]> CyberLeo.Net >> Repos - FreeBSD/releng/8.1.git/blob - contrib/bind9/lib/dns/rootns.c
Copy stable/8 to releng/8.1 in preparation for 8.1-RC1.
[FreeBSD/releng/8.1.git] / contrib / bind9 / lib / dns / rootns.c
1 /*
2  * Copyright (C) 2004, 2005, 2007, 2008  Internet Systems Consortium, Inc. ("ISC")
3  * Copyright (C) 1999-2002  Internet Software Consortium.
4  *
5  * Permission to use, copy, modify, and/or distribute this software for any
6  * purpose with or without fee is hereby granted, provided that the above
7  * copyright notice and this permission notice appear in all copies.
8  *
9  * THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
10  * REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
11  * AND FITNESS.  IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
12  * INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
13  * LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
14  * OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
15  * PERFORMANCE OF THIS SOFTWARE.
16  */
17
18 /* $Id: rootns.c,v 1.36 2008/09/24 02:46:22 marka Exp $ */
19
20 /*! \file */
21
22 #include <config.h>
23
24 #include <isc/buffer.h>
25 #include <isc/string.h>         /* Required for HP/UX (and others?) */
26 #include <isc/util.h>
27
28 #include <dns/callbacks.h>
29 #include <dns/db.h>
30 #include <dns/dbiterator.h>
31 #include <dns/fixedname.h>
32 #include <dns/log.h>
33 #include <dns/master.h>
34 #include <dns/rdata.h>
35 #include <dns/rdata.h>
36 #include <dns/rdataset.h>
37 #include <dns/rdatasetiter.h>
38 #include <dns/rdatastruct.h>
39 #include <dns/rdatatype.h>
40 #include <dns/result.h>
41 #include <dns/rootns.h>
42 #include <dns/view.h>
43
44 static char root_ns[] =
45 ";\n"
46 "; Internet Root Nameservers\n"
47 ";\n"
48 "$TTL 518400\n"
49 ".                       518400  IN      NS      A.ROOT-SERVERS.NET.\n"
50 ".                       518400  IN      NS      B.ROOT-SERVERS.NET.\n"
51 ".                       518400  IN      NS      C.ROOT-SERVERS.NET.\n"
52 ".                       518400  IN      NS      D.ROOT-SERVERS.NET.\n"
53 ".                       518400  IN      NS      E.ROOT-SERVERS.NET.\n"
54 ".                       518400  IN      NS      F.ROOT-SERVERS.NET.\n"
55 ".                       518400  IN      NS      G.ROOT-SERVERS.NET.\n"
56 ".                       518400  IN      NS      H.ROOT-SERVERS.NET.\n"
57 ".                       518400  IN      NS      I.ROOT-SERVERS.NET.\n"
58 ".                       518400  IN      NS      J.ROOT-SERVERS.NET.\n"
59 ".                       518400  IN      NS      K.ROOT-SERVERS.NET.\n"
60 ".                       518400  IN      NS      L.ROOT-SERVERS.NET.\n"
61 ".                       518400  IN      NS      M.ROOT-SERVERS.NET.\n"
62 "A.ROOT-SERVERS.NET.     3600000 IN      A       198.41.0.4\n"
63 "A.ROOT-SERVERS.NET.     3600000 IN      AAAA    2001:503:BA3E::2:30\n"
64 "B.ROOT-SERVERS.NET.     3600000 IN      A       192.228.79.201\n"
65 "C.ROOT-SERVERS.NET.     3600000 IN      A       192.33.4.12\n"
66 "D.ROOT-SERVERS.NET.     3600000 IN      A       128.8.10.90\n"
67 "E.ROOT-SERVERS.NET.     3600000 IN      A       192.203.230.10\n"
68 "F.ROOT-SERVERS.NET.     3600000 IN      A       192.5.5.241\n"
69 "F.ROOT-SERVERS.NET.     3600000 IN      AAAA    2001:500:2F::F\n"
70 "G.ROOT-SERVERS.NET.     3600000 IN      A       192.112.36.4\n"
71 "H.ROOT-SERVERS.NET.     3600000 IN      A       128.63.2.53\n"
72 "H.ROOT-SERVERS.NET.     3600000 IN      AAAA    2001:500:1::803F:235\n"
73 "I.ROOT-SERVERS.NET.     3600000 IN      A       192.36.148.17\n"
74 "J.ROOT-SERVERS.NET.     3600000 IN      A       192.58.128.30\n"
75 "J.ROOT-SERVERS.NET.     3600000 IN      AAAA    2001:503:C27::2:30\n"
76 "K.ROOT-SERVERS.NET.     3600000 IN      A       193.0.14.129\n"
77 "K.ROOT-SERVERS.NET.     3600000 IN      AAAA    2001:7FD::1\n"
78 "L.ROOT-SERVERS.NET.     3600000 IN      A       199.7.83.42\n"
79 "M.ROOT-SERVERS.NET.     3600000 IN      A       202.12.27.33\n"
80 "M.ROOT-SERVERS.NET.     3600000 IN      AAAA    2001:DC3::35\n";
81
82 static isc_result_t
83 in_rootns(dns_rdataset_t *rootns, dns_name_t *name) {
84         isc_result_t result;
85         dns_rdata_t rdata = DNS_RDATA_INIT;
86         dns_rdata_ns_t ns;
87
88         if (!dns_rdataset_isassociated(rootns))
89                 return (ISC_R_NOTFOUND);
90
91         result = dns_rdataset_first(rootns);
92         while (result == ISC_R_SUCCESS) {
93                 dns_rdataset_current(rootns, &rdata);
94                 result = dns_rdata_tostruct(&rdata, &ns, NULL);
95                 if (result != ISC_R_SUCCESS)
96                         return (result);
97                 if (dns_name_compare(name, &ns.name) == 0)
98                         return (ISC_R_SUCCESS);
99                 result = dns_rdataset_next(rootns);
100                 dns_rdata_reset(&rdata);
101         }
102         if (result == ISC_R_NOMORE)
103                 result = ISC_R_NOTFOUND;
104         return (result);
105 }
106
107 static isc_result_t
108 check_node(dns_rdataset_t *rootns, dns_name_t *name,
109            dns_rdatasetiter_t *rdsiter) {
110         isc_result_t result;
111         dns_rdataset_t rdataset;
112
113         dns_rdataset_init(&rdataset);
114         result = dns_rdatasetiter_first(rdsiter);
115         while (result == ISC_R_SUCCESS) {
116                 dns_rdatasetiter_current(rdsiter, &rdataset);
117                 switch (rdataset.type) {
118                 case dns_rdatatype_a:
119                 case dns_rdatatype_aaaa:
120                         result = in_rootns(rootns, name);
121                         if (result != ISC_R_SUCCESS)
122                                 goto cleanup;
123                         break;
124                 case dns_rdatatype_ns:
125                         if (dns_name_compare(name, dns_rootname) == 0)
126                                 break;
127                         /*FALLTHROUGH*/
128                 default:
129                         result = ISC_R_FAILURE;
130                         goto cleanup;
131                 }
132                 dns_rdataset_disassociate(&rdataset);
133                 result = dns_rdatasetiter_next(rdsiter);
134         }
135         if (result == ISC_R_NOMORE)
136                 result = ISC_R_SUCCESS;
137  cleanup:
138         if (dns_rdataset_isassociated(&rdataset))
139                 dns_rdataset_disassociate(&rdataset);
140         return (result);
141 }
142
143 static isc_result_t
144 check_hints(dns_db_t *db) {
145         isc_result_t result;
146         dns_rdataset_t rootns;
147         dns_dbiterator_t *dbiter = NULL;
148         dns_dbnode_t *node = NULL;
149         isc_stdtime_t now;
150         dns_fixedname_t fixname;
151         dns_name_t *name;
152         dns_rdatasetiter_t *rdsiter = NULL;
153
154         isc_stdtime_get(&now);
155
156         dns_fixedname_init(&fixname);
157         name = dns_fixedname_name(&fixname);
158
159         dns_rdataset_init(&rootns);
160         (void)dns_db_find(db, dns_rootname, NULL, dns_rdatatype_ns, 0,
161                           now, NULL, name, &rootns, NULL);
162         result = dns_db_createiterator(db, 0, &dbiter);
163         if (result != ISC_R_SUCCESS)
164                 goto cleanup;
165         result = dns_dbiterator_first(dbiter);
166         while (result == ISC_R_SUCCESS) {
167                 result = dns_dbiterator_current(dbiter, &node, name);
168                 if (result != ISC_R_SUCCESS)
169                         goto cleanup;
170                 result = dns_db_allrdatasets(db, node, NULL, now, &rdsiter);
171                 if (result != ISC_R_SUCCESS)
172                         goto cleanup;
173                 result = check_node(&rootns, name, rdsiter);
174                 if (result != ISC_R_SUCCESS)
175                         goto cleanup;
176                 dns_rdatasetiter_destroy(&rdsiter);
177                 dns_db_detachnode(db, &node);
178                 result = dns_dbiterator_next(dbiter);
179         }
180         if (result == ISC_R_NOMORE)
181                 result = ISC_R_SUCCESS;
182
183  cleanup:
184         if (dns_rdataset_isassociated(&rootns))
185                 dns_rdataset_disassociate(&rootns);
186         if (rdsiter != NULL)
187                 dns_rdatasetiter_destroy(&rdsiter);
188         if (node != NULL)
189                 dns_db_detachnode(db, &node);
190         if (dbiter != NULL)
191                 dns_dbiterator_destroy(&dbiter);
192         return (result);
193 }
194
195 isc_result_t
196 dns_rootns_create(isc_mem_t *mctx, dns_rdataclass_t rdclass,
197                   const char *filename, dns_db_t **target)
198 {
199         isc_result_t result, eresult;
200         isc_buffer_t source;
201         size_t len;
202         dns_rdatacallbacks_t callbacks;
203         dns_db_t *db = NULL;
204
205         REQUIRE(target != NULL && *target == NULL);
206
207         result = dns_db_create(mctx, "rbt", dns_rootname, dns_dbtype_zone,
208                                rdclass, 0, NULL, &db);
209         if (result != ISC_R_SUCCESS)
210                 return (result);
211
212         dns_rdatacallbacks_init(&callbacks);
213
214         len = strlen(root_ns);
215         isc_buffer_init(&source, root_ns, len);
216         isc_buffer_add(&source, len);
217
218         result = dns_db_beginload(db, &callbacks.add,
219                                   &callbacks.add_private);
220         if (result != ISC_R_SUCCESS)
221                 return (result);
222         if (filename != NULL) {
223                 /*
224                  * Load the hints from the specified filename.
225                  */
226                 result = dns_master_loadfile(filename, &db->origin,
227                                              &db->origin, db->rdclass,
228                                              DNS_MASTER_HINT,
229                                              &callbacks, db->mctx);
230         } else if (rdclass == dns_rdataclass_in) {
231                 /*
232                  * Default to using the Internet root servers.
233                  */
234                 result = dns_master_loadbuffer(&source, &db->origin,
235                                                &db->origin, db->rdclass,
236                                                DNS_MASTER_HINT,
237                                                &callbacks, db->mctx);
238         } else
239                 result = ISC_R_NOTFOUND;
240         eresult = dns_db_endload(db, &callbacks.add_private);
241         if (result == ISC_R_SUCCESS || result == DNS_R_SEENINCLUDE)
242                 result = eresult;
243         if (result != ISC_R_SUCCESS && result != DNS_R_SEENINCLUDE)
244                 goto db_detach;
245         if (check_hints(db) != ISC_R_SUCCESS)
246                 isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
247                               DNS_LOGMODULE_HINTS, ISC_LOG_WARNING,
248                               "extra data in root hints '%s'",
249                               (filename != NULL) ? filename : "<BUILT-IN>");
250         *target = db;
251         return (ISC_R_SUCCESS);
252
253  db_detach:
254         dns_db_detach(&db);
255
256         return (result);
257 }
258
259 static void
260 report(dns_view_t *view, dns_name_t *name, isc_boolean_t missing,
261        dns_rdata_t *rdata)
262 {
263         const char *viewname = "", *sep = "";
264         char namebuf[DNS_NAME_FORMATSIZE];
265         char typebuf[DNS_RDATATYPE_FORMATSIZE];
266         char databuf[sizeof("xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:123.123.123.123")];
267         isc_buffer_t buffer;
268         isc_result_t result;
269
270         if (strcmp(view->name, "_bind") != 0 &&
271             strcmp(view->name, "_default") != 0) {
272                 viewname = view->name;
273                 sep = ": view ";
274         }
275
276         dns_name_format(name, namebuf, sizeof(namebuf));
277         dns_rdatatype_format(rdata->type, typebuf, sizeof(typebuf));
278         isc_buffer_init(&buffer, databuf, sizeof(databuf) - 1);
279         result = dns_rdata_totext(rdata, NULL, &buffer);
280         RUNTIME_CHECK(result == ISC_R_SUCCESS);
281         databuf[isc_buffer_usedlength(&buffer)] = '\0';
282
283         if (missing)
284                 isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
285                               DNS_LOGMODULE_HINTS, ISC_LOG_WARNING,
286                               "checkhints%s%s: %s/%s (%s) missing from hints",
287                               sep, viewname, namebuf, typebuf, databuf);
288         else
289                 isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
290                               DNS_LOGMODULE_HINTS, ISC_LOG_WARNING,
291                               "checkhints%s%s: %s/%s (%s) extra record "
292                               "in hints", sep, viewname, namebuf, typebuf,
293                               databuf);
294 }
295
296 static isc_boolean_t
297 inrrset(dns_rdataset_t *rrset, dns_rdata_t *rdata) {
298         isc_result_t result;
299         dns_rdata_t current = DNS_RDATA_INIT;
300
301         result = dns_rdataset_first(rrset);
302         while (result == ISC_R_SUCCESS) {
303                 dns_rdataset_current(rrset, &current);
304                 if (dns_rdata_compare(rdata, &current) == 0)
305                         return (ISC_TRUE);
306                 dns_rdata_reset(&current);
307                 result = dns_rdataset_next(rrset);
308         }
309         return (ISC_FALSE);
310 }
311
312 /*
313  * Check that the address RRsets match.
314  *
315  * Note we don't complain about missing glue records.
316  */
317
318 static void
319 check_address_records(dns_view_t *view, dns_db_t *hints, dns_db_t *db,
320                       dns_name_t *name, isc_stdtime_t now)
321 {
322         isc_result_t hresult, rresult, result;
323         dns_rdataset_t hintrrset, rootrrset;
324         dns_rdata_t rdata = DNS_RDATA_INIT;
325         dns_name_t *foundname;
326         dns_fixedname_t fixed;
327
328         dns_rdataset_init(&hintrrset);
329         dns_rdataset_init(&rootrrset);
330         dns_fixedname_init(&fixed);
331         foundname = dns_fixedname_name(&fixed);
332
333         hresult = dns_db_find(hints, name, NULL, dns_rdatatype_a, 0,
334                               now, NULL, foundname, &hintrrset, NULL);
335         rresult = dns_db_find(db, name, NULL, dns_rdatatype_a,
336                               DNS_DBFIND_GLUEOK, now, NULL, foundname,
337                               &rootrrset, NULL);
338         if (hresult == ISC_R_SUCCESS &&
339             (rresult == ISC_R_SUCCESS || rresult == DNS_R_GLUE)) {
340                 result = dns_rdataset_first(&rootrrset);
341                 while (result == ISC_R_SUCCESS) {
342                         dns_rdata_reset(&rdata);
343                         dns_rdataset_current(&rootrrset, &rdata);
344                         if (!inrrset(&hintrrset, &rdata))
345                                 report(view, name, ISC_TRUE, &rdata);
346                         result = dns_rdataset_next(&rootrrset);
347                 }
348                 result = dns_rdataset_first(&hintrrset);
349                 while (result == ISC_R_SUCCESS) {
350                         dns_rdata_reset(&rdata);
351                         dns_rdataset_current(&hintrrset, &rdata);
352                         if (!inrrset(&rootrrset, &rdata))
353                                 report(view, name, ISC_FALSE, &rdata);
354                         result = dns_rdataset_next(&hintrrset);
355                 }
356         }
357         if (hresult == ISC_R_NOTFOUND &&
358             (rresult == ISC_R_SUCCESS || rresult == DNS_R_GLUE)) {
359                 result = dns_rdataset_first(&rootrrset);
360                 while (result == ISC_R_SUCCESS) {
361                         dns_rdata_reset(&rdata);
362                         dns_rdataset_current(&rootrrset, &rdata);
363                         report(view, name, ISC_TRUE, &rdata);
364                         result = dns_rdataset_next(&rootrrset);
365                 }
366         }
367         if (dns_rdataset_isassociated(&rootrrset))
368                 dns_rdataset_disassociate(&rootrrset);
369         if (dns_rdataset_isassociated(&hintrrset))
370                 dns_rdataset_disassociate(&hintrrset);
371
372         /*
373          * Check AAAA records.
374          */
375         hresult = dns_db_find(hints, name, NULL, dns_rdatatype_aaaa, 0,
376                               now, NULL, foundname, &hintrrset, NULL);
377         rresult = dns_db_find(db, name, NULL, dns_rdatatype_aaaa,
378                               DNS_DBFIND_GLUEOK, now, NULL, foundname,
379                               &rootrrset, NULL);
380         if (hresult == ISC_R_SUCCESS &&
381             (rresult == ISC_R_SUCCESS || rresult == DNS_R_GLUE)) {
382                 result = dns_rdataset_first(&rootrrset);
383                 while (result == ISC_R_SUCCESS) {
384                         dns_rdata_reset(&rdata);
385                         dns_rdataset_current(&rootrrset, &rdata);
386                         if (!inrrset(&hintrrset, &rdata))
387                                 report(view, name, ISC_TRUE, &rdata);
388                         dns_rdata_reset(&rdata);
389                         result = dns_rdataset_next(&rootrrset);
390                 }
391                 result = dns_rdataset_first(&hintrrset);
392                 while (result == ISC_R_SUCCESS) {
393                         dns_rdata_reset(&rdata);
394                         dns_rdataset_current(&hintrrset, &rdata);
395                         if (!inrrset(&rootrrset, &rdata))
396                                 report(view, name, ISC_FALSE, &rdata);
397                         dns_rdata_reset(&rdata);
398                         result = dns_rdataset_next(&hintrrset);
399                 }
400         }
401         if (hresult == ISC_R_NOTFOUND &&
402             (rresult == ISC_R_SUCCESS || rresult == DNS_R_GLUE)) {
403                 result = dns_rdataset_first(&rootrrset);
404                 while (result == ISC_R_SUCCESS) {
405                         dns_rdata_reset(&rdata);
406                         dns_rdataset_current(&rootrrset, &rdata);
407                         report(view, name, ISC_TRUE, &rdata);
408                         dns_rdata_reset(&rdata);
409                         result = dns_rdataset_next(&rootrrset);
410                 }
411         }
412         if (dns_rdataset_isassociated(&rootrrset))
413                 dns_rdataset_disassociate(&rootrrset);
414         if (dns_rdataset_isassociated(&hintrrset))
415                 dns_rdataset_disassociate(&hintrrset);
416 }
417
418 void
419 dns_root_checkhints(dns_view_t *view, dns_db_t *hints, dns_db_t *db) {
420         isc_result_t result;
421         dns_rdata_t rdata = DNS_RDATA_INIT;
422         dns_rdata_ns_t ns;
423         dns_rdataset_t hintns, rootns;
424         const char *viewname = "", *sep = "";
425         isc_stdtime_t now;
426         dns_name_t *name;
427         dns_fixedname_t fixed;
428
429         REQUIRE(hints != NULL);
430         REQUIRE(db != NULL);
431         REQUIRE(view != NULL);
432
433         isc_stdtime_get(&now);
434
435         if (strcmp(view->name, "_bind") != 0 &&
436             strcmp(view->name, "_default") != 0) {
437                 viewname = view->name;
438                 sep = ": view ";
439         }
440
441         dns_rdataset_init(&hintns);
442         dns_rdataset_init(&rootns);
443         dns_fixedname_init(&fixed);
444         name = dns_fixedname_name(&fixed);
445
446         result = dns_db_find(hints, dns_rootname, NULL, dns_rdatatype_ns, 0,
447                              now, NULL, name, &hintns, NULL);
448         if (result != ISC_R_SUCCESS) {
449                 isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
450                               DNS_LOGMODULE_HINTS, ISC_LOG_WARNING,
451                               "checkhints%s%s: unable to get root NS rrset "
452                               "from hints: %s", sep, viewname,
453                               dns_result_totext(result));
454                 goto cleanup;
455         }
456
457         result = dns_db_find(db, dns_rootname, NULL, dns_rdatatype_ns, 0,
458                              now, NULL, name, &rootns, NULL);
459         if (result != ISC_R_SUCCESS) {
460                 isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
461                               DNS_LOGMODULE_HINTS, ISC_LOG_WARNING,
462                               "checkhints%s%s: unable to get root NS rrset "
463                               "from cache: %s", sep, viewname,
464                               dns_result_totext(result));
465                 goto cleanup;
466         }
467
468         /*
469          * Look for missing root NS names.
470          */
471         result = dns_rdataset_first(&rootns);
472         while (result == ISC_R_SUCCESS) {
473                 dns_rdataset_current(&rootns, &rdata);
474                 result = dns_rdata_tostruct(&rdata, &ns, NULL);
475                 RUNTIME_CHECK(result == ISC_R_SUCCESS);
476                 result = in_rootns(&hintns, &ns.name);
477                 if (result != ISC_R_SUCCESS) {
478                         char namebuf[DNS_NAME_FORMATSIZE];
479                         /* missing from hints */
480                         dns_name_format(&ns.name, namebuf, sizeof(namebuf));
481                         isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
482                                       DNS_LOGMODULE_HINTS, ISC_LOG_WARNING,
483                                       "checkhints%s%s: unable to find root "
484                                       "NS '%s' in hints", sep, viewname,
485                                       namebuf);
486                 } else
487                         check_address_records(view, hints, db, &ns.name, now);
488                 dns_rdata_reset(&rdata);
489                 result = dns_rdataset_next(&rootns);
490         }
491         if (result != ISC_R_NOMORE) {
492                 goto cleanup;
493         }
494
495         /*
496          * Look for extra root NS names.
497          */
498         result = dns_rdataset_first(&hintns);
499         while (result == ISC_R_SUCCESS) {
500                 dns_rdataset_current(&hintns, &rdata);
501                 result = dns_rdata_tostruct(&rdata, &ns, NULL);
502                 RUNTIME_CHECK(result == ISC_R_SUCCESS);
503                 result = in_rootns(&rootns, &ns.name);
504                 if (result != ISC_R_SUCCESS) {
505                         char namebuf[DNS_NAME_FORMATSIZE];
506                         /* extra entry in hints */
507                         dns_name_format(&ns.name, namebuf, sizeof(namebuf));
508                         isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
509                                       DNS_LOGMODULE_HINTS, ISC_LOG_WARNING,
510                                       "checkhints%s%s: extra NS '%s' in hints",
511                                       sep, viewname, namebuf);
512                 }
513                 dns_rdata_reset(&rdata);
514                 result = dns_rdataset_next(&hintns);
515         }
516         if (result != ISC_R_NOMORE) {
517                 goto cleanup;
518         }
519
520  cleanup:
521         if (dns_rdataset_isassociated(&rootns))
522                 dns_rdataset_disassociate(&rootns);
523         if (dns_rdataset_isassociated(&hintns))
524                 dns_rdataset_disassociate(&hintns);
525 }