diff --git a/CHANGES b/CHANGES
index 7f93db9ce2..51375aa569 100644
--- a/CHANGES
+++ b/CHANGES
@@ -5,8 +5,8 @@
5547. [bug] BIND 9 failed to build with --disable-threads and
--with-geoip2. [GL #2324]
-5544. [func] Restore the default value of nocookie-udp-size to 4096.
- [GL #2250]
+5544. [func] Restore the default value of "nocookie-udp-size" to 4096
+ bytes. [GL #2250]
5541. [func] Adjust the "max-recursion-queries" default from 75 to
100. [GL #2305]
@@ -17,7 +17,7 @@
5539. [bug] Tighten handling of missing DNS COOKIE responses over
UDP by falling back to TCP. [GL #2275]
-5534. [bug] The synthesised CNAME from a DNAME was incorrectly
+5534. [bug] The CNAME synthesized from a DNAME was incorrectly
followed when the QTYPE was CNAME or ANY. [GL #2280]
--- 9.11.25 released ---
diff --git a/CONTRIBUTING b/CONTRIBUTING
index 72a58aec9b..a60bb03eff 100644
--- a/CONTRIBUTING
+++ b/CONTRIBUTING
@@ -31,20 +31,18 @@ BIND is maintained by the Internet Systems Consortium, a public-benefit
see the source, but only ISC employees have commit access. Until recently,
the source could only be seen once ISC had published a release: read
access to the source repository was restricted just as commit access was.
-That's now changing, with the opening of a public git mirror to the BIND
-source tree (see below).
+That's now changing, with the opening of a public git repository of the
+BIND source tree (see below).
Access to source code
Public BIND releases are always available from the ISC FTP site.
-A public-access GIT repository is also available at https://gitlab.isc.org
-. This repository is a mirror, updated several times per day, of the
-source repository maintained by ISC. It contains all the public release
-branches; upcoming releases can be viewed in their current state at any
-time. It does not contain development branches or unreviewed work in
-progress. Commits which address security vulnerablilities are withheld
-until after public disclosure.
+A public-access git repository is also available at https://gitlab.isc.org
+. This repository contains all public release branches. Upcoming releases
+can be viewed in their current state at any time. Short-lived development
+branches contain unreviewed work in progress. Commits which address
+security vulnerablilities are withheld until after public disclosure.
You can browse the source online via https://gitlab.isc.org/isc-projects/
bind9
diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md
index 570205b77a..6873d9794d 100644
--- a/CONTRIBUTING.md
+++ b/CONTRIBUTING.md
@@ -39,21 +39,19 @@ anyone can see the source, but only ISC employees have commit access.
Until recently, the source could only be seen once ISC had published
a release: read access to the source repository was restricted just
as commit access was. That's now changing, with the opening of a
-public git mirror to the BIND source tree (see below).
+public git repository of the BIND source tree (see below).
### Access to source code
Public BIND releases are always available from the
[ISC FTP site](ftp://ftp.isc.org/isc/bind9).
-A public-access GIT repository is also available at
-[https://gitlab.isc.org](https://gitlab.isc.org).
-This repository is a mirror, updated several times per day, of the
-source repository maintained by ISC. It contains all the public release
-branches; upcoming releases can be viewed in their current state at any
-time. It does *not* contain development branches or unreviewed work in
-progress. Commits which address security vulnerablilities are withheld
-until after public disclosure.
+A public-access git repository is also available at
+[https://gitlab.isc.org](https://gitlab.isc.org). This repository
+contains all public release branches. Upcoming releases can be viewed in
+their current state at any time. Short-lived development branches
+contain unreviewed work in progress. Commits which address security
+vulnerablilities are withheld until after public disclosure.
You can browse the source online via
[https://gitlab.isc.org/isc-projects/bind9](https://gitlab.isc.org/isc-projects/bind9)
diff --git a/doc/arm/notes-9.11.26.xml b/doc/arm/notes-9.11.26.xml
index 535dcb7006..4c78d15ea9 100644
--- a/doc/arm/notes-9.11.26.xml
+++ b/doc/arm/notes-9.11.26.xml
@@ -11,71 +11,30 @@
Notes for BIND 9.11.26
- Security Fixes
-
-
-
- None.
-
-
-
-
-
- Known Issues
-
-
-
- None.
-
-
-
-
-
- New Features
-
-
-
- None.
-
-
-
-
-
- Removed Features
-
-
-
- None.
-
-
-
-
-
Feature Changes
- Adjust the max-recursion-queries default
- from 75 to 100. Since the queries sent towards root and
- TLD servers are now included in the count (as a result
- of the fix for CVE-2020-8616),
- max-recursion-queries has a higher
- chance of being exceeded by non-attack queries, which is
- the main reason for increasing its default value. [GL
- #2305]
+ The default value of max-recursion-queries was
+ increased from 75 to 100. Since the queries sent towards root and TLD
+ servers are now included in the count (as a result of the fix for
+ CVE-2020-8616), max-recursion-queries has a higher
+ chance of being exceeded by non-attack queries, which is the main
+ reason for increasing its default value. [GL #2305]
-
- Restore the nocookie-udp-size default from 1232 to
- 4096. Normally the EDNS buffer size is configured by
- max-udp-size, but this configuration option
- overrides the value, but most people don't and won't realize there's
- an extra configuration option that needs to be tweaked. By changing
- the default here, we allow the the max-udp-size to
- be the sole option that needs to be changed when operator wants to
- change the default EDNS buffer size. [GL #2250]
-
+
+ The default value of nocookie-udp-size was restored
+ back to 4096 bytes. Since max-udp-size is the upper
+ bound for nocookie-udp-size, this change relieves
+ the operator from having to change
+ nocookie-udp-size together with
+ max-udp-size in order to increase the default EDNS
+ buffer size limit. nocookie-udp-size can still be
+ set to a value lower than max-udp-size, if desired.
+ [GL #2250]
+
@@ -84,21 +43,21 @@
- Tighten handling of missing DNS COOKIE responses over UDP by
+ Handling of missing DNS COOKIE responses over UDP was tightened by
falling back to TCP. [GL #2275]
- Building with native PKCS#11 support for AEP Keyper has
- been broken since BIND 9.11.22. This has been fixed. [GL
- #2315]
+ The CNAME synthesized from a DNAME was incorrectly followed when the
+ QTYPE was CNAME or ANY. [GL #2280]
- The synthesised CNAME from a DNAME was incorrectly followed
- when the QTYPE was CNAME or ANY. [GL #2280]
+ Building with native PKCS#11 support for AEP Keyper has been broken
+ since BIND 9.11.22. This has been fixed. [GL #2315]
+ #2315]