]> git.ipfire.org Git - thirdparty/knot-resolver.git/log
thirdparty/knot-resolver.git
14 months agorrl WIP: add temporary measurements of CPU time measurement code docs-develop-rrl-l16r8o/deployments/4090 rrl-wip-sample
Lukáš Ondráček [Wed, 15 May 2024 15:10:37 +0000 (17:10 +0200)] 
rrl WIP: add temporary measurements of CPU time measurement code

14 months agorrl WIP: increase precision of cpu work estimate using RDTSC docs-develop-rrl-l16r8o/deployments/4077
Lukáš Ondráček [Tue, 14 May 2024 11:53:16 +0000 (13:53 +0200)] 
rrl WIP: increase precision of cpu work estimate using RDTSC

14 months agodaemon/rrl WIP: estimate CPU work done on behalf of clients docs-develop-rrl-l16r8o/deployments/4015
Vladimír Čunát [Tue, 7 May 2024 10:34:15 +0000 (12:34 +0200)] 
daemon/rrl WIP: estimate CPU work done on behalf of clients

14 months agorrl: truncating answers when close to limit, dropping over limit docs-develop-rrl-8r8r8r/deployments/4008
Lukáš Ondráček [Mon, 6 May 2024 15:32:45 +0000 (17:32 +0200)] 
rrl: truncating answers when close to limit, dropping over limit

15 months agorrl nit: factor out using_avx() docs-develop-rrl-8r8r8r/deployments/3850
Vladimír Čunát [Sat, 20 Apr 2024 08:01:46 +0000 (10:01 +0200)] 
rrl nit: factor out using_avx()

15 months agofixup! rrl: improve error messages
Vladimír Čunát [Sat, 20 Apr 2024 07:55:32 +0000 (09:55 +0200)] 
fixup! rrl: improve error messages

15 months agofixup! rrl: modify KRU api to return maximum final load value docs-develop-rrl-8r8r8r/deployments/3849
Vladimír Čunát [Sat, 20 Apr 2024 07:16:29 +0000 (09:16 +0200)] 
fixup! rrl: modify KRU api to return maximum final load value

- reordering saves 8 bytes per struct (on typical 64-bit platforms)
- don't assume that *max_load_out is initialized reasonably
  (the doc-comment doesn't suggest that it's needed)

15 months agorrl: modify KRU api to return maximum final load value docs-develop-rrl-8r8r8r/deployments/3753
Lukáš Ondráček [Wed, 10 Apr 2024 16:17:26 +0000 (18:17 +0200)] 
rrl: modify KRU api to return maximum final load value

15 months agorrl: improve error messages docs-develop-rrl-8r8r8r/deployments/3745
Lukáš Ondráček [Wed, 10 Apr 2024 14:13:09 +0000 (16:13 +0200)] 
rrl: improve error messages

15 months agoMerge branch 'rrl-wip' of gitlab.nic.cz:knot/knot-resolver into rrl-wip docs-develop-rrl-8r8r8r/deployments/3736
Lukáš Ondráček [Wed, 10 Apr 2024 11:09:52 +0000 (13:09 +0200)] 
Merge branch 'rrl-wip' of gitlab.nic.cz:knot/knot-resolver into rrl-wip

15 months agorrl: disable parallel tests under valgrind in CI
Lukáš Ondráček [Wed, 10 Apr 2024 11:08:10 +0000 (13:08 +0200)] 
rrl: disable parallel tests under valgrind in CI

15 months agofixup! rrl: configurable limits in yaml, deinit docs-develop-rrl-8r8r8r/deployments/3729
Vladimír Čunát [Wed, 10 Apr 2024 09:06:59 +0000 (11:06 +0200)] 
fixup! rrl: configurable limits in yaml, deinit

I see no reason for these removed parts.

15 months agofixup! rrl: porting unit tests from Knot DNS docs-develop-rrl-8r8r8r/deployments/3714
Lukáš Ondráček [Mon, 8 Apr 2024 13:47:15 +0000 (15:47 +0200)] 
fixup! rrl: porting unit tests from Knot DNS

15 months agofixup! rrl: porting unit tests from Knot DNS docs-develop-rrl-8r8r8r/deployments/3713
Lukáš Ondráček [Mon, 8 Apr 2024 13:42:17 +0000 (15:42 +0200)] 
fixup! rrl: porting unit tests from Knot DNS

15 months agolib/dnssec nit: improve #include path docs-develop-rrl-8r8r8r/deployments/3709
Vladimír Čunát [Mon, 8 Apr 2024 08:52:01 +0000 (10:52 +0200)] 
lib/dnssec nit: improve #include path

No idea why it started causing issues now and for me, with:
lib/dnssec/nsec.c:19:10: fatal error: resolve.h: No such file or director

15 months agorrl: porting unit tests from Knot DNS docs-develop-rrl-8r8r8r/deployments/3675
Lukáš Ondráček [Wed, 3 Apr 2024 18:53:52 +0000 (20:53 +0200)] 
rrl: porting unit tests from Knot DNS

16 months agofixup! rrl: allow changing configuration on reload docs-develop-rrl-8r8r8r/deployments/3660
Lukáš Ondráček [Tue, 2 Apr 2024 15:47:27 +0000 (17:47 +0200)] 
fixup! rrl: allow changing configuration on reload

16 months agofixup! fixup! rrl: configurable limits in yaml, deinit docs-develop-rrl-8r8r8r/deployments/3658
Lukáš Ondráček [Tue, 2 Apr 2024 15:27:24 +0000 (17:27 +0200)] 
fixup! fixup! rrl: configurable limits in yaml, deinit

16 months agofixup! rrl: configurable limits in yaml, deinit docs-develop-rrl-8r8r8r/deployments/3657
Lukáš Ondráček [Tue, 2 Apr 2024 15:14:06 +0000 (17:14 +0200)] 
fixup! rrl: configurable limits in yaml, deinit

16 months agorrl: allow changing configuration on reload docs-develop-rrl-8r8r8r/deployments/3656
Lukáš Ondráček [Tue, 2 Apr 2024 14:17:05 +0000 (16:17 +0200)] 
rrl: allow changing configuration on reload

16 months agorrl: configurable limits in yaml, deinit docs-develop-rrl-8r8r8r/deployments/3624
Lukáš Ondráček [Wed, 27 Mar 2024 10:45:30 +0000 (11:45 +0100)] 
rrl: configurable limits in yaml, deinit

16 months agorrl: check and log chosen impl. (generic vs AVX2) docs-develop-rrl-8r8r8r/deployments/3594
Lukáš Ondráček [Tue, 26 Mar 2024 15:25:52 +0000 (16:25 +0100)] 
rrl: check and log chosen impl. (generic vs AVX2)

16 months agorrl: incorporate KRU changes from Knot DNS docs-develop-rrl-8r8r8r/deployments/3593
Lukáš Ondráček [Tue, 26 Mar 2024 15:10:40 +0000 (16:10 +0100)] 
rrl: incorporate KRU changes from Knot DNS

16 months agorrl: sharing memory between processes, basic limiting docs-develop-rrl-8r8r8r/deployments/3592
Lukáš Ondráček [Tue, 26 Mar 2024 11:38:18 +0000 (12:38 +0100)] 
rrl: sharing memory between processes, basic limiting

16 months agoPoC: rate-limit everything for now :-) docs-develop-rrl-8r8r8r/deployments/3515
Vladimír Čunát [Tue, 19 Mar 2024 11:15:14 +0000 (12:15 +0100)] 
PoC: rate-limit everything for now :-)

16 months agoWIP: CI nits docs-develop-rrl-8r8r8r/deployments/3509
Vladimír Čunát [Mon, 18 Mar 2024 18:26:13 +0000 (19:26 +0100)] 
WIP: CI nits

16 months agoTMP: replace symlinks by contents docs-develop-rrl-8r8r8r/deployments/3508
Vladimír Čunát [Mon, 18 Mar 2024 17:54:34 +0000 (18:54 +0100)] 
TMP: replace symlinks by contents

from knot-dns commit 033e81f81f5cc41e650eae056c4c2b5f0a61a7f8

16 months agoTMP: compile the KRU into daemon
Vladimír Čunát [Tue, 27 Feb 2024 09:09:22 +0000 (10:09 +0100)] 
TMP: compile the KRU into daemon

Meant for TMP easier development - you need to symlink daemon/rrl/knot
to knot-dns source, as the KRU source files will be taken from there.

16 months agoWIP: add contrib/openbsd/siphash.*
Vladimír Čunát [Tue, 27 Feb 2024 09:06:29 +0000 (10:06 +0100)] 
WIP: add contrib/openbsd/siphash.*

The same as knot-dns, except for dropping memzero() after hashing.

16 months agoMerge branch 'doc-move-pages' into '6.0' docs-develop-6-0-mvwoqi/deployments/3498
Oto Šťáva [Mon, 18 Mar 2024 09:56:44 +0000 (10:56 +0100)] 
Merge branch 'doc-move-pages' into '6.0'

remove `doc-dev` directory, merge into `doc/dev`

See merge request knot/knot-resolver!1515

16 months agoremove `doc-dev` directory, merge into `doc/dev` docs-develop-doc-nqguk5/deployments/3497
Oto Šťáva [Mon, 18 Mar 2024 09:38:48 +0000 (10:38 +0100)] 
remove `doc-dev` directory, merge into `doc/dev`

16 months agoMerge branch 'doc-separation' into '6.0' docs-develop-6-0-mvwoqi/deployments/3482
Oto Šťáva [Fri, 15 Mar 2024 15:11:58 +0000 (16:11 +0100)] 
Merge branch 'doc-separation' into '6.0'

Separate user and developer documentation

See merge request knot/knot-resolver!1514

16 months agodoc: better headings docs-develop-doc-nc674f/deployments/3481
Oto Šťáva [Fri, 15 Mar 2024 14:57:38 +0000 (15:57 +0100)] 
doc: better headings

16 months agoNEWS update
Oto Šťáva [Fri, 15 Mar 2024 13:55:44 +0000 (14:55 +0100)] 
NEWS update

16 months agodoc: various fixes
Oto Šťáva [Fri, 15 Mar 2024 13:24:29 +0000 (14:24 +0100)] 
doc: various fixes

Fix cross-references, heading levels, etc.

16 months agodoc/user: installation update
Aleš Mrázek [Fri, 19 Jan 2024 16:15:06 +0000 (17:15 +0100)] 
doc/user:  installation update

16 months agodoc/dev/index: add backlink to the user docs + warning
Oto Šťáva [Fri, 15 Mar 2024 10:45:46 +0000 (11:45 +0100)] 
doc/dev/index: add backlink to the user docs + warning

16 months agodoc/dev/build: add missing article
Oto Šťáva [Fri, 15 Mar 2024 10:44:54 +0000 (11:44 +0100)] 
doc/dev/build: add missing article

16 months agodoc: separate user and developer documentation
Aleš Mrázek [Mon, 15 Jan 2024 22:19:47 +0000 (23:19 +0100)] 
doc: separate user and developer documentation

This separates the documentation into a *blue* user documentation and a
*red* developer documentation, resolving problems where similar sections
collided in search queries, leading users to the advanced Lua config
documentation instead of the preferred declarative config one.

It also visually separates the two parts, so that users who do not wish
to meddle in Lua immediately see that they're somewhere wrong just by
seeing the red colour.

16 months agoMerge branch 'manager-install-config' into '6.0' docs-develop-6-0-mvwoqi/deployments/3461
Oto Šťáva [Wed, 13 Mar 2024 09:57:57 +0000 (10:57 +0100)] 
Merge branch 'manager-install-config' into '6.0'

python: expose prefix configuration as a module

See merge request knot/knot-resolver!1511

16 months agopython: expose prefix configuration as a module docs-develop-mana-huiulj/deployments/3460
Oto Šťáva [Fri, 1 Mar 2024 09:13:08 +0000 (10:13 +0100)] 
python: expose prefix configuration as a module

16 months agoMerge !1508: lib/dnssec: dnskey nits docs-develop-6-0-mvwoqi/deployments/3447
Vladimír Čunát [Mon, 11 Mar 2024 12:43:22 +0000 (13:43 +0100)] 
Merge !1508: lib/dnssec: dnskey nits

16 months agodocs: fix typo in an option name docs-develop-6-0-mvwoqi/deployments/3444
Vladimír Čunát [Mon, 11 Mar 2024 06:09:53 +0000 (07:09 +0100)] 
docs: fix typo in an option name

Reported on chat:
https://matrix.to/#/!yEaUZSBVTYRlULEqON:gitter.im/$ZXYw2v_QnbgIiP83lNtBiBptiJxqcXPKe4GI47tI86E?via=gitter.im&via=matrix.org&via=kack.it

16 months agolib/dnssec nit: reverse order of validating a DNSKEY set docs-develop-dnsk-496k20/deployments/3414
Vladimír Čunát [Mon, 4 Mar 2024 18:59:54 +0000 (19:59 +0100)] 
lib/dnssec nit: reverse order of validating a DNSKEY set

Suggested by Libor Peltan.

16 months agolib/dnssec: refactor kr_dnssec_key_*
Vladimír Čunát [Mon, 4 Mar 2024 18:20:37 +0000 (19:20 +0100)] 
lib/dnssec: refactor kr_dnssec_key_*

- The "ksk" and "zsk" in names were confusing,
  as they did NOT match the normal terms of KSK and ZSK.
- Add _usable() as a more useful function than _zsk() was.
- don't use 16-bit flag-sets; it's way easier to extract on byte level
- use inline for the simplified code

17 months agoMerge branch 'forward-auth-port' into '6.0' docs-develop-6-0-mvwoqi/deployments/3352 docs-develop-mana-huiulj/deployments/3354
Aleš Mrázek [Mon, 26 Feb 2024 12:05:54 +0000 (13:05 +0100)] 
Merge branch 'forward-auth-port' into '6.0'

forwarding to authoritative servers doesn't allow overriding ports

See merge request knot/knot-resolver!1505

17 months agodatamodel: forward: custom port and TLS are not supported for authoritative servers docs-develop-forw-z27d9j/deployments/3351
Aleš Mrázek [Fri, 23 Feb 2024 18:22:22 +0000 (19:22 +0100)] 
datamodel: forward: custom port and TLS are not supported for authoritative servers

17 months agodocument limitation of forwarding to authoritative servers
Vladimír Čunát [Fri, 23 Feb 2024 08:13:54 +0000 (09:13 +0100)] 
document limitation of forwarding to authoritative servers

17 months agoMerge !1504: kresctl: timeout for http request docs-develop-6-0-mvwoqi/deployments/3318
Vladimír Čunát [Wed, 21 Feb 2024 14:07:00 +0000 (15:07 +0100)] 
Merge !1504: kresctl: timeout for http request

17 months agoNEWS update docs-develop-kres-hedyoz/deployments/3317
Aleš Mrázek [Wed, 21 Feb 2024 14:05:44 +0000 (15:05 +0100)] 
NEWS update

17 months agoutils/request.py: higher timeout for http request docs-develop-kres-hedyoz/deployments/3316
Aleš Mrázek [Tue, 20 Feb 2024 17:29:21 +0000 (18:29 +0100)] 
utils/request.py: higher timeout for http request

17 months agoMerge branch 'python3.12-support' into '6.0' docs-develop-6-0-mvwoqi/deployments/3305
Aleš Mrázek [Tue, 20 Feb 2024 13:44:54 +0000 (14:44 +0100)] 
Merge branch 'python3.12-support' into '6.0'

manager: poetry: support for python 3.12

See merge request knot/knot-resolver!1502

17 months agomanager: update Python versions docs-develop-pyth-8k41w4/deployments/3304
Oto Šťáva [Tue, 20 Feb 2024 10:31:20 +0000 (11:31 +0100)] 
manager: update Python versions

Use the oldest supported Python by default again, since that ensures our
compatibility. Also, remove explicit Python versions from README to
avoid duplication - `pyenv install` just installs the versions that are
already in `.python-version`, so let's leverage that.

17 months agolint: fixes for new versions of tools
Aleš Mrázek [Mon, 19 Feb 2024 15:25:56 +0000 (16:25 +0100)] 
lint: fixes for new versions of tools

17 months agomanager: ci: switch to python 3.12
Aleš Mrázek [Mon, 19 Feb 2024 15:16:04 +0000 (16:16 +0100)] 
manager: ci:  switch to python 3.12

17 months agopoetry: support for python 3.12
Aleš Mrázek [Mon, 19 Feb 2024 15:14:40 +0000 (16:14 +0100)] 
poetry: support for python 3.12

- poetry: upgrade to 1.7.1
- poetry: python 3.7 support removed
- poetry: unnecessary tox tool removed
- poetry: deps version update

17 months agoMerge !1500: datamodel: support interface names with dashes docs-develop-6-0-mvwoqi/deployments/3295
Vladimír Čunát [Mon, 19 Feb 2024 09:34:55 +0000 (10:34 +0100)] 
Merge !1500: datamodel: support interface names with dashes

Fixes #900

17 months agodatamodel: support interface names with dashes docs-develop-inte-3so3h3/deployments/3294
Vladimír Čunát [Mon, 19 Feb 2024 09:02:55 +0000 (10:02 +0100)] 
datamodel: support interface names with dashes

Dashes can't be present in normal identifiers in Lua,
so we switch to a different syntactic sugar for the same thing.

17 months agoMerge branch 'manager-nits' into '6.0' docs-develop-6-0-mvwoqi/deployments/3274
Oto Šťáva [Fri, 16 Feb 2024 10:07:09 +0000 (11:07 +0100)] 
Merge branch 'manager-nits' into '6.0'

manager: nits, cleanups, fixes

See merge request knot/knot-resolver!1496

17 months agomanager: get rid of old linters and clean-up some warnings docs-develop-mana-s0qkcd/deployments/3273
Oto Šťáva [Mon, 5 Feb 2024 16:38:18 +0000 (17:38 +0100)] 
manager: get rid of old linters and clean-up some warnings

Removes references to pyright, which is not in use anymore. Also removes
warning suppressions and instead properly resolves the warnings.

17 months agomanager: move `build.py` to `build_c_extensions.py`
Oto Šťáva [Mon, 5 Feb 2024 16:03:44 +0000 (17:03 +0100)] 
manager: move `build.py` to `build_c_extensions.py`

This fixes a problem on some systems, where the `build.py` file
conflicts with the `build` module required by Poetry.

See <https://github.com/python-poetry/poetry/issues/7576>.

17 months agomanager: have pyenv prefer the latest Python version instead of the oldest
Oto Šťáva [Mon, 5 Feb 2024 16:02:41 +0000 (17:02 +0100)] 
manager: have pyenv prefer the latest Python version instead of the oldest

17 months agoMerge branch 'manager-api-cache-clear' into '6.0' docs-develop-6-0-mvwoqi/deployments/3268
Oto Šťáva [Thu, 15 Feb 2024 12:38:40 +0000 (13:38 +0100)] 
Merge branch 'manager-api-cache-clear' into '6.0'

manager: cache-clear command via HTTP API

Closes #876

See merge request knot/knot-resolver!1491

17 months agomanager/tests: validate JSON output from "kresctl cache clear --json" command docs-develop-mana-zr2tn9/deployments/3267
Aleš Mrázek [Thu, 15 Feb 2024 11:10:08 +0000 (12:10 +0100)] 
manager/tests: validate JSON output from "kresctl cache clear --json" command

17 months agokresctl: config: reduction of duplicate code related to the data parsing
Aleš Mrázek [Fri, 9 Feb 2024 15:05:37 +0000 (16:05 +0100)] 
kresctl: config: reduction of duplicate code related to the data parsing

- set: there is no need to specify the input data format
- get: YAML is now the default format for output data

17 months agokresctl: cache command: output formats for 'clear' operation
Aleš Mrázek [Fri, 9 Feb 2024 15:05:05 +0000 (16:05 +0100)] 
kresctl: cache command: output formats for 'clear' operation

17 months agomodeling: parsing: data dump from instances of class 'Renamed'
Aleš Mrázek [Fri, 9 Feb 2024 15:04:07 +0000 (16:04 +0100)] 
modeling: parsing: data dump from instances of class 'Renamed'

17 months agomanager: use proper JSON values for socket communication
Oto Šťáva [Fri, 9 Feb 2024 09:55:17 +0000 (10:55 +0100)] 
manager: use proper JSON values for socket communication

This commit adds a special JSON mode for control sockets.

The mode is activated by issuing a special `__json` command to the
socket, resulting in all Lua objects returned by all subsequent commands
to be serialized into JSONs, prepended by a 32-bit unsigned integer
byte-length value.

This JSON mode is now exclusively utilized by Manager, removing the need
to hackily strip single-quotes from the output and to read the output by
lines. Instead, it can always just read the 32-bit length value and
subsequently the whole JSON-formatted message, which is now
automatically deserialized into a Python object.

17 months ago'cache-clear' remade to 'cache/clear'
Aleš Mrázek [Tue, 6 Feb 2024 13:00:06 +0000 (14:00 +0100)] 
'cache-clear' remade to 'cache/clear'

17 months agonaming: replacing 'kids' suffix with 'kresids' for clarification
Aleš Mrázek [Mon, 5 Feb 2024 15:15:58 +0000 (16:15 +0100)] 
naming: replacing 'kids' suffix with 'kresids' for clarification

17 months agodoc: cache clearing
Aleš Mrázek [Mon, 29 Jan 2024 15:42:18 +0000 (16:42 +0100)] 
doc: cache clearing

17 months agomanager/tests: simple test for /cache-clear API endpoint
Aleš Mrázek [Mon, 29 Jan 2024 14:19:58 +0000 (15:19 +0100)] 
manager/tests: simple test for /cache-clear API endpoint

17 months agodoc/manager-client.rst: 'cache-clear' command added
Aleš Mrázek [Mon, 29 Jan 2024 14:09:28 +0000 (15:09 +0100)] 
doc/manager-client.rst: 'cache-clear' command added

17 months agoapi: cache-clear: validate data, render lua and send cmd
Aleš Mrázek [Mon, 22 Jan 2024 20:41:31 +0000 (21:41 +0100)] 
api: cache-clear: validate data, render lua and send cmd

17 months agodatamodel: schema and template for cache-clear command
Aleš Mrázek [Mon, 22 Jan 2024 20:36:46 +0000 (21:36 +0100)] 
datamodel: schema and template for cache-clear command

17 months agoapi: added cache-clear route
Aleš Mrázek [Mon, 22 Jan 2024 13:37:36 +0000 (14:37 +0100)] 
api: added cache-clear route

17 months agodatamodel: moving the main jinja template loader to the templates dir
Aleš Mrázek [Mon, 22 Jan 2024 13:02:00 +0000 (14:02 +0100)] 
datamodel: moving the main jinja template loader to the templates dir

17 months agocontroller: moving workers registration helpers out of the statistics module
Aleš Mrázek [Mon, 22 Jan 2024 12:57:10 +0000 (13:57 +0100)] 
controller: moving workers registration  helpers out of the statistics module

17 months agokresctl: 'cache-clear' command created
Aleš Mrázek [Tue, 14 Nov 2023 13:04:29 +0000 (14:04 +0100)] 
kresctl: 'cache-clear' command created

17 months agoMerge branch 'release-6.0.6' into 6.0 docs-develop-6-0-mvwoqi/deployments/3245 docs-release-v6-0-xz313r/deployments/3247 v6.0.6
Vladimír Čunát [Tue, 13 Feb 2024 13:17:57 +0000 (14:17 +0100)] 
Merge branch 'release-6.0.6' into 6.0

17 months agoRelease 6.0.6 docs-develop-rele-ilc2tz/deployments/3244
Vladimír Čunát [Tue, 13 Feb 2024 13:05:13 +0000 (14:05 +0100)] 
Release 6.0.6

17 months agoAUTHORS update
Vladimír Čunát [Tue, 13 Feb 2024 13:17:07 +0000 (14:17 +0100)] 
AUTHORS update

17 months agoMerge !1497: lib/dnssec: allow validating some RRsets around 64 KiB size docs-develop-6-0-mvwoqi/deployments/3243
Vladimír Čunát [Tue, 13 Feb 2024 13:09:56 +0000 (14:09 +0100)] 
Merge !1497: lib/dnssec: allow validating some RRsets around 64 KiB size

17 months agolib/dnssec: allow validating some RRsets around 64 KiB size
Vladimír Čunát [Tue, 6 Feb 2024 08:41:04 +0000 (09:41 +0100)] 
lib/dnssec: allow validating some RRsets around 64 KiB size

- only with libknot >= 3.4 though (which is not released yet)
- use stack instead of static buffer (saves RAM; see code comment)

17 months agoNEWS for 6.0.6
Vladimír Čunát [Tue, 13 Feb 2024 12:32:32 +0000 (13:32 +0100)] 
NEWS for 6.0.6

17 months agoMerge branch 'master' into dos-feb13-6.0 docs-develop-dos-hama3x/deployments/3237
Vladimír Čunát [Tue, 13 Feb 2024 12:12:41 +0000 (13:12 +0100)] 
Merge branch 'master' into dos-feb13-6.0

There were some nontrivial conflicts to resolve, NEWS + the line
    ctx->vld_limit_crypto = KR_VLD_LIMIT_CRYPTO_DEFAULT;
(I had this resolution prepared for a long time.)

17 months agorelease 5.7.1 docs-develop-mast-tzgd0f/deployments/3233 docs-develop-mast-tzgd0f/deployments/3239 docs-develop-mast-tzgd0f/deployments/3249 docs-develop-mast-tzgd0f/deployments/3252 docs-develop-mast-tzgd0f/deployments/3256 docs-develop-mast-tzgd0f/deployments/3259 docs-develop-mast-tzgd0f/deployments/3269 docs-develop-mast-tzgd0f/deployments/3272 docs-develop-mast-tzgd0f/deployments/3278 docs-develop-mast-tzgd0f/deployments/3281 docs-develop-mast-tzgd0f/deployments/3282 docs-develop-mast-tzgd0f/deployments/3285 docs-develop-mast-tzgd0f/deployments/3286 docs-develop-mast-tzgd0f/deployments/3289 docs-develop-mast-tzgd0f/deployments/3299 docs-develop-mast-tzgd0f/deployments/3302 docs-develop-mast-tzgd0f/deployments/3307 docs-develop-mast-tzgd0f/deployments/3310 docs-develop-mast-tzgd0f/deployments/3319 docs-develop-mast-tzgd0f/deployments/3322 docs-develop-mast-tzgd0f/deployments/3324 docs-develop-mast-tzgd0f/deployments/3327 docs-develop-nigh-589znp/deployments/3250 docs-develop-nigh-589znp/deployments/3257 docs-develop-nigh-589znp/deployments/3270 docs-develop-nigh-589znp/deployments/3279 docs-develop-nigh-589znp/deployments/3283 docs-develop-nigh-589znp/deployments/3287 docs-develop-nigh-589znp/deployments/3300 docs-develop-nigh-589znp/deployments/3308 docs-develop-nigh-589znp/deployments/3320 docs-develop-nigh-589znp/deployments/3325 docs-develop-stab-lrl9qw/deployments/3253 docs-release-v5-7-svl2lq/deployments/3235 v5.7.1
Aleš Mrázek [Tue, 13 Feb 2024 09:08:04 +0000 (10:08 +0100)] 
release 5.7.1

17 months agoMerge: mitigate CVE-2023-50387 "KeyTrap" docs-develop-mast-tzgd0f/deployments/3232
Vladimír Čunát [Tue, 13 Feb 2024 11:43:16 +0000 (12:43 +0100)] 
Merge: mitigate CVE-2023-50387 "KeyTrap"

DNSSEC verification complexity could be exploited to exhaust CPU resources and stall DNS resolvers.

Solution boils down mainly to limiting crypto-validations per packet.

17 months agoupdate NEWS with KeyTrap
Vladimír Čunát [Mon, 1 Jan 2024 15:25:05 +0000 (16:25 +0100)] 
update NEWS with KeyTrap

in a separate commit, as it will tend to conflict if patching

17 months agomitigate KeyTrap DoS = CVE-2023-50387
Vladimír Čunát [Tue, 16 Jan 2024 06:35:20 +0000 (07:35 +0100)] 
mitigate KeyTrap DoS = CVE-2023-50387

Improve: don't retry in this case.

17 months agomitigate KeyTrap DoS = CVE-2023-50387
Vladimír Čunát [Mon, 1 Jan 2024 15:21:10 +0000 (16:21 +0100)] 
mitigate KeyTrap DoS = CVE-2023-50387

17 months agolib/resolve kr_request_set_extended_error(): tweak priorities
Vladimír Čunát [Mon, 1 Jan 2024 15:05:46 +0000 (16:05 +0100)] 
lib/resolve kr_request_set_extended_error(): tweak priorities

Keep the first error in case priorities are equal.

At least with the current KeyTrap topic that should work better,
but blaming a single error is alchemy anyway, at least in some cases.

17 months agolib/dnssec kr_rrset_validate_with_key(): deduplicate cleanup
Vladimír Čunát [Sat, 30 Dec 2023 08:20:56 +0000 (09:20 +0100)] 
lib/dnssec kr_rrset_validate_with_key(): deduplicate cleanup

17 months agoMerge CVE-2023-50868: NSEC3 closest encloser proof can exhaust CPU
Vladimír Čunát [Tue, 13 Feb 2024 08:46:09 +0000 (09:46 +0100)] 
Merge CVE-2023-50868: NSEC3 closest encloser proof can exhaust CPU

17 months agoMerge branch 'master' into 6.0 docs-develop-6-0-mvwoqi/deployments/3227
Vladimír Čunát [Mon, 12 Feb 2024 13:06:28 +0000 (14:06 +0100)] 
Merge branch 'master' into 6.0

There were some conflicts with !1495

17 months agovalidator: compatibility with older libknot versions
Vladimír Čunát [Mon, 12 Feb 2024 10:30:50 +0000 (11:30 +0100)] 
validator: compatibility with older libknot versions

The value is in IANA registry, so it's very constant anyway.

17 months agoadd NEWS for NSEC3 mitigations from the previous few commits
Vladimír Čunát [Mon, 12 Feb 2024 10:23:42 +0000 (11:23 +0100)] 
add NEWS for NSEC3 mitigations from the previous few commits

17 months agovalidator: refuse to validate answers with more than 8 NSEC3 records
Vladimír Čunát [Mon, 12 Feb 2024 10:16:47 +0000 (11:16 +0100)] 
validator: refuse to validate answers with more than 8 NSEC3 records

17 months agovalidator: limit the amount of work on SHA1 in NSEC3 proofs
Vladimír Čunát [Mon, 12 Feb 2024 10:16:37 +0000 (11:16 +0100)] 
validator: limit the amount of work on SHA1 in NSEC3 proofs

17 months agolib/cache: limit the amount of work on SHA1
Vladimír Čunát [Sun, 11 Feb 2024 09:00:32 +0000 (10:00 +0100)] 
lib/cache: limit the amount of work on SHA1

That's when searching NSEC3 aggressive cache.