Compare commits
1,084 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
1faffc32a8 | ||
|
|
65771b447c | ||
|
|
2e2533ed0c | ||
|
|
8c2399e162 | ||
|
|
a859b5175e | ||
|
|
711c5c46ba | ||
|
|
7e9f5e27cc | ||
|
|
238ad5761b | ||
|
|
a0805bd05d | ||
|
|
f792799c7d | ||
|
|
c72c35866e | ||
|
|
3a99b5a25e | ||
|
|
55c3f8e6d3 | ||
|
|
fbbe880e06 | ||
|
|
211a5b09a6 | ||
|
|
046122bd9e | ||
|
|
0049ee45a4 | ||
|
|
78e7e9e5ff | ||
|
|
94cc562d63 | ||
|
|
c42426f289 | ||
|
|
f4645b66ad | ||
|
|
5cc93baa3a | ||
|
|
dcf19cde8d | ||
|
|
a7c81a2e29 | ||
|
|
c84bc8187a | ||
|
|
3d0ec51117 | ||
|
|
448bd64587 | ||
|
|
8d6979fcf3 | ||
|
|
3c1d216595 | ||
|
|
743cc89bef | ||
|
|
7911863b89 | ||
|
|
a166e83cd0 | ||
|
|
c5a273aaa5 | ||
|
|
88cf659c1d | ||
|
|
4fc3a0f1fa | ||
|
|
7c5c8f76ad | ||
|
|
492a790266 | ||
|
|
a3ca8b5f92 | ||
|
|
3bda563fa3 | ||
|
|
cc844e18ef | ||
|
|
c92030d6aa | ||
|
|
fa6f9dbbd1 | ||
|
|
d822836321 | ||
|
|
159d742c21 | ||
|
|
463e7a3d2d | ||
|
|
aef7570bb8 | ||
|
|
9f78615eb4 | ||
|
|
d7ce29383b | ||
|
|
6853a348fc | ||
|
|
666db3a14e | ||
|
|
54750e5360 | ||
|
|
4a8dd5ccc3 | ||
|
|
6800e44134 | ||
|
|
8b224f4fa8 | ||
|
|
4d97d1689a | ||
|
|
3f3e0c1c58 | ||
|
|
a5e89554c9 | ||
|
|
4cc7c36636 | ||
|
|
a324aa90fd | ||
|
|
c5b2e69f0c | ||
|
|
3088af74e3 | ||
|
|
2e5ec7e2b8 | ||
|
|
ed27e3714c | ||
|
|
0b246d18df | ||
|
|
21cc8ba4e6 | ||
|
|
988c021cf3 | ||
|
|
ea2fc21f01 | ||
|
|
0f0106cb47 | ||
|
|
feddafc9cf | ||
|
|
8bc9ab3888 | ||
|
|
273ea431d5 | ||
|
|
0b6554ff3d | ||
|
|
f2aec3c2c1 | ||
|
|
c7c0f860f4 | ||
|
|
a28c475b98 | ||
|
|
201205375b | ||
|
|
c72c74cce0 | ||
|
|
071ec07d27 | ||
|
|
549048cb0e | ||
|
|
0cd50aebbd | ||
|
|
5b3a19a8c2 | ||
|
|
a553c9e873 | ||
| 7ec2fb38ca | |||
|
|
e4107d36ce | ||
|
|
a3b1b4c6a2 | ||
|
|
7d1027aabf | ||
|
|
ad87dca169 | ||
|
|
ca5d3f0131 | ||
|
|
0dcd8bfd6d | ||
|
|
87f39d667e | ||
|
|
a4f0681ebe | ||
|
|
047b52731f | ||
|
|
ed057b3ada | ||
|
|
f25b47caaa | ||
|
|
170a2ffa18 | ||
|
|
9ac8e058af | ||
|
|
891dc1c77c | ||
|
|
109d2c0507 | ||
|
|
b57d168db4 | ||
|
|
9149d53bb7 | ||
|
|
401d76d40d | ||
|
|
bdfa7b950b | ||
|
|
2616681202 | ||
|
|
8346c4c3cd | ||
|
|
41715d279a | ||
|
|
245d49eb17 | ||
| 741c22ffcd | |||
| 3a874644a6 | |||
|
|
283878c63d | ||
| 91d6033500 | |||
|
|
e79cdb27f2 | ||
|
|
fcaee16034 | ||
|
|
59820e13a5 | ||
|
|
5e93e0b078 | ||
|
|
9899e74f4d | ||
|
|
7a039e1831 | ||
|
|
db9d0ed8b6 | ||
|
|
00135d6b20 | ||
|
|
d03e0852a9 | ||
|
|
286970af6a | ||
|
|
782e6f0ca5 | ||
|
|
bd877cd86b | ||
|
|
fc196eb713 | ||
|
|
3deb8ee245 | ||
|
|
7ee174a831 | ||
|
|
9678d7855f | ||
|
|
15dc7fb16a | ||
|
|
03b1f0a4e4 | ||
|
|
13b1bcc0f0 | ||
|
|
e853970bcf | ||
|
|
10cb7fcdc5 | ||
|
|
9303298043 | ||
|
|
6db5408538 | ||
|
|
e1fa37e19c | ||
|
|
ced3b36a51 | ||
|
|
9b329d0dd6 | ||
|
|
5e42931b09 | ||
|
|
21fe71bc46 | ||
|
|
99fd53a106 | ||
|
|
e6424d1a09 | ||
|
|
dc511b8cc3 | ||
|
|
5b047433e1 | ||
|
|
bbdbcbc779 | ||
|
|
24465000af | ||
|
|
cb7d24f2e5 | ||
|
|
4562ffc7be | ||
|
|
99f74efbdc | ||
|
|
a912dbe98b | ||
|
|
9ef018d129 | ||
|
|
e4b16641a8 | ||
|
|
c0c776f659 | ||
|
|
bd4f2660ac | ||
|
|
b33592e3c6 | ||
|
|
66ddbbdf47 | ||
|
|
989a3e3876 | ||
|
|
411463dad7 | ||
|
|
55526b37a7 | ||
|
|
8a47aa2c75 | ||
|
|
d540d034df | ||
|
|
f887e16911 | ||
|
|
e3377c558b | ||
|
|
bb9452718a | ||
|
|
bb1dcf68da | ||
|
|
fdb091757f | ||
|
|
48bb18e175 | ||
|
|
0cc36e95a3 | ||
|
|
e52a502150 | ||
|
|
ee4347d7db | ||
|
|
36d2b49469 | ||
|
|
cc49e08ee9 | ||
|
|
24d1ecd259 | ||
|
|
b0bc4995fb | ||
|
|
74f70469b1 | ||
|
|
3f2a16fed6 | ||
|
|
5df92605e8 | ||
|
|
de4624f6e0 | ||
|
|
c81513c758 | ||
|
|
c0565f0da1 | ||
|
|
11207651f7 | ||
|
|
3bb763c2a7 | ||
|
|
e20853883a | ||
|
|
ed2f945c40 | ||
|
|
a8e525a210 | ||
|
|
ec7f7e4c12 | ||
|
|
13da6470e0 | ||
|
|
25b398b4e2 | ||
|
|
0ddb138d48 | ||
|
|
f8d4aed3a6 | ||
|
|
cbb68a1d09 |
||
|
|
5a12a8cddc | ||
|
|
6d858e2834 |
||
|
|
67a5f4ae99 | ||
|
|
59865beb68 | ||
|
|
50423aedd6 | ||
|
|
113ef2a069 | ||
|
|
32ee97f516 | ||
|
|
4cac5c90e0 | ||
|
|
50e206624d | ||
|
|
9d509c6973 | ||
|
|
739136846c | ||
|
|
77857154b5 | ||
|
|
dc4646b7fd | ||
|
|
a58a3a3f05 | ||
|
|
3bd7080e53 | ||
|
|
c02f91407f | ||
|
|
9f3c818250 | ||
|
|
b257933675 | ||
|
c9d581a577 |
|||
|
|
2cc6a869e5 | ||
|
|
43d9682d13 | ||
|
|
48d8c90e0d | ||
|
|
2c4a614d01 | ||
|
|
83399543c1 | ||
|
|
08ea20b0dd | ||
|
|
9c54517d6f | ||
|
|
f8cb93d57c | ||
|
|
2e4a03677c | ||
|
|
76074cd59a | ||
|
|
f182202f6e | ||
| 718b1f98f8 | |||
|
|
d4a07bb1cc | ||
|
|
55f06ea072 | ||
|
|
71c1a9ec1e | ||
|
|
9bba50dd4a | ||
|
|
a6938e85a7 | ||
|
|
8713f270d5 | ||
|
|
c37bc659fa | ||
|
|
84e2317aef | ||
|
|
21682d00a6 | ||
|
|
f3d54bbf18 | ||
|
|
9a979d2e9c | ||
|
|
ce6a7853ac | ||
|
|
7c5d77a6ce | ||
|
|
af42e59070 |
||
|
|
684e4b0d0a | ||
|
|
cc152b028f | ||
|
|
6648a9230f | ||
|
|
893376130b | ||
|
|
dbc722407e | ||
|
|
bea44d51ee | ||
|
|
d955a1450b | ||
|
|
177a98f40b | ||
|
|
5c10c94304 | ||
|
|
7c7ec8981c | ||
|
|
ddf24a90e3 | ||
|
|
118269cb8c | ||
|
|
46e0d484ee | ||
|
|
91193796e7 | ||
|
|
d553bc086f | ||
|
|
1f381a9469 | ||
|
|
ad33c6c095 | ||
|
|
aae89bb5ed | ||
|
|
b4711541c2 | ||
|
|
01c5de480b | ||
|
|
293d93455e |
||
|
|
fa2913151c | ||
|
|
392ac795ce | ||
|
|
1d47d2b5c9 | ||
|
|
c8e4226ec1 | ||
|
|
d4dab07e86 | ||
|
|
165b833b3d | ||
|
|
f37fbc8205 | ||
|
|
dac5cf7a4c | ||
|
|
9e7477b3c4 | ||
|
|
1f070d7ab3 | ||
|
|
7ffde7d755 | ||
|
|
fe1a072435 | ||
|
|
c2387c40c7 | ||
|
|
11da1628d8 | ||
|
|
aa13488713 | ||
|
|
4158647a7a | ||
|
|
aa8fce7381 | ||
|
|
bd20caa99a | ||
|
|
f290ef8ed6 | ||
|
|
8a73c57ad4 | ||
|
|
1799c36d23 | ||
|
|
e1be70d96e | ||
|
|
ef5c71f941 | ||
|
|
e761bce6ce | ||
|
|
89421c0410 | ||
|
|
1667a58d2a | ||
|
|
7be72b675e | ||
|
|
bd765f0cce | ||
|
|
823e9d22cf | ||
|
|
7d8ad626e7 | ||
|
|
04a7c5632c | ||
|
|
cb3f3691e4 | ||
|
|
745f43ac05 | ||
|
|
2dfc59bcef | ||
|
|
bd472bc593 | ||
|
|
2053b89207 | ||
|
|
23ca292909 | ||
|
|
146cab7989 | ||
|
|
b4eefd1f96 | ||
|
|
192c76c22a | ||
|
|
78aed13f06 |
||
|
|
9a4be75094 | ||
|
|
2a2d2faeae | ||
|
|
e8b35851c3 | ||
|
|
0963df6403 | ||
|
|
b8ccda0801 | ||
|
|
f82859a3a0 | ||
|
|
8aa5837978 | ||
|
|
674cbdbb3e | ||
|
|
f9201b844d | ||
|
|
23458b3db1 | ||
|
|
7fe31e1892 | ||
|
|
8ad1379019 | ||
|
|
775befed48 | ||
|
|
40861268f3 | ||
|
|
afbbd0be52 | ||
|
|
3ef9cd3dce | ||
|
|
8b8d05ffc0 | ||
|
|
aaa1cdaabf | ||
| b72488cc24 | |||
|
|
076f5f80bc | ||
|
|
1d9c1cf435 | ||
|
|
1b133224fc | ||
|
|
5e13eb8e75 | ||
|
|
96e1d963a4 | ||
|
|
6e3b160e37 | ||
|
|
485d16a77e | ||
|
|
449ff581ad | ||
|
|
ce9edd09af | ||
|
|
2e8a3a9146 | ||
|
|
93e0db889f | ||
|
|
f3b42f85fe | ||
|
|
304cfaa8e0 | ||
|
|
6b3788d026 | ||
|
|
ec5a01d972 | ||
|
|
74c92fb0da | ||
|
|
29036faad7 | ||
|
|
5c15ad824e | ||
|
|
c223e3e275 | ||
|
|
fcefdeb129 | ||
|
|
15cfc8b402 | ||
|
|
80d0367669 | ||
|
|
a6f9fe005e | ||
|
|
814547323e | ||
|
|
78968700e2 | ||
|
|
b626a2bfa5 | ||
|
|
05dbc88928 | ||
|
|
b4a5bc525b | ||
|
|
6a048cc0b6 | ||
|
|
a6454b966c | ||
|
|
cc967eb09e | ||
|
|
eeb7df78d9 | ||
|
|
e34707285d | ||
|
|
0990c9b32d | ||
|
|
2dbb099871 | ||
|
|
3c4d9d472a | ||
|
|
aaee84a4fb | ||
|
|
df81e828c7 | ||
|
|
0b18b1b517 | ||
|
|
7726ce77a6 | ||
|
|
a1d448dbef | ||
|
|
c23c15d73b | ||
|
|
4fa84d9ccc | ||
|
|
b4802c2e65 | ||
|
|
43f4de9bf3 | ||
|
|
23657868e6 | ||
|
|
9406a85e89 | ||
|
|
d5106d287e | ||
|
|
9cfd91a473 | ||
|
|
ccf1b03734 | ||
|
|
c44ebdeade | ||
|
|
1a4de8b956 | ||
|
|
6f27f8e4a7 | ||
|
|
adcfd20cb2 | ||
|
|
547656b469 | ||
|
|
74b53c3a58 | ||
|
|
4f643ffc70 | ||
|
|
b29a7e26db | ||
|
|
c45a218eef | ||
|
|
9bef003ee5 | ||
|
|
8f4225c8a7 | ||
|
|
8544584691 | ||
|
|
dff9083e8c | ||
|
|
be8074fddc | ||
|
|
cba49a643a | ||
|
|
63bb1cf127 | ||
|
|
ed8f6043d7 | ||
|
|
86712fc834 | ||
|
|
2129c87815 | ||
|
|
176d144f32 | ||
|
|
d0053ae530 | ||
|
|
833ef7b7b4 | ||
|
|
69b861316f | ||
|
|
277938ec6c | ||
|
|
339db1a482 | ||
|
|
7eb2cf5e7b | ||
|
|
54fa84a387 | ||
|
|
545e2cb4bc | ||
|
|
0983c90fb0 | ||
|
|
5aee3f1742 | ||
|
|
5691e04b76 | ||
|
|
841d8832b4 | ||
|
|
d568c54c25 | ||
|
|
9d1aaa502b | ||
|
|
bf5bc99f81 | ||
|
|
0fa39c28ad | ||
|
|
8cd5c11f0d | ||
|
|
c5d9a5c66a | ||
|
|
01dd585828 | ||
|
|
1b89e61546 | ||
|
|
843e5f5094 | ||
|
|
72f1dad845 | ||
|
|
c92fe260ae | ||
|
|
b75571c4df | ||
|
|
23eefd9798 | ||
|
|
963c4b916b | ||
|
|
dab22dd2c2 | ||
|
|
fac5ed036c | ||
|
|
b4e74efbf2 | ||
|
|
448b6647dc | ||
|
|
371a1e3b7d | ||
|
|
afa1fa2af7 | ||
|
|
1050b1aed6 | ||
|
|
3a67af20ad | ||
|
|
16ecf0736f | ||
|
|
564c143a1b | ||
|
|
ecef966359 | ||
|
|
2a466330c5 | ||
|
|
625ca235be | ||
|
|
e97d036624 | ||
|
|
926c8e07af | ||
|
|
4b42a5c162 | ||
|
|
7232bc0a99 | ||
|
|
e2a32c8eca | ||
|
|
ae423dfbeb | ||
|
|
16bdca79ba | ||
|
|
812f6fb336 | ||
|
|
395fbedb17 | ||
|
|
bcfdb893b9 | ||
|
|
7bc8b1b992 | ||
|
|
1e4169114f | ||
|
|
2aa49f0cec | ||
|
|
25e332108e | ||
|
|
d0d728803b | ||
|
|
8da0172aac | ||
|
|
321554b987 | ||
|
|
d3fe8d6248 | ||
|
|
ec6f94669a | ||
|
|
f0b6f15ced | ||
|
|
bd6e8b8965 | ||
|
|
ad76423202 | ||
|
|
c2772a07e8 | ||
|
|
fa1631eef7 | ||
|
|
6fee3d63e9 | ||
|
|
6ecd16d458 | ||
|
|
1da60a891a | ||
|
|
de8fa0799a | ||
|
|
7a958a2a9f | ||
|
|
a699858667 | ||
|
|
432a81aeff | ||
|
|
9a4b768e18 | ||
| b2a708808a | |||
|
|
13f8f23ec5 | ||
|
|
32d91f12ca | ||
|
|
219b0e889f | ||
|
|
2830e00b88 | ||
|
|
685f10cbfd | ||
|
|
67a5cd83ff | ||
|
|
a1558710fb | ||
|
|
ae36af4c9f | ||
|
|
eba5779fc1 | ||
|
|
ad7b3b8f12 | ||
|
|
c64b079c36 | ||
|
|
cda9d12b65 | ||
|
5efb1da1ac |
|||
|
|
e665b7deb0 | ||
|
|
135784d7f2 | ||
|
|
e0ab89b893 | ||
|
|
fdbf64ca93 | ||
|
|
0b3ef49c00 | ||
|
|
8c65390bb6 | ||
|
|
2ac37f7a75 | ||
|
|
aeea22afaa | ||
|
|
cc69cd1e32 | ||
|
|
328fbf43a1 | ||
|
|
595af1f3d5 | ||
|
|
6e9104cae5 | ||
|
|
0ae69e04e1 | ||
|
|
37943d075e | ||
|
|
95d8248d50 | ||
|
|
e1f8ad2217 | ||
|
|
35334375ff | ||
|
|
899014a8d1 | ||
|
|
aefd72cf8f | ||
|
|
20ccb888af | ||
|
|
3fdc82d222 | ||
|
|
a38c250807 | ||
|
|
89e5350e43 | ||
|
|
572c587d29 | ||
|
|
41d69089c7 | ||
|
|
5c1f40d412 | ||
|
|
626855668d | ||
|
|
80b88039e8 | ||
|
|
3159fb6a8e | ||
|
|
ac50574b43 | ||
|
|
600bfd47ef | ||
|
|
72c97d6c12 | ||
|
|
69a52c5216 | ||
|
|
e3d0b186d1 | ||
|
|
5c4c792b8d | ||
|
|
0188ce47c6 | ||
|
|
de74eb1feb | ||
|
|
f3f402d7f2 | ||
|
|
b8176e5eb4 | ||
|
|
f17cd8fc68 | ||
|
|
36ff6aebe6 | ||
|
|
cc9419191f | ||
|
|
8c4729c436 | ||
|
|
f505a47d9b | ||
|
|
86ff90b834 | ||
|
|
029f0510e6 | ||
|
|
98bc345e0b | ||
|
|
40e8ab1f0c | ||
|
|
9d24906d8d | ||
|
|
5fe0b21885 | ||
|
|
56e7b0f856 | ||
|
|
cb2172301b | ||
|
|
128dd7c787 | ||
|
|
3931fea548 | ||
|
|
9a235f827e | ||
|
|
6787c0592a | ||
|
|
46c6c4cd84 | ||
|
|
4f517bd499 | ||
|
|
21ad2a883e | ||
|
|
bd8ef642c3 | ||
|
|
7d67be0060 | ||
|
|
1d54148484 | ||
|
|
f75d562486 | ||
|
|
539c207dc9 | ||
|
|
687255db6e | ||
|
|
c117ea001f | ||
|
|
76e1f1a098 | ||
|
|
cdabc47c40 | ||
|
|
27e37d675a | ||
|
|
028f8c2ce4 | ||
|
|
a10892eed8 | ||
|
|
3582b7047d | ||
|
|
358a6cb08d | ||
|
|
da51426156 | ||
|
|
7556fb076a | ||
|
|
db0b09231c | ||
|
|
9647ab2c58 | ||
|
|
661d72987e | ||
|
|
dd79d39eee | ||
|
|
e5f6b89e92 | ||
|
|
50d9fbf691 | ||
|
|
7536ed9d37 | ||
|
|
dbe3315c06 | ||
|
|
bdc5ebdfa5 | ||
|
|
f5cbbc1a87 | ||
|
|
4d8c709975 | ||
|
|
4645641491 | ||
|
|
2dc24d7a28 | ||
|
|
1f8ab5c253 | ||
|
|
0b15f32821 | ||
|
|
5d8eb8cf1d | ||
|
|
e9f0f4543b | ||
|
|
7584e54e6c | ||
|
|
79d28ed32a | ||
|
|
c81a9f4bd4 | ||
|
|
268c28154e | ||
|
|
84de79cc62 | ||
|
|
6bf59b0f11 | ||
|
|
508d643480 | ||
|
|
43f0ac7c91 | ||
|
|
f2fb8b7545 | ||
|
|
e42c700db9 | ||
|
|
85d0fb613e | ||
|
|
b0ccd9af19 | ||
| 3c983e38ec | |||
|
|
102df25a21 | ||
|
|
08bdf0ebe6 | ||
|
|
19b1efe0bb | ||
|
|
09e4b5788e | ||
|
|
bbe4229562 | ||
|
|
29088fe6b4 | ||
|
|
7e15fd4b3f | ||
|
|
3d5ea105bd | ||
|
|
fdce4eb560 | ||
|
|
f696d69809 | ||
|
|
9775c204db | ||
|
|
a925732bd1 | ||
|
|
8afcc7945f | ||
|
|
d886cd072d | ||
|
|
59793ad00a | ||
|
|
20cebfb8c5 | ||
|
|
e94c66494e | ||
|
|
27a8e54aa7 | ||
|
|
02e0755d17 | ||
|
|
3fed71e579 | ||
|
|
aeb3d0fc5d | ||
|
|
d591319212 | ||
|
|
379b90d05d | ||
|
|
03a1eba10d | ||
|
|
8ac7bef51e | ||
|
|
83466f11b9 | ||
|
|
d273b747cd | ||
|
|
4f7493080f | ||
|
|
bbb4f1d9a7 | ||
|
|
1a8262dde0 | ||
|
|
c009763d23 | ||
| c94cea9133 | |||
|
|
226577f014 | ||
|
|
703982aa78 | ||
| b4715c5089 | |||
|
|
c76f58f6ea | ||
|
|
caf3603af7 | ||
|
|
a3771cee48 | ||
|
|
d6c0550f5c | ||
|
|
1d29922e18 | ||
|
|
566e7ed5b9 | ||
|
|
5196f25446 | ||
|
|
0a65866650 | ||
|
|
e09c558cc5 | ||
|
|
71f9fb4731 | ||
|
|
c501776f39 | ||
|
|
ca42323df8 | ||
|
|
c1e4a2fd32 | ||
|
|
be760938ec | ||
|
|
548cd90fb3 | ||
|
|
7345adf157 | ||
|
|
f011164832 | ||
|
|
a62625f0bd | ||
|
|
f3967f6469 | ||
|
|
d0351fe60b | ||
|
|
a1f249d671 | ||
|
|
4e2098e221 | ||
|
|
407c2d38c0 | ||
|
|
02be4819ea | ||
|
|
4fa9972d29 | ||
|
|
e001c1a066 | ||
|
|
460bee9b36 | ||
|
|
c906894bd5 | ||
|
|
075927bb1c | ||
|
|
b6d2bfe08a | ||
|
|
83a76bb0d8 | ||
|
|
dce2d1bd1c | ||
|
|
23b1421845 | ||
|
|
1407f656a4 | ||
|
|
b746061914 | ||
| c095b972f6 | |||
|
|
0cc3dc9157 | ||
|
|
55b0a6bfc2 | ||
| 68221b27b3 | |||
| 7f37d19d5d | |||
|
|
4e390f5349 | ||
|
|
4b0aa8b659 | ||
|
|
7809ef4347 | ||
|
|
ed837c4f03 | ||
|
|
d18b5e4f2e | ||
|
|
4ecbfd89d6 | ||
|
|
9f33a20115 | ||
|
|
230113feee | ||
|
|
7ebf9a3e72 | ||
|
|
e983ad30af | ||
|
|
9d09f43a80 | ||
|
|
fb62390fbb | ||
|
|
01ddf2c8af | ||
|
|
14a63be5be | ||
|
|
1a8c6bc42b | ||
|
|
abe4be5502 | ||
|
|
cfca698d2b | ||
|
|
7eb562bbab | ||
|
|
0cd5a0ff48 | ||
|
|
3267c0ac54 | ||
|
|
cb97bbcb9f | ||
|
|
ab389647c8 | ||
|
|
f9f4e84366 | ||
|
|
426c09470b | ||
|
|
8beb2b82a5 | ||
|
|
93a69bb161 | ||
|
|
09394b223a | ||
|
|
c159c78652 | ||
|
|
48fc9b39c5 | ||
|
|
a556cfb3e4 | ||
|
|
3ddaff2ea9 | ||
|
|
3840facbe4 | ||
|
|
3d99690d74 | ||
|
|
55d3302131 | ||
|
|
4a918b84b0 | ||
|
|
d010f7191d | ||
|
|
a249bc6298 | ||
|
|
5caf68e0f8 | ||
|
|
5154ca3352 | ||
|
|
ba646ed5d4 | ||
|
|
65cc9d95ad | ||
|
|
f4daa58a90 | ||
|
|
d60cf6630d | ||
|
|
37d1c73624 | ||
|
|
bd600e49c8 | ||
|
|
0c054b2ac8 | ||
|
|
76b23b8702 | ||
|
|
df0cae9e8b | ||
|
|
1bf060007d | ||
|
|
2cc782fdff | ||
|
|
0a46a99c61 | ||
|
|
60039a5407 | ||
|
|
ad6dbbdee6 | ||
|
|
d0fda06135 | ||
|
|
4242e4f1c1 | ||
|
|
7731d63afb | ||
|
|
4ebe3dc7ef | ||
|
|
c9b9417fb2 | ||
|
|
31f953d106 | ||
|
|
2043f0c3c9 | ||
|
|
c69f33f779 | ||
|
|
2d741bb523 | ||
|
|
05cf2799f8 | ||
|
|
a54c4dc454 | ||
|
|
619831eeff | ||
|
|
151d963a40 | ||
|
|
0f7d49832f | ||
|
|
e73262808d | ||
|
|
cd3db89ffb | ||
|
|
15281fbc42 | ||
|
|
7d40dc1da5 | ||
|
|
d6323c1def | ||
|
|
2aeaf22a1a | ||
|
|
51e3f36892 | ||
|
|
7519c842dd | ||
|
|
d9b90b5d92 | ||
|
|
fd468c0f80 | ||
|
|
a013398319 | ||
|
|
f992a0bef3 | ||
|
|
c45bcb50cd | ||
|
|
2421460d24 | ||
|
|
99402419a5 | ||
|
|
06bfaa4fef | ||
|
|
c8bd0f2bc2 | ||
|
|
44476833c8 | ||
|
|
cf5dc7323a | ||
|
|
475645f00d | ||
|
|
341c7de50d | ||
|
|
773ac2b8b3 | ||
|
|
0e5b5af688 | ||
|
|
8d53d34994 | ||
|
|
bcb8c5a5f6 | ||
|
|
e845d82d1a | ||
|
|
6cd938d8ce | ||
|
|
dabddcf2c7 | ||
|
|
deca2d7733 | ||
|
|
4004a29b6c | ||
|
|
124c3fc2f1 | ||
|
|
d218af54a5 | ||
|
|
c7d6bc15c0 | ||
|
|
a58359fc07 | ||
|
|
1860966522 | ||
|
|
8e38086c4b | ||
|
|
6161cf7d2c | ||
|
|
45e102c98a | ||
|
|
928d804219 | ||
|
|
961e87b7c9 | ||
|
|
61b073aa6a | ||
|
|
2d24bcf904 | ||
|
|
70e2a7d863 | ||
|
|
771823363d | ||
|
|
4cd36470f8 | ||
|
|
4c513b0e09 | ||
|
|
2bd2458b3c | ||
|
|
86c080f6b6 | ||
|
|
6322cef147 | ||
|
|
3eb67c23c1 | ||
|
|
796ae3f199 | ||
|
|
95c9b3fdb6 | ||
|
|
36ea44a658 | ||
|
|
136022b9f3 | ||
|
|
a3e9bb8bda | ||
|
|
6fff3b39f0 | ||
|
|
8bf97dc309 | ||
|
|
100a9cfcec | ||
|
|
3e86a6bcba | ||
|
|
333f89f44e | ||
|
|
5bc2b4b996 | ||
|
|
9dbbf53ecc | ||
|
|
b783612511 | ||
|
|
2ccdf60e3a | ||
|
|
bbaece96c1 | ||
|
|
ebeac1bec4 | ||
|
|
559263dd25 | ||
|
|
d4ce1d893b | ||
|
|
bd297885de | ||
|
|
f214e0843b | ||
|
|
a0a60a6bd5 | ||
|
|
3afaba74d9 | ||
|
|
79e5ad687f | ||
|
|
516bc441f8 | ||
|
|
7a16468dc5 | ||
|
|
9b81ef32b1 | ||
|
|
5856f09a63 | ||
|
|
531ba12e2a | ||
|
|
5751312c59 | ||
|
|
9e44db5563 | ||
|
|
85ba863cb7 | ||
|
|
be7323a92d | ||
|
|
aa9e285744 | ||
|
|
62ad4d6446 | ||
|
|
fcc67a64f4 | ||
|
|
f9d514a29a | ||
|
|
0ebd48a0e0 | ||
|
|
056a92a871 | ||
|
|
6f55351f41 | ||
|
|
de6201fdf2 | ||
|
|
24bc8d6871 | ||
|
|
6b27902f03 | ||
|
|
5a5b2a1167 | ||
|
|
fd85eb9167 | ||
|
|
83dd31c546 | ||
|
|
b360005238 | ||
|
|
bc36826f0d | ||
|
|
8785971f78 | ||
|
|
df05e7d42d | ||
|
|
23ee02aeb0 | ||
|
|
dde47d54f6 | ||
|
|
5e22ace443 | ||
|
|
bb31346709 | ||
|
|
311ac6e9ab | ||
|
|
1f627ba683 | ||
|
|
e51639a1cf | ||
|
|
34adbeb306 | ||
|
|
7f138a6ba9 | ||
|
|
13e55cd35c | ||
|
|
b51a1f40e4 | ||
|
|
853a1f339e | ||
|
|
af6de1e113 | ||
|
|
19b1286fca | ||
|
|
b5bdffedac | ||
|
|
98e20566a4 | ||
|
|
830064b15d | ||
|
|
2fc1c6e8a5 | ||
|
|
98a514b98b | ||
|
|
b70aaadb53 | ||
|
|
e99cc3499f | ||
|
|
2af3ea715d | ||
|
|
f12e46d9ad | ||
|
|
dd9171cb2c | ||
| f8c1ad6758 | |||
|
|
fc549c69fc | ||
|
|
73232ec521 | ||
|
|
489141e153 | ||
|
|
3200281b05 | ||
|
|
7323239b74 | ||
|
|
583a06b173 | ||
|
|
91895cfac2 | ||
|
|
7ffd8214d5 | ||
|
|
c0e31848c2 | ||
|
|
146866cd45 | ||
|
|
ec60046d32 | ||
|
|
3475d4ccbe | ||
|
|
01aab7c4c3 | ||
|
|
32aa839776 | ||
|
|
35358171ac | ||
|
|
f949b56cdb | ||
|
|
913b3afd3d | ||
|
|
fc276131b5 | ||
|
|
8f3a7935d8 | ||
|
|
9b3f9635ea | ||
|
|
ce30f77919 | ||
|
|
d51b2c46ab | ||
|
|
205f42ddd6 | ||
| f483b8bf94 | |||
|
|
10e206f918 | ||
|
|
81608e7aa8 | ||
|
|
36c19fae23 | ||
|
|
8ff18349e6 | ||
|
|
b1c08c198e | ||
|
|
6ea5073522 | ||
|
|
fb507bf78c | ||
|
|
0ff4566640 | ||
|
|
f8a48cba51 | ||
|
|
98dc3420a0 | ||
|
|
f18d558f4f | ||
|
|
443731aa66 | ||
|
|
c768d86633 | ||
|
|
eebed2aabe | ||
|
|
e5a309e7ae | ||
|
|
5691aedf5b | ||
|
|
b2c2f375e2 | ||
|
|
cc7f3e831a | ||
|
|
1a7b0845f3 | ||
|
|
c5eef512c0 | ||
|
|
9e9db25803 | ||
|
|
a99cd96ce0 | ||
|
|
77020b9c5b | ||
|
|
6eed956cdf | ||
|
|
10534b2bf6 | ||
|
|
6ca2c1eec0 | ||
|
|
1e57f4955e | ||
|
|
73e3d597bb | ||
|
|
3471a1770a | ||
|
|
02d976683f | ||
|
|
31ee0f193c | ||
|
|
99fc20a35a | ||
|
|
20b9c8fe2a | ||
|
|
40b00446b3 | ||
|
|
484a9481dd | ||
|
|
c0263f95bd | ||
|
|
15ab9ca5f0 | ||
|
|
582a8191b4 | ||
|
|
e384734d67 | ||
|
|
23e79e02a4 | ||
|
|
6109c48d8a | ||
|
|
038864092f | ||
|
|
b246b77488 | ||
|
|
e00252b251 | ||
|
|
bd6af4d1fd | ||
|
|
19191709fc | ||
|
|
44f4a7a882 | ||
|
|
76073e2e5c | ||
|
|
95fd5e6c3e | ||
|
|
dcb87f0cf7 | ||
|
|
cb92bf7b74 | ||
|
|
7e92996f88 | ||
|
|
bdd5a0f2be | ||
|
|
aa8fd38bcf | ||
|
|
2eb6fc2cfe | ||
|
|
300cfcff2d | ||
|
|
b2b15fb648 | ||
|
|
5ca594a9cb | ||
|
|
bbeea42ab3 | ||
|
|
e31eda425b | ||
|
|
17ffe02220 | ||
|
|
62d611d7df | ||
|
|
bd244743f6 | ||
|
|
7bcaa52bb5 | ||
|
|
dd1c37e33f | ||
|
|
ed104584a8 | ||
|
|
b4f38cb187 | ||
|
|
512cdbdd86 | ||
|
|
72f5cc831d | ||
|
|
7c05423481 | ||
|
|
56125acf78 | ||
|
|
6bd75c5bd0 | ||
|
|
03c9c5d990 | ||
|
|
bb5d895564 | ||
|
|
27efb4347e | ||
|
|
565c3b28dc | ||
|
|
072956c6a2 | ||
|
|
31f7ce1b8b | ||
|
|
15c5cd7a8d | ||
|
|
62ace91e56 | ||
|
|
d5a069e563 | ||
|
|
2add4cbf1d | ||
|
|
8af0fe42da | ||
|
|
eff12eee3b | ||
|
|
3f1f99fa88 | ||
|
|
bbe5776b48 | ||
|
|
edea69c54e | ||
|
|
86e08aa78a | ||
|
|
007ac2d240 | ||
|
|
fa28231ea6 | ||
|
|
19fe83500b | ||
|
|
89803af2ce | ||
|
|
76b6450081 | ||
|
|
1c28622407 | ||
|
|
10a7d95225 | ||
|
|
f7ddf08324 | ||
|
|
77c85ac7ae | ||
|
|
c2ec1465ff | ||
|
|
de5c2d0120 | ||
|
|
fb5bf17ee8 | ||
|
|
0a58672414 | ||
|
|
0827e93fa6 | ||
|
|
b598411a0b | ||
|
|
902cff93ad | ||
|
|
fe4c11e287 | ||
|
|
2d6bd822c3 | ||
|
|
3416d0c170 | ||
|
|
62e2c7cd2c | ||
|
|
788dabf8dc | ||
|
|
a0180575d3 | ||
|
|
e93ead5573 | ||
|
|
a7cf97ec50 | ||
|
|
2be0bc65f4 | ||
|
|
969b1cbd8f | ||
|
|
f3718dfd1b | ||
|
|
9c2a844c6c | ||
|
|
c90d3f2232 | ||
|
|
e5705701dd | ||
|
|
066ea905d2 | ||
|
|
55b04de09a | ||
|
|
e51da3145d | ||
|
|
7fdb7fd693 | ||
|
|
9091db68d8 | ||
|
|
35f077d2e8 | ||
|
|
b82deb2ea7 | ||
|
|
af78c8d4b9 | ||
|
|
96fffb4804 | ||
|
|
45783cc5d4 | ||
|
|
1820066703 | ||
|
|
bd3ab6edda | ||
|
|
906dcded8c | ||
|
|
427dfbf651 | ||
|
|
83c4dc9822 | ||
|
|
6539046350 | ||
|
|
03f646e50f | ||
|
|
205d5ef896 | ||
|
|
0c76cb3934 | ||
|
|
24bf8edbd3 | ||
|
|
3ae660a68b | ||
|
|
35de41098b | ||
|
|
ec2f58a89c | ||
|
|
60fd3200ff | ||
|
|
c30533e317 | ||
|
|
03a58f5559 | ||
|
|
26292ab68c | ||
|
|
5ea70d6f4e | ||
|
|
7d1ee6c49c | ||
|
|
168cdeae16 | ||
|
|
f47d1818a7 | ||
|
|
1dab710357 | ||
|
|
f591b15708 | ||
|
|
b4717003a2 | ||
|
|
fb3a212e60 | ||
|
|
ef31ff85e9 | ||
|
|
5f04d34518 | ||
|
|
4e2ae06f1e | ||
|
|
497e1ae94e | ||
|
|
9e01d43e0e | ||
| 0200abfd54 | |||
| 286aa4d78c | |||
| 4f2e75b9bf | |||
| 729663244a | |||
| a05b51b9cd | |||
| 6139f9a32d | |||
| a510529323 | |||
| 2dcae4b105 | |||
| 3a49122da1 | |||
| d28e3c8a26 | |||
| 5c5cdca146 | |||
| 6766d81e82 | |||
| 90c9551d84 | |||
| 25c0200383 | |||
| 511f41b9e2 | |||
| 28242bb7c3 | |||
| 2e4a40499d | |||
| ddfd063bc3 | |||
| 724524768d | |||
| 2e702b326b | |||
| 66f11969cf | |||
| 5cb2d02ad3 | |||
| 05d01834a7 | |||
| 7f63ac6696 | |||
| a3155ae89b | |||
| 6201335188 | |||
| f5f9da1366 | |||
| 8a3138495d | |||
| 73dd15ee07 | |||
| 659e0f2321 | |||
| 79e214db26 | |||
| e08ea85cbe | |||
| 4583f16198 | |||
| 664403ec13 | |||
| 5246fdfd70 | |||
| 29d1d1d59f | |||
|
|
344c0744cd | ||
|
|
83e50b77dd | ||
|
|
49eb4b9677 | ||
|
|
6fcc997885 | ||
|
|
e76b450f1c | ||
|
|
bc0ace676a | ||
| 7129176f33 | |||
|
|
35a33a01be | ||
|
|
a57653b033 | ||
|
|
fc31cdddc1 | ||
|
|
10f5fb7f70 | ||
|
|
70dd0b41df | ||
|
|
278c8c423e | ||
|
|
23d86e2d25 | ||
|
|
44c905044b | ||
|
|
d74c490fb8 | ||
|
|
80c7ce2179 | ||
|
|
aefe828e5b | ||
|
|
313b9086cb | ||
|
|
38b9404262 | ||
|
|
64b22d012f | ||
|
|
da62e9e05a | ||
|
|
4c7385a92d | ||
|
|
053216a5df | ||
|
|
781dfac42c |
107 changed files with 15482 additions and 5931 deletions
12
.cvsignore
12
.cvsignore
|
|
@ -1,12 +0,0 @@
|
|||
bind-9.2.3rc3-deprecation_msg_shut_up.diff.bz2
|
||||
bind-9.2.4rc7.tar.gz
|
||||
bind-chroot.tar.gz
|
||||
bind-manpages-2.tar.bz2
|
||||
bind-manpages.patch.bz2
|
||||
bind-9.2.4rc8.tar.gz
|
||||
bind-9.3.0.tar.gz
|
||||
bind-9.3.1rc1.tar.gz
|
||||
libbind-man.tar.gz
|
||||
bind-9.3.1.tar.gz
|
||||
bind-9.3.2rc1.tar.gz
|
||||
bind-9.3.2.tar.gz
|
||||
1
.fmf/version
Normal file
1
.fmf/version
Normal file
|
|
@ -0,0 +1 @@
|
|||
1
|
||||
240
.gitignore
vendored
Normal file
240
.gitignore
vendored
Normal file
|
|
@ -0,0 +1,240 @@
|
|||
bind-9.7.1-P2.tar.gz
|
||||
config-8.tar.bz2
|
||||
bind-9.7.2b1.tar.gz
|
||||
/config-8.tar.bz2
|
||||
/bind-9.7.2rc1.tar.gz
|
||||
/bind-9.7.2.tar.gz
|
||||
/bind-9.7.2-P2.tar.gz
|
||||
/bind-9.7.2-P3.tar.gz
|
||||
/bind-9.7.3b1.tar.gz
|
||||
/bind-9.7.3rc1.tar.gz
|
||||
/bind-9.7.3.tar.gz
|
||||
/bind-9.8.0rc1.tar.gz
|
||||
/bind-9.8.0.tar.gz
|
||||
/bind-9.8.0-P1.tar.gz
|
||||
/bind-9.8.0-P2.tar.gz
|
||||
/bind-9.8.0-P4.tar.gz
|
||||
/bind-9.8.1rc1.tar.gz
|
||||
/bind-9.8.1.tar.gz
|
||||
/bind-9.9.0b1.tar.gz
|
||||
/bind-9.9.0b2.tar.gz
|
||||
/bind-9.9.0rc1.tar.gz
|
||||
/bind-9.9.0rc2.tar.gz
|
||||
/bind-9.9.0.tar.gz
|
||||
/bind-9.9.1.tar.gz
|
||||
/bind-9.9.1-P1.tar.gz
|
||||
/bind-9.9.1-P2.tar.gz
|
||||
/bind-9.9.1-P3.tar.gz
|
||||
/bind-9.9.2.tar.gz
|
||||
/bind-9.9.2-P1.tar.gz
|
||||
/config-9.tar.bz2
|
||||
/config-10.tar.bz2
|
||||
/bind-9.9.2-P2.tar.gz
|
||||
/bind-9.9.3rc1.tar.gz
|
||||
/config-11.tar.bz2
|
||||
/bind-9.9.3rc2.tar.gz
|
||||
/bind-9.9.3.tar.gz
|
||||
/bind-9.9.3-P1.tar.gz
|
||||
/bind-9.9.4b1.tar.gz
|
||||
/bind-9.9.4rc1.tar.gz
|
||||
/bind-9.9.4rc2.tar.gz
|
||||
/bind-9.9.4.tar.gz
|
||||
/config-12.tar.bz2
|
||||
/bind-9.9.5b1.tar.gz
|
||||
/bind-9.9.5rc2.tar.gz
|
||||
/bind-9.9.5.tar.gz
|
||||
/bind-9.9.5-P1.tar.gz
|
||||
/bind-9.9.6.tar.gz
|
||||
/bind-9.9.6-P1.tar.gz
|
||||
/bind-9.10.1b2.tar.gz
|
||||
/bind-9.10.1.tar.gz
|
||||
/bind-9.10.1-P1.tar.gz
|
||||
/bind-9.10.2rc1.tar.gz
|
||||
/bind-9.10.2rc2.tar.gz
|
||||
/bind-9.10.2.tar.gz
|
||||
/config-13.tar.bz2
|
||||
/config-14.tar.bz2
|
||||
/bind-9.10.2-P1.tar.gz
|
||||
/bind-9.10.2-P2.tar.gz
|
||||
/bind-9.10.2-P3.tar.gz
|
||||
/bind-9.10.3rc1.tar.gz
|
||||
/bind-9.10.3.tar.gz
|
||||
/bind-9.10.3-P2.tar.gz
|
||||
/config-15.tar.bz2
|
||||
/bind-9.10.3-P3.tar.gz
|
||||
/bind-9.10.3-P4.tar.gz
|
||||
/bind-9.10.4-P1.tar.gz
|
||||
/bind-9.10.4-P2.tar.gz
|
||||
/bind-9.10.4-P3.tar.gz
|
||||
/bind-9.10.4-P4.tar.gz
|
||||
/bind-9.11.0-P1.tar.gz
|
||||
/bind-9.11.0-P2.tar.gz
|
||||
/bind-9.11.0-P3.tar.gz
|
||||
/bind-9.11.0-P5.tar.gz
|
||||
/config-16.tar.bz2
|
||||
/bind-9.11.1-P1.tar.gz
|
||||
/bind-9.11.1-P2.tar.gz
|
||||
/bind-9.11.1-P3.tar.gz
|
||||
/bind-9.11.2b1.tar.gz
|
||||
/bind-9.11.2.tar.gz
|
||||
/config-17.tar.bz2
|
||||
/bind-9.11.2-P1.tar.gz
|
||||
/bind-9.11.3b1.tar.gz
|
||||
/bind-9.11.3.tar.gz
|
||||
/config-18.tar.bz2
|
||||
/bind-9.11.4rc1.tar.gz
|
||||
/bind-9.11.4.tar.gz
|
||||
/bind-9.11.4-P1.tar.gz
|
||||
/bind-9.11.4-P2.tar.gz
|
||||
/bind-9.11.5.tar.gz
|
||||
/bind-9.11.5-P1.tar.gz
|
||||
/config-19.tar.bz2
|
||||
/bind-9.11.5-P4.tar.gz
|
||||
/bind-9.11.6.tar.gz
|
||||
/bind-9.11.6-P1.tar.gz
|
||||
/bind-9.11.7.tar.gz
|
||||
/bind-9.11.8.tar.gz
|
||||
/bind-9.11.9.tar.gz
|
||||
/bind-9.11.10.tar.gz
|
||||
/bind-9.11.11.tar.gz
|
||||
/bind-9.11.12.tar.gz
|
||||
/bind-9.11.13.tar.gz
|
||||
/bind-9.11.13.tar.gz.asc
|
||||
/bind-9.11.14.tar.gz
|
||||
/bind-9.11.14.tar.gz.asc
|
||||
/bind-9.11.17.tar.gz
|
||||
/bind-9.11.17.tar.gz.asc
|
||||
/bind-9.11.18.tar.gz
|
||||
/bind-9.11.18.tar.gz.asc
|
||||
/bind-9.11.19.tar.gz
|
||||
/bind-9.11.19.tar.gz.asc
|
||||
/bind-9.11.20.tar.gz
|
||||
/bind-9.11.20.tar.gz.asc
|
||||
/bind-9.11.21.tar.gz
|
||||
/bind-9.11.21.tar.gz.asc
|
||||
/bind-9.11.22.tar.gz
|
||||
/bind-9.11.22.tar.gz.asc
|
||||
/bind-9.11.23.tar.gz
|
||||
/bind-9.11.23.tar.gz.asc
|
||||
/bind-9.11.24.tar.gz
|
||||
/bind-9.11.24.tar.gz.asc
|
||||
/bind-9.11.25.tar.gz
|
||||
/bind-9.11.25.tar.gz.asc
|
||||
/bind-9.11.26.tar.gz
|
||||
/bind-9.11.26.tar.gz.asc
|
||||
/bind-9.16.1.tar.xz
|
||||
/bind-9.16.1.tar.xz.asc
|
||||
/bind-9.16.2.tar.xz
|
||||
/bind-9.16.2.tar.xz.asc
|
||||
/bind-9.16.4.tar.xz
|
||||
/bind-9.16.4.tar.xz.asc
|
||||
/bind-9.16.5.tar.xz
|
||||
/bind-9.16.5.tar.xz.asc
|
||||
/bind-9.16.6.tar.xz
|
||||
/bind-9.16.6.tar.xz.asc
|
||||
/bind-9.16.7.tar.xz
|
||||
/bind-9.16.7.tar.xz.asc
|
||||
/bind-9.16.8.tar.xz
|
||||
/bind-9.16.8.tar.xz.asc
|
||||
/bind-9.16.9.tar.xz
|
||||
/bind-9.16.9.tar.xz.asc
|
||||
/bind-9.16.10.tar.xz
|
||||
/bind-9.16.10.tar.xz.asc
|
||||
/bind-9.16.11.tar.xz
|
||||
/bind-9.16.11.tar.xz.asc
|
||||
/bind-9.16.13.tar.xz
|
||||
/bind-9.16.13.tar.xz.asc
|
||||
/bind-9.16.15.tar.xz
|
||||
/bind-9.16.15.tar.xz.asc
|
||||
/bind-9.16.16.tar.xz
|
||||
/bind-9.16.16.tar.xz.asc
|
||||
/bind-9.16.17.tar.xz
|
||||
/bind-9.16.17.tar.xz.asc
|
||||
/bind-9.16.18.tar.xz
|
||||
/bind-9.16.18.tar.xz.asc
|
||||
/bind-9.16.19.tar.xz
|
||||
/bind-9.16.19.tar.xz.asc
|
||||
/bind-9.16.20.tar.xz
|
||||
/bind-9.16.20.tar.xz.asc
|
||||
/bind-9.16.21.tar.xz
|
||||
/bind-9.16.21.tar.xz.asc
|
||||
/bind-9.16.22.tar.xz
|
||||
/bind-9.16.22.tar.xz.asc
|
||||
/bind-9.16.23.tar.xz
|
||||
/bind-9.16.23.tar.xz.asc
|
||||
/bind-9.16.24.tar.xz
|
||||
/bind-9.16.24.tar.xz.asc
|
||||
/bind-9.16.25.tar.xz
|
||||
/bind-9.16.25.tar.xz.asc
|
||||
/bind-9.16.26.tar.xz
|
||||
/bind-9.16.26.tar.xz.asc
|
||||
/bind-9.16.27.tar.xz
|
||||
/bind-9.16.27.tar.xz.asc
|
||||
/bind-9.16.28.tar.xz
|
||||
/bind-9.16.28.tar.xz.asc
|
||||
/bind-9.16.29.tar.xz
|
||||
/bind-9.16.29.tar.xz.asc
|
||||
/bind-9.16.30.tar.xz
|
||||
/bind-9.16.30.tar.xz.asc
|
||||
/bind-9.18.0.tar.xz
|
||||
/bind-9.18.0.tar.xz.asc
|
||||
/bind-9.18.1.tar.xz
|
||||
/bind-9.18.1.tar.xz.asc
|
||||
/bind-9.18.2.tar.xz
|
||||
/bind-9.18.2.tar.xz.asc
|
||||
/bind-9.18.3.tar.xz
|
||||
/bind-9.18.3.tar.xz.asc
|
||||
/bind-9.18.4.tar.xz
|
||||
/bind-9.18.4.tar.xz.asc
|
||||
/bind-9.18.5.tar.xz
|
||||
/bind-9.18.5.tar.xz.asc
|
||||
/bind-9.18.6.tar.xz
|
||||
/bind-9.18.6.tar.xz.asc
|
||||
/bind-9.18.7.tar.xz
|
||||
/bind-9.18.7.tar.xz.asc
|
||||
/bind-9.18.8.tar.xz
|
||||
/bind-9.18.8.tar.xz.asc
|
||||
/bind-9.18.9.tar.xz
|
||||
/bind-9.18.9.tar.xz.asc
|
||||
/bind-9.18.10.tar.xz
|
||||
/bind-9.18.10.tar.xz.asc
|
||||
/bind-9.18.11.tar.xz
|
||||
/bind-9.18.11.tar.xz.asc
|
||||
/bind-9.18.12.tar.xz
|
||||
/bind-9.18.12.tar.xz.asc
|
||||
/bind-9.18.13.tar.xz
|
||||
/bind-9.18.13.tar.xz.asc
|
||||
/bind-9.18.14.tar.xz
|
||||
/bind-9.18.14.tar.xz.asc
|
||||
/bind-9.18.15.tar.xz
|
||||
/bind-9.18.15.tar.xz.asc
|
||||
/bind-9.18.16.tar.xz
|
||||
/bind-9.18.16.tar.xz.asc
|
||||
/bind-9.18.17.tar.xz
|
||||
/bind-9.18.17.tar.xz.asc
|
||||
/bind-9.18.18.tar.xz
|
||||
/bind-9.18.18.tar.xz.asc
|
||||
/bind-9.18.19.tar.xz
|
||||
/bind-9.18.19.tar.xz.asc
|
||||
/bind-9.18.20.tar.xz
|
||||
/bind-9.18.20.tar.xz.asc
|
||||
/bind-9.18.21.tar.xz
|
||||
/bind-9.18.21.tar.xz.asc
|
||||
/bind-9.18.24.tar.xz
|
||||
/bind-9.18.24.tar.xz.asc
|
||||
/bind-9.18.26.tar.xz
|
||||
/bind-9.18.26.tar.xz.asc
|
||||
/bind-9.18.28.tar.xz
|
||||
/bind-9.18.28.tar.xz.asc
|
||||
/bind-9.18.29.tar.xz
|
||||
/bind-9.18.29.tar.xz.asc
|
||||
/bind-9.18.30.tar.xz
|
||||
/bind-9.18.30.tar.xz.asc
|
||||
/bind-9.18.31.tar.xz
|
||||
/bind-9.18.31.tar.xz.asc
|
||||
/bind-9.18.32.tar.xz
|
||||
/bind-9.18.32.tar.xz.asc
|
||||
/bind-9.18.33.tar.xz
|
||||
/bind-9.18.33.tar.xz.asc
|
||||
/bind-9.18.*.tar.xz
|
||||
/bind-9.18.*.tar.xz.asc
|
||||
61
0001-Use-variable-PROGRAM_SUFFIX-in-install-target.patch
Normal file
61
0001-Use-variable-PROGRAM_SUFFIX-in-install-target.patch
Normal file
|
|
@ -0,0 +1,61 @@
|
|||
From 31bd3a0996a85c0fced0c6ace3da1241b30dc397 Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
||||
Date: Thu, 30 Apr 2026 17:28:40 +0200
|
||||
Subject: [PATCH] Use variable PROGRAM_SUFFIX in install target
|
||||
|
||||
--program-suffix is handled by configure itself. But some makefile rules
|
||||
need to know it by a special value. Provide that to make multiple
|
||||
versions installable together on a single system.
|
||||
---
|
||||
Makefile.top | 1 +
|
||||
bin/check/Makefile.am | 6 +++---
|
||||
bin/confgen/Makefile.am | 6 +++---
|
||||
3 files changed, 7 insertions(+), 6 deletions(-)
|
||||
|
||||
diff --git a/Makefile.top b/Makefile.top
|
||||
index e186d15..91c076b 100644
|
||||
--- a/Makefile.top
|
||||
+++ b/Makefile.top
|
||||
@@ -14,6 +14,7 @@ AM_CPPFLAGS = \
|
||||
AM_LDFLAGS = \
|
||||
$(STD_LDFLAGS)
|
||||
LDADD =
|
||||
+PROGRAM_SUFFIX =
|
||||
|
||||
if HOST_MACOS
|
||||
AM_LDFLAGS += \
|
||||
diff --git a/bin/check/Makefile.am b/bin/check/Makefile.am
|
||||
index 8f63c35..36f232c 100644
|
||||
--- a/bin/check/Makefile.am
|
||||
+++ b/bin/check/Makefile.am
|
||||
@@ -27,8 +27,8 @@ LDADD += \
|
||||
bin_PROGRAMS = named-checkconf named-checkzone
|
||||
|
||||
install-exec-hook:
|
||||
- ln -f $(DESTDIR)$(bindir)/named-checkzone \
|
||||
- $(DESTDIR)$(bindir)/named-compilezone
|
||||
+ ln -f $(DESTDIR)$(bindir)/named-checkzone$(PROGRAM_SUFFIX) \
|
||||
+ $(DESTDIR)$(bindir)/named-compilezone$(PROGRAM_SUFFIX)
|
||||
|
||||
uninstall-hook:
|
||||
- -rm -f $(DESTDIR)$(bindir)/named-compilezone
|
||||
+ -rm -f $(DESTDIR)$(bindir)/named-compilezone$(PROGRAM_SUFFIX)
|
||||
diff --git a/bin/confgen/Makefile.am b/bin/confgen/Makefile.am
|
||||
index c1dca43..fe86dd7 100644
|
||||
--- a/bin/confgen/Makefile.am
|
||||
+++ b/bin/confgen/Makefile.am
|
||||
@@ -23,8 +23,8 @@ libconfgen_la_SOURCES = \
|
||||
sbin_PROGRAMS = tsig-keygen rndc-confgen
|
||||
|
||||
install-exec-hook:
|
||||
- ln -f $(DESTDIR)$(sbindir)/tsig-keygen \
|
||||
- $(DESTDIR)$(sbindir)/ddns-confgen
|
||||
+ ln -f $(DESTDIR)$(sbindir)/tsig-keygen$(PROGRAM_SUFFIX) \
|
||||
+ $(DESTDIR)$(sbindir)/ddns-confgen$(PROGRAM_SUFFIX)
|
||||
|
||||
uninstall-hook:
|
||||
- -rm -f $(DESTDIR)$(sbindir)/ddns-confgen
|
||||
+ -rm -f $(DESTDIR)$(sbindir)/ddns-confgen$(PROGRAM_SUFFIX)
|
||||
--
|
||||
2.54.0
|
||||
|
||||
43
Changes.md
Normal file
43
Changes.md
Normal file
|
|
@ -0,0 +1,43 @@
|
|||
# Significant Changes in BIND9 package
|
||||
|
||||
## BIND 9.16
|
||||
|
||||
### New features
|
||||
|
||||
- *libuv* is used for network subsystem as a mandatory dependency
|
||||
- *dnssec-policy* support in named.conf is introduced, providing a a key and signing policy
|
||||
([KASP](https://gitlab.isc.org/isc-projects/bind9/-/wikis/DNSSEC-Key-and-Signing-Policy-(KASP)))
|
||||
- *trusted-keys* and *managed-keys* are deprecated, replaced by *trust-anchors*
|
||||
- *trust-anchors* support also anchor in a *DS* format, in addition to *DNSKEY* format
|
||||
- **dig, mdig** and **delv** support **+yaml** parameter to print detailed machine parseable output
|
||||
|
||||
### Feature changes
|
||||
|
||||
- Static trust anchor and *dnssec-validation auto;* are incompatible and cause fatal error, when used together.
|
||||
- *DS* and *CDS* now generates only SHA-256 digest, SHA-1 is no longer generated by default
|
||||
- SipHash 2-4 DNS Cookie ([RFC 7873](https://www.rfc-editor.org/rfc/rfc7873.html) is now default).
|
||||
Only AES alternative algorithm is kept, HMAC-SHA cookie support were removed.
|
||||
- **dnssec-signzone** and **dnssec-verify** commands print output to stdout, *-q* parameter can silence them
|
||||
|
||||
### Features removed
|
||||
|
||||
- *dnssec-enable* option is obsolete, DNSSEC support is always enabled
|
||||
- *dnssec-lookaside* option is deprecated and support for it removed from all tools
|
||||
- *cleaning-interval* option is removed
|
||||
|
||||
### Upstream release notes
|
||||
|
||||
- [9.16.10 notes](https://downloads.isc.org/isc/bind9/9.16.10/doc/arm/html/notes.html#notes-for-bind-9-16-10)
|
||||
- [9.16.0 notes](https://downloads.isc.org/isc/bind9/9.16.0/doc/arm/html/notes.html#notes-for-bind-9-16-0)
|
||||
|
||||
## BIND 9.14
|
||||
|
||||
- single thread support removed. Cannot provide *bind-export-libs* for DHCP
|
||||
- *lwres* support completely removed. Both daemon and library
|
||||
- common parts of daemon moved into *libns* shared library
|
||||
- introduced plugin for filtering aaaa responses
|
||||
- some SDB utilities no longer supported
|
||||
|
||||
### Upstream release notes
|
||||
|
||||
- [9.14.7 notes](https://downloads.isc.org/isc/bind9/9.14.7/RELEASE-NOTES-bind-9.14.7.html)
|
||||
|
|
@ -1,5 +0,0 @@
|
|||
|
||||
The files included in this package are obtained from
|
||||
ftp://ftp.internic.net/domain/, where they are made
|
||||
available for free to anybody. In other words, this package
|
||||
is created under a Public Domain license.
|
||||
6
Makefile
6
Makefile
|
|
@ -1,6 +0,0 @@
|
|||
# Makefile for source rpm: bind
|
||||
# $Id$
|
||||
NAME := bind
|
||||
SPECFILE = $(firstword $(wildcard *.spec))
|
||||
|
||||
include ../common/Makefile.common
|
||||
38
README.md
Normal file
38
README.md
Normal file
|
|
@ -0,0 +1,38 @@
|
|||
# BIND 9
|
||||
|
||||
[BIND (Berkeley Internet Name Domain)](https://www.isc.org/downloads/bind/doc/) is a complete, highly portable
|
||||
implementation of the DNS (Domain Name System) protocol.
|
||||
|
||||
Internet Systems Consortium
|
||||
([https://www.isc.org](https://www.isc.org)), a 501(c)(3) public benefit
|
||||
corporation dedicated to providing software and services in support of the
|
||||
Internet infrastructure, developed BIND 9 and is responsible for its
|
||||
ongoing maintenance and improvement.
|
||||
|
||||
More details about upstream project can be found on their
|
||||
[gitlab](https://gitlab.isc.org/isc-projects/bind9). This repository contains
|
||||
only upstream sources and packaging instructions for
|
||||
[Fedora Project](https://fedoraproject.org).
|
||||
|
||||
Any rebase requires to be built together with
|
||||
[bind-dyndb-ldap](https://src.fedoraproject.org/rpms/bind-dyndb-ldap/) to prevent conflict
|
||||
at installation of [freeipa-server-dns](https://src.fedoraproject.org/rpms/freeipa).
|
||||
Stable bodhi updates are checked, but rawhide are not checked explicitly.
|
||||
Symbol of libraries in *bind-libs* changes with every minor version change of bind,
|
||||
therefore they break any package dependent on bind-libs.
|
||||
|
||||
## Subpackages
|
||||
|
||||
The package contains several subpackages, some of them can be disabled on rebuild.
|
||||
|
||||
* **bind** -- *named* daemon providing DNS server
|
||||
* **bind-utils** -- set of tools to analyse DNS responses or update entries (dig, host)
|
||||
* **bind-doc** -- documentation for current bind, *BIND 9 Administrator Reference Manual*.
|
||||
* **bind-libs** -- Shared libraries used by some others programs
|
||||
* **bind-devel** -- Development headers for libs. Can be disabled by `--without DEVEL`
|
||||
|
||||
|
||||
## Optional features
|
||||
|
||||
* *GSSTSIG* -- Support for Kerberos authentication in BIND.
|
||||
* *LMDB* -- Support for dynamic database for managing runtime added zones. Provides faster removal of added zone with much less overhead. But requires lmdb linked to base libs.
|
||||
|
|
@ -1,79 +0,0 @@
|
|||
PGSQL BIND SDB driver
|
||||
|
||||
The postgresql BIND SDB driver is of experimental status and should not be
|
||||
used for production systems.
|
||||
|
||||
Usage:
|
||||
|
||||
o Use the named_sdb process ( put ENABLE_SDB=yes in /etc/sysconfig/named )
|
||||
|
||||
o Edit your named.conf to contain a database zone, eg. :
|
||||
|
||||
zone "pgdb.net." IN {
|
||||
type master;
|
||||
database "pgsql bind pgdb localhost pguser pgpasswd";
|
||||
# ^- DB name ^-Table ^-host ^-user ^-password
|
||||
};
|
||||
|
||||
o Create the database zone table
|
||||
The table must contain the columns "name", "rdtype", and "rdata", and
|
||||
is expected to contain a properly constructed zone. The program "zonetodb"
|
||||
creates such a table.
|
||||
|
||||
zonetodb usage:
|
||||
|
||||
zonetodb origin file dbname dbtable
|
||||
|
||||
where
|
||||
origin : zone origin, eg "pgdb.net."
|
||||
file : master zone database file, eg. pgdb.net.db
|
||||
dbname : name of postgresql database
|
||||
dbtable: name of table in database
|
||||
|
||||
Eg. to import this zone in the file 'pgdb.net.db' into the 'bind' database
|
||||
'pgdb' table:
|
||||
|
||||
---
|
||||
#pgdb.net.db:
|
||||
$TTL 1H
|
||||
@ SOA localhost. root.localhost. ( 1
|
||||
3H
|
||||
1H
|
||||
1W
|
||||
1H )
|
||||
NS localhost.
|
||||
host1 A 192.168.2.1
|
||||
host2 A 192.168.2.2
|
||||
host3 A 192.168.2.3
|
||||
host4 A 192.168.2.4
|
||||
host5 A 192.168.2.5
|
||||
host6 A 192.168.2.6
|
||||
host7 A 192.168.2.7
|
||||
---
|
||||
|
||||
Issue this command as the pgsql user authorized to update the bind database:
|
||||
|
||||
# zonetodb pgdb.net. pgdb.net.db bind pgdb
|
||||
|
||||
will create / update the pgdb table in the 'bind' db:
|
||||
|
||||
$ psql -dbind -c 'select * from pgdb;'
|
||||
name | ttl | rdtype | rdata
|
||||
----------------+------+--------+-----------------------------------------------------
|
||||
pgdb.net | 3600 | SOA | localhost. root.localhost. 1 10800 3600 604800 3600
|
||||
pgdb.net | 3600 | NS | localhost.
|
||||
host1.pgdb.net | 3600 | A | 192.168.2.1
|
||||
host2.pgdb.net | 3600 | A | 192.168.2.2
|
||||
host3.pgdb.net | 3600 | A | 192.168.2.3
|
||||
host4.pgdb.net | 3600 | A | 192.168.2.4
|
||||
host5.pgdb.net | 3600 | A | 192.168.2.5
|
||||
host6.pgdb.net | 3600 | A | 192.168.2.6
|
||||
host7.pgdb.net | 3600 | A | 192.168.2.7
|
||||
(9 rows)
|
||||
|
||||
I've tested exactly the above configuration with bind-sdb-9.3.1+ and it works OK.
|
||||
|
||||
NOTE: If you use pgsqldb SDB, ensure the postgresql service is started before the named
|
||||
service .
|
||||
|
||||
USE AT YOUR OWN RISK!
|
||||
16
bind-9.11.12.tar.gz.asc
Normal file
16
bind-9.11.12.tar.gz.asc
Normal file
|
|
@ -0,0 +1,16 @@
|
|||
-----BEGIN PGP SIGNATURE-----
|
||||
|
||||
iQIzBAABAgAdFiEErj+seWcR7Fn8AHqkdLtrmky7PTgFAl2WMooACgkQdLtrmky7
|
||||
PThv2RAAnXNLYTzXtH6ls29tRm5Hc+D6UaeqcWDNQ4BpkRVhrFxtukalGCi9mmB6
|
||||
NPJzFyXmaOW654pypCIuEgqJNFUpDtLzLzT7SUF+mhm+5plsaRSBnh4mq87l5KSp
|
||||
twODAPnfCJV+HBk5RmToLEstAbGQ7xEBTyQtZoFkY+V7zEFwENKiCvWsoSWOkYR3
|
||||
zXo3sKjc83HV9ShbW/mCtbZf5L0qlbrKOAzqJfAFMhNNJi8kMbmr/Zi2sIfN+Rhv
|
||||
g8HQo89Epv6r51yAdeED8idIX4rKjjcEtHrZeDmLdCcdHgSEj2sIlH92Joce6vL0
|
||||
S59A0rItIXm6fW8sz6WNpcj4tVtWYbIYjXZ4SPFNkaUrHv8cUekq+5vbI+v07Gh3
|
||||
2bhtDsDyTY5I1/AsY/EFmwkCAjUS00jZryBnuJpLB3v5JtUog4ek32yLBzPrqRBo
|
||||
1876j4nlXAia8mG0OgJNWZ0gHyUPe/TgfR8fQDLmHxHHlKrJNTEwY6bLW8jzFTX1
|
||||
zk510fI1K7J9tiQgf5wcBQ2h3EBlqzDNIJDovoATzLYIf0HKyVegh/vnQdtdEhUR
|
||||
1DzJAt3bsBfAP1AFfWPD/ACu5Zdm7SxY1wE/pjkwttDU3sRZqOfuwNBGeolu3cVN
|
||||
O9/h1zsyVeVS0ui2vu4+V4EvNitmXsVbG2doDq9L5yBiIKGO2Ew=
|
||||
=GCy6
|
||||
-----END PGP SIGNATURE-----
|
||||
16
bind-9.14.7.tar.gz.asc
Normal file
16
bind-9.14.7.tar.gz.asc
Normal file
|
|
@ -0,0 +1,16 @@
|
|||
-----BEGIN PGP SIGNATURE-----
|
||||
|
||||
iQIzBAABAgAdFiEErj+seWcR7Fn8AHqkdLtrmky7PTgFAl2WMpEACgkQdLtrmky7
|
||||
PTh/sg//QbNRAQvADQfwF1PPo+JxB+3WzQ9oJAWeHbOoiubwkUwO9xE+BEnTNd5o
|
||||
oM1lSLqFxNykOTaoeJlqPftPod1cxo7lSzkwflugGyB/59wliCpqCg053YV4x9mO
|
||||
QggvA/E50+0FI/Om/7v4GHGADu/JE83FovOueWAB0LgqfDSD6QFcNFF9sUJJ4P7r
|
||||
FcEXSWj8QbrHMWBKncZUOpD2ECotvtrYmi0DTHl1XfigESDQpWtsnTFuabCCsvkh
|
||||
ch9wQRplAes2Mf/aS5tl1y0QKKBFuEjtGiTdgrDl6o9GLnx6CueX5saZehu2EVkr
|
||||
fq2vEYUC2lRQSjuxSMMJ3L0TGUcl7+ixlAIISS2K9L5Xx7MhBXt/EH5KiKPfsEet
|
||||
3EH+DhxV5uXjDU7MgvREnxT+ssV23e0HWTz4tVVQ9LpvYmWPIgLcSOhHCc57yoQF
|
||||
c46V0f69dMWbMAlQ93EZSG274ZvpIszpK8+3hGI3/TuDFFgiQJeJJBFVtYJMle69
|
||||
3mEEclfzO7fBiXZFec6nVx2309bL64bafN7zszPKXl4XgoefOfD0v0eWqQT4fxfm
|
||||
dnGC0qMqSZs5F+d0fISV5JUUNYzt9PZjvnzqLLGOeTF6l3/n9G1mmNsXcxJ1OEIF
|
||||
6qh1oO7JTPjt0MFhKac4QjNQi/Bnp25O3I/PRyWZCbiwXkyvyQU=
|
||||
=ZT7s
|
||||
-----END PGP SIGNATURE-----
|
||||
66
bind-9.16-redhat_doc.patch
Normal file
66
bind-9.16-redhat_doc.patch
Normal file
|
|
@ -0,0 +1,66 @@
|
|||
From 402403b4bbb4f603693378e86b6c97997ccb0401 Mon Sep 17 00:00:00 2001
|
||||
From: Petr Mensik <pemensik@redhat.com>
|
||||
Date: Wed, 17 Jun 2020 23:17:13 +0200
|
||||
Subject: [PATCH] Update man named with Red Hat specifics
|
||||
|
||||
This is almost unmodified text and requires revalidation. Some of those
|
||||
statements are no longer correct.
|
||||
---
|
||||
bin/named/named.rst | 41 +++++++++++++++++++++++++++++++++++++++++
|
||||
1 file changed, 41 insertions(+)
|
||||
|
||||
diff --git a/bin/named/named.rst b/bin/named/named.rst
|
||||
index ea440b2..fa51984 100644
|
||||
--- a/bin/named/named.rst
|
||||
+++ b/bin/named/named.rst
|
||||
@@ -212,6 +212,47 @@ Files
|
||||
|named_pid|
|
||||
The default process-id file.
|
||||
|
||||
+Notes
|
||||
+~~~~~
|
||||
+
|
||||
+**Red Hat SELinux BIND Security Profile:**
|
||||
+
|
||||
+By default, Red Hat ships BIND with the most secure SELinux policy
|
||||
+that will not prevent normal BIND operation and will prevent exploitation
|
||||
+of all known BIND security vulnerabilities . See the selinux(8) man page
|
||||
+for information about SElinux.
|
||||
+
|
||||
+It is not necessary to run named in a chroot environment if the Red Hat
|
||||
+SELinux policy for named is enabled. When enabled, this policy is far
|
||||
+more secure than a chroot environment. Users are recommended to enable
|
||||
+SELinux and remove the bind-chroot package.
|
||||
+
|
||||
+*With this extra security comes some restrictions:*
|
||||
+
|
||||
+By default, the SELinux policy does not allow named to write any master
|
||||
+zone database files. Only the root user may create files in the $ROOTDIR/var/named
|
||||
+zone database file directory (the options { "directory" } option), where
|
||||
+$ROOTDIR is set in /etc/sysconfig/named.
|
||||
+
|
||||
+The "named" group must be granted read privelege to
|
||||
+these files in order for named to be enabled to read them.
|
||||
+
|
||||
+Any file created in the zone database file directory is automatically assigned
|
||||
+the SELinux file context *named_zone_t* .
|
||||
+
|
||||
+By default, SELinux prevents any role from modifying *named_zone_t* files; this
|
||||
+means that files in the zone database directory cannot be modified by dynamic
|
||||
+DNS (DDNS) updates or zone transfers.
|
||||
+
|
||||
+The Red Hat BIND distribution and SELinux policy creates three directories where
|
||||
+named is allowed to create and modify files: */var/named/slaves*, */var/named/dynamic*
|
||||
+*/var/named/data*. By placing files you want named to modify, such as
|
||||
+slave or DDNS updateable zone files and database / statistics dump files in
|
||||
+these directories, named will work normally and no further operator action is
|
||||
+required. Files in these directories are automatically assigned the '*named_cache_t*'
|
||||
+file context, which SELinux allows named to write.
|
||||
+
|
||||
+
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
--
|
||||
2.34.1
|
||||
|
||||
854
bind-9.18-CVE-2026-10723-test.patch
Normal file
854
bind-9.18-CVE-2026-10723-test.patch
Normal file
|
|
@ -0,0 +1,854 @@
|
|||
From 2a4786b0edde59274f682c9bd4ae4026c2d08218 Mon Sep 17 00:00:00 2001
|
||||
From: Evan Hunt <each@isc.org>
|
||||
Date: Wed, 1 Jul 2026 22:56:02 -0700
|
||||
Subject: [PATCH] add isctest.mark method for ecdsa_deterinistic
|
||||
|
||||
This checks support for ECDSA deterministic mode in the cryptography
|
||||
library.
|
||||
|
||||
(cherry picked from commit 6e44151466864d3dd783a20da83d01028781d3e2)
|
||||
(cherry picked from commit dc3f52388427f4f94087d984d5a2088b925810e2)
|
||||
|
||||
Reproducer for #5874 NSEC3 impersonation
|
||||
|
||||
LLM generated.
|
||||
|
||||
(cherry picked from commit f3e2eb333be3ac636f745aa13cfb8d9ee8af87d8)
|
||||
(cherry picked from commit 35e3d49d2222c13786a06021c7ed583d2a656e51)
|
||||
|
||||
Update reproducer #5874
|
||||
|
||||
Update the llm generated reproducer:
|
||||
- Move server.py into ans1/ans.py
|
||||
- Remove unnecessary named.conf configuration options
|
||||
- Add comments describing the steps (copied from GL issue)
|
||||
- Rename system test
|
||||
|
||||
(cherry picked from commit c1321fef165a2ef8c2bff971901c58941e8e694c)
|
||||
(cherry picked from commit 833dd3b230b92596074e8da15b12298f46c939f2)
|
||||
---
|
||||
bin/tests/system/chain/ans3/ans.py | 10 +-
|
||||
bin/tests/system/chain/ans4/ans.py | 8 +-
|
||||
bin/tests/system/cookie/ans9/ans.py | 7 +-
|
||||
bin/tests/system/digdelv/ans8/ans.py | 7 +-
|
||||
bin/tests/system/dnssec/ans10/ans.py | 11 +-
|
||||
bin/tests/system/forward/ans11/ans.py | 12 +-
|
||||
bin/tests/system/isctest/mark.py | 12 +
|
||||
.../system/nsec3_impersonation/ans1/ans.py | 280 ++++++++++++++++++
|
||||
.../nsec3_impersonation/ns2/named.conf.j2 | 33 +++
|
||||
.../tests_nsec3_impersonation.py | 152 ++++++++++
|
||||
bin/tests/system/qmin/ans2/ans.py | 11 +-
|
||||
bin/tests/system/qmin/ans3/ans.py | 11 +-
|
||||
bin/tests/system/qmin/ans4/ans.py | 11 +-
|
||||
bin/tests/system/resolver/ans10/ans.py | 12 +-
|
||||
14 files changed, 529 insertions(+), 48 deletions(-)
|
||||
create mode 100644 bin/tests/system/nsec3_impersonation/ans1/ans.py
|
||||
create mode 100644 bin/tests/system/nsec3_impersonation/ns2/named.conf.j2
|
||||
create mode 100644 bin/tests/system/nsec3_impersonation/tests_nsec3_impersonation.py
|
||||
|
||||
diff --git a/bin/tests/system/chain/ans3/ans.py b/bin/tests/system/chain/ans3/ans.py
|
||||
index 0a031c1145..7c54c3c51a 100644
|
||||
--- a/bin/tests/system/chain/ans3/ans.py
|
||||
+++ b/bin/tests/system/chain/ans3/ans.py
|
||||
@@ -19,10 +19,10 @@ import sys
|
||||
import signal
|
||||
import socket
|
||||
import select
|
||||
-from datetime import datetime, timedelta
|
||||
-import functools
|
||||
|
||||
-import dns, dns.message, dns.query
|
||||
+import dns
|
||||
+import dns.message
|
||||
+import dns.query
|
||||
from dns.rdatatype import *
|
||||
from dns.rdataclass import *
|
||||
from dns.rcode import *
|
||||
@@ -173,9 +173,9 @@ else:
|
||||
while running:
|
||||
try:
|
||||
inputready, outputready, exceptready = select.select(input, [], [])
|
||||
- except select.error as e:
|
||||
+ except select.error:
|
||||
break
|
||||
- except socket.error as e:
|
||||
+ except socket.error:
|
||||
break
|
||||
except KeyboardInterrupt:
|
||||
break
|
||||
diff --git a/bin/tests/system/chain/ans4/ans.py b/bin/tests/system/chain/ans4/ans.py
|
||||
index c969117368..de536b25bd 100755
|
||||
--- a/bin/tests/system/chain/ans4/ans.py
|
||||
+++ b/bin/tests/system/chain/ans4/ans.py
|
||||
@@ -22,7 +22,9 @@ import select
|
||||
from datetime import datetime, timedelta
|
||||
import functools
|
||||
|
||||
-import dns, dns.message, dns.query
|
||||
+import dns
|
||||
+import dns.message
|
||||
+import dns.query
|
||||
from dns.rdatatype import *
|
||||
from dns.rdataclass import *
|
||||
from dns.rcode import *
|
||||
@@ -371,9 +373,9 @@ else:
|
||||
while running:
|
||||
try:
|
||||
inputready, outputready, exceptready = select.select(input, [], [])
|
||||
- except select.error as e:
|
||||
+ except select.error:
|
||||
break
|
||||
- except socket.error as e:
|
||||
+ except socket.error:
|
||||
break
|
||||
except KeyboardInterrupt:
|
||||
break
|
||||
diff --git a/bin/tests/system/cookie/ans9/ans.py b/bin/tests/system/cookie/ans9/ans.py
|
||||
index 3b0f82cc1d..2710386d74 100644
|
||||
--- a/bin/tests/system/cookie/ans9/ans.py
|
||||
+++ b/bin/tests/system/cookie/ans9/ans.py
|
||||
@@ -15,9 +15,6 @@ import sys
|
||||
import signal
|
||||
import socket
|
||||
import select
|
||||
-from datetime import datetime, timedelta
|
||||
-import time
|
||||
-import functools
|
||||
|
||||
import dns
|
||||
import dns.edns
|
||||
@@ -257,9 +254,9 @@ else:
|
||||
while running:
|
||||
try:
|
||||
inputready, outputready, exceptready = select.select(input, [], [])
|
||||
- except select.error as e:
|
||||
+ except select.error:
|
||||
break
|
||||
- except socket.error as e:
|
||||
+ except socket.error:
|
||||
break
|
||||
except KeyboardInterrupt:
|
||||
break
|
||||
diff --git a/bin/tests/system/digdelv/ans8/ans.py b/bin/tests/system/digdelv/ans8/ans.py
|
||||
index 3e18edc1cc..1896a2bafc 100644
|
||||
--- a/bin/tests/system/digdelv/ans8/ans.py
|
||||
+++ b/bin/tests/system/digdelv/ans8/ans.py
|
||||
@@ -17,7 +17,8 @@ import socket
|
||||
import select
|
||||
import struct
|
||||
|
||||
-import dns, dns.message
|
||||
+import dns
|
||||
+import dns.message
|
||||
from dns.rcode import *
|
||||
|
||||
modes = [
|
||||
@@ -109,9 +110,9 @@ hung_conns = []
|
||||
while running:
|
||||
try:
|
||||
inputready, outputready, exceptready = select.select(input, [], [])
|
||||
- except select.error as e:
|
||||
+ except select.error:
|
||||
break
|
||||
- except socket.error as e:
|
||||
+ except socket.error:
|
||||
break
|
||||
except KeyboardInterrupt:
|
||||
break
|
||||
diff --git a/bin/tests/system/dnssec/ans10/ans.py b/bin/tests/system/dnssec/ans10/ans.py
|
||||
index 84bf0a2642..46af72a147 100644
|
||||
--- a/bin/tests/system/dnssec/ans10/ans.py
|
||||
+++ b/bin/tests/system/dnssec/ans10/ans.py
|
||||
@@ -16,10 +16,11 @@ import signal
|
||||
import socket
|
||||
import select
|
||||
from datetime import datetime, timedelta
|
||||
-import time
|
||||
-import functools
|
||||
|
||||
-import dns, dns.message, dns.query, dns.flags
|
||||
+import dns
|
||||
+import dns.message
|
||||
+import dns.query
|
||||
+import dns.flags
|
||||
from dns.rdatatype import *
|
||||
from dns.rdataclass import *
|
||||
from dns.rcode import *
|
||||
@@ -140,9 +141,9 @@ else:
|
||||
while running:
|
||||
try:
|
||||
inputready, outputready, exceptready = select.select(input, [], [])
|
||||
- except select.error as e:
|
||||
+ except select.error:
|
||||
break
|
||||
- except socket.error as e:
|
||||
+ except socket.error:
|
||||
break
|
||||
except KeyboardInterrupt:
|
||||
break
|
||||
diff --git a/bin/tests/system/forward/ans11/ans.py b/bin/tests/system/forward/ans11/ans.py
|
||||
index 00b5895f76..d5b8a5b037 100644
|
||||
--- a/bin/tests/system/forward/ans11/ans.py
|
||||
+++ b/bin/tests/system/forward/ans11/ans.py
|
||||
@@ -16,11 +16,11 @@ import signal
|
||||
import socket
|
||||
import select
|
||||
import struct
|
||||
-from datetime import datetime, timedelta
|
||||
-import time
|
||||
-import functools
|
||||
|
||||
-import dns, dns.message, dns.query, dns.flags
|
||||
+import dns
|
||||
+import dns.message
|
||||
+import dns.query
|
||||
+import dns.flags
|
||||
from dns.rdatatype import *
|
||||
from dns.rdataclass import *
|
||||
from dns.rcode import *
|
||||
@@ -192,9 +192,9 @@ hung_conns = []
|
||||
while running:
|
||||
try:
|
||||
inputready, outputready, exceptready = select.select(input, [], [])
|
||||
- except select.error as e:
|
||||
+ except select.error:
|
||||
break
|
||||
- except socket.error as e:
|
||||
+ except socket.error:
|
||||
break
|
||||
except KeyboardInterrupt:
|
||||
break
|
||||
diff --git a/bin/tests/system/isctest/mark.py b/bin/tests/system/isctest/mark.py
|
||||
index 53860a806c..098af5acfc 100644
|
||||
--- a/bin/tests/system/isctest/mark.py
|
||||
+++ b/bin/tests/system/isctest/mark.py
|
||||
@@ -88,3 +88,15 @@ softhsm2_environment = pytest.mark.skipif(
|
||||
),
|
||||
reason="SOFTHSM2_CONF and SOFTHSM2_MODULE environmental variables must be set and pkcs11-tool and softhsm2-util tools present",
|
||||
)
|
||||
+
|
||||
+ecdsa_deterministic = False
|
||||
+try:
|
||||
+ from cryptography.hazmat.backends import default_backend
|
||||
+
|
||||
+ ecdsa_deterministic = default_backend().ecdsa_deterministic_supported()
|
||||
+except Exception: # pylint: disable=broad-except
|
||||
+ pass
|
||||
+
|
||||
+with_ecdsa_deterministic = pytest.mark.skipif(
|
||||
+ not ecdsa_deterministic, reason="ECDSA deterministic signing is not supported"
|
||||
+)
|
||||
diff --git a/bin/tests/system/nsec3_impersonation/ans1/ans.py b/bin/tests/system/nsec3_impersonation/ans1/ans.py
|
||||
new file mode 100644
|
||||
index 0000000000..177e79c195
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/nsec3_impersonation/ans1/ans.py
|
||||
@@ -0,0 +1,280 @@
|
||||
+#!/usr/bin/python3
|
||||
+
|
||||
+# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
+#
|
||||
+# SPDX-License-Identifier: MPL-2.0
|
||||
+#
|
||||
+# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
+# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
+# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
+#
|
||||
+# See the COPYRIGHT file distributed with this work for additional
|
||||
+# information regarding copyright ownership.
|
||||
+
|
||||
+from collections.abc import AsyncGenerator
|
||||
+from dataclasses import dataclass
|
||||
+from pathlib import Path
|
||||
+
|
||||
+import json
|
||||
+
|
||||
+from cryptography.hazmat.primitives import serialization
|
||||
+
|
||||
+import dns.dnssec
|
||||
+import dns.flags
|
||||
+import dns.message
|
||||
+import dns.name
|
||||
+import dns.rcode
|
||||
+import dns.rdata
|
||||
+import dns.rdataclass
|
||||
+import dns.rdatatype
|
||||
+import dns.rrset
|
||||
+
|
||||
+from isctest.asyncserver import (
|
||||
+ AsyncDnsServer,
|
||||
+ DnsResponseSend,
|
||||
+ QueryContext,
|
||||
+ ResponseHandler,
|
||||
+)
|
||||
+
|
||||
+TTL = 300
|
||||
+TLD = "tld.test."
|
||||
+APEX_HASH = "1B40241KFORIOG780N4IKSCRLVETPCTQ"
|
||||
+ATTACKER = f"{APEX_HASH.lower()}.{TLD}"
|
||||
+VICTIM = f"victim.{TLD}"
|
||||
+AUTH_IP = "10.53.0.1"
|
||||
+
|
||||
+
|
||||
+@dataclass(frozen=True)
|
||||
+class Key:
|
||||
+ zone: dns.name.Name
|
||||
+ private_key: object
|
||||
+ dnskey: dns.rdata.Rdata
|
||||
+ ds: dns.rdata.Rdata
|
||||
+
|
||||
+
|
||||
+def name(text: str) -> dns.name.Name:
|
||||
+ return dns.name.from_text(text)
|
||||
+
|
||||
+
|
||||
+def load_keys() -> dict[str, Key]:
|
||||
+ path = Path(__file__).resolve().parent / "keys.json"
|
||||
+ with path.open(encoding="utf-8") as keys_file:
|
||||
+ raw_keys = json.load(keys_file)
|
||||
+
|
||||
+ keys = {}
|
||||
+ for zone, raw_key in raw_keys.items():
|
||||
+ private_key = serialization.load_pem_private_key(
|
||||
+ raw_key["private_pem"].encode("ascii"),
|
||||
+ password=None,
|
||||
+ )
|
||||
+ dnskey = dns.rdata.from_text(
|
||||
+ dns.rdataclass.IN, dns.rdatatype.DNSKEY, raw_key["dnskey"]
|
||||
+ )
|
||||
+ ds = dns.rdata.from_text(dns.rdataclass.IN, dns.rdatatype.DS, raw_key["ds"])
|
||||
+ keys[zone] = Key(name(zone), private_key, dnskey, ds)
|
||||
+
|
||||
+ return keys
|
||||
+
|
||||
+
|
||||
+def rrset(owner: str, rdtype: dns.rdatatype.RdataType, *rdatas: str) -> dns.rrset.RRset:
|
||||
+ return dns.rrset.from_text(owner, TTL, dns.rdataclass.IN, rdtype, *rdatas)
|
||||
+
|
||||
+
|
||||
+def rrset_from_rdata(owner: str, rdata: dns.rdata.Rdata) -> dns.rrset.RRset:
|
||||
+ return dns.rrset.from_rdata(name(owner), TTL, rdata)
|
||||
+
|
||||
+
|
||||
+def rrsig_rrset(covered: dns.rrset.RRset, signer: Key) -> dns.rrset.RRset:
|
||||
+ rrsig = dns.dnssec.sign(
|
||||
+ covered,
|
||||
+ signer.private_key,
|
||||
+ signer.zone,
|
||||
+ signer.dnskey,
|
||||
+ lifetime=86400,
|
||||
+ verify=True,
|
||||
+ )
|
||||
+ return dns.rrset.from_rdata(covered.name, covered.ttl, rrsig)
|
||||
+
|
||||
+
|
||||
+def add_signed(
|
||||
+ section: list[dns.rrset.RRset], covered: dns.rrset.RRset, signer: Key
|
||||
+) -> None:
|
||||
+ section.append(covered)
|
||||
+ section.append(rrsig_rrset(covered, signer))
|
||||
+
|
||||
+
|
||||
+def dnskey_rrset(zone: str, zone_key: Key) -> dns.rrset.RRset:
|
||||
+ return rrset_from_rdata(zone, zone_key.dnskey)
|
||||
+
|
||||
+
|
||||
+def ds_rrset(zone: str, zone_key: Key) -> dns.rrset.RRset:
|
||||
+ return rrset_from_rdata(zone, zone_key.ds)
|
||||
+
|
||||
+
|
||||
+def soa_rrset(zone: str) -> dns.rrset.RRset:
|
||||
+ return rrset(
|
||||
+ zone,
|
||||
+ dns.rdatatype.SOA,
|
||||
+ f"ns.{zone} hostmaster.{zone} 1 3600 600 86400 300",
|
||||
+ )
|
||||
+
|
||||
+
|
||||
+def ns_rrset(zone: str, ns_target: str) -> dns.rrset.RRset:
|
||||
+ return rrset(zone, dns.rdatatype.NS, ns_target)
|
||||
+
|
||||
+
|
||||
+def glue_rrset(ns_target: str, address: str) -> dns.rrset.RRset:
|
||||
+ return rrset(ns_target, dns.rdatatype.A, address)
|
||||
+
|
||||
+
|
||||
+def answer_dnskey(response: dns.message.Message, zone: str, zone_key: Key) -> None:
|
||||
+ add_signed(response.answer, dnskey_rrset(zone, zone_key), zone_key)
|
||||
+
|
||||
+
|
||||
+def answer_soa(response: dns.message.Message, zone: str, zone_key: Key) -> None:
|
||||
+ add_signed(response.answer, soa_rrset(zone), zone_key)
|
||||
+
|
||||
+
|
||||
+def answer_ns(
|
||||
+ response: dns.message.Message, zone: str, ns_target: str, zone_key: Key
|
||||
+) -> None:
|
||||
+ add_signed(response.answer, ns_rrset(zone, ns_target), zone_key)
|
||||
+
|
||||
+
|
||||
+class SignedResponseHandler(ResponseHandler):
|
||||
+ def __init__(self, keys: dict[str, Key]) -> None:
|
||||
+ self.keys = keys
|
||||
+
|
||||
+ async def get_responses(
|
||||
+ self, qctx: QueryContext
|
||||
+ ) -> AsyncGenerator[DnsResponseSend, None]:
|
||||
+ qctx.prepare_new_response(with_zone_data=False)
|
||||
+ qctx.response.flags |= dns.flags.AA
|
||||
+ qctx.response.set_rcode(dns.rcode.NOERROR)
|
||||
+ self.respond(qctx)
|
||||
+ yield DnsResponseSend(qctx.response, authoritative=True)
|
||||
+
|
||||
+ def respond(self, qctx: QueryContext) -> None:
|
||||
+ raise NotImplementedError
|
||||
+
|
||||
+
|
||||
+def child_nsec3_rrset() -> dns.rrset.RRset:
|
||||
+ rdata = dns.rdata.from_text(
|
||||
+ dns.rdataclass.IN,
|
||||
+ dns.rdatatype.NSEC3,
|
||||
+ f"1 0 0 - {APEX_HASH} NS SOA RRSIG DNSKEY NSEC3PARAM",
|
||||
+ )
|
||||
+ return dns.rrset.from_rdata(name(f"{APEX_HASH}.{TLD}"), TTL, rdata)
|
||||
+
|
||||
+
|
||||
+def forged_nxdomain(response: dns.message.Message, keys: dict[str, Key]) -> None:
|
||||
+ response.set_rcode(dns.rcode.NXDOMAIN)
|
||||
+
|
||||
+ add_signed(response.authority, soa_rrset(TLD), keys[TLD])
|
||||
+
|
||||
+ # The owner name derives zone "tld.test.", but the RRSIG signer is the
|
||||
+ # malicious child zone "1b40241kforiog780n4ikscrlvetpctq.tld.test.".
|
||||
+ add_signed(response.authority, child_nsec3_rrset(), keys[ATTACKER])
|
||||
+
|
||||
+
|
||||
+class VictimForgedNxdomainHandler(SignedResponseHandler):
|
||||
+ """
|
||||
+ This serves the forged response for the victim's domain.
|
||||
+ """
|
||||
+
|
||||
+ def match(self, qctx: QueryContext) -> bool:
|
||||
+ return qctx.qname == name(VICTIM) and qctx.qtype == dns.rdatatype.A
|
||||
+
|
||||
+ def respond(self, qctx: QueryContext) -> None:
|
||||
+ forged_nxdomain(qctx.response, self.keys)
|
||||
+
|
||||
+
|
||||
+class ChildDsHandler(SignedResponseHandler):
|
||||
+ """
|
||||
+ This will spoof the response for the malicious zone when qtype is DS.
|
||||
+ It is actually a validly signed DS response.
|
||||
+ """
|
||||
+
|
||||
+ def match(self, qctx: QueryContext) -> bool:
|
||||
+ return qctx.qname == name(ATTACKER) and qctx.qtype == dns.rdatatype.DS
|
||||
+
|
||||
+ def respond(self, qctx: QueryContext) -> None:
|
||||
+ response = qctx.response
|
||||
+ zone = ATTACKER
|
||||
+ child_key = self.keys[ATTACKER]
|
||||
+ parent_key = self.keys[TLD]
|
||||
+
|
||||
+ add_signed(response.answer, ds_rrset(zone, child_key), parent_key)
|
||||
+
|
||||
+
|
||||
+class AttackerZoneHandler(SignedResponseHandler):
|
||||
+ """
|
||||
+ Acts as the malicious authoritative name server. The zone being served
|
||||
+ is the hashed label of the parent zone (tld.test). This will respond
|
||||
+ for all queries qtype SOA, DNSKEY, NS at the apex. Any names below
|
||||
+ the apex are answered with an NXDOMAIN with no NSEC or NSEC3 present.
|
||||
+ """
|
||||
+
|
||||
+ def match(self, qctx: QueryContext) -> bool:
|
||||
+ return qctx.qname.is_subdomain(name(ATTACKER))
|
||||
+
|
||||
+ def respond(self, qctx: QueryContext) -> None:
|
||||
+ if qctx.qname == name(ATTACKER):
|
||||
+ if qctx.qtype == dns.rdatatype.DNSKEY:
|
||||
+ answer_dnskey(qctx.response, ATTACKER, self.keys[ATTACKER])
|
||||
+ elif qctx.qtype == dns.rdatatype.SOA:
|
||||
+ answer_soa(qctx.response, ATTACKER, self.keys[ATTACKER])
|
||||
+ else:
|
||||
+ answer_ns(
|
||||
+ qctx.response, ATTACKER, f"ns.{ATTACKER}", self.keys[ATTACKER]
|
||||
+ )
|
||||
+ qctx.response.additional.append(glue_rrset(f"ns.{ATTACKER}", AUTH_IP))
|
||||
+ return
|
||||
+
|
||||
+ qctx.response.set_rcode(dns.rcode.NXDOMAIN)
|
||||
+ add_signed(qctx.response.authority, soa_rrset(ATTACKER), self.keys[ATTACKER])
|
||||
+
|
||||
+
|
||||
+class TldZoneHandler(SignedResponseHandler):
|
||||
+ """
|
||||
+ Acts as the TLD who is being used in the attack, but is not a standard
|
||||
+ name server. It only responds with validly signed records for DNSKEY, SOA
|
||||
+ and NS on the apex. Any names below the apex are answered with an NXDOMAIN
|
||||
+ with no NSEC or NSEC3 present.
|
||||
+
|
||||
+ If we turn this into a regular name server than the attack won't work.
|
||||
+ The attack assumes that the adversary can inject these responses on-path.
|
||||
+ """
|
||||
+
|
||||
+ def match(self, qctx: QueryContext) -> bool:
|
||||
+ return qctx.qname.is_subdomain(name(TLD))
|
||||
+
|
||||
+ def respond(self, qctx: QueryContext) -> None:
|
||||
+ if qctx.qname == name(TLD):
|
||||
+ if qctx.qtype == dns.rdatatype.DNSKEY:
|
||||
+ answer_dnskey(qctx.response, TLD, self.keys[TLD])
|
||||
+ elif qctx.qtype == dns.rdatatype.SOA:
|
||||
+ answer_soa(qctx.response, TLD, self.keys[TLD])
|
||||
+ else:
|
||||
+ answer_ns(qctx.response, TLD, "ns.tld.test.", self.keys[TLD])
|
||||
+ qctx.response.additional.append(glue_rrset("ns.tld.test.", AUTH_IP))
|
||||
+ return
|
||||
+
|
||||
+ qctx.response.set_rcode(dns.rcode.NXDOMAIN)
|
||||
+ add_signed(qctx.response.authority, soa_rrset(TLD), self.keys[TLD])
|
||||
+
|
||||
+
|
||||
+def main() -> None:
|
||||
+ keys = load_keys()
|
||||
+ server = AsyncDnsServer(default_aa=True)
|
||||
+ server.install_response_handlers(
|
||||
+ VictimForgedNxdomainHandler(keys),
|
||||
+ ChildDsHandler(keys),
|
||||
+ AttackerZoneHandler(keys),
|
||||
+ TldZoneHandler(keys),
|
||||
+ )
|
||||
+ server.run()
|
||||
+
|
||||
+
|
||||
+if __name__ == "__main__":
|
||||
+ main()
|
||||
diff --git a/bin/tests/system/nsec3_impersonation/ns2/named.conf.j2 b/bin/tests/system/nsec3_impersonation/ns2/named.conf.j2
|
||||
new file mode 100644
|
||||
index 0000000000..2c9b0bba9e
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/nsec3_impersonation/ns2/named.conf.j2
|
||||
@@ -0,0 +1,33 @@
|
||||
+// validating resolver
|
||||
+
|
||||
+options {
|
||||
+ query-source address 10.53.0.2;
|
||||
+ notify-source 10.53.0.2;
|
||||
+ transfer-source 10.53.0.2;
|
||||
+ port @PORT@;
|
||||
+ pid-file "named.pid";
|
||||
+ listen-on { 10.53.0.2; };
|
||||
+ listen-on-v6 { none; };
|
||||
+ recursion yes;
|
||||
+ dnssec-validation yes;
|
||||
+};
|
||||
+
|
||||
+controls {
|
||||
+ inet 10.53.0.2 port @CONTROLPORT@ allow { any; } keys { rndc_key; };
|
||||
+};
|
||||
+
|
||||
+include "../../_common/rndc.key";
|
||||
+
|
||||
+zone "." {
|
||||
+ type hint;
|
||||
+ file "../../_common/root.hint";
|
||||
+};
|
||||
+
|
||||
+zone "tld.test" {
|
||||
+ type static-stub;
|
||||
+ server-addresses { 10.53.0.1; };
|
||||
+};
|
||||
+
|
||||
+trust-anchors {
|
||||
+ tld.test. static-key 257 3 13 "@TLD_DNSKEY@";
|
||||
+};
|
||||
diff --git a/bin/tests/system/nsec3_impersonation/tests_nsec3_impersonation.py b/bin/tests/system/nsec3_impersonation/tests_nsec3_impersonation.py
|
||||
new file mode 100644
|
||||
index 0000000000..bd9bd275b6
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/nsec3_impersonation/tests_nsec3_impersonation.py
|
||||
@@ -0,0 +1,152 @@
|
||||
+#!/usr/bin/python3
|
||||
+
|
||||
+# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
+#
|
||||
+# SPDX-License-Identifier: MPL-2.0
|
||||
+#
|
||||
+# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
+# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
+# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
+#
|
||||
+# See the COPYRIGHT file distributed with this work for additional
|
||||
+# information regarding copyright ownership.
|
||||
+
|
||||
+from pathlib import Path
|
||||
+
|
||||
+import json
|
||||
+
|
||||
+from cryptography.hazmat.primitives import serialization
|
||||
+from cryptography.hazmat.primitives.asymmetric import ec
|
||||
+
|
||||
+import dns.dnssec
|
||||
+import dns.flags
|
||||
+import dns.name
|
||||
+import dns.rdataclass
|
||||
+import dns.rdatatype
|
||||
+import pytest
|
||||
+
|
||||
+import isctest
|
||||
+import isctest.mark
|
||||
+
|
||||
+APEX_HASH = "1B40241KFORIOG780N4IKSCRLVETPCTQ"
|
||||
+ATTACKER = f"{APEX_HASH.lower()}.tld.test."
|
||||
+VICTIM = "victim.tld.test."
|
||||
+AUTH = "10.53.0.1"
|
||||
+RESOLVER = "10.53.0.2"
|
||||
+
|
||||
+pytestmark = [
|
||||
+ isctest.mark.with_ecdsa_deterministic,
|
||||
+ pytest.mark.extra_artifacts(
|
||||
+ [
|
||||
+ "ans*/ans.run",
|
||||
+ "ans*/keys.json",
|
||||
+ ]
|
||||
+ ),
|
||||
+]
|
||||
+
|
||||
+
|
||||
+def _make_key(zone):
|
||||
+ private_key = ec.generate_private_key(ec.SECP256R1())
|
||||
+ dnskey = dns.dnssec.make_dnskey(
|
||||
+ private_key.public_key(),
|
||||
+ algorithm="ECDSAP256SHA256",
|
||||
+ flags=257,
|
||||
+ )
|
||||
+ ds = dns.dnssec.make_ds(dns.name.from_text(zone), dnskey, "SHA256")
|
||||
+ private_pem = private_key.private_bytes(
|
||||
+ encoding=serialization.Encoding.PEM,
|
||||
+ format=serialization.PrivateFormat.PKCS8,
|
||||
+ encryption_algorithm=serialization.NoEncryption(),
|
||||
+ ).decode("ascii")
|
||||
+ return {
|
||||
+ "private_pem": private_pem,
|
||||
+ "dnskey": dnskey.to_text(),
|
||||
+ "ds": ds.to_text(),
|
||||
+ }
|
||||
+
|
||||
+
|
||||
+def bootstrap():
|
||||
+ zones = ["tld.test.", ATTACKER]
|
||||
+ keys = {zone: _make_key(zone) for zone in zones}
|
||||
+
|
||||
+ Path("ans1/keys.json").write_text(json.dumps(keys, indent=2), encoding="ascii")
|
||||
+
|
||||
+ tld_dnskey = "".join(keys["tld.test."]["dnskey"].split()[3:])
|
||||
+ return {"TLD_DNSKEY": tld_dnskey}
|
||||
+
|
||||
+
|
||||
+def check_dnskey_response(zone):
|
||||
+ query = isctest.query.create(zone, "DNSKEY")
|
||||
+ response = isctest.query.tcp(query, AUTH)
|
||||
+
|
||||
+ isctest.check.noerror(response)
|
||||
+ assert response.flags & dns.flags.AA
|
||||
+ assert (
|
||||
+ response.get_rrset(
|
||||
+ response.answer,
|
||||
+ dns.name.from_text(zone),
|
||||
+ dns.rdataclass.IN,
|
||||
+ dns.rdatatype.DNSKEY,
|
||||
+ )
|
||||
+ is not None
|
||||
+ ), response
|
||||
+
|
||||
+
|
||||
+def check_ds_response(zone):
|
||||
+ query = isctest.query.create(zone, "DS")
|
||||
+ response = isctest.query.tcp(query, AUTH)
|
||||
+
|
||||
+ isctest.check.noerror(response)
|
||||
+ assert response.flags & dns.flags.AA
|
||||
+ assert (
|
||||
+ response.get_rrset(
|
||||
+ response.answer,
|
||||
+ dns.name.from_text(zone),
|
||||
+ dns.rdataclass.IN,
|
||||
+ dns.rdatatype.DS,
|
||||
+ )
|
||||
+ is not None
|
||||
+ ), response
|
||||
+
|
||||
+
|
||||
+def test_attack_responses():
|
||||
+ check_dnskey_response("tld.test.")
|
||||
+ check_dnskey_response(ATTACKER)
|
||||
+ check_ds_response(ATTACKER)
|
||||
+
|
||||
+ query = isctest.query.create(VICTIM, "A")
|
||||
+ response = isctest.query.tcp(query, AUTH)
|
||||
+
|
||||
+ isctest.check.nxdomain(response)
|
||||
+ assert response.flags & dns.flags.AA
|
||||
+
|
||||
+ nsec3_owner = dns.name.from_text(f"{APEX_HASH}.tld.test.")
|
||||
+ nsec3 = response.get_rrset(
|
||||
+ response.authority,
|
||||
+ nsec3_owner,
|
||||
+ dns.rdataclass.IN,
|
||||
+ dns.rdatatype.NSEC3,
|
||||
+ )
|
||||
+ rrsig = response.get_rrset(
|
||||
+ response.authority,
|
||||
+ nsec3_owner,
|
||||
+ dns.rdataclass.IN,
|
||||
+ dns.rdatatype.RRSIG,
|
||||
+ covers=dns.rdatatype.NSEC3,
|
||||
+ )
|
||||
+
|
||||
+ assert nsec3 is not None, response
|
||||
+ assert rrsig is not None, response
|
||||
+ assert rrsig[0].signer == dns.name.from_text(ATTACKER)
|
||||
+
|
||||
+
|
||||
+def test_nsec3_impersonation():
|
||||
+ """
|
||||
+ Reproducer for #5874:
|
||||
+ F-006 DNSSEC Validation Bypass NSEC3 Apex Hash Label Parent Impersonation
|
||||
+ """
|
||||
+ query = isctest.query.create(VICTIM, "A")
|
||||
+ response = isctest.query.tcp(query, RESOLVER)
|
||||
+
|
||||
+ isctest.check.noadflag(response)
|
||||
+ isctest.check.servfail(response)
|
||||
diff --git a/bin/tests/system/qmin/ans2/ans.py b/bin/tests/system/qmin/ans2/ans.py
|
||||
index d372c2003b..9343fbc8ef 100755
|
||||
--- a/bin/tests/system/qmin/ans2/ans.py
|
||||
+++ b/bin/tests/system/qmin/ans2/ans.py
|
||||
@@ -15,11 +15,12 @@ import sys
|
||||
import signal
|
||||
import socket
|
||||
import select
|
||||
-from datetime import datetime, timedelta
|
||||
import time
|
||||
-import functools
|
||||
|
||||
-import dns, dns.message, dns.query, dns.flags
|
||||
+import dns
|
||||
+import dns.message
|
||||
+import dns.query
|
||||
+import dns.flags
|
||||
from dns.rdatatype import *
|
||||
from dns.rdataclass import *
|
||||
from dns.rcode import *
|
||||
@@ -432,9 +433,9 @@ else:
|
||||
while running:
|
||||
try:
|
||||
inputready, outputready, exceptready = select.select(input, [], [])
|
||||
- except select.error as e:
|
||||
+ except select.error:
|
||||
break
|
||||
- except socket.error as e:
|
||||
+ except socket.error:
|
||||
break
|
||||
except KeyboardInterrupt:
|
||||
break
|
||||
diff --git a/bin/tests/system/qmin/ans3/ans.py b/bin/tests/system/qmin/ans3/ans.py
|
||||
index b5ae73c3fa..4e7250790f 100755
|
||||
--- a/bin/tests/system/qmin/ans3/ans.py
|
||||
+++ b/bin/tests/system/qmin/ans3/ans.py
|
||||
@@ -15,11 +15,12 @@ import sys
|
||||
import signal
|
||||
import socket
|
||||
import select
|
||||
-from datetime import datetime, timedelta
|
||||
import time
|
||||
-import functools
|
||||
|
||||
-import dns, dns.message, dns.query, dns.flags
|
||||
+import dns
|
||||
+import dns.message
|
||||
+import dns.query
|
||||
+import dns.flags
|
||||
from dns.rdatatype import *
|
||||
from dns.rdataclass import *
|
||||
from dns.rcode import *
|
||||
@@ -261,9 +262,9 @@ else:
|
||||
while running:
|
||||
try:
|
||||
inputready, outputready, exceptready = select.select(input, [], [])
|
||||
- except select.error as e:
|
||||
+ except select.error:
|
||||
break
|
||||
- except socket.error as e:
|
||||
+ except socket.error:
|
||||
break
|
||||
except KeyboardInterrupt:
|
||||
break
|
||||
diff --git a/bin/tests/system/qmin/ans4/ans.py b/bin/tests/system/qmin/ans4/ans.py
|
||||
index 517217aec1..2d5556daff 100755
|
||||
--- a/bin/tests/system/qmin/ans4/ans.py
|
||||
+++ b/bin/tests/system/qmin/ans4/ans.py
|
||||
@@ -15,11 +15,12 @@ import sys
|
||||
import signal
|
||||
import socket
|
||||
import select
|
||||
-from datetime import datetime, timedelta
|
||||
import time
|
||||
-import functools
|
||||
|
||||
-import dns, dns.message, dns.query, dns.flags
|
||||
+import dns
|
||||
+import dns.message
|
||||
+import dns.query
|
||||
+import dns.flags
|
||||
from dns.rdatatype import *
|
||||
from dns.rdataclass import *
|
||||
from dns.rcode import *
|
||||
@@ -320,9 +321,9 @@ else:
|
||||
while running:
|
||||
try:
|
||||
inputready, outputready, exceptready = select.select(input, [], [])
|
||||
- except select.error as e:
|
||||
+ except select.error:
|
||||
break
|
||||
- except socket.error as e:
|
||||
+ except socket.error:
|
||||
break
|
||||
except KeyboardInterrupt:
|
||||
break
|
||||
diff --git a/bin/tests/system/resolver/ans10/ans.py b/bin/tests/system/resolver/ans10/ans.py
|
||||
index 6e95dbbfc6..d637c63e5a 100644
|
||||
--- a/bin/tests/system/resolver/ans10/ans.py
|
||||
+++ b/bin/tests/system/resolver/ans10/ans.py
|
||||
@@ -15,11 +15,11 @@ import sys
|
||||
import signal
|
||||
import socket
|
||||
import select
|
||||
-from datetime import datetime, timedelta
|
||||
-import time
|
||||
-import functools
|
||||
|
||||
-import dns, dns.message, dns.query, dns.flags
|
||||
+import dns
|
||||
+import dns.message
|
||||
+import dns.query
|
||||
+import dns.flags
|
||||
from dns.rdatatype import *
|
||||
from dns.rdataclass import *
|
||||
from dns.rcode import *
|
||||
@@ -128,9 +128,9 @@ else:
|
||||
while running:
|
||||
try:
|
||||
inputready, outputready, exceptready = select.select(input, [], [])
|
||||
- except select.error as e:
|
||||
+ except select.error:
|
||||
break
|
||||
- except socket.error as e:
|
||||
+ except socket.error:
|
||||
break
|
||||
except KeyboardInterrupt:
|
||||
break
|
||||
--
|
||||
2.55.0
|
||||
|
||||
67
bind-9.18-CVE-2026-10723.patch
Normal file
67
bind-9.18-CVE-2026-10723.patch
Normal file
|
|
@ -0,0 +1,67 @@
|
|||
From 608026780a43abe5b23a9af3af21808369032158 Mon Sep 17 00:00:00 2001
|
||||
From: Evan Hunt <each@isc.org>
|
||||
Date: Thu, 21 May 2026 14:41:55 -0700
|
||||
Subject: [PATCH] Check NSEC3 signer matches the owning zone
|
||||
|
||||
When validating NSEC3 records, reject any signature whose signer field
|
||||
does not match the zone owning the NSEC3.
|
||||
|
||||
This ensures that a child zone cannot impersonate its parent and forge
|
||||
NXDOMAIN responses for sibling domains.
|
||||
|
||||
Fixes: isc-projects/bind9#5874
|
||||
(cherry picked from commit 6e5066bb1f0f12d090e8707adb7d6ccf74f8012b)
|
||||
(cherry picked from commit c9cb6a5e24e43489cf3fd4d4cc2193b6a74499cb)
|
||||
---
|
||||
lib/dns/dnssec.c | 19 +++++++++++++++++--
|
||||
lib/isc/result.c | 2 +-
|
||||
2 files changed, 18 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/lib/dns/dnssec.c b/lib/dns/dnssec.c
|
||||
index b12529b5d5..9b9b1f2bb2 100644
|
||||
--- a/lib/dns/dnssec.c
|
||||
+++ b/lib/dns/dnssec.c
|
||||
@@ -424,10 +424,25 @@ dns_dnssec_verify(const dns_name_t *name, dns_rdataset_t *set, dst_key_t *key,
|
||||
}
|
||||
|
||||
/*
|
||||
- * NS, SOA and DNSKEY records are signed by their owner.
|
||||
- * DS records are signed by the parent.
|
||||
+ * NS, SOA and DNSKEY records are signed by their owners.
|
||||
+ * NSEC3 records are signed by the apex, exactly one level up
|
||||
+ * from their owner names.
|
||||
+ * DS records are signed by the parent zone.
|
||||
*/
|
||||
switch (set->type) {
|
||||
+ case dns_rdatatype_nsec3: {
|
||||
+ dns_name_t apex = DNS_NAME_INITEMPTY;
|
||||
+ labels = dns_name_countlabels(name);
|
||||
+ if (labels <= 1) {
|
||||
+ inc_stat(dns_dnssecstats_fail);
|
||||
+ return DNS_R_INVALIDNSEC3;
|
||||
+ }
|
||||
+ dns_name_split(name, labels - 1, NULL, &apex);
|
||||
+ if (!dns_name_equal(&apex, &sig.signer)) {
|
||||
+ inc_stat(dns_dnssecstats_fail);
|
||||
+ return DNS_R_SIGINVALID;
|
||||
+ }
|
||||
+ } break;
|
||||
case dns_rdatatype_ns:
|
||||
case dns_rdatatype_soa:
|
||||
case dns_rdatatype_dnskey:
|
||||
diff --git a/lib/isc/result.c b/lib/isc/result.c
|
||||
index 83e8cfeed7..b76c3d1f7b 100644
|
||||
--- a/lib/isc/result.c
|
||||
+++ b/lib/isc/result.c
|
||||
@@ -198,7 +198,7 @@ static const char *description[ISC_R_NRESULTS] = {
|
||||
[DNS_R_COVERINGNSEC] = "covering NSEC record returned",
|
||||
[DNS_R_MXISADDRESS] = "MX is an address",
|
||||
[DNS_R_DUPLICATE] = "duplicate query",
|
||||
- [DNS_R_INVALIDNSEC3] = "invalid NSEC3 owner name (wildcard)",
|
||||
+ [DNS_R_INVALIDNSEC3] = "invalid NSEC3 owner name",
|
||||
[DNS_R_NOTPRIMARY] = "not primary",
|
||||
[DNS_R_BROKENCHAIN] = "broken trust chain",
|
||||
[DNS_R_EXPIRED] = "expired",
|
||||
--
|
||||
2.55.0
|
||||
|
||||
320
bind-9.18-CVE-2026-10822-test.patch
Normal file
320
bind-9.18-CVE-2026-10822-test.patch
Normal file
|
|
@ -0,0 +1,320 @@
|
|||
From a4ce4c0ce5b8d7630417730dc1b98bf554e0801f Mon Sep 17 00:00:00 2001
|
||||
From: Mark Andrews <marka@isc.org>
|
||||
Date: Tue, 19 May 2026 10:44:04 +1000
|
||||
Subject: [PATCH] Check that dns_name_fromwire honours the active region
|
||||
|
||||
When reading DNS records from the wire the active region of the
|
||||
source buffer is set to the end of the current record. dns_name_fromwire
|
||||
should fail if it attempts to read past this setting.
|
||||
|
||||
(cherry picked from commit 3ed821d68b15fe4e6288e3054397d6bce7e65968)
|
||||
(cherry picked from commit d413c9ac2e29a728531354a69c8c8234c01b7d1e)
|
||||
|
||||
Check that a short PRIVATEDNS record is rejected
|
||||
|
||||
A bug in dns_name_fromwire meant that short PRIVATEDNS key
|
||||
records where being accepted. Test that this is no longer
|
||||
the case.
|
||||
|
||||
(cherry picked from commit f48d48027384d8c2210b5ce9e3eac7af101ead3d)
|
||||
(cherry picked from commit 19ac8b8e46aeb0a15e217bc7bdf485b31b87d9b4)
|
||||
|
||||
POC for PRIVATEDNS DNSKEY overrun not being detected
|
||||
|
||||
Construct a DNS message where a PRIVATEDNS DNSKEY identifier
|
||||
overruns the record boundary by 3 byte so that the label ends
|
||||
at the end of the compression pointer for the next record. The
|
||||
next type is less than 256 so the next octet is 00 terminating
|
||||
the identifier name. The transfered zone is then written to
|
||||
disk using master-format text triggering the assertion when the
|
||||
truncated identier is discovered.
|
||||
|
||||
Note this test will produce a false result in versions of
|
||||
BIND that do not check the PRIVATEDNS identifier as it looks
|
||||
for the error message when the transfer is aborted.
|
||||
|
||||
(cherry picked from commit 9ce3bce8bc8b4e9c6a9b1e84b5849c33eb27830e)
|
||||
(cherry picked from commit 8e066d3fc369e3346f22bb5cfb67a7ab08a74034)
|
||||
---
|
||||
bin/tests/system/xfer/ans9/ans.py | 142 ++++++++++++++++++++++++
|
||||
bin/tests/system/xfer/ns6/named.conf.in | 9 ++
|
||||
bin/tests/system/xfer/tests.sh | 16 +++
|
||||
tests/dns/name_test.c | 30 +++++
|
||||
tests/dns/rdata_test.c | 21 ++++
|
||||
5 files changed, 218 insertions(+)
|
||||
create mode 100644 bin/tests/system/xfer/ans9/ans.py
|
||||
|
||||
diff --git a/bin/tests/system/xfer/ans9/ans.py b/bin/tests/system/xfer/ans9/ans.py
|
||||
new file mode 100644
|
||||
index 0000000000..a9e73953ee
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/xfer/ans9/ans.py
|
||||
@@ -0,0 +1,142 @@
|
||||
+"""
|
||||
+Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
+
|
||||
+SPDX-License-Identifier: MPL-2.0
|
||||
+
|
||||
+This Source Code Form is subject to the terms of the Mozilla Public
|
||||
+License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
+file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
+
|
||||
+See the COPYRIGHT file distributed with this work for additional
|
||||
+information regarding copyright ownership.
|
||||
+"""
|
||||
+
|
||||
+from collections.abc import AsyncGenerator
|
||||
+
|
||||
+import dns.name
|
||||
+import dns.rcode
|
||||
+import dns.rdatatype
|
||||
+import dns.rrset
|
||||
+
|
||||
+from isctest.asyncserver import (
|
||||
+ ControllableAsyncDnsServer,
|
||||
+ DnsResponseSend,
|
||||
+ DomainHandler,
|
||||
+ QueryContext,
|
||||
+ ResponseAction,
|
||||
+ ToggleResponsesCommand,
|
||||
+)
|
||||
+
|
||||
+
|
||||
+class AXFRServer(DomainHandler):
|
||||
+ """
|
||||
+ Yield SOA and AXFR responses. Every new AXFR response increments the SOA
|
||||
+ version.
|
||||
+ """
|
||||
+
|
||||
+ domains = ["xfr-and-reconfig", "private-dns-overrun"]
|
||||
+
|
||||
+ def __init__(self) -> None:
|
||||
+ super().__init__()
|
||||
+ self.soa_version = 0
|
||||
+
|
||||
+ async def get_responses(
|
||||
+ self, qctx: QueryContext
|
||||
+ ) -> AsyncGenerator[ResponseAction, None]:
|
||||
+ # This is oversimplified because I am lazy - we are appending the SOA
|
||||
+ # RRset to the ANSWER section for _every_ QTYPE. named is only
|
||||
+ # expected to send a SOA query over UDP and then an AXFR query over
|
||||
+ # TCP. Responses to both of those start with a SOA RRset in the ANSWER
|
||||
+ # section :-)
|
||||
+ soa_message = qctx.response
|
||||
+ soa_rrset = dns.rrset.from_text(
|
||||
+ qctx.qname,
|
||||
+ 300,
|
||||
+ qctx.qclass,
|
||||
+ dns.rdatatype.SOA,
|
||||
+ f". . {self.soa_version} 0 0 0 0",
|
||||
+ )
|
||||
+ soa_message.answer.append(soa_rrset)
|
||||
+
|
||||
+ yield DnsResponseSend(soa_message)
|
||||
+
|
||||
+ if qctx.qtype == dns.rdatatype.SOA:
|
||||
+ # If QTYPE=SOA, the SOA record is the complete response.
|
||||
+ return
|
||||
+
|
||||
+ if qctx.qtype != dns.rdatatype.AXFR:
|
||||
+ # If QTYPE=AXFR, we will continue cramming RRsets into the ANSWER
|
||||
+ # section of a subsequent DNS message below.
|
||||
+ #
|
||||
+ # If QTYPE was not SOA or AXFR, abort. Yeah, we just sent a broken
|
||||
+ # response by yielding DnsResponseSend() with a SOA RRset in the
|
||||
+ # ANSWER section above. We will have to carry that burden for the
|
||||
+ # rest of our lives.
|
||||
+ return
|
||||
+
|
||||
+ # Send just the obligatory NS RRset at zone apex in the next message.
|
||||
+ # This is stupidly inefficient, but makes looping below simpler as we
|
||||
+ # will already have been done with the mandatory stuff by then.
|
||||
+ ns_message = qctx.prepare_new_response()
|
||||
+ ns_rrset = dns.rrset.from_text(
|
||||
+ qctx.qname, 300, qctx.qclass, dns.rdatatype.NS, "."
|
||||
+ )
|
||||
+ ns_message.answer.append(ns_rrset)
|
||||
+
|
||||
+ yield DnsResponseSend(ns_message)
|
||||
+
|
||||
+ # Generate the AXFR with a txt rrset.
|
||||
+ txt_message = qctx.prepare_new_response()
|
||||
+ txt_rrset = dns.rrset.from_text(
|
||||
+ qctx.qname,
|
||||
+ 300,
|
||||
+ qctx.qclass,
|
||||
+ dns.rdatatype.TXT,
|
||||
+ "foo bar",
|
||||
+ )
|
||||
+ txt_message.answer.append(txt_rrset)
|
||||
+
|
||||
+ yield DnsResponseSend(txt_message)
|
||||
+
|
||||
+ if qctx.qname == dns.name.from_text("private-dns-overrun"):
|
||||
+ # A message where the malformed DNSKEY algorithm identifier
|
||||
+ # finishes on a 00 byte in the next record. Assumes the
|
||||
+ # next record starts with a compression pointer which is
|
||||
+ # followed by the type which starts with 00.
|
||||
+
|
||||
+ # Generate malformed PRIVATE DNS DNSKEY
|
||||
+ dnskey_message = qctx.prepare_new_response()
|
||||
+ dnskey_rrset = dns.rrset.from_text(
|
||||
+ qctx.qname,
|
||||
+ 300,
|
||||
+ qctx.qclass,
|
||||
+ dns.rdatatype.DNSKEY,
|
||||
+ "\\# 12 00 00 00 fd 09 00 00 00 00 00 00 00",
|
||||
+ )
|
||||
+ dnskey_message.answer.append(dnskey_rrset)
|
||||
+ # Generate well formed PRIVATE DNS DNSKEY
|
||||
+ dnskey_rrset = dns.rrset.from_text(
|
||||
+ qctx.qname,
|
||||
+ 300,
|
||||
+ qctx.qclass,
|
||||
+ dns.rdatatype.DNSKEY,
|
||||
+ "\\# 12 00 00 00 fd 06 00 00 00 00 00 00 00",
|
||||
+ )
|
||||
+ dnskey_message.answer.append(dnskey_rrset)
|
||||
+
|
||||
+ yield DnsResponseSend(dnskey_message)
|
||||
+
|
||||
+ # Finish the AXFR transaction by sending the second SOA RRset.
|
||||
+ yield DnsResponseSend(soa_message)
|
||||
+
|
||||
+ # This makes sure that the next SOA request causes a new zone transfer
|
||||
+ self.soa_version += 1
|
||||
+
|
||||
+
|
||||
+if __name__ == "__main__":
|
||||
+ server = ControllableAsyncDnsServer(
|
||||
+ default_aa=True, default_rcode=dns.rcode.NOERROR
|
||||
+ )
|
||||
+ server.install_control_command(ToggleResponsesCommand())
|
||||
+ server.install_response_handler(AXFRServer())
|
||||
+ server.run()
|
||||
diff --git a/bin/tests/system/xfer/ns6/named.conf.in b/bin/tests/system/xfer/ns6/named.conf.in
|
||||
index 142383c89a..63809448f0 100644
|
||||
--- a/bin/tests/system/xfer/ns6/named.conf.in
|
||||
+++ b/bin/tests/system/xfer/ns6/named.conf.in
|
||||
@@ -83,3 +83,12 @@ zone "ixfr-too-big" {
|
||||
primaries { 10.53.0.1; };
|
||||
file "ixfr-too-big.bk";
|
||||
};
|
||||
+
|
||||
+# GL#6004
|
||||
+zone "private-dns-overrun" {
|
||||
+ type secondary;
|
||||
+ primaries { 10.53.0.9; };
|
||||
+ file "private-dns-overrun.bk";
|
||||
+ masterfile-format text; # force bug to be exercised
|
||||
+ request-ixfr no; # ans9 supports only axfr
|
||||
+};
|
||||
diff --git a/bin/tests/system/xfer/tests.sh b/bin/tests/system/xfer/tests.sh
|
||||
index a2c0adbc28..e08be175b7 100755
|
||||
--- a/bin/tests/system/xfer/tests.sh
|
||||
+++ b/bin/tests/system/xfer/tests.sh
|
||||
@@ -622,5 +622,21 @@ if [ $tmp -eq 0 ]; then
|
||||
fi
|
||||
status=$((status + tmp))
|
||||
|
||||
+# def test_malformed_private_dns_identifier_overrun(ns6):
|
||||
+# isctest.log.info(
|
||||
+# "Check that a malformed PRIVATEDNS DNSKEY which overruns the record is rejected"
|
||||
+# )
|
||||
+# with ns6.watch_log_from_start(timeout=60) as watcher_transfer_completed:
|
||||
+# watcher_transfer_completed.wait_for_line(
|
||||
+# "zone private-dns-overrun/IN: zone transfer finished: unexpected end of input"
|
||||
+# )
|
||||
+n=$((n + 1))
|
||||
+echo_i "Check that a malformed PRIVATEDNS DNSKEY which overruns the record is rejected ($n)"
|
||||
+tmp=0
|
||||
+nextpartreset ns6/named.run
|
||||
+retry 60 wait_for_message "zone private-dns-overrun/IN: zone transfer finished: unexpected end of input" || tmp=1
|
||||
+if test $tmp != 0; then echo_i "failed"; fi
|
||||
+status=$((status + tmp))
|
||||
+
|
||||
echo_i "exit status: $status"
|
||||
[ $status -eq 0 ] || exit 1
|
||||
diff --git a/tests/dns/name_test.c b/tests/dns/name_test.c
|
||||
index fb34dcace1..95f6598eb8 100644
|
||||
--- a/tests/dns/name_test.c
|
||||
+++ b/tests/dns/name_test.c
|
||||
@@ -335,6 +335,35 @@ ISC_RUN_TEST_IMPL(fromregion) {
|
||||
assert_false(dns_name_isabsolute(&name));
|
||||
}
|
||||
|
||||
+ISC_RUN_TEST_IMPL(fromwire) {
|
||||
+ dns_decompress_t dctx;
|
||||
+ dns_fixedname_t fixed;
|
||||
+ dns_name_t *name = dns_fixedname_initname(&fixed);
|
||||
+ isc_buffer_t b;
|
||||
+ unsigned char source[] = { 0x03, 'o', 'n', 'e', 0x00, 0x03,
|
||||
+ 't', 'w', 'o', 0x00, 0x05, 't',
|
||||
+ 'h', 'r', 'e', 'e', 0x00 };
|
||||
+ isc_result_t result;
|
||||
+
|
||||
+ isc_buffer_init(&b, source, sizeof(source));
|
||||
+ isc_buffer_add(&b, sizeof(source));
|
||||
+ isc_buffer_setactive(&b, 10); /* names 'one.' and 'two.' */
|
||||
+
|
||||
+ /*
|
||||
+ * We should only be able to read two names from the buffer
|
||||
+ * as the active region has been set to cover only the first
|
||||
+ * two.
|
||||
+ */
|
||||
+ dns_decompress_init(&dctx, -1, DNS_DECOMPRESS_STRICT);
|
||||
+ dns_decompress_setmethods(&dctx, DNS_COMPRESS_NONE);
|
||||
+ result = dns_name_fromwire(name, &b, &dctx, 0, NULL);
|
||||
+ assert_int_equal(result, ISC_R_SUCCESS);
|
||||
+ result = dns_name_fromwire(name, &b, &dctx, 0, NULL);
|
||||
+ assert_int_equal(result, ISC_R_SUCCESS);
|
||||
+ result = dns_name_fromwire(name, &b, &dctx, 0, NULL);
|
||||
+ assert_int_not_equal(result, ISC_R_SUCCESS);
|
||||
+}
|
||||
+
|
||||
/* is trust-anchor-telemetry test */
|
||||
ISC_RUN_TEST_IMPL(istat) {
|
||||
dns_fixedname_t fixed;
|
||||
@@ -778,6 +807,7 @@ ISC_TEST_LIST_START
|
||||
ISC_TEST_ENTRY(fullcompare)
|
||||
ISC_TEST_ENTRY(compression)
|
||||
ISC_TEST_ENTRY(fromregion)
|
||||
+ISC_TEST_ENTRY(fromwire)
|
||||
ISC_TEST_ENTRY(istat)
|
||||
ISC_TEST_ENTRY(init)
|
||||
ISC_TEST_ENTRY(invalidate)
|
||||
diff --git a/tests/dns/rdata_test.c b/tests/dns/rdata_test.c
|
||||
index 6354819d10..7f0df6e046 100644
|
||||
--- a/tests/dns/rdata_test.c
|
||||
+++ b/tests/dns/rdata_test.c
|
||||
@@ -2199,6 +2199,27 @@ ISC_RUN_TEST_IMPL(key) {
|
||||
|
||||
check_rdata(NULL, wire_ok, NULL, false, dns_rdataclass_in,
|
||||
dns_rdatatype_key, sizeof(dns_rdata_key_t));
|
||||
+
|
||||
+ /*
|
||||
+ * A valid PRIVATEDNS record with an active region shorter than the
|
||||
+ * actual record length. A bug in dns_name_fromwire meant that this
|
||||
+ * was previously accepted.
|
||||
+ */
|
||||
+ dns_decompress_t dctx;
|
||||
+ unsigned char key[] = { 0x00, 0x00, 0x00, 253, 0x07, 'e', 'x',
|
||||
+ 'a', 'm', 'p', 'l', 'e', 0x00 };
|
||||
+ unsigned char buf[sizeof(key)];
|
||||
+ isc_buffer_t source, target;
|
||||
+ isc_result_t result;
|
||||
+
|
||||
+ isc_buffer_init(&source, key, sizeof(key));
|
||||
+ isc_buffer_add(&source, sizeof(key));
|
||||
+ isc_buffer_setactive(&source, sizeof(key) - 1);
|
||||
+ isc_buffer_init(&target, buf, sizeof(buf));
|
||||
+ dns_decompress_init(&dctx, -1, DNS_DECOMPRESS_ANY);
|
||||
+ result = dns_rdata_fromwire(NULL, dns_rdataclass_in, dns_rdatatype_key,
|
||||
+ &source, &dctx, 0, &target);
|
||||
+ assert_int_not_equal(result, ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
/*
|
||||
--
|
||||
2.55.0
|
||||
|
||||
54
bind-9.18-CVE-2026-10822.patch
Normal file
54
bind-9.18-CVE-2026-10822.patch
Normal file
|
|
@ -0,0 +1,54 @@
|
|||
From 7596cbc240b0492461943f7c34d040fb66a7554c Mon Sep 17 00:00:00 2001
|
||||
From: Mark Andrews <marka@isc.org>
|
||||
Date: Tue, 19 May 2026 15:00:17 +1000
|
||||
Subject: [PATCH] Fix the yaml query zone name code in dnstap-read
|
||||
|
||||
When the buffer to read the query zone name was constructed
|
||||
isc_buffer_setactive was not called. This is now needed as
|
||||
dns_name_fromwire is being corrected to check the active region.
|
||||
|
||||
(cherry picked from commit a25522c28c46655a81d2bf1d96374c81d834b157)
|
||||
(cherry picked from commit a5f1a9d0d2ec021618924b14202ac96ead8299c1)
|
||||
|
||||
Fix dns_name_fromwire to honour the active region
|
||||
|
||||
dns_name_fromwire was not honouring the source buffer's active
|
||||
region when reading names from the wire. This allowed malformed
|
||||
records to be accepted when they shouldn't have been. This has
|
||||
been corrected.
|
||||
|
||||
(cherry picked from commit 7c4f07a7ef6b571073327b02209df7f75b9363ff)
|
||||
(cherry picked from commit e73b70a64453e7d97a11cb5f0afe8bb02d34aaf8)
|
||||
---
|
||||
bin/tools/dnstap-read.c | 1 +
|
||||
lib/dns/name.c | 2 +-
|
||||
2 files changed, 2 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/bin/tools/dnstap-read.c b/bin/tools/dnstap-read.c
|
||||
index a1d0243a1a..bb78ae12b1 100644
|
||||
--- a/bin/tools/dnstap-read.c
|
||||
+++ b/bin/tools/dnstap-read.c
|
||||
@@ -298,6 +298,7 @@ print_yaml(dns_dtdata_t *dt) {
|
||||
|
||||
isc_buffer_init(&b, m->query_zone.data, m->query_zone.len);
|
||||
isc_buffer_add(&b, m->query_zone.len);
|
||||
+ isc_buffer_setactive(&b, m->query_zone.len);
|
||||
|
||||
dns_decompress_init(&dctx, -1, DNS_DECOMPRESS_NONE);
|
||||
result = dns_name_fromwire(name, &b, &dctx, 0, NULL);
|
||||
diff --git a/lib/dns/name.c b/lib/dns/name.c
|
||||
index cc0e30e5b5..2ce868a2ba 100644
|
||||
--- a/lib/dns/name.c
|
||||
+++ b/lib/dns/name.c
|
||||
@@ -1833,7 +1833,7 @@ dns_name_fromwire(dns_name_t *const name, isc_buffer_t *const source,
|
||||
* The amount of the source we consumed is set once.
|
||||
*/
|
||||
const uint8_t *const source_buf = isc_buffer_base(source);
|
||||
- const uint8_t *const source_max = isc_buffer_used(source);
|
||||
+ const uint8_t *const source_max = isc_buffer_active(source);
|
||||
const uint8_t *const start = isc_buffer_current(source);
|
||||
const uint8_t *marker = start;
|
||||
const uint8_t *cursor = start;
|
||||
--
|
||||
2.55.0
|
||||
|
||||
69
bind-9.18-CVE-2026-11331-test.patch
Normal file
69
bind-9.18-CVE-2026-11331-test.patch
Normal file
|
|
@ -0,0 +1,69 @@
|
|||
From cde8bb21e09205a7bd1f41fd07ed011fc80d8d71 Mon Sep 17 00:00:00 2001
|
||||
From: Mark Andrews <marka@isc.org>
|
||||
Date: Fri, 10 Apr 2026 10:24:06 +1000
|
||||
Subject: [PATCH] Fix TTL extraction from A/AAAA record
|
||||
|
||||
(cherry picked from commit 89c86e338db2492b92e6618c586f146c6928dc6d)
|
||||
(cherry picked from commit adc8285d23e2eac6ec463f5dbc5a9596fdd36c60)
|
||||
|
||||
Check rpz name too long wildcard CNAME expansion handling
|
||||
|
||||
(cherry picked from commit 9345394e2097031b55b3ef34ceaadf5a7ebbeef2)
|
||||
(cherry picked from commit 095b11f20f911f5b8059bdc349b256d6c64ece30)
|
||||
---
|
||||
bin/tests/system/rpz/ns2/tld2.db | 2 ++
|
||||
bin/tests/system/rpz/ns4/tld4.db | 2 ++
|
||||
bin/tests/system/rpz/tests.sh | 7 +++++--
|
||||
3 files changed, 9 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/bin/tests/system/rpz/ns2/tld2.db b/bin/tests/system/rpz/ns2/tld2.db
|
||||
index c6f2556db5..c091ee27b7 100644
|
||||
--- a/bin/tests/system/rpz/ns2/tld2.db
|
||||
+++ b/bin/tests/system/rpz/ns2/tld2.db
|
||||
@@ -123,3 +123,5 @@ a7-1 A 192.168.7.1
|
||||
|
||||
a7-2 A 192.168.7.2
|
||||
TXT "a7-2 tld2 text"
|
||||
+
|
||||
+*.wild A 192.168.9.1
|
||||
diff --git a/bin/tests/system/rpz/ns4/tld4.db b/bin/tests/system/rpz/ns4/tld4.db
|
||||
index fca419c6dd..8accd76baf 100644
|
||||
--- a/bin/tests/system/rpz/ns4/tld4.db
|
||||
+++ b/bin/tests/system/rpz/ns4/tld4.db
|
||||
@@ -59,6 +59,8 @@ a3-6.tld2 A 56.56.56.56
|
||||
|
||||
a3-7.sub1.tld2 A 57.57.57.57
|
||||
|
||||
+*.wild.sub1.tld2 A 57.57.57.57
|
||||
+
|
||||
a3-8.tld2 A 58.58.58.58
|
||||
|
||||
a3-9.sub9.tld2 A 59.59.59.59
|
||||
diff --git a/bin/tests/system/rpz/tests.sh b/bin/tests/system/rpz/tests.sh
|
||||
index 87e4118ca3..5297437694 100644
|
||||
--- a/bin/tests/system/rpz/tests.sh
|
||||
+++ b/bin/tests/system/rpz/tests.sh
|
||||
@@ -391,7 +391,7 @@ addr() {
|
||||
digcmd $2 >$DIGNM
|
||||
#ckalive "$2" "server crashed by 'dig $2'" || return 1
|
||||
ADDR_ESC=$(echo "$ADDR" | sed -e 's/\./\\./g')
|
||||
- ADDR_TTL=$(sed -n -e "s/^[-.a-z0-9]\{1,\}[ ]*\([0-9]*\) IN AA* ${ADDR_ESC}\$/\1/p" $DIGNM)
|
||||
+ ADDR_TTL=$(sed -n -e "s/^[-.a-z0-9]\{1,\}[ ]*\([0-9]*\)[ ]IN[ ]AA*[ ]${ADDR_ESC}\$/\1/p" $DIGNM)
|
||||
if test -z "$ADDR_TTL"; then
|
||||
setret "'dig $2' wrong; no address $ADDR record in $DIGNM"
|
||||
return 0
|
||||
@@ -516,7 +516,10 @@ nochange TCP a3-9.tld2 # 33 tcp-only
|
||||
here x.servfail <<'EOF' # 34 qname-wait-recurse yes
|
||||
;; status: SERVFAIL, x
|
||||
EOF
|
||||
-addr 35.35.35.35 "x.servfail @$ns5" # 35 qname-wait-recurse no
|
||||
+addr 35.35.35.35 "x.servfail @$ns5" # 35 qname-wait-recurse no
|
||||
+here aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.wild.sub1.tld2 <<'EOF' # 36 wildcard CNAME name to long
|
||||
+ ;; status: YXDOMAIN, x
|
||||
+EOF
|
||||
end_group
|
||||
ckstats $ns3 test1 ns3 22
|
||||
ckstats $ns5 test1 ns5 1
|
||||
--
|
||||
2.55.0
|
||||
|
||||
31
bind-9.18-CVE-2026-11331.patch
Normal file
31
bind-9.18-CVE-2026-11331.patch
Normal file
|
|
@ -0,0 +1,31 @@
|
|||
From 49f4cc4e93f14f1d5b6a472124e6aa457167fede Mon Sep 17 00:00:00 2001
|
||||
From: Mark Andrews <marka@isc.org>
|
||||
Date: Fri, 10 Apr 2026 10:26:14 +1000
|
||||
Subject: [PATCH] Properly handle rpz name to long wildcard expansion
|
||||
|
||||
Previously a self referential CNAME and the original address
|
||||
record were returned. We now return a YXDOMAIN response.
|
||||
|
||||
(cherry picked from commit cfc4c4f69870ce492deaaa429453563d1621ded3)
|
||||
(cherry picked from commit dc328a199f96222e0c30cc20b7b795bfc2c9b2e4)
|
||||
---
|
||||
lib/ns/query.c | 3 ++-
|
||||
1 file changed, 2 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/lib/ns/query.c b/lib/ns/query.c
|
||||
index d3a10be9ba..3bd7daf79c 100644
|
||||
--- a/lib/ns/query.c
|
||||
+++ b/lib/ns/query.c
|
||||
@@ -7591,7 +7591,8 @@ query_rpzcname(query_ctx_t *qctx, dns_name_t *cname) {
|
||||
qctx->fname, NULL);
|
||||
if (result == DNS_R_NAMETOOLONG) {
|
||||
client->message->rcode = dns_rcode_yxdomain;
|
||||
- } else if (result != ISC_R_SUCCESS) {
|
||||
+ }
|
||||
+ if (result != ISC_R_SUCCESS) {
|
||||
return result;
|
||||
}
|
||||
} else {
|
||||
--
|
||||
2.55.0
|
||||
|
||||
280
bind-9.18-CVE-2026-11622.patch
Normal file
280
bind-9.18-CVE-2026-11622.patch
Normal file
|
|
@ -0,0 +1,280 @@
|
|||
From d7e1f4495d6bac8c29b332e04e9b27140339375b Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Ond=C5=99ej=20Sur=C3=BD?= <ondrej@sury.org>
|
||||
Date: Tue, 23 Jun 2026 10:59:38 +0200
|
||||
Subject: [PATCH] Make the dns_slabheaders in the cache reference counted
|
||||
|
||||
Instead of only reference counting the enclosing qpcnode, add the
|
||||
reference counting directly to the slabheaders. The reference is
|
||||
incremented when an rdataset is bound to the header and decremented when
|
||||
the rdataset is disassociated, so a stale slabheader can be removed from
|
||||
the node's down chain as soon as its own reference count reaches zero,
|
||||
instead of waiting for the whole qpcnode to become unreferenced.
|
||||
|
||||
Building on that, clean up the ancient headers eagerly: mark_ancient()
|
||||
is made idempotent, releases the header's own (container) reference and
|
||||
reaps the stale headers from the node's down chain as soon as their
|
||||
references reach zero. A header evicted over the per-name type limit is
|
||||
expired only after the new rdataset has been bound, so the bind's
|
||||
increment always precedes mark_ancient()'s decrement.
|
||||
|
||||
Because a header can now be reclaimed independently of its node, the
|
||||
rdataset iterators must keep the header they are positioned on alive:
|
||||
each iterator takes a reference on its current header and releases it
|
||||
when it advances or is destroyed. Iteration otherwise stays lazy and
|
||||
re-reads the node on every step, so it still observes records added to
|
||||
the node while the iterator is live, as zone signing requires.
|
||||
|
||||
The slab headers are shared with the zone databases, so the matching
|
||||
increment is added to every bind path. The noqname/closest proofs hand
|
||||
out rdatasets backed by bare slabs that have no header, so they are
|
||||
given a separate dns_rdataproof_rdatasetmethods that leaves the
|
||||
reference count untouched.
|
||||
|
||||
(cherry picked from commit 2dabf117e1264fd13fb33096f87e78a039fd1c6c)
|
||||
(cherry picked from commit 231b1ca3edfb26389e1af39181aa6b4413e87ec4)
|
||||
---
|
||||
bin/tests/system/reclimit/tests.sh | 4 +-
|
||||
lib/dns/include/dns/rdataslab.h | 1 +
|
||||
lib/dns/rbtdb.c | 77 +++++++++++++++++++++++++-----
|
||||
3 files changed, 69 insertions(+), 13 deletions(-)
|
||||
|
||||
diff --git a/bin/tests/system/reclimit/tests.sh b/bin/tests/system/reclimit/tests.sh
|
||||
index c15225488f..55ccac7759 100644
|
||||
--- a/bin/tests/system/reclimit/tests.sh
|
||||
+++ b/bin/tests/system/reclimit/tests.sh
|
||||
@@ -338,13 +338,13 @@ echo_i "checking that NXDOMAIN names over the max-types-per-name limit don't get
|
||||
|
||||
# Query for 10 NXDOMAIN types
|
||||
for ntype in $(seq 65270 65279); do
|
||||
- check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR big SOA 0 || ret=1
|
||||
+ check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR big SOA 120 || ret=1
|
||||
done
|
||||
# Wait at least 1 second
|
||||
sleep 1
|
||||
# Query for 10 NXDOMAIN types again - these should not be cached
|
||||
for ntype in $(seq 65270 65279); do
|
||||
- check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR big SOA 0 || ret=1
|
||||
+ check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR big SOA 120 || ret=1
|
||||
done
|
||||
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
diff --git a/lib/dns/include/dns/rdataslab.h b/lib/dns/include/dns/rdataslab.h
|
||||
index 5729c004ca..6bd3b5997d 100644
|
||||
--- a/lib/dns/include/dns/rdataslab.h
|
||||
+++ b/lib/dns/include/dns/rdataslab.h
|
||||
@@ -44,6 +44,7 @@
|
||||
#include <stdbool.h>
|
||||
|
||||
#include <isc/lang.h>
|
||||
+#include <isc/refcount.h>
|
||||
|
||||
#include <dns/types.h>
|
||||
|
||||
diff --git a/lib/dns/rbtdb.c b/lib/dns/rbtdb.c
|
||||
index 62bc97d783..0b8547950f 100644
|
||||
--- a/lib/dns/rbtdb.c
|
||||
+++ b/lib/dns/rbtdb.c
|
||||
@@ -158,6 +158,7 @@ struct noqname {
|
||||
};
|
||||
|
||||
typedef struct rdatasetheader {
|
||||
+ isc_refcount_t references;
|
||||
/*%
|
||||
* Locked by the owning node's lock.
|
||||
*/
|
||||
@@ -1447,6 +1448,7 @@ init_rdataset(dns_rbtdb_t *rbtdb, rdatasetheader_t *h) {
|
||||
h->heap_index = 0;
|
||||
atomic_init(&h->attributes, 0);
|
||||
atomic_init(&h->last_refresh_fail_ts, 0);
|
||||
+ isc_refcount_init(&h->references, 1);
|
||||
|
||||
STATIC_ASSERT(sizeof(h->attributes) == 2,
|
||||
"The .attributes field of rdatasetheader_t needs to be "
|
||||
@@ -1559,6 +1561,9 @@ rollback_node(dns_rbtnode_t *node, rbtdb_serial_t serial) {
|
||||
}
|
||||
}
|
||||
|
||||
+static void
|
||||
+clean_stale_headers(dns_rbtdb_t *rbtdb, isc_mem_t *mctx, rdatasetheader_t *top);
|
||||
+
|
||||
static void
|
||||
mark_header_ancient(dns_rbtdb_t *rbtdb, rdatasetheader_t *header) {
|
||||
uint_least16_t attributes = atomic_load_acquire(&header->attributes);
|
||||
@@ -1584,8 +1589,12 @@ mark_header_ancient(dns_rbtdb_t *rbtdb, rdatasetheader_t *header) {
|
||||
update_rrsetstats(rbtdb, header->type, attributes, false);
|
||||
header->node->dirty = 1;
|
||||
|
||||
+ isc_refcount_decrement(&header->references);
|
||||
+
|
||||
/* Increment the stats counter for the ancient RRtype. */
|
||||
update_rrsetstats(rbtdb, header->type, newattributes, true);
|
||||
+
|
||||
+ clean_stale_headers(rbtdb, rbtdb->common.mctx, header);
|
||||
}
|
||||
|
||||
static void
|
||||
@@ -1621,12 +1630,19 @@ static void
|
||||
clean_stale_headers(dns_rbtdb_t *rbtdb, isc_mem_t *mctx,
|
||||
rdatasetheader_t *top) {
|
||||
rdatasetheader_t *d, *down_next;
|
||||
+ rdatasetheader_t *down_parent = top;
|
||||
|
||||
for (d = top->down; d != NULL; d = down_next) {
|
||||
down_next = d->down;
|
||||
- free_rdataset(rbtdb, mctx, d);
|
||||
+ d->next = down_parent;
|
||||
+
|
||||
+ if (isc_refcount_current(&d->references) == 0) {
|
||||
+ free_rdataset(rbtdb, mctx, d);
|
||||
+ down_parent->down = down_next;
|
||||
+ } else {
|
||||
+ down_parent = d;
|
||||
+ }
|
||||
}
|
||||
- top->down = NULL;
|
||||
}
|
||||
|
||||
static void
|
||||
@@ -1642,6 +1658,7 @@ clean_cache_node(dns_rbtdb_t *rbtdb, dns_rbtnode_t *node) {
|
||||
for (current = node->data; current != NULL; current = top_next) {
|
||||
top_next = current->next;
|
||||
clean_stale_headers(rbtdb, mctx, current);
|
||||
+ INSIST(current->down == NULL);
|
||||
/*
|
||||
* If current is nonexistent, ancient, or stale and
|
||||
* we are not keeping stale, we can clean it up.
|
||||
@@ -3114,6 +3131,8 @@ bind_rdataset(dns_rbtdb_t *rbtdb, dns_rbtnode_t *node, rdatasetheader_t *header,
|
||||
return;
|
||||
}
|
||||
|
||||
+ isc_refcount_increment(&header->references);
|
||||
+
|
||||
dns__rbtnode_acquire(rbtdb, node, locktype);
|
||||
|
||||
INSIST(rdataset->methods == NULL); /* We must be disassociated. */
|
||||
@@ -6307,6 +6326,7 @@ add32(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, const dns_name_t *nodename,
|
||||
bool header_nx;
|
||||
bool newheader_nx;
|
||||
bool merge;
|
||||
+ bool do_expireheader = false;
|
||||
dns_rdatatype_t rdtype, covers;
|
||||
rbtdb_rdatatype_t negtype, sigtype;
|
||||
dns_trust_t trust;
|
||||
@@ -6856,6 +6876,7 @@ find_header:
|
||||
}
|
||||
|
||||
if (IS_CACHE(rbtdb) && overmaxtype(rbtdb, ntypes)) {
|
||||
+ do_expireheader = true;
|
||||
if (expireheader == NULL) {
|
||||
expireheader = newheader;
|
||||
}
|
||||
@@ -6869,15 +6890,6 @@ find_header:
|
||||
*/
|
||||
expireheader = newheader;
|
||||
}
|
||||
-
|
||||
- set_ttl(rbtdb, expireheader, 0);
|
||||
- mark_header_ancient(rbtdb, expireheader);
|
||||
- /*
|
||||
- * FIXME: In theory, we should mark the RRSIG
|
||||
- * and the header at the same time, but there is
|
||||
- * no direct link between those two header, so
|
||||
- * we would have to check the whole list again.
|
||||
- */
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -6901,6 +6913,15 @@ find_header:
|
||||
isc_rwlocktype_write, addedrdataset);
|
||||
}
|
||||
|
||||
+ /*
|
||||
+ * We need to delay the expiration of the header until we are bound to
|
||||
+ * it to prevent decrement-then-increment on the header references.
|
||||
+ */
|
||||
+ if (do_expireheader) {
|
||||
+ set_ttl(rbtdb, expireheader, 0);
|
||||
+ mark_header_ancient(rbtdb, expireheader);
|
||||
+ }
|
||||
+
|
||||
return ISC_R_SUCCESS;
|
||||
}
|
||||
|
||||
@@ -8692,6 +8713,12 @@ rdataset_disassociate(dns_rdataset_t *rdataset) {
|
||||
dns_db_t *db = rdataset->private1;
|
||||
dns_dbnode_t *node = rdataset->private2;
|
||||
|
||||
+ if (rdataset->methods == &rdataset_methods) {
|
||||
+ rdatasetheader_t *header = rdataset->private3;
|
||||
+ header--;
|
||||
+ isc_refcount_decrement(&header->references);
|
||||
+ }
|
||||
+
|
||||
detachnode(db, &node);
|
||||
}
|
||||
|
||||
@@ -8806,6 +8833,11 @@ rdataset_clone(dns_rdataset_t *source, dns_rdataset_t *target) {
|
||||
dns_dbnode_t *cloned_node = NULL;
|
||||
|
||||
attachnode(db, node, &cloned_node);
|
||||
+ if (source->methods == &rdataset_methods) {
|
||||
+ rdatasetheader_t *header = source->private3;
|
||||
+ header--;
|
||||
+ isc_refcount_increment(&header->references);
|
||||
+ }
|
||||
INSIST(!ISC_LINK_LINKED(target, link));
|
||||
*target = *source;
|
||||
ISC_LINK_INIT(target, link);
|
||||
@@ -8969,6 +9001,11 @@ rdatasetiter_destroy(dns_rdatasetiter_t **iteratorp) {
|
||||
|
||||
rbtiterator = (rbtdb_rdatasetiter_t *)(*iteratorp);
|
||||
|
||||
+ if (rbtiterator->current != NULL) {
|
||||
+ isc_refcount_decrement(&rbtiterator->current->references);
|
||||
+ rbtiterator->current = NULL;
|
||||
+ }
|
||||
+
|
||||
if (rbtiterator->common.version != NULL) {
|
||||
closeversion(rbtiterator->common.db,
|
||||
&rbtiterator->common.version, false);
|
||||
@@ -9046,9 +9083,18 @@ rdatasetiter_first(dns_rdatasetiter_t *iterator) {
|
||||
}
|
||||
}
|
||||
|
||||
+ if (header != NULL) {
|
||||
+ isc_refcount_increment0(&header->references);
|
||||
+ }
|
||||
+
|
||||
NODE_UNLOCK(&rbtdb->node_locks[rbtnode->locknum].lock,
|
||||
isc_rwlocktype_read);
|
||||
|
||||
+ if (rbtiterator->current != NULL) {
|
||||
+ isc_refcount_decrement(&rbtiterator->current->references);
|
||||
+ rbtiterator->current = NULL;
|
||||
+ }
|
||||
+
|
||||
rbtiterator->current = header;
|
||||
|
||||
if (header == NULL) {
|
||||
@@ -9140,9 +9186,18 @@ rdatasetiter_next(dns_rdatasetiter_t *iterator) {
|
||||
}
|
||||
}
|
||||
|
||||
+ if (header != NULL) {
|
||||
+ isc_refcount_increment0(&header->references);
|
||||
+ }
|
||||
+
|
||||
NODE_UNLOCK(&rbtdb->node_locks[rbtnode->locknum].lock,
|
||||
isc_rwlocktype_read);
|
||||
|
||||
+ if (rbtiterator->current != NULL) {
|
||||
+ isc_refcount_decrement(&rbtiterator->current->references);
|
||||
+ rbtiterator->current = NULL;
|
||||
+ }
|
||||
+
|
||||
rbtiterator->current = header;
|
||||
|
||||
if (header == NULL) {
|
||||
--
|
||||
2.55.0
|
||||
|
||||
144
bind-9.18-CVE-2026-11721-test.patch
Normal file
144
bind-9.18-CVE-2026-11721-test.patch
Normal file
|
|
@ -0,0 +1,144 @@
|
|||
From b08e0876639ab9f3dae3813202861fd1098f2611 Mon Sep 17 00:00:00 2001
|
||||
From: Mark Andrews <marka@isc.org>
|
||||
Date: Tue, 14 Apr 2026 13:46:22 +1000
|
||||
Subject: [PATCH] Test RRSIG record parsing
|
||||
|
||||
In particular test that labels and signer fields are consistent.
|
||||
|
||||
(cherry picked from commit 5a95e64731afe63d348d272cc4d3b2f9847150c2)
|
||||
(cherry picked from commit 19e496ca260b6a756ae1378e8ebcbdb666b7d9ed)
|
||||
---
|
||||
tests/dns/rdata_test.c | 110 +++++++++++++++++++++++++++++++++++++++++
|
||||
1 file changed, 110 insertions(+)
|
||||
|
||||
diff --git a/tests/dns/rdata_test.c b/tests/dns/rdata_test.c
|
||||
index 7f0df6e046..c704d98ed1 100644
|
||||
--- a/tests/dns/rdata_test.c
|
||||
+++ b/tests/dns/rdata_test.c
|
||||
@@ -2504,6 +2504,115 @@ ISC_RUN_TEST_IMPL(rkey) {
|
||||
dns_rdatatype_rkey, sizeof(dns_rdata_rkey_t));
|
||||
}
|
||||
|
||||
+ISC_RUN_TEST_IMPL(rrsig) {
|
||||
+ text_ok_t text_ok[] = {
|
||||
+ TEXT_VALID("SOA 8 0 86400 20260426170000 20260413160000 54393 "
|
||||
+ ". "
|
||||
+ "tFbcoVP8MnpecUquJ/aj+XeNgV7ts9GSHVkXaXRJrJ/"
|
||||
+ "TEkOZApVG0F6E "
|
||||
+ "9sYpxGk2ItweLL43ujioGj0HWwZDRR+vbur+O/"
|
||||
+ "dIdheiig1VvU+9HXLi "
|
||||
+ "QOViY9Kc64ixdyJhYCC5K+bO1qsHxd+"
|
||||
+ "KJXOaxyHbqchYkDFy4PL6qftE "
|
||||
+ "VaLkueRgjXgOsq/"
|
||||
+ "NxvCXDgAa5xy0+3Sl0myxIs8rJ5KeXfJQFe7qxgaw "
|
||||
+ "VjJsJTKw8neOTw2rQfLaigWu2LIWw+"
|
||||
+ "IyVrLjZJdLqGkiLBGd1w4X3U12 "
|
||||
+ "fFxoY3eqzNgBEtduoGKPZ/"
|
||||
+ "NpP9cuKJORJ18283aV8hR4WO91VR0q1zcM jLwqUg=="),
|
||||
+ /* labels too short for signer */
|
||||
+ TEXT_INVALID("SOA 8 0 86400 20260426170000 20260413160000 "
|
||||
+ "54393 example. "
|
||||
+ "tFbcoVP8MnpecUquJ/aj+XeNgV7ts9GSHVkXaXRJrJ/"
|
||||
+ "TEkOZApVG0F6E "
|
||||
+ "9sYpxGk2ItweLL43ujioGj0HWwZDRR+vbur+O/"
|
||||
+ "dIdheiig1VvU+9HXLi "
|
||||
+ "QOViY9Kc64ixdyJhYCC5K+bO1qsHxd+"
|
||||
+ "KJXOaxyHbqchYkDFy4PL6qftE "
|
||||
+ "VaLkueRgjXgOsq/"
|
||||
+ "NxvCXDgAa5xy0+3Sl0myxIs8rJ5KeXfJQFe7qxgaw "
|
||||
+ "VjJsJTKw8neOTw2rQfLaigWu2LIWw+"
|
||||
+ "IyVrLjZJdLqGkiLBGd1w4X3U12 "
|
||||
+ "fFxoY3eqzNgBEtduoGKPZ/"
|
||||
+ "NpP9cuKJORJ18283aV8hR4WO91VR0q1zcM jLwqUg=="),
|
||||
+ /*
|
||||
+ * Sentinel.
|
||||
+ */
|
||||
+ TEXT_SENTINEL()
|
||||
+ };
|
||||
+ wire_ok_t wire_ok[] = {
|
||||
+ WIRE_VALID(0x00, 0x06, 0x08, 0x00, 0x00, 0x01, 0x51, 0x80, 0x69,
|
||||
+ 0xee, 0x44, 0x90, 0x69, 0xdd, 0x13, 0x00, 0xd4, 0x79,
|
||||
+ 0x00, 0xb4, 0x56, 0xdc, 0xa1, 0x53, 0xfc, 0x32, 0x7a,
|
||||
+ 0x5e, 0x71, 0x4a, 0xae, 0x27, 0xf6, 0xa3, 0xf9, 0x77,
|
||||
+ 0x8d, 0x81, 0x5e, 0xed, 0xb3, 0xd1, 0x92, 0x1d, 0x59,
|
||||
+ 0x17, 0x69, 0x74, 0x49, 0xac, 0x9f, 0xd3, 0x12, 0x43,
|
||||
+ 0x99, 0x02, 0x95, 0x46, 0xd0, 0x5e, 0x84, 0xf6, 0xc6,
|
||||
+ 0x29, 0xc4, 0x69, 0x36, 0x22, 0xdc, 0x1e, 0x2c, 0xbe,
|
||||
+ 0x37, 0xba, 0x38, 0xa8, 0x1a, 0x3d, 0x07, 0x5b, 0x06,
|
||||
+ 0x43, 0x45, 0x1f, 0xaf, 0x6e, 0xea, 0xfe, 0x3b, 0xf7,
|
||||
+ 0x48, 0x76, 0x17, 0xa2, 0x8a, 0x0d, 0x55, 0xbd, 0x4f,
|
||||
+ 0xbd, 0x1d, 0x72, 0xe2, 0x40, 0xe5, 0x62, 0x63, 0xd2,
|
||||
+ 0x9c, 0xeb, 0x88, 0xb1, 0x77, 0x22, 0x61, 0x60, 0x20,
|
||||
+ 0xb9, 0x2b, 0xe6, 0xce, 0xd6, 0xab, 0x07, 0xc5, 0xdf,
|
||||
+ 0x8a, 0x25, 0x73, 0x9a, 0xc7, 0x21, 0xdb, 0xa9, 0xc8,
|
||||
+ 0x58, 0x90, 0x31, 0x72, 0xe0, 0xf2, 0xfa, 0xa9, 0xfb,
|
||||
+ 0x44, 0x55, 0xa2, 0xe4, 0xb9, 0xe4, 0x60, 0x8d, 0x78,
|
||||
+ 0x0e, 0xb2, 0xaf, 0xcd, 0xc6, 0xf0, 0x97, 0x0e, 0x00,
|
||||
+ 0x1a, 0xe7, 0x1c, 0xb4, 0xfb, 0x74, 0xa5, 0xd2, 0x6c,
|
||||
+ 0xb1, 0x22, 0xcf, 0x2b, 0x27, 0x92, 0x9e, 0x5d, 0xf2,
|
||||
+ 0x50, 0x15, 0xee, 0xea, 0xc6, 0x06, 0xb0, 0x56, 0x32,
|
||||
+ 0x6c, 0x25, 0x32, 0xb0, 0xf2, 0x77, 0x8e, 0x4f, 0x0d,
|
||||
+ 0xab, 0x41, 0xf2, 0xda, 0x8a, 0x05, 0xae, 0xd8, 0xb2,
|
||||
+ 0x16, 0xc3, 0xe2, 0x32, 0x56, 0xb2, 0xe3, 0x64, 0x97,
|
||||
+ 0x4b, 0xa8, 0x69, 0x22, 0x2c, 0x11, 0x9d, 0xd7, 0x0e,
|
||||
+ 0x17, 0xdd, 0x4d, 0x76, 0x7c, 0x5c, 0x68, 0x63, 0x77,
|
||||
+ 0xaa, 0xcc, 0xd8, 0x01, 0x12, 0xd7, 0x6e, 0xa0, 0x62,
|
||||
+ 0x8f, 0x67, 0xf3, 0x69, 0x3f, 0xd7, 0x2e, 0x28, 0x93,
|
||||
+ 0x91, 0x27, 0x5f, 0x36, 0xf3, 0x76, 0x95, 0xf2, 0x14,
|
||||
+ 0x78, 0x58, 0xef, 0x75, 0x55, 0x1d, 0x2a, 0xd7, 0x37,
|
||||
+ 0x0c, 0x8c, 0xbc, 0x2a, 0x52),
|
||||
+ /* labels too short for signer */
|
||||
+ WIRE_INVALID(
|
||||
+ 0x00, 0x06, 0x08, 0x00, 0x00, 0x01, 0x51, 0x80, 0x69,
|
||||
+ 0xee, 0x44, 0x90, 0x69, 0xdd, 0x13, 0x00, 0xd4, 0x79,
|
||||
+ 0x07, 0x65, 0x78, 0x61, 0x6d, 0x70, 0x6c, 0x65, 0x00,
|
||||
+ 0xb4, 0x56, 0xdc, 0xa1, 0x53, 0xfc, 0x32, 0x7a, 0x5e,
|
||||
+ 0x71, 0x4a, 0xae, 0x27, 0xf6, 0xa3, 0xf9, 0x77, 0x8d,
|
||||
+ 0x81, 0x5e, 0xed, 0xb3, 0xd1, 0x92, 0x1d, 0x59, 0x17,
|
||||
+ 0x69, 0x74, 0x49, 0xac, 0x9f, 0xd3, 0x12, 0x43, 0x99,
|
||||
+ 0x02, 0x95, 0x46, 0xd0, 0x5e, 0x84, 0xf6, 0xc6, 0x29,
|
||||
+ 0xc4, 0x69, 0x36, 0x22, 0xdc, 0x1e, 0x2c, 0xbe, 0x37,
|
||||
+ 0xba, 0x38, 0xa8, 0x1a, 0x3d, 0x07, 0x5b, 0x06, 0x43,
|
||||
+ 0x45, 0x1f, 0xaf, 0x6e, 0xea, 0xfe, 0x3b, 0xf7, 0x48,
|
||||
+ 0x76, 0x17, 0xa2, 0x8a, 0x0d, 0x55, 0xbd, 0x4f, 0xbd,
|
||||
+ 0x1d, 0x72, 0xe2, 0x40, 0xe5, 0x62, 0x63, 0xd2, 0x9c,
|
||||
+ 0xeb, 0x88, 0xb1, 0x77, 0x22, 0x61, 0x60, 0x20, 0xb9,
|
||||
+ 0x2b, 0xe6, 0xce, 0xd6, 0xab, 0x07, 0xc5, 0xdf, 0x8a,
|
||||
+ 0x25, 0x73, 0x9a, 0xc7, 0x21, 0xdb, 0xa9, 0xc8, 0x58,
|
||||
+ 0x90, 0x31, 0x72, 0xe0, 0xf2, 0xfa, 0xa9, 0xfb, 0x44,
|
||||
+ 0x55, 0xa2, 0xe4, 0xb9, 0xe4, 0x60, 0x8d, 0x78, 0x0e,
|
||||
+ 0xb2, 0xaf, 0xcd, 0xc6, 0xf0, 0x97, 0x0e, 0x00, 0x1a,
|
||||
+ 0xe7, 0x1c, 0xb4, 0xfb, 0x74, 0xa5, 0xd2, 0x6c, 0xb1,
|
||||
+ 0x22, 0xcf, 0x2b, 0x27, 0x92, 0x9e, 0x5d, 0xf2, 0x50,
|
||||
+ 0x15, 0xee, 0xea, 0xc6, 0x06, 0xb0, 0x56, 0x32, 0x6c,
|
||||
+ 0x25, 0x32, 0xb0, 0xf2, 0x77, 0x8e, 0x4f, 0x0d, 0xab,
|
||||
+ 0x41, 0xf2, 0xda, 0x8a, 0x05, 0xae, 0xd8, 0xb2, 0x16,
|
||||
+ 0xc3, 0xe2, 0x32, 0x56, 0xb2, 0xe3, 0x64, 0x97, 0x4b,
|
||||
+ 0xa8, 0x69, 0x22, 0x2c, 0x11, 0x9d, 0xd7, 0x0e, 0x17,
|
||||
+ 0xdd, 0x4d, 0x76, 0x7c, 0x5c, 0x68, 0x63, 0x77, 0xaa,
|
||||
+ 0xcc, 0xd8, 0x01, 0x12, 0xd7, 0x6e, 0xa0, 0x62, 0x8f,
|
||||
+ 0x67, 0xf3, 0x69, 0x3f, 0xd7, 0x2e, 0x28, 0x93, 0x91,
|
||||
+ 0x27, 0x5f, 0x36, 0xf3, 0x76, 0x95, 0xf2, 0x14, 0x78,
|
||||
+ 0x58, 0xef, 0x75, 0x55, 0x1d, 0x2a, 0xd7, 0x37, 0x0c,
|
||||
+ 0x8c, 0xbc, 0x2a, 0x52),
|
||||
+
|
||||
+ WIRE_SENTINEL()
|
||||
+ };
|
||||
+ check_rdata(text_ok, wire_ok, NULL, false, dns_rdataclass_in,
|
||||
+ dns_rdatatype_rrsig, sizeof(dns_rdata_rrsig_t));
|
||||
+}
|
||||
+
|
||||
ISC_RUN_TEST_IMPL(resinfo) {
|
||||
text_ok_t text_ok[] = {
|
||||
TEXT_VALID_CHANGED("qnamemin exterr=15,16,17 "
|
||||
@@ -3357,6 +3466,7 @@ ISC_TEST_ENTRY(nsec3)
|
||||
ISC_TEST_ENTRY(nxt)
|
||||
ISC_TEST_ENTRY(resinfo)
|
||||
ISC_TEST_ENTRY(rkey)
|
||||
+ISC_TEST_ENTRY(rrsig)
|
||||
ISC_TEST_ENTRY(sshfp)
|
||||
ISC_TEST_ENTRY(wallet)
|
||||
ISC_TEST_ENTRY(wks)
|
||||
--
|
||||
2.55.0
|
||||
|
||||
267
bind-9.18-CVE-2026-11721.patch
Normal file
267
bind-9.18-CVE-2026-11721.patch
Normal file
|
|
@ -0,0 +1,267 @@
|
|||
From 7a8a1f74c742e98fb5e105b013e7c2bd7af4a76c Mon Sep 17 00:00:00 2001
|
||||
From: Mark Andrews <marka@isc.org>
|
||||
Date: Tue, 14 Apr 2026 15:14:06 +1000
|
||||
Subject: [PATCH] Don't sign out of zone records in dnssec-signzone
|
||||
|
||||
dnssec-signzone was signing extraneous records that were not within
|
||||
the namespace of the zone. This no longer occurs.
|
||||
|
||||
(cherry picked from commit e45c9af7051421fd370f20ba8325199c606223fd)
|
||||
|
||||
Don't sign out of zone records in dnssec-signzone
|
||||
|
||||
dnssec-signzone was signing extraneous records that were not within
|
||||
the namespace of the zone. This no longer occurs.
|
||||
|
||||
(cherry picked from commit e45c9af7051421fd370f20ba8325199c606223fd)
|
||||
(cherry picked from commit 1a4986e2533f87e80eb21da3f06708d335aff1e2)
|
||||
|
||||
Invalid signed wildcard records were being accepted
|
||||
|
||||
An RRSIG whose Labels field indicates fewer labels than its signer
|
||||
name requires was being accepted. When such a record covers a
|
||||
wildcard, the validator reconstructs a wildcard owner name above the
|
||||
signer's zone and caches it as secure. RFC 8198 cache synthesis
|
||||
(synth-from-dnssec) then serves that forged wildcard for unrelated
|
||||
names, poisoning the cache.
|
||||
|
||||
These records are now rejected, both when an RRSIG is parsed and when
|
||||
its signature is verified.
|
||||
|
||||
(cherry picked from commit 084ca5ee10515e461d46b63df9660b8394bc7de9)
|
||||
(cherry picked from commit 15089066b15f826d7487c3d160b5872820f84b83)
|
||||
---
|
||||
bin/dnssec/dnssec-signzone.c | 5 ++++
|
||||
lib/dns/dnssec.c | 43 +++++++++++++++++++++++---------
|
||||
lib/dns/rdata/generic/rrsig_46.c | 37 ++++++++++++++++++++-------
|
||||
3 files changed, 64 insertions(+), 21 deletions(-)
|
||||
|
||||
diff --git a/bin/dnssec/dnssec-signzone.c b/bin/dnssec/dnssec-signzone.c
|
||||
index 73855e6284..9e3a48a592 100644
|
||||
--- a/bin/dnssec/dnssec-signzone.c
|
||||
+++ b/bin/dnssec/dnssec-signzone.c
|
||||
@@ -1643,6 +1643,11 @@ assignwork(isc_task_t *task, isc_task_t *worker) {
|
||||
dns_db_detachnode(gdb, &node);
|
||||
goto next;
|
||||
}
|
||||
+ if (!dns_name_issubdomain(name, gorigin)) {
|
||||
+ dumpnode(name, node);
|
||||
+ dns_db_detachnode(gdb, &node);
|
||||
+ goto next;
|
||||
+ }
|
||||
/*
|
||||
* Sort the zone data from the glue and out-of-zone data.
|
||||
* For NSEC zones nodes with zone data have NSEC records.
|
||||
diff --git a/lib/dns/dnssec.c b/lib/dns/dnssec.c
|
||||
index c7e922437c..b12529b5d5 100644
|
||||
--- a/lib/dns/dnssec.c
|
||||
+++ b/lib/dns/dnssec.c
|
||||
@@ -130,11 +130,11 @@ dns_dnssec_keyfromrdata(const dns_name_t *name, const dns_rdata_t *rdata,
|
||||
isc_buffer_t b;
|
||||
isc_region_t r;
|
||||
|
||||
- INSIST(name != NULL);
|
||||
- INSIST(rdata != NULL);
|
||||
- INSIST(mctx != NULL);
|
||||
- INSIST(key != NULL);
|
||||
- INSIST(*key == NULL);
|
||||
+ REQUIRE(name != NULL);
|
||||
+ REQUIRE(rdata != NULL);
|
||||
+ REQUIRE(mctx != NULL);
|
||||
+ REQUIRE(key != NULL);
|
||||
+ REQUIRE(*key == NULL);
|
||||
REQUIRE(rdata->type == dns_rdatatype_key ||
|
||||
rdata->type == dns_rdatatype_dnskey);
|
||||
|
||||
@@ -187,12 +187,14 @@ dns_dnssec_sign(const dns_name_t *name, dns_rdataset_t *set, dst_key_t *key,
|
||||
isc_result_t ret;
|
||||
isc_buffer_t *databuf = NULL;
|
||||
char data[256 + 8];
|
||||
+ unsigned int labels;
|
||||
unsigned int sigsize;
|
||||
dns_fixedname_t fnewname;
|
||||
dns_fixedname_t fsigner;
|
||||
|
||||
REQUIRE(name != NULL);
|
||||
- REQUIRE(dns_name_countlabels(name) <= 255);
|
||||
+ labels = dns_name_countlabels(name);
|
||||
+ REQUIRE(labels <= 255 && labels > 0);
|
||||
REQUIRE(set != NULL);
|
||||
REQUIRE(key != NULL);
|
||||
REQUIRE(inception != NULL);
|
||||
@@ -221,7 +223,7 @@ dns_dnssec_sign(const dns_name_t *name, dns_rdataset_t *set, dst_key_t *key,
|
||||
|
||||
sig.covered = set->type;
|
||||
sig.algorithm = dst_key_alg(key);
|
||||
- sig.labels = dns_name_countlabels(name) - 1;
|
||||
+ sig.labels = labels - 1;
|
||||
if (dns_name_iswildcard(name)) {
|
||||
sig.labels--;
|
||||
}
|
||||
@@ -365,10 +367,13 @@ dns_dnssec_verify(const dns_name_t *name, dns_rdataset_t *set, dst_key_t *key,
|
||||
isc_result_t ret;
|
||||
unsigned char data[300];
|
||||
dst_context_t *ctx = NULL;
|
||||
- int labels = 0;
|
||||
+ unsigned int labels;
|
||||
+ unsigned int siglabels;
|
||||
bool downcase = false;
|
||||
|
||||
REQUIRE(name != NULL);
|
||||
+ labels = dns_name_countlabels(name);
|
||||
+ REQUIRE(labels > 0);
|
||||
REQUIRE(set != NULL);
|
||||
REQUIRE(key != NULL);
|
||||
REQUIRE(mctx != NULL);
|
||||
@@ -383,6 +388,21 @@ dns_dnssec_verify(const dns_name_t *name, dns_rdataset_t *set, dst_key_t *key,
|
||||
return DNS_R_SIGINVALID;
|
||||
}
|
||||
|
||||
+ /*
|
||||
+ * The RRSIG labels field can't indicate fewer labels than the
|
||||
+ * signer. Also the labels shouldn't be greater than that of
|
||||
+ * the owner name.
|
||||
+ *
|
||||
+ * sig.labels doesn't include the root label, so add 1 to account
|
||||
+ * for it.
|
||||
+ */
|
||||
+ siglabels = sig.labels + 1;
|
||||
+ if (siglabels < dns_name_countlabels(&sig.signer) || siglabels > labels)
|
||||
+ {
|
||||
+ inc_stat(dns_dnssecstats_fail);
|
||||
+ return DNS_R_SIGINVALID;
|
||||
+ }
|
||||
+
|
||||
if (isc_serial_lt(sig.timeexpire, sig.timesigned)) {
|
||||
inc_stat(dns_dnssecstats_fail);
|
||||
return DNS_R_SIGINVALID;
|
||||
@@ -449,10 +469,9 @@ again:
|
||||
* If the name is an expanded wildcard, use the wildcard name.
|
||||
*/
|
||||
dns_fixedname_init(&fnewname);
|
||||
- labels = dns_name_countlabels(name) - 1;
|
||||
RUNTIME_CHECK(dns_name_downcase(name, dns_fixedname_name(&fnewname),
|
||||
NULL) == ISC_R_SUCCESS);
|
||||
- if (labels - sig.labels > 0) {
|
||||
+ if (labels > siglabels) {
|
||||
dns_name_split(dns_fixedname_name(&fnewname), sig.labels + 1,
|
||||
NULL, dns_fixedname_name(&fnewname));
|
||||
}
|
||||
@@ -463,7 +482,7 @@ again:
|
||||
* Create an envelope for each rdata: <name|type|class|ttl>.
|
||||
*/
|
||||
isc_buffer_init(&envbuf, data, sizeof(data));
|
||||
- if (labels - sig.labels > 0) {
|
||||
+ if (labels > siglabels) {
|
||||
isc_buffer_putuint8(&envbuf, 1);
|
||||
isc_buffer_putuint8(&envbuf, '*');
|
||||
memmove(data + 2, r.base, r.length);
|
||||
@@ -559,7 +578,7 @@ cleanup_struct:
|
||||
inc_stat(dns_dnssecstats_fail);
|
||||
}
|
||||
|
||||
- if (ret == ISC_R_SUCCESS && labels - sig.labels > 0) {
|
||||
+ if (ret == ISC_R_SUCCESS && labels > siglabels) {
|
||||
if (wild != NULL) {
|
||||
RUNTIME_CHECK(dns_name_concatenate(
|
||||
dns_wildcardname,
|
||||
diff --git a/lib/dns/rdata/generic/rrsig_46.c b/lib/dns/rdata/generic/rrsig_46.c
|
||||
index 10bc039e93..4cf4259c2b 100644
|
||||
--- a/lib/dns/rdata/generic/rrsig_46.c
|
||||
+++ b/lib/dns/rdata/generic/rrsig_46.c
|
||||
@@ -23,12 +23,12 @@
|
||||
static isc_result_t
|
||||
fromtext_rrsig(ARGS_FROMTEXT) {
|
||||
isc_token_t token;
|
||||
- unsigned char c;
|
||||
+ unsigned char alg, labels;
|
||||
long i;
|
||||
dns_rdatatype_t covered;
|
||||
- char *e;
|
||||
+ char *e = NULL;
|
||||
isc_result_t result;
|
||||
- dns_name_t name;
|
||||
+ dns_name_t signer;
|
||||
isc_buffer_t buffer;
|
||||
uint32_t time_signed, time_expire;
|
||||
|
||||
@@ -61,8 +61,8 @@ fromtext_rrsig(ARGS_FROMTEXT) {
|
||||
*/
|
||||
RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
|
||||
false));
|
||||
- RETTOK(dns_secalg_fromtext(&c, &token.value.as_textregion));
|
||||
- RETERR(mem_tobuffer(target, &c, 1));
|
||||
+ RETTOK(dns_secalg_fromtext(&alg, &token.value.as_textregion));
|
||||
+ RETERR(mem_tobuffer(target, &alg, 1));
|
||||
|
||||
/*
|
||||
* Labels.
|
||||
@@ -72,8 +72,8 @@ fromtext_rrsig(ARGS_FROMTEXT) {
|
||||
if (token.value.as_ulong > 0xffU) {
|
||||
RETTOK(ISC_R_RANGE);
|
||||
}
|
||||
- c = (unsigned char)token.value.as_ulong;
|
||||
- RETERR(mem_tobuffer(target, &c, 1));
|
||||
+ labels = (unsigned char)token.value.as_ulong;
|
||||
+ RETERR(mem_tobuffer(target, &labels, 1));
|
||||
|
||||
/*
|
||||
* Original ttl.
|
||||
@@ -144,12 +144,20 @@ fromtext_rrsig(ARGS_FROMTEXT) {
|
||||
*/
|
||||
RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
|
||||
false));
|
||||
- dns_name_init(&name, NULL);
|
||||
+ dns_name_init(&signer, NULL);
|
||||
buffer_fromregion(&buffer, &token.value.as_region);
|
||||
if (origin == NULL) {
|
||||
origin = dns_rootname;
|
||||
}
|
||||
- RETTOK(dns_name_fromtext(&name, &buffer, origin, options, target));
|
||||
+ RETTOK(dns_name_fromtext(&signer, &buffer, origin, options, target));
|
||||
+
|
||||
+ /*
|
||||
+ * (RRSIG labels doesn't include the root label, so add one
|
||||
+ * to normalize it before checking against the signer.)
|
||||
+ */
|
||||
+ if ((unsigned int)(labels + 1) < dns_name_countlabels(&signer)) {
|
||||
+ RETTOK(ISC_R_RANGE);
|
||||
+ }
|
||||
|
||||
/*
|
||||
* Sig.
|
||||
@@ -278,6 +286,7 @@ static isc_result_t
|
||||
fromwire_rrsig(ARGS_FROMWIRE) {
|
||||
isc_region_t sr;
|
||||
dns_name_t name;
|
||||
+ unsigned char labels;
|
||||
|
||||
REQUIRE(type == dns_rdatatype_rrsig);
|
||||
|
||||
@@ -300,6 +309,8 @@ fromwire_rrsig(ARGS_FROMWIRE) {
|
||||
return ISC_R_UNEXPECTEDEND;
|
||||
}
|
||||
|
||||
+ labels = sr.base[3];
|
||||
+
|
||||
isc_buffer_forward(source, 18);
|
||||
RETERR(mem_tobuffer(target, sr.base, 18));
|
||||
|
||||
@@ -309,6 +320,14 @@ fromwire_rrsig(ARGS_FROMWIRE) {
|
||||
dns_name_init(&name, NULL);
|
||||
RETERR(dns_name_fromwire(&name, source, dctx, options, target));
|
||||
|
||||
+ /*
|
||||
+ * (RRSIG labels doesn't include the root label, so add one
|
||||
+ * to normalize it before checking against the signer.)
|
||||
+ */
|
||||
+ if ((unsigned int)(labels + 1) < dns_name_countlabels(&name)) {
|
||||
+ RETERR(DNS_R_FORMERR);
|
||||
+ }
|
||||
+
|
||||
/*
|
||||
* Sig.
|
||||
*/
|
||||
--
|
||||
2.55.0
|
||||
|
||||
435
bind-9.18-CVE-2026-12617-test.patch
Normal file
435
bind-9.18-CVE-2026-12617-test.patch
Normal file
|
|
@ -0,0 +1,435 @@
|
|||
From a31296b120efc985fb1fc3c932882e965156473b Mon Sep 17 00:00:00 2001
|
||||
From: Colin Vidal <colin@isc.org>
|
||||
Date: Mon, 15 Jun 2026 11:34:08 +0200
|
||||
Subject: [PATCH] Reproducer for #5946 (assertion in some CNAME/DNAME queries)
|
||||
|
||||
Add a system test reproducing the issue reported by #5946, which
|
||||
is also CVE-2026-12617. There are two scenarios:
|
||||
|
||||
- A client send queries for a DNAME and A record to the resolver (ns3),
|
||||
and the authoritative server (ans2) responds positively to the A query
|
||||
but delay the DNAME response and respond later negatively;
|
||||
|
||||
- A client send queries for a CNAME and A record to the resolver (ns3),
|
||||
and the authoritative server (ans2) responds positively to the A query
|
||||
but delay the CNAME response and respond later with a self-referential
|
||||
CNAME.
|
||||
|
||||
The test does not check the results of the queries, however, it expects
|
||||
the resolver to correctly handle those and do not assert.
|
||||
|
||||
(cherry picked from commit e88271f2e584010157b068cc998dd76451273562)
|
||||
(cherry picked from commit bb92832fb6ae899bee7206c2d8966258461c2f71)
|
||||
|
||||
Stabilize timing in the cname_dname_negcache test
|
||||
|
||||
The #5946 reproducer relied on ans2 answering the negative DNAME/CNAME
|
||||
query a fixed second after receiving it, racing that delay against the
|
||||
resolver's per-query timeout. When the timeout fired first -- which
|
||||
happens under load, most notably under ThreadSanitizer, where named is
|
||||
slowed but ans2 (wall-clock) is not -- the resolver dropped the late
|
||||
answer, never processed the negative response, and the watched SOA never
|
||||
appeared, so the test timed out. This made it flaky on the
|
||||
security-bind-9.20 CI. Merely shortening the fixed delay would trade
|
||||
that for the opposite, worse failure: the negative answer arriving
|
||||
before the positive one is cached, silently not exercising the bug.
|
||||
|
||||
Release the negative answer based on the resolver's progress instead of
|
||||
a wall-clock deadline: hold it until ans2 has sent the positive answer
|
||||
(a shared event), then wait a short settle for the resolver to cache it.
|
||||
Both queries traverse the same delegation, so any latency reaching ans2
|
||||
shifts the positive send and the negative fetch's deadline together and
|
||||
cancels out; only the settle, kept well under MINIMUM_QUERY_TIMEOUT
|
||||
(301 ms), has to fit inside the per-query timeout.
|
||||
|
||||
Verified that the stabilized test still triggers the
|
||||
INSIST(namereln == dns_namereln_subdomain) assertion when the resolver
|
||||
fix is reverted.
|
||||
|
||||
Assisted-by: Claude:claude-opus-4-8
|
||||
(cherry picked from commit 738456d91564526e6f15c3858b4c809cd6749e1e)
|
||||
(cherry picked from commit 0c20ee4e8e68999ca617434cde65dd3808f57d8c)
|
||||
|
||||
Split cname_dname_negcache into per-scenario modules
|
||||
|
||||
The DNAME and CNAME scenarios shared a single module, hence a single
|
||||
module-scoped ns3 (the framework sets servers up per module, not per
|
||||
test function). test_dname_negcache cached foo.test. DNAME bar.test.;
|
||||
when test_cname_negcache ran next against the same resolver,
|
||||
cname.foo.test. was DNAME-mapped to cname.bar.test., so the resolver
|
||||
never queried ans2 for the self-referential CNAME and that half of the
|
||||
bug was never exercised. The hardcoded, unanchored "foo.test." watcher
|
||||
still matched test_dname's leftover SOA, so test_cname passed without
|
||||
testing anything -- the CNAME assertion had no coverage.
|
||||
|
||||
Give each scenario its own module so each gets a fresh server set, and
|
||||
anchor the watcher to the queried name so a test cannot pass on an
|
||||
unrelated record.
|
||||
|
||||
With the resolver fix reverted, each module now independently triggers
|
||||
its own assertion:
|
||||
|
||||
DNAME query.c INSIST(namereln == dns_namereln_subdomain)
|
||||
CNAME query.c INSIST(qctx->rdataset == NULL || qctx->qtype == dname)
|
||||
|
||||
Assisted-by: Claude:claude-opus-4-8
|
||||
(cherry picked from commit 3ef0b8d04a1653407cfb9ee88772ae18689b1318)
|
||||
(cherry picked from commit 887124315f03a006c4dc76e48ae3d0d8aac3c407)
|
||||
---
|
||||
.../system/cname_dname_negcache/ans2/ans.py | 148 ++++++++++++++++++
|
||||
.../system/cname_dname_negcache/common.py | 46 ++++++
|
||||
.../cname_dname_negcache/ns1/bar.test.db | 5 +
|
||||
.../cname_dname_negcache/ns1/named.conf.j2 | 24 +++
|
||||
.../system/cname_dname_negcache/ns1/root.db | 6 +
|
||||
.../system/cname_dname_negcache/ns1/test.db | 8 +
|
||||
.../cname_dname_negcache/ns3/named.conf.j2 | 11 ++
|
||||
.../tests_cname_negcache.py | 16 ++
|
||||
.../tests_dname_negcache.py | 16 ++
|
||||
9 files changed, 280 insertions(+)
|
||||
create mode 100644 bin/tests/system/cname_dname_negcache/ans2/ans.py
|
||||
create mode 100644 bin/tests/system/cname_dname_negcache/common.py
|
||||
create mode 100644 bin/tests/system/cname_dname_negcache/ns1/bar.test.db
|
||||
create mode 100644 bin/tests/system/cname_dname_negcache/ns1/named.conf.j2
|
||||
create mode 100644 bin/tests/system/cname_dname_negcache/ns1/root.db
|
||||
create mode 100644 bin/tests/system/cname_dname_negcache/ns1/test.db
|
||||
create mode 100644 bin/tests/system/cname_dname_negcache/ns3/named.conf.j2
|
||||
create mode 100644 bin/tests/system/cname_dname_negcache/tests_cname_negcache.py
|
||||
create mode 100644 bin/tests/system/cname_dname_negcache/tests_dname_negcache.py
|
||||
|
||||
diff --git a/bin/tests/system/cname_dname_negcache/ans2/ans.py b/bin/tests/system/cname_dname_negcache/ans2/ans.py
|
||||
new file mode 100644
|
||||
index 0000000000..392fe1e088
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/cname_dname_negcache/ans2/ans.py
|
||||
@@ -0,0 +1,148 @@
|
||||
+"""
|
||||
+Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
+
|
||||
+SPDX-License-Identifier: MPL-2.0
|
||||
+
|
||||
+This Source Code Form is subject to the terms of the Mozilla Public
|
||||
+License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
+file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
+
|
||||
+See the COPYRIGHT file distributed with this work for additional
|
||||
+information regarding copyright ownership.
|
||||
+"""
|
||||
+
|
||||
+from collections.abc import AsyncGenerator
|
||||
+
|
||||
+import asyncio
|
||||
+
|
||||
+from dns import name, rcode, rdataclass, rdatatype, rrset
|
||||
+
|
||||
+from isctest.asyncserver import (
|
||||
+ AsyncDnsServer,
|
||||
+ DnsResponseSend,
|
||||
+ QnameQtypeHandler,
|
||||
+ QueryContext,
|
||||
+ StaticResponseHandler,
|
||||
+)
|
||||
+
|
||||
+# The attack relies on the resolver caching the positive CNAME/DNAME answer
|
||||
+# *before* it processes the negative answer for the same name. The negative
|
||||
+# answer must therefore be held back until the positive one has been sent, but
|
||||
+# released again while the negative fetch is still waiting for it.
|
||||
+#
|
||||
+# Releasing it at a fixed wall-clock delay (the original approach) is racy: the
|
||||
+# delay must be larger than the time it takes the resolver to cache the
|
||||
+# positive answer, yet smaller than the resolver's per-query timeout. Under
|
||||
+# load -- most notably ThreadSanitizer, which slows down `named` but not this
|
||||
+# (wall-clock) server -- those bounds can be violated in either direction,
|
||||
+# making the test either time out (#5946 CI failures) or, worse, silently stop
|
||||
+# exercising the bug.
|
||||
+#
|
||||
+# Instead, gate the negative answer on an event set right after the positive
|
||||
+# answer is sent. Both queries traverse the same delegation, so any latency in
|
||||
+# reaching this server shifts the positive send and the negative fetch's
|
||||
+# deadline together and cancels out; only the small settle below has to fit
|
||||
+# inside the per-query timeout.
|
||||
+#
|
||||
+# _SETTLE must be longer than the few milliseconds the resolver needs to cache
|
||||
+# the positive answer, and shorter than MINIMUM_QUERY_TIMEOUT (301 ms in
|
||||
+# lib/dns/resolver.c) so the in-flight negative fetch has not given up yet.
|
||||
+_SETTLE = 0.1
|
||||
+
|
||||
+_dname_positive_sent = asyncio.Event()
|
||||
+_cname_positive_sent = asyncio.Event()
|
||||
+
|
||||
+
|
||||
+async def _hold_until_positive_cached(positive_sent: asyncio.Event) -> None:
|
||||
+ await positive_sent.wait()
|
||||
+ await asyncio.sleep(_SETTLE)
|
||||
+
|
||||
+
|
||||
+def build_rrset(
|
||||
+ qname: name.Name | str,
|
||||
+ rtype: rdatatype.RdataType,
|
||||
+ rdata: str,
|
||||
+ ttl: int = 300,
|
||||
+) -> rrset.RRset:
|
||||
+ return rrset.from_text(qname, ttl, rdataclass.IN, rtype, rdata)
|
||||
+
|
||||
+
|
||||
+class FooTestNsHandler(QnameQtypeHandler, StaticResponseHandler):
|
||||
+ qnames = ["foo.test."]
|
||||
+ qtypes = [rdatatype.NS]
|
||||
+ answer = [build_rrset("foo.test.", rdatatype.NS, "ns.foo.test.")]
|
||||
+ additional = [build_rrset("ns.foo.test.", rdatatype.A, "10.53.0.2")]
|
||||
+
|
||||
+
|
||||
+class DelayedDnameNegHandler(QnameQtypeHandler, StaticResponseHandler):
|
||||
+ qnames = ["foo.test."]
|
||||
+ qtypes = [rdatatype.DNAME]
|
||||
+ authority = [
|
||||
+ build_rrset(
|
||||
+ "foo.test.",
|
||||
+ rdatatype.SOA,
|
||||
+ "ns.test. op.ns.test. 2081509183 86400 3600 3600000 300",
|
||||
+ )
|
||||
+ ]
|
||||
+
|
||||
+ async def get_responses(
|
||||
+ self, qctx: QueryContext
|
||||
+ ) -> AsyncGenerator[DnsResponseSend, None]:
|
||||
+ await _hold_until_positive_cached(_dname_positive_sent)
|
||||
+ async for response in super().get_responses(qctx):
|
||||
+ yield response
|
||||
+
|
||||
+
|
||||
+class DnamePosHandler(QnameQtypeHandler, StaticResponseHandler):
|
||||
+ qnames = ["a.foo.test."]
|
||||
+ qtypes = [rdatatype.A]
|
||||
+ answer = [
|
||||
+ build_rrset("foo.test.", rdatatype.DNAME, "bar.test."),
|
||||
+ build_rrset("a.foo.test.", rdatatype.CNAME, "a.bar.test."),
|
||||
+ ]
|
||||
+
|
||||
+ async def get_responses(
|
||||
+ self, qctx: QueryContext
|
||||
+ ) -> AsyncGenerator[DnsResponseSend, None]:
|
||||
+ async for response in super().get_responses(qctx):
|
||||
+ yield response
|
||||
+ _dname_positive_sent.set()
|
||||
+
|
||||
+
|
||||
+class CnameHandler(QnameQtypeHandler):
|
||||
+ qnames = ["cname.foo.test."]
|
||||
+ qtypes = [rdatatype.CNAME, rdatatype.A]
|
||||
+ answer = [build_rrset("cname.foo.test.", rdatatype.CNAME, "cname.foo.test.")]
|
||||
+ authority = [
|
||||
+ build_rrset(
|
||||
+ "cname.foo.test.",
|
||||
+ rdatatype.SOA,
|
||||
+ "ns.test. op.ns.test. 2081509183 86400 3600 3600000 300",
|
||||
+ )
|
||||
+ ]
|
||||
+
|
||||
+ async def get_responses(
|
||||
+ self, qctx: QueryContext
|
||||
+ ) -> AsyncGenerator[DnsResponseSend, None]:
|
||||
+ if qctx.qtype == rdatatype.CNAME:
|
||||
+ await _hold_until_positive_cached(_cname_positive_sent)
|
||||
+ qctx.prepare_new_response(with_zone_data=False)
|
||||
+ qctx.response.authority.extend(self.authority)
|
||||
+ yield DnsResponseSend(qctx.response, authoritative=True)
|
||||
+ else:
|
||||
+ qctx.prepare_new_response(with_zone_data=False)
|
||||
+ qctx.response.answer.extend(self.answer)
|
||||
+ yield DnsResponseSend(qctx.response, authoritative=True)
|
||||
+ _cname_positive_sent.set()
|
||||
+
|
||||
+
|
||||
+def main() -> None:
|
||||
+ server = AsyncDnsServer(default_aa=True, default_rcode=rcode.NOERROR)
|
||||
+ server.install_response_handlers(
|
||||
+ FooTestNsHandler(), DelayedDnameNegHandler(), DnamePosHandler(), CnameHandler()
|
||||
+ )
|
||||
+ server.run()
|
||||
+
|
||||
+
|
||||
+if __name__ == "__main__":
|
||||
+ main()
|
||||
diff --git a/bin/tests/system/cname_dname_negcache/common.py b/bin/tests/system/cname_dname_negcache/common.py
|
||||
new file mode 100644
|
||||
index 0000000000..397cfdfa3d
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/cname_dname_negcache/common.py
|
||||
@@ -0,0 +1,46 @@
|
||||
+# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
+#
|
||||
+# SPDX-License-Identifier: MPL-2.0
|
||||
+#
|
||||
+# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
+# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
+# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
+#
|
||||
+# See the COPYRIGHT file distributed with this work for additional
|
||||
+# information regarding copyright ownership.
|
||||
+
|
||||
+from os import environ
|
||||
+from re import compile as Re
|
||||
+from re import escape
|
||||
+from socket import AF_INET, SOCK_DGRAM, socket
|
||||
+
|
||||
+import isctest
|
||||
+
|
||||
+
|
||||
+def run_attack(ns, name1, type1, name2, type2):
|
||||
+ msg1 = isctest.query.create(name1, type1, cd=True)
|
||||
+ msg2 = isctest.query.create(name2, type2, cd=True)
|
||||
+ port = int(environ["PORT"])
|
||||
+
|
||||
+ with socket(AF_INET, SOCK_DGRAM) as sock:
|
||||
+ # The order the requests go out doesn't matter. What is important is
|
||||
+ # that the first query starts recursion before the second query returns
|
||||
+ # the answer, and the second query returns the answer before the first
|
||||
+ # query returns the answer. (So, when the NOERROR/NODATA comes back from
|
||||
+ # the first query, the cache is queried and we get the positive response
|
||||
+ # cached from the second query attached to the fresp rdataset of the
|
||||
+ # response of the first query.)
|
||||
+ # That ordering is enforced by ans2, which holds back the negative
|
||||
+ # answer to the first query until it has answered the second one (see
|
||||
+ # ans2/ans.py); the resolver must not crash while reconciling them.
|
||||
+ sock.sendto(msg1.to_wire(), (ns.ip, port))
|
||||
+ sock.sendto(msg2.to_wire(), (ns.ip, port))
|
||||
+
|
||||
+ # The second query comes back immediately, the resolver caches the DNAME.
|
||||
+ # The first query comes back shortly after, once ans2 has released the
|
||||
+ # negative answer, and should not crash the server. Wait for the negative
|
||||
+ # SOA for this specific name (not just any foo.test. one) so the test cannot
|
||||
+ # pass on an unrelated record.
|
||||
+ soa = Re(rf"(?<![\w.]){escape(name1)}.*IN\s+SOA\s+ns\.test\.\s+op\.ns\.test\.")
|
||||
+ with ns.watch_log_from_start(timeout=15) as watcher:
|
||||
+ watcher.wait_for_sequence([soa])
|
||||
diff --git a/bin/tests/system/cname_dname_negcache/ns1/bar.test.db b/bin/tests/system/cname_dname_negcache/ns1/bar.test.db
|
||||
new file mode 100644
|
||||
index 0000000000..840b9c3a2c
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/cname_dname_negcache/ns1/bar.test.db
|
||||
@@ -0,0 +1,5 @@
|
||||
+$TTL 300
|
||||
+bar.test. IN SOA ns.bar.test. hostmaster.bar.test. 1 600 600 1200 600
|
||||
+bar.test. NS ns.bar.test.
|
||||
+ns A 10.53.0.1
|
||||
+a A 10.0.0.1
|
||||
diff --git a/bin/tests/system/cname_dname_negcache/ns1/named.conf.j2 b/bin/tests/system/cname_dname_negcache/ns1/named.conf.j2
|
||||
new file mode 100644
|
||||
index 0000000000..d72dd1181d
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/cname_dname_negcache/ns1/named.conf.j2
|
||||
@@ -0,0 +1,24 @@
|
||||
+options {
|
||||
+ query-source address @ns.ip@;
|
||||
+ port @PORT@;
|
||||
+ pid-file "named.pid";
|
||||
+ listen-on { @ns.ip@; };
|
||||
+ listen-on-v6 { none; };
|
||||
+ recursion no;
|
||||
+ dnssec-validation no;
|
||||
+};
|
||||
+
|
||||
+zone "." {
|
||||
+ type primary;
|
||||
+ file "root.db";
|
||||
+};
|
||||
+
|
||||
+zone "test." {
|
||||
+ type primary;
|
||||
+ file "test.db";
|
||||
+};
|
||||
+
|
||||
+zone "bar.test." {
|
||||
+ type primary;
|
||||
+ file "bar.test.db";
|
||||
+};
|
||||
diff --git a/bin/tests/system/cname_dname_negcache/ns1/root.db b/bin/tests/system/cname_dname_negcache/ns1/root.db
|
||||
new file mode 100644
|
||||
index 0000000000..c456c45b9d
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/cname_dname_negcache/ns1/root.db
|
||||
@@ -0,0 +1,6 @@
|
||||
+$TTL 300
|
||||
+. IN SOA ns. hostmaster. 1 600 600 1200 600
|
||||
+. NS a.root-servers.nil.
|
||||
+a.root-servers.nil. A 10.53.0.1
|
||||
+test NS ns.test
|
||||
+ns.test A 10.53.0.1
|
||||
diff --git a/bin/tests/system/cname_dname_negcache/ns1/test.db b/bin/tests/system/cname_dname_negcache/ns1/test.db
|
||||
new file mode 100644
|
||||
index 0000000000..acb68e00f8
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/cname_dname_negcache/ns1/test.db
|
||||
@@ -0,0 +1,8 @@
|
||||
+$TTL 300
|
||||
+test. IN SOA ns.test. hostmaster.test. 1 600 600 1200 600
|
||||
+test. NS ns.test.
|
||||
+ns A 10.53.0.1
|
||||
+bar NS ns.bar
|
||||
+ns.bar A 10.53.0.1
|
||||
+foo NS ns.foo
|
||||
+ns.foo A 10.53.0.2
|
||||
diff --git a/bin/tests/system/cname_dname_negcache/ns3/named.conf.j2 b/bin/tests/system/cname_dname_negcache/ns3/named.conf.j2
|
||||
new file mode 100644
|
||||
index 0000000000..197d72756b
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/cname_dname_negcache/ns3/named.conf.j2
|
||||
@@ -0,0 +1,11 @@
|
||||
+options {
|
||||
+ query-source address @ns.ip@;
|
||||
+ port @PORT@;
|
||||
+ pid-file "named.pid";
|
||||
+ listen-on { @ns.ip@; };
|
||||
+ listen-on-v6 { none; };
|
||||
+ recursion yes;
|
||||
+ dnssec-validation no;
|
||||
+};
|
||||
+
|
||||
+{% include "_common/root.hint.conf" %}
|
||||
diff --git a/bin/tests/system/cname_dname_negcache/tests_cname_negcache.py b/bin/tests/system/cname_dname_negcache/tests_cname_negcache.py
|
||||
new file mode 100644
|
||||
index 0000000000..a546d29109
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/cname_dname_negcache/tests_cname_negcache.py
|
||||
@@ -0,0 +1,16 @@
|
||||
+# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
+#
|
||||
+# SPDX-License-Identifier: MPL-2.0
|
||||
+#
|
||||
+# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
+# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
+# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
+#
|
||||
+# See the COPYRIGHT file distributed with this work for additional
|
||||
+# information regarding copyright ownership.
|
||||
+
|
||||
+from cname_dname_negcache.common import run_attack
|
||||
+
|
||||
+
|
||||
+def test_cname_negcache(ns3):
|
||||
+ run_attack(ns3, "cname.foo.test.", "CNAME", "cname.foo.test.", "A")
|
||||
diff --git a/bin/tests/system/cname_dname_negcache/tests_dname_negcache.py b/bin/tests/system/cname_dname_negcache/tests_dname_negcache.py
|
||||
new file mode 100644
|
||||
index 0000000000..41a80b4e05
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/cname_dname_negcache/tests_dname_negcache.py
|
||||
@@ -0,0 +1,16 @@
|
||||
+# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
+#
|
||||
+# SPDX-License-Identifier: MPL-2.0
|
||||
+#
|
||||
+# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
+# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
+# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
+#
|
||||
+# See the COPYRIGHT file distributed with this work for additional
|
||||
+# information regarding copyright ownership.
|
||||
+
|
||||
+from cname_dname_negcache.common import run_attack
|
||||
+
|
||||
+
|
||||
+def test_dname_negcache(ns3):
|
||||
+ run_attack(ns3, "foo.test.", "DNAME", "a.foo.test.", "A")
|
||||
--
|
||||
2.55.0
|
||||
|
||||
280
bind-9.18-CVE-2026-12617.patch
Normal file
280
bind-9.18-CVE-2026-12617.patch
Normal file
|
|
@ -0,0 +1,280 @@
|
|||
From 3138886f3767c0a6b933fd147c5465472209bac6 Mon Sep 17 00:00:00 2001
|
||||
From: Colin Vidal <colin@isc.org>
|
||||
Date: Thu, 18 Jun 2026 18:17:05 +0200
|
||||
Subject: [PATCH] Do not assert in some CNAME/DNAME queries
|
||||
|
||||
Fix a `named` crash because of a fail assertion for certains types of
|
||||
CNAME and DNAME queries:
|
||||
|
||||
- If a client queries for a DNAME and A record to the resolver, and the
|
||||
authoritative server responds positively to the A query but delay the
|
||||
DNAME response and respond later negatively;
|
||||
|
||||
- If a client queries for a CNAME and A record to the resolver, and the
|
||||
authoritative server responds positively to the A query but delay the
|
||||
CNAME response and respond later with a self-referential CNAME.
|
||||
|
||||
The first scenario consists of sending two queries: `foo.test./DNAME`
|
||||
and `a.foo.test./A`. The authoritative server delays the answer for
|
||||
`foo.test./DNAME` but immediately answers the DNAME record for the
|
||||
second query: `foo.test. DNAME bar.test.`. The resolver caches it,
|
||||
follows the DNAME, and resolves `a.bar.test./A`. The authoritative
|
||||
server eventually answers negatively for `foo.test./DNAME`
|
||||
(NOERROR/NODATA, with only an SOA in the authority section). The
|
||||
resolver pulls out the previously cached rdataset (because it has a
|
||||
higher trust level than the received negative answer), and wrongly (this
|
||||
is the first bug) sets the result to `DNS_R_DNAME` instead of
|
||||
`ISC_R_SUCCESS`. The code in `ns/query.c` that handles the resolver
|
||||
result interprets this as "this is a non-DNAME query and we got a DNAME
|
||||
rdataset, so follow the chain". It goes into the `query_dname()`
|
||||
function, which asserts that the qname is a subdomain of the owner name
|
||||
in the rdataset. That assertion fails because the qname (`foo.test.`) is
|
||||
exactly equal to the owner name of the DNAME (`foo.test.`), rather than
|
||||
being a subdomain of it. `DNS_R_DNAME` must only be set when the qtype
|
||||
is something other than DNAME and the resolver has obtained a DNAME that
|
||||
needs to be followed.
|
||||
|
||||
The second scenario consists of sending two queries:
|
||||
`cname.foo.test./CNAME` and `cname.foo.test./A`. The authoritative
|
||||
server delays the answer for `cname.foo.test./CNAME` but immediately
|
||||
answers the CNAME record for the second query: `cname.foo.test. CNAME
|
||||
cname.foo.test.`. Note that the CNAME is self-referential. The resolver
|
||||
caches it and sets the result code to `DNS_R_CNAME`. Then `ns/query.c`
|
||||
interprets this as "this is a non-CNAME query and we got a CNAME
|
||||
rdataset, so follow the chain" (which is correct in this case; however,
|
||||
because the CNAME rdataset is self-referential, the resolver responds
|
||||
with SERVFAIL, which is expected). The authoritative server eventually
|
||||
answers negatively for `cname.foo.test./CNAME`. The resolver then pulls
|
||||
out the previously cached CNAME rdataset (obtained from the A answer,
|
||||
even though it was self-referential, the resolver cached it) and wrongly
|
||||
sets the result to `DNS_R_CNAME` (this is the second bug). As noted
|
||||
above, `ns/query.c` interprets this as "this is a non-CNAME query and we
|
||||
got a CNAME rdataset, so follow the chain". The internals here are
|
||||
slightly more subtle: it first goes into `query_cname()` and sets the
|
||||
CNAME rdataset in the message answer section, then restarts the query to
|
||||
follow the CNAME. The restart retrieves the CNAME rdataset from the
|
||||
cache directly (without going to the resolver), and this time the query
|
||||
context result is `ISC_R_SUCCESS` (since it was found) and
|
||||
`qctx->rdataset` points to the same CNAME again (as it is
|
||||
self-referential), so it goes directly into the
|
||||
`query_prepresponse()/query_respond()` flow, which attempts to add the
|
||||
rdataset to the message answer again. However, this fails because the
|
||||
rdataset is already in the message, and the assertion which expects that
|
||||
operation to succeed fails (due to `qctx->rdataset` being set to `NULL`
|
||||
when ownership of the rdataset was transferred). `DNS_R_CNAME` must only
|
||||
be set when the qtype is something other than CNAME and the resolver has
|
||||
obtained a CNAME that needs to be followed.
|
||||
|
||||
In both cases, the correct answer from the resolver should have been
|
||||
`ISC_R_SUCCESS` (instead of respectively `DNS_R_DNAME` and
|
||||
`DNS_R_CNAME`) becuase the rdataset that has been looked up was found.
|
||||
|
||||
(cherry picked from commit 773d46d58c693047a5945c8fe40512edd0ac214e)
|
||||
(cherry picked from commit c740c37689f234e21a9b0ef760471ef2cf1133f5)
|
||||
---
|
||||
lib/dns/resolver.c | 137 ++++++++++++++++++++-------------------------
|
||||
1 file changed, 60 insertions(+), 77 deletions(-)
|
||||
|
||||
diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c
|
||||
index edc9c207e1..1f8b5058d1 100644
|
||||
--- a/lib/dns/resolver.c
|
||||
+++ b/lib/dns/resolver.c
|
||||
@@ -692,10 +692,10 @@ fctx_destroy(fetchctx_t *fctx, bool exiting);
|
||||
static void
|
||||
send_shutdown_events(dns_resolver_t *res);
|
||||
static isc_result_t
|
||||
-ncache_adderesult(dns_message_t *message, dns_db_t *cache, dns_dbnode_t *node,
|
||||
- dns_rdatatype_t covers, isc_stdtime_t now, dns_ttl_t minttl,
|
||||
- dns_ttl_t maxttl, bool optout, bool secure,
|
||||
- dns_rdataset_t *ardataset, isc_result_t *eresultp);
|
||||
+ncache_adderesult(fetchctx_t *fctx, dns_message_t *message, dns_dbnode_t *node,
|
||||
+ dns_rdatatype_t covers, isc_stdtime_t now, dns_ttl_t maxttl,
|
||||
+ bool optout, bool secure, dns_rdataset_t *ardataset,
|
||||
+ isc_result_t *eresultp);
|
||||
static void
|
||||
validated(isc_task_t *task, isc_event_t *event);
|
||||
static void
|
||||
@@ -5563,6 +5563,46 @@ has_000_label(dns_rdataset_t *nsecset) {
|
||||
return false;
|
||||
}
|
||||
|
||||
+/*
|
||||
+ * After a (non-error) negative-cache add, 'rdataset' is bound to whatever
|
||||
+ * rdataset the cache authoritatively holds for the queried name and type.
|
||||
+ * Map that to the result code the fetch should report:
|
||||
+ *
|
||||
+ * - A negative cache entry (the one we just added, or a pre-existing one):
|
||||
+ * DNS_R_NCACHENXDOMAIN or DNS_R_NCACHENXRRSET, depending on NXDOMAIN vs
|
||||
+ * NODATA.
|
||||
+ *
|
||||
+ * - A positive rdataset that was already cached at higher trust, which
|
||||
+ * caused our negative entry to be discarded (e.g. a CNAME or DNAME cached
|
||||
+ * by a concurrent query): ISC_R_SUCCESS, because that cached positive
|
||||
+ * answer is what gets returned. Note the specific case for CNAME and
|
||||
+ * DNAME *if* the query type is not the same as the rdataset type. There
|
||||
+ * is a chain to follow *only* if the query type doesn't ask for the CNAME
|
||||
+ * or the DNAME.
|
||||
+ */
|
||||
+static isc_result_t
|
||||
+fctx_setresult(fetchctx_t *fctx, dns_rdataset_t *rdataset) {
|
||||
+ isc_result_t result = ISC_R_SUCCESS;
|
||||
+
|
||||
+ if (NEGATIVE(rdataset)) {
|
||||
+ result = NXDOMAIN(rdataset) ? DNS_R_NCACHENXDOMAIN
|
||||
+ : DNS_R_NCACHENXRRSET;
|
||||
+ } else if (result == ISC_R_SUCCESS && rdataset->type != fctx->type) {
|
||||
+ switch (rdataset->type) {
|
||||
+ case dns_rdatatype_cname:
|
||||
+ result = DNS_R_CNAME;
|
||||
+ break;
|
||||
+ case dns_rdatatype_dname:
|
||||
+ result = DNS_R_DNAME;
|
||||
+ break;
|
||||
+ default:
|
||||
+ break;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ return result;
|
||||
+}
|
||||
+
|
||||
/*
|
||||
* The validator has finished.
|
||||
*/
|
||||
@@ -5836,8 +5876,7 @@ validated(isc_task_t *task, isc_event_t *event) {
|
||||
ttl = 0;
|
||||
}
|
||||
|
||||
- result = ncache_adderesult(message, fctx->cache, node, covers,
|
||||
- now, fctx->res->view->minncachettl,
|
||||
+ result = ncache_adderesult(fctx, message, node, covers, now,
|
||||
ttl, vevent->optout, vevent->secure,
|
||||
ardataset, &eresult);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
@@ -6081,23 +6120,7 @@ answer_response:
|
||||
*/
|
||||
INSIST(hevent->rdataset != NULL);
|
||||
if (dns_rdataset_isassociated(hevent->rdataset)) {
|
||||
- if (NEGATIVE(hevent->rdataset)) {
|
||||
- INSIST(eresult == DNS_R_NCACHENXDOMAIN ||
|
||||
- eresult == DNS_R_NCACHENXRRSET);
|
||||
- } else if (eresult == ISC_R_SUCCESS &&
|
||||
- hevent->rdataset->type != fctx->type)
|
||||
- {
|
||||
- switch (hevent->rdataset->type) {
|
||||
- case dns_rdatatype_cname:
|
||||
- eresult = DNS_R_CNAME;
|
||||
- break;
|
||||
- case dns_rdatatype_dname:
|
||||
- eresult = DNS_R_DNAME;
|
||||
- break;
|
||||
- default:
|
||||
- break;
|
||||
- }
|
||||
- }
|
||||
+ eresult = fctx_setresult(fctx, hevent->rdataset);
|
||||
}
|
||||
|
||||
hevent->result = eresult;
|
||||
@@ -6747,24 +6770,7 @@ cache_name(fetchctx_t *fctx, dns_name_t *name, dns_message_t *message,
|
||||
* event->result.
|
||||
*/
|
||||
if (dns_rdataset_isassociated(event->rdataset)) {
|
||||
- if (NEGATIVE(event->rdataset)) {
|
||||
- INSIST(eresult ==
|
||||
- DNS_R_NCACHENXDOMAIN ||
|
||||
- eresult == DNS_R_NCACHENXRRSET);
|
||||
- } else if (eresult == ISC_R_SUCCESS &&
|
||||
- event->rdataset->type != fctx->type)
|
||||
- {
|
||||
- switch (event->rdataset->type) {
|
||||
- case dns_rdatatype_cname:
|
||||
- eresult = DNS_R_CNAME;
|
||||
- break;
|
||||
- case dns_rdatatype_dname:
|
||||
- eresult = DNS_R_DNAME;
|
||||
- break;
|
||||
- default:
|
||||
- break;
|
||||
- }
|
||||
- }
|
||||
+ eresult = fctx_setresult(fctx, event->rdataset);
|
||||
}
|
||||
event->result = eresult;
|
||||
if (adbp != NULL && *adbp != NULL) {
|
||||
@@ -6833,12 +6839,14 @@ cache_message(fetchctx_t *fctx, dns_message_t *message,
|
||||
* eresult.
|
||||
*/
|
||||
static isc_result_t
|
||||
-ncache_adderesult(dns_message_t *message, dns_db_t *cache, dns_dbnode_t *node,
|
||||
- dns_rdatatype_t covers, isc_stdtime_t now, dns_ttl_t minttl,
|
||||
- dns_ttl_t maxttl, bool optout, bool secure,
|
||||
- dns_rdataset_t *ardataset, isc_result_t *eresultp) {
|
||||
+ncache_adderesult(fetchctx_t *fctx, dns_message_t *message, dns_dbnode_t *node,
|
||||
+ dns_rdatatype_t covers, isc_stdtime_t now, dns_ttl_t maxttl,
|
||||
+ bool optout, bool secure, dns_rdataset_t *ardataset,
|
||||
+ isc_result_t *eresultp) {
|
||||
isc_result_t result;
|
||||
dns_rdataset_t rdataset;
|
||||
+ dns_db_t *cache = fctx->cache;
|
||||
+ dns_ttl_t minttl = fctx->res->view->minncachettl;
|
||||
|
||||
if (ardataset == NULL) {
|
||||
dns_rdataset_init(&rdataset);
|
||||
@@ -6854,37 +6862,13 @@ ncache_adderesult(dns_message_t *message, dns_db_t *cache, dns_dbnode_t *node,
|
||||
}
|
||||
if (result == DNS_R_UNCHANGED || result == ISC_R_SUCCESS) {
|
||||
/*
|
||||
- * If the cache now contains a negative entry and we
|
||||
- * care about whether it is DNS_R_NCACHENXDOMAIN or
|
||||
- * DNS_R_NCACHENXRRSET then extract it.
|
||||
+ * The cache settled successfully (DNS_R_UNCHANGED means our
|
||||
+ * negative entry was discarded in favour of existing
|
||||
+ * higher-trust data). Either way 'ardataset' is now bound to
|
||||
+ * the rdataset the cache holds for this name and type; derive
|
||||
+ * the result code from it.
|
||||
*/
|
||||
- if (NEGATIVE(ardataset)) {
|
||||
- /*
|
||||
- * The cache data is a negative cache entry.
|
||||
- */
|
||||
- if (NXDOMAIN(ardataset)) {
|
||||
- *eresultp = DNS_R_NCACHENXDOMAIN;
|
||||
- } else {
|
||||
- *eresultp = DNS_R_NCACHENXRRSET;
|
||||
- }
|
||||
- } else {
|
||||
- /*
|
||||
- * The attempt to add a negative cache entry
|
||||
- * was rejected. Set *eresultp to reflect
|
||||
- * the type of the dataset being returned.
|
||||
- */
|
||||
- switch (ardataset->type) {
|
||||
- case dns_rdatatype_cname:
|
||||
- *eresultp = DNS_R_CNAME;
|
||||
- break;
|
||||
- case dns_rdatatype_dname:
|
||||
- *eresultp = DNS_R_DNAME;
|
||||
- break;
|
||||
- default:
|
||||
- *eresultp = ISC_R_SUCCESS;
|
||||
- break;
|
||||
- }
|
||||
- }
|
||||
+ *eresultp = fctx_setresult(fctx, ardataset);
|
||||
result = ISC_R_SUCCESS;
|
||||
}
|
||||
if (ardataset == &rdataset && dns_rdataset_isassociated(ardataset)) {
|
||||
@@ -7029,8 +7013,7 @@ ncache_message(fetchctx_t *fctx, dns_message_t *message,
|
||||
ttl = 0;
|
||||
}
|
||||
|
||||
- result = ncache_adderesult(message, fctx->cache, node, covers, now,
|
||||
- fctx->res->view->minncachettl, ttl, false,
|
||||
+ result = ncache_adderesult(fctx, message, node, covers, now, ttl, false,
|
||||
false, ardataset, &eresult);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto unlock;
|
||||
--
|
||||
2.55.0
|
||||
|
||||
416
bind-9.18-CVE-2026-13204-test.patch
Normal file
416
bind-9.18-CVE-2026-13204-test.patch
Normal file
|
|
@ -0,0 +1,416 @@
|
|||
From 89e950d215e9922e5af6e3c69b9d6a8750346bb6 Mon Sep 17 00:00:00 2001
|
||||
From: Alessio Podda <alessio@isc.org>
|
||||
Date: Fri, 12 Jun 2026 11:16:01 +0200
|
||||
Subject: [PATCH] Reproducer for #5985 addnoqname mismatch
|
||||
|
||||
LLM generated.
|
||||
|
||||
(cherry picked from commit 5f4de929b3e4749b6e32c51660be11c47c2514e6)
|
||||
(cherry picked from commit 0cf010c153518f1f9831e201891ecba8d8ba65e1)
|
||||
|
||||
Update reproducer #5985
|
||||
|
||||
Update the llm generated reproducer:
|
||||
- Move server.py into ans/ans1.py
|
||||
- Remove unncessary named.conf configuration options
|
||||
- Add comments describing the steps
|
||||
- Rename system test
|
||||
|
||||
(cherry picked from commit fd539807829dd7d2eb76c8b503083f5d84fec6f0)
|
||||
(cherry picked from commit 6c0e599ea85c0c53a4af09742e64e193da089bb4)
|
||||
---
|
||||
.../dnssec_findnoqname_mismatch/ans1/ans.py | 207 ++++++++++++++++++
|
||||
.../ns2/named.conf.j2 | 33 +++
|
||||
.../tests_findnoqname_mismatch.py | 126 +++++++++++
|
||||
3 files changed, 366 insertions(+)
|
||||
create mode 100644 bin/tests/system/dnssec_findnoqname_mismatch/ans1/ans.py
|
||||
create mode 100644 bin/tests/system/dnssec_findnoqname_mismatch/ns2/named.conf.j2
|
||||
create mode 100644 bin/tests/system/dnssec_findnoqname_mismatch/tests_findnoqname_mismatch.py
|
||||
|
||||
diff --git a/bin/tests/system/dnssec_findnoqname_mismatch/ans1/ans.py b/bin/tests/system/dnssec_findnoqname_mismatch/ans1/ans.py
|
||||
new file mode 100644
|
||||
index 0000000000..b36fc831c8
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/dnssec_findnoqname_mismatch/ans1/ans.py
|
||||
@@ -0,0 +1,207 @@
|
||||
+#!/usr/bin/python3
|
||||
+
|
||||
+# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
+#
|
||||
+# SPDX-License-Identifier: MPL-2.0
|
||||
+
|
||||
+from collections.abc import AsyncGenerator
|
||||
+from dataclasses import dataclass
|
||||
+from datetime import datetime, timedelta, timezone
|
||||
+from pathlib import Path
|
||||
+
|
||||
+import base64
|
||||
+import json
|
||||
+
|
||||
+from cryptography.hazmat.primitives import serialization
|
||||
+
|
||||
+import dns.dnssec
|
||||
+import dns.flags
|
||||
+import dns.message
|
||||
+import dns.name
|
||||
+import dns.rdata
|
||||
+import dns.rdataclass
|
||||
+import dns.rcode
|
||||
+import dns.rdatatype
|
||||
+import dns.rrset
|
||||
+
|
||||
+from isctest.asyncserver import (
|
||||
+ AsyncDnsServer,
|
||||
+ DnsResponseSend,
|
||||
+ QueryContext,
|
||||
+ ResponseHandler,
|
||||
+)
|
||||
+
|
||||
+TTL = 300
|
||||
+ZONE = "f217.test."
|
||||
+CHILD = f"evil.{ZONE}"
|
||||
+ATTACK = f"www.{CHILD}"
|
||||
+NSEC_OWNER = f"00000000.{CHILD}"
|
||||
+NSEC_NEXT = f"zzz.{CHILD}"
|
||||
+FORGED_A = "192.0.2.217"
|
||||
+
|
||||
+
|
||||
+@dataclass(frozen=True)
|
||||
+class Key:
|
||||
+ zone: dns.name.Name
|
||||
+ private_key: object
|
||||
+ dnskey: dns.rdata.Rdata
|
||||
+
|
||||
+
|
||||
+def name(text: str) -> dns.name.Name:
|
||||
+ return dns.name.from_text(text)
|
||||
+
|
||||
+
|
||||
+def load_key() -> Key:
|
||||
+ path = Path(__file__).resolve().parent / "keys.json"
|
||||
+ with path.open(encoding="utf-8") as keys_file:
|
||||
+ raw_key = json.load(keys_file)[ZONE]
|
||||
+
|
||||
+ private_key = serialization.load_pem_private_key(
|
||||
+ raw_key["private_pem"].encode("ascii"),
|
||||
+ password=None,
|
||||
+ )
|
||||
+ dnskey = dns.rdata.from_text(
|
||||
+ dns.rdataclass.IN, dns.rdatatype.DNSKEY, raw_key["dnskey"]
|
||||
+ )
|
||||
+ return Key(name(ZONE), private_key, dnskey)
|
||||
+
|
||||
+
|
||||
+def rrset(owner: str, rdtype: dns.rdatatype.RdataType, *rdatas: str) -> dns.rrset.RRset:
|
||||
+ return dns.rrset.from_text(owner, TTL, dns.rdataclass.IN, rdtype, *rdatas)
|
||||
+
|
||||
+
|
||||
+def rrset_from_rdata(owner: str, rdata: dns.rdata.Rdata) -> dns.rrset.RRset:
|
||||
+ return dns.rrset.from_rdata(name(owner), TTL, rdata)
|
||||
+
|
||||
+
|
||||
+def add_signed(
|
||||
+ section: list[dns.rrset.RRset], covered: dns.rrset.RRset, signer: Key
|
||||
+) -> None:
|
||||
+ rrsig = dns.dnssec.sign(
|
||||
+ covered,
|
||||
+ signer.private_key,
|
||||
+ signer.zone,
|
||||
+ signer.dnskey,
|
||||
+ lifetime=86400,
|
||||
+ verify=True,
|
||||
+ )
|
||||
+ section.append(covered)
|
||||
+ section.append(dns.rrset.from_rdata(covered.name, covered.ttl, rrsig))
|
||||
+
|
||||
+
|
||||
+def soa_rrset(zone: str) -> dns.rrset.RRset:
|
||||
+ return rrset(
|
||||
+ zone,
|
||||
+ dns.rdatatype.SOA,
|
||||
+ f"ns.{ZONE} hostmaster.{ZONE} 1 7200 3600 1209600 300",
|
||||
+ )
|
||||
+
|
||||
+
|
||||
+def garbage_rrsig(
|
||||
+ owner: str, covered: dns.rdatatype.RdataType, labels: int, signer: str
|
||||
+) -> dns.rrset.RRset:
|
||||
+ now = datetime.now(timezone.utc)
|
||||
+ inception = (now - timedelta(hours=1)).strftime("%Y%m%d%H%M%S")
|
||||
+ expiration = (now + timedelta(days=1)).strftime("%Y%m%d%H%M%S")
|
||||
+ signature = base64.b64encode(bytes(64)).decode("ascii")
|
||||
+ text = (
|
||||
+ f"{dns.rdatatype.to_text(covered)} 13 {labels} {TTL} "
|
||||
+ f"{expiration} {inception} 12345 {signer} {signature}"
|
||||
+ )
|
||||
+ rdata = dns.rdata.from_text(dns.rdataclass.IN, dns.rdatatype.RRSIG, text)
|
||||
+ return dns.rrset.from_rdata(name(owner), TTL, rdata)
|
||||
+
|
||||
+
|
||||
+def add_ds_denial(response: dns.message.Message, key: Key) -> None:
|
||||
+ add_signed(response.authority, soa_rrset(ZONE), key)
|
||||
+ nsec = rrset(CHILD, dns.rdatatype.NSEC, f"ns.{ZONE} NS RRSIG NSEC")
|
||||
+ add_signed(response.authority, nsec, key)
|
||||
+
|
||||
+
|
||||
+def add_attack_answer(response: dns.message.Message) -> None:
|
||||
+ """
|
||||
+ Crafted authoritative response to <q>.evil.f217.hack./A
|
||||
+
|
||||
+ ;; ANSWER
|
||||
+ <q>.evil.f217.hack. 300 IN A 192.0.2.217
|
||||
+ <q>.evil.f217.hack. 300 IN RRSIG A 13 1 300 <exp> <inc> 12345 evil.f217.hack. <base64 of 64×0x00>
|
||||
+ ^^^ Labels = 1, qname has 4 labels, wildcard heuristic fires
|
||||
+
|
||||
+ ;; AUTHORITY (single owner, three rdatasets in this wire order)
|
||||
+ 00000000.evil.f217.hack. 300 IN NSEC zzz.evil.f217.hack. A RRSIG NSEC
|
||||
+ 00000000.evil.f217.hack. 300 IN RRSIG NSEC 13 4 300 <exp> <inc> 12345 evil.f217.hack. <base64 of 64×0x00>
|
||||
+ 00000000.evil.f217.hack. 300 IN NSEC3 1 0 0 - VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV A RRSIG
|
||||
+ """
|
||||
+ # A + RRSIG
|
||||
+ response.answer.append(rrset(ATTACK, dns.rdatatype.A, FORGED_A))
|
||||
+ response.answer.append(garbage_rrsig(ATTACK, dns.rdatatype.A, 1, CHILD))
|
||||
+ # NSEC
|
||||
+ nsec = rrset(
|
||||
+ NSEC_OWNER,
|
||||
+ dns.rdatatype.NSEC,
|
||||
+ f"{NSEC_NEXT} A RRSIG NSEC",
|
||||
+ )
|
||||
+ response.authority.append(nsec)
|
||||
+ # RRSIG(NSEC)
|
||||
+ response.authority.append(
|
||||
+ garbage_rrsig(
|
||||
+ NSEC_OWNER,
|
||||
+ dns.rdatatype.NSEC,
|
||||
+ len(name(NSEC_OWNER).labels) - 1,
|
||||
+ CHILD,
|
||||
+ )
|
||||
+ )
|
||||
+ # NSEC3
|
||||
+ nsec3 = rrset(
|
||||
+ NSEC_OWNER,
|
||||
+ dns.rdatatype.NSEC3,
|
||||
+ "1 0 0 - VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV A RRSIG",
|
||||
+ )
|
||||
+ response.authority.append(nsec3)
|
||||
+
|
||||
+
|
||||
+class RuntimeCheckHandler(ResponseHandler):
|
||||
+ def __init__(self, key: Key) -> None:
|
||||
+ self.key = key
|
||||
+ self.zone = name(ZONE)
|
||||
+ self.child = name(CHILD)
|
||||
+ self.attack = name(ATTACK)
|
||||
+
|
||||
+ def match(self, qctx: QueryContext) -> bool:
|
||||
+ return qctx.qname.is_subdomain(self.zone)
|
||||
+
|
||||
+ async def get_responses(
|
||||
+ self, qctx: QueryContext
|
||||
+ ) -> AsyncGenerator[DnsResponseSend, None]:
|
||||
+ qctx.prepare_new_response(with_zone_data=False)
|
||||
+ qctx.response.flags |= dns.flags.AA
|
||||
+ qctx.response.set_rcode(dns.rcode.NOERROR)
|
||||
+
|
||||
+ if qctx.qname == self.zone and qctx.qtype == dns.rdatatype.DNSKEY:
|
||||
+ add_signed(
|
||||
+ qctx.response.answer,
|
||||
+ rrset_from_rdata(ZONE, self.key.dnskey),
|
||||
+ self.key,
|
||||
+ )
|
||||
+ elif qctx.qname == self.zone and qctx.qtype == dns.rdatatype.SOA:
|
||||
+ add_signed(qctx.response.answer, soa_rrset(ZONE), self.key)
|
||||
+ elif qctx.qname == self.child and qctx.qtype == dns.rdatatype.DS:
|
||||
+ add_ds_denial(qctx.response, self.key)
|
||||
+ elif qctx.qname == self.child and qctx.qtype == dns.rdatatype.DNSKEY:
|
||||
+ qctx.response.authority.append(soa_rrset(CHILD))
|
||||
+ elif qctx.qname == self.attack and qctx.qtype == dns.rdatatype.A:
|
||||
+ add_attack_answer(qctx.response)
|
||||
+ else:
|
||||
+ add_signed(qctx.response.authority, soa_rrset(ZONE), self.key)
|
||||
+
|
||||
+ yield DnsResponseSend(qctx.response, authoritative=True)
|
||||
+
|
||||
+
|
||||
+def main() -> None:
|
||||
+ server = AsyncDnsServer(default_aa=True)
|
||||
+ server.install_response_handlers(RuntimeCheckHandler(load_key()))
|
||||
+ server.run()
|
||||
+
|
||||
+
|
||||
+if __name__ == "__main__":
|
||||
+ main()
|
||||
diff --git a/bin/tests/system/dnssec_findnoqname_mismatch/ns2/named.conf.j2 b/bin/tests/system/dnssec_findnoqname_mismatch/ns2/named.conf.j2
|
||||
new file mode 100644
|
||||
index 0000000000..f4fbd8a617
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/dnssec_findnoqname_mismatch/ns2/named.conf.j2
|
||||
@@ -0,0 +1,33 @@
|
||||
+// validating resolver
|
||||
+
|
||||
+options {
|
||||
+ query-source address 10.53.0.2;
|
||||
+ notify-source 10.53.0.2;
|
||||
+ transfer-source 10.53.0.2;
|
||||
+ port @PORT@;
|
||||
+ pid-file "named.pid";
|
||||
+ listen-on { 10.53.0.2; };
|
||||
+ listen-on-v6 { none; };
|
||||
+ recursion yes;
|
||||
+ dnssec-validation yes;
|
||||
+};
|
||||
+
|
||||
+controls {
|
||||
+ inet 10.53.0.2 port @CONTROLPORT@ allow { any; } keys { rndc_key; };
|
||||
+};
|
||||
+
|
||||
+include "../../_common/rndc.key";
|
||||
+
|
||||
+zone "." {
|
||||
+ type hint;
|
||||
+ file "../../_common/root.hint";
|
||||
+};
|
||||
+
|
||||
+zone "f217.test" {
|
||||
+ type static-stub;
|
||||
+ server-addresses { 10.53.0.1; };
|
||||
+};
|
||||
+
|
||||
+trust-anchors {
|
||||
+ f217.test. static-key 257 3 13 "@ZONE_DNSKEY@";
|
||||
+};
|
||||
diff --git a/bin/tests/system/dnssec_findnoqname_mismatch/tests_findnoqname_mismatch.py b/bin/tests/system/dnssec_findnoqname_mismatch/tests_findnoqname_mismatch.py
|
||||
new file mode 100644
|
||||
index 0000000000..f3e332a360
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/dnssec_findnoqname_mismatch/tests_findnoqname_mismatch.py
|
||||
@@ -0,0 +1,126 @@
|
||||
+#!/usr/bin/python3
|
||||
+
|
||||
+# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
+#
|
||||
+# SPDX-License-Identifier: MPL-2.0
|
||||
+
|
||||
+from pathlib import Path
|
||||
+
|
||||
+import json
|
||||
+
|
||||
+from cryptography.hazmat.primitives import serialization
|
||||
+from cryptography.hazmat.primitives.asymmetric import ec
|
||||
+
|
||||
+import dns.dnssec
|
||||
+import dns.name
|
||||
+import dns.rdataclass
|
||||
+import dns.rdatatype
|
||||
+import pytest
|
||||
+
|
||||
+import isctest
|
||||
+import isctest.mark
|
||||
+
|
||||
+ZONE = "f217.test."
|
||||
+CHILD = f"evil.{ZONE}"
|
||||
+ATTACK = f"www.{CHILD}"
|
||||
+NSEC_OWNER = f"00000000.{CHILD}"
|
||||
+FORGED_A = "192.0.2.217"
|
||||
+AUTH = "10.53.0.1"
|
||||
+RESOLVER = "10.53.0.2"
|
||||
+
|
||||
+pytestmark = [
|
||||
+ isctest.mark.with_ecdsa_deterministic,
|
||||
+ pytest.mark.extra_artifacts(
|
||||
+ [
|
||||
+ "ans1/ans.run",
|
||||
+ "ans1/keys.json",
|
||||
+ ]
|
||||
+ ),
|
||||
+]
|
||||
+
|
||||
+
|
||||
+def _make_key():
|
||||
+ private_key = ec.generate_private_key(ec.SECP256R1())
|
||||
+ dnskey = dns.dnssec.make_dnskey(
|
||||
+ private_key.public_key(),
|
||||
+ algorithm="ECDSAP256SHA256",
|
||||
+ flags=257,
|
||||
+ )
|
||||
+ private_pem = private_key.private_bytes(
|
||||
+ encoding=serialization.Encoding.PEM,
|
||||
+ format=serialization.PrivateFormat.PKCS8,
|
||||
+ encryption_algorithm=serialization.NoEncryption(),
|
||||
+ ).decode("ascii")
|
||||
+ return {
|
||||
+ "private_pem": private_pem,
|
||||
+ "dnskey": dnskey.to_text(),
|
||||
+ }
|
||||
+
|
||||
+
|
||||
+def bootstrap():
|
||||
+ keys = {ZONE: _make_key()}
|
||||
+ Path("ans1/keys.json").write_text(json.dumps(keys, indent=2), encoding="ascii")
|
||||
+ zone_dnskey = "".join(keys[ZONE]["dnskey"].split()[3:])
|
||||
+ return {"ZONE_DNSKEY": zone_dnskey}
|
||||
+
|
||||
+
|
||||
+def _query(server, qname, qtype):
|
||||
+ query = isctest.query.create(qname, qtype)
|
||||
+ return isctest.query.tcp(query, server, attempts=1, timeout=5)
|
||||
+
|
||||
+
|
||||
+def _rrset(response, section, owner, rdtype, covers=None):
|
||||
+ if covers is None:
|
||||
+ return response.get_rrset(
|
||||
+ section, dns.name.from_text(owner), dns.rdataclass.IN, rdtype
|
||||
+ )
|
||||
+ return response.get_rrset(
|
||||
+ section,
|
||||
+ dns.name.from_text(owner),
|
||||
+ dns.rdataclass.IN,
|
||||
+ rdtype,
|
||||
+ covers=covers,
|
||||
+ )
|
||||
+
|
||||
+
|
||||
+def _has_a(response, section, owner, address):
|
||||
+ rrset = _rrset(response, section, owner, dns.rdatatype.A)
|
||||
+ return rrset is not None and any(rdata.address == address for rdata in rrset)
|
||||
+
|
||||
+
|
||||
+def _check_rrsig(response, section, owner, rdtype, signer, labels=None):
|
||||
+ rrsig = _rrset(response, section, owner, dns.rdatatype.RRSIG, covers=rdtype)
|
||||
+ assert rrsig is not None, response.to_text()
|
||||
+ assert rrsig[0].signer == dns.name.from_text(signer), response.to_text()
|
||||
+ if labels is not None:
|
||||
+ assert rrsig[0].labels == labels, response.to_text()
|
||||
+
|
||||
+
|
||||
+def test_malicious_findnoqname_addnoqname_mismatch():
|
||||
+ response = _query(AUTH, ATTACK, "A")
|
||||
+ isctest.check.noerror(response)
|
||||
+ assert _has_a(response, response.answer, ATTACK, FORGED_A), response.to_text()
|
||||
+ _check_rrsig(response, response.answer, ATTACK, dns.rdatatype.A, CHILD, labels=1)
|
||||
+
|
||||
+ # Has NSEC
|
||||
+ assert _rrset(response, response.authority, NSEC_OWNER, dns.rdatatype.NSEC)
|
||||
+ _check_rrsig(response, response.authority, NSEC_OWNER, dns.rdatatype.NSEC, CHILD)
|
||||
+ # Has NSEC3
|
||||
+ assert _rrset(response, response.authority, NSEC_OWNER, dns.rdatatype.NSEC3)
|
||||
+ assert (
|
||||
+ _rrset(
|
||||
+ response,
|
||||
+ response.authority,
|
||||
+ NSEC_OWNER,
|
||||
+ dns.rdatatype.RRSIG,
|
||||
+ covers=dns.rdatatype.NSEC3,
|
||||
+ )
|
||||
+ is None
|
||||
+ )
|
||||
+
|
||||
+
|
||||
+def test_resolver_findnoqname_addnoqname_mismatch():
|
||||
+ # Send one trigger query
|
||||
+ _query(RESOLVER, ATTACK, "A")
|
||||
+ response = _query(RESOLVER, ZONE, "SOA")
|
||||
+ isctest.check.noerror(response)
|
||||
--
|
||||
2.55.0
|
||||
|
||||
158
bind-9.18-CVE-2026-13204.patch
Normal file
158
bind-9.18-CVE-2026-13204.patch
Normal file
|
|
@ -0,0 +1,158 @@
|
|||
From 895cac04332d85489ddf881b28e18e9956f6e348 Mon Sep 17 00:00:00 2001
|
||||
From: Evan Hunt <each@isc.org>
|
||||
Date: Wed, 13 May 2026 20:45:57 -0700
|
||||
Subject: [PATCH] dns_rdataset_addnoqname() could find unsigned NSEC/NSEC3
|
||||
|
||||
The dns_rdatalist addnoqname() implementation searches for the first
|
||||
NSEC or NSEC3 record in a message, then for the first RRSIG covering
|
||||
that type in the same message. Previously, if no RRSIG for the type was
|
||||
found, the function accepted the unsigned record. Now, it will instead
|
||||
continue searching until an NSEC or NSEC3 that does have a matching
|
||||
signature is found.
|
||||
|
||||
When this function is called from validated() in resolver.c, a
|
||||
non-success return code is now treated as an error instead of triggering
|
||||
an assertion failure.
|
||||
|
||||
Fixes: isc-projects/bind9#5985
|
||||
(cherry picked from commit 57cba571ee31311e54d8a11cb38094d439f04e09)
|
||||
(cherry picked from commit 48f5aa5fb3746d6194edcc57e8792a8b3cc3b454)
|
||||
---
|
||||
lib/dns/rbtdb.c | 10 +++++++---
|
||||
lib/dns/rdatalist.c | 33 ++++++++++++++++-----------------
|
||||
lib/dns/resolver.c | 4 +++-
|
||||
lib/ns/query.c | 3 +--
|
||||
4 files changed, 27 insertions(+), 23 deletions(-)
|
||||
|
||||
diff --git a/lib/dns/rbtdb.c b/lib/dns/rbtdb.c
|
||||
index 0b8547950f..c922df557b 100644
|
||||
--- a/lib/dns/rbtdb.c
|
||||
+++ b/lib/dns/rbtdb.c
|
||||
@@ -6946,7 +6946,7 @@ delegating_type(dns_rbtdb_t *rbtdb, dns_rbtnode_t *node,
|
||||
static isc_result_t
|
||||
addnoqname(dns_rbtdb_t *rbtdb, rdatasetheader_t *newheader,
|
||||
uint32_t maxrrperset, dns_rdataset_t *rdataset) {
|
||||
- struct noqname *noqname;
|
||||
+ struct noqname *noqname = NULL;
|
||||
isc_mem_t *mctx = rbtdb->common.mctx;
|
||||
dns_name_t name;
|
||||
dns_rdataset_t neg, negsig;
|
||||
@@ -6958,7 +6958,9 @@ addnoqname(dns_rbtdb_t *rbtdb, rdatasetheader_t *newheader,
|
||||
dns_rdataset_init(&negsig);
|
||||
|
||||
result = dns_rdataset_getnoqname(rdataset, &name, &neg, &negsig);
|
||||
- RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
+ if (result != ISC_R_SUCCESS) {
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
|
||||
noqname = isc_mem_get(mctx, sizeof(*noqname));
|
||||
dns_name_init(&noqname->name, NULL);
|
||||
@@ -6984,7 +6986,9 @@ addnoqname(dns_rbtdb_t *rbtdb, rdatasetheader_t *newheader,
|
||||
cleanup:
|
||||
dns_rdataset_disassociate(&neg);
|
||||
dns_rdataset_disassociate(&negsig);
|
||||
- free_noqname(mctx, &noqname);
|
||||
+ if (noqname != NULL) {
|
||||
+ free_noqname(mctx, &noqname);
|
||||
+ }
|
||||
return result;
|
||||
}
|
||||
|
||||
diff --git a/lib/dns/rdatalist.c b/lib/dns/rdatalist.c
|
||||
index 98036f9cb3..2cca8d64be 100644
|
||||
--- a/lib/dns/rdatalist.c
|
||||
+++ b/lib/dns/rdatalist.c
|
||||
@@ -192,6 +192,7 @@ isc__rdatalist_addnoqname(dns_rdataset_t *rdataset, const dns_name_t *name) {
|
||||
dns_rdataset_t *neg = NULL;
|
||||
dns_rdataset_t *negsig = NULL;
|
||||
dns_rdataset_t *rdset;
|
||||
+ dns_rdataset_t *sigset;
|
||||
dns_ttl_t ttl;
|
||||
|
||||
REQUIRE(rdataset != NULL);
|
||||
@@ -199,30 +200,27 @@ isc__rdatalist_addnoqname(dns_rdataset_t *rdataset, const dns_name_t *name) {
|
||||
for (rdset = ISC_LIST_HEAD(name->list); rdset != NULL;
|
||||
rdset = ISC_LIST_NEXT(rdset, link))
|
||||
{
|
||||
- if (rdset->rdclass != rdataset->rdclass) {
|
||||
- continue;
|
||||
- }
|
||||
- if (rdset->type == dns_rdatatype_nsec ||
|
||||
- rdset->type == dns_rdatatype_nsec3)
|
||||
+ if (rdset->rdclass != rdataset->rdclass ||
|
||||
+ (rdset->type != dns_rdatatype_nsec &&
|
||||
+ rdset->type != dns_rdatatype_nsec3))
|
||||
{
|
||||
- neg = rdset;
|
||||
+ continue;
|
||||
}
|
||||
- }
|
||||
- if (neg == NULL) {
|
||||
- return ISC_R_NOTFOUND;
|
||||
- }
|
||||
|
||||
- for (rdset = ISC_LIST_HEAD(name->list); rdset != NULL;
|
||||
- rdset = ISC_LIST_NEXT(rdset, link))
|
||||
- {
|
||||
- if (rdset->type == dns_rdatatype_rrsig &&
|
||||
- rdset->covers == neg->type)
|
||||
+ for (sigset = ISC_LIST_HEAD(name->list); sigset != NULL;
|
||||
+ sigset = ISC_LIST_NEXT(sigset, link))
|
||||
{
|
||||
- negsig = rdset;
|
||||
+ if (sigset->type == dns_rdatatype_rrsig &&
|
||||
+ sigset->covers == rdset->type)
|
||||
+ {
|
||||
+ neg = rdset;
|
||||
+ negsig = sigset;
|
||||
+ break;
|
||||
+ }
|
||||
}
|
||||
}
|
||||
|
||||
- if (negsig == NULL) {
|
||||
+ if (neg == NULL || negsig == NULL) {
|
||||
return ISC_R_NOTFOUND;
|
||||
}
|
||||
/*
|
||||
@@ -238,6 +236,7 @@ isc__rdatalist_addnoqname(dns_rdataset_t *rdataset, const dns_name_t *name) {
|
||||
rdataset->ttl = neg->ttl = negsig->ttl = ttl;
|
||||
rdataset->attributes |= DNS_RDATASETATTR_NOQNAME;
|
||||
rdataset->private6 = name;
|
||||
+
|
||||
return ISC_R_SUCCESS;
|
||||
}
|
||||
|
||||
diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c
|
||||
index 1f8b5058d1..059ce53a9e 100644
|
||||
--- a/lib/dns/resolver.c
|
||||
+++ b/lib/dns/resolver.c
|
||||
@@ -5893,7 +5893,9 @@ validated(isc_task_t *task, isc_event_t *event) {
|
||||
result = dns_rdataset_addnoqname(
|
||||
vevent->rdataset,
|
||||
vevent->proofs[DNS_VALIDATOR_NOQNAMEPROOF]);
|
||||
- RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
+ if (result != ISC_R_SUCCESS) {
|
||||
+ goto noanswer_response;
|
||||
+ }
|
||||
INSIST(vevent->sigrdataset != NULL);
|
||||
vevent->sigrdataset->ttl = vevent->rdataset->ttl;
|
||||
if (vevent->proofs[DNS_VALIDATOR_CLOSESTENCLOSER] != NULL) {
|
||||
diff --git a/lib/ns/query.c b/lib/ns/query.c
|
||||
index 3bd7daf79c..2a2ba1daba 100644
|
||||
--- a/lib/ns/query.c
|
||||
+++ b/lib/ns/query.c
|
||||
@@ -7953,8 +7953,7 @@ query_addnoqnameproof(query_ctx_t *qctx) {
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
- result = dns_rdataset_getnoqname(qctx->noqname, fname, neg, negsig);
|
||||
- RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
+ CHECK(dns_rdataset_getnoqname(qctx->noqname, fname, neg, negsig));
|
||||
|
||||
query_addrrset(qctx, &fname, &neg, &negsig, dbuf,
|
||||
DNS_SECTION_AUTHORITY);
|
||||
--
|
||||
2.55.0
|
||||
|
||||
445
bind-9.18-CVE-2026-13321-test.patch
Normal file
445
bind-9.18-CVE-2026-13321-test.patch
Normal file
|
|
@ -0,0 +1,445 @@
|
|||
From eaa35628f4a201049295a8944f4d28e8a1013199 Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Ayd=C4=B1n=20Mercan?= <aydin@isc.org>
|
||||
Date: Wed, 6 May 2026 16:54:57 +0300
|
||||
Subject: [PATCH] Add system test for out-of-zone nsec dnssec bypass
|
||||
|
||||
A malicious zone with out-of-zone NSEC entries can get a DNSSEC
|
||||
validating resolver's cache to cover the victim zone for non-existence
|
||||
and prevent nameserver queries without DNSSEC failure.
|
||||
|
||||
Test for this case with an `evil.test` zone that tries to cover the
|
||||
`victim.test` zone.
|
||||
|
||||
(cherry picked from commit 654f9773c0af59965c343bdfeb096b3dffe9dd53)
|
||||
(cherry picked from commit c969ad2c17b43dd999e358bfeb280d3df6fab822)
|
||||
---
|
||||
.../system/dnssec_bypass/ns1/named.conf.j2 | 31 ++++
|
||||
bin/tests/system/dnssec_bypass/ns1/root.db | 19 +++
|
||||
bin/tests/system/dnssec_bypass/ns1/test.db | 23 +++
|
||||
.../system/dnssec_bypass/ns2/named.conf.j2 | 26 +++
|
||||
bin/tests/system/dnssec_bypass/ns2/victim.db | 18 +++
|
||||
bin/tests/system/dnssec_bypass/ns3/evil.db | 23 +++
|
||||
.../system/dnssec_bypass/ns3/named.conf.j2 | 26 +++
|
||||
.../system/dnssec_bypass/ns4/named.conf.j2 | 35 ++++
|
||||
.../system/dnssec_bypass/tests_bypass.py | 152 ++++++++++++++++++
|
||||
9 files changed, 353 insertions(+)
|
||||
create mode 100644 bin/tests/system/dnssec_bypass/ns1/named.conf.j2
|
||||
create mode 100644 bin/tests/system/dnssec_bypass/ns1/root.db
|
||||
create mode 100644 bin/tests/system/dnssec_bypass/ns1/test.db
|
||||
create mode 100644 bin/tests/system/dnssec_bypass/ns2/named.conf.j2
|
||||
create mode 100644 bin/tests/system/dnssec_bypass/ns2/victim.db
|
||||
create mode 100644 bin/tests/system/dnssec_bypass/ns3/evil.db
|
||||
create mode 100644 bin/tests/system/dnssec_bypass/ns3/named.conf.j2
|
||||
create mode 100644 bin/tests/system/dnssec_bypass/ns4/named.conf.j2
|
||||
create mode 100644 bin/tests/system/dnssec_bypass/tests_bypass.py
|
||||
|
||||
diff --git a/bin/tests/system/dnssec_bypass/ns1/named.conf.j2 b/bin/tests/system/dnssec_bypass/ns1/named.conf.j2
|
||||
new file mode 100644
|
||||
index 0000000000..59ced1831a
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/dnssec_bypass/ns1/named.conf.j2
|
||||
@@ -0,0 +1,31 @@
|
||||
+/*
|
||||
+ * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
+ *
|
||||
+ * SPDX-License-Identifier: MPL-2.0
|
||||
+ *
|
||||
+ * This Source Code Form is subject to the terms of the Mozilla Public
|
||||
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
+ * file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
+ *
|
||||
+ * See the COPYRIGHT file distributed with this work for additional
|
||||
+ * information regarding copyright ownership.
|
||||
+ */
|
||||
+
|
||||
+options {
|
||||
+ port @PORT@;
|
||||
+ pid-file "named.pid";
|
||||
+ listen-on { 10.53.0.1; };
|
||||
+ listen-on-v6 { none; };
|
||||
+ recursion no;
|
||||
+ dnssec-validation no;
|
||||
+};
|
||||
+
|
||||
+zone "test." {
|
||||
+ type primary;
|
||||
+ file "test.db.signed";
|
||||
+};
|
||||
+
|
||||
+zone "." {
|
||||
+ type primary;
|
||||
+ file "root.db.signed";
|
||||
+};
|
||||
diff --git a/bin/tests/system/dnssec_bypass/ns1/root.db b/bin/tests/system/dnssec_bypass/ns1/root.db
|
||||
new file mode 100644
|
||||
index 0000000000..8d98a0456c
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/dnssec_bypass/ns1/root.db
|
||||
@@ -0,0 +1,19 @@
|
||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
+;
|
||||
+; SPDX-License-Identifier: MPL-2.0
|
||||
+;
|
||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
+;
|
||||
+; See the COPYRIGHT file distributed with this work for additional
|
||||
+; information regarding copyright ownership.
|
||||
+
|
||||
+$TTL 3600
|
||||
+. IN SOA a.nil. a.nil. 1 3600 600 86400 300
|
||||
+. IN NS a.root-servers.nil.
|
||||
+
|
||||
+a.root-servers.nil. IN A 10.53.0.1
|
||||
+
|
||||
+test. IN NS ns1.test.
|
||||
+ns1.test. IN A 10.53.0.1
|
||||
diff --git a/bin/tests/system/dnssec_bypass/ns1/test.db b/bin/tests/system/dnssec_bypass/ns1/test.db
|
||||
new file mode 100644
|
||||
index 0000000000..6efcd95e42
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/dnssec_bypass/ns1/test.db
|
||||
@@ -0,0 +1,23 @@
|
||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
+;
|
||||
+; SPDX-License-Identifier: MPL-2.0
|
||||
+;
|
||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
+;
|
||||
+; See the COPYRIGHT file distributed with this work for additional
|
||||
+; information regarding copyright ownership.
|
||||
+
|
||||
+$ORIGIN test.
|
||||
+$TTL 3600
|
||||
+
|
||||
+@ IN SOA a a 1 3600 600 86400 300
|
||||
+ IN NS ns1.test.
|
||||
+ns1 IN A 10.53.0.1
|
||||
+
|
||||
+evil IN NS ns1.evil
|
||||
+ns1.evil IN A 10.53.0.3
|
||||
+
|
||||
+victim IN NS ns1.victim
|
||||
+ns1.victim IN A 10.53.0.2
|
||||
diff --git a/bin/tests/system/dnssec_bypass/ns2/named.conf.j2 b/bin/tests/system/dnssec_bypass/ns2/named.conf.j2
|
||||
new file mode 100644
|
||||
index 0000000000..e81cee7cac
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/dnssec_bypass/ns2/named.conf.j2
|
||||
@@ -0,0 +1,26 @@
|
||||
+/*
|
||||
+ * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
+ *
|
||||
+ * SPDX-License-Identifier: MPL-2.0
|
||||
+ *
|
||||
+ * This Source Code Form is subject to the terms of the Mozilla Public
|
||||
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
+ * file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
+ *
|
||||
+ * See the COPYRIGHT file distributed with this work for additional
|
||||
+ * information regarding copyright ownership.
|
||||
+ */
|
||||
+
|
||||
+options {
|
||||
+ port @PORT@;
|
||||
+ pid-file "named.pid";
|
||||
+ listen-on { 10.53.0.2; };
|
||||
+ listen-on-v6 { none; };
|
||||
+ recursion no;
|
||||
+ dnssec-validation no;
|
||||
+};
|
||||
+
|
||||
+zone "victim.test." {
|
||||
+ type primary;
|
||||
+ file "victim.db.signed";
|
||||
+};
|
||||
diff --git a/bin/tests/system/dnssec_bypass/ns2/victim.db b/bin/tests/system/dnssec_bypass/ns2/victim.db
|
||||
new file mode 100644
|
||||
index 0000000000..edcc234322
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/dnssec_bypass/ns2/victim.db
|
||||
@@ -0,0 +1,18 @@
|
||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
+;
|
||||
+; SPDX-License-Identifier: MPL-2.0
|
||||
+;
|
||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
+;
|
||||
+; See the COPYRIGHT file distributed with this work for additional
|
||||
+; information regarding copyright ownership.
|
||||
+
|
||||
+$ORIGIN victim.test.
|
||||
+$TTL 3600
|
||||
+
|
||||
+@ IN SOA ns1 hostmaster 1 3600 600 86400 2147483647
|
||||
+ IN NS ns1
|
||||
+
|
||||
+ns1 IN A 10.53.0.2
|
||||
diff --git a/bin/tests/system/dnssec_bypass/ns3/evil.db b/bin/tests/system/dnssec_bypass/ns3/evil.db
|
||||
new file mode 100644
|
||||
index 0000000000..618f9d3e85
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/dnssec_bypass/ns3/evil.db
|
||||
@@ -0,0 +1,23 @@
|
||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
+;
|
||||
+; SPDX-License-Identifier: MPL-2.0
|
||||
+;
|
||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
+;
|
||||
+; See the COPYRIGHT file distributed with this work for additional
|
||||
+; information regarding copyright ownership.
|
||||
+
|
||||
+$ORIGIN evil.test.
|
||||
+$TTL 300
|
||||
+
|
||||
+@ IN SOA ns1 hostmaster 1 3600 600 86400 300
|
||||
+ IN NS ns1
|
||||
+; Try to poison the victim zone in a resolver cache.
|
||||
+; If admitted, the aggressive NSEC cache will accept a range such as
|
||||
+; [evil.test, b.victim.test) and will cause the victim nameserver to
|
||||
+; be never queried.
|
||||
+ IN NSEC b.victim.test. NS SOA RRSIG NSEC DNSKEY
|
||||
+
|
||||
+ns1 IN A 10.53.0.3
|
||||
diff --git a/bin/tests/system/dnssec_bypass/ns3/named.conf.j2 b/bin/tests/system/dnssec_bypass/ns3/named.conf.j2
|
||||
new file mode 100644
|
||||
index 0000000000..17d3e18e4e
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/dnssec_bypass/ns3/named.conf.j2
|
||||
@@ -0,0 +1,26 @@
|
||||
+/*
|
||||
+ * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
+ *
|
||||
+ * SPDX-License-Identifier: MPL-2.0
|
||||
+ *
|
||||
+ * This Source Code Form is subject to the terms of the Mozilla Public
|
||||
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
+ * file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
+ *
|
||||
+ * See the COPYRIGHT file distributed with this work for additional
|
||||
+ * information regarding copyright ownership.
|
||||
+ */
|
||||
+
|
||||
+options {
|
||||
+ port @PORT@;
|
||||
+ pid-file "named.pid";
|
||||
+ listen-on { 10.53.0.3; };
|
||||
+ listen-on-v6 { none; };
|
||||
+ recursion no;
|
||||
+ dnssec-validation no;
|
||||
+};
|
||||
+
|
||||
+zone "evil.test." {
|
||||
+ type primary;
|
||||
+ file "evil.db.signed";
|
||||
+};
|
||||
diff --git a/bin/tests/system/dnssec_bypass/ns4/named.conf.j2 b/bin/tests/system/dnssec_bypass/ns4/named.conf.j2
|
||||
new file mode 100644
|
||||
index 0000000000..039695d9b7
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/dnssec_bypass/ns4/named.conf.j2
|
||||
@@ -0,0 +1,35 @@
|
||||
+/*
|
||||
+ * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
+ *
|
||||
+ * SPDX-License-Identifier: MPL-2.0
|
||||
+ *
|
||||
+ * This Source Code Form is subject to the terms of the Mozilla Public
|
||||
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
+ * file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
+ *
|
||||
+ * See the COPYRIGHT file distributed with this work for additional
|
||||
+ * information regarding copyright ownership.
|
||||
+ */
|
||||
+
|
||||
+options {
|
||||
+ query-source address 10.53.0.4;
|
||||
+ notify-source 10.53.0.4;
|
||||
+ transfer-source 10.53.0.4;
|
||||
+ port @PORT@;
|
||||
+ pid-file "named.pid";
|
||||
+ listen-on { 10.53.0.4; };
|
||||
+ listen-on-v6 { none; };
|
||||
+ allow-transfer { any; };
|
||||
+ recursion yes;
|
||||
+ dnssec-validation yes;
|
||||
+ synth-from-dnssec yes;
|
||||
+};
|
||||
+
|
||||
+trust-anchors {
|
||||
+ @root.domain@ @root.type@ @root.contents@;
|
||||
+};
|
||||
+
|
||||
+zone "." {
|
||||
+ type hint;
|
||||
+ file "../../_common/root.hint";
|
||||
+};
|
||||
diff --git a/bin/tests/system/dnssec_bypass/tests_bypass.py b/bin/tests/system/dnssec_bypass/tests_bypass.py
|
||||
new file mode 100644
|
||||
index 0000000000..c41bb7e016
|
||||
--- /dev/null
|
||||
+++ b/bin/tests/system/dnssec_bypass/tests_bypass.py
|
||||
@@ -0,0 +1,152 @@
|
||||
+# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
+#
|
||||
+# SPDX-License-Identifier: MPL-2.0
|
||||
+#
|
||||
+# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
+# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
+# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
+#
|
||||
+# See the COPYRIGHT file distributed with this work for additional
|
||||
+# information regarding copyright ownership.
|
||||
+
|
||||
+from datetime import datetime, timedelta, timezone
|
||||
+
|
||||
+import shutil
|
||||
+
|
||||
+from cryptography.hazmat.primitives.asymmetric import ec
|
||||
+
|
||||
+import dns.dnssec
|
||||
+import dns.name
|
||||
+import dns.rdataclass
|
||||
+import dns.rdataset
|
||||
+import dns.rdatatype
|
||||
+import dns.rrset
|
||||
+import dns.zone
|
||||
+
|
||||
+from isctest.run import EnvCmd
|
||||
+
|
||||
+import isctest
|
||||
+
|
||||
+TTL = 3600
|
||||
+
|
||||
+
|
||||
+def bootstrap():
|
||||
+ keygen = EnvCmd("KEYGEN", "-q -a ECDSA256")
|
||||
+ signer = EnvCmd("SIGNER", "-S -g -O full")
|
||||
+
|
||||
+ def sign_regular_zone(ns: str, zone: str, database: str) -> isctest.kasp.Key:
|
||||
+ isctest.log.info(f"{zone}: generate keys")
|
||||
+ keygen(zone, cwd=ns).out.strip()
|
||||
+ ksk = keygen(f"-f KSK {zone}", cwd=ns).out.strip()
|
||||
+
|
||||
+ isctest.log.info(f"{zone}: sign zone")
|
||||
+ signer(f"-o {zone} {database}", cwd=ns)
|
||||
+
|
||||
+ if ns != "ns1":
|
||||
+ shutil.copy(f"{ns}/dsset-{zone}", f"ns1/dsset-{zone}")
|
||||
+ shutil.copy(f"{ns}/{ksk}.key", f"ns1/{ksk}.key")
|
||||
+
|
||||
+ return isctest.kasp.Key(ksk, keydir=ns)
|
||||
+
|
||||
+ # dnssec-signzone and `dns.dnssec.sign_zone` correctly disregard the invalid
|
||||
+ # NSEC entries when signing the zone. However, for this test we actualy *want*
|
||||
+ # to serve invalid yet signed zones. To accomplish this we sign the zone and then
|
||||
+ # replace the correct entries with the faulty ones accompanied by its RRSIG.
|
||||
+ #
|
||||
+ # TODO(aydin): move this to `isctest` to sign broken zones
|
||||
+ def sign_rogue_zone(ns: str, zone: str, database: str) -> None:
|
||||
+ # Read zone.
|
||||
+ origin = dns.name.from_text(zone)
|
||||
+ data = dns.zone.from_file(f"{ns}/{database}", origin=origin, relativize=False)
|
||||
+
|
||||
+ # Get key for signing.
|
||||
+ isctest.log.info(f"{zone}: generate keys")
|
||||
+ private_key = ec.generate_private_key(ec.SECP256R1())
|
||||
+ dnskey = dns.dnssec.make_dnskey(
|
||||
+ public_key=private_key.public_key(),
|
||||
+ algorithm=dns.dnssec.Algorithm.ECDSAP256SHA256,
|
||||
+ flags=257,
|
||||
+ )
|
||||
+
|
||||
+ # Sign zone.
|
||||
+ isctest.log.info(f"{zone}: sign zone")
|
||||
+ now = datetime.now(timezone.utc)
|
||||
+ inception = now - timedelta(hours=1)
|
||||
+ expiration = now + timedelta(days=30)
|
||||
+
|
||||
+ for name, node in data.nodes.items():
|
||||
+ owner = name.derelativize(origin)
|
||||
+ rdatasets = list(node.rdatasets)
|
||||
+
|
||||
+ for rdataset in rdatasets:
|
||||
+ rrset = dns.rrset.RRset(owner, rdataset.rdclass, rdataset.rdtype)
|
||||
+ rrset.update(rdataset)
|
||||
+
|
||||
+ rrsig = dns.dnssec.sign(
|
||||
+ rrset=rrset,
|
||||
+ private_key=private_key,
|
||||
+ signer=origin,
|
||||
+ dnskey=dnskey,
|
||||
+ inception=inception,
|
||||
+ expiration=expiration,
|
||||
+ deterministic=False,
|
||||
+ )
|
||||
+
|
||||
+ rdataset = dns.rdataset.Rdataset(rrset.rdclass, dns.rdatatype.RRSIG)
|
||||
+ rdataset.add(rrsig, rrset.ttl)
|
||||
+ node.replace_rdataset(rdataset)
|
||||
+
|
||||
+ # Sign DNSKEY RRset.
|
||||
+ dnskey_rrset = dns.rrset.RRset(origin, dns.rdataclass.IN, dns.rdatatype.DNSKEY)
|
||||
+ dnskey_rrset.add(dnskey, ttl=TTL)
|
||||
+
|
||||
+ apex_node = data.nodes[origin]
|
||||
+ apex_node.replace_rdataset(dnskey_rrset)
|
||||
+
|
||||
+ rrsig = dns.dnssec.sign(
|
||||
+ rrset=dnskey_rrset,
|
||||
+ private_key=private_key,
|
||||
+ signer=origin,
|
||||
+ dnskey=dnskey,
|
||||
+ inception=inception,
|
||||
+ expiration=expiration,
|
||||
+ deterministic=False,
|
||||
+ )
|
||||
+ rdataset = dns.rdataset.Rdataset(rrset.rdclass, dns.rdatatype.RRSIG)
|
||||
+ rdataset.add(rrsig, dnskey_rrset.ttl)
|
||||
+ apex_node.replace_rdataset(rdataset)
|
||||
+
|
||||
+ # Output zone.
|
||||
+ data.to_file(f"{ns}/{database}.signed", relativize=False)
|
||||
+
|
||||
+ # Output DS.
|
||||
+ ds = dns.dnssec.make_ds(name=origin, key=dnskey, algorithm="SHA256")
|
||||
+ with open(f"ns1/dsset-{zone}", "w", encoding="utf-8") as f:
|
||||
+ f.write(f"{zone} {TTL} IN DS {ds.to_text()}\n")
|
||||
+
|
||||
+ sign_rogue_zone("ns3", "evil.test.", "evil.db")
|
||||
+ sign_regular_zone("ns2", "victim.test.", "victim.db")
|
||||
+ sign_regular_zone("ns1", "test.", "test.db")
|
||||
+ root_ksk = sign_regular_zone("ns1", ".", "root.db")
|
||||
+
|
||||
+ return {
|
||||
+ "root": root_ksk.into_ta("static-key"),
|
||||
+ }
|
||||
+
|
||||
+
|
||||
+def test_out_of_zone_nsec(ns4):
|
||||
+ isctest.log.info("trying to poison aggressive nsec cache")
|
||||
+ msg = isctest.query.create("nx.evil.test", "A")
|
||||
+ res = isctest.query.tcp(msg, ns4.ip)
|
||||
+ isctest.check.noadflag(res)
|
||||
+
|
||||
+ isctest.log.info("query victim from recursive")
|
||||
+ msg = isctest.query.create("victim.test", "SOA")
|
||||
+ res = isctest.query.tcp(msg, ns4.ip, attempts=1)
|
||||
+ isctest.check.noerror(res)
|
||||
+ isctest.check.adflag(res)
|
||||
+ isctest.check.rr_count_eq(res.answer, 2)
|
||||
+
|
||||
+ isctest.log.info("checking for query history on victim nameserver")
|
||||
+ with open("ns2/named.run", "r", encoding="utf-8") as f:
|
||||
+ assert "(victim.test): query 'victim.test/SOA/IN' approved" in f.read()
|
||||
--
|
||||
2.55.0
|
||||
|
||||
277
bind-9.18-CVE-2026-13321.patch
Normal file
277
bind-9.18-CVE-2026-13321.patch
Normal file
|
|
@ -0,0 +1,277 @@
|
|||
From 72967445f37a01d28b4ecb0e8f907e22fddd5087 Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Ayd=C4=B1n=20Mercan?= <aydin@isc.org>
|
||||
Date: Thu, 7 May 2026 18:59:20 +0300
|
||||
Subject: [PATCH] Reject out-of-zone NSEC next owner names
|
||||
|
||||
When verifying DNSSEC records, make sure that a next owner name of
|
||||
an NSEC record is a subdomain of the signer field.
|
||||
|
||||
This follows the specification RFC 4034, section 4.1.1:
|
||||
|
||||
Owner names of RRsets for which the given zone is not authoritative
|
||||
(such as glue records) MUST NOT be listed in the Next Domain Name
|
||||
unless at least one authoritative RRset exists at the same owner
|
||||
name.
|
||||
|
||||
While the above paragraph is intended for glue records, it also
|
||||
applies to out-of-zone data.
|
||||
|
||||
(cherry picked from commit 4065512d25b71605b9502bb69dfb903776d35aa9)
|
||||
(cherry picked from commit 058023c66f11d78590d4aa8c4f98946c4c965e21)
|
||||
|
||||
change dns_nsec_requiredtypespresent to dns_nsec_is_legal
|
||||
|
||||
Change `dns_nsec_requiredtypespresent` to `dns_nsec_is_legal` as a
|
||||
function for checking multiple NSEC validity rules.
|
||||
|
||||
Currently we now additionally check for out-of-zone NSEC entries.
|
||||
|
||||
(cherry picked from commit be2a6a497312469890b552907d039d2de0b44ccc)
|
||||
(cherry picked from commit f751e19a30d107f04c2f644aff9f8dab8fed03ab)
|
||||
---
|
||||
lib/dns/dnssec.c | 13 ++++++++++
|
||||
lib/dns/include/dns/dnssec.h | 6 +++++
|
||||
lib/dns/include/dns/nsec.h | 18 ++++++++++----
|
||||
lib/dns/nsec.c | 17 ++++++++++---
|
||||
lib/dns/resolver.c | 48 ++++++++++++++++++++++++++++++++++--
|
||||
lib/ns/query.c | 6 ++---
|
||||
6 files changed, 94 insertions(+), 14 deletions(-)
|
||||
|
||||
diff --git a/lib/dns/dnssec.c b/lib/dns/dnssec.c
|
||||
index 9b9b1f2bb2..5acaea9ecb 100644
|
||||
--- a/lib/dns/dnssec.c
|
||||
+++ b/lib/dns/dnssec.c
|
||||
@@ -357,8 +357,10 @@ isc_result_t
|
||||
dns_dnssec_verify(const dns_name_t *name, dns_rdataset_t *set, dst_key_t *key,
|
||||
bool ignoretime, unsigned int maxbits, isc_mem_t *mctx,
|
||||
dns_rdata_t *sigrdata, dns_name_t *wild) {
|
||||
+ dns_rdata_nsec_t nsec;
|
||||
dns_rdata_rrsig_t sig;
|
||||
dns_fixedname_t fnewname;
|
||||
+ dns_rdata_t rdata = DNS_RDATA_INIT;
|
||||
isc_region_t r;
|
||||
isc_buffer_t envbuf;
|
||||
dns_rdata_t *rdatas;
|
||||
@@ -464,6 +466,17 @@ dns_dnssec_verify(const dns_name_t *name, dns_rdataset_t *set, dst_key_t *key,
|
||||
}
|
||||
break;
|
||||
}
|
||||
+ /*
|
||||
+ * Check for out of zone NSEC entries.
|
||||
+ */
|
||||
+ if (set->type == dns_rdatatype_nsec) {
|
||||
+ RETERR(dns_rdataset_first(set));
|
||||
+ dns_rdataset_current(set, &rdata);
|
||||
+ RETERR(dns_rdata_tostruct(&rdata, &nsec, NULL));
|
||||
+ if (!dns_name_issubdomain(&nsec.next, &sig.signer)) {
|
||||
+ return DNS_R_NOVALIDNSEC;
|
||||
+ }
|
||||
+ }
|
||||
|
||||
again:
|
||||
ret = dst_context_create(key, mctx, DNS_LOGCATEGORY_DNSSEC, false,
|
||||
diff --git a/lib/dns/include/dns/dnssec.h b/lib/dns/include/dns/dnssec.h
|
||||
index cb8fd9dc20..2be11b9144 100644
|
||||
--- a/lib/dns/include/dns/dnssec.h
|
||||
+++ b/lib/dns/include/dns/dnssec.h
|
||||
@@ -151,6 +151,9 @@ dns_dnssec_verify(const dns_name_t *name, dns_rdataset_t *set, dst_key_t *key,
|
||||
* this record, as this requires a resolver or database.
|
||||
* If 'ignoretime' is true, temporal validity will not be checked.
|
||||
*
|
||||
+ * If 'set' is of type NSEC, this function also verifies that the
|
||||
+ * Next Name is a subdomain of the Signer's Name from 'sigrdata'.
|
||||
+ *
|
||||
* 'maxbits' specifies the maximum number of rsa exponent bits accepted.
|
||||
*
|
||||
* Requires:
|
||||
@@ -173,6 +176,9 @@ dns_dnssec_verify(const dns_name_t *name, dns_rdataset_t *set, dst_key_t *key,
|
||||
*\li #DNS_R_KEYUNAUTHORIZED - the key cannot sign this data (either
|
||||
* it is not a zone key or its flags prevent
|
||||
* authentication)
|
||||
+ *
|
||||
+ *\li #DNS_R_NOVALIDNSEC - the NSEC rdata is not valid
|
||||
+ *\li #DNS_R_KEYUNAUTHORIZED - the key cannot sign this data
|
||||
*\li DST_R_*
|
||||
*/
|
||||
|
||||
diff --git a/lib/dns/include/dns/nsec.h b/lib/dns/include/dns/nsec.h
|
||||
index 50df8e45f1..1e71bf14e8 100644
|
||||
--- a/lib/dns/include/dns/nsec.h
|
||||
+++ b/lib/dns/include/dns/nsec.h
|
||||
@@ -119,13 +119,21 @@ dns_nsec_noexistnodata(dns_rdatatype_t type, const dns_name_t *name,
|
||||
*/
|
||||
|
||||
bool
|
||||
-dns_nsec_requiredtypespresent(dns_rdataset_t *rdataset);
|
||||
-/*
|
||||
- * Return true if all the NSEC records in rdataset have both
|
||||
- * NSEC and RRSIG present.
|
||||
+dns_nsec_is_legal(dns_rdataset_t *rdataset, const dns_name_t *name);
|
||||
+/**<
|
||||
+ * \brief
|
||||
+ * Validates a rdataset of type NSEC.
|
||||
*
|
||||
- * Requires:
|
||||
+ * This functions checks for the following in the given rdataset:
|
||||
+ * \li All NSEC records have both NSEC and RRSIG present
|
||||
+ * \li All NSEC entries are under the `name`
|
||||
+ *
|
||||
+ * \par Requires:
|
||||
* \li rdataset to be a NSEC rdataset.
|
||||
+ * \li `name` is a valid dns_name_t
|
||||
+ *
|
||||
+ * \retval true if all the checks pass
|
||||
+ * \retval false otherwise
|
||||
*/
|
||||
|
||||
ISC_LANG_ENDDECLS
|
||||
diff --git a/lib/dns/nsec.c b/lib/dns/nsec.c
|
||||
index 80ee8d7d58..5abcce5f7f 100644
|
||||
--- a/lib/dns/nsec.c
|
||||
+++ b/lib/dns/nsec.c
|
||||
@@ -21,6 +21,7 @@
|
||||
#include <isc/util.h>
|
||||
|
||||
#include <dns/db.h>
|
||||
+#include <dns/name.h>
|
||||
#include <dns/nsec.h>
|
||||
#include <dns/rdata.h>
|
||||
#include <dns/rdatalist.h>
|
||||
@@ -497,8 +498,9 @@ dns_nsec_noexistnodata(dns_rdatatype_t type, const dns_name_t *name,
|
||||
}
|
||||
|
||||
bool
|
||||
-dns_nsec_requiredtypespresent(dns_rdataset_t *nsecset) {
|
||||
- dns_rdataset_t rdataset;
|
||||
+dns_nsec_is_legal(dns_rdataset_t *nsecset, const dns_name_t *name) {
|
||||
+ dns_rdataset_t rdataset = DNS_RDATASET_INIT;
|
||||
+ dns_rdata_nsec_t nsec;
|
||||
isc_result_t result;
|
||||
bool found = false;
|
||||
|
||||
@@ -513,12 +515,19 @@ dns_nsec_requiredtypespresent(dns_rdataset_t *nsecset) {
|
||||
{
|
||||
dns_rdata_t rdata = DNS_RDATA_INIT;
|
||||
dns_rdataset_current(&rdataset, &rdata);
|
||||
- if (!dns_nsec_typepresent(&rdata, dns_rdatatype_nsec) ||
|
||||
- !dns_nsec_typepresent(&rdata, dns_rdatatype_rrsig))
|
||||
+
|
||||
+ /* must never fail */
|
||||
+ result = dns_rdata_tostruct(&rdata, &nsec, NULL);
|
||||
+ INSIST(result == ISC_R_SUCCESS);
|
||||
+
|
||||
+ if (!dns_name_issubdomain(&nsec.next, name) ||
|
||||
+ !dns_nsec_typepresent(&rdata, dns_rdatatype_rrsig) ||
|
||||
+ !dns_nsec_typepresent(&rdata, dns_rdatatype_nsec))
|
||||
{
|
||||
dns_rdataset_disassociate(&rdataset);
|
||||
return false;
|
||||
}
|
||||
+
|
||||
found = true;
|
||||
}
|
||||
dns_rdataset_disassociate(&rdataset);
|
||||
diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c
|
||||
index 059ce53a9e..eac67f7a19 100644
|
||||
--- a/lib/dns/resolver.c
|
||||
+++ b/lib/dns/resolver.c
|
||||
@@ -65,7 +65,9 @@
|
||||
#include <dns/rootns.h>
|
||||
#include <dns/stats.h>
|
||||
#include <dns/tsig.h>
|
||||
+#include <dns/types.h>
|
||||
#include <dns/validator.h>
|
||||
+#include <dns/view.h>
|
||||
#include <dns/zone.h>
|
||||
|
||||
/* Detailed logging of fctx attach/detach */
|
||||
@@ -5603,6 +5605,36 @@ fctx_setresult(fetchctx_t *fctx, dns_rdataset_t *rdataset) {
|
||||
return result;
|
||||
}
|
||||
|
||||
+static bool
|
||||
+get_and_check_signer_name(dns_name_t *signer, dns_rdataset_t *sigrdataset) {
|
||||
+ dns_rdata_rrsig_t rrsig;
|
||||
+ isc_result_t result;
|
||||
+ dns_rdata_t rdata;
|
||||
+
|
||||
+ if (dns_rdataset_first(sigrdataset) != ISC_R_SUCCESS) {
|
||||
+ return false;
|
||||
+ }
|
||||
+
|
||||
+ rdata = (dns_rdata_t)DNS_RDATA_INIT;
|
||||
+ dns_rdataset_current(sigrdataset, &rdata);
|
||||
+ result = dns_rdata_tostruct(&rdata, &rrsig, NULL);
|
||||
+ INSIST(result == ISC_R_SUCCESS);
|
||||
+ dns_name_copy(&rrsig.signer, signer);
|
||||
+
|
||||
+ while (dns_rdataset_next(sigrdataset) == ISC_R_SUCCESS) {
|
||||
+ rdata = (dns_rdata_t)DNS_RDATA_INIT;
|
||||
+ dns_rdataset_current(sigrdataset, &rdata);
|
||||
+ result = dns_rdata_tostruct(&rdata, &rrsig, NULL);
|
||||
+ INSIST(result == ISC_R_SUCCESS);
|
||||
+
|
||||
+ if (!dns_name_equal(signer, &rrsig.signer)) {
|
||||
+ return false;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ return true;
|
||||
+}
|
||||
+
|
||||
/*
|
||||
* The validator has finished.
|
||||
*/
|
||||
@@ -5633,6 +5665,8 @@ validated(isc_task_t *task, isc_event_t *event) {
|
||||
dns_fixedname_t fwild;
|
||||
dns_name_t *wild = NULL;
|
||||
dns_message_t *message = NULL;
|
||||
+ dns_fixedname_t fsigner;
|
||||
+ dns_name_t *signer = NULL;
|
||||
|
||||
UNUSED(task); /* for now */
|
||||
|
||||
@@ -6021,10 +6055,20 @@ answer_response:
|
||||
}
|
||||
|
||||
/*
|
||||
- * Don't cache NSEC if missing NSEC or RRSIG types.
|
||||
+ * Don't cache if all the RRSIGs don't have the same
|
||||
+ * signer.
|
||||
+ */
|
||||
+ signer = dns_fixedname_initname(&fsigner);
|
||||
+ if (!get_and_check_signer_name(signer, sigrdataset)) {
|
||||
+ continue;
|
||||
+ }
|
||||
+
|
||||
+ /*
|
||||
+ * Don't cache NSEC if missing NSEC or RRSIG
|
||||
+ * types.
|
||||
*/
|
||||
if (rdataset->type == dns_rdatatype_nsec &&
|
||||
- !dns_nsec_requiredtypespresent(rdataset))
|
||||
+ !dns_nsec_is_legal(rdataset, signer))
|
||||
{
|
||||
continue;
|
||||
}
|
||||
diff --git a/lib/ns/query.c b/lib/ns/query.c
|
||||
index 2a2ba1daba..8bbcd7ff30 100644
|
||||
--- a/lib/ns/query.c
|
||||
+++ b/lib/ns/query.c
|
||||
@@ -10370,10 +10370,10 @@ query_coveringnsec(query_ctx_t *qctx) {
|
||||
}
|
||||
|
||||
/*
|
||||
- * If NSEC or RRSIG are missing from the type map
|
||||
- * reject the NSEC RRset.
|
||||
+ * Check that the NSEC entry is legal.
|
||||
+ * (NSEC + RRSIG present and the entry isn't out-of-zone)
|
||||
*/
|
||||
- if (!dns_nsec_requiredtypespresent(qctx->rdataset)) {
|
||||
+ if (!dns_nsec_is_legal(qctx->rdataset, signer)) {
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
--
|
||||
2.55.0
|
||||
|
||||
76
bind-9.18-dig-idn-input-always-test.patch
Normal file
76
bind-9.18-dig-idn-input-always-test.patch
Normal file
|
|
@ -0,0 +1,76 @@
|
|||
From 12f50726b6bd8f6b3ed6709695e0f6893bc865c6 Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
||||
Date: Tue, 16 Sep 2025 11:46:03 +0200
|
||||
Subject: [PATCH] Fix expectations on idna system test
|
||||
|
||||
IDNA tests always redirect output into the file. That means its
|
||||
behaviour has changed and is now processing IDN input by default and
|
||||
just disables IDN output by default.
|
||||
|
||||
New behaviour when redirected is the same as +idnin +noidnout, but does
|
||||
not fail hard on input errors.
|
||||
---
|
||||
bin/tests/system/idna/tests.sh | 12 ++++++------
|
||||
1 file changed, 6 insertions(+), 6 deletions(-)
|
||||
|
||||
diff --git a/bin/tests/system/idna/tests.sh b/bin/tests/system/idna/tests.sh
|
||||
index 398b7e1..37f02b1 100644
|
||||
--- a/bin/tests/system/idna/tests.sh
|
||||
+++ b/bin/tests/system/idna/tests.sh
|
||||
@@ -194,7 +194,7 @@ idna_enabled_test() {
|
||||
# Note that ASCII characters are converted to lower-case.
|
||||
|
||||
text="Checking valid non-ASCII label"
|
||||
- idna_test "$text" "" "München" "M\195\188nchen."
|
||||
+ idna_test "$text" "" "München" "xn--mnchen-3ya."
|
||||
idna_test "$text" "+noidnin +noidnout" "München" "M\195\188nchen."
|
||||
idna_test "$text" "+noidnin +idnout" "München" "M\195\188nchen."
|
||||
idna_test "$text" "+idnin +noidnout" "München" "xn--mnchen-3ya."
|
||||
@@ -218,7 +218,7 @@ idna_enabled_test() {
|
||||
# for the valid U-label.
|
||||
|
||||
text="Checking that non-transitional IDNA processing is used"
|
||||
- idna_test "$text" "" "faß.de" "fa\195\159.de."
|
||||
+ idna_test "$text" "" "faß.de" "xn--fa-hia.de."
|
||||
idna_test "$text" "+noidnin +noidnout" "faß.de" "fa\195\159.de."
|
||||
idna_test "$text" "+noidnin +idnout" "faß.de" "fa\195\159.de."
|
||||
idna_test "$text" "+idnin +noidnout" "faß.de" "xn--fa-hia.de."
|
||||
@@ -228,7 +228,7 @@ idna_enabled_test() {
|
||||
# onto the Greek sigma character ("σ") in IDNA2003.
|
||||
|
||||
text="Second check that non-transitional IDNA processing is used"
|
||||
- idna_test "$text" "" "βόλος.com" "\206\178\207\140\206\187\206\191\207\130.com."
|
||||
+ idna_test "$text" "" "βόλος.com" "xn--nxasmm1c.com."
|
||||
idna_test "$text" "+noidnin +noidnout" "βόλος.com" "\206\178\207\140\206\187\206\191\207\130.com."
|
||||
idna_test "$text" "+noidnin +idnout" "βόλος.com" "\206\178\207\140\206\187\206\191\207\130.com."
|
||||
idna_test "$text" "+idnin +noidnout" "βόλος.com" "xn--nxasmm1c.com."
|
||||
@@ -288,7 +288,7 @@ idna_enabled_test() {
|
||||
idna_test "$text" "" "xn--xx" "xn--xx."
|
||||
idna_test "$text" "+noidnin +noidnout" "xn--xx" "xn--xx."
|
||||
idna_fail "$text" "+noidnin +idnout" "xn--xx"
|
||||
- idna_fail "$text" "+idnin +noidnout" "xn--xx"
|
||||
+ idna_test "$text" "+idnin +noidnout" "xn--xx" "xn--xx."
|
||||
idna_fail "$text" "+idnin +idnout" "xn--xx"
|
||||
|
||||
# Fake A-label - the string does not translate to anything.
|
||||
@@ -297,7 +297,7 @@ idna_enabled_test() {
|
||||
idna_test "$text" "" "xn--ahahah" "xn--ahahah."
|
||||
idna_test "$text" "+noidnin +noidnout" "xn--ahahah" "xn--ahahah."
|
||||
idna_fail "$text" "+noidnin +idnout" "xn--ahahah"
|
||||
- idna_fail "$text" "+idnin +noidnout" "xn--ahahah"
|
||||
+ idna_test "$text" "+idnin +noidnout" "xn--ahahah" "xn--ahahah."
|
||||
idna_fail "$text" "+idnin +idnout" "xn--ahahah"
|
||||
|
||||
# Too long a label. The punycode string is too long (at 64 characters).
|
||||
@@ -324,7 +324,7 @@ idna_enabled_test() {
|
||||
# The +[no]idnout options should not have any effect on the test.
|
||||
|
||||
text="Checking invalid input U-label"
|
||||
- idna_test "$text" "" "√.com" "\226\136\154.com."
|
||||
+ idna_test "$text" "" "√.com" "xn--19g.com."
|
||||
idna_test "$text" "+noidnin +noidnout" "√.com" "\226\136\154.com."
|
||||
idna_test "$text" "+noidnin +idnout" "√.com" "\226\136\154.com."
|
||||
idna_test "$text" "+idnin +noidnout" "√.com" "xn--19g.com."
|
||||
--
|
||||
2.51.0
|
||||
|
||||
98
bind-9.18-dig-idn-input-always.patch
Normal file
98
bind-9.18-dig-idn-input-always.patch
Normal file
|
|
@ -0,0 +1,98 @@
|
|||
From fcc50604359a05e24003f3ff51c3812d8f307814 Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
||||
Date: Wed, 6 Nov 2024 21:29:47 +0100
|
||||
Subject: [PATCH] Allow always IDN input in dig
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Even when stdout is non-interactive terminal, allow unicode characters
|
||||
to be encoded into ACE form. Still disable IDN output, but unless
|
||||
+noidnin or IDN_DISABLE=1 env is detected, consider input as locale
|
||||
defined name.
|
||||
|
||||
Provides more isolated change, which issue #3527 introduced similar
|
||||
behavior into 9.19 with more changes.
|
||||
|
||||
Ignore input IDN errors when stdout is not terminal
|
||||
|
||||
Attempt to prevent visible regressions when enabling IDN on input
|
||||
always. Instead of new hard failures preventing IDN decoding of input
|
||||
name just use original input.
|
||||
|
||||
Should make the change backward compatible. When on interactive terminal
|
||||
behave the same way as before and emit hard errors. Become more
|
||||
forgiving in scripts where stdout leads to script. Decoding output is
|
||||
not enabled there and if input decoding fails, just use input as it was.
|
||||
|
||||
Change dig manual +idnin
|
||||
|
||||
Note in manual IDN input is always enabled. But it silently ignores
|
||||
errors when stdout is not a terminal to prevent regressions.
|
||||
|
||||
Signed-off-by: Petr Menšík <pemensik@redhat.com>
|
||||
---
|
||||
bin/dig/dig.rst | 5 ++---
|
||||
bin/dig/dighost.c | 16 ++++++++++++----
|
||||
2 files changed, 14 insertions(+), 7 deletions(-)
|
||||
|
||||
diff --git a/bin/dig/dig.rst b/bin/dig/dig.rst
|
||||
index 88b0a40307..e2bf3764d3 100644
|
||||
--- a/bin/dig/dig.rst
|
||||
+++ b/bin/dig/dig.rst
|
||||
@@ -453,9 +453,8 @@ abbreviation is unambiguous; for example, :option:`+cd` is equivalent to
|
||||
This option processes [or does not process] IDN domain names on input. This requires
|
||||
``IDN SUPPORT`` to have been enabled at compile time.
|
||||
|
||||
- The default is to process IDN input when standard output is a tty.
|
||||
- The IDN processing on input is disabled when :program:`dig` output is redirected
|
||||
- to files, pipes, and other non-tty file descriptors.
|
||||
+ The default is to process IDN input. The input IDN processing errors are ignored
|
||||
+ when :program:`dig` output is redirected to files, pipes, and other non-tty file descriptors.
|
||||
|
||||
.. option:: +idnout, +noidnout
|
||||
|
||||
diff --git a/bin/dig/dighost.c b/bin/dig/dighost.c
|
||||
index 0f8ac1335c..1307346192 100644
|
||||
--- a/bin/dig/dighost.c
|
||||
+++ b/bin/dig/dighost.c
|
||||
@@ -604,7 +604,7 @@ dig_lookup_t *
|
||||
make_empty_lookup(void) {
|
||||
dig_lookup_t *looknew;
|
||||
#ifdef HAVE_LIBIDN2
|
||||
- bool idn_allowed = isatty(1) ? (getenv("IDN_DISABLE") == NULL) : false;
|
||||
+ bool idn_allowed = (getenv("IDN_DISABLE") == NULL);
|
||||
#endif /* HAVE_LIBIDN2 */
|
||||
|
||||
debug("make_empty_lookup()");
|
||||
@@ -623,7 +623,7 @@ make_empty_lookup(void) {
|
||||
.badcookie = true,
|
||||
#ifdef HAVE_LIBIDN2
|
||||
.idnin = idn_allowed,
|
||||
- .idnout = idn_allowed,
|
||||
+ .idnout = isatty(1) && idn_allowed,
|
||||
#endif /* HAVE_LIBIDN2 */
|
||||
.udpsize = -1,
|
||||
.edns = -1,
|
||||
@@ -4871,8 +4871,16 @@ idn_locale_to_ace(const char *src, char *dst, size_t dstlen) {
|
||||
res = idn2_to_ascii_lz(src, &ascii_src, IDN2_TRANSITIONAL);
|
||||
}
|
||||
if (res != IDN2_OK) {
|
||||
- fatal("'%s' is not a legal IDNA2008 name (%s), use +noidnin",
|
||||
- src, idn2_strerror(res));
|
||||
+ if (isatty(1)) {
|
||||
+ fatal("'%s' is not a legal IDNA2008 name (%s), use +noidnin",
|
||||
+ src, idn2_strerror(res));
|
||||
+ } else {
|
||||
+ /* In case of non-terminal output silently ignore errors
|
||||
+ * in IDN input decoding. */
|
||||
+ (void)strlcpy(dst, src, dstlen);
|
||||
+ resetlocale(LC_ALL);
|
||||
+ return;
|
||||
+ }
|
||||
}
|
||||
|
||||
/*
|
||||
--
|
||||
2.50.1
|
||||
|
||||
54
bind-9.18-partial-additional-records.patch
Normal file
54
bind-9.18-partial-additional-records.patch
Normal file
|
|
@ -0,0 +1,54 @@
|
|||
From 3f686891729c7d39d879e8b5bb1aa17d874d265d Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
||||
Date: Thu, 19 Jun 2025 19:51:43 +0200
|
||||
Subject: [PATCH] Limit number of additional records fetched
|
||||
|
||||
Limit number of started fetches for additional zone instead of doing
|
||||
none. Keep limit of NS filled with additional records, but present at
|
||||
least some if possible.
|
||||
|
||||
Might help broken implementations relying on receiving addresses in the
|
||||
response for NS query in authoritative zone.
|
||||
---
|
||||
lib/dns/rdataset.c | 11 ++++++-----
|
||||
1 file changed, 6 insertions(+), 5 deletions(-)
|
||||
|
||||
diff --git a/lib/dns/rdataset.c b/lib/dns/rdataset.c
|
||||
index 532e49a..bfa8e37 100644
|
||||
--- a/lib/dns/rdataset.c
|
||||
+++ b/lib/dns/rdataset.c
|
||||
@@ -581,6 +581,7 @@ dns_rdataset_additionaldata(dns_rdataset_t *rdataset,
|
||||
size_t limit) {
|
||||
dns_rdata_t rdata = DNS_RDATA_INIT;
|
||||
isc_result_t result;
|
||||
+ size_t n = 0;
|
||||
|
||||
/*
|
||||
* For each rdata in rdataset, call 'add' for each name and type in the
|
||||
@@ -590,10 +591,6 @@ dns_rdataset_additionaldata(dns_rdataset_t *rdataset,
|
||||
REQUIRE(DNS_RDATASET_VALID(rdataset));
|
||||
REQUIRE((rdataset->attributes & DNS_RDATASETATTR_QUESTION) == 0);
|
||||
|
||||
- if (limit != 0 && dns_rdataset_count(rdataset) > limit) {
|
||||
- return DNS_R_TOOMANYRECORDS;
|
||||
- }
|
||||
-
|
||||
result = dns_rdataset_first(rdataset);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
return result;
|
||||
@@ -603,7 +600,11 @@ dns_rdataset_additionaldata(dns_rdataset_t *rdataset,
|
||||
dns_rdataset_current(rdataset, &rdata);
|
||||
result = dns_rdata_additionaldata(&rdata, owner_name, add, arg);
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
- result = dns_rdataset_next(rdataset);
|
||||
+ if (limit != 0 && ++n >= limit) {
|
||||
+ result = DNS_R_TOOMANYRECORDS;
|
||||
+ } else {
|
||||
+ result = dns_rdataset_next(rdataset);
|
||||
+ }
|
||||
}
|
||||
dns_rdata_reset(&rdata);
|
||||
} while (result == ISC_R_SUCCESS);
|
||||
--
|
||||
2.50.1
|
||||
|
||||
897
bind-9.18-pkcs11-provider.patch
Normal file
897
bind-9.18-pkcs11-provider.patch
Normal file
|
|
@ -0,0 +1,897 @@
|
|||
From 5bd1369eb7781ad2b349b99f783a7ed07fb7d6ac Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
||||
Date: Thu, 13 Feb 2025 13:20:28 +0100
|
||||
Subject: [PATCH] Backport OpenSSL 3 provider support
|
||||
|
||||
Use gist of 451edf324281d30fbbe5669223dcea331670847c and
|
||||
5fd6cfc625aa84005618236f4cd699c07367a3dc upstream commits, but do not do
|
||||
significant rebase together. Move engine loading of EVP_PKEY from label to
|
||||
openssl_link and copy provider variant from newer.
|
||||
|
||||
Remove legacy RSA calls from _fromlabel to separate engine handling
|
||||
code. Make rsa_check accepting EVP_PKEY pair only and use conditional
|
||||
compilation to verify them. Move checking of max exponent bits to
|
||||
rsa_check too, because it is done from all usages anyway.
|
||||
|
||||
Use rsa_check_legacy in places where bit checking is not necessary.
|
||||
|
||||
Fix keyfromlabel to not use engine parameter for provider keys
|
||||
|
||||
- Rework key checks to not require 'engine' tag, private key
|
||||
is valid with 'label' tag alone
|
||||
|
||||
- Fix _fromlabel() functions to work with engine == NULL
|
||||
|
||||
- Update dst__openssl_fromlabel_engine() to do provider lookup
|
||||
only when engine is not set
|
||||
|
||||
(cherry picked from commit de486d0ec5d5642ddb1820a1269f5406a2bb1c64)
|
||||
|
||||
Use dst_key_t label to signal isprivate property as a downstream
|
||||
alternative to upstream commit 74361b0b6e5a6b17ebeea6afe1ca990395d7a6dd.
|
||||
That would require additional heavier changes.
|
||||
|
||||
Downstream change:
|
||||
Move RSA bits check to legacy, let it use rsa_check for newer
|
||||
|
||||
rsabigexponent tests got broken by this change.
|
||||
---
|
||||
lib/dns/dst_openssl.h | 4 +
|
||||
lib/dns/dst_parse.c | 21 ++---
|
||||
lib/dns/openssl_link.c | 161 +++++++++++++++++++++++++++-----
|
||||
lib/dns/openssldh_link.c | 5 +
|
||||
lib/dns/opensslecdsa_link.c | 109 +++++++++++-----------
|
||||
lib/dns/openssleddsa_link.c | 40 +++-----
|
||||
lib/dns/opensslrsa_link.c | 181 ++++++++++++++----------------------
|
||||
7 files changed, 296 insertions(+), 225 deletions(-)
|
||||
|
||||
diff --git a/lib/dns/dst_openssl.h b/lib/dns/dst_openssl.h
|
||||
index 819af0f..cd386c0 100644
|
||||
--- a/lib/dns/dst_openssl.h
|
||||
+++ b/lib/dns/dst_openssl.h
|
||||
@@ -64,4 +64,8 @@ ENGINE *
|
||||
dst__openssl_getengine(const char *engine);
|
||||
#endif /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
||||
|
||||
+isc_result_t
|
||||
+dst__openssl_fromlabel(int key_base_id, const char *engine, const char *label,
|
||||
+ const char *pin, EVP_PKEY **ppub, EVP_PKEY **ppriv);
|
||||
+
|
||||
ISC_LANG_ENDDECLS
|
||||
diff --git a/lib/dns/dst_parse.c b/lib/dns/dst_parse.c
|
||||
index a353b86..7f3fe51 100644
|
||||
--- a/lib/dns/dst_parse.c
|
||||
+++ b/lib/dns/dst_parse.c
|
||||
@@ -195,10 +195,9 @@ check_rsa(const dst_private_t *priv, bool external) {
|
||||
|
||||
mask = (1ULL << TAG_SHIFT) - 1;
|
||||
|
||||
- if (have[TAG_RSA_ENGINE & mask]) {
|
||||
+ if (have[TAG_RSA_LABEL & mask]) {
|
||||
ok = have[TAG_RSA_MODULUS & mask] &&
|
||||
- have[TAG_RSA_PUBLICEXPONENT & mask] &&
|
||||
- have[TAG_RSA_LABEL & mask];
|
||||
+ have[TAG_RSA_PUBLICEXPONENT & mask];
|
||||
} else {
|
||||
ok = have[TAG_RSA_MODULUS & mask] &&
|
||||
have[TAG_RSA_PUBLICEXPONENT & mask] &&
|
||||
@@ -259,11 +258,9 @@ check_ecdsa(const dst_private_t *priv, bool external) {
|
||||
|
||||
mask = (1ULL << TAG_SHIFT) - 1;
|
||||
|
||||
- if (have[TAG_ECDSA_ENGINE & mask]) {
|
||||
- ok = have[TAG_ECDSA_LABEL & mask];
|
||||
- } else {
|
||||
- ok = have[TAG_ECDSA_PRIVATEKEY & mask];
|
||||
- }
|
||||
+ ok = have[TAG_ECDSA_LABEL & mask] ||
|
||||
+ have[TAG_ECDSA_PRIVATEKEY & mask];
|
||||
+
|
||||
return ok ? 0 : -1;
|
||||
}
|
||||
|
||||
@@ -295,11 +292,9 @@ check_eddsa(const dst_private_t *priv, bool external) {
|
||||
|
||||
mask = (1ULL << TAG_SHIFT) - 1;
|
||||
|
||||
- if (have[TAG_EDDSA_ENGINE & mask]) {
|
||||
- ok = have[TAG_EDDSA_LABEL & mask];
|
||||
- } else {
|
||||
- ok = have[TAG_EDDSA_PRIVATEKEY & mask];
|
||||
- }
|
||||
+ ok = have[TAG_EDDSA_LABEL & mask] ||
|
||||
+ have[TAG_EDDSA_PRIVATEKEY & mask];
|
||||
+
|
||||
return ok ? 0 : -1;
|
||||
}
|
||||
|
||||
diff --git a/lib/dns/openssl_link.c b/lib/dns/openssl_link.c
|
||||
index e3a89f4..2495be4 100644
|
||||
--- a/lib/dns/openssl_link.c
|
||||
+++ b/lib/dns/openssl_link.c
|
||||
@@ -44,6 +44,9 @@
|
||||
#if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000
|
||||
#include <openssl/engine.h>
|
||||
#endif /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
||||
+#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
+#include <openssl/store.h>
|
||||
+#endif
|
||||
|
||||
#include "openssl_shim.h"
|
||||
|
||||
@@ -51,6 +54,12 @@
|
||||
static ENGINE *e = NULL;
|
||||
#endif /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
||||
|
||||
+#define DST_RET(a) \
|
||||
+ { \
|
||||
+ result = a; \
|
||||
+ goto cleanup; \
|
||||
+ }
|
||||
+
|
||||
static void
|
||||
enable_fips_mode(void) {
|
||||
#ifdef HAVE_FIPS_MODE
|
||||
@@ -70,32 +79,28 @@ enable_fips_mode(void) {
|
||||
|
||||
isc_result_t
|
||||
dst__openssl_init(const char *engine) {
|
||||
- isc_result_t result = ISC_R_SUCCESS;
|
||||
-
|
||||
enable_fips_mode();
|
||||
|
||||
-#if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000
|
||||
if (engine != NULL && *engine == '\0') {
|
||||
engine = NULL;
|
||||
}
|
||||
|
||||
- if (engine != NULL) {
|
||||
- e = ENGINE_by_id(engine);
|
||||
- if (e == NULL) {
|
||||
- result = DST_R_NOENGINE;
|
||||
- goto cleanup_rm;
|
||||
- }
|
||||
- if (!ENGINE_init(e)) {
|
||||
- result = DST_R_NOENGINE;
|
||||
- goto cleanup_rm;
|
||||
- }
|
||||
- /* This will init the engine. */
|
||||
- if (!ENGINE_set_default(e, ENGINE_METHOD_ALL)) {
|
||||
- result = DST_R_NOENGINE;
|
||||
- goto cleanup_init;
|
||||
- }
|
||||
+ if (engine == NULL) {
|
||||
+ return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
+#if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000
|
||||
+ e = ENGINE_by_id(engine);
|
||||
+ if (e == NULL) {
|
||||
+ goto cleanup_rm;
|
||||
+ }
|
||||
+ if (!ENGINE_init(e)) {
|
||||
+ goto cleanup_rm;
|
||||
+ }
|
||||
+ /* This will init the engine. */
|
||||
+ if (!ENGINE_set_default(e, ENGINE_METHOD_ALL)) {
|
||||
+ goto cleanup_init;
|
||||
+ }
|
||||
return ISC_R_SUCCESS;
|
||||
cleanup_init:
|
||||
ENGINE_finish(e);
|
||||
@@ -105,10 +110,8 @@ cleanup_rm:
|
||||
}
|
||||
e = NULL;
|
||||
ERR_clear_error();
|
||||
-#else
|
||||
- UNUSED(engine);
|
||||
#endif /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
||||
- return result;
|
||||
+ return (DST_R_NOENGINE);
|
||||
}
|
||||
|
||||
void
|
||||
@@ -220,4 +223,120 @@ dst__openssl_getengine(const char *engine) {
|
||||
}
|
||||
#endif /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
||||
|
||||
+static isc_result_t
|
||||
+dst__openssl_fromlabel_engine(int key_base_id, const char *engine,
|
||||
+ const char *label,
|
||||
+ EVP_PKEY **ppub, EVP_PKEY **ppriv) {
|
||||
+#if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000
|
||||
+ isc_result_t result = ISC_R_SUCCESS;
|
||||
+ ENGINE *e = NULL;
|
||||
+ EVP_PKEY *pkey = NULL, *pubpkey = NULL;
|
||||
+
|
||||
+ UNUSED(key_base_id);
|
||||
+
|
||||
+ e = dst__openssl_getengine(engine);
|
||||
+ if (e == NULL) {
|
||||
+ DST_RET(dst__openssl_toresult(DST_R_NOENGINE));
|
||||
+ }
|
||||
+
|
||||
+ pubpkey = ENGINE_load_public_key(e, label, NULL, NULL);
|
||||
+ if (pubpkey == NULL) {
|
||||
+ DST_RET(dst__openssl_toresult2("ENGINE_load_public_key",
|
||||
+ DST_R_OPENSSLFAILURE));
|
||||
+ }
|
||||
+ if (EVP_PKEY_get_base_id(pubpkey) != key_base_id) {
|
||||
+ DST_RET(DST_R_BADKEYTYPE);
|
||||
+ }
|
||||
+ pkey = ENGINE_load_private_key(e, label, NULL, NULL);
|
||||
+ if (pkey == NULL) {
|
||||
+ DST_RET(dst__openssl_toresult2("ENGINE_load_private_key",
|
||||
+ DST_R_OPENSSLFAILURE));
|
||||
+ }
|
||||
+ if (EVP_PKEY_base_id(pkey) != key_base_id) {
|
||||
+ DST_RET(DST_R_INVALIDPRIVATEKEY);
|
||||
+ }
|
||||
+ *ppub = pubpkey;
|
||||
+ *ppriv = pkey;
|
||||
+cleanup:
|
||||
+ return result;
|
||||
+#else
|
||||
+ UNUSED(key_base_id);
|
||||
+ UNUSED(engine);
|
||||
+ UNUSED(label);
|
||||
+ UNUSED(ppub);
|
||||
+ UNUSED(ppriv);
|
||||
+ return DST_R_NOENGINE;
|
||||
+#endif
|
||||
+}
|
||||
+
|
||||
+
|
||||
+static isc_result_t
|
||||
+dst__openssl_fromlabel_provider(int key_base_id, const char *label, const char *pin,
|
||||
+ EVP_PKEY **ppub, EVP_PKEY **ppriv) {
|
||||
+ UNUSED(pin);
|
||||
+#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
||||
+ isc_result_t result = DST_R_OPENSSLFAILURE;
|
||||
+ OSSL_STORE_CTX *ctx = NULL;
|
||||
+
|
||||
+
|
||||
+ ctx = OSSL_STORE_open(label, NULL, NULL, NULL, NULL);
|
||||
+ if (!ctx) {
|
||||
+ DST_RET(dst__openssl_toresult2("OSSL_STORE_open_ex",
|
||||
+ DST_R_OPENSSLFAILURE));
|
||||
+ }
|
||||
+
|
||||
+ while (!OSSL_STORE_eof(ctx)) {
|
||||
+ OSSL_STORE_INFO *info = OSSL_STORE_load(ctx);
|
||||
+ if (info == NULL) {
|
||||
+ continue;
|
||||
+ }
|
||||
+ switch (OSSL_STORE_INFO_get_type(info)) {
|
||||
+ case OSSL_STORE_INFO_PKEY:
|
||||
+ if (*ppriv != NULL) {
|
||||
+ DST_RET(DST_R_INVALIDPRIVATEKEY);
|
||||
+ }
|
||||
+ *ppriv = OSSL_STORE_INFO_get1_PKEY(info);
|
||||
+ if (EVP_PKEY_get_base_id(*ppriv) != key_base_id) {
|
||||
+ DST_RET(DST_R_BADKEYTYPE);
|
||||
+ }
|
||||
+ break;
|
||||
+ case OSSL_STORE_INFO_PUBKEY:
|
||||
+ if (*ppub != NULL) {
|
||||
+ DST_RET(DST_R_INVALIDPUBLICKEY);
|
||||
+ }
|
||||
+ *ppub = OSSL_STORE_INFO_get1_PUBKEY(info);
|
||||
+ if (EVP_PKEY_get_base_id(*ppub) != key_base_id) {
|
||||
+ DST_RET(DST_R_BADKEYTYPE);
|
||||
+ }
|
||||
+ break;
|
||||
+ }
|
||||
+ OSSL_STORE_INFO_free(info);
|
||||
+ }
|
||||
+ if (*ppriv != NULL && *ppub != NULL) {
|
||||
+ result = ISC_R_SUCCESS;
|
||||
+ }
|
||||
+cleanup:
|
||||
+ OSSL_STORE_close(ctx);
|
||||
+ return result;
|
||||
+#else
|
||||
+ UNUSED(key_base_id);
|
||||
+ UNUSED(label);
|
||||
+ UNUSED(ppub);
|
||||
+ UNUSED(ppriv);
|
||||
+ return (DST_R_OPENSSLFAILURE);
|
||||
+#endif
|
||||
+}
|
||||
+
|
||||
+isc_result_t
|
||||
+dst__openssl_fromlabel(int key_base_id, const char *engine, const char *label,
|
||||
+ const char *pin, EVP_PKEY **ppub, EVP_PKEY **ppriv) {
|
||||
+ if (engine == NULL) {
|
||||
+ return (dst__openssl_fromlabel_provider(key_base_id, label,
|
||||
+ pin, ppub, ppriv));
|
||||
+ }
|
||||
+
|
||||
+ return (dst__openssl_fromlabel_engine(key_base_id, engine, label,
|
||||
+ ppub, ppriv));
|
||||
+}
|
||||
+
|
||||
/*! \file */
|
||||
diff --git a/lib/dns/openssldh_link.c b/lib/dns/openssldh_link.c
|
||||
index a4ba0f7..38345e6 100644
|
||||
--- a/lib/dns/openssldh_link.c
|
||||
+++ b/lib/dns/openssldh_link.c
|
||||
@@ -610,6 +610,11 @@ err:
|
||||
|
||||
static bool
|
||||
openssldh_isprivate(const dst_key_t *key) {
|
||||
+ if (key->label != NULL) {
|
||||
+ /* assume that _fromlabel will not pass without loading private key,
|
||||
+ * but for non-exportable key cannot get d value on the object. */
|
||||
+ return true;
|
||||
+ }
|
||||
#if OPENSSL_VERSION_NUMBER < 0x30000000L || OPENSSL_API_LEVEL < 30000
|
||||
DH *dh = key->keydata.dh;
|
||||
const BIGNUM *priv_key = NULL;
|
||||
diff --git a/lib/dns/opensslecdsa_link.c b/lib/dns/opensslecdsa_link.c
|
||||
index af45fdc..8b49b5d 100644
|
||||
--- a/lib/dns/opensslecdsa_link.c
|
||||
+++ b/lib/dns/opensslecdsa_link.c
|
||||
@@ -617,6 +617,12 @@ opensslecdsa_isprivate(const dst_key_t *key) {
|
||||
return false;
|
||||
}
|
||||
|
||||
+ if (key->label != NULL) {
|
||||
+ /* assume that _fromlabel will not pass without loading private key,
|
||||
+ * but for non-exportable key cannot get d value on the object. */
|
||||
+ return true;
|
||||
+ }
|
||||
+
|
||||
#if OPENSSL_VERSION_NUMBER < 0x30000000L || OPENSSL_API_LEVEL < 30000
|
||||
eckey = EVP_PKEY_get1_EC_KEY(pkey);
|
||||
|
||||
@@ -916,7 +922,7 @@ cleanup:
|
||||
|
||||
#if OPENSSL_VERSION_NUMBER < 0x30000000L || OPENSSL_API_LEVEL < 30000
|
||||
static isc_result_t
|
||||
-ecdsa_check(EC_KEY *eckey, EC_KEY *pubeckey) {
|
||||
+ecdsa_check_legacy(EC_KEY *eckey, EC_KEY *pubeckey) {
|
||||
const EC_POINT *pubkey;
|
||||
|
||||
pubkey = EC_KEY_get0_public_key(eckey);
|
||||
@@ -937,9 +943,42 @@ ecdsa_check(EC_KEY *eckey, EC_KEY *pubeckey) {
|
||||
|
||||
return ISC_R_FAILURE;
|
||||
}
|
||||
+
|
||||
+static isc_result_t
|
||||
+ecdsa_check(EVP_PKEY **pkey, EVP_PKEY *pubpkey, int group_nid) {
|
||||
+ isc_result_t result = ISC_R_FAILURE;
|
||||
+ EC_KEY *eckey;
|
||||
+ EC_KEY *pubeckey;
|
||||
+
|
||||
+ eckey = EVP_PKEY_get1_EC_KEY(*pkey);
|
||||
+ if (eckey == NULL) {
|
||||
+ DST_RET(dst__openssl_toresult(DST_R_OPENSSLFAILURE));
|
||||
+ }
|
||||
+ if (EC_GROUP_get_curve_name(EC_KEY_get0_group(eckey)) != group_nid) {
|
||||
+ DST_RET(DST_R_INVALIDPRIVATEKEY);
|
||||
+ }
|
||||
+
|
||||
+ pubeckey = EVP_PKEY_get1_EC_KEY(pubpkey);
|
||||
+ if (pubeckey == NULL) {
|
||||
+ DST_RET(dst__openssl_toresult(DST_R_OPENSSLFAILURE));
|
||||
+ }
|
||||
+ if (EC_GROUP_get_curve_name(EC_KEY_get0_group(pubeckey)) != group_nid) {
|
||||
+ DST_RET(DST_R_INVALIDPUBLICKEY);
|
||||
+ }
|
||||
+
|
||||
+ CHECK(ecdsa_check_legacy(eckey, pubeckey));
|
||||
+cleanup:
|
||||
+ if (pubeckey != NULL) {
|
||||
+ EC_KEY_free(pubeckey);
|
||||
+ }
|
||||
+ if (eckey != NULL) {
|
||||
+ EC_KEY_free(eckey);
|
||||
+ }
|
||||
+ return result;
|
||||
+}
|
||||
#else
|
||||
static isc_result_t
|
||||
-ecdsa_check(EVP_PKEY **pkey, EVP_PKEY *pubpkey) {
|
||||
+ecdsa_check(EVP_PKEY **pkey, EVP_PKEY *pubpkey, int group_nid) {
|
||||
isc_result_t result = ISC_R_FAILURE;
|
||||
int status;
|
||||
size_t pkey_len = 0;
|
||||
@@ -954,6 +993,8 @@ ecdsa_check(EVP_PKEY **pkey, EVP_PKEY *pubpkey) {
|
||||
EVP_PKEY_CTX *ctx = NULL;
|
||||
EVP_PKEY *pkey_new = NULL;
|
||||
|
||||
+ UNUSED(group_nid);
|
||||
+
|
||||
/* Check if `pkey` has a public key. */
|
||||
status = EVP_PKEY_get_octet_string_param(*pkey, OSSL_PKEY_PARAM_PUB_KEY,
|
||||
NULL, 0, &pkey_len);
|
||||
@@ -1267,7 +1308,7 @@ opensslecdsa_parse(dst_key_t *key, isc_lex_t *lexer, dst_key_t *pub) {
|
||||
pubeckey = EVP_PKEY_get1_EC_KEY(pub->keydata.pkey);
|
||||
}
|
||||
|
||||
- if (ecdsa_check(eckey, pubeckey) != ISC_R_SUCCESS) {
|
||||
+ if (ecdsa_check_legacy(eckey, pubeckey) != ISC_R_SUCCESS) {
|
||||
DST_RET(dst__openssl_toresult(DST_R_INVALIDPRIVATEKEY));
|
||||
}
|
||||
|
||||
@@ -1276,7 +1317,7 @@ opensslecdsa_parse(dst_key_t *key, isc_lex_t *lexer, dst_key_t *pub) {
|
||||
}
|
||||
#else
|
||||
if (ecdsa_check(&key->keydata.pkey,
|
||||
- pub == NULL ? NULL : pub->keydata.pkey) !=
|
||||
+ pub == NULL ? NULL : pub->keydata.pkey, NID_undef) !=
|
||||
ISC_R_SUCCESS)
|
||||
{
|
||||
DST_RET(dst__openssl_toresult(DST_R_INVALIDPRIVATEKEY));
|
||||
@@ -1309,11 +1350,7 @@ cleanup:
|
||||
static isc_result_t
|
||||
opensslecdsa_fromlabel(dst_key_t *key, const char *engine, const char *label,
|
||||
const char *pin) {
|
||||
-#if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
- ENGINE *e;
|
||||
- EC_KEY *eckey = NULL;
|
||||
- EC_KEY *pubeckey = NULL;
|
||||
int group_nid;
|
||||
EVP_PKEY *pkey = NULL;
|
||||
EVP_PKEY *pubpkey = NULL;
|
||||
@@ -1323,13 +1360,9 @@ opensslecdsa_fromlabel(dst_key_t *key, const char *engine, const char *label,
|
||||
|
||||
UNUSED(pin);
|
||||
|
||||
- if (engine == NULL || label == NULL) {
|
||||
+ if (label == NULL) {
|
||||
return DST_R_NOENGINE;
|
||||
}
|
||||
- e = dst__openssl_getengine(engine);
|
||||
- if (e == NULL) {
|
||||
- DST_RET(DST_R_NOENGINE);
|
||||
- }
|
||||
|
||||
if (key->key_alg == DST_ALG_ECDSA256) {
|
||||
group_nid = NID_X9_62_prime256v1;
|
||||
@@ -1337,48 +1370,27 @@ opensslecdsa_fromlabel(dst_key_t *key, const char *engine, const char *label,
|
||||
group_nid = NID_secp384r1;
|
||||
}
|
||||
|
||||
- /* Load private key. */
|
||||
- pkey = ENGINE_load_private_key(e, label, NULL, NULL);
|
||||
- if (pkey == NULL) {
|
||||
- DST_RET(dst__openssl_toresult2("ENGINE_load_private_key",
|
||||
- DST_R_OPENSSLFAILURE));
|
||||
- }
|
||||
+ CHECK(dst__openssl_fromlabel(EVP_PKEY_EC, engine, label, pin,
|
||||
+ &pubpkey, &pkey));
|
||||
+
|
||||
/* Check base id, group nid */
|
||||
if (EVP_PKEY_base_id(pkey) != EVP_PKEY_EC) {
|
||||
DST_RET(DST_R_INVALIDPRIVATEKEY);
|
||||
}
|
||||
- eckey = EVP_PKEY_get1_EC_KEY(pkey);
|
||||
- if (eckey == NULL) {
|
||||
- DST_RET(dst__openssl_toresult(DST_R_OPENSSLFAILURE));
|
||||
- }
|
||||
- if (EC_GROUP_get_curve_name(EC_KEY_get0_group(eckey)) != group_nid) {
|
||||
- DST_RET(DST_R_INVALIDPRIVATEKEY);
|
||||
- }
|
||||
-
|
||||
- /* Load public key. */
|
||||
- pubpkey = ENGINE_load_public_key(e, label, NULL, NULL);
|
||||
- if (pubpkey == NULL) {
|
||||
- DST_RET(dst__openssl_toresult2("ENGINE_load_public_key",
|
||||
- DST_R_OPENSSLFAILURE));
|
||||
- }
|
||||
/* Check base id, group nid */
|
||||
if (EVP_PKEY_base_id(pubpkey) != EVP_PKEY_EC) {
|
||||
DST_RET(DST_R_INVALIDPUBLICKEY);
|
||||
}
|
||||
- pubeckey = EVP_PKEY_get1_EC_KEY(pubpkey);
|
||||
- if (pubeckey == NULL) {
|
||||
- DST_RET(dst__openssl_toresult(DST_R_OPENSSLFAILURE));
|
||||
- }
|
||||
- if (EC_GROUP_get_curve_name(EC_KEY_get0_group(pubeckey)) != group_nid) {
|
||||
- DST_RET(DST_R_INVALIDPUBLICKEY);
|
||||
- }
|
||||
|
||||
- if (ecdsa_check(eckey, pubeckey) != ISC_R_SUCCESS) {
|
||||
+ if (ecdsa_check(&pkey, pubpkey, group_nid) != ISC_R_SUCCESS) {
|
||||
DST_RET(dst__openssl_toresult(DST_R_INVALIDPRIVATEKEY));
|
||||
}
|
||||
|
||||
+ if (engine != NULL)
|
||||
+ key->engine = isc_mem_strdup(key->mctx, engine);
|
||||
+ else
|
||||
+ key->engine = NULL;
|
||||
key->label = isc_mem_strdup(key->mctx, label);
|
||||
- key->engine = isc_mem_strdup(key->mctx, engine);
|
||||
key->key_size = EVP_PKEY_bits(pkey);
|
||||
key->keydata.pkey = pkey;
|
||||
pkey = NULL;
|
||||
@@ -1390,21 +1402,8 @@ cleanup:
|
||||
if (pkey != NULL) {
|
||||
EVP_PKEY_free(pkey);
|
||||
}
|
||||
- if (pubeckey != NULL) {
|
||||
- EC_KEY_free(pubeckey);
|
||||
- }
|
||||
- if (eckey != NULL) {
|
||||
- EC_KEY_free(eckey);
|
||||
- }
|
||||
|
||||
return result;
|
||||
-#else
|
||||
- UNUSED(key);
|
||||
- UNUSED(engine);
|
||||
- UNUSED(label);
|
||||
- UNUSED(pin);
|
||||
- return DST_R_NOENGINE;
|
||||
-#endif /* !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
||||
}
|
||||
|
||||
static dst_func_t opensslecdsa_functions = {
|
||||
diff --git a/lib/dns/openssleddsa_link.c b/lib/dns/openssleddsa_link.c
|
||||
index 6301db4..08d505b 100644
|
||||
--- a/lib/dns/openssleddsa_link.c
|
||||
+++ b/lib/dns/openssleddsa_link.c
|
||||
@@ -362,6 +362,12 @@ openssleddsa_isprivate(const dst_key_t *key) {
|
||||
return false;
|
||||
}
|
||||
|
||||
+ if (key->label != NULL) {
|
||||
+ /* assume that _fromlabel will not pass without loading private key,
|
||||
+ * but for non-exportable key cannot get d value on the object. */
|
||||
+ return true;
|
||||
+ }
|
||||
+
|
||||
/* Must have a buffer to actually check if there is a private key. */
|
||||
if (EVP_PKEY_get_raw_private_key(pkey, buf, &len) == 1) {
|
||||
return true;
|
||||
@@ -591,9 +597,7 @@ cleanup:
|
||||
static isc_result_t
|
||||
openssleddsa_fromlabel(dst_key_t *key, const char *engine, const char *label,
|
||||
const char *pin) {
|
||||
-#if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000
|
||||
isc_result_t result;
|
||||
- ENGINE *e;
|
||||
EVP_PKEY *pkey = NULL, *pubpkey = NULL;
|
||||
int baseid = EVP_PKEY_NONE;
|
||||
|
||||
@@ -616,28 +620,17 @@ openssleddsa_fromlabel(dst_key_t *key, const char *engine, const char *label,
|
||||
return ISC_R_NOTIMPLEMENTED;
|
||||
}
|
||||
|
||||
- if (engine == NULL) {
|
||||
- return DST_R_NOENGINE;
|
||||
- }
|
||||
- e = dst__openssl_getengine(engine);
|
||||
- if (e == NULL) {
|
||||
- return DST_R_NOENGINE;
|
||||
- }
|
||||
- pkey = ENGINE_load_private_key(e, label, NULL, NULL);
|
||||
- if (pkey == NULL) {
|
||||
- return dst__openssl_toresult2("ENGINE_load_private_key",
|
||||
- ISC_R_NOTFOUND);
|
||||
- }
|
||||
- if (EVP_PKEY_base_id(pkey) != baseid) {
|
||||
- DST_RET(DST_R_INVALIDPRIVATEKEY);
|
||||
- }
|
||||
+ DST_RET(dst__openssl_fromlabel(baseid, engine, label, pin,
|
||||
+ &pubpkey, &pkey));
|
||||
|
||||
- pubpkey = ENGINE_load_public_key(e, label, NULL, NULL);
|
||||
- if (eddsa_check(pkey, pubpkey) != ISC_R_SUCCESS) {
|
||||
+ if (EVP_PKEY_base_id(pkey) != baseid) {
|
||||
DST_RET(DST_R_INVALIDPRIVATEKEY);
|
||||
}
|
||||
|
||||
- key->engine = isc_mem_strdup(key->mctx, engine);
|
||||
+ if (engine != NULL)
|
||||
+ key->engine = isc_mem_strdup(key->mctx, engine);
|
||||
+ else
|
||||
+ key->engine = NULL;
|
||||
key->label = isc_mem_strdup(key->mctx, label);
|
||||
key->key_size = EVP_PKEY_bits(pkey);
|
||||
key->keydata.pkey = pkey;
|
||||
@@ -652,13 +645,6 @@ cleanup:
|
||||
EVP_PKEY_free(pkey);
|
||||
}
|
||||
return result;
|
||||
-#else /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
||||
- UNUSED(key);
|
||||
- UNUSED(engine);
|
||||
- UNUSED(label);
|
||||
- UNUSED(pin);
|
||||
- return DST_R_NOENGINE;
|
||||
-#endif /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
||||
}
|
||||
|
||||
static dst_func_t openssleddsa_functions = {
|
||||
diff --git a/lib/dns/opensslrsa_link.c b/lib/dns/opensslrsa_link.c
|
||||
index b92e1bf..12210e8 100644
|
||||
--- a/lib/dns/opensslrsa_link.c
|
||||
+++ b/lib/dns/opensslrsa_link.c
|
||||
@@ -545,6 +545,12 @@ opensslrsa_isprivate(const dst_key_t *key) {
|
||||
return false;
|
||||
}
|
||||
|
||||
+ if (key->label != NULL) {
|
||||
+ /* assume that _fromlabel will not pass without loading private key,
|
||||
+ * but for non-exportable key cannot get d value on the object. */
|
||||
+ return true;
|
||||
+ }
|
||||
+
|
||||
#if OPENSSL_VERSION_NUMBER < 0x30000000L || OPENSSL_API_LEVEL < 30000
|
||||
rsa = EVP_PKEY_get1_RSA(pkey);
|
||||
INSIST(rsa != NULL);
|
||||
@@ -995,7 +1001,7 @@ cleanup:
|
||||
|
||||
#if OPENSSL_VERSION_NUMBER < 0x30000000L || OPENSSL_API_LEVEL < 30000
|
||||
static isc_result_t
|
||||
-rsa_check(RSA *rsa, RSA *pub) {
|
||||
+rsa_check_legacy(RSA *rsa, RSA *pub) {
|
||||
const BIGNUM *n1 = NULL, *n2 = NULL;
|
||||
const BIGNUM *e1 = NULL, *e2 = NULL;
|
||||
BIGNUM *n = NULL, *e = NULL;
|
||||
@@ -1050,6 +1056,46 @@ rsa_check(RSA *rsa, RSA *pub) {
|
||||
|
||||
return ISC_R_SUCCESS;
|
||||
}
|
||||
+
|
||||
+static isc_result_t
|
||||
+rsa_check(EVP_PKEY *pkey, EVP_PKEY *pubpkey) {
|
||||
+ isc_result_t ret = ISC_R_FAILURE;
|
||||
+ RSA *rsa = NULL, *pubrsa = NULL;
|
||||
+ const BIGNUM *ex = NULL;
|
||||
+
|
||||
+ pubrsa = EVP_PKEY_get1_RSA(pubpkey);
|
||||
+ if (pubrsa == NULL) {
|
||||
+ DST_RET(dst__openssl_toresult(DST_R_OPENSSLFAILURE));
|
||||
+ }
|
||||
+
|
||||
+ rsa = EVP_PKEY_get1_RSA(pkey);
|
||||
+ if (rsa == NULL) {
|
||||
+ DST_RET(dst__openssl_toresult(DST_R_OPENSSLFAILURE));
|
||||
+ }
|
||||
+
|
||||
+ ret = rsa_check_legacy(rsa, pubrsa);
|
||||
+ if (ret != ISC_R_SUCCESS) {
|
||||
+ DST_RET(ret);
|
||||
+ }
|
||||
+
|
||||
+ RSA_get0_key(rsa, NULL, &ex, NULL);
|
||||
+
|
||||
+ if (ex == NULL) {
|
||||
+ DST_RET(dst__openssl_toresult(DST_R_INVALIDPRIVATEKEY));
|
||||
+ }
|
||||
+ if (BN_num_bits(ex) > RSA_MAX_PUBEXP_BITS) {
|
||||
+ DST_RET(ISC_R_RANGE);
|
||||
+ }
|
||||
+
|
||||
+err:
|
||||
+ if (rsa != NULL) {
|
||||
+ RSA_free(rsa);
|
||||
+ }
|
||||
+ if (pubrsa != NULL) {
|
||||
+ RSA_free(pubrsa);
|
||||
+ }
|
||||
+ return ret;
|
||||
+}
|
||||
#else
|
||||
static isc_result_t
|
||||
rsa_check(EVP_PKEY *pkey, EVP_PKEY *pubpkey) {
|
||||
@@ -1097,6 +1143,10 @@ rsa_check(EVP_PKEY *pkey, EVP_PKEY *pubpkey) {
|
||||
}
|
||||
}
|
||||
|
||||
+ if (BN_num_bits(e1) > RSA_MAX_PUBEXP_BITS) {
|
||||
+ DST_RET(ISC_R_RANGE);
|
||||
+ }
|
||||
+
|
||||
if (EVP_PKEY_eq(pkey, pubpkey) == 1) {
|
||||
DST_RET(ISC_R_SUCCESS);
|
||||
}
|
||||
@@ -1119,6 +1169,10 @@ cleanup:
|
||||
}
|
||||
#endif /* OPENSSL_VERSION_NUMBER < 0x30000000L || OPENSSL_API_LEVEL < 30000 */
|
||||
|
||||
+static isc_result_t
|
||||
+opensslrsa_fromlabel(dst_key_t *key, const char *engine, const char *label,
|
||||
+ const char *pin);
|
||||
+
|
||||
static isc_result_t
|
||||
opensslrsa_parse(dst_key_t *key, isc_lex_t *lexer, dst_key_t *pub) {
|
||||
dst_private_t priv;
|
||||
@@ -1131,12 +1185,8 @@ opensslrsa_parse(dst_key_t *key, isc_lex_t *lexer, dst_key_t *pub) {
|
||||
OSSL_PARAM *params = NULL;
|
||||
EVP_PKEY_CTX *ctx = NULL;
|
||||
#endif /* OPENSSL_VERSION_NUMBER < 0x30000000L || OPENSSL_API_LEVEL < 30000 */
|
||||
-#if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000
|
||||
- const BIGNUM *ex = NULL;
|
||||
- ENGINE *ep = NULL;
|
||||
- const char *engine = NULL;
|
||||
-#endif /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
||||
isc_mem_t *mctx = NULL;
|
||||
+ const char *engine = NULL;
|
||||
const char *label = NULL;
|
||||
EVP_PKEY *pkey = NULL;
|
||||
BIGNUM *n = NULL, *e = NULL, *d = NULL;
|
||||
@@ -1190,46 +1240,7 @@ opensslrsa_parse(dst_key_t *key, isc_lex_t *lexer, dst_key_t *pub) {
|
||||
* See if we can fetch it.
|
||||
*/
|
||||
if (label != NULL) {
|
||||
-#if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000
|
||||
- if (engine == NULL) {
|
||||
- DST_RET(DST_R_NOENGINE);
|
||||
- }
|
||||
- ep = dst__openssl_getengine(engine);
|
||||
- if (ep == NULL) {
|
||||
- DST_RET(dst__openssl_toresult(DST_R_NOENGINE));
|
||||
- }
|
||||
- pkey = ENGINE_load_private_key(ep, label, NULL, NULL);
|
||||
- if (pkey == NULL) {
|
||||
- DST_RET(dst__openssl_toresult2("ENGINE_load_private_"
|
||||
- "key",
|
||||
- ISC_R_NOTFOUND));
|
||||
- }
|
||||
- key->engine = isc_mem_strdup(key->mctx, engine);
|
||||
- key->label = isc_mem_strdup(key->mctx, label);
|
||||
-
|
||||
- rsa = EVP_PKEY_get1_RSA(pkey);
|
||||
- if (rsa == NULL) {
|
||||
- DST_RET(dst__openssl_toresult(DST_R_OPENSSLFAILURE));
|
||||
- }
|
||||
- if (rsa_check(rsa, pubrsa) != ISC_R_SUCCESS) {
|
||||
- DST_RET(dst__openssl_toresult(DST_R_INVALIDPRIVATEKEY));
|
||||
- }
|
||||
- RSA_get0_key(rsa, NULL, &ex, NULL);
|
||||
-
|
||||
- if (ex == NULL) {
|
||||
- DST_RET(dst__openssl_toresult(DST_R_INVALIDPRIVATEKEY));
|
||||
- }
|
||||
- if (BN_num_bits(ex) > RSA_MAX_PUBEXP_BITS) {
|
||||
- DST_RET(ISC_R_RANGE);
|
||||
- }
|
||||
-
|
||||
- key->key_size = EVP_PKEY_bits(pkey);
|
||||
- key->keydata.pkey = pkey;
|
||||
- pkey = NULL;
|
||||
- DST_RET(ISC_R_SUCCESS);
|
||||
-#else /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
||||
- DST_RET(DST_R_NOENGINE);
|
||||
-#endif /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
||||
+ DST_RET(opensslrsa_fromlabel(key, engine, label, NULL));
|
||||
}
|
||||
|
||||
for (i = 0; i < priv.nelements; i++) {
|
||||
@@ -1318,9 +1329,14 @@ opensslrsa_parse(dst_key_t *key, isc_lex_t *lexer, dst_key_t *pub) {
|
||||
BN_clear_free(iqmp);
|
||||
}
|
||||
}
|
||||
- if (rsa_check(rsa, pubrsa) != ISC_R_SUCCESS) {
|
||||
+ if (rsa_check_legacy(rsa, pubrsa) != ISC_R_SUCCESS) {
|
||||
DST_RET(dst__openssl_toresult(DST_R_INVALIDPRIVATEKEY));
|
||||
}
|
||||
+
|
||||
+ if (BN_num_bits(e) > RSA_MAX_PUBEXP_BITS) {
|
||||
+ DST_RET(ISC_R_RANGE);
|
||||
+ }
|
||||
+
|
||||
#else
|
||||
bld = OSSL_PARAM_BLD_new();
|
||||
if (bld == NULL) {
|
||||
@@ -1387,17 +1403,9 @@ opensslrsa_parse(dst_key_t *key, isc_lex_t *lexer, dst_key_t *pub) {
|
||||
DST_RET(dst__openssl_toresult(DST_R_OPENSSLFAILURE));
|
||||
}
|
||||
|
||||
- if (rsa_check(pkey, pub != NULL ? pub->keydata.pkey : NULL) !=
|
||||
- ISC_R_SUCCESS)
|
||||
- {
|
||||
- DST_RET(dst__openssl_toresult(DST_R_INVALIDPRIVATEKEY));
|
||||
- }
|
||||
+ CHECK(rsa_check(pkey, pub != NULL ? pub->keydata.pkey : NULL));
|
||||
#endif /* OPENSSL_VERSION_NUMBER < 0x30000000L || OPENSSL_API_LEVEL < 30000 */
|
||||
|
||||
- if (BN_num_bits(e) > RSA_MAX_PUBEXP_BITS) {
|
||||
- DST_RET(ISC_R_RANGE);
|
||||
- }
|
||||
-
|
||||
key->key_size = BN_num_bits(n);
|
||||
key->keydata.pkey = pkey;
|
||||
pkey = NULL;
|
||||
@@ -1461,69 +1469,31 @@ cleanup:
|
||||
static isc_result_t
|
||||
opensslrsa_fromlabel(dst_key_t *key, const char *engine, const char *label,
|
||||
const char *pin) {
|
||||
-#if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000
|
||||
- ENGINE *e = NULL;
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
EVP_PKEY *pkey = NULL, *pubpkey = NULL;
|
||||
- RSA *rsa = NULL, *pubrsa = NULL;
|
||||
- const BIGNUM *ex = NULL;
|
||||
|
||||
UNUSED(pin);
|
||||
|
||||
- if (engine == NULL) {
|
||||
- DST_RET(DST_R_NOENGINE);
|
||||
- }
|
||||
- e = dst__openssl_getengine(engine);
|
||||
- if (e == NULL) {
|
||||
- DST_RET(dst__openssl_toresult(DST_R_NOENGINE));
|
||||
- }
|
||||
+ CHECK(dst__openssl_fromlabel(EVP_PKEY_RSA, engine, label, pin,
|
||||
+ &pubpkey, &pkey));
|
||||
+ CHECK(rsa_check(pkey, pubpkey));
|
||||
|
||||
- pubpkey = ENGINE_load_public_key(e, label, NULL, NULL);
|
||||
- if (pubpkey == NULL) {
|
||||
- DST_RET(dst__openssl_toresult2("ENGINE_load_public_key",
|
||||
- DST_R_OPENSSLFAILURE));
|
||||
- }
|
||||
- pubrsa = EVP_PKEY_get1_RSA(pubpkey);
|
||||
- if (pubrsa == NULL) {
|
||||
- DST_RET(dst__openssl_toresult(DST_R_OPENSSLFAILURE));
|
||||
- }
|
||||
-
|
||||
- pkey = ENGINE_load_private_key(e, label, NULL, NULL);
|
||||
if (pkey == NULL) {
|
||||
- DST_RET(dst__openssl_toresult2("ENGINE_load_private_key",
|
||||
+ DST_RET(dst__openssl_toresult2("dst__openssl_fromlabel",
|
||||
DST_R_OPENSSLFAILURE));
|
||||
}
|
||||
|
||||
- key->engine = isc_mem_strdup(key->mctx, engine);
|
||||
+ if (engine != NULL)
|
||||
+ key->engine = isc_mem_strdup(key->mctx, engine);
|
||||
+ else
|
||||
+ key->engine = NULL;
|
||||
key->label = isc_mem_strdup(key->mctx, label);
|
||||
|
||||
- rsa = EVP_PKEY_get1_RSA(pkey);
|
||||
- if (rsa == NULL) {
|
||||
- DST_RET(dst__openssl_toresult(DST_R_OPENSSLFAILURE));
|
||||
- }
|
||||
- if (rsa_check(rsa, pubrsa) != ISC_R_SUCCESS) {
|
||||
- DST_RET(dst__openssl_toresult(DST_R_INVALIDPRIVATEKEY));
|
||||
- }
|
||||
- RSA_get0_key(rsa, NULL, &ex, NULL);
|
||||
-
|
||||
- if (ex == NULL) {
|
||||
- DST_RET(dst__openssl_toresult(DST_R_INVALIDPRIVATEKEY));
|
||||
- }
|
||||
- if (BN_num_bits(ex) > RSA_MAX_PUBEXP_BITS) {
|
||||
- DST_RET(ISC_R_RANGE);
|
||||
- }
|
||||
-
|
||||
key->key_size = EVP_PKEY_bits(pkey);
|
||||
key->keydata.pkey = pkey;
|
||||
pkey = NULL;
|
||||
|
||||
cleanup:
|
||||
- if (rsa != NULL) {
|
||||
- RSA_free(rsa);
|
||||
- }
|
||||
- if (pubrsa != NULL) {
|
||||
- RSA_free(pubrsa);
|
||||
- }
|
||||
if (pkey != NULL) {
|
||||
EVP_PKEY_free(pkey);
|
||||
}
|
||||
@@ -1531,13 +1501,6 @@ cleanup:
|
||||
EVP_PKEY_free(pubpkey);
|
||||
}
|
||||
return result;
|
||||
-#else /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
||||
- UNUSED(key);
|
||||
- UNUSED(engine);
|
||||
- UNUSED(label);
|
||||
- UNUSED(pin);
|
||||
- return DST_R_NOENGINE;
|
||||
-#endif /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
||||
}
|
||||
|
||||
static dst_func_t opensslrsa_functions = {
|
||||
--
|
||||
2.52.0
|
||||
|
||||
75
bind-9.18-unittest-netmgr-unstable.patch
Normal file
75
bind-9.18-unittest-netmgr-unstable.patch
Normal file
|
|
@ -0,0 +1,75 @@
|
|||
From 0f3a398fe813189c5dd56b0367a72c7b3f19504b Mon Sep 17 00:00:00 2001
|
||||
From: Petr Mensik <pemensik@redhat.com>
|
||||
Date: Wed, 14 Sep 2022 13:06:24 +0200
|
||||
Subject: [PATCH] Disable some often failing tests
|
||||
|
||||
Make those tests skipped in default build, when CI=true environment is
|
||||
set. It is not clear why they fail mostly on COPR, but they do fail
|
||||
often.
|
||||
---
|
||||
tests/isc/netmgr_test.c | 9 +++++++--
|
||||
1 file changed, 7 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/tests/isc/netmgr_test.c b/tests/isc/netmgr_test.c
|
||||
index 94e4bf7..7f9629c 100644
|
||||
--- a/tests/isc/netmgr_test.c
|
||||
+++ b/tests/isc/netmgr_test.c
|
||||
@@ -1567,13 +1567,13 @@ stream_half_recv_half_send(void **state __attribute__((unused))) {
|
||||
/* TCP */
|
||||
ISC_RUN_TEST_IMPL(tcp_noop) { stream_noop(state); }
|
||||
|
||||
-ISC_RUN_TEST_IMPL(tcp_noresponse) { stream_noresponse(state); }
|
||||
+ISC_RUN_TEST_IMPL(tcp_noresponse) { SKIP_IN_CI; stream_noresponse(state); }
|
||||
|
||||
ISC_RUN_TEST_IMPL(tcp_timeout_recovery) { stream_timeout_recovery(state); }
|
||||
|
||||
ISC_RUN_TEST_IMPL(tcp_recv_one) { stream_recv_one(state); }
|
||||
|
||||
-ISC_RUN_TEST_IMPL(tcp_recv_two) { stream_recv_two(state); }
|
||||
+ISC_RUN_TEST_IMPL(tcp_recv_two) { SKIP_IN_CI; stream_recv_two(state); }
|
||||
|
||||
ISC_RUN_TEST_IMPL(tcp_recv_send) {
|
||||
SKIP_IN_CI;
|
||||
@@ -1623,6 +1623,7 @@ ISC_RUN_TEST_IMPL(tcp_recv_one_quota) {
|
||||
}
|
||||
|
||||
ISC_RUN_TEST_IMPL(tcp_recv_two_quota) {
|
||||
+ SKIP_IN_CI;
|
||||
atomic_store(&check_listener_quota, true);
|
||||
stream_recv_two(state);
|
||||
}
|
||||
@@ -1836,6 +1837,7 @@ ISC_RUN_TEST_IMPL(tcpdns_recv_two) {
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
isc_nmsocket_t *listen_sock = NULL;
|
||||
|
||||
+ SKIP_IN_CI;
|
||||
atomic_store(&nsends, 2);
|
||||
|
||||
result = isc_nm_listentcpdns(listen_nm, &tcp_listen_addr,
|
||||
@@ -2095,6 +2097,7 @@ ISC_RUN_TEST_IMPL(tls_recv_one) {
|
||||
}
|
||||
|
||||
ISC_RUN_TEST_IMPL(tls_recv_two) {
|
||||
+ SKIP_IN_CI;
|
||||
stream_use_TLS = true;
|
||||
stream_recv_two(state);
|
||||
}
|
||||
@@ -2160,6 +2163,7 @@ ISC_RUN_TEST_IMPL(tls_recv_one_quota) {
|
||||
}
|
||||
|
||||
ISC_RUN_TEST_IMPL(tls_recv_two_quota) {
|
||||
+ SKIP_IN_CI;
|
||||
stream_use_TLS = true;
|
||||
atomic_store(&check_listener_quota, true);
|
||||
stream_recv_two(state);
|
||||
@@ -2395,6 +2399,7 @@ ISC_RUN_TEST_IMPL(tlsdns_recv_two) {
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
isc_nmsocket_t *listen_sock = NULL;
|
||||
|
||||
+ SKIP_IN_CI;
|
||||
atomic_store(&nsends, 2);
|
||||
|
||||
result = isc_nm_listentlsdns(listen_nm, &tcp_listen_addr,
|
||||
--
|
||||
2.37.2
|
||||
|
||||
|
|
@ -1,14 +0,0 @@
|
|||
--- bind-9.2.0rc3/bin/named/include/named/globals.h.varrun Thu Sep 13 01:59:38 2001
|
||||
+++ bind-9.2.0rc3/bin/named/include/named/globals.h Fri Sep 14 12:45:42 2001
|
||||
@@ -102,9 +102,9 @@
|
||||
EXTERN isc_boolean_t ns_g_logstderr INIT(ISC_FALSE);
|
||||
|
||||
EXTERN const char * ns_g_defaultpidfile INIT(NS_LOCALSTATEDIR
|
||||
- "/run/named.pid");
|
||||
+ "/run/named/named.pid");
|
||||
EXTERN const char * lwresd_g_defaultpidfile INIT(NS_LOCALSTATEDIR
|
||||
- "/run/lwresd.pid");
|
||||
+ "/run/named/lwresd.pid");
|
||||
EXTERN const char * ns_g_username INIT(NULL);
|
||||
|
||||
#undef EXTERN
|
||||
|
|
@ -1,11 +0,0 @@
|
|||
--- bind-9.2.2/configure.lr 2003-09-12 08:17:34.000000000 -0600
|
||||
+++ bind-9.2.2/configure 2003-09-12 08:17:52.000000000 -0600
|
||||
@@ -6178,7 +6178,7 @@
|
||||
echo $ECHO_N "(cached) $ECHO_C" >&6
|
||||
else
|
||||
ac_check_lib_save_LIBS=$LIBS
|
||||
-LIBS="-lnsl $LIBS"
|
||||
+LIBS="-lXXXnsl $LIBS"
|
||||
cat >conftest.$ac_ext <<_ACEOF
|
||||
#line $LINENO "configure"
|
||||
#include "confdefs.h"
|
||||
114
bind-9.20-nsupdate-tls-doc.patch
Normal file
114
bind-9.20-nsupdate-tls-doc.patch
Normal file
|
|
@ -0,0 +1,114 @@
|
|||
From c5c756ce2ac4c1563d024428e148ca27c7721f71 Mon Sep 17 00:00:00 2001
|
||||
From: Aram Sargsyan <aram@isc.org>
|
||||
Date: Wed, 21 Sep 2022 15:05:11 +0000
|
||||
Subject: [PATCH 2/3] Document nsupdate options related to DoT
|
||||
|
||||
Add documentation for the newly implemented DoT feature of the
|
||||
nsupdate program.
|
||||
|
||||
(cherry picked from commit bd8299d7b501234263a6aee98049f879b1c700b7)
|
||||
---
|
||||
bin/nsupdate/nsupdate.rst | 48 ++++++++++++++++++++++++++++++++++++++-
|
||||
1 file changed, 47 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/bin/nsupdate/nsupdate.rst b/bin/nsupdate/nsupdate.rst
|
||||
index 81bb4815cf4..f1ab5c76fa7 100644
|
||||
--- a/bin/nsupdate/nsupdate.rst
|
||||
+++ b/bin/nsupdate/nsupdate.rst
|
||||
@@ -19,7 +19,7 @@ nsupdate - dynamic DNS update utility
|
||||
Synopsis
|
||||
~~~~~~~~
|
||||
|
||||
-:program:`nsupdate` [**-d**] [**-D**] [**-i**] [**-L** level] [ [**-g**] | [**-o**] | [**-l**] | [**-y** [hmac:]keyname:secret] | [**-k** keyfile] ] [**-t** timeout] [**-u** udptimeout] [**-r** udpretries] [**-v**] [**-T**] [**-P**] [**-V**] [ [**-4**] | [**-6**] ] [filename]
|
||||
+:program:`nsupdate` [**-d**] [**-D**] [**-i**] [**-L** level] [ [**-g**] | [**-o**] | [**-l**] | [**-y** [hmac:]keyname:secret] | [**-k** keyfile] ] [ [**-S**] [**-K** tlskeyfile] [**-E** tlscertfile] [**-A** tlscafile] [**-H** tlshostname] [-O] ] [**-t** timeout] [**-u** udptimeout] [**-r** udpretries] [**-v**] [**-T**] [**-P**] [**-V**] [ [**-4**] | [**-6**] ] [filename]
|
||||
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
@@ -71,6 +71,15 @@ Options
|
||||
|
||||
This option sets use of IPv6 only.
|
||||
|
||||
+.. option:: -A tlscafile
|
||||
+
|
||||
+ This option specifies the file of the certificate authorities (CA) certificates
|
||||
+ (in PEM format) in order to verify the remote server TLS certificate when
|
||||
+ using DNS-over-TLS (DoT), to achieve Strict or Mutual TLS. When used, it will
|
||||
+ override the certificates from the global certificates store, which are
|
||||
+ otherwise used by default when :option:`-S` is enabled. This option can not
|
||||
+ be used in conjuction with :option:`-O`, and it implies :option:`-S`.
|
||||
+
|
||||
.. option:: -C
|
||||
|
||||
Overrides the default `resolv.conf` file. This is only intended for testing.
|
||||
@@ -84,10 +93,23 @@ Options
|
||||
|
||||
This option sets extra debug mode.
|
||||
|
||||
+.. option:: -E tlscertfile
|
||||
+
|
||||
+ This option sets the certificate(s) file for authentication for the
|
||||
+ DNS-over-TLS (DoT) transport to the remote server. The certificate
|
||||
+ chain file is expected to be in PEM format. This option implies :option:`-S`,
|
||||
+ and can only be used with :option:`-K`.
|
||||
+
|
||||
.. option:: -g
|
||||
|
||||
This option enables standard GSS-TSIG mode.
|
||||
|
||||
+.. option:: -H tlshostname
|
||||
+
|
||||
+ This option makes :program:`nsupdate` use the provided hostname during remote
|
||||
+ server TLS certificate verification. Otherwise, the DNS server name
|
||||
+ is used. This option implies :option:`-S`.
|
||||
+
|
||||
.. option:: -i
|
||||
|
||||
This option forces interactive mode, even when standard input is not a terminal.
|
||||
@@ -104,6 +126,13 @@ Options
|
||||
key used to authenticate Dynamic DNS update requests. In this case,
|
||||
the key specified is not an HMAC-MD5 key.
|
||||
|
||||
+.. option:: -K tlskeyfile
|
||||
+
|
||||
+ This option sets the key file for authenticated encryption for the
|
||||
+ DNS-over-TLS (DoT) transport with the remote server. The private key file is
|
||||
+ expected to be in PEM format. This option implies :option:`-S`, and can only
|
||||
+ be used with :option:`-E`.
|
||||
+
|
||||
.. option:: -l
|
||||
|
||||
This option sets local-host only mode, which sets the server address to localhost
|
||||
@@ -123,6 +152,14 @@ Options
|
||||
This option enables a non-standards-compliant variant of GSS-TSIG
|
||||
used by Windows 2000.
|
||||
|
||||
+.. option:: -O
|
||||
+
|
||||
+ This option enables Opportunistic TLS. When used, the remote peer's TLS
|
||||
+ certificate will not be verified. This option should be used for debugging
|
||||
+ purposes only, and it is not recommended to use it in production. This
|
||||
+ option can not be used in conjuction with :option:`-A`, and it implies
|
||||
+ :option:`-S`.
|
||||
+
|
||||
.. option:: -p port
|
||||
|
||||
This option sets the port to use for connections to a name server. The default is
|
||||
@@ -138,6 +175,15 @@ Options
|
||||
This option sets the number of UDP retries. The default is 3. If zero, only one update
|
||||
request is made.
|
||||
|
||||
+.. option:: -S
|
||||
+
|
||||
+ This option indicates whether to use DNS-over-TLS (DoT) when querying
|
||||
+ name servers specified by ``server servername port`` syntax in the input
|
||||
+ file, and the primary server discovered through a SOA request. When the
|
||||
+ :option:`-K` and :option:`-E` options are used, then the specified TLS
|
||||
+ client certificate and private key pair are used for authentication
|
||||
+ (Mutual TLS). This option implies :option:`-v`.
|
||||
+
|
||||
.. option:: -t timeout
|
||||
|
||||
This option sets the maximum time an update request can take before it is aborted. The
|
||||
--
|
||||
2.47.0
|
||||
|
||||
1630
bind-9.20-nsupdate-tls-test.patch
Normal file
1630
bind-9.20-nsupdate-tls-test.patch
Normal file
File diff suppressed because it is too large
Load diff
1386
bind-9.20-nsupdate-tls.patch
Normal file
1386
bind-9.20-nsupdate-tls.patch
Normal file
File diff suppressed because it is too large
Load diff
45
bind-9.20-tsig-keygen-suffix.patch
Normal file
45
bind-9.20-tsig-keygen-suffix.patch
Normal file
|
|
@ -0,0 +1,45 @@
|
|||
From 32f203d4e3c711cde5b1546a054be42b16436822 Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
||||
Date: Fri, 17 Jul 2026 19:42:39 +0200
|
||||
Subject: [PATCH] Support program suffixes of tsig-confgen and ddns-confgen
|
||||
|
||||
Suffixes different than .exe are used on Fedora. But those commands
|
||||
require exact names only. Allow switching between two variants only from
|
||||
prefix. That should work on all platforms. It should support also names
|
||||
like tsig-confgen-9.18 or tsig-confgen-9.20.
|
||||
|
||||
The same case applies to named-checkzone and named-compilezone.
|
||||
---
|
||||
bin/check/named-checkzone.c | 2 +-
|
||||
bin/confgen/tsig-keygen.c | 2 +-
|
||||
2 files changed, 2 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/bin/check/named-checkzone.c b/bin/check/named-checkzone.c
|
||||
index ae8feafc8c..5a1f712463 100644
|
||||
--- a/bin/check/named-checkzone.c
|
||||
+++ b/bin/check/named-checkzone.c
|
||||
@@ -137,7 +137,7 @@ main(int argc, char **argv) {
|
||||
}
|
||||
|
||||
#define PROGCMP(X) \
|
||||
- (strcasecmp(prog_name, X) == 0 || strcasecmp(prog_name, X ".exe") == 0)
|
||||
+ (strncasecmp(prog_name, X, strlen(X)) == 0)
|
||||
|
||||
if (PROGCMP("named-checkzone")) {
|
||||
progmode = progmode_check;
|
||||
diff --git a/bin/confgen/tsig-keygen.c b/bin/confgen/tsig-keygen.c
|
||||
index f0d2f9a245..9b13312b5b 100644
|
||||
--- a/bin/confgen/tsig-keygen.c
|
||||
+++ b/bin/confgen/tsig-keygen.c
|
||||
@@ -113,7 +113,7 @@ main(int argc, char **argv) {
|
||||
}
|
||||
|
||||
#define PROGCMP(X) \
|
||||
- (strcasecmp(progname, X) == 0 || strcasecmp(progname, X ".exe") == 0)
|
||||
+ (strncasecmp(progname, X, strlen(X)) == 0)
|
||||
|
||||
if (PROGCMP("tsig-keygen")) {
|
||||
progmode = progmode_keygen;
|
||||
--
|
||||
2.54.0
|
||||
|
||||
|
|
@ -1,26 +0,0 @@
|
|||
--- bind-9.3.1/bin/named_sdb/Makefile.in.dbus_archdep_libdir 2005-08-16 21:23:28.000000000 -0400
|
||||
+++ bind-9.3.1/bin/named_sdb/Makefile.in 2005-08-16 23:00:49.000000000 -0400
|
||||
@@ -35,8 +35,9 @@
|
||||
${LWRES_INCLUDES} ${DNS_INCLUDES} ${BIND9_INCLUDES} \
|
||||
${ISCCFG_INCLUDES} ${ISCCC_INCLUDES} ${ISC_INCLUDES} \
|
||||
${DBDRIVER_INCLUDES}
|
||||
+DBUS_ARCHDEP_LIBDIR ?= lib
|
||||
DBUS_INCLUDES = \
|
||||
- -I/usr/lib/dbus-1.0/include -I/usr/include/dbus-1.0
|
||||
+ -I/usr/${DBUS_ARCHDEP_LIBDIR}/dbus-1.0/include -I/usr/include/dbus-1.0
|
||||
CDEFINES =
|
||||
CWARNINGS =
|
||||
|
||||
--- bind-9.3.1/bin/named/Makefile.in.dbus_archdep_libdir 2005-08-16 21:23:28.000000000 -0400
|
||||
+++ bind-9.3.1/bin/named/Makefile.in 2005-08-16 23:00:58.000000000 -0400
|
||||
@@ -35,8 +35,9 @@
|
||||
${LWRES_INCLUDES} ${DNS_INCLUDES} ${BIND9_INCLUDES} \
|
||||
${ISCCFG_INCLUDES} ${ISCCC_INCLUDES} ${ISC_INCLUDES} \
|
||||
${DBDRIVER_INCLUDES}
|
||||
+DBUS_ARCHDEP_LIBDIR ?= lib
|
||||
DBUS_INCLUDES = \
|
||||
- -I/usr/lib/dbus-1.0/include -I/usr/include/dbus-1.0
|
||||
+ -I/usr/${DBUS_ARCHDEP_LIBDIR}/dbus-1.0/include -I/usr/include/dbus-1.0
|
||||
CDEFINES =
|
||||
CWARNINGS =
|
||||
|
||||
|
|
@ -1,36 +0,0 @@
|
|||
--- bind-9.3.1/bin/dig/dighost.c.next_server_on_referral 2005-08-16 16:27:33.000000000 -0400
|
||||
+++ bind-9.3.1/bin/dig/dighost.c 2005-08-16 16:27:49.000000000 -0400
|
||||
@@ -2765,7 +2765,17 @@
|
||||
UNLOCK_LOOKUP;
|
||||
return;
|
||||
}
|
||||
- if (msg->rcode == dns_rcode_servfail && !l->servfail_stops) {
|
||||
+ if ( (!l->servfail_stops)
|
||||
+ &&( (msg->rcode == dns_rcode_servfail)
|
||||
+ ||( (msg->rcode == dns_rcode_noerror)
|
||||
+ &&(msg->counts[DNS_SECTION_ANSWER] == 0)
|
||||
+ &&(msg->counts[DNS_SECTION_ADDITIONAL] == 0)
|
||||
+ &&((msg->flags & DNS_MESSAGEFLAG_RD) == DNS_MESSAGEFLAG_RD)
|
||||
+ &&((msg->flags & (DNS_MESSAGEFLAG_RA | DNS_MESSAGEFLAG_AA)) == 0)
|
||||
+ )
|
||||
+ )
|
||||
+ )
|
||||
+ {
|
||||
dig_query_t *next = ISC_LIST_NEXT(query, link);
|
||||
if (l->current_query == query)
|
||||
l->current_query = NULL;
|
||||
@@ -2783,9 +2793,11 @@
|
||||
*/
|
||||
if ((ISC_LIST_HEAD(l->q) != query) ||
|
||||
(ISC_LIST_NEXT(query, link) != NULL)) {
|
||||
- printf(";; Got SERVFAIL reply from %s, "
|
||||
- "trying next server\n",
|
||||
- query->servname);
|
||||
+ if( l->comments == ISC_TRUE )
|
||||
+ printf(";; Got %s reply from %s, "
|
||||
+ "trying next server\n",
|
||||
+ msg->rcode == dns_rcode_servfail ? "SERVFAIL" : "referral",
|
||||
+ query->servname);
|
||||
clear_query(query);
|
||||
check_next_lookup(l);
|
||||
dns_message_destroy(&msg);
|
||||
|
|
@ -1,78 +0,0 @@
|
|||
--- bind-9.3.1/bin/named/named.8.redhat_doc 2004-06-03 01:35:47.000000000 -0400
|
||||
+++ bind-9.3.1/bin/named/named.8 2005-05-17 21:22:25.000000000 -0400
|
||||
@@ -164,6 +164,75 @@
|
||||
.TP
|
||||
\fB\fI/var/run/named.pid\fB\fR
|
||||
The default process-id file.
|
||||
+.PP
|
||||
+.SH "NOTES"
|
||||
+.PP
|
||||
+.TP
|
||||
+\fBRed Hat SELinux BIND Security Profile:\fR
|
||||
+.PP
|
||||
+By default, Red Hat ships BIND with the most secure SELinux policy
|
||||
+that will not prevent normal BIND operation and will prevent exploitation
|
||||
+of all known BIND security vulnerabilities . See the selinux(8) man page
|
||||
+for information about SElinux.
|
||||
+.PP
|
||||
+It is not necessary to run named in a chroot environment if the Red Hat
|
||||
+SELinux policy for named is enabled. When enabled, this policy is far
|
||||
+more secure than a chroot environment. Users are recommended to enable
|
||||
+SELinux and remove the bind-chroot package.
|
||||
+.PP
|
||||
+With this extra security comes some restrictions:
|
||||
+.PP
|
||||
+By default, the SELinux policy does not allow named to write any master
|
||||
+zone database files. Only the root user may create files in the $ROOTDIR/var/named
|
||||
+zone database file directory (the options { "directory" } option), where
|
||||
+$ROOTDIR is set in /etc/sysconfig/named.
|
||||
+.PP
|
||||
+The "named" group must be granted read privelege to
|
||||
+these files in order for named to be enabled to read them.
|
||||
+.PP
|
||||
+Any file created in the zone database file directory is automatically assigned
|
||||
+the SELinux file context named_zone_t .
|
||||
+.PP
|
||||
+By default, SELinux prevents any role from modifying named_zone_t files; this
|
||||
+means that files in the zone database directory cannot be modified by dynamic
|
||||
+DNS (DDNS) updates or zone transfers.
|
||||
+.PP
|
||||
+The Red Hat BIND distribution and SELinux policy creates two directories where
|
||||
+named is allowed to create and modify files: $ROOTDIR/var/named/slaves and
|
||||
+$ROOTDIR/var/named/data. By placing files you want named to modify, such as
|
||||
+slave or DDNS updateable zone files and database / statistics dump files in
|
||||
+these directories, named will work normally and no further operator action is
|
||||
+required. Files in these directories are automatically assigned the 'named_cache_t'
|
||||
+file context, which SELinux allows named to write.
|
||||
+.PP
|
||||
+You can enable the named_t domain to write and create named_zone_t files by use
|
||||
+of the SELinux tunable boolean variable "named_write_master_zones", using the
|
||||
+setsebool(8) command or the system-config-security GUI . If you do this, you
|
||||
+must also set the ENABLE_ZONE_WRITE variable in /etc/sysconfig/named to
|
||||
+1 / yes to set the ownership of files in the $ROOTDIR/var/named directory
|
||||
+to named:named in order for named to be allowed to write them.
|
||||
+.PP
|
||||
+\fBRed Hat BIND named_sdb SDB support:\fR
|
||||
+.PP
|
||||
+Red Hat ships the bind-sdb RPM that provides the /usr/sbin/named_sdb program,
|
||||
+which is named compiled with the Simplified Database Backend modules that ISC
|
||||
+provides in the "contrib/sdb" directory.
|
||||
+.PP
|
||||
+The SDB modules for LDAP, PostGreSQL and DirDB are compiled into named_sdb.
|
||||
+.PP
|
||||
+To run named_sdb, set the ENABLE_SDB variable in /etc/sysconfig/named to 1 or "yes",
|
||||
+and then the "service named start" named initscript will run named_sdb instead
|
||||
+of named .
|
||||
+.PP
|
||||
+See the documentation for the various SDB modules in /usr/share/doc/bind-sdb-*/ .
|
||||
+.br
|
||||
+.PP
|
||||
+\fBRed Hat system-config-bind:\fR
|
||||
+.PP
|
||||
+Red Hat provides the system-config-bind GUI to configure named.conf and zone
|
||||
+database files. Run the "system-config-bind" command and access the manual
|
||||
+by selecting the Help menu.
|
||||
+.PP
|
||||
.SH "SEE ALSO"
|
||||
.PP
|
||||
\fIRFC 1033\fR,
|
||||
|
|
@ -1,85 +0,0 @@
|
|||
--- bind-9.3.1/bin/named_sdb/Makefile.in.sdb_dbus 2005-08-16 21:18:06.000000000 -0400
|
||||
+++ bind-9.3.1/bin/named_sdb/Makefile.in 2005-08-16 21:18:06.000000000 -0400
|
||||
@@ -35,7 +35,8 @@
|
||||
${LWRES_INCLUDES} ${DNS_INCLUDES} ${BIND9_INCLUDES} \
|
||||
${ISCCFG_INCLUDES} ${ISCCC_INCLUDES} ${ISC_INCLUDES} \
|
||||
${DBDRIVER_INCLUDES}
|
||||
-
|
||||
+DBUS_INCLUDES = \
|
||||
+ -I/usr/lib/dbus-1.0/include -I/usr/include/dbus-1.0
|
||||
CDEFINES =
|
||||
CWARNINGS =
|
||||
|
||||
@@ -52,6 +53,7 @@
|
||||
ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
||||
LWRESDEPLIBS = ../../lib/lwres/liblwres.@A@
|
||||
BIND9DEPLIBS = ../../lib/bind9/libbind9.@A@
|
||||
+DBUSLIBS= -ldbus-1
|
||||
|
||||
DEPLIBS = ${LWRESDEPLIBS} ${DNSDEPLIBS} ${BIND9DEPLIBS} \
|
||||
${ISCCFGDEPLIBS} ${ISCCCDEPLIBS} ${ISCDEPLIBS}
|
||||
@@ -70,7 +72,8 @@
|
||||
tkeyconf.o tsigconf.o update.o xfrout.o \
|
||||
zoneconf.o \
|
||||
lwaddr.o lwresd.o lwdclient.o lwderror.o lwdgabn.o \
|
||||
- lwdgnba.o lwdgrbn.o lwdnoop.o lwsearch.o \
|
||||
+ lwdgnba.o lwdgrbn.o lwdnoop.o lwsearch.o \
|
||||
+ dbus_service.o dbus_mgr.o \
|
||||
$(DBDRIVER_OBJS)
|
||||
|
||||
UOBJS = unix/os.o
|
||||
@@ -83,6 +86,7 @@
|
||||
zoneconf.c \
|
||||
lwaddr.c lwresd.c lwdclient.c lwderror.c lwdgabn.c \
|
||||
lwdgnba.c lwdgrbn.c lwdnoop.c lwsearch.c \
|
||||
+ dbus_service.c dbus_mgr.c \
|
||||
$(DBDRIVER_SRCS)
|
||||
|
||||
MANPAGES = named.8 lwresd.8 named.conf.5
|
||||
@@ -114,9 +118,14 @@
|
||||
-DNS_LOCALSTATEDIR=\"${localstatedir}\" \
|
||||
-c ${srcdir}/config.c
|
||||
|
||||
+dbus_service.o: dbus_service.c
|
||||
+ ${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} \
|
||||
+ ${DBUS_INCLUDES} \
|
||||
+ -c ${srcdir}/dbus_service.c
|
||||
+
|
||||
named_sdb@EXEEXT@: ${OBJS} ${UOBJS} ${DEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||
- ${OBJS} ${UOBJS} ${LIBS}
|
||||
+ ${OBJS} ${UOBJS} ${LIBS} ${DBUSLIBS}
|
||||
|
||||
doc man:: ${MANOBJS}
|
||||
|
||||
--- bind-9.3.1/bin/named_sdb/main.c.sdb_dbus 2005-08-16 21:18:06.000000000 -0400
|
||||
+++ bind-9.3.1/bin/named_sdb/main.c 2005-08-16 21:21:40.000000000 -0400
|
||||
@@ -243,7 +243,8 @@
|
||||
"usage: named [-4|-6] [-c conffile] [-d debuglevel] "
|
||||
"[-f|-g] [-n number_of_cpus]\n"
|
||||
" [-p port] [-s] [-t chrootdir] [-u username]\n"
|
||||
- " [-m {usage|trace|record}]\n");
|
||||
+ " [-m {usage|trace|record}]\n"
|
||||
+ " [-D ]\n");
|
||||
}
|
||||
|
||||
static void
|
||||
@@ -349,7 +350,7 @@
|
||||
|
||||
isc_commandline_errprint = ISC_FALSE;
|
||||
while ((ch = isc_commandline_parse(argc, argv,
|
||||
- "46c:C:d:fgi:lm:n:N:p:P:st:u:vx:")) != -1) {
|
||||
+ "46c:C:d:fgi:lm:n:N:p:P:st:u:vx:D")) != -1) {
|
||||
switch (ch) {
|
||||
case '4':
|
||||
if (disable4)
|
||||
@@ -438,6 +439,9 @@
|
||||
case 'v':
|
||||
printf("BIND %s\n", ns_g_version);
|
||||
exit(0);
|
||||
+ case 'D':
|
||||
+ ns_g_dbus = 1;
|
||||
+ break;
|
||||
case '?':
|
||||
usage();
|
||||
ns_main_earlyfatal("unknown option '-%c'",
|
||||
|
|
@ -1,27 +0,0 @@
|
|||
--- bind-9.3.1beta2/configure.in.openssl_suffix 2004-12-08 23:07:10.000000000 -0500
|
||||
+++ bind-9.3.1beta2/configure.in 2005-01-27 17:03:49.394814000 -0500
|
||||
@@ -374,6 +374,10 @@
|
||||
fi
|
||||
done
|
||||
fi
|
||||
+OSSUFFIX=
|
||||
+if test "$host_cpu" = "x86_64"; then
|
||||
+ OSSUFFIX=64
|
||||
+fi;
|
||||
case "$use_openssl" in
|
||||
no)
|
||||
AC_MSG_RESULT(no)
|
||||
@@ -416,11 +420,11 @@
|
||||
DNS_OPENSSL_LIBS="-L$use_openssl/lib -R$use_openssl/lib -lcrypto"
|
||||
;;
|
||||
*)
|
||||
- DNS_OPENSSL_LIBS="-L$use_openssl/lib -lcrypto"
|
||||
+ DNS_OPENSSL_LIBS="-L$use_openssl/lib${OSUFFIX} -lcrypto"
|
||||
;;
|
||||
esac
|
||||
fi
|
||||
- AC_MSG_RESULT(using openssl from $use_openssl/lib and $use_openssl/include)
|
||||
+ AC_MSG_RESULT(using openssl from $use_openssl/lib${OSSUFFIX} and $use_openssl/include)
|
||||
|
||||
saved_cflags="$CFLAGS"
|
||||
saved_libs="$LIBS"
|
||||
|
|
@ -1,11 +0,0 @@
|
|||
--- bind-9.3.1rc1/lib/bind/make/rules.in.fix_libbind_includedir 2004-10-19 20:14:47.000000000 -0400
|
||||
+++ bind-9.3.1rc1/lib/bind/make/rules.in 2005-02-18 12:31:24.000000000 -0500
|
||||
@@ -29,7 +29,7 @@
|
||||
exec_prefix = @exec_prefix@
|
||||
bindir = @bindir@
|
||||
sbindir = @sbindir@
|
||||
-includedir = @includedir@
|
||||
+includedir = @includedir@/bind
|
||||
libdir = @libdir@
|
||||
sysconfdir = @sysconfdir@
|
||||
localstatedir = @localstatedir@
|
||||
|
|
@ -1,170 +0,0 @@
|
|||
--- bind-9.3.1rc1/configure.in.sdb 2005-02-16 22:25:08.000000000 -0500
|
||||
+++ bind-9.3.1rc1/configure.in 2005-02-16 22:25:08.000000000 -0500
|
||||
@@ -2194,6 +2194,8 @@
|
||||
bin/check/Makefile
|
||||
bin/named/Makefile
|
||||
bin/named/unix/Makefile
|
||||
+ bin/named_sdb/Makefile
|
||||
+ bin/named_sdb/unix/Makefile
|
||||
bin/rndc/Makefile
|
||||
bin/rndc/unix/Makefile
|
||||
bin/dig/Makefile
|
||||
@@ -2215,6 +2217,7 @@
|
||||
bin/tests/system/tkey/Makefile
|
||||
bin/tests/headerdep_test.sh
|
||||
bin/dnssec/Makefile
|
||||
+ bin/sdb_tools/Makefile
|
||||
doc/Makefile
|
||||
doc/arm/Makefile
|
||||
doc/arm/nominum-docbook-html.dsl
|
||||
--- bind-9.3.1rc1/bin/named_sdb/main.c.sdb 2004-10-24 20:42:54.000000000 -0400
|
||||
+++ bind-9.3.1rc1/bin/named_sdb/main.c 2005-02-16 22:25:08.000000000 -0500
|
||||
@@ -71,6 +71,9 @@
|
||||
* Include header files for database drivers here.
|
||||
*/
|
||||
/* #include "xxdb.h" */
|
||||
+#include "ldapdb.h"
|
||||
+#include "pgsqldb.h"
|
||||
+#include "dirdb.h"
|
||||
|
||||
static isc_boolean_t want_stats = ISC_FALSE;
|
||||
static char program_name[ISC_DIR_NAMEMAX] = "named";
|
||||
@@ -656,7 +659,57 @@
|
||||
* Add calls to register sdb drivers here.
|
||||
*/
|
||||
/* xxdb_init(); */
|
||||
-
|
||||
+ result = ldapdb_init();
|
||||
+ if (result != ISC_R_SUCCESS)
|
||||
+ {
|
||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||
+ ISC_LOG_ERROR,
|
||||
+ "SDB ldap module initialisation failed: %s.",
|
||||
+ isc_result_totext(result)
|
||||
+ );
|
||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||
+ ISC_LOG_ERROR,
|
||||
+ "SDB ldap zone database will be unavailable."
|
||||
+ );
|
||||
+ }else
|
||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||
+ ISC_LOG_NOTICE, "SDB ldap zone database module loaded."
|
||||
+ );
|
||||
+
|
||||
+ result = pgsqldb_init();
|
||||
+ if (result != ISC_R_SUCCESS)
|
||||
+ {
|
||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||
+ ISC_LOG_ERROR,
|
||||
+ "SDB pgsql module initialisation failed: %s.",
|
||||
+ isc_result_totext(result)
|
||||
+ );
|
||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||
+ ISC_LOG_ERROR,
|
||||
+ "SDB pgsql zone database will be unavailable."
|
||||
+ );
|
||||
+ }else
|
||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||
+ ISC_LOG_NOTICE, "SDB postgreSQL DB zone database module loaded."
|
||||
+ );
|
||||
+
|
||||
+ result = dirdb_init();
|
||||
+ if (result != ISC_R_SUCCESS)
|
||||
+ {
|
||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||
+ ISC_LOG_ERROR,
|
||||
+ "SDB directory DB module initialisation failed: %s.",
|
||||
+ isc_result_totext(result)
|
||||
+ );
|
||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||
+ ISC_LOG_ERROR,
|
||||
+ "SDB directory DB zone database will be unavailable."
|
||||
+ );
|
||||
+ }else
|
||||
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||
+ ISC_LOG_NOTICE, "SDB directory DB zone database module loaded."
|
||||
+ );
|
||||
+
|
||||
ns_server_create(ns_g_mctx, &ns_g_server);
|
||||
}
|
||||
|
||||
@@ -673,6 +726,10 @@
|
||||
*/
|
||||
/* xxdb_clear(); */
|
||||
|
||||
+ ldapdb_clear();
|
||||
+ pgsqldb_clear();
|
||||
+ dirdb_clear();
|
||||
+
|
||||
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||
ISC_LOG_NOTICE, "exiting");
|
||||
ns_log_shutdown();
|
||||
--- bind-9.3.1rc1/bin/named_sdb/Makefile.in.sdb 2005-02-16 22:25:08.000000000 -0500
|
||||
+++ bind-9.3.1rc1/bin/named_sdb/Makefile.in 2005-02-16 22:25:08.000000000 -0500
|
||||
@@ -26,10 +26,10 @@
|
||||
#
|
||||
# Add database drivers here.
|
||||
#
|
||||
-DBDRIVER_OBJS =
|
||||
-DBDRIVER_SRCS =
|
||||
+DBDRIVER_OBJS = ldapdb.o pgsqldb.o dirdb.o
|
||||
+DBDRIVER_SRCS = ldapdb.c pgsqldb.c dirdb.c
|
||||
DBDRIVER_INCLUDES =
|
||||
-DBDRIVER_LIBS =
|
||||
+DBDRIVER_LIBS = -lldap -llber -lpq
|
||||
|
||||
CINCLUDES = -I${srcdir}/include -I${srcdir}/unix/include \
|
||||
${LWRES_INCLUDES} ${DNS_INCLUDES} ${BIND9_INCLUDES} \
|
||||
@@ -61,7 +61,7 @@
|
||||
|
||||
SUBDIRS = unix
|
||||
|
||||
-TARGETS = named@EXEEXT@ lwresd@EXEEXT@
|
||||
+TARGETS = named_sdb@EXEEXT@
|
||||
|
||||
OBJS = aclconf.o builtin.o client.o config.o control.o \
|
||||
controlconf.o interfacemgr.o \
|
||||
@@ -114,14 +114,10 @@
|
||||
-DNS_LOCALSTATEDIR=\"${localstatedir}\" \
|
||||
-c ${srcdir}/config.c
|
||||
|
||||
-named@EXEEXT@: ${OBJS} ${UOBJS} ${DEPLIBS}
|
||||
+named_sdb@EXEEXT@: ${OBJS} ${UOBJS} ${DEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||
${OBJS} ${UOBJS} ${LIBS}
|
||||
|
||||
-lwresd@EXEEXT@: named@EXEEXT@
|
||||
- rm -f lwresd@EXEEXT@
|
||||
- @LN@ named@EXEEXT@ lwresd@EXEEXT@
|
||||
-
|
||||
doc man:: ${MANOBJS}
|
||||
|
||||
docclean manclean maintainer-clean::
|
||||
@@ -132,13 +128,8 @@
|
||||
|
||||
installdirs:
|
||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
||||
- $(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man5
|
||||
- $(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
||||
|
||||
-install:: named@EXEEXT@ lwresd@EXEEXT@ installdirs
|
||||
- ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named@EXEEXT@ ${DESTDIR}${sbindir}
|
||||
- (cd ${DESTDIR}${sbindir}; rm -f lwresd@EXEEXT@; @LN@ named@EXEEXT@ lwresd@EXEEXT@)
|
||||
- ${INSTALL_DATA} ${srcdir}/named.8 ${DESTDIR}${mandir}/man8
|
||||
- ${INSTALL_DATA} ${srcdir}/lwresd.8 ${DESTDIR}${mandir}/man8
|
||||
- ${INSTALL_DATA} ${srcdir}/named.conf.5 ${DESTDIR}${mandir}/man5
|
||||
+install:: named_sdb@EXEEXT@ installdirs
|
||||
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named_sdb@EXEEXT@ ${DESTDIR}${sbindir}
|
||||
+
|
||||
|
||||
--- bind-9.3.1rc1/bin/Makefile.in.sdb 2004-03-06 05:21:10.000000000 -0500
|
||||
+++ bind-9.3.1rc1/bin/Makefile.in 2005-02-16 22:25:08.000000000 -0500
|
||||
@@ -19,7 +19,7 @@
|
||||
VPATH = @srcdir@
|
||||
top_srcdir = @top_srcdir@
|
||||
|
||||
-SUBDIRS = named rndc dig dnssec tests nsupdate check
|
||||
+SUBDIRS = named named_sdb rndc dig dnssec tests nsupdate check sdb_tools
|
||||
TARGETS =
|
||||
|
||||
@BIND9_MAKE_RULES@
|
||||
|
|
@ -1,67 +0,0 @@
|
|||
srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
top_srcdir = @top_srcdir@
|
||||
|
||||
@BIND9_VERSION@
|
||||
|
||||
@BIND9_MAKE_INCLUDES@
|
||||
|
||||
CINCLUDES = -I${srcdir}/include -I${srcdir}/unix/include \
|
||||
${LWRES_INCLUDES} ${DNS_INCLUDES} ${BIND9_INCLUDES} \
|
||||
${ISCCFG_INCLUDES} ${ISCCC_INCLUDES} ${ISC_INCLUDES}
|
||||
|
||||
DNSLIBS = ../../lib/dns/libdns.@A@ @DNS_CRYPTO_LIBS@
|
||||
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||
ISCCCLIBS = ../../lib/isccc/libisccc.@A@
|
||||
ISCLIBS = ../../lib/isc/libisc.@A@
|
||||
LWRESLIBS = ../../lib/lwres/liblwres.@A@
|
||||
BIND9LIBS = ../../lib/bind9/libbind9.@A@
|
||||
|
||||
DNSDEPLIBS = ../../lib/dns/libdns.@A@
|
||||
ISCCFGDEPLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||
ISCCCDEPLIBS = ../../lib/isccc/libisccc.@A@
|
||||
ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
||||
LWRESDEPLIBS = ../../lib/lwres/liblwres.@A@
|
||||
BIND9DEPLIBS = ../../lib/bind9/libbind9.@A@
|
||||
|
||||
DEPLIBS = ${LWRESDEPLIBS} ${DNSDEPLIBS} ${BIND9DEPLIBS} \
|
||||
${ISCCFGDEPLIBS} ${ISCCCDEPLIBS} ${ISCDEPLIBS}
|
||||
|
||||
LIBS = ${LWRESLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
||||
${ISCCFGLIBS} ${ISCCCLIBS} ${ISCLIBS} ${DBDRIVER_LIBS} @LIBS@
|
||||
|
||||
TARGETS = zone2ldap@EXEEXT@ zonetodb@EXEEXT@
|
||||
|
||||
OBJS = zone2ldap.o zonetodb.o
|
||||
|
||||
SRCS = zone2ldap.c zonetodb.c
|
||||
|
||||
MANPAGES = zone2ldap.1
|
||||
|
||||
EXT_CFLAGS = -fPIE
|
||||
|
||||
@BIND9_MAKE_RULES@
|
||||
|
||||
LDFLAGS += -pie -Wl,-z,relro,-z,now,-z,nodlopen,-z,noexecstack
|
||||
|
||||
LIBTOOL_MODE_COMPILE=
|
||||
|
||||
.SUFFIXES: .c .o
|
||||
|
||||
zone2ldap: zone2ldap.o ${DEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ zone2ldap.o -lldap -llber ${LIBS}
|
||||
|
||||
zonetodb: zonetodb.o ${DEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ zonetodb.o -lpq ${LIBS}
|
||||
|
||||
clean distclean manclean maintainer-clean::
|
||||
rm -f ${TARGETS} ${OBJS}
|
||||
|
||||
installdirs:
|
||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man1
|
||||
|
||||
install:: ${TARGETS} installdirs
|
||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zone2ldap ${DESTDIR}${sbindir}
|
||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zonetodb ${DESTDIR}${sbindir}
|
||||
${INSTALL_DATA} ${srcdir}/zone2ldap.1 ${DESTDIR}${mandir}/man1/zone2ldap.1
|
||||
|
|
@ -1,78 +0,0 @@
|
|||
--- bind-9.3.2/bin/named/named.8.redhat_doc 2005-10-12 22:33:46.000000000 -0400
|
||||
+++ bind-9.3.2/bin/named/named.8 2006-02-07 15:56:31.000000000 -0500
|
||||
@@ -169,6 +169,75 @@
|
||||
.TP
|
||||
\fI/var/run/named.pid\fR
|
||||
The default process\-id file.
|
||||
+.PP
|
||||
+.SH "NOTES"
|
||||
+.PP
|
||||
+.TP
|
||||
+\fBRed Hat SELinux BIND Security Profile:\fR
|
||||
+.PP
|
||||
+By default, Red Hat ships BIND with the most secure SELinux policy
|
||||
+that will not prevent normal BIND operation and will prevent exploitation
|
||||
+of all known BIND security vulnerabilities . See the selinux(8) man page
|
||||
+for information about SElinux.
|
||||
+.PP
|
||||
+It is not necessary to run named in a chroot environment if the Red Hat
|
||||
+SELinux policy for named is enabled. When enabled, this policy is far
|
||||
+more secure than a chroot environment. Users are recommended to enable
|
||||
+SELinux and remove the bind-chroot package.
|
||||
+.PP
|
||||
+With this extra security comes some restrictions:
|
||||
+.PP
|
||||
+By default, the SELinux policy does not allow named to write any master
|
||||
+zone database files. Only the root user may create files in the $ROOTDIR/var/named
|
||||
+zone database file directory (the options { "directory" } option), where
|
||||
+$ROOTDIR is set in /etc/sysconfig/named.
|
||||
+.PP
|
||||
+The "named" group must be granted read privelege to
|
||||
+these files in order for named to be enabled to read them.
|
||||
+.PP
|
||||
+Any file created in the zone database file directory is automatically assigned
|
||||
+the SELinux file context named_zone_t .
|
||||
+.PP
|
||||
+By default, SELinux prevents any role from modifying named_zone_t files; this
|
||||
+means that files in the zone database directory cannot be modified by dynamic
|
||||
+DNS (DDNS) updates or zone transfers.
|
||||
+.PP
|
||||
+The Red Hat BIND distribution and SELinux policy creates two directories where
|
||||
+named is allowed to create and modify files: $ROOTDIR/var/named/slaves and
|
||||
+$ROOTDIR/var/named/data. By placing files you want named to modify, such as
|
||||
+slave or DDNS updateable zone files and database / statistics dump files in
|
||||
+these directories, named will work normally and no further operator action is
|
||||
+required. Files in these directories are automatically assigned the 'named_cache_t'
|
||||
+file context, which SELinux allows named to write.
|
||||
+.PP
|
||||
+You can enable the named_t domain to write and create named_zone_t files by use
|
||||
+of the SELinux tunable boolean variable "named_write_master_zones", using the
|
||||
+setsebool(8) command or the system-config-security GUI . If you do this, you
|
||||
+must also set the ENABLE_ZONE_WRITE variable in /etc/sysconfig/named to
|
||||
+1 / yes to set the ownership of files in the $ROOTDIR/var/named directory
|
||||
+to named:named in order for named to be allowed to write them.
|
||||
+.PP
|
||||
+\fBRed Hat BIND named_sdb SDB support:\fR
|
||||
+.PP
|
||||
+Red Hat ships the bind-sdb RPM that provides the /usr/sbin/named_sdb program,
|
||||
+which is named compiled with the Simplified Database Backend modules that ISC
|
||||
+provides in the "contrib/sdb" directory.
|
||||
+.PP
|
||||
+The SDB modules for LDAP, PostGreSQL and DirDB are compiled into named_sdb.
|
||||
+.PP
|
||||
+To run named_sdb, set the ENABLE_SDB variable in /etc/sysconfig/named to 1 or "yes",
|
||||
+and then the "service named start" named initscript will run named_sdb instead
|
||||
+of named .
|
||||
+.PP
|
||||
+See the documentation for the various SDB modules in /usr/share/doc/bind-sdb-*/ .
|
||||
+.br
|
||||
+.PP
|
||||
+\fBRed Hat system-config-bind:\fR
|
||||
+.PP
|
||||
+Red Hat provides the system-config-bind GUI to configure named.conf and zone
|
||||
+database files. Run the "system-config-bind" command and access the manual
|
||||
+by selecting the Help menu.
|
||||
+.PP
|
||||
.SH "SEE ALSO"
|
||||
.PP
|
||||
RFC 1033,
|
||||
|
|
@ -1,313 +0,0 @@
|
|||
--- bind-9.3.2b1/make/rules.in.PIE 2005-05-12 17:36:17.000000000 -0400
|
||||
+++ bind-9.3.2b1/make/rules.in 2005-10-06 20:04:36.000000000 -0400
|
||||
@@ -118,6 +118,9 @@
|
||||
.c.@O@:
|
||||
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} -c $<
|
||||
|
||||
+.c.o:
|
||||
+ ${CC} ${ALL_CFLAGS} -c $<
|
||||
+
|
||||
SHELL = @SHELL@
|
||||
LIBTOOL = @LIBTOOL@
|
||||
LIBTOOL_MODE_COMPILE = ${LIBTOOL} @LIBTOOL_MODE_COMPILE@
|
||||
--- bind-9.3.2b1/bin/dnssec/Makefile.in.PIE 2005-05-01 20:25:54.000000000 -0400
|
||||
+++ bind-9.3.2b1/bin/dnssec/Makefile.in 2005-10-06 20:04:36.000000000 -0400
|
||||
@@ -41,7 +41,7 @@
|
||||
# Alphabetically
|
||||
TARGETS = dnssec-keygen@EXEEXT@ dnssec-signzone@EXEEXT@
|
||||
|
||||
-OBJS = dnssectool.@O@
|
||||
+OBJS = dnssectool.o
|
||||
|
||||
SRCS = dnssec-keygen.c dnssec-signzone.c dnssectool.c
|
||||
|
||||
@@ -51,19 +51,25 @@
|
||||
|
||||
MANOBJS = ${MANPAGES} ${HTMLPAGES}
|
||||
|
||||
+EXT_CFLAGS = -fPIE
|
||||
+
|
||||
@BIND9_MAKE_RULES@
|
||||
|
||||
-dnssec-keygen@EXEEXT@: dnssec-keygen.@O@ ${OBJS} ${DEPLIBS}
|
||||
+LDFLAGS += -pie -Wl,-z,relro,-z,now,-z,nodlopen,-z,noexecstack
|
||||
+
|
||||
+.SUFFIXES: .c .o
|
||||
+
|
||||
+dnssec-keygen@EXEEXT@: dnssec-keygen.o ${OBJS} ${DEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||
- dnssec-keygen.@O@ ${OBJS} ${LIBS}
|
||||
+ dnssec-keygen.o ${OBJS} ${LIBS}
|
||||
|
||||
-dnssec-signzone.@O@: dnssec-signzone.c
|
||||
- ${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} -DVERSION=\"${VERSION}\" \
|
||||
+dnssec-signzone.o: dnssec-signzone.c
|
||||
+ ${CC} ${ALL_CFLAGS} -DVERSION=\"${VERSION}\" \
|
||||
-c ${srcdir}/dnssec-signzone.c
|
||||
|
||||
-dnssec-signzone@EXEEXT@: dnssec-signzone.@O@ ${OBJS} ${DEPLIBS}
|
||||
+dnssec-signzone@EXEEXT@: dnssec-signzone.o ${OBJS} ${DEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||
- dnssec-signzone.@O@ ${OBJS} ${LIBS}
|
||||
+ dnssec-signzone.o ${OBJS} ${LIBS}
|
||||
|
||||
doc man:: ${MANOBJS}
|
||||
|
||||
--- bind-9.3.2b1/bin/named/Makefile.in.PIE 2004-09-06 17:47:25.000000000 -0400
|
||||
+++ bind-9.3.2b1/bin/named/Makefile.in 2005-10-06 20:04:36.000000000 -0400
|
||||
@@ -63,17 +63,17 @@
|
||||
|
||||
TARGETS = named@EXEEXT@ lwresd@EXEEXT@
|
||||
|
||||
-OBJS = aclconf.@O@ builtin.@O@ client.@O@ config.@O@ control.@O@ \
|
||||
- controlconf.@O@ interfacemgr.@O@ \
|
||||
- listenlist.@O@ log.@O@ logconf.@O@ main.@O@ notify.@O@ \
|
||||
- query.@O@ server.@O@ sortlist.@O@ \
|
||||
- tkeyconf.@O@ tsigconf.@O@ update.@O@ xfrout.@O@ \
|
||||
- zoneconf.@O@ \
|
||||
- lwaddr.@O@ lwresd.@O@ lwdclient.@O@ lwderror.@O@ lwdgabn.@O@ \
|
||||
- lwdgnba.@O@ lwdgrbn.@O@ lwdnoop.@O@ lwsearch.@O@ \
|
||||
+OBJS = aclconf.o builtin.o client.o config.o control.o \
|
||||
+ controlconf.o interfacemgr.o \
|
||||
+ listenlist.o log.o logconf.o main.o notify.o \
|
||||
+ query.o server.o sortlist.o \
|
||||
+ tkeyconf.o tsigconf.o update.o xfrout.o \
|
||||
+ zoneconf.o \
|
||||
+ lwaddr.o lwresd.o lwdclient.o lwderror.o lwdgabn.o \
|
||||
+ lwdgnba.o lwdgrbn.o lwdnoop.o lwsearch.o \
|
||||
$(DBDRIVER_OBJS)
|
||||
|
||||
-UOBJS = unix/os.@O@
|
||||
+UOBJS = unix/os.o
|
||||
|
||||
SRCS = aclconf.c builtin.c client.c config.c control.c \
|
||||
controlconf.c interfacemgr.c \
|
||||
@@ -91,16 +91,22 @@
|
||||
|
||||
MANOBJS = ${MANPAGES} ${HTMLPAGES}
|
||||
|
||||
+EXT_CFLAGS = -fPIE
|
||||
+
|
||||
@BIND9_MAKE_RULES@
|
||||
|
||||
-main.@O@: main.c
|
||||
- ${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} \
|
||||
+LDFLAGS += -pie -Wl,-z,relro,-z,now,-z,nodlopen,-z,noexecstack
|
||||
+
|
||||
+.SUFFIXES: .c .o
|
||||
+
|
||||
+main.o: main.c
|
||||
+ ${CC} ${ALL_CFLAGS} \
|
||||
-DVERSION=\"${VERSION}\" \
|
||||
-DNS_LOCALSTATEDIR=\"${localstatedir}\" \
|
||||
-DNS_SYSCONFDIR=\"${sysconfdir}\" -c ${srcdir}/main.c
|
||||
|
||||
-config.@O@: config.c
|
||||
- ${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} \
|
||||
+config.o: config.c
|
||||
+ ${CC} ${ALL_CFLAGS} \
|
||||
-DVERSION=\"${VERSION}\" \
|
||||
-DNS_LOCALSTATEDIR=\"${localstatedir}\" \
|
||||
-c ${srcdir}/config.c
|
||||
--- bind-9.3.2b1/bin/named/unix/Makefile.in.PIE 2004-03-08 04:04:15.000000000 -0500
|
||||
+++ bind-9.3.2b1/bin/named/unix/Makefile.in 2005-10-06 20:04:36.000000000 -0400
|
||||
@@ -27,10 +27,14 @@
|
||||
CDEFINES =
|
||||
CWARNINGS =
|
||||
|
||||
-OBJS = os.@O@
|
||||
+OBJS = os.o
|
||||
|
||||
SRCS = os.c
|
||||
|
||||
TARGETS = ${OBJS}
|
||||
|
||||
+EXT_CFLAGS = -fPIE
|
||||
+
|
||||
@BIND9_MAKE_RULES@
|
||||
+
|
||||
+.SUFFIXES: .c .o
|
||||
\ No newline at end of file
|
||||
--- bind-9.3.2b1/bin/check/Makefile.in.PIE 2004-07-20 03:01:48.000000000 -0400
|
||||
+++ bind-9.3.2b1/bin/check/Makefile.in 2005-10-06 20:04:36.000000000 -0400
|
||||
@@ -55,27 +55,33 @@
|
||||
|
||||
MANOBJS = ${MANPAGES} ${HTMLPAGES}
|
||||
|
||||
+EXT_CFLAGS = -fPIE
|
||||
+
|
||||
@BIND9_MAKE_RULES@
|
||||
|
||||
-named-checkconf.@O@: named-checkconf.c
|
||||
- ${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} \
|
||||
+LDFLAGS += -pie -Wl,-z,relro,-z,now,-z,nodlopen,-z,noexecstack
|
||||
+
|
||||
+.SUFFIXES: .c .o
|
||||
+
|
||||
+named-checkconf.o: named-checkconf.c
|
||||
+ ${CC} ${ALL_CFLAGS} \
|
||||
-DVERSION=\"${VERSION}\" \
|
||||
-c ${srcdir}/named-checkconf.c
|
||||
|
||||
-named-checkzone.@O@: named-checkzone.c
|
||||
- ${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} \
|
||||
+named-checkzone.o: named-checkzone.c
|
||||
+ ${CC} ${ALL_CFLAGS} \
|
||||
-DVERSION=\"${VERSION}\" \
|
||||
-c ${srcdir}/named-checkzone.c
|
||||
|
||||
-named-checkconf@EXEEXT@: named-checkconf.@O@ check-tool.@O@ ${ISCDEPLIBS} \
|
||||
+named-checkconf@EXEEXT@: named-checkconf.o check-tool.o ${ISCDEPLIBS} \
|
||||
${ISCCFGDEPLIBS} ${BIND9DEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||
- named-checkconf.@O@ check-tool.@O@ ${BIND9LIBS} ${ISCCFGLIBS} \
|
||||
+ named-checkconf.o check-tool.o ${BIND9LIBS} ${ISCCFGLIBS} \
|
||||
${DNSLIBS} ${ISCLIBS} ${LIBS}
|
||||
|
||||
-named-checkzone@EXEEXT@: named-checkzone.@O@ check-tool.@O@ ${ISCDEPLIBS} ${DNSDEPLIBS}
|
||||
+named-checkzone@EXEEXT@: named-checkzone.o check-tool.o ${ISCDEPLIBS} ${DNSDEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||
- named-checkzone.@O@ check-tool.@O@ ${DNSLIBS} ${ISCLIBS} ${LIBS}
|
||||
+ named-checkzone.o check-tool.o ${DNSLIBS} ${ISCLIBS} ${LIBS}
|
||||
|
||||
doc man:: ${MANOBJS}
|
||||
|
||||
--- bind-9.3.2b1/bin/nsupdate/Makefile.in.PIE 2004-07-20 03:01:49.000000000 -0400
|
||||
+++ bind-9.3.2b1/bin/nsupdate/Makefile.in 2005-10-06 20:04:36.000000000 -0400
|
||||
@@ -49,7 +49,7 @@
|
||||
|
||||
TARGETS = nsupdate@EXEEXT@
|
||||
|
||||
-OBJS = nsupdate.@O@
|
||||
+OBJS = nsupdate.o
|
||||
|
||||
UOBJS =
|
||||
|
||||
@@ -61,10 +61,16 @@
|
||||
|
||||
MANOBJS = ${MANPAGES} ${HTMLPAGES}
|
||||
|
||||
+EXT_CFLAGS = -fPIE
|
||||
+
|
||||
@BIND9_MAKE_RULES@
|
||||
|
||||
-nsupdate@EXEEXT@: nsupdate.@O@ ${UOBJS} ${DEPLIBS}
|
||||
- ${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ nsupdate.@O@ ${UOBJS} ${LIBS}
|
||||
+LDFLAGS += -pie -Wl,-z,relro,-z,now,-z,nodlopen,-z,noexecstack
|
||||
+
|
||||
+.SUFFIXES: .c .o
|
||||
+
|
||||
+nsupdate@EXEEXT@: nsupdate.o ${UOBJS} ${DEPLIBS}
|
||||
+ ${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ nsupdate.o ${UOBJS} ${LIBS}
|
||||
|
||||
doc man:: ${MANOBJS}
|
||||
|
||||
--- bind-9.3.2b1/bin/rndc/Makefile.in.PIE 2004-07-20 03:01:50.000000000 -0400
|
||||
+++ bind-9.3.2b1/bin/rndc/Makefile.in 2005-10-06 20:05:10.000000000 -0400
|
||||
@@ -57,28 +57,34 @@
|
||||
|
||||
MANOBJS = ${MANPAGES} ${HTMLPAGES}
|
||||
|
||||
-UOBJS = unix/os.@O@
|
||||
+UOBJS = unix/os.o
|
||||
+
|
||||
+EXT_CFLAGS = -fPIE
|
||||
|
||||
@BIND9_MAKE_RULES@
|
||||
|
||||
-rndc.@O@: rndc.c
|
||||
- ${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} \
|
||||
+LDFLAGS += -pie -Wl,-z,relro,-z,now,-z,nodlopen,-z,noexecstack
|
||||
+
|
||||
+.SUFFIXES: .c .o
|
||||
+
|
||||
+rndc.o: rndc.c
|
||||
+ ${CC} ${ALL_CFLAGS} \
|
||||
-DVERSION=\"${VERSION}\" \
|
||||
-DRNDC_CONFFILE=\"${sysconfdir}/rndc.conf\" \
|
||||
-DRNDC_KEYFILE=\"${sysconfdir}/rndc.key\" \
|
||||
-c ${srcdir}/rndc.c
|
||||
|
||||
-rndc-confgen.@O@: rndc-confgen.c
|
||||
- ${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} \
|
||||
+rndc-confgen.o: rndc-confgen.c
|
||||
+ ${CC} ${ALL_CFLAGS} \
|
||||
-DRNDC_KEYFILE=\"${sysconfdir}/rndc.key\" \
|
||||
-c ${srcdir}/rndc-confgen.c
|
||||
|
||||
-rndc@EXEEXT@: rndc.@O@ util.@O@ ${RNDCDEPLIBS}
|
||||
- ${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ rndc.@O@ util.@O@ \
|
||||
+rndc@EXEEXT@: rndc.o util.o ${RNDCDEPLIBS}
|
||||
+ ${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ rndc.o util.o \
|
||||
${RNDCLIBS}
|
||||
|
||||
-rndc-confgen@EXEEXT@: rndc-confgen.@O@ util.@O@ ${UOBJS} ${CONFDEPLIBS}
|
||||
- ${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ rndc-confgen.@O@ util.@O@ \
|
||||
+rndc-confgen@EXEEXT@: rndc-confgen.o util.o ${UOBJS} ${CONFDEPLIBS}
|
||||
+ ${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ rndc-confgen.o util.o \
|
||||
${UOBJS} ${CONFLIBS}
|
||||
|
||||
doc man:: ${MANOBJS}
|
||||
--- bind-9.3.2b1/bin/rndc/unix/Makefile.in.PIE 2004-03-07 23:04:24.000000000 -0500
|
||||
+++ bind-9.3.2b1/bin/rndc/unix/Makefile.in 2005-10-06 20:04:36.000000000 -0400
|
||||
@@ -27,10 +27,16 @@
|
||||
CDEFINES =
|
||||
CWARNINGS =
|
||||
|
||||
-OBJS = os.@O@
|
||||
+OBJS = os.o
|
||||
|
||||
SRCS = os.c
|
||||
|
||||
TARGETS = ${OBJS}
|
||||
|
||||
+EXT_CFLAGS = -fPIE
|
||||
+
|
||||
@BIND9_MAKE_RULES@
|
||||
+
|
||||
+LDFLAGS += -pie -Wl,-z,relro,-z,now,-z,nodlopen,-z,noexecstack
|
||||
+
|
||||
+.SUFFIXES: .c .o
|
||||
--- bind-9.3.2b1/bin/dig/Makefile.in.PIE 2004-08-18 19:25:57.000000000 -0400
|
||||
+++ bind-9.3.2b1/bin/dig/Makefile.in 2005-10-06 20:04:36.000000000 -0400
|
||||
@@ -51,7 +51,7 @@
|
||||
|
||||
TARGETS = dig@EXEEXT@ host@EXEEXT@ nslookup@EXEEXT@
|
||||
|
||||
-OBJS = dig.@O@ dighost.@O@ host.@O@ nslookup.@O@
|
||||
+OBJS = dig.o dighost.o host.o nslookup.o
|
||||
|
||||
UOBJS =
|
||||
|
||||
@@ -63,19 +63,25 @@
|
||||
|
||||
MANOBJS = ${MANPAGES} ${HTMLPAGES}
|
||||
|
||||
+EXT_CFLAGS = -fPIE
|
||||
+
|
||||
@BIND9_MAKE_RULES@
|
||||
|
||||
-dig@EXEEXT@: dig.@O@ dighost.@O@ ${UOBJS} ${DEPLIBS}
|
||||
+LDFLAGS += -pie -Wl,-z,relro,-z,now,-z,nodlopen,-z,noexecstack
|
||||
+
|
||||
+.SUFFIXES: .c .o
|
||||
+
|
||||
+dig@EXEEXT@: dig.o dighost.o ${UOBJS} ${DEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||
- dig.@O@ dighost.@O@ ${UOBJS} ${LIBS}
|
||||
+ dig.o dighost.o ${UOBJS} ${LIBS}
|
||||
|
||||
-host@EXEEXT@: host.@O@ dighost.@O@ ${UOBJS} ${DEPLIBS}
|
||||
+host@EXEEXT@: host.o dighost.o ${UOBJS} ${DEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||
- host.@O@ dighost.@O@ ${UOBJS} ${LIBS}
|
||||
+ host.o dighost.o ${UOBJS} ${LIBS}
|
||||
|
||||
-nslookup@EXEEXT@: nslookup.@O@ dighost.@O@ ${UOBJS} ${DEPLIBS}
|
||||
+nslookup@EXEEXT@: nslookup.o dighost.o ${UOBJS} ${DEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||
- nslookup.@O@ dighost.@O@ ${UOBJS} ${LIBS}
|
||||
+ nslookup.o dighost.o ${UOBJS} ${LIBS}
|
||||
|
||||
doc man:: ${MANOBJS}
|
||||
|
||||
|
|
@ -1,922 +0,0 @@
|
|||
--- /dev/null 2005-10-06 11:34:58.093275500 -0400
|
||||
+++ bind-9.3.2b1/bin/sdb_tools/ldap2zone.c 2005-10-06 18:57:32.000000000 -0400
|
||||
@@ -0,0 +1,397 @@
|
||||
+/*
|
||||
+ * Copyright (C) 2004, 2005 Stig Venaas <venaas@uninett.no>
|
||||
+ * $Id: ldap2zone.c,v 0.1 2005/04/23 21:30:12 venaas Exp $
|
||||
+ *
|
||||
+ * Permission to use, copy, modify, and distribute this software for any
|
||||
+ * purpose with or without fee is hereby granted, provided that the above
|
||||
+ * copyright notice and this permission notice appear in all copies.
|
||||
+ */
|
||||
+
|
||||
+#include <sys/types.h>
|
||||
+#include <stdio.h>
|
||||
+
|
||||
+#include <ldap.h>
|
||||
+
|
||||
+struct string {
|
||||
+ void *data;
|
||||
+ size_t len;
|
||||
+};
|
||||
+
|
||||
+struct assstack_entry {
|
||||
+ struct string key;
|
||||
+ struct string val;
|
||||
+ struct assstack_entry *next;
|
||||
+};
|
||||
+
|
||||
+struct assstack_entry *assstack_find(struct assstack_entry *stack, struct string *key) {
|
||||
+ for (; stack; stack = stack->next)
|
||||
+ if (stack->key.len == key->len && !memcmp(stack->key.data, key->data, key->len))
|
||||
+ return stack;
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
+void assstack_push(struct assstack_entry **stack, struct assstack_entry *item) {
|
||||
+ item->next = *stack;
|
||||
+ *stack = item;
|
||||
+}
|
||||
+
|
||||
+void assstack_insertbottom(struct assstack_entry **stack, struct assstack_entry *item) {
|
||||
+ struct assstack_entry *p;
|
||||
+
|
||||
+ item->next = NULL;
|
||||
+ if (!*stack) {
|
||||
+ *stack = item;
|
||||
+ return;
|
||||
+ }
|
||||
+ /* find end, should keep track of end somewhere */
|
||||
+ /* really a queue, not a stack */
|
||||
+ p = *stack;
|
||||
+ while (p->next)
|
||||
+ p = p->next;
|
||||
+ p->next = item;
|
||||
+}
|
||||
+
|
||||
+void printsoa(struct string *soa) {
|
||||
+ char *s;
|
||||
+ int i;
|
||||
+
|
||||
+ s = (char *)soa->data;
|
||||
+ i = 0;
|
||||
+ while (i < soa->len) {
|
||||
+ putchar(s[i]);
|
||||
+ if (s[i++] == ' ')
|
||||
+ break;
|
||||
+ }
|
||||
+ while (i < soa->len) {
|
||||
+ putchar(s[i]);
|
||||
+ if (s[i++] == ' ')
|
||||
+ break;
|
||||
+ }
|
||||
+ printf("(\n\t\t\t\t");
|
||||
+ while (i < soa->len) {
|
||||
+ putchar(s[i]);
|
||||
+ if (s[i++] == ' ')
|
||||
+ break;
|
||||
+ }
|
||||
+ printf("; Serialnumber\n\t\t\t\t");
|
||||
+ while (i < soa->len) {
|
||||
+ if (s[i] == ' ')
|
||||
+ break;
|
||||
+ putchar(s[i++]);
|
||||
+ }
|
||||
+ i++;
|
||||
+ printf("\t; Refresh\n\t\t\t\t");
|
||||
+ while (i < soa->len) {
|
||||
+ if (s[i] == ' ')
|
||||
+ break;
|
||||
+ putchar(s[i++]);
|
||||
+ }
|
||||
+ i++;
|
||||
+ printf("\t; Retry\n\t\t\t\t");
|
||||
+ while (i < soa->len) {
|
||||
+ if (s[i] == ' ')
|
||||
+ break;
|
||||
+ putchar(s[i++]);
|
||||
+ }
|
||||
+ i++;
|
||||
+ printf("\t; Expire\n\t\t\t\t");
|
||||
+ while (i < soa->len) {
|
||||
+ putchar(s[i++]);
|
||||
+ }
|
||||
+ printf(" )\t; Minimum TTL\n");
|
||||
+}
|
||||
+
|
||||
+void printrrs(char *defaultttl, struct assstack_entry *item) {
|
||||
+ struct assstack_entry *stack;
|
||||
+ char *s;
|
||||
+ int first;
|
||||
+ int i;
|
||||
+ char *ttl, *type;
|
||||
+ int top;
|
||||
+
|
||||
+ s = (char *)item->key.data;
|
||||
+
|
||||
+ if (item->key.len == 1 && *s == '@') {
|
||||
+ top = 1;
|
||||
+ printf("@\t");
|
||||
+ } else {
|
||||
+ top = 0;
|
||||
+ for (i = 0; i < item->key.len; i++)
|
||||
+ putchar(s[i]);
|
||||
+ if (item->key.len < 8)
|
||||
+ putchar('\t');
|
||||
+ putchar('\t');
|
||||
+ }
|
||||
+
|
||||
+ first = 1;
|
||||
+ for (stack = (struct assstack_entry *) item->val.data; stack; stack = stack->next) {
|
||||
+ ttl = (char *)stack->key.data;
|
||||
+ s = strchr(ttl, ' ');
|
||||
+ *s++ = '\0';
|
||||
+ type = s;
|
||||
+
|
||||
+ if (first)
|
||||
+ first = 0;
|
||||
+ else
|
||||
+ printf("\t\t");
|
||||
+
|
||||
+ if (strcmp(defaultttl, ttl))
|
||||
+ printf("%s", ttl);
|
||||
+ putchar('\t');
|
||||
+
|
||||
+ if (top) {
|
||||
+ top = 0;
|
||||
+ printf("IN\t%s\t", type);
|
||||
+ /* Should always be SOA here */
|
||||
+ if (!strcmp(type, "SOA")) {
|
||||
+ printsoa(&stack->val);
|
||||
+ continue;
|
||||
+ }
|
||||
+ } else
|
||||
+ printf("%s\t", type);
|
||||
+
|
||||
+ s = (char *)stack->val.data;
|
||||
+ for (i = 0; i < stack->val.len; i++)
|
||||
+ putchar(s[i]);
|
||||
+ putchar('\n');
|
||||
+ }
|
||||
+}
|
||||
+
|
||||
+void print_zone(char *defaultttl, struct assstack_entry *stack) {
|
||||
+ printf("$TTL %s\n", defaultttl);
|
||||
+ for (; stack; stack = stack->next)
|
||||
+ printrrs(defaultttl, stack);
|
||||
+};
|
||||
+
|
||||
+void usage(char *name) {
|
||||
+ fprintf(stderr, "Usage:%s zone-name LDAP-URL default-ttl [serial]\n", name);
|
||||
+ exit(1);
|
||||
+};
|
||||
+
|
||||
+void err(char *name, char *msg) {
|
||||
+ fprintf(stderr, "%s: %s\n", name, msg);
|
||||
+ exit(1);
|
||||
+};
|
||||
+
|
||||
+int putrr(struct assstack_entry **stack, struct berval *name, char *type, char *ttl, struct berval *val) {
|
||||
+ struct string key;
|
||||
+ struct assstack_entry *rr, *rrdata;
|
||||
+
|
||||
+ /* Do nothing if name or value have 0 length */
|
||||
+ if (!name->bv_len || !val->bv_len)
|
||||
+ return 0;
|
||||
+
|
||||
+ /* see if already have an entry for this name */
|
||||
+ key.len = name->bv_len;
|
||||
+ key.data = name->bv_val;
|
||||
+
|
||||
+ rr = assstack_find(*stack, &key);
|
||||
+ if (!rr) {
|
||||
+ /* Not found, create and push new entry */
|
||||
+ rr = (struct assstack_entry *) malloc(sizeof(struct assstack_entry));
|
||||
+ if (!rr)
|
||||
+ return -1;
|
||||
+ rr->key.len = name->bv_len;
|
||||
+ rr->key.data = (void *) malloc(rr->key.len);
|
||||
+ if (!rr->key.data) {
|
||||
+ free(rr);
|
||||
+ return -1;
|
||||
+ }
|
||||
+ memcpy(rr->key.data, name->bv_val, name->bv_len);
|
||||
+ rr->val.len = sizeof(void *);
|
||||
+ rr->val.data = NULL;
|
||||
+ if (name->bv_len == 1 && *(char *)name->bv_val == '@')
|
||||
+ assstack_push(stack, rr);
|
||||
+ else
|
||||
+ assstack_insertbottom(stack, rr);
|
||||
+ }
|
||||
+
|
||||
+ rrdata = (struct assstack_entry *) malloc(sizeof(struct assstack_entry));
|
||||
+ if (!rrdata) {
|
||||
+ free(rr->key.data);
|
||||
+ free(rr);
|
||||
+ return -1;
|
||||
+ }
|
||||
+ rrdata->key.len = strlen(type) + strlen(ttl) + 1;
|
||||
+ rrdata->key.data = (void *) malloc(rrdata->key.len);
|
||||
+ if (!rrdata->key.data) {
|
||||
+ free(rrdata);
|
||||
+ free(rr->key.data);
|
||||
+ free(rr);
|
||||
+ return -1;
|
||||
+ }
|
||||
+ sprintf((char *)rrdata->key.data, "%s %s", ttl, type);
|
||||
+
|
||||
+ rrdata->val.len = val->bv_len;
|
||||
+ rrdata->val.data = (void *) malloc(val->bv_len);
|
||||
+ if (!rrdata->val.data) {
|
||||
+ free(rrdata->key.data);
|
||||
+ free(rrdata);
|
||||
+ free(rr->key.data);
|
||||
+ free(rr);
|
||||
+ return -1;
|
||||
+ }
|
||||
+ memcpy(rrdata->val.data, val->bv_val, val->bv_len);
|
||||
+
|
||||
+ if (!strcmp(type, "SOA"))
|
||||
+ assstack_push((struct assstack_entry **) &(rr->val.data), rrdata);
|
||||
+ else
|
||||
+ assstack_insertbottom((struct assstack_entry **) &(rr->val.data), rrdata);
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
+int main(int argc, char **argv) {
|
||||
+ char *s, *hostporturl, *base = NULL;
|
||||
+ char *ttl, *defaultttl;
|
||||
+ LDAP *ld;
|
||||
+ char *fltr = NULL;
|
||||
+ LDAPMessage *res, *e;
|
||||
+ char *a, **ttlvals, **soavals, *serial;
|
||||
+ struct berval **vals, **names;
|
||||
+ char type[64];
|
||||
+ BerElement *ptr;
|
||||
+ int i, j, rc, msgid;
|
||||
+ struct assstack_entry *zone = NULL;
|
||||
+
|
||||
+ if (argc < 4 || argc > 5)
|
||||
+ usage(argv[0]);
|
||||
+
|
||||
+ hostporturl = argv[2];
|
||||
+
|
||||
+ if (hostporturl != strstr( hostporturl, "ldap"))
|
||||
+ err(argv[0], "Not an LDAP URL");
|
||||
+
|
||||
+ s = strchr(hostporturl, ':');
|
||||
+
|
||||
+ if (!s || strlen(s) < 3 || s[1] != '/' || s[2] != '/')
|
||||
+ err(argv[0], "Not an LDAP URL");
|
||||
+
|
||||
+ s = strchr(s+3, '/');
|
||||
+ if (s) {
|
||||
+ *s++ = '\0';
|
||||
+ base = s;
|
||||
+ s = strchr(base, '?');
|
||||
+ if (s)
|
||||
+ err(argv[0], "LDAP URL can only contain host, port and base");
|
||||
+ }
|
||||
+
|
||||
+ defaultttl = argv[3];
|
||||
+
|
||||
+ rc = ldap_initialize(&ld, hostporturl);
|
||||
+ if (rc != LDAP_SUCCESS)
|
||||
+ err(argv[0], "ldap_initialize() failed");
|
||||
+
|
||||
+ if (argc == 5) {
|
||||
+ /* serial number specified, check if different from one in SOA */
|
||||
+ fltr = (char *)malloc(strlen(argv[1]) + strlen("(&(relativeDomainName=@)(zoneName=))") + 1);
|
||||
+ sprintf(fltr, "(&(relativeDomainName=@)(zoneName=%s))", argv[1]);
|
||||
+ msgid = ldap_search(ld, base, LDAP_SCOPE_SUBTREE, fltr, NULL, 0);
|
||||
+ if (msgid == -1)
|
||||
+ err(argv[0], "ldap_search() failed");
|
||||
+
|
||||
+ while ((rc = ldap_result(ld, msgid, 0, NULL, &res)) != LDAP_RES_SEARCH_RESULT ) {
|
||||
+ /* not supporting continuation references at present */
|
||||
+ if (rc != LDAP_RES_SEARCH_ENTRY)
|
||||
+ err(argv[0], "ldap_result() returned cont.ref? Exiting");
|
||||
+
|
||||
+ /* only one entry per result message */
|
||||
+ e = ldap_first_entry(ld, res);
|
||||
+ if (e == NULL) {
|
||||
+ ldap_msgfree(res);
|
||||
+ err(argv[0], "ldap_first_entry() failed");
|
||||
+ }
|
||||
+
|
||||
+ soavals = ldap_get_values(ld, e, "SOARecord");
|
||||
+ if (soavals)
|
||||
+ break;
|
||||
+ }
|
||||
+
|
||||
+ ldap_msgfree(res);
|
||||
+ if (!soavals) {
|
||||
+ err(argv[0], "No SOA Record found");
|
||||
+ }
|
||||
+
|
||||
+ /* We have a SOA, compare serial numbers */
|
||||
+ /* Only checkinf first value, should be only one */
|
||||
+ s = strchr(soavals[0], ' ');
|
||||
+ s++;
|
||||
+ s = strchr(s, ' ');
|
||||
+ s++;
|
||||
+ serial = s;
|
||||
+ s = strchr(s, ' ');
|
||||
+ *s = '\0';
|
||||
+ if (!strcmp(serial, argv[4])) {
|
||||
+ ldap_value_free(soavals);
|
||||
+ err(argv[0], "serial numbers match");
|
||||
+ }
|
||||
+ ldap_value_free(soavals);
|
||||
+ }
|
||||
+
|
||||
+ if (!fltr)
|
||||
+ fltr = (char *)malloc(strlen(argv[1]) + strlen("(zoneName=)") + 1);
|
||||
+ if (!fltr)
|
||||
+ err(argv[0], "Malloc failed");
|
||||
+ sprintf(fltr, "(zoneName=%s)", argv[1]);
|
||||
+
|
||||
+ msgid = ldap_search(ld, base, LDAP_SCOPE_SUBTREE, fltr, NULL, 0);
|
||||
+ if (msgid == -1)
|
||||
+ err(argv[0], "ldap_search() failed");
|
||||
+
|
||||
+ while ((rc = ldap_result(ld, msgid, 0, NULL, &res)) != LDAP_RES_SEARCH_RESULT ) {
|
||||
+ /* not supporting continuation references at present */
|
||||
+ if (rc != LDAP_RES_SEARCH_ENTRY)
|
||||
+ err(argv[0], "ldap_result() returned cont.ref? Exiting");
|
||||
+
|
||||
+ /* only one entry per result message */
|
||||
+ e = ldap_first_entry(ld, res);
|
||||
+ if (e == NULL) {
|
||||
+ ldap_msgfree(res);
|
||||
+ err(argv[0], "ldap_first_entry() failed");
|
||||
+ }
|
||||
+
|
||||
+ names = ldap_get_values_len(ld, e, "relativeDomainName");
|
||||
+ if (!names)
|
||||
+ continue;
|
||||
+
|
||||
+ ttlvals = ldap_get_values(ld, e, "dNSTTL");
|
||||
+ ttl = ttlvals ? ttlvals[0] : defaultttl;
|
||||
+
|
||||
+ for (a = ldap_first_attribute(ld, e, &ptr); a != NULL; a = ldap_next_attribute(ld, e, ptr)) {
|
||||
+ char *s;
|
||||
+
|
||||
+ for (s = a; *s; s++)
|
||||
+ *s = toupper(*s);
|
||||
+ s = strstr(a, "RECORD");
|
||||
+ if ((s == NULL) || (s == a) || (s - a >= (signed int)sizeof(type))) {
|
||||
+ ldap_memfree(a);
|
||||
+ continue;
|
||||
+ }
|
||||
+
|
||||
+ strncpy(type, a, s - a);
|
||||
+ type[s - a] = '\0';
|
||||
+ vals = ldap_get_values_len(ld, e, a);
|
||||
+ if (vals) {
|
||||
+ for (i = 0; vals[i]; i++)
|
||||
+ for (j = 0; names[j]; j++)
|
||||
+ if (putrr(&zone, names[j], type, ttl, vals[i]))
|
||||
+ err(argv[0], "malloc failed");
|
||||
+ ldap_value_free_len(vals);
|
||||
+ }
|
||||
+ ldap_memfree(a);
|
||||
+ }
|
||||
+
|
||||
+ if (ptr)
|
||||
+ ber_free(ptr, 0);
|
||||
+ if (ttlvals)
|
||||
+ ldap_value_free(ttlvals);
|
||||
+ ldap_value_free_len(names);
|
||||
+ /* free this result */
|
||||
+ ldap_msgfree(res);
|
||||
+ }
|
||||
+
|
||||
+ /* free final result */
|
||||
+ ldap_msgfree(res);
|
||||
+
|
||||
+ print_zone(defaultttl, zone);
|
||||
+ return 0;
|
||||
+}
|
||||
--- bind-9.3.2b1/bin/sdb_tools/Makefile.in.fix_sdb_ldap 2005-02-17 01:43:28.000000000 -0500
|
||||
+++ bind-9.3.2b1/bin/sdb_tools/Makefile.in 2005-10-06 18:57:32.000000000 -0400
|
||||
@@ -30,11 +30,11 @@
|
||||
LIBS = ${LWRESLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
||||
${ISCCFGLIBS} ${ISCCCLIBS} ${ISCLIBS} ${DBDRIVER_LIBS} @LIBS@
|
||||
|
||||
-TARGETS = zone2ldap@EXEEXT@ zonetodb@EXEEXT@
|
||||
+TARGETS = zone2ldap@EXEEXT@ ldap2zone@EXEEXT@ zonetodb@EXEEXT@
|
||||
|
||||
-OBJS = zone2ldap.o zonetodb.o
|
||||
+OBJS = zone2ldap.o ldap2zone.o zonetodb.o
|
||||
|
||||
-SRCS = zone2ldap.c zonetodb.c
|
||||
+SRCS = zone2ldap.c ldap2zone.c zonetodb.c
|
||||
|
||||
MANPAGES = zone2ldap.1
|
||||
|
||||
@@ -54,6 +54,9 @@
|
||||
zonetodb: zonetodb.o ${DEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ zonetodb.o -lpq ${LIBS}
|
||||
|
||||
+ldap2zone: ldap2zone.o ${DEPLIBS}
|
||||
+ ${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ ldap2zone.o -lldap -llber ${LIBS}
|
||||
+
|
||||
clean distclean manclean maintainer-clean::
|
||||
rm -f ${TARGETS} ${OBJS}
|
||||
|
||||
@@ -63,5 +66,6 @@
|
||||
|
||||
install:: ${TARGETS} installdirs
|
||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zone2ldap ${DESTDIR}${sbindir}
|
||||
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} ldap2zone ${DESTDIR}${sbindir}
|
||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zonetodb ${DESTDIR}${sbindir}
|
||||
${INSTALL_DATA} ${srcdir}/zone2ldap.1 ${DESTDIR}${mandir}/man1/zone2ldap.1
|
||||
--- bind-9.3.2b1/bin/sdb_tools/zone2ldap.c.fix_sdb_ldap 2005-10-06 18:57:32.000000000 -0400
|
||||
+++ bind-9.3.2b1/bin/sdb_tools/zone2ldap.c 2005-10-06 18:57:32.000000000 -0400
|
||||
@@ -24,6 +24,7 @@
|
||||
#include <isc/hash.h>
|
||||
#include <isc/mem.h>
|
||||
#include <isc/print.h>
|
||||
+#include <isc/hash.h>
|
||||
#include <isc/result.h>
|
||||
|
||||
#include <dns/db.h>
|
||||
@@ -61,6 +62,9 @@
|
||||
/* usage Info */
|
||||
void usage (void);
|
||||
|
||||
+/* Check for existence of (and possibly add) containing dNSZone objects */
|
||||
+int lookup_dns_zones( ldap_info *ldinfo);
|
||||
+
|
||||
/* Add to the ldap dit */
|
||||
void add_ldap_values (ldap_info * ldinfo);
|
||||
|
||||
@@ -77,7 +81,7 @@
|
||||
int get_attr_list_size (char **tmp);
|
||||
|
||||
/* Get a DN */
|
||||
-char *build_dn_from_dc_list (char **dc_list, unsigned int ttl, int flag);
|
||||
+char *build_dn_from_dc_list (char **dc_list, unsigned int ttl, int flag, char *zone);
|
||||
|
||||
/* Add to RR list */
|
||||
void add_to_rr_list (char *dn, char *name, char *type, char *data,
|
||||
@@ -99,11 +103,27 @@
|
||||
init_ldap_conn ();
|
||||
void usage();
|
||||
|
||||
-char *argzone, *ldapbase, *binddn, *bindpw = NULL;
|
||||
-const char *ldapsystem = "localhost";
|
||||
-static const char *objectClasses[] =
|
||||
- { "top", "dNSZone", NULL };
|
||||
-static const char *topObjectClasses[] = { "top", NULL };
|
||||
+static char *argzone, *ldapbase, *binddn, *bindpw = NULL;
|
||||
+
|
||||
+/* these are needed to placate gcc4's const-ness const-ernations : */
|
||||
+static char localhost[] = "localhost";
|
||||
+static char *ldapsystem=&(localhost[0]);
|
||||
+/* dnszone schema class names: */
|
||||
+static char topClass [] ="top";
|
||||
+static char dNSZoneClass[] ="dNSZone";
|
||||
+static char objectClass [] ="objectClass";
|
||||
+static char dcObjectClass[]="dcObject";
|
||||
+/* dnszone schema attribute names: */
|
||||
+static char relativeDomainName[]="relativeDomainName";
|
||||
+static char dNSTTL []="dNSTTL";
|
||||
+static char zoneName []="zoneName";
|
||||
+static char dc []="dc";
|
||||
+static char sameZone []="@";
|
||||
+/* LDAPMod mod_values: */
|
||||
+static char *objectClasses []= { &(topClass[0]), &(dNSZoneClass[0]), NULL };
|
||||
+static char *topObjectClasses []= { &(topClass[0]), &(dcObjectClass[0]), &(dNSZoneClass[0]), NULL };
|
||||
+static char *dn_buffer [64]={NULL};
|
||||
+
|
||||
LDAP *conn;
|
||||
unsigned int debug = 0;
|
||||
|
||||
@@ -119,12 +139,12 @@
|
||||
isc_result_t result;
|
||||
char *basedn;
|
||||
ldap_info *tmp;
|
||||
- LDAPMod *base_attrs[2];
|
||||
- LDAPMod base;
|
||||
+ LDAPMod *base_attrs[5];
|
||||
+ LDAPMod base, dcBase, znBase, rdnBase;
|
||||
isc_buffer_t buff;
|
||||
char *zonefile=0L;
|
||||
char fullbasedn[1024];
|
||||
- char *ctmp;
|
||||
+ char *ctmp, *zn, *dcp[2], *znp[2], *rdn[2];
|
||||
dns_fixedname_t fixedzone, fixedname;
|
||||
dns_rdataset_t rdataset;
|
||||
char **dc_list;
|
||||
@@ -137,7 +157,7 @@
|
||||
extern char *optarg;
|
||||
extern int optind, opterr, optopt;
|
||||
int create_base = 0;
|
||||
- int topt;
|
||||
+ int topt, dcn, zdn, znlen;
|
||||
|
||||
if ((int) argc < 2)
|
||||
{
|
||||
@@ -145,7 +165,7 @@
|
||||
exit (-1);
|
||||
}
|
||||
|
||||
- while ((topt = getopt ((int) argc, argv, "D:w:b:z:f:h:?dcv")) != -1)
|
||||
+ while ((topt = getopt ((int) argc, argv, "D:Ww:b:z:f:h:?dcv")) != -1)
|
||||
{
|
||||
switch (topt)
|
||||
{
|
||||
@@ -164,8 +184,11 @@
|
||||
case 'w':
|
||||
bindpw = strdup (optarg);
|
||||
break;
|
||||
+ case 'W':
|
||||
+ bindpw = getpass("Enter LDAP Password: ");
|
||||
+ break;
|
||||
case 'b':
|
||||
- ldapbase = strdup (optarg);
|
||||
+ ldapbase = strdup (optarg);
|
||||
break;
|
||||
case 'z':
|
||||
argzone = strdup (optarg);
|
||||
@@ -277,27 +300,62 @@
|
||||
{
|
||||
if (debug)
|
||||
printf ("Creating base zone DN %s\n", argzone);
|
||||
-
|
||||
+
|
||||
dc_list = hostname_to_dn_list (argzone, argzone, DNS_TOP);
|
||||
- basedn = build_dn_from_dc_list (dc_list, 0, NO_SPEC);
|
||||
|
||||
- for (ctmp = &basedn[strlen (basedn)]; ctmp >= &basedn[0]; ctmp--)
|
||||
+ basedn = build_dn_from_dc_list (dc_list, 0, NO_SPEC, argzone);
|
||||
+ if (debug)
|
||||
+ printf ("base DN %s\n", basedn);
|
||||
+
|
||||
+ for (ctmp = &basedn[strlen (basedn)], dcn=0; ctmp >= &basedn[0]; ctmp--)
|
||||
{
|
||||
- if ((*ctmp == ',') || (ctmp == &basedn[0]))
|
||||
+ if ((*ctmp == ',') || (ctmp == &basedn[0]))
|
||||
{
|
||||
+
|
||||
base.mod_op = LDAP_MOD_ADD;
|
||||
- base.mod_type = (char*)"objectClass";
|
||||
- base.mod_values = (char**)topObjectClasses;
|
||||
+ base.mod_type = objectClass;
|
||||
+ base.mod_values = topObjectClasses;
|
||||
base_attrs[0] = (void*)&base;
|
||||
- base_attrs[1] = NULL;
|
||||
-
|
||||
+
|
||||
+ dcBase.mod_op = LDAP_MOD_ADD;
|
||||
+ dcBase.mod_type = dc;
|
||||
+ dcp[0]=dc_list[dcn];
|
||||
+ dcp[1]=0L;
|
||||
+ dcBase.mod_values=dcp;
|
||||
+ base_attrs[1] = (void*)&dcBase;
|
||||
+
|
||||
+ znBase.mod_op = LDAP_MOD_ADD;
|
||||
+ znBase.mod_type = zoneName;
|
||||
+ for( zdn = dcn, znlen = 0; zdn >= 0; zdn-- )
|
||||
+ znlen += strlen(dc_list[zdn])+1;
|
||||
+ znp[0] = (char*)malloc(znlen+1);
|
||||
+ znp[1] = 0L;
|
||||
+ for( zdn = dcn, zn=znp[0]; zdn >= 0; zdn-- )
|
||||
+ zn+=sprintf(zn,"%s%s",dc_list[zdn],
|
||||
+ ((zdn > 0) && (*(dc_list[zdn-1])!='.')) ? "." : ""
|
||||
+ );
|
||||
+
|
||||
+ znBase.mod_values = znp;
|
||||
+ base_attrs[2] = (void*)&znBase;
|
||||
+
|
||||
+ rdnBase.mod_op = LDAP_MOD_ADD;
|
||||
+ rdnBase.mod_type = relativeDomainName;
|
||||
+ rdn[0] = strdup(sameZone);
|
||||
+ rdn[1] = 0L;
|
||||
+ rdnBase.mod_values = rdn;
|
||||
+ base_attrs[3] = (void*)&rdnBase;
|
||||
+
|
||||
+ dcn++;
|
||||
+
|
||||
+ base.mod_values = topObjectClasses;
|
||||
+ base_attrs[4] = NULL;
|
||||
+
|
||||
if (ldapbase)
|
||||
{
|
||||
if (ctmp != &basedn[0])
|
||||
sprintf (fullbasedn, "%s,%s", ctmp + 1, ldapbase);
|
||||
else
|
||||
- sprintf (fullbasedn, "%s,%s", ctmp, ldapbase);
|
||||
-
|
||||
+ sprintf (fullbasedn, "%s,%s", ctmp, ldapbase);
|
||||
}
|
||||
else
|
||||
{
|
||||
@@ -306,8 +364,13 @@
|
||||
else
|
||||
sprintf (fullbasedn, "%s", ctmp);
|
||||
}
|
||||
+
|
||||
+ if( debug )
|
||||
+ printf("Full base dn: %s\n", fullbasedn);
|
||||
+
|
||||
result = ldap_add_s (conn, fullbasedn, base_attrs);
|
||||
ldap_result_check ("intial ldap_add_s", fullbasedn, result);
|
||||
+
|
||||
}
|
||||
|
||||
}
|
||||
@@ -383,14 +446,14 @@
|
||||
isc_result_check (result, "dns_rdata_totext");
|
||||
data[isc_buffer_usedlength (&buff)] = 0;
|
||||
|
||||
- dc_list = hostname_to_dn_list (name, argzone, DNS_OBJECT);
|
||||
+ dc_list = hostname_to_dn_list ((char*)name, argzone, DNS_OBJECT);
|
||||
len = (get_attr_list_size (dc_list) - 2);
|
||||
- dn = build_dn_from_dc_list (dc_list, ttl, WI_SPEC);
|
||||
+ dn = build_dn_from_dc_list (dc_list, ttl, WI_SPEC, argzone);
|
||||
|
||||
if (debug)
|
||||
printf ("Adding %s (%s %s) to run queue list.\n", dn, type, data);
|
||||
|
||||
- add_to_rr_list (dn, dc_list[len], type, data, ttl, DNS_OBJECT);
|
||||
+ add_to_rr_list (dn, dc_list[len], (char*)type, (char*)data, ttl, DNS_OBJECT);
|
||||
}
|
||||
|
||||
|
||||
@@ -430,7 +493,8 @@
|
||||
int attrlist;
|
||||
char ldap_type_buffer[128];
|
||||
char charttl[64];
|
||||
-
|
||||
+ char *zn;
|
||||
+ int znlen;
|
||||
|
||||
if ((tmp = locate_by_dn (dn)) == NULL)
|
||||
{
|
||||
@@ -465,13 +529,13 @@
|
||||
}
|
||||
}
|
||||
tmp->attrs[0]->mod_op = LDAP_MOD_ADD;
|
||||
- tmp->attrs[0]->mod_type = (char*)"objectClass";
|
||||
+ tmp->attrs[0]->mod_type = objectClass;
|
||||
|
||||
if (flags == DNS_OBJECT)
|
||||
- tmp->attrs[0]->mod_values = (char**)objectClasses;
|
||||
+ tmp->attrs[0]->mod_values = objectClasses;
|
||||
else
|
||||
{
|
||||
- tmp->attrs[0]->mod_values = (char**)topObjectClasses;
|
||||
+ tmp->attrs[0]->mod_values =topObjectClasses;
|
||||
tmp->attrs[1] = NULL;
|
||||
tmp->attrcnt = 2;
|
||||
tmp->next = ldap_info_base;
|
||||
@@ -480,7 +544,7 @@
|
||||
}
|
||||
|
||||
tmp->attrs[1]->mod_op = LDAP_MOD_ADD;
|
||||
- tmp->attrs[1]->mod_type = (char*)"relativeDomainName";
|
||||
+ tmp->attrs[1]->mod_type = relativeDomainName;
|
||||
tmp->attrs[1]->mod_values = (char **) calloc (sizeof (char *), 2);
|
||||
|
||||
if (tmp->attrs[1]->mod_values == (char **)NULL)
|
||||
@@ -502,7 +566,7 @@
|
||||
tmp->attrs[2]->mod_values[1] = NULL;
|
||||
|
||||
tmp->attrs[3]->mod_op = LDAP_MOD_ADD;
|
||||
- tmp->attrs[3]->mod_type = (char*)"dNSTTL";
|
||||
+ tmp->attrs[3]->mod_type = dNSTTL;
|
||||
tmp->attrs[3]->mod_values = (char **) calloc (sizeof (char *), 2);
|
||||
|
||||
if (tmp->attrs[3]->mod_values == (char **)NULL)
|
||||
@@ -512,10 +576,21 @@
|
||||
tmp->attrs[3]->mod_values[0] = strdup (charttl);
|
||||
tmp->attrs[3]->mod_values[1] = NULL;
|
||||
|
||||
+ znlen=strlen(gbl_zone);
|
||||
+ if ( *(gbl_zone + (znlen-1)) == '.' )
|
||||
+ { /* ldapdb MUST search by relative zone name */
|
||||
+ zn = (char*)malloc(znlen);
|
||||
+ strncpy(zn,gbl_zone,znlen-1);
|
||||
+ *(zn + (znlen-1))='\0';
|
||||
+ }else
|
||||
+ {
|
||||
+ zn = gbl_zone;
|
||||
+ }
|
||||
+
|
||||
tmp->attrs[4]->mod_op = LDAP_MOD_ADD;
|
||||
- tmp->attrs[4]->mod_type = (char*)"zoneName";
|
||||
+ tmp->attrs[4]->mod_type = zoneName;
|
||||
tmp->attrs[4]->mod_values = (char **)calloc(sizeof(char *), 2);
|
||||
- tmp->attrs[4]->mod_values[0] = gbl_zone;
|
||||
+ tmp->attrs[4]->mod_values[0] = zn;
|
||||
tmp->attrs[4]->mod_values[1] = NULL;
|
||||
|
||||
tmp->attrs[5] = NULL;
|
||||
@@ -526,7 +601,7 @@
|
||||
else
|
||||
{
|
||||
|
||||
- for (i = 0; tmp->attrs[i] != NULL; i++)
|
||||
+ for (i = 0; tmp->attrs[i] != NULL; i++)
|
||||
{
|
||||
sprintf (ldap_type_buffer, "%sRecord", type);
|
||||
if (!strncmp
|
||||
@@ -595,69 +670,105 @@
|
||||
hostname_to_dn_list (char *hostname, char *zone, unsigned int flags)
|
||||
{
|
||||
char *tmp;
|
||||
- static char *dn_buffer[64];
|
||||
int i = 0;
|
||||
- char *zname;
|
||||
- char *hnamebuff;
|
||||
-
|
||||
- zname = strdup (hostname);
|
||||
-
|
||||
- if (flags == DNS_OBJECT)
|
||||
- {
|
||||
+ char *hname=0L, *last=0L;
|
||||
+ int hlen=strlen(hostname), zlen=(strlen(zone));
|
||||
|
||||
- if (strlen (zname) != strlen (zone))
|
||||
- {
|
||||
- tmp = &zname[strlen (zname) - strlen (zone)];
|
||||
- *--tmp = '\0';
|
||||
- hnamebuff = strdup (zname);
|
||||
- zname = ++tmp;
|
||||
- }
|
||||
- else
|
||||
- hnamebuff = (char*)"@";
|
||||
- }
|
||||
- else
|
||||
- {
|
||||
- zname = zone;
|
||||
- hnamebuff = NULL;
|
||||
- }
|
||||
-
|
||||
- for (tmp = strrchr (zname, '.'); tmp != (char *) 0;
|
||||
- tmp = strrchr (zname, '.'))
|
||||
- {
|
||||
- *tmp++ = '\0';
|
||||
- dn_buffer[i++] = tmp;
|
||||
- }
|
||||
- dn_buffer[i++] = zname;
|
||||
- dn_buffer[i++] = hnamebuff;
|
||||
+/* printf("hostname: %s zone: %s\n",hostname, zone); */
|
||||
+ hname=0L;
|
||||
+ if(flags == DNS_OBJECT)
|
||||
+ {
|
||||
+ if( (zone[ zlen - 1 ] == '.') && (hostname[hlen - 1] != '.') )
|
||||
+ {
|
||||
+ hname=(char*)malloc(hlen + 1);
|
||||
+ hlen += 1;
|
||||
+ sprintf(hname, "%s.", hostname);
|
||||
+ hostname = hname;
|
||||
+ }
|
||||
+ if(strcmp(hostname, zone) == 0)
|
||||
+ {
|
||||
+ if( hname == 0 )
|
||||
+ hname=strdup(hostname);
|
||||
+ last = strdup(sameZone);
|
||||
+ }else
|
||||
+ {
|
||||
+ if( (hlen < zlen)
|
||||
+ ||( strcmp( hostname + (hlen - zlen), zone ) != 0)
|
||||
+ )
|
||||
+ {
|
||||
+ if( hname != 0 )
|
||||
+ free(hname);
|
||||
+ hname=(char*)malloc( hlen + zlen + 1);
|
||||
+ if( *zone == '.' )
|
||||
+ sprintf(hname, "%s%s", hostname, zone);
|
||||
+ else
|
||||
+ sprintf(hname,"%s",zone);
|
||||
+ }else
|
||||
+ {
|
||||
+ if( hname == 0 )
|
||||
+ hname = strdup(hostname);
|
||||
+ }
|
||||
+ last = hname;
|
||||
+ }
|
||||
+ }else
|
||||
+ { /* flags == DNS_TOP */
|
||||
+ hname = strdup(zone);
|
||||
+ last = hname;
|
||||
+ }
|
||||
+
|
||||
+ for (tmp = strrchr (hname, '.'); tmp != (char *) 0;
|
||||
+ tmp = strrchr (hname, '.'))
|
||||
+ {
|
||||
+ if( *( tmp + 1 ) != '\0' )
|
||||
+ {
|
||||
+ *tmp = '\0';
|
||||
+ dn_buffer[i++] = ++tmp;
|
||||
+ }else
|
||||
+ { /* trailing '.' ! */
|
||||
+ dn_buffer[i++] = strdup(".");
|
||||
+ *tmp = '\0';
|
||||
+ if( tmp == hname )
|
||||
+ break;
|
||||
+ }
|
||||
+ }
|
||||
+ if( ( last != hname ) && (tmp != hname) )
|
||||
+ dn_buffer[i++] = hname;
|
||||
+ dn_buffer[i++] = last;
|
||||
dn_buffer[i] = NULL;
|
||||
-
|
||||
return dn_buffer;
|
||||
}
|
||||
|
||||
-
|
||||
/* build an sdb compatible LDAP DN from a "dc_list" (char **).
|
||||
* will append dNSTTL information to each RR Record, with the
|
||||
* exception of "@"/SOA. */
|
||||
|
||||
char *
|
||||
-build_dn_from_dc_list (char **dc_list, unsigned int ttl, int flag)
|
||||
+build_dn_from_dc_list (char **dc_list, unsigned int ttl, int flag, char *zone)
|
||||
{
|
||||
int size;
|
||||
- int x;
|
||||
+ int x, znlen;
|
||||
static char dn[1024];
|
||||
char tmp[128];
|
||||
+ char zn[DNS_NAME_MAXTEXT+1];
|
||||
|
||||
bzero (tmp, sizeof (tmp));
|
||||
bzero (dn, sizeof (dn));
|
||||
size = get_attr_list_size (dc_list);
|
||||
+ znlen = strlen(zone);
|
||||
+ if ( *(zone + (znlen-1)) == '.' )
|
||||
+ { /* ldapdb MUST search by relative zone name */
|
||||
+ memcpy(&(zn[0]),zone,znlen-1);
|
||||
+ *(zn + (znlen-1))='\0';
|
||||
+ zone = zn;
|
||||
+ }
|
||||
for (x = size - 2; x > 0; x--)
|
||||
{
|
||||
if (flag == WI_SPEC)
|
||||
{
|
||||
if (x == (size - 2) && (strncmp (dc_list[x], "@", 1) == 0) && (ttl))
|
||||
- sprintf (tmp, "relativeDomainName=%s + dNSTTL=%d,", dc_list[x], ttl);
|
||||
+ sprintf (tmp, "zoneName=%s + relativeDomainName=%s,", zone, dc_list[x]);
|
||||
else if (x == (size - 2))
|
||||
- sprintf(tmp, "relativeDomainName=%s,",dc_list[x]);
|
||||
+ sprintf(tmp, "zoneName=%s + relativeDomainName=%s,", zone, dc_list[x]);
|
||||
else
|
||||
sprintf(tmp,"dc=%s,", dc_list[x]);
|
||||
}
|
||||
@@ -683,6 +794,7 @@
|
||||
init_ldap_conn ()
|
||||
{
|
||||
int result;
|
||||
+ char ldb_tag[]="LDAP Bind";
|
||||
conn = ldap_open (ldapsystem, LDAP_PORT);
|
||||
if (conn == NULL)
|
||||
{
|
||||
@@ -692,7 +804,7 @@
|
||||
}
|
||||
|
||||
result = ldap_simple_bind_s (conn, binddn, bindpw);
|
||||
- ldap_result_check ("ldap_simple_bind_s", (char*)"LDAP Bind", result);
|
||||
+ ldap_result_check ("ldap_simple_bind_s", ldb_tag , result);
|
||||
}
|
||||
|
||||
/* Like isc_result_check, only for LDAP */
|
||||
@@ -709,8 +821,6 @@
|
||||
}
|
||||
}
|
||||
|
||||
-
|
||||
-
|
||||
/* For running the ldap_info run queue. */
|
||||
void
|
||||
add_ldap_values (ldap_info * ldinfo)
|
||||
@@ -718,14 +828,14 @@
|
||||
int result;
|
||||
char dnbuffer[1024];
|
||||
|
||||
-
|
||||
if (ldapbase != NULL)
|
||||
sprintf (dnbuffer, "%s,%s", ldinfo->dn, ldapbase);
|
||||
else
|
||||
sprintf (dnbuffer, "%s", ldinfo->dn);
|
||||
|
||||
result = ldap_add_s (conn, dnbuffer, ldinfo->attrs);
|
||||
- ldap_result_check ("ldap_add_s", dnbuffer, result);
|
||||
+ ldap_result_check ("ldap_add_s", dnbuffer, result);
|
||||
+
|
||||
}
|
||||
|
||||
|
||||
@@ -736,7 +846,7 @@
|
||||
usage ()
|
||||
{
|
||||
fprintf (stderr,
|
||||
- "zone2ldap -D [BIND DN] -w [BIND PASSWORD] -b [BASE DN] -z [ZONE] -f [ZONE FILE] -h [LDAP HOST]\n"
|
||||
+ "zone2ldap -D [BIND DN] [-w BIND PASSWORD | -W:prompt] -b [BASE DN] -z [ZONE] -f [ZONE FILE] -h [LDAP HOST]\n"
|
||||
"\t[-c Create LDAP Base structure][-d Debug Output (lots !)]\n "
|
||||
);
|
||||
}
|
||||
|
|
@ -1,104 +0,0 @@
|
|||
--- bind-9.3.2b2/bin/dig/host.1.no_servfail_stops 2005-10-12 22:33:43.000000000 -0400
|
||||
+++ bind-9.3.2b2/bin/dig/host.1 2005-11-15 12:51:26.000000000 -0500
|
||||
@@ -30,7 +30,7 @@
|
||||
host \- DNS lookup utility
|
||||
.SH "SYNOPSIS"
|
||||
.HP 5
|
||||
-\fBhost\fR [\fB\-aCdlnrTwv\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-N\ \fR\fB\fIndots\fR\fR] [\fB\-R\ \fR\fB\fInumber\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-W\ \fR\fB\fIwait\fR\fR] [\fB\-4\fR] [\fB\-6\fR] {name} [server]
|
||||
+\fBhost\fR [\fB\-aCdlnrTwv\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-N\ \fR\fB\fIndots\fR\fR] [\fB\-R\ \fR\fB\fInumber\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-W\ \fR\fB\fIwait\fR\fR] [\fB\-4\fR] [\fB\-6\fR] [ \fB\-s\fR ] {name} [server]
|
||||
.SH "DESCRIPTION"
|
||||
.PP
|
||||
\fBhost\fR
|
||||
@@ -176,6 +176,11 @@
|
||||
option is used,
|
||||
\fBhost\fR
|
||||
will effectively wait forever for a reply. The time to wait for a response will be set to the number of seconds given by the hardware's maximum value for an integer quantity.
|
||||
+.PP
|
||||
+The \fB-s\fR option tells \fBhost\fR NOT to send the query to the next nameserver if any
|
||||
+server responds with a SERVFAIL response, which is the reverse of normal stub resolver
|
||||
+behaviour.
|
||||
+.PP
|
||||
.SH "FILES"
|
||||
.PP
|
||||
\fI/etc/resolv.conf\fR
|
||||
--- bind-9.3.2b2/bin/dig/nslookup.c.no_servfail_stops 2005-07-12 01:47:42.000000000 -0400
|
||||
+++ bind-9.3.2b2/bin/dig/nslookup.c 2005-11-15 12:49:55.000000000 -0500
|
||||
@@ -50,7 +50,8 @@
|
||||
comments = ISC_TRUE, section_question = ISC_TRUE,
|
||||
section_answer = ISC_TRUE, section_authority = ISC_TRUE,
|
||||
section_additional = ISC_TRUE, recurse = ISC_TRUE,
|
||||
- aaonly = ISC_FALSE;
|
||||
+ aaonly = ISC_FALSE, nofail=ISC_TRUE;
|
||||
+
|
||||
static isc_boolean_t in_use = ISC_FALSE;
|
||||
static char defclass[MXRD] = "IN";
|
||||
static char deftype[MXRD] = "A";
|
||||
@@ -631,6 +632,10 @@
|
||||
usesearch = ISC_FALSE;
|
||||
} else if (strncasecmp(opt, "sil", 3) == 0) {
|
||||
/* deprecation_msg = ISC_FALSE; */
|
||||
+ } else if (strncasecmp(opt, "fail", 3) == 0) {
|
||||
+ nofail=ISC_FALSE;
|
||||
+ } else if (strncasecmp(opt, "nofail", 3) == 0) {
|
||||
+ nofail=ISC_TRUE;
|
||||
} else {
|
||||
printf("*** Invalid option: %s\n", opt);
|
||||
}
|
||||
@@ -689,6 +694,8 @@
|
||||
lookup->section_authority = section_authority;
|
||||
lookup->section_additional = section_additional;
|
||||
lookup->new_search = ISC_TRUE;
|
||||
+ if ( nofail )
|
||||
+ lookup->servfail_stops = ISC_FALSE;
|
||||
ISC_LIST_INIT(lookup->q);
|
||||
ISC_LINK_INIT(lookup, link);
|
||||
ISC_LIST_APPEND(lookup_list, lookup, link);
|
||||
--- bind-9.3.2b2/bin/dig/nslookup.1.no_servfail_stops 2005-10-12 22:33:43.000000000 -0400
|
||||
+++ bind-9.3.2b2/bin/dig/nslookup.1 2005-11-15 12:49:55.000000000 -0500
|
||||
@@ -166,6 +166,12 @@
|
||||
Always use a virtual circuit when sending requests to the server.
|
||||
.sp
|
||||
(Default = novc)
|
||||
+.TP
|
||||
+\fB[no]fail\R
|
||||
+Try the next nameserver if a nameserver responds with SERVFAIL or
|
||||
+a referral (nofail) or terminate query (fail) on such a response.
|
||||
+
|
||||
+(Default = nofail)
|
||||
.RE
|
||||
.IP
|
||||
.SH "FILES"
|
||||
--- bind-9.3.2b2/bin/dig/host.c.no_servfail_stops 2005-07-03 23:29:45.000000000 -0400
|
||||
+++ bind-9.3.2b2/bin/dig/host.c 2005-11-15 12:49:55.000000000 -0500
|
||||
@@ -128,7 +128,8 @@
|
||||
" -w specifies to wait forever for a reply\n"
|
||||
" -W specifies how long to wait for a reply\n"
|
||||
" -4 use IPv4 query transport only\n"
|
||||
-" -6 use IPv6 query transport only\n", stderr);
|
||||
+" -6 use IPv6 query transport only\n"
|
||||
+" -s a SERVFAIL response should stop query\n", stderr);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
@@ -538,7 +539,10 @@
|
||||
|
||||
lookup = make_empty_lookup();
|
||||
|
||||
- while ((c = isc_commandline_parse(argc, argv, "lvwrdt:c:aTCN:R:W:Dni46"))
|
||||
+ lookup->servfail_stops = ISC_FALSE;
|
||||
+ lookup->comments = ISC_FALSE;
|
||||
+
|
||||
+ while ((c = isc_commandline_parse(argc, argv, "lvwrdt:c:aTCN:R:W:Dni46s"))
|
||||
!= EOF) {
|
||||
switch (c) {
|
||||
case 'l':
|
||||
@@ -676,6 +680,9 @@
|
||||
} else
|
||||
fatal("can't find IPv6 networking");
|
||||
break;
|
||||
+ case 's':
|
||||
+ lookup->servfail_stops = ISC_TRUE;
|
||||
+ break;
|
||||
}
|
||||
}
|
||||
|
||||
|
|
@ -1,252 +0,0 @@
|
|||
--- bind-9.3.2b2/contrib/sdb/ldap/zone2ldap.c.sdbsrc 2005-08-16 00:43:03.000000000 -0400
|
||||
+++ bind-9.3.2b2/contrib/sdb/ldap/zone2ldap.c 2005-11-15 12:57:44.000000000 -0500
|
||||
@@ -59,16 +59,16 @@
|
||||
ldap_info;
|
||||
|
||||
/* usage Info */
|
||||
-void usage ();
|
||||
+void usage (void);
|
||||
|
||||
/* Add to the ldap dit */
|
||||
void add_ldap_values (ldap_info * ldinfo);
|
||||
|
||||
/* Init an ldap connection */
|
||||
-void init_ldap_conn ();
|
||||
+void init_ldap_conn (void);
|
||||
|
||||
/* Ldap error checking */
|
||||
-void ldap_result_check (char *msg, char *dn, int err);
|
||||
+void ldap_result_check (const char *msg, char *dn, int err);
|
||||
|
||||
/* Put a hostname into a char ** array */
|
||||
char **hostname_to_dn_list (char *hostname, char *zone, unsigned int flags);
|
||||
@@ -84,7 +84,7 @@
|
||||
unsigned int ttl, unsigned int flags);
|
||||
|
||||
/* Error checking */
|
||||
-void isc_result_check (isc_result_t res, char *errorstr);
|
||||
+void isc_result_check (isc_result_t res, const char *errorstr);
|
||||
|
||||
/* Generate LDIF Format files */
|
||||
void generate_ldap (dns_name_t * dnsname, dns_rdata_t * rdata,
|
||||
@@ -93,11 +93,17 @@
|
||||
/* head pointer to the list */
|
||||
ldap_info *ldap_info_base = NULL;
|
||||
|
||||
+ldap_info *
|
||||
+locate_by_dn (char *dn);
|
||||
+void
|
||||
+init_ldap_conn ();
|
||||
+void usage();
|
||||
+
|
||||
char *argzone, *ldapbase, *binddn, *bindpw = NULL;
|
||||
-char *ldapsystem = "localhost";
|
||||
-static char *objectClasses[] =
|
||||
+const char *ldapsystem = "localhost";
|
||||
+static const char *objectClasses[] =
|
||||
{ "top", "dNSZone", NULL };
|
||||
-static char *topObjectClasses[] = { "top", NULL };
|
||||
+static const char *topObjectClasses[] = { "top", NULL };
|
||||
LDAP *conn;
|
||||
unsigned int debug = 0;
|
||||
|
||||
@@ -106,7 +112,7 @@
|
||||
#endif
|
||||
|
||||
int
|
||||
-main (int *argc, char **argv)
|
||||
+main (int argc, char **argv)
|
||||
{
|
||||
isc_mem_t *mctx = NULL;
|
||||
isc_entropy_t *ectx = NULL;
|
||||
@@ -116,7 +122,7 @@
|
||||
LDAPMod *base_attrs[2];
|
||||
LDAPMod base;
|
||||
isc_buffer_t buff;
|
||||
- char *zonefile;
|
||||
+ char *zonefile=0L;
|
||||
char fullbasedn[1024];
|
||||
char *ctmp;
|
||||
dns_fixedname_t fixedzone, fixedname;
|
||||
@@ -280,9 +286,9 @@
|
||||
if ((*ctmp == ',') || (ctmp == &basedn[0]))
|
||||
{
|
||||
base.mod_op = LDAP_MOD_ADD;
|
||||
- base.mod_type = "objectClass";
|
||||
- base.mod_values = topObjectClasses;
|
||||
- base_attrs[0] = &base;
|
||||
+ base.mod_type = (char*)"objectClass";
|
||||
+ base.mod_values = (char**)topObjectClasses;
|
||||
+ base_attrs[0] = (void*)&base;
|
||||
base_attrs[1] = NULL;
|
||||
|
||||
if (ldapbase)
|
||||
@@ -337,7 +343,7 @@
|
||||
* I should probably rename this function, as not to cause any
|
||||
* confusion with the isc* routines. Will exit on error. */
|
||||
void
|
||||
-isc_result_check (isc_result_t res, char *errorstr)
|
||||
+isc_result_check (isc_result_t res, const char *errorstr)
|
||||
{
|
||||
if (res != ISC_R_SUCCESS)
|
||||
{
|
||||
@@ -449,7 +455,7 @@
|
||||
exit (-1);
|
||||
}
|
||||
|
||||
- for (i = 0; i < flags; i++)
|
||||
+ for (i = 0; i < (int)flags; i++)
|
||||
{
|
||||
tmp->attrs[i] = (LDAPMod *) malloc (sizeof (LDAPMod));
|
||||
if (tmp->attrs[i] == (LDAPMod *) NULL)
|
||||
@@ -459,13 +465,13 @@
|
||||
}
|
||||
}
|
||||
tmp->attrs[0]->mod_op = LDAP_MOD_ADD;
|
||||
- tmp->attrs[0]->mod_type = "objectClass";
|
||||
+ tmp->attrs[0]->mod_type = (char*)"objectClass";
|
||||
|
||||
if (flags == DNS_OBJECT)
|
||||
- tmp->attrs[0]->mod_values = objectClasses;
|
||||
+ tmp->attrs[0]->mod_values = (char**)objectClasses;
|
||||
else
|
||||
{
|
||||
- tmp->attrs[0]->mod_values = topObjectClasses;
|
||||
+ tmp->attrs[0]->mod_values = (char**)topObjectClasses;
|
||||
tmp->attrs[1] = NULL;
|
||||
tmp->attrcnt = 2;
|
||||
tmp->next = ldap_info_base;
|
||||
@@ -474,7 +480,7 @@
|
||||
}
|
||||
|
||||
tmp->attrs[1]->mod_op = LDAP_MOD_ADD;
|
||||
- tmp->attrs[1]->mod_type = "relativeDomainName";
|
||||
+ tmp->attrs[1]->mod_type = (char*)"relativeDomainName";
|
||||
tmp->attrs[1]->mod_values = (char **) calloc (sizeof (char *), 2);
|
||||
|
||||
if (tmp->attrs[1]->mod_values == (char **)NULL)
|
||||
@@ -496,7 +502,7 @@
|
||||
tmp->attrs[2]->mod_values[1] = NULL;
|
||||
|
||||
tmp->attrs[3]->mod_op = LDAP_MOD_ADD;
|
||||
- tmp->attrs[3]->mod_type = "dNSTTL";
|
||||
+ tmp->attrs[3]->mod_type = (char*)"dNSTTL";
|
||||
tmp->attrs[3]->mod_values = (char **) calloc (sizeof (char *), 2);
|
||||
|
||||
if (tmp->attrs[3]->mod_values == (char **)NULL)
|
||||
@@ -507,7 +513,7 @@
|
||||
tmp->attrs[3]->mod_values[1] = NULL;
|
||||
|
||||
tmp->attrs[4]->mod_op = LDAP_MOD_ADD;
|
||||
- tmp->attrs[4]->mod_type = "zoneName";
|
||||
+ tmp->attrs[4]->mod_type = (char*)"zoneName";
|
||||
tmp->attrs[4]->mod_values = (char **)calloc(sizeof(char *), 2);
|
||||
tmp->attrs[4]->mod_values[0] = gbl_zone;
|
||||
tmp->attrs[4]->mod_values[1] = NULL;
|
||||
@@ -607,7 +613,7 @@
|
||||
zname = ++tmp;
|
||||
}
|
||||
else
|
||||
- hnamebuff = "@";
|
||||
+ hnamebuff = (char*)"@";
|
||||
}
|
||||
else
|
||||
{
|
||||
@@ -686,12 +692,12 @@
|
||||
}
|
||||
|
||||
result = ldap_simple_bind_s (conn, binddn, bindpw);
|
||||
- ldap_result_check ("ldap_simple_bind_s", "LDAP Bind", result);
|
||||
+ ldap_result_check ("ldap_simple_bind_s", (char*)"LDAP Bind", result);
|
||||
}
|
||||
|
||||
/* Like isc_result_check, only for LDAP */
|
||||
void
|
||||
-ldap_result_check (char *msg, char *dn, int err)
|
||||
+ldap_result_check (const char *msg, char *dn, int err)
|
||||
{
|
||||
if ((err != LDAP_SUCCESS) && (err != LDAP_ALREADY_EXISTS))
|
||||
{
|
||||
@@ -730,5 +736,8 @@
|
||||
usage ()
|
||||
{
|
||||
fprintf (stderr,
|
||||
- "zone2ldap -D [BIND DN] -w [BIND PASSWORD] -b [BASE DN] -z [ZONE] -f [ZONE FILE] -h [LDAP HOST]
|
||||
- [-c Create LDAP Base structure][-d Debug Output (lots !)] \n ");}
|
||||
+ "zone2ldap -D [BIND DN] -w [BIND PASSWORD] -b [BASE DN] -z [ZONE] -f [ZONE FILE] -h [LDAP HOST]\n"
|
||||
+ "\t[-c Create LDAP Base structure][-d Debug Output (lots !)]\n "
|
||||
+ );
|
||||
+}
|
||||
+
|
||||
--- bind-9.3.2b2/contrib/sdb/bdb/bdb.c.sdbsrc 2002-07-02 00:45:34.000000000 -0400
|
||||
+++ bind-9.3.2b2/contrib/sdb/bdb/bdb.c 2005-11-15 12:57:44.000000000 -0500
|
||||
@@ -43,7 +43,7 @@
|
||||
#include <dns/lib.h>
|
||||
#include <dns/ttl.h>
|
||||
|
||||
-#include <named/bdb.h>
|
||||
+#include "bdb.h"
|
||||
#include <named/globals.h>
|
||||
#include <named/config.h>
|
||||
|
||||
--- bind-9.3.2b2/contrib/sdb/pgsql/pgsqldb.c.sdbsrc 2004-03-08 04:04:22.000000000 -0500
|
||||
+++ bind-9.3.2b2/contrib/sdb/pgsql/pgsqldb.c 2005-11-15 12:57:44.000000000 -0500
|
||||
@@ -23,7 +23,7 @@
|
||||
#include <string.h>
|
||||
#include <stdlib.h>
|
||||
|
||||
-#include <pgsql/libpq-fe.h>
|
||||
+#include <libpq-fe.h>
|
||||
|
||||
#include <isc/mem.h>
|
||||
#include <isc/print.h>
|
||||
--- bind-9.3.2b2/contrib/sdb/pgsql/zonetodb.c.sdbsrc 2005-09-05 22:12:40.000000000 -0400
|
||||
+++ bind-9.3.2b2/contrib/sdb/pgsql/zonetodb.c 2005-11-15 12:58:12.000000000 -0500
|
||||
@@ -37,7 +37,7 @@
|
||||
#include <dns/rdatatype.h>
|
||||
#include <dns/result.h>
|
||||
|
||||
-#include <pgsql/libpq-fe.h>
|
||||
+#include <libpq-fe.h>
|
||||
|
||||
/*
|
||||
* Generate a PostgreSQL table from a zone.
|
||||
@@ -54,6 +54,9 @@
|
||||
char str[10240];
|
||||
|
||||
void
|
||||
+closeandexit(int status);
|
||||
+
|
||||
+void
|
||||
closeandexit(int status) {
|
||||
if (conn != NULL)
|
||||
PQfinish(conn);
|
||||
@@ -61,6 +64,9 @@
|
||||
}
|
||||
|
||||
void
|
||||
+check_result(isc_result_t result, const char *message);
|
||||
+
|
||||
+void
|
||||
check_result(isc_result_t result, const char *message) {
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
fprintf(stderr, "%s: %s\n", message,
|
||||
@@ -84,7 +90,8 @@
|
||||
}
|
||||
*dest++ = 0;
|
||||
}
|
||||
-
|
||||
+void
|
||||
+addrdata(dns_name_t *name, dns_ttl_t ttl, dns_rdata_t *rdata);
|
||||
void
|
||||
addrdata(dns_name_t *name, dns_ttl_t ttl, dns_rdata_t *rdata) {
|
||||
unsigned char namearray[DNS_NAME_MAXTEXT + 1];
|
||||
@@ -165,7 +172,7 @@
|
||||
check_result(result, "isc_mem_create");
|
||||
|
||||
result = isc_entropy_create(mctx, &ectx);
|
||||
- result_check (result, "isc_entropy_create");
|
||||
+ check_result (result, "isc_entropy_create");
|
||||
|
||||
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
|
||||
check_result (result, "isc_hash_create");
|
||||
28
bind-9.5-PIE.patch
Normal file
28
bind-9.5-PIE.patch
Normal file
|
|
@ -0,0 +1,28 @@
|
|||
From 13348a5fc64387bf53ef450688e181100d0ceddb Mon Sep 17 00:00:00 2001
|
||||
From: Petr Mensik <pemensik@redhat.com>
|
||||
Date: Thu, 12 Dec 2024 15:56:13 +0100
|
||||
Subject: [PATCH] Harden named service build flags
|
||||
|
||||
---
|
||||
bin/named/Makefile.am | 5 ++++-
|
||||
1 file changed, 4 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/bin/named/Makefile.am b/bin/named/Makefile.am
|
||||
index 57a023b..b832e9c 100644
|
||||
--- a/bin/named/Makefile.am
|
||||
+++ b/bin/named/Makefile.am
|
||||
@@ -33,7 +33,10 @@ endif HAVE_LIBXML2
|
||||
|
||||
AM_CPPFLAGS += \
|
||||
-DNAMED_LOCALSTATEDIR=\"${localstatedir}\" \
|
||||
- -DNAMED_SYSCONFDIR=\"${sysconfdir}\"
|
||||
+ -DNAMED_SYSCONFDIR=\"${sysconfdir}\" \
|
||||
+ -fpie
|
||||
+
|
||||
+AM_LDFLAGS += -pie -Wl,-z,relro,-z,now,-z,nodlopen,-z,noexecstack
|
||||
|
||||
sbin_PROGRAMS = named
|
||||
|
||||
--
|
||||
2.47.1
|
||||
|
||||
|
|
@ -1,11 +0,0 @@
|
|||
--- bind-9.2.2/lib/isc/unix/socket.c.bsdcompat 2003-02-18 02:28:41.000000000 -0500
|
||||
+++ bind-9.2.2/lib/isc/unix/socket.c 2003-07-19 15:40:49.784907968 -0400
|
||||
@@ -1365,7 +1365,7 @@ isc_socket_create(isc_socketmgr_t *manag
|
||||
return (ISC_R_UNEXPECTED);
|
||||
}
|
||||
|
||||
-#ifdef SO_BSDCOMPAT
|
||||
+#if 0
|
||||
if (setsockopt(sock->fd, SOL_SOCKET, SO_BSDCOMPAT,
|
||||
(void *)&on, sizeof on) < 0) {
|
||||
isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||
|
|
@ -1,252 +0,0 @@
|
|||
#!/bin/bash
|
||||
#
|
||||
# Script to control the bind-chroot ISC BIND named(8) server runtime environment.
|
||||
#
|
||||
# Usage:
|
||||
# [ -e | --enable ] [ -d | --disable ] | [ -s --sync ]
|
||||
#
|
||||
# -e | --enable: enable the bind-chroot environment
|
||||
# -d | --disable: disable the bind-chroot environment
|
||||
# -s | --sync: sync files between the bind chroot and / environments,
|
||||
# so they are correct for the current state of the bind-chroot
|
||||
# (enabled / disabled)
|
||||
# $BIND_CHROOT_PREFIX, default /var/named/chroot, is the location of the chroot.
|
||||
# $BIND_DIR, default /var/named, is the default un-chrooted bind directory.
|
||||
#
|
||||
# Copyright(C) 2006 Jason Vas Dias <jvdias@redhat.com>, Red Hat, Inc.
|
||||
#
|
||||
# This software is provided under the terms of the GNU
|
||||
# General Public License (GPL), as published at:
|
||||
# http://www.gnu.org/licenses/gpl.html .
|
||||
#
|
||||
#
|
||||
BIND_CHROOT_PREFIX=${BIND_CHROOT_PREFIX:-@BIND_CHROOT_PREFIX@}
|
||||
BIND_DIR=${BIND_DIR:-@BIND_DIR@}
|
||||
|
||||
function usage()
|
||||
{
|
||||
echo 'Usage:
|
||||
-e | --enable: enable the bind-chroot environment
|
||||
-d | --disable: disable the bind-chroot environment
|
||||
-s | --sync: sync files between the bind chroot and / environments,
|
||||
so they are correct for the current state of the bind-chroot
|
||||
(enabled / disabled)
|
||||
$BIND_CHROOT_PREFIX, default /var/named/chroot, is the location of the chroot.
|
||||
$BIND_DIR, default /var/named, is the default un-chrooted bind directory.
|
||||
';
|
||||
}
|
||||
|
||||
function rootdir()
|
||||
{
|
||||
. /etc/sysconfig/named
|
||||
if [ -n "$ROOTDIR" ]; then
|
||||
BIND_CHROOT_PREFIX="$ROOTDIR";
|
||||
BIND_CHROOT_PREFIX=`echo $BIND_CHROOT_PREFIX | sed 's#//*#/#g;s#/$##'`;
|
||||
if [ -L "$BIND_CHROOT_PREFIX" ]; then
|
||||
BIND_CHROOT_PREFIX=`/usr/bin/readlink "$BIND_CHROOT_PREFIX"`;
|
||||
fi
|
||||
return 0;
|
||||
fi;
|
||||
return 1;
|
||||
}
|
||||
|
||||
function check_dirs()
|
||||
{
|
||||
if [ -z "$BIND_CHROOT_PREFIX" ]; then
|
||||
rootdir;
|
||||
if [ -z "$BIND_CHROOT_PREFIX" ]; then
|
||||
usage;
|
||||
exit 1;
|
||||
fi;
|
||||
fi
|
||||
BIND_DIR=`echo $BIND_DIR | sed 's#//*#/#g;s#/$##'`;
|
||||
if [ -L "$BIND_DIR" ]; then
|
||||
BIND_DIR=`/usr/bin/readlink "$BIND_DIR"`;
|
||||
fi
|
||||
BIND_CHROOT_PREFIX=`echo $BIND_CHROOT_PREFIX | sed 's#//*#/#g;s#/$##'`;
|
||||
if [ -L "$BIND_CHROOT_PREFIX" ]; then
|
||||
BIND_CHROOT_PREFIX=`/usr/bin/readlink "$BIND_CHROOT_PREFIX"`;
|
||||
fi
|
||||
|
||||
/bin/mkdir -p ${BIND_DIR}/{slaves,data};
|
||||
/bin/chown root:named ${BIND_DIR};
|
||||
/bin/chown named:named ${BIND_DIR}/{slaves,data};
|
||||
/bin/chmod 750 ${BIND_DIR}
|
||||
/bin/chmod 770 ${BIND_DIR}/{slaves,data};
|
||||
|
||||
mkdir -p ${BIND_CHROOT_PREFIX}/{etc,dev,var/{run/named,named/{slaves,data}}};
|
||||
/bin/chown root:named ${BIND_CHROOT_PREFIX}/{etc,dev,var/{run,named/}};
|
||||
/bin/chmod 750 ${BIND_CHROOT_PREFIX}/{,etc,dev,var,var/{run,named/}};
|
||||
/bin/chown named:named ${BIND_CHROOT_PREFIX}/var/{run/named,named/{data,slaves}};
|
||||
/bin/chmod 770 ${BIND_CHROOT_PREFIX}/var/{run/named,named/{slaves,data}};
|
||||
|
||||
[ ! -e "${BIND_CHROOT_PREFIX}/dev/random" ] && /bin/mknod "${BIND_CHROOT_PREFIX}/dev/random" c 1 8
|
||||
[ ! -e "${BIND_CHROOT_PREFIX}/dev/zero" ] && /bin/mknod "${BIND_CHROOT_PREFIX}/dev/zero" c 1 5
|
||||
[ ! -e "${BIND_CHROOT_PREFIX}/dev/null" ] && /bin/mknod "${BIND_CHROOT_PREFIX}/dev/null" c 1 3
|
||||
[ ! -e "${BIND_CHROOT_PREFIX}/etc/localtime" ] && [ -e /etc/localtime ] && /bin/cp -fp /etc/localtime "${BIND_CHROOT_PREFIX}/etc/localtime";
|
||||
chmod 666 "${BIND_CHROOT_PREFIX}"/dev/{random,null,zero};
|
||||
if [ -d /selinux ] && [ -e /selinux/enforce ] && [ -x /usr/bin/chcon ]; then
|
||||
for dev in random zero null; do
|
||||
/usr/bin/chcon --reference=/dev/$dev ${BIND_CHROOT_PREFIX}/dev/$dev;
|
||||
done
|
||||
fi;
|
||||
}
|
||||
|
||||
check_dirs;
|
||||
|
||||
function replace_with_link()
|
||||
{ # replaces $dst second arg file with link to $src first arg file
|
||||
if [ $# -lt 2 ]; then
|
||||
return 1;
|
||||
fi;
|
||||
src=$1
|
||||
dst=$2
|
||||
if [ -z "$src" ] || [ -z "$dst" ] || [ "$src" = "$dst" ]; then
|
||||
return 1;
|
||||
fi
|
||||
if [ ! -e "$src" ]; then
|
||||
if [ ! -e "$dst" ]; then
|
||||
return 1;
|
||||
else
|
||||
if [ -L "$dst" ]; then
|
||||
dstlnk=`/usr/bin/readlink "$dst"`;
|
||||
if [ ! -e "$dstlnk" ] ; then
|
||||
return 1;
|
||||
fi
|
||||
rm -f "$dst";
|
||||
/bin/cp -fp "$dstlnk" "$dst";
|
||||
fi;
|
||||
/bin/mv "$dst" "$src";
|
||||
fi
|
||||
fi
|
||||
if [ -e "$dst" ]; then
|
||||
if [ ! -L "$dst" ]; then
|
||||
if [ ! -s "$dst" ]; then
|
||||
/bin/rm -f "$dst";
|
||||
else
|
||||
if [ "$src" -nt "$dst" ] || [ ! "$dst" -nt "$src" ] ; then
|
||||
/bin/mv "$dst" "$dst".`/bin/date +'%Y-%m-%d_%H-%M-%S.%N'`;
|
||||
else # [ "$dst" -nt "$src" ]
|
||||
/bin/mv "$src" "$src".`/bin/date +'%Y-%m-%d_%H-%M-%S.%N'`;
|
||||
/bin/mv "$dst" "$src";
|
||||
fi;
|
||||
fi;
|
||||
else
|
||||
dstlnk=`/usr/bin/readlink "$dst"`
|
||||
if [ "$dstlnk" != $src ]; then
|
||||
/bin/rm -f $dst;
|
||||
if [ "$dstlnk" != "$dst" ] && [ -s $dstlnk ]; then
|
||||
if [ "$dstlnk" -nt "$src" ] || [ ! "$dstlnk" -nt "$src" ] ; then
|
||||
/bin/cp -fp "$dstlnk" "$dst".`/bin/date +'%Y-%m-%d_%H-%M-%S.%N'`;
|
||||
else
|
||||
/bin/mv "$src" "$src".`/bin/date +'%Y-%m-%d_%H-%M-%S.%N'`;
|
||||
/bin/cp -fp "$dstlnk" "$src";
|
||||
fi;
|
||||
fi;
|
||||
else
|
||||
return 0;
|
||||
fi;
|
||||
fi;
|
||||
fi;
|
||||
/bin/ln -sf "$src" "$dst";
|
||||
return $?;
|
||||
}
|
||||
|
||||
function replace_with_file()
|
||||
{
|
||||
if [ $# -lt 2 ]; then
|
||||
return 1;
|
||||
fi;
|
||||
src=$1;
|
||||
dst=$2;
|
||||
if [ -z "$src" ] || [ -z "$dst" ] || [ "$src" = "$dst" ]; then
|
||||
return 1;
|
||||
fi
|
||||
if [ ! -e "$src" ]; then
|
||||
if [ -e "$dst" ]; then
|
||||
/bin/rm -f $dst;
|
||||
fi;
|
||||
return 1;
|
||||
fi;
|
||||
if [ -e "$dst" ]; then
|
||||
if [ ! -L "$dst" ]; then
|
||||
/bin/mv "$dst" "$dst".`/bin/date +'%Y-%m-%d_%H-%M-%S.%N'`;
|
||||
else
|
||||
/bin/rm -f "$dst";
|
||||
fi;
|
||||
fi;
|
||||
/bin/mv -f "$src" "$dst";
|
||||
}
|
||||
|
||||
function enable_bind_chroot()
|
||||
{
|
||||
if /bin/egrep -q '^ROOTDIR=' /etc/sysconfig/named; then
|
||||
/bin/sed -i -e 's#^ROOTDIR=.*$#ROOTDIR='${BIND_CHROOT_PREFIX}'#' /etc/sysconfig/named ;
|
||||
else
|
||||
echo 'ROOTDIR='${BIND_CHROOT_PREFIX} >> /etc/sysconfig/named;
|
||||
fi
|
||||
}
|
||||
|
||||
function disable_bind_chroot()
|
||||
{
|
||||
/bin/sed -i -e '/^ROOTDIR=/d' /etc/sysconfig/named;
|
||||
}
|
||||
|
||||
function sync_files()
|
||||
{
|
||||
shopt -q nullglob;
|
||||
ng=$?
|
||||
shopt -s nullglob;
|
||||
pfx=''
|
||||
if rootdir ; then # chroot is enabled
|
||||
/usr/bin/find /{etc/{named.*,rndc.*},${BIND_DIR#/}{/*,/data/*,/slaves/*}} -maxdepth 0 -type f |
|
||||
while read f;
|
||||
do
|
||||
replace_with_link ${BIND_CHROOT_PREFIX}/$f $f;
|
||||
done;
|
||||
pfx=${BIND_CHROOT_PREFIX}
|
||||
else # chroot is disabled
|
||||
/usr/bin/find /var/named/chroot/{etc/{named.*,rndc.*},var/named{/*,/data/*,/slaves/*}} -maxdepth 0 |
|
||||
while read f;
|
||||
do
|
||||
if [ ! -d "$f" ]; then
|
||||
replace_with_file $f ${f#$BIND_CHROOT_PREFIX};
|
||||
fi;
|
||||
done
|
||||
fi;
|
||||
if [ $ng -eq 1 ]; then
|
||||
shopt -u nullglob;
|
||||
fi;
|
||||
chown root:named ${pfx}/var/named/* >/dev/null 2>&1;
|
||||
chmod 750 ${pfx}/var/named >/dev/null 2>&1;
|
||||
chmod 640 ${pfx}/var/named/* >/dev/null 2>&1;
|
||||
chown named:named ${pfx}/var/named/{data{,/*},slaves{,*/}} >/dev/null 2>&1;
|
||||
chmod 770 ${pfx}/var/named/{data,slaves} >/dev/null 2>&1;
|
||||
chmod 640 ${pfx}/var/named/{data/*,slaves/*} >/dev/null 2>&1;
|
||||
}
|
||||
|
||||
case $1 in
|
||||
-e|--enable)
|
||||
enable_bind_chroot;
|
||||
sync_files;
|
||||
/sbin/service named condrestart
|
||||
exit $?;
|
||||
;;
|
||||
-d|--disable)
|
||||
disable_bind_chroot;
|
||||
sync_files;
|
||||
/sbin/service named condrestart
|
||||
/bin/umount ${BIND_CHROOT_PREFIX}/proc >/dev/null 2>&1 || :;
|
||||
/bin/umount ${BIND_CHROOT_PREFIX}/var/run/dbus >/dev/null 2>&1 || :;
|
||||
exit $?;
|
||||
;;
|
||||
-s|--sync)
|
||||
sync_files;
|
||||
exit $?;
|
||||
;;
|
||||
-q)
|
||||
;;
|
||||
*)
|
||||
usage;
|
||||
exit 1;
|
||||
esac
|
||||
38
bind-chroot.tmpfiles.d
Normal file
38
bind-chroot.tmpfiles.d
Normal file
|
|
@ -0,0 +1,38 @@
|
|||
# vim: ft=conf:
|
||||
# TODO: these definitions are in different form in rpm spec %files chroot section
|
||||
# find a way to have it defined only once
|
||||
#defattr(0664,root,named,-)
|
||||
c /var/named/chroot/dev/null 0664 root named - 1:3
|
||||
c /var/named/chroot/dev/random 0664 root named - 1:8
|
||||
c /var/named/chroot/dev/urandom 0664 root named - 1:9
|
||||
c /var/named/chroot/dev/zero 0664 root named - 1:5
|
||||
#defattr(0640,root,named,0750)
|
||||
d /var/named/chroot 0750 root named -
|
||||
d /var/named/chroot/dev 0750 root named -
|
||||
d /var/named/chroot/etc 0750 root named -
|
||||
d /var/named/chroot/etc/named 0750 root named -
|
||||
d /var/named/chroot/etc/pki 0750 root named -
|
||||
d /var/named/chroot/etc/pki/dnssec-keys 0750 root named -
|
||||
d /var/named/chroot/etc/crypto-policies 0750 root named -
|
||||
d /var/named/chroot/etc/crypto-policies/back-ends 0750 root named -
|
||||
d /var/named/chroot/var 0750 root named -
|
||||
d /var/named/chroot/run 0750 root named -
|
||||
#defattr(-,root,root,-)
|
||||
d /var/named/chroot/usr - root root -
|
||||
d /var/named/chroot/usr/lib64 - root root -
|
||||
d /var/named/chroot/usr/lib64/bind - root root -
|
||||
d /var/named/chroot/usr/lib64/named - root root -
|
||||
d /var/named/chroot/usr/share/GeoIP - root root -
|
||||
d /var/named/chroot/usr/share/named - root root -
|
||||
d /var/named/chroot/proc - root root -
|
||||
d /var/named/chroot/proc/sys - root root -
|
||||
d /var/named/chroot/proc/sys/net - root root -
|
||||
d /var/named/chroot/proc/sys/net/ipv4 - root root -
|
||||
#defattr(0660,root,named,01770)
|
||||
d /var/named/chroot/var/named 01770 root named -
|
||||
#defattr(0660,named,named,0770)
|
||||
d /var/named/chroot/var/tmp 0770 named named -
|
||||
d /var/named/chroot/var/log 0770 named named -
|
||||
#defattr(-,named,named,-)
|
||||
d /var/named/chroot/run/named - named named -
|
||||
L /var/named/chroot/var/run - named named - ../run
|
||||
|
|
@ -1,66 +0,0 @@
|
|||
--- bind-9.2.4rc6/lib/bind/Makefile.in.nonexec 2004-03-09 04:17:23.000000000 -0500
|
||||
+++ bind-9.2.4rc6/lib/bind/Makefile.in 2004-07-16 19:23:30.000000000 -0400
|
||||
@@ -111,7 +111,7 @@
|
||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${libdir}
|
||||
|
||||
install:: timestamp installdirs
|
||||
- ${LIBTOOL_MODE_INSTALL} ${INSTALL_DATA} libbind.@A@ ${DESTDIR}${libdir}
|
||||
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} libbind.@A@ ${DESTDIR}${libdir}
|
||||
|
||||
clean distclean::
|
||||
rm -f libbind.@SA@ libbind.la
|
||||
--- bind-9.2.4rc6/lib/dns/Makefile.in.nonexec 2004-04-14 20:35:27.000000000 -0400
|
||||
+++ bind-9.2.4rc6/lib/dns/Makefile.in 2004-07-16 19:25:40.000000000 -0400
|
||||
@@ -136,7 +136,7 @@
|
||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${libdir}
|
||||
|
||||
install:: timestamp installdirs
|
||||
- ${LIBTOOL_MODE_INSTALL} ${INSTALL_DATA} libdns.@A@ ${DESTDIR}${libdir}
|
||||
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} libdns.@A@ ${DESTDIR}${libdir}
|
||||
|
||||
clean distclean::
|
||||
rm -f libdns.@A@ timestamp
|
||||
--- bind-9.2.4rc6/lib/isc/Makefile.in.nonexec 2004-03-09 01:11:44.000000000 -0500
|
||||
+++ bind-9.2.4rc6/lib/isc/Makefile.in 2004-07-16 19:24:46.000000000 -0400
|
||||
@@ -105,7 +105,7 @@
|
||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${libdir}
|
||||
|
||||
install:: timestamp installdirs
|
||||
- ${LIBTOOL_MODE_INSTALL} ${INSTALL_DATA} libisc.@A@ ${DESTDIR}${libdir}
|
||||
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} libisc.@A@ ${DESTDIR}${libdir}
|
||||
|
||||
clean distclean::
|
||||
rm -f libisc.@A@ libisc.la timestamp
|
||||
--- bind-9.2.4rc6/lib/isccc/Makefile.in.nonexec 2004-03-09 01:12:25.000000000 -0500
|
||||
+++ bind-9.2.4rc6/lib/isccc/Makefile.in 2004-07-16 19:26:40.000000000 -0400
|
||||
@@ -80,7 +80,7 @@
|
||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${libdir}
|
||||
|
||||
install:: timestamp installdirs
|
||||
- ${LIBTOOL_MODE_INSTALL} ${INSTALL_DATA} libisccc.@A@ ${DESTDIR}${libdir}
|
||||
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} libisccc.@A@ ${DESTDIR}${libdir}
|
||||
|
||||
clean distclean::
|
||||
rm -f libisccc.@A@ timestamp
|
||||
--- bind-9.2.4rc6/lib/isccfg/Makefile.in.nonexec 2004-03-09 01:12:30.000000000 -0500
|
||||
+++ bind-9.2.4rc6/lib/isccfg/Makefile.in 2004-07-16 19:27:22.000000000 -0400
|
||||
@@ -77,7 +77,7 @@
|
||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${libdir}
|
||||
|
||||
install:: timestamp installdirs
|
||||
- ${LIBTOOL_MODE_INSTALL} ${INSTALL_DATA} libisccfg.@A@ ${DESTDIR}${libdir}
|
||||
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} libisccfg.@A@ ${DESTDIR}${libdir}
|
||||
|
||||
clean distclean::
|
||||
rm -f libisccfg.@A@ timestamp
|
||||
--- bind-9.2.4rc6/lib/lwres/Makefile.in.nonexec 2004-03-09 01:12:32.000000000 -0500
|
||||
+++ bind-9.2.4rc6/lib/lwres/Makefile.in 2004-07-16 19:28:19.000000000 -0400
|
||||
@@ -76,7 +76,7 @@
|
||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${libdir}
|
||||
|
||||
install:: timestamp installdirs
|
||||
- ${LIBTOOL_MODE_INSTALL} ${INSTALL_DATA} liblwres.@A@ ${DESTDIR}${libdir}
|
||||
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} liblwres.@A@ ${DESTDIR}${libdir}
|
||||
|
||||
clean distclean::
|
||||
rm -f liblwres.@A@ liblwres.la timestamp
|
||||
10
bind.tmpfiles.d
Normal file
10
bind.tmpfiles.d
Normal file
|
|
@ -0,0 +1,10 @@
|
|||
# vim: ft=conf:
|
||||
d /run/named 0755 named named -
|
||||
d /var/named 01770 root named -
|
||||
d /var/named/slaves 0770 named named -
|
||||
d /var/named/data 0770 named named -
|
||||
d /var/named/dynamic 0770 named named -
|
||||
L /var/named/named.ca 0640 named named - ../../../etc/named.ca
|
||||
L /var/named/named.localhost 0640 named named - ../../../usr/share/named/named.localhost
|
||||
L /var/named/named.loopback 0640 named named - ../../../usr/share/named/named.loopback
|
||||
L /var/named/named.empty 0640 named named - ../../../usr/share/named/named.empty
|
||||
226
bind97-exportlib.patch
Normal file
226
bind97-exportlib.patch
Normal file
|
|
@ -0,0 +1,226 @@
|
|||
diff -up bind-9.9.3rc2/isc-config.sh.in.exportlib bind-9.9.3rc2/isc-config.sh.in
|
||||
diff -up bind-9.9.3rc2/lib/export/dns/Makefile.in.exportlib bind-9.9.3rc2/lib/export/dns/Makefile.in
|
||||
--- bind-9.9.3rc2/lib/export/dns/Makefile.in.exportlib 2013-04-30 08:38:46.000000000 +0200
|
||||
+++ bind-9.9.3rc2/lib/export/dns/Makefile.in 2013-05-13 10:45:22.574089729 +0200
|
||||
@@ -35,9 +35,9 @@ CDEFINES = -DUSE_MD5 @USE_OPENSSL@ @USE_
|
||||
|
||||
CWARNINGS =
|
||||
|
||||
-ISCLIBS = ../isc/libisc.@A@
|
||||
+ISCLIBS = ../isc/libisc-export.@A@
|
||||
|
||||
-ISCDEPLIBS = ../isc/libisc.@A@
|
||||
+ISCDEPLIBS = ../isc/libisc-export.@A@
|
||||
|
||||
LIBS = @LIBS@
|
||||
|
||||
@@ -116,29 +116,29 @@ version.@O@: ${srcdir}/version.c
|
||||
-DLIBAGE=${LIBAGE} \
|
||||
-c ${srcdir}/version.c
|
||||
|
||||
-libdns.@SA@: ${OBJS}
|
||||
+libdns-export.@SA@: ${OBJS}
|
||||
${AR} ${ARFLAGS} $@ ${OBJS}
|
||||
${RANLIB} $@
|
||||
|
||||
-libdns.la: ${OBJS}
|
||||
+libdns-export.la: ${OBJS}
|
||||
${LIBTOOL_MODE_LINK} \
|
||||
- ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libdns.la \
|
||||
+ ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libdns-export.la \
|
||||
-rpath ${export_libdir} \
|
||||
-version-info ${LIBINTERFACE}:${LIBREVISION}:${LIBAGE} \
|
||||
${OBJS} ${ISCLIBS} @DNS_CRYPTO_LIBS@ ${LIBS}
|
||||
|
||||
-timestamp: libdns.@A@
|
||||
+timestamp: libdns-export.@A@
|
||||
touch timestamp
|
||||
|
||||
installdirs:
|
||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${export_libdir}
|
||||
|
||||
install:: timestamp installdirs
|
||||
- ${LIBTOOL_MODE_INSTALL} ${INSTALL_DATA} libdns.@A@ \
|
||||
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} libdns-export.@A@ \
|
||||
${DESTDIR}${export_libdir}/
|
||||
|
||||
clean distclean::
|
||||
- rm -f libdns.@A@ timestamp
|
||||
+ rm -f libdns-export.@A@ timestamp
|
||||
rm -f gen code.h include/dns/enumtype.h include/dns/enumclass.h
|
||||
rm -f include/dns/rdatastruct.h
|
||||
|
||||
diff -up bind-9.9.3rc2/lib/export/irs/Makefile.in.exportlib bind-9.9.3rc2/lib/export/irs/Makefile.in
|
||||
--- bind-9.9.3rc2/lib/export/irs/Makefile.in.exportlib 2013-04-30 08:38:46.000000000 +0200
|
||||
+++ bind-9.9.3rc2/lib/export/irs/Makefile.in 2013-05-13 10:45:22.575089729 +0200
|
||||
@@ -43,9 +43,9 @@ SRCS = context.c \
|
||||
gai_sterror.c getaddrinfo.c getnameinfo.c \
|
||||
resconf.c
|
||||
|
||||
-ISCLIBS = ../isc/libisc.@A@
|
||||
-DNSLIBS = ../dns/libdns.@A@
|
||||
-ISCCFGLIBS = ../isccfg/libisccfg.@A@
|
||||
+ISCLIBS = ../isc/libisc-export.@A@
|
||||
+DNSLIBS = ../dns/libdns-export.@A@
|
||||
+ISCCFGLIBS = ../isccfg/libisccfg-export.@A@
|
||||
|
||||
LIBS = @LIBS@
|
||||
|
||||
@@ -62,26 +62,26 @@ version.@O@: ${srcdir}/version.c
|
||||
-DLIBAGE=${LIBAGE} \
|
||||
-c ${srcdir}/version.c
|
||||
|
||||
-libirs.@SA@: ${OBJS} version.@O@
|
||||
+libirs-export.@SA@: ${OBJS} version.@O@
|
||||
${AR} ${ARFLAGS} $@ ${OBJS} version.@O@
|
||||
${RANLIB} $@
|
||||
|
||||
-libirs.la: ${OBJS} version.@O@
|
||||
+libirs-export.la: ${OBJS} version.@O@
|
||||
${LIBTOOL_MODE_LINK} \
|
||||
- ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libirs.la \
|
||||
+ ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libirs-export.la \
|
||||
-rpath ${export_libdir} \
|
||||
-version-info ${LIBINTERFACE}:${LIBREVISION}:${LIBAGE} \
|
||||
${OBJS} version.@O@ ${LIBS} ${ISCCFGLIBS} ${DNSLIBS} ${ISCLIBS}
|
||||
|
||||
-timestamp: libirs.@A@
|
||||
+timestamp: libirs-export.@A@
|
||||
touch timestamp
|
||||
|
||||
installdirs:
|
||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${export_libdir}
|
||||
|
||||
install:: timestamp installdirs
|
||||
- ${LIBTOOL_MODE_INSTALL} ${INSTALL_DATA} libirs.@A@ \
|
||||
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} libirs-export.@A@ \
|
||||
${DESTDIR}${export_libdir}/
|
||||
|
||||
clean distclean::
|
||||
- rm -f libirs.@A@ libirs.la timestamp
|
||||
+ rm -f libirs-export.@A@ libirs-export.la timestamp
|
||||
diff -up bind-9.9.3rc2/lib/export/isccfg/Makefile.in.exportlib bind-9.9.3rc2/lib/export/isccfg/Makefile.in
|
||||
--- bind-9.9.3rc2/lib/export/isccfg/Makefile.in.exportlib 2013-04-30 08:38:46.000000000 +0200
|
||||
+++ bind-9.9.3rc2/lib/export/isccfg/Makefile.in 2013-05-13 10:45:22.576089729 +0200
|
||||
@@ -30,11 +30,11 @@ CINCLUDES = -I. ${DNS_INCLUDES} -I${expo
|
||||
CDEFINES =
|
||||
CWARNINGS =
|
||||
|
||||
-ISCLIBS = ../isc/libisc.@A@
|
||||
-DNSLIBS = ../dns/libdns.@A@ @DNS_CRYPTO_LIBS@
|
||||
+ISCLIBS = ../isc/libisc-export.@A@
|
||||
+DNSLIBS = ../dns/libdns-export.@A@ @DNS_CRYPTO_LIBS@
|
||||
|
||||
ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
||||
-ISCCFGDEPLIBS = libisccfg.@A@
|
||||
+ISCCFGDEPLIBS = libisccfg-export.@A@
|
||||
|
||||
LIBS = @LIBS@
|
||||
|
||||
@@ -58,26 +58,26 @@ version.@O@: ${srcdir}/version.c
|
||||
-DLIBAGE=${LIBAGE} \
|
||||
-c ${srcdir}/version.c
|
||||
|
||||
-libisccfg.@SA@: ${OBJS}
|
||||
+libisccfg-export.@SA@: ${OBJS}
|
||||
${AR} ${ARFLAGS} $@ ${OBJS}
|
||||
${RANLIB} $@
|
||||
|
||||
-libisccfg.la: ${OBJS}
|
||||
+libisccfg-export.la: ${OBJS}
|
||||
${LIBTOOL_MODE_LINK} \
|
||||
- ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libisccfg.la \
|
||||
+ ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libisccfg-export.la \
|
||||
-rpath ${export_libdir} \
|
||||
-version-info ${LIBINTERFACE}:${LIBREVISION}:${LIBAGE} \
|
||||
${OBJS} ${LIBS} ${DNSLIBS} ${ISCLIBS}
|
||||
|
||||
-timestamp: libisccfg.@A@
|
||||
+timestamp: libisccfg-export.@A@
|
||||
touch timestamp
|
||||
|
||||
installdirs:
|
||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${export_libdir}
|
||||
|
||||
install:: timestamp installdirs
|
||||
- ${LIBTOOL_MODE_INSTALL} ${INSTALL_DATA} libisccfg.@A@ \
|
||||
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} libisccfg-export.@A@ \
|
||||
${DESTDIR}${export_libdir}/
|
||||
|
||||
clean distclean::
|
||||
- rm -f libisccfg.@A@ timestamp
|
||||
+ rm -f libisccfg-export.@A@ timestamp
|
||||
diff -up bind-9.9.3rc2/lib/export/isc/Makefile.in.exportlib bind-9.9.3rc2/lib/export/isc/Makefile.in
|
||||
--- bind-9.9.3rc2/lib/export/isc/Makefile.in.exportlib 2013-04-30 08:38:46.000000000 +0200
|
||||
+++ bind-9.9.3rc2/lib/export/isc/Makefile.in 2013-05-13 10:45:22.576089729 +0200
|
||||
@@ -100,6 +100,10 @@ SRCS = @ISC_EXTRA_SRCS@ \
|
||||
|
||||
LIBS = @LIBS@
|
||||
|
||||
+# Note: the order of SUBDIRS is important.
|
||||
+# Attempt to disable parallel processing.
|
||||
+.NOTPARALLEL:
|
||||
+.NO_PARALLEL:
|
||||
SUBDIRS = include unix nls @ISC_THREAD_DIR@
|
||||
TARGETS = timestamp
|
||||
|
||||
@@ -113,26 +117,26 @@ version.@O@: ${srcdir}/version.c
|
||||
-DLIBAGE=${LIBAGE} \
|
||||
-c ${srcdir}/version.c
|
||||
|
||||
-libisc.@SA@: ${OBJS}
|
||||
+libisc-export.@SA@: ${OBJS}
|
||||
${AR} ${ARFLAGS} $@ ${OBJS}
|
||||
${RANLIB} $@
|
||||
|
||||
-libisc.la: ${OBJS}
|
||||
+libisc-export.la: ${OBJS}
|
||||
${LIBTOOL_MODE_LINK} \
|
||||
- ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libisc.la \
|
||||
+ ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libisc-export.la \
|
||||
-rpath ${export_libdir} \
|
||||
-version-info ${LIBINTERFACE}:${LIBREVISION}:${LIBAGE} \
|
||||
${OBJS} ${LIBS}
|
||||
|
||||
-timestamp: libisc.@A@
|
||||
+timestamp: libisc-export.@A@
|
||||
touch timestamp
|
||||
|
||||
installdirs:
|
||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${export_libdir}
|
||||
|
||||
install:: timestamp installdirs
|
||||
- ${LIBTOOL_MODE_INSTALL} ${INSTALL_DATA} libisc.@A@ \
|
||||
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} libisc-export.@A@ \
|
||||
${DESTDIR}${export_libdir}
|
||||
|
||||
clean distclean::
|
||||
- rm -f libisc.@A@ libisc.la timestamp
|
||||
+ rm -f libisc-export.@A@ libisc-export.la timestamp
|
||||
diff -up bind-9.9.3rc2/lib/export/samples/Makefile.in.exportlib bind-9.9.3rc2/lib/export/samples/Makefile.in
|
||||
--- bind-9.9.3rc2/lib/export/samples/Makefile.in.exportlib 2013-04-30 08:38:46.000000000 +0200
|
||||
+++ bind-9.9.3rc2/lib/export/samples/Makefile.in 2013-05-13 10:45:22.577089729 +0200
|
||||
@@ -31,15 +31,15 @@ CINCLUDES = -I${srcdir}/include -I../dns
|
||||
CDEFINES =
|
||||
CWARNINGS =
|
||||
|
||||
-DNSLIBS = ../dns/libdns.@A@ @DNS_CRYPTO_LIBS@
|
||||
-ISCLIBS = ../isc/libisc.@A@
|
||||
-ISCCFGLIBS = ../isccfg/libisccfg.@A@
|
||||
-IRSLIBS = ../irs/libirs.@A@
|
||||
+DNSLIBS = ../dns/libdns-export.@A@ @DNS_CRYPTO_LIBS@
|
||||
+ISCLIBS = ../isc/libisc-export.@A@
|
||||
+ISCCFGLIBS = ../isccfg/libisccfg-export.@A@
|
||||
+IRSLIBS = ../irs/libirs-export.@A@
|
||||
|
||||
-DNSDEPLIBS = ../dns/libdns.@A@
|
||||
-ISCDEPLIBS = ../isc/libisc.@A@
|
||||
-ISCCFGDEPLIBS = ../isccfg/libisccfg.@A@
|
||||
-IRSDEPLIBS = ../irs/libirs.@A@
|
||||
+DNSDEPLIBS = ../dns/libdns-export.@A@
|
||||
+ISCDEPLIBS = ../isc/libisc-export.@A@
|
||||
+ISCCFGDEPLIBS = ../isccfg/libisccfg-export.@A@
|
||||
+IRSDEPLIBS = ../irs/libirs-export.@A@
|
||||
|
||||
DEPLIBS = ${DNSDEPLIBS} ${ISCCFGDEPLIBS} ${ISCDEPLIBS}
|
||||
|
||||
1
ci.fmf
Normal file
1
ci.fmf
Normal file
|
|
@ -0,0 +1 @@
|
|||
resultsdb-testcase: separate
|
||||
252
codesign2019.txt
Normal file
252
codesign2019.txt
Normal file
|
|
@ -0,0 +1,252 @@
|
|||
-----BEGIN PGP PUBLIC KEY BLOCK-----
|
||||
Comment: GPGTools - http://gpgtools.org
|
||||
|
||||
mQINBFwq9BQBEADHjPDCwsHVtxnMNilgu187W8a9rYTMLgLfQwioSbjsF7dUJu8m
|
||||
r1w2stcsatRs7HBk/j26RNJagY2Jt0QufOQLlTePpTl6UPU8EeiJ8c15DNf45TMk
|
||||
pa/3MdIVpDnBioyD1JNqsI4z+yCYZ7p/TRVCyh5vCcwmt5pdKjKMTcu7aD2PtTtI
|
||||
yhTIetJavy1HQmgOl4/t/nKL7Lll2xtZ56JFUt7epo0h69fiUvPewkhykzoEf4UG
|
||||
ZFHSLZKqdMNPs/Jr9n7zS+iOgEXJnKDkp8SoXpAcgJ5fncROMXpxgY2U+G5rB9n0
|
||||
/hvV1zG+EP6OLIGqekiDUga84LdmR/8Cyc7DimUmaoIZXrAo0Alpt0aZ8GimdKmh
|
||||
qirIguJOSrrsZTeZLilCWu37fRIjCQ3dSMNyhHJaOhRJQpQOEDG7jHxFak7627aF
|
||||
UnVwBAOK3NlFfbomapXQm64lYNoONGrpV0ctueD3VoPipxIyzNHHgcsXDZ6C00sv
|
||||
SbuuS9jlFEDonA6S8tApKgkEJuToBuopM4xqqwHNJ4e6QoXYjERIgIBTco3r/76D
|
||||
o22ZxSK1m2m2i+p0gnWTlFn6RH+r6gfLwZRj8iR4fa0yMn3DztyTO6H8AiaslONt
|
||||
LV2kvkhBar1/6dzlBvMdiRBejrVnw+Jg2bOmYTncFN00szPOXbEalps8wwARAQAB
|
||||
tE1JbnRlcm5ldCBTeXN0ZW1zIENvbnNvcnRpdW0sIEluYy4gKFNpZ25pbmcga2V5
|
||||
LCAyMDE5LTIwMjApIDxjb2Rlc2lnbkBpc2Mub3JnPokCVAQTAQgAPhYhBK4/rHln
|
||||
EexZ/AB6pHS7a5pMuz04BQJcKvQUAhsDBQkD7JcABQsJCAcCBhUKCQgLAgQWAgMB
|
||||
Ah4BAheAAAoJEHS7a5pMuz0476oP/1+UaSHfe4WVHV43QaQ/z1rw7vg2aHEwyWJA
|
||||
1D1tBr9+LvfohswwWBLIjcKRaoXZ4pLBFjuiYHBTsdaAQFeQQvQTXMmBx21ZyUZj
|
||||
tjim8f9T1JhmIrMx6tF14NbqFpjw82Mv0rc8y74pdRvkdnFigqLKUoN2tFQlKeG+
|
||||
5T24zNwrGrlR3S7gnM47nD1JqKwt4GnczLnMBW/0gbLscMUpAeNo/gY4g0GV/zkn
|
||||
Rt91bLpcEyDAv+ZhQZbkJ49dnNzl5cTK5+uQWnlAZAdPecdLkvBNRNgj/FKL41RF
|
||||
JGN6eqq3+jlPbyj9okeJoGQ64Ibv1ZHVTQIx5vT1+PuVX/Nm0GqSUZdLqR33daKI
|
||||
hjpgUdUK/D0AnN5ulVuE1NnZWjVDTXVEeU8DFvi4lxZVHnZixejxFIZ7vRMvyaHa
|
||||
xLwbevwEUuPLzWn3XhC5yQeqCe6zmzzaPhPlg6NTnM5wgzcKORqCXgxzmtnX+Pbd
|
||||
gXTwNKAJId/141vj1OtZQKJexG9QLufMjBg5rg/qdKooozremeM+FovIocbdFnmX
|
||||
pzP8it8r8FKi7FpXRE3fwxwba4Y9AS2/owtuixlJ2+7M2OXwZEtxyXTXw2v5GFOP
|
||||
vN64G/b71l9c3yKVlQ3BXD0jErv9XcieeFDR9PK0XGlsxykPcIXZYVy2KSWptkSf
|
||||
6f2op3tMiQEzBBABCAAdFiEEFcm6uMUTPAcGawLtlumWUDlMmawFAlwuSqAACgkQ
|
||||
lumWUDlMmaz+igf/ZW8OY5aWjRk7QiXp93jkWRIbMi8kB9jW5u6tfYXFjMADpqiQ
|
||||
yYdzEHFayRF92PQwj81UzIWzOWjErFWLDE2xol9sP5LdzeqoyED+XTqKggpVsIs+
|
||||
Lq672qnumQoZKp1YGb8MDocU2DNg/VsMdi7kCnEnPbcSuBxksmxGYomusXNrAF94
|
||||
1OJ2sqd9BuFamLIyn8XUCGGYlsvMoe4kTCg6Cc1sQvx0lDG8urKN57jBKWbP4alV
|
||||
+JBV5KQcf74gzPmE3ypgY1tMEwxyH/WyS9ekDbai0qauX6eUAsM1bduH8fIcknLS
|
||||
Zl5hrJTrzWFF9/DKOth8QOwhJ9zoIF1fcAsx9okBMwQQAQgAHRYhBHpqR7X54SM6
|
||||
0lUrXL2X3GOe6MR7BQJcLktcAAoJEL2X3GOe6MR7jwEH/iaolMeno1oeWAgzN6Mg
|
||||
bx3maweh/9Vqty1fwk7Crq1G78X5i1OCkknEL2p0Bfle4ApwcC4HZVcqCgoYpRV3
|
||||
/EEXtwkMNy3plWdBbLCQSev/E1D39GzgAHiMnv7NUJnkoJbvMrvrAiUTXPTtARMM
|
||||
gjEpvgEs60wuJxS8ESomRhe/KW4myxDoBxF+K+e5bOkOvvWVcAYJHWZ1BIZs4n6b
|
||||
+C2vO8q5aKTkQ/XvNT7utbTOqj1SGhItRaAQKXHBdzkQ1Et3wTA4+uRg4gK12624
|
||||
9LperYs26w9X9UzApl+qVxQhtWUw3tnUXMastDfQrRcvJgq1xpv++OqX5Uc93RTf
|
||||
SNWJAjMEEAEIAB0WIQS+DpdItxglOii7if/xsRvwXPAuVwUCXC5LlQAKCRDxsRvw
|
||||
XPAuV29KEACEwlTVVKe4gnBYHnlAD7csoQ0+gJ6C+Ofzlw+UItRIcFeVCAknSGBs
|
||||
NPxr9JStIvKpmsbSKpCNUEAYnRP2immh94y/C6BuTe1uUUmqBGr1f4OAUwZpmI29
|
||||
ixYeY/uUs9FZO3bS0/WtG46tdcJK41qtM0DYAGT3oeZhJMTW15dfvMGlFukauSOU
|
||||
+BbR+6sZhqdbWl/AOTE/6x5otnAaW0GObY/BW240Xq/KTgBrzVdK5qNoYsMVsiTd
|
||||
0im0JKvFG08ED+ZfcILhlO6G9jRhoTkhtYuf8CKN1dPf2IoB5FrRFf0xqRr9hNlk
|
||||
X7ViNMP9OPb8i3BubWvRi5rNSquCwrFATSiAgaA9Yi1BNzQsmQxOql9lsh7eCH7m
|
||||
+8zzUg9umWI6PkSv8vHBo2kPX73wmtEsF6vxJlk0yDBuQw7y0uuKh406tEEk4cP2
|
||||
8U4baq+ihpioupDhNuEII1h1Eh/RBE408RAOpcr+2F0m/fKOoJyz7u+AxyV81Ia6
|
||||
fyBnUfZnlfKo16w87c1HJRs9dKkRa5yGziBf9TcED3sru58Pftes2Nr80/iOh26i
|
||||
P2pRihcIyrmeAqDWnneErVCmPMDTe6zkMrm/0iZ25/Jfq+M8IHEzFEw3Y1FBOeFg
|
||||
9TyMDwYG2biJPTNTDO0BQ+Rrvs4SjFWEYSxgJSvG1jMfSPt5AR6MJrkCDQRcKvQU
|
||||
ARAAufZX5WzJr0lZAhxaGpHY6JMBr4jVOCP4TrDZhwC2K4CXNM/PLLNisWzquiWa
|
||||
FvUDhB89kCxrEhipwVFYhBr16CDQxrr8yhah3RIxrBMYhRTxgIAkANgkhGWfDJSE
|
||||
zXauA7krYtS3rYwhfXe4cNsTkLPbnMUlyLJcqj2wnZcZIt97aL+NFRPyfIw1KfUb
|
||||
9u3tB9seDYbvTEULeL07aTnHpWM5f3bTwJrJ2OFPzXseCCzPiVNh3Bv+YtJ1pMTr
|
||||
c/UHO5DoJuHLsF0wicPSrpD0twspFdR/0rT6eNycsaCtV4GQzBcMPvY7qai5XrZm
|
||||
Cqgluo1W6l6+F5YrKvRMtyyFkUNGcPywdjSlP44JyRrS2uzvFUViSsJArcmFG2TJ
|
||||
LCohnse8wqjw0dIUVbmDbE4zjaG56zkvu0k+04Wwp3XPgOZrbl6cbhX3yLhu/Gt0
|
||||
dzd9EReoNfKXk32hBzKas/vdeB5DZejbOOOWYftqyZC1LvDvvrYFhFK6VGozfZ6L
|
||||
Fml1hzn+xPahp5tRv93/T9zXeVPm9zilGMqm/gjRgh8ojWxNQoNzJyqTPWIvWmbu
|
||||
EIP3T3cTFq6lJpJsg3+sfzofGWZCGnBZQGqm8rEOoUWiaKe1BvQCX1x8p4/x8/tX
|
||||
TaVDpQCGoqxXt09plkDuGMuiDICxBlaHWUR2jLoHc2cLrB8AEQEAAYkCPAQYAQgA
|
||||
JhYhBK4/rHlnEexZ/AB6pHS7a5pMuz04BQJcKvQUAhsMBQkD7JcAAAoJEHS7a5pM
|
||||
uz04pB8P/Amfg54IFeALiPOrKbjC3bVAQzrsf09IL8sUln/LCZIx9HgGAJj/f35S
|
||||
Q35sK2ucjWiDX6qCxVrWmC6caQXFgXOFSKIlqladmmgj4sIdLM5wj4nbomHChpB5
|
||||
rqV/GgkFwWBQ3kPCatXvc8Bg+zKJ+wXgTuPFXefyE9R+SLuas2grQ9hAjvTGHYbq
|
||||
iYxSlNDFc1aHLAQ3bS76351MHuMHOpLzoB0OkZDCVNW4GNEqrLbINdr50RAK+Loo
|
||||
Z2UBIobEZjXYor9A2FWkSvdjyz6X1QKMdQMath6R91k/O0abBa7ly4/805eAGXM3
|
||||
w1Xf2eMlpiUs69BeYoJBklK8aNMntpDREunJjhiPU4JoDzSxl5Qv7LuXylyo0YJA
|
||||
9YmydKhTTcRdwsKc//nGr/ckg4BRl+VbtJBYvd3xGB7IQ+pT/TOakv9qCospAhr3
|
||||
EQjVP/XpnWJRd+x+dq8UXqwWmTenWDE42cNr7BDFJdOqS5ZWy4sIz4sdjpSxXMB9
|
||||
8iiRtKSpKRCJgXScB7SYebh835EgG2YyQGdhJMO7C6ok9POYQBqL8sBqRzImJKoT
|
||||
VDvOH42WArKwJWTHa4mPdiDHEIZlkONerec3JXtl4Mfv8cwZ5Lb8fSiB/x8AWvqs
|
||||
puc/7hQtkus4TcgutS1fwhAwpnFItpVF6+73CMQrJsblBdTjW0T+uQINBFxbVHwB
|
||||
EADebZOJbhPdhHeBPdlZYE3rRjB8scDpWdjrCupfmeTC9MM6JgCE4DEMBtBXk+h1
|
||||
+7wfpblYYNFwGVFvytG5nvGRDtHWxwd1Z9O8Fx4Zqu0Fx/wAn7ZL3ryE+tdHR7JK
|
||||
7SLxOa2X49T/8LY0U8Q65I4ZRo/b4VMcXApCmncw3QSRqHT/mYdNnf+HHPvi3jza
|
||||
md3iVptCS4Iaisc079DFda+htWXspBc13lmPi2vGQkWjjS3B4yO8JackyQPVhpsg
|
||||
KYbRBzOH0Kii8bXmyA6O5uIJYEddp5Veged4FE/ej3CrgGP1D0Yk1epx8lLbi9RB
|
||||
kwFS7DA5rQ23UnbSy1WyV1ZgPrWqQAWuGpjMTVTWN0ElI3AGxAnE8lZlSXyE+XyV
|
||||
uHjjIVrayBjLKVqDuSLdKZeCvI4QsyHH6F0NKJQkngvXxLZYxO6s0c2EFFLzdVWT
|
||||
1V9GMP8UsDrrb+JsZjUVmPR1tTP4xqEQG6KjfFoQm5XWpGtFwh91OK1lwf/Bx2/C
|
||||
j+PquLLFcj7hEP79VDTUZPQAduTTxIeTzHXH+x1PCHFB10xxH3e82VSdJeBUrJxn
|
||||
riXzK50SKTTmF+uYpHqE8Jg1N2Y1n5ksuxeYUy8PFjhAeBCqZ6ZcldUDf4999e/z
|
||||
PT8bwfCDr8jRdqJHrq7RxTJiP5RsMudWpKeohzJGwQ5uZwARAQABiQRyBBgBCAAm
|
||||
FiEErj+seWcR7Fn8AHqkdLtrmky7PTgFAlxbVHwCGwIFCQO9IQACQAkQdLtrmky7
|
||||
PTjBdCAEGQEIAB0WIQSVztolaxygoV8wL7WVIaftXazpGAUCXFtUfAAKCRCVIaft
|
||||
XazpGPeMEACm9nxA/VKf8RxDo2ZuTgyuSwlR8tCjAE4k3+UoiYUbamkW4pjx9Vgd
|
||||
1zC5bNxSWZ5vlJ4CH8ArKFqNK5LBVDZqhYureAo/1Af2b9vRJw0/QQHhuXz/jqeT
|
||||
wwrLuKpy796Gpt+aFfcmS0ZC4QXfxJERhAP6tu1p6YmAsSb+bjziQVkKrt9mhOrL
|
||||
dtz6WP0Fg1joRj33FgnnLtayHvtgQrNFI3ztCjk/B2FjYZxqbBGfk5gyo0cTE2Fi
|
||||
oLhG/XrxIoZepFMJkGYETnYQXrOt2KuJLvawV70YQmG8EqHYY8drKA0XDZs8TVdT
|
||||
5cvGvtm8ERz5znsssRBxQMI5Ml6O2ahrXp8Eq4htCzlvO8t2MOtzvqAJRiyAd6bA
|
||||
Uo+MGVRpnvePOR1SAgBXCd416rF0iCXc1utZxnqwdq9kJAZ+8mCLx4N4jk6AdGpX
|
||||
zcNkLg7QmUzXn75RxZ6GrIUYZJNMlswXq5XhSW4o8ePlaxWjh9+QTtU964AZhpA1
|
||||
uoHsKGTBxHJs0w6McZm14kb2PuaO2/rpf8s8IZyc93+Y5O/gHZ6/agBjA9qN6wkQ
|
||||
R1d5UhJC4QS/m35rBGBKK9X3fqQxaBCio6Qz+m4A3GchrztJpq+2P+ma5ylsTq5j
|
||||
V4njky26WNtrV7+N0C4Moj3I4Qn6YU/eSManTXzHzoiPZCEH/IOxgXIiD/9Zm3Zz
|
||||
I+h4NCfSGyP11/w1gEzlTHQ4at/FXIIDh0Y2ZNpWPffuFQLtcER2vyKPwhDYpGMy
|
||||
NNHXks4azfrXVCv0wmSNBbeS8pJrYtopZpCEBrAbg/YLv9m5lpDSRHaR3gv/qMZ7
|
||||
QxY+NwqciqTwGq68PuF4mDSvtfuFmbEES9Iybiie+eL/6DU2knfBjgshUe6vElR+
|
||||
LYoPQ45GY2IxRTJ1pMXaZw1+evwH3UvseRGkRygiaBgoU/qR4prynvjMQcacCa+C
|
||||
aRnXZJYp/usVBeY0xut9toc9/OcLGoBr5h9l5YjruO2vu8VHou8N0tarVQn3YbQR
|
||||
Fi+YtNtclWJa8Pq1AsKRTCFwDwP6eODv6mNOrEFydNRcpiQmzp47VWF/YHRfHzCq
|
||||
A1wHLxLUrpQTaVw6J4FqedAQ31aAO4faA7MS+ZMNBqZCZ7lTGC6TvojqqBAN2yX7
|
||||
AnnYpZHM+lGpi2/ukVzLqSkGmdNOgbu+UZvoej3YnHYig4yWP+z2xrlJl8bkhU/d
|
||||
r9IQE5aRCEPB/JWhHJ2/GqYl9qjshlB52+6X2KDarwptOtzT9ooArYhpMwKIYh34
|
||||
c7X8tlAKYk7V5j7txIRFDKKAftC7dM82PntXJxSkWyR70GYnYjiXyrqqerqT7xIC
|
||||
mDEQgFOPpy09zFW62paO9uiZw6qwybwqgGpoX7kCDQRcW1TbARAA3ERo2mPv2VVg
|
||||
ZUFr4MtPDm4UG00YJW/LYa3D3k0e9tdSScACXprk1sAoxUlQx/CSdErPKwXG4rax
|
||||
iN4t5nICUUNYSC0dh09G25jC7nwsWc0AYyZu+h/FzfvpOm3fBwmBlzILlGh0URwH
|
||||
Ffj9fHt6hos4C+3PFZZ/X24aMJF/cov1oYi9rqFwt/l0mgtPE88Iyj2/Vp3Lergg
|
||||
QMzKfEuyluj9fL2cgU0Qa7oAPXmaxhHtua4cvbM5SXGo3FXjIgzH9OfM+2orebeN
|
||||
wH1M3ec6w+nPmRmCJLvPKGOeS7GVXL5/aOyPlDWzSXYnpCKS2ntw4K4nt0IA8n8z
|
||||
1db109l/C2noDrDSJEqOo843ShNGTYOMVUrj3a+Y7o2ATc9pNZalf0PwnKas7NDb
|
||||
IJ152PEQw665iYXcv2awjLF6W0yuSq8kfiaAxIrsie2Dto0zgqOs0Ot9Y74u11Hh
|
||||
wBSHUO3mEZJScAAcI/yDF2PvjvCQSzu4mdXb77t6X2O6YHULz4A7bVQCMazcTDI9
|
||||
/S0W2+ixPnnJVnE3xgjK9zuizji8JDJw1hJCQM+yTLVqq9pfvcRfQ6uwpMRzz/O3
|
||||
S0zDRiA69/GyfNwkpgz5QaGpY02IK5WrQU1doRjIz4BHAYzoIOkMkRqTtjdElQZw
|
||||
/D3wSO2uwsEMNwRzibR/Lz1JF2aGn6EAEQEAAYkEcgQYAQgAJhYhBK4/rHlnEexZ
|
||||
/AB6pHS7a5pMuz04BQJcW1TbAhsCBQkDvSEAAkAJEHS7a5pMuz04wXQgBBkBCAAd
|
||||
FiEE1wyE5ktVjlvM7AchMuIXXx11eioFAlxbVNsACgkQMuIXXx11eiqCfQ//SFDf
|
||||
rOIEoslp6n6vlCuavOg02wvjskKQGP1P1Q4v40Fw1Gl87n9uXAoMpeF4H+pzUxOi
|
||||
BHYCQi+EemwocSThzaWfPzd3JG/0OcRymf+ZOcBb+58VJL7p88QdMFIAi5J+KMuA
|
||||
fEG0zLkc9anEnXoVMmQJX5K+6PyeVDvBbYGjLjQAsWTZTiVuQI0w3WxFtDGWqQII
|
||||
8e/qE0DA7c/auGn7j2hid308+FcdfpmLefW9YesWjE1yYvHoCRdFOJ/7Sft4MQCI
|
||||
Re7UET3TRMBvtisP2DcqyzGPp22s4ZYFCCJJNiB92bXdEl5zXe4Ff7JTfNE/QrR7
|
||||
Wg5R9hZHgHdbp8p8bA3f0y29YCx3puYg7BbmQWiMh3rXWE5b090pSpw0K9BQU3vO
|
||||
irr+5/2TaFOJXHl4VF03GrWsSncShCbdsdRIv4TB0lY2mN4q+e7bjlAzJJeoaS97
|
||||
GIqu3DBlAJyx/ZwWW23DXXwoQ4jNuJhpl2jaCE7rVQB0uLjbp0i9Zdd4SdYZxmO/
|
||||
Y+JfgoJz8eyx8wZi4eDz1ijN0WKsIGjxJH5VUK9STjijDMeG6ZZRLc6b1QCGhe97
|
||||
ZbDkEUTdQGoeu4L5Fiqoma13NEsf8ofBDv+myJm/O67Va9JI3gxhIrhmF7LMzQQp
|
||||
lYx2peZC1CmhEnn83dtt83mhXvX6Dth657BW/Qd+GQ//SVuTPuNkBXfrTi4dbnv+
|
||||
cU6IsoIBodTF/WsQ6h4kbtsPhO5DbrsLNuNumrqVEN8jw+HUsEeNvFNeMrTPdG2V
|
||||
87ShQ4BQGkCf+GFRBj0myxxXOFZYQx6RpY5fCe7yOcTzpkbnPWmm7V8HdOuZ0NnL
|
||||
JNQ5YogOI6UvXVKv35R9qBo+G9jkhhb0eaAu6BERzKVANKfsGN7545ElZ1qlffMh
|
||||
AQhXGb6TsvCeSg2cWGb2cnVL2d58uVukD4PDiq4qqwgClkF3bOO70SIgGrCteHbi
|
||||
4Hseopex5m6GqqjoUYXr7QQBwSaQdc+gKtEjMHCsHbUyHRk0qEHdEe+2RmL0d0ra
|
||||
QMJfKyYQjcCR7tnrgN4WD1h4NKRdC/KRW31MDmH9XVPrkOMQCUCnArXkOwdKWsKf
|
||||
h8af9HqweXOT1FHJN/M3tWaBpv6KoduF2f2pj1VhPZ2EqFUycJ26lrHyOpsynQR6
|
||||
+TD+c1uXotDwKN5RW+YL1cydk6mhib64fdOyPUeTcHehjMAFgM2f5wi35Ujcj8id
|
||||
37cWOqRsggSbMnGO4AUA/YtcVNG8TjZbakson8ENK7e8q4sEiNFUZ7/CtzNokwHQ
|
||||
5uOG1+qB85Y4ImGnIZVeiBpjt73VVawg4Zvm/omtW50P9R+4rVhMJZZFAgrWg8BH
|
||||
H/KNznW0vUuShG8B+2FA/eu5Ag0EXFtVDAEQAL5ftI1GgVJEFgX5VsuFnfBnH95c
|
||||
zqmwEXaTP4s7Xm3O0Wy579EzRUD1eEw/UaD/q2OHScwvMP65cZYQ9w4hnCN6H96P
|
||||
96Teo7LOMCssvSXIO7gqP33LKTqDzsIoAFHwWE3dq1jbyP6T1Je85mr0Edvk8kOC
|
||||
B1hudswAARno/7X9zGulhhwuEHk5Iey7R59yRUQqBctdNcetGyaiFjjX0evuVADi
|
||||
/z/s07XhDLDt7+3Vglh1/7XGC64QhB9QjZ8j0u7+0xfmLLjhi+7EpkDlAHIJXX1H
|
||||
0wAsPOGKlYruQUmIsMNfBINZeulHEBZ4cAd30xsM296DzJ6QL9sAGfYMhRs0YHB/
|
||||
EJ10Zv0iw1pU2jCCUv/9Kf4F4nwgHQWQP7JAbfhOIUOUq/YlxjTLnkd25+7vD3KH
|
||||
NQ6UiRDROR9Jwetpd/zokpf5O5iTBpVL+sCq+NsTZyDOjITve2sY0V8v10M+Z+pL
|
||||
cp/cUZ4JEDS/WJ4/ovBNJP8b+YwN/RBgCjl8UBX/N+e7AA52eYP2H9GK9XPkzSCE
|
||||
VxEf5PyjGrwedpoLkzagrHsDuWo3uBquLyneT/ozihqKQAuInUy5B7rWU4mpKHe5
|
||||
Vto5o6Zuj+6MgHgIQzRK6Da2ziMNEmroxwZibcYCtUPdvcvxGh+byclnzBclKjOw
|
||||
kAalFPx0SxEbHmzPABEBAAGJBHIEGAEIACYWIQSuP6x5ZxHsWfwAeqR0u2uaTLs9
|
||||
OAUCXFtVDAIbAgUJA70hAAJACRB0u2uaTLs9OMF0IAQZAQgAHRYhBK7WIv4CB360
|
||||
tcFGwUKiedJIzcMQBQJcW1UMAAoJEEKiedJIzcMQH+cQAIQYXDnqi4Hl21LtAgky
|
||||
pZxug+x/LECVlwkrIfaQF337+fG+H9J7SdU87Sn1Xe/YUgQnF0XP/fjIVFM0e/Tb
|
||||
xVlmTFqiejLnIwJJDgUaHO3POT2sGEyO3tc0mqSzyRBxtMQ8yvApccBhL5QODv3h
|
||||
hlRWgk5MXU0IPeXw134IWm+o/PRiPBoXPawvVfEVIBlUFaiSZASf4BAiSad4aJQe
|
||||
P8PyP7FPvQB1xiib0iSetn6ZmNeN2OSUJPiPA8aE9JCKuFtomVQEDM0BqQDl5A7h
|
||||
5O2uyf0Li+/ArqBvfBjrH03e5zbID02dO3D2BjsV3jUeVPQ5WDgVg8LH+nfg/rRy
|
||||
wfCsx9zFp1mt3K4xN2v7IKwxGndApgCcx17gsjzMvLz0J7sSGov4MNjzqvGEDKCl
|
||||
uUvNKXqy7je9xcQLpoyvWtoWFXWTbQAcK5Vv+hC67r9bHpjI1KuqA8hYqNKxsv7s
|
||||
wiLZdd4SK9SIuwf0j8/XTZwmoFfGolJil0ZNxyqBF39+CMVpaHdLM1qKZz99TVzS
|
||||
h4obOOjkUjK458xSo0XCbJ4qXYp7PgxyWK6GIbTozbbG/1ldw+LUnqxt8Shf797L
|
||||
J9lbI3ICuR2P5PYlKJf3b6D9GyfqyrP387fKAKhHsYkZ1XD54/8wIgTrdfeNPtL0
|
||||
1mjWDjw5KvO9kuPBjcmzgt+NrtsQAJwKeZsiqLLcY8kJ9xP+/xtTlh2iVuZMfxwq
|
||||
hwlo4MMCzpobLDZ/JKU398m77eboTKJSBfeUYxQd4ATn1L8NLKjLxKAaBkjEk0nN
|
||||
8w9OUQbFlhQ/asLzzF7Z9IGGh9/SEgBZ8V67a0O3Qw9Xdi3ARK3bbZ8RIVJ0+P9G
|
||||
CGrfq9j4ZmGA2L4irLjsvDAv7CSMb4WBKW8j0Jz5LFMwOMJgG1TT5c6lNqFj6y09
|
||||
rZcVLnt8+lUv2Bw3LC0oI1TjFkrrCzIdfg++mPi3K/ZFc50bvnWF4eCOjgZ5U9Vb
|
||||
sxFZq3+vTRcIfI9z2lZ9CNDRA1O5jGvuVtEGLiSLF2aJ6kiNriLuuGTlXfg/Fpgh
|
||||
GTvyppOTzF7PtHzHBQ/ZjnhWojnc/jyJRwLK8cCl6+EOc887v8BDmqgFWtmycsE2
|
||||
5fDJ7UFGP13g/eDL3ZUgMDty5dQaUOTX145t2KT+lMqpY6ZK2EC+eoqrnIGJ+tYy
|
||||
0l4RRxi10mbNhuPIIDdph7X+mUHgCeA9gyF0Y+LqiB6CX+zFg7ovLvnCbMPxdGXq
|
||||
z7AjfwqZBKI+BVuBeDtyW4onmElCu5cXNKsg3W0IlQlZf9PMDU6Ht0XLUs7EPfbQ
|
||||
sH1Vqi1XE1W/tGnkmjcpG/qlt9Gx1uwFGLP6iomqUBc2c0GZ6R1xplXvd3w3yC8d
|
||||
8lAgPGImuQINBFxbVToBEADkuxhQx9gxlzzCc0nUu2v82XsD+GzONp9irt14gslx
|
||||
te96eKaTXTi0t5eya0X5TIY3wbREwjlfAeM9AfcAmWcsM4izrfPtANM6WOxB2Tbz
|
||||
EY2cqv7NBQii7Z5aqPyjcIiT0b0Gs2evlDkn3xEBBqTSrNcnGSA29bZPIkaUb7Qo
|
||||
p/Ani0S3/tgcR21gXsJwkgpfNKwvPT03Lz3/o5rXAyag0M/25adgk9SVKNcXc8h2
|
||||
HSGv5ENjwUKNNnowVbNLw4287mFUM2Vd6unGJ2MBj7aUwTrfBl7gNV96mMdDJWcB
|
||||
hGKYkxUvibuHCa2KH7gTrnV6X7sdrgD5CbJMPq6OZNSP6n6bUVg22eHxoETplFwT
|
||||
4NvV3clRMWIAG1XgXR1l99LAh7PPnPMM1pHQGPwYHQskoBFS4g5knzHpB9h9TfZ3
|
||||
MM4cDZR5NgWmE0fYVnWe5ax+wW0/IOklUoHv3qoL4yiN9wFJq2oLzUNQd9+tsqiy
|
||||
vxSTh8iYmHegyn5KuBPsrMPgvqiKOdalTZKkak9DOx4cGQL2qHspKxiBOb6uox2v
|
||||
fjMQ5bDeUn+4DYMdnZNHeywCUegJmDakUtlfvN+136IDHGwfdGcitqzswzd3+PI2
|
||||
qlwPE19gkrp9NUaD3Qj2ZtDP7sU2cThc6Gra5KRFW8f98bI77j1Wu6pCnYFLqPz4
|
||||
QQARAQABiQRyBBgBCAAmFiEErj+seWcR7Fn8AHqkdLtrmky7PTgFAlxbVToCGwIF
|
||||
CQO9IQACQAkQdLtrmky7PTjBdCAEGQEIAB0WIQR5HX64jryNAThDSqwz3zWa56YK
|
||||
eQUCXFtVOgAKCRAz3zWa56YKeSWOEADK8u03LESGSQlZQqnnCAI8iYs1s+XRMEnG
|
||||
2tAQ1OK7/4eNgr1yZckmaW4FBMgeEgYIBJ7v3SlW7Hf7dE10TYPNGbP6UxVW8HIP
|
||||
rA4CINcGZXWWwpS374JNMS6A5eb6viuEgEMEi00jx0MmLvCMZKypmwXQUl5YJ5nB
|
||||
ytpQ1681mCQxGBMhT1eKQt3B4nAsoEnP+HnqVM/nKxBemSBNXX+C0b/YeQoLC3sD
|
||||
L+Z0NRI8U6PZl9Rokod3uynH0vfBYCEJd6MvsjtnJlVVaseYIA3ESNrFG12tw95I
|
||||
wKNrVCANZ1DBSyK4ovmmWsDrH+uFTHSLNjlxIuVxUfmXcLfgcepVCmd/7Z7UrWYr
|
||||
SXSvP0VG4ZmEPE7tNb8bfyADftO1cVsmcHBQeSrgvpSrTv9L8MocojpR5vJc1f+a
|
||||
sBT7rAeGzZP9riz1GmryXawaZgdLfaaJfzRQkc1uTChb7kMN+UMhVUdCAXmho0XO
|
||||
SfcsW84u/LpjdYh2Ww41xQO6EWvbZDNgD/Fdmp8Uh1MqJ1Dejri6kjNn6wPImXJd
|
||||
Eu6nHqWDRdYsfT4XUB18tB+4aIpFzCyIgpf7p1uaVU7Oqip5sZkc/WXKr77lV23m
|
||||
PQvpGRNCzgU2TJY7ktR3LOvUVN6wNfLMHzeQk18NdmcEGUrJ0YYtl9vE5/Eg9L6x
|
||||
LBH9PKt17IQ8D/9DLwQX8pl3fuTM8ZbzIPLxiXhbgzBBTXKRE2u1888+RIq9xE7c
|
||||
aVFjwq4qpgqZ5SFonTcG4Pi5ck3mFAzyA5zLRF+ckpmBpwSPMpLwCpv10369D1jh
|
||||
AF3JsUwt6DIb2BISMhh2ThSUMSKO75q8GSotsKjJyjD6vl1x4L7WXubTWxEiNuwD
|
||||
3kAjFWS1Z1VWtA9SURWAbsDaCV4VmwCCpSIwRr9OTbyu9XuMdMxGNpl8SwW7MVQb
|
||||
x4aYNvR7Hl/wIR71AHAXoSfrKp3p12anXjYYASHmbm16ugP4H7HLMBfznKet2f76
|
||||
gIxJr1CsAMTSqypcC1UoVb6Gz8djeIR+GU+6efHI4TIUMy5uMIUx8tYbwSEeo/y6
|
||||
NnjpJFYYjJa671iSABInNxs4+X+1zrFa+wl45EnaFxziEet2Qzv/VsusoLvLwnYi
|
||||
BZckclAS5xoVGFW0WJ01OfLUDHxGMt9GSheL8c+GLMaMtaCWunpmmt9zZ9WdpBOu
|
||||
AGluMG1Cee50TrhXaGE8CdNr8nOdSeLNAveBAPmuVa0JDSe20/D/RuYJLKeG9Vsq
|
||||
BZvjuGlOUsfl6UjtiGRbgS9OWpxeez5ugc9yyV+rBGIpmnIb+9quz2HmGxE65eA2
|
||||
cRNsZRIjFLzeAx/0RMaT1nlLFTBbUuZ+tJ+fgFtRGMhifZn1pb2dMQo0N7kCDQRc
|
||||
W1VuARAAv4LYaNq2Zev/v7M5DnxLpgHRcMkG7TOQpycrlK5653llpZzTy3mh5peW
|
||||
vcq3IDmdeUIJxQ+WDh2f0vS+NIKDC/HAddfHrZPbhO7zLxLcMW5KmV05ancaRSP0
|
||||
s0+IyQmvVxUNrgPinZiphlvRGoLXS6pdgfc4jIR9B2umPecfvfu/6EWFPnXZgG8K
|
||||
yY3Z+mwrmEO0FaXHBQuu6nactiPe79N4bLe8hk9RW6yIxLBeJzIoOlIcJmuRHapt
|
||||
nS2lV3mfhZdFnkAp1o6a2TL5BwgMY0wZUKZr78HEMKh6LbPN9rPepf0neUeq/k1l
|
||||
NJU7V6XMS+rezF31vgSJ5KoNGYhxtWZ54uksH2rcw7+ltpSVtqY91G/vibpRCJG3
|
||||
LdX/kxHni1NEWyZlpS/6ntuH6HSoNYsR9IMsbESs3QVCH74ApK88CxYCRB0SEo0M
|
||||
yAElbQ3bfEKCKl/FwC4IzAYAJ2arWKwBHRSJlsrNCtczrjG7j3EyJrn8+Tm5yjO6
|
||||
0THQjvc/nBxrNE09r1Lzz7jrDWC9Rl+BH6wqdniymoYyUAQsX2rZ+Jhah1Zkf+Gu
|
||||
76qtY+EH494dPM+0FazcBlgBd6/J5mh3Wk9JuecXLTEUGtzd1GmI9CENPAklCauX
|
||||
tNOWeTop27djuKWsZxuP1GyV6UYixFVOSWteyAbA32cncVv/2ZUAEQEAAYkEcgQY
|
||||
AQgAJhYhBK4/rHlnEexZ/AB6pHS7a5pMuz04BQJcW1VuAhsCBQkDvSEAAkAJEHS7
|
||||
a5pMuz04wXQgBBkBCAAdFiEEFWiQaF6g32oTce8gF8xdsfAIhAcFAlxbVW4ACgkQ
|
||||
F8xdsfAIhAd4jxAAiO9+VRQQ3eBOsJRgANdgL/l51kq7qE3u8xnSqNkrmdYDdT2H
|
||||
TYH5W4n2AmGo50BDafdjd6tut0qtzA3/hGWCooydxKFOsnIYziUeoHvlICj3RkHO
|
||||
y7utcFhAgRWi+kzFwnnXGf13dMU9iG7yvKrCrCEw44gzoQ1KnY1Xsj18n5JkqxeT
|
||||
94bzcSbz20OpOSIMfSQPrpy18WrZYwHodcIZ3IUUACCpMZdfTa9c/qHRQ/rcwl+B
|
||||
0JlHx0V4AYiSAsiMVgflO1Eqi7apPuwxPPd5nnHkrdDM9CYC3LdBORBXwncG3oZ5
|
||||
eTSXmsvFxHXH41JHsm/1QFcVmFAYhu9qJFCGiD+8UeTFtT+nnHU69BszgtUskqX8
|
||||
k9PqLdK7Vxkp16wc6WOp1NeIQ6Fd4PxTGrPqs9bJk7TlYtTFWpA0X+EMj/San+Ku
|
||||
PxqLEa4Ab12R4vs1pCrn/g1z3C/6ujH4B70HOrRTIeTjULJ6xdwXGtwUA09hio0r
|
||||
pHhtyZhAh5irUJNto4ZOk/Qyd+dfMsNvRJfbVIK2mmeRaBnp902AsQNgYVdi2Aki
|
||||
0h4kz3bVLGw7iD/xV2hV69+JwLSijkkmOpz/EjMwj0hDDYrHH3Y3o0dV3dNdk/5i
|
||||
6lQgcxSVsl9kWlHcoEllKbf0Hb1muKVwoGGYxFYna2jsLFVjG29M7iPSgrHjmg/+
|
||||
I3fmsLZ0VI9kmxniUlZ6gz5NB5PJ3RXmwKO9LkBgE5C1wpuZbNEQ1NsR2bprlJPm
|
||||
++GNSo8HaheuTRJn42kkOgfIJwjuvXih3FE/NtRA/W8H2uF6YLDjBKGZJbxQcmsd
|
||||
CTEuCRCVP8X7C5n3rl1YqzfWfNr8QFxvH7ivG7KOlSxvyTKcYatWb9uDUPrnr74f
|
||||
ZaMljHGsNyKj70MzZcrrsmt61yWGR0h+02rmIKlskl4hkh+qF5ehI+Bkd7eblsBy
|
||||
rxEREHq/ij2Vd7l0Z606YCE8vj8WfcsJj8JjwR3A+nND/oNJTTbQ3b8OvasvqIey
|
||||
WqqmGg73nbHjd/VIAUsfvnsEYatDk4pAA/wQr9c4T4s5Q/QRwDrAsa4J89FrDjWC
|
||||
hQBPL7TaP8Af/3Y3/86jLCN4lnW1qjPXv5rhBFeI0EVi1k1qdV06qr5HOk7CwQTT
|
||||
uc4rCdFcEnw8kVKZa/yFnlJfRa0Z4IwSahdp5fdFEuad6LpOcFFnYxWtIWhcg4GT
|
||||
RcMha/OZnsfqOqiAt6In+1IwuJBz3uMM7xw2AMaxzAejGEL63F81C5iJ6Ld6kQK+
|
||||
XblDW0G643bVbzkBb46MAT+UnLuWQUs3NDtk1FEioJyWUgbO/srMH4MoWM7rG8ZT
|
||||
nQPohNmPBrqL2phmE27HQsQ0rTjH2Z2ol7iy9OFMtT0=
|
||||
=MkGo
|
||||
-----END PGP PUBLIC KEY BLOCK-----
|
||||
148
dnszone.schema
148
dnszone.schema
|
|
@ -1,148 +0,0 @@
|
|||
# A schema for storing DNS zones in LDAP
|
||||
#
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.0.0 NAME 'dNSTTL'
|
||||
DESC 'An integer denoting time to live'
|
||||
EQUALITY integerMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.0.1 NAME 'dNSClass'
|
||||
DESC 'The class of a resource record'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.0.2 NAME 'zoneName'
|
||||
DESC 'The name of a zone, i.e. the name of the highest node in the zone'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.0.3 NAME 'relativeDomainName'
|
||||
DESC 'The starting labels of a domain name'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.1.12 NAME 'pTRRecord'
|
||||
DESC 'domain name pointer, RFC 1035'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.1.13 NAME 'hInfoRecord'
|
||||
DESC 'host information, RFC 1035'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.1.14 NAME 'mInfoRecord'
|
||||
DESC 'mailbox or mail list information, RFC 1035'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.1.16 NAME 'tXTRecord'
|
||||
DESC 'text string, RFC 1035'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.1.18 NAME 'aFSDBRecord'
|
||||
DESC 'for AFS Data Base location, RFC 1183'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.1.24 NAME 'SigRecord'
|
||||
DESC 'Signature, RFC 2535'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.1.25 NAME 'KeyRecord'
|
||||
DESC 'Key, RFC 2535'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.1.28 NAME 'aAAARecord'
|
||||
DESC 'IPv6 address, RFC 1886'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.1.29 NAME 'LocRecord'
|
||||
DESC 'Location, RFC 1876'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.1.30 NAME 'nXTRecord'
|
||||
DESC 'non-existant, RFC 2535'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.1.33 NAME 'sRVRecord'
|
||||
DESC 'service location, RFC 2782'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.1.35 NAME 'nAPTRRecord'
|
||||
DESC 'Naming Authority Pointer, RFC 2915'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.1.36 NAME 'kXRecord'
|
||||
DESC 'Key Exchange Delegation, RFC 2230'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.1.37 NAME 'certRecord'
|
||||
DESC 'certificate, RFC 2538'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.1.38 NAME 'a6Record'
|
||||
DESC 'A6 Record Type, RFC 2874'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.1.39 NAME 'dNameRecord'
|
||||
DESC 'Non-Terminal DNS Name Redirection, RFC 2672'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.1.43 NAME 'dSRecord'
|
||||
DESC 'Delegation Signer, RFC 3658'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.1.46 NAME 'rRSIGRecord'
|
||||
DESC 'RRSIG, RFC 3755'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
attributetype ( 1.3.6.1.4.1.2428.20.1.47 NAME 'nSECRecord'
|
||||
DESC 'NSEC, RFC 3755'
|
||||
EQUALITY caseIgnoreIA5Match
|
||||
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||
|
||||
objectclass ( 1.3.6.1.4.1.2428.20.3 NAME 'dNSZone'
|
||||
SUP top STRUCTURAL
|
||||
MUST ( zoneName $ relativeDomainName )
|
||||
MAY ( DNSTTL $ DNSClass $
|
||||
ARecord $ MDRecord $ MXRecord $ NSRecord $
|
||||
SOARecord $ CNAMERecord $ PTRRecord $ HINFORecord $
|
||||
MINFORecord $ TXTRecord $ SIGRecord $ KEYRecord $
|
||||
AAAARecord $ LOCRecord $ NXTRecord $ SRVRecord $
|
||||
NAPTRRecord $ KXRecord $ CERTRecord $ A6Record $
|
||||
DNAMERecord ) )
|
||||
16
gating.yaml
Normal file
16
gating.yaml
Normal file
|
|
@ -0,0 +1,16 @@
|
|||
--- !Policy
|
||||
product_versions:
|
||||
- fedora-*
|
||||
decision_contexts: [bodhi_update_push_testing]
|
||||
subject_type: koji_build
|
||||
rules:
|
||||
- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build./plans/tier1-public.functional}
|
||||
|
||||
#gating rawhide
|
||||
--- !Policy
|
||||
product_versions:
|
||||
- fedora-*
|
||||
decision_contexts: [bodhi_update_push_stable]
|
||||
subject_type: koji_build
|
||||
rules:
|
||||
- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build./plans/tier1-public.functional}
|
||||
33
generate-rndc-key.sh
Executable file
33
generate-rndc-key.sh
Executable file
|
|
@ -0,0 +1,33 @@
|
|||
#!/bin/bash
|
||||
|
||||
if [ -r /etc/rc.d/init.d/functions ]; then
|
||||
. /etc/rc.d/init.d/functions
|
||||
else
|
||||
success() {
|
||||
echo $" OK "
|
||||
}
|
||||
|
||||
failure() {
|
||||
echo -n " "
|
||||
echo $"FAILED"
|
||||
}
|
||||
fi
|
||||
|
||||
# This script generates /etc/rndc.key if doesn't exist AND if there is no rndc.conf
|
||||
|
||||
if [ ! -s /etc/rndc.key ] && [ ! -s /etc/rndc.conf ]; then
|
||||
echo -n $"Generating /etc/rndc.key:"
|
||||
if /usr/sbin/rndc-confgen -a -A hmac-sha256 > /dev/null 2>&1
|
||||
then
|
||||
chmod 640 /etc/rndc.key
|
||||
chown root:named /etc/rndc.key
|
||||
[ -x /sbin/restorecon ] && /sbin/restorecon /etc/rndc.key
|
||||
success $"/etc/rndc.key generation"
|
||||
echo
|
||||
else
|
||||
rc=$?
|
||||
failure $"/etc/rndc.key generation"
|
||||
echo
|
||||
exit $rc
|
||||
fi
|
||||
fi
|
||||
175
isc-keyblock.asc
Normal file
175
isc-keyblock.asc
Normal file
|
|
@ -0,0 +1,175 @@
|
|||
-----BEGIN PGP PUBLIC KEY BLOCK-----
|
||||
|
||||
mQINBGNjen4BEADDHiUVNbkFtiKPaMWjKxbKmF1nmv7XKjDhwSww6WFiGPbQyxNM
|
||||
r8EHlEJx5kMT67rx0IYMhTLiXm/9C4dGYyUfFWc35CGetuzstzCNkwJs7vZAhEyk
|
||||
+06CX4GFiHPOmWIupGCxFkNz1Qopz3ZePMlZRslVCHzW4dbg5NKLI0ojXlNaTDU5
|
||||
mgUXpsPi/6l6QE6q3ouvmWPF4u71cZ1+W4UkIRAXOlbVsDzGaMaoHjJd8cOM8DrZ
|
||||
gKHACNPjzqOvEujXDC2vyKw6XpxR+pHz0QcrRtlKnVhPNiKcDfw2mJJ5zxi9uSDc
|
||||
dh5FomMn9sS4gy2Tub2urELnPf9xnURftRGG3VO6nZc81ufQB4s1BNT2ny0Uhx5V
|
||||
mXUJwefMypMBfAvWCWBCeyWYtBeo7LT3NmtLq3oVGPfl7+a0ToFAYeghspK8/nOX
|
||||
6/fqF1MEtzvWjXljz6K7FSDYSY9AoaESLHGwCo6dtff5S7f1+l6PCUNo6aM/B5Ke
|
||||
SIAN9Lm6z2iVuy9Lukw+5IRoRKHHV4rJauPtDeYoWnNiSd7Q4vFtotUIjRpDARpm
|
||||
xWS711Q2T+knHFLEiU8QzxjLhOnTzh4n9dDLHCkOY5WM5krldVeL5EuTyPKinuSn
|
||||
oE01A7I4IGJp753CshibxjNYDiEOVeK93R38Y543edlIrYxnfyMVsiqPkwARAQAB
|
||||
tDRNaWNoYcWCIEvEmXBpZcWEIChDb2RlLVNpZ25pbmcgS2V5KSA8bWljaGFsQGlz
|
||||
Yy5vcmc+iQJOBBMBCgA4FiEEcGtsKGIOdvkdEfffUQpkKgbFLOwFAmNjen4CGwMF
|
||||
CwkIBwMFFQoJCAsFFgIDAQACHgECF4AACgkQUQpkKgbFLOwiLxAAjYuI4JQ8mPq7
|
||||
YrV9m4tu+jOKvoKfpjct2Rh02n/X3ChOgrdcXU898eH56tRk8Mv/E+cBTPN9zQn6
|
||||
rLprbYR2t2R+zgvuUZWA8In7aewoPIJw8OdlG0gTK9m3VHJIOhIX07qcFttSZw4m
|
||||
4rEU5mdxi9FatBWBzqnVm4Pn577aqRXK908j+6TvgWbZ6Cq0tw3syVT4kGj+93+P
|
||||
uIQQQkTYN8UDQPsAKzfzkbQC9I5YXBKUoB9CfhXig8V9N75R0gsWkJ8Vy/8wsPXT
|
||||
9/EPIIzhnhSuUIjvvBPbLGrzDgbhrfUQ/QVuXDVN8xl3rAWM/tiNGOnmzoYORyM5
|
||||
ftrnCDIaO4aVKR6rtEzfdQa5Kid1StfhFien/U8jYErxkEn2HRt2gVEX5nYq31T+
|
||||
0jgVode2Dzkm4+HKHmfOYsQeC07Mu6wZw9raNYqFjTcfh0ajFpLIT3j2YqOJE2jy
|
||||
KbcveJcy2NiOiUl13exIZuBkZm0wEVbvgVX1PlgL3GJqnbU/Q+maRTb8FBoQVsOd
|
||||
GIm7U/phU91qR+00SkOcp2LgHCCNKrmHXgiBNYBbInNIp6ze3bFvfKTRFn8WdY9v
|
||||
Z7vNfKar8rt90mpjYG9qMhmvh4E9icfp3wRUtOwyi7VVtVTTUq0iFTe2C0m0v6KW
|
||||
XcDwwwaTbl79BOqOH3Gp1flS2ECBsyiZAg0EY2N8xQEQAMWcyZbpxEyefX4JTszG
|
||||
ocpz8C8yqvZJQUfoDK5AecQWR7OegPkIqwJcHEH5cz+MduklXNQdra/snn6pxGig
|
||||
At3xCwfzRTH/aYXdjcjnma1elzZSTgk6Maw4zR/W9wea2DcUtMCcsys0gviN/VUe
|
||||
Aqt+5pmhy2PlEWfJG+Mzyrqgz3Q8hRyAJAKONAwNhs1A4ZqQX/6iuCkJbH1CBeoW
|
||||
+c+5qJHYEXsx25qR1yiKOFo5b90QOcwaebUq+xKQRlnESn75FTgDjDfDm9BqrHcn
|
||||
Tv79kOuIN5vhz4BCsuo5QbNu4RGrs/1VSTPvMf5AN7xs9pYNMAEde7pSF1Ps3B5p
|
||||
CE6iUw9L53ytV4iJQKXpzG29LofUu65YQjIXPgK7NbBO7FUHA41YbSfoWiOAjfMh
|
||||
iE025YM2+RPQh/Nrc3PqBj4h21ycT+d8eEXKfc/okbVFFE9dKS1hUwKgSrs7baOG
|
||||
CBZdpiB+t3jWrr8UrteALab7v0rndco3QKOe9U3f+Gm3MdgLK1TGiRgpdyiIXEel
|
||||
J7zhsdoYEvaKMgUOjhf+COdlf8b9ITg93mDKe8h0OcpirCXw4O2ma3sklabzZKZf
|
||||
CPhhja6Ro5gmO5pxaLau+esQWNrjEikynNIs+GRphtcFsVVH+ww26mR0nI65Llgv
|
||||
kb4+DrbDGSPP6R/C2q/LMLM1ABEBAAG0ME1pY2hhbCBOb3dhayAoQ29kZS1TaWdu
|
||||
aW5nIEtleSkgPG1ub3dha0Bpc2Mub3JnPokCTgQTAQoAOBYhBNmczq+Hl0cBTwON
|
||||
YxguI1eUYu+qBQJjY3zFAhsDBQsJCAcDBRUKCQgLBRYCAwEAAh4BAheAAAoJEBgu
|
||||
I1eUYu+q9IAP/j/GGneuvjwbXdATiQAmkiFlOxjs+SsO/hgA/mmWcm+Kpg4cAlbP
|
||||
C2xEDa6biJyZ8TmLZEqPNrRm/umiisC8JnIJpIbInn42n4aDCRDW35lrYGdnP1Ft
|
||||
fexnEOWAJBDRVvh9OnfRfvf+HLFfLFl40b/15YzkTYGIfrMR9y8zalkzXxsVNsyr
|
||||
9Eq2pmYR7BT2z8d/9SAVuh8D3qgUylIgcFcCFJodsrI4zJSpIMfMntwVsZxDlis8
|
||||
JVFN8/pfhuBBe6vjqX/cGJnj6OL3T12jvvniv13W3rar2Ocm6XA9j1t5TZNhKqAy
|
||||
azAKu52NtdJjh25B6C/H+haXAX1eduCCE74uSarqS3F1wf6JI3p8fnWzk4hZNzxp
|
||||
nZjIk3vrHNjE4jXTZosXCf5DoVRfMpNbxj3YEnXV+kNZQRYPPatUPgFYbxz91hbN
|
||||
tHyCiy0GmTyf0QId8LTc0y9mPtP9QureJJ6rL8lt7pvXyrYglqhxDgRhJIGKMKdw
|
||||
0bQtTEF4tyNzC4/sg4/omAGH66clhXlqMmuUjHSUiQyA4LL1mJl63Q+bwqXX4B8t
|
||||
898tSUmb4Jmg3jLZ3Z9Hl7H8Sp3yYPOLzb2YUF6w3xFsUrNNzVxHFo8tAtEhtEfX
|
||||
D+ypkowZq8g41WqMlOBrrzQFuExUSXckH2Cn97lV6lkBoueqxP+Zv0bbmQINBGNj
|
||||
qIkBEADDw/CKszyuFKpVp4Z26rKJ3ooOlp8p9a+fmfuknPtMjJMSX8xK8pOlK739
|
||||
K83yvDRUidT4+R9IAUKM7TqGA0hoPZmZQLiK0YLlAAXufKxO9IsDZI/7DuF2d8fu
|
||||
usKQfS4oJC/IbzOAVwgwodnvKhttLWutT09GxiHrnfVPu6Uf4A+GWtrcTIWhXuxE
|
||||
m7+16ToxBOTLtQ3hh79/RndUuM0ldKRRzJUzASGIPmdQJDLCKgSSeaGjZAdq6gkl
|
||||
qT/K/R8eoLWSOaBRq8lBE1k7Tq4nSwthMHtCQq4+vxFWH3VF9hwy6ixccROPqt9s
|
||||
fNfJK3KF4KGhfejMuVn/Lxp1v+Ne2DsdnVofFakAbBMpMyauzAyXPncYSfFhzLBD
|
||||
kkn7THkfRznmHD8ux89kV534EyqYLjAy8AAD6zNc3tSYgfC0UUw7yz05Sl/eV9Xc
|
||||
pbezu2ipONlXko8jpCQiiHck599cy+StrjjYPwcHF5m8uUlNnzHoUj8qsoK5SA8u
|
||||
RnTW2I4DFbL0+x8eL7gmNQYFdMaA4azogtaTFWgPL2jPJ3B+/bUfHDZflvR0FB5+
|
||||
OD/QHsDv4SB6uX8TOhGbFsHpt7E0scb2U9B8gQeQQJZ3jmcIRp+K18mjYh/ErDFW
|
||||
23ixBe7h3tn2MGUTOhv1ibOYDE3GYBuGLQiom6yhCs8zrneuAQARAQABtDFXbG9k
|
||||
ZWsgV2VuY2VsIChDb2RlLVNpZ25pbmcgS2V5KSA8d2xvZGVrQGlzYy5vcmc+iQJO
|
||||
BBMBCgA4FiEEAlmjO19aOkRmzzRcel4ITKylGIQFAmNjqIkCGwMFCwkIBwMFFQoJ
|
||||
CAsFFgIDAQACHgECF4AACgkQel4ITKylGIRk9g//XrvOYy9zQkpo4Dkol8yLxr99
|
||||
Dq9Ur2v8F5Ba4za4QdUxeYrlq8J827mkUqMtnlyb/+3zSMy2I6HAI8QxlDZL5K0g
|
||||
Gm7iLrwVTM8nAQiNU5vAe4D6PeO5ATBEvRdAUTQGz4xeaTrUXbmNUSC1dZEPvH1z
|
||||
Fa/Z1WZoy9GLeuWDXix6OXTP8FlQWUTL4/ILLtfJDsWCCX7efkyfnvad8Ye2NfU9
|
||||
tBjRX5QQ0Dpvgpr8/7El44XcmaHxPWEiq8X2p/d6j3nU/7LspUXRu3ptu5Q2RqMM
|
||||
iRDZme2c8zieHETpC7m5sshzGxRtT5jWEtZ6V37On5DNTObvXCiaGV95qgiHi5VG
|
||||
s3MFD3QSo1jJI951k68UM8V+OnzbJGN7TezZ3fTn5Pwdd4C4035QMl0E5NXCcXc8
|
||||
9d+3DeFmewRRGCaOKPuO/jFPLWcwMlQqp5tkNx8LpqEZfD7/t6FrSvDUsUDU8Rn0
|
||||
TQILnUZioO68HmeuJbhKaUCMuZGjBIbBqviiufFRiJuEFOVKADQ1u/P5ct/0T/gE
|
||||
JAho3aubzdYMH5DLsaw03W5KfOjeTLW10zSmSK65wnR6fdwlo5l/Sg6Z63QXD+/H
|
||||
/OIFgzviJkyoh6MkH55z2K8BDWbhOmaUBjNAcQEXV1KyHeLDkQ+TJfLjctv4KIpv
|
||||
D7i6kNIp1b6OSdDS9W+ZAg0EY2OzdwEQAMRWPO237ohaXNpKO+dw1qkfOYYisiTQ
|
||||
yfkT7BG0Xvu8jxeOdRuvUzzplgOfwWhOQkyEEXd205/PpwReeeRwhiu0BDSrzYGM
|
||||
KZdw9Bw4enoaOinf5WTqM76mc5WUYfvDJIiHies+ANxj4EqTzvSif9hxvvzrbKYV
|
||||
lHdaGtLm40D6yZSzDEe3X49DmEABM4g/Bs7NfVJcJ3LtLo6qbLy2tKEgNPW+VN/s
|
||||
harufucxnH5HM6BUUOGZx8L04UCNJu+jvZ0zjLc5DqubNO1526kZclAo94DfTkb+
|
||||
ir9nxKn7RkdcseibeYPdeIh3le6aU6M0KhTJs3RCxaQF9At08Vrrkh+wkK2Jr5QW
|
||||
bs8cHpEJ+Q7BwDuAQetFi94eq7Sswh4mjhJ6ZnFCx8v9EbQnvL76afMbhZOezpaQ
|
||||
aAwXVuIio2fsJpHfxWnXb93H1QKiOQdBZZLQGowcFQCqAWg7h2FwWWbKMV1smGHr
|
||||
/28tLZtk/4aSCd9cZ9+nofFPPemPLbYwnBECIZN21QKZ2oBXKxb3hchy4EBTKWtC
|
||||
G/fbTsjSfTCUpMNZ57HO3rGXchjSdIf+tTGJpAqWkTcXuhWXBMWPK6/2REk/DKis
|
||||
XHugHg9R9hqGs2DaMpGh5NrOLly9+0dsjU15iTQucXbCS9895bRtmDjIN8dLSo9H
|
||||
6DDw4yO7SHTlABEBAAG0NE1hcmNpbiBHb2R6aW5hIChDb2RlLVNpZ25pbmcgS2V5
|
||||
KSA8bWdvZHppbmFAaXNjLm9yZz6JAk4EEwEKADgWIQQJCioHkj+SW1dngDpC5d94
|
||||
yDJx2wUCY2OzdwIbAwULCQgHAwUVCgkICwUWAgMBAAIeAQIXgAAKCRBC5d94yDJx
|
||||
29U0D/41C8WaGEphQW1N5lT/1284qiPuz3w3iSciAAoAe8iHUGBcSNpAWQmWvWXI
|
||||
buKb92Gtt8JtSOHwQj8qiHjqRsUu02t/tEgQMQUq6p2jqbxODJfHR8oMFMMB0i0I
|
||||
RgKtEQeq5wRJpVtH+zIFSl9PorsJtHHfhVbqxvE/axcNKa+WaqZdHuKMqADupQEw
|
||||
6rD7yYVX6YPiHxMhba2AAAoHT/3VpHC0JidZ5BWGwkfnGbV1/7O91GHfJx6KN/AK
|
||||
DKb5hFl4TrieDLJzphBWg0y4FJ4K7WSIKvcT2cLel9f9pHV6ysqSZWkCbkjkaVIi
|
||||
LyoA0o7l263WU0D5oG2ihW6Pa2YrWHDDjfTem+kOEFsMjN+Gw74I4KWUBtldfnHK
|
||||
A8TyeviKkVok1lwDAoJ3LJi/bcyCLgBZLInOU31mQ7mIXq1ENCOIvQvaG0Lwdt59
|
||||
sBI8sknHkt+54t/VCaKbWSBOzgGur6EDf9WtPHWvHNCKEleDiHCELdhRYYtENO7T
|
||||
vTv6Fq6Lh26dor26LnARLPvGLAKwONJ0vlTEG8IyoD5AHz9MwdXYgzh8wIvc/HtD
|
||||
/0FlQGLd0WYVI6UjZfPxHOZAzARJKXLJMqiSn8hnO8v6JZaUcOF0yRKTKtzqsjzU
|
||||
v9TubCGdQAaCSCaD2fmA0BEs/FpOnZ8P1fXMpcHGEtMV0qc0wZkCDQRjY7/GARAA
|
||||
ubCCHkdiMblMA9ZlcOVN1Wep7TuYxQouATTb+73iHDQRNIU7DvluHoSq5zJe1Qst
|
||||
zjTmtlkr2dyI5JnBexUEKrw2X7gPXfLaXY01gLLB/Jn8tU9VxPqBybxmjmEdP58B
|
||||
I7BwmCyMYNqDuvPSfTMlogH/pF35Al+c8UbOfDEQqxSO2nKPNa4T5ZoVxvMxV4gn
|
||||
hEJPv8Xte/wiE+CxxbmO2we6rwJjWe7O3T0mNmqvpO8iIsLlQnwTFD5L1huywPc0
|
||||
UDHK0nl8k2lkue2buaOiancLatXt/i+L1DIimCgZwOt3DlVLURH5lz5ALXE/fn+5
|
||||
wKkp+XVyNTAEFhSGifgBDYFw3nZeRTU7unMsRssL8SjuwPWoCcRI/3VE08xCuXc+
|
||||
h6NpGfeJjLRgUSSBF+958djY320TcXaRLrqRhjcJ34dBsDYsRSC15nnq2JU6Vj5t
|
||||
rJL9qOdwVAFwKeAfROUULcy/LHZ3QgKLN5jOfdqYzE2KHk1+VANttRPTG34i6uq6
|
||||
yzCFFYadwST22+QWvxh2ohYj2INvvrzRf3lVxssWyb4USB0JPajgnGeNY/hSYfDa
|
||||
KArqOr9S+3q7h0v4RgoPxDRFIC8v/10W4wPC7R3wj0m/1WHkSm951Wtzq3V84uCF
|
||||
LLhx2ByNpnJFRFqklonAH3WHUIeYcdXAsTeunrGU/XsAEQEAAbQuR3JlZyBDaG91
|
||||
bGVzIChDb2RlLVNpZ25pbmcgS2V5KSA8Z3JlZ0Bpc2Mub3JnPokCTgQTAQoAOBYh
|
||||
BJWA1r8syA8eO7ESUt6rkdVLE8m4BQJjY7/GAhsDBQsJCAcDBRUKCQgLBRYCAwEA
|
||||
Ah4BAheAAAoJEN6rkdVLE8m42PwP/RFmUzgsoM23Z/NQ2AacCFTmHweEllkmf+25
|
||||
3hP80BuSHKsdzlmllFux+xbKZEpQK0nL3fqW8yyv69WmsoKZPpZJxmQ6bwUbtXC7
|
||||
rHkt5gfOXiTaxDBmgO2dcnDsKLb+bEQ7C5hay1P8rOvf13a4UZeTP37gRGmMr38+
|
||||
LvADIspIxBdSvFa7Hb4HKG4VVDai8jaPCF0q8daEWMJxyKSfOQBtSVVAzjLcGrYR
|
||||
bCPDAI1DEASyQOru52WREe4vJCwSaq9dZyGhaWcnyTVQO8bsSLxu7cUVxA3SOheQ
|
||||
izYKkYNbaBDmWlZxLYFsTUf5izEYdW5BwHaowmw22hSspFod+c37BoY/ePfkR5iQ
|
||||
YuEff/unyqvdHMDqIXWZqpAi5o5hW3jdCd7ZL5T0WWjz4CQ8eko1ZYYnYzZlDrge
|
||||
F0veW8+lzHBLx3Ad8HyVGwtRe+VV1V0AZ0lpWMtxo02ZDRtqNDqPqVfLT5P87ZPv
|
||||
r5GhKtedgrjwY2clgmCT0xgAKNxi2SC+c/vI5PRkIoqwbTiryLIYq8tl6T1k6AMY
|
||||
eN1ZNQR7eNEXpIvYRD/BZw7IWKkCRaKwfDVhUHCm0ikylwdLXIfEEEA5mu2LJeZh
|
||||
vCddhks0S8+lRyWR/3okurF6rlloNtM1pslceh2AMDwfs3fORhYJxFsV7O7fyRnD
|
||||
NS93fq56mQINBGNj8P4BEADXK//p0lWEUNUYirsm6BUyUXqPlPrpVTdPB1tJPj1o
|
||||
zgeMKFOpYRPU1IZF1G6pbKD09gL6y19LehQYx1a57PF7kCx2ZvvcFN24EHto1H1p
|
||||
Ti48dZ7KyyEO1rBeLY5Zjgz6YvQZcSH3cd6cTrAo7hPIAjtgSTWp04FjtYJqf+tT
|
||||
gf+9ZWY+i4nQ6/Q5Z5NUd8jsOcOoFDsmY6Fds+lzn0aZSg2yfd8fnX5QFOIwDv66
|
||||
aM25q2kvkrX0wtvSQbulC8x5g6fIB3xEL6MWbXcEBYkBMW5Cnw/Kmyj7lJwVwvEO
|
||||
FFhKaOH/d2LG3rM66gl048aJYLhEJyFSyooBynXs8S/NLDgca94Bvb54FPX8LC3p
|
||||
lqJRLxhdkha5NLcUYiHOq/L7LWdThh5rRAy87Ggog8TVza118K3oiYujlyVEzLhB
|
||||
NVMT8x5kl15YknVgOKJAv9j28bSZihHrS7aga1BtYFD8yA9MuuDaHARV6YmThkdg
|
||||
OEz/PNECjsxCLcT5Bbthzg6Jg1qo3Unyeup0UbyX4zxSphCVmerDmMYddLjJ/ydc
|
||||
1uxyn4IPINBSx2sAPuUIymhVC29MB6N+SnB37/poTvSsIH15Vg264OVdaervIpuC
|
||||
W3eUANr7zrdO85nc1CTWGhugFwccXv9nyxAt8zUF/ci17p1/mLpy9K3LqlStVI9j
|
||||
MwARAQABtDBDYXRoeSBBbG1vbmQgKENvZGUtU2lnbmluZyBLZXkpIDxjYXRoeWFA
|
||||
aXNjLm9yZz6JAk4EEwEKADgWIQT8h0w+P+hncHCscb617/asfhrd+AUCY2Pw/gIb
|
||||
AwULCQgHAwUVCgkICwUWAgMBAAIeAQIXgAAKCRC17/asfhrd+HM6D/9KD/n245Fq
|
||||
jVzew92lJtufAxAFkTA5WO6fXweMlUeqMOub4vpVMLPLoFe5TzWbJMtF0m/P5+aU
|
||||
YbcvZBWFHsrnwTgA55c1VrhggLOxpw4EU0TvBdwrO7PFOYc2WznaMG+mJdqw+uNM
|
||||
yK+G44aIaC6rvi3ILSo5HPnbgQWHs39QIRLLcUjtqvavQQeyYAl0zrvNI9Xrs/Nf
|
||||
eE6PS4hIXg90A9VJRhay18w9hA+STb+xmK+3oSwP1ayLqqQ43OnV/pExSHBsjBQk
|
||||
4p1nIPlRFL30lGp/o2MoBsRvQM1tELpgBTk1LaTHzuKEpOskrWU37xu0QgEtj7YE
|
||||
r0X+GGBxgJuUzqSyLsaDgH1sEDqE+AthFfv2dxDadcXM2cdch9y3OyuSMo89aWGc
|
||||
mEVyesjYoV40tDCG73qLtfehhV/iARDMCfnZGyGYIZdDBL+tZTNeLKVDIUi/R3x9
|
||||
OmpEl8ZuCuYltyEsJnCF/rQBVMgcTOmsMu6CMx+qT3kC8iGtHqkUT2ufpKISahTn
|
||||
e329FQjClEWwBHkr0T4K80Z0REjSo6UBtio73IOCxXe0RqO37L/qgo8xKZbLxy86
|
||||
857PRWJhgbw169FJ2kR5p+M5d/g/MUeYnigvWlORW5LyrFg6RnZ1ZbULZI80QhHN
|
||||
aSFf/w020HBsLCkzWA/XM6MO2ifJTSn8NpkCDQRkSjCrARAApLUMHAbmxUMWLgDQ
|
||||
apRZBwWXriEyIVqA/SIy1PyWPPFXqs3LZ5Kn5Gw1WO8PfzkPZNtccGmNLjujIoRB
|
||||
qR41nV5zxcpS896SujBoYl80A4F4v9Op9i2pFeI9r9acFcUDjbGWBqNro4EfRcJN
|
||||
Ctkd9+pl3TUvFX06QCTxmmHy3M81SW3b4NWI+jia1cKjCd+qBFBgKWdjSMBeVTBC
|
||||
R9eKqsBQ1UJql2bRzc8pReS+TYCeEbhaOCvUCCKCwGtsSUOW726iNB/4zR4OOuQV
|
||||
B9ORufwed+E/RXa8N08/l5O96uXG0krJtOVm0/qQcXOaKxiDo6djnAgCdjFK5zaj
|
||||
7594wqbI7de58alWb/egqIhjBTgk+/cO+epZ05qx5SoJZL7ny2ottrfS2cBqP4g1
|
||||
SIt1sYl9ImHmJkNrNDy0s25nE9Nga6OfRqVbwnwot4ouTGwj0oZsCjw+gWjDdztH
|
||||
1fUWSnlA8jaX9/RZG2wKt9dI+Tp/U4d5dyTb8lIIzzgtAzDmDfPxwwT0rxAAL13A
|
||||
gDkJ0AzXA4WTOxb/JE2yfCz//kt7n8SYM//LixL4VAB7e/wnfZBhTq0OFpaPjFU0
|
||||
h/k0dc40AqcUuK3lSSjQr3KTzRHtjz8qtN4DFSuyZac83QSVtWE1rFKjS8bl3XHC
|
||||
kFFRJ2dMt2WRSkLOYNiTGbYLvmEAEQEAAbQwQW5kcmVpIFBhdmVsIChDb2RlLVNp
|
||||
Z25pbmcgS2V5KSA8YW5kcmVpQGlzYy5vcmc+iQJOBBMBCgA4FiEE2mo1COZypJ3T
|
||||
gq/ZW49NkbiO2QkFAmRKMKsCGwMFCwkIBwMFFQoJCAsFFgIDAQACHgECF4AACgkQ
|
||||
W49NkbiO2QnQZw//XCpeqT0z/sqtu4FYWwYLz1OvWqhe+uA45f9BccnNSVkGFa7w
|
||||
3hlLQC/FLUIx2cVy9AluJBP29iQge/bCcXnzo/QvCbhe/4lCTxhr7nsBe1bWpuNI
|
||||
4Pl+cQxZQBwcz74zZ1jjaaQOqm3XtdZxeKNfCQmNvz389UZEk2m8K6qJD23fy20V
|
||||
n5Y2C502UuP3MitbYKBxBSbs+Auwy1evz/prQ9VeD4Nv3Zr+jWbWFW+dSDC8jkrX
|
||||
cGdwWrUQ51QD8VBB9lPWPGY6yTbRmacr4AlVSo2DAfyjHRrGHigRF/VAD5p1+u2g
|
||||
3UFLJaEyujfzwU1kG4+zQCWZ2W2UBOekklq/yefxEY5vU1/Lad7vQhBmogQNF21T
|
||||
FvLUE6ez7XNsdMZStDPiT8OoTyFZYLRM4yw5rWKw+1mICBv7NV82YD/8hoMoZPyX
|
||||
2tNRTXv2MZ6qD++0dMCIZNEyFTB344srvQSyJ7K7vwxulc7iFWngRA8oe6JkAhH4
|
||||
B0yNq1FJm6jIL41S2FmnDL3DlfAdKWapBqzgqkv+X5DQBaTlG9a4BcSsdMJgU/Yx
|
||||
dD03YsKhDtEWTqBmmEamR1K1CgCC3mOJfsHB5z+Qhdraz2hMr00EQrD5lnpLLpcF
|
||||
rYWoilvVlRy7Y7U5wfhY4074L2ZfB+yElKsvtfGKJX/8g+eJdeRuII+hjEc=
|
||||
=NX7P
|
||||
-----END PGP PUBLIC KEY BLOCK-----
|
||||
20
keygen.c
20
keygen.c
|
|
@ -1,20 +0,0 @@
|
|||
#include <stdio.h>
|
||||
#include <string.h>
|
||||
int main(int argc, char **argv)
|
||||
{
|
||||
FILE *f=fopen("/dev/urandom", "r");
|
||||
char key[61];
|
||||
int i=0;
|
||||
char tmp;
|
||||
memset(key, 0, 61);
|
||||
while(i<60) {
|
||||
tmp=fgetc(f);
|
||||
if((tmp>='a' && tmp<='z') ||
|
||||
(tmp>='A' && tmp<='Z') ||
|
||||
(tmp>='0' && tmp<='9'))
|
||||
key[i++]=tmp;
|
||||
}
|
||||
puts(key);
|
||||
fclose(f);
|
||||
return(0);
|
||||
}
|
||||
411
ldap2zone.c
Normal file
411
ldap2zone.c
Normal file
|
|
@ -0,0 +1,411 @@
|
|||
/*
|
||||
* Copyright (C) 2004, 2005 Stig Venaas <venaas@uninett.no>
|
||||
* $Id: ldap2zone.c,v 1.1 2007/07/24 15:18:00 atkac Exp $
|
||||
*
|
||||
* Permission to use, copy, modify, and distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*/
|
||||
|
||||
#define LDAP_DEPRECATED 1
|
||||
|
||||
#include <sys/types.h>
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <ctype.h>
|
||||
|
||||
#include <ldap.h>
|
||||
|
||||
struct string {
|
||||
void *data;
|
||||
size_t len;
|
||||
};
|
||||
|
||||
struct assstack_entry {
|
||||
struct string key;
|
||||
struct string val;
|
||||
struct assstack_entry *next;
|
||||
};
|
||||
|
||||
struct assstack_entry *assstack_find(struct assstack_entry *stack, struct string *key);
|
||||
void assstack_push(struct assstack_entry **stack, struct assstack_entry *item);
|
||||
void assstack_insertbottom(struct assstack_entry **stack, struct assstack_entry *item);
|
||||
void printsoa(struct string *soa);
|
||||
void printrrs(char *defaultttl, struct assstack_entry *item);
|
||||
void print_zone(char *defaultttl, struct assstack_entry *stack);
|
||||
void usage(char *name);
|
||||
void err(char *name, const char *msg);
|
||||
int putrr(struct assstack_entry **stack, struct berval *name, char *type, char *ttl, struct berval *val);
|
||||
|
||||
struct assstack_entry *assstack_find(struct assstack_entry *stack, struct string *key) {
|
||||
for (; stack; stack = stack->next)
|
||||
if (stack->key.len == key->len && !memcmp(stack->key.data, key->data, key->len))
|
||||
return stack;
|
||||
return NULL;
|
||||
}
|
||||
|
||||
void assstack_push(struct assstack_entry **stack, struct assstack_entry *item) {
|
||||
item->next = *stack;
|
||||
*stack = item;
|
||||
}
|
||||
|
||||
void assstack_insertbottom(struct assstack_entry **stack, struct assstack_entry *item) {
|
||||
struct assstack_entry *p;
|
||||
|
||||
item->next = NULL;
|
||||
if (!*stack) {
|
||||
*stack = item;
|
||||
return;
|
||||
}
|
||||
/* find end, should keep track of end somewhere */
|
||||
/* really a queue, not a stack */
|
||||
p = *stack;
|
||||
while (p->next)
|
||||
p = p->next;
|
||||
p->next = item;
|
||||
}
|
||||
|
||||
void printsoa(struct string *soa) {
|
||||
char *s;
|
||||
size_t i;
|
||||
|
||||
s = (char *)soa->data;
|
||||
i = 0;
|
||||
while (i < soa->len) {
|
||||
putchar(s[i]);
|
||||
if (s[i++] == ' ')
|
||||
break;
|
||||
}
|
||||
while (i < soa->len) {
|
||||
putchar(s[i]);
|
||||
if (s[i++] == ' ')
|
||||
break;
|
||||
}
|
||||
printf("(\n\t\t\t\t");
|
||||
while (i < soa->len) {
|
||||
putchar(s[i]);
|
||||
if (s[i++] == ' ')
|
||||
break;
|
||||
}
|
||||
printf("; Serialnumber\n\t\t\t\t");
|
||||
while (i < soa->len) {
|
||||
if (s[i] == ' ')
|
||||
break;
|
||||
putchar(s[i++]);
|
||||
}
|
||||
i++;
|
||||
printf("\t; Refresh\n\t\t\t\t");
|
||||
while (i < soa->len) {
|
||||
if (s[i] == ' ')
|
||||
break;
|
||||
putchar(s[i++]);
|
||||
}
|
||||
i++;
|
||||
printf("\t; Retry\n\t\t\t\t");
|
||||
while (i < soa->len) {
|
||||
if (s[i] == ' ')
|
||||
break;
|
||||
putchar(s[i++]);
|
||||
}
|
||||
i++;
|
||||
printf("\t; Expire\n\t\t\t\t");
|
||||
while (i < soa->len) {
|
||||
putchar(s[i++]);
|
||||
}
|
||||
printf(" )\t; Minimum TTL\n");
|
||||
}
|
||||
|
||||
void printrrs(char *defaultttl, struct assstack_entry *item) {
|
||||
struct assstack_entry *stack;
|
||||
char *s;
|
||||
int first;
|
||||
size_t i;
|
||||
char *ttl, *type;
|
||||
int top;
|
||||
|
||||
s = (char *)item->key.data;
|
||||
|
||||
if (item->key.len == 1 && *s == '@') {
|
||||
top = 1;
|
||||
printf("@\t");
|
||||
} else {
|
||||
top = 0;
|
||||
for (i = 0; i < item->key.len; i++)
|
||||
putchar(s[i]);
|
||||
if (item->key.len < 8)
|
||||
putchar('\t');
|
||||
putchar('\t');
|
||||
}
|
||||
|
||||
first = 1;
|
||||
for (stack = (struct assstack_entry *) item->val.data; stack; stack = stack->next) {
|
||||
ttl = (char *)stack->key.data;
|
||||
s = strchr(ttl, ' ');
|
||||
*s++ = '\0';
|
||||
type = s;
|
||||
|
||||
if (first)
|
||||
first = 0;
|
||||
else
|
||||
printf("\t\t");
|
||||
|
||||
if (strcmp(defaultttl, ttl))
|
||||
printf("%s", ttl);
|
||||
putchar('\t');
|
||||
|
||||
if (top) {
|
||||
top = 0;
|
||||
printf("IN\t%s\t", type);
|
||||
/* Should always be SOA here */
|
||||
if (!strcmp(type, "SOA")) {
|
||||
printsoa(&stack->val);
|
||||
continue;
|
||||
}
|
||||
} else
|
||||
printf("%s\t", type);
|
||||
|
||||
s = (char *)stack->val.data;
|
||||
for (i = 0; i < stack->val.len; i++)
|
||||
putchar(s[i]);
|
||||
putchar('\n');
|
||||
}
|
||||
}
|
||||
|
||||
void print_zone(char *defaultttl, struct assstack_entry *stack) {
|
||||
printf("$TTL %s\n", defaultttl);
|
||||
for (; stack; stack = stack->next)
|
||||
printrrs(defaultttl, stack);
|
||||
};
|
||||
|
||||
void usage(char *name) {
|
||||
fprintf(stderr, "Usage:%s zone-name LDAP-URL default-ttl [serial]\n", name);
|
||||
exit(1);
|
||||
};
|
||||
|
||||
void err(char *name, const char *msg) {
|
||||
fprintf(stderr, "%s: %s\n", name, msg);
|
||||
exit(1);
|
||||
};
|
||||
|
||||
int putrr(struct assstack_entry **stack, struct berval *name, char *type, char *ttl, struct berval *val) {
|
||||
struct string key;
|
||||
struct assstack_entry *rr, *rrdata;
|
||||
|
||||
/* Do nothing if name or value have 0 length */
|
||||
if (!name->bv_len || !val->bv_len)
|
||||
return 0;
|
||||
|
||||
/* see if already have an entry for this name */
|
||||
key.len = name->bv_len;
|
||||
key.data = name->bv_val;
|
||||
|
||||
rr = assstack_find(*stack, &key);
|
||||
if (!rr) {
|
||||
/* Not found, create and push new entry */
|
||||
rr = (struct assstack_entry *) malloc(sizeof(struct assstack_entry));
|
||||
if (!rr)
|
||||
return -1;
|
||||
rr->key.len = name->bv_len;
|
||||
rr->key.data = (void *) malloc(rr->key.len);
|
||||
if (!rr->key.data) {
|
||||
free(rr);
|
||||
return -1;
|
||||
}
|
||||
memcpy(rr->key.data, name->bv_val, name->bv_len);
|
||||
rr->val.len = sizeof(void *);
|
||||
rr->val.data = NULL;
|
||||
if (name->bv_len == 1 && *(char *)name->bv_val == '@')
|
||||
assstack_push(stack, rr);
|
||||
else
|
||||
assstack_insertbottom(stack, rr);
|
||||
}
|
||||
|
||||
rrdata = (struct assstack_entry *) malloc(sizeof(struct assstack_entry));
|
||||
if (!rrdata) {
|
||||
free(rr->key.data);
|
||||
free(rr);
|
||||
return -1;
|
||||
}
|
||||
rrdata->key.len = strlen(type) + strlen(ttl) + 1;
|
||||
rrdata->key.data = (void *) malloc(rrdata->key.len);
|
||||
if (!rrdata->key.data) {
|
||||
free(rrdata);
|
||||
free(rr->key.data);
|
||||
free(rr);
|
||||
return -1;
|
||||
}
|
||||
sprintf((char *)rrdata->key.data, "%s %s", ttl, type);
|
||||
|
||||
rrdata->val.len = val->bv_len;
|
||||
rrdata->val.data = (void *) malloc(val->bv_len);
|
||||
if (!rrdata->val.data) {
|
||||
free(rrdata->key.data);
|
||||
free(rrdata);
|
||||
free(rr->key.data);
|
||||
free(rr);
|
||||
return -1;
|
||||
}
|
||||
memcpy(rrdata->val.data, val->bv_val, val->bv_len);
|
||||
|
||||
if (!strcmp(type, "SOA"))
|
||||
assstack_push((struct assstack_entry **) &(rr->val.data), rrdata);
|
||||
else
|
||||
assstack_insertbottom((struct assstack_entry **) &(rr->val.data), rrdata);
|
||||
return 0;
|
||||
}
|
||||
|
||||
int main(int argc, char **argv) {
|
||||
char *s, *hostporturl, *base = NULL;
|
||||
char *ttl, *defaultttl;
|
||||
LDAP *ld;
|
||||
char *fltr = NULL;
|
||||
LDAPMessage *res, *e;
|
||||
char *a, **ttlvals, **soavals, *serial;
|
||||
struct berval **vals, **names;
|
||||
char type[64];
|
||||
BerElement *ptr;
|
||||
int i, j, rc, msgid;
|
||||
struct assstack_entry *zone = NULL;
|
||||
|
||||
if (argc < 4 || argc > 5)
|
||||
usage(argv[0]);
|
||||
|
||||
hostporturl = argv[2];
|
||||
|
||||
if (hostporturl != strstr( hostporturl, "ldap"))
|
||||
err(argv[0], "Not an LDAP URL");
|
||||
|
||||
s = strchr(hostporturl, ':');
|
||||
|
||||
if (!s || strlen(s) < 3 || s[1] != '/' || s[2] != '/')
|
||||
err(argv[0], "Not an LDAP URL");
|
||||
|
||||
s = strchr(s+3, '/');
|
||||
if (s) {
|
||||
*s++ = '\0';
|
||||
base = s;
|
||||
s = strchr(base, '?');
|
||||
if (s)
|
||||
err(argv[0], "LDAP URL can only contain host, port and base");
|
||||
}
|
||||
|
||||
defaultttl = argv[3];
|
||||
|
||||
rc = ldap_initialize(&ld, hostporturl);
|
||||
if (rc != LDAP_SUCCESS)
|
||||
err(argv[0], "ldap_initialize() failed");
|
||||
|
||||
if (argc == 5) {
|
||||
/* serial number specified, check if different from one in SOA */
|
||||
fltr = (char *)malloc(strlen(argv[1]) + strlen("(&(relativeDomainName=@)(zoneName=))") + 1);
|
||||
sprintf(fltr, "(&(relativeDomainName=@)(zoneName=%s))", argv[1]);
|
||||
msgid = ldap_search(ld, base, LDAP_SCOPE_SUBTREE, fltr, NULL, 0);
|
||||
if (msgid == -1)
|
||||
err(argv[0], "ldap_search() failed");
|
||||
|
||||
while ((rc = ldap_result(ld, msgid, 0, NULL, &res)) != LDAP_RES_SEARCH_RESULT ) {
|
||||
/* not supporting continuation references at present */
|
||||
if (rc != LDAP_RES_SEARCH_ENTRY)
|
||||
err(argv[0], "ldap_result() returned cont.ref? Exiting");
|
||||
|
||||
/* only one entry per result message */
|
||||
e = ldap_first_entry(ld, res);
|
||||
if (e == NULL) {
|
||||
ldap_msgfree(res);
|
||||
err(argv[0], "ldap_first_entry() failed");
|
||||
}
|
||||
|
||||
soavals = ldap_get_values(ld, e, "SOARecord");
|
||||
if (soavals)
|
||||
break;
|
||||
}
|
||||
|
||||
ldap_msgfree(res);
|
||||
if (!soavals) {
|
||||
err(argv[0], "No SOA Record found");
|
||||
}
|
||||
|
||||
/* We have a SOA, compare serial numbers */
|
||||
/* Only checkinf first value, should be only one */
|
||||
s = strchr(soavals[0], ' ');
|
||||
s++;
|
||||
s = strchr(s, ' ');
|
||||
s++;
|
||||
serial = s;
|
||||
s = strchr(s, ' ');
|
||||
*s = '\0';
|
||||
if (!strcmp(serial, argv[4])) {
|
||||
ldap_value_free(soavals);
|
||||
err(argv[0], "serial numbers match");
|
||||
}
|
||||
ldap_value_free(soavals);
|
||||
}
|
||||
|
||||
if (!fltr)
|
||||
fltr = (char *)malloc(strlen(argv[1]) + strlen("(zoneName=)") + 1);
|
||||
if (!fltr)
|
||||
err(argv[0], "Malloc failed");
|
||||
sprintf(fltr, "(zoneName=%s)", argv[1]);
|
||||
|
||||
msgid = ldap_search(ld, base, LDAP_SCOPE_SUBTREE, fltr, NULL, 0);
|
||||
if (msgid == -1)
|
||||
err(argv[0], "ldap_search() failed");
|
||||
|
||||
while ((rc = ldap_result(ld, msgid, 0, NULL, &res)) != LDAP_RES_SEARCH_RESULT ) {
|
||||
/* not supporting continuation references at present */
|
||||
if (rc != LDAP_RES_SEARCH_ENTRY)
|
||||
err(argv[0], "ldap_result() returned cont.ref? Exiting");
|
||||
|
||||
/* only one entry per result message */
|
||||
e = ldap_first_entry(ld, res);
|
||||
if (e == NULL) {
|
||||
ldap_msgfree(res);
|
||||
err(argv[0], "ldap_first_entry() failed");
|
||||
}
|
||||
|
||||
names = ldap_get_values_len(ld, e, "relativeDomainName");
|
||||
if (!names)
|
||||
continue;
|
||||
|
||||
ttlvals = ldap_get_values(ld, e, "dNSTTL");
|
||||
ttl = ttlvals ? ttlvals[0] : defaultttl;
|
||||
|
||||
for (a = ldap_first_attribute(ld, e, &ptr); a != NULL; a = ldap_next_attribute(ld, e, ptr)) {
|
||||
char *s;
|
||||
|
||||
for (s = a; *s; s++)
|
||||
*s = toupper(*s);
|
||||
s = strstr(a, "RECORD");
|
||||
if ((s == NULL) || (s == a) || (s - a >= (signed int)sizeof(type))) {
|
||||
ldap_memfree(a);
|
||||
continue;
|
||||
}
|
||||
|
||||
strncpy(type, a, s - a);
|
||||
type[s - a] = '\0';
|
||||
vals = ldap_get_values_len(ld, e, a);
|
||||
if (vals) {
|
||||
for (i = 0; vals[i]; i++)
|
||||
for (j = 0; names[j]; j++)
|
||||
if (putrr(&zone, names[j], type, ttl, vals[i]))
|
||||
err(argv[0], "malloc failed");
|
||||
ldap_value_free_len(vals);
|
||||
}
|
||||
ldap_memfree(a);
|
||||
}
|
||||
|
||||
if (ptr)
|
||||
ber_free(ptr, 0);
|
||||
if (ttlvals)
|
||||
ldap_value_free(ttlvals);
|
||||
ldap_value_free_len(names);
|
||||
/* free this result */
|
||||
ldap_msgfree(res);
|
||||
}
|
||||
|
||||
/* free final result */
|
||||
ldap_msgfree(res);
|
||||
|
||||
print_zone(defaultttl, zone);
|
||||
return 0;
|
||||
}
|
||||
|
|
@ -1,26 +0,0 @@
|
|||
--- bind-9.3.1rc1/lib/bind/irs/irs_data.c.fix_h_errno 2004-11-29 20:15:43.000000000 -0500
|
||||
+++ bind-9.3.1rc1/lib/bind/irs/irs_data.c 2005-03-09 21:05:52.000000000 -0500
|
||||
@@ -222,12 +222,7 @@
|
||||
void
|
||||
__h_errno_set(struct __res_state *res, int err) {
|
||||
|
||||
-
|
||||
-#if (__GLIBC__ > 2 || __GLIBC__ == 2 && __GLIBC_MINOR__ >= 3)
|
||||
- res->res_h_errno = err;
|
||||
-#else
|
||||
h_errno = res->res_h_errno = err;
|
||||
-#endif
|
||||
}
|
||||
|
||||
#endif /*__BIND_NOSTATIC*/
|
||||
--- bind-9.3.1rc1/lib/bind/resolv/res_query.c.fix_h_errno 2004-03-16 07:34:19.000000000 -0500
|
||||
+++ bind-9.3.1rc1/lib/bind/resolv/res_query.c 2005-03-09 21:53:34.000000000 -0500
|
||||
@@ -192,6 +192,8 @@
|
||||
}
|
||||
return (-1);
|
||||
}
|
||||
+ if( n > 0 )
|
||||
+ RES_SET_H_ERRNO(statp,0);
|
||||
return (n);
|
||||
}
|
||||
|
||||
|
|
@ -1,6 +0,0 @@
|
|||
# pkg-config file for libbind
|
||||
Name: libbind
|
||||
Description: BIND 8 compatible DNS Resolver Library
|
||||
Version: 9.3.2
|
||||
Libs: -L/usr/lib -lbind
|
||||
Cflags: -I/usr/include/bind
|
||||
|
|
@ -1,10 +0,0 @@
|
|||
$TTL 86400
|
||||
@ IN SOA localhost root (
|
||||
42 ; serial (d. adams)
|
||||
3H ; refresh
|
||||
15M ; retry
|
||||
1W ; expiry
|
||||
1D ) ; minimum
|
||||
IN NS localhost
|
||||
localhost IN A 127.0.0.1
|
||||
|
||||
|
|
@ -1,12 +0,0 @@
|
|||
$TTL 86400
|
||||
@ IN SOA @ root (
|
||||
42 ; serial (d. adams)
|
||||
3H ; refresh
|
||||
15M ; retry
|
||||
1W ; expiry
|
||||
1D ) ; minimum
|
||||
|
||||
IN NS @
|
||||
IN A 127.0.0.1
|
||||
IN AAAA ::1
|
||||
|
||||
143
makefile-replace-libs.py
Executable file
143
makefile-replace-libs.py
Executable file
|
|
@ -0,0 +1,143 @@
|
|||
#!/usr/bin/python3
|
||||
#
|
||||
# Makefile modificator
|
||||
#
|
||||
# Should help in building bin/tests/system tests standalone,
|
||||
# linked to libraries installed into the system.
|
||||
# TODO:
|
||||
# - Fix top_srcdir, because dyndb/driver/Makefile uses $TOPSRC/mkinstalldirs
|
||||
# - Fix conf.sh to contain paths to system tools
|
||||
# - Export $TOP/version somewhere, where it would be used
|
||||
# - system tests needs bin/tests code. Do not include just bin/tests/system
|
||||
#
|
||||
# Possible solution:
|
||||
#
|
||||
# sed -e 's/$TOP\/s\?bin\/\(delv\|confgen\|named\|nsupdate\|pkcs11\|python\|rndc\|check\|dig\|dnssec\|tools\)\/\([[:alnum:]-]\+\)/`type -p \2`/' conf.sh
|
||||
# sed -e 's,../../../../\(isc-config.sh\),\1,' builtin/tests.sh
|
||||
# or use: $NAMED -V | head -1 | cut -d ' ' -f 2
|
||||
|
||||
import re
|
||||
import argparse
|
||||
|
||||
"""
|
||||
Script for replacing Makefile ISC_INCLUDES with runtime flags.
|
||||
|
||||
Should translate part of Makefile to use isc-config.sh instead static linked sources.
|
||||
ISC_INCLUDES = -I/home/pemensik/rhel/bind/bind-9.11.12/build/lib/isc/include \
|
||||
-I${top_srcdir}/lib/isc \
|
||||
-I${top_srcdir}/lib/isc/include \
|
||||
-I${top_srcdir}/lib/isc/unix/include \
|
||||
-I${top_srcdir}/lib/isc/pthreads/include \
|
||||
-I${top_srcdir}/lib/isc/x86_32/include
|
||||
|
||||
Should be translated to:
|
||||
ISC_INCLUDES = $(shell isc-config.sh --cflags isc)
|
||||
"""
|
||||
|
||||
def isc_config(mode, lib):
|
||||
if mode:
|
||||
return '$(shell isc-config.sh {mode} {lib})'.format(mode=mode, lib=lib)
|
||||
else:
|
||||
return ''
|
||||
|
||||
def check_match(match, debug=False):
|
||||
"""
|
||||
Check this definition is handled by internal library
|
||||
"""
|
||||
if not match:
|
||||
return False
|
||||
lib = match.group(2).lower()
|
||||
ok = not lib_filter or lib in lib_filter
|
||||
if debug:
|
||||
print('{status} {lib}: {text}'.format(status=ok, lib=lib, text=match.group(1)))
|
||||
return ok
|
||||
|
||||
def fix_line(match, mode):
|
||||
lib = match.group(2).lower()
|
||||
return match.group(1)+isc_config(mode, lib)+"\n"
|
||||
|
||||
def fix_file_lines(path, debug=False):
|
||||
"""
|
||||
Opens file and scans fixes selected parameters
|
||||
|
||||
Returns list of lines if something should be changed,
|
||||
None if no action is required
|
||||
"""
|
||||
fixed = []
|
||||
changed = False
|
||||
with open(path, 'r') as fin:
|
||||
fout = None
|
||||
|
||||
line = next(fin, None)
|
||||
while line:
|
||||
appended = False
|
||||
while line.endswith("\\\n"):
|
||||
line += next(fin, None)
|
||||
|
||||
inc = re_includes.match(line)
|
||||
deplibs = re_deplibs.match(line)
|
||||
libs = re_libs.match(line)
|
||||
newline = None
|
||||
if check_match(inc, debug=debug):
|
||||
newline = fix_line(inc, '--cflags')
|
||||
elif check_match(deplibs, debug=debug):
|
||||
newline = fix_line(libs, None)
|
||||
elif check_match(libs, debug=debug):
|
||||
newline = fix_line(libs, '--libs')
|
||||
|
||||
if newline and line != newline:
|
||||
changed = True
|
||||
line = newline
|
||||
|
||||
fixed.append(line)
|
||||
line = next(fin, None)
|
||||
|
||||
if not changed:
|
||||
return None
|
||||
else:
|
||||
return fixed
|
||||
|
||||
def write_lines(path, lines):
|
||||
fout = open(path, 'w')
|
||||
for line in lines:
|
||||
fout.write(line)
|
||||
fout.close()
|
||||
|
||||
def print_lines(lines):
|
||||
for line in lines:
|
||||
print(line, end='')
|
||||
|
||||
if __name__ == '__main__':
|
||||
parser = argparse.ArgumentParser(description='Makefile multiline include replacer')
|
||||
parser.add_argument('files', nargs='+')
|
||||
parser.add_argument('--filter', type=str,
|
||||
default='isc isccc isccfg dns lwres bind9 irs',
|
||||
help='List of libraries supported by isc-config.sh')
|
||||
parser.add_argument('--check', action='store_true',
|
||||
help='Test file only')
|
||||
parser.add_argument('--print', action='store_true',
|
||||
help='Print changed file only')
|
||||
parser.add_argument('--debug', action='store_true',
|
||||
help='Enable debug outputs')
|
||||
|
||||
args = parser.parse_args()
|
||||
lib_filter = None
|
||||
|
||||
re_includes = re.compile(r'^\s*((\w+)_INCLUDES\s+=\s*).*')
|
||||
re_deplibs = re.compile(r'^\s*((\w+)DEPLIBS\s*=).*')
|
||||
re_libs = re.compile(r'^\s*((\w+)LIBS\s*=).*')
|
||||
|
||||
if args.filter:
|
||||
lib_filter = set(args.filter.split(' '))
|
||||
pass
|
||||
|
||||
for path in args.files:
|
||||
lines = fix_file_lines(path, debug=args.debug)
|
||||
if lines:
|
||||
if args.print:
|
||||
print_lines(lines)
|
||||
elif not args.check:
|
||||
write_lines(path, lines)
|
||||
print('File {path} was fixed'.format(path=path))
|
||||
else:
|
||||
print('File {path} does not need fixing'.format(path=path))
|
||||
12
named-chroot-setup.service.in
Normal file
12
named-chroot-setup.service.in
Normal file
|
|
@ -0,0 +1,12 @@
|
|||
[Unit]
|
||||
Description=Set-up/destroy chroot environment for named (DNS)
|
||||
BindsTo=named-chroot.service
|
||||
Wants=named-setup-rndc.service
|
||||
After=named-setup-rndc.service
|
||||
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
RemainAfterExit=yes
|
||||
ExecStart=/usr/libexec/%{name}/setup-named-chroot.sh /var/named/chroot on /etc/named-chroot.files
|
||||
ExecStop=/usr/libexec/%{name}/setup-named-chroot.sh /var/named/chroot off /etc/named-chroot.files
|
||||
27
named-chroot.files
Normal file
27
named-chroot.files
Normal file
|
|
@ -0,0 +1,27 @@
|
|||
# Configuration of files used in chroot
|
||||
# Following files are made available after named-chroot.service start
|
||||
# if they are missing or empty in target directory.
|
||||
/etc/localtime
|
||||
/etc/named.root.key
|
||||
/etc/named.ca
|
||||
/etc/named.conf
|
||||
/etc/named.rfc1912.zones
|
||||
/etc/rndc.conf
|
||||
/etc/rndc.key
|
||||
/etc/named.iscdlv.key
|
||||
/etc/crypto-policies/back-ends/bind.config
|
||||
/etc/protocols
|
||||
/etc/services
|
||||
/etc/named.dnssec.keys
|
||||
/etc/pki/dnssec-keys
|
||||
/etc/named
|
||||
/usr/lib64/bind
|
||||
/usr/lib/bind
|
||||
/usr/share/GeoIP
|
||||
/usr/share/named
|
||||
/run/named
|
||||
/proc/sys/net/ipv4/ip_local_port_range
|
||||
# Warning: the order is important
|
||||
# If a directory containing $ROOTDIR is listed here,
|
||||
# it MUST be listed last. (/var/named contains /var/named/chroot)
|
||||
/var/named
|
||||
32
named-chroot.service.in
Normal file
32
named-chroot.service.in
Normal file
|
|
@ -0,0 +1,32 @@
|
|||
# Don't forget to add "$AddUnixListenSocket /var/named/chroot/dev/log"
|
||||
# line to your /etc/rsyslog.conf file. Otherwise your logging becomes
|
||||
# broken when rsyslogd daemon is restarted (due update, for example).
|
||||
|
||||
[Unit]
|
||||
Description=Berkeley Internet Name Domain (DNS)
|
||||
Wants=nss-lookup.target
|
||||
Requires=named-chroot-setup.service
|
||||
Before=nss-lookup.target
|
||||
After=named-chroot-setup.service
|
||||
After=network.target
|
||||
|
||||
[Service]
|
||||
Type=forking
|
||||
Environment=OPTIONS=
|
||||
Environment=NAMEDCONF=/etc/named.conf
|
||||
EnvironmentFile=-/etc/sysconfig/named
|
||||
Environment=KRB5_KTNAME=/etc/named.keytab
|
||||
PIDFile=/var/named/chroot/run/named/named.pid
|
||||
|
||||
ExecStartPre=/bin/bash -c 'if [ ! "$DISABLE_ZONE_CHECKING" == "yes" ]; then %{_bindir}/named-checkconf%{program_suffix} -t /var/named/chroot -z "$NAMEDCONF"; else echo "Checking of zone files is disabled"; fi'
|
||||
ExecStart=%{_sbindir}/named%{program_suffix} -u named -c ${NAMEDCONF} -t /var/named/chroot $OPTIONS
|
||||
|
||||
ExecReload=/bin/sh -c 'if %{_sbindir}/rndc%{program_suffix} null > /dev/null 2>&1; then %{_sbindir}/rndc%{program_suffix} reload; else %{_bindir}/kill -HUP $MAINPID; fi'
|
||||
|
||||
ExecStop=/bin/sh -c '%{_sbindir}/rndc%{program_suffix} stop > /dev/null 2>&1 || %{_bindir}/kill -TERM $MAINPID'
|
||||
|
||||
PrivateTmp=false
|
||||
Restart=on-abnormal
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
|
|
@ -1,20 +0,0 @@
|
|||
<!DOCTYPE busconfig PUBLIC "-//freedesktop//DTD D-BUS Bus Configuration 1.0//EN"
|
||||
"http://www.freedesktop.org/standards/dbus/1.0/busconfig.dtd">
|
||||
<busconfig>
|
||||
<servicedir>/usr/share/dbus-1/services</servicedir>
|
||||
<policy user="named">
|
||||
<allow own="com.redhat.named"/>
|
||||
<allow send_interface="com.redhat.named"/>
|
||||
<allow send_destination="com.redhat.named"/>
|
||||
</policy>
|
||||
<policy user="root">
|
||||
<allow send_interface="com.redhat.named"/>
|
||||
<allow send_destination="com.redhat.named"/>
|
||||
</policy>
|
||||
<policy context="default">
|
||||
<deny own="com.redhat.named"/>
|
||||
<deny send_destination="com.redhat.named"/>
|
||||
<deny send_interface="com.redhat.named"/>
|
||||
</policy>
|
||||
</busconfig>
|
||||
|
||||
7
named-setup-rndc.service.in
Normal file
7
named-setup-rndc.service.in
Normal file
|
|
@ -0,0 +1,7 @@
|
|||
[Unit]
|
||||
Description=Generate rndc key for BIND (DNS)
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
|
||||
ExecStart=/usr/libexec/%{name}/generate-rndc-key.sh
|
||||
|
|
@ -1,8 +0,0 @@
|
|||
$TTL 86400
|
||||
@ IN SOA localhost. root.localhost. (
|
||||
42 ; serial (d. adams)
|
||||
3H ; refresh
|
||||
15M ; retry
|
||||
1W ; expiry
|
||||
1D ) ; minimum
|
||||
IN NS localhost.
|
||||
|
|
@ -1,34 +0,0 @@
|
|||
//
|
||||
// named.caching-nameserver.conf
|
||||
//
|
||||
// Provided by Red Hat bind-config package to configure the
|
||||
// ISC BIND named(8) DNS server as a caching only nameserver
|
||||
// (as a localhost DNS resolver only).
|
||||
//
|
||||
// DO NOT EDIT THIS FILE - use system-config-bind or an editor
|
||||
// to create named.conf - edits to this file will be lost on
|
||||
// bind-config package upgrade.
|
||||
//
|
||||
options {
|
||||
listen-on port 53 { 127.0.0.1; };
|
||||
listen-on-v6 port 53 { ::1; };
|
||||
directory "/var/named";
|
||||
dump-file "/var/named/data/cache_dump.db";
|
||||
statistics-file "/var/named/data/named_stats.txt";
|
||||
memstatistics-file "/var/named/data/named_mem_stats.txt";
|
||||
query-source port 53;
|
||||
query-source-v6 port 53;
|
||||
allow-query { localhost; };
|
||||
};
|
||||
logging {
|
||||
channel default_debug {
|
||||
file "data/named.run";
|
||||
severity dynamic;
|
||||
};
|
||||
};
|
||||
view localhost_resolver {
|
||||
match-clients { localhost; };
|
||||
match-destinations { localhost; };
|
||||
recursion yes;
|
||||
include "/etc/named.rfc1912.zones";
|
||||
};
|
||||
59
named.conf
Normal file
59
named.conf
Normal file
|
|
@ -0,0 +1,59 @@
|
|||
//
|
||||
// named.conf
|
||||
//
|
||||
// Provided by Red Hat bind package to configure the ISC BIND named(8) DNS
|
||||
// server as a caching only nameserver (as a localhost DNS resolver only).
|
||||
//
|
||||
// See /usr/share/doc/bind*/sample/ for example named configuration files.
|
||||
//
|
||||
|
||||
options {
|
||||
listen-on port 53 { 127.0.0.1; };
|
||||
listen-on-v6 port 53 { ::1; };
|
||||
directory "/var/named";
|
||||
dump-file "/var/named/data/cache_dump.db";
|
||||
statistics-file "/var/named/data/named_stats.txt";
|
||||
memstatistics-file "/var/named/data/named_mem_stats.txt";
|
||||
secroots-file "/var/named/data/named.secroots";
|
||||
recursing-file "/var/named/data/named.recursing";
|
||||
allow-query { localhost; };
|
||||
|
||||
/*
|
||||
- If you are building an AUTHORITATIVE DNS server, do NOT enable recursion.
|
||||
- If you are building a RECURSIVE (caching) DNS server, you need to enable
|
||||
recursion.
|
||||
- If your recursive DNS server has a public IP address, you MUST enable access
|
||||
control to limit queries to your legitimate users. Failing to do so will
|
||||
cause your server to become part of large scale DNS amplification
|
||||
attacks. Implementing BCP38 within your network would greatly
|
||||
reduce such attack surface
|
||||
*/
|
||||
recursion yes;
|
||||
|
||||
dnssec-validation yes;
|
||||
|
||||
managed-keys-directory "/var/named/dynamic";
|
||||
geoip-directory "/usr/share/GeoIP";
|
||||
|
||||
pid-file "/run/named/named.pid";
|
||||
session-keyfile "/run/named/session.key";
|
||||
|
||||
/* https://fedoraproject.org/wiki/Changes/CryptoPolicy */
|
||||
include "/etc/crypto-policies/back-ends/bind.config";
|
||||
};
|
||||
|
||||
logging {
|
||||
channel default_debug {
|
||||
file "data/named.run";
|
||||
severity dynamic;
|
||||
};
|
||||
};
|
||||
|
||||
zone "." IN {
|
||||
type hint;
|
||||
file "/etc/named.ca";
|
||||
};
|
||||
|
||||
include "/etc/named.rfc1912.zones";
|
||||
include "/etc/named.root.key";
|
||||
|
||||
243
named.conf.sample
Normal file
243
named.conf.sample
Normal file
|
|
@ -0,0 +1,243 @@
|
|||
/*
|
||||
Sample named.conf BIND DNS server 'named' configuration file
|
||||
for the Red Hat BIND distribution.
|
||||
|
||||
See the BIND Administrator's Reference Manual (ARM) for details, in:
|
||||
file:///usr/share/doc/bind-{version}/arm/Bv9ARM.html
|
||||
Also see the BIND Configuration GUI : /usr/bin/system-config-bind and
|
||||
its manual.
|
||||
*/
|
||||
|
||||
options
|
||||
{
|
||||
// Put files that named is allowed to write in the data/ directory:
|
||||
directory "/var/named"; // "Working" directory
|
||||
dump-file "data/cache_dump.db";
|
||||
statistics-file "data/named_stats.txt";
|
||||
memstatistics-file "data/named_mem_stats.txt";
|
||||
secroots-file "data/named.secroots";
|
||||
recursing-file "data/named.recursing";
|
||||
|
||||
|
||||
/*
|
||||
Specify listenning interfaces. You can use list of addresses (';' is
|
||||
delimiter) or keywords "any"/"none"
|
||||
*/
|
||||
//listen-on port 53 { any; };
|
||||
listen-on port 53 { 127.0.0.1; };
|
||||
|
||||
//listen-on-v6 port 53 { any; };
|
||||
listen-on-v6 port 53 { ::1; };
|
||||
|
||||
/*
|
||||
Access restrictions
|
||||
|
||||
There are two important options:
|
||||
allow-query { argument; };
|
||||
- allow queries for authoritative data
|
||||
|
||||
allow-query-cache { argument; };
|
||||
- allow queries for non-authoritative data (mostly cached data)
|
||||
|
||||
You can use address, network address or keywords "any"/"localhost"/"none" as argument
|
||||
Examples:
|
||||
allow-query { localhost; 10.0.0.1; 192.168.1.0/8; };
|
||||
allow-query-cache { ::1; fe80::5c63:a8ff:fe2f:4526; 10.0.0.1; };
|
||||
*/
|
||||
|
||||
allow-query { localhost; };
|
||||
allow-query-cache { localhost; };
|
||||
|
||||
/* Enable/disable recursion - recursion yes/no;
|
||||
|
||||
- If you are building an AUTHORITATIVE DNS server, do NOT enable recursion.
|
||||
- If you are building a RECURSIVE (caching) DNS server, you need to enable
|
||||
recursion.
|
||||
- If your recursive DNS server has a public IP address, you MUST enable access
|
||||
control to limit queries to your legitimate users. Failing to do so will
|
||||
cause your server to become part of large scale DNS amplification
|
||||
attacks. Implementing BCP38 within your network would greatly
|
||||
reduce such attack surface
|
||||
*/
|
||||
recursion yes;
|
||||
|
||||
/* DNSSEC related options. See information about keys ("Trusted keys", bellow) */
|
||||
|
||||
/* Enable DNSSEC validation on recursive servers */
|
||||
dnssec-validation yes;
|
||||
|
||||
/* In Fedora we use /run/named instead of default /var/run/named
|
||||
so we have to configure paths properly. */
|
||||
pid-file "/run/named/named.pid";
|
||||
session-keyfile "/run/named/session.key";
|
||||
|
||||
managed-keys-directory "/var/named/dynamic";
|
||||
|
||||
/* In Fedora we use system-wide Crypto Policy */
|
||||
/* https://fedoraproject.org/wiki/Changes/CryptoPolicy */
|
||||
include "/etc/crypto-policies/back-ends/bind.config";
|
||||
};
|
||||
|
||||
logging
|
||||
{
|
||||
/* If you want to enable debugging, eg. using the 'rndc trace' command,
|
||||
* named will try to write the 'named.run' file in the $directory (/var/named).
|
||||
* By default, SELinux policy does not allow named to modify the /var/named directory,
|
||||
* so put the default debug log file in data/ :
|
||||
*/
|
||||
channel default_debug {
|
||||
file "data/named.run";
|
||||
severity dynamic;
|
||||
};
|
||||
};
|
||||
|
||||
/*
|
||||
Views let a name server answer a DNS query differently depending on who is asking.
|
||||
|
||||
By default, if named.conf contains no "view" clauses, all zones are in the
|
||||
"default" view, which matches all clients.
|
||||
|
||||
Views are processed sequentially. The first match is used so the last view should
|
||||
match "any" - it's fallback and the most restricted view.
|
||||
|
||||
If named.conf contains any "view" clause, then all zones MUST be in a view.
|
||||
*/
|
||||
|
||||
view "localhost_resolver"
|
||||
{
|
||||
/* This view sets up named to be a localhost resolver ( caching only nameserver ).
|
||||
* If all you want is a caching-only nameserver, then you need only define this view:
|
||||
*/
|
||||
match-clients { localhost; };
|
||||
recursion yes;
|
||||
|
||||
# all views must contain the root hints zone:
|
||||
zone "." IN {
|
||||
type hint;
|
||||
file "/var/named/named.ca";
|
||||
};
|
||||
|
||||
/* these are zones that contain definitions for all the localhost
|
||||
* names and addresses, as recommended in RFC1912 - these names should
|
||||
* not leak to the other nameservers:
|
||||
*/
|
||||
include "/etc/named.rfc1912.zones";
|
||||
};
|
||||
view "internal"
|
||||
{
|
||||
/* This view will contain zones you want to serve only to "internal" clients
|
||||
that connect via your directly attached LAN interfaces - "localnets" .
|
||||
*/
|
||||
match-clients { localnets; };
|
||||
recursion yes;
|
||||
|
||||
zone "." IN {
|
||||
type hint;
|
||||
file "/var/named/named.ca";
|
||||
};
|
||||
|
||||
/* these are zones that contain definitions for all the localhost
|
||||
* names and addresses, as recommended in RFC1912 - these names should
|
||||
* not leak to the other nameservers:
|
||||
*/
|
||||
include "/etc/named.rfc1912.zones";
|
||||
|
||||
// These are your "authoritative" internal zones, and would probably
|
||||
// also be included in the "localhost_resolver" view above :
|
||||
|
||||
/*
|
||||
NOTE for dynamic DNS zones and secondary zones:
|
||||
|
||||
DO NOT USE SAME FILES IN MULTIPLE VIEWS!
|
||||
|
||||
If you are using views and DDNS/secondary zones it is strongly
|
||||
recommended to read FAQ on ISC site (www.isc.org), section
|
||||
"Configuration and Setup Questions", questions
|
||||
"How do I share a dynamic zone between multiple views?" and
|
||||
"How can I make a server a slave for both an internal and an external
|
||||
view at the same time?"
|
||||
*/
|
||||
|
||||
zone "my.internal.zone" {
|
||||
type primary;
|
||||
file "my.internal.zone.db";
|
||||
};
|
||||
zone "my.slave.internal.zone" {
|
||||
type secondary;
|
||||
file "slaves/my.slave.internal.zone.db";
|
||||
masters { /* put master nameserver IPs here */ 127.0.0.1; } ;
|
||||
// put slave zones in the slaves/ directory so named can update them
|
||||
};
|
||||
zone "my.ddns.internal.zone" {
|
||||
type primary;
|
||||
allow-update { key ddns_key; };
|
||||
file "dynamic/my.ddns.internal.zone.db";
|
||||
// put dynamically updateable zones in the slaves/ directory so named can update them
|
||||
};
|
||||
};
|
||||
|
||||
key ddns_key
|
||||
{
|
||||
algorithm hmac-sha256;
|
||||
secret "use /usr/sbin/ddns-confgen to generate TSIG keys";
|
||||
};
|
||||
|
||||
view "external"
|
||||
{
|
||||
/* This view will contain zones you want to serve only to "external" clients
|
||||
* that have addresses that are not match any above view:
|
||||
*/
|
||||
match-clients { any; };
|
||||
|
||||
zone "." IN {
|
||||
type hint;
|
||||
file "/var/named/named.ca";
|
||||
};
|
||||
|
||||
recursion no;
|
||||
// you'd probably want to deny recursion to external clients, so you don't
|
||||
// end up providing free DNS service to all takers
|
||||
|
||||
// These are your "authoritative" external zones, and would probably
|
||||
// contain entries for just your web and mail servers:
|
||||
|
||||
zone "my.external.zone" {
|
||||
type primary;
|
||||
file "my.external.zone.db";
|
||||
};
|
||||
};
|
||||
|
||||
/* Trusted keys
|
||||
|
||||
This statement contains DNSSEC keys. If you want DNSSEC aware resolver you
|
||||
should configure at least one trusted key.
|
||||
|
||||
Note that no key written below is valid. Especially root key because root zone
|
||||
is not signed yet.
|
||||
*/
|
||||
/*
|
||||
trust-anchors {
|
||||
// Root Key
|
||||
. initial-key 257 3 8 "AwEAAaz/tAm8yTn4Mfeh5eyI96WSVexTBAvkMgJzkKTOiW1vkIbzxeF3
|
||||
+/4RgWOq7HrxRixHlFlExOLAJr5emLvN7SWXgnLh4+B5xQlNVz8Og8kv
|
||||
ArMtNROxVQuCaSnIDdD5LKyWbRd2n9WGe2R8PzgCmr3EgVLrjyBxWezF
|
||||
0jLHwVN8efS3rCj/EWgvIWgb9tarpVUDK/b58Da+sqqls3eNbuv7pr+e
|
||||
oZG+SrDK6nWeL3c6H5Apxz7LjVc1uTIdsIXxuOLYA4/ilBmSVIzuDWfd
|
||||
RUfhHdY6+cn8HFRm+2hM8AnXGXws9555KrUB5qihylGa8subX2Nn6UwN
|
||||
R1AkUTV74bU=";
|
||||
|
||||
// Key for forward zone
|
||||
example.com. static-key 257 3 8 "AwEAAZ0aqu1rJ6orJynrRfNpPmayJZoAx9Ic2/Rl9VQW
|
||||
LMHyjxxem3VUSoNUIFXERQbj0A9Ogp0zDM9YIccKLRd6
|
||||
LmWiDCt7UJQxVdD+heb5Ec4qlqGmyX9MDabkvX2NvMws
|
||||
UecbYBq8oXeTT9LRmCUt9KUt/WOi6DKECxoG/bWTykrX
|
||||
yBR8elD+SQY43OAVjlWrVltHxgp4/rhBCvRbmdflunaP
|
||||
Igu27eE2U4myDSLT8a4A0rB5uHG4PkOa9dIRs9y00M2m
|
||||
Wf4lyPee7vi5few2dbayHXmieGcaAHrx76NGAABeY393
|
||||
xjlmDNcUkF1gpNWUla4fWZbbaYQzA93mLdrng+M=";
|
||||
|
||||
|
||||
// Key for reverse zone.
|
||||
2.0.192.IN-ADDRPA.NET. initial-ds 31406 8 2 "F78CF3344F72137235098ECBBD08947C2C9001C7F6A085A17F518B5D8F6B916D";
|
||||
};
|
||||
*/
|
||||
10
named.empty
Normal file
10
named.empty
Normal file
|
|
@ -0,0 +1,10 @@
|
|||
$TTL 3H
|
||||
@ IN SOA @ rname.invalid. (
|
||||
0 ; serial
|
||||
1D ; refresh
|
||||
1H ; retry
|
||||
1W ; expire
|
||||
3H ) ; minimum
|
||||
NS @
|
||||
A 127.0.0.1
|
||||
AAAA ::1
|
||||
265
named.init
265
named.init
|
|
@ -1,265 +0,0 @@
|
|||
#!/bin/bash
|
||||
#
|
||||
# named This shell script takes care of starting and stopping
|
||||
# named (BIND DNS server).
|
||||
#
|
||||
# chkconfig: - 13 87
|
||||
# description: named (BIND) is a Domain Name Server (DNS) \
|
||||
# that is used to resolve host names to IP addresses.
|
||||
# probe: true
|
||||
|
||||
# Source function library.
|
||||
. /etc/rc.d/init.d/functions
|
||||
|
||||
# Source networking configuration.
|
||||
[ -r /etc/sysconfig/network ] && . /etc/sysconfig/network
|
||||
|
||||
# Check that networking is up.
|
||||
[ "${NETWORKING}" = "no" ] && exit 1
|
||||
|
||||
[ -r /etc/sysconfig/named ] && . /etc/sysconfig/named
|
||||
|
||||
if [ -n "$ROOTDIR" ]; then
|
||||
ROOTDIR=`echo $ROOTDIR | sed 's#//*#/#g;s#/$##'`;
|
||||
rdl=`/usr/bin/readlink $ROOTDIR`;
|
||||
if [ -n "$rdl" ]; then
|
||||
ROOTDIR="$rdl";
|
||||
fi;
|
||||
fi
|
||||
|
||||
RETVAL=0
|
||||
named='named'
|
||||
if [[ "$ENABLE_SDB" = [yY1]* ]] && [ -x /usr/sbin/named_sdb ]; then
|
||||
named='named_sdb';
|
||||
fi;
|
||||
prog=$named
|
||||
|
||||
[ -x /usr/sbin/$named ] || exit 1
|
||||
|
||||
nmdcOption()
|
||||
{ let i=0;
|
||||
for a in $*;
|
||||
do ((++i));
|
||||
if [ $a = -c ]; then
|
||||
((++i));
|
||||
eval 'echo $'$i;
|
||||
elif [[ $a = -c* ]]; then
|
||||
echo ${a#-c};
|
||||
fi;
|
||||
done;
|
||||
}
|
||||
|
||||
named_c_option=`nmdcOption $OPTIONS`;
|
||||
named_conf=${named_c_option:-/etc/named.conf};
|
||||
|
||||
if [ ! -r ${ROOTDIR}${named_conf} ] ; then
|
||||
if [ -z "$named_c_option" ] && [ -r ${ROOTDIR}/etc/named.caching-nameserver.conf ]; then
|
||||
named_conf='/etc/named.caching-nameserver.conf';
|
||||
OPTIONS="$OPTIONS -c ${named_conf}";
|
||||
else
|
||||
echo Locating $ROOTDIR/${named_conf} failed:
|
||||
failure
|
||||
echo;
|
||||
fi;
|
||||
fi;
|
||||
|
||||
start() {
|
||||
# Start daemons.
|
||||
echo -n $"Starting $named: "
|
||||
if [ -n "`/sbin/pidof -o %PPID $named`" ]; then
|
||||
echo -n $"$named: already running"
|
||||
failure
|
||||
echo
|
||||
return 1
|
||||
fi
|
||||
ckcf_options='-z'; # enable named-checkzone for each zone (9.3.1+) !
|
||||
if [ -n "${ROOTDIR}" -a "x${ROOTDIR}" != "x/" ]; then
|
||||
OPTIONS="${OPTIONS} -t ${ROOTDIR}"
|
||||
ckcf_options="$ckcf_options -t ${ROOTDIR}";
|
||||
if [ -s /etc/localtime ]; then
|
||||
cp -fp /etc/localtime ${ROOTDIR}/etc/localtime
|
||||
fi;
|
||||
if [ ! -d ${ROOTDIR}/proc ]; then
|
||||
mkdir -p ${ROOTDIR}/proc
|
||||
fi
|
||||
if ! egrep -q '^/proc[[:space:]]+'${ROOTDIR}'/proc' /proc/mounts; then
|
||||
mount --bind /proc ${ROOTDIR}/proc >/dev/null 2>&1
|
||||
fi
|
||||
dbus=0;
|
||||
for a in $OPTIONS; do
|
||||
if [ $a = "-D" ]; then
|
||||
dbus=1;
|
||||
fi;
|
||||
done
|
||||
if [ $dbus -eq 1 ]; then
|
||||
if ! egrep -q '^/[^[:space:]]+[[:space:]]+'${ROOTDIR}'/var/run/dbus' /proc/mounts; then
|
||||
mkdir -p ${ROOTDIR}/var/run/dbus
|
||||
if [ ! -d /var/run/dbus ] ; then
|
||||
mkdir -p /var/run/dbus ;
|
||||
fi;
|
||||
mount --bind /var/run/dbus ${ROOTDIR}/var/run/dbus > /dev/null 2>&1;
|
||||
fi;
|
||||
fi;
|
||||
fi
|
||||
no_write_master_zones=0
|
||||
if [ -e /etc/selinux/config ]; then
|
||||
. /etc/selinux/config
|
||||
if [[ ( "$SELINUX" != 'disabled') && ("$SELINUXTYPE" != "") && (-d /etc/selinux/${SELINUXTYPE}) && (-e /etc/selinux/${SELINUXTYPE}/booleans || (-e /etc/selinux/${SELINUXTYPE}/booleans.local)) ]]; then
|
||||
if [ -e /etc/selinux/${SELINUXTYPE}/booleans.local ]; then
|
||||
. /etc/selinux/${SELINUXTYPE}/booleans.local;
|
||||
else
|
||||
. /etc/selinux/${SELINUXTYPE}/booleans;
|
||||
fi;
|
||||
if echo "$named_write_master_zones" | /bin/egrep -q '^[0-9]+$'; then
|
||||
if [ "$named_write_master_zones" -eq 1 ] ; then
|
||||
/bin/chown -f --from=root:named named:named $ROOTDIR/var/named
|
||||
elif [ "$named_write_master_zones" -eq 0 ] ; then
|
||||
/bin/chown -f --from=named:named root:named $ROOTDIR/var/named
|
||||
fi;
|
||||
fi;
|
||||
else
|
||||
no_write_master_zones=1
|
||||
fi;
|
||||
else
|
||||
no_write_master_zones=1
|
||||
fi;
|
||||
if [ "$no_write_master_zones" -eq 1 ]; then
|
||||
if [[ "$ENABLE_ZONE_WRITE" = [yY1]* ]]; then
|
||||
/bin/chown -f --from=root:named named:named $ROOTDIR/var/named
|
||||
elif [[ "$ENABLE_ZONE_WRITE" = [nN0]* ]]; then
|
||||
/bin/chown -f --from=named:named root:named $ROOTDIR/var/named
|
||||
fi;
|
||||
fi
|
||||
conf_ok=0;
|
||||
if [ -x /usr/sbin/named-checkconf ] && [ -x /usr/sbin/named-checkzone ] && /usr/sbin/named-checkconf $ckcf_options ${named_conf} >/dev/null 2>&1; then
|
||||
conf_ok=1;
|
||||
else
|
||||
RETVAL=$?;
|
||||
fi
|
||||
if [ $conf_ok -eq 1 ]; then
|
||||
daemon /usr/sbin/$named -u named ${OPTIONS};
|
||||
RETVAL=$?;
|
||||
if [ $RETVAL -eq 0 ]; then
|
||||
rm -f /var/run/named.pid
|
||||
rm -f /var/run/named_sdb.pid 2>/dev/null
|
||||
ln -s $ROOTDIR/var/run/named/named.pid /var/run/named.pid;
|
||||
if [ "$named" = "named_sdb" ]; then
|
||||
ln -s $ROOTDIR/var/run/named/named.pid /var/run/named_sdb.pid;
|
||||
fi;
|
||||
fi;
|
||||
else
|
||||
named_err="`/usr/sbin/named-checkconf $ckcf_options $named_conf 2>&1`";
|
||||
echo
|
||||
echo $"Error in named configuration"':';
|
||||
echo "$named_err";
|
||||
failure
|
||||
echo
|
||||
if [ -x /usr/bin/logger ]; then
|
||||
echo "$named_err" | /usr/bin/logger -pdaemon.error -tnamed
|
||||
fi;
|
||||
return $RETVAL;
|
||||
fi;
|
||||
[ $RETVAL -eq 0 ] && touch /var/lock/subsys/named
|
||||
echo
|
||||
return $RETVAL
|
||||
}
|
||||
stop() {
|
||||
# Stop daemons.
|
||||
echo -n $"Stopping $named: "
|
||||
/usr/sbin/rndc stop >/dev/null 2>&1
|
||||
RETVAL=$?
|
||||
if [ $RETVAL -eq 0 ]; then
|
||||
rm -f /var/lock/subsys/named
|
||||
rm -f /var/run/named.pid
|
||||
rm -f /var/run/named_sdb.pid 2>/dev/null
|
||||
elif /sbin/pidof -o %PPID $named >/dev/null; then
|
||||
killproc $named -TERM >/dev/null 2>&1
|
||||
RETVAL=$?
|
||||
if [ $RETVAL -eq 0 ]; then
|
||||
rm -f /var/lock/subsys/named
|
||||
rm -f /var/run/named.pid
|
||||
rm -f /var/run/named_sdb.pid 2>/dev/null
|
||||
fi;
|
||||
fi;
|
||||
if [ $RETVAL -eq 0 ]; then
|
||||
success
|
||||
else
|
||||
failure
|
||||
fi;
|
||||
echo
|
||||
return $RETVAL
|
||||
}
|
||||
rhstatus() {
|
||||
/usr/sbin/rndc status
|
||||
return $?
|
||||
}
|
||||
restart() {
|
||||
stop
|
||||
# wait a couple of seconds for the named to finish closing down
|
||||
sleep 2
|
||||
start
|
||||
}
|
||||
reload() {
|
||||
echo -n $"Reloading $named: "
|
||||
p=`/sbin/pidof -o %PPID $named`
|
||||
RETVAL=$?
|
||||
if [ "$RETVAL" -eq 0 ]; then
|
||||
/usr/sbin/rndc reload >/dev/null 2>&1 || /bin/kill -HUP $p;
|
||||
RETVAL=$?
|
||||
fi
|
||||
[ "$RETVAL" -eq 0 ] && success $"$named reload" || failure $"$named reload"
|
||||
echo
|
||||
return $?
|
||||
}
|
||||
probe() {
|
||||
# named knows how to reload intelligently; we don't want linuxconf
|
||||
# to offer to restart every time
|
||||
/usr/sbin/rndc reload >/dev/null 2>&1 || echo start
|
||||
return $?
|
||||
}
|
||||
checkconfig() {
|
||||
ckcf_options='-z'; # enable named-checkzone for each zone (9.3.1+) !
|
||||
if [ -n "${ROOTDIR}" -a "x${ROOTDIR}" != "x/" ]; then
|
||||
OPTIONS="${OPTIONS} -t ${ROOTDIR}"
|
||||
ckcf_options="$ckcf_options -t ${ROOTDIR}";
|
||||
fi;
|
||||
if [ -x /usr/sbin/named-checkconf ] && [ -x /usr/sbin/named-checkzone ] && /usr/sbin/named-checkconf $ckcf_options ${named_conf} | cat ; then
|
||||
return 0;
|
||||
else
|
||||
return 1;
|
||||
fi
|
||||
}
|
||||
|
||||
# See how we were called.
|
||||
case "$1" in
|
||||
start)
|
||||
start
|
||||
;;
|
||||
stop)
|
||||
stop
|
||||
;;
|
||||
status)
|
||||
rhstatus
|
||||
;;
|
||||
restart)
|
||||
restart
|
||||
;;
|
||||
condrestart)
|
||||
if [ -e /var/lock/subsys/named ]; then restart; fi
|
||||
;;
|
||||
reload)
|
||||
reload
|
||||
;;
|
||||
probe)
|
||||
probe
|
||||
;;
|
||||
checkconfig|configtest|check|test)
|
||||
checkconfig
|
||||
;;
|
||||
*)
|
||||
echo $"Usage: $0 {start|stop|status|restart|condrestart|reload|probe}"
|
||||
exit 1
|
||||
esac
|
||||
|
||||
exit $?
|
||||
|
||||
|
|
@ -1,9 +0,0 @@
|
|||
$TTL 86400
|
||||
@ IN SOA localhost. root.localhost. (
|
||||
1997022700 ; Serial
|
||||
28800 ; Refresh
|
||||
14400 ; Retry
|
||||
3600000 ; Expire
|
||||
86400 ) ; Minimum
|
||||
IN NS localhost.
|
||||
1 IN PTR localhost.
|
||||
|
|
@ -1,9 +0,0 @@
|
|||
$TTL 86400
|
||||
@ IN SOA localhost. root.localhost. (
|
||||
1997022700 ; Serial
|
||||
28800 ; Refresh
|
||||
14400 ; Retry
|
||||
3600000 ; Expire
|
||||
86400 ) ; Minimum
|
||||
IN NS localhost.
|
||||
1 IN PTR localhost.
|
||||
10
named.localhost
Normal file
10
named.localhost
Normal file
|
|
@ -0,0 +1,10 @@
|
|||
$TTL 1D
|
||||
@ IN SOA @ rname.invalid. (
|
||||
0 ; serial
|
||||
1D ; refresh
|
||||
1H ; retry
|
||||
1W ; expire
|
||||
3H ) ; minimum
|
||||
NS @
|
||||
A 127.0.0.1
|
||||
AAAA ::1
|
||||
|
|
@ -1,7 +1,10 @@
|
|||
/var/log/named.log {
|
||||
/var/named/data/named.run {
|
||||
missingok
|
||||
su named named
|
||||
create 0644 named named
|
||||
notifempty
|
||||
postrotate
|
||||
/sbin/service named reload 2> /dev/null > /dev/null || true
|
||||
/usr/bin/systemctl reload named.service > /dev/null 2>&1 || true
|
||||
/usr/bin/systemctl reload named-chroot.service > /dev/null 2>&1 || true
|
||||
endscript
|
||||
}
|
||||
|
|
|
|||
11
named.loopback
Normal file
11
named.loopback
Normal file
|
|
@ -0,0 +1,11 @@
|
|||
$TTL 1D
|
||||
@ IN SOA @ rname.invalid. (
|
||||
0 ; serial
|
||||
1D ; refresh
|
||||
1H ; retry
|
||||
1W ; expire
|
||||
3H ) ; minimum
|
||||
NS @
|
||||
A 127.0.0.1
|
||||
AAAA ::1
|
||||
PTR localhost.
|
||||
|
|
@ -1,48 +1,46 @@
|
|||
// named.rfc1912.zones:
|
||||
// vim: ft=named:
|
||||
//
|
||||
// Provided by Red Hat bind-config package
|
||||
// Provided by Red Hat caching-nameserver package
|
||||
//
|
||||
// ISC BIND named zone configuration for zones recommended by
|
||||
// RFC 1912 section 4.1 : localhost TLDs and address zones
|
||||
// and https://tools.ietf.org/html/rfc6303
|
||||
// (c)2007 R W Franks
|
||||
//
|
||||
// See /usr/share/doc/bind*/sample/ for example named configuration files.
|
||||
//
|
||||
// Note: empty-zones-enable yes; option is default.
|
||||
// If private ranges should be forwarded, add
|
||||
// disable-empty-zone "."; into options
|
||||
//
|
||||
|
||||
zone "." IN {
|
||||
type hint;
|
||||
file "named.ca";
|
||||
};
|
||||
|
||||
zone "localdomain" IN {
|
||||
type master;
|
||||
file "localdomain.zone";
|
||||
zone "localhost.localdomain" IN {
|
||||
type primary;
|
||||
file "/usr/share/named/named.localhost";
|
||||
allow-update { none; };
|
||||
};
|
||||
|
||||
zone "localhost" IN {
|
||||
type master;
|
||||
file "localhost.zone";
|
||||
type primary;
|
||||
file "/usr/share/named/named.localhost";
|
||||
allow-update { none; };
|
||||
};
|
||||
|
||||
zone "0.0.127.in-addr.arpa" IN {
|
||||
type master;
|
||||
file "named.local";
|
||||
zone "1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa" IN {
|
||||
type primary;
|
||||
file "/usr/share/named/named.loopback";
|
||||
allow-update { none; };
|
||||
};
|
||||
|
||||
zone "0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa" IN {
|
||||
type master;
|
||||
file "named.ip6.local";
|
||||
allow-update { none; };
|
||||
};
|
||||
|
||||
zone "255.in-addr.arpa" IN {
|
||||
type master;
|
||||
file "named.broadcast";
|
||||
zone "1.0.0.127.in-addr.arpa" IN {
|
||||
type primary;
|
||||
file "/usr/share/named/named.loopback";
|
||||
allow-update { none; };
|
||||
};
|
||||
|
||||
zone "0.in-addr.arpa" IN {
|
||||
type master;
|
||||
file "named.zero";
|
||||
type primary;
|
||||
file "/usr/share/named/named.empty";
|
||||
allow-update { none; };
|
||||
};
|
||||
|
|
|
|||
92
named.root
92
named.root
|
|
@ -1,80 +1,92 @@
|
|||
; This file holds the information on root name servers needed to
|
||||
; This file holds the information on root name servers needed to
|
||||
; initialize cache of Internet domain name servers
|
||||
; (e.g. reference this file in the "cache . <file>"
|
||||
; configuration file of BIND domain name servers).
|
||||
;
|
||||
; configuration file of BIND domain name servers).
|
||||
;
|
||||
; This file is made available by InterNIC
|
||||
; under anonymous FTP as
|
||||
; file /domain/named.cache
|
||||
; file /domain/named.cache
|
||||
; on server FTP.INTERNIC.NET
|
||||
; -OR- RS.INTERNIC.NET
|
||||
;
|
||||
; last update: Jan 29, 2004
|
||||
; related version of root zone: 2004012900
|
||||
; last update: December 20, 2023
|
||||
; related version of root zone: 2023122001
|
||||
;
|
||||
; FORMERLY NS.INTERNIC.NET
|
||||
;
|
||||
;
|
||||
; formerly NS.INTERNIC.NET
|
||||
;
|
||||
. 3600000 IN NS A.ROOT-SERVERS.NET.
|
||||
. 3600000 NS A.ROOT-SERVERS.NET.
|
||||
A.ROOT-SERVERS.NET. 3600000 A 198.41.0.4
|
||||
;
|
||||
; formerly NS1.ISI.EDU
|
||||
A.ROOT-SERVERS.NET. 3600000 AAAA 2001:503:ba3e::2:30
|
||||
;
|
||||
; FORMERLY NS1.ISI.EDU
|
||||
;
|
||||
. 3600000 NS B.ROOT-SERVERS.NET.
|
||||
B.ROOT-SERVERS.NET. 3600000 A 192.228.79.201
|
||||
;
|
||||
; formerly C.PSI.NET
|
||||
B.ROOT-SERVERS.NET. 3600000 A 170.247.170.2
|
||||
B.ROOT-SERVERS.NET. 3600000 AAAA 2801:1b8:10::b
|
||||
;
|
||||
; FORMERLY C.PSI.NET
|
||||
;
|
||||
. 3600000 NS C.ROOT-SERVERS.NET.
|
||||
C.ROOT-SERVERS.NET. 3600000 A 192.33.4.12
|
||||
;
|
||||
; formerly TERP.UMD.EDU
|
||||
C.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:2::c
|
||||
;
|
||||
; FORMERLY TERP.UMD.EDU
|
||||
;
|
||||
. 3600000 NS D.ROOT-SERVERS.NET.
|
||||
D.ROOT-SERVERS.NET. 3600000 A 128.8.10.90
|
||||
;
|
||||
; formerly NS.NASA.GOV
|
||||
D.ROOT-SERVERS.NET. 3600000 A 199.7.91.13
|
||||
D.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:2d::d
|
||||
;
|
||||
; FORMERLY NS.NASA.GOV
|
||||
;
|
||||
. 3600000 NS E.ROOT-SERVERS.NET.
|
||||
E.ROOT-SERVERS.NET. 3600000 A 192.203.230.10
|
||||
;
|
||||
; formerly NS.ISC.ORG
|
||||
E.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:a8::e
|
||||
;
|
||||
; FORMERLY NS.ISC.ORG
|
||||
;
|
||||
. 3600000 NS F.ROOT-SERVERS.NET.
|
||||
F.ROOT-SERVERS.NET. 3600000 A 192.5.5.241
|
||||
;
|
||||
; formerly NS.NIC.DDN.MIL
|
||||
F.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:2f::f
|
||||
;
|
||||
; FORMERLY NS.NIC.DDN.MIL
|
||||
;
|
||||
. 3600000 NS G.ROOT-SERVERS.NET.
|
||||
G.ROOT-SERVERS.NET. 3600000 A 192.112.36.4
|
||||
;
|
||||
; formerly AOS.ARL.ARMY.MIL
|
||||
G.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:12::d0d
|
||||
;
|
||||
; FORMERLY AOS.ARL.ARMY.MIL
|
||||
;
|
||||
. 3600000 NS H.ROOT-SERVERS.NET.
|
||||
H.ROOT-SERVERS.NET. 3600000 A 128.63.2.53
|
||||
;
|
||||
; formerly NIC.NORDU.NET
|
||||
H.ROOT-SERVERS.NET. 3600000 A 198.97.190.53
|
||||
H.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:1::53
|
||||
;
|
||||
; FORMERLY NIC.NORDU.NET
|
||||
;
|
||||
. 3600000 NS I.ROOT-SERVERS.NET.
|
||||
I.ROOT-SERVERS.NET. 3600000 A 192.36.148.17
|
||||
;
|
||||
; operated by VeriSign, Inc.
|
||||
I.ROOT-SERVERS.NET. 3600000 AAAA 2001:7fe::53
|
||||
;
|
||||
; OPERATED BY VERISIGN, INC.
|
||||
;
|
||||
. 3600000 NS J.ROOT-SERVERS.NET.
|
||||
J.ROOT-SERVERS.NET. 3600000 A 192.58.128.30
|
||||
;
|
||||
; operated by RIPE NCC
|
||||
J.ROOT-SERVERS.NET. 3600000 AAAA 2001:503:c27::2:30
|
||||
;
|
||||
; OPERATED BY RIPE NCC
|
||||
;
|
||||
. 3600000 NS K.ROOT-SERVERS.NET.
|
||||
K.ROOT-SERVERS.NET. 3600000 A 193.0.14.129
|
||||
;
|
||||
; operated by ICANN
|
||||
K.ROOT-SERVERS.NET. 3600000 A 193.0.14.129
|
||||
K.ROOT-SERVERS.NET. 3600000 AAAA 2001:7fd::1
|
||||
;
|
||||
; OPERATED BY ICANN
|
||||
;
|
||||
. 3600000 NS L.ROOT-SERVERS.NET.
|
||||
L.ROOT-SERVERS.NET. 3600000 A 198.32.64.12
|
||||
;
|
||||
; operated by WIDE
|
||||
L.ROOT-SERVERS.NET. 3600000 A 199.7.83.42
|
||||
L.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:9f::42
|
||||
;
|
||||
; OPERATED BY WIDE
|
||||
;
|
||||
. 3600000 NS M.ROOT-SERVERS.NET.
|
||||
M.ROOT-SERVERS.NET. 3600000 A 202.12.27.33
|
||||
; End of File
|
||||
M.ROOT-SERVERS.NET. 3600000 AAAA 2001:dc3::35
|
||||
; End of file
|
||||
18
named.root.key
Normal file
18
named.root.key
Normal file
|
|
@ -0,0 +1,18 @@
|
|||
trust-anchors {
|
||||
# ROOT KEYS: See https://data.iana.org/root-anchors/root-anchors.xml
|
||||
# for current trust anchor information.
|
||||
#
|
||||
# This key (20326) was published in the root zone in 2017.
|
||||
# Servers which were already using the old key (19036) should
|
||||
# roll seamlessly to this new one via RFC 5011 rollover. Servers
|
||||
# being set up for the first time can use the contents of this
|
||||
# file as initializing keys; thereafter, the keys in the
|
||||
# managed key database will be trusted and maintained
|
||||
# automatically.
|
||||
. initial-ds 20326 8 2 "E06D44B80B8F1D39A95C0B0D7C65D08458E880409BBC683457104237C7F8EC8D";
|
||||
# This key (38696) will be pre-published in the root zone in 2025
|
||||
# and is scheduled to begin signing in late 2026. At that time,
|
||||
# servers which were already using the old key (20326) should roll
|
||||
# seamlessly to this new one via RFC 5011 rollover.
|
||||
. initial-ds 38696 8 2 "683D2D0ACB8C9B712A1948B27F741219298D0A450D612C483AF444A4C0FB2B16";
|
||||
};
|
||||
|
|
@ -1,3 +0,0 @@
|
|||
[D-BUS Service]
|
||||
Name=com.redhat.named
|
||||
Exec=/usr/sbin/named
|
||||
28
named.service.in
Normal file
28
named.service.in
Normal file
|
|
@ -0,0 +1,28 @@
|
|||
[Unit]
|
||||
Description=Berkeley Internet Name Domain (DNS)
|
||||
Wants=nss-lookup.target
|
||||
Wants=named-setup-rndc.service
|
||||
Before=nss-lookup.target
|
||||
After=named-setup-rndc.service
|
||||
After=network.target
|
||||
|
||||
[Service]
|
||||
Type=forking
|
||||
Environment=OPTIONS=
|
||||
Environment=NAMEDCONF=/etc/named.conf
|
||||
EnvironmentFile=-/etc/sysconfig/named
|
||||
Environment=KRB5_KTNAME=/etc/named.keytab
|
||||
PIDFile=/run/named/named.pid
|
||||
|
||||
ExecStartPre=/bin/bash -c 'if [ ! "$DISABLE_ZONE_CHECKING" == "yes" ]; then %{_sbindir}/named-checkconf%{program_suffix} -z "$NAMEDCONF"; else echo "Checking of zone files is disabled"; fi'
|
||||
ExecStart=%{_sbindir}/named%{program_suffix} -u named -c ${NAMEDCONF} $OPTIONS
|
||||
|
||||
ExecReload=/bin/sh -c 'if %{_sbindir}/rndc%{program_suffix} null > /dev/null 2>&1; then %{_sbindir}/rndc%{program_suffix} reload; else %{_bindir}/kill -HUP $MAINPID; fi'
|
||||
|
||||
ExecStop=/bin/sh -c '%{_sbindir}/rndc%{program_suffix} stop > /dev/null 2>&1 || %{_bindir}/kill -TERM $MAINPID'
|
||||
|
||||
PrivateTmp=true
|
||||
Restart=on-abnormal
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
|
|
@ -1,23 +1,17 @@
|
|||
# BIND named process options
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
# Currently, you can use the following options:
|
||||
#
|
||||
# ROOTDIR="/some/where" -- will run named in a chroot environment.
|
||||
# you must set up the chroot environment
|
||||
# (install the bind-chroot package) before
|
||||
# doing this.
|
||||
#
|
||||
# OPTIONS="whatever" -- These additional options will be passed to named
|
||||
# at startup. Don't add -t here, use ROOTDIR instead.
|
||||
# at startup. Don't add -t here, enable proper
|
||||
# -chroot.service unit file.
|
||||
#
|
||||
# ENABLE_ZONE_WRITE=yes -- If SELinux is disabled, then allow named to write
|
||||
# its zone files and create files in its $ROOTDIR/var/named
|
||||
# directory, necessary for DDNS and slave zone transfers.
|
||||
# Slave zones should reside in the $ROOTDIR/var/named/slaves
|
||||
# directory, in which case you would not need to enable zone
|
||||
# writes. If SELinux is enabled, you must use only the
|
||||
# 'named_write_master_zones' variable to enable zone writes.
|
||||
# NAMEDCONF=/etc/named/alternate.conf
|
||||
# -- Don't use -c to change configuration file.
|
||||
# Extend systemd named.service instead or use this
|
||||
# variable.
|
||||
#
|
||||
# ENABLE_SDB=yes -- This enables use of 'named_sdb', which has support
|
||||
# -- for the ldap, pgsql and dir zone database backends
|
||||
# -- compiled in, to be used instead of named.
|
||||
# DISABLE_ZONE_CHECKING -- By default, service file calls named-checkzone
|
||||
# utility for every zone to ensure all zones are
|
||||
# valid before named starts. If you set this option
|
||||
# to 'yes' then service file doesn't perform those
|
||||
# checks.
|
||||
|
|
|
|||
3
named.sysusers
Normal file
3
named.sysusers
Normal file
|
|
@ -0,0 +1,3 @@
|
|||
#Type Name ID GECOS Home directory Shell
|
||||
u named 25 "Named" /var/named /sbin/nologin
|
||||
g named 25
|
||||
|
|
@ -1,8 +0,0 @@
|
|||
$TTL 86400
|
||||
@ IN SOA localhost. root.localhost. (
|
||||
42 ; serial (d. adams)
|
||||
3H ; refresh
|
||||
15M ; retry
|
||||
1W ; expiry
|
||||
1D ) ; minimum
|
||||
IN NS localhost.
|
||||
|
|
@ -1,123 +0,0 @@
|
|||
#!/usr/bin/perl
|
||||
#
|
||||
# This script uses the named D-BUS support, which must be enabled in
|
||||
# the running named with the named '-D' option, to get and print the
|
||||
# list of forwarding zones in the running server.
|
||||
#
|
||||
# It accepts an optional <zone> first argument which is the DNS name
|
||||
# of the zone whose forwarders (if any) will be retrieved.
|
||||
#
|
||||
# If no zone argument is specified, all forwarding zones will be listed.
|
||||
#
|
||||
# Usage: GetForwarders [-n -r] [ <zone> ]
|
||||
# -n : output forward zone statements for named.conf
|
||||
# -r : output in resolv.conf format
|
||||
# : no -r or -n: just list the forwarders
|
||||
#
|
||||
# Copyright(C) Jason Vas Dias<jvdias@redhat.com> Red Hat Inc. 2005
|
||||
#
|
||||
# This program is free software; you can redistribute it and/or modify
|
||||
# it under the terms of the GNU General Public License as published by
|
||||
# the Free Software Foundation at
|
||||
# http://www.fsf.org/licensing/licenses/gpl.txt
|
||||
# and included in this software distribution as the "LICENSE" file.
|
||||
#
|
||||
# This program is distributed in the hope that it will be useful,
|
||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
use Getopt::Std;
|
||||
|
||||
%opts=();
|
||||
|
||||
getopts("rn",\%opts);
|
||||
|
||||
$zone = '';
|
||||
if ( $#ARGV >= 0 )
|
||||
{
|
||||
$zone = "string:'". join("' string:'",@ARGV)."'";
|
||||
};
|
||||
|
||||
@dn=();
|
||||
|
||||
open(DNS,
|
||||
'/usr/bin/dbus-send --system --type=method_call --print-reply --reply-timeout=20000 '
|
||||
.'--dest=com.redhat.named /com/redhat/named com.redhat.named.text.GetForwarders '
|
||||
.$zone .'|'
|
||||
) || die("dbus-send failed: $?: $!");
|
||||
|
||||
while(<DNS>)
|
||||
{
|
||||
$_=~s/[\s\r\n]+$//;
|
||||
if ( /(\d{1,3})\.(\d{1,3})\.(\d{1,3})\.(\d{1,3})/ )
|
||||
{ # nameserver address
|
||||
push @{${$dn[-1]}{'s'}}, { 'a' => "$1.$2.$3.$4" };
|
||||
}elsif
|
||||
( /\"(\d+)\"$/ )
|
||||
{ # port
|
||||
if ( $1 != 53 )
|
||||
{
|
||||
${@{${$dn[-1]}{'s'}}[-1]}{'p'} = $1;
|
||||
};
|
||||
}elsif
|
||||
( /string\s+\"([^\"]+)\"$/ )
|
||||
{
|
||||
if ( ($1 eq 'first') || ($1 eq 'only') )
|
||||
{ # policy
|
||||
if( $1 eq 'only' )
|
||||
{ # not default
|
||||
${$dn[-1]}{'o'} = 1;
|
||||
}
|
||||
}else
|
||||
{ # new DN - "zone"
|
||||
push @dn, {'n'=>$1,'s'=>[]};
|
||||
};
|
||||
};
|
||||
};
|
||||
close(DNS);
|
||||
|
||||
if( exists($opts{'r'}) )
|
||||
{ # resolv.conf style:
|
||||
my %svrs=();
|
||||
print 'search ',
|
||||
join( ' ',
|
||||
grep { !( $_ =~ /\.in-addr\.arpa$/) }
|
||||
map { ${$_}{'n'} }
|
||||
@dn
|
||||
),"\n",
|
||||
'nameserver ',
|
||||
join( "\nnameserver ",
|
||||
grep { exists ( $svrs{ $_ } ) ? undef : { $svrs{$_}=$_ } }
|
||||
map { ${$_}{'a'} }
|
||||
map { @{${$_}{'s'}} } @dn
|
||||
),"\n";
|
||||
}elsif( exists($opts{'n'}) )
|
||||
{ # named.conf style:
|
||||
foreach $d (@dn)
|
||||
{
|
||||
print 'zone "',${$d}{'n'},'." IN { type forward; forwarders { ',
|
||||
join("; ",
|
||||
map { exists( ${$_}{'p'} )
|
||||
? ${$_}{'a'} . ' port ' . ${$_}{'p'}
|
||||
: ${$_}{'a'}
|
||||
} @{${$d}{'s'}}
|
||||
),
|
||||
'; }; ',
|
||||
exists(${$d}{'o'}) ? ' forward only; ' : '',
|
||||
"};\n";
|
||||
};
|
||||
}else
|
||||
{ # just list:
|
||||
foreach $d (@dn)
|
||||
{
|
||||
print ${$d}{'n'}, "\n\t",
|
||||
(exists(${$d}{'o'}) ? "forward only\n\t" : ''),
|
||||
join( "\n\t",
|
||||
map { exists( ${$_}{'p'} )
|
||||
? ${$_}{'a'} . ':' . ${$_}{'p'}
|
||||
: ${$_}{'a'}
|
||||
} @{${$d}{'s'}}
|
||||
),"\n";
|
||||
};
|
||||
};
|
||||
|
|
@ -1,52 +0,0 @@
|
|||
#!/bin/bash
|
||||
#
|
||||
# This script uses the named D-BUS support, which must be enabled in
|
||||
# the running named with the named '-D' option, to set the forwarding zones
|
||||
# in the running server.
|
||||
#
|
||||
# One zone argument is required, followed by any number of server IP (v4 or v6)
|
||||
# addresses. If the server IP address list is empty, any forwarders for the zone
|
||||
# will be removed.
|
||||
#
|
||||
# Usage:
|
||||
# SetForwarders [ -t <'first' | 'only'> ] <zone> [ <server IP> [...<server IP>] ]
|
||||
#
|
||||
# Copyright(C) Jason Vas Dias<jvdias@redhat.com> Red Hat Inc. 2005
|
||||
#
|
||||
# This program is free software; you can redistribute it and/or modify
|
||||
# it under the terms of the GNU General Public License as published by
|
||||
# the Free Software Foundation at
|
||||
# http://www.fsf.org/licensing/licenses/gpl.txt
|
||||
# and included in this software distribution as the "LICENSE" file.
|
||||
#
|
||||
# This program is distributed in the hope that it will be useful,
|
||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
usage() { echo "Usage: SetForwarders [ -t <'first' | 'only'> ] <zone> [ <server> [...<server>] ]"; }
|
||||
type=''
|
||||
if [ $# -eq 0 ]; then
|
||||
usage;
|
||||
exit 1;
|
||||
elif [ "$1" = "-t" ]; then
|
||||
if [ $# -lt 2 ]; then
|
||||
echo '-t option requires an argument.'
|
||||
exit 1;
|
||||
fi;
|
||||
type=$2;
|
||||
shift 2;
|
||||
fi;
|
||||
if [ $# -lt 1 ]; then
|
||||
echo '<zone> first argument required.'
|
||||
exit 1;
|
||||
fi;
|
||||
zone='string:'"$1";
|
||||
shift;
|
||||
servers='';
|
||||
if [ $# -gt 0 ]; then
|
||||
for svr in $*; do
|
||||
servers="$servers string:$svr";
|
||||
done
|
||||
fi;
|
||||
dbus-send --system --type=method_call --print-reply --reply-timeout=20000 --dest=com.redhat.named /com/redhat/named com.redhat.named.text.SetForwarders $zone $type $servers;
|
||||
10
plans/all.fmf
Normal file
10
plans/all.fmf
Normal file
|
|
@ -0,0 +1,10 @@
|
|||
summary: Test plan with all beakerlib tests
|
||||
environment+:
|
||||
PACKAGE: bind
|
||||
discover:
|
||||
how: fmf
|
||||
url: https://gitlab.com/redhat/centos-stream/tests/bind.git
|
||||
execute:
|
||||
how: tmt
|
||||
context:
|
||||
component: bind
|
||||
Some files were not shown because too many files have changed in this diff Show more
Loading…
Add table
Add a link
Reference in a new issue