]>
git.ipfire.org Git - thirdparty/unbound.git/log
George Thessalonikefs [Fri, 17 Apr 2020 09:33:12 +0000 (11:33 +0200)]
- Enable SNI by default in unbound-anchor.
George Thessalonikefs [Fri, 17 Apr 2020 09:27:39 +0000 (11:27 +0200)]
Revert "- Remove SNI support from unbound-anchor; TLS is used only for"
This reverts commit
9d197eb11061c2a7d805c9de5f411b425a030f05 .
Server-side software may use SNI to pick the correct virtual host.
George Thessalonikefs [Fri, 17 Apr 2020 08:42:58 +0000 (10:42 +0200)]
- Remove SNI support from unbound-anchor; TLS is used only for
encryption and not validation.
George Thessalonikefs [Thu, 16 Apr 2020 11:48:47 +0000 (13:48 +0200)]
- Add SNI support on more TLS connections (fixes #193).
- Add SNI support to unbound-anchor.
George Thessalonikefs [Wed, 15 Apr 2020 15:57:02 +0000 (17:57 +0200)]
- Fix #220: auth-zone section in config may lead to segfault.
W.C.A. Wijngaards [Tue, 7 Apr 2020 11:49:25 +0000 (13:49 +0200)]
- Merge PR #214 from gearnode: unbound-control-setup recreate
certificates. With the -r option the certificates are created
again, without it, only the files that do not exist are created.
Wouter Wijngaards [Tue, 7 Apr 2020 11:48:54 +0000 (13:48 +0200)]
Merge pull request #214 from gearnode/idempotent-nsd-unbound-setup
unbound-control-setup recreate certificates
Gearnode [Tue, 7 Apr 2020 11:19:36 +0000 (13:19 +0200)]
fix unbound-control-setup is not idempotent
Ralph Dolmans [Mon, 6 Apr 2020 16:00:06 +0000 (18:00 +0200)]
- Keep track of number of timeouts. Use this counter to determine if capsforid
fallback should be started.
George Thessalonikefs [Mon, 6 Apr 2020 10:32:18 +0000 (12:32 +0200)]
- More documentation for redis-expire-records option.
George Thessalonikefs [Wed, 1 Apr 2020 15:22:38 +0000 (17:22 +0200)]
Merge branch 'Talkabout-redis-expire-records'
George Thessalonikefs [Wed, 1 Apr 2020 15:14:58 +0000 (17:14 +0200)]
- Changes for PR #206 (formatting and remade lex and yacc output).
George Thessalonikefs [Wed, 1 Apr 2020 14:04:48 +0000 (16:04 +0200)]
Merge branch 'master' of https://github.com/Talkabout/unbound into Talkabout-redis-expire-records
Talkabout [Wed, 1 Apr 2020 11:32:13 +0000 (13:32 +0200)]
changed init logic of redis backend as per review request
Talkabout [Tue, 31 Mar 2020 21:10:45 +0000 (23:10 +0200)]
implemented review feedback
renamed option from 'redis-set-ttl' to 'redis-expire-records'
Talkabout [Tue, 31 Mar 2020 10:47:13 +0000 (12:47 +0200)]
added option 'redis-set-ttl' to define whether ttl should be added to redis records
added check for redis command 'setex' when initializing redis connection
updated documentation
minor improvements to previous changes
W.C.A. Wijngaards [Mon, 30 Mar 2020 12:55:00 +0000 (14:55 +0200)]
- Merge PR #208: Fix uncached CLIENT_RESPONSE'es on stateful
transports.
Wouter Wijngaards [Mon, 30 Mar 2020 12:54:31 +0000 (14:54 +0200)]
Merge pull request #208 from NLnetLabs/bugfix/dnstap-client-response-on-stateful-transports
Fix uncached CLIENT_RESPONSE'es on stateful transports
Willem Toorop [Mon, 30 Mar 2020 10:19:17 +0000 (12:19 +0200)]
Send tcp_req_info->spool_buffer as dnstap CLIENT_RESPONSE
When tcp_req_info exists. This fixes that dnstap CLIENT_RESPONSE messages did not contain the response message when answering on statful transport for uncached responses.
Willem Toorop [Mon, 30 Mar 2020 09:39:07 +0000 (11:39 +0200)]
Fix uncached CLIENT_RESPONSE'es on stateful transports
Because repinfo->c->buffer does not contain the response when the it did not came from cache.
Only after tcp_req_info_send_reply is called, is the response on the buffer which is used to fill the dnstap protobuf's.
W.C.A. Wijngaards [Mon, 30 Mar 2020 08:29:15 +0000 (10:29 +0200)]
nroff fix for dash.
W.C.A. Wijngaards [Mon, 30 Mar 2020 08:27:44 +0000 (10:27 +0200)]
- Merge PR #207: Clarify if-automatic listens on 0.0.0.0 and ::
Wouter Wijngaards [Mon, 30 Mar 2020 08:27:14 +0000 (10:27 +0200)]
Merge pull request #207 from NLnetLabs/maintenance/if-transparent-doc
Clarify if-automatic listens on 0.0.0.0 and ::
Willem Toorop [Mon, 30 Mar 2020 08:07:25 +0000 (10:07 +0200)]
Clarify if-automatic listens on 0.0.0.0 and ::
Talkabout [Sun, 29 Mar 2020 21:53:01 +0000 (23:53 +0200)]
honor 'server_expired_ttl' in redis
Talkabout [Sun, 29 Mar 2020 13:23:13 +0000 (15:23 +0200)]
Merge branch 'master' of https://github.com/Talkabout/unbound
Talkabout [Sun, 29 Mar 2020 13:22:10 +0000 (15:22 +0200)]
added logic for redis to honor ttl when serve_expired is not enabled
W.C.A. Wijngaards [Fri, 27 Mar 2020 15:07:03 +0000 (16:07 +0100)]
Changelog note for PR #203.
- Merge PR #203 from noloader: Update README-Travis.md with current
procedures.
Wouter Wijngaards [Fri, 27 Mar 2020 15:06:31 +0000 (16:06 +0100)]
Merge pull request #203 from noloader/master
Update README-Travis.md with current procedures
Ralph Dolmans [Fri, 27 Mar 2020 10:27:12 +0000 (11:27 +0100)]
Make unbound-control error returned on missing domain name more user friendly.
Jeffrey Walton [Thu, 26 Mar 2020 23:57:58 +0000 (19:57 -0400)]
Update README-Travis.md with current procedures
Ralph Dolmans [Thu, 26 Mar 2020 18:11:57 +0000 (19:11 +0100)]
- Fix RPZ concurrency issue when using auth_zone_reload.
George Thessalonikefs [Wed, 25 Mar 2020 13:10:27 +0000 (14:10 +0100)]
Changelog entry for #201
- Merge PR #201 from noloader: Fix OpenSSL cross-compaile warnings.
George Thessalonikefs [Wed, 25 Mar 2020 12:59:51 +0000 (13:59 +0100)]
Merge branch 'noloader-android'
George Thessalonikefs [Wed, 25 Mar 2020 12:58:40 +0000 (13:58 +0100)]
- Keep 'arm64-v8a' support for Travis android builds.
Jeffrey Walton [Wed, 25 Mar 2020 09:00:35 +0000 (05:00 -0400)]
Fix OpenSSL corss-compaile warning
warning: '__ANDROID_API__' macro redefined
W.C.A. Wijngaards [Tue, 24 Mar 2020 09:23:00 +0000 (10:23 +0100)]
- Travis fix for ios by omitting tools from install.
W.C.A. Wijngaards [Tue, 24 Mar 2020 08:36:27 +0000 (09:36 +0100)]
- Fixes for #200 : example.conf note and set_value for ip-dscp.
W.C.A. Wijngaards [Tue, 24 Mar 2020 08:32:04 +0000 (09:32 +0100)]
- Fixes on #200. and rerun autoconf.
W.C.A. Wijngaards [Tue, 24 Mar 2020 08:25:05 +0000 (09:25 +0100)]
Changelog for #200 and bison, flex regenerate.
- Merge PR #200 from yarikk: add ip-dscp option to specify the DSCP
tag for outgoing packets.
Wouter Wijngaards [Tue, 24 Mar 2020 08:24:16 +0000 (09:24 +0100)]
Merge pull request #200 from yarikk/ipdiffserv
add ip-dscp option to specify the DSCP tag for outgoing packets
Yaroslav K [Wed, 26 Feb 2020 20:58:13 +0000 (12:58 -0800)]
add setting IP DiffServ Codepoint (DSCP, previously TOS) on sockets
Yaroslav K [Wed, 4 Mar 2020 19:02:16 +0000 (11:02 -0800)]
add ip-dscp configuration option for setting IP DiffServ codepoint (DSCP, previously TOS) on sockets
W.C.A. Wijngaards [Mon, 23 Mar 2020 16:26:06 +0000 (17:26 +0100)]
- Fix compile on Solaris for unbound-checkconf.
George Thessalonikefs [Fri, 20 Mar 2020 12:06:43 +0000 (13:06 +0100)]
- Changelog note for PR #198: Declare lz_enter_rr_into_zone() static,
it's only used in this file, by fobser.
gthess [Fri, 20 Mar 2020 12:04:09 +0000 (13:04 +0100)]
Merge pull request #198 from fobser/missing_prototype
Declare lz_enter_rr_into_zone() static, it's only used in this file.
W.C.A. Wijngaards [Fri, 20 Mar 2020 10:54:57 +0000 (11:54 +0100)]
Changelog note for #197.
- Merge PR #197 from fobser: Make log_ident_revert_to_default() a
proper prototype.
Wouter Wijngaards [Fri, 20 Mar 2020 10:54:39 +0000 (11:54 +0100)]
Merge pull request #197 from fobser/proper_prototype
Make log_ident_revert_to_default() a proper prototype.
Florian Obser [Fri, 20 Mar 2020 10:53:13 +0000 (11:53 +0100)]
Declare lz_enter_rr_into_zone() static, it's only used in this file.
Pointed out by clang with -Wmissing-prototypes
Florian Obser [Fri, 20 Mar 2020 10:44:38 +0000 (11:44 +0100)]
Make log_ident_revert_to_default() a proper prototype.
Pointed out by clang with -Wstrict-prototypes.
Ralph Dolmans [Thu, 19 Mar 2020 17:11:22 +0000 (18:11 +0100)]
- Fix .travis.yml error, missing 'env' option.
Ralph Dolmans [Thu, 19 Mar 2020 16:59:08 +0000 (17:59 +0100)]
- Merge PR#194: Add libevent testing to Travis, by Jeffrey Walton.
Ralph Dolmans [Thu, 19 Mar 2020 16:58:01 +0000 (17:58 +0100)]
Merge branch 'noloader-libevent'
Ralph Dolmans [Thu, 19 Mar 2020 16:57:35 +0000 (17:57 +0100)]
Merge branch 'libevent' of https://github.com/noloader/unbound into noloader-libevent
Ralph Dolmans [Thu, 19 Mar 2020 16:38:09 +0000 (17:38 +0100)]
Merge branch 'fobser-kernel-random-port'
Ralph Dolmans [Thu, 19 Mar 2020 16:37:27 +0000 (17:37 +0100)]
Add changelog entries for PR#134.
Ralph Dolmans [Thu, 19 Mar 2020 16:34:46 +0000 (17:34 +0100)]
- Log warning when using outgoing-port-permit and outgoing-port-avoid
while explicit port randomisation is disabled.
Ralph Dolmans [Thu, 19 Mar 2020 14:48:12 +0000 (15:48 +0100)]
Merge branch 'kernel-random-port' of https://github.com/fobser/unbound into fobser-kernel-random-port
Ralph Dolmans [Thu, 19 Mar 2020 13:00:33 +0000 (14:00 +0100)]
- Fix #158: open tls-session-ticket-keys as binary, for Windows. By Daisuke
HIGASHI.
Ralph Dolmans [Thu, 19 Mar 2020 09:55:55 +0000 (10:55 +0100)]
Merge branch 'noloader-ios'
Ralph Dolmans [Thu, 19 Mar 2020 09:55:39 +0000 (10:55 +0100)]
- Merge PR#191: Update iOS testing on Travis, by Jeffrey Walton.
Jeffrey Walton [Tue, 17 Mar 2020 10:46:18 +0000 (06:46 -0400)]
Add libevent testing to Travis
Jeffrey Walton [Tue, 17 Mar 2020 10:32:13 +0000 (06:32 -0400)]
Sync with upstream
W.C.A. Wijngaards [Mon, 16 Mar 2020 08:44:38 +0000 (09:44 +0100)]
- Fix #192: In the unbound-checkconf tool, the module config of
dns64 subnetcache respip validator iterator is whitelisted, it was
reported it seems to work.
Wouter Wijngaards [Thu, 12 Mar 2020 09:49:24 +0000 (10:49 +0100)]
- Fix compile of test tools without protobuf.
Ralph Dolmans [Wed, 11 Mar 2020 16:37:50 +0000 (17:37 +0100)]
- Add check to make sure RPZ records are subdomain of configured zone origin.
George Thessalonikefs [Wed, 11 Mar 2020 10:50:38 +0000 (11:50 +0100)]
- Changelog entry for (Fix #189, Merge PR #190).
gthess [Wed, 11 Mar 2020 10:45:16 +0000 (11:45 +0100)]
Merge pull request #190 from noloader/netbsd
Fix NetBSD compile (GH #189)
W.C.A. Wijngaards [Wed, 11 Mar 2020 07:41:56 +0000 (08:41 +0100)]
Changelog for #188 and configure script created. Removed unneeded whitespace.
W.C.A. Wijngaards [Wed, 11 Mar 2020 07:39:48 +0000 (08:39 +0100)]
Fix #188: unbound-control.c:882:6: error: 'execlp' is unavailable: not available on tvOS
Jeffrey Walton [Wed, 11 Mar 2020 07:35:28 +0000 (03:35 -0400)]
Fix NetBSD compile (GH #189)
George Thessalonikefs [Fri, 6 Mar 2020 11:01:05 +0000 (12:01 +0100)]
Merge branch 'noloader-makefile'
George Thessalonikefs [Fri, 6 Mar 2020 10:59:13 +0000 (11:59 +0100)]
- Changelog note for PR #186: Fix unrecognized 'echo -n' option on OS X,
by noloader.
Jeffrey Walton [Thu, 5 Mar 2020 19:53:08 +0000 (14:53 -0500)]
Fix unrecognized 'echo -n' option on OS X
Also see https://github.com/NLnetLabs/unbound/issues/183.
This PR also updates a few typos in README-Travis.md, and expands the discussion of PKG_CONFIG_PATH for those who are not familiar with it.
W.C.A. Wijngaards [Thu, 5 Mar 2020 16:03:28 +0000 (17:03 +0100)]
Fix changelog note, it is #182, not #184.
W.C.A. Wijngaards [Thu, 5 Mar 2020 16:02:20 +0000 (17:02 +0100)]
Changelog note for #184.
- Fix PR #184 from noloader: Add iOS testing to Travis.
Wouter Wijngaards [Thu, 5 Mar 2020 16:01:59 +0000 (17:01 +0100)]
Merge pull request #182 from noloader/ios
Add iOS testing to Travis
Jeffrey Walton [Wed, 4 Mar 2020 17:03:20 +0000 (12:03 -0500)]
Add iOS testing to Travis
Ralph Dolmans [Wed, 4 Mar 2020 11:02:10 +0000 (12:02 +0100)]
- Update README-Travis.md (from PR #179), by Jeffrey Walton.
George Thessalonikefs [Wed, 4 Mar 2020 09:24:47 +0000 (10:24 +0100)]
- Merge PR #180 from noloader: Avoid calling exit in Travis script.
gthess [Wed, 4 Mar 2020 09:22:23 +0000 (10:22 +0100)]
Merge pull request #181 from noloader/openssl-pie
Fix OpenSSL -pie warning on Android
W.C.A. Wijngaards [Wed, 4 Mar 2020 07:18:00 +0000 (08:18 +0100)]
Changelog note for PR#180 .
- Merge PR#180 from noloader: Avoid calling exit in Travis script.
Wouter Wijngaards [Wed, 4 Mar 2020 07:17:39 +0000 (08:17 +0100)]
Merge pull request #180 from noloader/travis
Avoid calling exit in Travis script
Jeffrey Walton [Tue, 3 Mar 2020 21:25:25 +0000 (16:25 -0500)]
Test OpenSSL -pie changes
See https://github.com/openssl/openssl/issues/11237
Jeffrey Walton [Tue, 3 Mar 2020 19:01:06 +0000 (14:01 -0500)]
Avoid calling exit in Travis script
The Travis docs state it should not be done. Blame Jeffrey Walton. Sorry about that.
George Thessalonikefs [Tue, 3 Mar 2020 17:29:11 +0000 (18:29 +0100)]
- Upgrade config.guess(2020-01-01) and config.sub(2020-01-01).
George Thessalonikefs [Mon, 2 Mar 2020 15:12:51 +0000 (16:12 +0100)]
- Make contrib/android/install_openssl.sh Code of Conduct compliant.
George Thessalonikefs [Mon, 2 Mar 2020 14:22:19 +0000 (15:22 +0100)]
Merge branch 'noloader-android'
George Thessalonikefs [Mon, 2 Mar 2020 14:09:07 +0000 (15:09 +0100)]
- Merge PR #174: Add Android to Travis testing, by noloader.
- Move android build scripts to contrib/ and allow android tests to fail.
George Thessalonikefs [Mon, 2 Mar 2020 13:46:04 +0000 (14:46 +0100)]
Merge branch 'master' of https://github.com/noloader/unbound into noloader-android
Ralph Dolmans [Mon, 2 Mar 2020 13:14:25 +0000 (14:14 +0100)]
Merge branch 'noloader-openssl'
Ralph Dolmans [Mon, 2 Mar 2020 13:13:20 +0000 (14:13 +0100)]
- Add github reference in changelog (Fix #175, Merge PR #176)
Ralph Dolmans [Mon, 2 Mar 2020 13:06:10 +0000 (14:06 +0100)]
- Fix link error when OpenSSL is configured with no-engine, thanks noloader.
W.C.A. Wijngaards [Mon, 2 Mar 2020 12:33:34 +0000 (13:33 +0100)]
- Fix #177: dnstap does not build on macOS.
Willem Toorop [Mon, 2 Mar 2020 11:27:45 +0000 (12:27 +0100)]
Cleanup nettle_ecc_point when verifying for ...
... ECDSA256 with libnettle
Ralph Dolmans [Mon, 2 Mar 2020 11:23:38 +0000 (12:23 +0100)]
Merge branch 'openssl' of https://github.com/noloader/unbound into noloader-openssl
George Thessalonikefs [Mon, 2 Mar 2020 10:52:33 +0000 (11:52 +0100)]
- Fix compiler warning in dns64/dns64.c.
Jeffrey Walton [Sat, 29 Feb 2020 05:21:04 +0000 (00:21 -0500)]
Add Android to Travis testing.
Jeffrey Walton [Sat, 29 Feb 2020 18:11:29 +0000 (13:11 -0500)]
Fix link error when OpenSSL is configured with no-engine (GH #175)
W.C.A. Wijngaards [Fri, 28 Feb 2020 14:23:54 +0000 (15:23 +0100)]
Changelog note for PR #164 and text for release explanation.
- Merge PR #164: Framestreams, this branch implements dnstap
unidirectional connectivity in unbound. This has a number of
new features.
The dependency on libfstrm is removed. The fstrm protocol code
resides in dnstap/dnstap_fstrm.h and dnstap/dnstap_fstrm.c. This
contains a brief definition of what unbound needs.
The make unbound-dnstap-socket builds a debug tool,
unbound-dnstap-socket. It can listen, accept multiple DNSTAP
streams and print information. Commandline options control it.
Unbound can reconnect if the unix domain socket file socket is
closed. This uses exponential backoff after which it uses a
one second timer to throttle cpu down. There is also support
to use TCP and TLS for connecting to the log server. There
are new config options to turn them on, in the dnstap section
in the man page and example config file. dnstap-ip with IP
address of server for TCP or TLS use. dnstap-tls to turn
on TLS. And dnstap-tls-server-name, dnstap-tls-cert-bundle,
dnstap-tls-client-key-file and dnstap-tls-client-cert-file
to configure the certificates for server authentication and
client authentication, or leave at "" to not use that.