gthess
11f2e7e6ae
Merge pull request #617 from NLnetLabs/update-host-notation
...
Update stub/forward-host notation to accept port and tls-auth-name
2022-02-02 11:56:27 +01:00
gthess
414a37ed2b
Don't accidentaly introduce a troff macro
...
Co-authored-by: Wouter Wijngaards <wcawijngaards@users.noreply.github.com>
2022-02-02 11:53:38 +01:00
George Thessalonikefs
32c3bbd249
- Change aggressive-nsec default to yes.
2022-02-02 11:25:08 +01:00
George Thessalonikefs
c6b413069d
Changelog entry for #616
...
- Merge PR #616 : Update ratelimit logic. It also introduces
ratelimit-backoff and ip-ratelimit-backoff configuration options.
2022-02-02 11:18:14 +01:00
gthess
358e3a5963
Merge pull request #616 from NLnetLabs/bugfix/ratelimit
...
Update ratelimit logic
2022-02-02 11:16:04 +01:00
George Thessalonikefs
25eae982de
Merge branch 'Shchelk-bufferoverflow'
2022-02-02 10:50:54 +01:00
George Thessalonikefs
506d24c7a6
Changelog entry for #532
...
- Merge PR #532 from Shchelk: Fix: buffer overflow bug.
2022-02-02 10:48:56 +01:00
George Thessalonikefs
d81e1c999b
Merge branch 'bufferoverflow' of https://github.com/Shchelk/unbound into Shchelk-bufferoverflow
2022-02-02 10:42:06 +01:00
George Thessalonikefs
a5e9221933
Changelog note for #603 :
...
- Merge PR #603 from fobser: Use OpenSSL 1.1 API to access DSA and RSA
internals.
2022-02-01 18:00:46 +01:00
gthess
1199482372
Merge pull request #603 from fobser/dsa_rsa_internals
...
Use OpenSSL 1.1 API to access DSA and RSA internals
2022-02-01 17:58:11 +01:00
gthess
b93aa79a05
Prefer the libressl API from when it was available
2022-02-01 17:54:42 +01:00
gthess
7ddd456f02
Fix typo from review
...
Co-authored-by: Wouter Wijngaards <wcawijngaards@users.noreply.github.com>
2022-02-01 17:38:16 +01:00
George Thessalonikefs
814a234876
- Update stub/forward-host notation to accept port and tls-auth-name.
...
Fixes #546 .
2022-02-01 14:44:29 +01:00
George Thessalonikefs
10d9804149
Merge branch 'master' of github.com:NLnetLabs/unbound
2022-01-31 11:28:30 +01:00
George Thessalonikefs
a60bbd12ed
-Fix review comment for use-after-free when failing to send UDP out.
2022-01-31 11:27:35 +01:00
W.C.A. Wijngaards
84df46289d
- iana portlist update.
2022-01-31 10:53:22 +01:00
George Thessalonikefs
52283194eb
- Update unbound.conf manpage and example.conf file for ratelimit
...
options.
2022-01-30 01:04:15 +01:00
George Thessalonikefs
c8a6234aac
- Add tests for ratelimit.
2022-01-30 00:51:39 +01:00
George Thessalonikefs
3086335724
- Introduce ratelimit-backoff and ip-ratelimit-backoff options for more
...
aggressive rate limiting.
2022-01-30 00:36:29 +01:00
George Thessalonikefs
f857af873e
- Update ratelimit code for recent serviced_query changes and more
...
accurate ratelimit calculation.
2022-01-29 23:49:38 +01:00
George Thessalonikefs
888eb224a6
- Better cleanup on failed DoT/DoH listening socket creation.
2022-01-29 15:14:56 +01:00
George Thessalonikefs
c49e87e1b7
- Fix tls-* and ssl-* documented alternate syntax to also be available
...
through remote-control and unbound-checkconf.
2022-01-29 15:11:47 +01:00
W.C.A. Wijngaards
d10562c823
Merge branch 'master' of github.com:NLnetLabs/unbound
2022-01-26 16:41:04 +01:00
W.C.A. Wijngaards
54ea2948da
- Test for NSID in SERVFAIL response due to DNSSEC bogus.
2022-01-26 16:40:04 +01:00
George Thessalonikefs
ea47c08e70
- Fix #599 : [FR] RFC 9156 (obsoletes RFC 7816), by noting the new RFC
...
document.
2022-01-26 14:35:22 +01:00
George Thessalonikefs
79e755e1dd
Changelog note for #612 :
...
- Merge PR #612 : TCP race condition.
2022-01-25 17:29:52 +01:00
gthess
ddc3c754b0
Merge pull request #612 from NLnetLabs/tcp-race-condition
...
TCP race condition
2022-01-25 17:26:30 +01:00
George Thessalonikefs
5c85615515
- Fix #588 : Unbound 1.13.2 crashes due to p->pc is NULL in
...
serviced_udp_callback.
2022-01-25 17:15:37 +01:00
George Thessalonikefs
f0c6d26155
- Better bookkeeping when reclaiming the TCP buffer.
2022-01-25 10:32:37 +01:00
George Thessalonikefs
4573629fc4
- Mark waiting_tcp and serviced_query as being in the
...
cb_and_decommission stage to signal later code about their state;
prevents premature item deletion.
2022-01-25 09:46:16 +01:00
W.C.A. Wijngaards
70f13e54bf
Changelog note for #610
...
- Fix #610 : Undefine-shift in sldns_str2wire_hip_buf.
2022-01-25 09:02:55 +01:00
W.C.A. Wijngaards
12a1053dfa
- Fix #610 : Undefine-shift in sldns_str2wire_hip_buf.
2022-01-25 08:57:49 +01:00
George Thessalonikefs
c3c0186658
- Add serviced_query timer to send upstream queries outside of the mesh
...
flow to prevent race conditions.
2022-01-25 00:01:43 +01:00
George Thessalonikefs
8e76eb95a0
- For dnstap, do not wakeupnow right there. Instead zero the timer to
...
force the wakeup callback asap.
2022-01-19 15:32:02 +01:00
W.C.A. Wijngaards
c7ae3ef156
- For #602 : Allow the module-config "subnetcache validator cachedb
...
iterator".
2022-01-14 16:30:25 +01:00
W.C.A. Wijngaards
2996040c6c
- Add rpz: for-downstream: yesno option, where the RPZ zone is
...
authoritatively answered for, so the RPZ zone contents can be
checked with DNS queries directed at the RPZ zone.
2022-01-14 16:23:43 +01:00
George Thessalonikefs
3c8a79eed8
Changelog note for #605 :
...
- Merge PR #605 : Fix EDNS to upstream where the same option could be
attached more than once.
2022-01-14 15:38:15 +01:00
gthess
f00d96a21b
Merge pull request #605 from NLnetLabs/sq-region
...
Fix EDNS to upstream where the same option could be attached more than once
2022-01-14 15:33:22 +01:00
George Thessalonikefs
773d1f2911
- Make sure callback changes for EDNS are not lost.
2022-01-14 15:18:43 +01:00
George Thessalonikefs
de1e91fc7f
- Fix EDNS to upstream where the same option could be attached more than
...
once.
- Add a region to serviced_query for allocations.
2022-01-14 13:55:34 +01:00
Florian Obser
ff35659d5a
Use OpenSSL 1.1 API to access DSA and RSA internals
...
In LibreSSL 3.5, DSA and RSA internals will become opaque, so they can
no longer be accessed directly and the libunbound build will break. The
required API, DSA_set0_pqg(), DSA_set0_key() as well as RSA_set0_key(),
has been available since LibreSSL 2.7, so this change should not affect
any users.
From Theo Buehler.
2022-01-11 15:34:25 +01:00
George Thessalonikefs
a97604737b
- Fix prematurely terminated TCP queries when a reply has the same ID.
2022-01-11 10:00:45 +01:00
W.C.A. Wijngaards
d52d94c6db
Changelog note for #600
...
- Merge #600 from pemensik: Change file mode before changing file
owner.
2022-01-07 13:23:18 +01:00
Wouter Wijngaards
370a855f08
Merge pull request #600 from InfrastructureServices/remote-unix-chmod
...
Change file mode before changing file owner
2022-01-07 13:23:03 +01:00
Petr Mensik
c7f44b99e3
Change file mode before changing file owner
...
Change mode first when configuring remote control unix socket. Some
security systems might strip capability of changing other user's system
even to process with effective uid 0. That is done on Fedora by SELinux
policy and systemd for example. SELinux audit then shows errors, because
unbound tries modifying permissions of not own file. Fix just by mode
change as first step, make it owned by unbound:unbound user as the last
step only.
Related: rhbz#1905441
2022-01-07 12:08:32 +01:00
Alex Band
9bbbca5de9
Update documentation links
2022-01-07 10:21:50 +01:00
W.C.A. Wijngaards
33ef79d433
- Fix for #596 : Fix rpz-signal-nxdomain-ra to work for clientip
...
triggered operation.
2022-01-05 16:48:35 +01:00
W.C.A. Wijngaards
eccfe3e1f5
- Fix #598 : Fix unbound-checkconf fatal error: module conf
...
'respip dns64 validator iterator' is not known to work.
2022-01-05 16:14:47 +01:00
W.C.A. Wijngaards
adcbb6ced7
- Fix for #596 : add unit test for nsip trigger and signal unset RA.
2022-01-05 14:31:42 +01:00
W.C.A. Wijngaards
c678c696a1
- Fix for #596 : add unit test for nsdname trigger and signal unset RA.
2022-01-05 14:13:52 +01:00