bind9/bin/tests/system/nsprocessinglimit
Ondřej Surý c1ba80169c
Introduce max-delegation-servers configuration option
Make the maximum number of processed delegation nameservers configurable
via the new 'max-delegation-servers' option (default: 13), replacing the
hardcoded NS_PROCESSING_LIMIT (20).

The default is reduced to 13 to precisely match the maximum number of
root servers that can fit into a classic 512-byte UDP payload.  This
provides a natural, historically sound cap that mitigates resource
exhaustion and amplification attacks from artificially inflated or
misconfigured delegations.

The configuration option is strictly bounded between 1 and 100 to ensure
resolver stability.
2026-03-04 16:13:49 +01:00
..
ns1
ns2
ns3
ns4 Introduce max-delegation-servers configuration option 2026-03-04 16:13:49 +01:00
tests_nsprocessinglimit.py Introduce max-delegation-servers configuration option 2026-03-04 16:13:49 +01:00