Home | History | Annotate | Line # | Download | only in dns
      1 /*	$NetBSD: rdataset.h,v 1.17 2026/09/17 18:01:16 christos Exp $	*/
      2 
      3 /*
      4  * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
      5  *
      6  * SPDX-License-Identifier: MPL-2.0
      7  *
      8  * This Source Code Form is subject to the terms of the Mozilla Public
      9  * License, v. 2.0. If a copy of the MPL was not distributed with this
     10  * file, you can obtain one at https://mozilla.org/MPL/2.0/.
     11  *
     12  * See the COPYRIGHT file distributed with this work for additional
     13  * information regarding copyright ownership.
     14  */
     15 
     16 #pragma once
     17 
     18 /*****
     19 ***** Module Info
     20 *****/
     21 
     22 /*! \file dns/rdataset.h
     23  * \brief
     24  * A DNS rdataset is a handle that can be associated with a collection of
     25  * rdata all having a common owner name, class, and type.
     26  *
     27  * The dns_rdataset_t type is like a "virtual class".  To actually use
     28  * rdatasets, an implementation of the method suite (e.g. "slabbed rdata") is
     29  * required.
     30  *
     31  * XXX <more> XXX
     32  *
     33  * MP:
     34  *\li	Clients of this module must impose any required synchronization.
     35  *
     36  * Reliability:
     37  *\li	No anticipated impact.
     38  *
     39  * Resources:
     40  *\li	TBS
     41  *
     42  * Security:
     43  *\li	No anticipated impact.
     44  *
     45  * Standards:
     46  *\li	None.
     47  */
     48 
     49 #include <inttypes.h>
     50 #include <stdbool.h>
     51 
     52 #include <isc/lang.h>
     53 #include <isc/magic.h>
     54 #include <isc/stdtime.h>
     55 
     56 #include <dns/rdatastruct.h>
     57 #include <dns/types.h>
     58 
     59 #define DNS_RDATASET_MAXADDITIONAL 13
     60 
     61 /* Fixed RRSet helper macros */
     62 
     63 #define DNS_RDATASET_LENGTH 2;
     64 
     65 #if DNS_RDATASET_FIXED
     66 #define DNS_RDATASET_ORDER 2
     67 #define DNS_RDATASET_COUNT (count * 4)
     68 #else /* !DNS_RDATASET_FIXED */
     69 #define DNS_RDATASET_ORDER 0
     70 #define DNS_RDATASET_COUNT 0
     71 #endif /* DNS_RDATASET_FIXED */
     72 
     73 ISC_LANG_BEGINDECLS
     74 
     75 typedef enum {
     76 	dns_rdatasetadditional_fromauth,
     77 	dns_rdatasetadditional_fromcache,
     78 	dns_rdatasetadditional_fromglue
     79 } dns_rdatasetadditional_t;
     80 
     81 typedef struct dns_rdatasetmethods {
     82 	void (*disassociate)(dns_rdataset_t *rdataset DNS__DB_FLARG);
     83 	isc_result_t (*first)(dns_rdataset_t *rdataset);
     84 	isc_result_t (*next)(dns_rdataset_t *rdataset);
     85 	void (*current)(dns_rdataset_t *rdataset, dns_rdata_t *rdata);
     86 	void (*clone)(dns_rdataset_t	    *source,
     87 		      dns_rdataset_t *target DNS__DB_FLARG);
     88 	unsigned int (*count)(dns_rdataset_t *rdataset);
     89 	isc_result_t (*addnoqname)(dns_rdataset_t   *rdataset,
     90 				   const dns_name_t *name,
     91 				   dns_rdatatype_t   type);
     92 	isc_result_t (*getnoqname)(dns_rdataset_t *rdataset, dns_name_t *name,
     93 				   dns_rdataset_t	 *neg,
     94 				   dns_rdataset_t *negsig DNS__DB_FLARG);
     95 	void (*settrust)(dns_rdataset_t *rdataset, dns_trust_t trust);
     96 	void (*expire)(dns_rdataset_t *rdataset DNS__DB_FLARG);
     97 	void (*clearprefetch)(dns_rdataset_t *rdataset);
     98 	void (*setownercase)(dns_rdataset_t *rdataset, const dns_name_t *name);
     99 	void (*getownercase)(const dns_rdataset_t *rdataset, dns_name_t *name);
    100 	isc_result_t (*addglue)(dns_rdataset_t	*rdataset,
    101 				dns_dbversion_t *version, dns_message_t *msg);
    102 } dns_rdatasetmethods_t;
    103 
    104 #define DNS_RDATASET_MAGIC	ISC_MAGIC('D', 'N', 'S', 'R')
    105 #define DNS_RDATASET_VALID(set) ISC_MAGIC_VALID(set, DNS_RDATASET_MAGIC)
    106 
    107 /*%
    108  * Direct use of this structure by clients is strongly discouraged, except
    109  * for the 'link' field which may be used however the client wishes.  The
    110  * 'private', 'current', and 'index' fields MUST NOT be changed by clients.
    111  * rdataset implementations may change any of the fields.
    112  */
    113 struct dns_rdataset {
    114 	unsigned int	       magic;
    115 	dns_rdatasetmethods_t *methods;
    116 	ISC_LINK(dns_rdataset_t) link;
    117 
    118 	/*
    119 	 * XXX do we need these, or should they be retrieved by methods?
    120 	 * Leaning towards the latter, since they are not frequently required
    121 	 * once you have the rdataset.
    122 	 */
    123 	dns_rdataclass_t rdclass;
    124 	dns_rdatatype_t	 type;
    125 	dns_ttl_t	 ttl;
    126 
    127 	dns_trust_t	trust;
    128 	dns_rdatatype_t covers;
    129 
    130 	/*
    131 	 * attributes
    132 	 */
    133 	unsigned int attributes;
    134 
    135 	/*%
    136 	 * the counter provides the starting point in the "cyclic" order.
    137 	 * The value UINT32_MAX has a special meaning of "picking up a
    138 	 * random value." in order to take care of databases that do not
    139 	 * increment the counter.
    140 	 */
    141 	uint32_t count;
    142 
    143 	/*
    144 	 * This RRSIG RRset should be re-generated around this time.
    145 	 * Only valid if DNS_RDATASETATTR_RESIGN is set in attributes.
    146 	 */
    147 	union {
    148 		isc_stdtime_t resign;
    149 		isc_stdtime_t expire;
    150 	};
    151 
    152 	/*%
    153 	 * Extra fields used by various rdataset implementations, that is, by
    154 	 * the code referred to in the rdataset methods table. The names of
    155 	 * the structures roughly correspond to the file containing the
    156 	 * implementation, except that `rdlist` is used by `rdatalist.c`,
    157 	 * `sdb.c`, and `sdlz.c`.
    158 	 *
    159 	 * Pointers in these structs use incomplete structure types,
    160 	 * because the structure definitions and corresponding typedef
    161 	 * names might not be in scope in this header.
    162 	 */
    163 	/*@}*/
    164 	union {
    165 		struct {
    166 			struct dns_keynode *node;
    167 			dns_rdata_t	   *iter;
    168 		} keytable;
    169 
    170 		/*
    171 		 * An ncache rdataset is a view of memory held elsewhere:
    172 		 * raw can point to either a buffer on the stack or to an
    173 		 * rdataslab, such as in an rbtdb database.
    174 		 */
    175 		struct {
    176 			unsigned char *raw;
    177 			unsigned char *iter_pos;
    178 			unsigned int   iter_count;
    179 		} ncache;
    180 
    181 		/*
    182 		 * A slab rdataset provides access to an rdataslab. In
    183 		 * an rbtdb database, 'raw' will generally point to the
    184 		 * memory immediately following a slabheader. (There
    185 		 * is an exception in the case of rdatasets returned by
    186 		 * the `getnoqname` method; see comments in rbtdb.c
    187 		 * for details.)
    188 		 */
    189 		struct {
    190 			struct dns_db	       *db;
    191 			dns_dbnode_t	       *node;
    192 			unsigned char	       *raw;
    193 			unsigned char	       *iter_pos;
    194 			unsigned int		iter_count;
    195 			dns_slabheader_proof_t *noqname;
    196 		} slab;
    197 
    198 		/*
    199 		 * A proof rdataset is a view into a slabheader's noqname or
    200 		 * closest-encloser proof.  The header reference keeps the
    201 		 * proof memory alive for as long as the view is associated.
    202 		 * Keep the fields shared with 'slab' at the same offsets.
    203 		 */
    204 		struct {
    205 			struct dns_db	 *db;
    206 			dns_dbnode_t	 *node;
    207 			unsigned char	 *raw;
    208 			unsigned char	 *iter_pos;
    209 			unsigned int	  iter_count;
    210 			dns_slabheader_t *header;
    211 		} proof;
    212 
    213 		/*
    214 		 * A simple rdatalist, plus an optional dbnode used by
    215 		 * builtin and sdlz.
    216 		 */
    217 		struct {
    218 			struct dns_rdatalist *list;
    219 			struct dns_rdata     *iter;
    220 
    221 			/*
    222 			 * Refers to the name passed in by the caller of
    223 			 * dns_rdataset_addnoqname(), and the denial type
    224 			 * (NSEC or NSEC3) of the proof selected there.
    225 			 */
    226 			const struct dns_name *noqname;
    227 			dns_rdatatype_t	       noqnametype;
    228 			dns_dbnode_t	      *node;
    229 		} rdlist;
    230 
    231 #ifdef USE_DNSRPS
    232 		/*
    233 		 * DNSRPS rdatasets. dns_rpsdb_t is defined in dnsrps.h.
    234 		 */
    235 		struct {
    236 			dns_rpsdb_t *db;
    237 			void	    *iter_pos;
    238 			unsigned int iter_count;
    239 		} rps;
    240 #endif /* USE_DNSRPS */
    241 	};
    242 };
    243 
    244 #define DNS_RDATASET_COUNT_UNDEFINED UINT32_MAX
    245 
    246 #define DNS_RDATASET_INIT               \
    247 	{ .magic = DNS_RDATASET_MAGIC,  \
    248 	  .link = ISC_LINK_INITIALIZER, \
    249 	  .count = DNS_RDATASET_COUNT_UNDEFINED }
    250 
    251 /*!
    252  * \def DNS_RDATASETATTR_RENDERED
    253  *	Used by message.c to indicate that the rdataset was rendered.
    254  *
    255  * \def DNS_RDATASETATTR_TTLADJUSTED
    256  *	Used by message.c to indicate that the rdataset's rdata had differing
    257  *	TTL values, and the rdataset->ttl holds the smallest.
    258  *
    259  * \def DNS_RDATASETATTR_LOADORDER
    260  *	Output the RRset in load order.
    261  */
    262 
    263 #define DNS_RDATASETATTR_NONE	      0x00000000 /*%< No ordering. */
    264 #define DNS_RDATASETATTR_QUESTION     0x00000001
    265 #define DNS_RDATASETATTR_RENDERED     0x00000002 /*%< Used by message.c */
    266 #define DNS_RDATASETATTR_ANSWERED     0x00000004 /*%< Used by server. */
    267 #define DNS_RDATASETATTR_CACHE	      0x00000008 /*%< Used by resolver. */
    268 #define DNS_RDATASETATTR_ANSWER	      0x00000010 /*%< Used by resolver. */
    269 #define DNS_RDATASETATTR_ANSWERSIG    0x00000020 /*%< Used by resolver. */
    270 #define DNS_RDATASETATTR_EXTERNAL     0x00000040 /*%< Used by resolver. */
    271 #define DNS_RDATASETATTR_NCACHE	      0x00000080 /*%< Used by resolver. */
    272 #define DNS_RDATASETATTR_CHAINING     0x00000100 /*%< Used by resolver. */
    273 #define DNS_RDATASETATTR_TTLADJUSTED  0x00000200 /*%< Used by message.c */
    274 #define DNS_RDATASETATTR_FIXEDORDER   0x00000400 /*%< Fixed ordering. */
    275 #define DNS_RDATASETATTR_RANDOMIZE    0x00000800 /*%< Random ordering. */
    276 #define DNS_RDATASETATTR_CHASE	      0x00001000 /*%< Used by resolver. */
    277 #define DNS_RDATASETATTR_NXDOMAIN     0x00002000
    278 #define DNS_RDATASETATTR_NOQNAME      0x00004000
    279 #define DNS_RDATASETATTR_CHECKNAMES   0x00008000 /*%< Used by resolver. */
    280 #define DNS_RDATASETATTR_REQUIRED     0x00010000
    281 #define DNS_RDATASETATTR_REQUIREDGLUE DNS_RDATASETATTR_REQUIRED
    282 #define DNS_RDATASETATTR_LOADORDER    0x00020000
    283 #define DNS_RDATASETATTR_RESIGN	      0x00040000
    284 /* #define DNS_RDATASETATTR_CLOSEST      0x00080000 - Obsolete */
    285 #define DNS_RDATASETATTR_OPTOUT	      0x00100000 /*%< OPTOUT proof */
    286 #define DNS_RDATASETATTR_NEGATIVE     0x00200000
    287 #define DNS_RDATASETATTR_PREFETCH     0x00400000
    288 #define DNS_RDATASETATTR_CYCLIC	      0x00800000 /*%< Cyclic ordering. */
    289 #define DNS_RDATASETATTR_STALE	      0x01000000
    290 #define DNS_RDATASETATTR_ANCIENT      0x02000000
    291 #define DNS_RDATASETATTR_STALE_WINDOW 0x04000000
    292 /* #define DNS_RDATASETATTR_STALE_ADDED  0x08000000 - Obsolete */
    293 #define DNS_RDATASETATTR_KEEPCASE   0x10000000
    294 #define DNS_RDATASETATTR_STATICSTUB 0x20000000
    295 
    296 /*%
    297  * _OMITDNSSEC:
    298  * 	Omit DNSSEC records when rendering ncache records.
    299  */
    300 #define DNS_RDATASETTOWIRE_OMITDNSSEC 0x0001
    301 
    302 void
    303 dns_rdataset_init(dns_rdataset_t *rdataset);
    304 /*%<
    305  * Make 'rdataset' a valid, disassociated rdataset.
    306  *
    307  * Requires:
    308  *\li	'rdataset' is not NULL.
    309  *
    310  * Ensures:
    311  *\li	'rdataset' is a valid, disassociated rdataset.
    312  */
    313 
    314 void
    315 dns_rdataset_invalidate(dns_rdataset_t *rdataset);
    316 /*%<
    317  * Invalidate 'rdataset'.
    318  *
    319  * Requires:
    320  *\li	'rdataset' is a valid, disassociated rdataset.
    321  *
    322  * Ensures:
    323  *\li	If assertion checking is enabled, future attempts to use 'rdataset'
    324  *	without initializing it will cause an assertion failure.
    325  */
    326 
    327 #define dns_rdataset_disassociate(rdataset) \
    328 	dns__rdataset_disassociate(rdataset DNS__DB_FILELINE)
    329 void
    330 dns__rdataset_disassociate(dns_rdataset_t *rdataset DNS__DB_FLARG);
    331 /*%<
    332  * Disassociate 'rdataset' from its rdata, allowing it to be reused.
    333  *
    334  * Notes:
    335  *\li	The client must ensure it has no references to rdata in the rdataset
    336  *	before disassociating.
    337  *
    338  * Requires:
    339  *\li	'rdataset' is a valid, associated rdataset.
    340  *
    341  * Ensures:
    342  *\li	'rdataset' is a valid, disassociated rdataset.
    343  */
    344 
    345 bool
    346 dns_rdataset_isassociated(dns_rdataset_t *rdataset);
    347 /*%<
    348  * Is 'rdataset' associated?
    349  *
    350  * Requires:
    351  *\li	'rdataset' is a valid rdataset.
    352  *
    353  * Returns:
    354  *\li	#true			'rdataset' is associated.
    355  *\li	#false			'rdataset' is not associated.
    356  */
    357 
    358 void
    359 dns_rdataset_makequestion(dns_rdataset_t *rdataset, dns_rdataclass_t rdclass,
    360 			  dns_rdatatype_t type);
    361 /*%<
    362  * Make 'rdataset' a valid, associated, question rdataset, with a
    363  * question class of 'rdclass' and type 'type'.
    364  *
    365  * Notes:
    366  *\li	Question rdatasets have a class and type, but no rdata.
    367  *
    368  * Requires:
    369  *\li	'rdataset' is a valid, disassociated rdataset.
    370  *
    371  * Ensures:
    372  *\li	'rdataset' is a valid, associated, question rdataset.
    373  */
    374 
    375 #define dns_rdataset_clone(source, target) \
    376 	dns__rdataset_clone(source, target DNS__DB_FILELINE)
    377 void
    378 dns__rdataset_clone(dns_rdataset_t	  *source,
    379 		    dns_rdataset_t *target DNS__DB_FLARG);
    380 /*%<
    381  * Make 'target' refer to the same rdataset as 'source'.
    382  *
    383  * Requires:
    384  *\li	'source' is a valid, associated rdataset.
    385  *
    386  *\li	'target' is a valid, dissociated rdataset.
    387  *
    388  * Ensures:
    389  *\li	'target' references the same rdataset as 'source'.
    390  */
    391 
    392 unsigned int
    393 dns_rdataset_count(dns_rdataset_t *rdataset);
    394 /*%<
    395  * Return the number of records in 'rdataset'.
    396  *
    397  * Requires:
    398  *\li	'rdataset' is a valid, associated rdataset.
    399  *
    400  * Returns:
    401  *\li	The number of records in 'rdataset'.
    402  */
    403 
    404 isc_result_t
    405 dns_rdataset_first(dns_rdataset_t *rdataset);
    406 /*%<
    407  * Move the rdata cursor to the first rdata in the rdataset (if any).
    408  *
    409  * Requires:
    410  *\li	'rdataset' is a valid, associated rdataset.
    411  *
    412  * Returns:
    413  *\li	#ISC_R_SUCCESS
    414  *\li	#ISC_R_NOMORE			There are no rdata in the set.
    415  */
    416 
    417 isc_result_t
    418 dns_rdataset_next(dns_rdataset_t *rdataset);
    419 /*%<
    420  * Move the rdata cursor to the next rdata in the rdataset (if any).
    421  *
    422  * Requires:
    423  *\li	'rdataset' is a valid, associated rdataset.
    424  *
    425  * Returns:
    426  *\li	#ISC_R_SUCCESS
    427  *\li	#ISC_R_NOMORE			There are no more rdata in the set.
    428  */
    429 
    430 void
    431 dns_rdataset_current(dns_rdataset_t *rdataset, dns_rdata_t *rdata);
    432 /*%<
    433  * Make 'rdata' refer to the current rdata.
    434  *
    435  * Notes:
    436  *
    437  *\li	The data returned in 'rdata' is valid for the life of the
    438  *	rdataset; in particular, subsequent changes in the cursor position
    439  *	do not invalidate 'rdata'.
    440  *
    441  * Requires:
    442  *\li	'rdataset' is a valid, associated rdataset.
    443  *
    444  *\li	The rdata cursor of 'rdataset' is at a valid location (i.e. the
    445  *	result of last call to a cursor movement command was ISC_R_SUCCESS).
    446  *
    447  * Ensures:
    448  *\li	'rdata' refers to the rdata at the rdata cursor location of
    449  *\li	'rdataset'.
    450  */
    451 
    452 isc_result_t
    453 dns_rdataset_totext(dns_rdataset_t *rdataset, const dns_name_t *owner_name,
    454 		    bool omit_final_dot, bool question, isc_buffer_t *target);
    455 /*%<
    456  * Convert 'rdataset' to text format, storing the result in 'target'.
    457  *
    458  * Notes:
    459  *\li	The rdata cursor position will be changed.
    460  *
    461  *\li	The 'question' flag should normally be #false.  If it is
    462  *	#true, the TTL and rdata fields are not printed.  This is
    463  *	for use when printing an rdata representing a question section.
    464  *
    465  *\li	This interface is deprecated; use dns_master_rdatasettottext()
    466  * 	and/or dns_master_questiontotext() instead.
    467  *
    468  * Requires:
    469  *\li	'rdataset' is a valid rdataset.
    470  *
    471  *\li	'rdataset' is not empty.
    472  */
    473 
    474 isc_result_t
    475 dns_rdataset_towire(dns_rdataset_t *rdataset, const dns_name_t *owner_name,
    476 		    dns_compress_t *cctx, isc_buffer_t *target,
    477 		    unsigned int options, unsigned int *countp);
    478 /*%<
    479  * Convert 'rdataset' to wire format, compressing names as specified
    480  * in 'cctx', and storing the result in 'target'.
    481  *
    482  * Notes:
    483  *\li	The rdata cursor position will be changed.
    484  *
    485  *\li	The number of RRs added to target will be added to *countp.
    486  *
    487  * Requires:
    488  *\li	'rdataset' is a valid rdataset.
    489  *
    490  *\li	'rdataset' is not empty.
    491  *
    492  *\li	'countp' is a valid pointer.
    493  *
    494  * Ensures:
    495  *\li	On a return of ISC_R_SUCCESS, 'target' contains a wire format
    496  *	for the data contained in 'rdataset'.  Any error return leaves
    497  *	the buffer unchanged.
    498  *
    499  *\li	*countp has been incremented by the number of RRs added to
    500  *	target.
    501  *
    502  * Returns:
    503  *\li	#ISC_R_SUCCESS		- all ok
    504  *\li	#ISC_R_NOSPACE		- 'target' doesn't have enough room
    505  *
    506  *\li	Any error returned by dns_rdata_towire(), dns_rdataset_next(),
    507  *	dns_name_towire().
    508  */
    509 
    510 isc_result_t
    511 dns_rdataset_towiresorted(dns_rdataset_t   *rdataset,
    512 			  const dns_name_t *owner_name, dns_compress_t *cctx,
    513 			  isc_buffer_t *target, dns_rdatasetorderfunc_t order,
    514 			  const void *order_arg, unsigned int options,
    515 			  unsigned int *countp);
    516 /*%<
    517  * Like dns_rdataset_towire(), but sorting the rdatasets according to
    518  * the integer value returned by 'order' when called with the rdataset
    519  * and 'order_arg' as arguments.
    520  *
    521  * Requires:
    522  *\li	All the requirements of dns_rdataset_towire(), and
    523  *	that order_arg is NULL if and only if order is NULL.
    524  */
    525 
    526 isc_result_t
    527 dns_rdataset_towirepartial(dns_rdataset_t   *rdataset,
    528 			   const dns_name_t *owner_name, dns_compress_t *cctx,
    529 			   isc_buffer_t *target, dns_rdatasetorderfunc_t order,
    530 			   const void *order_arg, unsigned int options,
    531 			   unsigned int *countp, void **state);
    532 /*%<
    533  * Like dns_rdataset_towiresorted() except that a partial rdataset
    534  * may be written.
    535  *
    536  * Requires:
    537  *\li	All the requirements of dns_rdataset_towiresorted().
    538  *	If 'state' is non NULL then the current position in the
    539  *	rdataset will be remembered if the rdataset in not
    540  *	completely written and should be passed on on subsequent
    541  *	calls (NOT CURRENTLY IMPLEMENTED).
    542  *
    543  * Returns:
    544  *\li	#ISC_R_SUCCESS if all of the records were written.
    545  *\li	#ISC_R_NOSPACE if unable to fit in all of the records. *countp
    546  *		      will be updated to reflect the number of records
    547  *		      written.
    548  */
    549 
    550 isc_result_t
    551 dns_rdataset_additionaldata(dns_rdataset_t	    *rdataset,
    552 			    const dns_name_t	    *owner_name,
    553 			    dns_additionaldatafunc_t add, void *arg,
    554 			    size_t limit);
    555 /*%<
    556  * For each rdata in rdataset, call 'add' for each name and type in the
    557  * rdata which is subject to additional section processing.
    558  *
    559  * Requires:
    560  *
    561  *\li	'rdataset' is a valid, non-question rdataset.
    562  *
    563  *\li	'add' is a valid dns_additionaldatafunc_t
    564  *
    565  * Ensures:
    566  *
    567  *\li	If successful, dns_rdata_additionaldata() will have been called for
    568  *	each rdata in 'rdataset'.
    569  *
    570  *\li	If a call to dns_rdata_additionaldata() is not successful, the
    571  *	result returned will be the result of dns_rdataset_additionaldata().
    572  *
    573  *\li	If 'limit' is non-zero and the number of the rdatasets is larger
    574  *	than 'limit', no additional data will be processed.
    575  *
    576  * Returns:
    577  *
    578  *\li	#ISC_R_SUCCESS
    579  *
    580  *\li	#DNS_R_TOOMANYRECORDS in case rdataset count is larger than 'limit'
    581  *
    582  *\li	Any error that dns_rdata_additionaldata() can return.
    583  */
    584 
    585 #define dns_rdataset_getnoqname(rdataset, name, neg, negsig) \
    586 	dns__rdataset_getnoqname(rdataset, name, neg, negsig DNS__DB_FILELINE)
    587 isc_result_t
    588 dns__rdataset_getnoqname(dns_rdataset_t *rdataset, dns_name_t *name,
    589 			 dns_rdataset_t	       *neg,
    590 			 dns_rdataset_t *negsig DNS__DB_FLARG);
    591 /*%<
    592  * Return the noqname proof for this record.
    593  *
    594  * Requires:
    595  *\li	'rdataset' to be valid and #DNS_RDATASETATTR_NOQNAME to be set.
    596  *\li	'name' to be valid.
    597  *\li	'neg' and 'negsig' to be valid and not associated.
    598  */
    599 
    600 isc_result_t
    601 dns_rdataset_addnoqname(dns_rdataset_t *rdataset, dns_name_t *name,
    602 			dns_rdatatype_t type);
    603 /*%<
    604  * Associate a noqname proof with this record: the rdataset of 'type'
    605  * (NSEC or NSEC3) at 'name' together with the RRSIG rdataset covering it.
    606  * Sets #DNS_RDATASETATTR_NOQNAME if successful.
    607  * Adjusts the 'rdataset->ttl' to minimum of the 'rdataset->ttl' and
    608  * the 'nsec'/'nsec3' and 'rrsig(nsec)'/'rrsig(nsec3)' ttl.
    609  *
    610  * Requires:
    611  *\li	'rdataset' to be valid.
    612  *\li	'name' to be valid.
    613  *\li	'type' to be dns_rdatatype_nsec or dns_rdatatype_nsec3.
    614  *
    615  * Returns:
    616  *\li	#ISC_R_SUCCESS
    617  *\li	#ISC_R_NOTFOUND if 'name' has no rdataset of 'type' or no RRSIG
    618  *	 rdataset covering it.
    619  *\li	#ISC_R_NOTIMPLEMENTED if the rdataset implementation does not
    620  *	 support noqname proofs.
    621  */
    622 
    623 void
    624 dns_rdataset_settrust(dns_rdataset_t *rdataset, dns_trust_t trust);
    625 /*%<
    626  * Set the trust of the 'rdataset' to trust in any in the backing database.
    627  * The local trust level of 'rdataset' is also set.
    628  */
    629 
    630 #define dns_rdataset_expire(rdataset) \
    631 	dns__rdataset_expire(rdataset DNS__DB_FILELINE)
    632 void
    633 dns__rdataset_expire(dns_rdataset_t *rdataset DNS__DB_FLARG);
    634 /*%<
    635  * Mark the rdataset to be expired in the backing database.
    636  */
    637 
    638 void
    639 dns_rdataset_clearprefetch(dns_rdataset_t *rdataset);
    640 /*%<
    641  * Clear the PREFETCH attribute for the given rdataset in the
    642  * underlying database.
    643  *
    644  * In the cache database, this signals that the rdataset is not
    645  * eligible to be prefetched when the TTL is close to expiring.
    646  * It has no function in other databases.
    647  */
    648 
    649 void
    650 dns_rdataset_setownercase(dns_rdataset_t *rdataset, const dns_name_t *name);
    651 /*%<
    652  * Store the casing of 'name', the owner name of 'rdataset', into
    653  * a bitfield so that the name can be capitalized the same when when
    654  * the rdataset is used later. This sets the CASESET attribute.
    655  */
    656 
    657 void
    658 dns_rdataset_getownercase(const dns_rdataset_t *rdataset, dns_name_t *name);
    659 /*%<
    660  * If the CASESET attribute is set, retrieve the case bitfield that was
    661  * previously stored by dns_rdataset_getownername(), and capitalize 'name'
    662  * according to it. If CASESET is not set, do nothing.
    663  */
    664 
    665 void
    666 dns_rdataset_trimttl(dns_rdataset_t *rdataset, dns_rdataset_t *sigrdataset,
    667 		     dns_rdata_rrsig_t *rrsig, isc_stdtime_t now,
    668 		     bool acceptexpired);
    669 /*%<
    670  * Trim the ttl of 'rdataset' and 'sigrdataset' so that they will expire
    671  * at or before 'rrsig->expiretime'.  If 'acceptexpired' is true and the
    672  * signature has expired or will expire in the next 120 seconds, limit
    673  * the ttl to be no more than 120 seconds.
    674  *
    675  * The ttl is further limited by the original ttl as stored in 'rrsig'
    676  * and the original ttl values of 'rdataset' and 'sigrdataset'.
    677  *
    678  * Requires:
    679  * \li	'rdataset' is a valid rdataset.
    680  * \li	'sigrdataset' is a valid rdataset.
    681  * \li	'rrsig' is non NULL.
    682  */
    683 
    684 const char *
    685 dns_trust_totext(dns_trust_t trust);
    686 /*%<
    687  * Display trust in textual form.
    688  */
    689 
    690 isc_stdtime_t
    691 dns_rdataset_minresign(dns_rdataset_t *rdataset);
    692 /*%<
    693  * Return the minimum resign time from an RRSIG rdataset.
    694  *
    695  * This function iterates through all RRSIG records in the rdataset
    696  * and returns the earliest expiration time, which indicates when
    697  * the signatures should be resigned.
    698  *
    699  * Requires:
    700  * \li	'rdataset' is a valid rdataset.
    701  */
    702 
    703 ISC_LANG_ENDDECLS
    704