diff --git a/integration-tests/ixfr-out-incremental/policies/fast-incremental.toml b/integration-tests/ixfr-out-incremental/policies/fast-incremental.toml new file mode 100644 index 000000000..156a5cb1f --- /dev/null +++ b/integration-tests/ixfr-out-incremental/policies/fast-incremental.toml @@ -0,0 +1,25 @@ +# Setup incremental signing to produce predictable outputs so that we can +# easily compare the generated zone against expected output. +# +# Enable sending of NOTIFY messages to the NSD secondary. +version = "v1" + +[signer.denial] +type = "nsec" + +[signer] +serial-policy = "counter" +signature-inception-offset = 0 +signature-lifetime = 100 +signature-remain-time = 90 +signature-refresh-interval = 1 + +[key-manager.records] +dnskey.signature-inception-offset = 0 +cds.signature-inception-offset = 0 +dnskey.signature-lifetime = 10 +cds.signature-lifetime = 10 + +[server.outbound] +# NSD secondary listens on port 1054. +send-notify-to = ["127.0.0.1:1054"] diff --git a/integration-tests/ixfr-out-review/reference-output/loaded-review.ixfr-1-3 b/integration-tests/ixfr-out-review/reference-output/loaded-review.ixfr-1-3 new file mode 100644 index 000000000..fe72b7b79 --- /dev/null +++ b/integration-tests/ixfr-out-review/reference-output/loaded-review.ixfr-1-3 @@ -0,0 +1,11 @@ +example.test. 3600 IN SOA ns.example.test. mail.example.test. 3 60 60 3600 5 +example.test. 3600 IN SOA NS.example.test. mail.example.test. 1 60 60 3600 5 +NEZU.example.test. 3600 IN A 133.69.136.5 +example.test. 3600 IN SOA ns.example.test. mail.example.test. 2 60 60 3600 5 +JAIN-BB.example.test. 3600 IN A 133.69.136.4 +JAIN-BB.example.test. 3600 IN A 192.41.197.2 +example.test. 3600 IN SOA ns.example.test. mail.example.test. 2 60 60 3600 5 +JAIN-BB.example.test. 3600 IN A 133.69.136.4 +example.test. 3600 IN SOA ns.example.test. mail.example.test. 3 60 60 3600 5 +JAIN-BB.example.test. 3600 IN A 133.69.136.3 +example.test. 3600 IN SOA ns.example.test. mail.example.test. 3 60 60 3600 5 diff --git a/integration-tests/ixfr-out-review/reference-output/loaded-review.ixfr-2-3 b/integration-tests/ixfr-out-review/reference-output/loaded-review.ixfr-2-3 new file mode 100644 index 000000000..aa673c63b --- /dev/null +++ b/integration-tests/ixfr-out-review/reference-output/loaded-review.ixfr-2-3 @@ -0,0 +1,6 @@ +example.test. 3600 IN SOA ns.example.test. mail.example.test. 3 60 60 3600 5 +example.test. 3600 IN SOA ns.example.test. mail.example.test. 2 60 60 3600 5 +JAIN-BB.example.test. 3600 IN A 133.69.136.4 +example.test. 3600 IN SOA ns.example.test. mail.example.test. 3 60 60 3600 5 +JAIN-BB.example.test. 3600 IN A 133.69.136.3 +example.test. 3600 IN SOA ns.example.test. mail.example.test. 3 60 60 3600 5 diff --git a/integration-tests/ixfr-out-review/reference-output/loaded-review.ixfr-3-3 b/integration-tests/ixfr-out-review/reference-output/loaded-review.ixfr-3-3 new file mode 100644 index 000000000..ebe4c34bc --- /dev/null +++ b/integration-tests/ixfr-out-review/reference-output/loaded-review.ixfr-3-3 @@ -0,0 +1 @@ +example.test. 3600 IN SOA ns.example.test. mail.example.test. 3 60 60 3600 5 diff --git a/integration-tests/ixfr-out-review/reference-output/signed-review.ixfr-1-3 b/integration-tests/ixfr-out-review/reference-output/signed-review.ixfr-1-3 new file mode 100644 index 000000000..e9ec16609 --- /dev/null +++ b/integration-tests/ixfr-out-review/reference-output/signed-review.ixfr-1-3 @@ -0,0 +1,27 @@ +example.test. 3600 IN SOA ns.example.test. mail.example.test. 2026051202 60 60 3600 5 +example.test. 3600 IN SOA NS.example.test. mail.example.test. 2026051200 60 60 3600 5 +example.test. 3600 IN RRSIG SOA 15 2 3600 20200927122640 20200912122640 580 example.test. 0pT73Y+9z9QOkhX9UjRncbR6KyXgSqfxoCviwNhyN8BijAf3oJLVueZR zFNCkNkwg+goMKF9acAmRasdHmA/Dw== +example.test. 5 IN NSEC NEZU.example.test. NS SOA RRSIG NSEC DNSKEY +example.test. 5 IN RRSIG NSEC 15 2 5 20200927122640 20200912122640 580 example.test. ijL6SFOFQhPOfSQsTtV9I39aKWkJo6orbMXKcUQ6Woa/Ze+4q5oNK2R7 t8kgL8GTUySY3h3ljlA3SMp+zPjuBg== +NEZU.example.test. 3600 IN A 133.69.136.5 +NEZU.example.test. 3600 IN RRSIG A 15 3 3600 20200927122640 20200912122640 580 example.test. eP6CmrELzTgLGgki4TDyqAjNzl535SfnIVNYkjlXV/sDh9iJcNg9QCl8 Na8LR4HRM6RIEe3pw4aZCZg0SqCFDw== +NEZU.example.test. 5 IN NSEC NS.example.test. A RRSIG NSEC +NEZU.example.test. 5 IN RRSIG NSEC 15 3 5 20200927122640 20200912122640 580 example.test. moXs8yosAlQXN+OQborKKgMp0wBmPVN/9nM0lx61ZK2FTRdXSbRi349q CIuQ6bi2SmOD8pfmgSFRSVOiFTmPDg== +example.test. 3600 IN SOA ns.example.test. mail.example.test. 2026051201 60 60 3600 5 +example.test. 3600 IN RRSIG SOA 15 2 3600 20200927122640 20200912122640 580 example.test. h7+N8Sk54Vq/GBLi4TaoLkkjgfXpNHJJ+otwK/0twaKXcywWJEHQKVge R7kBOu89QcWJTY5yUYTdoVCPw7aOCg== +example.test. 5 IN NSEC JAIN-BB.example.test. NS SOA RRSIG NSEC DNSKEY +example.test. 5 IN RRSIG NSEC 15 2 5 20200927122640 20200912122640 580 example.test. XUPmDdnhSI7IFMQWMJPewxEN6dqhwj2b/Q/ah74BCvS5GCv4p5Tu2HlY lkDVRE93xZW4mdvb+P8CMcBPLDeBBQ== +JAIN-BB.example.test. 3600 IN A 133.69.136.4 +JAIN-BB.example.test. 3600 IN A 192.41.197.2 +JAIN-BB.example.test. 3600 IN RRSIG A 15 3 3600 20200927122640 20200912122640 580 example.test. SzU26WJGMDBev8rx6KcOrUreSX4hVp2jwbTKNWaHxvbzrdd0nDn52dw5 k1HTZsL2+aPuHBxGDYnUJYWlM1ZNDQ== +JAIN-BB.example.test. 5 IN NSEC NS.example.test. A RRSIG NSEC +JAIN-BB.example.test. 5 IN RRSIG NSEC 15 3 5 20200927122640 20200912122640 580 example.test. bjeFIBVSXyNxaGnWElV61PhoVo0/C7ztRmk/WLJ4R84tmBbIbSLN1bo0 1EkRvlbHJj/HNKHtUNZkGhDUe8SgAA== +example.test. 3600 IN SOA ns.example.test. mail.example.test. 2026051201 60 60 3600 5 +example.test. 3600 IN RRSIG SOA 15 2 3600 20200927122640 20200912122640 580 example.test. h7+N8Sk54Vq/GBLi4TaoLkkjgfXpNHJJ+otwK/0twaKXcywWJEHQKVge R7kBOu89QcWJTY5yUYTdoVCPw7aOCg== +JAIN-BB.example.test. 3600 IN A 133.69.136.4 +JAIN-BB.example.test. 3600 IN RRSIG A 15 3 3600 20200927122640 20200912122640 580 example.test. SzU26WJGMDBev8rx6KcOrUreSX4hVp2jwbTKNWaHxvbzrdd0nDn52dw5 k1HTZsL2+aPuHBxGDYnUJYWlM1ZNDQ== +example.test. 3600 IN SOA ns.example.test. mail.example.test. 2026051202 60 60 3600 5 +example.test. 3600 IN RRSIG SOA 15 2 3600 20200927122640 20200912122640 580 example.test. lw2qqnFjRO9k0FmtLHgcJPvzLPQidUMUW8Cx7l03eA6SxVVvfBr3nn5w sIfP4yw09HvKazQl10Xc47SfJNMKCw== +JAIN-BB.example.test. 3600 IN A 133.69.136.3 +JAIN-BB.example.test. 3600 IN RRSIG A 15 3 3600 20200927122640 20200912122640 580 example.test. xTVteJjlrzkL8U1vqPTE7mfOXjUrsnbdOiLOvjVJFeH20wV18HEjnHl8 PWsDtSVhvf9PemqDbjmjlP7HnPIjAA== +example.test. 3600 IN SOA ns.example.test. mail.example.test. 2026051202 60 60 3600 5 diff --git a/integration-tests/ixfr-out-review/reference-output/signed-review.ixfr-2-3 b/integration-tests/ixfr-out-review/reference-output/signed-review.ixfr-2-3 new file mode 100644 index 000000000..b3b56e6fc --- /dev/null +++ b/integration-tests/ixfr-out-review/reference-output/signed-review.ixfr-2-3 @@ -0,0 +1,10 @@ +example.test. 3600 IN SOA ns.example.test. mail.example.test. 2026051202 60 60 3600 5 +example.test. 3600 IN SOA ns.example.test. mail.example.test. 2026051201 60 60 3600 5 +example.test. 3600 IN RRSIG SOA 15 2 3600 20200927122640 20200912122640 580 example.test. h7+N8Sk54Vq/GBLi4TaoLkkjgfXpNHJJ+otwK/0twaKXcywWJEHQKVge R7kBOu89QcWJTY5yUYTdoVCPw7aOCg== +JAIN-BB.example.test. 3600 IN A 133.69.136.4 +JAIN-BB.example.test. 3600 IN RRSIG A 15 3 3600 20200927122640 20200912122640 580 example.test. SzU26WJGMDBev8rx6KcOrUreSX4hVp2jwbTKNWaHxvbzrdd0nDn52dw5 k1HTZsL2+aPuHBxGDYnUJYWlM1ZNDQ== +example.test. 3600 IN SOA ns.example.test. mail.example.test. 2026051202 60 60 3600 5 +example.test. 3600 IN RRSIG SOA 15 2 3600 20200927122640 20200912122640 580 example.test. lw2qqnFjRO9k0FmtLHgcJPvzLPQidUMUW8Cx7l03eA6SxVVvfBr3nn5w sIfP4yw09HvKazQl10Xc47SfJNMKCw== +JAIN-BB.example.test. 3600 IN A 133.69.136.3 +JAIN-BB.example.test. 3600 IN RRSIG A 15 3 3600 20200927122640 20200912122640 580 example.test. xTVteJjlrzkL8U1vqPTE7mfOXjUrsnbdOiLOvjVJFeH20wV18HEjnHl8 PWsDtSVhvf9PemqDbjmjlP7HnPIjAA== +example.test. 3600 IN SOA ns.example.test. mail.example.test. 2026051202 60 60 3600 5 diff --git a/integration-tests/ixfr-out-review/reference-output/signed-review.ixfr-3-3 b/integration-tests/ixfr-out-review/reference-output/signed-review.ixfr-3-3 new file mode 100644 index 000000000..32a65570b --- /dev/null +++ b/integration-tests/ixfr-out-review/reference-output/signed-review.ixfr-3-3 @@ -0,0 +1 @@ +example.test. 3600 IN SOA ns.example.test. mail.example.test. 2026051202 60 60 3600 5 diff --git a/integration-tests/ixfr-out/keys/Kexample.test.+015+00580.key b/integration-tests/ixfr-out/keys/Kexample.test.+015+00580.key new file mode 100644 index 000000000..224ce50d5 --- /dev/null +++ b/integration-tests/ixfr-out/keys/Kexample.test.+015+00580.key @@ -0,0 +1 @@ +example.test. IN DNSKEY 256 3 15 u7Tg6xf6Xgt0y+yUT8CQi1Nyy+tRopVHnZOFQz0zQ5A= diff --git a/integration-tests/ixfr-out/keys/Kexample.test.+015+00580.private b/integration-tests/ixfr-out/keys/Kexample.test.+015+00580.private new file mode 100644 index 000000000..c6ba81b21 --- /dev/null +++ b/integration-tests/ixfr-out/keys/Kexample.test.+015+00580.private @@ -0,0 +1,3 @@ +Private-key-format: v1.2 +Algorithm: 15 (ED25519) +PrivateKey: qCwt/EY9s1vGn0uj+4dlMQ5waOuFfIYpZZVrX43jdcc= diff --git a/integration-tests/ixfr-out/keys/Knotify-and-xfr-tsig.test.+015+10995.key b/integration-tests/ixfr-out/keys/Knotify-and-xfr-tsig.test.+015+10995.key new file mode 100644 index 000000000..9ef332abc --- /dev/null +++ b/integration-tests/ixfr-out/keys/Knotify-and-xfr-tsig.test.+015+10995.key @@ -0,0 +1 @@ +notify-and-xfr-tsig.test. IN DNSKEY 256 3 15 0efFuDXcYUyhaTUWgir/RaWrzAJWAa58VuEF+391Taw= diff --git a/integration-tests/ixfr-out/keys/Knotify-and-xfr-tsig.test.+015+10995.private b/integration-tests/ixfr-out/keys/Knotify-and-xfr-tsig.test.+015+10995.private new file mode 100644 index 000000000..b385fd508 --- /dev/null +++ b/integration-tests/ixfr-out/keys/Knotify-and-xfr-tsig.test.+015+10995.private @@ -0,0 +1,3 @@ +Private-key-format: v1.2 +Algorithm: 15 (ED25519) +PrivateKey: Nx9EHQ1RBhngQMCRQUxMsiD2ybaWRCiEdcDlW5isKoo= diff --git a/integration-tests/ixfr-out/policies/with-tsig.toml b/integration-tests/ixfr-out/policies/with-tsig.toml new file mode 100644 index 000000000..cc32f479d --- /dev/null +++ b/integration-tests/ixfr-out/policies/with-tsig.toml @@ -0,0 +1,32 @@ +# Setup incremental signing to produce predictable outputs so that we can +# easily compare the generated zone against expected output. +# +# Enable sending of NOTIFY messages using TSIG authentication to the NSD +# secondary. +version = "v1" + +[signer.denial] +type = "nsec" + +[signer] +serial-policy = "keep" +signature-inception-offset = 0 +signature-lifetime = 100000000 + +[key-manager.records] +dnskey.signature-inception-offset = 0 +cds.signature-inception-offset = 0 +dnskey.signature-lifetime = 100000000 +cds.signature-lifetime = 100000000 + +[server.outbound] +# NSD secondary listens on port 1054. +send-notify-to = ["127.0.0.1:1054^tsig-key"] + +# Require that the XFR request from the NSD secondary be signed with the +# specified TSIG key. Without this, a TSIG signed XFR request with a known +# key will still be accepted, but an XFR request that is NOT TSIG signed +# would also be accepted. In the test we verify that TSIG is required by +# Cascade by attempting a dig without the required TSIG key and showing +# that it fails. +accept-xfr-from = ["127.0.0.1^tsig-key"] diff --git a/integration-tests/ixfr-out/policies/without-tsig.toml b/integration-tests/ixfr-out/policies/without-tsig.toml new file mode 100644 index 000000000..07c1d9359 --- /dev/null +++ b/integration-tests/ixfr-out/policies/without-tsig.toml @@ -0,0 +1,23 @@ +# Setup incremental signing to produce predictable outputs so that we can +# easily compare the generated zone against expected output. +# +# Enable sending of NOTIFY messages to the NSD secondary. +version = "v1" + +[signer.denial] +type = "nsec" + +[signer] +serial-policy = "keep" +signature-inception-offset = 0 +signature-lifetime = 100000000 + +[key-manager.records] +dnskey.signature-inception-offset = 0 +cds.signature-inception-offset = 0 +dnskey.signature-lifetime = 100000000 +cds.signature-lifetime = 100000000 + +[server.outbound] +# NSD secondary listens on port 1054. +send-notify-to = ["127.0.0.1:1054"] diff --git a/integration-tests/ixfr-out/reference-output/example.test.axfr b/integration-tests/ixfr-out/reference-output/example.test.axfr new file mode 100644 index 000000000..c9577dd58 --- /dev/null +++ b/integration-tests/ixfr-out/reference-output/example.test.axfr @@ -0,0 +1,17 @@ +example.test. 3600 IN SOA ns.example.test. mail.example.test. 3 60 60 3600 5 +example.test. 3600 IN RRSIG SOA 15 2 3600 20231114221320 20200913122640 580 example.test. iVSTY7uTaal9mRd44phalz9+oHlQtNDGPrQb4rvx3SkdTMT21l9PDCVL BxomZOiC51WhuQX+8FxSiLQcN+sfAw== +example.test. 3600 IN NS NS.example.test. +example.test. 3600 IN RRSIG NS 15 2 3600 20231114221320 20200913122640 580 example.test. hUD4MZwiVtXmHs+VueFIIrTUKYzWfOiNWm2nTR1gtsHTYnGjRrVEH/ic 3XeWDtKK0EedUE5iOKIEfQyYpaTLAg== +example.test. 3600 IN DNSKEY 256 3 15 u7Tg6xf6Xgt0y+yUT8CQi1Nyy+tRopVHnZOFQz0zQ5A= +example.test. 3600 IN RRSIG DNSKEY 15 2 3600 20231114221320 20200913122640 580 example.test. xGC6Pj6iN7tOjmhnLxmw4yQt7CCxCVouXvdB1P3lsQwN0iFfxgamkU7j EqIQcPpl20erYZ4XoWwtOdoeaXwtAg== +example.test. 5 IN NSEC JAIN-BB.example.test. NS SOA RRSIG NSEC DNSKEY +example.test. 5 IN RRSIG NSEC 15 2 5 20231114221320 20200913122640 580 example.test. P/YK6hlW/FOz43gKHqT4zoxRBdKFinx8GktOFDKuM+CWNyfBkjUZEI04 e3pa5/GUNcLKwRYAyWlNQnONPuusCQ== +NS.example.test. 3600 IN A 133.69.136.1 +NS.example.test. 3600 IN RRSIG A 15 3 3600 20231114221320 20200913122640 580 example.test. EsKLrDOszkF8dHi6K8XYed5EbqU9fSlNO2+25pBO/qZk1nZm1RyDO15X KWoCf1jUUNsTR4sZkiu3OGV7oazcAA== +NS.example.test. 5 IN NSEC example.test. A RRSIG NSEC +NS.example.test. 5 IN RRSIG NSEC 15 3 5 20231114221320 20200913122640 580 example.test. hO9nn4+rxV08CFGkyXYzqGrRYNVOptJXZOaQLp6OSCMtte2iSQCq7UxJ p2KK2Q7aegqYKm6nNFoABmEYjZNlDQ== +JAIN-BB.example.test. 3600 IN A 133.69.136.3 +JAIN-BB.example.test. 3600 IN A 192.41.197.2 +JAIN-BB.example.test. 3600 IN RRSIG A 15 3 3600 20231114221320 20200913122640 580 example.test. gPZnGC1IeAz1VtEvYEV9jMLw7kFhwPKX9kMtH32/xC7zyYNOfmcWqffZ xbobEY8c/oS9z4WIiK8k4uFi90rQCA== +JAIN-BB.example.test. 5 IN NSEC NS.example.test. A RRSIG NSEC +JAIN-BB.example.test. 5 IN RRSIG NSEC 15 3 5 20231114221320 20200913122640 580 example.test. /S/FZGh/OBQjwaVRPXJChDNkraEeD7qtVvIAa8db4bYmylI4KWOsH991 XDjye2aOv1+qPZxXIfzuX/3ER8JUBA== diff --git a/integration-tests/ixfr-out/reference-output/example.test.ixfr-1-3 b/integration-tests/ixfr-out/reference-output/example.test.ixfr-1-3 new file mode 100644 index 000000000..56beb1143 --- /dev/null +++ b/integration-tests/ixfr-out/reference-output/example.test.ixfr-1-3 @@ -0,0 +1,73 @@ +; The input zone was based on RFC 1995 section 7. This diff should look +; similar to "the following incremental message" from that section, but with +; DNSSEC changes present as well. Our zone name differs to that of the example +; in RFC 1995 as we have to match the zone name configured in our secondary NSD +; instance. + +; === Start of IXFR +example.test. 3600 IN SOA ns.example.test. mail.example.test. 3 60 60 3600 5 + +; [DIFF 1]: "NEZU.JAIN.AD.JP. is removed and JAIN-BB.JAIN.AD.JP. is added." +; [DIFF 1]: Records from serial 1 to be removed. + +; Changing the SOA serial requires that we regenerate the RRSIG, so the old +; RRSIG has to be removed. +example.test. 3600 IN SOA NS.example.test. mail.example.test. 1 60 60 3600 5 +example.test. 3600 IN RRSIG SOA 15 2 3600 20231114221320 20200913122640 580 example.test. TlLDWFfpydqCQjy1oDPBXugGWraoyvvk83KdTsiq441t0/hYKmL2mFEH 2nwJ6fcuZT2hLpvl9gwk3bJCXrNdAQ== + +; Remove the A record and its associated RRSIG. +NEZU.example.test. 3600 IN A 133.69.136.5 +NEZU.example.test. 3600 IN RRSIG A 15 3 3600 20231114221320 20200913122640 580 example.test. k232/sABO752SeaFp3jHkIJMUGlDA0NG+iQh1gpGVsi07XqDce+JzNX4 NiWmz06kVu+SKu1HFHNvGJ3enh5/DQ== + +; Remove the A record from the NSEC type bitmap too, and also remove NSEC +; RRSIG as a new one will be added to replace it. +NEZU.example.test. 5 IN RRSIG NSEC 15 3 5 20231114221320 20200913122640 580 example.test. BCpvhGfe+GW4GnyJBBiqjMpiVZhCXv9ZMdh+RF7qf07V3jIePWJThAy2 yV5O4I7NhKgl6rqpOyv2+aSoW8tVDw== +NEZU.example.test. 5 IN NSEC NS.example.test. A RRSIG NSEC + +; As the entire NEZU.example.test. label was removed this also requires the +; next owner name in the NSEC chain to be changed so we have to remove the +; current NSEC on the previous owner and its associated RRSIG, new ones will +; be added. +example.test. 5 IN NSEC NEZU.example.test. NS SOA RRSIG NSEC DNSKEY +example.test. 5 IN RRSIG NSEC 15 2 5 20231114221320 20200913122640 580 example.test. Hyrs5CKpXfCCNC9OK9+07Ei5qhRjQ9EQZK3up84BCwlflhOCGQppddzM eHK0Klgl0ywKaD7dfV2w3SWvP7vTDA== + +; [DIFF 1]: Records to be added for serial 2. + +; The new SOA with the updated SERIAL and its associated RRSIG. +example.test. 3600 IN SOA ns.example.test. mail.example.test. 2 60 60 3600 5 +example.test. 3600 IN RRSIG SOA 15 2 3600 20231114221320 20200913122640 580 example.test. fYRpxmxV5HQl7wIPmuN+lrYQJalFuxi9iI0DX2/mM4kdh7q9GGutFTOZ kbdY4D+AZf25s08CZR1CPpd9o2Q3Dg== + +; A changed NSEC and associated RRSIG due to changes in the NSEC chain. +example.test. 5 IN NSEC JAIN-BB.example.test. NS SOA RRSIG NSEC DNSKEY +example.test. 5 IN RRSIG NSEC 15 2 5 20231114221320 20200913122640 580 example.test. P/YK6hlW/FOz43gKHqT4zoxRBdKFinx8GktOFDKuM+CWNyfBkjUZEI04 e3pa5/GUNcLKwRYAyWlNQnONPuusCQ== + +; Add new label JAIN-BB.example.test with two A records, associated NSEC and RRSIGs. +JAIN-BB.example.test. 3600 IN A 133.69.136.4 +JAIN-BB.example.test. 3600 IN A 192.41.197.2 +JAIN-BB.example.test. 5 IN NSEC NS.example.test. A RRSIG NSEC +JAIN-BB.example.test. 5 IN RRSIG NSEC 15 3 5 20231114221320 20200913122640 580 example.test. /S/FZGh/OBQjwaVRPXJChDNkraEeD7qtVvIAa8db4bYmylI4KWOsH991 XDjye2aOv1+qPZxXIfzuX/3ER8JUBA== +JAIN-BB.example.test. 3600 IN RRSIG A 15 3 3600 20231114221320 20200913122640 580 example.test. XLFJlxjJDzmdwqF2BgxWN7Swfty8HD3ILb6Mo7fHKrfYt6x3uxXIUIjO JFVwFBhavLTrOlOcXdBGoNTvceqTDg== + +; [DIFF 2]: "One of the IP addresses of JAIN-BB.JAIN.AD.JP. is changed." +; [DIFF 2]: Records from serial 2 to be removed. + +; The old SOA and associated RRSIG. +example.test. 3600 IN SOA ns.example.test. mail.example.test. 2 60 60 3600 5 +example.test. 3600 IN RRSIG SOA 15 2 3600 20231114221320 20200913122640 580 example.test. fYRpxmxV5HQl7wIPmuN+lrYQJalFuxi9iI0DX2/mM4kdh7q9GGutFTOZ kbdY4D+AZf25s08CZR1CPpd9o2Q3Dg== + +; The old A record and associated RRSIG. +JAIN-BB.example.test. 3600 IN A 133.69.136.4 +JAIN-BB.example.test. 3600 IN RRSIG A 15 3 3600 20231114221320 20200913122640 580 example.test. XLFJlxjJDzmdwqF2BgxWN7Swfty8HD3ILb6Mo7fHKrfYt6x3uxXIUIjO JFVwFBhavLTrOlOcXdBGoNTvceqTDg== + +; [DIFF 2]: Records to be added for serial 3. + +; The new SOA and associated RRSIG. +example.test. 3600 IN SOA ns.example.test. mail.example.test. 3 60 60 3600 5 +example.test. 3600 IN RRSIG SOA 15 2 3600 20231114221320 20200913122640 580 example.test. iVSTY7uTaal9mRd44phalz9+oHlQtNDGPrQb4rvx3SkdTMT21l9PDCVL BxomZOiC51WhuQX+8FxSiLQcN+sfAw== + +; The updated A record and associated RRSIG. +JAIN-BB.example.test. 3600 IN A 133.69.136.3 +JAIN-BB.example.test. 3600 IN RRSIG A 15 3 3600 20231114221320 20200913122640 580 example.test. gPZnGC1IeAz1VtEvYEV9jMLw7kFhwPKX9kMtH32/xC7zyYNOfmcWqffZ xbobEY8c/oS9z4WIiK8k4uFi90rQCA== + +; End of IXFR +example.test. 3600 IN SOA ns.example.test. mail.example.test. 3 60 60 3600 5 diff --git a/integration-tests/ixfr-out/reference-output/example.test.ixfr-2-3 b/integration-tests/ixfr-out/reference-output/example.test.ixfr-2-3 new file mode 100644 index 000000000..56f9a7289 --- /dev/null +++ b/integration-tests/ixfr-out/reference-output/example.test.ixfr-2-3 @@ -0,0 +1,10 @@ +example.test. 3600 IN SOA ns.example.test. mail.example.test. 3 60 60 3600 5 +example.test. 3600 IN SOA ns.example.test. mail.example.test. 2 60 60 3600 5 +example.test. 3600 IN RRSIG SOA 15 2 3600 20231114221320 20200913122640 580 example.test. fYRpxmxV5HQl7wIPmuN+lrYQJalFuxi9iI0DX2/mM4kdh7q9GGutFTOZ kbdY4D+AZf25s08CZR1CPpd9o2Q3Dg== +JAIN-BB.example.test. 3600 IN A 133.69.136.4 +JAIN-BB.example.test. 3600 IN RRSIG A 15 3 3600 20231114221320 20200913122640 580 example.test. XLFJlxjJDzmdwqF2BgxWN7Swfty8HD3ILb6Mo7fHKrfYt6x3uxXIUIjO JFVwFBhavLTrOlOcXdBGoNTvceqTDg== +example.test. 3600 IN SOA ns.example.test. mail.example.test. 3 60 60 3600 5 +example.test. 3600 IN RRSIG SOA 15 2 3600 20231114221320 20200913122640 580 example.test. iVSTY7uTaal9mRd44phalz9+oHlQtNDGPrQb4rvx3SkdTMT21l9PDCVL BxomZOiC51WhuQX+8FxSiLQcN+sfAw== +JAIN-BB.example.test. 3600 IN A 133.69.136.3 +JAIN-BB.example.test. 3600 IN RRSIG A 15 3 3600 20231114221320 20200913122640 580 example.test. gPZnGC1IeAz1VtEvYEV9jMLw7kFhwPKX9kMtH32/xC7zyYNOfmcWqffZ xbobEY8c/oS9z4WIiK8k4uFi90rQCA== +example.test. 3600 IN SOA ns.example.test. mail.example.test. 3 60 60 3600 5 diff --git a/integration-tests/ixfr-out/reference-output/example.test.ixfr-3-3 b/integration-tests/ixfr-out/reference-output/example.test.ixfr-3-3 new file mode 100644 index 000000000..ebe4c34bc --- /dev/null +++ b/integration-tests/ixfr-out/reference-output/example.test.ixfr-3-3 @@ -0,0 +1 @@ +example.test. 3600 IN SOA ns.example.test. mail.example.test. 3 60 60 3600 5 diff --git a/integration-tests/ixfr-out/reference-output/notify-and-xfr-tsig.test.axfr b/integration-tests/ixfr-out/reference-output/notify-and-xfr-tsig.test.axfr new file mode 100644 index 000000000..08e54a056 --- /dev/null +++ b/integration-tests/ixfr-out/reference-output/notify-and-xfr-tsig.test.axfr @@ -0,0 +1,17 @@ +notify-and-xfr-tsig.test. 3600 IN SOA ns.notify-and-xfr-tsig.test. mail.notify-and-xfr-tsig.test. 3 60 60 3600 5 +notify-and-xfr-tsig.test. 3600 IN RRSIG SOA 15 2 3600 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. caF70ZxIDm7UIXcj4RmkY5G+rcNFJp+wKpg17pUEz+N4P8+uxp3tYjYj 145UTqd36AUv4jsJgqEVN9roaZAbAw== +notify-and-xfr-tsig.test. 3600 IN NS NS.notify-and-xfr-tsig.test. +notify-and-xfr-tsig.test. 3600 IN RRSIG NS 15 2 3600 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. YDqsJSHx81jK/GSqDdnNDG3JN9v9SH6jgmsgbQNElcaSCXqMrR2Q3QFq wrYW06FgnadRgTySRZ2evzS3dYGaDw== +notify-and-xfr-tsig.test. 3600 IN DNSKEY 256 3 15 0efFuDXcYUyhaTUWgir/RaWrzAJWAa58VuEF+391Taw= +notify-and-xfr-tsig.test. 3600 IN RRSIG DNSKEY 15 2 3600 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. CIiRWX2DYaZRidc0nDl4zE0vmUCK2XFX2ekrJc1DVljIestEaJBAR2V1 ZQYOtCtb8y8AA/RCH8UFN2DYSM6+CQ== +notify-and-xfr-tsig.test. 5 IN NSEC JAIN-BB.notify-and-xfr-tsig.test. NS SOA RRSIG NSEC DNSKEY +notify-and-xfr-tsig.test. 5 IN RRSIG NSEC 15 2 5 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. z7aQTz7VOeeSwwftFsHr+f2BG1k1mVTGztiqZNUAYBkT5R+IlhWpzNdR KvpUSMcdgSNSsjKLQciFq/vYSqg7DA== +NS.notify-and-xfr-tsig.test. 3600 IN A 133.69.136.1 +NS.notify-and-xfr-tsig.test. 3600 IN RRSIG A 15 3 3600 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. ziPT0QEZ/gGcVltE17tqgf3jqo9SfesIffux+pIZwC3vO8eg1MnzPJOv Kmdl9vJQqS03FjwT+6r3xtjIVIfwAA== +NS.notify-and-xfr-tsig.test. 5 IN NSEC notify-and-xfr-tsig.test. A RRSIG NSEC +NS.notify-and-xfr-tsig.test. 5 IN RRSIG NSEC 15 3 5 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. nLNfo5CuJQd8qYbDywdefe0pFQ881jn3W6WEfNnkMg1daJk2ENcZUkiJ aeR7Hv7FPzTyavE2SQbuHfHrYDKoAA== +JAIN-BB.notify-and-xfr-tsig.test. 3600 IN A 133.69.136.3 +JAIN-BB.notify-and-xfr-tsig.test. 3600 IN A 192.41.197.2 +JAIN-BB.notify-and-xfr-tsig.test. 3600 IN RRSIG A 15 3 3600 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. 0X5PtAfOES8cyYc9kFoXfFB5w5AHBtTSlw8V2wd+UehtSgHMDX0ebUig C65dQahRoe6oELz7UNY7rv+BLOMrAA== +JAIN-BB.notify-and-xfr-tsig.test. 5 IN NSEC NS.notify-and-xfr-tsig.test. A RRSIG NSEC +JAIN-BB.notify-and-xfr-tsig.test. 5 IN RRSIG NSEC 15 3 5 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. Kn1CEC2iYr/uSRAZvM9SV2HRR0B8l8ObkvqYufiGO0en+OSLRmfgzviT Mdhdai9onUYr7ndQFHI8bSav5MBoCQ== diff --git a/integration-tests/ixfr-out/reference-output/notify-and-xfr-tsig.test.ixfr-1-3 b/integration-tests/ixfr-out/reference-output/notify-and-xfr-tsig.test.ixfr-1-3 new file mode 100644 index 000000000..33df5ea3e --- /dev/null +++ b/integration-tests/ixfr-out/reference-output/notify-and-xfr-tsig.test.ixfr-1-3 @@ -0,0 +1,27 @@ +notify-and-xfr-tsig.test. 3600 IN SOA ns.notify-and-xfr-tsig.test. mail.notify-and-xfr-tsig.test. 3 60 60 3600 5 +notify-and-xfr-tsig.test. 3600 IN SOA NS.notify-and-xfr-tsig.test. mail.notify-and-xfr-tsig.test. 1 60 60 3600 5 +NEZU.notify-and-xfr-tsig.test. 3600 IN A 133.69.136.5 +notify-and-xfr-tsig.test. 5 IN RRSIG NSEC 15 2 5 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. 0BtPWx9VOtcE1BMD3cLk1FR1YaT/1v32VuuxXh/XQgS97Nj80H+Qm57V ORpk/V6wkw2exuvz3ko2s2BfkaQqAQ== +notify-and-xfr-tsig.test. 3600 IN RRSIG SOA 15 2 3600 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. xzwl8jSWvas1L2Uqzfq8kGkPZzvTQyvrmv8Q3q+jVdTj7FIYCOXN3moZ MvasxJgo6euVesldGA0WzQ0UaIxyBw== +notify-and-xfr-tsig.test. 5 IN NSEC NEZU.notify-and-xfr-tsig.test. NS SOA RRSIG NSEC DNSKEY +NEZU.notify-and-xfr-tsig.test. 5 IN RRSIG NSEC 15 3 5 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. kNDs5mxnK6tKyDu1fBIAg1SnynqRQM7afK+hmPkLJD0SkvKEItomMbui gKlgDdtA7YWA8zTh4j7bwUq/tBlYAQ== +NEZU.notify-and-xfr-tsig.test. 3600 IN RRSIG A 15 3 3600 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. Etgfp3BL11ReT8j0UHQ5epj6l+mAH2+1Fmv/p74EQ3EsbpPiGx3c+96u XeRbWRCVVY/yCqH7E5j0NPHvFYhBAg== +NEZU.notify-and-xfr-tsig.test. 5 IN NSEC NS.notify-and-xfr-tsig.test. A RRSIG NSEC +notify-and-xfr-tsig.test. 3600 IN SOA ns.notify-and-xfr-tsig.test. mail.notify-and-xfr-tsig.test. 2 60 60 3600 5 +JAIN-BB.notify-and-xfr-tsig.test. 3600 IN A 133.69.136.4 +JAIN-BB.notify-and-xfr-tsig.test. 3600 IN A 192.41.197.2 +notify-and-xfr-tsig.test. 5 IN RRSIG NSEC 15 2 5 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. z7aQTz7VOeeSwwftFsHr+f2BG1k1mVTGztiqZNUAYBkT5R+IlhWpzNdR KvpUSMcdgSNSsjKLQciFq/vYSqg7DA== +notify-and-xfr-tsig.test. 3600 IN RRSIG SOA 15 2 3600 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. 0Qn9RoFrnZrhs8qy/GFWrSQ0ZUx11s60vVAzhBR0MhX9k8731t6Is5ic VwajxP8l3NM1PSvB0Eqamo0cyy6rCA== +notify-and-xfr-tsig.test. 5 IN NSEC JAIN-BB.notify-and-xfr-tsig.test. NS SOA RRSIG NSEC DNSKEY +JAIN-BB.notify-and-xfr-tsig.test. 5 IN RRSIG NSEC 15 3 5 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. Kn1CEC2iYr/uSRAZvM9SV2HRR0B8l8ObkvqYufiGO0en+OSLRmfgzviT Mdhdai9onUYr7ndQFHI8bSav5MBoCQ== +JAIN-BB.notify-and-xfr-tsig.test. 3600 IN RRSIG A 15 3 3600 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. SRcvE4FT1NE9uVZrrFv1f+xinA37/CZWac6bJ62REhIE2e90rbDr1i/e n31YVDZQOHeVTKZCuueVKXgPYyztCw== +JAIN-BB.notify-and-xfr-tsig.test. 5 IN NSEC NS.notify-and-xfr-tsig.test. A RRSIG NSEC +notify-and-xfr-tsig.test. 3600 IN SOA ns.notify-and-xfr-tsig.test. mail.notify-and-xfr-tsig.test. 2 60 60 3600 5 +JAIN-BB.notify-and-xfr-tsig.test. 3600 IN A 133.69.136.4 +notify-and-xfr-tsig.test. 3600 IN RRSIG SOA 15 2 3600 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. 0Qn9RoFrnZrhs8qy/GFWrSQ0ZUx11s60vVAzhBR0MhX9k8731t6Is5ic VwajxP8l3NM1PSvB0Eqamo0cyy6rCA== +JAIN-BB.notify-and-xfr-tsig.test. 3600 IN RRSIG A 15 3 3600 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. SRcvE4FT1NE9uVZrrFv1f+xinA37/CZWac6bJ62REhIE2e90rbDr1i/e n31YVDZQOHeVTKZCuueVKXgPYyztCw== +notify-and-xfr-tsig.test. 3600 IN SOA ns.notify-and-xfr-tsig.test. mail.notify-and-xfr-tsig.test. 3 60 60 3600 5 +JAIN-BB.notify-and-xfr-tsig.test. 3600 IN A 133.69.136.3 +notify-and-xfr-tsig.test. 3600 IN RRSIG SOA 15 2 3600 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. caF70ZxIDm7UIXcj4RmkY5G+rcNFJp+wKpg17pUEz+N4P8+uxp3tYjYj 145UTqd36AUv4jsJgqEVN9roaZAbAw== +JAIN-BB.notify-and-xfr-tsig.test. 3600 IN RRSIG A 15 3 3600 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. 0X5PtAfOES8cyYc9kFoXfFB5w5AHBtTSlw8V2wd+UehtSgHMDX0ebUig C65dQahRoe6oELz7UNY7rv+BLOMrAA== +notify-and-xfr-tsig.test. 3600 IN SOA ns.notify-and-xfr-tsig.test. mail.notify-and-xfr-tsig.test. 3 60 60 3600 5 diff --git a/integration-tests/ixfr-out/reference-output/notify-and-xfr-tsig.test.ixfr-2-3 b/integration-tests/ixfr-out/reference-output/notify-and-xfr-tsig.test.ixfr-2-3 new file mode 100644 index 000000000..9b3966fe2 --- /dev/null +++ b/integration-tests/ixfr-out/reference-output/notify-and-xfr-tsig.test.ixfr-2-3 @@ -0,0 +1,10 @@ +notify-and-xfr-tsig.test. 3600 IN SOA ns.notify-and-xfr-tsig.test. mail.notify-and-xfr-tsig.test. 3 60 60 3600 5 +notify-and-xfr-tsig.test. 3600 IN SOA ns.notify-and-xfr-tsig.test. mail.notify-and-xfr-tsig.test. 2 60 60 3600 5 +notify-and-xfr-tsig.test. 3600 IN RRSIG SOA 15 2 3600 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. 0Qn9RoFrnZrhs8qy/GFWrSQ0ZUx11s60vVAzhBR0MhX9k8731t6Is5ic VwajxP8l3NM1PSvB0Eqamo0cyy6rCA== +JAIN-BB.notify-and-xfr-tsig.test. 3600 IN A 133.69.136.4 +JAIN-BB.notify-and-xfr-tsig.test. 3600 IN RRSIG A 15 3 3600 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. SRcvE4FT1NE9uVZrrFv1f+xinA37/CZWac6bJ62REhIE2e90rbDr1i/e n31YVDZQOHeVTKZCuueVKXgPYyztCw== +notify-and-xfr-tsig.test. 3600 IN SOA ns.notify-and-xfr-tsig.test. mail.notify-and-xfr-tsig.test. 3 60 60 3600 5 +notify-and-xfr-tsig.test. 3600 IN RRSIG SOA 15 2 3600 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. caF70ZxIDm7UIXcj4RmkY5G+rcNFJp+wKpg17pUEz+N4P8+uxp3tYjYj 145UTqd36AUv4jsJgqEVN9roaZAbAw== +JAIN-BB.notify-and-xfr-tsig.test. 3600 IN A 133.69.136.3 +JAIN-BB.notify-and-xfr-tsig.test. 3600 IN RRSIG A 15 3 3600 20231114221320 20200913122640 10995 notify-and-xfr-tsig.test. 0X5PtAfOES8cyYc9kFoXfFB5w5AHBtTSlw8V2wd+UehtSgHMDX0ebUig C65dQahRoe6oELz7UNY7rv+BLOMrAA== +notify-and-xfr-tsig.test. 3600 IN SOA ns.notify-and-xfr-tsig.test. mail.notify-and-xfr-tsig.test. 3 60 60 3600 5 diff --git a/integration-tests/ixfr-out/reference-output/notify-and-xfr-tsig.test.ixfr-3-3 b/integration-tests/ixfr-out/reference-output/notify-and-xfr-tsig.test.ixfr-3-3 new file mode 100644 index 000000000..1808ea302 --- /dev/null +++ b/integration-tests/ixfr-out/reference-output/notify-and-xfr-tsig.test.ixfr-3-3 @@ -0,0 +1 @@ +notify-and-xfr-tsig.test. 3600 IN SOA ns.notify-and-xfr-tsig.test. mail.notify-and-xfr-tsig.test. 3 60 60 3600 5 diff --git a/integration-tests/scripts/manage-test-environment.sh b/integration-tests/scripts/manage-test-environment.sh index 349ce5d69..7ef29328f 100755 --- a/integration-tests/scripts/manage-test-environment.sh +++ b/integration-tests/scripts/manage-test-environment.sh @@ -299,7 +299,7 @@ pattern: zonefile: "%s.secondary-zone" allow-notify: 127.0.0.1 NOKEY # Until Cascade supports IXFR we always use AXFR - request-xfr: AXFR 127.0.0.1@${_cascade_port} NOKEY + request-xfr: 127.0.0.1@${_cascade_port} NOKEY provide-xfr: 127.0.0.1 NOKEY zone: @@ -310,21 +310,21 @@ zone: name: notify-tsig.test zonefile: "notify-tsig.test.secondary-zone" allow-notify: 127.0.0.1 tsig-key - request-xfr: AXFR 127.0.0.1@${_cascade_port} NOKEY + request-xfr: 127.0.0.1@${_cascade_port} NOKEY provide-xfr: 127.0.0.1 NOKEY zone: name: xfr-tsig.test zonefile: "xfr-tsig.test.secondary-zone" allow-notify: 127.0.0.1 NOKEY - request-xfr: AXFR 127.0.0.1@${_cascade_port} tsig-key + request-xfr: 127.0.0.1@${_cascade_port} tsig-key provide-xfr: 127.0.0.1 NOKEY zone: name: notify-and-xfr-tsig.test zonefile: "notify-and-xfr-tsig.test.secondary-zone" allow-notify: 127.0.0.1 tsig-key - request-xfr: AXFR 127.0.0.1@${_cascade_port} tsig-key + request-xfr: 127.0.0.1@${_cascade_port} tsig-key provide-xfr: 127.0.0.1 NOKEY EOF diff --git a/integration-tests/system-tests.yml b/integration-tests/system-tests.yml index 7e3fb8755..b3d27ed86 100644 --- a/integration-tests/system-tests.yml +++ b/integration-tests/system-tests.yml @@ -166,6 +166,46 @@ jobs: with: log-level: ${{ inputs.log-level }} + ixfr-out: + name: Serve manual zone edits via IXFR to the NSD secondary. + runs-on: ubuntu-latest + strategy: + matrix: + with-tsig: [true, false] + steps: + - uses: actions/checkout@v4 + - uses: ./.github/actions/set-build-profile + with: + build-profile: ${{ inputs.build-profile }} + - uses: ./integration-tests/tests/ixfr-out + with: + log-level: ${{ inputs.log-level }} + with-tsig: ${{ matrix.with-tsig }} + + ixfr-out-incremental: + name: Serve incremental signing changes via IXFR to the NSD secondary. + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - uses: ./.github/actions/set-build-profile + with: + build-profile: ${{ inputs.build-profile }} + - uses: ./integration-tests/tests/ixfr-out-incremental + with: + log-level: ${{ inputs.log-level }} + + ixfr-out-review: + name: Serve manual zone edits via IXFR for review. + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - uses: ./.github/actions/set-build-profile + with: + build-profile: ${{ inputs.build-profile }} + - uses: ./integration-tests/tests/ixfr-out-review + with: + log-level: ${{ inputs.log-level }} + incremental-signing: name: Test incremental signing. runs-on: ubuntu-latest diff --git a/integration-tests/tests/ixfr-out-incremental/action.yml b/integration-tests/tests/ixfr-out-incremental/action.yml new file mode 100644 index 000000000..47fa37e4b --- /dev/null +++ b/integration-tests/tests/ixfr-out-incremental/action.yml @@ -0,0 +1,162 @@ +# Making reusable composite actions documented at +# https://docs.github.com/en/actions/tutorials/create-actions/create-a-composite-action#creating-a-composite-action-within-the-same-repository +name: 'Serve incremental signing changes via IXFR to the NSD secondary.' +description: 'Serve a zone via IXFR to the NSD secondary.' +defaults: + # see: https://docs.github.com/en/actions/reference/workflows-and-actions/workflow-syntax#defaultsrunshell + run: + shell: bash --noprofile --norc -eo pipefail -x {0} +inputs: + log-level: + description: The level of logging that Cascade should output. + required: false + default: debug + type: choice + options: + - error + - warning + - info + - debug + - trace +runs: + using: "composite" + steps: + - uses: ./.github/actions/prepare-systest-env + - uses: ./.github/actions/setup-and-start-cascade + with: + log-level: ${{ inputs.log-level }} + + - name: Determine the downstream secondary zone config to use + id: set-vars + run: | + ZONE_NAME="example.test." + POLICY_NAME="fast-incremental" + KEY_NAME="Kexample.test.+015+00580.key" + echo "ZONE_NAME=${ZONE_NAME}" >> "$GITHUB_OUTPUT" + echo "POLICY_NAME=${POLICY_NAME}" >> "$GITHUB_OUTPUT" + echo "KEY_NAME=${KEY_NAME}" >> "$GITHUB_OUTPUT" + + - name: Add policy ${{ steps.set-vars.outputs.POLICY_NAME }} and reload + run: | + POLICY_DIR=$(integration-tests/scripts/get-default-path.sh policy-dir) + TEST_DIR="${PWD}/integration-tests/ixfr-out-incremental" + cp "${TEST_DIR}/policies/${{ steps.set-vars.outputs.POLICY_NAME }}.toml" "${POLICY_DIR}/" + cascade policy reload + + # The zone name has to match a zone configured in the downstream NSD + # nameserver. Zone 'notify-and-xfr-tsig.test' is a zone in the downstream + # NSD nameserver that is configured to expect TSIG to be used for the + # NOTIFY message it is sent, to use IXFR (as opposed to only AXFR) and for + # it to need to use TSIG to request an IXFR transfer from Cascade. + - name: Make a ${{ steps.set-vars.outputs.ZONE_NAME }} zone based on RFC 1995 section 7 + env: + ZONE_NAME: ${{ steps.set-vars.outputs.ZONE_NAME }} + run: | + cat >"${ZONE_NAME}zone" < (start + timeout))); then + cascade zone status ${ZONE_NAME} + echo "timeout: zone status did not report published zone available" >&2 + exit 1 + fi + sleep 1 + done + + - name: Expect serial 1 of zone ${{ steps.set-vars.outputs.ZONE_NAME }} at the NSD secondary + env: + ZONE_NAME: ${{ steps.set-vars.outputs.ZONE_NAME }} + run: | + timeout=10 # seconds + start=$(date +%s) + until dig +short @127.0.0.1 -p 1054 ${ZONE_NAME} SOA | grep -q "ns.${ZONE_NAME} mail.${ZONE_NAME} 1 60 60 3600 5"; do + if (($(date +%s) > (start + timeout))); then + cascade zone status ${ZONE_NAME} + dig +short @127.0.0.1 -p 1054 ${ZONE_NAME} SOA + echo "::error:: timeout: NSD did not acquire the zone changes" + exit 1 + fi + sleep 1 + done + + - name: Expect serial 2 of zone ${{ steps.set-vars.outputs.ZONE_NAME }} at the NSD secondary + env: + ZONE_NAME: ${{ steps.set-vars.outputs.ZONE_NAME }} + run: | + timeout=10 # seconds + start=$(date +%s) + until dig +short @127.0.0.1 -p 1054 ${ZONE_NAME} SOA | grep -q "ns.${ZONE_NAME} mail.${ZONE_NAME} 2 60 60 3600 5"; do + if (($(date +%s) > (start + timeout))); then + dig @127.0.0.1 -p 1054 ${ZONE_NAME} SOA + cascade zone status ${ZONE_NAME} + echo "::error:: timeout: NSD did not acquire the zone changes" + exit 1 + fi + sleep 1 + done + + - name: Expect serial 3 of zone ${{ steps.set-vars.outputs.ZONE_NAME }} at the NSD secondary + env: + ZONE_NAME: ${{ steps.set-vars.outputs.ZONE_NAME }} + run: | + timeout=10 # seconds + start=$(date +%s) + until dig +short @127.0.0.1 -p 1054 ${ZONE_NAME} SOA | grep -q "ns.${ZONE_NAME} mail.${ZONE_NAME} 3 60 60 3600 5"; do + if (($(date +%s) > (start + timeout))); then + cascade zone status ${ZONE_NAME} + dig +short @127.0.0.1 -p 1054 ${ZONE_NAME} SOA + echo "::error:: timeout: NSD did not acquire the zone changes" + exit 1 + fi + sleep 1 + done + + - name: Capture Cascade AXFR out + env: + ZONE_NAME: ${{ steps.set-vars.outputs.ZONE_NAME }} + run: | + dig +onesoa +noall +answer @127.0.0.1 -p 4542 ${ZONE_NAME} AXFR &> cascade-axfr.log + + - name: Compare NSD AXFR out to Cascade AXFR out + env: + ZONE_NAME: ${{ steps.set-vars.outputs.ZONE_NAME }} + run: | + dig +onesoa +noall +answer @127.0.0.1 -p 1054 ${ZONE_NAME} AXFR &> nsd-axfr.log + + # Pass -f to sort and -i to diff to normalize case in the Cascade and + # NSD output being compared, as NSD outputs lower case labels while + # Cascade preserves label case. -f tells sort not to order differently + # based on case, and -i tells diff to consider differing case to be + # equal. + + LC_COLLATE=C sort -f cascade-axfr.log > cascade-axfr.sorted + LC_COLLATE=C sort -f nsd-axfr.log > nsd-axfr.sorted + diff -u -w -i cascade-axfr.sorted nsd-axfr.sorted + + - name: Print log files on any failure in this job + uses: ./.github/actions/print-logfiles + if: failure() diff --git a/integration-tests/tests/ixfr-out-review/action.yml b/integration-tests/tests/ixfr-out-review/action.yml new file mode 100644 index 000000000..9b5d71caf --- /dev/null +++ b/integration-tests/tests/ixfr-out-review/action.yml @@ -0,0 +1,239 @@ +# Making reusable composite actions documented at +# https://docs.github.com/en/actions/tutorials/create-actions/create-a-composite-action#creating-a-composite-action-within-the-same-repository +name: 'Serve manual zone modifications via IXFR for review.' +description: 'Serve a zone via IXFR to the NSD secondary.' +defaults: + # see: https://docs.github.com/en/actions/reference/workflows-and-actions/workflow-syntax#defaultsrunshell + run: + shell: bash --noprofile --norc -eo pipefail -x {0} +inputs: + log-level: + description: The level of logging that Cascade should output. + required: false + default: debug + type: choice + options: + - error + - warning + - info + - debug + - trace +runs: + using: "composite" + steps: + - uses: ./.github/actions/setup-and-start-cascade + with: + log-level: ${{ inputs.log-level }} + fake-time: 1600000000 + + - name: Determine expected published serial number + id: set-vars + run: | + EXPECTED_SERIAL="$(date +'%Y%m%d00')" + echo "EXPECTED_SERIAL=${EXPECTED_SERIAL}" >>"$GITHUB_OUTPUT" + + - name: Make a zone based on RFC 1995 section 7 + run: | + cat >"example.test.zone" < (start + timeout))); then + cascade zone status example.test + echo "timeout: zone status did not report published zone available" >&2 + exit 1 + fi + sleep 1 + done + + - name: Expect serial 1 of the zone at the loaded review server + run: | + timeout=3 # seconds + start=$(date +%s) + until dig +short @127.0.0.1 -p 4540 example.test SOA | grep -qi "ns.example.test. mail.example.test. 1 60 60 3600 5"; do + if (($(date +%s) > (start + timeout))); then + cascade zone status example.test + dig +short @127.0.0.1 -p 4540 example.test SOA + echo "::error:: timeout: loaded review server is not serving serial 1 of the zone" + exit 1 + fi + sleep 1 + done + + - name: Expect serial 1 of the zone at the signed review server + env: + EXPECTED_SERIAL: ${{ steps.set-vars.outputs.EXPECTED_SERIAL }} + run: | + timeout=10 # seconds + start=$(date +%s) + until dig +short @127.0.0.1 -p 4541 example.test SOA | grep -qi "ns.example.test. mail.example.test. ${EXPECTED_SERIAL} 60 60 3600 5"; do + if (($(date +%s) > (start + timeout))); then + cascade zone status example.test + dig +short @127.0.0.1 -p 4541 example.test SOA + echo "::error:: timeout: signed review server is not serving serial 1 of the zone" + exit 1 + fi + sleep 1 + done + + - name: Edit and reload serial 2 of the zone + run: | + cat >"example.test.zone" < (start + timeout))); then + cascade zone status example.test + dig +short @127.0.0.1 -p 4540 example.test SOA + echo "::error:: timeout: loaded review server is not serving serial 2 of the zone" + exit 1 + fi + sleep 1 + done + + - name: Expect serial 2 of the zone at the signed review server + env: + EXPECTED_SERIAL: ${{ steps.set-vars.outputs.EXPECTED_SERIAL }} + run: | + timeout=10 # seconds + start=$(date +%s) + let EXPECTED_SERIAL=$(( EXPECTED_SERIAL + 1 )) + until dig +short @127.0.0.1 -p 4541 example.test SOA | grep -qi "ns.example.test. mail.example.test. ${EXPECTED_SERIAL} 60 60 3600 5"; do + if (($(date +%s) > (start + timeout))); then + cascade zone status example.test + dig +short @127.0.0.1 -p 4541 example.test SOA + echo "::error:: timeout: signed review server is not serving serial 2 of the zone" + exit 1 + fi + sleep 1 + done + + - name: Edit and reload serial 3 of the zone + run: | + cat >"example.test.zone" < (start + timeout))); then + cascade zone status example.test + dig +short @127.0.0.1 -p 4540 example.test SOA + echo "::error:: timeout: loaded review server is not serving serial 3 of the zone" + exit 1 + fi + sleep 1 + done + + - name: Expect serial 3 of the zone at the signed review server + env: + EXPECTED_SERIAL: ${{ steps.set-vars.outputs.EXPECTED_SERIAL }} + run: | + timeout=10 # seconds + start=$(date +%s) + let EXPECTED_SERIAL=$(( EXPECTED_SERIAL + 2 )) + until dig +short @127.0.0.1 -p 4541 example.test SOA | grep -qi "ns.example.test. mail.example.test. ${EXPECTED_SERIAL} 60 60 3600 5"; do + if (($(date +%s) > (start + timeout))); then + cascade zone status example.test + dig +short @127.0.0.1 -p 4541 example.test SOA + echo "::error:: timeout: signed review server is not serving serial 3 of the zone" + exit 1 + fi + sleep 1 + done + + - name: Verify IXFR of serial 1..=3 at the loaded review server + run: | + dig +onesoa +noall +answer @127.0.0.1 -p 4540 example.test -t IXFR=1 &> loaded-review-ixfr-1-3.log + TEST_DIR="${PWD}/integration-tests/ixfr-out-review" + LC_COLLATE=C sort "${TEST_DIR}/reference-output/loaded-review.ixfr-1-3" | egrep -v '^;|^$' > reference.output.sorted + LC_COLLATE=C sort loaded-review-ixfr-1-3.log > output.sorted + diff -u -w output.sorted reference.output.sorted + + - name: Verify IXFR of serial 2..=3 at the loaded review server + run: | + dig +onesoa +noall +answer @127.0.0.1 -p 4540 example.test -t IXFR=2 &> loaded-review-ixfr-2-3.log + TEST_DIR="${PWD}/integration-tests/ixfr-out-review" + LC_COLLATE=C sort "${TEST_DIR}/reference-output/loaded-review.ixfr-2-3" | egrep -v '^;|^$' > reference.output.sorted + LC_COLLATE=C sort loaded-review-ixfr-2-3.log > output.sorted + diff -u -w output.sorted reference.output.sorted + + - name: Verify IXFR of serial 3..=3 at the loaded review server + run: | + dig +onesoa +noall +answer @127.0.0.1 -p 4540 example.test -t IXFR=3 &> loaded-review-ixfr-3-3.log + TEST_DIR="${PWD}/integration-tests/ixfr-out-review" + LC_COLLATE=C sort "${TEST_DIR}/reference-output/loaded-review.ixfr-3-3" | egrep -v '^;|^$' > reference.output.sorted + LC_COLLATE=C sort loaded-review-ixfr-3-3.log > output.sorted + diff -u -w output.sorted reference.output.sorted + + - name: Verify IXFR of serial 1..=3 at the signed review server + env: + EXPECTED_SERIAL: ${{ steps.set-vars.outputs.EXPECTED_SERIAL }} + run: | + dig +onesoa +noall +answer @127.0.0.1 -p 4541 example.test -t IXFR=${EXPECTED_SERIAL} &> signed-review-ixfr-1-3.log + TEST_DIR="${PWD}/integration-tests/ixfr-out-review" + LC_COLLATE=C sort "${TEST_DIR}/reference-output/signed-review.ixfr-1-3" | egrep -v '^;|^$' > reference.output.sorted + LC_COLLATE=C sort signed-review-ixfr-1-3.log > output.sorted + diff -u -w output.sorted reference.output.sorted + + - name: Verify IXFR of serial 2..=3 at the signed review server + env: + EXPECTED_SERIAL: ${{ steps.set-vars.outputs.EXPECTED_SERIAL }} + run: | + dig +onesoa +noall +answer @127.0.0.1 -p 4541 example.test -t IXFR=$(( EXPECTED_SERIAL + 1 )) &> signed-review-ixfr-2-3.log + TEST_DIR="${PWD}/integration-tests/ixfr-out-review" + LC_COLLATE=C sort "${TEST_DIR}/reference-output/signed-review.ixfr-2-3" | egrep -v '^;|^$' > reference.output.sorted + LC_COLLATE=C sort signed-review-ixfr-2-3.log > output.sorted + diff -u -w output.sorted reference.output.sorted + + - name: Verify IXFR of serial 3..=3 at the signed review server + env: + EXPECTED_SERIAL: ${{ steps.set-vars.outputs.EXPECTED_SERIAL }} + run: | + dig +onesoa +noall +answer @127.0.0.1 -p 4541 example.test -t IXFR=$(( EXPECTED_SERIAL + 2 )) &> signed-review-ixfr-3-3.log + TEST_DIR="${PWD}/integration-tests/ixfr-out-review" + LC_COLLATE=C sort "${TEST_DIR}/reference-output/signed-review.ixfr-3-3" | egrep -v '^;|^$' > reference.output.sorted + LC_COLLATE=C sort signed-review-ixfr-3-3.log > output.sorted + diff -u -w output.sorted reference.output.sorted + + - name: Print log files on any failure in this job + uses: ./.github/actions/print-logfiles + if: failure() diff --git a/integration-tests/tests/ixfr-out/action.yml b/integration-tests/tests/ixfr-out/action.yml new file mode 100644 index 000000000..0cdab4edf --- /dev/null +++ b/integration-tests/tests/ixfr-out/action.yml @@ -0,0 +1,324 @@ +# Making reusable composite actions documented at +# https://docs.github.com/en/actions/tutorials/create-actions/create-a-composite-action#creating-a-composite-action-within-the-same-repository +name: 'Serve manual zone modifications via IXFR to the NSD secondary.' +description: 'Serve a zone via IXFR to the NSD secondary.' +defaults: + # see: https://docs.github.com/en/actions/reference/workflows-and-actions/workflow-syntax#defaultsrunshell + run: + shell: bash --noprofile --norc -eo pipefail -x {0} +inputs: + log-level: + description: The level of logging that Cascade should output. + required: false + default: debug + type: choice + options: + - error + - warning + - info + - debug + - trace + with-tsig: + description: Whether or not TSIG should be required for XFR out. + required: true + type: boolean +runs: + using: "composite" + steps: + - uses: ./.github/actions/prepare-systest-env + - uses: ./.github/actions/setup-and-start-cascade + with: + log-level: ${{ inputs.log-level }} + fake-time: 1600000000 + + - name: Determine the downstream secondary zone config to use + id: set-vars + run: | + if [[ "${{ inputs.with-tsig }}" == "true" ]]; then + ZONE_NAME="notify-and-xfr-tsig.test." + POLICY_NAME="with-tsig" + KEY_NAME="Knotify-and-xfr-tsig.test.+015+10995.key" + else + ZONE_NAME="example.test." + POLICY_NAME="without-tsig" + KEY_NAME="Kexample.test.+015+00580.key" + fi + echo "ZONE_NAME=${ZONE_NAME}" >> "$GITHUB_OUTPUT" + echo "POLICY_NAME=${POLICY_NAME}" >> "$GITHUB_OUTPUT" + echo "KEY_NAME=${KEY_NAME}" >> "$GITHUB_OUTPUT" + echo "TSIG_SPEC=hmac-sha256:tsig-key:COzoVsYQmXeXiyq1Quhp0bbVnMyxjPxsaGSoIWR98i0=" >> "$GITHUB_OUTPUT" + + - name: Add the TSIG key + if: ${{ inputs.with-tsig }} + run: | + cascade tsig add ${{ steps.set-vars.outputs.TSIG_SPEC }} + + - name: Add policy ${{ steps.set-vars.outputs.POLICY_NAME }} and reload + run: | + POLICY_DIR=$(integration-tests/scripts/get-default-path.sh policy-dir) + TEST_DIR="${PWD}/integration-tests/ixfr-out" + cp "${TEST_DIR}/policies/${{ steps.set-vars.outputs.POLICY_NAME }}.toml" "${POLICY_DIR}/" + cascade policy reload + + # The zone name has to match a zone configured in the downstream NSD + # nameserver. Zone 'notify-and-xfr-tsig.test' is a zone in the downstream + # NSD nameserver that is configured to expect TSIG to be used for the + # NOTIFY message it is sent, to use IXFR (as opposed to only AXFR) and for + # it to need to use TSIG to request an IXFR transfer from Cascade. + - name: Make a ${{ steps.set-vars.outputs.ZONE_NAME }} zone based on RFC 1995 section 7 + env: + ZONE_NAME: ${{ steps.set-vars.outputs.ZONE_NAME }} + run: | + cat >"${ZONE_NAME}zone" < (start + timeout))); then + cascade zone status ${ZONE_NAME} + echo "timeout: zone status did not report published zone available" >&2 + exit 1 + fi + sleep 1 + done + + - name: Expect serial 1 of zone ${{ steps.set-vars.outputs.ZONE_NAME }} at the NSD secondary + env: + ZONE_NAME: ${{ steps.set-vars.outputs.ZONE_NAME }} + run: | + timeout=10 # seconds + start=$(date +%s) + until dig +short @127.0.0.1 -p 1054 ${ZONE_NAME} SOA | grep -q "ns.${ZONE_NAME} mail.${ZONE_NAME} 1 60 60 3600 5"; do + if (($(date +%s) > (start + timeout))); then + cascade zone status ${ZONE_NAME} + dig +short @127.0.0.1 -p 1054 ${ZONE_NAME} SOA + echo "::error:: timeout: NSD did not acquire the zone changes" + exit 1 + fi + sleep 1 + done + + - name: Edit and reload serial 2 of zone ${{ steps.set-vars.outputs.ZONE_NAME }} + env: + ZONE_NAME: ${{ steps.set-vars.outputs.ZONE_NAME }} + run: | + cat >"${ZONE_NAME}zone" < (start + timeout))); then + cascade zone status ${ZONE_NAME} + echo "timeout: zone status did not report published zone available" >&2 + exit 1 + fi + sleep 1 + done + + - name: Expect serial 2 of zone ${{ steps.set-vars.outputs.ZONE_NAME }} at the NSD secondary + env: + ZONE_NAME: ${{ steps.set-vars.outputs.ZONE_NAME }} + run: | + timeout=10 # seconds + start=$(date +%s) + until dig +short @127.0.0.1 -p 1054 ${ZONE_NAME} SOA | grep -q "ns.${ZONE_NAME} mail.${ZONE_NAME} 2 60 60 3600 5"; do + if (($(date +%s) > (start + timeout))); then + dig @127.0.0.1 -p 1054 ${ZONE_NAME} SOA + cascade zone status ${ZONE_NAME} + echo "::error:: timeout: NSD did not acquire the zone changes" + exit 1 + fi + sleep 1 + done + + - name: Edit and reload serial 3 of zone ${{ steps.set-vars.outputs.ZONE_NAME }} + env: + ZONE_NAME: ${{ steps.set-vars.outputs.ZONE_NAME }} + run: | + cat >"${ZONE_NAME}zone" < (start + timeout))); then + cascade zone status ${ZONE_NAME} + echo "timeout: zone status did not report published zone available" >&2 + exit 1 + fi + sleep 1 + done + + - name: Expect serial 3 of zone ${{ steps.set-vars.outputs.ZONE_NAME }} at the NSD secondary + env: + ZONE_NAME: ${{ steps.set-vars.outputs.ZONE_NAME }} + run: | + timeout=10 # seconds + start=$(date +%s) + until dig +short @127.0.0.1 -p 1054 ${ZONE_NAME} SOA | grep -q "ns.${ZONE_NAME} mail.${ZONE_NAME} 3 60 60 3600 5"; do + if (($(date +%s) > (start + timeout))); then + cascade zone status ${ZONE_NAME} + dig +short @127.0.0.1 -p 1054 ${ZONE_NAME} SOA + echo "::error:: timeout: NSD did not acquire the zone changes" + exit 1 + fi + sleep 1 + done + + # Note: There is no NSD metric that I am aware of that we can use to + # verify that it received IXFR from Cascade instead of AXFR, nor is there + # any Cascade Prometheus metric or CLI command that we can use to check + # this either. Increasing the NSD log level to 9 doesn't cause it to + # report whether it received IXFR or AXFR either. + + - name: Verify that TSIG is required by Cascade + env: + ZONE_NAME: ${{ steps.set-vars.outputs.ZONE_NAME }} + run: | + if [[ "${{ inputs.with-tsig }}" == "false" ]]; then + exit 0 + fi + + # This should not succeed as it lacks the required TSIG key. + # Note that dig will exit with code 0 even if the request fails, + # because it considers an error response still to be successful + # receipt of a response, so we have to check the actual output. + dig @127.0.0.1 +yaml -p 4542 ${ZONE_NAME} AXFR &> dig-no-tsig.log + grep -Fq "status: REFUSED" dig-no-tsig.log + + - name: Verify Cascade AXFR out + env: + ZONE_NAME: ${{ steps.set-vars.outputs.ZONE_NAME }} + run: | + EXTRA_ARGS= + if [[ "${{ inputs.with-tsig }}" == "true" ]]; then + EXTRA_ARGS="-y ${{ steps.set-vars.outputs.TSIG_SPEC }}" + fi + dig +onesoa +noall +answer @127.0.0.1 -p 4542 ${EXTRA_ARGS} ${ZONE_NAME} AXFR &> cascade-axfr.log + TEST_DIR="${PWD}/integration-tests/ixfr-out" + LC_COLLATE=C sort "${TEST_DIR}/reference-output/${ZONE_NAME}axfr" | egrep -v '^;|^$' > reference.output.sorted + LC_COLLATE=C sort cascade-axfr.log > output.sorted + diff -u -w output.sorted reference.output.sorted + + # A UDP IXFR request should result in a single SOA response "to inform the + # client that a TCP query should be initiated". + - name: Verify that UDP is not supported + env: + ZONE_NAME: ${{ steps.set-vars.outputs.ZONE_NAME }} + run: | + EXTRA_ARGS= + if [[ "${{ inputs.with-tsig }}" == "true" ]]; then + EXTRA_ARGS="-y ${{ steps.set-vars.outputs.TSIG_SPEC }}" + fi + SOA_RR=$(dig +short +notcp +ignore @127.0.0.1 -p 4542 ${ZONE_NAME} -t IXFR=1 ${EXTRA_ARGS} 2>&1 | tee dig-udp-ixfr.log) + if [[ "${SOA_RR}" != "ns.${ZONE_NAME} mail.${ZONE_NAME} 3 60 60 3600 5" ]]; then + exit 1 + fi + + - name: Verify Cascade IXFR serial 1..=3 out + env: + ZONE_NAME: ${{ steps.set-vars.outputs.ZONE_NAME }} + run: | + EXTRA_ARGS= + if [[ "${{ inputs.with-tsig }}" == "true" ]]; then + EXTRA_ARGS="-y ${{ steps.set-vars.outputs.TSIG_SPEC }}" + fi + dig +onesoa +noall +answer @127.0.0.1 -p 4542 ${ZONE_NAME} -t IXFR=1 ${EXTRA_ARGS} &> cascade-ixfr-1-3.log + TEST_DIR="${PWD}/integration-tests/ixfr-out" + LC_COLLATE=C sort "${TEST_DIR}/reference-output/${ZONE_NAME}ixfr-1-3" | egrep -v '^;|^$' > reference.output.sorted + LC_COLLATE=C sort cascade-ixfr-1-3.log > output.sorted + diff -u -w output.sorted reference.output.sorted + + - name: Verify Cascade IXFR serial 2..=3 out + env: + ZONE_NAME: ${{ steps.set-vars.outputs.ZONE_NAME }} + run: | + EXTRA_ARGS= + if [[ "${{ inputs.with-tsig }}" == "true" ]]; then + EXTRA_ARGS="-y ${{ steps.set-vars.outputs.TSIG_SPEC }}" + fi + dig +onesoa +noall +answer @127.0.0.1 -p 4542 ${ZONE_NAME} -t IXFR=2 ${EXTRA_ARGS} &> cascade-ixfr-2-3.log + TEST_DIR="${PWD}/integration-tests/ixfr-out" + LC_COLLATE=C sort "${TEST_DIR}/reference-output/${ZONE_NAME}ixfr-2-3" | egrep -v '^;|^$' > reference.output.sorted + LC_COLLATE=C sort cascade-ixfr-2-3.log > output.sorted + diff -u -w output.sorted reference.output.sorted + + - name: Verify Cascade IXFR serial 3..=3 out + env: + ZONE_NAME: ${{ steps.set-vars.outputs.ZONE_NAME }} + run: | + EXTRA_ARGS= + if [[ "${{ inputs.with-tsig }}" == "true" ]]; then + EXTRA_ARGS="-y ${{ steps.set-vars.outputs.TSIG_SPEC }}" + fi + dig +onesoa +noall +answer @127.0.0.1 -p 4542 ${ZONE_NAME} -t IXFR=3 ${EXTRA_ARGS} &> cascade-ixfr-3-3.log + TEST_DIR="${PWD}/integration-tests/ixfr-out" + LC_COLLATE=C sort "${TEST_DIR}/reference-output/${ZONE_NAME}ixfr-3-3" | egrep -v '^;|^$' > reference.output.sorted + LC_COLLATE=C sort cascade-ixfr-3-3.log > output.sorted + diff -u -w output.sorted reference.output.sorted + + - name: Verify NSD AXFR out + env: + ZONE_NAME: ${{ steps.set-vars.outputs.ZONE_NAME }} + run: | + dig +onesoa +noall +answer @127.0.0.1 -p 1054 ${ZONE_NAME} AXFR &> nsd-axfr.log + TEST_DIR="${PWD}/integration-tests/ixfr-out" + + # Pass -f to sort and -i to diff to normalize case in the Cascade and + # NSD output being compared, as NSD outputs lower case labels while + # Cascade preserves label case. -f tells sort not to order differently + # based on case, and -i tells diff to consider differing case to be + # equal. + + LC_COLLATE=C sort -f "${TEST_DIR}/reference-output/${ZONE_NAME}axfr" | egrep -v '^;|^$' > reference.output.sorted + LC_COLLATE=C sort -f nsd-axfr.log > output.sorted + diff -u -w -i output.sorted reference.output.sorted + + - name: Print log files on any failure in this job + uses: ./.github/actions/print-logfiles + if: failure()