6021 Commits
Author SHA1 Message Date
Tinderbox User c7004347bc prep 9.14.1 2019-04-06 20:04:17 +00:00
Evan Hunt 79fad84bf6 CHANGES, release note
(cherry picked from commit 244e44af432121a05e0a308b7ccce96a8ecd28ab)
2019-04-06 12:58:12 -07:00
Evan Hunt 404be59527 CHANGES, release note
(cherry picked from commit ab5473007e91f011d003ff0ba5ab32fa0d56360c)
2019-04-06 12:57:57 -07:00
Witold KręcickiandEvan Hunt 6e63d7047d Fix deadlock in RPZ update code.
In dns_rpz_update_from_db we call setup_update which creates the db
iterator and calls dns_dbiterator_first. This unpauses the iterator and
might cause db->tree_lock to be acquired. We then do isc_task_send(...)
on an event to do quantum_update, which (correctly) after each iteration
calls dns_dbiterator_pause, and re-isc_task_sends itself.

That's an obvious bug, as we're holding a lock over an async task send -
if a task requesting write (e.g. prune_tree) is scheduled on the same
workers queue as update_quantum but before it, it will wait for the
write lock indefinitely, resulting in a deadlock.

To fix it we have to pause dbiterator in setup_update.

(cherry picked from commit 06021b3529)
2019-04-06 12:41:36 -07:00
Witold Kręcicki 4df48b84c1 CHANGES
(cherry picked from commit d11791e24c)
2019-04-03 16:34:33 +02:00
Mark Andrews ffdd736b63 add CHANGES
(cherry picked from commit b779342017)
2019-03-26 21:32:08 +11:00
Mark Andrews 7a0f39b848 add CHANGES
(cherry picked from commit bd670d4a04)
2019-03-26 19:54:40 +11:00
Tinderbox UserandEvan Hunt e6225b210b prep 9.14.0 2019-03-22 10:35:15 -07:00
Tinderbox UserandEvan Hunt 2d36283bc1 prep 9.14.0rc3 2019-03-22 10:35:15 -07:00
Evan Hunt 6b09e885b8 CHANGES, release notes
(cherry picked from commit 55a7961cf3)
2019-03-22 00:15:22 -07:00
Mark Andrews 5125a367ad add CHANGES
(cherry picked from commit e1db1b8dcb)
2019-03-22 06:52:10 +11:00
Mark Andrews 2818a83df9 add CHANGES
(cherry picked from commit c20b89fcf8)
2019-03-21 20:26:29 +11:00
Mark AndrewsandEvan Hunt 3954d4ec30 Remove revoked root DNSKEY from bind.keys.
(cherry picked from commit 0e805b58e8)
2019-03-18 21:21:39 -07:00
Mark Andrews b1c658b850 add CHANGES
(cherry picked from commit 788f784191)
2019-03-15 16:17:52 +11:00
Tony FinchandMark Andrews d69530cae8 A bit more cleanup in the dnssec-keygen manual
Remove another remnant of shared secret HMAC-MD5 support.

Explain that with currently recommended setups DNSKEY records are
inserted automatically, but you can still use $INCLUDE in other cases.

(cherry picked from commit acc3fa04b7)
2019-03-14 15:17:03 +11:00
Mark Andrews 1210201ab3 add CHANGES
(cherry picked from commit 32f2ae3791)
2019-03-14 09:01:12 +11:00
Evan Hunt a87585aba3 CHANGES
(cherry picked from commit 9463a781fb)
2019-03-12 13:59:12 -07:00
Witold KręcickiandEvan Hunt ec8621ae10 CHANGES
(cherry picked from commit 50f6054294)
2019-03-12 11:55:04 -07:00
Mark AndrewsandEvan Hunt 7dcee14699 add CHANGES
(cherry picked from commit ad785e4f93)
2019-03-11 11:22:13 -07:00
Evan Hunt 0faa56cb6c remove accidentally-included CHANGES notes 2019-03-11 10:58:51 -07:00
Michał Kępień 9fe1f29d39 Add CHANGES entry
5180.	[bug]		delv now honors the operating system's preferred
			ephemeral port range. [GL #925]

(cherry picked from commit bf98324956)
2019-03-08 13:14:01 +01:00
Tony FinchandMark Andrews 1e2bfb1460 cleanup: use dns_secalg_t and dns_dsdigest_t where appropriate
Use them in structs for various rdata types where they are missing.
This doesn't change the structs since we are replacing explicit
uint8_t field types with aliases for uint8_t.

Use dns_dsdigest_t in library function arguments.

Improve dnssec-cds with these more specific types.

(cherry picked from commit 0f219714e1)
2019-03-08 22:16:48 +11:00
Mark AndrewsandEvan Hunt cdf928d391 Handle EDQUOT and ENOSPC errors
(cherry picked from commit 435ae2f29a)
2019-03-07 21:23:39 -08:00
Mark AndrewsandEvan Hunt d76b2147a8 CHANGES, release note
(cherry picked from commit 89234643e1)
2019-03-07 13:29:37 -08:00
Evan Hunt 36d91876bf add CHANGES
(cherry picked from commit 57e44efc73)
2019-03-06 20:41:23 -08:00
Tony FinchandMark Andrews 7ddd24ba97 cleanup dnssec-keygen manual page
Alphabetize options and synopsis; remove spurious -z from synopsis;
remove remnants of deprecated -k option; remove mention of long-gone
TSIG support; refer to -T KEY in options that are only relevant to
pre-RFC3755 DNSSEC; remove unnecessary -n ZONE from the example, and
add a -f KSK example.

(cherry picked from commit 1954f8d2bf)
2019-03-07 11:14:55 +11:00
Mark Andrews ef46f75066 add CHANGES
(cherry picked from commit 5bc06a0a11)
2019-03-07 10:45:04 +11:00
Evan Hunt 71adab3f4a CHANGES
(cherry picked from commit 6d24292830)
2019-03-06 14:15:19 -08:00
Michał Kępień 0a5a0a5e97 Add CHANGES entry
5172.	[bug]		nsupdate now honors the operating system's preferred
			ephemeral port range. [GL #905]

(cherry picked from commit 0e64948274)
2019-03-06 14:03:37 +01:00
Michał KępieńandEvan Hunt f1f695ef5a Add CHANGES entry
5161.	[func]		named plugins are now installed into a separate
			directory.  Supplying a filename (a string without path
			separators) in a "plugin" configuration stanza now
			causes named to look for that plugin in that directory.
			[GL #878]

(cherry picked from commit d2c960cfc2)
2019-03-05 16:52:49 -08:00
Mark Andrews f9920f62c4 add CHANGES
(cherry picked from commit 5f125df462)
2019-03-04 14:08:21 +11:00
Evan Hunt 778cfd3a98 CHANGES 2019-02-28 16:07:41 -08:00
Tinderbox User 13c0bf922b prep 9.14.0rc1 2019-02-27 23:50:01 +00:00
Matthijs MekkingandMatthijs Mekking 0f520ac026 Update CHANGES 2019-02-22 15:26:43 +01:00
Tinderbox User 856c74700f prep 9.13.7 2019-02-21 01:57:08 +00:00
Mark AndrewsandEvan Hunt ed6c10d46b add CHANGES and release notes entries 2019-02-20 17:45:50 -08:00
Mark AndrewsandEvan Hunt 7d5b7192ec add CHANGES and release note entries 2019-02-20 17:45:49 -08:00
Matthijs MekkingandEvan Hunt ea5a5b77f9 CHANGES, notes 2019-02-20 17:45:48 -08:00
Evan Hunt bcc2fd679b CHANGES 2019-02-19 17:19:40 -08:00
Mark Andrews a0c0d76029 add CHANGES 2019-02-20 09:44:56 +11:00
Mark Andrews 3a21fdf884 add CHANGES 2019-02-20 09:29:07 +11:00
Tony FinchandMark Andrews 7ee56e2abd Improve dnssec-keymgr manual
Illustrate the syntax for the policy options, with semicolons.

Explicitly mention the "default" policy.

Fix a few typos and remove some redundant wording.
2019-02-18 14:12:45 +11:00
Michał Kępień 2b19b8511a Add CHANGES entry
5161.	[bug]		Do not require the SEP bit to be set for mirror zone
			trust anchors. [GL #873]
2019-02-14 11:03:35 +01:00
Evan Hunt 2e3b5db195 added DNAME support to DLZ LDAP schema, and fixed a DLZ compile error
Thanks to Roland Gruber for the schema contribution.
2019-02-10 11:49:01 -08:00
Mark Andrews a9fadafecd fix AMTRELAY name 2019-02-08 13:54:13 +11:00
Evan Hunt a242c704f5 CHANGES 2019-02-07 16:53:47 -08:00
Evan Hunt 72f6fb0697 CHANGES 2019-02-07 12:34:14 -08:00
Mark Andrews f73816ff0f error out if there are extra command line options 2019-02-07 19:49:44 +11:00
Tinderbox User b4d3f78293 prep 9.13.6 2019-02-06 22:13:05 +00:00
Michał KępieńandEvan Hunt c33e1c98db Add CHANGES entry
5156.	[doc]		Extended and refined the section of the ARM describing
			mirror zones. [GL #774]
2019-02-06 11:00:27 -08:00