aclconf.c revision ea419adc4eca4c3e44f2c282035b5dce6b795fe2
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson/*
499b34cea04a46823d003d4c0520c8b03e8513cbBrian Wellington * Copyright (C) 1999, 2000 Internet Software Consortium.
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrence *
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson * Permission to use, copy, modify, and distribute this software for any
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson * purpose with or without fee is hereby granted, provided that the above
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson * copyright notice and this permission notice appear in all copies.
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrence *
15a44745412679c30a6d022733925af70a38b715David Lawrence * THE SOFTWARE IS PROVIDED "AS IS" AND INTERNET SOFTWARE CONSORTIUM
15a44745412679c30a6d022733925af70a38b715David Lawrence * DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL
15a44745412679c30a6d022733925af70a38b715David Lawrence * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL
15a44745412679c30a6d022733925af70a38b715David Lawrence * INTERNET SOFTWARE CONSORTIUM BE LIABLE FOR ANY SPECIAL, DIRECT,
15a44745412679c30a6d022733925af70a38b715David Lawrence * INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING
15a44745412679c30a6d022733925af70a38b715David Lawrence * FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT,
15a44745412679c30a6d022733925af70a38b715David Lawrence * NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION
15a44745412679c30a6d022733925af70a38b715David Lawrence * WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson */
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson
9aba20edee4e704433a464ae43b070b0775de506Mark Andrews/* $Id: aclconf.c,v 1.21 2000/08/11 01:53:47 gson Exp $ */
9c3531d72aeaad6c5f01efe6a1c82023e1379e4dDavid Lawrence
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson#include <config.h>
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson
593cb00bd17e5e2ab0dcb7c635a9a81082dc5d0eAndreas Gustafsson#include <isc/mem.h>
593cb00bd17e5e2ab0dcb7c635a9a81082dc5d0eAndreas Gustafsson#include <isc/string.h> /* Required for HP/UX (and others?) */
9aba20edee4e704433a464ae43b070b0775de506Mark Andrews#include <isc/util.h>
3e14b69d196a3ebeecc4662c426344dcfd7db678Andreas Gustafsson
9aba20edee4e704433a464ae43b070b0775de506Mark Andrews#include <dns/acl.h>
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence#include <dns/aclconf.h>
d8e34837cd6c88c42b3ecdb9107a43ecf8252e79David Lawrence#include <dns/fixedname.h>
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence#include <dns/log.h>
9aba20edee4e704433a464ae43b070b0775de506Mark Andrews
364a82f7c25b62967678027043425201a5e5171aBob Halleyvoid
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafssondns_aclconfctx_init(dns_aclconfctx_t *ctx) {
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence ISC_LIST_INIT(ctx->named_acl_cache);
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence}
9aba20edee4e704433a464ae43b070b0775de506Mark Andrews
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafssonvoid
3e14b69d196a3ebeecc4662c426344dcfd7db678Andreas Gustafssondns_aclconfctx_destroy(dns_aclconfctx_t *ctx) {
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence dns_acl_t *dacl, *next;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson for (dacl = ISC_LIST_HEAD(ctx->named_acl_cache);
673ce7aebbb6d01c75b95f6df1ec491d6422b951Andreas Gustafsson dacl != NULL;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson dacl = next)
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson {
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence next = ISC_LIST_NEXT(dacl, nextincache);
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence dacl->name = NULL;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson dns_acl_detach(&dacl);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson }
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson}
9aba20edee4e704433a464ae43b070b0775de506Mark Andrews
9aba20edee4e704433a464ae43b070b0775de506Mark Andrewsstatic isc_result_t
9aba20edee4e704433a464ae43b070b0775de506Mark Andrewsconvert_named_acl(char *aclname, dns_c_ctx_t *cctx,
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson dns_aclconfctx_t *ctx, isc_mem_t *mctx,
600cfa2ba4c50017581b6c14e3a688a82ecebbe0David Lawrence dns_acl_t **target)
600cfa2ba4c50017581b6c14e3a688a82ecebbe0David Lawrence{
600cfa2ba4c50017581b6c14e3a688a82ecebbe0David Lawrence isc_result_t result;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson dns_c_acl_t *cacl;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson dns_acl_t *dacl;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson /* Look for an already-converted version. */
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson for (dacl = ISC_LIST_HEAD(ctx->named_acl_cache);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson dacl != NULL;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson dacl = ISC_LIST_NEXT(dacl, nextincache))
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson {
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson if (strcmp(aclname, dacl->name) == 0) {
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson dns_acl_attach(dacl, target);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson return ISC_R_SUCCESS;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson }
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson }
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson /* Not yet converted. Convert now. */
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson result = dns_c_acltable_getacl(cctx->acls, aclname, &cacl);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson if (result != ISC_R_SUCCESS) {
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson isc_log_write(dns_lctx, DNS_LOGCATEGORY_SECURITY,
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrence DNS_LOGMODULE_ACL, ISC_LOG_WARNING,
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson "undefined ACL '%s'", aclname);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson return (result);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson }
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson result = dns_acl_fromconfig(cacl->ipml, cctx, ctx, mctx, &dacl);
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrence if (result != ISC_R_SUCCESS)
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson return (result);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson dacl->name = isc_mem_strdup(dacl->mctx, aclname);
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrence ISC_LIST_APPEND(ctx->named_acl_cache, dacl, nextincache);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson dns_acl_attach(dacl, target);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson return (ISC_R_SUCCESS);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson}
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrencestatic isc_result_t
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafssonconvert_keyname(char *txtname, isc_mem_t *mctx, dns_name_t *dnsname) {
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrence isc_result_t result;
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrence isc_buffer_t buf;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson dns_fixedname_t fixname;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson unsigned int keylen;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson keylen = strlen(txtname);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson isc_buffer_init(&buf, txtname, keylen);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson isc_buffer_add(&buf, keylen);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson dns_fixedname_init(&fixname);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson result = dns_name_fromtext(dns_fixedname_name(&fixname), &buf,
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson dns_rootname, ISC_FALSE, NULL);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson if (result != ISC_R_SUCCESS) {
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson isc_log_write(dns_lctx, DNS_LOGCATEGORY_SECURITY,
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson DNS_LOGMODULE_ACL, ISC_LOG_WARNING,
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson "key name \"%s\" is not a valid domain name",
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson txtname);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson return (result);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson }
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson return (dns_name_dup(dns_fixedname_name(&fixname), mctx, dnsname));
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrence}
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafssonisc_result_t
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafssondns_acl_fromconfig(dns_c_ipmatchlist_t *caml,
e482a1c91ecb5e47bc26617bf310d6b5c41fad91Andreas Gustafsson dns_c_ctx_t *cctx,
e482a1c91ecb5e47bc26617bf310d6b5c41fad91Andreas Gustafsson dns_aclconfctx_t *ctx,
e482a1c91ecb5e47bc26617bf310d6b5c41fad91Andreas Gustafsson isc_mem_t *mctx,
e482a1c91ecb5e47bc26617bf310d6b5c41fad91Andreas Gustafsson dns_acl_t **target)
e482a1c91ecb5e47bc26617bf310d6b5c41fad91Andreas Gustafsson{
e482a1c91ecb5e47bc26617bf310d6b5c41fad91Andreas Gustafsson isc_result_t result;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson unsigned int count;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson dns_acl_t *dacl = NULL;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson dns_aclelement_t *de;
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrence dns_c_ipmatchelement_t *ce;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson REQUIRE(target != NULL && *target == NULL);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson count = 0;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson for (ce = ISC_LIST_HEAD(caml->elements);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson ce != NULL;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson ce = ISC_LIST_NEXT(ce, next))
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson count++;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson result = dns_acl_create(mctx, count, &dacl);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson if (result != ISC_R_SUCCESS)
0c8649cea98afc061dd2938fd315df53b8fc35caAndreas Gustafsson return (result);
0c8649cea98afc061dd2938fd315df53b8fc35caAndreas Gustafsson
0c8649cea98afc061dd2938fd315df53b8fc35caAndreas Gustafsson de = dacl->elements;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson for (ce = ISC_LIST_HEAD(caml->elements);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson ce != NULL;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson ce = ISC_LIST_NEXT(ce, next))
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson {
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson de->negative = dns_c_ipmatchelement_isneg(ce);
f621719829356f27e831507b75e88e8a655e48d8Danny Mayer switch (ce->type) {
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson case dns_c_ipmatch_pattern:
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson de->type = dns_aclelementtype_ipprefix;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson isc_netaddr_fromsockaddr(&de->u.ip_prefix.address,
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson &ce->u.direct.address);
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson /* XXX "mask" is a misnomer */
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson de->u.ip_prefix.prefixlen = ce->u.direct.mask;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson break;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson case dns_c_ipmatch_key:
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson de->type = dns_aclelementtype_keyname;
7bf91d95eb5a49117d5080bbd03839b9de5c8423Andreas Gustafsson dns_name_init(&de->u.keyname, NULL);
19f4d25fd5b35b1375b0b9f13b66770ee4a66154Brian Wellington result = convert_keyname(ce->u.key, mctx,
19f4d25fd5b35b1375b0b9f13b66770ee4a66154Brian Wellington &de->u.keyname);
f621719829356f27e831507b75e88e8a655e48d8Danny Mayer if (result != ISC_R_SUCCESS)
19f4d25fd5b35b1375b0b9f13b66770ee4a66154Brian Wellington goto cleanup;
19f4d25fd5b35b1375b0b9f13b66770ee4a66154Brian Wellington break;
19f4d25fd5b35b1375b0b9f13b66770ee4a66154Brian Wellington case dns_c_ipmatch_indirect:
19f4d25fd5b35b1375b0b9f13b66770ee4a66154Brian Wellington de->type = dns_aclelementtype_nestedacl;
19f4d25fd5b35b1375b0b9f13b66770ee4a66154Brian Wellington result = dns_acl_fromconfig(ce->u.indirect.list,
19f4d25fd5b35b1375b0b9f13b66770ee4a66154Brian Wellington cctx, ctx, mctx,
19f4d25fd5b35b1375b0b9f13b66770ee4a66154Brian Wellington &de->u.nestedacl);
7bf91d95eb5a49117d5080bbd03839b9de5c8423Andreas Gustafsson if (result != ISC_R_SUCCESS)
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson goto cleanup;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson break;
2883651930dc85cacae940fe2a81277dfc14807dBrian Wellington case dns_c_ipmatch_localhost:
2883651930dc85cacae940fe2a81277dfc14807dBrian Wellington de->type = dns_aclelementtype_localhost;
2883651930dc85cacae940fe2a81277dfc14807dBrian Wellington break;
2883651930dc85cacae940fe2a81277dfc14807dBrian Wellington
e482a1c91ecb5e47bc26617bf310d6b5c41fad91Andreas Gustafsson case dns_c_ipmatch_any:
e482a1c91ecb5e47bc26617bf310d6b5c41fad91Andreas Gustafsson de->type = dns_aclelementtype_any;
e482a1c91ecb5e47bc26617bf310d6b5c41fad91Andreas Gustafsson break;
2883651930dc85cacae940fe2a81277dfc14807dBrian Wellington
2883651930dc85cacae940fe2a81277dfc14807dBrian Wellington case dns_c_ipmatch_localnets:
2883651930dc85cacae940fe2a81277dfc14807dBrian Wellington de->type = dns_aclelementtype_localnets;
c67496c94321dfb68d209019f2b5872a81289c66Michael Sawyer break;
2b50457b870dd04fc5d875d9e6c8616c58ac5d85Michael Sawyer case dns_c_ipmatch_acl:
c67496c94321dfb68d209019f2b5872a81289c66Michael Sawyer de->type = dns_aclelementtype_nestedacl;
c67496c94321dfb68d209019f2b5872a81289c66Michael Sawyer result = convert_named_acl(ce->u.aclname,
c67496c94321dfb68d209019f2b5872a81289c66Michael Sawyer cctx, ctx, mctx,
c67496c94321dfb68d209019f2b5872a81289c66Michael Sawyer &de->u.nestedacl);
c67496c94321dfb68d209019f2b5872a81289c66Michael Sawyer if (result != ISC_R_SUCCESS)
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson goto cleanup;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson break;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson default:
f621719829356f27e831507b75e88e8a655e48d8Danny Mayer isc_log_write(dns_lctx, DNS_LOGCATEGORY_SECURITY,
bfe313722d5b2eff6c80336ed1f19c2f99a53de6Andreas Gustafsson DNS_LOGMODULE_ACL, ISC_LOG_WARNING,
78838d3e0cd62423c23de5503910e01884d2104bBrian Wellington "address match list contains "
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson "unsupported element type");
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson result = ISC_R_FAILURE;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson goto cleanup;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson }
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson de++;
68e4926b2262571e004b4be00b905ec776c01d9cMichael Graff dacl->length++;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson }
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson
68e4926b2262571e004b4be00b905ec776c01d9cMichael Graff *target = dacl;
5fc7ba3e1ac5d72239e9971e0f469dd5796738f9Andreas Gustafsson return (ISC_R_SUCCESS);
9aba20edee4e704433a464ae43b070b0775de506Mark Andrews
9aba20edee4e704433a464ae43b070b0775de506Mark Andrews cleanup:
9aba20edee4e704433a464ae43b070b0775de506Mark Andrews dns_acl_detach(&dacl);
9aba20edee4e704433a464ae43b070b0775de506Mark Andrews return (result);
9aba20edee4e704433a464ae43b070b0775de506Mark Andrews}
9aba20edee4e704433a464ae43b070b0775de506Mark Andrews