]> git.ipfire.org Git - thirdparty/bind9.git/log
thirdparty/bind9.git
6 years agouse relative widths for zone table
Mark Andrews [Wed, 20 Feb 2019 03:57:32 +0000 (14:57 +1100)] 
use relative widths for zone table

6 years agoMerge branch 'placeholder' into 'master'
Evan Hunt [Thu, 12 Mar 2020 07:37:05 +0000 (07:37 +0000)] 
Merge branch 'placeholder' into 'master'

placeholder

See merge request isc-projects/bind9!3214

6 years agoplaceholder
Evan Hunt [Thu, 12 Mar 2020 07:36:23 +0000 (00:36 -0700)] 
placeholder

6 years agoMerge branch '4-make-libtool-mandatory' into 'master'
Ondřej Surý [Wed, 11 Mar 2020 23:07:53 +0000 (23:07 +0000)] 
Merge branch '4-make-libtool-mandatory' into 'master'

Remove no-libtool and internal symtable configure options

See merge request isc-projects/bind9!3207

6 years agoImprove the backtrace to print symbols when backtrace_symbols() is available
Ondřej Surý [Wed, 11 Mar 2020 08:55:48 +0000 (09:55 +0100)] 
Improve the backtrace to print symbols when backtrace_symbols() is available

The previous commit removed the code related to the internal symbol
table.  On platforms where available, we can now use backtrace_symbols()
to print more verbose symbols table to the output.

As there's now general availability of backtrace() and
backtrace_symbols() functions (see below), the commit also removes the
usage of glibc internals and the custom stack tracing.

* backtrace(), backtrace_symbols(), and backtrace_symbols_fd() are
  provided in glibc since version 2.1.
* backtrace(), backtrace_symbols(), and backtrace_symbols_fd() first
  appeared in Mac OS X 10.5.
* The backtrace() library of functions first appeared in NetBSD 7.0 and
  FreeBSD 10.0.

6 years agoRemove support for internal symbol table
Evan Hunt [Wed, 11 Mar 2020 04:15:43 +0000 (21:15 -0700)] 
Remove support for internal symbol table

Since we can no longer generate an internal symbol table, there
doesn't seem to be much reason to retain the code that reads it.

6 years agoRemove configure option to compile without libtool
Ondřej Surý [Tue, 10 Mar 2020 12:46:42 +0000 (13:46 +0100)] 
Remove configure option to compile without libtool

libtool is a requirement to use automake (see GL #4), so this commit
removes the ability to compile BIND 9 without libtool.

6 years agoRemove the ability to generate internal symbol table
Ondřej Surý [Tue, 10 Mar 2020 12:35:18 +0000 (13:35 +0100)] 
Remove the ability to generate internal symbol table

The internal symbol table cannot be generated when libtool is in use,
which is going to be a mandatory in the next commit.

6 years agoMerge branch 'ondrej/fix-clang-format-headers-symlinks' into 'master'
Ondřej Surý [Wed, 11 Mar 2020 09:21:07 +0000 (09:21 +0000)] 
Merge branch 'ondrej/fix-clang-format-headers-symlinks' into 'master'

Fix .clang-format.headers symlinks

See merge request isc-projects/bind9!3212

6 years agoFixup the headers formatting
Ondřej Surý [Wed, 11 Mar 2020 09:19:32 +0000 (10:19 +0100)] 
Fixup the headers formatting

6 years agoFix the deeper symlinks to .clang-format.headers
Ondřej Surý [Wed, 11 Mar 2020 09:16:45 +0000 (10:16 +0100)] 
Fix the deeper symlinks to .clang-format.headers

6 years agoMerge branch 'michal/minor-release-note-tweaks' into 'master'
Michał Kępień [Wed, 11 Mar 2020 08:52:35 +0000 (08:52 +0000)] 
Merge branch 'michal/minor-release-note-tweaks' into 'master'

Minor release note tweaks

See merge request isc-projects/bind9!3210

6 years agoReorder release note sections
Michał Kępień [Wed, 11 Mar 2020 08:45:31 +0000 (09:45 +0100)] 
Reorder release note sections

6 years agoAdd GitLab identifier to rwlock release note
Michał Kępień [Wed, 11 Mar 2020 08:45:31 +0000 (09:45 +0100)] 
Add GitLab identifier to rwlock release note

6 years agoMerge branch '1636-add-release-note-about-controlling-source-ports' into 'master'
Michał Kępień [Wed, 11 Mar 2020 08:22:53 +0000 (08:22 +0000)] 
Merge branch '1636-add-release-note-about-controlling-source-ports' into 'master'

Add release note about controlling source ports

Closes #1636

See merge request isc-projects/bind9!3192

6 years agoAdd release note about controlling source ports
Michał Kępień [Wed, 11 Mar 2020 08:06:40 +0000 (09:06 +0100)] 
Add release note about controlling source ports

6 years agoRelease note wording tweaks
Michał Kępień [Wed, 11 Mar 2020 08:06:40 +0000 (09:06 +0100)] 
Release note wording tweaks

6 years agoMove pthread rwlocks release note to a section
Michał Kępień [Wed, 11 Mar 2020 08:06:40 +0000 (09:06 +0100)] 
Move pthread rwlocks release note to a section

6 years agoMerge branch 'matthijs-disable-mscv-kasp-system-test' into 'master'
Michał Kępień [Wed, 11 Mar 2020 07:18:49 +0000 (07:18 +0000)] 
Merge branch 'matthijs-disable-mscv-kasp-system-test' into 'master'

Disable kasp test on Windows

See merge request isc-projects/bind9!3206

6 years agoRemove leftover set_keydir
Matthijs Mekking [Tue, 10 Mar 2020 12:48:48 +0000 (13:48 +0100)] 
Remove leftover set_keydir

6 years agoDisable kasp test on Windows
Matthijs Mekking [Tue, 10 Mar 2020 12:29:35 +0000 (13:29 +0100)] 
Disable kasp test on Windows

The kasp system test is timing critical.  The test passes on all
Linux based machines, but fails frequently on Windows.  The test
takes a lot more time on Windows and at the final checks fail
because the expected next key event is too far off.  For example:

I:kasp:check next key event for zone step2.algorithm-roll.kasp (570)
I:kasp:error: bad next key event time 20909 for zone \
  step2.algorithm-roll.kasp (expect 21600)
I:kasp:failed

This is because the kasp system test calculates the time when the
next key event should occur based on the policy.  This assumes that
named is able to do key management within a minute.  But starting,
named, doing key management for other zones, and reconfiguring takes
much more time on Windows and thus the next key event on Windows is
much shorter than anticipated.

That this happens is a good thing because this means that the
correct next key event is used, but is not so nice for testing, as
it is hard to determine how much time named needed before finishing
the current key event.

Disable the kasp test on Windows now because it is blocking the
release.  We know the cause of these test failures, and it is clear
that this is a fault in the test, not the code.  Therefore we feel
comfortable disabling the test right now and work on a fix while
unblocking the release.

6 years agoMerge branch '1476-threadsanitizer-data-race-lib-isc-log-multiple-issues' into 'master'
Matthijs Mekking [Tue, 10 Mar 2020 12:11:19 +0000 (12:11 +0000)] 
Merge branch '1476-threadsanitizer-data-race-lib-isc-log-multiple-issues' into 'master'

Resolve "ThreadSanitizer: data race lib/isc/log.c - multiple issues"

Closes #1476

See merge request isc-projects/bind9!2791

6 years agoFixed data race in log.c
Diego Fronza [Fri, 20 Dec 2019 22:29:18 +0000 (19:29 -0300)] 
Fixed data race in log.c

A data race was happening while BIND was starting due to
isc_log_wouldlog function accessing lctx->logconfig without a lock.

To prevent that without incurring much costs, that variable was made
atomic.

6 years agoMerge branch 'mnowak/abi-tracker-helper' into 'master'
Michal Nowak [Tue, 10 Mar 2020 08:47:04 +0000 (08:47 +0000)] 
Merge branch 'mnowak/abi-tracker-helper' into 'master'

Add API Checker

See merge request isc-projects/bind9!3120

6 years agoAdd API Checker
Michal Nowak [Wed, 26 Feb 2020 10:24:45 +0000 (11:24 +0100)] 
Add API Checker

ABI checker tools generate HTML and TXT API compatibility reports of
BIND libraries. Comparison is being done between two bind source trees
which hold built BIND.

In the CI one version is the reference version defined by
BIND_BASELINE_VERSION variable, the latter one is the HEAD of branch
under test.

6 years agoMerge branch '1664-double-unlock' into 'master'
Evan Hunt [Mon, 9 Mar 2020 23:47:11 +0000 (23:47 +0000)] 
Merge branch '1664-double-unlock' into 'master'

remove redundant ZONEDB_UNLOCK

Closes #1664

See merge request isc-projects/bind9!3197

6 years agoremove redundant ZONEDB_UNLOCK
Evan Hunt [Mon, 9 Mar 2020 21:05:14 +0000 (14:05 -0700)] 
remove redundant ZONEDB_UNLOCK

6 years agoMerge branch 'ondrej/clang-format-improve-includes' into 'master'
Ondřej Surý [Mon, 9 Mar 2020 15:42:24 +0000 (15:42 +0000)] 
Merge branch 'ondrej/clang-format-improve-includes' into 'master'

Improve #include block sorting and grouping in clang-format

See merge request isc-projects/bind9!3193

6 years agoUse the new sorting rules to regroup #include headers
Ondřej Surý [Mon, 9 Mar 2020 15:17:26 +0000 (16:17 +0100)] 
Use the new sorting rules to regroup #include headers

6 years agoImprove the #include block sorting
Ondřej Surý [Mon, 9 Mar 2020 14:26:54 +0000 (15:26 +0100)] 
Improve the #include block sorting

The IncludeCategories was incomplete, it missed pk11/ and dst/ headers
and the rule that put "" header after all <> headers was broken.

6 years agoMerge branch '1653-dnssec-policy-view-race' into 'master'
Matthijs Mekking [Mon, 9 Mar 2020 14:40:59 +0000 (14:40 +0000)] 
Merge branch '1653-dnssec-policy-view-race' into 'master'

Resolve "Race condition with dnssec-policy, same zone in different views"

Closes #1653

See merge request isc-projects/bind9!3142

6 years agoUpdate changes, documentation
Matthijs Mekking [Tue, 3 Mar 2020 06:52:23 +0000 (07:52 +0100)] 
Update changes, documentation

6 years agoFix race condition dnssec-policy with views
Matthijs Mekking [Tue, 3 Mar 2020 05:58:45 +0000 (06:58 +0100)] 
Fix race condition dnssec-policy with views

When configuring the same dnssec-policy for two zones with the same
name but in different views, there is a race condition for who will
run the keymgr first. If running sequential only one set of keys will
be created, if running parallel two set of keys will be created.

Lock the kasp when running looking for keys and running the key
manager. This way, for the same zone in different views only one
keyset will be created.

The dnssec-policy does not implement sharing keys between different
zones.

6 years agoMerge branch 'michal/do-not-run-openbsd-system-test-jobs-for-tags' into 'master'
Michał Kępień [Mon, 9 Mar 2020 13:33:59 +0000 (13:33 +0000)] 
Merge branch 'michal/do-not-run-openbsd-system-test-jobs-for-tags' into 'master'

Do not run OpenBSD system test jobs for tags

See merge request isc-projects/bind9!3183

6 years agoDo not run OpenBSD system test jobs for tags
Michał Kępień [Mon, 9 Mar 2020 13:33:04 +0000 (14:33 +0100)] 
Do not run OpenBSD system test jobs for tags

OpenBSD virtual machines seem to affected particularly badly by other
activity happening on the host.  This causes trouble around release
time: when multiple tags are pushed to the repository, a large number of
jobs is started concurrently on all CI runners.  In extreme cases, this
causes the system test suite to run for about an hour (!) on OpenBSD
VMs, with multiple tests failing.  We investigated the test artifacts
for all such cases in the past and the outcome was always the same: test
failures were caused by extremely slow I/O on the guest.  We tried
various tricks to work around this problem, but nothing helped.

Given the above, stop running OpenBSD system test jobs for pending BIND
releases to prevent the results of these jobs from affecting the
assessment of a given release's readiness for publication.  This change
does not affect OpenBSD build jobs.  OpenBSD system test jobs will still
be run for scheduled and web-requested pipelines, to make sure we catch
any severe issues with test code on that platform sooner or later.

6 years agoMerge branch 'matthijs-refactor-kasp-test' into 'master'
Matthijs Mekking [Mon, 9 Mar 2020 12:22:56 +0000 (12:22 +0000)] 
Merge branch 'matthijs-refactor-kasp-test' into 'master'

Refactor kasp system test

See merge request isc-projects/bind9!3141

6 years agoAdd check calls to kasp zsk-retired test
Matthijs Mekking [Mon, 9 Mar 2020 09:38:58 +0000 (10:38 +0100)] 
Add check calls to kasp zsk-retired test

The test case for zsk-retired was missing the actual checks.  Add
them and fix the set_policy call to expect three keys.

6 years agoMore consistent spacing and comments
Matthijs Mekking [Mon, 9 Mar 2020 09:37:35 +0000 (10:37 +0100)] 
More consistent spacing and comments

Some comments started with a lowercased letter. Capitalized them to
be more consistent with the rest of the comments.

Add some newlines between `set_*` calls and check calls, also to be
more consistent with the other test cases.

6 years agoReplace key_states
Matthijs Mekking [Mon, 2 Mar 2020 10:50:55 +0000 (11:50 +0100)] 
Replace key_states

6 years agoReplace key_timings
Matthijs Mekking [Fri, 28 Feb 2020 11:27:41 +0000 (12:27 +0100)] 
Replace key_timings

6 years agoReplace key_properties
Matthijs Mekking [Fri, 28 Feb 2020 11:02:51 +0000 (12:02 +0100)] 
Replace key_properties

6 years agoReplace zone_properties
Matthijs Mekking [Thu, 27 Feb 2020 17:15:07 +0000 (18:15 +0100)] 
Replace zone_properties

6 years agoMerge branch '1413-fix-dnssec-test' into 'master'
Matthijs Mekking [Mon, 9 Mar 2020 11:02:10 +0000 (11:02 +0000)] 
Merge branch '1413-fix-dnssec-test' into 'master'

Fix dnssec test

Closes #1413

See merge request isc-projects/bind9!2956

6 years agoFix dnssec test
Matthijs Mekking [Thu, 23 Jan 2020 15:04:47 +0000 (16:04 +0100)] 
Fix dnssec test

There is a failure mode which gets triggered on heavily loaded
systems. A key change is scheduled in 5 seconds to make ZSK2 inactive
and ZSK3 active, but `named` takes more than 5 seconds to progress
from `rndc loadkeys` to the query check. At this time the SOA RRset
is already signed by the new ZSK which is not expected to be active
at that point yet.

Split up the checks to test the case where RRsets are signed
correctly with the offline KSK (maintained the signature) and
the active ZSK.  First run, RRsets should be signed with the still
active ZSK2, second run RRsets should be signed with the new active
ZSK3.

6 years agoMerge branch 'fix-glob-windows' into 'master'
Diego dos Santos Fronza [Fri, 6 Mar 2020 21:09:58 +0000 (21:09 +0000)] 
Merge branch 'fix-glob-windows' into 'master'

Fixed missing list initialization

See merge request isc-projects/bind9!3184

6 years agoFixed missing list initialization
Diego Fronza [Fri, 6 Mar 2020 19:53:20 +0000 (16:53 -0300)] 
Fixed missing list initialization

This commit fixes isc_glob function on windows environments.

The file_list_t * object pointed to by pglob->reserved was missing
ISC_LIST_INIT intialization macro.

6 years agoMerge branch 'kasp-test-algoroll' into 'master'
Matthijs Mekking [Fri, 6 Mar 2020 15:16:19 +0000 (15:16 +0000)] 
Merge branch 'kasp-test-algoroll' into 'master'

Test dnssec-policy algorithm rollover, fix some bugs

Closes #1626, #1625, and #1624

See merge request isc-projects/bind9!3086

6 years agoAdd additional wait period for algorithm rollover
Matthijs Mekking [Thu, 20 Feb 2020 15:00:50 +0000 (16:00 +0100)] 
Add additional wait period for algorithm rollover

We may be checking the algorithm steps too fast: the reconfig
command may still be in progress. Make sure the zones are signed
and loaded by digging the NSEC records for these zones.

6 years agoMake clang-format happy
Matthijs Mekking [Thu, 20 Feb 2020 10:04:08 +0000 (11:04 +0100)] 
Make clang-format happy

6 years agoupdate CHANGES
Matthijs Mekking [Wed, 19 Feb 2020 11:28:52 +0000 (12:28 +0100)] 
update CHANGES

6 years agoAdd CSK algorithm rollover test
Matthijs Mekking [Wed, 19 Feb 2020 11:28:36 +0000 (12:28 +0100)] 
Add CSK algorithm rollover test

6 years ago[#1624] dnssec-policy change retire unwanted keys
Matthijs Mekking [Tue, 18 Feb 2020 15:58:56 +0000 (16:58 +0100)] 
[#1624] dnssec-policy change retire unwanted keys

When changing a dnssec-policy, existing keys with properties that no
longer match were not being retired.

6 years ago[#1625] Algorithm rollover waited too long
Matthijs Mekking [Tue, 18 Feb 2020 15:57:37 +0000 (16:57 +0100)] 
[#1625] Algorithm rollover waited too long

Algorithm rollover waited too long before introducing zone
signatures.  It waited to make sure all signatures were resigned,
but when introducing a new algorithm, all signatures are resigned
immediately.  Only add the sign delay if there is a predecessor key.

6 years ago[#1626] Fix stuck algorithm rollover
Matthijs Mekking [Tue, 18 Feb 2020 15:55:36 +0000 (16:55 +0100)] 
[#1626] Fix stuck algorithm rollover

Algorithm rollover was stuck on submitting DS because keymgr thought
it would move to an invalid state.  It did not match the current
key because it checked it against the current key in the next state.
Fixed by when checking the current key, check it against the desired
state, not the existing state.

6 years agoAdd algorithm rollover test case
Matthijs Mekking [Tue, 18 Feb 2020 15:36:31 +0000 (16:36 +0100)] 
Add algorithm rollover test case

Add a test case for algorithm rollover.  This is triggered by
changing the dnssec-policy.  A new nameserver ns6 is introduced
for tests related to dnssec-policy changes.

This requires a slight change in check_next_key_event to only
check the last occurrence.  Also, change the debug log message in
lib/dns/zone.c to deal with checks when no next scheduled key event
exists (and default to loadkeys interval 3600).

6 years agoRemove unneeded step6 zone
Matthijs Mekking [Tue, 18 Feb 2020 15:34:20 +0000 (16:34 +0100)] 
Remove unneeded step6 zone

The zone 'step6.ksk-doubleksk.autosign' is configured but is not
set up nor tested.  Remove the unneeded configured zone.

6 years agoIntroduce enable dnssec test case
Matthijs Mekking [Tue, 18 Feb 2020 15:33:41 +0000 (16:33 +0100)] 
Introduce enable dnssec test case

6 years agoPrepare kasp for algorithm rollover test
Matthijs Mekking [Thu, 13 Feb 2020 10:35:38 +0000 (11:35 +0100)] 
Prepare kasp for algorithm rollover test

Algorithm rollover will require four keys so introduce KEY4.
Also it requires to look at key files for multiple algorithms so
change getting key ids to be algorithm rollover agnostic (adjusting
count checks).  The algorithm will be verified in check_key so
relaxing 'get_keyids' is fine.

Replace '${_alg_num}' with '$(key_get KEY[1-4] ALG_NUM)' in checks
to deal with multiple algorithms.

6 years agoMerge branch 'michal/fix-using-sibling-root-libuv-for-windows-builds' into 'master'
Michał Kępień [Fri, 6 Mar 2020 12:36:55 +0000 (12:36 +0000)] 
Merge branch 'michal/fix-using-sibling-root-libuv-for-windows-builds' into 'master'

Fix using sibling-root libuv for Windows builds

See merge request isc-projects/bind9!3181

6 years agoFix using sibling-root libuv for Windows builds
Michał Kępień [Fri, 6 Mar 2020 12:25:45 +0000 (13:25 +0100)] 
Fix using sibling-root libuv for Windows builds

HAVE_UV_IMPORT and other config.h macros must not be set unconditionally
because no existing libuv release exposes uv_import() and/or uv_export()
yet.  Windows builds not passing an explicit path to libuv to
win32utils/Configure are currently broken because of this, so comment
out the offending lines and describe when the aforementioned config.h
macros should be set.

6 years agoMerge branch '1515-ixfr-size-limit' into 'master'
Evan Hunt [Fri, 6 Mar 2020 02:51:18 +0000 (02:51 +0000)] 
Merge branch '1515-ixfr-size-limit' into 'master'

Send AXFR instead of requested IXFR if the size of the incremental transfer is too large to sensibly IXFR

Closes #1375 and #1515

See merge request isc-projects/bind9!3113

6 years agoCHANGES and release note
Evan Hunt [Mon, 24 Feb 2020 04:54:58 +0000 (20:54 -0800)] 
CHANGES and release note

6 years agoadd serial number to "transfer ended" log messages
Evan Hunt [Thu, 27 Feb 2020 19:43:03 +0000 (11:43 -0800)] 
add serial number to "transfer ended" log messages

6 years agoadd a system test for AXFR fallback when max-ixfr-ratio is exceeded
Evan Hunt [Sat, 22 Feb 2020 06:48:34 +0000 (22:48 -0800)] 
add a system test for AXFR fallback when max-ixfr-ratio is exceeded

also cleaned up the ixfr system test:

- use retry_quiet when applicable
- use scripts to generate test zones
- improve consistency

6 years agocheck size ratio when responding to IXFR requests
Evan Hunt [Sat, 22 Feb 2020 01:22:06 +0000 (17:22 -0800)] 
check size ratio when responding to IXFR requests

6 years agoimprove calculation of database transfer size
Evan Hunt [Sat, 22 Feb 2020 08:37:05 +0000 (00:37 -0800)] 
improve calculation of database transfer size

- change name of 'bytes' to 'xfrsize' in dns_db_getsize() parameter list
  and related variables; this is a more accurate representation of what
  the function is doing
- change the size calculations in dns_db_getsize() to more accurately
  represent the space needed for a *XFR message or journal file to contain
  the data in the database. previously we returned the sizes of all
  rdataslabs, including header overhead and offset tables, which
  resulted in the database size being reported as much larger than the
  equivalent *XFR or journal.
- map files caused a particular problem here: the fullname can't be
  determined from the node while a file is being deserialized, because
  the uppernode pointers aren't set yet. so we store "full name length"
  in the dns_rbtnode structure while serializing, and clear it after
  deserialization is complete.

6 years agodns_journal_iter_init() can now return the size of the delta
Evan Hunt [Sat, 22 Feb 2020 01:05:04 +0000 (17:05 -0800)] 
dns_journal_iter_init() can now return the size of the delta

the call initailizing a journal iterator can now optionally return
to the caller the size in bytes of an IXFR message (not including
DNS header overhead, signatures etc) containing the differences from
the beginning to the ending serial number.

this is calculated by scanning the journal transaction headers to
calculate the transfer size. since journal file records contain a length
field that is not included in IXFR messages, we subtract out the length
of those fields from the overall transaction length.

this necessitated adding an "RR count" field to the journal transaction
header, so we know how many length fields to subract. NOTE: this will
make existing journal files stop working!

6 years agoadd syntax and setter/getter functions to configure max-ixfr-ratio
Evan Hunt [Fri, 21 Feb 2020 18:53:08 +0000 (10:53 -0800)] 
add syntax and setter/getter functions to configure max-ixfr-ratio

6 years agodocument max-ixfr-ratio
Evan Hunt [Fri, 21 Feb 2020 21:08:49 +0000 (13:08 -0800)] 
document max-ixfr-ratio

6 years agoMerge branch '1628-release-process-failed-to-detect-that-header-file-was-not-installe...
Mark Andrews [Fri, 6 Mar 2020 01:04:07 +0000 (01:04 +0000)] 
Merge branch '1628-release-process-failed-to-detect-that-header-file-was-not-installed' into 'master'

Resolve "Release process failed to detect that header file was not installed."

Closes #1628

See merge request isc-projects/bind9!3089

6 years agotest installed header files
Mark Andrews [Wed, 19 Feb 2020 22:31:05 +0000 (09:31 +1100)] 
test installed header files

6 years agoMerge branch 'marka-install-missing-header-files' into 'master'
Mark Andrews [Thu, 5 Mar 2020 23:10:53 +0000 (23:10 +0000)] 
Merge branch 'marka-install-missing-header-files' into 'master'

Fix lists of installed header files

See merge request isc-projects/bind9!3173

6 years agoFix lists of installed header files
Michał Kępień [Thu, 5 Mar 2020 11:52:11 +0000 (12:52 +0100)] 
Fix lists of installed header files

6 years agoMerge branch 'wpk/only-use-timer-if-initialized' into 'master'
Witold Krecicki [Thu, 5 Mar 2020 23:08:02 +0000 (23:08 +0000)] 
Merge branch 'wpk/only-use-timer-if-initialized' into 'master'

Only use tcpdns timer if it's initialized.

See merge request isc-projects/bind9!3171

6 years agoOnly use tcpdns timer if it's initialized.
Witold Kręcicki [Thu, 5 Mar 2020 21:56:31 +0000 (22:56 +0100)] 
Only use tcpdns timer if it's initialized.

6 years agoMerge branch 'marka-sort-AC_CONFIG_FILES' into 'master'
Mark Andrews [Thu, 5 Mar 2020 21:47:02 +0000 (21:47 +0000)] 
Merge branch 'marka-sort-AC_CONFIG_FILES' into 'master'

sort AC_CONFIG_FILES

See merge request isc-projects/bind9!3167

6 years agosort AC_CONFIG_FILES
Mark Andrews [Thu, 5 Mar 2020 21:17:06 +0000 (08:17 +1100)] 
sort AC_CONFIG_FILES

6 years agoMerge branch '1643-tcp-connections-accounting' into 'master'
Witold Krecicki [Thu, 5 Mar 2020 20:31:04 +0000 (20:31 +0000)] 
Merge branch '1643-tcp-connections-accounting' into 'master'

Resolve "Problems reported in BIND 9.16.0 after hitting tcp-clients limit"

Closes #1643

See merge request isc-projects/bind9!3163

6 years agoCHANGES note
Witold Kręcicki [Thu, 5 Mar 2020 13:25:04 +0000 (14:25 +0100)] 
CHANGES note

6 years agoFix TCPDNS socket closing issues
Witold Kręcicki [Mon, 2 Mar 2020 11:10:26 +0000 (12:10 +0100)] 
Fix TCPDNS socket closing issues

6 years agoadd a test of normal TCP query behavior before and after high-water test
Evan Hunt [Fri, 28 Feb 2020 22:47:10 +0000 (14:47 -0800)] 
add a test of normal TCP query behavior before and after high-water test

6 years agoLimit TCP connection quota logging to 1/s
Witold Kręcicki [Fri, 28 Feb 2020 12:58:13 +0000 (13:58 +0100)] 
Limit TCP connection quota logging to 1/s

6 years agoProper accounting of active TCP connections
Witold Kręcicki [Fri, 28 Feb 2020 10:57:51 +0000 (11:57 +0100)] 
Proper accounting of active TCP connections

6 years agoMerge branch 'mnowak/respdiff' into 'master'
Michal Nowak [Thu, 5 Mar 2020 14:45:46 +0000 (14:45 +0000)] 
Merge branch 'mnowak/respdiff' into 'master'

Add respdiff test

See merge request isc-projects/bind9!3078

6 years agoAdd respdiff job
Michal Nowak [Thu, 6 Feb 2020 14:53:36 +0000 (15:53 +0100)] 
Add respdiff job

This job leverages respdiff test from the private bind-qa repo.

6 years agoMerge branch '1650-fix-race-in-killoldestclient' into 'master'
Witold Krecicki [Thu, 5 Mar 2020 09:02:11 +0000 (09:02 +0000)] 
Merge branch '1650-fix-race-in-killoldestclient' into 'master'

Destroy query in killoldestclient under a lock

Closes #1650

See merge request isc-projects/bind9!3146

6 years agoDestroy query in killoldestquery under a lock.
Witold Kręcicki [Tue, 3 Mar 2020 09:09:17 +0000 (10:09 +0100)] 
Destroy query in killoldestquery under a lock.

Fixes a race between ns_client_killoldestquery and ns_client_endrequest -
killoldestquery takes a client from `recursing` list while endrequest
destroys client object, then killoldestquery works on a destroyed client
object. Prevent it by holding reclist lock while cancelling query.

6 years agoMerge branch '1647-addtrustedkey-dnskey' into 'master'
Evan Hunt [Wed, 4 Mar 2020 23:41:11 +0000 (23:41 +0000)] 
Merge branch '1647-addtrustedkey-dnskey' into 'master'

Resolve "delv 9.16.0, failed to add trusted key '.': ran out of space"

Closes #1647

See merge request isc-projects/bind9!3158

6 years agoCHANGES
Evan Hunt [Wed, 4 Mar 2020 16:54:53 +0000 (08:54 -0800)] 
CHANGES

6 years agoadd a system test to check that delv loads trust anchors correctly
Evan Hunt [Wed, 4 Mar 2020 16:54:03 +0000 (08:54 -0800)] 
add a system test to check that delv loads trust anchors correctly

6 years agoFix dns_client_addtrustedkey(dns_rdatatype_dnskey)
Tony Finch [Fri, 28 Feb 2020 20:08:04 +0000 (20:08 +0000)] 
Fix dns_client_addtrustedkey(dns_rdatatype_dnskey)

Use a buffer that is big enough for DNSKEY records as well as DS
records.

6 years agoMerge branch 'mnowak/pkcs11-test-fix' into 'master'
Michal Nowak [Wed, 4 Mar 2020 16:06:31 +0000 (16:06 +0000)] 
Merge branch 'mnowak/pkcs11-test-fix' into 'master'

Fix pkcs11 test

Closes #1496

See merge request isc-projects/bind9!3116

6 years agoFix "pkcs11" system test
Michal Nowak [Wed, 4 Mar 2020 16:06:31 +0000 (16:06 +0000)] 
Fix "pkcs11" system test

  - Define the SLOT environment variable before starting the test.  This
    variable defaults to 0 and that does not work with SoftHSM 2.

  - The system test expects the PIN environment variable to be set to
    "1234" while bin/tests/prepare-softhsm2.sh sets it to "0000".
    Update bin/tests/prepare-softhsm2.sh so that it sets the PIN to
    "1234".

  - Move contents of bin/tests/system/pkcs11/prereq.sh to
    bin/tests/system/pkcs11/setup.sh as the former was creating a file
    called "supported" that was getting removed by the latter before
    bin/tests/system/pkcs11/tests.sh could access it.

  - Fix typo in "have_ecx".

6 years agoMerge branch 'wpk-use-pthread-rwlock-by-default' into 'master'
Witold Krecicki [Wed, 4 Mar 2020 09:50:56 +0000 (09:50 +0000)] 
Merge branch 'wpk-use-pthread-rwlock-by-default' into 'master'

Use pthread rwlocks by default

See merge request isc-projects/bind9!3125

6 years agoAdd release notes for pthread rwlocks change
Witold Kręcicki [Thu, 27 Feb 2020 12:21:31 +0000 (13:21 +0100)] 
Add release notes for pthread rwlocks change

6 years agoUse pthread rwlocks by default
Witold Kręcicki [Thu, 27 Feb 2020 12:21:31 +0000 (13:21 +0100)] 
Use pthread rwlocks by default

6 years agoMerge branch '1532-nta-validate-except' into 'master'
Evan Hunt [Wed, 4 Mar 2020 09:09:53 +0000 (09:09 +0000)] 
Merge branch '1532-nta-validate-except' into 'master'

list "validate-except" entries in "rndc nta -d" and "rndc secroots"

Closes #1532

See merge request isc-projects/bind9!3152

6 years agolist "validate-except" entries in "rndc nta -d" and "rndc secroots"
Evan Hunt [Wed, 4 Mar 2020 06:46:58 +0000 (22:46 -0800)] 
list "validate-except" entries in "rndc nta -d" and "rndc secroots"

- no longer exclude these entries when dumping the NTA table
- indicate "validate-except" entries with the keyword "permanent" in
  place of an expiry date
- add a test for this feature, and update other tests to account for
  the presence of extra lines in some rndc outputs
- incidentally removed the unused function dns_ntatable_dump()
- CHANGES, release note

6 years agoMerge branch '1656-masterformat-system-test-failed-missing-sleep-1' into 'master'
Mark Andrews [Wed, 4 Mar 2020 07:14:48 +0000 (07:14 +0000)] 
Merge branch '1656-masterformat-system-test-failed-missing-sleep-1' into 'master'

Resolve "masterformat system test failed - missing "sleep 1""

Closes #1656

See merge request isc-projects/bind9!3151

6 years agoproperly wait for zone to be loaded
Mark Andrews [Wed, 4 Mar 2020 04:39:08 +0000 (15:39 +1100)] 
properly wait for zone to be loaded