Re: [Freeipa-devel] [PATCH 0152] Replace TTL values 2^31-1 with 0.

2013-05-03 Thread Tomas Hozza
reasoning. There is also an error logged when the TTL has MSB set, so one can notice there is a bad TTL value set in LDAP. Regards, Tomas Hozza ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel

Re: [Freeipa-devel] [PATCH 0141] Generalize attribute_name-rdata_type conversions.

2013-05-06 Thread Tomas Hozza
memory freeing in free_ldapmod() function. Now one has to be be careful when it is statically or dynamically allocated. Before it was static in every case. Regards, Tomas Hozza ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com

Re: [Freeipa-devel] [PATCH 0142] Improve LDAP error logging

2013-05-07 Thread Tomas Hozza
char *format, ...) ISC_FORMAT_PRINTF(2, 3); Regards, Tomas Hozza ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel

Re: [Freeipa-devel] [PATCH 0143] Treat syntax errors in LDAP filters as fatal

2013-05-07 Thread Tomas Hozza
On 04/09/2013 03:39 PM, Petr Spacek wrote: Hello, Treat syntax errors in LDAP filters as fatal. Filters are hardcoded at the moment, this is preventive action. ACK. The patch looks good. (I didn't do functional test) Regards, Tomas Hozza

Re: [Freeipa-devel] [PATCH 0146] Disallow all dynamic updates if update policy configuration failed

2013-05-07 Thread Tomas Hozza
On 04/16/2013 10:40 AM, Petr Spacek wrote: Hello, Disallow all dynamic updates if update policy configuration failed. Without this patch the old update policy stays in effect when re-configuration failed. ACK. The patch looks good. (I didn't do functional test) Regards, Tomas Hozza

Re: [Freeipa-devel] [PATCH 0147] Improve error logging for zones with idnsAllowDynUpdate == FALSE.

2013-05-09 Thread Tomas Hozza
reasonable. (I didn't do functional test) Regards, Tomas Hozza ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel

Re: [Freeipa-devel] [PATCH 0148] Explicitly return SERVFAIL if PTR synchronization is misconfigured.

2013-05-09 Thread Tomas Hozza
be good to explicitly return SERVFAIL also if dynamic updates in PTR zone are disabled and modify the commit message to better express what this patch does. Regards, Tomas Hozza ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com

Re: [Freeipa-devel] [PATCH 0149] Clean up PTR record synchronization code and make it more robust

2013-05-09 Thread Tomas Hozza
, Tomas Hozza ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel

Re: [Freeipa-devel] [PATCH 0150] Do not delete whole node during PTR record synchronization.

2013-05-09 Thread Tomas Hozza
On 04/18/2013 04:58 PM, Petr Spacek wrote: Hello, Do not delete whole node during PTR record synchronization. https://fedorahosted.org/bind-dyndb-ldap/ticket/115 ACK. The patch looks good. Regards, Tomas Hozza ___ Freeipa-devel mailing

Re: [Freeipa-devel] [PATCH 0151] Disallow all zone transfers/queries if transfer/query policy configuration failed

2013-05-09 Thread Tomas Hozza
ACK. Patch looks OK! Regards, Tomas Hozza ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel

Re: [Freeipa-devel] [PATCH 0155] Fix IPv6 handling in PTR record synchronization

2013-05-28 Thread Tomas Hozza
ACK The patch looks good and works as expected. Regards, Tomas Hozza - Original Message - Hello, Fix IPv6 handling in PTR record synchronization. https://fedorahosted.org/bind-dyndb-ldap/ticket/118 -- Petr^2 Spacek ___ Freeipa

Re: [Freeipa-devel] [PATCHES 0156-0158] Automatically disable empty zones when necessary

2013-05-29 Thread Tomas Hozza
ACK. Patches look good and work as expected! Regards, Tomas Hozza - Original Message - Hello, this patch set enables bind-dyndb-ldap to automatically unload empty zone (see RFC 6303) if an explicit configuration for this zone is present in LDAP. Please test it with idnsZone

Re: [Freeipa-devel] [PATCH 0160] Fix crash triggered by missing sasl_user parameter

2013-05-31 Thread Tomas Hozza
ACK Works as expected. Regards, Tomas Hozza - Original Message - Hello, Fix crash triggered by missing sasl_user parameter. -- Petr^2 Spacek ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman

Re: [Freeipa-devel] [PATCH 0161] Validate authentication settings strictly

2013-05-31 Thread Tomas Hozza
ACK. Works OK. Regards, Tomas Hozza - Original Message - Hello, Validate authentication settings strictly. - auth_method 'SASL' do not accept bind_dn and password options - auth_method 'simple' do not accept sasl_* and krb5_* options - auth_method 'none' do not accept any

Re: [Freeipa-devel] [PATCH 0159] Deprecate configuration without persistent search

2013-05-31 Thread Tomas Hozza
ACK. Looks good. Regards, Tomas Hozza - Original Message - On 28.5.2013 15:55, Petr Spacek wrote: Hello, Deprecate configuration without persistent search. https://fedorahosted.org/bind-dyndb-ldap/ticket/120 This version of the patch adds notice to the README. -- Petr

Re: [Freeipa-devel] [PATCH 0162] Mark function arguments with __attribute__((nonnull)) when appropriate

2013-06-04 Thread Tomas Hozza
ACK. The change looks reasonable and I'm not able to come up with a better macro name... :) Regards, Tomas Hozza - Original Message - Hello, Mark function arguments with __attribute__((nonnull)) when appropriate. This patch prevents bugs like https://git.fedorahosted.org/cgit

Re: [Freeipa-devel] [PATCH 0166] Fix minor coding style issue in update_config()

2013-06-24 Thread Tomas Hozza
ACK The patch looks good. Regards, Tomas Hozza - Original Message - Hello, Fix minor coding style issue in update_config(). -- Petr^2 Spacek ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman

Re: [Freeipa-devel] [PATCH 0165] Fix crash caused by race-condition between shutdown and update processing

2013-06-25 Thread Tomas Hozza
ACK. Works as expected. Regards, Tomas Hozza - Original Message - Hello, Fix crash caused by race-condition between shutdown and update processing. Variable 'name' was uninitialized when manager_get_ldap_instance() returned ISC_R_NOTFOUND. The successive call

Re: [Freeipa-devel] [PATCH 0169-0170] Modernize autotools configuration

2013-07-10 Thread Tomas Hozza
/automake/2012-05/msg00014.html Thank you for catching this. Fixed patch is attached. ACK Regards, Tomas Hozza ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel

Re: [Freeipa-devel] [PATCH 0171-0172] Fix potential problems found by Clang static analyzer

2013-07-10 Thread Tomas Hozza
On 07/08/2013 10:51 AM, Petr Spacek wrote: Hello, several warnings from Clang static analyzer popped up after upgrade to Fedora 19. Attached patches should fix all problems found by clang-analyzer-3.3-0.6.rc3.fc19.x86_64. ACK Regards, Tomas Hozza

Re: [Freeipa-devel] [PATCH 0173] Improve logging for cases where SOA serial autoincrementation failed

2013-07-12 Thread Tomas Hozza
On 07/11/2013 12:24 PM, Petr Spacek wrote: Hello, Improve logging for cases where SOA serial autoincrementation failed. ACK Regards, Tomas Hozza ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo

Re: [Freeipa-devel] [PATCH 0174] Fix crash during zone_refresh triggered by connection failure

2013-07-18 Thread Tomas Hozza
, Tomas Hozza ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel

Re: [Freeipa-devel] [PATCH 0175-0177] Prepare transition from persistent search to RFC 4533

2013-07-18 Thread Tomas Hozza
On 07/16/2013 10:04 AM, Petr Spacek wrote: Hello, this patch set changes default configuration to 'psearch yes' and changes README and informational messages accordingly. ACK. Regards, Tomas Hozza ___ Freeipa-devel mailing list Freeipa-devel

Re: [Freeipa-devel] [PATCH 0178-0179] Preparation for 3.5 release

2013-07-18 Thread Tomas Hozza
On 07/16/2013 10:13 AM, Petr Spacek wrote: Hello, I plan to release 3.5 as soon as all previous patches are ACKed. ACK. Regards, Tomas Hozza ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa

Re: [Freeipa-devel] [PATCH 0180] Remove support for zone_refresh mode and options cache_ttl and psearch

2013-08-15 Thread Tomas Hozza
On 07/22/2013 01:23 PM, Petr Spacek wrote: Hello, Remove support for zone_refresh mode and options cache_ttl and psearch. All three options are ignored and persistent search is always enabled. ACK. Looks good and plugin works well with the change. Anyway I think it would be good to

Re: [Freeipa-devel] [PATCH 0192] Prevent deadlock in PTR record synchronization (versions = 2.x)

2013-10-01 Thread Tomas Hozza
On 09/26/2013 03:11 PM, Petr Spacek wrote: Hello, attached patch prevents/hides deadlock in plugin versions versions = 2.x. I plan to push it to v2 branch. Branches v3 and newer shouldn't be affected. https://fedorahosted.org/bind-dyndb-ldap/ticket/113 ACK. I tested the patch with:

Re: [Freeipa-devel] [PATCH 0182] Fix false error messages when nonexistent object/attribute is deleted

2013-10-07 Thread Tomas Hozza
On 08/01/2013 03:48 PM, Petr Spacek wrote: Hello, Fix false error messages when nonexistent object/attribute is deleted. This patch should go to branches v3 and master. ACK. Tested Patch bundle 181 - 185. Common tasks like adding/deleting/updating records work fine. Also PTR sync,

Re: [Freeipa-devel] [PATCH 0181] Replace LDAP persistent search with syncrepl (RFC 4533)

2013-10-07 Thread Tomas Hozza
On 07/22/2013 03:16 PM, Petr Spacek wrote: On 22.7.2013 13:23, Petr Spacek wrote: Hello, Replace LDAP persistent search with syncrepl (RFC 4533). All direct operations with LDAP Persistent Search control are replaced by ldap_sync_* calls. Syncrepl code works in exactly same way as old

Re: [Freeipa-devel] [PATCH 0183] Move data structures for parser from ldap_qresult_t to ldap_entry_t

2013-10-07 Thread Tomas Hozza
On 08/01/2013 03:49 PM, Petr Spacek wrote: Hello, Move data structures for parser from ldap_qresult_t to ldap_entry_t. The target branch is master. ACK. Tested Patch bundle 181 - 185. Common tasks like adding/deleting/updating records work fine. Also PTR sync, zone serial number

Re: [Freeipa-devel] [PATCH 0184] Use DNS_RDATA_MAXLENGTH from rdata.h instead of own definition

2013-10-07 Thread Tomas Hozza
On 08/01/2013 03:51 PM, Petr Spacek wrote: Hello, Use DNS_RDATA_MAXLENGTH from rdata.h instead of own definition. This minor fix could go to v3 and master. ACK. Tested Patch bundle 181 - 185. Common tasks like adding/deleting/updating records work fine. Also PTR sync, zone serial

Re: [Freeipa-devel] [PATCH 0185] Do not execute new LDAP search for each updated object

2013-10-07 Thread Tomas Hozza
On 08/01/2013 03:52 PM, Petr Spacek wrote: Hello, Do not execute new LDAP search for each updated object. Syncrepl delivers notification about change in particular object along with all data from the object. Resource Records are parsed out from this data instead of data obtained via

Re: [Freeipa-devel] [PATCH 0186-0191] Replace LDAP cache with RBTDB

2013-10-08 Thread Tomas Hozza
On 10/02/2013 12:57 PM, Petr Spacek wrote: On 13.9.2013 15:31, Petr Spacek wrote: On 14.8.2013 16:42, Petr Spacek wrote: On 14.8.2013 16:25, Petr Spacek wrote: On 1.8.2013 15:57, Petr Spacek wrote: Hello, attached monster patches replace our internal cache/database with RBTDB

Re: [Freeipa-devel] [PATCH 0186-0191] Replace LDAP cache with RBTDB

2013-10-23 Thread Tomas Hozza
On 10/10/2013 06:58 PM, Petr Spacek wrote: On 8.10.2013 12:00, Tomas Hozza wrote: On 10/02/2013 12:57 PM, Petr Spacek wrote: On 13.9.2013 15:31, Petr Spacek wrote: On 14.8.2013 16:42, Petr Spacek wrote: On 14.8.2013 16:25, Petr Spacek wrote: On 1.8.2013 15:57, Petr Spacek wrote: Hello

Re: [Freeipa-devel] [PATCH 0192-0196] Write all changes to journal

2013-10-23 Thread Tomas Hozza
On 10/10/2013 07:05 PM, Petr Spacek wrote: Hello, this patch set adds journaling to bind-dyndb-ldap. Journaling requires proper SOA serial maintenance, so from now SOA serial auto-incrementation is mandatory. Journal file is deleted on each start, so IXFR is limited to time frame from

Re: [Freeipa-devel] [PATCH 0197-0200] Preparation for bind-dyndb-ldap release 4.0

2013-10-23 Thread Tomas Hozza
On 10/11/2013 03:35 PM, Petr Spacek wrote: Hello, update documentation and schema files for upcoming version 4.0. This fixes typo in schema file: https://fedorahosted.org/bind-dyndb-ldap/ticket/121 Have a nice weekend! ACK. Looks good. Regards, Tomas

Re: [Freeipa-devel] [PATCH 0201] Report error if RFC 4533 initialization failed

2013-10-24 Thread Tomas Hozza
server? ACK. Patch works and looks good. Regards, Tomas Hozza ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel

Re: [Freeipa-devel] [PATCH 0202-0203] Improve performance of initial LDAP synchronizationDetect end of initial LDAP synchronization phase

2013-11-05 Thread Tomas Hozza
- Original Message - Hello, Improve performance of initial LDAP synchronization. Changes are not journaled and SOA serial is not incremented during initial LDAP synchronization. This eliminates unnecessary synchronous writes to journal and also unnecessary SOA serial writes to

Re: [Freeipa-devel] [PATCH][bind-dyndb-ldap] Fix warning duplicate 'const' declaration specifier

2014-01-17 Thread Tomas Hozza
/2008/07/18/reading-c-type-declarations/ Simple patch is attached. LS ACK. Looks good. Regards, Tomas Hozza -BEGIN PGP SIGNATURE- Version: GnuPG v1 Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/ iQEcBAEBAgAGBQJS2UbdAAoJEMWIetUdnzwtqKIIAKEnhrYiT85yvGYkMVUjGZ5Y

Re: [Freeipa-devel] [PATCH 0204] Remove obsolete zr_get_rbt() function from zone register

2014-01-17 Thread Tomas Hozza
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 11/11/2013 12:53 PM, Petr Spacek wrote: Hello, Remove obsolete zr_get_rbt() function from zone register. ACK. Patch looks good. Regards, Tomas Hozza -BEGIN PGP SIGNATURE- Version: GnuPG v1 Comment: Using GnuPG with Thunderbird

Re: [Freeipa-devel] [PATCH 0221] Make getcwd() calls safer

2014-02-18 Thread Tomas Hozza
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 02/18/2014 10:34 AM, Petr Spacek wrote: ewer GCC complains that I didn't check return value from getcwd() ... Hi. I reviewed all patches from PATCH 0181 to the latest one PATCH 0221 and tested the bind-dyndb-ldap on Fedora 20 (adding/removing

Re: [Freeipa-devel] [PATCH 0223] Update Fedora SPEC file for v4.0 (RPM expert needed)

2014-02-21 Thread Tomas Hozza
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Peter. See comments below... On 02/21/2014 10:46 AM, Petr Spacek wrote: Hello list, I want to release bind-dyndb-ldap 4.0 to Fedora 20+ but I have found that we need to enable SELinux boolean named_write_master_zones otherwise the plugin

Re: [Freeipa-devel] [PATCH 0223] Update Fedora SPEC file for v4.0 (RPM expert needed)

2014-02-21 Thread Tomas Hozza
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 02/21/2014 12:10 PM, Petr Spacek wrote: On 21.2.2014 11:05, Tomas Hozza wrote: On 02/21/2014 10:46 AM, Petr Spacek wrote: I want to release bind-dyndb-ldap 4.0 to Fedora 20+ but I have found that we need to enable SELinux boolean

Re: [Freeipa-devel] [PATCH 0223] Update Fedora SPEC file for v4.0 (RPM expert needed)

2014-02-21 Thread Tomas Hozza
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 02/21/2014 12:54 PM, Tomas Hozza wrote: On 02/21/2014 12:10 PM, Petr Spacek wrote: On 21.2.2014 11:05, Tomas Hozza wrote: On 02/21/2014 10:46 AM, Petr Spacek wrote: I want to release bind-dyndb-ldap 4.0 to Fedora 20+ but I have found that we

Re: [Freeipa-devel] [PATCH 0223] Update Fedora SPEC file for v4.0 (RPM expert needed)

2014-02-21 Thread Tomas Hozza
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 02/21/2014 01:37 PM, Petr Spacek wrote: On 21.2.2014 13:02, Tomas Hozza wrote: On 02/21/2014 12:54 PM, Tomas Hozza wrote: On 02/21/2014 12:10 PM, Petr Spacek wrote: On 21.2.2014 11:05, Tomas Hozza wrote: On 02/21/2014 10:46 AM, Petr Spacek

Re: [Freeipa-devel] [PATCH 0231] Fix record parsing to prevent child zone corruption

2014-04-09 Thread Tomas Hozza
by update_records() instead of delegation records in the parent zone. https://fedorahosted.org/bind-dyndb-ldap/ticket/134 ACK Solves the problem described in the ticket. Regards, Tomas Hozza -BEGIN PGP SIGNATURE- Version: GnuPG v1 Comment: Using GnuPG with Thunderbird - http://www.enigmail.net

Re: [Freeipa-devel] [PATCH 0234] Prevent NULL dereference before sync_concurr_limit_signal() calls

2014-04-09 Thread Tomas Hozza
. Sometimes it shutdowns cleanly and sometimes you can see a crash: Thank you for your time! ACK. I'm not able to reproduce the issue, but the patch looks reasonable and should not break anything. Regards, Tomas Hozza -BEGIN PGP SIGNATURE- Version: GnuPG v1 Comment: Using GnuPG

Re: [Freeipa-devel] [PATCH 0236] Fix crash in create_zone()

2014-05-05 Thread Tomas Hozza
encountered it during work on new DNSSEC code ... -- Petr^2 Spacek Looks good. ACK. Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc. http://cz.redhat.com ___ Freeipa

Re: [Freeipa-devel] [PATCH 0237] Handle paths without trailing / in fs_dirs_create()

2014-05-05 Thread Tomas Hozza
- Original Message - Hello, Handle paths without trailing / in fs_dirs_create(). This patch should go to all branches with fs_dirs_create() function. -- Petr^2 Spacek Looks good. ACK Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D

Re: [Freeipa-devel] [PATCH 0238] Update .gitignore to skip Eclipse and Autotools file

2014-05-05 Thread Tomas Hozza
- Original Message - Hello, Update .gitignore to skip Eclipse and Autotools files. -- Petr^2 Spacek ACK -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc. http://cz.redhat.com

Re: [Freeipa-devel] [PATCH 0239-0243] Refactor ldap_parse_master_zoneentry()

2014-05-06 Thread Tomas Hozza
242 will follow. The patch 243 introduced new compilation warning that Peter is aware of. Unfortunately we are unable to find the root cause of it, so leaving it as is for now... Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc

Re: [Freeipa-devel] [PATCH 0239-0243] Refactor ldap_parse_master_zoneentry()

2014-05-06 Thread Tomas Hozza
-Refactor-master-zone-configuration.patch fixes zone loading for zones without idnsAllowTransfer attribute in LDAP. Previously, the plugin refused to load such zones with error ISC_R_NOTFOUND - missing attribute was treated as fatal error. -- Petr^2 Spacek ACK. Regards, -- Tomas Hozza

Re: [Freeipa-devel] [PATCH 0251-0256] Add support for NSEC3

2014-05-21 Thread Tomas Hozza
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 05/21/2014 11:33 AM, Petr Spacek wrote: On 7.5.2014 15:27, Petr Spacek wrote: On 29.4.2014 23:34, Petr Spacek wrote: This patch set adds support for NSEC3. See commit messages for details. Patch 253 was obsoleted by patches 244v2 and 246v2.

Re: [Freeipa-devel] [PATCH][bind-dyndb-ldap] AUTOCONF: Improve detection of bind9 header files

2014-05-21 Thread Tomas Hozza
needn't be exported. LS ACK. Works like a charm... Thanks! Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc. http://cz.redhat.com ___ Freeipa-devel mailing list

Re: [Freeipa-devel] [PATCH 0257] Fix race condition during zone loading

2014-05-28 Thread Tomas Hozza
On 05/27/2014 03:59 PM, Petr Spacek wrote: On 27.5.2014 15:54, Petr Spacek wrote: Fix race condition during zone loading. DNS zone has to be added to DNS view before dns_zone_load() is called. It is necessary to prevent dns_zone_load() from racing with dns_zone_setview(). This race

Re: [Freeipa-devel] [PATCH 0257] Fix race condition during zone loading

2014-06-17 Thread Tomas Hozza
- Original Message - On 28.5.2014 13:26, Tomas Hozza wrote: On 05/27/2014 03:59 PM, Petr Spacek wrote: On 27.5.2014 15:54, Petr Spacek wrote: Fix race condition during zone loading. DNS zone has to be added to DNS view before dns_zone_load() is called. It is necessary

Re: [Freeipa-devel] [PATCH 0266] (aka 257.5) Fix zone reloading for in-line signed zones

2014-06-17 Thread Tomas Hozza
://fedorahosted.org/bind-dyndb-ldap/ticket/56 -- Petr^2 Spacek ACK. Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc. http://cz.redhat.com ___ Freeipa-devel mailing list

Re: [Freeipa-devel] [PATCH 0258] Fix run-time zone addition for secure zones

2014-06-17 Thread Tomas Hozza
, Fix run-time zone addition for secure zones. Here comes fix for the fix ... We really need a test-suite for bind-dyndb-ldap. https://fedorahosted.org/bind-dyndb-ldap/ticket/56 -- Petr^2 Spacek ACK. Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience

Re: [Freeipa-devel] [PATCH 0260] Add wrappers for isc_task_*exclusive()

2014-06-17 Thread Tomas Hozza
- Original Message - Hello, Add wrappers for isc_task_*exclusive(). This patch replaces scattered isc_task_* calls and associated locking to one place. It helps with debugging sometimes. -- Petr^2 Spacek Looks good. ACK. Regards, -- Tomas Hozza Software Engineer - EMEA

Re: [Freeipa-devel] [PATCH 0261-0262] Support run-time changes in idnsSecInlineSigning attribute

2014-06-17 Thread Tomas Hozza
- Original Message - Hello, This patch set allows you to change DNSSEC zone configuration at run-time. -- Petr^2 Spacek Looks good. ACK. Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc. http

Re: [Freeipa-devel] [PATCH 0259] Fix run-time zone addition for invalid secure zones

2014-06-17 Thread Tomas Hozza
to LDAP. This write generates LDAP modify event which again triggers ldap_parse_master_zoneentry() and so on. https://fedorahosted.org/bind-dyndb-ldap/ticket/56 -- Petr^2 Spacek Looks good. ACK. Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat

Re: [Freeipa-devel] [PATCH 0263-0265] Support root master zone in LDAP Follow BIND semantics for forwarders

2014-06-17 Thread Tomas Hozza
Spacek Looks good. ACK. Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc. http://cz.redhat.com ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https

Re: [Freeipa-devel] [PATCH] [dyndb] Fix error handling in configure_view() to prevent deadlocks

2014-09-17 Thread Tomas Hozza
); dns_dyndb_set_task(args, NULL); dns_dyndb_set_timermgr(args, NULL); isc_mem_put(mctx, args, sizeof(*args)); + + *argsp = NULL; } Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc. http://cz.redhat.com

Re: [Freeipa-devel] [PATCH] [dyndb] Fix error handling in configure_view() to prevent deadlocks

2014-09-18 Thread Tomas Hozza
On Thu 18 Sep 2014 08:49:05 AM CEST, Petr Spacek wrote: On 17.9.2014 20:04, Tomas Hozza wrote: On Tue 16 Sep 2014 07:32:39 PM CEST, Petr Spacek wrote: Hello, attached patches fix https://bugzilla.redhat.com/show_bug.cgi?id=1142150 https://bugzilla.redhat.com/show_bug.cgi?id=1142152

Re: [Freeipa-devel] [PATCH 0297] Add log message about initial LDAP synchronization

2014-09-22 Thread Tomas Hozza
On 09/17/2014 01:33 PM, Petr Spacek wrote: Hello, Add log message about initial LDAP synchronization. ACK. Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc. http://cz.redhat.com

Re: [Freeipa-devel] [PATCH 0298-0302] Implement handling of inactive master zones

2014-09-22 Thread Tomas Hozza
and Martin, please communicate who is going to review what :-) Thank you for your time! The code seems to be fine. ACK. Regards, - -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc. http://cz.redhat.com -BEGIN PGP

Re: [Freeipa-devel] [WIP] DNSSEC check for DNS forwarders

2014-10-09 Thread Tomas Hozza
to determine if network-provided DNS forwarders are DNSSEC enabled before configuring unbound server. Therefore I agree with the idea, however it is up to IPA developers how they end up implementing the probing. Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP

Re: [Freeipa-devel] [PATCH][bind-dyndb-ldap] AUTOCONF: Improve detection of bind9 header files

2014-11-26 Thread Tomas Hozza
into account during libdns version check so it actually did not work at all :-) Please review it (and send me a modified patch if you see a problem). Thank you for your time! ACK. No need to export CPPFLAGS any more! Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP

Re: [Freeipa-devel] [PATCH 0228] Drop unnecessary #define _BSD_SOURCE

2014-11-26 Thread Tomas Hozza
warning there. ACK. Works for me, too. Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc. http://cz.redhat.com ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman

Re: [Freeipa-devel] [PATCH 0306] Improve info messages about number of defined/loaded zones

2014-11-26 Thread Tomas Hozza
On 11/07/2014 01:33 PM, Petr Spacek wrote: Hello, Improve info messages about number of defined/loaded zones. ACK. The new message looks good. Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc. http://cz.redhat.com

Re: [Freeipa-devel] [PATCH 0309] Fix crash caused by interaction between forward and master zones

2014-11-26 Thread Tomas Hozza
. The patch looks good. Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc. http://cz.redhat.com ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa

Re: [Freeipa-devel] [PATCH 0308] Improve detection of BIND 9 isc__errno2result header file

2014-11-26 Thread Tomas Hozza
work even without explicit CFLAGS and it should also detect that bind-devel or bind-lite-devel packages are missing. Works for me ACK. Works for me, too. Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc. http://cz.redhat.com

Re: [Freeipa-devel] [PATCH 0310] Fix misleading error message about forward zones on reconnect

2014-11-26 Thread Tomas Hozza
it prints message: forward zone 'fw.example.com': loaded Log looks better now, ACK if Tomas has no objections. ACK. Looks good. Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc. http://cz.redhat.com

Re: [Freeipa-devel] [PATCH 0307] Send DNS NOTIFY message after any modification to the zone

2014-11-27 Thread Tomas Hozza
. Works for me... Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc. http://cz.redhat.com ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel

Re: [Freeipa-devel] [PATCH 0316] Fix crash triggered by zone objects with unexpected DN

2015-02-18 Thread Tomas Hozza
0x720a7f3b in ldap_syncrepl_watcher (arg=0x77fa3160) at ldap_helper.c:5247 #9 0x75dda52a in start_thread (arg=0x7fffea7cd700) at pthread_create.c:310 #10 0x7508d79d in clone () at ../sysdeps/unix/sysv/linux/x86_64/clone.S:109 -- Tomas Hozza Software Engineer - EMEA ENG

Re: [Freeipa-devel] [PATCH 0319] Fix crash caused by race condition during resolver cache flushing

2015-01-29 Thread Tomas Hozza
, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc. http://cz.redhat.com ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel

Re: [Freeipa-devel] [PATCH 0315] Support BIND 9.10

2015-01-09 Thread Tomas Hozza
dynamic updates work. I did not test other features yet. ACK. The driver compiles with BIND 9.10 and works with IPA. I tested basic usage. BTW available in COPR: http://copr-fe.cloud.fedoraproject.org/coprs/thozza/bind-9.10/ Tomas -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience

Re: [Freeipa-devel] [PATCH 0316] Fix crash triggered by zone objects with unexpected DN

2015-03-04 Thread Tomas Hozza
On 02/24/2015 03:01 PM, Petr Spacek wrote: Hello, On 18.2.2015 10:36, Tomas Hozza wrote: On 12/16/2014 04:32 PM, Petr Spacek wrote: Hello, Fix crash triggered by zone objects with unexpected DN. https://fedorahosted.org/bind-dyndb-ldap/ticket/148 NACK. The patch seems

Re: [Freeipa-devel] [PATCH 0322-0337] Fix mysterious failures in PTR record synchronization

2015-05-15 Thread Tomas Hozza
/blob/d616021d6665ebab97035efb687a88a4a139f636/src/ldap_helper.c#L4038 Other than that, patches look good. I tested them and reviewed from https://github.com/pspacek/bind-dyndb-ldap/commits/t155.syncptr ACK with the fix for unused variable. Regards, -- Tomas Hozza Software Engineer - EMEA ENG

Re: [Freeipa-devel] [PATCH 0384-0385] Replace isc_atomic_* in with reference counter

2015-06-23 Thread Tomas Hozza
/pspacek/bind-dyndb-ldap/commits/atomic_to_refcnt Thank you for review! I did formal review of patches 384 and 385. The fixed version looks good. ACK. Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc. http://cz.redhat.com -- Manage your

Re: [Freeipa-devel] [PATCH 0383] Fix metadb_iterator_destroy() to accept NULL iterators

2015-06-23 Thread Tomas Hozza
On 08.06.2015 14:08, Petr Spacek wrote: Hello, Fix metadb_iterator_destroy() to accept NULL iterators. This prevents potential crash in error handling, e.g. if memory allocation failed. Hi. I did formal review. The patch looks good. ACK. Regards, -- Tomas Hozza Software Engineer - EMEA

Re: [Freeipa-devel] [PATCH 0377-0382] Synchronize changes from LDAP after reconnect

2015-06-02 Thread Tomas Hozza
as LDAP URI to /etc/named.conf and then simulate changes by killing and restarting socat. Let me know if you need any assistance! Hi. I did a formal review of the code. Everything looks good. ACK. Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat

Re: [Freeipa-devel] [PATCH 0339-0363] Implement meta-database

2015-05-22 Thread Tomas Hozza
... It compiled, functional testing done by others. ACK Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc. http://cz.redhat.com -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com

Re: [Freeipa-devel] [PATCH 0368-0371] Support LDAP MODRDN for ordinary DNS records

2015-05-26 Thread Tomas Hozza
set depends on 'metadb' branch. It is also available from: https://github.com/pspacek/bind-dyndb-ldap/tree/modrdn Thank you for your time! I did formal review. Everything looks OK. ACK Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc

Re: [Freeipa-devel] [PATCH 0376] Add schema for unknown record types

2015-05-26 Thread Tomas Hozza
On 05/21/2015 12:42 PM, Petr Spacek wrote: Hello, Add schema for unknown record types. This patch complements my previous patch 367. The change was pushed to https://github.com/pspacek/bind-dyndb-ldap/tree/unknown_record_types , too. ACK Tomas -- Tomas Hozza Software Engineer

Re: [Freeipa-devel] [PATCH 0367] Support unknown record types (RFC 3597)

2015-05-26 Thread Tomas Hozza
NULL pointers in second iteration of while loops. I did only formal review. Didn't find any issues. ACK. Regards, -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc. http://cz.redhat.com -- Manage your subscription for the Freeipa-devel mailing list

Re: [Freeipa-devel] [PATCH 0399-0402] Do not log warning about empty zones which are already disabled or unloaded & prepare 9.0 release

2016-05-12 Thread Tomas Hozza
gged. Other than that, the changes look good to me. Regards, -- Tomas Hozza Senior Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D UTC+1 (CET) Red Hat Inc. http://cz.redhat.com -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo

Re: [Freeipa-devel] [PATCH 0393-0398] Unload automatic empty zones only if conflicting forward zone has policy 'only'Add ability to log warningsUnload automatic empty zones which are super/sub/equal d

2016-05-06 Thread Tomas Hozza
configure forward zone and you have global forwarding turned off. In case you configure a forward zone with forward "only" and it conflicts with an empty zone, you can get SERVFAIL from the server for hostname from such zone. It is reproducible only if you are quick enough. The next qu

Re: [Freeipa-devel] [PATCH 0391-0392] Add missing return value checks to pthread operations & replace strcmp(var, "") with strlen(var) to workaround Clang bug 20144

2016-05-05 Thread Tomas Hozza
how_bug.cgi?id=20144 > ACK. I was not able to reproduce the issues. However the changes look good to me. I tested the plugin on Fedora 24 with basic tasks (query, zone transfer, DNS update) without DNSSEC signing. Regards, -- Tomas Hozza Senior Software Engineer - EMEA ENG Developer Experience PGP