]> git.ipfire.org Git - thirdparty/bind9.git/log
thirdparty/bind9.git
3 years agoRemove dead code in xfrin.c
Mark Andrews [Mon, 18 Jul 2022 06:42:00 +0000 (16:42 +1000)] 
Remove dead code in xfrin.c

also removed unnecessary 'msg != NULL' check

   *** CID 352815:  Control flow issues  (DEADCODE) /lib/dns/xfrin.c: 1363 in xfrin_send_request()
   1357      isc_nmhandle_attach(send_xfr->handle, &xfr->sendhandle);
   1358      isc_refcount_increment0(&send_xfr->sends);
   1359      isc_nm_send(xfr->handle, &region, xfrin_send_done, send_xfr);
   1360
   1361     failure:
   1362      if (qname != NULL) {
   >>>     CID 352815:  Control flow issues  (DEADCODE)
   >>>     Execution cannot reach this statement: "dns_message_puttempname(msg...".
   1363      dns_message_puttempname(msg, &qname);
   1364      }
   1365      if (qrdataset != NULL) {
   1366      dns_message_puttemprdataset(msg, &qrdataset);
   1367      }
   1368      if (msg != NULL) {

   *** CID 352819:  Control flow issues  (DEADCODE) /lib/dns/xfrin.c: 1366 in xfrin_send_request()
   1360
   1361     failure:
   1362      if (qname != NULL) {
   1363      dns_message_puttempname(msg, &qname);
   1364      }
   1365      if (qrdataset != NULL) {
   >>>     CID 352819:  Control flow issues  (DEADCODE)
   >>>     Execution cannot reach this statement: "dns_message_puttemprdataset...".
   1366      dns_message_puttemprdataset(msg, &qrdataset);
   1367      }
   1368      if (msg != NULL) {
   1369      dns_message_detach(&msg);
   1370      }
   1371      if (soatuple != NULL) {

3 years agoMerge branch '3518-libxml2-deprecated-functions' into 'main'
Arаm Sаrgsyаn [Tue, 6 Sep 2022 09:42:01 +0000 (09:42 +0000)] 
Merge branch '3518-libxml2-deprecated-functions' into 'main'

Do not use libxml2 deprecated functions

Closes #3518

See merge request isc-projects/bind9!6727

3 years agoAdd CHANGES note for [GL #3518]
Aram Sargsyan [Mon, 5 Sep 2022 10:01:33 +0000 (10:01 +0000)] 
Add CHANGES note for [GL #3518]

3 years agoDo not use libxml2 deprecated functions
Aram Sargsyan [Mon, 5 Sep 2022 09:59:44 +0000 (09:59 +0000)] 
Do not use libxml2 deprecated functions

The usage of xmlInitThreads() and xmlCleanupThreads() functions in
libxml2 is now marked as deprecated, and these functions will be made
private in the future.

Use xmlInitParser() and xmlCleanupParser() instead of them.

3 years agoMerge branch 'aram/isc_nm_listentlsdns-error-path-bugfix' into 'main'
Arаm Sаrgsyаn [Tue, 6 Sep 2022 08:25:39 +0000 (08:25 +0000)] 
Merge branch 'aram/isc_nm_listentlsdns-error-path-bugfix' into 'main'

Fix isc_nm_listentlsdns() error path bug

See merge request isc-projects/bind9!6728

3 years agoFix isc_nm_listentlsdns() error path bug
Aram Sargsyan [Mon, 5 Sep 2022 14:42:32 +0000 (14:42 +0000)] 
Fix isc_nm_listentlsdns() error path bug

The isc_nm_listentlsdns() function erroneously calls
isc__nm_tcpdns_stoplistening() instead of isc__nm_tlsdns_stoplistening()
when something goes wrong, which can cause an assertion failure.

3 years agoMerge branch '3485-dig-fallback-to-idna2003' into 'main'
Ondřej Surý [Mon, 5 Sep 2022 08:36:48 +0000 (08:36 +0000)] 
Merge branch '3485-dig-fallback-to-idna2003' into 'main'

Allow fallback to IDNA2003 processing

Closes #3485

See merge request isc-projects/bind9!6699

3 years agoAdd CHANGES and release note for [GL #3485]
Ondřej Surý [Fri, 26 Aug 2022 10:28:10 +0000 (12:28 +0200)] 
Add CHANGES and release note for [GL #3485]

3 years agoEnable the IDNA2003 domain names in the idna system test
Ondřej Surý [Fri, 26 Aug 2022 11:10:22 +0000 (13:10 +0200)] 
Enable the IDNA2003 domain names in the idna system test

Allow the IDNA2003 tests to succeed after the fallback to IDNA2003 was
implemented.

3 years agoAllow fallback to IDNA2003 processing
Ondřej Surý [Fri, 26 Aug 2022 10:24:07 +0000 (12:24 +0200)] 
Allow fallback to IDNA2003 processing

In several cases where IDNA2008 mappings do not exist whereas IDNA2003
mappings do, dig was failing to process the suplied domain name.  Take a
backwards compatible approach, and convert the domain to IDNA2008 form,
and if that fails try the IDNA2003 conversion.

3 years agoMerge branch '3515-mctx-attach-detach-for-isc_mempool_t' into 'main'
Arаm Sаrgsyаn [Fri, 2 Sep 2022 09:02:38 +0000 (09:02 +0000)] 
Merge branch '3515-mctx-attach-detach-for-isc_mempool_t' into 'main'

Add mctx attach/detach when creating/destroying a memory pool

Closes #3515

See merge request isc-projects/bind9!6712

3 years agoAdd CHANGES note for [GL #3515]
Aram Sargsyan [Wed, 31 Aug 2022 12:35:53 +0000 (12:35 +0000)] 
Add CHANGES note for [GL #3515]

3 years agoAdd mctx attach/detach when creating/destroying a memory pool
Aram Sargsyan [Wed, 31 Aug 2022 12:30:38 +0000 (12:30 +0000)] 
Add mctx attach/detach when creating/destroying a memory pool

This should make sure that the memory context is not destroyed
before the memory pool, which is using the context.

3 years agoMerge branch '3514-cid-356328-deadcode-in-server.c' into 'main'
Arаm Sаrgsyаn [Fri, 2 Sep 2022 08:14:46 +0000 (08:14 +0000)] 
Merge branch '3514-cid-356328-deadcode-in-server.c' into 'main'

Resolve "CID 356328: Control flow issues (DEADCODE) in bin/named/server.c"

Closes #3514

See merge request isc-projects/bind9!6713

3 years agoUse the return value of isc_portset_create()
Aram Sargsyan [Wed, 31 Aug 2022 13:18:39 +0000 (13:18 +0000)] 
Use the return value of isc_portset_create()

There is an omission of assigning the return value coming from the
isc_portset_create() function to the result variable.

CID 356328:

    /bin/named/server.c: 8756 in load_configuration()
    8750            "creating UDP/IPv4 port set: %s",
    8751            isc_result_totext(result));
    8752      goto cleanup_bindkeys_parser;
    8753      }
    8754      isc_portset_create(named_g_mctx, &v6portset);
    8755      if (result != ISC_R_SUCCESS) {
    >>>     CID 356328:  Control flow issues  (DEADCODE)
    >>>     Execution cannot reach this statement: "isc_log_write(named_g_lctx,...".
    8756      isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
    8757            NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
    8758            "creating UDP/IPv6 port set: %s",
    8759            isc_result_totext(result));
    8760      goto cleanup_v4portset;
    8761      }

3 years agoMerge branch '3511-quote-yaml-addresses' into 'main'
Evan Hunt [Wed, 31 Aug 2022 23:16:32 +0000 (23:16 +0000)] 
Merge branch '3511-quote-yaml-addresses' into 'main'

quote addresses in YAML output

Closes #3511

See merge request isc-projects/bind9!6702

3 years agoCHANGES for [GL #3511]
Evan Hunt [Sat, 27 Aug 2022 01:00:50 +0000 (18:00 -0700)] 
CHANGES for [GL #3511]

3 years agoquote addresses in YAML output
Evan Hunt [Sat, 27 Aug 2022 00:58:55 +0000 (17:58 -0700)] 
quote addresses in YAML output

YAML strings should be quoted if they contain colon characters.
Since IPv6 addresses do, we now quote the query_address and
response_address strings in all YAML output.

3 years agoMerge branch '3501-dnstap-response' into 'main'
Evan Hunt [Wed, 31 Aug 2022 22:22:44 +0000 (22:22 +0000)] 
Merge branch '3501-dnstap-response' into 'main'

dnstap query_message field was erroneously set with responses

Closes #3501

See merge request isc-projects/bind9!6701

3 years agoCHANGES for [GL #3501]
Evan Hunt [Fri, 26 Aug 2022 23:01:31 +0000 (16:01 -0700)] 
CHANGES for [GL #3501]

3 years agodnstap query_message field was erroneously set with responses
Evan Hunt [Fri, 26 Aug 2022 22:38:34 +0000 (15:38 -0700)] 
dnstap query_message field was erroneously set with responses

The dnstap query_message field was in some cases being filled in
with response messages, along with the response_message field.
The query_message field should only be used when logging requests,
and the response_message field only when logging responses.

3 years agoMerge branch '3410-rpz-extended-errors' into 'main'
Arаm Sаrgsyаn [Wed, 31 Aug 2022 09:21:11 +0000 (09:21 +0000)] 
Merge branch '3410-rpz-extended-errors' into 'main'

RPZ Extended DNS Error Codes

Closes #3410

See merge request isc-projects/bind9!6700

3 years agoAdd CHANGES note for [GL #3410]
Aram Sargsyan [Fri, 26 Aug 2022 14:47:42 +0000 (14:47 +0000)] 
Add CHANGES note for [GL #3410]

3 years agoDocument RPZ Extended DNS Error (EDE) code configuration option
Aram Sargsyan [Fri, 26 Aug 2022 14:39:11 +0000 (14:39 +0000)] 
Document RPZ Extended DNS Error (EDE) code configuration option

Add information about the 'ede' option for response policy zones.

3 years agoAdd system tests for RPZ EDE codes
Aram Sargsyan [Fri, 26 Aug 2022 14:18:28 +0000 (14:18 +0000)] 
Add system tests for RPZ EDE codes

Check the new configuration option's syntax using the 'checkconf' system
test.

Check if the new option works by parsing DiG's output in the 'rpz'
system test.

3 years agoSet the extended DNS error code for RPZ-modified queries
Aram Sargsyan [Fri, 26 Aug 2022 14:15:16 +0000 (14:15 +0000)] 
Set the extended DNS error code for RPZ-modified queries

When enabled through a configuration option, set the configured EDE code
for the modified queries.

3 years agoAdd extended DNS error configuration option for RPZ zones
Aram Sargsyan [Fri, 26 Aug 2022 14:11:47 +0000 (14:11 +0000)] 
Add extended DNS error configuration option for RPZ zones

Implement the configuration option with its checking and parsing parts.

The option should be later used by BIND to set an extended error
code (EDE) for the queries modified in the result of RPZ processing.

3 years agoMerge branch 'aram/rpz-doc-update' into 'main'
Arаm Sаrgsyаn [Wed, 31 Aug 2022 08:52:35 +0000 (08:52 +0000)] 
Merge branch 'aram/rpz-doc-update' into 'main'

Update RPZ documentation in ARM

See merge request isc-projects/bind9!6705

3 years agoUpdate RPZ documentation
Aram Sargsyan [Fri, 26 Aug 2022 09:20:02 +0000 (09:20 +0000)] 
Update RPZ documentation

The RPZ documentation section with response policy rules and actions
is incomplete.

Add information about the 'RPZ-CLIENT-IP' rule, and 'TCP-Only' and
'DROP' actions.

3 years agoMerge branch 'ondrej-add-isc-loopmgr' into 'main'
Ondřej Surý [Fri, 26 Aug 2022 08:08:42 +0000 (08:08 +0000)] 
Merge branch 'ondrej-add-isc-loopmgr' into 'main'

Separate the event loop handling into a separate layer

Closes #3508

See merge request isc-projects/bind9!6040

3 years agoCHANGES and release note for [GL #3508]
Evan Hunt [Thu, 25 Aug 2022 22:06:33 +0000 (15:06 -0700)] 
CHANGES and release note for [GL #3508]

3 years agoClear the callbacks when isc_nm_stoplistening() is called
Ondřej Surý [Wed, 24 Aug 2022 12:59:50 +0000 (14:59 +0200)] 
Clear the callbacks when isc_nm_stoplistening() is called

When we are closing the listening sockets, there's a time window in
which the TCP connection could be accepted although the respective
stoplistening function has already returned to control to the caller.
Clear the accept callback function early, so it doesn't get called when
we are not interested in the incoming connections anymore.

3 years agoRemove the isc_app API
Ondřej Surý [Tue, 26 Jul 2022 11:03:53 +0000 (13:03 +0200)] 
Remove the isc_app API

The isc_app API is no longer used and has been removed.

3 years agoSplit netmgr_test into separate per-transport unit tests
Ondřej Surý [Tue, 26 Jul 2022 11:03:48 +0000 (13:03 +0200)] 
Split netmgr_test into separate per-transport unit tests

The netmgr_test unit test has been subdivided into tcp_test,
tcpdns_test, tls_test, tlsdns_test, and udp_test components.
These have been updated to use the new loopmgr.

3 years agoUpdate netmgr, tasks, and applications to use isc_loopmgr
Ondřej Surý [Tue, 26 Jul 2022 11:03:45 +0000 (13:03 +0200)] 
Update netmgr, tasks, and applications to use isc_loopmgr

Previously:

* applications were using isc_app as the base unit for running the
  application and signal handling.

* networking was handled in the netmgr layer, which would start a
  number of threads, each with a uv_loop event loop.

* task/event handling was done in the isc_task unit, which used
  netmgr event loops to run the isc_event calls.

In this refactoring:

* the network manager now uses isc_loop instead of maintaining its
  own worker threads and event loops.

* the taskmgr that manages isc_task instances now also uses isc_loopmgr,
  and every isc_task runs on a specific isc_loop bound to the specific
  thread.

* applications have been updated as necessary to use the new API.

* new ISC_LOOP_TEST macros have been added to enable unit tests to
  run isc_loop event loops. unit tests have been updated to use this
  where needed.

3 years agoUpdate isc_timer to use isc_loopmgr
Ondřej Surý [Tue, 26 Jul 2022 11:03:40 +0000 (13:03 +0200)] 
Update isc_timer to use isc_loopmgr

* isc_timer was rewritten using the uv_timer, and isc_timermgr_t was
  completely removed; isc_timer objects are now directly created on the
  isc_loop event loops.

* the isc_timer API has been simplified. the "inactive" timer type has
  been removed; timers are now stopped by calling isc_timer_stop()
  instead of resetting to inactive.

* isc_manager now creates a loop manager rather than a timer manager.

* modules and applications using isc_timer have been updated to use the
  new API.

3 years agoNew event loop handling API
Ondřej Surý [Tue, 26 Jul 2022 11:03:22 +0000 (13:03 +0200)] 
New event loop handling API

This commit introduces new APIs for applications and signal handling,
intended to replace isc_app for applications built on top of libisc.

* isc_app will be replaced with isc_loopmgr, which handles the
  starting and stopping of applications. In isc_loopmgr, the main
  thread is not blocked, but is part of the working thread set.
  The loop manager will start a number of threads, each with a
  uv_loop event loop running. Setup and teardown functions can be
  assigned which will run when the loop starts and stops, and
  jobs can be scheduled to run in the meantime. When
  isc_loopmgr_shutdown() is run from any the loops, all loops
  will shut down and the application can terminate.

* signal handling will now be handled with a separate isc_signal unit.
  isc_loopmgr only handles SIGTERM and SIGINT for application
  termination, but the application may install additional signal
  handlers, such as SIGHUP as a signal to reload configuration.

* new job running primitives, isc_job and isc_async, have been added.
  Both units schedule callbacks (specifying a callback function and
  argument) on an event loop. The difference is that isc_job unit is
  unlocked and not thread-safe, so it can be used to efficiently
  run jobs in the same thread, while isc_async is thread-safe and
  uses locking, so it can be used to pass jobs from one thread to
  another.

* isc_tid will be used to track the thread ID in isc_loop worker
  threads.

* unit tests have been added for the new APIs.

3 years agoSimplify the isc_event API
Ondřej Surý [Tue, 26 Jul 2022 11:03:01 +0000 (13:03 +0200)] 
Simplify the isc_event API

The ev_tag field was never used, and has now been removed.

3 years agoMerge branch '3505-missing-isc_mutex_destroy' into 'main'
Mark Andrews [Wed, 24 Aug 2022 07:00:17 +0000 (07:00 +0000)] 
Merge branch '3505-missing-isc_mutex_destroy' into 'main'

Resolve "missing isc_mutex_destroy"

Closes #3505

See merge request isc-projects/bind9!6696

3 years agoCall isc_mutex_destroy(&lasttime_mx);
Mark Andrews [Wed, 24 Aug 2022 06:41:55 +0000 (16:41 +1000)] 
Call isc_mutex_destroy(&lasttime_mx);

3 years agoMerge branch '3500-nsec3-missing-detach-node' into 'main'
Matthijs Mekking [Tue, 23 Aug 2022 10:03:28 +0000 (10:03 +0000)] 
Merge branch '3500-nsec3-missing-detach-node' into 'main'

nsec3.c: Add a missing dns_db_detachnode() call

Closes #3500

See merge request isc-projects/bind9!6692

3 years agoAdd CHANGES entry for #3500
Matthijs Mekking [Tue, 23 Aug 2022 09:04:00 +0000 (11:04 +0200)] 
Add CHANGES entry for #3500

There is no need for a release because this case was nearly impossible
to trigger (except for when 'sig-signing-type' was set to 0).

3 years agonsec3.c: Add a missing dns_db_detachnode() call
Matthijs Mekking [Tue, 23 Aug 2022 08:54:42 +0000 (10:54 +0200)] 
nsec3.c: Add a missing dns_db_detachnode() call

There is one case in 'dns_nsec3_activex()' where it returns but forgets
to detach the db node. Add the missing 'dns_db_detachnode()' call.

This case only triggers if 'sig-signing-type' (privatetype) is set to 0
(which by default is not), or if the function is called with 'complete'
is set to 'true' (which at this moment do not exist).

3 years agoMerge branch '3486-checkconf-dnssec-policy-nsec3-incompatible-algorithm' into 'main'
Matthijs Mekking [Mon, 22 Aug 2022 14:37:07 +0000 (14:37 +0000)] 
Merge branch '3486-checkconf-dnssec-policy-nsec3-incompatible-algorithm' into 'main'

Graceful dnssec-policy transition from NSEC only to NSEC3

Closes #3486

See merge request isc-projects/bind9!6647

3 years agoFix nsec3 system test issues
Matthijs Mekking [Fri, 19 Aug 2022 12:42:47 +0000 (14:42 +0200)] 
Fix nsec3 system test issues

The wait_for_zone_is_signed function was never called, which could lead
to test failures due to timing issues (where a zone was not fully signed
yet, but the test was trying to verify the zone).

Also add two missing set_nsec3param calls to ensure the ITERATIONS
value is set for these test cases.

3 years agoAdd change entry and release note for #3486
Matthijs Mekking [Wed, 10 Aug 2022 14:52:53 +0000 (16:52 +0200)] 
Add change entry and release note for #3486

News worthy.

3 years agoAdd test case for #3486
Matthijs Mekking [Wed, 10 Aug 2022 14:41:30 +0000 (16:41 +0200)] 
Add test case for #3486

Add two scenarios where we change the dnssec-policy from using RSASHA1
to something with NSEC3.

The first case should work, as the DS is still in hidden state and we
can basically do anything with DNSSEC.

The second case should fail, because the DS of the predecessor is
published and we can't immediately remove the predecessor DNSKEY. So
in this case we should keep the NSEC chain for a bit longer.

Add two more scenarios where we change the dnssec-policy from using
NSEC3 to something NSEC only. Both should work because there are no
restrictions on using NSEC when it comes to algorithms, but in the
cases where the DS is published we can't bluntly remove the predecessor.

Extend the nsec3 system test by also checking the DNSKEY RRset for the
expected DNSKEY records. This requires some "kasp system"-style setup
for each test (setting key properties and key states). Also move the
dnssec-verify check inside the check_nsec/check_nsec3 functions because
we will have to do that every time.

3 years agoWait with NSEC3 during a DNSSEC policy change
Matthijs Mekking [Wed, 10 Aug 2022 13:29:59 +0000 (15:29 +0200)] 
Wait with NSEC3 during a DNSSEC policy change

When doing a dnssec-policy reconfiguration from a zone with NSEC only
keys to a zone that uses NSEC3, figure out to wait with building the
NSEC3 chain.

Previously, BIND 9 would attempt to sign such a zone, but failed to
do so because the NSEC3 chain conflicted with existing DNSKEY records
in the zone that were not compatible with NSEC3.

There exists logic for detecting such a case in the functions
dnskey_sane() (in lib/dns/zone.c) and check_dnssec() (in
lib/ns/update.c). Both functions look very similar so refactor them
to use the same code and call the new function (called
dns_zone_check_dnskey_nsec3()).

Also update the dns_nsec_nseconly() function to take an additional
parameter 'diff' that, if provided, will be checked whether an
offending NSEC only DNSKEY will be deleted from the zone. If so,
this key will not be considered when checking the zone for NSEC only
DNSKEYs. This is needed to allow a transition from an NSEC zone with
NSEC only DNSKEYs to an NSEC3 zone.

3 years agoTest checkconf NSEC3 and incompatible algorithm
Matthijs Mekking [Wed, 10 Aug 2022 13:24:21 +0000 (15:24 +0200)] 
Test checkconf NSEC3 and incompatible algorithm

The check code for this already exists, but was untested.

3 years agoMerge branch '3463-httpd.c-non-empty-post-requests-bugfix' into 'main'
Arаm Sаrgsyаn [Fri, 19 Aug 2022 08:32:41 +0000 (08:32 +0000)] 
Merge branch '3463-httpd.c-non-empty-post-requests-bugfix' into 'main'

Fix statistics channel multiple request processing with non-empty HTTP bodies

Closes #3463

See merge request isc-projects/bind9!6597

3 years agoAdd pipelined POST requests check in the statschannel system test
Aram Sargsyan [Wed, 20 Jul 2022 13:33:40 +0000 (13:33 +0000)] 
Add pipelined POST requests check in the statschannel system test

Use `nc` to check that multiple POST requests with non-empty HTTP
body are serviced normally by the statistics channel.

3 years agoReplace expr commands with $((expression)) shell constucts
Aram Sargsyan [Wed, 20 Jul 2022 13:21:27 +0000 (13:21 +0000)] 
Replace expr commands with $((expression)) shell constucts

Update the "statschannel" system test to use the $((expression))
shell constucts instead of executing the `expr` program.

3 years agoAdd CHANGES not for [GL #3463]
Aram Sargsyan [Wed, 20 Jul 2022 10:27:29 +0000 (10:27 +0000)] 
Add CHANGES not for [GL #3463]

3 years agoFix statistics channel multiple request processing with non-empty bodies
Aram Sargsyan [Wed, 20 Jul 2022 10:18:56 +0000 (10:18 +0000)] 
Fix statistics channel multiple request processing with non-empty bodies

When the HTTP request has a body part after the HTTP headers, it is
not getting processed and is being prepended to the next request's data,
which results in an error when trying to parse it.

Improve the httpd.c:process_request() function with the following
additions:

1. Require that HTTP POST requests must have Content-Length header.
2. When Content-Length header is set, extract its value, and make sure
   that it is valid and that the whole request's body is received before
   processing the request.
3. Discard the request's body by consuming Content-Length worth of data
   in the buffer.

3 years agoEnhance the have_header() function to find the HTTP header's value
Aram Sargsyan [Wed, 20 Jul 2022 10:06:56 +0000 (10:06 +0000)] 
Enhance the have_header() function to find the HTTP header's value

Add a new `const char **fvalue` parameter to the httpd.c:have_header()
function which, when set, will point to the found header's value.

3 years agoMerge branch 'bug/main/delv-cfg_parser_reset' into 'main'
Mark Andrews [Fri, 19 Aug 2022 05:15:14 +0000 (05:15 +0000)] 
Merge branch 'bug/main/delv-cfg_parser_reset' into 'main'

Reset bind.keys parser after error on file

See merge request isc-projects/bind9!6468

3 years agoAdd CHANGES entry for [GL !6468]
Mark Andrews [Fri, 19 Aug 2022 04:38:32 +0000 (14:38 +1000)] 
Add CHANGES entry for [GL !6468]

3 years agoReset parser before parsing of internal trust anchor
Petr Menšík [Thu, 11 Aug 2022 09:41:30 +0000 (11:41 +0200)] 
Reset parser before parsing of internal trust anchor

It might be reused if /etc/bind.keys exists, but failed correct parsing.
Release traces of previous parsing attempt of different data.

3 years agoMerge branch '3499-duration-c-66-6-warning-array-subscript-is-of-type-char-on-netbsd...
Mark Andrews [Fri, 19 Aug 2022 02:28:45 +0000 (02:28 +0000)] 
Merge branch '3499-duration-c-66-6-warning-array-subscript-is-of-type-char-on-netbsd-9' into 'main'

Resolve "duration.c:66:6: warning: array subscript is of type 'char' on NetBSD 9"

Closes #3499

See merge request isc-projects/bind9!6685

3 years agoSilence negative array index warning with toupper
Mark Andrews [Fri, 19 Aug 2022 01:13:59 +0000 (11:13 +1000)] 
Silence negative array index warning with toupper

Cast to (unsigned char).

3 years agoMerge branch 'mnowak/freebsd-13.1' into 'main'
Michal Nowak [Thu, 18 Aug 2022 15:28:21 +0000 (15:28 +0000)] 
Merge branch 'mnowak/freebsd-13.1' into 'main'

Add FreeBSD 13.1

See merge request isc-projects/bind9!6656

3 years agoAdd FreeBSD 13.1
Michal Nowak [Fri, 12 Aug 2022 12:34:49 +0000 (14:34 +0200)] 
Add FreeBSD 13.1

3 years agoMerge branch 'artem-dig-http-plain-get-post-support-fix' into 'main'
Artem Boldariev [Thu, 18 Aug 2022 11:22:25 +0000 (11:22 +0000)] 
Merge branch 'artem-dig-http-plain-get-post-support-fix' into 'main'

DIG: fix handling of +http-plain-get and +http-plain-post options

See merge request isc-projects/bind9!6672

3 years agoModify CHANGES (+http-plain-{get, post} support fix in dig)
Artem Boldariev [Wed, 17 Aug 2022 10:34:52 +0000 (13:34 +0300)] 
Modify CHANGES (+http-plain-{get, post} support fix in dig)

This commit modifies the CHANGES file to mention that +http-plain-get
and +http-plain-post options support in dig was fixed.

3 years agoModify the doth system test to verify HTTP method usage
Artem Boldariev [Wed, 17 Aug 2022 14:36:50 +0000 (17:36 +0300)] 
Modify the doth system test to verify HTTP method usage

Before the commit some checks in the system test would try to verify
that different HTTP methods can be used and are functional. However,
until recently, it was not possible to tell from the output which
method was in fact used, so it turned out that +http-plain-get option
is broken.

This commit add the additional checks to prevent that from happening
in the future.

3 years agoDIG: mark HTTP GET method in output
Artem Boldariev [Wed, 17 Aug 2022 14:35:28 +0000 (17:35 +0300)] 
DIG: mark HTTP GET method in output

This commit makes dig mark the usage of HTTP(S) GET protocol usage in
its output.

3 years agoDIG: fix handling of +http-plain-{get, post} options
Artem Boldariev [Wed, 17 Aug 2022 10:19:32 +0000 (13:19 +0300)] 
DIG: fix handling of +http-plain-{get, post} options

Support for parsing +http-plain-get and +http-plain-post options was
broken. This commit fixes that.

3 years agoMerge tag 'v9_19_4'
Michal Nowak [Thu, 18 Aug 2022 09:29:56 +0000 (11:29 +0200)] 
Merge tag 'v9_19_4'

BIND 9.19.4

3 years agoMerge branch '3491-placeholder' into 'main'
Arаm Sаrgsyаn [Thu, 18 Aug 2022 09:12:34 +0000 (09:12 +0000)] 
Merge branch '3491-placeholder' into 'main'

Add placeholder for [GL #3491]

See merge request isc-projects/bind9!6679

3 years agoAdd placeholder for [GL #3491]
Aram Sargsyan [Thu, 18 Aug 2022 09:07:52 +0000 (09:07 +0000)] 
Add placeholder for [GL #3491]

3 years agoMerge branch '3494-dnssec-awk-test-is-not-precise-enough' into 'main'
Mark Andrews [Thu, 18 Aug 2022 03:41:17 +0000 (03:41 +0000)] 
Merge branch '3494-dnssec-awk-test-is-not-precise-enough' into 'main'

Resolve "DNSSEC awk test is not precise enough"

Closes #3494

See merge request isc-projects/bind9!6668

3 years agoImprove awk tests to prevent false negatives
Mark Andrews [Wed, 17 Aug 2022 02:08:16 +0000 (12:08 +1000)] 
Improve awk tests to prevent false negatives

The old code could incorrectly match "INSOA" in the RRSIG rdata
when looking for the SOA record.

3 years agoMerge branch 'mnowak/coverity-scan-2022.06' into 'main'
Michal Nowak [Wed, 17 Aug 2022 13:55:20 +0000 (13:55 +0000)] 
Merge branch 'mnowak/coverity-scan-2022.06' into 'main'

Use Coverity Scan 2022.06

See merge request isc-projects/bind9!6670

3 years agoUse Coverity Scan 2022.06
Michal Nowak [Wed, 17 Aug 2022 08:34:14 +0000 (10:34 +0200)] 
Use Coverity Scan 2022.06

3 years agoMerge branch 'mnowak/openbsd-7.1' into 'main'
Michal Nowak [Tue, 16 Aug 2022 15:01:20 +0000 (15:01 +0000)] 
Merge branch 'mnowak/openbsd-7.1' into 'main'

Add OpenBSD 7.1

See merge request isc-projects/bind9!6663

3 years agoAdd OpenBSD 7.1
Michal Nowak [Mon, 15 Aug 2022 14:33:32 +0000 (16:33 +0200)] 
Add OpenBSD 7.1

3 years agoMerge branch '3489-cid-355779-dynbuf-cannot-be-null' into 'main'
Arаm Sаrgsyаn [Tue, 16 Aug 2022 08:15:35 +0000 (08:15 +0000)] 
Merge branch '3489-cid-355779-dynbuf-cannot-be-null' into 'main'

Fix CID 355779: dynbuf cannot be NULL

Closes #3489

See merge request isc-projects/bind9!6652

3 years agoRefactor tkey.c:buildquery() error handling
Aram Sargsyan [Thu, 11 Aug 2022 18:27:11 +0000 (18:27 +0000)] 
Refactor tkey.c:buildquery() error handling

After an earlier code cleanup, `dns_rdatalist_tordataset()` always
succeeds, so the `RETERR` error handling macro below the function
call was removed. After that change the `dynbuf` variable can never
be `NULL` in the error handling code path under the `failure` label.

    *** CID 355779:  Null pointer dereferences  (REVERSE_INULL)
    /lib/dns/tkey.c: 997 in buildquery()
    991                 dns_message_puttempname(msg, &aname);
    992         }
    993         if (question != NULL) {
    994                 dns_rdataset_disassociate(question);
    995                 dns_message_puttemprdataset(msg, &question);
    996         }
    >>>     CID 355779:  Null pointer dereferences  (REVERSE_INULL)
    >>>     Null-checking "dynbuf" suggests that it may be null, but it has already been dereferenced on all paths leading to the check.
    997         if (dynbuf != NULL) {
    998                 isc_buffer_free(&dynbuf);
    999         }
    1000        return (result);
    1001     }
    1002

Refactor the `buildquery()` function to simplify its error handling.

3 years agoMerge branch '3492-fix-tkey.c-buildquery-cleanup' into 'main'
Arаm Sаrgsyаn [Tue, 16 Aug 2022 07:15:09 +0000 (07:15 +0000)] 
Merge branch '3492-fix-tkey.c-buildquery-cleanup' into 'main'

Fix tkey.c:buildquery() function's error handling

Closes #3492

See merge request isc-projects/bind9!6661

3 years agoAdd CHANGES note for [GL #3492]
Aram Sargsyan [Mon, 15 Aug 2022 11:40:38 +0000 (11:40 +0000)] 
Add CHANGES note for [GL #3492]

3 years agoFix tkey.c:buildquery() function's error handling
Aram Sargsyan [Mon, 15 Aug 2022 11:40:21 +0000 (11:40 +0000)] 
Fix tkey.c:buildquery() function's error handling

Add the missing cleanup code.

3 years agoMerge branch '3381-dnssec-policy-explicit-inline-signing' into 'main'
Matthijs Mekking [Mon, 15 Aug 2022 10:20:49 +0000 (10:20 +0000)] 
Merge branch '3381-dnssec-policy-explicit-inline-signing' into 'main'

dnssec-policy now requires inline-signing

Closes #3385

See merge request isc-projects/bind9!6403

3 years agoAdd change and release note for #3381
Matthijs Mekking [Tue, 7 Jun 2022 13:44:36 +0000 (15:44 +0200)] 
Add change and release note for #3381

Because folks want to know.

3 years agoRemove implicit inline-signing code
Matthijs Mekking [Tue, 7 Jun 2022 13:35:49 +0000 (15:35 +0200)] 
Remove implicit inline-signing code

Remove the code that sets implicit inline-signing on zones using
dnssec-policy.

3 years agoUpdate system tests
Matthijs Mekking [Tue, 7 Jun 2022 12:49:16 +0000 (14:49 +0200)] 
Update system tests

Update checkconf and kasp related system tests after requiring
inline-signing.

3 years agodnssec-policy now requires inline-signing
Matthijs Mekking [Tue, 7 Jun 2022 12:46:05 +0000 (14:46 +0200)] 
dnssec-policy now requires inline-signing

Having implicit inline-signing set for dnssec-policy when there is no
update policy is confusing, so lets make this explicit.

3 years agoMerge branch 'marka-placeholder' into 'main'
Mark Andrews [Mon, 15 Aug 2022 00:30:47 +0000 (00:30 +0000)] 
Merge branch 'marka-placeholder' into 'main'

Add placeholders for [GL #3487]

See merge request isc-projects/bind9!6659

3 years agoAdd placeholders for [GL #3487]
Mark Andrews [Mon, 15 Aug 2022 00:24:58 +0000 (10:24 +1000)] 
Add placeholders for [GL #3487]

3 years agoMerge branch '3488-prevent-adb-dump-race' into 'main'
Evan Hunt [Fri, 12 Aug 2022 22:20:01 +0000 (22:20 +0000)] 
Merge branch '3488-prevent-adb-dump-race' into 'main'

Lock the address entry bucket when dumping ADB namehook

Closes #3488, #3424, and #3425

See merge request isc-projects/bind9!6655

3 years agoLock the address entry bucket when dumping ADB namehook
Evan Hunt [Thu, 11 Aug 2022 22:06:34 +0000 (15:06 -0700)] 
Lock the address entry bucket when dumping ADB namehook

When dumping an ADB address entry associated with a name,
the name bucket lock was held, but the entry bucket lock was
not; this could cause data races when other threads were updating
address entry info. (These races are probably not operationally
harmful, but they triggered TSAN error reports.)

3 years agoMerge branch '3348-move-pkcs11-interface-test-to-debian' into 'main'
Michal Nowak [Thu, 11 Aug 2022 18:31:02 +0000 (18:31 +0000)] 
Merge branch '3348-move-pkcs11-interface-test-to-debian' into 'main'

Move OpenSSL-based PKCS#11 interface job to Debian "bullseye"

Closes #3348

See merge request isc-projects/bind9!6322

3 years agoMove OpenSSL-based PKCS#11 interface job to Debian "bullseye"
Michal Nowak [Tue, 17 May 2022 14:12:10 +0000 (16:12 +0200)] 
Move OpenSSL-based PKCS#11 interface job to Debian "bullseye"

Fedora 36 uses OpenSSL 3.0.2 by default, but the OpenSSL engine API
which we use for PKCS#11 is deprecated in OpenSSL 3.0.0. For the
keyfromlabel system test to work operating system with OpenSSL 1.1 needs
to be used.

3 years agoMerge branch '3458-reintroduce-without-cmocka-and-without-gssapi' into 'main'
Michal Nowak [Thu, 11 Aug 2022 15:56:50 +0000 (15:56 +0000)] 
Merge branch '3458-reintroduce-without-cmocka-and-without-gssapi' into 'main'

Configure Ubuntu 18.04 "bionic" without cmocka and GSS-API

Closes #3458

See merge request isc-projects/bind9!6631

3 years agoConfigure Ubuntu 18.04 "bionic" without cmocka and GSS-API
Michal Nowak [Wed, 3 Aug 2022 12:55:56 +0000 (14:55 +0200)] 
Configure Ubuntu 18.04 "bionic" without cmocka and GSS-API

--without-cmocka and --without-gssapi ./configure options have been lost
when Debian 9 "stretch" was dropped from the CI. This reintroduces them,
albeit to a slightly different platform.

3 years agoMerge branch 'mnowak/fix-mkeys-to-work-with-DEFAULT_ALGORITHM-properly' into 'main'
Michal Nowak [Wed, 10 Aug 2022 12:05:50 +0000 (12:05 +0000)] 
Merge branch 'mnowak/fix-mkeys-to-work-with-DEFAULT_ALGORITHM-properly' into 'main'

Fix mkeys to work with DEFAULT_ALGORITHM properly

See merge request isc-projects/bind9!6646

3 years agoFix mkeys to work with DEFAULT_ALGORITHM properly
Mark Andrews [Wed, 10 Aug 2022 07:20:30 +0000 (17:20 +1000)] 
Fix mkeys to work with DEFAULT_ALGORITHM properly

Stop using a RSASHA1 fixed key in ns3's named.conf as the
trusted key and instead compute a broken digest from the
real digest to use in trusted-keys.

3 years agoMerge branch '3483-memstat-assertion' into 'main'
Evan Hunt [Tue, 9 Aug 2022 18:20:11 +0000 (18:20 +0000)] 
Merge branch '3483-memstat-assertion' into 'main'

fix overflow error in mem_putstats()

Closes #3483

See merge request isc-projects/bind9!6641

3 years agofix overflow error in mem_putstats()
Evan Hunt [Mon, 8 Aug 2022 18:42:07 +0000 (11:42 -0700)] 
fix overflow error in mem_putstats()

an integer overflow could cause an assertion failure when
freeing memory.

3 years agoMerge branch 'mnowak/add-oracle-linux-9' into 'main'
Michal Nowak [Tue, 9 Aug 2022 14:43:29 +0000 (14:43 +0000)] 
Merge branch 'mnowak/add-oracle-linux-9' into 'main'

Add Oracle Linux 9

See merge request isc-projects/bind9!6581

3 years agokasp: stop using RSASHA1 unless necessary for the test
Mark Andrews [Wed, 22 Dec 2021 00:14:57 +0000 (11:14 +1100)] 
kasp: stop using RSASHA1 unless necessary for the test

Moves tests from being RSASHA1 based to RSASHA256 based where possible
and split out the remaining RSASHA1 based tests so that they are not
run on OS's that don't support RSASHA1.