[Pkg-freeipa-devel] [Git][freeipa-team/bind-dyndb-ldap][upstream] 27 commits: Modify empty zone conflicts under exclusive mode

Timo Aaltonen (@tjaalton) gitlab at salsa.debian.org
Mon Sep 28 14:34:36 BST 2026



Timo Aaltonen pushed to branch upstream at FreeIPA packaging / bind-dyndb-ldap


Commits:
7b4c1e28 by Petr Menšík at 2022-09-14T17:23:20+02:00
Modify empty zone conflicts under exclusive mode

Does not accept new request when exclusive mode is active. Zone table
can be modified even after main fwd entries have been added. Ensure
empty zones handling keeps exclusive mode active.

Exclusive mode were mentioned as the only protection it had by bind
maintainer:
https://gitlab.isc.org/isc-projects/bind9/-/merge_requests/6637#note_308928

- - - - -
5dd2fefa by Alexander Bokovoy at 2023-01-16T11:08:25+02:00
Support bind 9.18.10 or later

dns_db_allrdatasets() gained a new parameter. Adopt the code to allow
injecting 0 options if building against 9.18.10.

Fixes: https://pagure.io/bind-dyndb-ldap/issue/216

Signed-off-by: Alexander Bokovoy <abokovoy at redhat.com>

- - - - -
dc3a202a by Alexander Bokovoy at 2023-01-16T11:08:25+02:00
Fix broken bind 9.18.10 build

bind 9.18.10 added use of isrwlock in dns/zt.h but did not include
isc/rwlock.h

Fixes: https://pagure.io/bind-dyndb-ldap/issues/216

Signed-off-by: Alexander Bokovoy <abokovoy at redhat.com>

- - - - -
00131b7b by Alexander Bokovoy at 2023-01-16T12:34:49+02:00
adopt to bind 9.18.9+ loggers

Fixes: https://pagure.io/bind-dyndb-ldap/issues/216

Signed-off-by: Alexander Bokovoy <abokovoy at redhat.com>

- - - - -
47902df2 by Alexander Bokovoy at 2023-01-16T12:34:49+02:00
Handle dns_db_allrdatasets() backports too

With https://gitlab.isc.org/isc-projects/bind9/-/merge_requests/7189 the
changes were also backported to 9.16.36+ as well. Instead of checking
version, check if an additional define is present.

Signed-off-by: Alexander Bokovoy <abokovoy at redhat.com>

- - - - -
f435a334 by Petr Menšík at 2023-01-28T11:37:13+01:00
Minimal change to compile with BIND 9.18.11

DSCP codes are not working and their support were removed from BIND9. Do
not require them to be present.

- - - - -
5f37344d by Timo Aaltonen at 2023-03-20T11:23:41+02:00
Fix building against bind 9.18.13

db_registered got dropped from dns_rpc_zone.

Signed-off-by: Timo Aaltonen <tjaalton at debian.org>

- - - - -
1be57227 by Petr Menšík at 2023-03-22T15:14:45+01:00
Remove rpz_attach for BIND 9.16+

rpz_attach is never supplied from BIND9 code both in 9.16 or 9.18.
Remove our custom function and pass NULL as well. It would be never
called anyway.

Effectivery reverts most of previous commit.

- - - - -
131ddb91 by Petr Menšík at 2023-09-25T12:33:42+02:00
Detect and propagate atomic libraries like bind9

BIND9 headers expect atomic definitions are configured before they are
included. It needs adding atomic libraries detection in configure AND
including config.h before any ISC headers are included.

Move dyndb-config.h before isc headers anywhere where needed.

- - - - -
4435fec5 by Rafael Guterres Jeffman at 2023-09-26T08:58:37+00:00
Migrated to SPDX license

Signed-off-by: Rafael Guterres Jeffman <rjeffman at redhat.com>

- - - - -
dbbcc2f0 by Alexander Bokovoy at 2024-02-14T14:31:22+02:00
use BIND macros when defining DNS names

Fixes: https://pagure.io/bind-dyndb-ldap/issue/228

Signed-off-by: Alexander Bokovoy <abokovoy at redhat.com>

- - - - -
628db201 by Alexander Bokovoy at 2024-02-14T15:45:57+02:00
Include dydnb-config.h prior to any BIND headers

Signed-off-by: Alexander Bokovoy <abokovoy at redhat.com>

- - - - -
c7027ee2 by Stanislav Levin at 2024-03-25T20:02:36+03:00
Try to detect dns_db_settask signature at configure time

dns_db_settask's signature was changed as of bind 9.16.49 / 9.18.25 / 9.19.22
like:

before: dns_db_settask(dns_db_t *db, isc_task_t *task);
after:  dns_db_settask(dns_db_t *db, isc_task_t *task, isc_task_t *prunetask);

Fixes: https://pagure.io/bind-dyndb-ldap/issue/230
Signed-off-by: Stanislav Levin <slev at altlinux.org>

- - - - -
ff4948f7 by Petr Menšík at 2024-07-31T18:21:52+02:00
Support for bind 9.18.28

New CVEs introduced new database interface change. Do just minimal
change to allow fast rebuild of plugin.

Fixes #233.

- - - - -
33a671eb by Petr Menšík at 2024-08-07T16:19:46+02:00
Detect presence of dns_zone_setmaxrrperset

Because it were backported into bind-9.16 branch by upstream and testing
of simpler variant fails in some cases. This assumes these call do not
appear only after 9.18.28, but may be backported into previous versions.
Tests just call presence and assumes dns_db_setmaxtypepername will be
present also.

- - - - -
75b13ab3 by Alexander Bokovoy at 2025-01-22T11:26:31+02:00
Release v11.11 to support bind 9.18

Signed-off-by: Alexander Bokovoy <abokovoy at redhat.com>

- - - - -
1c31d25d by Stanislav Levin at 2025-12-18T12:29:26+03:00
Support build against bind 9.18.43

bind 9.18.43 introduced their version of CHECK macro:
https://gitlab.isc.org/isc-projects/bind9/-/merge_requests/11080

which is different from the local one. Prefer the latter because
it provides additional logging feature.

Fixes: https://pagure.io/bind-dyndb-ldap/issue/243
Signed-off-by: Stanislav Levin <slev at altlinux.org>

- - - - -
863c6927 by Alexander Bokovoy at 2026-01-07T16:08:40+02:00
bind-dyndb-ldap v12.0: relicense to MPL v2.0

Fixes: https://pagure.io/bind-dyndb-ldap/issue/225

Signed-off-by: Alexander Bokovoy <abokovoy at redhat.com>

- - - - -
3cce9371 by Alexander Bokovoy at 2026-01-07T16:50:16+02:00
Update autoconf infra to use autotools 2.72

Signed-off-by: Alexander Bokovoy <abokovoy at redhat.com>

- - - - -
68c13526 by Antonio Torres at 2026-04-28T14:26:04+02:00
Rewrite the plugin to support BIND 9.20

This rewrite completely changes file structure and design of the plugin,
as well the BIND functions used, in order to support BIND 9.20. Both
synchronization from BIND to LDAP and the other way around have been
implemented. The design has been renovated to use the new async API from
BIND.

Signed-off-by: Antonio Torres <antorres at redhat.com>

- - - - -
7857d766 by Antonio Torres at 2026-04-28T14:26:11+02:00
Adapt async code for BIND 9.20

BIND 9.20 removed isc_task_t and isc_event_t, which means all of the
usages during the async-related code must be replaced. This change
reenables code previously disabled for the rewrite, but adapts it to the
new architecture, while removing dead code and unneeded functions.

Co-Authored-By: Claude Opus 4.6 <noreply at anthropic.com>
Signed-off-by: Antonio Torres <antorres at redhat.com>

- - - - -
e2d93559 by Antonio Torres at 2026-04-28T14:26:11+02:00
Setup KASP for DNSSEC compatibility in BIND 9.20

In BIND 9.20, the zone_rekey() function was refactored to always
require a KASP (Key and Signing Policy) object for CDS/CDNSKEY
record management. When zone->kasp is NULL, zone_rekey() falls
back to zone->defaultkasp and unconditionally calls
dns_kasp_digests(zone->defaultkasp). Since dyndb-created zones
never had a KASP attached, this results in a REQUIRE assertion
failure and named crashes during zone maintenance:

  REQUIRE(((kasp) != ((void *)0) && ...)) failed
  dns_kasp_digests -> zone_rekey -> zone_maintenance

In BIND 9.18, zone_rekey() managed keys purely from key files on
disk without needing a KASP object. The legacy auto-dnssec flags
(DNS_ZONEKEY_ALLOW, DNS_ZONEKEY_MAINTAIN) were sufficient.

Fix this by creating a KASP policy matching BIND's built-in
"default" dnssec-policy (ECDSAP256SHA256 CSK, SHA-256 CDS digest,
standard signing parameters) and attaching it to each inline-signed
zone via dns_zone_setdefaultkasp() before dns_zone_rekey() is called.

The KASP defaults are taken from BIND 9.20's bin/named/config.c
built-in "default" dnssec-policy definition.

Co-Authored-By: Claude Opus 4.6 <noreply at anthropic.com>
Signed-off-by: Antonio Torres <antorres at redhat.com>

- - - - -
75c634ec by Antonio Torres at 2026-04-28T14:26:11+02:00
Add proper replacement for dns_rbt_*name functions

dns_rbt_findname, dns_rbt_addname and dns_rbt_deletename were removed in
BIND 9.20. Previously we replaced these functions with their
dns_rbt_*node counterparts, but this doesn't behave the same because the
original functions had checks in place for the different results coming
from these functions. Add wrappers around them to mimic the behaviour of
the old functions.

Co-Authored-By: Claude Opus 4.6 <noreply at anthropic.com>
Signed-off-by: Antonio Torres <antorres at redhat.com>

- - - - -
89b5e6e6 by Antonio Torres at 2026-04-28T14:26:11+02:00
Properly shutdown BIND process

Backport code from old BIND 9.18 to properly handle termination of the
worker thread.

Ensure that all memory is freed before process termination, using
existing functions for it.

Co-Authored-By: Claude Opus 4.6 <noreply at anthropic.com>
Signed-off-by: Antonio Torres <antorres at redhat.com>

- - - - -
cc93cf47 by Antonio Torres at 2026-04-28T14:26:11+02:00
Fix crash when enqueing task from worker thread

Newest minor version of BIND 9.20, 9.20.22, adds an additional check to
ensure that isc_work_enqueue is only called from the thread owning the
main loop. Add an additional function that runs isc_work_enqueue from
the loop thread, and make bdl_sync_dyndb_ldap_send thread-safe by
enqueing work with isc_async_run calling this new function.

Co-Authored-By: Claude Opus 4.6 <noreply at anthropic.com>
Signed-off-by: Antonio Torres <antorres at redhat.com>

- - - - -
0a938892 by Antonio Torres at 2026-04-28T14:26:11+02:00
Avoid syncrepl race when using nsupdate

When using nsupdate to modify N records, each call dispatched a separate
LDAP add operation to the worker thread. Each write would trigger a
syncrepl notification, carrying an intermediate LDAP state.

Fix this by having the worker read the current RBTDB state and send a
single LDAP_MOD_REPLACE with all values instead of doing it
individually. Since nsupdate writes synchronously on the loop thread
before the workers, every worker sees the complete final state, avoiding
intermediate states.

This wasn't needed in BIND 9.18 since the adds were sent to the zone
task, which would block on every add, meaning only the last syncrepl
event was heard, which carried the final state.

On BIND 9.20, nsupdate writebacks are not executed synchronously,
instead they're sent to workers. This means that a window is created
where a possible stale syncrepl event, queued before the nsupdate call,
can overwrite the rbtdb with old LDAP data, which then the workers would
read and persist it to LDAP, making the wrong state permanent. This is
fixed by tracking in-flight workers with an atomic counter, and skipping
syncrepl processing if this counter is not zero. Once all workers
complete their LDAP writes, syncrepl updates with these new changes are
received and processed normally (but since the LDAP data received
matches the rbtdb, it makes an empty diff, so it would be a no-op).

Co-Authored-By: Claude Opus 4.6 <noreply at anthropic.com>
Signed-off-by: Antonio Torres <antorres at redhat.com>

- - - - -
fabee202 by Antonio Torres at 2026-04-28T14:26:11+02:00
Release v13.0

Supports BIND 9.20.

Signed-off-by: Antonio Torres <antorres at redhat.com>

- - - - -


150 changed files:

- + .clang-format
- + .forgejo/workflows/makefile.yml
- + .forgejo/workflows/pre-commit.yml
- .gitignore
- + .pre-commit-config.yaml
- − AUTHORS
- − COPYING
- + Doxyfile
- + LICENSE
- + Makefile
- − Makefile.am
- NEWS
- README.md
- + bind-dyndb-ldap.spec
- − configure.ac
- − contrib/bind-dyndb-ldap.spec
- − contrib/gdb_extensions/README
- − contrib/gdb_extensions/ldap_attribute.py
- − contrib/gdb_extensions/ldap_entry.py
- − contrib/gdb_extensions/ldap_valuelist.py
- − doc/Makefile.am
- − doc/example.ldif
- − doc/schema.ldif
- + docs/architecture.md
- + docs/bind-event-loops.md
- + docs/index.md
- − releng/README
- − releng/bumpver.py
- − releng/srcversion.py
- + src/Makefile
- − src/Makefile.am
- src/acl.c
- src/acl.h
- − src/bindcfg.c
- − src/bindcfg.h
- + src/driver.c
- + src/driver.h
- + src/driver_config.c
- + src/driver_config.h
- + src/dyndb/dyndb.c
- + src/dyndb/dyndb.h
- − src/empty_zones.c
- − src/empty_zones.h
- − src/fs.c
- − src/fs.h
- src/fwd.c
- src/fwd.h
- − src/fwd_register.c
- − src/fwd_register.h
- + src/krb5.c
- + src/krb5.h
- − src/krb5_helper.c
- − src/krb5_helper.h
- + src/ldap/ldap.c
- + src/ldap/ldap.h
- + src/ldap/ldap_convert.c
- + src/ldap/ldap_convert.h
- + src/ldap/ldap_driver.c
- + src/ldap/ldap_driver.h
- + src/ldap/ldap_entry.c
- + src/ldap/ldap_entry.h
- + src/ldap/metadb.c
- + src/ldap/metadb.h
- + src/ldap/mldap.c
- + src/ldap/mldap.h
- − src/ldap_convert.c
- − src/ldap_convert.h
- − src/ldap_driver.c
- − src/ldap_driver.h
- − src/ldap_entry.c
- − src/ldap_entry.h
- − src/ldap_helper.c
- − src/ldap_helper.h
- − src/lock.c
- − src/lock.h
- − src/log.c
- − src/log.h
- − src/metadb.c
- − src/metadb.h
- − src/mldap.c
- − src/mldap.h
- src/rbt_helper.c
- src/rbt_helper.h
- − src/semaphore.c
- − src/semaphore.h
- − src/settings.c
- − src/settings.h
- − src/str.c
- − src/str.h
- + src/sync/sync.h
- + src/sync/sync_dyndb_ldap.c
- + src/sync/sync_ldap_dyndb.c
- + src/sync/syncptr.c
- + src/sync/syncptr.h
- − src/syncptr.c
- − src/syncptr.h
- − src/syncrepl.c
- − src/syncrepl.h
- src/types.h
- − src/util.h
- + src/utils/fs.c
- + src/utils/fs.h
- + src/utils/log.c
- + src/utils/log.h
- + src/utils/settings.c
- + src/utils/settings.h
- + src/utils/str.c
- + src/utils/str.h
- + src/utils/util.h
- − src/zone.c
- − src/zone.h
- − src/zone_register.c
- − src/zone_register.h
- + src/zones/empty_zones.c
- + src/zones/empty_zones.h
- + src/zones/fwd_register.c
- + src/zones/fwd_register.h
- + src/zones/zone.c
- + src/zones/zone.h
- + src/zones/zone_register.c
- + src/zones/zone_register.h
- − tests/azure/Dockerfiles/Dockerfile.build.fedora
- − tests/azure/Dockerfiles/docker-compose.yml
- − tests/azure/Dockerfiles/seccomp.json
- − tests/azure/azure-pipelines.yml
- − tests/azure/azure_definitions/gating-fedora.yml
- − tests/azure/azure_definitions/gating.yml
- − tests/azure/scripts/azure-run-integration-tests.sh
- − tests/azure/scripts/azure-run-tests.sh
- − tests/azure/scripts/dump_cores.sh
- − tests/azure/scripts/generate-matrix.py
- − tests/azure/scripts/install-debuginfo-fedora.sh
- − tests/azure/scripts/install-debuginfo.sh
- − tests/azure/scripts/setup_containers.py
- − tests/azure/scripts/variables-fedora.sh
- − tests/azure/scripts/variables.sh
- − tests/azure/templates/build-fedora.yml
- − tests/azure/templates/generate-job-variables.yml
- − tests/azure/templates/generate-matrix.yml
- − tests/azure/templates/prepare-build-fedora.yml
- − tests/azure/templates/publish-build.yml
- − tests/azure/templates/run-test.yml
- − tests/azure/templates/save-test-artifacts.yml
- − tests/azure/templates/setup-test-environment.yml
- − tests/azure/templates/test-config-template.yaml
- − tests/azure/templates/test-jobs.yml
- − tests/azure/templates/variables-common.yml
- − tests/azure/templates/variables-fedora.yml
- − tests/azure/templates/variables.yml
- + tests/make-and-run.sh


The diff was not included because it is too large.


View it on GitLab: https://salsa.debian.org/freeipa-team/bind-dyndb-ldap/-/compare/f71746a059d31afd09867901cc79a9d75d07d331...fabee2026613b66e34090e4c5f2a0b4796ac75d9

-- 
View it on GitLab: https://salsa.debian.org/freeipa-team/bind-dyndb-ldap/-/compare/f71746a059d31afd09867901cc79a9d75d07d331...fabee2026613b66e34090e4c5f2a0b4796ac75d9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/pkg-freeipa-devel/attachments/20260928/a4efc18f/attachment-0001.htm>


More information about the Pkg-freeipa-devel mailing list