2 * Copyright (C) 2004-2007, 2009-2014 Internet Systems Consortium, Inc. ("ISC")
3 * Copyright (C) 1999-2002 Internet Software Consortium.
5 * Permission to use, copy, modify, and/or distribute this software for any
6 * purpose with or without fee is hereby granted, provided that the above
7 * copyright notice and this permission notice appear in all copies.
9 * THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
10 * REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
11 * AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
12 * INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
13 * LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
14 * OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
15 * PERFORMANCE OF THIS SOFTWARE.
18 /* $Id: named-checkconf.c,v 1.54.62.2 2011/03/12 04:59:13 tbox Exp $ */
28 #include <isc/commandline.h>
30 #include <isc/entropy.h>
34 #include <isc/result.h>
35 #include <isc/string.h>
38 #include <isccfg/namedconf.h>
40 #include <bind9/check.h>
43 #include <dns/fixedname.h>
46 #include <dns/rdataclass.h>
47 #include <dns/result.h>
48 #include <dns/rootns.h>
51 #include "check-tool.h"
53 static const char *program = "named-checkconf";
55 isc_log_t *logc = NULL;
60 if (result != ISC_R_SUCCESS) \
65 ISC_PLATFORM_NORETURN_PRE static void
66 usage(void) ISC_PLATFORM_NORETURN_POST;
70 fprintf(stderr, "usage: %s [-h] [-j] [-p] [-v] [-z] [-t directory] "
71 "[named.conf]\n", program);
75 /*% directory callback */
77 directory_callback(const char *clausename, const cfg_obj_t *obj, void *arg) {
79 const char *directory;
81 REQUIRE(strcasecmp("directory", clausename) == 0);
89 directory = cfg_obj_asstring(obj);
90 result = isc_dir_chdir(directory);
91 if (result != ISC_R_SUCCESS) {
92 cfg_obj_log(obj, logc, ISC_LOG_ERROR,
93 "change directory to '%s' failed: %s\n",
94 directory, isc_result_totext(result));
98 return (ISC_R_SUCCESS);
102 get_maps(const cfg_obj_t **maps, const char *name, const cfg_obj_t **obj) {
107 if (cfg_map_get(maps[i], name, obj) == ISC_R_SUCCESS)
113 get_checknames(const cfg_obj_t **maps, const cfg_obj_t **obj) {
114 const cfg_listelt_t *element;
115 const cfg_obj_t *checknames;
116 const cfg_obj_t *type;
117 const cfg_obj_t *value;
125 result = cfg_map_get(maps[i], "check-names", &checknames);
126 if (result != ISC_R_SUCCESS)
128 if (checknames != NULL && !cfg_obj_islist(checknames)) {
132 for (element = cfg_list_first(checknames);
134 element = cfg_list_next(element)) {
135 value = cfg_listelt_value(element);
136 type = cfg_tuple_get(value, "type");
137 if (strcasecmp(cfg_obj_asstring(type), "master") != 0)
139 *obj = cfg_tuple_get(value, "mode");
146 config_get(const cfg_obj_t **maps, const char *name, const cfg_obj_t **obj) {
151 return (ISC_R_NOTFOUND);
152 if (cfg_map_get(maps[i], name, obj) == ISC_R_SUCCESS)
153 return (ISC_R_SUCCESS);
158 configure_hint(const char *zfile, const char *zclass, isc_mem_t *mctx) {
161 dns_rdataclass_t rdclass;
165 return (ISC_R_FAILURE);
167 DE_CONST(zclass, r.base);
168 r.length = strlen(zclass);
169 result = dns_rdataclass_fromtext(&rdclass, &r);
170 if (result != ISC_R_SUCCESS)
173 result = dns_rootns_create(mctx, rdclass, zfile, &db);
174 if (result != ISC_R_SUCCESS)
178 return (ISC_R_SUCCESS);
181 /*% configure the zone */
183 configure_zone(const char *vclass, const char *view,
184 const cfg_obj_t *zconfig, const cfg_obj_t *vconfig,
185 const cfg_obj_t *config, isc_mem_t *mctx)
191 const char *zfile = NULL;
192 const cfg_obj_t *maps[4];
193 const cfg_obj_t *zoptions = NULL;
194 const cfg_obj_t *classobj = NULL;
195 const cfg_obj_t *typeobj = NULL;
196 const cfg_obj_t *fileobj = NULL;
197 const cfg_obj_t *dbobj = NULL;
198 const cfg_obj_t *obj = NULL;
199 const cfg_obj_t *fmtobj = NULL;
200 dns_masterformat_t masterformat;
202 zone_options = DNS_ZONEOPT_CHECKNS | DNS_ZONEOPT_MANYERRORS;
204 zname = cfg_obj_asstring(cfg_tuple_get(zconfig, "name"));
205 classobj = cfg_tuple_get(zconfig, "class");
206 if (!cfg_obj_isstring(classobj))
209 zclass = cfg_obj_asstring(classobj);
211 zoptions = cfg_tuple_get(zconfig, "options");
212 maps[i++] = zoptions;
214 maps[i++] = cfg_tuple_get(vconfig, "options");
215 if (config != NULL) {
216 cfg_map_get(config, "options", &obj);
222 cfg_map_get(zoptions, "type", &typeobj);
224 return (ISC_R_FAILURE);
226 cfg_map_get(zoptions, "file", &fileobj);
228 zfile = cfg_obj_asstring(fileobj);
231 * Check hints files for hint zones.
232 * Skip loading checks for any type other than master.
234 if (strcasecmp(cfg_obj_asstring(typeobj), "hint") == 0)
235 return (configure_hint(zfile, zclass, mctx));
236 else if ((strcasecmp(cfg_obj_asstring(typeobj), "master") != 0))
237 return (ISC_R_SUCCESS);
240 return (ISC_R_FAILURE);
242 cfg_map_get(zoptions, "database", &dbobj);
244 return (ISC_R_SUCCESS);
247 if (get_maps(maps, "check-dup-records", &obj)) {
248 if (strcasecmp(cfg_obj_asstring(obj), "warn") == 0) {
249 zone_options |= DNS_ZONEOPT_CHECKDUPRR;
250 zone_options &= ~DNS_ZONEOPT_CHECKDUPRRFAIL;
251 } else if (strcasecmp(cfg_obj_asstring(obj), "fail") == 0) {
252 zone_options |= DNS_ZONEOPT_CHECKDUPRR;
253 zone_options |= DNS_ZONEOPT_CHECKDUPRRFAIL;
254 } else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
255 zone_options &= ~DNS_ZONEOPT_CHECKDUPRR;
256 zone_options &= ~DNS_ZONEOPT_CHECKDUPRRFAIL;
260 zone_options |= DNS_ZONEOPT_CHECKDUPRR;
261 zone_options &= ~DNS_ZONEOPT_CHECKDUPRRFAIL;
265 if (get_maps(maps, "check-mx", &obj)) {
266 if (strcasecmp(cfg_obj_asstring(obj), "warn") == 0) {
267 zone_options |= DNS_ZONEOPT_CHECKMX;
268 zone_options &= ~DNS_ZONEOPT_CHECKMXFAIL;
269 } else if (strcasecmp(cfg_obj_asstring(obj), "fail") == 0) {
270 zone_options |= DNS_ZONEOPT_CHECKMX;
271 zone_options |= DNS_ZONEOPT_CHECKMXFAIL;
272 } else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
273 zone_options &= ~DNS_ZONEOPT_CHECKMX;
274 zone_options &= ~DNS_ZONEOPT_CHECKMXFAIL;
278 zone_options |= DNS_ZONEOPT_CHECKMX;
279 zone_options &= ~DNS_ZONEOPT_CHECKMXFAIL;
283 if (get_maps(maps, "check-integrity", &obj)) {
284 if (cfg_obj_asboolean(obj))
285 zone_options |= DNS_ZONEOPT_CHECKINTEGRITY;
287 zone_options &= ~DNS_ZONEOPT_CHECKINTEGRITY;
289 zone_options |= DNS_ZONEOPT_CHECKINTEGRITY;
292 if (get_maps(maps, "check-mx-cname", &obj)) {
293 if (strcasecmp(cfg_obj_asstring(obj), "warn") == 0) {
294 zone_options |= DNS_ZONEOPT_WARNMXCNAME;
295 zone_options &= ~DNS_ZONEOPT_IGNOREMXCNAME;
296 } else if (strcasecmp(cfg_obj_asstring(obj), "fail") == 0) {
297 zone_options &= ~DNS_ZONEOPT_WARNMXCNAME;
298 zone_options &= ~DNS_ZONEOPT_IGNOREMXCNAME;
299 } else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
300 zone_options |= DNS_ZONEOPT_WARNMXCNAME;
301 zone_options |= DNS_ZONEOPT_IGNOREMXCNAME;
305 zone_options |= DNS_ZONEOPT_WARNMXCNAME;
306 zone_options &= ~DNS_ZONEOPT_IGNOREMXCNAME;
310 if (get_maps(maps, "check-srv-cname", &obj)) {
311 if (strcasecmp(cfg_obj_asstring(obj), "warn") == 0) {
312 zone_options |= DNS_ZONEOPT_WARNSRVCNAME;
313 zone_options &= ~DNS_ZONEOPT_IGNORESRVCNAME;
314 } else if (strcasecmp(cfg_obj_asstring(obj), "fail") == 0) {
315 zone_options &= ~DNS_ZONEOPT_WARNSRVCNAME;
316 zone_options &= ~DNS_ZONEOPT_IGNORESRVCNAME;
317 } else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
318 zone_options |= DNS_ZONEOPT_WARNSRVCNAME;
319 zone_options |= DNS_ZONEOPT_IGNORESRVCNAME;
323 zone_options |= DNS_ZONEOPT_WARNSRVCNAME;
324 zone_options &= ~DNS_ZONEOPT_IGNORESRVCNAME;
328 if (get_maps(maps, "check-sibling", &obj)) {
329 if (cfg_obj_asboolean(obj))
330 zone_options |= DNS_ZONEOPT_CHECKSIBLING;
332 zone_options &= ~DNS_ZONEOPT_CHECKSIBLING;
336 if (get_maps(maps, "check-spf", &obj)) {
337 if (strcasecmp(cfg_obj_asstring(obj), "warn") == 0) {
338 zone_options |= DNS_ZONEOPT_CHECKSPF;
339 } else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
340 zone_options &= ~DNS_ZONEOPT_CHECKSPF;
344 zone_options |= DNS_ZONEOPT_CHECKSPF;
348 if (get_checknames(maps, &obj)) {
349 if (strcasecmp(cfg_obj_asstring(obj), "warn") == 0) {
350 zone_options |= DNS_ZONEOPT_CHECKNAMES;
351 zone_options &= ~DNS_ZONEOPT_CHECKNAMESFAIL;
352 } else if (strcasecmp(cfg_obj_asstring(obj), "fail") == 0) {
353 zone_options |= DNS_ZONEOPT_CHECKNAMES;
354 zone_options |= DNS_ZONEOPT_CHECKNAMESFAIL;
355 } else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
356 zone_options &= ~DNS_ZONEOPT_CHECKNAMES;
357 zone_options &= ~DNS_ZONEOPT_CHECKNAMESFAIL;
361 zone_options |= DNS_ZONEOPT_CHECKNAMES;
362 zone_options |= DNS_ZONEOPT_CHECKNAMESFAIL;
365 masterformat = dns_masterformat_text;
367 result = config_get(maps, "masterfile-format", &fmtobj);
368 if (result == ISC_R_SUCCESS) {
369 const char *masterformatstr = cfg_obj_asstring(fmtobj);
370 if (strcasecmp(masterformatstr, "text") == 0)
371 masterformat = dns_masterformat_text;
372 else if (strcasecmp(masterformatstr, "raw") == 0)
373 masterformat = dns_masterformat_raw;
378 result = load_zone(mctx, zname, zfile, masterformat, zclass, NULL);
379 if (result != ISC_R_SUCCESS)
380 fprintf(stderr, "%s/%s/%s: %s\n", view, zname, zclass,
381 dns_result_totext(result));
385 /*% configure a view */
387 configure_view(const char *vclass, const char *view, const cfg_obj_t *config,
388 const cfg_obj_t *vconfig, isc_mem_t *mctx)
390 const cfg_listelt_t *element;
391 const cfg_obj_t *voptions;
392 const cfg_obj_t *zonelist;
393 isc_result_t result = ISC_R_SUCCESS;
394 isc_result_t tresult;
398 voptions = cfg_tuple_get(vconfig, "options");
401 if (voptions != NULL)
402 (void)cfg_map_get(voptions, "zone", &zonelist);
404 (void)cfg_map_get(config, "zone", &zonelist);
406 for (element = cfg_list_first(zonelist);
408 element = cfg_list_next(element))
410 const cfg_obj_t *zconfig = cfg_listelt_value(element);
411 tresult = configure_zone(vclass, view, zconfig, vconfig,
413 if (tresult != ISC_R_SUCCESS)
420 /*% load zones from the configuration */
422 load_zones_fromconfig(const cfg_obj_t *config, isc_mem_t *mctx) {
423 const cfg_listelt_t *element;
424 const cfg_obj_t *classobj;
425 const cfg_obj_t *views;
426 const cfg_obj_t *vconfig;
428 isc_result_t result = ISC_R_SUCCESS;
429 isc_result_t tresult;
433 (void)cfg_map_get(config, "view", &views);
434 for (element = cfg_list_first(views);
436 element = cfg_list_next(element))
441 vconfig = cfg_listelt_value(element);
442 if (vconfig != NULL) {
443 classobj = cfg_tuple_get(vconfig, "class");
444 if (cfg_obj_isstring(classobj))
445 vclass = cfg_obj_asstring(classobj);
447 vname = cfg_obj_asstring(cfg_tuple_get(vconfig, "name"));
448 tresult = configure_view(vclass, vname, config, vconfig, mctx);
449 if (tresult != ISC_R_SUCCESS)
454 tresult = configure_view("IN", "_default", config, NULL, mctx);
455 if (tresult != ISC_R_SUCCESS)
462 output(void *closure, const char *text, int textlen) {
464 if (fwrite(text, 1, textlen, stdout) != (size_t)textlen) {
470 /*% The main processing routine */
472 main(int argc, char **argv) {
474 cfg_parser_t *parser = NULL;
475 cfg_obj_t *config = NULL;
476 const char *conffile = NULL;
477 isc_mem_t *mctx = NULL;
480 isc_entropy_t *ectx = NULL;
481 isc_boolean_t load_zones = ISC_FALSE;
482 isc_boolean_t print = ISC_FALSE;
483 unsigned int flags = 0;
485 isc_commandline_errprint = ISC_FALSE;
487 while ((c = isc_commandline_parse(argc, argv, "dhjt:pvxz")) != EOF) {
498 result = isc_dir_chroot(isc_commandline_argument);
499 if (result != ISC_R_SUCCESS) {
500 fprintf(stderr, "isc_dir_chroot: %s\n",
501 isc_result_totext(result));
511 printf(VERSION "\n");
515 flags |= CFG_PRINTER_XKEY;
519 load_zones = ISC_TRUE;
520 docheckmx = ISC_FALSE;
521 docheckns = ISC_FALSE;
522 dochecksrv = ISC_FALSE;
526 if (isc_commandline_option != '?')
527 fprintf(stderr, "%s: invalid argument -%c\n",
528 program, isc_commandline_option);
534 fprintf(stderr, "%s: unhandled option -%c\n",
535 program, isc_commandline_option);
540 if (((flags & CFG_PRINTER_XKEY) != 0) && !print) {
541 fprintf(stderr, "%s: -x cannot be used without -p\n", program);
545 if (isc_commandline_index + 1 < argc)
547 if (argv[isc_commandline_index] != NULL)
548 conffile = argv[isc_commandline_index];
549 if (conffile == NULL || conffile[0] == '\0')
550 conffile = NAMED_CONFFILE;
556 RUNTIME_CHECK(isc_mem_create(0, 0, &mctx) == ISC_R_SUCCESS);
558 RUNTIME_CHECK(setup_logging(mctx, stdout, &logc) == ISC_R_SUCCESS);
560 RUNTIME_CHECK(isc_entropy_create(mctx, &ectx) == ISC_R_SUCCESS);
561 RUNTIME_CHECK(isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE)
564 dns_result_register();
566 RUNTIME_CHECK(cfg_parser_create(mctx, logc, &parser) == ISC_R_SUCCESS);
568 cfg_parser_setcallback(parser, directory_callback, NULL);
570 if (cfg_parse_file(parser, conffile, &cfg_type_namedconf, &config) !=
574 result = bind9_check_namedconf(config, logc, mctx);
575 if (result != ISC_R_SUCCESS)
578 if (result == ISC_R_SUCCESS && load_zones) {
579 result = load_zones_fromconfig(config, mctx);
580 if (result != ISC_R_SUCCESS)
584 if (print && exit_status == 0)
585 cfg_printx(config, flags, output, NULL);
586 cfg_obj_destroy(parser, &config);
588 cfg_parser_destroy(&parser);
592 isc_log_destroy(&logc);
595 isc_entropy_detach(&ectx);
597 isc_mem_destroy(&mctx);
603 return (exit_status);