e08a31e3178ef454e7dff1ab0de54f48a39fca21 |
|
04-Jan-2018 |
Mark Andrews <marka@isc.org> |
test devent->sigrdataset rather than devent->rdataset before calling query_putrdataset |
dc2a85bed7fcfceab0df1867fbc1d35796261ded |
|
05-Jan-2018 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
cad79077bd5b2616bc4a7a6b3cbc0953bef8917f |
|
04-Jan-2018 |
Mark Andrews <marka@isc.org> |
4857. [bug] Maintain attach/detach semantics for event->db,
event->node, event->rdataset and event->sigrdataset
in query.c. [RT #46891] |
3ed16e796dba90c96933c8a8a3f5b9404d8d3e61 |
|
13-Nov-2017 |
Mark Andrews <marka@isc.org> |
4817. [cleanup] Use DNS_NAME_INITABSOLUTE and DNS_NAME_INITNONABSOLUTE.
[RT #45433]
(cherry picked from commit 3d905e053369cff1412b9d20aa5bb23376e0fed4) |
4d39bffd9550fd87beba4e873056e1aee93c9bfc |
|
24-Oct-2017 |
Evan Hunt <each@isc.org> |
[v9_11] fix merge error; missing hunk from change 4780 |
b7b76d6b855cd4c1152c26d34fb61af05f965c5e |
|
24-Oct-2017 |
Evan Hunt <each@isc.org> |
[v9_11] omit NS from authority section if it was in answer
4780. [bug] When answering ANY queries, don't include the NS
RRset in the authority section if it was already
in the answer section. [RT #44543] |
1c8aa38b53a0494fc7d4c3439594d1913987f264 |
|
06-Oct-2017 |
Mark Andrews <marka@isc.org> |
4759. [func] Add logging channel "trust-anchor-telementry" to
record trust-anchor-telementry in incoming requests.
Both _ta-XXXX.<anchor>/NULL and EDNS KEY-TAG options
are logged. [RT #46124]
(cherry picked from commit b41c1aacbc550fa67bfa62df3114b1d668b9c8d8) |
d72952cf254b71c44e5e956a306016a5be9b9c38 |
|
27-Sep-2017 |
Mark Andrews <marka@isc.org> |
4739. [cleanup] Address clang static analysis warnings. [RT #45952]
(cherry picked from commit f9f3f20d2d08e1c8756a1b260d7c5125426d8395) |
68d7ff133c9a1b8cfe683c70e997d83395ffd155 |
|
26-Sep-2017 |
Evan Hunt <each@isc.org> |
[v9_11] backport rpz tweaks
4713. [cleanup] Minor revisions to RPZ code to reduce
differences with the development branch. [RT #46037] |
031bc55634f443c7c70fbf44c6ac6d8abe72f22b |
|
25-Aug-2017 |
Evan Hunt <each@isc.org> |
[v9_11] turn on minimal responses for CDS/CDNSKEY
4678. [cleanup] Turn on minimal responses for CDNSKEY and CDS in
addition to DNSKEY and DS. Thanks to Tony Finch.
[RT #45690]
(cherry picked from commit 391a3a2f202a374e20f394b92116f129dcbb99a1) |
7dbeb5e7f067585abfb12fac314a0d2a8f0dd040 |
|
09-Aug-2017 |
Evan Hunt <each@isc.org> |
[v9_11] silence gcc 7 warnings
4673. [port] Silence GCC 7 warnings. [RT #45592]
(cherry picked from commit cdacec1dcb93149b8efc7af38ec916adcdd706f3) |
b2e71853060a384070d422afda6d1c692ff608e3 |
|
23-Jun-2017 |
Mark Andrews <marka@isc.org> |
4640. [bug] If query_findversion failed in query_getdb due to
memory failure the error status was incorrectly
discarded. [RT #45331]
(cherry picked from commit b551ee14bd12fff52aa05f7f94cd4e17cea52be3) |
3a58e1fefb0a9fd5dab11f271a320c6b90473f76 |
|
12-Jun-2017 |
Mukund Sivaraman <muks@isc.org> |
Don't log NSDNAME failures as NSIP (#45052)
(cherry picked from commit 2c11da844192d8366a6e0047dff15a2746f9467e) |
3440cf9c60cd5d35634e7f274fd3eccbba2173a5 |
|
30-May-2017 |
Evan Hunt <each@isc.org> |
[v9_11] fix rpz formerr loop
4531. [security] Some RPZ configurations could go into an infinite
query loop when encountering responses with TTL=0.
(CVE-2017-3140) [RT #45181] |
fb9ef31fed818384ef8997f2dc5f27252c6f767e |
|
28-May-2017 |
Evan Hunt <each@isc.org> |
[v9_11] Add DLZ db version to activeversions
4628. [bug] Fixed a potential reference leak in query_getdb().
[RT #45247]
(cherry picked from commit 594eadcc341bc29f5977a5f09d910132ea9bd244) |
0b18154e45c6ea780bd10f24865bac1bdcd732d3 |
|
02-May-2017 |
Mark Andrews <marka@isc.org> |
remove unused assignments [RT #45147]
(cherry picked from commit 78551a3f2c9dd53a85386a6234860127e23befd9) |
fec9247b8f1ab52e999643ae03f0550387ec359f |
|
21-Apr-2017 |
Mukund Sivaraman <muks@isc.org> |
Validate glue before adding it to the additional section (#45062)
(cherry picked from commit b0dbcba2d25dfa49a2e705e4481298729334605a) |
b81977ae70138c9befd8fa4bb66b6145e1986561 |
|
14-Feb-2017 |
Mark Andrews <marka@isc.org> |
4575. [security] Dns64 with break-dnssec yes; can result in a
assertion failure. (CVE-2017-3136) [RT #44653]
(cherry picked from commit 3bce12e4b6d37f570ffc7747b499f8b90e8521ac) |
22e3ffcf2c52114092b2dbdf2bc1872371c96192 |
|
23-Jan-2017 |
Mark Andrews <marka@isc.org> |
4556. [security] Combining dns64 and rpz can result in dereferencing
a NULL pointer (read). (CVE-2017-3135) [RT#44434]
(cherry picked from commit 5abe80ef138340e3d4f551059a3c340b78940933) |
2f4e3e45d6bebe521d31c4b60d153f93f4b8e63f |
|
20-Jan-2017 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
eb032a17ef690d16329af2c467a219e0da3ff799 |
|
19-Jan-2017 |
Mark Andrews <marka@isc.org> |
whitespace
(cherry picked from commit bf0b64999352b8bf72b200ece4f9d6997e94e7ab) |
960989925556246cc86f1905a5d62e6b0b69dc02 |
|
29-Dec-2016 |
Mark Andrews <marka@isc.org> |
4531. [security] 'is_zone' was not being properly updated by redirect2
and subsequently preserved leading to an assertion
failure. (CVE-2016-9778) [RT #43837]
(cherry picked from commit d376792dae686e0fc0e3986ad3335d1b7ff0c279) |
9ee66e3a5b45654235472711439f9db1766c82ca |
|
05-Oct-2016 |
Mark Andrews <marka@isc.org> |
4472. [bug] Named could fail to find the correct NSEC3 records when
a zone was update between looking for the answer and
looking for the NSEC3 records proving non-existance
of the answer. [RT #43247] |
2fb6d3782b548ba678cfb8ff09e0d1e49fafb84d |
|
12-Aug-2016 |
Mark Andrews <marka@isc.org> |
4437. [func] Minimal-responses now has two additional modes
no-auth and no-auth-recursive which suppress
adding the NS records to the authority section
as well as the associated address records for the
nameservers. [RT #42005]
(cherry picked from commit 78e31dd18798f22828059b0f5cbc1c984c7e142c) |
33f91e248b67afa96c5b855ba3ace20b5d89dbd0 |
|
12-Aug-2016 |
Mark Andrews <marka@isc.org> |
4434. [protocol] Return EDNS EXPIRE option for master zones in addition
to slave zones. [RT #43008]
(cherry picked from commit bf2238b064ed2398a9e9db27c6fb73f58c4db38a) |
0c27b3fe77ac1d5094ba3521e8142d9e7973133f |
|
27-Jun-2016 |
Mark Andrews <marka@isc.org> |
4401. [misc] Change LICENSE to MPL 2.0. |
eb54bc33a21195c46b120a5db3758d71aae322cd |
|
03-Jun-2016 |
Mark Andrews <marka@isc.org> |
also cleanup node |
92ddd7ad2ca82375408b9f3078f29533402ff2cb |
|
03-Jun-2016 |
Mark Andrews <marka@isc.org> |
detach before restore |
b4750b59910e1deb1329120f480bd5f8780e3eac |
|
03-Jun-2016 |
Mark Andrews <marka@isc.org> |
reset zversion on restart |
aabcb1fde0ca255ff30f0a5c10cbd39f798cc5b7 |
|
27-May-2016 |
Mark Andrews <marka@isc.org> |
4377. [bug] Don't reuse zero TTL responses beyond the current
client set (excludes ANY/SIG/RRSIG queries).
[RT #42142] |
6c2a76b3e2ccd32c35814b6e0f54da00190749d7 |
|
26-May-2016 |
Evan Hunt <each@isc.org> |
[master] copyrights, win32 definitions |
ac110848296c18b3a3bfaa89bdee2dd00755b36f |
|
25-May-2016 |
Mark Andrews <marka@isc.org> |
4374. [bug] Use SAVE/RESTORE macros in query.c to reduce the
probability of reference counting errors as seen
in 4365. [RT #42405] |
0cbe448914be61d0f92b1e9d3adaeba87d25639d |
|
25-May-2016 |
Evan Hunt <each@isc.org> |
[master] minimal-any
4371. [func] New "minimal-any" option reduces the size of UDP
responses for qtype ANY by returning a single
arbitrarily selected RRset instead of all RRsets.
Thanks to Tony Finch. [RT #41615] |
c3beecc1bcc6e1c15176a699b41ca77ef6533c25 |
|
13-May-2016 |
Mark Andrews <marka@isc.org> |
4365. [bug] Address zone reference counting errors involving
nxdomain-redirect. [RT #42258] |
19d80ce5844e00a021643759adcbe27c11b485a0 |
|
05-May-2016 |
Witold Krecicki <wpk@isc.org> |
4358. [test] Added American Fuzzy Lop harness that allows
feeding fuzzed packets into BIND.
[RT #41723] |
08e36aa5a5c7697a839f83831fccf8fb3f792848 |
|
05-May-2016 |
Mark Andrews <marka@isc.org> |
4356. [func] Add the ability to specify whether to wait for
nameserver addresses to be looked up or not to
rpz with a new modifying directive 'nsip-wait-recurse'. [RT #35009] |
9da98335c185c39591150ccb4e307adc4cea44bc |
|
03-Mar-2016 |
Mukund Sivaraman <muks@isc.org> |
Code cleanups (#41656) |
68ecf1c9a5bca811f044052bcd43717b6d58a5fe |
|
04-Feb-2016 |
Mark Andrews <marka@isc.org> |
add missing line break |
d88ba937124b2a4f8a074fc2aef9caf2022308b4 |
|
03-Feb-2016 |
Mark Andrews <marka@isc.org> |
4313. [bug] Handle ns_client_replace failures in test mode.
[RT #41190] |
c46ac73c8f1d0133903c00332ab4fa4e2550ecc4 |
|
23-Jan-2016 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
630b2d0c5a04cfc8b08d4585b7a0d997c00d7341 |
|
22-Jan-2016 |
Evan Hunt <each@isc.org> |
[master] NOSETFC incorrectly applied
4300. [bug] A flag could be set in the wrong field when setting
up nonrecursive queries; this could cause the
SERVFAIL cache to cache responses it shouldn't.
New querytrace logging has been added which
identified this error. [RT #41155] |
f647c0df9fd334b19a5bdc9c252f90d94c0abf1e |
|
15-Dec-2015 |
Mark Andrews <marka@isc.org> |
4281. [bug] Teach dns_message_totext about BADCOOKIE. [RT #41257] |
04893d38e0c013c35a57f177c3012cdeb9ea086d |
|
21-Oct-2015 |
Mark Andrews <marka@isc.org> |
add blank line |
0526268c2b2806ceb67032e0bfee708b6e70e004 |
|
22-Oct-2015 |
Mark Andrews <marka@isc.org> |
4242. [bug] Replace the client if not already replaced when
prefetching. [RT #41001] |
2a12984ce69f7f49dc3aeef1b216e0c7c93373ac |
|
30-Sep-2015 |
Mark Andrews <marka@isc.org> |
4227. [bug] Silence static analysis warnings. [RT #40828 |
4d085258ccffeed949a8a8b91c07e4c0b46114d3 |
|
29-Sep-2015 |
Mark Andrews <marka@isc.org> |
make macro name match category name |
bf350c9f1ab59ac03e34e8063b4ce58662daec2a |
|
18-Aug-2015 |
Mukund Sivaraman <muks@isc.org> |
Fix RPZ bugs related to wildcard triggers (#40357) |
c631ff56bfe13f7b47ff01950364f4db423bf21a |
|
13-Aug-2015 |
Mark Andrews <marka@isc.org> |
Updated CHANGES note to include require-server-cookie:
4152. [func] Implement DNS COOKIE option. This replaces the
experimental SIT option of BIND 9.10. The following
named.conf directives are available: send-cookie,
cookie-secret, cookie-algorithm, nocookie-udp-size
and require-server-cookie. The following dig options
are available: +[no]cookie[=value] and +[no]badcookie.
[RT #39928] |
b485d0a67f77e3bdb0f99014f50b4facc1e61784 |
|
27-Jul-2015 |
Mark Andrews <marka@isc.org> |
if UDP and we have a bad cookie send a immediate badcookie response |
e8f98ec8d4dfe50e39b667f9d8c8c91804976ddc |
|
07-Jul-2015 |
Mark Andrews <marka@isc.org> |
future cookie code |
33ca26968b638b4ff9c657e9574d14d1a04a52dd |
|
06-Jul-2015 |
Mukund Sivaraman <muks@isc.org> |
Allow RPZ rewrite logging to be configured on a per-zone basis (#39754) |
8f0b326d9a895faa71b55cb3994b54ff4666faa9 |
|
06-Jul-2015 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
ce67023ae3ad39a77da5361d0187ab6f3f0219cb |
|
06-Jul-2015 |
Mark Andrews <marka@isc.org> |
4152. [func] Implement DNS COOKIE option. This replaces the
experimental SIT option of BIND 9.10. The following
named.conf directives are avaliable: send-cookie,
cookie-secret, cookie-algorithm and nocookie-udp-size.
The following dig options are available:
+[no]cookie[=value] and +[no]badcookie. [RT #39928] |
8e50c697839c12d55bca0202ce09bd81f069f909 |
|
26-Jun-2015 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
f10a67dad21d7dd87ee2144964faa639f96766b5 |
|
25-Jun-2015 |
Witold Krecicki <wpk@culm.net> |
Add statistics counters for nxdomain redirections. [RT #39790] |
27970e78c6cb2650893132944871a6ee24d86b02 |
|
10-Jun-2015 |
Evan Hunt <each@isc.org> |
[master] log outdated rpz settings regardless of enable-querytrace |
215049febbace211bc2207e50ff97d403e9c5fa1 |
|
10-Jun-2015 |
Evan Hunt <each@isc.org> |
[master] rpz_ver check was ineffective |
8c9fba44a41e3ea23e7e8405029980aba672f7ce |
|
04-Jun-2015 |
Evan Hunt <each@isc.org> |
[master] further RPZ fixes
4131. [bug] Addressed further problems with reloading RPZ
zones. [RT #39649] |
a32b6291aa5f797e1336869390f99d4a655484c2 |
|
27-May-2015 |
Evan Hunt <each@isc.org> |
[master] address regression
4126. [bug] Addressed a regression introduced in change #4121.
[RT #39611] |
705cea35a8f798340ac947713ab97791be521b52 |
|
21-May-2015 |
Mukund Sivaraman <muks@isc.org> |
Fix RPZ radix tree search() for CLIENT-IP triggers (#39481) |
b403f3b57e3a1cf0a8a98186d5a4419bc4f776b9 |
|
20-May-2015 |
Evan Hunt <each@isc.org> |
[master] revert erroneous cleanup |
54231cf0821bd45ce3f525631cc44f96e00996f4 |
|
20-May-2015 |
Evan Hunt <each@isc.org> |
[master] minor cleanup |
7e6cf6fc6e700061a1cec3bcf67786706d956fc5 |
|
20-May-2015 |
Evan Hunt <each@isc.org> |
[master] address a possible policy update race
4120. [bug] A bug in RPZ could cause the server to crash if
policy zones were updated while recursion was
pending for RPZ processing of an active query.
[RT #39415] |
fe76a642941adfa1ad62737dbcb0dbf85f06f54d |
|
07-May-2015 |
Mark Andrews <marka@isc.org> |
restore is_zone on return from redirect lookup [RT #37989b]
(cherry picked from commit 1d405c1412b3a2e5aafb37ea55b332914246349e) |
b299727c2ee225eb40b65e87407ef24b05114883 |
|
24-Apr-2015 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
c82b3781158672e8308b53a8b6289e432ceb48d0 |
|
23-Apr-2015 |
Mark Andrews <marka@isc.org> |
4108. [func] A additional nxdomain redirect (nxdomain-redirect)
method is now supported. [RT #37989] |
29d52c001ff976561669375cf0c866b815a90c49 |
|
03-Mar-2015 |
Mark Andrews <marka@isc.org> |
4081. [cleanup] Use dns_rdatalist_init consistently. [RT #38759] |
a8da00ef95ba37b9d071c2b8db1a0c967e060106 |
|
27-Feb-2015 |
Mark Andrews <marka@isc.org> |
4079. [func] Preserve the case of the ownername of records to
the RRset level. [RT #37442] |
1783676a64b8e390b756d775ae152509f1d76719 |
|
26-Feb-2015 |
Mukund Sivaraman <muks@isc.org> |
Add a --enable-querytrace configure switch for very verbose query tracelogging (#37520) |
4eefa351cc5549a2cebb45d274f10249e31f6945 |
|
03-Feb-2015 |
Mukund Sivaraman <muks@isc.org> |
Fix a leak of query fetchlock (#38454)
4052. [bug] Fix a leak of query fetchlock. [RT #38454] |
d8890e779c0a74a8738a746f130a4bed6d6954ca |
|
03-Feb-2015 |
Evan Hunt <each@isc.org> |
[master] silence RPZ log messages
4050. [cleanup] Silence occasional spurious "duplicate query" log
messages from RPZ. [RT #38510] |
c110d61b173a68420d19858abb80285be0dc1120 |
|
21-Jan-2015 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
11463c0ac24692e229ec87f307f5e7df3c0a7e10 |
|
20-Jan-2015 |
Evan Hunt <each@isc.org> |
[master] clean up gcc -Wshadow warnings
4039. [cleanup] Cleaned up warnings from gcc -Wshadow. [RT #37381] |
092d3b76db6b93b8029bd7d083e74fc80fb41858 |
|
24-Nov-2014 |
Mark Andrews <marka@isc.org> |
4010. [cleanup] Clear the prefetchable state when initiating a prefetch.
[RT #37399] |
05e448935cb2d6ab08c24257f6536362d3496512 |
|
20-Nov-2014 |
Evan Hunt <each@isc.org> |
[master] refactor max-recursion-queries
- the counters weren't set correctly when fetches timed out.
instead we now pass down a counter object. |
3230429e175dcaafe9c59967124d44c02ca0ccad |
|
18-Nov-2014 |
Evan Hunt <each@isc.org> |
[master] limit recursion depth and iterative queries
4006. [security] A flaw in delegation handling could be exploited
to put named into an infinite loop. This has
been addressed by placing limits on the number
of levels of recursion named will allow (default 7),
and the number of iterative queries that it will
send (default 50) before terminating a recursive
query (CVE-2014-8500).
The recursion depth limit is configured via the
"max-recursion-depth" option. [RT #35780] |
3cc8c7d63040a3eafde2b00e1f60465e7053208a |
|
05-Nov-2014 |
Evan Hunt <each@isc.org> |
[master] fix nxrrset in nxdomain redirection
4000. [bug] NXDOMAIN redirection incorrectly handled NXRRSET
from the redirect zone. [RT #37722] |
79921aeec24a15883cf3c22a15c77837e69a46be |
|
15-Oct-2014 |
Mark Andrews <marka@isc.org> |
3975. [bug] Don't populate or use the bad cache for queries that
don't request or use recursion. [RT #37466] |
947cf282a721b089c1106780f13ae8e6298bddb1 |
|
10-Sep-2014 |
Mark Andrews <marka@isc.org> |
3949. [experimental] Experimental support for draft-andrews-edns1 by sending
EDNS(1) queries (define DRAFT_ANDREWS_EDNS1 when
building). Add support for limiting the EDNS version
advertised to servers: server { edns-version 0; };
Log the EDNS version received in the query log.
[RT #35864] |
1aa8b80767f9be0db2df149d7a8236e48d1acf67 |
|
05-Sep-2014 |
Evan Hunt <each@isc.org> |
[master] fix warnings/doc errors
- possible use before assignment in query.c
- missing <varlistentry> in ARM |
a8783019814daa36dd57afe3f527462822834c3b |
|
04-Sep-2014 |
Evan Hunt <each@isc.org> |
[master] servfail cache
3943. [func] SERVFAIL responses can now be cached for a
limited time (configured by "servfail-ttl",
default 10 seconds, limit 30). This can reduce
the frequency of retries when an authoritative
server is known to be failing, e.g., due to
ongoing DNSSEC validation problems. [RT #21347] |
25c5d8e89efc6e6299a351eabcf55ac7e6005ebf |
|
29-Aug-2014 |
Mark Andrews <marka@isc.org> |
#include isc/print.h> |
f5c24a7f48cd68337c21dea47a448ae2ff2ccb8c |
|
29-Aug-2014 |
Evan Hunt <each@isc.org> |
[master] add better servfail logging
3937. [func] Added some debug logging to better indicate the
conditions causing SERVFAILs when resolving.
[RT #35538] |
cef76ee5bd845a80e06da934edce4225bdba22a1 |
|
22-Aug-2014 |
Mark Andrews <marka@isc.org> |
3921. [bug] AD was inappopriately set on RPZ responses. [RT #36833] |
25633bca239d1be056233c6e95f9ff86b1aa8193 |
|
01-Aug-2014 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
3a55d4352767acb4e0572aabfa917610001f5c9c |
|
31-Jul-2014 |
Mark Andrews <marka@isc.org> |
3904. [func] Add the RPZ SOA to the additional section. [RT36507] |
b8a9632333a92d73a503afe1aaa7990016c8bee9 |
|
19-Jun-2014 |
Evan Hunt <each@isc.org> |
[master] complete NTA work
3882. [func] By default, negative trust anchors will be tested
periodically to see whether data below them can be
validated, and if so, they will be allowed to
expire early. The "rndc nta -force" option
overrides this behvaior. The default NTA lifetime
and the recheck frequency can be configured by the
"nta-lifetime" and "nta-recheck" options. [RT #36146] |
8d8f9f7f86a33a155dd74b9b2c1317afca555d54 |
|
11-Jun-2014 |
Evan Hunt <each@isc.org> |
[master] suppress unnecessary db lookups in DLZ redirect zones
3876. [bug] Improve efficiency of DLZ redirect zones by
suppressing unnecessary database lookups. [RT #35835] |
44b0e0b1d5bdb103062d6bdeaa5c649c40e2541d |
|
30-May-2014 |
Mark Andrews <marka@isc.org> |
More changes for:
3864. [bug] RPZ didn't work well when being used as forwarder.
[RT #36060] |
3d751891410f9892ca1c1deba2f7d8556ae91b0c |
|
29-May-2014 |
Mark Andrews <marka@isc.org> |
3864. [bug] RPZ didn't work well when being used as forwarder.
[RT #36060] |
800d25b8482c52487b4dab53cb10fa74061f1e94 |
|
29-May-2014 |
Mark Andrews <marka@isc.org> |
3863. [bug] The "E" flag was missing from the query log as a
unintended side effect of code rearrangement to
support EDNS EXPIRE. [RT #36117] |
2c172a42b39da5913fc6b2c0d3ce987c206991fa |
|
11-May-2014 |
Mark Andrews <marka@isc.org> |
3842. [bug] Adjust RRL log-only logging category. [RT #35945] |
b36fc8294e1328912b940899d436c60986c92435 |
|
05-May-2014 |
Mark Andrews <marka@isc.org> |
3837. [security] A NULL pointer is passed to query_prefetch resulting
a REQUIRE assertion failure when a fetch is actually
initiated. [ RT #35899]
Squashed commit of the following:
commit 7f4e1f3917d743089c42cc52ec2c0eea598d2c00
Author: Mukund Sivaraman <muks@isc.org>
Date: Sun May 4 22:34:34 2014 +0530
Fix a comment
commit 6a35a6a2346013fa8e3798b9b680d8a3031fcb03
Author: Mark Andrews <marka@isc.org>
Date: Sun May 4 23:34:25 2014 +1000
pass the correct name to query_prefetch |
0dc0b029e9aecc6e2139109091ea68cc6aff7081 |
|
30-Apr-2014 |
Evan Hunt <each@isc.org> |
[master] log query errors at info when query logging is on
3830. [func] When query logging is enabled, log query errors at
the same level ('info') as the queries themselves.
[RT #35844] |
76884179fd3ba491db80a285c752671025f74730 |
|
28-Apr-2014 |
Mark Andrews <marka@isc.org> |
3823. [func] Log the rpz cname target when rewriting. [RT #35667] |
aefb3e308ba01ad47a3d3aaadf77a5edd4261cb9 |
|
25-Apr-2014 |
Evan Hunt <each@isc.org> |
[master] better DDNS in DLZ; mysqldyn
3821. [contrib] Added a new "mysqldyn" DLZ module with dynamic
update and transaction support. Thanks to Marty
Lee for the contribution. [RT #35656]
3820. [func] The DLZ API doesn't pass the database version to
the lookup() function; this can cause DLZ modules
that allow dynamic updates to mishandle prerequisite
checks. This has been corrected by adding a
'dbversion' field to the dns_clientinfo_t
structure. [RT #35656] |
e29c2b3903569a5101eac21e7210174e56957eca |
|
07-Mar-2014 |
Evan Hunt <each@isc.org> |
[master] fix misuses of isc__buffer functions, update comment |
a2fd1de97d9ff685697aadba7f67a450557b0a06 |
|
06-Mar-2014 |
Evan Hunt <each@isc.org> |
[master] fix DLZ coredump
3777. [bug] EDNS EXPIRE code could dump core when processing
DLZ queries. [RT #35493] |
20a96edbf9894e327a99f21acf3571422df5c7b0 |
|
21-Feb-2014 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
80b37f909aba5f8e7d74c10a9c71faef4315e77e |
|
20-Feb-2014 |
Mark Andrews <marka@isc.org> |
increment dns_nsstatscounter_recursclients when prefetching |
47cb20eae1ddb4ffc5957c78ef9ab753b2400a28 |
|
20-Feb-2014 |
Mark Andrews <marka@isc.org> |
add EDNS EXPIRE processing on ixfr and axfr out |
16134801ce8fffbb6c42bb54d544c3397a45ad06 |
|
20-Feb-2014 |
Mark Andrews <marka@isc.org> |
3750. [experimental] Partially implement EDNS EXPIRE option as described
in draft-andrews-dnsext-expire-00. Retrivial of
remaining time to expiry from slave zones is supported.
EXPIRE uses an experimental option code (65002) and
is subject to change. [RT #35416] |
e0c6a3944d4f5b7ed0ede17ab560898cd0b825e1 |
|
19-Feb-2014 |
Mark Andrews <marka@isc.org> |
silence Function returns no value |
b5f6271f4daf1e54501af2cb7dd278d7e8003d65 |
|
18-Feb-2014 |
Mark Andrews <marka@isc.org> |
3744. [experimental] SIT: send and process Source Identity Tokens
(which are similar to DNS Cookies by Donald Eastlake)
and are designed to help clients detect off path
spoofed responses and for servers to detect legitimate
clients.
SIT use a experimental EDNS option code (65001).
SIT can be enabled via --enable-developer or
--enable-sit. It is on by default in Windows.
RRL processing as been updated to know about SIT with
legitimate clients not being rate limited. [RT #35389] |
31f6244cc25ab0f8937edc26dbb26ba4f6a01f19 |
|
16-Feb-2014 |
Evan Hunt <each@isc.org> |
[master] tcp and udp stats counters
3739. [func] Added per-zone stats counters to track TCP and
UDP queries. [RT #35375] |
fef19ce621755c6c1242daa1294304208b540989 |
|
13-Jan-2014 |
Mark Andrews <marka@isc.org> |
fix for pre C99 compiler |
2cf1d5b0986d38e60db88a7b2360798e539d7636 |
|
13-Jan-2014 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
fb756ba3047770957173ba546257ca43af7ba3e4 |
|
12-Jan-2014 |
Mark Andrews <marka@isc.org> |
3703. [func] Prefetch about to expire records if they are queried
for, see prefetch option for details. [RT #35041] |
431a83fb29482c5170b3e4026e59bb14849a6707 |
|
10-Jan-2014 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
e851ea826066ac5a5b01c2c23218faa0273a12e8 |
|
09-Jan-2014 |
Evan Hunt <each@isc.org> |
[master] replace memcpy() with memmove().
3698. [cleanup] Replaced all uses of memcpy() with memmove().
[RT #35120] |
fa467e60c590072fd6848522456eb2cc41582c59 |
|
20-Dec-2013 |
Mark Andrews <marka@isc.org> |
3693. [security] memcpy was incorrectly called with overlapping
ranges resulting in malformed names being generated
on some platforms. This could cause INSIST failures
when serving NSEC3 signed zones. [RT #35120] |
225146b2c8c7de8dcff979841b56b15aef8aded2 |
|
18-Nov-2013 |
Mark Andrews <marka@isc.org> |
3674. [bug] RPZ zeroed ttls if the query type was '*'. [RT #35026] |
9a7f89279ed96c0f8cf17f05e090b147a7694ddf |
|
22-Sep-2013 |
Mark Andrews <marka@isc.org> |
remove unnecessary assignment |
9fa2a0deed3b880f3bf04d4f615c13a0d67cc0ce |
|
21-Sep-2013 |
Mark Andrews <marka@isc.org> |
3652. [bug] Address bug with rpz-drop policy. [RT #34816] |
5bdb12d2c6924ab6204d8b269754e887cf415652 |
|
09-Sep-2013 |
Mark Andrews <marka@isc.org> |
assignment not read |
997c2c5116927bab77284c24c3bd0d7f646da5ee |
|
19-Aug-2013 |
Mark Andrews <marka@isc.org> |
3636. [bug] Automatic empty zones now behave better with
forward only "zones" beneath them. [RT #34583] |
06ace051e7522b153b487581c9439fc8c162fb18 |
|
15-Aug-2013 |
Mark Andrews <marka@isc.org> |
3631. [bug] Remove spurious warning about missing signatures when
qtype is SIG. [RT #34600] |
d640b4a0ab9dec252749793f78a1ed1e8551ea19 |
|
25-Jul-2013 |
Evan Hunt <each@isc.org> |
[master] perf: eliminate cache stats attach/detach
3622. [tuning] Eliminate an unnecessary lock when incrementing
cache statistics. [RT #34339] |
960958c610db801f1c89d82281a1fbaa937e4011 |
|
13-Jul-2013 |
Evan Hunt <each@isc.org> |
[master] silence warning |
50464a33981af03d897f3fa3effdbd97396025d6 |
|
13-Jul-2013 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
421d4a06479e61fbdc35087f3c4abc9fe65ad72a |
|
12-Jul-2013 |
Evan Hunt <each@isc.org> |
[master] rpz work
3620. [func] Added "rpz-client-ip" policy triggers, enabling
RPZ responses to be configured on the basis of
the client IP address; this can be used, for
example, to blacklist misbehaving recursive
or stub resolvers. [RT #33605]
3619. [bug] Fixed a bug in RPZ with "recursive-only no;"
[RT #33776] |
89be55dc9040b119fd85bb33e7dc97d2ad454c6f |
|
08-Jun-2013 |
Evan Hunt <each@isc.org> |
[master] improve RRL handling of deferrals and slipped NXDOMAIN
3590. [bug] When using RRL on recursive servers, defer
rate-limiting until after recursion is complete;
also, use correct rcode for slipped NXDOMAIN
responses. [RT #33604] |
f3c8e48b95996c3020d138b87ee8941da29cc124 |
|
21-May-2013 |
Evan Hunt <each@isc.org> |
[master] change RRL log category 'query-errors'
3575. [func] Changed the logging category for RRL events from
'queries' to 'query-errors'. [RT #33540] |
a6d43d18b1f6164fd144b2fa25ea57f5566b3bf9 |
|
25-Apr-2013 |
Evan Hunt <each@isc.org> |
[master] fixed several RRL issues
3554. [bug] RRL failed to correctly rate-limit upward
referrals and failed to count dropped error
responses in the statistics. [RT #33225] |
73b3019760ed11af0598135c72739f4a98c95fe8 |
|
28-Mar-2013 |
Evan Hunt <each@isc.org> |
[master] address windows build warnings |
cab2b0d941d95ea9b59e8034826452de730c0d3e |
|
27-Feb-2013 |
Mark Andrews <marka@isc.org> |
remove unreachable line |
94315060c2b0d9deafabe72d6a0482405fd9d377 |
|
25-Feb-2013 |
Evan Hunt <each@isc.org> |
[master] RPZ speedup (phase 2, multiple RPZ's)
3495. [func] Support multiple response-policy zones, while
improving RPZ performance. [RT #32476] |
55e5c51e661e23e24573db84114a3837817745c9 |
|
25-Feb-2013 |
Evan Hunt <each@isc.org> |
[master] DNS RRL
3494. [func] DNS RRL: Blunt the impact of DNS reflection and
amplification attacks by rate-limiting substantially-
identical responses. [RT #28130] |
71f8edccba553c4ed4988dd12ac877564e4987d1 |
|
17-Jan-2013 |
Evan Hunt <each@isc.org> |
[master] fix DNS64 with RPZ-remapped A records
3468. [security] RPZ rules to generate A records (but not AAAA records)
could trigger an assertion failure when used in
conjunction with DNS64. [RT #32141] |
48019314431389cca5f8eba7ee9aa5bc08a67f4e |
|
10-Jan-2013 |
Mark Andrews <marka@isc.org> |
3461. [bug] Negative responses could incorrectly have AD=1
set. [RT #32237] |
6fe42ff85ced80bd2ccc49b429d36831b5f2a5b9 |
|
05-Jan-2013 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
222d38735f97f771054e223b03f84c5858252332 |
|
04-Jan-2013 |
Evan Hunt <each@isc.org> |
[master] allow-query-on works now
3448. [bug] The allow-query-on ACL was not processed correctly.
[RT #29486] |
abff0f462a758383d012887d3a97da4dac0c5a94 |
|
06-Dec-2012 |
Evan Hunt <each@isc.org> |
[master] pass client info to DLZ findzone method
3434. [bug] Pass client info to the DLZ findzone() entry
point in addition to lookup(). This makes it
possible for a database to answer differently
whether it's authoritative for a name depending
on the address of the client. [RT #31775] |
2b8bed6681d1541474f022586cbe728dfce36880 |
|
06-Dec-2012 |
Evan Hunt <each@isc.org> |
[master] multiple-dlz/dlz-nxdomain
3432. [func] Multiple DLZ databases can now be configured.
DLZ databases are searched in the order configured,
unless set to "search no", in which case a
zone can be configured to be retrieved from a
particular DLZ database by using a "dlz <name>"
option in the zone statement. DLZ databases can
support type "master" and "redirect" zones.
[RT #27597] |
68ba0155abd6be12dc211527e5420a7f124e0571 |
|
30-Nov-2012 |
Mark Andrews <marka@isc.org> |
silence clang --analyze warning |
aecadaf3b1bbbe0bd58f703989baf38eedd0ffca |
|
14-Nov-2012 |
ckb <ckb@isc.org> |
3418. [func] New XML schema (version 3.0) for the statistics channel
adds query type statistics at the zone level, and
flattens the XML tree and uses compressed format to
optimize parsing. Includes new XSL that permits
charting via the Google Charts API on browsers that
support javascript in XSL. The old XML schema has been
deprecated. [RT #30023]
3417. [placeholder] |
4786e693a7c4b41ba4554f06a2f6d16c74017f15 |
|
01-Nov-2012 |
Mark Andrews <marka@isc.org> |
3413. [func] Record the number of DNS64 AAAA RRsets that have been
synthesized. [RT #27636]
Squashed commit of the following:
commit b375c287a3d95ed2eb29977d4347d845f393add7
Author: Evan Hunt <each@isc.org>
Date: Wed Oct 24 21:28:04 2012 -0700
[rt27636] add dns64 responses stat counter |
41bbb34bc20f189af62e7047ce42822615417f15 |
|
03-Oct-2012 |
Evan Hunt <each@isc.org> |
fix coverity issues
3388. [bug] Fixed several Coverity warnings. [RT #30996] |
c872f39a00e8209ff6412b3383ed9099ac3e14a7 |
|
27-Sep-2012 |
Evan Hunt <each@isc.org> |
fixed an exploitable hang bug
3383. [security] A certain combinations of records in the RBT could
cause named to hang while populating the additional
section of a response. [RT #31090] |
4118cd4276c3f53f9f6f0133688e05e52d70336b |
|
31-Aug-2012 |
Mark Andrews <marka@isc.org> |
3371. [bug] AD=1 should behave like DO=1 when deciding whether to
add NS RRsets to the additional section or not.
[RT #30479] |
953692fa1e307b7325e383302d82b711d164a9d5 |
|
26-Jul-2012 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
e7857b5ee05414961bb11f9e57f654163fae6acb |
|
26-Jul-2012 |
ckb <ckb@isc.org> |
3356. [bug] Cap the TTL of signed RRsets when RRSIGs are
approaching their expiry, so they don't remain
in caches after expiry. [RT #26429] |
7865ea9545f28f12f046b32d24c989e8441b9812 |
|
14-Jun-2012 |
Mark Andrews <marka@isc.org> |
3339. [func] Allow the maximum supported rsa exponent size to be specified: "max-rsa-exponent-size <value>;" [RT #29228] |
7a440c4300b1a2712e18100772263c97ce1ab9d6 |
|
01-Jun-2012 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63 |
|
31-May-2012 |
Vernon Schryver <vjs@isc.org> |
Squashed commit of the following:
commit aea73609ac5d41ed091360e94370798965f28f05
commit eef7f44c57a060b24a426eb8888e16176a0a69b1
commit a88a26d864ad399fa2d40e3b9659b4d26f454ca1
commit 1b90d59568e7e3b65690c6bd075cf4d60b03e454
Merge: 74d8f73 cd02924
commit 74d8f73ed553bb64a305e284905762f7ff0029aa
commit 9a59ef6bbd4befe91e5691e8b85afe1cb7ab0706
commit c63606a53b4f1bb7066b37d3cfe588e9dc21a119
commit 2c392a840c8838455d144ce163bd873bee400c97
commit 0241f53563e6e7bed462a883d98a8931f01e0980
commit 79fe22b5d6f04bdaa3073cf54d41952194e879e1
commit 351b3049625f2edd39729dd85413e961b97d4b3b
commit 7207674fc77c9a10d84c0cb94e36d1c09bb31459
commit 543ad34cf08f901c20b438c9d2f45482cff13d5e
commit fc45b99ce4438627fdcbeb4365695ba0065fa46f
commit c425207f57e0a5157372aa7edbb79b13170563e5
commit ef8c5e23ca284e0ea02f69ce1f356d537c19d93b
commit ba0d4e3aa51efe412cfa1d031651f949442d1802
commit 41c7969c7cb6884b93011f7ace3fd9522efc021e
and more from CVS
for rt26172
Add
- optional "recursive-only yes|no" to the response-policy statement
- optional max-policy-ttl to limit the lies that "recursive-only no"
can introduce into resolvers' caches
- test that queries with RD=0 are not rewritten by default
- performance smoke test
Change encoding of PASSTHRU action to "rpz-passthru".
(The old encoding is still accepted.)
Fix rt26180 assert botch in zone_findrdataset() in this branch
as well.
Fix missing signatures on NOERROR results despite RPZ hits
when there are signatures and the client asks for DNSSEC, |
633c5dc507fa3133a6d49a55cfe84bf4fd522c72 |
|
15-May-2012 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
d878b8d87c3f46a25ccae9f5cfe6e39af67562e0 |
|
14-May-2012 |
Evan Hunt <each@isc.org> |
merged filter-aaaa-on-v6 (ATT SoW)
3327. [func] Added 'filter-aaaa-on-v6' option; this is similar
to 'filter-aaaa-on-v4' but applies to IPv6
connections. (Use "configure --enable-filter-aaaa"
to enable this option.) [RT #27308] |
dd2a0a6d2dec1c23787351e51b434a838dec5603 |
|
14-May-2012 |
Evan Hunt <each@isc.org> |
Merge statistics code (ATT SoW, rt24117)
This includes the following changes:
3326. [func] Added task list statistics: task model, worker
threads, quantum, tasks running, tasks ready.
[RT #27678]
3325. [func] Report cache statistics: memory use, number of
nodes, number of hash buckets, hit and miss counts.
[RT #27056]
3324. [test] Add better tests for ADB stats [RT #27057]
3323. [func] Report the number of buckets the resolver is using.
[RT #27020]
3322. [func] Monitor the number of active TCP and UDP dispatches.
[RT #27055]
3321. [func] Monitor the number of recursive fetches and the
number of open sockets, and report these values in
the statistics channel. [RT #27054]
3320. [func] Added support for monitoring of recursing client
count. [RT #27009]
3319. [func] Added support for monitoring of ADB entry count and
hash size. [RT #27057] |
85fcd0b9b2d80be4646187d7094e5644a52e3263 |
|
28-Mar-2012 |
Mark Andrews <marka@isc.org> |
3299. [bug] Make SDB handle errors from database drivers better.
[RT #28534] |
207845805eb591b77ffbd99735617cab7e2ed804 |
|
07-Mar-2012 |
Evan Hunt <each@isc.org> |
set $Id$ |
2d7f41d66caf648e9f178f0cfd78b097be61c92c |
|
06-Mar-2012 |
Evan Hunt <each@isc.org> |
Revert "Re-created rt27597a for ongoing DLZ work"
This reverts commit d731ee9121c3864839c3bdcd3b7ee603ec3999ff. |
d731ee9121c3864839c3bdcd3b7ee603ec3999ff |
|
05-Mar-2012 |
Evan Hunt <each@isc.org> |
Re-created rt27597a for ongoing DLZ work |
632c0f1e91cd1884c6c9c7b51f7189a1e9c6ea17 |
|
05-Mar-2012 |
Evan Hunt <each@isc.org> |
Revert accidental merge of unfinished DLZ work |
954501715d5cfa8f98171161bed80f962d8dede6 |
|
04-Mar-2012 |
Evan Hunt <each@isc.org> |
checkpoint: multiple-DLZ functionality
- multiple DLZ's can be specified, including multiple DLZ's using
the same driver; e.g., two different back-ends both loaded by the
dlopen driver
- new "search" option can be specified in a DLZ indicating whether
this DLZ database should be searched for unknown zones. The
default is "yes". If "no", then the zone can only be found by
named if it's registered in the zone table, which happens if the
zone is configured for dynamic updates, or if "dlz <dlzname>" is
specified in the zone statement. (The latter functionality is
incomplete in this commit). |
81274f4b08b04eade0936cd32a4ba56281d7c2d2 |
|
07-Feb-2012 |
Mark Andrews <marka@isc.org> |
3280. [bug] Potential double free of a rdataset on out of memory
with DNS64. [RT #27762] |
41f11644387cf54e4affe496c0532165ac41eb87 |
|
01-Feb-2012 |
Automatic Updater <source@isc.org> |
update copyright notice |
93143fd81acd86e594bac20c6c58b930dfe63a80 |
|
31-Jan-2012 |
Evan Hunt <each@isc.org> |
3273. [bug] AAAA responses could be returned in the additional
section even when filter-aaaa-on-v4 was in use.
[RT #27292] |
c19cfefe7e345c37ef3bb98b0db2d14fe7b1d583 |
|
07-Jan-2012 |
Evan Hunt <each@isc.org> |
3262. [bug] Signed responses were handled incorrectly by RPZ.
[RT #27316] |
f76bddd50b13009d5c0ed70cb6ab8f9cf427660e |
|
05-Jan-2012 |
Automatic Updater <source@isc.org> |
update copyright notice |
56c9fcf07580457442b80ac32bdb7c07aa0df870 |
|
04-Jan-2012 |
Evan Hunt <each@isc.org> |
3260. [bug] "rrset-order cyclic" could appear not to rotate
for some query patterns. [RT #27170/27185] |
7c6a1a11fa6342bd14f2804cd7753bdb1966d53d |
|
16-Nov-2011 |
Evan Hunt <each@isc.org> |
3218. [security] Cache lookup could return RRSIG data associated with
nonexistent records, leading to an assertion
failure. [RT #26590] |
7b4b6f361b2fb2291c2019b377a9c0c8e80cfd6b |
|
28-Oct-2011 |
Mark Andrews <marka@isc.org> |
3186. [bug] Version/db mis-match in rpz code. [RT #26180] |
ada40193c85276867c6904545601c7c01e3236c3 |
|
20-Oct-2011 |
Mark Andrews <marka@isc.org> |
3175. [bug] Fix how DNSSEC positive wildcard responses from a
NSEC3 signed zone are validated. Stop sending a
unnecessary NSEC3 record when generating such
responses. [RT #26200] |
304a539c5966697827f2a021303e634aee98503d |
|
14-Oct-2011 |
Automatic Updater <source@isc.org> |
update copyright notice |
9fee08f655527a5dd849b171daeeee1dbbccca76 |
|
13-Oct-2011 |
Vernon Schryver <vjs@isc.org> |
Commit rt25172 changes to HEAD including
- fix precedence among competing rules
- improve ARM text including documenting rule precedence
- try to rewrite CNAME chains until first hit
- new "rpz" logging channel
- same fix for "NS ." as in RT 24985 |
ea68e8eba9f1c853f38eb747ee8c66dcc27f2233 |
|
13-Oct-2011 |
Automatic Updater <source@isc.org> |
update copyright notice |
af850c4120c5bee9462de4def85d0b4c1b583963 |
|
13-Oct-2011 |
Mark Andrews <marka@isc.org> |
3168. [bug] Nxdomain redirection could trigger a assert with
a ANY query. [RT #26017] |
0e11ca0f0bdeb8eface941671926a9f4d2fc2685 |
|
12-Oct-2011 |
Automatic Updater <source@isc.org> |
update copyright notice |
793814f80703afdd69b59ade91e63efa81ae4178 |
|
11-Oct-2011 |
Evan Hunt <each@isc.org> |
3164. [func] Enable DLZ modules to retrieve client information,
so that responses can be changed depending on the
source address of the query. [RT #25768] |
ca894e53b544de8df0084f2d9d948770a2556ae1 |
|
03-Sep-2011 |
Automatic Updater <source@isc.org> |
update copyright notice |
9e4afc9b39fe5c5e44798944b72d6686a5be435c |
|
02-Sep-2011 |
Evan Hunt <each@isc.org> |
3151. [bug] Queries for type RRSIG or SIG could be handled
incorrectly. [RT #21050] |
475b1ed9cced1f92ce34bc2e59b3065dae48f366 |
|
09-Jun-2011 |
Mark Andrews <marka@isc.org> |
3126. [security] Using DNAME record to generate replacements caused
RPZ to exit with a assertion failure. [RT #23766] |
b64e3b8358177cbef5db7b99fc9ddc2efe48eed7 |
|
09-Jun-2011 |
Mark Andrews <marka@isc.org> |
3125. [security] Using wildcard CNAME records as a replacement with
RPZ caused named to exit with a assertion failure.
[RT #24715] |
6de9744cf9c64be2145f663e4051196a4eaa9d45 |
|
09-Jun-2011 |
Evan Hunt <each@isc.org> |
3124. [bug] Use an rdataset attribute flag to indicate
negative-cache records rather than using rrtype 0;
this will prevent problems when that rrtype is
used in actual DNS packets. [RT #24777]
3123. [security] Change #2912 exposed a latent flaw in
dns_rdataset_totext() that could cause named to
crash with an assertion failure. [RT #24777] |
c0984ac8bdb9ab8812374651bbabcfeb5873eb38 |
|
20-May-2011 |
Mark Andrews <marka@isc.org> |
3115. [bug] Named could fail to return requested data when
following a CNAME that points into the same zone.
[RT #2445] |
46ce2f7b604dc0b4e6673b8bd1f0f264486aa32e |
|
28-Apr-2011 |
Automatic Updater <source@isc.org> |
update copyright notice |
76db58eb818dc4839fa816df6a1a1ecb2c7a6bd0 |
|
27-Apr-2011 |
Evan Hunt <each@isc.org> |
3100. [security] Certain response policy zone configurations could
trigger an INSIST when receiving a query of type
RRSIG. [RT #24280] |
7a2173839c5ca103090431f36709fde99b599097 |
|
20-Apr-2011 |
Evan Hunt <each@isc.org> |
3099. [test] "dlz" system test now runs but gives R:SKIPPED if
not compiled with --with-dlz-filesystem. [RT #24146]
3098. [bug] DLZ zones were answering without setting the AA bit.
[RT #24146] |
a8e6a8cd6ceb5970bc5eab8d1d29cffb0e0a7c1a |
|
18-Mar-2011 |
Francis Dupont <fdupont@isc.org> |
fix too long with dname error |
0874abad14e3e9ecfc3dc1a1a2b9969f2f027724 |
|
11-Mar-2011 |
Mark Andrews <marka@isc.org> |
3069. [cleanup] Silence warnings messages from clang static analysis.
[RT #20256] |
422009fe5b15e31e7f5d09212bd1480121a1464e |
|
10-Mar-2011 |
Evan Hunt <each@isc.org> |
3066. [func] The DLZ "dlopen" driver is now built by default,
no longer requiring a configure option. To
disable it, use "configure --without-dlopen".
Driver also supported on win32. [RT #23467] |
45caada8cb80fdc96a2f530ade82118c76c2894e |
|
24-Feb-2011 |
Automatic Updater <source@isc.org> |
update copyright notice |
0e507dbb816575e6220fe309e8ada68897ffcdbe |
|
23-Feb-2011 |
Mark Andrews <marka@isc.org> |
2039. [func] Redirect on NXDOMAIN support. [RT #23146] |
57b403c1e9cd8f814c7dbf1808f6cd8d2efb7aea |
|
18-Feb-2011 |
Scott Mann <smann@isc.org> |
Fix prz SERVFAILs after failed zone transfers (RT23246). |
c1ee8bb4ba3e9ab1463403ed685729631de406b1 |
|
03-Feb-2011 |
Mark Andrews <marka@isc.org> |
3013. [bug] The DNS64 ttl was not always being set as expected.
[RT #23034] |
cc5e0baaef40e8df283558b9e1700f243168abd3 |
|
14-Jan-2011 |
Mark Andrews <marka@isc.org> |
arguements out of order |
9cee5bb02863bf191e12cd4297adabf1971020de |
|
13-Jan-2011 |
Automatic Updater <source@isc.org> |
update copyright notice |
87708bde16713bc02ff2598f4a82f98c699a2f2d |
|
13-Jan-2011 |
Mark Andrews <marka@isc.org> |
3008. [func] Response policy zones (RPZ) support. [RT #21726] |
d9ad0a55bb198caecf13c79f7e9a402fba8e68eb |
|
24-Dec-2010 |
Evan Hunt <each@isc.org> |
3000. [bug] More TKEY/GSS fixes:
- nsupdate can now get the default realm from
the user's Kerberos principal
- corrected gsstest compilation flags
- improved documentation
- fixed some NULL dereferences
[RT #22795] |
743bbdc18f839499862e4fb28ec32f607b1632dc |
|
16-Dec-2010 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
2947. [func] Add new zone type "static-stub". It's like a stub
zone, but the nameserver names and/or their IP
addresses are statically configured. [RT #21474]
(for 9.8.0) |
b8a9a7bef2c3060204c68aef4f3fce04afc1aaee |
|
09-Dec-2010 |
Automatic Updater <source@isc.org> |
update copyright notice |
e334405421979688f2d838805ac67ee47bd62976 |
|
08-Dec-2010 |
Mark Andrews <marka@isc.org> |
2981. [func] Partial DNS64 support (AAAA synthesis). [RT #21991] |
ed83fa75f5657ab2394a701f7ccc169dd9ef48fc |
|
24-Sep-2010 |
Mark Andrews <marka@isc.org> |
2963. [security] The allow-query acl was being applied instead of the
allow-query-cache acl to cache lookups. [RT #22114] |
082f42dcf2f38509a8c842013548f680a6ad06f3 |
|
15-Sep-2010 |
Mark Andrews <marka@isc.org> |
2960. [func] Check that named accepts non-authoritative answers.
[RT #21594] |
8fb412590e03dcf9de775dad1eb7acf320b575ed |
|
07-Sep-2010 |
Mark Andrews <marka@isc.org> |
2953. [bug] Silence spurious "expected covering NSEC3, got an
exact match" message when returning a wildcard
no data response. [RT #21744] |
f1f39b7e07b2665073d976c4d27e30988552b873 |
|
15-Jul-2010 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
2931. [bug] Temporarily and partially disable change 2864
because it would cause inifinite attempts of RRSIG
queries. This is an urgent care fix; we'll
revisit the issue and complete the fix later.
[RT #21710] |
1b67d9b719766459344caededa1e3f670985d311 |
|
27-Jun-2010 |
Automatic Updater <source@isc.org> |
update copyright notice |
810656a187f2c358323bbf679f792f19a46a7973 |
|
26-Jun-2010 |
Mark Andrews <marka@isc.org> |
2925. [bug] Named failed to accept uncachable negative responses
from insecure zones. [RT# 21555] |
b61690dbadef1bd32a84f0289abe862485979239 |
|
23-Jun-2010 |
Automatic Updater <source@isc.org> |
update copyright notice |
48dfee71508886d86fe8fb12f91961b5daf3141d |
|
22-Jun-2010 |
Mark Andrews <marka@isc.org> |
2920. [func] Allow 'filter-aaaa-on-v4' to be applied selectively
to IPv4 clients. New acl 'filter-aaaa' (default any). |
230987e819c3315bf71dcae063feaf7fa372296b |
|
13-Mar-2010 |
Automatic Updater <source@isc.org> |
update copyright notice |
fa2cb8d61d8699709b9fc14ed4f47bb63507b2a5 |
|
12-Mar-2010 |
Mark Andrews <marka@isc.org> |
2864. [bug] Direct SIG/RRSIG queries were not handled correctly.
[RT #21050] |
d8680445d6212d5552ea8a22fd2f9951b11c4b10 |
|
30-Dec-2009 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
2828. [security] Cached CNAME or DNAME RR could be returned to clients
without DNSSEC validation. [RT #20737]
9.4-ESV, 9.5.3, 9.6.2, 9.7.0, 9.8.0(?) |
5d9922e86f3d7f58f4c6b1234962ee4567108830 |
|
28-Nov-2009 |
Vernon Schryver <vjs@isc.org> |
Allow the optional filter-aaaa-on-v4 option in view statements to close #20635 |
d0ca4e90e2dd584db70e403ef92ab08d78d9cd6d |
|
25-Nov-2009 |
Mark Andrews <marka@isc.org> |
2786. [bug] Additional could be promoted to answer. [RT #20663] |
dc9270706619976c47236892c655ba76671c37f1 |
|
24-Nov-2009 |
Mark Andrews <marka@isc.org> |
2783. [func] Return minimal responses to EDNS/UDP queries with a UDP
buffer size of 512 or less. [RT #20654] |
a39a5f4d816ca7d3f43106712ca668dd1ab31d69 |
|
18-Nov-2009 |
Mark Andrews <marka@isc.org> |
2772. [security] When validating, track whether pending data was from
the additional section or not and only return it if
validates as secure. [RT #20438] |
9d856845d63784690e347c8e8dc013f1c830c86d |
|
03-Nov-2009 |
Mark Andrews <marka@isc.org> |
2744. [func] Log if a query was over TCP. [RT #19961] |
5f744ebbdc7caa4b0c700b2aedd7e604a0775dd6 |
|
27-Oct-2009 |
Automatic Updater <source@isc.org> |
update copyright notice |
c8aa7ce70d75d5d8f28f941e3a522c71e948b166 |
|
27-Oct-2009 |
Evan Hunt <each@isc.org> |
2732. [func] Add optional filter-aaaa-on-v4 option, available
if built with './configure --enable-filter-aaaa'.
Filters out AAAA answers to clients connecting
via IPv4. (This is NOT recommended for general
use.) [RT #20339] |
c07236a635d2bbe10ffd03804a2478835c7f7018 |
|
24-Oct-2009 |
Mark Andrews <marka@isc.org> |
2729. [func] When constructing a CNAME from a DNAME use the DNAME
TTL. [RT #20451] |
a12c8549d62d16cfcdf51c9ba9cdf7065191b4f6 |
|
15-Sep-2009 |
Mark Andrews <marka@isc.org> |
2678. [func] Treat DS queries as if "minimal-response yes;"
was set. [RT #20258] |
6beee732e49fb77e92afd613f8634f828b885560 |
|
05-Aug-2009 |
Mark Andrews <marka@isc.org> |
2643. [bug] Stub zones interacted badly with NSEC3 support.
[RT #19777] |
e47809ad55c0d9f9ea0ccc1809d98c40afd2d1e6 |
|
26-Jun-2009 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
cleanup: removed redundant initialization [RT #19866] |
ff380b05fec3746934c74b78bb44f641d2acb359 |
|
07-May-2009 |
Francis Dupont <fdupont@isc.org> |
comment fixes (rt19624) |
cc620f9fdb69c13f1ea12bb1c90bc442f6dc0117 |
|
30-Apr-2009 |
Francis Dupont <fdupont@isc.org> |
Improve a corner source of SERVFAILs [RT #19632] |
56708c6fb441402e0568f8947cdf0ddda40532b1 |
|
13-Mar-2009 |
Mark Andrews <marka@isc.org> |
2576. [bug] NSEC record were not being correctly signed when
a zone transitions from insecure to secure.
Handle such incorrectly signed zones. [RET #19114] |
d36ba0f0caa64111a9a3236944f730dfb3fe5245 |
|
03-Mar-2009 |
Mark Andrews <marka@isc.org> |
2570. [func] Log the destination address the query was sent to.
[RT #19209] |
692ce6c31351481644ce6167cb66edaff68cd493 |
|
16-Feb-2009 |
Mark Andrews <marka@isc.org> |
2551. [bug] Potential Reference leak on return. [RT #19341] |
d9059b0c38bd630c367d81424d72b1308cd74b04 |
|
27-Jan-2009 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
2537. [func] Added more statistics counters including those on socket
I/O events and query RTT histograms. [RT #18802] |
7f1785d0ded8897082abacec5219b27feac755af |
|
17-Jan-2009 |
Francis Dupont <fdupont@isc.org> |
spelling |
d7845fc5ba809d86c204fcfa50ea43f033e4d85e |
|
08-Jan-2009 |
Automatic Updater <source@isc.org> |
update copyright notice |
609f86163a9e80aa5ce0db79b67ee0b6e2a34b34 |
|
07-Jan-2009 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
2525. [func] New logging category "query-errors" to provide detailed
internal information about query failures, especially
about server failures. [RT #19027] |
cb30636abd508693d0095e1956c9d91f87513a51 |
|
16-Dec-2008 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
2516. [bug] glue sort for responses was performed even when not
needed. [RT #19039] |
69f0cf898e3ca5c701fb34d7074cc9897d71f4a0 |
|
08-Dec-2008 |
Mark Andrews <marka@isc.org> |
2507. [func] Log the recursion quota values when killing the
oldest query or refusing to recurse due to quota.
[RT #19022] |
a14aff6984062f01b6d88f485f0a3f68d99fc174 |
|
04-Nov-2008 |
Mark Andrews <marka@isc.org> |
2484. [bug] It was possible to trigger a REQUIRE failure when
adding NSEC3 proofs to the response in
query_addwildcardproof(). [RT #18828] |
24a56e15f7fd09c7ec3b22c380fb04891e23dec4 |
|
15-Oct-2008 |
Mark Andrews <marka@isc.org> |
silence compiler warning |
e6c5224571db729ff179d8085799acc9ba896b0f |
|
02-Oct-2008 |
Mark Andrews <marka@isc.org> |
2460. [bug] Don't call dns_db_getnsec3parameters() on the cache.
[RT #18697] |
6e2871232f7ede047799480370aff444be1f5a13 |
|
24-Sep-2008 |
Automatic Updater <source@isc.org> |
update copyright notice |
6098d364b690cb9dabf96e9664c4689c8559bd2e |
|
24-Sep-2008 |
Mark Andrews <marka@isc.org> |
2448. [func] Add NSEC3 support. [RT #15452] |
1e0209137159d4e16e4459cc8e804d657aad1af1 |
|
26-Aug-2008 |
Mark Andrews <marka@isc.org> |
2427. [func] Treat DNSKEY queries as if "minimal-response yes;"
was set. [RT #18528] |
229442301442890aee044a0df54d3787acd68e65 |
|
29-Apr-2008 |
Mark Andrews <marka@isc.org> |
2364. [bug] named could trigger a assertion when serving a
malformed signed zone. [RT #17828] |
bf64a0d5d9469c42622401bc5d55cf9888eeef44 |
|
23-Apr-2008 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
2361. [bug] "recursion" statistics counter could be counted
multiple times for a single query. [RT #17990] |
8907d8fa04fdaa65baf0bc6b01230b2ebde93106 |
|
03-Apr-2008 |
Mark Andrews <marka@isc.org> |
2355. [func] Extend the number statistics counters available.
[RT #17590] |
a76b380643a22f23a67a9df284e86cd7ef7608c1 |
|
01-Apr-2008 |
Mark Andrews <marka@isc.org> |
2349. [func] Provide incremental re-signing support for secure
dynamic zones. [RT #1091] |
1c3ed2a83d176d9023b51b60dfc96c133f678362 |
|
24-Jan-2008 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
2320. [func] Make statistics couters thread-safe for platforms
that support certain atomic operations. [RT #17466] |
2f012d936b5ccdf6520c96a4de23721dc58a2221 |
|
19-Jan-2008 |
Automatic Updater <source@isc.org> |
update copyright notice |
2678fccde3453facce53f857d95fec30ca4a284f |
|
09-Jan-2008 |
Mark Andrews <marka@isc.org> |
2290. [bug] Let AD in the query signal that the client wants AD
set in the response. [RT #17301] |
1da14e066c23245c255dedb311d5a9cf0e5bb667 |
|
03-Jan-2008 |
Automatic Updater <source@isc.org> |
update copyright notice |
f5d0f495847eb4eb9f0058e73051f855800bee0b |
|
02-Jan-2008 |
Mark Andrews <marka@isc.org> |
2285. [func] Test framework for client memory context management.
[RT #17377] |
05d2776f6fa8e3628555463b06cb43288c9ee68e |
|
26-Sep-2007 |
Evan Hunt <each@isc.org> |
Only set Authentic Data bit if client wants DNSSEC, per RFC 3655. [RT #17175] |
ec5347e2c775f027573ce5648b910361aa926c01 |
|
19-Jun-2007 |
Automatic Updater <source@isc.org> |
update copyright notice |
f3139b9d763cbfd3f8dbf1062191a688ed5195e4 |
|
18-May-2007 |
Mark Andrews <marka@isc.org> |
2187. [bug] query_addds(), query_addwildcardproof() and
query_addnxrrsetnsec() should take a version
arguement. [RT #16368] |
cd1e58c339b2a6709d543a525de0c995bf8b5868 |
|
30-Apr-2007 |
Mark Andrews <marka@isc.org> |
2172. [bug] query_addsoa() was being called with a non zone db.
[RT #16834] |
819b98479eff49ed93f57f4d65eb0ffe72136adc |
|
29-Mar-2007 |
Mark Andrews <marka@isc.org> |
2165. [func] Allow the destination address of a query to determine
if we will answer the query or recurse.
allow-query-on, allow-recursion-on and
allow-query-cache-on. [RT #16291] |
8943ff626fa337419cbffad6a4a910c7d99509f4 |
|
06-Feb-2007 |
Mark Andrews <marka@isc.org> |
2130. [func] Log if CD or DO were set. [RT #16640] |
f36c85c3cee0b7022d6a99077fab2e5afc4e357d |
|
08-Jan-2007 |
Mark Andrews <marka@isc.org> |
update copyright notice |
e7d32e57a5c8600893f91ec08f74117c983f8b8d |
|
08-Jan-2007 |
Mark Andrews <marka@isc.org> |
2125. [bug] dns_zone_getzeronosoattl() REQUIRE failure if DLZ
was defined. [RT #16574] |
1a8efeab76d34327a699894a6a404f97b341c57a |
|
07-Dec-2006 |
Mark Andrews <marka@isc.org> |
2110. [bug] "minimal-response yes;" interacted badly with BIND 8
priming queries. [RT #16491] |
f34249bb28093d6589196cd00ca040f503a65e2b |
|
31-Aug-2006 |
Mark Andrews <marka@isc.org> |
2066. [security] Handle SIG queries gracefully. [RT #16300] |
5d51f534831bd648436d22e4faf203fb9abdf3d4 |
|
05-Jun-2006 |
Mark Andrews <marka@isc.org> |
2036. [bug] 'rndc recursing' could cause trigger a REQUIRE.
[RT #16075] |
9a1e8f1baf3e5c53d6b6bfa97d7f60cb3358e404 |
|
26-May-2006 |
Mark Andrews <marka@isc.org> |
2032. [bug] Remove a INSIST in query_addadditional2(). [RT #16074] |
444bbadb54d4a676aa4b20685d3178d7988534b3 |
|
18-May-2006 |
Mark Andrews <marka@isc.org> |
2026. [bug] Rate limit the two recursive client exceeded messages.
[RT #16044] |
82ecc9cd96239649dfeb0a16e31c3b978d0d266a |
|
16-May-2006 |
Mark Andrews <marka@isc.org> |
2016. [bug] Return a partial answer if recursion is not
allowed but requested and we had the answer
to the original qname. [RT #15945] |
d2ef84e07b67e72a4bd9c729c6b8228067d17584 |
|
10-Mar-2006 |
Mark Andrews <marka@isc.org> |
2008. [func] It is now posssible to enable/disable DNSSEC
validation from rndc. This is useful for the
mobile hosts where the current connection point
breaks DNSSEC (firewall/proxy). [RT #15592]
rndc validation newstate [view] |
cfe92110ce4eaf19f7f3255d2961710879bdc9dd |
|
10-Mar-2006 |
Mark Andrews <marka@isc.org> |
2007. [func] It is now possible to explicitly enable DNSSEC
validation. default dnssec-validation no; to
be changed to yes in 9.5.0. [RT #15674] |
d76ed813a51465e5c47d521ab09ea20c06f1428d |
|
03-Mar-2006 |
Mark Andrews <marka@isc.org> |
1999. [func] Implement "rrset-order fixed". [RT #13662] |
45e1bd63587102c3bb361eaca42ee7b714fb3542 |
|
28-Feb-2006 |
Mark Andrews <marka@isc.org> |
1991. [cleanup] The configuration data, once read, should be treated
as readonly. Expand the use of const to enforce this
at compile time. [RT #15813] |
c2b2bd69faabd83143ffb30a132a2f20ebd9abda |
|
02-Feb-2006 |
Mark Andrews <marka@isc.org> |
1977. [bug] Silence noisy log message. [RT #15704] |
a1bc94109313bf4ebb6e6ff655d71d45582d2e43 |
|
05-Jan-2006 |
Mark Andrews <marka@isc.org> |
1959. [func] Control the zeroing of the negative response TTL to
a soa query. Defaults "zero-no-soa-ttl yes;" and
"zero-no-soa-ttl-cache no;". [RT #15460] |
acb4f5236966c2b680b949c1eda826948b24fc23 |
|
05-Jan-2006 |
Mark Andrews <marka@isc.org> |
update copyright notice |
fabf2ee6b01ee06a0de940b83d53cf57f9f79265 |
|
04-Jan-2006 |
Mark Andrews <marka@isc.org> |
1947. [func] It is now possible to configure named to accept
expired RRSIGs. Default "dnssec-accept-expired no;".
Setting "dnssec-accept-expired yes;" leaves named
vulnerable to replay attacks. [RT #14685] |
2674e1a455d4f71de09b2b60e7a8304b9a305588 |
|
30-Nov-2005 |
Mark Andrews <marka@isc.org> |
1940. [bug] Fixed a number of error conditions reported by
Coverity. |
faa4af28cff84d7ac45c1da98e40c00f65a24aa3 |
|
02-Nov-2005 |
Mark Andrews <marka@isc.org> |
1935. [bug] 'acache' was DO sensitive. [RT #15430]
1934. [func] Validate pending NS RRsets, in the authority section,
prior to returning them if it can be done without
requiring DNSKEYs to be fetched. [RT #15430] |
982e072a5000bfc072aee8b34f64112cf54369a5 |
|
13-Oct-2005 |
Mark Andrews <marka@isc.org> |
1927. [bug] Access to soanode or nsnode in rbtdb violated the
lock order rule and could cause a dead lock.
[RT# 15518] |
03e200df5dc283f24a6a349f0b31d3eab26da893 |
|
05-Sep-2005 |
Mark Andrews <marka@isc.org> |
1913. [func] Integrate contibuted DLZ code into named. [RT #11382] |
6b79e960e6ba2991aeb02a6c39af255ab7f06d99 |
|
18-Aug-2005 |
Mark Andrews <marka@isc.org> |
1913. [func] Automatic empty zone creation for D.F.IP6.ARPA and
friends. Note: RFC 1918 zones are not yet covered by
this but are likely to be in a future release.
New options: empty-server, empty-contact,
empty-zones-enable and disable-empty-zone. |
7c678cfe0bd477ded2995b9490d72edf7bc76a84 |
|
11-Aug-2005 |
Mark Andrews <marka@isc.org> |
1910. [cleanup] Don't add DNSKEY records to the additional section. |
7a80d6d5ba8473d38d9d99f97aee42f2aac02835 |
|
28-Jul-2005 |
Mark Andrews <marka@isc.org> |
result was not being assigned. |
8abe06b25d245ab2955d81525bfe6bd29b80908e |
|
27-Jul-2005 |
Mark Andrews <marka@isc.org> |
1905. [bug] Recursive clients soft quota support wasn't working
as expected. [RT #15103] |
fd780f3d47179d68ba2d4661fb9cac9ce1e74928 |
|
27-Jun-2005 |
Mark Andrews <marka@isc.org> |
1891. [func] Limit the number of recursive clients that can be
waiting for a single query (<qname,qtype,qclass>) to
resolve. New options clients-per-query and
max-clients-per-query. |
9b80f3a7c739a99b498a37a711a51b6a88df3a78 |
|
17-Jun-2005 |
Mark Andrews <marka@isc.org> |
1887. [func] Detect duplicates of UDP queries we are recursing on
and drop them. New stats category "duplicates".
[RT #14892] |
361a71b7e6b54d8b5488015d87ae2207e97586fb |
|
16-May-2005 |
Mark Andrews <marka@isc.org> |
typo in comment |
ab023a65562e62b85a824509d829b6fad87e00b1 |
|
27-Apr-2005 |
Rob Austein <sra@isc.org> |
1851. [doc] Doxygen comment markup. [RT #11398] |
b7b6b01a0d0622181a4c28dd60401f0ab2480d00 |
|
16-Mar-2005 |
Mark Andrews <marka@isc.org> |
update copyright |
e50b75e36ca79f84e2c9b2a12f6e28cbf22aaa83 |
|
15-Mar-2005 |
Mark Andrews <marka@isc.org> |
1804. [bug] Ensure that if we are queried for glue that it fits
in the additional section or TC is set to tell the
client to retry using TCP. [RT #10114] |
d0eb2cc33c5db3366a16b1cb0abcca6ec7c8ee3c |
|
21-Dec-2004 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
1526. [func] Implemented "additional section caching (or acache)",
an internal cache framework for additional section
content to improve response performance. Several
configuration options were provided to control the
behavior. |
85609ef4d72c1af28c07ed20df39f71b3276e72f |
|
30-Jun-2004 |
Mark Andrews <marka@isc.org> |
order should be signed. |
5b4a9ac6bfba91acd3ba976e75b14ee065d6f95e |
|
29-Jun-2004 |
Mark Andrews <marka@isc.org> |
1675. [bug] named would sometimes add extra NSEC records to
the authority section. |
4499c6cd5e376c59e06cd0be61f3620a1336bc5f |
|
14-May-2004 |
Mark Andrews <marka@isc.org> |
1635. [bug] Memory leak on error in query_addds(). |
42b48d11ca7b296324d7a8a98cdbf0070b0deb1d |
|
15-Apr-2004 |
Mark Andrews <marka@isc.org> |
hide ((isc_event_t **) (void *)) cast using a macro, ISC_EVENT_PTR. |
50105afc551903541608b11851d73278b23579a3 |
|
10-Mar-2004 |
Mark Andrews <marka@isc.org> |
1589. [func] DNSSEC lookaside validation.
enable-dnssec -> dnssec-enable |
dafcb997e390efa4423883dafd100c975c4095d6 |
|
05-Mar-2004 |
Mark Andrews <marka@isc.org> |
update copyright notice |
2047977ce2dfcfe3a0fa2d638c3242841310fad3 |
|
27-Feb-2004 |
Mark Andrews <marka@isc.org> |
1586. [func] "check-names" is now implemented. |
89783da064f4f9bf2e82d2b3941ddeffe2a8c30d |
|
17-Feb-2004 |
Mark Andrews <marka@isc.org> |
1581. [func] Disable DNSSEC support by default. To enable
DNSSEC specify "enable-dnssec yes;" in named.conf. |
daa73eae708d568d453e6082e0890d35886a9e0f |
|
03-Feb-2004 |
Mark Andrews <marka@isc.org> |
silence punned messages |
73f5c1ff00b20b6b105c95f689fc94f354727a84 |
|
27-Jan-2004 |
Mark Andrews <marka@isc.org> |
stop listening to AD |
2f35edba9c253f6eb236d797045af7b21e9d8fd2 |
|
21-Jan-2004 |
Mark Andrews <marka@isc.org> |
AD is independent of DO/AD |
9cf0970f43a41fe78a78d878f1d45c65f0b733d3 |
|
21-Jan-2004 |
Mark Andrews <marka@isc.org> |
1561. [bug] It was possible to release the same name twice if
named ran out of memory. [RT #10197] |
35541328a8c18ba1f984300dfe30ec8713c90031 |
|
14-Jan-2004 |
Mark Andrews <marka@isc.org> |
1558. [func] New DNSSEC 'disable-algorithms'. Support entry into
child zones for which we don't have a supported
algorithm. Such child zones are treated as unsigned.
1557. [func] Implement missing DNSSEC tests for
* NOQNAME proof with wildcard answers.
* NOWILDARD proof with NXDOMAIN.
Cache and return NOQNAME with wildcard answers. |
e407562a75eb93073bb72089cced150d7ffe4d4f |
|
25-Oct-2003 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
1528. [cleanup] Simplify some dns_name_ functions based on the
deprecation of bitstring labels. |
93d6dfaf66258337985427c86181f01fc51f0bb4 |
|
30-Sep-2003 |
Mark Andrews <marka@isc.org> |
1516. [func] Roll the DNSSEC types to RRSIG, NSEC and DNSKEY. |
1e271ac738152a9f8272835bd524b76b09fc6b09 |
|
30-Jul-2003 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
typo: s/baliwick/bailiwick/
(I hope it is okay to commit this since it is so trivial) |
b0c2141b236832664119c9c7c647359b0c7fead4 |
|
17-Apr-2003 |
Mark Andrews <marka@isc.org> |
1464. [bug] Preserve "out of zone" data for outgoing zone
transfers. [RT #5192] |
0c2509b0b9f9e455fa9d347d08f6ba9abd86d418 |
|
27-Feb-2003 |
Mark Andrews <marka@isc.org> |
1449. [bug] query_addbestns() didn't handle running out of memory
gracefully.
developer: marka
reviewer: explorer |
8b5de9701428e2b5eb50aba96af23dc1186124dd |
|
27-Feb-2003 |
Mark Andrews <marka@isc.org> |
1448. [bug] Handle empty wildcards labels.
developer: marka
reviewer: explorer |
308094e467bffc8d7fe62f2f53bcc991ca221953 |
|
31-Jan-2003 |
Mark Andrews <marka@isc.org> |
arguements reversed |
838d608e6f37038f2fb43980a7a9d6b6a490db36 |
|
21-Jan-2003 |
Mark Andrews <marka@isc.org> |
1422. [func] Log name/type/class when denying a query. [RT #4663] |
421e4cf66e4cba0b0751a34a9c027e39fe0474f9 |
|
18-Jan-2003 |
Mark Andrews <marka@isc.org> |
1416. [bug] Empty node should return NOERROR NODATA, not NXDOMAIN.
[RT #4715]
developer: marka
reviewer: explorer |
c86eed4bdecad9df12f992f9d743dfee3a6c5bdc |
|
14-Jan-2003 |
Mark Andrews <marka@isc.org> |
1410. [func] handle records that live in the parent zone, e.g. DS.
developer: marka
reviewer: explorer |
49a940dc68b30d9e4f9e1bd3c0503d8b90bb1726 |
|
27-Nov-2002 |
Mark Andrews <marka@isc.org> |
1402. [cleanup] A6 has been moved to experimental and is no longer
fully supported.
developer: jinmei
reviewer: marka |
02b772da47ad3abec8ce183560bfe735f3241e96 |
|
11-Sep-2002 |
Mark Andrews <marka@isc.org> |
developer: bwelling
reviewed: marka
Generating a response when the qname matches a wildcard and the type
doesn't exist didn't work; the NXT name was improperly expanded and the
wildcard proof was omitted. |
ab7ce5eb6e9183419e1edd2a8a5ac9c440f8f08a |
|
08-Sep-2002 |
Michael Graff <mgraff@isc.org> |
detach from quota in an error case. I don't know if this is strictly needed,
but it makes sense. It is probably done later as well, but all places
check for the pointer != NULL, so we'll be ok. |
9130ab90fe9b2d5a773e04efafd96753c7eaa14b |
|
06-Sep-2002 |
Mark Andrews <marka@isc.org> |
developer: bwelling
reviewer: marka
DNSSEC wildcard negative proof responses were longer than necessary in
some cases; the existence of a node for which the qname is a subdomain
obscures all shallower wildcards.
That is, query for y.x.foo.com. If the response contains an NXT
at x.foo.com, it's not necessary to prove that there's no wildcard at
*.foo.com, since it wouldn't be matched anyway. |
b6309ed962c4988a314d61742c4fbc4935467d68 |
|
27-Aug-2002 |
Mark Andrews <marka@isc.org> |
developer: jinmei
reviewer: marka
1368. [func] remove support for bitstring labels. |
a2239239cf22c68445bbc85ed5ab663f8bcedc1b |
|
19-Aug-2002 |
Mark Andrews <marka@isc.org> |
reviewed: marka
developer: bwelling
don't attempt to generate a wildcard proof unless the zone is secure. |
95d24aa0d0c34529438d67424dcabad9b8cd9810 |
|
07-Aug-2002 |
Mark Andrews <marka@isc.org> |
prevent assertion failure |
4c342614f80d867bba23e63795ec6ee79dd6395d |
|
06-Aug-2002 |
Mark Andrews <marka@isc.org> |
1354. [bug] Fix DNSSEC wildcard proof for CNAME/DNAME. |
f462e2f372d5e9f19b95a546b4c759b63795522a |
|
25-Jul-2002 |
Mark Andrews <marka@isc.org> |
remove unused label |
b972ff033b3efd52e747683face674dc4d2e431b |
|
24-Jul-2002 |
Mark Andrews <marka@isc.org> |
1338. [func] IPv6 synthesis is now performed for IP6.ARPA bit
string queries. |
fa4e1438016331502e6d665588021aa7ffef8cc2 |
|
24-Jul-2002 |
Mark Andrews <marka@isc.org> |
1337. [func] IPv6 synthesis is now performed for both IP6.ARPA
and IP6.INT nibble queries. |
34c1d0e1b64a75ffb4b17c2e5d8654f77d47ea06 |
|
23-Jul-2002 |
Mark Andrews <marka@isc.org> |
For some zones, querying for a non-DS record, then a DS record would
time out and SERVFAIL. |
edc944d166a7b2a04b17a47f3f470d292eaba922 |
|
23-Jul-2002 |
Mark Andrews <marka@isc.org> |
Change #1331 (Generate DNSSEC wildcard proofs) contained a memory leak. |
c54c1eaf26d5a7fc123c4af3712353156a766df1 |
|
19-Jul-2002 |
Mark Andrews <marka@isc.org> |
1251. [func] Generate DNSSEC wildcard proofs. |
240a5d160ae81853fba789316b3706c619679a7c |
|
17-Jul-2002 |
Mark Andrews <marka@isc.org> |
When returning a delegation from the cache and the DO bit is set, always
try to add a DS. The test for the existence of the sigrdataset was bogus
and crashed the server.
to reproduce:
- create a signed parent & child zone
- query a recursive server for the ns record of the child
- query the recursive server for a name in the child with +norec
bwelling |
8e5017af68416fb01be256340baa9ab9b28d9a31 |
|
11-Jul-2002 |
Mark Andrews <marka@isc.org> |
Recursive quota should apply to tcp queries when the tcp quota is reached. |
475fe52dc33d8d8344e8b1e48fa7bb6643f7ca66 |
|
09-Jul-2002 |
Mark Andrews <marka@isc.org> |
1345. [bug] If the tcpquota was exhausted it was possible to
to trigger a INSIST() failure. |
ac65e45126dda424b5cc9d2865b353dc0ec23e1e |
|
25-Jun-2002 |
Mark Andrews <marka@isc.org> |
1333. [func] Query log now says if the query was signed (S) or
if EDNS was used (E). |
0b09763c354ec91fb352b6b4cea383bd0195b2d8 |
|
17-Jun-2002 |
Mark Andrews <marka@isc.org> |
1328. [func] DS (delegation signer) support. |
7c441b7f4afdedb6e5a99f113a4f926a005fa950 |
|
28-Mar-2002 |
Mark Andrews <marka@isc.org> |
1239. [bug] Under certain circumstances named could continue to
use a name after it had been freed triggering
INSIST() failures. [RT #2614] |
2dd99c098ca162f985b7ef3c8142a964ad8281ae |
|
07-Mar-2002 |
Mark Andrews <marka@isc.org> |
1234. [bug] 'rrset-order' and 'sortlist' should be additive
not exclusive.
1223. [func] 'rrset-order' partially works 'cyclic' and 'random'
are supported. |
a7038d1a0513c8e804937ebc95fc9cb3a46c04f5 |
|
20-Feb-2002 |
Mark Andrews <marka@isc.org> |
copyrights |
b2ca6fd3a8293440b4d263723525396059cf2400 |
|
23-Jan-2002 |
Brian Wellington <source@isc.org> |
#1187 was both unclean and broken. Fix it and clean it up. |
9ab461a6ffed2ae2fe0380c30b69052db7473405 |
|
29-Dec-2001 |
Mark Andrews <marka@isc.org> |
1169. [func] Identify recursive queries in the query log. |
1f1d36a87b65186d9f89aac7f456ab1fd2a39ef6 |
|
30-Nov-2001 |
Andreas Gustafsson <source@isc.org> |
Check return values or cast them to (void), as required by the coding
standards; add exceptions to the coding standards for cases where this is
not desirable |
6b31d9c56874d3bd58b420cbe6cd64be502dbe08 |
|
26-Nov-2001 |
Andreas Gustafsson <source@isc.org> |
1136. [bug] CNAME records synthesized from DNAMEs did not
have a TTL of zero as required by RFC2672
[RT #2129] |
cde2f4dabe028abc1f090c2faaa8f029d32243dc |
|
17-Nov-2001 |
Andreas Gustafsson <source@isc.org> |
style |
773e64ec150c33269e748d96dd95726ed7e0d842 |
|
07-Nov-2001 |
Mark Andrews <marka@isc.org> |
try-edns is no more |
b352902413608d0eb310c4bb45412fa45734afbc |
|
29-Oct-2001 |
Andreas Gustafsson <source@isc.org> |
1077. [func] Do not accept further recursive clients when
the total number of of recursive lookups being
processed exceeds max-recursive-clients, even
if some of the lookups are internally generated.
[RT #1915, #1938] |
2562a84dc59209cc907be09d162b26859bcd8707 |
|
25-Oct-2001 |
Andreas Gustafsson <source@isc.org> |
make error message issued when exceeding the recursive client
quota more meaningful to users |
d352f188cb9e3820054b7451384a3d910619b4a1 |
|
25-Oct-2001 |
Andreas Gustafsson <source@isc.org> |
1072. [bug] The TCP client quota could be exceeded when
recursion occurred. [RT #1937] |
5b4f07a4f3c3d3639ea21728e85efddf25643876 |
|
24-Oct-2001 |
Andreas Gustafsson <source@isc.org> |
redid 1.204 using a subroutine to reduce code duplication and
to eliminate a rather confusing for loop |
b19619260fbd447b0fe3e709b2cc8ae38f27ec3f |
|
24-Oct-2001 |
Mark Andrews <marka@isc.org> |
1069. [func] Kill oldest recursive query when recursive query
quota is exhausted. |
5d4bffa427694a11cc0aa23ab47282dae25c1d26 |
|
23-Oct-2001 |
Mark Andrews <marka@isc.org> |
cancelled fetches wern't being detected. |
f0a464d58a5fbb75267eaab9023154bb8f8fc0ce |
|
23-Oct-2001 |
Mark Andrews <marka@isc.org> |
memory leak on error. |
9066d09c3ef804b997945d34c709e4d2a72d7318 |
|
01-Oct-2001 |
Andreas Gustafsson <source@isc.org> |
Removed all code within #ifdef DNS_OPT_NEWCODES*.
It was the last thing being sanitized out of releases; removing
it makes it possible to eliminate the sanitation process. |
808b909f27c30d36b27efb5aa5ef2d18f83b6d4b |
|
21-Sep-2001 |
Andreas Gustafsson <source@isc.org> |
1014. [bug] Some queries would cause statistics counters to
increment more than once or not at all. [RT #1321] |
2f734e0a7e518c89c2b2b179714b8885b7626b3a |
|
20-Sep-2001 |
Andreas Gustafsson <source@isc.org> |
sizeof style |
1e9efeeb225edd650659fbe6b0efe5fc90691446 |
|
11-Sep-2001 |
Andreas Gustafsson <source@isc.org> |
986. [bug] 'additional-from-auth no;' did not work reliably
in the case of queries answered from the cache.
[RT #1436] |
06a960c681566a163af5b9a655cf36023075ddcb |
|
30-Aug-2001 |
Mark Andrews <marka@isc.org> |
971. [func] 'try-edns' can be use to disable edns on all queries. |
135c1c53b8aa0a7d207faba272fe09e526b175b1 |
|
27-Aug-2001 |
Andreas Gustafsson <source@isc.org> |
don't INSIST() that calling dns_db_find() on the root hints
only binds the rdataset when returning ISC_R_SUCCESS, because that's not the case -
for example, if the root hints are '. 300 IN CNAME .', DNS_R_CNAME is returned and
the rdataset is bound |
89555ff443c8127a533f6c742316c9b1a713cfd5 |
|
27-Aug-2001 |
Mark Andrews <marka@isc.org> |
965. [bug] Using non root hints caused a rbtdb node reference
leak. [RT #1581, RT #1618] |
5465e5f7dd32dd6a959d49d436d4b89eedd6092d |
|
16-Jun-2001 |
Andreas Gustafsson <source@isc.org> |
query_getzonedb() formatted the domain name and class being queried
for at least once for every query to authoritative data, whether or not a log
message was actually printed, which adversely affected query performance |
6cc2f10547b8efd1b5a19cd54ddcc4ca27f7a7a7 |
|
19-May-2001 |
Andreas Gustafsson <source@isc.org> |
indentation |
3242899a56da9c245956979d5be9c92b2cf0ee24 |
|
28-Apr-2001 |
Andreas Gustafsson <source@isc.org> |
818. [bug] Certain pathological responses to ANY queries could
cause an assertion failure. [RT #1218] |
aed6a8ed2e706404ccca0f31faf110fd6efd34e6 |
|
09-Apr-2001 |
Andreas Gustafsson <source@isc.org> |
805. [bug] When using "forward only", missing root hints should
not cause queries to fail. [RT #1143] |
55ddb88e53838693370c213930beda1652b8a583 |
|
04-Apr-2001 |
Brian Wellington <source@isc.org> |
803. [bug] Treat all SIG queries as if they have the CD bit set,
otherwise no data will be returned [RT #749] |
b0390aab30438a13f533cccae9389945214b1421 |
|
20-Mar-2001 |
Brian Wellington <source@isc.org> |
783. [bug] Following CNAMEs could cause an assertion failure
when either using an sdb database or under very
rare conditions. |
fed2c6d18605f022714213129ab3932ef7ef0273 |
|
19-Mar-2001 |
Brian Wellington <source@isc.org> |
80 columns |
d9112843333472bb7700c02a10d18e2b253b2708 |
|
14-Mar-2001 |
Bob Halley <source@isc.org> |
add support for minimal-responses |
02a402afe50f8877729555d3e5d4fb82a10ef9a3 |
|
14-Mar-2001 |
Bob Halley <source@isc.org> |
add response minimization if MINIMIZE_RESPONSES is defined |
40fab71b52b377070c401da2af050f1b9c4502fe |
|
13-Mar-2001 |
Brian Wellington <source@isc.org> |
When querying for ANY at a zone apex, don't add NS records to the authority
section, since they're already in the answer section. |
55b62439233d930152690b9eba97b06d9dc13d23 |
|
11-Mar-2001 |
Mark Andrews <marka@isc.org> |
776. [func] Improved error reporting in denied messages. [RT #252] |
7c058f1c384ebdba74231111f9358cf08109a5db |
|
06-Mar-2001 |
Bob Halley <source@isc.org> |
remove incorrect CNAME/DNAME dead-end code from NXDOMAIN handling |
4e3f8e480f220ef8a87fd28d02f9001b8fc6f423 |
|
05-Mar-2001 |
Bob Halley <source@isc.org> |
fix memory leaks in query_find() |
50448dc92afd39f7fa283eb77d0cbd5770645e9b |
|
18-Feb-2001 |
Brian Wellington <source@isc.org> |
typo |
b270a97754aef2bf3a850e661816f7776387b74d |
|
18-Feb-2001 |
Brian Wellington <source@isc.org> |
Fix a case where the client could theoretically not free a temporary name.
It'll never happen, since dns_rdata_tostruct() cannot fail when passed a NULL
mctx, but it's more correct this way. |
f915bbfc2d3ca880064e3967ecd9a71422acbb4c |
|
14-Feb-2001 |
Andreas Gustafsson <source@isc.org> |
rdatas constructured by query_addcnamelike() always had
type CNAME, even when part of a non-CNAME rdataset |
65a66336a6e2ce2032f68139ef9c8afe18d08c14 |
|
14-Feb-2001 |
Andreas Gustafsson <source@isc.org> |
redid configuration locking using isc_task_beginexclusive()
and isc_task_endexclusive() instead of a multitude of separate
configuration rwlocks |
dc5415c9fd5476eeb9038db04304f6dec0871444 |
|
14-Feb-2001 |
Brian Wellington <source@isc.org> |
comment update |
3d76b54512770787f8038ceb623b3d50d26c425b |
|
29-Jan-2001 |
Brian Wellington <source@isc.org> |
Don't create a timer for every incoming query - only create it for updates,
notifies, and recursive queries. |
75534b639265e419fe481e31f42769f8ca20c87f |
|
27-Jan-2001 |
Andreas Gustafsson <source@isc.org> |
optimization: when deciding whether to do v6 syntheis, check the query type
before the ACL because it's usually faster that way |
d29da750d26001546abed66e8b726c991784f3ec |
|
23-Jan-2001 |
Brian Wellington <source@isc.org> |
statistics counting was slowing down the server. Make client.c:count_query()
inline and remove dns_stats_ncounters(), which just returned the public
constant DNS_STATS_NCOUNTERS. |
634784cb66a1c9ddee0c448f71580f024c8fe40b |
|
22-Jan-2001 |
Andreas Gustafsson <source@isc.org> |
701. [func] Root hints are now fully optional. Class IN
views use compiled-in hints by default, as
before. Non-IN views with no root hints now
provide authoritative service but not recursion.
A warning is logged if a view has neither root
hints nor authoritative data for the root. [RT #696] |
7946047f2d272e400167571b32ff3e7b346924a2 |
|
11-Jan-2001 |
Andreas Gustafsson <source@isc.org> |
name data are unsigned char, not char |
fd8125cac347fccd351241ba6e30d0d4f0778b0d |
|
10-Jan-2001 |
Andreas Gustafsson <source@isc.org> |
respond with NXDOMAIN, not SERVFAIL, when no PTR record is
found in either ip6.int or ip6.arpa |
14b90c6eb0eacbe1d31d5e4cf8ce9a0f87ae0289 |
|
09-Jan-2001 |
Andreas Gustafsson <source@isc.org> |
v6 synthesis code used uninitialized variable |
499b34cea04a46823d003d4c0520c8b03e8513cb |
|
09-Jan-2001 |
Brian Wellington <source@isc.org> |
copyright update |
576f85e5fdb8805307f318db79dfc0d19e390d1a |
|
09-Jan-2001 |
Andreas Gustafsson <source@isc.org> |
673. [func] The server can now convert RFC1886-style recursive
lookup requests into RFC2874-style lookups, when
enabled using the new option "allow-v6-synthesis". |
ad26c868910d4a7368fae94e5d7389d4139f7225 |
|
09-Jan-2001 |
Andreas Gustafsson <source@isc.org> |
checkpoint: IPv6 response synthesis implemented for the reverse
mapping case but still disabled due to lack of configurability |
4e13b2c33c7b944a3f4482444033870d6ecfb9ec |
|
08-Jan-2001 |
Andreas Gustafsson <source@isc.org> |
deal with CNAME loops in AAAA synthesis |
501f6a2fa5541c0384640d7f6dc4d592acebfee9 |
|
07-Jan-2001 |
Andreas Gustafsson <source@isc.org> |
checkpoint: IPv6 response synthesis implemented for the forward
mapping case but still disabled due to lack of configurability |
b23f160d5b0efb1c22ad4f61e5f5edf80e9f0f57 |
|
07-Jan-2001 |
Andreas Gustafsson <source@isc.org> |
simplified handling of the query type, removing the final
vestiges of support for multiple queries per packet, in preparation
for AAAA synthesis code which needs to know the query type earlier
than it was previously available |
ec772e873bd7f24418049b5b1b5d7c44ff781356 |
|
04-Jan-2001 |
Brian Wellington <source@isc.org> |
651. [func] The AD bit in responses now has the meaning
specified in <draft-ietf-dnsext-ad-is-secure>. |
6d5032f9a23fe1197610114983c9938ac419b20c |
|
03-Jan-2001 |
Brian Wellington <source@isc.org> |
Micro-optimizations:
- use the DNS_NAME_INIT macro in name.c
- create dns_name_copy() and use it instead of dns_name_concatenate()
when doing a copy. |
af5dc286ff4b750deec50d1c006aae5fc38019c0 |
|
28-Dec-2000 |
Mark Andrews <marka@isc.org> |
640. [bug] Memory leak in error path could cause
"mpctx->allocated == 0" failure. [RT #584] |
c8fc692fa1445ccfc39b68902546cdfc7ee30d3e |
|
16-Dec-2000 |
Brian Wellington <source@isc.org> |
618. [bug] Queries to a signed zone could sometimes cause
an assertion failure. |
78838d3e0cd62423c23de5503910e01884d2104b |
|
11-Dec-2000 |
Brian Wellington <source@isc.org> |
8 space -> tab conversion |
6fda1577669dca9e0d8e4832e407bac34cc12de6 |
|
07-Dec-2000 |
Mark Andrews <marka@isc.org> |
ISC_LINK_*UNSAFE -> ISC_LINK_INITAND* |
985013e61909471a24e1a80dbbab79d5528e6158 |
|
05-Dec-2000 |
Andreas Gustafsson <source@isc.org> |
don't increment the referral counter when using the root hints (RT #527) |
90ad126bb363ad419b1348dea2b8613b21b4ded8 |
|
02-Dec-2000 |
Andreas Gustafsson <source@isc.org> |
more DNS_OPT_NEWCODES sanitation |
ce1f5b8d0ae5936fd187c1f414ff12a7e3b0aa37 |
|
02-Dec-2000 |
Andreas Gustafsson <source@isc.org> |
rewrote much of the statistics counter code |
d3be9a9c6ef76a5d7671b0962785ca025b153d2b |
|
30-Nov-2000 |
Andreas Gustafsson <source@isc.org> |
583. [func] "rndc querylog" will now toggle logging of
queries, like "ndc querylog" in BIND 8. |
86a4d80e0624a10b1824d25018246e1ea63f55d2 |
|
23-Nov-2000 |
Andreas Gustafsson <source@isc.org> |
565. [func] Log queries more like BIND 8: query logging is now
done to category queries, level info. [RT #169] |
ab13b279aedeac78e0c9bf0e4d9461a91aa95627 |
|
23-Nov-2000 |
Andreas Gustafsson <source@isc.org> |
revert the change of 1.151->1.152 - it is more important to log
queries sanely than to log them the same way BIND 8 did |
6b5a6fbe1cc0ceb7e2b516aaada596b79360a5b8 |
|
20-Nov-2000 |
Bob Halley <source@isc.org> |
only set AD if they asked for DNSSEC |
7fd17f3f4d7d7330dea34781fe2844155517911d |
|
16-Nov-2000 |
David Lawrence <source@isc.org> |
565. [func] Log queries more like BIND 8. Query logging is done
to category "general", module "query", debug level 1.
[RT #169] |
e9f6414d40ac21743db777007260053323570835 |
|
15-Nov-2000 |
Andreas Gustafsson <source@isc.org> |
simplified query logging code by dropping support for EDNS1
multiple queries and by using dns_rdata{type,class}_format();
include the class in query log messages |
eb23b7b59001bba7d562034bdec3808caa1daf60 |
|
15-Nov-2000 |
Andreas Gustafsson <source@isc.org> |
eliminated compiler warnings;
renamed setup_sortlist() to ns_sortlist_setup() to conform
to naming conventions |
50faa6daf7e7550b3cd9d981ff3ddb9c0175080b |
|
14-Nov-2000 |
Andreas Gustafsson <source@isc.org> |
refactored sortlist code to make it possible to sort addresses
that are not part of an rdata, as required by lwresd |
78d78f05d91205cbde33ca87d24b8d13aa2d8d66 |
|
13-Nov-2000 |
Brian Wellington <source@isc.org> |
556. [func] The DNSSEC OK bit in the EDNS extended flags
is now implemented. Responses to queries without
this bit set will not contain any DNSSEC records. |
0042d68e2f0d655d5a1088dd5f8be3c79c2477a6 |
|
13-Nov-2000 |
Brian Wellington <source@isc.org> |
#include <string.h> |
1442a167f547a83311cf7dc518d974a62f563803 |
|
11-Nov-2000 |
Andreas Gustafsson <source@isc.org> |
minor fixes to sortlist comments and spacing |
917c8406f664390564755b0f59a2c9b9f0d3728a |
|
11-Nov-2000 |
Andreas Gustafsson <source@isc.org> |
handle negated sortlist entries correctly |
febaa091847ab004f40500cc475a819f2c73fcdd |
|
10-Nov-2000 |
Andreas Gustafsson <source@isc.org> |
551. [func] Implemented the 'sortlist' option. |
31eef7e2d402904bb7485eba88568ec3f39a7cfa |
|
09-Nov-2000 |
Michael Sawyer <source@isc.org> |
Use lowercase names for stats
statistic printing code cleanup
move some of the statistics stufdf to the server object |
a3a11c4f3fc9ba972802b811c4d95a9884d6ff4a |
|
08-Nov-2000 |
Michael Sawyer <source@isc.org> |
Add the ability (via rndc dump-statistics) to dump a file with counters of
various results given to queries. Enable the (previously disabled)
statistics-file config option. |
368b37b616234fce3d23099eb180f1dd38e1fb62 |
|
31-Oct-2000 |
Mark Andrews <marka@isc.org> |
dns_rdata_invalidate -> dns_rdata_reset |
c03bb27f0675a6e60ceea66b451548e8481bc05c |
|
25-Oct-2000 |
Mark Andrews <marka@isc.org> |
532. [func] Implement DNS UPDATE pseudo records using
DNS_RDATA_UPDATE flag.
531. [func] Rdata really should be initalized before being
assigned to (dns_rdata_fromwire(), dns_rdata_fromtext(),
dns_rdata_clone(), dns_rdata_fromregion()),
check that it is. |
5e589b5356a4125b5af32605dead82ab8b467c88 |
|
20-Oct-2000 |
Mark Andrews <marka@isc.org> |
Uninitalised link fixes, batch 1. |
55aed608cc0396f6b874bb1d691cefda8fcb49b8 |
|
17-Oct-2000 |
Michael Sawyer <source@isc.org> |
Add counters of incoming queries, server-wide and by zone. There is
currently no way to get these counts back *out* of the server, pending
a command channel. A temporary channel should be built for these data
soon. |
94b50bce2b5deeac93734457d5474736d7b76af1 |
|
12-Oct-2000 |
Michael Sawyer <source@isc.org> |
Add zone-specific reload and refresh capability to server and rndc |
f6b2acd608cb556cc6131d2f2295105e7de9d94e |
|
11-Oct-2000 |
Michael Sawyer <source@isc.org> |
Minor change to make GNS changes easier, as well as a minor typo. |
dc570b92f6cc60def4207733c7a194fbb69a4399 |
|
11-Oct-2000 |
Michael Sawyer <source@isc.org> |
Add support for proposed ZONE and VIEW opt attributes. These are currently
hidden behind #ifdef's, since no OPT code number has yet to be assigned
by the IANA. They are also not quite complete in all regards; VIEW
options are understood and ignored. ZONE options are understood and
acted upon, though some of the error cases aren't quite right.
Remove doubled isc_mem_stats in dighost.c
Update todo list.
Change literal 255's to DNS_NAME_MAXWIRE in name.c |
d1cbf714097e900ed1703529584d3e1a50e8a4a8 |
|
07-Oct-2000 |
Brian Wellington <source@isc.org> |
clean up suspicious looking and incorrect uses of dns_name_fromregion |
88cef4408ab6b4c48702ed1b3ae27e20f485d864 |
|
28-Sep-2000 |
Mark Andrews <marka@isc.org> |
493. [func] Return non-cachable (ttl = 0) NXDOMAIN responses
for SOA queries. This makes it easier to locate
the containing zone without polluting intermediate
caches. |
337ca1838428c52bca3c72288342ce3dee550a04 |
|
20-Sep-2000 |
Andreas Gustafsson <source@isc.org> |
475. [bug] query_getzonedb() sometimes returned a non-null version
on failure. This caused assertion failures when
generating query responses where names subject to
additional section processing pointed to a zone
to which access had been denied by means of the
allow-query option. [RT #336] |
3a1ad1b045fadfe9c77dc10f5ff8cbbea79a54a2 |
|
13-Sep-2000 |
Andreas Gustafsson <source@isc.org> |
removed #if 0'ed-out code |
b95c1391fa401f1dd1c71bbaf3c6a4f2b433c4d5 |
|
12-Sep-2000 |
Michael Graff <mgraff@isc.org> |
log query denied at INFO level, rather than error |
42e31e6ef7689e0c0569a1f9a5c250d73870b073 |
|
12-Sep-2000 |
Michael Graff <mgraff@isc.org> |
pass in the log level desired; make 'client denied recursion' log at debug level 1 always. |
1fc26319b5d69d19a7a31c8d0ab1afc2beef0c41 |
|
06-Sep-2000 |
Andreas Gustafsson <source@isc.org> |
423. [bug] When responding to a recusive query, errors that occur
after following a CNAME should cause the query to fail.
[RT #274] |
1865d559b0d3b253de4a9e215ee57b42426f752a |
|
27-Aug-2000 |
Michael Graff <mgraff@isc.org> |
Fix the database error, I think... Need to look at this better. |
2c1a16dc25dfb0be19580dd4f8c573e72b553753 |
|
22-Aug-2000 |
Brian Wellington <source@isc.org> |
Remove multiple question support, since edns1 is dead. |
e605e98f3e4be079f545b26bb53ba02a6d04b0b6 |
|
09-Aug-2000 |
Andreas Gustafsson <source@isc.org> |
use DNS_NAME_MAXTEXT/DNS_NAME_FORMATSIZE |
ff56121a989fd6dc133ed79afc4a2c1491c4c511 |
|
09-Aug-2000 |
Andreas Gustafsson <source@isc.org> |
use isc_log_wouldlog() |
40b1b44ed65b9655a135fc867ed9f0374c247ad4 |
|
08-Aug-2000 |
Andreas Gustafsson <source@isc.org> |
377. [bug] WHen additional data lookups were refused due to
allow-query, the databases were still being
attached causing reference leaks. |
575db903aabb08137a757d1c60ebb0d286ecff56 |
|
08-Aug-2000 |
Andreas Gustafsson <source@isc.org> |
375. [bug] Per-zone allow-query did not properly override the
view/global one for CNAME targets and additional
data [RT #220]. |
2ebe19d1a2b5381dcd6dce5882dfd5c98ab6db6d |
|
08-Aug-2000 |
Andreas Gustafsson <source@isc.org> |
SOA in authoritative negative responses had wrong TTL (RT #212) |
40f53fa8d9c6a4fc38c0014495e7a42b08f52481 |
|
01-Aug-2000 |
David Lawrence <source@isc.org> |
Trailing whitespace trimmed. Perhaps running "perl util/spacewhack.pl in your
own CVS tree will help minimize CVS conflicts. Maybe not.
Blame Graff for getting me to trim all trailing whitespace. |
6d3496c045bbf35514b4697ff20741975083e125 |
|
31-Jul-2000 |
Michael Graff <mgraff@isc.org> |
Implement additional-from-{glue,auth} [ yes | no ] ;
with yes being the default. These control searching in the cache and
other zones we are authorative for. This is mostly for gdib, but
may be useful elsewhere.
The config changes are renaming from glue-from-* to additional-from-*,
since this also prevents DNAME, CNAME, NS, MX, etc. additional data
from being followed. |
15a44745412679c30a6d022733925af70a38b715 |
|
27-Jul-2000 |
David Lawrence <source@isc.org> |
word wrap copyright notice at column 70 |
1702f1a0fec50e754a033cf3271676373c6b4c15 |
|
25-Jul-2000 |
Brian Wellington <source@isc.org> |
Add a 'fetchoptions' field to the query structure, which is currently 0
unless the query has the cd bit set. |
5d9e3392b2e0e05a6ec9096c113aa39bf54e8de2 |
|
25-Jul-2000 |
Brian Wellington <source@isc.org> |
Add support for the cd (checking disabled) bit. Setting the cd bit in a
query still doesn't completely work, since the resolver needs to be modified
also. Basically, if data is in the cache and trust == pending, it will now
be returned when the cd bit is set. |
70c2802fd7b9b77eda8a8366014afa4c559fd551 |
|
19-Jul-2000 |
Brian Wellington <source@isc.org> |
In query_addbestns, check that both the rdataset and sigrdataset are not
pending before adding them. |
04d58db32739157df6c44e3f37ecb83816fd3f75 |
|
10-Jul-2000 |
Andreas Gustafsson <source@isc.org> |
321. [bug] When synthesizing a CNAME RR for a DNAME
response, query_addcname() failed to intitialize
the type and class of the CNAME dns_rdata_t,
causing random failures. |
baeb4bcf32d035af33ab6da48e16f012b0c4a76d |
|
06-Jul-2000 |
Brian Wellington <source@isc.org> |
In query_find(), if we're looking up a key and dns_db_find() returns
DNS_R_DELEGATION, don't use the domain & ns set found by dns_db_find().
This means that a recursive server will not immediately ask the child zone
for a key set at the apex; the resolver will determine who to ask. |
4defd73fca0bcffeb1c768eec4379551e64b9254 |
|
06-Jul-2000 |
Andreas Gustafsson <source@isc.org> |
This is "the glue fix". It changes the additional data lookup
algorithm to more closely follow RFC1035, so that root servers will
provide a more complete set of name server glue addresses in ccTLD
referral responses.
For non-referral responses, the server no longer uses glue as
additional data.
For referral responses, the servers now looks for glue A/AAAA/A6 RRs
in the zone where the NS RRs reside, even in the case where this is
different from the zone where the A/AAAA/A6 RRs would have resided had
they been authoritative data.
A6 chains included as additional info may not yet fully follow these
rules. |
a074e41b97369be3ef1b09a6b13a1a063b6fae9c |
|
04-Jul-2000 |
Andreas Gustafsson <source@isc.org> |
style and new comments; no functional change |
4ecbc9c96ff58399e27481022c0c81b9df8845d2 |
|
26-Jun-2000 |
Michael Graff <mgraff@isc.org> |
Don't use TCP for outgoing queries just because the client is TCP. |
9c3531d72aeaad6c5f01efe6a1c82023e1379e4d |
|
23-Jun-2000 |
David Lawrence <source@isc.org> |
add RCS id string |
0bfcec250f9705a1211d0374f0fc1049960de84b |
|
15-Jun-2000 |
Mark Andrews <marka@isc.org> |
254. [bug] suppress "query denied" messages on additional data
lookups.
ISC-Bugs #139 |
0b056755b2f423ba5f6adac8f7851d78f7d11437 |
|
01-Jun-2000 |
David Lawrence <source@isc.org> |
225. [cleanup] The enumerated dns_rdatatype_* identifiers are now
cast to dns_rdatatype_t via macros of their same name
so that they are of the proper integral type wherever
a dns_rdatatype_t is needed.
(And a few prototypes that I recently bogusly changed to take "int" parameters
in place of "dns_rdatatype_t" to accomodate the type of an enum identifier
have been reverted to again properly take a dns_rdatatype_t.) |
7efc8c3f692fc3226c00ce8bdc1b90eb06562352 |
|
01-Jun-2000 |
David Lawrence <source@isc.org> |
Megacommit of many files.
Mostly, several functions that take pointers as arguments, almost
always char * pointers, had those pointers qualified with "const".
Those that returned pointers to previously const-qualified arguments
had their return values qualified as const. Some structure members
were qualified as const to retain that attribute from the variables
from which they were assigned.
Minor other ISC style cleanups. |
ed019cabc1cc75d4412010c331876e4ae5080a4d |
|
24-May-2000 |
David Lawrence <source@isc.org> |
fixed lines > 79 columns wide |
ffead635aac9a28527958a3c35734c6106ae833f |
|
24-May-2000 |
David Lawrence <source@isc.org> |
removed unused stack variable "set_ra" from ns_query_start.
wrapped long lines.
fixed comment to ISC style. |
949162ca40a79ca5afcaeb14794c12b774386098 |
|
11-May-2000 |
Andreas Gustafsson <source@isc.org> |
in [84], after allowing access to a zone based on the view
allow-query ACL, subsequent accesses to the same zone were denied because
dbversion->queryok was not being set. This caused mandatory glue to be
omitted from referral responses, ultimately causing lookups to fail if all
authoritative servers for the parent zone were running bind9. |
1a69a1a78cfaa86f3b68bbc965232b7876d4da2a |
|
08-May-2000 |
David Lawrence <source@isc.org> |
Megacommit of dozens of files.
Cleanup of redundant/useless header file inclusion.
ISC style lint, primarily for function declarations and standalone
comments -- ie, those that appear on a line without any code, which
should be written as follows:
/*
* This is a comment.
*/ |
09f22ac5b09e70bc526015f37168ba33e21ea91f |
|
02-May-2000 |
David Lawrence <source@isc.org> |
Redundant header work, mostly removing <dns/result.h> from installed
headers and adding it to source files that need it. |
b77f76be2d114ad1abecf7e6e6c1414a4ade44c1 |
|
29-Apr-2000 |
David Lawrence <source@isc.org> |
Where the methods field of an rdataset was compared to NULL, now use
dns_rdataset_isassociated() instead. |
82ca33427bdd4f3bc4ed3431e86bd810fe751674 |
|
28-Apr-2000 |
Andreas Gustafsson <source@isc.org> |
declare arguments as UNUSED() when used in assertions only |
6e49e91bd08778d7eae45a2229dcf41ed97cc636 |
|
27-Apr-2000 |
David Lawrence <source@isc.org> |
103. [func] libisc buffer API changes for <isc/buffer.h>:
Added:
isc_buffer_base(b) (pointer)
isc_buffer_current(b) (pointer)
isc_buffer_active(b) (pointer)
isc_buffer_used(b) (pointer)
isc_buffer_length(b) (int)
isc_buffer_usedlength(b) (int)
isc_buffer_consumedlength(b) (int)
isc_buffer_remaininglength(b) (int)
isc_buffer_activelength(b) (int)
isc_buffer_availablelength(b) (int)
Removed:
ISC_BUFFER_USEDCOUNT(b)
ISC_BUFFER_AVAILABLECOUNT(b)
isc_buffer_type(b)
Changed names:
isc_buffer_used(b, r) ->
isc_buffer_usedregion(b, r)
isc_buffer_available(b, r) ->
isc_buffer_available_region(b, r)
isc_buffer_consumed(b, r) ->
isc_buffer_consumedregion(b, r)
isc_buffer_active(b, r) ->
isc_buffer_activeregion(b, r)
isc_buffer_remaining(b, r) ->
isc_buffer_remainingregion(b, r)
Buffer types were removed, so the ISC_BUFFERTYPE_*
macros are no more, and the type argument to
isc_buffer_init and isc_buffer_allocate were removed.
isc_buffer_putstr is now void (instead of isc_result_t)
and requires that the caller ensure that there
is enough available buffer space for the string. |
924e26ea2f68b28d888912d332bfad825fd94bd3 |
|
25-Apr-2000 |
Bob Halley <source@isc.org> |
Look for KEY RRs in both the delegator and delegatee if we're
authoritative for both, the delegatee is nonsecure, and the query
name is at the top of the delegatee zone.
Apply allow-query ACL checks to all response data. |
e2fe0815b3c33c5c2c70b11329ac213f4deb18eb |
|
19-Apr-2000 |
Bob Halley <source@isc.org> |
conform to zt API change |
e44487bfc23599b6b240e09d83d1c862fecfcc82 |
|
17-Apr-2000 |
Michael Graff <mgraff@isc.org> |
convert sender, arg, action, etc. to ev_sender, ev_arg, ev_action, etc. |
15a0ed30600ea88fe1227233155586f0c3c6cc34 |
|
13-Apr-2000 |
Bob Halley <source@isc.org> |
fix [RT 94] (name buffer already in use assertion) |
ad2c5d060da962b576b79422205c59fec59b4aaf |
|
11-Apr-2000 |
Andreas Gustafsson <source@isc.org> |
use dns_name_format() when logging queries |
8469ee3726540781cf3b13db24bf5df9ee12fdc3 |
|
11-Apr-2000 |
Brian Wellington <source@isc.org> |
Don't include authority data if it would force us to unset the AD bit |
a672bfbee46c261729811405685db409bd7c9285 |
|
07-Apr-2000 |
Andreas Gustafsson <source@isc.org> |
wired up view options: allow-query, allow-recursion, allow-transfer |
419590499823ce15b5d2ad4fe71eaf04bd5a86c0 |
|
07-Apr-2000 |
Michael Graff <mgraff@isc.org> |
s/DNS_R_/ISC_R_/ change for some codes. |
66e2dd5001f249bc5e2c89074df41f769f13bf07 |
|
06-Apr-2000 |
Andreas Gustafsson <source@isc.org> |
wired up view options: recursion, auth-nxdomain, transfer-format |
074a4e34942394cffea0e8da406dea1d7a8db48a |
|
04-Apr-2000 |
Andreas Gustafsson <source@isc.org> |
provide more context in log messages |
d72c8b8c6a05f380c16518e683e8512c4ce96fc6 |
|
17-Mar-2000 |
Bob Halley <source@isc.org> |
Do not detach 'db' in the NOTFOUND case if it is NULL. This should not
happen, but is a possible result if the resolver returned NOTFOUND. |
3eef7eaba00e9bd468d8036c709a296a0e5b76f1 |
|
22-Feb-2000 |
Andreas Gustafsson <source@isc.org> |
renamed dns_acl_checkrequest() to ns_client_checkacl()
and moved it to bin/named/client.c to reflect the fact that it
implemented BIND ACL policy more than general-purpose library
functionality; resolve ACL defaults at configuration time
rather than when the ACL is evaluated |
52c6910afbf04041cc1b1c10af3e9a380fb500d7 |
|
14-Feb-2000 |
Brian Wellington <source@isc.org> |
Adding additional data caused an assertion for a signed zone. |
ae0bc2f30efa3cb40cc579835cd269476efbcb55 |
|
11-Feb-2000 |
Andreas Gustafsson <source@isc.org> |
Make client reference counts work the same way as all
other reference counts: replace ns_client_wait() and
ns_client_unwait() by ns_client_attach() and ns_client_detach(),
respectively |
e5f8f2659bf1cbaa5b45c09605a23dc8ba9f94d6 |
|
10-Feb-2000 |
Andreas Gustafsson <source@isc.org> |
yet another major reorganization of client shutdown
procedures, in preparation for client timeouts |
a1747570262ed336c213aaf6bd31bc91993a46de |
|
09-Feb-2000 |
Andreas Gustafsson <source@isc.org> |
implemented the 'localhost' and 'localnets' ACLs |
7d98a1783f222964bcde7d56dab77b822706204d |
|
03-Feb-2000 |
Bob Halley <source@isc.org> |
update copyrights |
bfab626984091c400ed70216746739e90f82f266 |
|
01-Feb-2000 |
Bob Halley <source@isc.org> |
When answering a nonrecursive query, do not use the cache if we have a
referral from authoritative data. |
4ab89b50e52be78226ef3edf810081d43bc45cd2 |
|
27-Jan-2000 |
Andreas Gustafsson <source@isc.org> |
need #include <dns/rdatatype.h> |
143c2d39fafc0e36e0fa291b7708b60309e5a1b6 |
|
27-Jan-2000 |
Andreas Gustafsson <source@isc.org> |
configuration locking checkpoint |
9e694201cfe00011e98bfa9cdb6358e7d050be7b |
|
25-Jan-2000 |
Andreas Gustafsson <source@isc.org> |
eliminated global variable ns_g_tkeyctx |
bf08eb90e44ed8717d538442600c4ad11adac61d |
|
21-Jan-2000 |
Brian Wellington <source@isc.org> |
use the new TSIG/TKEY code |
f87506d115bf655b71c3a2863f5b0be6443e6a3d |
|
21-Jan-2000 |
Bob Halley <source@isc.org> |
conform to resolver API change |
09df1930e91a52d76dc7d1350e77f455d5ca486d |
|
15-Jan-2000 |
Andreas Gustafsson <source@isc.org> |
client can now reserve multiple types of quota simultaneously;
client quota bug fixes |
559b10cc8f3e1dc4d93f55c9336f74839e9fa362 |
|
11-Jan-2000 |
Andreas Gustafsson <source@isc.org> |
client quotas; added reference counting to ns_interface_t
and ns_interfacemgr_t so that they can safely hold quota information |
45068fd4dc2bcd60a49486a6592d9b47b8058a2e |
|
07-Jan-2000 |
Bob Halley <source@isc.org> |
fix problem with SRV recursive additional data |
2cb0da946ee814875ab0e817d5cb6104f2dbbdad |
|
06-Jan-2000 |
Andreas Gustafsson <source@isc.org> |
the client and query data structures were not cleaned up
correctly if the server got a SIGINT with a recursive query in progress |
6b32dc65e4684fd8ee3ae11dc92d4ccb84911057 |
|
24-Dec-1999 |
Mark Andrews <marka@isc.org> |
A whole lot of logging currently disabled with noop MACRO. |
3ddd814a97de1d152ba0913c592d6e6dc83d38a6 |
|
23-Dec-1999 |
Michael Graff <mgraff@isc.org> |
dns_result_t is no more. s/dns_result_t/isc_result_t/ -- more later, when I need a break. |
143592a649a60dc6754dfb634da38113b8641888 |
|
22-Dec-1999 |
Andreas Gustafsson <source@isc.org> |
new client shutdown cleanup strategy |
2015bf18c956ef49bb6af144f69d0729cc37f2d5 |
|
17-Dec-1999 |
Michael Graff <mgraff@isc.org> |
remove ../../isc/util.h that Andreas put back in. |
58aaab3687aac838542ee4ef65a9c094a5d34ab0 |
|
17-Dec-1999 |
Michael Graff <mgraff@isc.org> |
isc_stdtime_get() now returns void, not isc_result_t. |
6017f424ee3c02d7f22132c77576ea38542fa949 |
|
17-Dec-1999 |
Andreas Gustafsson <source@isc.org> |
introducing dns_acl_t; other restructuring of server
configuration process aiming to reduce the degree of mutual dependency
between lib/dns/config and the rest of libdns |
440be4c866f6935ac069db79a414304507a664c2 |
|
16-Dec-1999 |
Michael Graff <mgraff@isc.org> |
move util.h to <isc/util.h> |
314b686c17de561eb40be56ad20830c6c86b165f |
|
14-Dec-1999 |
Bob Halley <source@isc.org> |
plug negative response memory leaks |
c295547c73968e3d378e0c828281d177a2b0ba12 |
|
11-Dec-1999 |
Andreas Gustafsson <source@isc.org> |
use the "recursion" and "allow-recursion" config options;
set RA correctly in responses |
f882ab1ac25f94c75f006ed167d1845fc5ca2966 |
|
10-Dec-1999 |
Andreas Gustafsson <source@isc.org> |
obey the "auth-nxdomain" config option (but the default
is now "no" |
0fb226f025e520b25800d46b8d2c240108055bc4 |
|
10-Dec-1999 |
Andreas Gustafsson <source@isc.org> |
implemented 'allow-query' config option |
031614c8da974236f88e07e0119b7d18ad80fe4f |
|
24-Nov-1999 |
Bob Halley <source@isc.org> |
Fix typo that was breaking A6 additional section processing. |
feee4510989e07f20c5ee9f7ec13ad3084a4b11e |
|
23-Nov-1999 |
Bob Halley <source@isc.org> |
log queries at debug level 1 |
93fa7f307828c4a411e922062c7d4417fdd5e251 |
|
22-Nov-1999 |
Bob Halley <source@isc.org> |
conform to a6 API changes |
672893c239062aa329eaab6acdb261764297bb3f |
|
16-Nov-1999 |
Bob Halley <source@isc.org> |
If the client used TCP, tell the resolver to do so as well. |
ecda717550f127cba1963fc16f9da4faaf5a7230 |
|
04-Nov-1999 |
Bob Halley <source@isc.org> |
deal with negative responses in query_simplefind() |
83ffabbfe130d7294589bc7719ec8c4239796608 |
|
03-Nov-1999 |
Bob Halley <source@isc.org> |
Deal with negative cache responses when using dns_db_findrdataset(). |
5305b2140b62e36eec8c30accc2f11cb2ce48227 |
|
02-Nov-1999 |
Bob Halley <source@isc.org> |
eliminate unused vars |
ecd4a905ec5e62293f5ad8dff47129364be61b7d |
|
02-Nov-1999 |
Bob Halley <source@isc.org> |
more fixes to 1.48 |
b3bdf85fd85a7f5c26e9f37c020e0b110cf8b485 |
|
02-Nov-1999 |
Mark Andrews <marka@isc.org> |
get additional section processing working again. |
efba17ab5654d86cbaed887d84a40da6472b94a4 |
|
29-Oct-1999 |
Bob Halley <source@isc.org> |
update client->now when resuming after recursion |
fe37278859bce157001cca14cdfa3a761b0d5012 |
|
29-Oct-1999 |
Mark Andrews <marka@isc.org> |
in6_addr.s6_addr is *always* an array. |
90ace4c9e063e67fb452907d11bf29eae618a355 |
|
26-Oct-1999 |
Brian Wellington <source@isc.org> |
preliminary TKEY support |
bf336d569445bfe2c9f37fd58864e2cac7bef1ff |
|
25-Oct-1999 |
Bob Halley <source@isc.org> |
Get rid of NXGLUE.
We would fail to do any A6 or AAAA additional data section processing if
the A RR didn't exist.
Suppress cache glue except when generating a referral. |
64a840af4969584d44d69e69b11f5da925981b43 |
|
21-Oct-1999 |
Bob Halley <source@isc.org> |
Remove unused variable 'nxglue' from query_addadditional(). |
b0d415629b9e1bcedfd09ee597414df0a5dee9d4 |
|
21-Oct-1999 |
Bob Halley <source@isc.org> |
Add query_addbestns(), which will add the deepest known zonecut for the
query name to the authority section of nonauthoritative replies.
query_addadditional() sometimes tried to detach from a nonattached node. |
71637c64895485247cc05567a555e78a645ed8ea |
|
21-Oct-1999 |
Bob Halley <source@isc.org> |
Add more comments about synthesizing a CNAME when following a DNAME. |
9ab8a7477d6a31275ca7d1f6b5f37c23a8a7e6cb |
|
21-Oct-1999 |
Bob Halley <source@isc.org> |
Synthesize an appropriate CNAME when following DNAME. |
d3376f4cf5fbaac629e37c0d247c8bf84677fa87 |
|
20-Oct-1999 |
Bob Halley <source@isc.org> |
start work to allow a client to be cancelled/idled |
d38a7a518f8de1a85e7fd9e0983b53191af366ec |
|
19-Oct-1999 |
Bob Halley <source@isc.org> |
Set AD. |
3f6714ce5467bcd36a64ae1878d7db1b5c989fa5 |
|
19-Oct-1999 |
Bob Halley <source@isc.org> |
Remove query_a6additional(), since the latest version of the DNS lookups
draft no longer requires type A and AAAA additional section processing for
the owner name of an A6 rrset. |
8a9f679d608fa86ad1987358ac82e0ebcf9c602a |
|
18-Oct-1999 |
Bob Halley <source@isc.org> |
Ensure version is always NULL for cache databases.
Plug a memory leak in the DNAME code. |
d680c5e7d5a10feb6208a5582ca0dbd30ec69fb9 |
|
17-Oct-1999 |
Bob Halley <source@isc.org> |
Do not free client->query.qname prematurely.
Detach from our fetch as soon as it is done. (Not doing this meant we
couldn't recurse again when restarting.)
Fix some bugs in the multiple question code that were causing qtype to be
set incorrectly when restarting after recursion. |
238c9f5aaa5704fae2a39a4f3fde52a28ef71195 |
|
16-Oct-1999 |
Bob Halley <source@isc.org> |
qtype was not restored correctly after recursion. |
a2250d2462f7b00f5643e746c35355ff470c6f00 |
|
16-Oct-1999 |
Bob Halley <source@isc.org> |
Negative caching support. |
6bd80c2c4edd3332697415ef6ad4940a40add963 |
|
15-Oct-1999 |
Bob Halley <source@isc.org> |
Ignore negative cache entries in ANY query responses. |
66a6c177577478b498de74c57b4dafe60d3f6ebf |
|
15-Oct-1999 |
Bob Halley <source@isc.org> |
When using the hints database, 'db' was not reset from the cache to the
hints database. Later on we'd try to detach a node from the hints database
using the cache database, and this would trigger an assertion. |
d60f5b9bc8c1e1f7ddebc6c7834f7550a8e8be6f |
|
14-Oct-1999 |
Bob Halley <source@isc.org> |
Zone support |
30b652c9f33e050c674dc40b37b21902880dc35c |
|
13-Oct-1999 |
Bob Halley <source@isc.org> |
improve post-recursion code |
93acd5fcca4cd22f56b245fd479113dc5a574f13 |
|
12-Oct-1999 |
Bob Halley <source@isc.org> |
add comment about possible standards change |
e24ae70756d8462bcc05ec13e35742d683581d41 |
|
11-Oct-1999 |
Bob Halley <source@isc.org> |
Make qrdataset an attribute of the client.
Get the foundname out of the fetch done event. |
4fdb67f4ebec8003fe8d4e34c2c1389725a4f793 |
|
07-Oct-1999 |
Bob Halley <source@isc.org> |
resolver support checkpoint; partial AD support |
15b1d6235189f12d75ead41edd9677c440d2f41d |
|
17-Sep-1999 |
Bob Halley <source@isc.org> |
Add NS records to the authority section when answering from a zone.
Do not put a name into a section more than once.
Make restarts part of query state.
We were leaking the old qname after a CNAME/DNAME restart.
Update A6 follower calls to conform with interface changes. |
0e5d1f7463f3b748b0aff6057c9d2d26cd15189b |
|
13-Sep-1999 |
Bob Halley <source@isc.org> |
cache support |
55dd0f94e6124dab8b9fc7c814c3cd4c3fa54a95 |
|
09-Sep-1999 |
Andreas Gustafsson <source@isc.org> |
typo caused SIGs to leak memory instead of being added to response |
6674b5827d3cc1f2869d301972b44635a74f4482 |
|
08-Sep-1999 |
Bob Halley <source@isc.org> |
only allow glue for the delegating zone |
9637357a7765cc63ae401e02c727b1202f20bc08 |
|
08-Sep-1999 |
Bob Halley <source@isc.org> |
a6 chains in additional data |
daf60b760441a51dbadd2ba70f8e370d21a44a7b |
|
08-Sep-1999 |
Bob Halley <source@isc.org> |
add a6 chains to additional data |
4556681e191b7c1654639895ce719d98f2822ee2 |
|
02-Sep-1999 |
Michael Graff <mgraff@isc.org> |
snapshot socket.[ch] code and commit dynbuf_t -> buffer_t changes |
3f185361a4ca047fbce4ca20c9b080ebace89b01 |
|
01-Sep-1999 |
Bob Halley <source@isc.org> |
Set AA correctly at zonecuts and in delegations.
Return glue when generating referrals.
Included signatures of additional data, if available.
An A6 query now causes type A and type AAAA additional section processing for
QNAME.
Add some comments. |
5c48c142e3ebf06718016d031815972d43c88018 |
|
01-Sep-1999 |
Bob Halley <source@isc.org> |
Doing a SIG query to a nonsecure zone was returning SERVFAIL instead of
no error, no data. |
732e0731dec1922747bb3b3147cf2c3d16b22eaa |
|
01-Sep-1999 |
Bob Halley <source@isc.org> |
SIG support |
241c94301bd00300c1908e06f07ac5ce8bad953a |
|
27-Aug-1999 |
Bob Halley <source@isc.org> |
get rid of warning |
549b6394e0cdb95698efcc23f6d58dee761838f8 |
|
26-Aug-1999 |
Bob Halley <source@isc.org> |
NXDOMAIN NXT support |
d662fd77ecb875663f3d7510a8dd03f369697da2 |
|
20-Aug-1999 |
Andreas Gustafsson <source@isc.org> |
enable outgoing zone transfers |
ff5fcd9e67c356d83ffc95682d764f8f42179bc5 |
|
19-Aug-1999 |
Bob Halley <source@isc.org> |
NXRRSET NXT support |
9d308c623699ec4f2eb38515e9350698ae0151fc |
|
18-Aug-1999 |
Bob Halley <source@isc.org> |
use only one database version per query |
cd1d7a62de8ca0202900f92b867772f9578140bb |
|
17-Aug-1999 |
Bob Halley <source@isc.org> |
remove test code that was erroneously left in |
84d821c5218f61a8e66463da92eedf4b26f7ce0a |
|
16-Aug-1999 |
Andreas Gustafsson <source@isc.org> |
check for meta-queries |
ac52827835770e41eb62d61e3889266217ac2128 |
|
12-Aug-1999 |
Bob Halley <source@isc.org> |
return YXDOMAIN if dname construction fails |
a7de9416692bf7bd36e53aeae8e0ec23d06a5f16 |
|
12-Aug-1999 |
Bob Halley <source@isc.org> |
cleanup and restructure find; add DNAME support |
173b32c660c1e4d5141b5ca740e8fab3c593652f |
|
06-Aug-1999 |
Bob Halley <source@isc.org> |
checkpoint: basic views, version.bind support |
b77cab68c65633bc534090b09fbac743b161f9b7 |
|
05-Aug-1999 |
Bob Halley <source@isc.org> |
checkpoint; crude TCP support |
f988b6764d2289711ed372fb6b3584a671bfd983 |
|
03-Aug-1999 |
Bob Halley <source@isc.org> |
checkpoint |
4e37c87da13906d11385700776111f207ee1fb2b |
|
03-Aug-1999 |
Bob Halley <source@isc.org> |
checkpoint; beginnings of additional data support |
6dc79bfdafe38c9ce811b84e2d4c71e6cf9f46b4 |
|
02-Aug-1999 |
Andreas Gustafsson <source@isc.org> |
unintialized variables |
5debbf1189c145db2da3cbf69a8c01379c5c68a3 |
|
29-Jul-1999 |
Bob Halley <source@isc.org> |
checkpoint |
a0d74f71acc2e13723ef29bf0b23cc9229b860f3 |
|
28-Jul-1999 |
Bob Halley <source@isc.org> |
remove events.h |
b4d79725458782ce4ae781255fc7a22614a8b484 |
|
28-Jul-1999 |
Bob Halley <source@isc.org> |
checkpoint |
7e6c9a9a733f7a57ace98e4692573f42a2cad0ed |
|
24-Jul-1999 |
Bob Halley <source@isc.org> |
add |