diff.c revision 1.1.1.1 1 /* $NetBSD: diff.c,v 1.1.1.1 2018/08/12 12:08:12 christos Exp $ */
2
3 /*
4 * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
5 *
6 * This Source Code Form is subject to the terms of the Mozilla Public
7 * License, v. 2.0. If a copy of the MPL was not distributed with this
8 * file, You can obtain one at http://mozilla.org/MPL/2.0/.
9 *
10 * See the COPYRIGHT file distributed with this work for additional
11 * information regarding copyright ownership.
12 */
13
14
15 /*! \file */
16
17 #include <config.h>
18
19 #include <stdlib.h>
20
21 #include <isc/buffer.h>
22 #include <isc/file.h>
23 #include <isc/mem.h>
24 #include <isc/print.h>
25 #include <isc/string.h>
26 #include <isc/util.h>
27
28 #include <dns/db.h>
29 #include <dns/diff.h>
30 #include <dns/log.h>
31 #include <dns/rdataclass.h>
32 #include <dns/rdatalist.h>
33 #include <dns/rdataset.h>
34 #include <dns/rdatastruct.h>
35 #include <dns/rdatatype.h>
36 #include <dns/result.h>
37 #include <dns/time.h>
38
39 #define CHECK(op) \
40 do { result = (op); \
41 if (result != ISC_R_SUCCESS) goto failure; \
42 } while (0)
43
44 #define DIFF_COMMON_LOGARGS \
45 dns_lctx, DNS_LOGCATEGORY_GENERAL, DNS_LOGMODULE_DIFF
46
47 static dns_rdatatype_t
48 rdata_covers(dns_rdata_t *rdata) {
49 return (rdata->type == dns_rdatatype_rrsig ?
50 dns_rdata_covers(rdata) : 0);
51 }
52
53 isc_result_t
54 dns_difftuple_create(isc_mem_t *mctx,
55 dns_diffop_t op, const dns_name_t *name, dns_ttl_t ttl,
56 dns_rdata_t *rdata, dns_difftuple_t **tp)
57 {
58 dns_difftuple_t *t;
59 unsigned int size;
60 unsigned char *datap;
61
62 REQUIRE(tp != NULL && *tp == NULL);
63
64 /*
65 * Create a new tuple. The variable-size wire-format name data and
66 * rdata immediately follow the dns_difftuple_t structure
67 * in memory.
68 */
69 size = sizeof(*t) + name->length + rdata->length;
70 t = isc_mem_allocate(mctx, size);
71 if (t == NULL)
72 return (ISC_R_NOMEMORY);
73 t->mctx = NULL;
74 isc_mem_attach(mctx, &t->mctx);
75 t->op = op;
76
77 datap = (unsigned char *)(t + 1);
78
79 memmove(datap, name->ndata, name->length);
80 dns_name_init(&t->name, NULL);
81 dns_name_clone(name, &t->name);
82 t->name.ndata = datap;
83 datap += name->length;
84
85 t->ttl = ttl;
86
87 dns_rdata_init(&t->rdata);
88 dns_rdata_clone(rdata, &t->rdata);
89 if (rdata->data != NULL) {
90 memmove(datap, rdata->data, rdata->length);
91 t->rdata.data = datap;
92 datap += rdata->length;
93 } else {
94 t->rdata.data = NULL;
95 INSIST(rdata->length == 0);
96 }
97
98 ISC_LINK_INIT(&t->rdata, link);
99 ISC_LINK_INIT(t, link);
100 t->magic = DNS_DIFFTUPLE_MAGIC;
101
102 INSIST(datap == (unsigned char *)t + size);
103
104 *tp = t;
105 return (ISC_R_SUCCESS);
106 }
107
108 void
109 dns_difftuple_free(dns_difftuple_t **tp) {
110 dns_difftuple_t *t = *tp;
111 isc_mem_t *mctx;
112
113 REQUIRE(DNS_DIFFTUPLE_VALID(t));
114
115 dns_name_invalidate(&t->name);
116 t->magic = 0;
117 mctx = t->mctx;
118 isc_mem_free(mctx, t);
119 isc_mem_detach(&mctx);
120 *tp = NULL;
121 }
122
123 isc_result_t
124 dns_difftuple_copy(dns_difftuple_t *orig, dns_difftuple_t **copyp) {
125 return (dns_difftuple_create(orig->mctx, orig->op, &orig->name,
126 orig->ttl, &orig->rdata, copyp));
127 }
128
129 void
130 dns_diff_init(isc_mem_t *mctx, dns_diff_t *diff) {
131 diff->mctx = mctx;
132 ISC_LIST_INIT(diff->tuples);
133 diff->magic = DNS_DIFF_MAGIC;
134 }
135
136 void
137 dns_diff_clear(dns_diff_t *diff) {
138 dns_difftuple_t *t;
139 REQUIRE(DNS_DIFF_VALID(diff));
140 while ((t = ISC_LIST_HEAD(diff->tuples)) != NULL) {
141 ISC_LIST_UNLINK(diff->tuples, t, link);
142 dns_difftuple_free(&t);
143 }
144 ENSURE(ISC_LIST_EMPTY(diff->tuples));
145 }
146
147 void
148 dns_diff_append(dns_diff_t *diff, dns_difftuple_t **tuplep)
149 {
150 ISC_LIST_APPEND(diff->tuples, *tuplep, link);
151 *tuplep = NULL;
152 }
153
154 /* XXX this is O(N) */
155
156 void
157 dns_diff_appendminimal(dns_diff_t *diff, dns_difftuple_t **tuplep)
158 {
159 dns_difftuple_t *ot, *next_ot;
160
161 REQUIRE(DNS_DIFF_VALID(diff));
162 REQUIRE(DNS_DIFFTUPLE_VALID(*tuplep));
163
164 /*
165 * Look for an existing tuple with the same owner name,
166 * rdata, and TTL. If we are doing an addition and find a
167 * deletion or vice versa, remove both the old and the
168 * new tuple since they cancel each other out (assuming
169 * that we never delete nonexistent data or add existing
170 * data).
171 *
172 * If we find an old update of the same kind as
173 * the one we are doing, there must be a programming
174 * error. We report it but try to continue anyway.
175 */
176 for (ot = ISC_LIST_HEAD(diff->tuples); ot != NULL;
177 ot = next_ot)
178 {
179 next_ot = ISC_LIST_NEXT(ot, link);
180 if (dns_name_caseequal(&ot->name, &(*tuplep)->name) &&
181 dns_rdata_compare(&ot->rdata, &(*tuplep)->rdata) == 0 &&
182 ot->ttl == (*tuplep)->ttl)
183 {
184 ISC_LIST_UNLINK(diff->tuples, ot, link);
185 if ((*tuplep)->op == ot->op) {
186 UNEXPECTED_ERROR(__FILE__, __LINE__,
187 "unexpected non-minimal diff");
188 } else {
189 dns_difftuple_free(tuplep);
190 }
191 dns_difftuple_free(&ot);
192 break;
193 }
194 }
195
196 if (*tuplep != NULL) {
197 ISC_LIST_APPEND(diff->tuples, *tuplep, link);
198 *tuplep = NULL;
199 }
200
201 ENSURE(*tuplep == NULL);
202 }
203
204 static isc_stdtime_t
205 setresign(dns_rdataset_t *modified) {
206 dns_rdata_t rdata = DNS_RDATA_INIT;
207 dns_rdata_rrsig_t sig;
208 isc_int64_t when;
209 isc_result_t result;
210
211 result = dns_rdataset_first(modified);
212 INSIST(result == ISC_R_SUCCESS);
213 dns_rdataset_current(modified, &rdata);
214 (void)dns_rdata_tostruct(&rdata, &sig, NULL);
215 if ((rdata.flags & DNS_RDATA_OFFLINE) != 0)
216 when = 0;
217 else
218 when = dns_time64_from32(sig.timeexpire);
219 dns_rdata_reset(&rdata);
220
221 result = dns_rdataset_next(modified);
222 while (result == ISC_R_SUCCESS) {
223 dns_rdataset_current(modified, &rdata);
224 (void)dns_rdata_tostruct(&rdata, &sig, NULL);
225 if ((rdata.flags & DNS_RDATA_OFFLINE) != 0) {
226 goto next_rr;
227 }
228 if (when == 0 || dns_time64_from32(sig.timeexpire) < when)
229 when = dns_time64_from32(sig.timeexpire);
230 next_rr:
231 dns_rdata_reset(&rdata);
232 result = dns_rdataset_next(modified);
233 }
234 INSIST(result == ISC_R_NOMORE);
235 return ((isc_stdtime_t)when);
236 }
237
238 static void
239 getownercase(dns_rdataset_t *rdataset, dns_name_t *name) {
240 if (dns_rdataset_isassociated(rdataset))
241 dns_rdataset_getownercase(rdataset, name);
242 }
243
244 static void
245 setownercase(dns_rdataset_t *rdataset, const dns_name_t *name) {
246 if (dns_rdataset_isassociated(rdataset))
247 dns_rdataset_setownercase(rdataset, name);
248 }
249
250 static isc_result_t
251 diff_apply(dns_diff_t *diff, dns_db_t *db, dns_dbversion_t *ver,
252 isc_boolean_t warn)
253 {
254 dns_difftuple_t *t;
255 dns_dbnode_t *node = NULL;
256 isc_result_t result;
257 char namebuf[DNS_NAME_FORMATSIZE];
258 char typebuf[DNS_RDATATYPE_FORMATSIZE];
259 char classbuf[DNS_RDATACLASS_FORMATSIZE];
260
261 REQUIRE(DNS_DIFF_VALID(diff));
262 REQUIRE(DNS_DB_VALID(db));
263
264 t = ISC_LIST_HEAD(diff->tuples);
265 while (t != NULL) {
266 dns_name_t *name;
267
268 INSIST(node == NULL);
269 name = &t->name;
270 /*
271 * Find the node.
272 * We create the node if it does not exist.
273 * This will cause an empty node to be created if the diff
274 * contains a deletion of an RR at a nonexistent name,
275 * but such diffs should never be created in the first
276 * place.
277 */
278
279 while (t != NULL && dns_name_equal(&t->name, name)) {
280 dns_rdatatype_t type, covers;
281 dns_diffop_t op;
282 dns_rdatalist_t rdl;
283 dns_rdataset_t rds;
284 dns_rdataset_t ardataset;
285 unsigned int options;
286
287 op = t->op;
288 type = t->rdata.type;
289 covers = rdata_covers(&t->rdata);
290
291 /*
292 * Collect a contiguous set of updates with
293 * the same operation (add/delete) and RR type
294 * into a single rdatalist so that the
295 * database rrset merging/subtraction code
296 * can work more efficiently than if each
297 * RR were merged into / subtracted from
298 * the database separately.
299 *
300 * This is done by linking rdata structures from the
301 * diff into "rdatalist". This uses the rdata link
302 * field, not the diff link field, so the structure
303 * of the diff itself is not affected.
304 */
305
306 dns_rdatalist_init(&rdl);
307 rdl.type = type;
308 rdl.covers = covers;
309 rdl.rdclass = t->rdata.rdclass;
310 rdl.ttl = t->ttl;
311
312 node = NULL;
313 if (type != dns_rdatatype_nsec3 &&
314 covers != dns_rdatatype_nsec3)
315 CHECK(dns_db_findnode(db, name, ISC_TRUE,
316 &node));
317 else
318 CHECK(dns_db_findnsec3node(db, name, ISC_TRUE,
319 &node));
320
321 while (t != NULL &&
322 dns_name_equal(&t->name, name) &&
323 t->op == op &&
324 t->rdata.type == type &&
325 rdata_covers(&t->rdata) == covers)
326 {
327 /*
328 * Remember the add name for
329 * dns_rdataset_setownercase.
330 */
331 name = &t->name;
332 if (t->ttl != rdl.ttl && warn) {
333 dns_name_format(name, namebuf,
334 sizeof(namebuf));
335 dns_rdatatype_format(t->rdata.type,
336 typebuf,
337 sizeof(typebuf));
338 dns_rdataclass_format(t->rdata.rdclass,
339 classbuf,
340 sizeof(classbuf));
341 isc_log_write(DIFF_COMMON_LOGARGS,
342 ISC_LOG_WARNING,
343 "'%s/%s/%s': TTL differs in "
344 "rdataset, adjusting "
345 "%lu -> %lu",
346 namebuf, typebuf, classbuf,
347 (unsigned long) t->ttl,
348 (unsigned long) rdl.ttl);
349 }
350 ISC_LIST_APPEND(rdl.rdata, &t->rdata, link);
351 t = ISC_LIST_NEXT(t, link);
352 }
353
354 /*
355 * Convert the rdatalist into a rdataset.
356 */
357 dns_rdataset_init(&rds);
358 dns_rdataset_init(&ardataset);
359 CHECK(dns_rdatalist_tordataset(&rdl, &rds));
360 rds.trust = dns_trust_ultimate;
361
362 /*
363 * Merge the rdataset into the database.
364 */
365 switch (op) {
366 case DNS_DIFFOP_ADD:
367 case DNS_DIFFOP_ADDRESIGN:
368 options = DNS_DBADD_MERGE | DNS_DBADD_EXACT |
369 DNS_DBADD_EXACTTTL;
370 result = dns_db_addrdataset(db, node, ver,
371 0, &rds, options,
372 &ardataset);
373 break;
374 case DNS_DIFFOP_DEL:
375 case DNS_DIFFOP_DELRESIGN:
376 options = DNS_DBSUB_EXACT | DNS_DBSUB_WANTOLD;
377 result = dns_db_subtractrdataset(db, node, ver,
378 &rds, options,
379 &ardataset);
380 break;
381 default:
382 INSIST(0);
383 }
384
385 if (result == ISC_R_SUCCESS) {
386 if (rds.type == dns_rdatatype_rrsig &&
387 (op == DNS_DIFFOP_DELRESIGN ||
388 op == DNS_DIFFOP_ADDRESIGN)) {
389 isc_stdtime_t resign;
390 resign = setresign(&ardataset);
391 dns_db_setsigningtime(db, &ardataset,
392 resign);
393 }
394 if (op == DNS_DIFFOP_ADD ||
395 op == DNS_DIFFOP_ADDRESIGN)
396 setownercase(&ardataset, name);
397 if (op == DNS_DIFFOP_DEL ||
398 op == DNS_DIFFOP_DELRESIGN)
399 getownercase(&ardataset, name);
400 } else if (result == DNS_R_UNCHANGED) {
401 /*
402 * This will not happen when executing a
403 * dynamic update, because that code will
404 * generate strictly minimal diffs.
405 * It may happen when receiving an IXFR
406 * from a server that is not as careful.
407 * Issue a warning and continue.
408 */
409 if (warn) {
410 dns_name_format(dns_db_origin(db),
411 namebuf,
412 sizeof(namebuf));
413 dns_rdataclass_format(dns_db_class(db),
414 classbuf,
415 sizeof(classbuf));
416 isc_log_write(DIFF_COMMON_LOGARGS,
417 ISC_LOG_WARNING,
418 "%s/%s: dns_diff_apply: "
419 "update with no effect",
420 namebuf, classbuf);
421 }
422 if (op == DNS_DIFFOP_ADD ||
423 op == DNS_DIFFOP_ADDRESIGN)
424 setownercase(&ardataset, name);
425 if (op == DNS_DIFFOP_DEL ||
426 op == DNS_DIFFOP_DELRESIGN)
427 getownercase(&ardataset, name);
428 } else if (result == DNS_R_NXRRSET) {
429 /*
430 * OK.
431 */
432 if (op == DNS_DIFFOP_DEL ||
433 op == DNS_DIFFOP_DELRESIGN)
434 getownercase(&ardataset, name);
435 if (dns_rdataset_isassociated(&ardataset))
436 dns_rdataset_disassociate(&ardataset);
437 } else {
438 if (dns_rdataset_isassociated(&ardataset))
439 dns_rdataset_disassociate(&ardataset);
440 CHECK(result);
441 }
442 dns_db_detachnode(db, &node);
443 if (dns_rdataset_isassociated(&ardataset))
444 dns_rdataset_disassociate(&ardataset);
445 }
446 }
447 return (ISC_R_SUCCESS);
448
449 failure:
450 if (node != NULL)
451 dns_db_detachnode(db, &node);
452 return (result);
453 }
454
455 isc_result_t
456 dns_diff_apply(dns_diff_t *diff, dns_db_t *db, dns_dbversion_t *ver) {
457 return (diff_apply(diff, db, ver, ISC_TRUE));
458 }
459
460 isc_result_t
461 dns_diff_applysilently(dns_diff_t *diff, dns_db_t *db, dns_dbversion_t *ver) {
462 return (diff_apply(diff, db, ver, ISC_FALSE));
463 }
464
465 /* XXX this duplicates lots of code in diff_apply(). */
466
467 isc_result_t
468 dns_diff_load(dns_diff_t *diff, dns_addrdatasetfunc_t addfunc,
469 void *add_private)
470 {
471 dns_difftuple_t *t;
472 isc_result_t result;
473
474 REQUIRE(DNS_DIFF_VALID(diff));
475
476 t = ISC_LIST_HEAD(diff->tuples);
477 while (t != NULL) {
478 dns_name_t *name;
479
480 name = &t->name;
481 while (t != NULL && dns_name_equal(&t->name, name)) {
482 dns_rdatatype_t type, covers;
483 dns_diffop_t op;
484 dns_rdatalist_t rdl;
485 dns_rdataset_t rds;
486
487 op = t->op;
488 type = t->rdata.type;
489 covers = rdata_covers(&t->rdata);
490
491 dns_rdatalist_init(&rdl);
492 rdl.type = type;
493 rdl.covers = covers;
494 rdl.rdclass = t->rdata.rdclass;
495 rdl.ttl = t->ttl;
496
497 while (t != NULL && dns_name_equal(&t->name, name) &&
498 t->op == op && t->rdata.type == type &&
499 rdata_covers(&t->rdata) == covers)
500 {
501 ISC_LIST_APPEND(rdl.rdata, &t->rdata, link);
502 t = ISC_LIST_NEXT(t, link);
503 }
504
505 /*
506 * Convert the rdatalist into a rdataset.
507 */
508 dns_rdataset_init(&rds);
509 CHECK(dns_rdatalist_tordataset(&rdl, &rds));
510 rds.trust = dns_trust_ultimate;
511
512 INSIST(op == DNS_DIFFOP_ADD);
513 result = (*addfunc)(add_private, name, &rds);
514 if (result == DNS_R_UNCHANGED) {
515 isc_log_write(DIFF_COMMON_LOGARGS,
516 ISC_LOG_WARNING,
517 "dns_diff_load: "
518 "update with no effect");
519 } else if (result == ISC_R_SUCCESS ||
520 result == DNS_R_NXRRSET) {
521 /*
522 * OK.
523 */
524 } else {
525 CHECK(result);
526 }
527 }
528 }
529 result = ISC_R_SUCCESS;
530 failure:
531 return (result);
532 }
533
534 /*
535 * XXX uses qsort(); a merge sort would be more natural for lists,
536 * and perhaps safer wrt thread stack overflow.
537 */
538 isc_result_t
539 dns_diff_sort(dns_diff_t *diff, dns_diff_compare_func *compare) {
540 unsigned int length = 0;
541 unsigned int i;
542 dns_difftuple_t **v;
543 dns_difftuple_t *p;
544 REQUIRE(DNS_DIFF_VALID(diff));
545
546 for (p = ISC_LIST_HEAD(diff->tuples);
547 p != NULL;
548 p = ISC_LIST_NEXT(p, link))
549 length++;
550 if (length == 0)
551 return (ISC_R_SUCCESS);
552 v = isc_mem_get(diff->mctx, length * sizeof(dns_difftuple_t *));
553 if (v == NULL)
554 return (ISC_R_NOMEMORY);
555 for (i = 0; i < length; i++) {
556 p = ISC_LIST_HEAD(diff->tuples);
557 v[i] = p;
558 ISC_LIST_UNLINK(diff->tuples, p, link);
559 }
560 INSIST(ISC_LIST_HEAD(diff->tuples) == NULL);
561 qsort(v, length, sizeof(v[0]), compare);
562 for (i = 0; i < length; i++) {
563 ISC_LIST_APPEND(diff->tuples, v[i], link);
564 }
565 isc_mem_put(diff->mctx, v, length * sizeof(dns_difftuple_t *));
566 return (ISC_R_SUCCESS);
567 }
568
569
570 /*
571 * Create an rdataset containing the single RR of the given
572 * tuple. The caller must allocate the rdata, rdataset and
573 * an rdatalist structure for it to refer to.
574 */
575
576 static isc_result_t
577 diff_tuple_tordataset(dns_difftuple_t *t, dns_rdata_t *rdata,
578 dns_rdatalist_t *rdl, dns_rdataset_t *rds)
579 {
580 REQUIRE(DNS_DIFFTUPLE_VALID(t));
581 REQUIRE(rdl != NULL);
582 REQUIRE(rds != NULL);
583
584 dns_rdatalist_init(rdl);
585 rdl->type = t->rdata.type;
586 rdl->rdclass = t->rdata.rdclass;
587 rdl->ttl = t->ttl;
588 dns_rdataset_init(rds);
589 ISC_LINK_INIT(rdata, link);
590 dns_rdata_clone(&t->rdata, rdata);
591 ISC_LIST_APPEND(rdl->rdata, rdata, link);
592 return (dns_rdatalist_tordataset(rdl, rds));
593 }
594
595 isc_result_t
596 dns_diff_print(dns_diff_t *diff, FILE *file) {
597 isc_result_t result;
598 dns_difftuple_t *t;
599 char *mem = NULL;
600 unsigned int size = 2048;
601 const char *op = NULL;
602
603 REQUIRE(DNS_DIFF_VALID(diff));
604
605 mem = isc_mem_get(diff->mctx, size);
606 if (mem == NULL)
607 return (ISC_R_NOMEMORY);
608
609 for (t = ISC_LIST_HEAD(diff->tuples); t != NULL;
610 t = ISC_LIST_NEXT(t, link))
611 {
612 isc_buffer_t buf;
613 isc_region_t r;
614
615 dns_rdatalist_t rdl;
616 dns_rdataset_t rds;
617 dns_rdata_t rd = DNS_RDATA_INIT;
618
619 result = diff_tuple_tordataset(t, &rd, &rdl, &rds);
620 if (result != ISC_R_SUCCESS) {
621 UNEXPECTED_ERROR(__FILE__, __LINE__,
622 "diff_tuple_tordataset failed: %s",
623 dns_result_totext(result));
624 result = ISC_R_UNEXPECTED;
625 goto cleanup;
626 }
627 again:
628 isc_buffer_init(&buf, mem, size);
629 result = dns_rdataset_totext(&rds, &t->name,
630 ISC_FALSE, ISC_FALSE, &buf);
631
632 if (result == ISC_R_NOSPACE) {
633 isc_mem_put(diff->mctx, mem, size);
634 size += 1024;
635 mem = isc_mem_get(diff->mctx, size);
636 if (mem == NULL) {
637 result = ISC_R_NOMEMORY;
638 goto cleanup;
639 }
640 goto again;
641 }
642
643 if (result != ISC_R_SUCCESS)
644 goto cleanup;
645 /*
646 * Get rid of final newline.
647 */
648 INSIST(buf.used >= 1 &&
649 ((char *) buf.base)[buf.used-1] == '\n');
650 buf.used--;
651
652 isc_buffer_usedregion(&buf, &r);
653 switch (t->op) {
654 case DNS_DIFFOP_EXISTS: op = "exists"; break;
655 case DNS_DIFFOP_ADD: op = "add"; break;
656 case DNS_DIFFOP_DEL: op = "del"; break;
657 case DNS_DIFFOP_ADDRESIGN: op = "add re-sign"; break;
658 case DNS_DIFFOP_DELRESIGN: op = "del re-sign"; break;
659 }
660 if (file != NULL)
661 fprintf(file, "%s %.*s\n", op, (int) r.length,
662 (char *) r.base);
663 else
664 isc_log_write(DIFF_COMMON_LOGARGS, ISC_LOG_DEBUG(7),
665 "%s %.*s", op, (int) r.length,
666 (char *) r.base);
667 }
668 result = ISC_R_SUCCESS;
669 cleanup:
670 if (mem != NULL)
671 isc_mem_put(diff->mctx, mem, size);
672 return (result);
673 }
674