rawlinp commented on a change in pull request #4409: Optimize TR DNSSEC zone
re-signing
URL: https://github.com/apache/trafficcontrol/pull/4409#discussion_r382296940
##########
File path:
traffic_router/core/src/main/java/com/comcast/cdn/traffic_control/traffic_router/core/dns/ZoneManager.java
##########
@@ -460,18 +499,37 @@ private static void generateZones(final TrafficRouter
tr, final LoadingCache<Zon
LOGGER.fatal("Unable to create zone: " +
ex.getMessage(), ex);
}
- primeZoneCache(domain, name, list, tr, zc, dzc,
generationTasks, primingTasks, ds);
+ primeZoneCache(domain, name, list, tr, zc, dzc,
generationTasks, primingTasks, ds, newDomainsToZoneKeys);
return records;
}
- @SuppressWarnings("PMD.CyclomaticComplexity")
+ @SuppressWarnings({"PMD.CyclomaticComplexity",
"PMD.ExcessiveParameterList"})
private static void primeZoneCache(final String domain, final Name
name, final List<Record> list, final TrafficRouter tr,
final LoadingCache<ZoneKey, Zone> zc, final
LoadingCache<ZoneKey, Zone> dzc, final List<Runnable> generationTasks,
- final BlockingQueue<Runnable> primingTasks, final
DeliveryService ds) {
+ final BlockingQueue<Runnable> primingTasks, final
DeliveryService ds, final ConcurrentMap<String, ZoneKey> newDomainsToZoneKeys) {
generationTasks.add(() -> {
try {
- final Zone zone =
zc.get(signatureManager.generateZoneKey(name, list)); // cause the zone to be
loaded into the new cache
+ final ZoneKey newZoneKey =
signatureManager.generateZoneKey(name, list);
+ if (tr.isDnssecZoneDiffingEnabled() &&
domainsToZoneKeys.containsKey(domain)) {
Review comment:
Yeah, the thing is `zc.get(newZoneKey)` is what actually creates and signs
the zone if the value isn't there already. So I'm pretty sure I have to
`newDomainsToZoneKeys.put(domain, newZoneKey);` _after_ doing `zc.get(...)` so
that it's definitely already signed if I want to reuse it. I might be wrong
about that, since the reference shouldn't change after adding it to
`newDomainsToZoneKeys`, but I feel better about not saving it into the map
until it's signed for sure.
----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
For queries about this service, please contact Infrastructure at:
[email protected]
With regards,
Apache Git Services