]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
Reduce the number of fetches we make when looking up addresses
authorMark Andrews <marka@isc.org>
Thu, 6 Feb 2020 06:19:10 +0000 (17:19 +1100)
committerMichał Kępień <michal@isc.org>
Tue, 5 May 2020 21:47:16 +0000 (23:47 +0200)
If there are more that 5 NS record for a zone only perform a
maximum of 4 address lookups for all the name servers.  This
limits the amount of remote lookup performed for server
addresses at each level for a given query.

lib/dns/adb.c
lib/dns/include/dns/adb.h
lib/dns/resolver.c

index b41a19d94a0aa0a3450f41c34f5fb3ccacb1b06b..251fb592fb5403829c4eca9c52de69e05f504474 100644 (file)
@@ -414,6 +414,7 @@ static void log_quota(dns_adbentry_t *entry, const char *fmt, ...)
 #define FIND_GLUEOK(fn)         (((fn)->options & DNS_ADBFIND_GLUEOK) != 0)
 #define FIND_HAS_ADDRS(fn)      (!ISC_LIST_EMPTY((fn)->list))
 #define FIND_RETURNLAME(fn)     (((fn)->options & DNS_ADBFIND_RETURNLAME) != 0)
+#define FIND_NOFETCH(fn)       (((fn)->options & DNS_ADBFIND_NOFETCH) != 0)
 
 /*
  * These are currently used on simple unsigned ints, so they are
@@ -3117,11 +3118,14 @@ dns_adb_createfind(dns_adb_t *adb, isc_task_t *task, isc_taskaction_t action,
  fetch:
        if ((WANT_INET(wanted_addresses) && NAME_HAS_V4(adbname)) ||
            (WANT_INET6(wanted_addresses) && NAME_HAS_V6(adbname)))
+       {
                have_address = true;
-       else
+       } else {
                have_address = false;
-       if (wanted_fetches != 0 &&
-           ! (FIND_AVOIDFETCHES(find) && have_address)) {
+       }
+       if (wanted_fetches != 0 && !(FIND_AVOIDFETCHES(find) && have_address) &&
+           !FIND_NOFETCH(find))
+       {
                /*
                 * We're missing at least one address family.  Either the
                 * caller hasn't instructed us to avoid fetches, or we don't
index 5ba920c853716fd4a972be95e33b52bf2d512868..768668182fdfe788fb3f4cdf13a3a7be18b4cad0 100644 (file)
@@ -207,6 +207,10 @@ struct dns_adbfind {
  *      lame for this query.
  */
 #define DNS_ADBFIND_OVERQUOTA          0x00000400
+/*%
+ *     Don't perform a fetch even if there are no address records available.
+ */
+#define DNS_ADBFIND_NOFETCH            0x00000800
 
 /*%
  * The answers to queries come back as a list of these.
index 73fc5763dcb3f63f497ed858a185143ba9a94dcd..4fdcbd821d2b8c3fff9219d98c356a0095f6d069 100644 (file)
 #define DEFAULT_MAX_QUERIES 75
 #endif
 
+/*
+ * After NS_FAIL_LIMIT attempts to fetch a name server address,
+ * if the number of addresses in the NS RRset exceeds NS_RR_LIMIT,
+ * stop trying to fetch, in order to avoid wasting resources.
+ */
+#define NS_FAIL_LIMIT 4
+#define NS_RR_LIMIT   5
+
 /* Number of hash buckets for zone counters */
 #ifndef RES_DOMAIN_BUCKETS
 #define RES_DOMAIN_BUCKETS     523
@@ -3371,8 +3379,7 @@ sort_finds(dns_adbfindlist_t *findlist, unsigned int bias) {
 static void
 findname(fetchctx_t *fctx, const dns_name_t *name, in_port_t port,
         unsigned int options, unsigned int flags, isc_stdtime_t now,
-        bool *overquota, bool *need_alternate)
-{
+        bool *overquota, bool *need_alternate, unsigned int *no_addresses) {
        dns_adbaddrinfo_t *ai;
        dns_adbfind_t *find;
        dns_resolver_t *res;
@@ -3465,8 +3472,12 @@ findname(fetchctx_t *fctx, const dns_name_t *name, in_port_t port,
                            ((res->dispatches4 == NULL &&
                              find->result_v6 != DNS_R_NXDOMAIN) ||
                             (res->dispatches6 == NULL &&
-                             find->result_v4 != DNS_R_NXDOMAIN)))
+                             find->result_v4 != DNS_R_NXDOMAIN))) {
                                *need_alternate = true;
+                       }
+                       if (no_addresses != NULL) {
+                               (*no_addresses)++;
+                       }
                } else {
                        if ((find->options & DNS_ADBFIND_OVERQUOTA) != 0) {
                                if (overquota != NULL)
@@ -3517,6 +3528,7 @@ fctx_getaddresses(fetchctx_t *fctx, bool badcache) {
        dns_rdata_ns_t ns;
        bool need_alternate = false;
        bool all_spilled = true;
+       unsigned int no_addresses = 0;
 
        FCTXTRACE5("getaddresses", "fctx->depth=", fctx->depth);
 
@@ -3684,20 +3696,28 @@ fctx_getaddresses(fetchctx_t *fctx, bool badcache) {
                 * Extract the name from the NS record.
                 */
                result = dns_rdata_tostruct(&rdata, &ns, NULL);
-               if (result != ISC_R_SUCCESS)
+               if (result != ISC_R_SUCCESS) {
                        continue;
+               }
 
-               findname(fctx, &ns.name, 0, stdoptions, 0, now,
-                        &overquota, &need_alternate);
+               if (no_addresses > NS_FAIL_LIMIT &&
+                   dns_rdataset_count(&fctx->nameservers) > NS_RR_LIMIT)
+               {
+                       stdoptions |= DNS_ADBFIND_NOFETCH;
+               }
+               findname(fctx, &ns.name, 0, stdoptions, 0, now, &overquota,
+                        &need_alternate, &no_addresses);
 
-               if (!overquota)
+               if (!overquota) {
                        all_spilled = false;
+               }
 
                dns_rdata_reset(&rdata);
                dns_rdata_freestruct(&ns);
        }
-       if (result != ISC_R_NOMORE)
+       if (result != ISC_R_NOMORE) {
                return (result);
+       }
 
        /*
         * Do we need to use 6 to 4?
@@ -3712,7 +3732,7 @@ fctx_getaddresses(fetchctx_t *fctx, bool badcache) {
                        if (!a->isaddress) {
                                findname(fctx, &a->_u._n.name, a->_u._n.port,
                                         stdoptions, FCTX_ADDRINFO_FORWARDER,
-                                        now, NULL, NULL);
+                                        now, NULL, NULL, NULL);
                                continue;
                        }
                        if (isc_sockaddr_pf(&a->_u.addr) != family)