]> git.ipfire.org Git - thirdparty/bind9.git/shortlog
thirdparty/bind9.git
2026-07-10  Nicki KřížekFix the dnssec_py test marks
2026-07-10  Aydın Mercan[CVE-2026-13321] sec: usr: Fix DNSSEC validation bypass...
2026-07-10  Evan Huntdns_rdataset_addnoqname() could find unsigned NSEC...
2026-07-10  Evan Hunt[CVE-2026-10723] sec: usr: Correct verification of...
2026-07-10  Aydın Mercanchange dns_nsec_requiredtypespresent to dns_nsec_is_legal
2026-07-10  Evan HuntMove the dnssec_findnoqname_mismatch test into dnssec_py
2026-07-10  Ondřej Surýfix: dev: Avoid needless queries when the DNSSEC valid...
2026-07-10  Matthijs MekkingUpdate reproducer #5874
2026-07-10  Aydın MercanReject out-of-zone NSEC next owner names
2026-07-10  Matthijs MekkingUpdate reproducer #5985
2026-07-10  Ondřej Surýsec: usr: Reclaim memory promptly when DNSSEC validatio...
2026-07-10  Ondřej SurýMake the per-fetch validation quota terminal in sub...
2026-07-10  Alessio PoddaReproducer for #5874 NSEC3 impersonation
2026-07-10  Aydın MercanAdd system test for out-of-zone nsec dnssec bypass
2026-07-10  Alessio PoddaReproducer for #5985 addnoqname mismatch
2026-07-10  Colin Vidalchg: dev: Follow-up of disambiguate `query_cname()...
2026-07-10  Ondřej SurýCancel the offloaded verification job when canceling...
2026-07-10  Evan HuntCheck NSEC3 signer matches the owning zone
2026-07-10  Mark Andrewsfix: nil: Add missing dumpnode call in dnssec-signzone
2026-07-10  Colin VidalConvert some chain shell-based system tests in python
2026-07-10  Colin Vidalchg: dev: Disambiguate `query_cname()` and `query_dname...
2026-07-10  Mark AndrewsTest dnssec-signzone -D and out-of-zone records
2026-07-10  Colin VidalFollow-up of disambiguate `query_cname()` and `query_dn...
2026-07-10  Ondřej Surý[CVE-2026-11605] sec: usr: Prevent excessive validation...
2026-07-10  Colin VidalDisambiguate `query_cname()` and `query_dname()` usage
2026-07-10  Mark AndrewsAdd missing dumpnode call in dnssec-signzone
2026-07-10  Mark Andrews[CVE-2026-11721] sec: usr: Invalid signed wildcard...
2026-07-10  Ondřej SurýCover excessive NSEC3 proofs
2026-07-10  Mark Andrews[CVE-2026-10822] sec: usr: Malformed DNSKEY records...
2026-07-10  Nicki KřížekAdd dnssec_py/tests_rrsig_labels_signer: reject Labels...
2026-07-10  Ondřej SurýLimit DNSSEC denial proof validation per fetch
2026-07-10  Mark Andrews[CVE-2026-11331] sec: usr: Fix handling of rpz CNAME...
2026-07-10  Mark AndrewsPOC for PRIVATEDNS DNSKEY overrun not being detected
2026-07-10  Mark AndrewsTest RRSIG record parsing
2026-07-10  Mark AndrewsProperly handle rpz name to long wildcard expansion
2026-07-10  Mark AndrewsTest dst_algorithm_fromdata
2026-07-10  Mark AndrewsInvalid signed wildcard records were being accepted
2026-07-10  Mark AndrewsCheck rpz name too long wildcard CNAME expansion handling
2026-07-10  Mark AndrewsCheck that a short PRIVATEDNS record is rejected
2026-07-10  Mark AndrewsDon't sign out of zone records in dnssec-signzone
2026-07-10  Mark AndrewsFix TTL extraction from A/AAAA record
2026-07-10  Mark AndrewsMake it clearer that decompression is not allowed here
2026-07-10  Mark AndrewsFix dns_name_fromwire to honour the active region
2026-07-10  Mark AndrewsFix dst_algorithm_fromdata to set the active range
2026-07-10  Mark AndrewsFix the yaml query zone name code in dnstap-read
2026-07-10  Mark AndrewsFix EDNS Report Channel checking code
2026-07-10  Mark AndrewsCheck that dns_name_fromwire honours the active region
2026-07-09  Ondřej Surýfix: dev: Print the full OID in PRIVATEOID key comments
2026-07-09  Ondřej SurýPrint the full OID in PRIVATEOID key comments
2026-07-09  Ondřej Surýfix: dev: Fix a crash when resolving names below a...
2026-07-09  Ondřej SurýReference-count the DNAME zonecut headers
2026-07-09  Ondřej Surýchg: dev: Support larger DNSSEC keys and signatures 6198-isc_buffer_reserve-wraps-near-uint_max
2026-07-09  Ondřej SurýRemove the fixed DST_KEY_MAXSIZE limit from key parsing...
2026-07-09  Ondřej SurýSize RRSIG rdata buffers by the maximum rdata length
2026-07-09  Ondřej SurýSize DNSKEY rdata buffers by the maximum rdata length
2026-07-08  Matthijs Mekkingfix: usr: Don't synthesize negative responses with...
2026-07-08  Ondřej SurýCover exact-name NODATA synthesis from a pending NSEC
2026-07-08  Evan HuntMerge NSEC synthesis tests
2026-07-08  Alessio PoddaReproducer for #5887 out of zone NSEC-next syntheisis
2026-07-08  Alessio PoddaReproducer for #5872 cache pending synthesis
2026-07-08  Alessio PoddaReproducer for #5977 cache poison NSEC piggyback
2026-07-08  Evan HuntDon't synthesize negative responses with pending NSEC
2026-07-08  Colin Vidalfix: dev: Detect UTF-16 surrogates in `isc_utf8_valid()`
2026-07-08  Colin VidalAdd UTF-8 unit test
2026-07-08  Colin VidalDetect UTF-16 surrogates in `isc_utf8_valid()`
2026-07-08  Colin Vidalfix: dev: Remove ACL detach deadcode from dyndb
2026-07-08  Colin VidalRemove ACL detach deadcode from dyndb
2026-07-07  Ondřej Surýchg: dev: Mark the related slabheader as visited on...
2026-07-07  Ondřej SurýMark the related slabheader as visited on cache hit
2026-07-07  Arаm Sаrgsyаnfix: dev: Include the IPv6 address's brackets in the...
2026-07-07  Aram SargsyanInclude the brackets when parsing a URI with a IPv6...
2026-07-07  Arаm Sаrgsyаnfix: dev: Improve the input validation of the isc_url_p...
2026-07-07  Aram SargsyanLimit allowed URL/URI size to 8192 bytes in the parser
2026-07-07  Ondřej SurýAdd IPv6 and authority cases to the isc_url_t unit...
2026-07-07  Ondřej SurýExtend the isc_url_t unit test with RFC 3986 cases
2026-07-07  Aram SargsyanAdd a unit test for isc_url_t
2026-07-07  Aram SargsyanAdd a maximum length for isc_url_parse() input buffer
2026-07-07  Arаm Sаrgsyаnfix: dev: Fix PROXYv2 header size truncation bug
2026-07-07  Aram SargsyanAdd new proxyheader unit tests
2026-07-07  Aram SargsyanFix PROXYv2 header size truncation bug
2026-07-07  Matthijs Mekkingnew: test: Test multi-master dnssec-policy setup
2026-07-07  Matthijs MekkingTest multi-master dnssec-policy setup
2026-07-03  Evan Huntfix: usr: Unvalidated opt-out NSEC3 could be accepted... alessio/split-query-delegation-baseline
2026-07-03  Evan HuntMerge "nsec3_wrong_zone" into "dnssec_nsec3"
2026-07-03  Alessio PoddaReproducer for #5970 acceptance of unvalidated NSEC3
2026-07-03  Evan HuntUnvalidated opt-out NSEC3 could be accepted in insecuri...
2026-07-02  Ondřej Surýfix: usr: Fix DNSSEC validation failures for names...
2026-07-02  Ondřej SurýAdd a system test resolving through a signed apex DNAME
2026-07-02  Ondřej SurýRestrict the alias-chain deadlock check to chaining...
2026-07-02  Nicki Křížekfix: test: Support serving signed child zone from its...
2026-07-02  Nicki KřížekSupport serving signed child zone from its parent's...
2026-07-02  Michał Kępieńchg: test: Update AsyncDnsServer-related test cookbook...
2026-07-02  Michał KępieńMove ans.py-related information to README.md
2026-07-02  Michał KępieńUpdate AsyncDnsServer-related test cookbook parts
2026-07-02  Nicki Křížekchg: test: Unify system test key and algorithm handling
2026-07-02  Nicki KřížekMove algorithm definitions into a top-level isctest...
2026-07-02  Nicki KřížekAdd private_key support to all ZoneKey implementations
2026-07-02  Nicki KřížekReplace get_dnsalg() with kasp.Key.algorithm
2026-07-02  Nicki KřížekAdd NSEC3RSASHA1 to list of algorithms
2026-07-02  Nicki KřížekMove dnskey method from kasp.Key to zone.FileZoneKey
next