2
0
mirror of https://gitlab.isc.org/isc-projects/bind9 synced 2025-08-29 05:28:00 +00:00

emit more helpful log for exceeding max-records-per-type

The new log message is emitted when adding or updating an RRset
fails due to exceeding the max-records-per-type limit. The log includes
the owner name and type, corresponding zone name, and the limit value.
It will be emitted on loading a zone file, inbound zone transfer
(both AXFR and IXFR), handling a DDNS update, or updating a cache DB.
It's especially helpful in the case of zone transfer, since the
secondary side doesn't have direct access to the offending zone data.

It could also be used for max-types-per-name, but this change
doesn't implement it yet as it's much less likely to happen
in practice.
This commit is contained in:
JINMEI Tatuya 2024-08-29 16:24:48 +09:00 committed by Mark Andrews
parent 8e0ec3fe0a
commit 4156995431
4 changed files with 54 additions and 0 deletions

View File

@ -36,6 +36,8 @@
#include <dns/clientinfo.h>
#include <dns/db.h>
#include <dns/master.h>
#include <dns/rdata.h>
#include <dns/rdataclass.h>
#include <dns/rdataset.h>
#include <dns/rdatasetiter.h>
@ -1179,3 +1181,25 @@ dns_db_setmaxtypepername(dns_db_t *db, uint32_t value) {
(db->methods->setmaxtypepername)(db, value);
}
}
void
dns__db_logtoomanyrecords(dns_db_t *db, const dns_name_t *name,
dns_rdatatype_t type, const char *op,
uint32_t limit) {
char namebuf[DNS_NAME_FORMATSIZE];
char originbuf[DNS_NAME_FORMATSIZE];
char typebuf[DNS_RDATATYPE_FORMATSIZE];
char clsbuf[DNS_RDATACLASS_FORMATSIZE];
dns_name_format(name, namebuf, sizeof(namebuf));
dns_name_format(&db->origin, originbuf, sizeof(originbuf));
dns_rdatatype_format(type, typebuf, sizeof(typebuf));
dns_rdataclass_format(db->rdclass, clsbuf, sizeof(clsbuf));
isc_log_write(
DNS_LOGCATEGORY_DATABASE, DNS_LOGMODULE_RBTDB, ISC_LOG_ERROR,
"error %s '%s/%s' in '%s/%s' (%s): %s (must not exceed %u)", op,
namebuf, typebuf, originbuf, clsbuf,
(db->attributes & DNS_DBATTR_CACHE) != 0 ? "cache" : "zone",
isc_result_totext(DNS_R_TOOMANYRECORDS), limit);
}

View File

@ -186,4 +186,13 @@ prio_type(dns_typepair_t type) {
return false;
}
void
dns__db_logtoomanyrecords(dns_db_t *db, const dns_name_t *name,
dns_rdatatype_t type, const char *op, uint32_t limit);
/*
* Emit a log message when adding an rdataset of name/type would exceed the
* 'maxrrperset' limit. 'op' is 'adding' or 'updating' depending on whether
* the addition is to create a new rdataset or to merge to an existing one.
*/
ISC_LANG_ENDDECLS

View File

@ -3412,6 +3412,11 @@ addrdataset(dns_db_t *db, dns_dbnode_t *node, dns_dbversion_t *version,
&region, sizeof(dns_slabheader_t),
qpdb->maxrrperset);
if (result != ISC_R_SUCCESS) {
if (result == DNS_R_TOOMANYRECORDS) {
dns__db_logtoomanyrecords((dns_db_t *)qpdb,
&qpnode->name, rdataset->type,
"adding", qpdb->maxrrperset);
}
return result;
}

View File

@ -1874,6 +1874,12 @@ add(qpzonedb_t *qpdb, qpznode_t *node, const dns_name_t *nodename,
header->resign_lsb;
}
} else {
if (result == DNS_R_TOOMANYRECORDS) {
dns__db_logtoomanyrecords(
(dns_db_t *)qpdb, nodename,
(dns_rdatatype_t)header->type,
"updating", qpdb->maxrrperset);
}
dns_slabheader_destroy(&newheader);
return result;
}
@ -2108,6 +2114,11 @@ loading_addrdataset(void *arg, const dns_name_t *name,
&region, sizeof(dns_slabheader_t),
qpdb->maxrrperset);
if (result != ISC_R_SUCCESS) {
if (result == DNS_R_TOOMANYRECORDS) {
dns__db_logtoomanyrecords((dns_db_t *)qpdb, name,
rdataset->type, "adding",
qpdb->maxrrperset);
}
return result;
}
@ -4604,6 +4615,11 @@ addrdataset(dns_db_t *db, dns_dbnode_t *dbnode, dns_dbversion_t *dbversion,
&region, sizeof(dns_slabheader_t),
qpdb->maxrrperset);
if (result != ISC_R_SUCCESS) {
if (result == DNS_R_TOOMANYRECORDS) {
dns__db_logtoomanyrecords((dns_db_t *)qpdb, &node->name,
rdataset->type, "adding",
qpdb->maxrrperset);
}
return result;
}