]>
git.ipfire.org Git - thirdparty/unbound.git/log
W.C.A. Wijngaards [Fri, 23 Oct 2020 10:10:30 +0000 (12:10 +0200)]
zonemd, unit test for unbound-control auth_zone_reload with zonemd.
W.C.A. Wijngaards [Fri, 23 Oct 2020 09:47:00 +0000 (11:47 +0200)]
zonemd, unbound-control auth_zone_reload errors when ZONEMD fails.
W.C.A. Wijngaards [Fri, 23 Oct 2020 09:44:28 +0000 (11:44 +0200)]
unbound-control auth_zone_reload sets zone to nonexpired and
also updates the xfr soa values from the new zonefile contents.
W.C.A. Wijngaards [Fri, 23 Oct 2020 09:20:08 +0000 (11:20 +0200)]
zonemd, zonemds are checked when a zone is auth_zone_reload from file,
or reload with unbound-control.
W.C.A. Wijngaards [Fri, 23 Oct 2020 08:14:21 +0000 (10:14 +0200)]
zonemd, unlock xfr lock for auth zone verify of zonemd for mesh new callback.
W.C.A. Wijngaards [Fri, 23 Oct 2020 07:12:51 +0000 (09:12 +0200)]
zonemd, unit test for auth zone zonemd axfr
zonemd, zonemds are checked after zone transfer.
W.C.A. Wijngaards [Thu, 22 Oct 2020 14:02:37 +0000 (16:02 +0200)]
zonemd, test for server start with zonemd from file.
W.C.A. Wijngaards [Thu, 22 Oct 2020 11:31:37 +0000 (13:31 +0200)]
zonemd, pass module stack as function argument.
W.C.A. Wijngaards [Thu, 22 Oct 2020 11:20:00 +0000 (13:20 +0200)]
zonemd, fix to harden against failure in pickup zonemd lookups.
W.C.A. Wijngaards [Thu, 22 Oct 2020 10:10:46 +0000 (12:10 +0200)]
zonemd, zonemds are checked at start
W.C.A. Wijngaards [Thu, 22 Oct 2020 07:49:27 +0000 (09:49 +0200)]
Merge branch 'master' into zonemd
W.C.A. Wijngaards [Thu, 22 Oct 2020 07:26:27 +0000 (09:26 +0200)]
- Fix that minimal-responses does not remove addresses from a priming
query response.
W.C.A. Wijngaards [Thu, 22 Oct 2020 06:47:40 +0000 (08:47 +0200)]
- Fix #333: Unbound Segmentation Fault w/ log_info Functions From
Python Mod.
George Thessalonikefs [Wed, 21 Oct 2020 15:44:04 +0000 (17:44 +0200)]
- Fix #320: potential memory corruption due to size miscomputation upton
custom region alloc init.
George Thessalonikefs [Wed, 21 Oct 2020 14:45:18 +0000 (16:45 +0200)]
- Fix #327: net/if.h check fails on some darwin versions; contribution by
Joshua Root.
W.C.A. Wijngaards [Wed, 21 Oct 2020 14:18:28 +0000 (16:18 +0200)]
zonemd, result of dnssec failures includes rrset and dnssec bogus reason.
W.C.A. Wijngaards [Wed, 21 Oct 2020 13:59:29 +0000 (15:59 +0200)]
zonemd, unit test remove debug.
W.C.A. Wijngaards [Wed, 21 Oct 2020 13:58:47 +0000 (15:58 +0200)]
zonemd, unit tests for verifying DNSKEY with trust anchor failures.
W.C.A. Wijngaards [Wed, 21 Oct 2020 13:04:06 +0000 (15:04 +0200)]
zonemd, unit tests for wrong NSEC RRSIGs.
W.C.A. Wijngaards [Wed, 21 Oct 2020 12:23:44 +0000 (14:23 +0200)]
zonemd, unit tests for DNSSEC type bitmaps.
W.C.A. Wijngaards [Wed, 21 Oct 2020 11:17:42 +0000 (13:17 +0200)]
zonemd, unit tests for wrong DNSSEC signatures.
W.C.A. Wijngaards [Wed, 21 Oct 2020 10:04:53 +0000 (12:04 +0200)]
zonemd, zonemd unit test in own file.
W.C.A. Wijngaards [Wed, 21 Oct 2020 09:56:41 +0000 (11:56 +0200)]
zonemd, fix that zonemd absence in unsigned zone does not invalidate zone.
W.C.A. Wijngaards [Wed, 21 Oct 2020 09:51:30 +0000 (11:51 +0200)]
zonemd, fix that dnssec denial does not invalidate zone.
zonemd, unit test of nsec and nsec3 denial.
W.C.A. Wijngaards [Wed, 21 Oct 2020 08:59:32 +0000 (10:59 +0200)]
Merge branch 'master' into zonemd
W.C.A. Wijngaards [Wed, 21 Oct 2020 08:56:51 +0000 (10:56 +0200)]
Add verbosity to debug occasional missing q1-10.example.net, from timer.
W.C.A. Wijngaards [Wed, 21 Oct 2020 08:35:47 +0000 (10:35 +0200)]
Changelog note for #228
- Merge PR #228 : infra-keep-probing option to probe hosts that are
down. Add infra-keep-probing: yes option. Hosts that are down are
probed more frequently.
With the option turned on, it probes about every 120 seconds,
eventually after exponential backoff, and that keeps that way. If
traffic keeps up for the domain. It probes with one at a time, eg.
one query is allowed to probe, other queries within that 120 second
interval are turned away.
Wouter Wijngaards [Wed, 21 Oct 2020 08:34:40 +0000 (10:34 +0200)]
Merge pull request #228 from NLnetLabs/infra-keep-probing
infra-keep-probing option to probe hosts that are down
W.C.A. Wijngaards [Wed, 21 Oct 2020 08:13:10 +0000 (10:13 +0200)]
Merge branch 'master' into infra-keep-probing
W.C.A. Wijngaards [Tue, 20 Oct 2020 14:49:49 +0000 (16:49 +0200)]
zonemd, unit test improved debug output and unit test dnssec verify zonemd
W.C.A. Wijngaards [Mon, 19 Oct 2020 14:26:22 +0000 (16:26 +0200)]
zonemd, unit test more zones.
George Thessalonikefs [Mon, 19 Oct 2020 13:10:17 +0000 (15:10 +0200)]
- Changelog entry for PR #324: Add modern X.509v3 extensions to
unbound-control TLS certificates, by James Renken.
George Thessalonikefs [Mon, 19 Oct 2020 13:04:15 +0000 (15:04 +0200)]
Merge branch 'master' of github.com:NLnetLabs/unbound
George Thessalonikefs [Mon, 19 Oct 2020 13:01:15 +0000 (15:01 +0200)]
Merge branch 'jprenken-master'; fixes #316.
George Thessalonikefs [Mon, 19 Oct 2020 13:00:30 +0000 (15:00 +0200)]
- Fix for attaching the X509v3 extensions to the client certificate.
W.C.A. Wijngaards [Mon, 19 Oct 2020 11:39:02 +0000 (13:39 +0200)]
- Clean the fix for out of order TCP processing limits on number
of queries. It was tested to work.
W.C.A. Wijngaards [Mon, 19 Oct 2020 11:36:53 +0000 (13:36 +0200)]
Fixup for clear of tcp handler structure.
W.C.A. Wijngaards [Mon, 19 Oct 2020 10:55:43 +0000 (12:55 +0200)]
- Fix to set the tcp handler event toggle flag back to default when
the handler structure is reused.
George Thessalonikefs [Mon, 19 Oct 2020 10:18:55 +0000 (12:18 +0200)]
Merge branch 'master' of https://github.com/jprenken/unbound into jprenken-master
W.C.A. Wijngaards [Mon, 19 Oct 2020 09:33:32 +0000 (11:33 +0200)]
Merge branch 'master' into zonemd
Ralph Dolmans [Mon, 19 Oct 2020 09:22:38 +0000 (11:22 +0200)]
Changelog entry for local-zone out of chunk regional allocation
Ralph Dolmans [Mon, 19 Oct 2020 09:21:30 +0000 (11:21 +0200)]
Merge pull request #329 from NLnetLabs/nochunk-region
local-zone regional allocations outside of chunk
W.C.A. Wijngaards [Mon, 19 Oct 2020 09:06:55 +0000 (11:06 +0200)]
- Log ip address when http session recv fails, eg. due to tls fail.
W.C.A. Wijngaards [Mon, 19 Oct 2020 08:59:41 +0000 (10:59 +0200)]
Unit test for doh downstream notls.
W.C.A. Wijngaards [Mon, 19 Oct 2020 08:43:35 +0000 (10:43 +0200)]
- Fix dnstap test to wait for log timer to see if queries are logged.
W.C.A. Wijngaards [Mon, 19 Oct 2020 08:41:03 +0000 (10:41 +0200)]
- Fix python documentation warning on functions.rst inplace_cb_reply.
W.C.A. Wijngaards [Mon, 19 Oct 2020 08:24:03 +0000 (10:24 +0200)]
- Fix #330: [Feature request] Add unencrypted DNS over HTTPS support.
This adds the option http-notls-downstream: yesno to change that,
and the dohclient test code has the -n option.
W.C.A. Wijngaards [Mon, 19 Oct 2020 08:14:40 +0000 (10:14 +0200)]
- Fix memory leak of https port string when reading config.
W.C.A. Wijngaards [Mon, 19 Oct 2020 07:06:33 +0000 (09:06 +0200)]
- Fix that http settings have colon in set_option, for
http-endpoint, http-max-streams, http-query-buffer-size,
http-response-buffer-size, and http-nodelay.
W.C.A. Wijngaards [Fri, 16 Oct 2020 15:26:58 +0000 (17:26 +0200)]
- Fix that the out of order TCP processing does not limit the
number of outstanding queries over a connection.
Ralph Dolmans [Fri, 16 Oct 2020 15:12:08 +0000 (17:12 +0200)]
- local-zone regional allocations outside of chunk to prevent large
chunk per small local-zone allocations.
W.C.A. Wijngaards [Fri, 16 Oct 2020 14:15:35 +0000 (16:15 +0200)]
zonemd, remove debug.
W.C.A. Wijngaards [Fri, 16 Oct 2020 14:09:13 +0000 (16:09 +0200)]
zonemd, unit tests for dnssec verify
George Thessalonikefs [Thu, 15 Oct 2020 13:53:16 +0000 (15:53 +0200)]
- Fix that if there are reply callbacks for the given rcode, those
are called per reply and a new message created if that was modified
by the call.
- Pass the comm_reply information to the inplace_cb_reply* functions
during the mesh state and update the documentation on that.
W.C.A. Wijngaards [Thu, 15 Oct 2020 10:27:22 +0000 (12:27 +0200)]
zonemd, unit test for dnssec verify, implement test.
W.C.A. Wijngaards [Thu, 15 Oct 2020 07:17:57 +0000 (09:17 +0200)]
zonemd, fix anchor unlock.
zonemd, unit test for dnssec verify function test harness.
W.C.A. Wijngaards [Thu, 15 Oct 2020 06:34:32 +0000 (08:34 +0200)]
Merge branch 'master' into zonemd
W.C.A. Wijngaards [Thu, 15 Oct 2020 06:22:42 +0000 (08:22 +0200)]
Changelog note for #326 and changes:
- DoH content length, simplify code, remove declaration after
statement and fix cast warning.
Wouter Wijngaards [Thu, 15 Oct 2020 06:19:37 +0000 (08:19 +0200)]
Merge pull request #326 from netblue30/master
DoH: implement content-length header field
netblue30 [Wed, 14 Oct 2020 15:32:14 +0000 (11:32 -0400)]
DoH: implement content-lenght header field
W.C.A. Wijngaards [Wed, 14 Oct 2020 12:52:32 +0000 (14:52 +0200)]
zonemd, nsec3 rr iterator is type int, like other nsec3 code.
W.C.A. Wijngaards [Wed, 14 Oct 2020 12:46:59 +0000 (14:46 +0200)]
zonemd, region freed, and qstate not used when not in a query, and nsec
and nsec3 bitmap checks.
W.C.A. Wijngaards [Wed, 14 Oct 2020 12:20:16 +0000 (14:20 +0200)]
- Free up auth zone parse region after use for lookup of host
W.C.A. Wijngaards [Wed, 14 Oct 2020 12:03:04 +0000 (14:03 +0200)]
- Fix that if there are on reply callbacks, those are called per
reply and a new message created if that was modified by the call.
W.C.A. Wijngaards [Wed, 14 Oct 2020 12:01:47 +0000 (14:01 +0200)]
- Fix that if there are on reply callbacks, those are called per
reply and a new message created if that was modified by the call.
W.C.A. Wijngaards [Wed, 14 Oct 2020 11:34:50 +0000 (13:34 +0200)]
zonemd, dnssec verification routines.
W.C.A. Wijngaards [Wed, 14 Oct 2020 08:06:28 +0000 (10:06 +0200)]
- Fix for python reply callback to see mesh state reply_list member,
it only removes it briefly for the commpoint call so that it does
not drop it and attempt to modify the reply list during reply.
W.C.A. Wijngaards [Tue, 13 Oct 2020 06:28:59 +0000 (08:28 +0200)]
- Fix #323: unbound testsuite fails on mock build in systemd-nspawn
if systemd support is build.
James Renken [Tue, 13 Oct 2020 05:06:20 +0000 (22:06 -0700)]
Add modern X.509v3 extensions to unbound-control TLS certificates
W.C.A. Wijngaards [Fri, 9 Oct 2020 14:47:49 +0000 (16:47 +0200)]
Formatting.
W.C.A. Wijngaards [Fri, 9 Oct 2020 14:46:20 +0000 (16:46 +0200)]
zonemd, routine to check zonemd hash if present
W.C.A. Wijngaards [Fri, 9 Oct 2020 13:14:27 +0000 (15:14 +0200)]
zonemd, defines for scheme and algorithm.
W.C.A. Wijngaards [Fri, 9 Oct 2020 13:05:46 +0000 (15:05 +0200)]
zonemd, doxygen comment fix.
W.C.A. Wijngaards [Fri, 9 Oct 2020 12:40:26 +0000 (14:40 +0200)]
zonemd, harden result length for unsupported algo in nettle digest final.
W.C.A. Wijngaards [Fri, 9 Oct 2020 12:32:24 +0000 (14:32 +0200)]
Merge branch 'master' into zonemd
W.C.A. Wijngaards [Fri, 9 Oct 2020 12:31:55 +0000 (14:31 +0200)]
- Fix warning in libnss compile, nss_buf2dsa is not used without DSA.
W.C.A. Wijngaards [Fri, 9 Oct 2020 12:30:56 +0000 (14:30 +0200)]
zonemd, libnss implementation and libnettle implementation. Both succeed
on unit tests.
W.C.A. Wijngaards [Fri, 9 Oct 2020 12:03:13 +0000 (14:03 +0200)]
zonemd, unit test, reorder test order
W.C.A. Wijngaards [Fri, 9 Oct 2020 11:59:44 +0000 (13:59 +0200)]
zonemd, unit test, tests the check routine and reason for failure.
W.C.A. Wijngaards [Fri, 9 Oct 2020 10:20:50 +0000 (12:20 +0200)]
zonemd, unit test, note example origins.
W.C.A. Wijngaards [Fri, 9 Oct 2020 10:18:25 +0000 (12:18 +0200)]
zonemd, unit test, succeeds at verifying examples of zonemd draft-12.
W.C.A. Wijngaards [Fri, 9 Oct 2020 09:19:31 +0000 (11:19 +0200)]
zonemd, digest code calls, secalgo openssl sha384 and sha512.
W.C.A. Wijngaards [Fri, 9 Oct 2020 07:01:52 +0000 (09:01 +0200)]
Merge branch 'master' into zonemd
W.C.A. Wijngaards [Fri, 9 Oct 2020 06:57:23 +0000 (08:57 +0200)]
- Fix dnstap socket and the chroot not applied properly to the dnstap
socket path.
W.C.A. Wijngaards [Thu, 8 Oct 2020 07:11:54 +0000 (09:11 +0200)]
- Fix #319: potential memory leak on config failure, in rpz config.
W.C.A. Wijngaards [Thu, 8 Oct 2020 07:09:55 +0000 (09:09 +0200)]
- Tag for 1.12.0 release.
- Current repo is version 1.12.1 in development.
W.C.A. Wijngaards [Tue, 6 Oct 2020 15:07:24 +0000 (17:07 +0200)]
zonemd, loop over zone and canonicalize data, test call in unit test.
W.C.A. Wijngaards [Tue, 6 Oct 2020 11:38:21 +0000 (13:38 +0200)]
test rr type parse inputs and print outputs.
W.C.A. Wijngaards [Tue, 6 Oct 2020 08:48:24 +0000 (10:48 +0200)]
Create branch zonemd
Add RR Type ZONEMD to RR definitions.
W.C.A. Wijngaards [Thu, 1 Oct 2020 07:11:22 +0000 (09:11 +0200)]
- Current repo is version 1.12.0 for release. Tag for 1.12.0rc1.
W.C.A. Wijngaards [Wed, 30 Sep 2020 12:55:35 +0000 (14:55 +0200)]
- Fix double loopexit for unbound-dnstap-socket after sigterm.
W.C.A. Wijngaards [Wed, 30 Sep 2020 09:43:46 +0000 (11:43 +0200)]
- Fix memory leak of edns tags at libunbound context delete.
W.C.A. Wijngaards [Wed, 30 Sep 2020 09:38:11 +0000 (11:38 +0200)]
- Easier kill of unbound-dnstap-socket tool in test.
W.C.A. Wijngaards [Wed, 30 Sep 2020 09:29:57 +0000 (11:29 +0200)]
- Fix stream_ssl, ssl_req_order and ssl_req_timeout tests for
alloc check debug output.
W.C.A. Wijngaards [Wed, 30 Sep 2020 09:21:24 +0000 (11:21 +0200)]
- Add dohclient test executable to gitignore.
W.C.A. Wijngaards [Wed, 30 Sep 2020 09:20:33 +0000 (11:20 +0200)]
- Fix doh tests when not compiled in.
Ralph Dolmans [Tue, 29 Sep 2020 12:07:38 +0000 (14:07 +0200)]
- DNS Flag Day 2020: change edns-buffer-size default to 1232.
W.C.A. Wijngaards [Tue, 29 Sep 2020 11:29:24 +0000 (13:29 +0200)]
- Fix unit test for dnstap changes, so that it waits for the timer.
Ralph Dolmans [Wed, 23 Sep 2020 12:35:51 +0000 (14:35 +0200)]
- Use inclusive language in configuration
W.C.A. Wijngaards [Wed, 23 Sep 2020 12:30:31 +0000 (14:30 +0200)]
- Fix to ifdef fptr wlist item for dnstap.