847eec
From fff2960981a3294ac641968a17558c8d7eecf74d Mon Sep 17 00:00:00 2001
847eec
From: Mark Andrews <marka@isc.org>
847eec
Date: Wed, 24 Aug 2022 12:21:50 +1000
847eec
Subject: [PATCH] Have dns_zt_apply lock the zone table
847eec
847eec
There where a number of places where the zone table should have
847eec
been locked, but wasn't, when dns_zt_apply was called.
847eec
847eec
Added a isc_rwlocktype_t type parameter to dns_zt_apply and adjusted
847eec
all calls to using it.  Removed locks in callers.
847eec
847eec
Modified upstream commit for v9_11
847eec
---
847eec
 bin/named/server.c       | 11 ++++++-----
847eec
 bin/named/statschannel.c |  8 ++++----
847eec
 lib/dns/include/dns/zt.h |  4 ++--
847eec
 lib/dns/tests/zt_test.c  |  3 ++-
847eec
 lib/dns/view.c           |  3 ++-
847eec
 lib/dns/zt.c             | 34 +++++++++++++++++++---------------
847eec
 6 files changed, 35 insertions(+), 28 deletions(-)
847eec
847eec
diff --git a/bin/named/server.c b/bin/named/server.c
847eec
index 9826588e6d..0b4b309461 100644
847eec
--- a/bin/named/server.c
847eec
+++ b/bin/named/server.c
847eec
@@ -8723,8 +8723,8 @@ load_configuration(const char *filename, ns_server_t *server,
847eec
 		    strcmp(view->name, "_bind") != 0)
847eec
 		{
847eec
 			dns_view_setviewrevert(view);
847eec
-			(void)dns_zt_apply(view->zonetable, false,
847eec
-					   removed, view);
847eec
+			(void)dns_zt_apply(view->zonetable, isc_rwlocktype_read,
847eec
+					   false, removed, view);
847eec
 		}
847eec
 		dns_view_detach(&view);
847eec
 	}
847eec
@@ -10090,8 +10090,8 @@ add_view_tolist(struct dumpcontext *dctx, dns_view_t *view) {
847eec
 	ISC_LIST_INIT(vle->zonelist);
847eec
 	ISC_LIST_APPEND(dctx->viewlist, vle, link);
847eec
 	if (dctx->dumpzones)
847eec
-		result = dns_zt_apply(view->zonetable, true,
847eec
-				      add_zone_tolist, dctx);
847eec
+		result = dns_zt_apply(view->zonetable, isc_rwlocktype_read,
847eec
+				      true, add_zone_tolist, dctx);
847eec
 	return (result);
847eec
 }
847eec
 
847eec
@@ -11367,7 +11367,8 @@ ns_server_sync(ns_server_t *server, isc_lex_t *lex, isc_buffer_t **text) {
847eec
 		for (view = ISC_LIST_HEAD(server->viewlist);
847eec
 		     view != NULL;
847eec
 		     view = ISC_LIST_NEXT(view, link)) {
847eec
-			result = dns_zt_apply(view->zonetable, false,
847eec
+			result = dns_zt_apply(view->zonetable,
847eec
+					      isc_rwlocktype_none, false,
847eec
 					      synczone, &cleanup);
847eec
 			if (result != ISC_R_SUCCESS &&
847eec
 			    tresult == ISC_R_SUCCESS)
847eec
diff --git a/bin/named/statschannel.c b/bin/named/statschannel.c
847eec
index 12ab048469..9828df0f4e 100644
847eec
--- a/bin/named/statschannel.c
847eec
+++ b/bin/named/statschannel.c
847eec
@@ -1833,8 +1833,8 @@ generatexml(ns_server_t *server, uint32_t flags,
847eec
 		if ((flags & STATS_XML_ZONES) != 0) {
847eec
 			TRY0(xmlTextWriterStartElement(writer,
847eec
 						       ISC_XMLCHAR "zones"));
847eec
-			result = dns_zt_apply(view->zonetable, true,
847eec
-					      zone_xmlrender, writer);
847eec
+			result = dns_zt_apply(view->zonetable, isc_rwlocktype_read,
847eec
+					      true, zone_xmlrender, writer);
847eec
 			if (result != ISC_R_SUCCESS)
847eec
 				goto error;
847eec
 			TRY0(xmlTextWriterEndElement(writer)); /* /zones */
847eec
@@ -2489,8 +2489,8 @@ generatejson(ns_server_t *server, size_t *msglen,
847eec
 			CHECKMEM(za);
847eec
 
847eec
 			if ((flags & STATS_JSON_ZONES) != 0) {
847eec
-				result = dns_zt_apply(view->zonetable, true,
847eec
-						      zone_jsonrender, za);
847eec
+				result = dns_zt_apply(view->zonetable, isc_rwlocktype_read,
847eec
+						      true, zone_jsonrender, za);
847eec
 				if (result != ISC_R_SUCCESS) {
847eec
 					goto error;
847eec
 				}
847eec
diff --git a/lib/dns/include/dns/zt.h b/lib/dns/include/dns/zt.h
847eec
index e658e5bb67..94212250da 100644
847eec
--- a/lib/dns/include/dns/zt.h
847eec
+++ b/lib/dns/include/dns/zt.h
847eec
@@ -177,11 +177,11 @@ dns_zt_freezezones(dns_zt_t *zt, bool freeze);
847eec
  */
847eec
 
847eec
 isc_result_t
847eec
-dns_zt_apply(dns_zt_t *zt, bool stop,
847eec
+dns_zt_apply(dns_zt_t *zt, isc_rwlocktype_t lock, bool stop,
847eec
 	     isc_result_t (*action)(dns_zone_t *, void *), void *uap);
847eec
 
847eec
 isc_result_t
847eec
-dns_zt_apply2(dns_zt_t *zt, bool stop, isc_result_t *sub,
847eec
+dns_zt_apply2(dns_zt_t *zt, isc_rwlocktype_t lock, bool stop, isc_result_t *sub,
847eec
 	      isc_result_t (*action)(dns_zone_t *, void *), void *uap);
847eec
 /*%<
847eec
  * Apply a given 'action' to all zone zones in the table.
847eec
diff --git a/lib/dns/tests/zt_test.c b/lib/dns/tests/zt_test.c
847eec
index 3f1e812d60..ee75303a50 100644
847eec
--- a/lib/dns/tests/zt_test.c
847eec
+++ b/lib/dns/tests/zt_test.c
847eec
@@ -145,7 +145,8 @@ apply(void **state) {
847eec
 	assert_non_null(view->zonetable);
847eec
 
847eec
 	assert_int_equal(nzones, 0);
847eec
-	result = dns_zt_apply(view->zonetable, false, count_zone, &nzones);
847eec
+	result = dns_zt_apply2(view->zonetable, isc_rwlocktype_read, false, NULL,
847eec
+			      count_zone, &nzones);
847eec
 	assert_int_equal(result, ISC_R_SUCCESS);
847eec
 	assert_int_equal(nzones, 1);
847eec
 
847eec
diff --git a/lib/dns/view.c b/lib/dns/view.c
847eec
index f01b4dea0f..bd1ced2863 100644
847eec
--- a/lib/dns/view.c
847eec
+++ b/lib/dns/view.c
847eec
@@ -676,7 +676,8 @@ dns_view_dialup(dns_view_t *view) {
847eec
 	REQUIRE(DNS_VIEW_VALID(view));
847eec
 	REQUIRE(view->zonetable != NULL);
847eec
 
847eec
-	(void)dns_zt_apply(view->zonetable, false, dialup, NULL);
847eec
+	(void)dns_zt_apply2(view->zonetable, isc_rwlocktype_read, false, NULL,
847eec
+			   dialup, NULL);
847eec
 }
847eec
 
847eec
 void
847eec
diff --git a/lib/dns/zt.c b/lib/dns/zt.c
847eec
index 3f12e247e0..af65740325 100644
847eec
--- a/lib/dns/zt.c
847eec
+++ b/lib/dns/zt.c
847eec
@@ -202,7 +202,8 @@ flush(dns_zone_t *zone, void *uap) {
847eec
 static void
847eec
 zt_destroy(dns_zt_t *zt) {
847eec
 	if (zt->flush) {
847eec
-		(void)dns_zt_apply(zt, false, flush, NULL);
847eec
+		(void)dns_zt_apply(zt, isc_rwlocktype_none,
847eec
+				   false, flush, NULL);
847eec
 	}
847eec
 	isc_refcount_destroy(&zt->references);
847eec
 	dns_rbt_destroy(&zt->table);
847eec
@@ -249,9 +250,7 @@ dns_zt_load(dns_zt_t *zt, bool stop) {
847eec
 
847eec
 	REQUIRE(VALID_ZT(zt));
847eec
 
847eec
-	RWLOCK(&zt->rwlock, isc_rwlocktype_read);
847eec
-	result = dns_zt_apply(zt, stop, load, NULL);
847eec
-	RWUNLOCK(&zt->rwlock, isc_rwlocktype_read);
847eec
+	result = dns_zt_apply2(zt, isc_rwlocktype_read, stop, NULL, load, NULL);
847eec
 	return (result);
847eec
 }
847eec
 
847eec
@@ -293,7 +292,7 @@ dns_zt_asyncload2(dns_zt_t *zt, dns_zt_allloaded_t alldone, void *arg,
847eec
 	 * Prevent loads_pending going to zero while kicking off the loads.
847eec
 	 */
847eec
 	zt->loads_pending++;
847eec
-	result = dns_zt_apply2(zt, false, NULL, asyncload, &params);
847eec
+	result = dns_zt_apply2(zt, isc_rwlocktype_none, false, NULL, asyncload, &params);
847eec
 	pending = --zt->loads_pending;
847eec
 	if (pending != 0) {
847eec
 		zt->loaddone = alldone;
847eec
@@ -342,9 +341,7 @@ dns_zt_loadnew(dns_zt_t *zt, bool stop) {
847eec
 
847eec
 	REQUIRE(VALID_ZT(zt));
847eec
 
847eec
-	RWLOCK(&zt->rwlock, isc_rwlocktype_read);
847eec
-	result = dns_zt_apply(zt, stop, loadnew, NULL);
847eec
-	RWUNLOCK(&zt->rwlock, isc_rwlocktype_read);
847eec
+	result = dns_zt_apply(zt, isc_rwlocktype_read, stop, loadnew, NULL);
847eec
 	return (result);
847eec
 }
847eec
 
847eec
@@ -366,9 +363,7 @@ dns_zt_freezezones(dns_zt_t *zt, bool freeze) {
847eec
 
847eec
 	REQUIRE(VALID_ZT(zt));
847eec
 
847eec
-	RWLOCK(&zt->rwlock, isc_rwlocktype_read);
847eec
-	result = dns_zt_apply2(zt, false, &tresult, freezezones, &freeze);
847eec
-	RWUNLOCK(&zt->rwlock, isc_rwlocktype_read);
847eec
+	result = dns_zt_apply2(zt, isc_rwlocktype_read, false, &tresult, freezezones, &freeze);
847eec
 	if (tresult == ISC_R_NOTFOUND)
847eec
 		tresult = ISC_R_SUCCESS;
847eec
 	return ((result == ISC_R_SUCCESS) ? tresult : result);
847eec
@@ -490,14 +485,14 @@ dns_zt_setviewrevert(dns_zt_t *zt) {
847eec
 }
847eec
 
847eec
 isc_result_t
847eec
-dns_zt_apply(dns_zt_t *zt, bool stop,
847eec
+dns_zt_apply(dns_zt_t *zt, isc_rwlocktype_t lock, bool stop,
847eec
 	     isc_result_t (*action)(dns_zone_t *, void *), void *uap)
847eec
 {
847eec
-	return (dns_zt_apply2(zt, stop, NULL, action, uap));
847eec
+	return (dns_zt_apply2(zt, lock, stop, NULL, action, uap));
847eec
 }
847eec
 
847eec
 isc_result_t
847eec
-dns_zt_apply2(dns_zt_t *zt, bool stop, isc_result_t *sub,
847eec
+dns_zt_apply2(dns_zt_t *zt, isc_rwlocktype_t lock, bool stop, isc_result_t *sub,
847eec
 	      isc_result_t (*action)(dns_zone_t *, void *), void *uap)
847eec
 {
847eec
 	dns_rbtnode_t *node;
847eec
@@ -508,6 +503,10 @@ dns_zt_apply2(dns_zt_t *zt, bool stop, isc_result_t *sub,
847eec
 	REQUIRE(VALID_ZT(zt));
847eec
 	REQUIRE(action != NULL);
847eec
 
847eec
+	if (lock != isc_rwlocktype_none) {
847eec
+		RWLOCK(&zt->rwlock, lock);
847eec
+	}
847eec
+
847eec
 	dns_rbtnodechain_init(&chain, zt->mctx);
847eec
 	result = dns_rbtnodechain_first(&chain, zt->table, NULL, NULL);
847eec
 	if (result == ISC_R_NOTFOUND) {
847eec
@@ -538,8 +537,13 @@ dns_zt_apply2(dns_zt_t *zt, bool stop, isc_result_t *sub,
847eec
 
847eec
  cleanup:
847eec
 	dns_rbtnodechain_invalidate(&chain);
847eec
-	if (sub != NULL)
847eec
+	if (sub != NULL) {
847eec
 		*sub = tresult;
847eec
+	}
847eec
+
847eec
+	if (lock != isc_rwlocktype_none) {
847eec
+		RWUNLOCK(&zt->rwlock, lock);
847eec
+	}
847eec
 
847eec
 	return (result);
847eec
 }
847eec
-- 
847eec
2.37.2
847eec