]>
git.ipfire.org Git - thirdparty/pdns.git/log
Remi Gacogne [Wed, 19 May 2021 17:44:12 +0000 (19:44 +0200)]
auth: Fix a 'temporary used in loop' warning reported by g++ 11.1.0
```
common_startup.cc: In function ‘void mainthread()’:
common_startup.cc:617:24: warning: loop variable ‘algotype’ of type ‘const string&’ {aka ‘const std::__cxx11::basic_string<char>&’} binds to a temporary constructed from type ‘const char* const’ [-Wrange-loop-construct]
617 | for (const string& algotype : {"ksk", "zsk"}) {
| ^~~~~~~~
common_startup.cc:617:24: note: use non-reference type ‘const string’ {aka ‘const std::__cxx11::basic_string<char>’} to make the copy explicit or ‘const char* const&’ to prevent copying
```
Remi Gacogne [Wed, 19 May 2021 17:23:24 +0000 (19:23 +0200)]
test-dnsname_cc.cc: Fix a 'temporary used in loop' warning reported by g++ 11.1.0
```
test-dnsname_cc.cc: In member function ‘void test_dnsname_cc::test_compare_canonical::test_method()’:
test-dnsname_cc.cc:684:26: warning: loop variable ‘b’ of type ‘const string&’ {aka ‘const std::__cxx11::basic_string<char>&’} binds to a temporary constructed from type ‘const char* const’ [-Wrange-loop-construct]
684 | for(const std::string& b : {"bert.com.", "alpha.nl.", "articles.xxx.",
| ^
test-dnsname_cc.cc:684:26: note: use non-reference type ‘const string’ {aka ‘const std::__cxx11::basic_string<char>’} to make the copy explicit or ‘const char* const&’ to prevent copying
```
Peter van Dijk [Wed, 19 May 2021 15:59:51 +0000 (17:59 +0200)]
Merge pull request #10260 from mind04/pdns-nsec3param
auth: lower max-nsec3-iterations to 100
Kees Monshouwer [Thu, 1 Apr 2021 18:03:28 +0000 (20:03 +0200)]
auth: lower max-nsec3-iterations to 100
Peter van Dijk [Wed, 19 May 2021 14:06:29 +0000 (16:06 +0200)]
Merge pull request #10424 from mind04/pdns-domain2zone
auth: replace domain-metadata-cache-ttl by zone-metadata-cache-ttl
Kees Monshouwer [Tue, 18 May 2021 16:55:44 +0000 (18:55 +0200)]
auth: change domain to zone round 1
Kees Monshouwer [Tue, 18 May 2021 16:44:20 +0000 (18:44 +0200)]
auth: replace domain-metadata-cache-ttl by zone-metadata-cache-ttl
Peter van Dijk [Wed, 19 May 2021 10:52:54 +0000 (12:52 +0200)]
Merge pull request #9464 from zeha/zonecache
auth: cache list of all domains
Peter van Dijk [Wed, 19 May 2021 09:15:21 +0000 (11:15 +0200)]
test zone-cache in gsqlite3 master and slave, with low TTL for more intensive testing
Otto Moerbeek [Wed, 19 May 2021 08:35:53 +0000 (10:35 +0200)]
Merge pull request #10349 from omoerbeek/rec-tcpiohandler
rec: move to tcpiohandler for outgoing TCP
Otto Moerbeek [Wed, 19 May 2021 08:34:49 +0000 (10:34 +0200)]
Merge pull request #10420 from omoerbeek/rec-nod-no-qm
rec: For the NOD lookup case, we don't want QName Minimization.
Remi Gacogne [Wed, 19 May 2021 07:21:31 +0000 (09:21 +0200)]
Merge pull request #10381 from rgacogne/ddist-better-padding
dnsdist: Reorganize the IDState and Rings fields
Chris Hofstaedtler [Tue, 18 May 2021 19:18:56 +0000 (21:18 +0200)]
Rename domaincache to zonecache, also ttl to refreshinterval
Otto Moerbeek [Tue, 18 May 2021 16:57:15 +0000 (18:57 +0200)]
Merge pull request #10282 from omoerbeek/qtype-tostring
Rename QType.getName() to QType.toString()
Otto [Fri, 9 Apr 2021 12:46:26 +0000 (14:46 +0200)]
Rename QType.getName() to QType.toString()
Peter van Dijk [Tue, 18 May 2021 15:41:04 +0000 (17:41 +0200)]
Merge pull request #10401 from mind04/consistent
auth: change the consistent-backends default to 'yes'
Otto [Tue, 18 May 2021 13:40:44 +0000 (15:40 +0200)]
For the NOD lookup case, we don't want QName Minimization.
Chris Hofstaedtler [Tue, 18 May 2021 12:11:59 +0000 (14:11 +0200)]
ueberbackend: include disabled domains in cache
Chris Hofstaedtler [Tue, 18 May 2021 12:10:38 +0000 (14:10 +0200)]
Add (domain-)cache-ttl to gsqlite3-master CI
Kees Monshouwer [Wed, 12 May 2021 23:18:41 +0000 (01:18 +0200)]
auth: change the consistent-backends default to 'yes'
Chris Hofstaedtler [Tue, 18 May 2021 07:56:21 +0000 (09:56 +0200)]
Treat vanished domains like they were never in the cache
Peter van Dijk [Mon, 17 May 2021 09:56:56 +0000 (11:56 +0200)]
Merge pull request #10400 from mind04/headers
add missing includes (Fedora 34, gcc 11.1 / clang 12)
Chris Hofstaedtler [Sat, 15 May 2021 22:10:59 +0000 (00:10 +0200)]
getAuth: abort if backend returned wrong SOA for cached domain
Chris Hofstaedtler [Sat, 15 May 2021 22:10:42 +0000 (00:10 +0200)]
getAuth: avoid throwing when no SOA is returned for cached domain
Chris Hofstaedtler [Mon, 10 May 2021 08:28:35 +0000 (10:28 +0200)]
auth-domaincache: use info-zone-query for inserted zone id
Also apply "RETURNING id" optimization for postgresql.
Chris Hofstaedtler [Mon, 10 May 2021 15:29:42 +0000 (17:29 +0200)]
lmdbbackend/createDomain: reuse RW transaction
Chris Hofstaedtler [Wed, 12 May 2021 09:37:28 +0000 (11:37 +0200)]
auth-domaincache: apply suggested comment improvement
Chris Hofstaedtler [Mon, 10 May 2021 08:31:12 +0000 (10:31 +0200)]
Apply clang-format
Chris Hofstaedtler [Mon, 10 May 2021 08:27:55 +0000 (10:27 +0200)]
auth-domaincache: add "new" headers
Chris Hofstaedtler [Mon, 10 May 2021 08:16:10 +0000 (10:16 +0200)]
setReplacePending: avoid lock
Chris Hofstaedtler [Mon, 10 May 2021 08:15:33 +0000 (10:15 +0200)]
test-auth-domaincache_cc: check zoneId value explicitly
Chris Hofstaedtler [Mon, 10 May 2021 08:12:59 +0000 (10:12 +0200)]
Tidy up style nits
Chris Hofstaedtler [Mon, 29 Mar 2021 13:49:39 +0000 (15:49 +0200)]
domaincache: preserve domains added while replace data collection was running
Chris Hofstaedtler [Mon, 15 Mar 2021 09:05:27 +0000 (10:05 +0100)]
Reformat
Chris Hofstaedtler [Sun, 14 Mar 2021 21:57:23 +0000 (22:57 +0100)]
Remove unused d_ops
Chris Hofstaedtler [Mon, 8 Feb 2021 12:51:04 +0000 (13:51 +0100)]
Add separate auth domain cache test
Chris Hofstaedtler [Mon, 8 Feb 2021 12:34:09 +0000 (13:34 +0100)]
AuthDomainCache: init d_ttl
Chris Hofstaedtler [Mon, 8 Feb 2021 12:33:58 +0000 (13:33 +0100)]
AuthDomainCache: use std::move
Chris Hofstaedtler [Mon, 8 Feb 2021 12:33:47 +0000 (13:33 +0100)]
Move extern AuthDomainCache into auth-domaincache.hh
Chris Hofstaedtler [Thu, 29 Oct 2020 11:59:02 +0000 (12:59 +0100)]
Enable domain cache on gsql tests
Chris Hofstaedtler [Thu, 29 Oct 2020 11:54:43 +0000 (12:54 +0100)]
Avoid abort if database server goes away
Chris Hofstaedtler [Mon, 19 Oct 2020 14:21:17 +0000 (16:21 +0200)]
auth: add a cache of existing domains
Kees Monshouwer [Tue, 11 May 2021 08:27:01 +0000 (10:27 +0200)]
add missing includes (Fedora 34, gcc 11.1 / clang 12)
Otto Moerbeek [Wed, 12 May 2021 14:24:01 +0000 (16:24 +0200)]
Merge pull request #10397 from aj-gh/fixdoc-refreshonttlperc
Fix docs: refresh-on-ttl-perc was added in 4.5.0
Andreas Jakum [Wed, 12 May 2021 13:52:07 +0000 (15:52 +0200)]
Fix docs: refresh-on-ttl-perc was added in 4.5.0
Peter van Dijk [Wed, 12 May 2021 11:45:50 +0000 (13:45 +0200)]
Merge pull request #10392 from Habbie/gpgsql-select-returning
auth gpgsql: use SELECT .. RETURNING to get inserted row ID
Otto Moerbeek [Wed, 12 May 2021 10:48:29 +0000 (12:48 +0200)]
Merge pull request #10394 from mnordhoff/rec-upgrade
Combine duplicate sections in Recursor upgrade guide
Peter van Dijk [Wed, 12 May 2021 10:26:55 +0000 (12:26 +0200)]
pdnsutil add-zone-key: better error formatting
Peter van Dijk [Wed, 12 May 2021 10:26:36 +0000 (12:26 +0200)]
auth gpgsql: use SELECT .. RETURNING to get inserted row ID, fixes #7175
Matt Nordhoff [Wed, 12 May 2021 08:07:01 +0000 (08:07 +0000)]
Combine duplicate sections in Recursor upgrade guide.
Also use more consistent capitalization and wording.
Pieter Lexis [Tue, 11 May 2021 16:11:53 +0000 (18:11 +0200)]
Merge pull request #10389 from Habbie/dockerignore-git
.dockerignore: do not ignore .git
Otto Moerbeek [Tue, 11 May 2021 13:25:08 +0000 (15:25 +0200)]
Merge pull request #10391 from omoerbeek/rec-fastopen-docs
rec: Better wording for fastopen docs.
Remi Gacogne [Tue, 11 May 2021 12:54:48 +0000 (14:54 +0200)]
Merge pull request #10350 from rgacogne/rec-duplicate-nsec-wc-proof
rec: Only add the NSEC and RRSIG records once in wildcard NODATA answers
Otto [Tue, 11 May 2021 12:18:58 +0000 (14:18 +0200)]
Better wording for fastopen docs.
Remi Gacogne [Tue, 11 May 2021 12:00:25 +0000 (14:00 +0200)]
Merge pull request #10388 from rgacogne/ddist-document-default-cache-cleaning-delay
dnsdist: Document the default value of setCacheCleaningDelay()
Peter van Dijk [Tue, 11 May 2021 10:27:33 +0000 (12:27 +0200)]
.dockerignore: do not ignore .git
because we ignore **/*.1 to not drag built manpages into the docker
context - but this also prevents any tags ending in .1 (like rec-4.5.1)
from being built
Remi Gacogne [Tue, 11 May 2021 10:01:52 +0000 (12:01 +0200)]
dnsdist: Document the default value of setCacheCleaningDelay()
Otto Moerbeek [Tue, 11 May 2021 09:30:54 +0000 (11:30 +0200)]
Merge pull request #10368 from omoerbeek/rec-prep-4.5.0
rec: Prep rec-4.5.1
Otto [Tue, 11 May 2021 08:07:00 +0000 (10:07 +0200)]
Rebase after secpoll update
Otto [Mon, 10 May 2021 10:38:46 +0000 (12:38 +0200)]
It's going to be 4.5.1
Otto Moerbeek [Fri, 7 May 2021 14:52:46 +0000 (16:52 +0200)]
Update pdns/recursordist/docs/appendices/EOL.rst
Co-authored-by: Pieter Lexis <pieter@plexis.eu>
Otto [Fri, 7 May 2021 07:32:04 +0000 (09:32 +0200)]
Prep rec-4.5.0
Remi Gacogne [Tue, 11 May 2021 08:00:36 +0000 (10:00 +0200)]
Merge pull request #10374 from rgacogne/ddist160-changelog
dnsdist: Changelog and secpoll update for 1.6.0
Remi Gacogne [Mon, 10 May 2021 08:18:53 +0000 (10:18 +0200)]
dnsdist: Changelog and secpoll update for 1.6.0
Remi Gacogne [Mon, 10 May 2021 14:03:52 +0000 (16:03 +0200)]
dnsdist: Add a few words about memory consumption in the documentation
Remi Gacogne [Mon, 10 May 2021 13:53:56 +0000 (15:53 +0200)]
dnsdist: Reorganize the IDState and Rings fields
Reducing the space lost to padding and thus the memory usage. This
change saves 1 MB of memory per downstream server in the default
configuration, and around 8 bytes per entry in the ring buffer.
Remi Gacogne [Mon, 10 May 2021 12:12:08 +0000 (14:12 +0200)]
Merge pull request #10379 from rgacogne/ddist-fix-changelog
dnsdist: Fix a typo in the ChangeLog header for 1.5.2
Remi Gacogne [Mon, 10 May 2021 12:08:20 +0000 (14:08 +0200)]
dnsdist: Fix a typo in the ChangeLog header for 1.5.2
Remi Gacogne [Mon, 10 May 2021 11:53:34 +0000 (13:53 +0200)]
Merge pull request #10163 from rgacogne/ddist152-changelog
dnsdist: Update ChangeLog and secpoll zone for 1.5.2
Otto Moerbeek [Mon, 10 May 2021 10:24:53 +0000 (12:24 +0200)]
Merge pull request #10375 from rgacogne/rec-aggressive-nsec-salt-race
rec: Prevent a race in the aggressive NSEC cache
Peter van Dijk [Mon, 10 May 2021 07:44:35 +0000 (09:44 +0200)]
Merge pull request #10364 from rgacogne/auth-fromiscmap-b64
auth: Don't choke on non-base64 values when importing zone keys
Remi Gacogne [Fri, 7 May 2021 15:25:01 +0000 (17:25 +0200)]
rec: Prevent a race in the aggressive NSEC cache
When a new NSEC3 record has a different salt than the one we know, we
update the zone entry with the new salt. Unfortunately, that salt was
read without holding the lock in `AggressiveNSECCache::getNSEC3Denial`,
leading to a possible data race.
Peter van Dijk [Sat, 8 May 2021 20:01:58 +0000 (22:01 +0200)]
Merge pull request #10370 from yantarou/ixfrdist_typo
docs: fix typo in ixfrdist docs
Pieter Lexis [Fri, 7 May 2021 12:34:02 +0000 (14:34 +0200)]
Merge pull request #10371 from mnordhoff/dnsdist-docs-tcaction
dnsdist docs: switch RA and RD
Matt Nordhoff [Fri, 7 May 2021 10:55:31 +0000 (10:55 +0000)]
dnsdist docs: switch RA and RD
Jan Hilberath [Fri, 7 May 2021 10:07:46 +0000 (19:07 +0900)]
docs: fix typo in ixfrdist docs
Remi Gacogne [Fri, 7 May 2021 07:55:03 +0000 (09:55 +0200)]
dnsdist: May the 10th seems more realistic for the 1.5.2 release
Otto Moerbeek [Thu, 6 May 2021 18:18:22 +0000 (20:18 +0200)]
Merge pull request #10353 from rgacogne/rec-dns64-on-rpz-hit-after-gettag-ffi-hit
rec: Apply dns64 on RPZ hits generated after a gettag_ffi hit
Otto Moerbeek [Thu, 6 May 2021 18:17:24 +0000 (20:17 +0200)]
Merge pull request #10292 from omoerbeek/rec-more-tsan
rec: Fix TSAN complaints: max stacksize and response stats size counters
Peter van Dijk [Thu, 6 May 2021 13:51:23 +0000 (15:51 +0200)]
Merge pull request #10361 from dmachard/auth-timeout-luarecords
auth: change default timeout to 2s for lua records
Remi Gacogne [Thu, 6 May 2021 13:00:18 +0000 (15:00 +0200)]
Fix typo in DNSCryptoKeyEngine::makeFromISCString
Co-authored-by: Peter van Dijk <peter.van.dijk@powerdns.com>
Remi Gacogne [Thu, 6 May 2021 10:12:43 +0000 (12:12 +0200)]
auth: Don't choke on non-base64 values when importing zone keys
DNSCryptoKeyEngine::makeFromISCFile(), called by `pdnsutil import-zone-key`
or the API, for example, would try to parse almost all values as a
base64 string. Depending on the version of OpenSSL, it could have lead
to a weird `Error: BIO_read failed to read all data from memory buffer`
error when the file contains a non-base64 value, like for example:
```
Flags: 257
```
Recent versions of OpenSSL seems to simply return that the value could
not be parsed, but older ones (OpenSSL 1.0.2k from CentOS 7 for example)
would report an incomplete read (BIO_should_retry() returning 1),
triggering an exception that prevents the key from being loaded.
This commits keeps a longer list of known non-base64 values, but
more importantly catch the base64 decoding exception and then store the
initial value instead of aborting. Only failure to decode known base64
values prevents the key from being loaded.
Remi Gacogne [Thu, 6 May 2021 08:10:12 +0000 (10:10 +0200)]
Merge pull request #10362 from Habbie/dnsdist-docs-tcaction
dnsdist docs: correct bits for TCAction
Peter van Dijk [Thu, 6 May 2021 04:13:22 +0000 (06:13 +0200)]
dnsdist docs: correct bits for TCAction
dmachard [Wed, 5 May 2021 16:51:50 +0000 (18:51 +0200)]
change default timeout to 2s for lua records
Remi Gacogne [Tue, 4 May 2021 16:30:47 +0000 (18:30 +0200)]
rec: Test the most simple condition first
Co-authored-by: Otto Moerbeek <otto.moerbeek@open-xchange.com>
Remi Gacogne [Tue, 4 May 2021 16:24:21 +0000 (18:24 +0200)]
dnsdist: Update ChangeLog and secpoll zone for 1.5.2
Otto [Mon, 3 May 2021 12:34:29 +0000 (14:34 +0200)]
Start using tcpiohandler for real
Remi Gacogne [Tue, 4 May 2021 12:56:40 +0000 (14:56 +0200)]
rec: Add a regression test for gettag_ffi, RPZ and DNS64 interaction
Remi Gacogne [Tue, 4 May 2021 10:29:32 +0000 (12:29 +0200)]
rec: Apply dns64 on RPZ hits generated after a gettag_ffi hit
We do special case the qname RPZ processing after a gettag_ffi hit,
leading to dns64 to not be applied in that case. This commit adds
dns64 handling to the special case.
Remi Gacogne [Tue, 4 May 2021 08:15:02 +0000 (10:15 +0200)]
Merge pull request #10347 from rgacogne/ddist-16rc2-changelog
dnsdist: Add ChangeLog and secpoll for 1.6.0-rc2
Remi Gacogne [Mon, 3 May 2021 14:37:12 +0000 (16:37 +0200)]
Merge pull request #10346 from rgacogne/ddist-dnscrypt-locks
dnsdist: Fix missing locks in DNSCrypt certificates management
Remi Gacogne [Mon, 3 May 2021 13:00:04 +0000 (15:00 +0200)]
rec: Only add the NSEC and RRSIG records once in wildcard NODATA answers
For wildcard-expanded answers we need to collect the proof that the
exact name does not exist and add them to the response. We also
collect that proof for negative answers.
When the answer is a wildcard-expanded NODATA, we only need to collect
them once, not twice.
Otto [Mon, 3 May 2021 10:48:03 +0000 (12:48 +0200)]
Replace Socket * by an fd in PacketID and fix GenUDPQueryResponse to
use fd instead of sock, which should only be used for tcp.
Also reorder PacketID fields so that large fields come before small ones and use modern init.
Remi Gacogne [Mon, 3 May 2021 09:23:46 +0000 (11:23 +0200)]
dnsdist: Add ChangeLog and secpoll for 1.6.0-rc2
Remi Gacogne [Mon, 3 May 2021 08:22:08 +0000 (10:22 +0200)]
dnsdist: Fix missing locks in DNSCrypt certificates management
In theory these functions should already be protected by the Lua
lock but better safe than sorry.
Found while working on the migration to LockGuarded.
Pieter Lexis [Mon, 3 May 2021 07:51:21 +0000 (09:51 +0200)]
Merge pull request #10293 from Habbie/update-builder
update builder - i accidentally downgraded it in
4f57dec4a7f1b94c6da4c0d3fdfecf73781bbcb2
Remi Gacogne [Mon, 3 May 2021 07:48:58 +0000 (09:48 +0200)]
Merge pull request #10327 from rgacogne/ddist-dynblocks-ebpf
dnsdist: Only use eBPF for "drop" actions, clean up more often
Otto Moerbeek [Fri, 30 Apr 2021 15:23:37 +0000 (17:23 +0200)]
Merge pull request #10344 from omoerbeek/boostm4-clang11.1
auto.m4: clang 11.1 is a thing
Otto Moerbeek [Fri, 30 Apr 2021 15:19:23 +0000 (17:19 +0200)]
Merge pull request #10343 from omoerbeek/dnsdist-test-warnings
dnsdist: fix test warnings