diff --git a/CHANGES b/CHANGES index 7f93db9ce2..51375aa569 100644 --- a/CHANGES +++ b/CHANGES @@ -5,8 +5,8 @@ 5547. [bug] BIND 9 failed to build with --disable-threads and --with-geoip2. [GL #2324] -5544. [func] Restore the default value of nocookie-udp-size to 4096. - [GL #2250] +5544. [func] Restore the default value of "nocookie-udp-size" to 4096 + bytes. [GL #2250] 5541. [func] Adjust the "max-recursion-queries" default from 75 to 100. [GL #2305] @@ -17,7 +17,7 @@ 5539. [bug] Tighten handling of missing DNS COOKIE responses over UDP by falling back to TCP. [GL #2275] -5534. [bug] The synthesised CNAME from a DNAME was incorrectly +5534. [bug] The CNAME synthesized from a DNAME was incorrectly followed when the QTYPE was CNAME or ANY. [GL #2280] --- 9.11.25 released --- diff --git a/CONTRIBUTING b/CONTRIBUTING index 72a58aec9b..a60bb03eff 100644 --- a/CONTRIBUTING +++ b/CONTRIBUTING @@ -31,20 +31,18 @@ BIND is maintained by the Internet Systems Consortium, a public-benefit see the source, but only ISC employees have commit access. Until recently, the source could only be seen once ISC had published a release: read access to the source repository was restricted just as commit access was. -That's now changing, with the opening of a public git mirror to the BIND -source tree (see below). +That's now changing, with the opening of a public git repository of the +BIND source tree (see below). Access to source code Public BIND releases are always available from the ISC FTP site. -A public-access GIT repository is also available at https://gitlab.isc.org -. This repository is a mirror, updated several times per day, of the -source repository maintained by ISC. It contains all the public release -branches; upcoming releases can be viewed in their current state at any -time. It does not contain development branches or unreviewed work in -progress. Commits which address security vulnerablilities are withheld -until after public disclosure. +A public-access git repository is also available at https://gitlab.isc.org +. This repository contains all public release branches. Upcoming releases +can be viewed in their current state at any time. Short-lived development +branches contain unreviewed work in progress. Commits which address +security vulnerablilities are withheld until after public disclosure. You can browse the source online via https://gitlab.isc.org/isc-projects/ bind9 diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 570205b77a..6873d9794d 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -39,21 +39,19 @@ anyone can see the source, but only ISC employees have commit access. Until recently, the source could only be seen once ISC had published a release: read access to the source repository was restricted just as commit access was. That's now changing, with the opening of a -public git mirror to the BIND source tree (see below). +public git repository of the BIND source tree (see below). ### Access to source code Public BIND releases are always available from the [ISC FTP site](ftp://ftp.isc.org/isc/bind9). -A public-access GIT repository is also available at -[https://gitlab.isc.org](https://gitlab.isc.org). -This repository is a mirror, updated several times per day, of the -source repository maintained by ISC. It contains all the public release -branches; upcoming releases can be viewed in their current state at any -time. It does *not* contain development branches or unreviewed work in -progress. Commits which address security vulnerablilities are withheld -until after public disclosure. +A public-access git repository is also available at +[https://gitlab.isc.org](https://gitlab.isc.org). This repository +contains all public release branches. Upcoming releases can be viewed in +their current state at any time. Short-lived development branches +contain unreviewed work in progress. Commits which address security +vulnerablilities are withheld until after public disclosure. You can browse the source online via [https://gitlab.isc.org/isc-projects/bind9](https://gitlab.isc.org/isc-projects/bind9) diff --git a/doc/arm/notes-9.11.26.xml b/doc/arm/notes-9.11.26.xml index 535dcb7006..4c78d15ea9 100644 --- a/doc/arm/notes-9.11.26.xml +++ b/doc/arm/notes-9.11.26.xml @@ -11,71 +11,30 @@
Notes for BIND 9.11.26 -
Security Fixes - - - - None. - - - -
- -
Known Issues - - - - None. - - - -
- -
New Features - - - - None. - - - -
- -
Removed Features - - - - None. - - - -
-
Feature Changes - Adjust the max-recursion-queries default - from 75 to 100. Since the queries sent towards root and - TLD servers are now included in the count (as a result - of the fix for CVE-2020-8616), - max-recursion-queries has a higher - chance of being exceeded by non-attack queries, which is - the main reason for increasing its default value. [GL - #2305] + The default value of max-recursion-queries was + increased from 75 to 100. Since the queries sent towards root and TLD + servers are now included in the count (as a result of the fix for + CVE-2020-8616), max-recursion-queries has a higher + chance of being exceeded by non-attack queries, which is the main + reason for increasing its default value. [GL #2305] - - Restore the nocookie-udp-size default from 1232 to - 4096. Normally the EDNS buffer size is configured by - max-udp-size, but this configuration option - overrides the value, but most people don't and won't realize there's - an extra configuration option that needs to be tweaked. By changing - the default here, we allow the the max-udp-size to - be the sole option that needs to be changed when operator wants to - change the default EDNS buffer size. [GL #2250] - + + The default value of nocookie-udp-size was restored + back to 4096 bytes. Since max-udp-size is the upper + bound for nocookie-udp-size, this change relieves + the operator from having to change + nocookie-udp-size together with + max-udp-size in order to increase the default EDNS + buffer size limit. nocookie-udp-size can still be + set to a value lower than max-udp-size, if desired. + [GL #2250] +
@@ -84,21 +43,21 @@ - Tighten handling of missing DNS COOKIE responses over UDP by + Handling of missing DNS COOKIE responses over UDP was tightened by falling back to TCP. [GL #2275] - Building with native PKCS#11 support for AEP Keyper has - been broken since BIND 9.11.22. This has been fixed. [GL - #2315] + The CNAME synthesized from a DNAME was incorrectly followed when the + QTYPE was CNAME or ANY. [GL #2280] - The synthesised CNAME from a DNAME was incorrectly followed - when the QTYPE was CNAME or ANY. [GL #2280] + Building with native PKCS#11 support for AEP Keyper has been broken + since BIND 9.11.22. This has been fixed. [GL #2315] + #2315]