tests.sh revision 337d408adbae1f91b625d0ce624fb39a66aae4d2
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington#!/bin/sh
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington#
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrence# Copyright (C) 2010, 2012, 2015 Internet Systems Consortium, Inc. ("ISC")
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington#
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington# Permission to use, copy, modify, and/or distribute this software for any
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington# purpose with or without fee is hereby granted, provided that the above
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrence# copyright notice and this permission notice appear in all copies.
15a44745412679c30a6d022733925af70a38b715David Lawrence#
15a44745412679c30a6d022733925af70a38b715David Lawrence# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
15a44745412679c30a6d022733925af70a38b715David Lawrence# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
15a44745412679c30a6d022733925af70a38b715David Lawrence# AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
15a44745412679c30a6d022733925af70a38b715David Lawrence# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
15a44745412679c30a6d022733925af70a38b715David Lawrence# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
15a44745412679c30a6d022733925af70a38b715David Lawrence# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
15a44745412679c30a6d022733925af70a38b715David Lawrence# PERFORMANCE OF THIS SOFTWARE.
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington# $Id: tests.sh,v 1.4 2012/01/31 23:47:31 tbox Exp $
50980039820700108f1f5eef1e42aa998a44f087Brian Wellington
9c3531d72aeaad6c5f01efe6a1c82023e1379e4dDavid LawrenceSYSTEMTESTTOP=..
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington. $SYSTEMTESTTOP/conf.sh
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonstatus=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonrm -f dig.out.*
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael GraffDIGOPTS="+tcp +noadd +nosea +nostat +nocmd -p 5300"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonfor conf in conf/good*.conf
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtondo
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington n=`expr $n + 1`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff echo "I:checking that $conf is accepted ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington ret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington $CHECKCONF "$conf" || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff if [ $ret != 0 ]; then echo "I:failed"; fi
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff status=`expr $status + $ret`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffdone
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Grafffor conf in conf/bad*.conf
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtondo
9a6bbb206efa528373c31928ebd0b7216c747a13Brian Wellington n=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington echo "I:checking that $conf is rejected ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington ret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington $CHECKCONF "$conf" >/dev/null && ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington if [ $ret != 0 ]; then echo "I:failed"; fi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington status=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtondone
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington#
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington# Authoritative tests against:
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff# filter-aaaa-on-v4 yes;
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff# filter-aaaa { 10.53.0.1; };
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff#
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffn=`expr $n + 1`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffecho "I:checking that AAAA is returned when only AAAA record exists, signed ($n)"
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffret=0
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff$DIG $DIGOPTS aaaa aaaa-only.signed -b 10.53.0.1 @10.53.0.1 > dig.out.ns1.test$n || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "AUTHORITY: 1," dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep ::2 dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffif [ $ret != 0 ]; then echo "I:failed"; fi
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffstatus=`expr $status + $ret`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffn=`expr $n + 1`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffecho "I:checking that AAAA is returned when only AAAA record exists, unsigned ($n)"
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffret=0
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff$DIG $DIGOPTS aaaa aaaa-only.unsigned -b 10.53.0.1 @10.53.0.1 > dig.out.ns1.test$n || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "AUTHORITY: 1," dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep ::5 dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffif [ $ret != 0 ]; then echo "I:failed"; fi
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffstatus=`expr $status + $ret`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffn=`expr $n + 1`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffecho "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, signed ($n)"
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffret=0
8a23742754e4640a298acb0d6bd7ed4da0c11798Brian Wellington$DIG $DIGOPTS aaaa dual.signed -b 10.53.0.1 @10.53.0.1 > dig.out.ns1.test$n || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "ANSWER: 0" dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "AUTHORITY: 0" dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "status: NOERROR" dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffif [ $ret != 0 ]; then echo "I:failed"; fi
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffstatus=`expr $status + $ret`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffn=`expr $n + 1`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffecho "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, unsigned ($n)"
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffret=0
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff$DIG $DIGOPTS aaaa dual.unsigned -b 10.53.0.1 @10.53.0.1 > dig.out.ns1.test$n || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "ANSWER: 0" dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "AUTHORITY: 0" dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "status: NOERROR" dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffif [ $ret != 0 ]; then echo "I:failed"; fi
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffstatus=`expr $status + $ret`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffn=`expr $n + 1`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffecho "I:checking that AAAA is returned when both AAAA and A records exist, signed and DO set ($n)"
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffret=0
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff$DIG $DIGOPTS aaaa dual.signed +dnssec -b 10.53.0.1 @10.53.0.1 > dig.out.ns1.test$n || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "AUTHORITY: 2," dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep ::3 dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffif [ $ret != 0 ]; then echo "I:failed"; fi
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffstatus=`expr $status + $ret`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffn=`expr $n + 1`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffecho "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, unsigned and DO set ($n)"
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffret=0
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff$DIG $DIGOPTS aaaa dual.unsigned -b 10.53.0.1 @10.53.0.1 > dig.out.ns1.test$n || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "ANSWER: 0" dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "AUTHORITY: 0," dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "status: NOERROR" dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffif [ $ret != 0 ]; then echo "I:failed"; fi
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffstatus=`expr $status + $ret`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffn=`expr $n + 1`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffecho "I:checking that AAAA is returned when both AAAA and A records exist and query source does not match acl ($n)"
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffret=0
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff$DIG $DIGOPTS aaaa dual.unsigned -b 10.53.0.2 @10.53.0.1 > dig.out.ns1.test$n || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "status: NOERROR" dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "AUTHORITY: 1," dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep ::6 dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffif [ $ret != 0 ]; then echo "I:failed"; fi
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffstatus=`expr $status + $ret`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffn=`expr $n + 1`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffecho "I:checking that A and not AAAA is returned when both AAAA and A records exist, signed and qtype=ANY ($n)"
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffret=0
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff$DIG $DIGOPTS any dual.signed -b 10.53.0.1 @10.53.0.1 > dig.out.ns1.test$n || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "status: NOERROR" dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "AUTHORITY: 0," dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "1.0.0.3" dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "::3" dig.out.ns1.test$n > /dev/null && ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffif [ $ret != 0 ]; then echo "I:failed"; fi
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffstatus=`expr $status + $ret`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffecho "I:checking that A and not AAAA is returned when both AAAA and A records exist, unsigned and qtype=ANY ($n)"
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffret=0
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff$DIG $DIGOPTS any dual.unsigned -b 10.53.0.1 @10.53.0.1 > dig.out.ns1.test$n || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "status: NOERROR" dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "AUTHORITY: 0," dig.out.ns1.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "1.0.0.6" dig.out.ns1.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "::6" dig.out.ns1.test$n > /dev/null && ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffif [ $ret != 0 ]; then echo "I:failed"; fi
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffstatus=`expr $status + $ret`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffn=`expr $n + 1`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffecho "I:checking that both A and AAAA are returned when both AAAA and A records exist, signed, qtype=ANY and DO is set ($n)"
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffret=0
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff$DIG $DIGOPTS any dual.signed +dnssec -b 10.53.0.1 @10.53.0.1 > dig.out.ns1.test$n || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "status: NOERROR" dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "AUTHORITY: 2," dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep ::3 dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "1.0.0.3" dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffif [ $ret != 0 ]; then echo "I:failed"; fi
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffstatus=`expr $status + $ret`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that A and not AAAA is returned when both AAAA and A records exist, unsigned, qtype=ANY and DO is set ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington$DIG $DIGOPTS any dual.unsigned +dnssec -b 10.53.0.1 @10.53.0.1 > dig.out.ns1.test$n || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "status: NOERROR" dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "AUTHORITY: 0," dig.out.ns1.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "1.0.0.6" dig.out.ns1.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "::6" dig.out.ns1.test$n > /dev/null && ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffif [ $ret != 0 ]; then echo "I:failed"; fi
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffstatus=`expr $status + $ret`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffn=`expr $n + 1`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffecho "I:checking that both A and AAAA are returned when both AAAA and A records exist, qtype=ANY and query source does not match acl ($n)"
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffret=0
8a23742754e4640a298acb0d6bd7ed4da0c11798Brian Wellington$DIG $DIGOPTS any dual.unsigned -b 10.53.0.2 @10.53.0.1 > dig.out.ns1.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "status: NOERROR" dig.out.ns1.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "AUTHORITY: 1," dig.out.ns1.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep 1.0.0.6 dig.out.ns1.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep ::6 dig.out.ns1.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonstatus=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that AAAA is returned when both AAAA and A record exists, unsigned over IPv6 ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif $TESTSOCK6 fd92:7065:b8e:ffff::1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonthen
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
9a6bbb206efa528373c31928ebd0b7216c747a13Brian Wellington$DIG $DIGOPTS aaaa dual.unsigned -b fd92:7065:b8e:ffff::1 @fd92:7065:b8e:ffff::1 > dig.out.ns1.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep 2001:db8::6 dig.out.ns1.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "AUTHORITY: 1," dig.out.ns1.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
9a6bbb206efa528373c31928ebd0b7216c747a13Brian Wellingtonstatus=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonelse
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I: skipped."
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonfi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that AAAA is omitted from additional section, qtype=NS ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington$DIG $DIGOPTS +add ns unsigned -b 10.53.0.1 @10.53.0.1 > dig.out.ns1.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep AAAA dig.out.ns1.test$n > /dev/null 2>&1 && ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "ANSWER: 1," dig.out.ns1.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "ADDITIONAL: 2" dig.out.ns1.test$n > /dev/null 2>&1 || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
9a6bbb206efa528373c31928ebd0b7216c747a13Brian Wellingtonstatus=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that AAAA is omitted from additional section, qtype=MX, unsigned ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington$DIG $DIGOPTS +add +dnssec mx unsigned -b 10.53.0.1 @10.53.0.1 > dig.out.ns1.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "^mx.unsigned.*AAAA" dig.out.ns1.test$n > /dev/null 2>&1 && ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
9a6bbb206efa528373c31928ebd0b7216c747a13Brian Wellingtonstatus=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that AAAA is included in additional section, qtype=MX, signed ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington$DIG $DIGOPTS +add +dnssec mx signed -b 10.53.0.1 @10.53.0.1 > dig.out.ns1.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "^mx.signed.*AAAA" dig.out.ns1.test$n > /dev/null 2>&1 || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "AUTHORITY: 2," dig.out.ns1.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonstatus=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that AAAA is included in additional section, qtype=MX, unsigned, over IPv6 ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif $TESTSOCK6 fd92:7065:b8e:ffff::1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonthen
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington$DIG $DIGOPTS +add +dnssec mx unsigned -b fd92:7065:b8e:ffff::1 @fd92:7065:b8e:ffff::1 > dig.out.ns1.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "^mx.unsigned.*AAAA" dig.out.ns1.test$n > /dev/null 2>&1 || ret=1
9a6bbb206efa528373c31928ebd0b7216c747a13Brian Wellingtongrep "AUTHORITY: 1," dig.out.ns1.test$n > /dev/null || ret=1
9a6bbb206efa528373c31928ebd0b7216c747a13Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
9a6bbb206efa528373c31928ebd0b7216c747a13Brian Wellingtonstatus=`expr $status + $ret`
9a6bbb206efa528373c31928ebd0b7216c747a13Brian Wellingtonelse
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I: skipped."
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonfi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington#
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington# Authoritative tests against:
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington# filter-aaaa-on-v4 break-dnssec;
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington# filter-aaaa { 10.53.0.4; };
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington#
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that AAAA is returned when only AAAA record exists, signed with break-dnssec ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington$DIG $DIGOPTS aaaa aaaa-only.signed -b 10.53.0.4 @10.53.0.4 > dig.out.ns4.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "AUTHORITY: 1," dig.out.ns4.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep ::2 dig.out.ns4.test$n > /dev/null || ret=1
50980039820700108f1f5eef1e42aa998a44f087Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
50980039820700108f1f5eef1e42aa998a44f087Brian Wellingtonstatus=`expr $status + $ret`
50980039820700108f1f5eef1e42aa998a44f087Brian Wellington
50980039820700108f1f5eef1e42aa998a44f087Brian Wellingtonn=`expr $n + 1`
50980039820700108f1f5eef1e42aa998a44f087Brian Wellingtonecho "I:checking that AAAA is returned when only AAAA record exists, unsigned with break-dnssec ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington$DIG $DIGOPTS aaaa aaaa-only.unsigned -b 10.53.0.4 @10.53.0.4 > dig.out.ns4.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "AUTHORITY: 1," dig.out.ns4.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep ::5 dig.out.ns4.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonstatus=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, signed with break-dnssec ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington$DIG $DIGOPTS aaaa dual.signed -b 10.53.0.4 @10.53.0.4 > dig.out.ns4.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "ANSWER: 0" dig.out.ns4.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "AUTHORITY: 0," dig.out.ns4.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "status: NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonstatus=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffn=`expr $n + 1`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffecho "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, unsigned with break-dnssec ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff$DIG $DIGOPTS aaaa dual.unsigned -b 10.53.0.4 @10.53.0.4 > dig.out.ns4.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "ANSWER: 0" dig.out.ns4.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "status: NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonstatus=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, signed and DO set with break-dnssec ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington$DIG $DIGOPTS aaaa dual.signed +dnssec -b 10.53.0.4 @10.53.0.4 > dig.out.ns4.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "ANSWER: 0" dig.out.ns4.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "status: NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonstatus=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, unsigned and DO set with break-dnssec ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington$DIG $DIGOPTS aaaa dual.unsigned -b 10.53.0.4 @10.53.0.4 > dig.out.ns4.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "ANSWER: 0" dig.out.ns4.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "status: NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonstatus=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that AAAA is returned when both AAAA and A records exist and query source does not match acl with break-dnssec ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington$DIG $DIGOPTS aaaa dual.unsigned -b 10.53.0.2 @10.53.0.4 > dig.out.ns4.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "status: NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep ::6 dig.out.ns4.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonstatus=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that A and not AAAA is returned when both AAAA and A records exist, signed and qtype=ANY with break-dnssec ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington$DIG $DIGOPTS any dual.signed -b 10.53.0.4 @10.53.0.4 > dig.out.ns4.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "status: NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "1.0.0.3" dig.out.ns4.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "::3" dig.out.ns4.test$n > /dev/null && ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonstatus=`expr $status + $ret`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that A and not AAAA is returned when both AAAA and A records exist, unsigned and qtype=ANY with break-dnssec ($n)"
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffret=0
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff$DIG $DIGOPTS any dual.unsigned -b 10.53.0.4 @10.53.0.4 > dig.out.ns4.test$n || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "status: NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "1.0.0.6" dig.out.ns4.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "::6" dig.out.ns4.test$n > /dev/null && ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffif [ $ret != 0 ]; then echo "I:failed"; fi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonstatus=`expr $status + $ret`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffn=`expr $n + 1`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffecho "I:checking that A and not AAAA is returned when both AAAA and A records exist, signed, qtype=ANY and DO is set with break-dnssec ($n)"
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffret=0
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff$DIG $DIGOPTS any dual.signed +dnssec -b 10.53.0.4 @10.53.0.4 > dig.out.ns4.test$n || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "status: NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "1.0.0.3" dig.out.ns4.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep ::3 dig.out.ns4.test$n > /dev/null && ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffif [ $ret != 0 ]; then echo "I:failed"; fi
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffstatus=`expr $status + $ret`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffn=`expr $n + 1`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffecho "I:checking that A and not AAAA is returned when both AAAA and A records exist, unsigned, qtype=ANY and DO is set with break-dnssec ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington$DIG $DIGOPTS any dual.unsigned +dnssec -b 10.53.0.4 @10.53.0.4 > dig.out.ns4.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "status: NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "1.0.0.6" dig.out.ns4.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "::6" dig.out.ns4.test$n > /dev/null && ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonstatus=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that both A and AAAA are returned when both AAAA and A records exist, qtype=ANY and query source does not match acl with break-dnssec ($n)"
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffret=0
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff$DIG $DIGOPTS any dual.unsigned -b 10.53.0.2 @10.53.0.4 > dig.out.ns4.test$n || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep "status: NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep 1.0.0.6 dig.out.ns4.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffgrep ::6 dig.out.ns4.test$n > /dev/null || ret=1
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffif [ $ret != 0 ]; then echo "I:failed"; fi
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffstatus=`expr $status + $ret`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graff
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffn=`expr $n + 1`
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffecho "I:checking that AAAA is returned when both AAAA and A record exists, unsigned over IPv6 with break-dnssec ($n)"
4e96d1fc0646de4d879e7a0bc1e7aba449a67596Michael Graffif $TESTSOCK6 fd92:7065:b8e:ffff::4
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonthen
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington$DIG $DIGOPTS aaaa dual.unsigned -b fd92:7065:b8e:ffff::4 @fd92:7065:b8e:ffff::4 > dig.out.ns4.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep 2001:db8::6 dig.out.ns4.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonstatus=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonelse
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I: skipped."
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonfi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that AAAA is omitted from additional section, qtype=NS, with break-dnssec ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington$DIG $DIGOPTS +add ns unsigned -b 10.53.0.4 @10.53.0.4 > dig.out.ns4.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep AAAA dig.out.ns4.test$n > /dev/null 2>&1 && ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "ADDITIONAL: 2" dig.out.ns4.test$n > /dev/null 2>&1 || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonstatus=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that AAAA is omitted from additional section, qtype=MX, unsigned, with break-dnssec ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington$DIG $DIGOPTS +add +dnssec mx unsigned -b 10.53.0.4 @10.53.0.4 > dig.out.ns4.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "^mx.unsigned.*AAAA" dig.out.ns4.test$n > /dev/null 2>&1 && ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonstatus=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that AAAA is omitted from additional section, qtype=MX, signed, with break-dnssec ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington$DIG $DIGOPTS +add +dnssec mx signed -b 10.53.0.4 @10.53.0.4 > dig.out.ns4.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "^mx.signed.*AAAA" dig.out.ns4.test$n > /dev/null 2>&1 && ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonstatus=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that AAAA is included in additional section, qtype=MX, unsigned, over IPv6, with break-dnssec ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif $TESTSOCK6 fd92:7065:b8e:ffff::4
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrencethen
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington$DIG $DIGOPTS +add +dnssec mx unsigned -b fd92:7065:b8e:ffff::4 @fd92:7065:b8e:ffff::4 > dig.out.ns4.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "^mx.unsigned.*AAAA" dig.out.ns4.test$n > /dev/null 2>&1 || ret=1
9a6bbb206efa528373c31928ebd0b7216c747a13Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
9a6bbb206efa528373c31928ebd0b7216c747a13Brian Wellingtonstatus=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonelse
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I: skipped."
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonfi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington#
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington# Recursive tests against:
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington# filter-aaaa-on-v4 yes;
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington# filter-aaaa { 10.53.0.2; };
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington#
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that AAAA is returned when only AAAA record exists, signed, recursive ($n)"
50980039820700108f1f5eef1e42aa998a44f087Brian Wellingtonret=0
50980039820700108f1f5eef1e42aa998a44f087Brian Wellington$DIG $DIGOPTS aaaa aaaa-only.signed -b 10.53.0.2 @10.53.0.2 > dig.out.ns2.test$n || ret=1
50980039820700108f1f5eef1e42aa998a44f087Brian Wellingtongrep ::2 dig.out.ns2.test$n > /dev/null || ret=1
50980039820700108f1f5eef1e42aa998a44f087Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
50980039820700108f1f5eef1e42aa998a44f087Brian Wellingtonstatus=`expr $status + $ret`
50980039820700108f1f5eef1e42aa998a44f087Brian Wellington
50980039820700108f1f5eef1e42aa998a44f087Brian Wellingtonn=`expr $n + 1`
50980039820700108f1f5eef1e42aa998a44f087Brian Wellingtonecho "I:checking that AAAA is returned when only AAAA record exists, unsigned, recursive ($n)"
50980039820700108f1f5eef1e42aa998a44f087Brian Wellingtonret=0
50980039820700108f1f5eef1e42aa998a44f087Brian Wellington$DIG $DIGOPTS aaaa aaaa-only.unsigned -b 10.53.0.2 @10.53.0.2 > dig.out.ns2.test$n || ret=1
50980039820700108f1f5eef1e42aa998a44f087Brian Wellingtongrep ::5 dig.out.ns2.test$n > /dev/null || ret=1
50980039820700108f1f5eef1e42aa998a44f087Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
50980039820700108f1f5eef1e42aa998a44f087Brian Wellingtonstatus=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, signed, recursive ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington$DIG $DIGOPTS aaaa dual.signed -b 10.53.0.2 @10.53.0.2 > dig.out.ns2.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "ANSWER: 0" dig.out.ns2.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonstatus=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, unsigned, recursive ($n)"
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonret=0
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington$DIG $DIGOPTS aaaa dual.unsigned -b 10.53.0.2 @10.53.0.2 > dig.out.ns2.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "ANSWER: 0" dig.out.ns2.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonstatus=`expr $status + $ret`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellington
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonn=`expr $n + 1`
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonecho "I:checking that AAAA is returned when both AAAA and A records exist, signed and DO set, recursive ($n)"
50980039820700108f1f5eef1e42aa998a44f087Brian Wellingtonret=0
50980039820700108f1f5eef1e42aa998a44f087Brian Wellington$DIG $DIGOPTS aaaa dual.signed +dnssec -b 10.53.0.2 @10.53.0.2 > dig.out.ns2.test$n || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtongrep ::3 dig.out.ns2.test$n > /dev/null || ret=1
878d3073b13833ee1a50dfeabf8e400b6fdfc754Brian Wellingtonif [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, unsigned and DO set, recursive ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned +dnssec -b 10.53.0.2 @10.53.0.2 > dig.out.ns2.test$n || ret=1
grep "ANSWER: 0" dig.out.ns2.test$n > /dev/null || ret=1
grep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is returned when both AAAA and A records exist and query source does not match acl, recursive ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned -b 10.53.0.1 @10.53.0.2 > dig.out.ns2.test$n || ret=1
grep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
grep ::6 dig.out.ns2.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, signed and qtype=ANY recursive ($n)"
ret=0
$DIG $DIGOPTS any dual.signed -b 10.53.0.2 @10.53.0.2 > dig.out.ns2.test$n || ret=1
grep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
grep "1.0.0.3" dig.out.ns2.test$n > /dev/null || ret=1
grep "::3" dig.out.ns2.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, unsigned and qtype=ANY recursive ($n)"
ret=0
$DIG $DIGOPTS any dual.unsigned -b 10.53.0.2 @10.53.0.2 > dig.out.ns2.test$n || ret=1
grep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
grep "1.0.0.6" dig.out.ns2.test$n > /dev/null || ret=1
grep "::6" dig.out.ns2.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that both A and AAAA are returned when both AAAA and A records exist, signed, qtype=ANY and DO is set, recursive ($n)"
ret=0
$DIG $DIGOPTS any dual.signed +dnssec -b 10.53.0.2 @10.53.0.2 > dig.out.ns2.test$n || ret=1
grep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
grep ::3 dig.out.ns2.test$n > /dev/null || ret=1
grep "1.0.0.3" dig.out.ns2.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, unsigned, qtype=ANY and DO is set, recursive ($n)"
ret=0
$DIG $DIGOPTS any dual.unsigned +dnssec -b 10.53.0.2 @10.53.0.2 > dig.out.ns2.test$n || ret=1
grep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
grep "1.0.0.6" dig.out.ns2.test$n > /dev/null || ret=1
grep "::6" dig.out.ns2.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that both A and AAAA are returned when both AAAA and A records exist, qtype=ANY and query source does not match acl, recursive ($n)"
ret=0
$DIG $DIGOPTS any dual.unsigned -b 10.53.0.1 @10.53.0.2 > dig.out.ns2.test$n || ret=1
grep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
grep 1.0.0.6 dig.out.ns2.test$n > /dev/null || ret=1
grep ::6 dig.out.ns2.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is returned when both AAAA and A record exists, unsigned over IPv6, recursive ($n)"
if $TESTSOCK6 fd92:7065:b8e:ffff::2
then
ret=0
$DIG $DIGOPTS aaaa dual.unsigned -b fd92:7065:b8e:ffff::2 @fd92:7065:b8e:ffff::2 > dig.out.ns2.test$n || ret=1
grep 2001:db8::6 dig.out.ns2.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
else
echo "I: skipped."
fi
n=`expr $n + 1`
echo "I:checking that AAAA is omitted from additional section, qtype=NS ($n)"
ret=0
$DIG $DIGOPTS +add ns unsigned -b 10.53.0.2 @10.53.0.2 > dig.out.ns2.test$n || ret=1
grep AAAA dig.out.ns2.test$n > /dev/null 2>&1 && ret=1
grep "ADDITIONAL: 2" dig.out.ns2.test$n > /dev/null 2>&1 || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is omitted from additional section, qtype=MX, unsigned ($n)"
ret=0
$DIG $DIGOPTS +add +dnssec mx unsigned -b 10.53.0.2 @10.53.0.2 > dig.out.ns2.test$n || ret=1
grep "^mx.unsigned.*AAAA" dig.out.ns2.test$n > /dev/null 2>&1 && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is included in additional section, qtype=MX, signed ($n)"
ret=0
$DIG $DIGOPTS +add +dnssec mx signed -b 10.53.0.2 @10.53.0.2 > dig.out.ns2.test$n || ret=1
grep "^mx.signed.*AAAA" dig.out.ns2.test$n > /dev/null 2>&1 || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is included in additional section, qtype=MX, unsigned, over IPv6 ($n)"
if $TESTSOCK6 fd92:7065:b8e:ffff::2
then
ret=0
$DIG $DIGOPTS +add +dnssec mx unsigned -b fd92:7065:b8e:ffff::2 @fd92:7065:b8e:ffff::2 > dig.out.ns2.test$n || ret=1
grep "^mx.unsigned.*AAAA" dig.out.ns2.test$n > /dev/null 2>&1 || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
else
echo "I: skipped."
fi
#
# Recursive tests against:
# filter-aaaa-on-v4 break-dnssec;
# filter-aaaa { 10.53.0.3; };
#
n=`expr $n + 1`
echo "I:checking that AAAA is returned when only AAAA record exists, signed, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa aaaa-only.signed -b 10.53.0.3 @10.53.0.3 > dig.out.ns3.test$n || ret=1
grep ::2 dig.out.ns3.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is returned when only AAAA record exists, unsigned, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa aaaa-only.unsigned -b 10.53.0.3 @10.53.0.3 > dig.out.ns3.test$n || ret=1
grep ::5 dig.out.ns3.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, signed, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.signed -b 10.53.0.3 @10.53.0.3 > dig.out.ns3.test$n || ret=1
grep "ANSWER: 0" dig.out.ns3.test$n > /dev/null || ret=1
grep "status: NOERROR" dig.out.ns3.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, unsigned, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned -b 10.53.0.3 @10.53.0.3 > dig.out.ns3.test$n || ret=1
grep "ANSWER: 0" dig.out.ns3.test$n > /dev/null || ret=1
grep "status: NOERROR" dig.out.ns3.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, signed and DO set, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.signed +dnssec -b 10.53.0.3 @10.53.0.3 > dig.out.ns3.test$n || ret=1
grep "ANSWER: 0" dig.out.ns3.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, unsigned and DO set, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned +dnssec -b 10.53.0.3 @10.53.0.3 > dig.out.ns3.test$n || ret=1
grep "ANSWER: 0" dig.out.ns3.test$n > /dev/null || ret=1
grep "status: NOERROR" dig.out.ns3.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is returned when both AAAA and A records exist and query source does not match acl, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned -b 10.53.0.1 @10.53.0.3 > dig.out.ns3.test$n || ret=1
grep "status: NOERROR" dig.out.ns3.test$n > /dev/null || ret=1
grep ::6 dig.out.ns3.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, signed and qtype=ANY with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS any dual.signed -b 10.53.0.3 @10.53.0.3 > dig.out.ns3.test$n || ret=1
grep "status: NOERROR" dig.out.ns3.test$n > /dev/null || ret=1
grep "1.0.0.3" dig.out.ns3.test$n > /dev/null || ret=1
grep "::3" dig.out.ns3.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, unsigned and qtype=ANY with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS any dual.unsigned -b 10.53.0.3 @10.53.0.3 > dig.out.ns3.test$n || ret=1
grep "status: NOERROR" dig.out.ns3.test$n > /dev/null || ret=1
grep "1.0.0.6" dig.out.ns3.test$n > /dev/null || ret=1
grep "::6" dig.out.ns3.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, signed, qtype=ANY and DO is set with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS any dual.signed +dnssec -b 10.53.0.3 @10.53.0.3 > dig.out.ns3.test$n || ret=1
grep "status: NOERROR" dig.out.ns3.test$n > /dev/null || ret=1
grep "1.0.0.3" dig.out.ns3.test$n > /dev/null || ret=1
grep ::3 dig.out.ns3.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, unsigned, qtype=ANY and DO is set with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS any dual.unsigned +dnssec -b 10.53.0.3 @10.53.0.3 > dig.out.ns3.test$n || ret=1
grep "status: NOERROR" dig.out.ns3.test$n > /dev/null || ret=1
grep "1.0.0.6" dig.out.ns3.test$n > /dev/null || ret=1
grep "::6" dig.out.ns3.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that both A and AAAA are returned when both AAAA and A records exist, qtype=ANY and query source does not match acl, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS any dual.unsigned -b 10.53.0.1 @10.53.0.3 > dig.out.ns3.test$n || ret=1
grep "status: NOERROR" dig.out.ns3.test$n > /dev/null || ret=1
grep 1.0.0.6 dig.out.ns3.test$n > /dev/null || ret=1
grep ::6 dig.out.ns3.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is returned when both AAAA and A record exists, unsigned over IPv6, recursive with break-dnssec ($n)"
if $TESTSOCK6 fd92:7065:b8e:ffff::3
then
ret=0
$DIG $DIGOPTS aaaa dual.unsigned -b fd92:7065:b8e:ffff::3 @fd92:7065:b8e:ffff::3 > dig.out.ns3.test$n || ret=1
grep 2001:db8::6 dig.out.ns3.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
else
echo "I: skipped."
fi
n=`expr $n + 1`
echo "I:checking that AAAA is omitted from additional section, qtype=NS, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS +add ns unsigned -b 10.53.0.3 @10.53.0.3 > dig.out.ns3.test$n || ret=1
grep AAAA dig.out.ns3.test$n > /dev/null 2>&1 && ret=1
grep "ADDITIONAL: 2" dig.out.ns3.test$n > /dev/null 2>&1 || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is omitted from additional section, qtype=MX, unsigned, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS +add +dnssec mx unsigned -b 10.53.0.3 @10.53.0.3 > dig.out.ns3.test$n || ret=1
grep "^mx.unsigned.*AAAA" dig.out.ns3.test$n > /dev/null 2>&1 && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is omitted from additional section, qtype=MX, signed, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS +add +dnssec mx signed -b 10.53.0.3 @10.53.0.3 > dig.out.ns3.test$n || ret=1
grep "^mx.signed.*AAAA" dig.out.ns3.test$n > /dev/null 2>&1 && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is included in additional section, qtype=MX, unsigned, over IPv6, recursive with break-dnssec ($n)"
if $TESTSOCK6 fd92:7065:b8e:ffff::3
then
ret=0
$DIG $DIGOPTS +add +dnssec mx unsigned -b fd92:7065:b8e:ffff::3 @fd92:7065:b8e:ffff::3 > dig.out.ns3.test$n || ret=1
grep "^mx.unsigned.*AAAA" dig.out.ns3.test$n > /dev/null 2>&1 || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
else
echo "I: skipped."
fi
$TESTSOCK6 fd92:7065:b8e:ffff::1 || {
echo "I:IPv6 address not configured; skipping IPv6 query tests"
echo "I:exit status: $status"
exit $status
}
# Reconfiguring for IPv6 tests
echo "I:reconfiguring servers"
cp -f ns1/named2.conf ns1/named.conf
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
cp -f ns2/named2.conf ns2/named.conf
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 reconfig 2>&1 | sed 's/^/I:ns2 /'
cp -f ns3/named2.conf ns3/named.conf
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 reconfig 2>&1 | sed 's/^/I:ns3 /'
cp -f ns4/named2.conf ns4/named.conf
$RNDC -c ../common/rndc.conf -s 10.53.0.4 -p 9953 reconfig 2>&1 | sed 's/^/I:ns4 /'
# BEGIN IPv6 TESTS
#
# Authoritative tests against:
# filter-aaaa-on-v6 yes;
# filter-aaaa { fd92:7065:b8e:ffff::1; };
#
n=`expr $n + 1`
echo "I:checking that AAAA is returned when only AAAA record exists, signed ($n)"
ret=0
$DIG $DIGOPTS aaaa aaaa-only.signed -b fd92:7065:b8e:ffff::1 @fd92:7065:b8e:ffff::1 > dig.out.ns1.test$n || ret=1
grep ::2 dig.out.ns1.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is returned when only AAAA record exists, unsigned ($n)"
ret=0
$DIG $DIGOPTS aaaa aaaa-only.unsigned -b fd92:7065:b8e:ffff::1 @fd92:7065:b8e:ffff::1 > dig.out.ns1.test$n || ret=1
grep ::5 dig.out.ns1.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, signed ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.signed -b fd92:7065:b8e:ffff::1 @fd92:7065:b8e:ffff::1 > dig.out.ns1.test$n || ret=1
grep "ANSWER: 0" dig.out.ns1.test$n > /dev/null || ret=1
grep "status: NOERROR" dig.out.ns1.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, unsigned ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned -b fd92:7065:b8e:ffff::1 @fd92:7065:b8e:ffff::1 > dig.out.ns1.test$n || ret=1
grep "ANSWER: 0" dig.out.ns1.test$n > /dev/null || ret=1
grep "status: NOERROR" dig.out.ns1.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is returned when both AAAA and A records exist, signed and DO set ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.signed +dnssec -b fd92:7065:b8e:ffff::1 @fd92:7065:b8e:ffff::1 > dig.out.ns1.test$n || ret=1
grep ::3 dig.out.ns1.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, unsigned and DO set ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned -b fd92:7065:b8e:ffff::1 @fd92:7065:b8e:ffff::1 > dig.out.ns1.test$n || ret=1
grep "ANSWER: 0" dig.out.ns1.test$n > /dev/null || ret=1
grep "status: NOERROR" dig.out.ns1.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is returned when both AAAA and A records exist and query source does not match acl ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned -b fd92:7065:b8e:ffff::2 @fd92:7065:b8e:ffff::1 > dig.out.ns1.test$n || ret=1
grep "status: NOERROR" dig.out.ns1.test$n > /dev/null || ret=1
grep ::6 dig.out.ns1.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, signed and qtype=ANY ($n)"
ret=0
$DIG $DIGOPTS any dual.signed -b fd92:7065:b8e:ffff::1 @fd92:7065:b8e:ffff::1 > dig.out.ns1.test$n || ret=1
grep "status: NOERROR" dig.out.ns1.test$n > /dev/null || ret=1
grep "1.0.0.3" dig.out.ns1.test$n > /dev/null || ret=1
grep "::3" dig.out.ns1.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, unsigned and qtype=ANY ($n)"
ret=0
$DIG $DIGOPTS any dual.unsigned -b fd92:7065:b8e:ffff::1 @fd92:7065:b8e:ffff::1 > dig.out.ns1.test$n || ret=1
grep "status: NOERROR" dig.out.ns1.test$n > /dev/null || ret=1
grep "1.0.0.6" dig.out.ns1.test$n > /dev/null || ret=1
grep "::6" dig.out.ns1.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that both A and AAAA are returned when both AAAA and A records exist, signed, qtype=ANY and DO is set ($n)"
ret=0
$DIG $DIGOPTS any dual.signed +dnssec -b fd92:7065:b8e:ffff::1 @fd92:7065:b8e:ffff::1 > dig.out.ns1.test$n || ret=1
grep "status: NOERROR" dig.out.ns1.test$n > /dev/null || ret=1
grep ::3 dig.out.ns1.test$n > /dev/null || ret=1
grep "1.0.0.3" dig.out.ns1.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, unsigned, qtype=ANY and DO is set ($n)"
ret=0
$DIG $DIGOPTS any dual.unsigned +dnssec -b fd92:7065:b8e:ffff::1 @fd92:7065:b8e:ffff::1 > dig.out.ns1.test$n || ret=1
grep "status: NOERROR" dig.out.ns1.test$n > /dev/null || ret=1
grep "1.0.0.6" dig.out.ns1.test$n > /dev/null || ret=1
grep "::6" dig.out.ns1.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that both A and AAAA are returned when both AAAA and A records exist, qtype=ANY and query source does not match acl ($n)"
ret=0
$DIG $DIGOPTS any dual.unsigned -b fd92:7065:b8e:ffff::2 @fd92:7065:b8e:ffff::1 > dig.out.ns1.test$n || ret=1
grep "status: NOERROR" dig.out.ns1.test$n > /dev/null || ret=1
grep 1.0.0.6 dig.out.ns1.test$n > /dev/null || ret=1
grep ::6 dig.out.ns1.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is returned when both AAAA and A record exists, unsigned over IPv4 ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned -b 10.53.0.1 @10.53.0.1 > dig.out.ns1.test$n || ret=1
grep 2001:db8::6 dig.out.ns1.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is omitted from additional section, qtype=NS ($n)"
ret=0
$DIG $DIGOPTS +add +dnssec ns unsigned -b fd92:7065:b8e:ffff::1 @fd92:7065:b8e:ffff::1 > dig.out.ns1.test$n || ret=1
grep AAAA dig.out.ns1.test$n > /dev/null 2>&1 && ret=1
grep "ADDITIONAL: 2" dig.out.ns1.test$n > /dev/null 2>&1 || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is omitted from additional section, qtype=MX, unsigned ($n)"
ret=0
$DIG $DIGOPTS +add +dnssec mx unsigned -b fd92:7065:b8e:ffff::1 @fd92:7065:b8e:ffff::1 > dig.out.ns1.test$n || ret=1
grep "^mx.unsigned.*AAAA" dig.out.ns1.test$n > /dev/null 2>&1 && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is included in additional section, qtype=MX, signed ($n)"
ret=0
$DIG $DIGOPTS +add +dnssec mx signed -b fd92:7065:b8e:ffff::1 @fd92:7065:b8e:ffff::1 > dig.out.ns1.test$n || ret=1
grep "^mx.signed.*AAAA" dig.out.ns1.test$n > /dev/null 2>&1 || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is included in additional section, qtype=MX, unsigned, over IPv4 ($n)"
ret=0
$DIG $DIGOPTS +add +dnssec mx unsigned -b 10.53.0.1 @10.53.0.1 > dig.out.ns1.test$n || ret=1
grep "^mx.unsigned.*AAAA" dig.out.ns1.test$n > /dev/null 2>&1 || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
#
# Authoritative tests against:
# filter-aaaa-on-v6 break-dnssec;
# filter-aaaa { fd92:7065:b8e:ffff::4; };
#
n=`expr $n + 1`
echo "I:checking that AAAA is returned when only AAAA record exists, signed with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa aaaa-only.signed -b fd92:7065:b8e:ffff::4 @fd92:7065:b8e:ffff::4 > dig.out.ns4.test$n || ret=1
grep ::2 dig.out.ns4.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is returned when only AAAA record exists, unsigned with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa aaaa-only.unsigned -b fd92:7065:b8e:ffff::4 @fd92:7065:b8e:ffff::4 > dig.out.ns4.test$n || ret=1
grep ::5 dig.out.ns4.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, signed with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.signed -b fd92:7065:b8e:ffff::4 @fd92:7065:b8e:ffff::4 > dig.out.ns4.test$n || ret=1
grep "ANSWER: 0" dig.out.ns4.test$n > /dev/null || ret=1
grep "status: NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, unsigned with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned -b fd92:7065:b8e:ffff::4 @fd92:7065:b8e:ffff::4 > dig.out.ns4.test$n || ret=1
grep "ANSWER: 0" dig.out.ns4.test$n > /dev/null || ret=1
grep "status: NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, signed and DO set with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.signed +dnssec -b fd92:7065:b8e:ffff::4 @fd92:7065:b8e:ffff::4 > dig.out.ns4.test$n || ret=1
grep "ANSWER: 0" dig.out.ns4.test$n > /dev/null || ret=1
grep "status: NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, unsigned and DO set with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned -b fd92:7065:b8e:ffff::4 @fd92:7065:b8e:ffff::4 > dig.out.ns4.test$n || ret=1
grep "ANSWER: 0" dig.out.ns4.test$n > /dev/null || ret=1
grep "status: NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is returned when both AAAA and A records exist and query source does not match acl with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned -b fd92:7065:b8e:ffff::2 @fd92:7065:b8e:ffff::4 > dig.out.ns4.test$n || ret=1
grep "status: NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
grep ::6 dig.out.ns4.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, signed and qtype=ANY with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS any dual.signed -b fd92:7065:b8e:ffff::4 @fd92:7065:b8e:ffff::4 > dig.out.ns4.test$n || ret=1
grep "status: NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
grep "1.0.0.3" dig.out.ns4.test$n > /dev/null || ret=1
grep "::3" dig.out.ns4.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, unsigned and qtype=ANY with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS any dual.unsigned -b fd92:7065:b8e:ffff::4 @fd92:7065:b8e:ffff::4 > dig.out.ns4.test$n || ret=1
grep "status: NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
grep "1.0.0.6" dig.out.ns4.test$n > /dev/null || ret=1
grep "::6" dig.out.ns4.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, signed, qtype=ANY and DO is set with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS any dual.signed +dnssec -b fd92:7065:b8e:ffff::4 @fd92:7065:b8e:ffff::4 > dig.out.ns4.test$n || ret=1
grep "status: NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
grep "1.0.0.3" dig.out.ns4.test$n > /dev/null || ret=1
grep ::3 dig.out.ns4.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, unsigned, qtype=ANY and DO is set with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS any dual.unsigned +dnssec -b fd92:7065:b8e:ffff::4 @fd92:7065:b8e:ffff::4 > dig.out.ns4.test$n || ret=1
grep "status: NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
grep "1.0.0.6" dig.out.ns4.test$n > /dev/null || ret=1
grep "::6" dig.out.ns4.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that both A and AAAA are returned when both AAAA and A records exist, qtype=ANY and query source does not match acl with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS any dual.unsigned -b fd92:7065:b8e:ffff::2 @fd92:7065:b8e:ffff::4 > dig.out.ns4.test$n || ret=1
grep "status: NOERROR" dig.out.ns4.test$n > /dev/null || ret=1
grep 1.0.0.6 dig.out.ns4.test$n > /dev/null || ret=1
grep ::6 dig.out.ns4.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is returned when both AAAA and A record exists, unsigned over IPv4 with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned -b 10.53.0.4 @10.53.0.4 > dig.out.ns4.test$n || ret=1
grep 2001:db8::6 dig.out.ns4.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is omitted from additional section, qtype=NS, with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS +add +dnssec ns unsigned -b fd92:7065:b8e:ffff::4 @fd92:7065:b8e:ffff::4 > dig.out.ns4.test$n || ret=1
grep AAAA dig.out.ns4.test$n > /dev/null 2>&1 && ret=1
grep "ADDITIONAL: 2" dig.out.ns4.test$n > /dev/null 2>&1 || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is omitted from additional section, qtype=MX, unsigned, with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS +add +dnssec mx unsigned -b fd92:7065:b8e:ffff::4 @fd92:7065:b8e:ffff::4 > dig.out.ns4.test$n || ret=1
grep "^mx.unsigned.*AAAA" dig.out.ns4.test$n > /dev/null 2>&1 && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is omitted from additional section, qtype=MX, signed, with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS +add +dnssec mx signed -b fd92:7065:b8e:ffff::4 @fd92:7065:b8e:ffff::4 > dig.out.ns4.test$n || ret=1
grep "^mx.signed.*AAAA" dig.out.ns4.test$n > /dev/null 2>&1 && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is included in additional section, qtype=MX, unsigned, over IPv4, with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS +add +dnssec mx unsigned -b 10.53.0.4 @10.53.0.4 > dig.out.ns4.test$n || ret=1
grep "^mx.unsigned.*AAAA" dig.out.ns4.test$n > /dev/null 2>&1 || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
#
# Recursive tests against:
# filter-aaaa-on-v6 yes;
# filter-aaaa { fd92:7065:b8e:ffff::2; };
#
n=`expr $n + 1`
echo "I:checking that AAAA is returned when only AAAA record exists, signed, recursive ($n)"
ret=0
$DIG $DIGOPTS aaaa aaaa-only.signed -b fd92:7065:b8e:ffff::2 @fd92:7065:b8e:ffff::2 > dig.out.ns2.test$n || ret=1
grep ::2 dig.out.ns2.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is returned when only AAAA record exists, unsigned, recursive ($n)"
ret=0
$DIG $DIGOPTS aaaa aaaa-only.unsigned -b fd92:7065:b8e:ffff::2 @fd92:7065:b8e:ffff::2 > dig.out.ns2.test$n || ret=1
grep ::5 dig.out.ns2.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, signed, recursive ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.signed -b fd92:7065:b8e:ffff::2 @fd92:7065:b8e:ffff::2 > dig.out.ns2.test$n || ret=1
grep "ANSWER: 0" dig.out.ns2.test$n > /dev/null || ret=1
grep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, unsigned, recursive ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned -b fd92:7065:b8e:ffff::2 @fd92:7065:b8e:ffff::2 > dig.out.ns2.test$n || ret=1
grep "ANSWER: 0" dig.out.ns2.test$n > /dev/null || ret=1
grep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is returned when both AAAA and A records exist, signed and DO set, recursive ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.signed +dnssec -b fd92:7065:b8e:ffff::2 @fd92:7065:b8e:ffff::2 > dig.out.ns2.test$n || ret=1
grep ::3 dig.out.ns2.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, unsigned and DO set, recursive ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned +dnssec -b fd92:7065:b8e:ffff::2 @fd92:7065:b8e:ffff::2 > dig.out.ns2.test$n || ret=1
grep "ANSWER: 0" dig.out.ns2.test$n > /dev/null || ret=1
grep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is returned when both AAAA and A records exist and query source does not match acl, recursive ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned -b fd92:7065:b8e:ffff::1 @fd92:7065:b8e:ffff::2 > dig.out.ns2.test$n || ret=1
grep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
grep ::6 dig.out.ns2.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, signed and qtype=ANY recursive ($n)"
ret=0
$DIG $DIGOPTS any dual.signed -b fd92:7065:b8e:ffff::2 @fd92:7065:b8e:ffff::2 > dig.out.ns2.test$n || ret=1
grep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
grep "1.0.0.3" dig.out.ns2.test$n > /dev/null || ret=1
grep "::3" dig.out.ns2.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, unsigned and qtype=ANY recursive ($n)"
ret=0
$DIG $DIGOPTS any dual.unsigned -b fd92:7065:b8e:ffff::2 @fd92:7065:b8e:ffff::2 > dig.out.ns2.test$n || ret=1
grep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
grep "1.0.0.6" dig.out.ns2.test$n > /dev/null || ret=1
grep "::6" dig.out.ns2.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that both A and AAAA are returned when both AAAA and A records exist, signed, qtype=ANY and DO is set, recursive ($n)"
ret=0
$DIG $DIGOPTS any dual.signed +dnssec -b fd92:7065:b8e:ffff::2 @fd92:7065:b8e:ffff::2 > dig.out.ns2.test$n || ret=1
grep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
grep ::3 dig.out.ns2.test$n > /dev/null || ret=1
grep "1.0.0.3" dig.out.ns2.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, unsigned, qtype=ANY and DO is set, recursive ($n)"
ret=0
$DIG $DIGOPTS any dual.unsigned +dnssec -b fd92:7065:b8e:ffff::2 @fd92:7065:b8e:ffff::2 > dig.out.ns2.test$n || ret=1
grep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
grep "1.0.0.6" dig.out.ns2.test$n > /dev/null || ret=1
grep "::6" dig.out.ns2.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that both A and AAAA are returned when both AAAA and A records exist, qtype=ANY and query source does not match acl, recursive ($n)"
ret=0
$DIG $DIGOPTS any dual.unsigned -b fd92:7065:b8e:ffff::1 @fd92:7065:b8e:ffff::2 > dig.out.ns2.test$n || ret=1
grep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
grep 1.0.0.6 dig.out.ns2.test$n > /dev/null || ret=1
grep ::6 dig.out.ns2.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is returned when both AAAA and A record exists, unsigned over IPv4, recursive ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned -b 10.53.0.2 @10.53.0.2 > dig.out.ns2.test$n || ret=1
grep 2001:db8::6 dig.out.ns2.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is omitted from additional section, qtype=NS ($n)"
ret=0
$DIG $DIGOPTS +add +dnssec ns unsigned -b fd92:7065:b8e:ffff::2 @fd92:7065:b8e:ffff::2 > dig.out.ns2.test$n || ret=1
grep AAAA dig.out.ns2.test$n > /dev/null 2>&1 && ret=1
grep "ADDITIONAL: 2" dig.out.ns2.test$n > /dev/null 2>&1 || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is omitted from additional section, qtype=MX, unsigned ($n)"
ret=0
$DIG $DIGOPTS +add +dnssec mx unsigned -b fd92:7065:b8e:ffff::2 @fd92:7065:b8e:ffff::2 > dig.out.ns2.test$n || ret=1
grep "^mx.unsigned.*AAAA" dig.out.ns2.test$n > /dev/null 2>&1 && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is included in additional section, qtype=MX, signed ($n)"
ret=0
$DIG $DIGOPTS +add +dnssec mx signed -b fd92:7065:b8e:ffff::2 @fd92:7065:b8e:ffff::2 > dig.out.ns2.test$n || ret=1
grep "^mx.signed.*AAAA" dig.out.ns2.test$n > /dev/null 2>&1 || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is included in additional section, qtype=MX, unsigned, over IPv4 ($n)"
ret=0
$DIG $DIGOPTS +add +dnssec mx unsigned -b 10.53.0.2 @10.53.0.2 > dig.out.ns2.test$n || ret=1
grep "^mx.unsigned.*AAAA" dig.out.ns2.test$n > /dev/null 2>&1 || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
#
# Recursive tests against:
# filter-aaaa-on-v6 yes;
# filter-aaaa { fd92:7065:b8e:ffff::3; };
#
n=`expr $n + 1`
echo "I:checking that AAAA is returned when only AAAA record exists, signed, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa aaaa-only.signed -b fd92:7065:b8e:ffff::3 @fd92:7065:b8e:ffff::3 > dig.out.ns3.test$n || ret=1
grep ::2 dig.out.ns3.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is returned when only AAAA record exists, unsigned, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa aaaa-only.unsigned -b fd92:7065:b8e:ffff::3 @fd92:7065:b8e:ffff::3 > dig.out.ns3.test$n || ret=1
grep ::5 dig.out.ns3.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, signed, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.signed -b fd92:7065:b8e:ffff::3 @fd92:7065:b8e:ffff::3 > dig.out.ns3.test$n || ret=1
grep "ANSWER: 0" dig.out.ns3.test$n > /dev/null || ret=1
grep "status: NOERROR" dig.out.ns3.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, unsigned, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned -b fd92:7065:b8e:ffff::3 @fd92:7065:b8e:ffff::3 > dig.out.ns3.test$n || ret=1
grep "ANSWER: 0" dig.out.ns3.test$n > /dev/null || ret=1
grep "status: NOERROR" dig.out.ns3.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, signed and DO set, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.signed +dnssec -b fd92:7065:b8e:ffff::3 @fd92:7065:b8e:ffff::3 > dig.out.ns3.test$n || ret=1
grep "ANSWER: 0" dig.out.ns3.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that NODATA/NOERROR is returned when both AAAA and A records exist, unsigned and DO set, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned +dnssec -b fd92:7065:b8e:ffff::3 @fd92:7065:b8e:ffff::3 > dig.out.ns3.test$n || ret=1
grep "ANSWER: 0" dig.out.ns3.test$n > /dev/null || ret=1
grep "status: NOERROR" dig.out.ns3.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is returned when both AAAA and A records exist and query source does not match acl, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned -b fd92:7065:b8e:ffff::1 @fd92:7065:b8e:ffff::3 > dig.out.ns3.test$n || ret=1
grep "status: NOERROR" dig.out.ns3.test$n > /dev/null || ret=1
grep ::6 dig.out.ns3.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, signed and qtype=ANY with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS any dual.signed -b fd92:7065:b8e:ffff::3 @fd92:7065:b8e:ffff::3 > dig.out.ns3.test$n || ret=1
grep "status: NOERROR" dig.out.ns3.test$n > /dev/null || ret=1
grep "1.0.0.3" dig.out.ns3.test$n > /dev/null || ret=1
grep "::3" dig.out.ns3.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, unsigned and qtype=ANY with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS any dual.unsigned -b fd92:7065:b8e:ffff::3 @fd92:7065:b8e:ffff::3 > dig.out.ns3.test$n || ret=1
grep "status: NOERROR" dig.out.ns3.test$n > /dev/null || ret=1
grep "1.0.0.6" dig.out.ns3.test$n > /dev/null || ret=1
grep "::6" dig.out.ns3.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, signed, qtype=ANY and DO is set with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS any dual.signed +dnssec -b fd92:7065:b8e:ffff::3 @fd92:7065:b8e:ffff::3 > dig.out.ns3.test$n || ret=1
grep "status: NOERROR" dig.out.ns3.test$n > /dev/null || ret=1
grep "1.0.0.3" dig.out.ns3.test$n > /dev/null || ret=1
grep ::3 dig.out.ns3.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that A and not AAAA is returned when both AAAA and A records exist, unsigned, qtype=ANY and DO is set with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS any dual.unsigned +dnssec -b fd92:7065:b8e:ffff::3 @fd92:7065:b8e:ffff::3 > dig.out.ns3.test$n || ret=1
grep "status: NOERROR" dig.out.ns3.test$n > /dev/null || ret=1
grep "1.0.0.6" dig.out.ns3.test$n > /dev/null || ret=1
grep "::6" dig.out.ns3.test$n > /dev/null && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that both A and AAAA are returned when both AAAA and A records exist, qtype=ANY and query source does not match acl, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS any dual.unsigned -b fd92:7065:b8e:ffff::1 @fd92:7065:b8e:ffff::3 > dig.out.ns3.test$n || ret=1
grep "status: NOERROR" dig.out.ns3.test$n > /dev/null || ret=1
grep 1.0.0.6 dig.out.ns3.test$n > /dev/null || ret=1
grep ::6 dig.out.ns3.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is returned when both AAAA and A record exists, unsigned over IPv4, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS aaaa dual.unsigned -b 10.53.0.3 @10.53.0.3 > dig.out.ns3.test$n || ret=1
grep 2001:db8::6 dig.out.ns3.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is omitted from additional section, qtype=NS, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS +add +dnssec ns unsigned -b fd92:7065:b8e:ffff::3 @fd92:7065:b8e:ffff::3 > dig.out.ns3.test$n || ret=1
grep AAAA dig.out.ns3.test$n > /dev/null 2>&1 && ret=1
grep "ADDITIONAL: 2" dig.out.ns3.test$n > /dev/null 2>&1 || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is omitted from additional section, qtype=MX, unsigned, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS +add +dnssec mx unsigned -b fd92:7065:b8e:ffff::3 @fd92:7065:b8e:ffff::3 > dig.out.ns3.test$n || ret=1
grep "^mx.unsigned.*AAAA" dig.out.ns3.test$n > /dev/null 2>&1 && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is omitted from additional section, qtype=MX, signed, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS +add +dnssec mx signed -b fd92:7065:b8e:ffff::3 @fd92:7065:b8e:ffff::3 > dig.out.ns3.test$n || ret=1
grep "^mx.signed.*AAAA" dig.out.ns3.test$n > /dev/null 2>&1 && ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
n=`expr $n + 1`
echo "I:checking that AAAA is included in additional section, qtype=MX, unsigned, over IPv4, recursive with break-dnssec ($n)"
ret=0
$DIG $DIGOPTS +add +dnssec mx unsigned -b 10.53.0.3 @10.53.0.3 > dig.out.ns3.test$n || ret=1
grep "^mx.unsigned.*AAAA" dig.out.ns3.test$n > /dev/null 2>&1 || ret=1
if [ $ret != 0 ]; then echo "I:failed"; fi
status=`expr $status + $ret`
echo "I:exit status: $status"
exit $status