]> git.ipfire.org Git - thirdparty/bind9.git/log
thirdparty/bind9.git
5 years agoDo not run "make recheck" if the test suite fails
Michał Kępień [Fri, 7 Aug 2020 12:35:05 +0000 (14:35 +0200)] 
Do not run "make recheck" if the test suite fails

Running "make recheck" after the test suite fails hides intermittent
system test failures in GitLab CI.  This makes it hard to identify which
branches are affected by a particular test failure mode and causes CI
results to be overly optimistic.  Prevent "make recheck" from being run
when "make check" fails to ensure GitLab CI results properly reflect the
stability of the "main" branch.

5 years agoMerge branch '1613-rndc-dnssec-checkds' into 'main'
Matthijs Mekking [Fri, 7 Aug 2020 11:19:09 +0000 (11:19 +0000)] 
Merge branch '1613-rndc-dnssec-checkds' into 'main'

Resolve "Signal DS submitting via rndc"

Closes #1613

See merge request isc-projects/bind9!3906

5 years agorndc dnssec -checkds set algorithm
Matthijs Mekking [Tue, 4 Aug 2020 08:33:19 +0000 (10:33 +0200)] 
rndc dnssec -checkds set algorithm

In the rare case that you have multiple keys acting as KSK and that
have the same keytag, you can now set the algorithm when calling
'-checkds'.

5 years agoAdd notes for #1613 (rndc dnssec -checkds)
Matthijs Mekking [Fri, 31 Jul 2020 09:15:49 +0000 (11:15 +0200)] 
Add notes for #1613 (rndc dnssec -checkds)

This is a new feature that should be mentioned in the notes.

5 years agoTest 'rndc dnssec -checkds' on multiple zones
Matthijs Mekking [Fri, 31 Jul 2020 09:13:53 +0000 (11:13 +0200)] 
Test 'rndc dnssec -checkds' on multiple zones

Make sure the 'checkds' command correctly sets the right key timing
metadata and also make sure that it rejects setting the key timing
metadata if there are multiple keys with the KSK role and no key
identifier is provided.

5 years agoMake 'parent-registration-delay' obsolete
Matthijs Mekking [Fri, 31 Jul 2020 07:58:59 +0000 (09:58 +0200)] 
Make 'parent-registration-delay' obsolete

With the introduction of 'checkds', the 'parent-registration-delay'
option becomes obsolete.

5 years agoAdjust kasp tests to use 'checkds'
Matthijs Mekking [Fri, 31 Jul 2020 07:04:07 +0000 (09:04 +0200)] 
Adjust kasp tests to use 'checkds'

With 'checkds' replacing 'parent-registration-delay', the kasp
test needs the expected times to be adjusted. Also the system test
needs to call 'rndc dnssec -checkds' to progress the rollovers.

Since we pretend that the KSK is active as soon as the DS is
submitted (and parent registration delay is no longer applicable)
we can simplify the 'csk_rollover_predecessor_keytimes' function
to take only one "addtime" parameter.

This commit also slightly changes the 'check_dnssecstatus' function,
passing the zone as a parameter.

5 years agoFix time printing in key files
Matthijs Mekking [Fri, 31 Jul 2020 06:52:05 +0000 (08:52 +0200)] 
Fix time printing in key files

Don't strip off the final character when printing times in key files.

With the introduction of 'rndc dnssec -status' we introduced
'isc_stdtime_tostring()'. This changed in behavior such that it was no
longer needed to strip of the final '\n' of the string format
datetime. However, in 'printtime()' it still stripped the final
character.

5 years agoImplement 'rndc dnssec -checkds'
Matthijs Mekking [Fri, 31 Jul 2020 06:37:51 +0000 (08:37 +0200)] 
Implement 'rndc dnssec -checkds'

Add a new 'rndc' command 'dnssec -checkds' that allows the user to
signal named that a new DS record has been seen published in the
parent, or that an existing DS record has been withdrawn from the
parent.

Upon the 'checkds' request, 'named' will write out the new state for
the key, updating the 'DSPublish' or 'DSRemoved' timing metadata.

This replaces the "parent-registration-delay" configuration option,
this was unreliable because it was purely time based (if the user
did not actually submit the new DS to the parent for example, this
could result in an invalid DNSSEC state).

Because we cannot rely on the parent registration delay for state
transition, we need to replace it with a different guard. Instead,
if a key wants its DS state to be moved to RUMOURED, the "DSPublish"
time must be set and must not be in the future. If a key wants its
DS state to be moved to UNRETENTIVE, the "DSRemoved" time must be set
and must not be in the future.

By default, with '-checkds' you set the time that the DS has been
published or withdrawn to now, but you can set a different time with
'-when'. If there is only one KSK for the zone, that key has its
DS state moved to RUMOURED. If there are multiple keys for the zone,
specify the right key with '-key'.

5 years agoInclude fuzz/fuzz.h in source tarballs
Michał Kępień [Thu, 6 Aug 2020 07:10:06 +0000 (09:10 +0200)] 
Include fuzz/fuzz.h in source tarballs

5 years agoUpdate BIND version to 9.17.4
Michał Kępień [Thu, 6 Aug 2020 07:10:06 +0000 (09:10 +0200)] 
Update BIND version to 9.17.4

5 years agoAdd a CHANGES marker
Michał Kępień [Thu, 6 Aug 2020 07:10:06 +0000 (09:10 +0200)] 
Add a CHANGES marker

5 years agoUpdate library API versions
Michał Kępień [Thu, 6 Aug 2020 07:10:06 +0000 (09:10 +0200)] 
Update library API versions

5 years agoMerge branch 'michal/prepare-release-notes-for-bind-9.17.4' into 'security-main'
Michał Kępień [Thu, 6 Aug 2020 06:14:38 +0000 (06:14 +0000)] 
Merge branch 'michal/prepare-release-notes-for-bind-9.17.4' into 'security-main'

Prepare release notes for BIND 9.17.4

See merge request isc-private/bind9!186

5 years agoReorder release notes
Michał Kępień [Wed, 5 Aug 2020 14:02:38 +0000 (16:02 +0200)] 
Reorder release notes

5 years agoPrepare release notes for BIND 9.17.4
Michał Kępień [Wed, 5 Aug 2020 14:02:38 +0000 (16:02 +0200)] 
Prepare release notes for BIND 9.17.4

5 years agoAdd release note for #1976
Michał Kępień [Wed, 5 Aug 2020 14:02:38 +0000 (16:02 +0200)] 
Add release note for #1976

5 years agoAdd release note for #1619
Michał Kępień [Wed, 5 Aug 2020 14:02:38 +0000 (16:02 +0200)] 
Add release note for #1619

5 years agoTweak and reword release notes
Michał Kępień [Wed, 5 Aug 2020 14:02:38 +0000 (16:02 +0200)] 
Tweak and reword release notes

5 years agoTweak and reword recent CHANGES entries
Michał Kępień [Wed, 5 Aug 2020 14:02:38 +0000 (16:02 +0200)] 
Tweak and reword recent CHANGES entries

5 years agoMerge branch '2055-grant-subdomain-fix' into 'security-main'
Michał Kępień [Wed, 5 Aug 2020 13:57:57 +0000 (13:57 +0000)] 
Merge branch '2055-grant-subdomain-fix' into 'security-main'

[CVE-2020-8624] Fix processing of "update-policy" rules of type "subdomain"

See merge request isc-private/bind9!189

5 years agoAdd CHANGES and release note for GL #2055
Mark Andrews [Wed, 29 Jul 2020 13:36:03 +0000 (23:36 +1000)] 
Add CHANGES and release note for GL #2055

5 years agoAdd a test for update-policy 'zonesub'
Mark Andrews [Tue, 4 Aug 2020 01:41:33 +0000 (11:41 +1000)] 
Add a test for update-policy 'zonesub'

The new test checks that 'update-policy zonesub' is properly enforced.

5 years agoAdd a test for update-policy 'subdomain'
Mark Andrews [Wed, 29 Jul 2020 13:36:03 +0000 (23:36 +1000)] 
Add a test for update-policy 'subdomain'

The new test checks that 'update-policy subdomain' is properly enforced.

5 years agoUpdate-policy 'subdomain' was incorrectly treated as 'zonesub'
Mark Andrews [Wed, 29 Jul 2020 13:36:03 +0000 (23:36 +1000)] 
Update-policy 'subdomain' was incorrectly treated as 'zonesub'

resulting in names outside the specified subdomain having the wrong
restrictions for the given key.

5 years agoMerge branch '2037-confidential-issue' into 'security-main'
Michał Kępień [Wed, 5 Aug 2020 13:54:14 +0000 (13:54 +0000)] 
Merge branch '2037-confidential-issue' into 'security-main'

[CVE-2020-8623]: Fix crash in pk11_numbits() with crafted packet when native-pkcs11 is used

See merge request isc-private/bind9!187

5 years agoAdd CHANGES and release note for GL #2037
Ondřej Surý [Tue, 21 Jul 2020 13:24:21 +0000 (15:24 +0200)] 
Add CHANGES and release note for GL #2037

5 years agoDon't strip the SOFTHSM2_CONF and SLOT environment variables when using ./run.sh
Ondřej Surý [Tue, 21 Jul 2020 14:03:44 +0000 (16:03 +0200)] 
Don't strip the SOFTHSM2_CONF and SLOT environment variables when using ./run.sh

5 years agoFix crash in pk11_numbits() when native-pkcs11 is used
Ondřej Surý [Tue, 21 Jul 2020 12:42:47 +0000 (14:42 +0200)] 
Fix crash in pk11_numbits() when native-pkcs11 is used

When pk11_numbits() is passed a user provided input that contains all
zeroes (via crafted DNS message), it would crash with assertion
failure.  Fix that by properly handling such input.

5 years agoMerge branch '2028-unexpectedend-and-tsig' into 'security-main'
Michał Kępień [Wed, 5 Aug 2020 13:50:27 +0000 (13:50 +0000)] 
Merge branch '2028-unexpectedend-and-tsig' into 'security-main'

[CVE-2020-8622] Properly handle malformed truncated responses to TSIG queries

See merge request isc-private/bind9!185

5 years agoAdd CHANGES and release notes for GL #2028
Mark Andrews [Wed, 15 Jul 2020 23:15:20 +0000 (09:15 +1000)] 
Add CHANGES and release notes for GL #2028

5 years agoAlways keep a copy of the message
Mark Andrews [Wed, 15 Jul 2020 06:07:51 +0000 (16:07 +1000)] 
Always keep a copy of the message

this allows it to be available even when dns_message_parse()
returns a error.

5 years agoMerge branch '1997-confidential-issue' into 'security-main'
Michał Kępień [Wed, 5 Aug 2020 13:46:23 +0000 (13:46 +0000)] 
Merge branch '1997-confidential-issue' into 'security-main'

[CVE-2020-8621] Ensure QNAME minimization is permanently disabled when forwarding

See merge request isc-private/bind9!184

5 years agoAdd CHANGES and release note for GL #1997
Evan Hunt [Fri, 10 Jul 2020 21:14:07 +0000 (14:14 -0700)] 
Add CHANGES and release note for GL #1997

5 years agopermanently disable QNAME minimization in a fetch when forwarding
Evan Hunt [Fri, 10 Jul 2020 20:53:30 +0000 (13:53 -0700)] 
permanently disable QNAME minimization in a fetch when forwarding

QNAME minimization is normally disabled when forwarding. if, in the
course of processing a fetch, we switch back to normal recursion at
some point, we can't safely start minimizing because we may have
been left in an inconsistent state.

5 years agoMerge branch '1996-confidential-issue' into 'security-main'
Michał Kępień [Wed, 5 Aug 2020 13:31:59 +0000 (13:31 +0000)] 
Merge branch '1996-confidential-issue' into 'security-main'

[CVE-2020-8620] Fix TCP DNS buffer sizes

See merge request isc-private/bind9!181

5 years agoAdd CHANGES and release note for GL #1996
Ondřej Surý [Fri, 31 Jul 2020 07:39:46 +0000 (09:39 +0200)] 
Add CHANGES and release note for GL #1996

5 years agoUse different allocators for UDP and TCP
Evan Hunt [Thu, 2 Jul 2020 14:27:38 +0000 (16:27 +0200)] 
Use different allocators for UDP and TCP

Each worker has a receive buffer with space for 20 DNS messages of up
to 2^16 bytes each, and the allocator function passed to uv_read_start()
or uv_udp_recv_start() will reserve a portion of it for use by sockets.
UDP can use recvmmsg() and so it needs that entire space, but TCP reads
one message at a time.

This commit introduces separate allocator functions for TCP and UDP
setting different buffer size limits, so that libuv will provide the
correct buffer sizes to each of them.

5 years agoMerge branch 'michal/remove-arm64-jobs-from-gitlab-ci' into 'main'
Michał Kępień [Wed, 5 Aug 2020 10:07:20 +0000 (10:07 +0000)] 
Merge branch 'michal/remove-arm64-jobs-from-gitlab-ci' into 'main'

Remove arm64 jobs from GitLab CI

See merge request isc-projects/bind9!3920

5 years agoRemove arm64 jobs from GitLab CI
Michał Kępień [Wed, 5 Aug 2020 10:04:59 +0000 (12:04 +0200)] 
Remove arm64 jobs from GitLab CI

The only arm64 runner we have at our disposal is suffering from
intermittent connectivity issues which make it unusable for extended
periods of time.  Remove arm64 jobs from GitLab CI until we manage to
set up an arm64 runner with more reliable connectivity.

5 years agoMerge branch '2065-set-max-cache-size-in-the-geoip2-system-test' into 'main'
Michał Kępień [Wed, 5 Aug 2020 09:07:52 +0000 (09:07 +0000)] 
Merge branch '2065-set-max-cache-size-in-the-geoip2-system-test' into 'main'

Set "max-cache-size" in the "geoip2" system test

Closes #2065

See merge request isc-projects/bind9!3919

5 years agoSet "max-cache-size" in the "geoip2" system test
Michał Kępień [Wed, 5 Aug 2020 07:04:53 +0000 (09:04 +0200)] 
Set "max-cache-size" in the "geoip2" system test

The named configuration files used in the "geoip2" system test cause a
rather large number of views (6-8) to be set up in each tested named
instance.  Each view has its own cache.

Commit e24bc324b455d9cad7b51acd3d5c7b4e40c66187 caused the RBT hash
table to be pre-allocated to a size derived from "max-cache-size", so
that it never needs to be rehashed.  The size of that hash table is not
expected to be significant enough to cause memory use issues in typical
conditions even for large "max-cache-size" settings.

However, these two factors combined can cause memory exhaustion issues
in GitLab CI, where we run multiple "instances" of the test suite in
parallel on the same runner, each test suite executes multiple system
tests concurrently, and each system test may potentially start multiple
named instances at the same time.  In practice, this problem currently
only seems to be affecting the "geoip2" system test, which is failing
intermittently due to named instances used by that test getting killed
by oom-killer.

Prevent the "geoip2" system test from failing intermittently by setting
"max-cache-size" in named configuration files used in that test to a low
value in order to keep memory usage at bay even with a large number of
views configured.

5 years agoMerge branch '2030-bind-arm-incorrectly-documents-the-processing-of-forwarders-still...
Michał Kępień [Tue, 4 Aug 2020 19:44:27 +0000 (19:44 +0000)] 
Merge branch '2030-bind-arm-incorrectly-documents-the-processing-of-forwarders-still-has-the-pre-9-3-0-explanation' into 'main'

Resolve "BIND ARM incorrectly documents the processing of forwarders (still has the pre 9.3.0 explanation)"

Closes #2030

See merge request isc-projects/bind9!3881

5 years agoUpdate description of forwarding behavior in ARM
Suzanne Goldlust [Thu, 23 Jul 2020 13:05:43 +0000 (13:05 +0000)] 
Update description of forwarding behavior in ARM

5 years agoMerge branch 'michal/add-placeholder-for-1475' into 'main'
Michał Kępień [Tue, 4 Aug 2020 13:49:37 +0000 (13:49 +0000)] 
Merge branch 'michal/add-placeholder-for-1475' into 'main'

Add placeholder for #1475

See merge request isc-projects/bind9!3916

5 years agoAdd placeholder for #1475
Michał Kępień [Tue, 4 Aug 2020 13:46:34 +0000 (15:46 +0200)] 
Add placeholder for #1475

5 years agoMerge branch 'marka-DNS_R_BADTSIG-map-to-FORMERR' into 'main'
Mark Andrews [Tue, 4 Aug 2020 13:02:24 +0000 (13:02 +0000)] 
Merge branch 'marka-DNS_R_BADTSIG-map-to-FORMERR' into 'main'

Map DNS_R_BADTSIG to FORMERR

See merge request isc-projects/bind9!3877

5 years agoCheck rcode is FORMERR
Mark Andrews [Fri, 31 Jul 2020 10:36:14 +0000 (20:36 +1000)] 
Check rcode is FORMERR

5 years agoMap DNS_R_BADTSIG to FORMERR
Mark Andrews [Wed, 22 Jul 2020 23:47:49 +0000 (09:47 +1000)] 
Map DNS_R_BADTSIG to FORMERR

Now that the log message has been printed set the result code to
DNS_R_FORMERR.  We don't do this via dns_result_torcode() as we
don't want upstream errors to produce FORMERR if that processing
end with DNS_R_BADTSIG.

5 years agoMerge branch 'ondrej/serve-stale-improvements' into 'main'
Matthijs Mekking [Tue, 4 Aug 2020 12:17:57 +0000 (12:17 +0000)] 
Merge branch 'ondrej/serve-stale-improvements' into 'main'

Serve-stale improvements

Closes #1712 and #1829

See merge request isc-projects/bind9!3872

5 years agoAdd CHANGES and release notes for GL #1712 and GL #1829
Ondřej Surý [Thu, 30 Jul 2020 13:10:49 +0000 (15:10 +0200)] 
Add CHANGES and release notes for GL #1712 and GL #1829

5 years agoAdd tests with stale-cache-disabled into serve-stale system test
Ondřej Surý [Thu, 30 Jul 2020 11:55:13 +0000 (13:55 +0200)] 
Add tests with stale-cache-disabled into serve-stale system test

Add a fifth named (ns5) that runs with `stale-cache-enable no;` and
check that there are no stale records in the cache.

5 years agoExpire the 0 TTL RRSet quickly rather using them for serve-stale
Ondřej Surý [Tue, 21 Jul 2020 09:35:42 +0000 (11:35 +0200)] 
Expire the 0 TTL RRSet quickly rather using them for serve-stale

When a received RRSet has TTL 0, they would be preserved for
serve-stale (default `max-stale-cache` is 12 hours) rather than expiring
them quickly from the cache database.

This commit makes sure the RRSet didn't have TTL 0 before marking the
entry in the database as "stale".

5 years agoAdd stale-cache-enable option and disable serve-stable by default
Ondřej Surý [Tue, 21 Jul 2020 08:38:55 +0000 (10:38 +0200)] 
Add stale-cache-enable option and disable serve-stable by default

The current serve-stale implementation in BIND 9 stores all received
records in the cache for a max-stale-ttl interval (default 12 hours).

This allows DNS operators to turn the serve-stale answers in an event of
large authoritative DNS outage.  The caching of the stale answers needs
to be enabled before the outage happens or the feature would be
otherwise useless.

The negative consequence of the default setting is the inevitable
cache-bloat that happens for every and each DNS operator running named.

In this MR, a new configuration option `stale-cache-enable` is
introduced that allows the operators to selectively enable or disable
the serve-stale feature of BIND 9 based on their decision.

The newly introduced option has been disabled by default,
e.g. serve-stale is disabled in the default configuration and has to be
enabled if required.

5 years agoMerge branch '2026-readme-md-typo' into 'main'
Mark Andrews [Tue, 4 Aug 2020 02:23:54 +0000 (02:23 +0000)] 
Merge branch '2026-readme-md-typo' into 'main'

Resolve "README.md -- typo"

Closes #2026

See merge request isc-projects/bind9!3912

5 years agoFixup typo in 'xcode-select --install'
Mark Andrews [Tue, 4 Aug 2020 02:19:15 +0000 (12:19 +1000)] 
Fixup typo in 'xcode-select --install'

5 years agoMerge branch 'michal/restore-placeholder-entry-at-sequence-number-5481' into 'main'
Michał Kępień [Mon, 3 Aug 2020 20:13:12 +0000 (20:13 +0000)] 
Merge branch 'michal/restore-placeholder-entry-at-sequence-number-5481' into 'main'

Restore placeholder entry at sequence number 5481

See merge request isc-projects/bind9!3910

5 years agoRestore placeholder entry at sequence number 5481
Michał Kępień [Mon, 3 Aug 2020 20:09:47 +0000 (22:09 +0200)] 
Restore placeholder entry at sequence number 5481

5 years agoMerge branch 'ondrej/add-isc_lex-fuzzing-test' into 'main'
Ondřej Surý [Fri, 31 Jul 2020 15:55:58 +0000 (15:55 +0000)] 
Merge branch 'ondrej/add-isc_lex-fuzzing-test' into 'main'

Re-enable tests in fuzz directory and add isc_lex_gettoken() and isc_lex_getmastertoken() tests

See merge request isc-projects/bind9!3908

5 years agoAdd fuzzing for the isc_lex (isc_lex_gettoken,isc_lex_getmastertoken) API
Ondřej Surý [Fri, 31 Jul 2020 11:53:38 +0000 (13:53 +0200)] 
Add fuzzing for the isc_lex (isc_lex_gettoken,isc_lex_getmastertoken) API

In this commit, the simple fuzzing tests for the isc_lex_gettoken() and
isc_lex_getmastertoken() functions have been added.

As part of this commit, the initialization has been moved from fuzz.h
constructor/destructor to LLVMFuzzerInitialize() in each fuzz test.  The
main.c of no-fuzzing and AFL modes have been modified to run the
LLVMFuzzerInitialize() at the start of the main() function mimicking
the libfuzzer mode of operation.

5 years agoRe-enable the fuzzing tests
Ondřej Surý [Fri, 31 Jul 2020 13:20:56 +0000 (15:20 +0200)] 
Re-enable the fuzzing tests

The fuzzing tests were temporarily disabled when the build system has been
converted to automake.  This commit restores the functionality to run the
fuzzing tests as part of the `make check`.  When the afl or libfuzzer
is enabled via ./configure, it uses a custom LOG_DRIVER (fuzz/<fuzzer.sh>).

Currently only libfuzzer.sh has been implemented that runs each fuzz
test for 5 seconds each.

5 years agoMerge branch '2038-use-freebind-when-bind-fails' into 'main'
Ondřej Surý [Fri, 31 Jul 2020 11:32:40 +0000 (11:32 +0000)] 
Merge branch '2038-use-freebind-when-bind-fails' into 'main'

Resolve "Bind not handling interfaces changes correctly when listen-on-v6  any  specified"

Closes #2038

See merge request isc-projects/bind9!3873

5 years agoAdd CHANGES and release note for GL #2038
Witold Kręcicki [Tue, 21 Jul 2020 12:56:45 +0000 (14:56 +0200)] 
Add CHANGES and release note for GL #2038

5 years agonetmgr: retry binding with IP_FREEBIND when EADDRNOTAVAIL is returned.
Witold Kręcicki [Tue, 21 Jul 2020 11:29:14 +0000 (13:29 +0200)] 
netmgr: retry binding with IP_FREEBIND when EADDRNOTAVAIL is returned.

When a new IPv6 interface/address appears it's first in a tentative
state - in which we cannot bind to it, yet it's already being reported
by the route socket. Because of that BIND9 is unable to listen on any
newly detected IPv6 addresses. Fix it by setting IP_FREEBIND option (or
equivalent option on other OSes) and then retrying bind() call.

5 years agoMerge branch 'ondrej/remove-distros-near-eol' into 'main'
Ondřej Surý [Fri, 31 Jul 2020 10:27:03 +0000 (10:27 +0000)] 
Merge branch 'ondrej/remove-distros-near-eol' into 'main'

Remove CentOS 6 from GitLab CI, it will EOL before BIND 9.18 is released

See merge request isc-projects/bind9!3799

5 years agoRemove CentOS 6 from GitLab CI
Ondřej Surý [Thu, 2 Jul 2020 09:27:39 +0000 (11:27 +0200)] 
Remove CentOS 6 from GitLab CI

CentOS 6 will reach EoL on November 30th, 2020, i.e. before BIND 9.18
will be released.  Remove it from GitLab CI.

5 years agoMerge branch 'ondrej/documentation-rebuild' into 'main'
Ondřej Surý [Fri, 31 Jul 2020 08:52:28 +0000 (08:52 +0000)] 
Merge branch 'ondrej/documentation-rebuild' into 'main'

Rebuild the documentation

See merge request isc-projects/bind9!3905

5 years agoRebuild the documentation
Ondřej Surý [Fri, 31 Jul 2020 07:54:57 +0000 (09:54 +0200)] 
Rebuild the documentation

5 years agoMerge branch 'ondrej/august-release-placeholders-1' into 'main'
Ondřej Surý [Fri, 31 Jul 2020 07:28:38 +0000 (07:28 +0000)] 
Merge branch 'ondrej/august-release-placeholders-1' into 'main'

Add placeholders for August release

See merge request isc-projects/bind9!3903

5 years agoAdd CHANGES placeholder for [GL #2055]
Ondřej Surý [Fri, 31 Jul 2020 07:27:00 +0000 (09:27 +0200)] 
Add CHANGES placeholder for [GL #2055]

5 years agoAdd CHANGES placeholder for [GL #1997]
Ondřej Surý [Fri, 31 Jul 2020 07:24:56 +0000 (09:24 +0200)] 
Add CHANGES placeholder for [GL #1997]

5 years agoAdd CHANGES placeholder for [GL #1996]
Ondřej Surý [Fri, 31 Jul 2020 07:23:52 +0000 (09:23 +0200)] 
Add CHANGES placeholder for [GL #1996]

5 years agoAdd CHANGES placeholder for [GL #2037]
Ondřej Surý [Fri, 31 Jul 2020 07:21:32 +0000 (09:21 +0200)] 
Add CHANGES placeholder for [GL #2037]

5 years agoMerge branch '2020-configure-call-needs-to-be-cleaned-up-main-gcc-centos6-amd64'...
Mark Andrews [Fri, 31 Jul 2020 06:26:11 +0000 (06:26 +0000)] 
Merge branch '2020-configure-call-needs-to-be-cleaned-up-main-gcc-centos6-amd64' into 'main'

Resolve "configure call needs to be cleaned up main: gcc:centos6:amd64"

Closes #2020

See merge request isc-projects/bind9!3853

5 years agoremove --with-python from summary
Mark Andrews [Fri, 31 Jul 2020 05:16:20 +0000 (15:16 +1000)] 
remove --with-python from summary

5 years agoremove references to --with-libtool
Mark Andrews [Thu, 30 Jul 2020 01:53:17 +0000 (11:53 +1000)] 
remove references to --with-libtool

5 years agoRemove --with-libtool comment from README
Mark Andrews [Thu, 30 Jul 2020 01:50:32 +0000 (11:50 +1000)] 
Remove --with-libtool comment from README

5 years agoRemove no longer valid configure flags from configure calls:
Mark Andrews [Tue, 14 Jul 2020 02:32:40 +0000 (12:32 +1000)] 
Remove no longer valid configure flags from configure calls:

--with-libtool, --without-make-clean, --with-python

5 years agoMerge branch '1456-always-check-return-from-isc_refcount_decrement' into 'main'
Mark Andrews [Fri, 31 Jul 2020 00:56:45 +0000 (00:56 +0000)] 
Merge branch '1456-always-check-return-from-isc_refcount_decrement' into 'main'

Resolve "always check return from isc_refcount_decrement"

Closes #1456

See merge request isc-projects/bind9!2707

5 years agoAlways check the return from isc_refcount_decrement.
Mark Andrews [Thu, 5 Dec 2019 02:29:45 +0000 (13:29 +1100)] 
Always check the return from isc_refcount_decrement.

Created isc_refcount_decrement_expect macro to test conditionally
the return value to ensure it is in expected range.  Converted
unchecked isc_refcount_decrement to use isc_refcount_decrement_expect.
Converted INSIST(isc_refcount_decrement()...) to isc_refcount_decrement_expect.

5 years agoMerge branch '2033-rndc-dnstap-roll-fix-was-incomplete' into 'main'
Mark Andrews [Thu, 30 Jul 2020 23:59:42 +0000 (23:59 +0000)] 
Merge branch '2033-rndc-dnstap-roll-fix-was-incomplete' into 'main'

Resolve "'rndc dnstap --roll' fix was incomplete"

Closes #2033

See merge request isc-projects/bind9!3868

5 years agoRefactor the code that counts the last log version to keep
Mark Andrews [Mon, 20 Jul 2020 01:53:40 +0000 (11:53 +1000)] 
Refactor the code that counts the last log version to keep

When silencing the Coverity warning in remove_old_tsversions(), the code
was refactored to reduce the indentation levels and break down the long
code into individual functions.  This improve fix for [GL #1989].

5 years agoMerge branch '48-drop-systemtesttop-from-bin-tests-system' into 'main'
Michal Nowak [Thu, 30 Jul 2020 14:14:39 +0000 (14:14 +0000)] 
Merge branch '48-drop-systemtesttop-from-bin-tests-system' into 'main'

Drop $SYSTEMTESTTOP from bin/tests/system/

Closes #48

See merge request isc-projects/bind9!3623

5 years agoMake sure we don't introduce SYSTEMTESTTOP anymore
Michal Nowak [Tue, 28 Jul 2020 12:42:55 +0000 (14:42 +0200)] 
Make sure we don't introduce SYSTEMTESTTOP anymore

':!.gitlab-ci.yml' is a pathspec pattern used to limit paths in the "git
grep" command to all but the .gitlab-ci.yml file which includes the
checked word itself. This requires Git 2.13.

5 years agoRemove cross-test dependency on ckdnsrps.sh
Michal Nowak [Tue, 28 Jul 2020 11:19:08 +0000 (13:19 +0200)] 
Remove cross-test dependency on ckdnsrps.sh

5 years agoFix name of the test directory of stop.pl in masterformat test
Michal Nowak [Tue, 28 Jul 2020 10:58:51 +0000 (12:58 +0200)] 
Fix name of the test directory of stop.pl in masterformat test

5 years agoEnsure test fails if packet.pl does not work as expected
Michal Nowak [Tue, 28 Jul 2020 10:45:31 +0000 (12:45 +0200)] 
Ensure test fails if packet.pl does not work as expected

5 years agoSource config.guess from source root
Michal Nowak [Tue, 21 Jul 2020 14:29:14 +0000 (16:29 +0200)] 
Source config.guess from source root

It seems that config.guess gets always created in source root, so for
that sake of out-of-tree system test, we should expect the file there
instead of where configure was run.

5 years agoDrop $SYSTEMTESTTOP from bin/tests/system/
Michal Nowak [Tue, 21 Jul 2020 10:12:59 +0000 (12:12 +0200)] 
Drop $SYSTEMTESTTOP from bin/tests/system/

The $SYSTEMTESTTOP shell variable if often set to .. in various shell
scripts inside bin/tests/system/, but most of the time it is only
used one line later, while sourcing conf.sh. This hardly improves
code readability.

$SYSTEMTESTTOP is also used for the purpose of referencing
scripts/files living in bin/tests/system/, but given that the
variable is always set to a short, relative path, we can drop it and
replace all of its occurrences with the relative path without adversely
affecting code readability.

5 years agoMerge branch 'michal/only-run-system-tests-as-root-in-developer-mode' into 'main'
Michał Kępień [Thu, 30 Jul 2020 13:45:00 +0000 (13:45 +0000)] 
Merge branch 'michal/only-run-system-tests-as-root-in-developer-mode' into 'main'

Only run system tests as root in developer mode

See merge request isc-projects/bind9!3894

5 years agoOnly run system tests as root in developer mode
Michał Kępień [Thu, 30 Jul 2020 12:07:49 +0000 (14:07 +0200)] 
Only run system tests as root in developer mode

Running system tests with root privileges is potentially dangerous.
Only allow it when explicitly requested (by building with
--enable-developer).

5 years agoMerge branch '2024-fix-idle-timeout-for-connected-tcp-sockets' into 'main'
Michał Kępień [Thu, 30 Jul 2020 09:32:07 +0000 (09:32 +0000)] 
Merge branch '2024-fix-idle-timeout-for-connected-tcp-sockets' into 'main'

Fix idle timeout for connected TCP sockets

Closes #2024

See merge request isc-projects/bind9!3854

5 years agoAdd CHANGES for GL #2024
Michał Kępień [Thu, 30 Jul 2020 08:58:39 +0000 (10:58 +0200)] 
Add CHANGES for GL #2024

5 years agoFix idle timeout for connected TCP sockets
Michał Kępień [Thu, 30 Jul 2020 08:58:39 +0000 (10:58 +0200)] 
Fix idle timeout for connected TCP sockets

When named acting as a resolver connects to an authoritative server over
TCP, it sets the idle timeout for that connection to 20 seconds.  This
fixed timeout was picked back when the default processing timeout for
each client query was hardcoded to 30 seconds.  Commit
000a8970f840a0c27c5cc404826853c4674362ac made this processing timeout
configurable through "resolver-query-timeout" and decreased its default
value to 10 seconds, but the idle TCP timeout was not adjusted to
reflect that change.  As a result, with the current defaults in effect,
a single hung TCP connection will consistently cause the resolution
process for a given query to time out.

Set the idle timeout for connected TCP sockets to half of the client
query processing timeout configured for a resolver.  This allows named
to handle hung TCP connections more robustly and prevents the timeout
mismatch issue from resurfacing in the future if the default is ever
changed again.

5 years agoMerge branch 'marka-placeholder' into 'main'
Mark Andrews [Wed, 29 Jul 2020 23:39:16 +0000 (23:39 +0000)] 
Merge branch 'marka-placeholder' into 'main'

placeholder for [GL #2028]

See merge request isc-projects/bind9!3893

5 years agoplaceholder for [GL #2028]
Mark Andrews [Wed, 29 Jul 2020 23:34:58 +0000 (09:34 +1000)] 
placeholder for [GL #2028]

5 years agoMerge branch '2050-libuv-version' into 'main'
Evan Hunt [Tue, 28 Jul 2020 02:49:19 +0000 (02:49 +0000)] 
Merge branch '2050-libuv-version' into 'main'

report libuv version string in `named -V`

Closes #2050

See merge request isc-projects/bind9!3887

5 years agoreport libuv version string in `named -V`
Evan Hunt [Sat, 25 Jul 2020 00:04:02 +0000 (17:04 -0700)] 
report libuv version string in `named -V`

5 years agoMerge branch '2031-win32-fix' into 'main'
Evan Hunt [Mon, 27 Jul 2020 21:33:07 +0000 (21:33 +0000)] 
Merge branch '2031-win32-fix' into 'main'

Resolve "Windows crashes with netmgr-based statschannel"

Closes #2031

See merge request isc-projects/bind9!3888

5 years agoinitialize, rather than invalidating, new http buffers
Evan Hunt [Mon, 27 Jul 2020 18:03:33 +0000 (11:03 -0700)] 
initialize, rather than invalidating, new http buffers

when building without ISC_BUFFER_USEINLINE (which is the default on
Windows) an assertion failure could occur when setting up a new
isc_httpd_t object for the statistics channel.