]> git.ipfire.org Git - thirdparty/bind9.git/log
thirdparty/bind9.git
22 months agoRemove OpenSSL Engine support
Ondřej Surý [Mon, 5 Aug 2024 09:40:42 +0000 (11:40 +0200)] 
Remove OpenSSL Engine support

The OpenSSL 1.x Engines support has been deprecated in the OpenSSL 3.x
and is going to be removed.  Remove the OpenSSL Engine support in favor
of OpenSSL Providers.

22 months agofix: Move matching isc_mem_destroy() outside of ifdef
Ondřej Surý [Mon, 5 Aug 2024 16:54:02 +0000 (16:54 +0000)] 
fix: Move matching isc_mem_destroy() outside of ifdef

The isc_mem_create() in printversion() was created outside of an #ifdef
HAVE_GEOIP, but destroyed inside the #ifdef; move it to the outside of
the #ifdef where it belongs.

This is really a nit as we immediately exit() after printing the
versions, but I found it and it would bug me for the rest of my life.

Merge branch 'ondrej/fix-missing-isc_mem_destroy-in-printversion' into 'main'

See merge request isc-projects/bind9!9255

22 months agoMove matching isc_mem_destroy() outside of ifdef alessio/regression/2ebcafd8c2
Ondřej Surý [Mon, 5 Aug 2024 13:55:53 +0000 (15:55 +0200)] 
Move matching isc_mem_destroy() outside of ifdef

The isc_mem_create() in printversion() was created outside of an #ifdef
HAVE_GEOIP, but destroyed inside the #ifdef; move it to the outside of
the #ifdef where it belongs.

This is really a nit as we immediately exit() after printing the
versions, but I found it and it would bug me for the rest of my life.

22 months agofix: usr: Fix assertion failure in the glue cache alessio/regression/227add4c3e
Ondřej Surý [Mon, 5 Aug 2024 14:24:14 +0000 (14:24 +0000)] 
fix: usr: Fix assertion failure in the glue cache

Fix an assertion failure that could happen as a result of data race between free_gluetable() and addglue() on the same headers.

Closes #4691

Merge branch '4691-fix-data-race-between-free_gluetable-and-addglue' into 'main'

Closes #4691

See merge request isc-projects/bind9!9126

22 months agofix: dev: don't use 'create' flag unnecessarily in findnode() alessio/regression/a26055f03e
Ondřej Surý [Mon, 5 Aug 2024 13:36:54 +0000 (13:36 +0000)] 
fix: dev: don't use 'create' flag unnecessarily in findnode()

when searching the cache for a node so that we can delete an rdataset, it isn't necessary to set the 'create' flag. if the
node doesn't exist yet, we won't be able to delete anything from it anyway.

Merge branch 'each-minor-findnode-refactor' into 'main'

See merge request isc-projects/bind9!9158

22 months agoFix the glue table in the QP and RBT zone databases
Ondřej Surý [Thu, 4 Jul 2024 08:07:18 +0000 (10:07 +0200)] 
Fix the glue table in the QP and RBT zone databases

When adding glue to the header, we add header to the wait-free stack to
be cleaned up later which sets wfc_node->next to non-NULL value.  When
the actual cleaning happens we would only cleanup the .glue_list, but
since the database isn't locked for the time being, the headers could be
reused while cleaning the existing glue entries, which creates a data
race between database versions.

Revert the code back to use per-database-version hashtable where keys
are the node pointers.  This allows each database version to have
independent glue cache table that doesn't affect nodes or headers that
could already "belong" to the future database version.

22 months agominor findnode optimization
Evan Hunt [Fri, 12 Jul 2024 21:06:20 +0000 (14:06 -0700)] 
minor findnode optimization

when searching the cache for a node so that we can delete an
rdataset, it is not necessary to set the 'create' flag. if the
node doesn't exist yet, we then we won't be able to delete
anything from it anyway.

22 months agochg: Clean up calls to dns_difftuple_create()
Ondřej Surý [Mon, 5 Aug 2024 13:31:46 +0000 (13:31 +0000)] 
chg: Clean up calls to dns_difftuple_create()

dns_difftuple_create() could only return success, so change
its type to void and clean up all the calls to it.

Merge branch 'each-difftuple-create-cannot-fail' into 'main'

See merge request isc-projects/bind9!9151

22 months agodns_difftuple_create() cannot fail
Evan Hunt [Fri, 12 Jul 2024 00:00:38 +0000 (17:00 -0700)] 
dns_difftuple_create() cannot fail

dns_difftuple_create() could only return success, so change
its type to void and clean up all the calls to it.

other functions that only returned a result value because of it
have been cleaned up in the same way.

22 months agofix: usr: Raise the log level of priming failures
Ondřej Surý [Mon, 5 Aug 2024 13:02:41 +0000 (13:02 +0000)] 
fix: usr: Raise the log level of priming failures

When a priming query is complete, it's currently logged at level ISC_LOG_DEBUG(1), regardless of success or failure. We are now raising it to ISC_LOG_NOTICE in the case of failure. [GL #3516]

Closes #3516

Merge branch '3516-log-priming-errors' into 'main'

Closes #3516

See merge request isc-projects/bind9!9121

22 months agoraise the log level of priming failures
Evan Hunt [Mon, 1 Jul 2024 20:00:04 +0000 (13:00 -0700)] 
raise the log level of priming failures

when a priming query is complete, it's currently logged at
level ISC_LOG_DEBUG(1), regardless of success or failure. we
are now raising it to ISC_LOG_NOTICE in the case of failure.

22 months agochg: dev: fix the rsa exponent to 65537
Ondřej Surý [Mon, 5 Aug 2024 11:22:32 +0000 (11:22 +0000)] 
chg: dev: fix the rsa exponent to 65537

There isn't a realistic reason to ever use e = 4294967297. Fortunately
its codepath wasn't reachable to users and can be safetly removed.

Keep in mind the `dns_key_generate` header comment was outdated. e = 3
hasn't been used since 2006 so there isn't a reason to panic. The
toggle was the public exponents between 65537 and 4294967297.

Merge branch 'aydin/rsa-cleanup' into 'main'

See merge request isc-projects/bind9!9133

22 months agofix the rsa exponent to 65537
Aydın Mercan [Tue, 9 Jul 2024 13:32:51 +0000 (16:32 +0300)] 
fix the rsa exponent to 65537

There isn't a realistic reason to ever use e = 4294967297. Fortunately
its codepath wasn't reachable to users and can be safetly removed.

Keep in mind the `dns_key_generate` header comment was outdated. e = 3
hasn't been used since 2006 so there isn't a reason to panic. The
toggle was the public exponents between 65537 and 4294967297.

22 months agochg: dev: remove the crc64 implementation
Ondřej Surý [Mon, 5 Aug 2024 11:21:38 +0000 (11:21 +0000)] 
chg: dev: remove the crc64 implementation

CRC-64 has been added for map files. Now that the map file format has
been removed, there isn't a reason to keep the implementation.

Merge branch 'aydin/cleanup-crc' into 'main'

See merge request isc-projects/bind9!9135

22 months agoremove the crc64 implementation
Aydın Mercan [Wed, 10 Jul 2024 11:49:20 +0000 (14:49 +0300)] 
remove the crc64 implementation

CRC-64 has been added for map files. Now that the map file format has
been removed, there isn't a reason to keep the implementation.

22 months agochg: dev: call rcu_barrier() in the isc_mem_destroy() just once
Ondřej Surý [Mon, 5 Aug 2024 10:24:53 +0000 (10:24 +0000)] 
chg: dev: call rcu_barrier() in the isc_mem_destroy() just once

The previous work in this area was led by the belief that we might be
calling call_rcu() from within call_rcu() callbacks.  After carefully
checking all the current callback, it became evident that this is not
the case and the problem isn't enough rcu_barrier() calls, but something
entirely else.

Call the rcu_barrier() just once as that's enough and the multiple
rcu_barrier() calls will not hide the real problem anymore, so we can
find it.

Merge branch '4607-call-a-single-rcu_barrier' into 'main'

See merge request isc-projects/bind9!9134

22 months agoCall rcu_barrier() in the isc_mem_destroy() just once
Ondřej Surý [Wed, 10 Jul 2024 16:50:33 +0000 (18:50 +0200)] 
Call rcu_barrier() in the isc_mem_destroy() just once

The previous work in this area was led by the belief that we might be
calling call_rcu() from within call_rcu() callbacks.  After carefully
checking all the current callback, it became evident that this is not
the case and the problem isn't enough rcu_barrier() calls, but something
entirely else.

Call the rcu_barrier() just once as that's enough and the multiple
rcu_barrier() calls will not hide the real problem anymore, so we can
find it.

22 months agochg: usr: require at least OpenSSL 1.1.1
Ondřej Surý [Mon, 5 Aug 2024 10:24:23 +0000 (10:24 +0000)] 
chg: usr: require at least OpenSSL 1.1.1

OpenSSL 1.1.1 or better (or equivalent LibreSSL version) is now required to compile BIND 9.

Closes #2806

Merge branch '2806-remove-ax_check_openssl' into 'main'

Closes #2806

See merge request isc-projects/bind9!9110

22 months agoRemove no longer needed OpenSSL shims and checks
Ondřej Surý [Mon, 1 Jul 2024 09:05:18 +0000 (11:05 +0200)] 
Remove no longer needed OpenSSL shims and checks

Since the minimal OpenSSL version is now OpenSSL 1.1.1, remove all kind
of OpenSSL shims and checks for functions that are now always present in
the OpenSSL libraries.

Co-authored-by: Ondřej Surý <ondrej@isc.org>
Co-authored-by: Aydın Mercan <aydin@isc.org>
22 months agoRemove AX_CHECK_OPENSSL macro
Ondřej Surý [Thu, 2 Sep 2021 11:24:46 +0000 (13:24 +0200)] 
Remove AX_CHECK_OPENSSL macro

OpenSSL supports pkg-config method since the 0.9.8 version and we
already require pkg-config for other mandatory libraries.  Also
the way the AX_CHECK_OPENSSL macro was integrated into the configure
script was confusing - the macro would be used only if the libcrypto.pc
and libssl.pc file are not usable, so calling ./configure
--with-openssl=/usr/local would have no effect when PKG_CHECK_MODULES
would be successful.

22 months agoBump the minimal OpenSSL version to 1.1.1
Ondřej Surý [Thu, 2 Sep 2021 11:24:46 +0000 (13:24 +0200)] 
Bump the minimal OpenSSL version to 1.1.1

As BIND 9.20 does not support RHEL/CentOS 7 which just reach
end-of-life, we can safely bump the OpenSSL requirements to version
1.1.1, which in turn will allow us to simplify our OpenSSL integration.

22 months agofix: usr: Fix assertion failure when checking named-checkconf version
Ondřej Surý [Mon, 5 Aug 2024 10:16:39 +0000 (10:16 +0000)] 
fix: usr: Fix assertion failure when checking named-checkconf version

Checking the version of `named-checkconf` would end with assertion failure.  This has been fixed.

Closes #4827

Merge branch '4827-cleanup-dst-only-if-initialized' into 'main'

Closes #4827

See merge request isc-projects/bind9!9243

22 months agoFix assertion failure when checking named-checkconf version
Ondřej Surý [Mon, 5 Aug 2024 08:24:37 +0000 (10:24 +0200)] 
Fix assertion failure when checking named-checkconf version

The dst_lib_destroy() should be called only if dst_lib_init() was called
before.  In named-checkconf, that is guarded by dst_cleanup variable
that was erroneously set to true by default.  Set the dst_cleanup to
'false' by default.

22 months agofix: usr: Valid TSIG signatures with invalid time cause crash
Ondřej Surý [Mon, 5 Aug 2024 09:40:10 +0000 (09:40 +0000)] 
fix: usr: Valid TSIG signatures with invalid time cause crash

An assertion failure triggers when the TSIG has valid cryptographic signature, but the time is invalid. This can happen when the times between the primary and secondary servers are not synchronised.

Closes #4811

Merge branch '4811-fix-isc_buffer_putuint48-buffer-size-requirement' into 'main'

Closes #4811

See merge request isc-projects/bind9!9234

22 months agoAdd a system test that sends TSIG with bad time
Ondřej Surý [Fri, 26 Jul 2024 00:21:39 +0000 (02:21 +0200)] 
Add a system test that sends TSIG with bad time

Add a system test that sets TSIG fudge to 0, waits three seconds and
then sends signed message to the server.  This tests the path where the
time difference between the client and the server is outside of the TSIG
fudge value.

22 months agoAdd tsig unit test for bad time and bad signatures
Ondřej Surý [Fri, 26 Jul 2024 00:05:43 +0000 (02:05 +0200)] 
Add tsig unit test for bad time and bad signatures

The tsig unit test was only testing if everything went ok, but it was
not testing whether the error paths work.  Add two more unit tests - one
uses the time outside of the TSIG skew, and the second trashes the
signature with random data.

22 months agoFix the assertion failure when putting 48-bit number to buffer
Ondřej Surý [Thu, 25 Jul 2024 18:30:03 +0000 (20:30 +0200)] 
Fix the assertion failure when putting 48-bit number to buffer

When putting the 48-bit number into a fixed-size buffer that's exactly 6
bytes, the assertion failure would occur as the 48-bit number is
internally represented as 64-bit number and the code was checking if
there is enough space for `sizeof(val)`.  This causes assertion failure
when otherwise valid TSIG signature has a bad timing information.

Specify the size of the argument explicitly, so the 48-bit number
doesn't require 8-byte long buffer.

22 months agofix: dev: Don't skip the counting if fcount_incr() is called with force==true alessio/regression/026024a6ae
Ondřej Surý [Mon, 5 Aug 2024 07:36:10 +0000 (07:36 +0000)] 
fix: dev: Don't skip the counting if fcount_incr() is called with force==true

The fcount_incr() was incorrectly skipping the accounting for the
fetches-per-zone if the force argument was set to true.  We want to skip
the accounting only when the fetches-per-zone is completely disabled,
but for individual names we need to do the accounting even if we are
forcing the result to be success.

Closes #4786

Merge branch '4786-forced-fcount_incr-should-still-increment-count-and-allowed' into 'main'

Closes #4786

See merge request isc-projects/bind9!9115

22 months agoDon't skip the counting if fcount_incr() is called with force==true
Ondřej Surý [Thu, 20 Jun 2024 16:59:56 +0000 (18:59 +0200)] 
Don't skip the counting if fcount_incr() is called with force==true

The fcount_incr() was incorrectly skipping the accounting for the
fetches-per-zone if the force argument was set to true.  We want to skip
the accounting only when the fetches-per-zone is completely disabled,
but for individual names we need to do the accounting even if we are
forcing the result to be success.

22 months agofix: test: Use LC_ALL to override all system locales
Ondřej Surý [Mon, 5 Aug 2024 07:33:02 +0000 (07:33 +0000)] 
fix: test: Use LC_ALL to override all system locales

The system tests were overriding the local locale by setting LANG to C.
This does not override the locale in case there are individual LC_<*>
variables like LC_CTYPE explicitly set.

Use LC_ALL=C instead which is the proper way of overriding all currently
set locales.

Merge branch 'ondrej/use-LC_ALL-not-LANG' into 'main'

See merge request isc-projects/bind9!9109

22 months agoUse LC_ALL to override all system locales
Ondřej Surý [Tue, 18 Jun 2024 06:56:18 +0000 (08:56 +0200)] 
Use LC_ALL to override all system locales

The system tests were overriding the local locale by setting LANG to C.
This does not override the locale in case there are individual LC_<*>
variables like LC_CTYPE explicitly set.

Use LC_ALL=C instead which is the proper way of overriding all currently
set locales.

22 months agofix: dev: Remove superfluous memset() in isc_nmsocket_init()
Ondřej Surý [Mon, 5 Aug 2024 07:32:39 +0000 (07:32 +0000)] 
fix: dev: Remove superfluous memset() in isc_nmsocket_init()

The tlsstream part of the isc_nmsocket_t gets initialized via designater
initializer and doesn't need the extra memset() later; just remove it.

Merge branch 'ondrej/remove-superfluous-memset-in-isc_nmsocket_init' into 'main'

See merge request isc-projects/bind9!9120

22 months agoRemove superfluous memset() in isc_nmsocket_init()
Ondřej Surý [Mon, 1 Jul 2024 15:49:27 +0000 (17:49 +0200)] 
Remove superfluous memset() in isc_nmsocket_init()

The tlsstream part of the isc_nmsocket_t gets initialized via designater
initializer and doesn't need the extra memset() later; just remove it.

22 months agofix: dev: Fix PTHREAD_MUTEX_ADAPTIVE_NP and PTHREAD_MUTEX_ERRORCHECK_NP usage
Ondřej Surý [Mon, 5 Aug 2024 07:31:54 +0000 (07:31 +0000)] 
fix: dev: Fix PTHREAD_MUTEX_ADAPTIVE_NP and PTHREAD_MUTEX_ERRORCHECK_NP usage

The PTHREAD_MUTEX_ADAPTIVE_NP and PTHREAD_MUTEX_ERRORCHECK_NP are
usually not defines, but enum values, so simple preprocessor check
doesn't work.

Check for PTHREAD_MUTEX_ADAPTIVE_NP from the autoconf AS_COMPILE_IFELSE
block and define HAVE_PTHREAD_MUTEX_ADAPTIVE_NP.  This should enable
adaptive mutex on Linux and FreeBSD.

As PTHREAD_MUTEX_ERRORCHECK actually comes from POSIX and Linux glibc
does define it when compatibility macros are being set, we can just use
PTHREAD_MUTEX_ERRORCHECK instead of PTHREAD_MUTEX_ERRORCHECK_NP.

Merge branch 'ondrej/fix-adaptive-mutex-use' into 'main'

See merge request isc-projects/bind9!9111

22 months agoFix PTHREAD_MUTEX_ADAPTIVE_NP and PTHREAD_MUTEX_ERRORCHECK_NP usage
Ondřej Surý [Tue, 18 Jun 2024 13:21:52 +0000 (15:21 +0200)] 
Fix PTHREAD_MUTEX_ADAPTIVE_NP and PTHREAD_MUTEX_ERRORCHECK_NP usage

The PTHREAD_MUTEX_ADAPTIVE_NP and PTHREAD_MUTEX_ERRORCHECK_NP are
usually not defines, but enum values, so simple preprocessor check
doesn't work.

Check for PTHREAD_MUTEX_ADAPTIVE_NP from the autoconf AS_COMPILE_IFELSE
block and define HAVE_PTHREAD_MUTEX_ADAPTIVE_NP.  This should enable
adaptive mutex on Linux and FreeBSD.

As PTHREAD_MUTEX_ERRORCHECK actually comes from POSIX and Linux glibc
does define it when compatibility macros are being set, we can just use
PTHREAD_MUTEX_ERRORCHECK instead of PTHREAD_MUTEX_ERRORCHECK_NP.

22 months agoRemove ISC_MUTEX_INITIALIZER
Ondřej Surý [Tue, 18 Jun 2024 13:21:10 +0000 (15:21 +0200)] 
Remove ISC_MUTEX_INITIALIZER

It's hard to get it right on different platforms and it's unused
in BIND 9 anyway.

22 months agoRemove defunct --with-locktype configure option
Ondřej Surý [Tue, 18 Jun 2024 12:49:37 +0000 (14:49 +0200)] 
Remove defunct --with-locktype configure option

The --with-locktype configure option was no-op, so it was removed.

22 months agochg: dev: Don't open route socket if we don't need it
Ondřej Surý [Mon, 5 Aug 2024 07:31:20 +0000 (07:31 +0000)] 
chg: dev: Don't open route socket if we don't need it

When automatic-interface-scan is disabled, the route socket was still
being opened.  Add new API to connect / disconnect from the route socket
only as needed.

Additionally, move the block that disables periodic interface rescans to
a place where it actually have access to the configuration values.
Previously, the values were being checked before the configuration was
loaded.

Closes #4757

Merge branch '4757-dont-open-routing-socket-if-not-needed' into 'main'

Closes #4757

See merge request isc-projects/bind9!9122

22 months agoDon't open route socket if we don't need it
Ondřej Surý [Tue, 2 Jul 2024 07:22:54 +0000 (09:22 +0200)] 
Don't open route socket if we don't need it

When automatic-interface-scan is disabled, the route socket was still
being opened.  Add new API to connect / disconnect from the route socket
only as needed.

Additionally, move the block that disables periodic interface rescans to
a place where it actually have access to the configuration values.
Previously, the values were being checked before the configuration was
loaded.

22 months agochg: dev: Clarify that cds_wfcq_dequeue_blocking() doesn't block if empty
Ondřej Surý [Mon, 5 Aug 2024 07:30:41 +0000 (07:30 +0000)] 
chg: dev: Clarify that cds_wfcq_dequeue_blocking() doesn't block if empty

Merge branch 'ondrej/clarify-cds_wfcq_dequeue_blocking' into 'main'

See merge request isc-projects/bind9!9124

22 months agoClarify that cds_wfcq_dequeue_blocking() doesn't block if empty
Ondřej Surý [Wed, 3 Jul 2024 09:51:09 +0000 (11:51 +0200)] 
Clarify that cds_wfcq_dequeue_blocking() doesn't block if empty

22 months agofix: usr: Remove extra newline from yaml output
Mark Andrews [Mon, 5 Aug 2024 03:36:41 +0000 (03:36 +0000)] 
fix: usr: Remove extra newline from yaml output

I split this into two commits, one for the actual newline removal, and one for issues I found, ruining the yaml output when some errors were outputted.

Closes: #4772
Merge branch 'yaml-indent' into 'main'

Closes #4772

See merge request isc-projects/bind9!9112

22 months agoRemove newlines from dighost errors calls
Yedaya Katsman [Sun, 16 Jun 2024 20:10:28 +0000 (23:10 +0300)] 
Remove newlines from dighost errors calls

Not all invocations had it, and this makes it more consistent with
dighost_warning. Also remove the conditional newline when not outputting
yaml

22 months agoRemove extra newline from +yaml output
Yedaya Katsman [Sun, 16 Jun 2024 20:09:53 +0000 (23:09 +0300)] 
Remove extra newline from +yaml output

The newlines weren't needed for the yaml syntax, and took up space.

22 months agofix: dev: CID 498025 and CID 498031: Overflowed constant INTEGER_OVERFLOW
Mark Andrews [Sun, 4 Aug 2024 23:48:31 +0000 (23:48 +0000)] 
fix: dev: CID 498025 and CID 498031: Overflowed constant INTEGER_OVERFLOW

Add INSIST to fail if the multiplication would cause the variables to overflow.

Closes #4798

Merge branch '4798-cid-498025-and-cid-498031-overflowed-constant-integer_overflow' into 'main'

Closes #4798

See merge request isc-projects/bind9!9131

22 months agoPrevent overflow of bufsize
Mark Andrews [Tue, 9 Jul 2024 01:55:46 +0000 (11:55 +1000)] 
Prevent overflow of bufsize

If bufsize overflows we will have an infinite loop.  In practice
this will not happen unless we have made a coding error.  Add an
INSIST to detect this condition.

    181retry:
    182        isc_buffer_allocate(mctx, &b, bufsize);
    183        result = dns_rdata_totext(rdata, NULL, b);
    184        if (result == ISC_R_NOSPACE) {
    185                isc_buffer_free(&b);

    CID 498031: (#1 of 1): Overflowed constant (INTEGER_OVERFLOW)
    overflow_const: Expression bufsize, which is equal to 0, overflows
    the type that receives it, an unsigned integer 32 bits wide.
    186                bufsize *= 2;
    187                goto retry;
    188        }

22 months agoPrevent overflow of size
Mark Andrews [Tue, 9 Jul 2024 01:59:39 +0000 (11:59 +1000)] 
Prevent overflow of size

If size overflows we will have an infinite loop.  In practice
this will not happen unless we have made a coding error.  Add
an INSIST to detect this condition.

    181        while (!done) {
    182                isc_buffer_allocate(mctx, &b, size);
    183                result = dns_rdata_totext(rdata, NULL, b);
    184                if (result == ISC_R_SUCCESS) {
    185                        printf("%.*s\n", (int)isc_buffer_usedlength(b),
    186                               (char *)isc_buffer_base(b));
    187                        done = true;
    188                } else if (result != ISC_R_NOSPACE) {
    189                        check_result(result, "dns_rdata_totext");
    190                }
    191                isc_buffer_free(&b);

    CID 498025: (#1 of 1): Overflowed constant (INTEGER_OVERFLOW)
    overflow_const: Expression size, which is equal to 0, overflows the type that
    receives it, an unsigned integer 32 bits wide.
    192                size *= 2;
    193        }

22 months agonew: doc: Clarify how to print default dnssec-policy
Petr Špaček [Fri, 2 Aug 2024 08:25:23 +0000 (08:25 +0000)] 
new: doc: Clarify how to print default dnssec-policy

Merge branch 'pspacek/doc-dnssec-policy-default' into 'main'

See merge request isc-projects/bind9!9092

22 months agoClarify how to print default dnssec-policy
Petr Špaček [Fri, 7 Jun 2024 07:45:48 +0000 (09:45 +0200)] 
Clarify how to print default dnssec-policy

Reading the source tree is unnecessarily complicated, we now have
command line option to print defaults.

22 months agofix: dev: Remove unnecessary operations
Mark Andrews [Fri, 2 Aug 2024 06:34:08 +0000 (06:34 +0000)] 
fix: dev: Remove unnecessary operations

Decrementing optlen immediately before calling continue is unneccesary
and inconsistent with the rest of dns_message_pseudosectiontoyaml
and dns_message_pseudosectiontotext.  Coverity was also reporting
an impossible false positive overflow of optlen (CID 499061).

    4176                        } else if (optcode == DNS_OPT_CLIENT_TAG) {
    4177                                uint16_t id;
    4178                                ADD_STRING(target, "; CLIENT-TAG:");
    4179                                if (optlen == 2U) {
    4180                                        id = isc_buffer_getuint16(&optbuf);
    4181                                        snprintf(buf, sizeof(buf), " %u\n", id);
    4182                                        ADD_STRING(target, buf);

    CID 499061: (#1 of 1): Overflowed constant (INTEGER_OVERFLOW)
    overflow_const: Expression optlen, which is equal to 65534, underflows
    the type that receives it, an unsigned integer 16 bits wide.
    4183                                        optlen -= 2;
    4184                                        POST(optlen);
    4185                                        continue;
    4186                                }
    4187                        } else if (optcode == DNS_OPT_SERVER_TAG) {

Merge branch 'marka-remove-unnecessary-operations' into 'main'

See merge request isc-projects/bind9!9130

22 months agoRemove unnecessary operations
Mark Andrews [Tue, 9 Jul 2024 00:29:30 +0000 (10:29 +1000)] 
Remove unnecessary operations

Decrementing optlen immediately before calling continue is unneccesary
and inconsistent with the rest of dns_message_pseudosectiontoyaml
and dns_message_pseudosectiontotext.  Coverity was also reporting
an impossible false positive overflow of optlen (CID 499061).

    4176                        } else if (optcode == DNS_OPT_CLIENT_TAG) {
    4177                                uint16_t id;
    4178                                ADD_STRING(target, "; CLIENT-TAG:");
    4179                                if (optlen == 2U) {
    4180                                        id = isc_buffer_getuint16(&optbuf);
    4181                                        snprintf(buf, sizeof(buf), " %u\n", id);
    4182                                        ADD_STRING(target, buf);

    CID 499061: (#1 of 1): Overflowed constant (INTEGER_OVERFLOW)
    overflow_const: Expression optlen, which is equal to 65534, underflows
    the type that receives it, an unsigned integer 16 bits wide.
    4183                                        optlen -= 2;
    4184                                        POST(optlen);
    4185                                        continue;
    4186                                }
    4187                        } else if (optcode == DNS_OPT_SERVER_TAG) {

22 months agofix: test: digdelv system test can report more errors than there actually are
Mark Andrews [Fri, 2 Aug 2024 03:01:19 +0000 (03:01 +0000)] 
fix: test: digdelv system test can report more errors than there actually are

Closes #4770

Merge branch '4770-digdelv-system-test-can-report-more-errors-than-they-actually-are' into 'main'

Closes #4770

See merge request isc-projects/bind9!9104

22 months agoReset 'ret' to zero at start of tests
Mark Andrews [Wed, 12 Jun 2024 22:57:14 +0000 (08:57 +1000)] 
Reset 'ret' to zero at start of tests

22 months agochg: usr: allow shorter resolver-query-timeout configuration
Arаm Sаrgsyаn [Thu, 1 Aug 2024 18:31:14 +0000 (18:31 +0000)] 
chg: usr: allow shorter resolver-query-timeout configuration

The minimum allowed value of 'resolver-query-timeout' was lowered to
301 milliseconds instead of the earlier 10000 milliseconds (which is the
default). As earlier, values less than or equal to 300 are converted to
seconds before applying the limit.

Closes #4320

Merge branch '4320-allow-shorter-resolver-query-timeout-configuration' into 'main'

Closes #4320

See merge request isc-projects/bind9!9091

22 months agoUpdate the resolver unit test
Aram Sargsyan [Thu, 6 Jun 2024 19:58:57 +0000 (19:58 +0000)] 
Update the resolver unit test

Before there was a gap from 301 to 9999 which would be converted
to 10000 and now there is no such gap.

This settimeout_belowmin test was checking the behavior of a value
in the gap. As there is now no gap left, the minimum is 301 and
anything below that is converted to seconds as before. In order
for this check to still test the "below minimum" behavior, change
the value from 9000 to 300.

Update the settimeout_overmax value test too so it logically aligns
with the minimum value test.

22 months agoDocument shorter resolver-query-timeout configuration
Aram Sargsyan [Thu, 6 Jun 2024 09:22:55 +0000 (09:22 +0000)] 
Document shorter resolver-query-timeout configuration

The lower limit is now 301 milliseconds instead of 10000 milliseconds.

22 months agoTest shorter resolver-query-timeout configuration
Aram Sargsyan [Thu, 6 Jun 2024 09:20:44 +0000 (09:20 +0000)] 
Test shorter resolver-query-timeout configuration

Add two new checks which test the shorter than usual
resolver-query-timeout configuration.

22 months agoAllow shorter resolver-query-timeout configuration
Aram Sargsyan [Thu, 6 Jun 2024 09:16:57 +0000 (09:16 +0000)] 
Allow shorter resolver-query-timeout configuration

There are use cases for which shorter timeout values make sense.
For example if there is a load balancer which sets RD=1 and
forwards queries to a BIND resolver which is then configured to
talk to backend servers which are not visible in the public NS set.
WIth a shorter timeout value the frontend can give back SERVFAIL
early when backends are not available and the ultimate client will
not penalize the BIND-frontend for non-response.

22 months agonew: usr: implement rndc retransfer -force
Arаm Sаrgsyаn [Thu, 1 Aug 2024 16:54:45 +0000 (16:54 +0000)] 
new: usr: implement rndc retransfer -force

A new optional argument '-force' has been added to the command channel
command 'rndc retransfer'. When it is specified, named aborts the
ongoing zone transfer (if there is one), and starts a new transfer.

Closes #2299

Merge branch '2299-implement-rndc-force-retransfer' into 'main'

Closes #2299

See merge request isc-projects/bind9!9102

22 months agoRename dns_zone_forcereload() to dns_zone_forcexfr()
Aram Sargsyan [Fri, 14 Jun 2024 21:17:54 +0000 (21:17 +0000)] 
Rename dns_zone_forcereload() to dns_zone_forcexfr()

The new name describes the function more accurately.

22 months agoTest rndc retransfer -force
Aram Sargsyan [Tue, 11 Jun 2024 12:26:08 +0000 (12:26 +0000)] 
Test rndc retransfer -force

Use a big zone and the slow transfer mode. Initiate a retransfer, wait
several seconds, then initiate a retransfer using a '-force' argument,
which should cancel the previous transfer and start a new one.

22 months agoMake dns_xfrin_shutdown() safe to run from a different loop
Aram Sargsyan [Tue, 11 Jun 2024 10:57:15 +0000 (10:57 +0000)] 
Make dns_xfrin_shutdown() safe to run from a different loop

If the current loop is different than the zone transfer's loop then
run the shutdown operation asynchronously.

22 months agoImplement rndc retransfer -force
Aram Sargsyan [Tue, 11 Jun 2024 10:55:18 +0000 (10:55 +0000)] 
Implement rndc retransfer -force

With this new optional argument if there is an ongoing zone
transfer it will be aborted before a new zone transfer is scheduled.

22 months agoDo not automatically restart a canceled zone transfer
Aram Sargsyan [Tue, 11 Jun 2024 10:53:06 +0000 (10:53 +0000)] 
Do not automatically restart a canceled zone transfer

If a zone transfer is canceled there is no need to try the
next primary or retry with AXFR.

22 months agofix: usr: fix generation of 6to4-self name expansion from IPv4 address
Mark Andrews [Thu, 1 Aug 2024 06:40:17 +0000 (06:40 +0000)] 
fix: usr: fix generation of 6to4-self name expansion from IPv4 address

The period between the most significant nibble of the encoded IPv4 address and the 2.0.0.2.IP6.ARPA suffix was missing resulting in the wrong name being checked. Add system test for 6to4-self implementation.

Closes #4766

Merge branch '4766-add-system-test-for-6to4-self' into 'main'

Closes #4766

See merge request isc-projects/bind9!9099

22 months agocheck 'update-policy 6to4-self' over IPv6
Mark Andrews [Fri, 7 Jun 2024 03:28:48 +0000 (13:28 +1000)] 
check 'update-policy 6to4-self' over IPv6

22 months agocheck 'update-policy 6to4-self' over IPv4
Mark Andrews [Wed, 5 Jun 2024 05:22:17 +0000 (15:22 +1000)] 
check 'update-policy 6to4-self' over IPv4

22 months agoAdd missing period to generated IPv4 6to4 name
Mark Andrews [Wed, 5 Jun 2024 03:59:39 +0000 (13:59 +1000)] 
Add missing period to generated IPv4 6to4 name

The period between the most significant nibble of the IPv4 address
and the 2.0.0.2.IP6.ARPA suffix was missing resulting in the wrong
name being checked.

22 months agofix: usr: fix false QNAME minimisation error being reported
Mark Andrews [Thu, 1 Aug 2024 05:16:20 +0000 (05:16 +0000)] 
fix: usr: fix false QNAME minimisation error being reported

Remove the false positive "success resolving" log message when QNAME minimisation is in effect and the final result is NXDOMAIN.

Closes #4784

Merge branch '4784-false-qname-minimisation-error-being-reported' into 'main'

Closes #4784

See merge request isc-projects/bind9!9117

22 months agoTest that false positive "success resolving" is not logged
Mark Andrews [Tue, 25 Jun 2024 04:00:51 +0000 (14:00 +1000)] 
Test that false positive "success resolving" is not logged

22 months agoCleanup old clang-format string splitting
Mark Andrews [Tue, 25 Jun 2024 06:42:25 +0000 (16:42 +1000)] 
Cleanup old clang-format string splitting

22 months agoRemove false positive qname minimisation error
Mark Andrews [Thu, 20 Jun 2024 04:02:24 +0000 (14:02 +1000)] 
Remove false positive qname minimisation error

Don't report qname minimisation NXDOMAIN errors when the result is
NXDOMAIN.

22 months agofix: usr: Dig +yaml was producing unexpected and/or invalid YAML output
Mark Andrews [Thu, 1 Aug 2024 03:44:17 +0000 (03:44 +0000)] 
fix: usr: Dig +yaml was producing unexpected and/or invalid YAML output

Closes #4796

Merge branch '4796-yaml-stringify-question-and-records' into 'main'

Closes #4796

See merge request isc-projects/bind9!9127

22 months agoTest yaml output with yaml specials
Mark Andrews [Mon, 8 Jul 2024 05:49:48 +0000 (15:49 +1000)] 
Test yaml output with yaml specials

22 months agoFix yaml output
Mark Andrews [Mon, 8 Jul 2024 04:00:14 +0000 (14:00 +1000)] 
Fix yaml output

In yaml mode we emit a string for each question and record.  Certain
names and data could result in invalid yaml being produced.  Use single
quote string for all questions and records.  This requires that single
quotes get converted to two quotes within the string.

22 months agochg: test: resolver system test didn't fail on all subtest errors
Mark Andrews [Thu, 1 Aug 2024 02:29:19 +0000 (02:29 +0000)] 
chg: test: resolver system test didn't fail on all subtest errors

Closes #4774

Merge branch '4774-resolver-system-test-didn-t-fail-on-all-subtest-errors' into 'main'

Closes #4774

See merge request isc-projects/bind9!9105

22 months agoresolver system test didn't record all failures
Mark Andrews [Mon, 17 Jun 2024 01:36:41 +0000 (11:36 +1000)] 
resolver system test didn't record all failures

22 months agofix: usr: SVBC alpn text parsing failed to reject zero length alpn
Mark Andrews [Thu, 1 Aug 2024 01:06:37 +0000 (01:06 +0000)] 
fix: usr: SVBC alpn text parsing failed to reject zero length alpn

Closes #4775

Merge branch '4775-reject-zero-length-alpn-in-alpn-fromtext' into 'main'

Closes #4775

See merge request isc-projects/bind9!9106

22 months agoCheck invalid alpn empty value
Mark Andrews [Sun, 30 Jun 2024 23:23:31 +0000 (09:23 +1000)] 
Check invalid alpn empty value

22 months agoCheck invalid alpn produced due to missing double escapes
Mark Andrews [Mon, 17 Jun 2024 07:00:36 +0000 (17:00 +1000)] 
Check invalid alpn produced due to missing double escapes

22 months agoProperly reject zero length ALPN in commatxt_fromtext
Mark Andrews [Mon, 17 Jun 2024 13:16:28 +0000 (23:16 +1000)] 
Properly reject zero length ALPN in commatxt_fromtext

ALPN are defined as 1*255OCTET in RFC 9460.  commatxt_fromtext was not
rejecting invalid inputs produces by missing a level of escaping
which where later caught be dns_rdata_fromwire on reception.

These inputs should have been rejected

svcb in svcb 1 1.svcb alpn=\,abc
svcb1 in svcb 1 1.svcb alpn=a\,\,abc

and generated 00 03 61 62 63 and 01 61 00 02 61 62 63 respectively.

The correct inputs to include commas in the alpn requires double
escaping.

svcb in svcb 1 1.svcb alpn=\\,abc
svcb1 in svcb 1 1.svcb alpn=a\\,\\,abc

and generate 04 2C 61 62 63 and 06 61 2C 2C 61 62 63 respectively.

22 months agochg: doc: update querylog documentation in ARM
Arаm Sаrgsyаn [Wed, 31 Jul 2024 16:05:55 +0000 (16:05 +0000)] 
chg: doc: update querylog documentation in ARM

Add a note that 'rndc reload' and 'rndc reconfig' can't change the
querylog option during the runtime of named.

Closes #4801

Merge branch '4801-arm-querylog-clarification' into 'main'

Closes #4801

See merge request isc-projects/bind9!9136

22 months agoUpdate querylog documentation in ARM
Aram Sargsyan [Wed, 10 Jul 2024 12:42:16 +0000 (12:42 +0000)] 
Update querylog documentation in ARM

Add a note that 'rndc reload' and 'rndc reconfig' can't change the
querylog option during the runtime of named.

22 months agochg: dev: replace #define DNS_GETDB_ with struct of bools
Arаm Sаrgsyаn [Wed, 31 Jul 2024 12:53:50 +0000 (12:53 +0000)] 
chg: dev: replace #define DNS_GETDB_ with struct of bools

Replace #define DNS_GETDB_ with struct of bools to make
it easier to pretty-print the attributes in a debugger.

Closes #4559

Merge branch '4559-convert-dns_getdb_x-defines-to-1-bit-long-bools' into 'main'

Closes #4559

See merge request isc-projects/bind9!9093

22 months agoReplace #define DNS_GETDB_ with struct of bools
Aram Sargsyan [Fri, 7 Jun 2024 10:18:09 +0000 (10:18 +0000)] 
Replace #define DNS_GETDB_ with struct of bools

This makes it easier to pretty-print the attributes in a debugger.

22 months agofix: usr: return SERVFAIL for a too long CNAME chain
Arаm Sаrgsyаn [Wed, 31 Jul 2024 11:50:33 +0000 (11:50 +0000)] 
fix: usr: return SERVFAIL for a too long CNAME chain

When cutting a long CNAME chain, named was returning NOERROR
instead of SERVFAIL (alongside with a partial answer). This
has been fixed.

Closes #4449

Merge branch '4449-return-servfail-for-a-long-cname-chain' into 'main'

Closes #4449

See merge request isc-projects/bind9!9090

22 months agoUpdate the chain test
Aram Sargsyan [Thu, 6 Jun 2024 20:49:34 +0000 (20:49 +0000)] 
Update the chain test

Update the CNAME chain test to correspond to the changed behavior,
because now named returns SERVFAIL when hitting the maximum query
restarts limit (e.g. happening when following a long CNAME chain).

In the current test auth will hit the limit and return partial data
with a SERVFAIL code, while the resolver will return no data with
a SERVFAIL code after auth returns SERVFAIL to it.

22 months agoTest that a long CNAME chain causes SERVFAIL
Aram Sargsyan [Thu, 6 Jun 2024 12:10:19 +0000 (12:10 +0000)] 
Test that a long CNAME chain causes SERVFAIL

Also check that the expected partial answer in returned too.

22 months agoReturn SERVFAIL for a too long CNAME chain
Aram Sargsyan [Thu, 6 Jun 2024 12:06:59 +0000 (12:06 +0000)] 
Return SERVFAIL for a too long CNAME chain

Due to the maximum query restart limitation a long CNAME chain
it is cut after 16 queries but named still returns NOERROR.

Return SERVFAIL instead and the partial answer.

22 months agochg: test: Improve crypto support detection and algorithm selection in pytest
Nicki Křížek [Wed, 31 Jul 2024 09:37:51 +0000 (09:37 +0000)] 
chg: test: Improve crypto support detection and algorithm selection in pytest

Ensure that the selected algorithms remains stable throughout the entire test session. Crypto support detection was rewritten to python and simplified.

Closes #4202

Closes #4422

Related #3810

Merge branch '4202-algorithm-detection-pytest' into 'main'

Closes #4202 and #4422

See merge request isc-projects/bind9!8803

22 months agoInitialize all environment variables when running isctest
Nicki Křížek [Fri, 10 May 2024 11:10:14 +0000 (13:10 +0200)] 
Initialize all environment variables when running isctest

Ensure all the variables are initialized when running the main function
of isctest module. This enables proper environment variables during test
script development when only conf.sh is sourced, rather than the script
being executed by the pytest runner.

22 months agoReplace testcrypto.sh invocations in tests
Tom Krizek [Wed, 24 Jan 2024 14:38:55 +0000 (15:38 +0100)] 
Replace testcrypto.sh invocations in tests

Use the provided environment variables instead.

22 months agoRewrite testcrypto.sh into python
Tom Krizek [Mon, 8 Jan 2024 11:54:19 +0000 (12:54 +0100)] 
Rewrite testcrypto.sh into python

Run the crypto support checks when initializing the isctest package and
save those results in environment variable. This removes the need to
repeatedly check for crypto operation support, as it's not something
that would change at test runtime.

22 months agoMove test algorithm configuration to isctest
Tom Krizek [Thu, 4 Jan 2024 16:27:32 +0000 (17:27 +0100)] 
Move test algorithm configuration to isctest

Instead of invoking get_algorithms.py script repeatedly (which may yield
different results), move the algorithm configuration to an isctest
module. This ensures the variables are consistent across the entire test
run.

22 months agonew: usr: add support for external log rotation tools
Mark Andrews [Wed, 31 Jul 2024 08:48:51 +0000 (08:48 +0000)] 
new: usr: add support for external log rotation tools

Add two mechanisms to close open log files.  The first is `rndc closelogs`.  The second is `kill -USR1 <pid>`.
They are intended to be used with external log rotation tools.

Closes #4780

Merge branch '4780-add-support-for-external-log-rotation-tools' into 'main'

Closes #4780

See merge request isc-projects/bind9!9113

22 months agoTest that 'kill -USR1' works
Mark Andrews [Wed, 26 Jun 2024 00:53:14 +0000 (10:53 +1000)] 
Test that 'kill -USR1' works

22 months agoDocument that SIGUSR1 closes log files
Mark Andrews [Wed, 26 Jun 2024 00:55:24 +0000 (10:55 +1000)] 
Document that SIGUSR1 closes log files

22 months agoConfigure SIGUSR1 to close log files
Mark Andrews [Wed, 26 Jun 2024 00:47:47 +0000 (10:47 +1000)] 
Configure SIGUSR1 to close log files

Some external log file rotation programs use signals to tell programs
to close log files.  SIGHUP can be used to do this but it also does
a full reconfiguration.  Configure named to accept SIGUSR1 as a
signal to close log files.

22 months agoTest that 'rndc closelogs' works
Mark Andrews [Wed, 19 Jun 2024 00:43:49 +0000 (10:43 +1000)] 
Test that 'rndc closelogs' works

22 months agoAdd a rndc command to close currently open log files
Mark Andrews [Wed, 19 Jun 2024 00:20:33 +0000 (10:20 +1000)] 
Add a rndc command to close currently open log files

The new command is 'rndc closelogs'.