diff --git a/bind-9.21-dual-sign-continue-test.patch b/bind-9.21-dual-sign-continue-test.patch deleted file mode 100644 index 18408af..0000000 --- a/bind-9.21-dual-sign-continue-test.patch +++ /dev/null @@ -1,115 +0,0 @@ -From 488d7bfc75f2988c6e461b8677bc0e27e58bd82e Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Ond=C5=99ej=20Sur=C3=BD?= -Date: Sat, 1 Nov 2025 12:00:59 +0100 -Subject: [PATCH] Add a system test with one good and one bad algorithm - -The case where there would be one supported algorithm and one already -unsupported (like RSAMD5 or RSASHA1) was missing. ---- - bin/tests/system/dnssec/ns2/example.db.in | 4 +++ - bin/tests/system/dnssec/ns2/sign.sh | 2 +- - bin/tests/system/dnssec/ns3/named.conf.j2 | 6 ++++ - bin/tests/system/dnssec/ns3/sign.sh | 31 +++++++++++++++++++++ - bin/tests/system/dnssec/tests_validation.py | 8 ++++++ - 5 files changed, 50 insertions(+), 1 deletion(-) - -diff --git a/bin/tests/system/dnssec/ns2/example.db.in b/bin/tests/system/dnssec/ns2/example.db.in -index 47c2eb7f0e..07429366ee 100644 ---- a/bin/tests/system/dnssec/ns2/example.db.in -+++ b/bin/tests/system/dnssec/ns2/example.db.in -@@ -202,3 +202,7 @@ ns3.extradsunknownoid A 10.53.0.3 - - extended-ds-unknown-oid NS ns3.extended-ds-unknown-oid - ns3.extended-ds-unknown-oid A 10.53.0.3 -+ -+; A secure subdomain with extra bad key -+extrabadkey NS ns3.extrabadkey -+ns3.extrabadkey A 10.53.0.3 -diff --git a/bin/tests/system/dnssec/ns2/sign.sh b/bin/tests/system/dnssec/ns2/sign.sh -index e3f18af15e..da9f5f07fc 100644 ---- a/bin/tests/system/dnssec/ns2/sign.sh -+++ b/bin/tests/system/dnssec/ns2/sign.sh -@@ -92,7 +92,7 @@ for subdomain in digest-alg-unsupported ds-unsupported secure badds \ - dnskey-nsec3-unknown managed-future future revkey \ - dname-at-apex-nsec3 occluded rsasha1 rsasha1-1024 \ - rsasha256oid rsasha512oid unknownoid extradsoid extradsunknownoid \ -- extended-ds-unknown-oid; do -+ extended-ds-unknown-oid extrabadkey; do - cp "../ns3/dsset-$subdomain.example." . - done - -diff --git a/bin/tests/system/dnssec/ns3/named.conf.j2 b/bin/tests/system/dnssec/ns3/named.conf.j2 -index 1a0edc14bb..9cbc58892c 100644 ---- a/bin/tests/system/dnssec/ns3/named.conf.j2 -+++ b/bin/tests/system/dnssec/ns3/named.conf.j2 -@@ -141,6 +141,12 @@ zone "extrakey.example" { - allow-update { any; }; - }; - -+zone "extrabadkey.example" { -+ type primary; -+ file "extrabadkey.example.db.signed"; -+ allow-update { any; }; -+}; -+ - zone "insecure.nsec3.example" { - type primary; - file "insecure.nsec3.example.db"; -diff --git a/bin/tests/system/dnssec/ns3/sign.sh b/bin/tests/system/dnssec/ns3/sign.sh -index 5512888b2f..ea81381eb2 100644 ---- a/bin/tests/system/dnssec/ns3/sign.sh -+++ b/bin/tests/system/dnssec/ns3/sign.sh -@@ -905,3 +905,34 @@ ksk=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -f KSK "$zone") - zsk=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" "$zone") - cat "$infile" "$ksk.key" "$zsk.key" >"$zonefile" - "$SIGNER" -g -o "$zone" "$zonefile" >/dev/null 2>&1 -+ -+# -+# -+# -+zone=extrabadkey.example. -+infile=template.db.in -+zonefile=extrabadkey.example.db -+ -+# Add KSK and ZSK that we will mangle to RSAMD5 -+ksk=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -f KSK "$zone") -+zsk=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" "$zone") -+cat "$infile" "$ksk.key" "$zsk.key" >"$zonefile" -+"$SIGNER" -g -O full -o "$zone" "$zonefile" >/dev/null 2>&1 -+ -+# Mangle the signatures to RSAMD5 and save them for future use -+sed -ne "s/\(IN[[:space:]]*RRSIG[[:space:]]*[A-Z]*\) $DEFAULT_ALGORITHM_NUMBER /\1 1 /p" <"$zonefile.signed" >"$zonefile.signed.rsamd5" -+ -+# Now add normal KSK and ZSK to the zone file -+ksk=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -f KSK "$zone") -+zsk=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" "$zone") -+cat "$infile" "$ksk.key" "$zsk.key" >"$zonefile" -+ -+# Mangle the DNSKEY algorithm numbers and add them to the signed zone file -+cat "$ksk.key" "$zsk.key" | sed -e "s/\(IN[[:space:]]*DNSKEY[[:space:]]*[0-9]* 3\) $DEFAULT_ALGORITHM_NUMBER /\1 1 /" >>"$zonefile" -+ -+# Sign normally -+"$SIGNER" -g -o "$zone" "$zonefile" >/dev/null 2>&1 -+ -+# Add the mangled signatures to signed zone file -+cat "$zonefile.signed.rsamd5" >>"$zonefile.signed" -+rm "$zonefile.signed.rsamd5" -diff --git a/bin/tests/system/dnssec/tests_validation.py b/bin/tests/system/dnssec/tests_validation.py -index e6d8ccc734..a27a899987 100644 ---- a/bin/tests/system/dnssec/tests_validation.py -+++ b/bin/tests/system/dnssec/tests_validation.py -@@ -1385,3 +1385,11 @@ def test_rrsigs_for_glue(): - record.rdtype == rdatatype.RRSIG and record.covers == rdatatype.A - for record in res.answer - ) -+ -+ -+def test_extra_bad_algorithm(): -+ msg = isctest.query.create("a.extrabadkey.example", "A") -+ res1 = isctest.query.tcp(msg, "10.53.0.3") -+ res2 = isctest.query.tcp(msg, "10.53.0.4") -+ isctest.check.same_answer(res1, res2) -+ isctest.check.adflag(res2) --- -2.51.1 - diff --git a/bind-9.21-dual-sign-continue.patch b/bind-9.21-dual-sign-continue.patch deleted file mode 100644 index 22e3cef..0000000 --- a/bind-9.21-dual-sign-continue.patch +++ /dev/null @@ -1,42 +0,0 @@ -From a94a7c1a1e6eecbead995a08bace33d23899a5da Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Ond=C5=99ej=20Sur=C3=BD?= -Date: Tue, 4 Nov 2025 02:09:38 +0100 -Subject: [PATCH] Skip unsupported algorithms when looking for signing key -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -When looking for a signing key in select_signing_key(), the result code -indicating unsupported algorithm would abort the search. Instead, skip -such keys and continue searching for the right key. - -Co-Authored-By: Aram Sargsyan -Co-Authored-By: Petr Menšík ---- - lib/dns/validator.c | 10 ++++++++-- - 1 file changed, 8 insertions(+), 2 deletions(-) - -diff --git a/lib/dns/validator.c b/lib/dns/validator.c -index c6781544b9..52677fbd80 100644 ---- a/lib/dns/validator.c -+++ b/lib/dns/validator.c -@@ -1092,8 +1092,14 @@ select_signing_key(dns_validator_t *val, dns_rdataset_t *rdataset) { - continue; - } - -- return dns_dnssec_keyfromrdata(&siginfo->signer, &rdata, -- val->view->mctx, &val->key); -+ result = dns_dnssec_keyfromrdata(&siginfo->signer, &rdata, -+ val->view->mctx, &val->key); -+ /* Don't count unsupported algorithm towards max fails */ -+ if (result == DST_R_UNSUPPORTEDALG) { -+ /* Continue with the next key */ -+ continue; -+ } -+ return result; - } - - return ISC_R_NOTFOUND; --- -2.51.1 - diff --git a/bind-9.21-unittest-32b-mem.patch b/bind-9.21-unittest-32b-mem.patch new file mode 100644 index 0000000..ba4e0fd --- /dev/null +++ b/bind-9.21-unittest-32b-mem.patch @@ -0,0 +1,112 @@ +From 4623873e588c86c6add4d53708e754e2d6f3e087 Mon Sep 17 00:00:00 2001 +From: Michal Nowak +Date: Wed, 20 May 2026 08:59:49 +0000 +Subject: [PATCH] Make deleg cleanuptests memory assertions 32-bit-safe + +Each address entry stored by dns_delegset_addaddr() is an +isc_netaddrlink_t, whose size depends on sizeof(void *) via the +ISC_LINK macro (24 bytes of address + two prev/next pointers): 40 +bytes on 64-bit, 32 bytes on 32-bit. The hardcoded 4 MB / 8 MB +ranges only held on 64-bit, so dns_deleg_cleanuptests failed on +armv7l with isc_mem_inuse() returning ~3.2 MB. + +Express the expected ranges in terms of sizeof(isc_netaddrlink_t) +so they scale with pointer width, and pull the 99999 entry count +out into a NENTRIES macro. + +Assisted-by: Claude:claude-opus-4-7 +--- + tests/dns/deleg_test.c | 30 ++++++++++++++++++++++-------- + 1 file changed, 22 insertions(+), 8 deletions(-) + +diff --git a/tests/dns/deleg_test.c b/tests/dns/deleg_test.c +index d3af6aba966..9497caf2753 100644 +--- a/tests/dns/deleg_test.c ++++ b/tests/dns/deleg_test.c +@@ -52,6 +52,15 @@ isc_stdtime_now(void) { + + #include + ++/* ++ * cleanuptests adds NENTRIES address entries to a delegset; each is an ++ * isc_netaddrlink_t whose size depends on sizeof(void *) via ISC_LINK. ++ * Express memory expectations in terms of that struct so the test works ++ * on both 32-bit and 64-bit targets. ++ */ ++#define NENTRIES 99999 ++#define ENTRIES_MEM(n) ((size_t)(n) * sizeof(isc_netaddrlink_t)) ++ + static void + shutdownloop(ISC_ATTR_UNUSED void *arg) { + isc_loopmgr_shutdown(); +@@ -587,7 +596,8 @@ cleanuptests_phase3(void *arg) { + dns_delegset_t *delegset = NULL; + isc_result_t result; + +- assert_int_in_range(isc_mem_inuse(db->mctx), 8000000, 8100000); ++ assert_int_in_range(isc_mem_inuse(db->mctx), ENTRIES_MEM(2 * NENTRIES), ++ ENTRIES_MEM(2 * NENTRIES) + 100000); + + /* + * baz. is there, but bar. is gone, as it has been +@@ -612,7 +622,8 @@ cleanuptests_phase2(void *arg) { + dns_delegset_t *delegset = NULL; + isc_result_t result; + +- assert_int_in_range(isc_mem_inuse(db->mctx), 4000000, 4100000); ++ assert_int_in_range(isc_mem_inuse(db->mctx), ENTRIES_MEM(NENTRIES), ++ ENTRIES_MEM(NENTRIES) + 100000); + + /* + * bar. is there +@@ -629,10 +640,11 @@ cleanuptests_phase2(void *arg) { + dns_delegset_allocdeleg(delegset, DNS_DELEGTYPE_DELEG_ADDRESSES, + &deleg); + +- for (size_t i = 0; i < 99999; i++) { ++ for (size_t i = 0; i < NENTRIES; i++) { + addipdeleg(AF_INET6, "1111::2222", delegset, deleg); + } +- assert_int_in_range(isc_mem_inuse(db->mctx), 8000000, 8100000); ++ assert_int_in_range(isc_mem_inuse(db->mctx), ENTRIES_MEM(2 * NENTRIES), ++ ENTRIES_MEM(2 * NENTRIES) + 100000); + writedb(db, "baz.", 30, &delegset, true); + deleg = NULL; + +@@ -677,11 +689,12 @@ cleanuptests(ISC_ATTR_UNUSED void *arg) { + + assert_int_in_range(isc_mem_inuse(db->mctx), 500, 2000); + +- for (size_t i = 0; i < 99999; i++) { ++ for (size_t i = 0; i < NENTRIES; i++) { + addipdeleg(AF_INET6, "1111::2222", delegset, deleg); + } + +- assert_int_in_range(isc_mem_inuse(db->mctx), 4000000, 4100000); ++ assert_int_in_range(isc_mem_inuse(db->mctx), ENTRIES_MEM(NENTRIES), ++ ENTRIES_MEM(NENTRIES) + 100000); + + writedb(db, "stuff.", 10, &delegset, true); + deleg = NULL; +@@ -694,7 +707,7 @@ cleanuptests(ISC_ATTR_UNUSED void *arg) { + dns_delegset_allocdeleg(delegset, DNS_DELEGTYPE_DELEG_ADDRESSES, + &deleg); + +- for (size_t i = 0; i < 99999; i++) { ++ for (size_t i = 0; i < NENTRIES; i++) { + addipdeleg(AF_INET6, "1111::2222", delegset, deleg); + } + +@@ -703,7 +716,8 @@ cleanuptests(ISC_ATTR_UNUSED void *arg) { + * with DB mem context) overmem conditions will be detected, and the + * expired node will be removed + */ +- assert_int_in_range(isc_mem_inuse(db->mctx), 8000000, 8100000); ++ assert_int_in_range(isc_mem_inuse(db->mctx), ENTRIES_MEM(2 * NENTRIES), ++ ENTRIES_MEM(2 * NENTRIES) + 100000); + writedb(db, "bar.", 30, &delegset, true); + deleg = NULL; + +-- +2.54.0 + diff --git a/bind9-next.spec b/bind9-next.spec index 5d27915..10c8946 100644 --- a/bind9-next.spec +++ b/bind9-next.spec @@ -17,11 +17,11 @@ # Do not set CI environment, include more unit tests, even less stable %bcond_with UNITTEST_ALL %bcond_without DNSTAP -%bcond_without LMDB %bcond_without DOC %bcond_with TSAN %bcond_without DTRACE %bcond_with OPENSSL_ENGINE +%bcond JEMALLOC 0%{?fedora} %{?!bind_uid: %global bind_uid 25} %{?!bind_gid: %global bind_gid 25} @@ -30,7 +30,9 @@ %global chroot_prefix %{bind_dir}/chroot %global chroot_create_directories /dev /run/named %{_localstatedir}/{log,named,tmp} \\\ %{_sysconfdir}/{crypto-policies/back-ends,pki/dnssec-keys,pki/tls,named} \\\ - %{_libdir}/bind %{_libdir}/named %{_datadir}/GeoIP /proc/sys/net/ipv4 + %{_libdir}/bind %{_libdir}/named %{_datadir}/{GeoIP,dns-root-data} /proc/sys/net/ipv4 +%global upstream_sources 0 2 +%global pgp_signed_sources 2 %global forgeurl0 https://gitlab.isc.org/isc-projects/bind9 @@ -52,7 +54,7 @@ Summary: The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) serv Name: bind9-next License: MPL-2.0 AND ISC AND BSD-3-clause AND MIT AND BSD-2-clause # -Version: 9.21.14 +Version: 9.21.22 Release: %autorelease Epoch: 32 Url: https://www.isc.org/downloads/bind/ @@ -64,17 +66,13 @@ Source2: https://downloads.isc.org/isc/bind9/%{version}/%{upname}-%{version}.ta Source3: named.logrotate Source4: https://www.isc.org/docs/isc-keyblock.asc Source16: named.conf -# Refresh by command: dig @a.root-servers.net. +tcp +norec -# or from URL -Source17: https://www.internic.net/domain/named.root Source18: named.localhost Source19: named.loopback Source20: named.empty Source23: named.rfc1912.zones Source25: named.conf.sample -Source27: named.root.key +Source27: named-mkroot.sh Source35: bind.tmpfiles.d -Source36: trusted-key.key Source37: named.service Source38: named-chroot.service Source41: setup-named-chroot.sh @@ -93,14 +91,15 @@ Patch3: bind-9.21-unittest-isc_rwlock-s390x.patch # https://gitlab.isc.org/isc-projects/bind9/-/issues/5328 # avoid often fails on i386, unsupported upstream Patch4: bind-9.21-unittest-qpdb-i386.patch -Patch5: bind-9.21-dual-sign-continue.patch -Patch6: bind-9.21-dual-sign-continue-test.patch +# https://gitlab.isc.org/isc-projects/bind9/-/merge_requests/12061 +Patch5: bind-9.21-unittest-32b-mem.patch %{?systemd_ordering} Requires: coreutils Requires(post): shadow-utils Requires(post): glibc-common Requires(post): grep +Requires: dns-root-data Requires: %{name}-libs%{?_isa} = %{epoch}:%{version}-%{release} Recommends: %{name}-utils %{name}-dnssec-utils %upname_compat %{upname} @@ -111,32 +110,36 @@ BuildRequires: gcc BuildRequires: make BuildRequires: openssl-devel BuildRequires: libtool -BuildRequires: meson +BuildRequires: meson >= 1.3.0 BuildRequires: ninja-build BuildRequires: pkgconfig -BuildRequires: libcap-devel -BuildRequires: libidn2-devel -BuildRequires: libxml2-devel +BuildRequires: pkgconfig(libcap) +BuildRequires: pkgconfig(libidn2) +BuildRequires: pkgconfig(libxml-2.0) BuildRequires: systemd-rpm-macros BuildRequires: selinux-policy BuildRequires: findutils BuildRequires: sed -BuildRequires: libnghttp2-devel -BuildRequires: userspace-rcu-devel +BuildRequires: pkgconfig(libnghttp2) +BuildRequires: pkgconfig(liburcu) BuildRequires: pkgconfig(libedit) +BuildRequires: dns-root-data # Compress the changelog BuildRequires: gzip -%if 0%{?fedora} -BuildRequires: jemalloc-devel -BuildRequires: gnupg2 +BuildRequires: pkgconfig(lmdb) +%if %{with JEMALLOC} +BuildRequires: pkgconfig(jemalloc) %endif -BuildRequires: libuv-devel +%if ! 0%{?rhel} +BuildRequires: gpgverify +%endif +BuildRequires: pkgconfig(libuv) %if %{with OPENSSL_ENGINE} BuildRequires: openssl-devel-engine %endif %if %{with UNITTEST} # make unit dependencies -BuildRequires: libcmocka-devel +BuildRequires: pkgconfig(cmocka) # Ensure we have lscpu BuildRequires: util-linux # Catch failing unittests coredumps @@ -151,9 +154,13 @@ BuildRequires: softhsm BuildRequires: perl(Net::DNS) perl(Net::DNS::Nameserver) perl(Time::HiRes) perl(Getopt::Long) BuildRequires: perl(English) BuildRequires: python3-pytest +BuildRequires: python3-pytest-xdist +BuildRequires: python3-dns +BuildRequires: python3-hypothesis # manual configuration requires this tool BuildRequires: iproute BuildRequires: python3-jinja2 +BuildRequires: lmdb-devel %if %{with SUDO} BuildRequires: libcap sudo %endif @@ -161,9 +168,6 @@ BuildRequires: libcap sudo %if %{with GSSTSIG} BuildRequires: krb5-devel %endif -%if %{with LMDB} -BuildRequires: lmdb-devel -%endif %if %{with JSON} BuildRequires: json-c-devel %endif @@ -246,15 +250,14 @@ Summary: Header files and libraries needed for bind-dyndb-ldap Provides: %{name}-lite-devel = %{epoch}:%{version}-%{release} Obsoletes: %{name}-lite-devel < 32:9.16.6-3 Requires: %{name}-libs%{?_isa} = %{epoch}:%{version}-%{release} -Requires: openssl-devel%{?_isa} libxml2-devel%{?_isa} +Requires: openssl-devel%{?_isa} +Requires: libxml2-devel%{?_isa} Requires: libcap-devel%{?_isa} +Requires: lmdb-devel%{?_isa} %upname_compat %{upname}-devel %if %{with GSSTSIG} Requires: krb5-devel%{?_isa} %endif -%if %{with LMDB} -Requires: lmdb-devel%{?_isa} -%endif %if %{with JSON} Requires: json-c-devel%{?_isa} %endif @@ -303,8 +306,8 @@ in HTML and PDF format. %endif %prep -%if 0%{?fedora} -# RHEL does not yet support this verification +%if ! 0%{?rhel} || 0%{?rhel} > 10 +# RHEL does not (again?) support this verification %{gpgverify} --keyring='%{SOURCE4}' --signature='%{SOURCE2}' --data='%{SOURCE0}' %endif %autosetup -n %{upname}-%{version} -p1 @@ -347,6 +350,10 @@ export STD_CDEFINES="$CPPFLAGS" #'s/([bind_VERSION_EXTRA],\s*\([^)]*\))/([bind_VERSION_EXTRA], \1-RH)/' \ #configure.ac +install -p -m 0755 %{SOURCE27} ./named-mkroot.sh # create named.root.key +./named-mkroot.sh +[ -f named.root.key ] + LIBDIR_SUFFIX= export LIBDIR_SUFFIX @@ -364,11 +371,6 @@ export LIBDIR_SUFFIX %if %{with GSSTSIG} -Dgssapi=enabled \ %endif -%if %{with LMDB} - -Dlmdb=enabled \ -%else - -Dlmdb=disabled \ -%endif %if %{with JSON} -Dstats-json=enabled \ %endif @@ -381,6 +383,9 @@ export LIBDIR_SUFFIX %if %{with DOC} -Ddoc=enabled \ %endif +%if %{without JEMALLOC} + -Djemalloc=disabled \ +%endif ; %if %{with DNSTAP} pushd lib @@ -394,6 +399,9 @@ export LIBDIR_SUFFIX %if %{with DOC} %meson_build man arm arm-epub %endif +%if %{with SYSTEMTEST} + %meson_build system-test-dependencies +%endif # Compress changelog by default gzip doc/changelog/changelog-*.rst @@ -411,6 +419,10 @@ gzip doc/changelog/changelog-*.rst export TSAN_OPTIONS="log_exe_name=true log_path=ThreadSanitizer exitcode=0" %endif +# We produce it runtime. Check it has valid syntax. +LD_LIBRARY_PATH="$LD_LIBRARY_PATH:${RPM_BUILD_ROOT}%{_libdir}" \ + ${RPM_BUILD_ROOT}%{_bindir}/named-checkconf ${RPM_BUILD_ROOT}%{_sysconfdir}/named.root.key + %if %{with UNITTEST} CPUS=$(lscpu -p=cpu,core | grep -v '^#' | wc -l) THREADS="$CPUS" @@ -460,18 +472,23 @@ export TSAN_OPTIONS="log_exe_name=true log_path=ThreadSanitizer exitcode=0" if [ -n "$CONFIGURED" ] then - set -e - pushd bin/tests + pushd bin/tests/system export CI_SYSTEM=yes # allow running tests as root chown -R ${USER} . # Can be unknown user - %meson_build test 2>&1 | tee test.log - e=$? + e=0 + pytest -n ${THREADS} --capture=tee-sys || e=$? [ "$CONFIGURED" = build ] && $SUDO sh ./ifconfig.sh down - popd if [ "$e" -ne 0 ]; then - echo "ERROR: this build of BIND failed 'make test'. Aborting." + echo "ERROR: failed running 'pytest' in system tests. Aborting." + ls -1 "$(pwd)"/*_tmp_* + for TMPTEST in *_tmp_* + do + echo "# $TMPTEST" + cat $TMPTEST/pytest.log.txt + done exit $e; fi; + popd else echo 'SKIPPED: tests require root, CAP_NET_ADMIN or already configured test addresses.' fi @@ -536,9 +553,6 @@ find ${RPM_BUILD_ROOT}/%{_libdir} -name '*.la' -exec '/bin/rm' '-f' '{}' ';'; %if %{without DNSTAP} rm -f ${RPM_BUILD_ROOT}%{_mandir}/man1/dnstap-read.1* || true %endif -%if %{without LMDB} -rm -f ${RPM_BUILD_ROOT}%{_mandir}/man8/named-nzd2nzf.8* || true -%endif pushd ${RPM_BUILD_ROOT}%{_mandir}/man8 ln -s ddns-confgen.8.gz tsig-keygen.8.gz @@ -576,13 +590,13 @@ touch ${RPM_BUILD_ROOT}%{_localstatedir}/log/named.log # configuration files: install -m 640 %{SOURCE16} ${RPM_BUILD_ROOT}%{_sysconfdir}/named.conf touch ${RPM_BUILD_ROOT}%{_sysconfdir}/rndc.{key,conf} -install -m 644 %{SOURCE27} ${RPM_BUILD_ROOT}%{_sysconfdir}/named.root.key -install -m 644 %{SOURCE36} ${RPM_BUILD_ROOT}%{_sysconfdir}/trusted-key.key +install -m 644 -p named.root.key ${RPM_BUILD_ROOT}%{_sysconfdir}/named.root.key +ln -s "%{_datadir}/dns-root-data/root.key" ${RPM_BUILD_ROOT}%{_sysconfdir}/trusted-key.key mkdir -p ${RPM_BUILD_ROOT}%{_sysconfdir}/named # data files: mkdir -p ${RPM_BUILD_ROOT}%{_localstatedir}/named -install -m 640 %{SOURCE17} ${RPM_BUILD_ROOT}%{_localstatedir}/named/named.ca +ln -s "%{_datadir}/dns-root-data/root.hints" ${RPM_BUILD_ROOT}%{_localstatedir}/named/named.ca install -m 640 %{SOURCE18} ${RPM_BUILD_ROOT}%{_localstatedir}/named/named.localhost install -m 640 %{SOURCE19} ${RPM_BUILD_ROOT}%{_localstatedir}/named/named.loopback install -m 640 %{SOURCE20} ${RPM_BUILD_ROOT}%{_localstatedir}/named/named.empty @@ -595,7 +609,7 @@ install -m 644 %{SOURCE25} sample/etc/named.conf install -m 644 %{SOURCE16} named.conf.default install -m 644 %{SOURCE23} sample/etc/named.rfc1912.zones install -m 644 %{SOURCE18} %{SOURCE19} %{SOURCE20} sample/var/named -install -m 644 %{SOURCE17} sample/var/named/named.ca +ln -s "%{_datadir}/dns-root-data/root.hints" sample/var/named/named.ca for f in my.internal.zone.db slaves/my.slave.internal.zone.db slaves/my.ddns.internal.zone.db my.external.zone.db; do echo '@ in soa localhost. root 1 3H 15M 1W 1D ns localhost.' > sample/var/named/$f; @@ -792,10 +806,8 @@ fi; %{_bindir}/dnstap-read %{_mandir}/man1/dnstap-read.1* %endif -%if %{with LMDB} %{_bindir}/named-nzd2nzf %{_mandir}/man1/named-nzd2nzf.1* -%endif %{_mandir}/man1/host.1* %{_mandir}/man1/nsupdate.1* %{_mandir}/man1/dig.1* diff --git a/named-chroot.files b/named-chroot.files index c186664..c901664 100644 --- a/named-chroot.files +++ b/named-chroot.files @@ -18,6 +18,7 @@ /usr/lib64/bind /usr/lib/bind /usr/share/GeoIP +/usr/share/dns-root-data /run/named /proc/sys/net/ipv4/ip_local_port_range # Warning: the order is important diff --git a/named-mkroot.sh b/named-mkroot.sh new file mode 100755 index 0000000..288725b --- /dev/null +++ b/named-mkroot.sh @@ -0,0 +1,20 @@ +#!/bin/sh +# Create named.root.key from dns-root-data package + +ROOT_DS=/usr/share/dns-root-data/root.ds +: ${OUTPUT:=named.root.key} + +if ! [ -r "$ROOT_DS" ]; then + echo "Root trust file is not readable: $ROOT_DS" + exit 1 +fi + +echo "# Autogenerated from $ROOT_DS" > "$OUTPUT" +echo "trust-anchors {" >> "$OUTPUT" +cat "$ROOT_DS" | while read DOMAIN CLS QTYPE KEYTAG ALG DIG HASH; +do + echo "$DOMAIN initial-ds $KEYTAG $ALG $DIG \"$HASH\";" >> "$OUTPUT"; +done +echo "}; " >> "$OUTPUT" +# Set the same modification time as data source. +touch -r $ROOT_DS "$OUTPUT" diff --git a/named.root b/named.root deleted file mode 100644 index 8b8a3b1..0000000 --- a/named.root +++ /dev/null @@ -1,92 +0,0 @@ -; This file holds the information on root name servers needed to -; initialize cache of Internet domain name servers -; (e.g. reference this file in the "cache . " -; configuration file of BIND domain name servers). -; -; This file is made available by InterNIC -; under anonymous FTP as -; file /domain/named.cache -; on server FTP.INTERNIC.NET -; -OR- RS.INTERNIC.NET -; -; last update: December 20, 2023 -; related version of root zone: 2023122001 -; -; FORMERLY NS.INTERNIC.NET -; -. 3600000 NS A.ROOT-SERVERS.NET. -A.ROOT-SERVERS.NET. 3600000 A 198.41.0.4 -A.ROOT-SERVERS.NET. 3600000 AAAA 2001:503:ba3e::2:30 -; -; FORMERLY NS1.ISI.EDU -; -. 3600000 NS B.ROOT-SERVERS.NET. -B.ROOT-SERVERS.NET. 3600000 A 170.247.170.2 -B.ROOT-SERVERS.NET. 3600000 AAAA 2801:1b8:10::b -; -; FORMERLY C.PSI.NET -; -. 3600000 NS C.ROOT-SERVERS.NET. -C.ROOT-SERVERS.NET. 3600000 A 192.33.4.12 -C.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:2::c -; -; FORMERLY TERP.UMD.EDU -; -. 3600000 NS D.ROOT-SERVERS.NET. -D.ROOT-SERVERS.NET. 3600000 A 199.7.91.13 -D.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:2d::d -; -; FORMERLY NS.NASA.GOV -; -. 3600000 NS E.ROOT-SERVERS.NET. -E.ROOT-SERVERS.NET. 3600000 A 192.203.230.10 -E.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:a8::e -; -; FORMERLY NS.ISC.ORG -; -. 3600000 NS F.ROOT-SERVERS.NET. -F.ROOT-SERVERS.NET. 3600000 A 192.5.5.241 -F.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:2f::f -; -; FORMERLY NS.NIC.DDN.MIL -; -. 3600000 NS G.ROOT-SERVERS.NET. -G.ROOT-SERVERS.NET. 3600000 A 192.112.36.4 -G.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:12::d0d -; -; FORMERLY AOS.ARL.ARMY.MIL -; -. 3600000 NS H.ROOT-SERVERS.NET. -H.ROOT-SERVERS.NET. 3600000 A 198.97.190.53 -H.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:1::53 -; -; FORMERLY NIC.NORDU.NET -; -. 3600000 NS I.ROOT-SERVERS.NET. -I.ROOT-SERVERS.NET. 3600000 A 192.36.148.17 -I.ROOT-SERVERS.NET. 3600000 AAAA 2001:7fe::53 -; -; OPERATED BY VERISIGN, INC. -; -. 3600000 NS J.ROOT-SERVERS.NET. -J.ROOT-SERVERS.NET. 3600000 A 192.58.128.30 -J.ROOT-SERVERS.NET. 3600000 AAAA 2001:503:c27::2:30 -; -; OPERATED BY RIPE NCC -; -. 3600000 NS K.ROOT-SERVERS.NET. -K.ROOT-SERVERS.NET. 3600000 A 193.0.14.129 -K.ROOT-SERVERS.NET. 3600000 AAAA 2001:7fd::1 -; -; OPERATED BY ICANN -; -. 3600000 NS L.ROOT-SERVERS.NET. -L.ROOT-SERVERS.NET. 3600000 A 199.7.83.42 -L.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:9f::42 -; -; OPERATED BY WIDE -; -. 3600000 NS M.ROOT-SERVERS.NET. -M.ROOT-SERVERS.NET. 3600000 A 202.12.27.33 -M.ROOT-SERVERS.NET. 3600000 AAAA 2001:dc3::35 -; End of file \ No newline at end of file diff --git a/named.root.key b/named.root.key index b57e61d..6d0904d 100644 --- a/named.root.key +++ b/named.root.key @@ -1,18 +1,5 @@ -trust-anchors { - # ROOT KEYS: See https://data.iana.org/root-anchors/root-anchors.xml - # for current trust anchor information. - # - # This key (20326) was published in the root zone in 2017. - # Servers which were already using the old key (19036) should - # roll seamlessly to this new one via RFC 5011 rollover. Servers - # being set up for the first time can use the contents of this - # file as initializing keys; thereafter, the keys in the - # managed key database will be trusted and maintained - # automatically. - . initial-ds 20326 8 2 "E06D44B80B8F1D39A95C0B0D7C65D08458E880409BBC683457104237C7F8EC8D"; - # This key (38696) will be pre-published in the root zone in 2025 - # and is scheduled to begin signing in late 2026. At that time, - # servers which were already using the old key (20326) should roll - # seamlessly to this new one via RFC 5011 rollover. - . initial-ds 38696 8 2 "683D2D0ACB8C9B712A1948B27F741219298D0A450D612C483AF444A4C0FB2B16"; -}; +# Autogenerated from /usr/share/dns-root-data/root.ds +truste-anchors { +. initial-ds 20326 8 2 "E06D44B80B8F1D39A95C0B0D7C65D08458E880409BBC683457104237C7F8EC8D"; +. initial-ds 38696 8 2 "683D2D0ACB8C9B712A1948B27F741219298D0A450D612C483AF444A4C0FB2B16"; +}; diff --git a/sources b/sources index 714e4db..c97ab7f 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (bind-9.21.14.tar.xz) = bf4bd0f5613d6c6d53f749f3269a34f3a5c74a7dc81e05922d58ba30f19d418e565838dd1182dd6052b9a62b3799d2d0f12451f2797af3279259df59cfc4be05 -SHA512 (bind-9.21.14.tar.xz.asc) = 91ccc82ca54d07dba07821c3410f92b563290ead48546d605b0dbd9958a831d9b90130002fbb325e0cdc913de64813d8ba4c48ec958ebba7f5f462d43f578394 +SHA512 (bind-9.21.22.tar.xz) = f9e11d150162661c755dabdd7862c0565e6a10077e2a6aee04f8cefce94c262d8928ff9e42f8c8750242aee3b0992afe2f49f72f0f8cab8b7e4ae1c9fc06e0fa +SHA512 (bind-9.21.22.tar.xz.asc) = 1e0bd14fad5754e12b6a4855dbed698dba74468790948316e17442e5bc840fc81d18e590fd78186a1e26e9526870b13470dcef6a15644e91775cc8883813ad24 diff --git a/trusted-key.key b/trusted-key.key deleted file mode 100644 index 2ef50c7..0000000 --- a/trusted-key.key +++ /dev/null @@ -1,2 +0,0 @@ -. 3600 IN DNSKEY 257 3 8 AwEAAaz/tAm8yTn4Mfeh5eyI96WSVexTBAvkMgJzkKTOiW1vkIbzxeF3+/4RgWOq7HrxRixHlFlExOLAJr5emLvN7SWXgnLh4+B5xQlNVz8Og8kvArMtNROxVQuCaSnIDdD5LKyWbRd2n9WGe2R8PzgCmr3EgVLrjyBxWezF0jLHwVN8efS3rCj/EWgvIWgb9tarpVUDK/b58Da+sqqls3eNbuv7pr+eoZG+SrDK6nWeL3c6H5Apxz7LjVc1uTIdsIXxuOLYA4/ilBmSVIzuDWfdRUfhHdY6+cn8HFRm+2hM8AnXGXws9555KrUB5qihylGa8subX2Nn6UwNR1AkUTV74bU= -. 3600 IN DNSKEY 257 3 8 AwEAAa96jeuknZlaeSrvyAJj6ZHv28hhOKkx3rLGXVaC6rXTsDc449/cidltpkyGwCJNnOAlFNKF2jBosZBU5eeHspaQWOmOElZsjICMQMC3aeHbGiShvZsx4wMYSjH8e7Vrhbu6irwCzVBApESjbUdpWWmEnhathWu1jo+siFUiRAAxm9qyJNg/wOZqqzL/dL/q8PkcRU5oUKEpUge71M3ej2/7CPqpdVwuMoTvoB+ZOT4YeGyxMvHmbrxlFzGOHOijtzN+u1TQNatX2XBuzZNQ1K+s2CXkPIZo7s6JgZyvaBevYtxPvYLw4z9mR7K2vaF18UYH9Z9GNUUeayffKC73PYc=