]> git.ipfire.org Git - thirdparty/bind9.git/log
thirdparty/bind9.git
5 years agoAdd CHANGES and release note for GL #2038
Witold Kręcicki [Tue, 21 Jul 2020 12:56:45 +0000 (14:56 +0200)] 
Add CHANGES and release note for GL #2038

5 years agonetmgr: retry binding with IP_FREEBIND when EADDRNOTAVAIL is returned.
Witold Kręcicki [Tue, 21 Jul 2020 11:29:14 +0000 (13:29 +0200)] 
netmgr: retry binding with IP_FREEBIND when EADDRNOTAVAIL is returned.

When a new IPv6 interface/address appears it's first in a tentative
state - in which we cannot bind to it, yet it's already being reported
by the route socket. Because of that BIND9 is unable to listen on any
newly detected IPv6 addresses. Fix it by setting IP_FREEBIND option (or
equivalent option on other OSes) and then retrying bind() call.

5 years agoMerge branch 'ondrej/remove-distros-near-eol' into 'main'
Ondřej Surý [Fri, 31 Jul 2020 10:27:03 +0000 (10:27 +0000)] 
Merge branch 'ondrej/remove-distros-near-eol' into 'main'

Remove CentOS 6 from GitLab CI, it will EOL before BIND 9.18 is released

See merge request isc-projects/bind9!3799

5 years agoRemove CentOS 6 from GitLab CI
Ondřej Surý [Thu, 2 Jul 2020 09:27:39 +0000 (11:27 +0200)] 
Remove CentOS 6 from GitLab CI

CentOS 6 will reach EoL on November 30th, 2020, i.e. before BIND 9.18
will be released.  Remove it from GitLab CI.

5 years agoMerge branch 'ondrej/documentation-rebuild' into 'main'
Ondřej Surý [Fri, 31 Jul 2020 08:52:28 +0000 (08:52 +0000)] 
Merge branch 'ondrej/documentation-rebuild' into 'main'

Rebuild the documentation

See merge request isc-projects/bind9!3905

5 years agoRebuild the documentation
Ondřej Surý [Fri, 31 Jul 2020 07:54:57 +0000 (09:54 +0200)] 
Rebuild the documentation

5 years agoMerge branch 'ondrej/august-release-placeholders-1' into 'main'
Ondřej Surý [Fri, 31 Jul 2020 07:28:38 +0000 (07:28 +0000)] 
Merge branch 'ondrej/august-release-placeholders-1' into 'main'

Add placeholders for August release

See merge request isc-projects/bind9!3903

5 years agoAdd CHANGES placeholder for [GL #2055]
Ondřej Surý [Fri, 31 Jul 2020 07:27:00 +0000 (09:27 +0200)] 
Add CHANGES placeholder for [GL #2055]

5 years agoAdd CHANGES placeholder for [GL #1997]
Ondřej Surý [Fri, 31 Jul 2020 07:24:56 +0000 (09:24 +0200)] 
Add CHANGES placeholder for [GL #1997]

5 years agoAdd CHANGES placeholder for [GL #1996]
Ondřej Surý [Fri, 31 Jul 2020 07:23:52 +0000 (09:23 +0200)] 
Add CHANGES placeholder for [GL #1996]

5 years agoAdd CHANGES placeholder for [GL #2037]
Ondřej Surý [Fri, 31 Jul 2020 07:21:32 +0000 (09:21 +0200)] 
Add CHANGES placeholder for [GL #2037]

5 years agoMerge branch '2020-configure-call-needs-to-be-cleaned-up-main-gcc-centos6-amd64'...
Mark Andrews [Fri, 31 Jul 2020 06:26:11 +0000 (06:26 +0000)] 
Merge branch '2020-configure-call-needs-to-be-cleaned-up-main-gcc-centos6-amd64' into 'main'

Resolve "configure call needs to be cleaned up main: gcc:centos6:amd64"

Closes #2020

See merge request isc-projects/bind9!3853

5 years agoremove --with-python from summary
Mark Andrews [Fri, 31 Jul 2020 05:16:20 +0000 (15:16 +1000)] 
remove --with-python from summary

5 years agoremove references to --with-libtool
Mark Andrews [Thu, 30 Jul 2020 01:53:17 +0000 (11:53 +1000)] 
remove references to --with-libtool

5 years agoRemove --with-libtool comment from README
Mark Andrews [Thu, 30 Jul 2020 01:50:32 +0000 (11:50 +1000)] 
Remove --with-libtool comment from README

5 years agoRemove no longer valid configure flags from configure calls:
Mark Andrews [Tue, 14 Jul 2020 02:32:40 +0000 (12:32 +1000)] 
Remove no longer valid configure flags from configure calls:

--with-libtool, --without-make-clean, --with-python

5 years agoMerge branch '1456-always-check-return-from-isc_refcount_decrement' into 'main'
Mark Andrews [Fri, 31 Jul 2020 00:56:45 +0000 (00:56 +0000)] 
Merge branch '1456-always-check-return-from-isc_refcount_decrement' into 'main'

Resolve "always check return from isc_refcount_decrement"

Closes #1456

See merge request isc-projects/bind9!2707

5 years agoAlways check the return from isc_refcount_decrement.
Mark Andrews [Thu, 5 Dec 2019 02:29:45 +0000 (13:29 +1100)] 
Always check the return from isc_refcount_decrement.

Created isc_refcount_decrement_expect macro to test conditionally
the return value to ensure it is in expected range.  Converted
unchecked isc_refcount_decrement to use isc_refcount_decrement_expect.
Converted INSIST(isc_refcount_decrement()...) to isc_refcount_decrement_expect.

5 years agoMerge branch '2033-rndc-dnstap-roll-fix-was-incomplete' into 'main'
Mark Andrews [Thu, 30 Jul 2020 23:59:42 +0000 (23:59 +0000)] 
Merge branch '2033-rndc-dnstap-roll-fix-was-incomplete' into 'main'

Resolve "'rndc dnstap --roll' fix was incomplete"

Closes #2033

See merge request isc-projects/bind9!3868

5 years agoRefactor the code that counts the last log version to keep
Mark Andrews [Mon, 20 Jul 2020 01:53:40 +0000 (11:53 +1000)] 
Refactor the code that counts the last log version to keep

When silencing the Coverity warning in remove_old_tsversions(), the code
was refactored to reduce the indentation levels and break down the long
code into individual functions.  This improve fix for [GL #1989].

5 years agoMerge branch '48-drop-systemtesttop-from-bin-tests-system' into 'main'
Michal Nowak [Thu, 30 Jul 2020 14:14:39 +0000 (14:14 +0000)] 
Merge branch '48-drop-systemtesttop-from-bin-tests-system' into 'main'

Drop $SYSTEMTESTTOP from bin/tests/system/

Closes #48

See merge request isc-projects/bind9!3623

5 years agoMake sure we don't introduce SYSTEMTESTTOP anymore
Michal Nowak [Tue, 28 Jul 2020 12:42:55 +0000 (14:42 +0200)] 
Make sure we don't introduce SYSTEMTESTTOP anymore

':!.gitlab-ci.yml' is a pathspec pattern used to limit paths in the "git
grep" command to all but the .gitlab-ci.yml file which includes the
checked word itself. This requires Git 2.13.

5 years agoRemove cross-test dependency on ckdnsrps.sh
Michal Nowak [Tue, 28 Jul 2020 11:19:08 +0000 (13:19 +0200)] 
Remove cross-test dependency on ckdnsrps.sh

5 years agoFix name of the test directory of stop.pl in masterformat test
Michal Nowak [Tue, 28 Jul 2020 10:58:51 +0000 (12:58 +0200)] 
Fix name of the test directory of stop.pl in masterformat test

5 years agoEnsure test fails if packet.pl does not work as expected
Michal Nowak [Tue, 28 Jul 2020 10:45:31 +0000 (12:45 +0200)] 
Ensure test fails if packet.pl does not work as expected

5 years agoSource config.guess from source root
Michal Nowak [Tue, 21 Jul 2020 14:29:14 +0000 (16:29 +0200)] 
Source config.guess from source root

It seems that config.guess gets always created in source root, so for
that sake of out-of-tree system test, we should expect the file there
instead of where configure was run.

5 years agoDrop $SYSTEMTESTTOP from bin/tests/system/
Michal Nowak [Tue, 21 Jul 2020 10:12:59 +0000 (12:12 +0200)] 
Drop $SYSTEMTESTTOP from bin/tests/system/

The $SYSTEMTESTTOP shell variable if often set to .. in various shell
scripts inside bin/tests/system/, but most of the time it is only
used one line later, while sourcing conf.sh. This hardly improves
code readability.

$SYSTEMTESTTOP is also used for the purpose of referencing
scripts/files living in bin/tests/system/, but given that the
variable is always set to a short, relative path, we can drop it and
replace all of its occurrences with the relative path without adversely
affecting code readability.

5 years agoMerge branch 'michal/only-run-system-tests-as-root-in-developer-mode' into 'main'
Michał Kępień [Thu, 30 Jul 2020 13:45:00 +0000 (13:45 +0000)] 
Merge branch 'michal/only-run-system-tests-as-root-in-developer-mode' into 'main'

Only run system tests as root in developer mode

See merge request isc-projects/bind9!3894

5 years agoOnly run system tests as root in developer mode
Michał Kępień [Thu, 30 Jul 2020 12:07:49 +0000 (14:07 +0200)] 
Only run system tests as root in developer mode

Running system tests with root privileges is potentially dangerous.
Only allow it when explicitly requested (by building with
--enable-developer).

5 years agoMerge branch '2024-fix-idle-timeout-for-connected-tcp-sockets' into 'main'
Michał Kępień [Thu, 30 Jul 2020 09:32:07 +0000 (09:32 +0000)] 
Merge branch '2024-fix-idle-timeout-for-connected-tcp-sockets' into 'main'

Fix idle timeout for connected TCP sockets

Closes #2024

See merge request isc-projects/bind9!3854

5 years agoAdd CHANGES for GL #2024
Michał Kępień [Thu, 30 Jul 2020 08:58:39 +0000 (10:58 +0200)] 
Add CHANGES for GL #2024

5 years agoFix idle timeout for connected TCP sockets
Michał Kępień [Thu, 30 Jul 2020 08:58:39 +0000 (10:58 +0200)] 
Fix idle timeout for connected TCP sockets

When named acting as a resolver connects to an authoritative server over
TCP, it sets the idle timeout for that connection to 20 seconds.  This
fixed timeout was picked back when the default processing timeout for
each client query was hardcoded to 30 seconds.  Commit
000a8970f840a0c27c5cc404826853c4674362ac made this processing timeout
configurable through "resolver-query-timeout" and decreased its default
value to 10 seconds, but the idle TCP timeout was not adjusted to
reflect that change.  As a result, with the current defaults in effect,
a single hung TCP connection will consistently cause the resolution
process for a given query to time out.

Set the idle timeout for connected TCP sockets to half of the client
query processing timeout configured for a resolver.  This allows named
to handle hung TCP connections more robustly and prevents the timeout
mismatch issue from resurfacing in the future if the default is ever
changed again.

5 years agoMerge branch 'marka-placeholder' into 'main'
Mark Andrews [Wed, 29 Jul 2020 23:39:16 +0000 (23:39 +0000)] 
Merge branch 'marka-placeholder' into 'main'

placeholder for [GL #2028]

See merge request isc-projects/bind9!3893

5 years agoplaceholder for [GL #2028]
Mark Andrews [Wed, 29 Jul 2020 23:34:58 +0000 (09:34 +1000)] 
placeholder for [GL #2028]

5 years agoMerge branch '2050-libuv-version' into 'main'
Evan Hunt [Tue, 28 Jul 2020 02:49:19 +0000 (02:49 +0000)] 
Merge branch '2050-libuv-version' into 'main'

report libuv version string in `named -V`

Closes #2050

See merge request isc-projects/bind9!3887

5 years agoreport libuv version string in `named -V`
Evan Hunt [Sat, 25 Jul 2020 00:04:02 +0000 (17:04 -0700)] 
report libuv version string in `named -V`

5 years agoMerge branch '2031-win32-fix' into 'main'
Evan Hunt [Mon, 27 Jul 2020 21:33:07 +0000 (21:33 +0000)] 
Merge branch '2031-win32-fix' into 'main'

Resolve "Windows crashes with netmgr-based statschannel"

Closes #2031

See merge request isc-projects/bind9!3888

5 years agoinitialize, rather than invalidating, new http buffers
Evan Hunt [Mon, 27 Jul 2020 18:03:33 +0000 (11:03 -0700)] 
initialize, rather than invalidating, new http buffers

when building without ISC_BUFFER_USEINLINE (which is the default on
Windows) an assertion failure could occur when setting up a new
isc_httpd_t object for the statistics channel.

5 years agoMerge branch '1619-rpz-wildcard-passthru-ignored' into 'main'
Diego dos Santos Fronza [Mon, 27 Jul 2020 14:34:08 +0000 (14:34 +0000)] 
Merge branch '1619-rpz-wildcard-passthru-ignored' into 'main'

Resolve "RPZ wildcard passthru ignored"

Closes #1619

See merge request isc-projects/bind9!3682

5 years agoAdd CHANGES entry
Diego Fronza [Fri, 12 Jun 2020 18:14:53 +0000 (15:14 -0300)] 
Add CHANGES entry

5 years agoAdd test for RPZ wildcard passthru ignored fix
Diego Fronza [Fri, 12 Jun 2020 18:09:02 +0000 (15:09 -0300)] 
Add test for RPZ wildcard passthru ignored fix

5 years agoFix rpz wildcard name matching
Diego Fronza [Tue, 9 Jun 2020 23:45:21 +0000 (20:45 -0300)] 
Fix rpz wildcard name matching

Whenever an exact match is found by dns_rbt_findnode(),
the highest level node in the chain will not be put into
chain->levels[] array, but instead the chain->end
pointer will be adjusted to point to that node.

Suppose we have the following entries in a rpz zone:
example.com     CNAME rpz-passthru.
*.example.com   CNAME rpz-passthru.

A query for www.example.com would result in the
following chain object returned by dns_rbt_findnode():

chain->level_count = 2
chain->level_matches = 2
chain->levels[0] = .
chain->levels[1] = example.com
chain->levels[2] = NULL
chain->end = www

Since exact matches only care for testing rpz set bits,
we need to test for rpz wild bits through iterating the nodechain, and
that includes testing the rpz wild bits in the highest level node found.

In the case of an exact match, chain->levels[chain->level_matches]
will be NULL, to address that we must use chain->end as the start point,
then iterate over the remaining levels in the chain.

5 years agoMerge branch '1999-add-a-regular-make-dist-job-to-ci' into 'main'
Michal Nowak [Fri, 24 Jul 2020 13:53:54 +0000 (13:53 +0000)] 
Merge branch '1999-add-a-regular-make-dist-job-to-ci' into 'main'

Add a regular "make dist" job to CI

Closes #1999

See merge request isc-projects/bind9!3803

5 years agoAdd a regular "make dist" job to CI
Michal Nowak [Fri, 3 Jul 2020 08:41:53 +0000 (10:41 +0200)] 
Add a regular "make dist" job to CI

It's easy to break "make dist" by adding and moving files around.
We should test this scenario regularly, to prevent release-time
surprises.

5 years agoMerge branch '2043-dns_rdata_hip_next-fails-to-return-isc_r_nomore-at-the-right-time...
Mark Andrews [Fri, 24 Jul 2020 05:19:45 +0000 (05:19 +0000)] 
Merge branch '2043-dns_rdata_hip_next-fails-to-return-isc_r_nomore-at-the-right-time' into 'main'

Resolve "dns_rdata_hip_next() fails to return ISC_R_NOMORE at the right time."

Closes #2043

See merge request isc-projects/bind9!3880

5 years agoAdd CHANGES note
Mark Andrews [Wed, 22 Jul 2020 07:49:27 +0000 (17:49 +1000)] 
Add CHANGES note

5 years agoCheck walking the hip rendezvous servers.
Mark Andrews [Wed, 22 Jul 2020 07:02:47 +0000 (17:02 +1000)] 
Check walking the hip rendezvous servers.

Also fixes extraneous white space at end of record when
there are no rendezvous servers.

5 years agoMerge branch 'marka-add-fallthrough' into 'main'
Mark Andrews [Fri, 24 Jul 2020 04:15:03 +0000 (04:15 +0000)] 
Merge branch 'marka-add-fallthrough' into 'main'

Add fallthrough and braces

See merge request isc-projects/bind9!3884

5 years agoAdd fallthrough and braces
Mark Andrews [Fri, 24 Jul 2020 03:49:56 +0000 (13:49 +1000)] 
Add fallthrough and braces

5 years agoMerge branch 'feature/master/unix-cleanup' into 'main'
Mark Andrews [Fri, 24 Jul 2020 03:02:07 +0000 (03:02 +0000)] 
Merge branch 'feature/master/unix-cleanup' into 'main'

Remove few lines in unix socket handling

See merge request isc-projects/bind9!2687

5 years agoRemove few lines in unix socket handling
Petr Menšík [Tue, 12 Mar 2019 12:20:11 +0000 (13:20 +0100)] 
Remove few lines in unix socket handling

Reuse the same checks two times, make difference minimal.

5 years agoMerge branch 'dstlib-failure-abort' into 'main'
Mark Andrews [Thu, 23 Jul 2020 00:46:12 +0000 (00:46 +0000)] 
Merge branch 'dstlib-failure-abort' into 'main'

Prevent crash on dst initialization failure

See merge request isc-projects/bind9!3876

5 years agoPrevent crash on dst initialization failure
Petr Menšík [Wed, 22 Jul 2020 16:55:02 +0000 (18:55 +0200)] 
Prevent crash on dst initialization failure

server might be created, but not yet fully initialized, when fatal
function is called. Check both server and task before attaching
exclusive task.

5 years agoMerge branch '1727-drop-use-of-featuretest-have-dlopen' into 'main'
Michal Nowak [Tue, 21 Jul 2020 09:24:38 +0000 (09:24 +0000)] 
Merge branch '1727-drop-use-of-featuretest-have-dlopen' into 'main'

Drop feature test for dlopen()

Closes #1727

See merge request isc-projects/bind9!3625

5 years agoDrop feature test for dlopen()
Michal Nowak [Tue, 2 Jun 2020 16:50:49 +0000 (18:50 +0200)] 
Drop feature test for dlopen()

With libtool being mandatory from 9.17 on, so is dlopen() (via libltdl).

5 years agoMerge branch '1775-resizing-growing-of-cache-hash-tables-causes-delays-in-processing...
Ondřej Surý [Tue, 21 Jul 2020 08:38:26 +0000 (08:38 +0000)] 
Merge branch '1775-resizing-growing-of-cache-hash-tables-causes-delays-in-processing-of-client-queries' into 'main'

Fix the rbt hashtable and grow it when setting max-cache-size

Closes #1775

See merge request isc-projects/bind9!3865

5 years agoAdd CHANGES and release note for #1775
Ondřej Surý [Mon, 20 Jul 2020 09:31:05 +0000 (11:31 +0200)] 
Add CHANGES and release note for #1775

5 years agoChange the dns_name hashing to use 32-bit values
Ondřej Surý [Thu, 16 Jul 2020 15:30:44 +0000 (17:30 +0200)] 
Change the dns_name hashing to use 32-bit values

Change the dns_hash_name() and dns_hash_fullname() functions to use
isc_hash32() as the maximum hashtable size in rbt is 0..UINT32_MAX
large.

5 years agoAdd isc_hash32() and rename isc_hash_function() to isc_hash64()
Ondřej Surý [Thu, 16 Jul 2020 15:29:44 +0000 (17:29 +0200)] 
Add isc_hash32() and rename isc_hash_function() to isc_hash64()

As the names suggest the original isc_hash64 function returns 64-bit
long hash values and the isc_hash32() returns 32-bit values.

5 years agoAdd HalfSipHash 2-4 reference implementation
Ondřej Surý [Thu, 16 Jul 2020 15:26:44 +0000 (17:26 +0200)] 
Add HalfSipHash 2-4 reference implementation

The HalfSipHash implementation has 32-bit keys and returns 32-bit
value.

5 years agoRemove OpenSSL based SipHash 2-4 implementation
Ondřej Surý [Thu, 16 Jul 2020 14:48:39 +0000 (16:48 +0200)] 
Remove OpenSSL based SipHash 2-4 implementation

Creation of EVP_MD_CTX and EVP_PKEY is quite expensive, so until we fix the code
to reuse the OpenSSL contexts and keys we'll use our own implementation of
siphash instead of trying to integrate with OpenSSL.

5 years agoFix the rbt hashtable and grow it when setting max-cache-size
Ondřej Surý [Thu, 16 Jul 2020 08:29:54 +0000 (10:29 +0200)] 
Fix the rbt hashtable and grow it when setting max-cache-size

There were several problems with rbt hashtable implementation:

1. Our internal hashing function returns uint64_t value, but it was
   silently truncated to unsigned int in dns_name_hash() and
   dns_name_fullhash() functions.  As the SipHash 2-4 higher bits are
   more random, we need to use the upper half of the return value.

2. The hashtable implementation in rbt.c was using modulo to pick the
   slot number for the hash table.  This has several problems because
   modulo is: a) slow, b) oblivious to patterns in the input data.  This
   could lead to very uneven distribution of the hashed data in the
   hashtable.  Combined with the single-linked lists we use, it could
   really hog-down the lookup and removal of the nodes from the rbt
   tree[a].  The Fibonacci Hashing is much better fit for the hashtable
   function here.  For longer description, read "Fibonacci Hashing: The
   Optimization that the World Forgot"[b] or just look at the Linux
   kernel.  Also this will make Diego very happy :).

3. The hashtable would rehash every time the number of nodes in the rbt
   tree would exceed 3 * (hashtable size).  The overcommit will make the
   uneven distribution in the hashtable even worse, but the main problem
   lies in the rehashing - every time the database grows beyond the
   limit, each subsequent rehashing will be much slower.  The mitigation
   here is letting the rbt know how big the cache can grown and
   pre-allocate the hashtable to be big enough to actually never need to
   rehash.  This will consume more memory at the start, but since the
   size of the hashtable is capped to `1 << 32` (e.g. 4 mio entries), it
   will only consume maximum of 32GB of memory for hashtable in the
   worst case (and max-cache-size would need to be set to more than
   4TB).  Calling the dns_db_adjusthashsize() will also cap the maximum
   size of the hashtable to the pre-computed number of bits, so it won't
   try to consume more gigabytes of memory than available for the
   database.

   FIXME: What is the average size of the rbt node that gets hashed?  I
   chose the pagesize (4k) as initial value to precompute the size of
   the hashtable, but the value is based on feeling and not any real
   data.

For future work, there are more places where we use result of the hash
value modulo some small number and that would benefit from Fibonacci
Hashing to get better distribution.

Notes:
a. A doubly linked list should be used here to speedup the removal of
   the entries from the hashtable.
b. https://probablydance.com/2018/06/16/fibonacci-hashing-the-optimization-that-the-world-forgot-or-a-better-alternative-to-integer-modulo/

5 years agoMerge branch 'mnowak/try-harder-to-analyze-cores' into 'main'
Michal Nowak [Mon, 20 Jul 2020 08:13:37 +0000 (08:13 +0000)] 
Merge branch 'mnowak/try-harder-to-analyze-cores' into 'main'

Rationalize backtrace logging, fail on core file presence

See merge request isc-projects/bind9!3867

5 years agoCheck tests for core files regardless of test status
Michal Nowak [Mon, 22 Jun 2020 17:55:40 +0000 (19:55 +0200)] 
Check tests for core files regardless of test status

Failed test should be checked for core files et al. and have
backtrace generated.

5 years agoRationalize backtrace logging
Michal Nowak [Mon, 22 Jun 2020 13:56:50 +0000 (15:56 +0200)] 
Rationalize backtrace logging

GDB backtrace generated via "thread apply all bt full" is too long for
standard output, lets save them to .txt file among other log files.

5 years agoEnsure various test issues are treated as failures
Michal Nowak [Mon, 22 Jun 2020 12:13:46 +0000 (14:13 +0200)] 
Ensure various test issues are treated as failures

Make sure bin/tests/system/run.sh returns a non-zero exit code if any of
the following happens:

  - the test being run produces a core dump,
  - assertion failures are found in the test's logs,
  - ThreadSanitizer reports are found after the test completes,
  - the servers started by the test fail to shut down cleanly.

This change is necessary to always fail a test in such cases (before the
migration to Automake, test failures were determined based on the
presence of "R:<test-name>:FAIL" lines in the test suite output and thus
it was not necessary for bin/tests/system/run.sh to return a non-zero
exit code).

5 years agoMerge branch 'michal/update-release-checklist' into 'main'
Michał Kępień [Thu, 16 Jul 2020 09:31:09 +0000 (09:31 +0000)] 
Merge branch 'michal/update-release-checklist' into 'main'

Update release checklist

See merge request isc-projects/bind9!3864

5 years agoUpdate release checklist
Michał Kępień [Thu, 16 Jul 2020 09:28:09 +0000 (11:28 +0200)] 
Update release checklist

Add an item to the release checklist to make sure confidential issues
assigned to the relevant milestone are made public after the BIND
versions addressing them are released.

5 years agoMerge branch '2022-stats-netmgr' into 'main'
Evan Hunt [Thu, 16 Jul 2020 06:04:21 +0000 (06:04 +0000)] 
Merge branch '2022-stats-netmgr' into 'main'

Resolve "use netmgr for statschannel"

Closes #2022

See merge request isc-projects/bind9!3847

5 years agoCHANGES, release note
Evan Hunt [Mon, 13 Jul 2020 21:05:55 +0000 (14:05 -0700)] 
CHANGES, release note

5 years agorewrite statschannel to use netmgr
Evan Hunt [Fri, 10 Jul 2020 02:36:10 +0000 (19:36 -0700)] 
rewrite statschannel to use netmgr

modify isc_httpd to use the network manager instead of the
isc_socket API.

also cleaned up bin/named/statschannel.c to use CHECK.

5 years agoMerge branch 'v9_17_3-release' into 'main'
Michał Kępień [Wed, 15 Jul 2020 21:09:46 +0000 (21:09 +0000)] 
Merge branch 'v9_17_3-release' into 'main'

Merge 9.17.3 release branch

See merge request isc-projects/bind9!3860

5 years agoSet up release notes for BIND 9.17.4
Michał Kępień [Wed, 15 Jul 2020 21:06:25 +0000 (23:06 +0200)] 
Set up release notes for BIND 9.17.4

5 years agoBump BIND_BASELINE_VERSION for ABI checks
Michał Kępień [Wed, 15 Jul 2020 21:06:25 +0000 (23:06 +0200)] 
Bump BIND_BASELINE_VERSION for ABI checks

5 years agoFix "make dist"
Michał Kępień [Fri, 3 Jul 2020 08:36:15 +0000 (10:36 +0200)] 
Fix "make dist"

5 years agoUpdate BIND version to 9.17.3
Michał Kępień [Fri, 3 Jul 2020 08:02:14 +0000 (10:02 +0200)] 
Update BIND version to 9.17.3

5 years agoAdd a CHANGES marker
Michał Kępień [Fri, 3 Jul 2020 08:02:14 +0000 (10:02 +0200)] 
Add a CHANGES marker

5 years agoUpdate library API versions
Michał Kępień [Fri, 3 Jul 2020 08:02:14 +0000 (10:02 +0200)] 
Update library API versions

5 years agoMerge branch 'michal/prepare-release-notes-for-bind-9.17.3' into v9_17_3-release
Michał Kępień [Fri, 3 Jul 2020 07:44:07 +0000 (09:44 +0200)] 
Merge branch 'michal/prepare-release-notes-for-bind-9.17.3' into v9_17_3-release

5 years agoReorder release notes
Michał Kępień [Fri, 3 Jul 2020 07:36:17 +0000 (09:36 +0200)] 
Reorder release notes

5 years agoAdd release note for #1958
Michał Kępień [Fri, 3 Jul 2020 07:36:17 +0000 (09:36 +0200)] 
Add release note for #1958

5 years agoAdd release note for #1938
Michał Kępień [Fri, 3 Jul 2020 07:36:17 +0000 (09:36 +0200)] 
Add release note for #1938

5 years agoAdd release note for #1937
Michał Kępień [Fri, 3 Jul 2020 07:36:17 +0000 (09:36 +0200)] 
Add release note for #1937

5 years agoTweak and reword release notes
Michał Kępień [Fri, 3 Jul 2020 07:36:17 +0000 (09:36 +0200)] 
Tweak and reword release notes

5 years agoPrepare release notes for BIND 9.17.3
Michał Kępień [Fri, 3 Jul 2020 07:36:17 +0000 (09:36 +0200)] 
Prepare release notes for BIND 9.17.3

5 years agoTweak and reword recent CHANGES entries
Michał Kępień [Fri, 3 Jul 2020 07:36:17 +0000 (09:36 +0200)] 
Tweak and reword recent CHANGES entries

5 years agoMerge branch '2006-coverity-checked-return-keymgr' into 'main'
Matthijs Mekking [Tue, 14 Jul 2020 15:46:56 +0000 (15:46 +0000)] 
Merge branch '2006-coverity-checked-return-keymgr' into 'main'

Fix Coverity keymgr reports

Closes #2006

See merge request isc-projects/bind9!3808

5 years agoCheck return value of dst_key_getbool()
Matthijs Mekking [Mon, 6 Jul 2020 10:07:24 +0000 (12:07 +0200)] 
Check return value of dst_key_getbool()

Fix Coverity CHECKED_RETURN reports for dst_key_getbool().  In most
cases we do not really care about its return value, but it is prudent
to check it.

In one case, where a dst_key_getbool() error should be treated
identically as success, cast the return value to void and add a relevant
comment.

5 years agoMerge branch 'michal/use-image-key-in-qemu-based-ci-job-templates' into 'main'
Michał Kępień [Tue, 14 Jul 2020 08:24:42 +0000 (08:24 +0000)] 
Merge branch 'michal/use-image-key-in-qemu-based-ci-job-templates' into 'main'

Use "image" key in QEMU-based CI job templates

See merge request isc-projects/bind9!3855

5 years agoUse "image" key in QEMU-based CI job templates
Michał Kępień [Tue, 14 Jul 2020 07:58:04 +0000 (09:58 +0200)] 
Use "image" key in QEMU-based CI job templates

Our GitLab Runner Custom executor scripts now use the "image" key
instead of the job name for determining the QCOW2 image to use for a
given CI job.  Update .gitlab-ci.yml to reflect that change.

5 years agoMerge branch 'u/fanf2/fix-signing' into 'main'
Mark Andrews [Tue, 14 Jul 2020 02:07:28 +0000 (02:07 +0000)] 
Merge branch 'u/fanf2/fix-signing' into 'main'

Fix re-signing when `sig-validity-interval` has two arguments

See merge request isc-projects/bind9!3735

5 years agoAdd release note for [GL !3735]
Mark Andrews [Thu, 25 Jun 2020 04:51:19 +0000 (14:51 +1000)] 
Add release note for [GL !3735]

5 years agoAdd CHANGES note for [GL !3735]
Mark Andrews [Thu, 25 Jun 2020 04:50:16 +0000 (14:50 +1000)] 
Add CHANGES note for [GL !3735]

5 years agoAdd regression test for [GL !3735]
Mark Andrews [Thu, 25 Jun 2020 11:27:29 +0000 (21:27 +1000)] 
Add regression test for [GL !3735]

Check that resign interval is actually in days rather than hours
by checking that RRSIGs are all within the allowed day range.

5 years agoFix re-signing when `sig-validity-interval` has two arguments
Tony Finch [Mon, 22 Jun 2020 19:23:29 +0000 (20:23 +0100)] 
Fix re-signing when `sig-validity-interval` has two arguments

Since October 2019 I have had complaints from `dnssec-cds` reporting
that the signatures on some of my test zones had expired. These were
zones signed by BIND 9.15 or 9.17, with a DNSKEY TTL of 24h and
`sig-validity-interval 10 8`.

This is the same setup we have used for our production zones since
2015, which is intended to re-sign the zones every 2 days, keeping
at least 8 days signature validity. The SOA expire interval is 7
days, so even in the presence of zone transfer problems, no-one
should ever see expired signatures. (These timers are a bit too
tight to be completely correct, because I should have increased
the expiry timers when I increased the DNSKEY TTLs from 1h to 24h.
But that should only matter when zone transfers are broken, which
was not the case for the error reports that led to this patch.)

For example, this morning my test zone contained:

        dev.dns.cam.ac.uk. 86400 IN RRSIG DNSKEY 13 5 86400 (
                                20200701221418 20200621213022 ...)

But one of my resolvers had cached:

        dev.dns.cam.ac.uk. 21424 IN RRSIG DNSKEY 13 5 86400 (
                                20200622063022 20200612061136 ...)

This TTL was captured at 20200622105807 so the resolver cached the
RRset 64976 seconds previously (18h02m56s), at 20200621165511
only about 12h before expiry.

The other symptom of this error was incorrect `resign` times in
the output from `rndc zonestatus`.

For example, I have configured a test zone

        zone fast.dotat.at {
                file "../u/z/fast.dotat.at";
                type primary;
                auto-dnssec maintain;
                sig-validity-interval 500 499;
        };

The zone is reset to a minimal zone containing only SOA and NS
records, and when `named` starts it loads and signs the zone. After
that, `rndc zonestatus` reports:

        next resign node: fast.dotat.at/NS
        next resign time: Fri, 28 May 2021 12:48:47 GMT

The resign time should be within the next 24h, but instead it is
near the signature expiry time, which the RRSIG(NS) says is
20210618074847. (Note 499 hours is a bit more than 20 days.)
May/June 2021 is less than 500 days from now because expiry time
jitter is applied to the NS records.

Using this test I bisected this bug to 09990672d which contained a
mistake leading to the resigning interval always being calculated in
hours, when days are expected.

This bug only occurs for configurations that use the two-argument form
of `sig-validity-interval`.

5 years agoMerge branch '1994-netscope-c-23-50-error-unused-parameter-addr-when-have_if_nametoin...
Mark Andrews [Tue, 14 Jul 2020 00:51:22 +0000 (00:51 +0000)] 
Merge branch '1994-netscope-c-23-50-error-unused-parameter-addr-when-have_if_nametoindex-undefined-on-illumos' into 'main'

Resolve "netscope.c:23:50: error: unused parameter 'addr' when HAVE_IF_NAMETOINDEX undefined on illumos"

Closes #1994

See merge request isc-projects/bind9!3829

5 years agoMark 'addr' as unused if HAVE_IF_NAMETOINDEX is not defined
Mark Andrews [Thu, 9 Jul 2020 05:04:31 +0000 (15:04 +1000)] 
Mark 'addr' as unused if HAVE_IF_NAMETOINDEX is not defined

Also 'zone' should be initialised to zero.

5 years agoMerge branch '1995-gssapictx-c-681-10-error-implicit-declaration-of-function-gsskrb5_...
Mark Andrews [Tue, 14 Jul 2020 00:05:39 +0000 (00:05 +0000)] 
Merge branch '1995-gssapictx-c-681-10-error-implicit-declaration-of-function-gsskrb5_register_acceptor_identity' into 'main'

Resolve "gssapictx.c:681:10: error: implicit declaration of function 'gsskrb5_register_acceptor_identity' on illumos"

Closes #1995

See merge request isc-projects/bind9!3830

5 years agoOnly call gsskrb5_register_acceptor_identity if we have gssapi_krb5.h.
Mark Andrews [Thu, 9 Jul 2020 05:30:59 +0000 (15:30 +1000)] 
Only call gsskrb5_register_acceptor_identity if we have gssapi_krb5.h.

5 years agoMerge branch '1993-check-c-1576-37-error-expected-identifier-before-numeric-constant...
Mark Andrews [Mon, 13 Jul 2020 22:06:48 +0000 (22:06 +0000)] 
Merge branch '1993-check-c-1576-37-error-expected-identifier-before-numeric-constant-on-illumos' into 'main'

Resolve "check.c:1576:37: error: expected identifier before numeric constant on illumos"

Closes #1993

See merge request isc-projects/bind9!3828