]>
git.ipfire.org Git - thirdparty/knot-dns.git/log
Libor Peltan [Tue, 12 Nov 2019 14:53:47 +0000 (15:53 +0100)]
DS push: fix removing DS rrset
Daniel Salzman [Mon, 11 Nov 2019 14:36:36 +0000 (15:36 +0100)]
dnssec: mute clang analyzer
Daniel Salzman [Mon, 11 Nov 2019 13:47:53 +0000 (14:47 +0100)]
dnssec: log keytag if rollover action failed
Daniel Salzman [Mon, 11 Nov 2019 12:33:22 +0000 (13:33 +0100)]
contrib: update LMDB to 0.9.24
Daniel Salzman [Mon, 11 Nov 2019 11:28:38 +0000 (11:28 +0000)]
Merge branch 'ci-distrotests-update' into 'master'
ci: distrotests update
See merge request knot/knot-dns!1089
Tomas Krizek [Fri, 8 Nov 2019 15:39:54 +0000 (16:39 +0100)]
distro/tests: add ubuntu1910
Tomas Krizek [Fri, 8 Nov 2019 15:36:43 +0000 (16:36 +0100)]
distro/tests: use fedora31
Tomas Krizek [Fri, 8 Nov 2019 15:32:45 +0000 (16:32 +0100)]
distro/tests: use generic/opensuse15 box
Tomas Krizek [Fri, 8 Nov 2019 15:30:57 +0000 (16:30 +0100)]
distro/tests: make ansible debug output readable
Daniel Salzman [Fri, 8 Nov 2019 15:20:48 +0000 (15:20 +0000)]
Merge branch 'glue_auth_fixes' into 'master'
Glue auth fixes
See merge request knot/knot-dns!1088
Libor Peltan [Fri, 8 Nov 2019 13:29:56 +0000 (14:29 +0100)]
adjust additionals: also changed nodes that aren't referenced by adds_reverse_tree
Libor Peltan [Fri, 8 Nov 2019 13:29:02 +0000 (14:29 +0100)]
nsec/3: adjust also unchanged node's flags as they might become auth
Daniel Salzman [Thu, 7 Nov 2019 18:22:45 +0000 (19:22 +0100)]
knot_rdataset_copy(): allow NULL source rdata if empty
Fixup for
bb0d2fb501158763f2fc417ffa902cea5b82695c
Daniel Salzman [Thu, 7 Nov 2019 14:51:30 +0000 (15:51 +0100)]
knot_rdataset_copy(): mute Clang analyzer
Vladimír Čunát [Wed, 6 Nov 2019 16:12:08 +0000 (17:12 +0100)]
knot_rdataset_add(): optimizing nitpicks
We avoid unnecessary seeking over the RRset.
Vladimír Čunát [Thu, 7 Nov 2019 07:51:50 +0000 (08:51 +0100)]
knot_rdataset_add(): optimize a bit
(while trying to keep diff small)
Daniel Salzman [Wed, 30 Oct 2019 12:27:03 +0000 (13:27 +0100)]
zone: don't log disabled flush when server shutdown or full zonedb reload
Daniel Salzman [Wed, 6 Nov 2019 16:05:58 +0000 (16:05 +0000)]
Merge branch 'fix_adjust_resalt' into 'master'
bugfix adjust: nsec3pointer and nsec3wildcard when nsec3param changed
See merge request knot/knot-dns!1087
Libor Peltan [Tue, 5 Nov 2019 16:40:17 +0000 (17:40 +0100)]
bugfix adjust: nsec3pointer and nsec3wildcard when nsec3param changed
Daniel Salzman [Tue, 5 Nov 2019 20:04:36 +0000 (21:04 +0100)]
Merge branch 'kdig_ocsp'
Daniel Salzman [Mon, 4 Nov 2019 10:06:16 +0000 (11:06 +0100)]
utils: some OCSP code refactoring
Daniel Salzman [Fri, 1 Nov 2019 13:57:36 +0000 (14:57 +0100)]
kdig: rename +[no]require-stapled +[no]tls-ocsp-stapling[=H]
Daniel Salzman [Tue, 29 Oct 2019 10:01:28 +0000 (11:01 +0100)]
utils: unify coding style of the OCSP code
Alexander Schultz [Mon, 28 Oct 2019 14:52:30 +0000 (10:52 -0400)]
Add support for requiring a valid stapled OCSP response for the server certificate when connecting via TLS.
Daniel Salzman [Tue, 5 Nov 2019 19:27:09 +0000 (20:27 +0100)]
tests: mute Clang 8 warnings
Daniel Salzman [Tue, 5 Nov 2019 15:26:20 +0000 (16:26 +0100)]
doc: update man page for knotc
Daniel Salzman [Tue, 5 Nov 2019 15:20:09 +0000 (16:20 +0100)]
doc: extend knotc zone-flush description
Libor Peltan [Wed, 23 Oct 2019 08:52:35 +0000 (10:52 +0200)]
bugfix: only mark modified nodes as safely signed...
this doesn't mean that the unchanged nodes aren't
safely checked for signatures;
we just avoid necessity to unify the nodes
with only the RRSIGS_VALID flag changed
Daniel Salzman [Fri, 1 Nov 2019 12:16:12 +0000 (13:16 +0100)]
ctl: protect zone flush to specified directory with an RCU lock
Libor Peltan [Thu, 31 Oct 2019 16:26:16 +0000 (17:26 +0100)]
nsec3params: zero flag shall be considered valid with opt-out
Daniel Salzman [Wed, 30 Oct 2019 20:44:02 +0000 (20:44 +0000)]
Merge branch 'nsec3_salt_check' into 'master'
nsec3: re-sign whole zone if salt changed
See merge request knot/knot-dns!1086
Libor Peltan [Wed, 30 Oct 2019 16:04:06 +0000 (17:04 +0100)]
nsec3: re-sign whole zone if salt changed
Daniel Salzman [Thu, 24 Oct 2019 19:26:27 +0000 (21:26 +0200)]
nsec3-chain: update function description
Daniel Salzman [Thu, 24 Oct 2019 17:13:57 +0000 (19:13 +0200)]
nsec3-chain: code cleanup
Daniel Salzman [Thu, 24 Oct 2019 07:42:47 +0000 (09:42 +0200)]
zone-update: remove redundant memory context
Libor Peltan [Thu, 24 Oct 2019 15:31:18 +0000 (17:31 +0200)]
zone update: warn if blocked by ctl zone transaction
Libor Peltan [Thu, 24 Oct 2019 12:45:39 +0000 (14:45 +0200)]
zone update: don't touch ctl transaction...
...it's blocked by COW lock anyway
...and it might lead to deadlock or memory corruption
Libor Peltan [Thu, 24 Oct 2019 12:41:40 +0000 (14:41 +0200)]
bugfix: semaphore: re-wait at semaphore if interrupted by signal
Daniel Salzman [Wed, 23 Oct 2019 16:17:55 +0000 (16:17 +0000)]
Merge branch 'fix_update_old_contents' into 'master'
zone_update: don't work with zone->contents ptr before other zone_update finished
See merge request knot/knot-dns!1082
Libor Peltan [Wed, 23 Oct 2019 13:45:11 +0000 (15:45 +0200)]
zone_update: don't work with zone->contents ptr before other zone_update finished
Jan Hák [Mon, 17 Jun 2019 11:04:16 +0000 (13:04 +0200)]
kdig: always randomize source port for TCP
fixes #575
Daniel Salzman [Wed, 23 Oct 2019 11:49:38 +0000 (13:49 +0200)]
notify,xfr: unify log messages
Daniel Salzman [Wed, 23 Oct 2019 06:57:09 +0000 (08:57 +0200)]
nsec: remove unused function parameter
Daniel Salzman [Wed, 23 Oct 2019 06:24:26 +0000 (08:24 +0200)]
refresh: fix bootstrap detection for initial serial logging
Daniel Salzman [Wed, 23 Oct 2019 06:23:40 +0000 (08:23 +0200)]
tests-extra: switch to new config option names
David Vašek [Tue, 22 Oct 2019 11:26:47 +0000 (13:26 +0200)]
conf: adjust the 0 (infinite) timeout value of tcp-io-timeout, tcp-remote-io-timeout
Daniel Salzman [Tue, 22 Oct 2019 09:29:57 +0000 (09:29 +0000)]
Merge branch 'journal_serial_loop' into 'master'
Journal serial loop
See merge request knot/knot-dns!1079
Libor Peltan [Wed, 16 Oct 2019 12:10:10 +0000 (14:10 +0200)]
load: don't continue if zone-in-journal load errors
Libor Peltan [Tue, 15 Oct 2019 12:50:46 +0000 (14:50 +0200)]
journal: warning instead of infloop on changeset X->X
...such changeset must not appear in journal, but well it might...
Daniel Salzman [Fri, 18 Oct 2019 17:47:24 +0000 (19:47 +0200)]
load: ignore DNSSEC records in the remove section of journal changesets
This can happen if 'zonefile-load: difference' and 'dnssec-signing: on` are
configured and the server tries to apply such a changeset on unsigned zone file.
Compatibility with journal versions < 2.9.
fixes #659
Daniel Salzman [Mon, 21 Oct 2019 10:53:15 +0000 (12:53 +0200)]
doc: add info about RRL and Cookies configuration order
Daniel Salzman [Mon, 21 Oct 2019 10:51:43 +0000 (10:51 +0000)]
Merge branch 'rpm-epel8-compat' into 'master'
distro/rpm: make spec EPEL8 compatible
See merge request knot/knot-dns!1080
Tomas Krizek [Mon, 21 Oct 2019 08:37:12 +0000 (10:37 +0200)]
distro/rpm: make spec EPEL8 compatible
Daniel Salzman [Fri, 18 Oct 2019 18:15:01 +0000 (20:15 +0200)]
doc: update man pages
Daniel Salzman [Fri, 18 Oct 2019 18:12:29 +0000 (20:12 +0200)]
ds-push: mute log 'debug: config, conf_id_get_txn (invalid parameter)'
David Vašek [Fri, 18 Oct 2019 12:35:57 +0000 (14:35 +0200)]
doc/dnstap: remove a dead link to Bugzilla at nlnetlabs.nl
An important comment from the page that has been removed from the web:
-----------------------------------------------------------------------------------------------------
From the following page (Bugzilla at NLnet Labs), which isn't available anymore.
https://www.nlnetlabs.nl/bugs-script/show_bug.cgi?format=multiple&id=741.
-----------------------------------------------------------------------------------------------------
Bug 741
[...]
Comment 10 Robert Edmonds 2016-01-27 17:15:04 CET
Hi, Igor:
The dnstap code in the DNS server (like Unbound), functions as a client rather than a server. It
needs a server on the other end of the socket to accept connections. I did it this way instead of
the other way around so that a single socket could be used to accept messages from several dnstap
senders. This is similar to how a syslog daemon listens for log messages from multiple processes at
a well-known AF_UNIX socket like /dev/log.
The server has to handshake with the client so that the client knows it is connected to the right
kind of server before it will begin sending frames. You cannot use mkfifo because the connection is
not a named pipe, and unless you can send the binary sequences used for the handshake frames I doubt
socat will work that well either.
If the AF_UNIX socket is not present, or the connection fails somehow, the connection will
automatically be reattempted, no often than every 5 seconds. (This is the default, but can be
changed with fstrm_iothr_options_set_reopen_interval(), though the Unbound dnstap implementation
just uses the default and doesn't expose this as a configuration knob.)
In the fstrm distribution is a utility called fstrm_capture that can be used to serve a capture
socket (it uses libevent and can multiplex traffic from multiple connected clients). Usage looks
like:
"fstrm_capture -t protobuf:dnstap.Dnstap -u /tmp/dnstap.sock -w /tmp/dnstap.out -ddddd"
Run this command before you start Unbound, otherwise if you start it after Unbound you may need to
send queries to the Unbound server (to force data into the fstrm queue) and wait for the reopen
interval to expire before Unbound attempts to reconnect.
This will listen on /tmp/dnstap.sock for connections of type "protobuf:dnstap.Dnstap" (the type used
by dnstap) and write the output to /tmp/dnstap.out. "-ddddd" will produce very high verbosity trace
output.
There is some more relevant info to setting up Unbound and dnstap in the comment on this bug report,
when dnstap was originally integrated into Unbound:
https://open.nlnetlabs.nl/bugs-script/show_bug.cgi?id=621#c1.
(The step #5 is obsolete now, since the dnstap patch is in the mainline source tree.)
There was also a very nice webinar produced last month by Carsten Strotmann and Men and Mice that
covers using dnstap with Unbound and a few other servers, available here:
https://www.menandmice.com/resources/educational-resources/webinars/dnstap-webinar/
Hope this helps!
-----------------------------------------------------------------------------------------------------
David Vašek [Fri, 18 Oct 2019 12:35:00 +0000 (14:35 +0200)]
doc: make some links to utilities
Daniel Salzman [Fri, 11 Oct 2019 10:02:01 +0000 (12:02 +0200)]
kdig: fix compile warning
Daniel Salzman [Thu, 10 Oct 2019 11:39:40 +0000 (13:39 +0200)]
Bump version 3.0.dev
Daniel Salzman [Thu, 10 Oct 2019 10:04:37 +0000 (12:04 +0200)]
doc: add migration from 2.8.x to 2.9.x
Daniel Salzman [Tue, 8 Oct 2019 14:46:20 +0000 (16:46 +0200)]
NEWS: update to 2.9.0
Daniel Salzman [Wed, 9 Oct 2019 14:59:19 +0000 (16:59 +0200)]
rrl: log both trigger source address and affected subnet
Daniel Salzman [Tue, 8 Oct 2019 20:48:46 +0000 (22:48 +0200)]
server: don't deinit other interfaces if one failed to create
Daniel Salzman [Tue, 8 Oct 2019 20:09:00 +0000 (22:09 +0200)]
server: don't assert if empty interface list
Daniel Salzman [Tue, 8 Oct 2019 11:01:24 +0000 (13:01 +0200)]
conf: rename max_*/min_* zone items
Daniel Salzman [Tue, 8 Oct 2019 12:04:45 +0000 (14:04 +0200)]
conf: rename 'max*_udp_payload' 'udp_max*_payload'
Daniel Salzman [Tue, 8 Oct 2019 08:31:28 +0000 (10:31 +0200)]
conf: rename 'server.max-tcp-clients' 'server.tcp-max-clients'
Daniel Salzman [Mon, 7 Oct 2019 14:14:16 +0000 (16:14 +0200)]
distro/rpm: update patch for test_net
Daniel Salzman [Mon, 7 Oct 2019 13:38:13 +0000 (15:38 +0200)]
tests-extra: move tcp-reuseport to basic/nsec(3)
Daniel Salzman [Mon, 7 Oct 2019 13:15:47 +0000 (15:15 +0200)]
distro/knot.service: add/increase LimitNOFILE to
1048576
Daniel Salzman [Mon, 7 Oct 2019 12:10:42 +0000 (14:10 +0200)]
distro/tests: remove files for openSUSE_Tumbleweed
'make dist' complained of "file name is too long (max 99)"
Daniel Salzman [Sun, 6 Oct 2019 17:32:23 +0000 (19:32 +0200)]
keymgr: cast pointer difference to proper type (lgtm.com)
Daniel Salzman [Sun, 6 Oct 2019 17:31:09 +0000 (19:31 +0200)]
geoip: cast pointer difference to proper type (lgtm.com)
Daniel Salzman [Sun, 6 Oct 2019 17:25:29 +0000 (19:25 +0200)]
tcp-handler: pass pointer instead of sockaddr_storage copy to tcp_log_error (lgtm.com)
Daniel Salzman [Sun, 6 Oct 2019 17:23:56 +0000 (19:23 +0200)]
doxygen: don't use logo as it's too big anyway
Daniel Salzman [Sun, 6 Oct 2019 10:23:02 +0000 (12:23 +0200)]
tests-extra: enable tcp-reusport in basic/query test, which consists of basic queries only
Daniel Salzman [Sun, 6 Oct 2019 10:22:08 +0000 (12:22 +0200)]
conf: disable tcp-reuseport by default
Daniel Salzman [Sun, 6 Oct 2019 09:11:01 +0000 (11:11 +0200)]
tests: mute some Coverity warnings
Daniel Salzman [Fri, 4 Oct 2019 19:23:53 +0000 (21:23 +0200)]
Unify character array initialization
Daniel Salzman [Fri, 4 Oct 2019 18:27:31 +0000 (20:27 +0200)]
contrib: replace 'struct sockaddr' with 'struct sockaddr_storage' where reasonable
Daniel Salzman [Sat, 5 Oct 2019 18:46:46 +0000 (20:46 +0200)]
Revert "tcp-handler: remove redundant while condition"
The condition is not redundant as 'nfds' is not always decremented.
This reverts commit
dd936d0ea34e8e95dadc0ed9dc186078723fb121 .
David Vašek [Fri, 9 Aug 2019 10:02:35 +0000 (12:02 +0200)]
contrib: multiplatform spinlocks
David Vašek [Fri, 4 Oct 2019 09:37:10 +0000 (11:37 +0200)]
src: remove useless initialization of WALK_LIST* counters
Daniel Salzman [Fri, 4 Oct 2019 14:18:40 +0000 (16:18 +0200)]
tcp-handler: don't accept more clients than configured
Daniel Salzman [Fri, 4 Oct 2019 14:13:13 +0000 (16:13 +0200)]
tcp-handler: remove redundant while condition
David Vašek [Mon, 19 Aug 2019 10:52:45 +0000 (12:52 +0200)]
tcp-handler: refactor TCP throttling calculation and make it work according to the docs
(The throttling should occur when clients > max-tcp-clients, not >= ).
David Vašek [Thu, 3 Oct 2019 09:40:47 +0000 (11:40 +0200)]
server: avoid repeated warnings and unify warn_* variables
Daniel Salzman [Thu, 3 Oct 2019 07:32:03 +0000 (09:32 +0200)]
server: remove useless initialization
David Vašek [Wed, 2 Oct 2019 07:41:03 +0000 (09:41 +0200)]
server: free unused memory before return
Daniel Salzman [Tue, 1 Oct 2019 17:54:53 +0000 (19:54 +0200)]
server: improve return checks in configure_sockets
Daniel Salzman [Tue, 1 Oct 2019 18:51:13 +0000 (20:51 +0200)]
server: unify return values from reconfigure functions
Daniel Salzman [Tue, 1 Oct 2019 18:38:06 +0000 (20:38 +0200)]
server: remove useless memsets, which can also be optimized out
David Vašek [Fri, 20 Sep 2019 07:21:25 +0000 (09:21 +0200)]
server: emit info about reuseport use to the log
David Vašek [Thu, 19 Sep 2019 14:14:54 +0000 (16:14 +0200)]
doc: document the use of the server.tcp-reuseport option
David Vašek [Thu, 3 Oct 2019 11:08:19 +0000 (13:08 +0200)]
server: enable setting of TCP reuseport via server.tcp-reuseport option
David Vašek [Thu, 19 Sep 2019 12:42:30 +0000 (14:42 +0200)]
conf, server: add server.tcp-reuseport configuration option
David Vašek [Thu, 12 Sep 2019 14:26:54 +0000 (16:26 +0200)]
server: reuseport implementation for TCP protocol
Based on work from @jhak with a fix and updated to the current code.
Daniel Salzman [Fri, 4 Oct 2019 16:46:49 +0000 (16:46 +0000)]
Merge branch 'doc_policy_ref' into 'master'
doc: better describe references and defaults
See merge request knot/knot-dns!1077
Daniel Salzman [Thu, 3 Oct 2019 18:57:18 +0000 (20:57 +0200)]
server: add info log about loaded configuration
Libor Peltan [Thu, 3 Oct 2019 14:43:50 +0000 (16:43 +0200)]
doc: better describe references and defaults