Commit 89775efda5 for bind
commit 89775efda51a4ce4160a48d9d3717e4cd4786158
Author: Evan Hunt <each@isc.org>
Date: Tue Sep 22 15:43:45 2026 -0700
Prerequisite checks weren't controlled by allow-query-on
When checking prerequisites while processing an UPDATE message,
the allow-query ACL was checked but allow-query-on was not.
diff --git a/lib/ns/update.c b/lib/ns/update.c
index 8426079e8a..a33e5a764f 100644
--- a/lib/ns/update.c
+++ b/lib/ns/update.c
@@ -313,37 +313,52 @@ inc_stats(ns_client_t *client, dns_zone_t *zone, isc_statscounter_t counter) {
* log a error otherwise we log a informational message.
*/
static isc_result_t
-checkqueryacl(ns_client_t *client, dns_acl_t *queryacl, dns_name_t *zonename,
- dns_acl_t *updateacl, dns_ssutable_t *ssutable) {
+checkqueryacl(ns_client_t *client, dns_name_t *zonename, dns_acl_t *queryacl,
+ dns_acl_t *queryonacl, dns_acl_t *updateacl,
+ dns_ssutable_t *ssutable) {
isc_result_t result;
char namebuf[DNS_NAME_FORMATSIZE];
char classbuf[DNS_RDATACLASS_FORMATSIZE];
bool update_possible =
((updateacl != NULL && !dns_acl_isnone(updateacl)) ||
ssutable != NULL);
+ int level = update_possible ? ISC_LOG_ERROR : ISC_LOG_INFO;
- result = ns_client_checkaclsilent(client, NULL, queryacl, true);
- if (result != ISC_R_SUCCESS) {
- int level = update_possible ? ISC_LOG_ERROR : ISC_LOG_INFO;
-
+ if (isc_log_wouldlog(level)) {
dns_name_format(zonename, namebuf, sizeof(namebuf));
dns_rdataclass_format(client->inner.view->rdclass, classbuf,
sizeof(classbuf));
+ }
+ result = ns_client_checkaclsilent(client, NULL, queryacl, true);
+ if (result != ISC_R_SUCCESS) {
ns_client_log(client, NS_LOGCATEGORY_UPDATE_SECURITY,
NS_LOGMODULE_UPDATE, level,
"update '%s/%s' denied due to allow-query",
namebuf, classbuf);
- } else if (!update_possible) {
- dns_name_format(zonename, namebuf, sizeof(namebuf));
- dns_rdataclass_format(client->inner.view->rdclass, classbuf,
- sizeof(classbuf));
+ dns_ede_add(&client->edectx, DNS_EDE_PROHIBITED, NULL);
+ return result;
+ }
+ result = ns_client_checkaclsilent(client, &client->inner.destaddr,
+ queryonacl, true);
+ if (result != ISC_R_SUCCESS) {
+ ns_client_log(client, NS_LOGCATEGORY_UPDATE_SECURITY,
+ NS_LOGMODULE_UPDATE, level,
+ "update '%s/%s' denied due to allow-query-on",
+ namebuf, classbuf);
+ dns_ede_add(&client->edectx, DNS_EDE_PROHIBITED, NULL);
+ return result;
+ }
+
+ if (!update_possible) {
result = DNS_R_REFUSED;
ns_client_log(client, NS_LOGCATEGORY_UPDATE_SECURITY,
NS_LOGMODULE_UPDATE, ISC_LOG_INFO,
"update '%s/%s' denied", namebuf, classbuf);
+ dns_ede_add(&client->edectx, DNS_EDE_PROHIBITED, NULL);
}
+
return result;
}
@@ -1592,8 +1607,9 @@ send_update(ns_client_t *client, dns_zone_t *zone) {
* so check that we are allowed to query this zone. Additionally,
* if we would refuse all updates for this zone, we bail out here.
*/
- CHECK(checkqueryacl(client, dns_zone_getqueryacl(zone),
- dns_zone_getorigin(zone),
+ CHECK(checkqueryacl(client, dns_zone_getorigin(zone),
+ dns_zone_getqueryacl(zone),
+ dns_zone_getqueryonacl(zone),
dns_zone_getupdateacl(zone), ssutable));
/*