internal named crash, dnssec-validation bug?

Sue True bloomingtonian at gmail.com
Mon Nov 22 20:43:38 UTC 2010


Hello,

We are running bind-9.7.2-P2 with dnssec-validation enabled for our 
internal nameservers, and our internal nameservers crashed at the time of 
reload around 2-4pm EST, one the nameserver with dnssec debug log enabled 
shows tons of 'deadlock error' for some of the sub-domains under .fr, like 
this:

20-Nov-2010 15:17:51.642 dnssec: debug 3: validating @0x13419450: 
multimania.fr DS: continuing validation would lead to deadlock: aborting 
validation

20-Nov-2010 15:17:51.642 dnssec: debug 3: validating @0x13419450: 
multimania.fr DS: deadlock found (create_fetch)

And here is the core dump:
...
Core was generated by `/usr/local/sbin/named -u named -t 
/usr/local/jail/dns/ -c /named/named.conf'.
Program terminated with signal 11, Segmentation fault.
#0  0x00002b948048691c in validated (task=<value optimized out>, 
event=0x2aaab2b8edb8) at resolver.c:4013
4013            isc_mem_put(fctx->res->buckets[fctx->bucketnum].mctx,
(gdb) backtrace
#0  0x00002b948048691c in validated (task=<value optimized out>, 
event=0x2aaab2b8edb8) at resolver.c:4013
#1  0x00002b9480d89eac in dispatch (uap=0x2b94811c6010) at task.c:1013
#2  run (uap=0x2b94811c6010) at task.c:1158
#3  0x0000003b31e06617 in start_thread () from /lib64/libpthread.so.0
#4  0x0000003b316d3c2d in clone () from /lib64/libc.so.6


It happened two month ago when .uk domain validation failed bacause of ZSK 
roll-over problem:

Sep 11 12:00:31 nameserver kernel: named[15795] general protection 
rip:2aaab72a0fac rsp:41b97030 error:0

11-Sep-2010 12:00:02.779 dnssec: debug 3:  validating @0x2aaabf53c790: 
u1fmklfv3rdcnamdc64sekgcdp05bbiu.uk NSEC3: continuing
validation would lea d to deadlock: aborting validation

11-Sep-2010 12:00:02.779 dnssec: debug 3:  validating @0x2aaabf53c790: 
u1fmklfv3rdcnamdc64sekgcdp05bbiu.uk NSEC3: deadlock found
(create_fetch)




Thanks,
Sue








More information about the bind-users mailing list