1let
2 common = { pkgs, ... }: {
3 networking.firewall.enable = false;
4 networking.useDHCP = false;
5 # for a host utility with IPv6 support
6 environment.systemPackages = [ pkgs.bind ];
7 };
8in import ./make-test.nix ({ pkgs, ...} : {
9 name = "nsd";
10 meta = with pkgs.stdenv.lib.maintainers; {
11 maintainers = [ aszlig ];
12 };
13
14 nodes = {
15 clientv4 = { lib, nodes, ... }: {
16 imports = [ common ];
17 networking.nameservers = lib.mkForce [
18 (lib.head nodes.server.config.networking.interfaces.eth1.ipv4.addresses).address
19 ];
20 networking.interfaces.eth1.ipv4.addresses = [
21 { address = "192.168.0.2"; prefixLength = 24; }
22 ];
23 };
24
25 clientv6 = { lib, nodes, ... }: {
26 imports = [ common ];
27 networking.nameservers = lib.mkForce [
28 (lib.head nodes.server.config.networking.interfaces.eth1.ipv6.addresses).address
29 ];
30 networking.interfaces.eth1.ipv4.addresses = [
31 { address = "dead:beef::2"; prefixLength = 24; }
32 ];
33 };
34
35 server = { lib, ... }: {
36 imports = [ common ];
37 networking.interfaces.eth1.ipv4.addresses = [
38 { address = "192.168.0.1"; prefixLength = 24; }
39 ];
40 networking.interfaces.eth1.ipv6.addresses = [
41 { address = "dead:beef::1"; prefixLength = 64; }
42 ];
43 services.nsd.enable = true;
44 services.nsd.rootServer = true;
45 services.nsd.interfaces = lib.mkForce [];
46 services.nsd.zones."example.com.".data = ''
47 @ SOA ns.example.com noc.example.com 666 7200 3600 1209600 3600
48 ipv4 A 1.2.3.4
49 ipv6 AAAA abcd::eeff
50 deleg NS ns.example.com
51 ns A 192.168.0.1
52 ns AAAA dead:beef::1
53 '';
54 services.nsd.zones."deleg.example.com.".data = ''
55 @ SOA ns.example.com noc.example.com 666 7200 3600 1209600 3600
56 @ A 9.8.7.6
57 @ AAAA fedc::bbaa
58 '';
59 services.nsd.zones.".".data = ''
60 @ SOA ns.example.com noc.example.com 666 7200 3600 1209600 3600
61 root A 1.8.7.4
62 root AAAA acbd::4
63 '';
64 };
65 };
66
67 testScript = ''
68 startAll;
69
70 $clientv4->waitForUnit("network.target");
71 $clientv6->waitForUnit("network.target");
72 $server->waitForUnit("nsd.service");
73
74 sub assertHost {
75 my ($type, $rr, $query, $expected) = @_;
76 my $self = $type eq 4 ? $clientv4 : $clientv6;
77 my $out = $self->succeed("host -$type -t $rr $query");
78 $self->log("output: $out");
79 chomp $out;
80 die "DNS IPv$type query on $query gave '$out' instead of '$expected'"
81 if ($out !~ $expected);
82 }
83
84 foreach (4, 6) {
85 subtest "ipv$_", sub {
86 assertHost($_, "a", "example.com", qr/has no [^ ]+ record/);
87 assertHost($_, "aaaa", "example.com", qr/has no [^ ]+ record/);
88
89 assertHost($_, "soa", "example.com", qr/SOA.*?noc\.example\.com/);
90 assertHost($_, "a", "ipv4.example.com", qr/address 1.2.3.4$/);
91 assertHost($_, "aaaa", "ipv6.example.com", qr/address abcd::eeff$/);
92
93 assertHost($_, "a", "deleg.example.com", qr/address 9.8.7.6$/);
94 assertHost($_, "aaaa", "deleg.example.com", qr/address fedc::bbaa$/);
95
96 assertHost($_, "a", "root", qr/address 1.8.7.4$/);
97 assertHost($_, "aaaa", "root", qr/address acbd::4$/);
98 };
99 }
100 '';
101})