d1bc66f4dfdc4a017b3236139787c85101620bb8Tinderbox User# Copyright (C) 2011-2017 Internet Systems Consortium, Inc. ("ISC")
0c27b3fe77ac1d5094ba3521e8142d9e7973133fMark Andrews# This Source Code Form is subject to the terms of the Mozilla Public
0c27b3fe77ac1d5094ba3521e8142d9e7973133fMark Andrews# License, v. 2.0. If a copy of the MPL was not distributed with this
0c27b3fe77ac1d5094ba3521e8142d9e7973133fMark Andrews# file, You can obtain one at http://mozilla.org/MPL/2.0/.
87708bde16713bc02ff2598f4a82f98c699a2f2dMark Andrews# test response policy zones (RPZ)
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Huntns2=$ns.2 # authoritative server whose records are rewritten
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Huntns4=$ns.4 # another authoritative server that is rewritten
87708bde16713bc02ff2598f4a82f98c699a2f2dMark Andrewswhile getopts "x" c; do
87708bde16713bc02ff2598f4a82f98c699a2f2dMark Andrewsshift `expr $OPTIND - 1 || true`
87708bde16713bc02ff2598f4a82f98c699a2f2dMark Andrews# really quit on control-C
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon SchryverRNDCCMD="$RNDC -c $SYSTEMTESTTOP/common/rndc.conf -p 9953 -s"
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Hunt # Also default to -bX where X is the @value so that OS X will choose
06e28e50bd06bf3127b560c97a81f67306bacb02Mark Andrews digcmd_args=`echo "+noadd +time=2 +tries=1 -p 5300 $*" | \
87708bde16713bc02ff2598f4a82f98c699a2f2dMark Andrews# set DIGNM=file name for dig output
88112d5fcb6b9e1d0f80105a9d2a6f09440c2401Mark Andrews while test -f $DIGNM; do
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver# (re)load the reponse policy zones with the rules in the file $TEST_FILE
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver echo "I:failed to update policy zone with $TEST_FILE"
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver # try to ensure that the server really has stopped
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver if test -z "$HAVE_CORE" -a -f ns$1/named.pid; then
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver if test -f ns$1/named.pid; then
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver if test -f ns$1/base.db; then
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver $PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns$1
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver# $1=server and irrelevant args $2=error message
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver $RNDCCMD $CKALIVE_IP status >/dev/null 2>&1 && return 0
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver # restart the server to avoid stalling waiting for it to stop
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Hunt NEW_CNT=0`sed -n -e 's/[ ]*\([0-9]*\).response policy.*/\1/p' \
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Hunt setret "I:wrong $LABEL $NSDIR statistics of $GOT instead of $EXPECTED"
3a26e75e3c475b6f2f34716fa2847bf015db57c5Mark Andrews NEW_CNT=0`sed -n -e 's/[ ]*\([0-9]*\).response policy.*/\1/p' \
3a26e75e3c475b6f2f34716fa2847bf015db57c5Mark Andrews if test "$GOT" -lt "$MIN" -o "$GOT" -gt "$MAX"; then
3a26e75e3c475b6f2f34716fa2847bf015db57c5Mark Andrews setret "I:wrong $LABEL $NSDIR statistics of $GOT instead of ${MIN}..${MAX}"
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver# $1=message $2=optional test file name
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver sed -e 's/[ ]add[ ]/ delete /' $TEST_FILE | $NSUPDATE
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver ckalive $ns3 "I:failed; ns3 server crashed and restarted"
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver# $1=dig args $2=other dig output file
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver #ckalive "$1" "I:server crashed by 'dig $1'" || return 1
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver if $PERL $SYSTEMTESTTOP/digcomp.pl $DIGNM $2 >/dev/null; then
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Hunt NEED_TCP=`echo "$1" | sed -n -e 's/[Tt][Cc][Pp].*/TCP/p'`
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Hunt RESULT_TCP=`sed -n -e 's/.*Truncated, retrying in TCP.*/TCP/p' $DIGNM`
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Hunt setret "I:'dig $1' wrong; no or unexpected truncation in $DIGNM"
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver# check only that the server does not crash
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver# $1=target domain $2=optional query type
87708bde16713bc02ff2598f4a82f98c699a2f2dMark Andrews# check rewrite to NXDOMAIN
87708bde16713bc02ff2598f4a82f98c699a2f2dMark Andrews# $1=target domain $2=optional query type
87708bde16713bc02ff2598f4a82f98c699a2f2dMark Andrews# check rewrite to NODATA
87708bde16713bc02ff2598f4a82f98c699a2f2dMark Andrews# $1=target domain $2=optional query type
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver | sed -e 's/^[a-z].* IN CNAME /;xxx &/' >$DIGNM
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver# check rewrite to an address
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver# modify the output so that it is easily compared, but save the original line
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver# $1=IPv4 address $2=digcmd args $3=optional TTL
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver #ckalive "$2" "I:server crashed by 'dig $2'" || return 1
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver ADDR_ESC=`echo "$ADDR" | sed -e 's/\./\\\\./g'`
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt ADDR_TTL=`sed -n -e "s/^[-.a-z0-9]\{1,\} *\([0-9]*\) IN AA* ${ADDR_ESC}\$/\1/p" $DIGNM`
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver setret "I:'dig $2' wrong; no address $ADDR record in $DIGNM"
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver if test -n "$3" && test "$ADDR_TTL" -ne "$3"; then
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver setret "I:'dig $2' wrong; TTL=$ADDR_TTL instead of $3 in $DIGNM"
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Hunt# Check that a response is not rewritten
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Hunt# Use $ns1 instead of the authority for most test domains, $ns2 to prevent
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Hunt# spurious differences for `dig +norecurse`
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Hunt# $1=optional "TCP" remaining args for dig
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt ckresult "$*" ${DIGNM}_OK && clean_result ${DIGNM}_OK
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver# check against a 'here document'
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Hunt# check dropped response
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan HuntDROPPED='^;; connection timed out; no servers could be reached'
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver# make prototype files to check against rewritten results
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Huntnochange sub.a3-2.tld2 # 5 miss where DNAME might work
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryvernxdomain a4-2.tld2 # 6 rewrite based on CNAME target
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryveraddr 12.12.12.12 a4-1.sub1.tld2 # 9 A replacement
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryveraddr 12.12.12.12 a4-1.sub2.tld2 # 10 A replacement with wildcard
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryveraddr 12.12.12.12 nxc1.sub1.tld2 # 11 replace NXDOMAIN with CNAME
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryveraddr 12.12.12.12 nxc2.sub1.tld2 # 12 replace NXDOMAIN with CNAME chain
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryveraddr 127.4.4.1 a4-4.tld2 # 13 prefer 1st conflicting QNAME zone
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryveraddr 56.56.56.56 a3-6.tld2 # 16 wildcard CNAME
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryveraddr 57.57.57.57 a3-7.sub1.tld2 # 17 wildcard CNAME
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryveraddr 127.0.0.16 a4-5-cname3.tld2 # 18 CNAME chain
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryveraddr 127.0.0.17 a4-6-cname3.tld2 # 19 stop short in CNAME chain
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Huntnochange a5-2.tld2 +norecurse # 20 check that RD=1 is required
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryvernxdomain c1.crash2.tld3 # 24 assert in rbtdb.c
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryvernxdomain a0-1.tld2 +dnssec # 25 simple DO=1 without signatures
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Huntnxdomain a0-1.tld2s +nodnssec # 26 simple DO=0 with signatures
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryvernochange a0-1.tld2s +dnssec # 27 simple DO=1 with signatures
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryvernxdomain a0-1s-cname.tld2s +dnssec # 28 DNSSEC too early in CNAME chain
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryvernochange a0-1-scname.tld2 +dnssec # 29 DNSSEC on target in CNAME chain
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Huntnochange a0-1.tld2s srv +auth +dnssec # 30 no write for DNSSEC and no record
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Hunthere x.servfail <<'EOF' # 34 qname-wait-recurse yes
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Huntaddr 35.35.35.35 "x.servfail @$ns5" # 35 qname-wait-recurse no
3d751891410f9892ca1c1deba2f7d8556ae91b0cMark Andrewsstart_group "NXDOMAIN/NODATA action on QNAME trigger" test1
3d751891410f9892ca1c1deba2f7d8556ae91b0cMark Andrewsnodata a3-2.tld2 @$ns6 # 3 nodata at DNAME itself
3d751891410f9892ca1c1deba2f7d8556ae91b0cMark Andrewsnxdomain a4-2.tld2 @$ns6 # 4 rewrite based on CNAME target
3d751891410f9892ca1c1deba2f7d8556ae91b0cMark Andrewsaddr 12.12.12.12 "a4-1.sub1.tld2 @$ns6" # 7 A replacement
3d751891410f9892ca1c1deba2f7d8556ae91b0cMark Andrewsaddr 12.12.12.12 "a4-1.sub2.tld2 @$ns6" # 8 A replacement with wildcard
3d751891410f9892ca1c1deba2f7d8556ae91b0cMark Andrewsaddr 127.4.4.1 "a4-4.tld2 @$ns6" # 9 prefer 1st conflicting QNAME zone
3d751891410f9892ca1c1deba2f7d8556ae91b0cMark Andrewsaddr 12.12.12.12 "nxc1.sub1.tld2 @$ns6" # 10 replace NXDOMAIN w/ CNAME
3d751891410f9892ca1c1deba2f7d8556ae91b0cMark Andrewsaddr 12.12.12.12 "nxc2.sub1.tld2 @$ns6" # 11 replace NXDOMAIN w/ CNAME chain
3d751891410f9892ca1c1deba2f7d8556ae91b0cMark Andrewsaddr 56.56.56.56 "a3-6.tld2 @$ns6" # 13 wildcard CNAME
3d751891410f9892ca1c1deba2f7d8556ae91b0cMark Andrewsaddr 57.57.57.57 "a3-7.sub1.tld2 @$ns6" # 14 wildcard CNAME
3d751891410f9892ca1c1deba2f7d8556ae91b0cMark Andrewsaddr 127.0.0.16 "a4-5-cname3.tld2 @$ns6" # 15 CNAME chain
3d751891410f9892ca1c1deba2f7d8556ae91b0cMark Andrewsaddr 127.0.0.17 "a4-6-cname3.tld2 @$ns6" # 16 stop short in CNAME chain
3d751891410f9892ca1c1deba2f7d8556ae91b0cMark Andrewsnxdomain c1.crash2.tld3 @$ns6 # 17 assert in rbtdb.c
3d751891410f9892ca1c1deba2f7d8556ae91b0cMark Andrewsnxdomain a0-1.tld2 +dnssec @$ns6 # 18 simple DO=1 without sigs
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryvernochange a3-2.tld2 # 2 no policy record so no change
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryvernochange a4-1.tld2 # 3 obsolete PASSTHRU record style
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryvernochange a4-2.tld2 -taaaa # 5 no A => no policy rewrite
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryvernochange a4-2.tld2 -ttxt # 6 no A => no policy rewrite
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryvernxdomain a4-2.tld2 -tany # 7 no A => no policy rewrite
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryveraddr 127.0.0.1 a5-1-2.tld2 # 11 prefer smallest policy address
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryveraddr 127.0.0.1 a5-3.tld2 # 12 prefer first conflicting IP zone
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Huntnochange a5-4.tld2 +norecurse # 13 check that RD=1 is required for #14
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Huntaddr 127.0.0.17 "a4-4.tld2 -b $ns1" # 17 client-IP address trigger
df0892aea6bfd20a01c3abf2b756625d23830390Mark Andrewsnxdomain a7-1.tld2 # 18 slave policy zone (RT34450)
df0892aea6bfd20a01c3abf2b756625d23830390Mark Andrewsgoodsoa="rpz.tld2. hostmaster.ns.tld2. 2 3600 1200 604800 60"
df0892aea6bfd20a01c3abf2b756625d23830390Mark Andrews soa=`$DIG -p 5300 +short soa bl.tld2 @10.53.0.3 -b10.53.0.3`
df0892aea6bfd20a01c3abf2b756625d23830390Mark Andrewssleep 1 # ensure that a clock tick has occured so that the reload takes effect
df0892aea6bfd20a01c3abf2b756625d23830390Mark Andrewsgoodsoa="rpz.tld2. hostmaster.ns.tld2. 3 3600 1200 604800 60"
df0892aea6bfd20a01c3abf2b756625d23830390Mark Andrews soa=`$DIG -p 5300 +short soa bl.tld2 @10.53.0.3 -b10.53.0.3`
df0892aea6bfd20a01c3abf2b756625d23830390Mark Andrewsnxdomain a7-1.tld2 # 20 slave policy zone (RT34450)
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver# check that IP addresses for previous group were deleted from the radix tree
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt # these tests assume "min-ns-dots 0"
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver nochange a3-1.tld2 +dnssec # 2 this once caused problems
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver nxdomain a3-1.sub1.tld2 # 3 NXDOMAIN *.sub1.tld2 by NSDNAME
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver addr 12.12.12.12 a4-2.subsub.sub2.tld2 # 6 walled garden for *.sub2.tld2
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver nochange a3-2.tld2. # 7 exempt rewrite by name
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver nochange a0-1.tld2. # 8 exempt rewrite by address block
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver addr 12.12.12.12 a4-1.tld2 # 9 prefer QNAME policy to NSDNAME
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver addr 127.0.0.1 a3-1.sub3.tld2 # 10 prefer policy for largest NSDNAME
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver nxdomain xxx.crash1.tld2 # 12 dns_db_detachnode() crash
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt echo "I:NSDNAME not checked; named configured with --disable-rpz-nsdname"
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt # these tests assume "min-ns-dots 0"
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver nochange a3-2.tld2. # 2 exempt rewrite by name
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver nochange a0-1.tld2. # 3 exempt rewrite by address block
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver nochange a3-1.tld4 # 4 different NS IP address
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt addr 41.41.41.41 a3-1.tld2 # 1 walled garden for all of tld2
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt addr 2041::41 'a3-1.tld2 AAAA' # 2 walled garden for all of tld2
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt here a3-1.tld2 TXT <<'EOF' # 3 text message for all of tld2
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt echo "I:NSIP not checked; named configured with --disable-rpz-nsip"
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver# policies in ./test5 overridden by response-policy{} in ns3/named.conf
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryvernochange a3-3.tld2 # 3 bl-no-op obsolete for passthru
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Huntnodata a3-5.tld2 # 5 bl-nodata zone recursive-only no
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Huntnodata a3-5.tld2 +norecurse # 6 bl-nodata zone recursive-only no
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Huntnxdomain a3-5.tld2 +norecurse @$ns5 # 8 bl-nodata global recursive-only no
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Huntnxdomain a3-5.tld2s @$ns5 # 9 bl-nodata global break-dnssec
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Huntnxdomain a3-5.tld2s +dnssec @$ns5 # 10 bl-nodata global break-dnssec
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryveraddr 59.59.59.59 a3-9.sub9.tld2 # 14 bl_wildcname
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryveraddr 12.12.12.12 a3-15.tld2 # 15 bl-garden via CNAME to a12.tld2
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryveraddr 127.0.0.16 a3-16.tld2 100 # 16 bl max-policy-ttl 100
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryveraddr 17.17.17.17 "a3-17.tld2 @$ns5" 90 # 17 ns5 bl max-policy-ttl 90
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryver# check that miscellaneous bugs are still absent
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt# This is not a bug, because any data leaked by writing 24.4.3.2.10.rpz-ip
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt# (or whatever) is available by publishing "foo A 10.2.3.4" and then
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt# resolving foo.
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver# superficial test for major performance bugs
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryverif test -n "$QPERF"; then
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt $QPERF -c -1 -l30 -d ns5/requests -s $ns5 -p 5300 >/dev/null
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt $QPERF -c -1 -l30 -d ns5/requests -s $ns5 -p 5300 >$PFILE
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt X=`sed -n -e 's/.*Returned *\([^ ]*:\) *\([0-9]*\) .*/\1\2/p' $PFILE \
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver sed -n -e 's/.*Queries per second: *\([0-9]*\).*/\1/p' ns5/$1.perf
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt # get qps with rpz
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt # turn off rpz and measure qps again
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt PERCENT=`expr \( "$RPZ" \* 100 + \( $NORPZ / 2 \) \) / $NORPZ`
421d4a06479e61fbdc35087f3c4abc9fe65ad72aEvan Hunt echo "I:$RPZ qps with RPZ is $PERCENT% of $NORPZ qps without RPZ"
86a85a3bbd3d4580982b2c02d9b4837bc6c2fae5Mark Andrews echo "I:$RPZ qps with rpz or $PERCENT% is below $MIN_PERCENT% of $NORPZ qps"
86a85a3bbd3d4580982b2c02d9b4837bc6c2fae5Mark Andrews echo "I:$RPZ qps with RPZ or $PERCENT% of $NORPZ qps without RPZ is too high"
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver echo "I:performance not checked; queryperf not available"
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver# restart the main test RPZ server to see if that creates a core file
9fee08f655527a5dd849b171daeeee1dbbccca76Vernon Schryverif test -z "$HAVE_CORE"; then
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63Vernon Schryver test -z "$HAVE_CORE" || setret "I:found $HAVE_CORE; memory leak?"
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt# look for complaints from lib/dns/rpz.c and bin/name/query.c
94315060c2b0d9deafabe72d6a0482405fd9d377Evan HuntEMSGS=`egrep -l 'invalid rpz|rpz.*failed' ns*/named.run`
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Huntif test -n "$EMSGS"; then
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt setret "I:error messages in $EMSGS starting with:"
94315060c2b0d9deafabe72d6a0482405fd9d377Evan Hunt egrep 'invalid rpz|rpz.*failed' ns*/named.run | sed -e '10,$d' -e 's/^/I: /'
225146b2c8c7de8dcff979841b56b15aef8aded2Mark Andrewsecho "I:checking that ttl values are not zeroed when qtype is '*'"
225146b2c8c7de8dcff979841b56b15aef8aded2Mark Andrews$DIG +noall +answer -p 5300 @$ns3 any a3-2.tld2 > dig.out.any
225146b2c8c7de8dcff979841b56b15aef8aded2Mark Andrewsttl=`awk '/a3-2 tld2 text/ {print $2}' dig.out.any`
225146b2c8c7de8dcff979841b56b15aef8aded2Mark Andrewsif test ${ttl:=0} -eq 0; then setret I:failed; fi
06e0d6bb126e9986f29036e671b59f48b1d2efbcEvan Huntecho "I:checking rpz updates/transfers with parent nodes added after children"
06e0d6bb126e9986f29036e671b59f48b1d2efbcEvan Hunt# regression test for RT #36272: the success condition
06e0d6bb126e9986f29036e671b59f48b1d2efbcEvan Hunt# is the slave server not crashing.
48789995c1d85ababbf488bf24198adba466bb87Mark Andrews $NSUPDATE -p 5300 << EOF
06e0d6bb126e9986f29036e671b59f48b1d2efbcEvan Huntupdate $2 $3 IN CNAME .
06e0d6bb126e9986f29036e671b59f48b1d2efbcEvan Huntupdate $2 $4 IN CNAME .
06e0d6bb126e9986f29036e671b59f48b1d2efbcEvan Hunt nsd $ns5 add example.com.policy1. '*.example.com.policy1.'
06e0d6bb126e9986f29036e671b59f48b1d2efbcEvan Hunt nsd $ns5 delete example.com.policy1. '*.example.com.policy1.'
06e0d6bb126e9986f29036e671b59f48b1d2efbcEvan Hunt nsd $ns5 add '*.example.com.policy1.' example.com.policy1.
06e0d6bb126e9986f29036e671b59f48b1d2efbcEvan Hunt nsd $ns5 delete '*.example.com.policy1.' example.com.policy1.
b947e1a521c6931f787d6d1b3604d5b138170c3dMukund Sivaramanecho "I:checking that going from a empty policy zone works"
ac5ed748602c890d596bed07b0b23b8b5f42b2f6Mark Andrewsnsd $ns5 add '*.x.servfail.policy2.' x.servfail.policy2.
ac5ed748602c890d596bed07b0b23b8b5f42b2f6Mark Andrewsgrep NXDOMAIN dig.out.ns7 > /dev/null || setret I:failed;
9b789c54f8829b867c4a888c47bd2310a790415aEvan Huntecho "I:checking rpz with delegation fails correctly"
9b789c54f8829b867c4a888c47bd2310a790415aEvan Hunt$DIG -p 5300 @$ns3 ns example.com > dig.out.delegation
9b789c54f8829b867c4a888c47bd2310a790415aEvan Huntgrep "status: SERVFAIL" dig.out.delegation > /dev/null || setret "I:failed"
87708bde16713bc02ff2598f4a82f98c699a2f2dMark Andrewsecho "I:exit status: $status"