]> git.ipfire.org Git - thirdparty/knot-resolver.git/log
thirdparty/knot-resolver.git
15 months agogitlab-ci: docs - breathe docs-fix
Oto Šťáva [Wed, 17 Apr 2024 08:26:07 +0000 (10:26 +0200)] 
gitlab-ci: docs - breathe

15 months agoMerge branch 'website-push-docs' into 'master' docs-develop-mast-tzgd0f/deployments/3798 docs-develop-mast-tzgd0f/deployments/3812 docs-develop-mast-tzgd0f/deployments/3815 docs-develop-mast-tzgd0f/deployments/3830 docs-develop-mast-tzgd0f/deployments/3833 docs-develop-mast-tzgd0f/deployments/3845 docs-develop-mast-tzgd0f/deployments/3848 docs-develop-mast-tzgd0f/deployments/3851 docs-develop-mast-tzgd0f/deployments/3854 docs-develop-mast-tzgd0f/deployments/3855 docs-develop-mast-tzgd0f/deployments/3858 docs-develop-mast-tzgd0f/deployments/3863 docs-develop-mast-tzgd0f/deployments/3866 docs-develop-mast-tzgd0f/deployments/3871 docs-develop-mast-tzgd0f/deployments/3874 docs-develop-mast-tzgd0f/deployments/3880 docs-develop-mast-tzgd0f/deployments/3883 docs-develop-mast-tzgd0f/deployments/3897 docs-develop-mast-tzgd0f/deployments/3900 docs-develop-mast-tzgd0f/deployments/3905 docs-develop-mast-tzgd0f/deployments/3908 docs-develop-mast-tzgd0f/deployments/3909 docs-develop-mast-tzgd0f/deployments/3912 docs-develop-mast-tzgd0f/deployments/3913 docs-develop-mast-tzgd0f/deployments/3916 docs-develop-mast-tzgd0f/deployments/3925 docs-develop-mast-tzgd0f/deployments/3928 docs-develop-mast-tzgd0f/deployments/3944 docs-develop-mast-tzgd0f/deployments/3947 docs-develop-mast-tzgd0f/deployments/3951 docs-develop-mast-tzgd0f/deployments/3954 docs-develop-nigh-589znp/deployments/3813 docs-develop-nigh-589znp/deployments/3831 docs-develop-nigh-589znp/deployments/3846 docs-develop-nigh-589znp/deployments/3852 docs-develop-nigh-589znp/deployments/3856 docs-develop-nigh-589znp/deployments/3864 docs-develop-nigh-589znp/deployments/3872 docs-develop-nigh-589znp/deployments/3881 docs-develop-nigh-589znp/deployments/3898 docs-develop-nigh-589znp/deployments/3906 docs-develop-nigh-589znp/deployments/3910 docs-develop-nigh-589znp/deployments/3914 docs-develop-nigh-589znp/deployments/3926 docs-develop-nigh-589znp/deployments/3945 docs-develop-nigh-589znp/deployments/3952 obs-knot-resolver-es11k1/deployments/3803 obs-knot-resolver-es11k1/deployments/3814 obs-knot-resolver-es11k1/deployments/3832 obs-knot-resolver-es11k1/deployments/3847 obs-knot-resolver-es11k1/deployments/3853 obs-knot-resolver-es11k1/deployments/3857 obs-knot-resolver-es11k1/deployments/3865 obs-knot-resolver-es11k1/deployments/3873 obs-knot-resolver-es11k1/deployments/3882 obs-knot-resolver-es11k1/deployments/3899 obs-knot-resolver-es11k1/deployments/3907 obs-knot-resolver-es11k1/deployments/3911 obs-knot-resolver-es11k1/deployments/3915 obs-knot-resolver-es11k1/deployments/3927 obs-knot-resolver-es11k1/deployments/3946 obs-knot-resolver-es11k1/deployments/3953
Oto Šťáva [Tue, 16 Apr 2024 13:38:58 +0000 (15:38 +0200)] 
Merge branch 'website-push-docs' into 'master'

gitlab-ci: push docs to the website (manual CI)

See merge request knot/knot-resolver!1530

15 months agogitlab-ci: push docs to the website (manual CI) docs-develop-webs-khkalp/deployments/3739
Oto Šťáva [Wed, 10 Apr 2024 10:43:11 +0000 (12:43 +0200)] 
gitlab-ci: push docs to the website (manual CI)

15 months agoMerge branch 'nits' into 'master' docs-develop-mast-tzgd0f/deployments/3735 docs-develop-mast-tzgd0f/deployments/3754 docs-develop-mast-tzgd0f/deployments/3757 docs-develop-mast-tzgd0f/deployments/3769 docs-develop-mast-tzgd0f/deployments/3772 docs-develop-mast-tzgd0f/deployments/3773 docs-develop-mast-tzgd0f/deployments/3776 docs-develop-mast-tzgd0f/deployments/3777 docs-develop-mast-tzgd0f/deployments/3780 docs-develop-mast-tzgd0f/deployments/3781 docs-develop-mast-tzgd0f/deployments/3784 docs-develop-mast-tzgd0f/deployments/3789 docs-develop-mast-tzgd0f/deployments/3792 docs-develop-nigh-589znp/deployments/3755 docs-develop-nigh-589znp/deployments/3770 docs-develop-nigh-589znp/deployments/3774 docs-develop-nigh-589znp/deployments/3778 docs-develop-nigh-589znp/deployments/3782 docs-develop-nigh-589znp/deployments/3790 obs-knot-resolver-es11k1/deployments/3756 obs-knot-resolver-es11k1/deployments/3771 obs-knot-resolver-es11k1/deployments/3775 obs-knot-resolver-es11k1/deployments/3779 obs-knot-resolver-es11k1/deployments/3783 obs-knot-resolver-es11k1/deployments/3791
Oto Šťáva [Wed, 10 Apr 2024 11:09:36 +0000 (13:09 +0200)] 
Merge branch 'nits' into 'master'

nits: unused variable, improved #include path

See merge request knot/knot-resolver!1529

15 months agolib/dnssec nit: improve #include path docs-develop-nits-2dntdj/deployments/3711 docs-develop-nits-2dntdj/deployments/3734
Vladimír Čunát [Mon, 8 Apr 2024 08:52:01 +0000 (10:52 +0200)] 
lib/dnssec nit: improve #include path

The issue was exposed when working on rrl-wip branch:
  lib/dnssec/nsec.c:19:10: fatal error: resolve.h: No such file or director

15 months agodaemon/engine nit: drop an unused variable
Vladimír Čunát [Wed, 27 Mar 2024 08:21:41 +0000 (09:21 +0100)] 
daemon/engine nit: drop an unused variable

Reported by clang.

15 months agoMerge branch 'shared-libkres-fix' into 'master' docs-develop-mast-tzgd0f/deployments/3692 docs-develop-mast-tzgd0f/deployments/3695 docs-develop-mast-tzgd0f/deployments/3698 docs-develop-mast-tzgd0f/deployments/3699 docs-develop-mast-tzgd0f/deployments/3702 docs-develop-mast-tzgd0f/deployments/3703 docs-develop-mast-tzgd0f/deployments/3706 docs-develop-mast-tzgd0f/deployments/3715 docs-develop-mast-tzgd0f/deployments/3718 docs-develop-mast-tzgd0f/deployments/3721 docs-develop-mast-tzgd0f/deployments/3724 docs-develop-nigh-589znp/deployments/3696 docs-develop-nigh-589znp/deployments/3700 docs-develop-nigh-589znp/deployments/3704 docs-develop-nigh-589znp/deployments/3716 docs-develop-nigh-589znp/deployments/3722 obs-knot-resolver-es11k1/deployments/3697 obs-knot-resolver-es11k1/deployments/3701 obs-knot-resolver-es11k1/deployments/3705 obs-knot-resolver-es11k1/deployments/3717 obs-knot-resolver-es11k1/deployments/3723
Oto Šťáva [Fri, 5 Apr 2024 10:22:56 +0000 (12:22 +0200)] 
Merge branch 'shared-libkres-fix' into 'master'

daemon/meson.build: add install_rpath to kresd

See merge request knot/knot-resolver!1528

15 months agodaemon/meson.build: add install_rpath to kresd docs-develop-shar-t8zrsp/deployments/3691
Oto Šťáva [Fri, 5 Apr 2024 09:57:22 +0000 (11:57 +0200)] 
daemon/meson.build: add install_rpath to kresd

This fixes the default use-case for developers when they put their
install prefix somewhere where the system `LD_LIBRARY_PATH` does not
point. Before this, `kresd` would fail to start after `ninja install`
because it would not be able to find the `libkres.so` library.

The original workaround to this was to use `meson configure
-Ddefault_library=static`, but firstly, we would like it to be working
with the default settings, and secondly, we would like to have it as
similar to what most users will encounter as possible.

16 months agoMerge branch 'release-5.7.2' into 'master' docs-develop-mast-tzgd0f/deployments/3615 docs-develop-mast-tzgd0f/deployments/3625 docs-develop-mast-tzgd0f/deployments/3628 docs-develop-mast-tzgd0f/deployments/3633 docs-develop-mast-tzgd0f/deployments/3636 docs-develop-mast-tzgd0f/deployments/3637 docs-develop-mast-tzgd0f/deployments/3640 docs-develop-mast-tzgd0f/deployments/3641 docs-develop-mast-tzgd0f/deployments/3643 docs-develop-mast-tzgd0f/deployments/3646 docs-develop-mast-tzgd0f/deployments/3647 docs-develop-mast-tzgd0f/deployments/3650 docs-develop-mast-tzgd0f/deployments/3664 docs-develop-mast-tzgd0f/deployments/3667 docs-develop-mast-tzgd0f/deployments/3676 docs-develop-mast-tzgd0f/deployments/3679 docs-develop-mast-tzgd0f/deployments/3684 docs-develop-mast-tzgd0f/deployments/3687 docs-develop-nigh-589znp/deployments/3626 docs-develop-nigh-589znp/deployments/3634 docs-develop-nigh-589znp/deployments/3638 docs-develop-nigh-589znp/deployments/3642 docs-develop-nigh-589znp/deployments/3644 docs-develop-nigh-589znp/deployments/3648 docs-develop-nigh-589znp/deployments/3665 docs-develop-nigh-589znp/deployments/3677 docs-develop-nigh-589znp/deployments/3685 docs-develop-stab-lrl9qw/deployments/3983 docs-release-stab-12mrv9/deployments/3981 docs-release-v5-7-c2cdq1/deployments/3618 obs-knot-resolver-8xyvhu/deployments/3619 obs-knot-resolver-es11k1/deployments/3627 obs-knot-resolver-es11k1/deployments/3635 obs-knot-resolver-es11k1/deployments/3639 obs-knot-resolver-es11k1/deployments/3645 obs-knot-resolver-es11k1/deployments/3649 obs-knot-resolver-es11k1/deployments/3666 obs-knot-resolver-es11k1/deployments/3678 obs-knot-resolver-es11k1/deployments/3686 obs-knot-resolver-kv62s6/deployments/3617 v5.7.2
Aleš Mrázek [Wed, 27 Mar 2024 16:38:30 +0000 (17:38 +0100)] 
Merge branch 'release-5.7.2' into 'master'

Release 5.7.2

See merge request knot/knot-resolver!1522

16 months agoci: obs: create venv and install apkg docs-develop-rele-m8rr9k/deployments/3611 docs-develop-rele-m8rr9k/deployments/3613 obs-knot-resolver-bs4hbr/deployments/3612
Aleš Mrázek [Wed, 27 Mar 2024 15:04:37 +0000 (16:04 +0100)] 
ci: obs: create venv and install apkg

16 months agoscripts/update-authors: explicit '--no-show-signature' docs-develop-rele-m8rr9k/deployments/3608 docs-develop-rele-m8rr9k/deployments/3610
Oto Šťáva [Wed, 27 Mar 2024 13:11:40 +0000 (14:11 +0100)] 
scripts/update-authors: explicit '--no-show-signature'

Fixes the script for users who have `log.showSignature` set to `true` in
their git config.

16 months agoRelease 5.7.2 docs-develop-rele-m8rr9k/deployments/3607
Oto Šťáva [Wed, 27 Mar 2024 12:52:57 +0000 (13:52 +0100)] 
Release 5.7.2

16 months agoMerge branch 'time_t' into 'master' docs-develop-mast-tzgd0f/deployments/3555 docs-develop-mast-tzgd0f/deployments/3565 docs-develop-mast-tzgd0f/deployments/3568 docs-develop-mast-tzgd0f/deployments/3569 docs-develop-mast-tzgd0f/deployments/3572 docs-develop-mast-tzgd0f/deployments/3573 docs-develop-mast-tzgd0f/deployments/3576 docs-develop-mast-tzgd0f/deployments/3586 docs-develop-mast-tzgd0f/deployments/3589 docs-develop-mast-tzgd0f/deployments/3595 docs-develop-mast-tzgd0f/deployments/3598 docs-develop-nigh-589znp/deployments/3566 docs-develop-nigh-589znp/deployments/3570 docs-develop-nigh-589znp/deployments/3574 docs-develop-nigh-589znp/deployments/3587 docs-develop-nigh-589znp/deployments/3596
Oto Šťáva [Fri, 22 Mar 2024 11:15:23 +0000 (12:15 +0100)] 
Merge branch 'time_t' into 'master'

daemon/lua: fix on 32-bit systems with 64-bit time_t

See merge request knot/knot-resolver!1510

16 months agodaemon/lua: fix on 32-bit systems with 64-bit time_t docs-develop-time-t0zmsd/deployments/3550
Vladimír Čunát [Wed, 6 Mar 2024 11:19:28 +0000 (12:19 +0100)] 
daemon/lua: fix on 32-bit systems with 64-bit time_t

This improves the heuristics.
The problem would be detected by meson, but not when cross-compiling,
in which case things would mostly run OK, except some lua code/modules.

16 months agoMerge !1501: various nits docs-develop-mast-tzgd0f/deployments/3415 docs-develop-mast-tzgd0f/deployments/3416 docs-develop-mast-tzgd0f/deployments/3419 docs-develop-mast-tzgd0f/deployments/3423 docs-develop-mast-tzgd0f/deployments/3426 docs-develop-mast-tzgd0f/deployments/3428 docs-develop-mast-tzgd0f/deployments/3431 docs-develop-mast-tzgd0f/deployments/3432 docs-develop-mast-tzgd0f/deployments/3435 docs-develop-mast-tzgd0f/deployments/3436 docs-develop-mast-tzgd0f/deployments/3439 docs-develop-mast-tzgd0f/deployments/3440 docs-develop-mast-tzgd0f/deployments/3443 docs-develop-mast-tzgd0f/deployments/3450 docs-develop-mast-tzgd0f/deployments/3453 docs-develop-mast-tzgd0f/deployments/3455 docs-develop-mast-tzgd0f/deployments/3458 docs-develop-mast-tzgd0f/deployments/3464 docs-develop-mast-tzgd0f/deployments/3467 docs-develop-mast-tzgd0f/deployments/3470 docs-develop-mast-tzgd0f/deployments/3473 docs-develop-mast-tzgd0f/deployments/3485 docs-develop-mast-tzgd0f/deployments/3488 docs-develop-mast-tzgd0f/deployments/3489 docs-develop-mast-tzgd0f/deployments/3492 docs-develop-mast-tzgd0f/deployments/3493 docs-develop-mast-tzgd0f/deployments/3496 docs-develop-mast-tzgd0f/deployments/3510 docs-develop-mast-tzgd0f/deployments/3513 docs-develop-mast-tzgd0f/deployments/3520 docs-develop-mast-tzgd0f/deployments/3523 docs-develop-mast-tzgd0f/deployments/3535 docs-develop-mast-tzgd0f/deployments/3538 docs-develop-mast-tzgd0f/deployments/3543 docs-develop-mast-tzgd0f/deployments/3546 docs-develop-nigh-589znp/deployments/3417 docs-develop-nigh-589znp/deployments/3424 docs-develop-nigh-589znp/deployments/3429 docs-develop-nigh-589znp/deployments/3433 docs-develop-nigh-589znp/deployments/3437 docs-develop-nigh-589znp/deployments/3441 docs-develop-nigh-589znp/deployments/3451 docs-develop-nigh-589znp/deployments/3456 docs-develop-nigh-589znp/deployments/3465 docs-develop-nigh-589znp/deployments/3471 docs-develop-nigh-589znp/deployments/3486 docs-develop-nigh-589znp/deployments/3490 docs-develop-nigh-589znp/deployments/3494 docs-develop-nigh-589znp/deployments/3511 docs-develop-nigh-589znp/deployments/3521 docs-develop-nigh-589znp/deployments/3536 docs-develop-nigh-589znp/deployments/3544
Vladimír Čunát [Tue, 5 Mar 2024 13:59:37 +0000 (14:59 +0100)] 
Merge !1501: various nits

16 months agolib/dnssec: rename 'check_crypto_limit' to 'account_crypto_limit'
Oto Šťáva [Fri, 16 Feb 2024 14:15:48 +0000 (15:15 +0100)] 
lib/dnssec: rename 'check_crypto_limit' to 'account_crypto_limit'

16 months agotests/integration/meson.build: refer to augeas as 'python-augeas'
Oto Šťáva [Fri, 16 Feb 2024 14:05:14 +0000 (15:05 +0100)] 
tests/integration/meson.build: refer to augeas as 'python-augeas'

This is so that it is more obvious that the PyPI package actually has
the `python-` prefix.

16 months agodaemon/proxyv2: nits
Oto Šťáva [Thu, 11 Jan 2024 10:16:10 +0000 (11:16 +0100)] 
daemon/proxyv2: nits

17 months agoMerge branch 'keytrap-related' into 'master' docs-develop-mast-tzgd0f/deployments/3332 docs-develop-mast-tzgd0f/deployments/3335 docs-develop-mast-tzgd0f/deployments/3338 docs-develop-mast-tzgd0f/deployments/3339 docs-develop-mast-tzgd0f/deployments/3342 docs-develop-mast-tzgd0f/deployments/3343 docs-develop-mast-tzgd0f/deployments/3346 docs-develop-mast-tzgd0f/deployments/3358 docs-develop-mast-tzgd0f/deployments/3361 docs-develop-mast-tzgd0f/deployments/3362 docs-develop-mast-tzgd0f/deployments/3365 docs-develop-mast-tzgd0f/deployments/3378 docs-develop-mast-tzgd0f/deployments/3381 docs-develop-mast-tzgd0f/deployments/3388 docs-develop-mast-tzgd0f/deployments/3391 docs-develop-mast-tzgd0f/deployments/3396 docs-develop-mast-tzgd0f/deployments/3399 docs-develop-mast-tzgd0f/deployments/3400 docs-develop-mast-tzgd0f/deployments/3403 docs-develop-mast-tzgd0f/deployments/3404 docs-develop-mast-tzgd0f/deployments/3407 docs-develop-mast-tzgd0f/deployments/3410 docs-develop-mast-tzgd0f/deployments/3413 docs-develop-nigh-589znp/deployments/3336 docs-develop-nigh-589znp/deployments/3340 docs-develop-nigh-589znp/deployments/3344 docs-develop-nigh-589znp/deployments/3359 docs-develop-nigh-589znp/deployments/3363 docs-develop-nigh-589znp/deployments/3379 docs-develop-nigh-589znp/deployments/3389 docs-develop-nigh-589znp/deployments/3397 docs-develop-nigh-589znp/deployments/3401 docs-develop-nigh-589znp/deployments/3405 docs-develop-nigh-589znp/deployments/3411
Oto Šťáva [Fri, 23 Feb 2024 09:36:47 +0000 (10:36 +0100)] 
Merge branch 'keytrap-related' into 'master'

improve assertions around current releases

See merge request knot/knot-resolver!1506

17 months agolib/cache: bump CACHE_VERSION docs-develop-keyt-jagcwb/deployments/3331
Vladimír Čunát [Fri, 23 Feb 2024 09:07:35 +0000 (10:07 +0100)] 
lib/cache: bump CACHE_VERSION

Ideally we would've done that at once with increasing NSEC3 strictness,
i.e. in 5.7.1 + 6.0.6, as otherwise we could run into some recoverable
assertions until the records got removed or expired.
We at least do the bump now.

17 months agolib/dnssec: fix imprecise assertion
Vladimír Čunát [Fri, 23 Feb 2024 08:33:21 +0000 (09:33 +0100)] 
lib/dnssec: fix imprecise assertion

It was no longer correct after commit cc5051b444130 (KeyTrap).

17 months agorelease 5.7.1 docs-develop-mast-tzgd0f/deployments/3233 docs-develop-mast-tzgd0f/deployments/3239 docs-develop-mast-tzgd0f/deployments/3249 docs-develop-mast-tzgd0f/deployments/3252 docs-develop-mast-tzgd0f/deployments/3256 docs-develop-mast-tzgd0f/deployments/3259 docs-develop-mast-tzgd0f/deployments/3269 docs-develop-mast-tzgd0f/deployments/3272 docs-develop-mast-tzgd0f/deployments/3278 docs-develop-mast-tzgd0f/deployments/3281 docs-develop-mast-tzgd0f/deployments/3282 docs-develop-mast-tzgd0f/deployments/3285 docs-develop-mast-tzgd0f/deployments/3286 docs-develop-mast-tzgd0f/deployments/3289 docs-develop-mast-tzgd0f/deployments/3299 docs-develop-mast-tzgd0f/deployments/3302 docs-develop-mast-tzgd0f/deployments/3307 docs-develop-mast-tzgd0f/deployments/3310 docs-develop-mast-tzgd0f/deployments/3319 docs-develop-mast-tzgd0f/deployments/3322 docs-develop-mast-tzgd0f/deployments/3324 docs-develop-mast-tzgd0f/deployments/3327 docs-develop-nigh-589znp/deployments/3250 docs-develop-nigh-589znp/deployments/3257 docs-develop-nigh-589znp/deployments/3270 docs-develop-nigh-589znp/deployments/3279 docs-develop-nigh-589znp/deployments/3283 docs-develop-nigh-589znp/deployments/3287 docs-develop-nigh-589znp/deployments/3300 docs-develop-nigh-589znp/deployments/3308 docs-develop-nigh-589znp/deployments/3320 docs-develop-nigh-589znp/deployments/3325 docs-develop-stab-lrl9qw/deployments/3253 docs-release-v5-7-svl2lq/deployments/3235 v5.7.1
Aleš Mrázek [Tue, 13 Feb 2024 09:08:04 +0000 (10:08 +0100)] 
release 5.7.1

17 months agoMerge: mitigate CVE-2023-50387 "KeyTrap" docs-develop-mast-tzgd0f/deployments/3232
Vladimír Čunát [Tue, 13 Feb 2024 11:43:16 +0000 (12:43 +0100)] 
Merge: mitigate CVE-2023-50387 "KeyTrap"

DNSSEC verification complexity could be exploited to exhaust CPU resources and stall DNS resolvers.

Solution boils down mainly to limiting crypto-validations per packet.

17 months agoupdate NEWS with KeyTrap
Vladimír Čunát [Mon, 1 Jan 2024 15:25:05 +0000 (16:25 +0100)] 
update NEWS with KeyTrap

in a separate commit, as it will tend to conflict if patching

17 months agomitigate KeyTrap DoS = CVE-2023-50387
Vladimír Čunát [Tue, 16 Jan 2024 06:35:20 +0000 (07:35 +0100)] 
mitigate KeyTrap DoS = CVE-2023-50387

Improve: don't retry in this case.

17 months agomitigate KeyTrap DoS = CVE-2023-50387
Vladimír Čunát [Mon, 1 Jan 2024 15:21:10 +0000 (16:21 +0100)] 
mitigate KeyTrap DoS = CVE-2023-50387

17 months agolib/resolve kr_request_set_extended_error(): tweak priorities
Vladimír Čunát [Mon, 1 Jan 2024 15:05:46 +0000 (16:05 +0100)] 
lib/resolve kr_request_set_extended_error(): tweak priorities

Keep the first error in case priorities are equal.

At least with the current KeyTrap topic that should work better,
but blaming a single error is alchemy anyway, at least in some cases.

17 months agolib/dnssec kr_rrset_validate_with_key(): deduplicate cleanup
Vladimír Čunát [Sat, 30 Dec 2023 08:20:56 +0000 (09:20 +0100)] 
lib/dnssec kr_rrset_validate_with_key(): deduplicate cleanup

17 months agoMerge CVE-2023-50868: NSEC3 closest encloser proof can exhaust CPU
Vladimír Čunát [Tue, 13 Feb 2024 08:46:09 +0000 (09:46 +0100)] 
Merge CVE-2023-50868: NSEC3 closest encloser proof can exhaust CPU

17 months agovalidator: compatibility with older libknot versions
Vladimír Čunát [Mon, 12 Feb 2024 10:30:50 +0000 (11:30 +0100)] 
validator: compatibility with older libknot versions

The value is in IANA registry, so it's very constant anyway.

17 months agoadd NEWS for NSEC3 mitigations from the previous few commits
Vladimír Čunát [Mon, 12 Feb 2024 10:23:42 +0000 (11:23 +0100)] 
add NEWS for NSEC3 mitigations from the previous few commits

17 months agovalidator: refuse to validate answers with more than 8 NSEC3 records
Vladimír Čunát [Mon, 12 Feb 2024 10:16:47 +0000 (11:16 +0100)] 
validator: refuse to validate answers with more than 8 NSEC3 records

17 months agovalidator: limit the amount of work on SHA1 in NSEC3 proofs
Vladimír Čunát [Mon, 12 Feb 2024 10:16:37 +0000 (11:16 +0100)] 
validator: limit the amount of work on SHA1 in NSEC3 proofs

17 months agolib/cache: limit the amount of work on SHA1
Vladimír Čunát [Sun, 11 Feb 2024 09:00:32 +0000 (10:00 +0100)] 
lib/cache: limit the amount of work on SHA1

That's when searching NSEC3 aggressive cache.

17 months agovalidator: similarly also limit excessive NSEC3 salt length
Vladimír Čunát [Tue, 2 Jan 2024 10:18:31 +0000 (11:18 +0100)] 
validator: similarly also limit excessive NSEC3 salt length

Limit combination of iterations and salt length, based on estimated
expense of the computation.  Note that the result only differs for
salt length > 44 which is rather nonsensical and very rare:
https://chat.dns-oarc.net/community/pl/h58qx9sjkbgt9dajb7x988p78a

17 months agovalidator: lower the NSEC3 iteration limit (150 -> 50)
Vladimír Čunát [Tue, 2 Jan 2024 09:05:28 +0000 (10:05 +0100)] 
validator: lower the NSEC3 iteration limit (150 -> 50)

Also done by BIND9 >= 9.19.19:
https://gitlab.isc.org/isc-projects/bind9/-/merge_requests/8515

The latest real-life measurements show that values above 50 are rare:
https://chat.dns-oarc.net/community/pl/aadp9wwrp7g7ux1b8chbzebmze

17 months agoMerge branch 'pkg-bionic' into 'master' docs-develop-mast-tzgd0f/deployments/3174 docs-develop-mast-tzgd0f/deployments/3175 docs-develop-mast-tzgd0f/deployments/3178 docs-develop-mast-tzgd0f/deployments/3191 docs-develop-mast-tzgd0f/deployments/3194 docs-develop-mast-tzgd0f/deployments/3195 docs-develop-mast-tzgd0f/deployments/3198 docs-develop-mast-tzgd0f/deployments/3209 docs-develop-mast-tzgd0f/deployments/3212 docs-develop-mast-tzgd0f/deployments/3216 docs-develop-mast-tzgd0f/deployments/3219 docs-develop-mast-tzgd0f/deployments/3220 docs-develop-mast-tzgd0f/deployments/3223 docs-develop-mast-tzgd0f/deployments/3228 docs-develop-mast-tzgd0f/deployments/3231 docs-develop-nigh-589znp/deployments/3176 docs-develop-nigh-589znp/deployments/3192 docs-develop-nigh-589znp/deployments/3196 docs-develop-nigh-589znp/deployments/3210 docs-develop-nigh-589znp/deployments/3217 docs-develop-nigh-589znp/deployments/3221 docs-develop-nigh-589znp/deployments/3229
Jakub Ružička [Tue, 6 Feb 2024 15:00:44 +0000 (16:00 +0100)] 
Merge branch 'pkg-bionic' into 'master'

pkg/distro/deb: fix doc build for Ubuntu 18.04

See merge request knot/knot-resolver!1495

17 months agopkg/distro/deb: fix doc build for Ubuntu 18.04 docs-develop-pkg-260b3i/deployments/3173
Jakub Ružička [Tue, 6 Feb 2024 13:32:56 +0000 (14:32 +0100)] 
pkg/distro/deb: fix doc build for Ubuntu 18.04

Due to mysterious reasons, Ubuntu 18.04 ARM builds doesn't invoke
dh_installinfo (even though amd64 does).

Merge knot-resolver-doc.info into knot-resolver-doc.docs for
compatibility.

17 months agodistro/pkg/deb: bump debhelper compat to 11
Jakub Ružička [Mon, 5 Feb 2024 17:10:21 +0000 (18:10 +0100)] 
distro/pkg/deb: bump debhelper compat to 11

Oldest supported distro requiring 11 is Ubuntu 18.04 Bionic Beaver.

17 months agoMerge !1494: compatibility with libknot's master (3.4 WIP) docs-develop-mast-tzgd0f/deployments/3166
Vladimír Čunát [Tue, 6 Feb 2024 11:40:35 +0000 (12:40 +0100)] 
Merge !1494: compatibility with libknot's master (3.4 WIP)

17 months agocompatibility with libknot's master (3.4 WIP) docs-develop-knot-chb1lt/deployments/3165
Vladimír Čunát [Tue, 6 Feb 2024 07:46:34 +0000 (08:46 +0100)] 
compatibility with libknot's master (3.4 WIP)

I'm adding this as a function, as in knot-resolver 6.x we have
one more place where it is used, and I find this more readable.

18 months agoMerge branch 'doc-logo-manual-colors-5' into 'master' docs-develop-mast-tzgd0f/deployments/3038 docs-develop-mast-tzgd0f/deployments/3041 docs-develop-mast-tzgd0f/deployments/3044 docs-develop-mast-tzgd0f/deployments/3047 docs-develop-mast-tzgd0f/deployments/3050 docs-develop-mast-tzgd0f/deployments/3052 docs-develop-mast-tzgd0f/deployments/3055 docs-develop-mast-tzgd0f/deployments/3063 docs-develop-mast-tzgd0f/deployments/3067 docs-develop-mast-tzgd0f/deployments/3070 docs-develop-mast-tzgd0f/deployments/3073 docs-develop-mast-tzgd0f/deployments/3074 docs-develop-mast-tzgd0f/deployments/3077 docs-develop-mast-tzgd0f/deployments/3078 docs-develop-mast-tzgd0f/deployments/3081 docs-develop-mast-tzgd0f/deployments/3084 docs-develop-mast-tzgd0f/deployments/3087 docs-develop-mast-tzgd0f/deployments/3089 docs-develop-mast-tzgd0f/deployments/3092 docs-develop-mast-tzgd0f/deployments/3093 docs-develop-mast-tzgd0f/deployments/3096 docs-develop-mast-tzgd0f/deployments/3097 docs-develop-mast-tzgd0f/deployments/3100 docs-develop-mast-tzgd0f/deployments/3105 docs-develop-mast-tzgd0f/deployments/3108 docs-develop-mast-tzgd0f/deployments/3109 docs-develop-mast-tzgd0f/deployments/3112 docs-develop-mast-tzgd0f/deployments/3113 docs-develop-mast-tzgd0f/deployments/3116 docs-develop-mast-tzgd0f/deployments/3120 docs-develop-mast-tzgd0f/deployments/3123 docs-develop-mast-tzgd0f/deployments/3124 docs-develop-mast-tzgd0f/deployments/3127 docs-develop-mast-tzgd0f/deployments/3131 docs-develop-mast-tzgd0f/deployments/3134 docs-develop-mast-tzgd0f/deployments/3139 docs-develop-mast-tzgd0f/deployments/3142 docs-develop-mast-tzgd0f/deployments/3145 docs-develop-mast-tzgd0f/deployments/3148 docs-develop-mast-tzgd0f/deployments/3150 docs-develop-mast-tzgd0f/deployments/3153 docs-develop-mast-tzgd0f/deployments/3154 docs-develop-mast-tzgd0f/deployments/3157 docs-develop-mast-tzgd0f/deployments/3161 docs-develop-mast-tzgd0f/deployments/3164 docs-develop-nigh-589znp/deployments/3042 docs-develop-nigh-589znp/deployments/3048 docs-develop-nigh-589znp/deployments/3053 docs-develop-nigh-589znp/deployments/3064 docs-develop-nigh-589znp/deployments/3071 docs-develop-nigh-589znp/deployments/3075 docs-develop-nigh-589znp/deployments/3079 docs-develop-nigh-589znp/deployments/3085 docs-develop-nigh-589znp/deployments/3090 docs-develop-nigh-589znp/deployments/3094 docs-develop-nigh-589znp/deployments/3098 docs-develop-nigh-589znp/deployments/3106 docs-develop-nigh-589znp/deployments/3110 docs-develop-nigh-589znp/deployments/3114 docs-develop-nigh-589znp/deployments/3121 docs-develop-nigh-589znp/deployments/3125 docs-develop-nigh-589znp/deployments/3132 docs-develop-nigh-589znp/deployments/3140 docs-develop-nigh-589znp/deployments/3146 docs-develop-nigh-589znp/deployments/3151 docs-develop-nigh-589znp/deployments/3155 docs-develop-nigh-589znp/deployments/3162
Oto Šťáva [Mon, 15 Jan 2024 20:57:35 +0000 (21:57 +0100)] 
Merge branch 'doc-logo-manual-colors-5' into 'master'

doc: adjust colors according to the logo manual

See merge request knot/knot-resolver!1489

18 months agodoc: adjust colors according to the logo manual docs-develop-doc-c5x6fl/deployments/3037
Oto Šťáva [Mon, 15 Jan 2024 19:11:13 +0000 (20:11 +0100)] 
doc: adjust colors according to the logo manual

18 months agoMerge branch 'sonarcloud-5-update' into 'master' docs-develop-mast-tzgd0f/deployments/3028
Oto Šťáva [Mon, 15 Jan 2024 09:54:55 +0000 (10:54 +0100)] 
Merge branch 'sonarcloud-5-update' into 'master'

ci/images/debian-11: update sonarcloud to version 5

See merge request knot/knot-resolver!1488

18 months agoci/images/debian-11: update sonarcloud to version 5 docs-develop-sona-zdh3hi/deployments/3027
Oto Šťáva [Mon, 15 Jan 2024 09:38:12 +0000 (10:38 +0100)] 
ci/images/debian-11: update sonarcloud to version 5

Old version caused failures due to unsupported Java version 11.

18 months agoMerge !1486: doc/requirements.txt: add sphinx_rtd_theme docs-develop-mast-tzgd0f/deployments/3002 docs-develop-mast-tzgd0f/deployments/3005 docs-develop-mast-tzgd0f/deployments/3008 docs-develop-mast-tzgd0f/deployments/3009 docs-develop-mast-tzgd0f/deployments/3012 docs-develop-mast-tzgd0f/deployments/3014 docs-develop-mast-tzgd0f/deployments/3017 docs-develop-mast-tzgd0f/deployments/3018 docs-develop-mast-tzgd0f/deployments/3021 docs-develop-mast-tzgd0f/deployments/3023 docs-develop-mast-tzgd0f/deployments/3026 docs-develop-nigh-589znp/deployments/3006 docs-develop-nigh-589znp/deployments/3010 docs-develop-nigh-589znp/deployments/3015 docs-develop-nigh-589znp/deployments/3019 docs-develop-nigh-589znp/deployments/3024 docs-develop-stab-lrl9qw/deployments/3004
Vladimír Čunát [Wed, 10 Jan 2024 16:23:12 +0000 (17:23 +0100)] 
Merge !1486: doc/requirements.txt: add sphinx_rtd_theme

18 months agodoc/requirements.txt: add sphinx_rtd_theme docs-develop-5-x-p0xmsm/deployments/3001
Oto Šťáva [Wed, 10 Jan 2024 15:39:52 +0000 (16:39 +0100)] 
doc/requirements.txt: add sphinx_rtd_theme

This should fix the ReadTheDocs build

18 months agoMerge branch 'docs-pages-5-backport' into 'master' docs-develop-mast-tzgd0f/deployments/2998
Oto Šťáva [Wed, 10 Jan 2024 15:12:09 +0000 (16:12 +0100)] 
Merge branch 'docs-pages-5-backport' into 'master'

Backport hosting docs in GitLab Pages into 5.x

See merge request knot/knot-resolver!1485

18 months ago.gitlab-ci: remove the `pages` job for 5.x docs-develop-docs-05qey4/deployments/2997
Oto Šťáva [Wed, 10 Jan 2024 15:04:14 +0000 (16:04 +0100)] 
.gitlab-ci: remove the `pages` job for 5.x

18 months agodoc/conf.py: jquery workaround docs-develop-docs-05qey4/deployments/2996
Oto Šťáva [Wed, 10 Jan 2024 14:18:57 +0000 (15:18 +0100)] 
doc/conf.py: jquery workaround

18 months ago.gitlab-ci: upgrade pip packages docs-develop-docs-05qey4/deployments/2995
Oto Šťáva [Wed, 10 Jan 2024 14:05:24 +0000 (15:05 +0100)] 
.gitlab-ci: upgrade pip packages

18 months agoscripts/make-doc.sh: backport changes from 6.0 docs-develop-docs-05qey4/deployments/2994
Oto Šťáva [Wed, 10 Jan 2024 13:49:11 +0000 (14:49 +0100)] 
scripts/make-doc.sh: backport changes from 6.0

18 months ago.gitlab-ci: remove old 'doc' target docs-develop-docs-05qey4/deployments/2991
Oto Šťáva [Wed, 10 Jan 2024 11:30:16 +0000 (12:30 +0100)] 
.gitlab-ci: remove old 'doc' target

18 months ago.gitlab-ci: fix Pages publishing docs-develop-docs-05qey4/deployments/2983
Oto Šťáva [Tue, 12 Sep 2023 12:27:09 +0000 (14:27 +0200)] 
.gitlab-ci: fix Pages publishing

This commit renames `docs:public` to `pages` as required by GitLab CI to
recognize Pages jobs correctly. It also adds the `public` directory into
`artifacts:paths`.

18 months ago.gitlab-ci.yml: use environments for documentation versioning
Oto Šťáva [Tue, 29 Aug 2023 08:38:13 +0000 (10:38 +0200)] 
.gitlab-ci.yml: use environments for documentation versioning

This leverages Environments on GitLab to expose different versions of
Knot Resolver docs. The `docs:build` job builds the documentation and
exposes it via job artifacts. Then `docs:develop` (for branches) and
`docs:release` (for tags) take these artifacts and expose them via an
Environment link (an example of this in action may be seen at
[https://gitlab.nic.cz/ostava/knot-resolver/-/environments]).

There is also an optional, manually runnable `docs:public` job, which,
when run, propagates the documentation to the main GitLab Pages of the
project (e.g. [https://knot.pages.nic.cz/knot-resolver]) - this will
probably be mostly used for the latest release, although this setup
pretty much allows us to swap it for whatever version we like at any
time.

20 months agoMerge !1478: etc/root.hints: B.root-servers.net updated addresses
Vladimír Čunát [Tue, 28 Nov 2023 14:32:06 +0000 (15:32 +0100)] 
Merge !1478: etc/root.hints: B.root-servers.net updated addresses

20 months agoetc/root.hints: B.root-servers.net updated addresses
Vladimír Čunát [Tue, 28 Nov 2023 13:44:55 +0000 (14:44 +0100)] 
etc/root.hints: B.root-servers.net updated addresses

Officially yesterday, but there's long overlap when both address pairs
are promised to work.  See e.g. this e-mail thread:
https://lists.dns-oarc.net/pipermail/dns-operations/2023-June/022052.html

20 months agoMerge !1470: lib/zonecut.c fetch_addr(): resurrect filtering by NO_IPV* obs-knot-resolver-es11k1/deployments/2853 obs-knot-resolver-es11k1/deployments/2861 obs-knot-resolver-es11k1/deployments/2862
Vladimír Čunát [Mon, 6 Nov 2023 09:41:59 +0000 (10:41 +0100)] 
Merge !1470: lib/zonecut.c fetch_addr(): resurrect filtering by NO_IPV*

20 months agolib/zonecut.c fetch_addr(): resurrect filtering by NO_IPV*
Vladimír Čunát [Fri, 3 Nov 2023 11:31:06 +0000 (12:31 +0100)] 
lib/zonecut.c fetch_addr(): resurrect filtering by NO_IPV*

This filtering was dropped in 4565cc596680 (v5.3.0).
Now it's reintroduced - but inside the function, as that seems nicer.
Nit: naming and comment were updated to fit the current usage.

As the code is designed so far (in whole history probably), in order
to detect whether we need to choose a zone cut closer to the root,
we need to do something like this in lib/zonecut.c already,
instead of just during server selection.

I don't think this change can break anything.
Fetching unusable addresses from cache seems pointless,
as selection wouldn't be allowed to use them or try resolving them.

21 months agoMerge branch 'news-5.7.0' into 'master' obs-knot-resolver-es11k1/deployments/2834 obs-knot-resolver-es11k1/deployments/2835 obs-knot-resolver-es11k1/deployments/2836 obs-knot-resolver-es11k1/deployments/2837 obs-knot-resolver-es11k1/deployments/2838 obs-knot-resolver-es11k1/deployments/2839 obs-knot-resolver-es11k1/deployments/2840 obs-knot-resolver-es11k1/deployments/2841 obs-knot-resolver-es11k1/deployments/2845 obs-knot-resolver-es11k1/deployments/2846 obs-knot-resolver-es11k1/deployments/2847
Oto Šťáva [Fri, 27 Oct 2023 14:05:10 +0000 (16:05 +0200)] 
Merge branch 'news-5.7.0' into 'master'

NEWS: improve the security entry in 5.7.0

See merge request knot/knot-resolver!1468

21 months agoNEWS: improve the security entry in 5.7.0
Vladimír Čunát [Mon, 23 Oct 2023 06:40:17 +0000 (08:40 +0200)] 
NEWS: improve the security entry in 5.7.0

21 months agoMerge !1463: ci macOS: update Knot DNS obs-knot-resolver-es11k1/deployments/2829 obs-knot-resolver-es11k1/deployments/2830 obs-knot-resolver-es11k1/deployments/2832 obs-knot-resolver-es11k1/deployments/2833
Vladimír Čunát [Mon, 23 Oct 2023 06:44:11 +0000 (08:44 +0200)] 
Merge !1463: ci macOS: update Knot DNS

21 months agoci macOS: wait on *both* builds
Vladimír Čunát [Tue, 3 Oct 2023 09:26:48 +0000 (11:26 +0200)] 
ci macOS: wait on *both* builds

At least I hope this will work as expected.

21 months agoci macOS: update Knot DNS
Vladimír Čunát [Tue, 3 Oct 2023 09:19:02 +0000 (11:19 +0200)] 
ci macOS: update Knot DNS

23 months agoMerge branch 'release-5.7.0' into 'master' obs-knot-resolver-8xyvhu/deployments/2634 obs-knot-resolver-es11k1/deployments/2635 obs-knot-resolver-es11k1/deployments/2636 obs-knot-resolver-es11k1/deployments/2638 obs-knot-resolver-es11k1/deployments/2639 obs-knot-resolver-es11k1/deployments/2640 obs-knot-resolver-es11k1/deployments/2641 obs-knot-resolver-es11k1/deployments/2654 obs-knot-resolver-es11k1/deployments/2664 obs-knot-resolver-es11k1/deployments/2665 obs-knot-resolver-es11k1/deployments/2666 obs-knot-resolver-es11k1/deployments/2667 obs-knot-resolver-es11k1/deployments/2670 obs-knot-resolver-es11k1/deployments/2671 obs-knot-resolver-es11k1/deployments/2672 obs-knot-resolver-es11k1/deployments/2675 obs-knot-resolver-es11k1/deployments/2677 obs-knot-resolver-es11k1/deployments/2678 obs-knot-resolver-es11k1/deployments/2679 obs-knot-resolver-es11k1/deployments/2683 obs-knot-resolver-es11k1/deployments/2697 obs-knot-resolver-es11k1/deployments/2698 obs-knot-resolver-es11k1/deployments/2710 obs-knot-resolver-es11k1/deployments/2718 obs-knot-resolver-es11k1/deployments/2720 obs-knot-resolver-es11k1/deployments/2721 obs-knot-resolver-es11k1/deployments/2728 obs-knot-resolver-es11k1/deployments/2733 obs-knot-resolver-es11k1/deployments/2741 obs-knot-resolver-es11k1/deployments/2745 obs-knot-resolver-es11k1/deployments/2751 obs-knot-resolver-es11k1/deployments/2754 obs-knot-resolver-es11k1/deployments/2755 obs-knot-resolver-es11k1/deployments/2765 obs-knot-resolver-es11k1/deployments/2772 obs-knot-resolver-es11k1/deployments/2774 obs-knot-resolver-es11k1/deployments/2775 obs-knot-resolver-es11k1/deployments/2776 obs-knot-resolver-es11k1/deployments/2777 obs-knot-resolver-es11k1/deployments/2778 obs-knot-resolver-es11k1/deployments/2779 obs-knot-resolver-es11k1/deployments/2784 obs-knot-resolver-es11k1/deployments/2787 obs-knot-resolver-es11k1/deployments/2805 obs-knot-resolver-es11k1/deployments/2806 obs-knot-resolver-es11k1/deployments/2808 obs-knot-resolver-es11k1/deployments/2809 obs-knot-resolver-es11k1/deployments/2811 obs-knot-resolver-es11k1/deployments/2812 obs-knot-resolver-es11k1/deployments/2814 obs-knot-resolver-es11k1/deployments/2816 obs-knot-resolver-es11k1/deployments/2818 obs-knot-resolver-es11k1/deployments/2819 obs-knot-resolver-es11k1/deployments/2820 obs-knot-resolver-es11k1/deployments/2821 obs-knot-resolver-es11k1/deployments/2822 obs-knot-resolver-es11k1/deployments/2823 obs-knot-resolver-es11k1/deployments/2824 obs-knot-resolver-es11k1/deployments/2825 obs-knot-resolver-es11k1/deployments/2826 obs-knot-resolver-es11k1/deployments/2827 obs-knot-resolver-kv62s6/deployments/2633 v5.7.0
Aleš Mrázek [Tue, 22 Aug 2023 08:51:29 +0000 (10:51 +0200)] 
Merge branch 'release-5.7.0' into 'master'

release 5.7.0

See merge request knot/knot-resolver!1448

23 months agoNEWS: date update
Aleš Mrázek [Tue, 22 Aug 2023 08:27:18 +0000 (10:27 +0200)] 
NEWS: date update

23 months agoAUTHORS update obs-knot-resolver-bs4hbr/deployments/2631
Aleš Mrázek [Mon, 21 Aug 2023 13:10:43 +0000 (15:10 +0200)] 
AUTHORS update

23 months agorelease 5.7.0
Aleš Mrázek [Mon, 21 Aug 2023 12:54:14 +0000 (14:54 +0200)] 
release 5.7.0

23 months agodaemon: more avoidance of excessive TCP reconnections
Vladimír Čunát [Sat, 29 Jul 2023 15:53:34 +0000 (17:53 +0200)] 
daemon: more avoidance of excessive TCP reconnections

Previously this penalization was only triggered if the remote server
closed TCP.  Now it's extended to us closing it when the server
(only) sends back some nonsense.  At least for the cases which I could
see immediately.

That's just three trivial one-line additions; the rest is refactoring.

23 months agoMerge !1441: .readthedocs.yaml: migrate configuration from web app obs-knot-resolver-es11k1/deployments/2616 obs-knot-resolver-es11k1/deployments/2617 obs-knot-resolver-es11k1/deployments/2618 obs-knot-resolver-es11k1/deployments/2619 obs-knot-resolver-es11k1/deployments/2620 obs-knot-resolver-es11k1/deployments/2621 obs-knot-resolver-es11k1/deployments/2622 obs-knot-resolver-es11k1/deployments/2623 obs-knot-resolver-es11k1/deployments/2624 obs-knot-resolver-es11k1/deployments/2625 obs-knot-resolver-es11k1/deployments/2626 obs-knot-resolver-es11k1/deployments/2627 obs-knot-resolver-es11k1/deployments/2628 obs-knot-resolver-es11k1/deployments/2629 obs-knot-resolver-es11k1/deployments/2630 obs-knot-resolver-es11k1/deployments/2632
Vladimír Čunát [Sun, 6 Aug 2023 07:24:46 +0000 (09:24 +0200)] 
Merge !1441: .readthedocs.yaml: migrate configuration from web app

23 months ago.readthedocs.yaml: migrate configuration from web app
Oto Šťáva [Fri, 4 Aug 2023 11:32:56 +0000 (13:32 +0200)] 
.readthedocs.yaml: migrate configuration from web app

Read the Docs is deprecating their web configuration. This commit
should migrate said configuration to the newly recommended YAML format.

2 years agoMerge !1422: avoid knot_pkt_default_padding_size() obs-knot-resolver-es11k1/deployments/2590 obs-knot-resolver-es11k1/deployments/2591 obs-knot-resolver-es11k1/deployments/2592 obs-knot-resolver-es11k1/deployments/2593 obs-knot-resolver-es11k1/deployments/2594 obs-knot-resolver-es11k1/deployments/2595 obs-knot-resolver-es11k1/deployments/2596 obs-knot-resolver-es11k1/deployments/2597 obs-knot-resolver-es11k1/deployments/2598 obs-knot-resolver-es11k1/deployments/2599 obs-knot-resolver-es11k1/deployments/2600 obs-knot-resolver-es11k1/deployments/2601 obs-knot-resolver-es11k1/deployments/2602 obs-knot-resolver-es11k1/deployments/2603 obs-knot-resolver-es11k1/deployments/2604 obs-knot-resolver-es11k1/deployments/2605 obs-knot-resolver-es11k1/deployments/2606 obs-knot-resolver-es11k1/deployments/2607 obs-knot-resolver-es11k1/deployments/2608 obs-knot-resolver-es11k1/deployments/2609 obs-knot-resolver-es11k1/deployments/2610 obs-knot-resolver-es11k1/deployments/2611 obs-knot-resolver-es11k1/deployments/2612 obs-knot-resolver-es11k1/deployments/2613 obs-knot-resolver-es11k1/deployments/2614 obs-knot-resolver-es11k1/deployments/2615
Vladimír Čunát [Tue, 11 Jul 2023 08:13:26 +0000 (10:13 +0200)] 
Merge !1422: avoid knot_pkt_default_padding_size()

2 years agoavoid knot_pkt_default_padding_size()
Vladimír Čunát [Wed, 28 Jun 2023 15:48:51 +0000 (17:48 +0200)] 
avoid knot_pkt_default_padding_size()

The reserved size in packet is a messy thing, broken by
https://gitlab.nic.cz/knot/knot-dns/-/commit/ded5fbf01d00a875f141
Fortunately this function is trivial, so we can inline what we need.
It gets complicated by an earlier typo fix, though.

2 years agoMerge !1406: hints: fix names inside home.arpa. obs-knot-resolver-es11k1/deployments/2562 obs-knot-resolver-es11k1/deployments/2563 obs-knot-resolver-es11k1/deployments/2564 obs-knot-resolver-es11k1/deployments/2565 obs-knot-resolver-es11k1/deployments/2566 obs-knot-resolver-es11k1/deployments/2567 obs-knot-resolver-es11k1/deployments/2568 obs-knot-resolver-es11k1/deployments/2569 obs-knot-resolver-es11k1/deployments/2572 obs-knot-resolver-es11k1/deployments/2573 obs-knot-resolver-es11k1/deployments/2574 obs-knot-resolver-es11k1/deployments/2575 obs-knot-resolver-es11k1/deployments/2576 obs-knot-resolver-es11k1/deployments/2577 obs-knot-resolver-es11k1/deployments/2578 obs-knot-resolver-es11k1/deployments/2579 obs-knot-resolver-es11k1/deployments/2580 obs-knot-resolver-es11k1/deployments/2581 obs-knot-resolver-es11k1/deployments/2582 obs-knot-resolver-es11k1/deployments/2583 obs-knot-resolver-es11k1/deployments/2584 obs-knot-resolver-es11k1/deployments/2585 obs-knot-resolver-es11k1/deployments/2586 obs-knot-resolver-es11k1/deployments/2587 obs-knot-resolver-es11k1/deployments/2588 obs-knot-resolver-es11k1/deployments/2589
Vladimír Čunát [Thu, 15 Jun 2023 15:22:44 +0000 (17:22 +0200)] 
Merge !1406: hints: fix names inside home.arpa.

2 years agohints: fix names inside home.arpa.
Vladimír Čunát [Sat, 10 Jun 2023 08:34:12 +0000 (10:34 +0200)] 
hints: fix names inside home.arpa.

Reported on https://forum.turris.cz/t/knot-resolver-with-local-fqdn-hostnames/19034/8

I write it as three comparisons, as it seems like a simple way of
still running only a single comparison in the typical case of QNAME
not falling under .arpa.

Tested just quickly, manually.  This chunk of code already is replaced
for kresd >= 6.0.0.

2 years agoMerge !1405: stricter C warnings: fix and add them to defaults+CI obs-knot-resolver-es11k1/deployments/2556 obs-knot-resolver-es11k1/deployments/2557 obs-knot-resolver-es11k1/deployments/2558 obs-knot-resolver-es11k1/deployments/2559 obs-knot-resolver-es11k1/deployments/2560 obs-knot-resolver-es11k1/deployments/2561
Vladimír Čunát [Fri, 9 Jun 2023 16:25:58 +0000 (18:25 +0200)] 
Merge !1405: stricter C warnings: fix and add them to defaults+CI

2 years agomeson: add more warnings from the C compiler
Vladimír Čunát [Wed, 7 Jun 2023 08:30:33 +0000 (10:30 +0200)] 
meson: add more warnings from the C compiler

I tested this still builds with gcc 6, gcc 13, clang 7, clang 16.
Our CI additionally does `-Werror`, so that the properties
will get maintained (on some Debian's default compiler and clang).
Warnings with gcc 13 seem clear for me now, too.

2 years agotreewide: fix -Wold-style-*
Vladimír Čunát [Wed, 7 Jun 2023 08:54:30 +0000 (10:54 +0200)] 
treewide: fix -Wold-style-*

2 years agotreewide: fix -Wstrict-prototypes
Vladimír Čunát [Wed, 7 Jun 2023 08:41:22 +0000 (10:41 +0200)] 
treewide: fix -Wstrict-prototypes

2 years agoMerge !1404: tests/dnstap: let Go handle its transitive dependencies obs-knot-resolver-es11k1/deployments/2555
Vladimír Čunát [Thu, 8 Jun 2023 06:09:15 +0000 (08:09 +0200)] 
Merge !1404: tests/dnstap: let Go handle its transitive dependencies

2 years agotests/dnstap: let Go handle its transitive dependencies
Oto Šťáva [Wed, 7 Jun 2023 13:04:10 +0000 (15:04 +0200)] 
tests/dnstap: let Go handle its transitive dependencies

Dependabot reported that we have some vulnerable dependencies. The
problem is that the ones it wants to bump to do not support older Go
versions, which we need to use due to some distros not having the most
recent Go packages available.

The `go.sum` file contains the outdated ones (because I tried with an
older Go), but as far as I can tell, from Go docs and other places, it
is actually not a lockfile, so newer Go should update the packages
regardless of what is in `go.sum`.

2 years agoMerge !1403: tests, ci: fix and reintroduce dnstap tests + nits obs-knot-resolver-es11k1/deployments/2554
Vladimír Čunát [Wed, 7 Jun 2023 11:36:57 +0000 (13:36 +0200)] 
Merge !1403: tests, ci: fix and reintroduce dnstap tests + nits

2 years agotests/pytests: adapt to new pylint
Oto Šťáva [Wed, 7 Jun 2023 06:15:41 +0000 (08:15 +0200)] 
tests/pytests: adapt to new pylint

New version of pylint removed the disabled `bad-continuation` check. It
also added a parens check that we were violating in
`test_random_close.py`, which is now fixed as well.

2 years agoci/images/README: add KNOT_BRANCH explanation
Oto Šťáva [Wed, 7 Jun 2023 06:09:56 +0000 (08:09 +0200)] 
ci/images/README: add KNOT_BRANCH explanation

2 years agoci: reintroduce Go tests into the CI
Oto Šťáva [Tue, 6 Jun 2023 12:50:20 +0000 (14:50 +0200)] 
ci: reintroduce Go tests into the CI

2 years agotests/dnstap: fix for Go 1.19 (and possibly others)
Oto Šťáva [Tue, 6 Jun 2023 08:10:53 +0000 (10:10 +0200)] 
tests/dnstap: fix for Go 1.19 (and possibly others)

2 years agoMerge !1401: lib/cache pkt_renew(): fix an edge-case bug obs-knot-resolver-es11k1/deployments/2546 obs-knot-resolver-es11k1/deployments/2547 obs-knot-resolver-es11k1/deployments/2548 obs-knot-resolver-es11k1/deployments/2549 obs-knot-resolver-es11k1/deployments/2550 obs-knot-resolver-es11k1/deployments/2551 obs-knot-resolver-es11k1/deployments/2552 obs-knot-resolver-es11k1/deployments/2553
Vladimír Čunát [Tue, 30 May 2023 07:19:19 +0000 (09:19 +0200)] 
Merge !1401: lib/cache pkt_renew(): fix an edge-case bug

2 years agolib/cache pkt_renew(): fix an edge-case bug
Vladimír Čunát [Mon, 29 May 2023 11:59:00 +0000 (13:59 +0200)] 
lib/cache pkt_renew(): fix an edge-case bug

It could happen that this condition didn't get triggered,
but the structures weren't completely clear.  In particular,
the current section could be past KNOT_ANSWER already.
Let's be more conservative here; pkt_recycle() shouldn't be expensive.

I'm not sure why I only ran into this on the new-policy branch,
but it really seems like bug here on master already.

2 years agoMerge !1397: hints docs: explain root hints better obs-knot-resolver-es11k1/deployments/2526 obs-knot-resolver-es11k1/deployments/2527 obs-knot-resolver-es11k1/deployments/2528 obs-knot-resolver-es11k1/deployments/2529 obs-knot-resolver-es11k1/deployments/2530 obs-knot-resolver-es11k1/deployments/2531 obs-knot-resolver-es11k1/deployments/2532 obs-knot-resolver-es11k1/deployments/2533 obs-knot-resolver-es11k1/deployments/2534 obs-knot-resolver-es11k1/deployments/2535 obs-knot-resolver-es11k1/deployments/2536 obs-knot-resolver-es11k1/deployments/2537 obs-knot-resolver-es11k1/deployments/2538 obs-knot-resolver-es11k1/deployments/2539 obs-knot-resolver-es11k1/deployments/2540 obs-knot-resolver-es11k1/deployments/2541 obs-knot-resolver-es11k1/deployments/2542 obs-knot-resolver-es11k1/deployments/2543 obs-knot-resolver-es11k1/deployments/2544 obs-knot-resolver-es11k1/deployments/2545
Vladimír Čunát [Wed, 10 May 2023 09:54:21 +0000 (11:54 +0200)] 
Merge !1397: hints docs: explain root hints better

2 years agohints docs: explain root hints better
Vladimír Čunát [Wed, 26 Apr 2023 09:16:34 +0000 (11:16 +0200)] 
hints docs: explain root hints better

The removed tip seemed especially misleading;
I don't think our root hints could've ever been used that way.
And latency to root servers has practically no impact on latency
of replies to reasonable answers (just like... once per day and TLD).

2 years agoMerge !1398: ci: drop debian 9
Vladimír Čunát [Wed, 10 May 2023 07:39:48 +0000 (09:39 +0200)] 
Merge !1398: ci: drop debian 9

2 years agoci: drop debian 9
Vladimír Čunát [Mon, 8 May 2023 08:39:41 +0000 (10:39 +0200)] 
ci: drop debian 9

It looks like downloads won't work anymore:
 https://gitlab.nic.cz/knot/knot-resolver/-/jobs/890201
 https://gitlab.nic.cz/knot/knot-resolver/-/jobs/890312
which is probably because long-term support ended last summer.

2 years agoMerge !1396: tests/integration/deckard: update obs-knot-resolver-es11k1/deployments/2489 obs-knot-resolver-es11k1/deployments/2490 obs-knot-resolver-es11k1/deployments/2491 obs-knot-resolver-es11k1/deployments/2492 obs-knot-resolver-es11k1/deployments/2493 obs-knot-resolver-es11k1/deployments/2494 obs-knot-resolver-es11k1/deployments/2495 obs-knot-resolver-es11k1/deployments/2496 obs-knot-resolver-es11k1/deployments/2497 obs-knot-resolver-es11k1/deployments/2498 obs-knot-resolver-es11k1/deployments/2499 obs-knot-resolver-es11k1/deployments/2500 obs-knot-resolver-es11k1/deployments/2501 obs-knot-resolver-es11k1/deployments/2502 obs-knot-resolver-es11k1/deployments/2503 obs-knot-resolver-es11k1/deployments/2504 obs-knot-resolver-es11k1/deployments/2505 obs-knot-resolver-es11k1/deployments/2506 obs-knot-resolver-es11k1/deployments/2507 obs-knot-resolver-es11k1/deployments/2508 obs-knot-resolver-es11k1/deployments/2509 obs-knot-resolver-es11k1/deployments/2510 obs-knot-resolver-es11k1/deployments/2511 obs-knot-resolver-es11k1/deployments/2512 obs-knot-resolver-es11k1/deployments/2513 obs-knot-resolver-es11k1/deployments/2514 obs-knot-resolver-es11k1/deployments/2515 obs-knot-resolver-es11k1/deployments/2516 obs-knot-resolver-es11k1/deployments/2517 obs-knot-resolver-es11k1/deployments/2518 obs-knot-resolver-es11k1/deployments/2519 obs-knot-resolver-es11k1/deployments/2520 obs-knot-resolver-es11k1/deployments/2521 obs-knot-resolver-es11k1/deployments/2522 obs-knot-resolver-es11k1/deployments/2523 obs-knot-resolver-es11k1/deployments/2524 obs-knot-resolver-es11k1/deployments/2525
Vladimír Čunát [Mon, 3 Apr 2023 12:35:25 +0000 (14:35 +0200)] 
Merge !1396: tests/integration/deckard: update

2 years agotests/integration/deckard: update
Vladimír Čunát [Mon, 3 Apr 2023 12:02:21 +0000 (14:02 +0200)] 
tests/integration/deckard: update

Adds just https://gitlab.nic.cz/knot/deckard/-/merge_requests/220

2 years agoMerge !1392: forwarding mode: tweak dealing with failures from forwarders obs-knot-resolver-es11k1/deployments/2478 obs-knot-resolver-es11k1/deployments/2479 obs-knot-resolver-es11k1/deployments/2480 obs-knot-resolver-es11k1/deployments/2481 obs-knot-resolver-es11k1/deployments/2482 obs-knot-resolver-es11k1/deployments/2483 obs-knot-resolver-es11k1/deployments/2484 obs-knot-resolver-es11k1/deployments/2485 obs-knot-resolver-es11k1/deployments/2486 obs-knot-resolver-es11k1/deployments/2487 obs-knot-resolver-es11k1/deployments/2488
Vladimír Čunát [Wed, 22 Mar 2023 15:59:49 +0000 (16:59 +0100)] 
Merge !1392: forwarding mode: tweak dealing with failures from forwarders

2 years agoNEWS: entry describing the previous three commits
Vladimír Čunát [Fri, 10 Mar 2023 17:29:42 +0000 (18:29 +0100)] 
NEWS: entry describing the previous three commits

The changes are potentially too significant to do in a patch update.

2 years agoimprove handling of SERVFAIL from forwarders
Vladimír Čunát [Wed, 8 Mar 2023 16:18:16 +0000 (17:18 +0100)] 
improve handling of SERVFAIL from forwarders

- selection: utilize address_state::broken also when forwarding
- selection: drop fallbacks that don't make sense when forwarding
- iterate: copy EDE codes on DNSSEC SERVFAILs

2 years agolib/resolve: when forwarding, prefer to send CD=0 upstream
Vladimír Čunát [Wed, 8 Mar 2023 13:25:39 +0000 (14:25 +0100)] 
lib/resolve: when forwarding, prefer to send CD=0 upstream

2 years agolib/resolve query_finalize: handle RD flag even if NO_EDNS
Vladimír Čunát [Wed, 8 Mar 2023 13:01:08 +0000 (14:01 +0100)] 
lib/resolve query_finalize: handle RD flag even if NO_EDNS

2 years agoMerge !1390: nits: destination-based view, ephemeral TLS cert obs-knot-resolver-es11k1/deployments/2466 obs-knot-resolver-es11k1/deployments/2467 obs-knot-resolver-es11k1/deployments/2468 obs-knot-resolver-es11k1/deployments/2469 obs-knot-resolver-es11k1/deployments/2470 obs-knot-resolver-es11k1/deployments/2471 obs-knot-resolver-es11k1/deployments/2472 obs-knot-resolver-es11k1/deployments/2473 obs-knot-resolver-es11k1/deployments/2474 obs-knot-resolver-es11k1/deployments/2475 obs-knot-resolver-es11k1/deployments/2476 obs-knot-resolver-es11k1/deployments/2477
Vladimír Čunát [Fri, 10 Mar 2023 09:55:57 +0000 (10:55 +0100)] 
Merge !1390: nits: destination-based view, ephemeral TLS cert