untrusted comment: verify with openbsd-79-base.pub RWTSdNN9A3yvWK5IRBq/xmDLWNasEPbbpQiRb0XCG2tP6CTpLGyTBtS24E3Vu1MwNw9yXFVHmcvpH1Svk7LFeUKc1kJoix1qrw4= OpenBSD 7.9 errata 022, September 30, 2026: Update nsd(8) to version 4.15.2. CVE-2026-12244 CVE-2026-12245 CVE-2026-12246 CVE-2026-12490 CVE-2026-18664 CVE-2026-18916 CVE-2026-19401 CVE-2026-19538 Apply by doing: signify -Vep /etc/signify/openbsd-79-base.pub -x 022_nsd.patch.sig \ -m - | (cd /usr/src && patch -p0) And then rebuild and install nsd: cd /usr/src/usr.sbin/nsd make -f Makefile.bsd-wrapper obj make -f Makefile.bsd-wrapper clean make -f Makefile.bsd-wrapper make -f Makefile.bsd-wrapper install Index: usr.sbin/nsd/README.md =================================================================== RCS file: /cvs/src/usr.sbin/nsd/README.md,v diff -u -p -r1.4 README.md --- usr.sbin/nsd/README.md 21 Mar 2026 21:36:36 -0000 1.4 +++ usr.sbin/nsd/README.md 21 Sep 2026 16:28:41 -0000 @@ -11,8 +11,7 @@ It has been developed for operations in reliability, stability and security are of high importance. If you have any feedback, we would love to hear from you. Don’t hesitate to [create an issue on Github](https://github.com/NLnetLabs/nsd/issues/new) -or post a message on the -[NSD mailing list](https://lists.nlnetlabs.nl/mailman/listinfo/nsd-users). +or post a message on our [community forum](https://community.nlnetlabs.nl/). You can learn more about NSD by reading our [documentation](https://nsd.docs.nlnetlabs.nl/). Index: usr.sbin/nsd/aclocal.m4 =================================================================== RCS file: /cvs/src/usr.sbin/nsd/aclocal.m4,v diff -u -p -r1.6 aclocal.m4 --- usr.sbin/nsd/aclocal.m4 6 Sep 2025 17:41:37 -0000 1.6 +++ usr.sbin/nsd/aclocal.m4 21 Sep 2026 16:28:41 -0000 @@ -1,6 +1,6 @@ -# generated automatically by aclocal 1.18.1 -*- Autoconf -*- +# generated automatically by aclocal 1.16.5 -*- Autoconf -*- -# Copyright (C) 1996-2025 Free Software Foundation, Inc. +# Copyright (C) 1996-2021 Free Software Foundation, Inc. # This file is free software; the Free Software Foundation # gives unlimited permission to copy and/or distribute it, @@ -13,7 +13,7 @@ m4_ifndef([AC_CONFIG_MACRO_DIRS], [m4_defun([_AM_CONFIG_MACRO_DIRS], [])m4_defun([AC_CONFIG_MACRO_DIRS], [_AM_CONFIG_MACRO_DIRS($@)])]) # pkg.m4 - Macros to locate and use pkg-config. -*- Autoconf -*- -# serial 13 (pkgconf) +# serial 12 (pkg-config-0.29.2) dnl Copyright © 2004 Scott James Remnant . dnl Copyright © 2012-2015 Dan Nicholson @@ -29,7 +29,9 @@ dnl MERCHANTABILITY or FITNESS FOR A PAR dnl General Public License for more details. dnl dnl You should have received a copy of the GNU General Public License -dnl along with this program; if not, see . +dnl along with this program; if not, write to the Free Software +dnl Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA +dnl 02111-1307, USA. dnl dnl As a special exception to the GNU General Public License, if you dnl distribute this file as part of a program that contains a @@ -58,8 +60,8 @@ m4_if(m4_version_compare(PKG_MACROS_VERS [m4_fatal([pkg.m4 version $1 or higher is required but ]PKG_MACROS_VERSION[ found])]) ])dnl PKG_PREREQ -dnl PKG_PROG_PKG_CONFIG([MIN-VERSION], [ACTION-IF-NOT-FOUND]) -dnl --------------------------------------------------------- +dnl PKG_PROG_PKG_CONFIG([MIN-VERSION]) +dnl ---------------------------------- dnl Since: 0.16 dnl dnl Search for the pkg-config tool and set the PKG_CONFIG variable to @@ -67,12 +69,6 @@ dnl first found in the path. Checks that dnl is at least MIN-VERSION. If MIN-VERSION is not specified, 0.9.0 is dnl used since that's the first version where most current features of dnl pkg-config existed. -dnl -dnl If pkg-config is not found or older than specified, it will result -dnl in an empty PKG_CONFIG variable. To avoid widespread issues with -dnl scripts not checking it, ACTION-IF-NOT-FOUND defaults to aborting. -dnl You can specify [PKG_CONFIG=false] as an action instead, which would -dnl result in pkg-config tests failing, but no bogus error messages. AC_DEFUN([PKG_PROG_PKG_CONFIG], [m4_pattern_forbid([^_?PKG_[A-Z_]+$]) m4_pattern_allow([^PKG_CONFIG(_(PATH|LIBDIR|SYSROOT_DIR|ALLOW_SYSTEM_(CFLAGS|LIBS)))?$]) @@ -93,9 +89,6 @@ if test -n "$PKG_CONFIG"; then AC_MSG_RESULT([no]) PKG_CONFIG="" fi -fi -if test -z "$PKG_CONFIG"; then - m4_default([$2], [AC_MSG_ERROR([pkg-config not found])]) fi[]dnl ])dnl PKG_PROG_PKG_CONFIG Index: usr.sbin/nsd/axfr.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/axfr.c,v diff -u -p -r1.25 axfr.c --- usr.sbin/nsd/axfr.c 21 Mar 2026 21:36:36 -0000 1.25 +++ usr.sbin/nsd/axfr.c 21 Sep 2026 16:28:41 -0000 @@ -79,7 +79,12 @@ query_axfr(struct nsd *nsd, struct query query_add_compression_domain(query, qdomain, QHEADERSZ); - assert(query->axfr_zone->soa_rrset->rr_count == 1); + if(query->axfr_zone->soa_rrset->rr_count != 1) { + VERBOSITY(2, (LOG_INFO, "axfr: zone %s soa rr count %u (expected 1), servfail for AXFR-out", domain_to_string(query->axfr_zone->apex), + (unsigned)query->axfr_zone->soa_rrset->rr_count)); + RCODE_SET(query->packet, RCODE_SERVFAIL); + return QUERY_PROCESSED; + } added = packet_encode_rr(query, query->axfr_zone->apex, query->axfr_zone->soa_rrset->rrs[0], @@ -135,8 +140,20 @@ query_axfr(struct nsd *nsd, struct query } } } - if (!added) + if (!added) { + if(total_added == 0) { + /* RR wire encoding exceeds TCP_MAX_MESSAGE_LEN; cannot transmit. */ + char apexstr[MAXDOMAINLEN * 5]; + domain_to_string_buf(query->axfr_zone->apex, apexstr); + VERBOSITY(2, (LOG_ERR, "axfr: RR at %s in zone %s too large for any DNS message " + "(wire encoding exceeds %d bytes), aborting transfer", + domain_to_string(query->axfr_current_rrset->rrs[query->axfr_current_rr]->owner), + apexstr, TCP_MAX_MESSAGE_LEN)); + RCODE_SET(query->packet, RCODE_SERVFAIL); + query->axfr_is_done = 1; + } goto return_answer; + } ++total_added; ++query->axfr_current_rr; } @@ -151,7 +168,6 @@ query_axfr(struct nsd *nsd, struct query } /* Add terminating SOA RR. */ - assert(query->axfr_zone->soa_rrset->rr_count == 1); added = packet_encode_rr(query, query->axfr_zone->apex, query->axfr_zone->soa_rrset->rrs[0], Index: usr.sbin/nsd/buffer.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/buffer.h,v diff -u -p -r1.5 buffer.h --- usr.sbin/nsd/buffer.h 3 Sep 2025 18:46:48 -0000 1.5 +++ usr.sbin/nsd/buffer.h 21 Sep 2026 16:28:41 -0000 @@ -260,6 +260,14 @@ buffer_write(buffer_type *buffer, const buffer->_position += count; } +static inline void +buffer_fill(buffer_type *buffer, const int c, size_t count) +{ + assert(buffer_available_at(buffer, buffer->_position, count)); + memset(buffer->_data + buffer->_position, c, count); + buffer->_position += count; +} + static inline int try_buffer_write_at(buffer_type *buffer, size_t at, const void *data, size_t count) { Index: usr.sbin/nsd/config.guess =================================================================== RCS file: /cvs/src/usr.sbin/nsd/config.guess,v diff -u -p -r1.5 config.guess --- usr.sbin/nsd/config.guess 6 Sep 2025 17:41:37 -0000 1.5 +++ usr.sbin/nsd/config.guess 21 Sep 2026 16:28:41 -0000 @@ -1,10 +1,10 @@ #! /bin/sh # Attempt to guess a canonical system name. -# Copyright 1992-2023 Free Software Foundation, Inc. +# Copyright 1992-2022 Free Software Foundation, Inc. # shellcheck disable=SC2006,SC2268 # see below for rationale -timestamp='2023-08-22' +timestamp='2022-01-09' # This file is free software; you can redistribute it and/or modify it # under the terms of the GNU General Public License as published by @@ -47,7 +47,7 @@ me=`echo "$0" | sed -e 's,.*/,,'` usage="\ Usage: $0 [OPTION] -Output the configuration name of the system '$me' is run on. +Output the configuration name of the system \`$me' is run on. Options: -h, --help print this help, then exit @@ -60,13 +60,13 @@ version="\ GNU config.guess ($timestamp) Originally written by Per Bothner. -Copyright 1992-2023 Free Software Foundation, Inc. +Copyright 1992-2022 Free Software Foundation, Inc. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE." help=" -Try '$me --help' for more information." +Try \`$me --help' for more information." # Parse command line while test $# -gt 0 ; do @@ -102,8 +102,8 @@ GUESS= # temporary files to be created and, as you can see below, it is a # headache to deal with in a portable fashion. -# Historically, 'CC_FOR_BUILD' used to be named 'HOST_CC'. We still -# use 'HOST_CC' if defined, but it is deprecated. +# Historically, `CC_FOR_BUILD' used to be named `HOST_CC'. We still +# use `HOST_CC' if defined, but it is deprecated. # Portable tmp directory creation inspired by the Autoconf team. @@ -155,9 +155,6 @@ Linux|GNU|GNU/*) set_cc_for_build cat <<-EOF > "$dummy.c" - #if defined(__ANDROID__) - LIBC=android - #else #include #if defined(__UCLIBC__) LIBC=uclibc @@ -172,7 +169,6 @@ Linux|GNU|GNU/*) LIBC=musl #endif #endif - #endif EOF cc_set_libc=`$CC_FOR_BUILD -E "$dummy.c" 2>/dev/null | grep '^LIBC' | sed 's, ,,g'` eval "$cc_set_libc" @@ -463,7 +459,7 @@ case $UNAME_MACHINE:$UNAME_SYSTEM:$UNAME UNAME_RELEASE=`uname -v` ;; esac - # Japanese Language versions have a version number like '4.1.3-JL'. + # Japanese Language versions have a version number like `4.1.3-JL'. SUN_REL=`echo "$UNAME_RELEASE" | sed -e 's/-/_/'` GUESS=sparc-sun-sunos$SUN_REL ;; @@ -908,7 +904,7 @@ EOF fi ;; *:FreeBSD:*:*) - UNAME_PROCESSOR=`uname -p` + UNAME_PROCESSOR=`/usr/bin/uname -p` case $UNAME_PROCESSOR in amd64) UNAME_PROCESSOR=x86_64 ;; @@ -970,37 +966,11 @@ EOF GNU_REL=`echo "$UNAME_RELEASE" | sed -e 's/[-(].*//'` GUESS=$UNAME_MACHINE-unknown-$GNU_SYS$GNU_REL-$LIBC ;; - x86_64:[Mm]anagarm:*:*|i?86:[Mm]anagarm:*:*) - GUESS="$UNAME_MACHINE-pc-managarm-mlibc" - ;; - *:[Mm]anagarm:*:*) - GUESS="$UNAME_MACHINE-unknown-managarm-mlibc" - ;; *:Minix:*:*) GUESS=$UNAME_MACHINE-unknown-minix ;; aarch64:Linux:*:*) - set_cc_for_build - CPU=$UNAME_MACHINE - LIBCABI=$LIBC - if test "$CC_FOR_BUILD" != no_compiler_found; then - ABI=64 - sed 's/^ //' << EOF > "$dummy.c" - #ifdef __ARM_EABI__ - #ifdef __ARM_PCS_VFP - ABI=eabihf - #else - ABI=eabi - #endif - #endif -EOF - cc_set_abi=`$CC_FOR_BUILD -E "$dummy.c" 2>/dev/null | grep '^ABI' | sed 's, ,,g'` - eval "$cc_set_abi" - case $ABI in - eabi | eabihf) CPU=armv8l; LIBCABI=$LIBC$ABI ;; - esac - fi - GUESS=$CPU-unknown-linux-$LIBCABI + GUESS=$UNAME_MACHINE-unknown-linux-$LIBC ;; aarch64_be:Linux:*:*) UNAME_MACHINE=aarch64_be @@ -1066,16 +1036,7 @@ EOF k1om:Linux:*:*) GUESS=$UNAME_MACHINE-unknown-linux-$LIBC ;; - kvx:Linux:*:*) - GUESS=$UNAME_MACHINE-unknown-linux-$LIBC - ;; - kvx:cos:*:*) - GUESS=$UNAME_MACHINE-unknown-cos - ;; - kvx:mbr:*:*) - GUESS=$UNAME_MACHINE-unknown-mbr - ;; - loongarch32:Linux:*:* | loongarch64:Linux:*:*) + loongarch32:Linux:*:* | loongarch64:Linux:*:* | loongarchx32:Linux:*:*) GUESS=$UNAME_MACHINE-unknown-linux-$LIBC ;; m32r*:Linux:*:*) @@ -1190,27 +1151,16 @@ EOF ;; x86_64:Linux:*:*) set_cc_for_build - CPU=$UNAME_MACHINE LIBCABI=$LIBC if test "$CC_FOR_BUILD" != no_compiler_found; then - ABI=64 - sed 's/^ //' << EOF > "$dummy.c" - #ifdef __i386__ - ABI=x86 - #else - #ifdef __ILP32__ - ABI=x32 - #endif - #endif -EOF - cc_set_abi=`$CC_FOR_BUILD -E "$dummy.c" 2>/dev/null | grep '^ABI' | sed 's, ,,g'` - eval "$cc_set_abi" - case $ABI in - x86) CPU=i686 ;; - x32) LIBCABI=${LIBC}x32 ;; - esac + if (echo '#ifdef __ILP32__'; echo IS_X32; echo '#endif') | \ + (CCOPTS="" $CC_FOR_BUILD -E - 2>/dev/null) | \ + grep IS_X32 >/dev/null + then + LIBCABI=${LIBC}x32 + fi fi - GUESS=$CPU-pc-linux-$LIBCABI + GUESS=$UNAME_MACHINE-pc-linux-$LIBCABI ;; xtensa*:Linux:*:*) GUESS=$UNAME_MACHINE-unknown-linux-$LIBC @@ -1230,7 +1180,7 @@ EOF GUESS=$UNAME_MACHINE-pc-sysv4.2uw$UNAME_VERSION ;; i*86:OS/2:*:*) - # If we were able to find 'uname', then EMX Unix compatibility + # If we were able to find `uname', then EMX Unix compatibility # is probably installed. GUESS=$UNAME_MACHINE-pc-os2-emx ;; @@ -1371,7 +1321,7 @@ EOF GUESS=ns32k-sni-sysv fi ;; - PENTIUM:*:4.0*:*) # Unisys 'ClearPath HMP IX 4000' SVR4/MP effort + PENTIUM:*:4.0*:*) # Unisys `ClearPath HMP IX 4000' SVR4/MP effort # says GUESS=i586-unisys-sysv4 ;; @@ -1417,11 +1367,8 @@ EOF BePC:Haiku:*:*) # Haiku running on Intel PC compatible. GUESS=i586-pc-haiku ;; - ppc:Haiku:*:*) # Haiku running on Apple PowerPC - GUESS=powerpc-apple-haiku - ;; - *:Haiku:*:*) # Haiku modern gcc (not bound by BeOS compat) - GUESS=$UNAME_MACHINE-unknown-haiku + x86_64:Haiku:*:*) + GUESS=x86_64-unknown-haiku ;; SX-4:SUPER-UX:*:*) GUESS=sx4-nec-superux$UNAME_RELEASE Index: usr.sbin/nsd/config.h.in =================================================================== RCS file: /cvs/src/usr.sbin/nsd/config.h.in,v diff -u -p -r1.47 config.h.in --- usr.sbin/nsd/config.h.in 21 Mar 2026 21:36:36 -0000 1.47 +++ usr.sbin/nsd/config.h.in 21 Sep 2026 16:28:41 -0000 @@ -46,22 +46,22 @@ /* Define to the default facility for syslog. */ #undef FACILITY -/* Define to 1 if you have the 'accept4' function. */ +/* Define to 1 if you have the `accept4' function. */ #undef HAVE_ACCEPT4 -/* Define to 1 if you have the 'alarm' function. */ +/* Define to 1 if you have the `alarm' function. */ #undef HAVE_ALARM -/* Define to 1 if you have the 'arc4random' function. */ +/* Define to 1 if you have the `arc4random' function. */ #undef HAVE_ARC4RANDOM -/* Define to 1 if you have the 'arc4random_uniform' function. */ +/* Define to 1 if you have the `arc4random_uniform' function. */ #undef HAVE_ARC4RANDOM_UNIFORM /* Define to 1 if you have the header file. */ #undef HAVE_ARPA_INET_H -/* Define to 1 if you have the 'ASN1_STRING_get0_data' function. */ +/* Define to 1 if you have the `ASN1_STRING_get0_data' function. */ #undef HAVE_ASN1_STRING_GET0_DATA /* Whether the C compiler accepts the "format" attribute */ @@ -76,148 +76,148 @@ /* Whether the C compiler accepts the "weak" attribute */ #undef HAVE_ATTR_WEAK -/* Define to 1 if you have the 'b64_ntop' function. */ +/* Define to 1 if you have the `b64_ntop' function. */ #undef HAVE_B64_NTOP -/* Define to 1 if you have the 'b64_pton' function. */ +/* Define to 1 if you have the `b64_pton' function. */ #undef HAVE_B64_PTON -/* Define to 1 if you have the 'basename' function. */ +/* Define to 1 if you have the `basename' function. */ #undef HAVE_BASENAME -/* Define to 1 if your system has a working 'chown' function. */ +/* Define to 1 if your system has a working `chown' function. */ #undef HAVE_CHOWN -/* Define to 1 if you have the 'chroot' function. */ +/* Define to 1 if you have the `chroot' function. */ #undef HAVE_CHROOT -/* Define to 1 if you have the 'clock_gettime' function. */ +/* Define to 1 if you have the `clock_gettime' function. */ #undef HAVE_CLOCK_GETTIME -/* Define to 1 if the system has the type 'cpuid_t'. */ +/* Define to 1 if the system has the type `cpuid_t'. */ #undef HAVE_CPUID_T -/* Define to 1 if the system has the type 'cpuset_t'. */ +/* Define to 1 if the system has the type `cpuset_t'. */ #undef HAVE_CPUSET_T -/* Define to 1 if the system has the type 'cpu_set_t'. */ +/* Define to 1 if the system has the type `cpu_set_t'. */ #undef HAVE_CPU_SET_T -/* Define to 1 if you have the 'CRYPTO_memcmp' function. */ +/* Define to 1 if you have the `CRYPTO_memcmp' function. */ #undef HAVE_CRYPTO_MEMCMP /* if time.h provides ctime_r prototype */ #undef HAVE_CTIME_R_PROTO -/* Define to 1 if you have the declaration of 'reallocarray', and to 0 if you +/* Define to 1 if you have the declaration of `reallocarray', and to 0 if you don't. */ #undef HAVE_DECL_REALLOCARRAY -/* Define to 1 if you have the declaration of 'SSL_CTX_set_ecdh_auto', and to +/* Define to 1 if you have the declaration of `SSL_CTX_set_ecdh_auto', and to 0 if you don't. */ #undef HAVE_DECL_SSL_CTX_SET_ECDH_AUTO -/* Define to 1 if you have the declaration of 'SSL_CTX_set_tmp_ecdh', and to 0 +/* Define to 1 if you have the declaration of `SSL_CTX_set_tmp_ecdh', and to 0 if you don't. */ #undef HAVE_DECL_SSL_CTX_SET_TMP_ECDH -/* Define to 1 if you have the 'dup2' function. */ +/* Define to 1 if you have the `dup2' function. */ #undef HAVE_DUP2 -/* Define to 1 if you have the 'EC_KEY_new_by_curve_name' function. */ +/* Define to 1 if you have the `EC_KEY_new_by_curve_name' function. */ #undef HAVE_EC_KEY_NEW_BY_CURVE_NAME /* Define to 1 if you have the header file. */ #undef HAVE_ENDIAN_H -/* Define to 1 if you have the 'endpwent' function. */ +/* Define to 1 if you have the `endpwent' function. */ #undef HAVE_ENDPWENT -/* Define to 1 if you have the 'ERR_load_crypto_strings' function. */ +/* Define to 1 if you have the `ERR_load_crypto_strings' function. */ #undef HAVE_ERR_LOAD_CRYPTO_STRINGS -/* Define to 1 if you have the 'ERR_load_SSL_strings' function. */ +/* Define to 1 if you have the `ERR_load_SSL_strings' function. */ #undef HAVE_ERR_LOAD_SSL_STRINGS -/* Define to 1 if you have the 'event_base_free' function. */ +/* Define to 1 if you have the `event_base_free' function. */ #undef HAVE_EVENT_BASE_FREE -/* Define to 1 if you have the 'event_base_get_method' function. */ +/* Define to 1 if you have the `event_base_get_method' function. */ #undef HAVE_EVENT_BASE_GET_METHOD -/* Define to 1 if you have the 'event_base_new' function. */ +/* Define to 1 if you have the `event_base_new' function. */ #undef HAVE_EVENT_BASE_NEW -/* Define to 1 if you have the 'event_base_once' function. */ +/* Define to 1 if you have the `event_base_once' function. */ #undef HAVE_EVENT_BASE_ONCE /* Define to 1 if you have the header file. */ #undef HAVE_EVENT_H -/* Define to 1 if you have the 'evhttp_free' function. */ +/* Define to 1 if you have the `evhttp_free' function. */ #undef HAVE_EVHTTP_FREE -/* Define to 1 if you have the 'EVP_cleanup' function. */ +/* Define to 1 if you have the `EVP_cleanup' function. */ #undef HAVE_EVP_CLEANUP -/* Define to 1 if you have the 'EVP_MAC_CTX_get_mac_size' function. */ +/* Define to 1 if you have the `EVP_MAC_CTX_get_mac_size' function. */ #undef HAVE_EVP_MAC_CTX_GET_MAC_SIZE -/* Define to 1 if you have the 'EVP_MAC_CTX_new' function. */ +/* Define to 1 if you have the `EVP_MAC_CTX_new' function. */ #undef HAVE_EVP_MAC_CTX_NEW -/* Define to 1 if you have the 'EVP_MAC_CTX_set_params' function. */ +/* Define to 1 if you have the `EVP_MAC_CTX_set_params' function. */ #undef HAVE_EVP_MAC_CTX_SET_PARAMS -/* Define to 1 if you have the 'EVP_PKEY_get0_type_name' function. */ +/* Define to 1 if you have the `EVP_PKEY_get0_type_name' function. */ #undef HAVE_EVP_PKEY_GET0_TYPE_NAME -/* Define to 1 if you have the 'ev_default_loop' function. */ +/* Define to 1 if you have the `ev_default_loop' function. */ #undef HAVE_EV_DEFAULT_LOOP -/* Define to 1 if you have the 'ev_loop' function. */ +/* Define to 1 if you have the `ev_loop' function. */ #undef HAVE_EV_LOOP -/* Define to 1 if you have the 'explicit_bzero' function. */ +/* Define to 1 if you have the `explicit_bzero' function. */ #undef HAVE_EXPLICIT_BZERO /* Define to 1 if you have the header file. */ #undef HAVE_FCNTL_H -/* Define to 1 if you have the 'fork' function. */ +/* Define to 1 if you have the `fork' function. */ #undef HAVE_FORK -/* Define to 1 if you have the 'freeaddrinfo' function. */ +/* Define to 1 if you have the `freeaddrinfo' function. */ #undef HAVE_FREEADDRINFO -/* Define to 1 if fseeko (and ftello) are declared in stdio.h. */ +/* Define to 1 if fseeko (and presumably ftello) exists and is declared. */ #undef HAVE_FSEEKO -/* Define to 1 if you have the 'fstrm_tcp_writer_options_init' function. */ +/* Define to 1 if you have the `fstrm_tcp_writer_options_init' function. */ #undef HAVE_FSTRM_TCP_WRITER_OPTIONS_INIT -/* Define to 1 if you have the 'gai_strerror' function. */ +/* Define to 1 if you have the `gai_strerror' function. */ #undef HAVE_GAI_STRERROR -/* Define to 1 if you have the 'getaddrinfo' function. */ +/* Define to 1 if you have the `getaddrinfo' function. */ #undef HAVE_GETADDRINFO -/* Define to 1 if you have the 'gethostname' function. */ +/* Define to 1 if you have the `gethostname' function. */ #undef HAVE_GETHOSTNAME -/* Define to 1 if you have the 'getifaddrs' function. */ +/* Define to 1 if you have the `getifaddrs' function. */ #undef HAVE_GETIFADDRS -/* Define to 1 if you have the 'getnameinfo' function. */ +/* Define to 1 if you have the `getnameinfo' function. */ #undef HAVE_GETNAMEINFO -/* Define to 1 if you have the 'getpwnam' function. */ +/* Define to 1 if you have the `getpwnam' function. */ #undef HAVE_GETPWNAM -/* Define to 1 if you have the 'getrandom' function. */ +/* Define to 1 if you have the `getrandom' function. */ #undef HAVE_GETRANDOM -/* Define to 1 if you have the 'glob' function. */ +/* Define to 1 if you have the `glob' function. */ #undef HAVE_GLOB /* Define to 1 if you have the header file. */ @@ -226,65 +226,65 @@ /* Define to 1 if you have the header file. */ #undef HAVE_GRP_H -/* Define to 1 if you have the 'HMAC_CTX_new' function. */ +/* Define to 1 if you have the `HMAC_CTX_new' function. */ #undef HAVE_HMAC_CTX_NEW -/* Define to 1 if you have the 'HMAC_CTX_reset' function. */ +/* Define to 1 if you have the `HMAC_CTX_reset' function. */ #undef HAVE_HMAC_CTX_RESET /* Define to 1 if you have the header file. */ #undef HAVE_IFADDRS_H -/* Define to 1 if you have the 'inet_aton' function. */ +/* Define to 1 if you have the `inet_aton' function. */ #undef HAVE_INET_ATON -/* Define to 1 if you have the 'inet_ntop' function. */ +/* Define to 1 if you have the `inet_ntop' function. */ #undef HAVE_INET_NTOP -/* Define to 1 if you have the 'inet_pton' function. */ +/* Define to 1 if you have the `inet_pton' function. */ #undef HAVE_INET_PTON -/* Define to 1 if you have the 'initgroups' function. */ +/* Define to 1 if you have the `initgroups' function. */ #undef HAVE_INITGROUPS /* Define to 1 if you have the header file. */ #undef HAVE_INTTYPES_H -/* Define to 1 if you have the 'crypto' library (-lcrypto). */ +/* Define to 1 if you have the `crypto' library (-lcrypto). */ #undef HAVE_LIBCRYPTO /* Define to 1 if you have the header file. */ #undef HAVE_LIMITS_H -/* Define to 1 if you have the 'localtime_r' function. */ +/* Define to 1 if you have the `localtime_r' function. */ #undef HAVE_LOCALTIME_R /* Define to 1 if you have the header file. */ #undef HAVE_LOGIN_CAP_H -/* Define to 1 if your system has a GNU libc compatible 'malloc' function, and +/* Define to 1 if your system has a GNU libc compatible `malloc' function, and to 0 otherwise. */ #undef HAVE_MALLOC -/* Define to 1 if you have the 'memcpy' function. */ +/* Define to 1 if you have the `memcpy' function. */ #undef HAVE_MEMCPY -/* Define to 1 if you have the 'memmove' function. */ +/* Define to 1 if you have the `memmove' function. */ #undef HAVE_MEMMOVE -/* Define to 1 if you have the 'memset' function. */ +/* Define to 1 if you have the `memset' function. */ #undef HAVE_MEMSET /* Define to 1 if you have the header file. */ #undef HAVE_MINIX_CONFIG_H -/* Define to 1 if you have the 'mmap' function. */ +/* Define to 1 if you have the `mmap' function. */ #undef HAVE_MMAP /* If sys/socket.h has a struct mmsghdr. */ #undef HAVE_MMSGHDR -/* Define to 1 if you have the 'munmap' function. */ +/* Define to 1 if you have the `munmap' function. */ #undef HAVE_MUNMAP /* Define to 1 if you have the header file. */ @@ -302,10 +302,10 @@ /* Define to 1 if you have the header file. */ #undef HAVE_OPENSSL_ERR_H -/* Define to 1 if you have the 'OPENSSL_init_crypto' function. */ +/* Define to 1 if you have the `OPENSSL_init_crypto' function. */ #undef HAVE_OPENSSL_INIT_CRYPTO -/* Define to 1 if you have the 'OPENSSL_init_ssl' function. */ +/* Define to 1 if you have the `OPENSSL_init_ssl' function. */ #undef HAVE_OPENSSL_INIT_SSL /* Define to 1 if you have the header file. */ @@ -320,16 +320,16 @@ /* Define to 1 if you have the header file. */ #undef HAVE_OPENSSL_X509V3_H -/* Define to 1 if you have the 'ppoll' function. */ +/* Define to 1 if you have the `ppoll' function. */ #undef HAVE_PPOLL -/* Define to 1 if you have the 'pselect' function. */ +/* Define to 1 if you have the `pselect' function. */ #undef HAVE_PSELECT /* if sys/select.h provides pselect prototype */ #undef HAVE_PSELECT_PROTO -/* Define to 1 if you have the 'pwrite' function. */ +/* Define to 1 if you have the `pwrite' function. */ #undef HAVE_PWRITE /* If we have reallocarray(3) */ @@ -347,49 +347,49 @@ /* Define if sendmmsg is implemented */ #undef HAVE_SENDMMSG -/* Define to 1 if you have the 'setproctitle' function. */ +/* Define to 1 if you have the `setproctitle' function. */ #undef HAVE_SETPROCTITLE -/* Define to 1 if you have the 'setregid' function. */ +/* Define to 1 if you have the `setregid' function. */ #undef HAVE_SETREGID -/* Define to 1 if you have the 'setresgid' function. */ +/* Define to 1 if you have the `setresgid' function. */ #undef HAVE_SETRESGID -/* Define to 1 if you have the 'setresuid' function. */ +/* Define to 1 if you have the `setresuid' function. */ #undef HAVE_SETRESUID -/* Define to 1 if you have the 'setreuid' function. */ +/* Define to 1 if you have the `setreuid' function. */ #undef HAVE_SETREUID -/* Define to 1 if you have the 'setusercontext' function. */ +/* Define to 1 if you have the `setusercontext' function. */ #undef HAVE_SETUSERCONTEXT -/* Define to 1 if you have the 'SHA1_Init' function. */ +/* Define to 1 if you have the `SHA1_Init' function. */ #undef HAVE_SHA1_INIT -/* Define to 1 if you have the 'sigaction' function. */ +/* Define to 1 if you have the `sigaction' function. */ #undef HAVE_SIGACTION /* Define to 1 if you have the header file. */ #undef HAVE_SIGNAL_H -/* Define to 1 if you have the 'sigprocmask' function. */ +/* Define to 1 if you have the `sigprocmask' function. */ #undef HAVE_SIGPROCMASK -/* Define to 1 if you have the 'snprintf' function. */ +/* Define to 1 if you have the `snprintf' function. */ #undef HAVE_SNPRINTF -/* Define to 1 if you have the 'socket' function. */ +/* Define to 1 if you have the `socket' function. */ #undef HAVE_SOCKET /* Define if you have the SSL libraries installed. */ #undef HAVE_SSL -/* Define to 1 if you have the 'SSL_CTX_set_security_level' function. */ +/* Define to 1 if you have the `SSL_CTX_set_security_level' function. */ #undef HAVE_SSL_CTX_SET_SECURITY_LEVEL -/* Define to 1 if you have the 'SSL_get1_peer_certificate' function. */ +/* Define to 1 if you have the `SSL_get1_peer_certificate' function. */ #undef HAVE_SSL_GET1_PEER_CERTIFICATE /* Define to 1 if you have the header file. */ @@ -407,19 +407,19 @@ /* Define to 1 if you have the header file. */ #undef HAVE_STDLIB_H -/* Define to 1 if you have the 'strcasecmp' function. */ +/* Define to 1 if you have the `strcasecmp' function. */ #undef HAVE_STRCASECMP -/* Define to 1 if you have the 'strchr' function. */ +/* Define to 1 if you have the `strchr' function. */ #undef HAVE_STRCHR -/* Define to 1 if you have the 'strdup' function. */ +/* Define to 1 if you have the `strdup' function. */ #undef HAVE_STRDUP -/* Define to 1 if you have the 'strerror' function. */ +/* Define to 1 if you have the `strerror' function. */ #undef HAVE_STRERROR -/* Define to 1 if you have the 'strftime' function. */ +/* Define to 1 if you have the `strftime' function. */ #undef HAVE_STRFTIME /* Define to 1 if you have the header file. */ @@ -428,34 +428,34 @@ /* Define to 1 if you have the header file. */ #undef HAVE_STRING_H -/* Define to 1 if you have the 'strlcat' function. */ +/* Define to 1 if you have the `strlcat' function. */ #undef HAVE_STRLCAT -/* Define to 1 if you have the 'strlcpy' function. */ +/* Define to 1 if you have the `strlcpy' function. */ #undef HAVE_STRLCPY -/* Define to 1 if you have the 'strncasecmp' function. */ +/* Define to 1 if you have the `strncasecmp' function. */ #undef HAVE_STRNCASECMP -/* Define to 1 if you have the 'strptime' function. */ +/* Define to 1 if you have the `strptime' function. */ #undef HAVE_STRPTIME -/* Define to 1 if you have the 'strtol' function. */ +/* Define to 1 if you have the `strtol' function. */ #undef HAVE_STRTOL -/* Define to 1 if 'sun_len' is a member of 'struct sockaddr_un'. */ +/* Define to 1 if `sun_len' is a member of `struct sockaddr_un'. */ #undef HAVE_STRUCT_SOCKADDR_UN_SUN_LEN -/* Define to 1 if 'st_mtimensec' is a member of 'struct stat'. */ +/* Define to 1 if `st_mtimensec' is a member of `struct stat'. */ #undef HAVE_STRUCT_STAT_ST_MTIMENSEC -/* Define to 1 if 'st_mtim.tv_nsec' is a member of 'struct stat'. */ +/* Define to 1 if `st_mtim.tv_nsec' is a member of `struct stat'. */ #undef HAVE_STRUCT_STAT_ST_MTIM_TV_NSEC /* If time.h has a struct timespec (for pselect). */ #undef HAVE_STRUCT_TIMESPEC -/* Define to 1 if you have the 'sysconf' function. */ +/* Define to 1 if you have the `sysconf' function. */ #undef HAVE_SYSCONF /* Define to 1 if you have the header file. */ @@ -506,7 +506,7 @@ /* Define if TLS 1.3 is supported by OpenSSL */ #undef HAVE_TLS_1_3 -/* Define to 1 if you have the 'tzset' function. */ +/* Define to 1 if you have the `tzset' function. */ #undef HAVE_TZSET /* Define to 1 if you have the header file. */ @@ -515,7 +515,7 @@ /* Define this if you have double va_list definitions. */ #undef HAVE_VA_LIST_DOUBLE_DEF -/* Define to 1 if you have the 'vfork' function. */ +/* Define to 1 if you have the `vfork' function. */ #undef HAVE_VFORK /* Define to 1 if you have the header file. */ @@ -524,13 +524,13 @@ /* Define to 1 if you have the header file. */ #undef HAVE_WCHAR_H -/* Define to 1 if 'fork' works. */ +/* Define to 1 if `fork' works. */ #undef HAVE_WORKING_FORK -/* Define to 1 if 'vfork' works. */ +/* Define to 1 if `vfork' works. */ #undef HAVE_WORKING_VFORK -/* Define to 1 if you have the 'writev' function. */ +/* Define to 1 if you have the `writev' function. */ #undef HAVE_WRITEV /* Define to the default nsd identity. */ @@ -545,6 +545,9 @@ /* Define to the maximum message length to pass to syslog. */ #undef MAXSYSLOGMSGLEN +/* Define to the default maximum number of CNAMEs to follow. */ +#undef MAX_CNAME_CHAIN + /* Define this to cleanup memory at exit (eg. for valgrind, etc.) */ #undef MEMCLEAN @@ -557,6 +560,10 @@ /* Define if mkdir has one argument. */ #undef MKDIR_HAS_ONE_ARG +/* Define this to enable experimental support for more than one catalog + consumer zone. */ +#undef MULTIPLE_CATALOG_CONSUMER_ZONES + /* Undefine this to enable internal runtime checks. */ #undef NDEBUG @@ -619,13 +626,13 @@ /* NSD shared files dir */ #undef SHAREDFILESDIR -/* The size of 'off_t', as computed by sizeof. */ +/* The size of `off_t', as computed by sizeof. */ #undef SIZEOF_OFF_T -/* The size of 'void*', as computed by sizeof. */ +/* The size of `void*', as computed by sizeof. */ #undef SIZEOF_VOIDP -/* Define to 1 if all of the C89 standard headers exist (not just the ones +/* Define to 1 if all of the C90 standard headers exist (not just the ones required in a freestanding environment). This macro is provided for backward compatibility; new code need not use it. */ #undef STDC_HEADERS @@ -680,7 +687,7 @@ /* Define this to configure to use the radix tree. */ #undef USE_RADIX_TREE -/* Enable extensions on AIX, Interix, z/OS. */ +/* Enable extensions on AIX 3, Interix. */ #ifndef _ALL_SOURCE # undef _ALL_SOURCE #endif @@ -741,15 +748,11 @@ #ifndef __STDC_WANT_IEC_60559_DFP_EXT__ # undef __STDC_WANT_IEC_60559_DFP_EXT__ #endif -/* Enable extensions specified by C23 Annex F. */ -#ifndef __STDC_WANT_IEC_60559_EXT__ -# undef __STDC_WANT_IEC_60559_EXT__ -#endif /* Enable extensions specified by ISO/IEC TS 18661-4:2015. */ #ifndef __STDC_WANT_IEC_60559_FUNCS_EXT__ # undef __STDC_WANT_IEC_60559_FUNCS_EXT__ #endif -/* Enable extensions specified by C23 Annex H and ISO/IEC TS 18661-3:2015. */ +/* Enable extensions specified by ISO/IEC TS 18661-3:2015. */ #ifndef __STDC_WANT_IEC_60559_TYPES_EXT__ # undef __STDC_WANT_IEC_60559_TYPES_EXT__ #endif @@ -793,8 +796,8 @@ /* Pathname to where the NSD transfer dir is created. */ #undef XFRDIR -/* Define to 1 if 'lex' declares 'yytext' as a 'char *' by default, not a - 'char[]'. */ +/* Define to 1 if `lex' declares `yytext' as a `char *' by default, not a + `char[]'. */ #undef YYTEXT_POINTER /* Pathname to the NSD zone list file. */ @@ -806,31 +809,25 @@ /* Number of bits in a file offset, on hosts where this is settable. */ #undef _FILE_OFFSET_BITS -/* Define to 1 if necessary to make fseeko visible. */ +/* Define to 1 to make fseeko visible on some hosts (e.g. glibc 2.2). */ #undef _LARGEFILE_SOURCE -/* Define to 1 on platforms where this makes off_t a 64-bit type. */ +/* Define for large files, on AIX-style hosts. */ #undef _LARGE_FILES /* Enable for compile on Minix */ #undef _NETBSD_SOURCE -/* Number of bits in time_t, on hosts where this is settable. */ -#undef _TIME_BITS - -/* Define to 1 on platforms where this makes time_t a 64-bit type. */ -#undef __MINGW_USE_VC2005_COMPAT - -/* Define to empty if 'const' does not conform to ANSI C. */ +/* Define to empty if `const' does not conform to ANSI C. */ #undef const -/* Define as 'int' if doesn't define. */ +/* Define to `int' if doesn't define. */ #undef gid_t /* in_addr_t */ #undef in_addr_t -/* Define to '__inline__' or '__inline' if that's what the C compiler +/* Define to `__inline__' or `__inline' if that's what the C compiler calls it, or to nothing if 'inline' is not supported under any name. */ #ifndef __cplusplus #undef inline @@ -851,7 +848,7 @@ /* Define to rpl_malloc if the replacement function should be used. */ #undef malloc -/* Define to 'long int' if does not define. */ +/* Define to `long int' if does not define. */ #undef off_t /* Define as a signed integer type capable of holding a process identifier. */ @@ -860,7 +857,7 @@ /* Define "sig_atomic_t" to "int" if "sig_atomic_t" is missing */ #undef sig_atomic_t -/* Define as 'unsigned int' if doesn't define. */ +/* Define to `unsigned int' if does not define. */ #undef size_t /* Define "socklen_t" to "int" if "socklen_t" is missing */ @@ -875,7 +872,7 @@ /* Define "suseconds_t" to "time_t" if "suseconds_t" is missing */ #undef suseconds_t -/* Define as 'int' if doesn't define. */ +/* Define to `int' if doesn't define. */ #undef uid_t /* Define "uint16_t" to "unsigned short" if "uint16_t" is missing */ @@ -893,7 +890,7 @@ /* Define "uintptr_t" to "void*" if "uintptr_t" is missing */ #undef uintptr_t -/* Define as 'fork' if 'vfork' does not work. */ +/* Define as `fork' if `vfork' does not work. */ #undef vfork Index: usr.sbin/nsd/config.sub =================================================================== RCS file: /cvs/src/usr.sbin/nsd/config.sub,v diff -u -p -r1.5 config.sub --- usr.sbin/nsd/config.sub 6 Sep 2025 17:41:37 -0000 1.5 +++ usr.sbin/nsd/config.sub 21 Sep 2026 16:28:41 -0000 @@ -1,10 +1,10 @@ #! /bin/sh # Configuration validation subroutine script. -# Copyright 1992-2023 Free Software Foundation, Inc. +# Copyright 1992-2022 Free Software Foundation, Inc. # shellcheck disable=SC2006,SC2268 # see below for rationale -timestamp='2023-09-19' +timestamp='2022-01-03' # This file is free software; you can redistribute it and/or modify it # under the terms of the GNU General Public License as published by @@ -76,13 +76,13 @@ Report bugs and patches to &2 + echo Invalid configuration \`"$1"\': more than four components >&2 exit 1 ;; *-*-*-*) @@ -145,8 +145,7 @@ case $1 in nto-qnx* | linux-* | uclinux-uclibc* \ | uclinux-gnu* | kfreebsd*-gnu* | knetbsd*-gnu* | netbsd*-gnu* \ | netbsd*-eabi* | kopensolaris*-gnu* | cloudabi*-eabi* \ - | storm-chaos* | os2-emx* | rtmk-nova* | managarm-* \ - | windows-* ) + | storm-chaos* | os2-emx* | rtmk-nova*) basic_machine=$field1 basic_os=$maybe_os ;; @@ -944,7 +943,7 @@ $basic_machine EOF IFS=$saved_IFS ;; - # We use 'pc' rather than 'unknown' + # We use `pc' rather than `unknown' # because (1) that's what they normally are, and # (2) the word "unknown" tends to confuse beginning users. i*86 | x86_64) @@ -1076,7 +1075,7 @@ case $cpu-$vendor in pentium-* | p5-* | k5-* | k6-* | nexgen-* | viac3-*) cpu=i586 ;; - pentiumpro-* | p6-* | 6x86-* | athlon-* | athlon_*-*) + pentiumpro-* | p6-* | 6x86-* | athlon-* | athalon_*-*) cpu=i686 ;; pentiumii-* | pentium2-* | pentiumiii-* | pentium3-*) @@ -1181,7 +1180,7 @@ case $cpu-$vendor in case $cpu in 1750a | 580 \ | a29k \ - | aarch64 | aarch64_be | aarch64c | arm64ec \ + | aarch64 | aarch64_be \ | abacus \ | alpha | alphaev[4-8] | alphaev56 | alphaev6[78] \ | alpha64 | alpha64ev[4-8] | alpha64ev56 | alpha64ev6[78] \ @@ -1200,23 +1199,45 @@ case $cpu-$vendor in | d10v | d30v | dlx | dsp16xx \ | e2k | elxsi | epiphany \ | f30[01] | f700 | fido | fr30 | frv | ft32 | fx80 \ - | javascript \ | h8300 | h8500 \ | hppa | hppa1.[01] | hppa2.0 | hppa2.0[nw] | hppa64 \ | hexagon \ | i370 | i*86 | i860 | i960 | ia16 | ia64 \ | ip2k | iq2000 \ | k1om \ - | kvx \ | le32 | le64 \ | lm32 \ - | loongarch32 | loongarch64 \ + | loongarch32 | loongarch64 | loongarchx32 \ | m32c | m32r | m32rle \ | m5200 | m68000 | m680[012346]0 | m68360 | m683?2 | m68k \ | m6811 | m68hc11 | m6812 | m68hc12 | m68hcs12x \ | m88110 | m88k | maxq | mb | mcore | mep | metag \ | microblaze | microblazeel \ - | mips* \ + | mips | mipsbe | mipseb | mipsel | mipsle \ + | mips16 \ + | mips64 | mips64eb | mips64el \ + | mips64octeon | mips64octeonel \ + | mips64orion | mips64orionel \ + | mips64r5900 | mips64r5900el \ + | mips64vr | mips64vrel \ + | mips64vr4100 | mips64vr4100el \ + | mips64vr4300 | mips64vr4300el \ + | mips64vr5000 | mips64vr5000el \ + | mips64vr5900 | mips64vr5900el \ + | mipsisa32 | mipsisa32el \ + | mipsisa32r2 | mipsisa32r2el \ + | mipsisa32r3 | mipsisa32r3el \ + | mipsisa32r5 | mipsisa32r5el \ + | mipsisa32r6 | mipsisa32r6el \ + | mipsisa64 | mipsisa64el \ + | mipsisa64r2 | mipsisa64r2el \ + | mipsisa64r3 | mipsisa64r3el \ + | mipsisa64r5 | mipsisa64r5el \ + | mipsisa64r6 | mipsisa64r6el \ + | mipsisa64sb1 | mipsisa64sb1el \ + | mipsisa64sr71k | mipsisa64sr71kel \ + | mipsr5900 | mipsr5900el \ + | mipstx39 | mipstx39el \ | mmix \ | mn10200 | mn10300 \ | moxie \ @@ -1264,7 +1285,7 @@ case $cpu-$vendor in ;; *) - echo "Invalid configuration '$1': machine '$cpu-$vendor' not recognized" 1>&2 + echo Invalid configuration \`"$1"\': machine \`"$cpu-$vendor"\' not recognized 1>&2 exit 1 ;; esac @@ -1285,12 +1306,11 @@ esac # Decode manufacturer-specific aliases for certain operating systems. -if test x"$basic_os" != x +if test x$basic_os != x then # First recognize some ad-hoc cases, or perhaps split kernel-os, or else just # set os. -obj= case $basic_os in gnu/linux*) kernel=linux @@ -1321,10 +1341,6 @@ EOF kernel=linux os=`echo "$basic_os" | sed -e 's|linux|gnu|'` ;; - managarm*) - kernel=managarm - os=`echo "$basic_os" | sed -e 's|managarm|mlibc|'` - ;; *) kernel= os=$basic_os @@ -1490,16 +1506,10 @@ case $os in os=eabi ;; *) - os= - obj=elf + os=elf ;; esac ;; - aout* | coff* | elf* | pe*) - # These are machine code file formats, not OSes - obj=$os - os= - ;; *) # No normalization, but not necessarily accepted, that comes below. ;; @@ -1518,15 +1528,12 @@ else # system, and we'll never get to this point. kernel= -obj= case $cpu-$vendor in score-*) - os= - obj=elf + os=elf ;; spu-*) - os= - obj=elf + os=elf ;; *-acorn) os=riscix1.2 @@ -1536,35 +1543,28 @@ case $cpu-$vendor in os=gnu ;; arm*-semi) - os= - obj=aout + os=aout ;; c4x-* | tic4x-*) - os= - obj=coff + os=coff ;; c8051-*) - os= - obj=elf + os=elf ;; clipper-intergraph) os=clix ;; hexagon-*) - os= - obj=elf + os=elf ;; tic54x-*) - os= - obj=coff + os=coff ;; tic55x-*) - os= - obj=coff + os=coff ;; tic6x-*) - os= - obj=coff + os=coff ;; # This must come before the *-dec entry. pdp10-*) @@ -1586,24 +1586,19 @@ case $cpu-$vendor in os=sunos3 ;; m68*-cisco) - os= - obj=aout + os=aout ;; mep-*) - os= - obj=elf + os=elf ;; mips*-cisco) - os= - obj=elf + os=elf ;; mips*-*) - os= - obj=elf + os=elf ;; or32-*) - os= - obj=coff + os=coff ;; *-tti) # must be before sparc entry or we get the wrong os. os=sysv3 @@ -1612,8 +1607,7 @@ case $cpu-$vendor in os=sunos4.1.1 ;; pru-*) - os= - obj=elf + os=elf ;; *-be) os=beos @@ -1694,12 +1688,10 @@ case $cpu-$vendor in os=uxpv ;; *-rom68k) - os= - obj=coff + os=coff ;; *-*bug) - os= - obj=coff + os=coff ;; *-apple) os=macos @@ -1717,8 +1709,7 @@ esac fi -# Now, validate our (potentially fixed-up) individual pieces (OS, OBJ). - +# Now, validate our (potentially fixed-up) OS. case $os in # Sometimes we do "kernel-libc", so those need to count as OSes. musl* | newlib* | relibc* | uclibc*) @@ -1729,9 +1720,6 @@ case $os in # VxWorks passes extra cpu info in the 4th filed. simlinux | simwindows | spe) ;; - # See `case $cpu-$os` validation below - ghcjs) - ;; # Now accept the basic system types. # The portable systems comes first. # Each alternative MUST end in a * to match a version number. @@ -1740,7 +1728,7 @@ case $os in | hpux* | unos* | osf* | luna* | dgux* | auroraux* | solaris* \ | sym* | plan9* | psp* | sim* | xray* | os68k* | v88r* \ | hiux* | abug | nacl* | netware* | windows* \ - | os9* | macos* | osx* | ios* | tvos* | watchos* \ + | os9* | macos* | osx* | ios* \ | mpw* | magic* | mmixware* | mon960* | lnews* \ | amigaos* | amigados* | msdos* | newsos* | unicos* | aof* \ | aos* | aros* | cloudabi* | sortix* | twizzler* \ @@ -1749,11 +1737,11 @@ case $os in | mirbsd* | netbsd* | dicos* | openedition* | ose* \ | bitrig* | openbsd* | secbsd* | solidbsd* | libertybsd* | os108* \ | ekkobsd* | freebsd* | riscix* | lynxos* | os400* \ - | bosx* | nextstep* | cxux* | oabi* \ - | ptx* | ecoff* | winnt* | domain* | vsta* \ + | bosx* | nextstep* | cxux* | aout* | elf* | oabi* \ + | ptx* | coff* | ecoff* | winnt* | domain* | vsta* \ | udi* | lites* | ieee* | go32* | aux* | hcos* \ | chorusrdb* | cegcc* | glidix* | serenity* \ - | cygwin* | msys* | moss* | proelf* | rtems* \ + | cygwin* | msys* | pe* | moss* | proelf* | rtems* \ | midipix* | mingw32* | mingw64* | mint* \ | uxpv* | beos* | mpeix* | udk* | moxiebox* \ | interix* | uwin* | mks* | rhapsody* | darwin* \ @@ -1766,7 +1754,7 @@ case $os in | onefs* | tirtos* | phoenix* | fuchsia* | redox* | bme* \ | midnightbsd* | amdhsa* | unleashed* | emscripten* | wasi* \ | nsk* | powerunix* | genode* | zvmoe* | qnx* | emx* | zephyr* \ - | fiwix* | mlibc* | cos* | mbr* ) + | fiwix* ) ;; # This one is extra strict with allowed versions sco3.2v2 | sco3.2v[4-9]* | sco5v6*) @@ -1774,99 +1762,41 @@ case $os in ;; none) ;; - kernel* | msvc* ) - # Restricted further below - ;; - '') - if test x"$obj" = x - then - echo "Invalid configuration '$1': Blank OS only allowed with explicit machine code file format" 1>&2 - fi - ;; - *) - echo "Invalid configuration '$1': OS '$os' not recognized" 1>&2 - exit 1 - ;; -esac - -case $obj in - aout* | coff* | elf* | pe*) - ;; - '') - # empty is fine - ;; *) - echo "Invalid configuration '$1': Machine code format '$obj' not recognized" 1>&2 - exit 1 - ;; -esac - -# Here we handle the constraint that a (synthetic) cpu and os are -# valid only in combination with each other and nowhere else. -case $cpu-$os in - # The "javascript-unknown-ghcjs" triple is used by GHC; we - # accept it here in order to tolerate that, but reject any - # variations. - javascript-ghcjs) - ;; - javascript-* | *-ghcjs) - echo "Invalid configuration '$1': cpu '$cpu' is not valid with os '$os$obj'" 1>&2 + echo Invalid configuration \`"$1"\': OS \`"$os"\' not recognized 1>&2 exit 1 ;; esac # As a final step for OS-related things, validate the OS-kernel combination # (given a valid OS), if there is a kernel. -case $kernel-$os-$obj in - linux-gnu*- | linux-dietlibc*- | linux-android*- | linux-newlib*- \ - | linux-musl*- | linux-relibc*- | linux-uclibc*- | linux-mlibc*- ) - ;; - uclinux-uclibc*- ) - ;; - managarm-mlibc*- | managarm-kernel*- ) +case $kernel-$os in + linux-gnu* | linux-dietlibc* | linux-android* | linux-newlib* \ + | linux-musl* | linux-relibc* | linux-uclibc* ) ;; - windows*-msvc*-) + uclinux-uclibc* ) ;; - -dietlibc*- | -newlib*- | -musl*- | -relibc*- | -uclibc*- | -mlibc*- ) + -dietlibc* | -newlib* | -musl* | -relibc* | -uclibc* ) # These are just libc implementations, not actual OSes, and thus # require a kernel. - echo "Invalid configuration '$1': libc '$os' needs explicit kernel." 1>&2 - exit 1 - ;; - -kernel*- ) - echo "Invalid configuration '$1': '$os' needs explicit kernel." 1>&2 - exit 1 - ;; - *-kernel*- ) - echo "Invalid configuration '$1': '$kernel' does not support '$os'." 1>&2 + echo "Invalid configuration \`$1': libc \`$os' needs explicit kernel." 1>&2 exit 1 ;; - *-msvc*- ) - echo "Invalid configuration '$1': '$os' needs 'windows'." 1>&2 - exit 1 - ;; - kfreebsd*-gnu*- | kopensolaris*-gnu*-) + kfreebsd*-gnu* | kopensolaris*-gnu*) ;; - vxworks-simlinux- | vxworks-simwindows- | vxworks-spe-) + vxworks-simlinux | vxworks-simwindows | vxworks-spe) ;; - nto-qnx*-) - ;; - os2-emx-) + nto-qnx*) ;; - *-eabi*- | *-gnueabi*-) + os2-emx) ;; - none--*) - # None (no kernel, i.e. freestanding / bare metal), - # can be paired with an machine code file format + *-eabi* | *-gnueabi*) ;; - -*-) + -*) # Blank kernel with real OS is always fine. ;; - --*) - # Blank kernel and OS with real machine code file format is always fine. - ;; - *-*-*) - echo "Invalid configuration '$1': Kernel '$kernel' not known to work with OS '$os'." 1>&2 + *-*) + echo "Invalid configuration \`$1': Kernel \`$kernel' not known to work with OS \`$os'." 1>&2 exit 1 ;; esac @@ -1949,7 +1879,7 @@ case $vendor in ;; esac -echo "$cpu-$vendor${kernel:+-$kernel}${os:+-$os}${obj:+-$obj}" +echo "$cpu-$vendor-${kernel:+$kernel-}$os" exit # Local variables: Index: usr.sbin/nsd/configlexer.lex =================================================================== RCS file: /cvs/src/usr.sbin/nsd/configlexer.lex,v diff -u -p -r1.28 configlexer.lex --- usr.sbin/nsd/configlexer.lex 21 Mar 2026 21:36:36 -0000 1.28 +++ usr.sbin/nsd/configlexer.lex 21 Sep 2026 16:28:41 -0000 @@ -315,6 +315,7 @@ tls-auth-port{COLON} { LEXOUT(("v(%s) " tls-auth-xfr-only{COLON} { LEXOUT(("v(%s) ", yytext)); return VAR_TLS_AUTH_XFR_ONLY;} tls-cert-bundle{COLON} { LEXOUT(("v(%s) ", yytext)); return VAR_TLS_CERT_BUNDLE; } proxy-protocol-port{COLON} { LEXOUT(("v(%s) ", yytext)); return VAR_PROXY_PROTOCOL_PORT; } +allow-proxy{COLON} { LEXOUT(("v(%s) ", yytext)); return VAR_ALLOW_PROXY;} answer-cookie{COLON} { LEXOUT(("v(%s) ", yytext)); return VAR_ANSWER_COOKIE;} cookie-secret{COLON} { LEXOUT(("v(%s) ", yytext)); return VAR_COOKIE_SECRET;} cookie-secret-file{COLON} { LEXOUT(("v(%s) ", yytext)); return VAR_COOKIE_SECRET_FILE;} @@ -337,6 +338,7 @@ xdp-program-path{COLON} { LEXOUT(("v(%s xdp-program-load{COLON} { LEXOUT(("v(%s) ", yytext)); return VAR_XDP_PROGRAM_LOAD; } xdp-bpffs-path{COLON} { LEXOUT(("v(%s) ", yytext)); return VAR_XDP_BPFFS_PATH; } xdp-force-copy{COLON} { LEXOUT(("v(%s) ", yytext)); return VAR_XDP_FORCE_COPY; } +udp-padding-port{COLON} { LEXOUT(("v(%s) ", yytext)); return VAR_UDP_PADDING_PORT;} {NEWLINE} { LEXOUT(("NL\n")); cfg_parser->line++;} servers={UNQUOTEDLETTER}* { Index: usr.sbin/nsd/configparser.y =================================================================== RCS file: /cvs/src/usr.sbin/nsd/configparser.y,v diff -u -p -r1.42 configparser.y --- usr.sbin/nsd/configparser.y 21 Mar 2026 21:36:36 -0000 1.42 +++ usr.sbin/nsd/configparser.y 21 Sep 2026 16:28:41 -0000 @@ -134,6 +134,7 @@ struct component { %token VAR_TLS_AUTH_XFR_ONLY %token VAR_TLS_CERT_BUNDLE %token VAR_PROXY_PROTOCOL_PORT +%token VAR_ALLOW_PROXY %token VAR_CPU_AFFINITY %token VAR_XFRD_CPU_AFFINITY %token VAR_SERVER_CPU_AFFINITY @@ -144,6 +145,7 @@ struct component { %token VAR_METRICS_INTERFACE %token VAR_METRICS_PORT %token VAR_METRICS_PATH +%token VAR_UDP_PADDING_PORT /* dnstap */ %token VAR_DNSTAP @@ -539,12 +541,18 @@ server_option: { cfg_parser->opt->tls_cert_bundle = region_strdup(cfg_parser->opt->region, $2); } | VAR_PROXY_PROTOCOL_PORT number { - struct proxy_protocol_port_list* elem = region_alloc_zero( + struct port_list* elem = region_alloc_zero( cfg_parser->opt->region, sizeof(*elem)); elem->port = $2; elem->next = cfg_parser->opt->proxy_protocol_port; cfg_parser->opt->proxy_protocol_port = elem; } + | VAR_ALLOW_PROXY STRING + { + acl_options_type* acl = parse_acl_info(cfg_parser->opt->region, $2, + "NOKEY"); + append_acl(&cfg_parser->opt->allow_proxy, acl); + } | VAR_ANSWER_COOKIE boolean { cfg_parser->opt->answer_cookie = $2; } | VAR_COOKIE_SECRET STRING @@ -680,6 +688,14 @@ server_option: #ifdef USE_METRICS cfg_parser->opt->metrics_path = region_strdup(cfg_parser->opt->region, $2); #endif /* USE_METRICS */ + } + | VAR_UDP_PADDING_PORT number + { + struct port_list* elem = region_alloc_zero( + cfg_parser->opt->region, sizeof(*elem)); + elem->port = $2; + elem->next = cfg_parser->opt->udp_padding_port; + cfg_parser->opt->udp_padding_port = elem; } ; Index: usr.sbin/nsd/configure =================================================================== RCS file: /cvs/src/usr.sbin/nsd/configure,v diff -u -p -r1.64 configure --- usr.sbin/nsd/configure 21 Mar 2026 21:36:36 -0000 1.64 +++ usr.sbin/nsd/configure 21 Sep 2026 16:28:41 -0000 @@ -1,11 +1,11 @@ #! /bin/sh # Guess values for system-dependent variables and create Makefiles. -# Generated by GNU Autoconf 2.72 for NSD 4.14.2. +# Generated by GNU Autoconf 2.71 for NSD 4.15.2. # # Report bugs to . # # -# Copyright (C) 1992-1996, 1998-2017, 2020-2023 Free Software Foundation, +# Copyright (C) 1992-1996, 1998-2017, 2020-2021 Free Software Foundation, # Inc. # # @@ -17,6 +17,7 @@ # Be more Bourne compatible DUALCASE=1; export DUALCASE # for MKS sh +as_nop=: if test ${ZSH_VERSION+y} && (emulate sh) >/dev/null 2>&1 then : emulate sh @@ -25,13 +26,12 @@ then : # is contrary to our usage. Disable this feature. alias -g '${1+"$@"}'='"$@"' setopt NO_GLOB_SUBST -else case e in #( - e) case `(set -o) 2>/dev/null` in #( +else $as_nop + case `(set -o) 2>/dev/null` in #( *posix*) : set -o posix ;; #( *) : ;; -esac ;; esac fi @@ -103,7 +103,7 @@ IFS=$as_save_IFS ;; esac -# We did not find ourselves, most probably we were run as 'sh COMMAND' +# We did not find ourselves, most probably we were run as `sh COMMAND' # in which case we are not to be found in the path. if test "x$as_myself" = x; then as_myself=$0 @@ -133,14 +133,15 @@ case $- in # (((( esac exec $CONFIG_SHELL $as_opts "$as_myself" ${1+"$@"} # Admittedly, this is quite paranoid, since all the known shells bail -# out after a failed 'exec'. +# out after a failed `exec'. printf "%s\n" "$0: could not re-execute with $CONFIG_SHELL" >&2 exit 255 fi # We don't want this to propagate to other subprocesses. { _as_can_reexec=; unset _as_can_reexec;} if test "x$CONFIG_SHELL" = x; then - as_bourne_compatible="if test \${ZSH_VERSION+y} && (emulate sh) >/dev/null 2>&1 + as_bourne_compatible="as_nop=: +if test \${ZSH_VERSION+y} && (emulate sh) >/dev/null 2>&1 then : emulate sh NULLCMD=: @@ -148,13 +149,12 @@ then : # is contrary to our usage. Disable this feature. alias -g '\${1+\"\$@\"}'='\"\$@\"' setopt NO_GLOB_SUBST -else case e in #( - e) case \`(set -o) 2>/dev/null\` in #( +else \$as_nop + case \`(set -o) 2>/dev/null\` in #( *posix*) : set -o posix ;; #( *) : ;; -esac ;; esac fi " @@ -172,9 +172,8 @@ as_fn_ret_failure && { exitcode=1; echo if ( set x; as_fn_ret_success y && test x = \"\$1\" ) then : -else case e in #( - e) exitcode=1; echo positional parameters were not saved. ;; -esac +else \$as_nop + exitcode=1; echo positional parameters were not saved. fi test x\$exitcode = x0 || exit 1 blah=\$(echo \$(echo blah)) @@ -188,15 +187,14 @@ test \$(( 1 + 1 )) = 2 || exit 1" if (eval "$as_required") 2>/dev/null then : as_have_required=yes -else case e in #( - e) as_have_required=no ;; -esac +else $as_nop + as_have_required=no fi if test x$as_have_required = xyes && (eval "$as_suggested") 2>/dev/null then : -else case e in #( - e) as_save_IFS=$IFS; IFS=$PATH_SEPARATOR +else $as_nop + as_save_IFS=$IFS; IFS=$PATH_SEPARATOR as_found=false for as_dir in /bin$PATH_SEPARATOR/usr/bin$PATH_SEPARATOR$PATH do @@ -229,13 +227,12 @@ IFS=$as_save_IFS if $as_found then : -else case e in #( - e) if { test -f "$SHELL" || test -f "$SHELL.exe"; } && +else $as_nop + if { test -f "$SHELL" || test -f "$SHELL.exe"; } && as_run=a "$SHELL" -c "$as_bourne_compatible""$as_required" 2>/dev/null then : CONFIG_SHELL=$SHELL as_have_required=yes -fi ;; -esac +fi fi @@ -257,7 +254,7 @@ case $- in # (((( esac exec $CONFIG_SHELL $as_opts "$as_myself" ${1+"$@"} # Admittedly, this is quite paranoid, since all the known shells bail -# out after a failed 'exec'. +# out after a failed `exec'. printf "%s\n" "$0: could not re-execute with $CONFIG_SHELL" >&2 exit 255 fi @@ -278,8 +275,7 @@ $0: a modern shell, or manually run the $0: shell if you do have one." fi exit 1 -fi ;; -esac +fi fi fi SHELL=${CONFIG_SHELL-/bin/sh} @@ -318,6 +314,14 @@ as_fn_exit () as_fn_set_status $1 exit $1 } # as_fn_exit +# as_fn_nop +# --------- +# Do nothing but, unlike ":", preserve the value of $?. +as_fn_nop () +{ + return $? +} +as_nop=as_fn_nop # as_fn_mkdir_p # ------------- @@ -386,12 +390,11 @@ then : { eval $1+=\$2 }' -else case e in #( - e) as_fn_append () +else $as_nop + as_fn_append () { eval $1=\$$1\$2 - } ;; -esac + } fi # as_fn_append # as_fn_arith ARG... @@ -405,14 +408,21 @@ then : { as_val=$(( $* )) }' -else case e in #( - e) as_fn_arith () +else $as_nop + as_fn_arith () { as_val=`expr "$@" || test $? -eq 1` - } ;; -esac + } fi # as_fn_arith +# as_fn_nop +# --------- +# Do nothing but, unlike ":", preserve the value of $?. +as_fn_nop () +{ + return $? +} +as_nop=as_fn_nop # as_fn_error STATUS ERROR [LINENO LOG_FD] # ---------------------------------------- @@ -486,8 +496,6 @@ as_cr_alnum=$as_cr_Letters$as_cr_digits /[$]LINENO/= ' <$as_myself | sed ' - t clear - :clear s/[$]LINENO.*/&-/ t lineno b @@ -536,6 +544,7 @@ esac as_echo='printf %s\n' as_echo_n='printf %s' + rm -f conf$$ conf$$.exe conf$$.file if test -d conf$$.dir; then rm -f conf$$.dir/conf$$.file @@ -547,9 +556,9 @@ if (echo >conf$$.file) 2>/dev/null; then if ln -s conf$$.file conf$$ 2>/dev/null; then as_ln_s='ln -s' # ... but there are two gotchas: - # 1) On MSYS, both 'ln -s file dir' and 'ln file dir' fail. - # 2) DJGPP < 2.04 has no symlinks; 'ln -s' creates a wrapper executable. - # In both cases, we have to default to 'cp -pR'. + # 1) On MSYS, both `ln -s file dir' and `ln file dir' fail. + # 2) DJGPP < 2.04 has no symlinks; `ln -s' creates a wrapper executable. + # In both cases, we have to default to `cp -pR'. ln -s conf$$.file conf$$.dir 2>/dev/null && test ! -f conf$$.exe || as_ln_s='cp -pR' elif ln conf$$.file conf$$ 2>/dev/null; then @@ -574,12 +583,10 @@ as_test_x='test -x' as_executable_p=as_fn_executable_p # Sed expression to map a string onto a valid CPP name. -as_sed_cpp="y%*$as_cr_letters%P$as_cr_LETTERS%;s%[^_$as_cr_alnum]%_%g" -as_tr_cpp="eval sed '$as_sed_cpp'" # deprecated +as_tr_cpp="eval sed 'y%*$as_cr_letters%P$as_cr_LETTERS%;s%[^_$as_cr_alnum]%_%g'" # Sed expression to map a string onto a valid variable name. -as_sed_sh="y%*+%pp%;s%[^_$as_cr_alnum]%_%g" -as_tr_sh="eval sed '$as_sed_sh'" # deprecated +as_tr_sh="eval sed 'y%*+%pp%;s%[^_$as_cr_alnum]%_%g'" test -n "$DJDIR" || exec 7<&0 /dev/null && - as_fn_error $? "invalid feature name: '$ac_useropt'" + as_fn_error $? "invalid feature name: \`$ac_useropt'" ac_useropt_orig=$ac_useropt ac_useropt=`printf "%s\n" "$ac_useropt" | sed 's/[-+.]/_/g'` case $ac_user_opts in @@ -962,7 +969,7 @@ do ac_useropt=`expr "x$ac_option" : 'x-*enable-\([^=]*\)'` # Reject names that are not valid shell variable names. expr "x$ac_useropt" : ".*[^-+._$as_cr_alnum]" >/dev/null && - as_fn_error $? "invalid feature name: '$ac_useropt'" + as_fn_error $? "invalid feature name: \`$ac_useropt'" ac_useropt_orig=$ac_useropt ac_useropt=`printf "%s\n" "$ac_useropt" | sed 's/[-+.]/_/g'` case $ac_user_opts in @@ -1175,7 +1182,7 @@ do ac_useropt=`expr "x$ac_option" : 'x-*with-\([^=]*\)'` # Reject names that are not valid shell variable names. expr "x$ac_useropt" : ".*[^-+._$as_cr_alnum]" >/dev/null && - as_fn_error $? "invalid package name: '$ac_useropt'" + as_fn_error $? "invalid package name: \`$ac_useropt'" ac_useropt_orig=$ac_useropt ac_useropt=`printf "%s\n" "$ac_useropt" | sed 's/[-+.]/_/g'` case $ac_user_opts in @@ -1191,7 +1198,7 @@ do ac_useropt=`expr "x$ac_option" : 'x-*without-\(.*\)'` # Reject names that are not valid shell variable names. expr "x$ac_useropt" : ".*[^-+._$as_cr_alnum]" >/dev/null && - as_fn_error $? "invalid package name: '$ac_useropt'" + as_fn_error $? "invalid package name: \`$ac_useropt'" ac_useropt_orig=$ac_useropt ac_useropt=`printf "%s\n" "$ac_useropt" | sed 's/[-+.]/_/g'` case $ac_user_opts in @@ -1221,8 +1228,8 @@ do | --x-librar=* | --x-libra=* | --x-libr=* | --x-lib=* | --x-li=* | --x-l=*) x_libraries=$ac_optarg ;; - -*) as_fn_error $? "unrecognized option: '$ac_option' -Try '$0 --help' for more information" + -*) as_fn_error $? "unrecognized option: \`$ac_option' +Try \`$0 --help' for more information" ;; *=*) @@ -1230,7 +1237,7 @@ Try '$0 --help' for more information" # Reject names that are not valid shell variable names. case $ac_envvar in #( '' | [0-9]* | *[!_$as_cr_alnum]* ) - as_fn_error $? "invalid variable name: '$ac_envvar'" ;; + as_fn_error $? "invalid variable name: \`$ac_envvar'" ;; esac eval $ac_envvar=\$ac_optarg export $ac_envvar ;; @@ -1280,7 +1287,7 @@ do as_fn_error $? "expected an absolute directory name for --$ac_var: $ac_val" done -# There might be people who depend on the old broken behavior: '$host' +# There might be people who depend on the old broken behavior: `$host' # used to hold the argument of --host etc. # FIXME: To remove some day. build=$build_alias @@ -1348,7 +1355,7 @@ if test ! -r "$srcdir/$ac_unique_file"; test "$ac_srcdir_defaulted" = yes && srcdir="$ac_confdir or .." as_fn_error $? "cannot find sources ($ac_unique_file) in $srcdir" fi -ac_msg="sources are in $srcdir, but 'cd $srcdir' does not work" +ac_msg="sources are in $srcdir, but \`cd $srcdir' does not work" ac_abs_confdir=`( cd "$srcdir" && test -r "./$ac_unique_file" || as_fn_error $? "$ac_msg" pwd)` @@ -1376,7 +1383,7 @@ if test "$ac_init_help" = "long"; then # Omit some internal or obsolete options to make the list less imposing. # This message is too long to be a string in the A/UX 3.1 sh. cat <<_ACEOF -'configure' configures NSD 4.14.2 to adapt to many kinds of systems. +\`configure' configures NSD 4.15.2 to adapt to many kinds of systems. Usage: $0 [OPTION]... [VAR=VALUE]... @@ -1390,11 +1397,11 @@ Configuration: --help=short display options specific to this package --help=recursive display the short help of all the included packages -V, --version display version information and exit - -q, --quiet, --silent do not print 'checking ...' messages + -q, --quiet, --silent do not print \`checking ...' messages --cache-file=FILE cache test results in FILE [disabled] - -C, --config-cache alias for '--cache-file=config.cache' + -C, --config-cache alias for \`--cache-file=config.cache' -n, --no-create do not create output files - --srcdir=DIR find the sources in DIR [configure dir or '..'] + --srcdir=DIR find the sources in DIR [configure dir or \`..'] Installation directories: --prefix=PREFIX install architecture-independent files in PREFIX @@ -1402,10 +1409,10 @@ Installation directories: --exec-prefix=EPREFIX install architecture-dependent files in EPREFIX [PREFIX] -By default, 'make install' will install all the files in -'$ac_default_prefix/bin', '$ac_default_prefix/lib' etc. You can specify -an installation prefix other than '$ac_default_prefix' using '--prefix', -for instance '--prefix=\$HOME'. +By default, \`make install' will install all the files in +\`$ac_default_prefix/bin', \`$ac_default_prefix/lib' etc. You can specify +an installation prefix other than \`$ac_default_prefix' using \`--prefix', +for instance \`--prefix=\$HOME'. For better control, use the options below. @@ -1442,7 +1449,7 @@ fi if test -n "$ac_init_help"; then case $ac_init_help in - short | recursive ) echo "Configuration of NSD 4.14.2:";; + short | recursive ) echo "Configuration of NSD 4.15.2:";; esac cat <<\_ACEOF @@ -1461,6 +1468,9 @@ Optional Features: problems for IPv6 --enable-root-server Configure NSD as a root server (obsolete) --disable-ipv6 Disables IPv6 support + --enable-multiple-catzones + Enable experimental support for more than one + catalog consumer zone --disable-bind8-stats Disable BIND8 like NSTATS & XSTATS and statistics in nsd-control --disable-zone-stats Disable per-zone statistics gathering (if enabled, @@ -1489,7 +1499,6 @@ Optional Features: --enable-tcp-fastopen Enable TCP Fast Open --disable-westmere Disable Westmere (SSE4.2) parser kernel --disable-haswell Disable Haswell (AVX2) parser kernel - --enable-year2038 support timestamps after 2038 Optional Packages: --with-PACKAGE[=ARG] use PACKAGE [ARG=yes] @@ -1521,6 +1530,8 @@ Optional Packages: --with-facility=name Syslog default facility (LOG_DAEMON) --with-tcp-timeout=number Limit the default tcp timeout + --with-max-cname-chain=number + Limit the maximum number of CNAMEs to follow --with-ssl=pathname enable SSL (will check /usr/local/ssl /usr/lib/ssl /usr/ssl /usr/pkg /usr/sfw /usr/local /usr /usr/local/opt/openssl) @@ -1545,7 +1556,7 @@ Some influential environment variables: you have headers in a nonstandard directory YFLAGS The list of arguments that will be passed by default to $YACC. This script will default YFLAGS to the empty string to avoid a - default value of '-d' given by some make applications. + default value of `-d' given by some make applications. CPP C preprocessor CLANG location of clang compiler (only needed for xdp) LLC location of LLVM static compiler (only needed for xdp) @@ -1564,7 +1575,7 @@ Some influential environment variables: SYSTEMD_DAEMON_LIBS linker flags for SYSTEMD_DAEMON, overriding pkg-config -Use these variables to override the choices made by 'configure' or to help +Use these variables to override the choices made by `configure' or to help it to find libraries and programs with nonstandard names/locations. Report bugs to . @@ -1631,10 +1642,10 @@ fi test -n "$ac_init_help" && exit $ac_status if $ac_init_version; then cat <<\_ACEOF -NSD configure 4.14.2 -generated by GNU Autoconf 2.72 +NSD configure 4.15.2 +generated by GNU Autoconf 2.71 -Copyright (C) 2023 Free Software Foundation, Inc. +Copyright (C) 2021 Free Software Foundation, Inc. This configure script is free software; the Free Software Foundation gives unlimited permission to copy, distribute and modify it. _ACEOF @@ -1673,12 +1684,11 @@ printf "%s\n" "$ac_try_echo"; } >&5 } && test -s conftest.$ac_objext then : ac_retval=0 -else case e in #( - e) printf "%s\n" "$as_me: failed program was:" >&5 +else $as_nop + printf "%s\n" "$as_me: failed program was:" >&5 sed 's/^/| /' conftest.$ac_ext >&5 - ac_retval=1 ;; -esac + ac_retval=1 fi eval $as_lineno_stack; ${as_lineno_stack:+:} unset as_lineno as_fn_set_status $ac_retval @@ -1697,8 +1707,8 @@ printf %s "checking for $2... " >&6; } if eval test \${$3+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ $4 #include <$2> @@ -1706,12 +1716,10 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : eval "$3=yes" -else case e in #( - e) eval "$3=no" ;; -esac +else $as_nop + eval "$3=no" fi -rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac +rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext fi eval ac_res=\$$3 { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5 @@ -1751,12 +1759,11 @@ printf "%s\n" "$ac_try_echo"; } >&5 } then : ac_retval=0 -else case e in #( - e) printf "%s\n" "$as_me: failed program was:" >&5 +else $as_nop + printf "%s\n" "$as_me: failed program was:" >&5 sed 's/^/| /' conftest.$ac_ext >&5 - ac_retval=1 ;; -esac + ac_retval=1 fi # Delete the IPA/IPO (Inter Procedural Analysis/Optimization) information # created by the PGI compiler (conftest_ipa8_conftest.oo), as it would @@ -1768,6 +1775,44 @@ fi } # ac_fn_c_try_link +# ac_fn_c_try_cpp LINENO +# ---------------------- +# Try to preprocess conftest.$ac_ext, and return whether this succeeded. +ac_fn_c_try_cpp () +{ + as_lineno=${as_lineno-"$1"} as_lineno_stack=as_lineno_stack=$as_lineno_stack + if { { ac_try="$ac_cpp conftest.$ac_ext" +case "(($ac_try" in + *\"* | *\`* | *\\*) ac_try_echo=\$ac_try;; + *) ac_try_echo=$ac_try;; +esac +eval ac_try_echo="\"\$as_me:${as_lineno-$LINENO}: $ac_try_echo\"" +printf "%s\n" "$ac_try_echo"; } >&5 + (eval "$ac_cpp conftest.$ac_ext") 2>conftest.err + ac_status=$? + if test -s conftest.err; then + grep -v '^ *+' conftest.err >conftest.er1 + cat conftest.er1 >&5 + mv -f conftest.er1 conftest.err + fi + printf "%s\n" "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5 + test $ac_status = 0; } > conftest.i && { + test -z "$ac_c_preproc_warn_flag$ac_c_werror_flag" || + test ! -s conftest.err + } +then : + ac_retval=0 +else $as_nop + printf "%s\n" "$as_me: failed program was:" >&5 +sed 's/^/| /' conftest.$ac_ext >&5 + + ac_retval=1 +fi + eval $as_lineno_stack; ${as_lineno_stack:+:} unset as_lineno + as_fn_set_status $ac_retval + +} # ac_fn_c_try_cpp + # ac_fn_c_check_type LINENO TYPE VAR INCLUDES # ------------------------------------------- # Tests whether TYPE exists after having included INCLUDES, setting cache @@ -1780,8 +1825,8 @@ printf %s "checking for $2... " >&6; } if eval test \${$3+y} then : printf %s "(cached) " >&6 -else case e in #( - e) eval "$3=no" +else $as_nop + eval "$3=no" cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ $4 @@ -1811,14 +1856,12 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : -else case e in #( - e) eval "$3=yes" ;; -esac +else $as_nop + eval "$3=yes" fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext fi -rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac +rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext fi eval ac_res=\$$3 { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5 @@ -1857,13 +1900,12 @@ printf "%s\n" "$ac_try_echo"; } >&5 test $ac_status = 0; }; } then : ac_retval=0 -else case e in #( - e) printf "%s\n" "$as_me: program exited with status $ac_status" >&5 +else $as_nop + printf "%s\n" "$as_me: program exited with status $ac_status" >&5 printf "%s\n" "$as_me: failed program was:" >&5 sed 's/^/| /' conftest.$ac_ext >&5 - ac_retval=$ac_status ;; -esac + ac_retval=$ac_status fi rm -rf conftest.dSYM conftest_ipa8_conftest.oo eval $as_lineno_stack; ${as_lineno_stack:+:} unset as_lineno @@ -1884,8 +1926,8 @@ printf %s "checking whether $as_decl_nam if eval test \${$3+y} then : printf %s "(cached) " >&6 -else case e in #( - e) as_decl_use=`echo $2|sed -e 's/(/((/' -e 's/)/) 0&/' -e 's/,/) 0& (/g'` +else $as_nop + as_decl_use=`echo $2|sed -e 's/(/((/' -e 's/)/) 0&/' -e 's/,/) 0& (/g'` eval ac_save_FLAGS=\$$6 as_fn_append $6 " $5" cat confdefs.h - <<_ACEOF >conftest.$ac_ext @@ -1909,14 +1951,12 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : eval "$3=yes" -else case e in #( - e) eval "$3=no" ;; -esac +else $as_nop + eval "$3=no" fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext eval $6=\$ac_save_FLAGS - ;; -esac + fi eval ac_res=\$$3 { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5 @@ -1936,15 +1976,15 @@ printf %s "checking for $2... " >&6; } if eval test \${$3+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ /* Define $2 to an innocuous variant, in case declares $2. For example, HP-UX 11i declares gettimeofday. */ #define $2 innocuous_$2 /* System header to define __stub macros and hopefully few prototypes, - which can conflict with char $2 (void); below. */ + which can conflict with char $2 (); below. */ #include #undef $2 @@ -1955,7 +1995,7 @@ else case e in #( #ifdef __cplusplus extern "C" #endif -char $2 (void); +char $2 (); /* The GNU C library defines this for functions which it implements to always fail with ENOSYS. Some functions are actually named something starting with __ and the normal name is an alias. */ @@ -1974,13 +2014,11 @@ _ACEOF if ac_fn_c_try_link "$LINENO" then : eval "$3=yes" -else case e in #( - e) eval "$3=no" ;; -esac +else $as_nop + eval "$3=no" fi rm -f core conftest.err conftest.$ac_objext conftest.beam \ - conftest$ac_exeext conftest.$ac_ext ;; -esac + conftest$ac_exeext conftest.$ac_ext fi eval ac_res=\$$3 { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5 @@ -1989,45 +2027,6 @@ printf "%s\n" "$ac_res" >&6; } } # ac_fn_c_check_func -# ac_fn_c_try_cpp LINENO -# ---------------------- -# Try to preprocess conftest.$ac_ext, and return whether this succeeded. -ac_fn_c_try_cpp () -{ - as_lineno=${as_lineno-"$1"} as_lineno_stack=as_lineno_stack=$as_lineno_stack - if { { ac_try="$ac_cpp conftest.$ac_ext" -case "(($ac_try" in - *\"* | *\`* | *\\*) ac_try_echo=\$ac_try;; - *) ac_try_echo=$ac_try;; -esac -eval ac_try_echo="\"\$as_me:${as_lineno-$LINENO}: $ac_try_echo\"" -printf "%s\n" "$ac_try_echo"; } >&5 - (eval "$ac_cpp conftest.$ac_ext") 2>conftest.err - ac_status=$? - if test -s conftest.err; then - grep -v '^ *+' conftest.err >conftest.er1 - cat conftest.er1 >&5 - mv -f conftest.er1 conftest.err - fi - printf "%s\n" "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5 - test $ac_status = 0; } > conftest.i && { - test -z "$ac_c_preproc_warn_flag$ac_c_werror_flag" || - test ! -s conftest.err - } -then : - ac_retval=0 -else case e in #( - e) printf "%s\n" "$as_me: failed program was:" >&5 -sed 's/^/| /' conftest.$ac_ext >&5 - - ac_retval=1 ;; -esac -fi - eval $as_lineno_stack; ${as_lineno_stack:+:} unset as_lineno - as_fn_set_status $ac_retval - -} # ac_fn_c_try_cpp - # ac_fn_c_check_member LINENO AGGR MEMBER VAR INCLUDES # ---------------------------------------------------- # Tries to find if the field MEMBER exists in type AGGR, after including @@ -2040,8 +2039,8 @@ printf %s "checking for $2.$3... " >&6; if eval test \${$4+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ $5 int @@ -2057,8 +2056,8 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : eval "$4=yes" -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ $5 int @@ -2074,15 +2073,12 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : eval "$4=yes" -else case e in #( - e) eval "$4=no" ;; -esac +else $as_nop + eval "$4=no" fi -rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac +rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext fi -rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac +rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext fi eval ac_res=\$$4 { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5 @@ -2136,19 +2132,18 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ac_hi=$ac_mid; break -else case e in #( - e) as_fn_arith $ac_mid + 1 && ac_lo=$as_val +else $as_nop + as_fn_arith $ac_mid + 1 && ac_lo=$as_val if test $ac_lo -le $ac_mid; then ac_lo= ac_hi= break fi - as_fn_arith 2 '*' $ac_mid + 1 && ac_mid=$as_val ;; -esac + as_fn_arith 2 '*' $ac_mid + 1 && ac_mid=$as_val fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext done -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ $4 int @@ -2183,23 +2178,20 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ac_lo=$ac_mid; break -else case e in #( - e) as_fn_arith '(' $ac_mid ')' - 1 && ac_hi=$as_val +else $as_nop + as_fn_arith '(' $ac_mid ')' - 1 && ac_hi=$as_val if test $ac_mid -le $ac_hi; then ac_lo= ac_hi= break fi - as_fn_arith 2 '*' $ac_mid && ac_mid=$as_val ;; -esac + as_fn_arith 2 '*' $ac_mid && ac_mid=$as_val fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext done -else case e in #( - e) ac_lo= ac_hi= ;; -esac +else $as_nop + ac_lo= ac_hi= fi -rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac +rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext # Binary search between lo and hi bounds. @@ -2222,9 +2214,8 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ac_hi=$ac_mid -else case e in #( - e) as_fn_arith '(' $ac_mid ')' + 1 && ac_lo=$as_val ;; -esac +else $as_nop + as_fn_arith '(' $ac_mid ')' + 1 && ac_lo=$as_val fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext done @@ -2272,9 +2263,8 @@ _ACEOF if ac_fn_c_try_run "$LINENO" then : echo >>conftest.val; read $3 config.log <<_ACEOF This file contains any messages produced by compilers while running configure, to aid debugging if configure makes a mistake. -It was created by NSD $as_me 4.14.2, which was -generated by GNU Autoconf 2.72. Invocation command line was +It was created by NSD $as_me 4.15.2, which was +generated by GNU Autoconf 2.71. Invocation command line was $ $0$ac_configure_args_raw @@ -2556,10 +2546,10 @@ esac printf "%s\n" "$as_me: loading site script $ac_site_file" >&6;} sed 's/^/| /' "$ac_site_file" >&5 . "$ac_site_file" \ - || { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} + || { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +printf "%s\n" "$as_me: error: in \`$ac_pwd':" >&2;} as_fn_error $? "failed to load site script $ac_site_file -See 'config.log' for more details" "$LINENO" 5; } +See \`config.log' for more details" "$LINENO" 5; } fi done @@ -2596,7 +2586,9 @@ struct stat; /* Most of the following tests are stolen from RCS 5.7 src/conf.sh. */ struct buf { int x; }; struct buf * (*rcsopen) (struct buf *, struct stat *, int); -static char *e (char **p, int i) +static char *e (p, i) + char **p; + int i; { return p[i]; } @@ -2610,21 +2602,6 @@ static char *f (char * (*g) (char **, in return s; } -/* C89 style stringification. */ -#define noexpand_stringify(a) #a -const char *stringified = noexpand_stringify(arbitrary+token=sequence); - -/* C89 style token pasting. Exercises some of the corner cases that - e.g. old MSVC gets wrong, but not very hard. */ -#define noexpand_concat(a,b) a##b -#define expand_concat(a,b) noexpand_concat(a,b) -extern int vA; -extern int vbee; -#define aye A -#define bee B -int *pvA = &expand_concat(v,aye); -int *pvbee = &noexpand_concat(v,bee); - /* OSF 4.0 Compaq cc is some sort of almost-ANSI by default. It has function prototypes and stuff, but not \xHH hex character constants. These do not provoke an error unfortunately, instead are silently treated @@ -2652,19 +2629,16 @@ ok |= (argc == 0 || f (e, argv, 0) != ar # Test code for whether the C compiler supports C99 (global declarations) ac_c_conftest_c99_globals=' -/* Does the compiler advertise C99 conformance? */ +// Does the compiler advertise C99 conformance? #if !defined __STDC_VERSION__ || __STDC_VERSION__ < 199901L # error "Compiler does not advertise C99 conformance" #endif -// See if C++-style comments work. - #include extern int puts (const char *); extern int printf (const char *, ...); extern int dprintf (int, const char *, ...); extern void *malloc (size_t); -extern void free (void *); // Check varargs macros. These examples are taken from C99 6.10.3.5. // dprintf is used instead of fprintf to avoid needing to declare @@ -2714,6 +2688,7 @@ typedef const char *ccp; static inline int test_restrict (ccp restrict text) { + // See if C++-style comments work. // Iterate through items via the restricted pointer. // Also check for declarations in for loops. for (unsigned int i = 0; *(text+i) != '\''\0'\''; ++i) @@ -2779,8 +2754,6 @@ ac_c_conftest_c99_main=' ia->datasize = 10; for (int i = 0; i < ia->datasize; ++i) ia->data[i] = i * 1.234; - // Work around memory leak warnings. - free (ia); // Check named initializers. struct named_init ni = { @@ -2802,7 +2775,7 @@ ac_c_conftest_c99_main=' # Test code for whether the C compiler supports C11 (global declarations) ac_c_conftest_c11_globals=' -/* Does the compiler advertise C11 conformance? */ +// Does the compiler advertise C11 conformance? #if !defined __STDC_VERSION__ || __STDC_VERSION__ < 201112L # error "Compiler does not advertise C11 conformance" #endif @@ -2998,9 +2971,8 @@ IFS=$as_save_IFS if $as_found then : -else case e in #( - e) as_fn_error $? "cannot find required auxiliary files:$ac_missing_aux_files" "$LINENO" 5 ;; -esac +else $as_nop + as_fn_error $? "cannot find required auxiliary files:$ac_missing_aux_files" "$LINENO" 5 fi @@ -3028,12 +3000,12 @@ for ac_var in $ac_precious_vars; do eval ac_new_val=\$ac_env_${ac_var}_value case $ac_old_set,$ac_new_set in set,) - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: '$ac_var' was set to '$ac_old_val' in the previous run" >&5 -printf "%s\n" "$as_me: error: '$ac_var' was set to '$ac_old_val' in the previous run" >&2;} + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: \`$ac_var' was set to \`$ac_old_val' in the previous run" >&5 +printf "%s\n" "$as_me: error: \`$ac_var' was set to \`$ac_old_val' in the previous run" >&2;} ac_cache_corrupted=: ;; ,set) - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: '$ac_var' was not set in the previous run" >&5 -printf "%s\n" "$as_me: error: '$ac_var' was not set in the previous run" >&2;} + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: \`$ac_var' was not set in the previous run" >&5 +printf "%s\n" "$as_me: error: \`$ac_var' was not set in the previous run" >&2;} ac_cache_corrupted=: ;; ,);; *) @@ -3042,18 +3014,18 @@ printf "%s\n" "$as_me: error: '$ac_var' ac_old_val_w=`echo x $ac_old_val` ac_new_val_w=`echo x $ac_new_val` if test "$ac_old_val_w" != "$ac_new_val_w"; then - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: '$ac_var' has changed since the previous run:" >&5 -printf "%s\n" "$as_me: error: '$ac_var' has changed since the previous run:" >&2;} + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: \`$ac_var' has changed since the previous run:" >&5 +printf "%s\n" "$as_me: error: \`$ac_var' has changed since the previous run:" >&2;} ac_cache_corrupted=: else - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: warning: ignoring whitespace changes in '$ac_var' since the previous run:" >&5 -printf "%s\n" "$as_me: warning: ignoring whitespace changes in '$ac_var' since the previous run:" >&2;} + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: warning: ignoring whitespace changes in \`$ac_var' since the previous run:" >&5 +printf "%s\n" "$as_me: warning: ignoring whitespace changes in \`$ac_var' since the previous run:" >&2;} eval $ac_var=\$ac_old_val fi - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: former value: '$ac_old_val'" >&5 -printf "%s\n" "$as_me: former value: '$ac_old_val'" >&2;} - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: current value: '$ac_new_val'" >&5 -printf "%s\n" "$as_me: current value: '$ac_new_val'" >&2;} + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: former value: \`$ac_old_val'" >&5 +printf "%s\n" "$as_me: former value: \`$ac_old_val'" >&2;} + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: current value: \`$ac_new_val'" >&5 +printf "%s\n" "$as_me: current value: \`$ac_new_val'" >&2;} fi;; esac # Pass precious variables to config.status. @@ -3069,11 +3041,11 @@ printf "%s\n" "$as_me: current value: fi done if $ac_cache_corrupted; then - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +printf "%s\n" "$as_me: error: in \`$ac_pwd':" >&2;} { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: changes in the environment can compromise the build" >&5 printf "%s\n" "$as_me: error: changes in the environment can compromise the build" >&2;} - as_fn_error $? "run '${MAKE-make} distclean' and/or 'rm $cache_file' + as_fn_error $? "run \`${MAKE-make} distclean' and/or \`rm $cache_file' and start over" "$LINENO" 5 fi ## -------------------- ## @@ -3129,8 +3101,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$CC"; then +else $as_nop + if test -n "$CC"; then ac_cv_prog_CC="$CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -3152,8 +3124,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi CC=$ac_cv_prog_CC if test -n "$CC"; then @@ -3175,8 +3146,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_ac_ct_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$ac_ct_CC"; then +else $as_nop + if test -n "$ac_ct_CC"; then ac_cv_prog_ac_ct_CC="$ac_ct_CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -3198,8 +3169,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi ac_ct_CC=$ac_cv_prog_ac_ct_CC if test -n "$ac_ct_CC"; then @@ -3234,8 +3204,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$CC"; then +else $as_nop + if test -n "$CC"; then ac_cv_prog_CC="$CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -3257,8 +3227,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi CC=$ac_cv_prog_CC if test -n "$CC"; then @@ -3280,8 +3249,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$CC"; then +else $as_nop + if test -n "$CC"; then ac_cv_prog_CC="$CC" # Let the user override the test. else ac_prog_rejected=no @@ -3320,8 +3289,7 @@ if test $ac_prog_rejected = yes; then ac_cv_prog_CC="$as_dir$ac_word${1+' '}$@" fi fi -fi ;; -esac +fi fi CC=$ac_cv_prog_CC if test -n "$CC"; then @@ -3345,8 +3313,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$CC"; then +else $as_nop + if test -n "$CC"; then ac_cv_prog_CC="$CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -3368,8 +3336,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi CC=$ac_cv_prog_CC if test -n "$CC"; then @@ -3395,8 +3362,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_ac_ct_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$ac_ct_CC"; then +else $as_nop + if test -n "$ac_ct_CC"; then ac_cv_prog_ac_ct_CC="$ac_ct_CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -3418,8 +3385,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi ac_ct_CC=$ac_cv_prog_ac_ct_CC if test -n "$ac_ct_CC"; then @@ -3457,8 +3423,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$CC"; then +else $as_nop + if test -n "$CC"; then ac_cv_prog_CC="$CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -3480,8 +3446,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi CC=$ac_cv_prog_CC if test -n "$CC"; then @@ -3503,8 +3468,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_ac_ct_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$ac_ct_CC"; then +else $as_nop + if test -n "$ac_ct_CC"; then ac_cv_prog_ac_ct_CC="$ac_ct_CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -3526,8 +3491,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi ac_ct_CC=$ac_cv_prog_ac_ct_CC if test -n "$ac_ct_CC"; then @@ -3556,10 +3520,10 @@ fi fi -test -z "$CC" && { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} +test -z "$CC" && { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +printf "%s\n" "$as_me: error: in \`$ac_pwd':" >&2;} as_fn_error $? "no acceptable C compiler found in \$PATH -See 'config.log' for more details" "$LINENO" 5; } +See \`config.log' for more details" "$LINENO" 5; } # Provide some information about the compiler. printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for C compiler version" >&5 @@ -3631,8 +3595,8 @@ printf "%s\n" "$ac_try_echo"; } >&5 printf "%s\n" "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5 test $ac_status = 0; } then : - # Autoconf-2.13 could set the ac_cv_exeext variable to 'no'. -# So ignore a value of 'no', otherwise this would lead to 'EXEEXT = no' + # Autoconf-2.13 could set the ac_cv_exeext variable to `no'. +# So ignore a value of `no', otherwise this would lead to `EXEEXT = no' # in a Makefile. We should not override ac_cv_exeext if it was cached, # so that the user can short-circuit this test for compilers unknown to # Autoconf. @@ -3652,7 +3616,7 @@ do ac_cv_exeext=`expr "$ac_file" : '[^.]*\(\..*\)'` fi # We set ac_cv_exeext here because the later test for it is not - # safe: cross compilers may not add the suffix if given an '-o' + # safe: cross compilers may not add the suffix if given an `-o' # argument, so we may need to know it at that point already. # Even if this section looks crufty: it has the advantage of # actually working. @@ -3663,9 +3627,8 @@ do done test "$ac_cv_exeext" = no && ac_cv_exeext= -else case e in #( - e) ac_file='' ;; -esac +else $as_nop + ac_file='' fi if test -z "$ac_file" then : @@ -3674,14 +3637,13 @@ printf "%s\n" "no" >&6; } printf "%s\n" "$as_me: failed program was:" >&5 sed 's/^/| /' conftest.$ac_ext >&5 -{ { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} +{ { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +printf "%s\n" "$as_me: error: in \`$ac_pwd':" >&2;} as_fn_error 77 "C compiler cannot create executables -See 'config.log' for more details" "$LINENO" 5; } -else case e in #( - e) { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: yes" >&5 -printf "%s\n" "yes" >&6; } ;; -esac +See \`config.log' for more details" "$LINENO" 5; } +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: yes" >&5 +printf "%s\n" "yes" >&6; } fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for C compiler default output file name" >&5 printf %s "checking for C compiler default output file name... " >&6; } @@ -3705,10 +3667,10 @@ printf "%s\n" "$ac_try_echo"; } >&5 printf "%s\n" "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5 test $ac_status = 0; } then : - # If both 'conftest.exe' and 'conftest' are 'present' (well, observable) -# catch 'conftest.exe'. For instance with Cygwin, 'ls conftest' will -# work properly (i.e., refer to 'conftest.exe'), while it won't with -# 'rm'. + # If both `conftest.exe' and `conftest' are `present' (well, observable) +# catch `conftest.exe'. For instance with Cygwin, `ls conftest' will +# work properly (i.e., refer to `conftest.exe'), while it won't with +# `rm'. for ac_file in conftest.exe conftest conftest.*; do test -f "$ac_file" || continue case $ac_file in @@ -3718,12 +3680,11 @@ for ac_file in conftest.exe conftest con * ) break;; esac done -else case e in #( - e) { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} +else $as_nop + { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +printf "%s\n" "$as_me: error: in \`$ac_pwd':" >&2;} as_fn_error $? "cannot compute suffix of executables: cannot compile and link -See 'config.log' for more details" "$LINENO" 5; } ;; -esac +See \`config.log' for more details" "$LINENO" 5; } fi rm -f conftest conftest$ac_cv_exeext { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_exeext" >&5 @@ -3739,8 +3700,6 @@ int main (void) { FILE *f = fopen ("conftest.out", "w"); - if (!f) - return 1; return ferror (f) || fclose (f) != 0; ; @@ -3780,27 +3739,26 @@ printf "%s\n" "$ac_try_echo"; } >&5 if test "$cross_compiling" = maybe; then cross_compiling=yes else - { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} + { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +printf "%s\n" "$as_me: error: in \`$ac_pwd':" >&2;} as_fn_error 77 "cannot run C compiled programs. -If you meant to cross compile, use '--host'. -See 'config.log' for more details" "$LINENO" 5; } +If you meant to cross compile, use \`--host'. +See \`config.log' for more details" "$LINENO" 5; } fi fi fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $cross_compiling" >&5 printf "%s\n" "$cross_compiling" >&6; } -rm -f conftest.$ac_ext conftest$ac_cv_exeext \ - conftest.o conftest.obj conftest.out +rm -f conftest.$ac_ext conftest$ac_cv_exeext conftest.out ac_clean_files=$ac_clean_files_save { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for suffix of object files" >&5 printf %s "checking for suffix of object files... " >&6; } if test ${ac_cv_objext+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ int @@ -3832,18 +3790,16 @@ then : break;; esac done -else case e in #( - e) printf "%s\n" "$as_me: failed program was:" >&5 +else $as_nop + printf "%s\n" "$as_me: failed program was:" >&5 sed 's/^/| /' conftest.$ac_ext >&5 -{ { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} +{ { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +printf "%s\n" "$as_me: error: in \`$ac_pwd':" >&2;} as_fn_error $? "cannot compute suffix of object files: cannot compile -See 'config.log' for more details" "$LINENO" 5; } ;; -esac +See \`config.log' for more details" "$LINENO" 5; } fi -rm -f conftest.$ac_cv_objext conftest.$ac_ext ;; -esac +rm -f conftest.$ac_cv_objext conftest.$ac_ext fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_objext" >&5 printf "%s\n" "$ac_cv_objext" >&6; } @@ -3854,8 +3810,8 @@ printf %s "checking whether the compiler if test ${ac_cv_c_compiler_gnu+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ int @@ -3872,14 +3828,12 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ac_compiler_gnu=yes -else case e in #( - e) ac_compiler_gnu=no ;; -esac +else $as_nop + ac_compiler_gnu=no fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ac_cv_c_compiler_gnu=$ac_compiler_gnu - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_c_compiler_gnu" >&5 printf "%s\n" "$ac_cv_c_compiler_gnu" >&6; } @@ -3897,8 +3851,8 @@ printf %s "checking whether $CC accepts if test ${ac_cv_prog_cc_g+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_save_c_werror_flag=$ac_c_werror_flag +else $as_nop + ac_save_c_werror_flag=$ac_c_werror_flag ac_c_werror_flag=yes ac_cv_prog_cc_g=no CFLAGS="-g" @@ -3916,8 +3870,8 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ac_cv_prog_cc_g=yes -else case e in #( - e) CFLAGS="" +else $as_nop + CFLAGS="" cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ @@ -3932,8 +3886,8 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : -else case e in #( - e) ac_c_werror_flag=$ac_save_c_werror_flag +else $as_nop + ac_c_werror_flag=$ac_save_c_werror_flag CFLAGS="-g" cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ @@ -3950,15 +3904,12 @@ if ac_fn_c_try_compile "$LINENO" then : ac_cv_prog_cc_g=yes fi -rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac +rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext fi -rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac +rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext - ac_c_werror_flag=$ac_save_c_werror_flag ;; -esac + ac_c_werror_flag=$ac_save_c_werror_flag fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_g" >&5 printf "%s\n" "$ac_cv_prog_cc_g" >&6; } @@ -3985,8 +3936,8 @@ printf %s "checking for $CC option to en if test ${ac_cv_prog_cc_c11+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_cv_prog_cc_c11=no +else $as_nop + ac_cv_prog_cc_c11=no ac_save_CC=$CC cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ @@ -4003,28 +3954,25 @@ rm -f core conftest.err conftest.$ac_obj test "x$ac_cv_prog_cc_c11" != "xno" && break done rm -f conftest.$ac_ext -CC=$ac_save_CC ;; -esac +CC=$ac_save_CC fi if test "x$ac_cv_prog_cc_c11" = xno then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: unsupported" >&5 printf "%s\n" "unsupported" >&6; } -else case e in #( - e) if test "x$ac_cv_prog_cc_c11" = x +else $as_nop + if test "x$ac_cv_prog_cc_c11" = x then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: none needed" >&5 printf "%s\n" "none needed" >&6; } -else case e in #( - e) { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_c11" >&5 +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_c11" >&5 printf "%s\n" "$ac_cv_prog_cc_c11" >&6; } - CC="$CC $ac_cv_prog_cc_c11" ;; -esac + CC="$CC $ac_cv_prog_cc_c11" fi ac_cv_prog_cc_stdc=$ac_cv_prog_cc_c11 - ac_prog_cc_stdc=c11 ;; -esac + ac_prog_cc_stdc=c11 fi fi if test x$ac_prog_cc_stdc = xno @@ -4034,8 +3982,8 @@ printf %s "checking for $CC option to en if test ${ac_cv_prog_cc_c99+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_cv_prog_cc_c99=no +else $as_nop + ac_cv_prog_cc_c99=no ac_save_CC=$CC cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ @@ -4052,28 +4000,25 @@ rm -f core conftest.err conftest.$ac_obj test "x$ac_cv_prog_cc_c99" != "xno" && break done rm -f conftest.$ac_ext -CC=$ac_save_CC ;; -esac +CC=$ac_save_CC fi if test "x$ac_cv_prog_cc_c99" = xno then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: unsupported" >&5 printf "%s\n" "unsupported" >&6; } -else case e in #( - e) if test "x$ac_cv_prog_cc_c99" = x +else $as_nop + if test "x$ac_cv_prog_cc_c99" = x then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: none needed" >&5 printf "%s\n" "none needed" >&6; } -else case e in #( - e) { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_c99" >&5 +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_c99" >&5 printf "%s\n" "$ac_cv_prog_cc_c99" >&6; } - CC="$CC $ac_cv_prog_cc_c99" ;; -esac + CC="$CC $ac_cv_prog_cc_c99" fi ac_cv_prog_cc_stdc=$ac_cv_prog_cc_c99 - ac_prog_cc_stdc=c99 ;; -esac + ac_prog_cc_stdc=c99 fi fi if test x$ac_prog_cc_stdc = xno @@ -4083,8 +4028,8 @@ printf %s "checking for $CC option to en if test ${ac_cv_prog_cc_c89+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_cv_prog_cc_c89=no +else $as_nop + ac_cv_prog_cc_c89=no ac_save_CC=$CC cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ @@ -4101,28 +4046,25 @@ rm -f core conftest.err conftest.$ac_obj test "x$ac_cv_prog_cc_c89" != "xno" && break done rm -f conftest.$ac_ext -CC=$ac_save_CC ;; -esac +CC=$ac_save_CC fi if test "x$ac_cv_prog_cc_c89" = xno then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: unsupported" >&5 printf "%s\n" "unsupported" >&6; } -else case e in #( - e) if test "x$ac_cv_prog_cc_c89" = x +else $as_nop + if test "x$ac_cv_prog_cc_c89" = x then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: none needed" >&5 printf "%s\n" "none needed" >&6; } -else case e in #( - e) { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_c89" >&5 +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_c89" >&5 printf "%s\n" "$ac_cv_prog_cc_c89" >&6; } - CC="$CC $ac_cv_prog_cc_c89" ;; -esac + CC="$CC $ac_cv_prog_cc_c89" fi ac_cv_prog_cc_stdc=$ac_cv_prog_cc_c89 - ac_prog_cc_stdc=c89 ;; -esac + ac_prog_cc_stdc=c89 fi fi @@ -4173,8 +4115,8 @@ printf %s "checking whether it is safe t if test ${ac_cv_safe_to_define___extensions__+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ # define __EXTENSIONS__ 1 @@ -4190,12 +4132,10 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ac_cv_safe_to_define___extensions__=yes -else case e in #( - e) ac_cv_safe_to_define___extensions__=no ;; -esac +else $as_nop + ac_cv_safe_to_define___extensions__=no fi -rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac +rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_safe_to_define___extensions__" >&5 printf "%s\n" "$ac_cv_safe_to_define___extensions__" >&6; } @@ -4205,8 +4145,8 @@ printf %s "checking whether _XOPEN_SOURC if test ${ac_cv_should_define__xopen_source+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_cv_should_define__xopen_source=no +else $as_nop + ac_cv_should_define__xopen_source=no if test $ac_cv_header_wchar_h = yes then : cat confdefs.h - <<_ACEOF >conftest.$ac_ext @@ -4225,8 +4165,8 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #define _XOPEN_SOURCE 500 @@ -4244,12 +4184,10 @@ if ac_fn_c_try_compile "$LINENO" then : ac_cv_should_define__xopen_source=yes fi -rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac +rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext -fi ;; -esac +fi fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_should_define__xopen_source" >&5 printf "%s\n" "$ac_cv_should_define__xopen_source" >&6; } @@ -4274,8 +4212,6 @@ printf "%s\n" "$ac_cv_should_define__xop printf "%s\n" "#define __STDC_WANT_IEC_60559_DFP_EXT__ 1" >>confdefs.h - printf "%s\n" "#define __STDC_WANT_IEC_60559_EXT__ 1" >>confdefs.h - printf "%s\n" "#define __STDC_WANT_IEC_60559_FUNCS_EXT__ 1" >>confdefs.h printf "%s\n" "#define __STDC_WANT_IEC_60559_TYPES_EXT__ 1" >>confdefs.h @@ -4295,9 +4231,8 @@ then : printf "%s\n" "#define _POSIX_1_SOURCE 2" >>confdefs.h -else case e in #( - e) MINIX= ;; -esac +else $as_nop + MINIX= fi if test $ac_cv_safe_to_define___extensions__ = yes then : @@ -4585,8 +4520,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$CC"; then +else $as_nop + if test -n "$CC"; then ac_cv_prog_CC="$CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -4608,8 +4543,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi CC=$ac_cv_prog_CC if test -n "$CC"; then @@ -4631,8 +4565,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_ac_ct_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$ac_ct_CC"; then +else $as_nop + if test -n "$ac_ct_CC"; then ac_cv_prog_ac_ct_CC="$ac_ct_CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -4654,8 +4588,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi ac_ct_CC=$ac_cv_prog_ac_ct_CC if test -n "$ac_ct_CC"; then @@ -4690,8 +4623,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$CC"; then +else $as_nop + if test -n "$CC"; then ac_cv_prog_CC="$CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -4713,8 +4646,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi CC=$ac_cv_prog_CC if test -n "$CC"; then @@ -4736,8 +4668,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$CC"; then +else $as_nop + if test -n "$CC"; then ac_cv_prog_CC="$CC" # Let the user override the test. else ac_prog_rejected=no @@ -4776,8 +4708,7 @@ if test $ac_prog_rejected = yes; then ac_cv_prog_CC="$as_dir$ac_word${1+' '}$@" fi fi -fi ;; -esac +fi fi CC=$ac_cv_prog_CC if test -n "$CC"; then @@ -4801,8 +4732,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$CC"; then +else $as_nop + if test -n "$CC"; then ac_cv_prog_CC="$CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -4824,8 +4755,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi CC=$ac_cv_prog_CC if test -n "$CC"; then @@ -4851,8 +4781,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_ac_ct_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$ac_ct_CC"; then +else $as_nop + if test -n "$ac_ct_CC"; then ac_cv_prog_ac_ct_CC="$ac_ct_CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -4874,8 +4804,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi ac_ct_CC=$ac_cv_prog_ac_ct_CC if test -n "$ac_ct_CC"; then @@ -4913,8 +4842,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$CC"; then +else $as_nop + if test -n "$CC"; then ac_cv_prog_CC="$CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -4936,8 +4865,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi CC=$ac_cv_prog_CC if test -n "$CC"; then @@ -4959,8 +4887,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_ac_ct_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$ac_ct_CC"; then +else $as_nop + if test -n "$ac_ct_CC"; then ac_cv_prog_ac_ct_CC="$ac_ct_CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -4982,8 +4910,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi ac_ct_CC=$ac_cv_prog_ac_ct_CC if test -n "$ac_ct_CC"; then @@ -5012,10 +4939,10 @@ fi fi -test -z "$CC" && { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} +test -z "$CC" && { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +printf "%s\n" "$as_me: error: in \`$ac_pwd':" >&2;} as_fn_error $? "no acceptable C compiler found in \$PATH -See 'config.log' for more details" "$LINENO" 5; } +See \`config.log' for more details" "$LINENO" 5; } # Provide some information about the compiler. printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for C compiler version" >&5 @@ -5047,8 +4974,8 @@ printf %s "checking whether the compiler if test ${ac_cv_c_compiler_gnu+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ int @@ -5065,14 +4992,12 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ac_compiler_gnu=yes -else case e in #( - e) ac_compiler_gnu=no ;; -esac +else $as_nop + ac_compiler_gnu=no fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ac_cv_c_compiler_gnu=$ac_compiler_gnu - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_c_compiler_gnu" >&5 printf "%s\n" "$ac_cv_c_compiler_gnu" >&6; } @@ -5090,8 +5015,8 @@ printf %s "checking whether $CC accepts if test ${ac_cv_prog_cc_g+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_save_c_werror_flag=$ac_c_werror_flag +else $as_nop + ac_save_c_werror_flag=$ac_c_werror_flag ac_c_werror_flag=yes ac_cv_prog_cc_g=no CFLAGS="-g" @@ -5109,8 +5034,8 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ac_cv_prog_cc_g=yes -else case e in #( - e) CFLAGS="" +else $as_nop + CFLAGS="" cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ @@ -5125,8 +5050,8 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : -else case e in #( - e) ac_c_werror_flag=$ac_save_c_werror_flag +else $as_nop + ac_c_werror_flag=$ac_save_c_werror_flag CFLAGS="-g" cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ @@ -5143,15 +5068,12 @@ if ac_fn_c_try_compile "$LINENO" then : ac_cv_prog_cc_g=yes fi -rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac +rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext fi -rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac +rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext - ac_c_werror_flag=$ac_save_c_werror_flag ;; -esac + ac_c_werror_flag=$ac_save_c_werror_flag fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_g" >&5 printf "%s\n" "$ac_cv_prog_cc_g" >&6; } @@ -5178,8 +5100,8 @@ printf %s "checking for $CC option to en if test ${ac_cv_prog_cc_c11+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_cv_prog_cc_c11=no +else $as_nop + ac_cv_prog_cc_c11=no ac_save_CC=$CC cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ @@ -5196,28 +5118,25 @@ rm -f core conftest.err conftest.$ac_obj test "x$ac_cv_prog_cc_c11" != "xno" && break done rm -f conftest.$ac_ext -CC=$ac_save_CC ;; -esac +CC=$ac_save_CC fi if test "x$ac_cv_prog_cc_c11" = xno then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: unsupported" >&5 printf "%s\n" "unsupported" >&6; } -else case e in #( - e) if test "x$ac_cv_prog_cc_c11" = x +else $as_nop + if test "x$ac_cv_prog_cc_c11" = x then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: none needed" >&5 printf "%s\n" "none needed" >&6; } -else case e in #( - e) { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_c11" >&5 +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_c11" >&5 printf "%s\n" "$ac_cv_prog_cc_c11" >&6; } - CC="$CC $ac_cv_prog_cc_c11" ;; -esac + CC="$CC $ac_cv_prog_cc_c11" fi ac_cv_prog_cc_stdc=$ac_cv_prog_cc_c11 - ac_prog_cc_stdc=c11 ;; -esac + ac_prog_cc_stdc=c11 fi fi if test x$ac_prog_cc_stdc = xno @@ -5227,8 +5146,8 @@ printf %s "checking for $CC option to en if test ${ac_cv_prog_cc_c99+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_cv_prog_cc_c99=no +else $as_nop + ac_cv_prog_cc_c99=no ac_save_CC=$CC cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ @@ -5245,28 +5164,25 @@ rm -f core conftest.err conftest.$ac_obj test "x$ac_cv_prog_cc_c99" != "xno" && break done rm -f conftest.$ac_ext -CC=$ac_save_CC ;; -esac +CC=$ac_save_CC fi if test "x$ac_cv_prog_cc_c99" = xno then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: unsupported" >&5 printf "%s\n" "unsupported" >&6; } -else case e in #( - e) if test "x$ac_cv_prog_cc_c99" = x +else $as_nop + if test "x$ac_cv_prog_cc_c99" = x then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: none needed" >&5 printf "%s\n" "none needed" >&6; } -else case e in #( - e) { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_c99" >&5 +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_c99" >&5 printf "%s\n" "$ac_cv_prog_cc_c99" >&6; } - CC="$CC $ac_cv_prog_cc_c99" ;; -esac + CC="$CC $ac_cv_prog_cc_c99" fi ac_cv_prog_cc_stdc=$ac_cv_prog_cc_c99 - ac_prog_cc_stdc=c99 ;; -esac + ac_prog_cc_stdc=c99 fi fi if test x$ac_prog_cc_stdc = xno @@ -5276,8 +5192,8 @@ printf %s "checking for $CC option to en if test ${ac_cv_prog_cc_c89+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_cv_prog_cc_c89=no +else $as_nop + ac_cv_prog_cc_c89=no ac_save_CC=$CC cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ @@ -5294,28 +5210,25 @@ rm -f core conftest.err conftest.$ac_obj test "x$ac_cv_prog_cc_c89" != "xno" && break done rm -f conftest.$ac_ext -CC=$ac_save_CC ;; -esac +CC=$ac_save_CC fi if test "x$ac_cv_prog_cc_c89" = xno then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: unsupported" >&5 printf "%s\n" "unsupported" >&6; } -else case e in #( - e) if test "x$ac_cv_prog_cc_c89" = x +else $as_nop + if test "x$ac_cv_prog_cc_c89" = x then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: none needed" >&5 printf "%s\n" "none needed" >&6; } -else case e in #( - e) { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_c89" >&5 +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_c89" >&5 printf "%s\n" "$ac_cv_prog_cc_c89" >&6; } - CC="$CC $ac_cv_prog_cc_c89" ;; -esac + CC="$CC $ac_cv_prog_cc_c89" fi ac_cv_prog_cc_stdc=$ac_cv_prog_cc_c89 - ac_prog_cc_stdc=c89 ;; -esac + ac_prog_cc_stdc=c89 fi fi @@ -5330,8 +5243,8 @@ printf %s "checking for a sed that does if test ${ac_cv_path_SED+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_script=s/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa/bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb/ +else $as_nop + ac_script=s/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa/bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb/ for ac_i in 1 2 3 4 5 6 7; do ac_script="$ac_script$as_nl$ac_script" done @@ -5356,10 +5269,9 @@ do as_fn_executable_p "$ac_path_SED" || continue # Check for GNU ac_path_SED and select it if it is found. # Check for GNU $ac_path_SED -case `"$ac_path_SED" --version 2>&1` in #( +case `"$ac_path_SED" --version 2>&1` in *GNU*) ac_cv_path_SED="$ac_path_SED" ac_path_SED_found=:;; -#( *) ac_count=0 printf %s 0123456789 >"conftest.in" @@ -5394,8 +5306,7 @@ IFS=$as_save_IFS else ac_cv_path_SED=$SED fi - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_path_SED" >&5 printf "%s\n" "$ac_cv_path_SED" >&6; } @@ -5411,8 +5322,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_AWK+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$AWK"; then +else $as_nop + if test -n "$AWK"; then ac_cv_prog_AWK="$AWK" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -5434,8 +5345,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi AWK=$ac_cv_prog_AWK if test -n "$AWK"; then @@ -5455,8 +5365,8 @@ printf %s "checking for grep that handle if test ${ac_cv_path_GREP+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -z "$GREP"; then +else $as_nop + if test -z "$GREP"; then ac_path_GREP_found=false # Loop through the user's path and test for each of PROGNAME-LIST as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -5475,10 +5385,9 @@ do as_fn_executable_p "$ac_path_GREP" || continue # Check for GNU ac_path_GREP and select it if it is found. # Check for GNU $ac_path_GREP -case `"$ac_path_GREP" --version 2>&1` in #( +case `"$ac_path_GREP" --version 2>&1` in *GNU*) ac_cv_path_GREP="$ac_path_GREP" ac_path_GREP_found=:;; -#( *) ac_count=0 printf %s 0123456789 >"conftest.in" @@ -5513,8 +5422,7 @@ IFS=$as_save_IFS else ac_cv_path_GREP=$GREP fi - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_path_GREP" >&5 printf "%s\n" "$ac_cv_path_GREP" >&6; } @@ -5526,8 +5434,8 @@ printf %s "checking for egrep... " >&6; if test ${ac_cv_path_EGREP+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if echo a | $GREP -E '(a|b)' >/dev/null 2>&1 +else $as_nop + if echo a | $GREP -E '(a|b)' >/dev/null 2>&1 then ac_cv_path_EGREP="$GREP -E" else if test -z "$EGREP"; then @@ -5549,10 +5457,9 @@ do as_fn_executable_p "$ac_path_EGREP" || continue # Check for GNU ac_path_EGREP and select it if it is found. # Check for GNU $ac_path_EGREP -case `"$ac_path_EGREP" --version 2>&1` in #( +case `"$ac_path_EGREP" --version 2>&1` in *GNU*) ac_cv_path_EGREP="$ac_path_EGREP" ac_path_EGREP_found=:;; -#( *) ac_count=0 printf %s 0123456789 >"conftest.in" @@ -5588,15 +5495,12 @@ else ac_cv_path_EGREP=$EGREP fi - fi ;; -esac + fi fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_path_EGREP" >&5 printf "%s\n" "$ac_cv_path_EGREP" >&6; } EGREP="$ac_cv_path_EGREP" - EGREP_TRADITIONAL=$EGREP - ac_cv_path_EGREP_TRADITIONAL=$EGREP for ac_prog in flex lex do @@ -5607,8 +5511,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_LEX+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$LEX"; then +else $as_nop + if test -n "$LEX"; then ac_cv_prog_LEX="$LEX" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -5630,8 +5534,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi LEX=$ac_cv_prog_LEX if test -n "$LEX"; then @@ -5689,8 +5592,8 @@ printf %s "checking for lex output file if test ${ac_cv_prog_lex_root+y} then : printf %s "(cached) " >&6 -else case e in #( - e) +else $as_nop + ac_cv_prog_lex_root=unknown { { ac_try="$LEX conftest.l" case "(($ac_try" in @@ -5707,8 +5610,7 @@ if test -f lex.yy.c; then ac_cv_prog_lex_root=lex.yy elif test -f lexyy.c; then ac_cv_prog_lex_root=lexyy -fi ;; -esac +fi fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_lex_root" >&5 printf "%s\n" "$ac_cv_prog_lex_root" >&6; } @@ -5723,15 +5625,15 @@ LEX_OUTPUT_ROOT=$ac_cv_prog_lex_root if test ${LEXLIB+y} then : -else case e in #( - e) +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for lex library" >&5 printf %s "checking for lex library... " >&6; } if test ${ac_cv_lib_lex+y} then : printf %s "(cached) " >&6 -else case e in #( - e) +else $as_nop + ac_save_LIBS="$LIBS" ac_found=false for ac_cv_lib_lex in 'none needed' -lfl -ll 'not found'; do @@ -5761,8 +5663,7 @@ rm -f core conftest.err conftest.$ac_obj fi done LIBS="$ac_save_LIBS" - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_lib_lex" >&5 printf "%s\n" "$ac_cv_lib_lex" >&6; } @@ -5774,12 +5675,10 @@ printf "%s\n" "$as_me: WARNING: required elif test "$ac_cv_lib_lex" = 'none needed' then : LEXLIB='' -else case e in #( - e) LEXLIB=$ac_cv_lib_lex ;; -esac +else $as_nop + LEXLIB=$ac_cv_lib_lex fi - ;; -esac + fi @@ -5791,8 +5690,8 @@ printf %s "checking whether yytext is a if test ${ac_cv_prog_lex_yytext_pointer+y} then : printf %s "(cached) " >&6 -else case e in #( - e) # POSIX says lex can declare yytext either as a pointer or an array; the +else $as_nop + # POSIX says lex can declare yytext either as a pointer or an array; the # default is implementation-dependent. Figure out which it is, since # not all implementations provide the %pointer and %array declarations. ac_cv_prog_lex_yytext_pointer=no @@ -5807,8 +5706,7 @@ then : ac_cv_prog_lex_yytext_pointer=yes fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_lex_yytext_pointer" >&5 printf "%s\n" "$ac_cv_prog_lex_yytext_pointer" >&6; } @@ -5831,8 +5729,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_YACC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$YACC"; then +else $as_nop + if test -n "$YACC"; then ac_cv_prog_YACC="$YACC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -5854,8 +5752,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi YACC=$ac_cv_prog_YACC if test -n "$YACC"; then @@ -5904,8 +5801,8 @@ if test -z "$INSTALL"; then if test ${ac_cv_path_install+y} then : printf %s "(cached) " >&6 -else case e in #( - e) as_save_IFS=$IFS; IFS=$PATH_SEPARATOR +else $as_nop + as_save_IFS=$IFS; IFS=$PATH_SEPARATOR for as_dir in $PATH do IFS=$as_save_IFS @@ -5959,8 +5856,7 @@ esac IFS=$as_save_IFS rm -rf conftest.one conftest.two conftest.dir - ;; -esac + fi if test ${ac_cv_path_install+y}; then INSTALL=$ac_cv_path_install @@ -5995,14 +5891,13 @@ then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: yes" >&5 printf "%s\n" "yes" >&6; } -else case e in #( - e) +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 printf "%s\n" "no" >&6; } as_fn_error $? "unable to find a lexer that supports -i. If one is available then set the LEX variable" "$LINENO" 5 - ;; -esac + fi # Check if lex defines yy_current_buffer, because 2.4.6 and older use it, @@ -6044,8 +5939,8 @@ cache=`echo g | sed 'y%.=/+-%___p_%'` if eval test \${cv_prog_cc_flag_$cache+y} then : printf %s "(cached) " >&6 -else case e in #( - e) +else $as_nop + echo 'void f(void){}' >conftest.c if test -z "`$CC $CPPFLAGS $CFLAGS -g -c conftest.c 2>&1`"; then eval "cv_prog_cc_flag_$cache=yes" @@ -6053,8 +5948,7 @@ else eval "cv_prog_cc_flag_$cache=no" fi rm -f conftest conftest.o conftest.c - ;; -esac + fi if eval "test \"`echo '$cv_prog_cc_flag_'$cache`\" = yes"; then @@ -6078,8 +5972,8 @@ cache=`echo O2 | sed 'y%.=/+-%___p_%'` if eval test \${cv_prog_cc_flag_$cache+y} then : printf %s "(cached) " >&6 -else case e in #( - e) +else $as_nop + echo 'void f(void){}' >conftest.c if test -z "`$CC $CPPFLAGS $CFLAGS -O2 -c conftest.c 2>&1`"; then eval "cv_prog_cc_flag_$cache=yes" @@ -6087,8 +5981,7 @@ else eval "cv_prog_cc_flag_$cache=no" fi rm -f conftest conftest.o conftest.c - ;; -esac + fi if eval "test \"`echo '$cv_prog_cc_flag_'$cache`\" = yes"; then @@ -6141,10 +6034,9 @@ printf "%s\n" "yes" >&6; } fi rm -f conftest conftest.c conftest.o -else case e in #( - e) CFLAGS="$BAKCFLAGS" ; { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 -printf "%s\n" "no" >&6; } ;; -esac +else $as_nop + CFLAGS="$BAKCFLAGS" ; { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 +printf "%s\n" "no" >&6; } fi rm -f core conftest.err conftest.$ac_objext conftest.beam \ conftest$ac_exeext conftest.$ac_ext @@ -6191,10 +6083,9 @@ printf "%s\n" "yes" >&6; } fi rm -f conftest conftest.c conftest.o -else case e in #( - e) LDFLAGS="$BAKLDFLAGS" ; CFLAGS="$BAKCFLAGS" ; { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 -printf "%s\n" "no" >&6; } ;; -esac +else $as_nop + LDFLAGS="$BAKLDFLAGS" ; CFLAGS="$BAKCFLAGS" ; { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 +printf "%s\n" "no" >&6; } fi rm -f core conftest.err conftest.$ac_objext conftest.beam \ conftest$ac_exeext conftest.$ac_ext @@ -6239,10 +6130,9 @@ printf "%s\n" "yes" >&6; } fi rm -f conftest conftest.c conftest.o -else case e in #( - e) LDFLAGS="$BAKLDFLAGS" ; { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 -printf "%s\n" "no" >&6; } ;; -esac +else $as_nop + LDFLAGS="$BAKLDFLAGS" ; { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 +printf "%s\n" "no" >&6; } fi rm -f core conftest.err conftest.$ac_objext conftest.beam \ conftest$ac_exeext conftest.$ac_ext @@ -6255,8 +6145,8 @@ printf %s "checking for an ANSI C-confor if test ${ac_cv_c_const+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ int @@ -6320,12 +6210,10 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ac_cv_c_const=yes -else case e in #( - e) ac_cv_c_const=no ;; -esac +else $as_nop + ac_cv_c_const=no fi -rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac +rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_c_const" >&5 printf "%s\n" "$ac_cv_c_const" >&6; } @@ -6340,8 +6228,8 @@ printf %s "checking for inline... " >&6; if test ${ac_cv_c_inline+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_cv_c_inline=no +else $as_nop + ac_cv_c_inline=no for ac_kw in inline __inline__ __inline; do cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ @@ -6359,8 +6247,7 @@ fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext test "$ac_cv_c_inline" != no && break done - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_c_inline" >&5 printf "%s\n" "$ac_cv_c_inline" >&6; } @@ -6380,26 +6267,169 @@ _ACEOF ;; esac -ac_fn_c_check_type "$LINENO" "uid_t" "ac_cv_type_uid_t" "$ac_includes_default" -if test "x$ac_cv_type_uid_t" = xyes +ac_ext=c +ac_cpp='$CPP $CPPFLAGS' +ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5' +ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5' +ac_compiler_gnu=$ac_cv_c_compiler_gnu +{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking how to run the C preprocessor" >&5 +printf %s "checking how to run the C preprocessor... " >&6; } +# On Suns, sometimes $CPP names a directory. +if test -n "$CPP" && test -d "$CPP"; then + CPP= +fi +if test -z "$CPP"; then + if test ${ac_cv_prog_CPP+y} +then : + printf %s "(cached) " >&6 +else $as_nop + # Double quotes because $CC needs to be expanded + for CPP in "$CC -E" "$CC -E -traditional-cpp" cpp /lib/cpp + do + ac_preproc_ok=false +for ac_c_preproc_warn_flag in '' yes +do + # Use a header file that comes with gcc, so configuring glibc + # with a fresh cross-compiler works. + # On the NeXT, cc -E runs the code through the compiler's parser, + # not just through cpp. "Syntax error" is here to catch this case. + cat confdefs.h - <<_ACEOF >conftest.$ac_ext +/* end confdefs.h. */ +#include + Syntax error +_ACEOF +if ac_fn_c_try_cpp "$LINENO" then : -else case e in #( - e) -printf "%s\n" "#define uid_t int" >>confdefs.h - ;; -esac +else $as_nop + # Broken: fails on valid input. +continue +fi +rm -f conftest.err conftest.i conftest.$ac_ext + + # OK, works on sane cases. Now check whether nonexistent headers + # can be detected and how. + cat confdefs.h - <<_ACEOF >conftest.$ac_ext +/* end confdefs.h. */ +#include +_ACEOF +if ac_fn_c_try_cpp "$LINENO" +then : + # Broken: success on invalid input. +continue +else $as_nop + # Passes both tests. +ac_preproc_ok=: +break +fi +rm -f conftest.err conftest.i conftest.$ac_ext + +done +# Because of `break', _AC_PREPROC_IFELSE's cleaning code was skipped. +rm -f conftest.i conftest.err conftest.$ac_ext +if $ac_preproc_ok +then : + break +fi + + done + ac_cv_prog_CPP=$CPP + +fi + CPP=$ac_cv_prog_CPP +else + ac_cv_prog_CPP=$CPP +fi +{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $CPP" >&5 +printf "%s\n" "$CPP" >&6; } +ac_preproc_ok=false +for ac_c_preproc_warn_flag in '' yes +do + # Use a header file that comes with gcc, so configuring glibc + # with a fresh cross-compiler works. + # On the NeXT, cc -E runs the code through the compiler's parser, + # not just through cpp. "Syntax error" is here to catch this case. + cat confdefs.h - <<_ACEOF >conftest.$ac_ext +/* end confdefs.h. */ +#include + Syntax error +_ACEOF +if ac_fn_c_try_cpp "$LINENO" +then : + +else $as_nop + # Broken: fails on valid input. +continue +fi +rm -f conftest.err conftest.i conftest.$ac_ext + + # OK, works on sane cases. Now check whether nonexistent headers + # can be detected and how. + cat confdefs.h - <<_ACEOF >conftest.$ac_ext +/* end confdefs.h. */ +#include +_ACEOF +if ac_fn_c_try_cpp "$LINENO" +then : + # Broken: success on invalid input. +continue +else $as_nop + # Passes both tests. +ac_preproc_ok=: +break +fi +rm -f conftest.err conftest.i conftest.$ac_ext + +done +# Because of `break', _AC_PREPROC_IFELSE's cleaning code was skipped. +rm -f conftest.i conftest.err conftest.$ac_ext +if $ac_preproc_ok +then : + +else $as_nop + { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +printf "%s\n" "$as_me: error: in \`$ac_pwd':" >&2;} +as_fn_error $? "C preprocessor \"$CPP\" fails sanity check +See \`config.log' for more details" "$LINENO" 5; } fi -ac_fn_c_check_type "$LINENO" "gid_t" "ac_cv_type_gid_t" "$ac_includes_default" -if test "x$ac_cv_type_gid_t" = xyes +ac_ext=c +ac_cpp='$CPP $CPPFLAGS' +ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5' +ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5' +ac_compiler_gnu=$ac_cv_c_compiler_gnu + + +{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for uid_t in sys/types.h" >&5 +printf %s "checking for uid_t in sys/types.h... " >&6; } +if test ${ac_cv_type_uid_t+y} +then : + printf %s "(cached) " >&6 +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext +/* end confdefs.h. */ +#include + +_ACEOF +if (eval "$ac_cpp conftest.$ac_ext") 2>&5 | + $EGREP "uid_t" >/dev/null 2>&1 then : + ac_cv_type_uid_t=yes +else $as_nop + ac_cv_type_uid_t=no +fi +rm -rf conftest* + +fi +{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_type_uid_t" >&5 +printf "%s\n" "$ac_cv_type_uid_t" >&6; } +if test $ac_cv_type_uid_t = no; then + +printf "%s\n" "#define uid_t int" >>confdefs.h + -else case e in #( - e) printf "%s\n" "#define gid_t int" >>confdefs.h - ;; -esac + fi @@ -6408,8 +6438,8 @@ fi if test "x$ac_cv_type_pid_t" = xyes then : -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #if defined _WIN64 && !defined __CYGWIN__ @@ -6428,16 +6458,14 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ac_pid_type='int' -else case e in #( - e) ac_pid_type='__int64' ;; -esac +else $as_nop + ac_pid_type='__int64' fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext printf "%s\n" "#define pid_t $ac_pid_type" >>confdefs.h - ;; -esac + fi @@ -6445,22 +6473,20 @@ ac_fn_c_check_type "$LINENO" "size_t" "a if test "x$ac_cv_type_size_t" = xyes then : -else case e in #( - e) +else $as_nop + printf "%s\n" "#define size_t unsigned int" >>confdefs.h - ;; -esac + fi ac_fn_c_check_type "$LINENO" "off_t" "ac_cv_type_off_t" "$ac_includes_default" if test "x$ac_cv_type_off_t" = xyes then : -else case e in #( - e) +else $as_nop + printf "%s\n" "#define off_t long int" >>confdefs.h - ;; -esac + fi @@ -6470,8 +6496,8 @@ printf %s "checking whether the C compil if test ${ac_cv_c_format_attribute+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_cv_c_format_attribute=no +else $as_nop + ac_cv_c_format_attribute=no cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include @@ -6491,13 +6517,11 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ac_cv_c_format_attribute="yes" -else case e in #( - e) ac_cv_c_format_attribute="no" ;; -esac +else $as_nop + ac_cv_c_format_attribute="no" fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext - ;; -esac + fi @@ -6515,8 +6539,8 @@ printf %s "checking whether the C compil if test ${ac_cv_c_unused_attribute+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_cv_c_unused_attribute=no +else $as_nop + ac_cv_c_unused_attribute=no cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include @@ -6535,13 +6559,11 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ac_cv_c_unused_attribute="yes" -else case e in #( - e) ac_cv_c_unused_attribute="no" ;; -esac +else $as_nop + ac_cv_c_unused_attribute="no" fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext - ;; -esac + fi @@ -6559,8 +6581,8 @@ printf %s "checking whether the C compil if test ${ac_cv_c_weak_attribute+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_cv_c_weak_attribute=no +else $as_nop + ac_cv_c_weak_attribute=no cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include @@ -6579,13 +6601,11 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ac_cv_c_weak_attribute="yes" -else case e in #( - e) ac_cv_c_weak_attribute="no" ;; -esac +else $as_nop + ac_cv_c_weak_attribute="no" fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext - ;; -esac + fi @@ -6606,8 +6626,8 @@ printf %s "checking whether the C compil if test ${ac_cv_c_noreturn_attribute+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_cv_c_noreturn_attribute=no +else $as_nop + ac_cv_c_noreturn_attribute=no cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include @@ -6626,13 +6646,11 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ac_cv_c_noreturn_attribute="yes" -else case e in #( - e) ac_cv_c_noreturn_attribute="no" ;; -esac +else $as_nop + ac_cv_c_noreturn_attribute="no" fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext - ;; -esac + fi @@ -6663,8 +6681,8 @@ printf "%s\n" "#define MEMCMP_IS_BROKEN esac -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include @@ -6683,8 +6701,8 @@ if ac_fn_c_try_run "$LINENO" then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: yes" >&5 printf "%s\n" "yes" >&6; } -else case e in #( - e) { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 printf "%s\n" "no" >&6; } printf "%s\n" "#define MEMCMP_IS_BROKEN 1" >>confdefs.h @@ -6695,12 +6713,10 @@ printf "%s\n" "#define MEMCMP_IS_BROKEN ;; esac - ;; -esac + fi rm -f core *.core core.conftest.* gmon.out bb.out conftest$ac_exeext \ - conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac + conftest.$ac_objext conftest.beam conftest.$ac_ext fi @@ -6709,8 +6725,8 @@ printf %s "checking whether ctime_r work if test ${ac_cv_c_ctime_c+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_cv_c_ctime_c=no +else $as_nop + ac_cv_c_ctime_c=no cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include @@ -6728,13 +6744,11 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ac_cv_c_ctime_c="yes" -else case e in #( - e) ac_cv_c_ctime_c="no" ;; -esac +else $as_nop + ac_cv_c_ctime_c="no" fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext - ;; -esac + fi @@ -6757,9 +6771,8 @@ fi if test ${with_libevent+y} then : withval=$with_libevent; -else case e in #( - e) withval="yes" ;; -esac +else $as_nop + withval="yes" fi if test x_$withval = x_yes -o x_$withval != x_no; then @@ -6823,21 +6836,15 @@ printf %s "checking for library containi if test ${ac_cv_search_clock_gettime+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_func_search_save_LIBS=$LIBS +else $as_nop + ac_func_search_save_LIBS=$LIBS cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ /* Override any GCC internal prototype to avoid an error. Use char because int might match the return type of a GCC - builtin and then its argument prototype would still apply. - The 'extern "C"' is for builds by C++ compilers; - although this is not generally supported in C code supporting it here - has little cost and some practical benefit (sr 110532). */ -#ifdef __cplusplus -extern "C" -#endif -char clock_gettime (void); + builtin and then its argument prototype would still apply. */ +char clock_gettime (); int main (void) { @@ -6868,13 +6875,11 @@ done if test ${ac_cv_search_clock_gettime+y} then : -else case e in #( - e) ac_cv_search_clock_gettime=no ;; -esac +else $as_nop + ac_cv_search_clock_gettime=no fi rm conftest.$ac_ext -LIBS=$ac_func_search_save_LIBS ;; -esac +LIBS=$ac_func_search_save_LIBS fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_clock_gettime" >&5 printf "%s\n" "$ac_cv_search_clock_gettime" >&6; } @@ -6900,8 +6905,8 @@ printf %s "checking for $CC options need if test ${ac_cv_c_undeclared_builtin_options+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_save_CFLAGS=$CFLAGS +else $as_nop + ac_save_CFLAGS=$CFLAGS ac_cv_c_undeclared_builtin_options='cannot detect' for ac_arg in '' -fno-builtin; do CFLAGS="$ac_save_CFLAGS $ac_arg" @@ -6920,8 +6925,8 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : -else case e in #( - e) # This test program should compile successfully. +else $as_nop + # This test program should compile successfully. # No library function is consistently available on # freestanding implementations, so test against a dummy # declaration. Include always-available headers on the @@ -6949,29 +6954,26 @@ then : if test x"$ac_arg" = x then : ac_cv_c_undeclared_builtin_options='none needed' -else case e in #( - e) ac_cv_c_undeclared_builtin_options=$ac_arg ;; -esac +else $as_nop + ac_cv_c_undeclared_builtin_options=$ac_arg fi break fi -rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac +rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext done CFLAGS=$ac_save_CFLAGS - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_c_undeclared_builtin_options" >&5 printf "%s\n" "$ac_cv_c_undeclared_builtin_options" >&6; } case $ac_cv_c_undeclared_builtin_options in #( 'cannot detect') : - { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} + { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +printf "%s\n" "$as_me: error: in \`$ac_pwd':" >&2;} as_fn_error $? "cannot make $CC report undeclared builtins -See 'config.log' for more details" "$LINENO" 5; } ;; #( +See \`config.log' for more details" "$LINENO" 5; } ;; #( 'none needed') : ac_c_undeclared_builtin_options='' ;; #( *) : @@ -6990,21 +6992,15 @@ printf %s "checking for library containi if test ${ac_cv_search_event_set+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_func_search_save_LIBS=$LIBS +else $as_nop + ac_func_search_save_LIBS=$LIBS cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ /* Override any GCC internal prototype to avoid an error. Use char because int might match the return type of a GCC - builtin and then its argument prototype would still apply. - The 'extern "C"' is for builds by C++ compilers; - although this is not generally supported in C code supporting it here - has little cost and some practical benefit (sr 110532). */ -#ifdef __cplusplus -extern "C" -#endif -char event_set (void); + builtin and then its argument prototype would still apply. */ +char event_set (); int main (void) { @@ -7035,13 +7031,11 @@ done if test ${ac_cv_search_event_set+y} then : -else case e in #( - e) ac_cv_search_event_set=no ;; -esac +else $as_nop + ac_cv_search_event_set=no fi rm conftest.$ac_ext -LIBS=$ac_func_search_save_LIBS ;; -esac +LIBS=$ac_func_search_save_LIBS fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_event_set" >&5 printf "%s\n" "$ac_cv_search_event_set" >&6; } @@ -7053,28 +7047,22 @@ then : fi -else case e in #( - e) +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for library containing event_set" >&5 printf %s "checking for library containing event_set... " >&6; } if test ${ac_cv_search_event_set+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_func_search_save_LIBS=$LIBS +else $as_nop + ac_func_search_save_LIBS=$LIBS cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ /* Override any GCC internal prototype to avoid an error. Use char because int might match the return type of a GCC - builtin and then its argument prototype would still apply. - The 'extern "C"' is for builds by C++ compilers; - although this is not generally supported in C code supporting it here - has little cost and some practical benefit (sr 110532). */ -#ifdef __cplusplus -extern "C" -#endif -char event_set (void); + builtin and then its argument prototype would still apply. */ +char event_set (); int main (void) { @@ -7105,13 +7093,11 @@ done if test ${ac_cv_search_event_set+y} then : -else case e in #( - e) ac_cv_search_event_set=no ;; -esac +else $as_nop + ac_cv_search_event_set=no fi rm conftest.$ac_ext -LIBS=$ac_func_search_save_LIBS ;; -esac +LIBS=$ac_func_search_save_LIBS fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_event_set" >&5 printf "%s\n" "$ac_cv_search_event_set" >&6; } @@ -7122,8 +7108,7 @@ then : fi - ;; -esac + fi ac_fn_c_check_func "$LINENO" "event_base_free" "ac_cv_func_event_base_free" if test "x$ac_cv_func_event_base_free" = xyes @@ -7185,12 +7170,11 @@ printf "%s\n" "#define USE_METRICS /**/" printf "%s\n" "#define NSD_METRICS_PORT 9100" >>confdefs.h -else case e in #( - e) +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: disabling prometheus metrics" >&5 printf "%s\n" "$as_me: disabling prometheus metrics" >&6;} - ;; -esac + fi done @@ -7208,8 +7192,8 @@ printf %s "checking for sys/wait.h that if test ${ac_cv_header_sys_wait_h+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include #include @@ -7233,12 +7217,10 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ac_cv_header_sys_wait_h=yes -else case e in #( - e) ac_cv_header_sys_wait_h=no ;; -esac +else $as_nop + ac_cv_header_sys_wait_h=no fi -rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac +rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_header_sys_wait_h" >&5 printf "%s\n" "$ac_cv_header_sys_wait_h" >&6; } @@ -7441,8 +7423,8 @@ printf %s "checking for double definitio if test ${ac_cv_c_va_list_def+y} then : printf %s "(cached) " >&6 -else case e in #( - e) +else $as_nop + cat >conftest.c < #include @@ -7454,8 +7436,7 @@ else eval "ac_cv_c_va_list_def=yes" fi rm -f conftest* - ;; -esac + fi if test $ac_cv_c_va_list_def = yes; then @@ -7480,8 +7461,8 @@ printf %s "checking whether strptime nee if test ${ac_cv_c_strptime_needs_defs+y} then : printf %s "(cached) " >&6 -else case e in #( - e) +else $as_nop + cat >conftest.c < int testing (void) { struct tm t; const char *timestr="201201"; return strptime(timestr, "%Y%m", &t) != 0; } @@ -7492,8 +7473,7 @@ else eval "ac_cv_c_strptime_needs_defs=yes" fi rm -f conftest* - ;; -esac + fi @@ -7513,21 +7493,15 @@ printf %s "checking for library containi if test ${ac_cv_search_inet_pton+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_func_search_save_LIBS=$LIBS +else $as_nop + ac_func_search_save_LIBS=$LIBS cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ /* Override any GCC internal prototype to avoid an error. Use char because int might match the return type of a GCC - builtin and then its argument prototype would still apply. - The 'extern "C"' is for builds by C++ compilers; - although this is not generally supported in C code supporting it here - has little cost and some practical benefit (sr 110532). */ -#ifdef __cplusplus -extern "C" -#endif -char inet_pton (void); + builtin and then its argument prototype would still apply. */ +char inet_pton (); int main (void) { @@ -7558,13 +7532,11 @@ done if test ${ac_cv_search_inet_pton+y} then : -else case e in #( - e) ac_cv_search_inet_pton=no ;; -esac +else $as_nop + ac_cv_search_inet_pton=no fi rm conftest.$ac_ext -LIBS=$ac_func_search_save_LIBS ;; -esac +LIBS=$ac_func_search_save_LIBS fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_inet_pton" >&5 printf "%s\n" "$ac_cv_search_inet_pton" >&6; } @@ -7580,21 +7552,15 @@ printf %s "checking for library containi if test ${ac_cv_search_socket+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_func_search_save_LIBS=$LIBS +else $as_nop + ac_func_search_save_LIBS=$LIBS cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ /* Override any GCC internal prototype to avoid an error. Use char because int might match the return type of a GCC - builtin and then its argument prototype would still apply. - The 'extern "C"' is for builds by C++ compilers; - although this is not generally supported in C code supporting it here - has little cost and some practical benefit (sr 110532). */ -#ifdef __cplusplus -extern "C" -#endif -char socket (void); + builtin and then its argument prototype would still apply. */ +char socket (); int main (void) { @@ -7625,13 +7591,11 @@ done if test ${ac_cv_search_socket+y} then : -else case e in #( - e) ac_cv_search_socket=no ;; -esac +else $as_nop + ac_cv_search_socket=no fi rm conftest.$ac_ext -LIBS=$ac_func_search_save_LIBS ;; -esac +LIBS=$ac_func_search_save_LIBS fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_socket" >&5 printf "%s\n" "$ac_cv_search_socket" >&6; } @@ -7650,8 +7614,8 @@ if test c${cross_compiling} = cno; then if test "$cross_compiling" = yes then : eval "ac_cv_c_strptime_works=maybe" -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #define _XOPEN_SOURCE 600 @@ -7664,13 +7628,11 @@ _ACEOF if ac_fn_c_try_run "$LINENO" then : eval "ac_cv_c_strptime_works=yes" -else case e in #( - e) eval "ac_cv_c_strptime_works=no" ;; -esac +else $as_nop + eval "ac_cv_c_strptime_works=no" fi rm -f core *.core core.conftest.* gmon.out bb.out conftest$ac_exeext \ - conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac + conftest.$ac_objext conftest.beam conftest.$ac_ext fi else @@ -7707,8 +7669,8 @@ then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: crosscompile(yes)" >&5 printf "%s\n" "crosscompile(yes)" >&6; } -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ @@ -7843,19 +7805,17 @@ then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: yes" >&5 printf "%s\n" "yes" >&6; } -else case e in #( - e) +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 printf "%s\n" "no" >&6; } printf "%s\n" "#define NONBLOCKING_IS_BROKEN 1" >>confdefs.h - ;; -esac + fi rm -f core *.core core.conftest.* gmon.out bb.out conftest$ac_exeext \ - conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac + conftest.$ac_objext conftest.beam conftest.$ac_ext fi fi @@ -7893,11 +7853,10 @@ printf "%s\n" "yes" >&6; } printf "%s\n" "#define MKDIR_HAS_ONE_ARG 1" >>confdefs.h -else case e in #( - e) { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 printf "%s\n" "no" >&6; } - ;; -esac + fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext @@ -7918,286 +7877,13 @@ fi -ac_ext=c -ac_cpp='$CPP $CPPFLAGS' -ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5' -ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5' -ac_compiler_gnu=$ac_cv_c_compiler_gnu -{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking how to run the C preprocessor" >&5 -printf %s "checking how to run the C preprocessor... " >&6; } -# On Suns, sometimes $CPP names a directory. -if test -n "$CPP" && test -d "$CPP"; then - CPP= -fi -if test -z "$CPP"; then - if test ${ac_cv_prog_CPP+y} -then : - printf %s "(cached) " >&6 -else case e in #( - e) # Double quotes because $CC needs to be expanded - for CPP in "$CC -E" "$CC -E -traditional-cpp" cpp /lib/cpp - do - ac_preproc_ok=false -for ac_c_preproc_warn_flag in '' yes -do - # Use a header file that comes with gcc, so configuring glibc - # with a fresh cross-compiler works. - # On the NeXT, cc -E runs the code through the compiler's parser, - # not just through cpp. "Syntax error" is here to catch this case. - cat confdefs.h - <<_ACEOF >conftest.$ac_ext -/* end confdefs.h. */ -#include - Syntax error -_ACEOF -if ac_fn_c_try_cpp "$LINENO" -then : - -else case e in #( - e) # Broken: fails on valid input. -continue ;; -esac -fi -rm -f conftest.err conftest.i conftest.$ac_ext - - # OK, works on sane cases. Now check whether nonexistent headers - # can be detected and how. - cat confdefs.h - <<_ACEOF >conftest.$ac_ext -/* end confdefs.h. */ -#include -_ACEOF -if ac_fn_c_try_cpp "$LINENO" -then : - # Broken: success on invalid input. -continue -else case e in #( - e) # Passes both tests. -ac_preproc_ok=: -break ;; -esac -fi -rm -f conftest.err conftest.i conftest.$ac_ext - -done -# Because of 'break', _AC_PREPROC_IFELSE's cleaning code was skipped. -rm -f conftest.i conftest.err conftest.$ac_ext -if $ac_preproc_ok -then : - break -fi - - done - ac_cv_prog_CPP=$CPP - ;; -esac -fi - CPP=$ac_cv_prog_CPP -else - ac_cv_prog_CPP=$CPP -fi -{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $CPP" >&5 -printf "%s\n" "$CPP" >&6; } -ac_preproc_ok=false -for ac_c_preproc_warn_flag in '' yes -do - # Use a header file that comes with gcc, so configuring glibc - # with a fresh cross-compiler works. - # On the NeXT, cc -E runs the code through the compiler's parser, - # not just through cpp. "Syntax error" is here to catch this case. - cat confdefs.h - <<_ACEOF >conftest.$ac_ext -/* end confdefs.h. */ -#include - Syntax error -_ACEOF -if ac_fn_c_try_cpp "$LINENO" -then : - -else case e in #( - e) # Broken: fails on valid input. -continue ;; -esac -fi -rm -f conftest.err conftest.i conftest.$ac_ext - - # OK, works on sane cases. Now check whether nonexistent headers - # can be detected and how. - cat confdefs.h - <<_ACEOF >conftest.$ac_ext -/* end confdefs.h. */ -#include -_ACEOF -if ac_fn_c_try_cpp "$LINENO" -then : - # Broken: success on invalid input. -continue -else case e in #( - e) # Passes both tests. -ac_preproc_ok=: -break ;; -esac -fi -rm -f conftest.err conftest.i conftest.$ac_ext - -done -# Because of 'break', _AC_PREPROC_IFELSE's cleaning code was skipped. -rm -f conftest.i conftest.err conftest.$ac_ext -if $ac_preproc_ok -then : - -else case e in #( - e) { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} -as_fn_error $? "C preprocessor \"$CPP\" fails sanity check -See 'config.log' for more details" "$LINENO" 5; } ;; -esac -fi - -ac_ext=c -ac_cpp='$CPP $CPPFLAGS' -ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5' -ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5' -ac_compiler_gnu=$ac_cv_c_compiler_gnu - - -{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for egrep -e" >&5 -printf %s "checking for egrep -e... " >&6; } -if test ${ac_cv_path_EGREP_TRADITIONAL+y} -then : - printf %s "(cached) " >&6 -else case e in #( - e) if test -z "$EGREP_TRADITIONAL"; then - ac_path_EGREP_TRADITIONAL_found=false - # Loop through the user's path and test for each of PROGNAME-LIST - as_save_IFS=$IFS; IFS=$PATH_SEPARATOR -for as_dir in $PATH$PATH_SEPARATOR/usr/xpg4/bin -do - IFS=$as_save_IFS - case $as_dir in #((( - '') as_dir=./ ;; - */) ;; - *) as_dir=$as_dir/ ;; - esac - for ac_prog in grep ggrep - do - for ac_exec_ext in '' $ac_executable_extensions; do - ac_path_EGREP_TRADITIONAL="$as_dir$ac_prog$ac_exec_ext" - as_fn_executable_p "$ac_path_EGREP_TRADITIONAL" || continue -# Check for GNU ac_path_EGREP_TRADITIONAL and select it if it is found. - # Check for GNU $ac_path_EGREP_TRADITIONAL -case `"$ac_path_EGREP_TRADITIONAL" --version 2>&1` in #( -*GNU*) - ac_cv_path_EGREP_TRADITIONAL="$ac_path_EGREP_TRADITIONAL" ac_path_EGREP_TRADITIONAL_found=:;; -#( -*) - ac_count=0 - printf %s 0123456789 >"conftest.in" - while : - do - cat "conftest.in" "conftest.in" >"conftest.tmp" - mv "conftest.tmp" "conftest.in" - cp "conftest.in" "conftest.nl" - printf "%s\n" 'EGREP_TRADITIONAL' >> "conftest.nl" - "$ac_path_EGREP_TRADITIONAL" -E 'EGR(EP|AC)_TRADITIONAL$' < "conftest.nl" >"conftest.out" 2>/dev/null || break - diff "conftest.out" "conftest.nl" >/dev/null 2>&1 || break - as_fn_arith $ac_count + 1 && ac_count=$as_val - if test $ac_count -gt ${ac_path_EGREP_TRADITIONAL_max-0}; then - # Best one so far, save it but keep looking for a better one - ac_cv_path_EGREP_TRADITIONAL="$ac_path_EGREP_TRADITIONAL" - ac_path_EGREP_TRADITIONAL_max=$ac_count - fi - # 10*(2^10) chars as input seems more than enough - test $ac_count -gt 10 && break - done - rm -f conftest.in conftest.tmp conftest.nl conftest.out;; -esac - - $ac_path_EGREP_TRADITIONAL_found && break 3 - done - done - done -IFS=$as_save_IFS - if test -z "$ac_cv_path_EGREP_TRADITIONAL"; then - : - fi -else - ac_cv_path_EGREP_TRADITIONAL=$EGREP_TRADITIONAL -fi - - if test "$ac_cv_path_EGREP_TRADITIONAL" -then : - ac_cv_path_EGREP_TRADITIONAL="$ac_cv_path_EGREP_TRADITIONAL -E" -else case e in #( - e) if test -z "$EGREP_TRADITIONAL"; then - ac_path_EGREP_TRADITIONAL_found=false - # Loop through the user's path and test for each of PROGNAME-LIST - as_save_IFS=$IFS; IFS=$PATH_SEPARATOR -for as_dir in $PATH$PATH_SEPARATOR/usr/xpg4/bin -do - IFS=$as_save_IFS - case $as_dir in #((( - '') as_dir=./ ;; - */) ;; - *) as_dir=$as_dir/ ;; - esac - for ac_prog in egrep - do - for ac_exec_ext in '' $ac_executable_extensions; do - ac_path_EGREP_TRADITIONAL="$as_dir$ac_prog$ac_exec_ext" - as_fn_executable_p "$ac_path_EGREP_TRADITIONAL" || continue -# Check for GNU ac_path_EGREP_TRADITIONAL and select it if it is found. - # Check for GNU $ac_path_EGREP_TRADITIONAL -case `"$ac_path_EGREP_TRADITIONAL" --version 2>&1` in #( -*GNU*) - ac_cv_path_EGREP_TRADITIONAL="$ac_path_EGREP_TRADITIONAL" ac_path_EGREP_TRADITIONAL_found=:;; -#( -*) - ac_count=0 - printf %s 0123456789 >"conftest.in" - while : - do - cat "conftest.in" "conftest.in" >"conftest.tmp" - mv "conftest.tmp" "conftest.in" - cp "conftest.in" "conftest.nl" - printf "%s\n" 'EGREP_TRADITIONAL' >> "conftest.nl" - "$ac_path_EGREP_TRADITIONAL" 'EGR(EP|AC)_TRADITIONAL$' < "conftest.nl" >"conftest.out" 2>/dev/null || break - diff "conftest.out" "conftest.nl" >/dev/null 2>&1 || break - as_fn_arith $ac_count + 1 && ac_count=$as_val - if test $ac_count -gt ${ac_path_EGREP_TRADITIONAL_max-0}; then - # Best one so far, save it but keep looking for a better one - ac_cv_path_EGREP_TRADITIONAL="$ac_path_EGREP_TRADITIONAL" - ac_path_EGREP_TRADITIONAL_max=$ac_count - fi - # 10*(2^10) chars as input seems more than enough - test $ac_count -gt 10 && break - done - rm -f conftest.in conftest.tmp conftest.nl conftest.out;; -esac - - $ac_path_EGREP_TRADITIONAL_found && break 3 - done - done - done -IFS=$as_save_IFS - if test -z "$ac_cv_path_EGREP_TRADITIONAL"; then - as_fn_error $? "no acceptable egrep could be found in $PATH$PATH_SEPARATOR/usr/xpg4/bin" "$LINENO" 5 - fi -else - ac_cv_path_EGREP_TRADITIONAL=$EGREP_TRADITIONAL -fi - ;; -esac -fi ;; -esac -fi -{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_path_EGREP_TRADITIONAL" >&5 -printf "%s\n" "$ac_cv_path_EGREP_TRADITIONAL" >&6; } - EGREP_TRADITIONAL=$ac_cv_path_EGREP_TRADITIONAL - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for int8_t" >&5 printf %s "checking for int8_t... " >&6; } if test ${ac_cv_type_int8_t+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include @@ -8227,16 +7913,14 @@ else case e in #( _ACEOF if (eval "$ac_cpp conftest.$ac_ext") 2>&5 | - $EGREP_TRADITIONAL "(^|[^a-zA-Z_0-9])int8_t[^a-zA-Z_0-9]" >/dev/null 2>&1 + $EGREP "(^|[^a-zA-Z_0-9])int8_t[^a-zA-Z_0-9]" >/dev/null 2>&1 then : ac_cv_type_int8_t=yes -else case e in #( - e) ac_cv_type_int8_t=no ;; -esac +else $as_nop + ac_cv_type_int8_t=no fi rm -rf conftest* - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_type_int8_t" >&5 printf "%s\n" "$ac_cv_type_int8_t" >&6; } @@ -8251,8 +7935,8 @@ printf %s "checking for int16_t... " >&6 if test ${ac_cv_type_int16_t+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include @@ -8282,16 +7966,14 @@ else case e in #( _ACEOF if (eval "$ac_cpp conftest.$ac_ext") 2>&5 | - $EGREP_TRADITIONAL "(^|[^a-zA-Z_0-9])int16_t[^a-zA-Z_0-9]" >/dev/null 2>&1 + $EGREP "(^|[^a-zA-Z_0-9])int16_t[^a-zA-Z_0-9]" >/dev/null 2>&1 then : ac_cv_type_int16_t=yes -else case e in #( - e) ac_cv_type_int16_t=no ;; -esac +else $as_nop + ac_cv_type_int16_t=no fi rm -rf conftest* - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_type_int16_t" >&5 printf "%s\n" "$ac_cv_type_int16_t" >&6; } @@ -8306,8 +7988,8 @@ printf %s "checking for int32_t... " >&6 if test ${ac_cv_type_int32_t+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include @@ -8337,16 +8019,14 @@ else case e in #( _ACEOF if (eval "$ac_cpp conftest.$ac_ext") 2>&5 | - $EGREP_TRADITIONAL "(^|[^a-zA-Z_0-9])int32_t[^a-zA-Z_0-9]" >/dev/null 2>&1 + $EGREP "(^|[^a-zA-Z_0-9])int32_t[^a-zA-Z_0-9]" >/dev/null 2>&1 then : ac_cv_type_int32_t=yes -else case e in #( - e) ac_cv_type_int32_t=no ;; -esac +else $as_nop + ac_cv_type_int32_t=no fi rm -rf conftest* - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_type_int32_t" >&5 printf "%s\n" "$ac_cv_type_int32_t" >&6; } @@ -8361,8 +8041,8 @@ printf %s "checking for int64_t... " >&6 if test ${ac_cv_type_int64_t+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include @@ -8392,16 +8072,14 @@ else case e in #( _ACEOF if (eval "$ac_cpp conftest.$ac_ext") 2>&5 | - $EGREP_TRADITIONAL "(^|[^a-zA-Z_0-9])int64_t[^a-zA-Z_0-9]" >/dev/null 2>&1 + $EGREP "(^|[^a-zA-Z_0-9])int64_t[^a-zA-Z_0-9]" >/dev/null 2>&1 then : ac_cv_type_int64_t=yes -else case e in #( - e) ac_cv_type_int64_t=no ;; -esac +else $as_nop + ac_cv_type_int64_t=no fi rm -rf conftest* - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_type_int64_t" >&5 printf "%s\n" "$ac_cv_type_int64_t" >&6; } @@ -8416,8 +8094,8 @@ printf %s "checking for uint8_t... " >&6 if test ${ac_cv_type_uint8_t+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include @@ -8447,16 +8125,14 @@ else case e in #( _ACEOF if (eval "$ac_cpp conftest.$ac_ext") 2>&5 | - $EGREP_TRADITIONAL "(^|[^a-zA-Z_0-9])uint8_t[^a-zA-Z_0-9]" >/dev/null 2>&1 + $EGREP "(^|[^a-zA-Z_0-9])uint8_t[^a-zA-Z_0-9]" >/dev/null 2>&1 then : ac_cv_type_uint8_t=yes -else case e in #( - e) ac_cv_type_uint8_t=no ;; -esac +else $as_nop + ac_cv_type_uint8_t=no fi rm -rf conftest* - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_type_uint8_t" >&5 printf "%s\n" "$ac_cv_type_uint8_t" >&6; } @@ -8471,8 +8147,8 @@ printf %s "checking for uint16_t... " >& if test ${ac_cv_type_uint16_t+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include @@ -8502,16 +8178,14 @@ else case e in #( _ACEOF if (eval "$ac_cpp conftest.$ac_ext") 2>&5 | - $EGREP_TRADITIONAL "(^|[^a-zA-Z_0-9])uint16_t[^a-zA-Z_0-9]" >/dev/null 2>&1 + $EGREP "(^|[^a-zA-Z_0-9])uint16_t[^a-zA-Z_0-9]" >/dev/null 2>&1 then : ac_cv_type_uint16_t=yes -else case e in #( - e) ac_cv_type_uint16_t=no ;; -esac +else $as_nop + ac_cv_type_uint16_t=no fi rm -rf conftest* - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_type_uint16_t" >&5 printf "%s\n" "$ac_cv_type_uint16_t" >&6; } @@ -8526,8 +8200,8 @@ printf %s "checking for uint32_t... " >& if test ${ac_cv_type_uint32_t+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include @@ -8557,16 +8231,14 @@ else case e in #( _ACEOF if (eval "$ac_cpp conftest.$ac_ext") 2>&5 | - $EGREP_TRADITIONAL "(^|[^a-zA-Z_0-9])uint32_t[^a-zA-Z_0-9]" >/dev/null 2>&1 + $EGREP "(^|[^a-zA-Z_0-9])uint32_t[^a-zA-Z_0-9]" >/dev/null 2>&1 then : ac_cv_type_uint32_t=yes -else case e in #( - e) ac_cv_type_uint32_t=no ;; -esac +else $as_nop + ac_cv_type_uint32_t=no fi rm -rf conftest* - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_type_uint32_t" >&5 printf "%s\n" "$ac_cv_type_uint32_t" >&6; } @@ -8581,8 +8253,8 @@ printf %s "checking for uint64_t... " >& if test ${ac_cv_type_uint64_t+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include @@ -8612,16 +8284,14 @@ else case e in #( _ACEOF if (eval "$ac_cpp conftest.$ac_ext") 2>&5 | - $EGREP_TRADITIONAL "(^|[^a-zA-Z_0-9])uint64_t[^a-zA-Z_0-9]" >/dev/null 2>&1 + $EGREP "(^|[^a-zA-Z_0-9])uint64_t[^a-zA-Z_0-9]" >/dev/null 2>&1 then : ac_cv_type_uint64_t=yes -else case e in #( - e) ac_cv_type_uint64_t=no ;; -esac +else $as_nop + ac_cv_type_uint64_t=no fi rm -rf conftest* - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_type_uint64_t" >&5 printf "%s\n" "$ac_cv_type_uint64_t" >&6; } @@ -8636,8 +8306,8 @@ printf %s "checking for socklen_t... " > if test ${ac_cv_type_socklen_t+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include @@ -8667,16 +8337,14 @@ else case e in #( _ACEOF if (eval "$ac_cpp conftest.$ac_ext") 2>&5 | - $EGREP_TRADITIONAL "(^|[^a-zA-Z_0-9])socklen_t[^a-zA-Z_0-9]" >/dev/null 2>&1 + $EGREP "(^|[^a-zA-Z_0-9])socklen_t[^a-zA-Z_0-9]" >/dev/null 2>&1 then : ac_cv_type_socklen_t=yes -else case e in #( - e) ac_cv_type_socklen_t=no ;; -esac +else $as_nop + ac_cv_type_socklen_t=no fi rm -rf conftest* - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_type_socklen_t" >&5 printf "%s\n" "$ac_cv_type_socklen_t" >&6; } @@ -8691,8 +8359,8 @@ printf %s "checking for sig_atomic_t... if test ${ac_cv_type_sig_atomic_t+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include @@ -8722,16 +8390,14 @@ else case e in #( _ACEOF if (eval "$ac_cpp conftest.$ac_ext") 2>&5 | - $EGREP_TRADITIONAL "(^|[^a-zA-Z_0-9])sig_atomic_t[^a-zA-Z_0-9]" >/dev/null 2>&1 + $EGREP "(^|[^a-zA-Z_0-9])sig_atomic_t[^a-zA-Z_0-9]" >/dev/null 2>&1 then : ac_cv_type_sig_atomic_t=yes -else case e in #( - e) ac_cv_type_sig_atomic_t=no ;; -esac +else $as_nop + ac_cv_type_sig_atomic_t=no fi rm -rf conftest* - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_type_sig_atomic_t" >&5 printf "%s\n" "$ac_cv_type_sig_atomic_t" >&6; } @@ -8746,8 +8412,8 @@ printf %s "checking for ssize_t... " >&6 if test ${ac_cv_type_ssize_t+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include @@ -8777,16 +8443,14 @@ else case e in #( _ACEOF if (eval "$ac_cpp conftest.$ac_ext") 2>&5 | - $EGREP_TRADITIONAL "(^|[^a-zA-Z_0-9])ssize_t[^a-zA-Z_0-9]" >/dev/null 2>&1 + $EGREP "(^|[^a-zA-Z_0-9])ssize_t[^a-zA-Z_0-9]" >/dev/null 2>&1 then : ac_cv_type_ssize_t=yes -else case e in #( - e) ac_cv_type_ssize_t=no ;; -esac +else $as_nop + ac_cv_type_ssize_t=no fi rm -rf conftest* - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_type_ssize_t" >&5 printf "%s\n" "$ac_cv_type_ssize_t" >&6; } @@ -8801,8 +8465,8 @@ printf %s "checking for suseconds_t... " if test ${ac_cv_type_suseconds_t+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include @@ -8832,16 +8496,14 @@ else case e in #( _ACEOF if (eval "$ac_cpp conftest.$ac_ext") 2>&5 | - $EGREP_TRADITIONAL "(^|[^a-zA-Z_0-9])suseconds_t[^a-zA-Z_0-9]" >/dev/null 2>&1 + $EGREP "(^|[^a-zA-Z_0-9])suseconds_t[^a-zA-Z_0-9]" >/dev/null 2>&1 then : ac_cv_type_suseconds_t=yes -else case e in #( - e) ac_cv_type_suseconds_t=no ;; -esac +else $as_nop + ac_cv_type_suseconds_t=no fi rm -rf conftest* - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_type_suseconds_t" >&5 printf "%s\n" "$ac_cv_type_suseconds_t" >&6; } @@ -8863,11 +8525,10 @@ ac_fn_c_check_type "$LINENO" "in_addr_t" if test "x$ac_cv_type_in_addr_t" = xyes then : -else case e in #( - e) +else $as_nop + printf "%s\n" "#define in_addr_t uint32_t" >>confdefs.h - ;; -esac + fi ac_fn_c_check_member "$LINENO" "struct sockaddr_storage" "ss_family" "ac_cv_member_struct_sockaddr_storage_ss_family" "$ac_includes_default @@ -8888,8 +8549,8 @@ ac_fn_c_check_member "$LINENO" "struct s if test "x$ac_cv_member_struct_sockaddr_storage_ss_family" = xyes then : -else case e in #( - e) +else $as_nop + ac_fn_c_check_member "$LINENO" "struct sockaddr_storage" "__ss_family" "ac_cv_member_struct_sockaddr_storage___ss_family" "$ac_includes_default #ifdef HAVE_NETINET_IN_H #include @@ -8914,8 +8575,7 @@ printf "%s\n" "#define ss_family __ss_fa fi - ;; -esac + fi ac_fn_c_check_member "$LINENO" "struct stat" "st_mtimensec" "ac_cv_member_struct_stat_st_mtimensec" "$ac_includes_default" @@ -8963,16 +8623,15 @@ printf %s "checking build system type... if test ${ac_cv_build+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_build_alias=$build_alias +else $as_nop + ac_build_alias=$build_alias test "x$ac_build_alias" = x && ac_build_alias=`$SHELL "${ac_aux_dir}config.guess"` test "x$ac_build_alias" = x && as_fn_error $? "cannot guess build type; you must specify one" "$LINENO" 5 ac_cv_build=`$SHELL "${ac_aux_dir}config.sub" $ac_build_alias` || as_fn_error $? "$SHELL ${ac_aux_dir}config.sub $ac_build_alias failed" "$LINENO" 5 - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_build" >&5 printf "%s\n" "$ac_cv_build" >&6; } @@ -8999,15 +8658,14 @@ printf %s "checking host system type... if test ${ac_cv_host+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test "x$host_alias" = x; then +else $as_nop + if test "x$host_alias" = x; then ac_cv_host=$ac_cv_build else ac_cv_host=`$SHELL "${ac_aux_dir}config.sub" $host_alias` || as_fn_error $? "$SHELL ${ac_aux_dir}config.sub $host_alias failed" "$LINENO" 5 fi - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_host" >&5 printf "%s\n" "$ac_cv_host" >&6; } @@ -9034,8 +8692,8 @@ printf %s "checking for working chown... if test ${ac_cv_func_chown_works+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test "$cross_compiling" = yes +else $as_nop + if test "$cross_compiling" = yes then : case "$host_os" in # (( # Guess yes on glibc systems. @@ -9043,8 +8701,8 @@ then : # If we don't know, assume the worst. *) ac_cv_func_chown_works=no ;; esac -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ $ac_includes_default #include @@ -9072,18 +8730,15 @@ _ACEOF if ac_fn_c_try_run "$LINENO" then : ac_cv_func_chown_works=yes -else case e in #( - e) ac_cv_func_chown_works=no ;; -esac +else $as_nop + ac_cv_func_chown_works=no fi rm -f core *.core core.conftest.* gmon.out bb.out conftest$ac_exeext \ - conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac + conftest.$ac_objext conftest.beam conftest.$ac_ext fi rm -f conftest.chown - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_func_chown_works" >&5 printf "%s\n" "$ac_cv_func_chown_works" >&6; } @@ -9116,19 +8771,19 @@ printf %s "checking for working fork... if test ${ac_cv_func_fork_works+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test "$cross_compiling" = yes +else $as_nop + if test "$cross_compiling" = yes then : ac_cv_func_fork_works=cross -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ $ac_includes_default int main (void) { - /* By R. Kuhlmann. */ + /* By Ruediger Kuhlmann. */ return fork () < 0; ; @@ -9138,16 +8793,13 @@ _ACEOF if ac_fn_c_try_run "$LINENO" then : ac_cv_func_fork_works=yes -else case e in #( - e) ac_cv_func_fork_works=no ;; -esac +else $as_nop + ac_cv_func_fork_works=no fi rm -f core *.core core.conftest.* gmon.out bb.out conftest$ac_exeext \ - conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac + conftest.$ac_objext conftest.beam conftest.$ac_ext fi - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_func_fork_works" >&5 printf "%s\n" "$ac_cv_func_fork_works" >&6; } @@ -9175,12 +8827,12 @@ printf %s "checking for working vfork... if test ${ac_cv_func_vfork_works+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test "$cross_compiling" = yes +else $as_nop + if test "$cross_compiling" = yes then : ac_cv_func_vfork_works=cross -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ /* Thanks to Paul Eggert for this test. */ $ac_includes_default @@ -9291,16 +8943,13 @@ _ACEOF if ac_fn_c_try_run "$LINENO" then : ac_cv_func_vfork_works=yes -else case e in #( - e) ac_cv_func_vfork_works=no ;; -esac +else $as_nop + ac_cv_func_vfork_works=no fi rm -f core *.core core.conftest.* gmon.out bb.out conftest$ac_exeext \ - conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac + conftest.$ac_objext conftest.beam conftest.$ac_ext fi - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_func_vfork_works" >&5 printf "%s\n" "$ac_cv_func_vfork_works" >&6; } @@ -9332,19 +8981,19 @@ printf %s "checking for GNU libc compati if test ${ac_cv_func_malloc_0_nonnull+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test "$cross_compiling" = yes +else $as_nop + if test "$cross_compiling" = yes then : case "$host_os" in # (( # Guess yes on platforms where we know the result. *-gnu* | freebsd* | netbsd* | openbsd* | bitrig* \ - | hpux* | solaris* | cygwin* | mingw* | windows* | msys* ) + | hpux* | solaris* | cygwin* | mingw* | msys* ) ac_cv_func_malloc_0_nonnull=yes ;; # If we don't know, assume the worst. *) ac_cv_func_malloc_0_nonnull=no ;; esac -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include @@ -9362,16 +9011,13 @@ _ACEOF if ac_fn_c_try_run "$LINENO" then : ac_cv_func_malloc_0_nonnull=yes -else case e in #( - e) ac_cv_func_malloc_0_nonnull=no ;; -esac +else $as_nop + ac_cv_func_malloc_0_nonnull=no fi rm -f core *.core core.conftest.* gmon.out bb.out conftest$ac_exeext \ - conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac + conftest.$ac_objext conftest.beam conftest.$ac_ext fi - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_func_malloc_0_nonnull" >&5 printf "%s\n" "$ac_cv_func_malloc_0_nonnull" >&6; } @@ -9380,8 +9026,8 @@ then : printf "%s\n" "#define HAVE_MALLOC 1" >>confdefs.h -else case e in #( - e) printf "%s\n" "#define HAVE_MALLOC 0" >>confdefs.h +else $as_nop + printf "%s\n" "#define HAVE_MALLOC 0" >>confdefs.h case " $LIBOBJS " in *" malloc.$ac_objext "* ) ;; @@ -9391,105 +9037,79 @@ esac printf "%s\n" "#define malloc rpl_malloc" >>confdefs.h - ;; -esac + fi printf "%s\n" "#define RETSIGTYPE void" >>confdefs.h -{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for declarations of fseeko and ftello" >&5 -printf %s "checking for declarations of fseeko and ftello... " >&6; } -if test ${ac_cv_func_fseeko_ftello+y} +{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for _LARGEFILE_SOURCE value needed for large files" >&5 +printf %s "checking for _LARGEFILE_SOURCE value needed for large files... " >&6; } +if test ${ac_cv_sys_largefile_source+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + while :; do + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ - -#if defined __hpux && !defined _LARGEFILE_SOURCE -# include -# if LONG_MAX >> 31 == 0 -# error "32-bit HP-UX 11/ia64 needs _LARGEFILE_SOURCE for fseeko in C++" -# endif -#endif #include /* for off_t */ -#include - + #include int main (void) { - - int (*fp1) (FILE *, off_t, int) = fseeko; - off_t (*fp2) (FILE *) = ftello; - return fseeko (stdin, 0, 0) - && fp1 (stdin, 0, 0) - && ftello (stdin) >= 0 - && fp2 (stdin) >= 0; - +int (*fp) (FILE *, off_t, int) = fseeko; + return fseeko (stdin, 0, 0) && fp (stdin, 0, 0); ; return 0; } _ACEOF -if ac_fn_c_try_compile "$LINENO" +if ac_fn_c_try_link "$LINENO" then : - ac_cv_func_fseeko_ftello=yes -else case e in #( - e) ac_save_CPPFLAGS="$CPPFLAGS" - CPPFLAGS="$CPPFLAGS -D_LARGEFILE_SOURCE=1" - cat confdefs.h - <<_ACEOF >conftest.$ac_ext + ac_cv_sys_largefile_source=no; break +fi +rm -f core conftest.err conftest.$ac_objext conftest.beam \ + conftest$ac_exeext conftest.$ac_ext + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ - -#if defined __hpux && !defined _LARGEFILE_SOURCE -# include -# if LONG_MAX >> 31 == 0 -# error "32-bit HP-UX 11/ia64 needs _LARGEFILE_SOURCE for fseeko in C++" -# endif -#endif +#define _LARGEFILE_SOURCE 1 #include /* for off_t */ -#include - + #include int main (void) { - - int (*fp1) (FILE *, off_t, int) = fseeko; - off_t (*fp2) (FILE *) = ftello; - return fseeko (stdin, 0, 0) - && fp1 (stdin, 0, 0) - && ftello (stdin) >= 0 - && fp2 (stdin) >= 0; - +int (*fp) (FILE *, off_t, int) = fseeko; + return fseeko (stdin, 0, 0) && fp (stdin, 0, 0); ; return 0; } _ACEOF -if ac_fn_c_try_compile "$LINENO" +if ac_fn_c_try_link "$LINENO" then : - ac_cv_func_fseeko_ftello="need _LARGEFILE_SOURCE" -else case e in #( - e) ac_cv_func_fseeko_ftello=no ;; -esac + ac_cv_sys_largefile_source=1; break fi -rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac +rm -f core conftest.err conftest.$ac_objext conftest.beam \ + conftest$ac_exeext conftest.$ac_ext + ac_cv_sys_largefile_source=unknown + break +done fi -rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;; +{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_sys_largefile_source" >&5 +printf "%s\n" "$ac_cv_sys_largefile_source" >&6; } +case $ac_cv_sys_largefile_source in #( + no | unknown) ;; + *) +printf "%s\n" "#define _LARGEFILE_SOURCE $ac_cv_sys_largefile_source" >>confdefs.h +;; esac -fi -{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_func_fseeko_ftello" >&5 -printf "%s\n" "$ac_cv_func_fseeko_ftello" >&6; } -if test "$ac_cv_func_fseeko_ftello" != no -then : - -printf "%s\n" "#define HAVE_FSEEKO 1" >>confdefs.h +rm -rf conftest* -fi -if test "$ac_cv_func_fseeko_ftello" = "need _LARGEFILE_SOURCE" -then : +# We used to try defining _XOPEN_SOURCE=500 too, to work around a bug +# in glibc 2.1.3, but that breaks too many other things. +# If you want fseeko and ftello with glibc, upgrade to a fixed glibc. +if test $ac_cv_sys_largefile_source != unknown; then -printf "%s\n" "#define _LARGEFILE_SOURCE 1" >>confdefs.h +printf "%s\n" "#define HAVE_FSEEKO 1" >>confdefs.h fi @@ -9498,34 +9118,31 @@ if test ${enable_largefile+y} then : enableval=$enable_largefile; fi -if test "$enable_largefile,$enable_year2038" != no,no -then : - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for $CC option to enable large file support" >&5 -printf %s "checking for $CC option to enable large file support... " >&6; } -if test ${ac_cv_sys_largefile_opts+y} + +if test "$enable_largefile" != no; then + + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for special C compiler options needed for large files" >&5 +printf %s "checking for special C compiler options needed for large files... " >&6; } +if test ${ac_cv_sys_largefile_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_save_CC="$CC" - ac_opt_found=no - for ac_opt in "none needed" "-D_FILE_OFFSET_BITS=64" "-D_LARGE_FILES=1" "-n32"; do - if test x"$ac_opt" != x"none needed" -then : - CC="$ac_save_CC $ac_opt" -fi - cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + ac_cv_sys_largefile_CC=no + if test "$GCC" != yes; then + ac_save_CC=$CC + while :; do + # IRIX 6.2 and later do not support large files by default, + # so use the C compiler's -n32 option if that helps. + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include -#ifndef FTYPE -# define FTYPE off_t -#endif - /* Check that FTYPE can represent 2**63 - 1 correctly. - We can't simply define LARGE_FTYPE to be 9223372036854775807, + /* Check that off_t can represent 2**63 - 1 correctly. + We can't simply define LARGE_OFF_T to be 9223372036854775807, since some C++ compilers masquerading as C compilers incorrectly reject 9223372036854775807. */ -#define LARGE_FTYPE (((FTYPE) 1 << 31 << 31) - 1 + ((FTYPE) 1 << 31 << 31)) - int FTYPE_is_large[(LARGE_FTYPE % 2147483629 == 721 - && LARGE_FTYPE % 2147483647 == 1) +#define LARGE_OFF_T (((off_t) 1 << 31 << 31) - 1 + ((off_t) 1 << 31 << 31)) + int off_t_is_large[(LARGE_OFF_T % 2147483629 == 721 + && LARGE_OFF_T % 2147483647 == 1) ? 1 : -1]; int main (void) @@ -9535,88 +9152,142 @@ main (void) return 0; } _ACEOF -if ac_fn_c_try_compile "$LINENO" -then : - if test x"$ac_opt" = x"none needed" -then : - # GNU/Linux s390x and alpha need _FILE_OFFSET_BITS=64 for wide ino_t. - CC="$CC -DFTYPE=ino_t" if ac_fn_c_try_compile "$LINENO" then : - -else case e in #( - e) CC="$CC -D_FILE_OFFSET_BITS=64" - if ac_fn_c_try_compile "$LINENO" -then : - ac_opt='-D_FILE_OFFSET_BITS=64' + break fi -rm -f core conftest.err conftest.$ac_objext conftest.beam ;; -esac +rm -f core conftest.err conftest.$ac_objext conftest.beam + CC="$CC -n32" + if ac_fn_c_try_compile "$LINENO" +then : + ac_cv_sys_largefile_CC=' -n32'; break fi rm -f core conftest.err conftest.$ac_objext conftest.beam + break + done + CC=$ac_save_CC + rm -f conftest.$ac_ext + fi fi - ac_cv_sys_largefile_opts=$ac_opt - ac_opt_found=yes +{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_sys_largefile_CC" >&5 +printf "%s\n" "$ac_cv_sys_largefile_CC" >&6; } + if test "$ac_cv_sys_largefile_CC" != no; then + CC=$CC$ac_cv_sys_largefile_CC + fi + + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for _FILE_OFFSET_BITS value needed for large files" >&5 +printf %s "checking for _FILE_OFFSET_BITS value needed for large files... " >&6; } +if test ${ac_cv_sys_file_offset_bits+y} +then : + printf %s "(cached) " >&6 +else $as_nop + while :; do + cat confdefs.h - <<_ACEOF >conftest.$ac_ext +/* end confdefs.h. */ +#include + /* Check that off_t can represent 2**63 - 1 correctly. + We can't simply define LARGE_OFF_T to be 9223372036854775807, + since some C++ compilers masquerading as C compilers + incorrectly reject 9223372036854775807. */ +#define LARGE_OFF_T (((off_t) 1 << 31 << 31) - 1 + ((off_t) 1 << 31 << 31)) + int off_t_is_large[(LARGE_OFF_T % 2147483629 == 721 + && LARGE_OFF_T % 2147483647 == 1) + ? 1 : -1]; +int +main (void) +{ + + ; + return 0; +} +_ACEOF +if ac_fn_c_try_compile "$LINENO" +then : + ac_cv_sys_file_offset_bits=no; break fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext - test $ac_opt_found = no || break - done - CC="$ac_save_CC" + cat confdefs.h - <<_ACEOF >conftest.$ac_ext +/* end confdefs.h. */ +#define _FILE_OFFSET_BITS 64 +#include + /* Check that off_t can represent 2**63 - 1 correctly. + We can't simply define LARGE_OFF_T to be 9223372036854775807, + since some C++ compilers masquerading as C compilers + incorrectly reject 9223372036854775807. */ +#define LARGE_OFF_T (((off_t) 1 << 31 << 31) - 1 + ((off_t) 1 << 31 << 31)) + int off_t_is_large[(LARGE_OFF_T % 2147483629 == 721 + && LARGE_OFF_T % 2147483647 == 1) + ? 1 : -1]; +int +main (void) +{ - test $ac_opt_found = yes || ac_cv_sys_largefile_opts="support not detected" ;; -esac + ; + return 0; +} +_ACEOF +if ac_fn_c_try_compile "$LINENO" +then : + ac_cv_sys_file_offset_bits=64; break fi -{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_sys_largefile_opts" >&5 -printf "%s\n" "$ac_cv_sys_largefile_opts" >&6; } - -ac_have_largefile=yes -case $ac_cv_sys_largefile_opts in #( - "none needed") : - ;; #( - "supported through gnulib") : - ;; #( - "support not detected") : - ac_have_largefile=no ;; #( - "-D_FILE_OFFSET_BITS=64") : - -printf "%s\n" "#define _FILE_OFFSET_BITS 64" >>confdefs.h - ;; #( - "-D_LARGE_FILES=1") : - -printf "%s\n" "#define _LARGE_FILES 1" >>confdefs.h - ;; #( - "-n32") : - CC="$CC -n32" ;; #( - *) : - as_fn_error $? "internal error: bad value for \$ac_cv_sys_largefile_opts" "$LINENO" 5 ;; +rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext + ac_cv_sys_file_offset_bits=unknown + break +done +fi +{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_sys_file_offset_bits" >&5 +printf "%s\n" "$ac_cv_sys_file_offset_bits" >&6; } +case $ac_cv_sys_file_offset_bits in #( + no | unknown) ;; + *) +printf "%s\n" "#define _FILE_OFFSET_BITS $ac_cv_sys_file_offset_bits" >>confdefs.h +;; esac - -if test "$enable_year2038" != no -then : - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for $CC option for timestamps after 2038" >&5 -printf %s "checking for $CC option for timestamps after 2038... " >&6; } -if test ${ac_cv_sys_year2038_opts+y} +rm -rf conftest* + if test $ac_cv_sys_file_offset_bits = unknown; then + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for _LARGE_FILES value needed for large files" >&5 +printf %s "checking for _LARGE_FILES value needed for large files... " >&6; } +if test ${ac_cv_sys_large_files+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_save_CPPFLAGS="$CPPFLAGS" - ac_opt_found=no - for ac_opt in "none needed" "-D_TIME_BITS=64" "-D__MINGW_USE_VC2005_COMPAT" "-U_USE_32_BIT_TIME_T -D__MINGW_USE_VC2005_COMPAT"; do - if test x"$ac_opt" != x"none needed" +else $as_nop + while :; do + cat confdefs.h - <<_ACEOF >conftest.$ac_ext +/* end confdefs.h. */ +#include + /* Check that off_t can represent 2**63 - 1 correctly. + We can't simply define LARGE_OFF_T to be 9223372036854775807, + since some C++ compilers masquerading as C compilers + incorrectly reject 9223372036854775807. */ +#define LARGE_OFF_T (((off_t) 1 << 31 << 31) - 1 + ((off_t) 1 << 31 << 31)) + int off_t_is_large[(LARGE_OFF_T % 2147483629 == 721 + && LARGE_OFF_T % 2147483647 == 1) + ? 1 : -1]; +int +main (void) +{ + + ; + return 0; +} +_ACEOF +if ac_fn_c_try_compile "$LINENO" then : - CPPFLAGS="$ac_save_CPPFLAGS $ac_opt" + ac_cv_sys_large_files=no; break fi - cat confdefs.h - <<_ACEOF >conftest.$ac_ext +rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ - - #include - /* Check that time_t can represent 2**32 - 1 correctly. */ - #define LARGE_TIME_T \\ - ((time_t) (((time_t) 1 << 30) - 1 + 3 * ((time_t) 1 << 30))) - int verify_time_t_range[(LARGE_TIME_T / 65537 == 65535 - && LARGE_TIME_T % 65537 == 0) - ? 1 : -1]; - +#define _LARGE_FILES 1 +#include + /* Check that off_t can represent 2**63 - 1 correctly. + We can't simply define LARGE_OFF_T to be 9223372036854775807, + since some C++ compilers masquerading as C compilers + incorrectly reject 9223372036854775807. */ +#define LARGE_OFF_T (((off_t) 1 << 31 << 31) - 1 + ((off_t) 1 << 31 << 31)) + int off_t_is_large[(LARGE_OFF_T % 2147483629 == 721 + && LARGE_OFF_T % 2147483647 == 1) + ? 1 : -1]; int main (void) { @@ -9627,73 +9298,49 @@ main (void) _ACEOF if ac_fn_c_try_compile "$LINENO" then : - ac_cv_sys_year2038_opts="$ac_opt" - ac_opt_found=yes + ac_cv_sys_large_files=1; break fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext - test $ac_opt_found = no || break - done - CPPFLAGS="$ac_save_CPPFLAGS" - test $ac_opt_found = yes || ac_cv_sys_year2038_opts="support not detected" ;; -esac + ac_cv_sys_large_files=unknown + break +done fi -{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_sys_year2038_opts" >&5 -printf "%s\n" "$ac_cv_sys_year2038_opts" >&6; } - -ac_have_year2038=yes -case $ac_cv_sys_year2038_opts in #( - "none needed") : - ;; #( - "support not detected") : - ac_have_year2038=no ;; #( - "-D_TIME_BITS=64") : - -printf "%s\n" "#define _TIME_BITS 64" >>confdefs.h - ;; #( - "-D__MINGW_USE_VC2005_COMPAT") : - -printf "%s\n" "#define __MINGW_USE_VC2005_COMPAT 1" >>confdefs.h - ;; #( - "-U_USE_32_BIT_TIME_T"*) : - { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} -as_fn_error $? "the 'time_t' type is currently forced to be 32-bit. It -will stop working after mid-January 2038. Remove -_USE_32BIT_TIME_T from the compiler flags. -See 'config.log' for more details" "$LINENO" 5; } ;; #( - *) : - as_fn_error $? "internal error: bad value for \$ac_cv_sys_year2038_opts" "$LINENO" 5 ;; +{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_sys_large_files" >&5 +printf "%s\n" "$ac_cv_sys_large_files" >&6; } +case $ac_cv_sys_large_files in #( + no | unknown) ;; + *) +printf "%s\n" "#define _LARGE_FILES $ac_cv_sys_large_files" >>confdefs.h +;; esac - +rm -rf conftest* + fi fi -fi # The cast to long int works around a bug in the HP C Compiler # version HP92453-01 B.11.11.23709.GP, which incorrectly rejects -# declarations like 'int a3[[(sizeof (unsigned char)) >= 0]];'. +# declarations like `int a3[[(sizeof (unsigned char)) >= 0]];'. # This bug is HP SR number 8606223364. { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking size of void*" >&5 printf %s "checking size of void*... " >&6; } if test ${ac_cv_sizeof_voidp+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if ac_fn_c_compute_int "$LINENO" "(long int) (sizeof (void*))" "ac_cv_sizeof_voidp" "$ac_includes_default" +else $as_nop + if ac_fn_c_compute_int "$LINENO" "(long int) (sizeof (void*))" "ac_cv_sizeof_voidp" "$ac_includes_default" then : -else case e in #( - e) if test "$ac_cv_type_voidp" = yes; then - { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} +else $as_nop + if test "$ac_cv_type_voidp" = yes; then + { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +printf "%s\n" "$as_me: error: in \`$ac_pwd':" >&2;} as_fn_error 77 "cannot compute sizeof (void*) -See 'config.log' for more details" "$LINENO" 5; } +See \`config.log' for more details" "$LINENO" 5; } else ac_cv_sizeof_voidp=0 - fi ;; -esac + fi fi - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_sizeof_voidp" >&5 printf "%s\n" "$ac_cv_sizeof_voidp" >&6; } @@ -9705,30 +9352,28 @@ printf "%s\n" "#define SIZEOF_VOIDP $ac_ # The cast to long int works around a bug in the HP C Compiler # version HP92453-01 B.11.11.23709.GP, which incorrectly rejects -# declarations like 'int a3[[(sizeof (unsigned char)) >= 0]];'. +# declarations like `int a3[[(sizeof (unsigned char)) >= 0]];'. # This bug is HP SR number 8606223364. { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking size of off_t" >&5 printf %s "checking size of off_t... " >&6; } if test ${ac_cv_sizeof_off_t+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if ac_fn_c_compute_int "$LINENO" "(long int) (sizeof (off_t))" "ac_cv_sizeof_off_t" "$ac_includes_default" +else $as_nop + if ac_fn_c_compute_int "$LINENO" "(long int) (sizeof (off_t))" "ac_cv_sizeof_off_t" "$ac_includes_default" then : -else case e in #( - e) if test "$ac_cv_type_off_t" = yes; then - { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} +else $as_nop + if test "$ac_cv_type_off_t" = yes; then + { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +printf "%s\n" "$as_me: error: in \`$ac_pwd':" >&2;} as_fn_error 77 "cannot compute sizeof (off_t) -See 'config.log' for more details" "$LINENO" 5; } +See \`config.log' for more details" "$LINENO" 5; } else ac_cv_sizeof_off_t=0 - fi ;; -esac + fi fi - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_sizeof_off_t" >&5 printf "%s\n" "$ac_cv_sizeof_off_t" >&6; } @@ -9762,21 +9407,15 @@ printf %s "checking for library containi if test ${ac_cv_search_setusercontext+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_func_search_save_LIBS=$LIBS +else $as_nop + ac_func_search_save_LIBS=$LIBS cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ /* Override any GCC internal prototype to avoid an error. Use char because int might match the return type of a GCC - builtin and then its argument prototype would still apply. - The 'extern "C"' is for builds by C++ compilers; - although this is not generally supported in C code supporting it here - has little cost and some practical benefit (sr 110532). */ -#ifdef __cplusplus -extern "C" -#endif -char setusercontext (void); + builtin and then its argument prototype would still apply. */ +char setusercontext (); int main (void) { @@ -9807,13 +9446,11 @@ done if test ${ac_cv_search_setusercontext+y} then : -else case e in #( - e) ac_cv_search_setusercontext=no ;; -esac +else $as_nop + ac_cv_search_setusercontext=no fi rm conftest.$ac_ext -LIBS=$ac_func_search_save_LIBS ;; -esac +LIBS=$ac_func_search_save_LIBS fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_setusercontext" >&5 printf "%s\n" "$ac_cv_search_setusercontext" >&6; } @@ -10099,8 +9736,8 @@ then : printf "%s\n" "#define HAVE_RECVMMSG 1" >>confdefs.h -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #ifdef HAVE_UNISTD_H @@ -10125,8 +9762,7 @@ printf "%s\n" "#define HAVE_RECVMMSG 1" fi rm -f core *.core core.conftest.* gmon.out bb.out conftest$ac_exeext \ - conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac + conftest.$ac_objext conftest.beam conftest.$ac_ext fi fi @@ -10142,8 +9778,8 @@ then : printf "%s\n" "#define HAVE_SENDMMSG 1" >>confdefs.h -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #ifdef HAVE_UNISTD_H @@ -10168,8 +9804,7 @@ printf "%s\n" "#define HAVE_SENDMMSG 1" fi rm -f core *.core core.conftest.* gmon.out bb.out conftest$ac_exeext \ - conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac + conftest.$ac_objext conftest.beam conftest.$ac_ext fi fi @@ -10367,12 +10002,11 @@ printf "%s\n" "yes" >&6; } printf "%s\n" "#define CPU_OR_THREE_ARGS 1" >>confdefs.h -else case e in #( - e) +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 printf "%s\n" "no" >&6; } - ;; -esac + fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext @@ -10421,10 +10055,9 @@ printf "%s\n" "yes" >&6; } printf "%s\n" "#define HAVE_SCHED_SETAFFINITY 1" >>confdefs.h -else case e in #( - e) { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 -printf "%s\n" "no" >&6; } ;; -esac +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 +printf "%s\n" "no" >&6; } fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext @@ -10436,14 +10069,13 @@ if test "x$ac_cv_func_basename" = xyes then : printf "%s\n" "#define HAVE_BASENAME 1" >>confdefs.h -else case e in #( - e) case " $LIBOBJS " in +else $as_nop + case " $LIBOBJS " in *" basename.$ac_objext "* ) ;; *) LIBOBJS="$LIBOBJS basename.$ac_objext" ;; esac - ;; -esac + fi ac_fn_c_check_func "$LINENO" "inet_aton" "ac_cv_func_inet_aton" @@ -10451,14 +10083,13 @@ if test "x$ac_cv_func_inet_aton" = xyes then : printf "%s\n" "#define HAVE_INET_ATON 1" >>confdefs.h -else case e in #( - e) case " $LIBOBJS " in +else $as_nop + case " $LIBOBJS " in *" inet_aton.$ac_objext "* ) ;; *) LIBOBJS="$LIBOBJS inet_aton.$ac_objext" ;; esac - ;; -esac + fi ac_fn_c_check_func "$LINENO" "inet_pton" "ac_cv_func_inet_pton" @@ -10466,14 +10097,13 @@ if test "x$ac_cv_func_inet_pton" = xyes then : printf "%s\n" "#define HAVE_INET_PTON 1" >>confdefs.h -else case e in #( - e) case " $LIBOBJS " in +else $as_nop + case " $LIBOBJS " in *" inet_pton.$ac_objext "* ) ;; *) LIBOBJS="$LIBOBJS inet_pton.$ac_objext" ;; esac - ;; -esac + fi ac_fn_c_check_func "$LINENO" "inet_ntop" "ac_cv_func_inet_ntop" @@ -10481,14 +10111,13 @@ if test "x$ac_cv_func_inet_ntop" = xyes then : printf "%s\n" "#define HAVE_INET_NTOP 1" >>confdefs.h -else case e in #( - e) case " $LIBOBJS " in +else $as_nop + case " $LIBOBJS " in *" inet_ntop.$ac_objext "* ) ;; *) LIBOBJS="$LIBOBJS inet_ntop.$ac_objext" ;; esac - ;; -esac + fi ac_fn_c_check_func "$LINENO" "snprintf" "ac_cv_func_snprintf" @@ -10496,14 +10125,13 @@ if test "x$ac_cv_func_snprintf" = xyes then : printf "%s\n" "#define HAVE_SNPRINTF 1" >>confdefs.h -else case e in #( - e) case " $LIBOBJS " in +else $as_nop + case " $LIBOBJS " in *" snprintf.$ac_objext "* ) ;; *) LIBOBJS="$LIBOBJS snprintf.$ac_objext" ;; esac - ;; -esac + fi ac_fn_c_check_func "$LINENO" "strlcat" "ac_cv_func_strlcat" @@ -10511,14 +10139,13 @@ if test "x$ac_cv_func_strlcat" = xyes then : printf "%s\n" "#define HAVE_STRLCAT 1" >>confdefs.h -else case e in #( - e) case " $LIBOBJS " in +else $as_nop + case " $LIBOBJS " in *" strlcat.$ac_objext "* ) ;; *) LIBOBJS="$LIBOBJS strlcat.$ac_objext" ;; esac - ;; -esac + fi ac_fn_c_check_func "$LINENO" "strlcpy" "ac_cv_func_strlcpy" @@ -10526,14 +10153,13 @@ if test "x$ac_cv_func_strlcpy" = xyes then : printf "%s\n" "#define HAVE_STRLCPY 1" >>confdefs.h -else case e in #( - e) case " $LIBOBJS " in +else $as_nop + case " $LIBOBJS " in *" strlcpy.$ac_objext "* ) ;; *) LIBOBJS="$LIBOBJS strlcpy.$ac_objext" ;; esac - ;; -esac + fi ac_fn_c_check_func "$LINENO" "strptime" "ac_cv_func_strptime" @@ -10541,14 +10167,13 @@ if test "x$ac_cv_func_strptime" = xyes then : printf "%s\n" "#define HAVE_STRPTIME 1" >>confdefs.h -else case e in #( - e) case " $LIBOBJS " in +else $as_nop + case " $LIBOBJS " in *" strptime.$ac_objext "* ) ;; *) LIBOBJS="$LIBOBJS strptime.$ac_objext" ;; esac - ;; -esac + fi ac_fn_c_check_func "$LINENO" "pselect" "ac_cv_func_pselect" @@ -10556,14 +10181,13 @@ if test "x$ac_cv_func_pselect" = xyes then : printf "%s\n" "#define HAVE_PSELECT 1" >>confdefs.h -else case e in #( - e) case " $LIBOBJS " in +else $as_nop + case " $LIBOBJS " in *" pselect.$ac_objext "* ) ;; *) LIBOBJS="$LIBOBJS pselect.$ac_objext" ;; esac - ;; -esac + fi ac_fn_c_check_func "$LINENO" "memmove" "ac_cv_func_memmove" @@ -10571,14 +10195,13 @@ if test "x$ac_cv_func_memmove" = xyes then : printf "%s\n" "#define HAVE_MEMMOVE 1" >>confdefs.h -else case e in #( - e) case " $LIBOBJS " in +else $as_nop + case " $LIBOBJS " in *" memmove.$ac_objext "* ) ;; *) LIBOBJS="$LIBOBJS memmove.$ac_objext" ;; esac - ;; -esac + fi ac_fn_c_check_func "$LINENO" "setproctitle" "ac_cv_func_setproctitle" @@ -10586,14 +10209,13 @@ if test "x$ac_cv_func_setproctitle" = xy then : printf "%s\n" "#define HAVE_SETPROCTITLE 1" >>confdefs.h -else case e in #( - e) case " $LIBOBJS " in +else $as_nop + case " $LIBOBJS " in *" setproctitle.$ac_objext "* ) ;; *) LIBOBJS="$LIBOBJS setproctitle.$ac_objext" ;; esac - ;; -esac + fi ac_fn_c_check_func "$LINENO" "explicit_bzero" "ac_cv_func_explicit_bzero" @@ -10601,14 +10223,13 @@ if test "x$ac_cv_func_explicit_bzero" = then : printf "%s\n" "#define HAVE_EXPLICIT_BZERO 1" >>confdefs.h -else case e in #( - e) case " $LIBOBJS " in +else $as_nop + case " $LIBOBJS " in *" explicit_bzero.$ac_objext "* ) ;; *) LIBOBJS="$LIBOBJS explicit_bzero.$ac_objext" ;; esac - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for reallocarray" >&5 @@ -10645,26 +10266,24 @@ $ac_includes_default if test "x$ac_cv_have_decl_reallocarray" = xyes then : ac_have_decl=1 -else case e in #( - e) ac_have_decl=0 ;; -esac +else $as_nop + ac_have_decl=0 fi printf "%s\n" "#define HAVE_DECL_REALLOCARRAY $ac_have_decl" >>confdefs.h if test $ac_have_decl = 1 then : -else case e in #( - e) +else $as_nop + printf "%s\n" "#define REALLOCARRAY_NEEDS_DEFINES 1" >>confdefs.h - ;; -esac + fi -else case e in #( - e) +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 printf "%s\n" "no" >&6; } case " $LIBOBJS " in @@ -10673,8 +10292,7 @@ printf "%s\n" "no" >&6; } ;; esac - ;; -esac + fi rm -f core conftest.err conftest.$ac_objext conftest.beam \ conftest$ac_exeext conftest.$ac_ext @@ -10701,10 +10319,9 @@ _ACEOF if ac_fn_c_try_link "$LINENO" then : found_b64_ntop=yes -else case e in #( - e) found_b64_ntop=no - ;; -esac +else $as_nop + found_b64_ntop=no + fi rm -f core conftest.err conftest.$ac_objext conftest.beam \ conftest$ac_exeext conftest.$ac_ext @@ -10729,10 +10346,9 @@ _ACEOF if ac_fn_c_try_link "$LINENO" then : found_b64_ntop=yes -else case e in #( - e) found_b64_ntop=no - ;; -esac +else $as_nop + found_b64_ntop=no + fi rm -f core conftest.err conftest.$ac_objext conftest.beam \ conftest$ac_exeext conftest.$ac_ext @@ -10773,16 +10389,15 @@ cat confdefs.h - <<_ACEOF >conftest.$ac_ _ACEOF if (eval "$ac_cpp conftest.$ac_ext") 2>&5 | - $EGREP_TRADITIONAL "[^a-zA-Z_]*pselect[^a-zA-Z_]" >/dev/null 2>&1 + $EGREP "[^a-zA-Z_]*pselect[^a-zA-Z_]" >/dev/null 2>&1 then : printf "%s\n" "#define HAVE_PSELECT_PROTO 1" >>confdefs.h { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: yes" >&5 printf "%s\n" "yes" >&6; } -else case e in #( - e) { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 -printf "%s\n" "no" >&6; } ;; -esac +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 +printf "%s\n" "no" >&6; } fi rm -rf conftest* @@ -10795,16 +10410,15 @@ cat confdefs.h - <<_ACEOF >conftest.$ac_ _ACEOF if (eval "$ac_cpp conftest.$ac_ext") 2>&5 | - $EGREP_TRADITIONAL "[^a-zA-Z_]*ctime_r[^a-zA-Z_]" >/dev/null 2>&1 + $EGREP "[^a-zA-Z_]*ctime_r[^a-zA-Z_]" >/dev/null 2>&1 then : printf "%s\n" "#define HAVE_CTIME_R_PROTO 1" >>confdefs.h { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: yes" >&5 printf "%s\n" "yes" >&6; } -else case e in #( - e) { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 -printf "%s\n" "no" >&6; } ;; -esac +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 +printf "%s\n" "no" >&6; } fi rm -rf conftest* @@ -10902,6 +10516,18 @@ fi printf "%s\n" "#define TCP_TIMEOUT $tcp_timeout" >>confdefs.h +max_cname_chain=18 + +# Check whether --with-max_cname_chain was given. +if test ${with_max_cname_chain+y} +then : + withval=$with_max_cname_chain; max_cname_chain=$withval +fi + + +printf "%s\n" "#define MAX_CNAME_CHAIN $max_cname_chain" >>confdefs.h + + # Check whether --enable-root-server was given. if test ${enable_root_server+y} then : @@ -10925,6 +10551,22 @@ printf "%s\n" "#define INET6 /**/" >>con ;; esac +# Check whether --enable-multiple-catalog-zones was given. +if test ${enable_multiple_catalog_zones+y} +then : + enableval=$enable_multiple_catalog_zones; +fi + +case "$enable_multiple_catalog_zones" in + yes) + +printf "%s\n" "#define MULTIPLE_CATALOG_CONSUMER_ZONES /**/" >>confdefs.h + + ;; + no|*) + ;; +esac + # Check whether --enable-bind8-stats was given. if test ${enable_bind8_stats+y} then : @@ -10977,8 +10619,8 @@ cache=`echo W | $SED 'y%.=/+-%___p_%'` if eval test \${cv_prog_cc_flag_$cache+y} then : printf %s "(cached) " >&6 -else case e in #( - e) +else $as_nop + echo 'void f(void){}' >conftest.c if test -z "`$CC -W -c conftest.c 2>&1`"; then eval "cv_prog_cc_flag_$cache=yes" @@ -10986,8 +10628,7 @@ else eval "cv_prog_cc_flag_$cache=no" fi rm -f conftest* - ;; -esac + fi if eval "test \"`echo '$cv_prog_cc_flag_'$cache`\" = yes"; then @@ -11010,8 +10651,8 @@ cache=`echo Wall | $SED 'y%.=/+-%___p_%' if eval test \${cv_prog_cc_flag_$cache+y} then : printf %s "(cached) " >&6 -else case e in #( - e) +else $as_nop + echo 'void f(void){}' >conftest.c if test -z "`$CC -Wall -c conftest.c 2>&1`"; then eval "cv_prog_cc_flag_$cache=yes" @@ -11019,8 +10660,7 @@ else eval "cv_prog_cc_flag_$cache=no" fi rm -f conftest* - ;; -esac + fi if eval "test \"`echo '$cv_prog_cc_flag_'$cache`\" = yes"; then @@ -11043,8 +10683,8 @@ cache=`echo Wextra | $SED 'y%.=/+-%___p_ if eval test \${cv_prog_cc_flag_$cache+y} then : printf %s "(cached) " >&6 -else case e in #( - e) +else $as_nop + echo 'void f(void){}' >conftest.c if test -z "`$CC -Wextra -c conftest.c 2>&1`"; then eval "cv_prog_cc_flag_$cache=yes" @@ -11052,8 +10692,7 @@ else eval "cv_prog_cc_flag_$cache=no" fi rm -f conftest* - ;; -esac + fi if eval "test \"`echo '$cv_prog_cc_flag_'$cache`\" = yes"; then @@ -11076,8 +10715,8 @@ cache=`echo Wdeclaration-after-statement if eval test \${cv_prog_cc_flag_$cache+y} then : printf %s "(cached) " >&6 -else case e in #( - e) +else $as_nop + echo 'void f(void){}' >conftest.c if test -z "`$CC -Wdeclaration-after-statement -c conftest.c 2>&1`"; then eval "cv_prog_cc_flag_$cache=yes" @@ -11085,8 +10724,7 @@ else eval "cv_prog_cc_flag_$cache=no" fi rm -f conftest* - ;; -esac + fi if eval "test \"`echo '$cv_prog_cc_flag_'$cache`\" = yes"; then @@ -11180,11 +10818,10 @@ if test ${with_ssl+y} then : withval=$with_ssl; -else case e in #( - e) +else $as_nop + withval="yes" - ;; -esac + fi if test x_$withval != x_no; then @@ -11260,14 +10897,8 @@ cat confdefs.h - <<_ACEOF >conftest.$ac_ /* Override any GCC internal prototype to avoid an error. Use char because int might match the return type of a GCC - builtin and then its argument prototype would still apply. - The 'extern "C"' is for builds by C++ compilers; - although this is not generally supported in C code supporting it here - has little cost and some practical benefit (sr 110532). */ -#ifdef __cplusplus -extern "C" -#endif -char SSL_CTX_new (void); + builtin and then its argument prototype would still apply. */ +char SSL_CTX_new (); int main (void) { @@ -11283,8 +10914,8 @@ then : printf "%s\n" "no" >&6; } LIBS="$BAKLIBS" -else case e in #( - e) +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: yes" >&5 printf "%s\n" "yes" >&6; } LIBS="$BAKLIBS" @@ -11293,21 +10924,15 @@ printf %s "checking for library containi if test ${ac_cv_search_dlopen+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_func_search_save_LIBS=$LIBS +else $as_nop + ac_func_search_save_LIBS=$LIBS cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ /* Override any GCC internal prototype to avoid an error. Use char because int might match the return type of a GCC - builtin and then its argument prototype would still apply. - The 'extern "C"' is for builds by C++ compilers; - although this is not generally supported in C code supporting it here - has little cost and some practical benefit (sr 110532). */ -#ifdef __cplusplus -extern "C" -#endif -char dlopen (void); + builtin and then its argument prototype would still apply. */ +char dlopen (); int main (void) { @@ -11338,13 +10963,11 @@ done if test ${ac_cv_search_dlopen+y} then : -else case e in #( - e) ac_cv_search_dlopen=no ;; -esac +else $as_nop + ac_cv_search_dlopen=no fi rm conftest.$ac_ext -LIBS=$ac_func_search_save_LIBS ;; -esac +LIBS=$ac_func_search_save_LIBS fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_dlopen" >&5 printf "%s\n" "$ac_cv_search_dlopen" >&6; } @@ -11355,8 +10978,7 @@ then : fi - ;; -esac + fi rm -f core conftest.err conftest.$ac_objext conftest.beam \ conftest$ac_exeext conftest.$ac_ext @@ -11383,8 +11005,8 @@ _ACEOF if ac_fn_c_try_link "$LINENO" then : -else case e in #( - e) +else $as_nop + BAKCFLAGS="$CFLAGS" CFLAGS="$CFLAGS -pthread" { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking if libcrypto needs -pthread" >&5 @@ -11394,14 +11016,8 @@ printf %s "checking if libcrypto needs - /* Override any GCC internal prototype to avoid an error. Use char because int might match the return type of a GCC - builtin and then its argument prototype would still apply. - The 'extern "C"' is for builds by C++ compilers; - although this is not generally supported in C code supporting it here - has little cost and some practical benefit (sr 110532). */ -#ifdef __cplusplus -extern "C" -#endif -char EVP_sha256 (void); + builtin and then its argument prototype would still apply. */ +char EVP_sha256 (); int main (void) { @@ -11416,18 +11032,16 @@ then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: yes" >&5 printf "%s\n" "yes" >&6; } -else case e in #( - e) +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 printf "%s\n" "no" >&6; } CFLAGS="$BAKCFLAGS" - ;; -esac + fi rm -f core conftest.err conftest.$ac_objext conftest.beam \ conftest$ac_exeext conftest.$ac_ext - ;; -esac + fi rm -f core conftest.err conftest.$ac_objext conftest.beam \ conftest$ac_exeext conftest.$ac_ext @@ -11439,22 +11053,16 @@ printf %s "checking for EVP_sha256 in -l if test ${ac_cv_lib_crypto_EVP_sha256+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_check_lib_save_LIBS=$LIBS +else $as_nop + ac_check_lib_save_LIBS=$LIBS LIBS="-lcrypto $LIBS" cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ /* Override any GCC internal prototype to avoid an error. Use char because int might match the return type of a GCC - builtin and then its argument prototype would still apply. - The 'extern "C"' is for builds by C++ compilers; - although this is not generally supported in C code supporting it here - has little cost and some practical benefit (sr 110532). */ -#ifdef __cplusplus -extern "C" -#endif -char EVP_sha256 (void); + builtin and then its argument prototype would still apply. */ +char EVP_sha256 (); int main (void) { @@ -11466,14 +11074,12 @@ _ACEOF if ac_fn_c_try_link "$LINENO" then : ac_cv_lib_crypto_EVP_sha256=yes -else case e in #( - e) ac_cv_lib_crypto_EVP_sha256=no ;; -esac +else $as_nop + ac_cv_lib_crypto_EVP_sha256=no fi rm -f core conftest.err conftest.$ac_objext conftest.beam \ conftest$ac_exeext conftest.$ac_ext -LIBS=$ac_check_lib_save_LIBS ;; -esac +LIBS=$ac_check_lib_save_LIBS fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_lib_crypto_EVP_sha256" >&5 printf "%s\n" "$ac_cv_lib_crypto_EVP_sha256" >&6; } @@ -11483,11 +11089,10 @@ then : LIBS="-lcrypto $LIBS" -else case e in #( - e) +else $as_nop + as_fn_error $? "OpenSSL found in $ssldir, but version 0.9.7 or higher is required" "$LINENO" 5 - ;; -esac + fi fi @@ -11624,8 +11229,8 @@ cache=`echo SHA1_Init | sed 'y%.=/+-%___ if eval test \${cv_cc_deprecated_$cache+y} then : printf %s "(cached) " >&6 -else case e in #( - e) +else $as_nop + echo ' #include ' >conftest.c @@ -11636,8 +11241,7 @@ else eval "cv_cc_deprecated_$cache=yes" fi rm -f conftest conftest.o conftest.c - ;; -esac + fi if eval "test \"`echo '$cv_cc_deprecated_'$cache`\" = yes"; then @@ -11683,9 +11287,8 @@ $ac_includes_default if test "x$ac_cv_have_decl_SSL_CTX_set_ecdh_auto" = xyes then : ac_have_decl=1 -else case e in #( - e) ac_have_decl=0 ;; -esac +else $as_nop + ac_have_decl=0 fi printf "%s\n" "#define HAVE_DECL_SSL_CTX_SET_ECDH_AUTO $ac_have_decl" >>confdefs.h ac_fn_check_decl "$LINENO" "SSL_CTX_set_tmp_ecdh" "ac_cv_have_decl_SSL_CTX_set_tmp_ecdh" " @@ -11715,9 +11318,8 @@ $ac_includes_default if test "x$ac_cv_have_decl_SSL_CTX_set_tmp_ecdh" = xyes then : ac_have_decl=1 -else case e in #( - e) ac_have_decl=0 ;; -esac +else $as_nop + ac_have_decl=0 fi printf "%s\n" "#define HAVE_DECL_SSL_CTX_SET_TMP_ECDH $ac_have_decl" >>confdefs.h @@ -11728,10 +11330,9 @@ then : printf "%s\n" "#define HAVE_TLS_1_3 1" >>confdefs.h -else case e in #( - e) { printf "%s\n" "$as_me:${as_lineno-$LINENO}: WARNING: No TLS 1.3, therefore XFR-over-TLS is disabled" >&5 -printf "%s\n" "$as_me: WARNING: No TLS 1.3, therefore XFR-over-TLS is disabled" >&2;} ;; -esac +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: WARNING: No TLS 1.3, therefore XFR-over-TLS is disabled" >&5 +printf "%s\n" "$as_me: WARNING: No TLS 1.3, therefore XFR-over-TLS is disabled" >&2;} fi BAKLIBS="$LIBS" @@ -11770,8 +11371,8 @@ cache=`echo ERR_load_SSL_strings | sed ' if eval test \${cv_cc_deprecated_$cache+y} then : printf %s "(cached) " >&6 -else case e in #( - e) +else $as_nop + echo ' #include ' >conftest.c @@ -11782,8 +11383,7 @@ else eval "cv_cc_deprecated_$cache=yes" fi rm -f conftest conftest.o conftest.c - ;; -esac + fi if eval "test \"`echo '$cv_cc_deprecated_'$cache`\" = yes"; then @@ -11872,8 +11472,8 @@ printf %s "checking for uintptr_t... " > if test ${ac_cv_type_uintptr_t+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ #include @@ -11903,16 +11503,14 @@ else case e in #( _ACEOF if (eval "$ac_cpp conftest.$ac_ext") 2>&5 | - $EGREP_TRADITIONAL "(^|[^a-zA-Z_0-9])uintptr_t[^a-zA-Z_0-9]" >/dev/null 2>&1 + $EGREP "(^|[^a-zA-Z_0-9])uintptr_t[^a-zA-Z_0-9]" >/dev/null 2>&1 then : ac_cv_type_uintptr_t=yes -else case e in #( - e) ac_cv_type_uintptr_t=no ;; -esac +else $as_nop + ac_cv_type_uintptr_t=no fi rm -rf conftest* - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_type_uintptr_t" >&5 printf "%s\n" "$ac_cv_type_uintptr_t" >&6; } @@ -11978,8 +11576,8 @@ cache=`echo Wno-address-of-packed-member if eval test \${cv_prog_cc_flag_$cache+y} then : printf %s "(cached) " >&6 -else case e in #( - e) +else $as_nop + echo 'void f(void){}' >conftest.c if test -z "`$CC $CPPFLAGS $CFLAGS -Wno-address-of-packed-member -c conftest.c 2>&1`"; then eval "cv_prog_cc_flag_$cache=yes" @@ -11987,8 +11585,7 @@ else eval "cv_prog_cc_flag_$cache=no" fi rm -f conftest conftest.o conftest.c - ;; -esac + fi if eval "test \"`echo '$cv_prog_cc_flag_'$cache`\" = yes"; then @@ -12025,21 +11622,15 @@ printf %s "checking for library containi if test ${ac_cv_search_xdp_program__open_file+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_func_search_save_LIBS=$LIBS +else $as_nop + ac_func_search_save_LIBS=$LIBS cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ /* Override any GCC internal prototype to avoid an error. Use char because int might match the return type of a GCC - builtin and then its argument prototype would still apply. - The 'extern "C"' is for builds by C++ compilers; - although this is not generally supported in C code supporting it here - has little cost and some practical benefit (sr 110532). */ -#ifdef __cplusplus -extern "C" -#endif -char xdp_program__open_file (void); + builtin and then its argument prototype would still apply. */ +char xdp_program__open_file (); int main (void) { @@ -12070,13 +11661,11 @@ done if test ${ac_cv_search_xdp_program__open_file+y} then : -else case e in #( - e) ac_cv_search_xdp_program__open_file=no ;; -esac +else $as_nop + ac_cv_search_xdp_program__open_file=no fi rm conftest.$ac_ext -LIBS=$ac_func_search_save_LIBS ;; -esac +LIBS=$ac_func_search_save_LIBS fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_xdp_program__open_file" >&5 printf "%s\n" "$ac_cv_search_xdp_program__open_file" >&6; } @@ -12085,9 +11674,8 @@ if test "$ac_res" != no then : test "$ac_res" = "none required" || LIBS="$ac_res $LIBS" -else case e in #( - e) as_fn_error $? "Cannot find libxdp, but is needed for xdp support." "$LINENO" 5 ;; -esac +else $as_nop + as_fn_error $? "Cannot find libxdp, but is needed for xdp support." "$LINENO" 5 fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for library containing bpf_map__fd" >&5 @@ -12095,21 +11683,15 @@ printf %s "checking for library containi if test ${ac_cv_search_bpf_map__fd+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_func_search_save_LIBS=$LIBS +else $as_nop + ac_func_search_save_LIBS=$LIBS cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ /* Override any GCC internal prototype to avoid an error. Use char because int might match the return type of a GCC - builtin and then its argument prototype would still apply. - The 'extern "C"' is for builds by C++ compilers; - although this is not generally supported in C code supporting it here - has little cost and some practical benefit (sr 110532). */ -#ifdef __cplusplus -extern "C" -#endif -char bpf_map__fd (void); + builtin and then its argument prototype would still apply. */ +char bpf_map__fd (); int main (void) { @@ -12140,13 +11722,11 @@ done if test ${ac_cv_search_bpf_map__fd+y} then : -else case e in #( - e) ac_cv_search_bpf_map__fd=no ;; -esac +else $as_nop + ac_cv_search_bpf_map__fd=no fi rm conftest.$ac_ext -LIBS=$ac_func_search_save_LIBS ;; -esac +LIBS=$ac_func_search_save_LIBS fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_bpf_map__fd" >&5 printf "%s\n" "$ac_cv_search_bpf_map__fd" >&6; } @@ -12155,9 +11735,8 @@ if test "$ac_res" != no then : test "$ac_res" = "none required" || LIBS="$ac_res $LIBS" -else case e in #( - e) as_fn_error $? "Cannot find libbpf, but is needed for xdp support." "$LINENO" 5 ;; -esac +else $as_nop + as_fn_error $? "Cannot find libbpf, but is needed for xdp support." "$LINENO" 5 fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for library containing cap_set_proc" >&5 @@ -12165,21 +11744,15 @@ printf %s "checking for library containi if test ${ac_cv_search_cap_set_proc+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_func_search_save_LIBS=$LIBS +else $as_nop + ac_func_search_save_LIBS=$LIBS cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ /* Override any GCC internal prototype to avoid an error. Use char because int might match the return type of a GCC - builtin and then its argument prototype would still apply. - The 'extern "C"' is for builds by C++ compilers; - although this is not generally supported in C code supporting it here - has little cost and some practical benefit (sr 110532). */ -#ifdef __cplusplus -extern "C" -#endif -char cap_set_proc (void); + builtin and then its argument prototype would still apply. */ +char cap_set_proc (); int main (void) { @@ -12210,13 +11783,11 @@ done if test ${ac_cv_search_cap_set_proc+y} then : -else case e in #( - e) ac_cv_search_cap_set_proc=no ;; -esac +else $as_nop + ac_cv_search_cap_set_proc=no fi rm conftest.$ac_ext -LIBS=$ac_func_search_save_LIBS ;; -esac +LIBS=$ac_func_search_save_LIBS fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_cap_set_proc" >&5 printf "%s\n" "$ac_cv_search_cap_set_proc" >&6; } @@ -12225,9 +11796,8 @@ if test "$ac_res" != no then : test "$ac_res" = "none required" || LIBS="$ac_res $LIBS" -else case e in #( - e) as_fn_error $? "Cannot find libcap, but is needed for xdp support." "$LINENO" 5 ;; -esac +else $as_nop + as_fn_error $? "Cannot find libcap, but is needed for xdp support." "$LINENO" 5 fi @@ -12242,8 +11812,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_CLANG+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$CLANG"; then +else $as_nop + if test -n "$CLANG"; then ac_cv_prog_CLANG="$CLANG" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -12265,8 +11835,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi CLANG=$ac_cv_prog_CLANG if test -n "$CLANG"; then @@ -12285,8 +11854,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_LLC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$LLC"; then +else $as_nop + if test -n "$LLC"; then ac_cv_prog_LLC="$LLC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -12308,8 +11877,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi LLC=$ac_cv_prog_LLC if test -n "$LLC"; then @@ -12343,9 +11911,8 @@ esac if test ${enable_dnstap+y} then : enableval=$enable_dnstap; opt_dnstap=$enableval -else case e in #( - e) opt_dnstap=yes ;; -esac +else $as_nop + opt_dnstap=yes fi @@ -12354,9 +11921,8 @@ fi if test ${with_dnstap_socket_path+y} then : withval=$with_dnstap_socket_path; opt_dnstap_socket_path=$withval -else case e in #( - e) opt_dnstap_socket_path="${localstatedir}/run/nsd-dnstap.sock" ;; -esac +else $as_nop + opt_dnstap_socket_path="${localstatedir}/run/nsd-dnstap.sock" fi @@ -12368,8 +11934,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_path_PROTOC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) case $PROTOC in +else $as_nop + case $PROTOC in [\\/]* | ?:[\\/]*) ac_cv_path_PROTOC="$PROTOC" # Let the user override the test with a path. ;; @@ -12394,7 +11960,6 @@ done IFS=$as_save_IFS ;; -esac ;; esac fi PROTOC=$ac_cv_path_PROTOC @@ -12417,8 +11982,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_path_PROTOC_C+y} then : printf %s "(cached) " >&6 -else case e in #( - e) case $PROTOC_C in +else $as_nop + case $PROTOC_C in [\\/]* | ?:[\\/]*) ac_cv_path_PROTOC_C="$PROTOC_C" # Let the user override the test with a path. ;; @@ -12443,7 +12008,6 @@ done IFS=$as_save_IFS ;; -esac ;; esac fi PROTOC_C=$ac_cv_path_PROTOC_C @@ -12471,8 +12035,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_path_PROTOC_GEN_C+y} then : printf %s "(cached) " >&6 -else case e in #( - e) case $PROTOC_GEN_C in +else $as_nop + case $PROTOC_GEN_C in [\\/]* | ?:[\\/]*) ac_cv_path_PROTOC_GEN_C="$PROTOC_GEN_C" # Let the user override the test with a path. ;; @@ -12497,7 +12061,6 @@ done IFS=$as_save_IFS ;; -esac ;; esac fi PROTOC_GEN_C=$ac_cv_path_PROTOC_GEN_C @@ -12547,8 +12110,8 @@ then : fi LDFLAGS="$LDFLAGS -L$withval/lib" -else case e in #( - e) +else $as_nop + # workaround for protobuf-c includes at old dir before protobuf-c-1.0.0 if test -f /usr/include/google/protobuf-c/protobuf-c.h; then CFLAGS="$CFLAGS -I/usr/include/google" @@ -12558,8 +12121,7 @@ else case e in #( LDFLAGS="$LDFLAGS -L/usr/local/lib" fi fi - ;; -esac + fi @@ -12577,21 +12139,15 @@ printf %s "checking for library containi if test ${ac_cv_search_fstrm_iothr_init+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_func_search_save_LIBS=$LIBS +else $as_nop + ac_func_search_save_LIBS=$LIBS cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ /* Override any GCC internal prototype to avoid an error. Use char because int might match the return type of a GCC - builtin and then its argument prototype would still apply. - The 'extern "C"' is for builds by C++ compilers; - although this is not generally supported in C code supporting it here - has little cost and some practical benefit (sr 110532). */ -#ifdef __cplusplus -extern "C" -#endif -char fstrm_iothr_init (void); + builtin and then its argument prototype would still apply. */ +char fstrm_iothr_init (); int main (void) { @@ -12622,13 +12178,11 @@ done if test ${ac_cv_search_fstrm_iothr_init+y} then : -else case e in #( - e) ac_cv_search_fstrm_iothr_init=no ;; -esac +else $as_nop + ac_cv_search_fstrm_iothr_init=no fi rm conftest.$ac_ext -LIBS=$ac_func_search_save_LIBS ;; -esac +LIBS=$ac_func_search_save_LIBS fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_fstrm_iothr_init" >&5 printf "%s\n" "$ac_cv_search_fstrm_iothr_init" >&6; } @@ -12637,9 +12191,8 @@ if test "$ac_res" != no then : test "$ac_res" = "none required" || LIBS="$ac_res $LIBS" -else case e in #( - e) as_fn_error $? "The fstrm library was not found. It is needed for dnstap, use --disable-dnstap, or install fstrm-devel" "$LINENO" 5 ;; -esac +else $as_nop + as_fn_error $? "The fstrm library was not found. It is needed for dnstap, use --disable-dnstap, or install fstrm-devel" "$LINENO" 5 fi @@ -12650,9 +12203,8 @@ if test "x$ac_cv_func_fstrm_tcp_writer_o then : printf "%s\n" "#define HAVE_FSTRM_TCP_WRITER_OPTIONS_INIT 1" >>confdefs.h -else case e in #( - e) as_fn_error $? "The fstrm library >= 0.4 was not found. It is needed for dnstap, use --disable-dnstap, or install fstrm-devel" "$LINENO" 5 ;; -esac +else $as_nop + as_fn_error $? "The fstrm library >= 0.4 was not found. It is needed for dnstap, use --disable-dnstap, or install fstrm-devel" "$LINENO" 5 fi done @@ -12661,21 +12213,15 @@ printf %s "checking for library containi if test ${ac_cv_search_protobuf_c_message_pack+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_func_search_save_LIBS=$LIBS +else $as_nop + ac_func_search_save_LIBS=$LIBS cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ /* Override any GCC internal prototype to avoid an error. Use char because int might match the return type of a GCC - builtin and then its argument prototype would still apply. - The 'extern "C"' is for builds by C++ compilers; - although this is not generally supported in C code supporting it here - has little cost and some practical benefit (sr 110532). */ -#ifdef __cplusplus -extern "C" -#endif -char protobuf_c_message_pack (void); + builtin and then its argument prototype would still apply. */ +char protobuf_c_message_pack (); int main (void) { @@ -12706,13 +12252,11 @@ done if test ${ac_cv_search_protobuf_c_message_pack+y} then : -else case e in #( - e) ac_cv_search_protobuf_c_message_pack=no ;; -esac +else $as_nop + ac_cv_search_protobuf_c_message_pack=no fi rm conftest.$ac_ext -LIBS=$ac_func_search_save_LIBS ;; -esac +LIBS=$ac_func_search_save_LIBS fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_protobuf_c_message_pack" >&5 printf "%s\n" "$ac_cv_search_protobuf_c_message_pack" >&6; } @@ -12721,9 +12265,8 @@ if test "$ac_res" != no then : test "$ac_res" = "none required" || LIBS="$ac_res $LIBS" -else case e in #( - e) as_fn_error $? "The protobuf-c library was not found. It is needed for dnstap, use --disable-dnstap, or install protobuf-c" "$LINENO" 5 ;; -esac +else $as_nop + as_fn_error $? "The protobuf-c library was not found. It is needed for dnstap, use --disable-dnstap, or install protobuf-c" "$LINENO" 5 fi @@ -12765,9 +12308,8 @@ printf "%s\n" "#define DNSTAP_SOCKET_PAT if test ${enable_systemd+y} then : enableval=$enable_systemd; -else case e in #( - e) enable_systemd=no ;; -esac +else $as_nop + enable_systemd=no fi have_systemd=no @@ -12787,8 +12329,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_path_PKG_CONFIG+y} then : printf %s "(cached) " >&6 -else case e in #( - e) case $PKG_CONFIG in +else $as_nop + case $PKG_CONFIG in [\\/]* | ?:[\\/]*) ac_cv_path_PKG_CONFIG="$PKG_CONFIG" # Let the user override the test with a path. ;; @@ -12813,7 +12355,6 @@ done IFS=$as_save_IFS ;; -esac ;; esac fi PKG_CONFIG=$ac_cv_path_PKG_CONFIG @@ -12836,8 +12377,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_path_ac_pt_PKG_CONFIG+y} then : printf %s "(cached) " >&6 -else case e in #( - e) case $ac_pt_PKG_CONFIG in +else $as_nop + case $ac_pt_PKG_CONFIG in [\\/]* | ?:[\\/]*) ac_cv_path_ac_pt_PKG_CONFIG="$ac_pt_PKG_CONFIG" # Let the user override the test with a path. ;; @@ -12862,7 +12403,6 @@ done IFS=$as_save_IFS ;; -esac ;; esac fi ac_pt_PKG_CONFIG=$ac_cv_path_ac_pt_PKG_CONFIG @@ -12903,9 +12443,6 @@ printf "%s\n" "no" >&6; } PKG_CONFIG="" fi fi -if test -z "$PKG_CONFIG"; then - as_fn_error $? "pkg-config not found" "$LINENO" 5 -fi if test "x$enable_systemd" != xno then : @@ -13095,9 +12632,8 @@ case "$enable_tcp_fastopen" in if test "x$ac_cv_have_decl_TCP_FASTOPEN" = xyes then : -else case e in #( - e) as_fn_error $? "TCP Fast Open is not available: please rerun without --enable-tcp-fastopen" "$LINENO" 5 ;; -esac +else $as_nop + as_fn_error $? "TCP Fast Open is not available: please rerun without --enable-tcp-fastopen" "$LINENO" 5 fi printf "%s\n" "#define USE_TCP_FASTOPEN 1" >>confdefs.h @@ -13175,8 +12711,8 @@ cat >confcache <<\_ACEOF # config.status only pays attention to the cache file if you give it # the --recheck option to rerun configure. # -# 'ac_cv_env_foo' variables (set or unset) will be overridden when -# loading this file, other *unset* 'ac_cv_foo' will be assigned the +# `ac_cv_env_foo' variables (set or unset) will be overridden when +# loading this file, other *unset* `ac_cv_foo' will be assigned the # following values. _ACEOF @@ -13206,14 +12742,14 @@ printf "%s\n" "$as_me: WARNING: cache va (set) 2>&1 | case $as_nl`(ac_space=' '; set) 2>&1` in #( *${as_nl}ac_space=\ *) - # 'set' does not quote correctly, so add quotes: double-quote + # `set' does not quote correctly, so add quotes: double-quote # substitution turns \\\\ into \\, and sed turns \\ into \. sed -n \ "s/'/'\\\\''/g; s/^\\([_$as_cr_alnum]*_cv_[_$as_cr_alnum]*\\)=\\(.*\\)/\\1='\\2'/p" ;; #( *) - # 'set' quotes correctly as required by POSIX, so do not add quotes. + # `set' quotes correctly as required by POSIX, so do not add quotes. sed -n "/^[_$as_cr_alnum]*_cv_[_$as_cr_alnum]*=/p" ;; esac | @@ -13274,12 +12810,6 @@ LIBOBJS=$ac_libobjs LTLIBOBJS=$ac_ltlibobjs -# Check whether --enable-year2038 was given. -if test ${enable_year2038+y} -then : - enableval=$enable_year2038; -fi - : "${CONFIG_STATUS=./config.status}" ac_write_fail=0 @@ -13309,6 +12839,7 @@ cat >>$CONFIG_STATUS <<\_ASEOF || as_wri # Be more Bourne compatible DUALCASE=1; export DUALCASE # for MKS sh +as_nop=: if test ${ZSH_VERSION+y} && (emulate sh) >/dev/null 2>&1 then : emulate sh @@ -13317,13 +12848,12 @@ then : # is contrary to our usage. Disable this feature. alias -g '${1+"$@"}'='"$@"' setopt NO_GLOB_SUBST -else case e in #( - e) case `(set -o) 2>/dev/null` in #( +else $as_nop + case `(set -o) 2>/dev/null` in #( *posix*) : set -o posix ;; #( *) : ;; -esac ;; esac fi @@ -13395,7 +12925,7 @@ IFS=$as_save_IFS ;; esac -# We did not find ourselves, most probably we were run as 'sh COMMAND' +# We did not find ourselves, most probably we were run as `sh COMMAND' # in which case we are not to be found in the path. if test "x$as_myself" = x; then as_myself=$0 @@ -13424,6 +12954,7 @@ as_fn_error () } # as_fn_error + # as_fn_set_status STATUS # ----------------------- # Set $? to STATUS, without forking. @@ -13463,12 +12994,11 @@ then : { eval $1+=\$2 }' -else case e in #( - e) as_fn_append () +else $as_nop + as_fn_append () { eval $1=\$$1\$2 - } ;; -esac + } fi # as_fn_append # as_fn_arith ARG... @@ -13482,12 +13012,11 @@ then : { as_val=$(( $* )) }' -else case e in #( - e) as_fn_arith () +else $as_nop + as_fn_arith () { as_val=`expr "$@" || test $? -eq 1` - } ;; -esac + } fi # as_fn_arith @@ -13570,9 +13099,9 @@ if (echo >conf$$.file) 2>/dev/null; then if ln -s conf$$.file conf$$ 2>/dev/null; then as_ln_s='ln -s' # ... but there are two gotchas: - # 1) On MSYS, both 'ln -s file dir' and 'ln file dir' fail. - # 2) DJGPP < 2.04 has no symlinks; 'ln -s' creates a wrapper executable. - # In both cases, we have to default to 'cp -pR'. + # 1) On MSYS, both `ln -s file dir' and `ln file dir' fail. + # 2) DJGPP < 2.04 has no symlinks; `ln -s' creates a wrapper executable. + # In both cases, we have to default to `cp -pR'. ln -s conf$$.file conf$$.dir 2>/dev/null && test ! -f conf$$.exe || as_ln_s='cp -pR' elif ln conf$$.file conf$$ 2>/dev/null; then @@ -13653,12 +13182,10 @@ as_test_x='test -x' as_executable_p=as_fn_executable_p # Sed expression to map a string onto a valid CPP name. -as_sed_cpp="y%*$as_cr_letters%P$as_cr_LETTERS%;s%[^_$as_cr_alnum]%_%g" -as_tr_cpp="eval sed '$as_sed_cpp'" # deprecated +as_tr_cpp="eval sed 'y%*$as_cr_letters%P$as_cr_LETTERS%;s%[^_$as_cr_alnum]%_%g'" # Sed expression to map a string onto a valid variable name. -as_sed_sh="y%*+%pp%;s%[^_$as_cr_alnum]%_%g" -as_tr_sh="eval sed '$as_sed_sh'" # deprecated +as_tr_sh="eval sed 'y%*+%pp%;s%[^_$as_cr_alnum]%_%g'" exec 6>&1 @@ -13673,8 +13200,8 @@ cat >>$CONFIG_STATUS <<\_ACEOF || ac_wri # report actual input values of CONFIG_FILES etc. instead of their # values after options handling. ac_log=" -This file was extended by NSD $as_me 4.14.2, which was -generated by GNU Autoconf 2.72. Invocation command line was +This file was extended by NSD $as_me 4.15.2, which was +generated by GNU Autoconf 2.71. Invocation command line was CONFIG_FILES = $CONFIG_FILES CONFIG_HEADERS = $CONFIG_HEADERS @@ -13705,7 +13232,7 @@ _ACEOF cat >>$CONFIG_STATUS <<\_ACEOF || ac_write_fail=1 ac_cs_usage="\ -'$as_me' instantiates files and other configuration actions +\`$as_me' instantiates files and other configuration actions from templates according to the current configuration. Unless the files and actions are specified as TAGs, all are instantiated by default. @@ -13737,11 +13264,11 @@ ac_cs_config_escaped=`printf "%s\n" "$ac cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1 ac_cs_config='$ac_cs_config_escaped' ac_cs_version="\\ -NSD config.status 4.14.2 -configured by $0, generated by GNU Autoconf 2.72, +NSD config.status 4.15.2 +configured by $0, generated by GNU Autoconf 2.71, with options \\"\$ac_cs_config\\" -Copyright (C) 2023 Free Software Foundation, Inc. +Copyright (C) 2021 Free Software Foundation, Inc. This config.status script is free software; the Free Software Foundation gives unlimited permission to copy, distribute and modify it." @@ -13802,8 +13329,8 @@ do ac_need_defaults=false;; --he | --h) # Conflict between --help and --header - as_fn_error $? "ambiguous option: '$1' -Try '$0 --help' for more information.";; + as_fn_error $? "ambiguous option: \`$1' +Try \`$0 --help' for more information.";; --help | --hel | -h ) printf "%s\n" "$ac_cs_usage"; exit ;; -q | -quiet | --quiet | --quie | --qui | --qu | --q \ @@ -13811,8 +13338,8 @@ Try '$0 --help' for more information.";; ac_cs_silent=: ;; # This is an error. - -*) as_fn_error $? "unrecognized option: '$1' -Try '$0 --help' for more information." ;; + -*) as_fn_error $? "unrecognized option: \`$1' +Try \`$0 --help' for more information." ;; *) as_fn_append ac_config_targets " $1" ac_need_defaults=false ;; @@ -13864,7 +13391,7 @@ do "Makefile") CONFIG_FILES="$CONFIG_FILES Makefile" ;; "$dnstap_config") CONFIG_FILES="$CONFIG_FILES $dnstap_config" ;; - *) as_fn_error $? "invalid argument: '$ac_config_target'" "$LINENO" 5;; + *) as_fn_error $? "invalid argument: \`$ac_config_target'" "$LINENO" 5;; esac done @@ -13883,7 +13410,7 @@ fi # creating and moving files from /tmp can sometimes cause problems. # Hook for its removal unless debugging. # Note that there is a small window in which the directory will not be cleaned: -# after its creation but before its name has been assigned to '$tmp'. +# after its creation but before its name has been assigned to `$tmp'. $debug || { tmp= ac_tmp= @@ -13907,7 +13434,7 @@ ac_tmp=$tmp # Set up the scripts for CONFIG_FILES section. # No need to generate them if there are no CONFIG_FILES. -# This happens for instance with './config.status config.h'. +# This happens for instance with `./config.status config.h'. if test -n "$CONFIG_FILES"; then @@ -14065,13 +13592,13 @@ fi # test -n "$CONFIG_FILES" # Set up the scripts for CONFIG_HEADERS section. # No need to generate them if there are no CONFIG_HEADERS. -# This happens for instance with './config.status Makefile'. +# This happens for instance with `./config.status Makefile'. if test -n "$CONFIG_HEADERS"; then cat >"$ac_tmp/defines.awk" <<\_ACAWK || BEGIN { _ACEOF -# Transform confdefs.h into an awk script 'defines.awk', embedded as +# Transform confdefs.h into an awk script `defines.awk', embedded as # here-document in config.status, that substitutes the proper values into # config.h.in to produce config.h. @@ -14181,7 +13708,7 @@ do esac case $ac_mode$ac_tag in :[FHL]*:*);; - :L* | :C*:*) as_fn_error $? "invalid tag '$ac_tag'" "$LINENO" 5;; + :L* | :C*:*) as_fn_error $? "invalid tag \`$ac_tag'" "$LINENO" 5;; :[FH]-) ac_tag=-:-;; :[FH]*) ac_tag=$ac_tag:$ac_tag.in;; esac @@ -14203,19 +13730,19 @@ do -) ac_f="$ac_tmp/stdin";; *) # Look for the file first in the build tree, then in the source tree # (if the path is not absolute). The absolute path cannot be DOS-style, - # because $ac_f cannot contain ':'. + # because $ac_f cannot contain `:'. test -f "$ac_f" || case $ac_f in [\\/$]*) false;; *) test -f "$srcdir/$ac_f" && ac_f="$srcdir/$ac_f";; esac || - as_fn_error 1 "cannot find input file: '$ac_f'" "$LINENO" 5;; + as_fn_error 1 "cannot find input file: \`$ac_f'" "$LINENO" 5;; esac case $ac_f in *\'*) ac_f=`printf "%s\n" "$ac_f" | sed "s/'/'\\\\\\\\''/g"`;; esac as_fn_append ac_file_inputs " '$ac_f'" done - # Let's still pretend it is 'configure' which instantiates (i.e., don't + # Let's still pretend it is `configure' which instantiates (i.e., don't # use $as_me), people would be surprised to read: # /* config.h. Generated by config.status. */ configure_input='Generated from '` @@ -14343,7 +13870,7 @@ cat >>$CONFIG_STATUS <<_ACEOF || ac_writ esac _ACEOF -# Neutralize VPATH when '$srcdir' = '.'. +# Neutralize VPATH when `$srcdir' = `.'. # Shell code in configure.ac might set extrasub. # FIXME: do we really want to maintain this feature? cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1 @@ -14373,9 +13900,9 @@ test -z "$ac_datarootdir_hack$ac_dataroo { ac_out=`sed -n '/\${datarootdir}/p' "$ac_tmp/out"`; test -n "$ac_out"; } && { ac_out=`sed -n '/^[ ]*datarootdir[ ]*:*=/p' \ "$ac_tmp/out"`; test -z "$ac_out"; } && - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: WARNING: $ac_file contains a reference to the variable 'datarootdir' + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: WARNING: $ac_file contains a reference to the variable \`datarootdir' which seems to be undefined. Please make sure it is defined" >&5 -printf "%s\n" "$as_me: WARNING: $ac_file contains a reference to the variable 'datarootdir' +printf "%s\n" "$as_me: WARNING: $ac_file contains a reference to the variable \`datarootdir' which seems to be undefined. Please make sure it is defined" >&2;} rm -f "$ac_tmp/stdin" Index: usr.sbin/nsd/configure.ac =================================================================== RCS file: /cvs/src/usr.sbin/nsd/configure.ac,v diff -u -p -r1.63 configure.ac --- usr.sbin/nsd/configure.ac 21 Mar 2026 21:36:36 -0000 1.63 +++ usr.sbin/nsd/configure.ac 21 Sep 2026 16:28:41 -0000 @@ -7,7 +7,7 @@ sinclude(dnstap/dnstap.m4) # autoconf-2.70 is needed for @runstatedir@ AC_PREREQ([2.70]) -AC_INIT([NSD],[4.14.2],[https://github.com/NLnetLabs/nsd/issues or nsd-bugs@nlnetlabs.nl]) +AC_INIT([NSD],[4.15.2],[https://github.com/NLnetLabs/nsd/issues or nsd-bugs@nlnetlabs.nl]) AC_CONFIG_HEADERS([config.h]) # @@ -987,6 +987,16 @@ AC_ARG_WITH([tcp_timeout], AC_DEFINE_UNQUOTED([TCP_TIMEOUT], $tcp_timeout, [Define to the default tcp timeout.]) dnl +dnl Determine the maximum CNAME chain length to return +dnl Defaults to 18 as a tribute to our dear colleague +dnl +max_cname_chain=18 +AC_ARG_WITH([max_cname_chain], + AS_HELP_STRING([--with-max-cname-chain=number],[Limit the maximum number of CNAMEs to follow]), + [max_cname_chain=$withval]) +AC_DEFINE_UNQUOTED([MAX_CNAME_CHAIN], $max_cname_chain, [Define to the default maximum number of CNAMEs to follow.]) + +dnl dnl Features dnl AC_ARG_ENABLE(root-server, AS_HELP_STRING([--enable-root-server],[Configure NSD as a root server (obsolete)])) @@ -998,6 +1008,15 @@ case "$enable_ipv6" in yes|*) AC_DEFINE_UNQUOTED([INET6], [], [Define this to enable IPv6 support.]) ;; +esac + +AC_ARG_ENABLE(multiple-catalog-zones, AS_HELP_STRING([--enable-multiple-catzones],[Enable experimental support for more than one catalog consumer zone])) +case "$enable_multiple_catalog_zones" in + yes) + AC_DEFINE_UNQUOTED([MULTIPLE_CATALOG_CONSUMER_ZONES], [], [Define this to enable experimental support for more than one catalog consumer zone.]) + ;; + no|*) + ;; esac AC_ARG_ENABLE(bind8-stats, AS_HELP_STRING([--disable-bind8-stats],[Disable BIND8 like NSTATS & XSTATS and statistics in nsd-control])) Index: usr.sbin/nsd/convert-release-notes.sh =================================================================== RCS file: /cvs/src/usr.sbin/nsd/convert-release-notes.sh,v diff -u -p -r1.1.1.1 convert-release-notes.sh --- usr.sbin/nsd/convert-release-notes.sh 21 Mar 2026 21:34:33 -0000 1.1.1.1 +++ usr.sbin/nsd/convert-release-notes.sh 21 Sep 2026 16:28:41 -0000 @@ -48,11 +48,6 @@ error_too_many_args() { } extract_release_notes() { - # Find latest version if VERSION was not specified - if [[ -z "$VERSION" ]]; then - VERSION=$(grep -E -m1 -B1 "^=====+$" <"$RELNOTES_FILE" | head -n1) - fi - sed -E -e "/^$VERSION/{ n; n; bfound }; d; bend" \ -e ':found; /\n=====+$/bstrip_trailer; N; bfound' \ -e ':strip_trailer; s/\n+([0-9]+\.[0-9]+\.[0-9]+)\n=====+$//' \ @@ -191,6 +186,11 @@ if ! [[ -f "$RELNOTES_FILE" ]]; then fi #### Generate text #### + +# Find latest version if VERSION was not specified +if [[ -z "$VERSION" ]]; then + VERSION=$(grep -E -m1 -B1 "^=====+$" <"$RELNOTES_FILE" | head -n1) +fi if [[ "$PRINT_EMAIL" == true ]]; then SHA256="" Index: usr.sbin/nsd/difffile.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/difffile.c,v diff -u -p -r1.25 difffile.c --- usr.sbin/nsd/difffile.c 21 Mar 2026 21:36:36 -0000 1.25 +++ usr.sbin/nsd/difffile.c 21 Sep 2026 16:28:41 -0000 @@ -505,7 +505,7 @@ find_rr_num(rrset_type* rrset, uint16_t } } /* this is odd. Log why rr cannot be found. */ - if (!add) { + if (!add && verbosity >= 3) { debug_find_rr_num(rrset, type, klass, rr); } return -1; @@ -522,6 +522,7 @@ nsec3_delete_rr_trigger(namedb_type* db, /* see if the domain was an NSEC3-domain in the chain, but no longer */ if(rr->type == TYPE_NSEC3 && rr->owner->nsec3 && rr->owner->nsec3->nsec3_node.key && + nsec3_has_owner_for_zone(rr->owner, zone) && nsec3_rr_uses_params(rr, zone) && nsec3_in_chain_count(rr->owner, zone) <= 1) { domain_type* prev = nsec3_chain_find_prev(zone, rr->owner); @@ -640,6 +641,7 @@ nsec3_add_rr_trigger(namedb_type* db, rr * in the udb has been adjusted) */ if(zone->nsec3_param && rr->type == TYPE_NSEC3 && (!rr->owner->nsec3 || !rr->owner->nsec3->nsec3_node.key) + && nsec3_has_owner_for_zone(rr->owner, zone) && nsec3_rr_uses_params(rr, zone)) { if(!zone->nsec3_last) { /* all nsec3s have previously been deleted, but @@ -711,6 +713,16 @@ delete_RR(namedb_type* db, const dname_t rrset_type* rrset_prev; #endif const nsd_type_descriptor_type *descriptor = nsd_type_descriptor(type); + if (!dname_is_subdomain(dname, domain_dname(zone->apex))) { + char zname[MAXDOMAINLEN * 5]; + domain_to_string_buf(zone->apex, zname); + VERBOSITY(2, (LOG_WARNING, + "out-of-zone record deletion in transfer for zone %s: " + "owner %s is outside zone; skipping", + zname, dname_to_string(dname, NULL))); + buffer_skip(packet, rdatalen); + return 1; + } domain = domain_table_find(db->domains, dname); if(!domain) { log_msg(LOG_WARNING, "diff: domain %s does not exist", @@ -725,8 +737,9 @@ delete_RR(namedb_type* db, const dname_t rrset = domain_find_rrset_and_prev(domain, zone, type, &rrset_prev); #endif if(!rrset) { - log_msg(LOG_WARNING, "diff: rrset %s does not exist", - dname_to_string(dname,0)); + VERBOSITY(2, (LOG_WARNING, + "diff: RRset to delete from <%s, %s> does not exist", + dname_to_string(dname,0), rrtype_to_string(type))); buffer_skip(packet, rdatalen); *softfail = 1; return 1; /* not fatal error */ @@ -735,6 +748,7 @@ delete_RR(namedb_type* db, const dname_t domain_table_type *temptable; int32_t rrnum, code; struct rr *rr; + int was_rrsig_dnskey = 0; temptable = domain_table_create(temp_region); /* This will ensure that the dnames in rdata are * normalized, conform RFC 4035, section 6.2 @@ -745,6 +759,7 @@ delete_RR(namedb_type* db, const dname_t "%s %s %s", dname_to_string(dname,0), rrtype_to_string(type), read_rdata_fail_str(code)); + return 0; } rr->owner = domain; rr->type = type; @@ -764,8 +779,9 @@ delete_RR(namedb_type* db, const dname_t && rrset->rr_count != 0) rrnum = 0; /* replace existing SOA if no match */ if(rrnum == -1) { - log_msg(LOG_WARNING, "diff: RR <%s, %s> does not exist", - dname_to_string(dname,0), rrtype_to_string(type)); + VERBOSITY(2, (LOG_WARNING, + "diff: RR to delete from RRset <%s, %s> does not exist", + dname_to_string(dname,0), rrtype_to_string(type))); *softfail = 1; return 1; /* not fatal error */ } @@ -773,6 +789,10 @@ delete_RR(namedb_type* db, const dname_t /* process triggers for RR deletions */ nsec3_delete_rr_trigger(db, rrset->rrs[rrnum], zone); #endif + if(domain == zone->apex && type == TYPE_RRSIG && + rr_rrsig_type_covered(rrset->rrs[rrnum])==TYPE_DNSKEY) + was_rrsig_dnskey = 1; + /* lower usage (possibly deleting other domains, and thus * invalidating the current RR's domain pointers) */ rr_lower_usage(db, rrset->rrs[rrnum]); @@ -822,6 +842,8 @@ delete_RR(namedb_type* db, const dname_t region_recycle(db->region, rrset_orig, sizeof(rrset_type) + rrset_orig->rr_count*sizeof(rr_type*)); +#endif /* PACKED_STRUCTS */ + rrset->rr_count --; if(domain == zone->apex) { /* Because the rrset struct is reallocated, * a pointer to it may need to be set again. */ @@ -829,10 +851,23 @@ delete_RR(namedb_type* db, const dname_t zone->soa_rrset = rrset; } else if(type == TYPE_NS) { zone->ns_rrset = rrset; + } else if(type == TYPE_RRSIG + && was_rrsig_dnskey) { + /* See if the zone is still signed */ + unsigned i; + int has_dnskey_rrsig = 0; + for (i = 0; i < rrset->rr_count; i++) { + if(rr_rrsig_type_covered( + rrset->rrs[i])== + TYPE_DNSKEY){ + has_dnskey_rrsig = 1; + break; + } + } + if(!has_dnskey_rrsig) + zone->is_secure = 0; } } -#endif /* PACKED_STRUCTS */ - rrset->rr_count --; #ifdef NSEC3 /* for type nsec3, the domain may have become a * 'normal' domain with its remaining data now */ @@ -973,6 +1008,16 @@ add_RR(namedb_type* db, const dname_type commit_RRset(db, zone, &collect_rrs2); return 1; } + if (!dname_is_subdomain(dname, domain_dname(zone->apex))) { + char zname[MAXDOMAINLEN * 5]; + domain_to_string_buf(zone->apex, zname); + VERBOSITY(2, (LOG_WARNING, + "out-of-zone record in transfer for zone %s: " + "owner %s is outside zone; skipping", + zname, dname_to_string(dname, NULL))); + buffer_skip(packet, rdatalen); + return 1; + } domain = domain_table_insert(db->domains, dname); assert(domain); if (domain != collect_rrs->domain || type != collect_rrs->type @@ -1275,6 +1320,14 @@ apply_ixfr(nsd_type* nsd, FILE *in, uint region_destroy(region); return 0; } + if (klass != CLASS_IN && type != TYPE_OPT) { + log_msg(LOG_ERR, "bad xfr non-IN-class RR %s %s %s", + dname_to_string(owner,0), + rrclass_to_string(klass), + rrtype_to_string(type)); + region_destroy(region); + return 0; + } DEBUG(DEBUG_XFRD,2, (LOG_INFO, "diff: %s parsed count %d, ax %d, delmode %d", domain_to_string(zone->apex), *rr_count, *is_axfr, *delete_mode)); @@ -1299,11 +1352,6 @@ apply_ixfr(nsd_type* nsd, FILE *in, uint if (*rr_count == 0) { assert(!*is_axfr); assert(!*delete_mode); - if (klass != CLASS_IN) { - log_msg(LOG_ERR, "first RR not SOA IN"); - region_destroy(region); - return 0; - } if(dname_compare(domain_dname(zone->apex), owner) != 0) { log_msg(LOG_ERR, "SOA dname not equal to zone %s", domain_to_string(zone->apex)); @@ -1316,10 +1364,9 @@ apply_ixfr(nsd_type* nsd, FILE *in, uint region_destroy(region); return 0; } - buffer_skip(packet, rrlen); - if(ixfr_store) ixfr_store_add_newsoa(ixfr_store, ttl, packet, rrlen); + buffer_skip(packet, rrlen); continue; } else if (*rr_count == 1) { @@ -1364,6 +1411,14 @@ apply_ixfr(nsd_type* nsd, FILE *in, uint just before soa - so it gets deleted and added too */ DEBUG(DEBUG_XFRD,2, (LOG_INFO, "diff: %s IXFRswapdel count %d, ax %d, delmode %d", domain_to_string(zone->apex), *rr_count, *is_axfr, *delete_mode)); + } else if(*is_axfr) { + if(!(seq_nr == seq_total-1 && i == ancount-1)) { + /* AXFR mode: a SOA at rr_count>=2 + * should not exist. Skip it rather + * than passing it to add_RR. */ + buffer_skip(packet, rrlen); + continue; + } } } else { if (*rr_count == 0) { @@ -2079,7 +2134,15 @@ task_process_add_zone(struct nsd* nsd, u return; } /* create zone */ +#ifdef NSEC3 + nsec3_superzone_clear_for_apex(nsd->db, zdname); +#endif z = find_or_create_zone(nsd->db, zdname, nsd->options, zname, pname); +#ifdef NSEC3 + /* If no z, it reinstates the content, if z created, it creates + * the content around the new zone apex (created with zone create). */ + nsec3_superzone_precompile_for_apex(nsd->db, zdname); +#endif if(!z) { region_recycle(nsd->db->region, (void*)zdname, dname_total_size(zdname)); @@ -2108,6 +2171,7 @@ task_process_del_zone(struct nsd* nsd, s return; #ifdef NSEC3 + nsec3_superzone_clear_for_apex(nsd->db, task->zname); nsec3_clear_precompile(nsd->db, zone); zone->nsec3_param = NULL; #endif @@ -2116,6 +2180,9 @@ task_process_del_zone(struct nsd* nsd, s /* remove from zonetree, apex, soa */ zopt = zone->opts; namedb_zone_delete(nsd->db, zone); +#ifdef NSEC3 + nsec3_superzone_precompile_for_apex(nsd->db, task->zname); +#endif /* remove from options (zone_list already edited by xfrd) */ zone_options_delete(nsd->options, zopt); } Index: usr.sbin/nsd/difffile.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/difffile.h,v diff -u -p -r1.8 difffile.h --- usr.sbin/nsd/difffile.h 21 Mar 2026 21:36:36 -0000 1.8 +++ usr.sbin/nsd/difffile.h 21 Sep 2026 16:28:41 -0000 @@ -125,7 +125,7 @@ struct task_list_d { uint32_t oldserial, newserial; /** general variable. for some used to see if zname is present. */ uint64_t yesno; - struct dname zname[0]; + struct dname zname[]; }; #define TASKLIST(ptr) ((struct task_list_d*)UDB_PTR(ptr)) /** create udb for tasks */ Index: usr.sbin/nsd/dname.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/dname.c,v diff -u -p -r1.18 dname.c --- usr.sbin/nsd/dname.c 21 Mar 2026 21:36:36 -0000 1.18 +++ usr.sbin/nsd/dname.c 21 Sep 2026 16:28:41 -0000 @@ -470,7 +470,8 @@ dname_concatenate(region_type *region, { uint8_t temp[MAXDOMAINLEN]; - assert(left->name_size + right->name_size - 1 <= MAXDOMAINLEN); + if(left->name_size + right->name_size - 1 > MAXDOMAINLEN) + return NULL; memcpy(temp, dname_name(left), left->name_size - 1); memcpy(temp + left->name_size - 1, dname_name(right), right->name_size); Index: usr.sbin/nsd/dns.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/dns.c,v diff -u -p -r1.24 dns.c --- usr.sbin/nsd/dns.c 21 Mar 2026 21:36:36 -0000 1.24 +++ usr.sbin/nsd/dns.c 21 Sep 2026 16:28:41 -0000 @@ -404,6 +404,14 @@ static const struct nsd_rdata_descriptor FIELD("target", RDATA_LITERAL_DNAME) }; +static const struct nsd_rdata_descriptor hhit_rdata_fields[] = { + FIELD("cbor blob", RDATA_REMAINDER) +}; + +static const struct nsd_rdata_descriptor brid_rdata_fields[] = { + FIELD("cbor blob", RDATA_REMAINDER) +}; + static const struct nsd_rdata_descriptor spf_rdata_fields[] = { FIELD("text", RDATA_REMAINDER) }; @@ -780,9 +788,15 @@ const nsd_type_descriptor_type type_desc TYPE("DSYNC", TYPE_DSYNC, TYPE_HAS_LITERAL_DNAME, read_dsync_rdata, write_generic_rdata, print_dsync_rdata, dsync_rdata_fields), + /* 67 */ + TYPE("HHIT", TYPE_HHIT, TYPE_HAS_NO_REFS, + read_hhit_rdata, write_generic_rdata, + print_hhit_rdata, hhit_rdata_fields), + /* 68 */ + TYPE("BRID", TYPE_BRID, TYPE_HAS_NO_REFS, + read_brid_rdata, write_generic_rdata, + print_brid_rdata, brid_rdata_fields), - UNKNOWN_TYPE(67), - UNKNOWN_TYPE(68), UNKNOWN_TYPE(69), UNKNOWN_TYPE(70), UNKNOWN_TYPE(71), Index: usr.sbin/nsd/dns.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/dns.h,v diff -u -p -r1.23 dns.h --- usr.sbin/nsd/dns.h 21 Mar 2026 21:36:36 -0000 1.23 +++ usr.sbin/nsd/dns.h 21 Sep 2026 16:28:41 -0000 @@ -152,6 +152,8 @@ typedef enum nsd_rc nsd_rc_type; #define TYPE_SVCB 64 /* RFC 9460 */ #define TYPE_HTTPS 65 /* RFC 9460 */ #define TYPE_DSYNC 66 /* RFC 9859 */ +#define TYPE_HHIT 67 /* RFC 9886 */ +#define TYPE_BRID 68 /* RFC 9886 */ #define TYPE_SPF 99 /* RFC 4408 */ @@ -193,6 +195,9 @@ typedef enum nsd_rc nsd_rc_type; #define SVCB_KEY_DOHPATH 7 #define SVCB_KEY_OHTTP 8 #define SVCB_KEY_TLS_SUPPORTED_GROUPS 9 +#define SVCB_KEY_DOCPATH 10 +#define SVCB_KEY_PVD 11 +#define SVCB_KEY_OOTS 12 #define MAXLABELLEN 63 #define MAXDOMAINLEN 255 @@ -209,6 +214,7 @@ typedef enum nsd_rc nsd_rc_type; #define EUI64ADDRLEN (64/8) #define NSEC3_HASH_LEN 20 +#define NSEC3_OWNER_LABEL_LEN (NSEC3_HASH_LEN * 8 / 5) /* * The following RDATA values are used in nsd_rdata_descriptor.length to Index: usr.sbin/nsd/edns.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/edns.c,v diff -u -p -r1.9 edns.c --- usr.sbin/nsd/edns.c 3 Sep 2025 18:46:48 -0000 1.9 +++ usr.sbin/nsd/edns.c 21 Sep 2026 16:28:41 -0000 @@ -20,6 +20,7 @@ #include "edns.h" #include "nsd.h" #include "query.h" +#include "options.h" #if !defined(HAVE_SSL) || !defined(HAVE_CRYPTO_MEMCMP) /* we need fixed time compare, pull it in from tsig.c */ @@ -71,6 +72,8 @@ edns_init_record(edns_record_type *edns) edns->dnssec_ok = 0; edns->nsid = 0; edns->zoneversion = 0; + edns->padding = 0; + edns->cookie_seen = 0; edns->cookie_status = COOKIE_NOT_PRESENT; edns->cookie_len = 0; edns->ede = -1; /* -1 means no Extended DNS Error */ @@ -88,7 +91,7 @@ edns_handle_option(uint16_t optcode, uin switch(optcode) { case NSID_CODE: /* is NSID enabled? */ - if(nsd->nsid_len > 0) { + if(nsd->nsid_len > 0 && !edns->nsid) { edns->nsid = 1; /* we have to check optlen, and move the buffer along */ buffer_skip(packet, optlen); @@ -101,7 +104,8 @@ edns_handle_option(uint16_t optcode, uin break; case COOKIE_CODE: /* Cookies enabled? */ - if(nsd->do_answer_cookie) { + if(nsd->do_answer_cookie && !edns->cookie_seen) { + edns->cookie_seen = 1; if (optlen == 8) edns->cookie_status = COOKIE_INVALID; else if (optlen < 16 || optlen > 40) @@ -117,6 +121,11 @@ edns_handle_option(uint16_t optcode, uin buffer_skip(packet, optlen); } break; + case PADDING_CODE: + if(query->tcp || query->may_pad) + edns->padding = 1; + buffer_skip(packet, optlen); + break; case ZONEVERSION_CODE: edns->zoneversion = 1; if(optlen > 0) @@ -257,11 +266,8 @@ void cookie_verify(query_type *q, struct q->edns.cookie_status = COOKIE_INVALID; - cookie_time = (q->edns.cookie[12] << 24) - | (q->edns.cookie[13] << 16) - | (q->edns.cookie[14] << 8) - | q->edns.cookie[15]; - + cookie_time = read_uint32(q->edns.cookie + 12); + now_uint32 = *now_p ? *now_p : (*now_p = (uint32_t)time(NULL)); if(compare_1982(now_uint32, cookie_time) > 0) { Index: usr.sbin/nsd/edns.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/edns.h,v diff -u -p -r1.7 edns.h --- usr.sbin/nsd/edns.h 6 Sep 2025 17:41:37 -0000 1.7 +++ usr.sbin/nsd/edns.h 21 Sep 2026 16:28:41 -0000 @@ -19,6 +19,7 @@ struct query; #define OPT_HDR 4U /* NSID opt header length */ #define NSID_CODE 3 /* nsid option code */ #define COOKIE_CODE 10 /* COOKIE option code */ +#define PADDING_CODE 12 /* Padding option code */ #define EDE_CODE 15 /* Extended DNS Errors option code */ #define ZONEVERSION_CODE 19 /* ZONEVERSION option code */ #define DNSSEC_OK_MASK 0x8000U /* do bit mask */ @@ -26,6 +27,9 @@ struct query; /* https://iana.org/assignments/dns-parameters/#zoneversion-type-values */ #define ZONEVERSION_SOA_SERIAL 0 +/* See RFC 8467 */ +#define PADDING_BLOCK_SZ 468 + struct edns_data { unsigned char ok[OPT_LEN]; @@ -64,6 +68,8 @@ struct edns_record int dnssec_ok; int nsid; int zoneversion; + int padding; + int cookie_seen; cookie_status_type cookie_status; size_t cookie_len; uint8_t cookie[40]; Index: usr.sbin/nsd/install-sh =================================================================== RCS file: /cvs/src/usr.sbin/nsd/install-sh,v diff -u -p -r1.3 install-sh --- usr.sbin/nsd/install-sh 6 Sep 2025 17:41:37 -0000 1.3 +++ usr.sbin/nsd/install-sh 21 Sep 2026 16:28:41 -0000 @@ -1,7 +1,7 @@ #!/bin/sh # install - install a program, script, or datafile -scriptversion=2023-11-23.18; # UTC +scriptversion=2020-11-14.01; # UTC # This originates from X11R5 (mit/util/scripts/install.sh), which was # later released in X11R6 (xc/config/util/install.sh) with the @@ -124,9 +124,9 @@ it's up to you to specify -f if you want If -S is not specified, no backups are attempted. -Report bugs to . -GNU Automake home page: . -General help using GNU software: ." +Email bug reports to bug-automake@gnu.org. +Automake home page: https://www.gnu.org/software/automake/ +" while test $# -ne 0; do case $1 in Index: usr.sbin/nsd/ipc.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/ipc.c,v diff -u -p -r1.14 ipc.c --- usr.sbin/nsd/ipc.c 6 Sep 2025 17:41:37 -0000 1.14 +++ usr.sbin/nsd/ipc.c 21 Sep 2026 16:28:41 -0000 @@ -574,10 +574,19 @@ xfrd_handle_ipc_read(struct event* handl if(!xfrd->reload_failed) { xfrd_check_failed_updates(); xfrd->reload_cmd_first_sent = 0; + xfrd->num_reload_failed_repeat = 0; + xfrd->num_xfrs_in_reload = 0; } else { + if(xfrd->num_reload_failed_repeat++ > + xfrd->num_xfrs_in_reload) { + /* More fails than zones, it may be that + * reload crashes, delete failed updates. */ + xfrd_check_failed_updates(); + } /* make reload happen again, right away */ xfrd_set_reload_now(xfrd); } + xfrd->num_xfrs_in_reload = 0; xfrd_prepare_zones_for_reload(); xfrd->reload_failed = 0; break; Index: usr.sbin/nsd/ixfr.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/ixfr.c,v diff -u -p -r1.6 ixfr.c --- usr.sbin/nsd/ixfr.c 21 Mar 2026 21:36:36 -0000 1.6 +++ usr.sbin/nsd/ixfr.c 21 Sep 2026 16:28:42 -0000 @@ -439,6 +439,7 @@ static int parse_qserial(struct buffer* { unsigned int i; uint16_t type, rdlen; + size_t rdpos; /* we must have a SOA in the authority section */ if(NSCOUNT(packet) == 0) return 0; @@ -460,6 +461,7 @@ static int parse_qserial(struct buffer* type = buffer_read_u16(packet); buffer_skip(packet, 6); rdlen = buffer_read_u16(packet); + rdpos = buffer_position(packet); if(!buffer_available(packet, rdlen)) return 0; if(type == TYPE_SOA) { @@ -471,6 +473,9 @@ static int parse_qserial(struct buffer* return 0; /* malformed rname */ if(!buffer_available(packet, 4)) return 0; + if(buffer_position(packet) + 20 != + rdpos + (size_t)rdlen) + return 0; /* malformed SOA rdata */ *qserial = buffer_read_u32(packet); return 1; } @@ -567,6 +572,7 @@ static struct ixfr_data* ixfr_data_prev( struct ixfr_data* cur, size_t* prevcount) { struct ixfr_data* prev; + int wrapped = 0; if(!cur || cur == (struct ixfr_data*)RBTREE_NULL) return NULL; if(cur->oldserial == ixfr->oldest_serial) @@ -600,6 +606,11 @@ static struct ixfr_data* ixfr_data_prev( /* We hit the first element in the tree, go again * at the last one. Wrap around. */ prev = (struct ixfr_data*)rbtree_last(ixfr->data); + if(wrapped) { + /* The lookup wrapped again, this is a loop. */ + return NULL; + } + wrapped = 1; } } /* no elements in list */ @@ -611,8 +622,11 @@ static int connect_ixfrs(struct zone_ixf uint32_t* end_serial) { struct ixfr_data* p = data; + size_t count = 0; while(p != NULL) { struct ixfr_data* next = ixfr_data_next(ixfr, p); + if(count++ > ixfr->data->count + 12) + return 0; /* loop */ if(next) { if(p->newserial != next->oldserial) { /* These ixfrs are not connected, @@ -688,6 +702,18 @@ static uint16_t ixfr_copy_rrs_into_packe query->ixfr_pos_of_newsoa = buffer_position(query->packet); } else { /* cannot add another RR, so return */ + if(total_added == 0) { + /* RR exceeds TCP_MAX_MESSAGE_LEN (65535 bytes): + * cannot fit in any DNS message. Abort the + * IXFR transfer rather than spinning. */ + VERBOSITY(2, (LOG_ERR, "ixfr_out: SOA RR in zone %s too large for any DNS message " + "(wire encoding exceeds %d bytes), aborting IXFR transfer", + + domain_to_string(query->zone->apex), + TCP_MAX_MESSAGE_LEN)); + RCODE_SET(query->packet, RCODE_SERVFAIL); + query->ixfr_is_done = 1; + } return total_added; } } @@ -701,6 +727,18 @@ static uint16_t ixfr_copy_rrs_into_packe total_added++; } else { /* cannot add another RR, so return */ + if(total_added == 0) { + /* RR exceeds TCP_MAX_MESSAGE_LEN (65535 bytes): + * cannot fit in any DNS message. Abort the + * IXFR transfer rather than spinning. */ + VERBOSITY(2, (LOG_ERR, "ixfr_out: SOA RR in zone %s too large for any DNS message " + "(wire encoding exceeds %d bytes), aborting IXFR transfer", + + domain_to_string(query->zone->apex), + TCP_MAX_MESSAGE_LEN)); + RCODE_SET(query->packet, RCODE_SERVFAIL); + query->ixfr_is_done = 1; + } return total_added; } } @@ -717,6 +755,21 @@ static uint16_t ixfr_copy_rrs_into_packe } else { /* the next record does not fit in the remaining * space of the packet */ + if(total_added == 0) { + /* RR exceeds TCP_MAX_MESSAGE_LEN (65535 bytes): + * cannot fit in any DNS message. Abort the + * IXFR transfer rather than spinning. */ + char apexstr[MAXDOMAINLEN * 5]; + char* ownerstr = ""; + if(rrlen) + ownerstr = wiredname2str(query->ixfr_data->del + query->ixfr_count_del); + domain_to_string_buf(query->zone->apex, apexstr); + VERBOSITY(2, (LOG_ERR, "ixfr_out: RR at %s in zone %s too large for any DNS message " + "(wire encoding exceeds %d bytes), aborting IXFR transfer", + ownerstr, apexstr, TCP_MAX_MESSAGE_LEN)); + RCODE_SET(query->packet, RCODE_SERVFAIL); + query->ixfr_is_done = 1; + } return total_added; } } @@ -733,6 +786,21 @@ static uint16_t ixfr_copy_rrs_into_packe } else { /* the next record does not fit in the remaining * space of the packet */ + if(total_added == 0) { + /* RR exceeds TCP_MAX_MESSAGE_LEN (65535 bytes): + * cannot fit in any DNS message. Abort the + * IXFR transfer rather than spinning. */ + char apexstr[MAXDOMAINLEN * 5]; + char* ownerstr = ""; + if(rrlen) + ownerstr = wiredname2str(query->ixfr_data->add + query->ixfr_count_add); + domain_to_string_buf(query->zone->apex, apexstr); + VERBOSITY(2, (LOG_ERR, "ixfr_out: RR at %s in zone %s too large for any DNS message " + "(wire encoding exceeds %d bytes), aborting IXFR transfer", + ownerstr, apexstr, TCP_MAX_MESSAGE_LEN)); + RCODE_SET(query->packet, RCODE_SERVFAIL); + query->ixfr_is_done = 1; + } return total_added; } } @@ -748,8 +816,10 @@ query_state_type query_ixfr(struct nsd * return QUERY_PROCESSED; pktcompression_init(&pcomp); - if (query->maxlen > IXFR_MAX_MESSAGE_LEN) + if (query->maxlen > IXFR_MAX_MESSAGE_LEN) { + buffer_set_position(query->packet, QHEADERSZ); query->maxlen = IXFR_MAX_MESSAGE_LEN; + } assert(!query_overflow(query)); /* only keep running values for most packets */ @@ -874,7 +944,8 @@ query_state_type query_ixfr(struct nsd * total_added = ixfr_copy_rrs_into_packet(query, &pcomp); - while(query->ixfr_count_add >= query->ixfr_data->add_len) { + while(!query->ixfr_is_done && + query->ixfr_count_add >= query->ixfr_data->add_len) { struct ixfr_data* next = ixfr_data_next(query->zone->ixfr, query->ixfr_data); /* finished the ixfr_data */ @@ -1074,7 +1145,8 @@ void ixfr_store_finish(struct ixfr_store ixfr_store_free(ixfr_store); return; } - zone_ixfr_add(ixfr_store->zone->ixfr, ixfr_store->data, 1); + zone_ixfr_add(ixfr_store->zone->ixfr, ixfr_store->data, 1, + ixfr_store->zone->opts->name); ixfr_store->data = NULL; /* free structure */ @@ -1180,6 +1252,12 @@ void ixfr_store_add_newsoa(struct ixfr_s } rdlen_uncompressed = primns_len + email_len + 4 + 4 + 4 + 4 + 4; + if(ixfr_store->data->oldsoa && ixfr_store->data->oldserial == serial) { + log_msg(LOG_ERR, "ixfr_store newsoa: duplicate serial number"); + ixfr_store_cancel(ixfr_store); + buffer_set_position(packet, oldpos); + return; + } ixfr_store->data->newserial = serial; /* store the soa record */ @@ -1234,6 +1312,12 @@ void ixfr_store_add_oldsoa(struct ixfr_s } rdlen_uncompressed = primns_len + email_len + 4 + 4 + 4 + 4 + 4; + if(ixfr_store->data->newsoa && ixfr_store->data->newserial == serial) { + log_msg(LOG_ERR, "ixfr_store oldsoa: duplicate serial number"); + ixfr_store_cancel(ixfr_store); + buffer_set_position(packet, oldpos); + return; + } ixfr_store->data->oldserial = serial; /* store the soa record */ @@ -1524,6 +1608,8 @@ static void zone_ixfr_remove_oldest(stru { if(ixfr->data->count > 0) { struct ixfr_data* oldest = ixfr_data_first(ixfr); + if(!oldest) + return; /* oldest_serial is stale, skip eviction */ if(ixfr->oldest_serial == oldest->oldserial) { if(ixfr->data->count > 1) { struct ixfr_data* next = ixfr_data_next(ixfr, oldest); @@ -1589,10 +1675,20 @@ void zone_ixfr_remove(struct zone_ixfr* ixfr_data_free(data); } -void zone_ixfr_add(struct zone_ixfr* ixfr, struct ixfr_data* data, int isnew) +void zone_ixfr_add(struct zone_ixfr* ixfr, struct ixfr_data* data, int isnew, + const char* zname) { memset(&data->node, 0, sizeof(data->node)); - if(ixfr->data->count == 0) { + data->node.key = &data->oldserial; + if(rbtree_insert(ixfr->data, &data->node) == NULL) { + /* duplicate oldserial in IXFR stream - reject the chunk. */ + log_msg(LOG_WARNING, "zone %s: chunk with duplicate " + "oldserial=%u discarded; broken journal chain prevented", + (zname?zname:""), (unsigned)data->oldserial); + ixfr_data_free(data); + return; + } + if(ixfr->data->count == 1) { ixfr->oldest_serial = data->oldserial; ixfr->newest_serial = data->oldserial; } else if(isnew) { @@ -1602,8 +1698,6 @@ void zone_ixfr_add(struct zone_ixfr* ixf /* added older entry, before the others */ ixfr->oldest_serial = data->oldserial; } - data->node.key = &data->oldserial; - rbtree_insert(ixfr->data, &data->node); ixfr->total_size += ixfr_data_size(data); } @@ -1844,7 +1938,7 @@ static int ixfr_rename_files(struct zone int dest_num_files) { struct ixfr_data* data, *startspot = NULL; - size_t prevcount = 0; + size_t prevcount = 0, count = 0; int destnum; if(!zone->ixfr || !zone->ixfr->data) return 1; @@ -1883,6 +1977,11 @@ static int ixfr_rename_files(struct zone * has been renamed to a temporary name */ startspot = data; data = ixfr_data_next(zone->ixfr, data); + if(count++ > zone->ixfr->data->count+12) { + /* loop */ + ixfr_delete_rest_files(zone, data, zfile, 1); + return 0; + } destnum--; } @@ -2555,6 +2654,7 @@ static int ixfr_data_read(struct nsd* ns const char* ixfrfile, uint32_t* dest_serial, int file_num) { struct ixfr_data_state state = { 0 }; + size_t ixfr_data_sz; if(!zone->apex) { return 0; @@ -2634,9 +2734,11 @@ static int ixfr_data_read(struct nsd* ns ixfr_data_free(state.data); return 0; } - zone_ixfr_add(zone->ixfr, state.data, 0); + ixfr_data_sz = ixfr_data_size(state.data); /* pick up size before + possible deletion of the item */ + zone_ixfr_add(zone->ixfr, state.data, 0, zone->opts->name); VERBOSITY(3, (LOG_INFO, "zone %s read %s IXFR data of %u bytes", - zone->opts->name, ixfrfile, (unsigned)ixfr_data_size(state.data))); + zone->opts->name, ixfrfile, (unsigned)ixfr_data_sz)); return 1; } Index: usr.sbin/nsd/ixfr.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/ixfr.h,v diff -u -p -r1.4 ixfr.h --- usr.sbin/nsd/ixfr.h 21 Mar 2026 21:36:36 -0000 1.4 +++ usr.sbin/nsd/ixfr.h 21 Sep 2026 16:28:42 -0000 @@ -215,7 +215,8 @@ void zone_ixfr_make_space(struct zone_ix void zone_ixfr_remove(struct zone_ixfr* ixfr, struct ixfr_data* data); /* add ixfr data to the zone_ixfr */ -void zone_ixfr_add(struct zone_ixfr* ixfr, struct ixfr_data* data, int isnew); +void zone_ixfr_add(struct zone_ixfr* ixfr, struct ixfr_data* data, int isnew, + const char* zname); /* find serial number in ixfr list, or NULL if not found */ struct ixfr_data* zone_ixfr_find_serial(struct zone_ixfr* ixfr, Index: usr.sbin/nsd/metrics.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/metrics.c,v diff -u -p -r1.1.1.2 metrics.c --- usr.sbin/nsd/metrics.c 21 Mar 2026 21:34:32 -0000 1.1.1.2 +++ usr.sbin/nsd/metrics.c 21 Sep 2026 16:28:42 -0000 @@ -19,6 +19,7 @@ #include #include #include +#include #include "nsd.h" #include "xfrd.h" @@ -349,49 +350,88 @@ metrics_http_callback(struct evhttp_requ } #ifdef BIND8_STATS -/** Change disallowed characters, '.' ':' to underscores '_'. */ +#define METRIC_MAX_LABELS 2 + +struct metrics_metric { + const char *prefix; + const char *name; + const char *type; + size_t label_count; + const char *label_names[METRIC_MAX_LABELS]; + const char *label_values[METRIC_MAX_LABELS]; +}; + static void -change_string_underscores(char* prefix) -{ - /* Prometheus does not want '.' in the metric names. But the zone - * statistics could have then in their name. - * Also ':' is not allowed. This routine enforeces that it - * has letters,digits,underscores. */ - char* s = prefix; - while(*s) { - if(!isalnum((unsigned char)*s) && *s != '_') - *s = '_'; - s++; - } +metric_init_with_prefix(struct metrics_metric *metric, const char *prefix) { + metric->prefix = prefix; + metric->name = ""; + metric->label_count = 0; } -/** print long number*/ -static int -print_longnum(struct evbuffer *buf, char* desc, uint64_t x) -{ - if(x > (uint64_t)1024*1024*1024) { - /*more than a Gb*/ - size_t front = (size_t)(x / (uint64_t)1000000); - size_t back = (size_t)(x % (uint64_t)1000000); - return evbuffer_add_printf(buf, "%s%lu%6.6lu\n", desc, - (unsigned long)front, (unsigned long)back); +static void +metric_set_name_and_type(struct metrics_metric *metric, const char *name, const char *type) { + metric->name = name; + metric->type = type; +} + +/* Add a `name="value"` label to the metric. + * The value must not contain `\`, `\n`, or `"`. */ +static void +metric_push_label(struct metrics_metric *metric, const char *name, const char *value) { + assert(metric->label_count < METRIC_MAX_LABELS); + metric->label_names[metric->label_count] = name; + metric->label_values[metric->label_count] = value; + metric->label_count++; +} + +static void +metric_pop_label(struct metrics_metric *metric) { + assert(metric->label_count > 0); + metric->label_count--; +} + +static void +metric_print(struct metrics_metric *metric, struct evbuffer *buf, uint64_t value) { + evbuffer_add_printf(buf, "%s%s", metric->prefix, metric->name); + for (size_t i = 0; i < metric->label_count; i++) { + evbuffer_add_printf(buf, "%c%s=\"%s\"", + i == 0 ? '{' : ',', + metric->label_names[i], + metric->label_values[i]); + } + if (metric->label_count > 0) { + evbuffer_add_printf(buf, "} %" PRIu64 "\n", value); } else { - return evbuffer_add_printf(buf, "%s%lu\n", desc, (unsigned long)x); + evbuffer_add_printf(buf, " %" PRIu64 "\n", value); } } +/** Print a metric value of `integral + decimals_micro * 1e-6`. */ static void -print_metric_help_and_type(struct evbuffer *buf, char *prefix, char *name, - char *help, char *type) +metric_print_micros(struct metrics_metric *metric, struct evbuffer *buf, + unsigned long integral, unsigned long decimals_micro) { + assert(metric->label_count == 0 + && "metric_print_micros is not implemented for metrics with labels"); + evbuffer_add_printf(buf, "%s%s %lu.%6.6lu\n", + metric->prefix, metric->name, integral, decimals_micro); +} + +static void +metric_print_pop(struct metrics_metric *metric, struct evbuffer *buf, uint64_t value) { + metric_print(metric, buf, value); + metric_pop_label(metric); +} + +static void +metric_print_help(struct metrics_metric *metric, struct evbuffer *buf, const char *help) { evbuffer_add_printf(buf, "# HELP %s%s %s\n# TYPE %s%s %s\n", - prefix, name, help, prefix, name, type); + metric->prefix, metric->name, help, + metric->prefix, metric->name, metric->type); } static void -print_stat_block(struct evbuffer *buf, struct nsdst* st, - char *name) -{ +print_stat_block(struct evbuffer *buf, struct nsdst* st, struct metrics_metric *metric) { size_t i; const char* rcstr[] = {"NOERROR", "FORMERR", "SERVFAIL", "NXDOMAIN", @@ -400,141 +440,139 @@ print_stat_block(struct evbuffer *buf, s "BADVERS" }; - char prefix[512] = {0}; - if (name) { - snprintf(prefix, sizeof(prefix), "nsd_zonestats_%s_", name); - change_string_underscores(prefix); - } else { - snprintf(prefix, sizeof(prefix), "nsd_"); - } - /* nsd_queries_by_type_total */ - print_metric_help_and_type(buf, prefix, "queries_by_type_total", - "Total number of queries received by type.", - "counter"); + metric_set_name_and_type(metric, "queries_by_type_total", "counter"); + metric_print_help(metric, buf, "Total number of queries received by type."); for(i=0; i<= 255; i++) { if(metrics_inhibit_zero && st->qtype[i] == 0 && strncmp(rrtype_to_string(i), "TYPE", 4) == 0) continue; - evbuffer_add_printf(buf, "%squeries_by_type_total{type=\"%s\"} %lu\n", - prefix, rrtype_to_string(i), (unsigned long)st->qtype[i]); + metric_push_label(metric, "type", rrtype_to_string(i)); + metric_print_pop(metric, buf, (uint64_t)st->qtype[i]); } /* nsd_queries_by_class_total */ - print_metric_help_and_type(buf, prefix, "queries_by_class_total", - "Total number of queries received by class.", - "counter"); + metric_set_name_and_type(metric, "queries_by_class_total", "counter"); + metric_print_help(metric, buf, "Total number of queries received by class."); for(i=0; i<4; i++) { if(metrics_inhibit_zero && st->qclass[i] == 0 && i != CLASS_IN) continue; - evbuffer_add_printf(buf, "%squeries_by_class_total{class=\"%s\"} %lu\n", - prefix, rrclass_to_string(i), (unsigned long)st->qclass[i]); + metric_push_label(metric, "class", rrclass_to_string(i)); + metric_print_pop(metric, buf, (uint64_t)st->qclass[i]); } /* nsd_queries_by_opcode_total */ - print_metric_help_and_type(buf, prefix, "queries_by_opcode_total", - "Total number of queries received by opcode.", - "counter"); + metric_set_name_and_type(metric, "queries_by_opcode_total", "counter"); + metric_print_help(metric, buf, "Total number of queries received by opcode."); for(i=0; i<6; i++) { if(metrics_inhibit_zero && st->opcode[i] == 0 && i != OPCODE_QUERY) continue; - evbuffer_add_printf(buf, "%squeries_by_opcode_total{opcode=\"%s\"} %lu\n", - prefix, opcode2str(i), (unsigned long)st->opcode[i]); + metric_push_label(metric, "opcode", opcode2str(i)); + metric_print_pop(metric, buf, (uint64_t)st->opcode[i]); } /* nsd_queries_by_rcode_total */ - print_metric_help_and_type(buf, prefix, "queries_by_rcode_total", - "Total number of queries received by rcode.", - "counter"); + metric_set_name_and_type(metric, "queries_by_rcode_total", "counter"); + metric_print_help(metric, buf, "Total number of queries received by rcode."); for(i=0; i<17; i++) { if(metrics_inhibit_zero && st->rcode[i] == 0 && i > RCODE_YXDOMAIN) /*NSD does not use larger*/ continue; - evbuffer_add_printf(buf, "%squeries_by_rcode_total{rcode=\"%s\"} %lu\n", - prefix, rcstr[i], (unsigned long)st->rcode[i]); + metric_push_label(metric, "rcode", rcstr[i]); + metric_print_pop(metric, buf, (uint64_t)st->rcode[i]); } /* nsd_queries_by_transport_total */ - print_metric_help_and_type(buf, prefix, "queries_by_transport_total", - "Total number of queries received by transport.", - "counter"); - evbuffer_add_printf(buf, "%squeries_by_transport_total{transport=\"udp\"} %lu\n", prefix, (unsigned long)st->qudp); - evbuffer_add_printf(buf, "%squeries_by_transport_total{transport=\"udp6\"} %lu\n", prefix, (unsigned long)st->qudp6); + metric_set_name_and_type(metric, "queries_by_transport_total", "counter"); + metric_print_help(metric, buf, "Total number of queries received by transport."); + metric_push_label(metric, "transport", "udp"); + metric_print_pop(metric, buf, (uint64_t)st->qudp); + metric_push_label(metric, "transport", "udp6"); + metric_print_pop(metric, buf, (uint64_t)st->qudp6); /* nsd_queries_with_edns_total */ - print_metric_help_and_type(buf, prefix, "queries_with_edns_total", - "Total number of queries received with EDNS OPT.", - "counter"); - evbuffer_add_printf(buf, "%squeries_with_edns_total %lu\n", prefix, (unsigned long)st->edns); + metric_set_name_and_type(metric, "queries_with_edns_total", "counter"); + metric_print_help(metric, buf, "Total number of queries received with EDNS OPT."); + metric_print(metric, buf, (uint64_t)st->edns); /* nsd_queries_with_edns_failed_total */ - print_metric_help_and_type(buf, prefix, "queries_with_edns_failed_total", - "Total number of queries received with EDNS OPT where EDNS parsing failed.", - "counter"); - evbuffer_add_printf(buf, "%squeries_with_edns_failed_total %lu\n", prefix, (unsigned long)st->ednserr); + metric_set_name_and_type(metric, "queries_with_edns_failed_total", "counter"); + metric_print_help(metric, buf, "Total number of queries received with EDNS OPT where EDNS parsing failed."); + metric_print(metric, buf, (uint64_t)st->ednserr); /* nsd_connections_total */ - print_metric_help_and_type(buf, prefix, "connections_total", - "Total number of connections.", - "counter"); - evbuffer_add_printf(buf, "%sconnections_total{transport=\"tcp\"} %lu\n", prefix, (unsigned long)st->ctcp); - evbuffer_add_printf(buf, "%sconnections_total{transport=\"tcp6\"} %lu\n", prefix, (unsigned long)st->ctcp6); - evbuffer_add_printf(buf, "%sconnections_total{transport=\"tls\"} %lu\n", prefix, (unsigned long)st->ctls); - evbuffer_add_printf(buf, "%sconnections_total{transport=\"tls6\"} %lu\n", prefix, (unsigned long)st->ctls6); + metric_set_name_and_type(metric, "connections_total", "counter"); + metric_print_help(metric, buf, "Total number of connections."); + metric_push_label(metric, "transport", "tcp"); + metric_print_pop(metric, buf, (uint64_t)st->ctcp); + metric_push_label(metric, "transport", "tcp6"); + metric_print_pop(metric, buf, (uint64_t)st->ctcp6); + metric_push_label(metric, "transport", "tls"); + metric_print_pop(metric, buf, (uint64_t)st->ctls); + metric_push_label(metric, "transport", "tls6"); + metric_print_pop(metric, buf, (uint64_t)st->ctls6); /* nsd_xfr_requests_served_total */ - print_metric_help_and_type(buf, prefix, "xfr_requests_served_total", - "Total number of answered zone transfers.", - "counter"); - evbuffer_add_printf(buf, "%sxfr_requests_served_total{xfrtype=\"AXFR\"} %lu\n", prefix, (unsigned long)st->raxfr); - evbuffer_add_printf(buf, "%sxfr_requests_served_total{xfrtype=\"IXFR\"} %lu\n", prefix, (unsigned long)st->rixfr); + metric_set_name_and_type(metric, "xfr_requests_served_total", "counter"); + metric_print_help(metric, buf, "Total number of answered zone transfers."); + metric_push_label(metric, "xfrtype", "AXFR"); + metric_print_pop(metric, buf, (uint64_t)st->raxfr); + metric_push_label(metric, "xfrtype", "IXFR"); + metric_print_pop(metric, buf, (uint64_t)st->rixfr); /* nsd_queries_dropped_total */ - print_metric_help_and_type(buf, prefix, "queries_dropped_total", - "Total number of dropped queries.", - "counter"); - evbuffer_add_printf(buf, "%squeries_dropped_total %lu\n", prefix, (unsigned long)st->dropped); + metric_set_name_and_type(metric, "queries_dropped_total", "counter"); + metric_print_help(metric, buf, "Total number of dropped queries."); + metric_print(metric, buf, (uint64_t)st->dropped); /* nsd_queries_rx_failed_total */ - print_metric_help_and_type(buf, prefix, "queries_rx_failed_total", - "Total number of queries where receive failed.", - "counter"); - evbuffer_add_printf(buf, "%squeries_rx_failed_total %lu\n", prefix, (unsigned long)st->rxerr); + metric_set_name_and_type(metric, "queries_rx_failed_total", "counter"); + metric_print_help(metric, buf, "Total number of queries where receive failed."); + metric_print(metric, buf, (uint64_t)st->rxerr); /* nsd_answers_tx_failed_total */ - print_metric_help_and_type(buf, prefix, "answers_tx_failed_total", - "Total number of answers where transmit failed.", - "counter"); - evbuffer_add_printf(buf, "%sanswers_tx_failed_total %lu\n", prefix, (unsigned long)st->txerr); + metric_set_name_and_type(metric, "answers_tx_failed_total", "counter"); + metric_print_help(metric, buf, "Total number of answers where transmit failed."); + metric_print(metric, buf, (uint64_t)st->txerr); /* nsd_answers_without_aa_total */ - print_metric_help_and_type(buf, prefix, "answers_without_aa_total", - "Total number of NOERROR answers without AA flag set.", - "counter"); - evbuffer_add_printf(buf, "%sanswers_without_aa_total %lu\n", prefix, (unsigned long)st->nona); + metric_set_name_and_type(metric, "answers_without_aa_total", "counter"); + metric_print_help(metric, buf, "Total number of NOERROR answers without AA flag set."); + metric_print(metric, buf, (uint64_t)st->nona); /* nsd_answers_truncated_total */ - print_metric_help_and_type(buf, prefix, "answers_truncated_total", - "Total number of truncated answers.", - "counter"); - evbuffer_add_printf(buf, "%sanswers_truncated_total %lu\n", prefix, (unsigned long)st->truncated); + metric_set_name_and_type(metric, "answers_truncated_total", "counter"); + metric_print_help(metric, buf, "Total number of truncated answers."); + metric_print(metric, buf, (uint64_t)st->truncated); } #ifdef USE_ZONE_STATS + void metrics_zonestat_print_one(struct evbuffer *buf, char *name, struct nsdst *zst) { - char prefix[512] = {0}; - snprintf(prefix, sizeof(prefix), "nsd_zonestats_%s_", name); - change_string_underscores(prefix); - - print_metric_help_and_type(buf, prefix, "queries_total", - "Total number of queries received.", "counter"); - evbuffer_add_printf(buf, "%squeries_total %lu\n", prefix, - (unsigned long)(zst->qudp + zst->qudp6 + zst->ctcp + + char* name_valid; + struct metrics_metric metric; + metric_init_with_prefix(&metric, "nsd_zonestats_"); + + /* The zonestat name can contain characters like '"' that would break the + * label value; replace them. */ + name_valid = strdup(name); + if (!name_valid) { + log_msg(LOG_ERR, "malloc failure"); + return; + } + metrics_make_label_value_valid(name_valid); + metric_push_label(&metric, "zone", name_valid); + + metric_set_name_and_type(&metric, "queries_total", "counter"); + metric_print_help(&metric, buf, "Total number of queries received."); + metric_print(&metric, buf, + (uint64_t)(zst->qudp + zst->qudp6 + zst->ctcp + zst->ctcp6 + zst->ctls + zst->ctls6)); - print_stat_block(buf, zst, name); + print_stat_block(buf, zst, &metric); + free(name_valid); } #endif /*USE_ZONE_STATS*/ @@ -545,23 +583,28 @@ metrics_print_stats(struct evbuffer *buf { size_t i; struct timeval elapsed, uptime; + struct metrics_metric metric; + char server_str[16] = {0}; + + metric_init_with_prefix(&metric, "nsd_"); /* nsd_queries_total */ - print_metric_help_and_type(buf, "nsd_", "queries_total", - "Total number of queries received.", "counter"); + metric_set_name_and_type(&metric, "queries_total", "counter"); + metric_print_help(&metric, buf, "Total number of queries received."); /*per CPU and total*/ for(i=0; insd->child_count; i++) { - evbuffer_add_printf(buf, "nsd_queries_total{server=\"%d\"} %lu\n", - (int)i, (unsigned long)xfrd->nsd->children[i].query_count); + sprintf(server_str, "%d", (int)i); + metric_push_label(&metric, "server", server_str); + metric_print_pop(&metric, buf, (uint64_t)xfrd->nsd->children[i].query_count); } - print_stat_block(buf, st, NULL); + print_stat_block(buf, st, &metric); /* uptime (in seconds) */ timeval_subtract(&uptime, now, &xfrd->nsd->metrics->boot_time); - print_metric_help_and_type(buf, "nsd_", "time_up_seconds_total", - "Uptime since server boot in seconds.", "counter"); - evbuffer_add_printf(buf, "nsd_time_up_seconds_total %lu.%6.6lu\n", + metric_set_name_and_type(&metric, "time_up_seconds_total", "counter"); + metric_print_help(&metric, buf, "Uptime since server boot in seconds."); + metric_print_micros(&metric, buf, (unsigned long)uptime.tv_sec, (unsigned long)uptime.tv_usec); /* time elapsed since last nsd-control stats reset (in seconds) */ @@ -572,48 +615,43 @@ metrics_print_stats(struct evbuffer *buf } else { timeval_subtract(&elapsed, now, &xfrd->nsd->metrics->stats_time); } - print_metric_help_and_type(buf, "nsd_", "time_elapsed_seconds", - "Time since last statistics printout and " - "reset (by nsd-control stats) in seconds.", - "untyped"); - evbuffer_add_printf(buf, "nsd_time_elapsed_seconds %lu.%6.6lu\n", + metric_set_name_and_type(&metric, "time_elapsed_seconds", "untyped"); + metric_print_help(&metric, buf, + "Time since last statistics printout and " + "reset (by nsd-control stats) in seconds."); + metric_print_micros(&metric, buf, (unsigned long)elapsed.tv_sec, (unsigned long)elapsed.tv_usec); /*mem info, database on disksize*/ - print_metric_help_and_type(buf, "nsd_", "size_db_on_disk_bytes", - "Size of DNS database on disk.", "gauge"); - print_longnum(buf, "nsd_size_db_on_disk_bytes ", st->db_disk); - - print_metric_help_and_type(buf, "nsd_", "size_db_in_mem_bytes", - "Size of DNS database in memory.", "gauge"); - print_longnum(buf, "nsd_size_db_in_mem_bytes ", st->db_mem); - - print_metric_help_and_type(buf, "nsd_", "size_xfrd_in_mem_bytes", - "Size of zone transfers and notifies in xfrd process, excluding TSIG data.", - "gauge"); - print_longnum(buf, "nsd_size_xfrd_in_mem_bytes ", region_get_mem(xfrd->region)); - - print_metric_help_and_type(buf, "nsd_", "size_config_on_disk_bytes", - "Size of zonelist file on disk, excluding nsd.conf.", - "gauge"); - print_longnum(buf, "nsd_size_config_on_disk_bytes ", - xfrd->nsd->options->zonelist_off); - - print_metric_help_and_type(buf, "nsd_", "size_config_in_mem_bytes", - "Size of config data in memory.", "gauge"); - print_longnum(buf, "nsd_size_config_in_mem_bytes ", region_get_mem( - xfrd->nsd->options->region)); + metric_set_name_and_type(&metric, "size_db_on_disk_bytes", "gauge"); + metric_print_help(&metric, buf, "Size of DNS database on disk."); + metric_print(&metric, buf, st->db_disk); + + metric_set_name_and_type(&metric, "size_db_in_mem_bytes", "gauge"); + metric_print_help(&metric, buf, "Size of DNS database in memory."); + metric_print(&metric, buf, st->db_mem); + + metric_set_name_and_type(&metric, "size_xfrd_in_mem_bytes", "gauge"); + metric_print_help(&metric, buf, "Size of zone transfers and notifies in xfrd process, excluding TSIG data."); + metric_print(&metric, buf, region_get_mem(xfrd->region)); + + metric_set_name_and_type(&metric, "size_config_on_disk_bytes", "gauge"); + metric_print_help(&metric, buf, "Size of zonelist file on disk, excluding nsd.conf."); + metric_print(&metric, buf, xfrd->nsd->options->zonelist_off); + + metric_set_name_and_type(&metric, "size_config_in_mem_bytes", "gauge"); + metric_print_help(&metric, buf, "Size of config data in memory."); + metric_print(&metric, buf, region_get_mem(xfrd->nsd->options->region)); /* number of zones serverd */ - print_metric_help_and_type(buf, "nsd_", "zones_primary", - "Number of primary zones served.", "gauge"); - evbuffer_add_printf(buf, "nsd_zones_primary %lu\n", - (unsigned long)(xfrd->notify_zones->count - xfrd->zones->count)); - - print_metric_help_and_type(buf, "nsd_", "zones_secondary", - "Number of secondary zones served.", "gauge"); - evbuffer_add_printf(buf, "nsd_zones_secondary %lu\n", - (unsigned long)xfrd->zones->count); + metric_set_name_and_type(&metric, "zones_primary", "gauge"); + metric_print_help(&metric, buf, "Number of primary zones served."); + metric_print(&metric, buf, + (uint64_t)(xfrd->notify_zones->count - xfrd->zones->count)); + + metric_set_name_and_type(&metric, "zones_secondary", "gauge"); + metric_print_help(&metric, buf, "Number of secondary zones served."); + metric_print(&metric, buf, (uint64_t)xfrd->zones->count); #ifdef USE_ZONE_STATS zonestat_print(NULL, buf, xfrd, clear, zonestats); /*per-zone statistics*/ Index: usr.sbin/nsd/metrics.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/metrics.h,v diff -u -p -r1.1.1.1 metrics.h --- usr.sbin/nsd/metrics.h 6 Sep 2025 17:38:33 -0000 1.1.1.1 +++ usr.sbin/nsd/metrics.h 21 Sep 2026 16:28:42 -0000 @@ -60,6 +60,7 @@ int daemon_metrics_open_ports(struct dae void daemon_metrics_attach(struct daemon_metrics* m, struct xfrd_state* xfrd); #ifdef BIND8_STATS + /** * Print stats as prometheus metrics to HTTP buffer * @param buf: the HTTP buffer to write to @@ -77,6 +78,35 @@ void metrics_print_stats(struct evbuffer struct timeval *rc_stats_time); #ifdef USE_ZONE_STATS + +/** + * Replace characters disallowed in Prometheus label values with '_'. + * + * According to [1], label values can be any UTF-8 characters, but backslash, + * double-quote, and line feed must be escaped. We could escape them but that + * changes the length of the string, and in practice for zonestats names you + * don't need these characters anyway so we just replace them. + * [1]: https://prometheus.io/docs/instrumenting/exposition_formats/#comments-help-text-and-type-information> + * + * @param value: the label value to edit. + * @return 1 if any changes were needed, 0 if the value was already valid. + */ +static inline int metrics_make_label_value_valid(char* value) { + int made_changes = 0; + char* s = value; + while(*s) { + switch (*s) { + case '\\': + case '"': + case '\n': + *s = '_'; + made_changes = 1; + } + s++; + } + return made_changes; +} + /** * Print zonestat metrics for a single zonestats object * @param buf: the HTTP buffer to write to Index: usr.sbin/nsd/namedb.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/namedb.c,v diff -u -p -r1.17 namedb.c --- usr.sbin/nsd/namedb.c 21 Mar 2026 21:36:36 -0000 1.17 +++ usr.sbin/nsd/namedb.c 21 Sep 2026 16:28:42 -0000 @@ -226,20 +226,36 @@ do_deldomain(namedb_type* db, domain_typ /* see if nsec3-nodes are used */ if(domain->nsec3) { - if(domain->nsec3->nsec3_node.key) - zone_del_domain_in_hash_tree(nsec3_tree_zone(db, domain) - ->nsec3tree, &domain->nsec3->nsec3_node); + if(domain->nsec3->nsec3_node.key) { + zone_type* nsec3zone = nsec3_tree_zone(db, domain); + if(nsec3zone) + zone_del_domain_in_hash_tree( + nsec3zone->nsec3tree, + &domain->nsec3->nsec3_node); + } if(domain->nsec3->hash_wc) { - if(domain->nsec3->hash_wc->hash.node.key) - zone_del_domain_in_hash_tree(nsec3_tree_zone(db, domain) - ->hashtree, &domain->nsec3->hash_wc->hash.node); - if(domain->nsec3->hash_wc->wc.node.key) - zone_del_domain_in_hash_tree(nsec3_tree_zone(db, domain) - ->wchashtree, &domain->nsec3->hash_wc->wc.node); + if(domain->nsec3->hash_wc->hash.node.key) { + zone_type* hzone = nsec3_tree_zone(db, domain); + if(hzone) + zone_del_domain_in_hash_tree( + hzone->hashtree, + &domain->nsec3->hash_wc->hash.node); + } + if(domain->nsec3->hash_wc->wc.node.key) { + zone_type* wczone = nsec3_tree_zone(db, domain); + if(wczone) + zone_del_domain_in_hash_tree( + wczone->wchashtree, + &domain->nsec3->hash_wc->wc.node); + } + } + if(domain->nsec3->ds_parent_hash && domain->nsec3->ds_parent_hash->node.key) { + zone_type* dszone = nsec3_tree_dszone(db, domain); + if(dszone) + zone_del_domain_in_hash_tree( + dszone->dshashtree, + &domain->nsec3->ds_parent_hash->node); } - if(domain->nsec3->ds_parent_hash && domain->nsec3->ds_parent_hash->node.key) - zone_del_domain_in_hash_tree(nsec3_tree_dszone(db, domain) - ->dshashtree, &domain->nsec3->ds_parent_hash->node); if(domain->nsec3->hash_wc) { region_recycle(db->domains->region, domain->nsec3->hash_wc, @@ -304,7 +320,10 @@ void zone_add_domain_in_hash_tree(region return; memset(node, 0, sizeof(rbnode_type)); node->key = domain; - rbtree_insert(*tree, node); + if(!rbtree_insert(*tree, node)) { + /* collision: clear key to prevent null content key in node. */ + node->key = NULL; + } } domain_table_type * Index: usr.sbin/nsd/nsd-checkconf.8.in =================================================================== RCS file: /cvs/src/usr.sbin/nsd/nsd-checkconf.8.in,v diff -u -p -r1.46 nsd-checkconf.8.in --- usr.sbin/nsd/nsd-checkconf.8.in 21 Mar 2026 21:36:36 -0000 1.46 +++ usr.sbin/nsd/nsd-checkconf.8.in 21 Sep 2026 16:28:42 -0000 @@ -1,4 +1,4 @@ -.TH "nsd\-checkconf" "8" "Mar 19, 2026" "NLnet Labs" "nsd 4.14.2" +.TH "nsd\-checkconf" "8" "sep 2, 2026" "NLnet Labs" "nsd 4.15.2" .\" Copyright (c) 2001\-2024, NLnet Labs. All rights reserved. .\" See LICENSE for the license. .SH "NAME" Index: usr.sbin/nsd/nsd-checkconf.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/nsd-checkconf.c,v diff -u -p -r1.39 nsd-checkconf.c --- usr.sbin/nsd/nsd-checkconf.c 6 Sep 2025 17:41:37 -0000 1.39 +++ usr.sbin/nsd/nsd-checkconf.c 21 Sep 2026 16:28:42 -0000 @@ -512,11 +512,17 @@ config_print_zone(nsd_options_type* opt, return; } if(strcasecmp(o, "proxy_protocol_port") == 0) { - struct proxy_protocol_port_list* p; + struct port_list* p; for(p = opt->proxy_protocol_port; p; p = p->next) printf("%d\n", p->port); return; } + if(strcasecmp(o, "udp_padding_port") == 0) { + struct port_list* p; + for(p = opt->udp_padding_port; p; p = p->next) + printf("%d\n", p->port); + return; + } printf("Server option not handled: %s\n", o); exit(1); } @@ -735,9 +741,14 @@ config_test_print_server(nsd_options_typ print_string_var("cookie-secret-file:", ""); } if(opt->proxy_protocol_port) { - struct proxy_protocol_port_list* p; + struct port_list* p; for(p = opt->proxy_protocol_port; p; p = p->next) printf("\tproxy-protocol-port: %d\n", p->port); + } + if(opt->udp_padding_port) { + struct port_list* p; + for(p = opt->udp_padding_port; p; p = p->next) + printf("\tudp-padding-port: %d\n", p->port); } #ifdef USE_METRICS Index: usr.sbin/nsd/nsd-checkzone.8.in =================================================================== RCS file: /cvs/src/usr.sbin/nsd/nsd-checkzone.8.in,v diff -u -p -r1.30 nsd-checkzone.8.in --- usr.sbin/nsd/nsd-checkzone.8.in 21 Mar 2026 21:36:36 -0000 1.30 +++ usr.sbin/nsd/nsd-checkzone.8.in 21 Sep 2026 16:28:42 -0000 @@ -1,4 +1,4 @@ -.TH "nsd\-checkzone" "8" "Mar 19, 2026" "NLnet Labs" "nsd 4.14.2" +.TH "nsd\-checkzone" "8" "sep 2, 2026" "NLnet Labs" "nsd 4.15.2" .\" Copyright (c) 2014-2024, NLnet Labs. All rights reserved. .\" See LICENSE for the license. .SH "NAME" Index: usr.sbin/nsd/nsd-control.8.in =================================================================== RCS file: /cvs/src/usr.sbin/nsd/nsd-control.8.in,v diff -u -p -r1.34 nsd-control.8.in --- usr.sbin/nsd/nsd-control.8.in 21 Mar 2026 21:36:36 -0000 1.34 +++ usr.sbin/nsd/nsd-control.8.in 21 Sep 2026 16:28:42 -0000 @@ -1,4 +1,4 @@ -.TH "nsd\-control" "8" "Mar 19, 2026" "NLnet Labs" "nsd 4.14.2" +.TH "nsd\-control" "8" "sep 2, 2026" "NLnet Labs" "nsd 4.15.2" .\" Copyright (c) 2011-2024, NLnet Labs. All rights reserved. .\" See LICENSE for the license. .SH "NAME" Index: usr.sbin/nsd/nsd.8.in =================================================================== RCS file: /cvs/src/usr.sbin/nsd/nsd.8.in,v diff -u -p -r1.48 nsd.8.in --- usr.sbin/nsd/nsd.8.in 21 Mar 2026 21:36:36 -0000 1.48 +++ usr.sbin/nsd/nsd.8.in 21 Sep 2026 16:28:42 -0000 @@ -1,9 +1,9 @@ -.TH "NSD" "8" "Mar 19, 2026" "NLnet Labs" "NSD 4.14.2" +.TH "NSD" "8" "sep 2, 2026" "NLnet Labs" "NSD 4.15.2" .\" Copyright (c) 2001\-2024, NLnet Labs. All rights reserved. .\" See LICENSE for the license. .SH "NAME" .B nsd -\- Name Server Daemon (NSD) version 4.14.2. +\- Name Server Daemon (NSD) version 4.15.2. .SH "SYNOPSIS" .B nsd .RB [ \-4 ] Index: usr.sbin/nsd/nsd.conf.5.in =================================================================== RCS file: /cvs/src/usr.sbin/nsd/nsd.conf.5.in,v diff -u -p -r1.54 nsd.conf.5.in --- usr.sbin/nsd/nsd.conf.5.in 21 Mar 2026 21:36:36 -0000 1.54 +++ usr.sbin/nsd/nsd.conf.5.in 21 Sep 2026 16:28:42 -0000 @@ -1,4 +1,4 @@ -.TH "nsd.conf" "5" "Mar 19, 2026" "NLnet Labs" "nsd 4.14.2" +.TH "nsd.conf" "5" "sep 2, 2026" "NLnet Labs" "nsd 4.15.2" .\" Copyright (c) 2001\-2024, NLnet Labs. All rights reserved. .\" See LICENSE for the license. .SH "NAME" @@ -632,6 +632,18 @@ times, additional port numbers can be us interface definitions that use this port number expect PROXYv2 proxy protocol traffic, for UDP, TCP and for TLS service. .TP +.B allow\-proxy:\fR +The allowed proxy senders, that can send PROXYv2 traffic. Without an +allow\-proxy option any IP address is allowed. It can be given multiple times +to allow multiple netblocks, or with /32 or /128 specific addresses can be +listed. +.TP +.B udp\-padding\-port:\fR +UDP requests received over this port containing an EDNS0 padding option will, +unlike ordinary UDP requests, be answered with a padded response. The option +may be given more than once. +Listening to the port needs to be configured separately with a \fBip\-address\fR or \fBinterface\fR option. +.TP .B xdp\-interface:\fR The interface to use XDP with. This enables the use of AF_XDP sockets for UDP queries. Default is "", disabled. (EXPERIMENTAL) @@ -690,14 +702,21 @@ can help with drivers with broken AF_XDP .TP .B metrics\-enable:\fR Enable the prometheus metrics HTTP endpoint. It exposes the same statistics as -the \fInsd\-control\fR(8) stats_noreset command, but with metric names +the \fInsd\-control stats_noreset\fR command, but with metric names following the prometheus specification. (Requires libevent2) -To generate per zone metrics, specify the \fBzonestats\fR option on the desired -zones. - -Beware, that when using \fInsd\-control\fR(8) stats (instead of stats_noreset), -the statistics will be reset for the HTTP metrics endpoint as well. +To generate metrics per zone (or more accurately, per zonestats group), +specify the \fBzonestats\fR option on the desired zones. This will expose the +zonestats metrics with the zonestats name as a label called "zone", for +example with \fBzonestats: examplezone\fR: +.sp +.nf + nsd_zonestats_queries_total{zone="examplezone"} +.fi +.sp +Beware, that when using \fInsd\-control stats\fR (instead of \fInsd\-control +stats_noreset\fR), the statistics will be reset for the HTTP metrics endpoint +as well. .TP .B metrics\-interface:\fR NSD will bind to the listed addresses or interfaces to serve the prometheus @@ -1035,7 +1054,7 @@ SAN (Subject Alternative Name) DNS entry .BR auth-domain-name of the defined .BR tls-auth . -The certificate validify is also verified with +The certificate validity is also verified with .BR tls-cert-bundle . If authentication of the secondary, based on the specified tls-auth authentication information, fails the XFR zone transfer will be refused. If the connection is performed Index: usr.sbin/nsd/nsd.conf.sample.in =================================================================== RCS file: /cvs/src/usr.sbin/nsd/nsd.conf.sample.in,v diff -u -p -r1.27 nsd.conf.sample.in --- usr.sbin/nsd/nsd.conf.sample.in 21 Mar 2026 21:36:36 -0000 1.27 +++ usr.sbin/nsd/nsd.conf.sample.in 21 Sep 2026 16:28:42 -0000 @@ -287,6 +287,10 @@ server: # expect PROXYv2. For UDP and TCP/TLS interfaces. # proxy-protocol-port: portno for each of the port numbers. + # Allowed proxy senders. Without an allow-proxy option, any IP address + # is allowed. This is the outer, proxy source address. + # allow-proxy: 192.0.2.0/24 + # The interface to use XDP with. Default is "", disabled. # xdp-interface: eth0 Index: usr.sbin/nsd/nsec3.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/nsec3.c,v diff -u -p -r1.30 nsec3.c --- usr.sbin/nsd/nsec3.c 21 Mar 2026 21:36:36 -0000 1.30 +++ usr.sbin/nsd/nsec3.c 21 Sep 2026 16:28:42 -0000 @@ -70,9 +70,11 @@ cmp_nsec3_tree(const void* x, const void const domain_type* a = (const domain_type*)x; const domain_type* b = (const domain_type*)y; /* labelcount + 32long label */ - assert(dname_name(domain_dname_const(a))[0] == 32); - assert(dname_name(domain_dname_const(b))[0] == 32); - return memcmp(dname_name(domain_dname_const(a)), dname_name(domain_dname_const(b)), 33); + assert(dname_name(domain_dname_const(a))[0] == NSEC3_OWNER_LABEL_LEN); + assert(dname_name(domain_dname_const(b))[0] == NSEC3_OWNER_LABEL_LEN); + return memcmp( dname_name(domain_dname_const(a)) + , dname_name(domain_dname_const(b)) + , NSEC3_OWNER_LABEL_LEN + 1); } void nsec3_zone_trees_create(struct region* region, zone_type* zone) @@ -123,6 +125,7 @@ nsec3_hash_and_store(zone_type* zone, co detect_nsec3_params(zone->nsec3_param, &nsec3_salt, &nsec3_saltlength, &nsec3_iterations); assert(nsec3_iterations >= 0 && nsec3_iterations <= 65536); + assert(dname); iterated_hash((unsigned char*)store, nsec3_salt, nsec3_saltlength, dname_name(dname), dname->name_size, nsec3_iterations); } @@ -144,9 +147,11 @@ nsec3_lookup_hash_and_wc(region_type* re domain->nsec3->hash_wc->hash.node.key = NULL; domain->nsec3->hash_wc->wc.node.key = NULL; nsec3_hash_and_store(zone, dname, domain->nsec3->hash_wc->hash.hash); - wcard = dname_parse(tmpregion, "*"); - wcard = dname_concatenate(tmpregion, wcard, dname); - nsec3_hash_and_store(zone, wcard, domain->nsec3->hash_wc->wc.hash); + if(dname->name_size + 2 <= MAXDOMAINLEN) { + wcard = dname_parse(tmpregion, "*"); + wcard = dname_concatenate(tmpregion, wcard, dname); + nsec3_hash_and_store(zone, wcard, domain->nsec3->hash_wc->wc.hash); + } } static void @@ -201,6 +206,23 @@ check_apex_soa(namedb_type* namedb, zone nsec3_hash_and_store(zone, dname, h); tmpregion = region_create(xalloc, free); hashed_apex = nsec3_b32_create(tmpregion, zone, h); + if(!hashed_apex) { + if(!nolog) { + if((int)domain_dname(zone->apex)->name_size >= 223) { + log_msg( LOG_ERR + , "apex %s too long for NSEC3 hash label" + , dname_to_string( + domain_dname(zone->apex), NULL)); + } else { + log_msg( LOG_ERR + , "cannot create NSEC3 hash label at %s" + , dname_to_string( + domain_dname(zone->apex), NULL)); + } + } + region_destroy(tmpregion); + return NULL; + } domain = domain_table_find(namedb->domains, hashed_apex); if(!domain) { if(!nolog) { @@ -224,13 +246,14 @@ check_apex_soa(namedb_type* namedb, zone return NULL; } for(j=0; jrr_count; j++) { - if(nsec3_has_soa(nsec3_rrset->rrs[j])) { + if(nsec3_has_soa(nsec3_rrset->rrs[j]) && + nsec3_rr_uses_params(nsec3_rrset->rrs[j], zone)) { region_destroy(tmpregion); return nsec3_rrset->rrs[j]; } } if(!nolog) { - log_msg(LOG_ERR, "%s NSEC3PARAM entry: hash(apex) NSEC3 has no SOA flag.", + log_msg(LOG_ERR, "%s NSEC3PARAM entry: hash(apex) NSEC3 has no SOA flag or different params.", domain_to_string(zone->apex)); log_msg(LOG_ERR, "hash(apex)= %s", dname_to_string(hashed_apex, NULL)); @@ -322,12 +345,89 @@ nsec3_rdata_params_ok(const rr_type *prr (memcmp(prr->rdata+2, rr->rdata+2, prr->rdlength-2) == 0); } + +/* Copied verbatim from simdzone/src/generic/base32.h */ +static const uint8_t b32rmap[256] = { + 0xfd, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 0 - 7 */ + 0xff, 0xfe, 0xfe, 0xfe, 0xfe, 0xfe, 0xff, 0xff, /* 8 - 15 */ + 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 16 - 23 */ + 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 24 - 31 */ + 0xfe, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 32 - 39 */ + 0xff, 0xff, 0xff, 0x3e, 0xff, 0xff, 0xff, 0x3f, /* 40 - 47 */ + 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, /* 48 - 55 */ + 0x08, 0x09, 0xff, 0xff, 0xff, 0xfd, 0xff, 0xff, /* 56 - 63 */ + 0xff, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x10, /* 64 - 71 */ + 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17, 0x18, /* 72 - 79 */ + 0x19, 0x1a, 0x1b, 0x1c, 0x1d, 0x1e, 0x1f, 0xff, /* 80 - 87 */ + 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 88 - 95 */ + 0xff, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x10, /* 96 - 103 */ + 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17, 0x18, /* 104 - 111 */ + 0x19, 0x1a, 0x1b, 0x1c, 0x1d, 0x1e, 0x1f, 0xff, /* 112 - 119 */ + 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 120 - 127 */ + 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 128 - 135 */ + 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 136 - 143 */ + 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 144 - 151 */ + 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 152 - 159 */ + 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 160 - 167 */ + 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 168 - 175 */ + 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 176 - 183 */ + 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 184 - 191 */ + 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 192 - 199 */ + 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 200 - 207 */ + 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 208 - 215 */ + 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 216 - 223 */ + 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 224 - 231 */ + 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 232 - 239 */ + 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 240 - 247 */ + 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, /* 248 - 255 */ +}; + + int nsec3_rr_uses_params(rr_type* rr, zone_type* zone) { + /* TODO: Test validness with base32hex parser from simdzone */ + const uint8_t* wire; + if(!rr || rr->rdlength < 6) return 0; - return nsec3_rdata_params_ok(zone->nsec3_param, rr); + wire = dname_name(domain_dname_const(rr->owner)); + if(wire[0] == NSEC3_OWNER_LABEL_LEN + && b32rmap[wire[ 1]] < 32 && b32rmap[wire[ 2]] < 32 + && b32rmap[wire[ 3]] < 32 && b32rmap[wire[ 4]] < 32 + && b32rmap[wire[ 5]] < 32 && b32rmap[wire[ 6]] < 32 + && b32rmap[wire[ 7]] < 32 && b32rmap[wire[ 8]] < 32 + && b32rmap[wire[ 9]] < 32 && b32rmap[wire[10]] < 32 + && b32rmap[wire[11]] < 32 && b32rmap[wire[12]] < 32 + && b32rmap[wire[13]] < 32 && b32rmap[wire[14]] < 32 + && b32rmap[wire[15]] < 32 && b32rmap[wire[16]] < 32 + && b32rmap[wire[17]] < 32 && b32rmap[wire[18]] < 32 + && b32rmap[wire[19]] < 32 && b32rmap[wire[20]] < 32 + && b32rmap[wire[21]] < 32 && b32rmap[wire[22]] < 32 + && b32rmap[wire[23]] < 32 && b32rmap[wire[24]] < 32 + && b32rmap[wire[25]] < 32 && b32rmap[wire[26]] < 32 + && b32rmap[wire[27]] < 32 && b32rmap[wire[28]] < 32 + && b32rmap[wire[29]] < 32 && b32rmap[wire[30]] < 32 + && b32rmap[wire[31]] < 32 && b32rmap[wire[32]] < 32) + return nsec3_rdata_params_ok(zone->nsec3_param, rr); + return 0; +} + +int +nsec3_has_owner_for_zone(domain_type* domain, zone_type* zone) +{ + if(dname_name(domain_dname_const(domain))[0] != NSEC3_OWNER_LABEL_LEN) + return 0; /* not b32.name */ + if(!(((size_t)domain_dname(domain)->label_count) == + ((size_t)domain_dname(zone->apex)->label_count)+1 && + ((size_t)domain_dname(domain)->name_size) == + ((size_t)domain_dname(zone->apex)->name_size) + + NSEC3_OWNER_LABEL_LEN+1 && + memcmp(dname_name(domain_dname_const(domain))+ + NSEC3_OWNER_LABEL_LEN+1, dname_name(domain_dname_const( + zone->apex)), domain_dname(zone->apex)->name_size) == 0)) + return 0; /* not b32.zonename */ + return 1; } int @@ -338,6 +438,8 @@ nsec3_in_chain_count(domain_type* domain int count = 0; if(!rrset || !zone->nsec3_param) return 0; /* no NSEC3s, none in the chain */ + if(!nsec3_has_owner_for_zone(domain, zone)) + return 0; /* wrong owner name */ for(i=0; irr_count; i++) { if(nsec3_rr_uses_params(rrset->rrs[i], zone)) count++; @@ -387,6 +489,89 @@ hash_tree_clear(rbtree_type* tree) tree->root = RBTREE_NULL; } +/* Clear nsec3 precompile for walked to domain */ +static void +nsec3_clear_precompile_walk(struct namedb* db, zone_type* zone, + domain_type* walk) +{ + if(walk->nsec3) { + if(nsec3_condition_hash(walk, zone)) { + walk->nsec3->nsec3_node.key = NULL; + walk->nsec3->nsec3_cover = NULL; + walk->nsec3->nsec3_wcard_child_cover = NULL; + walk->nsec3->nsec3_is_exact = 0; + if (walk->nsec3->hash_wc) { + region_recycle(db->domains->region, + walk->nsec3->hash_wc, + sizeof(nsec3_hash_wc_node_type)); + walk->nsec3->hash_wc = NULL; + } + } + if(nsec3_condition_dshash(walk, zone)) { + walk->nsec3->nsec3_ds_parent_cover = NULL; + walk->nsec3->nsec3_ds_parent_is_exact = 0; + if (walk->nsec3->ds_parent_hash) { + region_recycle(db->domains->region, + walk->nsec3->ds_parent_hash, + sizeof(nsec3_hash_node_type)); + walk->nsec3->ds_parent_hash = NULL; + } + } + } +} + +/* Find the zone above apex (that is the apex of a zone), NULL if none. */ +static struct zone* +find_superzone_of(struct namedb* db, const dname_type* apex) +{ + struct domain* apex_domain = domain_table_find(db->domains, apex); + if(apex_domain && apex_domain->parent) + return domain_find_zone(db, apex_domain->parent); + return NULL; +} + +void +nsec3_superzone_clear_for_apex(struct namedb* db, const dname_type* apex) +{ + domain_type* apex_domain, *walk; + struct zone* zone; /* the super zone of apex */ + zone = find_superzone_of(db, apex); + if(!zone) return; /* no super zone above the apex */ + if(!zone->nsec3_param) return; /* super is not an NSEC3 zone */ + + apex_domain = domain_table_find(db->domains, apex); + if(!domain_is_subdomain(apex_domain, zone->apex)) + return; /* robustness check */ + walk = apex_domain; + while(walk && domain_is_subdomain(walk, apex_domain)) { + if(walk->nsec3) { + if(nsec3_condition_hash(walk, zone)) { + zone_del_domain_in_hash_tree(zone->nsec3tree, + &walk->nsec3->nsec3_node); + if(walk->nsec3->hash_wc) { + zone_del_domain_in_hash_tree( + zone->hashtree, + &walk->nsec3->hash_wc->hash.node); + zone_del_domain_in_hash_tree( + zone->wchashtree, + &walk->nsec3->hash_wc->wc.node); + } + } + if(nsec3_condition_dshash(walk, zone)) { + if(walk->nsec3->ds_parent_hash) { + zone_del_domain_in_hash_tree(zone->dshashtree, + &walk->nsec3->ds_parent_hash->node); + } + } + } + nsec3_clear_precompile_walk(db, zone, walk); + walk = domain_next(walk); + } + /* clear nsec3_last if that was cleared */ + zone->nsec3_last = ((zone->nsec3tree && rbtree_last(zone->nsec3tree) != RBTREE_NULL)? + (domain_type*)rbtree_last(zone->nsec3tree)->key:NULL); +} + void nsec3_clear_precompile(struct namedb* db, zone_type* zone) { @@ -403,30 +588,7 @@ nsec3_clear_precompile(struct namedb* db /* wipe precompile */ walk = zone->apex; while(walk && domain_is_subdomain(walk, zone->apex)) { - if(walk->nsec3) { - if(nsec3_condition_hash(walk, zone)) { - walk->nsec3->nsec3_node.key = NULL; - walk->nsec3->nsec3_cover = NULL; - walk->nsec3->nsec3_wcard_child_cover = NULL; - walk->nsec3->nsec3_is_exact = 0; - if (walk->nsec3->hash_wc) { - region_recycle(db->domains->region, - walk->nsec3->hash_wc, - sizeof(nsec3_hash_wc_node_type)); - walk->nsec3->hash_wc = NULL; - } - } - if(nsec3_condition_dshash(walk, zone)) { - walk->nsec3->nsec3_ds_parent_cover = NULL; - walk->nsec3->nsec3_ds_parent_is_exact = 0; - if (walk->nsec3->ds_parent_hash) { - region_recycle(db->domains->region, - walk->nsec3->ds_parent_hash, - sizeof(nsec3_hash_node_type)); - walk->nsec3->ds_parent_hash = NULL; - } - } - } + nsec3_clear_precompile_walk(db, zone, walk); walk = domain_next(walk); } zone->nsec3_last = NULL; @@ -559,8 +721,6 @@ nsec3_precompile_domain(struct namedb* d /* add into tree */ zone_add_domain_in_hash_tree(db->region, &zone->hashtree, cmp_hash_tree, domain, &domain->nsec3->hash_wc->hash.node); - zone_add_domain_in_hash_tree(db->region, &zone->wchashtree, - cmp_wchash_tree, domain, &domain->nsec3->hash_wc->wc.node); /* lookup in tree cover ptr (or exact) */ exact = nsec3_find_cover(zone, domain->nsec3->hash_wc->hash.hash, @@ -570,10 +730,23 @@ nsec3_precompile_domain(struct namedb* d domain->nsec3->nsec3_is_exact = 1; else domain->nsec3->nsec3_is_exact = 0; - /* find cover for *.domain for wildcard denial */ - (void)nsec3_find_cover(zone, domain->nsec3->hash_wc->wc.hash, - sizeof(domain->nsec3->hash_wc->wc.hash), &result); - domain->nsec3->nsec3_wcard_child_cover = result; + /* If the wildcard (*.domain) fits within MAXDOMAINLEN, then add it to + * the wildcard hashtree and find the cover for it. Note that, in this + * case, its hash value has been computed (nsec3_lookup_hash_and_wc()). + */ + if(domain_dname(domain)->name_size + 2 <= MAXDOMAINLEN) { + zone_add_domain_in_hash_tree(db->region, &zone->wchashtree, + cmp_wchash_tree, domain, &domain->nsec3->hash_wc->wc.node); + (void)nsec3_find_cover(zone, domain->nsec3->hash_wc->wc.hash, + sizeof(domain->nsec3->hash_wc->wc.hash), &result); + domain->nsec3->nsec3_wcard_child_cover = result; + } else { + /* Setting to NULL is safe, because nsec3_add_rrset() is the + * only usage of nsec3_wcard_child_cover, and simply doesn't + * try to add anythin if it is NULL + */ + domain->nsec3->nsec3_wcard_child_cover = NULL; + } } void @@ -597,20 +770,43 @@ nsec3_precompile_domain_ds(struct namedb cmp_dshash_tree, domain, &domain->nsec3->ds_parent_hash->node); } -static void -parse_nsec3_name(const dname_type* dname, uint8_t* hash, size_t buflen) +static inline int +b32hex_p8ton5(const uint8_t* p, uint8_t* n) +{ + uint8_t ofs; + if((ofs = b32rmap[p[0]]) > 31) return 0; + n[0] = (uint8_t)(ofs << 3); + if((ofs = b32rmap[p[1]]) > 31) return 0; + n[0] |= (uint8_t)(ofs >> 2); + n[1] = (uint8_t)(ofs << 6); + if((ofs = b32rmap[p[2]]) > 31) return 0; + n[1] |= (uint8_t)(ofs << 1); + if((ofs = b32rmap[p[3]]) > 31) return 0; + n[1] |= (uint8_t)(ofs >> 4); + n[2] = (uint8_t)(ofs << 4); + if((ofs = b32rmap[p[4]]) > 31) return 0; + n[2] |= (uint8_t)(ofs >> 1); + n[3] = (uint8_t)(ofs << 7); + if((ofs = b32rmap[p[5]]) > 31) return 0; + n[3] |= (uint8_t)(ofs << 2); + if((ofs = b32rmap[p[6]]) > 31) return 0; + n[3] |= (uint8_t)(ofs >> 3); + n[4] = (uint8_t)(ofs << 5); + if((ofs = b32rmap[p[7]]) > 31) return 0; + n[4] |= ofs; + return 1; +} + +static int +parse_nsec3_name(const dname_type* dname, uint8_t* hash) { - /* first label must be the match, */ - size_t lablen = (buflen-1) * 8 / 5; + /* TODO: Do this with base32hex parser from simdzone */ const uint8_t* wire = dname_name(dname); - assert(lablen == 32 && buflen == NSEC3_HASH_LEN+1); - /* labels of length 32 for SHA1, and must have space+1 for convert */ - if(wire[0] != lablen) { - /* not NSEC3 */ - memset(hash, 0, buflen); - return; - } - (void)b32_pton((char*)wire+1, hash, buflen); + return wire[0] == NSEC3_OWNER_LABEL_LEN + && b32hex_p8ton5(wire + 1, hash) + && b32hex_p8ton5(wire + 9, hash + 5) + && b32hex_p8ton5(wire + 17, hash + 10) + && b32hex_p8ton5(wire + 25, hash + 15); } void @@ -627,6 +823,46 @@ nsec3_precompile_nsec3rr(namedb_type* db } } +/* nsec3 precompile for walked to domain */ +static void +nsec3_precompile_walk(struct namedb* db, zone_type* zone, domain_type* walk, + struct region* tmpregion) +{ + if(nsec3_condition_hash(walk, zone)) { + nsec3_precompile_domain(db, walk, zone, tmpregion); + region_free_all(tmpregion); + } + if(nsec3_condition_dshash(walk, zone)) + nsec3_precompile_domain_ds(db, walk, zone); +} + +void +nsec3_superzone_precompile_for_apex(struct namedb* db, const dname_type* apex) +{ + region_type* tmpregion; + domain_type* apex_domain, *walk; + struct zone* zone; /* the super zone of apex */ + zone = find_superzone_of(db, apex); + if(!zone) return; /* no super zone above the apex */ + if(!zone->nsec3_param) return; /* super is not an NSEC3 zone */ + + apex_domain = domain_table_find(db->domains, apex); + if(!domain_is_subdomain(apex_domain, zone->apex)) + return; /* robustness check */ + tmpregion = region_create(xalloc, free); + for(walk=apex_domain; walk && domain_is_subdomain(walk, apex_domain); + walk = domain_next(walk)) { + if(nsec3_in_chain_count(walk, zone) != 0) { + nsec3_precompile_nsec3rr(db, walk, zone); + } + } + for(walk=apex_domain; walk && domain_is_subdomain(walk, apex_domain); + walk = domain_next(walk)) { + nsec3_precompile_walk(db, zone, walk, tmpregion); + } + region_destroy(tmpregion); +} + void nsec3_precompile_newparam(namedb_type* db, zone_type* zone) { @@ -646,12 +882,7 @@ nsec3_precompile_newparam(namedb_type* d /* hash and precompile zone */ for(walk=zone->apex; walk && domain_is_subdomain(walk, zone->apex); walk = domain_next(walk)) { - if(nsec3_condition_hash(walk, zone)) { - nsec3_precompile_domain(db, walk, zone, tmpregion); - region_free_all(tmpregion); - } - if(nsec3_condition_dshash(walk, zone)) - nsec3_precompile_domain_ds(db, walk, zone); + nsec3_precompile_walk(db, zone, walk, tmpregion); if(++c % ZONEC_PCT_COUNT == 0 && time(NULL) > s + ZONEC_PCT_TIME) { s = time(NULL); VERBOSITY(1, (LOG_INFO, "nsec3 %s %d %%", @@ -776,8 +1007,13 @@ process_range(zone_type* zone, domain_ty * already allocated, and we need not allocate it here */ /* set start */ if(start) { - uint8_t hash[NSEC3_HASH_LEN+1]; - parse_nsec3_name(domain_dname(start), hash, sizeof(hash)); + uint8_t hash[NSEC3_HASH_LEN]; + if(!parse_nsec3_name(domain_dname(start), hash)) { + log_msg( LOG_WARNING + , "NSEC3 %s skipped due to invalid owner name" + , dname_to_string(domain_dname(start), 0)); + return; + } /* if exact match on first, set is_exact */ if(process_first(zone->hashtree, hash, &p, init_lookup_key_hash_tree)) { ((domain_type*)(p->key))->nsec3->nsec3_cover = nsec3; @@ -802,8 +1038,13 @@ process_range(zone_type* zone, domain_ty } /* set end */ if(end) { - uint8_t hash[NSEC3_HASH_LEN+1]; - parse_nsec3_name(domain_dname(end), hash, sizeof(hash)); + uint8_t hash[NSEC3_HASH_LEN]; + if(!parse_nsec3_name(domain_dname(end), hash)) { + log_msg( LOG_WARNING + , "NSEC3 %s skipped due to invalid owner name" + , dname_to_string(domain_dname(end), 0)); + return; + } process_end(zone->hashtree, hash, &p_end, init_lookup_key_hash_tree); process_end(zone->wchashtree, hash, &pwc_end, init_lookup_key_wc_tree); process_end(zone->dshashtree, hash, &pds_end, init_lookup_key_ds_tree); Index: usr.sbin/nsd/nsec3.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/nsec3.h,v diff -u -p -r1.4 nsec3.h --- usr.sbin/nsd/nsec3.h 20 Dec 2023 17:29:01 -0000 1.4 +++ usr.sbin/nsd/nsec3.h 21 Sep 2026 16:28:42 -0000 @@ -80,6 +80,8 @@ void nsec3_hash_and_store(struct zone* z int nsec3_rr_uses_params(struct rr* rr, struct zone* zone); /* number of NSEC3s that are in the zone chain */ int nsec3_in_chain_count(struct domain* domain, struct zone* zone); +/* if the NSEC3 record is b32.zone name */ +int nsec3_has_owner_for_zone(struct domain* domain, struct zone* zone); /* find previous NSEC3, or, lastinzone, or, NULL */ struct domain* nsec3_chain_find_prev(struct zone* zone, struct domain* domain); /* clear nsec3 precompile for the zone */ @@ -104,6 +106,12 @@ void nsec3_precompile_nsec3rr(struct nam struct zone* zone); /* precompile entire zone, assumes all is null at start */ void nsec3_precompile_newparam(struct namedb* db, struct zone* zone); +/* clear super zone of apex, for names subdomain of apex. */ +void nsec3_superzone_clear_for_apex(struct namedb* db, + const struct dname* apex); +/* precompile super zone of apex, for names subdomain of apex. */ +void nsec3_superzone_precompile_for_apex(struct namedb* db, + const struct dname* apex); /* create b32.zone for a hash, allocated in the region */ const struct dname* nsec3_b32_create(struct region* region, struct zone* zone, unsigned char* hash); Index: usr.sbin/nsd/options.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/options.c,v diff -u -p -r1.33 options.c --- usr.sbin/nsd/options.c 21 Mar 2026 21:36:36 -0000 1.33 +++ usr.sbin/nsd/options.c 21 Sep 2026 16:28:42 -0000 @@ -29,6 +29,7 @@ #include "rrl.h" #include "bitset.h" #include "xfrd.h" +#include "metrics.h" #include "configparser.h" config_parser_state_type* cfg_parser = 0; @@ -151,6 +152,8 @@ nsd_options_create(region_type* region) opt->tls_cert_bundle = NULL; opt->tls_auth_xfr_only = 0; opt->proxy_protocol_port = NULL; + opt->allow_proxy = NULL; + opt->udp_padding_port = NULL; opt->answer_cookie = 1; opt->cookie_secret = NULL; opt->cookie_staging_secret = NULL; @@ -333,6 +336,9 @@ parse_options_file(struct nsd_options* o tls_auth_options_find(opt, acl->tls_auth_name))) c_error("tls_auth %s in pattern %s could not be found", acl->tls_auth_name, pat->pname); + else if (!opt->tls_auth_port) + c_warning("provide-xfr has a tls-auth-name," + " but no tls-auth-port is configured"); } if(acl->nokey || acl->blocked) continue; @@ -959,10 +965,11 @@ zone_list_close(struct nsd_options* opt) } static void -c_error_va_list_pos(int showpos, const char* fmt, va_list args) +c_error_va_list_pos(int showpos, int is_error, const char* fmt, va_list args) { char* at = NULL; - cfg_parser->errors++; + if(is_error) + cfg_parser->errors++; if(showpos && c_text && c_text[0]!=0) { at = c_text; } @@ -975,7 +982,8 @@ c_error_va_list_pos(int showpos, const c snprintf(m, sizeof(m), "at '%s': ", at); (*cfg_parser->err)(cfg_parser->err_arg, m); } - (*cfg_parser->err)(cfg_parser->err_arg, "error: "); + (*cfg_parser->err)(cfg_parser->err_arg, + is_error ? "error: " : "warning: "); vsnprintf(m, sizeof(m), fmt, args); (*cfg_parser->err)(cfg_parser->err_arg, m); (*cfg_parser->err)(cfg_parser->err_arg, "\n"); @@ -983,7 +991,7 @@ c_error_va_list_pos(int showpos, const c } fprintf(stderr, "%s:%d: ", cfg_parser->filename, cfg_parser->line); if(at) fprintf(stderr, "at '%s': ", at); - fprintf(stderr, "error: "); + fprintf(stderr, is_error ? "error: " : "warning: "); vfprintf(stderr, fmt, args); fprintf(stderr, "\n"); } @@ -999,7 +1007,22 @@ c_error(const char *fmt, ...) } va_start(ap, fmt); - c_error_va_list_pos(showpos, fmt, ap); + c_error_va_list_pos(showpos, 1, fmt, ap); + va_end(ap); +} + +void +c_warning(const char *fmt, ...) +{ + va_list ap; + int showpos = 0; + + if (strcmp(fmt, "syntax error") == 0 || strcmp(fmt, "parse error") == 0) { + showpos = 1; + } + + va_start(ap, fmt); + c_error_va_list_pos(showpos, 0, fmt, ap); va_end(ap); } @@ -1942,6 +1965,28 @@ key_options_add_modify(struct nsd_option } int +acl_check_incoming_proxy(struct acl_options* acl, struct query* q, + struct acl_options** reason) +{ + if(reason) + *reason = NULL; + + while(acl) + { + DEBUG(DEBUG_XFRD,2, (LOG_INFO, "proxy testing allow-proxy acl %s", + acl->ip_address_spec)); + if(acl_addr_matches_proxy(acl, q)) { + if(reason) + *reason = acl; + return 1; + } + acl = acl->next; + } + + return -1; +} + +int acl_check_incoming_block_proxy(struct acl_options* acl, struct query* q, struct acl_options** reason) { @@ -1994,7 +2039,21 @@ acl_check_incoming(struct acl_options* a acl->ip_address_spec, acl->nokey?"NOKEY": (acl->blocked?"BLOCKED":acl->key_name))); #endif - if(acl_addr_matches(acl, q) && acl_key_matches(acl, q)) { +#ifdef HAVE_SSL + if (acl->tls_auth_name && !q->tls_auth) { + /* the acl requires a TLS client cert with name, but + * the connection did not came over a "tls-auth-port:" + */ + number++; + acl = acl->next; + continue; + } +#endif + if(acl_addr_matches(acl, q) && acl_key_matches(acl, q) +#ifdef HAVE_SSL + && acl_tls_auth_name_matches(acl, q) +#endif + ) { if(!match) { match = acl; /* remember first match */ @@ -2006,27 +2065,6 @@ acl_check_incoming(struct acl_options* a return -1; } } -#ifdef HAVE_SSL - /* we are in a acl with tls_auth */ - if (acl->tls_auth_name && q->tls_auth) { - /* we have auth_domain_name in tls_auth */ - if (acl->tls_auth_options && acl->tls_auth_options->auth_domain_name) { - if (!acl_tls_hostname_matches(q->tls_auth, acl->tls_auth_options->auth_domain_name)) { - VERBOSITY(3, (LOG_WARNING, - "client cert does not match %s %s", - acl->tls_auth_name, acl->tls_auth_options->auth_domain_name)); - q->cert_cn = NULL; - return -1; - } - VERBOSITY(5, (LOG_INFO, "%s %s verified", - acl->tls_auth_name, acl->tls_auth_options->auth_domain_name)); - q->cert_cn = acl->tls_auth_options->auth_domain_name; - } else { - /* nsd gives error on start for this, but check just in case */ - log_msg(LOG_ERR, "auth-domain-name not defined in %s", acl->tls_auth_name); - } - } -#endif number++; acl = acl->next; } @@ -2190,9 +2228,9 @@ acl_addr_match_range_v4(uint32_t* minval /* check treats x as one huge number */ /* if outside bounds, we are done */ - if(*minval > *x) + if(ntohl(*minval) > ntohl(*x)) return 0; - if(*maxval < *x) + if(ntohl(*maxval) < ntohl(*x)) return 0; return 1; @@ -2213,10 +2251,10 @@ acl_addr_match_range_v6(uint32_t* minval { /* if outside bounds, we are done */ if(checkmin) - if(minval[i] > x[i]) + if(ntohl(minval[i]) > ntohl(x[i])) return 0; if(checkmax) - if(maxval[i] < x[i]) + if(ntohl(maxval[i]) < ntohl(x[i])) return 0; /* if x is equal to a bound, that bound needs further checks */ if(checkmin && minval[i]!=x[i]) @@ -2239,13 +2277,18 @@ acl_addr_match_range_v6(uint32_t* minval * Copyright (C) 2012, iSEC Partners. * License: MIT License * Author: Alban Diquet + * + * Modified 20260805 W.C.A. Wijngaards - added san_present for RFC6125 + * conformance change. */ static int matches_subject_alternative_name( - const char *acl_cert_cn, size_t acl_cert_cn_len, const X509 *cert) + const char *acl_cert_cn, size_t acl_cert_cn_len, const X509 *cert, + int* san_present) { int result = 0; int san_names_nb = -1; STACK_OF(GENERAL_NAME) *san_names = NULL; + *san_present = 0; /* Try to extract the names within the SAN extension from the certificate */ san_names = X509_get_ext_d2i(cert, NID_subject_alt_name, NULL, NULL); @@ -2262,6 +2305,7 @@ static int matches_subject_alternative_n /* Skip non-DNS SAN entries. */ if (current_name->type != GEN_DNS) continue; + *san_present = 1; /* DNS SAN entry is present */ #if HAVE_ASN1_STRING_GET0_DATA str = (const char *)ASN1_STRING_get0_data(current_name->d.dNSName); #else @@ -2354,7 +2398,7 @@ static int matches_common_name( int acl_tls_hostname_matches(SSL* tls_auth, const char *acl_cert_cn) { - int result = 0; + int result = 0, san_present; size_t acl_cert_cn_len; X509 *client_cert; @@ -2382,8 +2426,9 @@ acl_tls_hostname_matches(SSL* tls_auth, */ acl_cert_cn_len = strlen(acl_cert_cn); - /* semi follow RFC6125#section-6.4.4 check SAN DNS first */ - if (!(result = matches_subject_alternative_name(acl_cert_cn, acl_cert_cn_len, client_cert))) + /* follow RFC6125#section-6.4.4 check SAN DNS first, and + * common name if there is no SAN DNS present. */ + if (!(result = matches_subject_alternative_name(acl_cert_cn, acl_cert_cn_len, client_cert, &san_present)) && !san_present) result = matches_common_name(acl_cert_cn, acl_cert_cn_len, client_cert); X509_free(client_cert); @@ -2431,6 +2476,35 @@ acl_key_matches(struct acl_options* acl, return 1; } +#ifdef HAVE_SSL +int +acl_tls_auth_name_matches(struct acl_options* acl, struct query* q) +{ + /* If no name specified, no name is required */ + if (!acl->tls_auth_name) + return 1; + + /* we have auth_domain_name in tls_auth */ + if (!acl->tls_auth_options + || !acl->tls_auth_options->auth_domain_name) { + /* nsd gives error on start for this, but check just in case */ + log_msg(LOG_ERR, "auth-domain-name not defined in %s", acl->tls_auth_name); + return 0; + } + if (!acl_tls_hostname_matches(q->tls_auth, + acl->tls_auth_options->auth_domain_name)) { + VERBOSITY(6, (LOG_DEBUG, "client cert does not match %s %s", + acl->tls_auth_name, + acl->tls_auth_options->auth_domain_name)); + return 0; + } + VERBOSITY(5, (LOG_INFO, "%s %s verified", acl->tls_auth_name, + acl->tls_auth_options->auth_domain_name)); + q->cert_cn = acl->tls_auth_options->auth_domain_name; + return 1; +} +#endif + int acl_same_host(struct acl_options* a, struct acl_options* b) { @@ -2941,12 +3015,30 @@ unsigned getzonestatid(struct nsd_option { #ifdef USE_ZONE_STATS const char* statname; + char* statname_valid; + int name_was_modified; struct zonestatname* n; rbnode_type* res; /* try to find the instantiated zonestat name */ if(!zopt->pattern->zonestats || zopt->pattern->zonestats[0]==0) return 0; /* no zone stats */ statname = config_cook_string(zopt, zopt->pattern->zonestats); + + #ifdef USE_METRICS + /* warn when we will lossily change the zonestat name in metrics */ + statname_valid = strdup(statname); + if(!statname_valid) { + log_msg(LOG_ERR, "malloc failed: %s", strerror(errno)); + exit(1); + } + name_was_modified = metrics_make_label_value_valid(statname_valid); + if (name_was_modified) { + log_msg(LOG_WARNING, "zonestats name \"%s\" contains disallowed characters, using \"%s\" in metrics", + statname, statname_valid); + } + free(statname_valid); + #endif /* USE_METRICS */ + res = rbtree_search(opt->zonestatnames, statname); if(res) return ((struct zonestatname*)res)->id; @@ -3124,10 +3216,8 @@ resolve_interface_names(struct nsd_optio } int -sockaddr_uses_proxy_protocol_port(struct nsd_options* options, - struct sockaddr* addr) +sockaddr_uses_port(struct sockaddr* addr, struct port_list* p) { - struct proxy_protocol_port_list* p; int port; #ifdef INET6 struct sockaddr_storage* ss = (struct sockaddr_storage*)addr; @@ -3147,7 +3237,6 @@ sockaddr_uses_proxy_protocol_port(struct return 0; /* unknown family */ } #endif - p = options->proxy_protocol_port; while(p) { if(p->port == port) return 1; Index: usr.sbin/nsd/options.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/options.h,v diff -u -p -r1.32 options.h --- usr.sbin/nsd/options.h 21 Mar 2026 21:36:36 -0000 1.32 +++ usr.sbin/nsd/options.h 21 Sep 2026 16:28:42 -0000 @@ -21,7 +21,7 @@ struct dname; struct tsig_key; struct buffer; struct nsd; -struct proxy_protocol_port_list; +struct port_list; typedef struct nsd_options nsd_options_type; @@ -147,7 +147,11 @@ struct nsd_options { int tls_auth_xfr_only; /* proxy protocol port list */ - struct proxy_protocol_port_list* proxy_protocol_port; + struct port_list* proxy_protocol_port; + /* Allowed proxy senders (the outer IP addr), it allows all if empty */ + struct acl_options* allow_proxy; + /* udp-padding-port list */ + struct port_list* udp_padding_port; /** remote control section. enable toggle. */ int control_enable; @@ -463,9 +467,9 @@ struct tls_auth_options { char* client_key_pw; }; -/* proxy protocol port option list */ -struct proxy_protocol_port_list { - struct proxy_protocol_port_list* next; +/* port option list */ +struct port_list { + struct port_list* next; int port; }; @@ -599,6 +603,7 @@ int acl_addr_matches_proxy(struct acl_op int acl_tls_hostname_matches(SSL* ssl, const char* acl_cert_cn); #endif int acl_key_matches(struct acl_options* acl, struct query* q); +int acl_tls_auth_name_matches(struct acl_options* acl, struct query* q); int acl_addr_match_mask(uint32_t* a, uint32_t* b, uint32_t* mask, size_t sz); int acl_addr_match_range_v6(uint32_t* minval, uint32_t* x, uint32_t* maxval, size_t sz); int acl_addr_match_range_v4(uint32_t* minval, uint32_t* x, uint32_t* maxval, size_t sz); @@ -606,6 +611,9 @@ int acl_addr_match_range_v4(uint32_t* mi /* check acl list for blocks on address, return 0 if none, -1 if blocked. */ int acl_check_incoming_block_proxy(struct acl_options* acl, struct query* q, struct acl_options** reason); +/* check acl list, proxy addr, if match return 1, -1 if no matches. */ +int acl_check_incoming_proxy(struct acl_options* acl, struct query* q, + struct acl_options** reason); /* returns true if acls are both from the same host */ int acl_same_host(struct acl_options* a, struct acl_options* b); @@ -641,6 +649,7 @@ const char* config_make_zonefile(struct /* parsing helpers */ void c_error(const char* msg, ...) ATTR_FORMAT(printf, 1,2); +void c_warning(const char* msg, ...) ATTR_FORMAT(printf, 1,2); int c_wrap(void); struct acl_options* parse_acl_info(region_type* region, char* ip, const char* key); @@ -665,8 +674,7 @@ void warn_if_directory(const char* filet * names. */ void resolve_interface_names(struct nsd_options* options); -/* See if the sockaddr port number is listed in the proxy protocol ports. */ -int sockaddr_uses_proxy_protocol_port(struct nsd_options* options, - struct sockaddr* addr); +/* See if the sockaddr port number is listed in the ports. */ +int sockaddr_uses_port(struct sockaddr* addr, struct port_list* ports); #endif /* OPTIONS_H */ Index: usr.sbin/nsd/query.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/query.c,v diff -u -p -r1.45 query.c --- usr.sbin/nsd/query.c 21 Mar 2026 21:36:36 -0000 1.45 +++ usr.sbin/nsd/query.c 21 Sep 2026 16:28:42 -0000 @@ -249,7 +249,9 @@ query_reset(query_type *q, size_t maxlen region_free_all(q->region); q->remote_addrlen = (socklen_t)sizeof(q->remote_addr); q->client_addrlen = (socklen_t)sizeof(q->client_addr); - q->is_proxied = 0; + q->may_pad = 0; + if(!is_tcp) + q->is_proxied = 0; q->maxlen = maxlen; q->reserved_space = 0; buffer_clear(q->packet); @@ -497,6 +499,7 @@ answer_notify(struct nsd* nsd, struct qu { int s = nsd->serve2xfrd_fd_send[nsd->this_child->child_num]; uint16_t sz; + uint32_t sz32; uint32_t acl_send = htonl(acl_num); uint32_t acl_xfr; size_t pos; @@ -517,8 +520,11 @@ answer_notify(struct nsd* nsd, struct qu return query_error(query, NSD_RC_SERVFAIL); /* forward to xfrd for processing Note. Blocking IPC I/O, but acl is OK. */ - sz = buffer_limit(query->packet) + sz32 = buffer_limit(query->packet) + sizeof(acl_send) + sizeof(acl_xfr); + if(sz32 > 0xFFFF) + return query_error(query, NSD_RC_SERVFAIL); + sz = (uint16_t)sz32; sz = htons(sz); if(!write_socket(s, &sz, sizeof(sz)) || !write_socket(s, buffer_begin(query->packet), @@ -1027,7 +1033,8 @@ answer_nodata(struct query *query, answe answer_soa(query, answer); #ifdef NSEC3 - if (query->edns.dnssec_ok && query->zone->nsec3_param) { + if (query->edns.dnssec_ok && query->zone->nsec3_param && + zone_is_secure(query->zone)) { nsec3_answer_nodata(query, answer, original); } else #endif @@ -1138,6 +1145,9 @@ answer_domain(struct nsd* nsd, struct qu zone_type* origzone = q->zone; ++q->cname_count; + if (q->cname_count >= MAX_CNAME_CHAIN) { + return; + } answer_lookup_zone(nsd, q, answer, closest_match->number, closest_match == closest_encloser, closest_match, closest_encloser, @@ -1232,6 +1242,7 @@ answer_authoritative(struct nsd *nsd, return; } DEBUG(DEBUG_QUERY,2, (LOG_INFO, "->result is %s", dname_to_string(newname, NULL))); + /* follow the DNAME */ (void)namedb_lookup(nsd->db, newname, &closest_match, &closest_encloser); /* synthesize CNAME record */ @@ -1248,6 +1259,9 @@ answer_authoritative(struct nsd *nsd, * of type CNAME */ return; } + if (q->cname_count >= MAX_CNAME_CHAIN) { + return; + } answer_lookup_zone(nsd, q, answer, newnum, closest_match == closest_encloser, @@ -1772,6 +1786,16 @@ query_process(query_type *q, nsd_type *n cookie_verify(q, nsd, now_p); query_prepare_response(q); + if(q->reserved_space + QHEADERSZ + (size_t)q->qname->name_size + + 2 /* qtype */ + 2 /* qclass */ > q->maxlen) { + /* Clear out some space, and return error, it does not fit. */ + q->edns.status = EDNS_NOT_PRESENT; + q->tsig.status = TSIG_NOT_PRESENT; + if(q->tcp) + return query_error(q, NSD_RC_SERVFAIL); + TC_SET(q->packet); + return query_error(q, NSD_RC_OK); + } if (q->qclass != CLASS_IN && q->qclass != CLASS_ANY) { if (q->qclass == CLASS_CH) { @@ -1835,7 +1859,21 @@ query_add_optional(query_type *q, nsd_ty + sizeof(uint8_t) + sizeof(uint8_t) + sizeof(uint32_t); - + if(q->edns.padding) { + size_t cur_sz = buffer_position(q->packet) + 2 + q->edns.opt_reserved_space; + size_t padded_sz = (((cur_sz - 1) / PADDING_BLOCK_SZ) + 1) * PADDING_BLOCK_SZ; + size_t to_padd = padded_sz - cur_sz; + /* Need 4 bytes for option code and length */ + q->edns.padding = to_padd >= 4 ? to_padd + : to_padd > 0 ? (PADDING_BLOCK_SZ + to_padd) + : 0; /* Multiple of PADDING_BLOCK_SZ, + * so no outgoing padding option */ + if(!buffer_available(q->packet, 2+q->edns.opt_reserved_space+q->edns.padding) || cur_sz + q->edns.padding > 65535) + q->edns.padding = 0; + if(q->edns.padding) { + q->edns.opt_reserved_space += q->edns.padding; + } + } if(q->edns.opt_reserved_space == 0 || !buffer_available( q->packet, 2+q->edns.opt_reserved_space)) { /* fill with NULLs */ @@ -1890,6 +1928,12 @@ query_add_optional(query_type *q, nsd_ty buffer_write(q->packet, q->edns.ede_text, q->edns.ede_text_len); + } + if(q->edns.padding) { + assert(q->edns.padding >= 4); + buffer_write_u16(q->packet, PADDING_CODE); + buffer_write_u16(q->packet, q->edns.padding - 4); + buffer_fill(q->packet, 0, q->edns.padding - 4); } } ARCOUNT_SET(q->packet, ARCOUNT(q->packet) + 1); Index: usr.sbin/nsd/query.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/query.h,v diff -u -p -r1.10 query.h --- usr.sbin/nsd/query.h 6 Sep 2025 17:41:37 -0000 1.10 +++ usr.sbin/nsd/query.h 21 Sep 2026 16:28:42 -0000 @@ -47,6 +47,9 @@ struct query { /* if set, the request came through a proxy */ int is_proxied; + /* if set, the response may be padded */ + int may_pad; + /* the client address * the same as remote_addr if not proxied */ #ifdef INET6 Index: usr.sbin/nsd/rdata.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/rdata.c,v diff -u -p -r1.20 rdata.c --- usr.sbin/nsd/rdata.c 21 Mar 2026 21:36:36 -0000 1.20 +++ usr.sbin/nsd/rdata.c 21 Sep 2026 16:28:42 -0000 @@ -105,6 +105,14 @@ static int print_svcparam_dohpath(struct static int print_svcparam_tls_supported_groups(struct buffer *output, uint16_t svcparamkey, const uint8_t* data, uint16_t datalen); +/* Print svcparam docpath */ +static int print_svcparam_docpath(struct buffer *output, + uint16_t svcparamkey, const uint8_t* data, uint16_t datalen); + +/* Print svcparam oots */ +static int print_svcparam_oots(struct buffer *output, + uint16_t svcparamkey, const uint8_t* data, uint16_t datalen); + static const nsd_svcparam_descriptor_type svcparams[] = { { SVCB_KEY_MANDATORY, "mandatory", print_svcparam_mandatory }, { SVCB_KEY_ALPN, "alpn", print_svcparam_alpn }, @@ -118,6 +126,9 @@ static const nsd_svcparam_descriptor_typ { SVCB_KEY_OHTTP, "ohttp", print_svcparam_no_value }, { SVCB_KEY_TLS_SUPPORTED_GROUPS, "tls-supported-groups", print_svcparam_tls_supported_groups }, + { SVCB_KEY_DOCPATH, "docpath", print_svcparam_docpath}, + { SVCB_KEY_PVD, "pvd", print_svcparam_no_value }, + { SVCB_KEY_OOTS, "oots", print_svcparam_oots}, }; /* @@ -137,7 +148,7 @@ print_name_literal(struct buffer *output { const uint8_t *name, *label, *limit; assert(rdlength >= *offset); - if (rdlength - *offset == 0) + if (rdlength < *offset || rdlength - *offset == 0) return 0; name = rdata + *offset; @@ -181,7 +192,7 @@ print_domain(struct buffer *output, uint { const struct dname *dname; struct domain *domain; - if(rdlength - *offset < (uint16_t)sizeof(void*)) + if(rdlength < *offset || rdlength - *offset < (uint16_t)sizeof(void*)) return 0; memcpy(&domain, rdata+*offset, sizeof(void*)); dname = domain_dname(domain); @@ -195,7 +206,7 @@ static inline int32_t skip_string(struct buffer* output, uint16_t rdlength, uint16_t* offset) { int32_t length; - if (rdlength - *offset < 1) + if (rdlength < *offset || rdlength - *offset < 1) return -1; length = buffer_read_u8(output); if (length + 1 > rdlength - *offset) @@ -236,7 +247,7 @@ print_string(struct buffer *output, uint if(rdlength - *offset < 1) return 0; n = rdata[*offset]; - if((size_t)rdlength - *offset < 1 + n) + if(rdlength < *offset || (size_t)rdlength - *offset < 1 + n) return 0; buffer_printf(output, "\""); for (size_t i = 1; i <= n; i++) { @@ -285,7 +296,7 @@ print_unquoted(buffer_type *output, uint uint8_t len; size_t i; - if(rdlength - *offset < 1) + if(rdlength < *offset || rdlength - *offset < 1) return 0; len = rdata[*offset]; if(((size_t)len) + 1 > (size_t)rdlength - *offset) @@ -336,7 +347,6 @@ print_ip4(struct buffer *output, size_t uint16_t *offset) { char str[INET_ADDRSTRLEN + 1]; - assert(rdlength >= *offset); if(((size_t)*offset) + 4 > rdlength) return 0; if(!inet_ntop(AF_INET, rdata + *offset, str, sizeof(str))) @@ -360,8 +370,7 @@ print_ip6(struct buffer *output, size_t uint16_t *offset) { char str[INET6_ADDRSTRLEN + 1]; - assert(rdlength >= *offset); - if (rdlength - *offset < 16) + if (rdlength < *offset || rdlength - *offset < 16) return 0; if (!inet_ntop(AF_INET6, rdata + *offset, str, sizeof(str))) return 0; @@ -384,8 +393,7 @@ print_ilnp64(struct buffer *output, uint uint16_t *offset) { uint16_t a1, a2, a3, a4; - assert(rdlength >= *offset); - if (rdlength - *offset < 8) + if (rdlength < *offset || rdlength - *offset < 8) return 0; a1 = read_uint16(rdata + *offset); a2 = read_uint16(rdata + *offset + 2); @@ -442,8 +450,7 @@ print_time(struct buffer *output, uint16 struct tm* tm; char buf[15]; - assert(rdlength >= *offset); - if (rdlength - *offset < 4) + if (rdlength < *offset || rdlength - *offset < 4) return 0; time = (time_t)read_uint32(rdata + *offset); tm = gmtime_r(&time, &tmbuf); @@ -469,7 +476,7 @@ print_base32(struct buffer *output, uint { size_t size; int length; - if(rdlength - *offset == 0) + if(rdlength < *offset || rdlength - *offset == 0) return 0; size = rdata[*offset]; if (rdlength - ((size_t)*offset) < 1 + size) @@ -506,6 +513,8 @@ print_base64(struct buffer *output, uint { int length; size_t size = rdlength - *offset; + if(rdlength < *offset) + return 0; if(size == 0) { /* single zero represents empty buffer */ buffer_write(output, "0", 1); @@ -552,6 +561,8 @@ print_base16(struct buffer *output, uint uint16_t *offset) { size_t size = rdlength - *offset; + if(rdlength < *offset) + return 0; if(size == 0) { /* single zero represents empty buffer, such as CDS deletes */ buffer_write(output, "0", 1); @@ -577,8 +588,7 @@ print_salt(struct buffer *output, uint16 uint16_t *offset) { uint8_t length; - assert(rdlength >= *offset); - if (rdlength - *offset == 0) + if (rdlength < *offset || rdlength - *offset == 0) return 0; length = rdata[*offset]; @@ -637,6 +647,8 @@ print_nsec_bitmap(struct buffer *output, { int insert_space = 0; + if(rdlength < *offset) + return 0; rdata += *offset; while(rdlength - *offset > 0) { uint8_t window, bitmap_size; @@ -682,6 +694,7 @@ svcparam_must_have_value(uint16_t svcpar case SVCB_KEY_MANDATORY: case SVCB_KEY_DOHPATH: case SVCB_KEY_TLS_SUPPORTED_GROUPS: + case SVCB_KEY_OOTS: return 1; default: break; @@ -696,12 +709,13 @@ svcparam_must_not_have_value(uint16_t sv switch (svcparamkey) { case SVCB_KEY_NO_DEFAULT_ALPN: case SVCB_KEY_OHTTP: + case SVCB_KEY_PVD: return 1; default: break; } return 0; -}; +} /* * Skip over the svcparams in the packet. Moves position. @@ -950,6 +964,52 @@ print_svcparam_tls_supported_groups(stru return 1; } +static int +print_svcparam_docpath(struct buffer *output, uint16_t svcparamkey, + const uint8_t* data, uint16_t datalen) +{ + if(datalen > 0) + return print_svcparam_alpn(output, svcparamkey, data, datalen); + buffer_print_svcparamkey(output, svcparamkey); + return 1; +} + +static int +print_svcparam_oots(struct buffer *output, uint16_t svcparamkey, + const uint8_t* data, uint16_t datalen) +{ + assert(datalen > 0); /* Guaranteed by svcparam_print */ + + buffer_print_svcparamkey(output, svcparamkey); + buffer_printf(output, "=\""); + while(((size_t)(*data)) + 2 <= (size_t)datalen) { + size_t transport_len = *data; + uint8_t percentage = data[transport_len + 1]; + size_t i; + + if(!transport_len || percentage > 100) + return 0; + + for(i=0; i < transport_len; i++) { + char ch = data[i + 1]; + if(!isgraph(ch) + || ch == '"' || ch == '\\' || ch == ',' || ch == ':') + return 0; + + buffer_write_u8(output, ch); + } + buffer_printf(output, ":%d", percentage); + data += transport_len + 2; + datalen -= transport_len + 2; + if(datalen) + buffer_write_u8(output, ','); + } + if(datalen) + return 0; + buffer_printf(output, "\""); + return 1; +} + /* * Print svcparam. * @param output: the string is output here. @@ -967,8 +1027,7 @@ print_svcparam(struct buffer *output, ui const uint8_t* dp; unsigned i; - assert(rdlength >= *offset); - if (rdlength - *offset < 4) + if (rdlength < *offset || rdlength - *offset < 4) return 0; key = read_uint16(rdata + *offset); @@ -2266,7 +2325,7 @@ print_nxt_rdata(struct buffer *output, c int bitmap_size; const uint8_t* bitmap; - assert(rr->rdlength > sizeof(void*)); + assert(rr->rdlength >= sizeof(void*)); if (!print_domain(output, rr->rdlength, rr->rdata, &length)) return 0; @@ -2560,7 +2619,10 @@ read_apl_rdata(struct domain_table *doma return MALFORMED; while (rdlength - length >= 4) { uint8_t afdlength = rdata[length + 3] & APL_LENGTH_MASK; - if (rdlength - (length + 4) < afdlength) + uint16_t afam = read_uint16(rdata + length); + if (rdlength - (length + 4) < afdlength || + (afam == 1 && afdlength > 4) || + (afam == 2 && afdlength > 16)) return MALFORMED; length += 4 + afdlength; } @@ -2590,7 +2652,7 @@ print_apl(struct buffer *output, size_t char text_address[INET6_ADDRSTRLEN + 1]; uint8_t address[16]; - if (size < 4) + if (rdlength < *offset || size < 4) return 0; address_family = read_uint16(rdata + *offset); @@ -2600,14 +2662,22 @@ print_apl(struct buffer *output, size_t af = -1; switch (address_family) { - case 1: af = AF_INET; break; - case 2: af = AF_INET6; break; + case 1: af = AF_INET; + if(length > 4) + return 0; + break; + case 2: af = AF_INET6; + if(length > 16) + return 0; + break; } if (af == -1 || size - 4 < length) return 0; memset(address, 0, sizeof(address)); + if(length > sizeof(address)) + return 0; memmove(address, rdata + *offset + 4, length); if (!inet_ntop(af, address, text_address, sizeof(text_address))) @@ -3123,6 +3193,8 @@ print_hip_rdata(struct buffer *output, c hit_length = rr->rdata[0]; pk_algorithm = rr->rdata[1]; pk_length = read_uint16(rr->rdata+2); + if(4 + (uint32_t)hit_length + (uint32_t)pk_length > (uint32_t)rr->rdlength) + return 0; buffer_printf(output, "%" PRIu8 " ", pk_algorithm); if(!print_base16(output, length+hit_length, rr->rdata, &length)) return 0; @@ -3282,7 +3354,7 @@ read_svcb_rdata(struct domain_table *dom struct domain *domain; struct dname_buffer target; uint16_t length = 2, svcparams_length = 0; - uint16_t size; + size_t size; const size_t mark = buffer_position(packet); /* short + name + svc_params */ @@ -3394,6 +3466,50 @@ print_dsync_rdata(struct buffer *output, rrtype_to_string(read_uint16(rr->rdata)), rr->rdata[2], read_uint16(rr->rdata+3)); if(!print_name_literal(output, rr->rdlength, rr->rdata, &length)) + return 0; + if(rr->rdlength != length) + return 0; + return 1; +} + +int32_t +read_hhit_rdata(struct domain_table *domains, uint16_t rdlength, + struct buffer *packet, struct rr **rr) +{ + /* A CBOR blob has at least 1 byte */ + if (rdlength < 1) + return MALFORMED; + return read_rdata(domains, rdlength, packet, rr); +} + +int +print_hhit_rdata(struct buffer *output, const struct rr *rr) +{ + uint16_t length = 0; + + if (!print_base64(output, rr->rdlength, rr->rdata, &length)) + return 0; + if(rr->rdlength != length) + return 0; + return 1; +} + +int32_t +read_brid_rdata(struct domain_table *domains, uint16_t rdlength, + struct buffer *packet, struct rr **rr) +{ + /* A CBOR blob has at least 1 byte */ + if (rdlength < 1) + return MALFORMED; + return read_rdata(domains, rdlength, packet, rr); +} + +int +print_brid_rdata(struct buffer *output, const struct rr *rr) +{ + uint16_t length = 0; + + if (!print_base64(output, rr->rdlength, rr->rdata, &length)) return 0; if(rr->rdlength != length) return 0; Index: usr.sbin/nsd/rdata.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/rdata.h,v diff -u -p -r1.4 rdata.h --- usr.sbin/nsd/rdata.h 21 Mar 2026 21:36:36 -0000 1.4 +++ usr.sbin/nsd/rdata.h 21 Sep 2026 16:28:42 -0000 @@ -421,6 +421,20 @@ int32_t read_dsync_rdata(struct domain_t /* Print rdata for type DSYNC. */ int print_dsync_rdata(struct buffer *output, const struct rr *rr); +/* Read rdata for type HHIT. */ +int32_t read_hhit_rdata(struct domain_table *domains, uint16_t rdlength, + struct buffer *packet, struct rr **rr); + +/* Print rdata for type HHIT. */ +int print_hhit_rdata(struct buffer *output, const struct rr *rr); + +/* Read rdata for type BRID. */ +int32_t read_brid_rdata(struct domain_table *domains, uint16_t rdlength, + struct buffer *packet, struct rr **rr); + +/* Print rdata for type BRID. */ +int print_brid_rdata(struct buffer *output, const struct rr *rr); + /* Read rdata for type NID. */ int32_t read_nid_rdata(struct domain_table *domains, uint16_t rdlength, struct buffer *packet, struct rr **rr); Index: usr.sbin/nsd/remote.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/remote.c,v diff -u -p -r1.30 remote.c --- usr.sbin/nsd/remote.c 21 Mar 2026 21:36:36 -0000 1.30 +++ usr.sbin/nsd/remote.c 21 Sep 2026 16:28:42 -0000 @@ -982,6 +982,10 @@ force_transfer_zone(xfrd_zone_type* zone xfrd_tcp_release(xfrd->tcp_set, zone); else if(zone->zone_handler.ev_fd != -1) xfrd_udp_release(zone); + if(zone->udp_waiting) + udp_zone_waiting_list_remove(zone); + if(zone->tcp_waiting) + tcp_zone_waiting_list_remove(zone); /* pretend we not longer have it and force any * zone to be downloaded (even same serial, w AXFR) */ zone->soa_disk_acquired = 0; @@ -1044,8 +1048,10 @@ print_zonestatus(RES* ssl, xfrd_state_ty } if(zone_is_catalog_consumer(zo)) { uint32_t serial = 0; - zone_type* zone = namedb_find_zone(xfrd->nsd->db, - (const dname_type*)zo->node.key); + zone_type* zone = xfrd->nsd->db + ? namedb_find_zone(xfrd->nsd->db, + (const dname_type*)zo->node.key) + : NULL; struct xfrd_catalog_consumer_zone* consumer_zone = (struct xfrd_catalog_consumer_zone*) rbtree_search( xfrd->catalog_consumer_zones @@ -1884,6 +1890,18 @@ repat_interrupt_zones(xfrd_state_type* x xfrd_udp_release(xz); xfrd_set_refresh_now(xz); } + if(xz->udp_waiting) { + log_msg(LOG_INFO, "udp_waiting for %s", + xz->apex_str); + udp_zone_waiting_list_remove(xz); + xfrd_set_refresh_now(xz); + } + if(xz->tcp_waiting) { + log_msg(LOG_INFO, "tcp_waiting for %s", + xz->apex_str); + tcp_zone_waiting_list_remove(xz); + xfrd_set_refresh_now(xz); + } xz->master = 0; xz->master_num = 0; xz->next_master = -1; @@ -2407,6 +2425,7 @@ do_assoc_tsig(RES* ssl, xfrd_state_type* char* arg2 = NULL; struct zone_options* zone; struct key_options* key_opt; + struct xfrd_zone* xzone; if(*arg == '\0') { (void)ssl_printf(ssl, "error: missing argument (zonename)\n"); @@ -2429,6 +2448,23 @@ do_assoc_tsig(RES* ssl, xfrd_state_type* return; } + /* Abort any in-flight transfer for this zone before mutating its ACL + * so that xfr->tsig stays consistent with zone->master->key_options. */ + xzone = xfrd_find_zone(xfrd, (dname_type*)zone->node.key); + if(xzone && xzone->tcp_conn != -1) { + xfrd_tcp_release(xfrd->tcp_set, xzone); + /* probe the current target again, if possible. */ + if(xzone->next_master == -1) + xzone->next_master = xzone->master_num; + xfrd_set_refresh_now(xzone); + } else if(xzone && xzone->zone_handler.ev_fd != -1) { + /* Also UDP can use the TSIG for signature. */ + xfrd_udp_release(xzone); + if(xzone->next_master == -1) + xzone->next_master = xzone->master_num; + xfrd_set_refresh_now(xzone); + } + zopt_set_acl_to_tsig(zone->pattern->allow_notify, region, arg2, key_opt); zopt_set_acl_to_tsig(zone->pattern->notify, region, arg2, key_opt); @@ -2476,6 +2512,7 @@ do_del_tsig(RES* ssl, xfrd_state_type* x } RBTREE_FOR(zone, struct zone_options*, xfrd->nsd->options->zone_options) { + xfrd_zone_type* xzone; if(acl_contains_tsig_key(zone->pattern->allow_notify, arg) || acl_contains_tsig_key(zone->pattern->notify, arg) || acl_contains_tsig_key(zone->pattern->request_xfr, arg) || @@ -2487,6 +2524,15 @@ do_del_tsig(RES* ssl, xfrd_state_type* x used_key = 1; break; } + xzone = xfrd_find_zone(xfrd, (dname_type*)zone->node.key); + if(xzone && xzone->latest_xfr && + xzone->latest_xfr->tsig.key == key_opt->tsig_key) { + if(!ssl_printf(ssl, "zone %s uses key %s\n", + zone->name, arg)) + return; + used_key = 1; + break; + } } if(used_key) { @@ -2838,8 +2884,17 @@ handle_req(struct daemon_remote* rc, str (void)ssl_printf(res, "error version mismatch\n"); return; } - /* always log control commands */ - VERBOSITY(0, (LOG_INFO, "control cmd: %s", buf)); + /* always log control command 'verbosity', others at 2, so + * they can be squelched if needed. */ + if(verbosity < 2) { + /* only the 'verbosity' command. */ + if(strncmp(skipwhite(buf), "verbosity", 9) == 0) { + VERBOSITY(0, (LOG_INFO, "control cmd: %s", buf)); + } + } else { + /* always log every control command. */ + VERBOSITY(2, (LOG_INFO, "control cmd: %s", buf)); + } /* figure out what to do */ execute_cmd(rc, res, buf); Index: usr.sbin/nsd/server.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/server.c,v diff -u -p -r1.56 server.c --- usr.sbin/nsd/server.c 21 Mar 2026 21:36:36 -0000 1.56 +++ usr.sbin/nsd/server.c 21 Sep 2026 16:28:43 -0000 @@ -158,6 +158,8 @@ struct udp_handler_data struct event event; /* if set, PROXYv2 is expected on this connection */ int pp2_enabled; + /* if set, padding is allowed on this connection */ + int may_pad; }; struct tcp_accept_handler_data { @@ -3221,7 +3223,9 @@ server_main(struct nsd *nsd) } #ifdef USE_XDP - xdp_server_cleanup(&nsd->xdp.xdp_server); + if (nsd->options->xdp_interface) { + xdp_server_cleanup(&nsd->xdp.xdp_server); + } #endif #ifdef MEMCLEAN /* OS collects memory pages */ @@ -3335,11 +3339,14 @@ add_udp_handler( data->nsd = nsd; data->socket = sock; - if(nsd->options->proxy_protocol_port && - sockaddr_uses_proxy_protocol_port(nsd->options, - (struct sockaddr *)&sock->addr.ai_addr)) { + if(sockaddr_uses_port((struct sockaddr *)&sock->addr.ai_addr, + nsd->options->proxy_protocol_port)) { data->pp2_enabled = 1; } + if(sockaddr_uses_port((struct sockaddr *)&sock->addr.ai_addr, + nsd->options->udp_padding_port)) { + data->may_pad = 1; + } memset(handler, 0, sizeof(*handler)); event_set(handler, sock->s, EV_PERSIST|EV_READ, handle_udp, data); @@ -3360,9 +3367,8 @@ add_tcp_handler( data->nsd = nsd; data->socket = sock; - if(nsd->options->proxy_protocol_port && - sockaddr_uses_proxy_protocol_port(nsd->options, - (struct sockaddr *)&sock->addr.ai_addr)) { + if(sockaddr_uses_port((struct sockaddr *)&sock->addr.ai_addr, + nsd->options->proxy_protocol_port)) { data->pp2_enabled = 1; } @@ -4058,6 +4064,35 @@ port_is_zero( #endif } +/* Check if proxy is allowed */ +static int +pp2_is_allowed(struct query* q) +{ + if(nsd.options->allow_proxy) { + struct acl_options* why = NULL; + if(acl_check_incoming_proxy(nsd.options->allow_proxy, q, + &why) == -1) { + if(verbosity >= 2) { + char proxy[128]; + addr2str(&q->remote_addr, proxy, sizeof(proxy)); + VERBOSITY(2, (LOG_INFO, "proxy-protocol: %s is not " + "in allow-proxy list", proxy)); + } + return 0; + } +#ifndef NDEBUG + /* It was allowed from acl 'why'. */ + if(why) { + char proxy[128]; + addr2str(&q->remote_addr, proxy, sizeof(proxy)); + DEBUG(DEBUG_QUERY,1, (LOG_INFO, "proxy %s passed acl %s", + proxy, why->ip_address_spec)); + } +#endif /* NDEBUG */ + } + return 1; +} + /* Parses the PROXYv2 header from buf and updates the struct. * Returns 1 on success, 0 on failure. */ static int @@ -4096,6 +4131,10 @@ consume_pp2_header(struct buffer* buf, s { struct sockaddr_in* addr = (struct sockaddr_in*)&q->client_addr; + if(ntohs(header->len) < PP2_HEADER_LEN_INET) { + VERBOSITY(4, (LOG_ERR, "proxy_protocol: header too short for IPv4 address")); + return 0; + } addr->sin_family = AF_INET; memmove(&addr->sin_addr.s_addr, &header->addr.addr4.src_addr, 4); @@ -4111,6 +4150,10 @@ consume_pp2_header(struct buffer* buf, s { struct sockaddr_in6* addr = (struct sockaddr_in6*)&q->client_addr; + if(ntohs(header->len) < PP2_HEADER_LEN_INET6) { + VERBOSITY(4, (LOG_ERR, "proxy_protocol: header too short for IPv6 address")); + return 0; + } memset(addr, 0, sizeof(*addr)); addr->sin6_family = AF_INET6; memmove(&addr->sin6_addr, @@ -4169,6 +4212,7 @@ handle_udp(int fd, short event, void* ar queries[i]->remote_addrlen = msgs[i].msg_hdr.msg_namelen; queries[i]->client_addrlen = (socklen_t)sizeof(queries[i]->client_addr); queries[i]->is_proxied = 0; + queries[i]->may_pad = data->may_pad; q = queries[i]; if (received == -1) { log_msg(LOG_ERR, "recvmmsg %d failed %s", i, strerror( @@ -4197,10 +4241,15 @@ handle_udp(int fd, short event, void* ar buffer_skip(q->packet, received); buffer_flip(q->packet); - if(data->pp2_enabled && !consume_pp2_header(q->packet, q, 0)) { - VERBOSITY(2, (LOG_ERR, "proxy-protocol: could not " - "consume PROXYv2 header")); - goto swap_drop; + if(data->pp2_enabled) { + if(!pp2_is_allowed(q)) + goto swap_drop; + if(!consume_pp2_header(q->packet, q, 0)) { + VERBOSITY(6, (LOG_ERR, "proxy-protocol: could not " + "consume PROXYv2 header")); + query_reset(queries[i], UDP_MAX_MESSAGE_LEN, 0); + goto swap_drop; + } } if(!q->is_proxied) { q->client_addrlen = q->remote_addrlen; @@ -4560,6 +4609,10 @@ handle_tcp_reading(int fd, short event, return; } buffer_flip(data->query->packet); + if(!pp2_is_allowed(data->query)) { + cleanup_tcp_handler(data); + return; + } if(!consume_pp2_header(data->query->packet, data->query, 1)) { VERBOSITY(6, (LOG_ERR, "proxy-protocol: could not consume PROXYv2 header")); @@ -4809,7 +4862,8 @@ handle_tcp_writing(int fd, short event, } #ifdef HAVE_WRITEV - sent -= sizeof(n_tcplen); + /* The number of bytes transmitted for the message content. */ + sent = data->bytes_transmitted - sizeof(n_tcplen); /* handle potential 'packet done' code */ goto packet_could_be_done; #endif @@ -5174,6 +5228,10 @@ handle_tls_reading(int fd, short event, return; } buffer_flip(data->query->packet); + if(!pp2_is_allowed(data->query)) { + cleanup_tcp_handler(data); + return; + } if(!consume_pp2_header(data->query->packet, data->query, 1)) { VERBOSITY(6, (LOG_ERR, "proxy-protocol: could not consume PROXYv2 header")); cleanup_tcp_handler(data); @@ -5415,7 +5473,6 @@ handle_tls_writing(int fd, short event, data->shake_state = tls_hs_read_event; tcp_handler_setup_event(data, handle_tls_reading, fd, EV_PERSIST | EV_READ | EV_TIMEOUT); } else if(want != SSL_ERROR_WANT_WRITE) { - cleanup_tcp_handler(data); { char client_ip[128], e[188]; if(data->query) { @@ -5427,6 +5484,7 @@ handle_tls_writing(int fd, short event, client_ip, "SSL_write error"); log_crypto_err(e); } + cleanup_tcp_handler(data); } return; } Index: usr.sbin/nsd/udb.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/udb.h,v diff -u -p -r1.6 udb.h --- usr.sbin/nsd/udb.h 20 Dec 2023 17:29:02 -0000 1.6 +++ usr.sbin/nsd/udb.h 21 Sep 2026 16:28:43 -0000 @@ -213,7 +213,6 @@ struct udb_base { int useful_compact; }; -typedef enum udb_chunk_type udb_chunk_type; /** chunk type enum, setting these types help recovery and debug */ enum udb_chunk_type { udb_chunk_type_free = 0, @@ -221,6 +220,7 @@ enum udb_chunk_type { udb_chunk_type_task, udb_chunk_type_internal }; +typedef enum udb_chunk_type udb_chunk_type; typedef struct udb_chunk_d udb_chunk_d; /** @@ -242,7 +242,7 @@ struct udb_chunk_d { * In the free chunk this is the previous pointer. */ udb_void ptrlist; /* user data space starts here, 64-bit aligned */ - uint8_t data[0]; + uint8_t data[]; /* last octet: exp of chunk */ }; @@ -287,7 +287,7 @@ struct udb_xl_chunk_d { /** size of this chunk in bytes */ uint64_t size; /** data of the XL chunk */ - uint8_t data[0]; + uint8_t data[]; /* uint64_t endsize: before last octet the size again. */ /* uint8_t pad[7]: padding to make last octet last. */ /* last octet: exp of chunk: special XL value */ Index: usr.sbin/nsd/verify.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/verify.c,v diff -u -p -r1.5 verify.c --- usr.sbin/nsd/verify.c 6 Sep 2025 17:41:37 -0000 1.5 +++ usr.sbin/nsd/verify.c 21 Sep 2026 16:28:43 -0000 @@ -371,11 +371,13 @@ verify_handle_command(int fd, short even sig_atomic_t mode; assert(nsd != NULL); - assert((event & (EV_READ + { + short ev_read = EV_READ; #ifdef EV_CLOSED - | EV_CLOSED + ev_read |= EV_CLOSED; #endif - ))); + assert((event & ev_read)); + } if((len = read(fd, &mode, sizeof(mode))) == -1) { log_msg(LOG_ERR, "verify: verify_handle_command: read: %s", Index: usr.sbin/nsd/xfrd-catalog-zones.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/xfrd-catalog-zones.c,v diff -u -p -r1.4 xfrd-catalog-zones.c --- usr.sbin/nsd/xfrd-catalog-zones.c 21 Mar 2026 21:36:36 -0000 1.4 +++ usr.sbin/nsd/xfrd-catalog-zones.c 21 Sep 2026 16:28:43 -0000 @@ -582,6 +582,7 @@ retry_adding: int valid_group_values; struct pattern_options *pattern = NULL; struct catalog_member_zone* to_add; + const dname_type* group_dname; if (domain_dname(member_id)->label_count > dname->label_count+2 || !(rrset = domain_find_rrset(member_id, zone, TYPE_PTR))) @@ -610,8 +611,12 @@ retry_adding: valid_group_values = 0; /* Lookup group. TXT for matching patterns */ - if(!namedb_lookup(xfrd->nsd->db, label_plus_dname("group", - domain_dname(member_id)), + group_dname = label_plus_dname("group", + domain_dname(member_id)); + /* If group_dname is NULL, then the group name is too long, + * and group properties are skipped for this member. */ + if(!group_dname + || !namedb_lookup(xfrd->nsd->db, group_dname, &group, &closest_encloser) || !(rrset = domain_find_rrset(group, zone, TYPE_TXT))) { ; /* pass */ @@ -973,13 +978,26 @@ xfrd_add_catalog_producer_member(struct producer_name = producer_zone->node.key; while(!cmz->member_id) { /* Make new member_id with this catalog producer */ + const dname_type* zones_name; char id_label[sizeof(uint32_t)*2+1]; uint32_t new_id = (uint32_t)random_generate(0x7fffffff); hex_ntop((void*)&new_id, sizeof(uint32_t), id_label, sizeof(id_label)); id_label[sizeof(uint32_t)*2] = 0; - cmz->member_id = label_plus_dname(id_label, - label_plus_dname("zones", producer_name)); + zones_name = label_plus_dname("zones", producer_name); + if(!zones_name) { + log_msg(LOG_ERR, "catalog producer: producer zone name " + "is too long, to add zones label. " + "Skipping addition of member zone"); + return; + } + cmz->member_id = label_plus_dname(id_label, zones_name); + if(!cmz->member_id) { + log_msg(LOG_ERR, "catalog producer: producer zone name " + "is too long, for member_id.zones labels. " + "Skipping addition of member zone"); + return; + } DEBUG(DEBUG_XFRD, 1, (LOG_INFO, "does member_id %s exist?", dname_to_string(cmz->member_id, NULL))); if (!rbtree_search(&producer_zone->member_ids, cmz)) { @@ -1185,6 +1203,19 @@ xfrd_process_catalog_producer_zone( return; /* No changes */ producer_name = (dname_type*)producer_zone->node.key; + if (producer_name->name_size > 234) { + /* For "group".<8char member id>."zones".apex. + * that is (1+5)+(1+8)+(1+5)+apex. + * 255 - (6+9+6) = 234 */ + log_msg(LOG_ERR, "catalog producer: name too long of " + "producer zone %s", dname_to_string(producer_name,0)); + return; + } + if (producer_name->label_count > 124) { + log_msg(LOG_ERR, "catalog producer: too many labels in name of " + "producer zone %s", dname_to_string(producer_name,0)); + return; + } xfr_writer_init(&xw, producer_zone); xfr_writer_add_SOA(&xw, producer_name, xw.new_serial); @@ -1201,6 +1232,7 @@ xfrd_process_catalog_producer_zone( /* IXFR */ xfr_writer_add_SOA(&xw, producer_name, xw.old_serial); while(producer_zone->to_delete) { + const dname_type* group_owner; struct xfrd_producer_member* to_delete = producer_zone->to_delete; @@ -1208,14 +1240,45 @@ xfrd_process_catalog_producer_zone( producer_zone->to_delete = to_delete->next; to_delete->next = NULL; + if((size_t)to_delete->member_id->name_size > 249) { + log_msg(LOG_ERR, "catalog producer: member_id " + "name_size %d too long for group property " + "owner; skipping delete of member zone %s", + (int)to_delete->member_id->name_size, + dname_to_string(to_delete->member_zone_name,0)); + region_recycle( xfrd->nsd->options->region + , (void *)to_delete->member_id + , dname_total_size(to_delete->member_id)); + region_recycle( xfrd->region /* allocated in perform_delzone */ + , (void *)to_delete->member_zone_name + , dname_total_size(to_delete->member_zone_name)); + region_recycle( xfrd->region, to_delete, sizeof(*to_delete)); + continue; + } + /* Write PTR */ xfr_writer_add_PTR(&xw, to_delete->member_id , to_delete->member_zone_name); /* Write group. TXT */ + group_owner = label_plus_dname("group", to_delete->member_id); + if(!group_owner) { + log_msg(LOG_ERR, "catalog producer: member_id " + "name_size %d too long for group property " + "owner; skipping delete of member zone %s", + (int)to_delete->member_id->name_size, + dname_to_string(to_delete->member_zone_name,0)); + region_recycle( xfrd->nsd->options->region + , (void *)to_delete->member_id + , dname_total_size(to_delete->member_id)); + region_recycle( xfrd->region /* allocated in perform_delzone */ + , (void *)to_delete->member_zone_name + , dname_total_size(to_delete->member_zone_name)); + region_recycle( xfrd->region, to_delete, sizeof(*to_delete)); + continue; + } xfr_writer_add_TXT( &xw - , label_plus_dname("group" - , to_delete->member_id) + , group_owner , to_delete->group_name); region_recycle( xfrd->nsd->options->region @@ -1232,19 +1295,38 @@ xfrd_process_catalog_producer_zone( add_member_zones: while(producer_zone->to_add) { struct xfrd_producer_member* to_add = producer_zone->to_add; + const dname_type* group_owner; /* Pop to_add from stack */ producer_zone->to_add = to_add->next; to_add->next = NULL; + if((size_t)to_add->member_id->name_size > 249) { + log_msg(LOG_ERR, "catalog producer: member_id " + "name_size %d too long for group property " + "owner; skipping member zone %s", + (int)to_add->member_id->name_size, + dname_to_string(to_add->member_zone_name,0)); + region_recycle(xfrd->region, to_add, sizeof(*to_add)); + continue; + } + /* Write PTR */ xfr_writer_add_PTR(&xw, to_add->member_id, to_add->member_zone_name); /* Write group. TXT */ + group_owner = label_plus_dname("group", to_add->member_id); + if(!group_owner) { + log_msg(LOG_ERR, "catalog producer: member_id too long " + "to construct group owner (name_size=%d); " + "skipping group property for member zone", + (int)to_add->member_id->name_size); + region_recycle(xfrd->region, to_add, sizeof(*to_add)); + continue; + } xfr_writer_add_TXT( &xw - , label_plus_dname("group" - , to_add->member_id) + , group_owner , to_add->group_name); /* Don't recycle any of the struct attributes as they come Index: usr.sbin/nsd/xfrd-tcp.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/xfrd-tcp.c,v diff -u -p -r1.32 xfrd-tcp.c --- usr.sbin/nsd/xfrd-tcp.c 6 Sep 2025 17:41:37 -0000 1.32 +++ usr.sbin/nsd/xfrd-tcp.c 21 Sep 2026 16:28:43 -0000 @@ -321,7 +321,7 @@ void pick_id_values(uint16_t* array, int for(j = max-num; jtcp_waiting) { + /* delete from tcp waiting list */ + if(z->tcp_waiting_prev) + z->tcp_waiting_prev->tcp_waiting_next = + z->tcp_waiting_next; + else xfrd->tcp_set->tcp_waiting_first = z->tcp_waiting_next; + if(z->tcp_waiting_next) + z->tcp_waiting_next->tcp_waiting_prev = + z->tcp_waiting_prev; + else xfrd->tcp_set->tcp_waiting_last = z->tcp_waiting_prev; + z->tcp_waiting = 0; + } +} + /* remove zone from tcp waiting list */ static void tcp_zone_waiting_list_popfirst(struct xfrd_tcp_set* set, xfrd_zone_type* zone) @@ -1100,6 +1117,8 @@ xfrd_tcp_setup_write_packet(struct xfrd_ struct xfrd_tcp* tcp = tp->tcp_w; assert(zone->tcp_conn != -1); assert(zone->tcp_waiting == 0); + /* make sure we have a master to query the xfr request to */ + assert(zone->master); /* start AXFR or IXFR for the zone */ if(zone->soa_disk_acquired == 0 || zone->master->use_axfr_only || zone->master->ixfr_disabled || @@ -1252,8 +1271,8 @@ int conn_write(struct xfrd_tcp* tcp) } tcp->total_bytes += sent; - if(sent > (ssize_t)sizeof(tcp->msglen)) - buffer_skip(tcp->packet, sent-sizeof(tcp->msglen)); + if(tcp->total_bytes > (ssize_t)sizeof(tcp->msglen)) + buffer_skip(tcp->packet, tcp->total_bytes-sizeof(tcp->msglen)); if(tcp->total_bytes < sizeof(tcp->msglen)) { /* incomplete write, resume later */ return 0; Index: usr.sbin/nsd/xfrd-tcp.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/xfrd-tcp.h,v diff -u -p -r1.6 xfrd-tcp.h --- usr.sbin/nsd/xfrd-tcp.h 6 Sep 2025 17:41:37 -0000 1.6 +++ usr.sbin/nsd/xfrd-tcp.h 21 Sep 2026 16:28:43 -0000 @@ -187,6 +187,8 @@ struct xfrd_tcp* xfrd_tcp_create(struct void xfrd_tcp_obtain(struct xfrd_tcp_set* set, struct xfrd_zone* zone); /* release tcp connection for a zone (starts waiting) */ void xfrd_tcp_release(struct xfrd_tcp_set* set, struct xfrd_zone* zone); +/* remove zone from tcp waiting list */ +void tcp_zone_waiting_list_remove(struct xfrd_zone* z); /* release tcp pipe entirely (does not stop the zones inside it) */ void xfrd_tcp_pipe_release(struct xfrd_tcp_set* set, struct xfrd_tcp_pipeline* tp, int conn); Index: usr.sbin/nsd/xfrd.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/xfrd.c,v diff -u -p -r1.36 xfrd.c --- usr.sbin/nsd/xfrd.c 21 Mar 2026 21:36:36 -0000 1.36 +++ usr.sbin/nsd/xfrd.c 21 Sep 2026 16:28:43 -0000 @@ -703,6 +703,7 @@ xfrd_process_soa_info_task(struct task_l zone_type* dbzone = NULL; xfrd_xfr_type* xfr; xfrd_xfr_type* prev_xfr; + int xfr_was_ixfr = 0; enum soainfo_hint hint; #ifndef NDEBUG time_t before; @@ -825,6 +826,10 @@ xfrd_process_soa_info_task(struct task_l dbzone = namedb_find_or_create_zone( xfrd->nsd->db, task->zname , consumer_zone->options); } + if(zone->latest_xfr) { + xfr_was_ixfr = (zone->latest_xfr->query_type == TYPE_IXFR); + } + /* soainfo_gone and soainfo_bad are straightforward, delete all updates that were transfered, i.e. acquired != 0. soainfo_ok is more complicated as it is possible that there are subsequent corrupt or @@ -913,6 +918,28 @@ xfrd_process_soa_info_task(struct task_l break; /* fall through */ case soainfo_gone: + if(hint == soainfo_gone) { + /* "rollback" on-disk soa information */ + zone->soa_disk_acquired = zone->soa_nsd_acquired; + zone->soa_disk = zone->soa_nsd; + } + if(hint == soainfo_gone && !soa_ptr) { + if(xfr_was_ixfr) { + /* Attempt without IXFR, maybe AXFR works. */ + xfrd_disable_ixfr(zone); + xfrd_set_zone_state(zone, xfrd_zone_refreshing); + xfrd_set_refresh_now(zone); + break; + } + /* The zone transfer update failed to apply. + * Okay to fallback from IXFR to AXFR, but after failed + * AXFR, wait for retry instead of immediate fetch */ + VERBOSITY(2, (LOG_INFO, "xfrd: zone %s transfer " + "failed to apply, waiting for retry", + zone->apex_str)); + xfrd_set_timer_retry(zone); + break; + } xfrd_handle_incoming_soa(zone, soa_ptr, acquired); break; } @@ -1019,24 +1046,8 @@ xfrd_deactivate_zone(xfrd_zone_type* z) } void -xfrd_del_slave_zone(xfrd_state_type* xfrd, const dname_type* dname) +udp_zone_waiting_list_remove(xfrd_zone_type* z) { - xfrd_zone_type* z = (xfrd_zone_type*)rbtree_delete(xfrd->zones, dname); - if(!z) return; - - /* io */ - if(z->tcp_waiting) { - /* delete from tcp waiting list */ - if(z->tcp_waiting_prev) - z->tcp_waiting_prev->tcp_waiting_next = - z->tcp_waiting_next; - else xfrd->tcp_set->tcp_waiting_first = z->tcp_waiting_next; - if(z->tcp_waiting_next) - z->tcp_waiting_next->tcp_waiting_prev = - z->tcp_waiting_prev; - else xfrd->tcp_set->tcp_waiting_last = z->tcp_waiting_prev; - z->tcp_waiting = 0; - } if(z->udp_waiting) { /* delete from udp waiting list */ if(z->udp_waiting_prev) @@ -1049,6 +1060,23 @@ xfrd_del_slave_zone(xfrd_state_type* xfr else xfrd->udp_waiting_last = z->udp_waiting_prev; z->udp_waiting = 0; } +} + +void +xfrd_del_slave_zone(xfrd_state_type* xfrd, const dname_type* dname) +{ + xfrd_zone_type* z = (xfrd_zone_type*)rbtree_delete(xfrd->zones, dname); + if(!z) return; + + /* io */ + if(z->tcp_waiting) { + /* delete from tcp waiting list */ + tcp_zone_waiting_list_remove(z); + } + if(z->udp_waiting) { + /* delete from udp waiting list */ + udp_zone_waiting_list_remove(z); + } xfrd_deactivate_zone(z); if(z->tcp_conn != -1) { xfrd_tcp_release(xfrd->tcp_set, z); @@ -1251,6 +1279,16 @@ xfrd_make_request(xfrd_zone_type* zone) if(zone->round_num >= XFRD_MAX_ROUNDS) { /* tried all servers that many times, wait */ zone->round_num = -1; + /* Discard NOTIFY serial hint. After one round of + * searching for it, at the upstream primaries, the + * notify hint need no longer be used. The retry + * timer is used, for one, earlier re-attempt. This + * is useful if the upstream is in-progress of loading + * the zone information. After the brief wait it may + * have completed that task. And this may catch the + * case where it notify is sent before the load + * activity has completed at the primary. */ + zone->soa_notified_acquired = 0; xfrd_set_timer_retry(zone); DEBUG(DEBUG_XFRD,1, (LOG_INFO, "xfrd zone %s makereq wait_retry, rd %d mr %d nx %d", @@ -1629,6 +1667,9 @@ xfrd_udp_read_packet(buffer_type* packet log_msg(LOG_ERR, "xfrd: recvfrom failed: %s", strerror(errno)); return 0; + } else if(received < QHEADERSZ) { + log_msg(LOG_ERR, "xfrd: UDP packet too small"); + return 0; } buffer_set_limit(packet, received); return 1; @@ -1984,6 +2025,8 @@ static int xfrd_parse_soa_info(buffer_ty { return 0; } + if(!buffer_available(packet, 20)) + return 0; soa->serial = htonl(buffer_read_u32(packet)); soa->refresh = htonl(buffer_read_u32(packet)); soa->retry = htonl(buffer_read_u32(packet)); @@ -2008,12 +2051,13 @@ xfrd_xfr_check_rrs(xfrd_zone_type* zone, /* first RR has already been checked */ const struct nsd_type_descriptor *descriptor; uint32_t tmp_serial = 0; - uint16_t type, rrlen; + uint16_t type, klass, rrlen; size_t i, soapos, mempos; const dname_type* dname; struct rr* rr; int32_t code; domain_table_type* owners; + enum { DELETING_RRs = 0, ADDING_RRs } ixfr_state = DELETING_RRs; for(i=0; ilatest_xfr->msg_rr_count) { @@ -2038,7 +2082,15 @@ xfrd_xfr_check_rrs(xfrd_zone_type* zone, } soapos = buffer_position(packet); type = buffer_read_u16(packet); - (void)buffer_read_u16(packet); /* class */ + klass = buffer_read_u16(packet); + if(klass != CLASS_IN && type != TYPE_OPT) { + log_msg(LOG_ERR, "xfrd: zone %s xfr " + "non-IN-class RR (%s type=%s class=%s), rejected", + zone->apex_str, dname_to_string(dname,0), + rrtype_to_string(type), + rrclass_to_string(klass)); + return 0; + } (void)buffer_read_u32(packet); /* ttl */ rrlen = buffer_read_u16(packet); if(!buffer_available(packet, rrlen)) { @@ -2082,6 +2134,7 @@ xfrd_xfr_check_rrs(xfrd_zone_type* zone, } zone->latest_xfr->msg_old_serial = ntohl(soa->serial); tmp_serial = ntohl(soa->serial); + ixfr_state = DELETING_RRs; } else if(ntohl(soa->serial) == zone->latest_xfr->msg_new_serial) { /* saw another SOA of new serial. */ @@ -2104,13 +2157,44 @@ xfrd_xfr_check_rrs(xfrd_zone_type* zone, "serial decreasing not allowed", zone->apex_str)); return 0; /* middle serial decreases in IXFR */ } + if(ntohl(soa->serial) == tmp_serial) { + if(ixfr_state == DELETING_RRs) { + DEBUG(DEBUG_XFRD,1, ( LOG_ERR, "xfrd: zone %s xfr serial duplicate " + "not allowed for serial %"PRIu32" while %s", + zone->apex_str, tmp_serial, + ( ixfr_state == DELETING_RRs + ? "deleting RRs" : "adding RRs"))); + return 0; /* middle serial is the same as the previous in IXFR */ + } + ixfr_state = DELETING_RRs; + } else { + assert(ntohl(soa->serial) > tmp_serial); + ixfr_state = ADDING_RRs; + } /* serial ok, update tmp serial */ tmp_serial = ntohl(soa->serial); } + else { + /* AXFR mode, rr_count>1, serial!=new_serial, + * RFC 5936 s2.2 forbids SOA in a non-terminal + * position with a different serial. Reject + * the stream. */ + DEBUG(DEBUG_XFRD,1, (LOG_ERR, "xfrd: zone %s axfr " + "unexpected mid-stream SOA serial %u", + zone->apex_str, + (unsigned)ntohl(soa->serial))); + return 0; /* SOA in middle of AXFR */ + } } buffer_set_position(packet, mempos); buffer_skip(packet, rrlen); } + if(buffer_position(packet) != buffer_limit(packet)) { + DEBUG(DEBUG_XFRD,1, (LOG_ERR, "xfrd: zone %s xfr bad, " + "trailing data %d bytes", zone->apex_str, + (int)(buffer_limit(packet)-buffer_position(packet)))); + return 0; /* trailing data */ + } /* packet seems to have a valid DNS RR structure */ return 1; } @@ -2628,6 +2712,7 @@ xfrd_handle_received_xfr_packet(xfrd_zon zone->latest_xfr->xfrfilenumber)) { zone->latest_xfr->sent = xfrd->nsd->mytask + 1; + xfrd->num_xfrs_in_reload++; } /* reset msg seq nr, so if that is nonnull we know xfr file exists */ zone->latest_xfr->msg_seq_nr = 0; @@ -2732,6 +2817,12 @@ xfrd_handle_notify_and_start_xfr(xfrd_zo } } +struct xfrd_zone* +xfrd_find_zone(xfrd_state_type* xfrd, const dname_type* dname) +{ + return (xfrd_zone_type*)rbtree_search(xfrd->zones, dname); +} + void xfrd_handle_passed_packet(buffer_type* packet, int acl_num, int acl_num_xfr) @@ -2942,6 +3033,8 @@ xfrd_prepare_zones_for_reload(void) xfr->msg_old_serial, xfr->msg_new_serial, xfr->xfrfilenumber); + if(send) + xfrd->num_xfrs_in_reload++; if(send && !reload) { reload = 1; xfrd_set_reload_timeout(); Index: usr.sbin/nsd/xfrd.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/xfrd.h,v diff -u -p -r1.15 xfrd.h --- usr.sbin/nsd/xfrd.h 21 Mar 2026 21:36:36 -0000 1.15 +++ usr.sbin/nsd/xfrd.h 21 Sep 2026 16:28:43 -0000 @@ -85,6 +85,8 @@ struct xfrd_state { uint8_t reload_failed; uint8_t can_send_reload; pid_t reload_pid; + int num_reload_failed_repeat; + int num_xfrs_in_reload; /* timeout for lost sigchild and reaping children */ struct event child_timer; int child_timer_added; @@ -389,6 +391,8 @@ void xfrd_set_timer(xfrd_zone_type* zone void xfrd_set_refresh_now(xfrd_zone_type* zone); /* unset the timer - no more timeouts, for when zone is queued */ void xfrd_unset_timer(xfrd_zone_type* zone); +/* remove the zone from the udp waiting list */ +void udp_zone_waiting_list_remove(xfrd_zone_type* z); /* remove the 'refresh now', remove it from the activated list */ void xfrd_deactivate_zone(xfrd_zone_type* z); @@ -487,5 +491,9 @@ const char* xfrd_pretty_time(time_t v); xfrd_xfr_type *xfrd_prepare_zone_xfr(xfrd_zone_type *zone, uint16_t query_type); void xfrd_delete_zone_xfr(xfrd_zone_type *zone, xfrd_xfr_type *xfr); + +/* Find zone by name. */ +struct xfrd_zone* xfrd_find_zone(xfrd_state_type* xfrd, + const dname_type* dname); #endif /* XFRD_H */ Index: usr.sbin/nsd/dnstap/dnstap.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/dnstap/dnstap.c,v diff -u -p -r1.7 dnstap.c --- usr.sbin/nsd/dnstap/dnstap.c 3 Sep 2025 18:46:48 -0000 1.7 +++ usr.sbin/nsd/dnstap/dnstap.c 21 Sep 2026 16:28:43 -0000 @@ -353,27 +353,37 @@ dt_tls_writer_open(void* obj) } if(connect(dtw->fd, (struct sockaddr*)&addr, addrlen) < 0) { log_msg(LOG_ERR, "dnstap: connect failed: %s", strerror(errno)); + close(dtw->fd); + dtw->fd = -1; return fstrm_res_failure; } - dtw->connected = 1; /* setup SSL */ dtw->ssl = SSL_new(dtw->ctx); if(!dtw->ssl) { log_msg(LOG_ERR, "dnstap: SSL_new failed"); + close(dtw->fd); + dtw->fd = -1; return fstrm_res_failure; } SSL_set_connect_state(dtw->ssl); (void)SSL_set_mode(dtw->ssl, SSL_MODE_AUTO_RETRY); if(!SSL_set_fd(dtw->ssl, dtw->fd)) { log_msg(LOG_ERR, "dnstap: SSL_set_fd failed"); +res_failure: + if(dtw->ssl) + SSL_shutdown(dtw->ssl); + SSL_free(dtw->ssl); + dtw->ssl = NULL; + close(dtw->fd); + dtw->fd = -1; return fstrm_res_failure; } if(dtw->tls_server_name && dtw->tls_server_name[0]) { if(!SSL_set1_host(dtw->ssl, dtw->tls_server_name)) { log_msg(LOG_ERR, "dnstap: TLS setting of hostname %s failed to %s", dtw->tls_server_name, dtw->ip); - return fstrm_res_failure; + goto res_failure; } } @@ -387,14 +397,14 @@ dt_tls_writer_open(void* obj) if(r != SSL_ERROR_WANT_READ && r != SSL_ERROR_WANT_WRITE) { if(r == SSL_ERROR_ZERO_RETURN) { log_msg(LOG_ERR, "dnstap: EOF on SSL_do_handshake"); - return fstrm_res_failure; + goto res_failure; } if(r == SSL_ERROR_SYSCALL) { log_msg(LOG_ERR, "dnstap: SSL_do_handshake failed: %s", strerror(errno)); - return fstrm_res_failure; + goto res_failure; } log_crypto_err("dnstap: SSL_do_handshake failed"); - return fstrm_res_failure; + goto res_failure; } /* wants to be called again */ } @@ -402,7 +412,7 @@ dt_tls_writer_open(void* obj) /* check authenticity of server */ if(SSL_get_verify_result(dtw->ssl) != X509_V_OK) { log_crypto_err("SSL verification failed"); - return fstrm_res_failure; + goto res_failure; } #ifdef HAVE_SSL_GET1_PEER_CERTIFICATE x = SSL_get1_peer_certificate(dtw->ssl); @@ -411,9 +421,10 @@ dt_tls_writer_open(void* obj) #endif if(!x) { log_crypto_err("Server presented no peer certificate"); - return fstrm_res_failure; + goto res_failure; } X509_free(x); + dtw->connected = 1; return fstrm_res_success; } Index: usr.sbin/nsd/doc/ChangeLog =================================================================== RCS file: /cvs/src/usr.sbin/nsd/doc/ChangeLog,v diff -u -p -r1.21 ChangeLog --- usr.sbin/nsd/doc/ChangeLog 21 Mar 2026 21:36:36 -0000 1.21 +++ usr.sbin/nsd/doc/ChangeLog 21 Sep 2026 16:28:43 -0000 @@ -1,3 +1,270 @@ +28 August 2026: Willem + - Fix client certificate checking by linking the tls-auth-name + requirement on an access control list item, to the other requirements + (IP address and/or TSIG key) on the same list item. + Thanks to voguemerry for the report + +24 August 2026: Willem + - Merge #502: An `udp-padding-port` configuration file option to enable + responding to the padding option on UDP, but on specific ports only. + This is convenient for setups where NSD is behind a frontend handling + the DNS over TLS. + - `--enable-multiple-catalog-zones` option to configure to enable + experimental support for multiple catalog consumer zones. + +19 August 2026: Willem + - Continue with 4.15.2 for development + +17 August 2026: Willem + - Fix for CVE-2026-18664: IP range access control restrictions are + bypassed for some unintended IP. + Thanks to Qifan Zhang, Palo Alto Networks for the report + https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18664.txt + - Fix for CVE-2026-18916: Any remote client can denial TCP service by + throttling the TCP receive window (down to 1). + Thanks to Qifan Zhang, Palo Alto Networks for the report + https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt + - Fix for CVE-2026-19401: Any remote client can denial UDP service by + sending a specifically crafted query with multiple DNS Cookie options. + Thanks to Qifan Zhang, Palo Alto Networks for the report + https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt + - Fix for CVE-2026-19538: Anyone with access to the proxy protocol port + over TCP or TLS can bypass BLOCKED access control items. + Thanks to Qifan Zhang, Palo Alto Networks for the report + https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txt + +14 August 2026: Willem + - Fix to ignore NSEC3 records with malformed owner name. In depth fix + to clear key for NSEC3 tree collisions. And a fix to limit the + reenactment of failed reloads, that ordinarily marks transfers as + corrupt, so that for crashes it waits with that zone for retry. This + allows other zones to update in the meantime. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix nsd-control reconfig so that change of a secondary zone while it + is on the udp or tcp waiting list does not crash after that. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix to reset the length of the incoming packet buffer after a failed + PROXYv2 header on UDP. It can cause an assertion failure on the next + packet. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix XoT transfer authentication to not fall back to the common name + if a DNS name is present in the certificate. This fixes the RFC6125 + conformance. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix dnstap over TLS certificate check for reconnection. Also clean up + file descriptor and SSL state on connection failures. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + +3 August 2026: Willem + - An `allow-proxy` configuration file option to specify allow access + control list for the PROXYv2 protocol port. + Thanks to Qifan Zhang, Palo Alto Networks, for the suggestion. + - Fix to prevent a configured primary from hampering loading its own + zone by providing a transfer with the OPT RR in the answer section + and the UDP Payload size (i.e. class) of the OPT RR set to something + else than 1 (IN). + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + +29 July 2026: Wouter + - Fix that when DNAME is limited due to the maximum CNAME chain + length, it copies the final DNAME with its CNAME into the + packet. Also fix unit test for limit on CNAME chain length. + +16 July 2026: Willem + - Merge #500: Support for the "oots" SVCB Service Parameter Key + +15 July 2026: Willem + - Merge #498: Support for the HHIT and BRID RR types + - Merge #499: Support for the "docpath" and "pvd" + SVCB Service Parameter Keys + +14 July 2026: Willem + - Fix that IXFR queries with overly large SOA records do not cause an + assertion failure in the server child process. The malformed SOA + record is rejected with FORMERR. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix that notify ahead of the zone serial does not cause perpetual + retransfer. After one round, and after another retry, it gives up, + and forgets the notified serial number. This allows the primary a + moment to retrieve the new zone version. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix that AXFR out for a zone with an oversize record does not loop. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix that IXFR out for a zone with an oversize record does not loop. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix serve childs crashing when queried for a very long CNAME chain + on ASAN builds. The maximum CNAME chain in responses is set to 18. + The value can be configured with the --with-max-cname-chain=number + option to configure. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix to have failed zone transfers retry after a time, instead of in a + loop, for transfers with failed contents. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix that an increase verbosity level is needed to warn about unfound + RRs to be deleted (from IXFR). Verbosity 2 for unfound RRsets and + unfound RDATA. Verbosity 3 to log which RR in the existing set does + not match. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix to ignore NSEC3s with wrong non-base32hex chars in owner label. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix Y2038 bug, where the server process would fail with undefined + behaviour, if it was built with address sanitizer undefined checks + enabled, for the timestamp in EDNS cookies. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix to not let `nsd-control zonestatus` crash the xfrd processes + when configured with multiple catalog consumers. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + +13 July 2026: Wouter + - Merge #496 from maertsen: Fix allow-query syntax in catalog + documentation. + +8 July 2026: Willem + - Merge #494: RFC 7830 EDNS0 padding option support with DoT + With padding suggestions from RFC 8467 for responses + Thanks kdrenard for the suggestion + +7 July 2026: Willem + - Merge the NSD 4.15.0 release into master. + - Continue with 4.15.1 for development + +7 July 2026: Wouter + - (part of 4.15.1): + - Merge #495 from ruuda: Include inttypes.h from metrics.c. + +29 June 2026: Jannik + - Merge #483 from ruuda: Improve Prometheus metrics: Move zonestats from + metric name to label + +2g June 2026: Willem + - Fix nsd-control assoc_tsig, if that interrupts a zone transfer in + progress, to not crash. It restarts the transfer from the primary. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix nsd-control del_tsig, if that interrupts a zone transfer in + progress, to not crash. It does not delete the key, if in use. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix catalog producer zone with long name, so that it does not crash + on that. Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix catalog consumer zone with long name for member unique label that + is long, so that it does not crash on that. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix that non-IN-class records cause a zone transfer to be rejected. + Also such records are not added from a transfer. This stops an + assertion failure. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix to disallow a SOA record in the middle of an AXFR. This stops an + assertion failure. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix to set zone is_secure to false when IXFR removes RRSIG DNSKEY. + This stops an assertion failure. Also fix soa and ns rrset change in + IXFR when packed rrsets are disabled. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix to handle NSEC3 zones without space for hashes. Zones with a apex + domain name length >= 223 bytes, that have a NSEC3PARAM must not be + prehashed, since the hashed owner name would not fit. + Thanks Qifan Zhang, Palo Alto Networks, for the report + - Fix to add hardening to zone_ixfr_remove_oldest, for IXFR processing. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix for xfrd crash with too short response to a UDP SOA query + Only for release builds and only when configured for XFR over UDP + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix that out-of-zone records are skipped from zone transfers. + Otherwise such records could stick around after zone deletion and + cause failures for DS queries. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + +25 June 2026: Willem + - Merge the NSD version 4.14.3 security release branch into master. + - Continue with 4.14.4 for development + +24 June 2026: Willem + - Fix for CVE-2026-12244: A specially crafted SVCB RR can cause a heap + overflow of up to 65509 attacker controlled bytes. + Thanks to Qifan Zhang, Palo Alto Networks for the report + https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12244.txt + - Fix for CVE-2026-12245: If NSD is configured with DNS over TLS, a + client that performs a TLS action, closing the connection early, + causes a crash and restart of the server process. An attacker can + keep all children in a crash-restart loop denying DoT service. + Thanks to Qifan Zhang, Palo Alto Networks for the report. + https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12245.txt + - Fix for CVE-2026-12246: The RR type APL rdata address, if too large, + causes out of bounds write on the stack, when the zonefile is written + out. Thanks to Qifan Zhang from Palo Alto Networks, Haruki Oyama from + Waseda University and zhangph for the report. + https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12246.txt + - Fix for CVE-2026-12490: Secondaries authenticated by a client + certificate to transfer a zone over TLS, can bypass verification by + transferring over TCP. + Thanks to Qifan Zhang, Palo Alto Networks for the report. + https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12490.txt + +22 Jun 2026: Willem + - More robust removing of RRs from an IXFR processing. + Thanks zhangph for reporting this issue + +22 Jun 2026: Wouter + - Fix unit test for stopmany for process role logs. + +22 Jun 2026: Willem + - Fix that wrong buffer position in IXFR for the first SOA causes the + storage to retrieve wrong information. Later data would overwrite it + so it did not cause observable trouble. Thanks to Tristan Madani + (@TristanInSec) from Talence Security for the report. + +22 Jun 2026: Willem + - Fix notify and zone transfer processing for malformed SOA records, + with a short rdata content. It stops an assertion failure. Thanks to + Tristan Madani (@TristanInSec) from Talence Security for the report. + +19 Jun 2026: Wouter + - Fix to update github ci actions/checkout to v7. + +18 Jun 2026: Willem + - Fix overflow for NSEC3 zones with 255-octet name + Thanks to Haruki Oyama (Waseda University) for the report, and + Qifan Zhang, Palo Alto Networks, for also reporting this issue. + +15 Jun 2026: Willem + - Fix print of NXT RR without bitmap + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + +15 Jun 2026: Willem + - Fix to not fail on NSEC3 records with a bad owner name. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + +15 Jun 2026: Willem + - Fix print of malformed HIP records. + Thanks to Qifan Zhang, Palo Alto Networks, for the report, and + Haruki Oyama (Waseda University) for also reporting this issue. + +15 Jun 2026: Willem + - Fix notify relay ipc to check for large size. + This stops desync of the internal notify pipe. + Thanks to Qifan Zhang, Palo Alto Networks for the report. + +15 Jun 2026: Willem + - Fix PROXYv2 header read and consume, it checks the header size. + Thanks to Qifan Zhang, Palo Alto Networks for the report. + +12 May 2026: Jannik + - Merge #484 from orlitzky: OpenRC: fix network deps and support both + supervisors + +24 April 2026: Jannik + - Merge #481 from jaredmauch: Fix pedantic/CodeQL warning in sources + +14 April 2026: Jannik + - Fix XDP cleanup code being executed even if xdp is not configured + +25 March 2026: Wouter + - Fix #478: Feature request: reduce syslog noise from frequent + read-only control commands (e.g. stats_noreset). It logs the + verbosity command always, and others at 2 and higher. + +19 March 2026: Jannik + - Continue with 4.14.3 for development + 11 March 2026: Wouter - Fix in IXFR processing, to commit the collected RRs before deletions. Index: usr.sbin/nsd/doc/README =================================================================== RCS file: /cvs/src/usr.sbin/nsd/doc/README,v diff -u -p -r1.11 README --- usr.sbin/nsd/doc/README 21 Mar 2026 21:36:36 -0000 1.11 +++ usr.sbin/nsd/doc/README 21 Sep 2026 16:28:43 -0000 @@ -21,7 +21,7 @@ 1.0 Introduction -This is NSD Name Server Daemon (NSD) version 4.14.2. +This is NSD Name Server Daemon (NSD) version 4.15.2. The NLnet Labs Name Server Daemon (NSD) is an authoritative RFC compliant DNS nameserver. It was first conceived to allow for more genetic @@ -57,7 +57,7 @@ and uses a simple configuration file 'ns 1.2 Quick build and install -Step 1: Unpack the source with gtar -xzvf nsd-4.14.2.tar.gz +Step 1: Unpack the source with gtar -xzvf nsd-4.15.2.tar.gz Step 2: Create user nsd or any other unprivileged user of your choice. In case of later make sure to use @@ -111,9 +111,9 @@ Step 11: If desired add 'nsd-control wri Use your favorite combination of tar and gnu zip to unpack the source, for example -$ gtar -xzvf nsd-4.14.2.tar.gz +$ gtar -xzvf nsd-4.15.2.tar.gz -will unpack the source into the ./nsd-4.14.2 directory... +will unpack the source into the ./nsd-4.15.2 directory... 2.2 Configuring NSD @@ -926,4 +926,4 @@ larger and regular donations please cont see http://www.nlnetlabs.nl/labs/contributors/. -$Id: README,v 1.11 2026/03/21 21:36:36 sthen Exp $ +$Id: README,v 1.14 2026/09/21 08:41:19 sthen Exp $ Index: usr.sbin/nsd/doc/RELNOTES =================================================================== RCS file: /cvs/src/usr.sbin/nsd/doc/RELNOTES,v diff -u -p -r1.19 RELNOTES --- usr.sbin/nsd/doc/RELNOTES 21 Mar 2026 21:36:36 -0000 1.19 +++ usr.sbin/nsd/doc/RELNOTES 21 Sep 2026 16:28:43 -0000 @@ -1,5 +1,217 @@ NSD RELEASE NOTES +4.15.2 +================ +FEATURES: + - Merge #494: RFC 7830 EDNS0 padding option support with DoT + With padding suggestions from RFC 8467 for responses + Thanks kdrenard for the suggestion + - Merge #498: Support for the HHIT and BRID RR types + - Merge #499: Support for the "docpath" and "pvd" + SVCB Service Parameter Keys + - Merge #500: Support for the "oots" SVCB Service Parameter Key + - An `allow-proxy` configuration file option to specify allow access + control list for the PROXYv2 protocol port. + Thanks to Qifan Zhang, Palo Alto Networks, for the suggestion. + - Merge #502: An `udp-padding-port` configuration file option to enable + responding to the padding option on UDP, but on specific ports only. + This is convenient for setups where NSD is behind a frontend handling + the DNS over TLS. + - `--enable-multiple-catalog-zones` option to configure to enable + experimental support for multiple catalog consumer zones. + +BUG FIXES: + - Merge #495 from ruuda: Include inttypes.h from metrics.c. + - Merge #496 from maertsen: Fix allow-query syntax in catalog + documentation. + - Fix that IXFR queries with overly large SOA records do not cause an + assertion failure in the server child process. The malformed SOA + record is rejected with FORMERR. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix that notify ahead of the zone serial does not cause perpetual + retransfer. After one round, and after another retry, it gives up, + and forgets the notified serial number. This allows the primary a + moment to retrieve the new zone version. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix that AXFR out for a zone with an oversize record does not loop. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix that IXFR out for a zone with an oversize record does not loop. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix serve childs crashing when queried for a very long CNAME chain + on ASAN builds. The maximum CNAME chain in responses is set to 18. + The value can be configured with the --with-max-cname-chain=number + option to configure. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix to have failed zone transfers retry after a time, instead of in a + loop, for transfers with failed contents. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix that an increase verbosity level is needed to warn about unfound + RRs to be deleted (from IXFR). Verbosity 2 for unfound RRsets and + unfound RDATA. Verbosity 3 to log which RR in the existing set does + not match. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix to ignore NSEC3s with wrong non-base32hex chars in owner label. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix Y2038 bug, where the server process would fail with undefined + behaviour, if it was built with address sanitizer undefined checks + enabled, for the timestamp in EDNS cookies. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix to not let `nsd-control zonestatus` crash the xfrd processes + when configured with multiple catalog consumers. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix to prevent a configured primary from hampering loading its own + zone by providing a transfer with the OPT RR in the answer section + and the UDP Payload size (i.e. class) of the OPT RR set to something + else than 1 (IN). + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix to ignore NSEC3 records with malformed owner name. In depth fix + to clear key for NSEC3 tree collisions. And a fix to limit the + reenactment of failed reloads, that ordinarily marks transfers as + corrupt, so that for crashes it waits with that zone for retry. This + allows other zones to update in the meantime. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix nsd-control reconfig so that change of a secondary zone while it + is on the udp or tcp waiting list does not crash after that. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix to reset the length of the incoming packet buffer after a failed + PROXYv2 header on UDP. It can cause an assertion failure on the next + packet. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix XoT transfer authentication to not fall back to the common name + if a DNS name is present in the certificate. This fixes the RFC6125 + conformance. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix dnstap over TLS certificate check for reconnection. Also clean up + file descriptor and SSL state on connection failures. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix client certificate checking by linking the tls-auth-name + requirement on an access control list item, to the other requirements + (IP address and/or TSIG key) on the same list item. + Thanks to voguemerry for the report + +4.15.1 +================ +FEATURES: +BUG FIXES: + - Fix for CVE-2026-18664: IP range access control restrictions are + bypassed for some unintended IP. + Thanks to Qifan Zhang, Palo Alto Networks for the report + Thanks to Claude and Ada Logics for the report + https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18664.txt + - Fix for CVE-2026-18916: Any remote client can denial TCP service by + throttling the TCP receive window (down to 1). + Thanks to Akhil Koul (https://github.com/akoul) for the report + https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt + - Fix for CVE-2026-19401: Any remote client can denial UDP service by + sending a specifically crafted query with multiple DNS Cookie options. + Thanks to Qifan Zhang, Palo Alto Networks for the report + Thanks to afldl for the report + https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt + - Fix for CVE-2026-19538: Anyone with access to the proxy protocol port + over TCP or TLS can bypass BLOCKED access control items. + Thanks to Qifan Zhang, Palo Alto Networks for the report + https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txt + +4.15.0 +================ +FEATURES: + - Merge #483 from ruuda: Improve Prometheus metrics: Move zonestats from + metric name to label +BUG FIXES: + - Fix #478: Feature request: reduce syslog noise from frequent + read-only control commands (e.g. stats_noreset). It logs the + verbosity command always, and others at 2 and higher. + - Fix XDP cleanup code being executed even if xdp is not configured + - Merge #481 from jaredmauch: Fix pedantic/CodeQL warning in sources + - Merge #484 from orlitzky: OpenRC: fix network deps and support both + supervisors + - Fix PROXYv2 header read and consume, it checks the header size. + Thanks to Qifan Zhang, Palo Alto Networks for the report. + - Fix notify relay ipc to check for large size. + This stops desync of the internal notify pipe. + Thanks to Qifan Zhang, Palo Alto Networks for the report. + - Fix print of malformed HIP records. + Thanks to Qifan Zhang, Palo Alto Networks, for the report, and + Haruki Oyama (Waseda University) for also reporting this issue. + - Fix to not fail on NSEC3 records with a bad owner name. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix print of NXT RR without bitmap + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix overflow for NSEC3 zones with 255-octet name + Thanks to Haruki Oyama (Waseda University) for the report, and + Qifan Zhang, Palo Alto Networks, for also reporting this issue. + - Fix to update github ci actions/checkout to v7. + - Fix notify and zone transfer processing for malformed SOA records, + with a short rdata content. It stops an assertion failure. Thanks to + Tristan Madani (@TristanInSec) from Talence Security for the report. + - Fix that wrong buffer position in IXFR for the first SOA causes the + storage to retrieve wrong information. Later data would overwrite it + so it did not cause observable trouble. Thanks to Tristan Madani + (@TristanInSec) from Talence Security for the report. + - More robust removing of RRs from an IXFR processing. + Thanks zhangph for reporting this issue + - Fix unit test for stopmany for process role logs. + - Fix nsd-control assoc_tsig, if that interrupts a zone transfer in + progress, to not crash. It restarts the transfer from the primary. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix nsd-control del_tsig, if that interrupts a zone transfer in + progress, to not crash. It does not delete the key, if in use. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix catalog producer zone with long name, so that it does not crash + on that. Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix catalog consumer zone with long name for member unique label that + is long, so that it does not crash on that. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix that non-IN-class records cause a zone transfer to be rejected. + Also such records are not added from a transfer. This stops an + assertion failure. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix to disallow a SOA record in the middle of an AXFR. This stops an + assertion failure. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix to set zone is_secure to false when IXFR removes RRSIG DNSKEY. + This stops an assertion failure. Also fix soa and ns rrset change in + IXFR when packed rrsets are disabled. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix to handle NSEC3 zones without space for hashes. Zones with a apex + domain name length >= 223 bytes, that have a NSEC3PARAM must not be + prehashed, since the hashed owner name would not fit. + Thanks Qifan Zhang, Palo Alto Networks, for the report + - Fix to add hardening to zone_ixfr_remove_oldest, for IXFR processing. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix for xfrd crash with too short response to a UDP SOA query + Only for release builds and only when configured for XFR over UDP + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + - Fix that out-of-zone records are skipped from zone transfers. + Otherwise such records could stick around after zone deletion and + cause failures for DS queries. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + +4.14.3 +================ +FEATURES: +BUG FIXES: + - Fix for CVE-2026-12244: A specially crafted SVCB RR can cause a heap + overflow of up to 65509 attacker controlled bytes. + Thanks to Qifan Zhang, Palo Alto Networks for the report + https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12244.txt + - Fix for CVE-2026-12245: If NSD is configured with DNS over TLS, a + client that performs a TLS action, closing the connection early, + causes a crash and restart of the server process. An attacker can + keep all children in a crash-restart loop denying DoT service. + Thanks to Qifan Zhang, Palo Alto Networks for the report. + https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12245.txt + - Fix for CVE-2026-12246: The RR type APL rdata address, if too large, + causes out of bounds write on the stack, when the zonefile is written + out. Thanks to Qifan Zhang from Palo Alto Networks, Haruki Oyama from + Waseda University and zhangph for the report. + https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12246.txt + - Fix for CVE-2026-12490: Secondaries authenticated by a client + certificate to transfer a zone over TLS, can bypass verification by + transferring over TCP. + Thanks to Qifan Zhang, Palo Alto Networks for the report. + https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12490.txt + 4.14.2 ================ FEATURES: Index: usr.sbin/nsd/simdzone/CHANGELOG.md =================================================================== RCS file: /cvs/src/usr.sbin/nsd/simdzone/CHANGELOG.md,v diff -u -p -r1.1.1.3 CHANGELOG.md --- usr.sbin/nsd/simdzone/CHANGELOG.md 21 Mar 2026 21:34:33 -0000 1.1.1.3 +++ usr.sbin/nsd/simdzone/CHANGELOG.md 21 Sep 2026 16:28:43 -0000 @@ -5,6 +5,31 @@ All notable changes to simdzone will be The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). +## [0.2.6] - 2026-09-02 + +### Added + +- Support for the HHIT and BRID RR types. +- Support for the "docpath", "pvd" and "oots" SVCB Service Parameters + +### Fixed + +- TXT records with more than 6465 rdata elements, crashes simdzone parsing. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. +- Fix unit test implicit conversion change of signedness warning. +- Fix unit test delimiters_overflow_txt to add block size padding for simd + operations. + +## [0.2.5] - 2026-07-07 + +### Added + +- Add riscv fallback detection (#261) + +### Fixed + +- Fix to parse SVCB and HTTPS svcparam ech=0. + ## [0.2.4] - 2025-12-04 ### Added Index: usr.sbin/nsd/simdzone/README.md =================================================================== RCS file: /cvs/src/usr.sbin/nsd/simdzone/README.md,v diff -u -p -r1.1.1.1 README.md --- usr.sbin/nsd/simdzone/README.md 3 Sep 2025 18:44:23 -0000 1.1.1.1 +++ usr.sbin/nsd/simdzone/README.md 21 Sep 2026 16:28:43 -0000 @@ -1,6 +1,7 @@ ![Build Status](https://github.com/NLnetLabs/simdzone/actions/workflows/build-test.yml/badge.svg) [![Coverity Status](https://scan.coverity.com/projects/27509/badge.svg)](https://scan.coverity.com/projects/nlnetlabs-simdzone) -[![Mastodon Follow](https://img.shields.io/mastodon/follow/109262826617293067?domain=https%3A%2F%2Ffosstodon.org&style=social)](https://fosstodon.org/@nlnetlabs) +[![Discuss on Discourse](https://img.shields.io/badge/Discourse-NLnet_Labs-orange?logo=Discourse)](https://community.nlnetlabs.nl/c/dns-libraries-tools/12) +[![Mastodon Follow](https://img.shields.io/mastodon/follow/114692612288811644?domain=social.nlnetlabs.nl&style=social)](https://social.nlnetlabs.nl/@nlnetlabs) # simdzone: Parsing zone files really fast @@ -33,7 +34,7 @@ instructions for parsing structured text simdzone, whose name is a play on [simdjson][simdjson], aims to achieve a similar performance boost for parsing zone data. -> Currently SSE4.2 and AVX2 are supported, a fallback is used otherwise. +> Currently SSE4.2 and AVX2 are supported. RISC-V and other non-x86_64 targets use the fallback kernel until a dedicated SIMD backend is added. > simdzone copies some code from the [simdjson][simdjson] project, with > permission to use and distribute it under the terms of Index: usr.sbin/nsd/simdzone/config.guess =================================================================== RCS file: /cvs/src/usr.sbin/nsd/simdzone/config.guess,v diff -u -p -r1.1.1.2 config.guess --- usr.sbin/nsd/simdzone/config.guess 6 Sep 2025 17:38:34 -0000 1.1.1.2 +++ usr.sbin/nsd/simdzone/config.guess 21 Sep 2026 16:28:43 -0000 @@ -1,10 +1,10 @@ #! /bin/sh # Attempt to guess a canonical system name. -# Copyright 1992-2023 Free Software Foundation, Inc. +# Copyright 1992-2022 Free Software Foundation, Inc. # shellcheck disable=SC2006,SC2268 # see below for rationale -timestamp='2023-08-22' +timestamp='2022-01-09' # This file is free software; you can redistribute it and/or modify it # under the terms of the GNU General Public License as published by @@ -47,7 +47,7 @@ me=`echo "$0" | sed -e 's,.*/,,'` usage="\ Usage: $0 [OPTION] -Output the configuration name of the system '$me' is run on. +Output the configuration name of the system \`$me' is run on. Options: -h, --help print this help, then exit @@ -60,13 +60,13 @@ version="\ GNU config.guess ($timestamp) Originally written by Per Bothner. -Copyright 1992-2023 Free Software Foundation, Inc. +Copyright 1992-2022 Free Software Foundation, Inc. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE." help=" -Try '$me --help' for more information." +Try \`$me --help' for more information." # Parse command line while test $# -gt 0 ; do @@ -102,8 +102,8 @@ GUESS= # temporary files to be created and, as you can see below, it is a # headache to deal with in a portable fashion. -# Historically, 'CC_FOR_BUILD' used to be named 'HOST_CC'. We still -# use 'HOST_CC' if defined, but it is deprecated. +# Historically, `CC_FOR_BUILD' used to be named `HOST_CC'. We still +# use `HOST_CC' if defined, but it is deprecated. # Portable tmp directory creation inspired by the Autoconf team. @@ -155,9 +155,6 @@ Linux|GNU|GNU/*) set_cc_for_build cat <<-EOF > "$dummy.c" - #if defined(__ANDROID__) - LIBC=android - #else #include #if defined(__UCLIBC__) LIBC=uclibc @@ -172,7 +169,6 @@ Linux|GNU|GNU/*) LIBC=musl #endif #endif - #endif EOF cc_set_libc=`$CC_FOR_BUILD -E "$dummy.c" 2>/dev/null | grep '^LIBC' | sed 's, ,,g'` eval "$cc_set_libc" @@ -463,7 +459,7 @@ case $UNAME_MACHINE:$UNAME_SYSTEM:$UNAME UNAME_RELEASE=`uname -v` ;; esac - # Japanese Language versions have a version number like '4.1.3-JL'. + # Japanese Language versions have a version number like `4.1.3-JL'. SUN_REL=`echo "$UNAME_RELEASE" | sed -e 's/-/_/'` GUESS=sparc-sun-sunos$SUN_REL ;; @@ -908,7 +904,7 @@ EOF fi ;; *:FreeBSD:*:*) - UNAME_PROCESSOR=`uname -p` + UNAME_PROCESSOR=`/usr/bin/uname -p` case $UNAME_PROCESSOR in amd64) UNAME_PROCESSOR=x86_64 ;; @@ -970,37 +966,11 @@ EOF GNU_REL=`echo "$UNAME_RELEASE" | sed -e 's/[-(].*//'` GUESS=$UNAME_MACHINE-unknown-$GNU_SYS$GNU_REL-$LIBC ;; - x86_64:[Mm]anagarm:*:*|i?86:[Mm]anagarm:*:*) - GUESS="$UNAME_MACHINE-pc-managarm-mlibc" - ;; - *:[Mm]anagarm:*:*) - GUESS="$UNAME_MACHINE-unknown-managarm-mlibc" - ;; *:Minix:*:*) GUESS=$UNAME_MACHINE-unknown-minix ;; aarch64:Linux:*:*) - set_cc_for_build - CPU=$UNAME_MACHINE - LIBCABI=$LIBC - if test "$CC_FOR_BUILD" != no_compiler_found; then - ABI=64 - sed 's/^ //' << EOF > "$dummy.c" - #ifdef __ARM_EABI__ - #ifdef __ARM_PCS_VFP - ABI=eabihf - #else - ABI=eabi - #endif - #endif -EOF - cc_set_abi=`$CC_FOR_BUILD -E "$dummy.c" 2>/dev/null | grep '^ABI' | sed 's, ,,g'` - eval "$cc_set_abi" - case $ABI in - eabi | eabihf) CPU=armv8l; LIBCABI=$LIBC$ABI ;; - esac - fi - GUESS=$CPU-unknown-linux-$LIBCABI + GUESS=$UNAME_MACHINE-unknown-linux-$LIBC ;; aarch64_be:Linux:*:*) UNAME_MACHINE=aarch64_be @@ -1066,16 +1036,7 @@ EOF k1om:Linux:*:*) GUESS=$UNAME_MACHINE-unknown-linux-$LIBC ;; - kvx:Linux:*:*) - GUESS=$UNAME_MACHINE-unknown-linux-$LIBC - ;; - kvx:cos:*:*) - GUESS=$UNAME_MACHINE-unknown-cos - ;; - kvx:mbr:*:*) - GUESS=$UNAME_MACHINE-unknown-mbr - ;; - loongarch32:Linux:*:* | loongarch64:Linux:*:*) + loongarch32:Linux:*:* | loongarch64:Linux:*:* | loongarchx32:Linux:*:*) GUESS=$UNAME_MACHINE-unknown-linux-$LIBC ;; m32r*:Linux:*:*) @@ -1190,27 +1151,16 @@ EOF ;; x86_64:Linux:*:*) set_cc_for_build - CPU=$UNAME_MACHINE LIBCABI=$LIBC if test "$CC_FOR_BUILD" != no_compiler_found; then - ABI=64 - sed 's/^ //' << EOF > "$dummy.c" - #ifdef __i386__ - ABI=x86 - #else - #ifdef __ILP32__ - ABI=x32 - #endif - #endif -EOF - cc_set_abi=`$CC_FOR_BUILD -E "$dummy.c" 2>/dev/null | grep '^ABI' | sed 's, ,,g'` - eval "$cc_set_abi" - case $ABI in - x86) CPU=i686 ;; - x32) LIBCABI=${LIBC}x32 ;; - esac + if (echo '#ifdef __ILP32__'; echo IS_X32; echo '#endif') | \ + (CCOPTS="" $CC_FOR_BUILD -E - 2>/dev/null) | \ + grep IS_X32 >/dev/null + then + LIBCABI=${LIBC}x32 + fi fi - GUESS=$CPU-pc-linux-$LIBCABI + GUESS=$UNAME_MACHINE-pc-linux-$LIBCABI ;; xtensa*:Linux:*:*) GUESS=$UNAME_MACHINE-unknown-linux-$LIBC @@ -1230,7 +1180,7 @@ EOF GUESS=$UNAME_MACHINE-pc-sysv4.2uw$UNAME_VERSION ;; i*86:OS/2:*:*) - # If we were able to find 'uname', then EMX Unix compatibility + # If we were able to find `uname', then EMX Unix compatibility # is probably installed. GUESS=$UNAME_MACHINE-pc-os2-emx ;; @@ -1371,7 +1321,7 @@ EOF GUESS=ns32k-sni-sysv fi ;; - PENTIUM:*:4.0*:*) # Unisys 'ClearPath HMP IX 4000' SVR4/MP effort + PENTIUM:*:4.0*:*) # Unisys `ClearPath HMP IX 4000' SVR4/MP effort # says GUESS=i586-unisys-sysv4 ;; @@ -1417,11 +1367,8 @@ EOF BePC:Haiku:*:*) # Haiku running on Intel PC compatible. GUESS=i586-pc-haiku ;; - ppc:Haiku:*:*) # Haiku running on Apple PowerPC - GUESS=powerpc-apple-haiku - ;; - *:Haiku:*:*) # Haiku modern gcc (not bound by BeOS compat) - GUESS=$UNAME_MACHINE-unknown-haiku + x86_64:Haiku:*:*) + GUESS=x86_64-unknown-haiku ;; SX-4:SUPER-UX:*:*) GUESS=sx4-nec-superux$UNAME_RELEASE Index: usr.sbin/nsd/simdzone/config.h.in =================================================================== RCS file: /cvs/src/usr.sbin/nsd/simdzone/config.h.in,v diff -u -p -r1.1.1.2 config.h.in --- usr.sbin/nsd/simdzone/config.h.in 6 Sep 2025 17:38:34 -0000 1.1.1.2 +++ usr.sbin/nsd/simdzone/config.h.in 21 Sep 2026 16:28:43 -0000 @@ -1,14 +1,14 @@ /* config.h.in. Generated from configure.ac by autoheader. */ -/* Define to 1 if you have the declaration of 'bswap16', and to 0 if you +/* Define to 1 if you have the declaration of `bswap16', and to 0 if you don't. */ #undef HAVE_DECL_BSWAP16 -/* Define to 1 if you have the declaration of 'bswap32', and to 0 if you +/* Define to 1 if you have the declaration of `bswap32', and to 0 if you don't. */ #undef HAVE_DECL_BSWAP32 -/* Define to 1 if you have the declaration of 'bswap64', and to 0 if you +/* Define to 1 if you have the declaration of `bswap64', and to 0 if you don't. */ #undef HAVE_DECL_BSWAP64 @@ -21,7 +21,7 @@ /* Define to 1 if you have the header file. */ #undef HAVE_INTTYPES_H -/* Define to 1 if you have the 'realpath' function. */ +/* Define to 1 if you have the `realpath' function. */ #undef HAVE_REALPATH /* Define to 1 if you have the header file. */ @@ -72,7 +72,7 @@ /* Define to the version of this package. */ #undef PACKAGE_VERSION -/* Define to 1 if all of the C89 standard headers exist (not just the ones +/* Define to 1 if all of the C90 standard headers exist (not just the ones required in a freestanding environment). This macro is provided for backward compatibility; new code need not use it. */ #undef STDC_HEADERS Index: usr.sbin/nsd/simdzone/config.sub =================================================================== RCS file: /cvs/src/usr.sbin/nsd/simdzone/config.sub,v diff -u -p -r1.1.1.2 config.sub --- usr.sbin/nsd/simdzone/config.sub 6 Sep 2025 17:38:34 -0000 1.1.1.2 +++ usr.sbin/nsd/simdzone/config.sub 21 Sep 2026 16:28:43 -0000 @@ -1,10 +1,10 @@ #! /bin/sh # Configuration validation subroutine script. -# Copyright 1992-2023 Free Software Foundation, Inc. +# Copyright 1992-2022 Free Software Foundation, Inc. # shellcheck disable=SC2006,SC2268 # see below for rationale -timestamp='2023-09-19' +timestamp='2022-01-03' # This file is free software; you can redistribute it and/or modify it # under the terms of the GNU General Public License as published by @@ -76,13 +76,13 @@ Report bugs and patches to &2 + echo Invalid configuration \`"$1"\': more than four components >&2 exit 1 ;; *-*-*-*) @@ -145,8 +145,7 @@ case $1 in nto-qnx* | linux-* | uclinux-uclibc* \ | uclinux-gnu* | kfreebsd*-gnu* | knetbsd*-gnu* | netbsd*-gnu* \ | netbsd*-eabi* | kopensolaris*-gnu* | cloudabi*-eabi* \ - | storm-chaos* | os2-emx* | rtmk-nova* | managarm-* \ - | windows-* ) + | storm-chaos* | os2-emx* | rtmk-nova*) basic_machine=$field1 basic_os=$maybe_os ;; @@ -944,7 +943,7 @@ $basic_machine EOF IFS=$saved_IFS ;; - # We use 'pc' rather than 'unknown' + # We use `pc' rather than `unknown' # because (1) that's what they normally are, and # (2) the word "unknown" tends to confuse beginning users. i*86 | x86_64) @@ -1076,7 +1075,7 @@ case $cpu-$vendor in pentium-* | p5-* | k5-* | k6-* | nexgen-* | viac3-*) cpu=i586 ;; - pentiumpro-* | p6-* | 6x86-* | athlon-* | athlon_*-*) + pentiumpro-* | p6-* | 6x86-* | athlon-* | athalon_*-*) cpu=i686 ;; pentiumii-* | pentium2-* | pentiumiii-* | pentium3-*) @@ -1181,7 +1180,7 @@ case $cpu-$vendor in case $cpu in 1750a | 580 \ | a29k \ - | aarch64 | aarch64_be | aarch64c | arm64ec \ + | aarch64 | aarch64_be \ | abacus \ | alpha | alphaev[4-8] | alphaev56 | alphaev6[78] \ | alpha64 | alpha64ev[4-8] | alpha64ev56 | alpha64ev6[78] \ @@ -1200,23 +1199,45 @@ case $cpu-$vendor in | d10v | d30v | dlx | dsp16xx \ | e2k | elxsi | epiphany \ | f30[01] | f700 | fido | fr30 | frv | ft32 | fx80 \ - | javascript \ | h8300 | h8500 \ | hppa | hppa1.[01] | hppa2.0 | hppa2.0[nw] | hppa64 \ | hexagon \ | i370 | i*86 | i860 | i960 | ia16 | ia64 \ | ip2k | iq2000 \ | k1om \ - | kvx \ | le32 | le64 \ | lm32 \ - | loongarch32 | loongarch64 \ + | loongarch32 | loongarch64 | loongarchx32 \ | m32c | m32r | m32rle \ | m5200 | m68000 | m680[012346]0 | m68360 | m683?2 | m68k \ | m6811 | m68hc11 | m6812 | m68hc12 | m68hcs12x \ | m88110 | m88k | maxq | mb | mcore | mep | metag \ | microblaze | microblazeel \ - | mips* \ + | mips | mipsbe | mipseb | mipsel | mipsle \ + | mips16 \ + | mips64 | mips64eb | mips64el \ + | mips64octeon | mips64octeonel \ + | mips64orion | mips64orionel \ + | mips64r5900 | mips64r5900el \ + | mips64vr | mips64vrel \ + | mips64vr4100 | mips64vr4100el \ + | mips64vr4300 | mips64vr4300el \ + | mips64vr5000 | mips64vr5000el \ + | mips64vr5900 | mips64vr5900el \ + | mipsisa32 | mipsisa32el \ + | mipsisa32r2 | mipsisa32r2el \ + | mipsisa32r3 | mipsisa32r3el \ + | mipsisa32r5 | mipsisa32r5el \ + | mipsisa32r6 | mipsisa32r6el \ + | mipsisa64 | mipsisa64el \ + | mipsisa64r2 | mipsisa64r2el \ + | mipsisa64r3 | mipsisa64r3el \ + | mipsisa64r5 | mipsisa64r5el \ + | mipsisa64r6 | mipsisa64r6el \ + | mipsisa64sb1 | mipsisa64sb1el \ + | mipsisa64sr71k | mipsisa64sr71kel \ + | mipsr5900 | mipsr5900el \ + | mipstx39 | mipstx39el \ | mmix \ | mn10200 | mn10300 \ | moxie \ @@ -1264,7 +1285,7 @@ case $cpu-$vendor in ;; *) - echo "Invalid configuration '$1': machine '$cpu-$vendor' not recognized" 1>&2 + echo Invalid configuration \`"$1"\': machine \`"$cpu-$vendor"\' not recognized 1>&2 exit 1 ;; esac @@ -1285,12 +1306,11 @@ esac # Decode manufacturer-specific aliases for certain operating systems. -if test x"$basic_os" != x +if test x$basic_os != x then # First recognize some ad-hoc cases, or perhaps split kernel-os, or else just # set os. -obj= case $basic_os in gnu/linux*) kernel=linux @@ -1321,10 +1341,6 @@ EOF kernel=linux os=`echo "$basic_os" | sed -e 's|linux|gnu|'` ;; - managarm*) - kernel=managarm - os=`echo "$basic_os" | sed -e 's|managarm|mlibc|'` - ;; *) kernel= os=$basic_os @@ -1490,16 +1506,10 @@ case $os in os=eabi ;; *) - os= - obj=elf + os=elf ;; esac ;; - aout* | coff* | elf* | pe*) - # These are machine code file formats, not OSes - obj=$os - os= - ;; *) # No normalization, but not necessarily accepted, that comes below. ;; @@ -1518,15 +1528,12 @@ else # system, and we'll never get to this point. kernel= -obj= case $cpu-$vendor in score-*) - os= - obj=elf + os=elf ;; spu-*) - os= - obj=elf + os=elf ;; *-acorn) os=riscix1.2 @@ -1536,35 +1543,28 @@ case $cpu-$vendor in os=gnu ;; arm*-semi) - os= - obj=aout + os=aout ;; c4x-* | tic4x-*) - os= - obj=coff + os=coff ;; c8051-*) - os= - obj=elf + os=elf ;; clipper-intergraph) os=clix ;; hexagon-*) - os= - obj=elf + os=elf ;; tic54x-*) - os= - obj=coff + os=coff ;; tic55x-*) - os= - obj=coff + os=coff ;; tic6x-*) - os= - obj=coff + os=coff ;; # This must come before the *-dec entry. pdp10-*) @@ -1586,24 +1586,19 @@ case $cpu-$vendor in os=sunos3 ;; m68*-cisco) - os= - obj=aout + os=aout ;; mep-*) - os= - obj=elf + os=elf ;; mips*-cisco) - os= - obj=elf + os=elf ;; mips*-*) - os= - obj=elf + os=elf ;; or32-*) - os= - obj=coff + os=coff ;; *-tti) # must be before sparc entry or we get the wrong os. os=sysv3 @@ -1612,8 +1607,7 @@ case $cpu-$vendor in os=sunos4.1.1 ;; pru-*) - os= - obj=elf + os=elf ;; *-be) os=beos @@ -1694,12 +1688,10 @@ case $cpu-$vendor in os=uxpv ;; *-rom68k) - os= - obj=coff + os=coff ;; *-*bug) - os= - obj=coff + os=coff ;; *-apple) os=macos @@ -1717,8 +1709,7 @@ esac fi -# Now, validate our (potentially fixed-up) individual pieces (OS, OBJ). - +# Now, validate our (potentially fixed-up) OS. case $os in # Sometimes we do "kernel-libc", so those need to count as OSes. musl* | newlib* | relibc* | uclibc*) @@ -1729,9 +1720,6 @@ case $os in # VxWorks passes extra cpu info in the 4th filed. simlinux | simwindows | spe) ;; - # See `case $cpu-$os` validation below - ghcjs) - ;; # Now accept the basic system types. # The portable systems comes first. # Each alternative MUST end in a * to match a version number. @@ -1740,7 +1728,7 @@ case $os in | hpux* | unos* | osf* | luna* | dgux* | auroraux* | solaris* \ | sym* | plan9* | psp* | sim* | xray* | os68k* | v88r* \ | hiux* | abug | nacl* | netware* | windows* \ - | os9* | macos* | osx* | ios* | tvos* | watchos* \ + | os9* | macos* | osx* | ios* \ | mpw* | magic* | mmixware* | mon960* | lnews* \ | amigaos* | amigados* | msdos* | newsos* | unicos* | aof* \ | aos* | aros* | cloudabi* | sortix* | twizzler* \ @@ -1749,11 +1737,11 @@ case $os in | mirbsd* | netbsd* | dicos* | openedition* | ose* \ | bitrig* | openbsd* | secbsd* | solidbsd* | libertybsd* | os108* \ | ekkobsd* | freebsd* | riscix* | lynxos* | os400* \ - | bosx* | nextstep* | cxux* | oabi* \ - | ptx* | ecoff* | winnt* | domain* | vsta* \ + | bosx* | nextstep* | cxux* | aout* | elf* | oabi* \ + | ptx* | coff* | ecoff* | winnt* | domain* | vsta* \ | udi* | lites* | ieee* | go32* | aux* | hcos* \ | chorusrdb* | cegcc* | glidix* | serenity* \ - | cygwin* | msys* | moss* | proelf* | rtems* \ + | cygwin* | msys* | pe* | moss* | proelf* | rtems* \ | midipix* | mingw32* | mingw64* | mint* \ | uxpv* | beos* | mpeix* | udk* | moxiebox* \ | interix* | uwin* | mks* | rhapsody* | darwin* \ @@ -1766,7 +1754,7 @@ case $os in | onefs* | tirtos* | phoenix* | fuchsia* | redox* | bme* \ | midnightbsd* | amdhsa* | unleashed* | emscripten* | wasi* \ | nsk* | powerunix* | genode* | zvmoe* | qnx* | emx* | zephyr* \ - | fiwix* | mlibc* | cos* | mbr* ) + | fiwix* ) ;; # This one is extra strict with allowed versions sco3.2v2 | sco3.2v[4-9]* | sco5v6*) @@ -1774,99 +1762,41 @@ case $os in ;; none) ;; - kernel* | msvc* ) - # Restricted further below - ;; - '') - if test x"$obj" = x - then - echo "Invalid configuration '$1': Blank OS only allowed with explicit machine code file format" 1>&2 - fi - ;; - *) - echo "Invalid configuration '$1': OS '$os' not recognized" 1>&2 - exit 1 - ;; -esac - -case $obj in - aout* | coff* | elf* | pe*) - ;; - '') - # empty is fine - ;; *) - echo "Invalid configuration '$1': Machine code format '$obj' not recognized" 1>&2 - exit 1 - ;; -esac - -# Here we handle the constraint that a (synthetic) cpu and os are -# valid only in combination with each other and nowhere else. -case $cpu-$os in - # The "javascript-unknown-ghcjs" triple is used by GHC; we - # accept it here in order to tolerate that, but reject any - # variations. - javascript-ghcjs) - ;; - javascript-* | *-ghcjs) - echo "Invalid configuration '$1': cpu '$cpu' is not valid with os '$os$obj'" 1>&2 + echo Invalid configuration \`"$1"\': OS \`"$os"\' not recognized 1>&2 exit 1 ;; esac # As a final step for OS-related things, validate the OS-kernel combination # (given a valid OS), if there is a kernel. -case $kernel-$os-$obj in - linux-gnu*- | linux-dietlibc*- | linux-android*- | linux-newlib*- \ - | linux-musl*- | linux-relibc*- | linux-uclibc*- | linux-mlibc*- ) - ;; - uclinux-uclibc*- ) - ;; - managarm-mlibc*- | managarm-kernel*- ) +case $kernel-$os in + linux-gnu* | linux-dietlibc* | linux-android* | linux-newlib* \ + | linux-musl* | linux-relibc* | linux-uclibc* ) ;; - windows*-msvc*-) + uclinux-uclibc* ) ;; - -dietlibc*- | -newlib*- | -musl*- | -relibc*- | -uclibc*- | -mlibc*- ) + -dietlibc* | -newlib* | -musl* | -relibc* | -uclibc* ) # These are just libc implementations, not actual OSes, and thus # require a kernel. - echo "Invalid configuration '$1': libc '$os' needs explicit kernel." 1>&2 - exit 1 - ;; - -kernel*- ) - echo "Invalid configuration '$1': '$os' needs explicit kernel." 1>&2 - exit 1 - ;; - *-kernel*- ) - echo "Invalid configuration '$1': '$kernel' does not support '$os'." 1>&2 + echo "Invalid configuration \`$1': libc \`$os' needs explicit kernel." 1>&2 exit 1 ;; - *-msvc*- ) - echo "Invalid configuration '$1': '$os' needs 'windows'." 1>&2 - exit 1 - ;; - kfreebsd*-gnu*- | kopensolaris*-gnu*-) + kfreebsd*-gnu* | kopensolaris*-gnu*) ;; - vxworks-simlinux- | vxworks-simwindows- | vxworks-spe-) + vxworks-simlinux | vxworks-simwindows | vxworks-spe) ;; - nto-qnx*-) - ;; - os2-emx-) + nto-qnx*) ;; - *-eabi*- | *-gnueabi*-) + os2-emx) ;; - none--*) - # None (no kernel, i.e. freestanding / bare metal), - # can be paired with an machine code file format + *-eabi* | *-gnueabi*) ;; - -*-) + -*) # Blank kernel with real OS is always fine. ;; - --*) - # Blank kernel and OS with real machine code file format is always fine. - ;; - *-*-*) - echo "Invalid configuration '$1': Kernel '$kernel' not known to work with OS '$os'." 1>&2 + *-*) + echo "Invalid configuration \`$1': Kernel \`$kernel' not known to work with OS \`$os'." 1>&2 exit 1 ;; esac @@ -1949,7 +1879,7 @@ case $vendor in ;; esac -echo "$cpu-$vendor${kernel:+-$kernel}${os:+-$os}${obj:+-$obj}" +echo "$cpu-$vendor-${kernel:+$kernel-}$os" exit # Local variables: Index: usr.sbin/nsd/simdzone/configure =================================================================== RCS file: /cvs/src/usr.sbin/nsd/simdzone/configure,v diff -u -p -r1.1.1.3 configure --- usr.sbin/nsd/simdzone/configure 21 Mar 2026 21:34:33 -0000 1.1.1.3 +++ usr.sbin/nsd/simdzone/configure 21 Sep 2026 16:28:44 -0000 @@ -1,11 +1,11 @@ #! /bin/sh # Guess values for system-dependent variables and create Makefiles. -# Generated by GNU Autoconf 2.72 for simdzone 0.2.4. +# Generated by GNU Autoconf 2.71 for simdzone 0.2.5. # # Report bugs to . # # -# Copyright (C) 1992-1996, 1998-2017, 2020-2023 Free Software Foundation, +# Copyright (C) 1992-1996, 1998-2017, 2020-2021 Free Software Foundation, # Inc. # # @@ -17,6 +17,7 @@ # Be more Bourne compatible DUALCASE=1; export DUALCASE # for MKS sh +as_nop=: if test ${ZSH_VERSION+y} && (emulate sh) >/dev/null 2>&1 then : emulate sh @@ -25,13 +26,12 @@ then : # is contrary to our usage. Disable this feature. alias -g '${1+"$@"}'='"$@"' setopt NO_GLOB_SUBST -else case e in #( - e) case `(set -o) 2>/dev/null` in #( +else $as_nop + case `(set -o) 2>/dev/null` in #( *posix*) : set -o posix ;; #( *) : ;; -esac ;; esac fi @@ -103,7 +103,7 @@ IFS=$as_save_IFS ;; esac -# We did not find ourselves, most probably we were run as 'sh COMMAND' +# We did not find ourselves, most probably we were run as `sh COMMAND' # in which case we are not to be found in the path. if test "x$as_myself" = x; then as_myself=$0 @@ -133,14 +133,15 @@ case $- in # (((( esac exec $CONFIG_SHELL $as_opts "$as_myself" ${1+"$@"} # Admittedly, this is quite paranoid, since all the known shells bail -# out after a failed 'exec'. +# out after a failed `exec'. printf "%s\n" "$0: could not re-execute with $CONFIG_SHELL" >&2 exit 255 fi # We don't want this to propagate to other subprocesses. { _as_can_reexec=; unset _as_can_reexec;} if test "x$CONFIG_SHELL" = x; then - as_bourne_compatible="if test \${ZSH_VERSION+y} && (emulate sh) >/dev/null 2>&1 + as_bourne_compatible="as_nop=: +if test \${ZSH_VERSION+y} && (emulate sh) >/dev/null 2>&1 then : emulate sh NULLCMD=: @@ -148,13 +149,12 @@ then : # is contrary to our usage. Disable this feature. alias -g '\${1+\"\$@\"}'='\"\$@\"' setopt NO_GLOB_SUBST -else case e in #( - e) case \`(set -o) 2>/dev/null\` in #( +else \$as_nop + case \`(set -o) 2>/dev/null\` in #( *posix*) : set -o posix ;; #( *) : ;; -esac ;; esac fi " @@ -172,9 +172,8 @@ as_fn_ret_failure && { exitcode=1; echo if ( set x; as_fn_ret_success y && test x = \"\$1\" ) then : -else case e in #( - e) exitcode=1; echo positional parameters were not saved. ;; -esac +else \$as_nop + exitcode=1; echo positional parameters were not saved. fi test x\$exitcode = x0 || exit 1 blah=\$(echo \$(echo blah)) @@ -187,15 +186,14 @@ test -x / || exit 1" if (eval "$as_required") 2>/dev/null then : as_have_required=yes -else case e in #( - e) as_have_required=no ;; -esac +else $as_nop + as_have_required=no fi if test x$as_have_required = xyes && (eval "$as_suggested") 2>/dev/null then : -else case e in #( - e) as_save_IFS=$IFS; IFS=$PATH_SEPARATOR +else $as_nop + as_save_IFS=$IFS; IFS=$PATH_SEPARATOR as_found=false for as_dir in /bin$PATH_SEPARATOR/usr/bin$PATH_SEPARATOR$PATH do @@ -228,13 +226,12 @@ IFS=$as_save_IFS if $as_found then : -else case e in #( - e) if { test -f "$SHELL" || test -f "$SHELL.exe"; } && +else $as_nop + if { test -f "$SHELL" || test -f "$SHELL.exe"; } && as_run=a "$SHELL" -c "$as_bourne_compatible""$as_required" 2>/dev/null then : CONFIG_SHELL=$SHELL as_have_required=yes -fi ;; -esac +fi fi @@ -256,7 +253,7 @@ case $- in # (((( esac exec $CONFIG_SHELL $as_opts "$as_myself" ${1+"$@"} # Admittedly, this is quite paranoid, since all the known shells bail -# out after a failed 'exec'. +# out after a failed `exec'. printf "%s\n" "$0: could not re-execute with $CONFIG_SHELL" >&2 exit 255 fi @@ -276,8 +273,7 @@ $0: message. Then install a modern shell $0: the script under such a shell if you do have one." fi exit 1 -fi ;; -esac +fi fi fi SHELL=${CONFIG_SHELL-/bin/sh} @@ -316,6 +312,14 @@ as_fn_exit () as_fn_set_status $1 exit $1 } # as_fn_exit +# as_fn_nop +# --------- +# Do nothing but, unlike ":", preserve the value of $?. +as_fn_nop () +{ + return $? +} +as_nop=as_fn_nop # as_fn_mkdir_p # ------------- @@ -384,12 +388,11 @@ then : { eval $1+=\$2 }' -else case e in #( - e) as_fn_append () +else $as_nop + as_fn_append () { eval $1=\$$1\$2 - } ;; -esac + } fi # as_fn_append # as_fn_arith ARG... @@ -403,14 +406,21 @@ then : { as_val=$(( $* )) }' -else case e in #( - e) as_fn_arith () +else $as_nop + as_fn_arith () { as_val=`expr "$@" || test $? -eq 1` - } ;; -esac + } fi # as_fn_arith +# as_fn_nop +# --------- +# Do nothing but, unlike ":", preserve the value of $?. +as_fn_nop () +{ + return $? +} +as_nop=as_fn_nop # as_fn_error STATUS ERROR [LINENO LOG_FD] # ---------------------------------------- @@ -484,8 +494,6 @@ as_cr_alnum=$as_cr_Letters$as_cr_digits /[$]LINENO/= ' <$as_myself | sed ' - t clear - :clear s/[$]LINENO.*/&-/ t lineno b @@ -534,6 +542,7 @@ esac as_echo='printf %s\n' as_echo_n='printf %s' + rm -f conf$$ conf$$.exe conf$$.file if test -d conf$$.dir; then rm -f conf$$.dir/conf$$.file @@ -545,9 +554,9 @@ if (echo >conf$$.file) 2>/dev/null; then if ln -s conf$$.file conf$$ 2>/dev/null; then as_ln_s='ln -s' # ... but there are two gotchas: - # 1) On MSYS, both 'ln -s file dir' and 'ln file dir' fail. - # 2) DJGPP < 2.04 has no symlinks; 'ln -s' creates a wrapper executable. - # In both cases, we have to default to 'cp -pR'. + # 1) On MSYS, both `ln -s file dir' and `ln file dir' fail. + # 2) DJGPP < 2.04 has no symlinks; `ln -s' creates a wrapper executable. + # In both cases, we have to default to `cp -pR'. ln -s conf$$.file conf$$.dir 2>/dev/null && test ! -f conf$$.exe || as_ln_s='cp -pR' elif ln conf$$.file conf$$ 2>/dev/null; then @@ -572,12 +581,10 @@ as_test_x='test -x' as_executable_p=as_fn_executable_p # Sed expression to map a string onto a valid CPP name. -as_sed_cpp="y%*$as_cr_letters%P$as_cr_LETTERS%;s%[^_$as_cr_alnum]%_%g" -as_tr_cpp="eval sed '$as_sed_cpp'" # deprecated +as_tr_cpp="eval sed 'y%*$as_cr_letters%P$as_cr_LETTERS%;s%[^_$as_cr_alnum]%_%g'" # Sed expression to map a string onto a valid variable name. -as_sed_sh="y%*+%pp%;s%[^_$as_cr_alnum]%_%g" -as_tr_sh="eval sed '$as_sed_sh'" # deprecated +as_tr_sh="eval sed 'y%*+%pp%;s%[^_$as_cr_alnum]%_%g'" test -n "$DJDIR" || exec 7<&0 /dev/null && - as_fn_error $? "invalid feature name: '$ac_useropt'" + as_fn_error $? "invalid feature name: \`$ac_useropt'" ac_useropt_orig=$ac_useropt ac_useropt=`printf "%s\n" "$ac_useropt" | sed 's/[-+.]/_/g'` case $ac_user_opts in @@ -853,7 +860,7 @@ do ac_useropt=`expr "x$ac_option" : 'x-*enable-\([^=]*\)'` # Reject names that are not valid shell variable names. expr "x$ac_useropt" : ".*[^-+._$as_cr_alnum]" >/dev/null && - as_fn_error $? "invalid feature name: '$ac_useropt'" + as_fn_error $? "invalid feature name: \`$ac_useropt'" ac_useropt_orig=$ac_useropt ac_useropt=`printf "%s\n" "$ac_useropt" | sed 's/[-+.]/_/g'` case $ac_user_opts in @@ -1066,7 +1073,7 @@ do ac_useropt=`expr "x$ac_option" : 'x-*with-\([^=]*\)'` # Reject names that are not valid shell variable names. expr "x$ac_useropt" : ".*[^-+._$as_cr_alnum]" >/dev/null && - as_fn_error $? "invalid package name: '$ac_useropt'" + as_fn_error $? "invalid package name: \`$ac_useropt'" ac_useropt_orig=$ac_useropt ac_useropt=`printf "%s\n" "$ac_useropt" | sed 's/[-+.]/_/g'` case $ac_user_opts in @@ -1082,7 +1089,7 @@ do ac_useropt=`expr "x$ac_option" : 'x-*without-\(.*\)'` # Reject names that are not valid shell variable names. expr "x$ac_useropt" : ".*[^-+._$as_cr_alnum]" >/dev/null && - as_fn_error $? "invalid package name: '$ac_useropt'" + as_fn_error $? "invalid package name: \`$ac_useropt'" ac_useropt_orig=$ac_useropt ac_useropt=`printf "%s\n" "$ac_useropt" | sed 's/[-+.]/_/g'` case $ac_user_opts in @@ -1112,8 +1119,8 @@ do | --x-librar=* | --x-libra=* | --x-libr=* | --x-lib=* | --x-li=* | --x-l=*) x_libraries=$ac_optarg ;; - -*) as_fn_error $? "unrecognized option: '$ac_option' -Try '$0 --help' for more information" + -*) as_fn_error $? "unrecognized option: \`$ac_option' +Try \`$0 --help' for more information" ;; *=*) @@ -1121,7 +1128,7 @@ Try '$0 --help' for more information" # Reject names that are not valid shell variable names. case $ac_envvar in #( '' | [0-9]* | *[!_$as_cr_alnum]* ) - as_fn_error $? "invalid variable name: '$ac_envvar'" ;; + as_fn_error $? "invalid variable name: \`$ac_envvar'" ;; esac eval $ac_envvar=\$ac_optarg export $ac_envvar ;; @@ -1171,7 +1178,7 @@ do as_fn_error $? "expected an absolute directory name for --$ac_var: $ac_val" done -# There might be people who depend on the old broken behavior: '$host' +# There might be people who depend on the old broken behavior: `$host' # used to hold the argument of --host etc. # FIXME: To remove some day. build=$build_alias @@ -1239,7 +1246,7 @@ if test ! -r "$srcdir/$ac_unique_file"; test "$ac_srcdir_defaulted" = yes && srcdir="$ac_confdir or .." as_fn_error $? "cannot find sources ($ac_unique_file) in $srcdir" fi -ac_msg="sources are in $srcdir, but 'cd $srcdir' does not work" +ac_msg="sources are in $srcdir, but \`cd $srcdir' does not work" ac_abs_confdir=`( cd "$srcdir" && test -r "./$ac_unique_file" || as_fn_error $? "$ac_msg" pwd)` @@ -1267,7 +1274,7 @@ if test "$ac_init_help" = "long"; then # Omit some internal or obsolete options to make the list less imposing. # This message is too long to be a string in the A/UX 3.1 sh. cat <<_ACEOF -'configure' configures simdzone 0.2.4 to adapt to many kinds of systems. +\`configure' configures simdzone 0.2.5 to adapt to many kinds of systems. Usage: $0 [OPTION]... [VAR=VALUE]... @@ -1281,11 +1288,11 @@ Configuration: --help=short display options specific to this package --help=recursive display the short help of all the included packages -V, --version display version information and exit - -q, --quiet, --silent do not print 'checking ...' messages + -q, --quiet, --silent do not print \`checking ...' messages --cache-file=FILE cache test results in FILE [disabled] - -C, --config-cache alias for '--cache-file=config.cache' + -C, --config-cache alias for \`--cache-file=config.cache' -n, --no-create do not create output files - --srcdir=DIR find the sources in DIR [configure dir or '..'] + --srcdir=DIR find the sources in DIR [configure dir or \`..'] Installation directories: --prefix=PREFIX install architecture-independent files in PREFIX @@ -1293,10 +1300,10 @@ Installation directories: --exec-prefix=EPREFIX install architecture-dependent files in EPREFIX [PREFIX] -By default, 'make install' will install all the files in -'$ac_default_prefix/bin', '$ac_default_prefix/lib' etc. You can specify -an installation prefix other than '$ac_default_prefix' using '--prefix', -for instance '--prefix=\$HOME'. +By default, \`make install' will install all the files in +\`$ac_default_prefix/bin', \`$ac_default_prefix/lib' etc. You can specify +an installation prefix other than \`$ac_default_prefix' using \`--prefix', +for instance \`--prefix=\$HOME'. For better control, use the options below. @@ -1334,7 +1341,7 @@ fi if test -n "$ac_init_help"; then case $ac_init_help in - short | recursive ) echo "Configuration of simdzone 0.2.4:";; + short | recursive ) echo "Configuration of simdzone 0.2.5:";; esac cat <<\_ACEOF @@ -1356,7 +1363,7 @@ Some influential environment variables: CPPFLAGS (Objective) C/C++ preprocessor flags, e.g. -I if you have headers in a nonstandard directory -Use these variables to override the choices made by 'configure' or to help +Use these variables to override the choices made by `configure' or to help it to find libraries and programs with nonstandard names/locations. Report bugs to . @@ -1423,10 +1430,10 @@ fi test -n "$ac_init_help" && exit $ac_status if $ac_init_version; then cat <<\_ACEOF -simdzone configure 0.2.4 -generated by GNU Autoconf 2.72 +simdzone configure 0.2.5 +generated by GNU Autoconf 2.71 -Copyright (C) 2023 Free Software Foundation, Inc. +Copyright (C) 2021 Free Software Foundation, Inc. This configure script is free software; the Free Software Foundation gives unlimited permission to copy, distribute and modify it. _ACEOF @@ -1465,12 +1472,11 @@ printf "%s\n" "$ac_try_echo"; } >&5 } && test -s conftest.$ac_objext then : ac_retval=0 -else case e in #( - e) printf "%s\n" "$as_me: failed program was:" >&5 +else $as_nop + printf "%s\n" "$as_me: failed program was:" >&5 sed 's/^/| /' conftest.$ac_ext >&5 - ac_retval=1 ;; -esac + ac_retval=1 fi eval $as_lineno_stack; ${as_lineno_stack:+:} unset as_lineno as_fn_set_status $ac_retval @@ -1508,12 +1514,11 @@ printf "%s\n" "$ac_try_echo"; } >&5 } then : ac_retval=0 -else case e in #( - e) printf "%s\n" "$as_me: failed program was:" >&5 +else $as_nop + printf "%s\n" "$as_me: failed program was:" >&5 sed 's/^/| /' conftest.$ac_ext >&5 - ac_retval=1 ;; -esac + ac_retval=1 fi # Delete the IPA/IPO (Inter Procedural Analysis/Optimization) information # created by the PGI compiler (conftest_ipa8_conftest.oo), as it would @@ -1537,8 +1542,8 @@ printf %s "checking for $2... " >&6; } if eval test \${$3+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ $4 #include <$2> @@ -1546,12 +1551,10 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : eval "$3=yes" -else case e in #( - e) eval "$3=no" ;; -esac +else $as_nop + eval "$3=no" fi -rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac +rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext fi eval ac_res=\$$3 { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5 @@ -1573,8 +1576,8 @@ printf %s "checking whether $as_decl_nam if eval test \${$3+y} then : printf %s "(cached) " >&6 -else case e in #( - e) as_decl_use=`echo $2|sed -e 's/(/((/' -e 's/)/) 0&/' -e 's/,/) 0& (/g'` +else $as_nop + as_decl_use=`echo $2|sed -e 's/(/((/' -e 's/)/) 0&/' -e 's/,/) 0& (/g'` eval ac_save_FLAGS=\$$6 as_fn_append $6 " $5" cat confdefs.h - <<_ACEOF >conftest.$ac_ext @@ -1598,14 +1601,12 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : eval "$3=yes" -else case e in #( - e) eval "$3=no" ;; -esac +else $as_nop + eval "$3=no" fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext eval $6=\$ac_save_FLAGS - ;; -esac + fi eval ac_res=\$$3 { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5 @@ -1625,15 +1626,15 @@ printf %s "checking for $2... " >&6; } if eval test \${$3+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ /* Define $2 to an innocuous variant, in case declares $2. For example, HP-UX 11i declares gettimeofday. */ #define $2 innocuous_$2 /* System header to define __stub macros and hopefully few prototypes, - which can conflict with char $2 (void); below. */ + which can conflict with char $2 (); below. */ #include #undef $2 @@ -1644,7 +1645,7 @@ else case e in #( #ifdef __cplusplus extern "C" #endif -char $2 (void); +char $2 (); /* The GNU C library defines this for functions which it implements to always fail with ENOSYS. Some functions are actually named something starting with __ and the normal name is an alias. */ @@ -1663,13 +1664,11 @@ _ACEOF if ac_fn_c_try_link "$LINENO" then : eval "$3=yes" -else case e in #( - e) eval "$3=no" ;; -esac +else $as_nop + eval "$3=no" fi rm -f core conftest.err conftest.$ac_objext conftest.beam \ - conftest$ac_exeext conftest.$ac_ext ;; -esac + conftest$ac_exeext conftest.$ac_ext fi eval ac_res=\$$3 { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5 @@ -1701,8 +1700,8 @@ cat >config.log <<_ACEOF This file contains any messages produced by compilers while running configure, to aid debugging if configure makes a mistake. -It was created by simdzone $as_me 0.2.4, which was -generated by GNU Autoconf 2.72. Invocation command line was +It was created by simdzone $as_me 0.2.5, which was +generated by GNU Autoconf 2.71. Invocation command line was $ $0$ac_configure_args_raw @@ -1948,10 +1947,10 @@ esac printf "%s\n" "$as_me: loading site script $ac_site_file" >&6;} sed 's/^/| /' "$ac_site_file" >&5 . "$ac_site_file" \ - || { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} + || { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +printf "%s\n" "$as_me: error: in \`$ac_pwd':" >&2;} as_fn_error $? "failed to load site script $ac_site_file -See 'config.log' for more details" "$LINENO" 5; } +See \`config.log' for more details" "$LINENO" 5; } fi done @@ -1987,7 +1986,9 @@ struct stat; /* Most of the following tests are stolen from RCS 5.7 src/conf.sh. */ struct buf { int x; }; struct buf * (*rcsopen) (struct buf *, struct stat *, int); -static char *e (char **p, int i) +static char *e (p, i) + char **p; + int i; { return p[i]; } @@ -2001,21 +2002,6 @@ static char *f (char * (*g) (char **, in return s; } -/* C89 style stringification. */ -#define noexpand_stringify(a) #a -const char *stringified = noexpand_stringify(arbitrary+token=sequence); - -/* C89 style token pasting. Exercises some of the corner cases that - e.g. old MSVC gets wrong, but not very hard. */ -#define noexpand_concat(a,b) a##b -#define expand_concat(a,b) noexpand_concat(a,b) -extern int vA; -extern int vbee; -#define aye A -#define bee B -int *pvA = &expand_concat(v,aye); -int *pvbee = &noexpand_concat(v,bee); - /* OSF 4.0 Compaq cc is some sort of almost-ANSI by default. It has function prototypes and stuff, but not \xHH hex character constants. These do not provoke an error unfortunately, instead are silently treated @@ -2043,19 +2029,16 @@ ok |= (argc == 0 || f (e, argv, 0) != ar # Test code for whether the C compiler supports C99 (global declarations) ac_c_conftest_c99_globals=' -/* Does the compiler advertise C99 conformance? */ +// Does the compiler advertise C99 conformance? #if !defined __STDC_VERSION__ || __STDC_VERSION__ < 199901L # error "Compiler does not advertise C99 conformance" #endif -// See if C++-style comments work. - #include extern int puts (const char *); extern int printf (const char *, ...); extern int dprintf (int, const char *, ...); extern void *malloc (size_t); -extern void free (void *); // Check varargs macros. These examples are taken from C99 6.10.3.5. // dprintf is used instead of fprintf to avoid needing to declare @@ -2105,6 +2088,7 @@ typedef const char *ccp; static inline int test_restrict (ccp restrict text) { + // See if C++-style comments work. // Iterate through items via the restricted pointer. // Also check for declarations in for loops. for (unsigned int i = 0; *(text+i) != '\''\0'\''; ++i) @@ -2170,8 +2154,6 @@ ac_c_conftest_c99_main=' ia->datasize = 10; for (int i = 0; i < ia->datasize; ++i) ia->data[i] = i * 1.234; - // Work around memory leak warnings. - free (ia); // Check named initializers. struct named_init ni = { @@ -2193,7 +2175,7 @@ ac_c_conftest_c99_main=' # Test code for whether the C compiler supports C11 (global declarations) ac_c_conftest_c11_globals=' -/* Does the compiler advertise C11 conformance? */ +// Does the compiler advertise C11 conformance? #if !defined __STDC_VERSION__ || __STDC_VERSION__ < 201112L # error "Compiler does not advertise C11 conformance" #endif @@ -2385,9 +2367,8 @@ IFS=$as_save_IFS if $as_found then : -else case e in #( - e) as_fn_error $? "cannot find required auxiliary files:$ac_missing_aux_files" "$LINENO" 5 ;; -esac +else $as_nop + as_fn_error $? "cannot find required auxiliary files:$ac_missing_aux_files" "$LINENO" 5 fi @@ -2415,12 +2396,12 @@ for ac_var in $ac_precious_vars; do eval ac_new_val=\$ac_env_${ac_var}_value case $ac_old_set,$ac_new_set in set,) - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: '$ac_var' was set to '$ac_old_val' in the previous run" >&5 -printf "%s\n" "$as_me: error: '$ac_var' was set to '$ac_old_val' in the previous run" >&2;} + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: \`$ac_var' was set to \`$ac_old_val' in the previous run" >&5 +printf "%s\n" "$as_me: error: \`$ac_var' was set to \`$ac_old_val' in the previous run" >&2;} ac_cache_corrupted=: ;; ,set) - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: '$ac_var' was not set in the previous run" >&5 -printf "%s\n" "$as_me: error: '$ac_var' was not set in the previous run" >&2;} + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: \`$ac_var' was not set in the previous run" >&5 +printf "%s\n" "$as_me: error: \`$ac_var' was not set in the previous run" >&2;} ac_cache_corrupted=: ;; ,);; *) @@ -2429,18 +2410,18 @@ printf "%s\n" "$as_me: error: '$ac_var' ac_old_val_w=`echo x $ac_old_val` ac_new_val_w=`echo x $ac_new_val` if test "$ac_old_val_w" != "$ac_new_val_w"; then - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: '$ac_var' has changed since the previous run:" >&5 -printf "%s\n" "$as_me: error: '$ac_var' has changed since the previous run:" >&2;} + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: \`$ac_var' has changed since the previous run:" >&5 +printf "%s\n" "$as_me: error: \`$ac_var' has changed since the previous run:" >&2;} ac_cache_corrupted=: else - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: warning: ignoring whitespace changes in '$ac_var' since the previous run:" >&5 -printf "%s\n" "$as_me: warning: ignoring whitespace changes in '$ac_var' since the previous run:" >&2;} + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: warning: ignoring whitespace changes in \`$ac_var' since the previous run:" >&5 +printf "%s\n" "$as_me: warning: ignoring whitespace changes in \`$ac_var' since the previous run:" >&2;} eval $ac_var=\$ac_old_val fi - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: former value: '$ac_old_val'" >&5 -printf "%s\n" "$as_me: former value: '$ac_old_val'" >&2;} - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: current value: '$ac_new_val'" >&5 -printf "%s\n" "$as_me: current value: '$ac_new_val'" >&2;} + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: former value: \`$ac_old_val'" >&5 +printf "%s\n" "$as_me: former value: \`$ac_old_val'" >&2;} + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: current value: \`$ac_new_val'" >&5 +printf "%s\n" "$as_me: current value: \`$ac_new_val'" >&2;} fi;; esac # Pass precious variables to config.status. @@ -2456,11 +2437,11 @@ printf "%s\n" "$as_me: current value: fi done if $ac_cache_corrupted; then - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +printf "%s\n" "$as_me: error: in \`$ac_pwd':" >&2;} { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: changes in the environment can compromise the build" >&5 printf "%s\n" "$as_me: error: changes in the environment can compromise the build" >&2;} - as_fn_error $? "run '${MAKE-make} distclean' and/or 'rm $cache_file' + as_fn_error $? "run \`${MAKE-make} distclean' and/or \`rm $cache_file' and start over" "$LINENO" 5 fi ## -------------------- ## @@ -2773,8 +2754,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$CC"; then +else $as_nop + if test -n "$CC"; then ac_cv_prog_CC="$CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -2796,8 +2777,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi CC=$ac_cv_prog_CC if test -n "$CC"; then @@ -2819,8 +2799,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_ac_ct_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$ac_ct_CC"; then +else $as_nop + if test -n "$ac_ct_CC"; then ac_cv_prog_ac_ct_CC="$ac_ct_CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -2842,8 +2822,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi ac_ct_CC=$ac_cv_prog_ac_ct_CC if test -n "$ac_ct_CC"; then @@ -2878,8 +2857,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$CC"; then +else $as_nop + if test -n "$CC"; then ac_cv_prog_CC="$CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -2901,8 +2880,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi CC=$ac_cv_prog_CC if test -n "$CC"; then @@ -2924,8 +2902,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$CC"; then +else $as_nop + if test -n "$CC"; then ac_cv_prog_CC="$CC" # Let the user override the test. else ac_prog_rejected=no @@ -2964,8 +2942,7 @@ if test $ac_prog_rejected = yes; then ac_cv_prog_CC="$as_dir$ac_word${1+' '}$@" fi fi -fi ;; -esac +fi fi CC=$ac_cv_prog_CC if test -n "$CC"; then @@ -2989,8 +2966,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$CC"; then +else $as_nop + if test -n "$CC"; then ac_cv_prog_CC="$CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -3012,8 +2989,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi CC=$ac_cv_prog_CC if test -n "$CC"; then @@ -3039,8 +3015,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_ac_ct_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$ac_ct_CC"; then +else $as_nop + if test -n "$ac_ct_CC"; then ac_cv_prog_ac_ct_CC="$ac_ct_CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -3062,8 +3038,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi ac_ct_CC=$ac_cv_prog_ac_ct_CC if test -n "$ac_ct_CC"; then @@ -3101,8 +3076,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$CC"; then +else $as_nop + if test -n "$CC"; then ac_cv_prog_CC="$CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -3124,8 +3099,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi CC=$ac_cv_prog_CC if test -n "$CC"; then @@ -3147,8 +3121,8 @@ printf %s "checking for $ac_word... " >& if test ${ac_cv_prog_ac_ct_CC+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test -n "$ac_ct_CC"; then +else $as_nop + if test -n "$ac_ct_CC"; then ac_cv_prog_ac_ct_CC="$ac_ct_CC" # Let the user override the test. else as_save_IFS=$IFS; IFS=$PATH_SEPARATOR @@ -3170,8 +3144,7 @@ done done IFS=$as_save_IFS -fi ;; -esac +fi fi ac_ct_CC=$ac_cv_prog_ac_ct_CC if test -n "$ac_ct_CC"; then @@ -3200,10 +3173,10 @@ fi fi -test -z "$CC" && { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} +test -z "$CC" && { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +printf "%s\n" "$as_me: error: in \`$ac_pwd':" >&2;} as_fn_error $? "no acceptable C compiler found in \$PATH -See 'config.log' for more details" "$LINENO" 5; } +See \`config.log' for more details" "$LINENO" 5; } # Provide some information about the compiler. printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for C compiler version" >&5 @@ -3275,8 +3248,8 @@ printf "%s\n" "$ac_try_echo"; } >&5 printf "%s\n" "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5 test $ac_status = 0; } then : - # Autoconf-2.13 could set the ac_cv_exeext variable to 'no'. -# So ignore a value of 'no', otherwise this would lead to 'EXEEXT = no' + # Autoconf-2.13 could set the ac_cv_exeext variable to `no'. +# So ignore a value of `no', otherwise this would lead to `EXEEXT = no' # in a Makefile. We should not override ac_cv_exeext if it was cached, # so that the user can short-circuit this test for compilers unknown to # Autoconf. @@ -3296,7 +3269,7 @@ do ac_cv_exeext=`expr "$ac_file" : '[^.]*\(\..*\)'` fi # We set ac_cv_exeext here because the later test for it is not - # safe: cross compilers may not add the suffix if given an '-o' + # safe: cross compilers may not add the suffix if given an `-o' # argument, so we may need to know it at that point already. # Even if this section looks crufty: it has the advantage of # actually working. @@ -3307,9 +3280,8 @@ do done test "$ac_cv_exeext" = no && ac_cv_exeext= -else case e in #( - e) ac_file='' ;; -esac +else $as_nop + ac_file='' fi if test -z "$ac_file" then : @@ -3318,14 +3290,13 @@ printf "%s\n" "no" >&6; } printf "%s\n" "$as_me: failed program was:" >&5 sed 's/^/| /' conftest.$ac_ext >&5 -{ { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} +{ { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +printf "%s\n" "$as_me: error: in \`$ac_pwd':" >&2;} as_fn_error 77 "C compiler cannot create executables -See 'config.log' for more details" "$LINENO" 5; } -else case e in #( - e) { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: yes" >&5 -printf "%s\n" "yes" >&6; } ;; -esac +See \`config.log' for more details" "$LINENO" 5; } +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: yes" >&5 +printf "%s\n" "yes" >&6; } fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for C compiler default output file name" >&5 printf %s "checking for C compiler default output file name... " >&6; } @@ -3349,10 +3320,10 @@ printf "%s\n" "$ac_try_echo"; } >&5 printf "%s\n" "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5 test $ac_status = 0; } then : - # If both 'conftest.exe' and 'conftest' are 'present' (well, observable) -# catch 'conftest.exe'. For instance with Cygwin, 'ls conftest' will -# work properly (i.e., refer to 'conftest.exe'), while it won't with -# 'rm'. + # If both `conftest.exe' and `conftest' are `present' (well, observable) +# catch `conftest.exe'. For instance with Cygwin, `ls conftest' will +# work properly (i.e., refer to `conftest.exe'), while it won't with +# `rm'. for ac_file in conftest.exe conftest conftest.*; do test -f "$ac_file" || continue case $ac_file in @@ -3362,12 +3333,11 @@ for ac_file in conftest.exe conftest con * ) break;; esac done -else case e in #( - e) { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} +else $as_nop + { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +printf "%s\n" "$as_me: error: in \`$ac_pwd':" >&2;} as_fn_error $? "cannot compute suffix of executables: cannot compile and link -See 'config.log' for more details" "$LINENO" 5; } ;; -esac +See \`config.log' for more details" "$LINENO" 5; } fi rm -f conftest conftest$ac_cv_exeext { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_exeext" >&5 @@ -3383,8 +3353,6 @@ int main (void) { FILE *f = fopen ("conftest.out", "w"); - if (!f) - return 1; return ferror (f) || fclose (f) != 0; ; @@ -3424,27 +3392,26 @@ printf "%s\n" "$ac_try_echo"; } >&5 if test "$cross_compiling" = maybe; then cross_compiling=yes else - { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} + { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +printf "%s\n" "$as_me: error: in \`$ac_pwd':" >&2;} as_fn_error 77 "cannot run C compiled programs. -If you meant to cross compile, use '--host'. -See 'config.log' for more details" "$LINENO" 5; } +If you meant to cross compile, use \`--host'. +See \`config.log' for more details" "$LINENO" 5; } fi fi fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $cross_compiling" >&5 printf "%s\n" "$cross_compiling" >&6; } -rm -f conftest.$ac_ext conftest$ac_cv_exeext \ - conftest.o conftest.obj conftest.out +rm -f conftest.$ac_ext conftest$ac_cv_exeext conftest.out ac_clean_files=$ac_clean_files_save { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for suffix of object files" >&5 printf %s "checking for suffix of object files... " >&6; } if test ${ac_cv_objext+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ int @@ -3476,18 +3443,16 @@ then : break;; esac done -else case e in #( - e) printf "%s\n" "$as_me: failed program was:" >&5 +else $as_nop + printf "%s\n" "$as_me: failed program was:" >&5 sed 's/^/| /' conftest.$ac_ext >&5 -{ { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} +{ { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +printf "%s\n" "$as_me: error: in \`$ac_pwd':" >&2;} as_fn_error $? "cannot compute suffix of object files: cannot compile -See 'config.log' for more details" "$LINENO" 5; } ;; -esac +See \`config.log' for more details" "$LINENO" 5; } fi -rm -f conftest.$ac_cv_objext conftest.$ac_ext ;; -esac +rm -f conftest.$ac_cv_objext conftest.$ac_ext fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_objext" >&5 printf "%s\n" "$ac_cv_objext" >&6; } @@ -3498,8 +3463,8 @@ printf %s "checking whether the compiler if test ${ac_cv_c_compiler_gnu+y} then : printf %s "(cached) " >&6 -else case e in #( - e) cat confdefs.h - <<_ACEOF >conftest.$ac_ext +else $as_nop + cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ int @@ -3516,14 +3481,12 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ac_compiler_gnu=yes -else case e in #( - e) ac_compiler_gnu=no ;; -esac +else $as_nop + ac_compiler_gnu=no fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ac_cv_c_compiler_gnu=$ac_compiler_gnu - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_c_compiler_gnu" >&5 printf "%s\n" "$ac_cv_c_compiler_gnu" >&6; } @@ -3541,8 +3504,8 @@ printf %s "checking whether $CC accepts if test ${ac_cv_prog_cc_g+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_save_c_werror_flag=$ac_c_werror_flag +else $as_nop + ac_save_c_werror_flag=$ac_c_werror_flag ac_c_werror_flag=yes ac_cv_prog_cc_g=no CFLAGS="-g" @@ -3560,8 +3523,8 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ac_cv_prog_cc_g=yes -else case e in #( - e) CFLAGS="" +else $as_nop + CFLAGS="" cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ @@ -3576,8 +3539,8 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : -else case e in #( - e) ac_c_werror_flag=$ac_save_c_werror_flag +else $as_nop + ac_c_werror_flag=$ac_save_c_werror_flag CFLAGS="-g" cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ @@ -3594,15 +3557,12 @@ if ac_fn_c_try_compile "$LINENO" then : ac_cv_prog_cc_g=yes fi -rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac +rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext fi -rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac +rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext - ac_c_werror_flag=$ac_save_c_werror_flag ;; -esac + ac_c_werror_flag=$ac_save_c_werror_flag fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_g" >&5 printf "%s\n" "$ac_cv_prog_cc_g" >&6; } @@ -3629,8 +3589,8 @@ printf %s "checking for $CC option to en if test ${ac_cv_prog_cc_c11+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_cv_prog_cc_c11=no +else $as_nop + ac_cv_prog_cc_c11=no ac_save_CC=$CC cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ @@ -3647,28 +3607,25 @@ rm -f core conftest.err conftest.$ac_obj test "x$ac_cv_prog_cc_c11" != "xno" && break done rm -f conftest.$ac_ext -CC=$ac_save_CC ;; -esac +CC=$ac_save_CC fi if test "x$ac_cv_prog_cc_c11" = xno then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: unsupported" >&5 printf "%s\n" "unsupported" >&6; } -else case e in #( - e) if test "x$ac_cv_prog_cc_c11" = x +else $as_nop + if test "x$ac_cv_prog_cc_c11" = x then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: none needed" >&5 printf "%s\n" "none needed" >&6; } -else case e in #( - e) { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_c11" >&5 +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_c11" >&5 printf "%s\n" "$ac_cv_prog_cc_c11" >&6; } - CC="$CC $ac_cv_prog_cc_c11" ;; -esac + CC="$CC $ac_cv_prog_cc_c11" fi ac_cv_prog_cc_stdc=$ac_cv_prog_cc_c11 - ac_prog_cc_stdc=c11 ;; -esac + ac_prog_cc_stdc=c11 fi fi if test x$ac_prog_cc_stdc = xno @@ -3678,8 +3635,8 @@ printf %s "checking for $CC option to en if test ${ac_cv_prog_cc_c99+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_cv_prog_cc_c99=no +else $as_nop + ac_cv_prog_cc_c99=no ac_save_CC=$CC cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ @@ -3696,28 +3653,25 @@ rm -f core conftest.err conftest.$ac_obj test "x$ac_cv_prog_cc_c99" != "xno" && break done rm -f conftest.$ac_ext -CC=$ac_save_CC ;; -esac +CC=$ac_save_CC fi if test "x$ac_cv_prog_cc_c99" = xno then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: unsupported" >&5 printf "%s\n" "unsupported" >&6; } -else case e in #( - e) if test "x$ac_cv_prog_cc_c99" = x +else $as_nop + if test "x$ac_cv_prog_cc_c99" = x then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: none needed" >&5 printf "%s\n" "none needed" >&6; } -else case e in #( - e) { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_c99" >&5 +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_c99" >&5 printf "%s\n" "$ac_cv_prog_cc_c99" >&6; } - CC="$CC $ac_cv_prog_cc_c99" ;; -esac + CC="$CC $ac_cv_prog_cc_c99" fi ac_cv_prog_cc_stdc=$ac_cv_prog_cc_c99 - ac_prog_cc_stdc=c99 ;; -esac + ac_prog_cc_stdc=c99 fi fi if test x$ac_prog_cc_stdc = xno @@ -3727,8 +3681,8 @@ printf %s "checking for $CC option to en if test ${ac_cv_prog_cc_c89+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_cv_prog_cc_c89=no +else $as_nop + ac_cv_prog_cc_c89=no ac_save_CC=$CC cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ @@ -3745,28 +3699,25 @@ rm -f core conftest.err conftest.$ac_obj test "x$ac_cv_prog_cc_c89" != "xno" && break done rm -f conftest.$ac_ext -CC=$ac_save_CC ;; -esac +CC=$ac_save_CC fi if test "x$ac_cv_prog_cc_c89" = xno then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: unsupported" >&5 printf "%s\n" "unsupported" >&6; } -else case e in #( - e) if test "x$ac_cv_prog_cc_c89" = x +else $as_nop + if test "x$ac_cv_prog_cc_c89" = x then : { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: none needed" >&5 printf "%s\n" "none needed" >&6; } -else case e in #( - e) { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_c89" >&5 +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_c89" >&5 printf "%s\n" "$ac_cv_prog_cc_c89" >&6; } - CC="$CC $ac_cv_prog_cc_c89" ;; -esac + CC="$CC $ac_cv_prog_cc_c89" fi ac_cv_prog_cc_stdc=$ac_cv_prog_cc_c89 - ac_prog_cc_stdc=c89 ;; -esac + ac_prog_cc_stdc=c89 fi fi @@ -3787,8 +3738,8 @@ cache=`echo g | sed 'y%.=/+-%___p_%'` if eval test \${cv_prog_cc_flag_$cache+y} then : printf %s "(cached) " >&6 -else case e in #( - e) +else $as_nop + echo 'void f(void){}' >conftest.c if test -z "`$CC $CPPFLAGS $CFLAGS -g -c conftest.c 2>&1`"; then eval "cv_prog_cc_flag_$cache=yes" @@ -3796,8 +3747,7 @@ else eval "cv_prog_cc_flag_$cache=no" fi rm -f conftest conftest.o conftest.c - ;; -esac + fi if eval "test \"`echo '$cv_prog_cc_flag_'$cache`\" = yes"; then @@ -3820,8 +3770,8 @@ cache=`echo O2 | sed 'y%.=/+-%___p_%'` if eval test \${cv_prog_cc_flag_$cache+y} then : printf %s "(cached) " >&6 -else case e in #( - e) +else $as_nop + echo 'void f(void){}' >conftest.c if test -z "`$CC $CPPFLAGS $CFLAGS -O2 -c conftest.c 2>&1`"; then eval "cv_prog_cc_flag_$cache=yes" @@ -3829,8 +3779,7 @@ else eval "cv_prog_cc_flag_$cache=no" fi rm -f conftest conftest.o conftest.c - ;; -esac + fi if eval "test \"`echo '$cv_prog_cc_flag_'$cache`\" = yes"; then @@ -3886,10 +3835,9 @@ printf "%s\n" "yes" >&6; } fi rm -f conftest conftest.c conftest.o -else case e in #( - e) LDFLAGS="$BAKLDFLAGS" ; CFLAGS="$BAKCFLAGS" ; { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 -printf "%s\n" "no" >&6; } ;; -esac +else $as_nop + LDFLAGS="$BAKLDFLAGS" ; CFLAGS="$BAKCFLAGS" ; { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 +printf "%s\n" "no" >&6; } fi rm -f core conftest.err conftest.$ac_objext conftest.beam \ conftest$ac_exeext conftest.$ac_ext @@ -3947,8 +3895,8 @@ printf %s "checking for $CC options need if test ${ac_cv_c_undeclared_builtin_options+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_save_CFLAGS=$CFLAGS +else $as_nop + ac_save_CFLAGS=$CFLAGS ac_cv_c_undeclared_builtin_options='cannot detect' for ac_arg in '' -fno-builtin; do CFLAGS="$ac_save_CFLAGS $ac_arg" @@ -3967,8 +3915,8 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : -else case e in #( - e) # This test program should compile successfully. +else $as_nop + # This test program should compile successfully. # No library function is consistently available on # freestanding implementations, so test against a dummy # declaration. Include always-available headers on the @@ -3996,29 +3944,26 @@ then : if test x"$ac_arg" = x then : ac_cv_c_undeclared_builtin_options='none needed' -else case e in #( - e) ac_cv_c_undeclared_builtin_options=$ac_arg ;; -esac +else $as_nop + ac_cv_c_undeclared_builtin_options=$ac_arg fi break fi -rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;; -esac +rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext done CFLAGS=$ac_save_CFLAGS - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_c_undeclared_builtin_options" >&5 printf "%s\n" "$ac_cv_c_undeclared_builtin_options" >&6; } case $ac_cv_c_undeclared_builtin_options in #( 'cannot detect') : - { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in '$ac_pwd':" >&5 -printf "%s\n" "$as_me: error: in '$ac_pwd':" >&2;} + { { printf "%s\n" "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +printf "%s\n" "$as_me: error: in \`$ac_pwd':" >&2;} as_fn_error $? "cannot make $CC report undeclared builtins -See 'config.log' for more details" "$LINENO" 5; } ;; #( +See \`config.log' for more details" "$LINENO" 5; } ;; #( 'none needed') : ac_c_undeclared_builtin_options='' ;; #( *) : @@ -4038,9 +3983,8 @@ $ac_includes_default if test "x$ac_cv_have_decl_bswap16" = xyes then : ac_have_decl=1 -else case e in #( - e) ac_have_decl=0 ;; -esac +else $as_nop + ac_have_decl=0 fi printf "%s\n" "#define HAVE_DECL_BSWAP16 $ac_have_decl" >>confdefs.h ac_fn_check_decl "$LINENO" "bswap32" "ac_cv_have_decl_bswap32" " @@ -4056,9 +4000,8 @@ $ac_includes_default if test "x$ac_cv_have_decl_bswap32" = xyes then : ac_have_decl=1 -else case e in #( - e) ac_have_decl=0 ;; -esac +else $as_nop + ac_have_decl=0 fi printf "%s\n" "#define HAVE_DECL_BSWAP32 $ac_have_decl" >>confdefs.h ac_fn_check_decl "$LINENO" "bswap64" "ac_cv_have_decl_bswap64" " @@ -4074,9 +4017,8 @@ $ac_includes_default if test "x$ac_cv_have_decl_bswap64" = xyes then : ac_have_decl=1 -else case e in #( - e) ac_have_decl=0 ;; -esac +else $as_nop + ac_have_decl=0 fi printf "%s\n" "#define HAVE_DECL_BSWAP64 $ac_have_decl" >>confdefs.h @@ -4109,8 +4051,8 @@ printf %s "checking whether C compiler a if test ${ax_cv_check_cflags___MMD+y} then : printf %s "(cached) " >&6 -else case e in #( - e) +else $as_nop + ax_check_save_flags=$CFLAGS CFLAGS="$CFLAGS -MMD" cat confdefs.h - <<_ACEOF >conftest.$ac_ext @@ -4127,22 +4069,19 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ax_cv_check_cflags___MMD=yes -else case e in #( - e) ax_cv_check_cflags___MMD=no ;; -esac +else $as_nop + ax_cv_check_cflags___MMD=no fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext - CFLAGS=$ax_check_save_flags ;; -esac + CFLAGS=$ax_check_save_flags fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ax_cv_check_cflags___MMD" >&5 printf "%s\n" "$ax_cv_check_cflags___MMD" >&6; } if test "x$ax_cv_check_cflags___MMD" = xyes then : DEPFLAGS="-MMD -MP" -else case e in #( - e) : ;; -esac +else $as_nop + : fi # Oracle Developer Studio (no -MP) @@ -4151,8 +4090,8 @@ printf %s "checking whether C compiler a if test ${ax_cv_check_cflags___xMMD+y} then : printf %s "(cached) " >&6 -else case e in #( - e) +else $as_nop + ax_check_save_flags=$CFLAGS CFLAGS="$CFLAGS -xMMD" cat confdefs.h - <<_ACEOF >conftest.$ac_ext @@ -4169,22 +4108,19 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ax_cv_check_cflags___xMMD=yes -else case e in #( - e) ax_cv_check_cflags___xMMD=no ;; -esac +else $as_nop + ax_cv_check_cflags___xMMD=no fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext - CFLAGS=$ax_check_save_flags ;; -esac + CFLAGS=$ax_check_save_flags fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ax_cv_check_cflags___xMMD" >&5 printf "%s\n" "$ax_cv_check_cflags___xMMD" >&6; } if test "x$ax_cv_check_cflags___xMMD" = xyes then : DEPFLAGS="-xMMD" -else case e in #( - e) : ;; -esac +else $as_nop + : fi @@ -4203,16 +4139,15 @@ printf %s "checking build system type... if test ${ac_cv_build+y} then : printf %s "(cached) " >&6 -else case e in #( - e) ac_build_alias=$build_alias +else $as_nop + ac_build_alias=$build_alias test "x$ac_build_alias" = x && ac_build_alias=`$SHELL "${ac_aux_dir}config.guess"` test "x$ac_build_alias" = x && as_fn_error $? "cannot guess build type; you must specify one" "$LINENO" 5 ac_cv_build=`$SHELL "${ac_aux_dir}config.sub" $ac_build_alias` || as_fn_error $? "$SHELL ${ac_aux_dir}config.sub $ac_build_alias failed" "$LINENO" 5 - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_build" >&5 printf "%s\n" "$ac_cv_build" >&6; } @@ -4239,15 +4174,14 @@ printf %s "checking host system type... if test ${ac_cv_host+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test "x$host_alias" = x; then +else $as_nop + if test "x$host_alias" = x; then ac_cv_host=$ac_cv_build else ac_cv_host=`$SHELL "${ac_aux_dir}config.sub" $host_alias` || as_fn_error $? "$SHELL ${ac_aux_dir}config.sub $host_alias failed" "$LINENO" 5 fi - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_host" >&5 printf "%s\n" "$ac_cv_host" >&6; } @@ -4274,15 +4208,14 @@ printf %s "checking target system type.. if test ${ac_cv_target+y} then : printf %s "(cached) " >&6 -else case e in #( - e) if test "x$target_alias" = x; then +else $as_nop + if test "x$target_alias" = x; then ac_cv_target=$ac_cv_host else ac_cv_target=`$SHELL "${ac_aux_dir}config.sub" $target_alias` || as_fn_error $? "$SHELL ${ac_aux_dir}config.sub $target_alias failed" "$LINENO" 5 fi - ;; -esac + fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_cv_target" >&5 printf "%s\n" "$ac_cv_target" >&6; } @@ -4336,8 +4269,8 @@ printf %s "checking whether C compiler a if test ${ax_cv_check_cflags__Werror__march_westmere+y} then : printf %s "(cached) " >&6 -else case e in #( - e) +else $as_nop + ax_check_save_flags=$CFLAGS CFLAGS="$CFLAGS -Werror -march=westmere" cat confdefs.h - <<_ACEOF >conftest.$ac_ext @@ -4354,22 +4287,19 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ax_cv_check_cflags__Werror__march_westmere=yes -else case e in #( - e) ax_cv_check_cflags__Werror__march_westmere=no ;; -esac +else $as_nop + ax_cv_check_cflags__Werror__march_westmere=no fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext - CFLAGS=$ax_check_save_flags ;; -esac + CFLAGS=$ax_check_save_flags fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ax_cv_check_cflags__Werror__march_westmere" >&5 printf "%s\n" "$ax_cv_check_cflags__Werror__march_westmere" >&6; } if test "x$ax_cv_check_cflags__Werror__march_westmere" = xyes then : : -else case e in #( - e) : ;; -esac +else $as_nop + : fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking whether C compiler accepts -march=haswell" >&5 @@ -4377,8 +4307,8 @@ printf %s "checking whether C compiler a if test ${ax_cv_check_cflags__Werror__march_haswell+y} then : printf %s "(cached) " >&6 -else case e in #( - e) +else $as_nop + ax_check_save_flags=$CFLAGS CFLAGS="$CFLAGS -Werror -march=haswell" cat confdefs.h - <<_ACEOF >conftest.$ac_ext @@ -4395,22 +4325,19 @@ _ACEOF if ac_fn_c_try_compile "$LINENO" then : ax_cv_check_cflags__Werror__march_haswell=yes -else case e in #( - e) ax_cv_check_cflags__Werror__march_haswell=no ;; -esac +else $as_nop + ax_cv_check_cflags__Werror__march_haswell=no fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext - CFLAGS=$ax_check_save_flags ;; -esac + CFLAGS=$ax_check_save_flags fi { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ax_cv_check_cflags__Werror__march_haswell" >&5 printf "%s\n" "$ax_cv_check_cflags__Werror__march_haswell" >&6; } if test "x$ax_cv_check_cflags__Werror__march_haswell" = xyes then : : -else case e in #( - e) : ;; -esac +else $as_nop + : fi @@ -4449,12 +4376,11 @@ printf "%s\n" "#define HAVE_WESTMERE 1" { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: yes" >&5 printf "%s\n" "yes" >&6; } -else case e in #( - e) +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 printf "%s\n" "no" >&6; } - ;; -esac + fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext CFLAGS="$BAKCFLAGS" @@ -4495,12 +4421,11 @@ printf "%s\n" "#define HAVE_HASWELL 1" > { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: yes" >&5 printf "%s\n" "yes" >&6; } -else case e in #( - e) +else $as_nop + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: no" >&5 printf "%s\n" "no" >&6; } - ;; -esac + fi rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext CFLAGS="$BAKCFLAGS" @@ -4515,9 +4440,8 @@ if test "x$ac_cv_func_realpath" = xyes then : printf "%s\n" "#define HAVE_REALPATH 1" >>confdefs.h -else case e in #( - e) as_fn_error $? "realpath is not available" "$LINENO" 5 ;; -esac +else $as_nop + as_fn_error $? "realpath is not available" "$LINENO" 5 fi done @@ -4538,8 +4462,8 @@ cat >confcache <<\_ACEOF # config.status only pays attention to the cache file if you give it # the --recheck option to rerun configure. # -# 'ac_cv_env_foo' variables (set or unset) will be overridden when -# loading this file, other *unset* 'ac_cv_foo' will be assigned the +# `ac_cv_env_foo' variables (set or unset) will be overridden when +# loading this file, other *unset* `ac_cv_foo' will be assigned the # following values. _ACEOF @@ -4569,14 +4493,14 @@ printf "%s\n" "$as_me: WARNING: cache va (set) 2>&1 | case $as_nl`(ac_space=' '; set) 2>&1` in #( *${as_nl}ac_space=\ *) - # 'set' does not quote correctly, so add quotes: double-quote + # `set' does not quote correctly, so add quotes: double-quote # substitution turns \\\\ into \\, and sed turns \\ into \. sed -n \ "s/'/'\\\\''/g; s/^\\([_$as_cr_alnum]*_cv_[_$as_cr_alnum]*\\)=\\(.*\\)/\\1='\\2'/p" ;; #( *) - # 'set' quotes correctly as required by POSIX, so do not add quotes. + # `set' quotes correctly as required by POSIX, so do not add quotes. sed -n "/^[_$as_cr_alnum]*_cv_[_$as_cr_alnum]*=/p" ;; esac | @@ -4666,6 +4590,7 @@ cat >>$CONFIG_STATUS <<\_ASEOF || as_wri # Be more Bourne compatible DUALCASE=1; export DUALCASE # for MKS sh +as_nop=: if test ${ZSH_VERSION+y} && (emulate sh) >/dev/null 2>&1 then : emulate sh @@ -4674,13 +4599,12 @@ then : # is contrary to our usage. Disable this feature. alias -g '${1+"$@"}'='"$@"' setopt NO_GLOB_SUBST -else case e in #( - e) case `(set -o) 2>/dev/null` in #( +else $as_nop + case `(set -o) 2>/dev/null` in #( *posix*) : set -o posix ;; #( *) : ;; -esac ;; esac fi @@ -4752,7 +4676,7 @@ IFS=$as_save_IFS ;; esac -# We did not find ourselves, most probably we were run as 'sh COMMAND' +# We did not find ourselves, most probably we were run as `sh COMMAND' # in which case we are not to be found in the path. if test "x$as_myself" = x; then as_myself=$0 @@ -4781,6 +4705,7 @@ as_fn_error () } # as_fn_error + # as_fn_set_status STATUS # ----------------------- # Set $? to STATUS, without forking. @@ -4820,12 +4745,11 @@ then : { eval $1+=\$2 }' -else case e in #( - e) as_fn_append () +else $as_nop + as_fn_append () { eval $1=\$$1\$2 - } ;; -esac + } fi # as_fn_append # as_fn_arith ARG... @@ -4839,12 +4763,11 @@ then : { as_val=$(( $* )) }' -else case e in #( - e) as_fn_arith () +else $as_nop + as_fn_arith () { as_val=`expr "$@" || test $? -eq 1` - } ;; -esac + } fi # as_fn_arith @@ -4927,9 +4850,9 @@ if (echo >conf$$.file) 2>/dev/null; then if ln -s conf$$.file conf$$ 2>/dev/null; then as_ln_s='ln -s' # ... but there are two gotchas: - # 1) On MSYS, both 'ln -s file dir' and 'ln file dir' fail. - # 2) DJGPP < 2.04 has no symlinks; 'ln -s' creates a wrapper executable. - # In both cases, we have to default to 'cp -pR'. + # 1) On MSYS, both `ln -s file dir' and `ln file dir' fail. + # 2) DJGPP < 2.04 has no symlinks; `ln -s' creates a wrapper executable. + # In both cases, we have to default to `cp -pR'. ln -s conf$$.file conf$$.dir 2>/dev/null && test ! -f conf$$.exe || as_ln_s='cp -pR' elif ln conf$$.file conf$$ 2>/dev/null; then @@ -5010,12 +4933,10 @@ as_test_x='test -x' as_executable_p=as_fn_executable_p # Sed expression to map a string onto a valid CPP name. -as_sed_cpp="y%*$as_cr_letters%P$as_cr_LETTERS%;s%[^_$as_cr_alnum]%_%g" -as_tr_cpp="eval sed '$as_sed_cpp'" # deprecated +as_tr_cpp="eval sed 'y%*$as_cr_letters%P$as_cr_LETTERS%;s%[^_$as_cr_alnum]%_%g'" # Sed expression to map a string onto a valid variable name. -as_sed_sh="y%*+%pp%;s%[^_$as_cr_alnum]%_%g" -as_tr_sh="eval sed '$as_sed_sh'" # deprecated +as_tr_sh="eval sed 'y%*+%pp%;s%[^_$as_cr_alnum]%_%g'" exec 6>&1 @@ -5030,8 +4951,8 @@ cat >>$CONFIG_STATUS <<\_ACEOF || ac_wri # report actual input values of CONFIG_FILES etc. instead of their # values after options handling. ac_log=" -This file was extended by simdzone $as_me 0.2.4, which was -generated by GNU Autoconf 2.72. Invocation command line was +This file was extended by simdzone $as_me 0.2.5, which was +generated by GNU Autoconf 2.71. Invocation command line was CONFIG_FILES = $CONFIG_FILES CONFIG_HEADERS = $CONFIG_HEADERS @@ -5062,7 +4983,7 @@ _ACEOF cat >>$CONFIG_STATUS <<\_ACEOF || ac_write_fail=1 ac_cs_usage="\ -'$as_me' instantiates files and other configuration actions +\`$as_me' instantiates files and other configuration actions from templates according to the current configuration. Unless the files and actions are specified as TAGs, all are instantiated by default. @@ -5094,11 +5015,11 @@ ac_cs_config_escaped=`printf "%s\n" "$ac cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1 ac_cs_config='$ac_cs_config_escaped' ac_cs_version="\\ -simdzone config.status 0.2.4 -configured by $0, generated by GNU Autoconf 2.72, +simdzone config.status 0.2.5 +configured by $0, generated by GNU Autoconf 2.71, with options \\"\$ac_cs_config\\" -Copyright (C) 2023 Free Software Foundation, Inc. +Copyright (C) 2021 Free Software Foundation, Inc. This config.status script is free software; the Free Software Foundation gives unlimited permission to copy, distribute and modify it." @@ -5157,8 +5078,8 @@ do ac_need_defaults=false;; --he | --h) # Conflict between --help and --header - as_fn_error $? "ambiguous option: '$1' -Try '$0 --help' for more information.";; + as_fn_error $? "ambiguous option: \`$1' +Try \`$0 --help' for more information.";; --help | --hel | -h ) printf "%s\n" "$ac_cs_usage"; exit ;; -q | -quiet | --quiet | --quie | --qui | --qu | --q \ @@ -5166,8 +5087,8 @@ Try '$0 --help' for more information.";; ac_cs_silent=: ;; # This is an error. - -*) as_fn_error $? "unrecognized option: '$1' -Try '$0 --help' for more information." ;; + -*) as_fn_error $? "unrecognized option: \`$1' +Try \`$0 --help' for more information." ;; *) as_fn_append ac_config_targets " $1" ac_need_defaults=false ;; @@ -5218,7 +5139,7 @@ do "config.h") CONFIG_HEADERS="$CONFIG_HEADERS config.h" ;; "Makefile") CONFIG_FILES="$CONFIG_FILES Makefile" ;; - *) as_fn_error $? "invalid argument: '$ac_config_target'" "$LINENO" 5;; + *) as_fn_error $? "invalid argument: \`$ac_config_target'" "$LINENO" 5;; esac done @@ -5237,7 +5158,7 @@ fi # creating and moving files from /tmp can sometimes cause problems. # Hook for its removal unless debugging. # Note that there is a small window in which the directory will not be cleaned: -# after its creation but before its name has been assigned to '$tmp'. +# after its creation but before its name has been assigned to `$tmp'. $debug || { tmp= ac_tmp= @@ -5261,7 +5182,7 @@ ac_tmp=$tmp # Set up the scripts for CONFIG_FILES section. # No need to generate them if there are no CONFIG_FILES. -# This happens for instance with './config.status config.h'. +# This happens for instance with `./config.status config.h'. if test -n "$CONFIG_FILES"; then @@ -5419,13 +5340,13 @@ fi # test -n "$CONFIG_FILES" # Set up the scripts for CONFIG_HEADERS section. # No need to generate them if there are no CONFIG_HEADERS. -# This happens for instance with './config.status Makefile'. +# This happens for instance with `./config.status Makefile'. if test -n "$CONFIG_HEADERS"; then cat >"$ac_tmp/defines.awk" <<\_ACAWK || BEGIN { _ACEOF -# Transform confdefs.h into an awk script 'defines.awk', embedded as +# Transform confdefs.h into an awk script `defines.awk', embedded as # here-document in config.status, that substitutes the proper values into # config.h.in to produce config.h. @@ -5535,7 +5456,7 @@ do esac case $ac_mode$ac_tag in :[FHL]*:*);; - :L* | :C*:*) as_fn_error $? "invalid tag '$ac_tag'" "$LINENO" 5;; + :L* | :C*:*) as_fn_error $? "invalid tag \`$ac_tag'" "$LINENO" 5;; :[FH]-) ac_tag=-:-;; :[FH]*) ac_tag=$ac_tag:$ac_tag.in;; esac @@ -5557,19 +5478,19 @@ do -) ac_f="$ac_tmp/stdin";; *) # Look for the file first in the build tree, then in the source tree # (if the path is not absolute). The absolute path cannot be DOS-style, - # because $ac_f cannot contain ':'. + # because $ac_f cannot contain `:'. test -f "$ac_f" || case $ac_f in [\\/$]*) false;; *) test -f "$srcdir/$ac_f" && ac_f="$srcdir/$ac_f";; esac || - as_fn_error 1 "cannot find input file: '$ac_f'" "$LINENO" 5;; + as_fn_error 1 "cannot find input file: \`$ac_f'" "$LINENO" 5;; esac case $ac_f in *\'*) ac_f=`printf "%s\n" "$ac_f" | sed "s/'/'\\\\\\\\''/g"`;; esac as_fn_append ac_file_inputs " '$ac_f'" done - # Let's still pretend it is 'configure' which instantiates (i.e., don't + # Let's still pretend it is `configure' which instantiates (i.e., don't # use $as_me), people would be surprised to read: # /* config.h. Generated by config.status. */ configure_input='Generated from '` @@ -5693,7 +5614,7 @@ cat >>$CONFIG_STATUS <<_ACEOF || ac_writ esac _ACEOF -# Neutralize VPATH when '$srcdir' = '.'. +# Neutralize VPATH when `$srcdir' = `.'. # Shell code in configure.ac might set extrasub. # FIXME: do we really want to maintain this feature? cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1 @@ -5722,9 +5643,9 @@ test -z "$ac_datarootdir_hack$ac_dataroo { ac_out=`sed -n '/\${datarootdir}/p' "$ac_tmp/out"`; test -n "$ac_out"; } && { ac_out=`sed -n '/^[ ]*datarootdir[ ]*:*=/p' \ "$ac_tmp/out"`; test -z "$ac_out"; } && - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: WARNING: $ac_file contains a reference to the variable 'datarootdir' + { printf "%s\n" "$as_me:${as_lineno-$LINENO}: WARNING: $ac_file contains a reference to the variable \`datarootdir' which seems to be undefined. Please make sure it is defined" >&5 -printf "%s\n" "$as_me: WARNING: $ac_file contains a reference to the variable 'datarootdir' +printf "%s\n" "$as_me: WARNING: $ac_file contains a reference to the variable \`datarootdir' which seems to be undefined. Please make sure it is defined" >&2;} rm -f "$ac_tmp/stdin" Index: usr.sbin/nsd/simdzone/configure.ac =================================================================== RCS file: /cvs/src/usr.sbin/nsd/simdzone/configure.ac,v diff -u -p -r1.1.1.3 configure.ac --- usr.sbin/nsd/simdzone/configure.ac 21 Mar 2026 21:34:33 -0000 1.1.1.3 +++ usr.sbin/nsd/simdzone/configure.ac 21 Sep 2026 16:28:44 -0000 @@ -10,7 +10,7 @@ # platform not supported by NSD here is undesirable. Builds for standalone use # or development/testing are required to use CMake. -AC_INIT([simdzone],[0.2.4],[https://github.com/NLnetLabs/simdzone/issues]) +AC_INIT([simdzone],[0.2.5],[https://github.com/NLnetLabs/simdzone/issues]) AC_CONFIG_HEADERS([config.h]) AC_CONFIG_FILES([Makefile]) Index: usr.sbin/nsd/simdzone/include/zone.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/simdzone/include/zone.h,v diff -u -p -r1.1.1.2 zone.h --- usr.sbin/nsd/simdzone/include/zone.h 6 Sep 2025 17:38:34 -0000 1.1.1.2 +++ usr.sbin/nsd/simdzone/include/zone.h 21 Sep 2026 16:28:44 -0000 @@ -185,8 +185,12 @@ extern "C" { #define ZONE_TYPE_SVCB (64u) /** Service binding @rfc{9460} */ #define ZONE_TYPE_HTTPS (65u) -/** Endpoint discovery for delegation synchronization @draft{ietf, dnsop-generalized-notify} */ +/** Endpoint discovery for delegation synchronization @rfc{9859]} */ #define ZONE_TYPE_DSYNC (66u) +/** Hierarchical Host Identity Tag @rfc{9886} */ +#define ZONE_TYPE_HHIT (67u) +/** UAS Broadcast Remote Identification @rfc{9886} */ +#define ZONE_TYPE_BRID (68u) /** Sender Policy Framework @rfc{7208} */ #define ZONE_TYPE_SPF (99u) /** Node Identifier @rfc{6742} */ @@ -255,6 +259,12 @@ extern "C" { #define ZONE_SVC_PARAM_KEY_OHTTP (8u) /** Supported groups in TLS @draft{ietf, tls-key-share-prediction} */ #define ZONE_SVC_PARAM_KEY_TLS_SUPPORTED_GROUPS (9u) +/** DNS over CoAP resource path @rfc{9953} */ +#define ZONE_SVC_PARAM_KEY_DOCPATH (10u) +/** PvD configuration is available at the well-known path @draft{ietf, intarea-proxy-config} */ +#define ZONE_SVC_PARAM_KEY_PVD (11u) +/** Per-transport operator confidence in serving the nameserver's query load over that transport, as a percentage @draft{johani, dnsop-svcb-oots} */ +#define ZONE_SVC_PARAM_KEY_OOTS (12u) /** Reserved ("invalid key") @rfc{9460} */ #define ZONE_SVC_PARAM_KEY_INVALID_KEY (65535u) /** @} */ @@ -366,7 +376,7 @@ struct zone_file { /** vector of tokens generated by the scanner guaranteed to be large enough to hold every token for a single read + terminators */ struct { const char **head, **tail, *tape[ZONE_TAPE_SIZE + 2]; } fields; - struct { const char **head, **tail, *tape[ZONE_TAPE_SIZE + 1]; } delimiters; + struct { const char **head, **tail, *tape[ZONE_TAPE_SIZE + 2]; } delimiters; struct { uint16_t *head, *tail, tape[ZONE_TAPE_SIZE + 1]; } newlines; }; Index: usr.sbin/nsd/simdzone/src/isadetection.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/simdzone/src/isadetection.h,v diff -u -p -r1.1.1.2 isadetection.h --- usr.sbin/nsd/simdzone/src/isadetection.h 6 Sep 2025 17:38:34 -0000 1.1.1.2 +++ usr.sbin/nsd/simdzone/src/isadetection.h 21 Sep 2026 16:28:44 -0000 @@ -107,6 +107,12 @@ static inline uint32_t detect_supported_ #endif +#elif defined(__riscv) + +static inline uint32_t detect_supported_architectures(void) { + return DEFAULT; +} + #elif defined(__x86_64__) || defined(_M_AMD64) // x64 // Can be found on Intel ISA Reference for CPUID Index: usr.sbin/nsd/simdzone/src/fallback/scanner.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/simdzone/src/fallback/scanner.h,v diff -u -p -r1.1.1.1 scanner.h --- usr.sbin/nsd/simdzone/src/fallback/scanner.h 3 Sep 2025 18:44:23 -0000 1.1.1.1 +++ usr.sbin/nsd/simdzone/src/fallback/scanner.h 21 Sep 2026 16:28:44 -0000 @@ -144,7 +144,7 @@ static really_inline int32_t reindex(par if (left >= ZONE_BLOCK_SIZE) { const char *data_limit = parser->file->buffer.data + (parser->file->buffer.length - ZONE_BLOCK_SIZE); - while (data <= data_limit && ((uintptr_t)tape_limit - (uintptr_t)tape) >= ZONE_BLOCK_SIZE) { + while (data <= data_limit && tape+ZONE_BLOCK_SIZE <= tape_limit) { scan(parser, data, data + ZONE_BLOCK_SIZE); parser->file->buffer.index += ZONE_BLOCK_SIZE; data += ZONE_BLOCK_SIZE; @@ -156,11 +156,10 @@ static really_inline int32_t reindex(par } // only scan partial blocks after reading all data - if (parser->file->end_of_file) { - assert(left < ZONE_BLOCK_SIZE); + if (parser->file->end_of_file && left < ZONE_BLOCK_SIZE) { if (!left) { parser->file->end_of_file = NO_MORE_DATA; - } else if (((uintptr_t)tape_limit - (uintptr_t)tape) >= left) { + } else if(tape+left <= tape_limit) { scan(parser, data, data + left); parser->file->end_of_file = NO_MORE_DATA; parser->file->buffer.index += left; Index: usr.sbin/nsd/simdzone/src/generic/scanner.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/simdzone/src/generic/scanner.h,v diff -u -p -r1.1.1.1 scanner.h --- usr.sbin/nsd/simdzone/src/generic/scanner.h 3 Sep 2025 18:44:23 -0000 1.1.1.1 +++ usr.sbin/nsd/simdzone/src/generic/scanner.h 21 Sep 2026 16:28:44 -0000 @@ -300,7 +300,7 @@ static really_inline int32_t reindex(par if (left >= ZONE_BLOCK_SIZE) { const char *data_limit = parser->file->buffer.data + (parser->file->buffer.length - ZONE_BLOCK_SIZE); - while (data <= data_limit && ((uintptr_t)tape_limit - (uintptr_t)tape) >= ZONE_BLOCK_SIZE) { + while (data <= data_limit && tape+ZONE_BLOCK_SIZE <= tape_limit) { simd_loadu_8x64(&block.input, (const uint8_t *)data); scan(parser, &block); write_indexes(parser, &block, 0); @@ -314,11 +314,10 @@ static really_inline int32_t reindex(par } // only scan partial blocks after reading all data - if (parser->file->end_of_file) { - assert(left < ZONE_BLOCK_SIZE); + if(parser->file->end_of_file && left < ZONE_BLOCK_SIZE) { if (!left) { parser->file->end_of_file = NO_MORE_DATA; - } else if (((uintptr_t)tape_limit - (uintptr_t)tape) >= left) { + } else if (tape+left <= tape_limit) { // input is required to be padded, but may contain garbage uint8_t buffer[ZONE_BLOCK_SIZE] = { 0 }; memcpy(buffer, data, left); Index: usr.sbin/nsd/simdzone/src/generic/svcb.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/simdzone/src/generic/svcb.h,v diff -u -p -r1.1.1.1 svcb.h --- usr.sbin/nsd/simdzone/src/generic/svcb.h 3 Sep 2025 18:44:23 -0000 1.1.1.1 +++ usr.sbin/nsd/simdzone/src/generic/svcb.h 21 Sep 2026 16:28:44 -0000 @@ -239,6 +239,10 @@ static int32_t parse_ech( (void)key; (void)param; + if(token->length == 1 && token->data[0] == '0') { + /* single 0 represents empty buffer */ + return 0; + } if (token->length / 4 > size / 3) SYNTAX_ERROR(parser, "maximum size exceeded"); @@ -416,6 +420,89 @@ static int32_t parse_tls_supported_group } nonnull_all +static int32_t parse_docpath( + parser_t *parser, + const type_info_t *type, + const rdata_info_t *field, + uint16_t key, + const svc_param_info_t *param, + rdata_t *rdata, + const token_t *token) +{ + return parse_alpn(parser, type, field, key, param, rdata, token); +} + +nonnull_all +static int32_t parse_oots( + parser_t *parser, + const type_info_t *type, + const rdata_info_t *field, + uint16_t key, + const svc_param_info_t *param, + rdata_t *rdata, + const token_t *token) +{ + const char *t = token->data, *te = token->data + token->length; + const uint8_t *rdata_start = rdata->octets; + + (void)field; + (void)key; + (void)param; + + while (t < te) { + const char *transport = t; + const uint8_t *transport_out = rdata->octets; + const char *colon = memchr(t, ':', (size_t)(te - t)); + + if (!colon) + SYNTAX_ERROR(parser, "No colon found in oots DNS transport in %s", NAME(type)); + + if(colon == t) + SYNTAX_ERROR(parser, "DNS transport name must have at least 1 character in %s", NAME(type)); + + if (rdata->octets + (colon - t) + 2 > rdata->limit) + SYNTAX_ERROR(parser, "No space for oots DNS transport in %s", NAME(type)); + + if (colon - t > 255) + SYNTAX_ERROR(parser, "DNS transport name too large in %s", NAME(type)); + + *rdata->octets++ = (uint8_t)(colon - t); + memcpy(rdata->octets, transport, (size_t)(colon - t)); + rdata->octets += (colon - t); + + t = colon + 1; + uint64_t number = 0; + for (;; t++) { + const uint64_t digit = (uint8_t)*t - '0'; + if (digit > 9) + break; + number = number * 10 + digit; + } + if(t == colon +1) + SYNTAX_ERROR(parser, "Oots percentage missing in %s", NAME(type)); + if (number > 100) + SYNTAX_ERROR(parser, "Invalid oots percentage in %s", NAME(type)); + + *rdata->octets++ = (uint8_t)number; + + const uint8_t *g; + for (g = rdata_start; g < transport_out; g += ((size_t)(*g)) + 2) { + if (memcmp(g, transport_out, ((size_t)(*transport_out)) + 1) == 0) + SEMANTIC_ERROR(parser, "Duplicate DNS transport in oots in %s", NAME(type)); + } + if (*t != ',') + break; + else + t++; + } + + if (t != te || rdata->octets > rdata->limit) + SYNTAX_ERROR(parser, "Invalid oots in %s", NAME(type)); + return 0; +} + + +nonnull_all static int32_t parse_mandatory_lax( parser_t *parser, const type_info_t *type, @@ -477,6 +564,12 @@ static const svc_param_info_t svc_params // draft-ietf-tls-key-share-prediction-01 section 3.1 SVC_PARAM("tls-supported-groups", 9u, MANDATORY_VALUE, parse_tls_supported_groups, parse_tls_supported_groups), + // RFC 9953 section 5: + SVC_PARAM("docpath", 10u, OPTIONAL_VALUE, parse_docpath, parse_docpath), + // draft-ietf-intarea-proxy-config-13 section 2.1: + SVC_PARAM("pvd", 11u, NO_VALUE, parse_unknown, parse_unknown), + // draft-johani-dnsop-svcb-oots + SVC_PARAM("oots", 12u, MANDATORY_VALUE, parse_oots, parse_oots), }; static const svc_param_info_t unknown_svc_param = @@ -542,6 +635,12 @@ static really_inline size_t scan_svc_par return (void)(*param = &svc_params[(*key = ZONE_SVC_PARAM_KEY_OHTTP)]), 5; else if (memcmp(data, "tls-supported-groups", 20) == 0) return (void)(*param = &svc_params[(*key = ZONE_SVC_PARAM_KEY_TLS_SUPPORTED_GROUPS)]), 20; + else if (memcmp(data, "docpath", 7) == 0) + return (void)(*param = &svc_params[(*key = ZONE_SVC_PARAM_KEY_DOCPATH)]), 7; + else if (memcmp(data, "pvd", 3) == 0) + return (void)(*param = &svc_params[(*key = ZONE_SVC_PARAM_KEY_PVD)]), 3; + else if (memcmp(data, "oots", 4) == 0) + return (void)(*param = &svc_params[(*key = ZONE_SVC_PARAM_KEY_OOTS)]), 4; else if (memcmp(data, "key", 3) == 0) return scan_unknown_svc_param_key(data, key, param); else Index: usr.sbin/nsd/simdzone/src/generic/type.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/simdzone/src/generic/type.h,v diff -u -p -r1.1.1.2 type.h --- usr.sbin/nsd/simdzone/src/generic/type.h 6 Sep 2025 17:38:34 -0000 1.1.1.2 +++ usr.sbin/nsd/simdzone/src/generic/type.h 21 Sep 2026 16:28:44 -0000 @@ -18,38 +18,38 @@ static const struct { const mnemonic_t *mnemonic; int32_t code; } types_and_classes[256] = { - V(0), V(0), V(0), V(0), V(0), V(0), T(34), V(0), - V(0), V(0), T(30), V(0), V(0), T(57), V(0), T(16), - V(0), V(0), T(56), T(14), T(12), V(0), V(0), T(13), - T(61), V(0), T(105), V(0), V(0), V(0), T(32), T(258), - V(0), T(107), T(47), V(0), V(0), V(0), T(17), V(0), - T(257), V(0), V(0), V(0), V(0), V(0), V(0), V(0), - T(65), V(0), V(0), T(18), V(0), T(1), V(0), T(263), - V(0), V(0), V(0), V(0), T(51), V(0), V(0), T(106), - T(3), V(0), V(0), T(31), V(0), V(0), V(0), V(0), - V(0), T(50), T(44), T(104), T(10), V(0), V(0), V(0), - V(0), V(0), T(55), V(0), T(28), V(0), V(0), V(0), - V(0), V(0), V(0), V(0), V(0), V(0), V(0), T(39), - T(35), V(0), V(0), T(5), T(29), T(262), V(0), V(0), - T(109), V(0), T(264), V(0), V(0), V(0), V(0), V(0), - V(0), T(21), V(0), V(0), V(0), V(0), V(0), V(0), - T(37), C(1), T(58), V(0), V(0), V(0), V(0), V(0), - V(0), V(0), V(0), C(3), V(0), T(52), T(11), T(20), - V(0), T(261), V(0), V(0), V(0), T(48), V(0), V(0), - V(0), T(25), C(2), T(43), V(0), V(0), C(4), T(60), - V(0), V(0), T(7), T(2), V(0), V(0), T(46), T(22), - V(0), V(0), V(0), V(0), V(0), V(0), V(0), T(64), - V(0), T(260), V(0), V(0), V(0), V(0), T(38), V(0), - V(0), T(259), T(59), V(0), V(0), V(0), T(42), T(36), - T(8), T(15), V(0), T(26), T(27), T(6), V(0), T(99), - V(0), V(0), V(0), V(0), V(0), V(0), V(0), T(53), - T(9), T(63), T(33), V(0), T(271), T(270), V(0), T(40), - V(0), V(0), T(24), T(19), V(0), V(0), V(0), V(0), - V(0), V(0), V(0), T(108), V(0), V(0), V(0), T(62), - V(0), V(0), V(0), V(0), V(0), T(66), T(4), V(0), - V(0), V(0), T(256), V(0), T(49), V(0), V(0), V(0), - V(0), V(0), T(45), V(0), V(0), T(23), V(0), V(0), - V(0), V(0), V(0), V(0), V(0), V(0), V(0), V(0) + V(0), V(0), T(58), T(66), V(0), V(0), T(65), V(0), + V(0), T(53), V(0), V(0), T(67), T(108), V(0), V(0), + V(0), T(4), V(0), V(0), V(0), T(49), V(0), V(0), + V(0), V(0), V(0), V(0), V(0), T(31), V(0), V(0), + V(0), V(0), V(0), T(28), T(104), V(0), T(257), V(0), + V(0), V(0), T(27), V(0), V(0), V(0), V(0), T(48), + V(0), V(0), V(0), V(0), V(0), T(1), V(0), T(47), + V(0), V(0), T(34), V(0), T(263), V(0), T(106), V(0), + V(0), V(0), V(0), V(0), V(0), T(35), V(0), T(25), + V(0), V(0), V(0), V(0), V(0), V(0), V(0), T(56), + T(14), T(260), T(107), V(0), T(13), T(68), V(0), T(17), + V(0), V(0), V(0), V(0), V(0), V(0), T(50), V(0), + V(0), T(109), T(52), T(258), V(0), V(0), T(45), V(0), + T(264), V(0), T(3), V(0), V(0), T(19), V(0), V(0), + V(0), V(0), V(0), V(0), V(0), V(0), V(0), V(0), + T(61), V(0), V(0), T(42), V(0), V(0), V(0), T(40), + V(0), V(0), T(24), T(60), V(0), V(0), T(55), V(0), + V(0), T(12), V(0), V(0), V(0), V(0), V(0), V(0), + V(0), V(0), T(11), V(0), V(0), V(0), V(0), V(0), + V(0), V(0), T(37), V(0), T(46), T(23), V(0), T(262), + T(64), V(0), T(261), V(0), T(29), T(21), V(0), V(0), + V(0), C(1), V(0), V(0), V(0), T(10), T(57), C(3), + T(271), T(33), V(0), V(0), V(0), V(0), V(0), T(259), + T(18), V(0), T(59), T(30), V(0), V(0), V(0), V(0), + T(16), V(0), V(0), T(7), T(6), C(2), T(43), T(20), + V(0), C(4), V(0), V(0), V(0), V(0), T(2), T(38), + T(22), T(51), V(0), V(0), V(0), V(0), V(0), T(99), + V(0), T(256), V(0), V(0), V(0), T(105), V(0), V(0), + T(44), T(39), V(0), V(0), T(8), V(0), T(5), V(0), + V(0), V(0), V(0), V(0), V(0), T(36), T(32), T(15), + V(0), T(26), V(0), V(0), V(0), T(270), V(0), V(0), + V(0), V(0), T(9), V(0), T(63), V(0), T(62), V(0) }; #undef V @@ -110,7 +110,7 @@ static really_inline uint8_t hash(uint64 prefix = le64toh(prefix); uint32_t value = (uint32_t)((prefix >> 32) ^ prefix); // magic value is generated using hash.c, rerun when adding types - return (uint8_t)((value * 3537259401ull) >> 32); + return (uint8_t)((value * 3547541308ull) >> 32); } nonnull_all Index: usr.sbin/nsd/simdzone/src/generic/types.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/simdzone/src/generic/types.h,v diff -u -p -r1.1.1.3 types.h --- usr.sbin/nsd/simdzone/src/generic/types.h 21 Mar 2026 21:34:33 -0000 1.1.1.3 +++ usr.sbin/nsd/simdzone/src/generic/types.h 21 Sep 2026 16:28:44 -0000 @@ -2340,6 +2340,55 @@ static int32_t parse_dsync_rdata( } nonnull_all +static int32_t check_hhit_rr( + parser_t *parser, const type_info_t *type, const rdata_t *rdata) +{ + // FIXME: It is a CBOR blob with some internal structure, but ignoring the + // internal structure, a minimally sized CBOR blob is 1 byte + if ((uintptr_t)rdata->octets - (uintptr_t)parser->rdata->octets < 1) + SYNTAX_ERROR(parser, "Invalid %s", NAME(type)); + return accept_rr(parser, type, rdata); +} + +nonnull_all +static int32_t parse_hhit_rdata( + parser_t *parser, const type_info_t *type, rdata_t *rdata, token_t *token) +{ + int32_t code; + const rdata_info_t *fields = type->rdata.fields; + + if ((code = parse_base64_sequence(parser, type, &fields[0], rdata, token)) < 0) + return code; + + return check_hhit_rr(parser, type, rdata); +} + +nonnull_all +static int32_t check_brid_rr( + parser_t *parser, const type_info_t *type, const rdata_t *rdata) +{ + // FIXME: It is a CBOR blob with some internal structure, but ignoring the + // internal structure, a minimally sized CBOR blob is 1 byte + if ((uintptr_t)rdata->octets - (uintptr_t)parser->rdata->octets < 1) + SYNTAX_ERROR(parser, "Invalid %s", NAME(type)); + return accept_rr(parser, type, rdata); +} + +nonnull_all +static int32_t parse_brid_rdata( + parser_t *parser, const type_info_t *type, rdata_t *rdata, token_t *token) +{ + int32_t code; + const rdata_info_t *fields = type->rdata.fields; + + if ((code = parse_base64_sequence(parser, type, &fields[0], rdata, token)) < 0) + return code; + + return check_brid_rr(parser, type, rdata); +} + + +nonnull_all static int32_t check_nid_rr( parser_t *parser, const type_info_t *type, const rdata_t *rdata) { @@ -3281,6 +3330,14 @@ static const rdata_info_t dsync_rdata_fi FIELD("target") }; +static const rdata_info_t hhit_rdata_fields[] = { + FIELD("cbor blob"), +}; + +static const rdata_info_t brid_rdata_fields[] = { + FIELD("cbor blob"), +}; + static const rdata_info_t spf_rdata_fields[] = { FIELD("text") }; @@ -3526,8 +3583,10 @@ static const type_info_t types[] = { check_https_rr, parse_https_rdata), TYPE("DSYNC", ZONE_TYPE_DSYNC, ZONE_CLASS_ANY, FIELDS(dsync_rdata_fields), check_dsync_rr, parse_dsync_rdata), - UNKNOWN_TYPE(67), - UNKNOWN_TYPE(68), + TYPE("HHIT", ZONE_TYPE_HHIT, ZONE_CLASS_ANY, FIELDS(hhit_rdata_fields), + check_hhit_rr, parse_hhit_rdata), + TYPE("BRID", ZONE_TYPE_BRID, ZONE_CLASS_ANY, FIELDS(brid_rdata_fields), + check_brid_rr, parse_brid_rdata), UNKNOWN_TYPE(69), UNKNOWN_TYPE(70), UNKNOWN_TYPE(71), Index: usr.sbin/nsd/simdzone/src/westmere/type.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/simdzone/src/westmere/type.h,v diff -u -p -r1.1.1.2 type.h --- usr.sbin/nsd/simdzone/src/westmere/type.h 6 Sep 2025 17:38:34 -0000 1.1.1.2 +++ usr.sbin/nsd/simdzone/src/westmere/type.h 21 Sep 2026 16:28:44 -0000 @@ -18,38 +18,38 @@ static const struct { const mnemonic_t *mnemonic; int32_t code; } types_and_classes[256] = { - V(0), V(0), V(0), V(0), V(0), V(0), T(34), V(0), - V(0), V(0), T(30), V(0), V(0), T(57), V(0), T(16), - V(0), V(0), T(56), T(14), T(12), V(0), V(0), T(13), - T(61), V(0), T(105), V(0), V(0), V(0), T(32), T(258), - V(0), T(107), T(47), V(0), V(0), V(0), T(17), V(0), - T(257), V(0), V(0), V(0), V(0), V(0), V(0), V(0), - T(65), V(0), V(0), T(18), V(0), T(1), V(0), T(263), - V(0), V(0), V(0), V(0), T(51), V(0), V(0), T(106), - T(3), V(0), V(0), T(31), V(0), V(0), V(0), V(0), - V(0), T(50), T(44), T(104), T(10), V(0), V(0), V(0), - V(0), V(0), T(55), V(0), T(28), V(0), V(0), V(0), - V(0), V(0), V(0), V(0), V(0), V(0), V(0), T(39), - T(35), V(0), V(0), T(5), T(29), T(262), V(0), V(0), - T(109), V(0), T(264), V(0), V(0), V(0), V(0), V(0), - V(0), T(21), V(0), V(0), V(0), V(0), V(0), V(0), - T(37), C(1), T(58), V(0), V(0), V(0), V(0), V(0), - V(0), V(0), V(0), C(3), V(0), T(52), T(11), T(20), - V(0), T(261), V(0), V(0), V(0), T(48), V(0), V(0), - V(0), T(25), C(2), T(43), V(0), V(0), C(4), T(60), - V(0), V(0), T(7), T(2), V(0), V(0), T(46), T(22), - V(0), V(0), V(0), V(0), V(0), V(0), V(0), T(64), - V(0), T(260), V(0), V(0), V(0), V(0), T(38), V(0), - V(0), T(259), T(59), V(0), V(0), V(0), T(42), T(36), - T(8), T(15), V(0), T(26), T(27), T(6), V(0), T(99), - V(0), V(0), V(0), V(0), V(0), V(0), V(0), T(53), - T(9), T(63), T(33), V(0), T(271), T(270), V(0), T(40), - V(0), V(0), T(24), T(19), V(0), V(0), V(0), V(0), - V(0), V(0), V(0), T(108), V(0), V(0), V(0), T(62), - V(0), V(0), V(0), V(0), V(0), T(66), T(4), V(0), - V(0), V(0), T(256), V(0), T(49), V(0), V(0), V(0), - V(0), V(0), T(45), V(0), V(0), T(23), V(0), V(0), - V(0), V(0), V(0), V(0), V(0), V(0), V(0), V(0) + V(0), V(0), T(58), T(66), V(0), V(0), T(65), V(0), + V(0), T(53), V(0), V(0), T(67), T(108), V(0), V(0), + V(0), T(4), V(0), V(0), V(0), T(49), V(0), V(0), + V(0), V(0), V(0), V(0), V(0), T(31), V(0), V(0), + V(0), V(0), V(0), T(28), T(104), V(0), T(257), V(0), + V(0), V(0), T(27), V(0), V(0), V(0), V(0), T(48), + V(0), V(0), V(0), V(0), V(0), T(1), V(0), T(47), + V(0), V(0), T(34), V(0), T(263), V(0), T(106), V(0), + V(0), V(0), V(0), V(0), V(0), T(35), V(0), T(25), + V(0), V(0), V(0), V(0), V(0), V(0), V(0), T(56), + T(14), T(260), T(107), V(0), T(13), T(68), V(0), T(17), + V(0), V(0), V(0), V(0), V(0), V(0), T(50), V(0), + V(0), T(109), T(52), T(258), V(0), V(0), T(45), V(0), + T(264), V(0), T(3), V(0), V(0), T(19), V(0), V(0), + V(0), V(0), V(0), V(0), V(0), V(0), V(0), V(0), + T(61), V(0), V(0), T(42), V(0), V(0), V(0), T(40), + V(0), V(0), T(24), T(60), V(0), V(0), T(55), V(0), + V(0), T(12), V(0), V(0), V(0), V(0), V(0), V(0), + V(0), V(0), T(11), V(0), V(0), V(0), V(0), V(0), + V(0), V(0), T(37), V(0), T(46), T(23), V(0), T(262), + T(64), V(0), T(261), V(0), T(29), T(21), V(0), V(0), + V(0), C(1), V(0), V(0), V(0), T(10), T(57), C(3), + T(271), T(33), V(0), V(0), V(0), V(0), V(0), T(259), + T(18), V(0), T(59), T(30), V(0), V(0), V(0), V(0), + T(16), V(0), V(0), T(7), T(6), C(2), T(43), T(20), + V(0), C(4), V(0), V(0), V(0), V(0), T(2), T(38), + T(22), T(51), V(0), V(0), V(0), V(0), V(0), T(99), + V(0), T(256), V(0), V(0), V(0), T(105), V(0), V(0), + T(44), T(39), V(0), V(0), T(8), V(0), T(5), V(0), + V(0), V(0), V(0), V(0), V(0), T(36), T(32), T(15), + V(0), T(26), V(0), V(0), V(0), T(270), V(0), V(0), + V(0), V(0), T(9), V(0), T(63), V(0), T(62), V(0) }; #undef V @@ -102,7 +102,7 @@ static really_inline uint8_t hash(uint64 { uint32_t value = (uint32_t)((prefix >> 32) ^ prefix); // magic value is generated using hash.c, rerun when adding types - return (uint8_t)((value * 3537259401ull) >> 32); + return (uint8_t)((value * 3547541308ull) >> 32); } nonnull_all Index: usr.sbin/nsd/util/proxy_protocol.c =================================================================== RCS file: /cvs/src/usr.sbin/nsd/util/proxy_protocol.c,v diff -u -p -r1.1 proxy_protocol.c --- usr.sbin/nsd/util/proxy_protocol.c 20 Dec 2023 17:29:02 -0000 1.1 +++ usr.sbin/nsd/util/proxy_protocol.c 21 Sep 2026 16:28:44 -0000 @@ -184,14 +184,23 @@ pp2_read_header(uint8_t* buf, size_t buf (header->ver_cmd & 0xF) != PP2_CMD_PROXY) { return PP_PARSE_UNKNOWN_CMD; } - /* Check for supported family and protocol */ - if(header->fam_prot != PP2_UNSPEC_UNSPEC && - header->fam_prot != PP2_INET_STREAM && - header->fam_prot != PP2_INET_DGRAM && - header->fam_prot != PP2_INET6_STREAM && - header->fam_prot != PP2_INET6_DGRAM && - header->fam_prot != PP2_UNIX_STREAM && - header->fam_prot != PP2_UNIX_DGRAM) { + /* Check for supported family and protocol, and that len covers + * the per-family address block (proxy-protocol.txt s2.2). */ + switch(header->fam_prot) { + case PP2_UNSPEC_UNSPEC: + break; + case PP2_INET_STREAM: + case PP2_INET_DGRAM: + if(ntohs(header->len) < PP2_HEADER_LEN_INET) + return PP_PARSE_SIZE; + break; + case PP2_INET6_STREAM: + case PP2_INET6_DGRAM: + if(ntohs(header->len) < PP2_HEADER_LEN_INET6) + return PP_PARSE_SIZE; + break; + default: + /* PP2_UNIX_STREAM, PP2_UNIX_DGRAM, others. */ return PP_PARSE_UNKNOWN_FAM_PROT; } /* We have a correct header */ Index: usr.sbin/nsd/util/proxy_protocol.h =================================================================== RCS file: /cvs/src/usr.sbin/nsd/util/proxy_protocol.h,v diff -u -p -r1.1 proxy_protocol.h --- usr.sbin/nsd/util/proxy_protocol.h 20 Dec 2023 17:29:02 -0000 1.1 +++ usr.sbin/nsd/util/proxy_protocol.h 21 Sep 2026 16:28:44 -0000 @@ -54,6 +54,15 @@ /** PROXYv2 version (protocol value) */ #define PP2_VERSION 0x2 +/** PROXYv2 minimum header.len value for TCP/UDP over IPv4 */ +#define PP2_HEADER_LEN_INET 12 + +/** PROXYv2 minimum header.len value for TCP/UDP over IPv6 */ +#define PP2_HEADER_LEN_INET6 36 + +/** PROXYv2 minimum header.len value for TCP/UDP over AF_UNIX */ +#define PP2_HEADER_LEN_UNIX 216 + /** * PROXYv2 command (protocol value). */