]>
git.ipfire.org Git - thirdparty/knot-resolver.git/log
Grigorii Demidov [Thu, 21 Jun 2018 12:42:08 +0000 (14:42 +0200)]
iterate: some special cases of transition to insecure zone
Petr Špaček [Mon, 25 Jun 2018 12:12:33 +0000 (14:12 +0200)]
Merge branch 'deckard-update' into 'master'
CI: support kresd-specific integration tests
See merge request knot/knot-resolver!541
Petr Špaček [Fri, 22 Jun 2018 15:05:46 +0000 (17:05 +0200)]
CI: workaround mangled timestamps in test jobs
Git sets file timestamp to the moment of checkout
while Gitlab copies gcda and gcno files in artefacts with timestamps
set to time of compilation in previous job. This leads to gcov/lcov
complaints about source timestamps being newer than profiling
timestampts etc.
Petr Špaček [Fri, 6 Apr 2018 17:53:26 +0000 (19:53 +0200)]
tests: support kresd-specific integration tests
Petr Špaček [Fri, 6 Apr 2018 12:37:55 +0000 (14:37 +0200)]
CI: clean up gitlab-ci.yml variables
Preparation for new integration tests.
Petr Špaček [Fri, 6 Apr 2018 07:18:13 +0000 (09:18 +0200)]
tests: integrate new Deckard test interface
Petr Špaček [Wed, 4 Apr 2018 12:41:23 +0000 (14:41 +0200)]
tests: split integration test to separate Makefile
This is preparation for more generic integration test framework.
Vladimír Čunát [Fri, 22 Jun 2018 09:26:51 +0000 (11:26 +0200)]
Merge !600: NSEC3 aggressive caching
Vladimír Čunát [Fri, 22 Jun 2018 09:14:00 +0000 (11:14 +0200)]
Merge branch 'master' into cache-NSEC3
Vladimír Čunát [Thu, 21 Jun 2018 10:18:55 +0000 (12:18 +0200)]
Merge !606: fix validation of explicit wildcard queries
Marek Vavruša [Mon, 18 Jun 2018 23:56:53 +0000 (16:56 -0700)]
nsec: correct wildcard proof check with queried for literal wildcard
The validation fails in current implementation when queried directly
for the wildcard. In that case the count of the common labels with the
NSEC record is the same, and not shorter by 1 (to accomodate wildcard
expansion).
Grigorii Demidov [Wed, 20 Jun 2018 10:28:12 +0000 (12:28 +0200)]
Merge branch 'http-allow-reuseport' into 'master'
http: allow all forks to process HTTP requests
See merge request knot/knot-resolver!406
Marek Vavruša [Tue, 6 Mar 2018 22:29:45 +0000 (14:29 -0800)]
modules/http: allow passing server options to http configuration
This allows HTTP server to start with reuseport, reuseaddr or v6only.
The reuseport allows running HTTP module on all forks, not just the main one.
Vladimír Čunát [Mon, 18 Jun 2018 10:00:31 +0000 (12:00 +0200)]
Merge !561: minor pack_t and nsrep refactoring
Marek Vavruša [Fri, 20 Apr 2018 03:15:19 +0000 (20:15 -0700)]
lib/generic/pack: switch to NULL on empty pack iterator
It's probably slightly safer to use NULL than end-array pointer,
so let's use it in this case. Significantly adapted by Vlada
from original Marek's change, after master fixed the corruption.
Marek Vavruša [Fri, 20 Apr 2018 03:54:36 +0000 (20:54 -0700)]
lib/nsrep: refactored copypasta
Vladimír Čunát [Mon, 18 Jun 2018 08:58:22 +0000 (10:58 +0200)]
cache: tiny nitpicks
Vladimír Čunát [Fri, 15 Jun 2018 16:47:39 +0000 (18:47 +0200)]
NEWS: add aggressive NSEC3
Vladimír Čunát [Fri, 15 Jun 2018 16:42:26 +0000 (18:42 +0200)]
Merge branch 'master' into cache-NSEC3
Vladimír Čunát [Fri, 15 Jun 2018 16:40:20 +0000 (18:40 +0200)]
reduce verbose logging - cases not really useful
Also tweak order of information when logging cache stash,
as it was rather unnatural.
Vladimír Čunát [Fri, 15 Jun 2018 15:31:41 +0000 (17:31 +0200)]
cache: more checks, comment cleanup
Vladimír Čunát [Fri, 15 Jun 2018 12:18:54 +0000 (14:18 +0200)]
cache: review stashing NSEC* parameters
Tomas Krizek [Fri, 15 Jun 2018 11:22:18 +0000 (13:22 +0200)]
Merge branch 'ci-docker' into 'master'
ci/Dockerfile.debian: use new respdiff git repo
See merge request knot/knot-resolver!602
Tomas Krizek [Fri, 15 Jun 2018 11:07:39 +0000 (13:07 +0200)]
ci/Dockerfile.debian: use new respdiff git repo
Vladimír Čunát [Fri, 15 Jun 2018 09:05:40 +0000 (11:05 +0200)]
cache: avoid potential out-of-bounds with NSEC3 params
It's possible the parser wouldn't let such RR through,
and it's most likely validator shouldn't let them through.
Even so, I feel better to check anyway.
Petr Špaček [Wed, 13 Jun 2018 16:15:00 +0000 (18:15 +0200)]
Merge branch 'tls-session-resumption' into 'master'
daemon/tls: session resumption with tickets (client & server side)
See merge request knot/knot-resolver!585
Vladimír Čunát [Wed, 13 Jun 2018 16:07:27 +0000 (18:07 +0200)]
cache find_leq_NSEC3: precise check for NSEC3 params
Vladimír Čunát [Wed, 13 Jun 2018 16:04:38 +0000 (18:04 +0200)]
cache: shorten repetitive `qry->flags` blocks
Vladimír Čunát [Wed, 13 Jun 2018 16:04:04 +0000 (18:04 +0200)]
cache entry_list_parse: squash a simple FIXME
Petr Špaček [Wed, 13 Jun 2018 15:54:56 +0000 (17:54 +0200)]
daemon/tls: disable session resumption with shared secret for now
There is no GnuTLS version which would make this safe.
See https://gitlab.com/gnutls/gnutls/issues/477
Vladimír Čunát [Tue, 12 Jun 2018 13:03:52 +0000 (15:03 +0200)]
opt-out nitpicks, eradicate kr_rank_test_noassert
Petr Špaček [Wed, 13 Jun 2018 14:00:01 +0000 (16:00 +0200)]
daemon/tls: add basic config tests
Petr Špaček [Wed, 13 Jun 2018 12:58:39 +0000 (14:58 +0200)]
daemon/tls: document limitations of the session key synchronization
Vladimír Čunát [Thu, 31 May 2018 11:51:03 +0000 (13:51 +0200)]
daemon/tls: work on server-side session tickets
Grigorii Demidov [Tue, 22 May 2018 08:21:19 +0000 (10:21 +0200)]
daemon/bindings: import tls session ticket key salt from file
Grigorii Demidov [Mon, 21 May 2018 15:55:35 +0000 (17:55 +0200)]
daemon/tls: session resumption with tickets (client & server side)
Vladimír Čunát [Tue, 12 Jun 2018 09:06:50 +0000 (11:06 +0200)]
separate most of code for retrieval from cache
api.c was growing too long.
Also a few other minor changes.
Vladimír Čunát [Mon, 11 Jun 2018 13:40:37 +0000 (15:40 +0200)]
WIP: minor code cleanups
Vladimír Čunát [Mon, 11 Jun 2018 08:14:47 +0000 (10:14 +0200)]
kr_rank_test*: avoid code duplication
Vladimír Čunát [Mon, 11 Jun 2018 07:58:16 +0000 (09:58 +0200)]
Merge branch 'master' into cache-NSEC3
Petr Špaček [Fri, 8 Jun 2018 13:19:41 +0000 (15:19 +0200)]
Merge branch 'tls-ciphers' into 'master'
restrict TLS ciphers
See merge request knot/knot-resolver!601
Vladimír Čunát [Fri, 8 Jun 2018 10:20:16 +0000 (12:20 +0200)]
daemon/tls: make gnutls_priority stricter
Otherwise CentOS 7 enables those two "ciphers" by default.
Noticed in #355.
Vladimír Čunát [Fri, 8 Jun 2018 10:19:02 +0000 (12:19 +0200)]
daemon/tls: don't segfault if gnutls_priority_* fails
Vladimír Čunát [Fri, 8 Jun 2018 09:57:11 +0000 (11:57 +0200)]
Merge remote-tracking branch 'o/master' into cache-NSEC3
Grigorii Demidov [Thu, 7 Jun 2018 09:27:11 +0000 (11:27 +0200)]
Merge branch 'policy_clear_ad' into 'master'
modules.policy: REFUSE, TC - clear AD flag in answers
See merge request knot/knot-resolver!599
Grigorii Demidov [Thu, 7 Jun 2018 09:02:14 +0000 (11:02 +0200)]
modules.policy: REFUSE, TC - clear AD flag in answers
Tomas Krizek [Thu, 7 Jun 2018 08:12:08 +0000 (10:12 +0200)]
Merge branch 'ci-epel-error' into 'master'
ci: make distro:epel-7 easier to debug in typical cases
See merge request knot/knot-resolver!598
Vladimír Čunát [Wed, 6 Jun 2018 15:53:01 +0000 (17:53 +0200)]
ci: make distro:epel-7 easier to debug in typical cases
Petr Špaček [Wed, 6 Jun 2018 13:32:14 +0000 (15:32 +0200)]
Merge branch 'tls-system-store' into 'master'
daemon/tls: use system CA with TLS_FORWARD policy
Closes #310
See merge request knot/knot-resolver!586
Petr Špaček [Mon, 4 Jun 2018 15:56:24 +0000 (17:56 +0200)]
daemon/tls: document new behavior
Grigorii Demidov [Tue, 22 May 2018 14:39:58 +0000 (16:39 +0200)]
daemon/tls: system CA's are used by default with TLS_FORWARD policy when ca_file parameter is omitted
Grigorii Demidov [Tue, 22 May 2018 09:15:33 +0000 (11:15 +0200)]
daemon/tls: use system CA with TLS_FORWARD policy
Grigorii Demidov [Tue, 5 Jun 2018 10:42:05 +0000 (12:42 +0200)]
Merge branch 'policy_REFUSE' into 'master'
Policy REFUSE; minot tweak
Closes #337
See merge request knot/knot-resolver!549
Petr Špaček [Tue, 10 Apr 2018 07:16:55 +0000 (09:16 +0200)]
kresd: improve error reporting if cache cannot be opened
For some weird reason kresd crashed on assert(false) if it cannot open
cache even though it handles this case properly without the assert.
Petr Špaček [Tue, 10 Apr 2018 07:15:38 +0000 (09:15 +0200)]
policy: add REFUSE policy
Fixes: #337
Grigorii Demidov [Thu, 31 May 2018 15:08:28 +0000 (17:08 +0200)]
Merge branch 'http-custom-endpoints' into 'master'
Allow creating custom endpoints in the HTTP module
See merge request knot/knot-resolver!527
Grigorii Demidov [Thu, 31 May 2018 10:28:33 +0000 (12:28 +0200)]
http: interface parameter check fix
Marek Vavruša [Tue, 27 Mar 2018 03:18:56 +0000 (20:18 -0700)]
http/prometheus: allow finalization of metrics table
This allows other modules to add or modify custom metrics or labels.
Marek Vavruša [Fri, 23 Mar 2018 18:20:36 +0000 (11:20 -0700)]
http/prometheus: allow custom namespaces
Marek Vavruša [Wed, 21 Mar 2018 22:57:19 +0000 (15:57 -0700)]
http: allow loading custom endpoints to http
Previously the module was created on configuration time, so it wasn't
possible to inject custom endpoints to the default interface.
Marek Vavruša [Wed, 21 Mar 2018 22:48:57 +0000 (15:48 -0700)]
bindings: always set AD=1 in internal queries just like real clients
The AD indicates validation request (but not request for DNSSEC records).
If the response can't be validated, resolver flips the AD to 0.
Tomas Krizek [Thu, 31 May 2018 13:45:04 +0000 (15:45 +0200)]
Merge branch 'packaging-update' into 'master'
distro: packaging updates
See merge request knot/knot-resolver!567
Tomas Krizek [Thu, 31 May 2018 13:31:22 +0000 (15:31 +0200)]
systemd: man page - update about system-kresd.slice
Tomas Krizek [Thu, 31 May 2018 13:23:23 +0000 (15:23 +0200)]
distro/rpm: handle systemd restarts in CentOS 7 compatible way
Tomas Krizek [Mon, 23 Apr 2018 15:59:23 +0000 (17:59 +0200)]
distro/rpm/knot-resolver.spec
Tomas Krizek [Mon, 23 Apr 2018 14:22:01 +0000 (16:22 +0200)]
distro/arch: add missing dependencies
Tomas Krizek [Mon, 23 Apr 2018 14:14:22 +0000 (16:14 +0200)]
distro/deb: remove obsolete dependencies libjansson and python3
Tomas Krizek [Mon, 23 Apr 2018 14:07:28 +0000 (16:07 +0200)]
distro/rpm: use Python3 to build doc
Tomas Krizek [Mon, 23 Apr 2018 14:06:50 +0000 (16:06 +0200)]
distro/*: remove obsolete memcached and redis dependency
Tomas Krizek [Mon, 23 Apr 2018 14:05:36 +0000 (16:05 +0200)]
distro/rpm: reformat spec file
Tomas Krizek [Mon, 23 Apr 2018 13:56:38 +0000 (15:56 +0200)]
distro/arch: reformat dependencies
Tomas Krizek [Mon, 23 Apr 2018 13:49:45 +0000 (15:49 +0200)]
distro/deb: reformat knot-resolver.dsc
Grigorii Demidov [Thu, 31 May 2018 07:26:01 +0000 (09:26 +0200)]
Merge branch 'lua-add-per-request-variables' into 'master'
daemon: allow per-request variables in Lua
See merge request knot/knot-resolver!533
Marek Vavruša [Wed, 28 Mar 2018 05:43:53 +0000 (22:43 -0700)]
daemon: allow per-request variables in Lua
The handlers in Lua can now store per-request variables that are automatically
GC'd when the request is finished. This is useful for stateful modules,
such as DNS64 that uses internal option flags for state tracking.
The layers can now get a variable table like so:
```
local vars = kres.request_t(r):vars()
vars.hello = true
```
The variables are persisted between different layers for each request.
Vladimír Čunát [Tue, 29 May 2018 11:15:46 +0000 (13:15 +0200)]
Merge branch 'nitpick-bugs' into 'master'
cache/entry_rr: fixed undefined behavior
See merge request knot/knot-resolver!595
Vladimír Čunát [Tue, 29 May 2018 11:11:40 +0000 (13:11 +0200)]
lib/cache: get rid of void-pointer arithmetic
Checked with -Wpointer-arith; still hindered by contrib/ucw.
Vladimír Čunát [Tue, 29 May 2018 09:44:15 +0000 (11:44 +0200)]
Merge pointer-arith changes into cache-NSEC3
Marek Vavruša [Tue, 29 May 2018 02:28:46 +0000 (19:28 -0700)]
cache/entry_rr: fixed undefined behavior
Pointer arithmetic with 'void *' is undefined, it only works as GNU extension.
Tomas Krizek [Mon, 28 May 2018 12:52:52 +0000 (14:52 +0200)]
Merge branch 'deb-cleanup' into 'master'
synchronize distro/deb with official debian packaging
See merge request knot/knot-resolver!593
Daniel Kahn Gillmor [Thu, 24 May 2018 17:31:53 +0000 (13:31 -0400)]
synchronize distro/deb with official debian packaging
Note that this is not an exact synchronization, just the salient parts
where i believe upstream wants to sync up with debian.
I've left alone indications of upstream package maintainership, and
I've left debhelper back at version 9, for example. and i've left the
differences between the shipped debian/kresd.conf (debian package
ships a minimal kresd.conf that doesn't load those four modules, in
particular).
Petr Špaček [Mon, 28 May 2018 10:49:16 +0000 (12:49 +0200)]
Merge branch 'doc-nitpicks' into 'master'
documentation nitpicks
See merge request knot/knot-resolver!592
Vladimír Čunát [Fri, 25 May 2018 14:07:39 +0000 (16:07 +0200)]
other docs nitpicks
I don't think it's good to write that we "provide a library",
as it currently doesn't seem suitable for usage outside kresd.
Vladimír Čunát [Thu, 24 May 2018 17:24:37 +0000 (19:24 +0200)]
policy, view: documentation nitpicks
It seems like implementation and docs got de-synchronized,
probably at some point very long ago (years).
Vladimír Čunát [Mon, 21 May 2018 08:57:17 +0000 (10:57 +0200)]
doc/build: refresh build-time requirements
Tomas Krizek [Fri, 25 May 2018 15:10:40 +0000 (17:10 +0200)]
Merge branch 'systemctl-start' into 'master'
doc: systemd -- clarify how to manually start all services.
See merge request knot/knot-resolver!591
Daniel Kahn Gillmor [Thu, 24 May 2018 15:01:22 +0000 (11:01 -0400)]
doc: systemd -- clarify how to manually start all services.
See https://github.com/systemd/systemd/issues/9080 for
details/discussion.
Tomas Krizek [Fri, 25 May 2018 14:48:15 +0000 (16:48 +0200)]
Merge branch 'ci-docker-update' into 'master'
ci: add pytest-xdist dependency for Deckard
See merge request knot/knot-resolver!590
Tomas Krizek [Fri, 25 May 2018 14:38:51 +0000 (16:38 +0200)]
ci: add pytest-xdist dependency for Deckard
Petr Špaček [Thu, 24 May 2018 17:06:09 +0000 (19:06 +0200)]
Merge branch 'endianness' into 'master'
handle htobe32 et al. on glibc systems with a non-Linux kernel
See merge request knot/knot-resolver!588
Daniel Kahn Gillmor [Thu, 24 May 2018 16:59:26 +0000 (12:59 -0400)]
handle htobe32 et al. on glibc systems with a non-Linux kernel
This fix copies over an updated #if clause from libknot's
src/contrib/endian.h.
This should resolve:
https://gitlab.labs.nic.cz/knot/knot-resolver/issues/348
See also discussion about this same problem in libknot from a couple
years ago:
https://bugs.debian.org/840460
I note that contrib/wire.h in knot-resolver is out of sync with
src/contrib/wire.h (and src/contrib/endian.h) from libknot. I don't
know whether there's any upstream preference for keeping these in sync
in some more reliable way than manual comparisons. For now i'm just
providing a narrow fix for the specific problem.
Petr Špaček [Sat, 19 May 2018 11:30:28 +0000 (13:30 +0200)]
Merge branch 'iter-minim-op' into 'master'
iterate: avoid turning off qname minimization in a case
Closes #339
See merge request knot/knot-resolver!584
Vladimír Čunát [Wed, 16 May 2018 11:59:06 +0000 (13:59 +0200)]
iterate: avoid turning off qname minimization in a case
Thanks to @ spakka for discovering this and authoring an earlier version
of this commit.
Vladimír Čunát [Wed, 16 May 2018 08:54:56 +0000 (10:54 +0200)]
Merge !576: validate: avoid incorrect downgrade of NS
Vladimír Čunát [Wed, 16 May 2018 08:19:48 +0000 (10:19 +0200)]
validate: be more careful with marking RRs as insecure
In case of referrals the authoritative server might add also another NS
record(s), and this might lead to downgrading the corresponding zones.
Regressed probably in
f0da0a35 !505.
Marek Vavruša [Tue, 1 May 2018 17:39:04 +0000 (10:39 -0700)]
improve verbose logs
Vladimír Čunát [Fri, 11 May 2018 16:13:09 +0000 (18:13 +0200)]
Merge branch 'master' into cache-NSEC3
Vladimír Čunát [Fri, 11 May 2018 16:11:47 +0000 (18:11 +0200)]
Merge !579: treewide: additional dname checks
Grigorii Demidov [Thu, 10 May 2018 12:16:53 +0000 (14:16 +0200)]
treewide: additional dname checks
Vladimír Čunát [Fri, 11 May 2018 15:29:31 +0000 (17:29 +0200)]
Merge !539: cleanup after knot minimal version bumps
Vladimír Čunát [Fri, 13 Apr 2018 16:09:31 +0000 (18:09 +0200)]
lua bindings: complete knot_pkt_t
We don't need the end, but I prefer to get rid of the exception,
as we now require libknot > 2.6 anyway and it only implies adding
a few more binding lines.