Arаm Sаrgsyаn [Mon, 15 Jun 2026 11:35:12 +0000 (11:35 +0000)]
fix: usr: Fix a 'deny-answer-aliases' configuration bypass issue
It was possible to use a maliciously crafted authoritative
zone to make :iscman:`named` resolver synthesize a ``DNAME``
"alias" that should have been rejected by the configured
:any:`deny-answer-aliases` option. This has been fixed.
Closes #5930
Merge branch '5930-deny-answer-aliases-and-cached-dname-buf-fix' into 'main'
Aram Sargsyan [Mon, 18 May 2026 09:17:51 +0000 (09:17 +0000)]
Fix a 'deny-answer-aliases' bug when using a cached DNAME
When using a cached DNAME to resolve a name, make sure to consult
the denied answers lists, otherwise it is possible to consutruct
a restricted alias by caching a DNAME that is a parent of the
denied alias. See the comments in the tests case from the previous
commit an example.
Aram Sargsyan [Mon, 18 May 2026 09:14:27 +0000 (09:14 +0000)]
Add a new 'deny-answer-aliases' check in 'resolver' system test
This new check exercises an attack against guarantees given by the
'deny-answer-aliases' configuration option by caching a DNAME
that is a parent of the restricted alias, and then "constructing"
the restricted alias from the cache.
Ondřej Surý [Fri, 12 Jun 2026 15:40:20 +0000 (17:40 +0200)]
fix: nil: Remove isc_mem_strndup()
The isc_mem_strndup() function had a single caller, the HTTP/2
request-path handling, which now uses isc_mem_allocate() and strlcpy()
directly. Remove the function from the libisc API.
Closes #6087
Merge branch '6087-remove-isc_mem_strndup' into 'main'
Ondřej Surý [Fri, 12 Jun 2026 14:17:46 +0000 (16:17 +0200)]
Remove isc_mem_strndup()
The function had a single caller, the HTTP/2 request-path handling in
the network manager, and its semantics (strlen() of the source clamped
to the requested size) amounted to an obscured bounded string copy.
Replace the only use with a plain allocation and strlcpy(), and drop the
function.
Arаm Sаrgsyаn [Fri, 12 Jun 2026 15:36:57 +0000 (15:36 +0000)]
fix: usr: Fix a zone transfer over TLS (XoT) issue when using the opportunistic TLS mode
The :iscman:`named` process, running as secondary DNS server,
configured to transfer a zone from a primary server using an
encrypted XoT transport in opportunistic TLS mode (i.e. without
peer certificate/hostname validation) could terminate unexpectedly
when the TLS ALPN negotiation with primary server was unsuccessful.
This has been fixed.
Closes #5957
Merge branch '5957-xot-xfrin_connect_done-bug-fix' into 'main'
Aram Sargsyan [Fri, 22 May 2026 11:31:37 +0000 (11:31 +0000)]
Fix a bug in xfrin.c:xfrin_connect_done()
When the connect callback's result is ISC_R_SUCCESS and the callback
changes the result because of some condition, the 'xfr' should not
be detached, because it now belongs to the receive callback.
Detach the reference only if the callback's result is non-success.
Aram Sargsyan [Fri, 22 May 2026 11:27:54 +0000 (11:27 +0000)]
Add a check for the "doth" system test
Configure a zone transfer using XoT (with opportunistic TLS) from
a non-DoT port, which does not provide ALPN "dot" (in this case
it will try to connect to a DoH port). This is expected to fail,
but the client should handle the error gracefully and not to crash.
Colin Vidal [Fri, 12 Jun 2026 14:50:23 +0000 (16:50 +0200)]
fix: dev: Fix delegdb dump buffer overflow
A buffer used to dump a DNS name in the delegdb dump flow was using the
wrong size: it was using `DNS_NAME_MAXWIRE` which is the actual max
length of a DNS name on the wire instead of using `DNS_NAME_FORMATSIZE`
which is the maximum length of a textual representation of a DNS name
(which can be way longer than `DNS_NAME_MAXWIRE` if using the master
file escape sequence format) plus 1 (end of string byte). This could
lead to a buffer overflow. This is now fixed.
Closes #6132
Merge branch '6132-delegdb-dump-overflow' into 'main'
Colin Vidal [Fri, 5 Jun 2026 09:58:02 +0000 (11:58 +0200)]
Fix delegdb dump buffer overflow
A buffer used to dump a DNS name in the delegdb dump flow was using the
wrong size: it was using `DNS_NAME_MAXWIRE` which is the actual max
length of a DNS name on the wire instead of using `DNS_NAME_FORMATSIZE`
which is the maximum length of a textual representation of a DNS name
(which can be way longer than `DNS_NAME_MAXWIRE` if using the master
file escape sequence format) plus 1 (end of string byte). This could
lead to a buffer overflow. This is now fixed.
Colin Vidal [Fri, 5 Jun 2026 09:55:07 +0000 (11:55 +0200)]
Add test for delegdb dump with very long name
Add a delegdb test which dump a database which contains a very long name
(using DNS master file format with escape sequence as defined per RFC
1035). This ensure that the delegdb uses large enough internal buffers
to load the names in DB and generate the dump. If this is not the case,
the test crashes on a build with address sanatizer enabled.
Nicki Křížek [Fri, 12 Jun 2026 12:37:21 +0000 (14:37 +0200)]
new: test: Add a system test cookbook
The README documents what the framework is; the cookbook documents how
to get common tasks done with it: iterating on a single test, adding a
new test directory, writing a regression reproducer, mocking a
misbehaving server with isctest.asyncserver, signing zones in
bootstrap(), and driving named via the NamedInstance fixtures. All
recipes are distilled from existing tests (cyclic_glue, dnssec_py,
dispatch) so they reflect the current canonical patterns.
Assisted-by: Claude:claude-fable-5
Merge branch 'nicki/systest-cookbook' into 'main'
Nicki Křížek [Thu, 11 Jun 2026 09:11:18 +0000 (09:11 +0000)]
Add a system test cookbook
The README documents what the framework is; the cookbook documents how
to get common tasks done with it: iterating on a single test, adding a
new test directory, writing a regression reproducer, mocking a
misbehaving server with isctest.asyncserver, signing zones in
bootstrap(), and driving named via the NamedInstance fixtures. All
recipes are distilled from existing tests (cyclic_glue, dnssec_py,
dispatch) so they reflect the current canonical patterns.
Michal Nowak [Fri, 12 Jun 2026 10:02:45 +0000 (12:02 +0200)]
new: ci: Enforce AI commit-trailer rules in danger checks
`CONTRIBUTING.md` documents several rules around how AI coding assistants should (and should not) be attributed in commit messages. Teach `dangerfile.py` to enforce them so that violations are caught at MR time.
Merge branch 'mnowak/danger-ai-trailer-checks' into 'main'
Michal Nowak [Tue, 5 May 2026 18:50:10 +0000 (20:50 +0200)]
Validate Assisted-by trailer format and tool list
CONTRIBUTING.md documents the Assisted-by trailer format as
Assisted-by: AGENT_NAME:MODEL_VERSION [TOOL1] [TOOL2]
and excludes basic development tools (git, compilers, meson,
ninja, editors, clang-format, black, ruff) from the optional
tool list.
Walk every `Assisted-by:` line in each commit message and emit a
`warn()` when:
- the line does not match the documented `AGENT:VERSION` shape;
- the optional tool list contains basic-tool names.
The basic-tool list extends the CONTRIBUTING.md examples with
other formatters, generic linters, and build/test runners
commonly invoked from `.gitlab-ci.yml`. Specialized analysis
tools (coccinelle, clang-tidy, AFL, Coverity, cppcheck,
valgrind, sanitizers) are intentionally absent so they remain
allowed in the trailer.
Use `warn()` rather than `fail()` because the format is
human-written and overly strict matching would produce false
positives on edge cases.
Michal Nowak [Tue, 5 May 2026 17:43:35 +0000 (19:43 +0200)]
Reject Signed-off-by trailers from AI tools in danger check
CONTRIBUTING.md states that AI agents must not add Signed-off-by
tags, since only humans can legally certify the Developer
Certificate of Origin. Mirror the existing LLM Co-Authored-By
check against the Signed-off-by trailer line so danger fails on
commits that violate the rule.
The shared alternation of known LLM agent names is factored out
into LLM_AGENT_NAMES_RE so adding a new tool only requires one
edit.
Michal Nowak [Tue, 5 May 2026 17:05:49 +0000 (19:05 +0200)]
Detect Co-Authored-By trailers and reject AI co-authors
CONTRIBUTING.md states that AI agents must not be listed as
co-authors and that contributors should use the `Assisted-by:`
trailer instead. Teach `dangerfile.py` to fail merge requests
whose commit messages include a `Co-Authored-By:` trailer naming
a known LLM (Claude, Codex, Mistral, Copilot, Gemini, Cursor,
Devin, Aider, Sourcegraph, CodeWhisperer).
For any other `Co-Authored-By:` trailer, emit an info-level
`message()` that includes the full trailer line so reviewers can
confirm the named co-author is a human contributor and not an
unrecognised AI tool.
Arаm Sаrgsyаn [Thu, 11 Jun 2026 14:38:23 +0000 (14:38 +0000)]
fix: usr: Fix a bug in GeoIP2 string matching
When using GeoIP2 ACLs (see :any:`acl`), :iscman:`named` could
incorrectly match a name using a sub-string instead of the full
name match. This has been fixed.
Closes #6019
Merge branch '6019-geoip2-string-match-buf-fix' into 'main'
Aram Sargsyan [Mon, 25 May 2026 14:19:53 +0000 (14:19 +0000)]
Fix 'geoip' ACL matching bug
The geoip2.c:match_string() function can incorrectly return 'true'
when matching strings of different lengths (i.e. it matches a
substring). Return 'false' when the lengths of the matched strings
are different.
Nicki Křížek [Thu, 11 Jun 2026 13:22:49 +0000 (15:22 +0200)]
chg: nil: Update the system test README for the pytest-native workflow
The README predated the meson migration and most of the pytest runner
features. Document building the test dependencies with meson and drop
the make-based instructions, the Makefile.am registration step, and the
stale -T flag list. Describe the jinja2 templating, bootstrap(), the
conftest fixtures, the pytest marks, and recommend node IDs and
parametrization over -k matching. Fix the directory naming rule, which
switched from hyphens to underscores.
Also declare pytest and pytest-xdist as required dependencies: the
runner's pytest.ini uses --dist=loadscope unconditionally, so pytest
without pytest-xdist cannot even start.
Related #3810
Assisted-by: Claude:claude-fable-5
Merge branch 'nicki/systest-readme-refresh' into 'main'
Nicki Křížek [Thu, 11 Jun 2026 09:07:08 +0000 (09:07 +0000)]
Update the system test README for the pytest-native workflow
The README predated the meson migration and most of the pytest runner
features. Document building the test dependencies with meson and drop
the make-based instructions, the Makefile.am registration step, and the
stale -T flag list. Describe the jinja2 templating, bootstrap(), the
conftest fixtures, the pytest marks, and recommend node IDs and
parametrization over -k matching. Fix the directory naming rule, which
switched from hyphens to underscores.
Also declare pytest and pytest-xdist as required dependencies: the
runner's pytest.ini uses --dist=loadscope unconditionally, so pytest
without pytest-xdist cannot even start.
The :any:`http-listener-clients` and :any:`http-streams-per-connection`
configuration options could be truncated to smaller values (or to ``0``,
which means unlimited) when very big configuration values were used, which
exceeded ``65535``. As a note - it is very unlikely that such big values
are used in production, and the default values for the affected options
are ``300`` and ``100``, correspondingly. This has been fixed.
Closes #6021
Merge branch '6021-doh-quota-type-truncation-fix' into 'main'
Aram Sargsyan [Mon, 25 May 2026 12:11:30 +0000 (12:11 +0000)]
Fix DoH quota global variables type
The 'named_g_http_listener_clients' and 'named_g_http_streams_per_conn'
global variables are defined as 'in_port_t', which is usually 16 bits,
but both the readers and the writers of those variables use 'uint32_t'
as the target/source, which can result in truncation.
Matthijs Mekking [Thu, 11 Jun 2026 11:27:41 +0000 (11:27 +0000)]
fix: usr: Ignore updates removing DNSKEY RRset with class ANY
When a Dynamic Update is received that removes the ``DNSKEY`` (or ``CDNSKEY``,
or ``CDS``) RRset, remove all records except the ones that are in use
for signing for the zone.
Closes #6045
Merge branch '6045-dns-update-delete-in-use-dnskey-any' into 'main'
When a Dynamic Update is received that removes the DNSKEY (or CDNSKEY,
or CDS) RRset, remove all records except the ones that are in use
for signing for the zone (with dnssec-policy).
Ben Scott [Wed, 10 Jun 2026 19:56:00 +0000 (15:56 -0400)]
Explicit sub-steps for assessing -S and EOL
For the step where we assess which product versions/branches are
vulnerable to the flaw, add explicit subordinate steps for assessing
Special Subscriber -S Preview edition, and end-of-life versions that
are still received paid fixes.
While we have GitLab labels to indicate affected versions, there is no
satisfactory mechanism in place to indicate that assessment of all
versions is complete, and thus anything not labeled as affected can be
considered immune. Explicit checklist steps will allow others to see
when assessment is complete.
Ben Scott [Wed, 10 Jun 2026 17:08:32 +0000 (13:08 -0400)]
CVE and CVSS+CWE as separate steps
"Assigning CVE" and "Assigning CVSS+CWE" are really two different
steps. CVE is bookeeping; we just request the ID and type it in.
CVSS and CWE require a judgement determination, and often involve
discussion. At the same time, sometimes we forget to put the CVE ID
in right away. Since we already have a separate step for CVE
assignment, let's put "update the issue with the CVE ID" in that step,
too. Then the second step can be entirely about CVSS+CWE. Same
number of steps, just clearer separation of what the steps are about.
Michal Nowak [Wed, 10 Jun 2026 19:49:10 +0000 (21:49 +0200)]
fix: test: Various system test stability fixes for CI
Doubling system-test parallelism and removing the `@pytest.mark.flaky` markers exposed a set of timing-sensitive failures across CI. This branch keeps only the fixes for failures that are test-robustness bugs. Other - frequent - failures often guarded by `@pytest.mark.flaky` have their separate MRs already.
Merge branch 'mnowak/system-test-stability-fixes' into 'main'
Michal Nowak [Wed, 3 Jun 2026 16:39:56 +0000 (16:39 +0000)]
Retry the SOA serial check in the rpz test
While a response-policy zone is being (re)loaded it can briefly answer
with no SOA (SERVFAIL/REFUSED), which `dig +short` renders as empty
output. get_sn() aborted the whole tests.sh on the first such miss,
defeating the retry_quiet() loop in ck_soa() that is meant to wait for
the reload to settle. Return failure instead so the check is retried.
Michal Nowak [Thu, 28 May 2026 13:38:37 +0000 (13:38 +0000)]
Drop flaky marker from the fetchlimit system test
With the per-domain limit and clients-per-query spill checks no longer
sensitive to fetch-counter timing, the test no longer needs the
flaky-retry workaround.
Michal Nowak [Wed, 10 Jun 2026 17:22:50 +0000 (17:22 +0000)]
Accept a clients-per-query spill range in the fetchlimit test
The clients-per-query spill steps required exactly 55 spills, but the
auto-tuning ramp-up lags under load and spills more. Accept the 55..75
range; the ramp-up is already verified by the "clients-per-query
increased to 10" log wait.
Michal Nowak [Wed, 10 Jun 2026 17:22:44 +0000 (17:22 +0000)]
Make the fetchlimit per-domain limit check robust under load
The per-domain limit step required the active fetch count for
lamesub.example to read exactly 40 on a single sample. It parsed the
cumulative "allowed" field (6) rather than the active count (field 3),
and even the active count can briefly dip below 40 between bursts.
Sample the active count with retry_quiet, flag only a count above 40,
and require the limit to be reached at least once.
Michal Nowak [Tue, 9 Jun 2026 11:22:56 +0000 (13:22 +0200)]
fix: test: Register orphaned diff and skr unit tests in meson build
Both test files existed on disk but were never added to the meson test
list when the build system switched from autoconf.
skr_test.c also had a spurious #include <dns/tls.h> for a header that
never existed in this repo -- no symbols from it were used. Removing
the include is the only fix needed; the test itself is correct and
passes.
Assisted-by: Claude:claude-opus-4-7
Merge branch 'mnowak/fix-orphaned-unit-tests' into 'main'
Michal Nowak [Sun, 24 May 2026 18:12:53 +0000 (18:12 +0000)]
Add build-time check for unregistered unit test files
Fail at meson configure time if a *_test.c file exists in a test
directory but is not listed in the corresponding test array. This
prevents test files from being silently orphaned when added without
updating meson.build, as happened with diff_test.c and skr_test.c.
Michal Nowak [Mon, 25 May 2026 08:17:02 +0000 (08:17 +0000)]
Register orphaned diff and skr unit tests in meson build
Both test files existed on disk but were never added to the meson test
list when the build system switched from autoconf.
skr_test.c also had a spurious #include <dns/tls.h> for a header that
never existed in this repo -- no symbols from it were used. Removing
the include is the only fix needed; the test itself is correct and
passes.
Nicki Křížek [Tue, 9 Jun 2026 10:34:25 +0000 (12:34 +0200)]
chg: test: Add NSEC3 answer correctness test to dnssec_py
Rewrite nsec3_answer/tests_nsec3.py as dnssec_py/tests_nsec3_answer.py
using the isctest.zone helpers for zone setup. ns1 (auth) and ns2
(resolver) were renumbered to ns2 and ns9 respectively to fit the
existing dnssec_py server infrastructure.
Assisted-by: Claude:claude-opus-4-8
Merge branch 'nicki/pytest-dnssec-py-nsec3-answer' into 'main'
Nicki Křížek [Mon, 8 Jun 2026 15:26:02 +0000 (15:26 +0000)]
Add NSEC3 answer correctness test to dnssec_py
Rewrite nsec3_answer/tests_nsec3.py as dnssec_py/tests_nsec3_answer.py
using the isctest.zone helpers for zone setup. ns1 (auth) and ns2
(resolver) were renumbered to ns2 and ns9 respectively to fit the
existing dnssec_py server infrastructure.
Nicki Křížek [Mon, 8 Jun 2026 15:34:35 +0000 (15:34 +0000)]
Add revoked truncated self-signed DNSKEY test to dnssec_py
Port test_truncated_dnskey from dnssec_malformed_dnskey into the shared
dnssec_py fixture harness, completing the migration and deleting the
remaining dnssec_malformed_dnskey files.
Nicki Křížek [Mon, 8 Jun 2026 15:33:59 +0000 (15:33 +0000)]
Add malformed ECDSA DNSKEY tests to dnssec_py
Port test_malformed_ecdsa and test_multiple_rrsigs from the standalone
dnssec_malformed_dnskey directory into the shared dnssec_py fixture
harness. The zone is renamed from example. to dnskey-malformed., the
resolver fixture changes from a dedicated ns3 to the shared ns9, and
trust anchors are wired in via bootstrap() rather than per-directory
config files.
Nicki Křížek [Tue, 9 Jun 2026 08:34:32 +0000 (10:34 +0200)]
chg: test: Add mixed DS test to dnssec_py
Rewrite dnssec_unsupported_ds/tests_mixed_ds.py as
dnssec_py/tests_mixed_ds.py using the isctest.zone helpers for zone
setup.
The test verifies that a zone whose DS RRset contains only an
unsupported algorithm DS and a bogus DS record is treated as insecure
by a validating resolver, resulting in SERVFAIL for queries to that
zone. The DS set for child.mixed-ds. is deliberately corrupted after
signing to contain a DS record with an unsupported algorithm (12) and
a DS record with an invalid digest, exercising the mixed-DS insecurity
proof path.
Assisted-by: Claude:claude-opus-4-8
Merge branch 'nicki/pytest-dnssec-py-mixed-ds' into 'main'
Nicki Křížek [Mon, 8 Jun 2026 15:19:22 +0000 (15:19 +0000)]
Add mixed DS test to dnssec_py
Rewrite dnssec_unsupported_ds/tests_mixed_ds.py as
dnssec_py/tests_mixed_ds.py using the isctest.zone helpers for zone
setup.
The test verifies that a zone whose DS RRset contains only an
unsupported algorithm DS and a bogus DS record is treated as insecure
by a validating resolver, resulting in SERVFAIL for queries to that
zone. The DS set for child.mixed-ds. is deliberately corrupted after
signing to contain a DS record with an unsupported algorithm (12) and
a DS record with an invalid digest, exercising the mixed-DS insecurity
proof path.
Ondřej Surý [Mon, 8 Jun 2026 16:01:03 +0000 (18:01 +0200)]
fix: usr: Reject unsupported RSA DNSKEY shapes during DNSSEC validation
An authoritative server publishing an RSA DNSKEY with an unusually
large modulus or an exotic public exponent could make each DNSSEC
signature check on a validating recursive resolver noticeably more
expensive than for a normally sized key. Such DNSKEYs are now
treated as invalid.
Closes #6008
Merge branch '6008-reject-oversized-rsa-dnskeys' into 'main'
Ondřej Surý [Tue, 19 May 2026 15:52:22 +0000 (17:52 +0200)]
Enforce strict RSA DNSKEY shape during DNSSEC validation
A resolver that validated DNSSEC accepted RSA DNSKEYs of any modulus
size up to OpenSSL's compile-time ceiling, and accepted any public
exponent the wire format could carry. RSA verification cost grows
sharply with the modulus length, so an authoritative server could
publish an oversized DNSKEY to make each signature check on the
resolver many times more expensive than for a normally sized key.
The intended verify-time cap had no effect because the helper it called
returned the public-exponent bit length rather than the modulus bit
length, so the test was always satisfied. Replace it with an honest
modulus-range check and a stricter exponent check that accepts only odd
exponents in the closed range [3, 2^32 + 1] (covering every Fermat
prime up to F5 and the odd intermediate values seen in deployed keys),
reject anything outside those bounds at every RSA key load path so an
invalid key never reaches the verifier, and keep the same checks at the
verifier as a backstop against future load paths.
Ondřej Surý [Mon, 8 Jun 2026 15:55:37 +0000 (17:55 +0200)]
fix: dev: Fix the memory ordering in the adaptive read-write lock
On hardware with a weak memory model, the internal read-write lock could
briefly admit a reader and a writer at the same time, risking sporadic
crashes or incorrect data. The reader/writer handshake now uses
sequentially consistent ordering so the two can no longer overlap.
Closes #6060
Merge branch '6060-rwlock-seq-cst-handshake' into 'main'
Ondřej Surý [Tue, 2 Jun 2026 04:32:20 +0000 (06:32 +0200)]
Use sequentially consistent ordering in the adaptive rwlock handshake
The adaptive isc_rwlock (the modified C-RW-WP variant) synchronizes a
reader against a writer through a store-buffer handshake across two
independent atomic objects: the reader publishes its arrival in
readers_ingress and then reads writers_lock, while the writer publishes
its lock in writers_lock and then reads the reader indicator. With the
acquire/release ordering introduced by the 2021 simplification, neither
side is forced to observe the other's publish store before its own check
load, so on weak-memory targets a reader could see writers_lock unlocked
while the writer sees the indicator empty, and both would enter their
critical sections at once.
Restore the sequentially consistent ordering the original algorithm
specifies on the handshake atomics. The single total order over the
seq_cst operations is what forbids the overlap; targeting individual
fences is both more fragile and, on x86, more expensive. On x86 this
ordering is free (seq_cst loads remain plain loads and the RMWs remain
lock-prefixed); the added cost falls only on the weak-memory targets that
actually need it.
Ondřej Surý [Mon, 8 Jun 2026 15:50:38 +0000 (17:50 +0200)]
rem: usr: Restrict views to the Internet (IN) class
Views could previously be declared in classes other than Internet (IN),
but that support was inconsistent — ``named-checkconf`` accepted configurations
that ``named`` then refused to load. Views are now restricted to class IN, and
both tools reject any other class. Configurations declaring a non-IN view
must drop the class to keep working.
Merge branch '5784-improve-class-handling' into 'main'
Ondřej Surý [Wed, 4 Mar 2026 12:24:53 +0000 (13:24 +0100)]
Disallow configuration of user-defined non-IN class views
Only class IN is allowed for user-defined views; the internally
generated `_bind` view stays in the CH class. Both `named` and the
shared checker in `lib/isccfg/check.c` now reject non-IN views, so a
config can no longer pass `named-checkconf` yet fail to start in
`named`.
Tests, configs, and catalog zones using CH or arbitrary classes
(e.g. `class10`) are removed accordingly.
Ondřej Surý [Thu, 4 Jun 2026 08:25:42 +0000 (10:25 +0200)]
Use variable size struct for zonecut ndata to avoid allocation
Previously, the node_deleg_t would do double allocation, one for the
struct itself and one for the zonecut. This has been changed to use
variable sized struct with the zonecut .ndata buffer attached to the end
of node_deleg_t structure.
Michal Nowak [Mon, 8 Jun 2026 13:23:27 +0000 (15:23 +0200)]
fix: ci: Escape literal dots in branch-name match regexes
The backports and merged-metadata rules used unescaped dots in their
branch-name regexes, causing them to over-match. Escape the dots so the
patterns match the intended version branch names exactly.
Assisted-by: Claude:claude-opus-4-8
Merge branch 'mnowak/ci-fix-regex-escaping' into 'main'
Michal Nowak [Wed, 3 Jun 2026 11:56:17 +0000 (11:56 +0000)]
Escape literal dots in branch-name match regexes
The backports and merged-metadata rules used unescaped dots in their
branch-name regexes, causing them to over-match. Escape the dots so the
patterns match the intended version branch names exactly.
Michal Nowak [Mon, 8 Jun 2026 11:44:10 +0000 (13:44 +0200)]
fix: dev: Preserve the request message across async SIG(0) processing
For SIG(0)-signed requests, view matching is offloaded and the request
is finished asynchronously from ns_client_request_continue(), which
passes client->inner.buffer to dns_dt_send(). That buffer aliases the
network manager's receive buffer, only valid during the read callback,
so it may already be freed and reused, producing garbage dnstap frames
(e.g. the "upforwd" sig0-over-DoT test fails with UQ=0).
Copy the request message when entering async mode and reference the
copy, freeing it in ns__client_reset_cb().
Assisted-by: Claude:claude-opus-4-8
Closes #6139
Merge branch '6139-dnstap-sig0-request-buffer-uaf' into 'main'
Michal Nowak [Thu, 4 Jun 2026 12:09:26 +0000 (12:09 +0000)]
Preserve the request buffer across async SIG(0) processing
For SIG(0)-signed requests, view matching is offloaded and the request
is finished asynchronously from ns_client_request_continue(), which
passes client->inner.buffer to dns_dt_send(). That buffer aliases the
network manager's receive buffer, only valid during the read callback,
so it may already be freed and reused, producing garbage dnstap frames
(e.g. the "upforwd" sig0-over-DoT test fails with UQ=0).
When the request is offloaded (ns_client_setup_view() returns
DNS_R_WAIT) and dnstap is enabled, copy the request buffer and point
client->inner.buffer at the copy so it survives the asynchronous hop;
free it in ns__client_reset_cb(). When dnstap is disabled there is no
async consumer of the buffer, so detach it from the receive buffer
instead.
Michal Nowak [Mon, 8 Jun 2026 10:09:24 +0000 (12:09 +0200)]
fix: dev: Build the fuzzers without the libbindtest test library
Every fuzz target depended on libtest_dep, which forces building the
libbindtest shared library. In a static build (as used by OSS-Fuzz)
that link fails: libbindtest's netmgr wrappers multiply-define symbols
that also live in the static libisc/libns archives, and the static
system libraries are not position independent.
Only fuzz_dns_qp actually uses the qp test helpers, so give it just
tests/libtest/qp.c via the new libtest_qp_dep and drop libtest_dep
from the fuzzers.
Assisted-by: Claude:claude-opus-4-8
Merge branch 'mnowak/fuzz-drop-libbindtest' into 'main'
Michal Nowak [Fri, 5 Jun 2026 10:08:03 +0000 (10:08 +0000)]
Build the fuzzers without the libbindtest test library
Every fuzz target depended on libtest_dep, which forces building the
libbindtest shared library. In a static build (as used by OSS-Fuzz)
that link fails: libbindtest's netmgr wrappers multiply-define symbols
that also live in the static libisc/libns archives, and the static
system libraries are not position independent.
Only fuzz_dns_qp actually uses the qp test helpers, so give it just
tests/libtest/qp.c via the new libtest_qp_dep and drop libtest_dep
from the fuzzers.
Michal Nowak [Fri, 5 Jun 2026 14:33:17 +0000 (16:33 +0200)]
chg: ci: Build unit tests in the unit test job
Building the unit tests in the build job ships them in the CI artifact
(+200 MB) and transfers them over the network. Build them in the unit
test job instead.
Git checks the sources out newer than the build tree restored from the
artifact, which would make meson rebuild all of BIND 9 in the unit test
job. Age the sources so the build is treated as up to date and only the
unit tests get compiled.
Assisted-by: Claude:claude-opus-4-8
Merge branch 'mnowak/build-unit-tests-in-unit-job' into 'main'
Michal Nowak [Wed, 3 Jun 2026 13:53:51 +0000 (13:53 +0000)]
Build unit tests in the unit test job
Building the unit tests in the build job ships them in the CI artifact
(+200 MB) and transfers them over the network. Build them in the unit
test job instead.
When Git checks out the sources, their modification times are newer than
the build tree restored from the artifact, so meson would rebuild all of
BIND 9 in the unit test job. Age the tracked sources so the build is
treated as up to date and only the unit tests get compiled.
Nicki Křížek [Thu, 4 Jun 2026 17:16:12 +0000 (19:16 +0200)]
new: test: pytest helpers for dnssec and zone setup
- Create `isctest.zone.Zone` helper for zone setup (including signing).
- Add `ZoneKey` helpers for both dnssec-keygen managed keys and python-based keys.
- Add `dnssec_py` shared test setup for DNSSEC tests.
- Add the first example - refactor `nsec3_delegations` into a `dnssec_py` test module.
Add ZoneKey helpers for key operations in isctest.zone
Introduce an abstract ZoneKey base class with two concrete
implementations:
- FileZoneKey wraps a dnssec-keygen-managed key file (kasp.Key).
- PythonZoneKey holds a Python-native keypair for dnspython-based
signing and key operations.
Both share ZoneKey.into_ta() and ZoneKey.is_ksk(). The ZoneKey
abstraction lets Zone.copy_dssets() and Zone.trust_anchors() handle
pure-Python keys without callers needing to know how the key was made.
Rewrite nsec3_delegation/tests_excessive_nsec3_iterations.py as
dnssec_py/tests_nsec3_iter_too_many.py using the isctest.zone helpers.
The test is a reproducer for CVE-2026-1519 [GL#5708]. It sets up a
delegation from nsec3-iter-too-many. (ns2) to an unsigned sub zone
(ns3), signing the parent with NSEC3 at 51 iterations. A validating
resolver (ns9) must use NSEC3 to prove the sub zone is insecure; the
excessive iteration count is logged as a warning. The test verifies that
the query still resolves successfully (insecure, not SERVFAIL) despite
the high iteration count.