]> git.ipfire.org Git - thirdparty/knot-resolver.git/log
thirdparty/knot-resolver.git
5 years agoMerge branch 'doc-quickstart' into 'master' obs-knot-dns-deve-jq0xxt/deployments/473 obs-knot-dns-deve-jq0xxt/deployments/475 obs-knot-dns-deve-jq0xxt/deployments/477 obs-knot-dns-deve-jq0xxt/deployments/479 obs-knot-dns-deve-jq0xxt/deployments/481 obs-knot-dns-deve-jq0xxt/deployments/483 obs-knot-dns-deve-jq0xxt/deployments/485 obs-knot-dns-deve-jq0xxt/deployments/487 obs-knot-dns-deve-jq0xxt/deployments/489 obs-knot-dns-deve-jq0xxt/deployments/491 obs-knot-dns-deve-jq0xxt/deployments/493 obs-knot-dns-deve-jq0xxt/deployments/495 obs-knot-dns-deve-jq0xxt/deployments/497 obs-knot-dns-deve-jq0xxt/deployments/499 obs-knot-dns-deve-jq0xxt/deployments/501 obs-knot-resolver-es11k1/deployments/474 obs-knot-resolver-es11k1/deployments/476 obs-knot-resolver-es11k1/deployments/478 obs-knot-resolver-es11k1/deployments/480 obs-knot-resolver-es11k1/deployments/482 obs-knot-resolver-es11k1/deployments/484 obs-knot-resolver-es11k1/deployments/486 obs-knot-resolver-es11k1/deployments/488 obs-knot-resolver-es11k1/deployments/490 obs-knot-resolver-es11k1/deployments/492 obs-knot-resolver-es11k1/deployments/494 obs-knot-resolver-es11k1/deployments/496 obs-knot-resolver-es11k1/deployments/498 obs-knot-resolver-es11k1/deployments/500 obs-knot-resolver-es11k1/deployments/502
Petr Špaček [Mon, 23 Dec 2019 19:08:34 +0000 (20:08 +0100)] 
Merge branch 'doc-quickstart' into 'master'

Quick start documentation

Closes #500, #499, and #498

See merge request knot/knot-resolver!867

5 years agodocs: quick start guide: final polish
Petr Špaček [Mon, 23 Dec 2019 17:30:51 +0000 (18:30 +0100)] 
docs: quick start guide: final polish

5 years agodocs: quick start documentation third draft corrections
Ales Mrazek [Thu, 17 Oct 2019 11:52:17 +0000 (13:52 +0200)] 
docs: quick start documentation third draft corrections

5 years agodocs: quick start documentation third draft
Ales Mrazek [Mon, 7 Oct 2019 11:37:30 +0000 (13:37 +0200)] 
docs: quick start documentation third draft

5 years agodocs: apply suggestion to doc/startguide.rst
Ales Mrazek [Thu, 3 Oct 2019 08:02:52 +0000 (08:02 +0000)] 
docs: apply suggestion to doc/startguide.rst

5 years agodocs: quick start documentation second draft
Ales Mrazek [Mon, 30 Sep 2019 12:11:35 +0000 (14:11 +0200)] 
docs: quick start documentation second draft

5 years agodocs: quick start documentation first draft
Ales Mrazek [Wed, 11 Sep 2019 12:34:25 +0000 (14:34 +0200)] 
docs: quick start documentation first draft

5 years agoMerge branch 'freebind' into 'master' obs-knot-dns-deve-jq0xxt/deployments/467 obs-knot-dns-deve-jq0xxt/deployments/469 obs-knot-dns-deve-jq0xxt/deployments/471 obs-knot-resolver-es11k1/deployments/468 obs-knot-resolver-es11k1/deployments/470 obs-knot-resolver-es11k1/deployments/472
Petr Špaček [Fri, 20 Dec 2019 15:11:26 +0000 (16:11 +0100)] 
Merge branch 'freebind' into 'master'

daemon/network: add freebind support

See merge request knot/knot-resolver!898

5 years agotests: sanity check for net.listen() and net.list()
Petr Špaček [Fri, 20 Dec 2019 14:18:00 +0000 (15:18 +0100)] 
tests: sanity check for net.listen() and net.list()

5 years agomodules/http: fix net.listen in config tests
Tomas Krizek [Fri, 13 Dec 2019 14:32:29 +0000 (15:32 +0100)] 
modules/http: fix net.listen in config tests

5 years agotests/config: add freebind test
Tomas Krizek [Wed, 11 Dec 2019 17:09:46 +0000 (18:09 +0100)] 
tests/config: add freebind test

5 years agobindings/net: throw lua error ofr net.listen() failures
Tomas Krizek [Wed, 11 Dec 2019 17:07:01 +0000 (18:07 +0100)] 
bindings/net: throw lua error ofr net.listen() failures

To avoid configuration errors, throw a lua error and crash
if it's not possible to bind as specified in net.listen().

For special use-cases, freebind=true should be used instead.

5 years agodaemon/io: rename to family_to_freebind_option()
Tomas Krizek [Wed, 11 Dec 2019 15:30:06 +0000 (16:30 +0100)] 
daemon/io: rename to family_to_freebind_option()

5 years agodoc: document freebind option for net.listen()
Tomas Krizek [Fri, 29 Nov 2019 15:19:10 +0000 (16:19 +0100)] 
doc: document freebind option for net.listen()

5 years agodaemon/bindings: add freebind option to net.list()
Tomas Krizek [Fri, 29 Nov 2019 15:04:10 +0000 (16:04 +0100)] 
daemon/bindings: add freebind option to net.list()

5 years agodaemon/network: add freebind support
Tomas Krizek [Fri, 29 Nov 2019 14:24:17 +0000 (15:24 +0100)] 
daemon/network: add freebind support

5 years agoMerge branch '521-replace-lua-socket-depedency-with-lua-http' into 'master'
Petr Špaček [Fri, 20 Dec 2019 13:32:33 +0000 (14:32 +0100)] 
Merge branch '521-replace-lua-socket-depedency-with-lua-http' into 'master'

replace lua-socket depedency with lua-http

Closes #512 and #521

See merge request knot/knot-resolver!894

5 years agoprefill: fix timer restart
Petr Špaček [Thu, 19 Dec 2019 18:10:02 +0000 (19:10 +0100)] 
prefill: fix timer restart

event.reschedule() is not a good idea for long-running downloads and in
general I have a bad feeling that it did not work as intended even for
retries after errors.

5 years agodaemon/lua/kluautil.lua: remove from global namespace
Lukáš Ježek [Thu, 19 Dec 2019 13:15:56 +0000 (14:15 +0100)] 
daemon/lua/kluautil.lua: remove from global namespace

5 years agomodules/prefill and TA: Move https_fetch to daemon/lua/kluautil.lua
Lukáš Ježek [Thu, 19 Dec 2019 10:28:02 +0000 (11:28 +0100)] 
modules/prefill and TA: Move https_fetch to daemon/lua/kluautil.lua

5 years agopackages: fix dependencies
Lukáš Ježek [Tue, 17 Dec 2019 07:59:06 +0000 (08:59 +0100)] 
packages: fix dependencies

5 years agoCI ASAN: switch from gcc to clang
Vladimír Čunát [Mon, 16 Dec 2019 09:43:12 +0000 (10:43 +0100)] 
CI ASAN: switch from gcc to clang

Trying to avoid https://github.com/google/sanitizers/issues/1010

5 years agoUpdate NEWS and doc
Lukáš Ježek [Fri, 13 Dec 2019 12:06:57 +0000 (13:06 +0100)] 
Update NEWS and doc

5 years agopackages: remove lua-socket
Lukáš Ježek [Fri, 13 Dec 2019 12:00:37 +0000 (13:00 +0100)] 
packages: remove lua-socket

5 years agomodules/graphite: Use module 'cqueues.socket' instead 'socket'
Lukáš Ježek [Fri, 13 Dec 2019 11:24:36 +0000 (12:24 +0100)] 
modules/graphite: Use module 'cqueues.socket' instead 'socket'

5 years agomodules/policy: Use module 'cqueues.socket' instead 'socket'
Lukáš Ježek [Fri, 13 Dec 2019 11:07:15 +0000 (12:07 +0100)] 
modules/policy: Use module 'cqueues.socket' instead 'socket'

5 years agodaemon/lua: add kluautil.lua file for helpers functions
Lukáš Ježek [Fri, 13 Dec 2019 10:21:11 +0000 (11:21 +0100)] 
daemon/lua: add kluautil.lua file for helpers functions

5 years agopackages: remove lua-sec and add lua-http
Lukáš Ježek [Fri, 6 Dec 2019 13:19:44 +0000 (14:19 +0100)] 
packages: remove lua-sec and add lua-http

5 years agodaemon/lua/trust_anchors: Use module 'http.request' instead 'ssl.https'
Lukáš Ježek [Thu, 5 Dec 2019 14:42:34 +0000 (15:42 +0100)] 
daemon/lua/trust_anchors: Use module 'http.request' instead 'ssl.https'

5 years agomodules/prefill: support large zone file
Lukáš Ježek [Thu, 5 Dec 2019 09:35:16 +0000 (10:35 +0100)] 
modules/prefill: support large zone file

5 years agomodules/prefill: Add the functionality to specify a custom CA file
Lukáš Ježek [Tue, 3 Dec 2019 13:34:00 +0000 (14:34 +0100)] 
modules/prefill: Add the functionality to specify a custom CA file

5 years agomodules/prefill: Remove unused ltn12
Lukáš Ježek [Fri, 22 Nov 2019 15:18:51 +0000 (16:18 +0100)] 
modules/prefill: Remove unused ltn12

5 years agomodules/prefill: Fetch root zone file asynchronously
Lukáš Ježek [Fri, 22 Nov 2019 14:33:04 +0000 (15:33 +0100)] 
modules/prefill: Fetch root zone file asynchronously

5 years agomodules/prefill: Use module 'http.request' instead 'ssl.https'
Lukáš Ježek [Fri, 22 Nov 2019 14:27:04 +0000 (15:27 +0100)] 
modules/prefill: Use module 'http.request' instead 'ssl.https'

5 years agoMerge branch 'multiple-config-files' into 'master' obs-knot-dns-deve-jq0xxt/deployments/465 obs-knot-resolver-es11k1/deployments/466
Petr Špaček [Thu, 19 Dec 2019 09:06:29 +0000 (10:06 +0100)] 
Merge branch 'multiple-config-files' into 'master'

daemon/main: support multiple config files

See merge request knot/knot-resolver!909

5 years agoclarify errors from luaL_dofile while loading configs
Petr Špaček [Thu, 19 Dec 2019 08:51:44 +0000 (09:51 +0100)] 
clarify errors from luaL_dofile while loading configs

5 years agodaemon/main: remove "-" from config array
Tomas Krizek [Fri, 13 Dec 2019 15:40:35 +0000 (16:40 +0100)] 
daemon/main: remove "-" from config array

5 years agodaemon/main: log config path and workdir
Tomas Krizek [Wed, 11 Dec 2019 15:05:12 +0000 (16:05 +0100)] 
daemon/main: log config path and workdir

5 years agolib/utils: create get_workdir() utility function
Tomas Krizek [Wed, 11 Dec 2019 14:24:31 +0000 (15:24 +0100)] 
lib/utils: create get_workdir() utility function

5 years agodaemon/main: use engine_loadconf() for default config
Tomas Krizek [Wed, 11 Dec 2019 12:09:35 +0000 (13:09 +0100)] 
daemon/main: use engine_loadconf() for default config

5 years agodaemon/main: remove useless l_dosandboxfile macro
Tomas Krizek [Tue, 10 Dec 2019 18:22:16 +0000 (19:22 +0100)] 
daemon/main: remove useless l_dosandboxfile macro

The exact same function is implemented as luaL_dofile() in Lua 5.1,
there seems to be no reason to use our project-specific macro for it.

https://www.lua.org/manual/5.1/manual.html#luaL_dofile

5 years agodaemon/main: support multiple config files
Tomas Krizek [Tue, 10 Dec 2019 17:58:56 +0000 (18:58 +0100)] 
daemon/main: support multiple config files

5 years agoMerge branch '520-prefill-remove-depedency-on-lua-filesystem-lfs' into 'master' obs-knot-dns-deve-jq0xxt/deployments/463 obs-knot-resolver-es11k1/deployments/464
Petr Špaček [Wed, 18 Dec 2019 15:20:42 +0000 (16:20 +0100)] 
Merge branch '520-prefill-remove-depedency-on-lua-filesystem-lfs' into 'master'

prefill: remove depedency on lua-filesystem (lfs)

Closes #520

See merge request knot/knot-resolver!912

5 years agoprefill: remove depedency on lua-filesystem (lfs)
Lukáš Ježek [Wed, 18 Dec 2019 14:13:56 +0000 (15:13 +0100)] 
prefill: remove depedency on lua-filesystem (lfs)

5 years agoMerge branch 'ci-obs-buildall' into 'master' obs-knot-dns-deve-jq0xxt/deployments/448 obs-knot-dns-deve-jq0xxt/deployments/450 obs-knot-dns-deve-jq0xxt/deployments/452 obs-knot-dns-deve-jq0xxt/deployments/454 obs-knot-dns-deve-jq0xxt/deployments/457 obs-knot-dns-deve-jq0xxt/deployments/461 obs-knot-resolver-es11k1/deployments/449 obs-knot-resolver-es11k1/deployments/451 obs-knot-resolver-es11k1/deployments/453 obs-knot-resolver-es11k1/deployments/455 obs-knot-resolver-es11k1/deployments/458 obs-knot-resolver-es11k1/deployments/462
Tomas Krizek [Thu, 12 Dec 2019 16:27:46 +0000 (17:27 +0100)] 
Merge branch 'ci-obs-buildall' into 'master'

ci: allow failure of obs:build:all

See merge request knot/knot-resolver!910

5 years agoci: allow failure of obs:build:all
Tomas Krizek [Thu, 12 Dec 2019 16:20:40 +0000 (17:20 +0100)] 
ci: allow failure of obs:build:all

This job tends to fail very often, but very frequently due to issues
with OBS itself - outside of our control. The output of the job can
still be useful to check manually, e.g. before releases.

5 years agoci: document confusing allow_failure: false
Tomas Krizek [Thu, 12 Dec 2019 16:19:29 +0000 (17:19 +0100)] 
ci: document confusing allow_failure: false

This value seems to be the default, but it is important to have
it set explicitly, otherwise when: manual actions could be skipped

https://docs.gitlab.com/ee/ci/yaml/#whenmanual

5 years agoMerge branch 'lua_gc' into 'master'
Petr Špaček [Thu, 12 Dec 2019 14:27:37 +0000 (15:27 +0100)] 
Merge branch 'lua_gc' into 'master'

lua: stop trying to tweak lua's GC

See merge request knot/knot-resolver!201

5 years agolua: stop trying to tweak lua's GC
Tomas Krizek [Wed, 9 Oct 2019 12:29:28 +0000 (14:29 +0200)] 
lua: stop trying to tweak lua's GC

cherry-picked from f0ca89ac, original author Vlada Cunat

TL;DR: I believe all lua_gc() calls stemmed from misunderstanding lua
documentation, and the current settings seem potentially dangerous.

First, let me rely on lua 5.1 docs, as luajit 2 is documented to have
done only minor changes in the GC.
http://www.lua.org/manual/5.1/manual.html#lua_gc
http://wiki.luajit.org/New-Garbage-Collector#rationale

Commit 5a709411 claims to have increased the speed of GC to 400 % of
speed of allocation, but LUA_GCSETSTEPMUL is the parameter that
controls that, and that one was lowered to 99 % and later in
0ee2d1d7 even to 50 %.  Documentation explicitly says that setting
the value under 100 % may cause problems.

The default values seem perfectly sane to me and currently I can't see
any particular reason to change them.  It's 200 % relative GC speed,
and waiting for allocated size to double before starting another cycle.

I assume the resulting possibility of GC being too slow caused the need
to explicitly force a non-incremental GC cycle once in a while, but
that seems not useful anymore and not good for latency.

5 years agoMerge branch 'reuseport-freebsd' into 'master' obs-knot-dns-deve-jq0xxt/deployments/445 obs-knot-resolver-8xyvhu/deployments/447 obs-knot-resolver-es11k1/deployments/446
Petr Špaček [Wed, 11 Dec 2019 10:02:59 +0000 (11:02 +0100)] 
Merge branch 'reuseport-freebsd' into 'master'

daemon/io: use SO_REUSEPORT_LB if available (FreeBSD 12.0+)

See merge request knot/knot-resolver!907

5 years agodaemon/io: use SO_REUSEPORT_LB if available (FreeBSD 12.0+)
Vladimír Čunát [Tue, 10 Dec 2019 16:08:30 +0000 (17:08 +0100)] 
daemon/io: use SO_REUSEPORT_LB if available (FreeBSD 12.0+)

and don't use SO_REUSEPORT on non-Linux.  (Free)BSD has a different
meaning for it, which only brings confusion - only the last instance
would be getting packets.

5 years agoMerge branch 'tty-logging' into 'master'
Petr Špaček [Wed, 11 Dec 2019 09:48:22 +0000 (10:48 +0100)] 
Merge branch 'tty-logging' into 'master'

daemon/ tty commands: don't log unless --verbose

Closes #528

See merge request knot/knot-resolver!908

5 years agodaemon/ tty commands: don't log unless --verbose
Vladimír Čunát [Tue, 10 Dec 2019 17:04:15 +0000 (18:04 +0100)] 
daemon/ tty commands: don't log unless --verbose

It's minimalistic: no change if in interactive or --verbose mode.

5 years agoMerge branch 'systemd-instance' into 'master' obs-knot-dns-deve-jq0xxt/deployments/440 obs-knot-dns-deve-jq0xxt/deployments/442 obs-knot-resolver-es11k1/deployments/441 obs-knot-resolver-es11k1/deployments/443
Petr Špaček [Mon, 9 Dec 2019 15:44:02 +0000 (16:44 +0100)] 
Merge branch 'systemd-instance' into 'master'

systemd: add env variable SYSTEMD_INSTANCE

See merge request knot/knot-resolver!906

5 years agosystemd: add env variable SYSTEMD_INSTANCE
Tomas Krizek [Fri, 6 Dec 2019 15:20:12 +0000 (16:20 +0100)] 
systemd: add env variable SYSTEMD_INSTANCE

5 years agoMerge branch 'ci-update' into 'master' obs-knot-dns-deve-jq0xxt/deployments/433 obs-knot-dns-deve-jq0xxt/deployments/435 obs-knot-dns-deve-jq0xxt/deployments/437 obs-knot-resolver-es11k1/deployments/434 obs-knot-resolver-es11k1/deployments/436 obs-knot-resolver-es11k1/deployments/438
Tomas Krizek [Fri, 6 Dec 2019 15:00:50 +0000 (16:00 +0100)] 
Merge branch 'ci-update' into 'master'

ci: updates

See merge request knot/knot-resolver!905

5 years agoci: update respdiff jobs
Tomas Krizek [Fri, 6 Dec 2019 12:34:39 +0000 (13:34 +0100)] 
ci: update respdiff jobs

5 years agoci: allow odvr release in tag pipelines
Tomas Krizek [Fri, 6 Dec 2019 11:48:55 +0000 (12:48 +0100)] 
ci: allow odvr release in tag pipelines

5 years agoMerge branch 'release-4-3-0' into 'master' obs-knot-dns-deve-jq0xxt/deployments/428 obs-knot-dns-deve-jq0xxt/deployments/430 obs-knot-resolver-8xyvhu/deployments/427 obs-knot-resolver-es11k1/deployments/429 obs-knot-resolver-es11k1/deployments/431 obs-knot-resolver-kv62s6/deployments/426 v4.3.0
Tomas Krizek [Wed, 4 Dec 2019 14:28:25 +0000 (15:28 +0100)] 
Merge branch 'release-4-3-0' into 'master'

update NEWS, bump to 4.3.0

See merge request knot/knot-resolver!904

5 years agoupdate NEWS, bump to 4.3.0
Tomas Krizek [Wed, 4 Dec 2019 13:19:47 +0000 (14:19 +0100)] 
update NEWS, bump to 4.3.0

5 years agoMerge branch '518-confidential-issue' into 'master'
Tomas Krizek [Wed, 4 Dec 2019 13:59:21 +0000 (14:59 +0100)] 
Merge branch '518-confidential-issue' into 'master'

Resolve "RRset merge operation is too slow for big RRsets"

Closes #518

See merge request knot/knot-resolver!903

5 years agoNEWS: update obs-knot-resolver-bs4hbr/deployments/425
Tomas Krizek [Wed, 4 Dec 2019 13:41:16 +0000 (14:41 +0100)] 
NEWS: update

5 years agodoc: clarify upgrade instructions for modules
Petr Špaček [Wed, 4 Dec 2019 08:39:45 +0000 (09:39 +0100)] 
doc: clarify upgrade instructions for modules

5 years agolib/utils kr_ranked_rrarray_add(): clarify merging RRs
Vladimír Čunát [Thu, 21 Nov 2019 14:28:47 +0000 (15:28 +0100)] 
lib/utils kr_ranked_rrarray_add(): clarify merging RRs

5 years agoci: skip MacOS tests in security repo
Petr Špaček [Wed, 20 Nov 2019 15:05:08 +0000 (16:05 +0100)] 
ci: skip MacOS tests in security repo

5 years agoiterate: better efficiency on huge RRsets
Vladimír Čunát [Wed, 13 Nov 2019 13:07:46 +0000 (14:07 +0100)] 
iterate: better efficiency on huge RRsets

- written relatively defensively - act OK even if the API
  isn't used in an ideal way
- CI lint:scan-build: bump the error count;
  It's only another instance of the mis-detected array_push().
- the removed stale note in modules/meson.build isn't really related

5 years agoMerge branch 'cname-limit' into 'master'
Tomas Krizek [Wed, 4 Dec 2019 13:25:41 +0000 (14:25 +0100)] 
Merge branch 'cname-limit' into 'master'

iterate: fix limit on CNAME chain length

See merge request knot/knot-resolver!899

5 years agoci: skip Travis build for security repo
Petr Špaček [Wed, 4 Dec 2019 07:05:42 +0000 (08:05 +0100)] 
ci: skip Travis build for security repo

5 years agoiterate: clarify error messages about CNAME chains
Petr Špaček [Tue, 3 Dec 2019 14:09:47 +0000 (15:09 +0100)] 
iterate: clarify error messages about CNAME chains

5 years agoiterate: tests for CNAME chain restrictions
Vladimír Čunát [Mon, 2 Dec 2019 15:00:40 +0000 (16:00 +0100)] 
iterate: tests for CNAME chain restrictions

5 years agoiterate: reduce CNAME length limit: 40 -> 13
Vladimír Čunát [Fri, 29 Nov 2019 16:03:41 +0000 (17:03 +0100)] 
iterate: reduce CNAME length limit: 40 -> 13

Unbound has limit 10, and practically useful numbers are way lower.

5 years agoiterate: fix limit on CNAME chain length
Vladimír Čunát [Fri, 29 Nov 2019 15:15:10 +0000 (16:15 +0100)] 
iterate: fix limit on CNAME chain length

The accounting was just broken and overly messy anyway.

5 years agoMerge !896: daemon: support dropping capabilities obs-knot-resolver-bs4hbr/deployments/424
Vladimír Čunát [Wed, 4 Dec 2019 09:57:18 +0000 (10:57 +0100)] 
Merge !896: daemon: support dropping capabilities

5 years agoNEWS: mention dropping capabilities
Tomas Krizek [Wed, 27 Nov 2019 14:08:11 +0000 (15:08 +0100)] 
NEWS: mention dropping capabilities

5 years agodistro/*: add libcap-ng dependency
Tomas Krizek [Wed, 27 Nov 2019 14:03:51 +0000 (15:03 +0100)] 
distro/*: add libcap-ng dependency

5 years agosystemd/nosocket: use capabilities
Tomas Krizek [Wed, 27 Nov 2019 11:55:06 +0000 (12:55 +0100)] 
systemd/nosocket: use capabilities

5 years agodaemon/main: add libcap-ng support to drop capabilities
Tomas Krizek [Tue, 26 Nov 2019 11:37:45 +0000 (12:37 +0100)] 
daemon/main: add libcap-ng support to drop capabilities

5 years agoMerge branch 'perf-lua-ffi_cleaned' into 'master' obs-knot-dns-deve-jq0xxt/deployments/420 obs-knot-dns-deve-jq0xxt/deployments/422 obs-knot-resolver-es11k1/deployments/421 obs-knot-resolver-es11k1/deployments/423
Petr Špaček [Mon, 2 Dec 2019 12:55:10 +0000 (13:55 +0100)] 
Merge branch 'perf-lua-ffi_cleaned' into 'master'

performance: lua-related improvements

See merge request knot/knot-resolver!874

5 years agomodules/ta_signal_query: optimize
Vladimír Čunát [Wed, 14 Aug 2019 15:16:58 +0000 (17:16 +0200)] 
modules/ta_signal_query: optimize

Basically the same as the parent commit (just much simpler).

5 years agomodules/ta_sentinel: optimize
Vladimír Čunát [Wed, 14 Aug 2019 14:53:23 +0000 (16:53 +0200)] 
modules/ta_sentinel: optimize

When all lua modules get unloaded, this change makes the module's
contribution to QPS unmeasurable (for me), saving a few percent.
The point is to almost always return very cheaply, in particular without
creating any lua GC object (like FFI for kr_query).

Note: some checks didn't make much sense, so I improved those as well.

5 years agomodules/policy: optimize special domain processing
Vladimír Čunát [Mon, 12 Aug 2019 14:08:37 +0000 (16:08 +0200)] 
modules/policy: optimize special domain processing

Running the full special-domain checks is relatively expensive.

5 years agomodules/policy: optimize postrules
Vladimír Čunát [Wed, 31 Jul 2019 13:55:43 +0000 (15:55 +0200)] 
modules/policy: optimize postrules

I've never seen anyone use postrules.

5 years agolua FFI: avoid frequent usage of lua_pushpointer()
Vladimír Čunát [Wed, 7 Aug 2019 07:36:13 +0000 (09:36 +0200)] 
lua FFI: avoid frequent usage of lua_pushpointer()

The new way of transitioning to layer callbacks - done because of
portability (mainly to aarch64) - is a bit expensive.  This is a simple
way of recovering that cost.  Merge 603a24f regressed speed a bit.

5 years agoMerge branch 'packaging-fixes' into 'master' obs-knot-dns-deve-jq0xxt/deployments/412 obs-knot-dns-deve-jq0xxt/deployments/414 obs-knot-dns-deve-jq0xxt/deployments/416 obs-knot-dns-deve-jq0xxt/deployments/418 obs-knot-resolver-es11k1/deployments/413 obs-knot-resolver-es11k1/deployments/415 obs-knot-resolver-es11k1/deployments/417 obs-knot-resolver-es11k1/deployments/419
Petr Špaček [Thu, 28 Nov 2019 09:06:17 +0000 (10:06 +0100)] 
Merge branch 'packaging-fixes' into 'master'

Packaging fixes

See merge request knot/knot-resolver!895

5 years agosystemd: add proper User/Group
Tomas Krizek [Wed, 27 Nov 2019 11:46:06 +0000 (12:46 +0100)] 
systemd: add proper User/Group

The Group= settings was ommited and default group of User= was
implicitly used. Now the group set at build time is respected.

GC didn't respect the user/group set at build time at all.

5 years agodistro/*: http module requires the same knot-resolver version
Tomas Krizek [Tue, 26 Nov 2019 11:58:02 +0000 (12:58 +0100)] 
distro/*: http module requires the same knot-resolver version

Previously, it was possible to update just "knot-resolver" even
when the "knot-resolver-module-http" package was installed, or the
other way around.

5 years agoMerge branch 'ci-timeout' into 'master' obs-knot-dns-deve-jq0xxt/deployments/410 obs-knot-resolver-es11k1/deployments/411
Tomas Krizek [Wed, 27 Nov 2019 14:57:22 +0000 (15:57 +0100)] 
Merge branch 'ci-timeout' into 'master'

ci: increase test timeout

See merge request knot/knot-resolver!897

5 years agoci: increase test timeout
Tomas Krizek [Wed, 27 Nov 2019 14:43:54 +0000 (15:43 +0100)] 
ci: increase test timeout

During heavy load, test:valgrind tends to fail quite often with timeout.
This should improve the situation.

5 years agoMerge branch 'packaging-docs' into 'master' obs-knot-dns-deve-jq0xxt/deployments/386 obs-knot-dns-deve-jq0xxt/deployments/388 obs-knot-dns-deve-jq0xxt/deployments/392 obs-knot-dns-deve-jq0xxt/deployments/394 obs-knot-dns-deve-jq0xxt/deployments/396 obs-knot-dns-deve-jq0xxt/deployments/399 obs-knot-dns-deve-jq0xxt/deployments/404 obs-knot-resolver-bs4hbr/deployments/385 obs-knot-resolver-es11k1/deployments/387 obs-knot-resolver-es11k1/deployments/389 obs-knot-resolver-es11k1/deployments/393 obs-knot-resolver-es11k1/deployments/395 obs-knot-resolver-es11k1/deployments/397 obs-knot-resolver-es11k1/deployments/400 obs-knot-resolver-es11k1/deployments/405
Petr Špaček [Wed, 20 Nov 2019 12:42:51 +0000 (12:42 +0000)] 
Merge branch 'packaging-docs' into 'master'

tests: packaging

See merge request knot/knot-resolver!892

5 years agotests: packaging
Lukáš Ježek [Mon, 18 Nov 2019 11:16:42 +0000 (12:16 +0100)] 
tests: packaging

Directory with subdirectory "packaging" is called "component".

List all components: python3 tests/packaging-doc.py --list
Run all tests/compoments: python3 tests/packaging-doc.py
Run specific test/component: python3 tests/packaging-doc.py --test <component>

The file structure for 1 component:
daemon - dependencies for 1 component "kresd daemon" (default component, must always be there)
scripts/distros - dependencies for 1 component for specific distro (must always be there)
scripts/dockerfile_gen.py - test Dockerfile generator, see below
tests/packaging.py - script to generate and build all combinations
                     of Docker files for all components
[component] - directory of component/test, see below
      (e.g. "client/packaging/", "modules/http/packaging/" etc.)

The file structure of each component:
[component]
<distro>/<version> - package names
- builddeps - list of build depedencies
- rundeps - list of runtime depedencies
- pre-build.sh - script called before build phase
- post-build.sh - script called after build phase
- pre-run.sh - script called before run phase
- post-run.sh - script called after run phase
- install.sh and build.sh script called during build phase
test.config or test.sh - kresd config test or shell script
note: content of "scripts/distroos" is same as "<distro>/<version>" of component.

There are "build" and "run" phases. "build" phase precedes "run" phase.
All script are called in this order:
1. pre-<phase>.sh
2. install packages specifed in the file "<phase>deps"
3a. for "build" phase: run build.sh and install.sh
3b. for "run" phase: run 'kresd -c [component]/test.config' or config.sh
4. remove packages specified in the file "<phase>deps"
5. post-<phase>.sh

Each step above is combines base components with a component under test.
E.g. component "scripts/distros" always precedes component "daemon/packaging"
and it precedes the tested component e.g. "modules/http".

In long term we might migrate this to py.test or some other well known
framework.

5 years agoMerge branch 'doh_decrypt' into 'master'
Tomas Krizek [Wed, 20 Nov 2019 12:19:11 +0000 (12:19 +0000)] 
Merge branch 'doh_decrypt' into 'master'

DoH debugging: auxiliary library for OpenSSL key logging

See merge request knot/knot-resolver!886

5 years agodistro/rpm: fix opensuse build
Tomas Krizek [Wed, 20 Nov 2019 10:45:42 +0000 (11:45 +0100)] 
distro/rpm: fix opensuse build

opensslkey_debug is never built for opensuse, because
openssl is not a dependency, thus there's no need to remove
the non-existent file.

5 years agodog debug: ignore -Wpedantic to unblock CI
Vladimír Čunát [Wed, 23 Oct 2019 13:18:51 +0000 (15:18 +0200)] 
dog debug: ignore -Wpedantic to unblock CI

It would be cumbersome to explicitly cast all those void*
to correct function types.

5 years agodoh debug: do not build debug_opensslkeylog if openssl is missing
Petr Špaček [Wed, 23 Oct 2019 11:34:08 +0000 (13:34 +0200)] 
doh debug: do not build debug_opensslkeylog if openssl is missing

5 years agoci: add openssl devel package for http module debug library
Petr Špaček [Tue, 22 Oct 2019 14:08:08 +0000 (16:08 +0200)] 
ci: add openssl devel package for http module debug library

5 years agodoh debug: add depedency on openssl to meson build
Petr Špaček [Tue, 22 Oct 2019 13:04:38 +0000 (15:04 +0200)] 
doh debug: add depedency on openssl to meson build

5 years agodoh debug: package debug_opensslkeylog.so
Petr Špaček [Tue, 22 Oct 2019 12:57:03 +0000 (14:57 +0200)] 
doh debug: package debug_opensslkeylog.so

5 years agodoh debug: log timestamp of each OPENSSLKEYLOGFILE opening
Petr Špaček [Tue, 22 Oct 2019 11:30:47 +0000 (13:30 +0200)] 
doh debug: log timestamp of each OPENSSLKEYLOGFILE opening

Wireshark 3.0.5 is able to deal with # comments in middle of log file.

5 years agodoh debug: create OPENSSLKEYLOGFILE accessible only by process owner
Petr Špaček [Tue, 22 Oct 2019 11:26:39 +0000 (13:26 +0200)] 
doh debug: create OPENSSLKEYLOGFILE accessible only by process owner

5 years agodoh debug: log timestamp of OPENSSLKEYLOGFILE creation
Petr Špaček [Tue, 22 Oct 2019 11:26:04 +0000 (13:26 +0200)] 
doh debug: log timestamp of OPENSSLKEYLOGFILE creation