xref: /netbsd-src/external/bsd/nsd/dist/doc/TODO (revision e2d5644acf1561cc97b6a8c8d51fddf773bb3a81)
1$Id: TODO,v 1.2 2022/09/24 17:38:17 christos Exp $
2
3AUTOCONF
4- check/translate arguments to --with-facility
5
6ZONE COMPILER
7- unify dns type table (name, dns type, yacc token, rdata types) prettier?
8- unify dns class table (name, dns type, yacc token) prettier?
9- one db file per zone (as an option?) (featurecreep)?
10  req by Alex (Bit). So that after rsync, zonec is fast with many zones.
11- if a zone is dropped from the config file, but not removed from the
12  nsd.db. NSD refuses to start. Should skip/drop the zone.
13  Redesign file format, so that you can skip a zone more easily, this
14  also makes multiply db files easier.
15- profile the zonec compiling speed. Speed it up. Many people complain about
16  this.
17- wireformat interop. testing for IPSECKEY type.
18- chown nsd nsd.db (Paul Wouters nsd-users mail)
19
20SERVER
21- make sure that we dont copy anything from the query we dont want to copy, like
22  funny headers etc
23- From Aaron Hopkins: set O_NONBLOCK on all sockets. Now a udp raging herd of
24  server can get woken up when a message arrives. One server handles the packet,
25  the rest blocks on that socket and does not serve other sockets.
26- From Aaron Hopkins: write tcp length and tcp data in one write operation,
27  instead of multiple calls to write. Avoids Nagle algo delay in this case.
28  preallocate 2 bytes in front of buffer to put them into.
29- Test TCP performance (do a lot of AXFRs, different zone sizes, and compare
30  time averages).
31- From Aaron Hopkins: after you do select calls, do multiple read calls
32  per select. This polling improves performance in high-load situations.
33  Speed test to prove that it does so.
34- Turn off TC bit on all error replies.
35- Bug #133: print empty statistic blocks. Not sure if the feature is wanted.
36- XFRD should throttle the number of notifys going out for a zone to
37  x/minute. (even if updates are very often).
38- Option to only notify a batch of slaves (from loads) at a time, with
39  timeout between.
40- Round robin selection to send notify to secondaries. So the last one
41  on the notify list does not diverge.
42- xfrd NOTIFY timeouts exponential backoff.
43- query SOA before getting AXFR and then cutting it off, it causes an errlog
44  on the master.
45- when verbose, print the ip addresses that cause network errors to the log.
46- the server reaps children every minute, this is bad for powersaving laptops.
47- Implement AXFR clarify, RFC 5936.
48
49SECURITY
50
51PURITY
52- some data is in network order some in host order, make it clear with prefixes
53  prettier?
54- brush up the function and identifiers names
55- The XFRD zone state can be split up in expired/service-possible and
56  in idle/zone-transfer-busy state flags. Is this more beautiful?
57- no more #ifdefs, remove them all, but keep configure options.
58- getflags on socket before setflags nonblocking.
59- exponential backoff for retries xfrd and notify.
60- conformance to RFC: NSD accepts TSIG before OPT in additional, but this
61  is not legal, only TSIG after OPT is allowed.
62- Allow for username: uid:gid, next to uid.gid.
63- Log error when serial in xfrd.state is inconsistent with that from nsd.db.
64
65NSD PATCH
66- -q(?) option: no output when no patch necessary
67- cleaner output on normal operation (don't mention memory)
68- patch on demand after a xfrd reload has occurred (including checks for disk
69  memory and a reload timeout (no more often than 15 minutes or so)?).
70
71CLEANUP
72- make so that startup sends SOA_INFO to xfrd just like reload does, prettier?
73- dlopen and dynlib checks can be removed from autoconf scripts.
74- If presentation format NSEC3 stays, put optout-iterations into one 4byte
75  datatype, easier reading and printing, avoids ugly special cases.
76
77DOCUMENTATION
78- document what to do when adding (or removing) a config option (what
79  changes have to be made in the code).
80
81OPTIMISATIONS
82- delete entire zone for AFXR during reload read in,
83  now walks the tree, but could use a double linked list to speed up.
84- less memory churn in deleting RRs/adding RRs: keep rrset->capacity num.
85  initial read in capacity==limit, if you want to add RRs, alloc capacity*2.
86- less memory churn in deleting rrsets : keep a linked list of deleted rrsets
87  for reuse.
88  Keep a list (based on buckets of size of the malloc) of rr arrays.
89  Keep a list (based on buckets of size of malloc) of rdata arrays.
90  Keep a list (buckets on size) of rdata_data allocs.
91  For reuse, buckets on char size, because we know most are small anyway
92  large ones can be discarded/churned.
93- Look for special purpose memory allocators for NSD.
94- compress dnames in ixfr queries (write_soa_buffer) (zone 2x, mname, rname).
95  small gain, nasty code.
96- compress dnames in tsig records, keyname, algorithmname.
97- compress names in packets by pointing to uncompressed_dname entries.
98  After each DNAME(with uncompressed target) follows a CNAME that can be
99  compressed in this way.
100- Do not give servfail during reload quit sync process. Only stop old
101  server processes once the new ones are forked and answering for secondary
102  zones (so when xfrd is done with sending zone state to all children).
103  The brief double answers are preferable to brief SERVFAIL.
104- nsd manual programs contain identical functions that are written down multiple
105  times. Do we need to introduce a util_programs.c or something?
106- reduce the memory leak on zone transfers (deleted domains are not removed from
107  tree).
108- Options server: ip-address: and zone: outgoing-interface are pretty much the same.
109- Options to make NSD restrict AXFR response messages to a single RR (RFC5936)
110
111TESTS
112- tpkg test for bug 157: a valid NSID EDNS0 option generates FORMERR on
113	nsd-3.0.5
114- tpkg test for bug 163: unable to read nsd.db when chroot'ed
115- tpkg test for bug 164: chkconfig
116- Update tpkg long tests
117- tpkg test for bug 347: NSEC3 no data tests when requesting DS
118From tpkg/bugzilla-bugs todo:
119!  - other ways to test this?
120! 3   "RCODE for dynamic updates" --- how to send dynamic updates?
121! 20   "256 questions per-se should generate form err"
122! 22   "trailing byte in queries (see also bug4)" ALLOW TESTING WITH TRACES
123! 31   "query section not included in 'NotImp' answers to updates"
124! 37   "invalid packet echoed on FormErr" - how to send stuff with tcp replay
125! 100   "zonec alters RRSIG inception/expiration" on sparc only --- hmmmm
126! 29   "NSD sends answer on notify"  - cannot send notify with DIG
127M  - Moet nog
128M 157   "return FORMERR if edns query is received with version=0 and rdlen>0"
129M 163   "..."
130M 164   "chkconfig"
131-  - too little information to write a testcase
132- 4   "Correctly handle queries with too much data"  to little info
133- 6   "different name encodings?"
134- 7   "sometimes label compression skip some parts"
135- 8   "do not exit on sendto buffer exhaustion"
136- 10   "Segmentation violation while trying to destroy the database on exit"
137- 11   "EDNS(0) spurious formerr"
138- 14   "Magic string alignment"
139- 15   "nsd hangs on some queries..."
140- 16   "zonec dumps core with HASH -z nl nl -c . examples/zones/root"
141- 18   "name compression not quite 100% yet"
142- 28   "Wrong additional section RRcount in case of EDNS."
143- 35   "sending wrong name errors (NXDOMAIN)"
144- 36   "we should not bounce on RR Type when doing a referral"
145
146