]>
git.ipfire.org Git - thirdparty/unbound.git/log
Florian Obser [Fri, 10 Jan 2020 12:55:55 +0000 (13:55 +0100)]
Allow the kernel to provide random source ports.
On some operating systems, for example OpenBSD since some decades, the
kernel binds to a random source port if asked for any port (port
number 0). There is no need to replicate this functionality in
userland.
W.C.A. Wijngaards [Thu, 20 Feb 2020 13:42:58 +0000 (14:42 +0100)]
- master branch has 1.10.1 version.
W.C.A. Wijngaards [Thu, 20 Feb 2020 13:41:39 +0000 (14:41 +0100)]
Note tag position in Changelog.
W.C.A. Wijngaards [Thu, 20 Feb 2020 08:17:40 +0000 (09:17 +0100)]
Merge branch 'master' of github.com:NLnetLabs/unbound
W.C.A. Wijngaards [Thu, 20 Feb 2020 08:17:24 +0000 (09:17 +0100)]
- Updated contrib/unbound_smf23.tar.gz with Solaris SMF service for
Unbound from Yuri Voinov.
Alex Band [Thu, 20 Feb 2020 08:13:54 +0000 (09:13 +0100)]
Add GitHub Sponsors for Organisations
W.C.A. Wijngaards [Wed, 19 Feb 2020 16:33:36 +0000 (17:33 +0100)]
Fix memory leak in error case. From review.
W.C.A. Wijngaards [Tue, 18 Feb 2020 16:20:45 +0000 (17:20 +0100)]
Fix issue reported by clang analyzer.
W.C.A. Wijngaards [Tue, 18 Feb 2020 16:04:08 +0000 (17:04 +0100)]
dnstap io, move control frame ready, accept and log to dnstap_fstrm code.
W.C.A. Wijngaards [Tue, 18 Feb 2020 15:30:13 +0000 (16:30 +0100)]
dnstap io, test for client authentication, unbound can send client
authentication credentials, when configured, and unbound-dnstap-socket can
verify the client credentials, and refuses the connection if missing.
W.C.A. Wijngaards [Tue, 18 Feb 2020 13:18:03 +0000 (14:18 +0100)]
dnstap io, test that failed name or auth certificate fails to connect tls.
W.C.A. Wijngaards [Tue, 18 Feb 2020 07:33:58 +0000 (08:33 +0100)]
Fix ifdef of X509_CHECK_FLAG_NO_PARTIAL_WILDCARDS, and
Merge branch 'master' into framestreams
W.C.A. Wijngaards [Tue, 18 Feb 2020 07:31:38 +0000 (08:31 +0100)]
- protect X509_CHECK_FLAG_NO_PARTIAL_WILDCARDS with ifdef for
different openssl versions.
W.C.A. Wijngaards [Mon, 17 Feb 2020 14:25:47 +0000 (15:25 +0100)]
Merge branch 'master' into framestreams
W.C.A. Wijngaards [Mon, 17 Feb 2020 14:24:29 +0000 (15:24 +0100)]
- changelog point where the tag for 1.10.0rc2 release is.
Ralph Dolmans [Mon, 17 Feb 2020 12:38:01 +0000 (13:38 +0100)]
typo fix
Ralph Dolmans [Mon, 17 Feb 2020 12:36:30 +0000 (13:36 +0100)]
- Add respip to supported module-config options in unbound-checkconf.
George Thessalonikefs [Mon, 17 Feb 2020 11:56:20 +0000 (12:56 +0100)]
- Remove unused variable.
W.C.A. Wijngaards [Mon, 17 Feb 2020 09:10:44 +0000 (10:10 +0100)]
Neater changelog
W.C.A. Wijngaards [Mon, 17 Feb 2020 09:09:46 +0000 (10:09 +0100)]
- contrib/drop2rpz: perl script that converts the Spamhaus DROP-List
in RPZ-Format, contributed by Andreas Schulze.
W.C.A. Wijngaards [Fri, 14 Feb 2020 14:44:55 +0000 (15:44 +0100)]
dnstap io, test TLS with peername and TLS authentication.
W.C.A. Wijngaards [Fri, 14 Feb 2020 14:41:17 +0000 (15:41 +0100)]
dnstap io, fix spinning reconnect when handshake fails for TLS.
W.C.A. Wijngaards [Fri, 14 Feb 2020 13:44:02 +0000 (14:44 +0100)]
dnstap io, test for TLS and reconnect for that. And fix unused parameters
for dt_create and fix check of socket path when using IP address.
W.C.A. Wijngaards [Fri, 14 Feb 2020 13:16:56 +0000 (14:16 +0100)]
dnstap io, test for TCP and reconnect for that.
W.C.A. Wijngaards [Fri, 14 Feb 2020 12:54:07 +0000 (13:54 +0100)]
Nicer comment text.
W.C.A. Wijngaards [Fri, 14 Feb 2020 12:23:58 +0000 (13:23 +0100)]
dnstap io, fix to compile without ssl.
W.C.A. Wijngaards [Fri, 14 Feb 2020 09:33:33 +0000 (10:33 +0100)]
dnstap io, fix clang analysis warning
W.C.A. Wijngaards [Fri, 14 Feb 2020 09:01:37 +0000 (10:01 +0100)]
dnstap io, dnstap tls default is yes, and man page documentation.
W.C.A. Wijngaards [Fri, 14 Feb 2020 08:40:37 +0000 (09:40 +0100)]
dnstap io, config entries parse and lex.
W.C.A. Wijngaards [Fri, 14 Feb 2020 08:03:09 +0000 (09:03 +0100)]
dnstap io, example.conf example, config_file entries for tcp and tls.
W.C.A. Wijngaards [Fri, 14 Feb 2020 06:57:57 +0000 (07:57 +0100)]
- Stop unbound-checkconf from insisting that auth-zone and rpz
zonefiles have to exist. They can not exist, and download later.
W.C.A. Wijngaards [Fri, 14 Feb 2020 06:54:49 +0000 (07:54 +0100)]
- Fix spelling in unbound.conf.5.in.
W.C.A. Wijngaards [Wed, 12 Feb 2020 15:49:18 +0000 (16:49 +0100)]
dnstap io, check peer verification in unbound-dnstap-socket tap_handshake.
W.C.A. Wijngaards [Wed, 12 Feb 2020 14:34:56 +0000 (15:34 +0100)]
dnstap io, move peer check into routine.
W.C.A. Wijngaards [Wed, 12 Feb 2020 14:23:58 +0000 (15:23 +0100)]
dnstap io, check peer verification in dtstream dtio_ssl_handshake.
W.C.A. Wijngaards [Wed, 12 Feb 2020 11:53:24 +0000 (12:53 +0100)]
Merge branch 'master' into stream-reuse
W.C.A. Wijngaards [Wed, 12 Feb 2020 11:53:12 +0000 (12:53 +0100)]
Merge branch 'master' into framestreams
W.C.A. Wijngaards [Wed, 12 Feb 2020 11:51:35 +0000 (12:51 +0100)]
- updated version number to 1.10.0.
W.C.A. Wijngaards [Wed, 12 Feb 2020 10:58:39 +0000 (11:58 +0100)]
Merge branch 'stream-reuse' of github.com:NLnetLabs/unbound into stream-reuse
W.C.A. Wijngaards [Wed, 12 Feb 2020 10:58:17 +0000 (11:58 +0100)]
Merge branch 'master' into stream-reuse
W.C.A. Wijngaards [Wed, 12 Feb 2020 10:58:01 +0000 (11:58 +0100)]
Merge branch 'master' into framestreams
W.C.A. Wijngaards [Wed, 12 Feb 2020 10:55:02 +0000 (11:55 +0100)]
- Fix compile warning when threads disabled.
W.C.A. Wijngaards [Wed, 12 Feb 2020 10:49:26 +0000 (11:49 +0100)]
- Fix to clean memory leak of respip_addr.lock when ip_tree deleted.
W.C.A. Wijngaards [Wed, 12 Feb 2020 10:29:55 +0000 (11:29 +0100)]
- Fix contrib/fastrpz.patch to apply cleanly. Fix for serve-stale
fixes, but it does not compile, conflicts with new rpz code.
W.C.A. Wijngaards [Wed, 12 Feb 2020 10:24:59 +0000 (11:24 +0100)]
- Fix contrib/fastrpz.patch to apply cleanly.
W.C.A. Wijngaards [Wed, 12 Feb 2020 10:15:24 +0000 (11:15 +0100)]
- Fix with libnettle make test with dsa disabled.
George Thessalonikefs [Mon, 10 Feb 2020 14:54:41 +0000 (15:54 +0100)]
- Clean debug comments.
George Thessalonikefs [Mon, 10 Feb 2020 12:56:22 +0000 (13:56 +0100)]
- Fix use after free on log-identity after a reload; Fixes #163.
George Thessalonikefs [Mon, 10 Feb 2020 09:31:47 +0000 (10:31 +0100)]
- Document 'ub_result.was_ratelimited' in libunbound.
W.C.A. Wijngaards [Thu, 6 Feb 2020 16:27:55 +0000 (17:27 +0100)]
Merge branch 'master' into stream-reuse
W.C.A. Wijngaards [Thu, 6 Feb 2020 14:33:02 +0000 (15:33 +0100)]
- Fix to put braces around empty if body when threading is disabled.
George Thessalonikefs [Thu, 6 Feb 2020 13:39:58 +0000 (14:39 +0100)]
- Document in unbound.conf manpage that configuration clauses can be repeated in the configuration file.
George Thessalonikefs [Thu, 6 Feb 2020 13:38:01 +0000 (14:38 +0100)]
- Cleaner code for mesh_serve_expired_lookup.
W.C.A. Wijngaards [Thu, 6 Feb 2020 13:01:45 +0000 (14:01 +0100)]
- Fix to lock and release once in mesh_serve_expired_lookup.
W.C.A. Wijngaards [Thu, 6 Feb 2020 11:22:15 +0000 (12:22 +0100)]
- Fix to lock zone before adding rpz qname trigger.
W.C.A. Wijngaards [Thu, 6 Feb 2020 10:51:17 +0000 (11:51 +0100)]
- Fix to create and destroy rpz_lock in auth_zones structure.
George Thessalonikefs [Thu, 6 Feb 2020 10:44:48 +0000 (11:44 +0100)]
- Fix num_reply_states and num_detached_states counting with
serve_expired_callback.
W.C.A. Wijngaards [Thu, 6 Feb 2020 10:09:30 +0000 (11:09 +0100)]
- Fix num_reply_addr counting in mesh and tcp drop due to size
after serve_stale commit.
W.C.A. Wijngaards [Thu, 6 Feb 2020 09:25:47 +0000 (10:25 +0100)]
Fix test to check if server up afterwards
W.C.A. Wijngaards [Wed, 5 Feb 2020 15:17:21 +0000 (16:17 +0100)]
dnstap io, set tls auth name in outgoing ssl
W.C.A. Wijngaards [Wed, 5 Feb 2020 14:04:04 +0000 (15:04 +0100)]
dnstap io, ssl write.
W.C.A. Wijngaards [Wed, 5 Feb 2020 13:25:47 +0000 (14:25 +0100)]
Merge branch 'master' into framestreams
gthess [Wed, 5 Feb 2020 13:20:27 +0000 (14:20 +0100)]
Serve stale (#159)
- Added serve-stale functionality as described in
draft-ietf-dnsop-serve-stale-10. `serve-expired-*` options can be used
to configure the behavior.
- Updated cachedb to honor `serve-expired-ttl`; Fixes #107.
- Renamed statistic `num.zero_ttl` to `num.expired` as expired replies
come with a configurable TTL value (`serve-expired-reply-ttl`).
- Fixed stats when replying with cached, cname-aliased records.
- Added missing default values for redis cachedb backend.
W.C.A. Wijngaards [Wed, 5 Feb 2020 12:59:56 +0000 (13:59 +0100)]
dnstap io, ssl handshake.
W.C.A. Wijngaards [Wed, 5 Feb 2020 12:03:58 +0000 (13:03 +0100)]
dnstap io, close fd routine.
W.C.A. Wijngaards [Tue, 4 Feb 2020 16:23:19 +0000 (17:23 +0100)]
dnstap io, ssl and ssl ctx creation.
W.C.A. Wijngaards [Tue, 4 Feb 2020 08:45:44 +0000 (09:45 +0100)]
dnstap create debug tool with other debug tools in list.
W.C.A. Wijngaards [Tue, 4 Feb 2020 08:40:00 +0000 (09:40 +0100)]
Merge branch 'master' into framestreams
Ralph Dolmans [Mon, 3 Feb 2020 15:53:50 +0000 (16:53 +0100)]
Merge branch 'master' of github.com:NLnetLabs/unbound
Ralph Dolmans [Mon, 3 Feb 2020 15:52:25 +0000 (16:52 +0100)]
- Reformat rpz disabled stats counter
Alex Band [Mon, 3 Feb 2020 15:51:03 +0000 (16:51 +0100)]
Link to NLnet Labs funding page
Ralph Dolmans [Mon, 3 Feb 2020 15:44:21 +0000 (16:44 +0100)]
- Add assertion to please static analyzer
Ralph Dolmans [Mon, 3 Feb 2020 13:19:44 +0000 (14:19 +0100)]
- remove unused code block in respip
W.C.A. Wijngaards [Fri, 31 Jan 2020 16:07:40 +0000 (17:07 +0100)]
dnstap io, connect and write over TCP.
W.C.A. Wijngaards [Fri, 31 Jan 2020 13:13:41 +0000 (14:13 +0100)]
dnstap unbound-dnstap-sock, comments and log output on tls error close.
W.C.A. Wijngaards [Fri, 31 Jan 2020 13:03:28 +0000 (14:03 +0100)]
dnstap unbound-dnstap-sock, read from TLS.
W.C.A. Wijngaards [Fri, 31 Jan 2020 12:05:06 +0000 (13:05 +0100)]
dnstap unbound-dnstap-sock, verbose accepted stream IP addresses
W.C.A. Wijngaards [Fri, 31 Jan 2020 10:18:14 +0000 (11:18 +0100)]
dnstap unbound-dnstap-sock, add -t option.
W.C.A. Wijngaards [Fri, 31 Jan 2020 10:11:43 +0000 (11:11 +0100)]
dnstap unbound-dnstap-sock, fixup check for ssl context create error.
W.C.A. Wijngaards [Fri, 31 Jan 2020 10:10:04 +0000 (11:10 +0100)]
dnstap unbound-dnstap-sock, tls options and context created.
W.C.A. Wijngaards [Fri, 31 Jan 2020 09:05:00 +0000 (10:05 +0100)]
dnstap unbound-dnstap-sock, fixup constant defines.
W.C.A. Wijngaards [Fri, 31 Jan 2020 09:02:51 +0000 (10:02 +0100)]
dnstap unbound-dnstap-sock, fixup signal handler exit.
W.C.A. Wijngaards [Fri, 31 Jan 2020 08:53:49 +0000 (09:53 +0100)]
dnstap unbound-dnstap-sock, can listen to multiple sockets, can listen
to TCP sockets, cleans up on exit after signal.
W.C.A. Wijngaards [Fri, 31 Jan 2020 06:49:38 +0000 (07:49 +0100)]
Merge branch 'master' into framestreams
W.C.A. Wijngaards [Fri, 31 Jan 2020 06:49:14 +0000 (07:49 +0100)]
- Fix fclose on error in TLS session ticket code.
Ralph Dolmans [Thu, 30 Jan 2020 18:15:58 +0000 (19:15 +0100)]
- Stop working on socket when socket() call returns an error.
- Check malloc return values in TLS session ticket code
W.C.A. Wijngaards [Thu, 30 Jan 2020 16:11:07 +0000 (17:11 +0100)]
- put fstrm protocol contents in separate files, dnstap_fstrm.c
and dnstap_fstrm.h
W.C.A. Wijngaards [Thu, 30 Jan 2020 15:22:12 +0000 (16:22 +0100)]
Merge branch 'master' into framestreams
W.C.A. Wijngaards [Thu, 30 Jan 2020 15:21:50 +0000 (16:21 +0100)]
Merge branch 'master' into stream-reuse
W.C.A. Wijngaards [Thu, 30 Jan 2020 15:15:51 +0000 (16:15 +0100)]
- Add getentropy_freebsd.o to Makefile dependencies.
W.C.A. Wijngaards [Thu, 30 Jan 2020 15:12:39 +0000 (16:12 +0100)]
- Add build rule for ipset to Makefile
Ralph Dolmans [Thu, 30 Jan 2020 15:04:27 +0000 (16:04 +0100)]
- Add changelog entry for RPZ merge
Ralph Dolmans [Thu, 30 Jan 2020 14:59:01 +0000 (15:59 +0100)]
Merge branch 'rpz'
Ralph Dolmans [Thu, 30 Jan 2020 14:57:34 +0000 (15:57 +0100)]
Merge branch 'master' into rpz
W.C.A. Wijngaards [Thu, 30 Jan 2020 14:49:57 +0000 (15:49 +0100)]
Merge branch 'master' into stream-reuse
W.C.A. Wijngaards [Thu, 30 Jan 2020 14:49:24 +0000 (15:49 +0100)]
Merge branch 'master' into framestreams
Ralph Dolmans [Thu, 30 Jan 2020 14:47:49 +0000 (15:47 +0100)]
- Add changelog entry for memory leak fix
Ralph Dolmans [Thu, 30 Jan 2020 14:45:54 +0000 (15:45 +0100)]
- Fix memory leak in do_auth_zone_transfer on success
W.C.A. Wijngaards [Thu, 30 Jan 2020 14:13:25 +0000 (15:13 +0100)]
dnstap io, add reconnect test.
Ralph Dolmans [Thu, 30 Jan 2020 13:58:25 +0000 (14:58 +0100)]
Merge branch 'master' of github.com:NLnetLabs/unbound