X-Git-Url: http://gitweb.michael.orlitzky.com/?p=valtz.git;a=blobdiff_plain;f=valtz;h=b9c61714d3fd2a47bffa84dedf18a4ddb3132524;hp=26d516db4a8350b2b4ccb4173eb8cd6ce5196865;hb=99ffe138ccd280105fb03438236529d1295384fd;hpb=097807e6b55527da495fa668a3c47fc938393743 diff --git a/valtz b/valtz index 26d516d..b9c6171 100755 --- a/valtz +++ b/valtz @@ -43,19 +43,18 @@ use File::Temp qw/ tempfile /; use File::Copy qw/ move /; -my $VERSION = $1 if '$Revision: 0.7 $' =~ /(\d+\.\d+)/; -my $COPYRIGHT = '; (C) 2003 Magnus Bodin, http://x42.com/software/'; +my $VERSION = '0.8'; + $| = 1; my %opt; -getopts('?fFhHiIqrRstT:x', \%opt); - +getopts('?fFhHiIqrRtT:', \%opt); -my $FILESUFFIXREGEXP = '('.join('|', qw/ - ,v ~ .bak .log .old .swp .tmp - /).')$'; +# Validation errors my $verrs_total = 0; + +# "Permission" errors with respect to what record types are allowed my $perrs_total = 0; @@ -76,6 +75,7 @@ my %validation_msg = ( 1008 => 'integer out of bounds', 1009 => 'must have at least three labels to be valid as mail address', 1010 => 'must not be 2(NS), 5(CNAME), 6(SOA), 12(PTR), 15(MX) or 252(AXFR)', + 1011 => 'IP address found where hostname expected' ); # NOTE : ONLY translate the right-hand part @@ -238,6 +238,13 @@ my %token_validator = ( 'x' => [ 5, sub { my ($type, $s) = @_; my $result = 0; + + # Check to see if someone put an IP address in a hostname + # field. The motivation for this was MX records where many + # people expect an IP address to be a valid response, but I + # see no harm in enforcing it elsewhere. + return 1011 if $s =~ /^\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\.?$/; + # check all parts for (split /\./, $s) { @@ -718,11 +725,6 @@ sub do_filterfile ($$) } for my $zonefile (@zonefiles) { - unless ($opt{s}) - { - next if $zonefile =~ /$FILESUFFIXREGEXP/i; - } - my $info = 0; my $filehandle = \*STDIN; my $fopen = 1; @@ -884,151 +886,48 @@ sub do_filterfile ($$) my $files = funiq(@ARGV); +sub usage { + print <<"--EOT"; +valtz $VERSION - validate tinydns-data files -if ($opt{h} || $opt{H} || $opt{'?'}) -{ - print <<"--EOT"; -valtz $VERSION, $COPYRIGHT -validates tinydns-data zone files Usage: - $0 [-hfFqrRiItTx] - - -h shows this help. - - - -f filter (don't just validate) file and output accepted lines to STDOUT. - - - -F treat files as filter configuration files for more advanced filtering. - These filterfiles one or several of the following filter directives: - - zonefile - zonefile file: - Defines the file(s) to be filtered. Can be a globbed value, like - /var/zones/external/* - - extralog - Defines an extra logfile that the STDERR output will be copied for - this specific filterfile. Useful if you have a lot of filterfiles - and want to separate the logs. - - deny - deny file: - Defines a zonepattern to explicitly DENY after implicitly allowing all. - (cannot be combined with allow) - - allow - allow file: - Defines a zonepattern to explicitly ALLOW after implicitly denying all. - - allowtype - Explicitly sets the allowed recordtypes. Note that even comments - has to be allowed (but these will not result in errors unless -t) - to be copied to the output. - - Multiple zonefile, allow- and deny-lines are allowed, but also the - alternative file:-line that points to a textfile containing one - value per line. - - - -r allows fqdn to be empty thus denoting the root. - This is also allowed per default when doing implict allow - see deny, - or when specifying 'allow .', i.e. explictly allowing root as such. - (cannot be combined with deny) - - - -R relaxes the validation and allows empty mname and p-fields.xi - This is probably not very useful. - - - -i allows the ip-fields to be empty as well. These will then not generate any - records. + $0 [-r] [-R] [-i] tinydns-file1 [tinydns-file2...] + $0 [-HiIqrRt] [-T types] -f tinydns-file1 [tinydns-file2 ...] - -I Include rejected lines as comments in output (valid when filtering). + $0 valtz [-fHiIqrRt] [-T types] -F filter-file1 [filter-file2 ...] +Flags: + -h print usage information + -f filter invalid lines (filter mode) + -F filter using configuration files (advanced filter mode) + -r allow "fqdn" fields to be empty + -R allow "mname" and "p" fields to be empty + -i allow "ip" fields to be empty + -I include rejected lines as comments (filtering only) + -q don't print valid lines to standard out (filtering only) + -t don't ignore comment lines (filtering only) + -T allow additional record types (advanced filtering only) - -q Do not echo valid lines to STDOUT. - - -s DO NOT ignore files ending with ,v ~ .bak .log .old .swp .tmp - which is done per default. - - - -t Give error even on #comment-lines when they are not allowed. - (These errors are silently ignored per default) - - - -T - A commandline way to explicitly set the allowed recordtypes. - This is _concatenated_ to the allowtype-allowed recordtypes. - - -x Exit with non-null exit code on errors; i.e. make errors detectable by - e.g. shell scripts; 1 = validation error, 2 = permission error, - 3 = combination of 1 and 2. - - - -All errors in the zonefiles are sent to STDERR. - - Example; simple use: - valtz zone-bodin-org - - Example; simple filter-use; - valtz -f /etc/zones/zone-* \ - >/etc/tinydns/data.filtered \ - 2>/var/log/tinydns/valtz.log - - Example; filterfile use; - valtz -F /etc/zones/filter/zones-otto \ - >/etc/tinydns/data.otto \ - 2>/var/log/tinydns/valtz.log - - - Example filterfile for using as import from primary (as above): - zonefile /var/zones/external/otto/zone-* - deny bodin.org - deny x42.com - extralog /var/log/tinydns/external-otto.log - - Example #2, strict filter for a certain user editing just A-records - - zonefile /home/felix/zones/zone-fl3x-net - allow fl3x.net - allowtype + - extralog /var/log/tinydns/fl3x-net.log - - Example #3, export filter to secondary - - zonefile /var/zones/primary/zone-* - # just allow OUR zones to be exported, not to annoy secondary partner - allow file:/var/zones/primary-zones.txt - # don't allow any other types than this; e.g. comments won't be exported - allowtype Z + @ . C - extralog /var/log/tinydns/primary-export.log +Errors are generally printed to standard error, and the exit code +shall reflect the presense of both usage and validation errors. See +the man page for details. --EOT - exit 0; } -elsif (@{$files} == 0) -{ - print <<"--EOT"; -valtz $VERSION, $COPYRIGHT -validates tinydns-data zone files -Usage: - Simple validation: - $0 [-qrRix] - Simple filtering: - $0 -f[qrRiItTx] - Extensive filtering: - $0 -F[qrRiItTx] - More help and information about options: - $0 -h +if ($opt{h} || $opt{H} || $opt{'?'}) { + usage(); ---EOT + # If they asked for help, ignore whatever else they may have done + # wrong. exit 0; } +if (@{$files} == 0) { + usage(); + exit 4; +} if ($opt{F}) { @@ -1047,11 +946,6 @@ else for my $zonefile (sort @{$files}) { - unless ($opt{s}) - { - next if $zonefile =~ /$FILESUFFIXREGEXP/i; - } - my $filehandle = \*STDIN; my $fopen = 1; if ($zonefile ne '-') @@ -1104,7 +998,7 @@ else } } -if ($opt{x} && ($verrs_total + $perrs_total)) +if ($verrs_total + $perrs_total) { my $exitcode = $verrs_total > 0 ? 1 : 0; $exitcode += $perrs_total > 0 ? 2 : 0;