]>
git.ipfire.org Git - thirdparty/knot-dns.git/log
Daniel Salzman [Mon, 27 Jul 2026 15:22:23 +0000 (17:22 +0200)]
Merge branch 'keymgr_adt' into 'master'
Keymgr adt
See merge request knot/knot-dns!1894
Libor Peltan [Tue, 21 Jul 2026 09:32:58 +0000 (11:32 +0200)]
keymgr: print ADT bit when listing keys
Libor Peltan [Tue, 21 Jul 2026 09:11:56 +0000 (11:11 +0200)]
keymgr: allow un/setting ADT bit
Libor Peltan [Mon, 27 Jul 2026 09:02:22 +0000 (11:02 +0200)]
Merge branch 'man_regenerate' into 'master'
Store unsubstituted variables in man pages in the tarball
See merge request knot/knot-dns!1895
Daniel Salzman [Mon, 27 Jul 2026 06:05:43 +0000 (08:05 +0200)]
libngtcp2: update embedded library to v1.25.0
Libor Peltan [Sat, 25 Jul 2026 08:35:49 +0000 (10:35 +0200)]
Merge branch 'lmdb_migration' into 'master'
Automatic LMDB migration from 0.9 to 1.x version
See merge request knot/knot-dns!1892
Libor Peltan [Sat, 25 Jul 2026 08:06:58 +0000 (10:06 +0200)]
mdb_dump/load: comments explaining not/including emb_prefix.h
Daniel Salzman [Fri, 24 Jul 2026 13:14:37 +0000 (15:14 +0200)]
man: store unsubstituted variables in the tarball, expand them during installation
David Vašek [Thu, 23 Jul 2026 12:45:56 +0000 (14:45 +0200)]
man/knotd: mention SIGTERM as a handled signal
David Vašek [Mon, 20 Jul 2026 12:42:00 +0000 (14:42 +0200)]
doc/operation: mention automatic zone purge of removed catalog members
David Vašek [Mon, 20 Jul 2026 12:34:34 +0000 (14:34 +0200)]
doc/operation: fix a typo
David Vašek [Fri, 26 Jun 2026 12:07:56 +0000 (14:07 +0200)]
doc/reference: add a hyperlink
Libor Peltan [Wed, 15 Jul 2026 08:25:12 +0000 (10:25 +0200)]
mdb_load: make the function thread-safe
Libor Peltan [Tue, 14 Jul 2026 10:50:26 +0000 (12:50 +0200)]
lmdb migration: move just data+lock.mdb instead of whole dir...
...because KASP DB dir contains also privkeys and TLSkey
...and users can have more junk in there
Daniel Salzman [Wed, 15 Jul 2026 10:55:52 +0000 (12:55 +0200)]
knot: add automatic LMDB migration from version 0.9
Daniel Salzman [Wed, 15 Jul 2026 10:55:25 +0000 (12:55 +0200)]
libs: transform mdb_dump and mdb_load to functions
Daniel Salzman [Thu, 23 Jul 2026 05:47:37 +0000 (07:47 +0200)]
tests: remove explicit #include <config.h>
Daniel Salzman [Thu, 23 Jul 2026 05:46:06 +0000 (07:46 +0200)]
configure: add quotes to test expression where missing
Daniel Salzman [Fri, 10 Jul 2026 05:38:16 +0000 (07:38 +0200)]
contrib: add mdb_load from LMDB 1.0.0
Daniel Salzman [Fri, 10 Jul 2026 09:19:52 +0000 (11:19 +0200)]
contrib: add mdb_dump from LMDB 0.9.35
Daniel Salzman [Sat, 4 Jul 2026 17:18:07 +0000 (19:18 +0200)]
contrib: add embedded LMDB 0.9.35
This helps with:
- database migration to LMDB 1.x
- occasional debugging
Daniel Salzman [Sat, 4 Jul 2026 18:40:52 +0000 (20:40 +0200)]
libknot/db: add workaround for mdb_drop() version 1.0.0 in lmdb.clear()
This fixes compatibility with LMDB 1.0.0, where mdb_drop() cannot be followed
by further additions within the same transaction. Otherwise, mdb_commit() fails
with "MDB_BAD_TXN: Transaction must abort, has a child, or is invalid".
Daniel Salzman [Sat, 18 Jul 2026 17:42:52 +0000 (19:42 +0200)]
Merge branch 'acl_fixes' into 'master'
ACL config checks
See merge request knot/security/knot-dns!3
Daniel Salzman [Thu, 16 Jul 2026 12:10:35 +0000 (14:10 +0200)]
Merge branch 'ddns_0rtt' into 'master'
requestor/QUIC: avoid 0-RTT when forwarding DDNS...
See merge request knot/security/knot-dns!2
Daniel Salzman [Fri, 17 Jul 2026 11:48:12 +0000 (13:48 +0200)]
conf: improve error messages in check_remote()
Libor Peltan [Wed, 15 Jul 2026 11:39:14 +0000 (13:39 +0200)]
Merge branch 'acl_fixes' into 'master'
ACL fixes
See merge request knot/security/knot-dns!1
Libor Peltan [Wed, 15 Jul 2026 16:27:17 +0000 (18:27 +0200)]
doc: DDNSoQ incl warning against 0-RTT from clients
Daniel Salzman [Fri, 17 Jul 2026 09:17:59 +0000 (11:17 +0200)]
conf: update 'acl.remote' conflict check
Daniel Salzman [Tue, 14 Jul 2026 07:42:11 +0000 (09:42 +0200)]
acl: refactor check_proto() and call it before cert_check()
Libor Peltan [Wed, 15 Jul 2026 16:26:44 +0000 (18:26 +0200)]
tests: DDNS forwarding over QUIC incl not using 0-RTT
Daniel Salzman [Tue, 14 Jul 2026 07:40:14 +0000 (09:40 +0200)]
tls_common: add check for empty session to knot_tls_cert_check_hostnames()
Libor Peltan [Wed, 15 Jul 2026 16:26:14 +0000 (18:26 +0200)]
requestor/QUIC: avoid 0-RTT when forwarding DDNS...
...0-RTT for DDNSoQ is discouraged due to replay attacks
Daniel Salzman [Tue, 14 Jul 2026 07:39:43 +0000 (09:39 +0200)]
acl: add check for empty tls_session to cert_check()
Libor Peltan [Wed, 15 Jul 2026 13:51:30 +0000 (15:51 +0200)]
DDNS/forwarding: verbose logging incl. addr and proto
Daniel Salzman [Sun, 19 Jul 2026 17:48:27 +0000 (19:48 +0200)]
distro/deb: align copyright with new release
Daniel Salzman [Sun, 19 Jul 2026 17:46:12 +0000 (19:46 +0200)]
distro/deb: use watch v5
Daniel Salzman [Sun, 19 Jul 2026 17:43:45 +0000 (19:43 +0200)]
distro/deb: set Standards-Version to 4.7.4
Daniel Salzman [Sun, 19 Jul 2026 17:42:25 +0000 (19:42 +0200)]
distro/deb: add procps dependency to knot-exporter
Daniel Salzman [Sun, 19 Jul 2026 17:40:07 +0000 (19:40 +0200)]
distro/deb: add 'Multi-Arch: same' to libraries
Daniel Salzman [Sat, 18 Jul 2026 18:21:21 +0000 (20:21 +0200)]
Merge branch 'last_signed_serial_conf' into 'master'
KASP/timers: configurable storage of last signed serial
See merge request knot/knot-dns!1891
Libor Peltan [Thu, 9 Jul 2026 08:35:03 +0000 (10:35 +0200)]
KASP/timers: configurable storage of last signed serial
Daniel Salzman [Fri, 17 Jul 2026 18:46:39 +0000 (20:46 +0200)]
tests-extra: increase robustness of catalog/generate_reconf
Libor Peltan [Fri, 17 Jul 2026 09:36:40 +0000 (11:36 +0200)]
Merge branch 'tcp_id' into 'master'
TCP thread id fix, refactoring
See merge request knot/knot-dns!1893
Daniel Salzman [Thu, 16 Jul 2026 11:46:48 +0000 (13:46 +0200)]
handlers: replace strerror() with knot_strerror()
Daniel Salzman [Thu, 16 Jul 2026 11:43:30 +0000 (13:43 +0200)]
udp-handler: use dthread indexing for XDP threads, unify with tcp-handler
Daniel Salzman [Thu, 16 Jul 2026 10:35:01 +0000 (12:35 +0200)]
tcp-handler: fix TCP socket indexing if TLS and TCP reuseport configured
Daniel Salzman [Wed, 8 Jul 2026 18:30:41 +0000 (20:30 +0200)]
tests-extra: improve bind_version() to accept newer extended string
Daniel Salzman [Wed, 8 Jul 2026 11:39:24 +0000 (13:39 +0200)]
Merge branch 'mempool-merge-with-kres'
Lukáš Ondráček [Tue, 7 Jul 2026 15:26:16 +0000 (17:26 +0200)]
contrib/ucw/mempool: remove mp_alloc_noalign
Lukáš Ondráček [Tue, 7 Jul 2026 14:15:46 +0000 (16:15 +0200)]
contrib/ucw/mempool: unify size types to size_t
Lukáš Ondráček [Mon, 6 Jul 2026 22:20:41 +0000 (00:20 +0200)]
contrib/ucw/mempool: add valgrind directives
Daniel Salzman [Wed, 7 Jan 2026 13:00:48 +0000 (14:00 +0100)]
contrib: add optional Valgrind Memcheck macros
Lukáš Ondráček [Tue, 9 Jun 2026 14:17:56 +0000 (16:17 +0200)]
contrib/ucw/mempool: include chunk metadata in requested size
Originally, the requested chunk size was enlarged by the size of its metadata (~16 B)
and then in mmap version of mempools it was rounded up to the page size.
As the requested size itself is usually rounded to whole pages,
the chunk size was roughly by one page larger than expected;
still the whole space could have been used by mempools.
In non-mmap version (not used here), the effect might have been even worse,
as the rounding may be involved on the allocator level
and so the excessive memory cannot be used by mempools.
Now, usable size of chunks is a little smaller than requested,
but allocated area size corresponds to what was requested.
Lukáš Ondráček [Tue, 9 Jun 2026 12:53:14 +0000 (14:53 +0200)]
contrib/ucw/mempool: add mp_shrink and mention missing parts
Lukáš Ondráček [Mon, 8 Jun 2026 10:46:22 +0000 (12:46 +0200)]
contrib/ucw/mempool: nits
Lukáš Ondráček [Thu, 4 Jun 2026 14:25:08 +0000 (16:25 +0200)]
contrib/ucw/mempool: add chunk to pool reference in debug mode
Lukáš Ondráček [Thu, 4 Jun 2026 14:19:08 +0000 (16:19 +0200)]
contrib/ucw/mempool: adjust license
Lukáš Ondráček [Tue, 2 Jun 2026 16:03:51 +0000 (18:03 +0200)]
contrib/ucw/mempool: extend mp_stats with used_size
It was introduced in a newer upstream version
and can be useful for calculating mempool overhead
as (total_size - used_size);
though it's not currently used even in kres.
Lukáš Ondráček [Tue, 2 Jun 2026 13:54:15 +0000 (15:54 +0200)]
contrib/ucw/mempools: remove unused *_zero methods
Lukáš Ondráček [Tue, 2 Jun 2026 12:44:11 +0000 (14:44 +0200)]
contrib/ucw/mempool: unify types with kres
Daniel Salzman [Tue, 7 Jul 2026 14:43:40 +0000 (16:43 +0200)]
Knot.files: update
Libor Peltan [Wed, 8 Jul 2026 09:01:00 +0000 (11:01 +0200)]
libknot/QUIC: proper timeout value for client conns...
...mostly needed for proper sweep function in kxdpgun
Libor Peltan [Wed, 8 Jul 2026 08:57:08 +0000 (10:57 +0200)]
Merge branch 'ctl_unset_ttl' into 'master'
ctl: use current TTL for zone-unset
See merge request knot/knot-dns!1890
Daniel Salzman [Mon, 6 Jul 2026 17:02:52 +0000 (19:02 +0200)]
ctl: use current TTL for zone-unset
Daniel Salzman [Mon, 6 Jul 2026 16:10:38 +0000 (18:10 +0200)]
Merge branch 'quic_errcrypto_close' into 'master'
quic: close connection on TLS handshake failure (bis)
See merge request knot/knot-dns!1889
Libor Peltan [Fri, 3 Jul 2026 13:22:20 +0000 (15:22 +0200)]
libknot/QUIC: improved error reporting when closing conn
Libor Peltan [Thu, 2 Jul 2026 12:51:13 +0000 (14:51 +0200)]
libknot/QUIC: simplify sending close when TSL handshake failed
Libor Peltan [Thu, 2 Jul 2026 12:39:12 +0000 (14:39 +0200)]
libknot/QUIC: refactoring: remove conn from table in send_special after sending excessiveLOADclosing pkt
Libor Peltan [Thu, 2 Jul 2026 12:38:36 +0000 (14:38 +0200)]
libknot/QUIC: refactoring: remove conn from table in send_special after sending closing pkt
vendemiat [Mon, 29 Jun 2026 23:45:14 +0000 (16:45 -0700)]
quic: close connection on TLS handshake failure
Close connection on NGTCP2_ERR_CRYPTO from ngtcp2_conn_read_pkt) instead
of silently discarding the packet.
Fixes timeout issues for clients failing TLS handshake (for e.g. ALPN
mismatch or certificate algorithm mismatch)
Libor Peltan [Thu, 2 Jul 2026 11:41:38 +0000 (13:41 +0200)]
Merge branch 'xdp_tcp_mtu' into 'master'
xdp: add missing Ethernet header in socket->frame_limit calculation from MTU
See merge request knot/knot-dns!1888
Daniel Salzman [Thu, 2 Jul 2026 06:14:17 +0000 (08:14 +0200)]
xdp: add missing Ethernet header in socket->frame_limit calculation from MTU
Daniel Salzman [Thu, 2 Jul 2026 05:51:22 +0000 (07:51 +0200)]
Merge branch 'rrset_static' into 'master'
Rrset static
See merge request knot/knot-dns!1887
Libor Peltan [Thu, 2 Jul 2026 04:49:57 +0000 (06:49 +0200)]
zone/offline expiry: improve log message
Libor Peltan [Wed, 1 Jul 2026 17:15:49 +0000 (19:15 +0200)]
knot: use knot_rrset_static() where appropriate
Libor Peltan [Wed, 3 Jun 2026 07:59:47 +0000 (09:59 +0200)]
libknot: helpers for static init of single-RR RRsets
Babak Farrokhi [Wed, 1 Jul 2026 12:18:14 +0000 (14:18 +0200)]
libknot: add support for EDE code 33 (Negative Trust Anchor)
Let users know what a resolver returned an insecure answer, when an NTA
is in effect.
IANA has already assigned an Extended DNS Error INFO-CODE 33 "Negative Trust Anchor"
Link: https://datatracker.ietf.org/doc/draft-farrokhi-dnsop-ede-nta/
Daniel Salzman [Tue, 30 Jun 2026 16:27:29 +0000 (18:27 +0200)]
tls: don't call gnutls_subject_alt_names_deinit() with the NULL argument
Daniel Salzman [Tue, 30 Jun 2026 13:18:53 +0000 (15:18 +0200)]
ctl: don't log interrupted poll() as warning during shutdown
Daniel Salzman [Tue, 30 Jun 2026 13:15:30 +0000 (15:15 +0200)]
libknot: add KNOT_EINTR (EINTR equivalent) error code
Daniel Salzman [Mon, 29 Jun 2026 10:42:50 +0000 (12:42 +0200)]
ctl: log failed accept if not a timeout
Daniel Salzman [Mon, 29 Jun 2026 13:07:22 +0000 (15:07 +0200)]
server: log error if a worker initialization fails
Daniel Salzman [Sun, 28 Jun 2026 13:34:06 +0000 (15:34 +0200)]
libngtcp2: update embedded library to v1.24.0
Daniel Salzman [Fri, 26 Jun 2026 16:09:23 +0000 (18:09 +0200)]
Merge branch 'events_ctl_improve' into 'master'
zone/events+ctl: refactoring: forced/user and more are now event flags/param
See merge request knot/knot-dns!1885
Libor Peltan [Tue, 16 Jun 2026 13:22:08 +0000 (15:22 +0200)]
zone/events+ctl: refactoring: forced/user and more are now event flags/param
Daniel Salzman [Fri, 26 Jun 2026 11:33:37 +0000 (13:33 +0200)]
Merge branch 'keymgr_trash_bin' into 'master'
"trash bin" for removed DNSSEC keys
See merge request knot/knot-dns!1881
David Vašek [Thu, 4 Jun 2026 14:20:35 +0000 (16:20 +0200)]
conf: fix a comment typo
David Vašek [Wed, 3 Jun 2026 20:45:02 +0000 (22:45 +0200)]
doc/operation: describe the zone removal procedure
David Vašek [Tue, 26 May 2026 14:56:32 +0000 (16:56 +0200)]
doc/operation: describe cleanup of removed legacy DNSSEC keys
David Vašek [Sun, 3 May 2026 10:10:46 +0000 (12:10 +0200)]
tests-extra: add a new test dnssec/trash_bin
For full testing, this test requires knotd binary built with
the following option:
./configure --with-gc-interval=30 ...
For good testing of the "trash bin" functionality, this option is
encouraged for all tests! There are no adverse side effects.
David Vašek [Mon, 27 Apr 2026 08:21:25 +0000 (10:21 +0200)]
tests-extra: dnssec/purge_keys -- update to "trash bin" use and current '+keys' purging
Daniel Salzman [Fri, 26 Jun 2026 09:10:11 +0000 (11:10 +0200)]
tests-extra: add fatal parameter to isset() and compare()
David Vašek [Tue, 21 Apr 2026 14:50:52 +0000 (16:50 +0200)]
kasp: policy-dependant default for trash-delay
David Vašek [Mon, 20 Apr 2026 08:08:05 +0000 (10:08 +0200)]
purge: when purging keys, use the "trash bin" instead of delete
David Vašek [Mon, 8 Jun 2026 10:58:08 +0000 (12:58 +0200)]
dnssec: use incomplete DNSSEC context for orphan keys
David Vašek [Mon, 8 Jun 2026 10:57:34 +0000 (12:57 +0200)]
dnssec: refactor kdnssec_ctx_deinit()
David Vašek [Wed, 15 Apr 2026 16:27:44 +0000 (18:27 +0200)]
doc/operation: DNSSEC key delete and recovery (the "trash bin" feature)
David Vašek [Thu, 16 Apr 2026 22:43:15 +0000 (00:43 +0200)]
keymgr: in 'trash-list', display stored key tag instead of calculating it
David Vašek [Mon, 30 Mar 2026 11:10:52 +0000 (13:10 +0200)]
keymgr: add the 'import-trash' command
David Vašek [Fri, 22 May 2026 11:58:08 +0000 (13:58 +0200)]
dnssec: modify kdnssec_load_private() to provide ksk_only flag of the keystore