opnsense-src/contrib/bind9/lib/isc/unix/stdtime.c
Doug Barton 37bb75f740 Upgrade to 9.6-ESV-R4-P1, which address the following issues:
1. Very large RRSIG RRsets included in a negative cache can trigger
an assertion failure that will crash named (BIND 9 DNS) due to an
off-by-one error in a buffer size check.

This bug affects all resolving name servers, whether DNSSEC validation
is enabled or not, on all BIND versions prior to today. There is a
possibility of malicious exploitation of this bug by remote users.

2. Named could fail to validate zones listed in a DLV that validated
insecure without using DLV and had DS records in the parent zone.

Add a patch provided by ru@ and confirmed by ISC to fix a crash at
shutdown time when a SIG(0) key is being used.
2011-05-28 00:21:28 +00:00

86 lines
2.1 KiB
C

/*
* Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 1999-2001 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
* purpose with or without fee is hereby granted, provided that the above
* copyright notice and this permission notice appear in all copies.
*
* THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
* REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
* AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
* INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
* LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
* OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: stdtime.c,v 1.19 2007-06-19 23:47:18 tbox Exp $ */
/*! \file */
#include <config.h>
#include <stddef.h> /* NULL */
#include <stdlib.h> /* NULL */
#include <syslog.h>
#include <sys/time.h>
#include <isc/stdtime.h>
#include <isc/util.h>
#ifndef ISC_FIX_TV_USEC
#define ISC_FIX_TV_USEC 1
#endif
#define US_PER_S 1000000
#if ISC_FIX_TV_USEC
static inline void
fix_tv_usec(struct timeval *tv) {
isc_boolean_t fixed = ISC_FALSE;
if (tv->tv_usec < 0) {
fixed = ISC_TRUE;
do {
tv->tv_sec -= 1;
tv->tv_usec += US_PER_S;
} while (tv->tv_usec < 0);
} else if (tv->tv_usec >= US_PER_S) {
fixed = ISC_TRUE;
do {
tv->tv_sec += 1;
tv->tv_usec -= US_PER_S;
} while (tv->tv_usec >=US_PER_S);
}
/*
* Call syslog directly as we are called from the logging functions.
*/
if (fixed)
(void)syslog(LOG_ERR, "gettimeofday returned bad tv_usec: corrected");
}
#endif
void
isc_stdtime_get(isc_stdtime_t *t) {
struct timeval tv;
/*
* Set 't' to the number of seconds since 00:00:00 UTC, January 1,
* 1970.
*/
REQUIRE(t != NULL);
RUNTIME_CHECK(gettimeofday(&tv, NULL) != -1);
#if ISC_FIX_TV_USEC
fix_tv_usec(&tv);
INSIST(tv.tv_usec >= 0);
#else
INSIST(tv.tv_usec >= 0 && tv.tv_usec < US_PER_S);
#endif
*t = (unsigned int)tv.tv_sec;
}