.1 had 9:37:1
|
||||
# 1.25.2 had 9:38:1
|
||||
# 1.26.0 had 9:39:1
|
||||
# 1.26.1 had 9:40:1
|
||||
|
||||
# Current -- the number of the binary API that we're implementing
|
||||
# Revision -- which iteration of the implementation of the binary
|
||||
@@ -483,7 +485,7 @@ PKG_PROG_PKG_CONFIG
|
||||
fi
|
||||
|
||||
# Checks for header files.
|
||||
AC_CHECK_HEADERS([stdarg.h stdbool.h netinet/in.h netinet/tcp.h sys/param.h sys/select.h sys/socket.h sys/un.h sys/uio.h sys/resource.h arpa/inet.h syslog.h netdb.h sys/wait.h pwd.h glob.h grp.h login_cap.h winsock2.h ws2tcpip.h endian.h sys/endian.h libkern/OSByteOrder.h sys/ipc.h sys/shm.h ifaddrs.h poll.h],,, [AC_INCLUDES_DEFAULT])
|
||||
AC_CHECK_HEADERS([stdarg.h stdbool.h netinet/in.h netinet/tcp.h sys/param.h sys/select.h sys/socket.h sys/un.h sys/uio.h sys/resource.h arpa/inet.h syslog.h netdb.h sys/wait.h pwd.h glob.h fnmatch.h grp.h login_cap.h winsock2.h ws2tcpip.h endian.h sys/endian.h libkern/OSByteOrder.h sys/ipc.h sys/shm.h ifaddrs.h poll.h],,, [AC_INCLUDES_DEFAULT])
|
||||
# net/if.h portability for Darwin see:
|
||||
# https://www.gnu.org/software/autoconf/manual/autoconf-2.69/html_node/Header-Portability.html
|
||||
AC_CHECK_HEADERS([net/if.h],,, [
|
||||
@@ -1080,12 +1082,19 @@ else
|
||||
AC_MSG_RESULT([no])
|
||||
fi
|
||||
AC_CHECK_HEADERS([openssl/conf.h openssl/engine.h openssl/bn.h openssl/dh.h openssl/dsa.h openssl/rsa.h openssl/core_names.h openssl/param_build.h],,, [AC_INCLUDES_DEFAULT])
|
||||
AC_CHECK_FUNCS([OPENSSL_config EVP_sha1 EVP_sha256 EVP_sha512 FIPS_mode EVP_default_properties_is_fips_enabled EVP_MD_CTX_new OpenSSL_add_all_digests OPENSSL_init_crypto EVP_cleanup ENGINE_cleanup ERR_load_crypto_strings CRYPTO_cleanup_all_ex_data ERR_free_strings RAND_cleanup DSA_SIG_set0 EVP_dss1 EVP_DigestVerify EVP_aes_256_cbc EVP_EncryptInit_ex HMAC_Init_ex CRYPTO_THREADID_set_callback EVP_MAC_CTX_set_params OSSL_PARAM_BLD_new BIO_set_callback_ex])
|
||||
AC_CHECK_FUNCS([OPENSSL_config EVP_sha1 EVP_sha256 EVP_sha512 FIPS_mode EVP_default_properties_is_fips_enabled EVP_MD_CTX_new OpenSSL_add_all_digests OPENSSL_init_crypto EVP_cleanup ENGINE_cleanup ERR_load_crypto_strings CRYPTO_cleanup_all_ex_data ERR_free_strings RAND_cleanup DSA_SIG_set0 EVP_dss1 EVP_DigestVerify EVP_aes_256_cbc EVP_EncryptInit_ex HMAC_Init_ex CRYPTO_THREADID_set_callback EVP_MAC_CTX_set_params OSSL_PARAM_BLD_new BIO_set_callback_ex OPENSSL_cleanup])
|
||||
|
||||
# these check_funcs need -lssl
|
||||
BAKLIBS="$LIBS"
|
||||
LIBS="-lssl $LIBS"
|
||||
AC_CHECK_FUNCS([OPENSSL_init_ssl SSL_CTX_set_security_level SSL_set1_host SSL_get0_peername X509_VERIFY_PARAM_set1_host SSL_CTX_set_ciphersuites SSL_CTX_set_tlsext_ticket_key_evp_cb SSL_CTX_set_alpn_select_cb SSL_get0_alpn_selected SSL_CTX_set_alpn_protos SSL_get1_peer_certificate])
|
||||
AC_CHECK_FUNCS([OPENSSL_init_ssl SSL_CTX_set_security_level SSL_set1_host SSL_get0_peername SSL_set1_dnsname X509_get_key_usage ASN1_STRING_get0_data X509_VERIFY_PARAM_set1_host SSL_CTX_set_ciphersuites SSL_CTX_set_tlsext_ticket_key_evp_cb SSL_CTX_set_alpn_select_cb SSL_get0_alpn_selected SSL_CTX_set_alpn_protos SSL_get1_peer_certificate])
|
||||
AC_CHECK_FUNCS([X509_NAME_get_text_by_NID])
|
||||
if test $ac_cv_func_X509_NAME_get_text_by_NID = yes; then
|
||||
ACX_FUNC_DEPRECATED([X509_NAME_get_text_by_NID], [
|
||||
(void)X509_NAME_get_text_by_NID(NULL, 0, NULL, 0);], [
|
||||
#include "openssl/x509.h"
|
||||
])
|
||||
fi
|
||||
LIBS="$BAKLIBS"
|
||||
|
||||
AC_CHECK_DECLS([SSL_COMP_get_compression_methods,sk_SSL_COMP_pop_free,SSL_CTX_set_ecdh_auto,SSL_CTX_set_tmp_ecdh], [], [], [
|
||||
@@ -1704,6 +1713,9 @@ if test x_$withval = x_yes -o x_$withval != x_no; then
|
||||
AC_CHECK_LIB([ngtcp2_crypto_ossl], [ngtcp2_crypto_encrypt_cb], [
|
||||
LIBS="$LIBS -lngtcp2_crypto_ossl"
|
||||
AC_DEFINE(USE_NGTCP2_CRYPTO_OSSL, 1, [Define this to use ngtcp2_crypto_ossl.])
|
||||
AC_CHECK_DECLS([ngtcp2_crypto_ossl_ctx_new], [], [AC_MSG_ERROR([No declaration of ngtcp2_crypto_ossl_ctx_new in the ngtcp2_crypto_ossl header file. Perhaps the ngtcp2_crypto_ossl devel header files need to be installed.])], [AC_INCLUDES_DEFAULT
|
||||
#include <ngtcp2/ngtcp2_crypto_ossl.h>
|
||||
])
|
||||
], [
|
||||
AC_CHECK_LIB([ngtcp2_crypto_openssl], [ngtcp2_crypto_encrypt_cb], [ LIBS="$LIBS -lngtcp2_crypto_openssl" ], [
|
||||
AC_CHECK_LIB([ngtcp2_crypto_quictls], [ngtcp2_crypto_encrypt_cb], [ LIBS="$LIBS -lngtcp2_crypto_quictls" ])
|
||||
@@ -1715,6 +1727,7 @@ if test x_$withval = x_yes -o x_$withval != x_no; then
|
||||
BAKLIBS="$LIBS"
|
||||
LIBS="-lssl $LIBS"
|
||||
AC_CHECK_FUNCS([SSL_is_quic], [], [AC_MSG_ERROR([No QUIC support detected in OpenSSL. Need OpenSSL version with QUIC support to enable DNS over QUIC with libngtcp2.])])
|
||||
AC_CHECK_FUNCS([SSL_set_quic_tls_early_data_enabled])
|
||||
LIBS="$BAKLIBS"
|
||||
|
||||
AC_CHECK_TYPES([struct ngtcp2_version_cid, ngtcp2_encryption_level],,,[AC_INCLUDES_DEFAULT
|
||||
@@ -1928,7 +1941,7 @@ AC_LINK_IFELSE([AC_LANG_PROGRAM([
|
||||
AC_MSG_RESULT(no))
|
||||
|
||||
AC_SEARCH_LIBS([setusercontext], [util])
|
||||
AC_CHECK_FUNCS([tzset sigprocmask fcntl getpwnam endpwent getrlimit setrlimit setsid chroot kill chown sleep usleep random srandom recvmsg sendmsg writev socketpair glob initgroups strftime localtime_r setusercontext _beginthreadex endservent endprotoent fsync shmget accept4 getifaddrs if_nametoindex poll gettid])
|
||||
AC_CHECK_FUNCS([tzset sigprocmask fcntl getpwnam endpwent getrlimit setrlimit setsid chroot kill chown sleep usleep random srandom recvmsg sendmsg writev socketpair glob fnmatch initgroups strftime localtime_r setusercontext _beginthreadex endservent endprotoent fsync shmget accept4 getifaddrs if_nametoindex poll gettid])
|
||||
AC_CHECK_FUNCS([setresuid],,[AC_CHECK_FUNCS([setreuid])])
|
||||
AC_CHECK_FUNCS([setresgid],,[AC_CHECK_FUNCS([setregid])])
|
||||
|
||||
|
||||
+2
-2
@@ -99,7 +99,7 @@ static void
|
||||
dump_rrset_line(struct config_strlist_head* txt, struct ub_packed_rrset_key* k,
|
||||
time_t now, size_t i)
|
||||
{
|
||||
char s[65535];
|
||||
char s[65535*4+2048];
|
||||
if(!packed_rr_to_string(k, i, now, s, sizeof(s))) {
|
||||
spool_txt_string(txt, "BADRR\n");
|
||||
return;
|
||||
@@ -455,7 +455,7 @@ load_rr(RES* ssl, sldns_buffer* buf, struct regional* region,
|
||||
/* read the line */
|
||||
if(!ssl_read_buf(ssl, buf))
|
||||
return 0;
|
||||
if(strncmp((char*)sldns_buffer_begin(buf), "BADRR\n", 6) == 0) {
|
||||
if(strcmp((char*)sldns_buffer_begin(buf), "BADRR") == 0) {
|
||||
*go_on = 0;
|
||||
return 1;
|
||||
}
|
||||
|
||||
+29
-11
@@ -217,7 +217,8 @@ setup_listen_sslctx(void** ctx, int is_dot, int is_doh,
|
||||
(cfg->tls_session_ticket_keys.first &&
|
||||
cfg->tls_session_ticket_keys.first->str[0] != 0),
|
||||
is_dot, is_doh, cfg->tls_protocols))) {
|
||||
fatal_exit("could not set up listen SSL_CTX");
|
||||
log_err("could not set up listen SSL_CTX");
|
||||
*ctx = NULL;
|
||||
}
|
||||
}
|
||||
#endif /* HAVE_SSL */
|
||||
@@ -259,7 +260,8 @@ void* daemon_setup_listen_quic_sslctx(struct daemon* daemon,
|
||||
pem += strlen(chroot);
|
||||
|
||||
if(!(ctx = quic_sslctx_create(key, pem, NULL))) {
|
||||
fatal_exit("could not set up quic SSL_CTX");
|
||||
log_err("could not set up quic SSL_CTX");
|
||||
return NULL;
|
||||
}
|
||||
return ctx;
|
||||
}
|
||||
@@ -277,8 +279,10 @@ void* daemon_setup_connect_dot_sslctx(struct daemon* daemon,
|
||||
bundle += strlen(chroot);
|
||||
|
||||
if(!(ctx = connect_sslctx_create(NULL, NULL, bundle,
|
||||
cfg->tls_win_cert)))
|
||||
fatal_exit("could not set up connect SSL_CTX");
|
||||
cfg->tls_win_cert))) {
|
||||
log_err("could not set up connect SSL_CTX");
|
||||
return NULL;
|
||||
}
|
||||
return ctx;
|
||||
}
|
||||
#endif /* HAVE_SSL */
|
||||
@@ -308,16 +312,22 @@ daemon_setup_sslctxs(struct daemon* daemon, struct config_file* cfg)
|
||||
}
|
||||
daemon->listen_dot_sslctx = daemon_setup_listen_dot_sslctx(
|
||||
daemon, cfg);
|
||||
if(!daemon->listen_dot_sslctx)
|
||||
fatal_exit("Could not set up listen dot sslctx");
|
||||
#ifdef HAVE_NGHTTP2_NGHTTP2_H
|
||||
if(cfg_has_https(cfg)) {
|
||||
daemon->listen_doh_sslctx =
|
||||
daemon_setup_listen_doh_sslctx(daemon, cfg);
|
||||
if(!daemon->listen_doh_sslctx)
|
||||
fatal_exit("Could not set up listen doh sslctx");
|
||||
}
|
||||
#endif
|
||||
#ifdef HAVE_NGTCP2
|
||||
if(cfg_has_quic(cfg)) {
|
||||
daemon->listen_quic_sslctx =
|
||||
daemon_setup_listen_quic_sslctx(daemon, cfg);
|
||||
if(!daemon->listen_quic_sslctx)
|
||||
fatal_exit("Could not set up listen quic sslctx");
|
||||
}
|
||||
#endif /* HAVE_NGTCP2 */
|
||||
|
||||
@@ -350,6 +360,8 @@ daemon_setup_sslctxs(struct daemon* daemon, struct config_file* cfg)
|
||||
}
|
||||
daemon->connect_dot_sslctx = daemon_setup_connect_dot_sslctx(
|
||||
daemon, cfg);
|
||||
if(!daemon->connect_dot_sslctx)
|
||||
fatal_exit("could not setup connect dot sslctx");
|
||||
#else /* HAVE_SSL */
|
||||
(void)daemon;(void)cfg;
|
||||
#endif /* HAVE_SSL */
|
||||
@@ -921,13 +933,14 @@ thread_start(void* arg)
|
||||
{
|
||||
struct worker* worker = (struct worker*)arg;
|
||||
int port_num = 0;
|
||||
log_assert(worker->thr_id);
|
||||
set_log_thread_id(worker, worker->daemon->cfg);
|
||||
{
|
||||
char name[16]; /* seems to be the safest size between
|
||||
different OSes */
|
||||
snprintf(name, sizeof(name), "unbound/%u", worker->thread_num);
|
||||
ub_thread_setname(worker->thr_id, name);
|
||||
/* worker->thr_id can be written to after the thread was made
|
||||
* by the creating thread, so this uses pthread_self. */
|
||||
ub_thread_setname(ub_thread_self(), name);
|
||||
}
|
||||
ub_thread_blocksigs();
|
||||
#ifdef THREADS_DISABLED
|
||||
@@ -942,8 +955,9 @@ thread_start(void* arg)
|
||||
port_num = 0;
|
||||
#endif
|
||||
if(!worker_init(worker, worker->daemon->cfg,
|
||||
worker->daemon->ports[port_num], 0))
|
||||
worker->daemon->ports[port_num], 0)) {
|
||||
fatal_exit("Could not initialize thread");
|
||||
}
|
||||
|
||||
worker_work(worker);
|
||||
return NULL;
|
||||
@@ -1105,8 +1119,9 @@ daemon_fork(struct daemon* daemon)
|
||||
|
||||
#if defined(HAVE_EV_LOOP) || defined(HAVE_EV_DEFAULT_LOOP)
|
||||
/* in libev the first inited base gets signals */
|
||||
if(!worker_init(daemon->workers[0], daemon->cfg, daemon->ports[0], 1))
|
||||
if(!worker_init(daemon->workers[0], daemon->cfg, daemon->ports[0], 1)) {
|
||||
fatal_exit("Could not initialize main thread");
|
||||
}
|
||||
#endif
|
||||
|
||||
/* Now create the threads and init the workers.
|
||||
@@ -1119,8 +1134,9 @@ daemon_fork(struct daemon* daemon)
|
||||
*/
|
||||
#if !(defined(HAVE_EV_LOOP) || defined(HAVE_EV_DEFAULT_LOOP))
|
||||
/* libevent has the last inited base get signals (or any base) */
|
||||
if(!worker_init(daemon->workers[0], daemon->cfg, daemon->ports[0], 1))
|
||||
if(!worker_init(daemon->workers[0], daemon->cfg, daemon->ports[0], 1)) {
|
||||
fatal_exit("Could not initialize main thread");
|
||||
}
|
||||
#endif
|
||||
signal_handling_playback(daemon->workers[0]);
|
||||
|
||||
@@ -1164,7 +1180,6 @@ daemon_cleanup(struct daemon* daemon)
|
||||
/* before stopping main worker, handle signals ourselves, so we
|
||||
don't die on multiple reload signals for example. */
|
||||
signal_handling_record();
|
||||
log_thread_set(NULL);
|
||||
/* clean up caches because
|
||||
* a) RRset IDs will be recycled after a reload, causing collisions
|
||||
* b) validation config can change, thus rrset, msg, keycache clear
|
||||
@@ -1270,7 +1285,7 @@ daemon_delete(struct daemon* daemon)
|
||||
# if HAVE_DECL_SSL_COMP_GET_COMPRESSION_METHODS && HAVE_DECL_SK_SSL_COMP_POP_FREE
|
||||
# ifndef S_SPLINT_S
|
||||
# if OPENSSL_VERSION_NUMBER < 0x10100000
|
||||
sk_SSL_COMP_pop_free(comp_meth, (void(*)())CRYPTO_free);
|
||||
sk_SSL_COMP_pop_free(comp_meth, (void(*)(SSL_COMP*))CRYPTO_free);
|
||||
# endif
|
||||
# endif
|
||||
# endif
|
||||
@@ -1293,6 +1308,9 @@ daemon_delete(struct daemon* daemon)
|
||||
# if defined(HAVE_SSL) && defined(OPENSSL_THREADS) && !defined(THREADS_DISABLED)
|
||||
ub_openssl_lock_delete();
|
||||
# endif
|
||||
#ifdef HAVE_OPENSSL_CLEANUP
|
||||
OPENSSL_cleanup();
|
||||
#endif
|
||||
#ifndef HAVE_ARC4RANDOM
|
||||
_ARC4_LOCK_DESTROY();
|
||||
#endif
|
||||
|
||||
+271
-17
@@ -307,7 +307,7 @@ add_open(const char* ip, int nr, struct listen_port** list, int noproto_is_err,
|
||||
#endif
|
||||
}
|
||||
} else {
|
||||
char* s = strchr(ip, '@');
|
||||
const char* s = strchr(ip, '@');
|
||||
char newif[128];
|
||||
if(s) {
|
||||
/* override port with ifspec@port */
|
||||
@@ -1533,18 +1533,95 @@ do_datas_add(struct daemon_remote* rc, RES* ssl, struct worker* worker)
|
||||
(void)ssl_printf(ssl, "added %d datas\n", num);
|
||||
}
|
||||
|
||||
static int
|
||||
perform_data_remove_rr(RES* ssl, struct local_zones* local_zones,
|
||||
uint8_t* rr, size_t len, size_t dname_len, char *arg)
|
||||
{
|
||||
uint16_t rr_class, rr_type;
|
||||
int labs;
|
||||
struct local_zone* z;
|
||||
struct local_data* ld;
|
||||
uint8_t *rdata;
|
||||
size_t rdata_len, index;
|
||||
struct packed_rrset_data* d;
|
||||
struct local_rrset* p;
|
||||
|
||||
rdata = sldns_wirerr_get_rdatawl(rr, len, dname_len);
|
||||
rdata_len = ((size_t)sldns_wirerr_get_rdatalen(rr, len, dname_len))+2;
|
||||
|
||||
labs = dname_count_labels(rr);
|
||||
|
||||
rr_class = sldns_wirerr_get_class(rr, len, dname_len);
|
||||
rr_type = sldns_wirerr_get_type(rr, len, dname_len);
|
||||
|
||||
z = local_zones_lookup(local_zones, rr, dname_len,
|
||||
labs, rr_class, rr_type, 1);
|
||||
if (!z) {
|
||||
ssl_printf(ssl, "error no zone for rr %s\n", arg);
|
||||
return 0;
|
||||
}
|
||||
|
||||
ld = local_zone_find_data(z, rr, dname_len, labs);
|
||||
if (!ld) {
|
||||
ssl_printf(ssl, "error no local data for rr %s\n", arg);
|
||||
return 0;
|
||||
}
|
||||
|
||||
p = ld->rrsets;
|
||||
while (p && ntohs(p->rrset->rk.type) != rr_type) {
|
||||
p = p->next;
|
||||
}
|
||||
|
||||
if (!p) {
|
||||
ssl_printf(ssl, "error no rrset for rr %s\n", arg);
|
||||
return 0;
|
||||
}
|
||||
|
||||
d = (struct packed_rrset_data*)p->rrset->entry.data;
|
||||
if (!packed_rrset_find_rr(d, rdata, rdata_len, &index)) {
|
||||
ssl_printf(ssl, "error rr %s not found in rrset\n", arg);
|
||||
return 0;
|
||||
}
|
||||
|
||||
if (!local_rrset_remove_rr(d, index)) {
|
||||
ssl_printf(ssl, "error unable to delete rr %s\n", arg);
|
||||
return 0;
|
||||
}
|
||||
|
||||
return 1;
|
||||
}
|
||||
|
||||
/** Remove RR data */
|
||||
static int
|
||||
perform_data_remove(RES* ssl, struct local_zones* zones, char* arg)
|
||||
{
|
||||
uint8_t* nm;
|
||||
int nmlabs;
|
||||
size_t nmlen;
|
||||
if(!parse_arg_name(ssl, arg, &nm, &nmlen, &nmlabs))
|
||||
uint8_t rr[LDNS_RR_BUF_SIZE], *nm;
|
||||
size_t len = sizeof(rr);
|
||||
int status, nmlabs;
|
||||
size_t nmlen, dname_len;
|
||||
|
||||
/* try to parse as a rr first */
|
||||
status = sldns_str2wire_rr_buf(arg, rr, &len, &dname_len, 3600,
|
||||
NULL, 0, NULL, 0);
|
||||
|
||||
/* try to parse as a domain name second */
|
||||
if (status != 0) {
|
||||
if (parse_arg_name(ssl, arg, &nm, &nmlen, &nmlabs)) {
|
||||
local_zones_del_data(zones, nm,
|
||||
nmlen, nmlabs, LDNS_RR_CLASS_IN);
|
||||
free(nm);
|
||||
return 1;
|
||||
}
|
||||
ssl_printf(ssl, "error cannot parse rr %s at %d: %s\n", arg,
|
||||
LDNS_WIREPARSE_OFFSET(status),
|
||||
sldns_get_errorstr_parse(status));
|
||||
return 0;
|
||||
local_zones_del_data(zones, nm,
|
||||
nmlen, nmlabs, LDNS_RR_CLASS_IN);
|
||||
free(nm);
|
||||
}
|
||||
|
||||
/* handle the rr case */
|
||||
if (!perform_data_remove_rr(ssl, zones, rr, len, dname_len, arg))
|
||||
return 0;
|
||||
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -2315,6 +2392,9 @@ zone_del_rrset(struct lruhash_entry* e, void* arg)
|
||||
(struct packed_rrset_data*)e->data;
|
||||
if(d->ttl > inf->expired) {
|
||||
d->ttl = inf->expired;
|
||||
if(d->ttl_add > inf->expired)
|
||||
d->ttl_add = inf->expired; /* for 0TTL rrsets,
|
||||
means that d->ttl_add <= d->ttl */
|
||||
inf->num_rrsets++;
|
||||
}
|
||||
}
|
||||
@@ -2601,7 +2681,7 @@ static int
|
||||
ssl_print_name_dp(RES* ssl, const char* str, uint8_t* nm, uint16_t dclass,
|
||||
struct delegpt* dp)
|
||||
{
|
||||
char buf[LDNS_MAX_DOMAINLEN];
|
||||
char buf[LDNS_MAX_DOMAINLEN], portstr[128], tls_auth_name[256];
|
||||
struct delegpt_ns* ns;
|
||||
struct delegpt_addr* a;
|
||||
int f = 0;
|
||||
@@ -2616,13 +2696,32 @@ ssl_print_name_dp(RES* ssl, const char* str, uint8_t* nm, uint16_t dclass,
|
||||
}
|
||||
for(ns = dp->nslist; ns; ns = ns->next) {
|
||||
dname_str(ns->name, buf);
|
||||
if(!ssl_printf(ssl, "%s%s", (f?" ":""), buf))
|
||||
if(ns->port != UNBOUND_DNS_PORT)
|
||||
snprintf(portstr, sizeof(portstr), "@%d", ns->port);
|
||||
else portstr[0]=0;
|
||||
if(ns->tls_auth_name)
|
||||
snprintf(tls_auth_name, sizeof(tls_auth_name), "#%s",
|
||||
ns->tls_auth_name);
|
||||
else tls_auth_name[0]=0;
|
||||
if(!ssl_printf(ssl, "%s%s%s%s", (f?" ":""), buf, portstr,
|
||||
tls_auth_name))
|
||||
return 0;
|
||||
f = 1;
|
||||
}
|
||||
for(a = dp->target_list; a; a = a->next_target) {
|
||||
int port = (unsigned)((a->addr.ss_family == AF_INET) ?
|
||||
ntohs(((struct sockaddr_in*)&a->addr)->sin_port) :
|
||||
ntohs(((struct sockaddr_in6*)&a->addr)->sin6_port));
|
||||
addr_to_str(&a->addr, a->addrlen, buf, sizeof(buf));
|
||||
if(!ssl_printf(ssl, "%s%s", (f?" ":""), buf))
|
||||
if(port != UNBOUND_DNS_PORT)
|
||||
snprintf(portstr, sizeof(portstr), "@%d", port);
|
||||
else portstr[0]=0;
|
||||
if(a->tls_auth_name)
|
||||
snprintf(tls_auth_name, sizeof(tls_auth_name), "#%s",
|
||||
a->tls_auth_name);
|
||||
else tls_auth_name[0]=0;
|
||||
if(!ssl_printf(ssl, "%s%s%s%s", (f?" ":""), buf, portstr,
|
||||
tls_auth_name))
|
||||
return 0;
|
||||
f = 1;
|
||||
}
|
||||
@@ -3238,6 +3337,10 @@ do_auth_zone_reload(RES* ssl, struct worker* worker, char* arg)
|
||||
return;
|
||||
}
|
||||
if(!auth_zone_read_zonefile(z, worker->env.cfg)) {
|
||||
/* The old tree was already cleared. Do not answer from the
|
||||
* failed load. */
|
||||
z->zone_expired = 1;
|
||||
auth_zone_clear_data(z);
|
||||
lock_rw_unlock(&z->lock);
|
||||
if(xfr) {
|
||||
lock_basic_unlock(&xfr->lock);
|
||||
@@ -3249,6 +3352,7 @@ do_auth_zone_reload(RES* ssl, struct worker* worker, char* arg)
|
||||
z->zone_expired = 0;
|
||||
if(xfr) {
|
||||
xfr->zone_expired = 0;
|
||||
xfr->num_ixfrs = 0;
|
||||
if(!xfr_find_soa(z, xfr)) {
|
||||
if(z->data.count == 0) {
|
||||
lock_rw_unlock(&z->lock);
|
||||
@@ -4941,6 +5045,74 @@ fr_check_changed_cfg_str2list(struct config_str2list* cmp1,
|
||||
}
|
||||
}
|
||||
|
||||
/** fast reload thread, check if config str3list has changed. */
|
||||
#define FR_CHECK_CHANGED_CFG_STR3LIST(desc, var, buff) do { \
|
||||
fr_check_changed_cfg_str3list(cfg->var, newcfg->var, desc, buff,\
|
||||
sizeof(buff)); \
|
||||
} while(0);
|
||||
static void
|
||||
fr_check_changed_cfg_str3list(struct config_str3list* cmp1,
|
||||
struct config_str3list* cmp2, const char* desc, char* str, size_t len)
|
||||
{
|
||||
struct config_str3list* p1 = cmp1, *p2 = cmp2;
|
||||
while(p1 && p2) {
|
||||
if((!p1->str && p2->str) ||
|
||||
(p1->str && !p2->str) ||
|
||||
(p1->str && p2->str && strcmp(p1->str, p2->str) != 0)) {
|
||||
/* The str3list is different. */
|
||||
fr_add_incompatible_option(desc, str, len);
|
||||
return;
|
||||
}
|
||||
if((!p1->str2 && p2->str2) ||
|
||||
(p1->str2 && !p2->str2) ||
|
||||
(p1->str2 && p2->str2 &&
|
||||
strcmp(p1->str2, p2->str2) != 0)) {
|
||||
/* The str3list is different. */
|
||||
fr_add_incompatible_option(desc, str, len);
|
||||
return;
|
||||
}
|
||||
if((!p1->str3 && p2->str3) ||
|
||||
(p1->str3 && !p2->str3) ||
|
||||
(p1->str3 && p2->str3 &&
|
||||
strcmp(p1->str3, p2->str3) != 0)) {
|
||||
/* The str3list is different. */
|
||||
fr_add_incompatible_option(desc, str, len);
|
||||
return;
|
||||
}
|
||||
p1 = p1->next;
|
||||
p2 = p2->next;
|
||||
}
|
||||
if((!p1 && p2) || (p1 && !p2)) {
|
||||
fr_add_incompatible_option(desc, str, len);
|
||||
}
|
||||
}
|
||||
|
||||
/** fast reload thread, check tag datas. */
|
||||
static int
|
||||
fr_check_tag_datas(struct fast_reload_thread* fr, struct config_file* newcfg)
|
||||
{
|
||||
char changed_str[1024];
|
||||
struct config_file* cfg = fr->worker->env.cfg;
|
||||
changed_str[0]=0;
|
||||
|
||||
/* Check for tag_datas in acl_addr. */
|
||||
FR_CHECK_CHANGED_CFG_STR3LIST("interface-tag-data", interface_tag_datas, changed_str);
|
||||
FR_CHECK_CHANGED_CFG_STR3LIST("access-control-tag-data", acl_tag_datas, changed_str);
|
||||
|
||||
if(changed_str[0] != 0) {
|
||||
if(fr->fr_drop_mesh)
|
||||
return 1; /* already dropping queries */
|
||||
fr->fr_drop_mesh = 1;
|
||||
fr->worker->daemon->fast_reload_drop_mesh = fr->fr_drop_mesh;
|
||||
if(!fr_output_printf(fr, "recursion referenced data has changed, with: '%s"
|
||||
"', and the queries have to be dropped"
|
||||
", setting '+d'\n", changed_str))
|
||||
return 0;
|
||||
fr_send_notification(fr, fast_reload_notification_printout);
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
|
||||
/** fast reload thread, check compatible config items */
|
||||
static int
|
||||
fr_check_compat_cfg(struct fast_reload_thread* fr, struct config_file* newcfg)
|
||||
@@ -5477,6 +5649,23 @@ xfr_masterlist_equal(struct auth_master* list1, struct auth_master* list2)
|
||||
return 0;
|
||||
}
|
||||
|
||||
/** See if configuration has changed. */
|
||||
static int
|
||||
xfr_config_equal(struct auth_xfer* xfr1, struct auth_xfer* xfr2)
|
||||
{
|
||||
if(xfr1 == NULL && xfr2 == NULL)
|
||||
return 1;
|
||||
if(xfr1 == NULL && xfr2 != NULL)
|
||||
return 0;
|
||||
if(xfr1 != NULL && xfr2 == NULL)
|
||||
return 0;
|
||||
if(xfr1->max_transfer_size != xfr2->max_transfer_size)
|
||||
return 0;
|
||||
if(xfr1->max_transfer_time != xfr2->max_transfer_time)
|
||||
return 0;
|
||||
return 1;
|
||||
}
|
||||
|
||||
/** See if the list of masters has changed. */
|
||||
static int
|
||||
xfr_masters_equal(struct auth_xfer* xfr1, struct auth_xfer* xfr2)
|
||||
@@ -5565,8 +5754,31 @@ auth_zones_check_changes(struct fast_reload_thread* fr,
|
||||
&old_serial)!=0);
|
||||
have_new = (auth_zone_get_serial(new_z,
|
||||
&new_serial)!=0);
|
||||
/* A change in primaries, also means it is different
|
||||
* and the change makes it fire new transfers, from
|
||||
* the new primaries. */
|
||||
/* Treat as changed when the old zone has an
|
||||
* outstanding ZONEMD DS/DNSKEY mesh callback.
|
||||
* This will make the worker pickup change code
|
||||
* remove the mesh callback, before the old zone is
|
||||
* deleted. Also it makes a new zonemd lookup.
|
||||
* The new lookup is needed, because the new zone
|
||||
* entry needs to have a valid zonemd result,
|
||||
* and if that is bad, needs to be invalidated.
|
||||
* Also if there is a race event where the
|
||||
* outstanding callback makes the zone invalid,
|
||||
* before fast-reload completes, the change makes
|
||||
* the new zone entry have a new zonemd lookup,
|
||||
* to then invalidate that new zone.
|
||||
* There is also a brief operational window at
|
||||
* program start when a zonemd has to be looked
|
||||
* up on-line, where the zone is operational.
|
||||
* And this copies that for such a race event.
|
||||
*/
|
||||
if(have_old != have_new || old_serial != new_serial
|
||||
|| !xfr_masters_equal(old_xfr, new_xfr)) {
|
||||
|| !xfr_masters_equal(old_xfr, new_xfr)
|
||||
|| !xfr_config_equal(old_xfr, new_xfr)
|
||||
|| old_z->zonemd_callback_env != NULL) {
|
||||
/* The zone has been changed. */
|
||||
if(!fr_add_auth_zone_change(fr, old_z, new_z,
|
||||
0, 0, 1)) {
|
||||
@@ -5639,6 +5851,8 @@ ct_create_sslctxs(struct fast_reload_construct* ct,
|
||||
/* Leave listen ctxs and file str at NULL */
|
||||
ct->connect_dot_sslctx = daemon_setup_connect_dot_sslctx(
|
||||
daemon, newcfg);
|
||||
if(!ct->connect_dot_sslctx)
|
||||
return 0;
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -5648,20 +5862,28 @@ ct_create_sslctxs(struct fast_reload_construct* ct,
|
||||
pem += strlen(chroot);
|
||||
|
||||
ct->listen_dot_sslctx = daemon_setup_listen_dot_sslctx(daemon, newcfg);
|
||||
if(!ct->listen_dot_sslctx)
|
||||
return 0;
|
||||
#ifdef HAVE_NGHTTP2_NGHTTP2_H
|
||||
if(cfg_has_https(newcfg)) {
|
||||
ct->listen_doh_sslctx = daemon_setup_listen_doh_sslctx(
|
||||
daemon, newcfg);
|
||||
if(!ct->listen_doh_sslctx)
|
||||
return 0;
|
||||
}
|
||||
#endif
|
||||
#ifdef HAVE_NGTCP2
|
||||
if(cfg_has_quic(newcfg)) {
|
||||
ct->listen_quic_sslctx = daemon_setup_listen_quic_sslctx(
|
||||
daemon, newcfg);
|
||||
if(!ct->listen_quic_sslctx)
|
||||
return 0;
|
||||
}
|
||||
#endif /* HAVE_NGTCP2 */
|
||||
ct->connect_dot_sslctx = daemon_setup_connect_dot_sslctx(daemon,
|
||||
newcfg);
|
||||
if(!ct->connect_dot_sslctx)
|
||||
return 0;
|
||||
|
||||
/* Store mtime and names */
|
||||
ct->ssl_service_key = strdup(newcfg->ssl_service_key);
|
||||
@@ -6631,9 +6853,12 @@ fr_reload_config(struct fast_reload_thread* fr, struct config_file* newcfg,
|
||||
}
|
||||
#ifdef USE_DNSTAP
|
||||
if(env->cfg->dnstap) {
|
||||
if(!fr->fr_nopause)
|
||||
dt_apply_cfg(daemon->dtenv, env->cfg);
|
||||
else dt_apply_logcfg(daemon->dtenv, env->cfg);
|
||||
if(!fr->fr_nopause) {
|
||||
if(!dt_apply_cfg(daemon->dtenv, env->cfg))
|
||||
log_warn("fast_reload: dnstap identity/version metadata not updated due to allocation failure");
|
||||
} else {
|
||||
dt_apply_logcfg(daemon->dtenv, env->cfg);
|
||||
}
|
||||
}
|
||||
#endif
|
||||
fr_adjust_cache(env, ct->oldcfg);
|
||||
@@ -6773,6 +6998,10 @@ fr_load_config(struct fast_reload_thread* fr, struct timeval* time_read,
|
||||
config_delete(newcfg);
|
||||
return 0;
|
||||
}
|
||||
if(!fr_check_tag_datas(fr, newcfg)) {
|
||||
config_delete(newcfg);
|
||||
return 0;
|
||||
}
|
||||
if(!fr_check_compat_cfg(fr, newcfg)) {
|
||||
config_delete(newcfg);
|
||||
return 0;
|
||||
@@ -6864,7 +7093,7 @@ static void* fast_reload_thread_main(void* arg)
|
||||
#endif
|
||||
log_thread_set(&fast_reload_thread->threadnum);
|
||||
|
||||
ub_thread_setname(fast_reload_thread->tid, name);
|
||||
ub_thread_setname(ub_thread_self(), name);
|
||||
(void)name; /* When setname is not defined, ignore the name variable. */
|
||||
|
||||
verbose(VERB_ALGO, "start fast reload thread");
|
||||
@@ -7587,7 +7816,8 @@ auth_zone_zonemd_stop_lookup(struct auth_zone* z, struct mesh_area* mesh)
|
||||
qinfo.local_alias = NULL;
|
||||
|
||||
mesh_remove_callback(mesh, &qinfo, qflags,
|
||||
&auth_zonemd_dnskey_lookup_callback, z);
|
||||
&auth_zonemd_dnskey_lookup_callback, z,
|
||||
z->zonemd_callback_unique_info);
|
||||
}
|
||||
|
||||
/** Pick up the auth zone locks. */
|
||||
@@ -7696,6 +7926,9 @@ auth_xfr_pickup_config(struct auth_xfer* loadxfr, struct auth_xfer* xfr)
|
||||
log_assert(loadxfr->namelabs == xfr->namelabs);
|
||||
log_assert(loadxfr->dclass == xfr->dclass);
|
||||
|
||||
xfr->max_transfer_size = loadxfr->max_transfer_size;
|
||||
xfr->max_transfer_time = loadxfr->max_transfer_time;
|
||||
|
||||
/* The lists can be swapped in, the other xfr struct will be deleted
|
||||
* afterwards. */
|
||||
probe_masters = xfr->task_probe->masters;
|
||||
@@ -7720,6 +7953,16 @@ fr_worker_auth_add(struct worker* worker, struct fast_reload_auth_change* item,
|
||||
/* The xfr item needs to be created. The auth zones lock
|
||||
* is held to make this possible. */
|
||||
xfr = auth_xfer_create(worker->env.auth_zones, item->new_z);
|
||||
if(!xfr) {
|
||||
log_err("out of memory in fr_worker_auth_add");
|
||||
lock_rw_unlock(&item->new_z->lock);
|
||||
lock_rw_unlock(&worker->env.auth_zones->lock);
|
||||
lock_rw_unlock(&worker->daemon->fast_reload_thread->old_auth_zones->lock);
|
||||
if(loadxfr) {
|
||||
lock_basic_unlock(&loadxfr->lock);
|
||||
}
|
||||
return;
|
||||
}
|
||||
auth_xfr_pickup_config(loadxfr, xfr);
|
||||
/* Serial information is copied into the xfr struct. */
|
||||
if(!xfr_find_soa(item->new_z, xfr)) {
|
||||
@@ -7789,6 +8032,17 @@ fr_worker_auth_cha(struct worker* worker, struct fast_reload_auth_change* item)
|
||||
} else if(loadxfr && !xfr) {
|
||||
/* Create the xfr. */
|
||||
xfr = auth_xfer_create(worker->env.auth_zones, item->new_z);
|
||||
if(!xfr) {
|
||||
log_err("out of memory in fr_worker_auth_cha");
|
||||
lock_rw_unlock(&item->new_z->lock);
|
||||
lock_rw_unlock(&item->old_z->lock);
|
||||
lock_rw_unlock(&worker->daemon->fast_reload_thread->old_auth_zones->lock);
|
||||
lock_rw_unlock(&worker->env.auth_zones->lock);
|
||||
if(loadxfr) {
|
||||
lock_basic_unlock(&loadxfr->lock);
|
||||
}
|
||||
return;
|
||||
}
|
||||
auth_xfr_pickup_config(loadxfr, xfr);
|
||||
item->new_z->zone_is_slave = 1;
|
||||
}
|
||||
|
||||
+1
-7
@@ -49,6 +49,7 @@
|
||||
#include <openssl/ssl.h>
|
||||
#endif
|
||||
#include "util/locks.h"
|
||||
#include "libunbound/remote.h"
|
||||
struct config_file;
|
||||
struct listen_list;
|
||||
struct listen_port;
|
||||
@@ -365,13 +366,6 @@ void fast_reload_thread_start(RES* ssl, struct worker* worker,
|
||||
*/
|
||||
void fast_reload_thread_stop(struct fast_reload_thread* fast_reload_thread);
|
||||
|
||||
/** fast reload thread commands to remote service thread event callback */
|
||||
void fast_reload_service_cb(int fd, short bits, void* arg);
|
||||
|
||||
/** fast reload callback for the remote control client connection */
|
||||
int fast_reload_client_callback(struct comm_point* c, void* arg, int err,
|
||||
struct comm_reply* rep);
|
||||
|
||||
/** fast reload printq delete list */
|
||||
void fast_reload_printq_list_delete(struct fast_reload_printq* list);
|
||||
|
||||
|
||||
+22
-6
@@ -422,12 +422,28 @@ void server_stats_obtain(struct worker* worker, struct worker* who,
|
||||
# endif
|
||||
#endif
|
||||
);
|
||||
log_err("server_stats_obtain: no response from worker %d "
|
||||
"(stats timeout); returning zero stats for this worker",
|
||||
who->thread_num);
|
||||
/* A later reply from the worker, would be sizeof stats reply,
|
||||
* and the worker_handle_control_cmd routine discards if
|
||||
* it is not a 4byte command, when that is received here. */
|
||||
memset(s, 0, sizeof(*s));
|
||||
return;
|
||||
}
|
||||
if(!tube_read_msg(worker->cmd, &reply, &len, 0)) {
|
||||
log_err("server_stats_obtain: failed to read stats from worker "
|
||||
"(tube read error); returning zero stats for this worker");
|
||||
memset(s, 0, sizeof(*s));
|
||||
return;
|
||||
}
|
||||
if(len != (uint32_t)sizeof(*s)) {
|
||||
log_err("server_stats_obtain: wrong stats length %d (expected %d); "
|
||||
"discarding", (int)len, (int)sizeof(*s));
|
||||
free(reply);
|
||||
memset(s, 0, sizeof(*s));
|
||||
return;
|
||||
}
|
||||
if(!tube_read_msg(worker->cmd, &reply, &len, 0))
|
||||
fatal_exit("failed to read stats over cmd channel");
|
||||
if(len != (uint32_t)sizeof(*s))
|
||||
fatal_exit("stats on cmd channel wrong length %d %d",
|
||||
(int)len, (int)sizeof(*s));
|
||||
memcpy(s, reply, (size_t)len);
|
||||
free(reply);
|
||||
}
|
||||
@@ -439,7 +455,7 @@ void server_stats_reply(struct worker* worker, int reset)
|
||||
verbose(VERB_ALGO, "write stats replymsg");
|
||||
if(!tube_write_msg(worker->daemon->workers[0]->cmd,
|
||||
(uint8_t*)&s, sizeof(s), 0))
|
||||
fatal_exit("could not write stat values over cmd channel");
|
||||
log_err("could not write stat values over cmd channel");
|
||||
}
|
||||
|
||||
void server_stats_add(struct ub_stats_info* total, struct ub_stats_info* a)
|
||||
|
||||
+28
-13
@@ -501,7 +501,9 @@ worker_handle_control_cmd(struct tube* ATTR_UNUSED(tube), uint8_t* msg,
|
||||
return;
|
||||
}
|
||||
if(len != sizeof(uint32_t)) {
|
||||
fatal_exit("bad control msg length %d", (int)len);
|
||||
verbose(VERB_ALGO, "bad control msg length %d", (int)len);
|
||||
free(msg);
|
||||
return;
|
||||
}
|
||||
cmd = sldns_read_uint32(msg);
|
||||
free(msg);
|
||||
@@ -714,7 +716,8 @@ apply_respip_action(struct worker* worker, const struct query_info* qinfo,
|
||||
struct respip_client_info* cinfo, struct reply_info* rep,
|
||||
struct sockaddr_storage* addr, socklen_t addrlen,
|
||||
struct ub_packed_rrset_key** alias_rrset,
|
||||
struct reply_info** encode_repp, struct auth_zones* az)
|
||||
struct reply_info** encode_repp, struct auth_zones* az,
|
||||
int* rpz_passthru)
|
||||
{
|
||||
struct respip_action_info actinfo = {0, 0, 0, 0, NULL, 0, NULL};
|
||||
actinfo.action = respip_none;
|
||||
@@ -725,7 +728,7 @@ apply_respip_action(struct worker* worker, const struct query_info* qinfo,
|
||||
return 1;
|
||||
|
||||
if(!respip_rewrite_reply(qinfo, cinfo, rep, encode_repp, &actinfo,
|
||||
alias_rrset, 0, worker->scratchpad, az, NULL,
|
||||
alias_rrset, 0, worker->scratchpad, az, rpz_passthru,
|
||||
worker->env.views, worker->env.respip_set))
|
||||
return 0;
|
||||
|
||||
@@ -772,7 +775,7 @@ answer_from_cache(struct worker* worker, struct query_info* qinfo,
|
||||
int* is_secure_answer, struct ub_packed_rrset_key** alias_rrset,
|
||||
struct reply_info** partial_repp,
|
||||
struct reply_info* rep, uint16_t id, uint16_t flags,
|
||||
struct comm_reply* repinfo, struct edns_data* edns)
|
||||
struct comm_reply* repinfo, struct edns_data* edns, int* rpz_passthru)
|
||||
{
|
||||
time_t timenow = *worker->env.now;
|
||||
uint16_t udpsize = edns->udp_size;
|
||||
@@ -882,7 +885,7 @@ answer_from_cache(struct worker* worker, struct query_info* qinfo,
|
||||
if((worker->daemon->use_response_ip || worker->daemon->use_rpz) &&
|
||||
!partial_rep && !apply_respip_action(worker, qinfo, cinfo, rep,
|
||||
&repinfo->client_addr, repinfo->client_addrlen, alias_rrset,
|
||||
&encode_rep, worker->env.auth_zones)) {
|
||||
&encode_rep, worker->env.auth_zones, rpz_passthru)) {
|
||||
goto bail_out;
|
||||
} else if(partial_rep &&
|
||||
!respip_merge_cname(partial_rep, qinfo, rep, cinfo,
|
||||
@@ -1494,6 +1497,8 @@ worker_handle_request(struct comm_point* c, void* arg, int error,
|
||||
struct reply_info* partial_rep = NULL;
|
||||
struct query_info* lookup_qinfo = &qinfo;
|
||||
struct query_info qinfo_tmp; /* placeholder for lookup_qinfo */
|
||||
uint8_t* alias_orig_qname = NULL; /* original qname for logs, if
|
||||
a local_alias is used to change the qname. */
|
||||
struct respip_client_info* cinfo = NULL, cinfo_tmp;
|
||||
struct timeval wait_time;
|
||||
struct check_request_result check_result = {0,0};
|
||||
@@ -1511,7 +1516,7 @@ worker_handle_request(struct comm_point* c, void* arg, int error,
|
||||
if (worker->stats.max_query_time_us < wait_queue_time)
|
||||
worker->stats.max_query_time_us = wait_queue_time;
|
||||
if(wait_queue_time >
|
||||
(long long)(worker->env.cfg->sock_queue_timeout * 1000000)) {
|
||||
(long long)worker->env.cfg->sock_queue_timeout * 1000000) {
|
||||
/* count and drop queries that were sitting in the socket queue too long */
|
||||
worker->stats.num_queries_timed_out++;
|
||||
return 0;
|
||||
@@ -1936,6 +1941,11 @@ worker_handle_request(struct comm_point* c, void* arg, int error,
|
||||
/* If we've found a local alias, replace the qname with the alias
|
||||
* target before resolving it. */
|
||||
if(qinfo.local_alias) {
|
||||
if(qinfo.local_alias->rrset &&
|
||||
qinfo.local_alias->rrset->rk.dname)
|
||||
/* Store the original qname, used for logs, since
|
||||
* local_alias can be removed by region_free_all. */
|
||||
alias_orig_qname = qinfo.local_alias->rrset->rk.dname;
|
||||
if(!local_alias_shallow_copy_qname(qinfo.local_alias, &qinfo.qname,
|
||||
&qinfo.qname_len)) {
|
||||
regional_free_all(worker->scratchpad);
|
||||
@@ -1983,7 +1993,7 @@ lookup_cache:
|
||||
&alias_rrset, &partial_rep, rep,
|
||||
*(uint16_t*)(void *)sldns_buffer_begin(c->buffer),
|
||||
sldns_buffer_read_u16_at(c->buffer, 2), repinfo,
|
||||
&edns)) {
|
||||
&edns, &rpz_passthru)) {
|
||||
/* prefetch it if the prefetch TTL expired.
|
||||
* Note that if there is more than one pass
|
||||
* its qname must be that used for cache
|
||||
@@ -2101,11 +2111,10 @@ send_reply_rc:
|
||||
{
|
||||
struct timeval tv;
|
||||
memset(&tv, 0, sizeof(tv));
|
||||
if(qinfo.local_alias && qinfo.local_alias->rrset &&
|
||||
qinfo.local_alias->rrset->rk.dname) {
|
||||
if(alias_orig_qname) {
|
||||
/* log original qname, before the local alias was
|
||||
* used to resolve that CNAME to something else */
|
||||
qinfo.qname = qinfo.local_alias->rrset->rk.dname;
|
||||
qinfo.qname = alias_orig_qname;
|
||||
log_reply_info(NO_VERBOSE, &qinfo,
|
||||
&repinfo->client_addr, repinfo->client_addrlen,
|
||||
tv, 1, c->buffer,
|
||||
@@ -2374,6 +2383,8 @@ worker_init(struct worker* worker, struct config_file *cfg,
|
||||
worker_stat_timer_cb, worker);
|
||||
if(!worker->stat_timer) {
|
||||
log_err("could not create statistics timer");
|
||||
worker_delete(worker);
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* we use the msg_buffer_size as a good estimate for what the
|
||||
@@ -2526,6 +2537,8 @@ worker_delete(struct worker* worker)
|
||||
/* don't touch worker->alloc, as it's maintained in daemon */
|
||||
regional_destroy(worker->env.scratch);
|
||||
regional_destroy(worker->scratchpad);
|
||||
/* The thread id can reference this worker's id value, so clear it. */
|
||||
log_thread_set(NULL);
|
||||
free(worker);
|
||||
}
|
||||
|
||||
@@ -2534,7 +2547,8 @@ worker_send_query(struct query_info* qinfo, uint16_t flags, int dnssec,
|
||||
int want_dnssec, int nocaps, int check_ratelimit,
|
||||
struct sockaddr_storage* addr, socklen_t addrlen, uint8_t* zone,
|
||||
size_t zonelen, int tcp_upstream, int ssl_upstream, char* tls_auth_name,
|
||||
struct module_qstate* q, int* was_ratelimited)
|
||||
struct module_qstate* q, int* was_ratelimited,
|
||||
int* ratelimit_incremented)
|
||||
{
|
||||
struct worker* worker = q->env->worker;
|
||||
struct outbound_entry* e = (struct outbound_entry*)regional_alloc(
|
||||
@@ -2546,7 +2560,7 @@ worker_send_query(struct query_info* qinfo, uint16_t flags, int dnssec,
|
||||
want_dnssec, nocaps, check_ratelimit, tcp_upstream,
|
||||
ssl_upstream, tls_auth_name, addr, addrlen, zone, zonelen, q,
|
||||
worker_handle_service_reply, e, worker->back->udp_buff, q->env,
|
||||
was_ratelimited);
|
||||
was_ratelimited, ratelimit_incremented);
|
||||
if(!e->qsent) {
|
||||
return NULL;
|
||||
}
|
||||
@@ -2595,7 +2609,8 @@ struct outbound_entry* libworker_send_query(
|
||||
struct sockaddr_storage* ATTR_UNUSED(addr), socklen_t ATTR_UNUSED(addrlen),
|
||||
uint8_t* ATTR_UNUSED(zone), size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream),
|
||||
int ATTR_UNUSED(ssl_upstream), char* ATTR_UNUSED(tls_auth_name),
|
||||
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited))
|
||||
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited),
|
||||
int* ATTR_UNUSED(ratelimit_incremented))
|
||||
{
|
||||
log_assert(0);
|
||||
return 0;
|
||||
|
||||
+59
-8
@@ -643,6 +643,12 @@ handle_event_moddone(struct module_qstate* qstate, int id)
|
||||
qstate->return_msg->rep &&
|
||||
reply_find_answer_rrset(&qstate->qinfo, qstate->return_msg->rep);
|
||||
int synth_qname = 0;
|
||||
if(could_synth && !has_data && qstate->env->need_to_validate &&
|
||||
qstate->return_msg && qstate->return_msg->rep &&
|
||||
qstate->return_msg->rep->security == sec_status_bogus) {
|
||||
verbose(VERB_ALGO, "dns64: bogus AAAA reply not synthesized");
|
||||
could_synth = 0;
|
||||
}
|
||||
|
||||
if(could_synth &&
|
||||
(!has_data ||
|
||||
@@ -654,8 +660,11 @@ handle_event_moddone(struct module_qstate* qstate, int id)
|
||||
|
||||
/* Store the response in cache. */
|
||||
if( (!iq || !iq->started_no_cache_store) &&
|
||||
!qstate->rpz_applied && !qstate->rpz_passthru &&
|
||||
!qstate->is_subnet_answer &&
|
||||
qstate->return_msg &&
|
||||
qstate->return_msg->rep &&
|
||||
!qstate->fwd_stub_no_cache &&
|
||||
!dns_cache_store(
|
||||
qstate->env, &qstate->qinfo, qstate->return_msg->rep,
|
||||
0, qstate->prefetch_leeway, 0, NULL,
|
||||
@@ -717,8 +726,15 @@ dns64_operate(struct module_qstate* qstate, enum module_ev event, int id,
|
||||
}
|
||||
if(qstate->ext_state[id] == module_finished) {
|
||||
iq = (struct dns64_qstate*)qstate->minfo[id];
|
||||
if(iq && iq->state != DNS64_INTERNAL_QUERY)
|
||||
qstate->no_cache_store = iq->started_no_cache_store;
|
||||
if(iq && iq->state != DNS64_INTERNAL_QUERY) {
|
||||
if(qstate->fwd_stub_no_cache) {
|
||||
/* If the forward/stub has no cache, then
|
||||
* continue with the query with no cache. */
|
||||
qstate->no_cache_store = qstate->fwd_stub_no_cache;
|
||||
} else {
|
||||
qstate->no_cache_store = iq->started_no_cache_store;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -825,6 +841,7 @@ dns64_adjust_a(int id, struct module_qstate* super, struct module_qstate* qstate
|
||||
size_t i, s;
|
||||
struct packed_rrset_data* fd, *dd;
|
||||
struct ub_packed_rrset_key* fk, *dk;
|
||||
int allocated_return_msg = 0;
|
||||
|
||||
verbose(VERB_ALGO, "converting A answers to AAAA answers");
|
||||
|
||||
@@ -840,6 +857,7 @@ dns64_adjust_a(int id, struct module_qstate* super, struct module_qstate* qstate
|
||||
return;
|
||||
memset(super->return_msg, 0, sizeof(*super->return_msg));
|
||||
super->return_msg->qinfo = super->qinfo;
|
||||
allocated_return_msg = 1;
|
||||
}
|
||||
|
||||
rep = qstate->return_msg->rep;
|
||||
@@ -852,11 +870,14 @@ dns64_adjust_a(int id, struct module_qstate* super, struct module_qstate* qstate
|
||||
rep->serve_expired_norec_ttl,
|
||||
rep->an_numrrsets, rep->ns_numrrsets, rep->ar_numrrsets,
|
||||
rep->rrset_count, rep->security, LDNS_EDE_NONE);
|
||||
if(!cp)
|
||||
if(!cp) {
|
||||
if(allocated_return_msg) super->return_msg = NULL;
|
||||
return;
|
||||
}
|
||||
|
||||
/* allocate ub_key structures special or not */
|
||||
if(!reply_info_alloc_rrset_keys(cp, NULL, super->region)) {
|
||||
if(allocated_return_msg) super->return_msg = NULL;
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -871,8 +892,10 @@ dns64_adjust_a(int id, struct module_qstate* super, struct module_qstate* qstate
|
||||
if(i<rep->an_numrrsets && fk->rk.type == htons(LDNS_RR_TYPE_A)) {
|
||||
/* also sets dk->entry.hash */
|
||||
dns64_synth_aaaa_data(fk, fd, dk, &dd, super->region, dns64_env);
|
||||
if(!dd)
|
||||
if(!dd) {
|
||||
if(allocated_return_msg) super->return_msg = NULL;
|
||||
return;
|
||||
}
|
||||
/* Delete negative AAAA record from cache stored by
|
||||
* the iterator module */
|
||||
rrset_cache_remove(super->env->rrset_cache, dk->rk.dname,
|
||||
@@ -889,15 +912,19 @@ dns64_adjust_a(int id, struct module_qstate* super, struct module_qstate* qstate
|
||||
dk->rk.dname = (uint8_t*)regional_alloc_init(super->region,
|
||||
fk->rk.dname, fk->rk.dname_len);
|
||||
|
||||
if(!dk->rk.dname)
|
||||
if(!dk->rk.dname) {
|
||||
if(allocated_return_msg) super->return_msg = NULL;
|
||||
return;
|
||||
}
|
||||
|
||||
s = packed_rrset_sizeof(fd);
|
||||
dd = (struct packed_rrset_data*)regional_alloc_init(
|
||||
super->region, fd, s);
|
||||
|
||||
if(!dd)
|
||||
if(!dd) {
|
||||
if(allocated_return_msg) super->return_msg = NULL;
|
||||
return;
|
||||
}
|
||||
}
|
||||
|
||||
packed_rrset_ptr_fixup(dd);
|
||||
@@ -928,8 +955,10 @@ dns64_adjust_ptr(struct module_qstate* qstate, struct module_qstate* super)
|
||||
return;
|
||||
super->return_msg->qinfo = super->qinfo;
|
||||
if (!(super->return_msg->rep = reply_info_copy(qstate->return_msg->rep,
|
||||
NULL, super->region)))
|
||||
NULL, super->region))) {
|
||||
super->return_msg = NULL;
|
||||
return;
|
||||
}
|
||||
|
||||
/*
|
||||
* Adjust the domain name of the answer RR set so that it matches the
|
||||
@@ -998,6 +1027,21 @@ dns64_inform_super(struct module_qstate* qstate, int id,
|
||||
/* Use return code from A query in response to client. */
|
||||
if (super->return_rcode != LDNS_RCODE_NOERROR)
|
||||
super->return_rcode = qstate->return_rcode;
|
||||
/* RPZ applied to the subquery need to then change (not cache)
|
||||
* the super query. With the super query not cached, it is
|
||||
* going to run the state machine modules on incoming queries,
|
||||
* that fetch the subquery (cache) response, and modify it
|
||||
* according to the rpz policy. That makes the synthesized
|
||||
* super query also adjusted by rpz policies. But loses cache
|
||||
* hits. Even though the subquery likely is answered from cache,
|
||||
* internally in its state machine process. */
|
||||
if(qstate->rpz_applied)
|
||||
super->rpz_applied = 1;
|
||||
if(qstate->rpz_passthru)
|
||||
super->rpz_passthru = 1;
|
||||
|
||||
/* Since the super qstate has a new response, its errinf is removed. */
|
||||
super->errinf = NULL;
|
||||
|
||||
/* Generate a response suitable for the original query. */
|
||||
if (qstate->qinfo.qtype == LDNS_RR_TYPE_A) {
|
||||
@@ -1006,9 +1050,16 @@ dns64_inform_super(struct module_qstate* qstate, int id,
|
||||
log_assert(qstate->qinfo.qtype == LDNS_RR_TYPE_PTR);
|
||||
dns64_adjust_ptr(qstate, super);
|
||||
}
|
||||
/* If the sub-query has no cache store, then also the super query. */
|
||||
if(qstate->fwd_stub_no_cache)
|
||||
super->fwd_stub_no_cache = 1;
|
||||
|
||||
/* Store the generated response in cache. */
|
||||
if ( (!super_dq || !super_dq->started_no_cache_store) &&
|
||||
if ( super->return_msg && super->return_msg->rep &&
|
||||
(!super_dq || !super_dq->started_no_cache_store) &&
|
||||
!qstate->fwd_stub_no_cache &&
|
||||
!super->rpz_applied && !super->rpz_passthru &&
|
||||
!super->is_subnet_answer &&
|
||||
!dns_cache_store(super->env, &super->qinfo, super->return_msg->rep,
|
||||
0, super->prefetch_leeway, 0, NULL, super->query_flags,
|
||||
qstate->qstarttime, qstate->is_valrec))
|
||||
|
||||
+8
-1
@@ -842,7 +842,14 @@ dnsc_parse_keys(struct dnsc_env *env, struct config_file *cfg)
|
||||
if(memcmp(current_keypair->crypt_publickey,
|
||||
env->signed_certs[c].server_publickey,
|
||||
crypto_box_PUBLICKEYBYTES) == 0) {
|
||||
dnsccert *current_cert = &env->certs[cert_id++];
|
||||
dnsccert* current_cert;
|
||||
if(cert_id >= env->signed_certs_count) {
|
||||
log_err("dnscrypt: secret key %s matches a cert that "
|
||||
"is already bound to another key (duplicate "
|
||||
"dnscrypt-secret-key?)", head->str);
|
||||
return -1;
|
||||
}
|
||||
current_cert = &env->certs[cert_id++];
|
||||
found_cert = 1;
|
||||
current_cert->keypair = current_keypair;
|
||||
memcpy(current_cert->magic_query,
|
||||
|
||||
+36
-17
@@ -176,26 +176,29 @@ dt_create(struct config_file* cfg)
|
||||
env->dtio = dt_io_thread_create();
|
||||
if(!env->dtio) {
|
||||
log_err("malloc failure");
|
||||
free(env);
|
||||
dt_delete(env);
|
||||
return NULL;
|
||||
}
|
||||
if(!dt_io_thread_apply_cfg(env->dtio, cfg)) {
|
||||
dt_io_thread_delete(env->dtio);
|
||||
free(env);
|
||||
dt_delete(env);
|
||||
return NULL;
|
||||
}
|
||||
if(!dt_apply_cfg(env, cfg)) {
|
||||
dt_delete(env);
|
||||
return NULL;
|
||||
}
|
||||
dt_apply_cfg(env, cfg);
|
||||
return env;
|
||||
}
|
||||
|
||||
static void
|
||||
static int
|
||||
dt_apply_identity(struct dt_env *env, struct config_file *cfg)
|
||||
{
|
||||
char buf[MAXHOSTNAMELEN+1];
|
||||
if (!cfg->dnstap_send_identity) {
|
||||
free(env->identity);
|
||||
env->identity = NULL;
|
||||
return;
|
||||
env->len_identity = 0;
|
||||
return 1;
|
||||
}
|
||||
free(env->identity);
|
||||
if (cfg->dnstap_identity == NULL || cfg->dnstap_identity[0] == 0) {
|
||||
@@ -203,36 +206,49 @@ dt_apply_identity(struct dt_env *env, struct config_file *cfg)
|
||||
buf[MAXHOSTNAMELEN] = 0;
|
||||
env->identity = strdup(buf);
|
||||
} else {
|
||||
fatal_exit("dt_apply_identity: gethostname() failed");
|
||||
log_err("dt_apply_identity: gethostname() failed: %s",
|
||||
strerror(errno));
|
||||
env->identity = NULL;
|
||||
env->len_identity = 0;
|
||||
return 0;
|
||||
}
|
||||
} else {
|
||||
env->identity = strdup(cfg->dnstap_identity);
|
||||
}
|
||||
if (env->identity == NULL)
|
||||
fatal_exit("dt_apply_identity: strdup() failed");
|
||||
if (env->identity == NULL) {
|
||||
log_err("dt_apply_identity: strdup() failed");
|
||||
env->len_identity = 0;
|
||||
return 0;
|
||||
}
|
||||
env->len_identity = (unsigned int)strlen(env->identity);
|
||||
verbose(VERB_OPS, "dnstap identity field set to \"%s\"",
|
||||
env->identity);
|
||||
return 1;
|
||||
}
|
||||
|
||||
static void
|
||||
static int
|
||||
dt_apply_version(struct dt_env *env, struct config_file *cfg)
|
||||
{
|
||||
if (!cfg->dnstap_send_version) {
|
||||
free(env->version);
|
||||
env->version = NULL;
|
||||
return;
|
||||
env->len_version = 0;
|
||||
return 1;
|
||||
}
|
||||
free(env->version);
|
||||
if (cfg->dnstap_version == NULL || cfg->dnstap_version[0] == 0)
|
||||
env->version = strdup(PACKAGE_STRING);
|
||||
else
|
||||
env->version = strdup(cfg->dnstap_version);
|
||||
if (env->version == NULL)
|
||||
fatal_exit("dt_apply_version: strdup() failed");
|
||||
if (env->version == NULL) {
|
||||
log_err("dt_apply_version: strdup() failed");
|
||||
env->len_version = 0;
|
||||
return 0;
|
||||
}
|
||||
env->len_version = (unsigned int)strlen(env->version);
|
||||
verbose(VERB_OPS, "dnstap version field set to \"%s\"",
|
||||
env->version);
|
||||
return 1;
|
||||
}
|
||||
|
||||
void
|
||||
@@ -276,15 +292,18 @@ dt_apply_logcfg(struct dt_env *env, struct config_file *cfg)
|
||||
lock_basic_unlock(&env->sample_lock);
|
||||
}
|
||||
|
||||
void
|
||||
int
|
||||
dt_apply_cfg(struct dt_env *env, struct config_file *cfg)
|
||||
{
|
||||
if (!cfg->dnstap)
|
||||
return;
|
||||
return 1;
|
||||
|
||||
dt_apply_identity(env, cfg);
|
||||
dt_apply_version(env, cfg);
|
||||
dt_apply_logcfg(env, cfg);
|
||||
if(!dt_apply_identity(env, cfg))
|
||||
return 0;
|
||||
if(!dt_apply_version(env, cfg))
|
||||
return 0;
|
||||
return 1;
|
||||
}
|
||||
|
||||
int
|
||||
|
||||
+2
-2
@@ -102,9 +102,9 @@ dt_create(struct config_file* cfg);
|
||||
* Apply config settings.
|
||||
* @param env: dnstap environment object.
|
||||
* @param cfg: new config settings.
|
||||
* @return false on failure.
|
||||
*/
|
||||
void
|
||||
dt_apply_cfg(struct dt_env *env, struct config_file *cfg);
|
||||
int dt_apply_cfg(struct dt_env *env, struct config_file *cfg);
|
||||
|
||||
/**
|
||||
* Apply config settings for log enable for message types.
|
||||
|
||||
+1
-1
@@ -2144,7 +2144,7 @@ static void* dnstap_io(void* arg)
|
||||
#endif
|
||||
log_thread_set(&dtio->threadnum);
|
||||
|
||||
ub_thread_setname(dtio->tid, name);
|
||||
ub_thread_setname(ub_thread_self(), name);
|
||||
|
||||
/* setup */
|
||||
verbose(VERB_ALGO, "start dnstap io thread");
|
||||
|
||||
@@ -1659,7 +1659,8 @@ struct outbound_entry* worker_send_query(
|
||||
socklen_t ATTR_UNUSED(addrlen), uint8_t* ATTR_UNUSED(zone),
|
||||
size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream),
|
||||
int ATTR_UNUSED(ssl_upstream), char* ATTR_UNUSED(tls_auth_name),
|
||||
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited))
|
||||
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited),
|
||||
int* ATTR_UNUSED(ratelimit_incremented))
|
||||
{
|
||||
log_assert(0);
|
||||
return 0;
|
||||
@@ -1693,7 +1694,8 @@ struct outbound_entry* libworker_send_query(
|
||||
socklen_t ATTR_UNUSED(addrlen), uint8_t* ATTR_UNUSED(zone),
|
||||
size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream),
|
||||
int ATTR_UNUSED(ssl_upstream), char* ATTR_UNUSED(tls_auth_name),
|
||||
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited))
|
||||
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited),
|
||||
int* ATTR_UNUSED(ratelimit_incremented))
|
||||
{
|
||||
log_assert(0);
|
||||
return 0;
|
||||
|
||||
+622
@@ -1,3 +1,552 @@
|
||||
11 August 2026: Wouter
|
||||
- Fix #1492 from zacek: Data race in log_init() on
|
||||
key_created/log_lock when calling ub_ctx_create()
|
||||
concurrently from multiple threads.
|
||||
- Fix stat_values.tdir test to have less test failures.
|
||||
|
||||
7 August 2026: Wouter
|
||||
- Fix #1489 from jplesnik: Replace removed Python 2 C API
|
||||
macros for SWIG 4.5.0 compatibility.
|
||||
|
||||
6 August 2026: Alex Khanin
|
||||
- Fix #1488: bounds check in packed_rr_to_string, it checked
|
||||
the assembled rr length against the output string length
|
||||
dest_len, instead of against the size of the rr buffer it
|
||||
writes into. Callers in cachedump.c and remote.c pass a
|
||||
dest_len larger than that buffer.
|
||||
- Unit test for packed_rr_to_string.
|
||||
|
||||
6 August 2026: Wouter
|
||||
- Fix #1485: the list_forwards command omits port numbers.
|
||||
The list_forwards and list_stubs commands for
|
||||
unbound-control print port and tls auth name.
|
||||
- Fix #1487: regression in 1.26.0, ipsecmod is now always
|
||||
partly enabled.
|
||||
|
||||
4 August 2026: Wouter
|
||||
- Fix to set makedist.sh to not wget config.sub and
|
||||
config.guess from git repo. The fetch times out, and the
|
||||
version from libtoolize is much more recent now than
|
||||
that it was when the wget was added.
|
||||
|
||||
31 July 2026: Wouter
|
||||
- For #1483: The failure reason when an NSEC NXDOMAIN is
|
||||
encountered when looking for an insecure delegation, is
|
||||
fixed to mention the NSEC records, instead of nonexistent
|
||||
NSEC3 records, that it attempted.
|
||||
|
||||
30 July 2026: Wouter
|
||||
- Fix #1482: DNS-over-QUIC doesn't work with simple config.
|
||||
That fixes interface-automatic for use with doq service.
|
||||
|
||||
28 July 2026: Wouter
|
||||
- Tag for 1.26.0rc1. The repo continues with version 1.26.1.
|
||||
This became 1.26.0 on 4 aug 2026.
|
||||
|
||||
24 July 2026: Wouter
|
||||
- Merge #1433 from jisakiel: Add new static zone type
|
||||
block_aaaa to suppress AAAA queries.
|
||||
- Unit test for block_a and block_aaaa.
|
||||
- Fix #1477: respip + dns64: dns64 uses A records modified by
|
||||
respip instead of original A records. Adds local-zone types
|
||||
block_a_wdata and block_aaaa_wdata, that are like block_a
|
||||
and block_aaaa, and uses local-data if present.
|
||||
- set code repository version to 1.26.0.
|
||||
- Update generated man pages.
|
||||
- Fix to allow test fake sha1 on systems with possible sha1
|
||||
support.
|
||||
- Fix to use sha256 for unbound-anchor unit test.
|
||||
- Fix unbound-anchor check for return value of
|
||||
X509_NAME_get_text_by_NID of the emailaddress.
|
||||
- Fix lock test protect for auth zone change.
|
||||
- Fix to lock shared_ports structure during initialisation.
|
||||
- Fix to lock anchor structure when file is set for it in
|
||||
parse of the header.
|
||||
- Merge #1480 from petrvaganoff: authzone: fix memory leak in
|
||||
xfer_set_masters() error path.
|
||||
- Fix unused variable warnings in shared_ports_fetch_random
|
||||
and shared_ports_return_port when compiled without threads.
|
||||
- Fix to guard access to shared ports interface array during
|
||||
set up, for analyzer.
|
||||
- Fix sign of comparison warning in shared ports setup.
|
||||
- Fix #1481: Fix to use tls-port after referral if
|
||||
tls-upstream is set.
|
||||
- Merge #1479 from psumbera: Fix pthread detection on
|
||||
Solaris 11.4.
|
||||
- Fix to call OPENSSL_cleanup on exit when that is defined.
|
||||
|
||||
23 July 2026: Wouter
|
||||
- Updated credits for Xuanchao Xie in 22 july changelog.
|
||||
- Merge #1478 from petrvaganoff: pythonmod: add check return
|
||||
value after ftell().
|
||||
- Fix that for NSEC3 proofs the NSEC3 zone, as the b32.name is
|
||||
checked to be the same as the signer name. Also RRSIGs are
|
||||
not considered valid when an NSEC3 is not b32.signerzone.
|
||||
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix that the aggressive negative cache does not insert NSEC
|
||||
records with overreaching next owner name. Also the result
|
||||
is not above the trust anchor's bailiwick. Also RRSIGS are
|
||||
not considered valid when an NSEC next owner name is not
|
||||
under the signer zone name. Thanks to Qifan Zhang, Palo
|
||||
Alto Networks, for the report.
|
||||
- Fix mesh cycle detection for configuration with respip CNAME
|
||||
loop and tagged clients. Thanks to Qifan Zhang, Palo Alto
|
||||
Networks, for the report.
|
||||
|
||||
22 July 2026: Wouter
|
||||
- Release tag for 1.25.2, with the security commits:
|
||||
- Fix CVE-2026-14586, Assertion in libngtcp2 when under pressure
|
||||
in high concurrency DNS-over-QUIC environments. Thanks to Kunta
|
||||
Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University,
|
||||
for the report.
|
||||
- Fix CVE-2026-32665, Remote DNS-over-QUIC denial of
|
||||
service due to `quic-size` budget bypass. Thanks to N0zoM1z0
|
||||
(https://github.com/N0zoM1z0) for the report. In addition, thanks to
|
||||
Kunta Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University,
|
||||
for also reporting this issue. In addition, thanks to Qifan Zhang,
|
||||
Palo Alto Networks, for also reporting this issue. In addition,
|
||||
thanks to Xuanchao Xie, Lutong Chen, and Kaiping Xue of the
|
||||
University of Science and Technology of China (USTC), for also
|
||||
reporting this issue.
|
||||
- Fix CVE-2026-40691, Packet of death for DNSCrypt over TCP. Thanks
|
||||
to Qifan Zhang, Palo Alto Networks, for the report. In addition,
|
||||
thanks to Trung Nguyen (@everping) of CyStack, for also reporting
|
||||
this issue.
|
||||
- Fix CVE-2026-41637, Degradation of resolution service from
|
||||
improperly accounted client-terminated DNS-over-QUIC queries. Thanks
|
||||
to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix CVE-2026-42955, Extra fix for CVE-2026-40622 to also clamp
|
||||
the TTL of A/AAAA records disallowing a one-time 'ghost domain'
|
||||
delegation renewal via glue records. Thanks to Qifan Zhang, Palo
|
||||
Alto Networks, for the report.
|
||||
- Fix CVE-2026-44621, Libunbound applications configured with
|
||||
'unwanted-reply-threshold' could eventually be abruptly
|
||||
terminated. Thanks to Qifan Zhang, Palo Alto Networks, for the
|
||||
report.
|
||||
- Fix CVE-2026-44687, Off-by-one error in 'harden-below-nxdomain'
|
||||
logic can shadow a stub/forward zone by a legitimate parent's
|
||||
NXDOMAIN. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix CVE-2026-44690, Cross-zone wildcard cache poisoning via
|
||||
RRSIG.labels manipulation. Thanks to Qifan Zhang, Palo Alto
|
||||
Networks, for the report.
|
||||
- Fix CVE-2026-46582, A wildcard replay, as another piece of data,
|
||||
triggers poisoning in the serve expired reply path. Thanks to
|
||||
Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix CVE-2026-50045, 'max-global-quota' reset by DNSSEC validation
|
||||
restarts. Thanks to Kunjie Shang, University of Science and
|
||||
Technology of China, for the report.
|
||||
- Fix CVE-2026-50046, Possible heap use-after-free in an error path
|
||||
when a DoT forwarded query is jostled out. Thanks to Qifan Zhang,
|
||||
Palo Alto Networks, for the report.
|
||||
- Fix CVE-2026-50243, 'response-ip'/'rpz' can rewrite BOGUS answers
|
||||
instead of returning SERVFAIL. Thanks to Qifan Zhang, Palo Alto
|
||||
Networks, for the report.
|
||||
- Fix CVE-2026-50248, BOGUS configured primary hostname accepted for
|
||||
XFR in auth/rpz zones. Thanks to Qifan Zhang, Palo Alto Networks,
|
||||
for the report.
|
||||
- Fix CVE-2026-50251, Attacker supplied `0.0.0.0`/`::` glue triggers
|
||||
defensive full-cache flush. Thanks to Qifan Zhang, Palo Alto
|
||||
Networks, for the report.
|
||||
- Fix CVE-2026-50252, Possible cache poisoning attack by mapping
|
||||
source port population per thread. Thanks to Inbal Schussheim and
|
||||
Amit Klein, Hebrew University, for the report.
|
||||
- Fix CVE-2026-52863, Memory corruption could lead to crash and
|
||||
denial of service. Thanks to Qifan Zhang, Palo Alto Networks,
|
||||
for the report.
|
||||
- Fix CVE-2026-54478, DNS Cookie bypass when combined with
|
||||
proxy-protocol use. Thanks to Qifan Zhang, Palo Alto Networks,
|
||||
for the report.
|
||||
- Fix CVE-2026-55708, Privacy/configuration issue when adding local
|
||||
data in views through 'unbound-control'. Thanks to Qifan Zhang,
|
||||
Palo Alto Networks, for the report.
|
||||
- Fix CVE-2026-55717, 'serve-expired-client-timeout' and 'response-ip'
|
||||
CNAME redirect could lead to a crash. Thanks to Qifan Zhang, Palo
|
||||
Alto Networks, for the report. In addition, thanks to Xin Wang,
|
||||
Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University,
|
||||
for also reporting this issue.
|
||||
- Fix CVE-2026-55973, 'dns-error-reporting: yes' leads to stack buffer
|
||||
overflow. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix CVE-2026-55990, Packet of death for a DNSCrypt misconfigured
|
||||
Unbound. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix CVE-2026-55991, Remote DNS-over-QUIC (DoQ) flow-control
|
||||
assertion failure in libngtcp2. Thanks to Qifan Zhang, Palo Alto
|
||||
Networks, for the report. In addition, thanks to Xuanchao Xie,
|
||||
Lutong Chen, and Kaiping Xue of the University of Science and
|
||||
Technology of China (USTC), for also reporting this issue.
|
||||
- Fix CVE-2026-56416, Possible heap buffer overflow when validator
|
||||
canonicalizes RDATA that contains domain name. Thanks to Qifan
|
||||
Zhang, Palo Alto Networks, for the report.
|
||||
- Fix CVE-2026-56444, Degradation of resolution service when
|
||||
'discard-timeout' and 'serve-expired-client-timeout' are combined in
|
||||
unusual configuration. Thanks to Qifan Zhang, Palo Alto Networks,
|
||||
for the report. In addition, thanks to Xin Wang, Jiapeng Li,
|
||||
and Jiajia Liu, Northwestern Polytechnical University, for also
|
||||
reporting this issue. In addition, thanks to Haruki Oyama (Waseda
|
||||
University), for also reporting this issue.
|
||||
- Set the repository to 1.25.3, it continues with the previous
|
||||
changes.
|
||||
- Unit test for CVE-2026-42955.
|
||||
- Unit test for CVE-2026-44687.
|
||||
- Unit test for CVE-2026-44690.
|
||||
- Unit test for CVE-2026-46582.
|
||||
- Unit test for CVE-2026-50045.
|
||||
- Unit test for CVE-2026-50243.
|
||||
- Unit test for CVE-2026-50248.
|
||||
- Unit test for CVE-2026-55717.
|
||||
- Unit test for CVE-2026-55973.
|
||||
- Unit test for CVE-2026-56416.
|
||||
- Fix error in log printout in fix for CVE-2026-50248, when the
|
||||
primary name is bogus.
|
||||
- iana portlist update.
|
||||
|
||||
21 July 2026: Wouter
|
||||
- Merge #1476 from petrvaganoff: ipsecmod: fix possible deref
|
||||
on null after reply_find_answer_rrset().
|
||||
|
||||
20 July 2026: Wouter
|
||||
- Merge #1475 from petrvaganoff: ipsecmod: fix deref on null
|
||||
in ipsecmod-whitelist after OOM.
|
||||
- Fix #1474: DoQ responses are never padded - pad-responses
|
||||
does not apply to comm_doq (RFC 9250 §5.4 MUST).
|
||||
|
||||
9 July 2026: Wouter
|
||||
- Merge #1383 from jdek: Fix randomness generation on
|
||||
macOS/iOS under chroot.
|
||||
- Fix unit test for malformed svcb for test on Windows.
|
||||
|
||||
2 July 2026: Wouter
|
||||
- Merge #1087: Overload `local_data_remove` to support removing
|
||||
specific records.
|
||||
|
||||
30 June 2026: Wouter
|
||||
- Fix #1469: dohclient: DoH POST missing content-length → :status
|
||||
400 from strict resolvers (Cloudflare, Mullvad).
|
||||
- iana portlist updated.
|
||||
|
||||
26 June 2026: Wouter
|
||||
- Merge #1467: daemon: fix DEREF_AFTER_NULL.EX.COND on
|
||||
worker_init. This fixes error handling if the worker
|
||||
stat_timer allocation has an out of memory error. That
|
||||
makes the server not crash later, attempting to use it.
|
||||
|
||||
24 June 2026: Wouter
|
||||
- Merge #1465 from dag-erling: Add libunbound/remote.h. Add
|
||||
a shared header containing prototypes for functions that
|
||||
both ends of a remote control connection need to implement.
|
||||
|
||||
19 June 2026: Wouter
|
||||
- Fix for #1457: fix thread setname for thread start of
|
||||
dnstap, and fast_reload.
|
||||
- Fix to update github ci actions/checkout to v7.
|
||||
- Fix warning about file_string_matches in unbound-checkconf.
|
||||
|
||||
17 June 2026: Wouter
|
||||
- Fix that after fast_reload the disown of the auth zone
|
||||
transfer task cleans the chunk list. Also fix the
|
||||
auth_transfer_limit test to use a forwarder for each type
|
||||
of failure, so the one is not blocked by the other waiting.
|
||||
- Fix to remove debug from auth_transfer_limit test.
|
||||
- Fix that unbound-checkconf checks if an auth-zone download
|
||||
can overwrite another file, by filename collision.
|
||||
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix that malloc failure in auth-zone insert rr does
|
||||
not create an empty node and does not cause an infinite
|
||||
loop. Thanks to Qifan Zhang, Palo Alto Networks, for
|
||||
the report.
|
||||
- Fix that unbound-control auth_zone_reload stops the
|
||||
server answering from the zone after a failure to read.
|
||||
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix that malloc failure in dns64_inform_super does
|
||||
not set up a half-built reply for cache store, that could
|
||||
lead to a crash. Thanks to Qifan Zhang, Palo Alto Networks,
|
||||
for the report.
|
||||
- Fix that malloc failure for new_local_rrset for RPZ qname
|
||||
trigger RR insert does not crash. It does not link a
|
||||
partial RRset, and logs an error on failure, and cleans
|
||||
up the dname allocation. Thanks to Qifan Zhang, Palo Alto
|
||||
Networks, for the report.
|
||||
- Fix that malloc failure in doq connection setup, does
|
||||
not crash in doq connection delete later. Thanks to Qifan
|
||||
Zhang, Palo Alto Networks, for the report.
|
||||
- Fix that malloc failure for ngtcp2_conn_server_new
|
||||
cleans up reference that older ngtcp2 versions can leave.
|
||||
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix that on malloc failure during accept of TCP, the
|
||||
socket is not left to cause a read event loop. It uses
|
||||
slow-accept to delay accepting new connections, if
|
||||
that fails it drops the new connections. When the tcp
|
||||
connection usage is full, it waits for 50msec, to allow
|
||||
existing queries to be resolved. Thanks to Qifan Zhang,
|
||||
Palo Alto Networks, for the report.
|
||||
- Fix that malloc failure for rpz_strip_nsdname is
|
||||
checked and handled, so that it does not crash later.
|
||||
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix that malloc failure during edns subnet addrtree
|
||||
insert is checked, so it does not crash later. Thanks to
|
||||
Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix to check the return value of auth_xfer_create
|
||||
during fast_reload auth-zone add and change processing.
|
||||
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix to check for malloc failure in rpz response create,
|
||||
for nodata and nxdomain, so it does not crash later.
|
||||
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix that fast_reload does not terminate the server
|
||||
on malloc failure for dnstap, or if gethostname fails.
|
||||
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix after malloc failure for stats, then it drains the pipe
|
||||
so the internal messaging stays correct. Also it does
|
||||
not exit the server if stats pipe communication fails.
|
||||
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix that fast_reload does not terminate the server
|
||||
on config read failure after malloc failure. Thanks to
|
||||
Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix that fast_reload does not terminate the server if
|
||||
random init for DNS cookies fails. The data is only random
|
||||
generated if cookies are enabled, and the random data
|
||||
is necessary. Thanks to Qifan Zhang, Palo Alto Networks,
|
||||
for the report.
|
||||
|
||||
17 June 2026: Yorgos
|
||||
- Fix memory leak on DNAME 0TTL records.
|
||||
|
||||
16 June 2026: Wouter
|
||||
- Fix to disallow $INCLUDE for secondary zones. Start up
|
||||
of server continues if a secondary zone fails to load.
|
||||
Failed loads clear the zone data, so there is no partial
|
||||
zone. Thanks to Qifan Zhang, Palo Alto Networks, for
|
||||
the report.
|
||||
- Fix that when SVCB records cannot be written out, and
|
||||
are written in unknown format, that the zone read allows
|
||||
such unknown format SVCB records. Thanks to Qifan Zhang,
|
||||
Palo Alto Networks, for the report.
|
||||
- Fix that a half-written trust anchor file does not crash
|
||||
the server at runtime. It unlinks a wrong file from the list.
|
||||
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix that auth-zone, and RPZ zones, do not allow out-of-zone
|
||||
records. These are records that are not under the zone apex.
|
||||
The out-of-zone records are dropped from the zone contents.
|
||||
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix that dns64 does not ignore the `forward-no-cache` and
|
||||
`stub-no-cache` options. Thanks to Qifan Zhang, Palo Alto
|
||||
Networks, for the report.
|
||||
- Fix that a signed wildcard NSEC, is checked before use,
|
||||
so it does not allow insecure DS proofs inappropriately.
|
||||
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix that after malloc failure a half-built local_alias does
|
||||
not crash the server. Thanks to Qifan Zhang, Palo Alto
|
||||
Networks, for the report.
|
||||
- Fix that for a zonefile only zone, if that file does not
|
||||
exist on server start, the server continues to start with
|
||||
a warning log message. Thanks to Qifan Zhang, Palo Alto
|
||||
Networks, for the report.
|
||||
- Fix that after malloc failure in RPZ load a half built
|
||||
list does not crash later. The newly created RRset is
|
||||
linked after creation has succeeded. Thanks to Qifan Zhang,
|
||||
Palo Alto Networks, for the report.
|
||||
- Fix that dnscrypt configuration does not crash, due to
|
||||
inconsistency between secret and public keys. Also
|
||||
duplicate files are skipped. Thanks to Qifan Zhang, Palo
|
||||
Alto Networks, for the report.
|
||||
- Fix locking in libunbound ub_ctx_set_event call.
|
||||
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix that libunbound pipe functions fail with error after
|
||||
an event base is set. Thanks to Qifan Zhang, Palo Alto
|
||||
Networks, for the report.
|
||||
- Fix for neater solution to clear log thread id after
|
||||
worker init failure. Thanks to Qifan Zhang, Palo Alto
|
||||
Networks, for the report.
|
||||
- Fix incorrect cleanup after an allocation failure for
|
||||
a delegation point. Thanks to Qifan Zhang, Palo Alto
|
||||
Networks, for the report.
|
||||
- Fix that after malloc failure in find_tag_datas, the
|
||||
local_alias is cleaned up. Thanks to Qifan Zhang, Palo
|
||||
Alto Networks, for the report.
|
||||
- Fix that after shared memory cannot be created, from
|
||||
`shm-enable`, the server does not crash. Thanks to Qifan
|
||||
Zhang, Palo Alto Networks, for the report.
|
||||
- Fix incorrect cleanup after an allocation failure for
|
||||
a delegation point in a region. Thanks to Qifan Zhang,
|
||||
Palo Alto Networks, for the report.
|
||||
- Fix after malloc failure the rrset_insert_rr in
|
||||
localzone processing, during RPZ qname trigger processing,
|
||||
the RRset retains its previous data correcly. Thanks to
|
||||
Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix for #1462: Fix that auth primary host name lookup
|
||||
allows CNAMEs.
|
||||
|
||||
15 June 2026: Wouter
|
||||
- Fix to add `max-transfer-size` and `max-transfer-time` that
|
||||
limit auth-zone and rpz transfer amount and time taken.
|
||||
Default is disabled. This hardens against unbounded
|
||||
transfers. Thanks to Qifan Zhang, Palo Alto Networks,
|
||||
for the report.
|
||||
- Fix perform a full transfer every number of incremental
|
||||
transfers, to stop increasing memory usage, for rpz
|
||||
zones. Thanks to Qifan Zhang, Palo Alto Networks, for
|
||||
the report.
|
||||
- Fix assertion failure for long HTTP header that fills
|
||||
buffer. Thanks to Qifan Zhang, Palo Alto Networks, for
|
||||
the report.
|
||||
- Fix buffer overflow when configured with lower than
|
||||
default size and http transfer. Thanks to Qifan Zhang,
|
||||
Palo Alto Networks, for the report.
|
||||
- Fix that misconfigured `iter-scrub-ns: 0` causes request
|
||||
failures. Thanks to Qifan Zhang, Palo Alto Networks,
|
||||
for the report.
|
||||
- Fix that fast_reload when a zonemd verification lookup
|
||||
it in progress with subnet loaded, deregisters the
|
||||
callback. Thanks to Qifan Zhang, Palo Alto Networks,
|
||||
for the report.
|
||||
- Fix for fast_reload that removes an auth zone while its
|
||||
lookups are in progress, for a primary name. Also after the
|
||||
change, it no longer picks up the old results. Thanks to
|
||||
Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix integer overflow in infra-cache-max-rtt calculation.
|
||||
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix erroneous DNS error report values after bogus AAAA
|
||||
query caused error information that was not cleared by
|
||||
a successful A subquery. Thanks to Qifan Zhang, Palo Alto
|
||||
Networks, for the report.
|
||||
- Fix integer overflow for very high values of
|
||||
`sock-queue-timeout`. Thanks to Qifan Zhang, Palo Alto
|
||||
Networks, for the report.
|
||||
- Fix that fast_reload does not terminate the server for
|
||||
errors in config, for key files. Thanks to Qifan Zhang,
|
||||
Palo Alto Networks, for the report.
|
||||
- Fix log of an aliased qname, to not use freed region
|
||||
memory. Thanks to Qifan Zhang, Palo Alto Networks, for
|
||||
the report.
|
||||
- Fix DNAME synthesis from cache that keeps use of 0TTL
|
||||
entries in a sliding window. It did not surpass RRSIG
|
||||
expiry. Thanks to Qifan Zhang, Palo Alto Networks, for
|
||||
the report.
|
||||
- Fix misconfigured ipsecmod hook causing path name
|
||||
similarity with other file. The ipsecmod is changed for
|
||||
exec of the hook. The ipsecmod hook, if a script, has to
|
||||
start now with a line like `#!/bin/sh`. Thanks to Qifan
|
||||
Zhang, Palo Alto Networks, for the report.
|
||||
- Fix that dns64 bypasses rpz-passthru rule during
|
||||
synthesis. This restricted more than necessary. Thanks to
|
||||
Qifan Zhang, Palo Alto Networks, for the report.
|
||||
|
||||
12 June 2026: Wouter
|
||||
- Fix that for auth-zone and rpz zones the allow-notify
|
||||
addresses and netblocks are available from start, and
|
||||
fix the probe step skip.
|
||||
|
||||
11 June 2026: Wouter
|
||||
- Fix for #1306: configure detects specifically the call to
|
||||
SSL_set_quic_tls_early_data_enabled and
|
||||
SSL_set_quic_early_data_enabled, so the correct one is used.
|
||||
- Fix for #1306: configure checks if the ngtcp2_crypto_ossl
|
||||
header file is available, and prints an error otherwise.
|
||||
- Fix #1437: Fix compile with OpenSSL 4.0.1.
|
||||
- Fix compile for OpenSSL 1.0.2 and before in server cleanup.
|
||||
|
||||
10 June 2026: Wouter
|
||||
- Fix pythonmod script read for numeric overflow.
|
||||
- Fix warnings with gcc in compat/inet_pton.c.
|
||||
|
||||
9 June 2026: Wouter
|
||||
- Fix unit test for ecs to check for malloc success.
|
||||
|
||||
3 June 2026: Wouter
|
||||
- Fix that the processing of class responses does not have
|
||||
a heap use-after-free. That could happen if at least two
|
||||
distinct classes are configured for resolution. Thanks
|
||||
to Qifan Zhang, Palo Alto Networks for the report.
|
||||
In addition, thanks to Xin Wang, Jiapeng Li, and Jiajia
|
||||
Liu, Northwestern Polytechnical University, for also
|
||||
reporting this.
|
||||
- Fix negative cache to work with NSEC3 records without salt.
|
||||
Thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern
|
||||
Polytechnical University, for the report.
|
||||
- Fix parse of svcbparam ech, it had incorrect length. Thanks
|
||||
to Qifan Zhang, Palo Alto Networks for the report.
|
||||
- Fix that quotation and escaping works the same in auth-zone
|
||||
url content, as in the zonefile read. Thanks to Qifan Zhang,
|
||||
Palo Alto Networks for the report.
|
||||
- Fix ipset module to use larger domain name buffers, and
|
||||
check buffer lengths. Thanks to Qifan Zhang, Palo Alto
|
||||
Networks for the report.
|
||||
- Fix PROXYv2 header read and consume, it checks the header
|
||||
size. Thanks to Qifan Zhang, Palo Alto Networks for
|
||||
the report.
|
||||
- Fix negative cache NSEC3 nodata proof, to use the correct
|
||||
message size. Thanks to Qifan Zhang, Palo Alto Networks,
|
||||
for the report.
|
||||
- Fix fast_reload for when a ZONEMD lookup is in progress.
|
||||
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix that validation canonicalization of domain names
|
||||
in rdata checks for buffer bounds. Thanks to Qifan Zhang,
|
||||
Palo Alto Networks, for the report.
|
||||
- Fix that dump_cache has a larger buffer for records,
|
||||
and it checks that an owner name does not collide with BADRR
|
||||
on the input, and changes verbosity on the log of failure in
|
||||
rrset to string. Thanks to Qifan Zhang, Palo Alto Networks,
|
||||
for the report.
|
||||
- Fix that dns64 cleans up the allocated message if the adjust
|
||||
routines fail, and checks if there is a reply before cache
|
||||
store, also unbound checks if A and AAAA are malformed
|
||||
for auth-zones. Thanks to Qifan Zhang, Palo Alto Networks,
|
||||
for the report.
|
||||
|
||||
3 June 2026: Yorgos
|
||||
- Fix const as reported by newest compiler warnings.
|
||||
|
||||
29 May 2026: Wouter
|
||||
- Fix header_seen detection for trust anchor files, so that it
|
||||
detects the id line.
|
||||
- iana portlist updated.
|
||||
- Update icannbundle.pem certificates in unbound-anchor. It
|
||||
has the public keys for 2009 to 2029 and for 2025 to 2045.
|
||||
- Fix unit test to check for new icannbundle.pem.
|
||||
|
||||
28 May 2026: Wouter
|
||||
- Fix #1457: race condition causes segfault when starting
|
||||
threads.
|
||||
|
||||
27 May 2026: Wouter
|
||||
- Fix for autotrust state-file line overflow, that can give
|
||||
hold-down bypass. Thanks to Qifan Zhang, Palo Alto Networks,
|
||||
for the report.
|
||||
- Fix to limit the DSNS per-label walk in the iterator. Thanks
|
||||
to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix that the ratelimit is decremented on successful
|
||||
referrals. Thanks to Qifan Zhang, Palo Alto Networks, for
|
||||
the report.
|
||||
- Fix that msgencode insert_query has the correct assertion,
|
||||
for a local_alias. Thanks to Qifan Zhang, Palo Alto Networks,
|
||||
for the report.
|
||||
- Fix to reset the tcp-timeout before applying a load based
|
||||
reduction. Thanks to Qifan Zhang, Palo Alto Networks, for the
|
||||
report.
|
||||
- Fix to decrement the per-netblock tcp connection limits, so
|
||||
it keeps usable. Thanks to Qifan Zhang, Palo Alto Networks,
|
||||
for the report.
|
||||
- Fix manual to document ratelimit, that it is for target
|
||||
nameservers for a domain, and keeps queries limited. Thanks
|
||||
to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix, in depth, for respip rewrite of dns64 responses. Thanks
|
||||
to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix that dns64 with subnetcache does not write ECS scoped
|
||||
answers to global cache. Thanks to Qifan Zhang, Palo Alto
|
||||
Networks, for the report.
|
||||
- Fix ipset module for name too long checks, race conditions
|
||||
on local name buffer, and for socket close race condition.
|
||||
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Fix that validator caps number of ANY RRsets it can
|
||||
validate, and the wait timer is shortened. Thanks to Qifan
|
||||
Zhang, Palo Alto Networks, for the report.
|
||||
- Fix analyzer warning in mesh_new_client.
|
||||
|
||||
26 May 2026: Wouter
|
||||
- Fix for mesh new client and mesh new callback to rollback the
|
||||
added address, tcp mesh state and callback when there is a failure
|
||||
to initialize. This fixes the mesh accounting of reply addresses.
|
||||
Thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern
|
||||
Polytechnical University, for the report
|
||||
|
||||
20 May 2026: Wouter
|
||||
- Fix CVE-2026-33278, Possible remote code execution during DNSSEC
|
||||
validation. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
@@ -27,6 +576,79 @@
|
||||
Networks, for the report.
|
||||
- Fix CVE-2026-44608, Use after free and crash in RPZ code. Thanks
|
||||
to Qifan Zhang, Palo Alto Networks, for the report.
|
||||
- Tag for 1.25.1 release, it contains the security fixes on 1.25.0.
|
||||
the code repository continues with in addition the previous fixes,
|
||||
for 1.25.2.
|
||||
- Unit test for CVE-2026-33278.
|
||||
- Unit test for CVE-2026-42944.
|
||||
- Unit test for CVE-2026-42959.
|
||||
- Unit test for CVE-2026-40622.
|
||||
- Unit test for CVE-2026-42960.
|
||||
- Fix in depth for serve-expired responses from cachedb, that it
|
||||
does not store bogus. Thanks to Qifan Zhang, Palo Alto Networks,
|
||||
for the report.
|
||||
- Fix lame server detection, for selfpointed glue records.
|
||||
Thanks to Shuhan Zhang, Dan Li, and Baojun Liu from Tsinghua
|
||||
University for the report.
|
||||
- Fix cleaning up DoH session. The same query can be on multiple
|
||||
streams in a session. Thanks to Qifan Zhang, Palo Alto Networks,
|
||||
for the report.
|
||||
- Fix for signed same-owner CNAME and ordinary RRset responses.
|
||||
Thanks to Xin Wang and Jiajia Liu, Northwestern Polytechnical
|
||||
University, for the report.
|
||||
|
||||
18 May 2026: Wouter
|
||||
- Fix for mixed class referrals, the resolver uses the query
|
||||
class. Thanks to Xin Wang and Jiajia Liu, Northwestern
|
||||
Polytechnical University, for the report.
|
||||
|
||||
15 May 2026: Wouter
|
||||
- Fix man page entry for so-sndbuf, it is for responses sent out.
|
||||
- Fix val_find_DS for robustness, to check the result of
|
||||
packet_rrset_copy_region before using it. Thanks to Xin Wang
|
||||
and Jiajia Liu, Northwestern Polytechnical University, for
|
||||
the report.
|
||||
- Fix that for dns64 answers, the AAAA query is checked to be
|
||||
DNSSEC validated, when DNSSEC is enabled. This improves
|
||||
the RFC6147 conformance of Unbound. Thanks to Xin Wang
|
||||
and Jiajia Liu, Northwestern Polytechnical University, for
|
||||
the report. In addition, thanks to Qifan Zhang, Palo Alto
|
||||
Networks, for reporting it.
|
||||
- Fix for allocation-failure hardening of rrset cache wildcard
|
||||
storage and canonical NSEC owner replacement. Thanks to Xin
|
||||
Wang and Jiajia Liu, Northwestern Polytechnical University,
|
||||
for the report.
|
||||
- Fix DNSSEC validation with libnettle for noncanonical RSA
|
||||
DNSKEYs with leading zeroes for n. Thanks to Xin Wang and
|
||||
Jiajia Liu, Northwestern Polytechnical University, for
|
||||
the report.
|
||||
- Fix DNSKEY size calculation for noncanonical RSA DNSKEYs
|
||||
with leading zeroes for n. Thanks to Xin Wang and Jiajia Liu,
|
||||
Northwestern Polytechnical University, for the report.
|
||||
|
||||
11 May 2026: Yorgos
|
||||
- Fix comment and verbose logging for EDNS fallback buffer size.
|
||||
|
||||
8 May 2026: Wouter
|
||||
- Fix to relax assertions after the TTL 0 handling change.
|
||||
This relaxes an assertion in cachedb (it fails instead),
|
||||
and for packet_rrset_copy_region.
|
||||
|
||||
7 May 2026: Wouter
|
||||
- Fix for Heap Out-of-Bounds Write via size_t-to-int Truncation
|
||||
in setup_if() - outside_network_create(). This fixes that
|
||||
large values for num_ports do not overflow and create
|
||||
invalid references after integer truncation. Thanks
|
||||
to Karnakar Reddy (@karnakarreddi) for the report.
|
||||
- Fix to clean up log ids after a failure to start a worker thread.
|
||||
|
||||
1 May 2026: Wouter
|
||||
- iana portlist updated.
|
||||
|
||||
29 April 2026: Wouter
|
||||
- tag for 1.25.0. The code repository continues with 1.25.1 in
|
||||
development.
|
||||
- Fix windows 64bit build for libssp dependency.
|
||||
|
||||
23 April 2026: Wouter
|
||||
- Merge #1441: Fix buffer overrun in
|
||||
|
||||
@@ -899,6 +899,10 @@ server:
|
||||
# that name
|
||||
# o block_a resolves all records normally but returns
|
||||
# NODATA for A queries and ignores local data for that name
|
||||
# o block_aaaa similarly to block_a, resolves all records normally but
|
||||
# returns NODATA for AAAA queries and ignores local data for that name
|
||||
# o block_a_wdata like block_a but uses local data if present.
|
||||
# o block_aaaa_wdata like block_aaaa but uses local data if present.
|
||||
# o always_null returns 0.0.0.0 or ::0 for any name in the zone.
|
||||
# o noview breaks out of that view towards global local-zones.
|
||||
#
|
||||
@@ -1287,6 +1291,9 @@ remote-control:
|
||||
# zonemd-check: no
|
||||
# zonemd-reject-absence: no
|
||||
# zonefile: "example.org.zone"
|
||||
# max-transfer-size: 0
|
||||
# max-transfer-time: 0
|
||||
|
||||
|
||||
# Views
|
||||
# Create named views. Name must be unique.
|
||||
@@ -1453,3 +1460,5 @@ remote-control:
|
||||
# rpz-signal-nxdomain-ra: no
|
||||
# for-downstream: no
|
||||
# tags: "example"
|
||||
# max-transfer-size: 0
|
||||
# max-transfer-time: 0
|
||||
|
||||
@@ -354,6 +354,8 @@ If the name already has no items, nothing happens.
|
||||
Often results in NXDOMAIN for the name (in a static zone), but if the name
|
||||
has become an empty nonterminal (there is still data in domain names below
|
||||
the removed name), NOERROR nodata answers are the result for that name.
|
||||
With a specific RR instead of a domain name, that specific record is
|
||||
removed from the local data, and not all the RR data.
|
||||
.UNINDENT
|
||||
.INDENT 0.0
|
||||
.TP
|
||||
|
||||
@@ -347,6 +347,8 @@ There are several commands that the server understands.
|
||||
Often results in NXDOMAIN for the name (in a static zone), but if the name
|
||||
has become an empty nonterminal (there is still data in domain names below
|
||||
the removed name), NOERROR nodata answers are the result for that name.
|
||||
With a specific RR instead of a domain name, that specific record is
|
||||
removed from the local data, and not all the RR data.
|
||||
|
||||
|
||||
@@UAHL@unbound-control.commands@local_zones@@
|
||||
|
||||
+107
-1
@@ -691,7 +691,7 @@ Default: 0 (use system value)
|
||||
.TP
|
||||
.B so\-sndbuf: \fI<number>\fP
|
||||
If not 0, then set the SO_SNDBUF socket option to get more buffer space on
|
||||
UDP port 53 outgoing queries.
|
||||
UDP port 53 outgoing responses.
|
||||
This for very busy servers handles spikes in answer traffic, otherwise:
|
||||
.INDENT 7.0
|
||||
.INDENT 3.5
|
||||
@@ -2312,6 +2312,13 @@ The defensive action is to clear the rrset and message caches, hopefully
|
||||
flushing away any poison.
|
||||
A value of 10 million is suggested.
|
||||
.sp
|
||||
It is useful to add 0.0.0.0/8 and \(aq::\(aq to the
|
||||
\fI\%do\-not\-query\-address\fP list.
|
||||
Otherwise they may be answered, from localhost, and the different source
|
||||
makes an unwanted reply that unnecessarily ticks up.
|
||||
The \fI\%do\-not\-query\-localhost\fP
|
||||
option includes them, the zero subnets, when it is enabled.
|
||||
.sp
|
||||
Default: 0 (disabled)
|
||||
.UNINDENT
|
||||
.INDENT 0.0
|
||||
@@ -2362,6 +2369,8 @@ If yes, deny queries of type ANY with an empty response.
|
||||
If disabled, Unbound responds with a short list of resource records if some
|
||||
can be found in the cache and makes the upstream type ANY query if there
|
||||
are none.
|
||||
The option stops the DNSSEC validation from processing, possibly lengthy,
|
||||
ANY responses, when the option is enabled.
|
||||
.sp
|
||||
Default: no
|
||||
.UNINDENT
|
||||
@@ -2910,6 +2919,9 @@ The types are
|
||||
\fI\%inform_redirect\fP,
|
||||
\fI\%always_transparent\fP,
|
||||
\fI\%block_a\fP,
|
||||
\fI\%block_aaaa\fP,
|
||||
\fI\%block_a_wdata\fP,
|
||||
\fI\%block_aaaa_wdata\fP,
|
||||
\fI\%always_refuse\fP,
|
||||
\fI\%always_nxdomain\fP,
|
||||
\fI\%always_null\fP,
|
||||
@@ -3100,6 +3112,32 @@ use IPv6 protocol and avoid any queries to IPv4.
|
||||
.UNINDENT
|
||||
.INDENT 7.0
|
||||
.TP
|
||||
.B block_aaaa
|
||||
Like \fI\%transparent\fP or
|
||||
\fI\%block_a\fP, but
|
||||
ignores local data and resolves normally all query types excluding AAAA.
|
||||
For AAAA queries it unconditionally returns NODATA.
|
||||
Useful in cases when there is a need to explicitly force all apps to
|
||||
use IPv4 protocol and avoid any queries to IPv6.
|
||||
.UNINDENT
|
||||
.INDENT 7.0
|
||||
.TP
|
||||
.B block_a_wdata
|
||||
Like \fI\%block_a\fP, but
|
||||
uses local data if present.
|
||||
If there is local data that is returned, and it acts like transparent.
|
||||
For A queries it returns NODATA.
|
||||
.UNINDENT
|
||||
.INDENT 7.0
|
||||
.TP
|
||||
.B block_aaaa_wdata
|
||||
Like \fI\%block_aaaa\fP, but
|
||||
uses local data if present.
|
||||
If there is local data that is returned, and it acts like transparent.
|
||||
For AAAA queries it returns NODATA.
|
||||
.UNINDENT
|
||||
.INDENT 7.0
|
||||
.TP
|
||||
.B always_refuse
|
||||
Like \fI\%refuse\fP, but ignores
|
||||
local data and refuses the query.
|
||||
@@ -3567,6 +3605,18 @@ For example, 1000 may be a suitable value to stop the server from being
|
||||
overloaded with random names, and keeps unbound from sending traffic to the
|
||||
nameservers for those zones.
|
||||
.sp
|
||||
It is intended to count the number of queries towards the nameservers
|
||||
for the zone, and keep those queries limited.
|
||||
When there is a delegation that needs a lot of lookups, those are
|
||||
charged in the counters for the destination, the target name, of
|
||||
the NS records.
|
||||
Since that is where the nameserver lookup queries are sent to.
|
||||
That keeps the target, the victim domain, from having many queries.
|
||||
With the \fI\%ratelimit\-factor\fP, some
|
||||
genuine queries that are also made to the target zone, can filter
|
||||
through, and then end up in cache, where the genuine answers have
|
||||
a chance to collect, keeping up service to some extent.
|
||||
.sp
|
||||
\fBNOTE:\fP
|
||||
.INDENT 7.0
|
||||
.INDENT 3.5
|
||||
@@ -4594,6 +4644,32 @@ If not given then no zonefile is used.
|
||||
If the file does not exist or is empty, Unbound will attempt to fetch zone
|
||||
data (eg. from the primary servers).
|
||||
.UNINDENT
|
||||
.INDENT 0.0
|
||||
.TP
|
||||
.B max\-transfer\-size: \fI<number>\fP
|
||||
Number of bytes size of the maximum zone transfer size.
|
||||
Larger transfers, over AXFR, IXFR and HTTP, are not allowed.
|
||||
A plain number is in bytes, append \(aqk\(aq, \(aqm\(aq or \(aqg\(aq for kilobytes, megabytes
|
||||
or gigabytes (1024*1024 bytes in a megabyte).
|
||||
The value \fB0\fP disables the feature.
|
||||
.sp
|
||||
Only consider for untrusted/misbehaving primaries that could hog resources
|
||||
and bring down the resolver.
|
||||
.sp
|
||||
Default: 0
|
||||
.UNINDENT
|
||||
.INDENT 0.0
|
||||
.TP
|
||||
.B max\-transfer\-time: \fI<msec>\fP
|
||||
Maximum time in milliseconds that a zone transfer is allowed to take from
|
||||
the start.
|
||||
The value \fB0\fP disables the feature.
|
||||
.sp
|
||||
Only consider for untrusted/misbehaving primaries that could hog resources
|
||||
and bring down the resolver.
|
||||
.sp
|
||||
Default: 0
|
||||
.UNINDENT
|
||||
.SH VIEW OPTIONS
|
||||
.sp
|
||||
These options are part of the \fBview:\fP section.
|
||||
@@ -5806,6 +5882,10 @@ from a webserver that would work.
|
||||
If you specify the hostname, you cannot use the domain from the zonefile,
|
||||
because it may not have that when retrieving that data, instead use a plain
|
||||
IP address to avoid a circular dependency on retrieving that IP address.
|
||||
.sp
|
||||
Every number of IXFR transfers, a full AXFR is performed.
|
||||
This is to consolidate the rpz memory, that would otherwise grow.
|
||||
The fixed value is after 5 IXFR transfers.
|
||||
.UNINDENT
|
||||
.INDENT 0.0
|
||||
.TP
|
||||
@@ -5928,6 +6008,32 @@ Enclose list of tags in quotes (\fB\(dq\(dq\fP) and put spaces between tags.
|
||||
If no tags are specified the policies from this section will be applied for
|
||||
all clients.
|
||||
.UNINDENT
|
||||
.INDENT 0.0
|
||||
.TP
|
||||
.B max\-transfer\-size: \fI<number>\fP
|
||||
Number of bytes size of the maximum zone transfer size.
|
||||
Larger transfers, over AXFR, IXFR and HTTP, are not allowed.
|
||||
A plain number is in bytes, append \(aqk\(aq, \(aqm\(aq or \(aqg\(aq for kilobytes, megabytes
|
||||
or gigabytes (1024*1024 bytes in a megabyte).
|
||||
The value \fB0\fP disables the feature.
|
||||
.sp
|
||||
Only consider for untrusted/misbehaving primaries that could hog resources
|
||||
and bring down the resolver.
|
||||
.sp
|
||||
Default: 0
|
||||
.UNINDENT
|
||||
.INDENT 0.0
|
||||
.TP
|
||||
.B max\-transfer\-time: \fI<msec>\fP
|
||||
Maximum time in milliseconds that a zone transfer is allowed to take from
|
||||
the start.
|
||||
The value \fB0\fP disables the feature.
|
||||
.sp
|
||||
Only consider for untrusted/misbehaving primaries that could hog resources
|
||||
and bring down the resolver.
|
||||
.sp
|
||||
Default: 0
|
||||
.UNINDENT
|
||||
.SH MEMORY CONTROL EXAMPLE
|
||||
.sp
|
||||
In the example config settings below memory usage is reduced.
|
||||
|
||||
+92
-1
@@ -642,7 +642,7 @@ These options are part of the ``server:`` section.
|
||||
|
||||
@@UAHL@unbound.conf@so-sndbuf@@: *<number>*
|
||||
If not 0, then set the SO_SNDBUF socket option to get more buffer space on
|
||||
UDP port 53 outgoing queries.
|
||||
UDP port 53 outgoing responses.
|
||||
This for very busy servers handles spikes in answer traffic, otherwise:
|
||||
|
||||
.. code-block:: text
|
||||
@@ -2107,6 +2107,8 @@ These options are part of the ``server:`` section.
|
||||
If disabled, Unbound responds with a short list of resource records if some
|
||||
can be found in the cache and makes the upstream type ANY query if there
|
||||
are none.
|
||||
The option stops the DNSSEC validation from processing, possibly lengthy,
|
||||
ANY responses, when the option is enabled.
|
||||
|
||||
Default: no
|
||||
|
||||
@@ -2590,6 +2592,9 @@ These options are part of the ``server:`` section.
|
||||
:ref:`inform_redirect<unbound.conf.local-zone.type.inform_redirect>`,
|
||||
:ref:`always_transparent<unbound.conf.local-zone.type.always_transparent>`,
|
||||
:ref:`block_a<unbound.conf.local-zone.type.block_a>`,
|
||||
:ref:`block_aaaa<unbound.conf.local-zone.type.block_aaaa>`,
|
||||
:ref:`block_a_wdata<unbound.conf.local-zone.type.block_a_wdata>`,
|
||||
:ref:`block_aaaa_wdata<unbound.conf.local-zone.type.block_aaaa_wdata>`,
|
||||
:ref:`always_refuse<unbound.conf.local-zone.type.always_refuse>`,
|
||||
:ref:`always_nxdomain<unbound.conf.local-zone.type.always_nxdomain>`,
|
||||
:ref:`always_null<unbound.conf.local-zone.type.always_null>`,
|
||||
@@ -2739,6 +2744,26 @@ These options are part of the ``server:`` section.
|
||||
Useful in cases when there is a need to explicitly force all apps to
|
||||
use IPv6 protocol and avoid any queries to IPv4.
|
||||
|
||||
@@UAHL@unbound.conf.local-zone.type@block_aaaa@@
|
||||
Like :ref:`transparent<unbound.conf.local-zone.type.transparent>` or
|
||||
:ref:`block_a<unbound.conf.local-zone.type.block_a>`, but
|
||||
ignores local data and resolves normally all query types excluding AAAA.
|
||||
For AAAA queries it unconditionally returns NODATA.
|
||||
Useful in cases when there is a need to explicitly force all apps to
|
||||
use IPv4 protocol and avoid any queries to IPv6.
|
||||
|
||||
@@UAHL@unbound.conf.local-zone.type@block_a_wdata@@
|
||||
Like :ref:`block_a<unbound.conf.local-zone.type.block_a>`, but
|
||||
uses local data if present.
|
||||
If there is local data that is returned, and it acts like transparent.
|
||||
For A queries it returns NODATA.
|
||||
|
||||
@@UAHL@unbound.conf.local-zone.type@block_aaaa_wdata@@
|
||||
Like :ref:`block_aaaa<unbound.conf.local-zone.type.block_aaaa>`, but
|
||||
uses local data if present.
|
||||
If there is local data that is returned, and it acts like transparent.
|
||||
For AAAA queries it returns NODATA.
|
||||
|
||||
@@UAHL@unbound.conf.local-zone.type@always_refuse@@
|
||||
Like :ref:`refuse<unbound.conf.local-zone.type.refuse>`, but ignores
|
||||
local data and refuses the query.
|
||||
@@ -3085,6 +3110,18 @@ These options are part of the ``server:`` section.
|
||||
overloaded with random names, and keeps unbound from sending traffic to the
|
||||
nameservers for those zones.
|
||||
|
||||
It is intended to count the number of queries towards the nameservers
|
||||
for the zone, and keep those queries limited.
|
||||
When there is a delegation that needs a lot of lookups, those are
|
||||
charged in the counters for the destination, the target name, of
|
||||
the NS records.
|
||||
Since that is where the nameserver lookup queries are sent to.
|
||||
That keeps the target, the victim domain, from having many queries.
|
||||
With the :ref:`ratelimit-factor<unbound.conf.ratelimit-factor>`, some
|
||||
genuine queries that are also made to the target zone, can filter
|
||||
through, and then end up in cache, where the genuine answers have
|
||||
a chance to collect, keeping up service to some extent.
|
||||
|
||||
.. note:: Configured forwarders are excluded from ratelimiting.
|
||||
|
||||
Default: 0
|
||||
@@ -4018,6 +4055,31 @@ fallback activates to fetch from the upstream instead of the SERVFAIL.
|
||||
If the file does not exist or is empty, Unbound will attempt to fetch zone
|
||||
data (eg. from the primary servers).
|
||||
|
||||
|
||||
@@UAHL@unbound.conf.auth@max-transfer-size@@: *<number>*
|
||||
Number of bytes size of the maximum zone transfer size.
|
||||
Larger transfers, over AXFR, IXFR and HTTP, are not allowed.
|
||||
A plain number is in bytes, append 'k', 'm' or 'g' for kilobytes, megabytes
|
||||
or gigabytes (1024*1024 bytes in a megabyte).
|
||||
The value ``0`` disables the feature.
|
||||
|
||||
Only consider for untrusted/misbehaving primaries that could hog resources
|
||||
and bring down the resolver.
|
||||
|
||||
Default: 0
|
||||
|
||||
|
||||
@@UAHL@unbound.conf.auth@max-transfer-time@@: *<msec>*
|
||||
Maximum time in milliseconds that a zone transfer is allowed to take from
|
||||
the start.
|
||||
The value ``0`` disables the feature.
|
||||
|
||||
Only consider for untrusted/misbehaving primaries that could hog resources
|
||||
and bring down the resolver.
|
||||
|
||||
Default: 0
|
||||
|
||||
|
||||
.. _unbound.conf.view:
|
||||
|
||||
View Options
|
||||
@@ -5098,6 +5160,10 @@ answer queries with that content.
|
||||
because it may not have that when retrieving that data, instead use a plain
|
||||
IP address to avoid a circular dependency on retrieving that IP address.
|
||||
|
||||
Every number of IXFR transfers, a full AXFR is performed.
|
||||
This is to consolidate the rpz memory, that would otherwise grow.
|
||||
The fixed value is after 5 IXFR transfers.
|
||||
|
||||
|
||||
@@UAHL@unbound.conf.rpz@master@@: *<IP address or host name>*
|
||||
Alternate syntax for :ref:`primary<unbound.conf.rpz.primary>`.
|
||||
@@ -5198,6 +5264,31 @@ answer queries with that content.
|
||||
If no tags are specified the policies from this section will be applied for
|
||||
all clients.
|
||||
|
||||
|
||||
@@UAHL@unbound.conf.rpz@max-transfer-size@@: *<number>*
|
||||
Number of bytes size of the maximum zone transfer size.
|
||||
Larger transfers, over AXFR, IXFR and HTTP, are not allowed.
|
||||
A plain number is in bytes, append 'k', 'm' or 'g' for kilobytes, megabytes
|
||||
or gigabytes (1024*1024 bytes in a megabyte).
|
||||
The value ``0`` disables the feature.
|
||||
|
||||
Only consider for untrusted/misbehaving primaries that could hog resources
|
||||
and bring down the resolver.
|
||||
|
||||
Default: 0
|
||||
|
||||
|
||||
@@UAHL@unbound.conf.rpz@max-transfer-time@@: *<msec>*
|
||||
Maximum time in milliseconds that a zone transfer is allowed to take from
|
||||
the start.
|
||||
The value ``0`` disables the feature.
|
||||
|
||||
Only consider for untrusted/misbehaving primaries that could hog resources
|
||||
and bring down the resolver.
|
||||
|
||||
Default: 0
|
||||
|
||||
|
||||
Memory Control Example
|
||||
----------------------
|
||||
|
||||
|
||||
@@ -459,6 +459,7 @@ addrtree_insert(struct addrtree *tree, const addrkey_t *addr,
|
||||
/* Data is stored in other leafnode */
|
||||
node = newnode;
|
||||
newnode = node_create(tree, elem, scope, ttl);
|
||||
if (!newnode) return;
|
||||
if (!edge_create(newnode, addr, sourcemask, node,
|
||||
index^1)) {
|
||||
clean_node(tree, newnode);
|
||||
|
||||
@@ -1015,6 +1015,7 @@ subnetmod_operate(struct module_qstate *qstate, enum module_ev event,
|
||||
subnet_ecs_opt_list_append(&sq->ecs_client_out,
|
||||
&qstate->edns_opts_front_out, qstate,
|
||||
qstate->region);
|
||||
qstate->is_subnet_answer = 1;
|
||||
}
|
||||
sq->wait_subquery_done = 0;
|
||||
qstate->ext_state[id] = module_finished;
|
||||
@@ -1094,6 +1095,7 @@ subnetmod_operate(struct module_qstate *qstate, enum module_ev event,
|
||||
qstate->env->cfg->prefetch)) {
|
||||
sne->num_msg_cache++;
|
||||
lock_rw_unlock(&sne->biglock);
|
||||
qstate->is_subnet_answer = 1;
|
||||
verbose(VERB_QUERY, "subnetcache: answered from cache");
|
||||
qstate->ext_state[id] = module_finished;
|
||||
|
||||
@@ -1165,6 +1167,7 @@ subnetmod_operate(struct module_qstate *qstate, enum module_ev event,
|
||||
subnet_ecs_opt_list_append(&sq->ecs_client_out,
|
||||
&qstate->edns_opts_front_out, qstate,
|
||||
qstate->region);
|
||||
qstate->is_subnet_answer = 1;
|
||||
if(verbosity >= VERB_ALGO) {
|
||||
subnet_log_print("reply has edns subnet",
|
||||
edns_opt_list_find(
|
||||
|
||||
@@ -100,6 +100,8 @@ ipsecmod_whitelist_apply_cfg(struct ipsecmod_env* ie,
|
||||
struct config_file* cfg)
|
||||
{
|
||||
ie->whitelist = rbtree_create(name_tree_compare);
|
||||
if (!ie->whitelist)
|
||||
return 0;
|
||||
if(!read_whitelist(ie->whitelist, cfg))
|
||||
return 0;
|
||||
name_tree_init_parents(ie->whitelist);
|
||||
|
||||
+91
-37
@@ -51,18 +51,28 @@
|
||||
#include "util/config_file.h"
|
||||
#include "services/cache/dns.h"
|
||||
#include "sldns/wire2str.h"
|
||||
#ifdef HAVE_SYS_WAIT_H
|
||||
#include <sys/wait.h>
|
||||
#endif
|
||||
|
||||
/** Apply configuration to ipsecmod module 'global' state. */
|
||||
static int
|
||||
ipsecmod_apply_cfg(struct ipsecmod_env* ipsecmod_env, struct config_file* cfg)
|
||||
{
|
||||
if(cfg->ipsecmod_whitelist &&
|
||||
!ipsecmod_whitelist_apply_cfg(ipsecmod_env, cfg))
|
||||
return 0;
|
||||
if(!cfg->ipsecmod_enabled)
|
||||
return 1;
|
||||
if(!cfg->ipsecmod_hook || (cfg->ipsecmod_hook && !cfg->ipsecmod_hook[0])) {
|
||||
log_err("ipsecmod: missing ipsecmod-hook.");
|
||||
return 0;
|
||||
}
|
||||
if(cfg->ipsecmod_whitelist &&
|
||||
!ipsecmod_whitelist_apply_cfg(ipsecmod_env, cfg))
|
||||
if(access(cfg->ipsecmod_hook, X_OK) != 0) {
|
||||
log_err("ipsecmod: ipsecmod-hook '%s' is not an executable file: %s",
|
||||
cfg->ipsecmod_hook, strerror(errno));
|
||||
return 0;
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -250,27 +260,16 @@ call_hook(struct module_qstate* qstate, struct ipsecmod_qstate* iq,
|
||||
struct ipsecmod_env* ATTR_UNUSED(ie))
|
||||
{
|
||||
size_t slen, tempdata_len, tempstring_len, i;
|
||||
char str[65535], *s, *tempstring;
|
||||
char qname_s[LDNS_MAX_DOMAINLEN*5+16], ttl_s[32], a_s[32768], k_s[32768];
|
||||
char *s, *tempstring;
|
||||
int w = 0, w_temp, qtype;
|
||||
struct ub_packed_rrset_key* rrset_key;
|
||||
struct packed_rrset_data* rrset_data;
|
||||
uint8_t *tempdata;
|
||||
pid_t pid;
|
||||
int st;
|
||||
char* argv[6];
|
||||
|
||||
/* Check if a shell is available */
|
||||
if(system(NULL) == 0) {
|
||||
log_err("ipsecmod: no shell available for ipsecmod-hook");
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* Zero the buffer. */
|
||||
s = str;
|
||||
slen = sizeof(str);
|
||||
memset(s, 0, slen);
|
||||
|
||||
/* Copy the hook into the buffer. */
|
||||
w += sldns_str_print(&s, &slen, "%s", qstate->env->cfg->ipsecmod_hook);
|
||||
/* Put space into the buffer. */
|
||||
w += sldns_str_print(&s, &slen, " ");
|
||||
/* Copy the qname into the buffer. */
|
||||
tempstring = sldns_wire2str_dname(qstate->qinfo.qname,
|
||||
qstate->qinfo.qname_len);
|
||||
@@ -283,17 +282,24 @@ call_hook(struct module_qstate* qstate, struct ipsecmod_qstate* iq,
|
||||
free(tempstring);
|
||||
return 0;
|
||||
}
|
||||
w += sldns_str_print(&s, &slen, "\"%s\"", tempstring);
|
||||
if(strlen(tempstring)+1 > sizeof(qname_s)) {
|
||||
log_err("ipsecmod: string too long");
|
||||
free(tempstring);
|
||||
return 0;
|
||||
}
|
||||
snprintf(qname_s, sizeof(qname_s), "%s", tempstring);
|
||||
free(tempstring);
|
||||
/* Put space into the buffer. */
|
||||
w += sldns_str_print(&s, &slen, " ");
|
||||
|
||||
/* Copy the IPSECKEY TTL into the buffer. */
|
||||
rrset_data = (struct packed_rrset_data*)iq->ipseckey_rrset->entry.data;
|
||||
w += sldns_str_print(&s, &slen, "\"%ld\"", (long)rrset_data->ttl);
|
||||
/* Put space into the buffer. */
|
||||
w += sldns_str_print(&s, &slen, " ");
|
||||
snprintf(ttl_s, sizeof(ttl_s), "%ld", (long)rrset_data->ttl);
|
||||
|
||||
rrset_key = reply_find_answer_rrset(&qstate->return_msg->qinfo,
|
||||
qstate->return_msg->rep);
|
||||
if(!rrset_key) {
|
||||
log_err("ipsecmod: could not find answer rrset for A/AAAA");
|
||||
return 0;
|
||||
}
|
||||
/* Double check that the records are indeed A/AAAA.
|
||||
* This should never happen as this function is only executed for A/AAAA
|
||||
* queries but make sure we don't pass anything other than A/AAAA to the
|
||||
@@ -304,9 +310,15 @@ call_hook(struct module_qstate* qstate, struct ipsecmod_qstate* iq,
|
||||
return 0;
|
||||
}
|
||||
rrset_data = (struct packed_rrset_data*)rrset_key->entry.data;
|
||||
/* Copy the A/AAAA record(s) into the buffer. Start and end this section
|
||||
* with a double quote. */
|
||||
w += sldns_str_print(&s, &slen, "\"");
|
||||
if(!rrset_data) {
|
||||
log_err("ipsecmod: Answer has no data");
|
||||
return 0;
|
||||
}
|
||||
/* Copy the A/AAAA record(s) into the buffer. */
|
||||
w = 0;
|
||||
s = a_s;
|
||||
slen = sizeof(a_s);
|
||||
memset(s, 0, slen);
|
||||
for(i=0; i<rrset_data->count; i++) {
|
||||
if(i > 0) {
|
||||
/* Put space into the buffer. */
|
||||
@@ -322,7 +334,7 @@ call_hook(struct module_qstate* qstate, struct ipsecmod_qstate* iq,
|
||||
} else if((size_t)w_temp >= slen) {
|
||||
s = NULL; /* We do not want str to point outside of buffer. */
|
||||
slen = 0;
|
||||
log_err("ipsecmod: shell command too long");
|
||||
log_err("ipsecmod: command addr argument too long");
|
||||
return 0;
|
||||
} else {
|
||||
s += w_temp;
|
||||
@@ -330,12 +342,17 @@ call_hook(struct module_qstate* qstate, struct ipsecmod_qstate* iq,
|
||||
w += w_temp;
|
||||
}
|
||||
}
|
||||
w += sldns_str_print(&s, &slen, "\"");
|
||||
/* Put space into the buffer. */
|
||||
w += sldns_str_print(&s, &slen, " ");
|
||||
if(w >= (int)sizeof(a_s)) {
|
||||
log_err("ipsecmod: command addr argument too long");
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* Copy the IPSECKEY record(s) into the buffer. Start and end this section
|
||||
* with a double quote. */
|
||||
w += sldns_str_print(&s, &slen, "\"");
|
||||
w = 0;
|
||||
s = k_s;
|
||||
slen = sizeof(k_s);
|
||||
memset(s, 0, slen);
|
||||
rrset_data = (struct packed_rrset_data*)iq->ipseckey_rrset->entry.data;
|
||||
for(i=0; i<rrset_data->count; i++) {
|
||||
if(i > 0) {
|
||||
@@ -362,15 +379,44 @@ call_hook(struct module_qstate* qstate, struct ipsecmod_qstate* iq,
|
||||
w += w_temp;
|
||||
}
|
||||
}
|
||||
w += sldns_str_print(&s, &slen, "\"");
|
||||
if(w >= (int)sizeof(str)) {
|
||||
log_err("ipsecmod: shell command too long");
|
||||
if(w >= (int)sizeof(k_s)) {
|
||||
log_err("ipsecmod: command ipseckey argument too long");
|
||||
return 0;
|
||||
}
|
||||
verbose(VERB_ALGO, "ipsecmod: shell command: '%s'", str);
|
||||
|
||||
/* ipsecmod-hook should return 0 on success. */
|
||||
if(system(str) != 0)
|
||||
/* exec the ipsecmod-hook */
|
||||
argv[0] = qstate->env->cfg->ipsecmod_hook;
|
||||
argv[1] = qname_s;
|
||||
argv[2] = ttl_s;
|
||||
argv[3] = a_s;
|
||||
argv[4] = k_s;
|
||||
argv[5] = NULL;
|
||||
verbose(VERB_ALGO, "ipsecmod: exec %s \"%s\" %s \"%s\" \"%s\"",
|
||||
argv[0], argv[1], argv[2], argv[3], argv[4]);
|
||||
if((pid = fork()) < 0) {
|
||||
log_err("ipsecmod: for exec, can not fork: %s",
|
||||
strerror(errno));
|
||||
return 0;
|
||||
}
|
||||
if(pid == 0) {
|
||||
if(execv(argv[0], argv) < 0)
|
||||
fprintf(stderr, "ipsecmod: execv: %s\n",
|
||||
strerror(errno));
|
||||
_exit(127);
|
||||
}
|
||||
while(1) {
|
||||
if(waitpid(pid, &st, 0) < 0) {
|
||||
if(errno == EINTR)
|
||||
continue;
|
||||
log_err("ipsecmod: wait_pid: %s", strerror(errno));
|
||||
}
|
||||
break;
|
||||
}
|
||||
if(!(WIFEXITED(st) && WEXITSTATUS(st) == 0)) {
|
||||
/* the command failed */
|
||||
return 0;
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -435,6 +481,12 @@ ipsecmod_handle_query(struct module_qstate* qstate,
|
||||
* ipsecmod_max_ttl. */
|
||||
rrset_key = reply_find_answer_rrset(&qstate->return_msg->qinfo,
|
||||
qstate->return_msg->rep);
|
||||
if(!rrset_key) {
|
||||
log_err("ipsecmod: reply-find-answer failed");
|
||||
errinf(qstate, "ipsecmod: reply-find-answer failed");
|
||||
ipsecmod_error(qstate, id);
|
||||
return;
|
||||
}
|
||||
rrset_data = (struct packed_rrset_data*)rrset_key->entry.data;
|
||||
if(rrset_data->ttl > (time_t)qstate->env->cfg->ipsecmod_max_ttl) {
|
||||
/* Update TTL for rrset to fixed value. */
|
||||
@@ -576,6 +628,8 @@ ipsecmod_inform_super(struct module_qstate* qstate, int id,
|
||||
verbose(VERB_ALGO, "super has no ipsecmod state");
|
||||
return;
|
||||
}
|
||||
if(!siq->enabled)
|
||||
return;
|
||||
|
||||
if(qstate->return_msg) {
|
||||
struct ub_packed_rrset_key* rrset_key = reply_find_answer_rrset(
|
||||
|
||||
+17
-14
@@ -143,7 +143,7 @@ static int add_to_ipset(filter_dev dev, const char *setname, const void *ipaddr,
|
||||
struct nlmsghdr *nlh;
|
||||
struct nfgenmsg *nfg;
|
||||
struct nlattr *nested[2];
|
||||
static char buffer[BUFF_LEN];
|
||||
char buffer[BUFF_LEN];
|
||||
|
||||
if (strlen(setname) >= IPSET_MAXNAMELEN) {
|
||||
errno = ENAMETOOLONG;
|
||||
@@ -208,13 +208,6 @@ ipset_add_rrset_data(struct ipset_env *ie,
|
||||
ret = add_to_ipset((filter_dev)ie->dev, setname, rr_data + 2, af);
|
||||
if (ret < 0) {
|
||||
log_err("ipset: could not add %s into %s", dname, setname);
|
||||
|
||||
#if HAVE_NET_PFVAR_H
|
||||
/* don't close as we might not be able to open again due to dropped privs */
|
||||
#else
|
||||
mnl_socket_close((filter_dev)ie->dev);
|
||||
ie->dev = NULL;
|
||||
#endif
|
||||
break;
|
||||
}
|
||||
}
|
||||
@@ -226,15 +219,15 @@ ipset_check_zones_for_rrset(struct module_env *env, struct ipset_env *ie,
|
||||
struct ub_packed_rrset_key *rrset, const char *qname, int qlen,
|
||||
const char *setname, int af)
|
||||
{
|
||||
static char dname[BUFF_LEN];
|
||||
char dname[LDNS_MAX_DOMAINLEN*4+16];
|
||||
const char *ds, *qs;
|
||||
int dlen, plen;
|
||||
|
||||
struct config_strlist *p;
|
||||
struct packed_rrset_data *d;
|
||||
|
||||
dlen = sldns_wire2str_dname_buf(rrset->rk.dname, rrset->rk.dname_len, dname, BUFF_LEN);
|
||||
if (dlen == 0) {
|
||||
dlen = sldns_wire2str_dname_buf(rrset->rk.dname, rrset->rk.dname_len, dname, sizeof(dname));
|
||||
if (dlen == 0 || dlen >= (int)sizeof(dname)) {
|
||||
log_err("bad domain name");
|
||||
return -1;
|
||||
}
|
||||
@@ -276,7 +269,7 @@ static int ipset_update(struct module_env *env, struct dns_msg *return_msg,
|
||||
const char *setname;
|
||||
struct ub_packed_rrset_key *rrset;
|
||||
int af;
|
||||
static char qname[BUFF_LEN];
|
||||
char qname[LDNS_MAX_DOMAINLEN*4+16];
|
||||
int qlen;
|
||||
|
||||
#ifdef HAVE_NET_PFVAR_H
|
||||
@@ -292,8 +285,8 @@ static int ipset_update(struct module_env *env, struct dns_msg *return_msg,
|
||||
#endif
|
||||
|
||||
qlen = sldns_wire2str_dname_buf(qinfo.qname, qinfo.qname_len,
|
||||
qname, BUFF_LEN);
|
||||
if(qlen == 0) {
|
||||
qname, sizeof(qname));
|
||||
if(qlen == 0 || qlen >= (int)sizeof(qname)) {
|
||||
log_err("bad domain name");
|
||||
return -1;
|
||||
}
|
||||
@@ -372,6 +365,16 @@ int ipset_init(struct module_env* env, int id) {
|
||||
|
||||
ipset_env->name_v4 = env->cfg->ipset_name_v4;
|
||||
ipset_env->name_v6 = env->cfg->ipset_name_v6;
|
||||
#ifndef HAVE_NET_PFVAR_H
|
||||
if (ipset_env->name_v4 && strlen(ipset_env->name_v4) >= IPSET_MAXNAMELEN) {
|
||||
log_err("ipset: name-v4 exceeds IPSET_MAXNAMELEN (%d)", IPSET_MAXNAMELEN);
|
||||
return 0;
|
||||
}
|
||||
if (ipset_env->name_v6 && strlen(ipset_env->name_v6) >= IPSET_MAXNAMELEN) {
|
||||
log_err("ipset: name-v6 exceeds IPSET_MAXNAMELEN (%d)", IPSET_MAXNAMELEN);
|
||||
return 0;
|
||||
}
|
||||
#endif
|
||||
|
||||
ipset_env->v4_enabled = !ipset_env->name_v4 || (strlen(ipset_env->name_v4) == 0) ? 0 : 1;
|
||||
ipset_env->v6_enabled = !ipset_env->name_v6 || (strlen(ipset_env->name_v6) == 0) ? 0 : 1;
|
||||
|
||||
+31
-24
@@ -118,10 +118,10 @@ delegpt_add_ns(struct delegpt* dp, struct regional* region, uint8_t* name,
|
||||
sizeof(struct delegpt_ns));
|
||||
if(!ns)
|
||||
return 0;
|
||||
ns->next = dp->nslist;
|
||||
ns->namelen = len;
|
||||
dp->nslist = ns;
|
||||
ns->name = regional_alloc_init(region, name, ns->namelen);
|
||||
if(!ns->name)
|
||||
return 0;
|
||||
ns->cache_lookup_count = 0;
|
||||
ns->resolved = 0;
|
||||
ns->got4 = 0;
|
||||
@@ -137,7 +137,9 @@ delegpt_add_ns(struct delegpt* dp, struct regional* region, uint8_t* name,
|
||||
} else {
|
||||
ns->tls_auth_name = NULL;
|
||||
}
|
||||
return ns->name != 0;
|
||||
ns->next = dp->nslist;
|
||||
dp->nslist = ns;
|
||||
return 1;
|
||||
}
|
||||
|
||||
struct delegpt_ns*
|
||||
@@ -223,11 +225,7 @@ delegpt_add_addr(struct delegpt* dp, struct regional* region,
|
||||
sizeof(struct delegpt_addr));
|
||||
if(!a)
|
||||
return 0;
|
||||
a->next_target = dp->target_list;
|
||||
dp->target_list = a;
|
||||
a->next_result = 0;
|
||||
a->next_usable = dp->usable_list;
|
||||
dp->usable_list = a;
|
||||
memcpy(&a->addr, addr, addrlen);
|
||||
a->addrlen = addrlen;
|
||||
a->attempts = 0;
|
||||
@@ -241,6 +239,10 @@ delegpt_add_addr(struct delegpt* dp, struct regional* region,
|
||||
} else {
|
||||
a->tls_auth_name = NULL;
|
||||
}
|
||||
a->next_target = dp->target_list;
|
||||
dp->target_list = a;
|
||||
a->next_usable = dp->usable_list;
|
||||
dp->usable_list = a;
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -398,30 +400,33 @@ delegpt_count_missing_targets(struct delegpt* dp, int* alllame)
|
||||
|
||||
/** find NS rrset in given list */
|
||||
static struct ub_packed_rrset_key*
|
||||
find_NS(struct reply_info* rep, size_t from, size_t to)
|
||||
find_NS(struct reply_info* rep, size_t from, size_t to, uint16_t qclass)
|
||||
{
|
||||
size_t i;
|
||||
for(i=from; i<to; i++) {
|
||||
if(ntohs(rep->rrsets[i]->rk.type) == LDNS_RR_TYPE_NS)
|
||||
if(ntohs(rep->rrsets[i]->rk.type) == LDNS_RR_TYPE_NS &&
|
||||
ntohs(rep->rrsets[i]->rk.rrset_class) == qclass)
|
||||
return rep->rrsets[i];
|
||||
}
|
||||
return NULL;
|
||||
}
|
||||
|
||||
struct delegpt*
|
||||
delegpt_from_message(struct dns_msg* msg, struct regional* region)
|
||||
delegpt_from_message(struct dns_msg* msg, struct regional* region, int port)
|
||||
{
|
||||
struct ub_packed_rrset_key* ns_rrset = NULL;
|
||||
struct delegpt* dp;
|
||||
size_t i;
|
||||
/* look for NS records in the authority section... */
|
||||
ns_rrset = find_NS(msg->rep, msg->rep->an_numrrsets,
|
||||
msg->rep->an_numrrsets+msg->rep->ns_numrrsets);
|
||||
msg->rep->an_numrrsets+msg->rep->ns_numrrsets,
|
||||
msg->qinfo.qclass);
|
||||
|
||||
/* In some cases (even legitimate, perfectly legal cases), the
|
||||
* NS set for the "referral" might be in the answer section. */
|
||||
if(!ns_rrset)
|
||||
ns_rrset = find_NS(msg->rep, 0, msg->rep->an_numrrsets);
|
||||
ns_rrset = find_NS(msg->rep, 0, msg->rep->an_numrrsets,
|
||||
msg->qinfo.qclass);
|
||||
|
||||
/* If there was no NS rrset in the authority section, then this
|
||||
* wasn't a referral message. (It might not actually be a
|
||||
@@ -436,7 +441,7 @@ delegpt_from_message(struct dns_msg* msg, struct regional* region)
|
||||
dp->has_parent_side_NS = 1; /* created from message */
|
||||
if(!delegpt_set_name(dp, region, ns_rrset->rk.dname))
|
||||
return NULL;
|
||||
if(!delegpt_rrset_add_ns(dp, region, ns_rrset, 0))
|
||||
if(!delegpt_rrset_add_ns(dp, region, ns_rrset, 0, port))
|
||||
return NULL;
|
||||
|
||||
/* add glue, A and AAAA in answer and additional section */
|
||||
@@ -447,10 +452,12 @@ delegpt_from_message(struct dns_msg* msg, struct regional* region)
|
||||
i < (msg->rep->an_numrrsets+msg->rep->ns_numrrsets))
|
||||
continue;
|
||||
|
||||
if(ntohs(s->rk.type) == LDNS_RR_TYPE_A) {
|
||||
if(ntohs(s->rk.type) == LDNS_RR_TYPE_A &&
|
||||
ntohs(s->rk.rrset_class) == msg->qinfo.qclass) {
|
||||
if(!delegpt_add_rrset_A(dp, region, s, 0, NULL))
|
||||
return NULL;
|
||||
} else if(ntohs(s->rk.type) == LDNS_RR_TYPE_AAAA) {
|
||||
} else if(ntohs(s->rk.type) == LDNS_RR_TYPE_AAAA &&
|
||||
ntohs(s->rk.rrset_class) == msg->qinfo.qclass) {
|
||||
if(!delegpt_add_rrset_AAAA(dp, region, s, 0, NULL))
|
||||
return NULL;
|
||||
}
|
||||
@@ -460,7 +467,7 @@ delegpt_from_message(struct dns_msg* msg, struct regional* region)
|
||||
|
||||
int
|
||||
delegpt_rrset_add_ns(struct delegpt* dp, struct regional* region,
|
||||
struct ub_packed_rrset_key* ns_rrset, uint8_t lame)
|
||||
struct ub_packed_rrset_key* ns_rrset, uint8_t lame, int port)
|
||||
{
|
||||
struct packed_rrset_data* nsdata = (struct packed_rrset_data*)
|
||||
ns_rrset->entry.data;
|
||||
@@ -475,7 +482,7 @@ delegpt_rrset_add_ns(struct delegpt* dp, struct regional* region,
|
||||
continue; /* bad format */
|
||||
/* add rdata of NS (= wirefmt dname), skip rdatalen bytes */
|
||||
if(!delegpt_add_ns(dp, region, nsdata->rr_data[i]+2, lame,
|
||||
NULL, UNBOUND_DNS_PORT))
|
||||
NULL, (port==-1?UNBOUND_DNS_PORT:port)))
|
||||
return 0;
|
||||
}
|
||||
return 1;
|
||||
@@ -534,7 +541,7 @@ delegpt_add_rrset(struct delegpt* dp, struct regional* region,
|
||||
if(!rrset)
|
||||
return 1;
|
||||
if(ntohs(rrset->rk.type) == LDNS_RR_TYPE_NS)
|
||||
return delegpt_rrset_add_ns(dp, region, rrset, lame);
|
||||
return delegpt_rrset_add_ns(dp, region, rrset, lame, -1);
|
||||
else if(ntohs(rrset->rk.type) == LDNS_RR_TYPE_A)
|
||||
return delegpt_add_rrset_A(dp, region, rrset, lame, additions);
|
||||
else if(ntohs(rrset->rk.type) == LDNS_RR_TYPE_AAAA)
|
||||
@@ -659,8 +666,6 @@ int delegpt_add_ns_mlc(struct delegpt* dp, uint8_t* name, uint8_t lame,
|
||||
free(ns);
|
||||
return 0;
|
||||
}
|
||||
ns->next = dp->nslist;
|
||||
dp->nslist = ns;
|
||||
ns->cache_lookup_count = 0;
|
||||
ns->resolved = 0;
|
||||
ns->got4 = 0;
|
||||
@@ -679,6 +684,8 @@ int delegpt_add_ns_mlc(struct delegpt* dp, uint8_t* name, uint8_t lame,
|
||||
} else {
|
||||
ns->tls_auth_name = NULL;
|
||||
}
|
||||
ns->next = dp->nslist;
|
||||
dp->nslist = ns;
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -704,11 +711,7 @@ int delegpt_add_addr_mlc(struct delegpt* dp, struct sockaddr_storage* addr,
|
||||
a = (struct delegpt_addr*)malloc(sizeof(struct delegpt_addr));
|
||||
if(!a)
|
||||
return 0;
|
||||
a->next_target = dp->target_list;
|
||||
dp->target_list = a;
|
||||
a->next_result = 0;
|
||||
a->next_usable = dp->usable_list;
|
||||
dp->usable_list = a;
|
||||
memcpy(&a->addr, addr, addrlen);
|
||||
a->addrlen = addrlen;
|
||||
a->attempts = 0;
|
||||
@@ -724,6 +727,10 @@ int delegpt_add_addr_mlc(struct delegpt* dp, struct sockaddr_storage* addr,
|
||||
} else {
|
||||
a->tls_auth_name = NULL;
|
||||
}
|
||||
a->next_target = dp->target_list;
|
||||
dp->target_list = a;
|
||||
a->next_usable = dp->usable_list;
|
||||
dp->usable_list = a;
|
||||
return 1;
|
||||
}
|
||||
|
||||
|
||||
@@ -221,10 +221,11 @@ int delegpt_add_ns(struct delegpt* dp, struct regional* regional,
|
||||
* @param regional: where to allocate the info.
|
||||
* @param ns_rrset: NS rrset.
|
||||
* @param lame: rrset is lame, disprefer it.
|
||||
* @param port: port or -1 if not set.
|
||||
* @return 0 on alloc error.
|
||||
*/
|
||||
int delegpt_rrset_add_ns(struct delegpt* dp, struct regional* regional,
|
||||
struct ub_packed_rrset_key* ns_rrset, uint8_t lame);
|
||||
struct ub_packed_rrset_key* ns_rrset, uint8_t lame, int port);
|
||||
|
||||
/**
|
||||
* Add target address to the delegation point.
|
||||
@@ -365,11 +366,12 @@ size_t delegpt_count_targets(struct delegpt* dp);
|
||||
*
|
||||
* @param msg: the dns message, referral.
|
||||
* @param regional: where to allocate delegation point.
|
||||
* @param port: if not -1 specifies a port number.
|
||||
* @return new delegation point or NULL on alloc error, or if the
|
||||
* message was not appropriate.
|
||||
*/
|
||||
struct delegpt* delegpt_from_message(struct dns_msg* msg,
|
||||
struct regional* regional);
|
||||
struct regional* regional, int port);
|
||||
|
||||
/**
|
||||
* Mark negative return in delegation point for specific nameserver.
|
||||
|
||||
@@ -107,7 +107,7 @@ response_type_from_cache(struct dns_msg* msg,
|
||||
enum response_type
|
||||
response_type_from_server(int rdset,
|
||||
struct dns_msg* msg, struct query_info* request, struct delegpt* dp,
|
||||
int* empty_nodata_found)
|
||||
int* empty_nodata_found, int msg_lame_empty, int msg_lame_referral)
|
||||
{
|
||||
uint8_t* origzone = (uint8_t*)"\000"; /* the default */
|
||||
struct ub_packed_rrset_key* s;
|
||||
@@ -122,6 +122,10 @@ response_type_from_server(int rdset,
|
||||
|
||||
/* If the message is NXDOMAIN, then it answers the question. */
|
||||
if(FLAGS_GET_RCODE(msg->rep->flags) == LDNS_RCODE_NXDOMAIN) {
|
||||
if(msg->rep->an_numrrsets == 0 &&
|
||||
msg->rep->ns_numrrsets == 0 &&
|
||||
msg_lame_empty)
|
||||
return RESPONSE_TYPE_LAME;
|
||||
/* make sure its not recursive when we don't want it to */
|
||||
if( (msg->rep->flags&BIT_RA) &&
|
||||
!(msg->rep->flags&BIT_AA) && !rdset)
|
||||
@@ -143,6 +147,10 @@ response_type_from_server(int rdset,
|
||||
if(FLAGS_GET_RCODE(msg->rep->flags) != LDNS_RCODE_NOERROR)
|
||||
return RESPONSE_TYPE_THROWAWAY;
|
||||
|
||||
if(msg->rep->an_numrrsets == 0 && msg->rep->ns_numrrsets == 0 &&
|
||||
msg_lame_empty)
|
||||
return RESPONSE_TYPE_LAME;
|
||||
|
||||
/* Note: TC bit has already been handled */
|
||||
|
||||
if(dp) {
|
||||
@@ -249,13 +257,16 @@ response_type_from_server(int rdset,
|
||||
* which gives ns==zone delegation from cache
|
||||
* without AA bit as well, with nodata nosoa*/
|
||||
/* real answer must be +AA and SOA RFC(2308),
|
||||
* so this is wrong, and we SERVFAIL it if
|
||||
* this is the only possible reply, if it
|
||||
* is misdeployed the THROWAWAY makes us pick
|
||||
* the next server from the selection */
|
||||
if(msg->rep->an_numrrsets==0 &&
|
||||
* this is picked up as lame_referral by the
|
||||
* sanitize step, so it can spot if there
|
||||
* was data in the answer section before
|
||||
* removal. If such data is then removed we
|
||||
* do not want to turn that answer into lame.
|
||||
* But if it was not there, it can be lame. */
|
||||
if(msg_lame_referral &&
|
||||
msg->rep->an_numrrsets==0 &&
|
||||
!(msg->rep->flags&BIT_AA) && !rdset)
|
||||
return RESPONSE_TYPE_THROWAWAY;
|
||||
return RESPONSE_TYPE_LAME;
|
||||
return RESPONSE_TYPE_ANSWER;
|
||||
}
|
||||
/* If we are getting a referral upwards (or to
|
||||
|
||||
@@ -120,10 +120,14 @@ enum response_type response_type_from_cache(struct dns_msg* msg,
|
||||
* @param dp: The delegation point that was being queried
|
||||
* when the response was returned.
|
||||
* @param empty_nodata_found: flag to keep track of empty nodata detection.
|
||||
* @param msg_lame_empty: The scrubber indicates that this empty message
|
||||
* is lame, before it became empty.
|
||||
* @param msg_lame_referral: returned true if the reply has a referral before
|
||||
* scrub.
|
||||
* @return the response type (CNAME or ANSWER).
|
||||
*/
|
||||
enum response_type response_type_from_server(int rdset,
|
||||
struct dns_msg* msg, struct query_info* request, struct delegpt* dp,
|
||||
int* empty_nodata_found);
|
||||
int* empty_nodata_found, int msg_lame_empty, int msg_lame_referral);
|
||||
|
||||
#endif /* ITERATOR_ITER_RESPTYPE_H */
|
||||
|
||||
+73
-3
@@ -316,6 +316,20 @@ synth_cname_rrset(uint8_t** sname, size_t* snamelen, uint8_t* alias,
|
||||
return cn;
|
||||
}
|
||||
|
||||
/** Check if the packet has type NS in answer or authority section */
|
||||
static int
|
||||
pkt_contains_ns(struct msg_parse* msg)
|
||||
{
|
||||
struct rrset_parse* rrset;
|
||||
for(rrset = msg->rrset_first; rrset; rrset = rrset->rrset_all_next) {
|
||||
if(rrset->type == LDNS_RR_TYPE_NS &&
|
||||
(rrset->section == LDNS_SECTION_ANSWER ||
|
||||
rrset->section == LDNS_SECTION_AUTHORITY))
|
||||
return 1;
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
/** check if DNAME applies to a name */
|
||||
static int
|
||||
pkt_strict_sub(sldns_buffer* pkt, uint8_t* sname, uint8_t* dr)
|
||||
@@ -394,6 +408,8 @@ shorten_rrset(sldns_buffer* pkt, struct rrset_parse* rrset, int count)
|
||||
struct rr_parse* rr = rrset->rr_first, *prev = NULL;
|
||||
if(!rr)
|
||||
return;
|
||||
if(count < 1)
|
||||
return; /* cannot leave a still-linked rrset_parse with rr_count == 0 */
|
||||
for(i=0; i<count; i++) {
|
||||
prev = rr;
|
||||
rr = rr->next;
|
||||
@@ -478,6 +494,7 @@ scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg,
|
||||
size_t snamelen = qinfo->qname_len;
|
||||
struct rrset_parse* rrset, *prev, *nsset=NULL;
|
||||
int cname_length = 0; /* number of CNAMEs, or DNAMEs */
|
||||
int has_answer = 0; /* if answer section contains nonCNAME,nonDNAME */
|
||||
|
||||
if(FLAGS_GET_RCODE(msg->flags) != LDNS_RCODE_NOERROR &&
|
||||
FLAGS_GET_RCODE(msg->flags) != LDNS_RCODE_NXDOMAIN &&
|
||||
@@ -519,6 +536,11 @@ scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg,
|
||||
(unsigned)rrset->rr_count);
|
||||
return 0;
|
||||
}
|
||||
if(has_answer) {
|
||||
remove_rrset("normalize: removing DNAME redirection after answer:",
|
||||
pkt, msg, prev, &rrset);
|
||||
continue;
|
||||
}
|
||||
if(!synth_cname(sname, snamelen, rrset, alias,
|
||||
&aliaslen, pkt)) {
|
||||
verbose(VERB_ALGO, "synthesized CNAME "
|
||||
@@ -569,6 +591,11 @@ scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg,
|
||||
if(rrset->type == LDNS_RR_TYPE_CNAME) {
|
||||
struct rrset_parse* nx = rrset->rrset_all_next;
|
||||
uint8_t* oldsname = sname;
|
||||
if(has_answer) {
|
||||
remove_rrset("normalize: removing redirection after answer:",
|
||||
pkt, msg, prev, &rrset);
|
||||
continue;
|
||||
}
|
||||
cname_length++;
|
||||
/* see if the next one is a DNAME, if so, swap them */
|
||||
if(nx && nx->section == LDNS_SECTION_ANSWER &&
|
||||
@@ -647,6 +674,7 @@ scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg,
|
||||
* will be removed by sanitize, so no additional for them */
|
||||
if(dname_pkt_compare(pkt, qinfo->qname, rrset->dname) == 0)
|
||||
mark_additional_rrset(pkt, msg, rrset);
|
||||
has_answer = 1;
|
||||
|
||||
prev = rrset;
|
||||
rrset = rrset->rrset_all_next;
|
||||
@@ -732,6 +760,11 @@ scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg,
|
||||
"RRset:", pkt, msg, prev, &rrset);
|
||||
continue;
|
||||
}
|
||||
if(ntohs(rrset->rrset_class) != qinfo->qclass) {
|
||||
remove_rrset("normalize: removing other class "
|
||||
"RRset:", pkt, msg, prev, &rrset);
|
||||
continue;
|
||||
}
|
||||
if(nsset == NULL) {
|
||||
nsset = rrset;
|
||||
} else {
|
||||
@@ -968,12 +1001,20 @@ scrub_sanitize_rr_length(sldns_buffer* pkt, struct msg_parse* msg,
|
||||
* @param env: module environment with config and cache.
|
||||
* @param ie: iterator environment with private address data.
|
||||
* @param qstate: for setting errinf for EDE error messages.
|
||||
* @param pkt_before_NS: if the packet had type NS before scrub. If that
|
||||
* is removed now, that indicates this may have been lame.
|
||||
* @param msg_lame_empty: returned true if the empty packet is lame.
|
||||
* @param msg_lame_referral: returned true if the reply has a referral before
|
||||
* scrub.
|
||||
* @param rdset: if RD bit was sent in query sent by unbound.
|
||||
* @return 0 on error.
|
||||
*/
|
||||
static int
|
||||
scrub_sanitize(sldns_buffer* pkt, struct msg_parse* msg,
|
||||
struct query_info* qinfo, uint8_t* zonename, struct module_env* env,
|
||||
struct iter_env* ie, struct module_qstate* qstate)
|
||||
struct iter_env* ie, struct module_qstate* qstate,
|
||||
int pkt_before_NS, int* msg_lame_empty, int* msg_lame_referral,
|
||||
int rdset)
|
||||
{
|
||||
int del_addi = 0; /* if additional-holding rrsets are deleted, we
|
||||
do not trust the normalized additional-A-AAAA any more */
|
||||
@@ -1130,6 +1171,21 @@ scrub_sanitize(sldns_buffer* pkt, struct msg_parse* msg,
|
||||
prev = rrset;
|
||||
rrset = rrset->rrset_all_next;
|
||||
}
|
||||
|
||||
/* If the packet is empty now, but it was not before. And there
|
||||
* was type NS in authority, then that indicates the answer is lame. */
|
||||
if(msg->rrset_first == NULL && pkt_before_NS) {
|
||||
*msg_lame_empty = 1;
|
||||
verbose(VERB_ALGO, "sanitize: empty message had referral to NS before, marked as lame");
|
||||
} else if(pkt_before_NS && msg->an_rrsets==0 &&
|
||||
!(msg->flags&BIT_AA) && !rdset) {
|
||||
/* If the packet is now a referral, not really a nodata,
|
||||
* then if it was also with an empty answer section before,
|
||||
* it is also lame. */
|
||||
*msg_lame_referral = 1;
|
||||
verbose(VERB_ALGO, "sanitize: message has referral not answer, marked as lame");
|
||||
}
|
||||
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -1137,11 +1193,15 @@ int
|
||||
scrub_message(sldns_buffer* pkt, struct msg_parse* msg,
|
||||
struct query_info* qinfo, uint8_t* zonename, struct regional* region,
|
||||
struct module_env* env, struct module_qstate* qstate,
|
||||
struct iter_env* ie)
|
||||
struct iter_env* ie, int* msg_lame_empty, int* msg_lame_referral,
|
||||
int rdset)
|
||||
{
|
||||
int pkt_before_NS;
|
||||
/* basic sanity checks */
|
||||
log_nametypeclass(VERB_ALGO, "scrub for", zonename, LDNS_RR_TYPE_NS,
|
||||
qinfo->qclass);
|
||||
*msg_lame_empty = 0;
|
||||
*msg_lame_referral = 0;
|
||||
if(msg->qdcount > 1)
|
||||
return 0;
|
||||
if( !(msg->flags&BIT_QR) )
|
||||
@@ -1166,11 +1226,21 @@ scrub_message(sldns_buffer* pkt, struct msg_parse* msg,
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* If the packet contains type NS in authority before scrub,
|
||||
* like a self referral. With the answer section empty, it
|
||||
* was not AA, the query was not sent with RD, with NS in auth,
|
||||
* and no SOA in auth. For a negative answer, type SOA is present.
|
||||
* This detects certain lameness if after has removed that. */
|
||||
pkt_before_NS = msg->an_rrsets == 0 &&
|
||||
!(msg->flags&BIT_AA) && !rdset &&
|
||||
pkt_contains_ns(msg) && !soa_in_auth(msg);
|
||||
|
||||
/* normalize the response, this cleans up the additional. */
|
||||
if(!scrub_normalize(pkt, msg, qinfo, region, env, zonename))
|
||||
return 0;
|
||||
/* delete all out-of-zone information */
|
||||
if(!scrub_sanitize(pkt, msg, qinfo, zonename, env, ie, qstate))
|
||||
if(!scrub_sanitize(pkt, msg, qinfo, zonename, env, ie, qstate,
|
||||
pkt_before_NS, msg_lame_empty, msg_lame_referral, rdset))
|
||||
return 0;
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -62,11 +62,16 @@ struct module_qstate;
|
||||
* @param env: module environment with config settings and cache.
|
||||
* @param qstate: for setting errinf for EDE error messages.
|
||||
* @param ie: iterator module environment data.
|
||||
* @param msg_lame_empty: returned true if the empty packet is lame.
|
||||
* @param msg_lame_referral: returned true if the reply has a referral before
|
||||
* scrub.
|
||||
* @param rdset: if RD bit was sent in query sent by unbound.
|
||||
* @return: false if the message is total waste. true if scrubbed with success.
|
||||
*/
|
||||
int scrub_message(struct sldns_buffer* pkt, struct msg_parse* msg,
|
||||
struct query_info* qinfo, uint8_t* zonename, struct regional* regional,
|
||||
struct module_env* env, struct module_qstate* qstate,
|
||||
struct iter_env* ie);
|
||||
struct iter_env* ie, int* msg_lame_empty, int* msg_lame_referral,
|
||||
int rdset);
|
||||
|
||||
#endif /* ITERATOR_ITER_SCRUB_H */
|
||||
|
||||
+10
-1
@@ -1313,7 +1313,8 @@ iter_lookup_parent_NS_from_cache(struct module_env* env, struct delegpt* dp,
|
||||
log_rrset_key(VERB_ALGO, "found parent-side NS in cache", akey);
|
||||
dp->has_parent_side_NS = 1;
|
||||
/* and mark the new names as lame */
|
||||
if(!delegpt_rrset_add_ns(dp, region, akey, 1)) {
|
||||
if(!delegpt_rrset_add_ns(dp, region, akey, 1,
|
||||
deleg_port_number(env))) {
|
||||
lock_rw_unlock(&akey->entry.lock);
|
||||
return 0;
|
||||
}
|
||||
@@ -1703,3 +1704,11 @@ iter_make_minimal(struct reply_info* rep)
|
||||
rep->ar_numrrsets = 0;
|
||||
rep->rrset_count -= rem;
|
||||
}
|
||||
|
||||
int
|
||||
deleg_port_number(struct module_env* env)
|
||||
{
|
||||
if(env->cfg->ssl_upstream)
|
||||
return env->cfg->ssl_port;
|
||||
return -1;
|
||||
}
|
||||
|
||||
@@ -483,4 +483,7 @@ void limit_nsec_ttl(struct dns_msg* msg);
|
||||
*/
|
||||
void iter_make_minimal(struct reply_info* rep);
|
||||
|
||||
/** See if we need a different port number */
|
||||
int deleg_port_number(struct module_env* env);
|
||||
|
||||
#endif /* ITERATOR_ITER_UTILS_H */
|
||||
|
||||
+66
-18
@@ -1511,6 +1511,7 @@ processInitRequest(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
verbose(VERB_ALGO, "no-cache set, going to the network");
|
||||
qstate->no_cache_lookup = 1;
|
||||
qstate->no_cache_store = 1;
|
||||
qstate->fwd_stub_no_cache = 1;
|
||||
msg = NULL;
|
||||
} else if(qstate->blacklist) {
|
||||
/* if cache, or anything else, was blacklisted then
|
||||
@@ -1530,7 +1531,7 @@ processInitRequest(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
msg = val_neg_getmsg(qstate->env->neg_cache, &iq->qchase,
|
||||
qstate->region, qstate->env->rrset_cache,
|
||||
qstate->env->scratch_buffer,
|
||||
*qstate->env->now, 1/*add SOA*/, NULL,
|
||||
*qstate->env->now, 1/*add SOA*/, dpname,
|
||||
qstate->env->cfg);
|
||||
}
|
||||
/* item taken from cache does not match our query name, thus
|
||||
@@ -2391,6 +2392,12 @@ processDSNSFind(struct module_qstate* qstate, struct iter_qstate* iq, int id)
|
||||
|
||||
/* go up one (more) step, until we hit the dp, if so, end */
|
||||
dname_remove_label(&iq->dsns_point, &iq->dsns_point_len);
|
||||
if(++iq->dsns_count > MAX_DSNS_FIND_COUNT) {
|
||||
verbose(VERB_QUERY, "DS NS search exceeded %d labels",
|
||||
MAX_DSNS_FIND_COUNT);
|
||||
errinf(qstate, "DS NS search exceeded label limit");
|
||||
return error_response_cache(qstate, id, LDNS_RCODE_SERVFAIL);
|
||||
}
|
||||
if(query_dname_compare(iq->dsns_point, iq->dp->name) == 0) {
|
||||
/* there was no inbetween nameserver, use the old delegation
|
||||
* point again. And this time, because dsns_point is nonNULL
|
||||
@@ -3073,7 +3080,9 @@ processQueryTargets(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
|
||||
/* Do not check ratelimit for forwarding queries or if we already got a
|
||||
* pass. */
|
||||
sq_check_ratelimit = (!(iq->chase_flags & BIT_RD) && !iq->ratelimit_ok);
|
||||
sq_check_ratelimit = ((!(iq->chase_flags & BIT_RD) &&
|
||||
!iq->ratelimit_ok));
|
||||
iq->ratelimit_incremented = 0;
|
||||
/* We have a valid target. */
|
||||
if(verbosity >= VERB_QUERY) {
|
||||
log_query_info(VERB_QUERY, "sending query:", &iq->qinfo_out);
|
||||
@@ -3099,7 +3108,8 @@ processQueryTargets(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
iq->dp->name, iq->dp->namelen,
|
||||
(iq->dp->tcp_upstream || qstate->env->cfg->tcp_upstream),
|
||||
(iq->dp->ssl_upstream || qstate->env->cfg->ssl_upstream),
|
||||
target->tls_auth_name, qstate, &sq_was_ratelimited);
|
||||
target->tls_auth_name, qstate, &sq_was_ratelimited,
|
||||
&iq->ratelimit_incremented);
|
||||
if(!outq) {
|
||||
if(sq_was_ratelimited) {
|
||||
lock_basic_lock(&ie->queries_ratelimit_lock);
|
||||
@@ -3137,7 +3147,6 @@ find_NS(struct reply_info* rep, size_t from, size_t to)
|
||||
return NULL;
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* Process the query response. All queries end up at this state first. This
|
||||
* process generally consists of analyzing the response and routing the
|
||||
@@ -3179,7 +3188,8 @@ processQueryResponse(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
orig_empty_nodata_found = iq->empty_nodata_found;
|
||||
type = response_type_from_server(
|
||||
(int)((iq->chase_flags&BIT_RD) || iq->chase_to_rd),
|
||||
iq->response, &iq->qinfo_out, iq->dp, &iq->empty_nodata_found);
|
||||
iq->response, &iq->qinfo_out, iq->dp, &iq->empty_nodata_found,
|
||||
iq->msg_lame_empty, iq->msg_lame_referral);
|
||||
iq->chase_to_rd = 0;
|
||||
/* remove TC flag, if this is erroneously set by TCP upstream */
|
||||
iq->response->rep->flags &= ~BIT_TC;
|
||||
@@ -3457,7 +3467,14 @@ processQueryResponse(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
iq->deleg_msg = iq->response;
|
||||
/* Keep current delegation point for label comparison */
|
||||
old_dp = iq->dp;
|
||||
iq->dp = delegpt_from_message(iq->response, qstate->region);
|
||||
/* A referral reply is "pleasant", refund the
|
||||
* parent dp's rate charge before descending to the child. */
|
||||
if(iq->ratelimit_incremented)
|
||||
infra_ratelimit_dec(qstate->env->infra_cache,
|
||||
old_dp->name, old_dp->namelen,
|
||||
*qstate->env->now);
|
||||
iq->dp = delegpt_from_message(iq->response, qstate->region,
|
||||
deleg_port_number(qstate->env));
|
||||
if (qstate->env->cfg->qname_minimisation)
|
||||
iq->minimisation_state = INIT_MINIMISE_STATE;
|
||||
if(!iq->dp) {
|
||||
@@ -3734,7 +3751,8 @@ prime_supers(struct module_qstate* qstate, int id, struct module_qstate* forq)
|
||||
log_assert(qstate->is_priming || foriq->wait_priming_stub);
|
||||
log_assert(qstate->return_rcode == LDNS_RCODE_NOERROR);
|
||||
/* Convert our response to a delegation point */
|
||||
dp = delegpt_from_message(qstate->return_msg, forq->region);
|
||||
dp = delegpt_from_message(qstate->return_msg, forq->region,
|
||||
deleg_port_number(forq->env));
|
||||
if(!dp) {
|
||||
/* if there is no convertible delegation point, then
|
||||
* the ANSWER type was (presumably) a negative answer. */
|
||||
@@ -3785,7 +3803,8 @@ processPrimeResponse(struct module_qstate* qstate, int id)
|
||||
iq->response->rep->flags &= ~(BIT_RD|BIT_RA); /* ignore rec-lame */
|
||||
type = response_type_from_server(
|
||||
(int)((iq->chase_flags&BIT_RD) || iq->chase_to_rd),
|
||||
iq->response, &iq->qchase, iq->dp, NULL);
|
||||
iq->response, &iq->qchase, iq->dp, NULL, iq->msg_lame_empty,
|
||||
iq->msg_lame_referral);
|
||||
if(type == RESPONSE_TYPE_ANSWER) {
|
||||
qstate->return_rcode = LDNS_RCODE_NOERROR;
|
||||
qstate->return_msg = iq->response;
|
||||
@@ -3949,7 +3968,8 @@ processDSNSResponse(struct module_qstate* qstate, int id,
|
||||
|
||||
/* else, store as DP and continue at querytargets */
|
||||
foriq->state = QUERYTARGETS_STATE;
|
||||
foriq->dp = delegpt_from_message(qstate->return_msg, forq->region);
|
||||
foriq->dp = delegpt_from_message(qstate->return_msg, forq->region,
|
||||
deleg_port_number(forq->env));
|
||||
if(!foriq->dp) {
|
||||
log_err("out of memory in dsns dp alloc");
|
||||
errinf(qstate, "malloc failure, in DS search");
|
||||
@@ -3998,7 +4018,7 @@ processClassResponse(struct module_qstate* qstate, int id,
|
||||
/* if there are records, copy RCODE */
|
||||
/* lower sec_state if this message is lower */
|
||||
if(from->rep->rrset_count != 0) {
|
||||
size_t n = from->rep->rrset_count+to->rep->rrset_count;
|
||||
size_t i, n = from->rep->rrset_count+to->rep->rrset_count;
|
||||
struct ub_packed_rrset_key** dest, **d;
|
||||
/* copy appropriate rcode */
|
||||
to->rep->flags = from->rep->flags;
|
||||
@@ -4020,24 +4040,49 @@ processClassResponse(struct module_qstate* qstate, int id,
|
||||
memcpy(dest, to->rep->rrsets, to->rep->an_numrrsets
|
||||
* sizeof(dest[0]));
|
||||
dest += to->rep->an_numrrsets;
|
||||
memcpy(dest, from->rep->rrsets, from->rep->an_numrrsets
|
||||
* sizeof(dest[0]));
|
||||
for(i=0; i<from->rep->an_numrrsets; i++) {
|
||||
dest[i] = packed_rrset_copy_region(
|
||||
from->rep->rrsets[i], forq->region, 0);
|
||||
if(!dest[i]) {
|
||||
log_err("malloc failed in collect ANY");
|
||||
foriq->state = FINISHED_STATE;
|
||||
return;
|
||||
}
|
||||
}
|
||||
dest += from->rep->an_numrrsets;
|
||||
/* copy NS */
|
||||
memcpy(dest, to->rep->rrsets+to->rep->an_numrrsets,
|
||||
to->rep->ns_numrrsets * sizeof(dest[0]));
|
||||
dest += to->rep->ns_numrrsets;
|
||||
memcpy(dest, from->rep->rrsets+from->rep->an_numrrsets,
|
||||
from->rep->ns_numrrsets * sizeof(dest[0]));
|
||||
for(i=0; i<from->rep->ns_numrrsets; i++) {
|
||||
dest[i] = packed_rrset_copy_region(
|
||||
from->rep->rrsets[
|
||||
from->rep->an_numrrsets+i],
|
||||
forq->region, 0);
|
||||
if(!dest[i]) {
|
||||
log_err("malloc failed in collect ANY");
|
||||
foriq->state = FINISHED_STATE;
|
||||
return;
|
||||
}
|
||||
}
|
||||
dest += from->rep->ns_numrrsets;
|
||||
/* copy AR */
|
||||
memcpy(dest, to->rep->rrsets+to->rep->an_numrrsets+
|
||||
to->rep->ns_numrrsets,
|
||||
to->rep->ar_numrrsets * sizeof(dest[0]));
|
||||
dest += to->rep->ar_numrrsets;
|
||||
memcpy(dest, from->rep->rrsets+from->rep->an_numrrsets+
|
||||
from->rep->ns_numrrsets,
|
||||
from->rep->ar_numrrsets * sizeof(dest[0]));
|
||||
for(i=0; i<from->rep->ar_numrrsets; i++) {
|
||||
dest[i] = packed_rrset_copy_region(
|
||||
from->rep->rrsets[
|
||||
from->rep->an_numrrsets+
|
||||
from->rep->ns_numrrsets+i],
|
||||
forq->region, 0);
|
||||
if(!dest[i]) {
|
||||
log_err("malloc failed in collect ANY");
|
||||
foriq->state = FINISHED_STATE;
|
||||
return;
|
||||
}
|
||||
}
|
||||
/* update counts */
|
||||
to->rep->rrsets = d;
|
||||
to->rep->an_numrrsets += from->rep->an_numrrsets;
|
||||
@@ -4395,7 +4440,10 @@ process_response(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
|
||||
/* normalize and sanitize: easy to delete items from linked lists */
|
||||
if(!scrub_message(pkt, prs, &iq->qinfo_out, iq->dp->name,
|
||||
qstate->env->scratch, qstate->env, qstate, ie)) {
|
||||
qstate->env->scratch, qstate->env, qstate, ie,
|
||||
&iq->msg_lame_empty, &iq->msg_lame_referral,
|
||||
(int)((iq->chase_flags&BIT_RD) || iq->chase_to_rd)
|
||||
)) {
|
||||
/* if 0x20 enabled, start fallback, but we have no message */
|
||||
if(event == module_event_capsfail && !iq->caps_fallback) {
|
||||
iq->caps_fallback = 1;
|
||||
|
||||
@@ -104,6 +104,11 @@ extern int BLACKLIST_PENALTY;
|
||||
#define RTT_BAND 400
|
||||
/** Number of retries for empty nodata packets before it is accepted. */
|
||||
#define EMPTY_NODATA_RETRY_COUNT 2
|
||||
/** max label-strip iterations in DSNS_FIND_STATE (RFC 4035 4.2 parent-NS
|
||||
* search) before giving up; bounds upstream NS sends per client DS.
|
||||
* Means the max number of labels in grandchild to the grandparent zone that
|
||||
* are co-hosted. */
|
||||
#define MAX_DSNS_FIND_COUNT 20
|
||||
|
||||
/**
|
||||
* Iterator global state for nat64.
|
||||
@@ -375,6 +380,10 @@ struct iter_qstate {
|
||||
/** if true, already tested for ratelimiting and passed the test */
|
||||
int ratelimit_ok;
|
||||
|
||||
/** If the last query, that may be a referral, incremented the
|
||||
* ratelimit counter. */
|
||||
int ratelimit_incremented;
|
||||
|
||||
/**
|
||||
* The query must store NS records from referrals as parentside RRs
|
||||
* Enabled once it hits resolution problems, to throttle retries.
|
||||
@@ -399,6 +408,8 @@ struct iter_qstate {
|
||||
uint8_t* dsns_point;
|
||||
/** length of the dname in dsns_point */
|
||||
size_t dsns_point_len;
|
||||
/** number of label-strip iterations performed in DSNS_FIND_STATE */
|
||||
int dsns_count;
|
||||
|
||||
/**
|
||||
* expected dnssec information for this iteration step.
|
||||
@@ -434,6 +445,13 @@ struct iter_qstate {
|
||||
* already so that it is accepted later. */
|
||||
int empty_nodata_found;
|
||||
|
||||
/** Store if the answer was empty, but lame, before it became empty.*/
|
||||
int msg_lame_empty;
|
||||
|
||||
/** Store if the answer was a referral, to self, before scrub. So the
|
||||
* it is not some sort of answer. */
|
||||
int msg_lame_referral;
|
||||
|
||||
/** list of pending queries to authoritative servers. */
|
||||
struct outbound_list outlist;
|
||||
|
||||
|
||||
@@ -167,6 +167,8 @@ struct ctx_query {
|
||||
ub_event_callback_type cb_event;
|
||||
/** for async query, the callback user arg */
|
||||
void* cb_arg;
|
||||
/** for async query the unique info */
|
||||
void* unique_info;
|
||||
|
||||
/** answer message, result from resolver lookup. */
|
||||
uint8_t* msg;
|
||||
|
||||
@@ -571,6 +571,8 @@ ub_ctx_async(struct ub_ctx* ctx, int dothread)
|
||||
int
|
||||
ub_poll(struct ub_ctx* ctx)
|
||||
{
|
||||
if(!ctx || ctx->event_base)
|
||||
return UB_INITFAIL;
|
||||
/* no need to hold lock while testing for readability. */
|
||||
return tube_poll(ctx->rr_pipe);
|
||||
}
|
||||
@@ -578,6 +580,8 @@ ub_poll(struct ub_ctx* ctx)
|
||||
int
|
||||
ub_fd(struct ub_ctx* ctx)
|
||||
{
|
||||
if(!ctx || ctx->event_base)
|
||||
return -1;
|
||||
return tube_read_fd(ctx->rr_pipe);
|
||||
}
|
||||
|
||||
@@ -672,6 +676,8 @@ ub_process(struct ub_ctx* ctx)
|
||||
int r;
|
||||
uint8_t* msg;
|
||||
uint32_t len;
|
||||
if(!ctx || ctx->event_base)
|
||||
return UB_INITFAIL;
|
||||
while(1) {
|
||||
msg = NULL;
|
||||
lock_basic_lock(&ctx->rrpipe_lock);
|
||||
@@ -700,6 +706,8 @@ ub_wait(struct ub_ctx* ctx)
|
||||
int r;
|
||||
uint8_t* msg;
|
||||
uint32_t len;
|
||||
if(!ctx || ctx->event_base)
|
||||
return UB_INITFAIL;
|
||||
/* this is basically the same loop as _process(), but with changes.
|
||||
* holds the rrpipe lock and waits with tube_wait */
|
||||
while(1) {
|
||||
@@ -837,6 +845,8 @@ ub_resolve_async(struct ub_ctx* ctx, const char* name, int rrtype,
|
||||
struct ctx_query* q;
|
||||
uint8_t* msg = NULL;
|
||||
uint32_t len = 0;
|
||||
if(!ctx || ctx->event_base)
|
||||
return UB_INITFAIL;
|
||||
|
||||
if(async_id)
|
||||
*async_id = 0;
|
||||
@@ -1467,8 +1477,15 @@ ub_ctx_set_event(struct ub_ctx* ctx, struct event_base* base) {
|
||||
|
||||
lock_basic_lock(&ctx->cfglock);
|
||||
/* destroy the current worker - safe to pass in NULL */
|
||||
|
||||
/* Unlock the cfglock during libworker_delete_event, since it
|
||||
* calls context_release_alloc, that wants to lock cfglock again.
|
||||
* Since the event base is used from one thread, the one that
|
||||
* called this function, it is safe to do so. */
|
||||
lock_basic_unlock(&ctx->cfglock);
|
||||
libworker_delete_event(ctx->event_worker);
|
||||
ctx->event_worker = NULL;
|
||||
lock_basic_lock(&ctx->cfglock);
|
||||
new_base = ub_libevent_event_base(base);
|
||||
if (new_base)
|
||||
ctx->event_base = new_base;
|
||||
|
||||
+11
-6
@@ -651,7 +651,8 @@ int libworker_fg(struct ub_ctx* ctx, struct ctx_query* q)
|
||||
}
|
||||
/* process new query */
|
||||
if(!mesh_new_callback(w->env->mesh, &qinfo, qflags, &edns,
|
||||
w->back->udp_buff, qid, libworker_fg_done_cb, q, 0)) {
|
||||
w->back->udp_buff, qid, libworker_fg_done_cb, q, 0,
|
||||
&q->unique_info)) {
|
||||
free(qinfo.qname);
|
||||
return UB_NOMEM;
|
||||
}
|
||||
@@ -732,7 +733,8 @@ int libworker_attach_mesh(struct ub_ctx* ctx, struct ctx_query* q,
|
||||
if(async_id)
|
||||
*async_id = q->querynum;
|
||||
if(!mesh_new_callback(w->env->mesh, &qinfo, qflags, &edns,
|
||||
w->back->udp_buff, qid, libworker_event_done_cb, q, 0)) {
|
||||
w->back->udp_buff, qid, libworker_event_done_cb, q, 0,
|
||||
&q->unique_info)) {
|
||||
free(qinfo.qname);
|
||||
return UB_NOMEM;
|
||||
}
|
||||
@@ -870,7 +872,8 @@ handle_newq(struct libworker* w, uint8_t* buf, uint32_t len)
|
||||
q->w = w;
|
||||
/* process new query */
|
||||
if(!mesh_new_callback(w->env->mesh, &qinfo, qflags, &edns,
|
||||
w->back->udp_buff, qid, libworker_bg_done_cb, q, 0)) {
|
||||
w->back->udp_buff, qid, libworker_bg_done_cb, q, 0,
|
||||
&q->unique_info)) {
|
||||
add_bg_result(w, q, NULL, UB_NOMEM, NULL, 0);
|
||||
}
|
||||
free(qinfo.qname);
|
||||
@@ -888,7 +891,8 @@ struct outbound_entry* libworker_send_query(struct query_info* qinfo,
|
||||
int check_ratelimit,
|
||||
struct sockaddr_storage* addr, socklen_t addrlen, uint8_t* zone,
|
||||
size_t zonelen, int tcp_upstream, int ssl_upstream, char* tls_auth_name,
|
||||
struct module_qstate* q, int* was_ratelimited)
|
||||
struct module_qstate* q, int* was_ratelimited,
|
||||
int* ratelimit_incremented)
|
||||
{
|
||||
struct libworker* w = (struct libworker*)q->env->worker;
|
||||
struct outbound_entry* e = (struct outbound_entry*)regional_alloc(
|
||||
@@ -900,7 +904,7 @@ struct outbound_entry* libworker_send_query(struct query_info* qinfo,
|
||||
want_dnssec, nocaps, check_ratelimit, tcp_upstream, ssl_upstream,
|
||||
tls_auth_name, addr, addrlen, zone, zonelen, q,
|
||||
libworker_handle_service_reply, e, w->back->udp_buff, q->env,
|
||||
was_ratelimited);
|
||||
was_ratelimited, ratelimit_incremented);
|
||||
if(!e->qsent) {
|
||||
return NULL;
|
||||
}
|
||||
@@ -985,7 +989,8 @@ struct outbound_entry* worker_send_query(struct query_info* ATTR_UNUSED(qinfo),
|
||||
struct sockaddr_storage* ATTR_UNUSED(addr), socklen_t ATTR_UNUSED(addrlen),
|
||||
uint8_t* ATTR_UNUSED(zone), size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream),
|
||||
int ATTR_UNUSED(ssl_upstream), char* ATTR_UNUSED(tls_auth_name),
|
||||
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited))
|
||||
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited),
|
||||
int* ATTR_UNUSED(ratelimit_incremented))
|
||||
{
|
||||
log_assert(0);
|
||||
return 0;
|
||||
|
||||
@@ -0,0 +1,65 @@
|
||||
/*
|
||||
* libunbound/remote.h - prototypes for remote control methods.
|
||||
*
|
||||
* Copyright (c) 2026, NLnet Labs. All rights reserved.
|
||||
*
|
||||
* This software is open source.
|
||||
*
|
||||
* Redistribution and use in source and binary forms, with or without
|
||||
* modification, are permitted provided that the following conditions
|
||||
* are met:
|
||||
*
|
||||
* Redistributions of source code must retain the above copyright notice,
|
||||
* this list of conditions and the following disclaimer.
|
||||
*
|
||||
* Redistributions in binary form must reproduce the above copyright notice,
|
||||
* this list of conditions and the following disclaimer in the documentation
|
||||
* and/or other materials provided with the distribution.
|
||||
*
|
||||
* Neither the name of the NLNET LABS nor the names of its contributors may
|
||||
* be used to endorse or promote products derived from this software without
|
||||
* specific prior written permission.
|
||||
*
|
||||
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
||||
* "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
||||
* LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
|
||||
* A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
|
||||
* HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
|
||||
* SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED
|
||||
* TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
|
||||
* PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
|
||||
* LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
|
||||
* NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
|
||||
* SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||
*/
|
||||
|
||||
/**
|
||||
* \file
|
||||
*
|
||||
* This file declares the methods that must be implemented to use the
|
||||
* remote control service.
|
||||
*/
|
||||
|
||||
#ifndef LIBUNBOUND_REMOTE_H
|
||||
#define LIBUNBOUND_REMOTE_H
|
||||
|
||||
struct comm_reply;
|
||||
struct comm_point;
|
||||
|
||||
/** fast reload thread commands to remote service thread event callback */
|
||||
void fast_reload_service_cb(int fd, short bits, void* arg);
|
||||
|
||||
/** fast reload callback for the remote control client connection */
|
||||
int fast_reload_client_callback(struct comm_point* c, void* arg, int err,
|
||||
struct comm_reply* rep);
|
||||
|
||||
/** handle remote control accept callbacks */
|
||||
int remote_accept_callback(struct comm_point*, void*, int, struct comm_reply*);
|
||||
|
||||
/** handle remote control data callbacks */
|
||||
int remote_control_callback(struct comm_point*, void*, int, struct comm_reply*);
|
||||
|
||||
/** routine to printout option values over SSL */
|
||||
void remote_get_opt_ssl(char* line, void* arg);
|
||||
|
||||
#endif /* LIBUNBOUND_REMOTE_H */
|
||||
+8
-11
@@ -70,6 +70,8 @@ struct query_info;
|
||||
* @param q: which query state to reactivate upon return.
|
||||
* @param was_ratelimited: it will signal back if the query failed to pass the
|
||||
* ratelimit check.
|
||||
* @param ratelimit_incremented: set to true if the ratelimit counter
|
||||
* was increased.
|
||||
* @return: false on failure (memory or socket related). no query was
|
||||
* sent.
|
||||
*/
|
||||
@@ -78,7 +80,8 @@ struct outbound_entry* libworker_send_query(struct query_info* qinfo,
|
||||
int check_ratelimit,
|
||||
struct sockaddr_storage* addr, socklen_t addrlen, uint8_t* zone,
|
||||
size_t zonelen, int tcp_upstream, int ssl_upstream, char* tls_auth_name,
|
||||
struct module_qstate* q, int* was_ratelimited);
|
||||
struct module_qstate* q, int* was_ratelimited,
|
||||
int* ratelimit_incremented);
|
||||
|
||||
/** process incoming serviced query replies from the network */
|
||||
int libworker_handle_service_reply(struct comm_point* c, void* arg, int error,
|
||||
@@ -126,6 +129,8 @@ void worker_sighandler(int sig, void* arg);
|
||||
* @param q: which query state to reactivate upon return.
|
||||
* @param was_ratelimited: it will signal back if the query failed to pass the
|
||||
* ratelimit check.
|
||||
* @param ratelimit_incremented: set to true if the ratelimit counter
|
||||
* was increased.
|
||||
* @return: false on failure (memory or socket related). no query was
|
||||
* sent.
|
||||
*/
|
||||
@@ -134,7 +139,8 @@ struct outbound_entry* worker_send_query(struct query_info* qinfo,
|
||||
int check_ratelimit,
|
||||
struct sockaddr_storage* addr, socklen_t addrlen, uint8_t* zone,
|
||||
size_t zonelen, int tcp_upstream, int ssl_upstream, char* tls_auth_name,
|
||||
struct module_qstate* q, int* was_ratelimited);
|
||||
struct module_qstate* q, int* was_ratelimited,
|
||||
int* ratelimit_incremented);
|
||||
|
||||
/**
|
||||
* process control messages from the main thread. Frees the control
|
||||
@@ -171,13 +177,4 @@ void worker_start_accept(void* arg);
|
||||
/** stop accept callback handler */
|
||||
void worker_stop_accept(void* arg);
|
||||
|
||||
/** handle remote control accept callbacks */
|
||||
int remote_accept_callback(struct comm_point*, void*, int, struct comm_reply*);
|
||||
|
||||
/** handle remote control data callbacks */
|
||||
int remote_control_callback(struct comm_point*, void*, int, struct comm_reply*);
|
||||
|
||||
/** routine to printout option values over SSL */
|
||||
void remote_get_opt_ssl(char* line, void* arg);
|
||||
|
||||
#endif /* LIBUNBOUND_WORKER_H */
|
||||
|
||||
@@ -466,9 +466,13 @@ if [ "$DOWIN" = "yes" ]; then
|
||||
|| error_cleanup "Could not configure"
|
||||
set +x
|
||||
else
|
||||
# Add -l:libssp:a to statically link libssp if possible.
|
||||
# Put it at the end of LIBS, to satisfy also linked in
|
||||
# dependencies.
|
||||
set -x
|
||||
$configure --enable-debug --enable-static-exe --disable-flto --disable-gost $* $cross_flag \
|
||||
|| error_cleanup "Could not configure"
|
||||
sed -i Makefile -e 's/^\(LIBS=.*\)$/\1 -l:libssp.a/'
|
||||
set +x
|
||||
fi
|
||||
info "Calling make"
|
||||
@@ -485,6 +489,7 @@ if [ "$DOWIN" = "yes" ]; then
|
||||
|| error_cleanup "Could not configure"
|
||||
set +x
|
||||
else
|
||||
# Do not add -l:libssp:a statically because it is a shared build.
|
||||
set -x
|
||||
$configure --enable-debug --disable-flto --disable-gost $* $shared_cross_flag \
|
||||
|| error_cleanup "Could not configure"
|
||||
@@ -603,6 +608,8 @@ rm -rf .git .travis.yml .gitattributes .github .gitignore || error_cleanup "Fail
|
||||
info "Adding libtool utils (libtoolize)."
|
||||
libtoolize -c --install || libtoolize -c || error_cleanup "Libtoolize failed."
|
||||
|
||||
# Turn this off, if the git repo times out for lookups.
|
||||
if test "updateconfigsub" = "false"; then
|
||||
# https://www.gnu.org/software/gettext/manual/html_node/config_002eguess.html
|
||||
info "Updating config.guess and config.sub"
|
||||
wget -O config.guess 'https://git.savannah.gnu.org/gitweb/?p=config.git;a=blob_plain;f=config.guess;hb=HEAD'
|
||||
@@ -616,6 +623,7 @@ if [ `uname -s | grep -i -c darwin` -ne 0 ]; then
|
||||
xattr -d com.apple.quarantine config.sub
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
|
||||
info "Building configure script (autoreconf)."
|
||||
autoreconf -f || error_cleanup "Autoconf failed."
|
||||
|
||||
+16
-15
@@ -79,7 +79,7 @@
|
||||
i+(int)((unsigned int)name[i]) < len) {
|
||||
memmove(buf, name + i + 1, (unsigned int)name[i]);
|
||||
buf[(unsigned int)name[i]] = 0;
|
||||
PyList_SetItem(list, cnt, PyString_FromString(buf));
|
||||
PyList_SetItem(list, cnt, PyUnicode_FromString(buf));
|
||||
}
|
||||
i += ((unsigned int)name[i]) + 1;
|
||||
cnt++;
|
||||
@@ -96,7 +96,7 @@
|
||||
|
||||
list = PyList_New(len);
|
||||
for (i=0; i < len; i++) {
|
||||
PyList_SET_ITEM(list, i, PyString_FromString(array[i]));
|
||||
PyList_SET_ITEM(list, i, PyUnicode_FromString(array[i]));
|
||||
}
|
||||
return list;
|
||||
}
|
||||
@@ -207,7 +207,7 @@ struct query_info {
|
||||
char buf[LDNS_MAX_DOMAINLEN];
|
||||
buf[0] = '\0';
|
||||
dname_str((uint8_t*)PyBytes_AsString(dname), buf);
|
||||
return PyString_FromString(buf);
|
||||
return PyUnicode_FromString(buf);
|
||||
}
|
||||
%}
|
||||
|
||||
@@ -345,7 +345,7 @@ struct packed_rrset_data {
|
||||
PyObject* _get_data_rr_len(struct packed_rrset_data* d, int idx) {
|
||||
if ((d != NULL) && (idx >= 0) &&
|
||||
((size_t)idx < (d->count+d->rrsig_count)))
|
||||
return PyInt_FromLong(d->rr_len[idx]);
|
||||
return PyLong_FromLong(d->rr_len[idx]);
|
||||
return Py_None;
|
||||
}
|
||||
void _set_data_rr_ttl(struct packed_rrset_data* d, int idx, uint32_t ttl)
|
||||
@@ -357,7 +357,7 @@ struct packed_rrset_data {
|
||||
PyObject* _get_data_rr_ttl(struct packed_rrset_data* d, int idx) {
|
||||
if ((d != NULL) && (idx >= 0) &&
|
||||
((size_t)idx < (d->count+d->rrsig_count)))
|
||||
return PyInt_FromLong(d->rr_ttl[idx]);
|
||||
return PyLong_FromLong(d->rr_ttl[idx]);
|
||||
return Py_None;
|
||||
}
|
||||
PyObject* _get_data_rr_data(struct packed_rrset_data* d, int idx) {
|
||||
@@ -555,12 +555,12 @@ struct sockaddr_storage {};
|
||||
|
||||
if (ss->ss_family == AF_INET) {
|
||||
const struct sockaddr_in *sa4 = (struct sockaddr_in *)ss;
|
||||
return PyInt_FromLong(ntohs(sa4->sin_port));
|
||||
return PyLong_FromLong(ntohs(sa4->sin_port));
|
||||
}
|
||||
|
||||
if (ss->ss_family == AF_INET6) {
|
||||
const struct sockaddr_in6 *sa6 = (struct sockaddr_in6 *)ss;
|
||||
return PyInt_FromLong(ntohs(sa6->sin6_port));
|
||||
return PyLong_FromLong(ntohs(sa6->sin6_port));
|
||||
}
|
||||
|
||||
return Py_None;
|
||||
@@ -574,7 +574,7 @@ struct sockaddr_storage {};
|
||||
}
|
||||
|
||||
sa6 = (struct sockaddr_in6 *)ss;
|
||||
return PyInt_FromLong(ntohl(sa6->sin6_flowinfo));
|
||||
return PyLong_FromLong(ntohl(sa6->sin6_flowinfo));
|
||||
}
|
||||
|
||||
PyObject *_sockaddr_storage_scope_id(const struct sockaddr_storage *ss) {
|
||||
@@ -585,7 +585,7 @@ struct sockaddr_storage {};
|
||||
}
|
||||
|
||||
sa6 = (struct sockaddr_in6 *)ss;
|
||||
return PyInt_FromLong(ntohl(sa6->sin6_scope_id));
|
||||
return PyLong_FromLong(ntohl(sa6->sin6_scope_id));
|
||||
}
|
||||
%}
|
||||
|
||||
@@ -661,7 +661,7 @@ struct edns_option {
|
||||
%inline %{
|
||||
PyObject* _edns_option_opt_code_get(struct edns_option* option) {
|
||||
uint16_t opt_code = option->opt_code;
|
||||
return PyInt_FromLong(opt_code);
|
||||
return PyLong_FromLong(opt_code);
|
||||
}
|
||||
|
||||
PyObject* _edns_option_opt_data_get(struct edns_option* option) {
|
||||
@@ -729,7 +729,8 @@ struct module_env {
|
||||
int check_ratelimit,
|
||||
struct sockaddr_storage* addr, socklen_t addrlen,
|
||||
uint8_t* zone, size_t zonelen, int tcp_upstream, int ssl_upstream,
|
||||
char* tls_auth_name, struct module_qstate* q, int* was_ratelimited);
|
||||
char* tls_auth_name, struct module_qstate* q, int* was_ratelimited,
|
||||
int* ratelimit_incremented);
|
||||
void (*detach_subs)(struct module_qstate* qstate);
|
||||
int (*attach_sub)(struct module_qstate* qstate,
|
||||
struct query_info* qinfo, struct respip_client_info* cinfo,
|
||||
@@ -1626,7 +1627,7 @@ int edns_opt_list_append(struct edns_option** list, uint16_t code, size_t len,
|
||||
}
|
||||
result = PyObject_Call(func, py_args, py_kwargs);
|
||||
if (result) {
|
||||
res = PyInt_AsLong(result);
|
||||
res = PyLong_AsLong(result);
|
||||
}
|
||||
out:
|
||||
Py_XDECREF(py_edns);
|
||||
@@ -1710,7 +1711,7 @@ out:
|
||||
}
|
||||
result = PyObject_Call(func, py_args, py_kwargs);
|
||||
if (result) {
|
||||
res = PyInt_AsLong(result);
|
||||
res = PyLong_AsLong(result);
|
||||
}
|
||||
out:
|
||||
Py_XDECREF(py_qinfo);
|
||||
@@ -1764,7 +1765,7 @@ out:
|
||||
}
|
||||
result = PyObject_Call(func, py_args, py_kwargs);
|
||||
if (result) {
|
||||
res = PyInt_AsLong(result);
|
||||
res = PyLong_AsLong(result);
|
||||
}
|
||||
out:
|
||||
Py_XDECREF(py_qstate);
|
||||
@@ -1813,7 +1814,7 @@ out:
|
||||
}
|
||||
result = PyObject_Call(func, py_args, py_kwargs);
|
||||
if (result) {
|
||||
res = PyInt_AsLong(result);
|
||||
res = PyLong_AsLong(result);
|
||||
}
|
||||
out:
|
||||
Py_XDECREF(py_qstate);
|
||||
|
||||
+18
-5
@@ -246,14 +246,14 @@ log_py_err(void)
|
||||
}
|
||||
|
||||
/* And it should be a string all ready to go - duplicate it. */
|
||||
if (!PyString_Check(obResult) && !PyUnicode_Check(obResult)) {
|
||||
if (!PyBytes_Check(obResult) && !PyUnicode_Check(obResult)) {
|
||||
log_err("pythonmod: cannot print exception, "
|
||||
"StringIO.getvalue() result did not String_Check"
|
||||
" or Unicode_Check");
|
||||
goto cleanup;
|
||||
}
|
||||
if(PyString_Check(obResult)) {
|
||||
result = PyString_AsString(obResult);
|
||||
if(PyBytes_Check(obResult)) {
|
||||
result = PyBytes_AsString(obResult);
|
||||
} else {
|
||||
ascstr = PyUnicode_AsASCIIString(obResult);
|
||||
result = PyBytes_AsString(ascstr);
|
||||
@@ -450,7 +450,7 @@ int pythonmod_init(struct module_env* env, int id)
|
||||
|
||||
pe->data = PyDict_New();
|
||||
/* add the script filename to the global "mod_env" for trivial access */
|
||||
fname = PyString_FromString(pe->fname);
|
||||
fname = PyUnicode_FromString(pe->fname);
|
||||
if(PyDict_SetItemString(pe->data, "script", fname) < 0) {
|
||||
log_err("pythonmod: could not add item to dictionary");
|
||||
Py_XDECREF(fname);
|
||||
@@ -487,10 +487,23 @@ int pythonmod_init(struct module_env* env, int id)
|
||||
/* for python 3.9 and newer */
|
||||
char* fstr = NULL;
|
||||
size_t flen = 0;
|
||||
long pos = 0;
|
||||
log_err("pythonmod: can't parse Python script %s", pe->fname);
|
||||
/* print the error to logs too, run it again */
|
||||
fseek(script_py, 0, SEEK_END);
|
||||
flen = (size_t)ftell(script_py);
|
||||
pos = ftell(script_py);
|
||||
if (pos == -1L) {
|
||||
log_err("ftell failed to print parse error: %s: %s",
|
||||
pe->fname, strerror(errno));
|
||||
goto fail_close_file;
|
||||
}
|
||||
flen = (size_t)pos;
|
||||
#ifdef SIZE_MAX
|
||||
if(flen > SIZE_MAX-2) {
|
||||
log_err("script file too large");
|
||||
goto fail_close_file;
|
||||
}
|
||||
#endif
|
||||
fstr = malloc(flen+1);
|
||||
if(!fstr) {
|
||||
log_err("malloc failure to print parse error");
|
||||
|
||||
+32
-21
@@ -899,27 +899,34 @@ respip_rewrite_reply(const struct query_info* qinfo,
|
||||
int rpz_cname_override = 0;
|
||||
char* log_name = NULL;
|
||||
|
||||
if(!cinfo)
|
||||
goto done;
|
||||
ctaglist = cinfo->taglist;
|
||||
ctaglen = cinfo->taglen;
|
||||
tag_actions = cinfo->tag_actions;
|
||||
tag_actions_size = cinfo->tag_actions_size;
|
||||
tag_datas = cinfo->tag_datas;
|
||||
tag_datas_size = cinfo->tag_datas_size;
|
||||
if(cinfo->view) {
|
||||
view = cinfo->view;
|
||||
lock_rw_rdlock(&view->lock);
|
||||
} else if(cinfo->view_name) {
|
||||
view = views_find_view(views, cinfo->view_name, 0);
|
||||
if(!view) {
|
||||
/* If the view no longer exists, the rewrite can not
|
||||
* be processed further. */
|
||||
verbose(VERB_ALGO, "respip: failed because view %s no "
|
||||
"longer exists", cinfo->view_name);
|
||||
return 0;
|
||||
if(!cinfo) {
|
||||
/* Internal mesh sub-query (e.g. dns64 A lookup): no
|
||||
* per-client view/tags, but global response-ip and RPZ
|
||||
* rpz-ip must still apply. */
|
||||
ctaglist = NULL; ctaglen = 0;
|
||||
tag_actions = NULL; tag_actions_size = 0;
|
||||
tag_datas = NULL; tag_datas_size = 0;
|
||||
} else {
|
||||
ctaglist = cinfo->taglist;
|
||||
ctaglen = cinfo->taglen;
|
||||
tag_actions = cinfo->tag_actions;
|
||||
tag_actions_size = cinfo->tag_actions_size;
|
||||
tag_datas = cinfo->tag_datas;
|
||||
tag_datas_size = cinfo->tag_datas_size;
|
||||
if(cinfo->view) {
|
||||
view = cinfo->view;
|
||||
lock_rw_rdlock(&view->lock);
|
||||
} else if(cinfo->view_name) {
|
||||
view = views_find_view(views, cinfo->view_name, 0);
|
||||
if(!view) {
|
||||
/* If the view no longer exists, the rewrite can not
|
||||
* be processed further. */
|
||||
verbose(VERB_ALGO, "respip: failed because view %s no "
|
||||
"longer exists", cinfo->view_name);
|
||||
return 0;
|
||||
}
|
||||
/* The view is rdlocked by views_find_view. */
|
||||
}
|
||||
/* The view is rdlocked by views_find_view. */
|
||||
}
|
||||
|
||||
log_assert(ipset);
|
||||
@@ -1157,8 +1164,10 @@ respip_operate(struct module_qstate* qstate, enum module_ev event, int id,
|
||||
* clients. */
|
||||
qstate->is_drop = 1;
|
||||
} else if(alias_rrset) {
|
||||
if(!generate_cname_request(qstate, alias_rrset))
|
||||
if(!generate_cname_request(qstate, alias_rrset)) {
|
||||
errinf(qstate, "Could not generate CNAME request");
|
||||
goto servfail;
|
||||
}
|
||||
next_state = module_wait_subquery;
|
||||
}
|
||||
qstate->return_msg->rep = new_rep;
|
||||
@@ -1172,6 +1181,7 @@ respip_operate(struct module_qstate* qstate, enum module_ev event, int id,
|
||||
servfail:
|
||||
qstate->return_rcode = LDNS_RCODE_SERVFAIL;
|
||||
qstate->return_msg = NULL;
|
||||
qstate->ext_state[id] = module_finished;
|
||||
}
|
||||
|
||||
int
|
||||
@@ -1268,6 +1278,7 @@ respip_inform_super(struct module_qstate* qstate, int id,
|
||||
return;
|
||||
|
||||
fail:
|
||||
errinf(super, "CNAME lookup failed");
|
||||
super->return_rcode = LDNS_RCODE_SERVFAIL;
|
||||
super->return_msg = NULL;
|
||||
return;
|
||||
|
||||
+290
-59
@@ -55,6 +55,7 @@
|
||||
#include "util/log.h"
|
||||
#include "util/module.h"
|
||||
#include "util/random.h"
|
||||
#include "util/timeval_func.h"
|
||||
#include "services/cache/dns.h"
|
||||
#include "services/outside_network.h"
|
||||
#include "services/listen_dnsport.h"
|
||||
@@ -95,6 +96,8 @@
|
||||
/** number of timeouts before we fallback from IXFR to AXFR,
|
||||
* because some versions of servers (eg. dnsmasq) drop IXFR packets. */
|
||||
#define NUM_TIMEOUTS_FALLBACK_IXFR 3
|
||||
/** number of IXFRs before an AXFR is performed, to consolidate RPZ memory. */
|
||||
#define NUM_IXFR_BEFORE_AXFR 5
|
||||
|
||||
/** pick up nextprobe task to start waiting to perform transfer actions */
|
||||
static void xfr_set_timeout(struct auth_xfer* xfr, struct module_env* env,
|
||||
@@ -106,6 +109,9 @@ static void xfr_probe_send_or_end(struct auth_xfer* xfr,
|
||||
* or transfer task if nothing to probe, or false if already in progress */
|
||||
static int xfr_start_probe(struct auth_xfer* xfr, struct module_env* env,
|
||||
struct auth_master* spec);
|
||||
/** copy the master addresses from the task_probe lookups to the allow_notify
|
||||
* list of masters */
|
||||
static void probe_copy_masters_for_allow_notify(struct auth_xfer* xfr);
|
||||
/** delete xfer structure (not its tree entry) */
|
||||
void auth_xfer_delete(struct auth_xfer* xfr);
|
||||
|
||||
@@ -432,7 +438,12 @@ auth_zone_create(struct auth_zones* az, uint8_t* nm, size_t nmlen,
|
||||
rbtree_init(&z->data, &auth_data_cmp);
|
||||
lock_rw_init(&z->lock);
|
||||
lock_protect(&z->lock, &z->name, sizeof(*z)-sizeof(rbnode_type)-
|
||||
sizeof(&z->rpz_az_next)-sizeof(&z->rpz_az_prev));
|
||||
sizeof(z->rpz_az_next)-sizeof(z->rpz_az_prev)-
|
||||
sizeof(z->max_transfer_size)-sizeof(z->max_transfer_size));
|
||||
lock_protect(&z->lock, &z->max_transfer_size,
|
||||
sizeof(z->max_transfer_size));
|
||||
lock_protect(&z->lock, &z->max_transfer_time,
|
||||
sizeof(z->max_transfer_time));
|
||||
lock_rw_wrlock(&z->lock);
|
||||
/* z lock protects all, except rbtree itself and the rpz linked list
|
||||
* pointers, which are protected using az->lock */
|
||||
@@ -1175,6 +1186,22 @@ az_insert_rr(struct auth_zone* z, uint8_t* rr, size_t rr_len,
|
||||
log_err("wrong class for RR");
|
||||
return 0;
|
||||
}
|
||||
if(rr_type == LDNS_RR_TYPE_A && rdatalen != 6 /* 2 + 4 */) {
|
||||
log_err("malformed A record");
|
||||
return 0;
|
||||
} else if(rr_type == LDNS_RR_TYPE_AAAA && rdatalen != 18 /* 2 + 16 */) {
|
||||
log_err("malformed AAAA record");
|
||||
return 0;
|
||||
}
|
||||
if(!dname_subdomain_c(dname, z->name)) {
|
||||
char nm[LDNS_MAX_DOMAINLEN], zn[LDNS_MAX_DOMAINLEN];
|
||||
dname_str(dname, nm);
|
||||
dname_str(z->name, zn);
|
||||
verbose(VERB_ALGO, "auth-zone %s: dropping out-of-zone RR "
|
||||
"%s", zn, nm);
|
||||
if(duplicate) *duplicate=1; /* treat as bad insert */
|
||||
return 1;
|
||||
}
|
||||
if(!(node=az_domain_find_or_create(z, dname, dname_len))) {
|
||||
log_err("cannot create domain");
|
||||
return 0;
|
||||
@@ -1182,6 +1209,10 @@ az_insert_rr(struct auth_zone* z, uint8_t* rr, size_t rr_len,
|
||||
if(!az_domain_add_rr(node, rr_type, rr_ttl, rdata, rdatalen,
|
||||
duplicate)) {
|
||||
log_err("cannot add RR to domain");
|
||||
if(node->rrsets == NULL) {
|
||||
(void)rbtree_delete(&z->data, node);
|
||||
auth_data_delete(node);
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
if(z->rpz) {
|
||||
@@ -1505,6 +1536,11 @@ az_parse_file(struct auth_zone* z, FILE* in, uint8_t* rr, size_t rrbuflen,
|
||||
"exceeded", fname, state->lineno);
|
||||
return 0;
|
||||
}
|
||||
/* A $INCLUDE is not expected for a secondary zone. */
|
||||
if(z->zone_is_slave) {
|
||||
log_err("%s:%d $INCLUDE not allowed for secondary zone", fname, state->lineno);
|
||||
return 0;
|
||||
}
|
||||
/* skip spaces */
|
||||
while(*incfile == ' ' || *incfile == '\t')
|
||||
incfile++;
|
||||
@@ -1570,6 +1606,16 @@ az_parse_file(struct auth_zone* z, FILE* in, uint8_t* rr, size_t rrbuflen,
|
||||
return 1;
|
||||
}
|
||||
|
||||
void auth_zone_clear_data(struct auth_zone* z)
|
||||
{
|
||||
/* clear the data tree */
|
||||
traverse_postorder(&z->data, auth_data_del, NULL);
|
||||
rbtree_init(&z->data, &auth_data_cmp);
|
||||
/* clear the RPZ policies */
|
||||
if(z->rpz)
|
||||
rpz_clear(z->rpz);
|
||||
}
|
||||
|
||||
int
|
||||
auth_zone_read_zonefile(struct auth_zone* z, struct config_file* cfg)
|
||||
{
|
||||
@@ -1592,10 +1638,16 @@ auth_zone_read_zonefile(struct auth_zone* z, struct config_file* cfg)
|
||||
in = fopen(zfilename, "r");
|
||||
if(!in) {
|
||||
char* n = sldns_wire2str_dname(z->name, z->namelen);
|
||||
if(z->zone_is_slave && errno == ENOENT) {
|
||||
/* we fetch the zone contents later, no file yet */
|
||||
verbose(VERB_ALGO, "no zonefile %s for %s",
|
||||
zfilename, n?n:"error");
|
||||
if(errno == ENOENT) {
|
||||
/* For a secondary, fetch the zone contents later, no
|
||||
* file yet. For a primary, no way to fetch the zone,
|
||||
* so warn. */
|
||||
if(z->zone_is_slave)
|
||||
verbose(VERB_ALGO, "no zonefile %s for %s",
|
||||
zfilename, n?n:"error");
|
||||
else
|
||||
log_warn("no zonefile %s for %s",
|
||||
zfilename, n?n:"error");
|
||||
free(n);
|
||||
return 1;
|
||||
}
|
||||
@@ -1798,9 +1850,11 @@ auth_zones_read_zones(struct auth_zones* az, struct config_file* cfg,
|
||||
RBTREE_FOR(z, struct auth_zone*, &az->ztree) {
|
||||
lock_rw_wrlock(&z->lock);
|
||||
if(!auth_zone_read_zonefile(z, cfg)) {
|
||||
/* For both secondary and primary zones, not fatal.
|
||||
* This keeps the server up. */
|
||||
auth_zone_clear_data(z);
|
||||
lock_rw_unlock(&z->lock);
|
||||
lock_rw_unlock(&az->lock);
|
||||
return 0;
|
||||
continue;
|
||||
}
|
||||
if(z->zonefile && z->zonefile[0]!=0 && env)
|
||||
zonemd_offline_verify(z, env, mods);
|
||||
@@ -2076,6 +2130,7 @@ auth_xfer_setup(struct auth_zone* z, struct auth_xfer* x)
|
||||
if(!xfr_find_soa(z, x)) {
|
||||
return 1;
|
||||
}
|
||||
x->is_rpz = (z->rpz!=NULL);
|
||||
/* nothing for probe, nextprobe and transfer tasks */
|
||||
return 1;
|
||||
}
|
||||
@@ -2135,6 +2190,9 @@ auth_zones_cfg(struct auth_zones* az, struct config_auth* c)
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
/* Populate the xfer related options early since we may create one now */
|
||||
z->max_transfer_size = c->max_transfer_size;
|
||||
z->max_transfer_time = c->max_transfer_time;
|
||||
if(c->masters || c->urls) {
|
||||
if(!(x=auth_zones_find_or_add_xfer(az, z))) {
|
||||
lock_rw_unlock(&az->lock);
|
||||
@@ -2168,7 +2226,12 @@ auth_zones_cfg(struct auth_zones* az, struct config_auth* c)
|
||||
z->zonemd_reject_absence = c->zonemd_reject_absence;
|
||||
if(c->isrpz && !z->rpz){
|
||||
if(!(z->rpz = rpz_create(c))){
|
||||
fatal_exit("Could not setup RPZ zones");
|
||||
log_err("Could not setup RPZ zones");
|
||||
if(x) {
|
||||
lock_basic_unlock(&x->lock);
|
||||
}
|
||||
lock_rw_unlock(&z->lock);
|
||||
lock_rw_unlock(&az->rpz_lock);
|
||||
return 0;
|
||||
}
|
||||
lock_protect(&z->lock, &z->rpz->local_zones, sizeof(*z->rpz));
|
||||
@@ -2206,6 +2269,10 @@ auth_zones_cfg(struct auth_zones* az, struct config_auth* c)
|
||||
lock_rw_unlock(&z->lock);
|
||||
return 0;
|
||||
}
|
||||
/* Pick up allow notify entries, early. This works for
|
||||
* addresses and netblocks. */
|
||||
if(!x->allow_notify_list)
|
||||
probe_copy_masters_for_allow_notify(x);
|
||||
lock_basic_unlock(&x->lock);
|
||||
}
|
||||
|
||||
@@ -2313,6 +2380,7 @@ auth_chunks_delete(struct auth_transfer* at)
|
||||
}
|
||||
at->chunks_first = NULL;
|
||||
at->chunks_last = NULL;
|
||||
at->chunks_total = 0;
|
||||
}
|
||||
|
||||
/** free master addr list */
|
||||
@@ -2644,7 +2712,7 @@ az_empty_nonterminal(struct auth_zone* z, struct query_info* qinfo,
|
||||
while(next && (rbnode_type*)next != RBTREE_NULL && next->rrsets == NULL) {
|
||||
/* the next name has empty rrsets, is an empty nonterminal
|
||||
* itself, see if there exists something below it */
|
||||
next = (struct auth_data*)rbtree_next(&node->node);
|
||||
next = (struct auth_data*)rbtree_next(&next->node);
|
||||
}
|
||||
if((rbnode_type*)next == RBTREE_NULL || !next) {
|
||||
/* there is no next node, so something below it cannot
|
||||
@@ -4298,7 +4366,7 @@ xfr_create_ixfr_packet(struct auth_xfer* xfr, sldns_buffer* buf, uint16_t id,
|
||||
{
|
||||
struct query_info qinfo;
|
||||
uint32_t serial;
|
||||
int have_zone;
|
||||
int have_zone, get_full = 0;
|
||||
have_zone = xfr->have_zone;
|
||||
serial = xfr->serial;
|
||||
|
||||
@@ -4311,7 +4379,18 @@ xfr_create_ixfr_packet(struct auth_xfer* xfr, sldns_buffer* buf, uint16_t id,
|
||||
xfr->task_transfer->on_ixfr_is_axfr = 0;
|
||||
xfr->task_transfer->on_ixfr = 1;
|
||||
qinfo.qtype = LDNS_RR_TYPE_IXFR;
|
||||
if(!have_zone || xfr->task_transfer->ixfr_fail || !master->ixfr) {
|
||||
if(xfr->num_ixfrs >= NUM_IXFR_BEFORE_AXFR && xfr->is_rpz) {
|
||||
/* For the RPZ, an IXFR is going to grow regions, and a
|
||||
* full transfer, zonefile read, AXFR and HTTP clear the
|
||||
* region, but IXFR does not. That memory keeps growing,
|
||||
* and getting a full transfer with AXFR here resets that.
|
||||
* The rpz->client_set->region, rpz->ns_set->region and
|
||||
* rpz->respip_set->region need to be reset, they are for
|
||||
* rpz-client-ip, rpz-nsip and rpz-ip. */
|
||||
get_full = 1;
|
||||
}
|
||||
if(!have_zone || xfr->task_transfer->ixfr_fail || !master->ixfr
|
||||
|| get_full) {
|
||||
qinfo.qtype = LDNS_RR_TYPE_AXFR;
|
||||
xfr->task_transfer->ixfr_fail = 0;
|
||||
xfr->task_transfer->on_ixfr = 0;
|
||||
@@ -4462,29 +4541,31 @@ chunkline_get_line(struct auth_chunk** chunk, size_t* chunk_pos,
|
||||
}
|
||||
|
||||
/** count number of open and closed parenthesis in a chunkline */
|
||||
static int
|
||||
int
|
||||
chunkline_count_parens(sldns_buffer* buf, size_t start)
|
||||
{
|
||||
size_t end = sldns_buffer_position(buf);
|
||||
size_t i;
|
||||
int count = 0;
|
||||
int squote = 0, dquote = 0;
|
||||
int dquote = 0;
|
||||
char prev_c = 0;
|
||||
for(i=start; i<end; i++) {
|
||||
char c = (char)sldns_buffer_read_u8_at(buf, i);
|
||||
if(squote && c != '\'') continue;
|
||||
if(dquote && c != '"') continue;
|
||||
if(c == '"')
|
||||
if(dquote && !(c == '"' && prev_c != '\\')) {
|
||||
prev_c = (prev_c == '\\' && c == '\\') ? 0 : c;
|
||||
continue;
|
||||
}
|
||||
if(c == '"' && prev_c != '\\')
|
||||
dquote = !dquote; /* skip quoted part */
|
||||
else if(c == '\'')
|
||||
squote = !squote; /* skip quoted part */
|
||||
else if(c == '(')
|
||||
else if(c == '(' && prev_c != '\\')
|
||||
count ++;
|
||||
else if(c == ')')
|
||||
else if(c == ')' && prev_c != '\\')
|
||||
count --;
|
||||
else if(c == ';') {
|
||||
else if(c == ';' && prev_c != '\\') {
|
||||
/* rest is a comment */
|
||||
return count;
|
||||
}
|
||||
prev_c = (prev_c == '\\' && c == '\\') ? 0 : c;
|
||||
}
|
||||
return count;
|
||||
}
|
||||
@@ -4495,20 +4576,22 @@ chunkline_remove_trailcomment(sldns_buffer* buf, size_t start)
|
||||
{
|
||||
size_t end = sldns_buffer_position(buf);
|
||||
size_t i;
|
||||
int squote = 0, dquote = 0;
|
||||
int dquote = 0;
|
||||
char prev_c = 0;
|
||||
for(i=start; i<end; i++) {
|
||||
char c = (char)sldns_buffer_read_u8_at(buf, i);
|
||||
if(squote && c != '\'') continue;
|
||||
if(dquote && c != '"') continue;
|
||||
if(c == '"')
|
||||
if(dquote && !(c == '"' && prev_c != '\\')) {
|
||||
prev_c = (prev_c == '\\' && c == '\\') ? 0 : c;
|
||||
continue;
|
||||
}
|
||||
if(c == '"' && prev_c != '\\')
|
||||
dquote = !dquote; /* skip quoted part */
|
||||
else if(c == '\'')
|
||||
squote = !squote; /* skip quoted part */
|
||||
else if(c == ';') {
|
||||
else if(c == ';' && prev_c != '\\') {
|
||||
/* rest is a comment */
|
||||
sldns_buffer_set_position(buf, i);
|
||||
return;
|
||||
}
|
||||
prev_c = (prev_c == '\\' && c == '\\') ? 0 : c;
|
||||
}
|
||||
/* nothing to remove */
|
||||
}
|
||||
@@ -4932,6 +5015,8 @@ apply_ixfr(struct auth_xfer* xfr, struct auth_zone* z,
|
||||
int delmode = 0;
|
||||
int softfail = 0;
|
||||
|
||||
xfr->num_ixfrs++;
|
||||
|
||||
/* start RR iterator over chunklist of packets */
|
||||
chunk_rrlist_start(xfr, &rr_chunk, &rr_num, &rr_pos);
|
||||
while(!chunk_rrlist_end(rr_chunk, rr_num)) {
|
||||
@@ -5067,16 +5152,11 @@ apply_axfr(struct auth_xfer* xfr, struct auth_zone* z,
|
||||
size_t rr_counter = 0;
|
||||
int have_end_soa = 0;
|
||||
|
||||
/* clear the data tree */
|
||||
traverse_postorder(&z->data, auth_data_del, NULL);
|
||||
rbtree_init(&z->data, &auth_data_cmp);
|
||||
/* clear the RPZ policies */
|
||||
if(z->rpz)
|
||||
rpz_clear(z->rpz);
|
||||
|
||||
auth_zone_clear_data(z);
|
||||
xfr->have_zone = 0;
|
||||
xfr->serial = 0;
|
||||
xfr->soa_zone_acquired = 0;
|
||||
xfr->num_ixfrs = 0;
|
||||
|
||||
/* insert all RRs in to the zone */
|
||||
/* insert the SOA only once, skip the last one */
|
||||
@@ -5169,16 +5249,11 @@ apply_http(struct auth_xfer* xfr, struct auth_zone* z,
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* clear the data tree */
|
||||
traverse_postorder(&z->data, auth_data_del, NULL);
|
||||
rbtree_init(&z->data, &auth_data_cmp);
|
||||
/* clear the RPZ policies */
|
||||
if(z->rpz)
|
||||
rpz_clear(z->rpz);
|
||||
|
||||
auth_zone_clear_data(z);
|
||||
xfr->have_zone = 0;
|
||||
xfr->serial = 0;
|
||||
xfr->soa_zone_acquired = 0;
|
||||
xfr->num_ixfrs = 0;
|
||||
|
||||
chunk = xfr->task_transfer->chunks_first;
|
||||
chunk_pos = 0;
|
||||
@@ -5359,6 +5434,7 @@ xfr_process_chunk_list(struct auth_xfer* xfr, struct module_env* env,
|
||||
/* apply data */
|
||||
if(xfr->task_transfer->master->http) {
|
||||
if(!apply_http(xfr, z, env->scratch_buffer)) {
|
||||
auth_zone_clear_data(z);
|
||||
lock_rw_unlock(&z->lock);
|
||||
verbose(VERB_ALGO, "http from %s: could not store data",
|
||||
xfr->task_transfer->master->host);
|
||||
@@ -5367,6 +5443,7 @@ xfr_process_chunk_list(struct auth_xfer* xfr, struct module_env* env,
|
||||
} else if(xfr->task_transfer->on_ixfr &&
|
||||
!xfr->task_transfer->on_ixfr_is_axfr) {
|
||||
if(!apply_ixfr(xfr, z, env->scratch_buffer)) {
|
||||
auth_zone_clear_data(z);
|
||||
lock_rw_unlock(&z->lock);
|
||||
verbose(VERB_ALGO, "xfr from %s: could not store IXFR"
|
||||
" data", xfr->task_transfer->master->host);
|
||||
@@ -5375,6 +5452,7 @@ xfr_process_chunk_list(struct auth_xfer* xfr, struct module_env* env,
|
||||
}
|
||||
} else {
|
||||
if(!apply_axfr(xfr, z, env->scratch_buffer)) {
|
||||
auth_zone_clear_data(z);
|
||||
lock_rw_unlock(&z->lock);
|
||||
verbose(VERB_ALGO, "xfr from %s: could not store AXFR"
|
||||
" data", xfr->task_transfer->master->host);
|
||||
@@ -5391,6 +5469,7 @@ xfr_process_chunk_list(struct auth_xfer* xfr, struct module_env* env,
|
||||
}
|
||||
z->soa_zone_acquired = *env->now;
|
||||
xfr->soa_zone_acquired = *env->now;
|
||||
xfr->is_rpz = (z->rpz!=NULL);
|
||||
|
||||
/* release xfr lock while verifying zonemd because it may have
|
||||
* to spawn lookups in the state machines */
|
||||
@@ -5440,16 +5519,50 @@ xfr_process_chunk_list(struct auth_xfer* xfr, struct module_env* env,
|
||||
return 1;
|
||||
}
|
||||
|
||||
/** Stop lookup using callback */
|
||||
static void
|
||||
xfr_stop_lookup(struct auth_master** lookup_target, void* lookup_unique_info,
|
||||
int lookup_aaaa, uint16_t dclass, struct mesh_area* mesh,
|
||||
mesh_cb_func_type cb, void* cb_arg)
|
||||
{
|
||||
struct query_info qinfo;
|
||||
uint8_t dname[LDNS_MAX_DOMAINLEN+1];
|
||||
if(!*lookup_target) return;
|
||||
qinfo.qname_len = sizeof(dname);
|
||||
if(sldns_str2wire_dname_buf((*lookup_target)->host, dname,
|
||||
&qinfo.qname_len) != 0) {
|
||||
*lookup_target = NULL;
|
||||
return;
|
||||
}
|
||||
qinfo.qname = dname;
|
||||
qinfo.qclass = dclass;
|
||||
qinfo.qtype = lookup_aaaa ? LDNS_RR_TYPE_AAAA : LDNS_RR_TYPE_A;
|
||||
qinfo.local_alias = NULL;
|
||||
log_query_info(VERB_ALGO, "removing xfr callback", &qinfo);
|
||||
|
||||
mesh_remove_callback(mesh, &qinfo, BIT_RD, cb, cb_arg,
|
||||
lookup_unique_info);
|
||||
*lookup_target = NULL;
|
||||
}
|
||||
|
||||
/** disown task_transfer. caller must hold xfr.lock */
|
||||
static void
|
||||
xfr_transfer_disown(struct auth_xfer* xfr)
|
||||
{
|
||||
/* remove data chunks */
|
||||
auth_chunks_delete(xfr->task_transfer);
|
||||
/* remove timer (from this worker's event base) */
|
||||
comm_timer_delete(xfr->task_transfer->timer);
|
||||
xfr->task_transfer->timer = NULL;
|
||||
/* remove the commpoint */
|
||||
comm_point_delete(xfr->task_transfer->cp);
|
||||
xfr->task_transfer->cp = NULL;
|
||||
if(xfr->task_transfer->env)
|
||||
xfr_stop_lookup(&xfr->task_transfer->lookup_target,
|
||||
xfr->task_transfer->lookup_unique_info,
|
||||
xfr->task_transfer->lookup_aaaa, xfr->dclass,
|
||||
xfr->task_transfer->env->mesh,
|
||||
&auth_xfer_transfer_lookup_callback, xfr);
|
||||
/* we don't own this item anymore */
|
||||
xfr->task_transfer->worker = NULL;
|
||||
xfr->task_transfer->env = NULL;
|
||||
@@ -5516,7 +5629,8 @@ xfr_transfer_lookup_host(struct auth_xfer* xfr, struct module_env* env)
|
||||
* called straight away */
|
||||
lock_basic_unlock(&xfr->lock);
|
||||
if(!mesh_new_callback(env->mesh, &qinfo, qflags, &edns, buf, 0,
|
||||
&auth_xfer_transfer_lookup_callback, xfr, 0)) {
|
||||
&auth_xfer_transfer_lookup_callback, xfr, 0,
|
||||
&xfr->task_transfer->lookup_unique_info)) {
|
||||
lock_basic_lock(&xfr->lock);
|
||||
log_err("out of memory lookup up master %s", master->host);
|
||||
return 0;
|
||||
@@ -5574,6 +5688,7 @@ xfr_transfer_init_fetch(struct auth_xfer* xfr, struct module_env* env)
|
||||
t.tv_sec = timeout/1000;
|
||||
t.tv_usec = (timeout%1000)*1000;
|
||||
#endif
|
||||
xfr->task_transfer->start_time = *env->now_tv;
|
||||
|
||||
if(master->http) {
|
||||
/* perform http fetch */
|
||||
@@ -5743,6 +5858,31 @@ xfr_master_add_addrs(struct auth_master* m, struct ub_packed_rrset_key* rrset,
|
||||
}
|
||||
}
|
||||
|
||||
/** check if the lookup target name equals the found answer name. */
|
||||
static int
|
||||
xfer_target_equals_answer_name(struct auth_master* lookup_target,
|
||||
struct ub_packed_rrset_key* answer, struct query_info* rq,
|
||||
struct reply_info* rep)
|
||||
{
|
||||
uint8_t qname[LDNS_MAX_DOMAINLEN+1];
|
||||
size_t qname_len;
|
||||
if(!lookup_target) return 0;
|
||||
if(!answer) return 0;
|
||||
qname_len = sizeof(qname);
|
||||
if(sldns_str2wire_dname_buf(lookup_target->host, qname, &qname_len)
|
||||
!= 0) {
|
||||
verbose(VERB_ALGO, "xfer_target_equals_answer_name: could not parse auth host name");
|
||||
return 0;
|
||||
}
|
||||
if(query_dname_compare(answer->rk.dname, qname) == 0)
|
||||
return 1;
|
||||
/* It could be a CNAME. */
|
||||
if(reply_find_rrset_section_an(rep, qname, qname_len,
|
||||
LDNS_RR_TYPE_CNAME, rq->qclass))
|
||||
return 1;
|
||||
return 0;
|
||||
}
|
||||
|
||||
/** callback for task_transfer lookup of host name, of A or AAAA */
|
||||
void auth_xfer_transfer_lookup_callback(void* arg, int rcode, sldns_buffer* buf,
|
||||
enum sec_status sec, char* why_bogus, int ATTR_UNUSED(was_ratelimited))
|
||||
@@ -5781,21 +5921,29 @@ void auth_xfer_transfer_lookup_callback(void* arg, int rcode, sldns_buffer* buf,
|
||||
/* parsed successfully */
|
||||
struct ub_packed_rrset_key* answer =
|
||||
reply_find_answer_rrset(&rq, rep);
|
||||
if(answer) {
|
||||
if(answer && xfer_target_equals_answer_name(
|
||||
xfr->task_transfer->lookup_target, answer,
|
||||
&rq, rep)) {
|
||||
xfr_master_add_addrs(xfr->task_transfer->
|
||||
lookup_target, answer, wanted_qtype);
|
||||
} else if(answer) {
|
||||
if(verbosity >= VERB_ALGO) {
|
||||
char zname[LDNS_MAX_DOMAINLEN];
|
||||
dname_str(xfr->name, zname);
|
||||
verbose(VERB_ALGO, "auth zone %s host %s type %s transfer lookup has mismatch in answer name", zname, ((xfr->task_transfer->lookup_target && xfr->task_transfer->lookup_target->host) ? xfr->task_transfer->lookup_target->host : "null"), (xfr->task_transfer->lookup_aaaa?"AAAA":"A"));
|
||||
}
|
||||
} else {
|
||||
if(verbosity >= VERB_ALGO) {
|
||||
char zname[LDNS_MAX_DOMAINLEN];
|
||||
dname_str(xfr->name, zname);
|
||||
verbose(VERB_ALGO, "auth zone %s host %s type %s transfer lookup has nodata", zname, xfr->task_transfer->lookup_target->host, (xfr->task_transfer->lookup_aaaa?"AAAA":"A"));
|
||||
verbose(VERB_ALGO, "auth zone %s host %s type %s transfer lookup has nodata", zname, ((xfr->task_transfer->lookup_target && xfr->task_transfer->lookup_target->host) ? xfr->task_transfer->lookup_target->host : "null"), (xfr->task_transfer->lookup_aaaa?"AAAA":"A"));
|
||||
}
|
||||
}
|
||||
} else {
|
||||
if(verbosity >= VERB_ALGO) {
|
||||
char zname[LDNS_MAX_DOMAINLEN];
|
||||
dname_str(xfr->name, zname);
|
||||
verbose(VERB_ALGO, "auth zone %s host %s type %s transfer lookup has no answer", zname, xfr->task_transfer->lookup_target->host, (xfr->task_transfer->lookup_aaaa?"AAAA":"A"));
|
||||
verbose(VERB_ALGO, "auth zone %s host %s type %s transfer lookup has no answer", zname, ((xfr->task_transfer->lookup_target && xfr->task_transfer->lookup_target->host) ? xfr->task_transfer->lookup_target->host : "null"), (xfr->task_transfer->lookup_aaaa?"AAAA":"A"));
|
||||
}
|
||||
}
|
||||
regional_free_all(temp);
|
||||
@@ -5803,10 +5951,11 @@ void auth_xfer_transfer_lookup_callback(void* arg, int rcode, sldns_buffer* buf,
|
||||
if(verbosity >= VERB_ALGO) {
|
||||
char zname[LDNS_MAX_DOMAINLEN];
|
||||
dname_str(xfr->name, zname);
|
||||
verbose(VERB_ALGO, "auth zone %s host %s type %s transfer lookup failed", zname, xfr->task_transfer->lookup_target->host, (xfr->task_transfer->lookup_aaaa?"AAAA":"A"));
|
||||
verbose(VERB_ALGO, "auth zone %s host %s type %s transfer lookup failed", zname, ((xfr->task_transfer->lookup_target && xfr->task_transfer->lookup_target->host) ? xfr->task_transfer->lookup_target->host : "null"), (xfr->task_transfer->lookup_aaaa?"AAAA":"A"));
|
||||
}
|
||||
}
|
||||
if(xfr->task_transfer->lookup_target->list &&
|
||||
if(xfr->task_transfer->lookup_target &&
|
||||
xfr->task_transfer->lookup_target->list &&
|
||||
xfr->task_transfer->lookup_target == xfr_transfer_current_master(xfr))
|
||||
xfr->task_transfer->scan_addr = xfr->task_transfer->lookup_target->list;
|
||||
|
||||
@@ -6136,6 +6285,7 @@ xfer_link_data(sldns_buffer* pkt, struct auth_xfer* xfr)
|
||||
if(xfr->task_transfer->chunks_last)
|
||||
xfr->task_transfer->chunks_last->next = e;
|
||||
xfr->task_transfer->chunks_last = e;
|
||||
xfr->task_transfer->chunks_total += e->len;
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -6231,6 +6381,15 @@ auth_xfer_transfer_timer_callback(void* arg)
|
||||
xfr_transfer_nexttarget_or_end(xfr, env);
|
||||
}
|
||||
|
||||
/** return the time taken by the transfer */
|
||||
static int
|
||||
auth_xfer_transfer_time_taken(struct auth_xfer* xfr, struct module_env* env)
|
||||
{
|
||||
struct timeval delta;
|
||||
timeval_subtract(&delta, env->now_tv, &xfr->task_transfer->start_time);
|
||||
return ((int)delta.tv_sec)*1000 + ((int)delta.tv_usec)/1000;
|
||||
}
|
||||
|
||||
/** callback for task_transfer tcp connections */
|
||||
int
|
||||
auth_xfer_transfer_tcp_callback(struct comm_point* c, void* arg, int err,
|
||||
@@ -6297,6 +6456,15 @@ auth_xfer_transfer_tcp_callback(struct comm_point* c, void* arg, int err,
|
||||
xfr->task_transfer->master->host);
|
||||
goto failed;
|
||||
}
|
||||
if(xfr->max_transfer_size > 0 &&
|
||||
xfr->task_transfer->chunks_total > xfr->max_transfer_size) {
|
||||
char zname[LDNS_MAX_DOMAINLEN];
|
||||
dname_str(xfr->name, zname);
|
||||
log_err("auth zone %s transfer from %s exceeded %u bytes, aborting",
|
||||
zname, xfr->task_transfer->master->host,
|
||||
(unsigned)xfr->max_transfer_size);
|
||||
goto failed;
|
||||
}
|
||||
/* if the transfer is done now, disconnect and process the list */
|
||||
if(transferdone) {
|
||||
comm_point_delete(xfr->task_transfer->cp);
|
||||
@@ -6305,6 +6473,16 @@ auth_xfer_transfer_tcp_callback(struct comm_point* c, void* arg, int err,
|
||||
return 0;
|
||||
}
|
||||
|
||||
if(xfr->max_transfer_time > 0 &&
|
||||
auth_xfer_transfer_time_taken(xfr, env) > xfr->max_transfer_time) {
|
||||
char zname[LDNS_MAX_DOMAINLEN];
|
||||
dname_str(xfr->name, zname);
|
||||
log_err("auth zone %s transfer from %s exceeded %u msec total running time, aborting",
|
||||
zname, xfr->task_transfer->master->host,
|
||||
(unsigned)xfr->max_transfer_time);
|
||||
goto failed;
|
||||
}
|
||||
|
||||
/* if we want to read more messages, setup the commpoint to read
|
||||
* a DNS packet, and the timeout */
|
||||
lock_basic_unlock(&xfr->lock);
|
||||
@@ -6360,6 +6538,16 @@ auth_xfer_transfer_http_callback(struct comm_point* c, void* arg, int err,
|
||||
xfr->task_transfer->master->host);
|
||||
goto failed;
|
||||
}
|
||||
if(xfr->max_transfer_size > 0 &&
|
||||
xfr->task_transfer->chunks_total > xfr->max_transfer_size) {
|
||||
char zname[LDNS_MAX_DOMAINLEN];
|
||||
dname_str(xfr->name, zname);
|
||||
log_err("auth zone %s http %s/%s exceeded %u bytes, aborting",
|
||||
zname, xfr->task_transfer->master->host,
|
||||
xfr->task_transfer->master->file,
|
||||
(unsigned)xfr->max_transfer_size);
|
||||
goto failed;
|
||||
}
|
||||
}
|
||||
/* if the transfer is done now, disconnect and process the list */
|
||||
if(err == NETEVENT_DONE) {
|
||||
@@ -6371,6 +6559,17 @@ auth_xfer_transfer_http_callback(struct comm_point* c, void* arg, int err,
|
||||
return 0;
|
||||
}
|
||||
|
||||
if(xfr->max_transfer_time > 0 &&
|
||||
auth_xfer_transfer_time_taken(xfr, env) > xfr->max_transfer_time) {
|
||||
char zname[LDNS_MAX_DOMAINLEN];
|
||||
dname_str(xfr->name, zname);
|
||||
log_err("auth zone %s transfer http %s/%s exceeded %u msec total running time, aborting",
|
||||
zname, xfr->task_transfer->master->host,
|
||||
xfr->task_transfer->master->file,
|
||||
(unsigned)xfr->max_transfer_time);
|
||||
goto failed;
|
||||
}
|
||||
|
||||
/* if we want to read more messages, setup the commpoint to read
|
||||
* a DNS packet, and the timeout */
|
||||
lock_basic_unlock(&xfr->lock);
|
||||
@@ -6413,6 +6612,12 @@ xfr_probe_disown(struct auth_xfer* xfr)
|
||||
/* remove the commpoint */
|
||||
comm_point_delete(xfr->task_probe->cp);
|
||||
xfr->task_probe->cp = NULL;
|
||||
if(xfr->task_probe->env)
|
||||
xfr_stop_lookup(&xfr->task_probe->lookup_target,
|
||||
xfr->task_probe->lookup_unique_info,
|
||||
xfr->task_probe->lookup_aaaa, xfr->dclass,
|
||||
xfr->task_probe->env->mesh,
|
||||
&auth_xfer_probe_lookup_callback, xfr);
|
||||
/* we don't own this item anymore */
|
||||
xfr->task_probe->worker = NULL;
|
||||
xfr->task_probe->env = NULL;
|
||||
@@ -6719,7 +6924,8 @@ xfr_probe_lookup_host(struct auth_xfer* xfr, struct module_env* env)
|
||||
* called straight away */
|
||||
lock_basic_unlock(&xfr->lock);
|
||||
if(!mesh_new_callback(env->mesh, &qinfo, qflags, &edns, buf, 0,
|
||||
&auth_xfer_probe_lookup_callback, xfr, 0)) {
|
||||
&auth_xfer_probe_lookup_callback, xfr, 0,
|
||||
&xfr->task_probe->lookup_unique_info)) {
|
||||
lock_basic_lock(&xfr->lock);
|
||||
log_err("out of memory lookup up master %s", master->host);
|
||||
return 0;
|
||||
@@ -6856,7 +7062,7 @@ void auth_xfer_probe_lookup_callback(void* arg, int rcode, sldns_buffer* buf,
|
||||
char zname[LDNS_MAX_DOMAINLEN];
|
||||
dname_str(xfr->name, zname);
|
||||
verbose(VERB_OPS, "auth zone %s: primary %s address probe lookup is DNSSEC bogus: %s",
|
||||
zname, xfr->task_transfer->lookup_target->host,
|
||||
zname, xfr->task_probe->lookup_target->host,
|
||||
(why_bogus?why_bogus:""));
|
||||
}
|
||||
/* fall through to next-lookup / next-master */
|
||||
@@ -6874,21 +7080,29 @@ void auth_xfer_probe_lookup_callback(void* arg, int rcode, sldns_buffer* buf,
|
||||
/* parsed successfully */
|
||||
struct ub_packed_rrset_key* answer =
|
||||
reply_find_answer_rrset(&rq, rep);
|
||||
if(answer) {
|
||||
if(answer && xfer_target_equals_answer_name(
|
||||
xfr->task_probe->lookup_target, answer,
|
||||
&rq, rep)) {
|
||||
xfr_master_add_addrs(xfr->task_probe->
|
||||
lookup_target, answer, wanted_qtype);
|
||||
} else if(answer) {
|
||||
if(verbosity >= VERB_ALGO) {
|
||||
char zname[LDNS_MAX_DOMAINLEN];
|
||||
dname_str(xfr->name, zname);
|
||||
verbose(VERB_ALGO, "auth zone %s host %s type %s probe lookup has mismatch in answer name", zname, ((xfr->task_probe->lookup_target && xfr->task_probe->lookup_target->host) ? xfr->task_probe->lookup_target->host : "null"), (xfr->task_probe->lookup_aaaa?"AAAA":"A"));
|
||||
}
|
||||
} else {
|
||||
if(verbosity >= VERB_ALGO) {
|
||||
char zname[LDNS_MAX_DOMAINLEN];
|
||||
dname_str(xfr->name, zname);
|
||||
verbose(VERB_ALGO, "auth zone %s host %s type %s probe lookup has nodata", zname, xfr->task_probe->lookup_target->host, (xfr->task_probe->lookup_aaaa?"AAAA":"A"));
|
||||
verbose(VERB_ALGO, "auth zone %s host %s type %s probe lookup has nodata", zname, ((xfr->task_probe->lookup_target && xfr->task_probe->lookup_target->host) ? xfr->task_probe->lookup_target->host : "null"), (xfr->task_probe->lookup_aaaa?"AAAA":"A"));
|
||||
}
|
||||
}
|
||||
} else {
|
||||
if(verbosity >= VERB_ALGO) {
|
||||
char zname[LDNS_MAX_DOMAINLEN];
|
||||
dname_str(xfr->name, zname);
|
||||
verbose(VERB_ALGO, "auth zone %s host %s type %s probe lookup has no address", zname, xfr->task_probe->lookup_target->host, (xfr->task_probe->lookup_aaaa?"AAAA":"A"));
|
||||
verbose(VERB_ALGO, "auth zone %s host %s type %s probe lookup has no address", zname, ((xfr->task_probe->lookup_target && xfr->task_probe->lookup_target->host) ? xfr->task_probe->lookup_target->host : "null"), (xfr->task_probe->lookup_aaaa?"AAAA":"A"));
|
||||
}
|
||||
}
|
||||
regional_free_all(temp);
|
||||
@@ -6896,10 +7110,11 @@ void auth_xfer_probe_lookup_callback(void* arg, int rcode, sldns_buffer* buf,
|
||||
if(verbosity >= VERB_ALGO) {
|
||||
char zname[LDNS_MAX_DOMAINLEN];
|
||||
dname_str(xfr->name, zname);
|
||||
verbose(VERB_ALGO, "auth zone %s host %s type %s probe lookup failed", zname, xfr->task_probe->lookup_target->host, (xfr->task_probe->lookup_aaaa?"AAAA":"A"));
|
||||
verbose(VERB_ALGO, "auth zone %s host %s type %s probe lookup failed", zname, ((xfr->task_probe->lookup_target && xfr->task_probe->lookup_target->host) ? xfr->task_probe->lookup_target->host : "null"), (xfr->task_probe->lookup_aaaa?"AAAA":"A"));
|
||||
}
|
||||
}
|
||||
if(xfr->task_probe->lookup_target->list &&
|
||||
if(xfr->task_probe->lookup_target &&
|
||||
xfr->task_probe->lookup_target->list &&
|
||||
xfr->task_probe->lookup_target == xfr_probe_current_master(xfr))
|
||||
xfr->task_probe->scan_addr = xfr->task_probe->lookup_target->list;
|
||||
|
||||
@@ -6966,8 +7181,8 @@ xfr_start_probe(struct auth_xfer* xfr, struct module_env* env,
|
||||
if(!have_probe_targets(xfr->task_probe->masters) &&
|
||||
xfr->task_probe->masters != NULL)
|
||||
xfr->task_probe->only_lookup = 1;
|
||||
if(!(xfr->task_probe->only_lookup &&
|
||||
xfr->task_probe->masters != NULL)) {
|
||||
if(!xfr->task_probe->only_lookup &&
|
||||
!have_probe_targets(xfr->task_probe->masters)) {
|
||||
/* useless to pick up task_probe, no masters to
|
||||
* probe. Instead attempt to pick up task transfer */
|
||||
if(xfr->task_transfer->worker == NULL) {
|
||||
@@ -7170,6 +7385,8 @@ auth_xfer_new(struct auth_zone* z)
|
||||
xfr->namelen = z->namelen;
|
||||
xfr->namelabs = z->namelabs;
|
||||
xfr->dclass = z->dclass;
|
||||
xfr->max_transfer_size = z->max_transfer_size;
|
||||
xfr->max_transfer_time = z->max_transfer_time;
|
||||
|
||||
xfr->task_nextprobe = (struct auth_nextprobe*)calloc(1,
|
||||
sizeof(struct auth_nextprobe));
|
||||
@@ -7379,35 +7596,48 @@ xfer_set_masters(struct auth_master** list, struct config_auth* c,
|
||||
{
|
||||
struct auth_master* m;
|
||||
struct config_strlist* p;
|
||||
struct auth_master** tail;
|
||||
/* list points to the first, or next pointer for the new element */
|
||||
while(*list) {
|
||||
list = &( (*list)->next );
|
||||
}
|
||||
if(with_http)
|
||||
for(p = c->urls; p; p = p->next) {
|
||||
tail = list;
|
||||
m = auth_master_new(&list);
|
||||
if(!m) return 0;
|
||||
m->http = 1;
|
||||
if(!parse_url(p->str, &m->host, &m->file, &m->port, &m->ssl))
|
||||
if(!parse_url(p->str, &m->host, &m->file, &m->port, &m->ssl)) {
|
||||
free(m->host);
|
||||
free(m->file);
|
||||
free(m);
|
||||
*tail = NULL;
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
for(p = c->masters; p; p = p->next) {
|
||||
tail = list;
|
||||
m = auth_master_new(&list);
|
||||
if(!m) return 0;
|
||||
m->ixfr = 1; /* this flag is not configurable */
|
||||
m->host = strdup(p->str);
|
||||
if(!m->host) {
|
||||
log_err("malloc failure");
|
||||
free(m);
|
||||
*tail = NULL;
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
for(p = c->allow_notify; p; p = p->next) {
|
||||
tail = list;
|
||||
m = auth_master_new(&list);
|
||||
if(!m) return 0;
|
||||
m->allow_notify = 1;
|
||||
m->host = strdup(p->str);
|
||||
if(!m->host) {
|
||||
log_err("malloc failure");
|
||||
free(m);
|
||||
*tail = NULL;
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
@@ -8561,7 +8791,8 @@ zonemd_lookup_dnskey(struct auth_zone* z, struct module_env* env)
|
||||
/* the callback can be called straight away */
|
||||
lock_rw_unlock(&z->lock);
|
||||
if(!mesh_new_callback(env->mesh, &qinfo, qflags, &edns, buf, 0,
|
||||
&auth_zonemd_dnskey_lookup_callback, z, 0)) {
|
||||
&auth_zonemd_dnskey_lookup_callback, z, 0,
|
||||
&z->zonemd_callback_unique_info)) {
|
||||
lock_rw_wrlock(&z->lock);
|
||||
log_err("out of memory lookup of %s for zonemd",
|
||||
(fetch_ds?"DS":"DNSKEY"));
|
||||
|
||||
@@ -144,6 +144,8 @@ struct auth_zone {
|
||||
struct module_env* zonemd_callback_env;
|
||||
/** for the zonemd callback, the type of data looked up */
|
||||
uint16_t zonemd_callback_qtype;
|
||||
/** for the zonemd callback, the unique info */
|
||||
void* zonemd_callback_unique_info;
|
||||
/** zone has been deleted */
|
||||
int zone_deleted;
|
||||
/** deletelist pointer, unused normally except during delete */
|
||||
@@ -153,6 +155,10 @@ struct auth_zone {
|
||||
struct auth_zone* rpz_az_next;
|
||||
/** previous auth zone containing RPZ data, or NULL */
|
||||
struct auth_zone* rpz_az_prev;
|
||||
/** The maximum auth zone transfer size, in bytes. */
|
||||
size_t max_transfer_size;
|
||||
/** The maximum auth zone transfer time taken, in msec. */
|
||||
int max_transfer_time;
|
||||
};
|
||||
|
||||
/**
|
||||
@@ -283,6 +289,15 @@ struct auth_xfer {
|
||||
* this is renewed every SOA probe and transfer. On zone load
|
||||
* from zonefile it is also set (with probe set soon to check) */
|
||||
time_t lease_time;
|
||||
|
||||
/** The maximum auth zone transfer size, in bytes. */
|
||||
size_t max_transfer_size;
|
||||
/** The maximum auth zone transfer time taken, in msec. */
|
||||
int max_transfer_time;
|
||||
/** the zone is an rpz zone */
|
||||
int is_rpz;
|
||||
/** the number of IXFRs since the last full transfer. */
|
||||
int num_ixfrs;
|
||||
};
|
||||
|
||||
/**
|
||||
@@ -331,6 +346,8 @@ struct auth_probe {
|
||||
|
||||
/** for the hostname lookups, which master is current */
|
||||
struct auth_master* lookup_target;
|
||||
/** for the lookup, the callback unique info */
|
||||
void* lookup_unique_info;
|
||||
/** are we looking up A or AAAA, first A, then AAAA (if ip6 enabled) */
|
||||
int lookup_aaaa;
|
||||
/** we only want to do lookups for making config work (for notify),
|
||||
@@ -379,12 +396,18 @@ struct auth_transfer {
|
||||
struct auth_chunk* chunks_first;
|
||||
/** last element in chunks list (to append new data at the end) */
|
||||
struct auth_chunk* chunks_last;
|
||||
/** running total of bytes held in chunks_first..chunks_last */
|
||||
size_t chunks_total;
|
||||
/** start time of the transfer */
|
||||
struct timeval start_time;
|
||||
|
||||
/** list of upstream masters for this zone, from config */
|
||||
struct auth_master* masters;
|
||||
|
||||
/** for the hostname lookups, which master is current */
|
||||
struct auth_master* lookup_target;
|
||||
/** for the lookup, the callback unique info */
|
||||
void* lookup_unique_info;
|
||||
/** are we looking up A or AAAA, first A, then AAAA (if ip6 enabled) */
|
||||
int lookup_aaaa;
|
||||
|
||||
@@ -828,4 +851,10 @@ void auth_xfer_delete(struct auth_xfer* xfr);
|
||||
*/
|
||||
void xfr_disown_tasks(struct auth_xfer* xfr, struct worker* worker);
|
||||
|
||||
/** count number of open and closed parenthesis in a chunkline */
|
||||
int chunkline_count_parens(struct sldns_buffer* buf, size_t start);
|
||||
|
||||
/** Clear data in auth zone */
|
||||
void auth_zone_clear_data(struct auth_zone* z);
|
||||
|
||||
#endif /* SERVICES_AUTHZONE_H */
|
||||
|
||||
Vendored
+13
-1
@@ -43,6 +43,7 @@
|
||||
#include "iterator/iter_utils.h"
|
||||
#include "validator/val_nsec.h"
|
||||
#include "validator/val_utils.h"
|
||||
#include "iterator/iter_utils.h"
|
||||
#include "services/cache/dns.h"
|
||||
#include "services/cache/rrset.h"
|
||||
#include "util/data/msgparse.h"
|
||||
@@ -586,8 +587,12 @@ dns_cache_find_delegation(struct module_env* env, uint8_t* qname,
|
||||
return NULL;
|
||||
}
|
||||
}
|
||||
if(!delegpt_rrset_add_ns(dp, region, nskey, 0))
|
||||
if(!delegpt_rrset_add_ns(dp, region, nskey, 0,
|
||||
deleg_port_number(env))) {
|
||||
lock_rw_unlock(&nskey->entry.lock);
|
||||
log_err("find_delegation: addns out of memory");
|
||||
return NULL;
|
||||
}
|
||||
lock_rw_unlock(&nskey->entry.lock); /* first unlock before next lookup*/
|
||||
/* find and add DS/NSEC (if any) */
|
||||
if(msg)
|
||||
@@ -782,11 +787,16 @@ synth_dname_msg(struct ub_packed_rrset_key* rrset, struct regional* region,
|
||||
uint8_t* newname, *dtarg = NULL;
|
||||
size_t newlen, dtarglen;
|
||||
time_t rr_ttl;
|
||||
int graceperiod = 0;
|
||||
if(TTL_IS_EXPIRED(d->ttl, now)) {
|
||||
/* Allow TTL=0 DNAME from upstream within grace period */
|
||||
if(!(rrset->rk.flags & PACKED_RRSET_UPSTREAM_0TTL))
|
||||
return NULL;
|
||||
rr_ttl = 0;
|
||||
/* Since PACKED_RRSET_UPSTREAM_0TTL set the flag that
|
||||
* the grace period has been applied, this stops the rrset
|
||||
* from getting stored back into the cache with a bigger TTL.*/
|
||||
graceperiod = 1;
|
||||
} else {
|
||||
rr_ttl = d->ttl - now;
|
||||
}
|
||||
@@ -814,6 +824,8 @@ synth_dname_msg(struct ub_packed_rrset_key* rrset, struct regional* region,
|
||||
msg->rep->rrsets[0] = packed_rrset_copy_region(rrset, region, now);
|
||||
if(!msg->rep->rrsets[0]) /* copy DNAME */
|
||||
return NULL;
|
||||
if(graceperiod)
|
||||
msg->rep->rrsets[0]->rk.flags |= PACKED_RRSET_0TTL_GRACE;
|
||||
/* synth CNAME rrset */
|
||||
get_cname_target(rrset, &dtarg, &dtarglen);
|
||||
if(!dtarg)
|
||||
|
||||
Vendored
+16
-5
@@ -215,6 +215,13 @@ rrset_cache_update(struct rrset_cache* r, struct rrset_ref* ref,
|
||||
int equal = 0;
|
||||
log_assert(ref->id != 0 && k->id != 0);
|
||||
log_assert(k->rk.dname != NULL);
|
||||
if((k->rk.flags&PACKED_RRSET_0TTL_GRACE) !=0) {
|
||||
log_nametypeclass(VERB_ALGO, "rrset store of PACKED_RRSET_0TTL_GRACE rrset skipped", k->rk.dname, rrset_type, ntohs(k->rk.rrset_class));
|
||||
ub_packed_rrset_parsedelete(k, alloc);
|
||||
return 0; /* Do not store 0TTL items after apply of
|
||||
the grace ttl amount.
|
||||
This means the ref was not changed by the call. */
|
||||
}
|
||||
/* looks up item with a readlock - no editing! */
|
||||
if((e=slabhash_lookup(&r->table, h, k, 0)) != 0) {
|
||||
/* return id and key as they will be used in the cache
|
||||
@@ -291,6 +298,8 @@ void rrset_cache_update_wildcard(struct rrset_cache* rrset_cache,
|
||||
{
|
||||
struct rrset_ref ref;
|
||||
uint8_t wc_dname[LDNS_MAX_DOMAINLEN+3];
|
||||
uint8_t* new_dname;
|
||||
size_t new_dname_len;
|
||||
|
||||
/* See if the RRSIG signer name allows this wildcard,
|
||||
* the new rrset should fall within the zone of the RRSIG signer(s). */
|
||||
@@ -310,14 +319,16 @@ void rrset_cache_update_wildcard(struct rrset_cache* rrset_cache,
|
||||
wc_dname[1] = (uint8_t)'*';
|
||||
memmove(wc_dname+2, ce, ce_len);
|
||||
|
||||
free(rrset->rk.dname);
|
||||
rrset->rk.dname_len = ce_len + 2;
|
||||
rrset->rk.dname = (uint8_t*)memdup(wc_dname, rrset->rk.dname_len);
|
||||
if(!rrset->rk.dname) {
|
||||
alloc_special_release(alloc, rrset);
|
||||
new_dname_len = ce_len + 2;
|
||||
new_dname = (uint8_t*)memdup(wc_dname, new_dname_len);
|
||||
if(!new_dname) {
|
||||
ub_packed_rrset_parsedelete(rrset, alloc);
|
||||
log_err("memdup failure in rrset_cache_update_wildcard");
|
||||
return;
|
||||
}
|
||||
free(rrset->rk.dname);
|
||||
rrset->rk.dname = new_dname;
|
||||
rrset->rk.dname_len = new_dname_len;
|
||||
|
||||
rrset->entry.hash = rrset_key_hash(&rrset->rk);
|
||||
ref.key = rrset;
|
||||
|
||||
+30
-10
@@ -1125,7 +1125,7 @@ make_sock_port(int stype, const char* ifname, int port,
|
||||
int use_systemd, int dscp, struct unbound_socket* ub_sock,
|
||||
const char* additional)
|
||||
{
|
||||
char* s = strchr(ifname, '@');
|
||||
const char* s = strchr(ifname, '@');
|
||||
if(s) {
|
||||
/* override port with ifspec@port */
|
||||
int port;
|
||||
@@ -1341,13 +1341,33 @@ ports_create_if(const char* ifname, int do_auto, int do_udp, int do_tcp,
|
||||
if((is_doq) && !(is_https || is_ssl)) do_tcp = 0;
|
||||
|
||||
if(do_auto) {
|
||||
enum listen_type auto_port_type;
|
||||
ub_sock = calloc(1, sizeof(struct unbound_socket));
|
||||
if(!ub_sock)
|
||||
return 0;
|
||||
if(is_dnscrypt) {
|
||||
auto_port_type = listen_type_udpancil_dnscrypt;
|
||||
add = "udpancil_dnscrypt";
|
||||
} else if(is_doq) {
|
||||
auto_port_type = listen_type_doq;
|
||||
add = "doq";
|
||||
if(if_listens_on(ifname, port, 53, NULL)) {
|
||||
log_err("DNS over QUIC is strictly not "
|
||||
"allowed on port 53 as per RFC 9250. "
|
||||
"Port 53 is for DNS datagrams. Error "
|
||||
"for interface '%s'.", ifname);
|
||||
free(ub_sock->addr);
|
||||
free(ub_sock);
|
||||
return 0;
|
||||
}
|
||||
} else {
|
||||
auto_port_type = listen_type_udpancil;
|
||||
add = "udpancil";
|
||||
}
|
||||
if((s = make_sock_port(SOCK_DGRAM, ifname, port, hints, 1,
|
||||
&noip6, rcv, snd, reuseport, transparent,
|
||||
tcp_mss, nodelay, freebind, use_systemd, dscp, ub_sock,
|
||||
(is_dnscrypt?"udpancil_dnscrypt":"udpancil"))) == -1) {
|
||||
add)) == -1) {
|
||||
free(ub_sock->addr);
|
||||
free(ub_sock);
|
||||
if(noip6) {
|
||||
@@ -1366,9 +1386,7 @@ ports_create_if(const char* ifname, int do_auto, int do_udp, int do_tcp,
|
||||
if (sock_queue_timeout && !set_recvtimestamp(s)) {
|
||||
log_warn("socket timestamping is not available");
|
||||
}
|
||||
if(!port_insert(list, s, is_dnscrypt
|
||||
?listen_type_udpancil_dnscrypt:listen_type_udpancil,
|
||||
is_pp2, ub_sock)) {
|
||||
if(!port_insert(list, s, auto_port_type, is_pp2, ub_sock)) {
|
||||
sock_close(s);
|
||||
free(ub_sock->addr);
|
||||
free(ub_sock);
|
||||
@@ -2167,7 +2185,7 @@ void tcp_req_info_clear(struct tcp_req_info* req)
|
||||
while(open) {
|
||||
nopen = open->next;
|
||||
mesh_state_remove_reply(open->mesh, open->mesh_state, req->cp,
|
||||
NULL);
|
||||
NULL, NULL);
|
||||
free(open);
|
||||
open = nopen;
|
||||
}
|
||||
@@ -3617,7 +3635,7 @@ stream_tree_del(rbnode_type* node, void* arg)
|
||||
stream = (struct doq_stream*)node;
|
||||
if(stream->mesh_state) {
|
||||
mesh_state_remove_reply(stream->mesh, stream->mesh_state,
|
||||
args->conn->doq_socket->cp, stream);
|
||||
args->conn->doq_socket->cp, NULL, stream);
|
||||
stream->mesh_state = NULL;
|
||||
}
|
||||
if(stream->in)
|
||||
@@ -3639,7 +3657,8 @@ doq_conn_delete(struct doq_conn* conn, struct doq_table* table)
|
||||
lock_rw_unlock(&conn->table->conid_lock);
|
||||
/* Remove the app data from ngtcp2 before SSL_free of conn->ssl,
|
||||
* because the ngtcp2 conn is deleted. */
|
||||
SSL_set_app_data(conn->ssl, NULL);
|
||||
if(conn->ssl)
|
||||
SSL_set_app_data(conn->ssl, NULL);
|
||||
if(conn->stream_tree.count != 0) {
|
||||
struct doq_stream_tree_del_args args;
|
||||
memset(&args, 0, sizeof(args));
|
||||
@@ -3956,7 +3975,7 @@ doq_stream_close(struct doq_conn* conn, struct doq_stream* stream,
|
||||
stream->is_closed = 1;
|
||||
if(stream->mesh_state) {
|
||||
mesh_state_remove_reply(stream->mesh, stream->mesh_state,
|
||||
conn->doq_socket->cp, stream);
|
||||
conn->doq_socket->cp, NULL, stream);
|
||||
stream->mesh_state = NULL;
|
||||
}
|
||||
doq_stream_off_write_list(conn, stream);
|
||||
@@ -4851,7 +4870,7 @@ doq_ssl_server_setup(SSL_CTX* ctx, struct doq_conn* conn)
|
||||
SSL_set_app_data(ssl, conn);
|
||||
#endif
|
||||
SSL_set_accept_state(ssl);
|
||||
#ifdef USE_NGTCP2_CRYPTO_OSSL
|
||||
#ifdef HAVE_SSL_SET_QUIC_TLS_EARLY_DATA_ENABLED
|
||||
SSL_set_quic_tls_early_data_enabled(ssl, 1);
|
||||
#else
|
||||
SSL_set_quic_early_data_enabled(ssl, 1);
|
||||
@@ -4960,6 +4979,7 @@ doq_conn_setup(struct doq_conn* conn, uint8_t* scid, size_t scidlen,
|
||||
rv = ngtcp2_conn_server_new(&conn->conn, &scid_cid, &sv_scid, &path,
|
||||
conn->version, &callbacks, &settings, ¶ms, NULL, conn);
|
||||
if(rv != 0) {
|
||||
conn->conn = NULL;
|
||||
lock_rw_unlock(&conn->table->conid_lock);
|
||||
log_err("ngtcp2_conn_server_new failed: %s",
|
||||
ngtcp2_strerror(rv));
|
||||
|
||||
+56
-11
@@ -386,8 +386,6 @@ new_local_rrset(struct regional* region, struct local_data* node,
|
||||
log_err("out of memory");
|
||||
return NULL;
|
||||
}
|
||||
rrset->next = node->rrsets;
|
||||
node->rrsets = rrset;
|
||||
rrset->rrset = (struct ub_packed_rrset_key*)
|
||||
regional_alloc_zero(region, sizeof(*rrset->rrset));
|
||||
if(!rrset->rrset) {
|
||||
@@ -408,6 +406,8 @@ new_local_rrset(struct regional* region, struct local_data* node,
|
||||
rrset->rrset->rk.dname_len = node->namelen;
|
||||
rrset->rrset->rk.type = htons(rrtype);
|
||||
rrset->rrset->rk.rrset_class = htons(rrclass);
|
||||
rrset->next = node->rrsets;
|
||||
node->rrsets = rrset;
|
||||
return rrset;
|
||||
}
|
||||
|
||||
@@ -431,6 +431,10 @@ rrset_insert_rr(struct regional* region, struct packed_rrset_data* pd,
|
||||
pd->rr_ttl = regional_alloc(region, sizeof(*pd->rr_ttl)*pd->count);
|
||||
pd->rr_data = regional_alloc(region, sizeof(*pd->rr_data)*pd->count);
|
||||
if(!pd->rr_len || !pd->rr_ttl || !pd->rr_data) {
|
||||
pd->count--;
|
||||
pd->rr_len = oldlen;
|
||||
pd->rr_ttl = oldttl;
|
||||
pd->rr_data = olddata;
|
||||
log_err("out of memory");
|
||||
return 0;
|
||||
}
|
||||
@@ -446,6 +450,10 @@ rrset_insert_rr(struct regional* region, struct packed_rrset_data* pd,
|
||||
pd->rr_ttl[0] = ttl;
|
||||
pd->rr_data[0] = regional_alloc_init(region, rdata, rdata_len);
|
||||
if(!pd->rr_data[0]) {
|
||||
pd->count--;
|
||||
pd->rr_len = oldlen;
|
||||
pd->rr_ttl = oldttl;
|
||||
pd->rr_data = olddata;
|
||||
log_err("out of memory");
|
||||
return 0;
|
||||
}
|
||||
@@ -671,7 +679,9 @@ lz_enter_rr_str(struct local_zones* zones, const char* rr)
|
||||
z = local_zones_lookup(zones, rr_name, len, labs, rr_class, rr_type, 1);
|
||||
if(!z) {
|
||||
lock_rw_unlock(&zones->lock);
|
||||
fatal_exit("internal error: no zone for rr %s", rr);
|
||||
log_err("internal error: no zone for rr %s", rr);
|
||||
free(rr_name);
|
||||
return 0;
|
||||
}
|
||||
lock_rw_wrlock(&z->lock);
|
||||
lock_rw_unlock(&zones->lock);
|
||||
@@ -1500,8 +1510,10 @@ find_tag_datas(struct query_info* qinfo, struct config_strlist* list,
|
||||
return 0; /* out of memory */
|
||||
qinfo->local_alias->rrset =
|
||||
regional_alloc_init(temp, r, sizeof(*r));
|
||||
if(!qinfo->local_alias->rrset)
|
||||
if(!qinfo->local_alias->rrset) {
|
||||
qinfo->local_alias = NULL;
|
||||
return 0; /* out of memory */
|
||||
}
|
||||
}
|
||||
return result;
|
||||
}
|
||||
@@ -1567,13 +1579,17 @@ local_data_answer(struct local_zone* z, struct module_env* env,
|
||||
return 0; /* out of memory */
|
||||
qinfo->local_alias->rrset = regional_alloc_init(
|
||||
temp, lr->rrset, sizeof(*lr->rrset));
|
||||
if(!qinfo->local_alias->rrset)
|
||||
if(!qinfo->local_alias->rrset) {
|
||||
qinfo->local_alias = NULL;
|
||||
return 0; /* out of memory */
|
||||
}
|
||||
qinfo->local_alias->rrset->rk.dname = qinfo->qname;
|
||||
qinfo->local_alias->rrset->rk.dname_len = qinfo->qname_len;
|
||||
get_cname_target(lr->rrset, &ctarget, &ctargetlen);
|
||||
if(!ctargetlen)
|
||||
if(!ctargetlen) {
|
||||
qinfo->local_alias = NULL;
|
||||
return 0; /* invalid cname */
|
||||
}
|
||||
if(dname_is_wild(ctarget)) {
|
||||
/* synthesize cname target */
|
||||
struct packed_rrset_data* d, *lr_d;
|
||||
@@ -1602,8 +1618,10 @@ local_data_answer(struct local_zone* z, struct module_env* env,
|
||||
sizeof(struct packed_rrset_data) + sizeof(size_t) +
|
||||
sizeof(uint8_t*) + sizeof(time_t) + sizeof(uint16_t)
|
||||
+ newtargetlen);
|
||||
if(!d)
|
||||
if(!d) {
|
||||
qinfo->local_alias = NULL;
|
||||
return 0; /* out of memory */
|
||||
}
|
||||
lr_d = (struct packed_rrset_data*)lr->rrset->entry.data;
|
||||
qinfo->local_alias->rrset->entry.data = d;
|
||||
d->ttl = lr_d->rr_ttl[0]; /* RFC6672-like behavior:
|
||||
@@ -1650,7 +1668,7 @@ local_zone_does_not_cover(struct local_zone* z, struct query_info* qinfo,
|
||||
struct local_data key;
|
||||
struct local_data* ld = NULL;
|
||||
struct local_rrset* lr = NULL;
|
||||
if(z->type == local_zone_always_transparent || z->type == local_zone_block_a)
|
||||
if(z->type == local_zone_always_transparent || z->type == local_zone_block_a || z->type == local_zone_block_aaaa)
|
||||
return 1;
|
||||
if(z->type != local_zone_transparent
|
||||
&& z->type != local_zone_typetransparent
|
||||
@@ -1661,7 +1679,9 @@ local_zone_does_not_cover(struct local_zone* z, struct query_info* qinfo,
|
||||
key.namelen = qinfo->qname_len;
|
||||
key.namelabs = labs;
|
||||
ld = (struct local_data*)rbtree_search(&z->data, &key.node);
|
||||
if(z->type == local_zone_transparent || z->type == local_zone_inform)
|
||||
if(z->type == local_zone_transparent || z->type == local_zone_inform
|
||||
|| z->type == local_zone_block_a_wdata
|
||||
|| z->type == local_zone_block_aaaa_wdata)
|
||||
return (ld == NULL);
|
||||
if(ld)
|
||||
lr = local_data_find_type(ld, qinfo->qtype, 1);
|
||||
@@ -1727,7 +1747,8 @@ local_zones_zone_answer(struct local_zone* z, struct module_env* env,
|
||||
|| lz_type == local_zone_always_transparent) {
|
||||
/* no NODATA or NXDOMAINS for this zone type */
|
||||
return 0;
|
||||
} else if(lz_type == local_zone_block_a) {
|
||||
} else if(lz_type == local_zone_block_a ||
|
||||
lz_type == local_zone_block_a_wdata) {
|
||||
/* Return NODATA for all A queries */
|
||||
if(qinfo->qtype == LDNS_RR_TYPE_A) {
|
||||
local_error_encode(qinfo, env, edns, repinfo, buf, temp,
|
||||
@@ -1736,6 +1757,17 @@ local_zones_zone_answer(struct local_zone* z, struct module_env* env,
|
||||
return 1;
|
||||
}
|
||||
|
||||
return 0;
|
||||
} else if(lz_type == local_zone_block_aaaa ||
|
||||
lz_type == local_zone_block_aaaa_wdata) {
|
||||
/* Return NODATA for all AAAA queries */
|
||||
if(qinfo->qtype == LDNS_RR_TYPE_AAAA) {
|
||||
local_error_encode(qinfo, env, edns, repinfo, buf, temp,
|
||||
LDNS_RCODE_NOERROR, (LDNS_RCODE_NOERROR|BIT_AA),
|
||||
LDNS_EDE_NONE, NULL);
|
||||
return 1;
|
||||
}
|
||||
|
||||
return 0;
|
||||
} else if(lz_type == local_zone_always_null) {
|
||||
/* 0.0.0.0 or ::0 or noerror/nodata for this zone type,
|
||||
@@ -1904,7 +1936,10 @@ local_zones_answer(struct local_zones* zones, struct module_env* env,
|
||||
lzt == local_zone_typetransparent ||
|
||||
lzt == local_zone_inform ||
|
||||
lzt == local_zone_always_transparent ||
|
||||
lzt == local_zone_block_a) &&
|
||||
lzt == local_zone_block_a ||
|
||||
lzt == local_zone_block_aaaa ||
|
||||
lzt == local_zone_block_a_wdata ||
|
||||
lzt == local_zone_block_aaaa_wdata) &&
|
||||
local_zone_does_not_cover(z, qinfo, labs)) {
|
||||
lock_rw_unlock(&z->lock);
|
||||
z = NULL;
|
||||
@@ -1953,6 +1988,7 @@ local_zones_answer(struct local_zones* zones, struct module_env* env,
|
||||
if(lzt != local_zone_always_refuse
|
||||
&& lzt != local_zone_always_transparent
|
||||
&& lzt != local_zone_block_a
|
||||
&& lzt != local_zone_block_aaaa
|
||||
&& lzt != local_zone_always_nxdomain
|
||||
&& lzt != local_zone_always_nodata
|
||||
&& lzt != local_zone_always_deny
|
||||
@@ -1984,6 +2020,9 @@ const char* local_zone_type2str(enum localzone_type t)
|
||||
case local_zone_inform_redirect: return "inform_redirect";
|
||||
case local_zone_always_transparent: return "always_transparent";
|
||||
case local_zone_block_a: return "block_a";
|
||||
case local_zone_block_aaaa: return "block_aaaa";
|
||||
case local_zone_block_a_wdata: return "block_a_wdata";
|
||||
case local_zone_block_aaaa_wdata: return "block_aaaa_wdata";
|
||||
case local_zone_always_refuse: return "always_refuse";
|
||||
case local_zone_always_nxdomain: return "always_nxdomain";
|
||||
case local_zone_always_nodata: return "always_nodata";
|
||||
@@ -2020,6 +2059,12 @@ int local_zone_str2type(const char* type, enum localzone_type* t)
|
||||
*t = local_zone_always_transparent;
|
||||
else if(strcmp(type, "block_a") == 0)
|
||||
*t = local_zone_block_a;
|
||||
else if(strcmp(type, "block_aaaa") == 0)
|
||||
*t = local_zone_block_aaaa;
|
||||
else if(strcmp(type, "block_a_wdata") == 0)
|
||||
*t = local_zone_block_a_wdata;
|
||||
else if(strcmp(type, "block_aaaa_wdata") == 0)
|
||||
*t = local_zone_block_aaaa_wdata;
|
||||
else if(strcmp(type, "always_refuse") == 0)
|
||||
*t = local_zone_always_refuse;
|
||||
else if(strcmp(type, "always_nxdomain") == 0)
|
||||
|
||||
@@ -93,6 +93,12 @@ enum localzone_type {
|
||||
local_zone_always_transparent,
|
||||
/** resolve normally, even when there is local data but return NODATA for A queries */
|
||||
local_zone_block_a,
|
||||
/** resolve normally, even when there is local data, but return NODATA for AAAA queries */
|
||||
local_zone_block_aaaa,
|
||||
/** resolve normally, use local data, else return NODATA for A queries */
|
||||
local_zone_block_a_wdata,
|
||||
/** resolve normally, use local data, else return NODATA for AAAA queries */
|
||||
local_zone_block_aaaa_wdata,
|
||||
/** answer with error, even when there is local data */
|
||||
local_zone_always_refuse,
|
||||
/** answer with nxdomain, even when there is local data */
|
||||
|
||||
+137
-56
@@ -424,6 +424,44 @@ mesh_serve_expired_init(struct mesh_state* mstate, int timeout)
|
||||
return 1;
|
||||
}
|
||||
|
||||
/** remove a reply without accounting, rollback the add reply. */
|
||||
static void
|
||||
mesh_remove_reply_without_accounting(struct mesh_state* s,
|
||||
struct mesh_reply* todel)
|
||||
{
|
||||
struct mesh_reply* r, *prev = NULL;
|
||||
for(r = s->reply_list; r; r = r->next) {
|
||||
if(r == todel) {
|
||||
if(prev)
|
||||
prev->next = r->next;
|
||||
else s->reply_list = r->next;
|
||||
r->next = NULL;
|
||||
/* todel is allocated in region */
|
||||
return;
|
||||
}
|
||||
prev = r;
|
||||
}
|
||||
}
|
||||
|
||||
/** remove a callback without accounting, rollback the add reply. */
|
||||
static void
|
||||
mesh_remove_callback_without_accounting(struct mesh_state* s,
|
||||
struct mesh_cb* todel)
|
||||
{
|
||||
struct mesh_cb* r, *prev = NULL;
|
||||
for(r = s->cb_list; r; r = r->next) {
|
||||
if(r == todel) {
|
||||
if(prev)
|
||||
prev->next = r->next;
|
||||
else s->cb_list = r->next;
|
||||
r->next = NULL;
|
||||
/* todel is allocated in region */
|
||||
return;
|
||||
}
|
||||
prev = r;
|
||||
}
|
||||
}
|
||||
|
||||
void mesh_new_client(struct mesh_area* mesh, struct query_info* qinfo,
|
||||
struct respip_client_info* cinfo, uint16_t qflags,
|
||||
struct edns_data* edns, struct comm_reply* rep, uint16_t qid,
|
||||
@@ -433,7 +471,8 @@ void mesh_new_client(struct mesh_area* mesh, struct query_info* qinfo,
|
||||
int unique = unique_mesh_state(edns->opt_list_in, mesh->env);
|
||||
int was_detached = 0;
|
||||
int was_noreply = 0;
|
||||
int added = 0;
|
||||
int added = 0, added_reply_without_accounting = 0, added_tcp = 0;
|
||||
struct mesh_reply* repadded = NULL;
|
||||
int timeout = mesh->env->cfg->serve_expired?
|
||||
mesh->env->cfg->serve_expired_client_timeout:0;
|
||||
struct sldns_buffer* r_buffer = rep->c->buffer;
|
||||
@@ -544,16 +583,18 @@ void mesh_new_client(struct mesh_area* mesh, struct query_info* qinfo,
|
||||
}
|
||||
}
|
||||
/* add reply to s */
|
||||
if(!mesh_state_add_reply(s, edns, rep, qid, qflags, qinfo)) {
|
||||
if(!mesh_state_add_reply(s, edns, rep, qid, qflags, qinfo, &repadded)) {
|
||||
log_err("mesh_new_client: out of memory; SERVFAIL");
|
||||
goto servfail_mem;
|
||||
}
|
||||
added_reply_without_accounting = 1;
|
||||
if(rep->c->tcp_req_info) {
|
||||
if(!tcp_req_info_add_meshstate(rep->c->tcp_req_info, mesh, s)) {
|
||||
log_err("mesh_new_client: out of memory add tcpreqinfo");
|
||||
goto servfail_mem;
|
||||
}
|
||||
}
|
||||
added_tcp = 1;
|
||||
if(rep->c->use_h2) {
|
||||
http2_stream_add_meshstate(rep->c->h2_stream, mesh, s);
|
||||
} else if(rep->c->type == comm_doq && rep->doq_stream) {
|
||||
@@ -575,6 +616,8 @@ void mesh_new_client(struct mesh_area* mesh, struct query_info* qinfo,
|
||||
}
|
||||
}
|
||||
#endif
|
||||
/* Since the acccounting now happens,
|
||||
* added_reply_without_accounting = 0; but that is not used. */
|
||||
infra_wait_limit_inc(mesh->env->infra_cache, rep, *mesh->env->now,
|
||||
mesh->env->cfg);
|
||||
/* update statistics */
|
||||
@@ -614,6 +657,11 @@ servfail_mem:
|
||||
else if(rep->c->type == comm_doq && rep->doq_stream)
|
||||
doq_stream_remove_mesh_state(rep->doq_stream);
|
||||
comm_point_send_reply(rep);
|
||||
if(added_reply_without_accounting) {
|
||||
mesh_remove_reply_without_accounting(s, repadded);
|
||||
if(added_tcp && rep->c->tcp_req_info)
|
||||
tcp_req_info_remove_mesh_state(rep->c->tcp_req_info, s);
|
||||
}
|
||||
if(added)
|
||||
mesh_state_delete(&s->s);
|
||||
return;
|
||||
@@ -622,7 +670,8 @@ servfail_mem:
|
||||
int
|
||||
mesh_new_callback(struct mesh_area* mesh, struct query_info* qinfo,
|
||||
uint16_t qflags, struct edns_data* edns, sldns_buffer* buf,
|
||||
uint16_t qid, mesh_cb_func_type cb, void* cb_arg, int rpz_passthru)
|
||||
uint16_t qid, mesh_cb_func_type cb, void* cb_arg, int rpz_passthru,
|
||||
void** unique_info)
|
||||
{
|
||||
struct mesh_state* s = NULL;
|
||||
int unique = unique_mesh_state(edns->opt_list_in, mesh->env);
|
||||
@@ -631,6 +680,7 @@ mesh_new_callback(struct mesh_area* mesh, struct query_info* qinfo,
|
||||
int was_detached = 0;
|
||||
int was_noreply = 0;
|
||||
int added = 0;
|
||||
struct mesh_cb* add_cb = NULL;
|
||||
uint16_t mesh_flags = qflags&(BIT_RD|BIT_CD);
|
||||
if(!unique)
|
||||
s = mesh_area_find(mesh, NULL, qinfo, mesh_flags, 0, 0);
|
||||
@@ -676,13 +726,14 @@ mesh_new_callback(struct mesh_area* mesh, struct query_info* qinfo,
|
||||
}
|
||||
}
|
||||
/* add reply to s */
|
||||
if(!mesh_state_add_cb(s, edns, buf, cb, cb_arg, qid, qflags)) {
|
||||
if(!mesh_state_add_cb(s, edns, buf, cb, cb_arg, qid, qflags, &add_cb)) {
|
||||
if(added)
|
||||
mesh_state_delete(&s->s);
|
||||
return 0;
|
||||
}
|
||||
/* add serve expired timer if not already there */
|
||||
if(timeout && !mesh_serve_expired_init(s, timeout)) {
|
||||
mesh_remove_callback_without_accounting(s, add_cb);
|
||||
if(added)
|
||||
mesh_state_delete(&s->s);
|
||||
return 0;
|
||||
@@ -693,6 +744,7 @@ mesh_new_callback(struct mesh_area* mesh, struct query_info* qinfo,
|
||||
(mesh->env->cachedb_enabled &&
|
||||
mesh->env->cfg->cachedb_check_when_serve_expired)) {
|
||||
if(!mesh_serve_expired_init(s, -1)) {
|
||||
mesh_remove_callback_without_accounting(s, add_cb);
|
||||
if(added)
|
||||
mesh_state_delete(&s->s);
|
||||
return 0;
|
||||
@@ -708,6 +760,8 @@ mesh_new_callback(struct mesh_area* mesh, struct query_info* qinfo,
|
||||
mesh->num_reply_states ++;
|
||||
}
|
||||
mesh->num_reply_addrs++;
|
||||
if(unique_info)
|
||||
*unique_info = s->unique;
|
||||
if(added)
|
||||
mesh_run(mesh, s, module_event_new, NULL);
|
||||
return 1;
|
||||
@@ -911,32 +965,9 @@ void mesh_report_reply(struct mesh_area* mesh, struct outbound_entry* e,
|
||||
mesh_run(mesh, e->qstate->mesh_info, event, e);
|
||||
}
|
||||
|
||||
/** copy strlist to region */
|
||||
static struct config_strlist*
|
||||
cfg_region_strlist_copy(struct regional* region, struct config_strlist* list)
|
||||
{
|
||||
struct config_strlist* result = NULL, *last = NULL, *s = list;
|
||||
while(s) {
|
||||
struct config_strlist* n = regional_alloc_zero(region,
|
||||
sizeof(*n));
|
||||
if(!n)
|
||||
return NULL;
|
||||
n->str = regional_strdup(region, s->str);
|
||||
if(!n->str)
|
||||
return NULL;
|
||||
if(last)
|
||||
last->next = n;
|
||||
else result = n;
|
||||
last = n;
|
||||
s = s->next;
|
||||
}
|
||||
return result;
|
||||
}
|
||||
|
||||
struct respip_client_info*
|
||||
mesh_copy_client_info(struct regional* region, struct respip_client_info* cinfo)
|
||||
{
|
||||
size_t i;
|
||||
struct respip_client_info* client_info;
|
||||
client_info = regional_alloc_init(region, cinfo, sizeof(*cinfo));
|
||||
if(!client_info)
|
||||
@@ -955,20 +986,13 @@ mesh_copy_client_info(struct regional* region, struct respip_client_info* cinfo)
|
||||
if(!client_info->tag_actions)
|
||||
return NULL;
|
||||
}
|
||||
if(cinfo->tag_datas) {
|
||||
client_info->tag_datas = regional_alloc_zero(region,
|
||||
sizeof(struct config_strlist*)*cinfo->tag_datas_size);
|
||||
if(!client_info->tag_datas)
|
||||
return NULL;
|
||||
for(i=0; i<cinfo->tag_datas_size; i++) {
|
||||
if(cinfo->tag_datas[i]) {
|
||||
client_info->tag_datas[i] = cfg_region_strlist_copy(
|
||||
region, cinfo->tag_datas[i]);
|
||||
if(!client_info->tag_datas[i])
|
||||
return NULL;
|
||||
}
|
||||
}
|
||||
}
|
||||
/* tag_datas is owned by the matched acl_addr in config_file; its
|
||||
* lifetime is until config reload, which tears down all mesh states
|
||||
* first. Keep the original pointer so client_info_compare()
|
||||
* can recognise two states from the same ACL entry. */
|
||||
/* fast reload insists on dropping the queries when interface-tag-data
|
||||
* or access-control-tag-data are changed. */
|
||||
/* client_info->tag_datas already copied by regional_alloc_init above */
|
||||
if(cinfo->view) {
|
||||
/* Do not copy the view pointer but store a name instead.
|
||||
* The name is looked up later when done, this means that
|
||||
@@ -1090,14 +1114,6 @@ mesh_state_cleanup(struct mesh_state* mstate)
|
||||
if(!mstate->replies_sent) {
|
||||
struct mesh_reply* rep = mstate->reply_list;
|
||||
struct mesh_cb* cb;
|
||||
/* One http2 stream could bring down its comm_point along with
|
||||
* the other streams which could share the same query. Do all
|
||||
* the http2 stream bookkeeping upfront. */
|
||||
for(; rep; rep=rep->next) {
|
||||
if(rep->query_reply.c->use_h2)
|
||||
http2_stream_remove_mesh_state(rep->h2_stream);
|
||||
}
|
||||
rep = mstate->reply_list;
|
||||
/* in tcp_req_info, the mstates linked are removed, but
|
||||
* the reply_list is now NULL, so the remove-from-empty-list
|
||||
* takes no time and also it does not do the mesh accounting */
|
||||
@@ -1241,6 +1257,9 @@ int mesh_add_sub(struct module_qstate* qstate, struct query_info* qinfo,
|
||||
log_err("mesh_attach_sub: out of memory");
|
||||
return 0;
|
||||
}
|
||||
/* inherit RPZ passthru from the parent so respip on the sub
|
||||
* sees the same client-IP/qname PASSTHRU decision */
|
||||
(*sub)->s.rpz_passthru = qstate->rpz_passthru;
|
||||
#ifdef UNBOUND_DEBUG
|
||||
n =
|
||||
#else
|
||||
@@ -1763,7 +1782,8 @@ void mesh_query_done(struct mesh_state* mstate)
|
||||
}
|
||||
}
|
||||
|
||||
if(mstate->reply_list && mstate->s.env->cfg->dns_error_reporting)
|
||||
if(mstate->reply_list && mstate->s.env->cfg->dns_error_reporting
|
||||
&& (!rep || rep->security != sec_status_secure))
|
||||
dns_error_reporting(&mstate->s, rep);
|
||||
|
||||
for(r = mstate->reply_list; r; r = r->next) {
|
||||
@@ -1946,6 +1966,25 @@ struct mesh_state* mesh_area_find(struct mesh_area* mesh,
|
||||
return result;
|
||||
}
|
||||
|
||||
struct mesh_state* mesh_area_find_unique(struct mesh_area* mesh,
|
||||
struct respip_client_info* cinfo, struct query_info* qinfo,
|
||||
uint16_t qflags, int prime, int valrec, void* unique_info)
|
||||
{
|
||||
struct mesh_state key;
|
||||
struct mesh_state* result;
|
||||
|
||||
key.node.key = &key;
|
||||
key.s.is_priming = prime;
|
||||
key.s.is_valrec = valrec;
|
||||
key.s.qinfo = *qinfo;
|
||||
key.s.query_flags = qflags;
|
||||
key.unique = (struct mesh_state*)unique_info;
|
||||
key.s.client_info = cinfo;
|
||||
|
||||
result = (struct mesh_state*)rbtree_search(&mesh->all, &key);
|
||||
return result;
|
||||
}
|
||||
|
||||
/** remove mesh state callback */
|
||||
int mesh_state_del_cb(struct mesh_state* s, mesh_cb_func_type cb, void* cb_arg)
|
||||
{
|
||||
@@ -1967,7 +2006,7 @@ int mesh_state_del_cb(struct mesh_state* s, mesh_cb_func_type cb, void* cb_arg)
|
||||
|
||||
int mesh_state_add_cb(struct mesh_state* s, struct edns_data* edns,
|
||||
sldns_buffer* buf, mesh_cb_func_type cb, void* cb_arg,
|
||||
uint16_t qid, uint16_t qflags)
|
||||
uint16_t qid, uint16_t qflags, struct mesh_cb** result)
|
||||
{
|
||||
struct mesh_cb* r = regional_alloc(s->s.region,
|
||||
sizeof(struct mesh_cb));
|
||||
@@ -1991,13 +2030,14 @@ int mesh_state_add_cb(struct mesh_state* s, struct edns_data* edns,
|
||||
r->qflags = qflags;
|
||||
r->next = s->cb_list;
|
||||
s->cb_list = r;
|
||||
*result = r;
|
||||
return 1;
|
||||
|
||||
}
|
||||
|
||||
int mesh_state_add_reply(struct mesh_state* s, struct edns_data* edns,
|
||||
struct comm_reply* rep, uint16_t qid, uint16_t qflags,
|
||||
const struct query_info* qinfo)
|
||||
const struct query_info* qinfo, struct mesh_reply** result)
|
||||
{
|
||||
struct mesh_reply* r = regional_alloc(s->s.region,
|
||||
sizeof(struct mesh_reply));
|
||||
@@ -2078,6 +2118,7 @@ int mesh_state_add_reply(struct mesh_state* s, struct edns_data* edns,
|
||||
r->local_alias = NULL;
|
||||
|
||||
s->reply_list = r;
|
||||
*result = r;
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -2235,8 +2276,29 @@ void mesh_run(struct mesh_area* mesh, struct mesh_state* mstate,
|
||||
enum module_ev ev, struct outbound_entry* e)
|
||||
{
|
||||
enum module_ext_state s;
|
||||
int numrun = 0;
|
||||
verbose(VERB_ALGO, "mesh_run: start");
|
||||
while(mstate) {
|
||||
if(numrun++ > MESH_MAX_RUN_ITER) {
|
||||
/* These modules are too much to activate, stop them.*/
|
||||
log_err("Too many module run iterations, deleting");
|
||||
while(mstate) {
|
||||
/* notify supers */
|
||||
if(mstate->super_set.count > 0) {
|
||||
verbose(VERB_ALGO, "notify supers of failure");
|
||||
mstate->s.return_msg = NULL;
|
||||
mstate->s.return_rcode = LDNS_RCODE_SERVFAIL;
|
||||
mesh_walk_supers(mesh, mstate);
|
||||
}
|
||||
mesh_state_delete(&mstate->s);
|
||||
if(mesh->run.count > 0) {
|
||||
/* pop random element off the runnable tree */
|
||||
mstate = (struct mesh_state*)mesh->run.root->key;
|
||||
(void)rbtree_delete(&mesh->run, mstate);
|
||||
} else mstate = NULL;
|
||||
}
|
||||
break;
|
||||
}
|
||||
/* run the module */
|
||||
fptr_ok(fptr_whitelist_mod_operate(
|
||||
mesh->mods.mod[mstate->s.curmod]->operate));
|
||||
@@ -2388,7 +2450,8 @@ void mesh_list_remove(struct mesh_state* m, struct mesh_state** fp,
|
||||
}
|
||||
|
||||
void mesh_state_remove_reply(struct mesh_area* mesh, struct mesh_state* m,
|
||||
struct comm_point* cp, struct doq_stream* doq_stream)
|
||||
struct comm_point* cp, struct http2_stream* h2_stream,
|
||||
struct doq_stream* doq_stream)
|
||||
{
|
||||
struct mesh_reply* n, *prev = NULL;
|
||||
n = m->reply_list;
|
||||
@@ -2397,6 +2460,7 @@ void mesh_state_remove_reply(struct mesh_area* mesh, struct mesh_state* m,
|
||||
if(!n) return; /* nothing to remove, also no accounting needed */
|
||||
while(n) {
|
||||
if(n->query_reply.c == cp
|
||||
&& (!h2_stream || n->h2_stream == h2_stream)
|
||||
&& (!doq_stream || n->query_reply.doq_stream == doq_stream)) {
|
||||
/* unlink it */
|
||||
if(prev) prev->next = n->next;
|
||||
@@ -2692,13 +2756,30 @@ int mesh_jostle_exceeded(struct mesh_area* mesh)
|
||||
}
|
||||
|
||||
void mesh_remove_callback(struct mesh_area* mesh, struct query_info* qinfo,
|
||||
uint16_t qflags, mesh_cb_func_type cb, void* cb_arg)
|
||||
uint16_t qflags, mesh_cb_func_type cb, void* cb_arg, void* unique_info)
|
||||
{
|
||||
struct mesh_state* s = NULL;
|
||||
s = mesh_area_find(mesh, NULL, qinfo, qflags&(BIT_RD|BIT_CD), 0, 0);
|
||||
if(!s) return;
|
||||
if(!mesh_state_del_cb(s, cb, cb_arg)) return;
|
||||
if(s && mesh_state_del_cb(s, cb, cb_arg))
|
||||
goto removed;
|
||||
if(unique_info) {
|
||||
s = mesh_area_find_unique(mesh, NULL, qinfo,
|
||||
qflags&(BIT_RD|BIT_CD), 0, 0, unique_info);
|
||||
if(s && mesh_state_del_cb(s, cb, cb_arg))
|
||||
goto removed;
|
||||
}
|
||||
/* mesh_area_find builds key.unique=NULL and cannot match a state
|
||||
* created with mesh_state_make_unique (e.g. subnetcache sets
|
||||
* env->unique_mesh). Fall back to a linear scan; cb+cb_arg is an
|
||||
* exact key (mesh_state_del_cb compares both).
|
||||
* This works for both lookups for zonemd and for hostname authzone. */
|
||||
RBTREE_FOR(s, struct mesh_state*, &mesh->all) {
|
||||
if(s->cb_list && mesh_state_del_cb(s, cb, cb_arg))
|
||||
goto removed;
|
||||
}
|
||||
return;
|
||||
|
||||
removed:
|
||||
/* It was in the list and removed. */
|
||||
log_assert(mesh->num_reply_addrs > 0);
|
||||
mesh->num_reply_addrs--;
|
||||
|
||||
+38
-5
@@ -69,6 +69,13 @@ struct respip_client_info;
|
||||
*/
|
||||
#define MESH_MAX_ACTIVATION 10000
|
||||
|
||||
/**
|
||||
* Maximum number of mesh state run items. These are different modules
|
||||
* activated during a mesh run. Any more is likely an infinite loop
|
||||
* in the module. It is then terminated, and states are deleted.
|
||||
*/
|
||||
#define MESH_MAX_RUN_ITER 10000
|
||||
|
||||
/**
|
||||
* Max number of references-to-references-to-references.. search size.
|
||||
* Any more is treated like 'too large', and the creation of a new
|
||||
@@ -342,11 +349,14 @@ void mesh_new_client(struct mesh_area* mesh, struct query_info* qinfo,
|
||||
* @param cb_arg: callback user arg.
|
||||
* @param rpz_passthru: if true, the rpz passthru was previously found and
|
||||
* further rpz processing is stopped.
|
||||
* @param unique_info: if nonnull, unique info is passed back to be used
|
||||
* for the callback remove call. It does not need to be deallocated.
|
||||
* @return 0 on error.
|
||||
*/
|
||||
int mesh_new_callback(struct mesh_area* mesh, struct query_info* qinfo,
|
||||
uint16_t qflags, struct edns_data* edns, struct sldns_buffer* buf,
|
||||
uint16_t qid, mesh_cb_func_type cb, void* cb_arg, int rpz_passthru);
|
||||
uint16_t qid, mesh_cb_func_type cb, void* cb_arg, int rpz_passthru,
|
||||
void** unique_info);
|
||||
|
||||
/**
|
||||
* New prefetch message. Create new query state if needed.
|
||||
@@ -543,6 +553,23 @@ struct mesh_state* mesh_area_find(struct mesh_area* mesh,
|
||||
struct respip_client_info* cinfo, struct query_info* qinfo,
|
||||
uint16_t qflags, int prime, int valrec);
|
||||
|
||||
/**
|
||||
* Find a unique mesh state in the mesh area. Pass relevant flags.
|
||||
*
|
||||
* @param mesh: the mesh area to look in.
|
||||
* @param cinfo: if non-NULL client specific info that may affect IP-based
|
||||
* actions that apply to the query result.
|
||||
* @param qinfo: what query
|
||||
* @param qflags: if RD / CD bit is set or not.
|
||||
* @param prime: if it is a priming query.
|
||||
* @param valrec: if it is a validation-recursion query.
|
||||
* @param unique_info: the unique info for the state. NULL can be passed.
|
||||
* @return: mesh state or NULL if not found.
|
||||
*/
|
||||
struct mesh_state* mesh_area_find_unique(struct mesh_area* mesh,
|
||||
struct respip_client_info* cinfo, struct query_info* qinfo,
|
||||
uint16_t qflags, int prime, int valrec, void* unique_info);
|
||||
|
||||
/**
|
||||
* Setup attachment super/sub relation between super and sub mesh state.
|
||||
* The relation must not be present when calling the function.
|
||||
@@ -562,11 +589,12 @@ int mesh_state_attachment(struct mesh_state* super, struct mesh_state* sub);
|
||||
* @param qid: ID of reply.
|
||||
* @param qflags: original query flags.
|
||||
* @param qinfo: original query info.
|
||||
* @param result: the allocated reply structure, for rollback.
|
||||
* @return: 0 on alloc error.
|
||||
*/
|
||||
int mesh_state_add_reply(struct mesh_state* s, struct edns_data* edns,
|
||||
struct comm_reply* rep, uint16_t qid, uint16_t qflags,
|
||||
const struct query_info* qinfo);
|
||||
const struct query_info* qinfo, struct mesh_reply** result);
|
||||
|
||||
/**
|
||||
* Create new callback structure and attach it to a mesh state.
|
||||
@@ -578,11 +606,12 @@ int mesh_state_add_reply(struct mesh_state* s, struct edns_data* edns,
|
||||
* @param cb_arg: callback user arg.
|
||||
* @param qid: ID of reply.
|
||||
* @param qflags: original query flags.
|
||||
* @param result: the allocated callback structure, for rollback.
|
||||
* @return: 0 on alloc error.
|
||||
*/
|
||||
int mesh_state_add_cb(struct mesh_state* s, struct edns_data* edns,
|
||||
struct sldns_buffer* buf, mesh_cb_func_type cb, void* cb_arg,
|
||||
uint16_t qid, uint16_t qflags);
|
||||
uint16_t qid, uint16_t qflags, struct mesh_cb** result);
|
||||
|
||||
/**
|
||||
* Run the mesh. Run all runnable mesh states. Which can create new
|
||||
@@ -683,11 +712,14 @@ void mesh_list_remove(struct mesh_state* m, struct mesh_state** fp,
|
||||
* @param mesh: to update the counters.
|
||||
* @param m: the mesh state.
|
||||
* @param cp: the comm_point to remove from the list.
|
||||
* @param h2_stream: if not NULL, it specifies the h2_stream to match
|
||||
* for the delete.
|
||||
* @param doq_stream: if not NULL, it specifies the doq_stream to match
|
||||
* for the delete.
|
||||
*/
|
||||
void mesh_state_remove_reply(struct mesh_area* mesh, struct mesh_state* m,
|
||||
struct comm_point* cp, struct doq_stream* doq_stream);
|
||||
struct comm_point* cp, struct http2_stream* h2_stream,
|
||||
struct doq_stream* doq_stream);
|
||||
|
||||
/** Callback for when the serve expired client timer has run out. Tries to
|
||||
* find an expired answer in the cache and reply that to the client.
|
||||
@@ -734,9 +766,10 @@ void mesh_respond_serve_expired(struct mesh_state* mstate);
|
||||
* @param qflags: flags from client query.
|
||||
* @param cb: callback function.
|
||||
* @param cb_arg: callback user arg.
|
||||
* @param unique_info: if not NULL, used to find a unique state for removal.
|
||||
*/
|
||||
void mesh_remove_callback(struct mesh_area* mesh, struct query_info* qinfo,
|
||||
uint16_t qflags, mesh_cb_func_type cb, void* cb_arg);
|
||||
uint16_t qflags, mesh_cb_func_type cb, void* cb_arg, void* unique_info);
|
||||
|
||||
/** Copy the client info to the query region. */
|
||||
struct respip_client_info* mesh_copy_client_info(struct regional* region,
|
||||
|
||||
@@ -1702,6 +1702,12 @@ static int setup_if(struct port_if* pif, const char* addrstr, size_t numfd,
|
||||
!netblockstrtoaddr(addrstr, UNBOUND_DNS_PORT,
|
||||
&pif->addr, &pif->addrlen, &pif->pfxlen))
|
||||
return 0;
|
||||
#ifdef INT_MAX
|
||||
if(numfd > (size_t)INT_MAX) {
|
||||
log_err("num_ports exceeds INT_MAX");
|
||||
return 0;
|
||||
}
|
||||
#endif
|
||||
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
|
||||
pif->shpif = shared_ports_find_if(shp, &pif->addr, pif->addrlen,
|
||||
pif->pfxlen);
|
||||
@@ -1777,6 +1783,13 @@ outside_network_create(struct comm_base *base, size_t bufsize,
|
||||
outside_network_delete(outnet);
|
||||
return NULL;
|
||||
}
|
||||
#ifdef INT_MAX
|
||||
if(num_ports > (size_t)INT_MAX) {
|
||||
log_err("outgoing num_ports exceeds INT_MAX");
|
||||
outside_network_delete(outnet);
|
||||
return NULL;
|
||||
}
|
||||
#endif
|
||||
#ifndef INET6
|
||||
do_ip6 = 0;
|
||||
#endif
|
||||
@@ -3349,9 +3362,9 @@ serviced_udp_callback(struct comm_point* c, void* arg, int error,
|
||||
if(error == NETEVENT_TIMEOUT) {
|
||||
if(sq->status == serviced_query_UDP_EDNS && sq->last_rtt < 5000 &&
|
||||
(serviced_query_udp_size(sq, serviced_query_UDP_EDNS_FRAG) < serviced_query_udp_size(sq, serviced_query_UDP_EDNS))) {
|
||||
/* fallback to 1480/1280 */
|
||||
/* fallback to 1472/1232 */
|
||||
sq->status = serviced_query_UDP_EDNS_FRAG;
|
||||
log_name_addr(VERB_ALGO, "try edns1xx0", sq->qbuf+10,
|
||||
log_name_addr(VERB_ALGO, "try edns1xx2", sq->qbuf+10,
|
||||
&sq->addr, sq->addrlen);
|
||||
if(!serviced_udp_send(sq, c->buffer)) {
|
||||
serviced_callbacks(sq, NETEVENT_CLOSED, c, rep);
|
||||
@@ -3488,7 +3501,8 @@ outnet_serviced_query(struct outside_network* outnet,
|
||||
char* tls_auth_name, struct sockaddr_storage* addr, socklen_t addrlen,
|
||||
uint8_t* zone, size_t zonelen, struct module_qstate* qstate,
|
||||
comm_point_callback_type* callback, void* callback_arg,
|
||||
sldns_buffer* buff, struct module_env* env, int* was_ratelimited)
|
||||
sldns_buffer* buff, struct module_env* env, int* was_ratelimited,
|
||||
int* ratelimit_incremented)
|
||||
{
|
||||
struct serviced_query* sq;
|
||||
struct service_callback* cb;
|
||||
@@ -3560,6 +3574,7 @@ outnet_serviced_query(struct outside_network* outnet,
|
||||
"delegation point", zone,
|
||||
LDNS_RR_TYPE_NS, LDNS_RR_CLASS_IN);
|
||||
}
|
||||
*ratelimit_incremented = 1;
|
||||
}
|
||||
/* make new serviced query entry */
|
||||
sq = serviced_create(outnet, buff, dnssec, want_dnssec, nocaps,
|
||||
@@ -3765,7 +3780,33 @@ setup_comm_ssl(struct comm_point* cp, struct outside_network* outnet,
|
||||
(void)SSL_set_tlsext_host_name(cp->ssl, host);
|
||||
}
|
||||
#endif
|
||||
#ifdef HAVE_SSL_SET1_HOST
|
||||
#ifdef HAVE_SSL_SET1_DNSNAME
|
||||
if((SSL_CTX_get_verify_mode(outnet->sslctx)&SSL_VERIFY_PEER)) {
|
||||
/* because we set SSL_VERIFY_PEER, in netevent in
|
||||
* ssl_handshake, it'll check if the certificate
|
||||
* verification has succeeded */
|
||||
/* SSL_VERIFY_PEER is set on the sslctx */
|
||||
/* and the certificates to verify with are loaded into
|
||||
* it with SSL_load_verify_locations or
|
||||
* SSL_CTX_set_default_verify_paths */
|
||||
/* setting the hostname makes openssl verify the
|
||||
* host name in the x509 certificate in the
|
||||
* SSL connection*/
|
||||
struct sockaddr_storage tmpaddr;
|
||||
socklen_t tmpaddrlen = (socklen_t)sizeof(tmpaddr);
|
||||
if(ipstrtoaddr(host, UNBOUND_DNS_PORT, &tmpaddr, &tmpaddrlen)) {
|
||||
if(!SSL_set1_ipaddr(cp->ssl, host)) {
|
||||
log_err("SSL_set1_ipaddr failed");
|
||||
return 0;
|
||||
}
|
||||
} else {
|
||||
if(!SSL_set1_dnsname(cp->ssl, host)) {
|
||||
log_err("SSL_set1_dnsname failed");
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
}
|
||||
#elif defined(HAVE_SSL_SET1_HOST)
|
||||
if((SSL_CTX_get_verify_mode(outnet->sslctx)&SSL_VERIFY_PEER)) {
|
||||
/* because we set SSL_VERIFY_PEER, in netevent in
|
||||
* ssl_handshake, it'll check if the certificate
|
||||
@@ -3894,7 +3935,8 @@ outnet_comm_point_for_http(struct outside_network* outnet,
|
||||
/* outnet_tcp_connect has closed fd on error for us */
|
||||
return 0;
|
||||
}
|
||||
cp = comm_point_create_http_out(outnet->base, 65552, cb, cb_arg,
|
||||
cp = comm_point_create_http_out(outnet->base,
|
||||
sldns_buffer_capacity(outnet->udp_buff), cb, cb_arg,
|
||||
outnet->udp_buff);
|
||||
if(!cp) {
|
||||
log_err("malloc failure");
|
||||
@@ -4085,13 +4127,15 @@ static int shared_ports_alloc_ifs(struct shared_ports* shp, char** ifs,
|
||||
size_t done_4 = 0, done_6 = 0;
|
||||
int i;
|
||||
for(i=0; i<num_ifs; i++) {
|
||||
if(str_is_ip6(ifs[i]) && do_ip6) {
|
||||
if(str_is_ip6(ifs[i]) && do_ip6 &&
|
||||
(int)done_6 < shp->num_ip6) {
|
||||
if(!shared_ports_setup_if(&shp->ip6_ifs[done_6],
|
||||
ifs[i], availports, numavailports))
|
||||
return 0;
|
||||
done_6++;
|
||||
}
|
||||
if(!str_is_ip6(ifs[i]) && do_ip4) {
|
||||
if(!str_is_ip6(ifs[i]) && do_ip4 &&
|
||||
(int)done_4 < shp->num_ip4) {
|
||||
if(!shared_ports_setup_if(&shp->ip4_ifs[done_4],
|
||||
ifs[i], availports, numavailports))
|
||||
return 0;
|
||||
@@ -4112,16 +4156,21 @@ struct shared_ports* shared_ports_create(char** ifs, int num_ifs, int do_ip4,
|
||||
return NULL;
|
||||
}
|
||||
lock_basic_init(&shp->lock);
|
||||
lock_protect(&shp->lock, shp, sizeof(*shp));
|
||||
lock_protect(&shp->lock, &shp->ip4_ifs, sizeof(shp->ip4_ifs));
|
||||
lock_protect(&shp->lock, &shp->num_ip4, sizeof(shp->num_ip4));
|
||||
lock_protect(&shp->lock, &shp->ip6_ifs, sizeof(shp->ip6_ifs));
|
||||
lock_protect(&shp->lock, &shp->num_ip6, sizeof(shp->num_ip6));
|
||||
|
||||
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
|
||||
/* Allocate interfaces */
|
||||
lock_basic_lock(&shp->lock);
|
||||
if(!shared_ports_alloc_ifs(shp, ifs, num_ifs, do_ip4, do_ip6,
|
||||
availports, numavailports)) {
|
||||
log_err("malloc failed");
|
||||
shared_ports_delete(shp);
|
||||
return NULL;
|
||||
}
|
||||
lock_basic_unlock(&shp->lock);
|
||||
#else
|
||||
(void)ifs; (void)num_ifs; (void)do_ip4; (void)do_ip6;
|
||||
(void)availports; (void)numavailports;
|
||||
@@ -4199,6 +4248,9 @@ int shared_ports_fetch_random(struct shared_ports* shp,
|
||||
int portno = 0, my_port = 0;
|
||||
if(!shpif)
|
||||
return 0;
|
||||
# ifdef THREADS_DISABLED
|
||||
(void)shp;
|
||||
# endif
|
||||
lock_basic_lock(&shp->lock);
|
||||
if(udp_connect) {
|
||||
/* if we connect() we cannot reuse fds for a port. */
|
||||
@@ -4256,6 +4308,9 @@ void shared_ports_return_port(struct shared_ports* shp,
|
||||
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
|
||||
if(!shpif)
|
||||
return;
|
||||
# ifdef THREADS_DISABLED
|
||||
(void)shp;
|
||||
# endif
|
||||
lock_basic_lock(&shp->lock);
|
||||
log_assert(shpif->inuse > 0);
|
||||
shpif->avail_ports[shpif->avail_total - shpif->inuse] = port;
|
||||
|
||||
@@ -538,7 +538,7 @@ struct serviced_query {
|
||||
serviced_query_UDP_EDNS_fallback,
|
||||
/** probe to test TCP noEDNS0 (EDNS gives FORMERRorNOTIMP) */
|
||||
serviced_query_TCP_EDNS_fallback,
|
||||
/** send UDP query with EDNS1480 (or 1280) */
|
||||
/** send UDP query with EDNS1472 (or 1232) */
|
||||
serviced_query_UDP_EDNS_FRAG
|
||||
}
|
||||
/** variable with current status */
|
||||
@@ -697,6 +697,8 @@ void pending_delete(struct outside_network* outnet, struct pending* p);
|
||||
* @param env: the module environment.
|
||||
* @param was_ratelimited: it will signal back if the query failed to pass the
|
||||
* ratelimit check.
|
||||
* @param ratelimit_incremented: set to true if the ratelimit counter
|
||||
* was increased.
|
||||
* @return 0 on error, or pointer to serviced query that is used to answer
|
||||
* this serviced query may be shared with other callbacks as well.
|
||||
*/
|
||||
@@ -706,7 +708,8 @@ struct serviced_query* outnet_serviced_query(struct outside_network* outnet,
|
||||
char* tls_auth_name, struct sockaddr_storage* addr, socklen_t addrlen,
|
||||
uint8_t* zone, size_t zonelen, struct module_qstate* qstate,
|
||||
comm_point_callback_type* callback, void* callback_arg,
|
||||
struct sldns_buffer* buff, struct module_env* env, int* was_ratelimited);
|
||||
struct sldns_buffer* buff, struct module_env* env, int* was_ratelimited,
|
||||
int* ratelimit_incremented);
|
||||
|
||||
/**
|
||||
* Remove service query callback.
|
||||
|
||||
+33
-17
@@ -721,13 +721,22 @@ rpz_insert_local_zones_trigger(struct local_zones* lz, uint8_t* dname,
|
||||
char* rrstr = sldns_wire2str_rr(rr, rr_len);
|
||||
if(rrstr == NULL) {
|
||||
log_err("malloc error while inserting rpz nsdname trigger");
|
||||
free(dname);
|
||||
if(!newzone)
|
||||
free(dname);
|
||||
lock_rw_unlock(&lz->lock);
|
||||
return;
|
||||
}
|
||||
lock_rw_wrlock(&z->lock);
|
||||
local_zone_enter_rr(z, dname, dnamelen, dnamelabs, rrtype,
|
||||
rrclass, ttl, rdata, rdata_len, rrstr);
|
||||
if(!local_zone_enter_rr(z, dname, dnamelen, dnamelabs, rrtype,
|
||||
rrclass, ttl, rdata, rdata_len, rrstr)) {
|
||||
log_err("rpz: could not enter local-data: %s", rrstr);
|
||||
if(!newzone)
|
||||
free(dname);
|
||||
lock_rw_unlock(&z->lock);
|
||||
lock_rw_unlock(&lz->lock);
|
||||
free(rrstr);
|
||||
return;
|
||||
}
|
||||
lock_rw_unlock(&z->lock);
|
||||
free(rrstr);
|
||||
}
|
||||
@@ -805,8 +814,9 @@ rpz_insert_nsdname_trigger(struct rpz* r, uint8_t* dname, size_t dnamelen,
|
||||
uint8_t* dname_stripped = NULL;
|
||||
size_t dnamelen_stripped = 0;
|
||||
|
||||
rpz_strip_nsdname_suffix(dname, dnamelen, &dname_stripped,
|
||||
&dnamelen_stripped);
|
||||
if(!rpz_strip_nsdname_suffix(dname, dnamelen, &dname_stripped,
|
||||
&dnamelen_stripped))
|
||||
return;
|
||||
if(a == RPZ_INVALID_ACTION) {
|
||||
verbose(VERB_ALGO, "rpz: skipping invalid action");
|
||||
free(dname_stripped);
|
||||
@@ -904,8 +914,8 @@ rpz_report_rrset_error(const char* msg, uint8_t* rr, size_t rr_len) {
|
||||
|
||||
/* from localzone.c; difference is we don't have a dname */
|
||||
static struct local_rrset*
|
||||
rpz_clientip_new_rrset(struct regional* region,
|
||||
struct clientip_synthesized_rr* raddr, uint16_t rrtype, uint16_t rrclass)
|
||||
rpz_clientip_new_rrset(struct regional* region, uint16_t rrtype,
|
||||
uint16_t rrclass)
|
||||
{
|
||||
struct packed_rrset_data* pd;
|
||||
struct local_rrset* rrset = (struct local_rrset*)
|
||||
@@ -914,8 +924,6 @@ rpz_clientip_new_rrset(struct regional* region,
|
||||
log_err("out of memory");
|
||||
return NULL;
|
||||
}
|
||||
rrset->next = raddr->data;
|
||||
raddr->data = rrset;
|
||||
rrset->rrset = (struct ub_packed_rrset_key*)
|
||||
regional_alloc_zero(region, sizeof(*rrset->rrset));
|
||||
if(rrset->rrset == NULL) {
|
||||
@@ -954,12 +962,18 @@ rpz_clientip_enter_rr(struct regional* region, struct clientip_synthesized_rr* r
|
||||
return 0;
|
||||
}
|
||||
|
||||
rrset = rpz_clientip_new_rrset(region, raddr, rrtype, rrclass);
|
||||
if(raddr->data == NULL) {
|
||||
rrset = rpz_clientip_new_rrset(region, rrtype, rrclass);
|
||||
if(rrset == NULL) {
|
||||
return 0;
|
||||
}
|
||||
|
||||
return rrset_insert_rr(region, rrset->rrset->entry.data, rdata, rdata_len, ttl, "");
|
||||
if(!rrset_insert_rr(region, rrset->rrset->entry.data, rdata, rdata_len, ttl, ""))
|
||||
return 0;
|
||||
|
||||
/* Link in now that the allocations have succeeded. */
|
||||
rrset->next = raddr->data;
|
||||
raddr->data = rrset;
|
||||
return 1;
|
||||
}
|
||||
|
||||
static int
|
||||
@@ -982,7 +996,6 @@ rpz_clientip_insert_trigger_rr(struct clientip_synthesized_rrset* set, struct so
|
||||
lock_rw_wrlock(&node->lock);
|
||||
lock_rw_unlock(&set->lock);
|
||||
|
||||
node->action = a;
|
||||
if(a == RPZ_LOCAL_DATA_ACTION) {
|
||||
if(!rpz_clientip_enter_rr(set->region, node, rrtype,
|
||||
rrclass, ttl, rdata, rdata_len)) {
|
||||
@@ -992,6 +1005,7 @@ rpz_clientip_insert_trigger_rr(struct clientip_synthesized_rrset* set, struct so
|
||||
}
|
||||
|
||||
}
|
||||
node->action = a;
|
||||
|
||||
lock_rw_unlock(&node->lock);
|
||||
|
||||
@@ -1977,8 +1991,9 @@ rpz_synthesize_nodata(struct rpz* ATTR_UNUSED(r), struct module_qstate* ms,
|
||||
0, /* total */
|
||||
sec_status_insecure,
|
||||
LDNS_EDE_NONE);
|
||||
if(msg->rep)
|
||||
msg->rep->authoritative = 1;
|
||||
if(!msg->rep)
|
||||
return NULL;
|
||||
msg->rep->authoritative = 1;
|
||||
if(!rpz_add_soa(msg->rep, ms, az))
|
||||
return NULL;
|
||||
return msg;
|
||||
@@ -2008,8 +2023,9 @@ rpz_synthesize_nxdomain(struct rpz* r, struct module_qstate* ms,
|
||||
0, /* total */
|
||||
sec_status_insecure,
|
||||
LDNS_EDE_NONE);
|
||||
if(msg->rep)
|
||||
msg->rep->authoritative = 1;
|
||||
if(!msg->rep)
|
||||
return NULL;
|
||||
msg->rep->authoritative = 1;
|
||||
if(!rpz_add_soa(msg->rep, ms, az))
|
||||
return NULL;
|
||||
return msg;
|
||||
|
||||
+11
-2
@@ -67,19 +67,28 @@ sldns_rr_dnskey_key_size_raw(const unsigned char* keydata,
|
||||
case LDNS_RSASHA512:
|
||||
#endif
|
||||
if (len > 0) {
|
||||
size_t nlen, offset;
|
||||
if (keydata[0] == 0) {
|
||||
/* big exponent */
|
||||
if (len > 3) {
|
||||
memmove(&int16, keydata + 1, 2);
|
||||
exp = ntohs(int16);
|
||||
return (len - exp - 3)*8;
|
||||
offset = 3;
|
||||
} else {
|
||||
return 0;
|
||||
}
|
||||
} else {
|
||||
exp = keydata[0];
|
||||
return (len-exp-1)*8;
|
||||
offset = 1;
|
||||
}
|
||||
if(exp+offset > len)
|
||||
return 0;
|
||||
nlen = len - exp - offset;
|
||||
/* prefixed zeroes mean a smaller value */
|
||||
while(nlen > 0 &&
|
||||
keydata[len-nlen] == 0)
|
||||
nlen--;
|
||||
return nlen*8;
|
||||
} else {
|
||||
return 0;
|
||||
}
|
||||
|
||||
+6
-4
@@ -842,7 +842,8 @@ rrinternal_parse_rdata(sldns_buffer* strbuf, char* token, size_t token_len,
|
||||
sldns_write_uint16(rr+dname_len+8, (uint16_t)(rr_cur_len-dname_len-10));
|
||||
*rr_len = rr_cur_len;
|
||||
/* SVCB/HTTPS handling */
|
||||
if (rr_type == LDNS_RR_TYPE_SVCB || rr_type == LDNS_RR_TYPE_HTTPS) {
|
||||
if ((rr_type == LDNS_RR_TYPE_SVCB || rr_type == LDNS_RR_TYPE_HTTPS)
|
||||
&& !was_unknown_rr_format) {
|
||||
size_t rdata_len = rr_cur_len - dname_len - 10;
|
||||
uint8_t *rdata = rr+dname_len + 10;
|
||||
|
||||
@@ -1201,7 +1202,7 @@ sldns_str2wire_svcbparam_ipv4hint(const char* val, uint8_t* rd, size_t* rd_len)
|
||||
{
|
||||
size_t count;
|
||||
char ip_str[INET_ADDRSTRLEN+1];
|
||||
char *next_ip_str;
|
||||
const char *next_ip_str;
|
||||
size_t i;
|
||||
|
||||
for (i = 0, count = 1; val[i]; i++) {
|
||||
@@ -1256,7 +1257,7 @@ sldns_str2wire_svcbparam_ipv6hint(const char* val, uint8_t* rd, size_t* rd_len)
|
||||
{
|
||||
size_t count;
|
||||
char ip_str[INET6_ADDRSTRLEN+1];
|
||||
char *next_ip_str;
|
||||
const char *next_ip_str;
|
||||
size_t i;
|
||||
|
||||
for (i = 0, count = 1; val[i]; i++) {
|
||||
@@ -1317,7 +1318,7 @@ static int
|
||||
sldns_str2wire_svcbparam_mandatory(const char* val, uint8_t* rd, size_t* rd_len)
|
||||
{
|
||||
size_t i, count, val_len;
|
||||
char* next_key;
|
||||
const char* next_key;
|
||||
|
||||
val_len = strlen(val);
|
||||
|
||||
@@ -1410,6 +1411,7 @@ sldns_str2wire_svcbparam_ech_value(const char* val, uint8_t* rd, size_t* rd_len)
|
||||
return LDNS_WIREPARSE_ERR_BUFFER_TOO_SMALL;
|
||||
sldns_write_uint16(rd, SVCB_KEY_ECH);
|
||||
sldns_write_uint16(rd + 2, 0);
|
||||
*rd_len = 4;
|
||||
|
||||
return LDNS_WIREPARSE_ERR_OK;
|
||||
}
|
||||
|
||||
+165
-11
@@ -156,7 +156,7 @@ char* wsa_strerror(int err);
|
||||
#endif
|
||||
|
||||
static const char ICANN_UPDATE_CA[] =
|
||||
/* The ICANN CA fetched at 24 Sep 2010. Valid to 2028 */
|
||||
/* The ICANN CA fetched at 29 May 2026. Valid to 20 Mar 2045 */
|
||||
"-----BEGIN CERTIFICATE-----\n"
|
||||
"MIIDdzCCAl+gAwIBAgIBATANBgkqhkiG9w0BAQsFADBdMQ4wDAYDVQQKEwVJQ0FO\n"
|
||||
"TjEmMCQGA1UECxMdSUNBTk4gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkxFjAUBgNV\n"
|
||||
@@ -177,6 +177,40 @@ static const char ICANN_UPDATE_CA[] =
|
||||
"15nu5JBSewrCkYqYYmaxyOC3WrVGfHZxVI7MpIFcGdvSb2a1uyuua8l0BKgk3ujF\n"
|
||||
"0/wsHNeP22qNyVO+XVBzrM8fk8BSUFuiT/6tZTYXRtEt5aKQZgXbKU5dUF3jT9qg\n"
|
||||
"j/Br5BZw3X/zd325TvnswzMC1+ljLzHnQGGk\n"
|
||||
"-----END CERTIFICATE-----\n"
|
||||
"\n"
|
||||
"-----BEGIN CERTIFICATE-----\n"
|
||||
"MIIFsTCCA5mgAwIBAgIUQFsYkgroBoe69HKQPy8/DQuiLwgwDQYJKoZIhvcNAQEN\n"
|
||||
"BQAwYDELMAkGA1UEBhMCVVMxDjAMBgNVBAoMBUlDQU5OMSYwJAYDVQQLDB1JQ0FO\n"
|
||||
"TiBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTEZMBcGA1UEAwwQSUNBTk4gUm9vdCBD\n"
|
||||
"QSB2MjAeFw0yNTAzMjAyMTA0MjZaFw00NTAzMjAyMTA0MjZaMGAxCzAJBgNVBAYT\n"
|
||||
"AlVTMQ4wDAYDVQQKDAVJQ0FOTjEmMCQGA1UECwwdSUNBTk4gQ2VydGlmaWNhdGlv\n"
|
||||
"biBBdXRob3JpdHkxGTAXBgNVBAMMEElDQU5OIFJvb3QgQ0EgdjIwggIiMA0GCSqG\n"
|
||||
"SIb3DQEBAQUAA4ICDwAwggIKAoICAQCepDjrubjR7en/uZWo7MAnzFIIvUPYEc7b\n"
|
||||
"+AlefdlEDQ1JEmpfrvt/4CX9lJ9ShIBR6zwrQeDvrj5XZ2kEjbJ8Nnc6sM/ojdyr\n"
|
||||
"5jSLqcDPH9fJg7jCW02KF8CtqWsnqcW6jjTIZcCWkg9lEixdF8QAjIEgJtZte+Yh\n"
|
||||
"XeyN0KD2EaO8U5Id0bLvMyphuO1OCGKzDtetcX8K7SvoshdJx3lPIlYzqXl0nVAY\n"
|
||||
"iCeNdeDzTNjEOHYJOP6dYoZI8nKRJltMkZcCCjBE2vQuSMY2w4pOlWk1skHjMWXj\n"
|
||||
"QsZzngXuNG56zialL0TPEDVWjWRjzOnruHUAs4KUY8Zs+Nt8JdSlXMi825PKoKpp\n"
|
||||
"ESs7/ZG1mPjVOYp7Z7ntrRjJFgnUBjWzVPOx4yHiJj1ur+OpqP18oP5YfqY+tKmz\n"
|
||||
"7vlfRGGOEd08a0XgZISDNKpMAovn5pRUHTWPCCjc28tns9ODPvr1cQi+QSwTv+v8\n"
|
||||
"wnA5etGrsead88Rv/ieaq5ikMJTRDfW4d9SY2uPcMGvfU6VdQLRhQkzEVTQNAJ1R\n"
|
||||
"i2lOoJbbjwnK+OU9OhST/OqdjJDJAhTAstdUnrr8WBU80xM75MIaaTjSBCvZ1wro\n"
|
||||
"pAi2hYb0tedTH6WarSW3MH9HcEoGGzs2GD3hDB0a2eCp+TdAs8Up944SjY7UV4Jx\n"
|
||||
"sOC7TxbmkQIDAQABo2MwYTAdBgNVHQ4EFgQU+1EuMRuOZ/ecsfYzNQ+yGZsxZrMw\n"
|
||||
"HwYDVR0jBBgwFoAU+1EuMRuOZ/ecsfYzNQ+yGZsxZrMwDwYDVR0TAQH/BAUwAwEB\n"
|
||||
"/zAOBgNVHQ8BAf8EBAMCAf4wDQYJKoZIhvcNAQENBQADggIBACz38SkKR1WsEZnX\n"
|
||||
"x1BKaS5/oQPw+7quDQCKGoD2Vz7CR7yQh4zQn/Hh0173vKvRWcwN2io0iLJ1ysv5\n"
|
||||
"jXBLeWZh3djiQlXP3iWp4s01SiUwmFssxi3SD1IT2jNosk1xcVWthle9zth7Y8Mp\n"
|
||||
"iUJYnHobP7tX7H2g+I8Rqw2sEX/yPSYMYcdH5a1xRMPOLHTyOaCgevRBBBtXkiAJ\n"
|
||||
"Ob9QKZTaFaXntPXBKNSGkVb2d+2qKyJMrwd0KNI+SVSoIgNDAxkNOdi9x6X6ETW2\n"
|
||||
"4aYFsytohFVkNUXx2eFYRim4yjnD8PHIvDQSofLfSAC5TOERtwUFd+Mw3/di+HCm\n"
|
||||
"50OJPyoxZLjWQCCfNUZzgZZOe+zT6lgBiV3KB0UuuAdq7jGUeH/328HJDi30BvNj\n"
|
||||
"+TNb9Hmpm+ZDguM+f8p7GxapX8AVNu/xErtl4msYiVJrr1qqV+qLLEMwIz0raujG\n"
|
||||
"FFDd6N43wgduffbU20pThry0Y7rku5+RZjUZe/T7ZL+NUKiqXAPufrkqVkjX/8T+\n"
|
||||
"wyNZz8KkiQwkJthojpppa79FDxn/A2M8tt+FQqIONAUPR2m5nurVgftQH0z5ZtDB\n"
|
||||
"YykUlkUiPOJNXoDOIkbpA7lW2wezeY4te+EiSeUZSE541N5QBwaItaonIZsIgn6C\n"
|
||||
"pMnwChV9468oRE20bdqq9+Go7g4E\n"
|
||||
"-----END CERTIFICATE-----\n";
|
||||
|
||||
static const char DS_TRUST_ANCHOR[] =
|
||||
@@ -1674,18 +1708,116 @@ static unsigned long
|
||||
get_usage_of_ex(X509* cert)
|
||||
{
|
||||
unsigned long val = 0;
|
||||
#ifdef HAVE_X509_GET_KEY_USAGE
|
||||
val = X509_get_key_usage(cert);
|
||||
if (val == UINT32_MAX)
|
||||
return 0;
|
||||
#else
|
||||
ASN1_BIT_STRING* s;
|
||||
if((s=X509_get_ext_d2i(cert, NID_key_usage, NULL, NULL))) {
|
||||
if(s->length > 0) {
|
||||
val = s->data[0];
|
||||
if(s->length > 1)
|
||||
val |= s->data[1] << 8;
|
||||
# ifdef HAVE_ASN1_STRING_GET0_DATA
|
||||
const unsigned char *data = ASN1_STRING_get0_data(s);
|
||||
# else
|
||||
const unsigned char *data = ASN1_STRING_data(s);
|
||||
# endif
|
||||
int len = ASN1_STRING_length(s);
|
||||
if(len > 0) {
|
||||
val = data[0];
|
||||
if(len > 1)
|
||||
val |= data[1] << 8;
|
||||
}
|
||||
ASN1_BIT_STRING_free(s);
|
||||
}
|
||||
#endif
|
||||
return val;
|
||||
}
|
||||
|
||||
#if !defined(HAVE_X509_NAME_GET_TEXT_BY_NID) || defined(DEPRECATED_X509_NAME_GET_TEXT_BY_NID)
|
||||
/** print verbose output about name extension data. */
|
||||
static void
|
||||
print_name_ext(
|
||||
#if OPENSSL_VERSION_NUMBER >= 0x40000000
|
||||
const
|
||||
#endif
|
||||
X509_NAME* nm, int nid, const char* str)
|
||||
{
|
||||
int lastpos = -1;
|
||||
for(;;) {
|
||||
#if OPENSSL_VERSION_NUMBER >= 0x40000000
|
||||
const
|
||||
#endif
|
||||
X509_NAME_ENTRY* ne;
|
||||
#if OPENSSL_VERSION_NUMBER >= 0x40000000
|
||||
const
|
||||
#endif
|
||||
ASN1_STRING *asn;
|
||||
const unsigned char *data;
|
||||
char buf[1024];
|
||||
|
||||
lastpos = X509_NAME_get_index_by_NID(nm, nid, lastpos);
|
||||
if(lastpos == -1 || lastpos == -2)
|
||||
break;
|
||||
ne = X509_NAME_get_entry(nm, lastpos);
|
||||
if(!ne) continue;
|
||||
asn = X509_NAME_ENTRY_get_data(ne);
|
||||
if(!asn) continue;
|
||||
# ifdef HAVE_ASN1_STRING_GET0_DATA
|
||||
data = ASN1_STRING_get0_data(asn);
|
||||
# else
|
||||
data = ASN1_STRING_data(asn);
|
||||
# endif
|
||||
if(!data) continue;
|
||||
if(ASN1_STRING_length(asn) > (int)sizeof(buf)-1) continue;
|
||||
memcpy(buf, data, ASN1_STRING_length(asn));
|
||||
buf[ASN1_STRING_length(asn)]=0;
|
||||
printf("%s: %s\n", str, buf);
|
||||
}
|
||||
}
|
||||
#endif /* X509_NAME_GET_TEXT_BY_NID */
|
||||
|
||||
#if !defined(HAVE_X509_NAME_GET_TEXT_BY_NID) || defined(DEPRECATED_X509_NAME_GET_TEXT_BY_NID)
|
||||
/** see if the valid emailaddr is present. */
|
||||
static int
|
||||
has_valid_emailaddr(
|
||||
#if OPENSSL_VERSION_NUMBER >= 0x40000000
|
||||
const
|
||||
#endif
|
||||
X509_NAME* nm, const char* p7signer)
|
||||
{
|
||||
int lastpos = -1;
|
||||
for(;;) {
|
||||
#if OPENSSL_VERSION_NUMBER >= 0x40000000
|
||||
const
|
||||
#endif
|
||||
X509_NAME_ENTRY* ne;
|
||||
#if OPENSSL_VERSION_NUMBER >= 0x40000000
|
||||
const
|
||||
#endif
|
||||
ASN1_STRING *asn;
|
||||
const unsigned char *data;
|
||||
|
||||
lastpos = X509_NAME_get_index_by_NID(nm,
|
||||
NID_pkcs9_emailAddress, lastpos);
|
||||
if(lastpos == -1 || lastpos == -2)
|
||||
break;
|
||||
ne = X509_NAME_get_entry(nm, lastpos);
|
||||
if(!ne) continue;
|
||||
asn = X509_NAME_ENTRY_get_data(ne);
|
||||
if(!asn) continue;
|
||||
# ifdef HAVE_ASN1_STRING_GET0_DATA
|
||||
data = ASN1_STRING_get0_data(asn);
|
||||
# else
|
||||
data = ASN1_STRING_data(asn);
|
||||
# endif
|
||||
if(!data) continue;
|
||||
if(ASN1_STRING_length(asn) == (int)strlen(p7signer) &&
|
||||
strncmp((char*)data, p7signer, strlen(p7signer)) == 0)
|
||||
return 1; /* match */
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
#endif /* X509_NAME_GET_TEXT_BY_NID */
|
||||
|
||||
/** get valid signers from the list of signers in the signature */
|
||||
static STACK_OF(X509)*
|
||||
get_valid_signers(PKCS7* p7, const char* p7signer)
|
||||
@@ -1705,6 +1837,9 @@ get_valid_signers(PKCS7* p7, const char* p7signer)
|
||||
return NULL;
|
||||
}
|
||||
for(i=0; i<sk_X509_num(signers); i++) {
|
||||
#if OPENSSL_VERSION_NUMBER >= 0x40000000
|
||||
const
|
||||
#endif
|
||||
X509_NAME* nm = X509_get_subject_name(
|
||||
sk_X509_value(signers, i));
|
||||
char buf[1024];
|
||||
@@ -1717,17 +1852,29 @@ get_valid_signers(PKCS7* p7, const char* p7signer)
|
||||
(int)sizeof(buf));
|
||||
printf("signer %d: Subject: %s\n", i,
|
||||
nmline?nmline:"no subject");
|
||||
#if !defined(HAVE_X509_NAME_GET_TEXT_BY_NID) || defined(DEPRECATED_X509_NAME_GET_TEXT_BY_NID)
|
||||
if(verb >= 3) {
|
||||
print_name_ext(nm, NID_commonName,
|
||||
"commonName");
|
||||
print_name_ext(nm, NID_pkcs9_emailAddress,
|
||||
"emailAddress");
|
||||
}
|
||||
#else
|
||||
if(verb >= 3 && X509_NAME_get_text_by_NID(nm,
|
||||
NID_commonName, buf, (int)sizeof(buf)))
|
||||
NID_commonName, buf, (int)sizeof(buf)) > 0)
|
||||
printf("commonName: %s\n", buf);
|
||||
if(verb >= 3 && X509_NAME_get_text_by_NID(nm,
|
||||
NID_pkcs9_emailAddress, buf, (int)sizeof(buf)))
|
||||
NID_pkcs9_emailAddress, buf, (int)sizeof(buf)) > 0)
|
||||
printf("emailAddress: %s\n", buf);
|
||||
#endif
|
||||
}
|
||||
if(verb) {
|
||||
int ku_loc = X509_get_ext_by_NID(
|
||||
sk_X509_value(signers, i), NID_key_usage, -1);
|
||||
if(verb >= 3 && ku_loc >= 0) {
|
||||
#if OPENSSL_VERSION_NUMBER >= 0x40000000
|
||||
const
|
||||
#endif
|
||||
X509_EXTENSION *ex = X509_get_ext(
|
||||
sk_X509_value(signers, i), ku_loc);
|
||||
if(ex) {
|
||||
@@ -1741,16 +1888,23 @@ get_valid_signers(PKCS7* p7, const char* p7signer)
|
||||
/* there is no name to check, return all records */
|
||||
if(verb) printf("did not check commonName of signer\n");
|
||||
} else {
|
||||
if(!X509_NAME_get_text_by_NID(nm,
|
||||
#if !defined(HAVE_X509_NAME_GET_TEXT_BY_NID) || defined(DEPRECATED_X509_NAME_GET_TEXT_BY_NID)
|
||||
if(!has_valid_emailaddr(nm, p7signer)) {
|
||||
if(verb) printf("removed cert with wrong emailaddress\n");
|
||||
continue; /* wrong name, skip it */
|
||||
}
|
||||
#else
|
||||
if(X509_NAME_get_text_by_NID(nm,
|
||||
NID_pkcs9_emailAddress,
|
||||
buf, (int)sizeof(buf))) {
|
||||
if(verb) printf("removed cert with no name\n");
|
||||
buf, (int)sizeof(buf)) <= 0) {
|
||||
if(verb) printf("removed cert with no emailaddress\n");
|
||||
continue; /* no name, no use */
|
||||
}
|
||||
if(strcmp(buf, p7signer) != 0) {
|
||||
if(verb) printf("removed cert with wrong name\n");
|
||||
if(verb) printf("removed cert with wrong emailaddress\n");
|
||||
continue; /* wrong name, skip it */
|
||||
}
|
||||
#endif
|
||||
}
|
||||
|
||||
/* check that the key usage allows digital signatures
|
||||
|
||||
@@ -73,6 +73,9 @@
|
||||
#ifdef HAVE_GLOB_H
|
||||
#include <glob.h>
|
||||
#endif
|
||||
#ifdef HAVE_FNMATCH_H
|
||||
#include <fnmatch.h>
|
||||
#endif
|
||||
#ifdef WITH_PYTHONMODULE
|
||||
#include "pythonmod/pythonmod.h"
|
||||
#endif
|
||||
@@ -728,6 +731,122 @@ check_modules_exist(const char* module_conf)
|
||||
}
|
||||
}
|
||||
|
||||
#ifdef USE_IPSECMOD
|
||||
/** Compare filename with string, true if it matches the name. */
|
||||
static int
|
||||
file_string_matches(char* str, char* fname, struct config_file* cfg)
|
||||
{
|
||||
char* f;
|
||||
if(!str || str[0] == 0)
|
||||
return 0;
|
||||
/* compare name after chroot and working dir are applied */
|
||||
f = fname_after_chroot(str, cfg, 1);
|
||||
if(!f) fatal_exit("out of memory");
|
||||
if(strcmp(fname, f) == 0) {
|
||||
free(f);
|
||||
return 1;
|
||||
}
|
||||
free(f);
|
||||
return 0;
|
||||
}
|
||||
#endif /* USE_IPSECMOD */
|
||||
|
||||
/** Compare filename with list of files, true if list contains the name. */
|
||||
static int
|
||||
file_list_contains(struct config_strlist* list, char* fname,
|
||||
struct config_file* cfg)
|
||||
{
|
||||
struct config_strlist* s;
|
||||
char* f;
|
||||
for(s = list; s; s = s->next) {
|
||||
if(!s->str || s->str[0] == 0)
|
||||
continue; /* skip if no file name */
|
||||
/* compare names after chroot and working dir are applied */
|
||||
f = fname_after_chroot(s->str, cfg, 1);
|
||||
if(!f) fatal_exit("out of memory");
|
||||
if(strcmp(fname, f) == 0) {
|
||||
free(f);
|
||||
return 1;
|
||||
}
|
||||
free(f);
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
/** Compare filename with list of files, true if list contains the name,
|
||||
* with glob compare. */
|
||||
static int
|
||||
file_list_contains_wild(struct config_strlist* list, char* fname,
|
||||
struct config_file* cfg)
|
||||
{
|
||||
struct config_strlist* s;
|
||||
char* f;
|
||||
for(s = list; s; s = s->next) {
|
||||
if(!s->str || s->str[0] == 0)
|
||||
continue; /* skip if no file name */
|
||||
/* compare names after chroot and working dir are applied */
|
||||
f = fname_after_chroot(s->str, cfg, 1);
|
||||
if(!f) fatal_exit("out of memory");
|
||||
if(strcmp(fname, f) == 0) {
|
||||
free(f);
|
||||
return 1;
|
||||
}
|
||||
#ifdef HAVE_FNMATCH
|
||||
if(fnmatch(f, fname, 0) == 0) {
|
||||
log_err("trusted-keys-file: \"%s\" matches zonefile '%s'",
|
||||
s->str, fname);
|
||||
free(f);
|
||||
return 1;
|
||||
}
|
||||
#endif
|
||||
free(f);
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
/** Check if the auth-zone/rpz zonefile: conflicts with other files,
|
||||
* so it would overwrite that file. Refuse it aliasing any read-side bootstrap
|
||||
* file. */
|
||||
static void
|
||||
check_file_clobber(struct config_file* cfg)
|
||||
{
|
||||
struct config_auth* p;
|
||||
char* zfile, *sourceopt = NULL;
|
||||
for(p = cfg->auths; p; p = p->next) {
|
||||
if(!p->name || p->name[0] == 0)
|
||||
continue; /* skip if no name */
|
||||
if(!p->zonefile || p->zonefile[0]==0)
|
||||
continue; /* no zone file */
|
||||
zfile = fname_after_chroot(p->zonefile, cfg, 1);
|
||||
if(!zfile) fatal_exit("out of memory");
|
||||
if(file_list_contains(cfg->auto_trust_anchor_file_list, zfile,
|
||||
cfg))
|
||||
sourceopt = "auto-trust-anchor-file";
|
||||
else if(file_list_contains(cfg->trust_anchor_file_list, zfile,
|
||||
cfg))
|
||||
sourceopt = "trust-anchor-file";
|
||||
else if(file_list_contains_wild(cfg->trusted_keys_file_list,
|
||||
zfile, cfg))
|
||||
sourceopt = "trusted-keys-file";
|
||||
else if(file_list_contains(cfg->root_hints, zfile, cfg))
|
||||
sourceopt = "root-hints";
|
||||
else if(file_list_contains(cfg->tls_session_ticket_keys.first,
|
||||
zfile, cfg))
|
||||
sourceopt = "tls-session-ticket-keys";
|
||||
#ifdef USE_IPSECMOD
|
||||
if(cfg->ipsecmod_enabled &&
|
||||
file_string_matches(cfg->ipsecmod_hook, zfile, cfg))
|
||||
sourceopt = "ipsecmod-hook";
|
||||
#endif
|
||||
if(sourceopt)
|
||||
fatal_exit("auth-zone '%s': zonefile \"%s\" "
|
||||
"is the same path as a %s option. "
|
||||
"The auth-zone transfer would overwrite it.",
|
||||
p->name, p->zonefile, sourceopt);
|
||||
free(zfile);
|
||||
}
|
||||
}
|
||||
|
||||
/** check configuration for errors */
|
||||
static void
|
||||
morechecks(struct config_file* cfg)
|
||||
@@ -822,6 +941,7 @@ morechecks(struct config_file* cfg)
|
||||
cfg->chrootdir, cfg);
|
||||
}
|
||||
#endif
|
||||
check_file_clobber(cfg);
|
||||
/* remove chroot setting so that modules are not stripping pathnames */
|
||||
free(cfg->chrootdir);
|
||||
cfg->chrootdir = NULL;
|
||||
|
||||
@@ -43,6 +43,7 @@
|
||||
#include "config.h"
|
||||
#include "libunbound/context.h"
|
||||
#include "libunbound/worker.h"
|
||||
#include "libunbound/remote.h"
|
||||
#include "util/fptr_wlist.h"
|
||||
#include "util/log.h"
|
||||
#include "services/mesh.h"
|
||||
@@ -102,7 +103,7 @@ struct outbound_entry* worker_send_query(
|
||||
socklen_t ATTR_UNUSED(addrlen), uint8_t* ATTR_UNUSED(zone),
|
||||
size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream), int ATTR_UNUSED(ssl_upstream),
|
||||
char* ATTR_UNUSED(tls_auth_name), struct module_qstate* ATTR_UNUSED(q),
|
||||
int* ATTR_UNUSED(was_ratelimited))
|
||||
int* ATTR_UNUSED(was_ratelimited), int* ATTR_UNUSED(ratelimit_incremented))
|
||||
{
|
||||
log_assert(0);
|
||||
return 0;
|
||||
@@ -142,7 +143,7 @@ struct outbound_entry* libworker_send_query(
|
||||
socklen_t ATTR_UNUSED(addrlen), uint8_t* ATTR_UNUSED(zone),
|
||||
size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream), int ATTR_UNUSED(ssl_upstream),
|
||||
char* ATTR_UNUSED(tls_auth_name), struct module_qstate* ATTR_UNUSED(q),
|
||||
int* ATTR_UNUSED(was_ratelimited))
|
||||
int* ATTR_UNUSED(was_ratelimited), int* ATTR_UNUSED(ratelimit_incremented))
|
||||
{
|
||||
log_assert(0);
|
||||
return 0;
|
||||
|
||||
+12
-3
@@ -146,7 +146,9 @@ submit_query(struct http2_session* h2_session, struct sldns_buffer* buf)
|
||||
{
|
||||
int32_t stream_id;
|
||||
struct http2_stream* h2_stream;
|
||||
nghttp2_nv headers[5];
|
||||
nghttp2_nv headers[6];
|
||||
size_t num_headers = 5;
|
||||
char clen[16];
|
||||
char* qb64;
|
||||
size_t qb64_size;
|
||||
size_t qb64_expected_size;
|
||||
@@ -194,9 +196,16 @@ submit_query(struct http2_session* h2_session, struct sldns_buffer* buf)
|
||||
headers[3].value = (uint8_t*)h2_session->authority;
|
||||
headers[4].name = (uint8_t*)"content-type";
|
||||
headers[4].value = (uint8_t*)h2_session->content_type;
|
||||
if(h2_session->post) {
|
||||
snprintf(clen, sizeof(clen), "%u",
|
||||
(unsigned)sldns_buffer_remaining(buf));
|
||||
headers[5].name = (uint8_t*)"content-length";
|
||||
headers[5].value = (uint8_t*)clen;
|
||||
num_headers = 6;
|
||||
}
|
||||
|
||||
printf("Request headers\n");
|
||||
for(i=0; i<sizeof(headers)/sizeof(headers[0]); i++) {
|
||||
for(i=0; i<num_headers; i++) {
|
||||
headers[i].namelen = strlen((char*)headers[i].name);
|
||||
headers[i].valuelen = strlen((char*)headers[i].value);
|
||||
headers[i].flags = NGHTTP2_NV_FLAG_NONE;
|
||||
@@ -204,7 +213,7 @@ submit_query(struct http2_session* h2_session, struct sldns_buffer* buf)
|
||||
}
|
||||
|
||||
stream_id = nghttp2_submit_request(h2_session->session, NULL, headers,
|
||||
sizeof(headers)/sizeof(headers[0]),
|
||||
num_headers,
|
||||
(h2_session->post) ? &data_prd : NULL, h2_stream);
|
||||
if(stream_id < 0) {
|
||||
printf("Failed to submit nghttp2 request");
|
||||
|
||||
+10
-5
@@ -1137,8 +1137,11 @@ static struct ngtcp2_conn* conn_client_setup(struct doq_client_data* data)
|
||||
client_chosen_version, &cbs, &settings, ¶ms,
|
||||
NULL, /* ngtcp2_mem allocator, use default */
|
||||
data /* callback argument */);
|
||||
if(!conn) fatal_exit("could not ngtcp2_conn_client_new: %s",
|
||||
ngtcp2_strerror(rv));
|
||||
if(rv!=0) {
|
||||
conn = NULL;
|
||||
fatal_exit("could not ngtcp2_conn_client_new: %s",
|
||||
ngtcp2_strerror(rv));
|
||||
}
|
||||
data->cc_algo = settings.cc_algo;
|
||||
return conn;
|
||||
}
|
||||
@@ -2098,7 +2101,7 @@ early_data_setup_session(struct doq_client_data* data)
|
||||
SSL_SESSION_free(session);
|
||||
return 0;
|
||||
}
|
||||
#ifdef USE_NGTCP2_CRYPTO_OSSL
|
||||
#ifdef HAVE_SSL_SET_QUIC_TLS_EARLY_DATA_ENABLED
|
||||
SSL_set_quic_tls_early_data_enabled(data->ssl, 1);
|
||||
#else
|
||||
SSL_set_quic_early_data_enabled(data->ssl, 1);
|
||||
@@ -2595,7 +2598,8 @@ struct outbound_entry* worker_send_query(
|
||||
socklen_t ATTR_UNUSED(addrlen), uint8_t* ATTR_UNUSED(zone),
|
||||
size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream),
|
||||
int ATTR_UNUSED(ssl_upstream), char* ATTR_UNUSED(tls_auth_name),
|
||||
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited))
|
||||
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited),
|
||||
int* ATTR_UNUSED(ratelimit_incremented))
|
||||
{
|
||||
log_assert(0);
|
||||
return 0;
|
||||
@@ -2629,7 +2633,8 @@ struct outbound_entry* libworker_send_query(
|
||||
socklen_t ATTR_UNUSED(addrlen), uint8_t* ATTR_UNUSED(zone),
|
||||
size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream),
|
||||
int ATTR_UNUSED(ssl_upstream), char* ATTR_UNUSED(tls_auth_name),
|
||||
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited))
|
||||
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited),
|
||||
int* ATTR_UNUSED(ratelimit_incremented))
|
||||
{
|
||||
log_assert(0);
|
||||
return 0;
|
||||
|
||||
@@ -1276,7 +1276,8 @@ struct serviced_query* outnet_serviced_query(struct outside_network* outnet,
|
||||
socklen_t addrlen, uint8_t* zone, size_t zonelen,
|
||||
struct module_qstate* qstate, comm_point_callback_type* callback,
|
||||
void* callback_arg, sldns_buffer* ATTR_UNUSED(buff),
|
||||
struct module_env* env, int* ATTR_UNUSED(was_ratelimited))
|
||||
struct module_env* env, int* ATTR_UNUSED(was_ratelimited),
|
||||
int* ATTR_UNUSED(ratelimit_incremented))
|
||||
{
|
||||
struct replay_runtime* runtime = (struct replay_runtime*)outnet->base;
|
||||
struct fake_pending* pend = (struct fake_pending*)calloc(1,
|
||||
|
||||
@@ -1027,6 +1027,38 @@ authzone_query_test(void)
|
||||
check_queries("example.com", zone_example_com, example_com_queries);
|
||||
}
|
||||
|
||||
/** Test chunkline_count_parens output */
|
||||
static void
|
||||
authzone_chunkline_count_parens_test(void)
|
||||
{
|
||||
sldns_buffer* buf;
|
||||
if(vbmp) printf("Testing chunkline_count_parens\n");
|
||||
buf = sldns_buffer_new(1024);
|
||||
if(!buf) fatal_exit("out of memory");
|
||||
|
||||
/* Check that escaped characters are handled, '\x', and in quotes. */
|
||||
sldns_buffer_printf(buf, "TXT \"x\" \\(");
|
||||
unit_assert(chunkline_count_parens(buf, 0) == 0);
|
||||
|
||||
sldns_buffer_clear(buf);
|
||||
sldns_buffer_printf(buf, "TXT ';x' (");
|
||||
unit_assert(chunkline_count_parens(buf, 0) == 0);
|
||||
|
||||
sldns_buffer_clear(buf);
|
||||
sldns_buffer_printf(buf, "TXT \"a;b\" (");
|
||||
unit_assert(chunkline_count_parens(buf, 0) == 1);
|
||||
|
||||
sldns_buffer_clear(buf);
|
||||
sldns_buffer_printf(buf, "TXT \\) )");
|
||||
unit_assert(chunkline_count_parens(buf, 0) == -1);
|
||||
|
||||
sldns_buffer_clear(buf);
|
||||
sldns_buffer_printf(buf, "TXT \"a\\\\\" \"(\" ");
|
||||
unit_assert(chunkline_count_parens(buf, 0) == 0);
|
||||
|
||||
sldns_buffer_free(buf);
|
||||
}
|
||||
|
||||
/** test authzone code */
|
||||
void
|
||||
authzone_test(void)
|
||||
@@ -1036,4 +1068,5 @@ authzone_test(void)
|
||||
authzone_compare_serial();
|
||||
authzone_read_test();
|
||||
authzone_query_test();
|
||||
authzone_chunkline_count_parens_test();
|
||||
}
|
||||
|
||||
@@ -141,6 +141,7 @@ static addrlen_t randomkey(addrkey_t **k, int maxlen)
|
||||
int bits = rand() % maxlen;
|
||||
int bytes = bits/8 + (bits%8>0); /*ceil*/
|
||||
*k = (addrkey_t *) malloc(bytes * sizeof(addrkey_t));
|
||||
if(!*k) fatal_exit("out of memory");
|
||||
for (byte = 0; byte < bytes; byte++) {
|
||||
(*k)[byte] = (addrkey_t)(rand() & 0xFF);
|
||||
}
|
||||
|
||||
@@ -279,10 +279,24 @@ b64_test(void)
|
||||
unit_assert(result == -1);
|
||||
}
|
||||
|
||||
/** test SVCB ech svcparam */
|
||||
static void
|
||||
svcb_ech_test(void)
|
||||
{
|
||||
uint8_t rr[LDNS_RR_BUF_SIZE];
|
||||
size_t rr_len = sizeof(rr), dname_len = 0;
|
||||
int e = sldns_str2wire_rr_buf("x. 300 IN HTTPS 1 . ech=0",
|
||||
rr, &rr_len, &dname_len, 300, NULL, 0, NULL, 0);
|
||||
unit_assert(e == LDNS_WIREPARSE_ERR_OK);
|
||||
unit_assert(rr_len == dname_len + 10 /* type,class,ttl,rdatalen */ + 7 /* rdata */);
|
||||
unit_assert(sldns_read_uint16(rr + dname_len + 8 /* rdlen */) == 7);
|
||||
}
|
||||
|
||||
void
|
||||
ldns_test(void)
|
||||
{
|
||||
unit_show_feature("sldns");
|
||||
rr_tests();
|
||||
b64_test();
|
||||
svcb_ech_test();
|
||||
}
|
||||
|
||||
@@ -1337,6 +1337,89 @@ static void mesh_test(void)
|
||||
free(c1);
|
||||
}
|
||||
|
||||
#include "util/data/packed_rrset.h"
|
||||
#include "sldns/sbuffer.h"
|
||||
/** packed_rrset unit tests */
|
||||
static void packed_rrset_test(void)
|
||||
{
|
||||
/* packed_rr_to_string assembles the dname, type, class, ttl and
|
||||
* rdata of one rr into a buffer of 65535 bytes. Check that it
|
||||
* refuses an rr that does not fit in there, also when the caller
|
||||
* passes a dest_len that is larger than that, like the callers in
|
||||
* daemon/cachedump.c and daemon/remote.c do. Without the check it
|
||||
* writes past the end of the assembly buffer. */
|
||||
uint8_t smalldname[] = "\003www\007example\003com";
|
||||
uint8_t smallrdata[] = {0, 4, 1, 2, 3, 4};
|
||||
uint8_t maxdname[LDNS_MAX_DOMAINLEN];
|
||||
struct ub_packed_rrset_key rrk;
|
||||
struct packed_rrset_data d;
|
||||
uint8_t* rr_data[1];
|
||||
size_t rr_len[1];
|
||||
time_t rr_ttl[1];
|
||||
size_t dest_len = 65535*4+2048; /* the size daemon/cachedump.c uses */
|
||||
char* dest = (char*)malloc(dest_len);
|
||||
int i;
|
||||
|
||||
unit_show_func("util/data/packed_rrset.c", "packed_rr_to_string");
|
||||
if(!dest) fatal_exit("out of memory");
|
||||
memset(&rrk, 0, sizeof(rrk));
|
||||
memset(&d, 0, sizeof(d));
|
||||
rrk.entry.data = &d;
|
||||
rrk.rk.rrset_class = htons(LDNS_RR_CLASS_IN);
|
||||
d.count = 1;
|
||||
d.rr_len = rr_len;
|
||||
d.rr_ttl = rr_ttl;
|
||||
d.rr_data = rr_data;
|
||||
rr_ttl[0] = 3600;
|
||||
|
||||
/* an ordinary rr is printed, also with the large dest_len */
|
||||
rrk.rk.dname = smalldname;
|
||||
rrk.rk.dname_len = sizeof(smalldname);
|
||||
rrk.rk.type = htons(LDNS_RR_TYPE_A);
|
||||
rr_data[0] = smallrdata;
|
||||
rr_len[0] = sizeof(smallrdata);
|
||||
unit_assert(packed_rr_to_string(&rrk, 0, 0, dest, dest_len) == 1);
|
||||
unit_assert(strstr(dest, "1.2.3.4") != NULL);
|
||||
|
||||
/* a dname of the maximum length, 127 labels of one character */
|
||||
for(i=0; i<127; i++) {
|
||||
maxdname[i*2] = 1;
|
||||
maxdname[i*2+1] = (uint8_t)'a';
|
||||
}
|
||||
maxdname[254] = 0;
|
||||
rrk.rk.dname = maxdname;
|
||||
rrk.rk.dname_len = sizeof(maxdname);
|
||||
rrk.rk.type = htons(LDNS_RR_TYPE_TXT);
|
||||
|
||||
/* 255+2+2+4+65272 is exactly 65535, that still fits */
|
||||
rr_len[0] = 65535 - 255 - 8;
|
||||
rr_data[0] = (uint8_t*)calloc(1, rr_len[0]);
|
||||
if(!rr_data[0]) fatal_exit("out of memory");
|
||||
sldns_write_uint16(rr_data[0], (uint16_t)(rr_len[0]-2));
|
||||
unit_assert(packed_rr_to_string(&rrk, 0, 0, dest, dest_len) == 1);
|
||||
free(rr_data[0]);
|
||||
|
||||
/* one more byte of rdata does not fit and must be refused */
|
||||
rr_len[0] = 65535 - 255 - 8 + 1;
|
||||
rr_data[0] = (uint8_t*)calloc(1, rr_len[0]);
|
||||
if(!rr_data[0]) fatal_exit("out of memory");
|
||||
sldns_write_uint16(rr_data[0], (uint16_t)(rr_len[0]-2));
|
||||
unit_assert(packed_rr_to_string(&rrk, 0, 0, dest, dest_len) == 0);
|
||||
unit_assert(dest[0] == 0);
|
||||
free(rr_data[0]);
|
||||
|
||||
/* the largest rdata an rr can hold, well over the buffer */
|
||||
rr_len[0] = 2 + 65535;
|
||||
rr_data[0] = (uint8_t*)calloc(1, rr_len[0]);
|
||||
if(!rr_data[0]) fatal_exit("out of memory");
|
||||
sldns_write_uint16(rr_data[0], 65535);
|
||||
unit_assert(packed_rr_to_string(&rrk, 0, 0, dest, dest_len) == 0);
|
||||
unit_assert(dest[0] == 0);
|
||||
free(rr_data[0]);
|
||||
|
||||
free(dest);
|
||||
}
|
||||
|
||||
void unit_show_func(const char* file, const char* func)
|
||||
{
|
||||
printf("test %s:%s\n", file, func);
|
||||
@@ -1409,6 +1492,7 @@ main(int argc, char* argv[])
|
||||
zonemd_test();
|
||||
tcpreuse_test();
|
||||
msgparse_test();
|
||||
packed_rrset_test();
|
||||
edns_ede_answer_encode_test();
|
||||
localzone_test();
|
||||
mesh_test();
|
||||
@@ -1445,6 +1529,9 @@ main(int argc, char* argv[])
|
||||
# ifdef HAVE_RAND_CLEANUP
|
||||
RAND_cleanup();
|
||||
# endif
|
||||
#ifdef HAVE_OPENSSL_CLEANUP
|
||||
OPENSSL_cleanup();
|
||||
#endif
|
||||
#elif defined(HAVE_NSS)
|
||||
if(NSS_Shutdown() != SECSuccess)
|
||||
fatal_exit("could not shutdown NSS");
|
||||
|
||||
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
do-not-query-localhost: no
|
||||
fake-sha1: yes
|
||||
verbosity: 8
|
||||
forward-zone:
|
||||
name: "."
|
||||
forward-addr: "127.0.0.1@@TOPORT@"
|
||||
|
||||
+3
-1
@@ -35,11 +35,13 @@ function check_insecure() {
|
||||
# test with good start key, and must do 5011 (no URL possible)
|
||||
echo "*** TEST 1 ***"
|
||||
echo $DS > root.key
|
||||
$PRE/unbound-anchor -x "notexist.xml" -s "notexist.p7s" $OPTS
|
||||
cat root.key
|
||||
$PRE/unbound-anchor -x "notexist.xml" -s "notexist.p7s" $OPTS -vvvv
|
||||
if test $? != 0; then
|
||||
echo "Exitcode not OK"
|
||||
exit 1
|
||||
fi
|
||||
cat root.key
|
||||
check_works
|
||||
# save for test 5
|
||||
cp root.key root.key.probed
|
||||
|
||||
Binary file not shown.
Binary file not shown.
+201
@@ -0,0 +1,201 @@
|
||||
#!/bin/sh
|
||||
|
||||
# run in temp dir.
|
||||
# Then for petal, move into basedir.
|
||||
# For test_cert.key and test_cert.pem, rename the output files to that.
|
||||
# And run signit.sh for both signature files, by commenting infile and outfile.
|
||||
# for test_cert.pem it has emailAddress and keyUsage, but petal.pem does not
|
||||
# need that.
|
||||
|
||||
# settings:
|
||||
|
||||
# directory for files
|
||||
DESTDIR=.
|
||||
|
||||
# issuer and subject name for certificates
|
||||
SERVERNAME=petal
|
||||
CLIENTNAME=petal
|
||||
|
||||
# validity period for certificates
|
||||
DAYS=7200
|
||||
|
||||
# size of keys in bits
|
||||
BITS=3072
|
||||
|
||||
# hash algorithm
|
||||
HASH=sha256
|
||||
|
||||
# base name for unbound server keys
|
||||
SVR_BASE=petal
|
||||
|
||||
# base name for unbound-control keys
|
||||
CTL_BASE=petal
|
||||
|
||||
# flag to recreate generated certificates
|
||||
RECREATE=0
|
||||
|
||||
# we want -rw-r----- access (say you run this as root: grp=yes (server), all=no).
|
||||
umask 0027
|
||||
|
||||
# end of options
|
||||
|
||||
set -eu
|
||||
|
||||
cleanup() {
|
||||
echo "removing artifacts"
|
||||
|
||||
rm -rf \
|
||||
server.cnf \
|
||||
client.cnf \
|
||||
"${SVR_BASE}_trust.pem" \
|
||||
"${CTL_BASE}_trust.pem" \
|
||||
"${SVR_BASE}_trust.srl"
|
||||
}
|
||||
|
||||
fatal() {
|
||||
printf "fatal error: $*\n" >/dev/stderr
|
||||
exit 1
|
||||
}
|
||||
|
||||
usage() {
|
||||
cat <<EOF
|
||||
usage: $0 OPTIONS
|
||||
OPTIONS
|
||||
-d <dir> used directory to store keys and certificates (default: $DESTDIR)
|
||||
-h show help notice
|
||||
-r recreate certificates
|
||||
EOF
|
||||
}
|
||||
|
||||
OPTIND=1
|
||||
while getopts 'd:hr' arg; do
|
||||
case "$arg" in
|
||||
d) DESTDIR="$OPTARG" ;;
|
||||
h) usage; exit 1 ;;
|
||||
r) RECREATE=1 ;;
|
||||
?) fatal "'$arg' unknown option" ;;
|
||||
esac
|
||||
done
|
||||
shift $((OPTIND - 1))
|
||||
|
||||
if ! openssl version </dev/null >/dev/null 2>&1; then
|
||||
echo "$0 requires openssl to be installed for keys/certificates generation." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "setup in directory $DESTDIR"
|
||||
cd "$DESTDIR"
|
||||
|
||||
trap cleanup INT
|
||||
|
||||
# ===
|
||||
# Generate server certificate
|
||||
# ===
|
||||
|
||||
# generate private key; do no recreate it if they already exist.
|
||||
if [ ! -f "$SVR_BASE.key" ]; then
|
||||
openssl genrsa -out "$SVR_BASE.key" "$BITS"
|
||||
fi
|
||||
|
||||
cat >server.cnf <<EOF
|
||||
[req]
|
||||
default_bits=$BITS
|
||||
default_md=$HASH
|
||||
prompt=no
|
||||
distinguished_name=req_distinguished_name
|
||||
x509_extensions=v3_ca
|
||||
[req_distinguished_name]
|
||||
commonName=$SERVERNAME
|
||||
emailAddress=$SERVERNAME
|
||||
[v3_ca]
|
||||
subjectKeyIdentifier=hash
|
||||
authorityKeyIdentifier=keyid:always,issuer:always
|
||||
basicConstraints=critical,CA:TRUE,pathlen:0
|
||||
subjectAltName=DNS:$SERVERNAME
|
||||
keyUsage = digitalSignature, keyCertSign
|
||||
EOF
|
||||
|
||||
[ -f server.cnf ] || fatal "cannot create openssl configuration"
|
||||
|
||||
if [ ! -f "$SVR_BASE.pem" -o $RECREATE -eq 1 ]; then
|
||||
openssl req \
|
||||
-new -x509 \
|
||||
-key "$SVR_BASE.key" \
|
||||
-config server.cnf \
|
||||
-days "$DAYS" \
|
||||
-out "$SVR_BASE.pem"
|
||||
|
||||
[ ! -f "SVR_BASE.pem" ] || fatal "cannot create server certificate"
|
||||
fi
|
||||
|
||||
# ===
|
||||
# Generate client certificate
|
||||
# ===
|
||||
|
||||
# generate private key; do no recreate it if they already exist.
|
||||
if [ ! -f "$CTL_BASE.key" ]; then
|
||||
openssl genrsa -out "$CTL_BASE.key" "$BITS"
|
||||
fi
|
||||
|
||||
cat >client.cnf <<EOF
|
||||
[req]
|
||||
default_bits=$BITS
|
||||
default_md=$HASH
|
||||
prompt=no
|
||||
distinguished_name=req_distinguished_name
|
||||
req_extensions=v3_req
|
||||
[req_distinguished_name]
|
||||
commonName=$CLIENTNAME
|
||||
[v3_req]
|
||||
basicConstraints=critical,CA:FALSE
|
||||
subjectAltName=DNS:$CLIENTNAME
|
||||
EOF
|
||||
|
||||
[ -f client.cnf ] || fatal "cannot create openssl configuration"
|
||||
|
||||
if [ ! -f "$CTL_BASE.pem" -o $RECREATE -eq 1 ]; then
|
||||
openssl x509 \
|
||||
-addtrust serverAuth \
|
||||
-in "$SVR_BASE.pem" \
|
||||
-out "${SVR_BASE}_trust.pem"
|
||||
|
||||
openssl req \
|
||||
-new \
|
||||
-config client.cnf \
|
||||
-key "$CTL_BASE.key" \
|
||||
| openssl x509 \
|
||||
-req \
|
||||
-days "$DAYS" \
|
||||
-CA "${SVR_BASE}_trust.pem" \
|
||||
-CAkey "$SVR_BASE.key" \
|
||||
-CAcreateserial \
|
||||
-$HASH \
|
||||
-extfile client.cnf \
|
||||
-extensions v3_req \
|
||||
-out "$CTL_BASE.pem"
|
||||
|
||||
[ ! -f "CTL_BASE.pem" ] || fatal "cannot create signed client certificate"
|
||||
fi
|
||||
|
||||
# remove unused permissions
|
||||
chmod o-rw \
|
||||
"$SVR_BASE.pem" \
|
||||
"$SVR_BASE.key"
|
||||
chmod g+r,o-rw \
|
||||
"$CTL_BASE.pem" \
|
||||
"$CTL_BASE.key"
|
||||
|
||||
cleanup
|
||||
|
||||
echo "Setup success. Certificates created. Enable in unbound.conf file to use"
|
||||
|
||||
# create trusted usage pem
|
||||
# openssl x509 -in $CTL_BASE.pem -addtrust clientAuth -out $CTL_BASE"_trust.pem"
|
||||
|
||||
# see details with openssl x509 -noout -text < $SVR_BASE.pem
|
||||
# echo "create $CTL_BASE""_browser.pfx (web client certificate)"
|
||||
# echo "create webbrowser PKCS#12 .PFX certificate file. In Firefox import in:"
|
||||
# echo "preferences - advanced - encryption - view certificates - your certs"
|
||||
# echo "empty password is used, simply click OK on the password dialog box."
|
||||
# openssl pkcs12 -export -in $CTL_BASE"_trust.pem" -inkey $CTL_BASE.key -name "unbound remote control client cert" -out $CTL_BASE"_browser.pfx" -password "pass:" || error "could not create browser certificate"
|
||||
|
||||
+40
-21
@@ -1,21 +1,40 @@
|
||||
-----BEGIN RSA PRIVATE KEY-----
|
||||
MIIDfQIBAAKBwQC1xQ/Kca6zszZbcCtdOTIH2Uy2gOy/DfabMUU7TmNPm0dVE0NJ
|
||||
RuN+Rm304SonpwghfP2/ULZNnuDgpG03/32yI7k/VzG6iA4hiF7tT/KAAWC/+2l1
|
||||
QCsawCV2bSrFK0VhcZr7ALqXd8vkDaQ867K029ypjOQtAJ85qdO3mERy7TGtdUcu
|
||||
O6hLeVet419YeQ2F8cfNxn63d7bOzNGLPW5xwaCd3UcgD+Ib0k4xfFvbinvPQUeU
|
||||
J/i4YDWexFYSL+ECAwEAAQKBwCLXXQl+9O+5AEhSnd1Go1Jh0pSA7eBJOuXQcebG
|
||||
Rb7ykp+6C4G2NtDziwwPRNdI6wQQQ0sym18RfyVQHydGr78/nbiIbB3HCn5e92Mh
|
||||
mefzW6ow9Kvm2txLzGKA1lvoyRbNm81jnG/eygi3u7Nqd5PNv+4dHj2RkTlmxOeh
|
||||
qnDMVP5md8uZPv6lYNnrnIzvLCR5vnPNdVwn89AqzI85IcDZdy0R9ZX4NBbsDgAU
|
||||
6ig6uXuRXvSGiyJ/OUXSrnogaQJhAOjvkHUhVZQkPOxO90TNH4j0GdKKtbSWxIdz
|
||||
lKfuJeBAEqs0TL+C6vbS81Xw3W1alyDdUBk3rJMOBqW6Ryq5HNL+j5H+Jfsh7fvc
|
||||
Yle+5wHGci0P9zCFZCrY8It7n9XFIwJhAMfEi6oJa2G8waPJ1bQhxka82Tf9pnKM
|
||||
XCn/1BBOFjVIx5F842cpA+zp5a62GENTGYPQTTRBB/2/ZwnW5aIkrlg54AtmbqBZ
|
||||
Oh+2kJdJQD/tfoVmc5soUE2ScTHadK5RKwJhAN4w9kjkXS+MSZjX0kIMsBIBVkhh
|
||||
C+aREjJqa9ir7/Ey7RvmLXdYuCxtGLRXp7/R8+rjcK49Tx6O+IRJZe042mfhbq3C
|
||||
EhS1Tr86f4xXix9EXlDhs9bSxrOgcAN9Dv/opQJhAK7eBcPaav0rVfYh/8emqQHS
|
||||
3fJ9Pu6WnzbEksWTFS2ff9KDGCx9YspIFJ5TF/oXDAaumGZdZrlgirm6O1kr8tGY
|
||||
F97i04PZl1+bWAaWQH+1TUNI43m2WFUPE7coG2tb8QJgcddDg9VlXliZqgcETZfJ
|
||||
kJmYETxrcSn3ao6v116N8yxhEgUgjkmsCTiFgx36iDVnXwK6PIt+sIu8MC7eYNa3
|
||||
berrv/M21K0LRn20IWRxvUobG070weHCAgkko7fTWgr2
|
||||
-----END RSA PRIVATE KEY-----
|
||||
-----BEGIN PRIVATE KEY-----
|
||||
MIIG/gIBADANBgkqhkiG9w0BAQEFAASCBugwggbkAgEAAoIBgQDiNGqbEmyFI9QF
|
||||
EvWcU36irjzp1W+VMuMHGD5PDYy5ib1QIrUcUQPvWydV4er/6gnpv6VQ+dfOeVlr
|
||||
Acu73kdh+N0u5UgjIY9CJnoN12eEGjTrVFlHoA2Ur/TMbN3DW20Nbyi5LUJ8KrGl
|
||||
Yg8tPbLqGvfJsIYTspBEzgQcJg5ZTD3YA2ZESrbZe2sOunri0j1myv+EoTqB4nPb
|
||||
ShHx8i11IJpUoBEoHoSyMQgEgYJqbmqCHaTGJWNxHUUhI5MmTPEzyrG6T0B3v5Pb
|
||||
y1eFOyAU+I4SCs0fqHPg4DbPlNTe/MEBm2LQAVrUFjcFx+Cq75oOa9sVp6xvBmYN
|
||||
nMiwGgLJYjN7l0lhRQEtao6tEGQUYbmpKoLQJMsKs6bjs6HK5TXMzQUfHATirmjE
|
||||
C1Fcb/eKJ27HNiKS+uw2g9Tpu/af2qKl3ePNUioPbMYtgGhu5csD22heGeilNVtN
|
||||
8D47kU0SveXjokV476CecW0SZnN9rVrvd0IqtnU9fMoAQyZE6ScCAwEAAQKCAYAk
|
||||
0//fS3qbmp+0S8ftMbLWbaPBNly6X9SSnSHX4Q7eTkyiNWRjPdV0LNUUqHmIPORs
|
||||
SCV0L5kxJpSmVV6EMcZRbyEjt3StM5ONY5JPmphh65peDheTD73mTVd/yOG6IrJ4
|
||||
k3Z/35yJdrIBiRuLdBYjA00Aa1sI7fOLIDePFasUYtNWzgbia3+lnPBrL3U+ZJhW
|
||||
mgpL36wU5XeTZlXRnGpGPY6i5ISmkYFtOYpioWtIRL3WfVkMYZ31FpzgrlgQzknQ
|
||||
lrKN2g7/3q0uLlbasgCsAK50hL2f2xxzsALDCGFjDJbwdIZKfdoxRbgS0L7q7gj0
|
||||
SUK4fc1obR5qHc2lTuCSzPpionq022ElC0DChupiosyXN4GxNZ2Dwoln4Y5s2YXo
|
||||
+VTtyYbVEib15WbhHorvfg0QUO00Nwqu+LVTVUXueNre2n507fSiOhCIpbPUWDGz
|
||||
RoeRFEP0T9+mzQgXr56TAiYunIat1qVxXrwaSWSXEfInGUTkdRUC4rctv7KJ1nEC
|
||||
gcEA8jDTh1OLBG3/JkQxQNOoqFUFssPlJ+z3LcyaNT6bM5lH5Vwn3sGOFWOMLILD
|
||||
f/qbGG/1VPVfoCEY1NEkYsocOMtkLIJrIdtD5DOnWz1JJE7Zh2AoWWfIfXd9v5sh
|
||||
m1fB3SVa6D9JtGoDnKttMl25Tqf6YehVo35Axxar74k3kC/vuZrp/81iZscdRsyK
|
||||
kQh9fPXl4Oqw2cUYdx3L8UprLS4JguvR0zXvbukJ75DjLZELvjnxBbA1vdtyQz58
|
||||
2uk1AoHBAO8aP5h08kwTIJCXS6uyAJ0F8F/30srAtchSpzsC3YEEs/Z+43D7W1RR
|
||||
Obw4KhVjjmFeh83U8pdEuUEjv3ua52+uoUCqTywe+o180owiWsTDSXVtDHiUD7bu
|
||||
x+nRnpk3flZD28GHKLdWMmJvd8DzMgsa9fJIucMYT7xQHzxCW+4nhhBckX9LEH7i
|
||||
Jo6MaVuh8b6NuZXOBgU3cp20GTZ3SwRNkKOigctQVZT4A1Vf4ioLrVyhv/LVLBC+
|
||||
UvoIu82wawKBwQDakMXU8sgaj0ocNp5caqdigphJ5BACIBBR/LuOIZnezw3bJ3ez
|
||||
x+l51ATEhp33+SnOu/sjWO2bjULjjHrRzKP7fVJB+NDGFSMH5rW52W0Qnzggu96u
|
||||
EMMWt6d8K3wAvQnvka6gubzCXIo18V7yfTKmkWGcyhe/HElJYmR4H9VNAnXNgsh6
|
||||
Wdfb+QWqxxymFotpImD6wdIoNX8GwJU0hHyEoW9j/320ppAV/6k/0fmzPZrjaVbi
|
||||
U0uss0ZC+TmkNaECgcB9L6gGYYyOyiDts1k6LvtlOzvMc0uZPmau2J+YJPrmVxkG
|
||||
QQ9CE0iRD+oDowBdrH9aeYzu9sSA8Mlx0o6p38O21J625bSILDwQoj72gfI2PO0U
|
||||
HyE9bIABzmk7AbZhEA4Eiojffa2St/2vTh9MFcioydfln7Aq9mqg9O41taS+P1FQ
|
||||
9bZ0CFA9rphzYA61nEee9kMprPG3/3zyFt5whuru+NF261m7onb8hRHxvD8EtpJx
|
||||
AnsmX/gvWAbHxJTXr7sCgcEAp6QAysy0/sgRYvzBkqv05kz4xBqy2a4ZKjnMLEWY
|
||||
7MicZiQrkSsEjMNDy20rjXfZbhDJWGVjBOZ1QsYehKhGAIoORXID9B3aZ32m//VU
|
||||
IUxkLcrIPLPmfdzZvlRPnQc/TAZNe41BGBa4WlDwTFE9TdpVtTzjW1ac5yBN7sa+
|
||||
V7YbBSiOhP+NuqQFQM01aaZCmOetcj70B4SwJVzswhITS0O+7ZAvicGJiQKTUvUY
|
||||
ijWm+Luu3QYDc2HBMwUAmHT5
|
||||
-----END PRIVATE KEY-----
|
||||
|
||||
+23
-12
@@ -1,14 +1,25 @@
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIICFzCCAUACCQDO660L5y5LGDANBgkqhkiG9w0BAQUFADAQMQ4wDAYDVQQDEwVw
|
||||
ZXRhbDAeFw0xMDA5MzAxMzQzMDFaFw0zMDA2MTcxMzQzMDFaMBAxDjAMBgNVBAMT
|
||||
BXBldGFsMIHfMA0GCSqGSIb3DQEBAQUAA4HNADCByQKBwQC1xQ/Kca6zszZbcCtd
|
||||
OTIH2Uy2gOy/DfabMUU7TmNPm0dVE0NJRuN+Rm304SonpwghfP2/ULZNnuDgpG03
|
||||
/32yI7k/VzG6iA4hiF7tT/KAAWC/+2l1QCsawCV2bSrFK0VhcZr7ALqXd8vkDaQ8
|
||||
67K029ypjOQtAJ85qdO3mERy7TGtdUcuO6hLeVet419YeQ2F8cfNxn63d7bOzNGL
|
||||
PW5xwaCd3UcgD+Ib0k4xfFvbinvPQUeUJ/i4YDWexFYSL+ECAwEAATANBgkqhkiG
|
||||
9w0BAQUFAAOBwQBBkX9KDP2RXbg+xPmdJ4P6CwvA5x1LZwC++ydVx4NlvT0pWicD
|
||||
ZUnXjcWAJlkeOuUBAqFG7WHTrXpUUAjmdqFVq2yFjteUYBdrFz0RDB2jM9feeKYO
|
||||
mTgxdZyT9a6humxCxt5VfgT02axLjm/2AqCyFPMbf4PASoJDln01AEuZLZ8Xl2gV
|
||||
bYHMnHTGoD1Hu6FNEzRgkMC6XT8X3YjHvzQhpc/qL5wEfEsinQGdX4twsuWbf8xd
|
||||
q7miNnkO8vd0maw=
|
||||
MIIERDCCAqygAwIBAgIUY5FZe4tAZd0ITNbceavVGLvEe2QwDQYJKoZIhvcNAQEL
|
||||
BQAwEDEOMAwGA1UEAwwFcGV0YWwwHhcNMjYwNzI0MDkwNTMyWhcNNDYwNDEwMDkw
|
||||
NTMyWjAQMQ4wDAYDVQQDDAVwZXRhbDCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCC
|
||||
AYoCggGBAOI0apsSbIUj1AUS9ZxTfqKuPOnVb5Uy4wcYPk8NjLmJvVAitRxRA+9b
|
||||
J1Xh6v/qCem/pVD51855WWsBy7veR2H43S7lSCMhj0Imeg3XZ4QaNOtUWUegDZSv
|
||||
9Mxs3cNbbQ1vKLktQnwqsaViDy09suoa98mwhhOykETOBBwmDllMPdgDZkRKttl7
|
||||
aw66euLSPWbK/4ShOoHic9tKEfHyLXUgmlSgESgehLIxCASBgmpuaoIdpMYlY3Ed
|
||||
RSEjkyZM8TPKsbpPQHe/k9vLV4U7IBT4jhIKzR+oc+DgNs+U1N78wQGbYtABWtQW
|
||||
NwXH4Krvmg5r2xWnrG8GZg2cyLAaAsliM3uXSWFFAS1qjq0QZBRhuakqgtAkywqz
|
||||
puOzocrlNczNBR8cBOKuaMQLUVxv94onbsc2IpL67DaD1Om79p/aoqXd481SKg9s
|
||||
xi2AaG7lywPbaF4Z6KU1W03wPjuRTRK95eOiRXjvoJ5xbRJmc32tWu93Qiq2dT18
|
||||
ygBDJkTpJwIDAQABo4GVMIGSMB0GA1UdDgQWBBSLQ6cvFrU2JiedggRXjiUemV3h
|
||||
QzBLBgNVHSMERDBCgBSLQ6cvFrU2JiedggRXjiUemV3hQ6EUpBIwEDEOMAwGA1UE
|
||||
AwwFcGV0YWyCFGORWXuLQGXdCEzW3Hmr1Ri7xHtkMBIGA1UdEwEB/wQIMAYBAf8C
|
||||
AQAwEAYDVR0RBAkwB4IFcGV0YWwwDQYJKoZIhvcNAQELBQADggGBANj5PXClrk76
|
||||
UddT6aniB/VbErfu1MwfyYSGhE4y5VVJVyD+wHYECswdm2IIo/v/4I+4KWgAcGPk
|
||||
u+j1B2iXN8sQTe500+KMSRFfaxdbwlX42+oDKwRoz8pwMzETyZYQA4PAE5j2rnjb
|
||||
n9USomWzvwavo7GRE6VauBcSAekrNFDjPw43tElmr2TTz4lUFXlvBlQvcbloJ4OU
|
||||
60ek8d1erlsLXzAtf4kCFH1aiII0g0fA448gnIOIgT9LiV88smKNDPVqusw9TBd5
|
||||
/f1R8ETy7jcIJ9TU34dy6S39s4aUjWUAZMV1TIH3wJPDsE6+1yD5OC5b50akIwpJ
|
||||
jO9naDRvgaHIWxJRcREXd+H7IlybL+l+Qq4L4RX583cdL/rZEWdnESgbDq7EkEPn
|
||||
ZbpjdM4oNGUlXsrZw0/GFgzYlN2MBFiLht6y2iBbhFxPb2SM3Xx/M5YnsNLym+I/
|
||||
m9mck/aeeSEyJ2uIfFfVndfPfqmKxwvoPu0OCv/ppsi+xTvhE6B/UQ==
|
||||
-----END CERTIFICATE-----
|
||||
|
||||
+40
-21
@@ -1,21 +1,40 @@
|
||||
-----BEGIN RSA PRIVATE KEY-----
|
||||
MIIDfAIBAAKBwQC48GhhmIU66TZKc3QiyF4L5bsm8Aly/y2SzLP+GACepK0OcOtD
|
||||
i2sXrTtoJDvGOPZ9ICqmIy8u/Q/cK26txNEeZFcClLcYF/U+NaqjEwrwkHEIgc3g
|
||||
8qnKrhzM61I8foAWVT7cqxFHDKYuClNITXk1i//Yzpnf9wvVKQ51W9UOtm/WA7g4
|
||||
IDHCuAjocyyNC3B7XqYawFDOsdMI4ZW7hC0hIRQOvBkvbvY8WxmsSkdd30u1KmoI
|
||||
Sg4y6OvnikrEEQkCAwEAAQKBwQC3hQlv37RF82sGkm8qnP6Ge+AuEYCu9v44cJ4k
|
||||
hZkH1I5OiEtN6anKAwOyolIWsCwZmrP3zW5jCIiWiRr5oReLOzMEwqK2a//XTdYY
|
||||
oSr38b3ZHUY59VP8Zq75woMGuNed35kAmGxzDRP1gI/TmvTvaHlqYyvxBtxnZJij
|
||||
Za1CrT+a9JvR6hI8xXrE33CF0T6JO1v3v0HeBuve5+83cCHKo+GyqIBjL3FJgefZ
|
||||
EsPz6rGnPDKTYgMyaljFV3LI5ikCYQDlaBnyiWk1C7tYO5x3CRoHoiuiiREZCncK
|
||||
QkSxjiDoSP0rc+3BQp2kG3yy6S9mN4qMQPELEtBa6bORogxNK+Pxg8TRI/+xgeFt
|
||||
bod5Bd4pfl6Y5hXm21JwELFlOzPI3PMCYQDOYK6Z7vegiOJyyAJXMjcI07H8S0Gr
|
||||
SZW8f4tHRzO+RrRpR5ANzarELX7nF/Qj5mPXiZNiiMDGocxqkNzIa5HFLOqBhRkv
|
||||
o7yC1Cj582dUBFHyEbsZxR6UMTPLdE3UaRMCYACC1Nv3dmaJ2ib+KwEQ4h/2Ooao
|
||||
K4OUxGMfdqu2l1gtIXNBVNxDW7qL3SFA57wgj4x0cJUHu7MYJjBC3igl2uIk2wFk
|
||||
RSOOGIR35JFec/o/r9JDYPUcs/hP8TU6hokCBQJgHbH/rZqa+vh3TPjGjXFmRdjg
|
||||
JWNWwaTG7OaVTd5K7bgSwYtQiQvs5Gl/dxUVRg0ilKLxGB6BTpN9bGAHxLbltK9v
|
||||
1s8l/praxyBr/PsvBQHSILi4aU7ZxY0G3OGRSV0NAmBx28Msdgc0yHh3qSkbwVEr
|
||||
gr7av1iOH73ee+o4CmMWXYUBHOMW5Su0s0QHjNGDMiRiRoCvzYqdLcJj9/sFJxOT
|
||||
CM35WGGeKDMNubX7C6YroQ91q7kUmhi7HHY3QOyhCDU=
|
||||
-----END RSA PRIVATE KEY-----
|
||||
-----BEGIN PRIVATE KEY-----
|
||||
MIIG/gIBADANBgkqhkiG9w0BAQEFAASCBugwggbkAgEAAoIBgQC7Tr0JP6gVKA2Z
|
||||
wtpcBmd27WquMfhdfePva0mV6oc+eE+py2gwHBUAVhMnnYAwT/7ziC0a7pel43tS
|
||||
NSHgr0oSUZJC2x+gYMKZ341Q+qNFUJTTv+hG41uKwGfcx02+0HuVU1A9m60PNtE2
|
||||
oc83Au8RwyPgcuzWwk3hmX6XUrZmz0vrUxbniLF9xl0gWeFFFWVeioItYDVAKxtl
|
||||
Ufrb5/9ju3mzfnEtWWEl+qfraA8DFA10BZRVUBKNB7aGc8KDRBwC4yQBHtIu8ob1
|
||||
9DGNe2lYnMCHPFR3dsCHjBYbuGf+J66uAxtMu0IygwI3inNtBUTnQ/QVv2fQNJc2
|
||||
vL9ic1BHSwi5byPld3igVCc35wmKLgKX0WtQKcuxI1BwYfaMK+jTZl6mQcE4AuMk
|
||||
tvhWbbLn7UQxNAe6X2JKM/M7ds1dIjyfL6nuB1yESX+FiRpjOMuRV1BwrPLJNOfl
|
||||
C9QkIRgoy1C9WxZUcigeDAApooDls4H/Q16tWdHj8toQWvYKVqMCAwEAAQKCAYBF
|
||||
/w+/pA1BEr26Z0nIuA/0Lpb+T+g7r+79Kr/OCV3PJ5DFqCDgUa47eO8hj8c2xr5E
|
||||
7e/FL8J2GMOeHgLx/y+UFu2slEyGV4KBlDwwNenL3mgvlXjM/OvZtztZExXnp+t3
|
||||
CzJiQ4nxtI+Mdf2E1lDW93Cx0ODXBLesBft7u0o0s2TwpRVbIwcJNJbanxwDABLo
|
||||
uKQbJuffefx76Z3wjgsvjwDU5fyPcOZQFhKoczOg995rLCaZlxnHoElCh4H6Ifod
|
||||
K9LQAERjLicBtSThAuO+0us353y3dJ6lY3iYsi2u69UBcvFSepzKjFsx/FPv8B8N
|
||||
QMmwpfEZvB4ODM7VvZkvmQZcN3HHopRJWVFWkTkCX5A0RXCXO+AaQV+AVJWnGCxj
|
||||
dyV6L1qBK/HsyOto9KGIHN1VFj+n4hTthNPWkDE7CkA7gAMomNvmlf6zNOrbwzro
|
||||
LznDK7OQC5Qqoge0R+u/l2xgqzIl8hl5jtmwhi6kT47HBBQ1dBKa6M4rNIFRr9EC
|
||||
gcEA9CTQHdAax7XcoeETto/TMKKfv0QyfIivscr250/87GNjzsKCK2MxHZ50jmtF
|
||||
7Q7iYhepRuvhbvF9h4BwK7fUbi/KQAW4qiVxqi+MfQkoVYdvnLgekhdmnrThqWmf
|
||||
p4ZTZ0tBe29m713WdozHZv6nNcyIrt0JXrVvIFDDpil/6ETHa+y6OMiePc8gklDD
|
||||
VVCwKpq+F+taFBzfgqNHkdnaMlP/I/35KEQyhV07aLJhR1leExoGkmc7eaK6WqVD
|
||||
iQqZAoHBAMRnVukeUNiSPZmC3IyyfD8iMXnjyPmb/+a9LmwaVOs4yjdBUmGTx+ZV
|
||||
mnDb94d3ijyshysbjCc8ebZ7FxuXoaIJ7JWYOgTeMJs1JOAoEVsHBtd1W/RpQ8Hr
|
||||
NegSwP4cmCzXAQOtenZnCC2QveHlngxk7rUiayj7G4awrJLtyW9Z9WAUokm810Nq
|
||||
muUXhHxRobc40H65+qyCuPODKz3wO4Lt5VaYd4vR+wkUFc0IghmRX0HVlVe/q9gA
|
||||
JgXwRPfMmwKBwDWRzkh8XSPs95hddqHcNQ664CproFhK9aIhUsO2fVyxAjlf3IgA
|
||||
n8pL9m85goJdfbbgUjhJkZFyU4Tj3bj6ARacTdh2aOqMhMA+5qiY1czOhuLwU2Ti
|
||||
1ZWFQu6VSn7Lrok/rgKTkxZ6lJA2m5oxziaz1lnoDiJF1ThWAFf5SyN/0/IOY14K
|
||||
Rw5w4Ei6h+G0brMqeQNulLlNDI3xncaW8pWQcK9JDt6S+DLjHiH+4fFx3n56e26s
|
||||
UBSEbDdvg74SIQKBwQCrCRM2j5/3+eKK/Nrz67snf692Zlduh9uiJL14hrXM4fe3
|
||||
hrsnHnrGq2WDQwucfQ11KQnNEIBM6u1TbH4DGVk4s0vEOnzMIHJTt0QVsM7sZoIe
|
||||
v6UEg2buSNb48tv+bwhWhCXt/fTXh4InrBSv1DZ+tKbsNrz7QzIFaXXfvhPdVInK
|
||||
0i1B6aHMo9mgB4roeG5MEL4AnhUehfhql5/goIQy0NkXQE9bA9GJZmRV2ULy4RYD
|
||||
TuxvLguIXxi9sy9cXGECgcEA2MCZvKU9hml/4n1/dEiNvSGEA9rz92Vzsb50yeRM
|
||||
3yLTaYe5koVNbag+IpqpCNP4T2xNnWIxv7ceqB78wxWykadF0z5T5I+/HBPYWLms
|
||||
mpQPr7grVqcX5gqxJoUwWwxvKLwh5KjqjRX43turXOWlsSHMVNH6KMLt1K3OtArs
|
||||
OMROcUcXBJc2hvr+YBeHOpIC1ZlawIr5BRi2FICN7TeIiE3h7VFY0ucAyOOKvfH9
|
||||
FzIeEhSTR60ZN1HtILhRJmjG
|
||||
-----END PRIVATE KEY-----
|
||||
|
||||
+25
-13
@@ -1,15 +1,27 @@
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIICWTCCAYKgAwIBAgIJAN5YIkuCvJf5MA0GCSqGSIb3DQEBBQUAMCYxDjAMBgNV
|
||||
BAMTBXBldGFsMRQwEgYJKoZIhvcNAQkBFgVwZXRhbDAeFw0xMzAxMTcxMTUyNDVa
|
||||
Fw0zMjEwMDQxMTUyNDVaMCYxDjAMBgNVBAMTBXBldGFsMRQwEgYJKoZIhvcNAQkB
|
||||
FgVwZXRhbDCB3zANBgkqhkiG9w0BAQEFAAOBzQAwgckCgcEAuPBoYZiFOuk2SnN0
|
||||
IsheC+W7JvAJcv8tksyz/hgAnqStDnDrQ4trF607aCQ7xjj2fSAqpiMvLv0P3Ctu
|
||||
rcTRHmRXApS3GBf1PjWqoxMK8JBxCIHN4PKpyq4czOtSPH6AFlU+3KsRRwymLgpT
|
||||
SE15NYv/2M6Z3/cL1SkOdVvVDrZv1gO4OCAxwrgI6HMsjQtwe16mGsBQzrHTCOGV
|
||||
u4QtISEUDrwZL272PFsZrEpHXd9LtSpqCEoOMujr54pKxBEJAgMBAAGjDzANMAsG
|
||||
A1UdDwQEAwIChDANBgkqhkiG9w0BAQUFAAOBwQCaA3ys5hDPMNV1oXIxH6u2KfAX
|
||||
C9tYJId/SR0x8whsZuNaSEZAgImdM5dnyWdjey8Pio772E9/F2aUBGFkdadZx4My
|
||||
d7hBfEi/NECEKs86k9g0ijbin41NKtnajb6GwyNQ9vDx7Z5FS8BZ3CD0BZIdCQUE
|
||||
gKuDSWBROQU3tqrjdk2QTwGQkj2mgzT871Jn1MwZw0mczPjS1y469Ejym8wi3uCd
|
||||
EboDOoGBCpmUQbxBv6JI75cUCdmNNEwjQjZ0XQw=
|
||||
MIIEkzCCAvugAwIBAgIUSAvgFLH//MkCJQDFBcJfyjrVJYswDQYJKoZIhvcNAQEL
|
||||
BQAwJjEOMAwGA1UEAwwFcGV0YWwxFDASBgkqhkiG9w0BCQEWBXBldGFsMB4XDTI2
|
||||
MDcyNDA5NDEyNloXDTQ2MDQxMDA5NDEyNlowJjEOMAwGA1UEAwwFcGV0YWwxFDAS
|
||||
BgkqhkiG9w0BCQEWBXBldGFsMIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKC
|
||||
AYEAu069CT+oFSgNmcLaXAZndu1qrjH4XX3j72tJleqHPnhPqctoMBwVAFYTJ52A
|
||||
ME/+84gtGu6XpeN7UjUh4K9KElGSQtsfoGDCmd+NUPqjRVCU07/oRuNbisBn3MdN
|
||||
vtB7lVNQPZutDzbRNqHPNwLvEcMj4HLs1sJN4Zl+l1K2Zs9L61MW54ixfcZdIFnh
|
||||
RRVlXoqCLWA1QCsbZVH62+f/Y7t5s35xLVlhJfqn62gPAxQNdAWUVVASjQe2hnPC
|
||||
g0QcAuMkAR7SLvKG9fQxjXtpWJzAhzxUd3bAh4wWG7hn/ieurgMbTLtCMoMCN4pz
|
||||
bQVE50P0Fb9n0DSXNry/YnNQR0sIuW8j5Xd4oFQnN+cJii4Cl9FrUCnLsSNQcGH2
|
||||
jCvo02ZepkHBOALjJLb4Vm2y5+1EMTQHul9iSjPzO3bNXSI8ny+p7gdchEl/hYka
|
||||
YzjLkVdQcKzyyTTn5QvUJCEYKMtQvVsWVHIoHgwAKaKA5bOB/0NerVnR4/LaEFr2
|
||||
ClajAgMBAAGjgbgwgbUwHQYDVR0OBBYEFHTJazw63SRJUbZ3slMXV9O9L7JIMGEG
|
||||
A1UdIwRaMFiAFHTJazw63SRJUbZ3slMXV9O9L7JIoSqkKDAmMQ4wDAYDVQQDDAVw
|
||||
ZXRhbDEUMBIGCSqGSIb3DQEJARYFcGV0YWyCFEgL4BSx//zJAiUAxQXCX8o61SWL
|
||||
MBIGA1UdEwEB/wQIMAYBAf8CAQAwEAYDVR0RBAkwB4IFcGV0YWwwCwYDVR0PBAQD
|
||||
AgKEMA0GCSqGSIb3DQEBCwUAA4IBgQBYyONVmgUv8mpGTp2U+12e715VDGQLRNEu
|
||||
TjGBgpVF4Vebw8E+L++Fzbd0iJVq0o1WzcM3SxdgPr/AZCqgbzHeRx3ZmE/7QNtF
|
||||
w+IvOU35VQAYlA3Caz2gYoTLYaCyPF1ZwH7cbviI1pdv1jWotHVYbK/hFXHx1GaF
|
||||
as3AHGAr1lGFFrnt0pA3G1VJACGEHOFZRxeDAwnyl9VN/JC8uujaSekA98fzspvk
|
||||
fQYTfOAhR4qd9smwg/af/cgJHcFeMbfLWYmeLa01zMR1NypBOdVJQOXCn9bBn6xW
|
||||
Niwa9JitzJaK0hRccdOEerw0UI/5s5xCKIYepn5MZ7RlWfarjBTZbVvyzkMMSFa4
|
||||
qB39pqLTQtxq3KLDpTs76Q+U9UyuQuxuC2kNyPHmpYgCT/2Aaiezx80GMeEL3XCJ
|
||||
L+vmo/3jU6miAXEFZRBCe1z8bwEWb1RiEHh/pVxRbIMRgtGfCQoQwHpZyx9VUWd0
|
||||
ZBYZlQ0Ql1YGPEuEWkobTBppzHsaIX8=
|
||||
-----END CERTIFICATE-----
|
||||
|
||||
@@ -0,0 +1,32 @@
|
||||
server:
|
||||
verbosity: 7
|
||||
# num-threads: 1
|
||||
interface: 127.0.0.1
|
||||
port: @PORT@
|
||||
use-syslog: no
|
||||
directory: ""
|
||||
pidfile: "unbound.pid"
|
||||
chroot: ""
|
||||
username: ""
|
||||
do-not-query-localhost: no
|
||||
use-caps-for-id: no
|
||||
|
||||
auth-zone:
|
||||
name: "example.com"
|
||||
for-upstream: yes
|
||||
for-downstream: yes
|
||||
master: "127.0.0.1@@TOPORT@"
|
||||
max-transfer-size: 512
|
||||
max-transfer-time: 2000
|
||||
auth-zone:
|
||||
name: "example2.com"
|
||||
for-upstream: yes
|
||||
for-downstream: yes
|
||||
master: "127.0.0.1@@TOPORT2@"
|
||||
max-transfer-size: 512
|
||||
max-transfer-time: 2000
|
||||
remote-control:
|
||||
control-enable: yes
|
||||
control-interface: @CONTROL_PATH@/controlpipe.@CONTROL_PID@
|
||||
control-use-cert: no
|
||||
|
||||
@@ -0,0 +1,16 @@
|
||||
BaseName: auth_transfer_limit
|
||||
Version: 1.0
|
||||
Description: Test limit of authority zone transfer.
|
||||
CreationDate: Tue May 12 03:00:00 PM CEST 2026
|
||||
Maintainer: dr. W.C.A. Wijngaards
|
||||
Category:
|
||||
Component:
|
||||
CmdDepends:
|
||||
Depends:
|
||||
Help:
|
||||
Pre: auth_transfer_limit.pre
|
||||
Post: auth_transfer_limit.post
|
||||
Test: auth_transfer_limit.test
|
||||
AuxFiles:
|
||||
Passed:
|
||||
Failure:
|
||||
@@ -0,0 +1,16 @@
|
||||
# #-- auth_transfer_limit.post --#
|
||||
# source the master var file when it's there
|
||||
[ -f ../.tpkg.var.master ] && source ../.tpkg.var.master
|
||||
# source the test var file when it's there
|
||||
[ -f .tpkg.var.test ] && source .tpkg.var.test
|
||||
#
|
||||
# do your teardown here
|
||||
. ../common.sh
|
||||
kill_pid $FWD_PID
|
||||
kill_pid $FWD2_PID
|
||||
kill_pid $UNBOUND_PID
|
||||
rm -f $CONTROL_PATH/controlpipe.$CONTROL_PID
|
||||
echo "> cat logfiles"
|
||||
cat fwd.log
|
||||
cat fwd2.log
|
||||
cat unbound.log
|
||||
@@ -0,0 +1,54 @@
|
||||
# #-- auth_transfer_limit.pre--#
|
||||
# source the master var file when it's there
|
||||
[ -f ../.tpkg.var.master ] && source ../.tpkg.var.master
|
||||
# use .tpkg.var.test for in test variable passing
|
||||
[ -f .tpkg.var.test ] && source .tpkg.var.test
|
||||
|
||||
PRE="../.."
|
||||
. ../common.sh
|
||||
if grep -e "define HAVE_PTHREAD 1" -e "define HAVE_SOLARIS_THREADS 1" -e "define HAVE_WINDOWS_THREADS 1" $PRE/config.h; then
|
||||
TEST_FAST_RELOAD="yes"
|
||||
else
|
||||
TEST_FAST_RELOAD="no"
|
||||
fi
|
||||
echo "TEST_FAST_RELOAD=$TEST_FAST_RELOAD" >> .tpkg.var.test
|
||||
|
||||
get_random_port 3
|
||||
UNBOUND_PORT=$RND_PORT
|
||||
FWD_PORT=$(($RND_PORT + 1))
|
||||
FWD2_PORT=$(($RND_PORT + 2))
|
||||
echo "UNBOUND_PORT=$UNBOUND_PORT" >> .tpkg.var.test
|
||||
echo "FWD_PORT=$FWD_PORT" >> .tpkg.var.test
|
||||
echo "FWD2_PORT=$FWD2_PORT" >> .tpkg.var.test
|
||||
|
||||
# start forwarders
|
||||
get_ldns_testns
|
||||
$LDNS_TESTNS -p $FWD_PORT auth_transfer_limit.testns >fwd.log 2>&1 &
|
||||
FWD_PID=$!
|
||||
echo "FWD_PID=$FWD_PID" >> .tpkg.var.test
|
||||
|
||||
$LDNS_TESTNS -p $FWD2_PORT auth_transfer_limit.testns2 >fwd2.log 2>&1 &
|
||||
FWD2_PID=$!
|
||||
echo "FWD2_PID=$FWD2_PID" >> .tpkg.var.test
|
||||
|
||||
# make config file
|
||||
CONTROL_PATH=/tmp
|
||||
CONTROL_PID=$$
|
||||
sed -e 's/@PORT\@/'$UNBOUND_PORT'/' \
|
||||
-e 's/@TOPORT\@/'$FWD_PORT'/' \
|
||||
-e 's/@TOPORT2\@/'$FWD2_PORT'/' \
|
||||
-e 's?@CONTROL_PATH\@?'$CONTROL_PATH'?' \
|
||||
-e 's/@CONTROL_PID@/'$CONTROL_PID'/' \
|
||||
< auth_transfer_limit.conf > ub.conf
|
||||
# start unbound in the background
|
||||
$PRE/unbound -d -c ub.conf >unbound.log 2>&1 &
|
||||
UNBOUND_PID=$!
|
||||
echo "UNBOUND_PID=$UNBOUND_PID" >> .tpkg.var.test
|
||||
echo "CONTROL_PATH=$CONTROL_PATH" >> .tpkg.var.test
|
||||
echo "CONTROL_PID=$CONTROL_PID" >> .tpkg.var.test
|
||||
|
||||
cat .tpkg.var.test
|
||||
wait_ldns_testns_up fwd.log
|
||||
wait_ldns_testns_up fwd2.log
|
||||
wait_unbound_up unbound.log
|
||||
|
||||
@@ -0,0 +1,100 @@
|
||||
# #-- auth_transfer_limit.test --#
|
||||
# source the master var file when it's there
|
||||
[ -f ../.tpkg.var.master ] && source ../.tpkg.var.master
|
||||
# use .tpkg.var.test for in test variable passing
|
||||
[ -f .tpkg.var.test ] && source .tpkg.var.test
|
||||
|
||||
PRE="../.."
|
||||
. ../common.sh
|
||||
# do the test
|
||||
|
||||
teststep "wait for unbound to transfer"
|
||||
sleep 3
|
||||
|
||||
teststep "check log for max-transfer-size"
|
||||
if grep "auth zone example.com. transfer.*exceeded 512 bytes" unbound.log; then
|
||||
echo "OK"
|
||||
else
|
||||
echo "Not OK"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
teststep "check log for max-transfer-time"
|
||||
if grep "auth zone example2.com. transfer.*exceeded 2000 msec" unbound.log; then
|
||||
echo "OK"
|
||||
else
|
||||
echo "Not OK"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if test "$TEST_FAST_RELOAD" == "yes"; then
|
||||
teststep "Testing with fast_reload"
|
||||
cp ub.conf ub.conf.old
|
||||
sed -e 's/max-transfer-size: 512/max-transfer-size: 500/' -e 's/max-transfer-time: 2000/max-transfer-time: 1000/' < ub.conf.old > ub.conf
|
||||
|
||||
teststep "unbound-control status"
|
||||
$PRE/unbound-control -c ub.conf status
|
||||
if test $? -ne 0; then
|
||||
echo "wrong exit value."
|
||||
exit 1
|
||||
else
|
||||
echo "exit value: OK"
|
||||
fi
|
||||
|
||||
teststep "unbound-control fast_reload +vvdp"
|
||||
$PRE/unbound-control -c ub.conf fast_reload +vvdp 2>&1 | tee output
|
||||
if test $? -ne 0; then
|
||||
echo "wrong exit value."
|
||||
exit 1
|
||||
else
|
||||
echo "exit value: OK"
|
||||
fi
|
||||
wait_logfile unbound.log "start fast reload thread" 60
|
||||
wait_logfile unbound.log "stop fast reload thread" 60
|
||||
wait_logfile unbound.log "joined with fastreload thread" 60
|
||||
|
||||
if grep "ok" output; then
|
||||
echo "OK"
|
||||
else
|
||||
echo "output not correct"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
teststep "wait for unbound to transfer"
|
||||
sleep 3
|
||||
|
||||
$PRE/unbound-control -c ub.conf auth_zone_transfer example.com 2>&1
|
||||
if test $? -ne 0; then
|
||||
echo "wrong exit value."
|
||||
exit 1
|
||||
else
|
||||
echo "exit value: OK"
|
||||
fi
|
||||
$PRE/unbound-control -c ub.conf auth_zone_transfer example2.com 2>&1
|
||||
if test $? -ne 0; then
|
||||
echo "wrong exit value."
|
||||
exit 1
|
||||
else
|
||||
echo "exit value: OK"
|
||||
fi
|
||||
teststep "wait for unbound to transfer"
|
||||
sleep 3
|
||||
|
||||
teststep "check log for max-transfer-size"
|
||||
if grep "auth zone example.com. transfer.*exceeded 500 bytes" unbound.log; then
|
||||
echo "OK"
|
||||
else
|
||||
echo "Not OK"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
teststep "check log for max-transfer-time"
|
||||
if grep "auth zone example2.com. transfer.*exceeded 1000 msec" unbound.log; then
|
||||
echo "OK"
|
||||
else
|
||||
echo "Not OK"
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
|
||||
exit 0
|
||||
@@ -0,0 +1,38 @@
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN SOA
|
||||
SECTION ANSWER
|
||||
example.com. IN SOA ns.example.com. hostmaster.example.com. 1 3600 900 86400 3600
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN AXFR
|
||||
SECTION ANSWER
|
||||
example.com. IN SOA ns.example.com. hostmaster.example.com. 1 3600 900 86400 3600
|
||||
example.com. IN NS ns.example.net.
|
||||
; too big!
|
||||
EXTRA_PACKET
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN AXFR
|
||||
SECTION ANSWER
|
||||
large01.example.com. IN TXT "123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789"
|
||||
large02.example.com. IN TXT "123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789"
|
||||
large03.example.com. IN TXT "123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789"
|
||||
large04.example.com. IN TXT "123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789"
|
||||
large05.example.com. IN TXT "123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789 123456789"
|
||||
EXTRA_PACKET
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN AXFR
|
||||
SECTION ANSWER
|
||||
www.example.com. IN A 1.2.3.4
|
||||
example.com. IN SOA ns.example.com. hostmaster.example.com. 1 3600 900 86400 3600
|
||||
ENTRY_END
|
||||
@@ -0,0 +1,35 @@
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
example2.com. IN SOA
|
||||
SECTION ANSWER
|
||||
example2.com. IN SOA ns.example2.com. hostmaster.example2.com. 1 3600 900 86400 3600
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
example2.com. IN AXFR
|
||||
SECTION ANSWER
|
||||
example2.com. IN SOA ns.example2.com. hostmaster.example2.com. 1 3600 900 86400 3600
|
||||
example2.com. IN NS ns.example2.net.
|
||||
EXTRA_PACKET
|
||||
REPLY QR AA NOERROR
|
||||
; too slow
|
||||
ADJUST packet_sleep=3
|
||||
SECTION QUESTION
|
||||
example2.com. IN AXFR
|
||||
SECTION ANSWER
|
||||
extra.example2.com. IN A 1.2.3.5
|
||||
EXTRA_PACKET
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
example2.com. IN AXFR
|
||||
SECTION ANSWER
|
||||
www.example2.com. IN A 1.2.3.4
|
||||
example2.com. IN SOA ns.example2.com. hostmaster.example2.com. 1 3600 900 86400 3600
|
||||
ENTRY_END
|
||||
Vendored
+294
@@ -0,0 +1,294 @@
|
||||
; config options
|
||||
server:
|
||||
trust-anchor: "example.net. 3600 IN DS 29332 8 2 fe9d2d1f797b8dbe717febca0b7ff2125e0bdc819eb529008aad5630e61d4d99"
|
||||
val-override-date: "20201020135527"
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
fake-sha1: yes
|
||||
trust-anchor-signaling: no
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: no
|
||||
|
||||
auth-zone:
|
||||
name: "example.com."
|
||||
master: ns.example.net.
|
||||
for-downstream: yes
|
||||
for-upstream: yes
|
||||
## fallback-enabled: no
|
||||
## this line generates zonefile: \n"/tmp/xxx.example.com"\n
|
||||
zonefile:
|
||||
TEMPFILE_NAME example.com
|
||||
## this is the inline file /tmp/xxx.example.com
|
||||
## the tempfiles are deleted when the testrun is over.
|
||||
TEMPFILE_CONTENTS example.com
|
||||
TEMPFILE_END
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test authority zone with bogus host name lookup
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode subdomain
|
||||
ADJUST copy_id copy_query
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
com. IN NS
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode subdomain
|
||||
ADJUST copy_id copy_query
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.net. IN A
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
example.net. IN NS ns2.example.net.
|
||||
SECTION ADDITIONAL
|
||||
ns2.example.net. IN A 1.2.3.45
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
com. IN NS
|
||||
SECTION ANSWER
|
||||
com. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode subdomain
|
||||
ADJUST copy_id copy_query
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN NS
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.44
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.44
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN NS
|
||||
SECTION ANSWER
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.44
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
ns.example.com. IN A
|
||||
SECTION ANSWER
|
||||
ns.example.com. IN A 1.2.3.44
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
ns.example.com. IN AAAA
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
www.example.com. IN A 1.2.3.44
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN NS
|
||||
SECTION ANSWER
|
||||
example.com. IN NS ns.example.com.
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN A 10.20.30.40
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN SOA
|
||||
SECTION ANSWER
|
||||
; serial, refresh, retry, expire, minimum
|
||||
example.com. IN SOA ns.example.com. hostmaster.example.com. 1 3600 900 86400 3600
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN AXFR
|
||||
SECTION ANSWER
|
||||
example.com. IN SOA ns.example.com. hostmaster.example.com. 1 3600 900 86400 3600
|
||||
example.com. IN NS ns.example.com.
|
||||
www.example.com. IN A 1.2.3.4
|
||||
example.com. IN SOA ns.example.com. hostmaster.example.com. 1 3600 900 86400 3600
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns2.example.net
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.45
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns2.example.net. IN A
|
||||
SECTION ANSWER
|
||||
ns2.example.net. 3600 IN A 1.2.3.45
|
||||
ns2.example.net. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 29332 example.net. ttH0qGYFJp0zfoqb6h9cDGhkosucRPI64gd3+i7gwAcbOtfGJhHR7+NQ7uH+gRRv4lzPEiWP6zM7IiSeC1o+gW/Y2u6J1a330KzikT1YxIWGQJ825NU3PJ5ifTC8IgrN8HFwBuof3K4x/ftdA9VRcyCbFicazOD4RLlbhffMpoVQKyRa/NqHT8mSWLPry9q9skgdyRk17f65i0sdSCEyCXv8+vX6vBxaMF3in+zQxvnA9nyB4omwLLJZx3jaF0+lSiBcx3u20DTbCC/cyjxJArhLlv1N5U3GRUpFXl1d7k0FmacQCP4H5UXSzy6vf6XoQwtfIgNzwYgFN5RuCdJ71w==
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns2.example.net. IN AAAA
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
example.net. 3600 IN SOA ns.example.com. root.example.com. 4 14400 3600 604800 3600
|
||||
example.net. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 29332 example.net. OWDPS0sJQOhZlqKUbdL8OVwT0u1e1asbjW+9dMRxIF/VoxxRaYIqD/lsn1U+irRrbIPDp9wxDdFu7ChddB1n2/do/by9xuIMLD00mkxSJduxMjRl/8hWvhBV6j8jqU0pbsxS3Oolcju8imrobEqqCDi1YVD6OQuBzwnQ7trF9mfANv208pDA4chWXWUimFETKzpc3aLarcm3qVnb53AQhggyLow/ZLG1egbwaGn3pcf+kPHw+G4MSOR1TtS0mWKiPgdYRiqSS+AqrZUu/ZuAKAGweKeIypDgm6RZC5M4FmRA+f8gZg2rI2Xog6TLt0qrjD8ARwXkyBq8wL3G0Ihkew==
|
||||
ns2.example.net. 3600 IN NSEC ns3.example.net. A RRSIG NSEC
|
||||
ns2.example.net. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 29332 example.net. MMDdm3yz6Ocreg8HE7Cf9EnIJ5NFCVzEv+I9zBeUR90pFBlrBY4LqmMxC5GXoEEc1iql5XpPkIspsWTkCUSWutoiDh4Vlg54HrZ4ONy8GzVzg5ePcuXT51nYq1xjfDx4Yi124GT/QKx4+B7HFoyFfoRT1Kf+uP3c7F7qK+VB3FrBBQpl7f6dX87qO23Bb+Vp+L0RPCmuLkhdnrM34bB6jT1lGwgsD4upDy81XKSH6uces8D/fvl0+Evzcy3gkKlxY6uzV53cUD0FM9AVg7/ZWXwQe5n7PIU9gzQ3xtnH5MA8fG6iUyVQJixjqzEqjJdh2PMJA31qTT2X6LQO95ZM2w==
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
example.net. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.net. 3600 IN DNSKEY 257 3 8 AwEAAb4WMOTBLTFvmBra5m6SK4VfViOzmvyUAU0qv861ZQXeEFvwlndqNU9rwRsMxrSWAYs5nHErKDn49usC/HyxxW1477iGFHhfgL4mjNreJm9zft2QFB1VLbRbEPYdDMLCn4co0qnG7/KG8W2i8Pym1L7f+aREwbLo+/716AS2PbaKMhfWLKLiq5wnBcUClQMNzCiwhqxDJp1oePqfkVdeUgXOtgi0dYRIKyQFhJ5VWJ22npoi/Gif0XLCADAlAwRLKc8o/yJkCxskzgpHpw5Cki1lclg0aq4ssOuPRQ+ne6IHYCz9D2mwzulblhLFamKdq7aHzNt4NlyxhpANVFiKLD8= ;{id = 29332 (ksk), size = 2048b}
|
||||
example.net. 3600 IN RRSIG DNSKEY 8 2 3600 20201116135527 20201019135527 29332 example.net. a0AqvyBN1Dr1Try1RBjbWjhaaTj3WGpSBywSxLu09bElAFinC3kUgk/WTjfsIIxruUHmzVgPssYeb5g79rdaz7YanSi06LQsnEjMS+hexSU6TXBCtJnhA8taKPlPj+qBRQL/Ptju72upty6Mw8eMG05QOQOa2WC5mPLgo2k6PmgsBMyW3Rhn+lldlmz1NZIZ3udDHs6xxX6Gjio67ogGm0MUbWRZo68oGt/xYv6JzZAVzZROlWvs5D+pf1Mrfzn3yOMJ0jh2XTXJAiw3vX+i2k/P/Yfscm7BWULJ7fBx+0JcDuYccd2mj9ijmD7KuM/laFSIUvxAixu7gV2TDrKEjw==
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.example.net. IN A
|
||||
SECTION ANSWER
|
||||
ns.example.net. IN A 1.2.3.44
|
||||
; bad RRSIG
|
||||
ns.example.net. 3600 IN RRSIG A 8 2 3600 20201116135527 20201019135527 29332 example.net. a0AqvyBN1Dr1Try1RBjbWjhaaTj3WGpSBywSxLu09bElAFinC3kUgk/WTjfsIIxruUHmzVgPssYeb5g79rdaz7YanSi06LQsnEjMS+hexSU6TXBCtJnhA8taKPlPj+qBRQL/Ptju72upty6Mw8eMG05QOQOa2WC5mPLgo2k6PmgsBMyW3Rhn+lldlmz1NZIZ3udDHs6xxX6Gjio67ogGm0MUbWRZo68oGt/xYv6JzZAVzZROlWvs5D+pf1Mrfzn3yOMJ0jh2XTXJAiw3vX+i2k/P/Yfscm7BWULJ7fBx+0JcDuYccd2mj9ijmD7KuM/laFSIUvxAixu7gV2TDrKEjw==
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.example.net. IN AAAA
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
example.net. 3600 IN SOA ns.example.com. root.example.com. 4 14400 3600 604800 3600
|
||||
example.net. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 29332 example.net. OWDPS0sJQOhZlqKUbdL8OVwT0u1e1asbjW+9dMRxIF/VoxxRaYIqD/lsn1U+irRrbIPDp9wxDdFu7ChddB1n2/do/by9xuIMLD00mkxSJduxMjRl/8hWvhBV6j8jqU0pbsxS3Oolcju8imrobEqqCDi1YVD6OQuBzwnQ7trF9mfANv208pDA4chWXWUimFETKzpc3aLarcm3qVnb53AQhggyLow/ZLG1egbwaGn3pcf+kPHw+G4MSOR1TtS0mWKiPgdYRiqSS+AqrZUu/ZuAKAGweKeIypDgm6RZC5M4FmRA+f8gZg2rI2Xog6TLt0qrjD8ARwXkyBq8wL3G0Ihkew==
|
||||
ns.example.net. 3600 IN NSEC ns2.example.net. A RRSIG NSEC
|
||||
ns.example.net. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 29332 example.net. bwmn1nX0amfcIK6+NXdX7i3VvebPGpVLd0Ry0P+5JbiLCO3lI8kbXxpQh2jpIAKAdfSq+WZPGAhwOSOTVak1mEcYf5xLvmiKWmGz0LH8RTCzQTAlcQTnuybmQWuwBjIXaetVQ1ADiJZK57M41d5lOE0KqWe5xfAHE+UhMOQ6JhQwLFK/QfQJB7ke1itM/qfsJHgdb/rbT7v7G8Nd342NMCZEgzP/wFyZ3JRP0XY5D7K71IuFZd9NfxXkKRMn5UM/lMDITqE3MknzXnsKJcH9SpoykKMya9SsrwI+IuOxpQkyiyd+N33H3di4uWI1MiWdayQnR2D3HhHi1Vdp42CDxQ==
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
; recursion happens here.
|
||||
STEP 20 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR AA RD RA SERVFAIL
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
ENTRY_END
|
||||
|
||||
STEP 30 TIME_PASSES ELAPSE 10
|
||||
STEP 40 TRAFFIC
|
||||
|
||||
STEP 50 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
; The bogus host was not used.
|
||||
STEP 60 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR AA RD RA SERVFAIL
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
ENTRY_END
|
||||
|
||||
; the zonefile was updated with new contents
|
||||
STEP 70 CHECK_TEMPFILE example.com
|
||||
FILE_BEGIN
|
||||
FILE_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+609
@@ -0,0 +1,609 @@
|
||||
; config options
|
||||
; The island of trust is at test.
|
||||
server:
|
||||
trust-anchor: "test. DS 1444 8 2 8a87d067fd09a5965244fe2e317dd26d182c468e0a7f26ecc4c7b479bf89db9b"
|
||||
val-override-date: "20201020135527"
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: no
|
||||
fake-sha1: yes
|
||||
trust-anchor-signaling: no
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
local-zone: test. nodefault
|
||||
log-servfail: yes
|
||||
module-config: "dns64 validator iterator"
|
||||
dns64-prefix: 64:ff9b::0/96
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test DNS64 with DNSSEC validation.
|
||||
; valid.example.test. both AAAA and A are DNSSEC valid
|
||||
; invaaaa.example.test. AAAA is invalid, A is DNSSEC valid
|
||||
; inva.example.test. AAAA is valid, A is DNSSEC invalid
|
||||
; invboth.example.test. AAAA is invalid, A is DNSSEC invalid
|
||||
; hasaaaa.example.test. has an AAAA record.
|
||||
; queries with and without CD flag.
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 300
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode subdomain
|
||||
ADJUST copy_id copy_query
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
test. IN NS
|
||||
SECTION AUTHORITY
|
||||
test. IN NS ns.test.
|
||||
SECTION ADDITIONAL
|
||||
ns.test. IN A 1.2.3.5
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.test
|
||||
RANGE_BEGIN 0 300
|
||||
ADDRESS 1.2.3.5
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
test. IN NS
|
||||
SECTION ANSWER
|
||||
test. IN NS ns.test
|
||||
test. 3600 IN RRSIG NS 8 1 3600 20201116135527 20201019135527 1444 test. RGCxIO32TbbLTk6xZmTr+fjYPH50hntBxeOQ2DIj2pDsmjALcHYtVkOfpfk2EhOhHZd+9PLuoJPbJh6a9NqLSFeBvr0XZoCZoQ2g0tCHUNHcH5EVjA2TuYBQem6DVYnPLJ3914aRx0uA1j42b8dC2xsam/XkOo7U+dLbUW2Os1s=
|
||||
SECTION ADDITIONAL
|
||||
ns.test. IN A 1.2.3.5
|
||||
ns.test. 3600 IN RRSIG A 8 2 3600 20201116135527 20201019135527 1444 test. GskCc4/k6GjH9V9Jz2V5L2XLiizbOeWkB0feSbf+aN859S3vxVvtuqkvIgwY4LafUO1QAn/pUcv9zA7rcFO++rlg+8t6gvZTo9p3v0bfeIv2uJDsfSBD5jDh0WXlxjekfnrKrQp7zE+GiA93tWwKUWKPvxXDgP+n886e6WcbHJw=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.test. IN A
|
||||
SECTION ANSWER
|
||||
ns.test. IN A 1.2.3.5
|
||||
ns.test. 3600 IN RRSIG A 8 2 3600 20201116135527 20201019135527 1444 test. GskCc4/k6GjH9V9Jz2V5L2XLiizbOeWkB0feSbf+aN859S3vxVvtuqkvIgwY4LafUO1QAn/pUcv9zA7rcFO++rlg+8t6gvZTo9p3v0bfeIv2uJDsfSBD5jDh0WXlxjekfnrKrQp7zE+GiA93tWwKUWKPvxXDgP+n886e6WcbHJw=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.test. IN AAAA
|
||||
SECTION AUTHORITY
|
||||
test. 3600 IN SOA ns.test. host.test. 20201 3600 1800 604800 3600
|
||||
test. 3600 IN RRSIG SOA 8 1 3600 20201116135527 20201019135527 1444 test. IZJIDmEgf0W7A5G7hvvZ2hUqJ9Trbv1/i7ySapDmPbYV9lVCmHHobySxO01yDhI2/Pvpsvxqrm1Tiv3BxH8uzZ4keKgiQjBsSy4htAsFct9I4E7ly2glPj/Fm3oun3PsjJDv5QYhx0KS7w4IQKU7Nc9pfJc92uoUI5bdoC1pRGw=
|
||||
ns.test. 3600 IN NSEC nz.test. A RRSIG
|
||||
ns.test. 3600 IN RRSIG NSEC 8 2 3600 20201116135527 20201019135527 1444 test. PElArVB3KPg8KHAP7lzcNbhFuXNxTsHNTn1dZVncB5qmWRdIaeKpaXDjpH0JSXMaelGFS+/QhuQ6Hmw9+4VyZFRqMzGhw4agUR/2bxABHcDIG4ZpUwyeSP61ATTfHUkQVxaH2wjCWI/tfmesdP2xVE4GXyUvCIBxU914MkZbULU=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
test. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
test. 3600 IN DNSKEY 257 3 8 AwEAAbd9WqjzE2Pynz21OG5doSf9hFzMr5dhzz2waZ3vTa+0o5r7AjTAqmA1yH/B3+aAMihUm5ucZSfVqo7+kOaRE8yFj9aivOmA1n1+JLevJq/oyvQyjxQN2Qb89LyaNUT5oKZIiL+uyyhNW3KDR3SSbQ/GBwQNDHVcZi+JDR3RC0r7 ;{id = 1444 (ksk), size = 1024b}
|
||||
test. 3600 IN RRSIG DNSKEY 8 1 3600 20201116135527 20201019135527 1444 test. UmRMS4iG9NBBHZYOtpwFFcJgbEb5SfHSgHd9XRe/8pTWM31WSDayn5ViPOBMqI1T5TXg2amc13dDI574xIM2oKMus3b5cBW72jJLW13jprBtslO6P8BMWb4HNnvLrJtQjwf3ErRirtTxinLmywQtmyr1cdthyG3Gp4N7i90fHSc=
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qname qtype
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
example.test. IN DS
|
||||
SECTION ANSWER
|
||||
example.test. 3600 IN DS 55567 8 2 a2d578906330a10a57d40462257b6ce038bad3f7bf4a45c46c46086e20a94b39
|
||||
example.test. 3600 IN RRSIG DS 8 2 3600 20201116135527 20201019135527 1444 test. P7+FTYW2qHuJ4I1YbuvseEz5X1lOYAraGEHB3C5y0OOCQFmhmSiFRdquNi2NlpcS6FXLdsE0EU+Bo1+0atTG4EkMWXbpF21lrtbB51BdsnlX4Mzc/o375fvjiOMwmF6wPCUaOUN62jrVrhsE/hedaVyDphDToqL17ETohwgUO2I=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode subdomain
|
||||
ADJUST copy_id copy_query
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.test. IN NS
|
||||
SECTION AUTHORITY
|
||||
example.test. IN NS ns.example.test.
|
||||
example.test. 3600 IN DS 55567 8 2 a2d578906330a10a57d40462257b6ce038bad3f7bf4a45c46c46086e20a94b39
|
||||
example.test. 3600 IN RRSIG DS 8 2 3600 20201116135527 20201019135527 1444 test. P7+FTYW2qHuJ4I1YbuvseEz5X1lOYAraGEHB3C5y0OOCQFmhmSiFRdquNi2NlpcS6FXLdsE0EU+Bo1+0atTG4EkMWXbpF21lrtbB51BdsnlX4Mzc/o375fvjiOMwmF6wPCUaOUN62jrVrhsE/hedaVyDphDToqL17ETohwgUO2I=
|
||||
SECTION ADDITIONAL
|
||||
ns.example.test. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.test.
|
||||
RANGE_BEGIN 0 300
|
||||
ADDRESS 1.2.3.4
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.test. IN NS
|
||||
SECTION ANSWER
|
||||
example.test. IN NS ns.example.test.
|
||||
example.test. 3600 IN RRSIG NS 8 2 3600 20201116135527 20201019135527 55567 example.test. l1JT0wMlK0YI7/CWHzexf/k0iafUhCgN+BdgjBXIRXmSQNf4HDTiAkbcWL2/15qtnp12nQy9JeiTdSQ3vtPoHAJX4C5uTWaze4ms+Wrrf+n92sLCjacP9x50uuicH3URT6cKb1QCAPwlvlWxIlZjAMYFScSns7+C441NMJT8aE4=
|
||||
SECTION ADDITIONAL
|
||||
ns.example.test. IN A 1.2.3.4
|
||||
ns.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. 2PWaVaccZFQgfPKXNsdEGYUVaashCAj1ZhBo9XRt5eQKUFvZcauBjMnXIuxZFyWeootn1fZGw6GuPI5W48Y0FDx38H6adprkFgQikso2Y64jDdDMWznSo38Z/XqP+U0+kq4vmwonvmEMpm7hKnNEXvhqGKyGzyBwb+CZVJ2L8Eo=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.example.test. IN A
|
||||
SECTION ANSWER
|
||||
ns.example.test. IN A 1.2.3.4
|
||||
ns.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. 2PWaVaccZFQgfPKXNsdEGYUVaashCAj1ZhBo9XRt5eQKUFvZcauBjMnXIuxZFyWeootn1fZGw6GuPI5W48Y0FDx38H6adprkFgQikso2Y64jDdDMWznSo38Z/XqP+U0+kq4vmwonvmEMpm7hKnNEXvhqGKyGzyBwb+CZVJ2L8Eo=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.example.test. IN AAAA
|
||||
SECTION AUTHORITY
|
||||
example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
|
||||
example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8=
|
||||
ns.example.test. 3600 IN NSEC nz.example.test. A RRSIG
|
||||
ns.example.test. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 55567 example.test. v/5aO/n8Ow21y7LE7JKZsFkUJU5MjIfadVRm2Tdb8f3RLwYDdBTs3aWeeEQdCRSUF61TmfJM1jIxlWQPuHbqzGnjSk7adw9gFpP7wFwoqG3/xdCFHoxo/3/1F/4Ankey3sDgKgOFsgnu40TlL36mGPYszeK+/2o3SAx2GM+3BdU=
|
||||
ENTRY_END
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.test. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.test. 3600 IN DNSKEY 257 3 8 AwEAAdug/L739i0mgN2nuK/bhxu3wFn5Ud9nK2+XUmZQlPUEZUC5YZvm1rfMmEWTGBn87fFxEu/kjFZHJ55JLzqsbbpVHLbmKCTT2gYR2FV2WDKROGKuYbVkJIXdKAjJ0ONuK507NinYvlWXIoxHn22KAWOd9wKgSTNHBlmGkX+ts3hh ;{id = 55567 (ksk), size = 1024b}
|
||||
example.test. 3600 IN RRSIG DNSKEY 8 2 3600 20201116135527 20201019135527 55567 example.test. IbWMC6quOuZFNPAVxQLqCJ9nLhindBo826rnLcg5yMgs9dGUSPOCXAfHTmbgJAUNs9HTFfrJWNvasnETs0UOpmEuifGwWdH1OlME7Gny4RL2QmITUFeMW81Jz1tiVQxFXl6yxT0jxOxvz+bqMHlrz+8IeWQXcO+GZTPu8ueq30g=
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
valid.example.test. AAAA
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
|
||||
example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8=
|
||||
valid.example.test. 3600 IN NSEC valid2.example.test. A RRSIG NSEC
|
||||
valid.example.test. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 55567 example.test. GgwpBUFe6s1OLhunIQt5IXPMc51bScvWApWC7j0GbqL3FvtDyHDW4+vBxSh4lxX+262wGkw4OksRXIq0jNm313s8RUKmfszKeNfOr7KwubNeTZnU8dhl7RwIbBAYzqv2KPT7fPX7Vi3sKYDbJrU+KJUBohueJdGf4Y6Ixcb6sqY=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
valid.example.test. A
|
||||
SECTION ANSWER
|
||||
valid.example.test. 3600 IN A 192.0.2.1
|
||||
valid.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. hZx175Bx+TmOZjv021Y5Os4254guBqMWLk9A1ixCM0B7v9s9WxMBidDvjiWO6dwjkvC4v8dfcoCWvoFfgwBNUFQQV9xDrqB06Oo4qyMftpyQrV/FsHrHQ7OlxaX/P5vhuPtQvLMj/J67P7WWIewqZV9SKP4I1vFX+c5L/uO/8Ts=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
invaaaa.example.test. AAAA
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
|
||||
example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8=
|
||||
invaaaa.example.test. 3600 IN NSEC invaaaa2.example.test. A RRSIG NSEC
|
||||
; signature on the NSEC is invalidated: (wrong keytag)
|
||||
; correct is:
|
||||
; invaaaa.example.test. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 55567 example.test. Xsc0PJbV3dYo6EweR5e/o4ROVNpJkWNdrDXNrU9vwwCOFrfdvkoOLCnmejpHM5V+v8yNt43l4gcurut8GU4hzBD2gdx1SdMV6k3Uv8UYRrQhidIwEynQRqaDhdAt7lCqTvKAn2iTHbHU9Fss0ezL01aYaCVTyPTeGZP6CgSzGU0=
|
||||
invaaaa.example.test. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 11567 example.test. Xsc0PJbV3dYo6EweR5e/o4ROVNpJkWNdrDXNrU9vwwCOFrfdvkoOLCnmejpHM5V+v8yNt43l4gcurut8GU4hzBD2gdx1SdMV6k3Uv8UYRrQhidIwEynQRqaDhdAt7lCqTvKAn2iTHbHU9Fss0ezL01aYaCVTyPTeGZP6CgSzGU0=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
invaaaa.example.test. A
|
||||
SECTION ANSWER
|
||||
invaaaa.example.test. 3600 IN A 192.0.2.2
|
||||
invaaaa.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. vNWrVbz9L8eaBXIulg+zswK02cjy+stKxHhedDclVqduavv7+6ZV7idFY+zlHZU6KxrfjGB8/UFMkdpOlcgrAy0D9YQAVjm2zCKzx6f3GSenlNWMlhwgeAJb+ozP/cmrZ+ctqF7id9q4E5P08yTPHEqEcdXDMG0iTEuSvel/p7I=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
inva.example.test. AAAA
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
|
||||
example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8=
|
||||
inva.example.test. 3600 IN NSEC inva2.example.test. A RRSIG NSEC
|
||||
inva.example.test. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 55567 example.test. 1Rltlowol5kpdPYUuOt4GQJJjUr7UvJQGuhJ58Tuwxsd1rt/M+HAM61lzE2z6xcT2ezw5ja60lzNQsMiFYP0JCwcT6874X4er4+544O6fwFVcZPEh9jTOEH5TsjiYT1OltIsPf8LSUchRAo8LMSbHBpfFHe6JPZiyvBs4N60/hM=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
inva.example.test. A
|
||||
SECTION ANSWER
|
||||
inva.example.test. 3600 IN A 192.0.2.3
|
||||
; signature is invalidated: (wrong keytag)
|
||||
; correct is:
|
||||
;inva.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. CrBrpUkdpdDv/rg6u5I/Ja5FOHUvTl8g0wxymHfrm+qQMCJ86CHdsON6g8JyCE4HsZ6ZXEc9/s5Qxnse/awlEKGjvM6SYRbXhhbjJDDY2MoitwYXLAocq2gM0tqZeKMnYZzMRiRdhaL4XvwubHAtD/gU/RiF2/uequViwlaFo8w=
|
||||
inva.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 11567 example.test. CrBrpUkdpdDv/rg6u5I/Ja5FOHUvTl8g0wxymHfrm+qQMCJ86CHdsON6g8JyCE4HsZ6ZXEc9/s5Qxnse/awlEKGjvM6SYRbXhhbjJDDY2MoitwYXLAocq2gM0tqZeKMnYZzMRiRdhaL4XvwubHAtD/gU/RiF2/uequViwlaFo8w=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
invboth.example.test. AAAA
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
|
||||
example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8=
|
||||
invboth.example.test. 3600 IN NSEC invboth2.example.test. A RRSIG NSEC
|
||||
; signature on the NSEC is invalidated: (wrong keytag)
|
||||
; correct is:
|
||||
;invboth.example.test. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 55567 example.test. w7oGj0Tb3o30iIknVEVToQ39DCQVUx9yV2mm1SkR4MBc4zj3eZRRoL40lHPrIndFRsrBxm7+pxdy29Nw+diWdQj5NnsEsPDSPRvkb04xaah22/zd7lmjLLx3qtFCZpEVbsLUGQAy546NmVlv65/TghlTFA3e6dOFtiwQhdWskyg=
|
||||
invboth.example.test. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 11567 example.test. w7oGj0Tb3o30iIknVEVToQ39DCQVUx9yV2mm1SkR4MBc4zj3eZRRoL40lHPrIndFRsrBxm7+pxdy29Nw+diWdQj5NnsEsPDSPRvkb04xaah22/zd7lmjLLx3qtFCZpEVbsLUGQAy546NmVlv65/TghlTFA3e6dOFtiwQhdWskyg=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
invboth.example.test. A
|
||||
SECTION ANSWER
|
||||
invboth.example.test. 3600 IN A 192.0.2.4
|
||||
; signature is invalidated: (wrong keytag)
|
||||
; correct is:
|
||||
;invboth.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. Dt7oT9T55C83sIo8P21SzpB9WWBvEllrj0QXzCkO5Jb7XFtt7YwNnBmRMwbLbRol3YUVCkGaY/mSrATuP5xiq0sPulr8togzKWD0QOAJrxOnuk40ffkp1zrwiqkH7tRy5S9wQUx+vUt7RT1PcEqWufI4XRPmbhFuPXIMM1i8Te8=
|
||||
invboth.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 11567 example.test. Dt7oT9T55C83sIo8P21SzpB9WWBvEllrj0QXzCkO5Jb7XFtt7YwNnBmRMwbLbRol3YUVCkGaY/mSrATuP5xiq0sPulr8togzKWD0QOAJrxOnuk40ffkp1zrwiqkH7tRy5S9wQUx+vUt7RT1PcEqWufI4XRPmbhFuPXIMM1i8Te8=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
hasaaaa.example.test. AAAA
|
||||
SECTION ANSWER
|
||||
hasaaaa.example.test. 3600 IN AAAA 2001::db8:5
|
||||
hasaaaa.example.test. 3600 IN RRSIG AAAA 8 3 3600 20201116135527 20201019135527 55567 example.test. eat6Eh6Sqy9OE+BUIdUzzKuToqFn7K62oLbNUcj+JG/mlv85xeM3fKGbbwyR1mDbt/mghLfcchxWDoXtWJtYbItFVpRn4UyIuqK2w4igUb/Ic7iKoBJ4ZWlfYadE5MnAhVSQ094yAj3iUWydqQXVmTJ4UAJ3ouyzCJS8LojzZS8=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
hasaaaa.example.test. A
|
||||
SECTION ANSWER
|
||||
hasaaaa.example.test. 3600 IN A 192.0.2.5
|
||||
hasaaaa.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. Lh0DMv541AunEERFv3Zck1JE4fCC48V247y5+4O/ciblzc67VDjlCnp2BAXtjoYgWmvRqtxgPMzttALbHN2YxweX0Tq6/Ji0iyvLepC6a0+LjT45KPAmXYEigX/oxyUX7bxKXJ0k+Tm9FdnesDMGuoDuk7gVYi9Bdrst8DWULJc=
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD DO
|
||||
SECTION QUESTION
|
||||
valid.example.test. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
STEP 2 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA AD DO NOERROR
|
||||
SECTION QUESTION
|
||||
valid.example.test. IN AAAA
|
||||
SECTION ANSWER
|
||||
valid.example.test. 0 IN AAAA 64:ff9b::c000:201
|
||||
ENTRY_END
|
||||
|
||||
; from cache
|
||||
STEP 10 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD DO
|
||||
SECTION QUESTION
|
||||
valid.example.test. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
STEP 11 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA AD DO NOERROR
|
||||
SECTION QUESTION
|
||||
valid.example.test. IN AAAA
|
||||
SECTION ANSWER
|
||||
valid.example.test. 0 IN AAAA 64:ff9b::c000:201
|
||||
ENTRY_END
|
||||
|
||||
; with cd flag
|
||||
STEP 20 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD CD DO
|
||||
SECTION QUESTION
|
||||
valid.example.test. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
STEP 21 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA AD CD DO NOERROR
|
||||
SECTION QUESTION
|
||||
valid.example.test. IN AAAA
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
|
||||
example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8= ;{id = 55567}
|
||||
valid.example.test. 3600 IN NSEC valid2.example.test. A RRSIG NSEC
|
||||
valid.example.test. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 55567 example.test. GgwpBUFe6s1OLhunIQt5IXPMc51bScvWApWC7j0GbqL3FvtDyHDW4+vBxSh4lxX+262wGkw4OksRXIq0jNm313s8RUKmfszKeNfOr7KwubNeTZnU8dhl7RwIbBAYzqv2KPT7fPX7Vi3sKYDbJrU+KJUBohueJdGf4Y6Ixcb6sqY= ;{id = 55567}
|
||||
ENTRY_END
|
||||
|
||||
; invaaaa.example.test.
|
||||
STEP 30 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD DO
|
||||
SECTION QUESTION
|
||||
invaaaa.example.test. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
STEP 31 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA DO SERVFAIL
|
||||
SECTION QUESTION
|
||||
invaaaa.example.test. IN AAAA
|
||||
SECTION ANSWER
|
||||
; It is not: invaaaa.example.test. 3600 IN AAAA 64:ff9b::c000:202
|
||||
ENTRY_END
|
||||
|
||||
; from cache
|
||||
STEP 40 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD DO
|
||||
SECTION QUESTION
|
||||
invaaaa.example.test. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
STEP 41 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA DO SERVFAIL
|
||||
SECTION QUESTION
|
||||
invaaaa.example.test. IN AAAA
|
||||
SECTION ANSWER
|
||||
ENTRY_END
|
||||
|
||||
; with cd flag
|
||||
STEP 50 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD CD DO
|
||||
SECTION QUESTION
|
||||
invaaaa.example.test. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
STEP 51 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA CD DO NOERROR
|
||||
SECTION QUESTION
|
||||
invaaaa.example.test. IN AAAA
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
|
||||
example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8= ;{id = 55567}
|
||||
invaaaa.example.test. 60 IN NSEC invaaaa2.example.test. A RRSIG NSEC
|
||||
invaaaa.example.test. 60 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 11567 example.test. Xsc0PJbV3dYo6EweR5e/o4ROVNpJkWNdrDXNrU9vwwCOFrfdvkoOLCnmejpHM5V+v8yNt43l4gcurut8GU4hzBD2gdx1SdMV6k3Uv8UYRrQhidIwEynQRqaDhdAt7lCqTvKAn2iTHbHU9Fss0ezL01aYaCVTyPTeGZP6CgSzGU0= ;{id = 11567}
|
||||
ENTRY_END
|
||||
|
||||
; inva.example.test.
|
||||
STEP 60 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD DO
|
||||
SECTION QUESTION
|
||||
inva.example.test. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
STEP 61 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA DO SERVFAIL
|
||||
SECTION QUESTION
|
||||
inva.example.test. IN AAAA
|
||||
SECTION ANSWER
|
||||
ENTRY_END
|
||||
|
||||
; from cache
|
||||
STEP 70 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD DO
|
||||
SECTION QUESTION
|
||||
inva.example.test. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
STEP 71 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA DO SERVFAIL
|
||||
SECTION QUESTION
|
||||
inva.example.test. IN AAAA
|
||||
SECTION ANSWER
|
||||
ENTRY_END
|
||||
|
||||
; with cd flag
|
||||
STEP 80 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD CD DO
|
||||
SECTION QUESTION
|
||||
inva.example.test. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
STEP 81 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA AD CD DO NOERROR
|
||||
SECTION QUESTION
|
||||
inva.example.test. IN AAAA
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
example.test. 0 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
|
||||
example.test. 0 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8= ;{id = 55567}
|
||||
inva.example.test. 0 IN NSEC inva2.example.test. A RRSIG NSEC
|
||||
inva.example.test. 0 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 55567 example.test. 1Rltlowol5kpdPYUuOt4GQJJjUr7UvJQGuhJ58Tuwxsd1rt/M+HAM61lzE2z6xcT2ezw5ja60lzNQsMiFYP0JCwcT6874X4er4+544O6fwFVcZPEh9jTOEH5TsjiYT1OltIsPf8LSUchRAo8LMSbHBpfFHe6JPZiyvBs4N60/hM= ;{id = 55567}
|
||||
ENTRY_END
|
||||
|
||||
; invboth.example.test.
|
||||
STEP 90 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD DO
|
||||
SECTION QUESTION
|
||||
invboth.example.test. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
STEP 91 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA DO SERVFAIL
|
||||
SECTION QUESTION
|
||||
invboth.example.test. IN AAAA
|
||||
SECTION ANSWER
|
||||
ENTRY_END
|
||||
|
||||
; from cache
|
||||
STEP 100 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD DO
|
||||
SECTION QUESTION
|
||||
invboth.example.test. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
STEP 101 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA DO SERVFAIL
|
||||
SECTION QUESTION
|
||||
invboth.example.test. IN AAAA
|
||||
SECTION ANSWER
|
||||
ENTRY_END
|
||||
|
||||
; with cd flag
|
||||
STEP 110 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD CD DO
|
||||
SECTION QUESTION
|
||||
invboth.example.test. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
STEP 111 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA CD DO NOERROR
|
||||
SECTION QUESTION
|
||||
invboth.example.test. IN AAAA
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
|
||||
example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8= ;{id = 55567}
|
||||
invboth.example.test. 60 IN NSEC invboth2.example.test. A RRSIG NSEC
|
||||
invboth.example.test. 60 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 11567 example.test. w7oGj0Tb3o30iIknVEVToQ39DCQVUx9yV2mm1SkR4MBc4zj3eZRRoL40lHPrIndFRsrBxm7+pxdy29Nw+diWdQj5NnsEsPDSPRvkb04xaah22/zd7lmjLLx3qtFCZpEVbsLUGQAy546NmVlv65/TghlTFA3e6dOFtiwQhdWskyg= ;{id = 11567}
|
||||
ENTRY_END
|
||||
|
||||
; hasaaaa.example.test.
|
||||
STEP 120 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD DO
|
||||
SECTION QUESTION
|
||||
hasaaaa.example.test. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
STEP 121 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA AD DO NOERROR
|
||||
SECTION QUESTION
|
||||
hasaaaa.example.test. IN AAAA
|
||||
SECTION ANSWER
|
||||
hasaaaa.example.test. 0 IN AAAA 2001::db8:5
|
||||
hasaaaa.example.test. 0 IN RRSIG AAAA 8 3 3600 20201116135527 20201019135527 55567 example.test. eat6Eh6Sqy9OE+BUIdUzzKuToqFn7K62oLbNUcj+JG/mlv85xeM3fKGbbwyR1mDbt/mghLfcchxWDoXtWJtYbItFVpRn4UyIuqK2w4igUb/Ic7iKoBJ4ZWlfYadE5MnAhVSQ094yAj3iUWydqQXVmTJ4UAJ3ouyzCJS8LojzZS8= ;{id = 55567}
|
||||
ENTRY_END
|
||||
|
||||
; from cache
|
||||
STEP 130 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD DO
|
||||
SECTION QUESTION
|
||||
hasaaaa.example.test. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
STEP 131 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA AD DO NOERROR
|
||||
SECTION QUESTION
|
||||
hasaaaa.example.test. IN AAAA
|
||||
SECTION ANSWER
|
||||
hasaaaa.example.test. 0 IN AAAA 2001::db8:5
|
||||
hasaaaa.example.test. 0 IN RRSIG AAAA 8 3 3600 20201116135527 20201019135527 55567 example.test. eat6Eh6Sqy9OE+BUIdUzzKuToqFn7K62oLbNUcj+JG/mlv85xeM3fKGbbwyR1mDbt/mghLfcchxWDoXtWJtYbItFVpRn4UyIuqK2w4igUb/Ic7iKoBJ4ZWlfYadE5MnAhVSQ094yAj3iUWydqQXVmTJ4UAJ3ouyzCJS8LojzZS8= ;{id = 55567}
|
||||
ENTRY_END
|
||||
|
||||
; with cd flag
|
||||
STEP 140 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD CD DO
|
||||
SECTION QUESTION
|
||||
hasaaaa.example.test. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
STEP 141 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA AD CD DO NOERROR
|
||||
SECTION QUESTION
|
||||
hasaaaa.example.test. IN AAAA
|
||||
SECTION ANSWER
|
||||
hasaaaa.example.test. 0 IN AAAA 2001::db8:5
|
||||
hasaaaa.example.test. 0 IN RRSIG AAAA 8 3 3600 20201116135527 20201019135527 55567 example.test. eat6Eh6Sqy9OE+BUIdUzzKuToqFn7K62oLbNUcj+JG/mlv85xeM3fKGbbwyR1mDbt/mghLfcchxWDoXtWJtYbItFVpRn4UyIuqK2w4igUb/Ic7iKoBJ4ZWlfYadE5MnAhVSQ094yAj3iUWydqQXVmTJ4UAJ3ouyzCJS8LojzZS8= ;{id = 55567}
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+209
@@ -0,0 +1,209 @@
|
||||
; config options go here.
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: no
|
||||
minimal-responses: yes
|
||||
module-config: "dns64 iterator"
|
||||
dns64-prefix: 64:ff9b::0/96
|
||||
forward-zone: name: "." forward-addr: 216.0.0.1
|
||||
forward-no-cache: yes
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test DNS64 with forward zone with forward-no-cache set.
|
||||
RANGE_BEGIN 0 15
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN A 10.20.30.40
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
RANGE_BEGIN 15 25
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN A 10.20.30.41
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
RANGE_BEGIN 25 35
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
www2.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www2.example.com. IN A 10.20.30.42
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
www2.example.com. IN AAAA
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
example.com. 300 IN SOA ns.example.com. host.example.com. 5 86400 7200 604800 300
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
RANGE_BEGIN 35 45
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
www2.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www2.example.com. IN A 10.20.30.43
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
www2.example.com. IN AAAA
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
example.com. 300 IN SOA ns.example.com. host.example.com. 5 86400 7200 604800 300
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
RANGE_BEGIN 45 55
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
www3.example.com. IN AAAA
|
||||
SECTION ANSWER
|
||||
www3.example.com. 3600 IN AAAA 2001:db8::5
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
RANGE_BEGIN 55 65
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
www3.example.com. IN AAAA
|
||||
SECTION ANSWER
|
||||
www3.example.com. 3600 IN AAAA 2001:db8::6
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; query for A record
|
||||
STEP 10 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
ENTRY_END
|
||||
STEP 11 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
REPLY QR RD RA
|
||||
MATCH opcode qname qtype all
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN A 10.20.30.40
|
||||
ENTRY_END
|
||||
|
||||
; the upstream has changed, ask for A record again
|
||||
STEP 20 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
ENTRY_END
|
||||
STEP 21 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
REPLY QR RD RA
|
||||
MATCH opcode qname qtype all
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN A 10.20.30.41
|
||||
ENTRY_END
|
||||
|
||||
; query for synthesized AAAA record
|
||||
STEP 30 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www2.example.com. IN AAAA
|
||||
ENTRY_END
|
||||
STEP 31 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
REPLY QR RD RA
|
||||
MATCH opcode qname qtype all
|
||||
SECTION QUESTION
|
||||
www2.example.com. IN AAAA
|
||||
SECTION ANSWER
|
||||
www2.example.com. 3600 IN AAAA 64:ff9b::a14:1e2a
|
||||
ENTRY_END
|
||||
|
||||
; the upstream has changed, query for synthesized AAAA again.
|
||||
STEP 40 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www2.example.com. IN AAAA
|
||||
ENTRY_END
|
||||
STEP 41 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
REPLY QR RD RA
|
||||
MATCH opcode qname qtype all
|
||||
SECTION QUESTION
|
||||
www2.example.com. IN AAAA
|
||||
SECTION ANSWER
|
||||
www2.example.com. 3600 IN AAAA 64:ff9b::a14:1e2b
|
||||
ENTRY_END
|
||||
|
||||
; query for AAAA record, that is present, no synthesis.
|
||||
STEP 50 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www3.example.com. IN AAAA
|
||||
ENTRY_END
|
||||
STEP 51 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
REPLY QR RD RA
|
||||
MATCH opcode qname qtype all
|
||||
SECTION QUESTION
|
||||
www3.example.com. IN AAAA
|
||||
SECTION ANSWER
|
||||
www3.example.com. 3600 IN AAAA 2001:db8::5
|
||||
ENTRY_END
|
||||
|
||||
; the upstream has changed, query for AAAA record again (no synthesis).
|
||||
STEP 60 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www3.example.com. IN AAAA
|
||||
ENTRY_END
|
||||
STEP 61 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
REPLY QR RD RA
|
||||
MATCH opcode qname qtype all
|
||||
SECTION QUESTION
|
||||
www3.example.com. IN AAAA
|
||||
SECTION ANSWER
|
||||
www3.example.com. 3600 IN AAAA 2001:db8::6
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+288
@@ -0,0 +1,288 @@
|
||||
; config options
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: no
|
||||
minimal-responses: yes
|
||||
log-servfail: yes
|
||||
module-config: "dns64 respip iterator"
|
||||
; or
|
||||
; module-config: "respip dns64 iterator"
|
||||
dns64-prefix: 64:ff9b::/96
|
||||
; possibly as well:
|
||||
; response-ip: 192.0.2.66/32 always_nxdomain
|
||||
|
||||
rpz:
|
||||
name: "rpz.example.com."
|
||||
rpz-log: yes
|
||||
rpz-log-name: "rpz.example.com"
|
||||
zonefile:
|
||||
TEMPFILE_NAME rpz.example.com
|
||||
TEMPFILE_CONTENTS rpz.example.com
|
||||
$ORIGIN example.com.
|
||||
rpz 3600 IN SOA ns1.rpz.gotham.com. hostmaster.rpz.example.com. (
|
||||
1379078166 28800 7200 604800 7200 )
|
||||
3600 IN NS ns1.rpz.example.com.
|
||||
3600 IN NS ns2.rpz.example.com.
|
||||
$ORIGIN rpz.example.com.
|
||||
; block 192.0.2.66/32
|
||||
32.66.2.0.192.rpz-ip IN CNAME .
|
||||
TEMPFILE_END
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test RPZ filtered query with DNS64 enabled.
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode subdomain
|
||||
ADJUST copy_id copy_query
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
tld. IN NS
|
||||
SECTION AUTHORITY
|
||||
tld. IN NS ns.tld.
|
||||
SECTION ADDITIONAL
|
||||
ns.tld. IN A 1.2.3.5
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.tld
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.5
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
tld. IN NS
|
||||
SECTION ANSWER
|
||||
tld. IN NS ns.tld
|
||||
SECTION ADDITIONAL
|
||||
ns.tld. IN A 1.2.3.5
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.tld. IN A
|
||||
SECTION ANSWER
|
||||
ns.tld. IN A 1.2.3.5
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.tld. IN AAAA
|
||||
SECTION AUTHORITY
|
||||
tld. 3600 IN SOA ns.tld. host.tld. 20201 3600 1800 604800 3600
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode subdomain
|
||||
ADJUST copy_id copy_query
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.tld. IN NS
|
||||
SECTION AUTHORITY
|
||||
example.tld. 5 IN NS ns.example.tld.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.tld. 5 IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.tld.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.tld. IN NS
|
||||
SECTION ANSWER
|
||||
example.tld. 86400 IN NS ns.example.tld.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.tld. 86400 IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.example.tld. IN A
|
||||
SECTION ANSWER
|
||||
ns.example.tld. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.example.tld. IN AAAA
|
||||
SECTION AUTHORITY
|
||||
example.tld. 3600 IN SOA ns.example.tld. host.example.tld. 20301 3600 1800 604800 3600
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
bad.example.tld. IN A
|
||||
SECTION ANSWER
|
||||
bad.example.tld. IN A 192.0.2.66
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
bad.example.tld. IN AAAA
|
||||
SECTION AUTHORITY
|
||||
example.tld. 3600 IN SOA ns.example.tld. host.example.tld. 20301 3600 1800 604800 3600
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
synth.example.tld. IN A
|
||||
SECTION ANSWER
|
||||
synth.example.tld. IN A 203.0.113.5
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
synth.example.tld. IN AAAA
|
||||
SECTION AUTHORITY
|
||||
example.tld. 3600 IN SOA ns.example.tld. host.example.tld. 20301 3600 1800 604800 3600
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
clean.example.tld. IN A
|
||||
SECTION ANSWER
|
||||
clean.example.tld. IN A 203.0.113.5
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
clean.example.tld. IN AAAA
|
||||
SECTION AUTHORITY
|
||||
example.tld. 3600 IN SOA ns.example.tld. host.example.tld. 20301 3600 1800 604800 3600
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD NOERROR
|
||||
SECTION QUESTION
|
||||
bad.example.tld. IN A
|
||||
ENTRY_END
|
||||
|
||||
; RPZ works on A query
|
||||
STEP 2 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA NXDOMAIN
|
||||
SECTION QUESTION
|
||||
bad.example.tld. IN A
|
||||
SECTION ANSWER
|
||||
ENTRY_END
|
||||
|
||||
STEP 10 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD NOERROR
|
||||
SECTION QUESTION
|
||||
synth.example.tld. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
; DNS64 synthesizes an unblocked address.
|
||||
STEP 11 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
synth.example.tld. IN AAAA
|
||||
SECTION ANSWER
|
||||
synth.example.tld. 3600 IN AAAA 64:ff9b::cb00:7105
|
||||
ENTRY_END
|
||||
|
||||
STEP 20 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD NOERROR
|
||||
SECTION QUESTION
|
||||
bad.example.tld. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
; synthesized AAAA for A that is blocked by RPZ.
|
||||
STEP 21 CHECK_ANSWER
|
||||
;ENTRY_BEGIN
|
||||
;MATCH all
|
||||
;REPLY QR RD RA NXDOMAIN
|
||||
;SECTION QUESTION
|
||||
;bad.example.tld. IN AAAA
|
||||
;SECTION ANSWER
|
||||
;ENTRY_END
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
bad.example.tld. IN AAAA
|
||||
SECTION AUTHORITY
|
||||
example.tld. 3600 IN SOA ns.example.tld. host.example.tld. 20301 3600 1800 604800 3600
|
||||
ENTRY_END
|
||||
|
||||
STEP 30 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD NOERROR
|
||||
SECTION QUESTION
|
||||
bad.example.tld. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
; same from cache.
|
||||
STEP 31 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
bad.example.tld. IN AAAA
|
||||
SECTION AUTHORITY
|
||||
example.tld. 3600 IN SOA ns.example.tld. host.example.tld. 20301 3600 1800 604800 3600
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+1202
File diff suppressed because it is too large
Load Diff
+221
@@ -0,0 +1,221 @@
|
||||
; Test DNS Error Reporting.
|
||||
|
||||
server:
|
||||
module-config: "validator iterator"
|
||||
trust-anchor-signaling: no
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
verbosity: 4
|
||||
qname-minimisation: no
|
||||
minimal-responses: no
|
||||
rrset-roundrobin: no
|
||||
trust-anchor: "test. DS 1444 8 2 8a87d067fd09a5965244fe2e317dd26d182c468e0a7f26ecc4c7b479bf89db9b"
|
||||
val-override-date: "20201020135527"
|
||||
ede: no # It is not needed for dns-error-reporting; only for clients to receive EDEs
|
||||
dns-error-reporting: yes
|
||||
do-ip6: no
|
||||
local-zone: test. nodefault
|
||||
log-servfail: yes
|
||||
|
||||
stub-zone:
|
||||
name: test
|
||||
stub-addr: 1.2.3.5
|
||||
stub-zone:
|
||||
name: an.agent
|
||||
stub-addr: 0.0.0.2
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test DNS Error Reporting with agent domain len malformed.
|
||||
|
||||
; ns.test
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.5
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
test. IN NS
|
||||
SECTION ANSWER
|
||||
test. IN NS ns.test
|
||||
test. 3600 IN RRSIG NS 8 1 3600 20201116135527 20201019135527 1444 test. RGCxIO32TbbLTk6xZmTr+fjYPH50hntBxeOQ2DIj2pDsmjALcHYtVkOfpfk2EhOhHZd+9PLuoJPbJh6a9NqLSFeBvr0XZoCZoQ2g0tCHUNHcH5EVjA2TuYBQem6DVYnPLJ3914aRx0uA1j42b8dC2xsam/XkOo7U+dLbUW2Os1s=
|
||||
SECTION ADDITIONAL
|
||||
ns.test. IN A 1.2.3.5
|
||||
ns.test. 3600 IN RRSIG A 8 2 3600 20201116135527 20201019135527 1444 test. GskCc4/k6GjH9V9Jz2V5L2XLiizbOeWkB0feSbf+aN859S3vxVvtuqkvIgwY4LafUO1QAn/pUcv9zA7rcFO++rlg+8t6gvZTo9p3v0bfeIv2uJDsfSBD5jDh0WXlxjekfnrKrQp7zE+GiA93tWwKUWKPvxXDgP+n886e6WcbHJw=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.test. IN A
|
||||
SECTION ANSWER
|
||||
ns.test. IN A 1.2.3.5
|
||||
ns.test. 3600 IN RRSIG A 8 2 3600 20201116135527 20201019135527 1444 test. GskCc4/k6GjH9V9Jz2V5L2XLiizbOeWkB0feSbf+aN859S3vxVvtuqkvIgwY4LafUO1QAn/pUcv9zA7rcFO++rlg+8t6gvZTo9p3v0bfeIv2uJDsfSBD5jDh0WXlxjekfnrKrQp7zE+GiA93tWwKUWKPvxXDgP+n886e6WcbHJw=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.test. IN AAAA
|
||||
SECTION AUTHORITY
|
||||
test. 3600 IN SOA ns.test. host.test. 20201 3600 1800 604800 3600
|
||||
test. 3600 IN RRSIG SOA 8 1 3600 20201116135527 20201019135527 1444 test. IZJIDmEgf0W7A5G7hvvZ2hUqJ9Trbv1/i7ySapDmPbYV9lVCmHHobySxO01yDhI2/Pvpsvxqrm1Tiv3BxH8uzZ4keKgiQjBsSy4htAsFct9I4E7ly2glPj/Fm3oun3PsjJDv5QYhx0KS7w4IQKU7Nc9pfJc92uoUI5bdoC1pRGw=
|
||||
ns.test. 3600 IN NSEC nz.test. A RRSIG
|
||||
ns.test. 3600 IN RRSIG NSEC 8 2 3600 20201116135527 20201019135527 1444 test. PElArVB3KPg8KHAP7lzcNbhFuXNxTsHNTn1dZVncB5qmWRdIaeKpaXDjpH0JSXMaelGFS+/QhuQ6Hmw9+4VyZFRqMzGhw4agUR/2bxABHcDIG4ZpUwyeSP61ATTfHUkQVxaH2wjCWI/tfmesdP2xVE4GXyUvCIBxU914MkZbULU=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
test. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
test. 3600 IN DNSKEY 257 3 8 AwEAAbd9WqjzE2Pynz21OG5doSf9hFzMr5dhzz2waZ3vTa+0o5r7AjTAqmA1yH/B3+aAMihUm5ucZSfVqo7+kOaRE8yFj9aivOmA1n1+JLevJq/oyvQyjxQN2Qb89LyaNUT5oKZIiL+uyyhNW3KDR3SSbQ/GBwQNDHVcZi+JDR3RC0r7 ;{id = 1444 (ksk), size = 1024b}
|
||||
test. 3600 IN RRSIG DNSKEY 8 1 3600 20201116135527 20201019135527 1444 test. UmRMS4iG9NBBHZYOtpwFFcJgbEb5SfHSgHd9XRe/8pTWM31WSDayn5ViPOBMqI1T5TXg2amc13dDI574xIM2oKMus3b5cBW72jJLW13jprBtslO6P8BMWb4HNnvLrJtQjwf3ErRirtTxinLmywQtmyr1cdthyG3Gp4N7i90fHSc=
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qname qtype
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
example.test. IN DS
|
||||
SECTION ANSWER
|
||||
example.test. 3600 IN DS 55567 8 2 a2d578906330a10a57d40462257b6ce038bad3f7bf4a45c46c46086e20a94b39
|
||||
example.test. 3600 IN RRSIG DS 8 2 3600 20201116135527 20201019135527 1444 test. P7+FTYW2qHuJ4I1YbuvseEz5X1lOYAraGEHB3C5y0OOCQFmhmSiFRdquNi2NlpcS6FXLdsE0EU+Bo1+0atTG4EkMWXbpF21lrtbB51BdsnlX4Mzc/o375fvjiOMwmF6wPCUaOUN62jrVrhsE/hedaVyDphDToqL17ETohwgUO2I=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode subdomain
|
||||
ADJUST copy_id copy_query
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.test. IN NS
|
||||
SECTION AUTHORITY
|
||||
example.test. IN NS ns.example.test.
|
||||
example.test. 3600 IN DS 55567 8 2 a2d578906330a10a57d40462257b6ce038bad3f7bf4a45c46c46086e20a94b39
|
||||
example.test. 3600 IN RRSIG DS 8 2 3600 20201116135527 20201019135527 1444 test. P7+FTYW2qHuJ4I1YbuvseEz5X1lOYAraGEHB3C5y0OOCQFmhmSiFRdquNi2NlpcS6FXLdsE0EU+Bo1+0atTG4EkMWXbpF21lrtbB51BdsnlX4Mzc/o375fvjiOMwmF6wPCUaOUN62jrVrhsE/hedaVyDphDToqL17ETohwgUO2I=
|
||||
SECTION ADDITIONAL
|
||||
ns.example.test. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.test.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.test. IN NS
|
||||
SECTION ANSWER
|
||||
example.test. IN NS ns.example.test.
|
||||
example.test. 3600 IN RRSIG NS 8 2 3600 20201116135527 20201019135527 55567 example.test. l1JT0wMlK0YI7/CWHzexf/k0iafUhCgN+BdgjBXIRXmSQNf4HDTiAkbcWL2/15qtnp12nQy9JeiTdSQ3vtPoHAJX4C5uTWaze4ms+Wrrf+n92sLCjacP9x50uuicH3URT6cKb1QCAPwlvlWxIlZjAMYFScSns7+C441NMJT8aE4=
|
||||
SECTION ADDITIONAL
|
||||
ns.example.test. IN A 1.2.3.4
|
||||
ns.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. 2PWaVaccZFQgfPKXNsdEGYUVaashCAj1ZhBo9XRt5eQKUFvZcauBjMnXIuxZFyWeootn1fZGw6GuPI5W48Y0FDx38H6adprkFgQikso2Y64jDdDMWznSo38Z/XqP+U0+kq4vmwonvmEMpm7hKnNEXvhqGKyGzyBwb+CZVJ2L8Eo=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.example.test. IN A
|
||||
SECTION ANSWER
|
||||
ns.example.test. IN A 1.2.3.4
|
||||
ns.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. 2PWaVaccZFQgfPKXNsdEGYUVaashCAj1ZhBo9XRt5eQKUFvZcauBjMnXIuxZFyWeootn1fZGw6GuPI5W48Y0FDx38H6adprkFgQikso2Y64jDdDMWznSo38Z/XqP+U0+kq4vmwonvmEMpm7hKnNEXvhqGKyGzyBwb+CZVJ2L8Eo=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.example.test. IN AAAA
|
||||
SECTION AUTHORITY
|
||||
example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
|
||||
example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8=
|
||||
ns.example.test. 3600 IN NSEC nz.example.test. A RRSIG
|
||||
example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600
|
||||
ENTRY_END
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.test. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.test. 3600 IN DNSKEY 257 3 8 AwEAAdug/L739i0mgN2nuK/bhxu3wFn5Ud9nK2+XUmZQlPUEZUC5YZvm1rfMmEWTGBn87fFxEu/kjFZHJ55JLzqsbbpVHLbmKCTT2gYR2FV2WDKROGKuYbVkJIXdKAjJ0ONuK507NinYvlWXIoxHn22KAWOd9wKgSTNHBlmGkX+ts3hh ;{id = 55567 (ksk), size = 1024b}
|
||||
example.test. 3600 IN RRSIG DNSKEY 8 2 3600 20201116135527 20201019135527 55567 example.test. IbWMC6quOuZFNPAVxQLqCJ9nLhindBo826rnLcg5yMgs9dGUSPOCXAfHTmbgJAUNs9HTFfrJWNvasnETs0UOpmEuifGwWdH1OlME7Gny4RL2QmITUFeMW81Jz1tiVQxFXl6yxT0jxOxvz+bqMHlrz+8IeWQXcO+GZTPu8ueq30g=
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.test. IN A
|
||||
SECTION ANSWER
|
||||
www.example.test. 3600 IN A 10.20.30.40
|
||||
; valid signature
|
||||
;www.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. OQEgDcpez8Bvdwd+hxA3v63FWJhutWkv9w+k+8RLcWv34WPhebsf7CBV74ggY2c+HafvYiuIFfhdF5CX28YQjxqWVzFgE6bEA6spPc6qdHiQaY/096/4SLCDcL+2EtOqcR/uZGj5uNhhaCJ9UjscBKfEZmHUOAMXKmjsvl0I/+I=
|
||||
; invalid: expired signature
|
||||
www.example.test. 3600 IN RRSIG A 8 3 3600 20200816135527 20200719135527 55567 example.test. DNM4PJALboBNDe5pJ2NScYqYYmmpq8E0NogjbDNithIcQ7HtzkssLIR46DiPb/B7QIhBRpfQ6sUwMb4l+NDhm82DxaecEwnAV6Y0zYK6dZ5jI7e8rDI2hkW/LO75qSZ8Y1I9pgX5uyeBCon42IVjc3vyYbRbFNv1xgJs5rk308U=
|
||||
SECTION ADDITIONAL
|
||||
HEX_EDNSDATA_BEGIN
|
||||
; This dns error reporting option is malformed, with garbage at end.
|
||||
00 12 ; opt-code (Report-Channel)
|
||||
00 28 ; opt-len 10 + 30
|
||||
02 61 6E 05 61 67 65 6E 74 00 ; an.agent.
|
||||
ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ; 30 0xFF tail
|
||||
ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
|
||||
HEX_EDNSDATA_END
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; an.agent
|
||||
RANGE_BEGIN 10 20
|
||||
ADDRESS 0.0.0.2
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
_er.1.www.example.test.7._er.an.agent. IN TXT
|
||||
SECTION ANSWER
|
||||
_er.1.www.example.test.7._er.an.agent. IN TXT "OK"
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; Query again
|
||||
STEP 10 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.test. IN A
|
||||
ENTRY_END
|
||||
|
||||
; Check that validation failed
|
||||
; (a DNS Error Report query should have been generated)
|
||||
STEP 11 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA SERVFAIL
|
||||
SECTION QUESTION
|
||||
www.example.test. IN A
|
||||
ENTRY_END
|
||||
|
||||
; answer the reporting agent reply.
|
||||
STEP 20 TRAFFIC
|
||||
|
||||
SCENARIO_END
|
||||
@@ -0,0 +1,3 @@
|
||||
example.com. IN SOA ns.example.com. hostmaster.example.com. 1 3600 900 86400 3600
|
||||
example.com. IN NS ns.example.net.
|
||||
www.example.com. IN A 1.2.3.4
|
||||
@@ -0,0 +1,34 @@
|
||||
server:
|
||||
verbosity: 7
|
||||
# num-threads: 1
|
||||
interface: 127.0.0.1
|
||||
port: @PORT@
|
||||
use-syslog: no
|
||||
directory: ""
|
||||
pidfile: "unbound.pid"
|
||||
chroot: ""
|
||||
username: ""
|
||||
do-not-query-localhost: no
|
||||
use-caps-for-id: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 127.0.0.1@@TOPORT@
|
||||
|
||||
remote-control:
|
||||
control-enable: yes
|
||||
control-interface: @CONTROL_PATH@/controlpipe.@CONTROL_PID@
|
||||
control-use-cert: no
|
||||
|
||||
auth-zone:
|
||||
name: "example.com"
|
||||
for-upstream: yes
|
||||
for-downstream: yes
|
||||
allow-notify: notif.example.net
|
||||
zonefile: "example.com.zone"
|
||||
master: "127.0.0.1@@TOPORT@"
|
||||
auth-zone:
|
||||
name: "example2.com"
|
||||
for-upstream: yes
|
||||
for-downstream: yes
|
||||
master: prim.example.net
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user