Compare commits
13 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
25d3d5e459 | ||
|
|
8136762a95 | ||
|
|
a5bdfab2ad | ||
|
|
fd81016e5c | ||
|
|
fcdfc58880 | ||
|
|
d5c5c64bfb | ||
|
|
cfcac9d28d | ||
|
|
26f39c0b26 | ||
|
|
b8ee1a2044 | ||
|
|
584a3dff4f | ||
|
|
9315af6f9d | ||
|
|
b3bece5114 | ||
|
|
09e47bcad7 |
10 changed files with 202 additions and 321 deletions
|
|
@ -1,115 +0,0 @@
|
|||
From 488d7bfc75f2988c6e461b8677bc0e27e58bd82e Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Ond=C5=99ej=20Sur=C3=BD?= <ondrej@isc.org>
|
||||
Date: Sat, 1 Nov 2025 12:00:59 +0100
|
||||
Subject: [PATCH] Add a system test with one good and one bad algorithm
|
||||
|
||||
The case where there would be one supported algorithm and one already
|
||||
unsupported (like RSAMD5 or RSASHA1) was missing.
|
||||
---
|
||||
bin/tests/system/dnssec/ns2/example.db.in | 4 +++
|
||||
bin/tests/system/dnssec/ns2/sign.sh | 2 +-
|
||||
bin/tests/system/dnssec/ns3/named.conf.j2 | 6 ++++
|
||||
bin/tests/system/dnssec/ns3/sign.sh | 31 +++++++++++++++++++++
|
||||
bin/tests/system/dnssec/tests_validation.py | 8 ++++++
|
||||
5 files changed, 50 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/bin/tests/system/dnssec/ns2/example.db.in b/bin/tests/system/dnssec/ns2/example.db.in
|
||||
index 47c2eb7f0e..07429366ee 100644
|
||||
--- a/bin/tests/system/dnssec/ns2/example.db.in
|
||||
+++ b/bin/tests/system/dnssec/ns2/example.db.in
|
||||
@@ -202,3 +202,7 @@ ns3.extradsunknownoid A 10.53.0.3
|
||||
|
||||
extended-ds-unknown-oid NS ns3.extended-ds-unknown-oid
|
||||
ns3.extended-ds-unknown-oid A 10.53.0.3
|
||||
+
|
||||
+; A secure subdomain with extra bad key
|
||||
+extrabadkey NS ns3.extrabadkey
|
||||
+ns3.extrabadkey A 10.53.0.3
|
||||
diff --git a/bin/tests/system/dnssec/ns2/sign.sh b/bin/tests/system/dnssec/ns2/sign.sh
|
||||
index e3f18af15e..da9f5f07fc 100644
|
||||
--- a/bin/tests/system/dnssec/ns2/sign.sh
|
||||
+++ b/bin/tests/system/dnssec/ns2/sign.sh
|
||||
@@ -92,7 +92,7 @@ for subdomain in digest-alg-unsupported ds-unsupported secure badds \
|
||||
dnskey-nsec3-unknown managed-future future revkey \
|
||||
dname-at-apex-nsec3 occluded rsasha1 rsasha1-1024 \
|
||||
rsasha256oid rsasha512oid unknownoid extradsoid extradsunknownoid \
|
||||
- extended-ds-unknown-oid; do
|
||||
+ extended-ds-unknown-oid extrabadkey; do
|
||||
cp "../ns3/dsset-$subdomain.example." .
|
||||
done
|
||||
|
||||
diff --git a/bin/tests/system/dnssec/ns3/named.conf.j2 b/bin/tests/system/dnssec/ns3/named.conf.j2
|
||||
index 1a0edc14bb..9cbc58892c 100644
|
||||
--- a/bin/tests/system/dnssec/ns3/named.conf.j2
|
||||
+++ b/bin/tests/system/dnssec/ns3/named.conf.j2
|
||||
@@ -141,6 +141,12 @@ zone "extrakey.example" {
|
||||
allow-update { any; };
|
||||
};
|
||||
|
||||
+zone "extrabadkey.example" {
|
||||
+ type primary;
|
||||
+ file "extrabadkey.example.db.signed";
|
||||
+ allow-update { any; };
|
||||
+};
|
||||
+
|
||||
zone "insecure.nsec3.example" {
|
||||
type primary;
|
||||
file "insecure.nsec3.example.db";
|
||||
diff --git a/bin/tests/system/dnssec/ns3/sign.sh b/bin/tests/system/dnssec/ns3/sign.sh
|
||||
index 5512888b2f..ea81381eb2 100644
|
||||
--- a/bin/tests/system/dnssec/ns3/sign.sh
|
||||
+++ b/bin/tests/system/dnssec/ns3/sign.sh
|
||||
@@ -905,3 +905,34 @@ ksk=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -f KSK "$zone")
|
||||
zsk=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" "$zone")
|
||||
cat "$infile" "$ksk.key" "$zsk.key" >"$zonefile"
|
||||
"$SIGNER" -g -o "$zone" "$zonefile" >/dev/null 2>&1
|
||||
+
|
||||
+#
|
||||
+#
|
||||
+#
|
||||
+zone=extrabadkey.example.
|
||||
+infile=template.db.in
|
||||
+zonefile=extrabadkey.example.db
|
||||
+
|
||||
+# Add KSK and ZSK that we will mangle to RSAMD5
|
||||
+ksk=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -f KSK "$zone")
|
||||
+zsk=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" "$zone")
|
||||
+cat "$infile" "$ksk.key" "$zsk.key" >"$zonefile"
|
||||
+"$SIGNER" -g -O full -o "$zone" "$zonefile" >/dev/null 2>&1
|
||||
+
|
||||
+# Mangle the signatures to RSAMD5 and save them for future use
|
||||
+sed -ne "s/\(IN[[:space:]]*RRSIG[[:space:]]*[A-Z]*\) $DEFAULT_ALGORITHM_NUMBER /\1 1 /p" <"$zonefile.signed" >"$zonefile.signed.rsamd5"
|
||||
+
|
||||
+# Now add normal KSK and ZSK to the zone file
|
||||
+ksk=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -f KSK "$zone")
|
||||
+zsk=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" "$zone")
|
||||
+cat "$infile" "$ksk.key" "$zsk.key" >"$zonefile"
|
||||
+
|
||||
+# Mangle the DNSKEY algorithm numbers and add them to the signed zone file
|
||||
+cat "$ksk.key" "$zsk.key" | sed -e "s/\(IN[[:space:]]*DNSKEY[[:space:]]*[0-9]* 3\) $DEFAULT_ALGORITHM_NUMBER /\1 1 /" >>"$zonefile"
|
||||
+
|
||||
+# Sign normally
|
||||
+"$SIGNER" -g -o "$zone" "$zonefile" >/dev/null 2>&1
|
||||
+
|
||||
+# Add the mangled signatures to signed zone file
|
||||
+cat "$zonefile.signed.rsamd5" >>"$zonefile.signed"
|
||||
+rm "$zonefile.signed.rsamd5"
|
||||
diff --git a/bin/tests/system/dnssec/tests_validation.py b/bin/tests/system/dnssec/tests_validation.py
|
||||
index e6d8ccc734..a27a899987 100644
|
||||
--- a/bin/tests/system/dnssec/tests_validation.py
|
||||
+++ b/bin/tests/system/dnssec/tests_validation.py
|
||||
@@ -1385,3 +1385,11 @@ def test_rrsigs_for_glue():
|
||||
record.rdtype == rdatatype.RRSIG and record.covers == rdatatype.A
|
||||
for record in res.answer
|
||||
)
|
||||
+
|
||||
+
|
||||
+def test_extra_bad_algorithm():
|
||||
+ msg = isctest.query.create("a.extrabadkey.example", "A")
|
||||
+ res1 = isctest.query.tcp(msg, "10.53.0.3")
|
||||
+ res2 = isctest.query.tcp(msg, "10.53.0.4")
|
||||
+ isctest.check.same_answer(res1, res2)
|
||||
+ isctest.check.adflag(res2)
|
||||
--
|
||||
2.51.1
|
||||
|
||||
|
|
@ -1,42 +0,0 @@
|
|||
From a94a7c1a1e6eecbead995a08bace33d23899a5da Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Ond=C5=99ej=20Sur=C3=BD?= <ondrej@isc.org>
|
||||
Date: Tue, 4 Nov 2025 02:09:38 +0100
|
||||
Subject: [PATCH] Skip unsupported algorithms when looking for signing key
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
When looking for a signing key in select_signing_key(), the result code
|
||||
indicating unsupported algorithm would abort the search. Instead, skip
|
||||
such keys and continue searching for the right key.
|
||||
|
||||
Co-Authored-By: Aram Sargsyan <aram@isc.org>
|
||||
Co-Authored-By: Petr Menšík <pemensik@redhat.com>
|
||||
---
|
||||
lib/dns/validator.c | 10 ++++++++--
|
||||
1 file changed, 8 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/lib/dns/validator.c b/lib/dns/validator.c
|
||||
index c6781544b9..52677fbd80 100644
|
||||
--- a/lib/dns/validator.c
|
||||
+++ b/lib/dns/validator.c
|
||||
@@ -1092,8 +1092,14 @@ select_signing_key(dns_validator_t *val, dns_rdataset_t *rdataset) {
|
||||
continue;
|
||||
}
|
||||
|
||||
- return dns_dnssec_keyfromrdata(&siginfo->signer, &rdata,
|
||||
- val->view->mctx, &val->key);
|
||||
+ result = dns_dnssec_keyfromrdata(&siginfo->signer, &rdata,
|
||||
+ val->view->mctx, &val->key);
|
||||
+ /* Don't count unsupported algorithm towards max fails */
|
||||
+ if (result == DST_R_UNSUPPORTEDALG) {
|
||||
+ /* Continue with the next key */
|
||||
+ continue;
|
||||
+ }
|
||||
+ return result;
|
||||
}
|
||||
|
||||
return ISC_R_NOTFOUND;
|
||||
--
|
||||
2.51.1
|
||||
|
||||
112
bind-9.21-unittest-32b-mem.patch
Normal file
112
bind-9.21-unittest-32b-mem.patch
Normal file
|
|
@ -0,0 +1,112 @@
|
|||
From 4623873e588c86c6add4d53708e754e2d6f3e087 Mon Sep 17 00:00:00 2001
|
||||
From: Michal Nowak <mnowak@isc.org>
|
||||
Date: Wed, 20 May 2026 08:59:49 +0000
|
||||
Subject: [PATCH] Make deleg cleanuptests memory assertions 32-bit-safe
|
||||
|
||||
Each address entry stored by dns_delegset_addaddr() is an
|
||||
isc_netaddrlink_t, whose size depends on sizeof(void *) via the
|
||||
ISC_LINK macro (24 bytes of address + two prev/next pointers): 40
|
||||
bytes on 64-bit, 32 bytes on 32-bit. The hardcoded 4 MB / 8 MB
|
||||
ranges only held on 64-bit, so dns_deleg_cleanuptests failed on
|
||||
armv7l with isc_mem_inuse() returning ~3.2 MB.
|
||||
|
||||
Express the expected ranges in terms of sizeof(isc_netaddrlink_t)
|
||||
so they scale with pointer width, and pull the 99999 entry count
|
||||
out into a NENTRIES macro.
|
||||
|
||||
Assisted-by: Claude:claude-opus-4-7
|
||||
---
|
||||
tests/dns/deleg_test.c | 30 ++++++++++++++++++++++--------
|
||||
1 file changed, 22 insertions(+), 8 deletions(-)
|
||||
|
||||
diff --git a/tests/dns/deleg_test.c b/tests/dns/deleg_test.c
|
||||
index d3af6aba966..9497caf2753 100644
|
||||
--- a/tests/dns/deleg_test.c
|
||||
+++ b/tests/dns/deleg_test.c
|
||||
@@ -52,6 +52,15 @@ isc_stdtime_now(void) {
|
||||
|
||||
#include <tests/isc.h>
|
||||
|
||||
+/*
|
||||
+ * cleanuptests adds NENTRIES address entries to a delegset; each is an
|
||||
+ * isc_netaddrlink_t whose size depends on sizeof(void *) via ISC_LINK.
|
||||
+ * Express memory expectations in terms of that struct so the test works
|
||||
+ * on both 32-bit and 64-bit targets.
|
||||
+ */
|
||||
+#define NENTRIES 99999
|
||||
+#define ENTRIES_MEM(n) ((size_t)(n) * sizeof(isc_netaddrlink_t))
|
||||
+
|
||||
static void
|
||||
shutdownloop(ISC_ATTR_UNUSED void *arg) {
|
||||
isc_loopmgr_shutdown();
|
||||
@@ -587,7 +596,8 @@ cleanuptests_phase3(void *arg) {
|
||||
dns_delegset_t *delegset = NULL;
|
||||
isc_result_t result;
|
||||
|
||||
- assert_int_in_range(isc_mem_inuse(db->mctx), 8000000, 8100000);
|
||||
+ assert_int_in_range(isc_mem_inuse(db->mctx), ENTRIES_MEM(2 * NENTRIES),
|
||||
+ ENTRIES_MEM(2 * NENTRIES) + 100000);
|
||||
|
||||
/*
|
||||
* baz. is there, but bar. is gone, as it has been
|
||||
@@ -612,7 +622,8 @@ cleanuptests_phase2(void *arg) {
|
||||
dns_delegset_t *delegset = NULL;
|
||||
isc_result_t result;
|
||||
|
||||
- assert_int_in_range(isc_mem_inuse(db->mctx), 4000000, 4100000);
|
||||
+ assert_int_in_range(isc_mem_inuse(db->mctx), ENTRIES_MEM(NENTRIES),
|
||||
+ ENTRIES_MEM(NENTRIES) + 100000);
|
||||
|
||||
/*
|
||||
* bar. is there
|
||||
@@ -629,10 +640,11 @@ cleanuptests_phase2(void *arg) {
|
||||
dns_delegset_allocdeleg(delegset, DNS_DELEGTYPE_DELEG_ADDRESSES,
|
||||
&deleg);
|
||||
|
||||
- for (size_t i = 0; i < 99999; i++) {
|
||||
+ for (size_t i = 0; i < NENTRIES; i++) {
|
||||
addipdeleg(AF_INET6, "1111::2222", delegset, deleg);
|
||||
}
|
||||
- assert_int_in_range(isc_mem_inuse(db->mctx), 8000000, 8100000);
|
||||
+ assert_int_in_range(isc_mem_inuse(db->mctx), ENTRIES_MEM(2 * NENTRIES),
|
||||
+ ENTRIES_MEM(2 * NENTRIES) + 100000);
|
||||
writedb(db, "baz.", 30, &delegset, true);
|
||||
deleg = NULL;
|
||||
|
||||
@@ -677,11 +689,12 @@ cleanuptests(ISC_ATTR_UNUSED void *arg) {
|
||||
|
||||
assert_int_in_range(isc_mem_inuse(db->mctx), 500, 2000);
|
||||
|
||||
- for (size_t i = 0; i < 99999; i++) {
|
||||
+ for (size_t i = 0; i < NENTRIES; i++) {
|
||||
addipdeleg(AF_INET6, "1111::2222", delegset, deleg);
|
||||
}
|
||||
|
||||
- assert_int_in_range(isc_mem_inuse(db->mctx), 4000000, 4100000);
|
||||
+ assert_int_in_range(isc_mem_inuse(db->mctx), ENTRIES_MEM(NENTRIES),
|
||||
+ ENTRIES_MEM(NENTRIES) + 100000);
|
||||
|
||||
writedb(db, "stuff.", 10, &delegset, true);
|
||||
deleg = NULL;
|
||||
@@ -694,7 +707,7 @@ cleanuptests(ISC_ATTR_UNUSED void *arg) {
|
||||
dns_delegset_allocdeleg(delegset, DNS_DELEGTYPE_DELEG_ADDRESSES,
|
||||
&deleg);
|
||||
|
||||
- for (size_t i = 0; i < 99999; i++) {
|
||||
+ for (size_t i = 0; i < NENTRIES; i++) {
|
||||
addipdeleg(AF_INET6, "1111::2222", delegset, deleg);
|
||||
}
|
||||
|
||||
@@ -703,7 +716,8 @@ cleanuptests(ISC_ATTR_UNUSED void *arg) {
|
||||
* with DB mem context) overmem conditions will be detected, and the
|
||||
* expired node will be removed
|
||||
*/
|
||||
- assert_int_in_range(isc_mem_inuse(db->mctx), 8000000, 8100000);
|
||||
+ assert_int_in_range(isc_mem_inuse(db->mctx), ENTRIES_MEM(2 * NENTRIES),
|
||||
+ ENTRIES_MEM(2 * NENTRIES) + 100000);
|
||||
writedb(db, "bar.", 30, &delegset, true);
|
||||
deleg = NULL;
|
||||
|
||||
--
|
||||
2.54.0
|
||||
|
||||
112
bind9-next.spec
112
bind9-next.spec
|
|
@ -17,11 +17,11 @@
|
|||
# Do not set CI environment, include more unit tests, even less stable
|
||||
%bcond_with UNITTEST_ALL
|
||||
%bcond_without DNSTAP
|
||||
%bcond_without LMDB
|
||||
%bcond_without DOC
|
||||
%bcond_with TSAN
|
||||
%bcond_without DTRACE
|
||||
%bcond_with OPENSSL_ENGINE
|
||||
%bcond JEMALLOC 0%{?fedora}
|
||||
|
||||
%{?!bind_uid: %global bind_uid 25}
|
||||
%{?!bind_gid: %global bind_gid 25}
|
||||
|
|
@ -30,7 +30,9 @@
|
|||
%global chroot_prefix %{bind_dir}/chroot
|
||||
%global chroot_create_directories /dev /run/named %{_localstatedir}/{log,named,tmp} \\\
|
||||
%{_sysconfdir}/{crypto-policies/back-ends,pki/dnssec-keys,pki/tls,named} \\\
|
||||
%{_libdir}/bind %{_libdir}/named %{_datadir}/GeoIP /proc/sys/net/ipv4
|
||||
%{_libdir}/bind %{_libdir}/named %{_datadir}/{GeoIP,dns-root-data} /proc/sys/net/ipv4
|
||||
%global upstream_sources 0 2
|
||||
%global pgp_signed_sources 2
|
||||
|
||||
%global forgeurl0 https://gitlab.isc.org/isc-projects/bind9
|
||||
|
||||
|
|
@ -52,7 +54,7 @@ Summary: The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) serv
|
|||
Name: bind9-next
|
||||
License: MPL-2.0 AND ISC AND BSD-3-clause AND MIT AND BSD-2-clause
|
||||
#
|
||||
Version: 9.21.14
|
||||
Version: 9.21.22
|
||||
Release: %autorelease
|
||||
Epoch: 32
|
||||
Url: https://www.isc.org/downloads/bind/
|
||||
|
|
@ -64,17 +66,13 @@ Source2: https://downloads.isc.org/isc/bind9/%{version}/%{upname}-%{version}.ta
|
|||
Source3: named.logrotate
|
||||
Source4: https://www.isc.org/docs/isc-keyblock.asc
|
||||
Source16: named.conf
|
||||
# Refresh by command: dig @a.root-servers.net. +tcp +norec
|
||||
# or from URL
|
||||
Source17: https://www.internic.net/domain/named.root
|
||||
Source18: named.localhost
|
||||
Source19: named.loopback
|
||||
Source20: named.empty
|
||||
Source23: named.rfc1912.zones
|
||||
Source25: named.conf.sample
|
||||
Source27: named.root.key
|
||||
Source27: named-mkroot.sh
|
||||
Source35: bind.tmpfiles.d
|
||||
Source36: trusted-key.key
|
||||
Source37: named.service
|
||||
Source38: named-chroot.service
|
||||
Source41: setup-named-chroot.sh
|
||||
|
|
@ -93,14 +91,15 @@ Patch3: bind-9.21-unittest-isc_rwlock-s390x.patch
|
|||
# https://gitlab.isc.org/isc-projects/bind9/-/issues/5328
|
||||
# avoid often fails on i386, unsupported upstream
|
||||
Patch4: bind-9.21-unittest-qpdb-i386.patch
|
||||
Patch5: bind-9.21-dual-sign-continue.patch
|
||||
Patch6: bind-9.21-dual-sign-continue-test.patch
|
||||
# https://gitlab.isc.org/isc-projects/bind9/-/merge_requests/12061
|
||||
Patch5: bind-9.21-unittest-32b-mem.patch
|
||||
|
||||
%{?systemd_ordering}
|
||||
Requires: coreutils
|
||||
Requires(post): shadow-utils
|
||||
Requires(post): glibc-common
|
||||
Requires(post): grep
|
||||
Requires: dns-root-data
|
||||
Requires: %{name}-libs%{?_isa} = %{epoch}:%{version}-%{release}
|
||||
Recommends: %{name}-utils %{name}-dnssec-utils
|
||||
%upname_compat %{upname}
|
||||
|
|
@ -111,32 +110,36 @@ BuildRequires: gcc
|
|||
BuildRequires: make
|
||||
BuildRequires: openssl-devel
|
||||
BuildRequires: libtool
|
||||
BuildRequires: meson
|
||||
BuildRequires: meson >= 1.3.0
|
||||
BuildRequires: ninja-build
|
||||
BuildRequires: pkgconfig
|
||||
BuildRequires: libcap-devel
|
||||
BuildRequires: libidn2-devel
|
||||
BuildRequires: libxml2-devel
|
||||
BuildRequires: pkgconfig(libcap)
|
||||
BuildRequires: pkgconfig(libidn2)
|
||||
BuildRequires: pkgconfig(libxml-2.0)
|
||||
BuildRequires: systemd-rpm-macros
|
||||
BuildRequires: selinux-policy
|
||||
BuildRequires: findutils
|
||||
BuildRequires: sed
|
||||
BuildRequires: libnghttp2-devel
|
||||
BuildRequires: userspace-rcu-devel
|
||||
BuildRequires: pkgconfig(libnghttp2)
|
||||
BuildRequires: pkgconfig(liburcu)
|
||||
BuildRequires: pkgconfig(libedit)
|
||||
BuildRequires: dns-root-data
|
||||
# Compress the changelog
|
||||
BuildRequires: gzip
|
||||
%if 0%{?fedora}
|
||||
BuildRequires: jemalloc-devel
|
||||
BuildRequires: gnupg2
|
||||
BuildRequires: pkgconfig(lmdb)
|
||||
%if %{with JEMALLOC}
|
||||
BuildRequires: pkgconfig(jemalloc)
|
||||
%endif
|
||||
BuildRequires: libuv-devel
|
||||
%if ! 0%{?rhel}
|
||||
BuildRequires: gpgverify
|
||||
%endif
|
||||
BuildRequires: pkgconfig(libuv)
|
||||
%if %{with OPENSSL_ENGINE}
|
||||
BuildRequires: openssl-devel-engine
|
||||
%endif
|
||||
%if %{with UNITTEST}
|
||||
# make unit dependencies
|
||||
BuildRequires: libcmocka-devel
|
||||
BuildRequires: pkgconfig(cmocka)
|
||||
# Ensure we have lscpu
|
||||
BuildRequires: util-linux
|
||||
# Catch failing unittests coredumps
|
||||
|
|
@ -151,9 +154,13 @@ BuildRequires: softhsm
|
|||
BuildRequires: perl(Net::DNS) perl(Net::DNS::Nameserver) perl(Time::HiRes) perl(Getopt::Long)
|
||||
BuildRequires: perl(English)
|
||||
BuildRequires: python3-pytest
|
||||
BuildRequires: python3-pytest-xdist
|
||||
BuildRequires: python3-dns
|
||||
BuildRequires: python3-hypothesis
|
||||
# manual configuration requires this tool
|
||||
BuildRequires: iproute
|
||||
BuildRequires: python3-jinja2
|
||||
BuildRequires: lmdb-devel
|
||||
%if %{with SUDO}
|
||||
BuildRequires: libcap sudo
|
||||
%endif
|
||||
|
|
@ -161,9 +168,6 @@ BuildRequires: libcap sudo
|
|||
%if %{with GSSTSIG}
|
||||
BuildRequires: krb5-devel
|
||||
%endif
|
||||
%if %{with LMDB}
|
||||
BuildRequires: lmdb-devel
|
||||
%endif
|
||||
%if %{with JSON}
|
||||
BuildRequires: json-c-devel
|
||||
%endif
|
||||
|
|
@ -246,15 +250,14 @@ Summary: Header files and libraries needed for bind-dyndb-ldap
|
|||
Provides: %{name}-lite-devel = %{epoch}:%{version}-%{release}
|
||||
Obsoletes: %{name}-lite-devel < 32:9.16.6-3
|
||||
Requires: %{name}-libs%{?_isa} = %{epoch}:%{version}-%{release}
|
||||
Requires: openssl-devel%{?_isa} libxml2-devel%{?_isa}
|
||||
Requires: openssl-devel%{?_isa}
|
||||
Requires: libxml2-devel%{?_isa}
|
||||
Requires: libcap-devel%{?_isa}
|
||||
Requires: lmdb-devel%{?_isa}
|
||||
%upname_compat %{upname}-devel
|
||||
%if %{with GSSTSIG}
|
||||
Requires: krb5-devel%{?_isa}
|
||||
%endif
|
||||
%if %{with LMDB}
|
||||
Requires: lmdb-devel%{?_isa}
|
||||
%endif
|
||||
%if %{with JSON}
|
||||
Requires: json-c-devel%{?_isa}
|
||||
%endif
|
||||
|
|
@ -303,8 +306,8 @@ in HTML and PDF format.
|
|||
%endif
|
||||
|
||||
%prep
|
||||
%if 0%{?fedora}
|
||||
# RHEL does not yet support this verification
|
||||
%if ! 0%{?rhel} || 0%{?rhel} > 10
|
||||
# RHEL does not (again?) support this verification
|
||||
%{gpgverify} --keyring='%{SOURCE4}' --signature='%{SOURCE2}' --data='%{SOURCE0}'
|
||||
%endif
|
||||
%autosetup -n %{upname}-%{version} -p1
|
||||
|
|
@ -347,6 +350,10 @@ export STD_CDEFINES="$CPPFLAGS"
|
|||
#'s/([bind_VERSION_EXTRA],\s*\([^)]*\))/([bind_VERSION_EXTRA], \1-RH)/' \
|
||||
#configure.ac
|
||||
|
||||
install -p -m 0755 %{SOURCE27} ./named-mkroot.sh # create named.root.key
|
||||
./named-mkroot.sh
|
||||
[ -f named.root.key ]
|
||||
|
||||
|
||||
LIBDIR_SUFFIX=
|
||||
export LIBDIR_SUFFIX
|
||||
|
|
@ -364,11 +371,6 @@ export LIBDIR_SUFFIX
|
|||
%if %{with GSSTSIG}
|
||||
-Dgssapi=enabled \
|
||||
%endif
|
||||
%if %{with LMDB}
|
||||
-Dlmdb=enabled \
|
||||
%else
|
||||
-Dlmdb=disabled \
|
||||
%endif
|
||||
%if %{with JSON}
|
||||
-Dstats-json=enabled \
|
||||
%endif
|
||||
|
|
@ -381,6 +383,9 @@ export LIBDIR_SUFFIX
|
|||
%if %{with DOC}
|
||||
-Ddoc=enabled \
|
||||
%endif
|
||||
%if %{without JEMALLOC}
|
||||
-Djemalloc=disabled \
|
||||
%endif
|
||||
;
|
||||
%if %{with DNSTAP}
|
||||
pushd lib
|
||||
|
|
@ -394,6 +399,9 @@ export LIBDIR_SUFFIX
|
|||
%if %{with DOC}
|
||||
%meson_build man arm arm-epub
|
||||
%endif
|
||||
%if %{with SYSTEMTEST}
|
||||
%meson_build system-test-dependencies
|
||||
%endif
|
||||
|
||||
# Compress changelog by default
|
||||
gzip doc/changelog/changelog-*.rst
|
||||
|
|
@ -411,6 +419,10 @@ gzip doc/changelog/changelog-*.rst
|
|||
export TSAN_OPTIONS="log_exe_name=true log_path=ThreadSanitizer exitcode=0"
|
||||
%endif
|
||||
|
||||
# We produce it runtime. Check it has valid syntax.
|
||||
LD_LIBRARY_PATH="$LD_LIBRARY_PATH:${RPM_BUILD_ROOT}%{_libdir}" \
|
||||
${RPM_BUILD_ROOT}%{_bindir}/named-checkconf ${RPM_BUILD_ROOT}%{_sysconfdir}/named.root.key
|
||||
|
||||
%if %{with UNITTEST}
|
||||
CPUS=$(lscpu -p=cpu,core | grep -v '^#' | wc -l)
|
||||
THREADS="$CPUS"
|
||||
|
|
@ -460,18 +472,23 @@ export TSAN_OPTIONS="log_exe_name=true log_path=ThreadSanitizer exitcode=0"
|
|||
|
||||
if [ -n "$CONFIGURED" ]
|
||||
then
|
||||
set -e
|
||||
pushd bin/tests
|
||||
pushd bin/tests/system
|
||||
export CI_SYSTEM=yes # allow running tests as root
|
||||
chown -R ${USER} . # Can be unknown user
|
||||
%meson_build test 2>&1 | tee test.log
|
||||
e=$?
|
||||
e=0
|
||||
pytest -n ${THREADS} --capture=tee-sys || e=$?
|
||||
[ "$CONFIGURED" = build ] && $SUDO sh ./ifconfig.sh down
|
||||
popd
|
||||
if [ "$e" -ne 0 ]; then
|
||||
echo "ERROR: this build of BIND failed 'make test'. Aborting."
|
||||
echo "ERROR: failed running 'pytest' in system tests. Aborting."
|
||||
ls -1 "$(pwd)"/*_tmp_*
|
||||
for TMPTEST in *_tmp_*
|
||||
do
|
||||
echo "# $TMPTEST"
|
||||
cat $TMPTEST/pytest.log.txt
|
||||
done
|
||||
exit $e;
|
||||
fi;
|
||||
popd
|
||||
else
|
||||
echo 'SKIPPED: tests require root, CAP_NET_ADMIN or already configured test addresses.'
|
||||
fi
|
||||
|
|
@ -536,9 +553,6 @@ find ${RPM_BUILD_ROOT}/%{_libdir} -name '*.la' -exec '/bin/rm' '-f' '{}' ';';
|
|||
%if %{without DNSTAP}
|
||||
rm -f ${RPM_BUILD_ROOT}%{_mandir}/man1/dnstap-read.1* || true
|
||||
%endif
|
||||
%if %{without LMDB}
|
||||
rm -f ${RPM_BUILD_ROOT}%{_mandir}/man8/named-nzd2nzf.8* || true
|
||||
%endif
|
||||
|
||||
pushd ${RPM_BUILD_ROOT}%{_mandir}/man8
|
||||
ln -s ddns-confgen.8.gz tsig-keygen.8.gz
|
||||
|
|
@ -576,13 +590,13 @@ touch ${RPM_BUILD_ROOT}%{_localstatedir}/log/named.log
|
|||
# configuration files:
|
||||
install -m 640 %{SOURCE16} ${RPM_BUILD_ROOT}%{_sysconfdir}/named.conf
|
||||
touch ${RPM_BUILD_ROOT}%{_sysconfdir}/rndc.{key,conf}
|
||||
install -m 644 %{SOURCE27} ${RPM_BUILD_ROOT}%{_sysconfdir}/named.root.key
|
||||
install -m 644 %{SOURCE36} ${RPM_BUILD_ROOT}%{_sysconfdir}/trusted-key.key
|
||||
install -m 644 -p named.root.key ${RPM_BUILD_ROOT}%{_sysconfdir}/named.root.key
|
||||
ln -s "%{_datadir}/dns-root-data/root.key" ${RPM_BUILD_ROOT}%{_sysconfdir}/trusted-key.key
|
||||
mkdir -p ${RPM_BUILD_ROOT}%{_sysconfdir}/named
|
||||
|
||||
# data files:
|
||||
mkdir -p ${RPM_BUILD_ROOT}%{_localstatedir}/named
|
||||
install -m 640 %{SOURCE17} ${RPM_BUILD_ROOT}%{_localstatedir}/named/named.ca
|
||||
ln -s "%{_datadir}/dns-root-data/root.hints" ${RPM_BUILD_ROOT}%{_localstatedir}/named/named.ca
|
||||
install -m 640 %{SOURCE18} ${RPM_BUILD_ROOT}%{_localstatedir}/named/named.localhost
|
||||
install -m 640 %{SOURCE19} ${RPM_BUILD_ROOT}%{_localstatedir}/named/named.loopback
|
||||
install -m 640 %{SOURCE20} ${RPM_BUILD_ROOT}%{_localstatedir}/named/named.empty
|
||||
|
|
@ -595,7 +609,7 @@ install -m 644 %{SOURCE25} sample/etc/named.conf
|
|||
install -m 644 %{SOURCE16} named.conf.default
|
||||
install -m 644 %{SOURCE23} sample/etc/named.rfc1912.zones
|
||||
install -m 644 %{SOURCE18} %{SOURCE19} %{SOURCE20} sample/var/named
|
||||
install -m 644 %{SOURCE17} sample/var/named/named.ca
|
||||
ln -s "%{_datadir}/dns-root-data/root.hints" sample/var/named/named.ca
|
||||
for f in my.internal.zone.db slaves/my.slave.internal.zone.db slaves/my.ddns.internal.zone.db my.external.zone.db; do
|
||||
echo '@ in soa localhost. root 1 3H 15M 1W 1D
|
||||
ns localhost.' > sample/var/named/$f;
|
||||
|
|
@ -792,10 +806,8 @@ fi;
|
|||
%{_bindir}/dnstap-read
|
||||
%{_mandir}/man1/dnstap-read.1*
|
||||
%endif
|
||||
%if %{with LMDB}
|
||||
%{_bindir}/named-nzd2nzf
|
||||
%{_mandir}/man1/named-nzd2nzf.1*
|
||||
%endif
|
||||
%{_mandir}/man1/host.1*
|
||||
%{_mandir}/man1/nsupdate.1*
|
||||
%{_mandir}/man1/dig.1*
|
||||
|
|
|
|||
|
|
@ -18,6 +18,7 @@
|
|||
/usr/lib64/bind
|
||||
/usr/lib/bind
|
||||
/usr/share/GeoIP
|
||||
/usr/share/dns-root-data
|
||||
/run/named
|
||||
/proc/sys/net/ipv4/ip_local_port_range
|
||||
# Warning: the order is important
|
||||
|
|
|
|||
20
named-mkroot.sh
Executable file
20
named-mkroot.sh
Executable file
|
|
@ -0,0 +1,20 @@
|
|||
#!/bin/sh
|
||||
# Create named.root.key from dns-root-data package
|
||||
|
||||
ROOT_DS=/usr/share/dns-root-data/root.ds
|
||||
: ${OUTPUT:=named.root.key}
|
||||
|
||||
if ! [ -r "$ROOT_DS" ]; then
|
||||
echo "Root trust file is not readable: $ROOT_DS"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "# Autogenerated from $ROOT_DS" > "$OUTPUT"
|
||||
echo "trust-anchors {" >> "$OUTPUT"
|
||||
cat "$ROOT_DS" | while read DOMAIN CLS QTYPE KEYTAG ALG DIG HASH;
|
||||
do
|
||||
echo "$DOMAIN initial-ds $KEYTAG $ALG $DIG \"$HASH\";" >> "$OUTPUT";
|
||||
done
|
||||
echo "}; " >> "$OUTPUT"
|
||||
# Set the same modification time as data source.
|
||||
touch -r $ROOT_DS "$OUTPUT"
|
||||
92
named.root
92
named.root
|
|
@ -1,92 +0,0 @@
|
|||
; This file holds the information on root name servers needed to
|
||||
; initialize cache of Internet domain name servers
|
||||
; (e.g. reference this file in the "cache . <file>"
|
||||
; configuration file of BIND domain name servers).
|
||||
;
|
||||
; This file is made available by InterNIC
|
||||
; under anonymous FTP as
|
||||
; file /domain/named.cache
|
||||
; on server FTP.INTERNIC.NET
|
||||
; -OR- RS.INTERNIC.NET
|
||||
;
|
||||
; last update: December 20, 2023
|
||||
; related version of root zone: 2023122001
|
||||
;
|
||||
; FORMERLY NS.INTERNIC.NET
|
||||
;
|
||||
. 3600000 NS A.ROOT-SERVERS.NET.
|
||||
A.ROOT-SERVERS.NET. 3600000 A 198.41.0.4
|
||||
A.ROOT-SERVERS.NET. 3600000 AAAA 2001:503:ba3e::2:30
|
||||
;
|
||||
; FORMERLY NS1.ISI.EDU
|
||||
;
|
||||
. 3600000 NS B.ROOT-SERVERS.NET.
|
||||
B.ROOT-SERVERS.NET. 3600000 A 170.247.170.2
|
||||
B.ROOT-SERVERS.NET. 3600000 AAAA 2801:1b8:10::b
|
||||
;
|
||||
; FORMERLY C.PSI.NET
|
||||
;
|
||||
. 3600000 NS C.ROOT-SERVERS.NET.
|
||||
C.ROOT-SERVERS.NET. 3600000 A 192.33.4.12
|
||||
C.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:2::c
|
||||
;
|
||||
; FORMERLY TERP.UMD.EDU
|
||||
;
|
||||
. 3600000 NS D.ROOT-SERVERS.NET.
|
||||
D.ROOT-SERVERS.NET. 3600000 A 199.7.91.13
|
||||
D.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:2d::d
|
||||
;
|
||||
; FORMERLY NS.NASA.GOV
|
||||
;
|
||||
. 3600000 NS E.ROOT-SERVERS.NET.
|
||||
E.ROOT-SERVERS.NET. 3600000 A 192.203.230.10
|
||||
E.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:a8::e
|
||||
;
|
||||
; FORMERLY NS.ISC.ORG
|
||||
;
|
||||
. 3600000 NS F.ROOT-SERVERS.NET.
|
||||
F.ROOT-SERVERS.NET. 3600000 A 192.5.5.241
|
||||
F.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:2f::f
|
||||
;
|
||||
; FORMERLY NS.NIC.DDN.MIL
|
||||
;
|
||||
. 3600000 NS G.ROOT-SERVERS.NET.
|
||||
G.ROOT-SERVERS.NET. 3600000 A 192.112.36.4
|
||||
G.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:12::d0d
|
||||
;
|
||||
; FORMERLY AOS.ARL.ARMY.MIL
|
||||
;
|
||||
. 3600000 NS H.ROOT-SERVERS.NET.
|
||||
H.ROOT-SERVERS.NET. 3600000 A 198.97.190.53
|
||||
H.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:1::53
|
||||
;
|
||||
; FORMERLY NIC.NORDU.NET
|
||||
;
|
||||
. 3600000 NS I.ROOT-SERVERS.NET.
|
||||
I.ROOT-SERVERS.NET. 3600000 A 192.36.148.17
|
||||
I.ROOT-SERVERS.NET. 3600000 AAAA 2001:7fe::53
|
||||
;
|
||||
; OPERATED BY VERISIGN, INC.
|
||||
;
|
||||
. 3600000 NS J.ROOT-SERVERS.NET.
|
||||
J.ROOT-SERVERS.NET. 3600000 A 192.58.128.30
|
||||
J.ROOT-SERVERS.NET. 3600000 AAAA 2001:503:c27::2:30
|
||||
;
|
||||
; OPERATED BY RIPE NCC
|
||||
;
|
||||
. 3600000 NS K.ROOT-SERVERS.NET.
|
||||
K.ROOT-SERVERS.NET. 3600000 A 193.0.14.129
|
||||
K.ROOT-SERVERS.NET. 3600000 AAAA 2001:7fd::1
|
||||
;
|
||||
; OPERATED BY ICANN
|
||||
;
|
||||
. 3600000 NS L.ROOT-SERVERS.NET.
|
||||
L.ROOT-SERVERS.NET. 3600000 A 199.7.83.42
|
||||
L.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:9f::42
|
||||
;
|
||||
; OPERATED BY WIDE
|
||||
;
|
||||
. 3600000 NS M.ROOT-SERVERS.NET.
|
||||
M.ROOT-SERVERS.NET. 3600000 A 202.12.27.33
|
||||
M.ROOT-SERVERS.NET. 3600000 AAAA 2001:dc3::35
|
||||
; End of file
|
||||
|
|
@ -1,18 +1,5 @@
|
|||
trust-anchors {
|
||||
# ROOT KEYS: See https://data.iana.org/root-anchors/root-anchors.xml
|
||||
# for current trust anchor information.
|
||||
#
|
||||
# This key (20326) was published in the root zone in 2017.
|
||||
# Servers which were already using the old key (19036) should
|
||||
# roll seamlessly to this new one via RFC 5011 rollover. Servers
|
||||
# being set up for the first time can use the contents of this
|
||||
# file as initializing keys; thereafter, the keys in the
|
||||
# managed key database will be trusted and maintained
|
||||
# automatically.
|
||||
. initial-ds 20326 8 2 "E06D44B80B8F1D39A95C0B0D7C65D08458E880409BBC683457104237C7F8EC8D";
|
||||
# This key (38696) will be pre-published in the root zone in 2025
|
||||
# and is scheduled to begin signing in late 2026. At that time,
|
||||
# servers which were already using the old key (20326) should roll
|
||||
# seamlessly to this new one via RFC 5011 rollover.
|
||||
. initial-ds 38696 8 2 "683D2D0ACB8C9B712A1948B27F741219298D0A450D612C483AF444A4C0FB2B16";
|
||||
};
|
||||
# Autogenerated from /usr/share/dns-root-data/root.ds
|
||||
truste-anchors {
|
||||
. initial-ds 20326 8 2 "E06D44B80B8F1D39A95C0B0D7C65D08458E880409BBC683457104237C7F8EC8D";
|
||||
. initial-ds 38696 8 2 "683D2D0ACB8C9B712A1948B27F741219298D0A450D612C483AF444A4C0FB2B16";
|
||||
};
|
||||
|
|
|
|||
4
sources
4
sources
|
|
@ -1,2 +1,2 @@
|
|||
SHA512 (bind-9.21.14.tar.xz) = bf4bd0f5613d6c6d53f749f3269a34f3a5c74a7dc81e05922d58ba30f19d418e565838dd1182dd6052b9a62b3799d2d0f12451f2797af3279259df59cfc4be05
|
||||
SHA512 (bind-9.21.14.tar.xz.asc) = 91ccc82ca54d07dba07821c3410f92b563290ead48546d605b0dbd9958a831d9b90130002fbb325e0cdc913de64813d8ba4c48ec958ebba7f5f462d43f578394
|
||||
SHA512 (bind-9.21.22.tar.xz) = f9e11d150162661c755dabdd7862c0565e6a10077e2a6aee04f8cefce94c262d8928ff9e42f8c8750242aee3b0992afe2f49f72f0f8cab8b7e4ae1c9fc06e0fa
|
||||
SHA512 (bind-9.21.22.tar.xz.asc) = 1e0bd14fad5754e12b6a4855dbed698dba74468790948316e17442e5bc840fc81d18e590fd78186a1e26e9526870b13470dcef6a15644e91775cc8883813ad24
|
||||
|
|
|
|||
|
|
@ -1,2 +0,0 @@
|
|||
. 3600 IN DNSKEY 257 3 8 AwEAAaz/tAm8yTn4Mfeh5eyI96WSVexTBAvkMgJzkKTOiW1vkIbzxeF3+/4RgWOq7HrxRixHlFlExOLAJr5emLvN7SWXgnLh4+B5xQlNVz8Og8kvArMtNROxVQuCaSnIDdD5LKyWbRd2n9WGe2R8PzgCmr3EgVLrjyBxWezF0jLHwVN8efS3rCj/EWgvIWgb9tarpVUDK/b58Da+sqqls3eNbuv7pr+eoZG+SrDK6nWeL3c6H5Apxz7LjVc1uTIdsIXxuOLYA4/ilBmSVIzuDWfdRUfhHdY6+cn8HFRm+2hM8AnXGXws9555KrUB5qihylGa8subX2Nn6UwNR1AkUTV74bU=
|
||||
. 3600 IN DNSKEY 257 3 8 AwEAAa96jeuknZlaeSrvyAJj6ZHv28hhOKkx3rLGXVaC6rXTsDc449/cidltpkyGwCJNnOAlFNKF2jBosZBU5eeHspaQWOmOElZsjICMQMC3aeHbGiShvZsx4wMYSjH8e7Vrhbu6irwCzVBApESjbUdpWWmEnhathWu1jo+siFUiRAAxm9qyJNg/wOZqqzL/dL/q8PkcRU5oUKEpUge71M3ej2/7CPqpdVwuMoTvoB+ZOT4YeGyxMvHmbrxlFzGOHOijtzN+u1TQNatX2XBuzZNQ1K+s2CXkPIZo7s6JgZyvaBevYtxPvYLw4z9mR7K2vaF18UYH9Z9GNUUeayffKC73PYc=
|
||||
Loading…
Add table
Add a link
Reference in a new issue