/
usr
/
include
/
bind9
/
dns
/
/usr/include/bind9/dns
mkdir
upload
Name
Size
Mode
Actions
acl.h
6477
0644
edit
dl
rm
adb.h
22267
0644
edit
dl
rm
badcache.h
3387
0644
edit
dl
rm
bit.h
798
0644
edit
dl
rm
byaddr.h
3598
0644
edit
dl
rm
cache.h
8730
0644
edit
dl
rm
callbacks.h
2280
0644
edit
dl
rm
catz.h
11881
0644
edit
dl
rm
cert.h
1465
0644
edit
dl
rm
client.h
14527
0644
edit
dl
rm
clientinfo.h
2015
0644
edit
dl
rm
compress.h
7047
0644
edit
dl
rm
db.h
50446
0644
edit
dl
rm
dbiterator.h
7385
0644
edit
dl
rm
dbtable.h
3167
0644
edit
dl
rm
diff.h
7039
0644
edit
dl
rm
dispatch.h
15538
0644
edit
dl
rm
dlz.h
10876
0644
edit
dl
rm
dlz_dlopen.h
4394
0644
edit
dl
rm
dns64.h
5720
0644
edit
dl
rm
dnsrps.h
2572
0644
edit
dl
rm
dnssec.h
12841
0644
edit
dl
rm
dnstap.h
10193
0644
edit
dl
rm
ds.h
1665
0644
edit
dl
rm
dsdigest.h
1713
0644
edit
dl
rm
dyndb.h
4869
0644
edit
dl
rm
ecdb.h
806
0644
edit
dl
rm
ecs.h
1250
0644
edit
dl
rm
edns.h
783
0644
edit
dl
rm
enumclass.h
1220
0644
edit
dl
rm
enumtype.h
8485
0644
edit
dl
rm
events.h
4451
0644
edit
dl
rm
fixedname.h
1652
0644
edit
dl
rm
forward.h
3060
0644
edit
dl
rm
geoip.h
2340
0644
edit
dl
rm
ipkeylist.h
2219
0644
edit
dl
rm
iptable.h
1521
0644
edit
dl
rm
journal.h
9712
0644
edit
dl
rm
kasp.h
12124
0644
edit
dl
rm
keydata.h
1047
0644
edit
dl
rm
keyflags.h
1277
0644
edit
dl
rm
keymgr.h
4107
0644
edit
dl
rm
keytable.h
7871
0644
edit
dl
rm
keyvalues.h
4083
0644
edit
dl
rm
lib.h
993
0644
edit
dl
rm
librpz.h
31401
0644
edit
dl
rm
lmdb.h
779
0644
edit
dl
rm
log.h
4029
0644
edit
dl
rm
lookup.h
2921
0644
edit
dl
rm
master.h
8786
0644
edit
dl
rm
masterdump.h
10133
0644
edit
dl
rm
message.h
39567
0644
edit
dl
rm
name.h
37781
0644
edit
dl
rm
ncache.h
4960
0644
edit
dl
rm
nsec.h
3065
0644
edit
dl
rm
nsec3.h
8258
0644
edit
dl
rm
nta.h
4846
0644
edit
dl
rm
opcode.h
1006
0644
edit
dl
rm
order.h
2010
0644
edit
dl
rm
peer.h
6475
0644
edit
dl
rm
portlist.h
2101
0644
edit
dl
rm
private.h
1962
0644
edit
dl
rm
rbt.h
37484
0644
edit
dl
rm
rcode.h
2472
0644
edit
dl
rm
rdata.h
22564
0644
edit
dl
rm
rdataclass.h
2248
0644
edit
dl
rm
rdatalist.h
2557
0644
edit
dl
rm
rdataset.h
18714
0644
edit
dl
rm
rdatasetiter.h
3912
0644
edit
dl
rm
rdataslab.h
4267
0644
edit
dl
rm
rdatastruct.h
62703
0644
edit
dl
rm
rdatatype.h
2290
0644
edit
dl
rm
request.h
9187
0644
edit
dl
rm
resolver.h
20152
0644
edit
dl
rm
result.h
9196
0644
edit
dl
rm
rootns.h
891
0644
edit
dl
rm
rpz.h
12156
0644
edit
dl
rm
rriterator.h
4214
0644
edit
dl
rm
rrl.h
6959
0644
edit
dl
rm
sdb.h
7350
0644
edit
dl
rm
sdlz.h
14090
0644
edit
dl
rm
secalg.h
1705
0644
edit
dl
rm
secproto.h
1556
0644
edit
dl
rm
soa.h
2179
0644
edit
dl
rm
ssu.h
7182
0644
edit
dl
rm
stats.h
24689
0644
edit
dl
rm
tcpmsg.h
3128
0644
edit
dl
rm
time.h
1693
0644
edit
dl
rm
timer.h
1050
0644
edit
dl
rm
tkey.h
7655
0644
edit
dl
rm
tsec.h
2946
0644
edit
dl
rm
tsig.h
8497
0644
edit
dl
rm
ttl.h
1876
0644
edit
dl
rm
types.h
14584
0644
edit
dl
rm
update.h
2004
0644
edit
dl
rm
validator.h
6679
0644
edit
dl
rm
version.h
679
0644
edit
dl
rm
view.h
35341
0644
edit
dl
rm
xfrin.h
2314
0644
edit
dl
rm
zone.h
65543
0644
edit
dl
rm
zonekey.h
776
0644
edit
dl
rm
zoneverify.h
1393
0644
edit
dl
rm
zt.h
5241
0644
edit
dl
rm
Edit:
/usr/include/bind9/dns/ssu.h
(7182B)
/* * Copyright (C) Internet Systems Consortium, Inc. ("ISC") * * This Source Code Form is subject to the terms of the Mozilla Public * License, v. 2.0. If a copy of the MPL was not distributed with this * file, you can obtain one at https://mozilla.org/MPL/2.0/. * * See the COPYRIGHT file distributed with this work for additional * information regarding copyright ownership. */ #ifndef DNS_SSU_H #define DNS_SSU_H 1 /*! \file dns/ssu.h */ #include <stdbool.h> #include <isc/lang.h> #include <dns/acl.h> #include <dns/types.h> #include <dst/dst.h> ISC_LANG_BEGINDECLS typedef enum { dns_ssumatchtype_name = 0, dns_ssumatchtype_subdomain = 1, dns_ssumatchtype_wildcard = 2, dns_ssumatchtype_self = 3, dns_ssumatchtype_selfsub = 4, dns_ssumatchtype_selfwild = 5, dns_ssumatchtype_selfkrb5 = 6, dns_ssumatchtype_selfms = 7, dns_ssumatchtype_subdomainms = 8, dns_ssumatchtype_subdomainkrb5 = 9, dns_ssumatchtype_tcpself = 10, dns_ssumatchtype_6to4self = 11, dns_ssumatchtype_external = 12, dns_ssumatchtype_local = 13, dns_ssumatchtype_selfsubms = 14, dns_ssumatchtype_selfsubkrb5 = 15, dns_ssumatchtype_max = 15, /* max value */ dns_ssumatchtype_dlz = 16 /* intentionally higher than _max */ } dns_ssumatchtype_t; isc_result_t dns_ssutable_create(isc_mem_t *mctx, dns_ssutable_t **table); /*%< * Creates a table that will be used to store simple-secure-update rules. * Note: all locking must be provided by the client. * * Requires: *\li 'mctx' is a valid memory context *\li 'table' is not NULL, and '*table' is NULL * * Returns: *\li ISC_R_SUCCESS *\li ISC_R_NOMEMORY */ isc_result_t dns_ssutable_createdlz(isc_mem_t *mctx, dns_ssutable_t **tablep, dns_dlzdb_t *dlzdatabase); /*%< * Create an SSU table that contains a dlzdatabase pointer, and a * single rule with matchtype dns_ssumatchtype_dlz. This type of SSU * table is used by writeable DLZ drivers to offload authorization for * updates to the driver. */ void dns_ssutable_attach(dns_ssutable_t *source, dns_ssutable_t **targetp); /*%< * Attach '*targetp' to 'source'. * * Requires: *\li 'source' is a valid SSU table *\li 'targetp' points to a NULL dns_ssutable_t *. * * Ensures: *\li *targetp is attached to source. */ void dns_ssutable_detach(dns_ssutable_t **tablep); /*%< * Detach '*tablep' from its simple-secure-update rule table. * * Requires: *\li 'tablep' points to a valid dns_ssutable_t * * Ensures: *\li *tablep is NULL *\li If '*tablep' is the last reference to the SSU table, all * resources used by the table will be freed. */ isc_result_t dns_ssutable_addrule(dns_ssutable_t *table, bool grant, const dns_name_t *identity, dns_ssumatchtype_t matchtype, const dns_name_t *name, unsigned int ntypes, dns_rdatatype_t *types); /*%< * Adds a new rule to a simple-secure-update rule table. The rule * either grants or denies update privileges of an identity (or set of * identities) to modify a name (or set of names) or certain types present * at that name. * * Notes: *\li If 'matchtype' is of SELF type, this rule only matches if the * name to be updated matches the signing identity. * *\li If 'ntypes' is 0, this rule applies to all types except * NS, SOA, RRSIG, and NSEC. * *\li If 'types' includes ANY, this rule applies to all types * except NSEC. * * Requires: *\li 'table' is a valid SSU table *\li 'identity' is a valid absolute name *\li 'matchtype' must be one of the defined constants. *\li 'name' is a valid absolute name *\li If 'ntypes' > 0, 'types' must not be NULL * * Returns: *\li ISC_R_SUCCESS *\li ISC_R_NOMEMORY */ bool dns_ssutable_checkrules(dns_ssutable_t *table, const dns_name_t *signer, const dns_name_t *name, const isc_netaddr_t *addr, bool tcp, const dns_aclenv_t *env, dns_rdatatype_t type, const dst_key_t *key); /*%< * Checks that the attempted update of (name, type) is allowed according * to the rules specified in the simple-secure-update rule table. If * no rules are matched, access is denied. * * Notes: * In dns_ssutable_checkrules(), 'addr' should only be * set if the request received via TCP. This provides a * weak assurance that the request was not spoofed. * 'addr' is to to validate dns_ssumatchtype_tcpself * and dns_ssumatchtype_6to4self rules. * * In dns_ssutable_checkrules2(), 'addr' can also be passed for * UDP requests and TCP is specified via the 'tcp' parameter. * In addition to dns_ssumatchtype_tcpself and * tcp_ssumatchtype_6to4self rules, the address * also be used to check dns_ssumatchtype_local rules. * If 'addr' is set then 'env' must also be set so that * requests from non-localhost addresses can be rejected. * * For dns_ssumatchtype_tcpself the addresses are mapped to * the standard reverse names under IN-ADDR.ARPA and IP6.ARPA. * RFC 1035, Section 3.5, "IN-ADDR.ARPA domain" and RFC 3596, * Section 2.5, "IP6.ARPA Domain". * * For dns_ssumatchtype_6to4self, IPv4 address are converted * to a 6to4 prefix (48 bits) per the rules in RFC 3056. Only * the top 48 bits of the IPv6 address are mapped to the reverse * name. This is independent of whether the most significant 16 * bits match 2002::/16, assigned for 6to4 prefixes, or not. * * Requires: *\li 'table' is a valid SSU table *\li 'signer' is NULL or a valid absolute name *\li 'addr' is NULL or a valid network address. *\li 'aclenv' is NULL or a valid ACL environment. *\li 'name' is a valid absolute name *\li if 'addr' is not NULL, 'env' is not NULL. */ /*% Accessor functions to extract rule components */ bool dns_ssurule_isgrant(const dns_ssurule_t *rule); /*% Accessor functions to extract rule components */ dns_name_t * dns_ssurule_identity(const dns_ssurule_t *rule); /*% Accessor functions to extract rule components */ unsigned int dns_ssurule_matchtype(const dns_ssurule_t *rule); /*% Accessor functions to extract rule components */ dns_name_t * dns_ssurule_name(const dns_ssurule_t *rule); /*% Accessor functions to extract rule components */ unsigned int dns_ssurule_types(const dns_ssurule_t *rule, dns_rdatatype_t **types); isc_result_t dns_ssutable_firstrule(const dns_ssutable_t *table, dns_ssurule_t **rule); /*%< * Initiates a rule iterator. There is no need to maintain any state. * * Returns: *\li #ISC_R_SUCCESS *\li #ISC_R_NOMORE */ isc_result_t dns_ssutable_nextrule(dns_ssurule_t *rule, dns_ssurule_t **nextrule); /*%< * Returns the next rule in the table. * * Returns: *\li #ISC_R_SUCCESS *\li #ISC_R_NOMORE */ bool dns_ssu_external_match(const dns_name_t *identity, const dns_name_t *signer, const dns_name_t *name, const isc_netaddr_t *tcpaddr, dns_rdatatype_t type, const dst_key_t *key, isc_mem_t *mctx); /*%< * Check a policy rule via an external application */ isc_result_t dns_ssu_mtypefromstring(const char *str, dns_ssumatchtype_t *mtype); /*%< * Set 'mtype' from 'str' * * Requires: *\li 'str' is not NULL. *\li 'mtype' is not NULL, * * Returns: *\li #ISC_R_SUCCESS *\li #ISC_R_NOTFOUND */ ISC_LANG_ENDDECLS #endif /* DNS_SSU_H */
Save
cmd:
run