[Freeipa-devel] [PATCH 0058, 0064] dns: do not add (forward)zone if it is already resolvable.

David Kupka dkupka at redhat.com
Thu Aug 27 12:22:47 UTC 2015


On 25/08/15 14:39, David Kupka wrote:
> On 25/08/15 10:37, David Kupka wrote:
>> On 24/08/15 16:51, Martin Basti wrote:
>>>
>>>
>>> On 08/20/2015 10:28 AM, David Kupka wrote:
>>>> On 31/07/15 13:32, Martin Basti wrote:
>>>>> On 30/07/15 14:38, Martin Basti wrote:
>>>>>> On 29/07/15 16:12, David Kupka wrote:
>>>>>>> https://fedorahosted.org/freeipa/ticket/5087
>>>>>> NACK
>>>>>>
>>>>>> You forgot to update API.txt file
>>>>
>>>> Thanks for catching that. Updated patch attached.
>>>>
>>>>>>
>>>>> I'm just curious, what is the reason to check if forward zone exists?
>>>>>
>>>>> IMO forwardzone must exists somewhere as the master zone. I don't
>>>>> think
>>>>> we should check forwardzones, this may give too many false positive
>>>>> errors.
>>>>
>>>> AIUI if the zone exist somewhere and is resolvable there is no need to
>>>> add it as a forward zone. If user for some reason want to do it he's
>>>> hiding the original zone and we should not allow this (without
>>>> --force).
>>>>
>>> Note: Petr2 agreed with David's solution
>>>
>>> LGTM, works as expected, but this patch prevents users to add
>>> conflicting zones via webUI (there is no --force field).
>>> We should improve webUI together with this patch.
>>>
>>> Martin^2
>>>
>>>>>
>>>>> Martin^2
>>>>>
>>>>
>>>
>>
>> The '--force' option was not in WebUI before even though it was in API.
>> IMO we should not expose '--force' options in WebUI at all.
>>
>
> Added similar options to ipa-{server,dns}-install and reworked the patch
> to not duplicate the code.
> Updated patch and one new attached.
>
>
>
Updated patch attached.

-- 
David Kupka
-------------- next part --------------
A non-text attachment was scrubbed...
Name: freeipa-dkupka-0058.3-dns-do-not-add-forward-zone-if-it-is-already-resolva.patch
Type: text/x-patch
Size: 7577 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20150827/8fc04cb0/attachment.bin>


More information about the Freeipa-devel mailing list