xref: /netbsd-src/external/mpl/bind/dist/bin/tests/system/views/tests.sh (revision a04395531661c5e8d314125d5ae77d4cbedd5d73)
1#!/bin/sh
2#
3# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
4#
5# This Source Code Form is subject to the terms of the Mozilla Public
6# License, v. 2.0. If a copy of the MPL was not distributed with this
7# file, you can obtain one at https://mozilla.org/MPL/2.0/.
8#
9# See the COPYRIGHT file distributed with this work for additional
10# information regarding copyright ownership.
11
12set -e
13
14SYSTEMTESTTOP=..
15# shellcheck source=conf.sh
16. $SYSTEMTESTTOP/conf.sh
17
18dig_with_opts() {
19	"$DIG" +tcp +noadd +nosea +nostat +noquest +nocomm +nocmd +noauth -p "${PORT}" "$@"
20}
21
22dig_with_shortopts() {
23	"$DIG" +tcp +short -p "${PORT}" "$@"
24}
25
26RNDCCMD="$RNDC -c $SYSTEMTESTTOP/common/rndc.conf -p ${CONTROLPORT} -s"
27
28status=0
29
30echo_i "fetching a.example from ns2's initial configuration"
31dig_with_opts a.example. @10.53.0.2 any > dig.out.ns2.1 || status=1
32
33echo_i "fetching a.example from ns3's initial configuration"
34dig_with_opts a.example. @10.53.0.3 any > dig.out.ns3.1 || status=1
35
36echo_i "copying in new configurations for ns2 and ns3"
37rm -f ns2/named.conf ns3/named.conf ns2/example.db
38cp -f ns2/example2.db ns2/example.db
39copy_setports ns2/named2.conf.in ns2/named.conf
40copy_setports ns3/named2.conf.in ns3/named.conf
41
42echo_i "reloading ns2 and ns3 with rndc"
43nextpart ns2/named.run > /dev/null
44nextpart ns3/named.run > /dev/null
45rndc_reload ns2 10.53.0.2
46rndc_reload ns3 10.53.0.3
47
48echo_i "wait for reload to complete"
49ret=0
50_check_reload() (
51  nextpartpeek ns2/named.run | grep "all zones loaded" > /dev/null && \
52  nextpartpeek ns3/named.run | grep "all zones loaded" > /dev/null && \
53  nextpartpeek ns3/named.run | grep "zone_dump: zone example/IN: enter" > /dev/null
54)
55retry_quiet 10 _check_reload || ret=1
56if [ $ret != 0 ]; then echo_i "failed"; fi
57status=$((status + ret))
58
59echo_i "fetching a.example from ns2's 10.53.0.4, source address 10.53.0.4"
60dig_with_opts -b 10.53.0.4 a.example. @10.53.0.4 any > dig.out.ns4.2 || status=1
61
62echo_i "fetching a.example from ns2's 10.53.0.2, source address 10.53.0.2"
63dig_with_opts -b 10.53.0.2 a.example. @10.53.0.2 any > dig.out.ns2.2 || status=1
64
65echo_i "fetching a.example from ns3's 10.53.0.3, source address defaulted"
66dig_with_opts @10.53.0.3 a.example. any > dig.out.ns3.2 || status=1
67
68echo_i "comparing ns3's initial a.example to one from reconfigured 10.53.0.2"
69digcomp dig.out.ns3.1 dig.out.ns2.2 || status=1
70
71echo_i "comparing ns3's initial a.example to one from reconfigured 10.53.0.3"
72digcomp dig.out.ns3.1 dig.out.ns3.2 || status=1
73
74echo_i "comparing ns2's initial a.example to one from reconfigured 10.53.0.4"
75digcomp dig.out.ns2.1 dig.out.ns4.2 || status=1
76
77echo_i "comparing ns2's initial a.example to one from reconfigured 10.53.0.3"
78echo_i "(should be different)"
79if $PERL ../digcomp.pl dig.out.ns2.1 dig.out.ns3.2 >/dev/null
80then
81	echo_i "no differences found.  something's wrong."
82	status=1
83fi
84
85echo_i "updating cloned zone in internal view"
86$NSUPDATE << EOF
87server 10.53.0.2 ${PORT}
88zone clone
89update add b.clone. 300 in a 10.1.0.3
90send
91EOF
92echo_i "sleeping to allow update to take effect"
93sleep 5
94
95echo_i "verifying update affected both views"
96ret=0
97one=$(dig_with_shortopts -b 10.53.0.2 @10.53.0.2 b.clone a)
98two=$(dig_with_shortopts -b 10.53.0.4 @10.53.0.2 b.clone a)
99if [ "$one" != "$two" ]; then
100        echo_i "'$one' does not match '$two'"
101        ret=1
102fi
103if [ $ret != 0 ]; then echo_i "failed"; fi
104status=$((status + ret))
105
106echo_i "verifying forwarder in cloned zone works"
107ret=0
108one=$(dig_with_shortopts -b 10.53.0.2 @10.53.0.2 child.clone txt)
109two=$(dig_with_shortopts -b 10.53.0.4 @10.53.0.2 child.clone txt)
110three=$(dig_with_shortopts @10.53.0.3 child.clone txt)
111four=$(dig_with_shortopts @10.53.0.5 child.clone txt)
112echo "$three" | grep NS3 > /dev/null || { ret=1; echo_i "expected response from NS3 got '$three'"; }
113echo "$four" | grep NS5 > /dev/null || { ret=1; echo_i "expected response from NS5 got '$four'"; }
114if [ "$one" = "$two" ]; then
115        echo_i "'$one' matches '$two'"
116        ret=1
117fi
118if [ "$one" != "$three" ]; then
119        echo_i "'$one' does not match '$three'"
120        ret=1
121fi
122if [ "$two" != "$four" ]; then
123        echo_i "'$two' does not match '$four'"
124        ret=1
125fi
126if [ $ret != 0 ]; then echo_i "failed"; fi
127status=$((status + ret))
128
129echo_i "verifying inline zones work with views"
130ret=0
131wait_for_signed() {
132    "$DIG" -p "${PORT}" @10.53.0.2 -b 10.53.0.2 +dnssec DNSKEY inline > dig.out.internal
133    "$DIG" -p "${PORT}" @10.53.0.2 -b 10.53.0.5 +dnssec DNSKEY inline > dig.out.external
134    grep "ANSWER: 4," dig.out.internal > /dev/null || return 1
135    grep "ANSWER: 4," dig.out.external > /dev/null || return 1
136    return 0
137}
138retry_quiet 10 wait_for_signed || ret=1
139int=$(awk '$4 == "DNSKEY" { print $8 }' dig.out.internal | sort)
140ext=$(awk '$4 == "DNSKEY" { print $8 }' dig.out.external | sort)
141test "$int" != "$ext" || ret=1
142if [ $ret != 0 ]; then echo_i "failed"; fi
143status=$((status + ret))
144
145echo_i "verifying adding of multiple inline zones followed by reconfiguration works"
146
147[ ! -f ns2/zones.conf ] && touch ns2/zones.conf
148copy_setports ns2/named3.conf.in ns2/named.conf
149
150i=1
151while [ $i -lt 50 ]; do
152	ret=0
153	zone_name=$(printf "example%03d.com" $i)
154
155	# Add a new zone to the configuration.
156	cat >> ns2/zones.conf <<-EOF
157	zone "${zone_name}" {
158	    type master;
159	    file "db.${zone_name}";
160	    dnssec-dnskey-kskonly yes;
161	    auto-dnssec maintain;
162	    inline-signing yes;
163	};
164	EOF
165
166	# Create a master file for the zone.
167	cat > "ns2/db.${zone_name}" <<-EOF
168	\$TTL 86400
169	@		IN	SOA	localhost. hostmaster.localhost (
170						1612542642 ; serial
171						12H ; refresh
172						1H  ; retry
173						2w  ; expiry
174						1h  ; minimum
175					)
176	@		IN      NS      localhost
177	localhost       IN      A       127.0.0.1
178	EOF
179
180	$KEYGEN -q -Kns2 -fk -aecdsa256 "${zone_name}" > /dev/null
181	$RNDCCMD 10.53.0.2 reconfig || ret=1
182	if [ $ret != 0 ]; then echo_i "failed"; break; fi
183	i=$((i + 1))
184done
185status=$((status + ret))
186
187echo_i "exit status: $status"
188[ "$status" -eq 0 ] || exit 1
189