Files
coredns/plugin/dynupdate/limits.go
houyuwushang 5aa4dc2941 plugin/dynupdate: add durable authenticated RFC 2136 updates (#8520)
* plugin/dynupdate: add authenticated RFC 2136 updates

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* plugin/dynupdate: fix README test fixtures

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* test: format README fixture map

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* plugin/dynupdate: persist updates and bound writable zones

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* plugin/dynupdate: preserve middleware and fix interoperability fixtures

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* test(dynupdate): validate Kea lifecycle and bounded zone costs

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* plugin/dynupdate: reject duplicate directives and harden client fixtures

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* plugin/dynupdate: fix update routing and startup validation

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

---------

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>
2026-09-22 00:53:26 -07:00

50 lines
898 B
Go

package dynupdate
import (
"fmt"
"github.com/miekg/dns"
)
const (
defaultMaxRecords = 10000
defaultMaxBytes = 8 << 20
defaultMaxUpdateRecords = 1024
)
type limits struct {
records, bytes, updateRecords int
}
func (l limits) defaults() limits {
if l.records == 0 {
l.records = defaultMaxRecords
}
if l.bytes == 0 {
l.bytes = defaultMaxBytes
}
if l.updateRecords == 0 {
l.updateRecords = defaultMaxUpdateRecords
}
return l
}
func (l limits) check(records []dns.RR) error {
l = l.defaults()
if len(records) > l.records {
return fmt.Errorf("zone exceeds max_records (%d)", l.records)
}
remaining := l.bytes
for _, rr := range records {
if rr == nil {
return fmt.Errorf("zone contains a nil record")
}
size := dns.Len(rr)
if size > remaining {
return fmt.Errorf("zone exceeds max_bytes (%d)", l.bytes)
}
remaining -= size
}
return nil
}