2 * Copyright (C) 2004-2007, 2009-2014 Internet Systems Consortium, Inc. ("ISC")
3 * Copyright (C) 1999-2002 Internet Software Consortium.
5 * Permission to use, copy, modify, and/or distribute this software for any
6 * purpose with or without fee is hereby granted, provided that the above
7 * copyright notice and this permission notice appear in all copies.
9 * THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
10 * REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
11 * AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
12 * INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
13 * LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
14 * OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
15 * PERFORMANCE OF THIS SOFTWARE.
18 /* $Id: named-checkconf.c,v 1.56 2011/03/12 04:59:46 tbox Exp $ */
28 #include <isc/commandline.h>
30 #include <isc/entropy.h>
34 #include <isc/result.h>
35 #include <isc/string.h>
38 #include <isccfg/namedconf.h>
40 #include <bind9/check.h>
43 #include <dns/fixedname.h>
46 #include <dns/rdataclass.h>
47 #include <dns/result.h>
48 #include <dns/rootns.h>
51 #include "check-tool.h"
53 static const char *program = "named-checkconf";
55 isc_log_t *logc = NULL;
60 if (result != ISC_R_SUCCESS) \
65 ISC_PLATFORM_NORETURN_PRE static void
66 usage(void) ISC_PLATFORM_NORETURN_POST;
70 fprintf(stderr, "usage: %s [-h] [-j] [-p] [-v] [-z] [-t directory] "
71 "[named.conf]\n", program);
75 /*% directory callback */
77 directory_callback(const char *clausename, const cfg_obj_t *obj, void *arg) {
79 const char *directory;
81 REQUIRE(strcasecmp("directory", clausename) == 0);
89 directory = cfg_obj_asstring(obj);
90 result = isc_dir_chdir(directory);
91 if (result != ISC_R_SUCCESS) {
92 cfg_obj_log(obj, logc, ISC_LOG_ERROR,
93 "change directory to '%s' failed: %s\n",
94 directory, isc_result_totext(result));
98 return (ISC_R_SUCCESS);
102 get_maps(const cfg_obj_t **maps, const char *name, const cfg_obj_t **obj) {
107 if (cfg_map_get(maps[i], name, obj) == ISC_R_SUCCESS)
113 get_checknames(const cfg_obj_t **maps, const cfg_obj_t **obj) {
114 const cfg_listelt_t *element;
115 const cfg_obj_t *checknames;
116 const cfg_obj_t *type;
117 const cfg_obj_t *value;
125 result = cfg_map_get(maps[i], "check-names", &checknames);
126 if (result != ISC_R_SUCCESS)
128 if (checknames != NULL && !cfg_obj_islist(checknames)) {
132 for (element = cfg_list_first(checknames);
134 element = cfg_list_next(element)) {
135 value = cfg_listelt_value(element);
136 type = cfg_tuple_get(value, "type");
137 if (strcasecmp(cfg_obj_asstring(type), "master") != 0)
139 *obj = cfg_tuple_get(value, "mode");
146 config_get(const cfg_obj_t **maps, const char *name, const cfg_obj_t **obj) {
151 return (ISC_R_NOTFOUND);
152 if (cfg_map_get(maps[i], name, obj) == ISC_R_SUCCESS)
153 return (ISC_R_SUCCESS);
158 configure_hint(const char *zfile, const char *zclass, isc_mem_t *mctx) {
161 dns_rdataclass_t rdclass;
165 return (ISC_R_FAILURE);
167 DE_CONST(zclass, r.base);
168 r.length = strlen(zclass);
169 result = dns_rdataclass_fromtext(&rdclass, &r);
170 if (result != ISC_R_SUCCESS)
173 result = dns_rootns_create(mctx, rdclass, zfile, &db);
174 if (result != ISC_R_SUCCESS)
178 return (ISC_R_SUCCESS);
181 /*% configure the zone */
183 configure_zone(const char *vclass, const char *view,
184 const cfg_obj_t *zconfig, const cfg_obj_t *vconfig,
185 const cfg_obj_t *config, isc_mem_t *mctx)
191 const char *zfile = NULL;
192 const cfg_obj_t *maps[4];
193 const cfg_obj_t *zoptions = NULL;
194 const cfg_obj_t *classobj = NULL;
195 const cfg_obj_t *typeobj = NULL;
196 const cfg_obj_t *fileobj = NULL;
197 const cfg_obj_t *dbobj = NULL;
198 const cfg_obj_t *obj = NULL;
199 const cfg_obj_t *fmtobj = NULL;
200 dns_masterformat_t masterformat;
202 zone_options = DNS_ZONEOPT_CHECKNS | DNS_ZONEOPT_MANYERRORS;
204 zname = cfg_obj_asstring(cfg_tuple_get(zconfig, "name"));
205 classobj = cfg_tuple_get(zconfig, "class");
206 if (!cfg_obj_isstring(classobj))
209 zclass = cfg_obj_asstring(classobj);
211 zoptions = cfg_tuple_get(zconfig, "options");
212 maps[i++] = zoptions;
214 maps[i++] = cfg_tuple_get(vconfig, "options");
215 if (config != NULL) {
216 cfg_map_get(config, "options", &obj);
222 cfg_map_get(zoptions, "type", &typeobj);
224 return (ISC_R_FAILURE);
226 cfg_map_get(zoptions, "file", &fileobj);
228 zfile = cfg_obj_asstring(fileobj);
231 * Check hints files for hint zones.
232 * Skip loading checks for any type other than
233 * master and redirect
235 if (strcasecmp(cfg_obj_asstring(typeobj), "hint") == 0)
236 return (configure_hint(zfile, zclass, mctx));
237 else if ((strcasecmp(cfg_obj_asstring(typeobj), "master") != 0) &&
238 (strcasecmp(cfg_obj_asstring(typeobj), "redirect") != 0))
239 return (ISC_R_SUCCESS);
242 return (ISC_R_FAILURE);
244 cfg_map_get(zoptions, "database", &dbobj);
246 return (ISC_R_SUCCESS);
249 if (get_maps(maps, "check-dup-records", &obj)) {
250 if (strcasecmp(cfg_obj_asstring(obj), "warn") == 0) {
251 zone_options |= DNS_ZONEOPT_CHECKDUPRR;
252 zone_options &= ~DNS_ZONEOPT_CHECKDUPRRFAIL;
253 } else if (strcasecmp(cfg_obj_asstring(obj), "fail") == 0) {
254 zone_options |= DNS_ZONEOPT_CHECKDUPRR;
255 zone_options |= DNS_ZONEOPT_CHECKDUPRRFAIL;
256 } else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
257 zone_options &= ~DNS_ZONEOPT_CHECKDUPRR;
258 zone_options &= ~DNS_ZONEOPT_CHECKDUPRRFAIL;
262 zone_options |= DNS_ZONEOPT_CHECKDUPRR;
263 zone_options &= ~DNS_ZONEOPT_CHECKDUPRRFAIL;
267 if (get_maps(maps, "check-mx", &obj)) {
268 if (strcasecmp(cfg_obj_asstring(obj), "warn") == 0) {
269 zone_options |= DNS_ZONEOPT_CHECKMX;
270 zone_options &= ~DNS_ZONEOPT_CHECKMXFAIL;
271 } else if (strcasecmp(cfg_obj_asstring(obj), "fail") == 0) {
272 zone_options |= DNS_ZONEOPT_CHECKMX;
273 zone_options |= DNS_ZONEOPT_CHECKMXFAIL;
274 } else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
275 zone_options &= ~DNS_ZONEOPT_CHECKMX;
276 zone_options &= ~DNS_ZONEOPT_CHECKMXFAIL;
280 zone_options |= DNS_ZONEOPT_CHECKMX;
281 zone_options &= ~DNS_ZONEOPT_CHECKMXFAIL;
285 if (get_maps(maps, "check-integrity", &obj)) {
286 if (cfg_obj_asboolean(obj))
287 zone_options |= DNS_ZONEOPT_CHECKINTEGRITY;
289 zone_options &= ~DNS_ZONEOPT_CHECKINTEGRITY;
291 zone_options |= DNS_ZONEOPT_CHECKINTEGRITY;
294 if (get_maps(maps, "check-mx-cname", &obj)) {
295 if (strcasecmp(cfg_obj_asstring(obj), "warn") == 0) {
296 zone_options |= DNS_ZONEOPT_WARNMXCNAME;
297 zone_options &= ~DNS_ZONEOPT_IGNOREMXCNAME;
298 } else if (strcasecmp(cfg_obj_asstring(obj), "fail") == 0) {
299 zone_options &= ~DNS_ZONEOPT_WARNMXCNAME;
300 zone_options &= ~DNS_ZONEOPT_IGNOREMXCNAME;
301 } else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
302 zone_options |= DNS_ZONEOPT_WARNMXCNAME;
303 zone_options |= DNS_ZONEOPT_IGNOREMXCNAME;
307 zone_options |= DNS_ZONEOPT_WARNMXCNAME;
308 zone_options &= ~DNS_ZONEOPT_IGNOREMXCNAME;
312 if (get_maps(maps, "check-srv-cname", &obj)) {
313 if (strcasecmp(cfg_obj_asstring(obj), "warn") == 0) {
314 zone_options |= DNS_ZONEOPT_WARNSRVCNAME;
315 zone_options &= ~DNS_ZONEOPT_IGNORESRVCNAME;
316 } else if (strcasecmp(cfg_obj_asstring(obj), "fail") == 0) {
317 zone_options &= ~DNS_ZONEOPT_WARNSRVCNAME;
318 zone_options &= ~DNS_ZONEOPT_IGNORESRVCNAME;
319 } else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
320 zone_options |= DNS_ZONEOPT_WARNSRVCNAME;
321 zone_options |= DNS_ZONEOPT_IGNORESRVCNAME;
325 zone_options |= DNS_ZONEOPT_WARNSRVCNAME;
326 zone_options &= ~DNS_ZONEOPT_IGNORESRVCNAME;
330 if (get_maps(maps, "check-sibling", &obj)) {
331 if (cfg_obj_asboolean(obj))
332 zone_options |= DNS_ZONEOPT_CHECKSIBLING;
334 zone_options &= ~DNS_ZONEOPT_CHECKSIBLING;
338 if (get_maps(maps, "check-spf", &obj)) {
339 if (strcasecmp(cfg_obj_asstring(obj), "warn") == 0) {
340 zone_options |= DNS_ZONEOPT_CHECKSPF;
341 } else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
342 zone_options &= ~DNS_ZONEOPT_CHECKSPF;
346 zone_options |= DNS_ZONEOPT_CHECKSPF;
350 if (get_checknames(maps, &obj)) {
351 if (strcasecmp(cfg_obj_asstring(obj), "warn") == 0) {
352 zone_options |= DNS_ZONEOPT_CHECKNAMES;
353 zone_options &= ~DNS_ZONEOPT_CHECKNAMESFAIL;
354 } else if (strcasecmp(cfg_obj_asstring(obj), "fail") == 0) {
355 zone_options |= DNS_ZONEOPT_CHECKNAMES;
356 zone_options |= DNS_ZONEOPT_CHECKNAMESFAIL;
357 } else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
358 zone_options &= ~DNS_ZONEOPT_CHECKNAMES;
359 zone_options &= ~DNS_ZONEOPT_CHECKNAMESFAIL;
363 zone_options |= DNS_ZONEOPT_CHECKNAMES;
364 zone_options |= DNS_ZONEOPT_CHECKNAMESFAIL;
367 masterformat = dns_masterformat_text;
369 result = config_get(maps, "masterfile-format", &fmtobj);
370 if (result == ISC_R_SUCCESS) {
371 const char *masterformatstr = cfg_obj_asstring(fmtobj);
372 if (strcasecmp(masterformatstr, "text") == 0)
373 masterformat = dns_masterformat_text;
374 else if (strcasecmp(masterformatstr, "raw") == 0)
375 masterformat = dns_masterformat_raw;
380 result = load_zone(mctx, zname, zfile, masterformat, zclass, NULL);
381 if (result != ISC_R_SUCCESS)
382 fprintf(stderr, "%s/%s/%s: %s\n", view, zname, zclass,
383 dns_result_totext(result));
387 /*% configure a view */
389 configure_view(const char *vclass, const char *view, const cfg_obj_t *config,
390 const cfg_obj_t *vconfig, isc_mem_t *mctx)
392 const cfg_listelt_t *element;
393 const cfg_obj_t *voptions;
394 const cfg_obj_t *zonelist;
395 isc_result_t result = ISC_R_SUCCESS;
396 isc_result_t tresult;
400 voptions = cfg_tuple_get(vconfig, "options");
403 if (voptions != NULL)
404 (void)cfg_map_get(voptions, "zone", &zonelist);
406 (void)cfg_map_get(config, "zone", &zonelist);
408 for (element = cfg_list_first(zonelist);
410 element = cfg_list_next(element))
412 const cfg_obj_t *zconfig = cfg_listelt_value(element);
413 tresult = configure_zone(vclass, view, zconfig, vconfig,
415 if (tresult != ISC_R_SUCCESS)
422 /*% load zones from the configuration */
424 load_zones_fromconfig(const cfg_obj_t *config, isc_mem_t *mctx) {
425 const cfg_listelt_t *element;
426 const cfg_obj_t *classobj;
427 const cfg_obj_t *views;
428 const cfg_obj_t *vconfig;
430 isc_result_t result = ISC_R_SUCCESS;
431 isc_result_t tresult;
435 (void)cfg_map_get(config, "view", &views);
436 for (element = cfg_list_first(views);
438 element = cfg_list_next(element))
443 vconfig = cfg_listelt_value(element);
444 if (vconfig != NULL) {
445 classobj = cfg_tuple_get(vconfig, "class");
446 if (cfg_obj_isstring(classobj))
447 vclass = cfg_obj_asstring(classobj);
449 vname = cfg_obj_asstring(cfg_tuple_get(vconfig, "name"));
450 tresult = configure_view(vclass, vname, config, vconfig, mctx);
451 if (tresult != ISC_R_SUCCESS)
456 tresult = configure_view("IN", "_default", config, NULL, mctx);
457 if (tresult != ISC_R_SUCCESS)
464 output(void *closure, const char *text, int textlen) {
466 if (fwrite(text, 1, textlen, stdout) != (size_t)textlen) {
472 /*% The main processing routine */
474 main(int argc, char **argv) {
476 cfg_parser_t *parser = NULL;
477 cfg_obj_t *config = NULL;
478 const char *conffile = NULL;
479 isc_mem_t *mctx = NULL;
482 isc_entropy_t *ectx = NULL;
483 isc_boolean_t load_zones = ISC_FALSE;
484 isc_boolean_t print = ISC_FALSE;
485 unsigned int flags = 0;
487 isc_commandline_errprint = ISC_FALSE;
489 while ((c = isc_commandline_parse(argc, argv, "dhjt:pvxz")) != EOF) {
500 result = isc_dir_chroot(isc_commandline_argument);
501 if (result != ISC_R_SUCCESS) {
502 fprintf(stderr, "isc_dir_chroot: %s\n",
503 isc_result_totext(result));
513 printf(VERSION "\n");
517 flags |= CFG_PRINTER_XKEY;
521 load_zones = ISC_TRUE;
522 docheckmx = ISC_FALSE;
523 docheckns = ISC_FALSE;
524 dochecksrv = ISC_FALSE;
528 if (isc_commandline_option != '?')
529 fprintf(stderr, "%s: invalid argument -%c\n",
530 program, isc_commandline_option);
536 fprintf(stderr, "%s: unhandled option -%c\n",
537 program, isc_commandline_option);
542 if (((flags & CFG_PRINTER_XKEY) != 0) && !print) {
543 fprintf(stderr, "%s: -x cannot be used without -p\n", program);
547 if (isc_commandline_index + 1 < argc)
549 if (argv[isc_commandline_index] != NULL)
550 conffile = argv[isc_commandline_index];
551 if (conffile == NULL || conffile[0] == '\0')
552 conffile = NAMED_CONFFILE;
558 RUNTIME_CHECK(isc_mem_create(0, 0, &mctx) == ISC_R_SUCCESS);
560 RUNTIME_CHECK(setup_logging(mctx, stdout, &logc) == ISC_R_SUCCESS);
562 RUNTIME_CHECK(isc_entropy_create(mctx, &ectx) == ISC_R_SUCCESS);
563 RUNTIME_CHECK(isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE)
566 dns_result_register();
568 RUNTIME_CHECK(cfg_parser_create(mctx, logc, &parser) == ISC_R_SUCCESS);
570 cfg_parser_setcallback(parser, directory_callback, NULL);
572 if (cfg_parse_file(parser, conffile, &cfg_type_namedconf, &config) !=
576 result = bind9_check_namedconf(config, logc, mctx);
577 if (result != ISC_R_SUCCESS)
580 if (result == ISC_R_SUCCESS && load_zones) {
581 result = load_zones_fromconfig(config, mctx);
582 if (result != ISC_R_SUCCESS)
586 if (print && exit_status == 0)
587 cfg_printx(config, flags, output, NULL);
588 cfg_obj_destroy(parser, &config);
590 cfg_parser_destroy(&parser);
594 isc_log_destroy(&logc);
597 isc_entropy_detach(&ectx);
599 isc_mem_destroy(&mctx);
605 return (exit_status);