]>
git.ipfire.org Git - thirdparty/knot-resolver.git/log
Ondřej Surý [Thu, 9 Mar 2017 12:44:15 +0000 (13:44 +0100)]
Update deckard to latest master
Ondřej Surý [Wed, 8 Mar 2017 12:39:34 +0000 (13:39 +0100)]
Merge branch 'cherry-pick-
2ff4eb98 ' into '1.2'
Merge branch 'fix-auth-qname' into '1.2'
See merge request !230
Ondřej Surý [Wed, 8 Mar 2017 12:24:42 +0000 (13:24 +0100)]
Get a fresh deckard copy before the build
Ondřej Surý [Wed, 8 Mar 2017 12:03:03 +0000 (13:03 +0100)]
Update NEWS
Ondřej Surý [Wed, 8 Mar 2017 10:58:14 +0000 (11:58 +0100)]
Merge branch 'fix-auth-qname' into 'master'
layer\iterate: when processing delegations, check if qname is at\below new authority
See merge request !229
Ondřej Surý [Wed, 8 Mar 2017 12:00:08 +0000 (13:00 +0100)]
Merge branch '1.2.4-dev' into '1.2'
1.2.4 dev
See merge request !227
Ondřej Surý [Wed, 8 Mar 2017 10:58:14 +0000 (11:58 +0100)]
Merge branch 'fix-auth-qname' into 'master'
layer\iterate: when processing delegations, check if qname is at\below new authority
See merge request !229
Grigorii Demidov [Wed, 8 Mar 2017 10:14:00 +0000 (11:14 +0100)]
layer\iterate: when proccessing delegations, check if qname is at\below new authority
Ondřej Surý [Mon, 6 Mar 2017 12:50:58 +0000 (13:50 +0100)]
Update deckard to val_cname_secure_insecure tests
Ondřej Surý [Mon, 6 Mar 2017 12:32:11 +0000 (13:32 +0100)]
Merge branch 'update-gitignore-zonefile.lua' into 'master'
Add daemon/lua/zonefile.lua to git ignore list
See merge request !228
Ondřej Surý [Mon, 6 Mar 2017 12:29:17 +0000 (13:29 +0100)]
Add daemon/lua/zonefile.lua to git ignore list
Petr Špaček [Mon, 6 Mar 2017 12:24:20 +0000 (13:24 +0100)]
Clarify conditions when invalid RRSIG can lead to AD=1 response
Further clarification of
fb957a9b5593aaa46dcfddd9adb488cf898b4a45
Ondřej Surý [Mon, 6 Mar 2017 12:08:03 +0000 (13:08 +0100)]
Merge branch 'dnstap' into 'master'
add dnstap module
See merge request !213
Ondřej Surý [Mon, 6 Mar 2017 12:06:13 +0000 (13:06 +0100)]
Test failing make clean on missing dnstap dependencies
Ondřej Surý [Mon, 6 Mar 2017 12:02:18 +0000 (13:02 +0100)]
modules/dnstap: Change option names to socket_path and log_responses, we don't use camelCase anywhere else
Ondřej Surý [Mon, 6 Mar 2017 11:54:40 +0000 (12:54 +0100)]
dnstap module also needs protobuf-c compiler (protoc-c)
Vladimír Čunát [Wed, 22 Feb 2017 13:47:26 +0000 (14:47 +0100)]
modules/dnstap: move description into the docs
Vladimír Čunát [Wed, 22 Feb 2017 12:50:10 +0000 (13:50 +0100)]
modules/dnstap: nitpicks
Vladimír Čunát [Wed, 22 Feb 2017 12:10:21 +0000 (13:10 +0100)]
dnstap.proto: move from contrib into module
... and generate files instead of including them.
Vicky Shrestha [Tue, 17 Jan 2017 08:08:17 +0000 (08:08 +0000)]
minor changes from https://github.com/CZ-NIC/knot-resolver/pull/39
Vicky Shrestha [Fri, 30 Dec 2016 20:14:55 +0000 (12:14 -0800)]
adding dnstap to documentation
Vicky Shrestha [Fri, 30 Dec 2016 20:14:02 +0000 (12:14 -0800)]
dnstap tests requires go 1.5+
removing it from make test since default go version for language
C in Travis is 1.4 which has no vendoring support
Vicky Shrestha [Mon, 26 Dec 2016 09:16:05 +0000 (01:16 -0800)]
adding dnstap dependencies to bootstrap
Vicky Shrestha [Mon, 26 Dec 2016 08:05:49 +0000 (00:05 -0800)]
fixing makefile to compile protobuf if dnstap is enabled
Vicky Shrestha [Sat, 24 Dec 2016 18:04:53 +0000 (10:04 -0800)]
Fixing structs after rebasing upstream changes
Vicky Shrestha [Thu, 8 Dec 2016 07:26:04 +0000 (23:26 -0800)]
dnstap testing application
Vicky Shrestha [Thu, 22 Sep 2016 22:32:27 +0000 (15:32 -0700)]
Adding dnstap module
Ondřej Surý [Mon, 6 Mar 2017 11:41:01 +0000 (12:41 +0100)]
Clarify security section
Ondřej Surý [Mon, 6 Mar 2017 10:59:17 +0000 (11:59 +0100)]
Update NEWS
Grigorii Demidov [Fri, 3 Mar 2017 09:17:06 +0000 (10:17 +0100)]
lib/resolve: deferred answer processing was fixed
Vladimír Čunát [Thu, 2 Mar 2017 17:28:14 +0000 (18:28 +0100)]
rrcache: don't store NSEC3 and their signatures
They would end up cached by their hashed owner names and then even
returned if explicitly queried by that hashed name, which is not correct:
https://tools.ietf.org/html/rfc4035#section-2.3
Internally we only need these for non-existence proofs, and those are
stored in pktcache instead.
Grigorii Demidov [Wed, 1 Mar 2017 12:47:27 +0000 (13:47 +0100)]
layer/validate: don't treat anwsers which contain DS non-existance proof as unsecured
Vladimír Čunát [Fri, 3 Mar 2017 12:28:28 +0000 (13:28 +0100)]
Merge !226: lib/resolve: deferred answer processing was fixed
Vladimír Čunát [Fri, 3 Mar 2017 12:04:02 +0000 (13:04 +0100)]
Merge !225: rrcache: don't store NSEC3 and their signatures
Vladimír Čunát [Fri, 3 Mar 2017 12:02:39 +0000 (13:02 +0100)]
Merge !224: layer/validate: fix missing AD flag in some cases
Fixes #164.
Grigorii Demidov [Fri, 3 Mar 2017 09:17:06 +0000 (10:17 +0100)]
lib/resolve: deferred answer processing was fixed
Vladimír Čunát [Thu, 2 Mar 2017 17:28:14 +0000 (18:28 +0100)]
rrcache: don't store NSEC3 and their signatures
They would end up cached by their hashed owner names and then even
returned if explicitly queried by that hashed name, which is not correct:
https://tools.ietf.org/html/rfc4035#section-2.3
Internally we only need these for non-existence proofs, and those are
stored in pktcache instead.
Grigorii Demidov [Wed, 1 Mar 2017 12:47:27 +0000 (13:47 +0100)]
layer/validate: don't treat anwsers which contain DS non-existance proof as unsecured
Vladimír Čunát [Wed, 1 Mar 2017 10:18:52 +0000 (11:18 +0100)]
Merge !218: cherry-picks for 1.2.4
Vladimír Čunát [Wed, 1 Mar 2017 10:16:38 +0000 (11:16 +0100)]
update NEWS with notable chanages
Petr Špaček [Wed, 1 Mar 2017 08:13:22 +0000 (09:13 +0100)]
Merge branch 'full_check_integration' into 'master'
Update check-integration to run full test suite from Deckard
See merge request !220
(cherry picked from commit
f8487fd6e7743bd4e92336750e8cada6a4296826 )
Marek Vavruša [Tue, 28 Feb 2017 19:05:20 +0000 (11:05 -0800)]
daemon: fixed memory leak and array bounds check fail
(cherry picked from commit
924d99364548cf6f1b7d4d131fc08a3e04ecb524 )
Vladimír Čunát [Wed, 1 Mar 2017 09:59:56 +0000 (10:59 +0100)]
Merge !221: daemon: fixed memory leak and array bounds check fail
Submitted as https://github.com/CZ-NIC/knot-resolver/pull/42
Petr Špaček [Wed, 1 Mar 2017 08:13:22 +0000 (09:13 +0100)]
Merge branch 'full_check_integration' into 'master'
Update check-integration to run full test suite from Deckard
See merge request !220
Marek Vavruša [Tue, 28 Feb 2017 19:05:20 +0000 (11:05 -0800)]
daemon: fixed memory leak and array bounds check fail
Petr Špaček [Tue, 28 Feb 2017 16:27:36 +0000 (17:27 +0100)]
tests: print warning if check-integration is executed with PREFIX outside of source directory
Petr Špaček [Tue, 28 Feb 2017 10:46:04 +0000 (11:46 +0100)]
tests: use tests/deckard/kresd_run.sh for check-integration target
Now the check-integration is (again) doing the same set of tests
as kresd_run.sh in Deckard tree.
Vladimír Čunát [Tue, 28 Feb 2017 13:33:29 +0000 (14:33 +0100)]
Merge 219: lib/resolve: forward +cd in stub mode; minor bugfix
Grigorii Demidov [Tue, 28 Feb 2017 12:30:25 +0000 (13:30 +0100)]
lib/resolve: forward +cd in stub mode; minor bugfix in debug output
(cherry picked from commit
218f1b78b31ac4742f27a48027748e3989951bee )
Grigorii Demidov [Tue, 28 Feb 2017 12:30:25 +0000 (13:30 +0100)]
lib/resolve: forward +cd in stub mode; minor bugfix in debug output
Vladimír Čunát [Mon, 20 Feb 2017 10:26:27 +0000 (11:26 +0100)]
lua: add net.outgoing_{v4,v6} and documentation
Fixes https://gitlab.labs.nic.cz/knot/resolver/issues/158
The naming is inspired by Unbound's "outgoing-interface".
Vladimír Čunát [Mon, 20 Feb 2017 09:12:38 +0000 (10:12 +0100)]
daemon: support restricting outgoing IP address
Vladimír Čunát [Mon, 20 Feb 2017 07:06:57 +0000 (08:06 +0100)]
utils: add union inaddr
It will be a useful idiom for IP address storage and correct conversion
of sockaddr* pointers.
Vladimír Čunát [Mon, 13 Feb 2017 13:01:50 +0000 (14:01 +0100)]
trust anchors: improve logging of failures
engine_cmd() doesn't print the error() exceptions thrown from lua;
it only leaves the message on lua stack.
(cherry picked from commit
a316b9f7a74723770c61f1412d9b55b873bfd003 )
Vladimír Čunát [Tue, 28 Feb 2017 11:42:23 +0000 (12:42 +0100)]
Merge !202: trust anchor improvements
Ondřej Surý [Tue, 28 Feb 2017 11:03:19 +0000 (12:03 +0100)]
Update to 1.2.4-dev
Grigorii Demidov [Fri, 3 Feb 2017 09:59:07 +0000 (10:59 +0100)]
modules/policy: allow QTRACE policy to be chained with other policies
Vladimír Čunát [Thu, 26 Jan 2017 15:02:41 +0000 (16:02 +0100)]
hints.add_hosts(path): a new property
So far it wasn't possible to load multiple files (!). Real use case:
https://forum.turris.cz/t/how-to-configure-local-address-dns-resoultion-on-omnia/1000/14
Vladimír Čunát [Fri, 27 Jan 2017 17:10:06 +0000 (18:10 +0100)]
libkresd: link against libuv
Vladimír Čunát [Fri, 17 Feb 2017 15:41:18 +0000 (16:41 +0100)]
iterate: remove function unused after parent merge
Vladimír Čunát [Tue, 28 Feb 2017 10:49:26 +0000 (11:49 +0100)]
Merge !210: support setting address for outgoing connections
Closes #158.
Vladimír Čunát [Fri, 20 Jan 2017 17:43:01 +0000 (18:43 +0100)]
module: document the API and simplify the code
This does NOT change the module API/ABI in any way.
Vladimír Čunát [Mon, 20 Feb 2017 10:26:27 +0000 (11:26 +0100)]
lua: add net.outgoing_{v4,v6} and documentation
Fixes https://gitlab.labs.nic.cz/knot/resolver/issues/158
The naming is inspired by Unbound's "outgoing-interface".
Vladimír Čunát [Mon, 20 Feb 2017 09:12:38 +0000 (10:12 +0100)]
daemon: support restricting outgoing IP address
Vladimír Čunát [Wed, 15 Feb 2017 17:19:32 +0000 (18:19 +0100)]
kres-gen.lua: reduce installed whitespace
Vladimír Čunát [Wed, 8 Feb 2017 12:13:57 +0000 (13:13 +0100)]
lua cache.* fixes
- docs: fix cache.current_* since long ago
d5272b4
- don't allow "cache.foo = 'bar'" for abitrary foo
- restore cache['nic.cz'] after
b31bad2ccf while not breaking completion
- #cache won't work on lua 5.1, so remove it
Štěpán Balážik [Wed, 1 Feb 2017 14:19:56 +0000 (15:19 +0100)]
lua sandbox: fix syntactic sugar for `cache` table in order for tab-completion to work properly
Vladimír Čunát [Wed, 15 Feb 2017 10:11:12 +0000 (11:11 +0100)]
.gitignore: add some entries
All either generated by the build system or some "standard tools".
Vladimír Čunát [Fri, 27 Jan 2017 16:48:34 +0000 (17:48 +0100)]
policy.MIRROR: support IPv6 link-local addresses
Grigorii Demidov [Fri, 17 Feb 2017 10:36:11 +0000 (11:36 +0100)]
layer/iterate: some improvements in cname chain unrolling
Vladimír Čunát [Fri, 27 Jan 2017 15:57:16 +0000 (16:57 +0100)]
policy.FORWARD: support IPv6 link-local addresses
These shouldn't make any problems:
- the verbose messages don't print any scope, and
- reputation cache doesn't consider scope.
Grigorii Demidov [Tue, 28 Feb 2017 09:47:05 +0000 (10:47 +0100)]
tests: sync deckard; cleanup
Grigorii Demidov [Mon, 27 Feb 2017 12:19:48 +0000 (13:19 +0100)]
layer/validate: fix duplicate records in AUTHORITY section in case of WC expansion proof
Vladimír Čunát [Fri, 24 Feb 2017 10:26:28 +0000 (11:26 +0100)]
lua: do *not* truncate cache size to unsigned
... and perform extra checks when converting from the floating-point
number.
Grigorii Demidov [Tue, 28 Feb 2017 09:59:09 +0000 (10:59 +0100)]
Merge branch 'fix-dups' into 'master'
layer/validate: fix duplicate records in AUTHORITY section in case of WC expansion proof
See merge request !216
Grigorii Demidov [Tue, 28 Feb 2017 09:47:05 +0000 (10:47 +0100)]
tests: sync deckard; cleanup
Vladimír Čunát [Tue, 28 Feb 2017 09:24:20 +0000 (10:24 +0100)]
Merge !209: iterate: remove unused function
Grigorii Demidov [Mon, 27 Feb 2017 12:19:48 +0000 (13:19 +0100)]
layer/validate: fix duplicate records in AUTHORITY section in case of WC expansion proof
Vladimír Čunát [Tue, 14 Feb 2017 15:44:27 +0000 (16:44 +0100)]
trust anchors: persist the state and timer
The format of TA store is compatible both ways with old kresd.
Note: it requires the parent commit to work, i.e. new libzscanner.
Vladimír Čunát [Tue, 14 Feb 2017 15:13:23 +0000 (16:13 +0100)]
zonefile.lua: support comments and string input
Comment parsing will only be supported in future libzscanner version.
Also move out of the module, as trust_anchors.lua requires it and isn't
in a module.
Vladimír Čunát [Fri, 24 Feb 2017 14:07:36 +0000 (15:07 +0100)]
Merge !215: lua: do *not* truncate cache size to unsigned
Vladimír Čunát [Fri, 24 Feb 2017 10:26:28 +0000 (11:26 +0100)]
lua: do *not* truncate cache size to unsigned
... and perform extra checks when converting from the floating-point
number.
Vladimír Čunát [Thu, 23 Feb 2017 14:37:53 +0000 (15:37 +0100)]
Merge !214: various fixes for 1.2.3
Ondřej Surý [Thu, 23 Feb 2017 13:24:50 +0000 (14:24 +0100)]
Prepare 1.2.3 release
Ondřej Surý [Fri, 17 Feb 2017 14:18:25 +0000 (15:18 +0100)]
Disable storing GLUE records into the cache in the QUERY_PERMISSIVE mode
Vladimír Čunát [Mon, 20 Feb 2017 12:50:39 +0000 (13:50 +0100)]
iterate: skip answer RRs that don't match the query
Fixes https://gitlab.labs.nic.cz/knot/resolver/issues/160
Grigorii Demidov [Wed, 15 Feb 2017 11:57:08 +0000 (12:57 +0100)]
layer/iterate: some additional processing for referrals
Grigorii Demidov [Thu, 16 Feb 2017 12:23:41 +0000 (13:23 +0100)]
lib/resolve: zonecut fetching error was fixed
Vladimír Čunát [Tue, 21 Feb 2017 15:00:43 +0000 (16:00 +0100)]
Merge !211: iterate: skip answer RRs that don't match the query
Fixes #160.
Vladimír Čunát [Tue, 21 Feb 2017 14:53:41 +0000 (15:53 +0100)]
Merge !184: add workarounds module
Vladimír Čunát [Tue, 21 Feb 2017 11:13:41 +0000 (12:13 +0100)]
workarounds: add magazine-fashion.net
Some of their nameservers return 192.168.1.1, but it seems an
improvement, as meaningful address is returned sometimes now.
Vladimír Čunát [Tue, 21 Feb 2017 10:38:19 +0000 (11:38 +0100)]
workarounds: add another NS set with bogus 0x20 PTR
Vladimír Čunát [Mon, 20 Feb 2017 12:50:39 +0000 (13:50 +0100)]
iterate: skip answer RRs that don't match the query
Fixes https://gitlab.labs.nic.cz/knot/resolver/issues/160
Vladimír Čunát [Mon, 20 Feb 2017 07:06:57 +0000 (08:06 +0100)]
utils: add union inaddr
It will be a useful idiom for IP address storage and correct conversion
of sockaddr* pointers.
Petr Špaček [Fri, 17 Feb 2017 19:20:12 +0000 (20:20 +0100)]
Merge branch 'harden-permissive-mode' into 'master'
Disable storing GLUE records into the cache in the QUERY_PERMISSIVE mode
See merge request !208
Ondřej Surý [Fri, 17 Feb 2017 14:18:25 +0000 (15:18 +0100)]
Disable storing GLUE records into the cache in the QUERY_PERMISSIVE mode
Vladimír Čunát [Fri, 17 Feb 2017 15:41:18 +0000 (16:41 +0100)]
iterate: remove function unused after parent merge
Grigorii Demidov [Fri, 17 Feb 2017 11:57:21 +0000 (12:57 +0100)]
Merge branch 'fix-cname-unroll' into 'master'
layer/iterate: some improvements in cname chain unrolling
See merge request !207
Grigorii Demidov [Fri, 17 Feb 2017 10:36:11 +0000 (11:36 +0100)]
layer/iterate: some improvements in cname chain unrolling
Grigorii Demidov [Thu, 16 Feb 2017 14:22:10 +0000 (15:22 +0100)]
Merge branch 'fix-unsecured-secured' into 'master'
lib/resolve: zonecut fetching error was fixed
See merge request !205