Compare commits

..
Author SHA1 Message Date
W.C.A. Wijngaards 48d0aea60a - auth-load-thread, unit test for auth_load_http. 2026-08-11 16:50:24 +02:00
W.C.A. Wijngaards 17bbcac979 - auth-load-thread, fix buffer free in http processing. 2026-08-11 16:50:00 +02:00
W.C.A. Wijngaards fd8ebbb19c Merge branch 'master' into auth-load-thread 2026-08-11 16:23:20 +02:00
W.C.A. Wijngaards 2adbbea365 - auth-load-thread, print thread details in log at high verbosity, 8. 2026-08-11 16:23:03 +02:00
W.C.A. Wijngaards 8ee0bca833 - Fix stat_values.tdir test to have less test failures. 2026-08-11 10:07:38 +02:00
W.C.A. Wijngaards c58e6add2b - Fix #1492 from zacek: Data race in log_init() on
key_created/log_lock when calling ub_ctx_create()
  concurrently from multiple threads.
2026-08-11 09:42:30 +02:00
W.C.A. Wijngaards 156c00a727 Merge branch 'master' into auth-load-thread 2026-08-10 16:42:59 +02:00
W.C.A. Wijngaards d753f95956 - auth-load-thread, print time taken during auth load processing. 2026-08-10 16:42:04 +02:00
W.C.A. Wijngaards 93a56205cf - Fix #1489 from jplesnik: Replace removed Python 2 C API
macros for SWIG 4.5.0 compatibility.
2026-08-07 08:57:32 +02:00
W.C.A. Wijngaards 709f622658 Note issue number in Changlog entry. 2026-08-06 17:15:55 +02:00
akhanin-dnsfandGitHub 307fc6f062 - Fix bounds check in packed_rr_to_string, it checked the (#1488)
assembled rr length against the output string length
  dest_len, instead of against the size of the rr buffer it
  writes into. Callers in cachedump.c and remote.c pass a
  dest_len larger than that buffer.
- Unit test for packed_rr_to_string.
2026-08-06 17:04:05 +02:00
W.C.A. Wijngaards 8b33c5d7ff - Fix #1487: regression in 1.26.0, ipsecmod is now always
partly enabled.
2026-08-06 09:46:18 +02:00
W.C.A. Wijngaards 36bd52afb9 Fix typo in Changelog. 2026-08-06 09:08:33 +02:00
W.C.A. Wijngaards b7d13ff12b - Fix ##1485: the list_forwards command omits port numbers.
The list_forwards and list_stubs commands for
  unbound-control print port and tls auth name.
2026-08-06 09:08:17 +02:00
W.C.A. Wijngaards bdfcfb861f - Fix to set makedist.sh to not wget config.sub and
config.guess from git repo. The fetch times out, and the
  version from libtoolize is much more recent now than
  that it was when the wget was added.
2026-08-04 10:04:34 +02:00
W.C.A. Wijngaards b444deffd2 Note 1.26.0 release. 2026-08-04 10:01:59 +02:00
W.C.A. Wijngaards ff28b7e5cf - For #1483: The failure reason when an NSEC NXDOMAIN is
encountered when looking for an insecure delegation, is
  fixed to mention the NSEC records, instead of nonexistent
  NSEC3 records, that it attempted.
2026-07-31 09:53:47 +02:00
W.C.A. Wijngaards 79b84bbc91 - Fix #1482: DNS-over-QUIC doesn't work with simple config.
That fixes interface-automatic for use with doq service.
2026-07-30 08:24:42 +02:00
W.C.A. Wijngaards cbfc3b0342 - Tag for 1.26.0rc1. The repo continues with version 1.26.1. 2026-07-28 09:45:59 +02:00
W.C.A. Wijngaards a45da353d3 - Fix to call OPENSSL_cleanup on exit when that is defined. 2026-07-24 17:04:38 +02:00
W.C.A. Wijngaards c21e3ee929 Changelog note for #1479
- Merge #1479 from psumbera: Fix pthread detection on
  Solaris 11.4.
2026-07-24 15:35:55 +02:00
8a38bed262 Fix pthread detection on Solaris 11.4 (#1479)
AX_PTHREAD requires _REENTRANT to confirm that pthread support is enabled.
Solaris 11.4 headers no longer use the macro, and GCC 16 therefore no
longer defines it for -pthread.

Detect XPG7 support in the target headers and require _REENTRANT only on
older Solaris releases. The existing pthread compile and link test remains
the final capability check.

This follows the canonical Autoconf Archive change:
https://github.com/autoconf-archive/autoconf-archive/pull/341

Regenerate configure with Autoconf 2.71.

Tested on Solaris 11.4 with GCC 15.2 and GCC 16.1. The Autoconf Archive
change was also tested on Solaris 11.3.

Co-authored-by: Rainer Orth <ro@CeBiTec.Uni-Bielefeld.DE>
2026-07-24 15:34:18 +02:00
W.C.A. Wijngaards 7cc7a43ff6 Changelog note for #1481.
- Fix #1481: Fix to use tls-port after referral if
  tls-upstream is set.
2026-07-24 15:32:20 +02:00
W.C.A. Wijngaards 9bd8df0149 - Fix to use tls-port after referral if tls-upstream is set. 2026-07-24 15:31:06 +02:00
W.C.A. Wijngaards 8f7411057f - Fix sign of comparison warning in shared ports setup. 2026-07-24 14:44:44 +02:00
W.C.A. Wijngaards ca1fe4f82a - Fix to guard access to shared ports interface array during
set up, for analyzer.
2026-07-24 14:38:46 +02:00
W.C.A. Wijngaards e183c2c506 - Fix unused variable warnings in shared_ports_fetch_random
and shared_ports_return_port when compiled without threads.
2026-07-24 14:37:17 +02:00
W.C.A. Wijngaards 52b18fc6f5 Changelog entry for #1480
- Merge #1480 from petrvaganoff: authzone: fix memory leak in
  xfer_set_masters() error path.
2026-07-24 12:25:34 +02:00
Petr VaganovandGitHub e6d00725c2 authzone: fix memory leak in xfer_set_masters() error path (#1480)
Added memory deallocation for the `file` and `host` fields of the
`auth_master` node in the event of a URL/allocation error, and
unlinked the partially created node from the masters list by
resetting the link that pointed to it.

Signed-off-by: Petr Vaganov <petrvaganoff@gmail.com>
2026-07-24 12:24:49 +02:00
W.C.A. Wijngaards e597711824 - Fix lock test protect for auth zone change.
- Fix to lock shared_ports structure during initialisation.
- Fix to lock anchor structure when file is set for it in
2026-07-24 12:13:09 +02:00
W.C.A. Wijngaards e1e646c6fc - Fix to allow test fake sha1 on systems with possible sha1
support.
- Fix to use sha256 for unbound-anchor unit test.
- Fix unbound-anchor check for return value of
  X509_NAME_get_text_by_NID of the emailaddress.
2026-07-24 11:50:15 +02:00
W.C.A. Wijngaards fc3b5b4f63 - Update generated man pages. 2026-07-24 10:03:41 +02:00
W.C.A. Wijngaards 1e904a3ce5 - set code repository version to 1.26.0. 2026-07-24 09:45:49 +02:00
W.C.A. Wijngaards 79e100a7fb - Fix #1477: respip + dns64: dns64 uses A records modified by
respip instead of original A records. Adds local-zone types
  block_a_wdata and block_aaaa_wdata, that are like block_a
  and block_aaaa, and uses local-data if present.
2026-07-24 09:29:17 +02:00
W.C.A. Wijngaards a65d3d7283 - Unit test for block_a and block_aaaa. 2026-07-24 09:03:45 +02:00
W.C.A. Wijngaards 3b8766aa43 Changelog note for #1433
- Merge #1433 from jisakiel: Add new static zone type
  block_aaaa to suppress AAAA queries.
2026-07-24 08:53:30 +02:00
c8b3c89a39 Add new static zone type block_aaaa to suppress AAAA queries (#1433)
Following d5b9a790f lead for block_a - this would allow suppressing AAAA queries instead for sticking to IPV4.

Co-authored-by: Jisakiel <jisakiel@users.noreply.github.com>
2026-07-24 08:52:20 +02:00
W.C.A. Wijngaards a05d460e66 - Fix mesh cycle detection for configuration with respip CNAME
loop and tagged clients. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-07-23 16:28:45 +02:00
W.C.A. Wijngaards 5eb362a6c0 - Fix that the aggressive negative cache does not insert NSEC
records with overreaching next owner name. Also the result
  is not above the trust anchor's bailiwick. Also RRSIGS are
  not considered valid when an NSEC next owner name is not
  under the signer zone name. Thanks to Qifan Zhang, Palo
  Alto Networks, for the report.
2026-07-23 16:17:59 +02:00
W.C.A. Wijngaards 0735cb28d1 - Fix that for NSEC3 proofs the NSEC3 zone, as the b32.name is
checked to be the same as the signer name. Also RRSIGs are
  not considered valid when an NSEC3 is not b32.signerzone.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-07-23 15:54:59 +02:00
W.C.A. Wijngaards 737c28e836 Changelog entry for #1478
- Merge #1478 from petrvaganoff: pythonmod: add check return
  value after ftell().
2026-07-23 10:22:53 +02:00
Petr VaganovandGitHub 1bab2dfafa pythonmod: add check return value after ftell() (#1478)
Variable 'flen', which might receive a negative value at pythonmod.c:493
by calling function 'ftell', is used without checking at pythonmod.c:508
by calling function 'fread'.

Found by the static analyzer Svace (ISP RAS).

Signed-off-by: Petr Vaganov <petrvaganoff@gmail.com>
2026-07-23 10:22:02 +02:00
W.C.A. Wijngaards 22e2c5b6d1 - Updated credits for Xuanchao Xie in 22 july changelog. 2026-07-23 10:01:10 +02:00
W.C.A. Wijngaards 914dbfea4e - iana portlist update. 2026-07-22 14:12:34 +02:00
W.C.A. Wijngaards cf5e6e89a5 - Fix error in log printout in fix for CVE-2026-50248, when the
primary name is bogus.
2026-07-22 12:16:49 +02:00
W.C.A. Wijngaards 4941edf275 - Unit test for CVE-2026-56416. 2026-07-22 12:06:00 +02:00
W.C.A. Wijngaards b08723ef97 - Unit test for CVE-2026-55973. 2026-07-22 12:04:35 +02:00
W.C.A. Wijngaards c163fbc505 - Unit test for CVE-2026-55717. 2026-07-22 12:03:48 +02:00
W.C.A. Wijngaards eed3f1ab38 - Unit test for CVE-2026-50248. 2026-07-22 12:00:19 +02:00
W.C.A. Wijngaards 63501f51bb - Unit test for CVE-2026-50243. 2026-07-22 11:59:36 +02:00
W.C.A. Wijngaards 1ae2570bda - Unit test for CVE-2026-46582. 2026-07-22 11:58:18 +02:00
W.C.A. Wijngaards 9ad825b267 - Unit test for CVE-2026-50045. 2026-07-22 11:57:13 +02:00
W.C.A. Wijngaards 3d5e6c0692 - Unit test for CVE-2026-44690. 2026-07-22 11:56:08 +02:00
W.C.A. Wijngaards 23e19ca6fc - Unit test for CVE-2026-44687. 2026-07-22 11:55:09 +02:00
W.C.A. Wijngaards 9f757aa9f3 - Unit test for CVE-2026-42955. 2026-07-22 11:54:00 +02:00
W.C.A. Wijngaards 1df6c170ff Changelog entry for 1.25.2.
- Set the repository to 1.25.3, it continues with the previous
  changes.
2026-07-22 11:38:48 +02:00
W.C.A. Wijngaards 7a95bedc26 Fix conflict merge fixup. 2026-07-22 11:36:06 +02:00
W.C.A. Wijngaards ae685bc33d Move repo to version 1.25.3. 2026-07-22 11:34:48 +02:00
W.C.A. Wijngaards 91ac449bcd Merge branch 'branch-1.25.2' 2026-07-22 11:33:54 +02:00
W.C.A. Wijngaards c33ad1b1a2 rerun autoconf. 2026-07-22 10:21:21 +02:00
W.C.A. Wijngaards 84d9682dd0 - Fix CVE-2026-56444, Degradation of resolution service when
'discard-timeout' and 'serve-expired-client-timeout' are combined in
  unusual configuration. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report. In addition, thanks to Xin Wang, Jiapeng Li,
  and Jiajia Liu, Northwestern Polytechnical University, for also
  reporting this issue. In addition, thanks to Haruki Oyama (Waseda
  University), for also reporting this issue.
2026-07-22 10:19:50 +02:00
W.C.A. Wijngaards 4b1635e194 - Fix CVE-2026-56416, Possible heap buffer overflow when validator
canonicalizes RDATA that contains domain name. Thanks to Qifan
  Zhang, Palo Alto Networks, for the report.
2026-07-22 10:19:28 +02:00
W.C.A. Wijngaards aac261cbb3 - Fix CVE-2026-55991, Remote DNS-over-QUIC (DoQ) flow-control
assertion failure in libngtcp2. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report. In addition, thanks to Xuanchao Xie,
  for also reporting this issue.
2026-07-22 10:19:02 +02:00
W.C.A. Wijngaards ae1b3810cc - Fix CVE-2026-55990, Packet of death for a DNSCrypt misconfigured
Unbound. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-07-22 10:18:41 +02:00
W.C.A. Wijngaards 96f8755520 - Fix CVE-2026-55973, 'dns-error-reporting: yes' leads to stack buffer
overflow. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-07-22 10:18:16 +02:00
W.C.A. Wijngaards 2ce2ca3691 - Fix CVE-2026-55717, 'serve-expired-client-timeout' and 'response-ip'
CNAME redirect could lead to a crash. Thanks to Qifan Zhang, Palo
  Alto Networks, for the report. In addition, thanks to Xin Wang,
  Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University,
  for also reporting this issue.
2026-07-22 10:17:32 +02:00
W.C.A. Wijngaards c29ff70f6a - Fix CVE-2026-55708, Privacy/configuration issue when adding local
data in views through 'unbound-control'. Thanks to Qifan Zhang,
  Palo Alto Networks, for the report.
2026-07-22 10:17:10 +02:00
W.C.A. Wijngaards 8a15ffee62 - Fix CVE-2026-54478, DNS Cookie bypass when combined with
proxy-protocol use. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-07-22 10:16:42 +02:00
W.C.A. Wijngaards 8c702de175 - Fix CVE-2026-52863, Memory corruption could lead to crash and
denial of service. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-07-22 10:16:03 +02:00
W.C.A. Wijngaards 804cff4c15 - Fix CVE-2026-50252, Possible cache poisoning attack by mapping
source port population per thread. Thanks to Inbal Schussheim and
  Amit Klein, Hebrew University, for the report.
2026-07-22 10:15:31 +02:00
W.C.A. Wijngaards e180b06298 - Fix CVE-2026-50251, Attacker supplied 0.0.0.0/:: glue triggers
defensive full-cache flush. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-07-22 10:15:02 +02:00
W.C.A. Wijngaards 3530c81e29 - Fix CVE-2026-50248, BOGUS configured primary hostname accepted for
XFR in auth/rpz zones. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-07-22 10:14:35 +02:00
W.C.A. Wijngaards 02b16de1ae - Fix CVE-2026-50243, 'response-ip'/'rpz' can rewrite BOGUS answers
instead of returning SERVFAIL. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-07-22 10:14:04 +02:00
W.C.A. Wijngaards 1ad8d4c395 - Fix CVE-2026-50046, Possible heap use-after-free in an error path
when a DoT forwarded query is jostled out. Thanks to Qifan Zhang,
  Palo Alto Networks, for the report.
2026-07-22 10:13:36 +02:00
W.C.A. Wijngaards 364ac737f7 - Fix CVE-2026-50045, 'max-global-quota' reset by DNSSEC validation
restarts. Thanks to Kunjie Shang, University of Science and
  Technology of China, for the report.
2026-07-22 10:13:14 +02:00
W.C.A. Wijngaards f7637a4f18 - Fix CVE-2026-44690, Cross-zone wildcard cache poisoning via
RRSIG.labels manipulation. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-07-22 10:12:38 +02:00
W.C.A. Wijngaards 1e1940383a - Fix CVE-2026-44687, Off-by-one error in 'harden-below-nxdomain'
logic can shadow a stub/forward zone by a legitimate parent's
  NXDOMAIN. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-07-22 10:12:03 +02:00
W.C.A. Wijngaards f52a9e864b - Fix CVE-2026-44621, Libunbound applications configured with
'unwanted-reply-threshold' could eventually be abruptly
  terminated. Thanks to Qifan Zhang, Palo Alto Networks, for the
  report.
2026-07-22 10:11:26 +02:00
W.C.A. Wijngaards 13ec8d0f26 - Fix CVE-2026-42955, Extra fix for CVE-2026-40622 to also clamp
the TTL of A/AAAA records disallowing a one-time 'ghost domain'
  delegation renewal via glue records. Thanks to Qifan Zhang, Palo
  Alto Networks, for the report.
2026-07-22 10:11:04 +02:00
W.C.A. Wijngaards 27f22b8808 - Fix CVE-2026-41637, Degradation of resolution service from
improperly accounted client-terminated DNS-over-QUIC queries. Thanks
  to Qifan Zhang, Palo Alto Networks, for the report.
2026-07-22 10:10:24 +02:00
W.C.A. Wijngaards f54e0791ba - Fix CVE-2026-40691, Packet of death for DNSCrypt over TCP. Thanks
to Qifan Zhang, Palo Alto Networks, for the report. In addition,
  thanks to Trung Nguyen (@everping) of CyStack, for also reporting
  this issue.
2026-07-22 10:09:50 +02:00
W.C.A. Wijngaards 01dfd2f466 - Fix CVE-2026-32665, Remote DNS-over-QUIC denial of
service due to `quic-size` budget bypass. Thanks to N0zoM1z0
  (https://github.com/N0zoM1z0) for the report. In addition, thanks to
  Kunta Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University,
  for also reporting this issue. In addition, thanks to Qifan Zhang,
  Palo Alto Networks, for also reporting this issue. In addition,
  thanks to Xuanchao Xie, for also reporting this issue.
2026-07-22 10:09:26 +02:00
W.C.A. Wijngaards f157c691bb - Fix CVE-2026-14586, Assertion in libngtcp2 when under pressure
in high concurrency DNS-over-QUIC environments. Thanks to Kunta
  Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University,
  for the report.
2026-07-22 10:08:48 +02:00
W.C.A. Wijngaards fea0ff550b - Fix CVE-2026-46582, A wildcard replay, as another piece of data,
triggers poisoning in the serve expired reply path. Thanks to
  Qifan Zhang, Palo Alto Networks, for the report.
2026-07-22 10:07:52 +02:00
W.C.A. Wijngaards 87d59bfced Set version to 1.25.2 2026-07-22 10:06:30 +02:00
W.C.A. Wijngaards 25b2543e5e Changelog note for #1476
- Merge #1476 from petrvaganoff: ipsecmod: fix possible deref
  on null after reply_find_answer_rrset().
2026-07-21 11:57:14 +02:00
Petr VaganovandGitHub 7133e0d32a ipsecmod: fix possible deref on null after reply_find_answer_rrset() (#1476)
Return value of a function 'reply_find_answer_rrset' is dereferenced at
ipsecmod.c:438 without checking for NULL, but it is usually checked for
this function (10/12).

Found by the static analyzer Svace (ISP	RAS).

Signed-off-by: Petr Vaganov <petrvaganoff@gmail.com>
2026-07-21 11:56:29 +02:00
W.C.A. Wijngaards fac7584830 - Fix #1474: DoQ responses are never padded - pad-responses
does not apply to comm_doq (RFC 9250 §5.4 MUST).
2026-07-20 10:14:26 +02:00
W.C.A. Wijngaards 87f9258fb4 Changelog entry for #1475
- Merge #1475 from petrvaganoff: ipsecmod: fix deref on null
  in ipsecmod-whitelist after OOM.
2026-07-20 10:05:45 +02:00
Petr VaganovandGitHub a2fe5356b5 ipsecmod: fix deref on null in ipsecmod-whitelist after OOM (#1475)
DEREF_OF_NULL.RET.STAT Return value of a function 'rbtree_create'
is dereferenced at ipsecmod-whitelist.c:105 without checking for
NULL, but it is usually checked for this function (5/6).

In ipsecmod_whitelist_apply_cfg(), the return value of rbtree_create()
is not checked for NULL before being used.

Found by the static analyzer Svace (ISP	RAS).

Signed-off-by: Petr Vaganov <petrvaganoff@gmail.com>
2026-07-20 10:04:47 +02:00
W.C.A. Wijngaards ad9b12a863 - Fix unit test for malformed svcb for test on Windows. 2026-07-09 09:52:09 +02:00
W.C.A. Wijngaards 61ca4111a1 Changelog note and explanation comment for #1383
- Merge #1383 from jdek: Fix randomness generation on
  macOS/iOS under chroot.
2026-07-09 09:21:56 +02:00
J. DekkerandGitHub 71a971d70c - Fix randomness generation on macOS/iOS under chroot (#1383)
SecRandomCopyBytes() has existed since macOS 10.7 (2011) and iOS 2.0 (2008), and is the primary API for cryptographic random numbers.
2026-07-09 09:19:42 +02:00
W.C.A. Wijngaards 61d6c0e766 - auth-load-thread, implement active thread counter for auth load threads. 2026-07-07 17:21:16 +02:00
W.C.A. Wijngaards b4daa2d0fa - auth-load-thread, use define for constant for number of records before poll. 2026-07-07 16:26:42 +02:00
W.C.A. Wijngaards 425b701fb9 - auth-load-thread, fix memory leak on alloc failure when appending rrset
copy for ixfr main zone data copy.
2026-07-03 16:39:28 +02:00
W.C.A. Wijngaards 0a5cde80f1 - auth-load-thread, auth-task-threads: num config option that enables and
disables the auth load thread.
2026-07-03 14:03:15 +02:00
W.C.A. Wijngaards 58ede90fdb Merge branch 'master' into auth-load-thread 2026-07-02 15:28:24 +02:00
W.C.A. Wijngaards ba4f8478e6 Add changelog note for #1087, remove copyright line as discussed, and
compile fixes for newer local_zones_lookup, unused variable warnings
fixed, and also manual page description of the feature.
- Merge #1087: Overload `local_data_remove` to support removing
  specific records.
2026-07-02 15:04:51 +02:00
R. Christian McDonaldandGitHub 374a18cc5b Overload local_data_remove to support removing specific records (#1087)
Here we overload the `local_data_remove` control command to support
deleting specific records. Curently, this command deletes all records
for a given zone. The modification works by attempting to parse the
command argument first as a complete record and then as just a domain
name, if the first attempt failed.

This preserves the command's behavior, while also supporting removing
specific records from the zone tree.

Signed-off-by: R. Christian McDonald <rcm@rcm.sh>
2026-07-02 14:55:54 +02:00
W.C.A. Wijngaards 55ae8da032 - auth-load-thread, basic test and fixes so it works. 2026-07-02 11:10:06 +02:00
W.C.A. Wijngaards 6bd86df72e - auth-load-thread, simplify cleanup in end transfer load process. 2026-07-02 08:55:13 +02:00
W.C.A. Wijngaards 0efd3605cc Merge branch 'master' into auth-load-thread 2026-07-01 16:54:55 +02:00
W.C.A. Wijngaards a2f2f53ef9 - auth-load-thread, process end of successful transfer. 2026-07-01 16:54:36 +02:00
W.C.A. Wijngaards b5a03093f6 - auth-load-thread, check for quit during the processing. 2026-07-01 14:41:40 +02:00
W.C.A. Wijngaards 8eba898135 - auth-load-thread, process AXFR, by loading, swap in, delete of old. 2026-07-01 14:27:31 +02:00
W.C.A. Wijngaards 56f66de89f - auth-load-thread, process IXFR, by making a copy, adjust changes, swap in. 2026-07-01 13:05:19 +02:00
W.C.A. Wijngaards 2fbaee2255 - auth-load-thread, process transfer content and swap result back in. 2026-06-30 16:53:27 +02:00
W.C.A. Wijngaards f35561287a - iana portlist updated. 2026-06-30 12:38:33 +02:00
W.C.A. Wijngaards 672b9659cf - Fix #1469: dohclient: DoH POST missing content-length → :status
400 from strict resolvers (Cloudflare, Mullvad).
2026-06-30 12:14:00 +02:00
W.C.A. Wijngaards a122490461 - auth-load-thread, poll for quit and process load transfer end. 2026-06-29 16:52:20 +02:00
W.C.A. Wijngaards 7826b4f306 Merge branch 'master' into auth-load-thread 2026-06-29 16:00:01 +02:00
W.C.A. Wijngaards 380994219f - auth-load-thread, make and run auth load thread. 2026-06-26 17:11:12 +02:00
W.C.A. Wijngaards 153accb8de - auth-load-thread, put create_socketpair and sock_poll_timeout into
util/net_help.h
2026-06-26 15:22:08 +02:00
W.C.A. Wijngaards 7bb1c62263 - auth-load-thread, add authload.c to Makefile.in. 2026-06-26 14:27:12 +02:00
W.C.A. Wijngaards 1578b6e180 - auth-load-thread, add services/authload.c and services/authload.h 2026-06-26 14:00:04 +02:00
W.C.A. Wijngaards 1978add0cd - Merge #1467: daemon: fix DEREF_AFTER_NULL.EX.COND on
worker_init. This fixes error handling if the worker
  stat_timer allocation has an out of memory error. That
  makes the server not crash later, attempting to use it.
2026-06-26 13:44:27 +02:00
Petr VaganovandGitHub 6cbcea3ac7 daemon: fix DEREF_AFTER_NULL.EX.COND on worker_init (#1467)
Found by the static analyzer Svace (ISP RAS).

After having been compared to a NULL value at worker.c:2216,
pointer 'worker->stat_timer' is passed in call to function
'worker_restart_timer' at worker.c:2319,where it is
dereferenced at worker.c:2029.

Fix that stat_timer creation failure in worker_init does
not continue with a NULL timer that causes a crash later.

Signed-off-by: Petr Vaganov <petrvaganoff@gmail.com>
2026-06-26 13:42:29 +02:00
W.C.A. Wijngaards 65e23d4b6f - Merge #1465 from dag-erling: Add libunbound/remote.h. Add
a shared header containing prototypes for functions that
  both ends of a remote control connection need to implement.
2026-06-25 11:16:01 +02:00
Dag-Erling SmørgravandGitHub fbe41cdef9 Add libunbound/remote.h (#1465)
Add a shared header containing prototypes for functions that both ends
of a remote control connection need to implement.
2026-06-25 11:14:37 +02:00
W.C.A. Wijngaards 01a95108b3 - Fix warning about file_string_matches in unbound-checkconf. 2026-06-19 09:30:46 +02:00
W.C.A. Wijngaards f75d11821f - Fix to update github ci actions/checkout to v7. 2026-06-19 09:25:39 +02:00
W.C.A. Wijngaards 6aa5cfc903 - Fix for #1457: fix thread setname for thread start of
dnstap, and fast_reload.
2026-06-19 08:37:23 +02:00
Yorgos Thessalonikefs f6931c794e - Fix memory leak on DNAME 0TTL records. 2026-06-17 17:30:21 +02:00
W.C.A. Wijngaards 4c5082ad05 - Fix that fast_reload does not terminate the server if
random init for DNS cookies fails. The data is only random
  generated if cookies are enabled, and the random data
  is necessary. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-06-17 16:15:15 +02:00
W.C.A. Wijngaards 5fb892a097 - Fix that fast_reload does not terminate the server
on config read failure after malloc failure. Thanks to
  Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 16:10:48 +02:00
W.C.A. Wijngaards 55e9532d16 - Fix after malloc failure for stats, then it drains the pipe
so the internal messaging stays correct. Also it does
  not exit the server if stats pipe communication fails.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 16:05:45 +02:00
W.C.A. Wijngaards fff6657cea - Fix that fast_reload does not terminate the server
on malloc failure for dnstap, or if gethostname fails.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 16:02:21 +02:00
W.C.A. Wijngaards 45d1e75caf - Fix to check for malloc failure in rpz response create,
for nodata and nxdomain, so it does not crash later.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 15:59:29 +02:00
W.C.A. Wijngaards b806f16c8b - Fix to check the return value of auth_xfer_create
during fast_reload auth-zone add and change processing.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 15:57:30 +02:00
W.C.A. Wijngaards 8d3348c71b - Fix that malloc failure during edns subnet addrtree
insert is checked, so it does not crash later. Thanks to
  Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 15:55:33 +02:00
W.C.A. Wijngaards e2cc14681e - Fix that malloc failure for rpz_strip_nsdname is
checked and handled, so that it does not crash later.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 15:53:28 +02:00
W.C.A. Wijngaards 5ae979bb6e - Fix that on malloc failure during accept of TCP, the
socket is not left to cause a read event loop. It uses
  slow-accept to delay accepting new connections, if
  that fails it drops the new connections. When the tcp
  connection usage is full, it waits for 50msec, to allow
  existing queries to be resolved. Thanks to Qifan Zhang,
  Palo Alto Networks, for the report.
2026-06-17 15:37:04 +02:00
W.C.A. Wijngaards 8f2fbd66fc - Fix that malloc failure for ngtcp2_conn_server_new
cleans up reference that older ngtcp2 versions can leave.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 15:33:06 +02:00
W.C.A. Wijngaards b5909d8d22 - Fix that malloc failure in doq connection setup, does
not crash in doq connection delete later. Thanks to Qifan
  Zhang, Palo Alto Networks, for the report.
2026-06-17 15:29:48 +02:00
W.C.A. Wijngaards fa8e94f155 - Fix that malloc failure for new_local_rrset for RPZ qname
trigger RR insert does not crash. It does not link a
  partial RRset, and logs an error on failure, and cleans
  up the dname allocation. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-06-17 15:26:56 +02:00
W.C.A. Wijngaards cb5683aeae - Fix that malloc failure in dns64_inform_super does
not set up a half-built reply for cache store, that could
  lead to a crash. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-06-17 15:23:25 +02:00
W.C.A. Wijngaards c9715724ec - Fix that unbound-control auth_zone_reload stops the
server answering from the zone after a failure to read.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 15:20:22 +02:00
W.C.A. Wijngaards 78d9cfffd8 - Fix that malloc failure in auth-zone insert rr does
not create an empty node and does not cause an infinite
  loop. Thanks to Qifan Zhang, Palo Alto Networks, for
  the report.
2026-06-17 15:16:21 +02:00
W.C.A. Wijngaards b47b1d048d - Fix that unbound-checkconf checks if an auth-zone download
can overwrite another file, by filename collision.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 15:11:42 +02:00
W.C.A. Wijngaards 740952fb82 - Fix to remove debug from auth_transfer_limit test. 2026-06-17 11:38:24 +02:00
W.C.A. Wijngaards 5c550f4548 - Fix that after fast_reload the disown of the auth zone
transfer task cleans the chunk list. Also fix the
  auth_transfer_limit test to use a forwarder for each type
  of failure, so the one is not blocked by the other waiting.
2026-06-17 11:37:06 +02:00
W.C.A. Wijngaards 3d78cb8d9a - Fix for #1462: Fix that auth primary host name lookup
allows CNAMEs.
2026-06-16 11:13:47 +02:00
W.C.A. Wijngaards 1ab75c0043 - Fix after malloc failure the rrset_insert_rr in
localzone processing, during RPZ qname trigger processing,
  the RRset retains its previous data correcly. Thanks to
  Qifan Zhang, Palo Alto Networks, for the report.
2026-06-16 10:59:37 +02:00
W.C.A. Wijngaards bebc8d516b - Fix incorrect cleanup after an allocation failure for
a delegation point in a region. Thanks to Qifan Zhang,
  Palo Alto Networks, for the report.
2026-06-16 10:56:36 +02:00
W.C.A. Wijngaards a7debe7ff6 - Fix that after shared memory cannot be created, from
`shm-enable`, the server does not crash. Thanks to Qifan
  Zhang, Palo Alto Networks, for the report.
2026-06-16 10:53:40 +02:00
W.C.A. Wijngaards 215e3920ef - Fix that after malloc failure in find_tag_datas, the
local_alias is cleaned up. Thanks to Qifan Zhang, Palo
  Alto Networks, for the report.
2026-06-16 10:51:49 +02:00
W.C.A. Wijngaards aabf28aef5 - Fix incorrect cleanup after an allocation failure for
a delegation point. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-06-16 10:49:50 +02:00
W.C.A. Wijngaards aa09835c90 - Fix for neater solution to clear log thread id after
worker init failure. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-06-16 10:48:17 +02:00
W.C.A. Wijngaards 9b9e13b665 - Fix that libunbound pipe functions fail with error after
an event base is set. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-06-16 10:44:41 +02:00
W.C.A. Wijngaards f72e11ef5b - Fix locking in libunbound ub_ctx_set_event call.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-16 10:42:39 +02:00
W.C.A. Wijngaards a45e54555d - Fix that dnscrypt configuration does not crash, due to
inconsistency between secret and public keys. Also
  duplicate files are skipped. Thanks to Qifan Zhang, Palo
  Alto Networks, for the report.
2026-06-16 10:40:10 +02:00
W.C.A. Wijngaards 4693c00c9f - Fix that after malloc failure in RPZ load a half built
list does not crash later. The newly created RRset is
  linked after creation has succeeded. Thanks to Qifan Zhang,
  Palo Alto Networks, for the report.
2026-06-16 10:35:41 +02:00
W.C.A. Wijngaards 8fe23e0297 - Fix that for a zonefile only zone, if that file does not
exist on server start, the server continues to start with
  a warning log message. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-06-16 10:26:25 +02:00
W.C.A. Wijngaards 8557788699 - Fix that after malloc failure a half-built local_alias does
not crash the server. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-06-16 10:12:19 +02:00
W.C.A. Wijngaards 81a19ebeb3 - Fix that a signed wildcard NSEC, is checked before use,
so it does not allow insecure DS proofs inappropriately.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-16 10:09:00 +02:00
W.C.A. Wijngaards 299df5ec77 - Fix that dns64 does not ignore the forward-no-cache and
`stub-no-cache` options. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-06-16 09:52:46 +02:00
W.C.A. Wijngaards 6f9b6db7be - Fix that auth-zone, and RPZ zones, do not allow out-of-zone
records. These are records that are not under the zone apex.
  The out-of-zone records are dropped from the zone contents.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-16 09:48:10 +02:00
W.C.A. Wijngaards 96f15b9160 - Fix that a half-written trust anchor file does not crash
the server at runtime. It unlinks a wrong file from the list.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-16 09:45:10 +02:00
W.C.A. Wijngaards 159384c2a9 - Fix that when SVCB records cannot be written out, and
are written in unknown format, that the zone read allows
  such unknown format SVCB records. Thanks to Qifan Zhang,
  Palo Alto Networks, for the report.
2026-06-16 09:36:33 +02:00
W.C.A. Wijngaards 621fc91453 - Fix to disallow $INCLUDE for secondary zones. Start up
of server continues if a secondary zone fails to load.
  Failed loads clear the zone data, so there is no partial
  zone. Thanks to Qifan Zhang, Palo Alto Networks, for
  the report.
2026-06-16 09:30:52 +02:00
W.C.A. Wijngaards 543c49f76c - Fix that dns64 bypasses rpz-passthru rule during
synthesis. This restricted more than necessary. Thanks to
  Qifan Zhang, Palo Alto Networks, for the report.
2026-06-15 16:50:42 +02:00
W.C.A. Wijngaards d0a760a587 - Fix misconfigured ipsecmod hook causing path name
similarity with other file. The ipsecmod is changed for
  exec of the hook. The ipsecmod hook, if a script, has to
  start now with a line like `#!/bin/sh`. Thanks to Qifan
  Zhang, Palo Alto Networks, for the report.
2026-06-15 16:45:53 +02:00
W.C.A. Wijngaards f68cca4097 - Fix DNAME synthesis from cache that keeps use of 0TTL
entries in a sliding window. It did not surpass RRSIG
  expiry. Thanks to Qifan Zhang, Palo Alto Networks, for
  the report.
2026-06-15 16:39:34 +02:00
W.C.A. Wijngaards 3129357874 - Fix log of an aliased qname, to not use freed region
memory. Thanks to Qifan Zhang, Palo Alto Networks, for
  the report.
2026-06-15 16:34:17 +02:00
W.C.A. Wijngaards fc09352df6 - Fix that fast_reload does not terminate the server for
errors in config, for key files. Thanks to Qifan Zhang,
  Palo Alto Networks, for the report.
2026-06-15 16:31:37 +02:00
W.C.A. Wijngaards 06da5d45a3 - Fix integer overflow for very high values of
`sock-queue-timeout`. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-06-15 16:28:30 +02:00
W.C.A. Wijngaards 69524cadad - Fix erroneous DNS error report values after bogus AAAA
query caused error information that was not cleared by
  a successful A subquery. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-06-15 16:26:35 +02:00
W.C.A. Wijngaards 98e95d80e6 - Fix integer overflow in infra-cache-max-rtt calculation.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-15 16:22:50 +02:00
W.C.A. Wijngaards 2f8aa8a43a - Fix for fast_reload that removes an auth zone while its
lookups are in progress, for a primary name. Also after the
  change, it no longer picks up the old results. Thanks to
  Qifan Zhang, Palo Alto Networks, for the report.
2026-06-15 16:18:56 +02:00
W.C.A. Wijngaards 56e60e37ae - Fix that fast_reload when a zonemd verification lookup
it in progress with subnet loaded, deregisters the
  callback. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-06-15 16:16:50 +02:00
W.C.A. Wijngaards 8f5348ab47 - Fix that misconfigured iter-scrub-ns: 0 causes request
failures. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-06-15 16:04:24 +02:00
W.C.A. Wijngaards c5d693b21c - Fix buffer overflow when configured with lower than
default size and http transfer. Thanks to Qifan Zhang,
  Palo Alto Networks, for the report.
2026-06-15 16:01:51 +02:00
W.C.A. Wijngaards 27e3ac55b9 - Fix assertion failure for long HTTP header that fills
buffer. Thanks to Qifan Zhang, Palo Alto Networks, for
  the report.
2026-06-15 15:54:37 +02:00
W.C.A. Wijngaards 7879218773 Fix comment. 2026-06-15 15:53:00 +02:00
W.C.A. Wijngaards 1354624ba4 - Fix perform a full transfer every number of incremental
transfers, to stop increasing memory usage, for auth-zone
  and rpz zones. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-06-15 15:51:03 +02:00
W.C.A. Wijngaards 153f8d5353 - Fix to add max-transfer-size and max-transfer-time that
limit auth-zone and rpz transfer amount and time taken.
  Default is disabled. This hardens against unbounded
  transfers. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-06-15 15:45:03 +02:00
W.C.A. Wijngaards a1cecf7462 - Fix that for auth-zone and rpz zones the allow-notify
addresses and netblocks are available from start, and
  fix the probe step skip.
2026-06-12 11:48:14 +02:00
W.C.A. Wijngaards e2dac8a00a - Fix compile for OpenSSL 1.0.2 and before in server cleanup. 2026-06-11 17:31:19 +02:00
W.C.A. Wijngaards ecd41bef27 - Fix #1437: Fix compile with OpenSSL 4.0.1. 2026-06-11 17:31:01 +02:00
W.C.A. Wijngaards fd2131687a - Fix for #1306: configure checks if the ngtcp2_crypto_ossl
header file is available, and prints an error otherwise.
2026-06-11 11:43:46 +02:00
W.C.A. Wijngaards 316b9ab4fc - Fix for #1306: configure detects specifically the call to
SSL_set_quic_tls_early_data_enabled and
  SSL_set_quic_early_data_enabled, so the correct one is used.
2026-06-11 11:04:50 +02:00
W.C.A. Wijngaards d45daaf313 - Fix warnings with gcc in compat/inet_pton.c. 2026-06-10 16:43:41 +02:00
W.C.A. Wijngaards db1c6d6557 - Fix pythonmod script read for numeric overflow. 2026-06-10 11:24:02 +02:00
W.C.A. Wijngaards e7a713a525 - Fix unit test for ecs to check for malloc success. 2026-06-09 16:41:37 +02:00
Alex BandandGitHub 39e67508c9 change mailing list to forum 2026-06-08 21:48:04 +02:00
W.C.A. Wijngaards 3eab974ca2 - Fix that dns64 cleans up the allocated message if the adjust
routines fail, and checks if there is a reply before cache
  store, also unbound checks if A and AAAA are malformed
  for auth-zones. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-06-03 14:56:20 +02:00
W.C.A. Wijngaards b1d1dcb3b6 - Fix that dump_cache has a larger buffer for records,
and it checks that an owner name does not collide with BADRR
  on the input, and changes verbosity on the log of failure in
  rrset to string.  Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-06-03 14:51:16 +02:00
W.C.A. Wijngaards 10cb62aca2 - Fix that validation canonicalization of domain names
in rdata checks for buffer bounds. Thanks to Qifan Zhang,
  Palo Alto Networks, for the report.
2026-06-03 14:48:06 +02:00
W.C.A. Wijngaards 6da73aba38 - Fix fast_reload for when a ZONEMD lookup is in progress.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-03 14:42:47 +02:00
W.C.A. Wijngaards 1b1b9626ee - Fix negative cache NSEC3 nodata proof, to use the correct
message size. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-06-03 14:40:17 +02:00
W.C.A. Wijngaards 8bc074043a - Fix PROXYv2 header read and consume, it checks the header
size. Thanks to Qifan Zhang, Palo Alto Networks for
  the report.
2026-06-03 14:37:37 +02:00
W.C.A. Wijngaards 04a6322aa4 - Fix ipset module to use larger domain name buffers, and
check buffer lengths. Thanks to Qifan Zhang, Palo Alto
  Networks for the report.
2026-06-03 14:35:06 +02:00
W.C.A. Wijngaards 5748f518d1 - Fix that quotation and escaping works the same in auth-zone
url content, as in the zonefile read. Thanks to Qifan Zhang,
  Palo Alto Networks for the report.
2026-06-03 14:32:14 +02:00
W.C.A. Wijngaards d05eff4d54 - Fix parse of svcbparam ech, it had incorrect length. Thanks
to Qifan Zhang, Palo Alto Networks for the report.
2026-06-03 14:05:48 +02:00
Yorgos Thessalonikefs 4544eaa4cc - Fix const as reported by newest compiler warnings. 2026-06-03 14:00:04 +02:00
W.C.A. Wijngaards 5d0770d0ad - Fix negative cache to work with NSEC3 records without salt.
Thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern
  Polytechnical University, for the report.
2026-06-03 13:56:31 +02:00
W.C.A. Wijngaards 7f4beb846e - Fix that the processing of class responses does not have
a heap use-after-free. That could happen if at least two
  distinct classes are configured for resolution. Thanks
  to Qifan Zhang, Palo Alto Networks for the report.
  In addition, thanks to Xin Wang, Jiapeng Li, and Jiajia
  Liu, Northwestern Polytechnical University, for also
  reporting this.
2026-06-03 12:14:30 +02:00
W.C.A. Wijngaards 8e8c04e1b9 - Fix unit test to check for new icannbundle.pem. 2026-05-29 12:10:40 +02:00
W.C.A. Wijngaards bf0da2ed21 - Update icannbundle.pem certificates in unbound-anchor. It
has the public keys for 2009 to 2029 and for 2025 to 2045.
2026-05-29 12:10:07 +02:00
W.C.A. Wijngaards 670ece06df - iana portlist updated. 2026-05-29 11:54:40 +02:00
W.C.A. Wijngaards 9e41903be8 - Fix header_seen detection for trust anchor files, so that it
detects the id line.
2026-05-29 11:54:03 +02:00
W.C.A. Wijngaards 57f92cc97e - Fix #1457: race condition causes segfault when starting
threads.
2026-05-28 09:34:04 +02:00
W.C.A. Wijngaards c0741ccc68 - Fix analyzer warning in mesh_new_client. 2026-05-27 16:03:15 +02:00
W.C.A. Wijngaards fb2745024a - Fix that validator caps number of ANY RRsets it can
validate, and the wait timer is shortened. Thanks to Qifan
  Zhang, Palo Alto Networks, for the report.
2026-05-27 13:38:10 +02:00
W.C.A. Wijngaards 0c15ddd133 - Fix ipset module for name too long checks, race conditions
on local name buffer, and for socket close race condition.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-05-27 13:34:32 +02:00
W.C.A. Wijngaards b53504049c - Fix that dns64 with subnetcache does not write ECS scoped
answers to global cache. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-05-27 13:31:11 +02:00
W.C.A. Wijngaards a5324e58eb - Fix, in depth, for respip rewrite of dns64 responses. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
2026-05-27 13:28:41 +02:00
W.C.A. Wijngaards 963cd68535 - Fix manual to document ratelimit, that it is for target
nameservers for a domain, and keeps queries limited. Thanks
  to Qifan Zhang, Palo Alto Networks, for the report.
2026-05-27 13:24:44 +02:00
W.C.A. Wijngaards 047df73887 - Fix to decrement the per-netblock tcp connection limits, so
it keeps usable. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-05-27 13:20:35 +02:00
W.C.A. Wijngaards d2e1ea7d19 - Fix to reset the tcp-timeout before applying a load based
reduction. Thanks to Qifan Zhang, Palo Alto Networks, for the
  report.
2026-05-27 13:17:35 +02:00
W.C.A. Wijngaards fbbe95ba5b - Fix that msgencode insert_query has the correct assertion,
for a local_alias. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-05-27 12:20:04 +02:00
W.C.A. Wijngaards 758c649611 - Fix that the ratelimit is decremented on successful
referrals. Thanks to Qifan Zhang, Palo Alto Networks, for
  the report.
2026-05-27 12:16:23 +02:00
W.C.A. Wijngaards a23f95f620 - Fix to limit the DSNS per-label walk in the iterator. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
2026-05-27 12:12:39 +02:00
W.C.A. Wijngaards 5363570df0 - Fix for autotrust state-file line overflow, that can give
hold-down bypass. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-05-27 12:09:01 +02:00
W.C.A. Wijngaards 368857a45b - Fix for mesh new client and mesh new callback to rollback the
added address, tcp mesh state and callback when there is a failure
  to initialize. This fixes the mesh accounting of reply addresses.
  Thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern
  Polytechnical University, for the report
2026-05-26 16:20:11 +02:00
W.C.A. Wijngaards 40b16d0565 - Fix for signed same-owner CNAME and ordinary RRset responses.
Thanks to Xin Wang and Jiajia Liu, Northwestern Polytechnical
  University, for the report.
2026-05-20 16:30:37 +02:00
W.C.A. Wijngaards 08e901a1ac - Fix cleaning up DoH session. The same query can be on multiple
streams in a session. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-05-20 15:04:12 +02:00
W.C.A. Wijngaards bc703c9129 - Fix lame server detection, for selfpointed glue records.
Thanks to Shuhan Zhang, Dan Li, and Baojun Liu from Tsinghua
  University for the report.
2026-05-20 15:01:42 +02:00
W.C.A. Wijngaards 9ce52de6c1 - Fix in depth for serve-expired responses from cachedb, that it
does not store bogus. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-05-20 14:58:26 +02:00
W.C.A. Wijngaards b3aa262477 Remove the debug file. 2026-05-20 12:43:08 +02:00
W.C.A. Wijngaards 25e112c674 - Unit test for CVE-2026-44390. 2026-05-20 12:42:04 +02:00
W.C.A. Wijngaards 0d2282d551 - Unit test for CVE-2026-42960. 2026-05-20 12:40:32 +02:00
W.C.A. Wijngaards b5f21f4165 - Unit test for CVE-2026-40622. 2026-05-20 12:37:17 +02:00
W.C.A. Wijngaards d357935f66 - Unit test for CVE-2026-42959. 2026-05-20 12:35:38 +02:00
W.C.A. Wijngaards 9d2e0f1c02 - Unit test for CVE-2026-42944. 2026-05-20 12:34:16 +02:00
W.C.A. Wijngaards b46ff5c18e - Unit test for CVE-2026-33278. 2026-05-20 12:32:43 +02:00
W.C.A. Wijngaards f597105800 - Tag for 1.25.1 release, it contains the security fixes on 1.25.0.
the code repository continues with in addition the previous fixes,
  for 1.25.2.
2026-05-20 11:31:53 +02:00
W.C.A. Wijngaards 3692517a41 Merge branch 'branch-1.25.1' 2026-05-20 11:19:56 +02:00
W.C.A. Wijngaards 75b6dba593 - Fix CVE-2026-44608, Use after free and crash in RPZ code. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
2026-05-20 10:22:52 +02:00
W.C.A. Wijngaards 138fb48eac Changelog entry.
- Fix CVE-2026-44390, Unbounded name compression in certain cases
  causes degradation of service. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-05-20 10:22:10 +02:00
W.C.A. Wijngaards dae7a37974 - Fix CVE-2026-44390, Unbounded name compression in certain cases
causes degradation of service. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-05-20 10:21:26 +02:00
W.C.A. Wijngaards 8ae4b4545d - Fix CVE-2026-42960, Possible cache poisoning attack while following
delegation. Thanks to TaoFei Guo from Peking University, Yang Luo
  and JianJun Chen, Tsinghua University, for the report.
2026-05-20 10:20:45 +02:00
W.C.A. Wijngaards c343fff3a4 - Fix CVE-2026-42923, Degradation of service with unbounded NSEC3
hash calculations. Thanks to Qifan Zhang, Palo Alto Networks, for
  the report.
2026-05-20 10:20:02 +02:00
W.C.A. Wijngaards a794c87578 - Fix CVE-2026-42534, Jostle logic bypass degrades resolution
performance. Thanks to Qifan Zhang, Palo Alto Networks, for the
  report.
2026-05-20 10:19:08 +02:00
W.C.A. Wijngaards ef5ca84360 - Fix CVE-2026-41292, Parsing a long list of incoming EDNS options
degrades performance. Thanks to GitHub user 'N0zoM1z0', also Qifan
  Zhang from Palo Alto Networks, for the report.
2026-05-20 10:18:23 +02:00
W.C.A. Wijngaards 8d8fa42266 - Fix CVE-2026-40622, "Ghost domain name" variant. Thanks to Qifan
Zhang, Palo Alto Networks, for the report.
2026-05-20 10:16:18 +02:00
W.C.A. Wijngaards a587535c5d - Fix CVE-2026-32792, Packet of death with DNSCrypt. Thanks to Andrew
Griffiths from 'calif.io' for the report.
2026-05-20 10:15:30 +02:00
W.C.A. Wijngaards 94d5babaee - Fix CVE-2026-42959, Crash during DNSSEC validation of malicious
content. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-05-20 10:14:32 +02:00
W.C.A. Wijngaards fe946ba4e9 - Fix CVE-2026-42944, Heap overflow and crash with multiple nsid,
cookie, padding EDNS options. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-05-20 10:13:55 +02:00
W.C.A. Wijngaards 6a31e470f8 - Fix CVE-2026-33278, Possible remote code execution during DNSSEC
validation. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-05-20 10:13:08 +02:00
W.C.A. Wijngaards e577695aeb Set version to 1.25.1 for release. 2026-05-20 10:11:15 +02:00
W.C.A. Wijngaards a58bd6cb1e - Fix for mixed class referrals, the resolver uses the query
class. Thanks to Xin Wang and Jiajia Liu, Northwestern
  Polytechnical University, for the report.
2026-05-18 16:42:39 +02:00
W.C.A. Wijngaards 4bad944ae4 - Fix DNSKEY size calculation for noncanonical RSA DNSKEYs
with leading zeroes for n. Thanks to Xin Wang and Jiajia Liu,
  Northwestern Polytechnical University, for the report.
2026-05-15 16:22:59 +02:00
W.C.A. Wijngaards 594182f109 - Fix DNSSEC validation with libnettle for noncanonical RSA
DNSKEYs with leading zeroes for n. Thanks to Xin Wang and
  Jiajia Liu, Northwestern Polytechnical University, for
  the report.
2026-05-15 16:20:52 +02:00
W.C.A. Wijngaards 53c261cb33 - Fix for allocation-failure hardening of rrset cache wildcard
storage and canonical NSEC owner replacement. Thanks to Xin
  Wang and Jiajia Liu, Northwestern Polytechnical University,
  for the report.
2026-05-15 16:00:58 +02:00
W.C.A. Wijngaards 8703d9a5be - Fix that for dns64 answers, the AAAA query is checked to be
DNSSEC validated, when DNSSEC is enabled. This improves
  the RFC6147 conformance of Unbound. Thanks to Xin Wang
  and Jiajia Liu, Northwestern Polytechnical University, for
  the report. In addition, thanks to Qifan Zhang, Palo Alto
  Networks, for reporting it.
2026-05-15 15:43:18 +02:00
W.C.A. Wijngaards aa9f1e68ff - Fix val_find_DS for robustness, to check the result of
packet_rrset_copy_region before using it. Thanks to Xin Wang
  and Jiajia Liu, Northwestern Polytechnical University, for
  the report.
2026-05-15 14:27:18 +02:00
W.C.A. Wijngaards 84a4f556b1 Merge branch 'master' of github.com:NLnetLabs/unbound 2026-05-15 08:42:40 +02:00
W.C.A. Wijngaards 5b166dbf0a - Fix man page entry for so-sndbuf, it is for responses sent out. 2026-05-15 08:42:27 +02:00
Yorgos Thessalonikefs 9e2233b821 - Fix another comment for EDNS fallback buffer size. 2026-05-14 13:11:17 +02:00
Yorgos Thessalonikefs 13716dc8be - Fix comment and verbose logging for EDNS fallback buffer size. 2026-05-11 20:39:38 +02:00
W.C.A. Wijngaards 8ada1bd88d - Fix to relax assertions after the TTL 0 handling change.
This relaxes an assertion in cachedb (it fails instead),
  and for packet_rrset_copy_region.
2026-05-08 10:09:41 +02:00
W.C.A. Wijngaards 9c80bb9fb0 - Fix to clean up log ids after a failure to start a worker thread. 2026-05-07 14:42:29 +02:00
W.C.A. Wijngaards 33e2863862 - Fix for Heap Out-of-Bounds Write via size_t-to-int Truncation
in setup_if() - outside_network_create(). This fixes that
  large values for num_ports do not overflow and create
  invalid references after integer truncation. Thanks
  to Karnakar Reddy (@karnakarreddi) for the report.
2026-05-07 14:40:48 +02:00
W.C.A. Wijngaards 027e23a11d - iana portlist updated. 2026-05-01 11:25:49 +02:00
W.C.A. Wijngaards 62e8db1c6a - Fix windows 64bit build for libssp dependency. 2026-04-29 15:06:09 +02:00
W.C.A. Wijngaards 581b2f31bc - tag for 1.25.0. The code repository continues with 1.25.1 in
development.
2026-04-29 12:10:23 +02:00
226 changed files with 20243 additions and 2002 deletions
+1 -1
View File
@@ -173,7 +173,7 @@ jobs:
cross_platform_config: "--enable-debug --disable-flto --with-libevent --disable-static"
steps:
- uses: actions/checkout@v6
- uses: actions/checkout@v7
with:
submodules: false
persist-credentials: false
+1 -1
View File
@@ -12,7 +12,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/checkout@v7
with:
persist-credentials: false
- name: configure
+4 -2
View File
@@ -125,7 +125,7 @@ services/localzone.c services/mesh.c services/modstack.c services/view.c \
services/rpz.c util/rfc_1982.c \
services/outbound_list.c services/outside_network.c util/alloc.c \
util/config_file.c util/configlexer.c util/configparser.c \
util/shm_side/shm_main.c services/authzone.c \
util/shm_side/shm_main.c services/authzone.c services/authload.c \
util/fptr_wlist.c util/locks.c util/log.c util/mini_event.c util/module.c \
util/netevent.c util/net_help.c util/random.c util/rbtree.c util/regional.c \
util/rtt.c util/siphash.c util/edns.c util/storage/dnstree.c util/storage/lookup3.c \
@@ -152,7 +152,8 @@ autotrust.lo val_anchor.lo rpz.lo rfc_1982.lo proxy_protocol.lo \
validator.lo val_kcache.lo val_kentry.lo val_neg.lo val_nsec3.lo val_nsec.lo \
val_secalgo.lo val_sigcrypt.lo val_utils.lo dns64.lo $(CACHEDB_OBJ) authzone.lo \
$(SUBNET_OBJ) $(PYTHONMOD_OBJ) $(CHECKLOCK_OBJ) $(DNSTAP_OBJ) $(DNSCRYPT_OBJ) \
$(IPSECMOD_OBJ) $(IPSET_OBJ) $(DYNLIBMOD_OBJ) respip.lo timeval_func.lo
$(IPSECMOD_OBJ) $(IPSET_OBJ) $(DYNLIBMOD_OBJ) respip.lo timeval_func.lo \
authload.lo
COMMON_OBJ_WITHOUT_UB_EVENT=$(COMMON_OBJ_WITHOUT_NETCALL) netevent.lo listen_dnsport.lo \
outside_network.lo
COMMON_OBJ=$(COMMON_OBJ_WITHOUT_UB_EVENT) ub_event.lo
@@ -721,6 +722,7 @@ depend:
ipset.lo ipset.o: $(srcdir)/ipset/ipset.c
doqclient.lo doqclient.o: $(srcdir)/testcode/doqclient.c
unitdoq.lo unitdoq.o: $(srcdir)/testcode/unitdoq.c
authload.lo authload.o: $(srcdir)/services/authload.c
# Dependencies
dns.lo dns.o: $(srcdir)/services/cache/dns.c config.h $(srcdir)/iterator/iter_delegpt.h $(srcdir)/util/log.h \
+1 -1
View File
@@ -10,7 +10,7 @@ Unbound is a validating, recursive, caching DNS resolver. It is designed to be
fast and lean and incorporates modern features based on open standards. If you
have any feedback, we would love to hear from you. Dont hesitate to
[create an issue on Github](https://github.com/NLnetLabs/unbound/issues/new)
or post a message on the [Unbound mailing list](https://lists.nlnetlabs.nl/mailman/listinfo/unbound-users).
or post a message on our [community forum](https://community.nlnetlabs.nl/).
You can learn more about Unbound by reading our
[documentation](https://unbound.docs.nlnetlabs.nl/).
+17 -2
View File
@@ -87,7 +87,7 @@
# modified version of the Autoconf Macro, you may extend this special
# exception to the GPL to apply to your modified version as well.
#serial 31
#serial 32
AU_ALIAS([ACX_PTHREAD], [AX_PTHREAD])
AC_DEFUN([AX_PTHREAD], [
@@ -249,7 +249,22 @@ AS_IF([test "x$ax_pthread_clang" = "xyes"],
# correctly enabled
case $host_os in
darwin* | hpux* | linux* | osf* | solaris*)
solaris*)
# Solaris 11.4 introduced XPG7 support and did away with the need for
# _REENTRANT.
AC_EGREP_CPP([AX_PTHREAD_SOLARIS__REENTRANT],
[
# undef _XOPEN_SOURCE
# include <sys/feature_tests.h>
# if _XOPEN_VERSION < 700
AX_PTHREAD_SOLARIS__REENTRANT
# endif
],
[ax_pthread_check_macro="_REENTRANT"],
[ax_pthread_check_macro="--"])
;;
darwin* | hpux* | linux* | osf*)
ax_pthread_check_macro="_REENTRANT"
;;
+11
View File
@@ -401,6 +401,12 @@ prep_data(struct module_qstate* qstate, struct sldns_buffer* buf)
FLAGS_GET_RCODE(qstate->return_msg->rep->flags) !=
LDNS_RCODE_YXDOMAIN)
return 0;
/* Do not persist data the validator has not yet seen, or has rejected.
* Otherwise an expired blob could maybe reach clients via
* serve-expired. */
if(qstate->env->need_to_validate &&
qstate->return_msg->rep->security == sec_status_bogus)
return 0;
/* We don't store the reply if its TTL is 0. This is probably coming
* from upstream and it is not meant to be stored. */
if(qstate->return_msg->rep->ttl == 0)
@@ -863,6 +869,11 @@ cachedb_handle_query(struct module_qstate* qstate,
return;
}
/* No 0TTL answers escaping from external cache. */
if(qstate->return_msg->rep->ttl == 0) {
qstate->return_msg = NULL;
qstate->ext_state[id] = module_wait_module;
return;
}
log_assert(qstate->return_msg->rep->ttl > 0);
qstate->is_cachedb_answer = 1;
/* we are done with the query */
+9 -382
View File
@@ -20,398 +20,25 @@
* http://man.openbsd.org/getentropy.2
*/
#include <TargetConditionals.h>
#include <sys/types.h>
#include <sys/param.h>
#include <sys/ioctl.h>
#include <sys/resource.h>
#include <sys/syscall.h>
#include <sys/sysctl.h>
#include <sys/statvfs.h>
#include <sys/socket.h>
#include <sys/mount.h>
#include <sys/mman.h>
#include <sys/stat.h>
#include <sys/time.h>
#include <stdlib.h>
#include <stdint.h>
#include <stdio.h>
#include <termios.h>
#include <fcntl.h>
#include <signal.h>
#include <string.h>
/* Modified to use SecRandomCopyBytes. It is from macOS 10.7 (2011) and
* iOS 2.0 (2008), and is the primary API for cryptographic random numbers. */
#include <errno.h>
#include <unistd.h>
#include <time.h>
#include <mach/mach_time.h>
#include <mach/mach_host.h>
#include <mach/host_info.h>
#if TARGET_OS_OSX
#include <sys/socketvar.h>
#include <sys/vmmeter.h>
#endif
#include <netinet/in.h>
#include <netinet/tcp.h>
#if TARGET_OS_OSX
#include <netinet/udp.h>
#include <netinet/ip_var.h>
#include <netinet/tcp_var.h>
#include <netinet/udp_var.h>
#endif
#include <CommonCrypto/CommonDigest.h>
#define SHA512_Update(a, b, c) (CC_SHA512_Update((a), (b), (c)))
#define SHA512_Init(xxx) (CC_SHA512_Init((xxx)))
#define SHA512_Final(xxx, yyy) (CC_SHA512_Final((xxx), (yyy)))
#define SHA512_CTX CC_SHA512_CTX
#define SHA512_DIGEST_LENGTH CC_SHA512_DIGEST_LENGTH
#define REPEAT 5
#define min(a, b) (((a) < (b)) ? (a) : (b))
#define HX(a, b) \
do { \
if ((a)) \
HD(errno); \
else \
HD(b); \
} while (0)
#define HR(x, l) (SHA512_Update(&ctx, (char *)(x), (l)))
#define HD(x) (SHA512_Update(&ctx, (char *)&(x), sizeof (x)))
#define HF(x) (SHA512_Update(&ctx, (char *)&(x), sizeof (void*)))
#include <Security/SecRandom.h>
int getentropy(void *buf, size_t len);
static int getentropy_urandom(void *buf, size_t len);
static int getentropy_fallback(void *buf, size_t len);
int
getentropy(void *buf, size_t len)
{
int ret = -1;
if (len > 256) {
errno = EIO;
return (-1);
goto error;
}
/*
* Try to get entropy with /dev/urandom
*
* This can fail if the process is inside a chroot or if file
* descriptors are exhausted.
*/
ret = getentropy_urandom(buf, len);
if (ret != -1)
return (ret);
/*
* Entropy collection via /dev/urandom and sysctl have failed.
*
* No other API exists for collecting entropy, and we have
* no failsafe way to get it on OSX that is not sensitive
* to resource exhaustion.
*
* We have very few options:
* - Even syslog_r is unsafe to call at this low level, so
* there is no way to alert the user or program.
* - Cannot call abort() because some systems have unsafe
* corefiles.
* - Could raise(SIGKILL) resulting in silent program termination.
* - Return EIO, to hint that arc4random's stir function
* should raise(SIGKILL)
* - Do the best under the circumstances....
*
* This code path exists to bring light to the issue that OSX
* does not provide a failsafe API for entropy collection.
*
* We hope this demonstrates that OSX should consider
* providing a new failsafe API which works in a chroot or
* when file descriptors are exhausted.
*/
#undef FAIL_INSTEAD_OF_TRYING_FALLBACK
#ifdef FAIL_INSTEAD_OF_TRYING_FALLBACK
raise(SIGKILL);
#endif
ret = getentropy_fallback(buf, len);
if (ret != -1)
return (ret);
if (SecRandomCopyBytes(kSecRandomDefault, len, buf) == errSecSuccess) {
return 0;
}
error:
errno = EIO;
return (ret);
}
static int
getentropy_urandom(void *buf, size_t len)
{
struct stat st;
size_t i;
int fd, flags;
int save_errno = errno;
start:
flags = O_RDONLY;
#ifdef O_NOFOLLOW
flags |= O_NOFOLLOW;
#endif
#ifdef O_CLOEXEC
flags |= O_CLOEXEC;
#endif
fd = open("/dev/urandom", flags, 0);
if (fd == -1) {
if (errno == EINTR)
goto start;
goto nodevrandom;
}
#ifndef O_CLOEXEC
fcntl(fd, F_SETFD, fcntl(fd, F_GETFD) | FD_CLOEXEC);
#endif
/* Lightly verify that the device node looks sane */
if (fstat(fd, &st) == -1 || !S_ISCHR(st.st_mode)) {
close(fd);
goto nodevrandom;
}
for (i = 0; i < len; ) {
size_t wanted = len - i;
ssize_t ret = read(fd, (char *)buf + i, wanted);
if (ret == -1) {
if (errno == EAGAIN || errno == EINTR)
continue;
close(fd);
goto nodevrandom;
}
i += ret;
}
close(fd);
errno = save_errno;
return (0); /* satisfied */
nodevrandom:
errno = EIO;
return (-1);
}
#if TARGET_OS_OSX
static int tcpmib[] = { CTL_NET, AF_INET, IPPROTO_TCP, TCPCTL_STATS };
static int udpmib[] = { CTL_NET, AF_INET, IPPROTO_UDP, UDPCTL_STATS };
static int ipmib[] = { CTL_NET, AF_INET, IPPROTO_IP, IPCTL_STATS };
#endif
static int kmib[] = { CTL_KERN, KERN_USRSTACK };
static int hwmib[] = { CTL_HW, HW_USERMEM };
static int
getentropy_fallback(void *buf, size_t len)
{
uint8_t results[SHA512_DIGEST_LENGTH];
int save_errno = errno, e, pgs = getpagesize(), faster = 0, repeat;
static int cnt;
struct timespec ts;
struct timeval tv;
struct rusage ru;
sigset_t sigset;
struct stat st;
SHA512_CTX ctx;
static pid_t lastpid;
pid_t pid;
size_t i, ii, m;
char *p;
#if TARGET_OS_OSX
struct tcpstat tcpstat;
struct udpstat udpstat;
struct ipstat ipstat;
#endif
u_int64_t mach_time;
unsigned int idata;
void *addr;
pid = getpid();
if (lastpid == pid) {
faster = 1;
repeat = 2;
} else {
faster = 0;
lastpid = pid;
repeat = REPEAT;
}
for (i = 0; i < len; ) {
int j;
SHA512_Init(&ctx);
for (j = 0; j < repeat; j++) {
HX((e = gettimeofday(&tv, NULL)) == -1, tv);
if (e != -1) {
cnt += (int)tv.tv_sec;
cnt += (int)tv.tv_usec;
}
mach_time = mach_absolute_time();
HD(mach_time);
ii = sizeof(addr);
HX(sysctl(kmib, sizeof(kmib) / sizeof(kmib[0]),
&addr, &ii, NULL, 0) == -1, addr);
ii = sizeof(idata);
HX(sysctl(hwmib, sizeof(hwmib) / sizeof(hwmib[0]),
&idata, &ii, NULL, 0) == -1, idata);
#if TARGET_OS_OSX
ii = sizeof(tcpstat);
HX(sysctl(tcpmib, sizeof(tcpmib) / sizeof(tcpmib[0]),
&tcpstat, &ii, NULL, 0) == -1, tcpstat);
ii = sizeof(udpstat);
HX(sysctl(udpmib, sizeof(udpmib) / sizeof(udpmib[0]),
&udpstat, &ii, NULL, 0) == -1, udpstat);
ii = sizeof(ipstat);
HX(sysctl(ipmib, sizeof(ipmib) / sizeof(ipmib[0]),
&ipstat, &ii, NULL, 0) == -1, ipstat);
#endif
HX((pid = getpid()) == -1, pid);
HX((pid = getsid(pid)) == -1, pid);
HX((pid = getppid()) == -1, pid);
HX((pid = getpgid(0)) == -1, pid);
HX((e = getpriority(0, 0)) == -1, e);
if (!faster) {
ts.tv_sec = 0;
ts.tv_nsec = 1;
(void) nanosleep(&ts, NULL);
}
HX(sigpending(&sigset) == -1, sigset);
HX(sigprocmask(SIG_BLOCK, NULL, &sigset) == -1,
sigset);
HF(getentropy); /* an addr in this library */
HF(printf); /* an addr in libc */
p = (char *)&p;
HD(p); /* an addr on stack */
p = (char *)&errno;
HD(p); /* the addr of errno */
if (i == 0) {
struct sockaddr_storage ss;
struct statvfs stvfs;
struct termios tios;
struct statfs stfs;
socklen_t ssl;
off_t off;
/*
* Prime-sized mappings encourage fragmentation;
* thus exposing some address entropy.
*/
struct mm {
size_t npg;
void *p;
} mm[] = {
{ 17, MAP_FAILED }, { 3, MAP_FAILED },
{ 11, MAP_FAILED }, { 2, MAP_FAILED },
{ 5, MAP_FAILED }, { 3, MAP_FAILED },
{ 7, MAP_FAILED }, { 1, MAP_FAILED },
{ 57, MAP_FAILED }, { 3, MAP_FAILED },
{ 131, MAP_FAILED }, { 1, MAP_FAILED },
};
for (m = 0; m < sizeof mm/sizeof(mm[0]); m++) {
HX(mm[m].p = mmap(NULL,
mm[m].npg * pgs,
PROT_READ|PROT_WRITE,
MAP_PRIVATE|MAP_ANON, -1,
(off_t)0), mm[m].p);
if (mm[m].p != MAP_FAILED) {
size_t mo;
/* Touch some memory... */
p = mm[m].p;
mo = cnt %
(mm[m].npg * pgs - 1);
p[mo] = 1;
cnt += (int)((long)(mm[m].p)
/ pgs);
}
/* Check cnts and times... */
mach_time = mach_absolute_time();
HD(mach_time);
cnt += (int)mach_time;
HX((e = getrusage(RUSAGE_SELF,
&ru)) == -1, ru);
if (e != -1) {
cnt += (int)ru.ru_utime.tv_sec;
cnt += (int)ru.ru_utime.tv_usec;
}
}
for (m = 0; m < sizeof mm/sizeof(mm[0]); m++) {
if (mm[m].p != MAP_FAILED)
munmap(mm[m].p, mm[m].npg * pgs);
mm[m].p = MAP_FAILED;
}
HX(stat(".", &st) == -1, st);
HX(statvfs(".", &stvfs) == -1, stvfs);
HX(statfs(".", &stfs) == -1, stfs);
HX(stat("/", &st) == -1, st);
HX(statvfs("/", &stvfs) == -1, stvfs);
HX(statfs("/", &stfs) == -1, stfs);
HX((e = fstat(0, &st)) == -1, st);
if (e == -1) {
if (S_ISREG(st.st_mode) ||
S_ISFIFO(st.st_mode) ||
S_ISSOCK(st.st_mode)) {
HX(fstatvfs(0, &stvfs) == -1,
stvfs);
HX(fstatfs(0, &stfs) == -1,
stfs);
HX((off = lseek(0, (off_t)0,
SEEK_CUR)) < 0, off);
}
if (S_ISCHR(st.st_mode)) {
HX(tcgetattr(0, &tios) == -1,
tios);
} else if (S_ISSOCK(st.st_mode)) {
memset(&ss, 0, sizeof ss);
ssl = sizeof(ss);
HX(getpeername(0,
(void *)&ss, &ssl) == -1,
ss);
}
}
HX((e = getrusage(RUSAGE_CHILDREN,
&ru)) == -1, ru);
if (e != -1) {
cnt += (int)ru.ru_utime.tv_sec;
cnt += (int)ru.ru_utime.tv_usec;
}
} else {
/* Subsequent hashes absorb previous result */
HD(results);
}
HX((e = gettimeofday(&tv, NULL)) == -1, tv);
if (e != -1) {
cnt += (int)tv.tv_sec;
cnt += (int)tv.tv_usec;
}
HD(cnt);
}
SHA512_Final(results, &ctx);
memcpy((char *)buf + i, results, min(sizeof(results), len - i));
i += min(sizeof(results), len - i);
}
explicit_bzero(&ctx, sizeof ctx);
explicit_bzero(results, sizeof results);
errno = save_errno;
return (0); /* satisfied */
return -1;
}
+3 -10
View File
@@ -59,10 +59,7 @@ static int inet_pton6 (const char *src, uint8_t *dst);
* Paul Vixie, 1996.
*/
int
inet_pton(af, src, dst)
int af;
const char *src;
void *dst;
inet_pton(int af, const char *src, void *dst)
{
switch (af) {
case AF_INET:
@@ -91,9 +88,7 @@ inet_pton(af, src, dst)
* Paul Vixie, 1996.
*/
static int
inet_pton4(src, dst)
const char *src;
uint8_t *dst;
inet_pton4(const char *src, uint8_t *dst)
{
static const char digits[] = "0123456789";
int saw_digit, octets, ch;
@@ -145,9 +140,7 @@ inet_pton4(src, dst)
* Paul Vixie, 1996.
*/
static int
inet_pton6(src, dst)
const char *src;
uint8_t *dst;
inet_pton6(const char *src, uint8_t *dst)
{
static const char xdigits_l[] = "0123456789abcdef",
xdigits_u[] = "0123456789ABCDEF";
+32
View File
@@ -31,6 +31,9 @@
/* Whether daemon is deprecated */
#undef DEPRECATED_DAEMON
/* Whether X509_NAME_get_text_by_NID is deprecated */
#undef DEPRECATED_X509_NAME_GET_TEXT_BY_NID
/* Deprecate RSA 1024 bit length, makes that an unsupported key */
#undef DEPRECATE_RSA_1024
@@ -60,6 +63,9 @@
/* Define to 1 if you have the <arpa/inet.h> header file. */
#undef HAVE_ARPA_INET_H
/* Define to 1 if you have the `ASN1_STRING_get0_data' function. */
#undef HAVE_ASN1_STRING_GET0_DATA
/* Whether the C compiler accepts the "fallthrough" attribute */
#undef HAVE_ATTR_FALLTHROUGH
@@ -140,6 +146,10 @@
to 0 if you don't. */
#undef HAVE_DECL_NGTCP2_CRYPTO_ENCRYPT_CB
/* Define to 1 if you have the declaration of `ngtcp2_crypto_ossl_ctx_new',
and to 0 if you don't. */
#undef HAVE_DECL_NGTCP2_CRYPTO_OSSL_CTX_NEW
/* Define to 1 if you have the declaration of `NID_ED25519', and to 0 if you
don't. */
#undef HAVE_DECL_NID_ED25519
@@ -289,6 +299,12 @@
/* Define to 1 if you have the `FIPS_mode' function. */
#undef HAVE_FIPS_MODE
/* Define to 1 if you have the `fnmatch' function. */
#undef HAVE_FNMATCH
/* Define to 1 if you have the <fnmatch.h> header file. */
#undef HAVE_FNMATCH_H
/* Define to 1 if you have the `fork' function. */
#undef HAVE_FORK
@@ -513,6 +529,9 @@
/* Define to 1 if you have the <openssl/bn.h> header file. */
#undef HAVE_OPENSSL_BN_H
/* Define to 1 if you have the `OPENSSL_cleanup' function. */
#undef HAVE_OPENSSL_CLEANUP
/* Define to 1 if you have the `OPENSSL_config' function. */
#undef HAVE_OPENSSL_CONFIG
@@ -685,9 +704,16 @@
/* Define to 1 if you have the `SSL_is_quic' function. */
#undef HAVE_SSL_IS_QUIC
/* Define to 1 if you have the `SSL_set1_dnsname' function. */
#undef HAVE_SSL_SET1_DNSNAME
/* Define to 1 if you have the `SSL_set1_host' function. */
#undef HAVE_SSL_SET1_HOST
/* Define to 1 if you have the `SSL_set_quic_tls_early_data_enabled' function.
*/
#undef HAVE_SSL_SET_QUIC_TLS_EARLY_DATA_ENABLED
/* Define to 1 if you have the <stdarg.h> header file. */
#undef HAVE_STDARG_H
@@ -852,6 +878,12 @@
/* Define to 1 if you have the <ws2tcpip.h> header file. */
#undef HAVE_WS2TCPIP_H
/* Define to 1 if you have the `X509_get_key_usage' function. */
#undef HAVE_X509_GET_KEY_USAGE
/* Define to 1 if you have the `X509_NAME_get_text_by_NID' function. */
#undef HAVE_X509_NAME_GET_TEXT_BY_NID
/* Define to 1 if you have the `X509_VERIFY_PARAM_set1_host' function. */
#undef HAVE_X509_VERIFY_PARAM_SET1_HOST
Vendored
+175 -14
View File
@@ -1,6 +1,6 @@
#! /bin/sh
# Guess values for system-dependent variables and create Makefiles.
# Generated by GNU Autoconf 2.71 for unbound 1.25.0.
# Generated by GNU Autoconf 2.71 for unbound 1.26.1.
#
# Report bugs to <unbound-bugs@nlnetlabs.nl or https://github.com/NLnetLabs/unbound/issues>.
#
@@ -622,8 +622,8 @@ MAKEFLAGS=
# Identity of this package.
PACKAGE_NAME='unbound'
PACKAGE_TARNAME='unbound'
PACKAGE_VERSION='1.25.0'
PACKAGE_STRING='unbound 1.25.0'
PACKAGE_VERSION='1.26.1'
PACKAGE_STRING='unbound 1.26.1'
PACKAGE_BUGREPORT='unbound-bugs@nlnetlabs.nl or https://github.com/NLnetLabs/unbound/issues'
PACKAGE_URL=''
@@ -1513,7 +1513,7 @@ if test "$ac_init_help" = "long"; then
# Omit some internal or obsolete options to make the list less imposing.
# This message is too long to be a string in the A/UX 3.1 sh.
cat <<_ACEOF
\`configure' configures unbound 1.25.0 to adapt to many kinds of systems.
\`configure' configures unbound 1.26.1 to adapt to many kinds of systems.
Usage: $0 [OPTION]... [VAR=VALUE]...
@@ -1579,7 +1579,7 @@ fi
if test -n "$ac_init_help"; then
case $ac_init_help in
short | recursive ) echo "Configuration of unbound 1.25.0:";;
short | recursive ) echo "Configuration of unbound 1.26.1:";;
esac
cat <<\_ACEOF
@@ -1832,7 +1832,7 @@ fi
test -n "$ac_init_help" && exit $ac_status
if $ac_init_version; then
cat <<\_ACEOF
unbound configure 1.25.0
unbound configure 1.26.1
generated by GNU Autoconf 2.71
Copyright (C) 2021 Free Software Foundation, Inc.
@@ -2489,7 +2489,7 @@ cat >config.log <<_ACEOF
This file contains any messages produced by compilers while
running configure, to aid debugging if configure makes a mistake.
It was created by unbound $as_me 1.25.0, which was
It was created by unbound $as_me 1.26.1, which was
generated by GNU Autoconf 2.71. Invocation command line was
$ $0$ac_configure_args_raw
@@ -3251,13 +3251,13 @@ ac_compiler_gnu=$ac_cv_c_compiler_gnu
UNBOUND_VERSION_MAJOR=1
UNBOUND_VERSION_MINOR=25
UNBOUND_VERSION_MINOR=26
UNBOUND_VERSION_MICRO=0
UNBOUND_VERSION_MICRO=1
LIBUNBOUND_CURRENT=9
LIBUNBOUND_REVISION=36
LIBUNBOUND_REVISION=40
LIBUNBOUND_AGE=1
# 1.0.0 had 0:12:0
# 1.0.1 had 0:13:0
@@ -3361,6 +3361,10 @@ LIBUNBOUND_AGE=1
# 1.24.1 had 9:34:1
# 1.24.2 had 9:35:1
# 1.25.0 had 9:36:1
# 1.25.1 had 9:37:1
# 1.25.2 had 9:38:1
# 1.26.0 had 9:39:1
# 1.26.1 had 9:40:1
# Current -- the number of the binary API that we're implementing
# Revision -- which iteration of the implementation of the binary
@@ -16003,6 +16007,13 @@ if test "x$ac_cv_header_glob_h" = xyes
then :
printf "%s\n" "#define HAVE_GLOB_H 1" >>confdefs.h
fi
ac_fn_c_check_header_compile "$LINENO" "fnmatch.h" "ac_cv_header_fnmatch_h" "$ac_includes_default
"
if test "x$ac_cv_header_fnmatch_h" = xyes
then :
printf "%s\n" "#define HAVE_FNMATCH_H 1" >>confdefs.h
fi
ac_fn_c_check_header_compile "$LINENO" "grp.h" "ac_cv_header_grp_h" "$ac_includes_default
"
@@ -18405,7 +18416,31 @@ fi
# correctly enabled
case $host_os in
darwin* | hpux* | linux* | osf* | solaris*)
solaris*)
# Solaris 11.4 introduced XPG7 support and did away with the need for
# _REENTRANT.
cat confdefs.h - <<_ACEOF >conftest.$ac_ext
/* end confdefs.h. */
# undef _XOPEN_SOURCE
# include <sys/feature_tests.h>
# if _XOPEN_VERSION < 700
AX_PTHREAD_SOLARIS__REENTRANT
# endif
_ACEOF
if (eval "$ac_cpp conftest.$ac_ext") 2>&5 |
$EGREP "AX_PTHREAD_SOLARIS__REENTRANT" >/dev/null 2>&1
then :
ax_pthread_check_macro="_REENTRANT"
else $as_nop
ax_pthread_check_macro="--"
fi
rm -rf conftest*
;;
darwin* | hpux* | linux* | osf*)
ax_pthread_check_macro="_REENTRANT"
;;
@@ -21059,6 +21094,12 @@ then :
printf "%s\n" "#define HAVE_BIO_SET_CALLBACK_EX 1" >>confdefs.h
fi
ac_fn_c_check_func "$LINENO" "OPENSSL_cleanup" "ac_cv_func_OPENSSL_cleanup"
if test "x$ac_cv_func_OPENSSL_cleanup" = xyes
then :
printf "%s\n" "#define HAVE_OPENSSL_CLEANUP 1" >>confdefs.h
fi
# these check_funcs need -lssl
@@ -21087,6 +21128,24 @@ if test "x$ac_cv_func_SSL_get0_peername" = xyes
then :
printf "%s\n" "#define HAVE_SSL_GET0_PEERNAME 1" >>confdefs.h
fi
ac_fn_c_check_func "$LINENO" "SSL_set1_dnsname" "ac_cv_func_SSL_set1_dnsname"
if test "x$ac_cv_func_SSL_set1_dnsname" = xyes
then :
printf "%s\n" "#define HAVE_SSL_SET1_DNSNAME 1" >>confdefs.h
fi
ac_fn_c_check_func "$LINENO" "X509_get_key_usage" "ac_cv_func_X509_get_key_usage"
if test "x$ac_cv_func_X509_get_key_usage" = xyes
then :
printf "%s\n" "#define HAVE_X509_GET_KEY_USAGE 1" >>confdefs.h
fi
ac_fn_c_check_func "$LINENO" "ASN1_STRING_get0_data" "ac_cv_func_ASN1_STRING_get0_data"
if test "x$ac_cv_func_ASN1_STRING_get0_data" = xyes
then :
printf "%s\n" "#define HAVE_ASN1_STRING_GET0_DATA 1" >>confdefs.h
fi
ac_fn_c_check_func "$LINENO" "X509_VERIFY_PARAM_set1_host" "ac_cv_func_X509_VERIFY_PARAM_set1_host"
if test "x$ac_cv_func_X509_VERIFY_PARAM_set1_host" = xyes
@@ -21131,6 +21190,54 @@ then :
fi
ac_fn_c_check_func "$LINENO" "X509_NAME_get_text_by_NID" "ac_cv_func_X509_NAME_get_text_by_NID"
if test "x$ac_cv_func_X509_NAME_get_text_by_NID" = xyes
then :
printf "%s\n" "#define HAVE_X509_NAME_GET_TEXT_BY_NID 1" >>confdefs.h
fi
if test $ac_cv_func_X509_NAME_get_text_by_NID = yes; then
{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking if X509_NAME_get_text_by_NID is deprecated" >&5
printf %s "checking if X509_NAME_get_text_by_NID is deprecated... " >&6; }
cache=`echo X509_NAME_get_text_by_NID | sed 'y%.=/+-%___p_%'`
if eval test \${cv_cc_deprecated_$cache+y}
then :
printf %s "(cached) " >&6
else $as_nop
echo '
#include "openssl/x509.h"
' >conftest.c
echo 'void f(void){
(void)X509_NAME_get_text_by_NID(NULL, 0, NULL, 0); }' >>conftest.c
if test -z "`$CC $CPPFLAGS $CFLAGS -c conftest.c 2>&1 | grep -e deprecated -e unavailable`"; then
eval "cv_cc_deprecated_$cache=no"
else
eval "cv_cc_deprecated_$cache=yes"
fi
rm -f conftest conftest.o conftest.c
fi
if eval "test \"`echo '$cv_cc_deprecated_'$cache`\" = yes"; then
{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: yes" >&5
printf "%s\n" "yes" >&6; }
printf "%s\n" "#define DEPRECATED_X509_NAME_GET_TEXT_BY_NID 1" >>confdefs.h
:
else
{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5
printf "%s\n" "no" >&6; }
:
fi
fi
LIBS="$BAKLIBS"
ac_fn_check_decl "$LINENO" "SSL_COMP_get_compression_methods" "ac_cv_have_decl_SSL_COMP_get_compression_methods" "
@@ -22637,6 +22744,24 @@ then :
printf "%s\n" "#define USE_NGTCP2_CRYPTO_OSSL 1" >>confdefs.h
ac_fn_check_decl "$LINENO" "ngtcp2_crypto_ossl_ctx_new" "ac_cv_have_decl_ngtcp2_crypto_ossl_ctx_new" "$ac_includes_default
#include <ngtcp2/ngtcp2_crypto_ossl.h>
" "$ac_c_undeclared_builtin_options" "CFLAGS"
if test "x$ac_cv_have_decl_ngtcp2_crypto_ossl_ctx_new" = xyes
then :
ac_have_decl=1
else $as_nop
ac_have_decl=0
fi
printf "%s\n" "#define HAVE_DECL_NGTCP2_CRYPTO_OSSL_CTX_NEW $ac_have_decl" >>confdefs.h
if test $ac_have_decl = 1
then :
else $as_nop
as_fn_error $? "No declaration of ngtcp2_crypto_ossl_ctx_new in the ngtcp2_crypto_ossl header file. Perhaps the ngtcp2_crypto_ossl devel header files need to be installed." "$LINENO" 5
fi
else $as_nop
@@ -22816,6 +22941,13 @@ else $as_nop
fi
done
ac_fn_c_check_func "$LINENO" "SSL_set_quic_tls_early_data_enabled" "ac_cv_func_SSL_set_quic_tls_early_data_enabled"
if test "x$ac_cv_func_SSL_set_quic_tls_early_data_enabled" = xyes
then :
printf "%s\n" "#define HAVE_SSL_SET_QUIC_TLS_EARLY_DATA_ENABLED 1" >>confdefs.h
fi
LIBS="$BAKLIBS"
ac_fn_c_check_type "$LINENO" "struct ngtcp2_version_cid" "ac_cv_type_struct_ngtcp2_version_cid" "$ac_includes_default
@@ -22921,6 +23053,29 @@ printf "%s\n" "no" >&6; }
fi
rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext
ac_fn_check_decl "$LINENO" "CLOCK_MONOTONIC
" "ac_cv_have_decl_CLOCK_MONOTONIC_________" "$ac_includes_default
#ifdef TIME_WITH_SYS_TIME
# include <sys/time.h>
# include <time.h>
#else
# ifdef HAVE_SYS_TIME_H
# include <sys/time.h>
# else
# include <time.h>
# endif
#endif
" "$ac_c_undeclared_builtin_options" "CFLAGS"
if test "x$ac_cv_have_decl_CLOCK_MONOTONIC_________" = xyes
then :
else $as_nop
as_fn_error $? "ngtcp2 for QUIC needs at least CLOCK_MONOTONIC on the system" "$LINENO" 5
fi
fi
# set static linking for uninstalled libraries if requested
@@ -23755,6 +23910,12 @@ if test "x$ac_cv_func_glob" = xyes
then :
printf "%s\n" "#define HAVE_GLOB 1" >>confdefs.h
fi
ac_fn_c_check_func "$LINENO" "fnmatch" "ac_cv_func_fnmatch"
if test "x$ac_cv_func_fnmatch" = xyes
then :
printf "%s\n" "#define HAVE_FNMATCH 1" >>confdefs.h
fi
ac_fn_c_check_func "$LINENO" "initgroups" "ac_cv_func_initgroups"
if test "x$ac_cv_func_initgroups" = xyes
@@ -25551,7 +25712,7 @@ printf "%s\n" "#define MAXSYSLOGMSGLEN 10240" >>confdefs.h
version=1.25.0
version=1.26.1
{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for build time" >&5
printf %s "checking for build time... " >&6; }
@@ -26081,7 +26242,7 @@ cat >>$CONFIG_STATUS <<\_ACEOF || ac_write_fail=1
# report actual input values of CONFIG_FILES etc. instead of their
# values after options handling.
ac_log="
This file was extended by unbound $as_me 1.25.0, which was
This file was extended by unbound $as_me 1.26.1, which was
generated by GNU Autoconf 2.71. Invocation command line was
CONFIG_FILES = $CONFIG_FILES
@@ -26149,7 +26310,7 @@ ac_cs_config_escaped=`printf "%s\n" "$ac_cs_config" | sed "s/^ //; s/'/'\\\\\\\\
cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1
ac_cs_config='$ac_cs_config_escaped'
ac_cs_version="\\
unbound config.status 1.25.0
unbound config.status 1.26.1
configured by $0, generated by GNU Autoconf 2.71,
with options \\"\$ac_cs_config\\"
+38 -7
View File
@@ -11,15 +11,15 @@ sinclude(dnscrypt/dnscrypt.m4)
# must be numbers. ac_defun because of later processing
m4_define([VERSION_MAJOR],[1])
m4_define([VERSION_MINOR],[25])
m4_define([VERSION_MICRO],[0])
m4_define([VERSION_MINOR],[26])
m4_define([VERSION_MICRO],[1])
AC_INIT([unbound],m4_defn([VERSION_MAJOR]).m4_defn([VERSION_MINOR]).m4_defn([VERSION_MICRO]),[unbound-bugs@nlnetlabs.nl or https://github.com/NLnetLabs/unbound/issues],[unbound])
AC_SUBST(UNBOUND_VERSION_MAJOR, [VERSION_MAJOR])
AC_SUBST(UNBOUND_VERSION_MINOR, [VERSION_MINOR])
AC_SUBST(UNBOUND_VERSION_MICRO, [VERSION_MICRO])
LIBUNBOUND_CURRENT=9
LIBUNBOUND_REVISION=36
LIBUNBOUND_REVISION=40
LIBUNBOUND_AGE=1
# 1.0.0 had 0:12:0
# 1.0.1 had 0:13:0
@@ -123,6 +123,10 @@ LIBUNBOUND_AGE=1
# 1.24.1 had 9:34:1
# 1.24.2 had 9:35:1
# 1.25.0 had 9:36:1
# 1.25.1 had 9:37:1
# 1.25.2 had 9:38:1
# 1.26.0 had 9:39:1
# 1.26.1 had 9:40:1
# Current -- the number of the binary API that we're implementing
# Revision -- which iteration of the implementation of the binary
@@ -481,7 +485,7 @@ PKG_PROG_PKG_CONFIG
fi
# Checks for header files.
AC_CHECK_HEADERS([stdarg.h stdbool.h netinet/in.h netinet/tcp.h sys/param.h sys/select.h sys/socket.h sys/un.h sys/uio.h sys/resource.h arpa/inet.h syslog.h netdb.h sys/wait.h pwd.h glob.h grp.h login_cap.h winsock2.h ws2tcpip.h endian.h sys/endian.h libkern/OSByteOrder.h sys/ipc.h sys/shm.h ifaddrs.h poll.h],,, [AC_INCLUDES_DEFAULT])
AC_CHECK_HEADERS([stdarg.h stdbool.h netinet/in.h netinet/tcp.h sys/param.h sys/select.h sys/socket.h sys/un.h sys/uio.h sys/resource.h arpa/inet.h syslog.h netdb.h sys/wait.h pwd.h glob.h fnmatch.h grp.h login_cap.h winsock2.h ws2tcpip.h endian.h sys/endian.h libkern/OSByteOrder.h sys/ipc.h sys/shm.h ifaddrs.h poll.h],,, [AC_INCLUDES_DEFAULT])
# net/if.h portability for Darwin see:
# https://www.gnu.org/software/autoconf/manual/autoconf-2.69/html_node/Header-Portability.html
AC_CHECK_HEADERS([net/if.h],,, [
@@ -1078,12 +1082,19 @@ else
AC_MSG_RESULT([no])
fi
AC_CHECK_HEADERS([openssl/conf.h openssl/engine.h openssl/bn.h openssl/dh.h openssl/dsa.h openssl/rsa.h openssl/core_names.h openssl/param_build.h],,, [AC_INCLUDES_DEFAULT])
AC_CHECK_FUNCS([OPENSSL_config EVP_sha1 EVP_sha256 EVP_sha512 FIPS_mode EVP_default_properties_is_fips_enabled EVP_MD_CTX_new OpenSSL_add_all_digests OPENSSL_init_crypto EVP_cleanup ENGINE_cleanup ERR_load_crypto_strings CRYPTO_cleanup_all_ex_data ERR_free_strings RAND_cleanup DSA_SIG_set0 EVP_dss1 EVP_DigestVerify EVP_aes_256_cbc EVP_EncryptInit_ex HMAC_Init_ex CRYPTO_THREADID_set_callback EVP_MAC_CTX_set_params OSSL_PARAM_BLD_new BIO_set_callback_ex])
AC_CHECK_FUNCS([OPENSSL_config EVP_sha1 EVP_sha256 EVP_sha512 FIPS_mode EVP_default_properties_is_fips_enabled EVP_MD_CTX_new OpenSSL_add_all_digests OPENSSL_init_crypto EVP_cleanup ENGINE_cleanup ERR_load_crypto_strings CRYPTO_cleanup_all_ex_data ERR_free_strings RAND_cleanup DSA_SIG_set0 EVP_dss1 EVP_DigestVerify EVP_aes_256_cbc EVP_EncryptInit_ex HMAC_Init_ex CRYPTO_THREADID_set_callback EVP_MAC_CTX_set_params OSSL_PARAM_BLD_new BIO_set_callback_ex OPENSSL_cleanup])
# these check_funcs need -lssl
BAKLIBS="$LIBS"
LIBS="-lssl $LIBS"
AC_CHECK_FUNCS([OPENSSL_init_ssl SSL_CTX_set_security_level SSL_set1_host SSL_get0_peername X509_VERIFY_PARAM_set1_host SSL_CTX_set_ciphersuites SSL_CTX_set_tlsext_ticket_key_evp_cb SSL_CTX_set_alpn_select_cb SSL_get0_alpn_selected SSL_CTX_set_alpn_protos SSL_get1_peer_certificate])
AC_CHECK_FUNCS([OPENSSL_init_ssl SSL_CTX_set_security_level SSL_set1_host SSL_get0_peername SSL_set1_dnsname X509_get_key_usage ASN1_STRING_get0_data X509_VERIFY_PARAM_set1_host SSL_CTX_set_ciphersuites SSL_CTX_set_tlsext_ticket_key_evp_cb SSL_CTX_set_alpn_select_cb SSL_get0_alpn_selected SSL_CTX_set_alpn_protos SSL_get1_peer_certificate])
AC_CHECK_FUNCS([X509_NAME_get_text_by_NID])
if test $ac_cv_func_X509_NAME_get_text_by_NID = yes; then
ACX_FUNC_DEPRECATED([X509_NAME_get_text_by_NID], [
(void)X509_NAME_get_text_by_NID(NULL, 0, NULL, 0);], [
#include "openssl/x509.h"
])
fi
LIBS="$BAKLIBS"
AC_CHECK_DECLS([SSL_COMP_get_compression_methods,sk_SSL_COMP_pop_free,SSL_CTX_set_ecdh_auto,SSL_CTX_set_tmp_ecdh], [], [], [
@@ -1702,6 +1713,9 @@ if test x_$withval = x_yes -o x_$withval != x_no; then
AC_CHECK_LIB([ngtcp2_crypto_ossl], [ngtcp2_crypto_encrypt_cb], [
LIBS="$LIBS -lngtcp2_crypto_ossl"
AC_DEFINE(USE_NGTCP2_CRYPTO_OSSL, 1, [Define this to use ngtcp2_crypto_ossl.])
AC_CHECK_DECLS([ngtcp2_crypto_ossl_ctx_new], [], [AC_MSG_ERROR([No declaration of ngtcp2_crypto_ossl_ctx_new in the ngtcp2_crypto_ossl header file. Perhaps the ngtcp2_crypto_ossl devel header files need to be installed.])], [AC_INCLUDES_DEFAULT
#include <ngtcp2/ngtcp2_crypto_ossl.h>
])
], [
AC_CHECK_LIB([ngtcp2_crypto_openssl], [ngtcp2_crypto_encrypt_cb], [ LIBS="$LIBS -lngtcp2_crypto_openssl" ], [
AC_CHECK_LIB([ngtcp2_crypto_quictls], [ngtcp2_crypto_encrypt_cb], [ LIBS="$LIBS -lngtcp2_crypto_quictls" ])
@@ -1713,6 +1727,7 @@ if test x_$withval = x_yes -o x_$withval != x_no; then
BAKLIBS="$LIBS"
LIBS="-lssl $LIBS"
AC_CHECK_FUNCS([SSL_is_quic], [], [AC_MSG_ERROR([No QUIC support detected in OpenSSL. Need OpenSSL version with QUIC support to enable DNS over QUIC with libngtcp2.])])
AC_CHECK_FUNCS([SSL_set_quic_tls_early_data_enabled])
LIBS="$BAKLIBS"
AC_CHECK_TYPES([struct ngtcp2_version_cid, ngtcp2_encryption_level],,,[AC_INCLUDES_DEFAULT
@@ -1734,6 +1749,22 @@ if test x_$withval = x_yes -o x_$withval != x_no; then
AC_MSG_RESULT(no)
])
AC_CHECK_DECL([CLOCK_MONOTONIC]
, []
, [AC_MSG_ERROR([ngtcp2 for QUIC needs at least CLOCK_MONOTONIC on the system])]
, [AC_INCLUDES_DEFAULT
#ifdef TIME_WITH_SYS_TIME
# include <sys/time.h>
# include <time.h>
#else
# ifdef HAVE_SYS_TIME_H
# include <sys/time.h>
# else
# include <time.h>
# endif
#endif
])
fi
# set static linking for uninstalled libraries if requested
@@ -1910,7 +1941,7 @@ AC_LINK_IFELSE([AC_LANG_PROGRAM([
AC_MSG_RESULT(no))
AC_SEARCH_LIBS([setusercontext], [util])
AC_CHECK_FUNCS([tzset sigprocmask fcntl getpwnam endpwent getrlimit setrlimit setsid chroot kill chown sleep usleep random srandom recvmsg sendmsg writev socketpair glob initgroups strftime localtime_r setusercontext _beginthreadex endservent endprotoent fsync shmget accept4 getifaddrs if_nametoindex poll gettid])
AC_CHECK_FUNCS([tzset sigprocmask fcntl getpwnam endpwent getrlimit setrlimit setsid chroot kill chown sleep usleep random srandom recvmsg sendmsg writev socketpair glob fnmatch initgroups strftime localtime_r setusercontext _beginthreadex endservent endprotoent fsync shmget accept4 getifaddrs if_nametoindex poll gettid])
AC_CHECK_FUNCS([setresuid],,[AC_CHECK_FUNCS([setreuid])])
AC_CHECK_FUNCS([setresgid],,[AC_CHECK_FUNCS([setregid])])
+2 -2
View File
@@ -99,7 +99,7 @@ static void
dump_rrset_line(struct config_strlist_head* txt, struct ub_packed_rrset_key* k,
time_t now, size_t i)
{
char s[65535];
char s[65535*4+2048];
if(!packed_rr_to_string(k, i, now, s, sizeof(s))) {
spool_txt_string(txt, "BADRR\n");
return;
@@ -455,7 +455,7 @@ load_rr(RES* ssl, sldns_buffer* buf, struct regional* region,
/* read the line */
if(!ssl_read_buf(ssl, buf))
return 0;
if(strncmp((char*)sldns_buffer_begin(buf), "BADRR\n", 6) == 0) {
if(strcmp((char*)sldns_buffer_begin(buf), "BADRR") == 0) {
*go_on = 0;
return 1;
}
+50 -15
View File
@@ -79,12 +79,14 @@
#include "util/tcp_conn_limit.h"
#include "util/edns.h"
#include "services/listen_dnsport.h"
#include "services/outside_network.h"
#include "services/cache/rrset.h"
#include "services/cache/infra.h"
#include "services/localzone.h"
#include "services/view.h"
#include "services/modstack.h"
#include "services/authzone.h"
#include "services/authload.h"
#include "util/module.h"
#include "util/random.h"
#include "util/tube.h"
@@ -216,7 +218,8 @@ setup_listen_sslctx(void** ctx, int is_dot, int is_doh,
(cfg->tls_session_ticket_keys.first &&
cfg->tls_session_ticket_keys.first->str[0] != 0),
is_dot, is_doh, cfg->tls_protocols))) {
fatal_exit("could not set up listen SSL_CTX");
log_err("could not set up listen SSL_CTX");
*ctx = NULL;
}
}
#endif /* HAVE_SSL */
@@ -258,7 +261,8 @@ void* daemon_setup_listen_quic_sslctx(struct daemon* daemon,
pem += strlen(chroot);
if(!(ctx = quic_sslctx_create(key, pem, NULL))) {
fatal_exit("could not set up quic SSL_CTX");
log_err("could not set up quic SSL_CTX");
return NULL;
}
return ctx;
}
@@ -276,8 +280,10 @@ void* daemon_setup_connect_dot_sslctx(struct daemon* daemon,
bundle += strlen(chroot);
if(!(ctx = connect_sslctx_create(NULL, NULL, bundle,
cfg->tls_win_cert)))
fatal_exit("could not set up connect SSL_CTX");
cfg->tls_win_cert))) {
log_err("could not set up connect SSL_CTX");
return NULL;
}
return ctx;
}
#endif /* HAVE_SSL */
@@ -307,16 +313,22 @@ daemon_setup_sslctxs(struct daemon* daemon, struct config_file* cfg)
}
daemon->listen_dot_sslctx = daemon_setup_listen_dot_sslctx(
daemon, cfg);
if(!daemon->listen_dot_sslctx)
fatal_exit("Could not set up listen dot sslctx");
#ifdef HAVE_NGHTTP2_NGHTTP2_H
if(cfg_has_https(cfg)) {
daemon->listen_doh_sslctx =
daemon_setup_listen_doh_sslctx(daemon, cfg);
if(!daemon->listen_doh_sslctx)
fatal_exit("Could not set up listen doh sslctx");
}
#endif
#ifdef HAVE_NGTCP2
if(cfg_has_quic(cfg)) {
daemon->listen_quic_sslctx =
daemon_setup_listen_quic_sslctx(daemon, cfg);
if(!daemon->listen_quic_sslctx)
fatal_exit("Could not set up listen quic sslctx");
}
#endif /* HAVE_NGTCP2 */
@@ -349,6 +361,8 @@ daemon_setup_sslctxs(struct daemon* daemon, struct config_file* cfg)
}
daemon->connect_dot_sslctx = daemon_setup_connect_dot_sslctx(
daemon, cfg);
if(!daemon->connect_dot_sslctx)
fatal_exit("could not setup connect dot sslctx");
#else /* HAVE_SSL */
(void)daemon;(void)cfg;
#endif /* HAVE_SSL */
@@ -577,6 +591,17 @@ daemon_init(void)
free(daemon);
return NULL;
}
if(!(daemon->auth_load_info = auth_load_info_create())) {
edns_strings_delete(daemon->env->edns_strings);
auth_zones_delete(daemon->env->auth_zones);
acl_list_delete(daemon->acl_interface);
acl_list_delete(daemon->acl);
tcl_list_delete(daemon->tcl);
edns_known_options_delete(daemon->env);
free(daemon->env);
free(daemon);
return NULL;
}
return daemon;
}
@@ -813,6 +838,10 @@ daemon_create_workers(struct daemon* daemon)
fatal_exit("out of memory during daemon init");
numport = daemon_get_shufport(daemon, shufport);
verbose(VERB_ALGO, "total of %d outgoing ports available", numport);
if(!(daemon->shared_ports = shared_ports_create(daemon->cfg->out_ifs,
daemon->cfg->num_out_ifs, daemon->cfg->do_ip4,
daemon->cfg->do_ip6, shufport, numport)))
fatal_exit("could not setup shared ports: out of memory");
#ifdef HAVE_NGTCP2
if (cfg_has_quic(daemon->cfg)) {
@@ -843,10 +872,7 @@ daemon_create_workers(struct daemon* daemon)
#endif
}
for(i=0; i<daemon->num; i++) {
if(!(daemon->workers[i] = worker_create(daemon, i,
shufport+numport*i/daemon->num,
numport*(i+1)/daemon->num - numport*i/daemon->num)))
/* the above is not ports/numthr, due to rounding */
if(!(daemon->workers[i] = worker_create(daemon, i)))
fatal_exit("could not create worker");
}
/* create per-worker alloc caches if not reusing existing ones. */
@@ -919,13 +945,14 @@ thread_start(void* arg)
{
struct worker* worker = (struct worker*)arg;
int port_num = 0;
log_assert(worker->thr_id);
set_log_thread_id(worker, worker->daemon->cfg);
{
char name[16]; /* seems to be the safest size between
different OSes */
snprintf(name, sizeof(name), "unbound/%u", worker->thread_num);
ub_thread_setname(worker->thr_id, name);
/* worker->thr_id can be written to after the thread was made
* by the creating thread, so this uses pthread_self. */
ub_thread_setname(ub_thread_self(), name);
}
ub_thread_blocksigs();
#ifdef THREADS_DISABLED
@@ -940,8 +967,9 @@ thread_start(void* arg)
port_num = 0;
#endif
if(!worker_init(worker, worker->daemon->cfg,
worker->daemon->ports[port_num], 0))
worker->daemon->ports[port_num], 0)) {
fatal_exit("Could not initialize thread");
}
worker_work(worker);
return NULL;
@@ -1103,8 +1131,9 @@ daemon_fork(struct daemon* daemon)
#if defined(HAVE_EV_LOOP) || defined(HAVE_EV_DEFAULT_LOOP)
/* in libev the first inited base gets signals */
if(!worker_init(daemon->workers[0], daemon->cfg, daemon->ports[0], 1))
if(!worker_init(daemon->workers[0], daemon->cfg, daemon->ports[0], 1)) {
fatal_exit("Could not initialize main thread");
}
#endif
/* Now create the threads and init the workers.
@@ -1117,8 +1146,9 @@ daemon_fork(struct daemon* daemon)
*/
#if !(defined(HAVE_EV_LOOP) || defined(HAVE_EV_DEFAULT_LOOP))
/* libevent has the last inited base get signals (or any base) */
if(!worker_init(daemon->workers[0], daemon->cfg, daemon->ports[0], 1))
if(!worker_init(daemon->workers[0], daemon->cfg, daemon->ports[0], 1)) {
fatal_exit("Could not initialize main thread");
}
#endif
signal_handling_playback(daemon->workers[0]);
@@ -1162,7 +1192,6 @@ daemon_cleanup(struct daemon* daemon)
/* before stopping main worker, handle signals ourselves, so we
don't die on multiple reload signals for example. */
signal_handling_record();
log_thread_set(NULL);
/* clean up caches because
* a) RRset IDs will be recycled after a reload, causing collisions
* b) validation config can change, thus rrset, msg, keycache clear
@@ -1204,6 +1233,8 @@ daemon_cleanup(struct daemon* daemon)
if(!daemon->reuse_cache || daemon->need_to_exit)
daemon_clear_allocs(daemon);
daemon->num = 0;
shared_ports_delete(daemon->shared_ports);
daemon->shared_ports = NULL;
#ifdef USE_DNSTAP
dt_delete(daemon->dtenv);
daemon->dtenv = NULL;
@@ -1243,6 +1274,7 @@ daemon_delete(struct daemon* daemon)
edns_strings_delete(daemon->env->edns_strings);
auth_zones_delete(daemon->env->auth_zones);
}
auth_load_info_delete(daemon->auth_load_info);
ub_randfree(daemon->rand);
alloc_clear(&daemon->superalloc);
acl_list_delete(daemon->acl);
@@ -1266,7 +1298,7 @@ daemon_delete(struct daemon* daemon)
# if HAVE_DECL_SSL_COMP_GET_COMPRESSION_METHODS && HAVE_DECL_SK_SSL_COMP_POP_FREE
# ifndef S_SPLINT_S
# if OPENSSL_VERSION_NUMBER < 0x10100000
sk_SSL_COMP_pop_free(comp_meth, (void(*)())CRYPTO_free);
sk_SSL_COMP_pop_free(comp_meth, (void(*)(SSL_COMP*))CRYPTO_free);
# endif
# endif
# endif
@@ -1289,6 +1321,9 @@ daemon_delete(struct daemon* daemon)
# if defined(HAVE_SSL) && defined(OPENSSL_THREADS) && !defined(THREADS_DISABLED)
ub_openssl_lock_delete();
# endif
#ifdef HAVE_OPENSSL_CLEANUP
OPENSSL_cleanup();
#endif
#ifndef HAVE_ARC4RANDOM
_ARC4_LOCK_DESTROY();
#endif
+6
View File
@@ -62,6 +62,8 @@ struct doq_table;
struct cookie_secrets;
struct fast_reload_thread;
struct fast_reload_printq;
struct auth_load_general_info;
struct shared_ports;
#include "dnstap/dnstap_config.h"
#ifdef USE_DNSTAP
@@ -97,6 +99,8 @@ struct daemon {
int rc_port;
/** listening ports for remote control */
struct listen_port* rc_ports;
/** the shared ports structure, with random ports numbers. */
struct shared_ports* shared_ports;
/** remote control connections management (for first worker) */
struct daemon_remote* rc;
/** ssl context for listening to dnstcp over ssl */
@@ -188,6 +192,8 @@ struct daemon {
int fast_reload_tcl_has_changes;
/** config file name */
char* cfgfile;
/** Auth load threads, the number of active threads. */
struct auth_load_general_info* auth_load_info;
};
/**
+288 -386
View File
@@ -115,9 +115,6 @@
#ifdef HAVE_NETDB_H
#include <netdb.h>
#endif
#ifdef HAVE_POLL_H
#include <poll.h>
#endif
/* just for portability */
#ifdef SQ
@@ -307,7 +304,7 @@ add_open(const char* ip, int nr, struct listen_port** list, int noproto_is_err,
#endif
}
} else {
char* s = strchr(ip, '@');
const char* s = strchr(ip, '@');
char newif[128];
if(s) {
/* override port with ifspec@port */
@@ -1533,18 +1530,95 @@ do_datas_add(struct daemon_remote* rc, RES* ssl, struct worker* worker)
(void)ssl_printf(ssl, "added %d datas\n", num);
}
static int
perform_data_remove_rr(RES* ssl, struct local_zones* local_zones,
uint8_t* rr, size_t len, size_t dname_len, char *arg)
{
uint16_t rr_class, rr_type;
int labs;
struct local_zone* z;
struct local_data* ld;
uint8_t *rdata;
size_t rdata_len, index;
struct packed_rrset_data* d;
struct local_rrset* p;
rdata = sldns_wirerr_get_rdatawl(rr, len, dname_len);
rdata_len = ((size_t)sldns_wirerr_get_rdatalen(rr, len, dname_len))+2;
labs = dname_count_labels(rr);
rr_class = sldns_wirerr_get_class(rr, len, dname_len);
rr_type = sldns_wirerr_get_type(rr, len, dname_len);
z = local_zones_lookup(local_zones, rr, dname_len,
labs, rr_class, rr_type, 1);
if (!z) {
ssl_printf(ssl, "error no zone for rr %s\n", arg);
return 0;
}
ld = local_zone_find_data(z, rr, dname_len, labs);
if (!ld) {
ssl_printf(ssl, "error no local data for rr %s\n", arg);
return 0;
}
p = ld->rrsets;
while (p && ntohs(p->rrset->rk.type) != rr_type) {
p = p->next;
}
if (!p) {
ssl_printf(ssl, "error no rrset for rr %s\n", arg);
return 0;
}
d = (struct packed_rrset_data*)p->rrset->entry.data;
if (!packed_rrset_find_rr(d, rdata, rdata_len, &index)) {
ssl_printf(ssl, "error rr %s not found in rrset\n", arg);
return 0;
}
if (!local_rrset_remove_rr(d, index)) {
ssl_printf(ssl, "error unable to delete rr %s\n", arg);
return 0;
}
return 1;
}
/** Remove RR data */
static int
perform_data_remove(RES* ssl, struct local_zones* zones, char* arg)
{
uint8_t* nm;
int nmlabs;
size_t nmlen;
if(!parse_arg_name(ssl, arg, &nm, &nmlen, &nmlabs))
uint8_t rr[LDNS_RR_BUF_SIZE], *nm;
size_t len = sizeof(rr);
int status, nmlabs;
size_t nmlen, dname_len;
/* try to parse as a rr first */
status = sldns_str2wire_rr_buf(arg, rr, &len, &dname_len, 3600,
NULL, 0, NULL, 0);
/* try to parse as a domain name second */
if (status != 0) {
if (parse_arg_name(ssl, arg, &nm, &nmlen, &nmlabs)) {
local_zones_del_data(zones, nm,
nmlen, nmlabs, LDNS_RR_CLASS_IN);
free(nm);
return 1;
}
ssl_printf(ssl, "error cannot parse rr %s at %d: %s\n", arg,
LDNS_WIREPARSE_OFFSET(status),
sldns_get_errorstr_parse(status));
return 0;
local_zones_del_data(zones, nm,
nmlen, nmlabs, LDNS_RR_CLASS_IN);
free(nm);
}
/* handle the rr case */
if (!perform_data_remove_rr(ssl, zones, rr, len, dname_len, arg))
return 0;
return 1;
}
@@ -1658,6 +1732,14 @@ do_view_data_add(RES* ssl, struct worker* worker, char* arg)
ssl_printf(ssl,"error out of memory\n");
return;
}
if(!v->isfirst) {
/* Global local-zone is not used for this view,
* therefore add defaults to this view-specific
* local-zone. */
struct config_file lz_cfg;
memset(&lz_cfg, 0, sizeof(lz_cfg));
local_zone_enter_defaults(v->local_zones, &lz_cfg);
}
}
do_data_add(ssl, v->local_zones, arg2);
lock_rw_unlock(&v->lock);
@@ -1683,6 +1765,14 @@ do_view_datas_add(struct daemon_remote* rc, RES* ssl, struct worker* worker,
ssl_printf(ssl,"error out of memory\n");
return;
}
if(!v->isfirst) {
/* Global local-zone is not used for this view,
* therefore add defaults to this view-specific
* local-zone. */
struct config_file lz_cfg;
memset(&lz_cfg, 0, sizeof(lz_cfg));
local_zone_enter_defaults(v->local_zones, &lz_cfg);
}
}
/* put the view name in the command buf */
(void)snprintf(buf+strlen(buf), sizeof(buf)-strlen(buf), "%s ", arg);
@@ -2299,6 +2389,9 @@ zone_del_rrset(struct lruhash_entry* e, void* arg)
(struct packed_rrset_data*)e->data;
if(d->ttl > inf->expired) {
d->ttl = inf->expired;
if(d->ttl_add > inf->expired)
d->ttl_add = inf->expired; /* for 0TTL rrsets,
means that d->ttl_add <= d->ttl */
inf->num_rrsets++;
}
}
@@ -2585,7 +2678,7 @@ static int
ssl_print_name_dp(RES* ssl, const char* str, uint8_t* nm, uint16_t dclass,
struct delegpt* dp)
{
char buf[LDNS_MAX_DOMAINLEN];
char buf[LDNS_MAX_DOMAINLEN], portstr[128], tls_auth_name[256];
struct delegpt_ns* ns;
struct delegpt_addr* a;
int f = 0;
@@ -2600,13 +2693,32 @@ ssl_print_name_dp(RES* ssl, const char* str, uint8_t* nm, uint16_t dclass,
}
for(ns = dp->nslist; ns; ns = ns->next) {
dname_str(ns->name, buf);
if(!ssl_printf(ssl, "%s%s", (f?" ":""), buf))
if(ns->port != UNBOUND_DNS_PORT)
snprintf(portstr, sizeof(portstr), "@%d", ns->port);
else portstr[0]=0;
if(ns->tls_auth_name)
snprintf(tls_auth_name, sizeof(tls_auth_name), "#%s",
ns->tls_auth_name);
else tls_auth_name[0]=0;
if(!ssl_printf(ssl, "%s%s%s%s", (f?" ":""), buf, portstr,
tls_auth_name))
return 0;
f = 1;
}
for(a = dp->target_list; a; a = a->next_target) {
int port = (unsigned)((a->addr.ss_family == AF_INET) ?
ntohs(((struct sockaddr_in*)&a->addr)->sin_port) :
ntohs(((struct sockaddr_in6*)&a->addr)->sin6_port));
addr_to_str(&a->addr, a->addrlen, buf, sizeof(buf));
if(!ssl_printf(ssl, "%s%s", (f?" ":""), buf))
if(port != UNBOUND_DNS_PORT)
snprintf(portstr, sizeof(portstr), "@%d", port);
else portstr[0]=0;
if(a->tls_auth_name)
snprintf(tls_auth_name, sizeof(tls_auth_name), "#%s",
a->tls_auth_name);
else tls_auth_name[0]=0;
if(!ssl_printf(ssl, "%s%s%s%s", (f?" ":""), buf, portstr,
tls_auth_name))
return 0;
f = 1;
}
@@ -3222,6 +3334,10 @@ do_auth_zone_reload(RES* ssl, struct worker* worker, char* arg)
return;
}
if(!auth_zone_read_zonefile(z, worker->env.cfg)) {
/* The old tree was already cleared. Do not answer from the
* failed load. */
z->zone_expired = 1;
auth_zone_clear_data(z);
lock_rw_unlock(&z->lock);
if(xfr) {
lock_basic_unlock(&xfr->lock);
@@ -3233,6 +3349,7 @@ do_auth_zone_reload(RES* ssl, struct worker* worker, char* arg)
z->zone_expired = 0;
if(xfr) {
xfr->zone_expired = 0;
xfr->num_ixfrs = 0;
if(!xfr_find_soa(z, xfr)) {
if(z->data.count == 0) {
lock_rw_unlock(&z->lock);
@@ -4346,92 +4463,6 @@ int remote_control_callback(struct comm_point* c, void* arg, int err,
return 0;
}
/**
* This routine polls a socket for readiness.
* @param fd: file descriptor, -1 uses no fd for a timer only.
* @param timeout: time in msec to wait. 0 means nonblocking test,
* -1 waits blocking for events.
* @param pollin: check for input event.
* @param pollout: check for output event.
* @param event: output variable, set to true if the event happens.
* It is false if there was an error or timeout.
* @return false is system call failure, also logged.
*/
static int
sock_poll_timeout(int fd, int timeout, int pollin, int pollout, int* event)
{
int loopcount = 0;
/* Loop if the system call returns an errno to do so, like EINTR. */
log_assert(pollin || pollout);
while(1) {
struct pollfd p, *fds;
int nfds, ret;
if(++loopcount > IPC_LOOP_MAX) {
log_err("sock_poll_timeout: loop");
if(event)
*event = 0;
return 0;
}
if(fd == -1) {
fds = NULL;
nfds = 0;
} else {
fds = &p;
nfds = 1;
memset(&p, 0, sizeof(p));
p.fd = fd;
#ifndef USE_WINSOCK
p.events = POLLERR
| POLLHUP
;
#endif
if(pollin)
p.events |= POLLIN;
if(pollout)
p.events |= POLLOUT;
}
#ifndef USE_WINSOCK
ret = poll(fds, nfds, timeout);
#else
if(fds == NULL) {
Sleep(timeout);
ret = 0;
} else {
ret = WSAPoll(fds, nfds, timeout);
}
#endif
if(ret == -1) {
#ifndef USE_WINSOCK
if(
errno == EINTR || errno == EAGAIN
# ifdef EWOULDBLOCK
|| errno == EWOULDBLOCK
# endif
) continue; /* Try again. */
#endif
/* For WSAPoll we only get errors here:
* o WSAENETDOWN
* o WSAEFAULT
* o WSAEINVAL
* o WSAENOBUFS
*/
log_err("poll: %s", sock_strerror(errno));
if(event)
*event = 0;
return 0;
} else if(ret == 0) {
/* Timeout */
if(event)
*event = 0;
return 1;
}
break;
}
if(event)
*event = 1;
return 1;
}
/** fast reload convert fast reload notification status to string */
static const char*
fr_notification_to_string(enum fast_reload_notification status)
@@ -4925,6 +4956,74 @@ fr_check_changed_cfg_str2list(struct config_str2list* cmp1,
}
}
/** fast reload thread, check if config str3list has changed. */
#define FR_CHECK_CHANGED_CFG_STR3LIST(desc, var, buff) do { \
fr_check_changed_cfg_str3list(cfg->var, newcfg->var, desc, buff,\
sizeof(buff)); \
} while(0);
static void
fr_check_changed_cfg_str3list(struct config_str3list* cmp1,
struct config_str3list* cmp2, const char* desc, char* str, size_t len)
{
struct config_str3list* p1 = cmp1, *p2 = cmp2;
while(p1 && p2) {
if((!p1->str && p2->str) ||
(p1->str && !p2->str) ||
(p1->str && p2->str && strcmp(p1->str, p2->str) != 0)) {
/* The str3list is different. */
fr_add_incompatible_option(desc, str, len);
return;
}
if((!p1->str2 && p2->str2) ||
(p1->str2 && !p2->str2) ||
(p1->str2 && p2->str2 &&
strcmp(p1->str2, p2->str2) != 0)) {
/* The str3list is different. */
fr_add_incompatible_option(desc, str, len);
return;
}
if((!p1->str3 && p2->str3) ||
(p1->str3 && !p2->str3) ||
(p1->str3 && p2->str3 &&
strcmp(p1->str3, p2->str3) != 0)) {
/* The str3list is different. */
fr_add_incompatible_option(desc, str, len);
return;
}
p1 = p1->next;
p2 = p2->next;
}
if((!p1 && p2) || (p1 && !p2)) {
fr_add_incompatible_option(desc, str, len);
}
}
/** fast reload thread, check tag datas. */
static int
fr_check_tag_datas(struct fast_reload_thread* fr, struct config_file* newcfg)
{
char changed_str[1024];
struct config_file* cfg = fr->worker->env.cfg;
changed_str[0]=0;
/* Check for tag_datas in acl_addr. */
FR_CHECK_CHANGED_CFG_STR3LIST("interface-tag-data", interface_tag_datas, changed_str);
FR_CHECK_CHANGED_CFG_STR3LIST("access-control-tag-data", acl_tag_datas, changed_str);
if(changed_str[0] != 0) {
if(fr->fr_drop_mesh)
return 1; /* already dropping queries */
fr->fr_drop_mesh = 1;
fr->worker->daemon->fast_reload_drop_mesh = fr->fr_drop_mesh;
if(!fr_output_printf(fr, "recursion referenced data has changed, with: '%s"
"', and the queries have to be dropped"
", setting '+d'\n", changed_str))
return 0;
fr_send_notification(fr, fast_reload_notification_printout);
}
return 1;
}
/** fast reload thread, check compatible config items */
static int
fr_check_compat_cfg(struct fast_reload_thread* fr, struct config_file* newcfg)
@@ -5461,6 +5560,23 @@ xfr_masterlist_equal(struct auth_master* list1, struct auth_master* list2)
return 0;
}
/** See if configuration has changed. */
static int
xfr_config_equal(struct auth_xfer* xfr1, struct auth_xfer* xfr2)
{
if(xfr1 == NULL && xfr2 == NULL)
return 1;
if(xfr1 == NULL && xfr2 != NULL)
return 0;
if(xfr1 != NULL && xfr2 == NULL)
return 0;
if(xfr1->max_transfer_size != xfr2->max_transfer_size)
return 0;
if(xfr1->max_transfer_time != xfr2->max_transfer_time)
return 0;
return 1;
}
/** See if the list of masters has changed. */
static int
xfr_masters_equal(struct auth_xfer* xfr1, struct auth_xfer* xfr2)
@@ -5549,8 +5665,31 @@ auth_zones_check_changes(struct fast_reload_thread* fr,
&old_serial)!=0);
have_new = (auth_zone_get_serial(new_z,
&new_serial)!=0);
/* A change in primaries, also means it is different
* and the change makes it fire new transfers, from
* the new primaries. */
/* Treat as changed when the old zone has an
* outstanding ZONEMD DS/DNSKEY mesh callback.
* This will make the worker pickup change code
* remove the mesh callback, before the old zone is
* deleted. Also it makes a new zonemd lookup.
* The new lookup is needed, because the new zone
* entry needs to have a valid zonemd result,
* and if that is bad, needs to be invalidated.
* Also if there is a race event where the
* outstanding callback makes the zone invalid,
* before fast-reload completes, the change makes
* the new zone entry have a new zonemd lookup,
* to then invalidate that new zone.
* There is also a brief operational window at
* program start when a zonemd has to be looked
* up on-line, where the zone is operational.
* And this copies that for such a race event.
*/
if(have_old != have_new || old_serial != new_serial
|| !xfr_masters_equal(old_xfr, new_xfr)) {
|| !xfr_masters_equal(old_xfr, new_xfr)
|| !xfr_config_equal(old_xfr, new_xfr)
|| old_z->zonemd_callback_env != NULL) {
/* The zone has been changed. */
if(!fr_add_auth_zone_change(fr, old_z, new_z,
0, 0, 1)) {
@@ -5623,6 +5762,8 @@ ct_create_sslctxs(struct fast_reload_construct* ct,
/* Leave listen ctxs and file str at NULL */
ct->connect_dot_sslctx = daemon_setup_connect_dot_sslctx(
daemon, newcfg);
if(!ct->connect_dot_sslctx)
return 0;
return 1;
}
@@ -5632,20 +5773,28 @@ ct_create_sslctxs(struct fast_reload_construct* ct,
pem += strlen(chroot);
ct->listen_dot_sslctx = daemon_setup_listen_dot_sslctx(daemon, newcfg);
if(!ct->listen_dot_sslctx)
return 0;
#ifdef HAVE_NGHTTP2_NGHTTP2_H
if(cfg_has_https(newcfg)) {
ct->listen_doh_sslctx = daemon_setup_listen_doh_sslctx(
daemon, newcfg);
if(!ct->listen_doh_sslctx)
return 0;
}
#endif
#ifdef HAVE_NGTCP2
if(cfg_has_quic(newcfg)) {
ct->listen_quic_sslctx = daemon_setup_listen_quic_sslctx(
daemon, newcfg);
if(!ct->listen_quic_sslctx)
return 0;
}
#endif /* HAVE_NGTCP2 */
ct->connect_dot_sslctx = daemon_setup_connect_dot_sslctx(daemon,
newcfg);
if(!ct->connect_dot_sslctx)
return 0;
/* Store mtime and names */
ct->ssl_service_key = strdup(newcfg->ssl_service_key);
@@ -6127,6 +6276,7 @@ fr_atomic_copy_cfg(struct config_file* oldcfg, struct config_file* cfg,
COPY_VAR_ptr(acls);
COPY_VAR_int(donotquery_localhost);
COPY_VAR_ptr(tcp_connection_limits);
COPY_VAR_int(auth_task_threads);
COPY_VAR_int(harden_short_bufsize);
COPY_VAR_int(harden_large_queries);
COPY_VAR_int(harden_glue);
@@ -6615,9 +6765,12 @@ fr_reload_config(struct fast_reload_thread* fr, struct config_file* newcfg,
}
#ifdef USE_DNSTAP
if(env->cfg->dnstap) {
if(!fr->fr_nopause)
dt_apply_cfg(daemon->dtenv, env->cfg);
else dt_apply_logcfg(daemon->dtenv, env->cfg);
if(!fr->fr_nopause) {
if(!dt_apply_cfg(daemon->dtenv, env->cfg))
log_warn("fast_reload: dnstap identity/version metadata not updated due to allocation failure");
} else {
dt_apply_logcfg(daemon->dtenv, env->cfg);
}
}
#endif
fr_adjust_cache(env, ct->oldcfg);
@@ -6757,6 +6910,10 @@ fr_load_config(struct fast_reload_thread* fr, struct timeval* time_read,
config_delete(newcfg);
return 0;
}
if(!fr_check_tag_datas(fr, newcfg)) {
config_delete(newcfg);
return 0;
}
if(!fr_check_compat_cfg(fr, newcfg)) {
config_delete(newcfg);
return 0;
@@ -6848,7 +7005,7 @@ static void* fast_reload_thread_main(void* arg)
#endif
log_thread_set(&fast_reload_thread->threadnum);
ub_thread_setname(fast_reload_thread->tid, name);
ub_thread_setname(ub_thread_self(), name);
(void)name; /* When setname is not defined, ignore the name variable. */
verbose(VERB_ALGO, "start fast reload thread");
@@ -6908,286 +7065,6 @@ done_error:
}
#endif /* !THREADS_DISABLED */
/** create a socketpair for bidirectional communication, false on failure */
static int
create_socketpair(int* pair, struct ub_randstate* rand)
{
#ifndef USE_WINSOCK
if(socketpair(AF_UNIX, SOCK_STREAM, 0, pair) == -1) {
log_err("socketpair: %s", strerror(errno));
return 0;
}
(void)rand;
#else
struct sockaddr_in addr, baddr, accaddr, connaddr;
socklen_t baddrlen, accaddrlen, connaddrlen;
uint8_t localhost[] = {127, 0, 0, 1};
uint8_t nonce[16], recvnonce[16];
size_t i;
int lst, pollin_event, bcount, loopcount;
int connect_poll_timeout = 200; /* msec to wait for connection */
ssize_t ret;
pair[0] = -1;
pair[1] = -1;
for(i=0; i<sizeof(nonce); i++) {
nonce[i] = ub_random_max(rand, 256);
}
lst = socket(AF_INET, SOCK_STREAM, 0);
if(lst == -1) {
log_err("create_socketpair: socket: %s", sock_strerror(errno));
return 0;
}
memset(&addr, 0, sizeof(addr));
addr.sin_family = AF_INET;
addr.sin_port = 0;
memcpy(&addr.sin_addr, localhost, 4);
if(bind(lst, (struct sockaddr*)&addr, (socklen_t)sizeof(addr))
== -1) {
log_err("create socketpair: bind: %s", sock_strerror(errno));
sock_close(lst);
return 0;
}
if(listen(lst, 12) == -1) {
log_err("create socketpair: listen: %s", sock_strerror(errno));
sock_close(lst);
return 0;
}
pair[1] = socket(AF_INET, SOCK_STREAM, 0);
if(pair[1] == -1) {
log_err("create socketpair: socket: %s", sock_strerror(errno));
sock_close(lst);
return 0;
}
baddrlen = (socklen_t)sizeof(baddr);
if(getsockname(lst, (struct sockaddr*)&baddr, &baddrlen) == -1) {
log_err("create socketpair: getsockname: %s",
sock_strerror(errno));
sock_close(lst);
sock_close(pair[1]);
pair[1] = -1;
return 0;
}
if(baddrlen > (socklen_t)sizeof(baddr)) {
log_err("create socketpair: getsockname returned addr too big");
sock_close(lst);
sock_close(pair[1]);
pair[1] = -1;
return 0;
}
/* the socket is blocking */
if(connect(pair[1], (struct sockaddr*)&baddr, baddrlen) == -1) {
log_err("create socketpair: connect: %s",
sock_strerror(errno));
sock_close(lst);
sock_close(pair[1]);
pair[1] = -1;
return 0;
}
if(!sock_poll_timeout(lst, connect_poll_timeout, 1, 0, &pollin_event)) {
log_err("create socketpair: poll for accept failed: %s",
sock_strerror(errno));
sock_close(lst);
sock_close(pair[1]);
pair[1] = -1;
return 0;
}
if(!pollin_event) {
log_err("create socketpair: poll timeout for accept");
sock_close(lst);
sock_close(pair[1]);
pair[1] = -1;
return 0;
}
accaddrlen = (socklen_t)sizeof(accaddr);
pair[0] = accept(lst, (struct sockaddr*)&accaddr, &accaddrlen);
if(pair[0] == -1) {
log_err("create socketpair: accept: %s", sock_strerror(errno));
sock_close(lst);
sock_close(pair[1]);
pair[1] = -1;
return 0;
}
if(accaddrlen > (socklen_t)sizeof(accaddr)) {
log_err("create socketpair: accept returned addr too big");
sock_close(lst);
sock_close(pair[0]);
sock_close(pair[1]);
pair[0] = -1;
pair[1] = -1;
return 0;
}
if(accaddr.sin_family != AF_INET ||
memcmp(localhost, &accaddr.sin_addr, 4) != 0) {
log_err("create socketpair: accept from wrong address");
sock_close(lst);
sock_close(pair[0]);
sock_close(pair[1]);
pair[0] = -1;
pair[1] = -1;
return 0;
}
connaddrlen = (socklen_t)sizeof(connaddr);
if(getsockname(pair[1], (struct sockaddr*)&connaddr, &connaddrlen)
== -1) {
log_err("create socketpair: getsockname connectedaddr: %s",
sock_strerror(errno));
sock_close(lst);
sock_close(pair[0]);
sock_close(pair[1]);
pair[0] = -1;
pair[1] = -1;
return 0;
}
if(connaddrlen > (socklen_t)sizeof(connaddr)) {
log_err("create socketpair: getsockname connectedaddr returned addr too big");
sock_close(lst);
sock_close(pair[0]);
sock_close(pair[1]);
pair[0] = -1;
pair[1] = -1;
return 0;
}
if(connaddr.sin_family != AF_INET ||
memcmp(localhost, &connaddr.sin_addr, 4) != 0) {
log_err("create socketpair: getsockname connectedaddr returned wrong address");
sock_close(lst);
sock_close(pair[0]);
sock_close(pair[1]);
pair[0] = -1;
pair[1] = -1;
return 0;
}
if(accaddr.sin_port != connaddr.sin_port) {
log_err("create socketpair: accept from wrong port");
sock_close(lst);
sock_close(pair[0]);
sock_close(pair[1]);
pair[0] = -1;
pair[1] = -1;
return 0;
}
sock_close(lst);
loopcount = 0;
bcount = 0;
while(1) {
if(++loopcount > IPC_LOOP_MAX) {
log_err("create socketpair: send failed due to loop");
sock_close(pair[0]);
sock_close(pair[1]);
pair[0] = -1;
pair[1] = -1;
return 0;
}
ret = send(pair[1], (void*)(nonce+bcount),
sizeof(nonce)-bcount, 0);
if(ret == -1) {
if(
#ifndef USE_WINSOCK
errno == EINTR || errno == EAGAIN
# ifdef EWOULDBLOCK
|| errno == EWOULDBLOCK
# endif
#else
WSAGetLastError() == WSAEINTR ||
WSAGetLastError() == WSAEINPROGRESS ||
WSAGetLastError() == WSAEWOULDBLOCK
#endif
)
continue; /* Try again. */
log_err("create socketpair: send: %s", sock_strerror(errno));
sock_close(pair[0]);
sock_close(pair[1]);
pair[0] = -1;
pair[1] = -1;
return 0;
} else if(ret+(ssize_t)bcount != sizeof(nonce)) {
bcount += ret;
if((size_t)bcount < sizeof(nonce))
continue;
}
break;
}
if(!sock_poll_timeout(pair[0], connect_poll_timeout, 1, 0, &pollin_event)) {
log_err("create socketpair: poll failed: %s",
sock_strerror(errno));
sock_close(pair[0]);
sock_close(pair[1]);
pair[0] = -1;
pair[1] = -1;
return 0;
}
if(!pollin_event) {
log_err("create socketpair: poll timeout for recv");
sock_close(pair[0]);
sock_close(pair[1]);
pair[0] = -1;
pair[1] = -1;
return 0;
}
loopcount = 0;
bcount = 0;
while(1) {
if(++loopcount > IPC_LOOP_MAX) {
log_err("create socketpair: recv failed due to loop");
sock_close(pair[0]);
sock_close(pair[1]);
pair[0] = -1;
pair[1] = -1;
return 0;
}
ret = recv(pair[0], (void*)(recvnonce+bcount),
sizeof(nonce)-bcount, 0);
if(ret == -1) {
if(
#ifndef USE_WINSOCK
errno == EINTR || errno == EAGAIN
# ifdef EWOULDBLOCK
|| errno == EWOULDBLOCK
# endif
#else
WSAGetLastError() == WSAEINTR ||
WSAGetLastError() == WSAEINPROGRESS ||
WSAGetLastError() == WSAEWOULDBLOCK
#endif
)
continue; /* Try again. */
log_err("create socketpair: recv: %s", sock_strerror(errno));
sock_close(pair[0]);
sock_close(pair[1]);
pair[0] = -1;
pair[1] = -1;
return 0;
} else if(ret == 0) {
log_err("create socketpair: stream closed");
sock_close(pair[0]);
sock_close(pair[1]);
pair[0] = -1;
pair[1] = -1;
return 0;
} else if(ret+(ssize_t)bcount != sizeof(nonce)) {
bcount += ret;
if((size_t)bcount < sizeof(nonce))
continue;
}
break;
}
if(memcmp(nonce, recvnonce, sizeof(nonce)) != 0) {
log_err("create socketpair: recv wrong nonce");
sock_close(pair[0]);
sock_close(pair[1]);
pair[0] = -1;
pair[1] = -1;
return 0;
}
#endif
return 1;
}
/** fast reload thread. setup the thread info */
static int
fast_reload_thread_setup(struct worker* worker, int fr_verb, int fr_nopause,
@@ -7571,7 +7448,8 @@ auth_zone_zonemd_stop_lookup(struct auth_zone* z, struct mesh_area* mesh)
qinfo.local_alias = NULL;
mesh_remove_callback(mesh, &qinfo, qflags,
&auth_zonemd_dnskey_lookup_callback, z);
&auth_zonemd_dnskey_lookup_callback, z,
z->zonemd_callback_unique_info);
}
/** Pick up the auth zone locks. */
@@ -7680,6 +7558,9 @@ auth_xfr_pickup_config(struct auth_xfer* loadxfr, struct auth_xfer* xfr)
log_assert(loadxfr->namelabs == xfr->namelabs);
log_assert(loadxfr->dclass == xfr->dclass);
xfr->max_transfer_size = loadxfr->max_transfer_size;
xfr->max_transfer_time = loadxfr->max_transfer_time;
/* The lists can be swapped in, the other xfr struct will be deleted
* afterwards. */
probe_masters = xfr->task_probe->masters;
@@ -7704,6 +7585,16 @@ fr_worker_auth_add(struct worker* worker, struct fast_reload_auth_change* item,
/* The xfr item needs to be created. The auth zones lock
* is held to make this possible. */
xfr = auth_xfer_create(worker->env.auth_zones, item->new_z);
if(!xfr) {
log_err("out of memory in fr_worker_auth_add");
lock_rw_unlock(&item->new_z->lock);
lock_rw_unlock(&worker->env.auth_zones->lock);
lock_rw_unlock(&worker->daemon->fast_reload_thread->old_auth_zones->lock);
if(loadxfr) {
lock_basic_unlock(&loadxfr->lock);
}
return;
}
auth_xfr_pickup_config(loadxfr, xfr);
/* Serial information is copied into the xfr struct. */
if(!xfr_find_soa(item->new_z, xfr)) {
@@ -7773,6 +7664,17 @@ fr_worker_auth_cha(struct worker* worker, struct fast_reload_auth_change* item)
} else if(loadxfr && !xfr) {
/* Create the xfr. */
xfr = auth_xfer_create(worker->env.auth_zones, item->new_z);
if(!xfr) {
log_err("out of memory in fr_worker_auth_cha");
lock_rw_unlock(&item->new_z->lock);
lock_rw_unlock(&item->old_z->lock);
lock_rw_unlock(&worker->daemon->fast_reload_thread->old_auth_zones->lock);
lock_rw_unlock(&worker->env.auth_zones->lock);
if(loadxfr) {
lock_basic_unlock(&loadxfr->lock);
}
return;
}
auth_xfr_pickup_config(loadxfr, xfr);
item->new_z->zone_is_slave = 1;
}
+1 -7
View File
@@ -49,6 +49,7 @@
#include <openssl/ssl.h>
#endif
#include "util/locks.h"
#include "libunbound/remote.h"
struct config_file;
struct listen_list;
struct listen_port;
@@ -365,13 +366,6 @@ void fast_reload_thread_start(RES* ssl, struct worker* worker,
*/
void fast_reload_thread_stop(struct fast_reload_thread* fast_reload_thread);
/** fast reload thread commands to remote service thread event callback */
void fast_reload_service_cb(int fd, short bits, void* arg);
/** fast reload callback for the remote control client connection */
int fast_reload_client_callback(struct comm_point* c, void* arg, int err,
struct comm_reply* rep);
/** fast reload printq delete list */
void fast_reload_printq_list_delete(struct fast_reload_printq* list);
+22 -6
View File
@@ -422,12 +422,28 @@ void server_stats_obtain(struct worker* worker, struct worker* who,
# endif
#endif
);
log_err("server_stats_obtain: no response from worker %d "
"(stats timeout); returning zero stats for this worker",
who->thread_num);
/* A later reply from the worker, would be sizeof stats reply,
* and the worker_handle_control_cmd routine discards if
* it is not a 4byte command, when that is received here. */
memset(s, 0, sizeof(*s));
return;
}
if(!tube_read_msg(worker->cmd, &reply, &len, 0)) {
log_err("server_stats_obtain: failed to read stats from worker "
"(tube read error); returning zero stats for this worker");
memset(s, 0, sizeof(*s));
return;
}
if(len != (uint32_t)sizeof(*s)) {
log_err("server_stats_obtain: wrong stats length %d (expected %d); "
"discarding", (int)len, (int)sizeof(*s));
free(reply);
memset(s, 0, sizeof(*s));
return;
}
if(!tube_read_msg(worker->cmd, &reply, &len, 0))
fatal_exit("failed to read stats over cmd channel");
if(len != (uint32_t)sizeof(*s))
fatal_exit("stats on cmd channel wrong length %d %d",
(int)len, (int)sizeof(*s));
memcpy(s, reply, (size_t)len);
free(reply);
}
@@ -439,7 +455,7 @@ void server_stats_reply(struct worker* worker, int reset)
verbose(VERB_ALGO, "write stats replymsg");
if(!tube_write_msg(worker->daemon->workers[0]->cmd,
(uint8_t*)&s, sizeof(s), 0))
fatal_exit("could not write stat values over cmd channel");
log_err("could not write stat values over cmd channel");
}
void server_stats_add(struct ub_stats_info* total, struct ub_stats_info* a)
+45 -26
View File
@@ -501,7 +501,9 @@ worker_handle_control_cmd(struct tube* ATTR_UNUSED(tube), uint8_t* msg,
return;
}
if(len != sizeof(uint32_t)) {
fatal_exit("bad control msg length %d", (int)len);
verbose(VERB_ALGO, "bad control msg length %d", (int)len);
free(msg);
return;
}
cmd = sldns_read_uint32(msg);
free(msg);
@@ -714,7 +716,8 @@ apply_respip_action(struct worker* worker, const struct query_info* qinfo,
struct respip_client_info* cinfo, struct reply_info* rep,
struct sockaddr_storage* addr, socklen_t addrlen,
struct ub_packed_rrset_key** alias_rrset,
struct reply_info** encode_repp, struct auth_zones* az)
struct reply_info** encode_repp, struct auth_zones* az,
int* rpz_passthru)
{
struct respip_action_info actinfo = {0, 0, 0, 0, NULL, 0, NULL};
actinfo.action = respip_none;
@@ -725,7 +728,7 @@ apply_respip_action(struct worker* worker, const struct query_info* qinfo,
return 1;
if(!respip_rewrite_reply(qinfo, cinfo, rep, encode_repp, &actinfo,
alias_rrset, 0, worker->scratchpad, az, NULL,
alias_rrset, 0, worker->scratchpad, az, rpz_passthru,
worker->env.views, worker->env.respip_set))
return 0;
@@ -772,7 +775,7 @@ answer_from_cache(struct worker* worker, struct query_info* qinfo,
int* is_secure_answer, struct ub_packed_rrset_key** alias_rrset,
struct reply_info** partial_repp,
struct reply_info* rep, uint16_t id, uint16_t flags,
struct comm_reply* repinfo, struct edns_data* edns)
struct comm_reply* repinfo, struct edns_data* edns, int* rpz_passthru)
{
time_t timenow = *worker->env.now;
uint16_t udpsize = edns->udp_size;
@@ -882,7 +885,7 @@ answer_from_cache(struct worker* worker, struct query_info* qinfo,
if((worker->daemon->use_response_ip || worker->daemon->use_rpz) &&
!partial_rep && !apply_respip_action(worker, qinfo, cinfo, rep,
&repinfo->client_addr, repinfo->client_addrlen, alias_rrset,
&encode_rep, worker->env.auth_zones)) {
&encode_rep, worker->env.auth_zones, rpz_passthru)) {
goto bail_out;
} else if(partial_rep &&
!respip_merge_cname(partial_rep, qinfo, rep, cinfo,
@@ -1494,6 +1497,8 @@ worker_handle_request(struct comm_point* c, void* arg, int error,
struct reply_info* partial_rep = NULL;
struct query_info* lookup_qinfo = &qinfo;
struct query_info qinfo_tmp; /* placeholder for lookup_qinfo */
uint8_t* alias_orig_qname = NULL; /* original qname for logs, if
a local_alias is used to change the qname. */
struct respip_client_info* cinfo = NULL, cinfo_tmp;
struct timeval wait_time;
struct check_request_result check_result = {0,0};
@@ -1511,7 +1516,7 @@ worker_handle_request(struct comm_point* c, void* arg, int error,
if (worker->stats.max_query_time_us < wait_queue_time)
worker->stats.max_query_time_us = wait_queue_time;
if(wait_queue_time >
(long long)(worker->env.cfg->sock_queue_timeout * 1000000)) {
(long long)worker->env.cfg->sock_queue_timeout * 1000000) {
/* count and drop queries that were sitting in the socket queue too long */
worker->stats.num_queries_timed_out++;
return 0;
@@ -1550,6 +1555,7 @@ worker_handle_request(struct comm_point* c, void* arg, int error,
return 0;
}
query_error(c->buffer, LDNS_RCODE_FORMERR, 0);
sldns_buffer_copy(c->dnscrypt_buffer, c->buffer);
return 1;
}
dname_str(qinfo.qname, buf);
@@ -1568,6 +1574,7 @@ worker_handle_request(struct comm_point* c, void* arg, int error,
query_error(c->buffer, LDNS_RCODE_SERVFAIL,
qinfo.qname_len);
worker->stats.num_query_dnscrypt_cleartext++;
sldns_buffer_copy(c->dnscrypt_buffer, c->buffer);
return 1;
}
worker->stats.num_query_dnscrypt_cert++;
@@ -1828,7 +1835,13 @@ worker_handle_request(struct comm_point* c, void* arg, int error,
server_stats_insquery(&worker->stats, c, qinfo.qtype,
qinfo.qclass, &edns, repinfo);
if(c->type != comm_udp)
#ifdef USE_DNSCRYPT
edns.udp_size = (c->dnscrypt && repinfo->is_dnscrypted)
? sldns_buffer_capacity(c->buffer) - DNSCRYPT_REPLY_HEADER_SIZE
: 65535;
#else
edns.udp_size = 65535; /* max size for TCP replies */
#endif
if(qinfo.qclass == LDNS_RR_CLASS_CH && answer_chaos(worker, &qinfo,
&edns, repinfo, c->buffer)) {
regional_free_all(worker->scratchpad);
@@ -1928,6 +1941,11 @@ worker_handle_request(struct comm_point* c, void* arg, int error,
/* If we've found a local alias, replace the qname with the alias
* target before resolving it. */
if(qinfo.local_alias) {
if(qinfo.local_alias->rrset &&
qinfo.local_alias->rrset->rk.dname)
/* Store the original qname, used for logs, since
* local_alias can be removed by region_free_all. */
alias_orig_qname = qinfo.local_alias->rrset->rk.dname;
if(!local_alias_shallow_copy_qname(qinfo.local_alias, &qinfo.qname,
&qinfo.qname_len)) {
regional_free_all(worker->scratchpad);
@@ -1975,7 +1993,7 @@ lookup_cache:
&alias_rrset, &partial_rep, rep,
*(uint16_t*)(void *)sldns_buffer_begin(c->buffer),
sldns_buffer_read_u16_at(c->buffer, 2), repinfo,
&edns)) {
&edns, &rpz_passthru)) {
/* prefetch it if the prefetch TTL expired.
* Note that if there is more than one pass
* its qname must be that used for cache
@@ -2093,11 +2111,10 @@ send_reply_rc:
{
struct timeval tv;
memset(&tv, 0, sizeof(tv));
if(qinfo.local_alias && qinfo.local_alias->rrset &&
qinfo.local_alias->rrset->rk.dname) {
if(alias_orig_qname) {
/* log original qname, before the local alias was
* used to resolve that CNAME to something else */
qinfo.qname = qinfo.local_alias->rrset->rk.dname;
qinfo.qname = alias_orig_qname;
log_reply_info(NO_VERBOSE, &qinfo,
&repinfo->client_addr, repinfo->client_addrlen,
tv, 1, c->buffer,
@@ -2112,7 +2129,7 @@ send_reply_rc:
}
}
#ifdef USE_DNSCRYPT
if(!dnsc_handle_uncurved_request(repinfo)) {
if(!dnsc_handle_uncurved_request(repinfo, c->buffer)) {
return 0;
}
#endif
@@ -2225,23 +2242,16 @@ void worker_probe_timer_cb(void* arg)
}
struct worker*
worker_create(struct daemon* daemon, int id, int* ports, int n)
worker_create(struct daemon* daemon, int id)
{
unsigned int seed;
struct worker* worker = (struct worker*)calloc(1,
sizeof(struct worker));
if(!worker)
return NULL;
worker->numports = n;
worker->ports = (int*)memdup(ports, sizeof(int)*n);
if(!worker->ports) {
free(worker);
return NULL;
}
worker->daemon = daemon;
worker->thread_num = id;
if(!(worker->cmd = tube_create())) {
free(worker->ports);
free(worker);
return NULL;
}
@@ -2249,7 +2259,6 @@ worker_create(struct daemon* daemon, int id, int* ports, int n)
if(!(worker->rndstate = ub_initstate(daemon->rand))) {
log_err("could not init random numbers.");
tube_delete(worker->cmd);
free(worker->ports);
free(worker);
return NULL;
}
@@ -2348,14 +2357,14 @@ worker_init(struct worker* worker, struct config_file *cfg,
cfg->out_ifs, cfg->num_out_ifs, cfg->do_ip4, cfg->do_ip6,
cfg->do_tcp?cfg->outgoing_num_tcp:0, cfg->ip_dscp,
worker->daemon->env->infra_cache, worker->rndstate,
cfg->use_caps_bits_for_id, worker->ports, worker->numports,
cfg->use_caps_bits_for_id,
cfg->unwanted_threshold, cfg->outgoing_tcp_mss,
&worker_alloc_cleanup, worker,
cfg->do_udp || cfg->udp_upstream_without_downstream,
worker->daemon->connect_dot_sslctx, cfg->delay_close,
cfg->tls_use_sni, dtenv, cfg->udp_connect,
cfg->max_reuse_tcp_queries, cfg->tcp_reuse_timeout,
cfg->tcp_auth_query_timeout);
cfg->tcp_auth_query_timeout, worker->daemon->shared_ports);
if(!worker->back) {
log_err("could not create outgoing sockets");
worker_delete(worker);
@@ -2374,6 +2383,8 @@ worker_init(struct worker* worker, struct config_file *cfg,
worker_stat_timer_cb, worker);
if(!worker->stat_timer) {
log_err("could not create statistics timer");
worker_delete(worker);
return 0;
}
/* we use the msg_buffer_size as a good estimate for what the
@@ -2506,7 +2517,6 @@ worker_delete(struct worker* worker)
tube_delete(worker->cmd);
comm_timer_delete(worker->stat_timer);
comm_timer_delete(worker->env.probe_timer);
free(worker->ports);
if(worker->thread_num == 0) {
#ifdef UB_ON_WINDOWS
wsvc_desetup_worker(worker);
@@ -2527,6 +2537,8 @@ worker_delete(struct worker* worker)
/* don't touch worker->alloc, as it's maintained in daemon */
regional_destroy(worker->env.scratch);
regional_destroy(worker->scratchpad);
/* The thread id can reference this worker's id value, so clear it. */
log_thread_set(NULL);
free(worker);
}
@@ -2535,7 +2547,8 @@ worker_send_query(struct query_info* qinfo, uint16_t flags, int dnssec,
int want_dnssec, int nocaps, int check_ratelimit,
struct sockaddr_storage* addr, socklen_t addrlen, uint8_t* zone,
size_t zonelen, int tcp_upstream, int ssl_upstream, char* tls_auth_name,
struct module_qstate* q, int* was_ratelimited)
struct module_qstate* q, int* was_ratelimited,
int* ratelimit_incremented)
{
struct worker* worker = q->env->worker;
struct outbound_entry* e = (struct outbound_entry*)regional_alloc(
@@ -2547,7 +2560,7 @@ worker_send_query(struct query_info* qinfo, uint16_t flags, int dnssec,
want_dnssec, nocaps, check_ratelimit, tcp_upstream,
ssl_upstream, tls_auth_name, addr, addrlen, zone, zonelen, q,
worker_handle_service_reply, e, worker->back->udp_buff, q->env,
was_ratelimited);
was_ratelimited, ratelimit_incremented);
if(!e->qsent) {
return NULL;
}
@@ -2596,7 +2609,8 @@ struct outbound_entry* libworker_send_query(
struct sockaddr_storage* ATTR_UNUSED(addr), socklen_t ATTR_UNUSED(addrlen),
uint8_t* ATTR_UNUSED(zone), size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream),
int ATTR_UNUSED(ssl_upstream), char* ATTR_UNUSED(tls_auth_name),
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited))
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited),
int* ATTR_UNUSED(ratelimit_incremented))
{
log_assert(0);
return 0;
@@ -2638,6 +2652,11 @@ void libworker_event_done_cb(void* ATTR_UNUSED(arg), int ATTR_UNUSED(rcode),
log_assert(0);
}
void libworker_alloc_cleanup(void* ATTR_UNUSED(arg))
{
log_assert(0);
}
int context_query_cmp(const void* ATTR_UNUSED(a), const void* ATTR_UNUSED(b))
{
log_assert(0);
+1 -7
View File
@@ -104,10 +104,6 @@ struct worker {
struct listen_dnsport* front;
/** the backside outside network interface to the auth servers */
struct outside_network* back;
/** ports to be used by this worker. */
int* ports;
/** number of ports for this worker */
int numports;
/** the signal handler */
struct comm_signal* comsig;
/** commpoint to listen to commands. */
@@ -146,11 +142,9 @@ struct worker {
* with backpointers only. Use worker_init on it later.
* @param daemon: the daemon that this worker thread is part of.
* @param id: the thread number from 0.. numthreads-1.
* @param ports: the ports it is allowed to use, array.
* @param n: the number of ports.
* @return: the new worker or NULL on alloc failure.
*/
struct worker* worker_create(struct daemon* daemon, int id, int* ports, int n);
struct worker* worker_create(struct daemon* daemon, int id);
/**
* Initialize worker.
+59 -8
View File
@@ -643,6 +643,12 @@ handle_event_moddone(struct module_qstate* qstate, int id)
qstate->return_msg->rep &&
reply_find_answer_rrset(&qstate->qinfo, qstate->return_msg->rep);
int synth_qname = 0;
if(could_synth && !has_data && qstate->env->need_to_validate &&
qstate->return_msg && qstate->return_msg->rep &&
qstate->return_msg->rep->security == sec_status_bogus) {
verbose(VERB_ALGO, "dns64: bogus AAAA reply not synthesized");
could_synth = 0;
}
if(could_synth &&
(!has_data ||
@@ -654,8 +660,11 @@ handle_event_moddone(struct module_qstate* qstate, int id)
/* Store the response in cache. */
if( (!iq || !iq->started_no_cache_store) &&
!qstate->rpz_applied && !qstate->rpz_passthru &&
!qstate->is_subnet_answer &&
qstate->return_msg &&
qstate->return_msg->rep &&
!qstate->fwd_stub_no_cache &&
!dns_cache_store(
qstate->env, &qstate->qinfo, qstate->return_msg->rep,
0, qstate->prefetch_leeway, 0, NULL,
@@ -717,8 +726,15 @@ dns64_operate(struct module_qstate* qstate, enum module_ev event, int id,
}
if(qstate->ext_state[id] == module_finished) {
iq = (struct dns64_qstate*)qstate->minfo[id];
if(iq && iq->state != DNS64_INTERNAL_QUERY)
qstate->no_cache_store = iq->started_no_cache_store;
if(iq && iq->state != DNS64_INTERNAL_QUERY) {
if(qstate->fwd_stub_no_cache) {
/* If the forward/stub has no cache, then
* continue with the query with no cache. */
qstate->no_cache_store = qstate->fwd_stub_no_cache;
} else {
qstate->no_cache_store = iq->started_no_cache_store;
}
}
}
}
@@ -825,6 +841,7 @@ dns64_adjust_a(int id, struct module_qstate* super, struct module_qstate* qstate
size_t i, s;
struct packed_rrset_data* fd, *dd;
struct ub_packed_rrset_key* fk, *dk;
int allocated_return_msg = 0;
verbose(VERB_ALGO, "converting A answers to AAAA answers");
@@ -840,6 +857,7 @@ dns64_adjust_a(int id, struct module_qstate* super, struct module_qstate* qstate
return;
memset(super->return_msg, 0, sizeof(*super->return_msg));
super->return_msg->qinfo = super->qinfo;
allocated_return_msg = 1;
}
rep = qstate->return_msg->rep;
@@ -852,11 +870,14 @@ dns64_adjust_a(int id, struct module_qstate* super, struct module_qstate* qstate
rep->serve_expired_norec_ttl,
rep->an_numrrsets, rep->ns_numrrsets, rep->ar_numrrsets,
rep->rrset_count, rep->security, LDNS_EDE_NONE);
if(!cp)
if(!cp) {
if(allocated_return_msg) super->return_msg = NULL;
return;
}
/* allocate ub_key structures special or not */
if(!reply_info_alloc_rrset_keys(cp, NULL, super->region)) {
if(allocated_return_msg) super->return_msg = NULL;
return;
}
@@ -871,8 +892,10 @@ dns64_adjust_a(int id, struct module_qstate* super, struct module_qstate* qstate
if(i<rep->an_numrrsets && fk->rk.type == htons(LDNS_RR_TYPE_A)) {
/* also sets dk->entry.hash */
dns64_synth_aaaa_data(fk, fd, dk, &dd, super->region, dns64_env);
if(!dd)
if(!dd) {
if(allocated_return_msg) super->return_msg = NULL;
return;
}
/* Delete negative AAAA record from cache stored by
* the iterator module */
rrset_cache_remove(super->env->rrset_cache, dk->rk.dname,
@@ -889,15 +912,19 @@ dns64_adjust_a(int id, struct module_qstate* super, struct module_qstate* qstate
dk->rk.dname = (uint8_t*)regional_alloc_init(super->region,
fk->rk.dname, fk->rk.dname_len);
if(!dk->rk.dname)
if(!dk->rk.dname) {
if(allocated_return_msg) super->return_msg = NULL;
return;
}
s = packed_rrset_sizeof(fd);
dd = (struct packed_rrset_data*)regional_alloc_init(
super->region, fd, s);
if(!dd)
if(!dd) {
if(allocated_return_msg) super->return_msg = NULL;
return;
}
}
packed_rrset_ptr_fixup(dd);
@@ -928,8 +955,10 @@ dns64_adjust_ptr(struct module_qstate* qstate, struct module_qstate* super)
return;
super->return_msg->qinfo = super->qinfo;
if (!(super->return_msg->rep = reply_info_copy(qstate->return_msg->rep,
NULL, super->region)))
NULL, super->region))) {
super->return_msg = NULL;
return;
}
/*
* Adjust the domain name of the answer RR set so that it matches the
@@ -998,6 +1027,21 @@ dns64_inform_super(struct module_qstate* qstate, int id,
/* Use return code from A query in response to client. */
if (super->return_rcode != LDNS_RCODE_NOERROR)
super->return_rcode = qstate->return_rcode;
/* RPZ applied to the subquery need to then change (not cache)
* the super query. With the super query not cached, it is
* going to run the state machine modules on incoming queries,
* that fetch the subquery (cache) response, and modify it
* according to the rpz policy. That makes the synthesized
* super query also adjusted by rpz policies. But loses cache
* hits. Even though the subquery likely is answered from cache,
* internally in its state machine process. */
if(qstate->rpz_applied)
super->rpz_applied = 1;
if(qstate->rpz_passthru)
super->rpz_passthru = 1;
/* Since the super qstate has a new response, its errinf is removed. */
super->errinf = NULL;
/* Generate a response suitable for the original query. */
if (qstate->qinfo.qtype == LDNS_RR_TYPE_A) {
@@ -1006,9 +1050,16 @@ dns64_inform_super(struct module_qstate* qstate, int id,
log_assert(qstate->qinfo.qtype == LDNS_RR_TYPE_PTR);
dns64_adjust_ptr(qstate, super);
}
/* If the sub-query has no cache store, then also the super query. */
if(qstate->fwd_stub_no_cache)
super->fwd_stub_no_cache = 1;
/* Store the generated response in cache. */
if ( (!super_dq || !super_dq->started_no_cache_store) &&
if ( super->return_msg && super->return_msg->rep &&
(!super_dq || !super_dq->started_no_cache_store) &&
!qstate->fwd_stub_no_cache &&
!super->rpz_applied && !super->rpz_passthru &&
!super->is_subnet_answer &&
!dns_cache_store(super->env, &super->qinfo, super->return_msg->rep,
0, super->prefetch_leeway, 0, NULL, super->query_flags,
qstate->qstarttime, qstate->is_valrec))
+32 -5
View File
@@ -361,7 +361,7 @@ dnscrypt_server_uncurve(struct dnsc_env* env,
len -= DNSCRYPT_QUERY_HEADER_SIZE;
while (*sldns_buffer_at(buffer, --len) == 0)
while (len>0 && *sldns_buffer_at(buffer, --len) == 0)
;
if (*sldns_buffer_at(buffer, len) != 0x80) {
@@ -474,10 +474,18 @@ dnscrypt_server_curve(const dnsccert *cert,
uint8_t *const buf = sldns_buffer_begin(buffer);
size_t len = sldns_buffer_limit(buffer);
if(len + DNSCRYPT_REPLY_HEADER_SIZE > sldns_buffer_capacity(buffer))
return -1;
sldns_buffer_clear(buffer);
if(udp){
if (max_len > max_reply_size)
max_len = max_reply_size;
}
if(max_len > sldns_buffer_capacity(buffer))
max_len = sldns_buffer_capacity(buffer);
if(max_len > 65535)
max_len = 65535;
memcpy(nonce, client_nonce, crypto_box_HALF_NONCEBYTES);
@@ -520,6 +528,7 @@ dnscrypt_server_curve(const dnsccert *cert,
DNSCRYPT_MAGIC_HEADER_LEN,
nonce,
crypto_box_NONCEBYTES);
sldns_buffer_flip(buffer);
sldns_buffer_set_limit(buffer, len + DNSCRYPT_REPLY_HEADER_SIZE);
return 0;
}
@@ -663,6 +672,8 @@ dnsc_find_cert(struct dnsc_env* dnscenv, struct sldns_buffer* buffer)
}
dnscrypt_header = (struct dnscrypt_query_header *)sldns_buffer_begin(buffer);
for (i = 0U; i < dnscenv->signed_certs_count; i++) {
if(!certs[i].keypair)
continue;
if (memcmp(certs[i].magic_query, dnscrypt_header->magic_query,
DNSCRYPT_MAGIC_HEADER_LEN) == 0) {
return &certs[i];
@@ -804,6 +815,7 @@ dnsc_parse_keys(struct dnsc_env *env, struct config_file *cfg)
sizeof *env->keypairs);
env->certs = sodium_allocarray(env->signed_certs_count,
sizeof *env->certs);
memset(env->certs, 0, env->signed_certs_count * sizeof(*env->certs));
cert_id = 0U;
keypair_id = 0U;
@@ -830,7 +842,14 @@ dnsc_parse_keys(struct dnsc_env *env, struct config_file *cfg)
if(memcmp(current_keypair->crypt_publickey,
env->signed_certs[c].server_publickey,
crypto_box_PUBLICKEYBYTES) == 0) {
dnsccert *current_cert = &env->certs[cert_id++];
dnsccert* current_cert;
if(cert_id >= env->signed_certs_count) {
log_err("dnscrypt: secret key %s matches a cert that "
"is already bound to another key (duplicate "
"dnscrypt-secret-key?)", head->str);
return -1;
}
current_cert = &env->certs[cert_id++];
found_cert = 1;
current_cert->keypair = current_keypair;
memcpy(current_cert->magic_query,
@@ -912,12 +931,13 @@ dnsc_handle_curved_request(struct dnsc_env* dnscenv,
}
int
dnsc_handle_uncurved_request(struct comm_reply *repinfo)
dnsc_handle_uncurved_request(struct comm_reply *repinfo,
struct sldns_buffer* buffer)
{
if(!repinfo->c->dnscrypt) {
return 1;
}
sldns_buffer_copy(repinfo->c->dnscrypt_buffer, repinfo->c->buffer);
sldns_buffer_copy(repinfo->c->dnscrypt_buffer, buffer);
if(!repinfo->is_dnscrypted) {
return 1;
}
@@ -963,12 +983,19 @@ dnsc_create(void)
int
dnsc_apply_cfg(struct dnsc_env *env, struct config_file *cfg)
{
int nkeys;
if(dnsc_parse_certs(env, cfg) <= 0) {
fatal_exit("dnsc_apply_cfg: no cert file loaded");
}
if(dnsc_parse_keys(env, cfg) <= 0) {
nkeys = dnsc_parse_keys(env, cfg);
if(nkeys <= 0) {
fatal_exit("dnsc_apply_cfg: no key file loaded");
}
if((size_t)nkeys < env->signed_certs_count) {
fatal_exit("dnsc_apply_cfg: %u dnscrypt-provider-cert file(s) have no "
"matching dnscrypt-secret-key",
(unsigned)(env->signed_certs_count - (size_t)nkeys));
}
randombytes_buf(env->hash_key, sizeof env->hash_key);
env->provider_name = cfg->dnscrypt_provider;
+2 -1
View File
@@ -128,7 +128,8 @@ int dnsc_handle_curved_request(struct dnsc_env* dnscenv,
* \return 0 in case of failure.
*/
int dnsc_handle_uncurved_request(struct comm_reply *repinfo);
int dnsc_handle_uncurved_request(struct comm_reply *repinfo,
struct sldns_buffer* buffer);
/**
* Computes the size of the shared secret cache entry.
+36 -17
View File
@@ -176,26 +176,29 @@ dt_create(struct config_file* cfg)
env->dtio = dt_io_thread_create();
if(!env->dtio) {
log_err("malloc failure");
free(env);
dt_delete(env);
return NULL;
}
if(!dt_io_thread_apply_cfg(env->dtio, cfg)) {
dt_io_thread_delete(env->dtio);
free(env);
dt_delete(env);
return NULL;
}
if(!dt_apply_cfg(env, cfg)) {
dt_delete(env);
return NULL;
}
dt_apply_cfg(env, cfg);
return env;
}
static void
static int
dt_apply_identity(struct dt_env *env, struct config_file *cfg)
{
char buf[MAXHOSTNAMELEN+1];
if (!cfg->dnstap_send_identity) {
free(env->identity);
env->identity = NULL;
return;
env->len_identity = 0;
return 1;
}
free(env->identity);
if (cfg->dnstap_identity == NULL || cfg->dnstap_identity[0] == 0) {
@@ -203,36 +206,49 @@ dt_apply_identity(struct dt_env *env, struct config_file *cfg)
buf[MAXHOSTNAMELEN] = 0;
env->identity = strdup(buf);
} else {
fatal_exit("dt_apply_identity: gethostname() failed");
log_err("dt_apply_identity: gethostname() failed: %s",
strerror(errno));
env->identity = NULL;
env->len_identity = 0;
return 0;
}
} else {
env->identity = strdup(cfg->dnstap_identity);
}
if (env->identity == NULL)
fatal_exit("dt_apply_identity: strdup() failed");
if (env->identity == NULL) {
log_err("dt_apply_identity: strdup() failed");
env->len_identity = 0;
return 0;
}
env->len_identity = (unsigned int)strlen(env->identity);
verbose(VERB_OPS, "dnstap identity field set to \"%s\"",
env->identity);
return 1;
}
static void
static int
dt_apply_version(struct dt_env *env, struct config_file *cfg)
{
if (!cfg->dnstap_send_version) {
free(env->version);
env->version = NULL;
return;
env->len_version = 0;
return 1;
}
free(env->version);
if (cfg->dnstap_version == NULL || cfg->dnstap_version[0] == 0)
env->version = strdup(PACKAGE_STRING);
else
env->version = strdup(cfg->dnstap_version);
if (env->version == NULL)
fatal_exit("dt_apply_version: strdup() failed");
if (env->version == NULL) {
log_err("dt_apply_version: strdup() failed");
env->len_version = 0;
return 0;
}
env->len_version = (unsigned int)strlen(env->version);
verbose(VERB_OPS, "dnstap version field set to \"%s\"",
env->version);
return 1;
}
void
@@ -276,15 +292,18 @@ dt_apply_logcfg(struct dt_env *env, struct config_file *cfg)
lock_basic_unlock(&env->sample_lock);
}
void
int
dt_apply_cfg(struct dt_env *env, struct config_file *cfg)
{
if (!cfg->dnstap)
return;
return 1;
dt_apply_identity(env, cfg);
dt_apply_version(env, cfg);
dt_apply_logcfg(env, cfg);
if(!dt_apply_identity(env, cfg))
return 0;
if(!dt_apply_version(env, cfg))
return 0;
return 1;
}
int
+2 -2
View File
@@ -102,9 +102,9 @@ dt_create(struct config_file* cfg);
* Apply config settings.
* @param env: dnstap environment object.
* @param cfg: new config settings.
* @return false on failure.
*/
void
dt_apply_cfg(struct dt_env *env, struct config_file *cfg);
int dt_apply_cfg(struct dt_env *env, struct config_file *cfg);
/**
* Apply config settings for log enable for message types.
+1 -1
View File
@@ -2144,7 +2144,7 @@ static void* dnstap_io(void* arg)
#endif
log_thread_set(&dtio->threadnum);
ub_thread_setname(dtio->tid, name);
ub_thread_setname(ub_thread_self(), name);
/* setup */
verbose(VERB_ALGO, "start dnstap io thread");
+9 -2
View File
@@ -1659,7 +1659,8 @@ struct outbound_entry* worker_send_query(
socklen_t ATTR_UNUSED(addrlen), uint8_t* ATTR_UNUSED(zone),
size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream),
int ATTR_UNUSED(ssl_upstream), char* ATTR_UNUSED(tls_auth_name),
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited))
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited),
int* ATTR_UNUSED(ratelimit_incremented))
{
log_assert(0);
return 0;
@@ -1693,7 +1694,8 @@ struct outbound_entry* libworker_send_query(
socklen_t ATTR_UNUSED(addrlen), uint8_t* ATTR_UNUSED(zone),
size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream),
int ATTR_UNUSED(ssl_upstream), char* ATTR_UNUSED(tls_auth_name),
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited))
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited),
int* ATTR_UNUSED(ratelimit_incremented))
{
log_assert(0);
return 0;
@@ -1735,6 +1737,11 @@ void libworker_event_done_cb(void* ATTR_UNUSED(arg), int ATTR_UNUSED(rcode),
log_assert(0);
}
void libworker_alloc_cleanup(void* ATTR_UNUSED(arg))
{
log_assert(0);
}
int context_query_cmp(const void* ATTR_UNUSED(a), const void* ATTR_UNUSED(b))
{
log_assert(0);
+652
View File
@@ -1,3 +1,655 @@
11 August 2026: Wouter
- Fix #1492 from zacek: Data race in log_init() on
key_created/log_lock when calling ub_ctx_create()
concurrently from multiple threads.
- Fix stat_values.tdir test to have less test failures.
7 August 2026: Wouter
- Fix #1489 from jplesnik: Replace removed Python 2 C API
macros for SWIG 4.5.0 compatibility.
6 August 2026: Alex Khanin
- Fix #1488: bounds check in packed_rr_to_string, it checked
the assembled rr length against the output string length
dest_len, instead of against the size of the rr buffer it
writes into. Callers in cachedump.c and remote.c pass a
dest_len larger than that buffer.
- Unit test for packed_rr_to_string.
6 August 2026: Wouter
- Fix #1485: the list_forwards command omits port numbers.
The list_forwards and list_stubs commands for
unbound-control print port and tls auth name.
- Fix #1487: regression in 1.26.0, ipsecmod is now always
partly enabled.
4 August 2026: Wouter
- Fix to set makedist.sh to not wget config.sub and
config.guess from git repo. The fetch times out, and the
version from libtoolize is much more recent now than
that it was when the wget was added.
31 July 2026: Wouter
- For #1483: The failure reason when an NSEC NXDOMAIN is
encountered when looking for an insecure delegation, is
fixed to mention the NSEC records, instead of nonexistent
NSEC3 records, that it attempted.
30 July 2026: Wouter
- Fix #1482: DNS-over-QUIC doesn't work with simple config.
That fixes interface-automatic for use with doq service.
28 July 2026: Wouter
- Tag for 1.26.0rc1. The repo continues with version 1.26.1.
This became 1.26.0 on 4 aug 2026.
24 July 2026: Wouter
- Merge #1433 from jisakiel: Add new static zone type
block_aaaa to suppress AAAA queries.
- Unit test for block_a and block_aaaa.
- Fix #1477: respip + dns64: dns64 uses A records modified by
respip instead of original A records. Adds local-zone types
block_a_wdata and block_aaaa_wdata, that are like block_a
and block_aaaa, and uses local-data if present.
- set code repository version to 1.26.0.
- Update generated man pages.
- Fix to allow test fake sha1 on systems with possible sha1
support.
- Fix to use sha256 for unbound-anchor unit test.
- Fix unbound-anchor check for return value of
X509_NAME_get_text_by_NID of the emailaddress.
- Fix lock test protect for auth zone change.
- Fix to lock shared_ports structure during initialisation.
- Fix to lock anchor structure when file is set for it in
parse of the header.
- Merge #1480 from petrvaganoff: authzone: fix memory leak in
xfer_set_masters() error path.
- Fix unused variable warnings in shared_ports_fetch_random
and shared_ports_return_port when compiled without threads.
- Fix to guard access to shared ports interface array during
set up, for analyzer.
- Fix sign of comparison warning in shared ports setup.
- Fix #1481: Fix to use tls-port after referral if
tls-upstream is set.
- Merge #1479 from psumbera: Fix pthread detection on
Solaris 11.4.
- Fix to call OPENSSL_cleanup on exit when that is defined.
23 July 2026: Wouter
- Updated credits for Xuanchao Xie in 22 july changelog.
- Merge #1478 from petrvaganoff: pythonmod: add check return
value after ftell().
- Fix that for NSEC3 proofs the NSEC3 zone, as the b32.name is
checked to be the same as the signer name. Also RRSIGs are
not considered valid when an NSEC3 is not b32.signerzone.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that the aggressive negative cache does not insert NSEC
records with overreaching next owner name. Also the result
is not above the trust anchor's bailiwick. Also RRSIGS are
not considered valid when an NSEC next owner name is not
under the signer zone name. Thanks to Qifan Zhang, Palo
Alto Networks, for the report.
- Fix mesh cycle detection for configuration with respip CNAME
loop and tagged clients. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
22 July 2026: Wouter
- Release tag for 1.25.2, with the security commits:
- Fix CVE-2026-14586, Assertion in libngtcp2 when under pressure
in high concurrency DNS-over-QUIC environments. Thanks to Kunta
Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University,
for the report.
- Fix CVE-2026-32665, Remote DNS-over-QUIC denial of
service due to `quic-size` budget bypass. Thanks to N0zoM1z0
(https://github.com/N0zoM1z0) for the report. In addition, thanks to
Kunta Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University,
for also reporting this issue. In addition, thanks to Qifan Zhang,
Palo Alto Networks, for also reporting this issue. In addition,
thanks to Xuanchao Xie, Lutong Chen, and Kaiping Xue of the
University of Science and Technology of China (USTC), for also
reporting this issue.
- Fix CVE-2026-40691, Packet of death for DNSCrypt over TCP. Thanks
to Qifan Zhang, Palo Alto Networks, for the report. In addition,
thanks to Trung Nguyen (@everping) of CyStack, for also reporting
this issue.
- Fix CVE-2026-41637, Degradation of resolution service from
improperly accounted client-terminated DNS-over-QUIC queries. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
- Fix CVE-2026-42955, Extra fix for CVE-2026-40622 to also clamp
the TTL of A/AAAA records disallowing a one-time 'ghost domain'
delegation renewal via glue records. Thanks to Qifan Zhang, Palo
Alto Networks, for the report.
- Fix CVE-2026-44621, Libunbound applications configured with
'unwanted-reply-threshold' could eventually be abruptly
terminated. Thanks to Qifan Zhang, Palo Alto Networks, for the
report.
- Fix CVE-2026-44687, Off-by-one error in 'harden-below-nxdomain'
logic can shadow a stub/forward zone by a legitimate parent's
NXDOMAIN. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix CVE-2026-44690, Cross-zone wildcard cache poisoning via
RRSIG.labels manipulation. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix CVE-2026-46582, A wildcard replay, as another piece of data,
triggers poisoning in the serve expired reply path. Thanks to
Qifan Zhang, Palo Alto Networks, for the report.
- Fix CVE-2026-50045, 'max-global-quota' reset by DNSSEC validation
restarts. Thanks to Kunjie Shang, University of Science and
Technology of China, for the report.
- Fix CVE-2026-50046, Possible heap use-after-free in an error path
when a DoT forwarded query is jostled out. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
- Fix CVE-2026-50243, 'response-ip'/'rpz' can rewrite BOGUS answers
instead of returning SERVFAIL. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix CVE-2026-50248, BOGUS configured primary hostname accepted for
XFR in auth/rpz zones. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix CVE-2026-50251, Attacker supplied `0.0.0.0`/`::` glue triggers
defensive full-cache flush. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix CVE-2026-50252, Possible cache poisoning attack by mapping
source port population per thread. Thanks to Inbal Schussheim and
Amit Klein, Hebrew University, for the report.
- Fix CVE-2026-52863, Memory corruption could lead to crash and
denial of service. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix CVE-2026-54478, DNS Cookie bypass when combined with
proxy-protocol use. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix CVE-2026-55708, Privacy/configuration issue when adding local
data in views through 'unbound-control'. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
- Fix CVE-2026-55717, 'serve-expired-client-timeout' and 'response-ip'
CNAME redirect could lead to a crash. Thanks to Qifan Zhang, Palo
Alto Networks, for the report. In addition, thanks to Xin Wang,
Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University,
for also reporting this issue.
- Fix CVE-2026-55973, 'dns-error-reporting: yes' leads to stack buffer
overflow. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix CVE-2026-55990, Packet of death for a DNSCrypt misconfigured
Unbound. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix CVE-2026-55991, Remote DNS-over-QUIC (DoQ) flow-control
assertion failure in libngtcp2. Thanks to Qifan Zhang, Palo Alto
Networks, for the report. In addition, thanks to Xuanchao Xie,
Lutong Chen, and Kaiping Xue of the University of Science and
Technology of China (USTC), for also reporting this issue.
- Fix CVE-2026-56416, Possible heap buffer overflow when validator
canonicalizes RDATA that contains domain name. Thanks to Qifan
Zhang, Palo Alto Networks, for the report.
- Fix CVE-2026-56444, Degradation of resolution service when
'discard-timeout' and 'serve-expired-client-timeout' are combined in
unusual configuration. Thanks to Qifan Zhang, Palo Alto Networks,
for the report. In addition, thanks to Xin Wang, Jiapeng Li,
and Jiajia Liu, Northwestern Polytechnical University, for also
reporting this issue. In addition, thanks to Haruki Oyama (Waseda
University), for also reporting this issue.
- Set the repository to 1.25.3, it continues with the previous
changes.
- Unit test for CVE-2026-42955.
- Unit test for CVE-2026-44687.
- Unit test for CVE-2026-44690.
- Unit test for CVE-2026-46582.
- Unit test for CVE-2026-50045.
- Unit test for CVE-2026-50243.
- Unit test for CVE-2026-50248.
- Unit test for CVE-2026-55717.
- Unit test for CVE-2026-55973.
- Unit test for CVE-2026-56416.
- Fix error in log printout in fix for CVE-2026-50248, when the
primary name is bogus.
- iana portlist update.
21 July 2026: Wouter
- Merge #1476 from petrvaganoff: ipsecmod: fix possible deref
on null after reply_find_answer_rrset().
20 July 2026: Wouter
- Merge #1475 from petrvaganoff: ipsecmod: fix deref on null
in ipsecmod-whitelist after OOM.
- Fix #1474: DoQ responses are never padded - pad-responses
does not apply to comm_doq (RFC 9250 §5.4 MUST).
9 July 2026: Wouter
- Merge #1383 from jdek: Fix randomness generation on
macOS/iOS under chroot.
- Fix unit test for malformed svcb for test on Windows.
2 July 2026: Wouter
- Merge #1087: Overload `local_data_remove` to support removing
specific records.
30 June 2026: Wouter
- Fix #1469: dohclient: DoH POST missing content-length → :status
400 from strict resolvers (Cloudflare, Mullvad).
- iana portlist updated.
26 June 2026: Wouter
- Merge #1467: daemon: fix DEREF_AFTER_NULL.EX.COND on
worker_init. This fixes error handling if the worker
stat_timer allocation has an out of memory error. That
makes the server not crash later, attempting to use it.
24 June 2026: Wouter
- Merge #1465 from dag-erling: Add libunbound/remote.h. Add
a shared header containing prototypes for functions that
both ends of a remote control connection need to implement.
19 June 2026: Wouter
- Fix for #1457: fix thread setname for thread start of
dnstap, and fast_reload.
- Fix to update github ci actions/checkout to v7.
- Fix warning about file_string_matches in unbound-checkconf.
17 June 2026: Wouter
- Fix that after fast_reload the disown of the auth zone
transfer task cleans the chunk list. Also fix the
auth_transfer_limit test to use a forwarder for each type
of failure, so the one is not blocked by the other waiting.
- Fix to remove debug from auth_transfer_limit test.
- Fix that unbound-checkconf checks if an auth-zone download
can overwrite another file, by filename collision.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that malloc failure in auth-zone insert rr does
not create an empty node and does not cause an infinite
loop. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
- Fix that unbound-control auth_zone_reload stops the
server answering from the zone after a failure to read.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that malloc failure in dns64_inform_super does
not set up a half-built reply for cache store, that could
lead to a crash. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix that malloc failure for new_local_rrset for RPZ qname
trigger RR insert does not crash. It does not link a
partial RRset, and logs an error on failure, and cleans
up the dname allocation. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix that malloc failure in doq connection setup, does
not crash in doq connection delete later. Thanks to Qifan
Zhang, Palo Alto Networks, for the report.
- Fix that malloc failure for ngtcp2_conn_server_new
cleans up reference that older ngtcp2 versions can leave.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that on malloc failure during accept of TCP, the
socket is not left to cause a read event loop. It uses
slow-accept to delay accepting new connections, if
that fails it drops the new connections. When the tcp
connection usage is full, it waits for 50msec, to allow
existing queries to be resolved. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
- Fix that malloc failure for rpz_strip_nsdname is
checked and handled, so that it does not crash later.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that malloc failure during edns subnet addrtree
insert is checked, so it does not crash later. Thanks to
Qifan Zhang, Palo Alto Networks, for the report.
- Fix to check the return value of auth_xfer_create
during fast_reload auth-zone add and change processing.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix to check for malloc failure in rpz response create,
for nodata and nxdomain, so it does not crash later.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that fast_reload does not terminate the server
on malloc failure for dnstap, or if gethostname fails.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix after malloc failure for stats, then it drains the pipe
so the internal messaging stays correct. Also it does
not exit the server if stats pipe communication fails.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that fast_reload does not terminate the server
on config read failure after malloc failure. Thanks to
Qifan Zhang, Palo Alto Networks, for the report.
- Fix that fast_reload does not terminate the server if
random init for DNS cookies fails. The data is only random
generated if cookies are enabled, and the random data
is necessary. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
17 June 2026: Yorgos
- Fix memory leak on DNAME 0TTL records.
16 June 2026: Wouter
- Fix to disallow $INCLUDE for secondary zones. Start up
of server continues if a secondary zone fails to load.
Failed loads clear the zone data, so there is no partial
zone. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
- Fix that when SVCB records cannot be written out, and
are written in unknown format, that the zone read allows
such unknown format SVCB records. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
- Fix that a half-written trust anchor file does not crash
the server at runtime. It unlinks a wrong file from the list.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that auth-zone, and RPZ zones, do not allow out-of-zone
records. These are records that are not under the zone apex.
The out-of-zone records are dropped from the zone contents.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that dns64 does not ignore the `forward-no-cache` and
`stub-no-cache` options. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix that a signed wildcard NSEC, is checked before use,
so it does not allow insecure DS proofs inappropriately.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that after malloc failure a half-built local_alias does
not crash the server. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix that for a zonefile only zone, if that file does not
exist on server start, the server continues to start with
a warning log message. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix that after malloc failure in RPZ load a half built
list does not crash later. The newly created RRset is
linked after creation has succeeded. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
- Fix that dnscrypt configuration does not crash, due to
inconsistency between secret and public keys. Also
duplicate files are skipped. Thanks to Qifan Zhang, Palo
Alto Networks, for the report.
- Fix locking in libunbound ub_ctx_set_event call.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that libunbound pipe functions fail with error after
an event base is set. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix for neater solution to clear log thread id after
worker init failure. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix incorrect cleanup after an allocation failure for
a delegation point. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix that after malloc failure in find_tag_datas, the
local_alias is cleaned up. Thanks to Qifan Zhang, Palo
Alto Networks, for the report.
- Fix that after shared memory cannot be created, from
`shm-enable`, the server does not crash. Thanks to Qifan
Zhang, Palo Alto Networks, for the report.
- Fix incorrect cleanup after an allocation failure for
a delegation point in a region. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
- Fix after malloc failure the rrset_insert_rr in
localzone processing, during RPZ qname trigger processing,
the RRset retains its previous data correcly. Thanks to
Qifan Zhang, Palo Alto Networks, for the report.
- Fix for #1462: Fix that auth primary host name lookup
allows CNAMEs.
15 June 2026: Wouter
- Fix to add `max-transfer-size` and `max-transfer-time` that
limit auth-zone and rpz transfer amount and time taken.
Default is disabled. This hardens against unbounded
transfers. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix perform a full transfer every number of incremental
transfers, to stop increasing memory usage, for rpz
zones. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
- Fix assertion failure for long HTTP header that fills
buffer. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
- Fix buffer overflow when configured with lower than
default size and http transfer. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
- Fix that misconfigured `iter-scrub-ns: 0` causes request
failures. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix that fast_reload when a zonemd verification lookup
it in progress with subnet loaded, deregisters the
callback. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix for fast_reload that removes an auth zone while its
lookups are in progress, for a primary name. Also after the
change, it no longer picks up the old results. Thanks to
Qifan Zhang, Palo Alto Networks, for the report.
- Fix integer overflow in infra-cache-max-rtt calculation.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix erroneous DNS error report values after bogus AAAA
query caused error information that was not cleared by
a successful A subquery. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix integer overflow for very high values of
`sock-queue-timeout`. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix that fast_reload does not terminate the server for
errors in config, for key files. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
- Fix log of an aliased qname, to not use freed region
memory. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
- Fix DNAME synthesis from cache that keeps use of 0TTL
entries in a sliding window. It did not surpass RRSIG
expiry. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
- Fix misconfigured ipsecmod hook causing path name
similarity with other file. The ipsecmod is changed for
exec of the hook. The ipsecmod hook, if a script, has to
start now with a line like `#!/bin/sh`. Thanks to Qifan
Zhang, Palo Alto Networks, for the report.
- Fix that dns64 bypasses rpz-passthru rule during
synthesis. This restricted more than necessary. Thanks to
Qifan Zhang, Palo Alto Networks, for the report.
12 June 2026: Wouter
- Fix that for auth-zone and rpz zones the allow-notify
addresses and netblocks are available from start, and
fix the probe step skip.
11 June 2026: Wouter
- Fix for #1306: configure detects specifically the call to
SSL_set_quic_tls_early_data_enabled and
SSL_set_quic_early_data_enabled, so the correct one is used.
- Fix for #1306: configure checks if the ngtcp2_crypto_ossl
header file is available, and prints an error otherwise.
- Fix #1437: Fix compile with OpenSSL 4.0.1.
- Fix compile for OpenSSL 1.0.2 and before in server cleanup.
10 June 2026: Wouter
- Fix pythonmod script read for numeric overflow.
- Fix warnings with gcc in compat/inet_pton.c.
9 June 2026: Wouter
- Fix unit test for ecs to check for malloc success.
3 June 2026: Wouter
- Fix that the processing of class responses does not have
a heap use-after-free. That could happen if at least two
distinct classes are configured for resolution. Thanks
to Qifan Zhang, Palo Alto Networks for the report.
In addition, thanks to Xin Wang, Jiapeng Li, and Jiajia
Liu, Northwestern Polytechnical University, for also
reporting this.
- Fix negative cache to work with NSEC3 records without salt.
Thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern
Polytechnical University, for the report.
- Fix parse of svcbparam ech, it had incorrect length. Thanks
to Qifan Zhang, Palo Alto Networks for the report.
- Fix that quotation and escaping works the same in auth-zone
url content, as in the zonefile read. Thanks to Qifan Zhang,
Palo Alto Networks for the report.
- Fix ipset module to use larger domain name buffers, and
check buffer lengths. Thanks to Qifan Zhang, Palo Alto
Networks for the report.
- Fix PROXYv2 header read and consume, it checks the header
size. Thanks to Qifan Zhang, Palo Alto Networks for
the report.
- Fix negative cache NSEC3 nodata proof, to use the correct
message size. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix fast_reload for when a ZONEMD lookup is in progress.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that validation canonicalization of domain names
in rdata checks for buffer bounds. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
- Fix that dump_cache has a larger buffer for records,
and it checks that an owner name does not collide with BADRR
on the input, and changes verbosity on the log of failure in
rrset to string. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix that dns64 cleans up the allocated message if the adjust
routines fail, and checks if there is a reply before cache
store, also unbound checks if A and AAAA are malformed
for auth-zones. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
3 June 2026: Yorgos
- Fix const as reported by newest compiler warnings.
29 May 2026: Wouter
- Fix header_seen detection for trust anchor files, so that it
detects the id line.
- iana portlist updated.
- Update icannbundle.pem certificates in unbound-anchor. It
has the public keys for 2009 to 2029 and for 2025 to 2045.
- Fix unit test to check for new icannbundle.pem.
28 May 2026: Wouter
- Fix #1457: race condition causes segfault when starting
threads.
27 May 2026: Wouter
- Fix for autotrust state-file line overflow, that can give
hold-down bypass. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix to limit the DSNS per-label walk in the iterator. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that the ratelimit is decremented on successful
referrals. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
- Fix that msgencode insert_query has the correct assertion,
for a local_alias. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix to reset the tcp-timeout before applying a load based
reduction. Thanks to Qifan Zhang, Palo Alto Networks, for the
report.
- Fix to decrement the per-netblock tcp connection limits, so
it keeps usable. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix manual to document ratelimit, that it is for target
nameservers for a domain, and keeps queries limited. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
- Fix, in depth, for respip rewrite of dns64 responses. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that dns64 with subnetcache does not write ECS scoped
answers to global cache. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix ipset module for name too long checks, race conditions
on local name buffer, and for socket close race condition.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix that validator caps number of ANY RRsets it can
validate, and the wait timer is shortened. Thanks to Qifan
Zhang, Palo Alto Networks, for the report.
- Fix analyzer warning in mesh_new_client.
26 May 2026: Wouter
- Fix for mesh new client and mesh new callback to rollback the
added address, tcp mesh state and callback when there is a failure
to initialize. This fixes the mesh accounting of reply addresses.
Thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern
Polytechnical University, for the report
20 May 2026: Wouter
- Fix CVE-2026-33278, Possible remote code execution during DNSSEC
validation. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix CVE-2026-42944, Heap overflow and crash with multiple nsid,
cookie, padding EDNS options. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix CVE-2026-42959, Crash during DNSSEC validation of malicious
content. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix CVE-2026-32792, Packet of death with DNSCrypt. Thanks to Andrew
Griffiths from 'calif.io' for the report.
- Fix CVE-2026-40622, "Ghost domain name" variant. Thanks to Qifan
Zhang, Palo Alto Networks, for the report.
- Fix CVE-2026-41292, Parsing a long list of incoming EDNS options
degrades performance. Thanks to GitHub user 'N0zoM1z0', also Qifan
Zhang from Palo Alto Networks, for the report.
- Fix CVE-2026-42534, Jostle logic bypass degrades resolution
performance. Thanks to Qifan Zhang, Palo Alto Networks, for the
report.
- Fix CVE-2026-42923, Degradation of service with unbounded NSEC3
hash calculations. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
- Fix CVE-2026-42960, Possible cache poisoning attack while following
delegation. Thanks to TaoFei Guo from Peking University, Yang Luo
and JianJun Chen, Tsinghua University, for the report.
- Fix CVE-2026-44390, Unbounded name compression in certain cases
causes degradation of service. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix CVE-2026-44608, Use after free and crash in RPZ code. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
- Tag for 1.25.1 release, it contains the security fixes on 1.25.0.
the code repository continues with in addition the previous fixes,
for 1.25.2.
- Unit test for CVE-2026-33278.
- Unit test for CVE-2026-42944.
- Unit test for CVE-2026-42959.
- Unit test for CVE-2026-40622.
- Unit test for CVE-2026-42960.
- Fix in depth for serve-expired responses from cachedb, that it
does not store bogus. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix lame server detection, for selfpointed glue records.
Thanks to Shuhan Zhang, Dan Li, and Baojun Liu from Tsinghua
University for the report.
- Fix cleaning up DoH session. The same query can be on multiple
streams in a session. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
- Fix for signed same-owner CNAME and ordinary RRset responses.
Thanks to Xin Wang and Jiajia Liu, Northwestern Polytechnical
University, for the report.
18 May 2026: Wouter
- Fix for mixed class referrals, the resolver uses the query
class. Thanks to Xin Wang and Jiajia Liu, Northwestern
Polytechnical University, for the report.
15 May 2026: Wouter
- Fix man page entry for so-sndbuf, it is for responses sent out.
- Fix val_find_DS for robustness, to check the result of
packet_rrset_copy_region before using it. Thanks to Xin Wang
and Jiajia Liu, Northwestern Polytechnical University, for
the report.
- Fix that for dns64 answers, the AAAA query is checked to be
DNSSEC validated, when DNSSEC is enabled. This improves
the RFC6147 conformance of Unbound. Thanks to Xin Wang
and Jiajia Liu, Northwestern Polytechnical University, for
the report. In addition, thanks to Qifan Zhang, Palo Alto
Networks, for reporting it.
- Fix for allocation-failure hardening of rrset cache wildcard
storage and canonical NSEC owner replacement. Thanks to Xin
Wang and Jiajia Liu, Northwestern Polytechnical University,
for the report.
- Fix DNSSEC validation with libnettle for noncanonical RSA
DNSKEYs with leading zeroes for n. Thanks to Xin Wang and
Jiajia Liu, Northwestern Polytechnical University, for
the report.
- Fix DNSKEY size calculation for noncanonical RSA DNSKEYs
with leading zeroes for n. Thanks to Xin Wang and Jiajia Liu,
Northwestern Polytechnical University, for the report.
11 May 2026: Yorgos
- Fix comment and verbose logging for EDNS fallback buffer size.
8 May 2026: Wouter
- Fix to relax assertions after the TTL 0 handling change.
This relaxes an assertion in cachedb (it fails instead),
and for packet_rrset_copy_region.
7 May 2026: Wouter
- Fix for Heap Out-of-Bounds Write via size_t-to-int Truncation
in setup_if() - outside_network_create(). This fixes that
large values for num_ports do not overflow and create
invalid references after integer truncation. Thanks
to Karnakar Reddy (@karnakarreddi) for the report.
- Fix to clean up log ids after a failure to start a worker thread.
1 May 2026: Wouter
- iana portlist updated.
29 April 2026: Wouter
- tag for 1.25.0. The code repository continues with 1.25.1 in
development.
- Fix windows 64bit build for libssp dependency.
23 April 2026: Wouter
- Merge #1441: Fix buffer overrun in
doq_repinfo_retrieve_localaddr().
+9
View File
@@ -899,6 +899,10 @@ server:
# that name
# o block_a resolves all records normally but returns
# NODATA for A queries and ignores local data for that name
# o block_aaaa similarly to block_a, resolves all records normally but
# returns NODATA for AAAA queries and ignores local data for that name
# o block_a_wdata like block_a but uses local data if present.
# o block_aaaa_wdata like block_aaaa but uses local data if present.
# o always_null returns 0.0.0.0 or ::0 for any name in the zone.
# o noview breaks out of that view towards global local-zones.
#
@@ -1287,6 +1291,9 @@ remote-control:
# zonemd-check: no
# zonemd-reject-absence: no
# zonefile: "example.org.zone"
# max-transfer-size: 0
# max-transfer-time: 0
# Views
# Create named views. Name must be unique.
@@ -1453,3 +1460,5 @@ remote-control:
# rpz-signal-nxdomain-ra: no
# for-downstream: no
# tags: "example"
# max-transfer-size: 0
# max-transfer-time: 0
+2
View File
@@ -354,6 +354,8 @@ If the name already has no items, nothing happens.
Often results in NXDOMAIN for the name (in a static zone), but if the name
has become an empty nonterminal (there is still data in domain names below
the removed name), NOERROR nodata answers are the result for that name.
With a specific RR instead of a domain name, that specific record is
removed from the local data, and not all the RR data.
.UNINDENT
.INDENT 0.0
.TP
+2
View File
@@ -347,6 +347,8 @@ There are several commands that the server understands.
Often results in NXDOMAIN for the name (in a static zone), but if the name
has become an empty nonterminal (there is still data in domain names below
the removed name), NOERROR nodata answers are the result for that name.
With a specific RR instead of a domain name, that specific record is
removed from the local data, and not all the RR data.
@@UAHL@unbound-control.commands@local_zones@@
+107 -1
View File
@@ -691,7 +691,7 @@ Default: 0 (use system value)
.TP
.B so\-sndbuf: \fI<number>\fP
If not 0, then set the SO_SNDBUF socket option to get more buffer space on
UDP port 53 outgoing queries.
UDP port 53 outgoing responses.
This for very busy servers handles spikes in answer traffic, otherwise:
.INDENT 7.0
.INDENT 3.5
@@ -2312,6 +2312,13 @@ The defensive action is to clear the rrset and message caches, hopefully
flushing away any poison.
A value of 10 million is suggested.
.sp
It is useful to add 0.0.0.0/8 and \(aq::\(aq to the
\fI\%do\-not\-query\-address\fP list.
Otherwise they may be answered, from localhost, and the different source
makes an unwanted reply that unnecessarily ticks up.
The \fI\%do\-not\-query\-localhost\fP
option includes them, the zero subnets, when it is enabled.
.sp
Default: 0 (disabled)
.UNINDENT
.INDENT 0.0
@@ -2362,6 +2369,8 @@ If yes, deny queries of type ANY with an empty response.
If disabled, Unbound responds with a short list of resource records if some
can be found in the cache and makes the upstream type ANY query if there
are none.
The option stops the DNSSEC validation from processing, possibly lengthy,
ANY responses, when the option is enabled.
.sp
Default: no
.UNINDENT
@@ -2910,6 +2919,9 @@ The types are
\fI\%inform_redirect\fP,
\fI\%always_transparent\fP,
\fI\%block_a\fP,
\fI\%block_aaaa\fP,
\fI\%block_a_wdata\fP,
\fI\%block_aaaa_wdata\fP,
\fI\%always_refuse\fP,
\fI\%always_nxdomain\fP,
\fI\%always_null\fP,
@@ -3100,6 +3112,32 @@ use IPv6 protocol and avoid any queries to IPv4.
.UNINDENT
.INDENT 7.0
.TP
.B block_aaaa
Like \fI\%transparent\fP or
\fI\%block_a\fP, but
ignores local data and resolves normally all query types excluding AAAA.
For AAAA queries it unconditionally returns NODATA.
Useful in cases when there is a need to explicitly force all apps to
use IPv4 protocol and avoid any queries to IPv6.
.UNINDENT
.INDENT 7.0
.TP
.B block_a_wdata
Like \fI\%block_a\fP, but
uses local data if present.
If there is local data that is returned, and it acts like transparent.
For A queries it returns NODATA.
.UNINDENT
.INDENT 7.0
.TP
.B block_aaaa_wdata
Like \fI\%block_aaaa\fP, but
uses local data if present.
If there is local data that is returned, and it acts like transparent.
For AAAA queries it returns NODATA.
.UNINDENT
.INDENT 7.0
.TP
.B always_refuse
Like \fI\%refuse\fP, but ignores
local data and refuses the query.
@@ -3567,6 +3605,18 @@ For example, 1000 may be a suitable value to stop the server from being
overloaded with random names, and keeps unbound from sending traffic to the
nameservers for those zones.
.sp
It is intended to count the number of queries towards the nameservers
for the zone, and keep those queries limited.
When there is a delegation that needs a lot of lookups, those are
charged in the counters for the destination, the target name, of
the NS records.
Since that is where the nameserver lookup queries are sent to.
That keeps the target, the victim domain, from having many queries.
With the \fI\%ratelimit\-factor\fP, some
genuine queries that are also made to the target zone, can filter
through, and then end up in cache, where the genuine answers have
a chance to collect, keeping up service to some extent.
.sp
\fBNOTE:\fP
.INDENT 7.0
.INDENT 3.5
@@ -4594,6 +4644,32 @@ If not given then no zonefile is used.
If the file does not exist or is empty, Unbound will attempt to fetch zone
data (eg. from the primary servers).
.UNINDENT
.INDENT 0.0
.TP
.B max\-transfer\-size: \fI<number>\fP
Number of bytes size of the maximum zone transfer size.
Larger transfers, over AXFR, IXFR and HTTP, are not allowed.
A plain number is in bytes, append \(aqk\(aq, \(aqm\(aq or \(aqg\(aq for kilobytes, megabytes
or gigabytes (1024*1024 bytes in a megabyte).
The value \fB0\fP disables the feature.
.sp
Only consider for untrusted/misbehaving primaries that could hog resources
and bring down the resolver.
.sp
Default: 0
.UNINDENT
.INDENT 0.0
.TP
.B max\-transfer\-time: \fI<msec>\fP
Maximum time in milliseconds that a zone transfer is allowed to take from
the start.
The value \fB0\fP disables the feature.
.sp
Only consider for untrusted/misbehaving primaries that could hog resources
and bring down the resolver.
.sp
Default: 0
.UNINDENT
.SH VIEW OPTIONS
.sp
These options are part of the \fBview:\fP section.
@@ -5806,6 +5882,10 @@ from a webserver that would work.
If you specify the hostname, you cannot use the domain from the zonefile,
because it may not have that when retrieving that data, instead use a plain
IP address to avoid a circular dependency on retrieving that IP address.
.sp
Every number of IXFR transfers, a full AXFR is performed.
This is to consolidate the rpz memory, that would otherwise grow.
The fixed value is after 5 IXFR transfers.
.UNINDENT
.INDENT 0.0
.TP
@@ -5928,6 +6008,32 @@ Enclose list of tags in quotes (\fB\(dq\(dq\fP) and put spaces between tags.
If no tags are specified the policies from this section will be applied for
all clients.
.UNINDENT
.INDENT 0.0
.TP
.B max\-transfer\-size: \fI<number>\fP
Number of bytes size of the maximum zone transfer size.
Larger transfers, over AXFR, IXFR and HTTP, are not allowed.
A plain number is in bytes, append \(aqk\(aq, \(aqm\(aq or \(aqg\(aq for kilobytes, megabytes
or gigabytes (1024*1024 bytes in a megabyte).
The value \fB0\fP disables the feature.
.sp
Only consider for untrusted/misbehaving primaries that could hog resources
and bring down the resolver.
.sp
Default: 0
.UNINDENT
.INDENT 0.0
.TP
.B max\-transfer\-time: \fI<msec>\fP
Maximum time in milliseconds that a zone transfer is allowed to take from
the start.
The value \fB0\fP disables the feature.
.sp
Only consider for untrusted/misbehaving primaries that could hog resources
and bring down the resolver.
.sp
Default: 0
.UNINDENT
.SH MEMORY CONTROL EXAMPLE
.sp
In the example config settings below memory usage is reduced.
+99 -1
View File
@@ -642,7 +642,7 @@ These options are part of the ``server:`` section.
@@UAHL@unbound.conf@so-sndbuf@@: *<number>*
If not 0, then set the SO_SNDBUF socket option to get more buffer space on
UDP port 53 outgoing queries.
UDP port 53 outgoing responses.
This for very busy servers handles spikes in answer traffic, otherwise:
.. code-block:: text
@@ -2055,6 +2055,13 @@ These options are part of the ``server:`` section.
flushing away any poison.
A value of 10 million is suggested.
It is useful to add 0.0.0.0/8 and '::' to the
:ref:`do-not-query-address<unbound.conf.do-not-query-address>` list.
Otherwise they may be answered, from localhost, and the different source
makes an unwanted reply that unnecessarily ticks up.
The :ref:`do-not-query-localhost<unbound.conf.do-not-query-localhost>`
option includes them, the zero subnets, when it is enabled.
Default: 0 (disabled)
@@ -2100,6 +2107,8 @@ These options are part of the ``server:`` section.
If disabled, Unbound responds with a short list of resource records if some
can be found in the cache and makes the upstream type ANY query if there
are none.
The option stops the DNSSEC validation from processing, possibly lengthy,
ANY responses, when the option is enabled.
Default: no
@@ -2583,6 +2592,9 @@ These options are part of the ``server:`` section.
:ref:`inform_redirect<unbound.conf.local-zone.type.inform_redirect>`,
:ref:`always_transparent<unbound.conf.local-zone.type.always_transparent>`,
:ref:`block_a<unbound.conf.local-zone.type.block_a>`,
:ref:`block_aaaa<unbound.conf.local-zone.type.block_aaaa>`,
:ref:`block_a_wdata<unbound.conf.local-zone.type.block_a_wdata>`,
:ref:`block_aaaa_wdata<unbound.conf.local-zone.type.block_aaaa_wdata>`,
:ref:`always_refuse<unbound.conf.local-zone.type.always_refuse>`,
:ref:`always_nxdomain<unbound.conf.local-zone.type.always_nxdomain>`,
:ref:`always_null<unbound.conf.local-zone.type.always_null>`,
@@ -2732,6 +2744,26 @@ These options are part of the ``server:`` section.
Useful in cases when there is a need to explicitly force all apps to
use IPv6 protocol and avoid any queries to IPv4.
@@UAHL@unbound.conf.local-zone.type@block_aaaa@@
Like :ref:`transparent<unbound.conf.local-zone.type.transparent>` or
:ref:`block_a<unbound.conf.local-zone.type.block_a>`, but
ignores local data and resolves normally all query types excluding AAAA.
For AAAA queries it unconditionally returns NODATA.
Useful in cases when there is a need to explicitly force all apps to
use IPv4 protocol and avoid any queries to IPv6.
@@UAHL@unbound.conf.local-zone.type@block_a_wdata@@
Like :ref:`block_a<unbound.conf.local-zone.type.block_a>`, but
uses local data if present.
If there is local data that is returned, and it acts like transparent.
For A queries it returns NODATA.
@@UAHL@unbound.conf.local-zone.type@block_aaaa_wdata@@
Like :ref:`block_aaaa<unbound.conf.local-zone.type.block_aaaa>`, but
uses local data if present.
If there is local data that is returned, and it acts like transparent.
For AAAA queries it returns NODATA.
@@UAHL@unbound.conf.local-zone.type@always_refuse@@
Like :ref:`refuse<unbound.conf.local-zone.type.refuse>`, but ignores
local data and refuses the query.
@@ -3078,6 +3110,18 @@ These options are part of the ``server:`` section.
overloaded with random names, and keeps unbound from sending traffic to the
nameservers for those zones.
It is intended to count the number of queries towards the nameservers
for the zone, and keep those queries limited.
When there is a delegation that needs a lot of lookups, those are
charged in the counters for the destination, the target name, of
the NS records.
Since that is where the nameserver lookup queries are sent to.
That keeps the target, the victim domain, from having many queries.
With the :ref:`ratelimit-factor<unbound.conf.ratelimit-factor>`, some
genuine queries that are also made to the target zone, can filter
through, and then end up in cache, where the genuine answers have
a chance to collect, keeping up service to some extent.
.. note:: Configured forwarders are excluded from ratelimiting.
Default: 0
@@ -4011,6 +4055,31 @@ fallback activates to fetch from the upstream instead of the SERVFAIL.
If the file does not exist or is empty, Unbound will attempt to fetch zone
data (eg. from the primary servers).
@@UAHL@unbound.conf.auth@max-transfer-size@@: *<number>*
Number of bytes size of the maximum zone transfer size.
Larger transfers, over AXFR, IXFR and HTTP, are not allowed.
A plain number is in bytes, append 'k', 'm' or 'g' for kilobytes, megabytes
or gigabytes (1024*1024 bytes in a megabyte).
The value ``0`` disables the feature.
Only consider for untrusted/misbehaving primaries that could hog resources
and bring down the resolver.
Default: 0
@@UAHL@unbound.conf.auth@max-transfer-time@@: *<msec>*
Maximum time in milliseconds that a zone transfer is allowed to take from
the start.
The value ``0`` disables the feature.
Only consider for untrusted/misbehaving primaries that could hog resources
and bring down the resolver.
Default: 0
.. _unbound.conf.view:
View Options
@@ -5091,6 +5160,10 @@ answer queries with that content.
because it may not have that when retrieving that data, instead use a plain
IP address to avoid a circular dependency on retrieving that IP address.
Every number of IXFR transfers, a full AXFR is performed.
This is to consolidate the rpz memory, that would otherwise grow.
The fixed value is after 5 IXFR transfers.
@@UAHL@unbound.conf.rpz@master@@: *<IP address or host name>*
Alternate syntax for :ref:`primary<unbound.conf.rpz.primary>`.
@@ -5191,6 +5264,31 @@ answer queries with that content.
If no tags are specified the policies from this section will be applied for
all clients.
@@UAHL@unbound.conf.rpz@max-transfer-size@@: *<number>*
Number of bytes size of the maximum zone transfer size.
Larger transfers, over AXFR, IXFR and HTTP, are not allowed.
A plain number is in bytes, append 'k', 'm' or 'g' for kilobytes, megabytes
or gigabytes (1024*1024 bytes in a megabyte).
The value ``0`` disables the feature.
Only consider for untrusted/misbehaving primaries that could hog resources
and bring down the resolver.
Default: 0
@@UAHL@unbound.conf.rpz@max-transfer-time@@: *<msec>*
Maximum time in milliseconds that a zone transfer is allowed to take from
the start.
The value ``0`` disables the feature.
Only consider for untrusted/misbehaving primaries that could hog resources
and bring down the resolver.
Default: 0
Memory Control Example
----------------------
+1
View File
@@ -459,6 +459,7 @@ addrtree_insert(struct addrtree *tree, const addrkey_t *addr,
/* Data is stored in other leafnode */
node = newnode;
newnode = node_create(tree, elem, scope, ttl);
if (!newnode) return;
if (!edge_create(newnode, addr, sourcemask, node,
index^1)) {
clean_node(tree, newnode);
+3
View File
@@ -1015,6 +1015,7 @@ subnetmod_operate(struct module_qstate *qstate, enum module_ev event,
subnet_ecs_opt_list_append(&sq->ecs_client_out,
&qstate->edns_opts_front_out, qstate,
qstate->region);
qstate->is_subnet_answer = 1;
}
sq->wait_subquery_done = 0;
qstate->ext_state[id] = module_finished;
@@ -1094,6 +1095,7 @@ subnetmod_operate(struct module_qstate *qstate, enum module_ev event,
qstate->env->cfg->prefetch)) {
sne->num_msg_cache++;
lock_rw_unlock(&sne->biglock);
qstate->is_subnet_answer = 1;
verbose(VERB_QUERY, "subnetcache: answered from cache");
qstate->ext_state[id] = module_finished;
@@ -1165,6 +1167,7 @@ subnetmod_operate(struct module_qstate *qstate, enum module_ev event,
subnet_ecs_opt_list_append(&sq->ecs_client_out,
&qstate->edns_opts_front_out, qstate,
qstate->region);
qstate->is_subnet_answer = 1;
if(verbosity >= VERB_ALGO) {
subnet_log_print("reply has edns subnet",
edns_opt_list_find(
+2
View File
@@ -100,6 +100,8 @@ ipsecmod_whitelist_apply_cfg(struct ipsecmod_env* ie,
struct config_file* cfg)
{
ie->whitelist = rbtree_create(name_tree_compare);
if (!ie->whitelist)
return 0;
if(!read_whitelist(ie->whitelist, cfg))
return 0;
name_tree_init_parents(ie->whitelist);
+91 -37
View File
@@ -51,18 +51,28 @@
#include "util/config_file.h"
#include "services/cache/dns.h"
#include "sldns/wire2str.h"
#ifdef HAVE_SYS_WAIT_H
#include <sys/wait.h>
#endif
/** Apply configuration to ipsecmod module 'global' state. */
static int
ipsecmod_apply_cfg(struct ipsecmod_env* ipsecmod_env, struct config_file* cfg)
{
if(cfg->ipsecmod_whitelist &&
!ipsecmod_whitelist_apply_cfg(ipsecmod_env, cfg))
return 0;
if(!cfg->ipsecmod_enabled)
return 1;
if(!cfg->ipsecmod_hook || (cfg->ipsecmod_hook && !cfg->ipsecmod_hook[0])) {
log_err("ipsecmod: missing ipsecmod-hook.");
return 0;
}
if(cfg->ipsecmod_whitelist &&
!ipsecmod_whitelist_apply_cfg(ipsecmod_env, cfg))
if(access(cfg->ipsecmod_hook, X_OK) != 0) {
log_err("ipsecmod: ipsecmod-hook '%s' is not an executable file: %s",
cfg->ipsecmod_hook, strerror(errno));
return 0;
}
return 1;
}
@@ -250,27 +260,16 @@ call_hook(struct module_qstate* qstate, struct ipsecmod_qstate* iq,
struct ipsecmod_env* ATTR_UNUSED(ie))
{
size_t slen, tempdata_len, tempstring_len, i;
char str[65535], *s, *tempstring;
char qname_s[LDNS_MAX_DOMAINLEN*5+16], ttl_s[32], a_s[32768], k_s[32768];
char *s, *tempstring;
int w = 0, w_temp, qtype;
struct ub_packed_rrset_key* rrset_key;
struct packed_rrset_data* rrset_data;
uint8_t *tempdata;
pid_t pid;
int st;
char* argv[6];
/* Check if a shell is available */
if(system(NULL) == 0) {
log_err("ipsecmod: no shell available for ipsecmod-hook");
return 0;
}
/* Zero the buffer. */
s = str;
slen = sizeof(str);
memset(s, 0, slen);
/* Copy the hook into the buffer. */
w += sldns_str_print(&s, &slen, "%s", qstate->env->cfg->ipsecmod_hook);
/* Put space into the buffer. */
w += sldns_str_print(&s, &slen, " ");
/* Copy the qname into the buffer. */
tempstring = sldns_wire2str_dname(qstate->qinfo.qname,
qstate->qinfo.qname_len);
@@ -283,17 +282,24 @@ call_hook(struct module_qstate* qstate, struct ipsecmod_qstate* iq,
free(tempstring);
return 0;
}
w += sldns_str_print(&s, &slen, "\"%s\"", tempstring);
if(strlen(tempstring)+1 > sizeof(qname_s)) {
log_err("ipsecmod: string too long");
free(tempstring);
return 0;
}
snprintf(qname_s, sizeof(qname_s), "%s", tempstring);
free(tempstring);
/* Put space into the buffer. */
w += sldns_str_print(&s, &slen, " ");
/* Copy the IPSECKEY TTL into the buffer. */
rrset_data = (struct packed_rrset_data*)iq->ipseckey_rrset->entry.data;
w += sldns_str_print(&s, &slen, "\"%ld\"", (long)rrset_data->ttl);
/* Put space into the buffer. */
w += sldns_str_print(&s, &slen, " ");
snprintf(ttl_s, sizeof(ttl_s), "%ld", (long)rrset_data->ttl);
rrset_key = reply_find_answer_rrset(&qstate->return_msg->qinfo,
qstate->return_msg->rep);
if(!rrset_key) {
log_err("ipsecmod: could not find answer rrset for A/AAAA");
return 0;
}
/* Double check that the records are indeed A/AAAA.
* This should never happen as this function is only executed for A/AAAA
* queries but make sure we don't pass anything other than A/AAAA to the
@@ -304,9 +310,15 @@ call_hook(struct module_qstate* qstate, struct ipsecmod_qstate* iq,
return 0;
}
rrset_data = (struct packed_rrset_data*)rrset_key->entry.data;
/* Copy the A/AAAA record(s) into the buffer. Start and end this section
* with a double quote. */
w += sldns_str_print(&s, &slen, "\"");
if(!rrset_data) {
log_err("ipsecmod: Answer has no data");
return 0;
}
/* Copy the A/AAAA record(s) into the buffer. */
w = 0;
s = a_s;
slen = sizeof(a_s);
memset(s, 0, slen);
for(i=0; i<rrset_data->count; i++) {
if(i > 0) {
/* Put space into the buffer. */
@@ -322,7 +334,7 @@ call_hook(struct module_qstate* qstate, struct ipsecmod_qstate* iq,
} else if((size_t)w_temp >= slen) {
s = NULL; /* We do not want str to point outside of buffer. */
slen = 0;
log_err("ipsecmod: shell command too long");
log_err("ipsecmod: command addr argument too long");
return 0;
} else {
s += w_temp;
@@ -330,12 +342,17 @@ call_hook(struct module_qstate* qstate, struct ipsecmod_qstate* iq,
w += w_temp;
}
}
w += sldns_str_print(&s, &slen, "\"");
/* Put space into the buffer. */
w += sldns_str_print(&s, &slen, " ");
if(w >= (int)sizeof(a_s)) {
log_err("ipsecmod: command addr argument too long");
return 0;
}
/* Copy the IPSECKEY record(s) into the buffer. Start and end this section
* with a double quote. */
w += sldns_str_print(&s, &slen, "\"");
w = 0;
s = k_s;
slen = sizeof(k_s);
memset(s, 0, slen);
rrset_data = (struct packed_rrset_data*)iq->ipseckey_rrset->entry.data;
for(i=0; i<rrset_data->count; i++) {
if(i > 0) {
@@ -362,15 +379,44 @@ call_hook(struct module_qstate* qstate, struct ipsecmod_qstate* iq,
w += w_temp;
}
}
w += sldns_str_print(&s, &slen, "\"");
if(w >= (int)sizeof(str)) {
log_err("ipsecmod: shell command too long");
if(w >= (int)sizeof(k_s)) {
log_err("ipsecmod: command ipseckey argument too long");
return 0;
}
verbose(VERB_ALGO, "ipsecmod: shell command: '%s'", str);
/* ipsecmod-hook should return 0 on success. */
if(system(str) != 0)
/* exec the ipsecmod-hook */
argv[0] = qstate->env->cfg->ipsecmod_hook;
argv[1] = qname_s;
argv[2] = ttl_s;
argv[3] = a_s;
argv[4] = k_s;
argv[5] = NULL;
verbose(VERB_ALGO, "ipsecmod: exec %s \"%s\" %s \"%s\" \"%s\"",
argv[0], argv[1], argv[2], argv[3], argv[4]);
if((pid = fork()) < 0) {
log_err("ipsecmod: for exec, can not fork: %s",
strerror(errno));
return 0;
}
if(pid == 0) {
if(execv(argv[0], argv) < 0)
fprintf(stderr, "ipsecmod: execv: %s\n",
strerror(errno));
_exit(127);
}
while(1) {
if(waitpid(pid, &st, 0) < 0) {
if(errno == EINTR)
continue;
log_err("ipsecmod: wait_pid: %s", strerror(errno));
}
break;
}
if(!(WIFEXITED(st) && WEXITSTATUS(st) == 0)) {
/* the command failed */
return 0;
}
return 1;
}
@@ -435,6 +481,12 @@ ipsecmod_handle_query(struct module_qstate* qstate,
* ipsecmod_max_ttl. */
rrset_key = reply_find_answer_rrset(&qstate->return_msg->qinfo,
qstate->return_msg->rep);
if(!rrset_key) {
log_err("ipsecmod: reply-find-answer failed");
errinf(qstate, "ipsecmod: reply-find-answer failed");
ipsecmod_error(qstate, id);
return;
}
rrset_data = (struct packed_rrset_data*)rrset_key->entry.data;
if(rrset_data->ttl > (time_t)qstate->env->cfg->ipsecmod_max_ttl) {
/* Update TTL for rrset to fixed value. */
@@ -576,6 +628,8 @@ ipsecmod_inform_super(struct module_qstate* qstate, int id,
verbose(VERB_ALGO, "super has no ipsecmod state");
return;
}
if(!siq->enabled)
return;
if(qstate->return_msg) {
struct ub_packed_rrset_key* rrset_key = reply_find_answer_rrset(
+17 -14
View File
@@ -143,7 +143,7 @@ static int add_to_ipset(filter_dev dev, const char *setname, const void *ipaddr,
struct nlmsghdr *nlh;
struct nfgenmsg *nfg;
struct nlattr *nested[2];
static char buffer[BUFF_LEN];
char buffer[BUFF_LEN];
if (strlen(setname) >= IPSET_MAXNAMELEN) {
errno = ENAMETOOLONG;
@@ -208,13 +208,6 @@ ipset_add_rrset_data(struct ipset_env *ie,
ret = add_to_ipset((filter_dev)ie->dev, setname, rr_data + 2, af);
if (ret < 0) {
log_err("ipset: could not add %s into %s", dname, setname);
#if HAVE_NET_PFVAR_H
/* don't close as we might not be able to open again due to dropped privs */
#else
mnl_socket_close((filter_dev)ie->dev);
ie->dev = NULL;
#endif
break;
}
}
@@ -226,15 +219,15 @@ ipset_check_zones_for_rrset(struct module_env *env, struct ipset_env *ie,
struct ub_packed_rrset_key *rrset, const char *qname, int qlen,
const char *setname, int af)
{
static char dname[BUFF_LEN];
char dname[LDNS_MAX_DOMAINLEN*4+16];
const char *ds, *qs;
int dlen, plen;
struct config_strlist *p;
struct packed_rrset_data *d;
dlen = sldns_wire2str_dname_buf(rrset->rk.dname, rrset->rk.dname_len, dname, BUFF_LEN);
if (dlen == 0) {
dlen = sldns_wire2str_dname_buf(rrset->rk.dname, rrset->rk.dname_len, dname, sizeof(dname));
if (dlen == 0 || dlen >= (int)sizeof(dname)) {
log_err("bad domain name");
return -1;
}
@@ -276,7 +269,7 @@ static int ipset_update(struct module_env *env, struct dns_msg *return_msg,
const char *setname;
struct ub_packed_rrset_key *rrset;
int af;
static char qname[BUFF_LEN];
char qname[LDNS_MAX_DOMAINLEN*4+16];
int qlen;
#ifdef HAVE_NET_PFVAR_H
@@ -292,8 +285,8 @@ static int ipset_update(struct module_env *env, struct dns_msg *return_msg,
#endif
qlen = sldns_wire2str_dname_buf(qinfo.qname, qinfo.qname_len,
qname, BUFF_LEN);
if(qlen == 0) {
qname, sizeof(qname));
if(qlen == 0 || qlen >= (int)sizeof(qname)) {
log_err("bad domain name");
return -1;
}
@@ -372,6 +365,16 @@ int ipset_init(struct module_env* env, int id) {
ipset_env->name_v4 = env->cfg->ipset_name_v4;
ipset_env->name_v6 = env->cfg->ipset_name_v6;
#ifndef HAVE_NET_PFVAR_H
if (ipset_env->name_v4 && strlen(ipset_env->name_v4) >= IPSET_MAXNAMELEN) {
log_err("ipset: name-v4 exceeds IPSET_MAXNAMELEN (%d)", IPSET_MAXNAMELEN);
return 0;
}
if (ipset_env->name_v6 && strlen(ipset_env->name_v6) >= IPSET_MAXNAMELEN) {
log_err("ipset: name-v6 exceeds IPSET_MAXNAMELEN (%d)", IPSET_MAXNAMELEN);
return 0;
}
#endif
ipset_env->v4_enabled = !ipset_env->name_v4 || (strlen(ipset_env->name_v4) == 0) ? 0 : 1;
ipset_env->v6_enabled = !ipset_env->name_v6 || (strlen(ipset_env->name_v6) == 0) ? 0 : 1;
+31 -24
View File
@@ -118,10 +118,10 @@ delegpt_add_ns(struct delegpt* dp, struct regional* region, uint8_t* name,
sizeof(struct delegpt_ns));
if(!ns)
return 0;
ns->next = dp->nslist;
ns->namelen = len;
dp->nslist = ns;
ns->name = regional_alloc_init(region, name, ns->namelen);
if(!ns->name)
return 0;
ns->cache_lookup_count = 0;
ns->resolved = 0;
ns->got4 = 0;
@@ -137,7 +137,9 @@ delegpt_add_ns(struct delegpt* dp, struct regional* region, uint8_t* name,
} else {
ns->tls_auth_name = NULL;
}
return ns->name != 0;
ns->next = dp->nslist;
dp->nslist = ns;
return 1;
}
struct delegpt_ns*
@@ -223,11 +225,7 @@ delegpt_add_addr(struct delegpt* dp, struct regional* region,
sizeof(struct delegpt_addr));
if(!a)
return 0;
a->next_target = dp->target_list;
dp->target_list = a;
a->next_result = 0;
a->next_usable = dp->usable_list;
dp->usable_list = a;
memcpy(&a->addr, addr, addrlen);
a->addrlen = addrlen;
a->attempts = 0;
@@ -241,6 +239,10 @@ delegpt_add_addr(struct delegpt* dp, struct regional* region,
} else {
a->tls_auth_name = NULL;
}
a->next_target = dp->target_list;
dp->target_list = a;
a->next_usable = dp->usable_list;
dp->usable_list = a;
return 1;
}
@@ -398,30 +400,33 @@ delegpt_count_missing_targets(struct delegpt* dp, int* alllame)
/** find NS rrset in given list */
static struct ub_packed_rrset_key*
find_NS(struct reply_info* rep, size_t from, size_t to)
find_NS(struct reply_info* rep, size_t from, size_t to, uint16_t qclass)
{
size_t i;
for(i=from; i<to; i++) {
if(ntohs(rep->rrsets[i]->rk.type) == LDNS_RR_TYPE_NS)
if(ntohs(rep->rrsets[i]->rk.type) == LDNS_RR_TYPE_NS &&
ntohs(rep->rrsets[i]->rk.rrset_class) == qclass)
return rep->rrsets[i];
}
return NULL;
}
struct delegpt*
delegpt_from_message(struct dns_msg* msg, struct regional* region)
delegpt_from_message(struct dns_msg* msg, struct regional* region, int port)
{
struct ub_packed_rrset_key* ns_rrset = NULL;
struct delegpt* dp;
size_t i;
/* look for NS records in the authority section... */
ns_rrset = find_NS(msg->rep, msg->rep->an_numrrsets,
msg->rep->an_numrrsets+msg->rep->ns_numrrsets);
msg->rep->an_numrrsets+msg->rep->ns_numrrsets,
msg->qinfo.qclass);
/* In some cases (even legitimate, perfectly legal cases), the
* NS set for the "referral" might be in the answer section. */
if(!ns_rrset)
ns_rrset = find_NS(msg->rep, 0, msg->rep->an_numrrsets);
ns_rrset = find_NS(msg->rep, 0, msg->rep->an_numrrsets,
msg->qinfo.qclass);
/* If there was no NS rrset in the authority section, then this
* wasn't a referral message. (It might not actually be a
@@ -436,7 +441,7 @@ delegpt_from_message(struct dns_msg* msg, struct regional* region)
dp->has_parent_side_NS = 1; /* created from message */
if(!delegpt_set_name(dp, region, ns_rrset->rk.dname))
return NULL;
if(!delegpt_rrset_add_ns(dp, region, ns_rrset, 0))
if(!delegpt_rrset_add_ns(dp, region, ns_rrset, 0, port))
return NULL;
/* add glue, A and AAAA in answer and additional section */
@@ -447,10 +452,12 @@ delegpt_from_message(struct dns_msg* msg, struct regional* region)
i < (msg->rep->an_numrrsets+msg->rep->ns_numrrsets))
continue;
if(ntohs(s->rk.type) == LDNS_RR_TYPE_A) {
if(ntohs(s->rk.type) == LDNS_RR_TYPE_A &&
ntohs(s->rk.rrset_class) == msg->qinfo.qclass) {
if(!delegpt_add_rrset_A(dp, region, s, 0, NULL))
return NULL;
} else if(ntohs(s->rk.type) == LDNS_RR_TYPE_AAAA) {
} else if(ntohs(s->rk.type) == LDNS_RR_TYPE_AAAA &&
ntohs(s->rk.rrset_class) == msg->qinfo.qclass) {
if(!delegpt_add_rrset_AAAA(dp, region, s, 0, NULL))
return NULL;
}
@@ -460,7 +467,7 @@ delegpt_from_message(struct dns_msg* msg, struct regional* region)
int
delegpt_rrset_add_ns(struct delegpt* dp, struct regional* region,
struct ub_packed_rrset_key* ns_rrset, uint8_t lame)
struct ub_packed_rrset_key* ns_rrset, uint8_t lame, int port)
{
struct packed_rrset_data* nsdata = (struct packed_rrset_data*)
ns_rrset->entry.data;
@@ -475,7 +482,7 @@ delegpt_rrset_add_ns(struct delegpt* dp, struct regional* region,
continue; /* bad format */
/* add rdata of NS (= wirefmt dname), skip rdatalen bytes */
if(!delegpt_add_ns(dp, region, nsdata->rr_data[i]+2, lame,
NULL, UNBOUND_DNS_PORT))
NULL, (port==-1?UNBOUND_DNS_PORT:port)))
return 0;
}
return 1;
@@ -534,7 +541,7 @@ delegpt_add_rrset(struct delegpt* dp, struct regional* region,
if(!rrset)
return 1;
if(ntohs(rrset->rk.type) == LDNS_RR_TYPE_NS)
return delegpt_rrset_add_ns(dp, region, rrset, lame);
return delegpt_rrset_add_ns(dp, region, rrset, lame, -1);
else if(ntohs(rrset->rk.type) == LDNS_RR_TYPE_A)
return delegpt_add_rrset_A(dp, region, rrset, lame, additions);
else if(ntohs(rrset->rk.type) == LDNS_RR_TYPE_AAAA)
@@ -659,8 +666,6 @@ int delegpt_add_ns_mlc(struct delegpt* dp, uint8_t* name, uint8_t lame,
free(ns);
return 0;
}
ns->next = dp->nslist;
dp->nslist = ns;
ns->cache_lookup_count = 0;
ns->resolved = 0;
ns->got4 = 0;
@@ -679,6 +684,8 @@ int delegpt_add_ns_mlc(struct delegpt* dp, uint8_t* name, uint8_t lame,
} else {
ns->tls_auth_name = NULL;
}
ns->next = dp->nslist;
dp->nslist = ns;
return 1;
}
@@ -704,11 +711,7 @@ int delegpt_add_addr_mlc(struct delegpt* dp, struct sockaddr_storage* addr,
a = (struct delegpt_addr*)malloc(sizeof(struct delegpt_addr));
if(!a)
return 0;
a->next_target = dp->target_list;
dp->target_list = a;
a->next_result = 0;
a->next_usable = dp->usable_list;
dp->usable_list = a;
memcpy(&a->addr, addr, addrlen);
a->addrlen = addrlen;
a->attempts = 0;
@@ -724,6 +727,10 @@ int delegpt_add_addr_mlc(struct delegpt* dp, struct sockaddr_storage* addr,
} else {
a->tls_auth_name = NULL;
}
a->next_target = dp->target_list;
dp->target_list = a;
a->next_usable = dp->usable_list;
dp->usable_list = a;
return 1;
}
+4 -2
View File
@@ -221,10 +221,11 @@ int delegpt_add_ns(struct delegpt* dp, struct regional* regional,
* @param regional: where to allocate the info.
* @param ns_rrset: NS rrset.
* @param lame: rrset is lame, disprefer it.
* @param port: port or -1 if not set.
* @return 0 on alloc error.
*/
int delegpt_rrset_add_ns(struct delegpt* dp, struct regional* regional,
struct ub_packed_rrset_key* ns_rrset, uint8_t lame);
struct ub_packed_rrset_key* ns_rrset, uint8_t lame, int port);
/**
* Add target address to the delegation point.
@@ -365,11 +366,12 @@ size_t delegpt_count_targets(struct delegpt* dp);
*
* @param msg: the dns message, referral.
* @param regional: where to allocate delegation point.
* @param port: if not -1 specifies a port number.
* @return new delegation point or NULL on alloc error, or if the
* message was not appropriate.
*/
struct delegpt* delegpt_from_message(struct dns_msg* msg,
struct regional* regional);
struct regional* regional, int port);
/**
* Mark negative return in delegation point for specific nameserver.
+12
View File
@@ -132,6 +132,18 @@ donotq_apply_cfg(struct iter_donotq* dq, struct config_file* cfg)
if(cfg->do_ip6) {
if(!donotq_str_cfg(dq, "::1"))
return 0;
if(!donotq_str_cfg(dq, "::ffff:127.0.0.0/104"))
return 0;
}
/* RFC 1122 3.2.1.3 / RFC 6890 / RFC 4291 2.5.2: not valid as
* destination; on Linux these route to the local host. */
if(!donotq_str_cfg(dq, "0.0.0.0/8"))
return 0;
if(cfg->do_ip6) {
if(!donotq_str_cfg(dq, "::"))
return 0;
if(!donotq_str_cfg(dq, "::ffff:0:0/96"))
return 0;
}
}
addr_tree_init_parents(&dq->tree);
+18 -7
View File
@@ -107,7 +107,7 @@ response_type_from_cache(struct dns_msg* msg,
enum response_type
response_type_from_server(int rdset,
struct dns_msg* msg, struct query_info* request, struct delegpt* dp,
int* empty_nodata_found)
int* empty_nodata_found, int msg_lame_empty, int msg_lame_referral)
{
uint8_t* origzone = (uint8_t*)"\000"; /* the default */
struct ub_packed_rrset_key* s;
@@ -122,6 +122,10 @@ response_type_from_server(int rdset,
/* If the message is NXDOMAIN, then it answers the question. */
if(FLAGS_GET_RCODE(msg->rep->flags) == LDNS_RCODE_NXDOMAIN) {
if(msg->rep->an_numrrsets == 0 &&
msg->rep->ns_numrrsets == 0 &&
msg_lame_empty)
return RESPONSE_TYPE_LAME;
/* make sure its not recursive when we don't want it to */
if( (msg->rep->flags&BIT_RA) &&
!(msg->rep->flags&BIT_AA) && !rdset)
@@ -143,6 +147,10 @@ response_type_from_server(int rdset,
if(FLAGS_GET_RCODE(msg->rep->flags) != LDNS_RCODE_NOERROR)
return RESPONSE_TYPE_THROWAWAY;
if(msg->rep->an_numrrsets == 0 && msg->rep->ns_numrrsets == 0 &&
msg_lame_empty)
return RESPONSE_TYPE_LAME;
/* Note: TC bit has already been handled */
if(dp) {
@@ -249,13 +257,16 @@ response_type_from_server(int rdset,
* which gives ns==zone delegation from cache
* without AA bit as well, with nodata nosoa*/
/* real answer must be +AA and SOA RFC(2308),
* so this is wrong, and we SERVFAIL it if
* this is the only possible reply, if it
* is misdeployed the THROWAWAY makes us pick
* the next server from the selection */
if(msg->rep->an_numrrsets==0 &&
* this is picked up as lame_referral by the
* sanitize step, so it can spot if there
* was data in the answer section before
* removal. If such data is then removed we
* do not want to turn that answer into lame.
* But if it was not there, it can be lame. */
if(msg_lame_referral &&
msg->rep->an_numrrsets==0 &&
!(msg->rep->flags&BIT_AA) && !rdset)
return RESPONSE_TYPE_THROWAWAY;
return RESPONSE_TYPE_LAME;
return RESPONSE_TYPE_ANSWER;
}
/* If we are getting a referral upwards (or to
+5 -1
View File
@@ -120,10 +120,14 @@ enum response_type response_type_from_cache(struct dns_msg* msg,
* @param dp: The delegation point that was being queried
* when the response was returned.
* @param empty_nodata_found: flag to keep track of empty nodata detection.
* @param msg_lame_empty: The scrubber indicates that this empty message
* is lame, before it became empty.
* @param msg_lame_referral: returned true if the reply has a referral before
* scrub.
* @return the response type (CNAME or ANSWER).
*/
enum response_type response_type_from_server(int rdset,
struct dns_msg* msg, struct query_info* request, struct delegpt* dp,
int* empty_nodata_found);
int* empty_nodata_found, int msg_lame_empty, int msg_lame_referral);
#endif /* ITERATOR_ITER_RESPTYPE_H */
+80 -4
View File
@@ -316,6 +316,20 @@ synth_cname_rrset(uint8_t** sname, size_t* snamelen, uint8_t* alias,
return cn;
}
/** Check if the packet has type NS in answer or authority section */
static int
pkt_contains_ns(struct msg_parse* msg)
{
struct rrset_parse* rrset;
for(rrset = msg->rrset_first; rrset; rrset = rrset->rrset_all_next) {
if(rrset->type == LDNS_RR_TYPE_NS &&
(rrset->section == LDNS_SECTION_ANSWER ||
rrset->section == LDNS_SECTION_AUTHORITY))
return 1;
}
return 0;
}
/** check if DNAME applies to a name */
static int
pkt_strict_sub(sldns_buffer* pkt, uint8_t* sname, uint8_t* dr)
@@ -394,6 +408,8 @@ shorten_rrset(sldns_buffer* pkt, struct rrset_parse* rrset, int count)
struct rr_parse* rr = rrset->rr_first, *prev = NULL;
if(!rr)
return;
if(count < 1)
return; /* cannot leave a still-linked rrset_parse with rr_count == 0 */
for(i=0; i<count; i++) {
prev = rr;
rr = rr->next;
@@ -478,6 +494,7 @@ scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg,
size_t snamelen = qinfo->qname_len;
struct rrset_parse* rrset, *prev, *nsset=NULL;
int cname_length = 0; /* number of CNAMEs, or DNAMEs */
int has_answer = 0; /* if answer section contains nonCNAME,nonDNAME */
if(FLAGS_GET_RCODE(msg->flags) != LDNS_RCODE_NOERROR &&
FLAGS_GET_RCODE(msg->flags) != LDNS_RCODE_NXDOMAIN &&
@@ -519,6 +536,11 @@ scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg,
(unsigned)rrset->rr_count);
return 0;
}
if(has_answer) {
remove_rrset("normalize: removing DNAME redirection after answer:",
pkt, msg, prev, &rrset);
continue;
}
if(!synth_cname(sname, snamelen, rrset, alias,
&aliaslen, pkt)) {
verbose(VERB_ALGO, "synthesized CNAME "
@@ -569,6 +591,11 @@ scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg,
if(rrset->type == LDNS_RR_TYPE_CNAME) {
struct rrset_parse* nx = rrset->rrset_all_next;
uint8_t* oldsname = sname;
if(has_answer) {
remove_rrset("normalize: removing redirection after answer:",
pkt, msg, prev, &rrset);
continue;
}
cname_length++;
/* see if the next one is a DNAME, if so, swap them */
if(nx && nx->section == LDNS_SECTION_ANSWER &&
@@ -647,6 +674,7 @@ scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg,
* will be removed by sanitize, so no additional for them */
if(dname_pkt_compare(pkt, qinfo->qname, rrset->dname) == 0)
mark_additional_rrset(pkt, msg, rrset);
has_answer = 1;
prev = rrset;
rrset = rrset->rrset_all_next;
@@ -732,6 +760,11 @@ scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg,
"RRset:", pkt, msg, prev, &rrset);
continue;
}
if(ntohs(rrset->rrset_class) != qinfo->qclass) {
remove_rrset("normalize: removing other class "
"RRset:", pkt, msg, prev, &rrset);
continue;
}
if(nsset == NULL) {
nsset = rrset;
} else {
@@ -777,7 +810,13 @@ scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg,
rrset->rrset_all_next = NULL;
return 1;
}
mark_additional_rrset(pkt, msg, rrset);
/* Only mark glue as allowed for type NS in the authority
* section. Other RR types do not get glue for them, it
* is allowed from the answer section, but not authority
* so that a message can not have address records cached
* as a side effect to the query. */
if(rrset->type==LDNS_RR_TYPE_NS)
mark_additional_rrset(pkt, msg, rrset);
prev = rrset;
rrset = rrset->rrset_all_next;
}
@@ -962,12 +1001,20 @@ scrub_sanitize_rr_length(sldns_buffer* pkt, struct msg_parse* msg,
* @param env: module environment with config and cache.
* @param ie: iterator environment with private address data.
* @param qstate: for setting errinf for EDE error messages.
* @param pkt_before_NS: if the packet had type NS before scrub. If that
* is removed now, that indicates this may have been lame.
* @param msg_lame_empty: returned true if the empty packet is lame.
* @param msg_lame_referral: returned true if the reply has a referral before
* scrub.
* @param rdset: if RD bit was sent in query sent by unbound.
* @return 0 on error.
*/
static int
scrub_sanitize(sldns_buffer* pkt, struct msg_parse* msg,
struct query_info* qinfo, uint8_t* zonename, struct module_env* env,
struct iter_env* ie, struct module_qstate* qstate)
struct iter_env* ie, struct module_qstate* qstate,
int pkt_before_NS, int* msg_lame_empty, int* msg_lame_referral,
int rdset)
{
int del_addi = 0; /* if additional-holding rrsets are deleted, we
do not trust the normalized additional-A-AAAA any more */
@@ -1124,6 +1171,21 @@ scrub_sanitize(sldns_buffer* pkt, struct msg_parse* msg,
prev = rrset;
rrset = rrset->rrset_all_next;
}
/* If the packet is empty now, but it was not before. And there
* was type NS in authority, then that indicates the answer is lame. */
if(msg->rrset_first == NULL && pkt_before_NS) {
*msg_lame_empty = 1;
verbose(VERB_ALGO, "sanitize: empty message had referral to NS before, marked as lame");
} else if(pkt_before_NS && msg->an_rrsets==0 &&
!(msg->flags&BIT_AA) && !rdset) {
/* If the packet is now a referral, not really a nodata,
* then if it was also with an empty answer section before,
* it is also lame. */
*msg_lame_referral = 1;
verbose(VERB_ALGO, "sanitize: message has referral not answer, marked as lame");
}
return 1;
}
@@ -1131,11 +1193,15 @@ int
scrub_message(sldns_buffer* pkt, struct msg_parse* msg,
struct query_info* qinfo, uint8_t* zonename, struct regional* region,
struct module_env* env, struct module_qstate* qstate,
struct iter_env* ie)
struct iter_env* ie, int* msg_lame_empty, int* msg_lame_referral,
int rdset)
{
int pkt_before_NS;
/* basic sanity checks */
log_nametypeclass(VERB_ALGO, "scrub for", zonename, LDNS_RR_TYPE_NS,
qinfo->qclass);
*msg_lame_empty = 0;
*msg_lame_referral = 0;
if(msg->qdcount > 1)
return 0;
if( !(msg->flags&BIT_QR) )
@@ -1160,11 +1226,21 @@ scrub_message(sldns_buffer* pkt, struct msg_parse* msg,
return 0;
}
/* If the packet contains type NS in authority before scrub,
* like a self referral. With the answer section empty, it
* was not AA, the query was not sent with RD, with NS in auth,
* and no SOA in auth. For a negative answer, type SOA is present.
* This detects certain lameness if after has removed that. */
pkt_before_NS = msg->an_rrsets == 0 &&
!(msg->flags&BIT_AA) && !rdset &&
pkt_contains_ns(msg) && !soa_in_auth(msg);
/* normalize the response, this cleans up the additional. */
if(!scrub_normalize(pkt, msg, qinfo, region, env, zonename))
return 0;
/* delete all out-of-zone information */
if(!scrub_sanitize(pkt, msg, qinfo, zonename, env, ie, qstate))
if(!scrub_sanitize(pkt, msg, qinfo, zonename, env, ie, qstate,
pkt_before_NS, msg_lame_empty, msg_lame_referral, rdset))
return 0;
return 1;
}
+6 -1
View File
@@ -62,11 +62,16 @@ struct module_qstate;
* @param env: module environment with config settings and cache.
* @param qstate: for setting errinf for EDE error messages.
* @param ie: iterator module environment data.
* @param msg_lame_empty: returned true if the empty packet is lame.
* @param msg_lame_referral: returned true if the reply has a referral before
* scrub.
* @param rdset: if RD bit was sent in query sent by unbound.
* @return: false if the message is total waste. true if scrubbed with success.
*/
int scrub_message(struct sldns_buffer* pkt, struct msg_parse* msg,
struct query_info* qinfo, uint8_t* zonename, struct regional* regional,
struct module_env* env, struct module_qstate* qstate,
struct iter_env* ie);
struct iter_env* ie, int* msg_lame_empty, int* msg_lame_referral,
int rdset);
#endif /* ITERATOR_ITER_SCRUB_H */
+10 -1
View File
@@ -1313,7 +1313,8 @@ iter_lookup_parent_NS_from_cache(struct module_env* env, struct delegpt* dp,
log_rrset_key(VERB_ALGO, "found parent-side NS in cache", akey);
dp->has_parent_side_NS = 1;
/* and mark the new names as lame */
if(!delegpt_rrset_add_ns(dp, region, akey, 1)) {
if(!delegpt_rrset_add_ns(dp, region, akey, 1,
deleg_port_number(env))) {
lock_rw_unlock(&akey->entry.lock);
return 0;
}
@@ -1703,3 +1704,11 @@ iter_make_minimal(struct reply_info* rep)
rep->ar_numrrsets = 0;
rep->rrset_count -= rem;
}
int
deleg_port_number(struct module_env* env)
{
if(env->cfg->ssl_upstream)
return env->cfg->ssl_port;
return -1;
}
+3
View File
@@ -483,4 +483,7 @@ void limit_nsec_ttl(struct dns_msg* msg);
*/
void iter_make_minimal(struct reply_info* rep);
/** See if we need a different port number */
int deleg_port_number(struct module_env* env);
#endif /* ITERATOR_ITER_UTILS_H */
+113 -38
View File
@@ -81,7 +81,8 @@ int BLACKLIST_PENALTY = (120000*4);
/** Timeout when only a single probe query per IP is allowed. */
int PROBE_MAXRTO = PROBE_MAXRTO_DEFAULT; /* in msec */
static void target_count_increase_nx(struct iter_qstate* iq, int num);
static void target_count_increase_nx(struct module_qstate* qstate,
struct iter_qstate* iq, int num);
int
iter_init(struct module_env* env, int id)
@@ -250,7 +251,7 @@ error_supers(struct module_qstate* qstate, int id, struct module_qstate* super)
if((dpns->got4 == 2 || (!ie->supports_ipv4 && !ie->nat64.use_nat64)) &&
(dpns->got6 == 2 || !ie->supports_ipv6)) {
dpns->resolved = 1; /* mark as failed */
target_count_increase_nx(super_iq, 1);
target_count_increase_nx(super, super_iq, 1);
}
}
if(qstate->qinfo.qtype == LDNS_RR_TYPE_NS) {
@@ -734,7 +735,7 @@ is_caps_whitelisted(struct iter_env* ie, struct iter_qstate* iq)
* created for the parent query.
*/
static void
target_count_create(struct iter_qstate* iq)
target_count_create(struct module_qstate* qstate, struct iter_qstate* iq)
{
if(!iq->target_count) {
iq->target_count = (int*)calloc(TARGET_COUNT_MAX, sizeof(int));
@@ -742,33 +743,57 @@ target_count_create(struct iter_qstate* iq)
if(iq->target_count) {
iq->target_count[TARGET_COUNT_REF] = 1;
iq->nxns_dp = (uint8_t**)calloc(1, sizeof(uint8_t*));
/* continue global quota from where it was. */
if(qstate->global_quota_reached >
iq->target_count[TARGET_COUNT_GLOBAL_QUOTA])
iq->target_count[TARGET_COUNT_GLOBAL_QUOTA] =
qstate->global_quota_reached;
}
}
}
static void
target_count_increase(struct iter_qstate* iq, int num)
target_count_store(struct module_qstate* qstate, struct iter_qstate* iq)
{
target_count_create(iq);
if(iq->target_count) {
/* By storing the global quota counter, it stays
* there to be picked up if the module is restarted,
* eg. due to a validator retry, and then the
* target_count_create routine picks it up. */
if(iq->target_count[TARGET_COUNT_GLOBAL_QUOTA] >
qstate->global_quota_reached)
qstate->global_quota_reached =
iq->target_count[TARGET_COUNT_GLOBAL_QUOTA];
}
}
static void
target_count_increase(struct module_qstate* qstate,
struct iter_qstate* iq, int num)
{
target_count_create(qstate, iq);
if(iq->target_count)
iq->target_count[TARGET_COUNT_QUERIES] += num;
iq->dp_target_count++;
}
static void
target_count_increase_nx(struct iter_qstate* iq, int num)
target_count_increase_nx(struct module_qstate* qstate,
struct iter_qstate* iq, int num)
{
target_count_create(iq);
target_count_create(qstate, iq);
if(iq->target_count)
iq->target_count[TARGET_COUNT_NX] += num;
}
static void
target_count_increase_global_quota(struct iter_qstate* iq, int num)
target_count_increase_global_quota(struct module_qstate* qstate,
struct iter_qstate* iq, int num)
{
target_count_create(iq);
target_count_create(qstate, iq);
if(iq->target_count)
iq->target_count[TARGET_COUNT_GLOBAL_QUOTA] += num;
target_count_store(qstate, iq);
}
/**
@@ -861,7 +886,7 @@ generate_sub_request(uint8_t* qname, size_t qnamelen, uint16_t qtype,
subiq = (struct iter_qstate*)subq->minfo[id];
memset(subiq, 0, sizeof(*subiq));
subiq->num_target_queries = 0;
target_count_create(iq);
target_count_create(qstate, iq);
subiq->target_count = iq->target_count;
if(iq->target_count) {
iq->target_count[TARGET_COUNT_REF] ++; /* extra reference */
@@ -1486,6 +1511,7 @@ processInitRequest(struct module_qstate* qstate, struct iter_qstate* iq,
verbose(VERB_ALGO, "no-cache set, going to the network");
qstate->no_cache_lookup = 1;
qstate->no_cache_store = 1;
qstate->fwd_stub_no_cache = 1;
msg = NULL;
} else if(qstate->blacklist) {
/* if cache, or anything else, was blacklisted then
@@ -1505,7 +1531,7 @@ processInitRequest(struct module_qstate* qstate, struct iter_qstate* iq,
msg = val_neg_getmsg(qstate->env->neg_cache, &iq->qchase,
qstate->region, qstate->env->rrset_cache,
qstate->env->scratch_buffer,
*qstate->env->now, 1/*add SOA*/, NULL,
*qstate->env->now, 1/*add SOA*/, dpname,
qstate->env->cfg);
}
/* item taken from cache does not match our query name, thus
@@ -2234,7 +2260,7 @@ processLastResort(struct module_qstate* qstate, struct iter_qstate* iq,
return error_response_cache(qstate, id, LDNS_RCODE_SERVFAIL);
}
iq->num_target_queries += qs;
target_count_increase(iq, qs);
target_count_increase(qstate, iq, qs);
if(qs != 0) {
qstate->ext_state[id] = module_wait_subquery;
return 0; /* and wait for them */
@@ -2290,7 +2316,7 @@ processLastResort(struct module_qstate* qstate, struct iter_qstate* iq,
* lookups at a time. */
verbose(VERB_ALGO, "try parent-side glue lookup");
iq->num_target_queries += query_count;
target_count_increase(iq, query_count);
target_count_increase(qstate, iq, query_count);
qstate->ext_state[id] = module_wait_subquery;
return 0;
}
@@ -2310,7 +2336,7 @@ processLastResort(struct module_qstate* qstate, struct iter_qstate* iq,
if(query_count != 0) { /* suspend to await results */
verbose(VERB_ALGO, "try parent-side glue lookup");
iq->num_target_queries += query_count;
target_count_increase(iq, query_count);
target_count_increase(qstate, iq, query_count);
qstate->ext_state[id] = module_wait_subquery;
return 0;
}
@@ -2366,6 +2392,12 @@ processDSNSFind(struct module_qstate* qstate, struct iter_qstate* iq, int id)
/* go up one (more) step, until we hit the dp, if so, end */
dname_remove_label(&iq->dsns_point, &iq->dsns_point_len);
if(++iq->dsns_count > MAX_DSNS_FIND_COUNT) {
verbose(VERB_QUERY, "DS NS search exceeded %d labels",
MAX_DSNS_FIND_COUNT);
errinf(qstate, "DS NS search exceeded label limit");
return error_response_cache(qstate, id, LDNS_RCODE_SERVFAIL);
}
if(query_dname_compare(iq->dsns_point, iq->dp->name) == 0) {
/* there was no inbetween nameserver, use the old delegation
* point again. And this time, because dsns_point is nonNULL
@@ -2788,7 +2820,7 @@ processQueryTargets(struct module_qstate* qstate, struct iter_qstate* iq,
return error_response_cache(qstate, id, LDNS_RCODE_SERVFAIL);
}
iq->num_target_queries += extra;
target_count_increase(iq, extra);
target_count_increase(qstate, iq, extra);
if(iq->num_target_queries > 0) {
/* wait to get all targets, we want to try em */
verbose(VERB_ALGO, "wait for all targets for fallback");
@@ -2839,7 +2871,7 @@ processQueryTargets(struct module_qstate* qstate, struct iter_qstate* iq,
/* errors ignored, these targets are not strictly necessary for
* this result, we do not have to reply with SERVFAIL */
iq->num_target_queries += extra;
target_count_increase(iq, extra);
target_count_increase(qstate, iq, extra);
}
/* Add the current set of unused targets to our queue. */
@@ -2962,7 +2994,7 @@ processQueryTargets(struct module_qstate* qstate, struct iter_qstate* iq,
LDNS_RCODE_SERVFAIL);
}
iq->num_target_queries += qs;
target_count_increase(iq, qs);
target_count_increase(qstate, iq, qs);
}
/* Since a target query might have been made, we
* need to check again. */
@@ -3022,7 +3054,7 @@ processQueryTargets(struct module_qstate* qstate, struct iter_qstate* iq,
* this result, we do not have to reply with SERVFAIL */
if(extra > 0) {
iq->num_target_queries += extra;
target_count_increase(iq, extra);
target_count_increase(qstate, iq, extra);
check_waiting_queries(iq, qstate, id);
/* undo qname minimise step because we'll get back here
* to do it again */
@@ -3035,7 +3067,7 @@ processQueryTargets(struct module_qstate* qstate, struct iter_qstate* iq,
}
}
target_count_increase_global_quota(iq, 1);
target_count_increase_global_quota(qstate, iq, 1);
if(iq->target_count && iq->target_count[TARGET_COUNT_GLOBAL_QUOTA]
> MAX_GLOBAL_QUOTA) {
char s[LDNS_MAX_DOMAINLEN];
@@ -3048,7 +3080,9 @@ processQueryTargets(struct module_qstate* qstate, struct iter_qstate* iq,
/* Do not check ratelimit for forwarding queries or if we already got a
* pass. */
sq_check_ratelimit = (!(iq->chase_flags & BIT_RD) && !iq->ratelimit_ok);
sq_check_ratelimit = ((!(iq->chase_flags & BIT_RD) &&
!iq->ratelimit_ok));
iq->ratelimit_incremented = 0;
/* We have a valid target. */
if(verbosity >= VERB_QUERY) {
log_query_info(VERB_QUERY, "sending query:", &iq->qinfo_out);
@@ -3074,7 +3108,8 @@ processQueryTargets(struct module_qstate* qstate, struct iter_qstate* iq,
iq->dp->name, iq->dp->namelen,
(iq->dp->tcp_upstream || qstate->env->cfg->tcp_upstream),
(iq->dp->ssl_upstream || qstate->env->cfg->ssl_upstream),
target->tls_auth_name, qstate, &sq_was_ratelimited);
target->tls_auth_name, qstate, &sq_was_ratelimited,
&iq->ratelimit_incremented);
if(!outq) {
if(sq_was_ratelimited) {
lock_basic_lock(&ie->queries_ratelimit_lock);
@@ -3112,7 +3147,6 @@ find_NS(struct reply_info* rep, size_t from, size_t to)
return NULL;
}
/**
* Process the query response. All queries end up at this state first. This
* process generally consists of analyzing the response and routing the
@@ -3154,7 +3188,8 @@ processQueryResponse(struct module_qstate* qstate, struct iter_qstate* iq,
orig_empty_nodata_found = iq->empty_nodata_found;
type = response_type_from_server(
(int)((iq->chase_flags&BIT_RD) || iq->chase_to_rd),
iq->response, &iq->qinfo_out, iq->dp, &iq->empty_nodata_found);
iq->response, &iq->qinfo_out, iq->dp, &iq->empty_nodata_found,
iq->msg_lame_empty, iq->msg_lame_referral);
iq->chase_to_rd = 0;
/* remove TC flag, if this is erroneously set by TCP upstream */
iq->response->rep->flags &= ~BIT_TC;
@@ -3432,7 +3467,14 @@ processQueryResponse(struct module_qstate* qstate, struct iter_qstate* iq,
iq->deleg_msg = iq->response;
/* Keep current delegation point for label comparison */
old_dp = iq->dp;
iq->dp = delegpt_from_message(iq->response, qstate->region);
/* A referral reply is "pleasant", refund the
* parent dp's rate charge before descending to the child. */
if(iq->ratelimit_incremented)
infra_ratelimit_dec(qstate->env->infra_cache,
old_dp->name, old_dp->namelen,
*qstate->env->now);
iq->dp = delegpt_from_message(iq->response, qstate->region,
deleg_port_number(qstate->env));
if (qstate->env->cfg->qname_minimisation)
iq->minimisation_state = INIT_MINIMISE_STATE;
if(!iq->dp) {
@@ -3709,7 +3751,8 @@ prime_supers(struct module_qstate* qstate, int id, struct module_qstate* forq)
log_assert(qstate->is_priming || foriq->wait_priming_stub);
log_assert(qstate->return_rcode == LDNS_RCODE_NOERROR);
/* Convert our response to a delegation point */
dp = delegpt_from_message(qstate->return_msg, forq->region);
dp = delegpt_from_message(qstate->return_msg, forq->region,
deleg_port_number(forq->env));
if(!dp) {
/* if there is no convertible delegation point, then
* the ANSWER type was (presumably) a negative answer. */
@@ -3760,7 +3803,8 @@ processPrimeResponse(struct module_qstate* qstate, int id)
iq->response->rep->flags &= ~(BIT_RD|BIT_RA); /* ignore rec-lame */
type = response_type_from_server(
(int)((iq->chase_flags&BIT_RD) || iq->chase_to_rd),
iq->response, &iq->qchase, iq->dp, NULL);
iq->response, &iq->qchase, iq->dp, NULL, iq->msg_lame_empty,
iq->msg_lame_referral);
if(type == RESPONSE_TYPE_ANSWER) {
qstate->return_rcode = LDNS_RCODE_NOERROR;
qstate->return_msg = iq->response;
@@ -3879,7 +3923,7 @@ processTargetResponse(struct module_qstate* qstate, int id,
/* no new addresses, increase the nxns counter, like
* this could be a list of wildcards with no new
* addresses */
target_count_increase_nx(foriq, 1);
target_count_increase_nx(qstate, foriq, 1);
}
verbose(VERB_ALGO, "added target response");
delegpt_log(VERB_ALGO, foriq->dp);
@@ -3891,7 +3935,7 @@ processTargetResponse(struct module_qstate* qstate, int id,
dpns->resolved = 1; /* fail the target */
/* do not count cached answers */
if(qstate->reply_origin && qstate->reply_origin->len != 0) {
target_count_increase_nx(foriq, 1);
target_count_increase_nx(qstate, foriq, 1);
}
}
}
@@ -3924,7 +3968,8 @@ processDSNSResponse(struct module_qstate* qstate, int id,
/* else, store as DP and continue at querytargets */
foriq->state = QUERYTARGETS_STATE;
foriq->dp = delegpt_from_message(qstate->return_msg, forq->region);
foriq->dp = delegpt_from_message(qstate->return_msg, forq->region,
deleg_port_number(forq->env));
if(!foriq->dp) {
log_err("out of memory in dsns dp alloc");
errinf(qstate, "malloc failure, in DS search");
@@ -3973,7 +4018,7 @@ processClassResponse(struct module_qstate* qstate, int id,
/* if there are records, copy RCODE */
/* lower sec_state if this message is lower */
if(from->rep->rrset_count != 0) {
size_t n = from->rep->rrset_count+to->rep->rrset_count;
size_t i, n = from->rep->rrset_count+to->rep->rrset_count;
struct ub_packed_rrset_key** dest, **d;
/* copy appropriate rcode */
to->rep->flags = from->rep->flags;
@@ -3995,24 +4040,49 @@ processClassResponse(struct module_qstate* qstate, int id,
memcpy(dest, to->rep->rrsets, to->rep->an_numrrsets
* sizeof(dest[0]));
dest += to->rep->an_numrrsets;
memcpy(dest, from->rep->rrsets, from->rep->an_numrrsets
* sizeof(dest[0]));
for(i=0; i<from->rep->an_numrrsets; i++) {
dest[i] = packed_rrset_copy_region(
from->rep->rrsets[i], forq->region, 0);
if(!dest[i]) {
log_err("malloc failed in collect ANY");
foriq->state = FINISHED_STATE;
return;
}
}
dest += from->rep->an_numrrsets;
/* copy NS */
memcpy(dest, to->rep->rrsets+to->rep->an_numrrsets,
to->rep->ns_numrrsets * sizeof(dest[0]));
dest += to->rep->ns_numrrsets;
memcpy(dest, from->rep->rrsets+from->rep->an_numrrsets,
from->rep->ns_numrrsets * sizeof(dest[0]));
for(i=0; i<from->rep->ns_numrrsets; i++) {
dest[i] = packed_rrset_copy_region(
from->rep->rrsets[
from->rep->an_numrrsets+i],
forq->region, 0);
if(!dest[i]) {
log_err("malloc failed in collect ANY");
foriq->state = FINISHED_STATE;
return;
}
}
dest += from->rep->ns_numrrsets;
/* copy AR */
memcpy(dest, to->rep->rrsets+to->rep->an_numrrsets+
to->rep->ns_numrrsets,
to->rep->ar_numrrsets * sizeof(dest[0]));
dest += to->rep->ar_numrrsets;
memcpy(dest, from->rep->rrsets+from->rep->an_numrrsets+
from->rep->ns_numrrsets,
from->rep->ar_numrrsets * sizeof(dest[0]));
for(i=0; i<from->rep->ar_numrrsets; i++) {
dest[i] = packed_rrset_copy_region(
from->rep->rrsets[
from->rep->an_numrrsets+
from->rep->ns_numrrsets+i],
forq->region, 0);
if(!dest[i]) {
log_err("malloc failed in collect ANY");
foriq->state = FINISHED_STATE;
return;
}
}
/* update counts */
to->rep->rrsets = d;
to->rep->an_numrrsets += from->rep->an_numrrsets;
@@ -4116,6 +4186,7 @@ processFinished(struct module_qstate* qstate, struct iter_qstate* iq,
iter_store_parentside_neg(qstate->env, &qstate->qinfo,
iq->deleg_msg?iq->deleg_msg->rep:
(iq->response?iq->response->rep:NULL));
target_count_store(qstate, iq);
if(!iq->response) {
verbose(VERB_ALGO, "No response is set, servfail");
errinf(qstate, "(no response found at query finish)");
@@ -4369,7 +4440,10 @@ process_response(struct module_qstate* qstate, struct iter_qstate* iq,
/* normalize and sanitize: easy to delete items from linked lists */
if(!scrub_message(pkt, prs, &iq->qinfo_out, iq->dp->name,
qstate->env->scratch, qstate->env, qstate, ie)) {
qstate->env->scratch, qstate->env, qstate, ie,
&iq->msg_lame_empty, &iq->msg_lame_referral,
(int)((iq->chase_flags&BIT_RD) || iq->chase_to_rd)
)) {
/* if 0x20 enabled, start fallback, but we have no message */
if(event == module_event_capsfail && !iq->caps_fallback) {
iq->caps_fallback = 1;
@@ -4531,6 +4605,7 @@ iter_clear(struct module_qstate* qstate, int id)
iq = (struct iter_qstate*)qstate->minfo[id];
if(iq) {
outbound_list_clear(&iq->outlist);
target_count_store(qstate, iq);
if(iq->target_count && --iq->target_count[TARGET_COUNT_REF] == 0) {
free(iq->target_count);
if(*iq->nxns_dp) free(*iq->nxns_dp);
+18
View File
@@ -104,6 +104,11 @@ extern int BLACKLIST_PENALTY;
#define RTT_BAND 400
/** Number of retries for empty nodata packets before it is accepted. */
#define EMPTY_NODATA_RETRY_COUNT 2
/** max label-strip iterations in DSNS_FIND_STATE (RFC 4035 4.2 parent-NS
* search) before giving up; bounds upstream NS sends per client DS.
* Means the max number of labels in grandchild to the grandparent zone that
* are co-hosted. */
#define MAX_DSNS_FIND_COUNT 20
/**
* Iterator global state for nat64.
@@ -375,6 +380,10 @@ struct iter_qstate {
/** if true, already tested for ratelimiting and passed the test */
int ratelimit_ok;
/** If the last query, that may be a referral, incremented the
* ratelimit counter. */
int ratelimit_incremented;
/**
* The query must store NS records from referrals as parentside RRs
* Enabled once it hits resolution problems, to throttle retries.
@@ -399,6 +408,8 @@ struct iter_qstate {
uint8_t* dsns_point;
/** length of the dname in dsns_point */
size_t dsns_point_len;
/** number of label-strip iterations performed in DSNS_FIND_STATE */
int dsns_count;
/**
* expected dnssec information for this iteration step.
@@ -434,6 +445,13 @@ struct iter_qstate {
* already so that it is accepted later. */
int empty_nodata_found;
/** Store if the answer was empty, but lame, before it became empty.*/
int msg_lame_empty;
/** Store if the answer was a referral, to self, before scrub. So the
* it is not some sort of answer. */
int msg_lame_referral;
/** list of pending queries to authoritative servers. */
struct outbound_list outlist;
+49
View File
@@ -0,0 +1,49 @@
/*
* libunbound/authload.h - prototypes for auth load methods.
*
* Copyright (c) 2026, NLnet Labs. All rights reserved.
*
* This software is open source.
*
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions
* are met:
*
* Redistributions of source code must retain the above copyright notice,
* this list of conditions and the following disclaimer.
*
* Redistributions in binary form must reproduce the above copyright notice,
* this list of conditions and the following disclaimer in the documentation
* and/or other materials provided with the distribution.
*
* Neither the name of the NLNET LABS nor the names of its contributors may
* be used to endorse or promote products derived from this software without
* specific prior written permission.
*
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
* "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
* LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
* A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
* HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
* SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED
* TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
* PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
* LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
* NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
* SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
*/
/**
* \file
*
* This file declares the methods that must be implemented to use the
* auth load service.
*/
#ifndef LIBUNBOUND_AUTHLOAD_H
#define LIBUNBOUND_AUTHLOAD_H
/** The worker routine that services the auth load connection. */
void worker_auth_load_service_cb(int fd, short bits, void* arg);
#endif /* LIBUNBOUND_AUTHLOAD_H */
+2
View File
@@ -167,6 +167,8 @@ struct ctx_query {
ub_event_callback_type cb_event;
/** for async query, the callback user arg */
void* cb_arg;
/** for async query the unique info */
void* unique_info;
/** answer message, result from resolver lookup. */
uint8_t* msg;
+17
View File
@@ -571,6 +571,8 @@ ub_ctx_async(struct ub_ctx* ctx, int dothread)
int
ub_poll(struct ub_ctx* ctx)
{
if(!ctx || ctx->event_base)
return UB_INITFAIL;
/* no need to hold lock while testing for readability. */
return tube_poll(ctx->rr_pipe);
}
@@ -578,6 +580,8 @@ ub_poll(struct ub_ctx* ctx)
int
ub_fd(struct ub_ctx* ctx)
{
if(!ctx || ctx->event_base)
return -1;
return tube_read_fd(ctx->rr_pipe);
}
@@ -672,6 +676,8 @@ ub_process(struct ub_ctx* ctx)
int r;
uint8_t* msg;
uint32_t len;
if(!ctx || ctx->event_base)
return UB_INITFAIL;
while(1) {
msg = NULL;
lock_basic_lock(&ctx->rrpipe_lock);
@@ -700,6 +706,8 @@ ub_wait(struct ub_ctx* ctx)
int r;
uint8_t* msg;
uint32_t len;
if(!ctx || ctx->event_base)
return UB_INITFAIL;
/* this is basically the same loop as _process(), but with changes.
* holds the rrpipe lock and waits with tube_wait */
while(1) {
@@ -837,6 +845,8 @@ ub_resolve_async(struct ub_ctx* ctx, const char* name, int rrtype,
struct ctx_query* q;
uint8_t* msg = NULL;
uint32_t len = 0;
if(!ctx || ctx->event_base)
return UB_INITFAIL;
if(async_id)
*async_id = 0;
@@ -1467,8 +1477,15 @@ ub_ctx_set_event(struct ub_ctx* ctx, struct event_base* base) {
lock_basic_lock(&ctx->cfglock);
/* destroy the current worker - safe to pass in NULL */
/* Unlock the cfglock during libworker_delete_event, since it
* calls context_release_alloc, that wants to lock cfglock again.
* Since the event base is used from one thread, the one that
* called this function, it is safe to do so. */
lock_basic_unlock(&ctx->cfglock);
libworker_delete_event(ctx->event_worker);
ctx->event_worker = NULL;
lock_basic_lock(&ctx->cfglock);
new_base = ub_libevent_event_base(base);
if (new_base)
ctx->event_base = new_base;
+22 -8
View File
@@ -105,6 +105,7 @@ libworker_delete_env(struct libworker* w)
SSL_CTX_free(w->sslctx);
#endif
outside_network_delete(w->back);
shared_ports_delete(w->shared_ports);
}
/** delete libworker struct */
@@ -219,17 +220,25 @@ libworker_setup(struct ub_ctx* ctx, int is_bg, struct ub_event_base* eb)
libworker_delete(w);
return NULL;
}
if(!(w->shared_ports = shared_ports_create(cfg->out_ifs,
cfg->num_out_ifs, cfg->do_ip4, cfg->do_ip6, ports, numports))) {
if(!w->is_bg || w->is_bg_thread) {
lock_basic_unlock(&ctx->cfglock);
}
libworker_delete(w);
return NULL;
}
w->back = outside_network_create(w->base, cfg->msg_buffer_size,
(size_t)cfg->outgoing_num_ports, cfg->out_ifs,
cfg->num_out_ifs, cfg->do_ip4, cfg->do_ip6,
cfg->do_tcp?cfg->outgoing_num_tcp:0, cfg->ip_dscp,
w->env->infra_cache, w->env->rnd, cfg->use_caps_bits_for_id,
ports, numports, cfg->unwanted_threshold,
cfg->unwanted_threshold,
cfg->outgoing_tcp_mss, &libworker_alloc_cleanup, w,
cfg->do_udp || cfg->udp_upstream_without_downstream, w->sslctx,
cfg->delay_close, cfg->tls_use_sni, NULL, cfg->udp_connect,
cfg->max_reuse_tcp_queries, cfg->tcp_reuse_timeout,
cfg->tcp_auth_query_timeout);
cfg->tcp_auth_query_timeout, w->shared_ports);
w->env->outnet = w->back;
if(!w->is_bg || w->is_bg_thread) {
lock_basic_unlock(&ctx->cfglock);
@@ -642,7 +651,8 @@ int libworker_fg(struct ub_ctx* ctx, struct ctx_query* q)
}
/* process new query */
if(!mesh_new_callback(w->env->mesh, &qinfo, qflags, &edns,
w->back->udp_buff, qid, libworker_fg_done_cb, q, 0)) {
w->back->udp_buff, qid, libworker_fg_done_cb, q, 0,
&q->unique_info)) {
free(qinfo.qname);
return UB_NOMEM;
}
@@ -723,7 +733,8 @@ int libworker_attach_mesh(struct ub_ctx* ctx, struct ctx_query* q,
if(async_id)
*async_id = q->querynum;
if(!mesh_new_callback(w->env->mesh, &qinfo, qflags, &edns,
w->back->udp_buff, qid, libworker_event_done_cb, q, 0)) {
w->back->udp_buff, qid, libworker_event_done_cb, q, 0,
&q->unique_info)) {
free(qinfo.qname);
return UB_NOMEM;
}
@@ -861,7 +872,8 @@ handle_newq(struct libworker* w, uint8_t* buf, uint32_t len)
q->w = w;
/* process new query */
if(!mesh_new_callback(w->env->mesh, &qinfo, qflags, &edns,
w->back->udp_buff, qid, libworker_bg_done_cb, q, 0)) {
w->back->udp_buff, qid, libworker_bg_done_cb, q, 0,
&q->unique_info)) {
add_bg_result(w, q, NULL, UB_NOMEM, NULL, 0);
}
free(qinfo.qname);
@@ -879,7 +891,8 @@ struct outbound_entry* libworker_send_query(struct query_info* qinfo,
int check_ratelimit,
struct sockaddr_storage* addr, socklen_t addrlen, uint8_t* zone,
size_t zonelen, int tcp_upstream, int ssl_upstream, char* tls_auth_name,
struct module_qstate* q, int* was_ratelimited)
struct module_qstate* q, int* was_ratelimited,
int* ratelimit_incremented)
{
struct libworker* w = (struct libworker*)q->env->worker;
struct outbound_entry* e = (struct outbound_entry*)regional_alloc(
@@ -891,7 +904,7 @@ struct outbound_entry* libworker_send_query(struct query_info* qinfo,
want_dnssec, nocaps, check_ratelimit, tcp_upstream, ssl_upstream,
tls_auth_name, addr, addrlen, zone, zonelen, q,
libworker_handle_service_reply, e, w->back->udp_buff, q->env,
was_ratelimited);
was_ratelimited, ratelimit_incremented);
if(!e->qsent) {
return NULL;
}
@@ -976,7 +989,8 @@ struct outbound_entry* worker_send_query(struct query_info* ATTR_UNUSED(qinfo),
struct sockaddr_storage* ATTR_UNUSED(addr), socklen_t ATTR_UNUSED(addrlen),
uint8_t* ATTR_UNUSED(zone), size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream),
int ATTR_UNUSED(ssl_upstream), char* ATTR_UNUSED(tls_auth_name),
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited))
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited),
int* ATTR_UNUSED(ratelimit_incremented))
{
log_assert(0);
return 0;
+3
View File
@@ -60,6 +60,7 @@ struct tube;
struct sldns_buffer;
struct ub_event_base;
struct query_info;
struct shared_ports;
/**
* The library-worker status structure
@@ -84,6 +85,8 @@ struct libworker {
struct comm_base* base;
/** the backside outside network interface to the auth servers */
struct outside_network* back;
/** shared ports structure */
struct shared_ports* shared_ports;
/** random() table for this worker. */
struct ub_randstate* rndstate;
/** sslcontext for SSL wrapped DNS over TCP queries */
+65
View File
@@ -0,0 +1,65 @@
/*
* libunbound/remote.h - prototypes for remote control methods.
*
* Copyright (c) 2026, NLnet Labs. All rights reserved.
*
* This software is open source.
*
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions
* are met:
*
* Redistributions of source code must retain the above copyright notice,
* this list of conditions and the following disclaimer.
*
* Redistributions in binary form must reproduce the above copyright notice,
* this list of conditions and the following disclaimer in the documentation
* and/or other materials provided with the distribution.
*
* Neither the name of the NLNET LABS nor the names of its contributors may
* be used to endorse or promote products derived from this software without
* specific prior written permission.
*
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
* "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
* LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
* A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
* HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
* SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED
* TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
* PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
* LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
* NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
* SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
*/
/**
* \file
*
* This file declares the methods that must be implemented to use the
* remote control service.
*/
#ifndef LIBUNBOUND_REMOTE_H
#define LIBUNBOUND_REMOTE_H
struct comm_reply;
struct comm_point;
/** fast reload thread commands to remote service thread event callback */
void fast_reload_service_cb(int fd, short bits, void* arg);
/** fast reload callback for the remote control client connection */
int fast_reload_client_callback(struct comm_point* c, void* arg, int err,
struct comm_reply* rep);
/** handle remote control accept callbacks */
int remote_accept_callback(struct comm_point*, void*, int, struct comm_reply*);
/** handle remote control data callbacks */
int remote_control_callback(struct comm_point*, void*, int, struct comm_reply*);
/** routine to printout option values over SSL */
void remote_get_opt_ssl(char* line, void* arg);
#endif /* LIBUNBOUND_REMOTE_H */
+8 -11
View File
@@ -70,6 +70,8 @@ struct query_info;
* @param q: which query state to reactivate upon return.
* @param was_ratelimited: it will signal back if the query failed to pass the
* ratelimit check.
* @param ratelimit_incremented: set to true if the ratelimit counter
* was increased.
* @return: false on failure (memory or socket related). no query was
* sent.
*/
@@ -78,7 +80,8 @@ struct outbound_entry* libworker_send_query(struct query_info* qinfo,
int check_ratelimit,
struct sockaddr_storage* addr, socklen_t addrlen, uint8_t* zone,
size_t zonelen, int tcp_upstream, int ssl_upstream, char* tls_auth_name,
struct module_qstate* q, int* was_ratelimited);
struct module_qstate* q, int* was_ratelimited,
int* ratelimit_incremented);
/** process incoming serviced query replies from the network */
int libworker_handle_service_reply(struct comm_point* c, void* arg, int error,
@@ -126,6 +129,8 @@ void worker_sighandler(int sig, void* arg);
* @param q: which query state to reactivate upon return.
* @param was_ratelimited: it will signal back if the query failed to pass the
* ratelimit check.
* @param ratelimit_incremented: set to true if the ratelimit counter
* was increased.
* @return: false on failure (memory or socket related). no query was
* sent.
*/
@@ -134,7 +139,8 @@ struct outbound_entry* worker_send_query(struct query_info* qinfo,
int check_ratelimit,
struct sockaddr_storage* addr, socklen_t addrlen, uint8_t* zone,
size_t zonelen, int tcp_upstream, int ssl_upstream, char* tls_auth_name,
struct module_qstate* q, int* was_ratelimited);
struct module_qstate* q, int* was_ratelimited,
int* ratelimit_incremented);
/**
* process control messages from the main thread. Frees the control
@@ -171,13 +177,4 @@ void worker_start_accept(void* arg);
/** stop accept callback handler */
void worker_stop_accept(void* arg);
/** handle remote control accept callbacks */
int remote_accept_callback(struct comm_point*, void*, int, struct comm_reply*);
/** handle remote control data callbacks */
int remote_control_callback(struct comm_point*, void*, int, struct comm_reply*);
/** routine to printout option values over SSL */
void remote_get_opt_ssl(char* line, void* arg);
#endif /* LIBUNBOUND_WORKER_H */
+8
View File
@@ -466,9 +466,13 @@ if [ "$DOWIN" = "yes" ]; then
|| error_cleanup "Could not configure"
set +x
else
# Add -l:libssp:a to statically link libssp if possible.
# Put it at the end of LIBS, to satisfy also linked in
# dependencies.
set -x
$configure --enable-debug --enable-static-exe --disable-flto --disable-gost $* $cross_flag \
|| error_cleanup "Could not configure"
sed -i Makefile -e 's/^\(LIBS=.*\)$/\1 -l:libssp.a/'
set +x
fi
info "Calling make"
@@ -485,6 +489,7 @@ if [ "$DOWIN" = "yes" ]; then
|| error_cleanup "Could not configure"
set +x
else
# Do not add -l:libssp:a statically because it is a shared build.
set -x
$configure --enable-debug --disable-flto --disable-gost $* $shared_cross_flag \
|| error_cleanup "Could not configure"
@@ -603,6 +608,8 @@ rm -rf .git .travis.yml .gitattributes .github .gitignore || error_cleanup "Fail
info "Adding libtool utils (libtoolize)."
libtoolize -c --install || libtoolize -c || error_cleanup "Libtoolize failed."
# Turn this off, if the git repo times out for lookups.
if test "updateconfigsub" = "false"; then
# https://www.gnu.org/software/gettext/manual/html_node/config_002eguess.html
info "Updating config.guess and config.sub"
wget -O config.guess 'https://git.savannah.gnu.org/gitweb/?p=config.git;a=blob_plain;f=config.guess;hb=HEAD'
@@ -616,6 +623,7 @@ if [ `uname -s | grep -i -c darwin` -ne 0 ]; then
xattr -d com.apple.quarantine config.sub
fi
fi
fi
info "Building configure script (autoreconf)."
autoreconf -f || error_cleanup "Autoconf failed."
+16 -15
View File
@@ -79,7 +79,7 @@
i+(int)((unsigned int)name[i]) < len) {
memmove(buf, name + i + 1, (unsigned int)name[i]);
buf[(unsigned int)name[i]] = 0;
PyList_SetItem(list, cnt, PyString_FromString(buf));
PyList_SetItem(list, cnt, PyUnicode_FromString(buf));
}
i += ((unsigned int)name[i]) + 1;
cnt++;
@@ -96,7 +96,7 @@
list = PyList_New(len);
for (i=0; i < len; i++) {
PyList_SET_ITEM(list, i, PyString_FromString(array[i]));
PyList_SET_ITEM(list, i, PyUnicode_FromString(array[i]));
}
return list;
}
@@ -207,7 +207,7 @@ struct query_info {
char buf[LDNS_MAX_DOMAINLEN];
buf[0] = '\0';
dname_str((uint8_t*)PyBytes_AsString(dname), buf);
return PyString_FromString(buf);
return PyUnicode_FromString(buf);
}
%}
@@ -345,7 +345,7 @@ struct packed_rrset_data {
PyObject* _get_data_rr_len(struct packed_rrset_data* d, int idx) {
if ((d != NULL) && (idx >= 0) &&
((size_t)idx < (d->count+d->rrsig_count)))
return PyInt_FromLong(d->rr_len[idx]);
return PyLong_FromLong(d->rr_len[idx]);
return Py_None;
}
void _set_data_rr_ttl(struct packed_rrset_data* d, int idx, uint32_t ttl)
@@ -357,7 +357,7 @@ struct packed_rrset_data {
PyObject* _get_data_rr_ttl(struct packed_rrset_data* d, int idx) {
if ((d != NULL) && (idx >= 0) &&
((size_t)idx < (d->count+d->rrsig_count)))
return PyInt_FromLong(d->rr_ttl[idx]);
return PyLong_FromLong(d->rr_ttl[idx]);
return Py_None;
}
PyObject* _get_data_rr_data(struct packed_rrset_data* d, int idx) {
@@ -555,12 +555,12 @@ struct sockaddr_storage {};
if (ss->ss_family == AF_INET) {
const struct sockaddr_in *sa4 = (struct sockaddr_in *)ss;
return PyInt_FromLong(ntohs(sa4->sin_port));
return PyLong_FromLong(ntohs(sa4->sin_port));
}
if (ss->ss_family == AF_INET6) {
const struct sockaddr_in6 *sa6 = (struct sockaddr_in6 *)ss;
return PyInt_FromLong(ntohs(sa6->sin6_port));
return PyLong_FromLong(ntohs(sa6->sin6_port));
}
return Py_None;
@@ -574,7 +574,7 @@ struct sockaddr_storage {};
}
sa6 = (struct sockaddr_in6 *)ss;
return PyInt_FromLong(ntohl(sa6->sin6_flowinfo));
return PyLong_FromLong(ntohl(sa6->sin6_flowinfo));
}
PyObject *_sockaddr_storage_scope_id(const struct sockaddr_storage *ss) {
@@ -585,7 +585,7 @@ struct sockaddr_storage {};
}
sa6 = (struct sockaddr_in6 *)ss;
return PyInt_FromLong(ntohl(sa6->sin6_scope_id));
return PyLong_FromLong(ntohl(sa6->sin6_scope_id));
}
%}
@@ -661,7 +661,7 @@ struct edns_option {
%inline %{
PyObject* _edns_option_opt_code_get(struct edns_option* option) {
uint16_t opt_code = option->opt_code;
return PyInt_FromLong(opt_code);
return PyLong_FromLong(opt_code);
}
PyObject* _edns_option_opt_data_get(struct edns_option* option) {
@@ -729,7 +729,8 @@ struct module_env {
int check_ratelimit,
struct sockaddr_storage* addr, socklen_t addrlen,
uint8_t* zone, size_t zonelen, int tcp_upstream, int ssl_upstream,
char* tls_auth_name, struct module_qstate* q, int* was_ratelimited);
char* tls_auth_name, struct module_qstate* q, int* was_ratelimited,
int* ratelimit_incremented);
void (*detach_subs)(struct module_qstate* qstate);
int (*attach_sub)(struct module_qstate* qstate,
struct query_info* qinfo, struct respip_client_info* cinfo,
@@ -1626,7 +1627,7 @@ int edns_opt_list_append(struct edns_option** list, uint16_t code, size_t len,
}
result = PyObject_Call(func, py_args, py_kwargs);
if (result) {
res = PyInt_AsLong(result);
res = PyLong_AsLong(result);
}
out:
Py_XDECREF(py_edns);
@@ -1710,7 +1711,7 @@ out:
}
result = PyObject_Call(func, py_args, py_kwargs);
if (result) {
res = PyInt_AsLong(result);
res = PyLong_AsLong(result);
}
out:
Py_XDECREF(py_qinfo);
@@ -1764,7 +1765,7 @@ out:
}
result = PyObject_Call(func, py_args, py_kwargs);
if (result) {
res = PyInt_AsLong(result);
res = PyLong_AsLong(result);
}
out:
Py_XDECREF(py_qstate);
@@ -1813,7 +1814,7 @@ out:
}
result = PyObject_Call(func, py_args, py_kwargs);
if (result) {
res = PyInt_AsLong(result);
res = PyLong_AsLong(result);
}
out:
Py_XDECREF(py_qstate);
+18 -5
View File
@@ -246,14 +246,14 @@ log_py_err(void)
}
/* And it should be a string all ready to go - duplicate it. */
if (!PyString_Check(obResult) && !PyUnicode_Check(obResult)) {
if (!PyBytes_Check(obResult) && !PyUnicode_Check(obResult)) {
log_err("pythonmod: cannot print exception, "
"StringIO.getvalue() result did not String_Check"
" or Unicode_Check");
goto cleanup;
}
if(PyString_Check(obResult)) {
result = PyString_AsString(obResult);
if(PyBytes_Check(obResult)) {
result = PyBytes_AsString(obResult);
} else {
ascstr = PyUnicode_AsASCIIString(obResult);
result = PyBytes_AsString(ascstr);
@@ -450,7 +450,7 @@ int pythonmod_init(struct module_env* env, int id)
pe->data = PyDict_New();
/* add the script filename to the global "mod_env" for trivial access */
fname = PyString_FromString(pe->fname);
fname = PyUnicode_FromString(pe->fname);
if(PyDict_SetItemString(pe->data, "script", fname) < 0) {
log_err("pythonmod: could not add item to dictionary");
Py_XDECREF(fname);
@@ -487,10 +487,23 @@ int pythonmod_init(struct module_env* env, int id)
/* for python 3.9 and newer */
char* fstr = NULL;
size_t flen = 0;
long pos = 0;
log_err("pythonmod: can't parse Python script %s", pe->fname);
/* print the error to logs too, run it again */
fseek(script_py, 0, SEEK_END);
flen = (size_t)ftell(script_py);
pos = ftell(script_py);
if (pos == -1L) {
log_err("ftell failed to print parse error: %s: %s",
pe->fname, strerror(errno));
goto fail_close_file;
}
flen = (size_t)pos;
#ifdef SIZE_MAX
if(flen > SIZE_MAX-2) {
log_err("script file too large");
goto fail_close_file;
}
#endif
fstr = malloc(flen+1);
if(!fstr) {
log_err("malloc failure to print parse error");
+39 -22
View File
@@ -899,27 +899,34 @@ respip_rewrite_reply(const struct query_info* qinfo,
int rpz_cname_override = 0;
char* log_name = NULL;
if(!cinfo)
goto done;
ctaglist = cinfo->taglist;
ctaglen = cinfo->taglen;
tag_actions = cinfo->tag_actions;
tag_actions_size = cinfo->tag_actions_size;
tag_datas = cinfo->tag_datas;
tag_datas_size = cinfo->tag_datas_size;
if(cinfo->view) {
view = cinfo->view;
lock_rw_rdlock(&view->lock);
} else if(cinfo->view_name) {
view = views_find_view(views, cinfo->view_name, 0);
if(!view) {
/* If the view no longer exists, the rewrite can not
* be processed further. */
verbose(VERB_ALGO, "respip: failed because view %s no "
"longer exists", cinfo->view_name);
return 0;
if(!cinfo) {
/* Internal mesh sub-query (e.g. dns64 A lookup): no
* per-client view/tags, but global response-ip and RPZ
* rpz-ip must still apply. */
ctaglist = NULL; ctaglen = 0;
tag_actions = NULL; tag_actions_size = 0;
tag_datas = NULL; tag_datas_size = 0;
} else {
ctaglist = cinfo->taglist;
ctaglen = cinfo->taglen;
tag_actions = cinfo->tag_actions;
tag_actions_size = cinfo->tag_actions_size;
tag_datas = cinfo->tag_datas;
tag_datas_size = cinfo->tag_datas_size;
if(cinfo->view) {
view = cinfo->view;
lock_rw_rdlock(&view->lock);
} else if(cinfo->view_name) {
view = views_find_view(views, cinfo->view_name, 0);
if(!view) {
/* If the view no longer exists, the rewrite can not
* be processed further. */
verbose(VERB_ALGO, "respip: failed because view %s no "
"longer exists", cinfo->view_name);
return 0;
}
/* The view is rdlocked by views_find_view. */
}
/* The view is rdlocked by views_find_view. */
}
log_assert(ipset);
@@ -1114,7 +1121,13 @@ respip_operate(struct module_qstate* qstate, enum module_ev event, int id,
if((qstate->qinfo.qtype == LDNS_RR_TYPE_A ||
qstate->qinfo.qtype == LDNS_RR_TYPE_AAAA ||
qstate->qinfo.qtype == LDNS_RR_TYPE_ANY) &&
qstate->return_msg && qstate->return_msg->rep) {
qstate->return_msg && qstate->return_msg->rep &&
!(qstate->env->need_to_validate &&
(!(qstate->query_flags & BIT_CD)
|| qstate->env->cfg->ignore_cd) &&
(qstate->return_msg->rep->security <= sec_status_bogus
|| qstate->return_msg->rep->security ==
sec_status_secure_sentinel_fail))) {
struct reply_info* new_rep = qstate->return_msg->rep;
struct ub_packed_rrset_key* alias_rrset = NULL;
struct respip_action_info actinfo = {0, 0, 0, 0, NULL, 0, NULL};
@@ -1151,8 +1164,10 @@ respip_operate(struct module_qstate* qstate, enum module_ev event, int id,
* clients. */
qstate->is_drop = 1;
} else if(alias_rrset) {
if(!generate_cname_request(qstate, alias_rrset))
if(!generate_cname_request(qstate, alias_rrset)) {
errinf(qstate, "Could not generate CNAME request");
goto servfail;
}
next_state = module_wait_subquery;
}
qstate->return_msg->rep = new_rep;
@@ -1166,6 +1181,7 @@ respip_operate(struct module_qstate* qstate, enum module_ev event, int id,
servfail:
qstate->return_rcode = LDNS_RCODE_SERVFAIL;
qstate->return_msg = NULL;
qstate->ext_state[id] = module_finished;
}
int
@@ -1262,6 +1278,7 @@ respip_inform_super(struct module_qstate* qstate, int id,
return;
fail:
errinf(super, "CNAME lookup failed");
super->return_rcode = LDNS_RCODE_SERVFAIL;
super->return_msg = NULL;
return;
+921
View File
@@ -0,0 +1,921 @@
/*
* services/authload.c - authoritative zone load thread
*
* Copyright (c) 2026, NLnet Labs. All rights reserved.
*
* This software is open source.
*
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions
* are met:
*
* Redistributions of source code must retain the above copyright notice,
* this list of conditions and the following disclaimer.
*
* Redistributions in binary form must reproduce the above copyright notice,
* this list of conditions and the following disclaimer in the documentation
* and/or other materials provided with the distribution.
*
* Neither the name of the NLNET LABS nor the names of its contributors may
* be used to endorse or promote products derived from this software without
* specific prior written permission.
*
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
* "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
* LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
* A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
* HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
* SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED
* TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
* PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
* LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
* NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
* SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
*/
/**
* \file
*
* This file contains the auth load thread. This loads authority zone
* and RPZ zone information in a thread, in a separate memory structure.
* When it is done, the information is swapped over to the running server.
*/
#include "config.h"
#include "services/authload.h"
#include "daemon/worker.h"
#include "daemon/daemon.h"
#include "services/authzone.h"
#include "libunbound/authload.h"
#include "util/net_help.h"
#include "util/log.h"
#include "util/ub_event.h"
#include "util/timeval_func.h"
#include "util/data/dname.h"
/** Get memory use of buffer. */
static size_t
buffer_get_mem(struct sldns_buffer* buf)
{
if(!buf) return 0;
return sizeof(*buf) + (buf->_data?buf->_capacity:0);
}
/** Auth load notification to string, for descriptive purposes. */
static const char*
auth_load_notification_to_string(enum auth_load_notification_type status)
{
switch(status) {
case auth_load_notification_exit:
return "auth_load_notification_exit";
default:
break;
}
return "unknown_auth_load_notification_value";
}
/** delete chunks */
static void
auth_chunk_list_delete(struct auth_chunk* first)
{
struct auth_chunk* c = first, *cn;
while(c) {
cn = c->next;
free(c->data);
free(c);
c = cn;
}
}
/** Delete auth load task item */
static void
auth_load_task_delete(struct auth_load_task* task)
{
if(!task)
return;
free(task->name);
free(task->host);
free(task->file);
auth_chunk_list_delete(task->chunks_first);
free(task);
}
/** Create new auth load task item */
static struct auth_load_task*
auth_load_task_create(void)
{
struct auth_load_task* task = (struct auth_load_task*)calloc(1,
sizeof(*task));
return task;
}
/** Pick up the work content of task transfer of auth xfr */
static int
auth_load_task_pickup_xfr(struct auth_load_task* task, struct auth_xfer* xfr)
{
task->name = memdup(xfr->name, xfr->namelen);
if(!task->name)
return 0;
task->namelen = xfr->namelen;
task->dclass = xfr->dclass;
if(xfr->task_transfer->master && xfr->task_transfer->master->host) {
task->host = strdup(xfr->task_transfer->master->host);
if(!task->host)
return 0;
}
if(xfr->task_transfer->master && xfr->task_transfer->master->file) {
task->file = strdup(xfr->task_transfer->master->file);
if(!task->file)
return 0;
}
if(xfr->task_transfer->master)
task->on_http = xfr->task_transfer->master->http;
task->on_ixfr = xfr->task_transfer->on_ixfr;
task->on_ixfr_is_axfr = xfr->task_transfer->on_ixfr_is_axfr;
task->serial = xfr->serial;
if(xfr->task_transfer->chunks_first) {
task->chunks_first = xfr->task_transfer->chunks_first;
task->chunks_last = xfr->task_transfer->chunks_last;
task->chunks_total = xfr->task_transfer->chunks_total;
/* The task now has the chunks. Remove them from the
* xfr structure. */
xfr->task_transfer->chunks_first = 0;
xfr->task_transfer->chunks_last = 0;
xfr->task_transfer->chunks_total = 0;
}
if(task->on_http)
task->task_type = AUTH_LOAD_TASK_HTTPCHUNKS;
else task->task_type = AUTH_LOAD_TASK_TRANSFER;
return 1;
}
/** Create xfr task */
static struct auth_load_task*
auth_load_task_create_xfr(struct auth_xfer* xfr, struct worker* worker)
{
struct auth_load_task* task = auth_load_task_create();
if(!task) {
log_err("out of memory");
return 0;
}
task->worker = worker;
if(!auth_load_task_pickup_xfr(task, xfr)) {
log_err("out of memory");
auth_load_task_delete(task);
return 0;
}
return task;
}
int
auth_load_thread_poll_for_quit(struct auth_load_thread* thr)
{
int inevent, loopexit = 0;
uint8_t cmd;
ssize_t ret;
if(!thr)
return 0;
if(thr->need_to_quit)
return 1;
/* Is there data? */
if(!sock_poll_timeout(thr->commpair[1], 0, 1, 0, &inevent)) {
log_err("auth_load_thread_poll_for_quit: poll failed");
return 0;
}
if(!inevent)
return 0;
/* Read the data */
while(1) {
if(++loopexit > 200) {
log_err("auth_load_thread_poll_for_quit: recv loops %s",
sock_strerror(errno));
return 0;
}
ret = recv(thr->commpair[1], ((char*)&cmd), sizeof(cmd), 0);
if(ret == -1) {
if(
#ifndef USE_WINSOCK
errno == EINTR || errno == EAGAIN
# ifdef EWOULDBLOCK
|| errno == EWOULDBLOCK
# endif
#else
WSAGetLastError() == WSAEINTR ||
WSAGetLastError() == WSAEINPROGRESS ||
WSAGetLastError() == WSAEWOULDBLOCK
#endif
)
continue; /* Try again. */
log_err("auth_load_thread_poll_for_quit: recv: %s",
sock_strerror(errno));
return 0;
} else if(ret == 0) {
log_err("auth_load_thread_poll_for_quit: recv: EOF");
return 0;
}
break;
}
if(cmd == auth_load_notification_exit) {
thr->need_to_quit = 1;
verbose(VERB_ALGO, "auth load: exit notification received");
return 1;
}
log_err("auth_load_thread_poll_for_quit: unknown notification status "
"received: %d %s", cmd, auth_load_notification_to_string(cmd));
return 0;
}
/** Signal the worker connected to an auth load thread the status */
static void
auth_load_thread_signal_worker(struct auth_load_thread* thr, int status)
{
int outevent, loopexit = 0;
ssize_t ret;
uint8_t to_send;
verbose(VERB_ALGO, "auth load thread: send status %d", status);
/* Make a blocking attempt to send. But meanwhile stay responsive,
* once in a while for quit commands. In case the server has to quit. */
/* see if there is incoming quit signals */
if(auth_load_thread_poll_for_quit(thr))
return;
to_send = (uint8_t)status;
while(1) {
if(++loopexit > 200) {
log_err("auth load thread: could not send status");
return;
}
/* wait for socket to become writable */
if(!sock_poll_timeout(thr->commpair[1],
200, /* msec wait before check for quit, and loop to
wait again. */
0, 1, &outevent)) {
log_err("auth load thread: poll failed");
return;
}
if(auth_load_thread_poll_for_quit(thr))
return;
if(!outevent)
continue;
ret = send(thr->commpair[1], &to_send, 1, 0);
if(ret == -1) {
if(
#ifndef USE_WINSOCK
errno == EINTR || errno == EAGAIN
# ifdef EWOULDBLOCK
|| errno == EWOULDBLOCK
# endif
#else
WSAGetLastError() == WSAEINTR ||
WSAGetLastError() == WSAEINPROGRESS ||
WSAGetLastError() == WSAEWOULDBLOCK
#endif
)
continue; /* Try again. */
log_err("auth load thread signal worker: send: %s",
sock_strerror(errno));
return;
} else if(ret < 1) {
continue;
}
break;
}
}
/** Create proxy auth zone structure, that is used to hold the data
* that is processed. */
static struct auth_zone*
auth_zone_create_proxy(uint8_t* nm, size_t nmlen, uint16_t dclass)
{
struct auth_zone* z = (struct auth_zone*)calloc(1, sizeof(*z));
if(!z) {
return NULL;
}
z->node.key = z;
z->dclass = dclass;
z->namelen = nmlen;
z->namelabs = dname_count_labels(nm);
z->name = memdup(nm, nmlen);
if(!z->name) {
free(z);
return NULL;
}
rbtree_init(&z->data, &auth_data_cmp);
return z;
}
/** Delete proxy auth zone structure */
static void
auth_zone_delete_proxy(struct auth_zone* z)
{
if(!z)
return;
traverse_postorder(&z->data, auth_data_del, NULL);
if(z->rpz)
rpz_delete(z->rpz);
free(z->name);
free(z);
}
/** Calculate memory use of the authload thread for this task.
* The size of the task struct, with the data chunks, and the proxy auth zone
* structure that is created while the other auth zone is used for queries,
* and other added memory.
*/
static void
auth_load_calc_mem(struct auth_load_task* task, struct auth_zone* z,
size_t other)
{
size_t m = 0;
if(verbosity < 8) {
task->mem_used = 0;
return;
}
m += other;
m += sizeof(*task);
m += task->namelen;
m += getmem_str(task->host);
m += getmem_str(task->file);
m += task->chunks_total;
m += auth_zone_get_mem(z);
task->mem_used = m;
}
/** Swap the final zone contents with the live zone */
static void
auth_load_swap_zone(struct auth_load_thread* thr, struct auth_zone* proxyz)
{
rbtree_type data;
struct rpz* rpz;
struct auth_zone* z;
lock_rw_rdlock(&thr->task->worker->env.auth_zones->lock);
z = auth_zone_find(thr->task->worker->env.auth_zones,
thr->task->name, thr->task->namelen, thr->task->dclass);
if(!z) {
lock_rw_unlock(&thr->task->worker->env.auth_zones->lock);
verbose(VERB_ALGO, "auth zone missing after auth load.");
return;
}
lock_rw_wrlock(&z->lock);
lock_rw_unlock(&thr->task->worker->env.auth_zones->lock);
data = proxyz->data;
proxyz->data = z->data;
z->data = data;
rpz = proxyz->rpz;
proxyz->rpz = z->rpz;
z->rpz = rpz;
lock_rw_unlock(&z->lock);
}
/** Process http transfer */
static int
auth_load_process_http(struct auth_load_thread* thr)
{
struct auth_load_task* task = thr->task;
struct sldns_buffer* scratch_buffer;
struct auth_zone* z;
size_t scratch_mem;
scratch_buffer = sldns_buffer_new(sldns_buffer_capacity(
thr->task->worker->env.scratch_buffer));
if(!scratch_buffer) {
log_err("out of memory");
return 0;
}
scratch_mem = buffer_get_mem(scratch_buffer);
z = auth_zone_create_proxy(task->name, task->namelen, task->dclass);
if(!z) {
log_err("out of memory");
sldns_buffer_free(scratch_buffer);
return 0;
}
if(auth_load_thread_poll_for_quit(thr)) {
sldns_buffer_free(scratch_buffer);
auth_zone_delete_proxy(z);
return 0;
}
xfr_http_preview(task->file, task->chunks_first);
if(!xfr_http_syntax_check(task->name, task->namelen, task->dclass,
task->host, task->file, task->chunks_first, scratch_buffer)) {
sldns_buffer_free(scratch_buffer);
auth_zone_delete_proxy(z);
return 0;
}
if(auth_load_thread_poll_for_quit(thr)) {
sldns_buffer_free(scratch_buffer);
auth_zone_delete_proxy(z);
return 0;
}
if(!xfr_apply_http(task->name, task->namelen, task->host, task->file,
task->chunks_first, z, scratch_buffer, thr)) {
sldns_buffer_free(scratch_buffer);
auth_zone_delete_proxy(z);
return 0;
}
sldns_buffer_free(scratch_buffer);
if(z->rpz)
rpz_finish_config(z->rpz);
if(auth_load_thread_poll_for_quit(thr)) {
auth_zone_delete_proxy(z);
return 0;
}
auth_load_calc_mem(task, z, scratch_mem);
auth_load_swap_zone(thr, z);
auth_zone_delete_proxy(z);
return 1;
}
/** Copy RRset and append it to the domain, update last pointer. */
static int
rrset_append_copy(struct auth_data* domain, struct auth_rrset* rrset,
struct auth_rrset** last)
{
struct auth_rrset* s = calloc(1, sizeof(*s));
if(!s)
return 0;
s->type = rrset->type;
s->data = (struct packed_rrset_data*)memdup(rrset->data,
packed_rrset_sizeof(rrset->data));
if(!s->data) {
free(s);
return 0;
}
packed_rrset_ptr_fixup(s->data);
if(!*last)
domain->rrsets = s;
else (*last)->next = s;
*last = s;
return 1;
}
/** Copy the existing zone for modification */
static int
auth_load_copy_into_zone(struct auth_load_thread* thr, struct auth_zone* proxyz)
{
int count = 0;
struct auth_zone* z;
struct auth_data* d;
lock_rw_rdlock(&thr->task->worker->env.auth_zones->lock);
z = auth_zone_find(thr->task->worker->env.auth_zones,
thr->task->name, thr->task->namelen, thr->task->dclass);
if(!z) {
lock_rw_unlock(&thr->task->worker->env.auth_zones->lock);
verbose(VERB_ALGO, "auth zone missing for copy for IXFR.");
return 0;
}
lock_rw_rdlock(&z->lock);
lock_rw_unlock(&thr->task->worker->env.auth_zones->lock);
/* Copy from z into proxyz. */
RBTREE_FOR(d, struct auth_data*, &z->data) {
struct auth_rrset* rrset, *last = NULL;
struct auth_data* proxy_d = az_domain_create(proxyz,
d->name, d->namelen);
if(!proxy_d) {
log_err("out of memory");
lock_rw_unlock(&z->lock);
return 0;
}
for(rrset = d->rrsets; rrset; rrset=rrset->next) {
if(!rrset_append_copy(proxy_d, rrset, &last)) {
log_err("out of memory");
lock_rw_unlock(&z->lock);
return 0;
}
if((count++)%10000 == 0) {
if(auth_load_thread_poll_for_quit(thr)) {
lock_rw_unlock(&z->lock);
return 0;
}
}
}
if((count++)%10000 == 0) {
if(auth_load_thread_poll_for_quit(thr)) {
lock_rw_unlock(&z->lock);
return 0;
}
}
}
lock_rw_unlock(&z->lock);
return 1;
}
/** Process ixfr transfer */
static int
auth_load_process_ixfr(struct auth_load_thread* thr)
{
struct auth_load_task* task = thr->task;
struct sldns_buffer* scratch_buffer;
struct auth_zone* z;
size_t scratch_mem;
scratch_buffer = sldns_buffer_new(sldns_buffer_capacity(
thr->task->worker->env.scratch_buffer));
if(!scratch_buffer) {
log_err("out of memory");
return 0;
}
scratch_mem = buffer_get_mem(scratch_buffer);
z = auth_zone_create_proxy(task->name, task->namelen, task->dclass);
if(!z) {
log_err("out of memory");
sldns_buffer_free(scratch_buffer);
return 0;
}
if(auth_load_thread_poll_for_quit(thr)) {
sldns_buffer_free(scratch_buffer);
auth_zone_delete_proxy(z);
return 0;
}
/* Copy the existing zone for modification, that uses a read lock.
* That then does not interrupt the service of threads. */
if(!auth_load_copy_into_zone(thr, z)) {
sldns_buffer_free(scratch_buffer);
auth_zone_delete_proxy(z);
return 0;
}
if(!xfr_apply_ixfr(task->chunks_first, task->serial, z,
scratch_buffer, thr)) {
sldns_buffer_free(scratch_buffer);
auth_zone_delete_proxy(z);
return 0;
}
sldns_buffer_free(scratch_buffer);
if(auth_load_thread_poll_for_quit(thr)) {
auth_zone_delete_proxy(z);
return 0;
}
auth_load_calc_mem(task, z, scratch_mem);
auth_load_swap_zone(thr, z);
auth_zone_delete_proxy(z);
return 1;
}
/** Process axfr transfer */
static int
auth_load_process_axfr(struct auth_load_thread* thr)
{
struct auth_load_task* task = thr->task;
struct sldns_buffer* scratch_buffer;
struct auth_zone* z;
size_t scratch_mem;
scratch_buffer = sldns_buffer_new(sldns_buffer_capacity(
thr->task->worker->env.scratch_buffer));
if(!scratch_buffer) {
log_err("out of memory");
return 0;
}
scratch_mem = buffer_get_mem(scratch_buffer);
z = auth_zone_create_proxy(task->name, task->namelen, task->dclass);
if(!z) {
log_err("out of memory");
sldns_buffer_free(scratch_buffer);
return 0;
}
if(auth_load_thread_poll_for_quit(thr)) {
sldns_buffer_free(scratch_buffer);
auth_zone_delete_proxy(z);
return 0;
}
if(!xfr_apply_axfr(task->chunks_first, z, scratch_buffer, thr)) {
sldns_buffer_free(scratch_buffer);
auth_zone_delete_proxy(z);
return 0;
}
sldns_buffer_free(scratch_buffer);
if(auth_load_thread_poll_for_quit(thr)) {
auth_zone_delete_proxy(z);
return 0;
}
auth_load_calc_mem(task, z, scratch_mem);
auth_load_swap_zone(thr, z);
auth_zone_delete_proxy(z);
return 1;
}
/** In the auth load thread, process the task */
static int
auth_load_thread_process(struct auth_load_thread* thr)
{
struct auth_load_task* task = thr->task;
struct timeval start, end;
if(gettimeofday(&start, NULL) < 0)
log_err("gettimeofday: %s", strerror(errno));
/* apply data */
if(task->on_http) {
if(!auth_load_process_http(thr))
return 0;
} else if(task->on_ixfr && !task->on_ixfr_is_axfr) {
if(!auth_load_process_ixfr(thr))
return 0;
} else {
if(!auth_load_process_axfr(thr))
return 0;
}
if(gettimeofday(&end, NULL) < 0)
log_err("gettimeofday: %s", strerror(errno));
timeval_subtract(&thr->task->time_taken, &end, &start);
return 1;
}
/** The auth load thread. The thread main function. */
static void*
auth_load_thread_main(void* arg)
{
struct auth_load_thread* thr = (struct auth_load_thread*)arg;
int s;
const char name[16] = "unbound/authld"; /* seems to be the safest size
between different OSes */
#if defined(HAVE_GETTID) && !defined(THREADS_DISABLED)
thr->thread_tid = gettid();
if(thr->thread_tid_log)
log_thread_set(&thr->thread_tid);
else
#endif
log_thread_set(&thr->threadnum);
ub_thread_setname(ub_thread_self(), name);
(void)name; /* When setname is not defined, ignore the name variable. */
verbose(VERB_ALGO, "start auth load thread");
s = auth_load_thread_process(thr);
/* The result is sent to the worker, that reaps the thread. */
auth_load_thread_signal_worker(thr, s);
verbose(VERB_ALGO, "stop auth load thread");
return NULL;
}
/** Delete auth load thread structure */
static void
auth_load_thread_delete(struct auth_load_thread* thr)
{
if(!thr)
return;
if(thr->service_event && thr->service_event_is_added) {
ub_event_del(thr->service_event);
thr->service_event_is_added = 0;
}
if(thr->service_event)
ub_event_free(thr->service_event);
if(thr->commpair[0] != -1)
sock_close(thr->commpair[0]);
if(thr->commpair[1] != -1)
sock_close(thr->commpair[1]);
auth_load_task_delete(thr->task);
free(thr);
}
/** Create auth load thread structure */
static struct auth_load_thread*
auth_load_thread_create(struct auth_load_task* task)
{
int numworkers;
struct auth_load_thread* thr = (struct auth_load_thread*)calloc(1,
sizeof(*thr));
if(!thr)
return NULL;
numworkers = task->worker->daemon->num;
/* This number is printed into the logs */
thr->threadnum = numworkers+3;
thr->task = task;
thr->commpair[0] = -1;
thr->commpair[1] = -1;
if(!create_socketpair(thr->commpair, task->worker->daemon->rand)) {
auth_load_thread_delete(thr);
return NULL;
}
#ifdef HAVE_GETTID
thr->thread_tid_log = task->worker->env.cfg->log_thread_id;
#endif
return thr;
}
/** The worker routine that services the auth load connection. */
void
worker_auth_load_service_cb(int ATTR_UNUSED(fd), short ATTR_UNUSED(bits),
void* arg)
{
struct auth_load_thread* thr = (struct auth_load_thread*)arg;
uint8_t recv_item;
ssize_t ret;
struct auth_xfer* xfr;
struct auth_chunk* chunk_list;
struct module_env* env = &thr->task->worker->env;
int ixfr_fail;
struct timeval time_taken;
size_t mem_used, chunks_total;
log_assert(thr->commpair[0] >= 0);
ret = recv(thr->commpair[0], &recv_item, 1, 0);
if(ret == -1) {
if(
#ifndef USE_WINSOCK
errno == EINTR || errno == EAGAIN
# ifdef EWOULDBLOCK
|| errno == EWOULDBLOCK
# endif
#else
WSAGetLastError() == WSAEINTR ||
WSAGetLastError() == WSAEINPROGRESS
#endif
)
return; /* Continue later. */
#ifdef USE_WINSOCK
if(WSAGetLastError() == WSAEWOULDBLOCK) {
ub_winsock_tcp_wouldblock(thr->service_event,
UB_EV_READ);
return; /* Continue later. */
}
#endif
log_err("read status from auth load thread, recv: %s",
sock_strerror(errno));
return;
} else if(ret == 0) {
verbose(VERB_ALGO, "closed connection from auth load thread");
/* handle this like an error */
recv_item = 0;
/* ret<1: No short read on 1 byte, to continue later on */
}
/* Deal with the result of auth load thread */
verbose(VERB_ALGO, "auth load status is %d", (int)recv_item);
verbose(VERB_ALGO, "join with auth load thread");
ub_thread_join(thr->tid);
verbose(VERB_ALGO, "joined with auth load thread");
lock_rw_rdlock(&thr->task->worker->env.auth_zones->lock);
xfr = auth_xfer_find(thr->task->worker->env.auth_zones,
thr->task->name, thr->task->namelen, thr->task->dclass);
if(!xfr) {
lock_rw_unlock(&thr->task->worker->env.auth_zones->lock);
verbose(VERB_ALGO, "auth load: xfr is gone");
auth_load_thread_delete(thr);
auth_load_info_release_thread(env);
return;
}
lock_basic_lock(&xfr->lock);
lock_rw_unlock(&thr->task->worker->env.auth_zones->lock);
ixfr_fail = thr->task->ixfr_fail;
time_taken = thr->task->time_taken;
mem_used = thr->task->mem_used;
chunks_total = thr->task->chunks_total;
if(thr->task->on_http) {
chunk_list = thr->task->chunks_first;
thr->task->chunks_first = NULL;
thr->task->chunks_last = NULL;
thr->task->chunks_total = 0;
} else {
chunk_list = NULL;
}
auth_load_thread_delete(thr);
auth_load_info_release_thread(env);
xfr_process_load_end_transfer(xfr, env, recv_item, ixfr_fail,
&time_taken, mem_used, chunks_total, chunk_list);
}
/** Attach worker to the auth load thread. */
static int
auth_load_thread_attach(struct auth_load_thread* thr, struct worker* worker)
{
/* Setup listener in worker, that connects via a pipe to the
* auth load thread.
* The listener has to be nonblocking, so the the remote servicing
* thread can continue to service DNS queries.
* The commpair[1] element can stay blocking, it is used by the
* auth load thread. The thread needs to wait at these times, when
* it has to check briefly it can use poll. */
verbose(VERB_ALGO, "auth_load_thread_attach");
fd_set_nonblock(thr->commpair[0]);
if(!comm_base_internal(worker->base)) {
verbose(VERB_ALGO, "auth load thread: no event base");
return 0;
}
thr->service_event = ub_event_new(comm_base_internal(worker->base),
thr->commpair[0], UB_EV_READ | UB_EV_PERSIST,
worker_auth_load_service_cb, thr);
if(!thr->service_event) {
log_err("out of memory");
return 0;
}
if(ub_event_add(thr->service_event, NULL) != 0) {
log_err("out of memory");
return 0;
}
thr->service_event_is_added = 1;
return 1;
}
/** Create and start the auth load thread, with the task */
static int
auth_load_start_thread(struct auth_load_task* task)
{
struct auth_load_thread* thr = auth_load_thread_create(task);
if(!thr) {
log_err("out of memory");
auth_load_task_delete(task);
return 0;
}
if(!auth_load_thread_attach(thr, task->worker)) {
log_err("out of memory");
auth_load_thread_delete(thr);
return 0;
}
/* Start auth load thread */
ub_thread_create(&thr->tid, auth_load_thread_main, thr);
return 1;
}
int auth_load_add_task_xfr(struct auth_xfer* xfr, struct worker* worker)
{
struct auth_load_task* task;
int can_run = 0;
verbose(VERB_ALGO, "auth load add task");
/* Check auth load count */
can_run = 1;
/* Create new thread */
task = auth_load_task_create_xfr(xfr, worker);
if(!task)
return 0;
if(can_run) {
verbose(VERB_ALGO, "auth load start thread");
if(!auth_load_start_thread(task))
return 0;
verbose(VERB_ALGO, "auth load thread started");
return 1;
}
/* Make wait item */
return 0;
}
struct auth_load_general_info* auth_load_info_create(void)
{
struct auth_load_general_info* auth_load_info =
(struct auth_load_general_info*)calloc(1,
sizeof(*auth_load_info));
if(!auth_load_info) {
log_err("malloc failure");
return NULL;
}
lock_basic_init(&auth_load_info->lock);
lock_protect(&auth_load_info->lock,
&auth_load_info->num_auth_load_threads,
sizeof(auth_load_info->num_auth_load_threads));
return auth_load_info;
}
void auth_load_info_delete(struct auth_load_general_info* auth_load_info)
{
if(!auth_load_info)
return;
lock_basic_destroy(&auth_load_info->lock);
free(auth_load_info);
}
int auth_load_info_grab_thread(struct module_env* env)
{
struct auth_load_general_info* auth_load_info =
env->worker->daemon->auth_load_info;
struct config_file* cfg = env->cfg;
int ret = 0;
lock_basic_lock(&auth_load_info->lock);
if(auth_load_info->num_auth_load_threads < cfg->auth_task_threads) {
ret = 1;
auth_load_info->num_auth_load_threads++;
}
lock_basic_unlock(&auth_load_info->lock);
return ret;
}
void auth_load_info_release_thread(struct module_env* env)
{
struct auth_load_general_info* auth_load_info =
env->worker->daemon->auth_load_info;
lock_basic_lock(&auth_load_info->lock);
if(auth_load_info->num_auth_load_threads == 0) {
verbose(VERB_ALGO, "release of auth load thread, but "
"num_auth_load_threads not > 0.");
} else {
auth_load_info->num_auth_load_threads--;
}
lock_basic_unlock(&auth_load_info->lock);
}
+203
View File
@@ -0,0 +1,203 @@
/*
* services/authload.h - authoritative zone load thread
*
* Copyright (c) 2026, NLnet Labs. All rights reserved.
*
* This software is open source.
*
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions
* are met:
*
* Redistributions of source code must retain the above copyright notice,
* this list of conditions and the following disclaimer.
*
* Redistributions in binary form must reproduce the above copyright notice,
* this list of conditions and the following disclaimer in the documentation
* and/or other materials provided with the distribution.
*
* Neither the name of the NLNET LABS nor the names of its contributors may
* be used to endorse or promote products derived from this software without
* specific prior written permission.
*
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
* "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
* LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
* A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
* HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
* SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED
* TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
* PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
* LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
* NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
* SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
*/
/**
* \file
*
* This file contains the auth load thread. This loads authority zone
* and RPZ zone information in a thread, in a separate memory structure.
* When it is done, the information is swapped over to the running server.
*/
#ifndef SERVICES_AUTHLOAD_H
#define SERVICES_AUTHLOAD_H
#include "util/locks.h"
struct worker;
struct auth_xfer;
struct module_env;
struct auth_load_task;
/**
* General information for auth load threads. The number of active threads.
*/
struct auth_load_general_info {
/** lock on this structure */
lock_basic_type lock;
/** The number of active auth load threads. */
int num_auth_load_threads;
};
/**
* The types of notifications that the auth load thread sends around.
*/
enum auth_load_notification_type {
/** This is sent to make the auth load thread perform exit */
auth_load_notification_exit
};
/**
* The auth load thread. The thread runs to load authority zone information
* and RPZ information into memory. It loads into a copy. Then that is swapped
* over to the running server. This keeps the server responsive while the
* information is loaded.
*/
struct auth_load_thread {
/** the thread number for the thread,
* must be first to cast thread arg to int* in checklock code. */
int threadnum;
/** thread id, of the io thread */
ub_thread_type tid;
#ifdef HAVE_GETTID
/** thread tid, the LWP id */
pid_t thread_tid;
/** if logging should include the LWP id */
int thread_tid_log;
#endif
/** communication socket pair, that sends commands */
int commpair[2];
/** if the thread has to quit */
int need_to_quit;
/** the event that listens on the worker to commpair,
* it receives content from the auth load thread. */
void* service_event;
/** if the event that listens on the worker has
* been added to the comm base. */
int service_event_is_added;
/** the worker that the auth load is connected to */
struct worker* worker;
/** The task that the thread is working on */
struct auth_load_task* task;
};
/**
* The types of tasks that the auth load can perform.
*/
enum auth_load_task_type {
AUTH_LOAD_TASK_TRANSFER,
AUTH_LOAD_TASK_ZONEFILE_READ,
AUTH_LOAD_TASK_ZONEFILE_WRITE,
AUTH_LOAD_TASK_HTTPCHUNKS
};
/**
* The task for the auth load. The task can be to load a zone transfer, AXFR,
* IXFR, from zonefile, and from a http read, from chunks.
*/
struct auth_load_task {
/** The type of the task */
enum auth_load_task_type task_type;
/** The task is connected with this worker */
struct worker* worker;
/** The zone name */
uint8_t* name;
/** The zone namelen */
size_t namelen;
/** The zone class */
uint16_t dclass;
/** name of the host that the transfer comes from. */
char* host;
/** file part of the url that the transfer comes from, or NULL. */
char* file;
/** Set if the host is http transfer, if false it is AXFR or IXFR. */
int on_http;
/** Set if the transfer is doing IXFR */
int on_ixfr;
/** Set if the transfer is an IXFR but we detected an AXFR contents */
int on_ixfr_is_axfr;
/** Set if the ixfr failed. (So that there can be backoff to AXFR). */
int ixfr_fail;
/** current serial (from SOA), if we have no zone, 0
* This is for checking the IXFR result. */
uint32_t serial;
/** the data chunks, or NULL, to process. */
struct auth_chunk* chunks_first;
/** last data chunk */
struct auth_chunk* chunks_last;
/** size of data in data chunks. */
size_t chunks_total;
/** time taken for the task */
struct timeval time_taken;
/** memory used for the task */
size_t mem_used;
};
/**
* Add a new task to be performed by the auth load thread.
* It starts a thread, or makes a wait list item.
* @param xfr: zone transfer to start for.
* @param worker: worker that is connected to the task.
* @return false on failure.
*/
int auth_load_add_task_xfr(struct auth_xfer* xfr, struct worker* worker);
/** See if there is a quit signal, true if so. */
int auth_load_thread_poll_for_quit(struct auth_load_thread* thr);
/**
* Create auth load info structure.
* @return NULL on failure.
*/
struct auth_load_general_info* auth_load_info_create(void);
/**
* Delete auth load info structure.
* @param auth_load_info: to delete.
*/
void auth_load_info_delete(struct auth_load_general_info* auth_load_info);
/**
* Grab a new thread from the auth load count.
* @param env: with auth_load_info with the active thread count.
* and config file, with configured maximum.
* @return false on failure, like too many active, true if successful.
*/
int auth_load_info_grab_thread(struct module_env* env);
/**
* Release thread from auth load count. It is done.
* @param env: with auth_load_info with the active thread count.
*/
void auth_load_info_release_thread(struct module_env* env);
#endif /* SERVICES_AUTHLOAD_H */
+677 -177
View File
File diff suppressed because it is too large Load Diff
+68
View File
@@ -65,6 +65,7 @@ struct auth_probe;
struct auth_transfer;
struct auth_master;
struct auth_chunk;
struct auth_load_thread;
/**
* Authoritative zones, shared.
@@ -144,6 +145,8 @@ struct auth_zone {
struct module_env* zonemd_callback_env;
/** for the zonemd callback, the type of data looked up */
uint16_t zonemd_callback_qtype;
/** for the zonemd callback, the unique info */
void* zonemd_callback_unique_info;
/** zone has been deleted */
int zone_deleted;
/** deletelist pointer, unused normally except during delete */
@@ -153,6 +156,10 @@ struct auth_zone {
struct auth_zone* rpz_az_next;
/** previous auth zone containing RPZ data, or NULL */
struct auth_zone* rpz_az_prev;
/** The maximum auth zone transfer size, in bytes. */
size_t max_transfer_size;
/** The maximum auth zone transfer time taken, in msec. */
int max_transfer_time;
};
/**
@@ -283,6 +290,15 @@ struct auth_xfer {
* this is renewed every SOA probe and transfer. On zone load
* from zonefile it is also set (with probe set soon to check) */
time_t lease_time;
/** The maximum auth zone transfer size, in bytes. */
size_t max_transfer_size;
/** The maximum auth zone transfer time taken, in msec. */
int max_transfer_time;
/** the zone is an rpz zone */
int is_rpz;
/** the number of IXFRs since the last full transfer. */
int num_ixfrs;
};
/**
@@ -331,6 +347,8 @@ struct auth_probe {
/** for the hostname lookups, which master is current */
struct auth_master* lookup_target;
/** for the lookup, the callback unique info */
void* lookup_unique_info;
/** are we looking up A or AAAA, first A, then AAAA (if ip6 enabled) */
int lookup_aaaa;
/** we only want to do lookups for making config work (for notify),
@@ -379,12 +397,18 @@ struct auth_transfer {
struct auth_chunk* chunks_first;
/** last element in chunks list (to append new data at the end) */
struct auth_chunk* chunks_last;
/** running total of bytes held in chunks_first..chunks_last */
size_t chunks_total;
/** start time of the transfer */
struct timeval start_time;
/** list of upstream masters for this zone, from config */
struct auth_master* masters;
/** for the hostname lookups, which master is current */
struct auth_master* lookup_target;
/** for the lookup, the callback unique info */
void* lookup_unique_info;
/** are we looking up A or AAAA, first A, then AAAA (if ip6 enabled) */
int lookup_aaaa;
@@ -828,4 +852,48 @@ void auth_xfer_delete(struct auth_xfer* xfr);
*/
void xfr_disown_tasks(struct auth_xfer* xfr, struct worker* worker);
/** count number of open and closed parenthesis in a chunkline */
int chunkline_count_parens(struct sldns_buffer* buf, size_t start);
/** Clear data in auth zone */
void auth_zone_clear_data(struct auth_zone* z);
/** Get memory usage of auth zone */
size_t auth_zone_get_mem(struct auth_zone* z);
/** create domain with the given name */
struct auth_data* az_domain_create(struct auth_zone* z, uint8_t* nm,
size_t nmlen);
/** helper traverse to delete zones */
void auth_data_del(rbnode_type* n, void* arg);
/** Handle the end of an auth load task. */
void xfr_process_load_end_transfer(struct auth_xfer* xfr,
struct module_env* env, uint8_t status, int ixfr_fail,
struct timeval* time_taken, size_t mem_used, size_t chunks_total,
struct auth_chunk* chunk_list);
/** Log preview of http transfer */
void xfr_http_preview(const char* file, struct auth_chunk* chunk_list);
/** Check syntax of first part of the http download */
int xfr_http_syntax_check(uint8_t* name, size_t namelen, uint16_t dclass,
const char* host, const char* file, struct auth_chunk* chunk_list,
struct sldns_buffer* scratch_buffer);
/** Apply http transfer to auth_zone */
int xfr_apply_http(uint8_t* name, size_t namelen, const char* host,
const char* file, struct auth_chunk* chunk_list, struct auth_zone* z,
struct sldns_buffer* scratch_buffer, struct auth_load_thread* thr);
/** Apply IXFR transfer to auth_zone */
int xfr_apply_ixfr(struct auth_chunk* chunk_list, uint32_t xfr_serial,
struct auth_zone* z, struct sldns_buffer* scratch_buffer,
struct auth_load_thread* thr);
/** Apply AXFR transfer to auth_zone */
int xfr_apply_axfr(struct auth_chunk* chunk_list, struct auth_zone* z,
struct sldns_buffer* scratch_buffer, struct auth_load_thread* thr);
#endif /* SERVICES_AUTHZONE_H */
+23 -3
View File
@@ -43,6 +43,7 @@
#include "iterator/iter_utils.h"
#include "validator/val_nsec.h"
#include "validator/val_utils.h"
#include "iterator/iter_utils.h"
#include "services/cache/dns.h"
#include "services/cache/rrset.h"
#include "util/data/msgparse.h"
@@ -277,6 +278,8 @@ find_closest_of_type(struct module_env* env, uint8_t* qname, size_t qnamelen,
/* snip off front label */
lablen = *qname;
if(lablen == 0)
break;
qname += lablen + 1;
qnamelen -= lablen + 1;
}
@@ -584,8 +587,12 @@ dns_cache_find_delegation(struct module_env* env, uint8_t* qname,
return NULL;
}
}
if(!delegpt_rrset_add_ns(dp, region, nskey, 0))
if(!delegpt_rrset_add_ns(dp, region, nskey, 0,
deleg_port_number(env))) {
lock_rw_unlock(&nskey->entry.lock);
log_err("find_delegation: addns out of memory");
return NULL;
}
lock_rw_unlock(&nskey->entry.lock); /* first unlock before next lookup*/
/* find and add DS/NSEC (if any) */
if(msg)
@@ -712,10 +719,16 @@ struct dns_msg*
dns_msg_deepcopy_region(struct dns_msg* origin, struct regional* region)
{
size_t i;
struct ub_packed_rrset_key** saved_rrsets;
struct dns_msg* res = NULL;
size_t rep_alloc_size = sizeof(struct reply_info)
- sizeof(struct rrset_ref); /* this is the size of res->rep
allocated in gen_dns_msg() */
res = gen_dns_msg(region, &origin->qinfo, origin->rep->rrset_count);
if(!res) return NULL;
*res->rep = *origin->rep;
saved_rrsets = res->rep->rrsets; /* save rrsets alloc by gen_dns_msg */
memcpy(res->rep, origin->rep, rep_alloc_size);
res->rep->rrsets = saved_rrsets;
if(origin->rep->reason_bogus_str) {
res->rep->reason_bogus_str = regional_strdup(region,
origin->rep->reason_bogus_str);
@@ -774,11 +787,16 @@ synth_dname_msg(struct ub_packed_rrset_key* rrset, struct regional* region,
uint8_t* newname, *dtarg = NULL;
size_t newlen, dtarglen;
time_t rr_ttl;
int graceperiod = 0;
if(TTL_IS_EXPIRED(d->ttl, now)) {
/* Allow TTL=0 DNAME from upstream within grace period */
if(!(rrset->rk.flags & PACKED_RRSET_UPSTREAM_0TTL))
return NULL;
rr_ttl = 0;
/* Since PACKED_RRSET_UPSTREAM_0TTL set the flag that
* the grace period has been applied, this stops the rrset
* from getting stored back into the cache with a bigger TTL.*/
graceperiod = 1;
} else {
rr_ttl = d->ttl - now;
}
@@ -806,6 +824,8 @@ synth_dname_msg(struct ub_packed_rrset_key* rrset, struct regional* region,
msg->rep->rrsets[0] = packed_rrset_copy_region(rrset, region, now);
if(!msg->rep->rrsets[0]) /* copy DNAME */
return NULL;
if(graceperiod)
msg->rep->rrsets[0]->rk.flags |= PACKED_RRSET_0TTL_GRACE;
/* synth CNAME rrset */
get_cname_target(rrset, &dtarg, &dtarglen);
if(!dtarg)
@@ -1059,7 +1079,7 @@ dns_cache_lookup(struct module_env* env,
if(env->cfg->harden_below_nxdomain) {
while(!dname_is_root(k.qname)) {
if(dpname && dpnamelen
&& !dname_subdomain_c(k.qname, dpname))
&& !dname_strict_subdomain_c(k.qname, dpname))
break; /* no synth nxdomain above the stub */
dname_remove_label(&k.qname, &k.qname_len);
h = query_info_hash(&k, flags);
+66 -7
View File
@@ -50,6 +50,7 @@
#include "util/regional.h"
#include "util/alloc.h"
#include "util/net_help.h"
#include "validator/val_utils.h"
void
rrset_markdel(void* key)
@@ -126,7 +127,8 @@ rrset_cache_touch(struct rrset_cache* r, struct ub_packed_rrset_key* key,
/** see if rrset needs to be updated in the cache */
static int
need_to_update_rrset(void* nd, void* cd, time_t timenow, int equal, int ns)
need_to_update_rrset(void* nd, void* cd, time_t timenow, int equal, int ns,
int a_aaaa)
{
struct packed_rrset_data* newd = (struct packed_rrset_data*)nd;
struct packed_rrset_data* cached = (struct packed_rrset_data*)cd;
@@ -149,6 +151,20 @@ need_to_update_rrset(void* nd, void* cd, time_t timenow, int equal, int ns)
if(equal && !TTL_IS_EXPIRED(cached->ttl, timenow) &&
cached->security == sec_status_bogus)
return 0;
/* ghost-domain: never let an NS overwrite extend lifetime
* past the entry it replaces, regardless of trust. */
/* Also for A/AAAA and it is glue. */
if((ns ||
(a_aaaa && cached->trust==rrset_trust_add_noAA))
&& !TTL_IS_EXPIRED(cached->ttl, timenow) &&
newd->ttl > cached->ttl) {
size_t i;
if(a_aaaa) newd->trust=rrset_trust_add_noAA;
newd->ttl = cached->ttl;
for(i=0; i<(newd->count+newd->rrsig_count); i++)
if(newd->rr_ttl[i] > newd->ttl)
newd->rr_ttl[i] = newd->ttl;
}
return 1;
}
/* o item in cache has expired */
@@ -199,6 +215,13 @@ rrset_cache_update(struct rrset_cache* r, struct rrset_ref* ref,
int equal = 0;
log_assert(ref->id != 0 && k->id != 0);
log_assert(k->rk.dname != NULL);
if((k->rk.flags&PACKED_RRSET_0TTL_GRACE) !=0) {
log_nametypeclass(VERB_ALGO, "rrset store of PACKED_RRSET_0TTL_GRACE rrset skipped", k->rk.dname, rrset_type, ntohs(k->rk.rrset_class));
ub_packed_rrset_parsedelete(k, alloc);
return 0; /* Do not store 0TTL items after apply of
the grace ttl amount.
This means the ref was not changed by the call. */
}
/* looks up item with a readlock - no editing! */
if((e=slabhash_lookup(&r->table, h, k, 0)) != 0) {
/* return id and key as they will be used in the cache
@@ -213,7 +236,8 @@ rrset_cache_update(struct rrset_cache* r, struct rrset_ref* ref,
equal = rrsetdata_equal((struct packed_rrset_data*)k->entry.
data, (struct packed_rrset_data*)e->data);
if(!need_to_update_rrset(k->entry.data, e->data, timenow,
equal, (rrset_type==LDNS_RR_TYPE_NS))) {
equal, (rrset_type==LDNS_RR_TYPE_NS),
(rrset_type==LDNS_RR_TYPE_A || rrset_type==LDNS_RR_TYPE_AAAA))) {
/* cache is superior, return that value */
lock_rw_unlock(&e->lock);
ub_packed_rrset_parsedelete(k, alloc);
@@ -245,12 +269,45 @@ rrset_cache_update(struct rrset_cache* r, struct rrset_ref* ref,
return 0;
}
/** See if the name is a within signer authority */
static int
dname_subdomain_rrsig_signers(uint8_t* dname,
struct ub_packed_rrset_key* rrset)
{
struct packed_rrset_data* d = (struct packed_rrset_data*)
rrset->entry.data;
size_t i;
if(!d || !d->rrsig_count)
return 0;
for(i=0; i<d->rrsig_count; i++) {
uint8_t* sname = NULL;
size_t slen = 0;
rrsig_get_signer(d->rr_data[d->count+i], d->rr_len[d->count+i],
&sname, &slen);
if(!sname || !slen)
return 0; /* malformed */
if(!dname_subdomain_c(dname, sname))
return 0; /* not a subdomain */
}
return 1;
}
void rrset_cache_update_wildcard(struct rrset_cache* rrset_cache,
struct ub_packed_rrset_key* rrset, uint8_t* ce, size_t ce_len,
struct alloc_cache* alloc, time_t timenow)
{
struct rrset_ref ref;
uint8_t wc_dname[LDNS_MAX_DOMAINLEN+3];
uint8_t* new_dname;
size_t new_dname_len;
/* See if the RRSIG signer name allows this wildcard,
* the new rrset should fall within the zone of the RRSIG signer(s). */
if(!dname_subdomain_rrsig_signers(ce, rrset)) {
verbose(VERB_ALGO, "wildcard canonical parent outside signer authority");
return;
}
rrset = packed_rrset_copy_alloc(rrset, alloc, timenow);
if(!rrset) {
log_err("malloc failure in rrset_cache_update_wildcard");
@@ -262,14 +319,16 @@ void rrset_cache_update_wildcard(struct rrset_cache* rrset_cache,
wc_dname[1] = (uint8_t)'*';
memmove(wc_dname+2, ce, ce_len);
free(rrset->rk.dname);
rrset->rk.dname_len = ce_len + 2;
rrset->rk.dname = (uint8_t*)memdup(wc_dname, rrset->rk.dname_len);
if(!rrset->rk.dname) {
alloc_special_release(alloc, rrset);
new_dname_len = ce_len + 2;
new_dname = (uint8_t*)memdup(wc_dname, new_dname_len);
if(!new_dname) {
ub_packed_rrset_parsedelete(rrset, alloc);
log_err("memdup failure in rrset_cache_update_wildcard");
return;
}
free(rrset->rk.dname);
rrset->rk.dname = new_dname;
rrset->rk.dname_len = new_dname_len;
rrset->entry.hash = rrset_key_hash(&rrset->rk);
ref.key = rrset;
+186 -82
View File
@@ -42,7 +42,6 @@
#ifdef HAVE_SYS_TYPES_H
# include <sys/types.h>
#endif
#include <sys/time.h>
#include <limits.h>
#ifdef USE_TCP_FASTOPEN
#include <netinet/tcp.h>
@@ -1126,7 +1125,7 @@ make_sock_port(int stype, const char* ifname, int port,
int use_systemd, int dscp, struct unbound_socket* ub_sock,
const char* additional)
{
char* s = strchr(ifname, '@');
const char* s = strchr(ifname, '@');
if(s) {
/* override port with ifspec@port */
int port;
@@ -1342,13 +1341,33 @@ ports_create_if(const char* ifname, int do_auto, int do_udp, int do_tcp,
if((is_doq) && !(is_https || is_ssl)) do_tcp = 0;
if(do_auto) {
enum listen_type auto_port_type;
ub_sock = calloc(1, sizeof(struct unbound_socket));
if(!ub_sock)
return 0;
if(is_dnscrypt) {
auto_port_type = listen_type_udpancil_dnscrypt;
add = "udpancil_dnscrypt";
} else if(is_doq) {
auto_port_type = listen_type_doq;
add = "doq";
if(if_listens_on(ifname, port, 53, NULL)) {
log_err("DNS over QUIC is strictly not "
"allowed on port 53 as per RFC 9250. "
"Port 53 is for DNS datagrams. Error "
"for interface '%s'.", ifname);
free(ub_sock->addr);
free(ub_sock);
return 0;
}
} else {
auto_port_type = listen_type_udpancil;
add = "udpancil";
}
if((s = make_sock_port(SOCK_DGRAM, ifname, port, hints, 1,
&noip6, rcv, snd, reuseport, transparent,
tcp_mss, nodelay, freebind, use_systemd, dscp, ub_sock,
(is_dnscrypt?"udpancil_dnscrypt":"udpancil"))) == -1) {
add)) == -1) {
free(ub_sock->addr);
free(ub_sock);
if(noip6) {
@@ -1367,9 +1386,7 @@ ports_create_if(const char* ifname, int do_auto, int do_udp, int do_tcp,
if (sock_queue_timeout && !set_recvtimestamp(s)) {
log_warn("socket timestamping is not available");
}
if(!port_insert(list, s, is_dnscrypt
?listen_type_udpancil_dnscrypt:listen_type_udpancil,
is_pp2, ub_sock)) {
if(!port_insert(list, s, auto_port_type, is_pp2, ub_sock)) {
sock_close(s);
free(ub_sock->addr);
free(ub_sock);
@@ -2167,7 +2184,8 @@ void tcp_req_info_clear(struct tcp_req_info* req)
open = req->open_req_list;
while(open) {
nopen = open->next;
mesh_state_remove_reply(open->mesh, open->mesh_state, req->cp);
mesh_state_remove_reply(open->mesh, open->mesh_state, req->cp,
NULL, NULL);
free(open);
open = nopen;
}
@@ -3399,14 +3417,13 @@ doq_table_delete(struct doq_table* table)
}
struct doq_timer*
doq_timer_find_time(struct doq_table* table, struct timeval* tv)
doq_timer_find_time(struct doq_table* table, ngtcp2_tstamp ts)
{
struct doq_timer key;
struct rbnode_type* node;
log_assert(table != NULL);
memset(&key, 0, sizeof(key));
key.time.tv_sec = tv->tv_sec;
key.time.tv_usec = tv->tv_usec;
key.time_mono = ts;
node = rbtree_search(table->timer_tree, &key);
if(node)
return (struct doq_timer*)node->key;
@@ -3454,7 +3471,7 @@ doq_timer_list_remove(struct doq_table* table, struct doq_timer* timer)
if(!timer->timer_in_list)
return;
/* The item in the rbtree has the list start and end. */
rb_timer = doq_timer_find_time(table, &timer->time);
rb_timer = doq_timer_find_time(table, timer->time_mono);
if(rb_timer) {
if(timer->setlist_prev)
timer->setlist_prev->setlist_next = timer->setlist_next;
@@ -3500,7 +3517,8 @@ doq_timer_unset(struct doq_table* table, struct doq_timer* timer)
}
void doq_timer_set(struct doq_table* table, struct doq_timer* timer,
struct doq_server_socket* worker_doq_socket, struct timeval* tv)
struct doq_server_socket* worker_doq_socket, struct timeval* tv,
ngtcp2_tstamp ts)
{
struct doq_timer* rb_timer;
if(verbosity >= VERB_ALGO && timer->conn) {
@@ -3514,14 +3532,14 @@ void doq_timer_set(struct doq_table* table, struct doq_timer* timer,
(int)rel.tv_sec, (int)rel.tv_usec);
}
if(timer->timer_in_tree || timer->timer_in_list) {
if(timer->time.tv_sec == tv->tv_sec &&
timer->time.tv_usec == tv->tv_usec)
if(timer->time_mono == ts)
return; /* already set on that time */
doq_timer_unset(table, timer);
}
timer->time.tv_sec = tv->tv_sec;
timer->time.tv_usec = tv->tv_usec;
rb_timer = doq_timer_find_time(table, tv);
timer->time_real.tv_sec = tv->tv_sec;
timer->time_real.tv_usec = tv->tv_usec;
timer->time_mono = ts;
rb_timer = doq_timer_find_time(table, ts);
if(rb_timer) {
/* There is a timeout already with this value. Timer is
* added to the setlist. */
@@ -3597,15 +3615,29 @@ doq_conn_create(struct comm_point* c, struct doq_pkt_addr* paddr,
return conn;
}
/** The arguments for doq stream tree del. */
struct doq_stream_tree_del_args {
/** The doq table. */
struct doq_table* table;
/** The doq connection for the stream. */
struct doq_conn* conn;
};
/** delete stream tree node */
static void
stream_tree_del(rbnode_type* node, void* arg)
{
struct doq_table* table = (struct doq_table*)arg;
struct doq_stream_tree_del_args* args = (struct doq_stream_tree_del_args*)arg;
struct doq_table* table = args->table;
struct doq_stream* stream;
if(!node)
return;
stream = (struct doq_stream*)node;
if(stream->mesh_state) {
mesh_state_remove_reply(stream->mesh, stream->mesh_state,
args->conn->doq_socket->cp, NULL, stream);
stream->mesh_state = NULL;
}
if(stream->in)
doq_table_quic_size_subtract(table, stream->inlen);
if(stream->out)
@@ -3625,9 +3657,14 @@ doq_conn_delete(struct doq_conn* conn, struct doq_table* table)
lock_rw_unlock(&conn->table->conid_lock);
/* Remove the app data from ngtcp2 before SSL_free of conn->ssl,
* because the ngtcp2 conn is deleted. */
SSL_set_app_data(conn->ssl, NULL);
if(conn->ssl)
SSL_set_app_data(conn->ssl, NULL);
if(conn->stream_tree.count != 0) {
traverse_postorder(&conn->stream_tree, stream_tree_del, table);
struct doq_stream_tree_del_args args;
memset(&args, 0, sizeof(args));
args.table = table;
args.conn = conn;
traverse_postorder(&conn->stream_tree, stream_tree_del, &args);
}
free(conn->key.dcid);
SSL_free(conn->ssl);
@@ -3700,13 +3737,9 @@ int doq_timer_cmp(const void* key1, const void* key2)
{
struct doq_timer* e = (struct doq_timer*)key1;
struct doq_timer* f = (struct doq_timer*)key2;
if(e->time.tv_sec < f->time.tv_sec)
if(e->time_mono < f->time_mono)
return -1;
if(e->time.tv_sec > f->time.tv_sec)
return 1;
if(e->time.tv_usec < f->time.tv_usec)
return -1;
if(e->time.tv_usec > f->time.tv_usec)
if(e->time_mono > f->time_mono)
return 1;
return 0;
}
@@ -3940,6 +3973,11 @@ doq_stream_close(struct doq_conn* conn, struct doq_stream* stream,
if(stream->is_closed)
return 1;
stream->is_closed = 1;
if(stream->mesh_state) {
mesh_state_remove_reply(stream->mesh, stream->mesh_state,
conn->doq_socket->cp, NULL, stream);
stream->mesh_state = NULL;
}
doq_stream_off_write_list(conn, stream);
if(send_shutdown) {
verbose(VERB_ALGO, "doq: shutdown stream_id %d with app_error_code %d",
@@ -3969,7 +4007,8 @@ doq_stream_close(struct doq_conn* conn, struct doq_stream* stream,
/** doq stream pick up answer data from buffer */
static int
doq_stream_pickup_answer(struct doq_stream* stream, struct sldns_buffer* buf)
doq_stream_pickup_answer(struct doq_conn* conn, struct doq_stream* stream,
struct sldns_buffer* buf)
{
stream->is_answer_available = 1;
if(stream->out) {
@@ -3979,6 +4018,11 @@ doq_stream_pickup_answer(struct doq_stream* stream, struct sldns_buffer* buf)
}
stream->nwrite = 0;
stream->outlen = sldns_buffer_limit(buf);
if(!doq_table_quic_size_available(conn->doq_socket->table,
conn->doq_socket->cfg, stream->outlen)) {
verbose(VERB_ALGO, "doq stream: no space for reply length");
return 0;
}
/* For quic the output bytes have to stay allocated and available,
* for potential resends, until the remote end has acknowledged them.
* This includes the tcplen start uint16_t, in outlen_wire. */
@@ -4005,24 +4049,56 @@ doq_stream_send_reply(struct doq_conn* conn, struct doq_stream* stream,
if(stream->out)
doq_table_quic_size_subtract(conn->doq_socket->table,
stream->outlen);
if(!doq_stream_pickup_answer(stream, buf))
if(!doq_stream_pickup_answer(conn, stream, buf))
return 0;
doq_table_quic_size_add(conn->doq_socket->table, stream->outlen);
doq_stream_on_write_list(conn, stream);
doq_conn_write_enable(conn);
return 1;
}
#endif /* HAVE_NGTCP2 */
void
doq_stream_add_meshstate(struct doq_stream* stream,
struct mesh_area* mesh, struct mesh_state* m)
{
#ifdef HAVE_NGTCP2
stream->mesh = mesh;
stream->mesh_state = m;
#else
(void)stream; (void)mesh; (void)m;
#endif
}
void
doq_stream_remove_mesh_state(struct doq_stream* stream)
{
#ifdef HAVE_NGTCP2
if(!stream)
return;
stream->mesh_state = NULL;
#else
(void)stream;
#endif
}
#ifdef HAVE_NGTCP2
/** doq stream data length has completed, allocations can be done. False on
* allocation failure. */
static int
doq_stream_datalen_complete(struct doq_stream* stream, struct doq_table* table)
doq_stream_datalen_complete(struct doq_conn* conn, struct doq_stream* stream,
struct doq_table* table)
{
if(stream->inlen > 1024*1024) {
log_err("doq stream in length too large %d",
(int)stream->inlen);
return 0;
}
if(!doq_table_quic_size_available(table, conn->doq_socket->cfg,
stream->inlen)) {
verbose(VERB_ALGO, "doq stream: no space for query length");
return 0;
}
stream->in = calloc(1, stream->inlen);
if(!stream->in) {
log_err("doq could not read stream, calloc failed: "
@@ -4067,6 +4143,7 @@ doq_stream_data_complete(struct doq_conn* conn, struct doq_stream* stream)
return 0;
}
c->repinfo.doq_streamid = stream->stream_id;
c->repinfo.doq_stream = stream;
conn->doq_socket->current_conn = conn;
fptr_ok(fptr_whitelist_comm_point(c->callback));
if( (*c->callback)(c, c->cb_arg, NETEVENT_NOERROR, &c->repinfo)) {
@@ -4083,8 +4160,9 @@ doq_stream_data_complete(struct doq_conn* conn, struct doq_stream* stream)
/** doq receive data for a stream, more bytes of the incoming data */
static int
doq_stream_recv_data(struct doq_stream* stream, const uint8_t* data,
size_t datalen, int* recv_done, struct doq_table* table)
doq_stream_recv_data(struct doq_conn* conn, struct doq_stream* stream,
const uint8_t* data, size_t datalen, int* recv_done,
struct doq_table* table)
{
int got_data = 0;
/* read the tcplength uint16_t at the start */
@@ -4105,7 +4183,7 @@ doq_stream_recv_data(struct doq_stream* stream, const uint8_t* data,
if(stream->nread == 2) {
/* the initial length value is completed */
stream->inlen = ntohs(tcplen);
if(!doq_stream_datalen_complete(stream, table))
if(!doq_stream_datalen_complete(conn, stream, table))
return 0;
} else {
/* store for later */
@@ -4254,12 +4332,11 @@ doq_submit_new_token(struct doq_conn* conn)
ngtcp2_ssize tokenlen;
int ret;
const ngtcp2_path* path = ngtcp2_conn_get_path(conn->conn);
ngtcp2_tstamp ts = doq_get_timestamp_nanosec();
tokenlen = ngtcp2_crypto_generate_regular_token(token,
conn->doq_socket->static_secret,
conn->doq_socket->static_secret_len, path->remote.addr,
path->remote.addrlen, ts);
path->remote.addrlen, doq_get_timestamp_nanosec());
if(tokenlen < 0) {
log_err("doq ngtcp2_crypto_generate_regular_token failed");
return 1;
@@ -4322,8 +4399,7 @@ doq_stream_open_cb(ngtcp2_conn* ATTR_UNUSED(conn), int64_t stream_id,
verbose(VERB_ALGO, "doq: stream with this id already exists");
return 0;
}
if(stream_id != 0 && stream_id != 4 && /* allow one stream on a new connection */
!doq_table_quic_size_available(doq_conn->doq_socket->table,
if(!doq_table_quic_size_available(doq_conn->doq_socket->table,
doq_conn->doq_socket->cfg, sizeof(*stream)
+ 100 /* estimated query in */
+ 512 /* estimated response out */
@@ -4381,8 +4457,8 @@ doq_recv_stream_data_cb(ngtcp2_conn* ATTR_UNUSED(conn), uint32_t flags,
return 0;
}
if(datalen != 0) {
if(!doq_stream_recv_data(stream, data, datalen, &recv_done,
doq_conn->doq_socket->table))
if(!doq_stream_recv_data(doq_conn, stream, data, datalen,
&recv_done, doq_conn->doq_socket->table))
return NGTCP2_ERR_CALLBACK_FAILURE;
}
if((flags&NGTCP2_STREAM_DATA_FLAG_FIN)!=0) {
@@ -4451,6 +4527,29 @@ doq_stream_reset_cb(ngtcp2_conn* ATTR_UNUSED(conn), int64_t stream_id,
return 0;
}
/** ngtcp2 extend_max_stream_data function */
int doq_extend_max_stream_data_cb(ngtcp2_conn* ATTR_UNUSED(conn),
int64_t stream_id, uint64_t max_data, void* user_data,
void* ATTR_UNUSED(stream_user_data))
{
struct doq_conn* doq_conn = (struct doq_conn*)user_data;
struct doq_stream* stream;
verbose(VERB_ALGO, "doq extend_max_stream_data stream id %d "
"max_data %d ", (int)stream_id, (int)max_data);
if(max_data == 0)
return 0;
stream = doq_stream_find(doq_conn, stream_id);
if(!stream) {
verbose(VERB_ALGO, "doq: unknown stream %d", (int)stream_id);
return 0;
}
if(!stream->is_answer_available)
return 0;
doq_stream_on_write_list(doq_conn, stream);
doq_conn_write_enable(doq_conn);
return 0;
}
/** ngtcp2 acked_stream_data_offset callback function */
static int
doq_acked_stream_data_offset_cb(ngtcp2_conn* ATTR_UNUSED(conn),
@@ -4771,7 +4870,7 @@ doq_ssl_server_setup(SSL_CTX* ctx, struct doq_conn* conn)
SSL_set_app_data(ssl, conn);
#endif
SSL_set_accept_state(ssl);
#ifdef USE_NGTCP2_CRYPTO_OSSL
#ifdef HAVE_SSL_SET_QUIC_TLS_EARLY_DATA_ENABLED
SSL_set_quic_tls_early_data_enabled(ssl, 1);
#else
SSL_set_quic_early_data_enabled(ssl, 1);
@@ -4825,6 +4924,7 @@ doq_conn_setup(struct doq_conn* conn, uint8_t* scid, size_t scidlen,
callbacks.stream_open = doq_stream_open_cb;
callbacks.stream_close = doq_stream_close_cb;
callbacks.stream_reset = doq_stream_reset_cb;
callbacks.extend_max_stream_data = doq_extend_max_stream_data_cb;
callbacks.acked_stream_data_offset = doq_acked_stream_data_offset_cb;
callbacks.recv_stream_data = doq_recv_stream_data_cb;
@@ -4879,6 +4979,7 @@ doq_conn_setup(struct doq_conn* conn, uint8_t* scid, size_t scidlen,
rv = ngtcp2_conn_server_new(&conn->conn, &scid_cid, &sv_scid, &path,
conn->version, &callbacks, &settings, &params, NULL, conn);
if(rv != 0) {
conn->conn = NULL;
lock_rw_unlock(&conn->table->conid_lock);
log_err("ngtcp2_conn_server_new failed: %s",
ngtcp2_strerror(rv));
@@ -5101,23 +5202,30 @@ doq_conn_clear_conids(struct doq_conn* conn)
ngtcp2_tstamp doq_get_timestamp_nanosec(void)
{
#ifdef CLOCK_REALTIME
struct timespec tp;
memset(&tp, 0, sizeof(tp));
/* Get a nanosecond time, that can be compared with the event base. */
if(clock_gettime(CLOCK_REALTIME, &tp) == -1) {
log_err("clock_gettime failed: %s", strerror(errno));
#ifdef CLOCK_BOOTTIME
if(clock_gettime(CLOCK_BOOTTIME, &tp) == -1) {
#endif
if(clock_gettime(CLOCK_MONOTONIC, &tp) == -1) {
log_err("clock_gettime failed: %s", strerror(errno));
}
#ifdef CLOCK_BOOTTIME
}
#endif
return ((uint64_t)tp.tv_sec)*((uint64_t)1000000000) +
((uint64_t)tp.tv_nsec);
#else
}
static struct timeval doq_get_timevalue(void)
{
struct timeval tv;
memset(&tv, 0, sizeof(tv));
if(gettimeofday(&tv, NULL) < 0) {
log_err("gettimeofday failed: %s", strerror(errno));
memset(&tv, 0, sizeof(tv));
}
return ((uint64_t)tv.tv_sec)*((uint64_t)1000000000) +
((uint64_t)tv.tv_usec)*((uint64_t)1000);
#endif /* CLOCK_REALTIME */
return tv;
}
/** doq start the closing period for the connection. */
@@ -5240,18 +5348,17 @@ doq_conn_recv(struct comm_point* c, struct doq_pkt_addr* paddr,
int* err_drop)
{
int ret;
ngtcp2_tstamp ts;
struct ngtcp2_path path;
memset(&path, 0, sizeof(path));
path.remote.addr = (struct sockaddr*)&paddr->addr;
path.remote.addrlen = paddr->addrlen;
path.local.addr = (struct sockaddr*)&paddr->localaddr;
path.local.addrlen = paddr->localaddrlen;
ts = doq_get_timestamp_nanosec();
ret = ngtcp2_conn_read_pkt(conn->conn, &path, pi,
sldns_buffer_begin(c->doq_socket->pkt_buf),
sldns_buffer_limit(c->doq_socket->pkt_buf), ts);
sldns_buffer_limit(c->doq_socket->pkt_buf),
doq_get_timestamp_nanosec());
if(ret != 0) {
if(err_retry)
*err_retry = 0;
@@ -5339,7 +5446,6 @@ doq_conn_write_streams(struct comm_point* c, struct doq_conn* conn,
{
struct doq_stream* stream = conn->stream_write_first;
ngtcp2_path_storage ps;
ngtcp2_tstamp ts = doq_get_timestamp_nanosec();
size_t num_packets = 0, max_packets = 65535;
ngtcp2_path_storage_zero(&ps);
@@ -5392,7 +5498,8 @@ doq_conn_write_streams(struct comm_point* c, struct doq_conn* conn,
ret = ngtcp2_conn_writev_stream(conn->conn, &ps.path, &pi,
sldns_buffer_begin(c->doq_socket->pkt_buf),
sldns_buffer_remaining(c->doq_socket->pkt_buf),
&ndatalen, flags, stream_id, datav, datav_count, ts);
&ndatalen, flags, stream_id, datav, datav_count,
doq_get_timestamp_nanosec());
if(ret < 0) {
if(ret == NGTCP2_ERR_WRITE_MORE) {
verbose(VERB_ALGO, "doq: write more, ndatalen %d", (int)ndatalen);
@@ -5407,26 +5514,20 @@ doq_conn_write_streams(struct comm_point* c, struct doq_conn* conn,
continue;
} else if(ret == NGTCP2_ERR_STREAM_DATA_BLOCKED) {
verbose(VERB_ALGO, "doq: ngtcp2_conn_writev_stream returned NGTCP2_ERR_STREAM_DATA_BLOCKED");
#ifdef HAVE_NGTCP2_CCERR_DEFAULT
ngtcp2_ccerr_set_application_error(
&conn->ccerr, -1, NULL, 0);
#else
ngtcp2_connection_close_error_set_application_error(&conn->last_error, -1, NULL, 0);
#endif
if(err_drop)
*err_drop = 0;
if(!doq_conn_close_error(c, conn)) {
if(err_drop)
*err_drop = 1;
if(stream) {
doq_stream_off_write_list(conn, stream);
stream = stream->write_next;
continue;
} else {
break;
}
return 0;
} else if(ret == NGTCP2_ERR_STREAM_SHUT_WR) {
verbose(VERB_ALGO, "doq: ngtcp2_conn_writev_stream returned NGTCP2_ERR_STREAM_SHUT_WR");
#ifdef HAVE_NGTCP2_CCERR_DEFAULT
ngtcp2_ccerr_set_application_error(
&conn->ccerr, -1, NULL, 0);
&conn->ccerr, DOQ_APP_ERROR_CODE, NULL, 0);
#else
ngtcp2_connection_close_error_set_application_error(&conn->last_error, -1, NULL, 0);
ngtcp2_connection_close_error_set_application_error(&conn->last_error, DOQ_APP_ERROR_CODE, NULL, 0);
#endif
if(err_drop)
*err_drop = 0;
@@ -5464,7 +5565,8 @@ doq_conn_write_streams(struct comm_point* c, struct doq_conn* conn,
if(ret == 0) {
/* congestion limited */
doq_conn_write_disable(conn);
ngtcp2_conn_update_pkt_tx_time(conn->conn, ts);
ngtcp2_conn_update_pkt_tx_time(conn->conn,
doq_get_timestamp_nanosec());
return 1;
}
sldns_buffer_set_position(c->doq_socket->pkt_buf, ret);
@@ -5478,7 +5580,7 @@ doq_conn_write_streams(struct comm_point* c, struct doq_conn* conn,
if(stream)
stream = stream->write_next;
}
ngtcp2_conn_update_pkt_tx_time(conn->conn, ts);
ngtcp2_conn_update_pkt_tx_time(conn->conn, doq_get_timestamp_nanosec());
return 1;
}
@@ -5555,32 +5657,35 @@ doq_table_pop_first(struct doq_table* table)
}
int
doq_conn_check_timer(struct doq_conn* conn, struct timeval* tv)
doq_conn_check_timer(struct doq_conn* conn, struct timeval* tv, ngtcp2_tstamp* ts)
{
ngtcp2_tstamp expiry = ngtcp2_conn_get_expiry(conn->conn);
ngtcp2_tstamp now = doq_get_timestamp_nanosec();
ngtcp2_tstamp doq_expiry = ngtcp2_conn_get_expiry(conn->conn);
ngtcp2_tstamp doq_now = doq_get_timestamp_nanosec();
ngtcp2_tstamp t;
struct timeval now = doq_get_timevalue();
if(expiry <= now) {
if(doq_expiry <= doq_now || doq_expiry == UINT64_MAX) {
/* UINT64_MAX means there is no next expiry. */
/* The timer has already expired, add with zero timeout.
* This should call the callback straight away. Calling it
* from the event callbacks is cleaner than calling it here,
* because then it is always called with the same locks and
* so on. This routine only has the conn.lock. */
t = now;
t = doq_now;
memcpy(tv, &now, sizeof(*tv));
} else {
t = expiry;
t = doq_expiry;
memset(tv, 0, sizeof(*tv));
tv->tv_sec = (doq_expiry - doq_now) / NGTCP2_SECONDS;
tv->tv_usec = ((doq_expiry - doq_now) / NGTCP2_MICROSECONDS)%1000000;
timeval_add(tv, &now);
}
/* convert to timeval */
memset(tv, 0, sizeof(*tv));
tv->tv_sec = t / NGTCP2_SECONDS;
tv->tv_usec = (t / NGTCP2_MICROSECONDS)%1000000;
*ts = t;
/* If we already have a timer, is it the right value? */
if(conn->timer.timer_in_tree || conn->timer.timer_in_list) {
if(conn->timer.time.tv_sec == tv->tv_sec &&
conn->timer.time.tv_usec == tv->tv_usec)
if(conn->timer.time_mono == *ts)
return 0;
}
return 1;
@@ -5601,13 +5706,12 @@ doq_conn_log_line(struct doq_conn* conn, char* s)
int
doq_conn_handle_timeout(struct doq_conn* conn)
{
ngtcp2_tstamp now = doq_get_timestamp_nanosec();
int rv;
if(verbosity >= VERB_ALGO)
doq_conn_log_line(conn, "timeout");
rv = ngtcp2_conn_handle_expiry(conn->conn, now);
rv = ngtcp2_conn_handle_expiry(conn->conn, doq_get_timestamp_nanosec());
if(rv != 0) {
verbose(VERB_ALGO, "ngtcp2_conn_handle_expiry failed: %s",
ngtcp2_strerror(rv));
+29 -8
View File
@@ -61,6 +61,8 @@ struct config_file;
struct addrinfo;
struct sldns_buffer;
struct tcl_list;
struct mesh_area;
struct mesh_state;
/**
* Listening for queries structure.
@@ -538,8 +540,11 @@ void doq_table_delete(struct doq_table* table);
struct doq_timer {
/** The rbnode in the tree sorted by timeout value. Key this struct. */
struct rbnode_type node;
/** The timeout value. Monotonic value used with ngtcp2.
* This time value is used for the tree operations. */
ngtcp2_tstamp time_mono;
/** The timeout value. Absolute time value. */
struct timeval time;
struct timeval time_real;
/** If the timer is in the time tree, with the node. */
int timer_in_tree;
/** If there are more timers with the exact same timeout value,
@@ -689,6 +694,11 @@ struct doq_stream {
uint8_t* out;
/** if the stream is on the write list */
uint8_t on_write_list;
/** The mesh area and mesh state, set when this stream's query was
* dispatched into the mesh; used to detach the reply on stream close */
struct mesh_area* mesh;
/** the mesh state for the query, is nonNULL when there is one. */
struct mesh_state* mesh_state;
/** the prev and next on the write list, if on the list */
struct doq_stream* write_prev, *write_next;
};
@@ -791,7 +801,16 @@ int doq_stream_close(struct doq_conn* conn, struct doq_stream* stream,
/** send reply for a connection */
int doq_stream_send_reply(struct doq_conn* conn, struct doq_stream* stream,
struct sldns_buffer* buf);
#endif /* HAVE_NGTCP2 */
/** add mesh state to doq stream */
void doq_stream_add_meshstate(struct doq_stream* stream,
struct mesh_area* mesh, struct mesh_state* m);
/** remove mesh state from doq stream */
void doq_stream_remove_mesh_state(struct doq_stream* stream);
#ifdef HAVE_NGTCP2
/** the connection has write interest, wants to write packets */
void doq_conn_write_enable(struct doq_conn* conn);
@@ -813,10 +832,12 @@ struct doq_conn* doq_table_pop_first(struct doq_table* table);
* doq check if the timer for the conn needs to be changed.
* @param conn: connection, caller must hold lock on it.
* @param tv: time value, absolute time, returned.
* @param ts: time stamp, absolute time, returned.
* @return true if timer needs to be set to tv, false if no change is needed
* to the timer. The timer is already set to the right time in that case.
*/
int doq_conn_check_timer(struct doq_conn* conn, struct timeval* tv);
int doq_conn_check_timer(struct doq_conn* conn, struct timeval* tv,
ngtcp2_tstamp* ts);
/** doq remove timer from tree */
void doq_timer_tree_remove(struct doq_table* table, struct doq_timer* timer);
@@ -829,11 +850,12 @@ void doq_timer_unset(struct doq_table* table, struct doq_timer* timer);
/** doq set the timer and add it. */
void doq_timer_set(struct doq_table* table, struct doq_timer* timer,
struct doq_server_socket* worker_doq_socket, struct timeval* tv);
struct doq_server_socket* worker_doq_socket, struct timeval* tv,
ngtcp2_tstamp ts);
/** doq find a timeout in the timer tree */
struct doq_timer* doq_timer_find_time(struct doq_table* table,
struct timeval* tv);
ngtcp2_tstamp ts);
/** doq handle timeout for a connection. Pass conn locked. Returns false for
* deletion. */
@@ -851,6 +873,9 @@ int doq_table_quic_size_available(struct doq_table* table,
/** doq get the quic size value */
size_t doq_table_quic_size_get(struct doq_table* table);
/** get a timestamp in nanoseconds */
ngtcp2_tstamp doq_get_timestamp_nanosec(void);
#endif /* HAVE_NGTCP2 */
char* set_ip_dscp(int socket, int addrfamily, int ds);
@@ -866,8 +891,4 @@ void doq_client_event_cb(int fd, short event, void* arg);
/** timer event callback for testcode/doqclient */
void doq_client_timer_cb(int fd, short event, void* arg);
#ifdef HAVE_NGTCP2
/** get a timestamp in nanoseconds */
ngtcp2_tstamp doq_get_timestamp_nanosec(void);
#endif
#endif /* LISTEN_DNSPORT_H */
+56 -11
View File
@@ -386,8 +386,6 @@ new_local_rrset(struct regional* region, struct local_data* node,
log_err("out of memory");
return NULL;
}
rrset->next = node->rrsets;
node->rrsets = rrset;
rrset->rrset = (struct ub_packed_rrset_key*)
regional_alloc_zero(region, sizeof(*rrset->rrset));
if(!rrset->rrset) {
@@ -408,6 +406,8 @@ new_local_rrset(struct regional* region, struct local_data* node,
rrset->rrset->rk.dname_len = node->namelen;
rrset->rrset->rk.type = htons(rrtype);
rrset->rrset->rk.rrset_class = htons(rrclass);
rrset->next = node->rrsets;
node->rrsets = rrset;
return rrset;
}
@@ -431,6 +431,10 @@ rrset_insert_rr(struct regional* region, struct packed_rrset_data* pd,
pd->rr_ttl = regional_alloc(region, sizeof(*pd->rr_ttl)*pd->count);
pd->rr_data = regional_alloc(region, sizeof(*pd->rr_data)*pd->count);
if(!pd->rr_len || !pd->rr_ttl || !pd->rr_data) {
pd->count--;
pd->rr_len = oldlen;
pd->rr_ttl = oldttl;
pd->rr_data = olddata;
log_err("out of memory");
return 0;
}
@@ -446,6 +450,10 @@ rrset_insert_rr(struct regional* region, struct packed_rrset_data* pd,
pd->rr_ttl[0] = ttl;
pd->rr_data[0] = regional_alloc_init(region, rdata, rdata_len);
if(!pd->rr_data[0]) {
pd->count--;
pd->rr_len = oldlen;
pd->rr_ttl = oldttl;
pd->rr_data = olddata;
log_err("out of memory");
return 0;
}
@@ -671,7 +679,9 @@ lz_enter_rr_str(struct local_zones* zones, const char* rr)
z = local_zones_lookup(zones, rr_name, len, labs, rr_class, rr_type, 1);
if(!z) {
lock_rw_unlock(&zones->lock);
fatal_exit("internal error: no zone for rr %s", rr);
log_err("internal error: no zone for rr %s", rr);
free(rr_name);
return 0;
}
lock_rw_wrlock(&z->lock);
lock_rw_unlock(&zones->lock);
@@ -1500,8 +1510,10 @@ find_tag_datas(struct query_info* qinfo, struct config_strlist* list,
return 0; /* out of memory */
qinfo->local_alias->rrset =
regional_alloc_init(temp, r, sizeof(*r));
if(!qinfo->local_alias->rrset)
if(!qinfo->local_alias->rrset) {
qinfo->local_alias = NULL;
return 0; /* out of memory */
}
}
return result;
}
@@ -1567,13 +1579,17 @@ local_data_answer(struct local_zone* z, struct module_env* env,
return 0; /* out of memory */
qinfo->local_alias->rrset = regional_alloc_init(
temp, lr->rrset, sizeof(*lr->rrset));
if(!qinfo->local_alias->rrset)
if(!qinfo->local_alias->rrset) {
qinfo->local_alias = NULL;
return 0; /* out of memory */
}
qinfo->local_alias->rrset->rk.dname = qinfo->qname;
qinfo->local_alias->rrset->rk.dname_len = qinfo->qname_len;
get_cname_target(lr->rrset, &ctarget, &ctargetlen);
if(!ctargetlen)
if(!ctargetlen) {
qinfo->local_alias = NULL;
return 0; /* invalid cname */
}
if(dname_is_wild(ctarget)) {
/* synthesize cname target */
struct packed_rrset_data* d, *lr_d;
@@ -1602,8 +1618,10 @@ local_data_answer(struct local_zone* z, struct module_env* env,
sizeof(struct packed_rrset_data) + sizeof(size_t) +
sizeof(uint8_t*) + sizeof(time_t) + sizeof(uint16_t)
+ newtargetlen);
if(!d)
if(!d) {
qinfo->local_alias = NULL;
return 0; /* out of memory */
}
lr_d = (struct packed_rrset_data*)lr->rrset->entry.data;
qinfo->local_alias->rrset->entry.data = d;
d->ttl = lr_d->rr_ttl[0]; /* RFC6672-like behavior:
@@ -1650,7 +1668,7 @@ local_zone_does_not_cover(struct local_zone* z, struct query_info* qinfo,
struct local_data key;
struct local_data* ld = NULL;
struct local_rrset* lr = NULL;
if(z->type == local_zone_always_transparent || z->type == local_zone_block_a)
if(z->type == local_zone_always_transparent || z->type == local_zone_block_a || z->type == local_zone_block_aaaa)
return 1;
if(z->type != local_zone_transparent
&& z->type != local_zone_typetransparent
@@ -1661,7 +1679,9 @@ local_zone_does_not_cover(struct local_zone* z, struct query_info* qinfo,
key.namelen = qinfo->qname_len;
key.namelabs = labs;
ld = (struct local_data*)rbtree_search(&z->data, &key.node);
if(z->type == local_zone_transparent || z->type == local_zone_inform)
if(z->type == local_zone_transparent || z->type == local_zone_inform
|| z->type == local_zone_block_a_wdata
|| z->type == local_zone_block_aaaa_wdata)
return (ld == NULL);
if(ld)
lr = local_data_find_type(ld, qinfo->qtype, 1);
@@ -1727,7 +1747,8 @@ local_zones_zone_answer(struct local_zone* z, struct module_env* env,
|| lz_type == local_zone_always_transparent) {
/* no NODATA or NXDOMAINS for this zone type */
return 0;
} else if(lz_type == local_zone_block_a) {
} else if(lz_type == local_zone_block_a ||
lz_type == local_zone_block_a_wdata) {
/* Return NODATA for all A queries */
if(qinfo->qtype == LDNS_RR_TYPE_A) {
local_error_encode(qinfo, env, edns, repinfo, buf, temp,
@@ -1736,6 +1757,17 @@ local_zones_zone_answer(struct local_zone* z, struct module_env* env,
return 1;
}
return 0;
} else if(lz_type == local_zone_block_aaaa ||
lz_type == local_zone_block_aaaa_wdata) {
/* Return NODATA for all AAAA queries */
if(qinfo->qtype == LDNS_RR_TYPE_AAAA) {
local_error_encode(qinfo, env, edns, repinfo, buf, temp,
LDNS_RCODE_NOERROR, (LDNS_RCODE_NOERROR|BIT_AA),
LDNS_EDE_NONE, NULL);
return 1;
}
return 0;
} else if(lz_type == local_zone_always_null) {
/* 0.0.0.0 or ::0 or noerror/nodata for this zone type,
@@ -1904,7 +1936,10 @@ local_zones_answer(struct local_zones* zones, struct module_env* env,
lzt == local_zone_typetransparent ||
lzt == local_zone_inform ||
lzt == local_zone_always_transparent ||
lzt == local_zone_block_a) &&
lzt == local_zone_block_a ||
lzt == local_zone_block_aaaa ||
lzt == local_zone_block_a_wdata ||
lzt == local_zone_block_aaaa_wdata) &&
local_zone_does_not_cover(z, qinfo, labs)) {
lock_rw_unlock(&z->lock);
z = NULL;
@@ -1953,6 +1988,7 @@ local_zones_answer(struct local_zones* zones, struct module_env* env,
if(lzt != local_zone_always_refuse
&& lzt != local_zone_always_transparent
&& lzt != local_zone_block_a
&& lzt != local_zone_block_aaaa
&& lzt != local_zone_always_nxdomain
&& lzt != local_zone_always_nodata
&& lzt != local_zone_always_deny
@@ -1984,6 +2020,9 @@ const char* local_zone_type2str(enum localzone_type t)
case local_zone_inform_redirect: return "inform_redirect";
case local_zone_always_transparent: return "always_transparent";
case local_zone_block_a: return "block_a";
case local_zone_block_aaaa: return "block_aaaa";
case local_zone_block_a_wdata: return "block_a_wdata";
case local_zone_block_aaaa_wdata: return "block_aaaa_wdata";
case local_zone_always_refuse: return "always_refuse";
case local_zone_always_nxdomain: return "always_nxdomain";
case local_zone_always_nodata: return "always_nodata";
@@ -2020,6 +2059,12 @@ int local_zone_str2type(const char* type, enum localzone_type* t)
*t = local_zone_always_transparent;
else if(strcmp(type, "block_a") == 0)
*t = local_zone_block_a;
else if(strcmp(type, "block_aaaa") == 0)
*t = local_zone_block_aaaa;
else if(strcmp(type, "block_a_wdata") == 0)
*t = local_zone_block_a_wdata;
else if(strcmp(type, "block_aaaa_wdata") == 0)
*t = local_zone_block_aaaa_wdata;
else if(strcmp(type, "always_refuse") == 0)
*t = local_zone_always_refuse;
else if(strcmp(type, "always_nxdomain") == 0)
+7 -1
View File
@@ -93,6 +93,12 @@ enum localzone_type {
local_zone_always_transparent,
/** resolve normally, even when there is local data but return NODATA for A queries */
local_zone_block_a,
/** resolve normally, even when there is local data, but return NODATA for AAAA queries */
local_zone_block_aaaa,
/** resolve normally, use local data, else return NODATA for A queries */
local_zone_block_a_wdata,
/** resolve normally, use local data, else return NODATA for AAAA queries */
local_zone_block_aaaa_wdata,
/** answer with error, even when there is local data */
local_zone_always_refuse,
/** answer with nxdomain, even when there is local data */
@@ -573,7 +579,7 @@ enum respip_action {
respip_always_nxdomain = local_zone_always_nxdomain,
/** answer with nodata response */
respip_always_nodata = local_zone_always_nodata,
/** answer with nodata response */
/** drop query */
respip_always_deny = local_zone_always_deny,
/** RPZ: truncate answer in order to force switch to tcp */
respip_truncate = local_zone_truncate,
+198 -73
View File
@@ -297,12 +297,14 @@ int mesh_make_new_space(struct mesh_area* mesh, sldns_buffer* qbuf)
if(mesh->num_reply_states < mesh->max_reply_states)
return 1;
/* try to kick out a jostle-list item */
if(m && m->reply_list && m->list_select == mesh_jostle_list) {
if(m && m->list_select == mesh_jostle_list) {
/* how old is it? */
struct timeval age;
timeval_subtract(&age, mesh->env->now_tv,
&m->reply_list->start_time);
if(timeval_smaller(&mesh->jostle_max, &age)) {
if(m->has_first_reply_time)
timeval_subtract(&age, mesh->env->now_tv,
&m->first_reply_time);
if(!m->has_first_reply_time ||
timeval_smaller(&mesh->jostle_max, &age)) {
/* its a goner */
log_nametypeclass(VERB_ALGO, "query jostled out to "
"make space for a new one",
@@ -422,6 +424,44 @@ mesh_serve_expired_init(struct mesh_state* mstate, int timeout)
return 1;
}
/** remove a reply without accounting, rollback the add reply. */
static void
mesh_remove_reply_without_accounting(struct mesh_state* s,
struct mesh_reply* todel)
{
struct mesh_reply* r, *prev = NULL;
for(r = s->reply_list; r; r = r->next) {
if(r == todel) {
if(prev)
prev->next = r->next;
else s->reply_list = r->next;
r->next = NULL;
/* todel is allocated in region */
return;
}
prev = r;
}
}
/** remove a callback without accounting, rollback the add reply. */
static void
mesh_remove_callback_without_accounting(struct mesh_state* s,
struct mesh_cb* todel)
{
struct mesh_cb* r, *prev = NULL;
for(r = s->cb_list; r; r = r->next) {
if(r == todel) {
if(prev)
prev->next = r->next;
else s->cb_list = r->next;
r->next = NULL;
/* todel is allocated in region */
return;
}
prev = r;
}
}
void mesh_new_client(struct mesh_area* mesh, struct query_info* qinfo,
struct respip_client_info* cinfo, uint16_t qflags,
struct edns_data* edns, struct comm_reply* rep, uint16_t qid,
@@ -431,7 +471,8 @@ void mesh_new_client(struct mesh_area* mesh, struct query_info* qinfo,
int unique = unique_mesh_state(edns->opt_list_in, mesh->env);
int was_detached = 0;
int was_noreply = 0;
int added = 0;
int added = 0, added_reply_without_accounting = 0, added_tcp = 0;
struct mesh_reply* repadded = NULL;
int timeout = mesh->env->cfg->serve_expired?
mesh->env->cfg->serve_expired_client_timeout:0;
struct sldns_buffer* r_buffer = rep->c->buffer;
@@ -465,6 +506,8 @@ void mesh_new_client(struct mesh_area* mesh, struct query_info* qinfo,
"incoming query.");
if(rep->c->use_h2)
http2_stream_remove_mesh_state(rep->c->h2_stream);
else if(rep->c->type == comm_doq && rep->doq_stream)
doq_stream_remove_mesh_state(rep->doq_stream);
comm_point_drop_reply(rep);
mesh->stats_dropped++;
return;
@@ -478,6 +521,8 @@ void mesh_new_client(struct mesh_area* mesh, struct query_info* qinfo,
"dropping incoming query.");
if(rep->c->use_h2)
http2_stream_remove_mesh_state(rep->c->h2_stream);
else if(rep->c->type == comm_doq && rep->doq_stream)
doq_stream_remove_mesh_state(rep->doq_stream);
comm_point_drop_reply(rep);
mesh->num_queries_replyaddr_limit++;
return;
@@ -538,18 +583,22 @@ void mesh_new_client(struct mesh_area* mesh, struct query_info* qinfo,
}
}
/* add reply to s */
if(!mesh_state_add_reply(s, edns, rep, qid, qflags, qinfo)) {
if(!mesh_state_add_reply(s, edns, rep, qid, qflags, qinfo, &repadded)) {
log_err("mesh_new_client: out of memory; SERVFAIL");
goto servfail_mem;
}
added_reply_without_accounting = 1;
if(rep->c->tcp_req_info) {
if(!tcp_req_info_add_meshstate(rep->c->tcp_req_info, mesh, s)) {
log_err("mesh_new_client: out of memory add tcpreqinfo");
goto servfail_mem;
}
}
added_tcp = 1;
if(rep->c->use_h2) {
http2_stream_add_meshstate(rep->c->h2_stream, mesh, s);
} else if(rep->c->type == comm_doq && rep->doq_stream) {
doq_stream_add_meshstate(rep->doq_stream, mesh, s);
}
/* add serve expired timer if required and not already there */
if(timeout && !mesh_serve_expired_init(s, timeout)) {
@@ -567,6 +616,8 @@ void mesh_new_client(struct mesh_area* mesh, struct query_info* qinfo,
}
}
#endif
/* Since the acccounting now happens,
* added_reply_without_accounting = 0; but that is not used. */
infra_wait_limit_inc(mesh->env->infra_cache, rep, *mesh->env->now,
mesh->env->cfg);
/* update statistics */
@@ -603,7 +654,14 @@ servfail_mem:
qinfo, qid, qflags, edns);
if(rep->c->use_h2)
http2_stream_remove_mesh_state(rep->c->h2_stream);
else if(rep->c->type == comm_doq && rep->doq_stream)
doq_stream_remove_mesh_state(rep->doq_stream);
comm_point_send_reply(rep);
if(added_reply_without_accounting) {
mesh_remove_reply_without_accounting(s, repadded);
if(added_tcp && rep->c->tcp_req_info)
tcp_req_info_remove_mesh_state(rep->c->tcp_req_info, s);
}
if(added)
mesh_state_delete(&s->s);
return;
@@ -612,7 +670,8 @@ servfail_mem:
int
mesh_new_callback(struct mesh_area* mesh, struct query_info* qinfo,
uint16_t qflags, struct edns_data* edns, sldns_buffer* buf,
uint16_t qid, mesh_cb_func_type cb, void* cb_arg, int rpz_passthru)
uint16_t qid, mesh_cb_func_type cb, void* cb_arg, int rpz_passthru,
void** unique_info)
{
struct mesh_state* s = NULL;
int unique = unique_mesh_state(edns->opt_list_in, mesh->env);
@@ -621,6 +680,7 @@ mesh_new_callback(struct mesh_area* mesh, struct query_info* qinfo,
int was_detached = 0;
int was_noreply = 0;
int added = 0;
struct mesh_cb* add_cb = NULL;
uint16_t mesh_flags = qflags&(BIT_RD|BIT_CD);
if(!unique)
s = mesh_area_find(mesh, NULL, qinfo, mesh_flags, 0, 0);
@@ -666,13 +726,14 @@ mesh_new_callback(struct mesh_area* mesh, struct query_info* qinfo,
}
}
/* add reply to s */
if(!mesh_state_add_cb(s, edns, buf, cb, cb_arg, qid, qflags)) {
if(!mesh_state_add_cb(s, edns, buf, cb, cb_arg, qid, qflags, &add_cb)) {
if(added)
mesh_state_delete(&s->s);
return 0;
}
/* add serve expired timer if not already there */
if(timeout && !mesh_serve_expired_init(s, timeout)) {
mesh_remove_callback_without_accounting(s, add_cb);
if(added)
mesh_state_delete(&s->s);
return 0;
@@ -683,6 +744,7 @@ mesh_new_callback(struct mesh_area* mesh, struct query_info* qinfo,
(mesh->env->cachedb_enabled &&
mesh->env->cfg->cachedb_check_when_serve_expired)) {
if(!mesh_serve_expired_init(s, -1)) {
mesh_remove_callback_without_accounting(s, add_cb);
if(added)
mesh_state_delete(&s->s);
return 0;
@@ -698,6 +760,8 @@ mesh_new_callback(struct mesh_area* mesh, struct query_info* qinfo,
mesh->num_reply_states ++;
}
mesh->num_reply_addrs++;
if(unique_info)
*unique_info = s->unique;
if(added)
mesh_run(mesh, s, module_event_new, NULL);
return 1;
@@ -901,33 +965,9 @@ void mesh_report_reply(struct mesh_area* mesh, struct outbound_entry* e,
mesh_run(mesh, e->qstate->mesh_info, event, e);
}
/** copy strlist to region */
static struct config_strlist*
cfg_region_strlist_copy(struct regional* region, struct config_strlist* list)
{
struct config_strlist* result = NULL, *last = NULL, *s = list;
while(s) {
struct config_strlist* n = regional_alloc_zero(region,
sizeof(*n));
if(!n)
return NULL;
n->str = regional_strdup(region, s->str);
if(!n->str)
return NULL;
if(last)
last->next = n;
else result = n;
last = n;
s = s->next;
}
return result;
}
/** Copy the client info to the query region. */
static struct respip_client_info*
struct respip_client_info*
mesh_copy_client_info(struct regional* region, struct respip_client_info* cinfo)
{
size_t i;
struct respip_client_info* client_info;
client_info = regional_alloc_init(region, cinfo, sizeof(*cinfo));
if(!client_info)
@@ -946,20 +986,13 @@ mesh_copy_client_info(struct regional* region, struct respip_client_info* cinfo)
if(!client_info->tag_actions)
return NULL;
}
if(cinfo->tag_datas) {
client_info->tag_datas = regional_alloc_zero(region,
sizeof(struct config_strlist*)*cinfo->tag_datas_size);
if(!client_info->tag_datas)
return NULL;
for(i=0; i<cinfo->tag_datas_size; i++) {
if(cinfo->tag_datas[i]) {
client_info->tag_datas[i] = cfg_region_strlist_copy(
region, cinfo->tag_datas[i]);
if(!client_info->tag_datas[i])
return NULL;
}
}
}
/* tag_datas is owned by the matched acl_addr in config_file; its
* lifetime is until config reload, which tears down all mesh states
* first. Keep the original pointer so client_info_compare()
* can recognise two states from the same ACL entry. */
/* fast reload insists on dropping the queries when interface-tag-data
* or access-control-tag-data are changed. */
/* client_info->tag_datas already copied by regional_alloc_init above */
if(cinfo->view) {
/* Do not copy the view pointer but store a name instead.
* The name is looked up later when done, this means that
@@ -969,6 +1002,11 @@ mesh_copy_client_info(struct regional* region, struct respip_client_info* cinfo)
cinfo->view->name);
if(!client_info->view_name)
return NULL;
} else if(cinfo->view_name) {
client_info->view_name = regional_strdup(region,
cinfo->view_name);
if(!client_info->view_name)
return NULL;
}
return client_info;
}
@@ -1076,14 +1114,6 @@ mesh_state_cleanup(struct mesh_state* mstate)
if(!mstate->replies_sent) {
struct mesh_reply* rep = mstate->reply_list;
struct mesh_cb* cb;
/* One http2 stream could bring down its comm_point along with
* the other streams which could share the same query. Do all
* the http2 stream bookkeeping upfront. */
for(; rep; rep=rep->next) {
if(rep->query_reply.c->use_h2)
http2_stream_remove_mesh_state(rep->h2_stream);
}
rep = mstate->reply_list;
/* in tcp_req_info, the mstates linked are removed, but
* the reply_list is now NULL, so the remove-from-empty-list
* takes no time and also it does not do the mesh accounting */
@@ -1227,6 +1257,9 @@ int mesh_add_sub(struct module_qstate* qstate, struct query_info* qinfo,
log_err("mesh_attach_sub: out of memory");
return 0;
}
/* inherit RPZ passthru from the parent so respip on the sub
* sees the same client-IP/qname PASSTHRU decision */
(*sub)->s.rpz_passthru = qstate->rpz_passthru;
#ifdef UNBOUND_DEBUG
n =
#else
@@ -1482,6 +1515,10 @@ mesh_send_reply(struct mesh_state* m, int rcode, struct reply_info* rep,
* for HTTP/2 stream to refer to mesh state, in case
* connection gets cleanup before HTTP/2 stream close. */
r->h2_stream->mesh_state = NULL;
#ifdef HAVE_NGTCP2
} else if(r->query_reply.doq_stream) {
r->query_reply.doq_stream->mesh_state = NULL;
#endif
}
/* send the reply */
/* We don't reuse the encoded answer if:
@@ -1636,9 +1673,9 @@ static void dns_error_reporting(struct module_qstate* qstate,
opt = edns_opt_list_find(qstate->edns_opts_back_in,
LDNS_EDNS_REPORT_CHANNEL);
if(!opt) return;
agent_domain_len = opt->opt_len;
agent_domain = opt->opt_data;
if(dname_valid(agent_domain, agent_domain_len) < 3) {
agent_domain_len = dname_valid(agent_domain, opt->opt_len);
if(agent_domain_len < 3) {
/* The agent domain needs to be a valid dname that is not the
* root; from RFC9567. */
return;
@@ -1745,7 +1782,8 @@ void mesh_query_done(struct mesh_state* mstate)
}
}
if(mstate->reply_list && mstate->s.env->cfg->dns_error_reporting)
if(mstate->reply_list && mstate->s.env->cfg->dns_error_reporting
&& (!rep || rep->security != sec_status_secure))
dns_error_reporting(&mstate->s, rep);
for(r = mstate->reply_list; r; r = r->next) {
@@ -1775,6 +1813,8 @@ void mesh_query_done(struct mesh_state* mstate)
mstate->reply_list = NULL;
if(r->query_reply.c->use_h2)
http2_stream_remove_mesh_state(r->h2_stream);
else if(r->query_reply.doq_stream)
doq_stream_remove_mesh_state(r->query_reply.doq_stream);
comm_point_drop_reply(&r->query_reply);
mstate->reply_list = reply_list;
log_assert(mstate->s.env->mesh->num_reply_addrs > 0);
@@ -1812,6 +1852,8 @@ void mesh_query_done(struct mesh_state* mstate)
mstate->reply_list = NULL;
if(r->query_reply.c->use_h2) {
http2_stream_remove_mesh_state(r->h2_stream);
} else if(r->query_reply.doq_stream) {
doq_stream_remove_mesh_state(r->query_reply.doq_stream);
}
comm_point_drop_reply(&r->query_reply);
mstate->reply_list = reply_list;
@@ -1924,6 +1966,25 @@ struct mesh_state* mesh_area_find(struct mesh_area* mesh,
return result;
}
struct mesh_state* mesh_area_find_unique(struct mesh_area* mesh,
struct respip_client_info* cinfo, struct query_info* qinfo,
uint16_t qflags, int prime, int valrec, void* unique_info)
{
struct mesh_state key;
struct mesh_state* result;
key.node.key = &key;
key.s.is_priming = prime;
key.s.is_valrec = valrec;
key.s.qinfo = *qinfo;
key.s.query_flags = qflags;
key.unique = (struct mesh_state*)unique_info;
key.s.client_info = cinfo;
result = (struct mesh_state*)rbtree_search(&mesh->all, &key);
return result;
}
/** remove mesh state callback */
int mesh_state_del_cb(struct mesh_state* s, mesh_cb_func_type cb, void* cb_arg)
{
@@ -1945,7 +2006,7 @@ int mesh_state_del_cb(struct mesh_state* s, mesh_cb_func_type cb, void* cb_arg)
int mesh_state_add_cb(struct mesh_state* s, struct edns_data* edns,
sldns_buffer* buf, mesh_cb_func_type cb, void* cb_arg,
uint16_t qid, uint16_t qflags)
uint16_t qid, uint16_t qflags, struct mesh_cb** result)
{
struct mesh_cb* r = regional_alloc(s->s.region,
sizeof(struct mesh_cb));
@@ -1969,13 +2030,14 @@ int mesh_state_add_cb(struct mesh_state* s, struct edns_data* edns,
r->qflags = qflags;
r->next = s->cb_list;
s->cb_list = r;
*result = r;
return 1;
}
int mesh_state_add_reply(struct mesh_state* s, struct edns_data* edns,
struct comm_reply* rep, uint16_t qid, uint16_t qflags,
const struct query_info* qinfo)
const struct query_info* qinfo, struct mesh_reply** result)
{
struct mesh_reply* r = regional_alloc(s->s.region,
sizeof(struct mesh_reply));
@@ -1995,6 +2057,10 @@ int mesh_state_add_reply(struct mesh_state* s, struct edns_data* edns,
r->qid = qid;
r->qflags = qflags;
r->start_time = *s->s.env->now_tv;
if(s->reply_list == NULL && !s->has_first_reply_time) {
s->first_reply_time = r->start_time;
s->has_first_reply_time = 1;
}
r->next = s->reply_list;
r->qname = regional_alloc_init(s->s.region, qinfo->qname,
s->s.qinfo.qname_len);
@@ -2003,6 +2069,8 @@ int mesh_state_add_reply(struct mesh_state* s, struct edns_data* edns,
if(rep->c->use_h2)
r->h2_stream = rep->c->h2_stream;
else r->h2_stream = NULL;
if(rep->c->type != comm_doq)
r->query_reply.doq_stream = NULL;
/* Data related to local alias stored in 'qinfo' (if any) is ephemeral
* and can be different for different original queries (even if the
@@ -2050,6 +2118,7 @@ int mesh_state_add_reply(struct mesh_state* s, struct edns_data* edns,
r->local_alias = NULL;
s->reply_list = r;
*result = r;
return 1;
}
@@ -2207,8 +2276,29 @@ void mesh_run(struct mesh_area* mesh, struct mesh_state* mstate,
enum module_ev ev, struct outbound_entry* e)
{
enum module_ext_state s;
int numrun = 0;
verbose(VERB_ALGO, "mesh_run: start");
while(mstate) {
if(numrun++ > MESH_MAX_RUN_ITER) {
/* These modules are too much to activate, stop them.*/
log_err("Too many module run iterations, deleting");
while(mstate) {
/* notify supers */
if(mstate->super_set.count > 0) {
verbose(VERB_ALGO, "notify supers of failure");
mstate->s.return_msg = NULL;
mstate->s.return_rcode = LDNS_RCODE_SERVFAIL;
mesh_walk_supers(mesh, mstate);
}
mesh_state_delete(&mstate->s);
if(mesh->run.count > 0) {
/* pop random element off the runnable tree */
mstate = (struct mesh_state*)mesh->run.root->key;
(void)rbtree_delete(&mesh->run, mstate);
} else mstate = NULL;
}
break;
}
/* run the module */
fptr_ok(fptr_whitelist_mod_operate(
mesh->mods.mod[mstate->s.curmod]->operate));
@@ -2360,7 +2450,8 @@ void mesh_list_remove(struct mesh_state* m, struct mesh_state** fp,
}
void mesh_state_remove_reply(struct mesh_area* mesh, struct mesh_state* m,
struct comm_point* cp)
struct comm_point* cp, struct http2_stream* h2_stream,
struct doq_stream* doq_stream)
{
struct mesh_reply* n, *prev = NULL;
n = m->reply_list;
@@ -2368,7 +2459,9 @@ void mesh_state_remove_reply(struct mesh_area* mesh, struct mesh_state* m,
* there is no accounting twice */
if(!n) return; /* nothing to remove, also no accounting needed */
while(n) {
if(n->query_reply.c == cp) {
if(n->query_reply.c == cp
&& (!h2_stream || n->h2_stream == h2_stream)
&& (!doq_stream || n->query_reply.doq_stream == doq_stream)) {
/* unlink it */
if(prev) prev->next = n->next;
else m->reply_list = n->next;
@@ -2381,6 +2474,10 @@ void mesh_state_remove_reply(struct mesh_area* mesh, struct mesh_state* m,
* share the same comm_point); make sure the streams
* don't point back. */
if(n->h2_stream) n->h2_stream->mesh_state = NULL;
#ifdef HAVE_NGTCP2
if(n->query_reply.doq_stream)
n->query_reply.doq_stream->mesh_state = NULL;
#endif
/* prev = prev; */
n = n->next;
@@ -2421,9 +2518,10 @@ apply_respip_action(struct module_qstate* qstate,
/* xxx_deny actions mean dropping the reply, unless the original reply
* was redirected to response-ip data. */
if((actinfo->action == respip_deny ||
if(actinfo->action == respip_always_deny ||
((actinfo->action == respip_deny ||
actinfo->action == respip_inform_deny) &&
*encode_repp == rep)
*encode_repp == rep))
*encode_repp = NULL;
return 1;
@@ -2488,12 +2586,15 @@ mesh_serve_expired_callback(void* arg)
qstate->client_info, &actinfo, msg->rep, &alias_rrset, &encode_rep,
qstate->env->auth_zones)) {
return;
} else if(partial_rep &&
!respip_merge_cname(partial_rep, &qstate->qinfo, msg->rep,
} else if(partial_rep) {
if(!respip_merge_cname(partial_rep, &qstate->qinfo, msg->rep,
qstate->client_info, must_validate, &encode_rep, qstate->region,
qstate->env->auth_zones, qstate->env->views,
qstate->env->respip_set)) {
return;
return;
}
/* merge succeeded; final reply, no further alias pass */
partial_rep = NULL;
}
if(!encode_rep || alias_rrset) {
if(!encode_rep) {
@@ -2504,6 +2605,7 @@ mesh_serve_expired_callback(void* arg)
partial_rep = encode_rep;
}
}
msg->rep = encode_rep;
/* We've found a partial reply ending with an
* alias. Replace the lookup qinfo for the
* alias target and lookup the cache again to
@@ -2530,9 +2632,10 @@ mesh_serve_expired_callback(void* arg)
log_dns_msg("Serve expired lookup", &qstate->qinfo, msg->rep);
for(r = mstate->reply_list; r; r = r->next) {
struct timeval old;
timeval_subtract(&old, mstate->s.env->now_tv, &r->start_time);
if(mstate->s.env->cfg->discard_timeout != 0 &&
if(mesh_is_udp(r)) {
struct timeval old;
timeval_subtract(&old, mstate->s.env->now_tv, &r->start_time);
if(mstate->s.env->cfg->discard_timeout != 0 &&
((int)old.tv_sec)*1000+((int)old.tv_usec)/1000 >
mstate->s.env->cfg->discard_timeout) {
/* Drop the reply, it is too old */
@@ -2548,10 +2651,15 @@ mesh_serve_expired_callback(void* arg)
mstate->reply_list = NULL;
if(r->query_reply.c->use_h2)
http2_stream_remove_mesh_state(r->h2_stream);
else if(r->query_reply.doq_stream)
doq_stream_remove_mesh_state(r->query_reply.doq_stream);
comm_point_drop_reply(&r->query_reply);
mstate->reply_list = reply_list;
log_assert(mstate->s.env->mesh->num_reply_addrs > 0);
mstate->s.env->mesh->num_reply_addrs--;
mstate->s.env->mesh->num_queries_discard_timeout++;
continue;
}
}
i++;
@@ -2648,13 +2756,30 @@ int mesh_jostle_exceeded(struct mesh_area* mesh)
}
void mesh_remove_callback(struct mesh_area* mesh, struct query_info* qinfo,
uint16_t qflags, mesh_cb_func_type cb, void* cb_arg)
uint16_t qflags, mesh_cb_func_type cb, void* cb_arg, void* unique_info)
{
struct mesh_state* s = NULL;
s = mesh_area_find(mesh, NULL, qinfo, qflags&(BIT_RD|BIT_CD), 0, 0);
if(!s) return;
if(!mesh_state_del_cb(s, cb, cb_arg)) return;
if(s && mesh_state_del_cb(s, cb, cb_arg))
goto removed;
if(unique_info) {
s = mesh_area_find_unique(mesh, NULL, qinfo,
qflags&(BIT_RD|BIT_CD), 0, 0, unique_info);
if(s && mesh_state_del_cb(s, cb, cb_arg))
goto removed;
}
/* mesh_area_find builds key.unique=NULL and cannot match a state
* created with mesh_state_make_unique (e.g. subnetcache sets
* env->unique_mesh). Fall back to a linear scan; cb+cb_arg is an
* exact key (mesh_state_del_cb compares both).
* This works for both lookups for zonemd and for hostname authzone. */
RBTREE_FOR(s, struct mesh_state*, &mesh->all) {
if(s->cb_list && mesh_state_del_cb(s, cb, cb_arg))
goto removed;
}
return;
removed:
/* It was in the list and removed. */
log_assert(mesh->num_reply_addrs > 0);
mesh->num_reply_addrs--;
+50 -5
View File
@@ -69,6 +69,13 @@ struct respip_client_info;
*/
#define MESH_MAX_ACTIVATION 10000
/**
* Maximum number of mesh state run items. These are different modules
* activated during a mesh run. Any more is likely an infinite loop
* in the module. It is then terminated, and states are deleted.
*/
#define MESH_MAX_RUN_ITER 10000
/**
* Max number of references-to-references-to-references.. search size.
* Any more is treated like 'too large', and the creation of a new
@@ -191,6 +198,12 @@ struct mesh_state {
struct module_qstate s;
/** the list of replies to clients for the results */
struct mesh_reply* reply_list;
/** if it has a first reply time */
int has_first_reply_time;
/** wall-clock time the first client reply was attached;
* used by mesh_make_new_space() so duplicate retransmits
* cannot reset jostle aging. */
struct timeval first_reply_time;
/** the list of callbacks for the results */
struct mesh_cb* cb_list;
/** set of superstates (that want this state's result)
@@ -336,11 +349,14 @@ void mesh_new_client(struct mesh_area* mesh, struct query_info* qinfo,
* @param cb_arg: callback user arg.
* @param rpz_passthru: if true, the rpz passthru was previously found and
* further rpz processing is stopped.
* @param unique_info: if nonnull, unique info is passed back to be used
* for the callback remove call. It does not need to be deallocated.
* @return 0 on error.
*/
int mesh_new_callback(struct mesh_area* mesh, struct query_info* qinfo,
uint16_t qflags, struct edns_data* edns, struct sldns_buffer* buf,
uint16_t qid, mesh_cb_func_type cb, void* cb_arg, int rpz_passthru);
uint16_t qid, mesh_cb_func_type cb, void* cb_arg, int rpz_passthru,
void** unique_info);
/**
* New prefetch message. Create new query state if needed.
@@ -537,6 +553,23 @@ struct mesh_state* mesh_area_find(struct mesh_area* mesh,
struct respip_client_info* cinfo, struct query_info* qinfo,
uint16_t qflags, int prime, int valrec);
/**
* Find a unique mesh state in the mesh area. Pass relevant flags.
*
* @param mesh: the mesh area to look in.
* @param cinfo: if non-NULL client specific info that may affect IP-based
* actions that apply to the query result.
* @param qinfo: what query
* @param qflags: if RD / CD bit is set or not.
* @param prime: if it is a priming query.
* @param valrec: if it is a validation-recursion query.
* @param unique_info: the unique info for the state. NULL can be passed.
* @return: mesh state or NULL if not found.
*/
struct mesh_state* mesh_area_find_unique(struct mesh_area* mesh,
struct respip_client_info* cinfo, struct query_info* qinfo,
uint16_t qflags, int prime, int valrec, void* unique_info);
/**
* Setup attachment super/sub relation between super and sub mesh state.
* The relation must not be present when calling the function.
@@ -556,11 +589,12 @@ int mesh_state_attachment(struct mesh_state* super, struct mesh_state* sub);
* @param qid: ID of reply.
* @param qflags: original query flags.
* @param qinfo: original query info.
* @param result: the allocated reply structure, for rollback.
* @return: 0 on alloc error.
*/
int mesh_state_add_reply(struct mesh_state* s, struct edns_data* edns,
struct comm_reply* rep, uint16_t qid, uint16_t qflags,
const struct query_info* qinfo);
const struct query_info* qinfo, struct mesh_reply** result);
/**
* Create new callback structure and attach it to a mesh state.
@@ -572,11 +606,12 @@ int mesh_state_add_reply(struct mesh_state* s, struct edns_data* edns,
* @param cb_arg: callback user arg.
* @param qid: ID of reply.
* @param qflags: original query flags.
* @param result: the allocated callback structure, for rollback.
* @return: 0 on alloc error.
*/
int mesh_state_add_cb(struct mesh_state* s, struct edns_data* edns,
struct sldns_buffer* buf, mesh_cb_func_type cb, void* cb_arg,
uint16_t qid, uint16_t qflags);
uint16_t qid, uint16_t qflags, struct mesh_cb** result);
/**
* Run the mesh. Run all runnable mesh states. Which can create new
@@ -677,9 +712,14 @@ void mesh_list_remove(struct mesh_state* m, struct mesh_state** fp,
* @param mesh: to update the counters.
* @param m: the mesh state.
* @param cp: the comm_point to remove from the list.
* @param h2_stream: if not NULL, it specifies the h2_stream to match
* for the delete.
* @param doq_stream: if not NULL, it specifies the doq_stream to match
* for the delete.
*/
void mesh_state_remove_reply(struct mesh_area* mesh, struct mesh_state* m,
struct comm_point* cp);
struct comm_point* cp, struct http2_stream* h2_stream,
struct doq_stream* doq_stream);
/** Callback for when the serve expired client timer has run out. Tries to
* find an expired answer in the cache and reply that to the client.
@@ -726,8 +766,13 @@ void mesh_respond_serve_expired(struct mesh_state* mstate);
* @param qflags: flags from client query.
* @param cb: callback function.
* @param cb_arg: callback user arg.
* @param unique_info: if not NULL, used to find a unique state for removal.
*/
void mesh_remove_callback(struct mesh_area* mesh, struct query_info* qinfo,
uint16_t qflags, mesh_cb_func_type cb, void* cb_arg);
uint16_t qflags, mesh_cb_func_type cb, void* cb_arg, void* unique_info);
/** Copy the client info to the query region. */
struct respip_client_info* mesh_copy_client_info(struct regional* region,
struct respip_client_info* cinfo);
#endif /* SERVICES_MESH_H */
+381 -72
View File
@@ -208,6 +208,7 @@ static void
waiting_tcp_delete(struct waiting_tcp* w)
{
if(!w) return;
free(w->tls_auth_name);
if(w->timer)
comm_timer_delete(w->timer);
free(w);
@@ -1480,7 +1481,7 @@ portcomm_loweruse(struct outside_network* outnet, struct port_comm* pc)
pif = pc->pif;
log_assert(pif->inuse > 0);
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
pif->avail_ports[pif->avail_total - pif->inuse] = pc->number;
shared_ports_return_port(outnet->shared_ports, pif->shpif, pc->number);
#endif
pif->inuse--;
pif->out[pc->index] = pif->out[pif->inuse];
@@ -1694,19 +1695,25 @@ create_pending_tcp(struct outside_network* outnet, size_t bufsize)
}
/** setup an outgoing interface, ready address */
static int setup_if(struct port_if* pif, const char* addrstr,
int* avail, int numavail, size_t numfd)
static int setup_if(struct port_if* pif, const char* addrstr, size_t numfd,
struct shared_ports* shp)
{
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
pif->avail_total = numavail;
pif->avail_ports = (int*)memdup(avail, (size_t)numavail*sizeof(int));
if(!pif->avail_ports)
return 0;
#endif
if(!ipstrtoaddr(addrstr, UNBOUND_DNS_PORT, &pif->addr, &pif->addrlen) &&
!netblockstrtoaddr(addrstr, UNBOUND_DNS_PORT,
&pif->addr, &pif->addrlen, &pif->pfxlen))
return 0;
#ifdef INT_MAX
if(numfd > (size_t)INT_MAX) {
log_err("num_ports exceeds INT_MAX");
return 0;
}
#endif
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
pif->shpif = shared_ports_find_if(shp, &pif->addr, pif->addrlen,
pif->pfxlen);
#else
(void)shp;
#endif
pif->maxout = (int)numfd;
pif->inuse = 0;
pif->out = (struct port_comm**)calloc(numfd,
@@ -1720,12 +1727,12 @@ struct outside_network*
outside_network_create(struct comm_base *base, size_t bufsize,
size_t num_ports, char** ifs, int num_ifs, int do_ip4,
int do_ip6, size_t num_tcp, int dscp, struct infra_cache* infra,
struct ub_randstate* rnd, int use_caps_for_id, int* availports,
int numavailports, size_t unwanted_threshold, int tcp_mss,
struct ub_randstate* rnd, int use_caps_for_id,
size_t unwanted_threshold, int tcp_mss,
void (*unwanted_action)(void*), void* unwanted_param, int do_udp,
void* sslctx, int delayclose, int tls_use_sni, struct dt_env* dtenv,
int udp_connect, int max_reuse_tcp_queries, int tcp_reuse_timeout,
int tcp_auth_query_timeout)
int tcp_auth_query_timeout, struct shared_ports* shared_ports)
{
struct outside_network* outnet = (struct outside_network*)
calloc(1, sizeof(struct outside_network));
@@ -1760,6 +1767,7 @@ outside_network_create(struct comm_base *base, size_t bufsize,
outnet->do_udp = do_udp;
outnet->tcp_mss = tcp_mss;
outnet->ip_dscp = dscp;
outnet->shared_ports = shared_ports;
#ifndef S_SPLINT_S
if(delayclose) {
outnet->delayclose = 1;
@@ -1770,11 +1778,18 @@ outside_network_create(struct comm_base *base, size_t bufsize,
if(udp_connect) {
outnet->udp_connect = 1;
}
if(numavailports == 0 || num_ports == 0) {
if(num_ports == 0) {
log_err("no outgoing ports available");
outside_network_delete(outnet);
return NULL;
}
#ifdef INT_MAX
if(num_ports > (size_t)INT_MAX) {
log_err("outgoing num_ports exceeds INT_MAX");
outside_network_delete(outnet);
return NULL;
}
#endif
#ifndef INET6
do_ip6 = 0;
#endif
@@ -1831,13 +1846,13 @@ outside_network_create(struct comm_base *base, size_t bufsize,
/* allocate interfaces */
if(num_ifs == 0) {
if(do_ip4 && !setup_if(&outnet->ip4_ifs[0], "0.0.0.0",
availports, numavailports, num_ports)) {
num_ports, outnet->shared_ports)) {
log_err("malloc failed");
outside_network_delete(outnet);
return NULL;
}
if(do_ip6 && !setup_if(&outnet->ip6_ifs[0], "::",
availports, numavailports, num_ports)) {
num_ports, outnet->shared_ports)) {
log_err("malloc failed");
outside_network_delete(outnet);
return NULL;
@@ -1848,7 +1863,7 @@ outside_network_create(struct comm_base *base, size_t bufsize,
for(i=0; i<num_ifs; i++) {
if(str_is_ip6(ifs[i]) && do_ip6) {
if(!setup_if(&outnet->ip6_ifs[done_6], ifs[i],
availports, numavailports, num_ports)){
num_ports, outnet->shared_ports)){
log_err("malloc failed");
outside_network_delete(outnet);
return NULL;
@@ -1857,7 +1872,7 @@ outside_network_create(struct comm_base *base, size_t bufsize,
}
if(!str_is_ip6(ifs[i]) && do_ip4) {
if(!setup_if(&outnet->ip4_ifs[done_4], ifs[i],
availports, numavailports, num_ports)){
num_ports, outnet->shared_ports)){
log_err("malloc failed");
outside_network_delete(outnet);
return NULL;
@@ -1935,9 +1950,6 @@ outside_network_delete(struct outside_network* outnet)
comm_point_delete(pc->cp);
free(pc);
}
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
free(outnet->ip4_ifs[i].avail_ports);
#endif
free(outnet->ip4_ifs[i].out);
}
free(outnet->ip4_ifs);
@@ -1951,9 +1963,6 @@ outside_network_delete(struct outside_network* outnet)
comm_point_delete(pc->cp);
free(pc);
}
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
free(outnet->ip6_ifs[i].avail_ports);
#endif
free(outnet->ip6_ifs[i].out);
}
free(outnet->ip6_ifs);
@@ -2163,7 +2172,10 @@ static int
select_ifport(struct outside_network* outnet, struct pending* pend,
int num_if, struct port_if* ifs)
{
int my_if, my_port, fd, portno, inuse, tries=0;
int my_if, fd, portno, inuse, tries=0;
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
int reused;
#endif
struct port_if* pif;
/* randomly select interface and port */
if(num_if == 0) {
@@ -2177,37 +2189,35 @@ select_ifport(struct outside_network* outnet, struct pending* pend,
my_if = ub_random_max(outnet->rnd, num_if);
pif = &ifs[my_if];
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
if(outnet->udp_connect) {
/* if we connect() we cannot reuse fds for a port */
if(pif->inuse >= pif->avail_total) {
tries++;
if(tries < MAX_PORT_RETRY)
continue;
log_err("failed to find an open port, drop msg");
return 0;
}
my_port = pif->inuse + ub_random_max(outnet->rnd,
pif->avail_total - pif->inuse);
} else {
my_port = ub_random_max(outnet->rnd, pif->avail_total);
if(my_port < pif->inuse) {
/* port already open */
pend->pc = pif->out[my_port];
verbose(VERB_ALGO, "using UDP if=%d port=%d",
my_if, pend->pc->number);
break;
}
if(!shared_ports_fetch_random(outnet->shared_ports,
pif->shpif, outnet->rnd, outnet->udp_connect,
pif->inuse, &portno, &reused)) {
tries++;
if(tries < MAX_PORT_RETRY)
continue;
log_err("failed to find an open port, drop msg");
return 0;
}
if(reused) {
/* port already open */
log_assert(portno < pif->inuse);
pend->pc = pif->out[portno];
verbose(VERB_ALGO, "using UDP if=%d port=%d",
my_if, pend->pc->number);
break;
}
/* try to open new port, if fails, loop to try again */
log_assert(pif->inuse < pif->maxout);
portno = pif->avail_ports[my_port - pif->inuse];
#else
my_port = portno = 0;
portno = 0;
#endif
/* try to open new port, if fails, loop to try again */
fd = udp_sockport(&pif->addr, pif->addrlen, pif->pfxlen,
portno, &inuse, outnet->rnd, outnet->ip_dscp);
if(fd == -1 && !inuse) {
/* nonrecoverable error making socket */
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
shared_ports_return_port(outnet->shared_ports,
pif->shpif, portno);
#endif
return 0;
}
if(fd != -1) {
@@ -2224,6 +2234,11 @@ select_ifport(struct outside_network* outnet, struct pending* pend,
pend->addrlen);
}
sock_close(fd);
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
shared_ports_return_port(
outnet->shared_ports,
pif->shpif, portno);
#endif
return 0;
}
}
@@ -2241,14 +2256,14 @@ select_ifport(struct outside_network* outnet, struct pending* pend,
/* grab port in interface */
pif->out[pif->inuse] = pend->pc;
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
pif->avail_ports[my_port - pif->inuse] =
pif->avail_ports[pif->avail_total-pif->inuse-1];
#endif
pif->inuse++;
break;
}
/* failed, already in use */
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
shared_ports_return_port(outnet->shared_ports, pif->shpif,
portno);
#endif
verbose(VERB_QUERY, "port %d in use, trying another", portno);
tries++;
if(tries == MAX_PORT_RETRY) {
@@ -2540,7 +2555,16 @@ pending_tcp_query(struct serviced_query* sq, sldns_buffer* packet,
w->cb = callback;
w->cb_arg = callback_arg;
w->ssl_upstream = sq->ssl_upstream;
w->tls_auth_name = sq->tls_auth_name;
if(sq->tls_auth_name) {
w->tls_auth_name = strdup(sq->tls_auth_name);
if(!w->tls_auth_name) {
comm_timer_delete(w->timer);
free(w);
return NULL;
}
} else {
w->tls_auth_name = NULL;
}
w->timeout = timeout;
w->id_node.key = NULL;
w->write_wait_prev = NULL;
@@ -3338,9 +3362,9 @@ serviced_udp_callback(struct comm_point* c, void* arg, int error,
if(error == NETEVENT_TIMEOUT) {
if(sq->status == serviced_query_UDP_EDNS && sq->last_rtt < 5000 &&
(serviced_query_udp_size(sq, serviced_query_UDP_EDNS_FRAG) < serviced_query_udp_size(sq, serviced_query_UDP_EDNS))) {
/* fallback to 1480/1280 */
/* fallback to 1472/1232 */
sq->status = serviced_query_UDP_EDNS_FRAG;
log_name_addr(VERB_ALGO, "try edns1xx0", sq->qbuf+10,
log_name_addr(VERB_ALGO, "try edns1xx2", sq->qbuf+10,
&sq->addr, sq->addrlen);
if(!serviced_udp_send(sq, c->buffer)) {
serviced_callbacks(sq, NETEVENT_CLOSED, c, rep);
@@ -3477,7 +3501,8 @@ outnet_serviced_query(struct outside_network* outnet,
char* tls_auth_name, struct sockaddr_storage* addr, socklen_t addrlen,
uint8_t* zone, size_t zonelen, struct module_qstate* qstate,
comm_point_callback_type* callback, void* callback_arg,
sldns_buffer* buff, struct module_env* env, int* was_ratelimited)
sldns_buffer* buff, struct module_env* env, int* was_ratelimited,
int* ratelimit_incremented)
{
struct serviced_query* sq;
struct service_callback* cb;
@@ -3549,6 +3574,7 @@ outnet_serviced_query(struct outside_network* outnet,
"delegation point", zone,
LDNS_RR_TYPE_NS, LDNS_RR_CLASS_IN);
}
*ratelimit_incremented = 1;
}
/* make new serviced query entry */
sq = serviced_create(outnet, buff, dnssec, want_dnssec, nocaps,
@@ -3630,13 +3656,16 @@ fd_for_dest(struct outside_network* outnet, struct sockaddr_storage* to_addr,
{
struct sockaddr_storage* addr;
socklen_t addrlen;
int i, try, pnum, dscp;
int i, try, dscp;
struct port_if* pif;
/* create fd */
dscp = outnet->ip_dscp;
for(try = 0; try<1000; try++) {
int port = 0;
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
int reused = 0;
#endif
int freebind = 0;
int noproto = 0;
int inuse = 0;
@@ -3665,16 +3694,18 @@ fd_for_dest(struct outside_network* outnet, struct sockaddr_storage* to_addr,
addr = &pif->addr;
addrlen = pif->addrlen;
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
pnum = ub_random_max(outnet->rnd, pif->avail_total);
if(pnum < pif->inuse) {
/* port already open */
port = pif->out[pnum]->number;
} else {
/* unused ports in start part of array */
port = pif->avail_ports[pnum - pif->inuse];
if(!shared_ports_fetch_random(outnet->shared_ports,
pif->shpif, outnet->rnd, 0, pif->inuse,
&port, &reused)) {
/* try again, perhaps another interface. */
continue;
}
if(reused) {
log_assert(port < pif->inuse);
port = pif->out[port]->number;
}
#else
pnum = port = 0;
port = 0;
#endif
if(addr_is_ip6(to_addr, to_addrlen)) {
struct sockaddr_in6 sa = *(struct sockaddr_in6*)addr;
@@ -3689,6 +3720,14 @@ fd_for_dest(struct outside_network* outnet, struct sockaddr_storage* to_addr,
(struct sockaddr*)addr, addrlen, 1, &inuse, &noproto,
0, 0, 0, NULL, 0, freebind, 0, dscp);
}
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
if(!reused) {
/* Return the port to the pool, since the caller does
* not keep track of it, also have done fd, and bind. */
shared_ports_return_port(outnet->shared_ports,
pif->shpif, port);
}
#endif
if(fd != -1) {
return fd;
}
@@ -3741,7 +3780,33 @@ setup_comm_ssl(struct comm_point* cp, struct outside_network* outnet,
(void)SSL_set_tlsext_host_name(cp->ssl, host);
}
#endif
#ifdef HAVE_SSL_SET1_HOST
#ifdef HAVE_SSL_SET1_DNSNAME
if((SSL_CTX_get_verify_mode(outnet->sslctx)&SSL_VERIFY_PEER)) {
/* because we set SSL_VERIFY_PEER, in netevent in
* ssl_handshake, it'll check if the certificate
* verification has succeeded */
/* SSL_VERIFY_PEER is set on the sslctx */
/* and the certificates to verify with are loaded into
* it with SSL_load_verify_locations or
* SSL_CTX_set_default_verify_paths */
/* setting the hostname makes openssl verify the
* host name in the x509 certificate in the
* SSL connection*/
struct sockaddr_storage tmpaddr;
socklen_t tmpaddrlen = (socklen_t)sizeof(tmpaddr);
if(ipstrtoaddr(host, UNBOUND_DNS_PORT, &tmpaddr, &tmpaddrlen)) {
if(!SSL_set1_ipaddr(cp->ssl, host)) {
log_err("SSL_set1_ipaddr failed");
return 0;
}
} else {
if(!SSL_set1_dnsname(cp->ssl, host)) {
log_err("SSL_set1_dnsname failed");
return 0;
}
}
}
#elif defined(HAVE_SSL_SET1_HOST)
if((SSL_CTX_get_verify_mode(outnet->sslctx)&SSL_VERIFY_PEER)) {
/* because we set SSL_VERIFY_PEER, in netevent in
* ssl_handshake, it'll check if the certificate
@@ -3870,7 +3935,8 @@ outnet_comm_point_for_http(struct outside_network* outnet,
/* outnet_tcp_connect has closed fd on error for us */
return 0;
}
cp = comm_point_create_http_out(outnet->base, 65552, cb, cb_arg,
cp = comm_point_create_http_out(outnet->base,
sldns_buffer_capacity(outnet->udp_buff), cb, cb_arg,
outnet->udp_buff);
if(!cp) {
log_err("malloc failure");
@@ -3919,11 +3985,7 @@ if_get_mem(struct port_if* pif)
{
size_t s;
int i;
s = sizeof(*pif) +
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
sizeof(int)*pif->avail_total +
#endif
sizeof(struct port_comm*)*pif->maxout;
s = sizeof(*pif) + sizeof(struct port_comm*)*pif->maxout;
for(i=0; i<pif->inuse; i++)
s += sizeof(*pif->out[i]) +
comm_point_get_mem(pif->out[i]->cp);
@@ -4011,3 +4073,250 @@ serviced_get_mem(struct serviced_query* sq)
return s;
}
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
/** Setup shared port interface */
static int shared_ports_setup_if(struct shared_ports_if* shpif, char* str,
int* availports, int numavailports)
{
shpif->avail_ports = (int*)memdup(availports,
(size_t)numavailports*sizeof(int));
if(!shpif->avail_ports)
return 0;
shpif->avail_total = numavailports;
shpif->inuse = 0;
shpif->pfxlen = 0;
if(!ipstrtoaddr(str, UNBOUND_DNS_PORT, &shpif->addr, &shpif->addrlen) &&
!netblockstrtoaddr(str, UNBOUND_DNS_PORT, &shpif->addr,
&shpif->addrlen, &shpif->pfxlen))
return 0;
return 1;
}
#endif
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
/** Allocate shared ports interfaces */
static int shared_ports_alloc_ifs(struct shared_ports* shp, char** ifs,
int num_ifs, int do_ip4, int do_ip6, int* availports,
int numavailports)
{
#ifndef INET6
do_ip6 = 0;
#endif
calc_num46(ifs, num_ifs, do_ip4, do_ip6,
&shp->num_ip4, &shp->num_ip6);
if(shp->num_ip4 != 0) {
if(!(shp->ip4_ifs = (struct shared_ports_if*)calloc(
(size_t)shp->num_ip4,
sizeof(struct shared_ports_if))))
return 0;
}
if(shp->num_ip6 != 0) {
if(!(shp->ip6_ifs = (struct shared_ports_if*)calloc(
(size_t)shp->num_ip6,
sizeof(struct shared_ports_if))))
return 0;
}
if(num_ifs == 0) {
if(do_ip4 && !shared_ports_setup_if(&shp->ip4_ifs[0],
"0.0.0.0", availports, numavailports))
return 0;
if(do_ip6 && !shared_ports_setup_if(&shp->ip6_ifs[0],
"::", availports, numavailports))
return 0;
} else {
size_t done_4 = 0, done_6 = 0;
int i;
for(i=0; i<num_ifs; i++) {
if(str_is_ip6(ifs[i]) && do_ip6 &&
(int)done_6 < shp->num_ip6) {
if(!shared_ports_setup_if(&shp->ip6_ifs[done_6],
ifs[i], availports, numavailports))
return 0;
done_6++;
}
if(!str_is_ip6(ifs[i]) && do_ip4 &&
(int)done_4 < shp->num_ip4) {
if(!shared_ports_setup_if(&shp->ip4_ifs[done_4],
ifs[i], availports, numavailports))
return 0;
done_4++;
}
}
}
return 1;
}
#endif
struct shared_ports* shared_ports_create(char** ifs, int num_ifs, int do_ip4,
int do_ip6, int* availports, int numavailports)
{
struct shared_ports* shp = calloc(1, sizeof(*shp));
if(!shp) {
log_err("malloc failed");
return NULL;
}
lock_basic_init(&shp->lock);
lock_protect(&shp->lock, &shp->ip4_ifs, sizeof(shp->ip4_ifs));
lock_protect(&shp->lock, &shp->num_ip4, sizeof(shp->num_ip4));
lock_protect(&shp->lock, &shp->ip6_ifs, sizeof(shp->ip6_ifs));
lock_protect(&shp->lock, &shp->num_ip6, sizeof(shp->num_ip6));
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
/* Allocate interfaces */
lock_basic_lock(&shp->lock);
if(!shared_ports_alloc_ifs(shp, ifs, num_ifs, do_ip4, do_ip6,
availports, numavailports)) {
log_err("malloc failed");
shared_ports_delete(shp);
return NULL;
}
lock_basic_unlock(&shp->lock);
#else
(void)ifs; (void)num_ifs; (void)do_ip4; (void)do_ip6;
(void)availports; (void)numavailports;
#endif
return shp;
}
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
/** Delete shared ports interface structure */
static void shared_ports_if_delete(struct shared_ports_if* shpif)
{
if(!shpif)
return;
free(shpif->avail_ports);
}
#endif
void shared_ports_delete(struct shared_ports* shp)
{
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
int i;
#endif
if(!shp)
return;
lock_basic_destroy(&shp->lock);
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
for(i=0; i<shp->num_ip4; i++) {
shared_ports_if_delete(&shp->ip4_ifs[i]);
}
free(shp->ip4_ifs);
for(i=0; i<shp->num_ip6; i++) {
shared_ports_if_delete(&shp->ip6_ifs[i]);
}
free(shp->ip6_ifs);
#endif
free(shp);
}
struct shared_ports_if* shared_ports_find_if(struct shared_ports* shp,
struct sockaddr_storage* addr, socklen_t addrlen, int pfxlen)
{
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
struct shared_ports_if* ret, *ifs = NULL;
int i, num_ifs = 0;
lock_basic_lock(&shp->lock);
if(addr_is_ip6(addr, addrlen)) {
ifs = shp->ip6_ifs;
num_ifs = shp->num_ip6;
} else {
ifs = shp->ip4_ifs;
num_ifs = shp->num_ip4;
}
for(i=0; i<num_ifs; i++) {
if(sockaddr_cmp(addr, addrlen, &ifs[i].addr,
ifs[i].addrlen) == 0
&& pfxlen == ifs[i].pfxlen) {
ret = &ifs[i];
lock_basic_unlock(&shp->lock);
return ret;
}
}
lock_basic_unlock(&shp->lock);
return NULL;
#else
(void)shp; (void)addr; (void)addrlen; (void)pfxlen;
return NULL;
#endif
}
int shared_ports_fetch_random(struct shared_ports* shp,
struct shared_ports_if* shpif, struct ub_randstate* rnd,
int udp_connect, int reusenum, int* port, int* reused)
{
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
int portno = 0, my_port = 0;
if(!shpif)
return 0;
# ifdef THREADS_DISABLED
(void)shp;
# endif
lock_basic_lock(&shp->lock);
if(udp_connect) {
/* if we connect() we cannot reuse fds for a port. */
if(shpif->inuse >= shpif->avail_total) {
lock_basic_unlock(&shp->lock);
return 0;
}
my_port = ub_random_max(rnd,
shpif->avail_total - shpif->inuse);
} else {
/* select from free ports and open ports on this thread. */
if(shpif->inuse >= shpif->avail_total) {
lock_basic_unlock(&shp->lock);
if(reusenum == 0) {
return 0;
}
my_port = ub_random_max(rnd, reusenum);
*port = my_port;
*reused = 1;
return 1;
}
my_port = ub_random_max(rnd, shpif->avail_total - shpif->inuse
+ reusenum);
if(my_port < reusenum) {
/* port already open */
lock_basic_unlock(&shp->lock);
*port = my_port;
*reused = 1;
return 1;
}
my_port -= reusenum;
}
log_assert(shpif->inuse < shpif->avail_total);
log_assert(my_port >= 0 && my_port < shpif->avail_total);
portno = shpif->avail_ports[my_port];
shpif->avail_ports[my_port] =
shpif->avail_ports[shpif->avail_total-shpif->inuse-1];
shpif->inuse++;
lock_basic_unlock(&shp->lock);
*port = portno;
*reused = 0;
return 1;
#else
(void)shp; (void)shpif; (void)rnd; (void)udp_connect;
(void)reusenum;
*port = 0;
*reused = 0;
return 1;
#endif
}
void shared_ports_return_port(struct shared_ports* shp,
struct shared_ports_if* shpif, int port)
{
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
if(!shpif)
return;
# ifdef THREADS_DISABLED
(void)shp;
# endif
lock_basic_lock(&shp->lock);
log_assert(shpif->inuse > 0);
shpif->avail_ports[shpif->avail_total - shpif->inuse] = port;
shpif->inuse--;
lock_basic_unlock(&shp->lock);
#else
(void)shp; (void)shpif; (void)port;
#endif
}
+101 -13
View File
@@ -70,6 +70,8 @@ struct module_env;
struct module_qstate;
struct query_info;
struct config_file;
struct shared_ports;
struct shared_ports_if;
/**
* Send queries to outside servers and wait for answers from servers.
@@ -119,6 +121,9 @@ struct outside_network {
int udp_connect;
/** number of udp packets sent. */
size_t num_udp_outgoing;
/** the shared ports structure, with random ports numbers.
* This is a reference to the member in the daemon structure. */
struct shared_ports* shared_ports;
/** array of outgoing IP4 interfaces */
struct port_if* ip4_ifs;
@@ -211,11 +216,8 @@ struct port_if {
int pfxlen;
#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION
/** the available ports array. These are unused.
* Only the first total-inuse part is filled. */
int* avail_ports;
/** the total number of available ports (size of the array) */
int avail_total;
/** the shared port numbers for this interface. */
struct shared_ports_if* shpif;
#endif
/** array of the commpoints currently in use.
@@ -245,6 +247,42 @@ struct port_comm {
struct comm_point* cp;
};
/**
* Shared ports, the list of ports shared across threads
*/
struct shared_ports {
/** mutex on the ports */
lock_basic_type lock;
/** array of IP4 interfaces */
struct shared_ports_if* ip4_ifs;
/** number of outgoing IP4 interfaces */
int num_ip4;
/** array of IP6 interfaces */
struct shared_ports_if* ip6_ifs;
/** number of outgoing IP6 interfaces */
int num_ip6;
};
/**
* Shared ports for an interface.
*/
struct shared_ports_if {
/** address ready to allocate new socket (except port no). */
struct sockaddr_storage addr;
/** length of addr field */
socklen_t addrlen;
/** if a netblock, the prefix */
int pfxlen;
/** the available ports array. These are unused.
* Only the first total-inuse part is filled. */
int* avail_ports;
/** the total number of available ports (size of the array) */
int avail_total;
/** the number in use. */
int inuse;
};
/**
* Reuse TCP connection, still open can be used again.
*/
@@ -419,7 +457,7 @@ struct waiting_tcp {
void* cb_arg;
/** if it uses ssl upstream */
int ssl_upstream;
/** ref to the tls_auth_name from the serviced_query */
/** owned copy of the tls_auth_name (malloced) */
char* tls_auth_name;
/** the packet was involved in an error, to stop looping errors */
int error_count;
@@ -500,7 +538,7 @@ struct serviced_query {
serviced_query_UDP_EDNS_fallback,
/** probe to test TCP noEDNS0 (EDNS gives FORMERRorNOTIMP) */
serviced_query_TCP_EDNS_fallback,
/** send UDP query with EDNS1480 (or 1280) */
/** send UDP query with EDNS1472 (or 1232) */
serviced_query_UDP_EDNS_FRAG
}
/** variable with current status */
@@ -551,8 +589,6 @@ struct serviced_query {
* @param infra: pointer to infra cached used for serviced queries.
* @param rnd: stored to create random numbers for serviced queries.
* @param use_caps_for_id: enable to use 0x20 bits to encode id randomness.
* @param availports: array of available ports.
* @param numavailports: number of available ports in array.
* @param unwanted_threshold: when to take defensive action.
* @param unwanted_action: the action to take.
* @param unwanted_param: user parameter to action.
@@ -567,17 +603,18 @@ struct serviced_query {
* @param max_reuse_tcp_queries: max number of queries on a reuse connection.
* @param tcp_reuse_timeout: timeout for REUSE entries in milliseconds.
* @param tcp_auth_query_timeout: timeout in milliseconds for TCP queries to auth servers.
* @param shared_ports: the shared_ports structure.
* @return: the new structure (with no pending answers) or NULL on error.
*/
struct outside_network* outside_network_create(struct comm_base* base,
size_t bufsize, size_t num_ports, char** ifs, int num_ifs,
int do_ip4, int do_ip6, size_t num_tcp, int dscp, struct infra_cache* infra,
struct ub_randstate* rnd, int use_caps_for_id, int* availports,
int numavailports, size_t unwanted_threshold, int tcp_mss,
struct ub_randstate* rnd, int use_caps_for_id,
size_t unwanted_threshold, int tcp_mss,
void (*unwanted_action)(void*), void* unwanted_param, int do_udp,
void* sslctx, int delayclose, int tls_use_sni, struct dt_env *dtenv,
int udp_connect, int max_reuse_tcp_queries, int tcp_reuse_timeout,
int tcp_auth_query_timeout);
int tcp_auth_query_timeout, struct shared_ports* shared_ports);
/**
* Delete outside_network structure.
@@ -660,6 +697,8 @@ void pending_delete(struct outside_network* outnet, struct pending* p);
* @param env: the module environment.
* @param was_ratelimited: it will signal back if the query failed to pass the
* ratelimit check.
* @param ratelimit_incremented: set to true if the ratelimit counter
* was increased.
* @return 0 on error, or pointer to serviced query that is used to answer
* this serviced query may be shared with other callbacks as well.
*/
@@ -669,7 +708,8 @@ struct serviced_query* outnet_serviced_query(struct outside_network* outnet,
char* tls_auth_name, struct sockaddr_storage* addr, socklen_t addrlen,
uint8_t* zone, size_t zonelen, struct module_qstate* qstate,
comm_point_callback_type* callback, void* callback_arg,
struct sldns_buffer* buff, struct module_env* env, int* was_ratelimited);
struct sldns_buffer* buff, struct module_env* env, int* was_ratelimited,
int* ratelimit_incremented);
/**
* Remove service query callback.
@@ -819,6 +859,54 @@ struct comm_point* outnet_comm_point_for_http(struct outside_network* outnet,
/** connect tcp connection to addr, 0 on failure */
int outnet_tcp_connect(int s, struct sockaddr_storage* addr, socklen_t addrlen);
/**
* Create new shared ports structure.
* @param ifs: interface names (or NULL for default interface).
* These interfaces must be able to access all authoritative servers.
* @param num_ifs: number of names in array ifs.
* @param do_ip4: service IP4.
* @param do_ip6: service IP6.
* @param availports: array of available ports.
* @param numavailports: number of available ports in array.
* @return new, or NULL on failure.
*/
struct shared_ports* shared_ports_create(char** ifs, int num_ifs, int do_ip4,
int do_ip6, int* availports, int numavailports);
/**
* Delete shared ports structure.
* @param shp: shared ports structure.
*/
void shared_ports_delete(struct shared_ports* shp);
/** Find interface in shared ports. */
struct shared_ports_if* shared_ports_find_if(struct shared_ports* shp,
struct sockaddr_storage* addr, socklen_t addrlen, int pfxlen);
/**
* Get a shared port from the list of random ports.
* @param shp: shared ports structure.
* @param shpif: the shared ports interface.
* @param rnd: used to make random numbers.
* @param udp_connect: set to true if no reuse is possible.
* @param reusenum: number of ports that can be reused (already open).
* @param port: the port number is returned.
* @param reused: if the port numer is reused, returned.
* @return false on failure. That can mean no more free ports to use.
*/
int shared_ports_fetch_random(struct shared_ports* shp,
struct shared_ports_if* shpif, struct ub_randstate* rnd,
int udp_connect, int reusenum, int* port, int* reused);
/**
* Return a shared port to the list of random ports.
* @param shp: shared ports structure.
* @param shpif: the shared ports interface.
* @param port: port number to return to be used again.
*/
void shared_ports_return_port(struct shared_ports* shp,
struct shared_ports_if* shpif, int port);
/** callback for incoming udp answers from the network */
int outnet_udp_cb(struct comm_point* c, void* arg, int error,
struct comm_reply *reply_info);
+39 -21
View File
@@ -721,13 +721,22 @@ rpz_insert_local_zones_trigger(struct local_zones* lz, uint8_t* dname,
char* rrstr = sldns_wire2str_rr(rr, rr_len);
if(rrstr == NULL) {
log_err("malloc error while inserting rpz nsdname trigger");
free(dname);
if(!newzone)
free(dname);
lock_rw_unlock(&lz->lock);
return;
}
lock_rw_wrlock(&z->lock);
local_zone_enter_rr(z, dname, dnamelen, dnamelabs, rrtype,
rrclass, ttl, rdata, rdata_len, rrstr);
if(!local_zone_enter_rr(z, dname, dnamelen, dnamelabs, rrtype,
rrclass, ttl, rdata, rdata_len, rrstr)) {
log_err("rpz: could not enter local-data: %s", rrstr);
if(!newzone)
free(dname);
lock_rw_unlock(&z->lock);
lock_rw_unlock(&lz->lock);
free(rrstr);
return;
}
lock_rw_unlock(&z->lock);
free(rrstr);
}
@@ -805,8 +814,9 @@ rpz_insert_nsdname_trigger(struct rpz* r, uint8_t* dname, size_t dnamelen,
uint8_t* dname_stripped = NULL;
size_t dnamelen_stripped = 0;
rpz_strip_nsdname_suffix(dname, dnamelen, &dname_stripped,
&dnamelen_stripped);
if(!rpz_strip_nsdname_suffix(dname, dnamelen, &dname_stripped,
&dnamelen_stripped))
return;
if(a == RPZ_INVALID_ACTION) {
verbose(VERB_ALGO, "rpz: skipping invalid action");
free(dname_stripped);
@@ -904,8 +914,8 @@ rpz_report_rrset_error(const char* msg, uint8_t* rr, size_t rr_len) {
/* from localzone.c; difference is we don't have a dname */
static struct local_rrset*
rpz_clientip_new_rrset(struct regional* region,
struct clientip_synthesized_rr* raddr, uint16_t rrtype, uint16_t rrclass)
rpz_clientip_new_rrset(struct regional* region, uint16_t rrtype,
uint16_t rrclass)
{
struct packed_rrset_data* pd;
struct local_rrset* rrset = (struct local_rrset*)
@@ -914,8 +924,6 @@ rpz_clientip_new_rrset(struct regional* region,
log_err("out of memory");
return NULL;
}
rrset->next = raddr->data;
raddr->data = rrset;
rrset->rrset = (struct ub_packed_rrset_key*)
regional_alloc_zero(region, sizeof(*rrset->rrset));
if(rrset->rrset == NULL) {
@@ -954,12 +962,18 @@ rpz_clientip_enter_rr(struct regional* region, struct clientip_synthesized_rr* r
return 0;
}
rrset = rpz_clientip_new_rrset(region, raddr, rrtype, rrclass);
if(raddr->data == NULL) {
rrset = rpz_clientip_new_rrset(region, rrtype, rrclass);
if(rrset == NULL) {
return 0;
}
return rrset_insert_rr(region, rrset->rrset->entry.data, rdata, rdata_len, ttl, "");
if(!rrset_insert_rr(region, rrset->rrset->entry.data, rdata, rdata_len, ttl, ""))
return 0;
/* Link in now that the allocations have succeeded. */
rrset->next = raddr->data;
raddr->data = rrset;
return 1;
}
static int
@@ -982,7 +996,6 @@ rpz_clientip_insert_trigger_rr(struct clientip_synthesized_rrset* set, struct so
lock_rw_wrlock(&node->lock);
lock_rw_unlock(&set->lock);
node->action = a;
if(a == RPZ_LOCAL_DATA_ACTION) {
if(!rpz_clientip_enter_rr(set->region, node, rrtype,
rrclass, ttl, rdata, rdata_len)) {
@@ -992,6 +1005,7 @@ rpz_clientip_insert_trigger_rr(struct clientip_synthesized_rrset* set, struct so
}
}
node->action = a;
lock_rw_unlock(&node->lock);
@@ -1977,8 +1991,9 @@ rpz_synthesize_nodata(struct rpz* ATTR_UNUSED(r), struct module_qstate* ms,
0, /* total */
sec_status_insecure,
LDNS_EDE_NONE);
if(msg->rep)
msg->rep->authoritative = 1;
if(!msg->rep)
return NULL;
msg->rep->authoritative = 1;
if(!rpz_add_soa(msg->rep, ms, az))
return NULL;
return msg;
@@ -2008,8 +2023,9 @@ rpz_synthesize_nxdomain(struct rpz* r, struct module_qstate* ms,
0, /* total */
sec_status_insecure,
LDNS_EDE_NONE);
if(msg->rep)
msg->rep->authoritative = 1;
if(!msg->rep)
return NULL;
msg->rep->authoritative = 1;
if(!rpz_add_soa(msg->rep, ms, az))
return NULL;
return msg;
@@ -2469,6 +2485,7 @@ rpz_callback_from_iterator_module(struct module_qstate* ms, struct iter_qstate*
{
struct auth_zones* az;
struct auth_zone* a;
struct dns_msg* ret = NULL;
struct clientip_synthesized_rr* raddr = NULL;
struct rpz* r = NULL;
struct local_zone* z = NULL;
@@ -2512,13 +2529,11 @@ rpz_callback_from_iterator_module(struct module_qstate* ms, struct iter_qstate*
z = rpz_delegation_point_zone_lookup(is->dp, r->nsdname_zones,
is->qchase.qclass, &match);
if(z != NULL) {
lock_rw_unlock(&a->lock);
break;
}
raddr = rpz_delegation_point_ipbased_trigger_lookup(r, is);
if(raddr != NULL) {
lock_rw_unlock(&a->lock);
break;
}
lock_rw_unlock(&a->lock);
@@ -2533,9 +2548,12 @@ rpz_callback_from_iterator_module(struct module_qstate* ms, struct iter_qstate*
if(z) {
lock_rw_unlock(&z->lock);
}
return rpz_apply_nsip_trigger(ms, &is->qchase, r, raddr, a);
ret = rpz_apply_nsip_trigger(ms, &is->qchase, r, raddr, a);
} else {
ret = rpz_apply_nsdname_trigger(ms, &is->qchase, r, z, &match, a);
}
return rpz_apply_nsdname_trigger(ms, &is->qchase, r, z, &match, a);
lock_rw_unlock(&a->lock);
return ret;
}
struct dns_msg* rpz_callback_from_iterator_cname(struct module_qstate* ms,
+11 -2
View File
@@ -67,19 +67,28 @@ sldns_rr_dnskey_key_size_raw(const unsigned char* keydata,
case LDNS_RSASHA512:
#endif
if (len > 0) {
size_t nlen, offset;
if (keydata[0] == 0) {
/* big exponent */
if (len > 3) {
memmove(&int16, keydata + 1, 2);
exp = ntohs(int16);
return (len - exp - 3)*8;
offset = 3;
} else {
return 0;
}
} else {
exp = keydata[0];
return (len-exp-1)*8;
offset = 1;
}
if(exp+offset > len)
return 0;
nlen = len - exp - offset;
/* prefixed zeroes mean a smaller value */
while(nlen > 0 &&
keydata[len-nlen] == 0)
nlen--;
return nlen*8;
} else {
return 0;
}
+6 -4
View File
@@ -842,7 +842,8 @@ rrinternal_parse_rdata(sldns_buffer* strbuf, char* token, size_t token_len,
sldns_write_uint16(rr+dname_len+8, (uint16_t)(rr_cur_len-dname_len-10));
*rr_len = rr_cur_len;
/* SVCB/HTTPS handling */
if (rr_type == LDNS_RR_TYPE_SVCB || rr_type == LDNS_RR_TYPE_HTTPS) {
if ((rr_type == LDNS_RR_TYPE_SVCB || rr_type == LDNS_RR_TYPE_HTTPS)
&& !was_unknown_rr_format) {
size_t rdata_len = rr_cur_len - dname_len - 10;
uint8_t *rdata = rr+dname_len + 10;
@@ -1201,7 +1202,7 @@ sldns_str2wire_svcbparam_ipv4hint(const char* val, uint8_t* rd, size_t* rd_len)
{
size_t count;
char ip_str[INET_ADDRSTRLEN+1];
char *next_ip_str;
const char *next_ip_str;
size_t i;
for (i = 0, count = 1; val[i]; i++) {
@@ -1256,7 +1257,7 @@ sldns_str2wire_svcbparam_ipv6hint(const char* val, uint8_t* rd, size_t* rd_len)
{
size_t count;
char ip_str[INET6_ADDRSTRLEN+1];
char *next_ip_str;
const char *next_ip_str;
size_t i;
for (i = 0, count = 1; val[i]; i++) {
@@ -1317,7 +1318,7 @@ static int
sldns_str2wire_svcbparam_mandatory(const char* val, uint8_t* rd, size_t* rd_len)
{
size_t i, count, val_len;
char* next_key;
const char* next_key;
val_len = strlen(val);
@@ -1410,6 +1411,7 @@ sldns_str2wire_svcbparam_ech_value(const char* val, uint8_t* rd, size_t* rd_len)
return LDNS_WIREPARSE_ERR_BUFFER_TOO_SMALL;
sldns_write_uint16(rd, SVCB_KEY_ECH);
sldns_write_uint16(rd + 2, 0);
*rd_len = 4;
return LDNS_WIREPARSE_ERR_OK;
}
+165 -11
View File
@@ -156,7 +156,7 @@ char* wsa_strerror(int err);
#endif
static const char ICANN_UPDATE_CA[] =
/* The ICANN CA fetched at 24 Sep 2010. Valid to 2028 */
/* The ICANN CA fetched at 29 May 2026. Valid to 20 Mar 2045 */
"-----BEGIN CERTIFICATE-----\n"
"MIIDdzCCAl+gAwIBAgIBATANBgkqhkiG9w0BAQsFADBdMQ4wDAYDVQQKEwVJQ0FO\n"
"TjEmMCQGA1UECxMdSUNBTk4gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkxFjAUBgNV\n"
@@ -177,6 +177,40 @@ static const char ICANN_UPDATE_CA[] =
"15nu5JBSewrCkYqYYmaxyOC3WrVGfHZxVI7MpIFcGdvSb2a1uyuua8l0BKgk3ujF\n"
"0/wsHNeP22qNyVO+XVBzrM8fk8BSUFuiT/6tZTYXRtEt5aKQZgXbKU5dUF3jT9qg\n"
"j/Br5BZw3X/zd325TvnswzMC1+ljLzHnQGGk\n"
"-----END CERTIFICATE-----\n"
"\n"
"-----BEGIN CERTIFICATE-----\n"
"MIIFsTCCA5mgAwIBAgIUQFsYkgroBoe69HKQPy8/DQuiLwgwDQYJKoZIhvcNAQEN\n"
"BQAwYDELMAkGA1UEBhMCVVMxDjAMBgNVBAoMBUlDQU5OMSYwJAYDVQQLDB1JQ0FO\n"
"TiBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTEZMBcGA1UEAwwQSUNBTk4gUm9vdCBD\n"
"QSB2MjAeFw0yNTAzMjAyMTA0MjZaFw00NTAzMjAyMTA0MjZaMGAxCzAJBgNVBAYT\n"
"AlVTMQ4wDAYDVQQKDAVJQ0FOTjEmMCQGA1UECwwdSUNBTk4gQ2VydGlmaWNhdGlv\n"
"biBBdXRob3JpdHkxGTAXBgNVBAMMEElDQU5OIFJvb3QgQ0EgdjIwggIiMA0GCSqG\n"
"SIb3DQEBAQUAA4ICDwAwggIKAoICAQCepDjrubjR7en/uZWo7MAnzFIIvUPYEc7b\n"
"+AlefdlEDQ1JEmpfrvt/4CX9lJ9ShIBR6zwrQeDvrj5XZ2kEjbJ8Nnc6sM/ojdyr\n"
"5jSLqcDPH9fJg7jCW02KF8CtqWsnqcW6jjTIZcCWkg9lEixdF8QAjIEgJtZte+Yh\n"
"XeyN0KD2EaO8U5Id0bLvMyphuO1OCGKzDtetcX8K7SvoshdJx3lPIlYzqXl0nVAY\n"
"iCeNdeDzTNjEOHYJOP6dYoZI8nKRJltMkZcCCjBE2vQuSMY2w4pOlWk1skHjMWXj\n"
"QsZzngXuNG56zialL0TPEDVWjWRjzOnruHUAs4KUY8Zs+Nt8JdSlXMi825PKoKpp\n"
"ESs7/ZG1mPjVOYp7Z7ntrRjJFgnUBjWzVPOx4yHiJj1ur+OpqP18oP5YfqY+tKmz\n"
"7vlfRGGOEd08a0XgZISDNKpMAovn5pRUHTWPCCjc28tns9ODPvr1cQi+QSwTv+v8\n"
"wnA5etGrsead88Rv/ieaq5ikMJTRDfW4d9SY2uPcMGvfU6VdQLRhQkzEVTQNAJ1R\n"
"i2lOoJbbjwnK+OU9OhST/OqdjJDJAhTAstdUnrr8WBU80xM75MIaaTjSBCvZ1wro\n"
"pAi2hYb0tedTH6WarSW3MH9HcEoGGzs2GD3hDB0a2eCp+TdAs8Up944SjY7UV4Jx\n"
"sOC7TxbmkQIDAQABo2MwYTAdBgNVHQ4EFgQU+1EuMRuOZ/ecsfYzNQ+yGZsxZrMw\n"
"HwYDVR0jBBgwFoAU+1EuMRuOZ/ecsfYzNQ+yGZsxZrMwDwYDVR0TAQH/BAUwAwEB\n"
"/zAOBgNVHQ8BAf8EBAMCAf4wDQYJKoZIhvcNAQENBQADggIBACz38SkKR1WsEZnX\n"
"x1BKaS5/oQPw+7quDQCKGoD2Vz7CR7yQh4zQn/Hh0173vKvRWcwN2io0iLJ1ysv5\n"
"jXBLeWZh3djiQlXP3iWp4s01SiUwmFssxi3SD1IT2jNosk1xcVWthle9zth7Y8Mp\n"
"iUJYnHobP7tX7H2g+I8Rqw2sEX/yPSYMYcdH5a1xRMPOLHTyOaCgevRBBBtXkiAJ\n"
"Ob9QKZTaFaXntPXBKNSGkVb2d+2qKyJMrwd0KNI+SVSoIgNDAxkNOdi9x6X6ETW2\n"
"4aYFsytohFVkNUXx2eFYRim4yjnD8PHIvDQSofLfSAC5TOERtwUFd+Mw3/di+HCm\n"
"50OJPyoxZLjWQCCfNUZzgZZOe+zT6lgBiV3KB0UuuAdq7jGUeH/328HJDi30BvNj\n"
"+TNb9Hmpm+ZDguM+f8p7GxapX8AVNu/xErtl4msYiVJrr1qqV+qLLEMwIz0raujG\n"
"FFDd6N43wgduffbU20pThry0Y7rku5+RZjUZe/T7ZL+NUKiqXAPufrkqVkjX/8T+\n"
"wyNZz8KkiQwkJthojpppa79FDxn/A2M8tt+FQqIONAUPR2m5nurVgftQH0z5ZtDB\n"
"YykUlkUiPOJNXoDOIkbpA7lW2wezeY4te+EiSeUZSE541N5QBwaItaonIZsIgn6C\n"
"pMnwChV9468oRE20bdqq9+Go7g4E\n"
"-----END CERTIFICATE-----\n";
static const char DS_TRUST_ANCHOR[] =
@@ -1674,18 +1708,116 @@ static unsigned long
get_usage_of_ex(X509* cert)
{
unsigned long val = 0;
#ifdef HAVE_X509_GET_KEY_USAGE
val = X509_get_key_usage(cert);
if (val == UINT32_MAX)
return 0;
#else
ASN1_BIT_STRING* s;
if((s=X509_get_ext_d2i(cert, NID_key_usage, NULL, NULL))) {
if(s->length > 0) {
val = s->data[0];
if(s->length > 1)
val |= s->data[1] << 8;
# ifdef HAVE_ASN1_STRING_GET0_DATA
const unsigned char *data = ASN1_STRING_get0_data(s);
# else
const unsigned char *data = ASN1_STRING_data(s);
# endif
int len = ASN1_STRING_length(s);
if(len > 0) {
val = data[0];
if(len > 1)
val |= data[1] << 8;
}
ASN1_BIT_STRING_free(s);
}
#endif
return val;
}
#if !defined(HAVE_X509_NAME_GET_TEXT_BY_NID) || defined(DEPRECATED_X509_NAME_GET_TEXT_BY_NID)
/** print verbose output about name extension data. */
static void
print_name_ext(
#if OPENSSL_VERSION_NUMBER >= 0x40000000
const
#endif
X509_NAME* nm, int nid, const char* str)
{
int lastpos = -1;
for(;;) {
#if OPENSSL_VERSION_NUMBER >= 0x40000000
const
#endif
X509_NAME_ENTRY* ne;
#if OPENSSL_VERSION_NUMBER >= 0x40000000
const
#endif
ASN1_STRING *asn;
const unsigned char *data;
char buf[1024];
lastpos = X509_NAME_get_index_by_NID(nm, nid, lastpos);
if(lastpos == -1 || lastpos == -2)
break;
ne = X509_NAME_get_entry(nm, lastpos);
if(!ne) continue;
asn = X509_NAME_ENTRY_get_data(ne);
if(!asn) continue;
# ifdef HAVE_ASN1_STRING_GET0_DATA
data = ASN1_STRING_get0_data(asn);
# else
data = ASN1_STRING_data(asn);
# endif
if(!data) continue;
if(ASN1_STRING_length(asn) > (int)sizeof(buf)-1) continue;
memcpy(buf, data, ASN1_STRING_length(asn));
buf[ASN1_STRING_length(asn)]=0;
printf("%s: %s\n", str, buf);
}
}
#endif /* X509_NAME_GET_TEXT_BY_NID */
#if !defined(HAVE_X509_NAME_GET_TEXT_BY_NID) || defined(DEPRECATED_X509_NAME_GET_TEXT_BY_NID)
/** see if the valid emailaddr is present. */
static int
has_valid_emailaddr(
#if OPENSSL_VERSION_NUMBER >= 0x40000000
const
#endif
X509_NAME* nm, const char* p7signer)
{
int lastpos = -1;
for(;;) {
#if OPENSSL_VERSION_NUMBER >= 0x40000000
const
#endif
X509_NAME_ENTRY* ne;
#if OPENSSL_VERSION_NUMBER >= 0x40000000
const
#endif
ASN1_STRING *asn;
const unsigned char *data;
lastpos = X509_NAME_get_index_by_NID(nm,
NID_pkcs9_emailAddress, lastpos);
if(lastpos == -1 || lastpos == -2)
break;
ne = X509_NAME_get_entry(nm, lastpos);
if(!ne) continue;
asn = X509_NAME_ENTRY_get_data(ne);
if(!asn) continue;
# ifdef HAVE_ASN1_STRING_GET0_DATA
data = ASN1_STRING_get0_data(asn);
# else
data = ASN1_STRING_data(asn);
# endif
if(!data) continue;
if(ASN1_STRING_length(asn) == (int)strlen(p7signer) &&
strncmp((char*)data, p7signer, strlen(p7signer)) == 0)
return 1; /* match */
}
return 0;
}
#endif /* X509_NAME_GET_TEXT_BY_NID */
/** get valid signers from the list of signers in the signature */
static STACK_OF(X509)*
get_valid_signers(PKCS7* p7, const char* p7signer)
@@ -1705,6 +1837,9 @@ get_valid_signers(PKCS7* p7, const char* p7signer)
return NULL;
}
for(i=0; i<sk_X509_num(signers); i++) {
#if OPENSSL_VERSION_NUMBER >= 0x40000000
const
#endif
X509_NAME* nm = X509_get_subject_name(
sk_X509_value(signers, i));
char buf[1024];
@@ -1717,17 +1852,29 @@ get_valid_signers(PKCS7* p7, const char* p7signer)
(int)sizeof(buf));
printf("signer %d: Subject: %s\n", i,
nmline?nmline:"no subject");
#if !defined(HAVE_X509_NAME_GET_TEXT_BY_NID) || defined(DEPRECATED_X509_NAME_GET_TEXT_BY_NID)
if(verb >= 3) {
print_name_ext(nm, NID_commonName,
"commonName");
print_name_ext(nm, NID_pkcs9_emailAddress,
"emailAddress");
}
#else
if(verb >= 3 && X509_NAME_get_text_by_NID(nm,
NID_commonName, buf, (int)sizeof(buf)))
NID_commonName, buf, (int)sizeof(buf)) > 0)
printf("commonName: %s\n", buf);
if(verb >= 3 && X509_NAME_get_text_by_NID(nm,
NID_pkcs9_emailAddress, buf, (int)sizeof(buf)))
NID_pkcs9_emailAddress, buf, (int)sizeof(buf)) > 0)
printf("emailAddress: %s\n", buf);
#endif
}
if(verb) {
int ku_loc = X509_get_ext_by_NID(
sk_X509_value(signers, i), NID_key_usage, -1);
if(verb >= 3 && ku_loc >= 0) {
#if OPENSSL_VERSION_NUMBER >= 0x40000000
const
#endif
X509_EXTENSION *ex = X509_get_ext(
sk_X509_value(signers, i), ku_loc);
if(ex) {
@@ -1741,16 +1888,23 @@ get_valid_signers(PKCS7* p7, const char* p7signer)
/* there is no name to check, return all records */
if(verb) printf("did not check commonName of signer\n");
} else {
if(!X509_NAME_get_text_by_NID(nm,
#if !defined(HAVE_X509_NAME_GET_TEXT_BY_NID) || defined(DEPRECATED_X509_NAME_GET_TEXT_BY_NID)
if(!has_valid_emailaddr(nm, p7signer)) {
if(verb) printf("removed cert with wrong emailaddress\n");
continue; /* wrong name, skip it */
}
#else
if(X509_NAME_get_text_by_NID(nm,
NID_pkcs9_emailAddress,
buf, (int)sizeof(buf))) {
if(verb) printf("removed cert with no name\n");
buf, (int)sizeof(buf)) <= 0) {
if(verb) printf("removed cert with no emailaddress\n");
continue; /* no name, no use */
}
if(strcmp(buf, p7signer) != 0) {
if(verb) printf("removed cert with wrong name\n");
if(verb) printf("removed cert with wrong emailaddress\n");
continue; /* wrong name, skip it */
}
#endif
}
/* check that the key usage allows digital signatures
+120
View File
@@ -73,6 +73,9 @@
#ifdef HAVE_GLOB_H
#include <glob.h>
#endif
#ifdef HAVE_FNMATCH_H
#include <fnmatch.h>
#endif
#ifdef WITH_PYTHONMODULE
#include "pythonmod/pythonmod.h"
#endif
@@ -728,6 +731,122 @@ check_modules_exist(const char* module_conf)
}
}
#ifdef USE_IPSECMOD
/** Compare filename with string, true if it matches the name. */
static int
file_string_matches(char* str, char* fname, struct config_file* cfg)
{
char* f;
if(!str || str[0] == 0)
return 0;
/* compare name after chroot and working dir are applied */
f = fname_after_chroot(str, cfg, 1);
if(!f) fatal_exit("out of memory");
if(strcmp(fname, f) == 0) {
free(f);
return 1;
}
free(f);
return 0;
}
#endif /* USE_IPSECMOD */
/** Compare filename with list of files, true if list contains the name. */
static int
file_list_contains(struct config_strlist* list, char* fname,
struct config_file* cfg)
{
struct config_strlist* s;
char* f;
for(s = list; s; s = s->next) {
if(!s->str || s->str[0] == 0)
continue; /* skip if no file name */
/* compare names after chroot and working dir are applied */
f = fname_after_chroot(s->str, cfg, 1);
if(!f) fatal_exit("out of memory");
if(strcmp(fname, f) == 0) {
free(f);
return 1;
}
free(f);
}
return 0;
}
/** Compare filename with list of files, true if list contains the name,
* with glob compare. */
static int
file_list_contains_wild(struct config_strlist* list, char* fname,
struct config_file* cfg)
{
struct config_strlist* s;
char* f;
for(s = list; s; s = s->next) {
if(!s->str || s->str[0] == 0)
continue; /* skip if no file name */
/* compare names after chroot and working dir are applied */
f = fname_after_chroot(s->str, cfg, 1);
if(!f) fatal_exit("out of memory");
if(strcmp(fname, f) == 0) {
free(f);
return 1;
}
#ifdef HAVE_FNMATCH
if(fnmatch(f, fname, 0) == 0) {
log_err("trusted-keys-file: \"%s\" matches zonefile '%s'",
s->str, fname);
free(f);
return 1;
}
#endif
free(f);
}
return 0;
}
/** Check if the auth-zone/rpz zonefile: conflicts with other files,
* so it would overwrite that file. Refuse it aliasing any read-side bootstrap
* file. */
static void
check_file_clobber(struct config_file* cfg)
{
struct config_auth* p;
char* zfile, *sourceopt = NULL;
for(p = cfg->auths; p; p = p->next) {
if(!p->name || p->name[0] == 0)
continue; /* skip if no name */
if(!p->zonefile || p->zonefile[0]==0)
continue; /* no zone file */
zfile = fname_after_chroot(p->zonefile, cfg, 1);
if(!zfile) fatal_exit("out of memory");
if(file_list_contains(cfg->auto_trust_anchor_file_list, zfile,
cfg))
sourceopt = "auto-trust-anchor-file";
else if(file_list_contains(cfg->trust_anchor_file_list, zfile,
cfg))
sourceopt = "trust-anchor-file";
else if(file_list_contains_wild(cfg->trusted_keys_file_list,
zfile, cfg))
sourceopt = "trusted-keys-file";
else if(file_list_contains(cfg->root_hints, zfile, cfg))
sourceopt = "root-hints";
else if(file_list_contains(cfg->tls_session_ticket_keys.first,
zfile, cfg))
sourceopt = "tls-session-ticket-keys";
#ifdef USE_IPSECMOD
if(cfg->ipsecmod_enabled &&
file_string_matches(cfg->ipsecmod_hook, zfile, cfg))
sourceopt = "ipsecmod-hook";
#endif
if(sourceopt)
fatal_exit("auth-zone '%s': zonefile \"%s\" "
"is the same path as a %s option. "
"The auth-zone transfer would overwrite it.",
p->name, p->zonefile, sourceopt);
free(zfile);
}
}
/** check configuration for errors */
static void
morechecks(struct config_file* cfg)
@@ -822,6 +941,7 @@ morechecks(struct config_file* cfg)
cfg->chrootdir, cfg);
}
#endif
check_file_clobber(cfg);
/* remove chroot setting so that modules are not stripping pathnames */
free(cfg->chrootdir);
cfg->chrootdir = NULL;
+9 -2
View File
@@ -43,6 +43,7 @@
#include "config.h"
#include "libunbound/context.h"
#include "libunbound/worker.h"
#include "libunbound/remote.h"
#include "util/fptr_wlist.h"
#include "util/log.h"
#include "services/mesh.h"
@@ -102,7 +103,7 @@ struct outbound_entry* worker_send_query(
socklen_t ATTR_UNUSED(addrlen), uint8_t* ATTR_UNUSED(zone),
size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream), int ATTR_UNUSED(ssl_upstream),
char* ATTR_UNUSED(tls_auth_name), struct module_qstate* ATTR_UNUSED(q),
int* ATTR_UNUSED(was_ratelimited))
int* ATTR_UNUSED(was_ratelimited), int* ATTR_UNUSED(ratelimit_incremented))
{
log_assert(0);
return 0;
@@ -128,6 +129,12 @@ worker_alloc_cleanup(void* ATTR_UNUSED(arg))
log_assert(0);
}
void
libworker_alloc_cleanup(void* ATTR_UNUSED(arg))
{
log_assert(0);
}
struct outbound_entry* libworker_send_query(
struct query_info* ATTR_UNUSED(qinfo), uint16_t ATTR_UNUSED(flags),
int ATTR_UNUSED(dnssec), int ATTR_UNUSED(want_dnssec),
@@ -136,7 +143,7 @@ struct outbound_entry* libworker_send_query(
socklen_t ATTR_UNUSED(addrlen), uint8_t* ATTR_UNUSED(zone),
size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream), int ATTR_UNUSED(ssl_upstream),
char* ATTR_UNUSED(tls_auth_name), struct module_qstate* ATTR_UNUSED(q),
int* ATTR_UNUSED(was_ratelimited))
int* ATTR_UNUSED(was_ratelimited), int* ATTR_UNUSED(ratelimit_incremented))
{
log_assert(0);
return 0;
+12 -3
View File
@@ -146,7 +146,9 @@ submit_query(struct http2_session* h2_session, struct sldns_buffer* buf)
{
int32_t stream_id;
struct http2_stream* h2_stream;
nghttp2_nv headers[5];
nghttp2_nv headers[6];
size_t num_headers = 5;
char clen[16];
char* qb64;
size_t qb64_size;
size_t qb64_expected_size;
@@ -194,9 +196,16 @@ submit_query(struct http2_session* h2_session, struct sldns_buffer* buf)
headers[3].value = (uint8_t*)h2_session->authority;
headers[4].name = (uint8_t*)"content-type";
headers[4].value = (uint8_t*)h2_session->content_type;
if(h2_session->post) {
snprintf(clen, sizeof(clen), "%u",
(unsigned)sldns_buffer_remaining(buf));
headers[5].name = (uint8_t*)"content-length";
headers[5].value = (uint8_t*)clen;
num_headers = 6;
}
printf("Request headers\n");
for(i=0; i<sizeof(headers)/sizeof(headers[0]); i++) {
for(i=0; i<num_headers; i++) {
headers[i].namelen = strlen((char*)headers[i].name);
headers[i].valuelen = strlen((char*)headers[i].value);
headers[i].flags = NGHTTP2_NV_FLAG_NONE;
@@ -204,7 +213,7 @@ submit_query(struct http2_session* h2_session, struct sldns_buffer* buf)
}
stream_id = nghttp2_submit_request(h2_session->session, NULL, headers,
sizeof(headers)/sizeof(headers[0]),
num_headers,
(h2_session->post) ? &data_prd : NULL, h2_stream);
if(stream_id < 0) {
printf("Failed to submit nghttp2 request");
+17 -7
View File
@@ -1137,8 +1137,11 @@ static struct ngtcp2_conn* conn_client_setup(struct doq_client_data* data)
client_chosen_version, &cbs, &settings, &params,
NULL, /* ngtcp2_mem allocator, use default */
data /* callback argument */);
if(!conn) fatal_exit("could not ngtcp2_conn_client_new: %s",
ngtcp2_strerror(rv));
if(rv!=0) {
conn = NULL;
fatal_exit("could not ngtcp2_conn_client_new: %s",
ngtcp2_strerror(rv));
}
data->cc_algo = settings.cc_algo;
return conn;
}
@@ -1519,9 +1522,9 @@ doq_client_send_pkt(struct doq_client_data* data, uint32_t ecn, uint8_t* buf,
}
log_err("doq sendmsg: %s", strerror(errno));
#ifdef HAVE_NGTCP2_CCERR_DEFAULT
ngtcp2_ccerr_set_application_error(&data->ccerr, -1, NULL, 0);
ngtcp2_ccerr_set_application_error(&data->ccerr, 1, NULL, 0);
#else
ngtcp2_connection_close_error_set_application_error(&data->last_error, -1, NULL, 0);
ngtcp2_connection_close_error_set_application_error(&data->last_error, 1, NULL, 0);
#endif
return 0;
}
@@ -2098,7 +2101,7 @@ early_data_setup_session(struct doq_client_data* data)
SSL_SESSION_free(session);
return 0;
}
#ifdef USE_NGTCP2_CRYPTO_OSSL
#ifdef HAVE_SSL_SET_QUIC_TLS_EARLY_DATA_ENABLED
SSL_set_quic_tls_early_data_enabled(data->ssl, 1);
#else
SSL_set_quic_early_data_enabled(data->ssl, 1);
@@ -2595,7 +2598,8 @@ struct outbound_entry* worker_send_query(
socklen_t ATTR_UNUSED(addrlen), uint8_t* ATTR_UNUSED(zone),
size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream),
int ATTR_UNUSED(ssl_upstream), char* ATTR_UNUSED(tls_auth_name),
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited))
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited),
int* ATTR_UNUSED(ratelimit_incremented))
{
log_assert(0);
return 0;
@@ -2629,7 +2633,8 @@ struct outbound_entry* libworker_send_query(
socklen_t ATTR_UNUSED(addrlen), uint8_t* ATTR_UNUSED(zone),
size_t ATTR_UNUSED(zonelen), int ATTR_UNUSED(tcp_upstream),
int ATTR_UNUSED(ssl_upstream), char* ATTR_UNUSED(tls_auth_name),
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited))
struct module_qstate* ATTR_UNUSED(q), int* ATTR_UNUSED(was_ratelimited),
int* ATTR_UNUSED(ratelimit_incremented))
{
log_assert(0);
return 0;
@@ -2671,6 +2676,11 @@ void libworker_event_done_cb(void* ATTR_UNUSED(arg), int ATTR_UNUSED(rcode),
log_assert(0);
}
void libworker_alloc_cleanup(void* ATTR_UNUSED(arg))
{
log_assert(0);
}
int context_query_cmp(const void* ATTR_UNUSED(a), const void* ATTR_UNUSED(b))
{
log_assert(0);
+29 -4
View File
@@ -1126,15 +1126,16 @@ outside_network_create(struct comm_base* base, size_t bufsize,
int ATTR_UNUSED(dscp),
struct infra_cache* infra,
struct ub_randstate* ATTR_UNUSED(rnd),
int ATTR_UNUSED(use_caps_for_id), int* ATTR_UNUSED(availports),
int ATTR_UNUSED(numavailports), size_t ATTR_UNUSED(unwanted_threshold),
int ATTR_UNUSED(use_caps_for_id),
size_t ATTR_UNUSED(unwanted_threshold),
int ATTR_UNUSED(outgoing_tcp_mss),
void (*unwanted_action)(void*), void* ATTR_UNUSED(unwanted_param),
int ATTR_UNUSED(do_udp), void* ATTR_UNUSED(sslctx),
int ATTR_UNUSED(delayclose), int ATTR_UNUSED(tls_use_sni),
struct dt_env* ATTR_UNUSED(dtenv), int ATTR_UNUSED(udp_connect),
int ATTR_UNUSED(max_reuse_tcp_queries), int ATTR_UNUSED(tcp_reuse_timeout),
int ATTR_UNUSED(tcp_auth_query_timeout))
int ATTR_UNUSED(tcp_auth_query_timeout),
struct shared_ports* ATTR_UNUSED(shared_ports))
{
struct replay_runtime* runtime = (struct replay_runtime*)base;
struct outside_network* outnet = calloc(1,
@@ -1275,7 +1276,8 @@ struct serviced_query* outnet_serviced_query(struct outside_network* outnet,
socklen_t addrlen, uint8_t* zone, size_t zonelen,
struct module_qstate* qstate, comm_point_callback_type* callback,
void* callback_arg, sldns_buffer* ATTR_UNUSED(buff),
struct module_env* env, int* ATTR_UNUSED(was_ratelimited))
struct module_env* env, int* ATTR_UNUSED(was_ratelimited),
int* ATTR_UNUSED(ratelimit_incremented))
{
struct replay_runtime* runtime = (struct replay_runtime*)outnet->base;
struct fake_pending* pend = (struct fake_pending*)calloc(1,
@@ -1980,6 +1982,20 @@ int outnet_tcp_connect(int ATTR_UNUSED(s), struct sockaddr_storage* ATTR_UNUSED(
return 0;
}
struct shared_ports* shared_ports_create(char** ATTR_UNUSED(ifs),
int ATTR_UNUSED(num_ifs), int ATTR_UNUSED(do_ip4),
int ATTR_UNUSED(do_ip6), int* ATTR_UNUSED(availports),
int ATTR_UNUSED(numavailports))
{
return calloc(1, sizeof(struct shared_ports));
}
void shared_ports_delete(struct shared_ports* shp)
{
if(!shp) return;
free(shp);
}
int tcp_req_info_add_meshstate(struct tcp_req_info* ATTR_UNUSED(req),
struct mesh_area* ATTR_UNUSED(mesh), struct mesh_state* ATTR_UNUSED(m))
{
@@ -2021,6 +2037,15 @@ void http2_stream_remove_mesh_state(struct http2_stream* ATTR_UNUSED(h2_stream))
{
}
void doq_stream_add_meshstate(struct doq_stream* ATTR_UNUSED(stream),
struct mesh_area* ATTR_UNUSED(mesh), struct mesh_state* ATTR_UNUSED(m))
{
}
void doq_stream_remove_mesh_state(struct doq_stream* ATTR_UNUSED(stream))
{
}
void fast_reload_service_cb(int ATTR_UNUSED(fd), short ATTR_UNUSED(event),
void* ATTR_UNUSED(arg))
{
+3
View File
@@ -264,6 +264,9 @@ setup_config(FILE* in, int* lineno, int* pass_argc, char* pass_argv[])
fprintf(cfg, " pidfile: \"\"\n");
fprintf(cfg, " val-log-level: 2\n");
fprintf(cfg, " log-servfail: yes\n");
/* the extra thread needs pipe communication that is not available
* from fake_event calls. So auth-task-threads: 0 disables them. */
fprintf(cfg, " auth-task-threads: 0\n");
fprintf(cfg, "remote-control: control-enable: no\n");
while(fgets(line, MAX_LINE_LEN-1, in)) {
parse = line;
+33
View File
@@ -1027,6 +1027,38 @@ authzone_query_test(void)
check_queries("example.com", zone_example_com, example_com_queries);
}
/** Test chunkline_count_parens output */
static void
authzone_chunkline_count_parens_test(void)
{
sldns_buffer* buf;
if(vbmp) printf("Testing chunkline_count_parens\n");
buf = sldns_buffer_new(1024);
if(!buf) fatal_exit("out of memory");
/* Check that escaped characters are handled, '\x', and in quotes. */
sldns_buffer_printf(buf, "TXT \"x\" \\(");
unit_assert(chunkline_count_parens(buf, 0) == 0);
sldns_buffer_clear(buf);
sldns_buffer_printf(buf, "TXT ';x' (");
unit_assert(chunkline_count_parens(buf, 0) == 0);
sldns_buffer_clear(buf);
sldns_buffer_printf(buf, "TXT \"a;b\" (");
unit_assert(chunkline_count_parens(buf, 0) == 1);
sldns_buffer_clear(buf);
sldns_buffer_printf(buf, "TXT \\) )");
unit_assert(chunkline_count_parens(buf, 0) == -1);
sldns_buffer_clear(buf);
sldns_buffer_printf(buf, "TXT \"a\\\\\" \"(\" ");
unit_assert(chunkline_count_parens(buf, 0) == 0);
sldns_buffer_free(buf);
}
/** test authzone code */
void
authzone_test(void)
@@ -1036,4 +1068,5 @@ authzone_test(void)
authzone_compare_serial();
authzone_read_test();
authzone_query_test();
authzone_chunkline_count_parens_test();
}
+1
View File
@@ -141,6 +141,7 @@ static addrlen_t randomkey(addrkey_t **k, int maxlen)
int bits = rand() % maxlen;
int bytes = bits/8 + (bits%8>0); /*ceil*/
*k = (addrkey_t *) malloc(bytes * sizeof(addrkey_t));
if(!*k) fatal_exit("out of memory");
for (byte = 0; byte < bytes; byte++) {
(*k)[byte] = (addrkey_t)(rand() & 0xFF);
}
+14
View File
@@ -279,10 +279,24 @@ b64_test(void)
unit_assert(result == -1);
}
/** test SVCB ech svcparam */
static void
svcb_ech_test(void)
{
uint8_t rr[LDNS_RR_BUF_SIZE];
size_t rr_len = sizeof(rr), dname_len = 0;
int e = sldns_str2wire_rr_buf("x. 300 IN HTTPS 1 . ech=0",
rr, &rr_len, &dname_len, 300, NULL, 0, NULL, 0);
unit_assert(e == LDNS_WIREPARSE_ERR_OK);
unit_assert(rr_len == dname_len + 10 /* type,class,ttl,rdatalen */ + 7 /* rdata */);
unit_assert(sldns_read_uint16(rr + dname_len + 8 /* rdlen */) == 7);
}
void
ldns_test(void)
{
unit_show_feature("sldns");
rr_tests();
b64_test();
svcb_ech_test();
}
+145 -2
View File
@@ -1092,7 +1092,7 @@ static void edns_ede_encode_notxt_fit_test( struct query_info* qinfo,
{
struct edns_data edns;
sldns_buffer* pkt;
uint16_t edns_field_size, ede_txt_size;
size_t edns_field_size, ede_txt_size;
int found_ede = 0, found_ede_other = 0, found_ede_txt = 0;
int found_other_edns = 0;
edns_ede_encode_setup(&edns, region);
@@ -1123,7 +1123,7 @@ static void edns_ede_encode_no_fit_test( struct query_info* qinfo,
{
struct edns_data edns;
sldns_buffer* pkt;
uint16_t edns_field_size, ede_size, ede_txt_size;
size_t edns_field_size, ede_size, ede_txt_size;
int found_ede = 0, found_ede_other = 0, found_ede_txt = 0;
int found_other_edns = 0;
edns_ede_encode_setup(&edns, region);
@@ -1282,6 +1282,144 @@ static void localzone_test(void)
localzone_parents_test();
}
#include "services/mesh.h"
/** mesh unit tests */
static void mesh_test(void)
{
struct regional* r2, *r3;
struct respip_client_info* c1, *c2, *c3;
unit_show_func("services/mesh.c", "mesh_copy_client_info");
r2 = regional_create();
r3 = regional_create();
if(!r2 || !r3) fatal_exit("out of memory");
c1 = calloc(1, sizeof(*c1));
if(!c1) fatal_exit("out of memory");
c1->view = calloc(1, sizeof(*c1->view));
if(!c1->view) fatal_exit("out of memory");
c1->view->name = strdup("view1");
if(!c1->view->name) fatal_exit("out of memory");
c2 = mesh_copy_client_info(r2, c1);
if(!c2) fatal_exit("out of memory");
c3 = mesh_copy_client_info(r3, c2);
if(!c3) fatal_exit("out of memory");
unit_assert(strcmp(c1->view->name, c2->view_name) == 0);
unit_assert(strcmp(c1->view->name, c3->view_name) == 0);
/* make sure that the c3 view_name is in the r3 region. */
unit_assert(r3->next == NULL); /* only the first chunk present atm */
if(strlen(c3->view_name) >= r3->large_object_size) {
char* a = r3->large_list;
int found = 0;
while(a) {
if(strcmp(c3->view_name,
a + /* ALIGNEMENT */ sizeof(uint64_t)) == 0) {
found = 1;
break;
}
a = *(char**)a;
}
unit_assert(found == 1);
} else {
/* The allocation is expected in the r3 region first chunk */
unit_assert((uint8_t*)c3->view_name < ((uint8_t*)r3)+r3->first_size);
}
regional_destroy(r2);
/* ASAN should complain for the freed access below */
unit_assert(strcmp(c1->view->name, c3->view_name) == 0);
regional_destroy(r3);
free(c1->view->name);
free(c1->view);
free(c1);
}
#include "util/data/packed_rrset.h"
#include "sldns/sbuffer.h"
/** packed_rrset unit tests */
static void packed_rrset_test(void)
{
/* packed_rr_to_string assembles the dname, type, class, ttl and
* rdata of one rr into a buffer of 65535 bytes. Check that it
* refuses an rr that does not fit in there, also when the caller
* passes a dest_len that is larger than that, like the callers in
* daemon/cachedump.c and daemon/remote.c do. Without the check it
* writes past the end of the assembly buffer. */
uint8_t smalldname[] = "\003www\007example\003com";
uint8_t smallrdata[] = {0, 4, 1, 2, 3, 4};
uint8_t maxdname[LDNS_MAX_DOMAINLEN];
struct ub_packed_rrset_key rrk;
struct packed_rrset_data d;
uint8_t* rr_data[1];
size_t rr_len[1];
time_t rr_ttl[1];
size_t dest_len = 65535*4+2048; /* the size daemon/cachedump.c uses */
char* dest = (char*)malloc(dest_len);
int i;
unit_show_func("util/data/packed_rrset.c", "packed_rr_to_string");
if(!dest) fatal_exit("out of memory");
memset(&rrk, 0, sizeof(rrk));
memset(&d, 0, sizeof(d));
rrk.entry.data = &d;
rrk.rk.rrset_class = htons(LDNS_RR_CLASS_IN);
d.count = 1;
d.rr_len = rr_len;
d.rr_ttl = rr_ttl;
d.rr_data = rr_data;
rr_ttl[0] = 3600;
/* an ordinary rr is printed, also with the large dest_len */
rrk.rk.dname = smalldname;
rrk.rk.dname_len = sizeof(smalldname);
rrk.rk.type = htons(LDNS_RR_TYPE_A);
rr_data[0] = smallrdata;
rr_len[0] = sizeof(smallrdata);
unit_assert(packed_rr_to_string(&rrk, 0, 0, dest, dest_len) == 1);
unit_assert(strstr(dest, "1.2.3.4") != NULL);
/* a dname of the maximum length, 127 labels of one character */
for(i=0; i<127; i++) {
maxdname[i*2] = 1;
maxdname[i*2+1] = (uint8_t)'a';
}
maxdname[254] = 0;
rrk.rk.dname = maxdname;
rrk.rk.dname_len = sizeof(maxdname);
rrk.rk.type = htons(LDNS_RR_TYPE_TXT);
/* 255+2+2+4+65272 is exactly 65535, that still fits */
rr_len[0] = 65535 - 255 - 8;
rr_data[0] = (uint8_t*)calloc(1, rr_len[0]);
if(!rr_data[0]) fatal_exit("out of memory");
sldns_write_uint16(rr_data[0], (uint16_t)(rr_len[0]-2));
unit_assert(packed_rr_to_string(&rrk, 0, 0, dest, dest_len) == 1);
free(rr_data[0]);
/* one more byte of rdata does not fit and must be refused */
rr_len[0] = 65535 - 255 - 8 + 1;
rr_data[0] = (uint8_t*)calloc(1, rr_len[0]);
if(!rr_data[0]) fatal_exit("out of memory");
sldns_write_uint16(rr_data[0], (uint16_t)(rr_len[0]-2));
unit_assert(packed_rr_to_string(&rrk, 0, 0, dest, dest_len) == 0);
unit_assert(dest[0] == 0);
free(rr_data[0]);
/* the largest rdata an rr can hold, well over the buffer */
rr_len[0] = 2 + 65535;
rr_data[0] = (uint8_t*)calloc(1, rr_len[0]);
if(!rr_data[0]) fatal_exit("out of memory");
sldns_write_uint16(rr_data[0], 65535);
unit_assert(packed_rr_to_string(&rrk, 0, 0, dest, dest_len) == 0);
unit_assert(dest[0] == 0);
free(rr_data[0]);
free(dest);
}
void unit_show_func(const char* file, const char* func)
{
printf("test %s:%s\n", file, func);
@@ -1354,8 +1492,10 @@ main(int argc, char* argv[])
zonemd_test();
tcpreuse_test();
msgparse_test();
packed_rrset_test();
edns_ede_answer_encode_test();
localzone_test();
mesh_test();
#ifdef CLIENT_SUBNET
ecs_test();
#endif /* CLIENT_SUBNET */
@@ -1389,6 +1529,9 @@ main(int argc, char* argv[])
# ifdef HAVE_RAND_CLEANUP
RAND_cleanup();
# endif
#ifdef HAVE_OPENSSL_CLEANUP
OPENSSL_cleanup();
#endif
#elif defined(HAVE_NSS)
if(NSS_Shutdown() != SECSuccess)
fatal_exit("could not shutdown NSS");
+276
View File
@@ -41,6 +41,7 @@
#include "config.h"
#include "testcode/unitmain.h"
#include "util/log.h"
#include "util/net_help.h"
#include "util/random.h"
#include "services/outside_network.h"
@@ -479,6 +480,278 @@ static void reuse_write_wait_test(void)
check_reuse_write_wait_removal(1, &reuse, store, 0, 1);
}
static void shared_port_test_ifs(void)
{
struct shared_ports* shp;
struct shared_ports_if* shpif;
char* ifs[] = {"1.2.3.4", "1.2.3.5", "::1:2", "::1:3"};
int availports[] = {1, 2, 3, 4};
struct sockaddr_storage addr;
socklen_t addrlen;
shp = shared_ports_create(ifs, 4, 1, 1, availports, 4);
unit_assert(shp);
if(!ipstrtoaddr("1.2.3.4", UNBOUND_DNS_PORT, &addr, &addrlen))
log_err("could not parse");
shpif = shared_ports_find_if(shp, &addr, addrlen, 0);
unit_assert(shpif);
if(!ipstrtoaddr("1.2.3.5", UNBOUND_DNS_PORT, &addr, &addrlen))
log_err("could not parse");
shpif = shared_ports_find_if(shp, &addr, addrlen, 0);
unit_assert(shpif);
if(!ipstrtoaddr("::1:2", UNBOUND_DNS_PORT, &addr, &addrlen))
log_err("could not parse");
shpif = shared_ports_find_if(shp, &addr, addrlen, 0);
unit_assert(shpif);
if(!ipstrtoaddr("::1:3", UNBOUND_DNS_PORT, &addr, &addrlen))
log_err("could not parse");
shpif = shared_ports_find_if(shp, &addr, addrlen, 0);
unit_assert(shpif);
shared_ports_delete(shp);
}
/** See if a port is on the shared_ports ports list */
static int
pif_list_contains(struct shared_ports_if* shpif, int item)
{
int i;
unit_assert(shpif->inuse >= 0 && shpif->inuse <= shpif->avail_total);
for(i=0; i< shpif->avail_total - shpif->inuse; i++) {
if(shpif->avail_ports[i] == item)
return 1;
}
return 0;
}
/** See if a number of ports are on the shared_ports list */
static int
pif_list_contains_items(struct shared_ports_if* shpif, int item1,
int item2, int item3, int item4)
{
if(item1 != -1 && !pif_list_contains(shpif, item1))
return 0;
if(item2 != -1 && !pif_list_contains(shpif, item2))
return 0;
if(item3 != -1 && !pif_list_contains(shpif, item3))
return 0;
if(item4 != -1 && !pif_list_contains(shpif, item4))
return 0;
return 1;
}
static void shared_port_test_port(void)
{
struct shared_ports* shp;
struct shared_ports_if* shpif;
char* ifs[] = {"1.2.3.4", "1.2.3.5"};
int availports[] = {1, 2, 3, 4};
struct sockaddr_storage addr;
socklen_t addrlen;
int p1, p2, p3, reused;
struct ub_randstate* rnd;
rnd = ub_initstate(NULL);
unit_assert(rnd);
shp = shared_ports_create(ifs, 2, 1, 1, availports, 4);
unit_assert(shp);
if(!ipstrtoaddr("1.2.3.4", UNBOUND_DNS_PORT, &addr, &addrlen))
log_err("could not parse");
shpif = shared_ports_find_if(shp, &addr, addrlen, 0);
unit_assert(shpif);
unit_assert(shpif->avail_total == 4);
unit_assert(shpif->inuse == 0);
unit_assert(pif_list_contains_items(shpif, 1, 2, 3, 4));
if(!shared_ports_fetch_random(shp, shpif, rnd,
0, 0, &p1, &reused)) {
unit_assert(0); /* should succeed */
}
unit_assert(reused == 0);
unit_assert(p1 != 0);
unit_assert(!pif_list_contains(shpif, p1));
if(p1 != 1) unit_assert(pif_list_contains(shpif, 1));
if(p1 != 2) unit_assert(pif_list_contains(shpif, 2));
if(p1 != 3) unit_assert(pif_list_contains(shpif, 3));
if(p1 != 4) unit_assert(pif_list_contains(shpif, 4));
unit_assert(shpif->avail_total == 4);
unit_assert(shpif->inuse == 1);
shared_ports_return_port(shp, shpif, p1);
unit_assert(shpif->avail_total == 4);
unit_assert(shpif->inuse == 0);
unit_assert(pif_list_contains_items(shpif, 1, 2, 3, 4));
/* pick up two items */
if(!shared_ports_fetch_random(shp, shpif, rnd,
0, 0, &p1, &reused)) {
unit_assert(0); /* should succeed */
}
unit_assert(reused == 0);
unit_assert(p1 != 0);
if(!shared_ports_fetch_random(shp, shpif, rnd,
0, 0, &p2, &reused)) {
unit_assert(0); /* should succeed */
}
unit_assert(reused == 0);
unit_assert(p2 != 0);
unit_assert(!pif_list_contains(shpif, p1));
unit_assert(!pif_list_contains(shpif, p2));
if(p1 != 1 && p2 != 1) unit_assert(pif_list_contains(shpif, 1));
if(p1 != 2 && p2 != 2) unit_assert(pif_list_contains(shpif, 2));
if(p1 != 3 && p2 != 3) unit_assert(pif_list_contains(shpif, 3));
if(p1 != 4 && p2 != 4) unit_assert(pif_list_contains(shpif, 4));
unit_assert(shpif->avail_total == 4);
unit_assert(shpif->inuse == 2);
shared_ports_return_port(shp, shpif, p1);
unit_assert(pif_list_contains(shpif, p1));
unit_assert(shpif->avail_total == 4);
unit_assert(shpif->inuse == 1);
shared_ports_return_port(shp, shpif, p2);
unit_assert(pif_list_contains(shpif, p2));
unit_assert(shpif->avail_total == 4);
unit_assert(shpif->inuse == 0);
unit_assert(pif_list_contains_items(shpif, 1, 2, 3, 4));
/* pick up three items */
if(!shared_ports_fetch_random(shp, shpif, rnd,
0, 0, &p1, &reused)) {
unit_assert(0); /* should succeed */
}
unit_assert(reused == 0);
unit_assert(p1 != 0);
if(!shared_ports_fetch_random(shp, shpif, rnd,
0, 0, &p2, &reused)) {
unit_assert(0); /* should succeed */
}
unit_assert(reused == 0);
unit_assert(p2 != 0);
if(!shared_ports_fetch_random(shp, shpif, rnd,
0, 0, &p3, &reused)) {
unit_assert(0); /* should succeed */
}
unit_assert(reused == 0);
unit_assert(p3 != 0);
unit_assert(!pif_list_contains(shpif, p1));
unit_assert(!pif_list_contains(shpif, p2));
unit_assert(!pif_list_contains(shpif, p3));
if(p1 != 1 && p2 != 1 && p3 != 1)
unit_assert(pif_list_contains(shpif, 1));
if(p1 != 2 && p2 != 2 && p3 != 2)
unit_assert(pif_list_contains(shpif, 2));
if(p1 != 3 && p2 != 3 && p3 != 3)
unit_assert(pif_list_contains(shpif, 3));
if(p1 != 4 && p2 != 4 && p3 != 4)
unit_assert(pif_list_contains(shpif, 4));
unit_assert(shpif->avail_total == 4);
unit_assert(shpif->inuse == 3);
shared_ports_return_port(shp, shpif, p1);
unit_assert(pif_list_contains(shpif, p1));
unit_assert(shpif->avail_total == 4);
unit_assert(shpif->inuse == 2);
shared_ports_return_port(shp, shpif, p2);
unit_assert(pif_list_contains(shpif, p2));
unit_assert(shpif->avail_total == 4);
unit_assert(shpif->inuse == 1);
shared_ports_return_port(shp, shpif, p3);
unit_assert(pif_list_contains(shpif, p3));
unit_assert(shpif->avail_total == 4);
unit_assert(shpif->inuse == 0);
unit_assert(pif_list_contains_items(shpif, 1, 2, 3, 4));
/* pick up all four items */
if(!shared_ports_fetch_random(shp, shpif, rnd,
0, 0, &p1, &reused)) {
unit_assert(0); /* should succeed */
}
unit_assert(reused == 0);
unit_assert(p1 != 0);
if(!shared_ports_fetch_random(shp, shpif, rnd,
0, 0, &p1, &reused)) {
unit_assert(0); /* should succeed */
}
unit_assert(reused == 0);
unit_assert(p1 != 0);
if(!shared_ports_fetch_random(shp, shpif, rnd,
0, 0, &p1, &reused)) {
unit_assert(0); /* should succeed */
}
unit_assert(reused == 0);
unit_assert(p1 != 0);
if(!shared_ports_fetch_random(shp, shpif, rnd,
0, 0, &p1, &reused)) {
unit_assert(0); /* should succeed */
}
unit_assert(reused == 0);
unit_assert(p1 != 0);
unit_assert(!pif_list_contains(shpif, 1));
unit_assert(!pif_list_contains(shpif, 2));
unit_assert(!pif_list_contains(shpif, 3));
unit_assert(!pif_list_contains(shpif, 4));
unit_assert(shpif->avail_total == 4);
unit_assert(shpif->inuse == 4);
/* more fetches fail, it is fully inuse. */
unit_assert(!shared_ports_fetch_random(shp, shpif, rnd, 0, 0, &p2,
&reused));
unit_assert(!shared_ports_fetch_random(shp, shpif, rnd, 0, 0, &p3,
&reused));
unit_assert(shpif->avail_total == 4);
unit_assert(shpif->inuse == 4);
/* reuse is then always the case */
if(!shared_ports_fetch_random(shp, shpif, rnd,
0 /* can reuse */, 4 /* reusenum */, &p1, &reused)) {
unit_assert(0); /* should succeed */
}
unit_assert(reused == 1);
unit_assert(p1 >= 0 && p1 < 4 /* reusenum */);
if(!shared_ports_fetch_random(shp, shpif, rnd,
0 /* can reuse */, 4 /* reusenum */, &p1, &reused)) {
unit_assert(0); /* should succeed */
}
unit_assert(reused == 1);
unit_assert(p1 >= 0 && p1 < 4 /* reusenum */);
/* return all the ports */
shared_ports_return_port(shp, shpif, 1);
unit_assert(pif_list_contains(shpif, 1));
unit_assert(shpif->avail_total == 4);
unit_assert(shpif->inuse == 3);
shared_ports_return_port(shp, shpif, 2);
unit_assert(pif_list_contains(shpif, 2));
unit_assert(shpif->avail_total == 4);
unit_assert(shpif->inuse == 2);
shared_ports_return_port(shp, shpif, 3);
unit_assert(pif_list_contains(shpif, 3));
unit_assert(shpif->avail_total == 4);
unit_assert(shpif->inuse == 1);
shared_ports_return_port(shp, shpif, 4);
unit_assert(pif_list_contains(shpif, 4));
unit_assert(shpif->avail_total == 4);
unit_assert(shpif->inuse == 0);
unit_assert(pif_list_contains_items(shpif, 1, 2, 3, 4));
shared_ports_delete(shp);
ub_randfree(rnd);
}
void tcpreuse_test(void)
{
unit_show_feature("tcp_reuse");
@@ -486,4 +759,7 @@ void tcpreuse_test(void)
tcp_reuse_tree_list_test();
waiting_tcp_list_test();
reuse_write_wait_test();
unit_show_feature("shared_ports");
shared_port_test_ifs();
shared_port_test_port();
}
@@ -2,6 +2,7 @@
server:
do-not-query-localhost: no
fake-sha1: yes
verbosity: 8
forward-zone:
name: "."
forward-addr: "127.0.0.1@@TOPORT@"
+3 -1
View File
@@ -35,11 +35,13 @@ function check_insecure() {
# test with good start key, and must do 5011 (no URL possible)
echo "*** TEST 1 ***"
echo $DS > root.key
$PRE/unbound-anchor -x "notexist.xml" -s "notexist.p7s" $OPTS
cat root.key
$PRE/unbound-anchor -x "notexist.xml" -s "notexist.p7s" $OPTS -vvvv
if test $? != 0; then
echo "Exitcode not OK"
exit 1
fi
cat root.key
check_works
# save for test 5
cp root.key root.key.probed
Binary file not shown.
Binary file not shown.
+201
View File
@@ -0,0 +1,201 @@
#!/bin/sh
# run in temp dir.
# Then for petal, move into basedir.
# For test_cert.key and test_cert.pem, rename the output files to that.
# And run signit.sh for both signature files, by commenting infile and outfile.
# for test_cert.pem it has emailAddress and keyUsage, but petal.pem does not
# need that.
# settings:
# directory for files
DESTDIR=.
# issuer and subject name for certificates
SERVERNAME=petal
CLIENTNAME=petal
# validity period for certificates
DAYS=7200
# size of keys in bits
BITS=3072
# hash algorithm
HASH=sha256
# base name for unbound server keys
SVR_BASE=petal
# base name for unbound-control keys
CTL_BASE=petal
# flag to recreate generated certificates
RECREATE=0
# we want -rw-r----- access (say you run this as root: grp=yes (server), all=no).
umask 0027
# end of options
set -eu
cleanup() {
echo "removing artifacts"
rm -rf \
server.cnf \
client.cnf \
"${SVR_BASE}_trust.pem" \
"${CTL_BASE}_trust.pem" \
"${SVR_BASE}_trust.srl"
}
fatal() {
printf "fatal error: $*\n" >/dev/stderr
exit 1
}
usage() {
cat <<EOF
usage: $0 OPTIONS
OPTIONS
-d <dir> used directory to store keys and certificates (default: $DESTDIR)
-h show help notice
-r recreate certificates
EOF
}
OPTIND=1
while getopts 'd:hr' arg; do
case "$arg" in
d) DESTDIR="$OPTARG" ;;
h) usage; exit 1 ;;
r) RECREATE=1 ;;
?) fatal "'$arg' unknown option" ;;
esac
done
shift $((OPTIND - 1))
if ! openssl version </dev/null >/dev/null 2>&1; then
echo "$0 requires openssl to be installed for keys/certificates generation." >&2
exit 1
fi
echo "setup in directory $DESTDIR"
cd "$DESTDIR"
trap cleanup INT
# ===
# Generate server certificate
# ===
# generate private key; do no recreate it if they already exist.
if [ ! -f "$SVR_BASE.key" ]; then
openssl genrsa -out "$SVR_BASE.key" "$BITS"
fi
cat >server.cnf <<EOF
[req]
default_bits=$BITS
default_md=$HASH
prompt=no
distinguished_name=req_distinguished_name
x509_extensions=v3_ca
[req_distinguished_name]
commonName=$SERVERNAME
emailAddress=$SERVERNAME
[v3_ca]
subjectKeyIdentifier=hash
authorityKeyIdentifier=keyid:always,issuer:always
basicConstraints=critical,CA:TRUE,pathlen:0
subjectAltName=DNS:$SERVERNAME
keyUsage = digitalSignature, keyCertSign
EOF
[ -f server.cnf ] || fatal "cannot create openssl configuration"
if [ ! -f "$SVR_BASE.pem" -o $RECREATE -eq 1 ]; then
openssl req \
-new -x509 \
-key "$SVR_BASE.key" \
-config server.cnf \
-days "$DAYS" \
-out "$SVR_BASE.pem"
[ ! -f "SVR_BASE.pem" ] || fatal "cannot create server certificate"
fi
# ===
# Generate client certificate
# ===
# generate private key; do no recreate it if they already exist.
if [ ! -f "$CTL_BASE.key" ]; then
openssl genrsa -out "$CTL_BASE.key" "$BITS"
fi
cat >client.cnf <<EOF
[req]
default_bits=$BITS
default_md=$HASH
prompt=no
distinguished_name=req_distinguished_name
req_extensions=v3_req
[req_distinguished_name]
commonName=$CLIENTNAME
[v3_req]
basicConstraints=critical,CA:FALSE
subjectAltName=DNS:$CLIENTNAME
EOF
[ -f client.cnf ] || fatal "cannot create openssl configuration"
if [ ! -f "$CTL_BASE.pem" -o $RECREATE -eq 1 ]; then
openssl x509 \
-addtrust serverAuth \
-in "$SVR_BASE.pem" \
-out "${SVR_BASE}_trust.pem"
openssl req \
-new \
-config client.cnf \
-key "$CTL_BASE.key" \
| openssl x509 \
-req \
-days "$DAYS" \
-CA "${SVR_BASE}_trust.pem" \
-CAkey "$SVR_BASE.key" \
-CAcreateserial \
-$HASH \
-extfile client.cnf \
-extensions v3_req \
-out "$CTL_BASE.pem"
[ ! -f "CTL_BASE.pem" ] || fatal "cannot create signed client certificate"
fi
# remove unused permissions
chmod o-rw \
"$SVR_BASE.pem" \
"$SVR_BASE.key"
chmod g+r,o-rw \
"$CTL_BASE.pem" \
"$CTL_BASE.key"
cleanup
echo "Setup success. Certificates created. Enable in unbound.conf file to use"
# create trusted usage pem
# openssl x509 -in $CTL_BASE.pem -addtrust clientAuth -out $CTL_BASE"_trust.pem"
# see details with openssl x509 -noout -text < $SVR_BASE.pem
# echo "create $CTL_BASE""_browser.pfx (web client certificate)"
# echo "create webbrowser PKCS#12 .PFX certificate file. In Firefox import in:"
# echo "preferences - advanced - encryption - view certificates - your certs"
# echo "empty password is used, simply click OK on the password dialog box."
# openssl pkcs12 -export -in $CTL_BASE"_trust.pem" -inkey $CTL_BASE.key -name "unbound remote control client cert" -out $CTL_BASE"_browser.pfx" -password "pass:" || error "could not create browser certificate"
+40 -21
View File
@@ -1,21 +1,40 @@
-----BEGIN RSA PRIVATE KEY-----
MIIDfQIBAAKBwQC1xQ/Kca6zszZbcCtdOTIH2Uy2gOy/DfabMUU7TmNPm0dVE0NJ
RuN+Rm304SonpwghfP2/ULZNnuDgpG03/32yI7k/VzG6iA4hiF7tT/KAAWC/+2l1
QCsawCV2bSrFK0VhcZr7ALqXd8vkDaQ867K029ypjOQtAJ85qdO3mERy7TGtdUcu
O6hLeVet419YeQ2F8cfNxn63d7bOzNGLPW5xwaCd3UcgD+Ib0k4xfFvbinvPQUeU
J/i4YDWexFYSL+ECAwEAAQKBwCLXXQl+9O+5AEhSnd1Go1Jh0pSA7eBJOuXQcebG
Rb7ykp+6C4G2NtDziwwPRNdI6wQQQ0sym18RfyVQHydGr78/nbiIbB3HCn5e92Mh
mefzW6ow9Kvm2txLzGKA1lvoyRbNm81jnG/eygi3u7Nqd5PNv+4dHj2RkTlmxOeh
qnDMVP5md8uZPv6lYNnrnIzvLCR5vnPNdVwn89AqzI85IcDZdy0R9ZX4NBbsDgAU
6ig6uXuRXvSGiyJ/OUXSrnogaQJhAOjvkHUhVZQkPOxO90TNH4j0GdKKtbSWxIdz
lKfuJeBAEqs0TL+C6vbS81Xw3W1alyDdUBk3rJMOBqW6Ryq5HNL+j5H+Jfsh7fvc
Yle+5wHGci0P9zCFZCrY8It7n9XFIwJhAMfEi6oJa2G8waPJ1bQhxka82Tf9pnKM
XCn/1BBOFjVIx5F842cpA+zp5a62GENTGYPQTTRBB/2/ZwnW5aIkrlg54AtmbqBZ
Oh+2kJdJQD/tfoVmc5soUE2ScTHadK5RKwJhAN4w9kjkXS+MSZjX0kIMsBIBVkhh
C+aREjJqa9ir7/Ey7RvmLXdYuCxtGLRXp7/R8+rjcK49Tx6O+IRJZe042mfhbq3C
EhS1Tr86f4xXix9EXlDhs9bSxrOgcAN9Dv/opQJhAK7eBcPaav0rVfYh/8emqQHS
3fJ9Pu6WnzbEksWTFS2ff9KDGCx9YspIFJ5TF/oXDAaumGZdZrlgirm6O1kr8tGY
F97i04PZl1+bWAaWQH+1TUNI43m2WFUPE7coG2tb8QJgcddDg9VlXliZqgcETZfJ
kJmYETxrcSn3ao6v116N8yxhEgUgjkmsCTiFgx36iDVnXwK6PIt+sIu8MC7eYNa3
berrv/M21K0LRn20IWRxvUobG070weHCAgkko7fTWgr2
-----END RSA PRIVATE KEY-----
-----BEGIN PRIVATE KEY-----
MIIG/gIBADANBgkqhkiG9w0BAQEFAASCBugwggbkAgEAAoIBgQDiNGqbEmyFI9QF
EvWcU36irjzp1W+VMuMHGD5PDYy5ib1QIrUcUQPvWydV4er/6gnpv6VQ+dfOeVlr
Acu73kdh+N0u5UgjIY9CJnoN12eEGjTrVFlHoA2Ur/TMbN3DW20Nbyi5LUJ8KrGl
Yg8tPbLqGvfJsIYTspBEzgQcJg5ZTD3YA2ZESrbZe2sOunri0j1myv+EoTqB4nPb
ShHx8i11IJpUoBEoHoSyMQgEgYJqbmqCHaTGJWNxHUUhI5MmTPEzyrG6T0B3v5Pb
y1eFOyAU+I4SCs0fqHPg4DbPlNTe/MEBm2LQAVrUFjcFx+Cq75oOa9sVp6xvBmYN
nMiwGgLJYjN7l0lhRQEtao6tEGQUYbmpKoLQJMsKs6bjs6HK5TXMzQUfHATirmjE
C1Fcb/eKJ27HNiKS+uw2g9Tpu/af2qKl3ePNUioPbMYtgGhu5csD22heGeilNVtN
8D47kU0SveXjokV476CecW0SZnN9rVrvd0IqtnU9fMoAQyZE6ScCAwEAAQKCAYAk
0//fS3qbmp+0S8ftMbLWbaPBNly6X9SSnSHX4Q7eTkyiNWRjPdV0LNUUqHmIPORs
SCV0L5kxJpSmVV6EMcZRbyEjt3StM5ONY5JPmphh65peDheTD73mTVd/yOG6IrJ4
k3Z/35yJdrIBiRuLdBYjA00Aa1sI7fOLIDePFasUYtNWzgbia3+lnPBrL3U+ZJhW
mgpL36wU5XeTZlXRnGpGPY6i5ISmkYFtOYpioWtIRL3WfVkMYZ31FpzgrlgQzknQ
lrKN2g7/3q0uLlbasgCsAK50hL2f2xxzsALDCGFjDJbwdIZKfdoxRbgS0L7q7gj0
SUK4fc1obR5qHc2lTuCSzPpionq022ElC0DChupiosyXN4GxNZ2Dwoln4Y5s2YXo
+VTtyYbVEib15WbhHorvfg0QUO00Nwqu+LVTVUXueNre2n507fSiOhCIpbPUWDGz
RoeRFEP0T9+mzQgXr56TAiYunIat1qVxXrwaSWSXEfInGUTkdRUC4rctv7KJ1nEC
gcEA8jDTh1OLBG3/JkQxQNOoqFUFssPlJ+z3LcyaNT6bM5lH5Vwn3sGOFWOMLILD
f/qbGG/1VPVfoCEY1NEkYsocOMtkLIJrIdtD5DOnWz1JJE7Zh2AoWWfIfXd9v5sh
m1fB3SVa6D9JtGoDnKttMl25Tqf6YehVo35Axxar74k3kC/vuZrp/81iZscdRsyK
kQh9fPXl4Oqw2cUYdx3L8UprLS4JguvR0zXvbukJ75DjLZELvjnxBbA1vdtyQz58
2uk1AoHBAO8aP5h08kwTIJCXS6uyAJ0F8F/30srAtchSpzsC3YEEs/Z+43D7W1RR
Obw4KhVjjmFeh83U8pdEuUEjv3ua52+uoUCqTywe+o180owiWsTDSXVtDHiUD7bu
x+nRnpk3flZD28GHKLdWMmJvd8DzMgsa9fJIucMYT7xQHzxCW+4nhhBckX9LEH7i
Jo6MaVuh8b6NuZXOBgU3cp20GTZ3SwRNkKOigctQVZT4A1Vf4ioLrVyhv/LVLBC+
UvoIu82wawKBwQDakMXU8sgaj0ocNp5caqdigphJ5BACIBBR/LuOIZnezw3bJ3ez
x+l51ATEhp33+SnOu/sjWO2bjULjjHrRzKP7fVJB+NDGFSMH5rW52W0Qnzggu96u
EMMWt6d8K3wAvQnvka6gubzCXIo18V7yfTKmkWGcyhe/HElJYmR4H9VNAnXNgsh6
Wdfb+QWqxxymFotpImD6wdIoNX8GwJU0hHyEoW9j/320ppAV/6k/0fmzPZrjaVbi
U0uss0ZC+TmkNaECgcB9L6gGYYyOyiDts1k6LvtlOzvMc0uZPmau2J+YJPrmVxkG
QQ9CE0iRD+oDowBdrH9aeYzu9sSA8Mlx0o6p38O21J625bSILDwQoj72gfI2PO0U
HyE9bIABzmk7AbZhEA4Eiojffa2St/2vTh9MFcioydfln7Aq9mqg9O41taS+P1FQ
9bZ0CFA9rphzYA61nEee9kMprPG3/3zyFt5whuru+NF261m7onb8hRHxvD8EtpJx
AnsmX/gvWAbHxJTXr7sCgcEAp6QAysy0/sgRYvzBkqv05kz4xBqy2a4ZKjnMLEWY
7MicZiQrkSsEjMNDy20rjXfZbhDJWGVjBOZ1QsYehKhGAIoORXID9B3aZ32m//VU
IUxkLcrIPLPmfdzZvlRPnQc/TAZNe41BGBa4WlDwTFE9TdpVtTzjW1ac5yBN7sa+
V7YbBSiOhP+NuqQFQM01aaZCmOetcj70B4SwJVzswhITS0O+7ZAvicGJiQKTUvUY
ijWm+Luu3QYDc2HBMwUAmHT5
-----END PRIVATE KEY-----
+23 -12
View File
@@ -1,14 +1,25 @@
-----BEGIN CERTIFICATE-----
MIICFzCCAUACCQDO660L5y5LGDANBgkqhkiG9w0BAQUFADAQMQ4wDAYDVQQDEwVw
ZXRhbDAeFw0xMDA5MzAxMzQzMDFaFw0zMDA2MTcxMzQzMDFaMBAxDjAMBgNVBAMT
BXBldGFsMIHfMA0GCSqGSIb3DQEBAQUAA4HNADCByQKBwQC1xQ/Kca6zszZbcCtd
OTIH2Uy2gOy/DfabMUU7TmNPm0dVE0NJRuN+Rm304SonpwghfP2/ULZNnuDgpG03
/32yI7k/VzG6iA4hiF7tT/KAAWC/+2l1QCsawCV2bSrFK0VhcZr7ALqXd8vkDaQ8
67K029ypjOQtAJ85qdO3mERy7TGtdUcuO6hLeVet419YeQ2F8cfNxn63d7bOzNGL
PW5xwaCd3UcgD+Ib0k4xfFvbinvPQUeUJ/i4YDWexFYSL+ECAwEAATANBgkqhkiG
9w0BAQUFAAOBwQBBkX9KDP2RXbg+xPmdJ4P6CwvA5x1LZwC++ydVx4NlvT0pWicD
ZUnXjcWAJlkeOuUBAqFG7WHTrXpUUAjmdqFVq2yFjteUYBdrFz0RDB2jM9feeKYO
mTgxdZyT9a6humxCxt5VfgT02axLjm/2AqCyFPMbf4PASoJDln01AEuZLZ8Xl2gV
bYHMnHTGoD1Hu6FNEzRgkMC6XT8X3YjHvzQhpc/qL5wEfEsinQGdX4twsuWbf8xd
q7miNnkO8vd0maw=
MIIERDCCAqygAwIBAgIUY5FZe4tAZd0ITNbceavVGLvEe2QwDQYJKoZIhvcNAQEL
BQAwEDEOMAwGA1UEAwwFcGV0YWwwHhcNMjYwNzI0MDkwNTMyWhcNNDYwNDEwMDkw
NTMyWjAQMQ4wDAYDVQQDDAVwZXRhbDCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCC
AYoCggGBAOI0apsSbIUj1AUS9ZxTfqKuPOnVb5Uy4wcYPk8NjLmJvVAitRxRA+9b
J1Xh6v/qCem/pVD51855WWsBy7veR2H43S7lSCMhj0Imeg3XZ4QaNOtUWUegDZSv
9Mxs3cNbbQ1vKLktQnwqsaViDy09suoa98mwhhOykETOBBwmDllMPdgDZkRKttl7
aw66euLSPWbK/4ShOoHic9tKEfHyLXUgmlSgESgehLIxCASBgmpuaoIdpMYlY3Ed
RSEjkyZM8TPKsbpPQHe/k9vLV4U7IBT4jhIKzR+oc+DgNs+U1N78wQGbYtABWtQW
NwXH4Krvmg5r2xWnrG8GZg2cyLAaAsliM3uXSWFFAS1qjq0QZBRhuakqgtAkywqz
puOzocrlNczNBR8cBOKuaMQLUVxv94onbsc2IpL67DaD1Om79p/aoqXd481SKg9s
xi2AaG7lywPbaF4Z6KU1W03wPjuRTRK95eOiRXjvoJ5xbRJmc32tWu93Qiq2dT18
ygBDJkTpJwIDAQABo4GVMIGSMB0GA1UdDgQWBBSLQ6cvFrU2JiedggRXjiUemV3h
QzBLBgNVHSMERDBCgBSLQ6cvFrU2JiedggRXjiUemV3hQ6EUpBIwEDEOMAwGA1UE
AwwFcGV0YWyCFGORWXuLQGXdCEzW3Hmr1Ri7xHtkMBIGA1UdEwEB/wQIMAYBAf8C
AQAwEAYDVR0RBAkwB4IFcGV0YWwwDQYJKoZIhvcNAQELBQADggGBANj5PXClrk76
UddT6aniB/VbErfu1MwfyYSGhE4y5VVJVyD+wHYECswdm2IIo/v/4I+4KWgAcGPk
u+j1B2iXN8sQTe500+KMSRFfaxdbwlX42+oDKwRoz8pwMzETyZYQA4PAE5j2rnjb
n9USomWzvwavo7GRE6VauBcSAekrNFDjPw43tElmr2TTz4lUFXlvBlQvcbloJ4OU
60ek8d1erlsLXzAtf4kCFH1aiII0g0fA448gnIOIgT9LiV88smKNDPVqusw9TBd5
/f1R8ETy7jcIJ9TU34dy6S39s4aUjWUAZMV1TIH3wJPDsE6+1yD5OC5b50akIwpJ
jO9naDRvgaHIWxJRcREXd+H7IlybL+l+Qq4L4RX583cdL/rZEWdnESgbDq7EkEPn
ZbpjdM4oNGUlXsrZw0/GFgzYlN2MBFiLht6y2iBbhFxPb2SM3Xx/M5YnsNLym+I/
m9mck/aeeSEyJ2uIfFfVndfPfqmKxwvoPu0OCv/ppsi+xTvhE6B/UQ==
-----END CERTIFICATE-----
+40 -21
View File
@@ -1,21 +1,40 @@
-----BEGIN RSA PRIVATE KEY-----
MIIDfAIBAAKBwQC48GhhmIU66TZKc3QiyF4L5bsm8Aly/y2SzLP+GACepK0OcOtD
i2sXrTtoJDvGOPZ9ICqmIy8u/Q/cK26txNEeZFcClLcYF/U+NaqjEwrwkHEIgc3g
8qnKrhzM61I8foAWVT7cqxFHDKYuClNITXk1i//Yzpnf9wvVKQ51W9UOtm/WA7g4
IDHCuAjocyyNC3B7XqYawFDOsdMI4ZW7hC0hIRQOvBkvbvY8WxmsSkdd30u1KmoI
Sg4y6OvnikrEEQkCAwEAAQKBwQC3hQlv37RF82sGkm8qnP6Ge+AuEYCu9v44cJ4k
hZkH1I5OiEtN6anKAwOyolIWsCwZmrP3zW5jCIiWiRr5oReLOzMEwqK2a//XTdYY
oSr38b3ZHUY59VP8Zq75woMGuNed35kAmGxzDRP1gI/TmvTvaHlqYyvxBtxnZJij
Za1CrT+a9JvR6hI8xXrE33CF0T6JO1v3v0HeBuve5+83cCHKo+GyqIBjL3FJgefZ
EsPz6rGnPDKTYgMyaljFV3LI5ikCYQDlaBnyiWk1C7tYO5x3CRoHoiuiiREZCncK
QkSxjiDoSP0rc+3BQp2kG3yy6S9mN4qMQPELEtBa6bORogxNK+Pxg8TRI/+xgeFt
bod5Bd4pfl6Y5hXm21JwELFlOzPI3PMCYQDOYK6Z7vegiOJyyAJXMjcI07H8S0Gr
SZW8f4tHRzO+RrRpR5ANzarELX7nF/Qj5mPXiZNiiMDGocxqkNzIa5HFLOqBhRkv
o7yC1Cj582dUBFHyEbsZxR6UMTPLdE3UaRMCYACC1Nv3dmaJ2ib+KwEQ4h/2Ooao
K4OUxGMfdqu2l1gtIXNBVNxDW7qL3SFA57wgj4x0cJUHu7MYJjBC3igl2uIk2wFk
RSOOGIR35JFec/o/r9JDYPUcs/hP8TU6hokCBQJgHbH/rZqa+vh3TPjGjXFmRdjg
JWNWwaTG7OaVTd5K7bgSwYtQiQvs5Gl/dxUVRg0ilKLxGB6BTpN9bGAHxLbltK9v
1s8l/praxyBr/PsvBQHSILi4aU7ZxY0G3OGRSV0NAmBx28Msdgc0yHh3qSkbwVEr
gr7av1iOH73ee+o4CmMWXYUBHOMW5Su0s0QHjNGDMiRiRoCvzYqdLcJj9/sFJxOT
CM35WGGeKDMNubX7C6YroQ91q7kUmhi7HHY3QOyhCDU=
-----END RSA PRIVATE KEY-----
-----BEGIN PRIVATE KEY-----
MIIG/gIBADANBgkqhkiG9w0BAQEFAASCBugwggbkAgEAAoIBgQC7Tr0JP6gVKA2Z
wtpcBmd27WquMfhdfePva0mV6oc+eE+py2gwHBUAVhMnnYAwT/7ziC0a7pel43tS
NSHgr0oSUZJC2x+gYMKZ341Q+qNFUJTTv+hG41uKwGfcx02+0HuVU1A9m60PNtE2
oc83Au8RwyPgcuzWwk3hmX6XUrZmz0vrUxbniLF9xl0gWeFFFWVeioItYDVAKxtl
Ufrb5/9ju3mzfnEtWWEl+qfraA8DFA10BZRVUBKNB7aGc8KDRBwC4yQBHtIu8ob1
9DGNe2lYnMCHPFR3dsCHjBYbuGf+J66uAxtMu0IygwI3inNtBUTnQ/QVv2fQNJc2
vL9ic1BHSwi5byPld3igVCc35wmKLgKX0WtQKcuxI1BwYfaMK+jTZl6mQcE4AuMk
tvhWbbLn7UQxNAe6X2JKM/M7ds1dIjyfL6nuB1yESX+FiRpjOMuRV1BwrPLJNOfl
C9QkIRgoy1C9WxZUcigeDAApooDls4H/Q16tWdHj8toQWvYKVqMCAwEAAQKCAYBF
/w+/pA1BEr26Z0nIuA/0Lpb+T+g7r+79Kr/OCV3PJ5DFqCDgUa47eO8hj8c2xr5E
7e/FL8J2GMOeHgLx/y+UFu2slEyGV4KBlDwwNenL3mgvlXjM/OvZtztZExXnp+t3
CzJiQ4nxtI+Mdf2E1lDW93Cx0ODXBLesBft7u0o0s2TwpRVbIwcJNJbanxwDABLo
uKQbJuffefx76Z3wjgsvjwDU5fyPcOZQFhKoczOg995rLCaZlxnHoElCh4H6Ifod
K9LQAERjLicBtSThAuO+0us353y3dJ6lY3iYsi2u69UBcvFSepzKjFsx/FPv8B8N
QMmwpfEZvB4ODM7VvZkvmQZcN3HHopRJWVFWkTkCX5A0RXCXO+AaQV+AVJWnGCxj
dyV6L1qBK/HsyOto9KGIHN1VFj+n4hTthNPWkDE7CkA7gAMomNvmlf6zNOrbwzro
LznDK7OQC5Qqoge0R+u/l2xgqzIl8hl5jtmwhi6kT47HBBQ1dBKa6M4rNIFRr9EC
gcEA9CTQHdAax7XcoeETto/TMKKfv0QyfIivscr250/87GNjzsKCK2MxHZ50jmtF
7Q7iYhepRuvhbvF9h4BwK7fUbi/KQAW4qiVxqi+MfQkoVYdvnLgekhdmnrThqWmf
p4ZTZ0tBe29m713WdozHZv6nNcyIrt0JXrVvIFDDpil/6ETHa+y6OMiePc8gklDD
VVCwKpq+F+taFBzfgqNHkdnaMlP/I/35KEQyhV07aLJhR1leExoGkmc7eaK6WqVD
iQqZAoHBAMRnVukeUNiSPZmC3IyyfD8iMXnjyPmb/+a9LmwaVOs4yjdBUmGTx+ZV
mnDb94d3ijyshysbjCc8ebZ7FxuXoaIJ7JWYOgTeMJs1JOAoEVsHBtd1W/RpQ8Hr
NegSwP4cmCzXAQOtenZnCC2QveHlngxk7rUiayj7G4awrJLtyW9Z9WAUokm810Nq
muUXhHxRobc40H65+qyCuPODKz3wO4Lt5VaYd4vR+wkUFc0IghmRX0HVlVe/q9gA
JgXwRPfMmwKBwDWRzkh8XSPs95hddqHcNQ664CproFhK9aIhUsO2fVyxAjlf3IgA
n8pL9m85goJdfbbgUjhJkZFyU4Tj3bj6ARacTdh2aOqMhMA+5qiY1czOhuLwU2Ti
1ZWFQu6VSn7Lrok/rgKTkxZ6lJA2m5oxziaz1lnoDiJF1ThWAFf5SyN/0/IOY14K
Rw5w4Ei6h+G0brMqeQNulLlNDI3xncaW8pWQcK9JDt6S+DLjHiH+4fFx3n56e26s
UBSEbDdvg74SIQKBwQCrCRM2j5/3+eKK/Nrz67snf692Zlduh9uiJL14hrXM4fe3
hrsnHnrGq2WDQwucfQ11KQnNEIBM6u1TbH4DGVk4s0vEOnzMIHJTt0QVsM7sZoIe
v6UEg2buSNb48tv+bwhWhCXt/fTXh4InrBSv1DZ+tKbsNrz7QzIFaXXfvhPdVInK
0i1B6aHMo9mgB4roeG5MEL4AnhUehfhql5/goIQy0NkXQE9bA9GJZmRV2ULy4RYD
TuxvLguIXxi9sy9cXGECgcEA2MCZvKU9hml/4n1/dEiNvSGEA9rz92Vzsb50yeRM
3yLTaYe5koVNbag+IpqpCNP4T2xNnWIxv7ceqB78wxWykadF0z5T5I+/HBPYWLms
mpQPr7grVqcX5gqxJoUwWwxvKLwh5KjqjRX43turXOWlsSHMVNH6KMLt1K3OtArs
OMROcUcXBJc2hvr+YBeHOpIC1ZlawIr5BRi2FICN7TeIiE3h7VFY0ucAyOOKvfH9
FzIeEhSTR60ZN1HtILhRJmjG
-----END PRIVATE KEY-----
+25 -13
View File
@@ -1,15 +1,27 @@
-----BEGIN CERTIFICATE-----
MIICWTCCAYKgAwIBAgIJAN5YIkuCvJf5MA0GCSqGSIb3DQEBBQUAMCYxDjAMBgNV
BAMTBXBldGFsMRQwEgYJKoZIhvcNAQkBFgVwZXRhbDAeFw0xMzAxMTcxMTUyNDVa
Fw0zMjEwMDQxMTUyNDVaMCYxDjAMBgNVBAMTBXBldGFsMRQwEgYJKoZIhvcNAQkB
FgVwZXRhbDCB3zANBgkqhkiG9w0BAQEFAAOBzQAwgckCgcEAuPBoYZiFOuk2SnN0
IsheC+W7JvAJcv8tksyz/hgAnqStDnDrQ4trF607aCQ7xjj2fSAqpiMvLv0P3Ctu
rcTRHmRXApS3GBf1PjWqoxMK8JBxCIHN4PKpyq4czOtSPH6AFlU+3KsRRwymLgpT
SE15NYv/2M6Z3/cL1SkOdVvVDrZv1gO4OCAxwrgI6HMsjQtwe16mGsBQzrHTCOGV
u4QtISEUDrwZL272PFsZrEpHXd9LtSpqCEoOMujr54pKxBEJAgMBAAGjDzANMAsG
A1UdDwQEAwIChDANBgkqhkiG9w0BAQUFAAOBwQCaA3ys5hDPMNV1oXIxH6u2KfAX
C9tYJId/SR0x8whsZuNaSEZAgImdM5dnyWdjey8Pio772E9/F2aUBGFkdadZx4My
d7hBfEi/NECEKs86k9g0ijbin41NKtnajb6GwyNQ9vDx7Z5FS8BZ3CD0BZIdCQUE
gKuDSWBROQU3tqrjdk2QTwGQkj2mgzT871Jn1MwZw0mczPjS1y469Ejym8wi3uCd
EboDOoGBCpmUQbxBv6JI75cUCdmNNEwjQjZ0XQw=
MIIEkzCCAvugAwIBAgIUSAvgFLH//MkCJQDFBcJfyjrVJYswDQYJKoZIhvcNAQEL
BQAwJjEOMAwGA1UEAwwFcGV0YWwxFDASBgkqhkiG9w0BCQEWBXBldGFsMB4XDTI2
MDcyNDA5NDEyNloXDTQ2MDQxMDA5NDEyNlowJjEOMAwGA1UEAwwFcGV0YWwxFDAS
BgkqhkiG9w0BCQEWBXBldGFsMIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKC
AYEAu069CT+oFSgNmcLaXAZndu1qrjH4XX3j72tJleqHPnhPqctoMBwVAFYTJ52A
ME/+84gtGu6XpeN7UjUh4K9KElGSQtsfoGDCmd+NUPqjRVCU07/oRuNbisBn3MdN
vtB7lVNQPZutDzbRNqHPNwLvEcMj4HLs1sJN4Zl+l1K2Zs9L61MW54ixfcZdIFnh
RRVlXoqCLWA1QCsbZVH62+f/Y7t5s35xLVlhJfqn62gPAxQNdAWUVVASjQe2hnPC
g0QcAuMkAR7SLvKG9fQxjXtpWJzAhzxUd3bAh4wWG7hn/ieurgMbTLtCMoMCN4pz
bQVE50P0Fb9n0DSXNry/YnNQR0sIuW8j5Xd4oFQnN+cJii4Cl9FrUCnLsSNQcGH2
jCvo02ZepkHBOALjJLb4Vm2y5+1EMTQHul9iSjPzO3bNXSI8ny+p7gdchEl/hYka
YzjLkVdQcKzyyTTn5QvUJCEYKMtQvVsWVHIoHgwAKaKA5bOB/0NerVnR4/LaEFr2
ClajAgMBAAGjgbgwgbUwHQYDVR0OBBYEFHTJazw63SRJUbZ3slMXV9O9L7JIMGEG
A1UdIwRaMFiAFHTJazw63SRJUbZ3slMXV9O9L7JIoSqkKDAmMQ4wDAYDVQQDDAVw
ZXRhbDEUMBIGCSqGSIb3DQEJARYFcGV0YWyCFEgL4BSx//zJAiUAxQXCX8o61SWL
MBIGA1UdEwEB/wQIMAYBAf8CAQAwEAYDVR0RBAkwB4IFcGV0YWwwCwYDVR0PBAQD
AgKEMA0GCSqGSIb3DQEBCwUAA4IBgQBYyONVmgUv8mpGTp2U+12e715VDGQLRNEu
TjGBgpVF4Vebw8E+L++Fzbd0iJVq0o1WzcM3SxdgPr/AZCqgbzHeRx3ZmE/7QNtF
w+IvOU35VQAYlA3Caz2gYoTLYaCyPF1ZwH7cbviI1pdv1jWotHVYbK/hFXHx1GaF
as3AHGAr1lGFFrnt0pA3G1VJACGEHOFZRxeDAwnyl9VN/JC8uujaSekA98fzspvk
fQYTfOAhR4qd9smwg/af/cgJHcFeMbfLWYmeLa01zMR1NypBOdVJQOXCn9bBn6xW
Niwa9JitzJaK0hRccdOEerw0UI/5s5xCKIYepn5MZ7RlWfarjBTZbVvyzkMMSFa4
qB39pqLTQtxq3KLDpTs76Q+U9UyuQuxuC2kNyPHmpYgCT/2Aaiezx80GMeEL3XCJ
L+vmo/3jU6miAXEFZRBCe1z8bwEWb1RiEHh/pVxRbIMRgtGfCQoQwHpZyx9VUWd0
ZBYZlQ0Ql1YGPEuEWkobTBppzHsaIX8=
-----END CERTIFICATE-----
+18
View File
@@ -0,0 +1,18 @@
server:
verbosity: 8
# num-threads: 1
interface: 127.0.0.1
port: @PORT@
use-syslog: no
directory: ""
pidfile: "unbound.pid"
chroot: ""
username: ""
do-not-query-localhost: no
auth-task-threads: 1
auth-zone:
name: "example.com"
for-upstream: yes
for-downstream: yes
master: "127.0.0.1@@TOPORT@"
+16
View File
@@ -0,0 +1,16 @@
BaseName: auth_load
Version: 1.0
Description: Perform AXFR for authority zone with auth load thread
CreationDate: Thu 2 Jul 09:35:40 CEST 2026
Maintainer: dr. W.C.A. Wijngaards
Category:
Component:
CmdDepends:
Depends:
Help:
Pre: auth_load.pre
Post: auth_load.post
Test: auth_load.test
AuxFiles:
Passed:
Failure:
+12
View File
@@ -0,0 +1,12 @@
# #-- auth_load.post --#
# source the master var file when it's there
[ -f ../.tpkg.var.master ] && source ../.tpkg.var.master
# source the test var file when it's there
[ -f .tpkg.var.test ] && source .tpkg.var.test
#
# do your teardown here
. ../common.sh
kill_pid $FWD_PID
kill_pid $UNBOUND_PID
cat fwd.log
cat unbound.log

Some files were not shown because too many files have changed in this diff Show More