X-Git-Url: http://www.average.org/gitweb/?p=pdns-pipe-nmc.git;a=blobdiff_plain;f=README.md;h=c7dd3574610f1d26482d9b5ea23d8c5270dbde53;hp=9ea13471ecd4ac4664d481fd67fab557812869b3;hb=f5e9870ed6d3307c08e583a7874d8c35e0ea6978;hpb=cda8ce8f796f83823821c20537986d53cd868a73 diff --git a/README.md b/README.md index 9ea1347..c7dd357 100644 --- a/README.md +++ b/README.md @@ -15,16 +15,23 @@ frontend, and has simple backend interface. ## Building -The program is built as a single executable to be run by PowerDns's -pipe backend. It is written in [Haskell](http://www.haskell.org/). -There is no `cabal` configuration at the moment, so to build it, -simply run +The program is a single executable to be run by PowerDns's pipe +backend. It is written in [Haskell](http://www.haskell.org/). +If you have haskell installed on your system, run ``` -ghc --make pdns-pipe-nmc +cabal configure ``` -and install any missing packages it complains about. +followed by + +``` +cabal build +``` + +and hopefully it will tell you what packages are missing. You can +install them either with your OS package manager (if they exist in +your distribution) or with `cabal install`. ## Installing @@ -77,26 +84,71 @@ keep it guarded. so the communication will happen over DNSSEC protocol without the need to keep the signatures in the zone data itself. You probably would need to create signing key for the PowerDNS instance, and add -the corresponding public key as "trused" into the configuration of +the corresponding public key as "trusted" into the configuration of your resolvers. ## Status -Alpha. It is insufficiently tested, and there are loose ends in the -functionality. For example, version in the `SOA` record is bogus. -Some of the the problems are due to incomplete and/or imprecise -[definition of the domain data format](https://wiki.namecoin.info/index.php?title=Domain_Name_Specification) -on the wiki. That said, I am using it to access some of the `.bit` websites -and did not notice anomalies so far. +Beta. It is mostly feature-complete, but insufficiently tested. +It implements the +[data format specification](http://www.average.org/pdns-pipe-nmc/spec.html) +(SPEC.md in the source distribution) that slightly deviates from the +[official specification](https://wiki.namecoin.info/index.php?title=Domain_Name_Specification). +I am using it to access some of the `.bit` websites and it works +for me. Try at your risk. -## Getting the Software +## Unsolved problems + +The biggest problem by far is generating meaningful `SOA` records. + +### SOA Version a.k.a. Generation Count + +DNS infrastructure (including PowerDNS implementation) relies on the +"generation" field of the `SOA` RR when it makes decision to invalidate +the cache. So, if there is zone data in the DNS cache, and a DNS server +needs to respond to a request about an object from that zone, it first +checks if the TTL has expired. If it has not, the server takes the data +from the cache. If it has expired, the server asks the "authoritative +source" (which is in our case the dnamecoin daemon) for the SOA record +and compares the generation count in the received response with the +number kept in the cache. If the "authoritative" SOA does not have a +greater generation count than the cached SOA, DNS server **does not** +refresh its cache, presuming that the data there is still valid. + +So, it is important that the generation count in the SOA record is +incremented every time when the domain object, or any of the object that +it "include"-s or to which it "delegate"-s is changed. + +At present, there is no machanism for that. In most cases, simply +summing the number of entries in `name_history`-s of all domain object +involved in resolution would work, but this approach would produce +wrong result when an "import" entry is removed from a domain, because +in such case the sum would decrease. It would also not notice the +changes in an object "include"-ed in a subdomain, unless complete +recursive resolution of the subdomain tree is enforced for when +SOA record is requested. That would invalidate the reason to have +caching in the first place. + +One possible workaround, currently implemented in `pdns-pipe-nmc`, is to +use a derivative of absolute time, in our case the number of 10-munute +intervals elapsed since Namecoin was concieved, as the SOA generation +count. + +### Nameserver field + +There is no "reasonable" value that could be placed there. Except +possibly the name of the host on which the PoweDNS instance is running, +in the `.bit` zone. Currently, `pdns-pipe-nmc` just puts a dot "." +there, and no problems where noticed so far. -### Source +## Getting the Software Check the [project homepage](http://www.average.org/pdns-pipe-nmc/). +### Source + Git [clone](git://git.average.org/git/pdns-pipe-nmc.git) or [browse](http://www.average.org/gitweb/?p=pdns-pipe-nmc.git;a=summary), or use [github mirror](https://github.com/crosser/pdns-pipe-nmc). @@ -105,9 +157,11 @@ or use [github mirror](https://github.com/crosser/pdns-pipe-nmc). There is a binary built for x86_64 Linux with glibc6: -|----------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------| | Executable file | PGP | -| [pdns-pipe-nmc.linux-glibc6.x86_64.2014-04-20.git-e9bd43f](pdns-pipe-nmc.linux-glibc6.x86_64.2014-04-20.git-e9bd43f) | [sig](pdns-pipe-nmc.linux-glibc6.x86_64.2014-04-20.git-e9bd43f.sig) | +|----------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------| +| [**pdns-pipe-nmc.linux-glibc6.x86_64.2014-05-01.git-0.9.0.0**](http://www.average.org/pdns-pipe-nmc.linux-glibc6.x86_64.2014-05-01.git-0.9.0.0) | [sig](http://www.average.org/pdns-pipe-nmc/pdns-pipe-nmc.linux-glibc6.x86_64.2014-05-01.git-0.9.0.0.sig) | +| [pdns-pipe-nmc.linux-glibc6.x86_64.2014-04-22.git-108b6c2](http://www.average.org/pdns-pipe-nmc/pdns-pipe-nmc.linux-glibc6.x86_64.2014-04-22.git-108b6c2) | [sig](http://www.average.org/pdns-pipe-nmc/pdns-pipe-nmc.linux-glibc6.x86_64.2014-04-22.git-108b6c2.sig) | +| [pdns-pipe-nmc.linux-glibc6.x86_64.2014-04-20.git-e9bd43f](http://www.average.org/pdns-pipe-nmc/pdns-pipe-nmc.linux-glibc6.x86_64.2014-04-20.git-e9bd43f) | [sig](http://www.average.org/pdns-pipe-nmc/pdns-pipe-nmc.linux-glibc6.x86_64.2014-04-20.git-e9bd43f.sig) | ## Author