1516N/A1345. [bug] When performing a nonexistence proof, the validator
382N/A should discard parent NXTs from higher in the DNS.
382N/A1343. [contrib] queryperf now reports a summary of returned
382N/A rcodes (-c), rcodes are printed in mnemonic form (-v).
382N/A1342. [func] Report the current serial with periodic commits when
382N/A rolling forward the journal.
382N/A1341. [func] Generate DNSSEC wildcard proofs.
382N/A1340. [bug] When processing events (non-threaded) only allow
382N/A the task one chance to use to use its quantum.
382N/A1339. [func] named-checkzone will now check if nameservers that
382N/A appear to be IP addresses. Available modes "fail",
382N/A "warn" (default) and "ignore" the results of the
382N/A1338. [bug] The validator could incorrectly verify an invalid
1431N/A1337. [bug] The validator would incorrectly mark data as insecure
382N/A when seeing a bogus signature before a correct
1431N/A validation was not being performed. [RT #3284]
1431N/A1335. [bug] If the tcpquota was exhausted it was possible to
1431N/A to trigger a INSIST() failure.
1431N/A1332. [bug] dnssec-signzone usage message was misleading.
2028N/A1331. [bug] If the last RRset in a zone is glue, dnssec-signzone
2301N/A would incorrectly duplicate its output and sign it.
1968N/A1330. [doc] query-source-v6 was missing from options section.
2606N/A1329. [func] libbind: log attempts to exploit #1328.
1431N/A1328. [bug] libbind: Remote buffer overrun.
2028N/A1327. [port] libbind: TrueUNIX 5.1 does not like __align as a
382N/A1326. [bug] libbind: gethostans() could get out of sync parsing
2028N/A the response if there was a very long CNAME chain.
1895N/A1325. [bug] Options should apply to the internal _bind view.
1895N/A1324. [port] Handle ECONNRESET from sendmsg() [unix].
2970N/A1323. [func] Query log now says if the query was signed (S) or
2028N/A1322. [func] Log TSIG key used w/ outgoing zone transfers.
2843N/A1321. [bug] lwres_getrrsetbyname leaked memory. [RT #3159]
2843N/A1320. [bug] 'rndc stop' failed to cause zones to be flushed
2843N/A1319. [func] Log that a zone transfer was covered by a TSIG.
2843N/A1318. [func] DS (delegation signer) support.
2843N/A1317. [bug] nsupdate: allow white space base64 key data.
2843N/A1316. [bug] Badly encoded LOC record when the size, horizontal
2843N/A precision or vertical precision was 0.1m.
2843N/A1315. [bug] Document that internal zones are included in the
873N/A1314. [func] New function: dns_zone_name().
873N/A1313. [func] Option 'flush-zones-on-shutdown <boolean>;'.
873N/A1312. [func] Extended rndc dumpdb to support dumping of zones and
873N/A view selection: 'dumpdb [-all|-zones|-cache] [view]'.
873N/A1311. [func] New category 'update-security'.
1540N/A1310. [port] Compaq Trucluster support.
1540N/A1309. [bug] Set AI_ADDRCONFIG when looking up addresses
1540N/A via getaddrinfo() (affects dig, host, nslookup, rndc
873N/A could be left with a trailing "\" after configure
1968N/A1307. [port] linux: make handling EINVAL from socket() no longer
1968N/A conditional on #ifdef LINUX.
1968N/A1306. [bug] isc_log_closefilelogs() needed to lock the log
2064N/A1305. [bug] isc_log_setdebuglevel() needed to lock the log
873N/A1304. [func] libbind: no longer attempts bit string labels for
873N/A for nibble style resolution.
873N/A1303. [func] Entropy can now be retrieved from EGDs. [RT #2438]
873N/A1302. [func] Enable IPv6 support when using ioctl style interface
873N/A scanning and OS supports SIOCGLIFADDR using struct
1431N/A1301. [func] Enable IPv6 support when using sysctl style interface
1431N/A1300. [func] "dig axfr" now reports the number of messages
2028N/A as well as the number of records.
2028N/A1299. [port] See if -ldl is required for OpenSSL? [RT #2672]
1431N/A reflect written requirements.
873N/A1297. [bug] REQUIRE that DNS_DBADD_MERGE only be set when adding
873N/A a rdataset to a zone db in the rbtdb implementation of
2028N/A1296. [bug] dns_name_downcase() enforce requirement that
2028N/A target != NULL or name->buffer != NULL.
2028N/A1295. [func] lwres: probe the system to see what address families
2028N/A1294. [bug] The RTT estimate on unused servers was not aged.
2028N/A1293. [func] Use "dataready" accept filter if available.
873N/A1292. [port] libbind: hpux 11.11 interface scaning.
873N/A1291. [func] Log zone when unable to get private keys to update
2028N/A zone. Log zone when NXT records are missing from
873N/A1290. [bug] libbind: escape '(' and ')' when coverting to
2028N/A1289. [port] Darwin uses (unsigned long) for size_t. [RT #2590]
2028N/A1288. [func] dig: now supports +[no]cl +[no]ttlid.
2028N/A1287. [func] You can now create your own customised printing
2028N/A styles: dns_master_stylecreate() and
2028N/A1285. [port] libbind: hpux: treat all hpux systems as BIG_ENDIAN.
2028N/A1284. [bug] Memory leak in lwres_gnbarequest_parse().
2028N/A1283. [port] libbind: solaris: 64 bit binary compatability.
2028N/A1282. [contrib] Berkeley DB 4.0 sdb implementation from
2028N/A Nuno Miguel Rodrigues <nmr@co.sapo.pt>.
873N/A1281. [bug] "recursion available: {denied,approved}" was too
873N/A1280. [bug] Check that system inet_pton() and inet_ntop() support
1431N/A1278. [port] Openserver: the value FD_SETSIZE depends on whether
873N/A1277. [func] isc_file_openunique() now creates file using mode
1431N/A1276. [bug] ISC_LINK_INIT, ISC_LINK_UNLINK, ISC_LIST_DEQUEUE,
1431N/A __ISC_LINK_UNLINKUNSAFE and __ISC_LIST_DEQUEUEUNSAFE
2028N/A are not C++ compatible, use *_TYPE versions instead.
2028N/A1275. [bug] libbind: LINK_INIT and UNLINK were not compatible with
2028N/A C++, use LINK_INIT_TYPE and UNLINK_TYPE instead.
2028N/A1273. [bug] Reference after free error if dns_dispatchmgr_create()
2028N/A1272. [bug] ns_server_destroy() failed to set *serverp to NULL.
2028N/A1271. [func] libbind: ns_sign2() and ns_sign_tcp() now provide
2028N/A support for compressed TSIG owner names.
2028N/A1270. [func] libbind: res_update can now update IPv6 servers,
2028N/A new function res_findzonecut2().
1431N/A1269. [bug] libbind: get_salen() IPv6 support was broken for OSs
1431N/A1268. [bug] libbind: res_nametotype() and res_nametoclass() were
873N/A1267. [bug] Failure to write pid-file should not be fatal on
873N/A1266. [contrib] 'queryperf' now has EDNS (-e) + DNSSEC DO (-D) support.
873N/A1265. [bug] When verifying that an NXT proves nonexistence, check
873N/A the rcode of the message and only do the matching NXT
873N/A check. That is, for NXDOMAIN responses, check that
873N/A the name is in the range between the NXT owner and
873N/A next name, and for NOERROR NODATA responses, check
873N/A that the type is not present in the NXT bitmap.
873N/A1264. [func] preferred-glue option from BIND 8.3.
873N/A1263. [bug] The dnssec system test failed to remove the correct
873N/A1262. [bug] Dig, host and nslookup were not checking the address
873N/A the answer was coming from against the address it was
2028N/A1261. [port] win32: a make file contained absolute version specific
2028N/A1260. [func] Nsupdate will report the address the update was
2028N/A1249. [bug] Missing masters clause was not handled gracefully.
2028N/A1248. [bug] DESTDIR was not being propogated between makes.
2028N/A1246. [func] New functions isc_sockaddr_issitelocal(),
2028N/A isc_sockaddr_islinklocal(), isc_netaddr_issitelocal()
2028N/A and isc_netaddr_islinklocal().
2028N/A1245. [bug] Treat ENOBUFS, ENOMEM and ENFILE as soft errors for
2028N/A1244. [bug] Receiving a TCP message from a blackhole address would
2028N/A prevent further messages being received over that
2028N/A1243. [bug] It was possible to trigger a REQUIRE() in
2028N/A dns_message_findtype(). [RT #2659]
2028N/A1242. [bug] named-checkzone failed if a journal existed. [RT #2657]
2028N/A1241. [bug] Drop received UDP messsages with a zero source port
2843N/A as these are invariably forged. [RT #2621]
2028N/A1240. [bug] It was possible to leak zone references by
2028N/A specifying an incorrect zone to rndc.
2843N/A1239. [bug] Under certain circumstances named could continue to
2843N/A use a name after it had been freed triggering
2843N/A INSIST() failures. [RT #2614]
2843N/A1238. [bug] It is possible to lockup the server when shutting down
2843N/A if notifies were being processed. [RT #2591]
2843N/A1237. [bug] nslookup: "set q=type" failed.
2843N/A1236. [bug] dns_rdata{class,type}_fromtext() didn't handle non
2843N/A NULL terminated text regions. [RT #2588]
2843N/A1235. [func] Report 'out of memory' errors from openssl.
2843N/A dns_result_register(). DNS_R_SEENINCLUDE should not
2028N/A1233. [bug] The flags field of a KEY record can be expressed in
2028N/A1231. [port] HPUX 11.11 recvmsg() can return spurious EADDRNOTAVAIL.
1902N/A1230. [bug] isccc_cc_isreply() and isccc_cc_isack() were broken.
1902N/A1229. [bug] named would crash if it received a TSIG signed
1902N/A query as part of an AXFR response. [RT #2570]
2843N/A1228. [bug] 'make install' did not depend on 'make all'. [RT #2559]
2843N/A1227. [bug] dns_lex_getmastertoken() now returns ISC_R_BADNUMBER
2843N/A if a number was expected and some other token was
2843N/A1226. [func] Use EDNS for zone refresh queries. [RT #2551]
2843N/A1225. [func] dns_message_setopt() no longer requires that
2843N/A dns_message_renderbegin() to have been called.
2843N/A1224. [bug] 'rrset-order' and 'sortlist' should be additive
2843N/A1223. [func] 'rrset-order' partially works 'cyclic' and 'random'
2028N/A1222. [bug] Specifying 'port *' did not always result in a system
2028N/A selected (non-reserved) port being used. [RT #2537]
2028N/A1221. [bug] Zone types 'master', 'slave' and 'stub' were not being
2028N/A compared case insensitively. [RT #2542]
2606N/A1220. [func] Support for APL rdata type.
873N/A1219. [func] Named now reports the TSIG extended error code when
382N/A signature verification fails. [RT #1651]
2028N/A1218. [bug] Named incorrectly returned SERVFAIL rather than
2606N/A NOTAUTH when there was a TSIG BADTIME error. [RT #2519]
2606N/A1217. [func] Report locations of previous key definition when a
2028N/A1216. [bug] Multiple server clauses for the same server were not
2028N/A1214. [bug] Win32: isc_file_renameunique() could leave zero length
2028N/A1213. [func] Report view associated with client if it is not a
2028N/A standard view (_default or _bind).
2028N/A1212. [port] libbind: 64k answer buffers were causing stack space
2028N/A to be exceeded for certain OS. Use heap space instead.
2028N/A1211. [bug] dns_name_fromtext() incorrectly handled certain
2028N/A valid octal bitlabels. [RT #2483]
2028N/A1210. [bug] libbind: getnameinfo() failed to lookup IPv4 mapped /
2028N/A compatible addresses. [RT #2461]
2028N/A1209. [bug] Dig, host, nslookup were not checking the message ids
2028N/A on the responses. [RT #2454]
2028N/A1208. [bug] dns_master_load*() failed to log a error message if
1431N/A an error was detected when parsing the ownername of
1431N/A1207. [bug] libbind: getaddrinfo() could call freeaddrinfo() with
1431N/A1206. [bug] SERVFAIL and NOTIMP responses to an EDNS query should
2043N/A1205. [bug] OPT, TSIG and TKEY cannot be used to set the "class"
2043N/A1204. [bug] libbind: res_nupdate() failed to update the name
2043N/A server addresses before sending the update.
2043N/A1203. [func] Report locations of previous acl and zone definitions
2043N/A when a duplicate is detected.
2043N/A1202. [func] New functions: cfg_obj_line() and cfg_obj_file().
1431N/A1201. [bug] Require that if 'callbacks' is passed to
2065N/A dns_rdata_fromtext(), callbacks->error and
1431N/A callbacks->warn are initialized.
2028N/A1200. [bug] Log 'errno' that we are unable to convert to
2206N/A1199. [doc] ARM reference to RFC 2157 should have been RFC 1918.
2206N/A1198. [bug] OPT printing style was not consistant with the way the
2206N/A header fields are printed. The DO bit was not reported
2689N/A if set. Report if any of the MBZ bits are set.
2689N/A1197. [bug] Attempts to define the same acl multiple times were not
2689N/A1196. [contrib] update mdnkit to 2.2.3.
2689N/A1195. [bug] Attempts to redefine builtin acls should be caught.
1431N/A1194. [bug] Not all duplicate zone definitions were being detected
2028N/A1193. [bug] dig +besteffort parsing didn't handle packet
1902N/A truncation. dns_message_parse() has new flag
1902N/A DNS_MESSAGE_IGNORETRUNCATION.
1431N/A1192. [bug] The seconds fields in LOC records were restricted
2028N/A to three decimal places. More decimal places should
2028N/A be allowed but warned about.
1431N/A1191. [bug] A dynamic update removing the last non-apex name in
2028N/A a secure zone would fail. [RT #2399]
1431N/A1190. [func] Add the "rndc freeze" and "rndc unfreeze" commands.
2028N/A1189. [bug] On some systems, malloc(0) returns NULL, which
1431N/A could cause the caller to report an out of memory
1431N/A1188. [bug] Dynamic updates of a signed zone would fail if
1431N/A some of the zone private keys were unavailable.
1431N/A1187. [bug] named was incorrectly returning DNSSEC records
1431N/A in negative responses when the DO bit was not set.
1431N/A1186. [bug] isc_hex_tobuffer(,,length = 0) failed to unget the
1431N/A EOL token when reading to end of line.
1431N/A unless RES_INIT is set when calling res_*init().
2026N/A1184. [bug] libbind: call res_ndestroy() if RES_INIT is set
2026N/A when res_*init() is called.
2026N/A1183. [bug] Handle ENOSR error when writing to the internal
2026N/A1182. [bug] The server could throw an assertion failure when
2026N/A constructing a negative response packet.
2026N/A1181. [func] Add the "key-directory" configuration statement,
1431N/A which allows the server to look for online signing
1431N/A keys in alternate directories.
1431N/A1180. [func] dnssec-keygen should always generate keys with
1431N/A protocol 3 (DNSSEC), since it's less confusing
1475N/A1179. [func] Add SIG(0) support to nsupdate.
1431N/A1178. [func] Follow and cache (if appropriate) A6 and other
1431N/A data chains to completion in the additional section.
1431N/A1177. [func] Report view when loading zones if it is not a
1431N/A standard view (_default or _bind). [RT #2270]
2028N/A1176. [doc] Document that allow-v6-synthesis is only performed
2028N/A for clients that are supplied recursive service.
2028N/A1175. [bug] named-checkzone and named-checkconf failed to call
2028N/A dns_result_register() at startup which could
2028N/A result in runtime exceptions when printing
2028N/A "out of memory" errors. [RT #2335]
2028N/A1174. [bug] Win32: add WSAECONNRESET to the expected errors
1431N/A1173. [bug] Potential memory leaks in isc_log_create() and
1431N/A isc_log_settag(). [RT #2336]
1902N/A1172. [doc] Add CERT, GPOS, KX, NAPTR, NSAP, PX and TXT to
1431N/A1171. [func] Added function isc_region_compare(), updated files in
1431N/A1170. [bug] Don't attempt to print the token when a I/O error
2028N/A1169. [func] Identify recursive queries in the query log.
1431N/A1168. [bug] Empty also-notify clauses were not handled. [RT #2309]
1431N/A1167. [contrib] nslint-2.1a3 (from author).
1431N/A1166. [bug] "Not Implemented" should be reported as NOTIMP,
1431N/A1165. [bug] We were rejecting notify-source{-v6} in zone clauses.
1431N/A1164. [bug] Empty masters clauses in slave / stub zones were not
2073N/A handled gracefully. [RT #2262]
1431N/A1163. [func] isc_time_formattimestamp() now includes the year.
1431N/A1162. [bug] The allow-notify option was not accepted in slave
1431N/A1161. [bug] named-checkzone looped on unbalanced brackets.
1431N/A1160. [bug] Generating Diffie-Hellman keys longer than 1024
2028N/A bits could fail. [RT #2241]
2028N/A1159. [bug] MD and MF are not permitted to be loaded by RFC1123.
1902N/A1158. [func] Report the client's address when logging notify
2028N/A1157. [func] match-clients and match-destinations now accept
2028N/A1156. [port] The configure test for strsep() incorrectly
2028N/A succeeded on certain patched versions of
2028N/A1155. [func] Recover from master files being removed from under
2028N/A1154. [bug] Don't attempt to obtain the netmask of a interface
2028N/A if there is no address configured. [RT #2176]
2028N/A1153. [func] 'rndc {stop|halt} -p' now reports the process id
2028N/A of the instance of named being shutdown.
2028N/A1152. [bug] libbind: read buffer overflows.
2028N/A1151. [bug] nslookup failed to check that the arguments to
2028N/A the port, timeout, and retry options were
2028N/A valid integers and in range. [RT #2099]
2028N/A1150. [bug] named incorrectly accepted TTL values
2028N/A containing plus or minus signs, such as
2028N/A1149. [func] New function isc_parse_uint32().
2028N/A1148. [func] 'rndc-confgen -a' now provides positive feedback.
2028N/A1147. [func] Set IPV6_V6ONLY on IPv6 sockets if supported by
2028N/A the OS. listen-on-v6 { any; }; should no longer
2028N/A result in IPv4 queries be accepted. Similarly
2028N/A control { inet :: ... }; should no longer result
2028N/A in IPv4 connections being accepted. This can be
2028N/A overridden at compile time by defining
2028N/A supported by the OS by a new function
2028N/A by printing nothing. [RT #2065]
2065N/A1144. [bug] rndc-confgen would crash if both the -a and -t
2028N/A options were specified. [RT #2159]
2028N/A1143. [bug] When a trusted-keys statement was present and named
2028N/A was built without crypto support, it would leak memory.
2028N/A1142. [bug] dnssec-signzone would fail to delete temporary files
2028N/A in some failure cases. [RT #2144]
2028N/A1141. [bug] When named rejected a control message, it would
2028N/A leak a file descriptor and memory. It would also
2028N/A fail to respond, causing rndc to hang.
2028N/A1140. [bug] rndc-confgen did not accept IPv6 addresses as arguments
2028N/A to the -s option. [RT #2138]
2028N/A1139. [func] It is now possible to flush a given name from the
2028N/A cache(s) via 'rndc flushname name [view]'. [RT #2051]
2028N/A1138. [func] It is now possible to flush a given name from the
2028N/A cache by calling the new function
2028N/A1137. [func] It is now possible to flush a given name from the
2028N/A ADB by calling the new function dns_adb_flushname().
2028N/A1136. [bug] CNAME records synthesized from DNAMEs did not
2028N/A have a TTL of zero as required by RFC2672.
2028N/A1135. [func] You can now override the default syslog() facility for
2028N/A1134. [bug] Multithreaded servers could deadlock in ferror()
2028N/A when reloading zone files. [RT #1951, #1998]
2028N/A1133. [bug] IN6_IS_ADDR_LOOPBACK was not portably defined on
2028N/A platforms without IN6_IS_ADDR_LOOPBACK. [RT #2106]
2028N/A1132. [func] Improve UPDATE prerequisite failure diagnotic messages.
2028N/A1131. [bug] The match-destinations view option did not work with
2028N/A IPv6 destinations. [RT #2073, #2074]
2028N/A1130. [bug] Log messages reporting an out-of-range serial number
2065N/A did not include the out-of-range number but the
1431N/A following token. [RT #2076]
1431N/A1129. [bug] Multithreaded servers could crash under heavy
2028N/A resolution load due to a race condition. [RT #2018]
2028N/A1128. [func] sdb drivers can now provide RR data in either text
2028N/A or wire format, the latter using the new functions
2028N/A dns_sdb_putrdata() and dns_sdb_putnamedrdata().
2028N/A1127. [func] rndc: If the server to contact has multiple addresses,
2028N/A1126. [bug] The server could access a freed event if shut
2028N/A down while a client start event was pending
2028N/A1125. [bug] rndc: -k option was missing from usage message.
2043N/A1124. [doc] dig: +[no]dnssec, +[no]besteffort and +[no]fail
2043N/A are now documented. [RT #2052]
2043N/A1123. [bug] dig +[no]fail did not match description. [RT #2052]
2043N/A1122. [tuning] Resolution timeout reduced from 90 to 30 seconds.
2974N/A1121. [bug] The server could attempt to access a NULL zone
2974N/A table if shut down while resolving.
2043N/A1120. [bug] Errors in options were not fatal. [RT #2002]
2028N/A1118. [bug] On multithreaded servers, a race condition
2028N/A during resolver shutdown. [RT #2029]
1431N/A1117. [port] The configure check for in6addr_loopback incorrectly
1431N/A succeeded on AIX 4.3 when compiling with -O2
1431N/A because the test code was optimized away.
2301N/A1116. [bug] Setting transfers in a server clause, transfers-in,
2301N/A or transfers-per-ns to a value greater than
2301N/A 2147483647 disabled transfers. [RT #2002]
2301N/A1115. [func] Set maximum values for cleaning-interval,
2301N/A heartbeat-interval, interface-interval,
2301N/A max-transfer-idle-in, max-transfer-idle-out,
2301N/A max-transfer-time-in, max-transfer-time-out,
2301N/A statistics-interval of 28 days and
2301N/A sig-validity-interval of 3660 days. [RT #2002]
2301N/A1114. [port] Ignore more accept() errors. [RT #2021]
2301N/A1113. [bug] The allow-update-forwarding option was ignored
2301N/A when specified in a view. [RT #2014]
2301N/A1111. [bug] Multithreaded servers could deadlock processing
2301N/A recursive queries due to a locking hieararchy
2301N/A1110. [bug] dig should only accept valid abbreviations of +options.
2301N/A1109. [bug] nsupdate accepted illegal ttl values.
2301N/A1108. [bug] On Win32, rndc was hanging when named was not running
2301N/A due to failure to select for exceptional conditions
2301N/A1107. [bug] nsupdate could catch an assertion failure if an
2301N/A invalid domain name was given as the argument to
2301N/A1106. [bug] After seeing an out of range TTL, nsupdate would
2301N/A treat all TTLs as out of range. [RT #2001]
2028N/A1105. [port] OpenUNIX 8 enable threads by default. [RT #1970]
1431N/A1104. [bug] Invalid arguments to the transfer-format option
1431N/A could cause an assertion failure. [RT #1995]
1902N/A1102. [doc] Note that query logging is enabled by directing the
2028N/A queries category to a channel.
2206N/A1101. [bug] Array bounds read error in lwres_gai_strerror.
2028N/A1100. [bug] libbind: DNSSEC key ids were computed incorrectly.
2028N/A1098. [bug] libbind: HMAC-MD5 key files are now mode 0600.
2028N/A1097. [func] libbind: RES_PRF_TRUNC for dig.
2028N/A1096. [func] libbind: "DNSSEC OK" (DO) support.
2028N/A1095. [func] libbind: resolver option: no-tld-query. disables
2028N/A trying unqualified as a tld. no_tld_query is also
2028N/A supported for FreeBSD compatability.
2028N/A1094. [func] libbind: add support gcc's format string checking.
2028N/A1093. [doc] libbind: miscellaneous nroff fixes.
2028N/A1092. [bug] libbind: get*by*() failed to check if res_init() had
2028N/A1091. [bug] libbind: misplaced va_end().
2028N/A the amount of memory consumed resulting in garbage
2028N/A address being returned. Alignment calculations were
2028N/A wasting space. We weren't suppressing duplicate
2465N/A1089. [func] libbind: inet_{cidr,net}_{pton,ntop}() now have IPv6
2465N/A1087. [bug] libbind: struct __res_state too large on 64 bit arch.
2028N/A1086. [port] libbind: sunos: old sprintf.
2028N/A1085. [port] libbind: solaris: sys_nerr and sys_errlist do not
2465N/A exist when compiling in 64 bit mode.
2028N/A1084. [cleanup] libbind: gai_strerror() re-written.
2028N/A1083. [bug] The default control channel listened on the
2465N/A wildcard adress, not the loopback as documented.
2028N/A1082. [bug] The -g option to named incorrectly caused logging
2028N/A to be sent to syslog in addition to stderr.
2028N/A1081. [bug] Multicast queries were incorrectly identified
2028N/A based on the source address, not the destination
2028N/A1080. [bug] BIND 8 compatibility: accept bare IP prefixes
2028N/A as the second element of a two-element top level
2028N/A sort list statement. [RT #1964]
1431N/A1079. [bug] BIND 8 compatibility: accept bare elements at top
2301N/A level of sort list treating them as if they were
2028N/A a single element list. [RT #1963]
2301N/A1078. [bug] We failed to correct bad tv_usec values in one case.
2028N/A1077. [func] Do not accept further recursive clients when
2028N/A the total number of of recursive lookups being
2028N/A processed exceeds max-recursive-clients, even
2028N/A if some of the lookups are internally generated.
1431N/A1076. [bug] A badly defined global key could trigger an assertion
1902N/A1075. [bug] Out-of-range network prefix lengths were not
1902N/A1074. [bug] Running out of memory in dump_rdataset() could
1431N/A cause an assertion failure. [RT #1946]
2028N/A1073. [bug] The ADB cache cleaning should also be space driven.
2028N/A1072. [bug] The TCP client quota could be exceeded when
2028N/A recursion occurred. [RT #1937]
2028N/A1071. [bug] Sockets listening for TCP DNS connections
2028N/A specified an excessive listen backlog. [RT #1937]
2028N/A1070. [bug] Copy DNSSEC OK (DO) to response as specified by
2028N/A1068. [bug] errno could be overwritten by catgets(). [RT #1921]
2028N/A1067. [func] Allow quotas to be soft, isc_quota_soft().
2028N/A1066. [bug] Provide a thread safe wrapper for strerror().
1431N/A1065. [func] Runtime support to select new / old style interface
1431N/A1064. [bug] Do not shut down active network interfaces if we
1431N/A are unable to scan the interface list. [RT #1921]
2028N/A1063. [bug] libbind: "make install" was failing on IRIX.
2028N/A1062. [bug] If the control channel listener socket was shut
2028N/A down before server exit, the listener object could
2028N/A1061. [bug] If periodic cache cleaning happened to start
1431N/A while cleaning due to reaching the configured
1431N/A maximum cache size was in progress, the server
1431N/A could catch an assertion failure. [RT #1912]
2028N/A1060. [func] Move refresh, stub and notify UDP retry processing
2028N/A1059. [func] dns_request now support will now retry UDP queries,
2028N/A dns_request_createvia2() and dns_request_createraw2().
2028N/A1058. [func] Limited lifetime ticker timers are now available,
2028N/A1057. [bug] Reloading the server after adding a "file" clause
2028N/A to a zone statement could cause the server to
2028N/A crash due to a typo in change 1016.
2028N/A1056. [bug] Rndc could catch an assertion failure on SIGINT due
2028N/A to an uninitialized variable. [RT #1908]
2028N/A1055. [func] Version and hostname queries can now be disabled
2028N/A using "version none;" and "hostname none;",
2028N/A1054. [bug] On Win32, cfg_categories and cfg_modules need to be
2028N/A exported from the libisccfg DLL.
1431N/A1053. [bug] Dig did not increase its timeout when receiving
2028N/A AXFRs unless the +time option was used. [RT #1904]
2028N/A1052. [bug] Journals were not being created in binary mode
2028N/A resulting in "journal format not recognized" error
2028N/A1051. [bug] Do not ignore a network interface completely just
2028N/A because it has a noncontiguous netmask. Instead,
2028N/A omit it from the localnets ACL and issue a warning.
2028N/A1050. [bug] Log messages reporting malformed IP addresses in
2028N/A address lists such as that of the forwarders option
2028N/A failed to include the correct error code, file
2028N/A name, and line number. [RT #1890]
2028N/A1049. [func] "pid-file none;" will disable writing a pid file.
2028N/A1048. [bug] Servers built with -DISC_MEM_USE_INTERNAL_MALLOC=1
2028N/A1047. [bug] named was incorrectly refusing all requests signed
2028N/A with a TSIG key derived from an unsigned TKEY
2028N/A negotiation with a NOERROR response. [RT #1886]
2028N/A1046. [bug] The help message for the --with-openssl configure
2028N/A option was inaccurate. [RT #1880]
2028N/A1045. [bug] It was possible to skip saving glue for a nameserver
2028N/A1044. [bug] Specifying allow-transfer, notify-source, or
2028N/A notify-source-v6 in a stub zone was not treated
2028N/A1043. [bug] Specifying a transfer-source or transfer-source-v6
2028N/A option in the zone statement for a master zone was
2028N/A not treated as an error. [RT #1876]
2028N/A1042. [bug] The "config" logging category did not work properly.
2028N/A on SIGINT due to an uninitialized variable. [RT #1867]
2028N/A1040. [bug] Multiple listen-on-v6 options with different ports
2028N/A were not accepted. [RT #1875]
2028N/A1039. [bug] Negative responses with CNAMEs in the answer section
2028N/A were cached incorrectly. [RT #1862]
2028N/A1038. [bug] In servers configured with a tkey-domain option,
2028N/A TKEY queries with an owner name other than the root
2028N/A could cause an assertion failure. [RT #1866, #1869]
2028N/A1037. [bug] Negative responses whose authority section contain
2028N/A SOA or NS records whose owner names are not equal
2028N/A equal to or parents of the query name should be
2028N/A1036. [func] Silently drop requests received via multicast as
2028N/A long as there is no final multicast DNS standard.
2028N/A1035. [bug] If we respond to multicast queries (which we
2028N/A currently do not), respond from a unicast address
2028N/A as specified in RFC 1123. [RT #137]
2028N/A1034. [bug] Ignore the RD bit on multicast queries as specified
2028N/A1033. [bug] Always respond to requests with an unsupported opcode
2028N/A with NOTIMP, even if we don't have a matching view
2028N/A or cannot determine the class.
2028N/A the machine hosting the nameserver. This is useful
2028N/A in diagnosing problems with anycast servers.
2028N/A exited with an error rather than defaulting
2028N/A to using the loopback address. [RT #1836]
2028N/A of the configuration file to return a failure
2028N/A status even though they were logged. [RT #1847]
2028N/A in the wrong directory. [RT #1833]
2028N/A1027. [bug] RRs having the reserved type 0 should be rejected.
2028N/A1025. [bug] Don't use multicast addresses to resolve iterative
2028N/A1024. [port] Compilation failed on HP-UX 11.11 due to
2028N/A incompatible use of the SIOCGLIFCONF macro
2028N/A1023. [func] Accept hints without TTLs.
2028N/A1022. [bug] Don't report empty root hints as "extra data".
2028N/A1021. [bug] On Win32, log message timestamps were one month
2028N/A later than they should have been, and the server
2028N/A would exhibit unspecified behavior in December.
2028N/A1020. [bug] IXFR log messages did not distinguish between
2028N/A true IXFRs, AXFR-style IXFRs, and mere version
1431N/A1019. [bug] The value of the lame-ttl option was limited to 18000
1431N/A seconds, not 1800 seconds as documented. [RT #1803]
1431N/A1018. [bug] The default log channel was not always initialized
1431N/A1017. [bug] When specifying TSIG keys to dig and nsupdate using
1431N/A the -k option, they must be HMAC-MD5 keys. [RT #1810]
1779N/A1016. [bug] Slave zones with no backup file were re-transferred
1779N/A1015. [bug] Log channels that had a "versions" option but no
1779N/A "size" option failed to create numbered log
1779N/A1014. [bug] Some queries would cause statistics counters to
1779N/A increment more than once or not at all. [RT #1321]
2580N/A1013. [bug] It was possible to cancel a query twice when marking
1431N/A a server as bogus or by having a blackhole acl.
1507N/A1012. [bug] The -p option to named did not behave as documented.
1779N/A1011. [cleanup] Removed isc_dir_current().
1779N/A1010. [bug] The server could attempt to execute a command channel
1779N/A command after initiating server shutdown, causing
1779N/A an assertion failure. [RT #1766]
1779N/A1009. [port] OpenUNIX 8 support. [RT #1728]
1779N/A1006. [bug] If a KEY RR was found missing during DNSSEC validation,
2028N/A an assertion failure could subsequently be triggered
1779N/A in the resolver. [RT #1763]
1431N/A1005. [bug] Don't copy nonzero RCODEs from request to response.
1779N/A1004. [port] Deal with recvfrom() returning EHOSTDOWN. [RT #1770]
1431N/A1003. [func] Add the +retry option to dig.
1431N/A including the file name and line number. [RT #1759]
1431N/A1001. [bug] win32 socket code doio_recv was not catching a
1431N/A WSACONNRESET error when a client was timing out
1431N/A the request and closing its socket. [RT #1745]
1431N/A1000. [bug] BIND 8 compatibility: accept "HESIOD" as an alias
1431N/A 999. [func] "rndc retransfer zone [class [view]]" added.
1431N/A 998. [func] named-checkzone now has arguments to specify the
1431N/A chroot directory (-t) and working directory (-w).
1431N/A 997. [func] Add support for RSA-SHA1 keys (RFC3110).
1431N/A 996. [func] Issue warning if the configuration filename contains
2028N/A 995. [bug] dig, host, nslookup: using a raw IPv6 address as a
1431N/A target address should be fatal on a IPv4 only system.
1431N/A 994. [func] Treat non-authoritative responses to queries for type
1431N/A NS as referrals even if the NS records are in the
1431N/A answer section, because BIND 8 servers incorrectly
1431N/A send them that way. This is necessary for DNSSEC
1431N/A validation of the NS records of a secure zone to
2028N/A succeed when the parent is a BIND 8 server. [RT #1706]
1902N/A 993. [func] dig: -v now reports the version.
1902N/A 992. [doc] dig: ~/.digrc is now documented.
1902N/A 991. [func] Lower UDP refresh timeout messages to level
1902N/A 990. [bug] The rndc-confgen man page was not installed.
1902N/A 989. [bug] Report filename if $INCLUDE fails for file related
1902N/A 988. [bug] 'additional-from-auth no;' did not work reliably
1968N/A in the case of queries answered from the cache.
1902N/A 987. [bug] "dig -help" didn't show "+[no]stats".
2028N/A 986. [bug] "dig +noall" failed to clear stats and command
2028N/A 985. [func] Consider network interfaces to be up iff they have
2073N/A a nonzero IP address rather than based on the
1431N/A 984. [bug] Multithreading should be enabled by default on
1968N/A Solaris 2.7 and newer, but it wasn't.
1431N/A 983. [func] The server now supports generating IXFR difference
1431N/A sequences for non-dynamic zones by comparing zone
2028N/A versions, when enabled using the new config
2028N/A option "ixfr-from-differences". [RT #1727]
2028N/A 982. [func] If "memstatistics-file" is set in options the memory
1902N/A statistics will be written to it.
1902N/A 981. [func] The dnssec tools can now take multiple '-r randomfile'
2028N/A 980. [bug] Incoming zone transfers restarting after an error
1431N/A could trigger an assertion failure. [RT #1692]
2028N/A 979. [func] Incremental master file dumping. dns_master_dumpinc(),
2043N/A dns_master_dumptostreaminc(), dns_dumpctx_attach(),
2043N/A dns_dumpctx_detach(), dns_dumpctx_cancel(),
2028N/A dns_dumpctx_db() and dns_dumpctx_version().
1431N/A 978. [bug] dns_db_attachversion() had an invalid REQUIRE()
1431N/A 977. [bug] Improve "not at top of zone" error message.
1431N/A 976. [func] named-checkconf can now test load master zones
1431N/A (named-checkconf -z). [RT #1468]
1431N/A 975. [bug] "max-cache-size default;" as a view option
1431N/A caused an assertion failure.
1475N/A 974. [bug] "max-cache-size unlimited;" as a global option
2028N/A 973. [bug] Failed to log the question name when logging:
2028N/A "bad zone transfer request: non-authoritative zone
873N/A 972. [bug] The file modification time code in
zone.c was using the
873N/A wrong epoch. [RT #1667]
1431N/A 970. [func] 'max-journal-size' can now be used to set a target
1902N/A 969. [func] dig now supports the undocumented dig 8 feature
382N/A of allowing arbitrary labels, not just dotted
2028N/A decimal quads, with the -x option. This can be
382N/A used to conveniently look up RFC2317 names as in
2028N/A "dig -x 10.0.0.0-127". [RT #827, #1576, #1598]
2028N/A 968. [bug] On win32, the isc_time_now() function was unnecessarily
2028N/A calling strtime(). [RT #1671]
382N/A 967. [bug] On win32, the link for bindevt was not including the
873N/A required resource file to enable the event viewer
873N/A to interpret the error messages in the event log,
1431N/A 965. [bug] Including data other than root server NS and A
1431N/A records in the root hint file could cause a rbtdb
2028N/A node reference leak. [RT #1581, #1618]
1431N/A 964. [func] Warn if data other than root server NS and A records
2028N/A are found in the root hint file. [RT #1581, #1618]
2028N/A 963. [bug] Bad ISC_LANG_ENDDECLS. [RT #1645]
2028N/A 962. [bug] libbind: bad "#undef", don't attempt to install
2028N/A 961. [bug] Tried to use a IPV6 feature when ISC_PLATFORM_HAVEIPV6
2028N/A was not defined. [RT #1482]
2028N/A 960. [port] liblwres failed to build on systems with support for
2028N/A getrrsetbyname() in the OS. [RT #1592]
2028N/A 959. [port] On FreeBSD, determine the number of CPUs by calling
2028N/A 958. [port] ssize_t is not available on all platforms. [RT #1607]
2028N/A 956. [bug] ns_g_autorndcfile changed to ns_g_keyfile
2028N/A change #953. win32 .make file for rndc-confgen
2028N/A 955. [bug] When using views, the zone's class was not being
2028N/A inherited from the view's class. [RT #1583]
2028N/A 954. [bug] When requesting AXFRs or IXFRs using dig, host, or
2028N/A nslookup, the RD bit should not be set as zone
2028N/A transfers are inherently nonrecursive. [RT #1575]
2026N/A named and rndc will look for this file and use
2026N/A it to configure a default control channel key
2026N/A if not already configured using a different
2028N/A it must be created by manually running
2028N/A 952. [bug] The server required manual intervention to serve the
2026N/A affected zones if it died between creating a journal
2028N/A and committing the first change to it.
2028N/A 951. [bug] CFLAGS was not passed to the linker when
2028N/A linking some of the test programs under
1431N/A 950. [bug] Explicit TTLs did not properly override $TTL
1431N/A due to a bug in change 834. [RT #1558]
1431N/A 949. [bug] host was unable to print records larger than 512
1431N/A 948. [port] Integrated support for building on Windows NT /
1431N/A 947. [bug] dns_rdata_soa_t had a badly named element "mname" which
1431N/A was really the RNAME field from RFC1035. To avoid
1431N/A confusion and silent errors that would occur it the
2028N/A "origin" and "mname" elements were given their correct
1431N/A names "mname" and "rname" respectively, the "mname"
2026N/A element is renamed to "contact".
2026N/A configuration parser syntax tables, and therefore
2026N/A 945. [func] Add the new view-specific options
2026N/A "match-destinations" and "match-recursive-only".
2026N/A 944. [func] Check for expired signatures on load.
2065N/A 943. [bug] The server could crash when receiving a command
2026N/A via rndc if the configuration file listed only
2026N/A nonexistent keys in the controls statement. [RT #1530]
2026N/A 942. [port] libbind: GETNETBYADDR_ADDR_T was not correctly
1431N/A 941. [bug] The configuration checker crashed if a slave
1431N/A zone didn't contain a masters statement. [RT #1514]
1431N/A 940. [bug] Double zone locking failure on error path. [RT #1510]
1431N/A 939. [port] Add the --disable-linux-caps option to configure for
1431N/A systems that manage capabilities outside of named.
2028N/A 937. [bug] A race when shutting down a zone could trigger a
2028N/A INSIST() failure. [RT #1034]
1431N/A 936. [func] Warn about IPv4 addresses that are not complete
1431N/A 935. [bug] inet_pton failed to reject leading zeros.
1431N/A 934. [port] Deal with systems where accept() spuriously returns
1431N/A 933. [bug] configure failed doing libbind on platforms not
1431N/A supported by BIND 8. [RT #1496]
1902N/A 932. [bug] Use INSTALL_SCRIPT, not INSTALL_PROGRAM,
2028N/A 931. [bug] The controls statement only attempted to verify
2028N/A messages using the first key in the key list.
2028N/A 930. [func] Query performance testing tool added as
2028N/A 928. [bug] nsupdate would send empty update packets if the
2028N/A send (or empty line) command was run after
2028N/A another send but before any new updates or
2028N/A prerequisites were specified. It should simply
1431N/A 927. [bug] Don't hold the zone lock for the entire dump to disk.
1431N/A 926. [bug] The resolver could deadlock with the ADB when
1431N/A shutting down (multithreaded builds only).
1431N/A 925. [cleanup] Remove openssl from the distribution; require that
1431N/A --with-openssl be specified if DNSSEC is needed.
1431N/A 924. [port] Extend support for pre-RFC2133 IPv6 implementation.
1431N/A 923. [bug] Multiline TSIG secrets (and other multiline strings)
1431N/A 922. [func] Added two new lwres_getrrsetbyname() result codes,
1902N/A 921. [bug] lwres returned an incorrect error code if it received
1895N/A 920. [func] Increase the lwres receive buffer size to 16K.
2028N/A 918. [func] In nsupdate, TSIG errors are no longer treated as
2028N/A 917. [func] New nsupdate command 'key', allowing TSIG keys to
2028N/A be specified in the nsupdate command stream rather
873N/A 916. [bug] Specifying type ixfr to dig without specifying
873N/A a serial number failed in unexpected ways.
873N/A 915. [func] The named-checkconf and named-checkzone programs
873N/A now have a '-v' option for printing their version.
2028N/A 914. [bug] Global 'server' statements were rejected when
1902N/A using views, even though they were accepted
2028N/A 913. [bug] Cache cleaning was not sufficiently aggressive.
382N/A 912. [bug] Attempts to set the 'additional-from-cache' or
2028N/A 'additional-from-auth' option to 'no' in a
2028N/A server with recursion enabled will now
2028N/A be ignored and cause a warning message.
873N/A 910. [port] Some pre-RFC2133 IPv6 implementations do not define
873N/A IN6ADDR_ANY_INIT. [RT #1416]
2962N/A 908. [func] New program, rndc-confgen, to simplify setting up rndc.
2962N/A 907. [func] The ability to get entropy from either the
2962N/A random device, a user-provided file or from
2962N/A the keyboard was migrated from the DNSSEC tools
382N/A to libisc as isc_entropy_usebestsource().
2028N/A 906. [port] Separated the system independent portion of
382N/A 905. [bug] Configuring a forward "zone" for the root domain
1452N/A 904. [bug] The server would leak memory if attempting to use
1452N/A an expired TSIG key. [RT #1406]
2028N/A 903. [bug] dig should not crash when receiving a TCP packet
2028N/A 902. [bug] The -d option was ignored if both -t and -g were also
2028N/A string of FreeBSD systems; configure and
2028N/A due to inappropriate use of a void value.
2028N/A [RT #1372, #1373, #1386, #1387, #1395]
2028N/A 898. [bug] "dig" failed to set a nonzero exit status
2028N/A on UDP query timeout. [RT #1323]
2028N/A string of UnixWare systems; configure now recognizes
2028N/A 896. [bug] If a configuration file is set on named's command line
2028N/A and it has a relative pathname, the current directory
2028N/A (after any possible jailing resulting from named -t)
2028N/A will be prepended to it so that reloading works
2028N/A properly even when a directory option is present.
2028N/A 895. [func] New function, isc_dir_current(), akin to POSIX's
1431N/A 894. [bug] When using the DNSSEC tools, a message intended to warn
1431N/A when the keyboard was being used because of the lack
1431N/A of a suitable random device was not being printed.
2028N/A 893. [func] Removed isc_file_test() and added isc_file_exists()
2028N/A for the basic functionality that was being added
1431N/A 891. [bug] Return an error when a SIG(0) signed response to
873N/A an unsigned query is seen. This should actually
873N/A do the verification, but it's not currently
1431N/A 890. [cleanup] The man pages no longer require the mandoc macros
1431N/A and should now format cleanly using most versions of
2028N/A nroff, and HTML versions of the man pages have been
1902N/A added. Both are generated from DocBook source.
382N/A 889. [port] Eliminated blank lines before .TH in nroff man
873N/A pages since they cause problems with some versions
382N/A 888. [bug] Don't die when using TKEY to delete a nonexistent
1431N/A 887. [port] Detect broken compilers that can't call static
1431N/A functions from inline functions. [RT #1212]
1902N/A 866. [func] Close debug only file channels when debug is set to
2028N/A 865. [bug] The new configuration parser did not allow
2028N/A the optional debug level in a "severity debug"
2028N/A clause of a logging channel to be omitted.
2028N/A This is now allowed and treated as "severity
2028N/A debug 1;" like it does in BIND 8.2.4, not as
2028N/A "severity debug 0;" like it did in BIND 9.1.
2026N/A 864. [cleanup] Multithreading is now enabled by default on
2026N/A OSF1, Solaris 2.7 and newer, AIX, IRIX, and HP-UX.
2026N/A 863. [bug] If an error occurred while an outgoing zone transfer
2026N/A was starting up, the server could access a domain
2026N/A name that had already been freed when logging a
2026N/A message saying that the transfer was starting.
2026N/A 862. [bug] Use after realloc(), non portable pointer arithmetic in
2028N/A 861. [port] Add support for Mac OS X, by making it equivalent
2028N/A file shipped with Mac OS X. [RT #1355]
2028N/A 860. [func] Drop cross class glue in zone transfers.
2026N/A 859. [bug] Cache cleaning now won't swamp the CPU if there
873N/A is a persistent overlimit condition.
2028N/A 858. [func] isc_mem_setwater() no longer requires that when the
2028N/A callback function is non-NULL then its hi_water
1431N/A argument must be greater than its lo_water argument
1431N/A (they can now be equal) or that they be non-zero.
2028N/A 857. [cleanup] Use ISC_MAGIC() to define all magic numbers for
1902N/A structs, for our friends in EBCDIC-land.
2043N/A 856. [func] Allow partial rdatasets to be returned in answer and
2043N/A authority sections to help non-TCP capable clients
2043N/A recover from truncation. [RT #1301]
1431N/A 855. [bug] Stop spurious "using RFC 1035 TTL semantics" warnings.
2028N/A 854. [bug] The config parser didn't properly handle config
2028N/A options that were specified in units of time other
2028N/A 853. [bug] configure_view_acl() failed to detach existing acls.
2028N/A 852. [bug] Handle responses from servers which do not know
2028N/A 851. [cleanup] The obsolete support-ixfr option was not properly
2028N/A 850. [bug] dns_rbt_findnode() would not find nodes that were
2028N/A split on a bitstring label somewhere other than in
2028N/A the last label of the node. [RT #1351]
2028N/A 848. [func] A minimum max-cache-size of two megabytes is enforced
2028N/A 847. [func] Added isc_file_test(), which currently only has
2028N/A some very basic functionality to test for the
1431N/A existence of a file, whether a pathname is absolute,
2028N/A or whether a pathname is the fundamental representation
2028N/A of the current directory. It is intended that this
2301N/A function can be expanded to test other things a
2301N/A programmer might want to know about a file.
2301N/A 846. [func] A non-zero 'param' to dst_key_generate() when making an
2301N/A hmac-md5 key means that good entropy is not required.
2301N/A 845. [bug] The access rights on the public file of a symmetric
2301N/A key are now restricted as soon as the file is opened,
2301N/A rather than after it has been written and closed.
2301N/A or if any inet phrase of a controls statement is
2301N/A lacking a keys clause, then a key will be automatically
2693N/A will use this file only if its normal configuration
2301N/A file, or one provided on the command line, does not
2962N/A 842. [func] 'rndc flush' now takes an optional view.
2301N/A 841. [bug] When sdb modules were not declared threadsafe, their
2301N/A create and destroy functions were not serialized.
2301N/A 840. [bug] The config file parser could print the wrong file
2962N/A name if an error was detected after an included file
2301N/A 839. [func] Dump packets for which there was no view or that the
2301N/A class could not be determined to category "unmatched".
2301N/A 837. [cleanup] Multithreading is now enabled by default only on
2301N/A OSF1, Solaris 2.7 and newer, and AIX.
2962N/A 836. [func] Upgraded libtool to 1.4.
2962N/A 835. [bug] The dispatcher could enter a busy loop if
2962N/A it got an I/O error receiving on a UDP socket.
2301N/A 834. [func] Accept (but warn about) master files beginning with
2301N/A an SOA record without an explicit TTL field and
2301N/A lacking a $TTL directive, by using the SOA MINTTL
2301N/A as a default TTL. This is for backwards compatibility
2301N/A with old versions of BIND 8, which accepted such
2693N/A files without warning although they are illegal
2301N/A all the integer-valued fields of the SOA RR.
2301N/A should depend on --sysconfdir like it does in named.
2301N/A 830. [func] Implement 'rndc status'.
2693N/A 829. [bug] The DNS_R_ZONECUT result code should only be returned
2301N/A when an ANY query is made with DNS_DBFIND_GLUEOK set.
2301N/A In all other ANY query cases, returning the delegation
2301N/A 828. [bug] The errno value from recvfrom() could be overwritten
2301N/A by logging code. [RT #1293]
2301N/A 827. [bug] When an IXFR protocol error occurs, the slave
2301N/A 826. [bug] Some IXFR protocol errors were not detected.
2301N/A 825. [bug]
zone.c:ns_query() detached from the wrong zone
2301N/A 824. [bug] Correct line numbers reported by dns_master_load().
2301N/A 823. [func] The output of "dig -h" now goes to stdout so that it
2301N/A can easily be piped through "more". [RT #1254]
2301N/A 822. [bug] Sending nxrrset prerequisites would crash nsupdate.
2301N/A 821. [bug] The program name used when logging to syslog should
2693N/A be stripped of leading path components.
2301N/A 820. [bug] Name server address lookups failed to follow
2693N/A A6 chains into the glue of local authoritative
2301N/A 819. [bug] In certain cases, the resolver's attempts to
2301N/A restart an address lookup at the root could cause
2301N/A the fetch to deadlock (with itself) instead of
2301N/A 818. [bug] Certain pathological responses to ANY queries could
2301N/A cause an assertion failure. [RT #1218]
2301N/A 817. [func] Adjust timeouts for dialup zone queries.
2301N/A 816. [bug] Report potential problems with log file accessibility
2301N/A at configuration time, since such problems can't
2301N/A reliably be reported at the time they actually occur.
2301N/A 815. [bug] If a log file was specified with a path separator
2301N/A character (
i.e. "/") in its name and the directory
2301N/A did not exist, the log file's name was treated as
2301N/A though it were the directory name. [RT #1189]
2693N/A 814. [bug] Socket objects left over from accept() failures
2693N/A were incorrectly destroyed, causing corruption
2301N/A of socket manager data structures.
2301N/A 813. [bug] File descriptors exceeding FD_SETSIZE were handled
2301N/A 812. [bug] dig sometimes printed incomplete IXFR responses
2301N/A due to an uninitialized variable. [RT #1188]
2301N/A 811. [bug] Parentheses were not quoted in zone dumps. [RT #1194]
2301N/A 810. [bug] The signer name in SIG records was not properly
2301N/A 809. [bug] Configuring a non-local address as a transfer-source
2301N/A could cause an assertion failure during load.
2301N/A 808. [func] Add 'rndc flush' to flush the server's cache.
2693N/A 807. [bug] When setting up TCP connections for incoming zone
2301N/A transfers, the transfer-source port was not
2301N/A 806. [bug] DNS_R_SEENINCLUDE was failing to propagate back up
2301N/A the calling stack to the zone maintence level, causing
2301N/A zones to not reload when an included file was touched
2301N/A but the top-level zone file was not.
2301N/A 805. [bug] When using "forward only", missing root hints should
2301N/A not cause queries to fail. [RT #1143]
2301N/A 804. [bug] Attempting to obtain entropy could fail in some
2301N/A situations. This would be most common on systems
2301N/A with user-space threads. [RT #1131]
2301N/A 803. [bug] Treat all SIG queries as if they have the CD bit set,
2301N/A otherwise no data will be returned [RT #749]
2301N/A 802. [bug] DNSSEC key tags were computed incorrectly in almost
2693N/A 801. [bug] nsupdate should treat lines beginning with ';' as
2301N/A 800. [bug] dnssec-signzone produced incorrect statistics for
2693N/A 799. [bug] The ADB didn't find AAAA glue in a zone unless A6
2301N/A 798. [bug] nsupdate should be able to reject bad input lines
2301N/A 797. [func] Issue a warning if the 'directory' option contains
2693N/A 796. [func] When a size limit is associated with a log file,
2301N/A only roll it when the size is reached, not every
2301N/A time the log file is opened. [RT #1096]
2693N/A 795. [func] Add the +multiline option to dig. [RT #1095]
2693N/A 794. [func] Implement the "port" and "default-port" statements
2301N/A 793. [cleanup] The DNSSEC tools could create filenames that were
2693N/A illegal or contained shell metacharacters. They
2693N/A now use a different text encoding of names that
2301N/A doesn't have these problems. [RT #1101]
2301N/A 792. [cleanup] Replace the OMAPI command channel protocol with a
2301N/A 791. [bug] The command channel now works over IPv6.
2693N/A 790. [bug] Wildcards created using dynamic update or IXFR
2693N/A could fail to match. [RT #1111]
2301N/A 789. [bug] The "localhost" and "localnets" ACLs did not match
2301N/A when used as the second element of a two-element
2301N/A 788. [func] Add the "match-mapped-addresses" option, which
2301N/A causes IPv6 v4mapped addresses to be treated as
2301N/A IPv4 addresses for the purpose of acl matching.
2301N/A 787. [bug] The DNSSEC tools failed to downcase domain
2301N/A names when mapping them into file names.
2301N/A 785. [bug] A race condition in the resolver could cause
2301N/A an assertion failure. [RT #673, #872, #1048]
2301N/A 784. [bug] nsupdate and other programs would not quit properly
2301N/A if some signals were blocked by the caller. [RT #1081]
2530N/A 783. [bug] Following CNAMEs could cause an assertion failure
2530N/A when either using an sdb database or under very
2530N/A 782. [func] Implement the "serial-query-rate" option.
2301N/A 781. [func] Avoid error packet loops by dropping duplicate FORMERR
2301N/A 780. [bug] Error handling code dealing with out of memory or
2301N/A other rare errors could lead to assertion failures
2301N/A by calling functions on unitialized names. [RT #1065]
2301N/A 779. [func] Added the "minimal-responses" option.
1968N/A 778. [bug] When starting cache cleaning, cleaning_timer_action()
1968N/A returned without first pausing the iterator, which
1968N/A could cause deadlock. [RT #998]
2028N/A 777. [bug] An empty forwarders list in a zone failed to override
2028N/A global forwarders. [RT #995]
1968N/A 776. [func] Improved error reporting in denied messages. [RT #252]
1431N/A 774. [func] max-cache-size is implemented.
1968N/A 773. [func] Added isc_rwlock_trylock() to attempt to lock without
1902N/A 772. [bug] Owner names could be incorrectly omitted from cache
1431N/A dumps in the presence of negative caching entries.
2028N/A 771. [cleanup] TSIG errors related to unsynchronized clocks
2028N/A are logged better. [RT #919]
2028N/A 770. [func] Add the "edns yes_or_no" statement to the server
1431N/A 769. [func] Improved error reporting when parsing rdata. [RT #740]
1431N/A 768. [bug] The server did not emit an SOA when a CNAME
1431N/A or DNAME chain ended in NXDOMAIN in an
1431N/A 766. [bug] A few cases in query_find() could leak fname.
1431N/A This would trigger the mpctx->allocated == 0
2028N/A assertion when the server exited.
1902N/A [RT #739, #776, #798, #812, #818, #821, #845,
1635N/A 765. [func] ACL names are once again case insensitive, like
1431N/A 764. [func] Configuration files now allow "include" directives
1968N/A in more places, such as inside the "view" statement.
1431N/A 763. [func] Configuration files no longer have reserved words.
2028N/A 761. [bug] _REENTRANT was still defined when building with
1431N/A 760. [contrib] Significant enhancements to the pgsql sdb driver.
1431N/A 759. [bug] The resolver didn't turn off "avoid fetches" mode
1431N/A when restarting, possibly causing resolution
1431N/A to fail when it should not. This bug only affected
1431N/A platforms which support both IPv4 and IPv6. [RT #927]
2028N/A 758. [bug] The "avoid fetches" code did not treat negative
1902N/A cache entries correctly, causing fetches that would
1431N/A be useful to be avoided. This bug only affected
2028N/A platforms which support both IPv4 and IPv6. [RT #927]
2028N/A 757. [func] Log zone transfers.
1431N/A 756. [bug] dns_zone_load() could "return" success when no master
2028N/A 754. [bug] Certain failure conditions sending UDP packets
1431N/A could cause the server to retry the transmission
1431N/A 753. [bug] dig, host, and nslookup would fail to contact a
1431N/A remote server if getaddrinfo() returned an IPv6
2028N/A address on a system that doesn't support IPv6.
2028N/A 752. [func] Correct bad tv_usec elements returned by
1431N/A 751. [func] Log successful zone loads / transfers. [RT #898]
1431N/A 750. [bug] A query should not match a DNAME whose trust level
1431N/A 749. [bug] When a query matched a DNAME in a secure zone, the
1895N/A server did not return the signature of the DNAME.
2028N/A 747. [bug] The code to determine whether an IXFR was possible
2028N/A did not properly check for a database that could
2028N/A not have a journal. [RT #865, #908]
2028N/A 746. [bug] The sdb didn't clone rdatasets properly, causing
2028N/A a crash when the server followed delegations. [RT #905]
2028N/A 745. [func] Report the owner name of records that fail
2028N/A semantic checks while loading.
2028N/A 744. [bug] When returning DNS_R_CNAME or DNS_R_DNAME as the
2028N/A result of an ANY or SIG query, the resolver failed
2028N/A to setup the return event's rdatasets, causing an
2028N/A assertion failure in the query code. [RT #881]
2028N/A 743. [bug] Receiving a large number of certain malformed
2028N/A answers could cause named to stop responding.
2028N/A 741. [port] Support openssl-engine. [RT #709]
2028N/A 740. [port] Handle openssl library mismatches slightly better.
2028N/A assuming it will be there for only a predefined
2028N/A 738. [bug] If a non-threadsafe sdb driver supported AXFR and
2028N/A received an AXFR request, it would deadlock or die
2028N/A with an assertion failure. [RT #852]
2028N/A 736. [func] New functions isc_task_{begin,end}exclusive().
2028N/A 735. [doc] Add BIND 4 migration notes.
2028N/A 734. [bug] An attempt to re-lock the zone lock could occur if
2028N/A the server was shutdown during a zone tranfer.
2028N/A 733. [bug] Reference counts of dns_acl_t objects need to be
2028N/A locked but were not. [RT #801, #821]
2028N/A 732. [bug] Glue with 0 TTL could also cause SERVFAIL. [RT #828]
2028N/A 731. [bug] Certain zone errors could cause named-checkzone to
2028N/A fail ungracefully. [RT #819]
2028N/A 730. [bug] lwres_getaddrinfo() returns the correct result when
1191N/A it fails to contact a server. [RT #768]
2843N/A 729. [port] pthread_setconcurrency() needs to be called on Solaris.
2843N/A 728. [bug] Fix comment processing on master file directives.
2843N/A 727. [port] Work around OS bug where accept() succeeds but
2843N/A fails to fill in the peer address of the accepted
2843N/A connection, by treating it as an error rather than
2843N/A an assertion failure. [RT #809]
2843N/A 726. [func] Implement the "trace" and "notrace" commands in rndc.
2843N/A 725. [bug] Installing man pages could fail.
2962N/A 724. [func] New libisc functions isc_netaddr_any(),
2843N/A 723. [bug] Referrals whose NS RRs had a 0 TTL caused the resolver
2962N/A to return DNS_R_SERVFAIL. [RT #783]
2962N/A 722. [func] Allow incremental loads to be canceled.
2962N/A 721. [cleanup] Load manager and dns_master_loadfilequota() are no
2843N/A 720. [bug] Server could enter infinite loop in
2843N/A 719. [bug] Rapid reloads could trigger an assertion failure.
2843N/A 717. [bug] Certain TKEY processing failure modes could
2843N/A reference an uninitialized variable, causing the
2843N/A 716. [bug] The first line of a $INCLUDE master file was lost if
2843N/A an origin was specified. [RT #744]
2843N/A 715. [bug] Resolving some A6 chains could cause an assertion
2843N/A 714. [bug] Preserve interval timers across reloads unless changed.
2843N/A 713. [func] named-checkconf takes '-t directory' similar to named.
2843N/A 712. [bug] Sending a large signed update message caused an
2843N/A assertion failure. [RT #718]
2843N/A 711. [bug] The libisc and liblwres implementations of
2843N/A inet_ntop contained an off by one error.
2843N/A 710. [func] The forwarders statement now takes an optional
2843N/A 709. [bug] ANY or SIG queries for data with a TTL of 0
2843N/A would return SERVFAIL. [RT #620]
2843N/A 708. [bug] When building with --with-openssl, the openssl headers
2843N/A included with BIND 9 should not be used. [RT #702]
2843N/A 707. [func] The "filename" argument to named-checkzone is no
2843N/A longer optional, to reduce confusion. [RT #612]
2843N/A 706. [bug] Zones with an explicit "allow-update { none; };"
2843N/A were considered dynamic and therefore not reloaded
2843N/A on SIGHUP or "rndc reload".
2962N/A 705. [port] Work out resource limit type for use where rlim_t is
2962N/A 704. [port] RLIMIT_NOFILE is not available on all platforms.
2843N/A use 127.0.0.1 instead. [RT #693]
2843N/A 701. [func] Root hints are now fully optional. Class IN
2962N/A views use compiled-in hints by default, as
2843N/A before. Non-IN views with no root hints now
2843N/A provide authoritative service but not recursion.
2962N/A A warning is logged if a view has neither root
2962N/A hints nor authoritative data for the root. [RT #696]
2962N/A 700. [bug] $GENERATE range check was wrong. [RT #688]
2962N/A 699. [bug] The lexer mishandled empty quoted strings. [RT #694]
2843N/A 698. [bug] Aborting nsupdate with ^C would lead to several
2843N/A 697. [bug] nsupdate was not compatible with the undocumented
2843N/A BIND 8 behavior of ignoring TTLs in "update delete"
2962N/A 696. [bug] lwresd would die with an assertion failure when passed
2962N/A a zero-length name. [RT #692]
2962N/A 695. [bug] If the resolver attempted to query a blackholed or
2984N/A bogus server, the resolution would fail immediately.
2984N/A 694. [bug] $GENERATE did not produce the last entry.
2984N/A the server to crash while loading.
2984N/A 692. [bug] Deal with systems that have getaddrinfo() but not
2843N/A 691. [bug] Configuring per-view forwarders caused an assertion
2843N/A 690. [func] $GENERATE now supports DNAME. [RT #654]
2843N/A 689. [doc] man pages are now installed. [RT #210]
2843N/A 688. [func] "make tags" now works on systems with the
2843N/A 687. [bug] Only say we have IPv6, with sufficent functionality,
2843N/A if it has actually been tested. [RT #586]
2843N/A 686. [bug] dig and nslookup can now be properly aborted during
2843N/A blocking operations. [RT #568]
2962N/A 684. [bug] Memory leak with view forwarders. [RT #656]
2843N/A 683. [bug] File descriptor leak in isc_lex_openfile().
2843N/A 682. [bug] nslookup displayed SOA records incorrectly. [RT #665]
2962N/A 681. [bug] $GENERATE specifying output format was broken. [RT #653]
2843N/A 680. [bug] dns_rdata_fromstruct() mishandled options bigger
2962N/A 679. [bug] $INCLUDE could leak memory and file descriptors on
2843N/A 678. [bug] "transfer-format one-answer;" could trigger an assertion
2843N/A 677. [bug] dnssec-signzone would occasionally use the wrong ttl
2843N/A for database operations and fail. [RT #643]
2843N/A 676. [bug] Log messages about lame servers to category
2843N/A 'lame-servers' rather than 'resolver', so as not
2843N/A to be gratuitously incompatible with BIND 8.
2843N/A 675. [bug] TKEY queries could cause the server to leak
2843N/A 674. [func] Allow messages to be TSIG signed / verified using
2843N/A a offset from the current time.
2843N/A 673. [func] The server can now convert RFC1886-style recursive
2843N/A lookup requests into RFC2874-style lookups, when
2843N/A enabled using the new option "allow-v6-synthesis".
2843N/A 672. [bug] The wrong time was in the "time signed" field when
2843N/A replying with BADTIME error.
2843N/A 671. [bug] The message code was failing to parse a message with
2843N/A no question section and a TSIG record. [RT #628]
2843N/A 670. [bug] The lwres replacements for getaddrinfo and
2843N/A getipnodebyname didn't properly check for the
2843N/A existence of the sockaddr sa_len field.
2843N/A 669. [bug] dnssec-keygen now makes the public key file
2843N/A non-world-readable for symmetric keys. [RT #403]
2843N/A 668. [func] named-checkzone now reports multiple errors in master
2843N/A 667. [bug] On Linux, running named with the -u option and a
2843N/A non-world-readable configuration file didn't work.
2843N/A 666. [bug] If a request sent by dig is longer than 512 bytes,
2843N/A 665. [bug] Signed responses were not sent when the size of the
2843N/A TSIG + question exceeded the maximum message size.
2843N/A 664. [bug] The t_tasks and t_timers module tests are now skipped
2843N/A when building without threads, since they require
2984N/A 663. [func] Accept a size_spec, not just an integer, in the
2843N/A (unimplemented and ignored) max-ixfr-log-size option
2843N/A for compatibility with recent versions of BIND 8.
2843N/A 662. [bug] dns_rdata_fromtext() failed to log certain errors.
2843N/A 661. [bug] Certain UDP IXFR requests caused an assertion failure
2843N/A (mpctx->allocated == 0). [RT #355, #394, #623]
2843N/A 660. [port] Detect multiple CPUs on HP-UX and IRIX.
2843N/A 659. [performance] Rewrite the name compression code to be much faster.
2843N/A 658. [cleanup] Remove all vestiges of 16 bit global compression.
2843N/A 657. [bug] When a listen-on statement in an lwres block does not
2843N/A specify a port, use 921, not 53. Also update the
2843N/A listen-on documentation. [RT #616]
2843N/A 656. [func] Treat an unescaped newline in a quoted string as
2843N/A an error. This means that TXT records with missing
2843N/A close quotes should have meaningful errors printed.
2843N/A 655. [bug] Improve error reporting on unexpected eof when loading
2843N/A 654. [bug] Origin was being forgotten in TCP retries in dig.
2843N/A 653. [bug] +defname option in dig was reversed in sense.
2843N/A 652. [bug] zone_saveunique() did not report the new name.
2843N/A 651. [func] The AD bit in responses now has the meaning
2843N/A specified in <draft-ietf-dnsext-ad-is-secure>.
2843N/A 650. [bug] SIG(0) records were being generated and verified
2843N/A 649. [bug] It was possible to join to an already running fctx
2843N/A after it had "cloned" its events, but before it sent
2843N/A them. In this case, the event of the newly joined
2843N/A fetch would not contain the answer, and would
2843N/A trigger the INSIST() in fctx_sendevents(). In
2843N/A BIND 9.0, this bug did not trigger an INSIST(), but
2843N/A caused the fetch to fail with a SERVFAIL result.
2843N/A [RT #588, #597, #605, #607]
2843N/A 648. [port] Add support for pre-RFC2133 IPv6 implementations.
2843N/A 647. [bug] Resolver queries sent after following multiple
2843N/A referrals had excessively long retransmission
2843N/A timeouts due to incorrectly counting the referrals
2843N/A didn't _cleanly_ fix the problem it was trying to fix.
2843N/A 644. [bug] #622 needed more work. [RT #562]
2843N/A 643. [bug] xfrin error messages made more verbose, added class
2843N/A 642. [bug] Break the exit_check() race in the zone module.
2843N/A 641. [bug] $GENERATE caused a uninitialized link to be used.
2843N/A 640. [bug] Memory leak in error path could cause
2843N/A "mpctx->allocated == 0" failure. [RT #584]
2843N/A 639. [bug] Reading entropy from the keyboard would sometimes fail.
2843N/A to get a prototype for time() when pthreads was not
2843N/A 637. [port] Use isc_u?int64_t instead of (unsigned) long long in
2843N/A be compiled even if the platform does not need it.
2843N/A 636. [port] Shut up MSVC++ about a possible loss of precision
2843N/A in the ISC__BUFFER_PUTUINT*() macros. [RT #592]
2843N/A 635. [bug] Reloading a server with a configured blackhole list
2843N/A would cause an assertion. [RT #590]
2843N/A 634. [bug] A log file will completely stop being written when
2843N/A it reaches the maximum size in all cases, not just
2843N/A when versioning is also enabled. [RT #570]
2843N/A 633. [port] Cope with rlim_t missing on
BSD/OS systems. [RT #575]
2843N/A 632. [bug] The index array of the journal file was
2843N/A corrupted as it was written to disk.
2843N/A 631. [port] Build without thread support on systems without
2843N/A 630. [bug] Locking failure in zone code. [RT #582]
2843N/A 629. [bug] 9.1.0b1 dereferenced a null pointer and crashed
2843N/A when responding to a UDP IXFR request.
2843N/A 628. [bug] If the root hints contained only AAAA addresses,
2843N/A named would be unable to perform resolution.
2843N/A 627. [bug] The EDNS0 blackhole detection code of change 324
2843N/A waited for three retransmissions to each server,
2843N/A which takes much too long when a domain has many
2843N/A name servers and all of them drop EDNS0 queries.
2843N/A Now we retry without EDNS0 after three consecutive
2843N/A timeouts, even if they are all from different
2843N/A 626. [bug] The lightweight resolver daemon no longer crashes
2843N/A when asked for a SIG rrset. [RT #558]
2843N/A 625. [func] Zones now inherit their class from the enclosing view.
2843N/A 624. [bug] The zone object could get timer events after it had
2843N/A been destroyed, causing a server crash. [RT #571]
2843N/A 623. [func] Added "named-checkconf" and "named-checkzone" program
2843N/A 622. [bug] A canceled request could be destroyed before
2843N/A dns_request_destroy() was called. [RT #562]
2843N/A 621. [port] Disable IPv6 at runtime if IPv6 sockets are unusable.
2843N/A This mostly affects Red Hat Linux 7.0, which has
2843N/A conflicts between libc and the kernel.
2843N/A 620. [bug] dns_master_load*inc() now require 'task' and 'load'
2843N/A to be non-null. Also 'done' will not be called if
2843N/A dns_master_load*inc() fails immediately. [RT #565]
2843N/A 618. [bug] Queries to a signed zone could sometimes cause
2843N/A 617. [bug] When using dynamic update to add a new RR to an
2843N/A existing RRset with a different TTL, the journal
2843N/A entries generated from the update did not include
2843N/A explicit deletions and re-additions of the existing
2843N/A RRs to update their TTL to the new value.
2843N/A 616. [func] dnssec-signzone -t output now includes performance
2843N/A 615. [bug] dnssec-signzone did not like child keysets signed
2843N/A 614. [bug] Checks for uninitialized link fields were prone
2843N/A to false positives, causing assertion failures.
2843N/A The checks are now disabled by default and may
2843N/A be re-enabled by defining ISC_LIST_CHECKINIT.
2843N/A 613. [bug] "rndc reload zone" now reloads primary zones.
2843N/A It previously only updated slave and stub zones,
2843N/A if an SOA query indicated an out of date serial.
2843N/A 612. [cleanup] Shutup a ridiculously noisy HP-UX compiler that
2843N/A complains relentlessly about how its treatment
2843N/A of 'const' has changed as well as how casting
2843N/A sometimes tightens alignment constraints.
2843N/A 611. [func] allow-notify can be used to permit processing of
2843N/A notify messages from hosts other than a slave's
2843N/A 610. [func] rndc dumpdb is now supported.
2843N/A 609. [bug] getrrsetbyname() would crash lwresd if the server
2843N/A found more SIGs than answers. [RT #554]
2843N/A 608. [func] dnssec-signzone now adds a comment to the zone
2843N/A with the time the file was signed.
2843N/A 607. [bug] nsupdate would fail if it encountered a CNAME or
2843N/A DNAME in a response to an SOA query. [RT #515]
2843N/A 606. [bug] Compiling with --disable-threads failed due
2843N/A to isc_thread_self() being incorrectly defined
2843N/A as an integer rather than a function.
2843N/A 605. [func] New function isc_lex_getlasttokentext().
2843N/A numbers when long comments were present.
2843N/A 603. [bug] Make dig handle multiple types or classes on the same
2843N/A 602. [func] Cope automatically with UnixWare's broken
2843N/A IN6_IS_ADDR_* macros. [RT #539]
2843N/A 601. [func] Return a non-zero exit code if an update fails
2962N/A 600. [bug] Reverse lookups sometimes failed in dig, etc...
2843N/A 599. [func] Added four new functions to the libisc log API to
2843N/A support i18n messages. isc_log_iwrite(),
2843N/A isc_log_ivwrite(), isc_log_iwrite1() and
2843N/A isc_log_ivwrite1() were added.
2962N/A 598. [bug] An update-policy statement would cause the server
2843N/A to assert while loading. [RT #536]
2843N/A 597. [func] dnssec-signzone is now multithreaded.
2843N/A 596. [bug] DNS_RDATASLAB_FORCE and DNS_RDATASLAB_EXACT are
2843N/A 595. [port] On Linux 2.2, socket() returns EINVAL when it
2962N/A should return EAFNOSUPPORT. Work around this.
2843N/A 594. [func] sdb drivers are now assumed to not be thread-safe
2843N/A unless the DNS_SDBFLAG_THREADSAFE flag is supplied.
2843N/A 593. [bug] If a secure zone was missing all its NXTs and
2843N/A a dynamic update was attempted, the server entered
2843N/A 592. [bug] The sig-validity-interval option now specifies a
2843N/A number of days, not seconds. This matches the
2843N/A 591. [bug] Work around non-reentrancy in openssl by disabling
2843N/A 590. [doc] There are now man pages for the lwres library in
2843N/A 589. [bug] The server could deadlock if a zone was updated
2843N/A while being transferred out.
2843N/A 588. [bug] ctx->in_use was not being correctly initialized when
2843N/A when pushing a file for $INCLUDE. [RT #523]
2843N/A 587. [func] A warning is now printed if the "allow-update"
2843N/A option allows updates based on the source IP
2843N/A address, to alert users to the fact that this
2843N/A is insecure and becoming increasingly so as
2843N/A servers capable of update forwarding are being
2843N/A 586. [bug] multiple views with the same name were fatal. [RT #516]
2843N/A 585. [func] dns_db_addrdataset() and and dns_rdataslab_merge()
2843N/A now support 'exact' additions in a similar manner to
2843N/A dns_db_subtractrdataset() and dns_rdataslab_subtract().
2843N/A 584. [func] You can now say 'notify explicit'; to suppress
2843N/A notification of the servers listed in NS records
2843N/A and notify only those servers listed in the
2843N/A 583. [func] "rndc querylog" will now toggle logging of
2843N/A queries, like "ndc querylog" in BIND 8.
2843N/A 582. [bug] dns_zone_idetach() failed to lock the zone.
2843N/A 581. [bug] log severity was not being correctly processed.
2843N/A 580. [func] Ignore trailing garbage on incoming DNS packets,
2843N/A for interoperability with broken server
2843N/A 579. [bug] nsupdate did not take a filename to read update from.
2843N/A 578. [func] New config option "notify-source", to specify the
2843N/A source address for notify messages.
2843N/A 577. [func] Log illegal RDATA combinations.
e.g. multiple
2843N/A singlton types, cname and other data.
2843N/A 576. [doc] isc_log_create() description did not match reality.
2843N/A 575. [bug] isc_log_create() was not setting internal state
2843N/A correctly to reflect the default channels created.
2843N/A 574. [bug] TSIG signed queries sent by the resolver would fail to
2843N/A have their responses validated and would leak memory.
2843N/A 573. [bug] The journal files of IXFRed slave zones were
2843N/A inadvertantly discarded on server reload, causing
2843N/A "journal out of sync with zone" errors on subsequent
2843N/A 572. [bug] Quoted strings were not accepted as key names in
2843N/A 571. [bug] It was possible to create an rdataset of singleton
2843N/A type which had more than one rdata. [RT #154]
2843N/A both a CNAME and "other data". [RT #154]
2843N/A 569. [func] The DNSSEC AD bit will not be set on queries which
2843N/A have not requested a DNSSEC response.
2843N/A 567. [bug] Setting the zone transfer timeout to zero caused an
2843N/A assertion failure. [RT #302]
2843N/A 566. [func] New public function dns_timer_setidle().
2843N/A 565. [func] Log queries more like BIND 8: query logging is now
2843N/A done to category "queries", level "info". [RT #169]
2843N/A 564. [func] Add sortlist support to lwresd.
2843N/A 563. [func] New public functions dns_rdatatype_format() and
2843N/A dns_rdataclass_format(), for convenient formatting
2843N/A 561. [func] The 'datasize', 'stacksize', 'coresize' and 'files'
2843N/A clauses of the options{} statement are now implemented.
2843N/A 560. [bug] dns_name_split did not properly the resulting prefix
2843N/A when a maximal length bitstring label was split which
2843N/A was preceded by another bitstring label. [RT #429]
2843N/A 559. [bug] dns_name_split did not properly create the suffix
2843N/A when splitting within a maximal length bitstring label.
2843N/A 558. [func] New functions, isc_resource_getlimit and
2843N/A 557. [func] Symbolic constants for libisc integral types.
2843N/A 556. [func] The DNSSEC OK bit in the EDNS extended flags
2843N/A is now implemented. Responses to queries without
2843N/A this bit set will not contain any DNSSEC records.
2843N/A 555. [bug] A slave server attempting a zone transfer could
2843N/A crash with an assertion failure on certain
2843N/A malformed responses from the master. [RT #457]
2843N/A 554. [bug] In some cases, not all of the dnssec tools were
2843N/A 553. [bug] Incoming zone transfers deferred due to quota
2843N/A were not started when quota was increased but
2843N/A only when a transfer in progress finished. [RT #456]
2843N/A 552. [bug] We were not correctly detecting the end of all c-style
2843N/A 551. [func] Implemented the 'sortlist' option.
2843N/A 550. [func] Support unknown rdata types and classes.
2843N/A 549. [bug] "make" did not immediately abort the build when a
2843N/A subdirectory make failed [RT #450].
2843N/A 548. [func] The lexer now ungets tokens more correctly.
2843N/A 546. [func] Option 'lame-ttl' is now implemented.
2843N/A 545. [func] Name limit and counting options removed from dig;
2843N/A they didn't work properly, and cannot be correctly
2843N/A implemented without significant changes.
2843N/A 544. [func] Add statistics option, enable statistics-file option,
2843N/A add RNDC option "dump-statistics" to write out a
2843N/A 543. [doc] The 'port' option is now documented.
2843N/A 542. [func] Add support for update forwarding as required for
2843N/A full compliance with RFC2136. It is turned off
2843N/A by default and can be enabled using the
2843N/A 'allow-update-forwarding' option.
2843N/A 541. [func] Add bogus server support.
2843N/A 540. [func] Add dialup support.
2843N/A 539. [func] Support the blackhole option.
2843N/A 538. [bug] fix buffer overruns by 1 in lwres_getnameinfo().
2843N/A 536. [func] Use transfer-source{-v6} when sending refresh queries.
2843N/A Transfer-source{-v6} now take a optional port
2843N/A parameter for setting the UDP source port. The port
2843N/A parameter is ignored for TCP.
2843N/A 535. [func] Use transfer-source{-v6} when forwarding update
2843N/A 534. [func] Ancestors have been removed from RBT chains. Ancestor
2843N/A information can be discerned via node parent pointers.
2843N/A 533. [func] Incorporated name hashing into the RBT database to
2843N/A 532. [func] Implement DNS UPDATE pseudo records using
2843N/A 531. [func] Rdata really should be initialized before being assigned
2843N/A to (dns_rdata_fromwire(), dns_rdata_fromtext(),
2843N/A dns_rdata_clone(), dns_rdata_fromregion()),
2843N/A 530. [func] New function dns_rdata_invalidate().
2843N/A 529. [bug] 521 contained a bug which caused zones to always
1431N/A 528. [func] The ISC_LIST_XXXX macros now perform sanity checks
1431N/A on their arguments. ISC_LIST_XXXXUNSAFE can be use
1431N/A to skip the checks however use with caution.
1431N/A 527. [func] New function dns_rdata_clone().
1431N/A 526. [bug] nsupdate incorrectly refused to add RRs with a TTL
1902N/A 525. [func] New arguments 'options' for dns_db_subtractrdataset(),
1431N/A and 'flags' for dns_rdataslab_subtract() allowing you
1431N/A to request that the RR's must exist prior to deletion.
1431N/A DNS_R_NOTEXACT is returned if the condition is not met.
1191N/A 524. [func] The 'forward' and 'forwarders' statement in
1431N/A non-forward zones should work now.
1537N/A 523. [doc] The source to the Administrator Reference Manual is
1431N/A now an XML file using the DocBook DTD, and is included
2026N/A in the distribution. The plain text version of the
2026N/A ARM is temporarily unavailable while we figure out
2026N/A how to generate readable plain text from the XML.
2026N/A 522. [func] The lightweight resolver daemon can now use
2026N/A a real configuration file, and its functionality
2026N/A can be provided by a name server. Also, the -p and -P
2026N/A options to lwresd have been reversed.
2026N/A 521. [bug] Detect master files which contain $INCLUDE and always
2026N/A 520. [bug] Upgraded libtool to 1.3.5, which makes shared
2026N/A library builds almost work on AIX (and possibly
2028N/A 519. [bug] dns_name_split() would improperly split some bitstring
2606N/A labels, zeroing a few of the least signficant bits in
2028N/A the prefix part. When such an improperly created
2206N/A prefix was returned to the RBT database, the bogus
2028N/A label was dutifully stored, corrupting the tree.
2028N/A 518. [bug] The resolver did not realize that a DNAME which was
2028N/A "the answer" to the client's query was "the answer",
2028N/A and such queries would fail. [RT #399]
2028N/A 517. [bug] The resolver's DNAME code would trigger an assertion
2064N/A if there was more than one DNAME in the chain.
2064N/A 516. [bug] Cache lookups which had a NULL node pointer,
e.g. 2028N/A those by dns_view_find(), and which would match a
2028N/A 515. [bug] The ssu table was not being attached / detached
2028N/A by dns_zone_[sg]etssutable. [RT#397]
2028N/A 514. [func] Retry refresh and notify queries if they timeout.
2028N/A 513. [func] New functionality added to rdnc and server to allow
2028N/A individual zones to be refreshed or reloaded.
2028N/A 512. [bug] The zone transfer code could throw an execption with
2028N/A 511. [bug] The message code could throw an assertion on an
2028N/A out of memory failure. [RT #392]
2028N/A 510. [bug] Remove spurious view notify warning. [RT #376]
2028N/A 509. [func] Add support for write of zone files on shutdown.
2028N/A 508. [func] dns_message_parse() can now do a best-effort
2028N/A attempt, which should allow dig to print more invalid
2028N/A 507. [func] New functions dns_zone_flush(), dns_zt_flushanddetach()
2028N/A and dns_view_flushanddetach().
2028N/A 506. [func] Do not fail to start on errors in zone files.
2028N/A 505. [bug] nsupdate was printing "unknown result code". [RT #373]
2028N/A 504. [bug] The zone was not being marked as dirty when updated via
2028N/A 503. [bug] dumptime was not being set along with
2028N/A 502. [func] On a SERVFAIL reply, DiG will now try the next server
2028N/A in the list, unless the +fail option is specified.
2028N/A 501. [bug] Incorrect port numbers were being displayed by
2028N/A 500. [func] Nearly useless +details option removed from DiG.
2219N/A 499. [func] In DiG, specifying a class with -c or type with -t
2219N/A changes command-line parsing so that classes and
2219N/A types are only recognized if following -c or -t.
2219N/A This allows hosts with the same name as a class or
2028N/A 498. [doc] There is now a man page for "dig"
2028N/A 497. [bug] The error messages printed when an IP match list
2028N/A contained a network address with a nonzero host
2028N/A part where not sufficiently detailed. [RT #365]
2028N/A 496. [bug] named didn't sanity check numeric parameters. [RT #361]
2028N/A 495. [bug] nsupdate was unable to handle large records. [RT #368]
2028N/A 494. [func] Do not cache NXDOMAIN responses for SOA queries.
2028N/A 493. [func] Return non-cachable (ttl = 0) NXDOMAIN responses
2028N/A for SOA queries. This makes it easier to locate
2028N/A the containing zone without polluting intermediate
2028N/A 492. [bug] attempting to reload a zone caused the server fail
2028N/A to shutdown cleanly. [RT #360]
2028N/A 491. [bug] nsupdate would segfault when sending certain
2028N/A prerequisites with empty RDATA. [RT #356]
2028N/A obtained an SOA containing the zone's configured
2028N/A retry time, perform the SOA query retries using
2028N/A exponential backoff. [RT #337]
2028N/A 489. [func] The zone manager now has a "i/o" queue.
2028N/A 488. [bug] Locks weren't properly destroyed in some cases.
2028N/A 487. [port] flockfile() is not defined on all systems.
2028N/A 486. [bug] nslookup: "set all" and "server" commands showed
2028N/A the incorrect port number if a port other than 53
2028N/A 485. [func] When dig had more than one server to query, it would
2028N/A send all of the messages at the same time. Add
2028N/A rate limiting of the transmitted messages.
2028N/A 484. [bug] When the server was reloaded after removing addresses
2028N/A were still listening on the removed addresses due
2028N/A to reference count loops. [RT #325]
2028N/A 483. [bug] nslookup: "set all" showed a "search" option but it
2028N/A 482. [bug] nslookup: a plain "server" or "lserver" should be
2028N/A 481. [bug] nslookup:get_next_command() stack size could exceed
2028N/A 480. [bug] strtok() is not thread safe. [RT #349]
2028N/A 479. [func] The test suite can now be run by typing "make check"
2028N/A or "make test" at the top level.
2028N/A 478. [bug] "make install" failed if the directory specified with
2028N/A --prefix did not already exist.
2028N/A its directory was created. [RT #324]
2028N/A 476. [bug] A zone could expire while a zone transfer was in
2028N/A progress triggering a INSIST failure. [RT #329]
2028N/A 475. [bug] query_getzonedb() sometimes returned a non-null version
2028N/A on failure. This caused assertion failures when
2028N/A generating query responses where names subject to
2028N/A additional section processing pointed to a zone
2028N/A to which access had been denied by means of the
2028N/A allow-query option. [RT #336]
2028N/A 474. [bug] The mnemonic of the CHAOS class is CH according to
2028N/A RFC1035, but it was printed and read only as CHAOS.
2028N/A We now accept both forms as input, and print it
2843N/A 473. [bug] nsupdate overran the end of the list of name servers
2028N/A when no servers could be reached, typically causing
2028N/A it to print the error message "dns_request_create:
2028N/A 472. [bug] Off-by-one error caused isc_time_add() to sometimes
2028N/A produce invalid time values.
2515N/A 470. [func] $GENERATE is now supported. See also
2942N/A 469. [bug] "query-source address * port 53;" now works.
2942N/A 468. [bug] dns_master_load*() failed to report file and line
2064N/A number in certain error conditions.
2064N/A 467. [bug] dns_master_load*() failed to log an error if
2028N/A 466. [bug] dns_master_load*() could return success when it failed.
2028N/A 465. [cleanup] Allow 0 to be set as an omapi_value_t value by
2606N/A 464. [cleanup] Build with openssl's RSA code instead of dnssafe.
2028N/A 463. [bug] nsupdate sent malformed SOA queries to the second
2606N/A query sent to the first one failed.
2606N/A 462. [bug] --disable-ipv6 should work now.
2028N/A 461. [bug] Specifying an unknown key in the "keys" clause of the
2028N/A "controls" statement caused a NULL pointer dereference.
2028N/A 460. [bug] Much of the DNSSEC code only worked with class IN.
2028N/A 459. [bug] Nslookup processed the "set" command incorrectly.
2028N/A 458. [bug] Nslookup didn't properly check class and type values.
2028N/A timeouts in certain situations, causing an
2606N/A unnecessary warning message to be printed.
2028N/A 456. [bug] Stub zones were not resetting the refresh and expire
2028N/A counters, loadtime or clearing the DNS_ZONE_REFRESH
2028N/A (refresh in progress) flag upon successful update.
2028N/A This disabled further refreshing of the stub zone,
2028N/A causing it to eventually expire. [RT #300]
2028N/A 455. [doc] Document IPv4 prefix notation does not require a
2028N/A dotted decimal quad but may be just dotted decimal.
2028N/A 454. [bug] Enforce dotted decimal and dotted decimal quad where
2028N/A 453. [bug] Warn if the obsolete option "maintain-ixfr-base"
2028N/A 452. [bug] Warn if the unimplemented option "statistics-file"
2028N/A 451. [func] Update forwarding implememted.
2028N/A 450. [func] New function ns_client_sendraw().
2028N/A 449. [bug] isc_bitstring_copy() only works correctly if the
2028N/A two bitstrings have the same lsb0 value, but this
2028N/A requirement was not documented, nor was there a
2028N/A 448. [bug] Host output formatting change, to match v8. [RT #255]
2028N/A 447. [bug] Dig didn't properly retry in TCP mode after
2028N/A a truncated reply. [RT #277]
2028N/A 446. [bug] Confusing notify log message. [RT #298]
2028N/A 445. [bug] Doing a 0 bit isc_bitstring_copy() of an lsb0
2028N/A bitstring triggered a REQUIRE statement. The REQUIRE
2028N/A statement was incorrect. [RT #297]
2028N/A 444. [func] "recursion denied" messages are always logged at
2028N/A debug level 1, now, rather than sometimes at ERROR.
2064N/A This silences these warnings in the usual case, where
2028N/A some clients set the RD bit in all queries.
2028N/A 443. [bug] When loading a master file failed because of an
2028N/A unrecognized RR type name, the error message
2028N/A did not include the file name and line number.
2028N/A 442. [bug] TSIG signed messages that did not match any view
2028N/A crashed the server. [RT #290]
2028N/A 441. [bug] Nodes obscured by a DNAME were inaccessible even
2028N/A when DNS_DBFIND_GLUEOK was set.
2028N/A 440. [func] New function dns_zone_forwardupdate().
2028N/A 439. [func] New function dns_request_createraw().
2028N/A 438. [func] New function dns_message_getrawmessage().
2028N/A 437. [func] Log NOTIFY activity to the notify channel.
2028N/A 436. [bug] If recvmsg() returned EHOSTUNREACH or ENETUNREACH,
2028N/A which sometimes happens on Linux, named would enter
2028N/A a busy loop. Also, unexpected socket errors were
2028N/A not logged at a high enough logging level to be
2028N/A useful in diagnosing this situation. [RT #275]
2028N/A 435. [bug] dns_zone_dump() overwrote existing zone files
2028N/A rather than writing to a temporary file and
2028N/A renaming. This could lead to empty or partial
2028N/A zone files being left around in certain error
2028N/A conditions involving the initial transfer of a
2028N/A slave zone, interfering with subsequent server
2028N/A 434. [func] New function isc_file_isabsolute().
2028N/A 433. [func] isc_base64_decodestring() now accepts newlines
2028N/A within the base64 data. This makes it possible
2028N/A to break up the key data in a "trusted-keys"
2028N/A statement into multiple lines. [RT #284]
2028N/A retry time is now a random value between 75% and
2028N/A 100% of the configured value.
2028N/A 431. [func] Log at ISC_LOG_INFO when a zone is successfully
2028N/A 430. [bug] Rewrote the lightweight resolver client management
2028N/A code to handle shutdown correctly and general
2028N/A 429. [bug] The space reserved for a TSIG record in a response
2028N/A was 2 bytes too short, leading to message
2028N/A DNS_R_BADDB for nodes which had neither NXT nor SIG NXT
2028N/A generating negative responses in a secure zone.
2028N/A 427. [bug] Avoid going into an infinite loop when the validator
2028N/A gets a negative response to a key query where the
2028N/A records are signed by the missing key.
2028N/A 426. [bug] Attempting to generate an oversized RSA key could
2028N/A cause dnssec-keygen to dump core.
2028N/A 425. [bug] Warn about the auth-nxdomain default value change
2028N/A if there is no auth-nxdomain statement in the
2028N/A 424. [bug] notify_createmessage() could trigger an assertion
2028N/A failure when creating the notify message failed,
2028N/A e.g. due to corrupt zones with multiple SOA records.
2028N/A 423. [bug] When responding to a recusive query, errors that occur
2028N/A after following a CNAME should cause the query to fail.
2028N/A 422. [func] get rid of isc_random_t, and make isc_random_get()
2028N/A and isc_random_jitter() use rand() internally
2028N/A instead of local state. Note that isc_random_*()
2028N/A functions are only for weak, non-critical "randomness"
2028N/A such as timing jitter and such.
2028N/A 421. [bug] nslookup would exit when given a blank line as input.
2028N/A 420. [bug] nslookup failed to implement the "exit" command.
2028N/A 419. [bug] The certificate type PKIX was misspelled as SKIX.
2028N/A 418. [bug] At debug levels >= 10, getting an unexpected
2028N/A socket receive error would crash the server
2028N/A while trying to log the error message.
2028N/A 417. [func] Add isc_app_block() and isc_app_unblock(), which
2028N/A allow an application to handle signals while
2028N/A 416. [bug] Slave zones with no master file tried to use a
2028N/A NULL pointer for a journal file name when they
2028N/A received an IXFR. [RT #273]
2028N/A 415. [bug] The logging code leaked file descriptors.
2028N/A 414. [bug] Server did not shut down until all incoming zone
2028N/A 413. [bug] Notify could attempt to use the zone database after
2028N/A it had been unloaded. [RT#267]
2028N/A 412. [bug] named -v didn't print the version.
2028N/A 411. [bug] A typo in the HS A code caused an assertion failure.
2606N/A 410. [bug] lwres_gethostbyname() and company set lwres_h_errno
2606N/A to a random value on success.
2606N/A 409. [bug] If named was shut down early in the startup
2606N/A process, ns_omapi_shutdown() would attempt to lock
2606N/A an unintialized mutex. [RT #262]
2606N/A 408. [bug] stub zones could leak memory and reference counts if
2606N/A all the masters were unreachable.
2028N/A 407. [bug] isc_rwlock_lock() would needlessly block
2028N/A readers when it reached the read quota even
2028N/A if no writers were waiting.
2028N/A 406. [bug] Log messages were occasionally lost or corrupted
2028N/A due to a race condition in isc_log_doit().
2028N/A 405. [func] Add support for selective forwarding (forward zones)
2028N/A 404. [bug] The request library didn't completely work with IPv6.
2028N/A 403. [bug] "host" did not use the search list.
2028N/A 402. [bug] Treat undefined acls as errors, rather than
2028N/A warning and then later throwing an assertion.
2028N/A 401. [func] Added simple database API.
2028N/A 400. [bug] SIG(0) signing and verifying was done incorrectly.
2028N/A 399. [bug] When reloading the server with a config file
2028N/A containing a syntax error, it could catch an
2028N/A assertion failure trying to perform zone
2028N/A maintenance on, or sending notifies from,
2028N/A tentatively created zones whose views were
2028N/A never fully configured and lacked an address
2028N/A database and request manager.
2028N/A 398. [bug] "dig" sometimes caught an assertion failure when
2028N/A using TSIG, depending on the key length.
2028N/A 397. [func] Added utility functions dns_view_gettsig() and
2028N/A 396. [doc] There is now a man page for "nsupdate"
2028N/A 395. [bug] nslookup printed incorrect RR type mnemonics
2028N/A for RRs of type >= 21 [RT #237].
2028N/A 394. [bug] Current name was not propagated via $INCLUDE.
2028N/A 393. [func] Initial answer while loading (awl) support.
2028N/A Entry points: dns_master_loadfileinc(),
2028N/A dns_master_loadstreaminc(), dns_master_loadbufferinc().
2028N/A Note: calls to dns_master_load*inc() should be rate
2028N/A be rate limited so as to not use up all file
2028N/A 392. [func] Add ISC_R_FAMILYNOSUPPORT. Returned when OS does
2970N/A not support the given address family requested.
2970N/A 391. [clarity] ISC_R_FAMILY -> ISC_R_FAMILYMISMATCH.
2970N/A 390. [func] The function dns_zone_setdbtype() now takes
2970N/A both the zone database type and its arguments,
2970N/A making the functions dns_zone_adddbarg()
2970N/A and dns_zone_cleardbargs() unnecessary.
2970N/A 389. [bug] Attempting to send a reqeust over IPv6 using
2970N/A dns_request_create() on a system without IPv6
2970N/A support caused an assertion failure [RT #235].
2970N/A 388. [func] dig and host can now do reverse ipv6 lookups.
2970N/A 387. [func] Add dns_byaddr_createptrname(), which converts
2970N/A an address into the name used by a PTR query.
2970N/A 386. [bug] Missing strdup() of ACL name caused random
2970N/A ACL matching failures [RT #228].
2970N/A 385. [cleanup] Removed functions dns_zone_equal(), dns_zone_print(),
2970N/A 384. [bug] nsupdate was incorrectly limiting TTLs to 65535 instead
2970N/A 383. [func] When writing a master file, print the SOA and NS
2970N/A records (and their SIGs) before other records.
2970N/A 382. [bug] named -u failed on many Linux systems where the
2970N/A libc provided kernel headers do not match
2970N/A 381. [bug] Check for IPV6_RECVPKTINFO and use it instead of
2970N/A IPV6_PKTINFO if found. [RT #229]
2970N/A 380. [bug] nsupdate didn't work with IPv6.
2970N/A 379. [func] New library function isc_sockaddr_anyofpf().
2970N/A 378. [func] named and lwresd will log the command line arguments
2970N/A they were started with in the "starting ..." message.
2970N/A 377. [bug] When additional data lookups were refused due to
2970N/A "allow-query", the databases were still being
2970N/A attached causing reference leaks.
2970N/A 376. [bug] The server should always use good entropy when
2970N/A performing cryptographic functions needing entropy.
2970N/A 375. [bug] Per-zone "allow-query" did not properly override the
2970N/A 374. [bug] SOA in authoritative negative responses had wrong TTL.
2970N/A 373. [func] nslookup is now installed by "make install".
2970N/A 372. [bug] Deal with Microsoft DNS servers appending two bytes of
2970N/A garbage to zone transfer requests.
2970N/A 371. [bug] At high debug levels, doing an outgoing zone transfer
2970N/A of a very large RRset could cause an assertion failure
2970N/A 370. [bug] The error messages for rollforward failures were
2970N/A max-retry-time, min-retry-time,
2970N/A max-refresh-time, min-refresh-time.
2970N/A 368. [func] Restructure the internal ".bind" view so that more
2028N/A 367. [bug] Allow proper selection of server on nslookup command
2028N/A 366. [func] Allow use of '-' batch file in dig for stdin.
2028N/A 365. [bug] nsupdate -k leaked memory.
2028N/A 364. [func] Added additional-from-{cache,auth}
2028N/A 362. [bug] rndc no longer aborts if the configuration file is
2028N/A missing an options statement. [RT #209]
2028N/A 361. [func] When the RBT find or chain functions set the name and
2028N/A origin for a node that stores the root label
2028N/A the name is now set to an empty name, instead of ".",
2962N/A to simplify later use of the name and origin by
2028N/A dns_name_concatenate(), dns_name_totext() or
2028N/A 360. [func] dns_name_totext() and dns_name_format() now allow
2028N/A an empty name to be passed, which is formatted as "@".
2028N/A 359. [bug] dnssec-signzone occasionally signed glue records.
2028N/A 358. [cleanup] Rename the intermediate files used by the dnssec
2028N/A 357. [bug] The zone file parser crashed if the argument
2028N/A to $INCLUDE was a quoted string.
2028N/A 356. [cleanup] isc_task_send no longer requires event->sender to
2028N/A 355. [func] Added isc_dir_createunique(), similar to mkdtemp().
2028N/A 354. [doc] Man pages for the dnssec tools are now included in
2028N/A 352. [bug] Race condition in dns_client_t startup could cause
2028N/A 351. [bug] Constructing a response with rcode SERVFAIL to a TSIG
2028N/A signed query could crash the server.
2028N/A 350. [bug] Also-notify lists specified in the global options
2028N/A block were not correctly reference counted, causing
2028N/A 349. [bug] Processing a query with the CD bit set now works
2028N/A and 'additional-from-cache' now supported in view and
2028N/A 347. [bug] Don't crash if an argument is left off options in dig.
2028N/A * Significantly improve structure handling
2028N/A * Don't pre-load entire batch files
2028N/A * Shorten timeouts to match v8's behavior
2028N/A 344. [bug] When shutting down, lwresd sometimes tried
2028N/A to shut down its client tasks twice,
2028N/A 343. [bug] Although zone maintenance SOA queries and
2028N/A notify requests were signed with TSIG keys
2028N/A when configured for the server in case,
2028N/A the TSIG was not verified on the response.
2028N/A 342. [bug] The wrong name was being passed to
2028N/A dns_name_dup() when generating a TSIG
2028N/A statement to allow authentication via TSIG keys:
2028N/A 10.0.0.1 port 5353 key "foo";
2028N/A 340. [bug] The top-level COPYRIGHT file was missing from
2028N/A 339. [bug] DNSSEC validation of the response to an ANY
2028N/A query at a name with a CNAME RR in a secure
2028N/A zone triggered an assertion failure.
2028N/A 338. [bug] lwresd logged to syslog as named, not lwresd.
2028N/A 337. [bug] "dig" did not recognize "nsap-ptr" as an RR type
2028N/A 336. [bug] "dig -f" used 64 k of memory for each line in
2028N/A the file. It now uses much less, though still
2028N/A proportionally to the file size.
2028N/A 335. [bug] named would occasionally attempt recursion when
2028N/A it was disallowed or undesired.
2028N/A 334. [func] Added hmac-md5 to libisc.
2028N/A 333. [bug] The resolver incorrectly accepted referrals to
2028N/A domains that were not parents of the query name,
2028N/A causing assertion failures.
2028N/A 332. [func] New function dns_name_reset().
2028N/A 331. [bug] Only log "recursion denied" if RD is set. [RT #178]
2028N/A 330. [bug] Many debugging messages were partially formatted
2028N/A even when debugging was turned off, causing a
2028N/A significant decrease in query performance.
2028N/A 329. [func] omapi_auth_register() now takes a size_t argument for
2028N/A the length of a key's secret data. Previously
2028N/A OMAPI only stored secrets up to the first NUL byte.
2028N/A 328. [func] Added isc_base64_decodestring().
2028N/A address where a host specification was required.
2028N/A 326. [func] 'keys' in an 'inet' control statement is now
2028N/A required and must have at least one item in it.
2028N/A A "not supported" warning is now issued if a 'unix'
2028N/A control channel is defined.
2028N/A 325. [bug] isc_lex_gettoken was processing octal strings when
2028N/A ISC_LEXOPT_CNUMBER was not set.
2028N/A 324. [func] In the resolver, turn EDNS0 off if there is no
2028N/A response after a number of retransmissions.
2028N/A This is to allow queries some chance of succeeding
2028N/A even if all the authoritative servers of a zone
2028N/A silently discard EDNS0 requests instead of
2028N/A sending an error response like they ought to.
2028N/A 323. [bug] dns_rbt_findname() did not ignore empty rbt nodes.
2028N/A Because of this, servers authoritative for a parent
2028N/A and grandchild zone but not authoritative for the
2028N/A intervening child zone did not correctly issue
2028N/A referrals to the servers of the child zone.
2310N/A 322. [bug] Queries for KEY RRs are now sent to the parent
2028N/A server before the authoritative one, making
2028N/A DNSSEC insecurity proofs work in many cases
2028N/A where they previously didn't.
2028N/A 321. [bug] When synthesizing a CNAME RR for a DNAME
2028N/A response, query_addcname() failed to intitialize
2028N/A the type and class of the CNAME dns_rdata_t,
2028N/A uses authentication to talk to named, command
2028N/A line syntax changed. This will all be described
2028N/A to configure the OMAPI command channel.
2028N/A 318. [func] dns_c_ndcctx_destroy() could never return anything
2028N/A except ISC_R_SUCCESS; made it have void return instead.
2028N/A 317. [func] Use callbacks from libomapi to determine if a
2028N/A new connection is valid, and if a key requested
2028N/A to be used with that connection is valid.
2028N/A 316. [bug] Generate a warning if we detect an unexpected <eof>
2028N/A 315. [bug] Handle non-empty blanks lines. [RT #163]
2028N/A more than one key specified for the inet clause.
2028N/A error. Instead, parse as much as possible, but
2028N/A still return an error if one was found.
2028N/A 312. [bug] Increase the number of allowed elements in the
2028N/A are more than this, ignore the remainder rather
2028N/A than returning a failure in lwres_conf_parse.
2028N/A 311. [bug] lwres_conf_parse failed when the first line of
2028N/A allow { any; } keys { "foo"; }
2028N/A - allow "port xxx" to be left out of statement,
2028N/A in which case it defaults to omapi's default port
2028N/A 309. [bug] When sending a referral, the server did not look
2028N/A for name server addresses as glue in the zone
2028N/A holding the NS RRset in the case where this zone
2028N/A was not the same as the one where it looked for
2028N/A name server addresses as authoritative data.
2028N/A 308. [bug] Treat a SOA record not at top of zone as an error
2028N/A when loading a zone. [RT #154]
2028N/A 307. [bug] When canceling a query, the resolver didn't check for
2028N/A isc_socket_sendto() calls that did not yet have their
2028N/A completion events posted, so it could (rarely) end up
2028N/A destroying the query context and then want to use
2028N/A it again when the send event posted, triggering an
2028N/A assertion as it tried to cancel an already-canceled
2028N/A 306. [bug] Reading HMAC-MD5 private key files didn't work.
2028N/A 305. [bug] When reloading the server with a config file
2028N/A containing a syntax error, it could catch an
2028N/A assertion failure trying to perform zone
2028N/A maintenance on tentatively created zones whose
2028N/A views were never fully configured and lacked
2028N/A 304. [bug] If more than LWRES_CONFMAXNAMESERVERS servers
2028N/A instead of returning failure.
2028N/A 303. [bug] Add additional sanity checks to differentiate a AXFR
2028N/A response vs a IXFR response. [RT #157]
2028N/A 302. [bug] In dig, host, and nslookup, MXNAME should be large
2028N/A enough to hold any legal domain name in presentation
2028N/A 301. [bug] Uninitialized pointer in host:printmessage(). [RT #159]
2028N/A on platforms lacking IPv6 because each included their
2028N/A own ipv6 header file for the missing definitions. Now
2028N/A the other (ISC_IPV6_H and LWRES_IPV6_H).
2028N/A 299. [cleanup] Get the user and group information before changing the
2028N/A root directory, so the administrator does not need to
2028N/A keep a copy of the user and group databases in the
2028N/A chroot'ed environment. Suggested by Hakan Olsson.
2028N/A 298. [bug] A mutex deadlock occurred during shutdown of the
2028N/A interface manager under certain conditions.
2028N/A Digital Unix systems were the most affected.
2028N/A 297. [bug] Specifying a key name that wasn't fully qualified
2028N/A in certain parts of the config file could cause
2028N/A 296. [bug] "make install" from a separate build directory
2028N/A failed unless configure had been run in the source
2028N/A 295. [bug] When invoked with type==CNAME and a message
2028N/A not constructed by dns_message_parse(),
2028N/A dns_message_findname() failed to find anything
2028N/A due to checking for attribute bits that are set
2028N/A only in dns_message_parse(). This caused an
2028N/A infinite loop when constructing the response to
2028N/A an ANY query at a CNAME in a secure zone.
2028N/A 294. [bug] If we run out of space in while processing glue
2028N/A when reading a master file and commit "current name"
2028N/A reverts to "name_current" instead of staying as
2028N/A 293. [port] Add support for FreeBSD 4.0 system tests.
2028N/A 292. [bug] Due to problems with the way some operating systems
2028N/A handle simultaneous listening on IPv4 and IPv6
2028N/A addresses, the server no longer listens on IPv6
2028N/A addresses by default. To revert to the previous
2028N/A behavior, specify "listen-on-v6 { any; };" in
2028N/A 291. [func] Caching servers no longer send outgoing queries
2028N/A over TCP just because the incoming recursive query
2028N/A 290. [cleanup] +twiddle option to dig (for testing only) removed.
2028N/A 289. [cleanup] dig is now installed in $bindir instead of $sbindir.
2028N/A host is now installed in $bindir. (Be sure to remove
2028N/A 288. [func] rndc is now installed by "make install" into $sbindir.
2028N/A 287. [bug] rndc now works again as "rndc 127.1 reload" (for
2028N/A only that task). Parsing its configuration file and
2028N/A using digital signatures for authentication has been
2028N/A disabled until named supports the "controls" statement,
2028N/A 286. [bug] On Solaris 2, when named inherited a signal state
2301N/A where SIGHUP had the SIG_IGN action, SIGHUP would
2301N/A be ignored rather than causing the server to reload
2301N/A 285. [bug] A change made to the dst API for beta4 inadvertently
2301N/A broke OMAPI's creation of a dst key from an incoming
2301N/A message, causing an assertion to be triggered. Fixed.
2301N/A 284. [func] The DNSSEC key generation and signing tools now
2301N/A generate randomness from keyboard input on systems
2301N/A 283. [cleanup] The 'lwresd' program is now a link to 'named'.
2301N/A 282. [bug] The lexer now returns ISC_R_RANGE if parsed integer is
2301N/A too big for an unsigned long.
2301N/A 281. [bug] Fixed list of recognized config file category names.
2301N/A easily build applications that link with
2301N/A 279. [bug] Private omapi function symbols shared between
2301N/A protected using the ISC convention of starting with
2301N/A the library name and two underscores ("omapi__"...)
2301N/A note of when isc_log_categorybyname() wasn't able
2301N/A to find the category name and would then apply the
2301N/A channel list of the unknown category to all categories.
2301N/A 277. [bug] isc_log_categorybyname() and isc_log_modulebyname()
2301N/A would fail to find the first member of any category
2301N/A or module array apart from the internal defaults.
2301N/A Thus, for example, the "notify" category was improperly
2301N/A 276. [bug] dig now supports maximum sized TCP messages.
2301N/A 275. [bug] The definition of lwres_gai_strerror() was missing
2301N/A 274. [bug] TSIG AXFR verify failed when talking to a BIND 8
2301N/A 273. [func] The default for the 'transfer-format' option is
2301N/A now 'many-answers'. This will break zone transfers
2301N/A to BIND 4.9.5 and older unless there is an explicit
2301N/A 'one-answer' configuration.
2301N/A 272. [bug] The sending of large TCP responses was canceled
2301N/A in mid-transmission due to a race condition
2301N/A caused by the failure to set the client object's
2301N/A "newstate" variable correctly when transitioning
2301N/A 271. [func] Attempt to probe the number of cpus in named
2591N/A if unspecified rather than defaulting to 1.
2301N/A 270. [func] Allow maximum sized TCP answers.
2301N/A 269. [bug] Failed DNSSEC validations could cause an assertion
2301N/A failure by causing clone_results() to be called with
2301N/A 268. [doc] A plain text version of the Administrator
2301N/A Reference Manual is now included in the distribution,
2301N/A 267. [func] Nsupdate is now provided in the distribution.
2301N/A 266. [bug]
zone.c:save_nsrrset() node was not initialized.
2301N/A 265. [bug] dns_request_create() now works for TCP.
2301N/A 264. [func] Dispatch can not take TCP sockets in connecting
2301N/A state. Set DNS_DISPATCHATTR_CONNECTED when calling
2301N/A dns_dispatch_createtcp() for connected TCP sockets
2301N/A or call dns_dispatch_starttcp() when the socket is
2028N/A 263. [func] New logging channel type 'stderr'
2028N/A 262. [bug] 'master' was not initialized in
zone.c:stub_callback().
2028N/A 261. [func] Add dns_zone_markdirty().
2028N/A 260. [bug] Running named as a non-root user failed on Linux
2028N/A kernels new enough to support retaining capabilities
2028N/A 259. [func] New random-device and random-seed-file statements
2028N/A 257. [bug] The server detached the last zone manager reference
2028N/A too early, while it could still be in use by queries.
2028N/A This manifested itself as assertion failures during the
2028N/A shutdown process for busy name servers. [RT #133]
2301N/A isc_ratelimiter_shutdown guarantees that the rate
2301N/A limiter is detached from its task.
2301N/A 255. [func] New function dns_zonemgr_attach().
2301N/A 254. [bug] Suppress "query denied" messages on additional data
2301N/A comments (anywhere in line, not just as the beginning).
2301N/A It also aborted when an unrecognized keyword was seen,
2301N/A now it silently ignores the entire line.
2301N/A 251. [bug] lwresd caught an assertion failure on startup.
2301N/A 250. [bug] fixed handling of size+unit when value would be too
2301N/A large for internal representation.
2301N/A 249. [cleanup] max-cache-size config option now takes a size-spec
2301N/A like 'datasize', except 'default' is not allowed.
2301N/A 248. [bug] global lame-ttl option was not being printed when
2301N/A config structures were written out.
2301N/A 247. [cleanup] Rename cache-size config option to max-cache-size.
2301N/A 246. [func] Rename global option cachesize to cache-size and
2301N/A add corresponding option to view statement.
2301N/A 245. [bug] If an uncompressed name will take more than 255
2301N/A bytes and the buffer is sufficiently long,
2301N/A dns_name_fromwire should return DNS_R_FORMERR,
2301N/A not ISC_R_NOSPACE. This bug caused cause the
2301N/A server to catch an assertion failure when it
2301N/A received a query for a name longer than 255
2301N/A 242. [cleanup] fixed incorrect warning about auth-nxdomain usage.
2301N/A 241. [cleanup] nscount and soacount have been removed from the
2301N/A dns_master_*() argument lists.
2301N/A 240. [func] databases now come in three flavours: zone, cache
2301N/A 239. [func] If ISC_MEM_DEBUG is enabled, the variable
2301N/A isc_mem_debugging controls whether messages
2028N/A 238. [cleanup] A few more compilation warnings have been quieted:
2028N/A + PTHREAD_ONCE_INIT unbraced initializer warnings on
2028N/A + IN6ADDR_ANY_INIT unbraced initializer warnings on
2028N/A 237. [bug] If connect() returned ENOBUFS when the resolver was
2028N/A initiating a TCP query, the socket didn't get
2028N/A destroyed, and the server did not shut down cleanly.
2028N/A 236. [func] Added new listen-on-v6 config file statement.
2028N/A 235. [func] Consider it a config file error if a listen-on
2028N/A statement has an IPv6 address in it, or a
2028N/A listen-on-v6 statement has an IPv4 address in it.
2028N/A 234. [bug] Allow a trusted-key's first field (domain-name) be
2028N/A either a quoted or an unquoted string, instead of
2028N/A 233. [cleanup] Convert all config structure integer values to unsigned
2028N/A integer (isc_uint32_t) to match grammer.
2028N/A 232. [bug] Allow slave zones to not have a file.
2028N/A 231. [func] Support new 'port' clause in config file options
2028N/A section. Causes 'listen-on', 'masters' and
2028N/A 'also-notify' statements to use its value instead of
2028N/A 229. [func] Support config file sig-validity-interval statement
2028N/A in options, views and zone statements (master
2028N/A 228. [cleanup] Logging messages in config module stripped of
2028N/A 227. [cleanup] The enumerated identifiers dns_rdataclass_*,
2028N/A dns_rcode_*, dns_opcode_*, and dns_trust_* are
2028N/A also now cast to their appropriate types, as with
2028N/A dns_rdatatype_* in item number 225 below.
2028N/A 226. [func] dns_name_totext() now always prints the root name as
2028N/A '.', even when omit_final_dot is true.
2028N/A 225. [cleanup] The enumerated dns_rdatatype_* identifiers are now
2028N/A cast to dns_rdatatype_t via macros of their same name
2028N/A so that they are of the proper integral type wherever
2028N/A a dns_rdatatype_t is needed.
2028N/A 224. [cleanup] The entire project builds cleanly with gcc's
2028N/A -Wcast-qual and -Wwrite-strings warnings enabled,
2028N/A which is now the default when using gcc. (Warnings
2028N/A unfortunately to be expected.)
2028N/A 223. [func] Several functions were reprototyped to qualify one
2028N/A or more of their arguments with "const". Similarly,
2028N/A several functions that return pointers now have
2028N/A those pointers qualified with const.
2028N/A 222. [bug] The global 'also-notify' option was ignored.
2028N/A 221. [bug] An uninitialized variable was sometimes passed to
2028N/A dns_rdata_freestruct() when loading a zone, causing
2028N/A 220. [cleanup] Set the default outgoing port in the view, and
2028N/A set it in sockaddrs returned from the ADB.
2028N/A 219. [bug] Signed truncated messages more correctly follow
2028N/A 218. [func] When an rdataset is signed, its ttl is normalized
2028N/A based on the signature validity period.
2028N/A 217. [func] Also-notify and trusted-keys can now be used in
2028N/A 216. [func] The 'max-cache-ttl' and 'max-ncache-ttl' options
2028N/A 215. [bug] Failures at certain points in request processing
2028N/A could cause the assertion INSIST(client->lockview
2028N/A 214. [func] New public function isc_netaddr_format(), for
2028N/A formatting network addresses in log messages.
2028N/A 213. [bug] Don't leak memory when reloading the zone if
2028N/A an update-policy clause was present in the old zone.
2028N/A 211. [func] The 'key' and 'server' statements can now occur
2028N/A 210. [bug] The 'allow-transfer' option was ignored for slave
2028N/A zones, and the 'transfers-per-ns' option was
2843N/A 209. [cleanup] Upgraded openssl files to new version 0.9.5a
2843N/A 208. [func] Added ISC_OFFSET_MAXIMUM for the maximum value
2843N/A 207. [func] The dnssec tools properly use the logging subsystem.
2843N/A 206. [cleanup] dst now stores the key name as a dns_name_t, not
2843N/A 205. [cleanup] On IRIX, turn off the mostly harmless warnings 1692
2843N/A ("prototyped function redeclared without prototype")
2843N/A and 1552 ("variable ... set but not used") when
2843N/A directories, which contain code imported from outside
2843N/A 204. [cleanup] On
HP/UX, pass +vnocompatwarnings to the linker
2843N/A to quiet the warnings that "The linked output may not
2843N/A 203. [func] notify and zone soa queries are now tsig signed when
2843N/A 202. [func] isc_lex_getsourceline() changed from returning int
2843N/A to returning unsigned long, the type of its underlying
2843N/A 200. [bug] Failures in sending query responses to clients
2843N/A 199. [bug] isc_heap_delete() sometimes violated the heap
2843N/A invariant, causing timer events not to be posted
2843N/A 198. [func] Dispatch managers hold memory pools which
2843N/A any managed dispatcher may use. This allows
2843N/A us to avoid dipping into the memory context for
2843N/A most allocations. [19-May-2000 explorer]
2843N/A 197. [bug] When an incoming AXFR or IXFR completes, the
2843N/A zone's internal state is refreshed from the
2843N/A SOA data. [19-May-2000 explorer]
2843N/A 196. [func] Dispatchers can be shared easily between views
2843N/A 195. [bug] Including the NXT record of the root domain
2843N/A in a negative response caused an assertion
2843N/A 194. [doc] The PDF version of the Administrator's Reference
2843N/A Manual is no longer included in the ISC BIND9
2843N/A 193. [func] changed dst_key_free() prototype.
2843N/A 192. [bug] Zone configuration validation is now done at end
2843N/A of config file parsing, and before loading
2843N/A 191. [func] Patched to compile on UnixWare
7.x. This platform
2843N/A is not directly supported by the ISC.
2843N/A 190. [cleanup] The DNSSEC tools have been moved to a separate
2843N/A directory dnssec/ and given the following new,
2028N/A Their command line arguments have also been changed to
2028N/A be more consistent. dnssec-keygen now prints the
2028N/A name of the generated key files (sans extension)
2026N/A on standard output to simplify its use in automated
1191N/A 189. [func] isc_time_secondsastimet(), a new function, will ensure
1431N/A that the number of seconds in an isc_time_t does not
1431N/A exceed the range of a time_t, or return ISC_R_RANGE.
1431N/A Similarly, isc_time_now(), isc_time_nowplusinterval(),
1431N/A isc_time_add() and isc_time_subtract() now check the
1191N/A isc_time_subtract, this changed a calling requirement
2028N/A (ie, something that could generate an assertion)
2028N/A into merely a condition that returns an error result.
2028N/A isc_time_add() and isc_time_subtract() were void-
2028N/A valued before but now return isc_result_t.
2028N/A 188. [func] Log a warning message when an incoming zone transfer
2028N/A 187. [func] isc_ratelimter_enqueue() has an additional argument
1191N/A 186. [func] dns_request_getresponse() has an additional argument
1968N/A 185. [bug] Fixed up handling of ISC_MEMCLUSTER_LEGACY. Several
1968N/A public functions did not have an isc__ prefix, and
1968N/A referred to functions that had previously been
1968N/A standard, which says that such names are reserved.
1968N/A 183. [func] ISC_LOG_PRINTTAG option for log channels. Useful
1968N/A for logging the program name or other identifier.
1968N/A 182. [cleanup] New commandline parameters for dnssec tools
1968N/A 181. [func] Added dst_key_buildfilename and dst_key_parsefilename
1968N/A 180. [func] New isc_result_t ISC_R_RANGE. Supersedes DNS_R_RANGE.
1968N/A before any zone or view statements.
1968N/A has non-empty list of masters defined.
1968N/A 177. [func] New per-zone boolean:
2028N/A intended to let a zone be disabled without having
2028N/A to comment out the entire zone statement.
2028N/A 176. [func] New global and per-view option:
2097N/A 175. [func] New global and per-view option:
2028N/A additional-data internal | minimal | maximal;
2028N/A 174. [func] New public function isc_sockaddr_format(), for
2028N/A formatting socket addresses in log messages.
2028N/A 173. [func] Keep a queue of zones waiting for zone transfer
2028N/A quota so that a new transfer can be dispatched
2097N/A immediately whenever quota becomes available.
2028N/A 172. [bug] $TTL directive was sometimes missing from dumped
2028N/A master files because totext_ctx_init() failed to
2028N/A initialize ctx->current_ttl_valid.
2028N/A 171. [cleanup] On NetBSD systems, the mit-pthreads or
2028N/A unproven-pthreads library is now always used
2028N/A unless --with-ptl2 is explicitly specified on
2028N/A the configure command line. The
2028N/A --with-mit-pthreads option is no longer needed
2028N/A 170. [cleanup] Remove inter server consistancy checks from zone,
1968N/A these should return as a seperate module in 9.1.
1968N/A dns_zone_checkservers(), dns_zone_checkparents(),
1968N/A dns_zone_checkchildren(), dns_zone_checkglue().
1968N/A Remove dns_zone_setadb(), dns_zone_setresolver(),
1968N/A dns_zone_setrequestmgr() these should now be found
1968N/A 169. [func] ratelimiter can now process N events per interval.
1968N/A due to not consuming the semicolon ending the include
1968N/A statement before switching input streams.
1968N/A 167. [bug] Make lack of masters for a slave zone a soft error.
2097N/A 166. [bug] Keygen was overwriting existing keys if key_id
1968N/A conflicted, now it will retry, and non-null keys
1968N/A with key_id == 0 are not generated anymore. Key
2097N/A was not able to generate NOAUTHCONF DSA key,
1968N/A increased RSA key size to 2048 bits.
1968N/A 165. [cleanup] Silence "end-of-loop condition not reached" warnings
1968N/A 164. [func] Added functions isc_stdio_open(), isc_stdio_close(),
1968N/A isc_stdio_seek(), isc_stdio_read(), isc_stdio_write(),
1968N/A isc_stdio_flush(), isc_stdio_sync(), isc_file_remove()
1968N/A to encapsulate nonportable usage of errno and sync.
1968N/A 163. [func] Added result codes ISC_R_FILENOTFOUND and
2028N/A 162. [bug] Ensure proper range for arguments to
ctype.h functions.
2028N/A 161. [cleanup] error in yyparse prototype that only HPUX caught.
2028N/A 160. [cleanup] getnet*() are not going to be implemented at this
2843N/A 159. [func] Redefinition of config file elements is now an
2843N/A error (instead of a warning).
2028N/A 158. [bug] Log channel and category list copy routines
2028N/A weren't assigning properly to output parameter.
1968N/A 157. [port] Fix missing prototype for getopt().
1968N/A 156. [func] Support new 'database' statement in zone.
1968N/A 155. [bug] ns_notify_start() was not detaching the found zone.
1968N/A 154. [func] The signer now logs libdns warnings to stderr even when
1968N/A not verbose, and in a nicer format.
2028N/A 153. [func] dns_rdata_tostruct() 'mctx' is now optional. If 'mctx'
2028N/A is NULL then you need to preserve the 'rdata' until
1968N/A you have finished using the structure as there may be
2028N/A references to the associated memory. If 'mctx' is
2028N/A non-NULL it is guaranteed that there are no references
2028N/A to memory associated with 'rdata'.
1968N/A dns_rdata_freestruct() must be called if 'mctx' was
2028N/A non-NULL and may safely be called if 'mctx' was NULL.
2028N/A 152. [bug] keygen dumped core if domain name argument was omitted
1968N/A 151. [func] Support 'disabled' statement in zone config (causes
1968N/A zone to be parsed and then ignored). Currently must
1968N/A come after the 'type' clause.
2028N/A 150. [func] Support optional ports in masters and also-notify
2028N/A 149. [cleanup] Removed usused argument 'olist' from
2028N/A dns_c_view_unsetordering().
2064N/A 148. [cleanup] Stop issuing some warnings about some configuration
2064N/A file statements that were not implemented, but now are.
2064N/A 147. [bug] Changed yacc union size to be smaller for yaccs that
2064N/A put yacc-stack on the real stack.
2028N/A 146. [cleanup] More general redundant header file cleanup. Rather
2028N/A than continuing to itemize every header which changed,
2028N/A this changelog entry just notes that if a header file
2028N/A did not need another header file that it was including
2028N/A in order to provide its advertized functionality, the
2028N/A inclusion of the other header file was removed. See
2028N/A ISC_LANG_ENDDECLS to header files that had function
2028N/A prototypes, and removed it from those that did not.
2028N/A 144. [cleanup] libdns header files too numerous to name were made
2028N/A to conform to the same style for multiple inclusion
2028N/A 143. [func] Added function dns_rdatatype_isknown().
2028N/A 141. [bug] Corrupt requests with multiple questions could
2028N/A cause an assertion failure.
138. [cleanup] isc_strtouq moved from str.[ch] to string.[ch] and
renamed isc_string_touint64. isc_strsep moved from
made to conform to the same style for multiple
for ISC_R_* codes used in macros.
129. [bug] The 'default_debug' log channel was not set up when
'category default' was present in the config file
128. [cleanup] <
isc/dir.h> had ISC_LANG_BEGINDECLS instead of
ISC_LANG_ENDDECLS at end of header.
127. [cleanup] The contracts for the comparision routines
dns_name_fullcompare(), dns_name_compare(),
dns_name_rdatacompare(), and dns_rdata_compare() now
specify that the order value returned is < 0, 0, or > 0
124. [func] signer now imports parent's zone key signature
and creates null
keys/sets zone status bit for
symbol fixed from ISC_SYMBOL_H to ISC_SYMTAB_H.
119. [cleanup] structure definitions for generic rdata stuctures do
not have _generic_ in their names.
118. [cleanup]
libdns.a is now namespace-clean, on NetBSD, excepting
YACC crust (yyparse, etc) [2000-apr-27 explorer]
dns_zone_clearnotify() and dns_zone_addnotify()
are replaced by dns_zone_setnotifyalso().
dns_zone_clearmasters() and dns_zone_addmaster()
are replaced by dns_zone_setmasters().
116. [func] Added <
isc/offset.h> for isc_offset_t (aka off_t
115. [port] Shut up the -Wmissing-declarations warning about
113. [func] Utility programs dig and host added.
109. [bug] "make depend" did nothing for
107. [func] Add keysigner and keysettool.
106. [func] Allow dnssec verifications to ignore the validity
period. Used by several of the dnssec tools.
implicit conventions the developers have used.
104. [bug] Made compress_add and compress_find static to
isc_buffer_base(b) (pointer)
isc_buffer_current(b) (pointer)
isc_buffer_active(b) (pointer)
isc_buffer_used(b) (pointer)
isc_buffer_length(b) (int)
isc_buffer_usedlength(b) (int)
isc_buffer_consumedlength(b) (int)
isc_buffer_remaininglength(b) (int)
isc_buffer_activelength(b) (int)
isc_buffer_availablelength(b) (int)
ISC_BUFFER_AVAILABLECOUNT(b)
isc_buffer_usedregion(b, r)
isc_buffer_available(b, r) ->
isc_buffer_available_region(b, r)
isc_buffer_consumed(b, r) ->
isc_buffer_consumedregion(b, r)
isc_buffer_active(b, r) ->
isc_buffer_activeregion(b, r)
isc_buffer_remaining(b, r) ->
isc_buffer_remainingregion(b, r)
Buffer types were removed, so the ISC_BUFFERTYPE_*
macros are no more, and the type argument to
isc_buffer_init and isc_buffer_allocate were removed.
isc_buffer_putstr is now void (instead of isc_result_t)
and requires that the caller ensure that there
is enough available buffer space for the string.
102. [port] Correctly detect inet_aton, inet_pton and inet_ptop
99. [cleanup] Rate limiter now has separate shutdown() and
destroy() functions, and it guarantees that all
queued events are delivered even in the shutdown case.
unless ISC_PLATFORM_NEEDVSNPRINTF is defined.
94. [cleanup] Some installed header files did not compile as C++.
<
isc/mem.h>. isc_interface_t and isc_interfaceiter_t
84. [func] allow-query ACL checks now apply to all data
83. [func] If the server is authoritative for both a
delegating zone and its (nonsecure) delegatee, and
a query is made for a KEY RR at the top of the
delegatee, then the server will look for a KEY
in the delegator if it is not found in the delegatee.
78. [cleanup] lwres_conftest renamed to lwresconf_test for
consistency with other *_test programs.
77. [cleanup] typedef of isc_time_t and isc_interval_t moved from
76. [cleanup] Rewrote keygen.
75. [func] Don't load a zone if its database file is older
than the last time the zone was loaded.
73. [func] New "file" API in libisc, including new function
isc_file_getmodtime, isc_mktemplate renamed to
isc_file_mktemplate and isc_ufile renamed to
isc_file_openunique. By no means an exhaustive API,
it is just what's needed for now.
72. [func] DNS_RBTFIND_NOPREDECESSOR and DNS_RBTFIND_NOOPTIONS
added for dns_rbt_findnode, the former to disable the
setting of the chain to the predecessor, and the
latter to make clear when no options are set.
71. [cleanup] Made explicit the implicit REQUIREs of
isc_time_seconds, isc_time_nanoseconds, and
70. [func] isc_time_set() added.
69. [bug] The zone object's master and also-notify lists grew
longer with each server reload.
68. [func] Partial support for SIG(0) on incoming messages.
67. [performance] Allow use of alternate (compile-time supplied)
66. [func] Data in authoritative zones should have a trust level
65. [cleanup] Removed obsolete typedef of dns_zone_callbackarg_t
64. [func] The RBT, DB, and zone table APIs now allow the
caller find the most-enclosing superdomain of
63 [func] Generate NOTIFY messages.
62. [func] Add UDP refresh support.
61. [cleanup] Use single quotes consistently in log messages.
60. [func] Catch and disallow singleton types on message
59. [bug] Cause
net/host unreachable to be a hard error
when sending and receiving.
== 0 assertion in query_newname().
57. [func] Added dns_nxt_typepresent()
56. [bug] SIG records were not properly returned in cached
55. [bug] Responses containing multiple names in the authority
section were not negatively cached.
54. [bug] If a fetch with sigrdataset==NULL joined one with
sigrdataset!=NULL or vice versa, the resolver
could catch an assertion or lose signature data,
52. [bug] rndc: taskmgr and socketmgr were not initialized
50. [func] RBT deletion no longer requires a valid chain to work,
and dns_rbt_deletenode was added.
49. [func] Each cache now has its own mctx.
48. [func] isc_task_create() no longer takes an mctx.
isc_task_mem() has been eliminated.
47. [func] A number of modules now use memory context reference
46. [func] Memory contexts are now reference counted.
Added isc_mem_inuse() and isc_mem_preallocate().
Renamed isc_mem_destroy_check() to
isc_mem_setdestroycheck().
45. [bug] The trusted-key statement incorrectly loaded keys.
44. [bug] Don't include authority data if it would force us
to unset the AD bit in the message.
43. [bug] DNSSEC verification of cached rdatasets was failing.
42. [cleanup] Simplified logging of messages with embedded domain
names by introducing a new convenience function
41. [func] Use PR_SET_KEEPCAPS on Linux 2.3.99-pre3 and later
to allow 'named' to run as a non-root user while
retaining the ability to bind() to privileged
40. [func] Introduced new logging category "dnssec" and
39. [cleanup] Moved the typedefs for isc_region_t, isc_textregion_t,
38. [bug] TSIG signed incoming zone transfers work now.
37. [bug] If the first RR in an incoming zone transfer was
not an SOA, the server died with an assertion failure
instead of just reporting an error.
36. [cleanup] Change DNS_R_SUCCESS (and others) to ISC_R_SUCCESS
35. [performance] Log messages which are of a level too high to be
logged by any channel in the logging configuration
will not cause the log mutex to be locked.
34. [bug] Recursion was allowed even with 'recursion no'.
33. [func] The RBT now maintains a parent pointer at each node.
30. [func] config file grammer change to support optional
29. [func] support new config file view options:
auth-nxdomain recursion query-source
query-source-v6 transfer-source
transfer-source-v6 max-transfer-time-out
max-transfer-idle-out transfer-format
request-ixfr provide-ixfr cleaning-interval
fetch-glue notify rfc2308-type1 lame-ttl
28. [func] support lame-ttl, min-roots and serial-queries
Including it on other platforms (eg, NetBSD) can
cause a forced #error from the C preprocessor.
26. [func] new match-clients statement in config file view.
25. [bug] make install failed to install <
isc/log.h> and
24. [cleanup] Eliminate some unnecessary #includes of header
23. [cleanup] Provide more context in log messages about client
requests, using a new function ns_client_log().
22. [bug] SIGs weren't returned in the answer section when
the query resulted in a fetch.
21. [port] Look at STD_CINCLUDES after CINCLUDES during
compilation, so additional system include directories
can be searched but header files in the bind9 source
tree with conflicting names take precedence. This
avoids issues with installed versions of dnssafe and
20. [func] Configuration file post-load validation of zones
failed if there were no zones.
19. [bug] dns_zone_notifyreceive() failed to unlock the zone
lock in certain error cases.
18. [bug] Use AC_TRY_LINK rather than AC_TRY_COMPILE in
17. [func] Do configuration file post-load validation of zones.
16. [bug] put quotes around key names on config file
output to avoid possible keyword clashes.
15. [func] Add dns_name_dupwithoffsets(). This function is
improves comparison performance for duped names.
14. [bug] free_rbtdb() could have 'put' unallocated memory in
12. [bug] Fixed possible unitialized variable error.
11. [bug] axfr_rrstream_first() didn't check the result code of
db_rr_iterator_first(), possibly causing an assertion
10. [bug] A bug in the code which makes EDNS0 OPT records in
9. [cleanup] replaced bit-setting code in
confctx.c and replaced
repeated code with macro calls.
8. [bug] Shutdown of incoming zone transfer accessed
7. [cleanup] removed 'listen-on' from view statement.
6. [bug] quote RR names when generating config file to
prevent possible clash with config file keywords
statements must now be enclosed by an 'update-policy'
linux 2.3 kernel includes due to conflicts between
C library includes and the kernel includes. We now
avoid pulling in other linux kernel .h files.
3. [bug] TKEYs go in the answer section of responses, not
2. [bug] Generating cryptographic randomness failed on
1. [bug] The installdirs rule in
prevented the isc directory from being created if it
# This tells Emacs to use hard tabs in this file.