Commit f87bf8e471 for bind

commit f87bf8e4716dd3afa2c641fcf9b694a94bb78508
Author: OndÅ™ej Surý <ondrej@isc.org>
Date:   Thu Sep 24 16:42:57 2026 +0200

    Revert "When caching names, check for CNAME RRsets"

    This reverts the resolver part of commit 69a560fff1 and keeps its
    serve-stale test cases.

diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c
index 74f0ce535a..b9af354e54 100644
--- a/lib/dns/resolver.c
+++ b/lib/dns/resolver.c
@@ -69,7 +69,6 @@
 #include <dns/rdataclass.h>
 #include <dns/rdatalist.h>
 #include <dns/rdataset.h>
-#include <dns/rdatasetiter.h>
 #include <dns/rdatastruct.h>
 #include <dns/rdatatype.h>
 #include <dns/resolver.h>
@@ -5573,83 +5572,6 @@ delete_rrset(fetchctx_t *fctx, dns_name_t *name, dns_rdatatype_t type) {
 	dns_db_detachnode(&node);
 }

-/*
- * When caching a CNAME, evict other RRsets at the same owner name,
- * according to the RFC specifications.
- *
- * RFC 1034, 3.6.2: Aliases and canonical names
- *   If a CNAME RR is present at a node, no other data should be
- *   present.
- * RFC 2181, 10.1: CNAME resource records
- *   An alias name (label of a CNAME record) may,
- *   if DNSSEC is in use, have SIG, NXT, and KEY RRs, but may have no
- *   other data.
- * RFC 2535, 2.3.5: Special Considerations with CNAME
- * RFC 4034, 3: The RRSIG Resource Record
- *   Because every authoritative RRset in a zone must be protected by a
- *   digital signature, RRSIG RRs must be present for names containing a
- *   CNAME RR.  This is a change to the traditional DNS specification
- *   [RFC1034], which stated that if a CNAME is present for a name, it is
- *   the only type allowed at that name.
- * RFC 4034, 4: The NSEC Resource Record
- *   Because every authoritative name in a zone must be part of the NSEC
- *   chain, NSEC RRs must be present for names containing a CNAME RR.
- *   This is a change to the traditional DNS specification [RFC1034],
- *   which stated that if a CNAME is present for a name, it is the only
- *   type allowed at that name.
- *
- * So types allowed next to CNAME are: KEY, SIG, NXT, RRSIG, and NSEC.
- */
-static void
-evict_cname_other(fetchctx_t *fctx, dns_name_t *name) {
-	isc_result_t result;
-	dns_dbnode_t *node = NULL;
-	dns_rdatasetiter_t *rdsiter = NULL;
-
-	result = dns_db_findnode(fctx->cache, name, false, &node);
-	if (result != ISC_R_SUCCESS) {
-		return;
-	}
-
-	result = dns_db_allrdatasets(fctx->cache, node, NULL, 0, 0, &rdsiter);
-	if (result != ISC_R_SUCCESS) {
-		dns_db_detachnode(&node);
-		return;
-	}
-
-	DNS_RDATASETITER_FOREACH(rdsiter) {
-		dns_rdataset_t rdataset = DNS_RDATASET_INIT;
-		dns_rdatasetiter_current(rdsiter, &rdataset);
-
-		if (NEGATIVE(&rdataset)) {
-			/* Keep all negative entries */
-			dns_rdataset_disassociate(&rdataset);
-			continue;
-		}
-
-		dns_typepair_t typepair = DNS_TYPEPAIR_VALUE(rdataset.type,
-							     rdataset.covers);
-		switch (typepair) {
-		/* NSEC records are allowed */
-		case DNS_TYPEPAIR(dns_rdatatype_nsec):
-		case DNS_SIGTYPEPAIR(dns_rdatatype_nsec):
-		/* Keep the CNAME and its signature */
-		case DNS_TYPEPAIR(dns_rdatatype_cname):
-		case DNS_SIGTYPEPAIR(dns_rdatatype_cname):
-			dns_rdataset_disassociate(&rdataset);
-			continue;
-		default:
-			/* Evict everything else */
-			dns_db_deleterdataset(fctx->cache, node, NULL,
-					      rdataset.type, rdataset.covers);
-			dns_rdataset_disassociate(&rdataset);
-		}
-	}
-
-	dns_rdatasetiter_destroy(&rdsiter);
-	dns_db_detachnode(&node);
-}
-
 static isc_result_t
 cache_rrset(fetchctx_t *fctx, isc_stdtime_t now, dns_name_t *name,
 	    dns_rdataset_t *rdataset, dns_rdataset_t *sigrdataset,
@@ -5704,19 +5626,6 @@ cache_rrset(fetchctx_t *fctx, isc_stdtime_t now, dns_name_t *name,
 		result = dns_db_findnode(fctx->cache, name, true, &node);
 	}

-	/*
-	 * Evict CNAME records, according to the RFC rules (see
-	 * evict_cname_other).
-	 *
-	 * Note that a signature is tied to the type it covers and is deleted
-	 * along with the covered RRset in 'delete_rrset()'.
-	 */
-	if (!dns_rdataset_matchestype(rdataset, dns_rdatatype_cname) &&
-	    !dns_rdataset_matchestype(rdataset, dns_rdatatype_nsec))
-	{
-		delete_rrset(fctx, name, dns_rdatatype_cname);
-	}
-
 	if (result == ISC_R_SUCCESS) {
 		result = dns_db_addrdataset(fctx->cache, node, NULL, now,
 					    rdataset, options | equalok, added);
@@ -6450,14 +6359,6 @@ rctx_cachename(respctx_t *rctx, dns_message_t *message, dns_name_t *name) {
 			goto cleanup;
 		}

-		/*
-		 * If CNAME, delete other RRsets at the same name
-		 * from the cache.
-		 */
-		if (rdataset->type == dns_rdatatype_cname) {
-			evict_cname_other(fctx, name);
-		}
-
 		/* Find the signature for this rdataset */
 		sigrdataset = getrrsig(name, rdataset->type);